VLDB 2026 Research / reviewers in the wild / expert
Kunpeng Bai
dblp:180/8994
· DBLP profile ↗
6ranked-venue papers
3as first author
2since 2021 · last 2025
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 4 · 2 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Decentralized Privacy-Preserving Authenticated Key Exchange Using Real-World AttributesabstractWhile decentralized authentication mechanisms have gained significant attention for enabling user-centric identity management without centralized authorities, the critical counterpart - authenticated key exchange (AKE) in decentralized settings - remains understudied. Although it forms the basis for secure communication in decentralized scenarios, shifting existing AKE protocols to decentralized settings is impractical: the trust assumption is different, and the insufficient support for dynamic identity attributes, etc. To address these challenges, we present a novel decentralized AKE protocol that innovatively integrates attribute authentication with key exchange through multi-party secure computation. Building upon MPCAuth's foundational framework (S&P 23), our protocol goes further to provide key exchange based on authentication of real-world attributes such as a digital passport and email address, etc. Our protocol establishes a new paradigm for decentralized AKE without complex credential operations and heavy zero-knowledge proof. The core of our protocol is a distributed way to securely reconstruct the attributes and establish a session key. We further evaluate its performance across multiple servers. Experimental results on servers under 5 demonstrate that it can finish the full AKE procedure in an acceptable time, enabling efficient and scalable multi-party key AKE in distributed environments. Xiao Lan, Hao Ren 0001, Kunpeng Bai |
ACSAC | 6 |
| 2025 | ThPlA: Threshold Passwordless Authentication Made Usable and ScalableabstractPasswordless user authentication schemes with FIDO as the standard have been widely deployed in web applications. Users use hardware tokens to store their identity credentials (i.e., signing keys) and implement strong authentication through a challenge-response mechanism, avoiding the security risks associated with traditional password-based authentication. Distributed Web services can greatly alleviate the system reliability problem caused by single points of failure, and thus have received increasing attention and research. In distributed systems, resources are distributed across multiple servers, and users must interact with them (or a subset of them in thresholding) to obtain network services. User authentication among the distributed (threshold) systems also poses a challenge: how to ensure security and ease of use at the same time? In particular, users need to authenticate to multiple servers when accessing distributed services, and in the case of using FIDO authentication, users need to authenticate to each server using challenge-response authentication, which will greatly reduce the user experience. In this work, we propose the concept namedThreshold Passwordless Authentication(ThPlA) to address this issue. ThPlA allows users to authenticate to at-of-nthresholding system. ThPlA is designed to be compatible with existing FIDO tokens and requires no extra hardware modifications; the user only needs to interact with the hardware token once during an authentication session; and on the service side, the servers do not need to communicate with each other. ThPlA is based on the component namedNon-interactive Threshold Nonce Generation(NI-ThNG), which extends the two-party challenge-response mechanism tot-of-nsettings. We provide a formal definition of ThPlA and NI-ThNG and give practical constructions. We also provide a performance evaluation of ThPlA and NI-ThNG, respectively. Our experimental results show that the schemes are efficient and practical for real-world applications, even in large-scale distributed systems. Qianwen Gao, Yuan Lu 0001, Kunpeng Bai, Zhenfeng Zhang, Yichi Tu |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2018 | Unification of identifiers in the Sea-Cloud system
Kunpeng Bai, Dongdai Lin, Chuankun Wu |
Frontiers Comput. Sci. | 2 |
| 2018 | Protect white-box AES to resist table composition attacksabstractWhite‐box cryptography protects cryptographic software in a white‐box attack context (WBAC), where the dynamic execution of the cryptographic software is under full control of an adversary. Protecting AES in the white‐box setting attracted many scientists and engineers, and several solutions emerged. However, almost all these solutions have been badly broken by various efficient white‐box attacks, which target compositions of key‐embedding lookup tables. In 2014, Luo, Lai, and You proposed a new WBAC‐oriented AES implementation, and claimed that their implementation is secure against both Billet et al . 's attack and De Mulder et al . 's attack. In this study, based on the existing table‐composition‐targeting cryptanalysis techniques, the authors show that the secret key of the Luo–Lai–You (LLY) implementation can be recovered with a time complexity of about 2 44 . Furthermore, the authors propose a new white‐box AES implementation based on table lookups, which is shown to be resistant against the existing table‐composition‐targeting white‐box attacks. The authors, key‐embedding tables are obfuscated with large affine mappings, which cannot be cancelled out by table compositions of the existing cryptanalysis techniques. Although their implementation requires twice as much memory as the LLY WBAES to store the tables, its speed is about 63 times of the latter. Kunpeng Bai, Chuankun Wu, Zhenfeng Zhang |
IET Inf. Secur. | 1 |
| 2016 | An AES-Like Cipher and Its White-Box ImplementationabstractWhite-box cryptography aims at implementing a cipher to protect its key from being extracted in an untrusted environment, where the attacker has full access to the execution of the cryptographic software. In 2002, Chow et al. proposed the original white-box implementation of AES. Afterwards, various white-box implementations were presented. However, they were all badly broken because of a weakness of the implemented cryptographic algorithms: every parameter of the cryptographic operations is fixed except the round keys. In this paper, we present an AES-like cipher based on key-dependent S-boxes. The new cipher is designed to meet the design criteria of AES and hence provides a security level comparable to AES to resist black-box attacks. Moreover, we present a white-box implementation for our AES-like cipher, which is sufficient to withstand existing white-box attacks. Kunpeng Bai, Chuankun Wu |
Comput. J. | 1 |
| 2016 | A secure white-box SM4 implementationabstractWhite-box cryptography aims at implementing a cipher to protect its key from being extracted in a white-box attack context, where an attacker has full control over dynamic execution of the cryptographic software. So far, most white-box implementations exploit lookup-table-based techniques and have been broken because of a weakness that the embedded large linear encodings are cancelled out by compositions of lookup tables. In this paper, we propose a new lookup-table-based white-box implementation for the Chinese block cipher standard SM4 that can protect the large linear encodings from being cancelled out. Our implementation, which can resist a series of white-box attacks, requires 32.5MB of memory to store the lookup tables and is about nine times as fast as the previous Xiao–Lai white-box SM4 implementation. Copyright © 2015 John Wiley & Sons, Ltd. Kunpeng Bai, Chuankun Wu |
Secur. Commun. Networks | 1 |