EDBT 2026 Demo / reviewers in the wild / expert
Lein Harn
dblp:h/LeinHarn
· DBLP profile ↗
93ranked-venue papers
41as first author
24since 2021 · last 2025
0000-0003-0922-6148ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 38 · 18 first-author · 7 since 2021Computer networks · 22 · 7 first-author · 7 since 2021Databases, data management, data science and information retrieval · 12 · 8 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 9 · 5 first-author · 5 since 2021Theory of computation · 6 · 3 first-authorSoftware engineering, systems software and programming languages · 5 · 1 first-author · 1 since 2021Systems, architecture and hardware · 4 · 2 first-author · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | A new robust PKC encryption method based on invertible matrix multiplication for HIE in medical IoT systemsabstractAbstract Electronic health information exchange (HIE) allows doctors, nurses, pharmacists, other health care providers and patients to appropriately access and securely share a patient’s vital medical information electronically—improving the speed, quality, safety and cost of patient care. At present, public key cryptography (PKC) is the most secure and practical cryptographic techniques to achieve this function in healthcare information exchange for medical IoT systems. ElGamal cryptosystem is one of the most well-known public key cryptosystems (they are also called asymmetric key cryptosystems), which is based on the discrete logarithm problem. At present, with the development of quantum computer technology, the ElGamal cryptosystem may be attacked by quantum algorithms. At the same time, since ElGamal requires several secure random integers to resist cryptographic analysis and ensure communication security and securing data sharing. Especially, when the encrypted information is large, multiple random numbers need to be used for grouping encryption, which makes the efficiency of ElGamal need to be improved. It is necessary to construct an alternative cryptographic algorithm that is more secure and efficient than ElGamal. In this paper, we construct a new public key cryptosystem (PKC) based on the discrete logarithm problem in $$GL\left(n,p\right)$$ G L n , p , which is constructed by the invertible matrix multiplication and can become an alternative version of the ElGamal public key cryptosystem. We call it Matrix ElGamal cryptosystem (M-EPKC). It is proved that the proposed PKC is computationally secure, which can provide the same security as the ElGamal cryptosystem in a much smaller finite field and use fewer random integers when encrypting large amounts of messages. For matrices of size $$n$$ n , ElGamal PKC requires $$n$$ n times more random numbers to encrypt plaintext with the same amount of data. The proposed M-EPKC is not only proved to be resistant to Shor’s algorithm attack (Shor in SIAM Rev 41: 303–332, 1999) on the integer field, but it can also improve its own computational efficiency by accelerating the decryption algorithm. Therefore, compare with the ElGamal cryptosystem, our proposed M-EPKC can provide a more secure and efficient method in healthcare information exchange for medical IoT systems. Ching-Fang Hsu 0001, Lein Harn, Zhuo Zhao |
Cybersecur. | 3 |
| 2025 | Provably Secure and Efficient One-to-Many Authentication and Key Agreement Protocol for Resource-Asymmetric Smart EnvironmentsabstractThe smart environment is a crucial application of the Internet of Things(IoT). Due to its growing security and efficiency needs, recent years have seen the proposal of numerous authentication and key agreement (AKA) protocols. Unfortunately, most of existing AKA protocols only support one-to-one AKA and rely on the elliptic curve cryptosystem, resulting in huge overhead. In addition, these protocols fail to consider the resource-asymmetric characteristics of this scenario. That is, the resources on the gateway side are abundant, while the resources on user sides and device sides are limited. In order to achieve efficient and secure one-to-many AKA establishment in this scenario, where one-to-many means that users can realize key agreements with multiple smart devices at the same time. For the first time, this paper uses the one-to-many computing structure of the Chinese Remainder Theorem (CRT) to design an efficient one-to-many AKA establishment, which is perfectly adapted to resource-asymmetric allocation in smart environments. Compared with existing solutions, this solution has the following advantages. Firstly, our protocol is suitable for resource-asymmetric environments, where the gateway acts as an intermediate node and uses rich resources to integrate multiple AKA requests. Secondly, the solution supports users to negotiate session keys with multiple smart devices at the same time. Thirdly, we prove the protocol’s security under the Real-or-Random (ROR) model. In addition, we perform formal security verification of the protocol using the Automated Validation of Internet Security Protocols and Applications(AVISPA) tool. Finally, the security and efficiency of this solution are superior to similar solutions. Specifically, our solution can meet 18 security and functionality requirements. Compared with the latest similar scheme, assuming that the number of smart devices is 10, our scheme reduces the computational cost by 75.75%. At the same time, in terms of communication cost, our protocol reduces it by 37.78%. Ching-Fang Hsu 0001, Jianqun Cui, Man Ho Au, Lein Harn, Quanrun Li |
IEEE Internet Things J. | 5 |
| 2025 | Lightweight and Provably Secure Privacy-Preserving Implicit Authentication Protocol Using Weighted-MinHash for IoV Environment
Honglang Hu, Ching-Fang Hsu 0001, Man Ho Au, Jianqun Cui, Lein Harn, Zhuo Zhao |
IEEE Trans. Intell. Transp. Syst. | 5 |
| 2025 | Provably secure and lightweight authentication protocol using PUF and blockchain for smart grids
Honglang Hu, Ching-Fang Hsu 0001, Jianqun Cui, Lein Harn, Qihang Hou |
J. Supercomput. | 4 |
| 2024 | Extremely Lightweight Constant-Round Membership-Authenticated Group Key Establishment for Resource-Constrained Smart Environments toward 5GabstractAbstract With rapid development of next-generation mobile networks and communications (5G networks), group-oriented applications in resource-constrained smart environments (RSEs), such as smart homes and smart classrooms, have attracted great attentions. Due to the insecure communications between resource-constrained devices, secure group communications in RSE toward 5G face many challenges. In RSE toward 5G, lightweight communications and low computational overheads are crucial. Besides, the private tokens used to generate the group key are expected to be reused multiple times. However, the conventional frameworks for secure group communications cannot meet these requirements. A practical construction of extremely lightweight constant-round membership authenticated group key establishment framework is proposed in this paper for RSE toward 5G, which not only implements identity authentication among the members and group key establishment but also ensures extremely lightweight computation and communication costs by each group member. In our proposed scheme, the increase in the number of group members will not lead to a linear or logarithmic increase in the communication and calculation costs at the member side. Our framework also resists external and internal attacks and meets all the desirable security features. In this framework, the privacy of tokens can be well protected, so that they can be reused for multiple times. Therefore, our scheme significantly reduces the costs of communication and calculation, and it is more efficient compared with the related schemes in the literature. This proposal is fairly suitable for lightweight membership authentication and group key establishment in RSE toward 5G. Ching-Fang Hsu 0001, Zhe Xia, Tianshu Cheng, Lein Harn |
Comput. J. | 4 |
| 2024 | PRLAP-IoD: A PUF-based Robust and Lightweight Authentication Protocol for Internet of Drones
Ching-Fang Hsu 0001, Man Ho Au, Lein Harn, Jianqun Cui, Zhe Xia, Zhuo Zhao |
Comput. Networks | 4 |
| 2024 | Lightweight ring-neighbor-based user authentication and group-key agreement for internet of dronesabstractAbstract As mobile internet and Internet of Things technologies continue to advance, the application scenarios of peer-to-peer Internet of Drones (IoD) are becoming increasingly diverse. However, the development of IoD also faces significant challenges, such as security, privacy protection, and limited computing power, which require technological innovation to overcome. For group secure communication, it is necessary to provide two basic services, user authentication and group key agreement. Due to the limited storage of IoD devices, group key negotiation requires lightweight calculations, and conventional schemes cannot satisfy the requirements of group communication in the IoD. To this end, a new lightweight communication scheme based on ring neighbors is presented in this paper for IoD, which not only realizes the identity verification of user and group key negotiation, but also improves computational efficiency on each group member side. A detailed security analysis substantiates that the designed scheme is capable of withstanding attacks from both internal and external adversaries while satisfying all defined security requirements. More importantly, in our proposal, the computational cost on the user side remains unaffected by the variability of the number of members participating in group communication, as members communicate in a non-interactive manner through broadcasting. As a result, the protocol proposed in this article demonstrates lower computational and communication costs in comparison to other cryptographic schemes. Hence, this proposal presents a more appealing approach to lightweight group key agreement protocol with user authentication for application in the IoD. Zhuo Zhao, Ching-Fang Hsu 0001, Lein Harn, Zhe Xia |
Cybersecur. | 3 |
| 2024 | A revocable and comparable attribute-based signature scheme from lattices for IoMT
Ching-Fang Hsu 0001, Man Ho Au, Lein Harn, Jianqun Cui, Zhuo Zhao |
J. Syst. Archit. | 4 |
| 2024 | Efficient and Privacy-Preserving Skyline Queries Over Encrypted Data Under a Blockchain-Based Audit ArchitectureabstractSkyline queries is an advanced data mining algorithm suitable for multi-criteria decision-making scenarios (i.e., medical pre-diagnosis). Privacy-preserving skyline queries schemes are usually constructed by certain methods of cryptography such as additive homomorphic cryptosystem, secret sharing technology, etc. Interestingly, these secure skyline queries schemes require that skyline computations do not reveal any message details, including encrypted inter-tuple domination relations, among which privacy schemes based on homomorphic cryptosystems are the most popular due to their strong security. However, existing secure skyline queries schemes not only suffer from low computational efficiency, but also do not have sufficient security for privacy-key management in the system. To address the above issues, this paper designs an efficient and privacy-preserving skyline queries over encrypted data under a blockchain-based audit architecture. Firstly, we propose a blockchain-based audit architecture that not only provides error auditing functionality but also makes our scheme suitable for (distributed) multi-user scenarios while providing secure key management in the system. Secondly, we implement a series of secure sub-protocols using the CRT-Based Paillier encryption algorithm and construct a privacy sparse matrix elimination protocol to reduce the size of the dataset, leading to a significant reduction in computational cost without compromising privacy. Finally, we put forward our secure skyline queries protocol and prove its security. The performance evaluation shows that our proposed method our proposed method is significantly more efficient (at least 7.4 times faster) compared to current methods. Shuchang Zeng, Ching-Fang Hsu 0001, Lein Harn, Yi-Ning Liu 0002, Yang Liu 0368 |
IEEE Trans. Knowl. Data Eng. | 3 |
| 2023 | Efficient and Secure Authentication Key Establishment Protocol Using Chaotic Map and PUF in Smart EnvironmentsabstractWith the rapid growth and popularization of the Internet of Things (IoT), it has been applied to numerous fields such as smart industry, smart agriculture and smart home. Designing practical and robust authentication key agreement (AKA) schemes for smart environments has become a pressing problem to be solved. Due to differences in security requirements and resource allocation in smart environments, which we call security-asymmetry and resource-asymmetry, it is necessary to design specific AKA schemes for this environment. Since the design of remote AKA protocols does not fully consider security-asymmetry and resource-asymmetry, many existing schemes are not practical in smart environments. With regard to security-asymmetry, compared with traditional public-key techniques applied in AKA schemes, chaotic map is more effective than modular exponentiation and scalar multiplication, and it supplies many feasible attributes such as unpredictability, unrepeatability, uncertainty, which can be used to achieve communication security between users and gateways, while security operations based on hash function are sufficient to secure communications between gateways and smart devices. In view of resource-asymmetry, the complex operations in the authentication process can be completed by the gateway, so as to make full use of the rich resources on gateway side and reduce the use of resources on user side and device side. Based on such considerations, an efficient and secure authentication key agreement scheme based on chaotic map and physical unclonable function (PUF) for smart environments is proposed. We present a rigorous informal analysis of the proposed scheme. Moreover, the formal security verification is accomplished using the Automated Validation of Internet Security Protocols and Applications (AVISPA) tool. Finally, performance evaluations indicate the proposed protocol consumes less communication cost and computation cost while achieving more security functions compared to other four state-of-the-art related schemes. Fengling Pang, Ching-Fang Hsu 0001, Man Ho Au, Lein Harn, Li Long |
TrustCom | 4 |
| 2023 | Multiple Blind Signature for e-Voting and e-CashabstractAbstract In this paper, we propose a new cryptographic primitive, called multiple blind signature (MBS), which is designed based on the integration of both normal blind signature scheme and dual signature. The major difference between a normal blind signature and an MBS is that using a normal blind signature, only one message, $m$, can be verified, but using an MBS, any subset, ${M}^{\prime }$, of multiple messages in a set, $M$, where ${M}^{\prime}{\subseteq} M$, can be verified. With this additional property, we will show that MBS is especially suitable for e-voting and e-cash applications. In other words, we classify these processes in two applications into two phases, on-line and off-line phases. One unique property of this design is that most time-consuming computation and interaction can be performed in advance in off-line phase. There is no cost of computation and interaction in the online phase. Lein Harn, Ching-Fang Hsu 0001, Zhe Xia |
Comput. J. | 1 |
| 2023 | Construction of Lightweight Authenticated Joint Arithmetic Computation for 5G IoT NetworksabstractAbstract The next generation of Internet of Things (IoT) networks and mobile communications (5G IoT networks) has the particularity of being heterogeneous, therefore, it has very strong ability to compute, store, etc. Group-oriented applications demonstrate its potential ability in 5G IoT networks. One of the main challenges for secure group-oriented applications (SGA) in 5G IoT networks is how to secure communication and computation among these heterogeneous devices. Conventional protocols are not suitable for SGA in 5G IoT networks since multiparty joint computation in this environment requires lightweight communication and computation overhead. Furthermore, the primary task of SGA is to securely transmit various types of jointly computing data. Hence, membership authentication and secure multiparty joint arithmetic computation become two fundamental security services in SGA for 5G IoT networks. The membership authentication allows communication entities to authenticate their communication partners and the multiparty joint computations allow a secret output to be shared among all communication entities. The multiparty joint computation result can be used to protect exchange information in the communication or be used as a result that all users jointly compute by using their secret inputs. A novel construction of computation/communications-efficient membership authenticated joint arithmetic computation is proposed in this paper for 5G IoT networks, which not only integrates the function of membership authentication and joint arithmetic computation but also realizes both computation and communication efficiency on each group member side. Our protocol is secure against inside attackers and outside attackers, and also meets all the described security goals. Meanwhile, in this construction the privacy of tokens can be well protected so tokens can be reused multiple times. This proposal is noninteractive and can be easily extended to joint arithmetic computation with any number of inputs. Hence, our design has more attraction for lightweight membership authenticated joint arithmetic computation in 5G IoT networks. Ching-Fang Hsu 0001, Lein Harn, Zhe Xia, Jianqun Cui, Jingxue Chen |
Comput. J. | 2 |
| 2023 | Ideal dynamic threshold Multi-secret data sharing in smart environments for sustainable cities
Ching-Fang Hsu 0001, Zhe Xia, Lein Harn, Man Ho Au, Jianqun Cui, Zhuo Zhao |
Inf. Sci. | 3 |
| 2023 | Simple and efficient threshold changeable secret sharing
Lein Harn, Ching-Fang Hsu 0001, Zhe Xia, Shuchang Zeng, Fengling Pang |
J. Inf. Secur. Appl. | 1 |
| 2023 | A Practical Lightweight Anonymous Authentication and Key Establishment Scheme for Resource-Asymmetric Smart EnvironmentsabstractWith the rapid developments of Internet of Things (IoT) technologies, the security of sensitive data has attracted more and more attention for many resource-asymmetric smart environments, such as smart home, smart agriculture and so on. The resource-asymmetry environment refers to the uneven distribution of resources on different devices side, which is specifically manifested as gateway side is resource-rich, user side and device side are resource-restricted. Hence, a secure and practical authentication key establishment scheme for such smart environments is urgently needed. Recently many researchers have designed authentication and key establishment schemes for security purpose, however most of them cannot consider the excess of gateway resources and guarantee the anonymity of user, and further, they are not suitable for resource-asymmetric smart environments because they are not lightweight enough in user side and smart device side. Due to the fact that Rabin cryptosystem has the large difference in time-consuming between encryption and decryption, it is extremely suitable for constructing authentication and key establishment scheme for resource-asymmetric smart environments. So, a new practical authentication and key establishment scheme based on the Rabin cryptosystem for resource-asymmetric smart environments is proposed, which can make better use of the advantages of abundant gateway resources and realize the lightweight operations on device side and user side, and at the same time can provide user anonymity. With Proverif and BAN logic, we can prove that our solution not only provides anonymity, but also satisfies all defined security features. Simultaneously, compared with latest similar protocols in computation cost and communication overhead, the results show that our scheme is more effective. Hence, our design has more attraction for authentication and key establishment scheme in resource-asymmetric smart environments. Linyan Bai, Ching-Fang Hsu 0001, Lein Harn, Jianqun Cui, Zhuo Zhao |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2023 | Three-Factor Anonymous Authentication and Key Agreement Based on Fuzzy Biological Extraction for Industrial Internet of ThingsabstractWith the increasing popularity and wide application of the Internet, the users (such as managers and data consumers) in the Industrial Internet of Things (IIoT) can remotely analyze and control real-time data collected by various smart sensor devices. However, there are many security and privacy issues in the process of transmitting collected data through public channels in IIoT environment. In order to against the illegal access by opponents, a novel anonymous user authentication and key agreement scheme based on hash and elliptic curve encryption is proposed in this article, which not only uses a pseudonym tuple database in control nodes to realize the functions of user dynamic joining and anonymity protection, but also resists key loss and device capture attacks through fuzzy biometric extraction technology. In addition, the formal secure analysis of the proposed scheme is carried out using the BAN logic model and ROR model, which proves the security of the proposed scheme. Meanwhile, we also prove the scheme can against the described existing attacks and meet the design goals by a detailed informal security discussion. Compared with the latest similar IIoT authentication proposals, our solution has a very obvious advantage in communication efficiency and realizes more functions. Hence, our scheme is more suitable for the IIoT environment, and can also generate greater benefits. Ching-Fang Hsu 0001, Lein Harn, Jianqun Cui, Zhuo Zhao |
IEEE Trans. Serv. Comput. | 3 |
| 2022 | A novel threshold changeable secret sharing scheme
Lein Harn, Ching-Fang Hsu 0001, Zhe Xia |
Frontiers Comput. Sci. | 1 |
| 2022 | Lightweight key establishment with the assistance of mutually connected sensors in wireless sensor networks (WSNs)abstractAbstract Sensitive data collected by a wireless sensor network (WSN) should be protected by a secret key shared between two adjacent (or neighboring) sensors. Sensors are mobile devices with limited memory and computational power, and sensors are deployed in a field randomly in which relative positions among sensors cannot be pre‐determined. Key distribution in WSN is a challenging research problem. Random key distribution is one of the most popular key distribution techniques in WSN; but it is a probabilistic key distribution scheme since two neighboring sensors may or may not share any pairwise key. There are many published papers to improve the probability of connectivity of two neighboring sensors. In this paper, a novel design of lightweight key establishment is proposed based on top of random key distribution. The first scheme can increase the probability of connectivity of two neighboring sensors, and the second scheme can also enable sensors to authenticate the established pairwise key. Both schemes need only XOR operation so they are lightweight and especially suitable for WSNs. Wei Liu 0240, Lein Harn, Jian Weng 0001 |
IET Commun. | 2 |
| 2021 | Non-interactive integrated membership authentication and group arithmetic computation output for 5G sensor networksabstractAbstract Group‐oriented applications show its potential ability in the next generation of wireless sensor networks (5G WSNs), which have the particularity of being heterogeneous and so have different capabilities in terms of storage, computing, communicating and energy. One of the main challenges for secure group‐oriented applications (SGA) in 5G WSNs is how to secure communication between these heterogeneous devices. Conventional protocols are not suitable for SGA in 5G sensor networks since multiparty output establishment in this environment requires lightweight communication and computation overhead, further the primary task of SGA in 5G WSNs is to securely transmit various types of jointly computing data. Hence, membership authentication and multiparty output for arithmetic computations become two fundamental and necessary security services in SGA for 5G WSNs. In this paper we propose a novel design of non‐interactive integrated membership authenticated multiparty output for arithmetic computations in 5G sensor networks, which embeds the function of membership authentication and multiparty output for arithmetic computations. Since any arithmetic computation function is composed of multiple additions and multiplications, our result serves as a general method for multiparty computation output in SGA. This design is more suitable for lightweight membership authenticated multiparty arithmetic computations output in 5G sensor networks. Ching-Fang Hsu 0001, Lein Harn, Zhe Xia, Maoyuan Zhang, Zhuo Zhao |
IET Commun. | 2 |
| 2021 | Design of ideal secret sharing based on new results on representable quadripartite matroids
Ching-Fang Hsu 0001, Lein Harn, Zhe Xia, Maoyuan Zhang, Quanrun Li |
J. Inf. Secur. Appl. | 2 |
| 2021 | Non-interactive secure multi-party arithmetic computations with confidentiality for P2P networks
Lein Harn, Zhe Xia, Ching-Fang Hsu 0001 |
Peer-to-Peer Netw. Appl. | 1 |
| 2021 | PUF-Based Mutual-Authenticated Key Distribution for Dynamic Sensor NetworksabstractBecause of the movements of sensor nodes and unknown mobility pattern, how to ensure two communicating (static or mobile) nodes authenticate and share a pairwise key is important. In this paper, we propose a mutual-authenticated key distribution scheme based on physical unclonable functions (PUFs) for dynamic sensor networks. Compared with traditional key predistribution schemes, the proposal reduces the storage overhead and the key exposure risks and thereby improves the resilience against node capture attacks. Mutual authentication is provided by the PUF challenge-response mechanism. However, the PUF response is not transmitted in plain forms so as to resist the modelling attacks, which is vulnerable in some existing PUF-based schemes. We demonstrate the proposed scheme to improve the secure connectivity and other performances by analysis and experiments. Yijun Cui, Lein Harn, Shuo Qiu |
Secur. Commun. Networks | 3 |
| 2021 | Lightweight Privacy-Preserving Data Sharing Scheme for Internet of Medical ThingsabstractInternet of Medical Things (IoMT) is a kind of Internet of Things (IoT) that includes patients and medical sensors. Patients can share real‐time medical data collected in IoMT with medical professionals. This enables medical professionals to provide patients with efficient medical services. Due to the high efficiency of cloud computing, patients prefer to share gathering medical information using cloud servers. However, sharing medical data on the cloud server will cause security issues, because these data involve the privacy of patients. Although recently many researchers have designed data sharing schemes in medical domain for security purpose, most of them cannot guarantee the anonymity of patients and provide access control for shared health data, and further, they are not lightweight enough for IoMT. Due to these security and efficiency issues, a novel lightweight privacy‐preserving data sharing scheme is constructed in this paper for IoMT. This scheme can achieve the anonymity of patients and access control of shared medical data. At the same time, it satisfies all described security features. In addition, this scheme can achieve lightweight computations by using elliptic curve cryptography (ECC), XOR operations, and hash function. Furthermore, performance evaluation demonstrates that the proposed scheme takes less computation cost through comparison with similar solutions. Therefore, it is fairly an attractive solution for efficient and secure data sharing in IoMT. Zhuo Zhao, Ching-Fang Hsu 0001, Lein Harn, Lulu Ke |
Wirel. Commun. Mob. Comput. | 3 |
| 2021 | Lightweight and flexible key distribution schemes for secure group communications
Lein Harn, Ching-Fang Hsu 0001, Zhe Xia |
Wirel. Networks | 1 |
| 2020 | Lightweight group key distribution schemes based on pre-shared pairwise keysabstractIn a secure communication, a one‐time session key is needed to be shared among all participants. Most well‐known key distribution schemes, such as Diffie–Hellman public‐key key distribution scheme invented in 1976 and quantum key distribution scheme invented in 1984 (also called the BB84 scheme), can only allow two users to share a key in conventional one‐to‐one communications. There are many research papers in the literature to propose group key distribution schemes for multiple participants in modern group communications. In this study, the authors propose lightweight group key distributions using pre‐shared pairwise keys. The authors first propose a three‐party group key distribution scheme. They then extend the basic three‐party scheme to establish a group key for a large size of group communications. The proposed generalised schemes can be based to any type of pairwise key distribution schemes, e.g. either quantum or non‐quantum. Moreover, both generalised multi‐party group key distribution schemes are lightweight. The main operations in the proposed schemes are key comparison between two or more than two keys (i.e. logic XOR operation) and the computation of key derivation functions. Lein Harn, Ching-Fang Hsu 0001, Zhe Xia |
IET Commun. | 1 |
| 2020 | Secret sharing with secure secret reconstruction
Lein Harn, Zhe Xia, Ching-Fang Hsu 0001, Yi-Ning Liu 0002 |
Inf. Sci. | 1 |
| 2020 | UMKESS: user-oriented multi-group key establishments using secret sharing
Ching-Fang Hsu 0001, Lein Harn, Bing Zeng 0005 |
Wirel. Networks | 2 |
| 2019 | Provably Secure Group Authentication in the Asynchronous Communication Model
Zhe Xia, Lein Harn, Bo Yang 0003, Mingwu Zhang, Yi Mu 0001, Willy Susilo, Weizhi Meng 0001 |
ICICS | 2 |
| 2019 | Hierarchical Key Management Scheme with Probabilistic Security in a Wireless Sensor Network (WSN)abstractSecuring data transferred over a WSN is required to protect data from being compromised by attackers. Sensors in the WSN must share keys that are utilized to protect data transmitted between sensor nodes. There are several approaches introduced in the literature for key establishment in WSNs. Designing a key distribution/establishment scheme in WSNs is a challenging task due to the limited resources of sensor nodes. Polynomial-based key distribution schemes have been proposed in WSNs to provide a lightweight solution for resource-constraint devices. More importantly, polynomial-based schemes guarantee that a pairwise key exists between two sensors in the WSNs. However, one problem associated with all polynomial-based approaches in WSNs is that they are vulnerable to sensor capture attacks. Specifically, the attacker can compromise the security of the entire network by capturing a fixed number of sensors. In this paper, we propose a novel polynomial-based scheme with a probabilistic security feature that effectively reduces the security risk of sensor-captured attacks and requires minimal memory and computation overhead. Furthermore, our design can be extended to provide hierarchical key management to support data aggregation in WSNs. Ashwag Albakri, Lein Harn, Sejun Song |
Secur. Commun. Networks | 2 |
| 2018 | Centralized Group Key Establishment Protocol without a Mutually Trusted Third Party
Lein Harn, Ching-Fang Hsu 0001 |
Mob. Networks Appl. | 1 |
| 2017 | A Practical Hybrid Group Key Establishment for Secure Group CommunicationsabstractA group key establishment enables a group key shared among all group members. In this paper, we proposed a novel group key establishment, which is a hybrid of the Diffie–Hellman (DH) public-key scheme and the secret sharing scheme. Our protocol takes the advantages of the DH scheme, which does not need a mutually trusted key generation center (KGC) and the secret sharing scheme, which reduces the computational time. Employing the DH scheme allows any group member to act as a KGC to distribute a secret key to all group members. The secret sharing scheme is used as the encryption tool to transfer a group key to group members. Since public-key encryption involves modular exponentiations using a larger modulus (say at least 1024 bits) as compared with the secret sharing encryption involves polynomial operations using a smaller modulus (say only 160 bits), our proposed approach is faster than the broadcast encryption in public-key setting. We show that our protocol can provide key secrecy, key authentication and key independence. Lein Harn, Ching-Fang Hsu 0001 |
Comput. J. | 1 |
| 2017 | A Novel Design of Membership Authentication and Group Key Establishment ProtocolabstractA new type of authentication, called group authentication, has been proposed recently which can authenticate all users belonging to the same group at once in a group communication. However, the group authentication can only detect the existence of nonmembers but cannot identify who are the nonmembers. Furthermore, in a group communication, it needs not only to authenticate memberships but also to establish a group key among all members. In this paper, we propose a novel design to provide both membership authentication and group key establishment. Our proposed membership authentication can not only detect nonmembers but also identify who are the nonmembers. We first propose a basic membership authentication and key establishment protocol which can only support one-time group communication. Then, we extend the basic protocol to support multiple group communications. Our design is unique since tokens of users issued by a group manager (GM) during registration are used for both membership authentication and group key establishment. Lein Harn, Ching-Fang Hsu 0001 |
Secur. Commun. Networks | 1 |
| 2017 | How to Share Secret Efficiently over NetworksabstractIn a secret-sharing scheme, the secret is shared among a set of shareholders, and it can be reconstructed if a quorum of these shareholders work together by releasing their secret shares. However, in many applications, it is undesirable for nonshareholders to learn the secret. In these cases, pairwise secure channels are needed among shareholders to exchange the shares. In other words, a shared key needs to be established between every pair of shareholders. But employing an additional key establishment protocol may make the secret-sharing schemes significantly more complicated. To solve this problem, we introduce a new type of secret-sharing, calledprotected secret-sharing(PSS), in which the shares possessed by shareholders not only can be used to reconstruct the original secret but also can be used to establish the shared keys between every pair of shareholders. Therefore, in the secret reconstruction phase, the recovered secret is only available to shareholders but not to nonshareholders. In this paper, an information theoretically secure PSS scheme is proposed, its security properties are analyzed, and its computational complexity is evaluated. Moreover, our proposed PSS scheme also can be applied to threshold cryptosystems to prevent nonshareholders from learning the output of the protocols. Lein Harn, Ching-Fang Hsu 0001, Zhe Xia, Junwei Zhou 0002 |
Secur. Commun. Networks | 1 |
| 2017 | Computation-efficient key establishment in wireless group communications
Ching-Fang Hsu 0001, Lein Harn, Yi Mu 0001, Maoyuan Zhang |
Wirel. Networks | 2 |
| 2016 | Realizing secret sharing with general access structure
Lein Harn, Ching-Fang Hsu 0001, Mingwu Zhang, Tingting He 0003, Maoyuan Zhang |
Inf. Sci. | 1 |
| 2015 | Dynamic threshold secret reconstruction and its application to the threshold cryptography
Lein Harn, Ching-Fang Hsu 0001 |
Inf. Process. Lett. | 1 |
| 2015 | Fair secret reconstruction in (t, n) secret sharing
Lein Harn, Changlu Lin, Yong Li 0002 |
J. Inf. Secur. Appl. | 1 |
| 2015 | An image-based key agreement protocol using the morphing technique
Chin-Chen Chang 0001, Lein Harn, Shih-Chang Chang |
Multim. Tools Appl. | 3 |
| 2015 | Conference key establishment protocol using a multivariate polynomial and its applicationsabstractAbstract In 1992, a non‐interactivek‐securem‐conference protocol based on anm‐variate polynomial has been proposed. Each user needs to store a (m − 1)‐polynomial having degreekas a private share. A secret conference key involvingmusers can be computed by each conference member non‐interactively using each private share. There is no overhead to exchange information in order to establish a conference key. However, the storage space of each user is exponentially proportional to the group size of the conference. In this paper, we propose a key establishment protocol using a multivariate polynomial inZN, whereNis a RSA modulus. One unique feature of using this special type of polynomials for conference key protocol is that the storage space of each user is fixed and is independent to the group size of the conference. User can use their shares obtained from a key generation center initially to establish conference keys consisting of different users. Furthermore, we propose two applications to demonstrate the importance of using this special type of polynomials to design solutions. One is the private reconstruction of secret in a secret sharing scheme over network, and the other is the secure group communication. Copyright © 2014 John Wiley & Sons, Ltd. Lein Harn, Guang Gong |
Secur. Commun. Networks | 1 |
| 2014 | Group key distribution with full-healing propertyabstractA new type of group key distribution, called “Full-Healing” Group Key Distribution (F-GKD), is proposed in this paper which can help new-added members to recover the historical session keys. It is specially designed to support practical (but not confidential and critical) applications (such as Chat and Instant Messaging Systems (CIMS), Massively Multiplayer Online Games (MMOG)) with requirement of “Historical Session Recovery”, in which later-added members can recover the content in the conversations among earlier members. The property of “full-healing” is not only focused on registered-session recovery as most self-healing or mutual-healing group key distribution schemes, it enables an authorized group member to recover entire key chain for the historical sessions. We give a formal definition of the “full-healing” and introduce technical details and properties of the F-GKD schemes. Moreover, we propose a basic F-GKD scheme by using a one-way hash function and Shamir's secret sharing. Analysis proves that the proposed scheme has the following advantages: it is efficient in key recovery without additional transmissions from group manager or other neighboring members; it is collusion-resistant and information theoretically secure; it is communication efficient and flexible to member addition/revocation; it guarantees forward secrecy due to the one-way hash operations. Lein Harn |
ICCCN | 3 |
| 2014 | Generalised cheater detection and identificationabstractCheater detection and identification are important issues in the process of secret reconstruction. To detect and identify cheaters most of the algorithms need the dealer to generate and distribute additional information to shareholders. Recently, algorithms have been proposed to detect and identify cheaters. If more than t (i.e. the threshold) shares, for example j (i.e. t < j ) shares in the secret reconstruction, then redundancy of shares can be used to detect and identify cheaters. The detectability and identifiability of cheaters are proportional to the number of redundant shares. However, the number of redundant shares, j − t is fixed if original shares are used in the secret reconstruction. So, a threshold changeable verifiable secret sharing (TCVSS) has been developed, which allows shareholders working together to change the threshold t into a new threshold t ′ (i.e. t ′ < j ) and generate new shares; whereas at the same time, maintain the original secret. The verifiability of the proposed TCVSS enables shareholders to verify that their new shares have been properly generated. The number of redundant shares can be changed to j − t ′ if new shares are used in the secret reconstruction. Discussion on how to determine the new threshold t ′ in order to detect and identify cheaters successfully has also been included. Lein Harn |
IET Inf. Secur. | 1 |
| 2014 | Comments on 'fair (t, n) threshold secret sharing scheme'abstractTian et al . have proposed a fair ( t , n ) threshold secret sharing scheme recently. Three attacks have been introduced and analysed in this study. Among them, two attacks are associated with a synchronous network where the shares are released simultaneously, and one attack is associated with an asynchronous network where the shares are released asynchronously. In this study, the authors want to point out that the scheme only works properly in a synchronous network; but not in an asynchronous network. In other words, Theorem 3 in their paper which was associated with the attack in an asynchronous network is incorrect. Lein Harn |
IET Inf. Secur. | 1 |
| 2014 | Multilevel threshold secret sharing based on the Chinese Remainder Theorem
Lein Harn, Fuyou Miao 0001 |
Inf. Process. Lett. | 1 |
| 2014 | Secure secret reconstruction and multi-secret sharing schemes with unconditional securityabstractABSTRACT In Shamir's (t,n) secret sharing (SS) scheme, the secretsis divided intonshares by a dealer and is shared amongnshareholders in such a way that anytor more thantshares can reconstruct this secret; but fewer thantshares cannot obtain any information about the secrets. In this paper, we will introduce the security problem that an adversary can obtain the secret when there are more thantparticipants in Shamir's secret reconstruction. Asecure secret reconstruction scheme, which prevents the adversary from obtaining the secret is proposed. In our scheme,Lagrange components, which are linear combination of shares, are used to reconstruct the secret. Lagrange component can protect shares unconditionally. We show that this scheme can be extended to design a multi‐secret sharing scheme. All existing multi‐secret sharing schemes are based on some cryptographic assumptions, such as a secure one‐way function or solving the discrete logarithm problem; but, our proposed multi‐secret sharing scheme is unconditionally secure. Copyright © 2013 John Wiley & Sons, Ltd. Lein Harn |
Secur. Commun. Networks | 1 |
| 2014 | Verifiable secret sharing based on the Chinese remainder theoremabstractABSTRACT A (t,n) secret sharing scheme (SS) enables a dealer to divide a secret into n shares in such a way that (i) the secret can be recovered successfully with t or more than t shares, and (ii) the secret cannot be recovered with fewer than t shares. A verifiable secret sharing scheme (VSS) has been proposed to allow shareholders to verify that their shares are generated by the dealer consistently without compromising the secrecy of both shares and the secret. So far, there is only one secure Chinese remainder theorem‐based VSS using the RSA assumption. We propose a Chinese remainder theorem‐based VSS scheme without making any computational assumptions, which is a simple extension of Azimuth–Bloom (t,n) SS. Just like the most well‐known Shamir's SS, the proposed VSS is unconditionally secure. We use a linear combination of both the secret and the verification secret to protect the secrecy of both the secret and shares in the verification. In addition, we show that no information is leaked when there are fewer than t shares in the secret reconstruction. Copyright © 2013 John Wiley & Sons, Ltd. Lein Harn, Fuyou Miao 0001, Chin-Chen Chang 0001 |
Secur. Commun. Networks | 1 |
| 2014 | Secure universal designated verifier identity-based signcryptionabstractABSTRACT In 2003, Steinfeld et al. introduced the notion of universal designated verifier signature (UDVS), which allows a signature holder, who receives a signature from the signer, to convince a designated verifier whether he is possession of a signer's signature; at the same time, the verifier cannot transfer such conviction to anyone else. These signatures devote to protect the receiver's privacy, that is, the receiver may want to prove to any designated verifier who he is in possession of such signature signed by the known signer but reluctant to disclose it. Moreover, the receiver also does not want the verifier to be able to convince anyone that he is in possession of such signature. In the existing UDVS schemes, a secure channel is required between the signer and the signature holder to transfer the signature. This paper, for the first time, proposes the notion of universal designated verifier signcryption without this secure channel by combining the notions of UDVS and signcryption. We give the formal definitions and a concrete construction of universal designated verifier identity‐based signcryption scheme. We also give the formal security proofs for our scheme under the random oracle model. Copyright © 2013 John Wiley & Sons, Ltd. Changlu Lin, Pinhui Ke, Lein Harn, Shengyuan Zhang |
Secur. Commun. Networks | 4 |
| 2014 | Simulatable and secure certificate-based threshold signature without pairingsabstractABSTRACT We propose the notion and define the security model of a certificate‐based threshold signature. The model is a general model that allows both the master secret key and user secret keys to be determined and distributed to the corresponding participators. Furthermore, the model can be easily converted into an identity‐based (ID‐based) threshold signature model to solve the key escrow problem and can be converted into a certificateless threshold signature model. In addition, we propose a secure and efficient certificate‐based threshold signature scheme. Compared with previous ID‐based threshold signature and certificateless threshold signature, our scheme requires no computation of pairings and no trusted dealer. In addition, in our proposed scheme, unlike most schemes that require all members to jointly generate a certificate or a signature, it only requirestor more thantmembers to generate a certificate or a signature. Our proposed scheme can detect dishonest participants as well. Therefore, our scheme is more practical than existing schemes. We show that our scheme is existentially unforgeable against adaptive chosen message attacks under the discrete logarithm assumption. Copyright © 2013 John Wiley & Sons, Ltd. Feng Wang 0020, Chin-Chen Chang 0001, Lein Harn |
Secur. Commun. Networks | 3 |
| 2013 | Verifiable symmetric polynomial-based key distribution schemesabstractABSTRACT Symmetric polynomial‐based key distribution scheme has been widely adopted in various communication applications. This type of key distribution consists of a server and a set of users, where the server is responsible to distribute shares for each user via a symmetric polynomial. Based on the property of symmetry of this polynomial, each pair of users can compute a common secret key using their shares for establishing a secure communication channel. However, some users may receive faulty shares from the server because of some uncertain factors in the communication environment, such as software failures and transmission errors. As a result, the users who receive faulty shares cannot share common secret keys with other users. To solve this problem, in this paper, we propose two individual verifiable key distribution schemes on the basis of a symmetric polynomial based key distribution. In both our proposed schemes, the server adopts the same approach to distribute shares for users; the users are able to verify the validity of their shares without revealing them before establishing communication channels. If all shares are verified valid, users can ensure that each pair of them possesses a common secret key, they can establish secure communication channels when needed; otherwise, all users can collaborate to identify those users who possess faulty shares and require the server to distribute a set of valid shares for those users. Furthermore, both our proposed schemes are efficient, because the procedures of verification and identification do not involve any complicated cryptographic operation. Copyright © 2012 John Wiley & Sons, Ltd. Yan-Xiao Liu 0001, Yuqing Zhang 0001, Lein Harn, Yupu Hu |
Secur. Commun. Networks | 3 |
| 2013 | Group AuthenticationabstractA new type of authentication, call group authentication, which authenticates all users belonging to the same group is proposed in this paper. The group authentication is specially designed for group-oriented applications. The group authentication is no longer a one-to-one type of authentication as most conventional user authentication schemes which have one prover and one verifier; but, it is a many-to-many type of authentication which has multiple provers and multiple verifiers. We propose a basic t-secure m-user n-group authentication scheme ((t, m, n) GAS), where t is the threshold of the proposed scheme, m is the number of users participated in the group authentication, and n is the number of members of the group, which is based on Shamir's (t, n) secret sharing (SS) scheme. The basic scheme can only work properly in synchronous communications. We also propose asynchronous (t, m, n) GASs, one is a GAS with one-time authentication and the other is a GAS with multiple authentications. The (t, m, n) GAS is very efficient since it is sufficient to authenticate all users at once if all users are group members; however, if there are nonmembers, it can be used as a preprocess before applying conventional user authentication to identify nonmembers. Lein Harn |
IEEE Trans. Computers | 1 |
| 2013 | An Efficient Threshold Anonymous Authentication Scheme for Privacy-Preserving CommunicationsabstractAnonymous authentication enables any user to be authenticated without being identified. (t,n)-threshold ring signatures, introduced by Bresson et. al., are ring signature schemes that allow a group of t members to jointly sign a message anonymously in a ring of n members. Threshold ring signature schemes provide a nice tradeoff between anonymity and creditability since it allows multiple ring members to sign a message jointly. The complexity in both signature generation and signature verification of the threshold ring signature scheme proposed by Bresson et. al. is O(n2). They also proposed an efficient threshold ring signature scheme based on an (n,t)-complete fair partition, with complexity O(n log n). In this paper, a new efficient (t,n)-threshold ring signature scheme is proposed. This scheme is constructed through a system of t linear equations and n variables, where t is generally a fixed number that is much smaller than n. The proposed threshold ring signature scheme can provide unconditional signer ambiguity, threshold unforgeability and provable security in the random oracle model. The complexity of signature generation and signature verification of the proposed threshold ring signature scheme are O(t log22t) and O(n), respectively. Furthermore, the length of the threshold ring signature is the same as the regular ring signature introduced by Rivest et. al., which is 2n+2, while the length of the threshold ring signature scheme proposed by Bresson et. al. is 3n-t+3. Jian Ren 0001, Lein Harn |
IEEE Trans. Wirel. Commun. | 2 |
| 2012 | Efficient (n, t, n) secret sharing schemes
Yan-Xiao Liu 0001, Lein Harn, Ching-Nung Yang, Yuqing Zhang 0001 |
J. Syst. Softw. | 2 |
| 2012 | $k$ Out of $n$ Region Incrementing Scheme in Visual CryptographyabstractRecently, Wang introduced a novel (2,n) region incrementing visual cryptographic scheme (RIVCS), which can gradually reconstruct secrets in a single image with multiple security levels. In RIVCS, the secret image is subdivided into multiple regions in such a way that anytshadow images, where 2 ≤t≤n, can be used to reveal the (t-1) th region. However, Wang's scheme suffers from the incorrect-color problem, which the colors of reconstructed images may be reversed (i.e., the black and white are reversed). If the color of text is also the secret information, the incorrect-color problem will compromise the secret. Additionally, Wang's scheme is only suitable for the 2-out-of-ncase, i.e., (k,n)-RIVCS wherek=2. In this paper, we propose a general (k,n)-RIVCS, wherekandnare any integers, that is able to reveal correct colors of all regions. This paper has made three main contributions: 1) our scheme is a general (k,n)-RIVCS, wherekandncan be any integers; 2) the incorrect-color problem is solved; and 3) our (k,n)-RIVCS is theoretically proven to satisfy the security and contrast conditions. Ching-Nung Yang, Hsiang-Wen Shih, Chih-Cheng Wu, Lein Harn |
IEEE Trans. Circuits Syst. Video Technol. | 4 |
| 2011 | Fully Deniable Message Authentication Protocols Preserving ConfidentialityabstractAlthough the objective of secure communication can be achieved by using cryptographic tools, the undeniability that results from cryptographic properties may create a potential threat to the sender of the message. Unfortunately, most existing deniable protocols only provide 1-out-of-2 deniability. When both parties (the sender and the receiver) are allowed to deny generating the message, a dispute might occur between these two parties. The 1-out-of-2 deniable protocol can result in an unfair resolution of the dispute. Therefore, we propose a new model of deniability, called 1-out-of-∞ deniability, that can provide full deniability. The 1-out-of-∞ deniability protocol allows the originator of the message to deny that he or she generated the message, since there are an infinite number of possible message generators; at the same time, all transmitted messages can be protected and authenticated between the sender and the intended receiver. Our design can be implemented by using any public-key cryptography technique. We also analyze the correctness of the proposed protocols based on logical rules, and two practical examples are given to illustrate our design. Lein Harn, Chia-Yin Lee, Changlu Lin, Chin-Chen Chang 0001 |
Comput. J. | 1 |
| 2011 | Generalized Digital Certificate for User Authentication and Key Establishment for Secure CommunicationsabstractPublic-key digital certificate has been widely used in public-key infrastructure (PKI) to provide user public key authentication. However, the public-key digital certificate itself cannot be used as a security factor to authenticate user. In this paper, we propose the concept of generalized digital certificate (GDC) that can be used to provide user authentication and key agreement. A GDC contains user's public information, such as the information of user's digital driver's license, the information of a digital birth certificate, etc., and a digital signature of the public information signed by a trusted certificate authority (CA). However, the GDC does not contain any user's public key. Since the user does not have any private and public key pair, key management in using GDC is much simpler than using public-key digital certificate. The digital signature of the GDC is used as a secret token of each user that will never be revealed to any verifier. Instead, the owner proves to the verifier that he has the knowledge of the signature by responding to the verifier's challenge. Based on this concept, we propose both discrete logarithm (DL)-based and integer factoring (IF)-based protocols that can achieve user authentication and secret key establishment. Lein Harn, Jian Ren 0001 |
IEEE Trans. Wirel. Commun. | 1 |
| 2010 | Efficient On-line/Off-line Signature Schemes Based on Multiple-Collision Trapdoor Hash FamiliesabstractThe first on-line/off-line signature scheme introduced by Even et al. in 1990 has two problems: (a) impractical signature length and (b) a one-time use of signature generated during the off-line phase. In 2001, Shamir and Tauman significantly shortened the length of the signature by using trapdoor hash families introduced by Krawczyk and Rabin in 2000. However, each trapdoor hash value and its signature in the off-line phase of Shamir and Tauman's signature scheme can be used for signing only one message in the on-line phase. In this paper, we propose multiple-collision trapdoor hash families based on discrete logarithm and factoring assumptions, and provide formal proofs of their security. We also introduce an efficient on-line/off-line signature scheme based on our proposed trapdoor hash families. Our on-line/off-line signature scheme can re-use a trapdoor hash value for signing multiple messages. If a signer includes this trapdoor hash value in the public-key digital certificate, there is no need to have any regular digital signature scheme to sign the trapdoor hash value in the off-line phase. Lein Harn, Wen-Jung Hsin, Changlu Lin |
Comput. J. | 1 |
| 2010 | Distributed security for multi-agent systems - review and applicationsabstractAs two major communication technologies, the internet and wireless, are maturing rapidly to dominate our civilised life, the authors urgently need to re-establish users’ confidence to harvest new potential applications of large-scale distributed systems. Service agents and distributed multi-agent systems (MASs) have shown the potential to help with this move as the lack of trust caused by heavily compromised security issues and concerns coupled with the out-of-date solutions are hindering the progress. The authors therefore seek new remedies to ensure that the continuity in developing new economies is maintained through building new solutions to address today's techno-economical problems. Following a scan of the literature the authors discuss the state-of-the-art progress followed by some observations and remarks for the researchers in the field. Here the authors recognise the need for new ‘distributed security’ solutions, as an overlay service, to rejuvenate and exploit the distributed artificial intelligence (AI) techniques for secure MAS as a natural solution to pave the way to enable a long awaited application paradigm of the near future. Habib F. Rashvand, Khaled Salah 0001, José M. Alcaraz Calero, Lein Harn |
IET Inf. Secur. | 4 |
| 2010 | Strong (n, t, n) verifiable secret sharing scheme
Lein Harn, Changlu Lin |
Inf. Sci. | 1 |
| 2010 | Authenticated Group Key Transfer Protocol Based on Secret SharingabstractKey transfer protocols rely on a mutually trusted key generation center (KGC) to select session keys and transport session keys to all communication entities secretly. Most often, KGC encrypts session keys under another secret key shared with each entity during registration. In this paper, we propose an authenticated key transfer protocol based on secret sharing scheme that KGC can broadcast group key information to all group members at once and only authorized group members can recover the group key; but unauthorized users cannot recover the group key. The confidentiality of this transformation is information theoretically secure. We also provide authentication for transporting this group key. Goals and security threats of our proposed group key transfer protocol will be analyzed in detail. Lein Harn, Changlu Lin |
IEEE Trans. Computers | 1 |
| 2009 | Ideal Perfect Multilevel Threshold Secret Sharing SchemeabstractShamir proposed the first (t, n) threshold secret sharing scheme. Shamir's scheme is ideal and perfect. In this paper, we propose two modifications of Shamir's secret sharing scheme. In our first modification, each shareholder keeps both x-coordinate and y-coordinate of a polynomial as private share. In our second modification, dealer uses polynomial with degree larger than the threshold value t to generate shares for a (t, n) threshold scheme. We show that these two modified schemes are ideal and perfect. Using these two modifications, we design a multilevel threshold secret sharing schemes (MTSS). We prove that the proposed scheme is secure. Changlu Lin, Lein Harn, Dingfeng Ye |
IAS | 2 |
| 2009 | Information-theoretically Secure Strong Verifiable Secret Sharing
Changlu Lin, Lein Harn, Dingfeng Ye |
SECRYPT | 2 |
| 2009 | Detection and identification of cheaters in ( t , n ) secret sharing scheme
Lein Harn, Changlu Lin |
Des. Codes Cryptogr. | 1 |
| 2009 | Design of DL-based certificateless digital signatures
Lein Harn, Jian Ren 0001, Changlu Lin |
J. Syst. Softw. | 1 |
| 2008 | An Improved Time-Bound Hierarchical Key Assignment SchemeabstractRecently, Chien [1] proposed a time-bound hierarchical key assignment scheme based on tamper-resistant devices. Chein's scheme greatly reduces computation load and implementation cost. However, it has a security weakness against X. Yi's three-party collusion attack [2]. In this paper, we improved Chien's scheme without public key cryptography and our scheme is resistant to X. Yi's three-party collusion attack. The most important is that our scheme is as efficient as Chein's. Finally, we have made an experiment to verify our conclusion. Mingxing He, Lein Harn |
APSCC | 3 |
| 2008 | Efficient identity-based RSA multisignatures
Lein Harn, Jian Ren 0001 |
Comput. Secur. | 1 |
| 2008 | Generalized Ring SignaturesabstractRing signature was first introduced in 2001. In a ring signature, instead of revealing the actual identity of the message signer, it specifies a set of possible signers. The verifier can be convinced that the signature was indeed generated by one of the ring members, however, she is unable to tell which member actually produced the signature. In this paper, we propose a generalized ring signature scheme and a generalized multi-signer ring signature based on the original ElGamal signature scheme. The proposed ring signature can achieve unconditional signer ambiguity and is secure against adaptive chosen-message attacks in the random oracle model. Comparing to ring signature based on RSA algorithm, the proposed generalized ring signature scheme has three advantages: (1) all ring members can share the same prime number and all operations can be performed in the same domain; (2) by combining with multi-signatures, we can develop the generalized multi-signer ring signature schemes to enforce cross-organizational involvement in message leaking. It may result in a higher level of confidence or broader coverage on the message source; and (3) the proposed ring signature is a convertible ring signature. It enables the actual message signer to prove to a verifier that only she is capable of generating the ring signature. Jian Ren 0001, Lein Harn |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2006 | An Improved Free-Roaming Mobile Agent Security Protocol against Colluded Truncation AttacksabstractThis paper proposes an improved free-roaming mobile agent security protocol. The scheme uses "one hop backwards and two hops forwards" chain relation as the protocol core to implement the generally accepted mobile agent security properties. This scheme defends most known attacks, especially colluded truncation attacks and several special cases Darren Xu, Lein Harn, Mayur Narasimhan, Junzhou Luo |
COMPSAC (2) | 2 |
| 2006 | Ring Signature Based on ElGamal Signature
Jian Ren 0001, Lein Harn |
WASA | 2 |
| 2005 | RINK-RKP: a scheme for key predistribution and shared-key discovery in sensor networksabstractEfficient schemes for key predistribution and shared-key discovery play a vital role in security and efficiency of pairwise key establishment in sensor networks. In this paper, we propose a scheme for key predistribution using hash-chain and subsequent shared-key discovery. We show potential active attacks on sensor networks due to key predistribution which can have severer consequences as compared to attacks described in existing proposals. We also show that as compared to the existing schemes, our scheme is more resilient to these active attacks. Manish Mehta 0003, Dijiang Huang, Lein Harn |
IPCCC | 3 |
| 1999 | Public-key cryptosystems based on cubic finite field extensionsabstractThe cryptographic properties of third-order linear feedback shift-register (LFSR) sequences over GF(p) are investigated. A fast computational algorithm for evaluating the kth term of a characteristic sequence of order 3 is presented. Based on these properties, a new public-key distribution scheme and an RSA-type encryption algorithm are proposed. Their security, implementation, information rate, and computational cost for the new schemes are discussed. Guang Gong, Lein Harn |
IEEE Trans. Inf. Theory | 2 |
| 1995 | Authentication Protocols for Personal Communication SystemsabstractMasquerading and eavesdropping are major threats to the security of wireless communications. To provide proper protection for the communication of the wireless link, contents of the communication should be enciphered and mutual authentication should be conducted between the subscriber and the serving network. Several protocols have been proposed by standards bodies and independent researchers in recent years to counteract these threats. However, the strength of these protocols is usually weakened in the roaming environment where the security breach of a visited network could lead to persistent damages to subscribers who visit. The subscriber's identity is not well protected in most protocols, and appropriate mechanisms solving disputes on roaming bills are not supported either. To solve these problems, new authentication protocols are proposed in this paper with new security features that have not been fully explored before. Hung-Yu Lin, Lein Harn |
SIGCOMM | 2 |
| 1995 | Fair Reconstruction of a Secret
Hung-Yu Lin, Lein Harn |
Inf. Process. Lett. | 2 |
| 1994 | A Protocol for Establishing Secure Communication Channels in a Large NetworkabstractKnowledge exchange and information access in a truly distributed network often require transmitting of data through open media. Consequently, data presented through such an environment are vulnerable to attacks. To minimize such vulnerability, data transformation or encryption/decryption techniques are often utilized among senders and receivers to achieve secure communication. Since data encryption/decryption requires sharing of a secret session key, finding an efficient way to distribute the session key in a large-scale, truly distributed network has been a nontrivial task. This paper presents a protocol for efficiently distributing session keys in such an environment to establish a secure channel. We assume the target network consists of many locally trusted centers, and each center has many users attached to it. The scheme incorporates the public-key distribution concept and the RSA encryption scheme as the basic mathematical tools, but eliminates the storage problem associated with huge public-key files. In addition, the proposed scheme has the added feature of providing the authenticate session key to the two parties in a secure communication.> Lein Harn |
IEEE Trans. Knowl. Data Eng. | 1 |
| 1993 | ID-Based Cryptographic Schemes for User Identification, Digital Signature, and Key DistributionabstractIn 1984, A. Shamir introduced the concept of an identity-based cryptosystem. In this system, each user needs to visit a key authentication center (KAC) and identify himself before joining a communication network. Once a user is accepted, the KAC will provide him with a secret key. In this way, if a user wants to communicate with others, he or she only needs to know the identity of his communication partner and the public key of the KAC. There is no public file required in this system. However, Shamir did not succeed in constructing an identity-based cryptosystem, but only in constructing an identity-based signature scheme. The authors here propose three identity-based cryptographic schemes based on the discrete logarithm problem: the user identification scheme, the digital signature scheme, and the key distribution scheme. The schemes are based on the digital signature scheme of G.B. Agnew et al. (1990), which is reviewed.> Lein Harn, Shoubao Yang |
IEEE J. Sel. Areas Commun. | 1 |
| 1993 | Key management for decentralized computer network servicesabstractThe authors propose an efficient scheme for key management, incorporating smart card technology and the master key concept, for both users and providers in multiservice environments over a large-scale network. This scheme has the following features. Every service can handle its own authentication and administration. Every user has a smart card with a single master key. The service keys can be regenerated within the card in a very secure manner. Users can also update their master keys by themselves without third-party intervention. As there is no need for storing any user password in the service center (except, perhaps, for a user PIN number), security is greatly enhanced.> Lein Harn, Hung-Yu Lin |
IEEE Trans. Commun. | 1 |
| 1992 | An l-Span Generalized Secret Sharing Scheme
Lein Harn, Hung-Yu Lin |
CRYPTO | 1 |
| 1992 | A software authentication system for information integrity
Lein Harn, Hung-Yu Lin, Shoubao Yang |
Comput. Secur. | 1 |
| 1991 | On Oblivious Transfer Protocol and Its Application for the Exchange of Secrets
Lein Harn, Hung-Yu Lin |
ASIACRYPT | 1 |
| 1991 | Generalized Threshold Cryptosystems
Chi-Sung Laih, Lein Harn |
ASIACRYPT | 2 |
| 1991 | Two Efficient Server-Aided Secret Computation Protocols Based on the Addition Sequence
Chi-Sung Laih, Sung-Ming Yen, Lein Harn |
ASIACRYPT | 3 |
| 1991 | A Generalized Secret Sharing Scheme With Cheater Detection
Hung-Yu Lin, Lein Harn |
ASIACRYPT | 2 |
| 1990 | Entropy as a measure of database informationabstractAn estimate of the information a database contains and the quantification of the vulnerability of that database to compromise by inferential methods is discussed. Such a measure could be used to evaluate the deterrent value of extant protection methods and provide a measure of the potential for inferential compromise through the use of one of the known attack tools. The authors explore the use of the concept of entropy as defined for information by C.E. Shannon (1948; 1951), for the purpose of quantifying information content in a database and develop a measure of vulnerability based on entropy. Use of the measure, when exact disclosure through the use of a tracker is anticipated, is characterized for both static and dynamic databases at design and operational time.> Elizabeth A. Unger, Lein Harn, Vijay Kumar 0002 |
ACSAC | 2 |
| 1990 | A cryptographic key generation scheme for multilevel data security
Lein Harn, Hung-Yu Lin |
Comput. Secur. | 1 |
| 1990 | An Efficient Probabilistic Encryption Scheme
Lein Harn, Thomas Kiesler |
Inf. Process. Lett. | 1 |
| 1989 | An extended cryptographic key generation scheme for multilevel data securityabstractS. Akl and P. Taylor (Proc. Crypto-82, p.237-250, 1982) proposed an elegant solution to the multilevel key distribution problem, using a cryptographic approach. In the present work, two problems associated with the Akl-Taylor scheme are considered. First, a time-memory tradeoff technique to overcome the problem of the extremely large memory space required by the Akl-Taylor scheme is proposed. Second, an extended scheme that localizes within a small region as much as possible the inserting/deleting problem associated with the Akl-Taylor scheme is proposed.> Lein Harn, Yaw-Ruey Chien, Thomas Kiesler |
ACSAC | 1 |
| 1989 | Two new efficient cryptosystems based on Rabin's scheme: alternatives to RSA cryptosystemabstractProposes two distinct cryptosystems based on Rabin's scheme. The first incorporates coding theory and provides encryption only. The second provides simultaneously both private encryption and digital signature for network users. In the cases where the second scheme provides only encryption or only digital signature, the scheme provides that the bit ratio between plaintext and ciphertext is 1:1, i.e. equivalent to that of the RSA scheme.> Lein Harn, Thomas Kiesler |
ACSAC | 1 |
| 1989 | Dynamic Threshold Scheme Based on the Definition of Cross-Product in an N-Dimentional Linear Space
Chi-Sung Laih, Lein Harn, Jau-Yien Lee, Tzonelih Hwang |
CRYPTO | 2 |
| 1989 | Password Authentication Based On Public-Key Distribution CryptosystemabstractA password authentication mechanism based on the public-key distribution cryptosystem is proposed. The scheme uses an authentication table to replace the traditional password file. With this scheme, even if the authentication table is comprised, the system security is preserved. The user's password is effectively bound to the user's identification in a timely, efficient, and simple manner.> Lein Harn, Chi-Sung Laih |
ICDE | 1 |
| 1989 | A New Scheme for ID-Based Cryptosystems and SignatureabstractA novel ID-based cryptographic scheme for implementing a public-key cryptosystem and signature is proposed. Instead of generating and publishing a public key for each user, the ID-based scheme permits each user to choose his/her name or network address as his/her public key. This eliminates the needs of a large public field and the exchange of private or public keys. The major advantage of the ID-based cryptosystem based on this scheme over other published ID-based cryptosystems is that the number of users can be extended to t*L users without degrading the system's security even when users conspire, where L is the number of the system's secrets, and t is the number of factors in p-1, where p is a large prime number.> Chi-Sung Laih, Jau-Yien Lee, Lein Harn, Chin-Hsing Chen |
INFOCOM | 3 |
| 1989 | Authenticated Group Key Distribution Scheme for a Large Distributed NetworkabstractThe authors propose a decentralized key distribution scheme. In this scheme, there are as many local key centers as needed and each user needs to select a key center at which to register when first joining the network. The most significant feature of the method is that each center needs only a single secret key. All personal keys that it needs for delivering encrypted keys to groups of users can be derived from this single key through a one-way function.> Lein Harn, Thomas Kiesler |
S&P | 1 |
| 1989 | A new threshold scheme and its application in designing the conference key distribution cryptosystem
Chi-Sung Laih, Jau-Yien Lee, Lein Harn |
Inf. Process. Lett. | 3 |
| 1989 | Linearly shift knapsack public-key cryptosystemabstractTwo algorithms are proposed to improve the Merkle-Hellman knapsack public-key cryptosystem. an approach to transform a superincreasing sequence to a high-density knapsack sequence is proposed. The algorithm is easy to implement and eliminates the redundancy of many knapsack cryptosystems. A linear shift method is used to improve the security of the knapsack public-key cryptosystem. It is shown that several knapsacks (e.g., the so-called useless knapsack), which cannot be generated by using the Merkle-Hellman scheme, can be generated by the linear shift method. Thus A. Shamir's (1982, 1984) attack to the original knapsack, as well as the low-density attack to the iterated knapsack, cannot be applied to this system successfully. It is interesting to note that the concept of the requirement of being one-to-one in practical enciphering keys is not necessary for this system.> Chi-Sung Laih, Jau-Yien Lee, Lein Harn, Yan-Kuin Su |
IEEE J. Sel. Areas Commun. | 3 |
| 1989 | On the Design of a Single-Key-Lock Mechanism Based on Newton's Interpolating PolynomialabstractA single-key-lock (SKL) mechanism used for implementing the access matrix of a computer protection system is proposed. The key selection is very flexible. The lock values are generated recursively using the Newton interpolating polynomial. A new user/file can be inserted into the system without recomputing all locks/keys. Since the computational load of the key-lock operation depends on the key positions in the access matrix, a user-hierarchy structure can be constructed for the mechanism. Thus, the smallest key value is assigned to a user who accesses the information resources more frequently than others, in order to reduce the average computation time. An example is included to illustrate this idea.> Chi-Sung Laih, Lein Harn, Jau-Yien Lee |
IEEE Trans. Software Eng. | 2 |
| 1988 | A conference key distribution system based on the Lagrange interpolating polynomialabstractA conference key distribution system (CKDS) can provide a common secret communication key to a set of M stations. A CKDS based on Lagrange interpolating polynomial is introduced. It is easy to see that breaking this system is equivalent to break the Diffie-Hellman public-key distribution system. This conference key is selected by the conference chairstation and hidden in the Lagrange interpolating polynomial. Recovering this key by each participating station only requires M-1 multiplications and M-2 additions over a finite field GF(P).> Erl-Huei Lu, Wen-Yie Hwang, Lein Harn, Jau-Yien Lee |
INFOCOM | 3 |