VLDB 2026 Research / reviewers in the wild / expert
Yuewu Wang
dblp:01/3425
· DBLP profile ↗
50ranked-venue papers
0as first author
21since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 34 · 14 since 2021Computer networks · 7 · 2 since 2021Systems, architecture and hardware · 5 · 4 since 2021Artificial intelligence and machine learning · 3Software engineering, systems software and programming languages · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Cross-Application Key Abuse Attack against Hardware-backed Android Keystore
Zeping Wu, Lingguang Lei, Pingjian Wang, Yuewu Wang, Xiaojuan Feng |
ICC | 4 |
| 2026 | FBRoT: Transforming Flash Memory into Root of Trust for IoT Terminals
Yuewu Wang, Lingguang Lei, Shijie Jia 0001, Jiwu Jing |
SECON | 3 |
| 2026 | Using Learning with Rounding to Instantiate Post-Quantum Cryptographic AlgorithmsabstractThe Learning with Rounding (LWR) problem, introduced as a deterministic variant of Learning with Errors (LWE), has become a promising foundation for post-quantum cryptography. This Systematization of Knowledge (SoK) article presents a comprehensive survey of the theoretical foundations, algorithmic developments, and practical implementations of LWR-based cryptographic schemes. We introduce LWR within the broader landscape of lattice-based cryptography and post-quantum security, highlighting its advantages such as reduced randomness, improved efficiency, and enhanced side-channel resistance. We explore the evolution of security reductions from LWR to LWE, including recent advances that support practical parameter regimes and address challenges in both bounded and unbounded sample settings. This article systematically reviews existing LWR-based schemes — including Saber, Lizard, Florete, Espada, Sable, and SMAUG — analyzing their design choices, parameter sets, and performance tradeoffs. Furthermore, we examine the impact of LWR on side-channel resistance, failure probabilities, and masking efficiency, demonstrating its suitability for secure and efficient implementations. By consolidating the research spanning theory and practice, this SoK aims at guiding future cryptographic design and standardization efforts leveraging LWR. Andrea Basso 0002, Joppe W. Bos, Jan-Pieter D'Anvers, Angshuman Karmakar, Jose Maria Bermudo Mera, Joost Renes, Sujoy Sinha Roy, Frederik Vercauteren, Peng Wang 0009, Yuewu Wang, Shicong Zhang, Chenxin Zhong |
ACM Trans. Embed. Comput. Syst. | 10 |
| 2025 | Mitigating the Unprivileged User Namespaces Based Privilege Escalation Attacks with Linux Capabilities
Jingzi Meng, Yuewu Wang, Lingguang Lei, Chunjing Kou, Peng Wang 0009, Huawei Lu |
ACISP (3) | 2 |
| 2025 | Tracing Your Roots: Exploring the Security Issues of Root Certificates in Android TLS Connections
Yuewu Wang, Lingguang Lei, Peng Wang 0009, Chunjing Kou |
Inscrypt (2) | 2 |
| 2025 | How to Recover the Full Plaintext of XCB
Peng Wang 0009, Shuping Mao, Ruozhou Xu, Jiwu Jing, Yuewu Wang |
CRYPTO (5) | 5 |
| 2025 | DEBridge: Towards Secure and Practical Plausibly Deniable Encryption Based on USB Bridge Controller
Chongyu Long, Yuewu Wang, Lingguang Lei, Haoyang Xing, Jiwu Jing |
ESORICS (2) | 2 |
| 2025 | CapAssess: An Endeavor to Assess and Enhance Linux Capabilities UtilizationabstractThe Linux capabilities mechanism divides the root privileges to provide more fine-grained access control, but its effectiveness depends on proper implementation and configuration. The scattered enforcement of capabilities in the kernel and its sporadic usage in programs pose challenges in gathering assessment information. To address this, we propose three tools for diagnosing potential problems in its design, implementation, and utilization. First, we employ LLVM/Clang to examine the capabilities enforcement in the kernel to map capabilities checks to files. This is the first attempt to explore the interaction between capabilities and other mechanisms, such as UGO. Second, We propose a pattern-based method to identify the sensitive kernel functions protected by capabilities, quanti-fying the overlap problem of capabilities. Third, we employ a customized fuzzing approach to determine the minimal set of capabilities required by programs, offering insight for secure usage. Additionally, Our study is further guided by international access management standards, providing structured criteria for the assessment. Leveraging data collected by our tools, we identify imperfections of capabilities and reported to stakeholders. To the best of our knowledge, this is the first systematic assessment of Linux capabilities. Jingzi Meng, Yuewu Wang, Lingguang Lei, Jiwu Jing, Pingjian Wang, Chunjing Kou, Peng Wang 0009 |
SANER | 2 |
| 2025 | AsyncGBP${}^{+}$+: Bridging SSL/TLS and Heterogeneous Computing Power With GPU-Based ProvidersabstractThe rapid evolution of GPUs has emerged as a promising solution for accelerating the worldwide used SSL/TLS, which faces performance bottlenecks due to its underlying heavy cryptographic computations. Nevertheless, substantial structural adjustments from the parallel mode of GPUs to the serial mode of the SSL/TLS stack are imperative, potentially constraining the practical deployment of GPUs. In this paper, we propose AsyncGBP${}^{+}$, a three-level framework that facilitates the seamless conversion of cryptographic requests from synchronous to asynchronous mode. We conduct an in-depth analysis of the OpenSSL provider and cryptographic primitive features relevant to GPU implementations, aiming to fully exploit the potential of GPUs. Notably, AsyncGBP${}^{+}$supports three working settings (offline/online/hybrid), finely tailored for various public key cryptographic primitives, including traditional ones like X25519, Ed25519, ECDSA, and the quantum-safe CRYSTALS-Kyber. A comprehensive evaluation demonstrates that AsyncGBP${}^{+}$can efficiently achieve an improvement of up to 137.8$\times$compared to the default OpenSSL provider (for X25519, Ed25519, ECDSA) and 113.30$\times$compared to OpenSSL-compatibleliboqs(for CRYSTALS-Kyber) in a single-process setting. Furthermore, AsyncGBP${}^{+}$surpasses the current fastest commercial-off-the-shelf OpenSSL-compatible TLS accelerator with a 5.3$\times$to 7.0$\times$performance improvement. Yi Bian 0001, Fangyu Zheng, Yuewu Wang, Lingguang Lei, Jiankuo Dong, Guang Fan 0001, Jiwu Jing |
IEEE Trans. Computers | 3 |
| 2024 | HiddenStor: A Steganographic Storage System Built on Secret Sharing
Yuewu Wang, Chunjing Kou, Peng Wang 0009, Jiwu Jing |
Inscrypt (1) | 2 |
| 2024 | ARPSSO: An OIDC-Compatible Privacy-Preserving SSO Scheme Based on RP Anonymization
Junlin He, Lingguang Lei, Yuewu Wang, Pingjian Wang, Jiwu Jing |
ESORICS (2) | 3 |
| 2024 | A Lightweight Defense Scheme Against Usermode Helper Privilege Escalation Using Linux Capability
Jingzi Meng, Yuewu Wang, Lingguang Lei, Chunjing Kou, Peng Wang 0009 |
ISC (1) | 2 |
| 2024 | CacheIEE: Cache-Assisted Isolated Execution Environment on ARM Multi-Core PlatformsabstractARM TrustZone technology has been widely used to create Trusted Execution Environments (TEEs) for enhancing the security of applications. However, the increasing number of installed security-sensitive applications in the secure world will inevitably enlarge the trusted computing base (TCB) of TEE systems. To minimize the TCB of the secure world and increase application portability, Isolated Execution Environments (IEEs) are proposed to protect applications in enclaves created in the normal world. However, existing IEE systems cannot provide the same level of security as the TEE systems, particularly, on resolving the multi-vector attacks that include both physical memory disclosure attacks and software attacks. In this article, we develop a new cache-assisted IEE system called CacheIEE that creates enclaves in the L1 data cache of the normal world to protect sensitive data against multi-vector attacks. First, by always storing the sensitive data in the L1 data cache, CacheIEE can effectively prevent physical memory disclosure attacks. Second, we protect the L1 data cache against untrusted rich OS running in other cores. To support more applications, CacheIEE can process large-size sensitive data in the L1 data cache with constrained capacity. We implement a system prototype of CacheIEE and verify its security and practicability. Jie Wang 0138, Kun Sun 0001, Lingguang Lei, Yuewu Wang, Jiwu Jing, Shengye Wan, Qi Li 0002 |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2024 | Condo: Enhancing Container Isolation Through Kernel Permission Data ProtectionabstractContainer technology is widely adopted due to its features such as light weight and ease of rapid deployment. However, as an OS-level virtualization mechanism, container isolation relies on the kernel’s security mechanisms and the kernel permission data (usually non-control flow data) used by these mechanisms. None of the existing mitigation schemes for non-control flow data attacks provide an effective and practical solution to container security since they either trigger too much overhead, have limited effectiveness over attacks launched in specific ways, or can only be used to protect some specific kernel data. In addition, none of them accurately identify the kernel data associated with container isolation. In this paper, we provide a solution called Condo that enhances container isolation by protecting the associated kernel permission data. We first present a generic non-control flow kernel data protection mechanism that protects different types of kernel data uniformly with low overhead and is not limited by attack methods or data types. We then demystify the models of various kernel access control mechanisms in the container environment, and identify the subject and object permission data that are critical to container isolation. Finally, we provide a solution named Condo to enhance container isolation, which is completely transparent to the existing container ecosystem, including containerized applications and container management/orchestration tools such as Docker. Experimental results show that Condo can effectively reduce the compromises of container isolation due to memory corruption attacks with an acceptable overhead. Shouyin Xu, Yuewu Wang, Lingguang Lei, Kun Sun 0001, Jiwu Jing, Jie Wang 0138 |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2023 | AsyncGBP: Unleashing the Potential of Heterogeneous Computing for SSL/TLS with GPU-based ProviderabstractThe proliferation of IoT and 5G technologies has led to an explosion of data traffic that data centers must handle while ensuring secure transmission via SSL/TLS. The high volume of cryptographic operations required imposes performance bottlenecks. The GPU-based cryptographic accelerator is one of the competitive solutions. However, significant structural differences with practical applications confine their capacities to specific domains, such as offline cryptanalysis, undermining their potential for real-world cryptographic acceleration. Yi Bian 0001, Fangyu Zheng, Yuewu Wang, Lingguang Lei, Jiankuo Dong, Jiwu Jing |
ICPP | 3 |
| 2023 | Towards Faster Fully Homomorphic Encryption Implementation with Integer and Floating-point Computing Power of GPUsabstractFully Homomorphic Encryption (FHE) allows computations on encrypted data without knowledge of the plaintext message and currently has been the focus of both academia and industry. However, the performance issue hinders its large-scale application, highlighting the urgent requirements of high-performance FHE implementations.With noticing the tremendous potential of GPUs in the field of cryptographic acceleration, this paper comprehensively investigates how to convert the available computing resources residing in GPUs into FHE workhorses, and implement a full set of low-level and middle-level FHE primitives based on two arithmetic units (i.e., INT32 and FP64 units) with three types of data precision (i.e., INT32, INT64 and FP64). This paper gives a comprehensive evaluation and comparison based on each road-map. Our implementations of fundamental functions outperform the implementations on the same platform by 1.7× to 16.7×. Taking CKKS FHE schemes as a case study, our implementation of homomorphic multiplication achieves 3.2× speedup over the state-of-the-art GPU-based implementation, even considering the difference of platforms. The detailed evaluation and comparison of this paper would offer a vital reference for the follow-up work to choose appropriate underlying arithmetic units and important primitive optimizations in GPU-based FHE implementations. Guang Fan 0001, Fangyu Zheng, Lipeng Wan 0002, Yuan Zhao 0015, Jiankuo Dong, Yuewu Wang, Jingqiang Lin 0001 |
IPDPS | 8 |
| 2022 | A Novel High-Performance Implementation of CRYSTALS-Kyber with AI Accelerator
Lipeng Wan 0002, Fangyu Zheng, Guang Fan 0001, Rong Wei, Yuewu Wang, Jingqiang Lin 0001, Jiankuo Dong |
ESORICS (3) | 6 |
| 2022 | Booting IoT Terminal Device Securely with eMMCabstractSecure boot is an effective defense mechanism against attacks on system images. However, traditional secure boot mechanisms could not well serve in the IoT scenario. They usually integrate the root key and cryptographic algorithms used for boot authentication into read-only storage like on-chip ROM, which can only be written by the manufacturer and are unchangeable once written. Modification of cryptographic algorithms and root key is sometimes necessary in the IoT scenario. First, some on-the-market IoT devices are shipped with vulnerable cryptographic algorithms (e.g., SHA-1, RSA-1024) that need to be updated. Second, when transferring the ownership of IoT devices, it may be essential to change the root key of IoT devices. In this paper, we propose a secure boot solution for IoT devices, which supports changing the root key and cryptographic algorithms flexibly. Specifically, we store the secure boot associated codes and data in the eMMC (embedded MultiMediaCard), which is a storage device widely deployed on IoT devices. We leverage the write protection mechanism of eMMC to prevent the codes and data from being tampered with by the runtime codes. In addition, a secure cryptographic algorithms and root key updating mechanism has been introduced, which allows only legal updating requests by verifying the identity of the requester. The experimental results show that the scheme can boot the system securely with negligible overhead. Yuewu Wang, Lingguang Lei, Yingjiao Niu |
TrustCom | 2 |
| 2022 | TrustSAMP: Securing Streaming Music Against Multivector Attacks on ARM PlatformabstractStreaming music has dominated the digital music industry in recent years, which allows users to enjoy a huge music library online with a low subscription price. Terminal-side audio DRM (Digital Right Management) is very critical for streaming music industry, compromising of which will cause unrestricted listening, dumping and unauthorized secondary distribution. However, existing DRM protection schemes mainly focus on defeating software attacks but lack complete shielding against the physical memory disclosure attacks, which may even be launched by the owner of the terminal device. In this paper, we propose a terminal-side audio DRM solution called TrustSAMP to protect the copyrighted audio data against both software attacks and physical memory disclosure attacks. The basic idea is to process the audio data plaintext only in certain on-SoC components secured by ARM TrustZone. To minimize the TCB (Trusted Computing Base) of the secure world, we separate the control flow and the data flow of the Linux audio subsystem and port only the codes used for audio data decryption and plaintext transfer into the secure world. Moreover, we leave most driver codes of the audio-associated on-SoC components in the rich OS (i.e., in the normal world), and introduce a tiny proxy in the secure world to control the associated registers according to the requests from the normal-world drivers. The prototype implemented on real hardware shows that TrustSAMP can play a variety of wav-format audio with very small overhead and negligible loss of audio quality. Yanchu Li, Lingguang Lei, Yuewu Wang, Jiwu Jing |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2021 | Heterogeneous-PAKE: Bridging the Gap between PAKE Protocols and Their Real-World DeploymentabstractTwo entities, who only share a password and communicate over an insecure channel, authenticate each other and agree on a large session key for protecting their subsequent communication. This is called the password-authenticated key exchange (PAKE) protocol. PAKE protocol has been considered a suitable substitute for the prevailing hash-based authentication which is vulnerable to various attacks. However, vendors are discouraged by both its prohibitively computational overheads as well as integrating costs, leading to its limited use since being proposed. Rong Wei, Fangyu Zheng, Jiankuo Dong, Guang Fan 0001, Lipeng Wan 0002, Jingqiang Lin 0001, Yuewu Wang |
ACSAC | 8 |
| 2021 | Vulnerable Service Invocation and CountermeasuresabstractBefore Android 5.0, the services in Android applications can be invoked either explicitly or implicitly. However, since the implicit service invocations may suffer service hijacking attacks and thus lead to sensitive data leakage, they have been forbidden since Android 5.0. Thereafter the Android system will simply throw an exception and crash the applications that still invokes services implicitly, so that it was expected that application developers will be forced to convert the implicit service invocations to explicit ones. In this paper, we develop a static analysis framework called ISA to analyze the effectiveness of forbidden policy on removing the vulnerable service invocations. We collect two datasets containing common 1390 apps downloaded 1 to 3 months before the forbidden policy is enforced and 30 months after the forbidden policy is enforced, respectively. Our preliminary analysis indicates a 82.58% reduction in the number of vulnerable service invocations due to the enforcement of forbidden policy. However, upon further investigation, we discover that the forbidden policy fails to resolve service hijacking attacks. We find that 36 popular applications are still vulnerable to service hijacking attacks, which can lead to the leakage of sensitive information such as user login credential. Finally, we analyze the reasons of the residue vulnerable invocations and then propose two countermeasures. Lingguang Lei, Kun Sun 0001, Yuewu Wang, Jiwu Jing, Yi He 0020, Pingjian Wang |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2020 | Cache-in-the-Middle (CITM) Attacks: Manipulating Sensitive Data in Isolated Execution EnvironmentsabstractThe traditional usage of ARM TrustZone has difficulty on solving the conflicts between the manufacturers that want to minimize the trusted computing base by constraining the installation of third-party applications in the secure world and the third-party application developers who prefer to have the freedom of installing their applications into the secure world. To address this issue, researchers propose to create Isolated Execution Environments (called IEEs) in the normal world to protect the security-sensitive applications. In this paper, we perform a systematic study on the IEE data protection models and the ARM cache attributes, and discover three cache-based attacks called CITM that can be leveraged to manipulate the sensitive data protected in IEEs. Specifically, due to the inefficient and incoherent security measures on the cache that maps to the IEE memory (i.e., memory designated for IEEs), attackers in the normal world may compromise the security of IEE data by manipulating the IEE memory during concurrent execution, bypassing the security measures enforced when a security-sensitive application is suspended or finished, or misusing the incomplete security measures during IEE's context switching processes. We conduct case studies of CITM attacks on three well-known IEE systems including SANCTUARY, Ginseng, and TrustICE to illustrate the feasibility to exploit them on real hardware testbeds. Finally, we analyze the root causes of the CITM attacks and propose a countermeasure to defeat them. The experimental results show that our defense scheme has a small overhead. Jie Wang 0138, Kun Sun 0001, Lingguang Lei, Shengye Wan, Yuewu Wang, Jiwu Jing |
CCS | 5 |
| 2020 | User Alignment with Jumping Seed Alignment Information PropagationabstractUser Alignment is to find users belonging to a same real person on different social networks and has become a fundamental task for many sequent applications such as cross-network recommendation systems. When matching users in multiple social networks, existing approaches always know some correctly matched users, which can be called seeds. Then, existing methods strongly depend on the neighboring users of each user to propagate alignment information from seeds and align probable matching users implicitly. However, the completeness and validity of original alignment information among seeds cannot be fully preserved when learning and aligning multiple user spaces. In this paper, we propose a unified framework named Jumping Seed Alignment Information Propagation (JSAIP) to flexibly leverage, for each user, complete and correct alignment information from seeds. Specifically, JSAIP learns a reasonable user space for each social network by preserving enough original network and label information. Then, JSAIP ensures the correct alignment among seeds and shared labels to reduce the diversity between different user spaces. Finally, JSAIP constructs jumping links from seeds to each user in each social network and ultilizes original seed alignment information to enhance or rectify the alignment information propagated from neighbors. Experiments on real world datasets demonstrate the effectiveness of our proposed JSAIP method compared to several state-of-the-art methods. Xiang Li 0045, Yijun Su, Neng Gao, Ji Xiang, Yuewu Wang |
IJCNN | 5 |
| 2020 | PIV4DB: Probabilistic Integrity Verification for Cloud DatabaseabstractMany organizations and enterprises use cloud databases to store data to improve management efficiency and save costs. However, cloud service providers may hide the fact that data integrity has been compromised for protecting their business reputation. Thus, how to verify the data integrity of cloud database in an effective way is very important for data owner. Existing integrity verification methods usually require cloud service provider to develop additional interfaces which are hard to be actually deployed. In addition, they cannot effectively detect tampering and deletion of a small amount of data. This paper presents a novel probabilistic integrity verification scheme (called PIV4DB) to address above challenges. Different from traditional methods, PIV4DB efficiently verifies the data integrity of cloud database by randomly selecting part of groups of tuples instead of querying all the tuples. Experimental results demonstrated that with validating 0.5% among 100k groups, PIV4DB could detect the corruption with 99% probability when the integrity of 920 out of billions of tuples are compromised. In addition, PIV4DB does not need extra cooperation with cloud service provider by just adding a new column of random numbers to the database and only using standard SQL statements to verify integrity. Pingjian Wang, Xiaozhuo Gu, Yuewu Wang, Jingqiang Lin 0001 |
ISCC | 4 |
| 2020 | Evaluation on the Security of Commercial Cloud Container Services
Lingguang Lei, Yuewu Wang, Kun Sun 0001, Jingzi Meng |
ISC | 3 |
| 2020 | SASAK: Shrinking the Attack Surface for Android Kernel with Stricter "seccomp" RestrictionsabstractThe following topics are dealt with: learning (artificial intelligence); mobile computing; security of data; Internet of Things; optimisation; resource allocation; data privacy; protocols; and cloud computing. Yingjiao Niu, Lingguang Lei, Yuewu Wang, Shijie Jia 0001, Chunjing Kou |
MSN | 3 |
| 2020 | TrustICT: an efficient trusted interaction interface between isolated execution domains on ARM multi-core processorsabstractThe Trusted Execution Environment (TEE) has been widely used to protect the security-sensitive sensing systems on Internet-of-Thing (IoT) devices. In the TEE systems, the execution environment is securely divided into a normal domain and a higher privileged secure domain which executing sensing systems through hardware. One common way to achieve the protection is implementing the sensitive functions of the sensing systems as trusted applications (TAs) in the well-isolated secure domain. Users in rich OS have to call TAs through the client applications (CAs), and the invocations must pass through the rich OS kernel. However, an untrusted rich OS may launch man-in-the-middle attacks on the communication between the CAs and TAs, and the misuse of cross-domain communication channel is becoming one severe threat on the TEE systems. In this paper, we develop a defense system named TrustICT to construct a lightweight trusted interaction channel between CAs and TAs without modifying existing TEE architecture. The main idea is to block attacks on the cross-domain interactions via dynamically setting the access permission of domain-shared memory, locking it from kernel mode and unlocking it only to legal CAs in the user mode. Particularly, we propose a multi-core scheduling strategy to defeat potential attacks from all privileged cores. Compared to existing cryptography-based methods, TrustICT dramatically reduces the system overhead since it does not require time-consuming cryptographic computation or sophisticated real-time kernel protection. We implement a prototype of TrustICT on a Freescale i.MX6Quad platform with the OP-TEE software system and evaluate its impacts on rich OS and the cross-domain transactions. Jie Wang 0138, Yuewu Wang, Lingguang Lei, Kun Sun 0001, Jiwu Jing |
SenSys | 2 |
| 2020 | SecureESFS: Sharing Android External Storage Files in A Securer WayabstractAs an essential component on Android devices, External Storage is frequently used for sharing files between different apps. Therefore, compared to Internal Storage, the access control on the External Storage is usually very loose. However, a lot of sensitive files might be stored on the External Storage, which makes it an attractive target for the attackers. Since Android 10, a security mechanism named Scoped Storage has been introduced to protect the sensitive files on the External Storage. However, this mechanism is mainly used to protect the app-specific files, and can't support the sharing of sensitive files between trusted apps in a secure and flexible way. In this paper, we present a secure External Storage sensitive file sharing solution named SecureESFS. It first extends a Linux kernel security mechanism named ACL on the SDCardFS filesystem to protect the External Storage. With different ACL policy settings, the user can dynamically share sensitive files between trusted apps according to specific business needs. We also enforce the integrity protection on the ACL policies by checking the hash message authentication codes (HMAC) of these policies. Moreover, we design a transparent encryption mechanism in SecureESFS to protect the sensitive files on the External Storage, when the Android devices are physically accessed by the attackers, such as removing the SD card. For versions lower than Android 10, SecureESFS can provide independent protection and secure sharing for the sensitive files on the External Storage. For versions higher than Android 10, SecureESFS can achieve the secure sharing of sensitive files while Scoped Storage provides protection for the app-specific files. SecureESFS may also be used to enhance the security of the Scoped Storage mechanism. Experiments conducted on a prototype show that SecureESFS works well and incurs acceptable overhead. Yuewu Wang, Lingguang Lei, Jiwu Jing |
TrustCom | 2 |
| 2019 | OCRAM-Assisted Sensitive Data Protection on ARM-Based Platform
Dawei Chu, Yuewu Wang, Lingguang Lei, Yanchu Li, Jiwu Jing, Kun Sun 0001 |
ESORICS (2) | 2 |
| 2019 | SuiT: Secure User Interface Based on TrustZoneabstractIn lots of security-aware scenarios, trusted user interface (TUI) is indispensable. For example, before signing a payment information, user needs to approve the information. Digital right management (DRM) related applications also need TUI supporting. Although current mobile platforms have provided TEE (Trusted Execution Environment) OS to support trusted applications running, introducing additional drivers into TEE OS is not very secure. The additional drivers may increase the code size of TEE OS and expand the attack surface. In this paper, we present a novel secure UI framework called SuiT based on ARM TrustZone hardware security extension. A secure UI driver and a shadow UI driver are implemented in the normal world. In the secure world, only additional switching code is introduced. When an application needs to interact with user in a trustworthy way, the shadow UI driver will take the place of original UI driver to complete the user interaction. During the UI driver switching process, a temporary trusted execution environment for secure UI driver is dynamically built by the switching code in the secure world. The trusted execution environment ensures that the secure UI driver is executed in a secure way and the potential attacks from rich OS can not tamper with the process of user interaction. We also implement a prototype of SuiT based on Android system and Freescale ARM processor with TrustZone extension. Experimental results demonstrate that SuiT can work well with negligible overhead. Yuewu Wang, Lingguang Lei |
ICC | 2 |
| 2019 | Aligning Users Across Social Networks by Joint User and Label Consistence Representation
Xiang Li 0045, Yijun Su, Neng Gao, Ji Xiang, Yuewu Wang |
ICONIP (2) | 6 |
| 2019 | Anchor User Oriented Accordant Embedding for User Identity Linkage
Xiang Li 0045, Yijun Su, Neng Gao, Ji Xiang, Yuewu Wang |
ICONIP (5) | 6 |
| 2019 | ALTEE: Constructing Trustworthy Execution Environment for Mobile App DynamicallyabstractTEE(Trusted Execution Environment) has became one of the most popular security features for mobile platforms. Current TEE solutions usually implement secure functions in Trusted applications (TA) running over a trusted OS in the secure world. Host App may access these secure functions through the TEE driver. Unfortunately, such architecture is not very secure. A trusted OS has to be loaded in secure world to support TA running. Thus, the code size in secure world became large. As more and more TA is installed, the secure code size will be further larger and larger. Lots of real attack case have been reported [1]. In this paper, we present a novel TEE constructing method named ALTEE. Different from existing TEE solutions, ALTEE includes secure code in host app, and constructs a trustworthy execution environment for it dynamically whenever the code needs to be run. Yuewu Wang, Lingguang Lei |
ISCC | 2 |
| 2019 | DangerNeighbor attack: Information leakage via postMessage mechanism in HTML5
Chong Guan, Kun Sun 0001, Lingguang Lei, Pingjian Wang, Yuewu Wang, Wei Chen 0006 |
Comput. Secur. | 5 |
| 2018 | A Measurement Study on Linux Container Security: Attacks and CountermeasuresabstractLinux container mechanism has attracted a lot of attention and is increasingly utilized to deploy industry applications. Though it is a consensus that the container mechanism is not secure due to the kernel-sharing property, it lacks a concrete and systematical evaluation on its security using real world exploits. In this paper, we collect an attack dataset including 223 exploits that are effective on the container platform, and classify them into different categories using a two-dimensional attack taxonomy. Then we evaluate the security of existing Linux container mechanism using 88 typical exploits filtered out from the dataset. We find 50 (56.82%) exploits can successfully launch attacks from inside the container with the default configuration. Since the privilege escalation exploits can completely disable the container protection mechanism, we conduct an in-depth analysis on these exploits. We find the kernel security mechanisms such as Capability, Seccomp, and MAC play a more important role in preventing privilege escalation than the container isolation mechanisms (i.e., Namespace and Cgroup). However, the interdependence and mutual-influence relationship among these kernel security mechanisms may make them fall into the "short board effect" and impair their protection capability. By studying the 11 exploits that still can successfully break the isolation provided by container and achieve privilege escalation, we identify a common 4-step attack model followed by all 11 exploits. Finally, we propose a defense mechanism to effectively defeat those identified privilege escalation attacks. Lingguang Lei, Yuewu Wang, Jiwu Jing, Kun Sun 0001 |
ACSAC | 3 |
| 2017 | Splitting Third-Party Libraries' Privileges from Android Apps
Jiawei Zhan, Xiaozhuo Gu, Yuewu Wang, Yingjiao Niu |
ACISP (2) | 4 |
| 2017 | Vulnerable Implicit Service: A RevisitabstractThe services in Android applications can be invoked either explicitly or implicitly before Android 5.0. However, since the implicit service invocations suffer service hijacking attacks and thus lead to sensitive information leakage, they have been forbidden since Android 5.0. Thereafter since the Android system will simply throw an exception and crash the application that still invokes services implicitly, it was expected that application developers will be forced to convert the implicit service invocations to explicit ones by specifying the package name of the service to be called. Lingguang Lei, Yi He 0020, Kun Sun 0001, Jiwu Jing, Yuewu Wang, Qi Li 0002, Jian Weng 0001 |
CCS | 5 |
| 2017 | SPEAKER: Split-Phase Execution of Application Containers
Lingguang Lei, Kun Sun 0001, Chris Shenefiel, Yuewu Wang, Qi Li 0002 |
DIMVA | 6 |
| 2017 | Enforcing ACL Access Control on Android Platform
Xiaohai Cai, Xiaozhuo Gu, Yuewu Wang, Zhenhuan Cao |
ISC | 3 |
| 2015 | TrustOTP: Transforming Smartphones into Secure One-Time Password TokensabstractTwo-factor authentication has been widely used due to the vulnerabilities associated with traditional text-based password. One-time password (OTP) plays an indispensable role on authenticating mobile users to critical web services that demand a high level of security. As the smartphones are increasingly gaining popularity nowadays, software-based OTP generators have been developed and installed into smartphones as software apps, which bring great convenience to the users without introducing extra burden. However, software-based OTP solutions cannot guarantee the confidentiality of the generated passwords or even the seeds when the mobile OS is compromised. Moreover, they also suffer from denial-of-service attacks when the mobile OS crashes. Hardware-based OTP tokens can solve these security problems in the software-based OTP solutions; however, it is inconvenient for the users to carry physical tokens with them, particularly, when there are more than one token to be carried. In this paper, we present TrustOTP, a secure one-time password solution that can achieve both the flexibility of software tokens and the security of hardware tokens by using ARM TrustZone technology. TrustOTP can not only protect the confidentiality of the OTPs against a malicious mobile OS, but also guarantee reliable OTP generation and trusted OTP display when the mobile OS is compromised or even crashes. It is flexible to integrate multiple OTP algorithms and instances for different application scenarios on the same smartphone platform without modifying the mobile OS. We develop a prototype of TrustOTP on Freescale i.MX53 QSB. The experimental results show that TrustOTP has small impacts on the mobile OS and its power consumption is low. He Sun 0005, Kun Sun 0001, Yuewu Wang, Jiwu Jing |
CCS | 3 |
| 2015 | TrustICE: Hardware-Assisted Isolated Computing Environments on Mobile DevicesabstractMobile devices have been widely used to process sensitive data and perform important transactions. It is a challenge to protect secure code from a malicious mobile OS. ARM TrustZone technology can protect secure code in a secure domain from an untrusted normal domain. However, since the attack surface of the secure domain will increase along with the size of secure code, it becomes arduous to negotiate with OEMs to get new secure code installed. We propose a novel TrustZone-based isolation framework named TrustICE to create isolated computing environments (ICEs) in the normal domain. TrustICE securely isolates the secure code in an ICE from an untrusted Rich OS in the normal domain. The trusted computing base (TCB) of TrustICE remains small and unchanged regardless of the amount of secure code being protected. Our prototype shows that the switching time between an ICE and the Rich OS is less than 12 ms. He Sun 0005, Kun Sun 0001, Yuewu Wang, Jiwu Jing, Haining Wang 0001 |
DSN | 3 |
| 2015 | DeepDroid: Dynamically Enforcing Enterprise Policy on Android Devices
Xueqiang Wang, Kun Sun 0001, Yuewu Wang, Jiwu Jing |
NDSS | 3 |
| 2015 | Reliable and Trustworthy Memory Acquisition on SmartphonesabstractWith the wide usage of smartphones in our daily life, new malware is emerging to compromise the mobile OS and then steal or manipulate sensitive data from mobile applications. Forensic analysis tools demand a reliable and trustworthy memory acquisition of the operating systems running on the smartphones for further digital forensic analysis. However, a compromised OS may launch denial of service attacks to prevent a valid memory acquisition by forensic examiners. In this paper, we develop a TrustZone-based memory acquisition mechanism called TrustDump that is capable of reliably and securely obtaining the RAM memory and CPU registers of the mobile OS even if the OS has crashed or been compromised. TrustDump is isolated from the mobile OS by TrustZone. Instead of using a hypervisor to ensure the isolation between the OS and the memory acquisition tool, we rely on ARM TrustZone to achieve a hardware-assisted isolation with a small trusted computing base. TrustDump can include basic online analysis modules to catch malware in an early stage. Moreover, the acquired memory and register data can be sent to a remote server through a fast Micro-USB port for real-time forensics analysis when the OS runs or a slow serial port for further forensic analysis when the OS has crashed. A trusted graphical user interface is integrated in the TrustZone to authenticate the user and prevent the misuse of our memory acquisition tool. We build a TrustDump prototype on Freescale i.MX53 QSB. He Sun 0005, Kun Sun 0001, Yuewu Wang, Jiwu Jing |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2014 | Once Root Always a Threat: Analyzing the Security Threats of Android Permission System
Zhongwen Zhang, Yuewu Wang, Jiwu Jing, Qiongxiao Wang, Lingguang Lei |
ACISP | 2 |
| 2014 | TrustDump: Reliable Memory Acquisition on Smartphones
He Sun 0005, Kun Sun 0001, Yuewu Wang, Jiwu Jing, Sushil Jajodia |
ESORICS (1) | 3 |
| 2012 | Efficient Missing Tag Detection in a Large RFID SystemabstractMissing tag detection is an important problem for large RFID application systems (e.g., inventory control), and is drawing more and more attention from the research community in recent years. Li et al. proposed the Iterative ID-free Protocol (IIP) to identify the missing tags in a large RFID system, achieving high time efficiency. However, our analysis and experiments show that the time efficiency of IIP drops sharply when the missing rate increases. By exploiting information contained in the expected singleton slots, we propose IIPS to improve IIP, achieving high and steady time efficiency under both high and low missing rates. Furthermore, by identifying the missing tags in the expected collision slots and dynamically computing the missing rate through estimation of the present tags and statistics about the missing tags, we propose IIPS-CP and IIPS-CM, achieving higher time efficiency than IIPS under high missing rates. Our simulations show that, compared with IIP, when the number of total tags is 10000 and the missing rate is 80%, IIPS, IIPS-CP and IIPS-CM reduce the average time for identifying each tag by 84.8%, 88.9% and 89.3%, respectively. Cunqing Ma, Jingqiang Lin 0001, Yuewu Wang |
TrustCom | 3 |
| 2012 | Offline RFID Grouping Proofs with Trusted TimestampsabstractWith the wide deployment of RFID applications, RFID security issues are drawing more and more attention. The RFID grouping proof aims to provide a verifiable evidence that two or more RFID tags were scanned simultaneously. It extends the yoking proof for two RFID tags, to prove the coexistence of a set of tags (e.g., some drugs can only be sold in the existence of a prescription). In many grouping proof scenarios, the time when the grouping proof was generated is critical to judge whether a transaction is legal or not, and the protocol usually should work in offline mode. Although lots of grouping proof protocols with various features have been proposed, they either work in online mode or have difficulties in generating a grouping proof with the precise transaction time in offline mode. Therefore, we propose a protocol to generate offline RFID grouping proofs with trusted timestamps, where the verifier can obtain the precise transaction time. As far as we know, it is the first practical offline grouping proof protocol that includes the precise transaction time. Properties, performance evaluation and security analysis of our design are also presented in this paper. Cunqing Ma, Jingqiang Lin 0001, Yuewu Wang, Ming Shang |
TrustCom | 3 |
| 2012 | A Scalable Anonymity Scheme Based on DHT Distributed InquiryabstractTwo key factors in the design of anonymity schemes are the scalability and the security of the relay node selection. In this paper, a scalable, secure anonymity scheme based on DHT inquiry mechanism is presented. Unlike the most existing schemes, every relay node's routing information (RRI) is stored as normal data in DHT overlay. The routing information can be inquired just with corresponding relay node's Relay ID (RID).All RID is maintained by SA to fill a dynamic range. So, user only needs to get the range of RID to select relay nodes, which is a datum with constant size. Such a mechanism significantly improve the scalability of scheme. Furthermore, RID assigned by SA also provides a more stable and provable relationship between relay nodes, which can be used to help validation of RRI storage. With this innovation, security measures are introduced. The framework of the scheme, key technical details and security analysis are described in this paper. In addition, simulation experiments are conducted to validate the effectiveness of this scheme. Yuewu Wang, Jiwu Jing, Zhongwen Zhang |
TrustCom | 2 |
| 2009 | A Novel Contagion-Like Patch Dissemination Mechanism against Peer-to-Peer File-Sharing Worms
Xiaofeng Nie, Jiwu Jing, Yuewu Wang |
Inscrypt | 3 |
| 2008 | An Improved Method of Hybrid Worm SimulationabstractThe large-scaled worm infestation promotes the investigation of worm character. The current research of worm character can be classified into three categories: mathematical modeling of worm, emulation based on testbed, and package level worm simulation. However, in spite of the higher accuracy, the latter two methods require a high power of memory and computation, which poses a challenge to the large-scaled worm simulation. To solve this problem, a hybrid model of simulation was proposed with a selective abstraction. The hybrid worm simulation is a combination of mathematics analysis and package level simulation, achieving a better compromise between accuracy and efficiency. However, existing hybrid simulation framework still has some limitations, because the mathematic model of it can not consider the effect of defense and network congestion very well. In order to improve the accuracy of hybrid worm simulation, the current study proposes a novel method based on a two-factor model and provides experimental evidence of the higher accuracy of simulation by using the new method. Jiwu Jing, Yuewu Wang |
WAIM | 3 |