The diverse properties of wireless networks are fulfilled with the assistance of digital twin (DT), which utilizes a virtual model of the physical object (PO) to provide predictions and control decisions. However, the open wireless channels and key leakage of compromised entities (including DT and PO) pose significant security issues, highlighting the need for secure data transmission schemes. Meanwhile, it is impractical to directly apply the existing works and cryptographic primitives to DT-empowered wireless networks (DTWNs) due to the absence of a solution to capture the security requirements comprehensively. Moreover, the essential characteristics for protecting historical data cannot be met. Therefore, this paper proposes a security-enhanced data transmission scheme with fine-grained and flexible revocation by customizing a novel cryptographic primitive named forward-secure puncturable signed encryption (FS-PSE). Our scheme enables confidential data dissemination/acquisition between the physical and virtual space while ensuring authentication of the real-time information and feedback results. In addition, three revocation modes are defined. Based on these modes, the entities can flexibly revoke any decryption-&-signature, decryption, and signature capability in a fine-grained approach, thereby providing security protections for the historically transmitted data even though the entity is compromised. Moreover, our scheme is instantiated with a concrete FS-PSE construction and extended to support outsourced computing to improve efficiency. Finally, the formal security proof and performance evaluation demonstrate the security and practicality of our scheme.
Low Earth orbit satellite constellations with seamless network coverage and onboard computers enable autonomous on-orbit anomaly identification of remote wind turbines. However, they face several challenges. First, limited visible periods caused by orbital characteristics mandate that one satellite holds anomalies and the other collects surveillance data. Second, passively injected satellites could intercept and grasp onboard message flows. Third, a restricted onboard energy supply budget restrains intersatellite communications and onboard computations. With the above challenges, we propose a secure on-orbit anomaly identification (SOAI) scheme between a pair of satellites through an $\text{XOR}$ filter, which further exploits laconic private set intersection to eliminate false positives. The secure on-orbit anomaly querying scheme achieves the verifiable querying of anomalies derived from $\text{SOAI}$ . Comprehensive security analysis shows that the $\text{SOAI}$ scheme achieves confidentiality under a simulation-based real/ideal world model. Moreover, we compare the $\text{SOAI}$ scheme with two baseline schemes in terms of communication overheads and computational costs, and evaluation results show that our scheme outperforms the compared schemes, and our scheme is feasible in the OneWeb constellation near the polar regions.
The cloud-edge computing model has been expected to play a revolutionary role in promoting the quality of future generation large-scale Internet of Things (IoT) services. However, security and privacy in data sharing remain crucial issues hindering the success of cloud-edge IoT services. While some solutions based on attribute-based encryption (ABE) have been proposed to address these issues, they still face practical challenges such as attribute privacy leakage, resource-constrained devices, dynamic user groups, inflexible and inefficient service response. To address these challenges, this paper proposes a privacy-preserving fine-grained data sharing scheme with dynamic service (PF2DS), which implements access control by calculating the inner product between an attribute vector and an access vector. PF2DS is also capable of providing dynamic user group services through an efficient and indirect user revocation mechanism that periodically updates the key-embedded leaf nodes. Building on PF2DS, edge-assisted PF2DS (EPF2DS) delegates most of the operations to the edge device, which facilitates the performance of resource-constrained IoT devices. EPF2DS also supports efficient and asynchronous keyword search over the ciphertexts stored in the cloud. We demonstrate the security by the rigorous security proof. Both theoretical comparisons and experimental simulations demonstrate the practicality and superiority of our schemes over existing works.
Weighted set sampling has been proven essential for generating discrete numbers based on their weights and found broad applications in recommendation systems. The extension of this method, known as weighted range set sampling (WRSS), specifies a query range and applies weighted set sampling to the data within that range. With the proliferation of cloud computing, outsourcing encrypted data and data processing tasks to cloud servers has become a common practice to overcome data storage and processing challenges while protecting data privacy. Existing studies have proposed many privacy-preserving solutions for various customized query and data processing tasks, none have specifically addressed privacy-preserving WRSS. In response to this gap, our paper introduces an efficient and privacy-preserving WRSS scheme. We begin by leveraging the three-party secret sharing (TPSS) scheme as a foundation to design an enhanced three-party secret sharing (eTPSS) scheme with superior storage and computational efficiency. Building upon the eTPSS scheme, we introduce a series of private algorithms to safeguard WRSS privacy. Our scheme integrates the use of a binary search tree and the alias method for WRSS, ensuring privacy through eTPSS-based private algorithms. A thorough security analysis under the simulation-based real/ideal worlds model showcases the effectiveness of our proposed scheme. The proposed scheme's efficiency has been substantiated through extensive experiments, demonstrating that our scheme marks a significant advancement in addressing the challenges posed by privacy-preserving WRSS.
Outsourcing big data to cloud servers has gained prominence, and growing concerns about privacy, alongside privacy-related regulations, underscore the need to encrypt data before sending them to the cloud. Nevertheless, encryption significantly hampers the query capabilities of data, particularly in the case of vertically distributed data. This paper focuses on developing secure and efficient similarity query schemes for vertically distributed data in cloud environments. As is known, current solutions are constrained by limitations in query efficiency, approximate query results, and their ability to support vertical data. To address these issues, we introduce two novel schemes: a Fast Similarity Query Scheme (FSQ) and a Non-interactive Similarity Query Scheme (NoSQ) for outsourced distributed data. In the FSQ scheme, we enhance query efficiency by designing a trusted execution environment (TEE) assisted fast secret sharing (FSS) scheme and a series of FSS-based private algorithms, enabling secure data index construction and fast similarity query processing. For the NoSQ scheme, we eliminate communication overheads by designing a TEE assisted non-interactive secret sharing (NoSS) scheme and a series of NoSS-based private algorithms. Both schemes have undergone rigorous security validation using a simulation-based real/ideal worlds model, and their efficiency has been confirmed through comprehensive experiments.
Outsourcing decision tree models to cloud servers can allow model providers to distribute their models at scale without purchasing dedicated hardware for model hosting. However, model providers may be forced to disclose private model details when hosting their models in the cloud. Due to the time and monetary investments associated with model training, model providers may be reluctant to host their models in the cloud due to these privacy concerns. Furthermore, clients may be reluctant to use these outsourced models because their private queries or their results may be disclosed to the cloud servers. In this paper, we propose BloomDT, a privacy-preserving scheme for decision tree inference, which uses Bloom filters to hide the original decision tree's structure, the threshold values of each node, and the order in which features are tested while maintaining reliable classification results that are secure even if the cloud servers collude. Our scheme's security and performance are verified through rigorous testing and analysis.
The proliferation of intelligent connected vehicles (ICVs) has catalyzed the emergence of vehicular crowdsensing (VCS) applications, wherein sensing tasks are assigned to ICVs with abundant sensing resources and high mobility. To select workers whose future trajectories have sufficient spatio-temporal similarity with the target sensing area, workers unavoidably need to upload their trajectories to the VCS platform that is not fully trusted, thereby triggering location privacy concerns. Recently, numerous privacy-preserving worker selection schemes have been put forth. Nevertheless, they either fail to enable flexible arbitrary query ranges or incur substantial communication and computation costs, which severely limits their suitability for VCS applications. To tackle the above two issues simultaneously, we propose a novel efficient and privacy-preserving VCS worker selection scheme that supports flexible arbitrary spatial ranges. By utilizing the Bloom filter technique and lightweight cryptographic tools, our proposed scheme allows the VCS platform to efficiently collaborate with the fog server to compute the spatio-temporal similarity without leaking location-derived Bloom filters. Rigid security analysis shows that our scheme effectively preserves the location privacy of both workers and the query user. Extensive experiments are conducted and the results demonstrate that our scheme is significantly more efficient in both communication and computation compared with the state-of-the-art scheme.
The Industrial Internet of Things (IIoT) has brought practical application value to many industries, where significant amounts of IIoT data and resources are outsourced to cloud server (CS) via diverse networks for data fusion, monitoring, sharing, and calculation analysis. Considering privacy, there is a need to execute the encryption operation on the data before outsourcing, while how to retrieve the encrypted data from CS becomes a thorny issue. Furthermore, the untrusted CS in charge of storing and searching the ciphertexts may return incorrect or incomplete search results for some interest. Verifiable public key searchable encryption (VPKSE) provides the ability to encrypt data, retrieve ciphertext, and verify search results simultaneously. However, the malicious behavior of CS has not been sufficiently considered in most existing schemes, that is, their verifiability only ensures the correctness of search results, neglecting completeness. In this paper, the verifiability of VPKSE is re-examined, and three verifiability levels are defined detailedly. On this basis, a blockchain-assisted verifiable certificated-based searchable encryption (BVCBSE) scheme for IIoT is put forward. The integration of blockchain and cryptographic accumulator ensures that an untrusted CS must return correct and complete search results, achieving the highest level of verifiability. In addition, security analysis demonstrates that BVCBSE can resist keyword guessing attack. Performance evaluation illustrates that BVCBSE is efficient and practical.
Vehicular social networks (VSNs), as the convergence of social networks and vehicular ad hoc networks, have brought many useful services to vehicle communication by collecting and sharing data between vehicles. In order to efficiently share data and satisfy the growing requirement of privacy protection, data owners typically encrypt and outsource the data to the cloud. Nevertheless, encryption undoubtedly reduces the availability of shared data, e.g., keyword search. Although a number of schemes supporting keyword search of shared data have been put forward, they still have issues with respect to security, functionality, and efficiency. In this paper, a server-assisted data sharing (SADS) system with support for conjunctive keyword search is presented. Specifically, to resist online keyword guessing attack, we devise an advanced keyword derivation mechanism to derive the keyword set, in which the conception of verifiable parallel oblivious unpredictable function is proposed to check whether the assisted server honestly responds to the derived keyword request. Moreover, the computation and communication costs of keyword trapdoor in SADS are constant. Concurrently, SADS achieves the anonymous data sharing and traceability of malicious vehicle data owner. The security of SADS is formally proved and analyzed. Performance evaluation also shows that our system is efficient and practical.
Human-Object Interaction (HOI) detection, which aims to identify humans and objects with interactive behaviors in images and predict the behaviors between them, is of great significance for semantic understanding. The existing works primarily focus on exploring the fine-grained semantic features of humans and objects, as well as the spatial relationships between them. However, these methods do not leverage the contextual information within the interaction area, which could potentially be valuable for predicting interaction behavior. To investigate the impact of contextual information on behavior prediction, we propose a novel approach to extract both independent and interactive features and fuse them. Specifically, our method is capable of extracting interaction features from the interaction region. These features are then merged with fine-grained independent features of humans and objects. Finally, the fused features are utilized to predict interaction behavior. In addition, the feature fusion module does not add extra storage and computation costs to our method. Experiments demonstrate the effectiveness of our method, achieving state-of-the-art performance on two benchmark HOI datasets, namely HCO-DET and V-COCO.
The increasing prevalence of cloud computing drives the exploration of various secure query schemes over encrypted data, among which secure spatial keyword query has drawn a great deal of attention due to its broad application in location-based services. However, most existing schemes are either limited to the boolean keyword test or incapable of protecting access pattern privacy. Although the state-of-the-art secure spatial keyword query scheme can support keyword similarity while preserving access pattern privacy, it is unable to cope with the arbitrary spatial range, which is more general, and has limitations in efficiency and security. In this paper, we propose a new secure spatial keyword similarity query scheme that can support arbitrary spatial ranges and enhance the efficiency and security of the state-of-the-art scheme at the same time. Specifically, we first present a new homomorphic encryption technique by improving the popular symmetric homomorphic encryption (SHE). After that, we propose a novel approach to make supporting arbitrary spatial ranges over encrypted data possible, in which a spatial encoding technique is designed to improve performance. Finally, by designing a pack-based solution to protect access pattern privacy, our proposed scheme can hide the number of query results while optimizing performance. We formally prove the security of our proposed scheme and conduct experiments to evaluate its performance. The results indicate that our proposed scheme outperforms the state-of-the-art scheme in both the computational costs and communication overhead.
Big data have witnessed a growing trend towards vertically distributed storage, with various queries on vertically organized data recognized as effective means for unlocking data's inherent value. Several solutions have emerged for enabling privacy-preserving queries on vertically distributed data using secure multi-party computation techniques. However, these approaches often involve substantial communication overheads among data owners and place significant computational burdens on them, rendering them impractical for resource-constrained data owners. Outsourcing vertically distributed queries to the cloud can substantially alleviate the computational burdens on data owners, and efficient index construction is crucial for outsourced queries on vertical data. In light of this, we present the pioneering “Privacy-Preserving k-d Tree Building” (PTreeB) scheme for vertically distributed outsourced data in this study. Our scheme begins with the development of a private random dimension choosing algorithm (PCDim) and a private equality test (PET) algorithm, leveraging additive Paillier homomorphic encryption. Subsequently, these algorithms, along with various efficiency-enhancing strategies, including pre-sorting each data owner's data and adopting a dual-key system for data privacy protection, form the foundation of our PTreeB scheme. We rigorously demonstrate the security of our scheme, and its efficiency is validated through extensive experimentation.
As a practical machine learning method, the K-nearest neighbors (KNN) classification has received widespread attention. The achievement of the KNN classification relies heavily on a large amount of labeled data. However, in the real world, data is often held by different data owners. How to realize efficient joint computing among multiple data owners under the premise of protecting data security and privacy is an urgent problem to be solved. In this paper, we construct a secure multi-party KNN classification scheme (SecKNN) based on function secret sharing (FSS) technology, which is a novel cryptographic primitive and can achieve cheap communication and computation costs for secure computation. Compared with the existing works, our scheme dramatically reduces computational overhead and runs roughly 50.8 times faster than the state-of-the-art approach. Furthermore, our scheme supports the secure KNN classification under general distance functions such as Euclidean distance, Manhattan distance, and Hamming distance. To implement our SecKNN scheme, we design two efficient FSS schemes for Hamming distance function, which implements secure two-party and multi-party Hamming distance computation in a single round. They can be considered as independent research results. Finally, we give formal security proofs for the proposed protocols and validate the effectiveness and efficiency of our protocols through experiments.
The low-Earth orbit (LEO) satellite constellation holds immense potential for offshore wind farm surveillance since it can provide all-day and all-weather monitoring capabilities facilitated by satellite collaboration. However, it faces significant challenges. First, limited downlink transmission bandwidth constrained by ground stations and constraint on-orbit resources necessitate selective data downloads, focusing only on differences between consecutive data sets. Second, a passively injected satellite in open space poses a risk of unauthorized data extraction from neighboring satellites. Third, onboard energy constraints limit the feasibility of computationally intensive cryptographic operations. To tackle these challenges for the first time, we propose a novel secure and efficient on-orbit comparison (SEOC) scheme. Our solution begins with introducing a lightweight matrix encryption-based secure inner product (MSIP) technique tailored for secure on-orbit comparison. We further enhance communication efficiency by integrating a Cuckoo filter to reduce costs, complementing a novel difference comparison tree (DCTree) structure to manage false positives. Through comprehensive security analysis, the $\textsf {MSIP}$ technique achieves selective security, and the $\textsf {SEOC}$ scheme is secure under the universally composable (UC) framework. At last, performance evaluations demonstrate the high efficiency of our approach in terms of computational costs and communication overheads, which adapts to the limited on-orbit resources.
Geographic information system (GIS) enables operations for capturing, manipulating, analyzing, and displaying the spatial characteristics of objects on Earth's surface. As the objects in GISs are mostly location-dependent, various location privacy-preserving schemes are proposed to support the secure spatial query and analysis. However, existing location privacy-preserving mechanisms mainly focus on the $k$ -nearest neighbor ( $k$ NN) queries and range queries and fail to consider the practical geographic implementation with quad-trees. We propose an efficient and privacy-preserving point-of-interest (POI) query scheme along the movement trajectory under the quad-tree setup in a two-server mode. Specifically, we first convert the secure identification of the target lowest-level tile into a series of private information retrieval (PIR) processes and securely derive the target POIs along the movement trajectory within the identified tile by constructing a linear polynomial passing through the origin and destination for secure distance comparison. Our scheme also supports the efficient loading of POIs contained in the adjacent tiles with privacy preservation. Security analysis demonstrates that ours can achieve the security goals of privacy preservation and confidentiality. We execute performance evaluations to show and validate the system efficiency, i.e., computational costs and communication overheads.
The low Earth orbit (LEO) satellite edge computing paradigm provides remote sites with flexible, reliable, and scalable edge computing capabilities. Characterized by the orbital motion patterns and harsh space environments, the LEO satellite edge computing faces unique security challenges in terms of the secure collaboration of multiple satellites and the intellectual property protection of models. Under the unique space environment and security demands, we propose a secure satellite edge computing framework in this paper. By taking a remote electricity line outage identification use case as an example, our framework first achieves the secure delegation of the line outage identification task among multiple satellites, which is realized through a secure query $(\mathsf {SQuery})$ scheme to check the availability of the target time slot. Meanwhile, we also design a SHE-enabled secure inner-product encryption ( $\mathsf {SSIPE}$ ) protocol, to achieve the secure multinomial logistic regression (MLR) based line outage identification on-orbit. To reduce the complexity brought by the computationally intensive homomorphic multiplication between two ciphertexts, we further grasp the idea and design a “divide-and-conquer” based secure query ( $\mathsf {DSQuery}$ ) scheme, which converts this homomorphic multiplication operation between ciphertexts into the homomorphic addition operation. As far as we know, this is the first scheme investigating the secure task delegation among different satellites on-orbit. Besides, detailed security analyses are performed to demonstrate the security properties of confidentiality and authentication. In performance evaluations, we test and compare the computational and communication overhead of our scheme and other straightforward schemes. Simulation results show that the $\mathsf {DSQuery}$ scheme greatly reduces the computational cost, which saves the stringent on-orbit computation resources of LEO satellites.
Low Earth orbit (LEO) satellite constellations support intelligent driving applications in areas without terrestrial network coverage. As the LEO-satellite integrated vehicular network experiences dual mobility of satellites and vehicles, the mainstream IP-based mobility management protocols may not adapt to the dynamic network topology and violate location privacy. Given the above challenges, we propose a secure and privacy-preserving distributed location management (DMM) scheme in a LEO-satellite integrated vehicular network with dense ground stations. The proposed scheme achieves the privacy-preserving location update through a conditional privacy preservation protocol, which guarantees secure data delivery when the binding ground station changes before the periodic pseudonym update. Meanwhile, the proposed scheme achieves the privacy-preserving and multi-level data delivery with batch authentication. As our scheme is the first concerning location privacy in an LEO satellite constellation, we compare it with two competing schemes: the first without a Merkle hash tree and the second without a cuckoo filter. Simulation results show that ours outperforms the two competing schemes regarding computation costs and communication overhead. To balance the trade-off between privacy and complexity, we also formulate an objective function concerning the pseudonym update period and derive its optimal solution.
Digital Twin (DT) technology, by performing simulation, analysis, and prediction over the data mapped to digital space, can create a digital replica of the physical object. It can be combined with edge computing or cloud computing to provide broad vehicle-to-everything applications and improve the service quality of vehicular ad-hoc networks (VANETs). In this paper, DT technology and mobile edge computing are integrated into VANETs to introduce a framework of mobile digital twin edge network-driven VANETs (MDTEN-Driven VANETs). Moreover, facing the security and privacy challenges in the framework, we propose a synchronized privacy-preserving authentication (SPPA) scheme. In SPPA, we first design a synchronized anonymous certificateless aggregate signature (SA-CLAS) to achieve the authentication with time state synchronization and the privacy preservation of the real identity. Furthermore, to deal with malicious vehicles, we adopt blockchain technology and devise a smart contract algorithm to manage the public information of vehicles. The security analysis demonstrates that SA-CLAS is existentially unforgeable under adaptive chosen message attacks, and SPPA can satisfy the necessary security requirements. The performance evaluation shows the efficiency and practicality of SA-CLAS and SPPA. Besides, the designed smart contract is implemented in an Ethereum test network, which presents an acceptable blockchain consumption.
Big data and bursting cloud computing technologies have facilitated an increasing trend of outsourcing data-driven services to the cloud, where the reverse kNN (RkNN) query is a popularly outsourced query service. The RkNN query aims to retrieve objects having the query object as kNN and widely applied in the product recommendation. Considering privacy concerns, the outsourced query services are demanded to protect data privacy, and consequently a series of privacy-preserving query solutions have been put forth. Nevertheless, RkNN query over high-dimensional data has not been studied to date. In this work, we design the first efficient and privacy-preserving RkNN query scheme over encrypted high-dimensional data, named PHRkNN. Specifically, we first introduce a pivot filter condition for the RkNN query and utilize it to deliberately design a pivot filter R-tree (PFR-tree) to organize the high-dimensional dataset such that the RkNN query has sublinear query efficiency. Then, we propose our PHRkNN scheme by designing some homomorphic encryption based private algorithms and applying them to privately achieve PFR-tree based RkNN query. After that, we propose an oblivious PHRkNN scheme on the basis of the PHRkNN scheme by designing a private random tree permutation (PRTP) algorithm to protect the access pattern privacy. The security of our PHRkNN scheme and oblivious PHRkNN scheme is proved by the simulation-based security analysis. The performance is verified through computational costs and communication overheads evaluation.
Community search over graphs, which is believed as a powerful tool for locating subgraphs of closely related vertices, has received considerable attention in recent years, and $k$ -truss is such a popular community search metric to obtain subgraphs in which every edge forms $(k-2)$ triangles. In this paper, we particularly consider $k$ -truss community query services, which will return all $k$ -truss communities containing a given query vertex. As is known, when the size of graph grows, for achieving better performance, it is natural for a service provider to outsource the services to a powerful cloud. However, this stresses the need for privacy-preserving $k$ -truss community query services, as the cloud server is not fully trustable. Over the past years, many schemes focusing on privacy-preserving graph computation have been put forth, but none of them can well support privacy-preserving $k$ -truss community queries. Aiming at this challenge, we first propose a privacy-preserving $k$ -truss community query scheme ( $k$ TCQ) by constructing boolean circuits with homomorphic encryption technique and a table-based index. After that, we also design an efficiency-enhanced version ( $k$ TCQ+) based on a stream cipher scheme to reduce the encrypted index's size and improve the query efficiency. Detailed security analysis shows that both $k$ TCQ and $k$ TCQ+ can well preserve data privacy and access pattern privacy, and extensive experimental results also demonstrate that $k$ TCQ+ can observably reduce the size of encrypted index and the query time by $12\times$ and $5.9\times$ , respectively.
Ali A. Ghorbani合作论文数Faculty of Computer Science;UNB2