Shohei Kakei

dblp:178/5088 · DBLP profile ↗
← Back
7ranked-venue papers
2as first author
7since 2021 · last 2026
0000-0003-3137-4956ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 4 · 1 first-author · 4 since 2021Artificial intelligence and machine learning · 1 · 1 first-author · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2026 VDDPI: Verifiable Decentralized Data Processing Infrastructure for Data Usage Control and Confidential Data Processing
Shota Tokuda, Shohei Kakei, Yoshiaki Shiraishi, Shoichi Saito
IEEE Trans. Dependable Secur. Comput.2
2025 Investigating the Inconsistency of Errors Between CAs in the Wild for Trustworthiness Evaluation in Cross-Domain Authentication
abstract
Motivated by challenges in cyber-physical systems (CPS), this paper investigates the inconsistency of errors between certification authorities (CAs) to evaluate trustworthiness in cross-domain authentication. CPS integrates physical space and cyberspace through interconnected devices. Cross-domain authentication is essential for CPS, enabling dynamic communication between devices from different domains. Public key infrastructure (PKI) facilitates this authentication as multiple CAs bind public keys to device identities. However, recent research on evaluating the trustworthiness of PKI focuses on a single CA and overlooks the relationships between CAs. We analyze the inconsistency of errors between CAs based on public key certificates collected from the wild via Censys. Our findings reveal that CAs with inconsistencies often lack essential access information for CAs, risking incomplete certificate verification and communication with fraudulent devices. This research highlights the importance of considering CA relationships in trustworthiness evaluations for secure cross-domain authentication in heterogeneous CPS environments.
Shohei Kakei, Yoshiaki Shiraishi, Shoichi Saito
KES1
2024 Decentralized Data Usage Control with Confidential Data Processing on Trusted Execution Environment and Distributed Ledger Technology
Shota Tokuda, Shohei Kakei, Yoshiaki Shiraishi, Shoichi Saito
NSS2
2023 Blockchain-based cross-domain authorization system for user-centric resource sharing
abstract
User-centric data sharing is essential to encourage citizens' active participation in the digital economy. One key to smart cities, a form of the digital economy, is the promotion of public use of citizen data. Nevertheless, it is not easy to utilize data without citizens’ consent. In this study, we took a technological approach to these issues. User-managed access (UMA) is a well-known framework for delegating resource access rights to others on the Internet. In UMA, authorization mechanisms are designed to be centralized so that resource owners can centrally manage access rights for various resources stored in different domains. However, the lack of transparency in the authorization mechanism is a barrier to its implementation in large-scale systems such as smart cities. In this study, we developed a blockchain-based cross-domain authorization architecture that enables a resource-sharing ecosystem in which organizations that wish to utilize data can freely trade with each other. The proposed architecture solves the transparency problem that conventional authorization systems have had by designing the authorization mechanism on blockchain technology. We implemented the proposed architecture as smart contracts and evaluated its processing performance. The resultant time required for delegating access rights and accessing resources was less than 500 ​ms. Furthermore, we found that the fluctuation in the processing time overhead was small. Based on these results, we concluded that performance degradation with the proposed architecture is minor.
Yuki Ezawa, Shohei Kakei, Yoshiaki Shiraishi, Masami Mohri, Masakatu Morii
Blockchain Res. Appl.2
2022 Plug and Analyze: Usable Dynamic Taint Tracker for Android Apps
abstract
Taint analyses, especially static taint analyses, are utilized to uncover hidden and suspicious behaviors in Android apps. However, current static taint analyzers use imprecise Android models, producing unreliable results and increasing the result verification cost. On the other hand, current dynamic taint trackers accurately detect execution paths. However, they depend on specific Android versions and modified devices, reducing their usability. Also, the users may not be able to analyze prepared datasets comprehensively. The results of the current analyses would be biased and less trustworthy. This paper presents a new dynamic taint analyzer called T-Recs that tracks information flows by recording the app execution at the app's bytecode level on an Android device and reconstructing the execution on a server independently of specific Android versions and devices. The users can instantly start analyzing apps with T-Recs after plugging an unmodified device into their computer. We implemented and evaluated T-Recs with 158 apps of DroidBench 3.0 in comparison with current taint analyzers: FlowDroid (w/ and w/o IC3), Amandroid, DroidSafe, and TaintDroid (w/ and w/o IntelliDroid), and only T-Recs achieved 100% accuracy. The result of privacy leak detection in 96 popular Google Play apps shows that T-Recs detected 43 true positives, the highest among compared tools. Also, T-Recs analyzed 39,480 apps from Google Play and Anzhi, showing that T-Recs can be applied to apps that vary in supported SDK versions. Further, the result of ID leak detection in 158 popular apps from Google Play in 2021 shows that T-Recs can detect leaks in recently-developed apps. T-Recs is one of the promising tools for future app analysis.
Hiroki Inayoshi, Shohei Kakei, Shoichi Saito
SCAM2
2022 Granting Access Privileges Using OpenID Connect in Permissioned Distributed Ledgers
Shohei Kakei, Yoshiaki Shiraishi, Shoichi Saito
SecureComm1
2021 VTDroid: Value-based Tracking for Overcoming Anti-Taint-Analysis Techniques in Android Apps
abstract
Bytecode-level taint tracking discovers suspicious apps on the Android platform; however, malicious apps can bypass it by transferring information via system layers in the Android. A context tainting countermeasure has been devised, but since it employs a list of flow-causing API methods, it will miss flows when unlisted methods are exploited and can also produce false positives. This paper presents a new taint-tracking technique operating value logging and matching based on the flows’ characteristics to detect such flows without relying on lists of API methods. We implemented it into our taint-tracking system called VTDroid and confirmed its effectiveness with our test suite. We also evaluated it with popular apps collected from Google Play. The results show that the precision of VTDroid is 37 points higher than the context tainting.
Hiroki Inayoshi, Shohei Kakei, Eiji Takimoto, Koichi Mouri, Shoichi Saito
ARES2