Shihan Qin

dblp:164/1542 · DBLP profile ↗
← Back
3ranked-venue papers
2as first author
3since 2021 · last 2026
0009-0002-3310-241XORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 2 · 1 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2026 Securing leakage and collusion attacks on encrypted cloud storage using memorizable passwords
abstract
Abstract Encryption is the most direct technique to protect data confidentiality when users outsource their data to the cloud. Typically, ciphertexts are stored in the cloud, while cryptographic keys are managed by a key management server (KMS). However, this approach introduces new challenges in securely managing both keys and ciphertexts. Specifically, two crucial issues remain unresolved. One is that the simultaneous leakage of data encryption key and ciphertexts stored in cloud can directly compromise user data. Another is that if the cloud and KMS collude, they can trivially retrieve user data. In this work, we propose a Password-protected Encrypted Cloud Storage scheme PECS that is resilient to the aforementioned leakage and collusion attacks. In PECS, the users can encrypt/decrypt their data using only a password without storing any key material, and neither the cloud nor KMS learns any information about the user data or keys. Technically, we introduce a re-encryption mechanism performed by the cloud to prevent an adversary from obtaining the original ciphertexts. Furthermore, the user encrypts key wrap before sending it to the cloud, under a pair of password-derived secret and public key. Both the data encryption keys and password are protected from being exposed by the servers through an oblivious pseudorandom function (OPRF). Provable security and efficiency of PECS are demonstrated through comprehensive analyses.
Shihan Qin, Rui Zhang 0002, Hui Ma 0002
Cybersecur.1
2025 Practical and veritable threshold multi-factor authentication for mobile devices
abstract
Abstract Multi-factor authentication (MFA) is extensively employed in mobile applications to enhance security, including Internet of Vehicles, healthcare systems, smart homes, etc. Traditional MFA requires users to present specific factors, which can be inconvenient if certain factors are unavailable. To address this, $ (t, n) $-threshold MFA (T-MFA) allows users to select any $ t $ out of $ n $ registered factors for authentication. However, existing T-MFA solutions face four key issues: (i) reliance on $ n-1 $ devices, which may be impractical; (ii) susceptibility to denial of service when the mandatory factor fails; (iii) limited factor types, reducing user flexibility; and (iv) increasing client-side computational costs with higher $ t $. In this work, we propose a veritable $ (t, n) $-threshold multi-factor authenticated key exchange protocol that addresses these challenges. Utilizing oblivious programmable pseudorandom functions (OPPRF) as main tools, we eliminate dependence on multiple devices, mandatory factors, and restricted factor types, achieving what we called veritable. We present a new construction of batched OPPRF to reduce client-side costs from $ O(t) $ to $ O(1) $, with 2 exponentiations cost by the client and $ t+1 $ by the server. We implement it with JavaScript to validate its flexibility and efficiency, making it highly suitable for mobile device applications.
Shihan Qin, Yansen Xin, Birou Gao, Rui Zhang 0002
Comput. J.1
2025 Cocoon: certificateless blockchain wallet supporting both stealth address and revocation
abstract
Abstract The breaches of the blockchain wallet keys greatly harm the security of blockchain transactions. To protect the secret keys, the known solutions, such as hierarchical deterministic wallets proposed in BIP32 or stealth addresses adopted in Monero, have been extensively researched. However, most of the existing works assume the key is safe, in the sense that it cannot be stolen or damaged, which is not true in practice. Moreover, current key revocation mechanisms either rely on centralized authorities, compromising decentralization, or require economic incentives to ensure nodes remain consistantly online. In this paper, we introduce Cocoon, the first blockchain wallet scheme that supports stealth addresses and provides a wallet revocation mechanism without the need for certificates. Cocoon not only ensures the privacy of wallet secret keys but also can individually revoke compromised keys with high performance. Our contributions are three-fold: First, we present the formal model and the related security definitions. Next, we give a generic construction based on the hierarchical identity-based signature, identity-based key encapsulation mechanism and non-interactive zero-knowledge proof. We then extend the scheme to the hierarchical setting for diverse scenarios. Finally, we give the implementation, and the results show that the scheme is practical.
Birou Gao, Rui Zhang 0002, Yang Tao 0001, Shihan Qin
Cybersecur.4