EDBT 2026 Demo / reviewers in the wild / expert
Feng Li 0041
dblp:92/2954-41
· DBLP profile ↗
11ranked-venue papers
3as first author
10since 2021 · last 2025
0000-0002-8294-7606ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 5 · 1 first-author · 4 since 2021Computer networks · 4 · 4 since 2021Systems, architecture and hardware · 2 · 2 first-author · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | SCRM: Secure and Controllable Similarity Retrieval in Multiuser SettingsabstractCloud computing has become an essential paradigm for facilitating large-scale and privacy-preserving encrypted image retrieval in Internet of Things (IoT) environments. However, existing encrypted image retrieval schemes face challenges in balancing retrieval efficiency and data security, which hinders their practical adoption. On one hand, retrieval-efficient schemes based on secure k-Nearest Neighbor (kNN) are prone to known-plaintext attacks; on the other hand, highly secure schemes based on homomorphic encryption often suffer from excessive computational and storage overhead. Furthermore, supporting multi-user environments and enforcing fine-grained access control over query users are critical challenges in IoT-based retrieval systems. To tackle these issues, we propose a Secure and Controllable similarity Retrieval scheme in Multi-user settings (SCRM), which achieves a practical trade-off between efficiency and security while enabling multi-user management. First, we design an efficient and privacy-preserving similarity computation method that is resilient against known-plaintext attacks. Second, we introduce a key conversion protocol that enables similarity retrieval in multi-user settings without requiring key sharing. Third, we integrate attribute-based encryption to enforce fine-grained access control and trace query users who may leak decryption keys. A correctness analysis confirms that SCRM ensures accurate similarity retrieval while supporting access control. Furthermore, a formal security analysis demonstrates that SCRM effectively protects data privacy against known-plaintext attacks. Finally, extensive experiments on real-world image dataset validate the efficiency and effectiveness of SCRM. Yingying Li 0001, Feng Li 0041, Gaopan Hou, Yu Guan 0003, Zhiquan Liu 0001, Qi Xie 0001 |
IEEE Internet Things J. | 2 |
| 2025 | Efficient Privacy-Preserving Similarity Retrieval With Fine-Grained Access ControlabstractPrivacy-preserving similarity retrieval for ciphertext images has broad applications in Internet of Things (IoT) areas, including smart healthcare, face recognition, and social networking. However, most existing privacy-preserving schemes suffer from inefficient retrieval and limited security guarantees due to the use of unreasonable encryption methods. In addition, those supporting fine-grained access control often lack scalability or are computationally inefficient. To address these challenges, we propose an efficient similarity retrieval scheme for ciphertext images that ensures both privacy preservation and fine-grained access control. First, we construct an encrypted index tree using clustering to improve retrieval efficiency while preserving high recall. Second, we achieve security against chosen-plaintext attacks (CPA) and result verification by employing symmetric homomorphic encryption and Merkle hash tree. Third, we realize access control for each image, enabling simultaneous access verification and similarity retrieval via a single inner product operation. Our theoretical and experimental analysis shows that the proposed scheme is CPA-secure and achieves up to 100× faster query processing than existing CPA-secure schemes, with the ability to retrieve 2000 ciphertext images within 0.5 seconds for 128-dimensional feature vectors. Yingying Li 0001, Feng Li 0041, Fuqun Wang, Zhiquan Liu 0001, Qi Xie 0001, Song Han 0006 |
IEEE Internet Things J. | 2 |
| 2024 | Practical Revocable Keyword Search Over Mobile Cloud-Assisted Internet of ThingsabstractSearchable encryption (SE) can potentially be used to guarantee both data confidentiality and searchability over mobile cloud-assisted Internet of things. However, existing SE solutions mainly focus on user revocation rather than keyword revocation. The keyword revocation may be required in certain situations. For example, patients do not allow their doctors to access records on some diseases such as syphilis. Hence, we propose a basic Revocable Keyword Search (RKS) scheme over encrypted electronic medical records in the group setting, which supports keyword revocation (by using a revocation list) and authorized access permissions (via a group key exchange protocol). Then, we design an enhanced RKS (called RKS+) to significantly reduce the size of revoked keyword ciphertexts and the costs of token generation and ciphertext retrieval. Our schemes also support efficient user revocation by updating only one index component, and guarantee forward security. The formal security analysis proves that our schemes are secure against both chosen-keyword attacks and chosen-plaintext attacks, and findings from the empirical evaluations demonstrate that our schemes are efficient and practical. Shuqin Liu, Yinbin Miao, Feng Li 0041, Xinghua Li 0001, Kim-Kwang Raymond Choo, Robert H. Deng |
IEEE Internet Things J. | 3 |
| 2024 | REKS: Role-Based Encrypted Keyword Search With Enhanced Access Control for Outsourced Cloud DataabstractKeyword-based search over encrypted data is an important technique to achieve both data confidentiality and utilization in cloud outsourcing services. While commonly used access control mechanisms, such as identity-based encryption and attribute-based encryption, do not generally scale well for hierarchical access permissions. To solve this problem, we propose a Role-based Encrypted Keyword Search (REKS) scheme by using the role-based access control and broadcast encryption. Specifically, REKS allows owners to deploy hierarchical access control by allowing users with parent roles to have access permissions from child roles. Using REKS, we further facilitate token generation preprocessing and efficient user management, thereby significantly reducing the users' final token generation and index update overheads, respectively. Formal security analysis proves that REKS is secure against chosen keyword and internal keyword guessing attacks, and findings from the empirical evaluations demonstrate that REKS is efficient and practical. Yinbin Miao, Feng Li 0041, Xiaohua Jia, Huaxiong Wang, Ximeng Liu, Kim-Kwang Raymond Choo, Robert H. Deng |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2024 | Verifiable Outsourced Attribute-Based Encryption Scheme for Cloud-Assisted Mobile E-Health SystemabstractThe cloud-assisted mobile electronic health (e-health) system facilitates e-health data sharing between healthcare providers and patients, but also raises the security and privacy concerns of e-health data. Although Ciphertext-Policy Attribute-Based Encryption (CP-ABE) has been a promising technique to achieve fine-grained access control over encrypted e-health data, it still incurs high encryption and decryption burdens on mobile users such as smartphones and sensors. In addition, malicious cloud servers may conduct incorrect operations due to various interest incentives (e.g., leaking sensitive information to illegal users, saving computation and storage costs). To solve the above issues, in this paper we first propose an Outsourced CP-ABE (OABE) with verifiable encryption scheme by splitting secret keys corresponding to an attribute set and using the short signature, which not only reduces the encryption and decryption complexities of mobile users but also guarantees that cloud servers correctly perform encryption operations. Then, we extend OABE to construct outsourced CP-ABE with verifiable decryption (OABE+) by utilizing the verifiable tag mechanism, which guarantees that cloud servers correctly conduct the ciphertext transformation. Formal security analysis proves that our schemes are selectively secure against unauthorized accesses and malicious operations. Extensive experiments using various real-world datasets demonstrate that our schemes are efficient and feasible in real applications. Yinbin Miao, Feng Li 0041, Xinghua Li 0001, Jianting Ning, Hongwei Li 0001, Kim-Kwang Raymond Choo, Robert H. Deng |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2024 | Time-Controllable Keyword Search Scheme With Efficient Revocation in Mobile E-Health CloudabstractElectronic health (e-health) systems may outsource data such as patient e-health records to mobile cloud servers for efficiency gains (e.g., minimizing local storage and computation costs). However, such a move may result in privacy implications in the presence of semi-honest cloud servers. Searchable Encryption (SE) can potentially facilitate privacy-preserving searches based on keywords for encrypted data stored in the mobile cloud, but most existing SE solutions do not support temporal access control (i.e., a mechanism that grants access permissions to users for specified time ranges). Hence, in this paper we design a time-controllable keyword search scheme by using an attribute-based comparable access control. This allows users to match indexes encrypted at specified time intervals. Then, we improve the basic framework to support efficient user revocation using secret sharing. We then formally prove the security of our proposed frameworks against chosen-keyword attack and key collusion attack, as well as achieving keyword secrecy. We also evaluate the performance of our proposed approach using a real-world dataset to demonstrate their practical utility. Yinbin Miao, Feng Li 0041, Xinghua Li 0001, Zhiquan Liu 0001, Jianting Ning, Hongwei Li 0001, Kim-Kwang Raymond Choo, Robert H. Deng |
IEEE Trans. Mob. Comput. | 2 |
| 2023 | Beyond Volume Pattern: Storage-Efficient Boolean Searchable Symmetric Encryption with Suppressed Leakage
Feng Li 0041, Jianfeng Ma 0001, Yinbin Miao, Xiangfu Song |
ESORICS (1) | 1 |
| 2023 | Verifiable and Dynamic Multi-Keyword Search Over Encrypted Cloud Data Using BitmapabstractSearchable Symmetric Encryption (SSE), which enables users to search over encrypted data without decryption, has gained increasing attention from both academic and industrial fields. However, existing SSE schemes either have low search efficiency or cannot support multi-keyword search, dynamic updates, and result verification simultaneously. To solve these problems, we propose a Verifiable and Dynamic Multi-keyword Search (VDMS) scheme over encrypted data by using the bitmap and RSA accumulator, which provides multi-keyword search over encrypted data in an efficient, verifiable and updated way. The bitmap is used as a data structure to build the indexes, which improves the search efficiency and reduces the storage space of the indexes. The RSA accumulator and bitmap are combined to verify the correctness of results. Formal security analysis proves that our VDMS is adaptively secure against Chosen-Keyword Attacks (CKA), and empirical experiments using a real-world dataset demonstrate that our VDMS is efficient and feasible in practical applications. Feng Li 0041, Jianfeng Ma 0001, Yinbin Miao, Qi Jiang 0001, Ximeng Liu, Kim-Kwang Raymond Choo |
IEEE Trans. Cloud Comput. | 1 |
| 2023 | Towards Efficient Verifiable Boolean Search Over Encrypted Cloud DataabstractSymmetric Searchable Encryption (SSE) schemes facilitate searching over encrypted data, and have been extensively explored to improve function, efficiency or security. There are, however, additional functions that we need to consider in a real-world setting. For example, forward and backward privacy are required to adequately secure newly added documents and deleted documents in Dynamic SSE (DSSE) schemes, and support boolean search (that allows users to search over encrypted data using basic boolean operations) to achieve improved efficiency and retrieval accuracy. Therefore, in this article we first construct the Verifiable Boolean Search over encrypted data (VBS), and then improve VBS to achieve Forward and Backward privacy (VBS-FB). Finally, we formally prove the security of our proposed schemes, and evaluate their performance using real-world datasets. Feng Li 0041, Jianfeng Ma 0001, Yinbin Miao, Zhiquan Liu 0001, Kim-Kwang Raymond Choo, Ximeng Liu, Robert H. Deng |
IEEE Trans. Cloud Comput. | 1 |
| 2021 | Enabling Efficient Spatial Keyword Queries on Encrypted Data With Strong Security GuaranteesabstractStructured Encryption (STE), which allows a server to provide secure search services on encrypted data structures, has been widely investigated in recent years. To meet expressive search requirements in practical applications, a large number of STE constructions have been proposed either on textual keywords or spatial data. However, STE on spatio-textual data, which are widely used in location-based services, has not been fully investigated. In this paper, we formally define the notion of Spatial Keyword Structured Encryption (SKSE) and propose several concrete SKSE constructions with various efficiency-security trade-offs. Firstly, we propose a basic construction with linear search complexity, which only leaks the private files matching both spatial range query and all query keywords. Then, to improve the search efficiency on large-scale datasets, we present a novel tree-based construction with sub-linear search complexity. Finally, we introduce a post-validation approach to remove false positives and further improve storage and search performance. Our constructions are general in the sense that they can be constructed from any hidden vector encryption schemes, including public-key setting and symmetric-key setting, which can meet different sharing requirements. Our rigorous security analysis and comprehensive performance evaluation demonstrate that the proposed constructions are secure and outperform the start-of-the-art solutions. Xiangyu Wang 0010, Jianfeng Ma 0001, Feng Li 0041, Ximeng Liu, Yinbin Miao, Robert H. Deng |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2020 | IMShell-Dec: Pay More Attention to External Links in PowerShell
Ruidong Han, Chao Yang 0016, Jianfeng Ma 0001, Siqi Ma 0001, Yunbo Wang, Feng Li 0041 |
SEC | 6 |