EDBT 2026 Demo / reviewers in the wild / expert
Yi-Ning Liu 0002
dblp:92/20-2 · also Yining Liu 0002
· DBLP profile ↗
70ranked-venue papers
12as first author
50since 2021 · last 2026
0000-0002-6487-7595ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 22 · 6 first-author · 13 since 2021Computer networks · 20 · 1 first-author · 18 since 2021Applied, interdisciplinary, general and emerging computing · 14 · 2 first-author · 12 since 2021Systems, architecture and hardware · 6 · 2 first-author · 3 since 2021Databases, data management, data science and information retrieval · 5 · 3 since 2021Artificial intelligence and machine learning · 2 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Verifiable and Robust Privacy-Preserving Multidimensional Truth Discovery for IoT CrowdsensingabstractThe rapid proliferation of IoT devices has popularized crowdsensing for distributed data collection, where Truth Discovery plays a critical role in inferring reliable information from heterogeneous observations. However, existing privacy-preserving truth discovery schemes face challenges including inefficient verifiability, limited weighting strategies, insufficient robustness, and excessive overhead. In this paper, we introduce VRPMTD, a verifiable, robust, and privacy-preserving multi-dimensional truth discovery framework. We achieve scalable verifiability via CRT based packing of multidimensional measurements together with commitments and a linear homomorphic hash. This design allows the data requester to batch verify aggregated results. To improve accuracy, we design a novel weighting mechanism using a Gaussian radial basis function residual and a sliding-window temporal loss, allowing workers’ weights to reflect both long-term reliability and recent behavior. Additionally, the framework improves robustness under realistic sensing and network failures. To optimize efficiency, we implement a lightweight dual-layer encryption mechanism and a difference-based uploading strategy. Formal security analysis indicates that VRPMTD preserves the input-level confidentiality of workers’ raw measurements and ensures verifiability of outsourced aggregation. Extensive experiments on real-world datasets and IoT devices demonstrate that VRPMTD achieves higher accuracy while incurring lower overhead. Jingxue Chen, Yuanjun Xia, Yangfan Liang, Yi-Ning Liu 0002 |
IEEE Internet Things J. | 6 |
| 2026 | A multi-functional and privacy-preserving data aggregation scheme for smart grid
Zhixin Zeng, Zuxin Yu, Long Li 0005, Yi-Ning Liu 0002, Huadong Liu |
J. Syst. Archit. | 5 |
| 2026 | An Unbounded Multi-Input Quadratic Functional Encryption Scheme for Secure Cloud-Based Machine LearningabstractWith the advent of cloud computing, traditional machine learning (ML) are migrating into cloud-based ML day by day following the concept of machine learning as a cloud service, which enables multiple entities to contribute to and benefit from shared datasets and models. As well as training the linear classification model, training the nonlinear classification model is also an essential task in cloud-based ML. However, this task commonly involves learning knowledge from different datasets provided by various entities, which often contain sensitive information like patients' physiological indices. Therefore, it gives rise a natural question how to allow multiple users collaboratively participating in a nonlinear classification task while preserving these datas' privacy. As a promising cryptographic tool, the concept of unbounded multiinput functional encryption can be developed to answer such a question, such as google search engines are running over this concept-based ML approaches. However, most of existing approaches are derived from this concept with inner product functionality, specifying for a linear classification model and thus fails to cope with a non-linear classification one. In this paper, we introduce an advanced cryptographic concept called unbounded multi-input quadratic functional encryption, and give a concrete construction which allows arbitrary number of users participating in the classifying tasks with a nonlinear classification model but without divulging their private data. Moreover, we provide a strict mathematical security proof under a well-defined security model as well as some security attacks are analyzed, followed by an experimental analysis and comparison on a real dateset as well as a practical use case to demonstrate our scheme's performance. Zhenhua Chen 0001, Kaili Long, Qiqi Lai, Long Li 0005, Yi-Ning Liu 0002, Hao Wang 0007 |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2026 | EPRU: Efficient and Privacy-Aware Reputation Update Scheme With a Dual-Threshold Mechanism for Vehicular PlatoonsabstractVehicular platooning demands secure and trustworthy inter-vehicle communications to maintain platoon stability, traffic efficiency, and driving safety. Existing privacy-preserving authentication schemes protect message integrity over open channels but often overlook the credibility of message content, allowing authenticated yet misleading data. Reputation management frameworks address this by evaluating vehicle behavior, yet most employ periodic updates, delaying detection of sudden misbehavior. This paper proposes a reputation-based authentication mechanism (EPRU) that establishes trust between vehicles by evaluating vehicle behavior and historical records, thereby ensuring the reliability of message transmission between vehicles. Our EPRU incorporates a dynamic aggregation trigger mechanism that updates vehicle credit scores based on verified feedback collected in real time, thereby accurately reflecting behavioral changes. Furthermore, a combination of ElGamal encryption and homomorphic encryption is employed to safeguard vehicle identities and feedback data during transmission and processing. Formal security proofs and extensive analysis demonstrate resistance to forgery, replay, and modification attacks, ensuring the confidentiality, integrity, and authenticity of both messages and feedback data. Experimental results demonstrate that our EPRU reduces computation overhead by at least 3.05% and communicational cost by 37.5% compared with recent state-of-the-art schemes, highlighting its practicality and efficiency for real-time, privacy-aware vehicular platoon systems. Hongyuan Cheng, Xiaosong Guan, Yi-Ning Liu 0002, Jiuru Wang, Zhiquan Liu 0001 |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2026 | SSAA: Secure Semi-Asynchronous Aggregation for Decentralized Federated Learning on Heterogeneous DevicesabstractDecentralized federated learning (DFL) has been widely used in edge computing and Internet of Things (IoT) settings with many devices. However, the heterogeneity of devices (e.g., varying computational capacity, stability, security requirements) can impact the performance of DFL applications. Our proposed SSAA, a secure aggregation scheme for DFL on heterogeneous devices, presented in this paper is designed to improve the efficiency of DFL while preserving privacy. Specifically, SSAA accelerates aggregation by synchronously coupling aggregation device-set formation with aggregation computation, and can cope with device availability and performance variability to maintain stable and efficient aggregation. By extending homomorphic encryption to support cross-round ciphertext continuity, SSAA enables reliable and secure decryption under large-scale dropouts in the original aggregation set, making it practical for dynamic DFL environments. In addition, we prove that SSAA is semi-honestly secure and resistant to device collusion attacks – fundamental security requirements for applications involving heterogeneous devices. We also implement SSAA and comprehensively evaluate its performance to demonstrate its practicability. Cheng Guo 0001, Xinyu Tang 0001, Kim-Kwang Raymond Choo, Yi-Ning Liu 0002 |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2026 | An Efficient and Anonymous Authentication Scheme With Session Key Agreement for Vehicular Ad Hoc NetworksabstractVehicular Ad hoc Networks (VANETs) enable vehicles and roadside units (RSUs) to exchange safety-related information over public wireless channels, thereby enhancing transportation system security and efficiency. However, malicious adversaries may impersonate RSUs to disseminate false information or masquerade as legitimate vehicles to gain unauthorized services. To counter such threats, mutual authentication between vehicles and RSUs is crucial. This task is particularly challenging due to the high mobility of vehicles and the resource constraints of both vehicles and RSUs. In this paper, we propose an Efficient and Anonymous Authentication Scheme with Session Key Agreement (EA2S2KA), which leverages Elliptic Curve Cryptography (ECC) and Physical Unclonable Functions (PUFs) to achieve lightweight, fast, and secure authentication. We conduct an informal security analysis, a formal security proof under the real-or-random (RoR) model, and formal security verification using AVISPA, all of which confirm that EA2S2KA resists a broad range of security threats in VANETs. Performance comparisons with recently proposed schemes show that EA2S2KA provides stronger security guarantees while achieving the lowest total computation cost and ranking among the top three in communication efficiency. Furthermore, NS-3 simulations confirm its practicality in large-scale and dynamic environments through evaluations of the authentication success rate, average authentication delay, and authentication message throughput. Jiping Li, Jing Chen 0003, Yi-Ning Liu 0002, Shouyin Liu, Yuanyuan Zhang 0015 |
IEEE Trans. Intell. Transp. Syst. | 3 |
| 2026 | Fully Anonymous Broadcast Signcryption for Secure Health Data Transmission in WBANs
Yangfan Liang, Gao Liu, Xianchao Zhang 0002, Jingxue Chen, Yuanjun Xia, Yi-Ning Liu 0002 |
IEEE Trans. Mob. Comput. | 7 |
| 2026 | LCMS: Efficient Lattice-Based Conditional Privacy-Preserving Multi-Receiver Signcryption Scheme for Internet of VehiclesabstractInternet of Vehicles (IoV) requires robust security and privacy protection mechanisms to enable trusted traffic information exchange, while also requiring low communication and low computing overhead to meet the real-time requirements of IoV. Existing signcryption schemes suffer from quantum vulnerability, inadequate unlinkability/vehicle anonymity, absence of revocability, poor scalability, inadequate management of malicious entities, and high communication and computational overhead. So we propose an efficient lattice-based conditional privacy-preserving multi-receiver signcryption scheme (LCMS) that systematically addresses these gaps through three core innovations: 1) Privacy preservation is achieved via a pseudonym mechanism integrated with certificateless key generation, which ensures vehicle anonymity and weak unlinkability while preventing malicious key generation center and key escrow; 2) Malicious entity management through dynamic revocability and distributed decryption among roadside units, preventing unilateral message access; and 3) Post-quantum efficiency is achieved by leveraging the Learning With Rounding problem to eliminate expensive Gaussian sampling, combined with ciphertext packing techniques. This reduces time overhead, the size of signcryptexts, and communication overhead, while lowering the overall storage overhead of the scheme through the MP12 trapdoor. Security proofs show LCMS achieves Existential Unforgeability under Adaptive Identity Chosen-Message Attack and Indistinguishability under Adaptive Identity ChosenCiphertext Attack in the Random Oracle Model, with rigorously validated resistance against multiple IoV -specific attacks. Experimental results via SageMath implementation demonstrate that our scheme exhibits a smaller signcryptext size and lower signcryption/unsigncryption time compared to existing random lattice-based signcryption schemes. Scalability tests with 300 vehicles and 300 roadside units (RSUs) were completed within 56 seconds. Communication overhead analysis confirms practical feasibility for IEEE 802.11p vehicle communication protocol, and RSU serving capability evaluation under realistic vehicle density (100-200km2) and speed (40-60km/h) further validates system practicality. LCMS provides a quantum. Songshou Dong, Huaxiong Wang, Yi-Ning Liu 0002 |
IEEE Trans. Netw. Serv. Manag. | 4 |
| 2026 | Efficient Conditional Privacy-Preserving Heterogeneous Broadcast Signcryption for Collision Warning in VANETsabstractReal-time performance is of utmost significance for communication in certain specific scenarios of vehicle-to-infrastructure (V2I) like collision warning systems. Vehicle-to-Everything (V2X) Broadcast signcryption is very suitable for these scenarios. However, current solutions prioritize generality, but may not be suitable for specialized communication situations, and many broadcast signcryption schemes suffer from low communication verification efficiency due to the sequence of decryption before verification. Moreover, most of existing broadcast signcryption schemes with single cryptosystem are not applicable for the heterogeneous networks of different Internet of Vehicles. To address these challenges, an efficient conditional privacy-preserving heterogeneous broadcast signcryption scheme(ECPHBS) is proposed, improving roadside unit verification to support batch verification of ciphertexts through a pre-authentication mechanism, and allowing vehicles to conduct secure communication with roadside units under the certificateless cryptosystem and the identity-based cryptosystem. Meanwhile, a tracking and revocation mechanism was introduced to achieve conditional privacy protection. Our formal security analysis demonstrates that the ECPHBS scheme formally achieves IND-CCA2 security under the CDH assumption and EUF-CMA security under the ECDL problem. Experimental results confirm its superior verification efficiency, especially with an increasing number of receiving RSUs, and a constant communication overhead. Furthermore, the RSU service capability analysis shows that our scheme enables RSUs to fully handle communication requests from approximately 500 vehicles within a 150-meter range, outperforming comparative schemes. Qi Xie 0001, Nankun Mu, Yi-Ning Liu 0002 |
IEEE Trans. Netw. Serv. Manag. | 5 |
| 2026 | DeGKG: Efficient Decentralized Inter-Group Key Generation for Drone SwarmsabstractThe security of collaboration among drone swarms necessitates the creation of inter-swarm/group keys. However, current solutions lack an inter-group key establishment mechanism that supports uniformity, flexibility, trustworthiness, efficiency and scalability to enable secure and efficient inter-swarm communications. In this paper, we propose DeGKG, an efficient decentralized inter-group key generation scheme that offers the construction of inter-swarm encryption keys for various drone swarms. It leverages the regional similarity of satellite cluster signals to construct drone swarm public/private key pairs, and employs the Chinese remainder theorem to integrate the swarm public keys for creating inter-group encryption keys, significantly reducing the number of complex cryptographic operations and the burden of inter-swarm key creation, and ensuring the scalability. In addition, the inter-swarm key creation allows the division of drones without the regional similarity of satellite cluster signals into various swarms, each composed of drones with the signal similarity, thus supporting the key establishment among all the drones and efficacy. An efficient blockchain consensus mechanism is implemented to uniformly generate inter-group encryption keys for various swarm combinations without relying on a trusted third party, thus ensuring the efficiency, flexibility, and trustworthiness of the generation. We prove the security of DeGKG, and demonstrate its efficacy and efficiency through simulations and comparisons. Gao Liu, Wensen Jiang, Ning Wang 0003, Yi-Ning Liu 0002, Tao Xiang 0001 |
IEEE Trans. Netw. | 4 |
| 2025 | DSAFL:Decentralized secure aggregation with communication path optimization for cross-silo federated learning
Cheng Guo 0001, Xinyu Tang 0001, Yi-Ning Liu 0002 |
Comput. Networks | 4 |
| 2025 | An Efficient and Revocable PUF-Based Authentication Scheme for Secure V2R Mutual Communication in VANETsabstractIn vehicular Ad hoc networks (VANETs), vehicles and roadside units (RSUs) utilize open wireless channels to exchange safety-critical data, facilitating real-time decision-making for enhanced road safety and traffic management efficiency in intelligent transportation systems (ITS). However, the openness of these channels exposes them to various security threats. Malicious adversaries may impersonate RSUs to forge and distribute harmful commands, manipulating vehicular behavior, or masquerade as legitimate vehicles to bypass authentication protocols and gain unauthorized access. Such attacks jeopardize the security and functionality of the VANETs, underscoring the necessity of robust mutual authentication between vehicles and RSUs. Existing centralized trust authority (TA)-dependent schemes for vehicle-to-RSU (V2R) authentication incur high computational overhead, introduce authentication latency, and cause a single point of failure, particularly in dense traffic scenarios. To address these challenges, we propose ERAS2KN, an efficient and revocable authentication scheme with session key negotiation. By integrating Physical Unclonable Functions (PUFs) with lightweight cryptography, such as one-way hash functions, bitwise XOR, and symmetric encryption, ERAS2KN enables rapid mutual authentication and secure session key establishment. Comprehensive security analysis, including informal evaluation, formal security proof based on the Real-or-Random (RoR) model, and automated validation using AVISPA, confirms ERAS2KN’s resilience against vehicle impersonation, eavesdropping, vehicle/RSU compromise, man-in-the-middle, and other advance attacks. Performance evaluations demonstrate that ERAS2KN surpasses existing schemes by delivering enhanced security features while achieving the lowest computational overhead, communication overhead, and energy consumption cost, making it ideal for high-density VANETs environments. Jiping Li, Jing Chen 0003, Yi-Ning Liu 0002, Shouyin Liu, Yuanyuan Zhang 0015 |
IEEE Internet Things J. | 3 |
| 2025 | FPMDA: Fault-Tolerant and Privacy-Enhanced Multidimensional Data Aggregation Without TAabstractMany privacy-preserving multidimensional data aggregation (PPMDA) schemes have been proposed to safeguard user privacy and provide aggregated real-time data for the control center (CC) to optimize power allocation in the smart grid. However, without Trusted Authority (TA), existing PPMDA schemes cannot simultaneously provide lightweight encryption, achieve fault tolerance, and resist collusion attacks between fog nodes and CC. To address these issues, we propose a fault-tolerant and privacy-enhanced multidimensional data aggregation scheme without TA (FPMDA) based on fog computing. Specifically, the Chinese Remainder Theorem is leveraged to enhance the efficiency of multidimensional data processing, and an innovative dual-masking approach is introduced to ensure the security of data aggregation. In addition, employing the homomorphic property of the (t, k)-threshold secret sharing algorithm, we design a data aggregation method that enhances security and fault tolerance, making it resilient against insider attacks. Finally, compared with existing schemes, FPMDA not only significantly enhances privacy preservation while maintaining required security properties but also achieves low computational and communication load, demonstrating practicality for resource-constrained smart meters. Huadong Liu, Yuanxing Peng, Zuxin Yu, Yi-Ning Liu 0002, Long Li 0005, Zhixin Zeng |
IEEE Internet Things J. | 4 |
| 2025 | EAPDS: Efficient Auditable and Privacy-Preservation Data-Sharing Scheme Based on Attribute-Based Encryption for IoMTabstractData sharing schemes based on the Internet of Medical Things (IoMT) have emerged as a more convenient way to monitor and manage individuals’ health. However, this scenario faces challenges such as privacy preservation, effectiveness, and practicality, which hinder its further development. To the best of our knowledge, there is no agreed-upon data-sharing method that addresses all of these problems. In this paper, we make a step ahead by designing an Efficient and Auditable Privacy-preservation Data Sharing scheme (EAPDS) based on multi-authority attribute-based encryption. EAPDS designs an auditable anonymous authentication mechanism to realize identity privacy protection, as well as an efficient multi-authority attribute-based encryption mechanism to achieve the efficiency and practicability of data-sharing. Formal security analysis demonstrates EAPDS can resist replayable chosen-ciphertext attack. Many performance evaluation experiments and functional analyses show that EAPDS not only performs better than existing medical data-sharing schemes in terms of efficiency, but also in terms of privacy protection and feasibility. Consequently, our EAPDS scheme holds promising application prospects. Hui Wang 0124, Yong Xie 0003, Min Luo 0002, Yi-Ning Liu 0002, Syed Hamad Shirazi |
IEEE Internet Things J. | 4 |
| 2025 | Privacy-preserving multidimensional data aggregation for diverse electricity data users
Huadong Liu, Yuanxing Peng, Yi-Ning Liu 0002, Zhixin Zeng |
J. Syst. Archit. | 3 |
| 2025 | SAMK: Secure Aggregation for Federated Learning Under Multiple Keys With Low Communication RoundsabstractWhile multi-key homomorphic encryption (MKHE) ensures privacy in federated learning (FL) by encrypting model updates, its requirement for aggregate ciphertext decryption and dropout handling increases communication rounds during aggregation. To enable secure multi-key aggregation with low communication rounds, we propose SAMK. SAMK enables the server to compute the sum of model updates from clients participating in FL, while keeping these updates encrypted by different keys throughout the computation. By utilizing the polynomial property of the BFV ciphertext, SAMK successfully implements individual decryption of the aggregated ciphertext (encrypted under multiple keys) by each client using their respective keys, resulting in low communication rounds. It means that in SAMK, all client interactions are avoided and the client-server interaction is only once (ciphertext uploads and downloads) in each round of aggregation computation. In addition, SAMK is robust to any number of clients dropping out at any time, and the client who has dropped out after uploading model updates, can still get the correct aggregation result upon reconnecting. We prove the security of SAMK for semi-honest server and clients, where client collusion is also considered. At last, we implement SAMK and comprehensively evaluate its performance to demonstrate its practicability. Cheng Guo 0001, Ximeng Liu, Kim-Kwang Raymond Choo, Yi-Ning Liu 0002 |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2025 | PECHA: Privacy-Preserving and Efficient Cross-Domain Handover Authentication for Heterogeneous NetworksabstractThe sixth-generation (6G) mobile communication networks are perceived as large-scale heterogeneous networks. With their increased heterogenization and densification, it is crucial to guarantee the security and efficiency of user equipment's handovers between networks. However, existing cross-domain handover authentication schemes cannot ensure handover authentication efficiency and cannot balance privacy and system efficiency, which thus cannot be directly applied in heterogeneous networks. In this paper, we present PECHA, a privacy-preserving and efficient cross-domain handover authentication scheme for heterogeneous networks, which enables anonymous authentication on user equipment (UE) through the collision property of chameleon hash functions. PECHA ensures authentication efficiency by employing the interplanetary file system and blockchain to synchronize UE's authentication information to target networks in advance. The privacy and system efficiency are balanced by modeling the unlinkability of UE's new and old chameleon hash values and determining the update frequency of UE chameleon hash value. PECHA also achieves correctness, mutual authentication and key agreement, anonymity, unlinkability, conditional privacy, forward/backward secrecy, robustness, known randomness secrecy, key escrow freeness and rapid response, and resists against spoofing attacks, replay attacks and man-in-the-middle attacks. Comprehensive performance analysis, evaluation and comparisons show that PECHA is efficient with respect to both computation and communication. Gao Liu, Hao Li 0103, Ning Wang 0003, Biwen Chen, Junqing Le, Yi-Ning Liu 0002, Tao Xiang 0001 |
IEEE Trans. Dependable Secur. Comput. | 6 |
| 2025 | Lightweight and Dropout Toleration Aggregation for Privacy Crowdsourcing Federated LearningabstractFederated learning-based mobile crowdsourcing (F-MCS) leverages crowdsourcing for large-scale data perception, but it faces challenges from privacy concerns and network instability problems. Hence, privacy-protecting F-MCS schemes have been proposed to address these issues by aggregating local models on a trusted central server or a trusted third party (TTP). However, these schemes are still vulnerable to single points of failure and other malicious attacks, making them impractical. Moreover, due to the instability of the communication network, workers in the F-MCS scheme may drop out of the task, which oversees the entire model aggregation. In order to tackle the obstacles above, we design an aggregation method combined with Shamir secret sharing that comes with secure aggregation of global models without relying on a TTP. In addition, to enhance the robustness and adaptability of the scheme, we handle worker disconnection and new user joining to maintain protocol continuity and data integrity, thus tolerating dropouts and dynamic participation. We have conducted a thorough analysis of the scheme’s security, which shows that it can effectively protect user data privacy. Furthermore, our experimental results demonstrate that the proposed scheme performs well in model accuracy and is comparable to the system performance in the nondropout case. Yunwei Dong, Meng Li 0006, Yi-Ning Liu 0002 |
IEEE Trans. Ind. Informatics | 4 |
| 2025 | LWAKA: Lightweight Anonymous Authenticated Key Agreement for VANETsabstractAuthenticated key agreement (AKA) between vehicles and road side units (RSUs) is crucial in vehicular ad-hoc networks (VANETs). However, existing solutions still suffer from high overheads of AKA and lack a mechanism to balance privacy strength and system efficiency. In this paper, we present a lightweight anonymous authenticated key agreement (LWAKA) scheme for VANETs, supporting lightweight anonymous authentication and key agreement between vehicles and RSUs simultaneously. In particular, vehicles’ authentication information is synchronized to target RSUs in advance for accelerating authentication, and lightweight cryptographic operations (i.e., hash function, hash-based message authentication, physical unclonable function, fuzzy extractor and symmetric encryption) are employed to ensure the high efficiency of AKA in terms of computation and communication overheads. The system efficiency and privacy are balanced through modeling the relationship between the frequency of pseudonym updates and the unlinkability of the vehicles’ new and old pseudonyms. Security analysis shows that LWAKA not only achieves anonymity, conditional privacy, pseudonym unlinkability, key escrow freeness, and physical security, but also resists against most known attacks. Comparative experimental results demonstrate that LWAKA outperforms existing schemes in terms of lightweight design. Gao Liu, Hao Li 0103, Junqing Le, Ning Wang 0003, Nankun Mu, Zhiquan Liu 0001, Yi-Ning Liu 0002, Tao Xiang 0001 |
IEEE Trans. Intell. Transp. Syst. | 7 |
| 2024 | AggNoteBot: A Robust Botnet Building Using Aggressive Cloud Notes
Yi-Ning Liu 0002, Yanze Kang, Weizhi Meng 0001 |
ACISP (3) | 2 |
| 2024 | A secure and lightweight cloud data deduplication scheme with efficient access control and key management
Xinyu Tang 0001, Cheng Guo 0001, Kim-Kwang Raymond Choo, Xueru Jiang, Yi-Ning Liu 0002 |
Comput. Commun. | 5 |
| 2024 | Data Verifiable Personalized Access Control Electronic Healthcare Record Sharing Based on Blockchain in IoT EnvironmentabstractElectronic health records (EHRs) based on the Internet of Things (IoT) can provide real-time health data for quick intelligent medical services and give convenience to many data-sharing scenarios. However, EHRs also face various security threats since they are highly private. To the best of our knowledge, no recognized data-sharing work can satisfy the stringent privacy requirements of EHRs. Motivated by this, we propose a blockchain-based personalized access control EHR-sharing scheme with data verifiability, which can safeguard the interests of data owners (DOs) and users simultaneously. First, we take ciphertext-policy attribute-based encryption to achieve personalized access control for DOs. Second, we design an interactive zero-knowledge proof protocol between DOs and users, which can provide authenticity verification of EHR for users and prevent EHR away from forgery. In addition, smart contracts and the interplanetary file system are used to reduce the computation and storage costs of patients. Finally, the security analysis shows that the proposed scheme meets the predefined security goals. The performance analysis demonstrates that the proposed scheme is efficient and can be applied to practical electronic medical record sharing scenarios. Hui Wang 0124, Yong Xie 0003, Yi-Ning Liu 0002, Xiong Li 0002, Phuntsog Dorje |
IEEE Internet Things J. | 3 |
| 2024 | SVCA: Secure and Verifiable Chained Aggregation for Privacy-Preserving Federated LearningabstractFederated learning (FL), as a distributed machine learning paradigm, enables multiple users to train machine learning models locally using individual data and then update global model in a privacy-preserving aggregated manner. However, in FL, the users model parameters are at risk of a privacy breach. Furthermore, the aggregation server may forge aggregated results. To address these problems, in this paper, we propose SVCA, a secure and verifiable chained aggregation for privacy-preserving federated learning (PPFL) scheme. Specifically, we first group users and construct a chained aggregation structure, then employ secret sharing to prevent the entire group of users dropout, and finally propose a scheme for secure verification of the aggregation result to ensure the result correctness and the security of the verification process. The security analysis shows that SVCA not only protects the privacy of users but also ensures the training integrity. Extensive experimental results demonstrate the practical performance of SVCA without compromising classification accuracy. Yuanjun Xia, Yi-Ning Liu 0002, Shi Dong 0001, Meng Li 0006, Cheng Guo 0001 |
IEEE Internet Things J. | 2 |
| 2024 | Efficient Pairing-Free Certificateless Signcryption Scheme for Secure Data Transmission in IoMTabstractThe Internet of Medical Things (IoMT) builds a bridge between patients and doctors, facilitating patients’ being diagnosed and monitored by uploading physiological indicators without visiting the hospital. However, physiological indicators are sensitive data of patients, making it a challenge to achieve verifiability of data sources while ensuring data privacy during data transmission of IoMT. Due to its ease of deployment and the ability to provide both encryption and signature, certificateless signcryption (CLSC) is suitable for designing secure data-transfer protocol in IoMT. Nevertheless, internal adversaries “malicious users” and “malicious KGC,” capable of launching Type I and Type II attacks, threaten the security of present CLSC schemes, making most of them insecure. In this work, after giving an example of a recent CLCS scheme suffering Type I attack, we propose an efficient pairing-free CLCS scheme suitable for secure data transmission in IoMT based on the idea of zero-knowledge proof. It not only provides confidentiality and unforgeability of transmitted data under the Type I and Type II attacks but also achieves lower computational and communication overhead, and public verifiability. Finally, compared with the five recent CLSC schemes, theoretical analysis and experimental testing results show that the proposed scheme outperforms the other five schemes in terms of computation and communication costs as well as security. Therefore, our scheme is better suited for constructing secure data transmission in IoMT scenarios. Jianhong Zhang 0001, Chenghe Dong, Yi-Ning Liu 0002 |
IEEE Internet Things J. | 3 |
| 2024 | Practical and Secure Password Authentication and Key-Agreement-Scheme-Based Dual Server for IoT Devices in 5G NetworkabstractAs the proliferation of 5th Generation Mobile Communication Technology (5G) accelerates the adoption of Internet of Things (IoT) applications, building robust and secure communication channel becomes increasingly crucial with the exponential growth of connected devices. The 3rd Generation Partnership Project (3GPP) has established security standards for 5G systems, including mechanisms such as the 5G-Authentication and Key Agreement (5G-AKA), which enables establish secure sessions in untrustworthy participants or insecure channels. The private key which untrustworthy parties have independently or transmitted through insecure channels, may involve risk of information leakage in 5G-AKA. Motivated by this challenge, we propose a practical and secure dual-server key agreement scheme based on password authentication for IoT devices in 5G networks. The scheme ensures secure reliable key storage and key transmission, mitigating risks associated with key information leakage through a dual-server architecture and three-lock security policy. Importantly, we avoid ownership of the complete key by any untrustworthy entity in insecure 5G network to ensure key security. The scheme can resilience to various security threats prevalent in 5G networks through rigorous formal security. We analyze the communication and computational loads to illustrate the protocol’s practicality and efficacy. Songsong Zhang, Yi-Ning Liu 0002, Tiegang Gao, Yong Xie 0003 |
IEEE Internet Things J. | 2 |
| 2024 | A game-theory-based scheme to facilitate consensus latency minimization in sharding blockchain
Cheng Guo 0001, Yingmo Jie, Yi-Ning Liu 0002 |
Inf. Sci. | 4 |
| 2024 | TridentShell: An enhanced covert and scalable backdoor injection attack on web applicationsabstractWeb backdoor attack is an increasingly prevalent network attack that can result in substantial losses for webmasters. During a cyber-attack, system vulnerabilities and web application flaws are usually used to implant a web shell inside victim servers. To mitigate the many threats posed by web shells, research has focused on static feature detection, which has evolved rapidly in recent years. However, static feature detection has inherent limitations and security risks. In this paper, we present TridentShell, a novel web backdoor attack that can inject an invisible backdoor into a victim server without leaving any traces of the attack. Furthermore, TridentShell can circumvent almost all static detection methods. Unlike existing approaches, which leverage traditional encryption and obfuscation technologies to avoid detection, our proposed attack is intended to blend into the web application server naturally. In this work, we introduce enhancements to the original TridentShell, which is not traceable—in theory—since it uses a blockchain-based decentralized C&C server with better presentation capability. The experimental results show that our TridentShell can effectively compromise five different types of Java application servers (covering around 87% Java application servers in the market), and can scrub any attack traces from the server, making it especially difficult to detect. Xiaobo Yu, Weizhi Meng 0001, Yi-Ning Liu 0002 |
J. Netw. Comput. Appl. | 3 |
| 2024 | Secure pairing-free certificateless aggregate signcryption scheme for IoT
Yi-Ning Liu 0002, Lihui Li, Yangfan Liang |
J. Syst. Archit. | 3 |
| 2024 | Forward Private Verifiable Dynamic Searchable Symmetric Encryption With Efficient Conjunctive QueryabstractDynamic searchable symmetric encryption (DSSE) allows efficient searches over encrypted databases and also supports clients in their updating of the data, such as those stored in a remote cloud server. However, recent attacks suggest the risk of leakage during such updates, which consequently impacts on the privacy of the queries. In addition, existing DSSE schemes that support forward privacy generally rely on the honest-but-curious server and support only single-keyword retrieval, which limits the application scenarios. In this paper, we present the design of a verifiable DSSE protocol, which supports efficient conjunctive query with forward privacy. In our scheme, the forward index is constructed by a novel form, i.e.,$ t$-puncturable PRFs, and the authentication tag is designed by symmetric cryptography. During conjunctive queries, we narrow the scope by an inverted index, and then we determine the results of the final query through the forward index. Meanwhile, we can use verification tag to check the correctness and completeness of the result. In addition, we present an extension to support backward privacy, and our experimental evaluations show that our proposed approach achieves better performance on both conjunctive queries and updates than other competing solutions and ensures efficient verification. Cheng Guo 0001, Xinyu Tang 0001, Kim-Kwang Raymond Choo, Yi-Ning Liu 0002 |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2024 | DeGKM: Decentralized Group Key Management for Content Push in Integrated NetworksabstractGroup-based content push can be widely applied in integrated networks, where group key management is crucial for the push's security. Existing group key management methods mainly include symmetric group key agreement, broadcast encryption, asymmetric group key agreement, and attribute-based encryption. However, most of them do not consider user equipment (UE) identity privacy and unlinkability, cannot support flexibility and efficiency due to each UE maintaining group keys, and lack the trustworthiness of UE and group key management, which hinders the widespread adoption of group-based content push in trustless environments like integrated networks. In this paper, we investigate a novel decentralized group key management (DeGKM) scheme for group-based content push in integrated networks, where different operators manage pseudonyms and group keys across domains in a decentralized manner. In particular, our scheme adopts verifiable shuffling to establish a unified and trustworthy inter-domain pseudonym management approach that can preserve UE identity privacy and pseudonym unlinkability without relying on a trusted third party, and introduces a unified inter-domain group key management method based on Chinese remainder theorem and blockchain that significantly guarantees the flexibility, efficiency and trustworthiness. We formally prove the security of DeGKM and show its efficiency through simulations and comparisons with related works. Gao Liu, Hao Li 0103, Ning Wang 0003, Tao Xiang 0001, Yi-Ning Liu 0002 |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2024 | An Efficient and Dynamic Privacy-Preserving Federated Learning System for Edge ComputingabstractFederated learning (FL) has been used to enhance privacy protection in edge computing systems. However, attacks on uploaded model gradients may lead to private data leakage, and edge devices frequently joining and leaving will impact the system running. In this paper, we propose a dynamic and flexible federated edge learning (FEL) scheme that can defend against malicious edge servers and edge devices to recover sensitive data and efficiently manage edge devices. A heterogeneity-aware scheduling strategy is designed to take into account the different impacts of heterogeneous edge devices on global model performance. The strategy determines the order of devices participation in each round based on the relative contribution level of the online edge device model, and the edge device with the highest contribution level is selected first. Numerical experiments show that our system improves test accuracy and time, and the security analyses show that our scheme meets the security requirements. Xinyu Tang 0001, Cheng Guo 0001, Kim-Kwang Raymond Choo, Yi-Ning Liu 0002 |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2024 | Physically Secure and Privacy-Preserving Charging Authentication Framework With Data Aggregation in Vehicle-to-Grid NetworksabstractIn response to critical security threats such as data tampering, identity impersonation, and channel eavesdropping in Vehicle-to-Grid (V2G) networks, numerous charging authentication schemes have been proposed. However, these schemes either lack sufficient anonymity, physical security, or electricity consumption data aggregation for electricity dispatch. In light of these considerations, we propose a comprehensive solution—a physically secure and privacy-preserving charging authentication framework with data aggregation, comprising two foundational schemes. The first scheme introduces a fully anonymous authentication system. In this approach, an Electric Vehicle (EV) seeking charging generates a random signature for its charging request. Subsequently, a Charging Station (CS) verifies the signature, granting charging services upon successful validation. Notably, this process guarantees the EV’s real identity remains undisclosed, even to the Control Center (CC). Moreover, this scheme also addresses potential physical attacks through the incorporation of a physical unclonable function. The second scheme involves a privacy-preserving data aggregation scheme, aggregating total electricity consumption of CSs in a given area while simultaneously preserving individual CSs’ electricity consumption data from potential leakage. Subsequently, the aggregated electricity consumption data is transmitted back to the CC, enabling efficient electricity coordination. A detailed security and privacy analysis demonstrates that our proposed framework meets intended security and privacy objectives. The final performance evaluation underscores the advantages of our proposed framework in comparison with related work. Yangfan Liang, Yi-Ning Liu 0002, Xianchao Zhang 0002, Gao Liu |
IEEE Trans. Intell. Transp. Syst. | 2 |
| 2024 | Privacy-Preserving Truth Discovery Based on Secure Multi-Party Computation in Vehicle-Based Mobile CrowdsensingabstractVehicle-based mobile crowdsensing has gained widespread attention due to its low cost and efficient data collection mode. One common method to improve the accuracy of sensing data in this context is truth discovery. However, the emergence of privacy leakage and data misuse has reduced users’ motivation to participate in sensing tasks. Meanwhile, existing solutions for privacy-preserving truth discovery generally suffer from low computational efficiency and frequent interactions between users and servers. Hence, this paper proposes a novel privacy-preserving truth discovery scheme based on secure multi-party computation. For the purpose of high efficiency and strong privacy protection, we utilize the Secret Sharing method to securely decompose data and construct a Secure Multi-party Computation protocol to compute the ground truth. In addition, the weight value generated by truth discovery is employed as a quantitative data quality indicator that dynamically adjusts the user’s rewards and constructs a data quality-driven incentive mechanism. Finally, we demonstrate the high performance of our method through a detailed analysis, showing its effectiveness even in scenarios with numerous users. Tao Peng 0011, Wentao Zhong, Guojun Wang 0001, Shui Yu 0001, Yi-Ning Liu 0002, Yi Yang 0027, Xuyun Zhang |
IEEE Trans. Intell. Transp. Syst. | 6 |
| 2024 | Efficient and Privacy-Preserving Skyline Queries Over Encrypted Data Under a Blockchain-Based Audit ArchitectureabstractSkyline queries is an advanced data mining algorithm suitable for multi-criteria decision-making scenarios (i.e., medical pre-diagnosis). Privacy-preserving skyline queries schemes are usually constructed by certain methods of cryptography such as additive homomorphic cryptosystem, secret sharing technology, etc. Interestingly, these secure skyline queries schemes require that skyline computations do not reveal any message details, including encrypted inter-tuple domination relations, among which privacy schemes based on homomorphic cryptosystems are the most popular due to their strong security. However, existing secure skyline queries schemes not only suffer from low computational efficiency, but also do not have sufficient security for privacy-key management in the system. To address the above issues, this paper designs an efficient and privacy-preserving skyline queries over encrypted data under a blockchain-based audit architecture. Firstly, we propose a blockchain-based audit architecture that not only provides error auditing functionality but also makes our scheme suitable for (distributed) multi-user scenarios while providing secure key management in the system. Secondly, we implement a series of secure sub-protocols using the CRT-Based Paillier encryption algorithm and construct a privacy sparse matrix elimination protocol to reduce the size of the dataset, leading to a significant reduction in computational cost without compromising privacy. Finally, we put forward our secure skyline queries protocol and prove its security. The performance evaluation shows that our proposed method our proposed method is significantly more efficient (at least 7.4 times faster) compared to current methods. Shuchang Zeng, Ching-Fang Hsu 0001, Lein Harn, Yi-Ning Liu 0002, Yang Liu 0368 |
IEEE Trans. Knowl. Data Eng. | 4 |
| 2023 | A Scalable Sharding Protocol Based on Cross-Shard Dynamic Transaction Confirmation for Alliance Chain in Intelligent SystemsabstractApplying sharding protocol to address scalability challenges in alliance chain is popular. However, inevitable cross-shard transactions significantly hamper performance even at low ratios, negating scalability benefits when they dominate as shard scale grows. This article proposes a new sharding protocol suitable for alliance chain that reduces cross-shard transaction impact, improving system performance. It adopts a directed acyclic graph ledger, enabling parallel transaction processing, and employs dynamic transaction confirmation consensus for simplicity. The protocol's sharding process and node score mechanism can deter malicious behavior. Experiments show that compared with mainstream sharding protocols, the protocol performs better when affected by cross-shard transactions. Moreover, its throughput has shown improvement compared to high-performance protocols without cross-shard transactions. This solution suits systems requiring high throughput and reliability, maintaining a stable performance advantage even as cross-shard transactions increase to the usual maximum ratio. Nigang Sun, Yi-Ning Liu 0002, Varsha Arya |
Int. J. Semantic Web Inf. Syst. | 3 |
| 2023 | Scan-free verifiable public-key searchable encryption supporting efficient user updates in distributed systems
Pengxu Tian, Cheng Guo 0001, Yingmo Jie, Yi-Ning Liu 0002, Lin Yao 0001 |
J. Inf. Secur. Appl. | 4 |
| 2023 | Dummy trajectory generation scheme based on generative adversarial networks
Jingkang Yang 0001, Xiaobo Yu, Weizhi Meng 0001, Yi-Ning Liu 0002 |
Neural Comput. Appl. | 4 |
| 2023 | OPERA: Optional Dimensional Privacy-Preserving Data Aggregation for Smart Healthcare SystemsabstractMassive multidimensional health data collected from Internet of Things (IoT) devices are driving a new era of smart health, and with it come privacy concerns. Privacy-preserving data aggregation (PDA) is a proven solution providing statistics while hiding raw data. However, existing PDA schemes ignore the willingness of data owners to share, so data owners may refuse to share data. To increase their willingness to contribute data, we propose an OPtional dimEnsional pRivacy-preserving data Aggregation scheme(OPERA)to provide data contributors with options on sharing dimensions while keeping their choices and data private. OPERA uses selection vectors to represent the decisions of users and count participants dimensionally and achieves data privacy and utility based on a multisecret sharing method and symmetric homomorphic cryptography. Analyses show that in OPERA, the probability of adversaries breaching privacy is less than 4.68e-97. Performance evaluations demonstrate that OPERA is outstanding in computation and practical in communication. Huadong Liu, Tianlong Gu, Mohammad Shojafar, Mamoun Alazab, Yi-Ning Liu 0002 |
IEEE Trans. Ind. Informatics | 5 |
| 2023 | Unlinkable Signcryption Scheme for Multi-Receiver in VANETsabstractAn increasing number of researchers are turning their attention to signcryption, particularly in the context of multi-receiver communication scenarios, due to its ability to simultaneously provide authentication, integrity, and confidentiality of messages. However, existing signcryption schemes have not been able to fully implement sender unlinkability. Specifically, when a sender signcrypts a secret message and obtains the corresponding ciphertext, the intended recipient must use the sender’s identity or public key to complete the unsigncryption process and retrieve the plaintext. Consequently, the recipient can link the sender via the same identity or public key. To address this issue, we present an Unlinkable Signcryption Scheme for Multi-Receiver (USS-MR). With Chinese Remainder Theorem (CRT), our USS-MR enables a vehicle to send the same secret message to a group of RoadSide Units (RSUs). Additionally, when a new message requires signcryption, the vehicle generates a new key pair, making it impossible for any RSU to link the vehicle through its public key. In our USS-MR, we have adopted a pseudonym mechanism to provide conditional privacy, which hides the real identity of the vehicle through the use of pseudonyms and avoids linking it to the identity. Moreover, if a vehicle is found to engage in malicious behavior, it will not only be tracked but also subjected to revocation. Comprehensive security analyses demonstrate that our USS-MR satisfies various security, privacy, and functionality requirements and effectively resists common attacks in Vehicular Ad-hoc Networks (VANETs). Finally, our USS-MR demonstrates certain advantages in terms of computation and communication when compared to relevant studies. In particular, our USS-MR maintains a consistent communication burden of 388 bytes. Yangfan Liang, Hongyang Yan, Yi-Ning Liu 0002 |
IEEE Trans. Intell. Transp. Syst. | 3 |
| 2022 | Lightweight and Practical Privacy-Preserving Image Masking in Smart Community
Yi-Ning Liu 0002, Weizhi Meng 0001 |
ICICS | 2 |
| 2022 | MSDA: multi-subset data aggregation scheme without trusted third party
Zhixin Zeng, Yi-Ning Liu 0002, Liang Chang 0003 |
Frontiers Comput. Sci. | 3 |
| 2022 | A fault tolerance data aggregation scheme for fog computingabstractThe fog computing makes the cloud-based internet of things to be more suitable for the time and location-sensitive applications. However, it is still facing challenges to balance the usability of data and privacy protection. In the past years, some excellent works have tried to address this concern using the aggregation method. However, the fact that IoT devices at the edge of the network may malfunction is not paid enough attention. In this paper, a fault-tolerant data aggregation scheme for fog computing networks is presented by employing Shamir's secret sharing and ElGamal cryptosystem. The proposed scheme ensures that even though a few IoT devices fail to work, the aggregated value can still be obtained with the number of IoT devices that reach the threshold of collaboration. In addition, security analysis and performance evaluation show the proposed scheme achieves security, privacy, and efficiency. Zhixin Zeng, Liang Chang 0003, Yi-Ning Liu 0002 |
Int. J. Inf. Comput. Secur. | 3 |
| 2022 | PPVF: Privacy-Preserving Protocol for Vehicle Feedback in Cloud-Assisted VANETabstractThe vehicular ad hoc network (VANET) is a platform for exchanging information between vehicles and everything to enhance driver’s driving experience and improve traffic conditions. The reputation system plays an essential role in judging whether to communicate with the target vehicle based on other vehicles’ feedback. However, existing reputation systems ignore the privacy protection of feedback providers. Additionally, traditional VANET based on wireless sensor networks (WSNs) has limited power, storage, and processing capabilities, which cannot meet the real-world demands in a practical VANET deployment. Thus, we attempt to integrate cloud computing with VANET and proposes a privacy-preserving protocol of vehicle feedback (PPVF) for cloud-assisted VANET. In cloud-assisted VANET, we integrate homomorphic encryption and data aggregation technology to design the scheme PPVF, in which with the assistance of the roadside units (RSU), cloud service provider (CSP) obtains the total number of vehicles with the corresponding parameters in the feedback for reputation calculation without violating individual feedback privacy. Simulation results and security analysis confirm that PPVF achieves effective privacy protection for vehicle feedback with acceptable computational and communication burden. Besides, the RSU is capable of handling 1999 messages for every$300ms$, so as the number of vehicles in the communication domain increases, the PPVF has a lower message loss rate. Hongyuan Cheng, Mohammad Shojafar, Mamoun Alazab, Rahim Tafazolli, Yi-Ning Liu 0002 |
IEEE Trans. Intell. Transp. Syst. | 5 |
| 2022 | PLVA: Privacy-Preserving and Lightweight V2I Authentication ProtocolabstractVehicular ad hoc networks (VANETs) significantly improves the efficiency and safety of driving since it reduces traffic jams and avoiding accidents, in which the necessary security goals are guaranteed using cryptographic method. In reality, the computation efficiency is very important in implementing the protocol in VANETs. When a vehicle with high speed enters in the coverage of a roadside unit (RSU), the computation overhead of authentication not only affects the communication experience, but also downgrades the driving safety. The feasible solution is to share a message in advance between vehicle and RSU with the help of certification authority (CA), however, CA can deduce the vehicle’s route that should be privacy. In this paper, a privacy-preserving and lightweight V2I authentication (PLVA) protocol is proposed. Specifically, in the beginning phase, all roadside units in a region are converted to a vector using the Moore curve technique, then, a vehicle deduces the RSUs’ information on its planning route using BGN homomorphic encryption before the vehicle begins its trip, meanwhile, CA knows nothing about the route plan although it assists the above process. With the deduced RSUs’ information, fast authentication is achieved between vehicle and each RSU on its route. Moreover, performance evaluation illustrates that our PLVA is efficient in practical VANETs environment. Song-Zhan Lv, Yi-Ning Liu 0002 |
IEEE Trans. Intell. Transp. Syst. | 2 |
| 2022 | PPRP: Preserving-Privacy Route Planning Scheme in VANETsabstractRoute planning helps a vehicle to share a message with the roadside units (RSUs) on its path in advance, which greatly speeds the authentication between the vehicle and the RSUs when the vehicle enters the RSUs’ coverage. In addition, since only a small amount of necessary information needs to be shared between the vehicle and the RSUs, route planning can reduce the storage overhead of the vehicle’s on-board unit (OBU) and the RSUs. However, the message sharing requires the assistance of the certification authority (CA), which will lead CA easily to obtain the vehicle’s planning route. Although CA knows the vehicle’s registration information and helps the vehicle to communicate with RSUs, it is unacceptable that the path of their vehicle is obtained by CA for most drivers. In fact, vehicle’s sensitive information such as planning route, starting time, stop place, should be privacy for others including CA. Inspired with the method of oblivious transfer, a preserving-privacy route planning scheme in VANETs is proposed in this article, in which, a vehicle deduces the information of RSUs on its path with the help of CA, while CA knows nothing about which RSUs’ information has been deduced by the vehicle. Later, fast authentication or other service is easily achieved between the vehicle and the RSUs (V2R) with the pre-shared information. After V2R authentication, vehicles could easily communicate with adjacent vehicles with the help of RSUs (V2V). Finally, compared with related schemes, performance evaluation illustrates the proposed scheme is better in terms of time consumption. Yangfan Liang, Yi-Ning Liu 0002, Brij B. Gupta |
ACM Trans. Internet Techn. | 2 |
| 2021 | TridentShell: a Covert and Scalable Backdoor Injection Attack on Web Applications
Xiaobo Yu, Weizhi Meng 0001, Yi-Ning Liu 0002 |
ISC | 4 |
| 2021 | A secure and trustworthy medical record sharing scheme based on searchable encryption and blockchain
Xinyu Tang 0001, Cheng Guo 0001, Kim-Kwang Raymond Choo, Yi-Ning Liu 0002, Long Li 0005 |
Comput. Networks | 4 |
| 2021 | Fault-Tolerant Multisubset Aggregation Scheme for Smart GridabstractAs smart cities and nations are fast becoming a reality, so does the underpinning infrastructure, such as smart grids. One particular challenge associated with smart grid implementation is the need to ensure privacy preserving multisubset data aggregation. Existing approaches generally require the collaboration of a trusted third party (TTP), which may not be practical. This also increases the threat exposure, as the attacker can now target the TTP who may be servicing several smart grid operators. Therefore, in this article, a fault-tolerant multisubset data aggregation scheme is proposed. Our scheme aggregates the total electricity consumption value, and obtains the number of users and the total electricity consumption in different numerical intervals, without relying on any TTP. Detailed system analysis shows that our scheme prevents the leakage of single data, as well as guarantees the efficiency when new user joins and existing user leaves. Findings from our evaluation also demonstrate that system robustness is achieved with negligible cost. Yi-Ning Liu 0002, Kim-Kwang Raymond Choo |
IEEE Trans. Ind. Informatics | 2 |
| 2021 | HDMA: Hybrid D2D Message Authentication Scheme for 5G-Enabled VANETsabstractThe fifth-generation (5G) mobile communication technology with higher capacity and data rate, ultra-low device to device (D2D) latency, and massive device connectivity will greatly promote the development of vehicular ad hoc networks (VANETs). Meantime, new challenges such as security, privacy and efficiency are raised. In this article, a hybrid D2D message authentication (HDMA) scheme is proposed for 5G-enabled VANETs, in which a novel group signature-based algorithm is used for mutual authentication between vehicle to vehicle (V2V) communication. In addition, a pre-computed lookup table is adopted to reduce the computation overhead of modular exponentiation operation. Security analysis shows that HDMA is robust to resist various security attacks, and performance analysis also points out that, the authentication overhead of HDMA is more efficient than some traditional schemes with the help of the pre-computed lookup table in V2V and vehicle to infrastructure (V2I) communication. Chien-Ming Chen 0001, Saru Kumari, Mohammad Shojafar, Rahim Tafazolli, Yi-Ning Liu 0002 |
IEEE Trans. Intell. Transp. Syst. | 6 |
| 2021 | FPETD: Fault-Tolerant and Privacy-Preserving Electricity Theft DetectionabstractElectricity theft occurs from time to time in the smart grid, which can cause great losses to the power supplier, so it is necessary to prevent the occurrence of electricity theft. Using machine learning as an electricity theft detection tool can quickly lock participants suspected of electricity theft; however, directly publishing user data to the detector for machine learning‐based detection may expose user privacy. In this paper, we propose a real‐time fault‐tolerant and privacy‐preserving electricity theft detection (FPETD) scheme that combines n‐source anonymity and a convolutional neural network (CNN). In our scheme, we designed a fault‐tolerant raw data collection protocol to collect electricity data and cut off the correspondence between users and their data, thereby ensuring the fault tolerance and data privacy during the electricity theft detection process. Experiments have proven that our dimensionality reduction method makes our model have an accuracy rate of 92.86% for detecting electricity theft, which is much better than others. Siliang Dong, Zhixin Zeng, Yi-Ning Liu 0002 |
Wirel. Commun. Mob. Comput. | 3 |
| 2020 | Secret sharing with secure secret reconstruction
Lein Harn, Zhe Xia, Ching-Fang Hsu 0001, Yi-Ning Liu 0002 |
Inf. Sci. | 4 |
| 2020 | Lightweight privacy-preserving data aggregation protocol against internal attacks in smart grid
Xiao-di Wang, Weizhi Meng 0001, Yi-Ning Liu 0002 |
J. Inf. Secur. Appl. | 3 |
| 2020 | Fault-Tolerant Privacy-Preserving Data Aggregation for Smart GridabstractIn smart grids (SG), data aggregation is widely used to strike a balance between data usability and privacy protection. The fault tolerance is an important requirement to improve the robustness of data aggregation protocols, which enables normal execution of the protocols even with failures on some entities. However, to achieve fault tolerance, most schemes either sacrifice the aggregation accuracy due to the use of differential privacy or substitution strategy or need to rely on an online trusted entity to manage all user blinding factors. In this paper, a ( k,n ) threshold privacy-preserving data aggregation scheme named ( k,n )-PDA is proposed, which reconciles data usability and data privacy through the BGN cryptosystem and achieves fault tolerance with accurate aggregation using Shamir’s secret sharing without any online trusted entity. Besides, our scheme supports the efficient changing of users’ membership. Specifically, the dynamic secrete key is distributed to n smart meters (SMs) through the threshold secret sharing algorithm. When k or more meters participate in the aggregation, the data service center (DSC) can reconstruct the key to compute the aggregate results, and less than k SMs cannot recover the key. Thus, our solution still works functionally even if up to n−k SMs fail; also, it resists attacks from the collusion of less than k SMs. Moreover, system and performance analyses demonstrate that our scheme achieves privacy, fault tolerance, and membership dynamics with high efficiency. Huadong Liu, Tianlong Gu, Yi-Ning Liu 0002, Jingcheng Song, Zhixin Zeng |
Wirel. Commun. Mob. Comput. | 3 |
| 2019 | Privacy-preserving raw data collection without a trusted authority for IoT
Yi-Ning Liu 0002, Yan-Ping Wang, Xiao-Fen Wang, Zhe Xia, Jingfang Xu |
Comput. Networks | 1 |
| 2019 | A progressively essential secret image sharing scheme using hierarchy shadow
Yan-Xiang Hu, Yi-Ning Liu 0002 |
J. Inf. Secur. Appl. | 2 |
| 2019 | Detection of Dummy Trajectories Using Convolutional Neural NetworksabstractNowadays, privacy in trajectory is an important issue in the coming big data era. In order to provide better protection for trajectory privacy, a number of solutions have been proposed in the literature, and the dummy trajectory method has attracted great interests in both academia and industry recently due to the following advantages: (1) neither a third-party server nor other parties’ cooperation is necessary; (2) location-based services are not influenced; and (3) its algorithm is relatively simple and efficient. However, most of trajectory privacy generations usually consider the geometric shape of the trajectory; meanwhile the real human mobility feature is usually neglected. In fact, the real trajectory is not the product of random probability. In this paper, convolutional neural network (CNN) is used as the learning machine to train with lots of the real trajectory and the generated dummy trajectory sets. Then, the trained classifier is used to distinguish the dummy from the real trajectory. Experiments demonstrate that the method using CNN is very efficient, and more than 90% of dummy trajectories can be detected. Moreover, the real trajectory erroneous judgment rate is below 10% for most of real trajectories. Jiaji Pan, Yi-Ning Liu 0002, Weiming Zhang 0001 |
Secur. Commun. Networks | 2 |
| 2019 | A Practical Privacy-Preserving Data Aggregation (3PDA) Scheme for Smart GridabstractThe real-time electricity consumption data can be used in value-added service such as big data analysis, meanwhile the single user's privacy needs to be protected. How to balance the data utility and the privacy preservation is a vital issue, where the privacy-preserving data aggregation could be a feasible solution. Most of the existing data aggregation schemes rely on a trusted third party (TTP). However, this assumption will have negative impact on reliability, because the system can be easily knocked down by the denial of service attack. In this paper, a practical privacy-preserving data aggregation scheme is proposed without TTP, in which the users with some extent trust construct a virtual aggregation area to mask the single user's data, and meanwhile, the aggregation result almost has no effect for the data utility in large scale applications. The computation cost and communication overhead are reduced in order to promote the practicability. Moreover, the security analysis and the performance evaluation show that the proposed scheme is robust and efficient. Yi-Ning Liu 0002, Wei Guo 0012, Chun-I Fan, Liang Chang 0003, Chi Cheng 0003 |
IEEE Trans. Ind. Informatics | 1 |
| 2019 | E-voting scheme using secret sharing and K-anonymity
Yi-Ning Liu 0002, Quanyu Zhao |
World Wide Web | 1 |
| 2018 | Privacy-Preserving Data Collection for Mobile Phone Sensing Tasks
Yi-Ning Liu 0002, Yan-Ping Wang, Xiao-Fen Wang, Zhe Xia, Jingfang Xu |
ISPEC | 1 |
| 2018 | An improved threshold multi-level image recovery scheme
Yi-Ning Liu 0002 |
J. Inf. Secur. Appl. | 1 |
| 2018 | A novel multiple-level secret image sharing scheme
Yi-Ning Liu 0002, Zu-Bin Chen |
Multim. Tools Appl. | 1 |
| 2017 | A secure data backup scheme using multi-factor authenticationabstractSensitive data stored in laptops or other mobile devices can easily be lost, stolen, misplaced or corrupted, the remote backup storage technique is used to address these issues; however, the backup server could not be fully trusted, the data should be encrypted in advance. Although the key is more easily protected due to the smaller size compared with the backup data, it is still impossible for ordinary human to remember. A user‐centred design data backup scheme is proposed using multi‐factor authentication. The user firstly selects a symmetrical key and divides it into three shares, then destroys the key. The key can easily be reconstructed by combining the shares stored in the user's smart card and the laptop. Even if the smart card or laptop is lost, the key can still be recovered with the password and biometrics. The proposed scheme not only achieves the required security goals but also is more robust and practical. Yi-Ning Liu 0002, Liang Chang 0003, Zhe Xia, Debiao He, Chi Cheng 0003 |
IET Inf. Secur. | 1 |
| 2013 | A lightweight micropayment scheme based on Lagrange interpolation formulaabstractABSTRACT On the basis of hash chain and Lagrange interpolation formula over a finite field, a lightweight micropayment scheme is proposed. Compared with Micali and Rivest's micropayment scheme, the improved scheme achieves three additional properties to ensure it suitable for mobile network. First it reduces the computing burden without digital signature algorithm, which is essential for limited mobile terminal. Second, the user, the merchant, and the bank are all equally involved in the selection of payable checks, which ensure the proposed scheme is fair for all parties. Moreover, the privacy of scheme is also achieved for the computational infeasibility of calculating the inverse of secure one‐way function. The improved micropayment scheme is secure, fair, and efficient, and privacy‐preserving, especially suitable for mobile network. Copyright © 2012 John Wiley & Sons, Ltd. Yi-Ning Liu 0002, Jihong Yan |
Secur. Commun. Networks | 1 |
| 2013 | An Improved Authenticated Group Key Transfer Protocol Based on Secret SharingabstractTo achieve secure group communication, one-time session keys need to be shared among group members in a secure and authenticated manner. In this paper, we propose an improved authenticated key transfer protocol based on Shamir's secret sharing. The proposed protocol achieves key confidentiality due to security of Shamir's secret sharing and provides key authentication by broadcasting a single authentication message to all members. Furthermore, the proposed scheme resists against both insider and outsider attacks. Yi-Ning Liu 0002, Chi Cheng 0003, Jianyu Cao, Tao Jiang 0002 |
IEEE Trans. Computers | 1 |
| 2011 | An Improved Electronic Voting Scheme without a Trusted Random Number Generator
Yi-Ning Liu 0002, Peiyong Sun, Jihong Yan, Jianyu Cao |
Inscrypt | 1 |
| 2011 | A novel reputation computation model based on subjective logic for mobile ad hoc networks
Yi-Ning Liu 0002, Keqiu Li, Yingwei Jin, Yong Zhang 0030, Wenyu Qu |
Future Gener. Comput. Syst. | 1 |
| 2011 | A GroupTrust model based on service similarity evaluation in P2P networksabstractThe open and anonymous nature of peer-to-peer (P2P) networks makes it an ideal medium for attackers to spread malicious contents, which in turn leads to lower quality of network services due to lack of effective trust management mechanism. To improve the quality of services (or transactions), this paper proposes a novel trust and reputation model, named as GroupTrust, based on peer group and evaluation similarity degree in P2P networks. In the proposed model, trust relationships between peers are divided into three categories: trust relationship within a peer group, trust relationship between different groups, and trust relationship between a peer in a peer group with another peer out of this peer group. The model presents the evaluation similarity degree under different context of services and gives local and global reputation computation. Experimental results demonstrate that this model can get more real trust value and deal with the malicious attacks efficiently by comparison with existing models. © 2010 Wiley Periodicals, Inc. Yong Zhang 0030, Hongliang Zheng, Yi-Ning Liu 0002, Keqiu Li, Wenyu Qu |
Int. J. Intell. Syst. | 3 |
| 2010 | A Novel Class of 2-D Binary Sequences With Zero Correlation ZoneabstractIn this letter, we propose a novel scheme to construct a novel class of 2-D binary sequences with zero correlation zone, which is based on perfect arrays and orthogonal sequences. Compared with all existing 2-D binary sequences, the proposed construction can generate more sets of two-dimensional binary sequences with long zero correlation zone. Moreover, the constructed 2-D sequence sets could be applied directly, such as arrays of sound sources, position detection arrays, phased-array antennas, time-frequency coding, and spatial correlation. Chi Cheng 0003, Tao Jiang 0002, Yi-Ning Liu 0002 |
IEEE Signal Process. Lett. | 3 |
| 2009 | A Novel Reputation Computation Model Based on Subjective Logic for Mobile Ad Hoc NetworksabstractSelfish behaviors significantly affect the overall performance of mobile ad hoc networks (MANETs). Reputation systems have been proved to be an efficient way to block such behaviors in MANETs. Several reputation models based on subjective logic have been proposed to improve the reputation mechanism, in which an uncertainty value is introduced for reputation computation when the local information is not sufficient. However, these reputation models fail to utilize the recommended opinions effectively and reduce the uncertainty value while these opinions are combined. In this paper, we propose a novel reputation computation model based on subjective logic to overcome the above deficiencies. We consider not only the recommenders' trustworthiness but also the familiarities among the recommended nodes during reputation computations. This familiarity is defined as a certainty value which is used to weight opinions in reputation computation. In our model, the recommendations of nodes with low trustworthiness or high uncertainty on the recommended nodes have little impact on the recommended nodes' reputations so that nodes can reach opinions with lower uncertainty value through reputation computations. We conduct simulations to evaluate our model on its performance. The simulation results show that the proposed model achieves about 40% improvement in the time of discovering and isolating selfish nodes compared with a previous model based on subjective logic and selfish nodes' success rate is further reduced by up to 10%. Yi-Ning Liu 0002, Keqiu Li, Yong Zhang 0030, Wenyu Qu |
NSS | 1 |
| 2008 | A Trust Model Based on Similarity Evaluation in P2P NetworksabstractDue to lack of effective trust management mechanism, there are a lot of deceptive behaviors in P2P networks, which seriously decrease the quality of network services. In order to improve the quality of services (or transactions), this paper proposes a novel trust and reputation model based on similarity evaluation in P2P environments. According to the different context of services, the model gives the similarity degree evaluation, and presents local reputation and global reputation computation. Experimental results demonstrate that this model can get more real trust value and deal with the malicious attacks. Yingwei Jin, Yong Zhang 0030, Wenyu Qu, Yi-Ning Liu 0002, Keqiu Li |
ISPA | 4 |