Chang Xu 0004

dblp:97/2966-4 · DBLP profile ↗
← Back
62ranked-venue papers
27as first author
38since 2021 · last 2026
0000-0002-9726-7232ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 23 · 12 first-author · 17 since 2021Systems, architecture and hardware · 11 · 5 first-author · 7 since 2021Security and privacy · 10 · 3 first-author · 6 since 2021Applied, interdisciplinary, general and emerging computing · 7 · 5 first-author · 3 since 2021Databases, data management, data science and information retrieval · 6Software engineering, systems software and programming languages · 5 · 2 first-author · 5 since 2021
YearPublicationVenuePosition
2026 HySLA: Hybrid DPoS-DAG Model for Secure, Scalable, and Low-Latency Access Control in Internet of Vehicles
Awais Bilal, Kashif Sharif, Liehuang Zhu, Fan Li 0001, Chang Xu 0004, Md. Monjurul Karim
IEEE Internet Things J.5
2026 Self-Attention Clustering-Based Defense Against Eclipse Attacks on Ethereum
abstract
The rapid growth of blockchain technology and the increasing number of network nodes have heightened the risk of sophisticated attacks. Among these, Eclipse attacks present a serious threat to decentralized networks by exploiting their peer-to-peer structures. While previous research has explored artificial intelligence techniques to defend against Eclipse attacks, evolving attack patterns continue to challenge existing defenses. In this paper, we propose a novel defense framework that integrates a clustering approach based on self-attention encoders within a multi-kernel neural network clustering model. Our method utilizes parallel subnetworks to extract category-specific features from multiple perspectives, generating discriminative cluster centroids that are combined with raw transaction data to train a robust classifier for detecting Eclipse attacks in Ethereum networks. To evaluate our approach, we simulate Eclipse attacks on the Ethereum testnet and conduct extensive experiments. The results demonstrate that our method achieves a detection accuracy of 98.5% and improves classification performance by 5% compared to models trained without cluster-enhanced features, confirming the effectiveness of the proposed defense.
Chengzhi Gao, Guoxie Jin, Chang Xu 0004, Liehuang Zhu, Kashif Sharif
IEEE Internet Things J.4
2026 Blockchain-Assisted Privacy-Preserving and Robust Federated Learning in Edge Computing
Chang Xu 0004, Liehuang Zhu, Lianyi Sun, Kashif Sharif
IEEE Internet Things J.2
2026 TCFL: Trapdoor homomorphic encryption based federated learning aggregator with filter
abstract
Although federated learning prevents direct exposure of user data during training, numerous studies have demonstrated its vulnerability to security threats. Federated learning faces even greater risks due to its wide distribution, large number of users, and uncontrollable local data. Attackers can launch inference attacks to deduce users’ information from local model gradients. Furthermore, some malicious participants may launch poisoning attacks by tampering with local data or model updates. How to identify poisoning attacks while preserving user privacy in federated learning remains a major challenge, especially when the proportion of Byzantine clients is greater than or equal to 50%, which makes defense strategies harder to design. To address these challenges, we propose a robust federated learning aggregation scheme TCFL based on two-trapdoor homomorphic encryption. TCFL can preserve update privacy and prevent key leakage, and it can identify encrypted malicious gradients using a maximum clique filtering mechanism based on Euclidean distance. We provide convergence and security analyses of the scheme, and conduct extensive experiments on three benchmark image-classification datasets under multiple data and model poisoning attacks with attacker ratios ranging from 0% to 90%. The results show that, under these evaluated settings, TCFL maintains higher test accuracy and robustness than existing aggregation rules while retaining acceptable computational overhead.
Chang Xu 0004, Liehuang Zhu
Peer Peer Netw. Appl.3
2026 Evaluation to Integration: Hybrid Feature Selection Framework With Ensemble Machine Learning for Intrusion Detection
abstract
We study feature selection (FS) for flow-based intrusion detection and propose a deterministic hybrid-FS that fuses Mutual Information, Random-Forest, and XGBoost importances under a simplex search with a single threshold. Using CIC-IDS-2017, CSE-CIC-IDS2018, and NF-UNSW-NB15, we evaluate ten FS techniques paired with six ensembles under a leakage-safe protocol. The hybrid-FS consistently matches or exceeds the best single selectors while reducing feature count (e.g.,$78 \rightarrow 31$) and improving runtime. Throughput rises by$\sim$9–10% and per-flow latency drops from$0.44 \rightarrow 0.40$ms (p50) and$1.40 \rightarrow 1.20$ms (p99), with mean$\pm$95% CIs and paired tests. False-positive rate (FPR) decreases by 15–19% ($\approx$22 fewer false alarms per hour at 100k flows/h). Against representative PSO/GA hybrids, our fusion attains small but consistent macro-F1 gains and 15–25% FPR reductions at comparable latency. We clarify adversarial robustness with an explicit FGSM feature-space threat model and DeepPackGen configuration, and we diagnose cross-dataset shift with lightweight mitigations. A 24-hour SOC replay links FPR to analyst time savings (2.5–3.7 hours/day) without sacrificing macro-F1 or AUROC. The results position deterministic, compact FS as a practical choice for inline IDS where tail latency and alert volume matter.
Awais Bilal, Kashif Sharif, Liehuang Zhu, Fan Li 0001, Chang Xu 0004, Md. Monjurul Karim
IEEE Trans. Dependable Secur. Comput.5
2026 BCADS: Blockchain-Assisted Cross-Domain Authentication With Decentralized Identity for VANETs Under Strict Oversight
abstract
Cross-domain authentication is essential for se curing communication between different management domains in Vehicular Ad Hoc Networks (VANETs). However, existing blockchain-based cross-domain authentication schemes, which rely on centralized entities or smart contracts for distributed identity management, face challenges in terms of latency, trust assumptions, security guarantees, and deployment flexibility. Furthermore, many of these schemes do not fully meet the stringent regulatory requirements of real-world VANET sce narios and provide limited protection of vehicle privacy. In this paper, we introduce BCADS, a Blockchain-assisted Cross domain Authentication with Decentralized identity for VANETs under Strict oversight. BCADS enables vehicles to autonomously generate and manage their identifiers, eliminating reliance on a single centralized authority and mitigating single points of failure by jointly maintaining identity records on a consortium blockchain infrastructure. In addition, BCADS is designed to accommodate regulatory mandates while protecting user privacy and data confidentiality. The scheme addresses key limitations of prior designs by supporting flexible identity management and strong privacy protection within a practical architecture. Security analysis shows that BCADS withstands a broad range of attacks and achieves the desired security properties. Performance measurements and simulation experiments indicate that BCADS reduces computational costs by up to 36.6% and communication costs by up to 87.1%, demonstrating its practicality for deployment in real-world VANETs.
Chang Xu 0004, Liehuang Zhu
IEEE Trans. Dependable Secur. Comput.2
2025 Revocable DSSE in Healthcare Systems With Range Query Support
abstract
With the rapid development of cloud computing, online health monitoring systems are becoming increasingly prevalent. To protect medical data privacy while supporting search operations, Dynamic Searchable Symmetric Encryption (DSSE) technology has been widely used in health monitoring systems. For better monitoring of patient status, keyword range query is also a necessary requirement for the DSSE scheme. Furthermore, in the multi-user setting, user revocation usually leads the owner to download and re-encrypt all indexes, resulting in significant computational overhead. In this paper, we propose a lightweight revocable DSSE scheme with range query support. First, we propose a novel and privacy-preserving range query algorithm that defends plaintext inference attacks. Second, we design a singly linked list structure based on delegatable pseudorandom functions and key-updatable pseudorandom functions, which support lightweight user revocation. Rigorous security analysis proves the security of our proposed range query scheme and demonstrates that our scheme can achieve forward and backward privacy. Experimental evaluations show that our scheme is highly efficient.
Yandong Zheng, Chang Xu 0004, Liehuang Zhu
IEEE Trans. Big Data3
2025 PCSR: Enabling Cross-Modal Semantic Retrieval With Privacy Preservation
abstract
Cross-modal semantic retrieval systems face significant privacy risks due to storing plaintext data on cloud servers. We propose PCSR, a privacy-preserving framework enabling semantic search directly on encrypted high-dimensional data. It consists of three essential modules: a cross-modal encoder, an approximate nearest neighbor (ANN) search algorithm, and an encryption algorithm. Specifically, we utilize CLIP, a deep neural network model, to extract features of images and texts. We design two ANN search methods for high-dimensional feature vectors by utilizing the space partitioning technique and Singular Value Decomposition algorithms, respectively. Furthermore, we employ adapted Random Matrix Multiplication (RMM) for efficient and secure vector similarity computations. Our rigorous security analysis demonstrates that our proposed schemes are secure. We conduct experiments on four datasets and systematically compare the performance of different encrypted retrieval methods. The superior performance validates the feasibility and efficiency of our proposed schemes.
Yandong Zheng, Chang Xu 0004, Liehuang Zhu, Can Zhang 0002
IEEE Trans. Inf. Forensics Secur.3
2025 Enhanced Smart Contract Vulnerability Detection via Graph Neural Networks: Achieving High Accuracy and Efficiency
abstract
As blockchain technology becomes prevalent, smart contracts have shown significant utility in finance and supply chain management. However, vulnerabilities in smart contracts pose serious threats to blockchain security, leading to substantial economic losses. Therefore, developing effective vulnerability detection solutions is urgent. To address this issue, we propose a method for detecting vulnerabilities in smart contracts using graph neural networks (GNNs) that can identify eight common vulnerabilities. Our method is fully automated, applicable to all Ethereum smart contracts, and does not require expert-defined rules or manually defined features. We extract the Control Flow Graph and Abstract Syntax Graph from the smart contract code, which are then processed by a GNN to generate feature vectors for classification. Experiments on a real Ethereum dataset demonstrate that our method significantly outperforms existing state-of-the-art approaches. For individual detection tasks, the combined source code and bytecode method achieves an average accuracy of 95.78%, with a peak of 99.13%, and an average F1 score of 93.80%. Compared to competitors, our method shows an average improvement of 51.92% in accuracy and 47.21% in F1 score. The bytecode-only method achieves an average accuracy of 94.68% and an F1 score of 92.36%. For multi-class tasks, both methods achieve high accuracies of 91.26% and 87.34%, with F1 scores of 97.42% and 96.43%, respectively.
Chang Xu 0004, Huaiyu Xu, Liehuang Zhu, Kashif Sharif
IEEE Trans. Software Eng.1
2024 A Lightweight Privacy-Preserving Asynchronous Federated Learning Scheme in Internet of Vehicles
abstract
The Internet of Vehicles (IoV) facilitates wireless communication and information exchange among vehicles, road infrastructure, and pedestrians, creating a comprehensive network for intelligent vehicle control. Within the IoV framework, numerous computing tasks typically transmitted to the cloud for centralized processing lead to significant latency and substantial cloud computing burdens. To optimize IoV efficiency while safeguarding vehicle data privacy, federated learning (FL) has shown promising potential. However, due to vehicle mobility, FL encounters challenges such as communication bandwidth limitations, varying road conditions, and data transmission delays. Additionally, traditional FL methods do not fully ensure the non-disclosure of user data during aggregation. To address these issues, we propose a lightweight encryption-based asynchronous federated learning scheme (LPAsyFL) for privacy protection in IoV. This scheme supports user participation and withdrawal, ensuring security in honest but curious environments. By utilizing lightweight cryptographic primitives and asynchronous aggregation techniques, we introduce a dynamic aggregation mechanism that reduces communication overhead and enhances model aggregation efficiency. Simulation results on various datasets demonstrate that our approach reduces communication costs and improves aggregation efficiency in the vehicular network.
Chang Xu 0004, Liehuang Zhu, Kashif Sharif
ISPA3
2024 Privacy-Preserving and Robust Federated Learning Based on Secret Sharing
abstract
Federated learning (FL) is a machine learning method that enables model training without centralizing data for integration. However, FL is vulnerable to poisoning attacks, in which an attacker manipulates the malicious clients to corrupt the global model via poisoning their local training data or model updates, resulting in compromised model accuracy and degraded performance. In addition, in FL, although the original data can be trained without leaving the local devices, some attackers can obtain the private information of training participants through model parameters, causing privacy leaks. In order to solve the above problems, we propose a privacy-preserving federated learning robust aggregation scheme based on secret sharing. This scheme is implemented based on secret sharing technology, protecting clients’ data privacy while achieving Byzantine-robust. Moreover, our scheme considers the two situations of honest majority and malicious majority of clients; that is, the model can effectively resist poisoning attacks when the proportion of malicious clients is less than 50% or more than 50%. Extensive experiments show that our scheme is secure against various common poisoning attacks and is more robust than some existing aggregation rules, even when malicious actors account for the majority.
Jiajia Mei, Chang Xu 0004, Liehuang Zhu, Guoxie Jin, Kashif Sharif
ISPA3
2024 Blockchain-Based Lightweight and Privacy-Preserving Quality Assurance Framework in Crowdsensing Systems
abstract
The novel sensing paradigm known as crowdsensing leverages ubiquitous smart devices to collect data in Internet of Things (IoT) applications. Traditional crowdsensing schemes assume a central framework to execute truth discovery algorithm to assure data quality, which may introduce reliability and privacy issues. Blockchain is a promising technology that provides a decentralized, transparent, and immutable platform. However, designing a blockchain-based quality assurance scheme in crowdsensing is not a trivial problem. First, truth discovery is a time-consuming iterative algorithm, which is not practical to execute on blockchain. Second, privacy-preserving schemes always require that the participants join in multiround communications, which is not acceptable in open blockchain because of users’ highly unpredictable behaviors. Finally, on-chain data are publicly accessible, and achieving a good balance between data utility and privacy is an important issue. In this article, we propose a lightweight quality assurance framework atop blockchain to build a reliable, privacy preserving, and fair crowdsensing system. Specifically, we carefully design two kinds of smart contracts to cooperatively maintain a long-term reliable platform to execute crowdsensing tasks. In the contracts, we devise a reputation-based aggregator selection algorithm to reach the consensus on truthful results while avoiding expensive on-chain iterative processes. The participant selection scheme and reward policy are further utilized to filter appropriate participants to complete the task. Our scheme also protects data privacy and does not require communications between participants. Finally, we implement and deploy the contracts on Ethereum and conduct extensive experiments to demonstrate that the contracts can practically execute crowdsensing tasks.
Chang Xu 0004, Liehuang Zhu, Rongxing Lu, Yunguo Guan, Xiaoming Zhang 0001
IEEE Internet Things J.2
2024 EWDPS: A Novel Framework for Early Warning and Detection on Ethereum Phishing Scams
abstract
Ethereum is the second-largest blockchain platform, and the financial value of its cryptocurrency has constantly increased. Unfortunately, regulatory challenges have resulted in a surge of scams, particularly phishing, which now accounts for over 50% of fraudulent funds. Therefore, phishing scam issues have become a top priority, thus calling for dynamic early warning and accurate identification to achieve effective market regulation. However, the existing works focusing on phishing address detection do not consider early warnings for phishing scams. Furthermore, these methods depend on static graphs to extract node information and overlook the dynamic evolution process of the Ethereum network. In this article, we propose EWDPS, a novel framework to achieve dynamic early warning and effectively identify phishing scams on Ethereum. Specifically, we create a new network called the dynamic temporal transaction network (DTTN), which effectively models the dynamic temporal evolution of transactions. In DTTN, we propose the concepts of temporal evolution interaction network and account feature interaction network. Next, we design a novel feature extraction module to capture temporal sequential patterns effectively. This module takes full advantage of the dynamic interaction process of node-related transactions. Finally, we innovatively use the extracted account, network, and temporal features to enhance transaction representation in multiple dimensions. Extensive experiments show that our proposed scheme effectively achieves dynamic early warning and accurately identifies phishing scams. EWDPS achieves 92.20% accuracy, 95.90% precision, 96.77% recall, and 96.53% F1-score, and outperforms the state-of-the-art methods in phishing address identification.
Chang Xu 0004, Rongrong Li, Liehuang Zhu, Kashif Sharif
IEEE Internet Things J.1
2024 Dynamic Fine-Grained SLA Management for 6G eMBB-Plus Slice Using mDNN & Smart Contracts
abstract
The advent of 6G networks promises revolutionary advances in dynamism, intelligence, and decentralization. Realizing the full potential of 6G requires adaptable service level agreements (SLAs) that can optimize performance based on dynamic network conditions. In this paper, we suggested a method based on the Hyperledger Sawtooth blockchain’s smart contract with the Reptile meta-learning algorithm to solve the rigidity of static SLA and centralization problems. In order to sustain the quality of service in the radio access network and core network domain of 6G networks, this work focuses on SLA management for efficient resource allocation for the eMBB-plus slice. Our approach entails breaking down static SLAs into finer-grained components, transferring those components onto Hyperledger Sawtooth smart contracts, and using the Reptile meta-learning algorithm to forecast SLA metrics and resource requirements. A dynamic tariff model, also proposed within the smart contract, handles increased user demands. We evaluate the solution by analyzing Reptile performance, resource allocation, and SLA violations under dynamic demands. Results demonstrate the efficiency of this AI-driven, blockchain-based approach for automated, optimized 6G eMBB-plus resource management adhering to dynamic fine-grained SLAs. This work highlights the synergistic potential of AI and blockchain for trusted and intelligent 6G service delivery.
Sadaf Bukhari, Kashif Sharif, Liehuang Zhu, Chang Xu 0004, Fan Li 0001, Sujit Biswas
IEEE Trans. Serv. Comput.4
2024 A Federated Learning Architecture for Blockchain DDoS Attacks Detection
abstract
The rapid development of blockchain technology has led to a constant increase in its financial and technological value. However, this has also led to malicious attacks. Distributed denial-of-service attacks pose a considerable threat to blockchain technology out of many attacks due to its effectiveness and distributed nature. To protect the blockchain from DDoS attacks, researchers have proposed a large number of defensive schemes. However, these schemes are not well-suited for use in practical situations. In this work, we propose a DDoS attack detection scheme based on centralized federated learning, where multiple participating nodes locally train models and upload them to a central node for aggregation. Additionally, we propose a more suitable method for blockchain scenarios, using decentralized federated learning technology, where multiple nodes exchange models in a peer-to-peer manner to complete model training without a central server. We simulate DDoS attacks in blockchain and generate a large dataset by combining it with traditional network layer DDoS attack data to evaluate the effectiveness of our schemes. The experimental results show that the proposed schemes perform well in classification accuracy, demonstrating that our techniques can detect DDoS attacks effectively.
Chang Xu 0004, Guoxie Jin, Rongxing Lu, Liehuang Zhu, Yunguo Guan, Kashif Sharif
IEEE Trans. Serv. Comput.1
2023 Illegal Accounts Detection on Ethereum Using Heterogeneous Graph Transformer Networks
Chang Xu 0004, Liehuang Zhu, Xiaoming Zhang 0001
ICICS1
2023 How to Find a Bitcoin Mixer: A Dual Ensemble Model for Bitcoin Mixing Service Detection
abstract
Bitcoin is the first decentralized peer-to-peer cryptocurrency that has gained popularity by providing users with transaction anonymity. With the development of Bitcoin and the higher privacy requirements of users, mixing services have emerged to enhance Bitcoin anonymity by obfuscating the flow of funds. However, they are also widely used for illegal activities due to its strong anonymity, especially for money laundering. Therefore, detecting mixing services has great significance for Bitcoin anti-money laundering. In this article, we propose a novel detection scheme to identify the addresses belonging to Bitcoin mixing services. Specifically, we first construct the Bitcoin mixing data set, which summarizes a total of 26 features to describe the transaction behavior of addresses. Next, we design a new classification model, called the Dual Ensemble Classification Model. The model combines the advantages of multiple models based on different algorithms and obtains better classification performance. In order to detect more complex mixing patterns, we also extract transaction subgraphs from the established Bitcoin address-transaction network. The subgraphs are then classified using a kernel-based graph classification method, which is embedded in the model. Comprehensive experiments on three data sets demonstrate the effectiveness of our scheme, and the proposed model has a detection accuracy of 99.84% for the Bitcoin mixing service.
Chang Xu 0004, Ruting Xiong, Liehuang Zhu, Xiaoming Zhang 0001
IEEE Internet Things J.1
2023 EBDL: Effective blockchain-based covert storage channel with dynamic labels
Can Zhang 0002, Liehuang Zhu, Chang Xu 0004, Zijian Zhang 0001, Rongxing Lu
J. Netw. Comput. Appl.3
2023 Privacy-preserving and fault-tolerant aggregation of time-series data without TA
Chang Xu 0004, Run Yin, Liehuang Zhu, Can Zhang 0002, Kashif Sharif
Peer Peer Netw. Appl.1
2023 Efficient Strong Privacy-Preserving Conjunctive Keyword Search Over Encrypted Cloud Data
abstract
Searchable symmetric encryption (SSE) supports keyword search over outsourced symmetrically encrypted data. Dynamic searchable symmetric encryption (DSSE), a variant of SSE, further enables data updating. Most DSSE works with conjunctive keyword search primarily consider forward and backward privacy. Ideally, the server should only learn the result sets involving all keywords in the conjunction. However, existing schemes suffer from keyword pair result pattern (KPRP) leakage, revealing the partial result sets containing two of query keywords. We propose the first DSSE scheme to address aforementioned concerns that achieves strong privacy-preserving conjunctive keyword search. Specifically, our scheme can maintain forward and backward privacy and eliminate KPRP leakage, offering a higher level of security. The search complexity scales with the number of documents stored in the database in several existing schemes. However, the complexity of our scheme scales with the update frequency of the least frequent keyword in the conjunction, which is much smaller than the size of the entire database. Besides, we devise a least frequent keyword acquisition protocol to reduce frequent interactions between clients. Finally, we analyze the security of our scheme and evaluate its performance theoretically and experimentally. The results show that our scheme has strong privacy preservation and efficiency.
Chang Xu 0004, Ruijuan Wang, Liehuang Zhu, Chuan Zhang 0003, Rongxing Lu, Kashif Sharif
IEEE Trans. Big Data1
2023 BSDP: Blockchain-Based Smart Parking for Digital-Twin Empowered Vehicular Sensing Networks With Privacy Protection
abstract
The popularity of vehicles brings parking issues, especially in the downtown area. To tackle these issues, the concept of smart parking is presented, which utilizes industrial Internet of Things (IIoT) devices and vehicular sensor networks (VSNs) to monitor the available parking spaces and nearby traffic conditions. Unfortunately, the centralized architecture of existing solutions cannot guarantee data reliability. Besides, some privacy issues still violate the VSN participants' sensitive information. We propose a novelBlockchain-based smart parking scheme in digital-twin empowered VSNs with privacy protection, named BSDP. In BSDP, the digital twin network is introduced to monitor and predict traffic conditions nearby a parking lot. The blockchain and smart contract are utilized to achieve reliable data storage and correct parking response, respectively. Besides, the privacy of both driver and VSN participants can be protected. Experimental result shows that the proposed BSDP scheme achieves acceptable efficiency in resource-constrained vehicular networks.
Can Zhang 0002, Liehuang Zhu, Chang Xu 0004
IEEE Trans. Ind. Informatics3
2023 Non-Interactive Multi-Client Searchable Symmetric Encryption With Small Client Storage
abstract
Considerable attention has been paid to dynamic searchable symmetric encryption (DSSE) which allows users to search on dynamically updated encrypted databases. To improve the performance of real-world applications, recent non-interactive multi-client DSSE schemes are targeted at avoiding per-query interaction between data owners and data users. However, existing non-interactive multi-client DSSE schemes do not consider forward privacy or backward privacy, making them exposed to leakage abuse attacks. Besides, most existing DSSE schemes with forward and backward privacy rely on keeping a keyword operation counter or an inverted index, resulting in a heavy storage burden on the data owner side. To address these issues, we propose a non-interactive multi-client DSSE scheme with small client storage, and our proposed scheme can provide both forward privacy and backward privacy. Specifically, we first design a lightweight storage chain structure that binds all keywords to a single state to reduce the storage cost. Then, we present a Hidden Key technique, which preserves non-interactive forward privacy through time range queries, ensuring that data with newer timestamps cannot match earlier time ranges. We conduct extensive experiments to validate our methods, which demonstrate computational efficiency. Moreover, security analysis proves the privacy-preserving property of our methods.
Chang Xu 0004, Rongxing Lu, Liehuang Zhu, Chuan Zhang 0003, Yunguo Guan
IEEE Trans. Serv. Comput.2
2023 EPPFM: Efficient and Privacy-Preserving Querying of Electronic Medical Records With Forward Privacy in Multiuser Setting
abstract
With the application of the Internet of Things (IoT) and cloud computing, the eHealthcare industry has developed markedly, attracting many patients to seek medical treatment in an eHealthcare system. However, for patients who first register in the system, due to lack of experience, an important aspect is to choose appropriate medical services. Considering the sensitivity of health care data and the semi-honest nature of the cloud server, it is a good solution to use searchable encryption (SE) to obtain some historical electronic medical records (EMRs) that are consistent with the patient's symptom keyword combination and have high service scores for reference. However, existing SE schemes still have issues meeting the requirements of the eHealthcare system for flexible authorization and revocation, efficiency, and forward privacy. To resolve these issues, we propose two efficient and privacy-preserving electronic medical records query schemes with forward privacy in a multiuser setting (EPPFM). First, we present the basic scheme EPPFM-I to achieve a multiuser multikeyword exact match query under linear search complexity. In EPPFM-I, we also use the pseudorandom function (PRF) to perform the function of forward privacy. Then, we use a bucket structure to construct the improved scheme EPPFM-II, which has a faster-than-linear search complexity. Finally, we use detailed security analysis and extensive simulations to show the security and efficiency of the proposed schemes, respectively.
Chang Xu 0004, Zijian Chan, Liehuang Zhu, Can Zhang 0002, Rongxing Lu, Yunguo Guan
IEEE Trans. Sustain. Comput.1
2023 Non-Interactive DSSE for Medical Data Sharing With Forward and Backward Privacy
abstract
In medical cloud computing, more medical data owners are preferred to outsource their sensitive data to the cloud after encryption. Meanwhile, dynamic searchable symmetric encryption (DSSE) provides the capability for data users to query over the dynamically-updated encrypted database. To reduce update leakage, a secure DSSE scheme usually requires forward and backward privacy. However, existing multi-client DSSE schemes with forward and backward privacy require the data owner to keep online to respond to per-query interaction from data users. To address this issue, we propose a multi-client non-interactive DSSE scheme with forward and backward privacy, namely MCNI. The core design of MCNI is leveraging time range queries to achieve non-interactive forward privacy since the past queries cannot be used to search the newly-added timestamps. To enable efficient time range queries, we convert the timestamp and time range into the boolean wildcard form and develop Boolean Wildcard Matching (BWM) algorithm that formulates the match as a dot product calculation problem. Finally, we combine the polynomial fitting technique, time range query, and random matrix multiplication technique to achieve efficient keyword searches without revealing sensitive information. Theoretical analysis and extensive experiments demonstrate the security and effectiveness of our proposed scheme, respectively.
Chang Xu 0004, Liehuang Zhu, Chuan Zhang 0003, Rongxing Lu, Yunguo Guan, Kashif Sharif
IEEE Trans. Sustain. Comput.2
2022 Privacy-Preserving and Fault-Tolerant Aggregation of Time-Series Data With a Semi-Trusted Authority
abstract
Time-series data aggregation in Internet of Things applications is a useful operation, where the time-series data is sensed by a group of users, and gathered by the aggregator for real-time analysis. However, some security and privacy challenges still affect the collection and aggregation process. Although existing privacy-preserving solutions achieve strong privacy guarantees, they introduce a fully trusted TA that is difficult to realize in the real world. Besides, they cannot be directly applied in time-series data aggregation scenarios due to unacceptable efficiency. In this article, we propose a privacy-preserving time-series data aggregation scheme with a semi-trusted authority. Moreover, our scheme also supports arbitrary aggregate functions and fault tolerance to enhance the reliability and scalability of data aggregation. Security analysis demonstrates that our proposed scheme achieves$(n-k)$-source anonymity even if$k(k\leq (n-2))$data providers collude with the cloud server. We also conduct thorough experiments based on a simulated data aggregation scenario to show the high computation and communication efficiency of our scheme.
Chang Xu 0004, Run Yin, Liehuang Zhu, Chuan Zhang 0003, Can Zhang 0002, Kashif Sharif
IEEE Internet Things J.1
2022 Reliable and Privacy-Preserving Top-k Disease Matching Schemes for E-Healthcare Systems
abstract
The integration of body sensors, cloud computing, and mobile communication technologies has significantly improved the development and availability of e-healthcare systems. In an e-healthcare system, health service providers upload real patients’ clinical data and diagnostic treatments to the cloud server. Afterward, the users can submit queries with specific body sensor parameters, to obtaining pertinent${k}$diagnostic files. The results are ranked based on ranking algorithms that match the query parameters to the ones in diagnostic files. However, privacy concerns arise while matching disease, since the clinical data and diagnostic files contain sensitive information. In this work, we propose two reliable and privacy-preserving Top-${k}$disease matching schemes. The first scheme is constructed based on our proposed weighted Euclidean distance comparison algorithm under secure${k}$-nearest neighbor technique to get${k}$diagnostic files. It allows users to set different weights for each body indicator as per their needs. The second scheme is designed by comparing Euclidean distances under the modified Paillier homomorphic encryption algorithm where a superlinear sequence is used to reduce the computational and communication overhead. The user side incurs slightly higher computational costs, but the trusted party does not need to execute encryption operations. Hence, the proposed two schemes can be applied in different application scenarios. Simulations on synthetic and real data prove the efficiency of the schemes, and security analysis establishes the privacy-preservation properties.
Chang Xu 0004, Liehuang Zhu, Chuan Zhang 0003, Kashif Sharif, Huishu Wu
IEEE Internet Things J.1
2022 EPDL: An efficient and privacy-preserving deep learning for crowdsensing
Chang Xu 0004, Guoxie Jin, Liehuang Zhu, Chuan Zhang 0003
Peer-to-Peer Netw. Appl.1
2022 Location Privacy-Preserving Task Recommendation With Geometric Range Query in Mobile Crowdsensing
abstract
In mobile crowdsensing, location-based task recommendation requires each data requester to submit a task-related geometric range to crowdsensing service providers such that they can match suitable workers within this range. Generally, a trusted server (i.e., database owner) should be deployed to protect location privacy during the process, which is not desirable in practice. In this paper, we propose the location privacy-preserving task recommendation (PPTR) schemes with geometric range query in mobile crowdsensing without the trusted database owner. Specifically, we first propose a PPTR scheme with linear search complexity, named PPTR-L, based on a two-server model. By leveraging techniques of polynomial fitting and randomizable matrix multiplication, PPTR-L enables the service provider to find the workers located in the data requester’s arbitrary geometric query range without disclosing the sensitive location privacy. To further improve query efficiency, we design a novel data structure for task recommendation and propose PPTR-F to achieve faster-than-linear search complexity. Through security analysis, it is shown that our schemes can protect the confidentiality of workers’ locations and data requesters’ queries. Extensive experiments are performed to demonstrate that our schemes can achieve high computational efficiency in terms of geometric range query.
Chuan Zhang 0003, Liehuang Zhu, Chang Xu 0004, Jianbing Ni, Cheng Huang 0001, Xuemin Shen
IEEE Trans. Mob. Comput.3
2022 TDFL: Truth Discovery Based Byzantine Robust Federated Learning
abstract
Federated learning (FL) enables data owners to train a joint global model without sharing private data. However, it is vulnerable to Byzantine attackers that can launch poisoning attacks to destroy model training. Existing defense strategies rely on the additional datasets to train trustable server models or trusted execution environments to mitigate attacks. Besides, these strategies can only tolerate a small number of malicious users or resist a few types of poisoning attacks. To address these challenges, we design a novel federated learning methodTDFL,TruthDiscovery basedFederatedLearning, which can defend against multiple poisoning attacks without additional datasets even when the Byzantine users are$\geq 50\%$. Specifically, the TDFL considers different scenarios with different malicious proportions. For Honest-majority setting (Byzantine$< 50\%$), we design a special robust truth discovery aggregation scheme to remove malicious model updates, which can assign weights according to users’ contribution; for Byzantine-majority setting (Byzantine$\geq 50\%$), we use maximum clique-based filter to guarantee global model quality. To the best of our knowledge, this is the first study that uses truth discovery to defend against poisoning attacks. It is also the first scheme which can achieve strong robustness under multiple kinds of attacks launched by high proportion attackers without root datasets. Extensive comparative experiments are designed with five state-of-the-art aggregation rules under five types of classical poisoning attacks on different datasets. The experimental results demonstrate that TDFL is practical and achieves reasonable Byzantine-robustness.
Chang Xu 0004, Liehuang Zhu, Chuan Zhang 0003, Guoxie Jin, Kashif Sharif
IEEE Trans. Parallel Distributed Syst.1
2022 TPPR: A Trust-Based and Privacy-Preserving Platoon Recommendation Scheme in VANET
abstract
Vehicle platoon, a novel vehicle driving paradigm that organizes a group of vehicles in the nose-to-tail structure, has been considered as a potential solution to reduce traffic congestion and increase travel comfort. In such a platoon system, head vehicles’ performances are usually evaluated by user vehicles’ feedbacks. Selection of an appropriate and reliable head vehicle while not disclosing user vehicles’ privacy has become an interesting problem. In this article, we present a trust-based and privacy-preserving platoon recommendation scheme, called TPPR, to enable potential user vehicles to avoid selecting the malicious head vehicles. The basic concept of TPPR is that each user vehicle holds a trust value, and the reputation score of the head vehicle is calculated via a truth discovery process. To preserve vehicles’ privacy, pseudonyms and Paillier cryptosystem are applied. In addition, novel authentication protocols are designed to ensure that only the valid vehicles (i.e., the vehicles holding the truthful trust values and joining the vehicle platoon) can pass the authentication. A comprehensive security analysis is conducted to prove that the proposed TPPR scheme is secure against several sophisticated attacks in vehicular ad hoc networks. Moreover, extensive simulations are conducted to demonstrate the correctness and effectiveness of the proposed scheme.
Chuan Zhang 0003, Liehuang Zhu, Chang Xu 0004, Kashif Sharif, Kai Ding 0008, Ximeng Liu, Xiaojiang Du, Mohsen Guizani
IEEE Trans. Serv. Comput.3
2022 Dynamic Data Transaction in Crowdsensing Based on Multi-Armed Bandits and Shapley Value
abstract
Crowdsensing gradually forms a big data market where workers are willing to trade reusable data with different data collectors. It is challenging for the data collector to choose the transaction party due to the changeable value of the data, while determining the transaction price is also a tough issue. In this paper, we research the dynamic data transaction in crowdsensing. The contribution of the new data to the collector is modeled as the Shapley value, with each worker as a player in the cooperative game. The data collector then judges the contribution of the worker and determines the transaction object. To maximum the profit in the transaction, the collector will dynamically adjust the offering price to workers. The contextual bandit model is utilized in the price decision, with each candidate price as an arm and the time-variant data value as the context. Based on the classic LinUCB learning policy, we learn the mapping of the observed data value and the reward, and estimate the optimal reward in current transaction. The simulation on the data demonstrates that the actual reward got by the collector is close to the maximum reward he can get, which verifies the effectiveness of our scheme.
Chang Xu 0004, Yayun Si, Liehuang Zhu, Chuan Zhang 0003, Kashif Sharif, Huishu Wu
IEEE Trans. Sustain. Comput.1
2021 V-EPTD: A Verifiable and Efficient Scheme for Privacy-Preserving Truth Discovery
Chang Xu 0004, Hongzhou Rao, Liehuang Zhu, Chuan Zhang 0003, Kashif Sharif
ICA3PP (3)1
2021 Achieving Efficient and Privacy-preserving Biometric Identification in Cloud Computing
abstract
Biometrics identification has been used in a growing number of fields in recent years, since it is more secure, classified and convenient. With the development of cloud computing, database systems are able to upload large amounts of biometric data to cloud server for storage and identification to save local memory and improve computational efficiency. However, this involves potential privacy concerns because of the introduction of third-party platforms. In this paper, we achieve computational and communication efficiency in biometric identification, while preserving the privacy of data. Specifically, the database system firstly encrypts all biometric data and query data. Then, it sends the ciphertext to a cloud server to carry out matching tasks. Finally, the cloud server returns the index of final matches to the system so that it can check whether the biometric vector is legal or not. Detailed security analysis indicates that the proposed scheme can resist powerful attacks. Beyond that, Experiments show that the scheme is more efficient in computation and communication than stat of art biometric identification schemes.
Chang Xu 0004, Lvhan Zhang, Liehuang Zhu, Chuan Zhang 0003, Kashif Sharif
TrustCom1
2021 Blockchain-Based Verifiable DSSE with Forward Security in Multi-server Environments
Chang Xu 0004, Lan Yu, Liehuang Zhu, Can Zhang 0002
WASA (3)1
2021 Exploring active attacks for three incorrect implementations of the ISO/IEC 9798 in satellite networks
Zhengjia Zhu, Zijian Zhang 0001, Tielei Li, Jiamou Liu, Bakhadyr Khoussainov, Chang Xu 0004
Comput. Commun.7
2021 Enabling privacy-preserving multi-level attribute based medical service recommendation in eHealthcare systems
Chang Xu 0004, Jiachen Wang 0006, Liehuang Zhu, Kashif Sharif, Chuan Zhang 0003, Can Zhang 0002
Peer-to-Peer Netw. Appl.1
2021 A blockchain-based dynamic searchable symmetric encryption scheme under multiple clouds
Chang Xu 0004, Lan Yu, Liehuang Zhu, Can Zhang 0002
Peer-to-Peer Netw. Appl.1
2021 Reliable and Privacy-Preserving Truth Discovery for Mobile Crowdsensing Systems
abstract
Truth discovery has received considerable attention in mobile crowdsensing systems. In real practice, it is vital to resolve conflicts among a large amount of sensory data and estimate the truthful information. Although truth discovery has been widely explored to improve aggregation accuracy, numerous security and privacy issues still need to be addressed. Existing schemes either do not guarantee the privacy of each participating user, or fail to consider practical needs in crowdsensing systems. In this paper, we present two reliable and privacy-preserving truth discovery schemes for different scenarios. Our first design is fit for applications where users are relatively stable. By employing the homomorphic Paillier encryption, one-way hash chain, and super-increasing sequence techniques, this approach not only guarantees strong privacy, but also is highly efficient and practical. Our second design suits applications where users are frequently moving. In such an application, we explore data perturbation and homomorphic Paillier encryption to shift all user workloads to the server side, without compromising users' privacy. Through detailed security analysis, we demonstrate that both schemes are secure, practical, and privacy-preserving. Moreover, extensive experiments based on real world and simulated mobile crowdsensing systems, we demonstrate the efficiency of our proposed schemes.
Chuan Zhang 0003, Liehuang Zhu, Chang Xu 0004, Ximeng Liu, Kashif Sharif
IEEE Trans. Dependable Secur. Comput.3
2020 A Privacy-Preserving Location-Aware and Traffic Order-Based Route Collection Scheme in VANETs
abstract
Collecting driving routes is effective in predicting traffic patterns and alleviating traffic jams. However, due to the sensitivity of the location information, drivers are usually reluctant to share their route information. Although some efforts have been made to address this challenge, most of them either do not consider traffic order issues or fall short of achieving practical efficiency. In this paper, we propose an efficient and privacy-preserving route collection scheme, named EPRC, to solve the above-mentioned problems. The main idea of EPRC is to perform location-aware and traffic order-based route aggregation on drivers' encrypted data using super-increasing sequences and a homomorphic encryption cryptosystem. The proposed scheme achieves better computation and communication efficiency by reducing computational complexity and communication overhead from O(M) to O(1), where M denotes the number of road segments. Security analysis demonstrates the privacy of an individual driver's route is preserved under standard cryptographic assumptions. Performance evaluations via implementing EPRC on mobile devices and systems show EPRC's efficiency in terms of computation and communication costs.
Chuan Zhang 0003, Liehuang Zhu, Chang Xu 0004, Kashif Sharif
GLOBECOM3
2020 Efficient and Privacy-Preserving Non-Interactive Truth Discovery for Mobile Crowdsensing
abstract
Truth discovery is one of the key technologies to extract truthful information from unreliable sensory data collected by different mobile devices in mobile crowdsensing, but the sensory data and the outputs of truth discovery (i.e., truths and mobile devices' weights) may contain sensitive information and cause serious privacy concerns. In this paper, we propose an efficient and privacy-preServing non-interActive Truth discovEry scheme (SATE) in mobile crowdsensing. Specifically, SATE is designed based on a two-cloud model. First, the sensory data is encoded into two parts (i.e., perturbed data and noises) at the mobile device, which are maintained by two clouds separately. Second, by utilizing an adapted distributed public key homomorphic cryptosystem, two clouds can co-operatively exchange the intermediate weights and truths in a privacy preserving manner and thus achieve privacy-preserving truth discovery without the participation of the mobile devices. Security analysis demonstrates that SATE can provide full privacy protection for sensory data, weights, and truths. Performance evaluation also shows that SATE can achieve high computational efficiency and low communication overhead on the mobile devices, since there is no time-consuming cryptographic operation involved.
Chuan Zhang 0003, Liehuang Zhu, Chang Xu 0004, Jianbing Ni, Cheng Huang 0001, Xuemin Shen
GLOBECOM3
2020 PPLS: a privacy-preserving location-sharing scheme in mobile online social networks
Chang Xu 0004, Liehuang Zhu, Kashif Sharif, Chuan Zhang 0003, Xiaojiang Du, Mohsen Guizani
Sci. China Inf. Sci.1
2020 An efficient and privacy-preserving truth discovery scheme in crowdsensing applications
Chuan Zhang 0003, Chang Xu 0004, Liehuang Zhu, Can Zhang 0002, Huishu Wu
Comput. Secur.2
2020 Aggregate in my way: Privacy-preserving data aggregation without trusted authority in ICN
Chang Xu 0004, Lvhan Zhang, Liehuang Zhu, Chuan Zhang 0003, Xiaojiang Du, Mohsen Guizani, Kashif Sharif
Future Gener. Comput. Syst.1
2020 T-CAM: Time-based content access control mechanism for ICN subscription systems
Liehuang Zhu, Nassoro M. R. Lwamo, Kashif Sharif, Chang Xu 0004, Xiaojiang Du, Mohsen Guizani, Fan Li 0001
Future Gener. Comput. Syst.4
2020 A privacy-preserving data aggregation scheme for dynamic groups in fog computing
Liehuang Zhu, Chang Xu 0004, Kashif Sharif, Rongxing Lu
Inf. Sci.3
2020 PGAS: Privacy-preserving graph encryption for accurate constrained shortest distance queries
Can Zhang 0002, Liehuang Zhu, Chang Xu 0004, Kashif Sharif, Chuan Zhang 0003, Ximeng Liu
Inf. Sci.3
2019 LPTD: Achieving lightweight and privacy-preserving truth discovery in CIoT
Chuan Zhang 0003, Liehuang Zhu, Chang Xu 0004, Kashif Sharif, Xiaojiang Du, Mohsen Guizani
Future Gener. Comput. Syst.3
2019 Pay as How You Behave: A Truthful Incentive Mechanism for Mobile Crowdsensing
abstract
Mobile crowdsensing (MCS) is widely applied in large-scale distributed networks for collecting sensing data from workers. In an MCS system, workers are recruited to complete tasks for data requesters, and they will get profits. Accordingly, how to establish an effective incentive mechanism has become an important issue to consider. Since workers are naturally selfish, they try to maximize individual benefits while minimize costs. In this article, we propose a truthful incentive mechanism which pays for the workers by the workers' performance in the task just completed and the reputation. For each worker, through the future prediction function, we get the reputation of the worker by utilizing the previous performances. In the proposed scheme, partial payment for the workers is distributed depending on workers' reputation. The final payment is based on punishments and rewards according to the performances. Moreover, data accuracy and response time are introduced to evaluate the worker performance in the task. It can be demonstrated that the mechanism provides continuous incentives to workers compared to the single ex-ante and ex-post pricing schemes. The experimental results show that our mechanism is effective.
Chang Xu 0004, Yayun Si, Liehuang Zhu, Chuan Zhang 0003, Kashif Sharif, Can Zhang 0002
IEEE Internet Things J.1
2019 Achieving Searchable and Privacy-Preserving Data Sharing for Cloud-Assisted E-Healthcare System
abstract
The integration of wearable wireless devices and cloud computing in e-health systems has significantly improved their effectiveness and availability. Patients can upload their personal health information (PHI) files to the cloud, from where the health service providers (HSPs) can obtain appropriate information to determine the health state. This system not only reduces the costs associated to healthcare but also provides timely diagnosis to save lives. However, a number of privacy concerns arise while sharing sensitive information. In this paper, we propose a novel privacy-preserving patient health information sharing scheme, which allows HSPs to access and search PHI files in a secure yet efficient manner. We make use of the searchable encryption technique with keyword range search and multikeyword search. The proposed privacy-preserving equality test protocol allows different types of numeric comparison searches on encrypted data. We also use a variant of bloom filter and message authentication code to classify PHI files, filter false data, and check integrity of search results. The simulations on real-world and synthetic data show the feasibility and efficiency of the system, and security analysis proves the privacy-preservation properties.
Chang Xu 0004, Liehuang Zhu, Kashif Sharif, Chuan Zhang 0003
IEEE Internet Things J.1
2019 PPMR: A Privacy-Preserving Online Medical Service Recommendation Scheme in eHealthcare System
abstract
With the continuous development of eHealthcare systems, medical service recommendation has received great attention. However, although it can recommend doctors to users, there are still challenges in ensuring the accuracy and privacy of recommendation. In this paper, to ensure the accuracy of the recommendation, we consider doctors' reputation scores and similarities between users' demands and doctors' information as the basis of the medical service recommendation. The doctors' reputation scores are measured by multiple feedbacks from users. We propose two concrete algorithms to compute the similarity and the reputation scores in a privacy-preserving way based on the modified Paillier cryptosystem, truth discovery technology, and the Dirichlet distribution. Detailed security analysis is given to show its security prosperities. In addition, extensive experiments demonstrate the efficiency in terms of computational time for truth discovery and recommendation process.
Chang Xu 0004, Jiachen Wang 0006, Liehuang Zhu, Chuan Zhang 0003, Kashif Sharif
IEEE Internet Things J.1
2019 SUAA: A Secure User Authentication Scheme with Anonymity for the Single & Multi-server Environments
Nassoro M. R. Lwamo, Liehuang Zhu, Chang Xu 0004, Kashif Sharif, Ximeng Liu, Chuan Zhang 0003
Inf. Sci.3
2019 PPTDS: A privacy-preserving truth discovery scheme in crowd sensing systems
Chuan Zhang 0003, Liehuang Zhu, Chang Xu 0004, Kashif Sharif, Ximeng Liu
Inf. Sci.3
2018 PPDP: An efficient and privacy-preserving disease prediction scheme in cloud-based e-Healthcare system
Chuan Zhang 0003, Liehuang Zhu, Chang Xu 0004, Rongxing Lu
Future Gener. Comput. Syst.3
2018 PRIF: A Privacy-Preserving Interest-Based Forwarding Scheme for Social Internet of Vehicles
abstract
Recent advances in socially aware networks (SANs) have allowed its use in many domains, out of which the Social Internet of Vehicles (SIOV) is of prime importance. SANs can provide a promising routing and forwarding paradigm for SIOV by using interest-based communication. Though able to improve the forwarding performance, existing interest-based schemes fail to consider the important issue of protecting users' interest information. In this paper, we propose a privacy-preserving interest-based forwarding scheme (PRIF) for SIOV, which not only protects the interest information but also improves the forwarding performance. We propose a privacy-preserving authentication protocol to recognize communities among mobile nodes. During data routing and forwarding, a node can know others' interests only if they are affiliated with the same community. Moreover, to improve forwarding performance, a new metric community energy is introduced to indicate vehicular social proximity. Community energy is generated when two nodes encounter one another and information is shared among them. PRIF considers this energy metric to select forwarders toward the destination node or the destination community. Security analysis indicates PRIF can protect nodes' interest information. In addition, extensive simulations have been conducted to demonstrate that PRIF outperforms the existing algorithms, including the BEEINFO, Epidemic, and PRoPHET.
Liehuang Zhu, Chuan Zhang 0003, Chang Xu 0004, Xiaojiang Du, Rixin Xu, Kashif Sharif, Mohsen Guizani
IEEE Internet Things J.3
2017 PTBI: An efficient privacy-preserving biometric identification based on perturbed term in the cloud
Chuan Zhang 0003, Liehuang Zhu, Chang Xu 0004
Inf. Sci.3
2016 A universal method for realizing non-repudiable provable data possession in cloud storage
abstract
Abstract Provable data possession (PDP) and proofs of retrievability (POR) are techniques for a client to verify the integrity of outsourced data on an untrusted server, and numerous PDP/POR schemes with public or private verification have been proposed so far. However, existing schemes cannot handle the following issue satisfactorily: Driven by profits, a malicious client may accuse an honest server and repudiate the correct proof of data possession. Based on the commitment function, we present a universal method that can reform any private verification PDP/POR scheme into a non‐repudiable PDP (NRPDP)/POR scheme. As a case study, we propose a concrete NRPDP scheme with private verification, which allows both the client and the server to prove their innocence and verify whether the other side is honest. Moreover, we prove the security of both the method and NRPDP in the random oracle model and implement a prototype based on the NRPDP scheme in a realistic cloud platform. Experimental results on large dataset (10GB) show that the NRPDP can be executed efficiently as private verification schemes and outperforms the public schemes more than 60% in terms of verification time. Foremost, non‐repudiation can be guaranteed efficaciously in NRPDP. Copyright © 2016 John Wiley & Sons, Ltd.
Liehuang Zhu, Chang Xu 0004, Yijia Lilong
Secur. Commun. Networks3
2015 One-Round Affiliation-Hiding Authenticated Asymmetric Group Key Agreement with Semi-trusted Group Authority
abstract
Affiliation-Hiding Authenticated Asymmetric Group Key Agreement (AH-AAGKA) protocol can be utilized by the members of a group to authenticate each other secretly. The participants affiliated to the group can execute the AH-AAGKA protocol to establish a common encryption key. Any legitimate participant can compute its own decryption key corresponding to the encryption key. Particularly, every legitimate player's affiliation information is only revealed to other legitimate players. In this paper, we present a one-round AH-AAGKA protocol. Compared with previous work, in our protocol, Group Authority (GA) does not need to be fully trusted (we call it semi-trusted). Therefore, GA cannot impersonate any honest user to execute the protocol. Meanwhile, GA can trace group members through analyzing the communication flows. Our protocol holds the affiliation-hiding property and detectability. Additionally, our scheme exhibits Perfect Forward Secrecy for both GA and outside attackers.
Chang Xu 0004, Liehuang Zhu, Zhoujun Li 0001
Comput. J.1
2015 Transferable conditional e-cash with optimal anonymity in the standard model
abstract
Transferable conditional electronic‐cash (e‐cash) allows the recipient of a coin in a transaction to transfer it in a later payment transaction to the third person based on the outcome not known in advance. Anonymity is a very important property for a transferable conditional e‐cash. However, none of the existed transferable conditional e‐cash achieve the optimal anonymity because of its special structure, that is, introducing transferability in the conditional e‐cash. In this study, they novelly present a transferable conditional e‐cash scheme using a totally different structure, that is, adding condition into the transferable e‐cash. Thanks to employing Groth–Sahai proofs systems and commuting signatures, the new transferable conditional e‐cash satisfies optimal anonymity. Accordingly, they present an extended security model by introducing a publisher who is responsible for publishing two outcomes of a condition. Then, they prove the new scheme's security in the standard model. Compared with the existing transferable conditional e‐cash, the efficiency of the new scheme is also improved since the size of the computation and communication is constant.
Jiangxiao Zhang, Hua Guo 0001, Zhoujun Li 0001, Chang Xu 0004
IET Inf. Secur.4
2014 Affiliation-Hiding Authenticated Asymmetric Group Key Agreement Based on Short Signature
abstract
The notion of Affiliation-Hiding Authenticated Group Key Agreement (AH-AGKA) protocols was first introduced by Jarecki et al. in CT-RSA 2007, where they presented two concrete AH-AGKA protocols. In this paper, we show that Jarecki et al.'s second protocol has some drawbacks. We propose a new affiliation-hiding protocol. Differing from Jarecki et al.'s protocol, our protocol is asymmetric. Compared with existing AH-AGKA protocols, our scheme not only exhibits the affiliation-hiding property, but also holds the properties of detectability and perfect forward secrecy.
Chang Xu 0004, Hua Guo 0001, Zhoujun Li 0001, Yi Mu 0001
Comput. J.1
2013 Efficient and dynamic key management for multiple identities in identity-based systems
Hua Guo 0001, Chang Xu 0004, Zhoujun Li 0001, Yi Mu 0001
Inf. Sci.2
2013 New construction of affiliation-hiding authenticated group key agreement
abstract
ABSTRACT In CT‐RSA 2007, Jarecki, Kim, and Tsudik introduced the notion of affiliation‐hiding authenticated group key agreement (AH‐AGKA) protocols and presented two concrete AH‐AGKA protocols. In this paper, we will show that these protocols have some drawbacks. We will also introduce the notion of affiliation‐hiding authenticated asymmetric group key agreement (AH‐AAGKA) and present an AH‐AAGKA protocol. AH‐AAGKA protocols allow the participants of a group to establish a common encryption key associated with several decryption keys; each of which can only be computed by the corresponding legitimate participant. Meanwhile, any party is assured that its affiliation is revealed to the participants that belong to the same group only. Compared with previous AH‐AGKA protocols, if invalid players participate in our protocol, legitimate participants can identify these invalid players. In contrast to existing AH‐AGKA protocols, our protocol holds perfect forward secrecy, which is proven in a novel security model we proposed. Additionally, we present a new privacy model to prove that our protocol achieves linkable affiliation‐hiding property. Copyright © 2012 John Wiley & Sons, Ltd.
Chang Xu 0004, Hua Guo 0001, Zhoujun Li 0001, Yi Mu 0001
Secur. Commun. Networks1
2012 Affiliation-Hiding Authenticated Asymmetric Group Key Agreement
abstract
We introduce the concept of Affiliation-Hiding Authenticated Asymmetric Group Key Agreement (AH-AAGKA) and construct a concrete one-round AH-AAGKA protocol. An AH-AAGKA protocol allows the participants of a group to establish a common encryption key associated with several decryption keys; each of which can only be computed by the corresponding legitimate group member. An AH-AAGKA protocol has the following privacy feature. For a member 𝒰i of a group G, if 𝒰i participates in an AH-AAGKA protocol, any protocol participant 𝒰j cannot learn whether 𝒰i is a member of G, unless 𝒰j himself is a member of group G. Our scheme demonstrates new features in comparison with other existing AH-AGKA protocols. If non-group members participate in our protocol, honest parties can identify these non-group members. Our scheme also captures Unlinkability and Perfect Forward Secrecy (PFS), which are missing in other existing schemes. We propose a novel security model to prove that our protocol holds PFS and present a new privacy model to prove that our scheme meets Affiliation-Hiding property.
Chang Xu 0004, Zhoujun Li 0001, Yi Mu 0001, Hua Guo 0001
Comput. J.1