In resource-constrained environments such as IoT sensors and mobile devices, there is a strong demand for efficient conjunctive keyword search over privacy-sensitive data. However, existing schemes struggle to simultaneously suppress sterm equality leakage, the cross-query intersection pattern (IP), and the volume pattern without incurring prohibitive overhead. In this article, we present XORCMM, a practical volume-hiding encrypted multimap (EMM) designed for robust leakage suppression. First, we shift the index construction from single keywords to global-ordering co-occurrence pairs, which ensures that search tokens are no longer tied to static keyword identities, thereby suppressing sterm equality leakage. Second, we integrate an incremental multiset hash aggregation mechanism directly into a fully padded Xor filter (XF). This allows the server to aggregate multiple conjunctive results into a single, fixed-length response, concealing both IP and volume patterns while eliminating the data redundancy of prior schemes. Third, we employ a prefix-constrained PRF to compactly encode keyword pairs, generating succinct query tokens whose size is independent of keyword volumes. Formal security analysis proves that XORCMM is adaptively secure with sterm equality, IP, and volume leakages hidden. Experimental results demonstrate that XORCMM achieves up to a 2.99x speedup in client setup, a 3.3x speedup in server query time, and reductions of 47% in response size and 84.61% in search-token size, providing a stronger security guarantee with significantly higher efficiency.
This research proposes a dynamic resource allocation method for vehicle-to-everything (V2X) communications in the sixth generation (6G) cellular networks. Cellular V2X (C-V2X) communications empower advanced applications but at the same time bring unprecedented challenges in how to fully utilize the limited physical-layer resources, given the fact that most of the applications require both ultra low latency, high-data rate and high reliability. Resource allocation plays a pivotal role to satisfy such requirements as well as guarantee Quality of Service (QoS). Based on this observation, a novel fuzzy-logic-assisted $Q$ learning (FAQ) model is proposed to intelligently and dynamically allocate resources by taking advantage of the centralized allocation mode. The proposed FAQ model reuses the resources to maximize the network throughput while minimizing the interference caused by concurrent transmissions. The fuzzy-logic module expedites the learning and improves the performance of the $Q$ -learning. A mathematical model is developed to analyze the network throughput considering the interference. To evaluate the performance, a system model for V2X communications is built for urban areas, where various V2X services are deployed in the network. Simulation results show that the proposed FAQ algorithm can significantly outperform deep reinforcement learning, $Q$ -learning and other advanced allocation strategies regarding the convergence speed and the network throughput.
Searchable encryption is a technique that can support operations on encrypted data directly. However, searchable encryption is still vulnerable to attacks that exploit the leakages from encrypted query results. This paper presents an effective multi-server searchable encryption scheme to prevent volume and access pattern leakages. To hide the volume leakage of a keyword, a new index construction is proposed to compress multiple results into one index. To prevent the attacker from observing the access pattern of injected records, the update and search phases are executed in batches, such that the server can only retrieve multiple numbers of fixed volumes. To reduce the co-occurrence leakage, we propose our index distribution algorithm. Both records and queries are dispatched among cloud servers such that the attacker cannot recover the trapdoor values by only observing one cloud server. We use the minimum s−t cut algorithm to find the optimal assignment strategy that can diminish the query response time and the information disclosure at the same time. We formally analyze the security strengths and conduct evaluations. The experimental results indicate that our designs can strike a good balance between security and efficiency.
In last two years, universities around the world have been using hyflex teaching due to COVID-19. This allows students to attend physical/online lectures in a flexible manner. A hyflex class comprises classroom students as well as online students. In this paper, we present a model for hyflex classrooms that highlights 4Cs: Content, Collaboration, Community and Communication. Based on the 4C model, a hyflex classroom has been designed and implemented through various teaching/learning tools or elements. These include the effective use of presentation slides, annotations, chatbox, open education resources, multiple choice exercises, group exercises etc. The effectiveness of these tools/elements were evaluated by means of an initial student survey. These results provide valuable insights into hyflex teaching/learning.
In this paper, we spotlight vehicle-to-everything (V2X) communications in 5G cellular networks. Cellular V2X (C-V2X) communications in 5G enable more advanced services with requirements of ultra-low latency and ultra-high reliability. How to make full use of the limited physical-layer resources is a key determinant to guarantee the quality of service (QoS). Therefore, resource allocation plays an essential role in exchanging information between vehicles, infrastructure, and other devices. In order to intelligently and reasonably allocate resources, a self-adaptive fuzzy logic-based strategy is developed in this paper. To evaluate the network performance for this adaptive strategy, a system model for V2X communications is built for urban areas, and typical safety and non-safety services are deployed in the network. Simulation results reveal that the proposed fuzzy logic-based algorithm can substantially improve resource utilization and satisfy the requirements of V2X services, compared with prior counterparts, which cannot provide guaranteed services due to low resource utilization.
Recent years have seen considerable interest in mobile cloud computing and edge cloud computing. This paper presents a mobile Intercloud system for supporting mobile cloud computing in general and edge cloud computing in particular. In essence, a mobile user with a mobile terminal can set up a virtual mobile terminal with applications and data in a central/home cloud. The virtual mobile terminal can facilitate task and computation offloading and other functions. Moreover, when a mobile terminal joins an edge cloud, the virtual mobile terminal (including required applications and data) can be migrated to enhance system efficiency and the user experience (e.g., shorter access delays). An experimental prototype has been developed for evaluating certain basic object transfer functions. To support the application transfer function, we formulate both finite- and infinite-horizon Markov decision models to determine decision policies (i.e., should an application be transferred to an edge cloud). The transfer decision depends on various factors, including transfer cost, duration associated with the edge cloud, usage probability, and usage cost in the central cloud and edge cloud. Based on the models, we obtain closed-form solutions for the decision policies, which can be expressed in meaningful formulas to provide useful insights for edge cloud computing in general. To evaluate the mobile Intercloud system for edge cloud computing, we conducted extensive evaluations, including experimental evaluation for testing the basic functions and protocols, analytical evaluation for studying the analytical models, and simulation evaluation for analyzing performance in a multiuser and multicloud environment in particular. The experimental, simulation, and analytical results provide useful insights into the design and development of the mobile Intercloud system for edge cloud computing as well as decision policies for application transfer.
The vulnerabilities in cryptographic currencies facilitate the adversarial attacks. Therefore, the attackers have incentives to increase their rewards by strategic behaviors. Block withholding attacks (BWH) are such behaviors that attackers withhold blocks in the target pools to subvert the blockchain ecosystem. Furthermore, BWH attacks may dwarf the countermeasures by combining with selfish mining attacks or other strategic behaviors, for example, fork after withholding (FAW) attacks and power adaptive withholding (PAW) attacks. That is, the attackers may be intelligent enough such that they can dynamically gear their behaviors to optimal attacking strategies. In this paper, we propose mixed-BWH attacks with respect to intelligent attackers, who leverage reinforcement learning to pin down optimal strategic behaviors to maximize their rewards. More specifically, the intelligent attackers strategically toggle among BWH, FAW, and PAW attacks. Their main target is to fine-tune the optimal behaviors, which incur maximal rewards. The attackers pinpoint the optimal attacking actions with reinforcement learning, which is formalized into a Markov decision process. The simulation results show that the rewards of the mixed strategy are much higher than that of honest strategy for the attackers. Therefore, the attackers have enough incentives to adopt the mixed strategy.
With the increasing popularity of e-learning in higher education institutions, there is a need to develop data analytics tools to analyze e-learning data, student learning behavior and student performance. In recent years, there has been growing interest in educational data mining, which can provide useful insights into student learning behavior, providing holistic analysis. This paper presents an online data analytics tool called Studentlyzer, which applies data mining to analyze student data. It can cluster student datasets using K-means clustering, and visualize the graphical results through a web browser. Two real-world student e-learning datasets, the Open University Learning Analytics Dataset (OULAD) and Educational Processing Mining (EPM) dataset, were used to demonstrate Studentlyzer’s usefulness. The results provide valuable insights about students. In general, Studentlyzer can help identify students who are similar (e.g., with similar study behavior) and provide useful information about student performance and student behavior (e.g., their correlation).
With the advent of cloud computing, there is a potential need for the interconnection of clouds (i.e., Intercloud). Intercloud seeks to connect heterogeneous clouds together to form a network of clouds. As an extension to our previous work, this paper gives an overview of an Intercloud system with a focus on the Intercloud Gateways and Intercloud communications protocol. To analyze the performance of the Intercloud systems, we have conducted experiments under different settings and scenarios. Furthermore, we have evaluated the Intercloud system to support a mobile Intercloud application.
For cloud data storage, data privacy and security are two key concerns. Although sensitive data can be encrypted before they are stored in the cloud, the encrypted data can hardly be processed efficiently. Hence, a lightweight solution is required to satisfy both high security and high efficiency requirements. In this paper, we study the problem of range query over encrypted data. The main idea is to transform the range comparison to a privacy-preserving set intersection operation. To protect record privacy, our scheme builds searchable encrypted indexes for records that are secure against inference attack. To ensure the privacy of range queries, non-deterministic encryption, which has not been achieved in range query before, is proposed to hide the search pattern of queries. During range comparison, our scheme neither leaks the order relationship between the upper/lower bound of a range query and the encrypted index, nor produces false positives in the query results. We have implemented our scheme and evaluated its performance in comparison with other schemes. The comparison results indicate that our scheme has a shorter index size and search time than the order-revealing encryption (ORE) scheme when the processing unit is large. Meanwhile, our scheme only leaks the access pattern, and is proved to be more secure than existing schemes.
Searchable encryption seeks to support untrusted third parties to conduct direct searching over encrypted data. However, recent research has found that searchable encryption is vulnerable to attacks, which exploit the statistical relationship or pattern identified from encrypted query results. In this paper, we study the problem of access pattern leakage attack on searchable encryption under a multi-cloud environment. Basically, both database records and queries are distributed among different cloud servers, so that each cloud server can only have partial information about queries and their results. To minimize the query response time while protecting information disclosure, we formulate the record and query assignment as an optimization problem, and solve the problem (i.e., finding the best possible solution) by the minimum s - t cut algorithm. Numerical results show that on average 13% access pattern information can be saved by our assignment strategy while maintaining good query response time.
The convergence of Internet of Things, cloud computing, and wireless body-area networks (WBANs) has greatly promoted the industrialization of electronic/mobile-healthcare (e-/m-healthcare). However, the further flourishing of e-/m-healthcare still faces many challenges including information security and privacy preservation. To address these problems, a healthcare system (HES) framework is designed that collects medical data from WBANs, transmits them through an extensive wireless sensor network infrastructure, and finally, publishes them into wireless personal-area networks via a gateway. Furthermore, HES involves the groups of send-receive model scheme to realize key distribution and secure data transmission, the homomorphic encryption based on matrix scheme to ensure privacy, and an expert system able to analyze the scrambled medical data and feedback the results automatically. Theoretical and experimental evaluations are conducted to demonstrate the security, privacy, and improved performance of HES compared with current systems or schemes. Finally, the prototype implementation of HES is explored to verify its feasibility.
In recent years, there has been considerable interest in Intercloud. Inspired by the Internet, Intercloud allows clouds to be interconnected, forming a cloud/network of clouds. With Intercloud, many new and powerful cloud computing services can be provided. One of the basic problems with supporting Intercloud is the need to address the issue of how to ensure that clouds can communicate with each other effectively and efficiently. Inspired by the HyperText Transfer Protocol (HTTP), this paper presents an Intercloud Communications Protocol (ICCP). ICCP allows clouds to communicate with each other using a common protocol, which is transparent to the underlying application programming interfaces of different clouds. It also includes security functions to ensure confidentiality and integrity. Essentially, clouds can communicate with each other based on XML-based request/response messages in a secure manner. An Intercloud Gateway prototype has been developed to demonstrate the basic functionalities of the ICCP, such as transferring data objects securely. The proposed framework is expected to inspire innovative cloud computing services as well as pose challenging research problems.
在两层无线传感器网络查询过程中,攻击者可能破坏敏感数据的隐私性或者操纵被俘获的传感器节点,提交不完整或错误的查询结果.为此,提出了一种安全范围查询协议ZOSR,ZOSR在存储节点正确处理范围查询的同时,有效地保护数据的隐私性和查询结果的完整性.首先,将感知数据与查询范围上下界的两次比较过程,转换为感知数据与查询范围中值距离和查询范围半径值之间的一次比较过程.为了保护数据的隐私性,将待比较的数值进行Z-O编码,并与HMAC消息认证机制结合,使得ZOSR协议在共谋攻击的情况下,无法破坏网络中其他节点的隐私性.最后,为了实现查询结果的完整性验证,对于未满足查询条件的感知数据通过共享密钥构造其验证码.
Recently, secure query has become a significant issue for researchers. It proposes the concept of secure multi-party query in Internet of things or sensor networks making use of “underground parties” to guarantee network security. Based on a novel network model assumption, it adopts homomorphic privacy and secure multi-party computation techniques to realize the above mentioned secure query, and then it puts forward the horizontal and vertical query algorithm in the top-k query through cooperation of underground parties. Thereafter, by the simulation tests it compares the time efficiency of the proposed algorithm with other typical sort algorithms under different top-k scenarios. At last, it analyzes the relationship between query time and number of underground party nodes.
The best is to read these instructions and follow the outline of this text. This paper models and simulates the parking behaviors in a main commercial area in Peace Plaza, Dalian City. By analyzing the simulation results, we propose a feasible plan to solve the problem that some customers cannot find a parking space and there are too many illegal parking behaviors in this area. The simulation shows that it can effectively reduce the number of cars that can't find a parking space or illegally park by the road.
提出基于Jini的服务框架,打破设备的限制,增强服务的扩展能力,从而适应不断增长的应用需求.据此框架,本文实现了一个节能系统,以验证本框架的可用性.
Intercloud seeks to facilitate resource sharing among clouds. To support Intercloud, a trust evaluation framework among clouds and users is required. For trust evaluation, conventional protocols are typically based on a centralized architecture focusing on a one-way relationship. For Intercloud, the environment is highly dynamic and distributed, and relationships can be one-way or two-way ( i.e., clouds provide services to each other). This paper presents a distributed trust evaluation protocol with privacy protection for Intercloud. The new contributions and innovative features are summarized below. First, feedback is protected by homomorphic encryption with verifiable secret sharing. Second, to cater to the dynamic nature of Intercloud, trust evaluation can be conducted in a distributed manner and is functional even when some of the parties are offline. Third, to facilitate customized trust evaluation, an innovative mechanism is used to store feedback, such that it can be processed flexibly while protecting feedback privacy. The protocol has been proved based on a formal security model. Simulations have been performed to demonstrate the effectiveness of the protocol. The results show that even when half of the clouds are malicious or offline, by choosing suitable operational parameters the protocol can still support effective trust evaluation with privacy protection.