EDBT 2026 Demo / reviewers in the wild / expert
Futai Zhang
dblp:99/1384
· DBLP profile ↗
63ranked-venue papers
2as first author
25since 2021 · last 2026
0000-0001-8984-1030ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 26 · 1 first-author · 10 since 2021Computer networks · 13 · 10 since 2021Databases, data management, data science and information retrieval · 8 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 8 · 3 since 2021Software engineering, systems software and programming languages · 2 · 2 since 2021Theory of computation · 2Systems, architecture and hardware · 1Human-computer interaction and ubiquitous computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Forward-Secure Identity-Based Signcryption With Equality Test for Social Recommendation on Smart IoT DevicesabstractWith the deep integration of smart IoT devices with social networks, platforms use user-interest similarity for social recommendations to connect like-minded people. Identity-based encryption with equality test (IBEET) enables equivalence testing of interest ciphertexts encrypted under different public keys and avoids costly certificate management. It is beneficial for privacy-preserving social recommendations on smart IoT devices. Nevertheless, existing IBEET schemes suffer from two critical flaws: the lack of forward security allows historical trapdoor holders to test newly generated ciphertexts, and the absence of ciphertext origin authentication impedes the legality verification of the ciphertext source. In this paper, taking into account IoT-device features like limited resources, we introduce a forward secure identity-based signcryption scheme with equality test enabling public verification (FS-IBSCET-PV) for social recommendation. It enables the platforms to leverage users’ trapdoors to perform equality tests on interest ciphertexts, accurately matching users who share common interests. Meanwhile, users can submit time-limited authorized trapdoors when needing recommendation services, thus effectively reducing the risk of trapdoor misuse. Furthermore, upon receiving recommendation results, users can publicly verify their origin without extra decryption to ensure the authenticity of the recommendations, consequently mitigating the hardware overhead. Security analysis and simulation experiments show that FS-IBSCET-PV has enhanced functionality and better testing efficiency than related schemes. It provides a secure and practical solution for privacy-preserving social recommendations on resource-limited smart IoT devices. Wenjie Yang 0001, Qunhao Ou, Futai Zhang, Anjia Yang |
IEEE Internet Things J. | 4 |
| 2026 | Practical Certificateless Aggregate Signcryption With Public Verification for IoMTabstractIn the Internet of Medical Things (IoMT), ensuring the confidentiality, integrity, and authenticity of sensitive medical data poses a significant challenge. Signcryption, merging digital signature and public-key encryption into one logical step, offers a promising solution for such resource-constrained networks. Most existing signcryption schemes inherently lack public verification, which prevents third parties (such as routers) from early identifying illegal messages without decryption. In this paper, we propose a practical certificateless aggregate signcryption scheme with public verification for IoMT. Our design uses elliptic curves and follows the certificateless cryptosystem framework. Thus, it not only avoids time-consuming pairing operations but also addresses the issues of certificate management and key escrow. Meanwhile, individual signcryptions can be compressed into a single aggregate signcryption, optimizing computational and communication overheads. Furthermore, both the pre-aggregated and aggregated signcryptions support public verification, effectively enabling the early elimination of illegal messages. We further present formal security proofs for our construction and reduce its security to the hardness of the one-sided gap Diffie-Hellman (OGDH) and the elliptic curve discrete logarithm (ECDL) problems. Performance analysis reveals that, compared with prior studies, this scheme preemptively blocks illegal message spread, reduces receiving-end load, and better suits resource-constrained IoMT. Wenjie Yang 0001, Tao Li 0043, Futai Zhang, Zhiquan Liu 0001 |
IEEE Internet Things J. | 3 |
| 2026 | Efficient Certificate-Based Authentication for Privacy-Preserving Federated Learning in IIoTabstractIn the Federated Learning (FL) paradigm, authentication mechanisms serve as a critical safeguard by preventing unauthorized entities from joining the training process, thereby ensuring the security of both models and data. However, many existing FL authentication schemes have issues regarding security or efficiency. In this paper, we propose a novel pairing-free certificate-based signature scheme and deploy it in the context of privacy-preserving FL. At its core, the proposed scheme is rooted in an elliptic curve certificate-based cryptosystem, which ensures gradient unforgeability without relying on secure channels for key distribution. Additionally, it incorporates a pseudonym-based framework that guarantees participant anonymity during model training while enabling publicly verifiable traceability. Meanwhile, it integrates a dynamic participant management strategy that combines similarity-based quality assessment with a dynamic reputation evaluation to optimize collaborative effectiveness. Performance evaluations show that our proposed scheme reduces signature-related overhead and achieves superior model performance, outperforming existing privacy-preserving FL authentication schemes in communication and computational efficiency. Wenjie Yang 0001, Xinjie Zheng, Futai Zhang |
IEEE Internet Things J. | 3 |
| 2026 | IIoT Data Sharing: CP-A$\!^{2}$2BE With Outsourced Decryption and Verifiable RevocationabstractWith the rapid development of Industrial Internet of Things (IIoT), data sharing as a cornerstone function of IIoT, has attracted considerable attention. Ciphertext-policy attribute-based encryption is extensively used to ensure confidentiality and fine-grained access control in such scenarios. Nevertheless, most existing schemes face critical challenges, including high decryption overhead, inadequate attribute privacy protection, and the absence of verifiable revocation mechanisms, which significantly impede their applications in industrial manufacturing systems. To address these challenges, this paper introduces a ciphertext-policy anonymous attribute-based encryption (CP-A$^{2}$BE) scheme with outsourced decryption and verifiable revocation. It encompasses three key innovations: Firstly, a distributed edge computing architecture is established, leveraging pre-deployed edge nodes within factories to offer outsourced decryption services. Secondly, while safeguarding the privacy of industrial data, the attribute privacy of devices and personnel is also taken into consideration. Thirdly, a verifiable revocation mechanism employing commitment-based techniques is presented to enable real-time access control updates while ensuring the data integrity of revocation operations performed by cloud servers. Experimental evaluation shows that our proposed scheme is practical for data sharing in resource-limited IIoT, especially as the decryption time consistently remains at 26 milliseconds, regardless of the number of attributes involved. Wenjie Yang 0001, Futai Zhang, Shengmin Xu, Zhiquan Liu 0001 |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2026 | Dual-Server Public-Key Authenticated Searchable Encryption With Constant Trapdoor Against Inside Keyword Guessing AttacksabstractPublic key authenticated encryption with keyword search (PAEKS) is an advanced asymmetric searchable encryption technique that provides strong resistance against inside keyword guessing attacks (KGAs). However, most PAEKS schemes are limited to one-to-one search, resulting in a linear increase in the number of trapdoors as the number of senders grows. Some solutions have been introduced, but they are still deficient in security or privacy. In this paper, we propose a novel dual-server public key authenticated searchable encryption scheme with constant trapdoor. The proposed scheme achieves robust security against inside KGAs even if a malicious server is allowed to collude with certain data senders. Meanwhile, in contrast to existing schemes, it prevents the leakage of keyword equivalence among unretrieved ciphertexts. Moreover, the data receiver in our system only needs to create one trapdoor per keyword to search for their ciphertexts produced by different data senders, which is not achievable in most prior works. The experimental results demonstrate that our proposed construction maintains comparable performance to existing solutions, especially in multi-sender scenarios. Wenjie Yang 0001, Shujie Lin, Futai Zhang, Anjia Yang |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2026 | Forward Secure Identity-Based Encryption With Equality Test for Privacy-Preserving Friendship Recommendation on Social PlatformsabstractOn social platforms, the friendship recommendation models deployed suggest potential friends based on the similarities among users. As privacy concerns rise, more users choose to encrypt their attributes before requesting recommendation services. Identity-based encryption with equality test (IBEET) supports encrypted data comparison under different users' identities (public keys) and avoids the need for costly certificate management. This makes it highly suitable for implementing privacy-preserving friendship recommendation on social platforms. Nevertheless, most existing IBEET schemes lack the ability to control the validity period of trapdoors used for testing. Historical trapdoors may be maliciously utilized to test encrypted data generated in the future. To address this issue, we propose a forward secure identity-based encryption with equality test for friendship recommendation. Our construction enables an authorized tester to provide privacy-preserving recommendations based on encrypted data among different users. Furthermore, to control the tester's testing capability, time slots are encoded by the 0/1-encoding mechanism and embedded into both ciphertexts and trapdoors. This ensures that only the authorized tester possessing valid trapdoors can perform tests on specific ciphertexts. Under the bilinear Diffie-Hellman assumption in the random oracle model, we prove that the proposed IBEET achieves OW-ID-CCA security when the attacker has access to the trapdoor and IND-ID-CCA security when the attacker does not. Experiment simulation demonstrates that our construction outperforms existing ones in overall performance, particularly in testing that requires frequent execution for recommendation. Wenjie Yang 0001, Futai Zhang, Anjia Yang |
IEEE Trans. Mob. Comput. | 3 |
| 2025 | Certificate-Based Quasi-linearly Homomorphic Signatures: Definition, Construction, and Application to Data Integrity Auditing
Jintao Cai, Futai Zhang, Wenjie Yang 0001, Shao-Jun Yang, Yichi Huang, Rongmao Chen, Willy Susilo |
ICICS (1) | 2 |
| 2025 | Block Tag Updatable Certificate-Based Integrity Auditing for Long-Term Cloud StorageabstractCloud auditing enables remote data integrity verification without downloading the entire dataset, significantly advancing cloud storage services. In long-term usage scenarios, key exposure poses a critical challenge, as a compromised private key enables the cloud service provider (CSP) to forge tags for incorrect data. Although key updatable auditing protocols have been proposed to mitigate key exposure risks, most do not support tag updates triggered by key changes, allowing the CSP to still exploit the leaked historical key for tag forgery. In this article, we propose a block tag updatable certificate-based integrity auditing protocol for long-term cloud storage. By leveraging certificate-based cryptography, our protocol eliminates the need for costly secure channels. It supports simultaneous key and tag updates, ensuring that even with previous private key leaks, the CSP cannot forge valid tags under newly updated key-pairs. The protocol achieves high efficiency through: 1) 2-D data partitioning that reduces computational and storage overhead; 2) optimized tag generation requiring only one map-to-point hash function operation for multiple data blocks; 3) strategic delegation of computationally intensive tag update operations to the CSP; and 4) constant-time proof verification regardless of the number of challenged blocks. Security proofs and performance evaluations demonstrate that the protocol offers desirable security and efficiency, making it well-suited for long-term cloud storage. Jintao Cai, Futai Zhang, Wenjie Yang 0001, Shao-Jun Yang |
IEEE Internet Things J. | 2 |
| 2025 | Secure Pairing-Free Certificate-Based Online/Offline Signcryption Scheme With Conditional Privacy Preserving for VANETsabstractIn vehicular ad hoc networks (VANETs), the core feature lies in the secure and prompt exchange of information between vehicles. To further enhance this feature, many signcryption schemes adopted to VANETs are proposed. However, most existing schemes still suffer from security or efficiency drawbacks. In this article, we propose a pairing-free certificate-based online/offline signcryption scheme constructed by elliptic curve, aiming to make the communication system of VANETs more lightweight and more secure. It not only ensures data confidentiality and unforgeability within one logic step but also eliminates the need of secure channels for key distribution. When deployed in VANETs, it can precompute many intricate operations in the offline phase and support batch verification of multiple messages. Moreover, our deployment provides pseudonym-based conditional privacy preserving for vehicles and its traceability results about malicious behaviors can be publicly verified, guaranteeing accountability. It also considers common attacks involved in VANETs, including but not limited to impersonation attacks, collusion attacks, and man-in-the-middle attacks. These advantages of our construction make it highly practical for VANETs, which have been demonstrated in our simulation experiments. Wenjie Yang 0001, Peiwei Cao, Futai Zhang, Zhiquan Liu 0001 |
IEEE Internet Things J. | 3 |
| 2025 | An Efficient Revocable Identity-Based Aggregate Signature Scheme With Designated Verifiers in Healthcare Wireless Sensor NetworksabstractIn healthcare wireless sensor networks (HWSNs), a process of medical diagnosis heavily relies on the medical data collected by lightweight sensors, as any malicious modification may result in severe consequences. Furthermore, large-scale data transmission in HWSNs would impose significant communication overhead. Therefore, efficiently guaranteeing the availability of these data while reducing the communication cost is crucial in HWSNs. Aggregate signatures suit the resource-limited environments, but existing ones still face several challenges, including vulnerability to coalition attacks, privacy preservation, and revocation of misbehaving signers. In this paper, we propose an efficient revocable identity-based aggregate signature scheme with designated verifiers (R-IBAS-DV) for HWSNs. In our proposed scheme, numerous individual signatures on the collected medical data can be aggregated into a succinct aggregate signature and their validity is equivalent to that of the aggregate signature. The equivalence property of our proposed scheme is sound even under coalition attacks and exclusively verifiable by designated healthcare professionals. Meanwhile, our proposed scheme is rooted in Hess’s practical identity-based signature, thereby circumventing costly certificate management. Additionally, it incorporates RSA accumulators to facilitate the efficient revocation of malicious signers. Security analysis and performance comparisons demonstrate that our R-IBAS-DV scheme offers enhanced security and lower computation overhead, making it particularly suitable for resource-constrained HWSNs. Wenjie Yang 0001, Junzhe Fan, Futai Zhang, Anjia Yang, Zhiquan Liu 0001 |
IEEE Internet Things J. | 3 |
| 2025 | Efficient Attribute-Based Searchable Encryption With Policy Hiding Over Personal Health RecordsabstractDue to the introduction of cloud computing in healthcare services, personal health records (PHRs) have being uploaded to cloud servers in increasing numbers. Since data confidentiality requirements exist, data owners should encrypt their PHRs in advance of transmitting them to a cloud server. Attribute-based encryption with keyword search (ABKS) technique ensures that the encrypted PHRs are able to retrieved by other data users whose attributes match access polices granted by data owners. However, access polices are public in most existing ABKS schemes, which can reveal sensitive information contained in PHRs. In this article, we provide an efficient ABKS scheme with policy hiding for PHRs that implements the following features. (1) The fine-grained access control is achieved where data owners can authorize which data users can retrieve encrypted PHRs. (2) The access policy is hidden to safeguard sensitive information from being leaked. (3) The costs of storage and computation do not grow linearly as the number of attributes increases. The security of the presented ABKS scheme is reduced to the truncated$q$-DABDHE assumption and the DDH assumption. Its performance is also demonstrated by our extensive simulation experiments. Wenjie Yang 0001, Futai Zhang, Jianting Ning |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2025 | Theory and Applications of Sequentially Threshold Public-Key Cryptography: Practical Private Key Safeguarding and Secure Use for Individual UsersabstractMotivated by the needs of power distribution as well as private key protection, the theory and implementation techniques of threshold public-key cryptography (PKC) have been being developed for a long time. However, researches in this field mainly focus on the needs and constraints in distributed environments which consist of nodes with computing capabilities and connected via peer-to-peer and broadcasting communication channels. The resulting schemes are theoretically helpful for private key security but inconvenient for individual users as their implementation requires distributed computing and networking system with broadcasting channels. To address the private key security issue of PKC schemes for individual users, this paper proposes the concept and general construction of sequentially threshold PKC under a communication model consisting of a computing device and several offline storages where broadcasting channels are not required. To illustrate the new paradigm, we design and realize a sequentially threshold Schnorr signature schemeSTSS. The security proofs forSTSSindicate its effectiveness of achieving unforeability under traditional attacks as well as security incidents caused by human faults and system failures. The experiments on FIPS recommended curves P-256, P-384, and P-521 show thatSTSSis comparable with the original Schnorr scheme in terms of time consumed for generating a signature. The construction of sequentially threshold ElGamal decrtyption scheme is also presented. Finally, we illustrate the application ofSTSSin the Blockchain ecosystem. Jie Zhang 0030, Futai Zhang, Xinyi Huang 0001 |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2025 | An Enhanced Offline/Online Heterogeneous Signcryption Protocol With Batch Verification for Edge Computing-Based VANETsabstractSigncryption can efficiently ensure data confidentiality and authenticity simultaneously, which makes it ideal for use in secure communication of vehicular ad hoc networks (VANETs). Recently, Ali et al. constructed an efficient offline/online heterogeneous signcryption protocol for edge computing-based internet of vehicles (IEEE Trans. Intell. Transp. Syst., vol. 24, no. 12, pp. 14506-14519, Dec. 2023). In this paper, we demonstrate that their signcryption protocol lacks robustness against public key replacement attacks, and then introduce an enhanced signcryption protocol secure in the random oracles. Our certificate-based and identity-based heterogeneous signcryption protocol enables communication between entities in different cryptosystems, while ensuring pseudonym-based conditional privacy for vehicles. Additionally, it supports public verification for tracing malicious behavior from anonymous vehicles. Unlike other protocols, our protocol avoids costly pairings or map-to-point hashes, and incorporates online/offline construction and batch verification, significantly reducing communication delays and computational overhead. Performance analysis shows that our protocol outperforms existing approaches in VANETs. Peiwei Cao, Wenjie Yang 0001, Futai Zhang |
IEEE Trans. Intell. Transp. Syst. | 4 |
| 2024 | Quasi-Linearly Homomorphic Signature for Data Integrity Auditing in Cloud Storage
Futai Zhang, Yichi Huang, Wenjie Yang 0001, Jinmei Tian |
Inscrypt (2) | 1 |
| 2024 | An Efficient Aggregate Signature Scheme With Designated Verifier Based on the Schnorr Signature in Healthcare Wireless Sensor NetworksabstractIn healthcare wireless sensor networks (HWSNs), a lot of personal medical data are collected by wireless sensors. Given that a medical diagnostic analysis heavily relies on these medical data, any tampering with medical data may potentially result in severe consequences. So how to efficiently authenticate the collected medical data is a challenging work in such resource-constrained application scenarios. In this article, we propose an efficient aggregate signature (AS) scheme with designated verifier based on the Schnorr signature over an elliptic curve group for HWSNs. In our signature scheme, the set of many individual signatures on very large amounts of collected medical data can be compressed into a concise AS and their availability can be reduced to the validity of the AS only believed by a designated verifier. Unauthorized entities cannot trace the origin of these medical data authenticated by the AS. Meanwhile, our proposed scheme can also stop compressing any invalid individual signature into a valid AS even if all signers collude. Malicious signers are unable to deny the authenticated data by forging a valid AS based on several invalid individual signatures. Experimental simulation shows that the computation cost of our provably secure AS scheme is notably lower than that of existing works. Wenjie Yang 0001, Junzhe Fan, Futai Zhang |
IEEE Internet Things J. | 3 |
| 2024 | An Efficient and Practical Conditional Privacy-Preserving Aggregate Authentication for Vehicular Ad-Hoc NetworksabstractRecently, Zhu et al. introduced a conditional privacy-preserving authentication scheme based on certificateless aggregate signature (CLAS) for vehicular ad-hoc networks (VANETs). In this paper, we put forward a re-cryptanalysis to their CLAS and provide four concrete forgeries to disprove its security for VANETs. In addition, we also propose a provably secure CLAS scheme with a new aggregate algorithm for VANETs. This algorithm guarantees that the validities of all single signatures are publicly deduced to the validity of a concise aggregate signature. Performance analysis shows that our scheme not only supports public verification but also has short signature size and/or low computation cost compared with existing related works, which is very practical for VANETs. Wenjie Yang 0001, Junzhe Fan, Futai Zhang |
IEEE Trans. Intell. Transp. Syst. | 5 |
| 2022 | Structure-Preserving Linearly Homomorphic Signature with Designated Combiner for Subspace
Yumei Li 0003, Mingwu Zhang, Futai Zhang |
ACISP | 3 |
| 2022 | eCK-Secure Authenticated Key Exchange against Auxiliary Input LeakageabstractAbstract Authenticated key exchange protocols are quite important primitives for practical applications, since they enable two parties to generate a shared high entropy secret key. In this paper we mainly focus on the authenticated key exchange (AKE) against auxiliary input leakage. As the major contribution of this work, we present a generic framework for the construction of AKE protocols that are secure against auxiliary input leakage. An instantiation based on the generalized decisional Diffie-Hellman (GDDH) assumption in the standard model is also given to demonstrate the feasibility of our proposed framework. We also give a comparison among the existing leakage resilient AKE protocols with auxiliary inputs. Sujuan Li, Futai Zhang |
Comput. J. | 2 |
| 2022 | An Efficient Certificate-Based Data Integrity Auditing Protocol for Cloud-Assisted WBANsabstractWith the evolution of wireless body area networks (WBANs), wearable equipment will improve the human healthcare service. However, the medical data generated in WBANs increase dramatically with time, and the massive data cause the storage burden. With the help of cloud computing, the cloud service provider (CSP) can assist data owners in storing these data collected by sensors. By keeping their data in the CSP, the data integrity and authenticity is a big concern of data owners. To date, many data integrity auditing protocols have been proposed to address this issue. Most of them rely on traditional public-key mechanism, or identity-based cryptography (IBC), or certificateless cryptography (CLC). However, they suffer from the heavy cost of certificate management, key escrow, or the requirement of a secret channel for each user, respectively. To solve these drawbacks, we propose an efficient certificate-based data integrity auditing protocol for cloud-assisted WBANs. In our protocol, the computation cost in tag generation for a data block is fixed, and is independent of the size of the data block. We prove our protocol is secure in the random oracle model (ROM) and use the Java pairing-based cryptography library (JPBC) to implement the protocol. The experimental results show that our protocol is computationally efficient and practical. Yumei Li 0003, Futai Zhang |
IEEE Internet Things J. | 2 |
| 2022 | Identity-Based Key Agreement for Blockchain-Powered Intelligent EdgeabstractIn the new paradigm of blockchain-powered intelligent edge, the key agreement is a significant problem that has not been extensively studied so far. Existing key agreement protocols in the traditional public-key setting are usually too complicated and heavy for edge and end devices. Besides, most protocols in use do not have effective measures to resist side-channel attacks, which are increasingly threatening cloud servers, edge devices, and end devices. Identity (ID)-based protocols can be conveniently implemented in the blockchain-powered intelligent edge. Several leakage-resilient ID-based protocols, which can resist side-channel attacks, have been proposed. However, they all involve time-consuming pairing computations. Besides, none of them address side-channel attacks to the key generation center (KGC). This article designs and realizes two novel ID-based key agreement protocols for the blockchain-powered intelligent edge, including an extended Canetti-Krawczyk (eCK) secure ID-based authenticated key agreement (AKA) protocol and a continuous after-the-fact leakage-resilient eCK (CAFL-eCK) secure ID-based AKA protocol. Both protocols do not involve any heavy pairing computation. Besides, the second one can resist side-channel attacks to the KGC and the communicating parties. A hybrid implementation of the two protocols can achieve high efficiency and strong security at the same time in blockchain-powered intelligent edge environments. This is demonstrated via a use case of a blockchain-powered smart home. Jie Zhang 0030, Futai Zhang |
IEEE Internet Things J. | 2 |
| 2022 | VILS: A Verifiable Image Licensing SystemabstractImage licensing regulates the scope, type, and limitations of using an image through an agreement. However, it is challenging to verify whether an agreement has been fulfilled honestly. Existing techniques, such as watermarking and perceptual hashing, help check image originality and editing operations specified in the agreement, but fail to achieve editor designation. In this paper, we propose a verifiable image licensing system (VILS) which provides an effective solution to verify if a received image is used legally according to its licensing agreement. The core building block of our design is a new kind of cryptographic primitive, called accumulator with a designated entity. The new accumulator helps achieve not only editing restriction, but also editor designation in image authentication. Our VILS has the following two appealing features: (1) Authorization: Only an authorized licensee who edits an image with operations declared in a licensing agreement can produce valid images; (2) Efficiency: The verification of VILS is efficient and independent of the number of operations or image size. Compared with the most relevant schemes from the state-of-the-art, the new design enriches the functionality of image authentication but reduces the verification time by 40%. Haixia Chen, Xinyi Huang 0001, Jianting Ning, Futai Zhang, Chao Lin 0003 |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2022 | Data Access Control in Cloud Computing: Flexible and Receiver ExtendableabstractBroadcast encryption provides a promising technique of data access control for specified users in cloud computing. A data uploader can generate a ciphertext for a set of chosen users such that only the intended users are able to access the data. However, with the rapidly increasing of collaboration between users, it is desired to extend the receiver set to grant decryption right for more users. The existing broadcast encryption systems cannot support receiver extension. In this article, we for the first time take this problem into consideration and give a solution. We take the merits of identity-based cryptosystem and propose a notion of EIBBE: a flexible data access control with receiver extendable for cloud computing based on broadcast encryption. It allows the authorized user to extend the receiver set$S$stated in the IBBE ciphertext by adding a new receiver set$S^{\prime }$without re-encryption. Both the users in$S$and$S^{\prime }$can access the data successfully. Moreover, the data uploader determines the maximum number of extended receivers. We then give a concrete construction of EIBBE and provide a rigorous security analysis of our proposed scheme. Finally, we demonstrate the scheme's efficiency and feasibility. Jianchang Lai, Fuchun Guo, Willy Susilo, Xinyi Huang 0001, Peng Jiang 0007, Futai Zhang |
IEEE Trans. Serv. Comput. | 6 |
| 2022 | Secure Data Delivery With Identity-Based Linearly Homomorphic Network Coding Signature Scheme in IoTabstractWith the appearance and flourishing development of the Internet of Things (IoT), wireless sensor networks technology has been attracting increasing attention. Network coding is an indispensable technology in the wireless sensor networks, which can improve network transmission throughput. However, pollution attacks is a serious security problem that must be faced in the process of data coding. Although the homomorphic network coding signature schemes can solve this troublesome, the high signature generation and verification cost of these schemes will reduce the transmission efficiency. In this article, we propose an efficient identity-based linearly homomorphic network coding signature scheme for wireless sensor networks to guarantee data integrity and authenticity. In our scheme, the computation cost of signature generation and verification are both independent of the size of the data packet. The scheme is proved secure against existential forgery under adaptive chosen identity and adaptive chosen subspace attacks in random oracle model. Using Java pairing-based Cryptography Library (JPBC), the simulation results illustrate that our scheme is more efficient in practical application. Yumei Li 0003, Futai Zhang, Xin Liu 0074 |
IEEE Trans. Serv. Comput. | 2 |
| 2021 | Lightweight certificateless linearly homomorphic network coding signature scheme for electronic health systemabstractAbstract With the flourishing development of the Internet of Things (IoT), the electronic health system (EHS) as a leading technology has attracted widespread attention. However, the unsatisfactory network transmission throughput hinders practical applications of EHS to some extent. Network coding can solve this problem, but it also incurs another drawback called pollution attack. Pollution attack can be prevented by using homomorphic network coding signature schemes to check whether a corrupted packet is injected. However, existing schemes require high computational cost for signature verification which will reduce the transmission efficiency. A lightweight certificateless linearly homomorphic network coding signature scheme is proposed. This scheme requires a quite low computational cost when both signing and verifying a data packet. In addition, it is proved that the scheme is secure, and it was implemented by using the Java Pairing‐Based Cryptography Library (JPBC) on a personal computer (PC). The simulation results illustrate that our scheme is efficient. Yumei Li 0003, Futai Zhang, Yinxia Sun |
IET Inf. Secur. | 2 |
| 2021 | Leakage-Resilient Authenticated Key Exchange for Edge Artificial IntelligenceabstractEdge Artificial Intelligence (AI) is a timely complement of cloud-based AI. By introducing intelligence to the edge, it alleviates privacy concerns of streaming and storing data to the cloud, enables real-time operations where milliseconds matter, and brings AI services to remote areas with poor networking infrastructures. Security is a significant problem in Edge AI applications such as self-driving cars and intelligent healthcare. Since the edge devices are empowered to process data and take actions, attacking and compromising them can cause serious damage. However, the wide deployment of computationally limited devices in edge environments and the increasing happening of side-channel (or leakage) attacks pose critical challenges to security. This article thereby aims to enhance the security for Edge AI by designing and developing lightweight and leakage-resilient authenticated key exchange (LRAKE) protocols. Compared with available LRAKE protocols, the proposed protocols in this article can be effortless applied in some mainstreaming security and communication standards. Moreover, this article realizes prototypes and presents implementation details; and a use case of applying the proposed protocol in Bluetooth 5.0 is illustrated. The theoretical design and implementation details will provide a guidance of applying the LRAKE protocols in Edge AI applications. Jie Zhang 0030, Futai Zhang, Xin Huang 0005, Xin Liu 0074 |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2020 | On the General Construction of Tightly Secure Identity-Based Signature SchemesabstractAbstract A tightly secure scheme has a reduction, where the reduction loss is a small constant. Identity-based signature (IBS) is an important cryptographic primitive, and tightly secure IBS schemes enjoy the advantage that the security parameter can be optimal to achieve a certain security level. General constructions of IBS schemes (Bellare, M., Namprempre, C., and Neven, G. (2004) Security Proofs for Identity-Based Identification and Signature Schemes. In Proc. EUROCRYPT 2004, May 2–6, pp. 268–286. Springer, Berlin, Interlaken, Switzerland; Galindo, D., Herranz, J., and Kiltz, E. (2006) On the Generic Construction of Identity-Based Signatures With Additional Properties. In Proceedings of ASIACRYPT 2006, December 3–7, pp. 178–193. Springer, Berlin, Shanghai, China) and their security have been extensively studied. However, the security is not tight and how to generally construct a tightly secure IBS scheme remains unknown. In this paper, we concentrate on the general constructions of IBS schemes. We first take an insight into previous constructions and analyze the reason why it cannot achieve tight security. To further study possible tightly secure constructions, we propose another general construction, which could be seen as a different framework of IBS schemes. Our construction requires two traditional signature schemes, whereas the construction by Bellare et al. uses one scheme in a two-round iteration. There are no additional operations in our general construction. Its main advantage is providing the possibility of achieving tight security for IBS schemes in the random oracle model. Combining two known signature schemes, we present an efficient IBS scheme with tight security as an example. Ge Wu 0001, Zhen Zhao 0005, Fuchun Guo, Willy Susilo, Futai Zhang |
Comput. J. | 5 |
| 2020 | Certificateless aggregate signature scheme secure against fully chosen-key attacks
Ge Wu 0001, Futai Zhang, Fuchun Guo, Willy Susilo |
Inf. Sci. | 2 |
| 2020 | Revocable identity-based encryption with server-aided ciphertext evolution
Yinxia Sun, Yi Mu 0001, Willy Susilo, Futai Zhang, Anmin Fu |
Theor. Comput. Sci. | 4 |
| 2019 | Tightly Secure Public-Key Cryptographic Schemes from One-More Assumptions
Ge Wu 0001, Jianchang Lai, Fuchun Guo, Willy Susilo, Futai Zhang |
J. Comput. Sci. Technol. | 5 |
| 2018 | Revocable Certificateless Encryption with Ciphertext Evolution
Yinxia Sun, Futai Zhang, Anmin Fu |
ACISP | 2 |
| 2018 | Provably secure certificate-based encryption with leakage resilience
Yuyan Guo, Jiguo Li 0001, Yang Lu 0001, Yichen Zhang 0003, Futai Zhang |
Theor. Comput. Sci. | 5 |
| 2017 | New Certificateless Public Key Encryption Secure Against Malicious KGC Attacks in the Standard Model
Wenjie Yang 0001, Jian Weng 0001, Futai Zhang |
ICICS | 3 |
| 2016 | Updatable Lossy Trapdoor Functions and Its Application in Continuous Leakage
Sujuan Li, Yi Mu 0001, Mingwu Zhang, Futai Zhang |
ProvSec | 4 |
| 2016 | Continuous leakage-resilient certificate-based encryption
Jiguo Li 0001, Yuyan Guo, Qihong Yu, Yang Lu 0001, Yichen Zhang 0003, Futai Zhang |
Inf. Sci. | 6 |
| 2016 | Attacks to some verifiable multi-secret sharing schemes and two improved schemes
Futai Zhang, Jie Zhang 0030 |
Inf. Sci. | 2 |
| 2015 | Information-theoretical secure verifiable secret sharing with vector space access structures over bilinear groups and its applications
Jie Zhang 0030, Futai Zhang |
Future Gener. Comput. Syst. | 2 |
| 2015 | Efficient revocable certificateless encryption against decryption key exposureabstractCertificateless public key cryptosystem (CLPKC) improves the identity based public key cryptosystem to be key‐escrow free. Many research works on CLPKC have been presented so far. However, the revocation problem in CLPKC still lacks effective solutions. The current revocation approaches suffer from either low efficiency or security weakness. In this study, we propose the first ‘scalable revocable’ certificateless encryption (RCLE) scheme against ‘decryption key exposure’. The scheme is provably secure in the standard model. Moreover, we give a second interesting RCLE scheme whose decryption key is very short. Yinxia Sun, Futai Zhang, Robert H. Deng |
IET Inf. Secur. | 2 |
| 2014 | A Provably Secure Ring Signature Scheme with Bounded Leakage Resilience
Huaqun Wang, Qianhong Wu, Futai Zhang, Josep Domingo-Ferrer |
ISPEC | 4 |
| 2014 | Information-Theoretical Secure Verifiable Secret Sharing with Vector Space Access Structures over Bilinear Groups
Jie Zhang 0030, Futai Zhang |
ISPEC | 2 |
| 2014 | Efficient Revocable Certificateless Encryption Secure in the Standard ModelabstractCertificateless encryption (CLE) effectively solves the inherent key escrow problem in identity-based encryption while retaining its keeping certificate-free property. Although a number of CLE schemes have been available in the literature, little attention has been paid to the problem of user revocation in the certificateless setting. In this work, we study CLE systems with user revocation capabilities. At first, we establish reasonable security models for revocable CLE (RCLE) schemes. Then we put forward the first efficient and CCA2-secure RCLE scheme in the standard model. A rigorous security proof of our RCLE scheme is presented based on the decisional truncated q-ABDHE assumption and decisional bilinear Diffie–Hellman (DBDH) assumption. Futai Zhang, Yinxia Sun |
Comput. J. | 2 |
| 2014 | Cryptanalysis and improvement on a certificateless encryption scheme in the standard modelabstractCertificateless public key cryptography (CL-PKC) is an important type of public key cryptography, which effectively solves the inherent key escrow problem in identity-based public key cryptography. As the adversarial models in CL-PKC are relatively complex, designing efficient and secure certificateless encryption schemes in the standard model has been an interesting and challenging research topic. In this paper, we give cryptanalysis to an existing certificateless encryption scheme in the standard model. We show its insecurity by demonstrating two kinds of attacks. Then, we modify the original scheme to obtain a secure one. A rigorous security proof of the modified scheme is presented in the standard model based on the decisional bilinear Diffie-Hellman (DBDH) assumption and decisional truncated q -ABDHE assumption. Futai Zhang, Yinxia Sun, Sujuan Li |
Int. J. Inf. Comput. Secur. | 2 |
| 2014 | Notes on the security of certificateless aggregate signature schemes
Futai Zhang, Ge Wu 0001 |
Inf. Sci. | 1 |
| 2014 | Efficient certificateless encryption withstanding attacks from malicious KGC without using random oraclesabstractABSTRACT As the key generation center (KGC) in a certificateless cryptosystem is no longer fully trusted, for practical applications, a secure certificateless encryption (CLE) scheme should withstand malicious KGC attacks. In this paper, we investigate practical CLE schemes withstanding attacks from a malicious KGC without resorting to random oracles. At first, we show the insecurity of the CLE scheme (ZW scheme) presented by Zhang and Wang. Although ZW scheme was proved to be chosen ciphertext secure without using random oracles, we find that it cannot resist attacks from a malicious KGC. We show an attack that demonstrates a malicious KGC can easily decrypt a target ciphertext using chosen ciphertext attack. After that, we introduce a new efficient CLE scheme. We prove its CCA2 security without using random oracles. Our new scheme not only gets rid of the security drawbacks of ZW scheme but also keeps its most distinctive feature of a short public key length. The formal security proofs of the new scheme are presented without using random oracles assuming the hardness of the decisional truncated q‐augmented bilinear Diffie‐Hellman exponent (q‐ABDHE) problem and the hardness of the decisional bilinear Diffie–Hellman problem. Copyright © 2013 John Wiley & Sons, Ltd. Wenjie Yang 0001, Futai Zhang |
Secur. Commun. Networks | 2 |
| 2013 | On security of a certificateless signcryption scheme
Songqin Miao, Futai Zhang, Sujuan Li, Yi Mu 0001 |
Inf. Sci. | 2 |
| 2012 | Practical Certificateless Public Key Encryption in the Standard Model
Wenjie Yang 0001, Futai Zhang |
NSS | 2 |
| 2012 | Delegation of signing rights using certificateless proxy signatures
Lei Zhang 0009, Futai Zhang, Qianhong Wu |
Inf. Sci. | 2 |
| 2010 | Efficient many-to-one authentication with certificateless aggregate signatures
Lei Zhang 0009, Qianhong Wu, Futai Zhang |
Comput. Networks | 4 |
| 2010 | Certificateless threshold signature scheme from bilinear maps
Futai Zhang, Xinyi Huang 0001, Yi Mu 0001, Willy Susilo, Lei Zhang 0009 |
Inf. Sci. | 2 |
| 2010 | Simulatable certificateless two-party authenticated key agreement protocol
Lei Zhang 0009, Futai Zhang, Qianhong Wu, Josep Domingo-Ferrer |
Inf. Sci. | 2 |
| 2009 | A new certificateless aggregate signature scheme
Lei Zhang 0009, Futai Zhang |
Comput. Commun. | 2 |
| 2009 | Cryptanalysis of a Generalized Ring Signature SchemeabstractThe concept of ring signature was first introduced by Rivest et al. in 2001. In a ring signature, instead of revealing the actual identity of the message signer, it specifies a set of possible signers. The verifier can be convinced that the signature was indeed generated by one of the ring members; however, the verifier is unable to tell which member actually produced the signature. A convertible ring signature scheme allows the real signer to convert a ring signature into an ordinary signature by revealing secret information about the ring signature. Thus, the real signer can prove the ownership of a ring signature if necessary, and the the other members in the ring cannot prove the ownership of a ring signature. Based on the original ElGamal signature scheme, a generalized ring signature scheme was proposed for the first time in 2008. The proposed ring signature can achieve unconditional signer ambiguity and is secure against adaptive chosen-message attack in the random oracle model. By comparing to ring signatures based on RSA algorithm, the authors claimed that the proposed generalized ring signature scheme is convertible. It enables the actual message signer to prove to a verifier that only she is capable of generating the ring signature. Through cryptanalysis, we show that the convertibility of the generalized ring signature scheme cannot be satisfied. Everyone in the ring signature has the ability to claim that she generates the generalized ring signature. Huaqun Wang, Futai Zhang, Yanfei Sun |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2008 | A New Provably Secure Certificateless Signature SchemeabstractCertificateless public key cryptography was introduced by Al-Riyami and Paterson to overcome the key escrow problem of ID-PKC. In this paper, we present an efficient certificateless signature scheme using bilinear maps. The scheme can be proved secure in the strongest security model of certificateless signature schemes. In terms of computational cost, totally, only two pairing operations are required for signing and verification. It is more efficient than the other existing certificateless signature schemes secure against a super type I/II adversary. Lei Zhang 0009, Futai Zhang |
ICC | 2 |
| 2007 | Strongly Secure Certificateless Public Key Encryption Without Pairing
Yinxia Sun, Futai Zhang, Joonsang Baek |
CANS | 2 |
| 2007 | A Provably Secure Ring Signature Scheme in Certificateless Cryptography
Lei Zhang 0009, Futai Zhang, Wei Wu 0001 |
ProvSec | 2 |
| 2007 | Breaking and Repairing Trapdoor-Free Group Signature Schemes from Asiacrypt'2004
Xinyi Huang 0001, Willy Susilo, Yi Mu 0001, Futai Zhang |
J. Comput. Sci. Technol. | 4 |
| 2006 | Certificateless Designated Verifier Signature SchemesabstractDesignated verifier signature schemes allow a signer to convince a designated verifier, in such a way that only the designated verifier will believe with the authenticity of such a signature. The previous constructions of designated verifier signature rely on the underlying public key Infrastructure, that requires both signer and verifier to verify the authenticity of the public keys, and hence, the certificates are required. In contrast to the previous constructions, in this paper, we propose the first notion and construction of the certificateless designated verifier signature scheme. In our new notion, the necessity of certificates are eliminated. We show that our scheme satisfies all the requirements of the designated verifier signature schemes in the certificateless system. We also provide complete security proofs for our scheme and prove that our scheme is unforgeable under the assumption of the gap bilinear Diffie-Hellman problem in the random oracle model Xinyi Huang 0001, Willy Susilo, Yi Mu 0001, Futai Zhang |
AINA (2) | 4 |
| 2006 | Short (Identity-Based) Strong Designated Verifier Signature Schemes
Xinyi Huang 0001, Willy Susilo, Yi Mu 0001, Futai Zhang |
ISPEC | 4 |
| 2006 | Restricted Universal Designated Verifier Signature
Xinyi Huang 0001, Willy Susilo, Yi Mu 0001, Futai Zhang |
UIC | 4 |
| 2005 | Identity-Based Ring Signcryption Schemes: Cryptographic Primitives for Preserving Privacy and Authenticity in the Ubiquitous WorldabstractIn this paper, we present a new concept called an identity based ring signcryption scheme (IDRSC,). We argue that this is an important cryptographic primitive that must be used to protect privacy and authenticity of a collection of users who are connected through an ad-hoc network, such as Bluetooth. We also present an efficient IDRSC scheme based on bilinear pairing. As a regular signcryption scheme, our scheme combines the functionality of signature and encryption schemes. However, the idea is to have an identity based system. In our scheme, a user can anonymously sign-crypts a message on behalf of the group. We show that our scheme outperforms a traditional identity based scheme, that is obtained by a standard sign-then-encrypt mechanism, in terms of the length of the ciphertext. We also provide a formal proof of our scheme with the chosen cipher-text security under the decisional bilinear Diffie-Hellman assumption, which is believed to be intractable. Xinyi Huang 0001, Willy Susilo, Yi Mu 0001, Futai Zhang |
AINA | 4 |
| 2005 | On the Security of Certificateless Signature Schemes from Asiacrypt 2003
Xinyi Huang 0001, Willy Susilo, Yi Mu 0001, Futai Zhang |
CANS | 4 |
| 2002 | Selection of Secure Hyperelliptic Curves of g_2 Based on a Subfield
Fangguo Zhang, Futai Zhang, Yumin Wang |
J. Comput. Sci. Technol. | 2 |
| 2001 | Fast Scalar Multiplication on the Jacobian of a Family of Hyperelliptic Curves
Fangguo Zhang, Futai Zhang, Yumin Wang |
ICICS | 2 |
| 2000 | Fair Electronic Cash Systems with Multiple Banks
Fangguo Zhang, Futai Zhang, Yumin Wang |
SEC | 2 |