VLDB 2026 Research / reviewers in the wild / expert
Hyunsoo Kwon
dblp:147/1530
· DBLP profile ↗
16ranked-venue papers
7as first author
5since 2021 · last 2025
0000-0002-6728-0698ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 4 · 2 first-authorGraphics, computer vision, multimedia, augmented reality and games · 4 · 2 first-authorSecurity and privacy · 3 · 2 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 first-authorSystems, architecture and hardware · 1 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Deep Dive into In-app Browsers: Uncovering Hidden Pitfalls in Certificate ValidationabstractWhile providing a seamless user experience by enabling web access within the app, in-app browsers raise security concerns, particularly in certificate validation, which can leave users vulnerable to Man-In-The-Middle (MITM) or phishing attacks unless appropriately implemented.In this paper, we systematically evaluated the certificate validation mechanisms of in-app browsers, also known as WebView, focusing on how effectively they comply with X.509 certificate standards and support advanced certificate extensions related to revocation and Certificate Transparency (CT). To ensure reproducibility and enable platform-specific trust anchor control which is particularly challenging on Android 14 and later, we developed a unified framework called FAITH using physical devices for iOS and Android emulators. Using FAITH and 115 crafted certificate chains—including 87 non-compliant chains and 28 designed to test advanced certificate extensions—we tested 20 popular Android and iOS apps, as well as desktop and mobile browsers. Android WebView apps accepted 77.0% of non-compliant chains and all non-compliant intermediate CA certificate tests, significantly higher than mainstream browsers and iOS apps. We identified the root cause in Android WebView's reliance on the system-level certificate validation handler, which performs minimal checks and lacks support for extensions such as OCSP Must-Staple and Precertificate. Additionally, we found that cached intermediate CA certificates are reused during validation in Android WebView, which exposes the process to unintended bypass of certificate checks. To demonstrate its real-world impact, we constructed a detailed CA caching attack scenario, and disclosed it to responsible vendors including Google. The reported bug was subsequently acknowledged as a valid security vulnerability. Finally, we conclude by providing recommendations to improve WebView's certificate validation behavior. Woonghee Lee 0004, Junbeom Hur, Hyunsoo Kwon |
CCS | 3 |
| 2023 | Certificate Transparency With Enhanced PrivacyabstractDigital certificates play an important role in the authentication of communicating parties for transport layer security. Recently, however, frequent incidents such as the illegal issuance of fake certificates by a compromised certificate authority have raised concerns about the legacy certificate system. Certificate Transparency (CT) mitigates such issues by employing a log server to audit issued certificates publicly, making the certificate issuance and verification processes transparent. Unfortunately, the legacy CT ecosystem suffers from log server compromises and user browsing information leakage. Furthermore, the data structure for the certificate management in the legacy CT system incurs computation overhead linear to the number of registered certificates in the log. In this paper, we propose a secure CT scheme by leveraging a shared value tree (SVT), a novel log structure specifically designed to address the log server compromise and browsing information leakage problems. The verification time of SVT remains constant regardless of the number of registered certificates in the log. We analyze our scheme on the legacy CT system to demonstrate its incremental deployability, guaranteeing a smooth transition toward a more secure web ecosystem. Hyunsoo Kwon, Sangtae Lee, Minjae Kim 0008, Changhee Hahn, Junbeom Hur |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2022 | Efficient IoT Management With Resilience to Unauthorized Access to Cloud StorageabstractCloud-based Internet of Things (IoT) management services are a promising means of ingesting data from globally dispersed devices. In this setting, it is important to regulate access to data managed by potentially untrusted cloud servers. Attribute-based encryption (ABE) is a highly effective tool for access control. However, applying ABE to IoT environments shows limitations in the following three aspects: First, the demands for storage resources increase in proportion to the complexity of the access control policies. Second, the computation cost of ABE is onerous for resource-limited devices. Lastly, ABE alone is intractable to prevent illegal key-sharing which leads to unauthorized access to data. In this article, we propose an efficient and secure cloud-based IoT data management scheme using ABE. First, we remove the storage-side dependency on the complexity of the access control policies. Second, a substantial part of computationally intensive operations is securely outsourced to the cloud servers. Lastly, unauthorized access to data via illegal key-sharing is strictly forbidden. Our security analysis and experimental results show the security and practicability of the proposed scheme. Changhee Hahn, Jongkil Kim, Hyunsoo Kwon, Junbeom Hur |
IEEE Trans. Cloud Comput. | 3 |
| 2022 | Enabling Fast Public Auditing and Data Dynamics in Cloud ServicesabstractPublic auditing enables efficient integrity checks of data assigned to cloud servers. In this article, we revisit the public auditing for encrypted data, in which a major concern is how to effectively support data dynamics, i.e., data modification, insertion, and deletion. We first determine which factor in existing auditing schemes most limits data dynamics from a cost perspective. We then propose a novel public auditing scheme that provides data dynamics that are orders of magnitude faster than previous methods. Our auditing challenge-response protocol reduces the computation cost of the third-party auditor (TPA) significantly, thus increasing the verification speed for the auditing results. Performance and security analysis demonstrates that the proposed scheme generates minimal computation costs while guaranteeing data integrity and privacy against an untrusted cloud. Changhee Hahn, Hyunsoo Kwon, Daeyeong Kim, Junbeom Hur |
IEEE Trans. Serv. Comput. | 2 |
| 2021 | Enabling Fast Public Auditing and Data Dynamics in Cloud ServicesabstractHosting data in the cloud minimizes maintenance requirements, allowing users to easily access their data on cloud servers. However, cloud servers have full control over outsourced data, which raises security concerns about data integrity. The cloud, for example, might have the financial incentive to discard rarely accessed data, freeing up valuable storage space to, say, host other data-centric applications. Therefore, users need to confirm periodically that their data is intact but this has become increasingly onerous due to the ever-growing volume of data being outsourced. Changhee Hahn, Hyunsoo Kwon, Junbeom Hur |
SERVICES | 2 |
| 2020 | (In-)Security of Cookies in HTTPS: Cookie Theft by Removing Cookie FlagsabstractHyperText Transfer Protocol (HTTP) cookies are widely used on the web to enhance communication efficiency between a client and a server by storing stateful information. However, cookies may contain private and sensitive information about users. Thus, in order to guarantee the security of cookies, most web browsers and servers support not only Transport Layer Security (TLS) but also other mechanisms such as HTTP Strict Transport Security and cookie flags. However, a recent study has shown that it is possible to circumvent cookie flags in HTTPS by exploiting a vulnerability in HTTP software that allows message truncation. In this paper, we propose a novel cookie hijacking attack called rotten cookie which deactivates cookie flags even if they are protected by TLS by exploiting a weakness in HTTP in terms of integrity checks. According to our investigation, all major browsers ignore uninterpretable sections of the header of HTTP response messages and accept incorrect formats without any rejection. We demonstrate that, when combined with TLS or application vulnerabilities, this form of attack can obtain private cookies by removing cookie flags. Thus, the attacker can impersonate a legitimate user in the eyes of the server when cookies are used as an authentication token. We prove the practicality of our attack by demonstrating that our attack can lead five major web browsers to accept a cookie without any cookie flags. We thus present a mitigation strategy for the transport layer to preserve cookie security against our attack. Hyunsoo Kwon, Hyunjae Nam, Sangtae Lee, Changhee Hahn, Junbeom Hur |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2019 | Trustworthy Delegation Toward Securing Mobile Healthcare Cyber-Physical SystemsabstractAttribute-based encryption (ABE) offers a promising solution for flexible access control over sensitive personal health records in a mobile healthcare system on top of a public cloud infrastructure. However, ABE cannot be simply applied to lightweight devices due to its substantial computation cost during decryption. This problem could be alleviated by delegating significant parts of the decryption operations to computationally powerful parties, such as cloud servers, but the correctness of the delegated computation would be at stake. Thus, previous works enabled users to validate the partial decryption by employing a cryptographic commitment or message authentication code (MAC). This paper demonstrates that the previous commitment or MAC-based schemes cannot support verifiability in the presence of potentially malevolent cloud servers. We propose two concrete attacks on previous commitment or MAC-based schemes. We propose an effective countermeasure scheme for securing resource-limited mobile healthcare systems and provide a rigorous security proof in the standard model, demonstrating that the proposed scheme is secure against our attacks. The experimental analysis shows that the proposed scheme provides the similar performance compared with the previous commitment-based schemes and outperforms the MAC-based scheme. Changhee Hahn, Hyunsoo Kwon, Junbeom Hur |
IEEE Internet Things J. | 2 |
| 2019 | Secure deduplication with reliable and revocable key management in fog computing
Hyunsoo Kwon, Changhee Hahn, Kyungtae Kang, Junbeom Hur |
Peer-to-Peer Netw. Appl. | 1 |
| 2018 | Toward Trustworthy Delegation: Verifiable Outsourced Decryption with Tamper-Resistance in Public Cloud StorageabstractFor building a secure cloud storage service on top of a public cloud infrastructure, attribute-based encryption (ABE) has been a preferred solution due to its flexible access control. ABE, however, incurs heavy computation cost on users during decryption. Thus, previous studies solved this problem by enabling cloud servers to perform a part of decryption operations on behalf of the users. In order to empower users to verify the correctness of the delegated decryption by the cloud, they employed a cryptographic commitment or message authentication code (MAC) to enable users to check the correctness of partial decryption of the cloud. However, the previous schemes fail to ensure the correctness of computation in the presence of malicious cloud servers. In this paper, we propose a novel and generic commitment scheme for ABE, which is secure against tampering attacks by malicious cloud servers. According to the performance analysis, the proposed scheme is only 0.5 ms slower on average than the previous commitment-based schemes and two to three times faster than the MAC-based scheme. Changhee Hahn, Hyunsoo Kwon, Junbeom Hur |
IEEE CLOUD | 2 |
| 2017 | Scalable and Reliable Key Management for Secure Deduplication in Cloud StorageabstractSecure deduplication using convergent encryption eliminates duplicate data and stores only one copy to save storage costs while preserving the security of the outsourced data. However, convergent encryption produces a number of encryption keys, of which size is linear to the number of different data. Although a deduplication scheme has been proposed for efficient convergent key management recently, it has drawbacks in terms of scalability and key management security. In order to solve these problems, we propose a novel secure deduplication scheme with scalable and reliable key management based on paring-based cryptography. The proposed scheme does not require additional secure channels to distribute key components while still guaranteeing secure key management as opposed to the previous schemes. Hyunsoo Kwon, Changhee Hahn, Dongyoung Koo, Junbeom Hur |
CLOUD | 1 |
| 2017 | Secure deduplication for multimedia data with user revocation in cloud storage
Hyunsoo Kwon, Changhee Hahn, Junbeom Hur |
Multim. Tools Appl. | 1 |
| 2017 | Secure authentication using ciphertext policy attribute-based encryption in mobile multi-hop networks
Hyunsoo Kwon, Daeyeong Kim, Changhee Hahn, Junbeom Hur |
Multim. Tools Appl. | 1 |
| 2016 | Enhanced authentication for outsourced educational contents through provable block possession
Changhee Hahn, Hyunsoo Kwon, Junbeom Hur |
Multim. Tools Appl. | 2 |
| 2016 | Privacy-preserving public auditing for educational multimedia data in cloud computing
Daeyeong Kim, Hyunsoo Kwon, Changhee Hahn, Junbeom Hur |
Multim. Tools Appl. | 2 |
| 2014 | A Privacy Threat in 4th Generation Mobile Telephony and Its Countermeasure
Changhee Hahn, Hyunsoo Kwon, Kyungtae Kang, Junbeom Hur |
WASA | 2 |
| 2014 | Secure Device-to-Device Authentication in Mobile Multi-hop Networks
Hyunsoo Kwon, Changhee Hahn, Kyungtae Kang, Junbeom Hur |
WASA | 1 |