VLDB 2026 Research / reviewers in the wild / expert
Pingjian Wang
dblp:08/8125
· DBLP profile ↗
8ranked-venue papers
0as first author
5since 2021 · last 2026
0009-0008-9292-6615ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 4 · 2 since 2021Security and privacy · 3 · 2 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Cross-Application Key Abuse Attack against Hardware-backed Android Keystore
Zeping Wu, Lingguang Lei, Pingjian Wang, Yuewu Wang, Xiaojuan Feng |
ICC | 3 |
| 2025 | CapAssess: An Endeavor to Assess and Enhance Linux Capabilities UtilizationabstractThe Linux capabilities mechanism divides the root privileges to provide more fine-grained access control, but its effectiveness depends on proper implementation and configuration. The scattered enforcement of capabilities in the kernel and its sporadic usage in programs pose challenges in gathering assessment information. To address this, we propose three tools for diagnosing potential problems in its design, implementation, and utilization. First, we employ LLVM/Clang to examine the capabilities enforcement in the kernel to map capabilities checks to files. This is the first attempt to explore the interaction between capabilities and other mechanisms, such as UGO. Second, We propose a pattern-based method to identify the sensitive kernel functions protected by capabilities, quanti-fying the overlap problem of capabilities. Third, we employ a customized fuzzing approach to determine the minimal set of capabilities required by programs, offering insight for secure usage. Additionally, Our study is further guided by international access management standards, providing structured criteria for the assessment. Leveraging data collected by our tools, we identify imperfections of capabilities and reported to stakeholders. To the best of our knowledge, this is the first systematic assessment of Linux capabilities. Jingzi Meng, Yuewu Wang, Lingguang Lei, Jiwu Jing, Pingjian Wang, Chunjing Kou, Peng Wang 0009 |
SANER | 5 |
| 2024 | ARPSSO: An OIDC-Compatible Privacy-Preserving SSO Scheme Based on RP Anonymization
Junlin He, Lingguang Lei, Yuewu Wang, Pingjian Wang, Jiwu Jing |
ESORICS (2) | 4 |
| 2021 | A Secure And High Concurrency SM2 Cooperative Signature Algorithm For Mobile NetworkabstractMobile devices have been widely used to deploy security-sensitive applications such as mobile payments, mobile offices etc. SM2 digital signature technology is critical in these applications to provide the protection including identity authentication, data integrity, action non-repudiation. Since mobile devices are prone to being stolen or lost, several server-aided SM2 cooperative signature schemes have been proposed for the mobile scenario. However, existing solutions could not well fit the high-concurrency scenario which needs lightweight computation and communication complexity, especially for the server sides. In this paper, we propose a SM2 cooperative signature algorithm (SM2-CSA) for the high-concurrency scenario, which involves only one-time client-server interaction and one elliptic curve addition operation on the server side in the signing procedure. Theoretical analysis and practical tests shows that SM2-CSA can provide better computation and communication efficiency compared with existing schemes without compromising the security. Wenfei Qian, Pingjian Wang, Lingguang Lei, Tianyu Chen 0016, Bikuan Zhang |
MSN | 2 |
| 2021 | Vulnerable Service Invocation and CountermeasuresabstractBefore Android 5.0, the services in Android applications can be invoked either explicitly or implicitly. However, since the implicit service invocations may suffer service hijacking attacks and thus lead to sensitive data leakage, they have been forbidden since Android 5.0. Thereafter the Android system will simply throw an exception and crash the applications that still invokes services implicitly, so that it was expected that application developers will be forced to convert the implicit service invocations to explicit ones. In this paper, we develop a static analysis framework called ISA to analyze the effectiveness of forbidden policy on removing the vulnerable service invocations. We collect two datasets containing common 1390 apps downloaded 1 to 3 months before the forbidden policy is enforced and 30 months after the forbidden policy is enforced, respectively. Our preliminary analysis indicates a 82.58% reduction in the number of vulnerable service invocations due to the enforcement of forbidden policy. However, upon further investigation, we discover that the forbidden policy fails to resolve service hijacking attacks. We find that 36 popular applications are still vulnerable to service hijacking attacks, which can lead to the leakage of sensitive information such as user login credential. Finally, we analyze the reasons of the residue vulnerable invocations and then propose two countermeasures. Lingguang Lei, Kun Sun 0001, Yuewu Wang, Jiwu Jing, Yi He 0020, Pingjian Wang |
IEEE Trans. Dependable Secur. Comput. | 7 |
| 2020 | PIV4DB: Probabilistic Integrity Verification for Cloud DatabaseabstractMany organizations and enterprises use cloud databases to store data to improve management efficiency and save costs. However, cloud service providers may hide the fact that data integrity has been compromised for protecting their business reputation. Thus, how to verify the data integrity of cloud database in an effective way is very important for data owner. Existing integrity verification methods usually require cloud service provider to develop additional interfaces which are hard to be actually deployed. In addition, they cannot effectively detect tampering and deletion of a small amount of data. This paper presents a novel probabilistic integrity verification scheme (called PIV4DB) to address above challenges. Different from traditional methods, PIV4DB efficiently verifies the data integrity of cloud database by randomly selecting part of groups of tuples instead of querying all the tuples. Experimental results demonstrated that with validating 0.5% among 100k groups, PIV4DB could detect the corruption with 99% probability when the integrity of 920 out of billions of tuples are compromised. In addition, PIV4DB does not need extra cooperation with cloud service provider by just adding a new column of random numbers to the database and only using standard SQL statements to verify integrity. Pingjian Wang, Xiaozhuo Gu, Yuewu Wang, Jingqiang Lin 0001 |
ISCC | 2 |
| 2019 | DangerNeighbor attack: Information leakage via postMessage mechanism in HTML5
Chong Guan, Kun Sun 0001, Lingguang Lei, Pingjian Wang, Yuewu Wang, Wei Chen 0006 |
Comput. Secur. | 4 |
| 2017 | Employing Smartwatch for Enhanced Password Authentication
Bing Chang, Yingjiu Li, Pingjian Wang, Wen Tao Zhu |
WASA | 4 |