Leyou Zhang

dblp:87/317 · DBLP profile ↗
← Back
38ranked-venue papers
15as first author
29since 2021 · last 2026
0000-0003-4950-1140ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 11 · 3 first-author · 7 since 2021Systems, architecture and hardware · 9 · 1 first-author · 9 since 2021Computer networks · 9 · 6 first-author · 9 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 2 first-author · 1 since 2021Artificial intelligence and machine learning · 2 · 1 first-author · 1 since 2021Software engineering, systems software and programming languages · 2 · 1 first-author · 2 since 2021Theory of computation · 1 · 1 first-author
YearPublicationVenuePosition
2026 Lightweight distributed data sharing with dual anonymity for accident traceability in VANETs
Leyou Zhang, Qing Wu 0005, Fatemeh Rezaeibagha
J. Inf. Secur. Appl.2
2026 Enhanced verifiable traceability and policy update data-sharing system for IoMT against flooding and DDoS attacks
Leyou Zhang, Lingfeng Yang, Qing Wu 0005
J. Inf. Secur. Appl.1
2026 Cloud-aided practical multi-keyword medical data retrieval based on ABE
Baichengjia Sun, Leyou Zhang, Ronghua Liang
J. Syst. Archit.2
2026 Low storage and fast single-server private information retrieval with sublinear server computation for intelligent medical care
Leyou Zhang, Yuqi Jia 0002, Qing Wu 0005
Knowl. Based Syst.1
2026 Cloud-Assisted Verifiable and Updatable Private Set Union Protocol for Enhancing Network Intrusion Detection
Qing Wu 0005, Xijia Dong, Leyou Zhang, Yue Lei, Zilong Yan
IEEE Trans. Netw. Serv. Manag.3
2025 Revisiting LWR: A Novel Reduction Through Quantum Approximations
abstract
Pseudorandom functions (PRFs) are a very important tool in cryptography, and the learning with rounding (LWR) problem is one of the main issues in their construction. LWR problem, is to find from ⌊ A s ⌋ p , where and is the rounding function. The LWR problem is considered a variant of the learning with error (LWE) problem, that is, to find s from b = A s + e , where , and LWE has been reduced to GapSVP and SIVP. The hardness of the lattice problems is the security foundation of the issued schemes. The best‐known reduction for LWR was completed using information‐theoretic entropy arguments, and the reduction requires q ≥ 2 n m p . It does not directly reduce to the closest vector problem (CVP) problem, but rather to the LWE problem. However, the reduction in the aforementioned work significantly reduces the difficulty of LWR. To more accurately characterize the hardness of LWR, this paper uses statistical approximation and a Quantum Fourier Transform to reduce LWR to the CVP, thereby ensuring the hardness of LWR. Furthermore, unlike the previous conclusions, our reduction involves minimal loss and has broad security conditions, requiring only that , where q and p are prime numbers and 0 < α < 1.
Zhuang Shan, Leyou Zhang, Qiqi Lai
IET Inf. Secur.2
2025 Traceable and Verifiable Authorized Cloud-Assisted PSI-CA Protocol for Blockchain-Enabled Intelligent Logistics
abstract
Amid the rapid development of e-commerce and logistics, enterprises urgently require advanced digital technologies to achieve modernization and intelligent transformation, thereby meeting the fast-changing market demands. Within the logistics Internet of Things (IoT), companies face numerous scenarios that necessitate quantifying the degree of data overlap, where only acquiring statistical information suffices. The Private Set Intersection Cardinality (PSI-CA) technology offers an almost ideal solution. However, an effective approach must not only safeguard privacy but also enable companies to demonstrate their data protection capabilities to consumers. Existing PSI-CA solutions neglect the sustainable development needs of enterprises in terms of data correctness, integrity, management transparency, and user retention. Therefore, this paper proposes, for the first time, a trackable and verifiable authorized cloud-assisted PSI-CA (TVACPSI-CA) protocol, upon which a multi-threaded intelligent logistics system (ILS) is designed to harmonize data privacy protection with operational efficiency in logistics enterprises. The protocol employs accumulators, oblivious pseudorandom function (OPRF), zero-knowledge proof, digital signatures and blockchain technology to achieve objectives such as data privacy protection, access control, correctness verification of delegated computation, data integrity protection, abuse resistance, and traceability. This facilitates enterprises in mitigating security risks and enhancing customer trust. We rigorously analyze and prove the security of our solution. Finally, a comparative analysis with existing approaches demonstrates that the proposed scheme balances between high security and low communication/computational overhead. This provides the logistics industry with a secure, efficient, and scalable data-sharing solution, thereby enabling operational optimization.
Qing Wu 0005, Yue Lei, Leyou Zhang, Xijia Dong, Fatemeh Rezaeibagha
IEEE Internet Things J.3
2025 PrivaRisk: Verifiable and auditable OPRF-based PSI for financial data sharing
Yue Lei, Qing Wu 0005, Leyou Zhang, Xijia Dong, Zilong Yan
J. Inf. Secur. Appl.3
2025 Authenticable Distributed Homomorphic Private Counter and its application in data analysis of edge computing
abstract
The rapid proliferation of advanced technologies, including the Internet of Things (IoT), cloud computing , and edge computing , has led to an exponential growth in structured and unstructured data, generated and collected across diverse applications. It is important to develop secure techniques that can efficiently process large volumes of data while preserving privacy. Privacy-preserving data analytics on encrypted data have gained popularity for performing essential calculations within cloud storage servers . However, applying these techniques to fully homomorphic encryption introduces inefficiencies and computational overheads. While homomorphic encryption allows for delegated execution of arithmetic operations directly on ciphertexts via cloud services, ensuring both efficiency and correctness in data computations remains a challenging endeavor. Most existing studies overlook simultaneous data aggregation while maintaining integrity and privacy for analytical purposes. In response, we propose an Authenticable Distributed Homomorphic Private Counter Scheme (ADHPC) for privacy-preserving data analysis in cloud computing. Our scheme securely and efficiently aggregates encrypted data within distributed edge computing environments, subsequently allowing authorized parties to decrypt and validate it. To authenticate the encrypted data, we employ an authenticable additive homomorphic encryption scheme based on online and offline setup stages. We demonstrate the applicability and efficiency of our proposed approach through implementation results and a comprehensive security analysis.
Fatemeh Rezaeibagha, Leyou Zhang, Ke Huang 0002, Lanxiang Chen
J. Inf. Secur. Appl.2
2025 Cloud-assisted verifiable and traceable multi-party threshold private set intersection protocol for ride-sharing scheme
Qing Wu 0005, Xijia Dong, Leyou Zhang, Yue Lei, Ziquan Zhao
J. Inf. Secur. Appl.3
2025 Fast post-quantum private set intersection from oblivious pseudorandom function for mobile social networks
Zhuang Shan, Leyou Zhang, Qing Wu 0005, Qiqi Lai, Fuchun Guo
J. Syst. Archit.2
2024 Blockchain-Aided Anonymous Traceable and Revocable Access Control Scheme With Dynamic Policy Updating for the Cloud IoT
abstract
The Internet of Things has been applied in various fields of industry, which has promoted the intelligent development of the industry and improved efficiency in industrial production. The devices involved in the IoT have generated useful and sensitive data over time and upload the data to the cloud to realize real-time data sharing. To ensure the confidentiality of data, many systems use attribute-based encryption primitive to encrypt data. However, there are still some security and privacy problems in this mode, such as the lack of identification of malicious users who leaked private keys, performance bottleneck caused by excessive reliance on a single central authority (CA), and vulnerability because a single CA holds the private keys of all users in the system. In this article, white-box tracking is used to identify malicious users. The alliance chain is introduced to support multiauthority environments, where the consensus nodes are managed by different authorities and assist CA in generating partial private keys. To protect users’ privacy, users remain anonymous at all times during their interactions with blockchain consensus. The security analysis and simulation results show that the proposed scheme outperformed other comparable schemes, indicating that it is a preferable scheme.
Leyou Zhang, Qing Wu 0005, Fatemeh Rezaeibagha
IEEE Internet Things J.1
2024 Enhanced Secure Attribute-Based Dynamic Data Sharing Scheme With Efficient Access Policy Hiding and Policy Updating for IoMT
abstract
The application of 5G makes the medical Internet of Things(IoMT) bring many opportunities to the medical industry. It is expected to improve the quality and efficiency of medical services and improve people’s quality of life. However, a large number of data and users are generated by smart devices in IoMT. How to access and share securely the dynamic data and manage the dynamic users has been a challenging problem at present. Many various methods were introduced to solve it. However, collusion attacks, privacy leakage, and high computational costs are not solved or only partly solved. In this paper, we analyze the most recent work at first and point out their drawbacks. Additionally, the user revocation method adopted by these schemes can not prevent revoked users from colluding with unrevoked users or the cloud to obtain shared data. Subsequently, we propose an efficient policy hiding and policy updating attribute-based data sharing scheme. The proposals support user revocation, which solves the collusion between the revoked users and unrevoked users or the cloud. Under this scheme, attributes are divided into attribute names and attribute values, and sensitive information attribute values are hidden in access policies to protect user privacy. We reduce user computational overhead by using outsourced techniques and policy update methods. The scheme is proved to be fully secure which is stronger than most of the existing works. The comparison and simulation results confirm the advantages of the proposed scheme over the available in the IoMT.
Leyou Zhang, Shuwei Xie, Qing Wu 0005, Fatemeh Rezaeibagha
IEEE Internet Things J.1
2024 An anonymous and large-universe data-sharing scheme with traceability for medical cloud storage
Qing Wu 0005, Guoqiang Meng, Leyou Zhang, Yue Lei
J. Syst. Archit.3
2024 Flexibly expressive and revocable multi-authority KP-ABE scheme from RLWE for Internet of Medical Things
Shuwei Xie, Leyou Zhang, Qing Wu 0005, Fatemeh Rezaeibagha
J. Syst. Archit.2
2023 SPMAC: Secure and privacy-preserving multi-authority access control for fog-enabled IoT cloud storage
Ruonan Ma, Leyou Zhang
J. Syst. Archit.2
2023 Toward Secure Data Computation and Outsource for Multi-User Cloud-Based IoT
abstract
Cloud computing has promoted the success of Internet of Things (IoT) with offering abundant storage and computation resources where the data from IoT sensors can be remotely outsourced to the cloud servers, whereas storing, exchanging and processing data collected through IoT sensors via centralised or decentralised cloud servers make cloud-based IoT systems prone to internal or external attacks. To protect IoT data against potential malicious users and adversaries, some cryptographic schemes have been applied to ensure confidentiality and integrity of IoT data. It is however a challenging task to perform any arithmetical computations once data items are encrypted. Fully-homomorphic encryption which is based on lattices can, in principle, provide a solution, but it is unfortunately inefficient in computation and hence cannot be applied to IoT. Fully-homomorphic encryption is feasible when we allow the involvement of a semi-trusted server. However, it is challenging to provide such a system in the situation of distributed environments for shared IoT data. We solve this problem and provide a fully-homomorphic encryption scheme for cloud-based IoT applications. We introduce a new method with the aid of a semi-trusted server that can help compute the homomorphic multiplications without gaining any useful information of the encrypted data. We show how our scheme is applied to multi-user IoT security and prove its semantic security. We also conduct experiments to justify its efficiency and applicability to multi-user cloud-based IoT systems.
Fatemeh Rezaeibagha, Yi Mu 0001, Ke Huang 0002, Lanxiang Chen, Leyou Zhang
IEEE Trans. Cloud Comput.5
2023 BE-TRDSS: Blockchain-Enabled Secure and Efficient Traceable-Revocable Data-Sharing Scheme in Industrial Internet of Things
abstract
As an important component of the Industrial Internet of Things (IIoT), the smart factory uses IIoT and equipment-monitoring technology to collect data to reasonably arrange the production. A large number of data is collected and uploaded to the IIoT cloud platform. However, the IIoT cloud platform is semitrusted and has structural limitations and vulnerability, which makes it necessary to realize data dynamic security sharing and malicious users' tracking. In this article, we show that the most recent work on this issue is still vulnerable to security threats at first. Then, a blockchain-enabled dynamic and traceable data-sharing scheme for a smart factory is proposed. Blockchain performs the user authentication and stores the ciphertext index and public keys to avoid tampering with shared data. The tracking algorithm tracks malicious users and adds them to a revocation list embedded in the ciphertext. And the authority can flexibly select domain or user revocation as required. The LSSS access policy is hidden to protect user privacy, and the cloud server uses the match test algorithm to detect whether users meet the hidden access policy. Additionally, online–offline encryption and outsourced decryption improve the efficiency of the scheme where the ciphertext and the pairing operations required for decryption achieve constant size. A performance analysis shows that the scheme can resist a variety of collusion attacks, and simulations show that it outperforms current schemes.
Ruonan Ma, Leyou Zhang, Qing Wu 0005, Yi Mu 0001, Fatemeh Rezaeibagha
IEEE Trans. Ind. Informatics2
2023 Authenticable Additive Homomorphic Scheme and its Application for MEC-Based IoT
abstract
The integration of Internet of Things (IoT) and cloud computing are always seen as promising technologies to enhance streamlined data collection, share and exchange. Although the advances in edge computing, particularly mobile edge computing (MEC), could enhance the performance of data collection and computation via computing offloading, security and privacy impediments have made new challenges to data integrity and confidentiality, in particular when multiple edges or nodes at different locations collect IoT data. Homomorphic encryption therefore has shown promising advantages for cloud computing, offering arithmetic operations to be carried out on the encrypted data without revealing the secret key. While fully homomorphic encryption introduced by Gentry, in 2009, allows both additive and multiplicative operations, it has shown significant implementation drawbacks due to the parameters generation and memory consumption. In this work, we focus on partially homomorphic encryption, which can be efficiently computed. However, it is challenging to add authentication feature for the verification and aggregation capability. We propose a novel secure and privacy preserving authenticable homomorphic encryption (AHEC) scheme. We demonstrate an application of our AHEC scheme for MEC-based IoT systems and provide security analysis to prove that our scheme is secure against chosen plaintext attack (IND-CPA) and unforgeability (UNF) under DDH-ZN2 and Lift-DH-ZN2 assumptions. Experimental results show that our proposed scheme is efficient for practical applications.
Fatemeh Rezaeibagha, Yi Mu 0001, Ke Huang 0002, Lanxiang Chen, Leyou Zhang
IEEE Trans. Serv. Comput.5
2022 BA-RMKABSE: Blockchain-aided Ranked Multi-keyword Attribute-based Searchable Encryption with Hiding Policy for Smart Health System
Jian Su 0004, Leyou Zhang, Yi Mu 0001
Future Gener. Comput. Syst.2
2022 Secure Decentralized Attribute-Based Sharing of Personal Health Records With Blockchain
abstract
Personal health records (PHRs) are located in a patient-centered electronic health system in which users can store and share medical information. However, PHRs have recently been plagued by security issues, such as the leakage of personal health information, illegal access to patient data, and data tampering. Recent security developments, such as introducing an access control policy with attribute-based encryption (ABE) or utilizing blockchain, have only been partially successful in solving these issues. Ongoing challenges to PHR sharing include single points of failure, node cheating attacks, and fair keyword search issues. In this article, we tackle these challenges by introducing a distributed PHR-sharing scheme based on blockchain and ciphertext policy ABE (CP-ABE), which allows for fast and efficient encryption and decryption. Blockchain maintains the integrity and the tracing source of the data while also recording all operations on the data in the form of transactions. In addition, the blockchain nodes act as attribute authorities to construct the CP-ABE cryptosystem. The tracing of malicious blockchain nodes is realized by tracing cryptography algorithms. Furthermore, the fair retrieval of ciphertext is achieved by employing smart contracts. To overcome the limited storage capacity of blockchain, we adopt both the on-chain and off-chain storage modes in our new system. Security analysis indicates that our new scheme remains intact when threatened by an indistinguishable chosen plaintext attack (IND-CPA) and an indistinguishable chosen keywords attack (IND-CKA). As such, we conclude that our proposed approach is feasible and efficient.
Leyou Zhang, Tianshuai Zhang, Qing Wu 0005, Yi Mu 0001, Fatemeh Rezaeibagha
IEEE Internet Things J.1
2022 A Secure and Efficient Decentralized Access Control Scheme Based on Blockchain for Vehicular Social Networks
abstract
The vehicular social network (VSN) is an emerging mobile communication system combining a vehicle ad hoc network (VANET) with a social network. It provides a new means of sharing, disseminating, and delivering data for passengers, drivers, and vehicles. However, a VSN may expose users’ private information, such as identities, location information, and trajectories, and tampering with shared data may lead to security and safety problems in vehicle systems. Considering the security and privacy preservation of shared data, we propose a lightweight decentralized multiauthority access control scheme based on ciphertext-policy attribute-based encryption (CP-ABE) and blockchain, by which a decentralized multiauthorization node supports vehicle users by performing lightweight calculations with the assistance of the vehicle cloud service provider (VCSP). We use blockchain to record storage and access transactions, achieving self-verification by users and tamper-resistance of ciphertexts. An improved smart contract reduces the workload of verification by users and achieves privacy preservation by hiding the policy. It supports user revocation and outsourced decryption, enabling more flexibility and better performance. A security and performance analysis shows that our scheme has clear advantages over existing schemes.
Leyou Zhang, Ye Zhang 0026, Qing Wu 0005, Yi Mu 0001, Fatemeh Rezaeibagha
IEEE Internet Things J.1
2022 Blockchain-enabled multi-authorization and multi-cloud attribute-based keyword search over encrypted data in the cloud
Qing Wu 0005, Taotao Lai, Leyou Zhang, Yi Mu 0001, Fatemeh Rezaeibagha
J. Syst. Archit.3
2022 A traceable and revocable multi-authority access control scheme with privacy preserving for mHealth
Leyou Zhang, Chuchu Zhao, Qing Wu 0005, Yi Mu 0001, Fatemeh Rezaeibagha
J. Syst. Archit.1
2022 Secure Outsourced Attribute-Based Sharing Framework for Lightweight Devices in Smart Health Systems
abstract
The rapid evolution of the Internet of Things has led to the development of smart health. As a form of medical care that uses advanced Internet technology to realize better diagnosis and treatment of patients, smart health transitions medical services move toward real intelligence and greatly helps users. And in smart health, the secure sharing of personal health records (PHRs) is one of the main concerns of patients and medical personnel. Many attribute-based sharing models have been proposed to secure the sharing of PHRs, but there are still two problems to resolve. One is the potential disclosure of the patient data. The attribute-based model achieves flexible access control, but the access policies contain sensitive information of patients. The disclosure of the policy will lead to the leakage of data of the users. The other is the high computational and storage overhead, particularly in smart health systems with limited computing power. In this article, we present a Smart Health-Lightweight Fine-Grained Sharing (SH-LFGS) framework based on attribute-based encryption (ABE). It achieves a fully hidden access policy by adopting Viéte's formula. SH-LFGS introduces an online/offline mechanism in the PHR encryption phase and the outsourced verifiable decryption mechanism. Because the decrypting test requires only one bilinear pair operation, the SH-LFGS can achieve the task of lightweight computation. Analysis of the performance and security of the proposed model confirm its efficiency and security.
Leyou Zhang, Wenting You, Yi Mu 0001
IEEE Trans. Serv. Comput.1
2021 Enhanced bitcoin with two-factor authentication
abstract
Bitcoin transactions rely on digital signatures to prove the ownership of bitcoin. The private signing key of the bitcoin owner is the key component to enable a bitcoin transaction. If the signing key of a bitcoin is stolen, the theft who possesses the key can make a transaction of the bitcoin. In this paper, based on the distance-based encryption (DBE), we propose an enhanced version of bitcoin in order to protect the signing key. Our approach is based on our two-factor authentication, where the signing key cannot be retrieved without being identified via the password and biometric authentication scheme, and the user is only required to enter his password and fingerprint (or other biometric information such as a factual image) to retrieve the key. By doing this, we can effectively improve the bitcoin security and provide stronger authentication. An attractive feature of our scheme is that one of encryption schemes is asymmetric, in the sense that the decryption key (biometric information) is not stored in the device. We also provide the security model and proof to justify the security of our scheme.
Fatemeh Rezaeibagha, Yi Mu 0001, Ke Huang 0002, Leyou Zhang
Int. J. Inf. Comput. Secur.4
2021 Secure and Privacy-Preserved Data Collection for IoT Wireless Sensors
abstract
The captured data from smart devices via Internet of Things (IoT) wireless sensors are vulnerable to numerous online and offline attacks and unauthorized accesses, hence, some digital signature and encryption solutions have been designed to ensure public verifiability, data integrity, and confidentiality. However, there are still some issues to be addressed. For example, the data source is revealed to the public due to the public verifiability of digital signatures, in which authentication is transferrable. Moreover, computation of these data can only be done after decryption, restricting outsourced computation, such as a computing facility from a cloud. The best approach of private computation, which supports outsourced computation, is based on homomorphic encryption. However, significant computational overhead is a concern. To deal with these issues, in this article, we propose an efficient and provably secure scheme based on designated-verifier proofs, deniable authentication and homomorphic encryption for secure and lightweight data collection, batch verification, and data analysis in the privacy-preserved IoT wireless sensors applications. The main contribution of our work is the privacy-preserved IoT wireless sensors system along with a novel deniable authenticated homomorphic encryption scheme that can securely aggregate data from IoT wireless sensors for secure outsourced applications. To prove the security and efficiency of our proposed scheme, we provide formal security analysis and performance comparisons for IoT wireless sensors.
Fatemeh Rezaeibagha, Yi Mu 0001, Ke Huang 0002, Leyou Zhang, Xinyi Huang 0001
IEEE Internet Things J.4
2021 Privacy-Preserving Flexible Access Control for Encrypted Data in Internet of Things
abstract
Along with the development of edge computing and the cloud, the Internet of Things (IoT) is affecting and changing people’s lives. Data sharing has played an important role in the IoT, but the leakage of private user information poses a new security threat to the users. Thus, flexible fine-grained access control for such shared data is proposed in this article as an effective and secure method of eliminating vulnerabilities. However, the disclosure of access policies will also expose users’ private information. Recently, Yanget al.attempted to solve this problem and proposed a framework based on attribute-based encryption for shared data onto IEEE IoT-J(DOI: 10.1109/JIOT.2016.2571718). They hide the access policies by using a bloom filter (BF) and attempt to address privacy preservation in IoT. However, we demonstrate several security weaknesses of their framework and point out its vulnerability to dictionary attacks and access policy guessing attacks. Then, an improved IoT solution is proposed. Under this proposal, the attribute values are stored in BF while the attribute names are embedded in the access policy. The proposed scheme can resist dictionary attacks and access policy guessing attacks. In addition, it simultaneously realizes large attribute sets, an efficient decryption algorithm, and adaptive security. Security analysis and performance evaluations show that the presented scheme achieves higher security and implementation simplicity in the IoT than other currently available schemes.
Leyou Zhang, Jun Wang 0109, Yi Mu 0001
IEEE Internet Things J.1
2021 Multiauthority Access Control With Anonymous Authentication for Personal Health Record
abstract
A personal health record (PHR) system is a smart health system that serves patients and doctors. A PHR is usually stored in a cloud and managed by a semitrusted cloud provider. However, there is still a possibility of the exposure of personal health information to semitrusted parties and unauthorized users. To protect the privacy of patients and ensure that patients can control their PHRs, a patient-centric PHR sharing framework is proposed in this article. In this framework, all PHRs are protected with multiauthority attribute-based encryption before outsourcing, which solves the key hosting problem and achieves fine-grained access control to PHRs. Furthermore, an anonymous authentication between the cloud and the user is proposed to ensure data integrity on the cloud while not exposing the user's identity during authentication. The proposed authentication is issued from a new online-offline attribute-based signature. It can make the encrypted PHRs resist collusion attacks and not be forged during the period of sharing, which enhances patients' control of their PHRs. Online-offline and outsourcing decryption also reduces calculation costs and improves operational efficiency. Finally, comparisons are given based on numerical experiments.
Leyou Zhang, Yadi Ye, Yi Mu 0001
IEEE Internet Things J.1
2020 Interpretable Sequence Learning for Covid-19 Forecasting
abstract
We propose a novel approach that integrates machine learning into compartmental disease modeling (e.g., SEIR) to predict the progression of COVID-19. Our model is explainable by design as it explicitly shows how different compartments evolve and it uses interpretable encoders to incorporate covariates and improve performance. Explainability is valuable to ensure that the model's forecasts are credible to epidemiologists and to instill confidence in end-users such as policy makers and healthcare institutions. Our model can be applied at different geographic resolutions, and we demonstrate it for states and counties in the United States. We show that our model provides more accurate forecasts compared to the alternatives, and that it provides qualitatively meaningful explanatory insights.
Sercan Ö. Arik, Chun-Liang Li, Jinsung Yoon, Rajarishi Sinha, Arkady Epshteyn, Long T. Le, Vikas Menon, Shashank Singh 0005, Leyou Zhang, Martin Nikoltchev, Yash Sonthalia, Hootan Nakhost, Elli Kanal, Tomas Pfister
NeurIPS9
2019 Privacy-preserving decentralized ABE for secure sharing of personal health records in cloud storage
Pengfei Liang 0001, Leyou Zhang, Juan Ren
J. Inf. Secur. Appl.2
2017 Adaptively Secure Hierarchical Identity-Based Encryption over Lattice
Leyou Zhang, Qing Wu 0005
NSS1
2017 Novel Leakage-Resilient Attribute-Based Encryption from Hash Proof System
abstract
As an important primitive, attribute-based encryption (ABE) has attracted much attention in the relative-leakage model. However, the leakage rate in almost all of the existing ABE schemes is restricted with a leakage parameter. It implicitly suggests that higher leakage rate results in larger ciphertexts and keys. Aiming at tackling the challenge, novel leakage-resilient ciphertext-policy attribute-based encryption (CP-ABE) and key-policy attribute-based encryption (KP-ABE) are designed in this paper. It achieves shorter secret key size and simultaneously does not suffer from the undesirable drawback above. To realize this, the concepts of CP-AB-HPS and KP-AB-HPS are introduced, which generalize the notion of hash proof system (HPS) to attribute-based setting. Under some static assumptions, the proposed schemes are proved adaptively secure in the standard model. In addition, the results in simulation experiments indicate that the proposed scheme is efficient and practical.
Leyou Zhang, Jingxia Zhang, Yi Mu 0001
Comput. J.1
2016 Compact Anonymous Hierarchical Identity-Based Encryption with Constant Size Private Keys
abstract
We present a new construction of anonymous hierarchical identity-based encryption (HIBE) over prime order groups. The distinct feature of our proposed scheme is that both private key and ciphertext have a constant size, which has never been achieved in all other existing anonymous HIBE schemes. Moreover, we utilized a double exponent technique to generate the ciphertext in order to provide anonymity. This simple and efficient method allows us to construct a more compact anonymous HIBE in prime order groups. Under the decisional bilinear |$n+1$|-Diffie–Hellman exponent assumption and linear assumption, we show that the proposed scheme is secure and anonymous against chosen plaintext attacks in the standard model.
Leyou Zhang, Yi Mu 0001, Qing Wu 0005
Comput. J.1
2012 Direct CCA Secure Identity-Based Broadcast Encryption
Leyou Zhang, Qing Wu 0005, Yupu Hu
NSS1
2011 CCA2 secure biometric identity based encryption with constant-size ciphertext
abstract
We propose a new biometric identity based encryption scheme (Bio-IBE), in which user biometric information is used to generate the public key with a fuzzy extractor. This is the first Bio-IBE scheme that achieves constant size ciphertext. This is also a scheme that is secure against the adaptive chosen ciphertext attack (CCA2). Details are presented along with a discussion of Shamir’s threshold secret sharing and fuzzy extraction of biometrics, which is based on error correction codes. We also define a security model and prove that the security of the proposed scheme is reduced to the decisional bilinear Diffie-Hellman (DBDH) assumption. The comparison shows that the proposed scheme has better efficiency and stronger security compared with the available Bio-IBE schemes.
Yang Yang 0026, Yupu Hu, Leyou Zhang, Chun-hui Sun
J. Zhejiang Univ. Sci. C3
2009 New Construction of Short Hierarchical ID-Based Signature in the Standard Model
abstract
In this paper, a new construction of hierarchical ID-Based signature (HIBS) scheme is proposed. The new scheme has some advantages over the available schemes: the private keys size shrinks as the identity depth increases and the signature size is a constant as it consists of three group elements. Furthermore, under the h-CDH assumption, our scheme is provably secure in the standard model. This assumption is more natural than many of the hardness assumptions recently introduced to HIBS in the standard model.
Leyou Zhang, Yupu Hu, Qing Wu 0005
Fundam. Informaticae1
2008 On the Computational Efficiency of XTR+
Ningbo Mu, Yupu Hu, Leyou Zhang
Inscrypt3