Yunxia Han

dblp:09/1114 · DBLP profile ↗
← Back
10ranked-venue papers
4as first author
6since 2021 · last 2026
0000-0002-1978-1164ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 7 · 3 first-author · 6 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 1 first-author
YearPublicationVenuePosition
2026 SE-ASSO: A Security-Enhanced Anonymous Single-Sign-On Authentication Scheme
abstract
Anonymous Single-Sign-On (ASSO) enables users to authenticate with an identity server and obtain a master token that grants anonymous access to multiple services. We analyze existing password-based ASSO schemes and identify two fundamental security vulnerabilities. First, an adversary may enumerate potential passwords of a target user and forge valid authentication requests to the identity server. By analyzing the master tokens returned by the identity server using a designated equation, the adversary can recover the user’s password.We refer to this attack as Master Token Password Inference Attacks (MT-PIA). Second, a malicious manufacturer may embed a biased randomness source in users’ devices, causing cryptographic operations to produce predictable outputs. This enables the manufacturer to efficiently recover users’ secrets, which is known as subversion attacks. To mitigate MT-PIA, we propose a secure master token generation mechanism that protects users’ master tokens using two factors: a password and a security key. This mechanism prevents adversaries from forging valid authentication requests and ensures that, even if they intercept master tokens from the identity server, they cannot infer users’ passwords without users’ associated security keys. To counter subversion attacks, we design a cryptographic reverse firewall–based randomness generation mechanism. In this design, a reverse firewall is deployed between each user’s device and the external to assist in generating uniformly distributed randomness. Leveraging these two mechanisms, we develop a security-enhanced ASSO scheme, referred to as SE-ASSO, and conduct a comprehensive evaluation demonstrating its strong security and practicality for real-world deployment.
Shanshan Li 0004, Mengfan Ma, Yunxia Han
IEEE Trans. Inf. Forensics Secur.3
2025 Towards subversion-resistant password-protected encryption for deduplicated cloud storage
Shanshan Li 0004, Mengfan Ma, Yunxia Han, Chunxiang Xu
J. Inf. Secur. Appl.3
2024 A Secure Two-Factor Authentication Key Exchange Scheme
abstract
Two-factor authentication key exchange (AKE) is an effective way to strengthen the security of password-authenticated key exchange. Most two-factor AKE schemes using smart cards as the second factor require users to have the second factor with them any time, which causes users inconveniences. Biometrics provide a user-friendly manner to achieve two-factor AKE since they need not be carried. However, biometrics may have less entropy than expected and would suffer from offline guessing attacks. In this paper, we propose a secure two-factor authentication key exchange scheme TAKE that resists offline guessing attacks against biometrics and passwords. In TAKE, a user generates a combined factor of his/her biometrics and password. To protect the combined factor, the user and the server leverages secure two-party computation to blind it with a key which is protected in a trusted execution environment. Thus, TAKE prevents an adversary from eavesdropping on the combined factor, and simultaneously guarantees that he cannot recover the combined factor from blinded one to undertake offline guessing attacks even if he compromises the server and obtains the blinded combined factor. We provide the formal security proof of TAKE. The experiments show that TAKE is efficient in terms of storage, computation, and communication overhead.
Yunxia Han, Chunxiang Xu, Changsong Jiang, Kefei Chen
IEEE Trans. Dependable Secur. Comput.1
2024 Two-Factor Authenticated Key Exchange From Biometrics With Low Entropy Rates
abstract
Multi-factor authenticated key exchange (AKE) enables a user to be authenticated by a server using multiple factors and negotiate a shared session key to protect subsequent communications. Most existing multi-factor AKE schemes utilize biometrics as one factor due to their uniqueness and invariance properties. To support matching for noisy biometrics and protect them, fuzzy extractors are employed to extract a constant random string from varying biometric measurements without disclosing biometric data. However, the fuzzy extractors used in these schemes merely work on biometrics with an entropy rate greater than the error rate. Hence these schemes are unsuitable for biometrics with low entropy rates. In this paper, we propose a secure two-factor AKE scheme dubbed AHEAD from passwords and biometrics, which eliminates the limitation of biometric entropy rates. In AHEAD, we conceive a matching mechanism to simultaneously check whether an input biometric measurement with low entropy rates is close enough to the registered one, and whether an input password exactly matches the registered password. The mechanism allows a valid user to generate a secret element shared with the server in an oblivious way. By adopting a randomization technique, the secret element can be randomized for derivation of session keys. The security and efficiency of AHEAD are demonstrated by formal security proofs and experimental evaluations.
Changsong Jiang, Chunxiang Xu, Yunxia Han, Zhao Zhang 0026, Kefei Chen
IEEE Trans. Inf. Forensics Secur.3
2024 Privacy-Preserving Cryptocurrency With Threshold Authentication and Regulation
abstract
Cryptocurrency allows for immutable and transparent payments in the decentralized manner. The transparency nature inevitably leads to leakage of users’ private information. Although existing schemes provided privacy preservation in cryptocurrencies, they fail to consider regulation and facilitates conducting illegal activities. To solve this problem, several works aimed at striking a balance between preservation of users’ privacy and identification of malicious users. However, they introduced a central authority (which runs counter to the decentralization design of cryptocurrencies), and reveals only the pseudonym of a malicious user other than her/his real identity due to lack of authentication. In this work, we propose PICTURE, a privacy-preserving cryptocurrency with threshold authentication and regulation. In PICTURE, a user registers to a group of authorities (instead of a centralized one) who cooperatively issue the user with a master account which is actually a randomizable signature. The user randomizes the master account to be authenticated and transact anonymously. Besides, the transaction contains a record, with which the authorities can reveal the user’s identity (that is used in registration) in the threshold way. Our construction enables the user to prove that the record is well-formed with only a standard Schnorr’s protocol, leading to lower overheads compared with existing works. We provide a formal security proof to demonstrate that PICTURE is secure, and conduct a comprehensive performance evaluation to show that PICTURE is ready to be deployed in real world.
Zhao Zhang 0026, Chunxiang Xu, Yunxia Han
IEEE Trans. Inf. Forensics Secur.3
2023 ttPAKE: Typo tolerance password-authenticated key exchange
Yunxia Han, Chunxiang Xu, Shanshan Li 0004, Changsong Jiang, Kefei Chen
J. Inf. Secur. Appl.1
2020 On the Security of a Key Agreement and Key Protection Scheme
abstract
We point out that the key agreement and key protection scheme (published in IEEE Transactions on Information Forensics and Security, doi: 10.1109/TIFS.2018.2850299) fails to achieve the two-factor security. We demonstrate that in the scheme, if an adversary can control the master device of a target user, he can impersonate the user to pass the server's authentication.
Yunxia Han, Chunxiang Xu, Debiao He, Kefei Chen
IEEE Trans. Inf. Forensics Secur.1
2005 Sit-based LUCC assessment system for sustainable agriculture development in Western China methodology and case study
Xiuwan Chen, Caicong Wu, Yingchun Tao, Jixing Wu, Pengrun Yang, Yunxia Han
IGARSS6
2005 Precision management of winter wheat based on aerial images and hyperspectral data obtained by unmanned aircraft
abstract
Variable rate fertilization (VRF), a kind of precision management, was attempted in an experiment farm of winter wheat. The farm was divided into 48 test cells, which the level of the field nutrient varied in different cells in 2004. The hyperspectral reflectance and the remote sensing images of the farm were acquired using a handheld spectroradiometer and an unmanned aircraft respectively, and then the characteristics of the hyperspectral data and the aerial images were calculated. A yield map was obtained by using a combine with yield monitor and DGPS. Soil total nitrogen of each test cells was analyzed by grid-sampling method. The vegetation indices and the color characteristics calculated denoted fertilization status and growing condition of winter wheat. The reflectance showed obvious negative correlation with soil total nitrogen and yield in 520-700 nm and positive correlation with R/(R+G+B). The grain yield showed negative correlation with R/(R+G+B). Soil total nitrogen had a great effect on yield when total nitrogen was less than 200 kg/hm2 at elongating stage of winter wheat. After performing VRF management, the difference of the yield was reduced and the total yield was increased. The efficiency of the fertilizer was improved and the environment pollution was decreased. It could be concluded that the precision management based on the aerial images and the hyperspectral data could promote farming production.
Yunxia Han, Minzan Li, Xijie Zhang, Liangliang Jia, Xingping Chen, Fusuo Zhang
IGARSS1
2005 Research on the application mode of spatial information technology for precision agriculture in Xinjiang
abstract
Spatial information technology has been the main strength to improve Xinjiang's environment and agriculture sustainable development. According to the specific characteristics and requirements, and the serious problems in face of Xinjiang, the paper studied the application mode of spatial information technology for precision agriculture. To realize the development strategic, an integrated PAMS (Precision Agriculture Monitoring and Servicing System in Xinjiang) system was brought forward and designed to improve the utilization of spatial information for ecosystem and environment protection, and agricultural production (precision agriculture). Shihezi was selected as the demonstration area. The PAMS system included spatial information acquiring, processing, analyzing, decision making and service platforms (systems). The aerial remote sensing system would be an important platform and tools for high resolution requirements and emergent events especially, and has been placed to the preferential position. The system, proposed to be developed in Shihezi city, could provide a possible approach for resolving the serious problems in face of Xinjiang.
Caicong Wu, Xiuwan Chen, Yingchun Tao, Pengrun Yang, Yunxia Han
IGARSS6