VLDB 2026 Research / reviewers in the wild / expert
Jiayao Gao
dblp:204/7942
· DBLP profile ↗
11ranked-venue papers
3as first author
7since 2021 · last 2026
0000-0002-8954-1668ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 7 · 3 first-author · 4 since 2021Security and privacy · 3 · 3 since 2021Human-computer interaction and ubiquitous computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | WBSLT: A Framework for White-Box Encryption Based on Substitution-Linear Transformation Ciphers
Yang Shi 0002, Tianchen Gao, Jiayao Gao, Kaifeng Huang 0001 |
NDSS | 4 |
| 2026 | Securing Symmetric Encryption Based on Substitution-Permutation Network Against White-Box AttacksabstractExtensive research has been done on the security of symmetric encryption algorithms in the black-box attack contexts, where the execution platforms are supposed to be secure. Recent studies intend to secure encryption algorithms in a more challenging but widely adopted scenario, the white-attack context (WBAC), where the adversaries have full visibility of the implementations of cryptosystems and full control over execution platforms. Various of approaches for protecting symmetric encryption algorithms in the WBAC have been proposed. Unfortunately, most existing approaches have been broken. This paper proposes a novel approach for securing symmetric encryption algorithms based on substitution-permutation network (SPN). Our key idea is to incorporate additional secret components into lookup tables to expand and dramatically change the inner states of encryption. Unlike existing approaches, these components do not need to be annihilated in adjacent rounds, and the ciphertext remains essentially unchanged. To recover the plaintext, only simple operations and the standard decryption algorithm are required. Our approach can be applied to protect SPN-based symmetric encryption algorithms such as AES. Security analysis indicates that the approach is expected to be resistant to both existing and unknown attacks. Furthermore, experimental evaluation shows that our approach performs well on various platforms. Yang Shi 0002, Tianchen Gao, Qiaoliang Ouyang, Junqing Liang, Mianhong Li, Jiayao Gao, Xiapu Luo |
IEEE Trans. Dependable Secur. Comput. | 6 |
| 2025 | An Obfuscator for Securing Ring Confidential Transactions' Signing Keys of CryptocurrenciesabstractRing Confidential Transaction (RingCT) protocols are widely used in cryptocurrencies to protect user privacy. Consequently, a corresponding digital signature scheme, such as a ring signature scheme that hides the signers’ identities, is required. Accordingly, the security of a RingCT protocol depends on the confidentiality of the secret signing keys of the underlying ring signature scheme. However, existing solutions like hardware wallets, Trusted Execution Environments (TEEs), and threshold signature schemes have limitations such as specified expensive hardware, targeting attacks at CPUs on insufficiently secure hardware, and overheads caused by multiple parties. On the contrary, program obfuscation for signature schemes offers advantages over these existing approaches. Concretely, we propose a novel obfuscator that secures the secret keys of the concise linkable spontaneous anonymous group (CLSAG) signature scheme, which is the latest ring signature scheme used in Monero’s RingCT protocol. To achieve enhanced security, the proposed obfuscator leverages Paillier homomorphic encryption to transform secret keys into an obfuscated form resistant to attacks. The security of the proposed obfuscator has been formally proved. Computational efficiency has been both theoretically analyzed and experimentally evaluated with positive results on various testing platforms. Yang Shi 0002, Minyu Teng, Tianyuan Luo, Wenyuan Jiang, Jiayao Gao, Man Ho Au |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2025 | SHBC-VDRM: Space-Hard Block Cipher for Video Digital Rights ManagementabstractVideo has become the primary channel for people to access information and engage in leisure and entertainment activities. Video service platforms have emerged to meet these demands and create significant profits. These platforms aggregate diverse videos and offer subscription services, aiming to provide convenient and personalized viewing experiences. To safeguard the copyright of video content against unauthorized access, these platforms employ digital rights management (DRM) technologies. However, the use of DRM faces significant security challenges due to the presence of malware or malicious users, which can compromise the decryption program running on user devices and lead to illegal video content distribution. This paper proposes a high-performance encryption scheme for video DRM protection. We establish the security of our proposed scheme through rigorous mathematical proof and analyze its effectiveness in the context of the video DRM scenario. Furthermore, the experimental results demonstrate that our scheme outperforms other schemes. Overall, our proposed scheme offers a promising solution to the security challenges faced by DRM technologies in protecting video content. Its efficiency, security, and resilience to various attacks make it a viable option for video service platforms seeking to enhance the security of their digital content. Yang Shi 0002, Qiaoliang Ouyang, Jinkun Wang, Guodong Ye, Bowen Du 0002, Jiayao Gao |
IEEE Trans. Netw. Serv. Manag. | 9 |
| 2024 | Obfuscating Ciphertext-Policy Attribute-Based Re-Encryption for Sensor Networks with Cloud StorageabstractWith the rapid growth of wireless sensor networks, secure data transmission, storage, and distribution in such networks has become an urgent demand. To defend against security risks such as data leakage, key compromise, and unauthorized misuse of data simultaneously, we propose a novel obfuscatable ciphertext-policy attribute-based re-encryption scheme with a specially designed obfuscator. The proposed scheme leverages program obfuscation to transform the re-encryption program codes into an unintelligible form and embed the private keys into the obfuscated implementation. Consequently, the proposed scheme protects data confidentiality and keeps the secrecy of the private key while providing fine-grained access control. Formal proofs for the security of the proposed re-encryption scheme and the obfuscator are provided. Extensive experiments have been conducted on representative platforms, including cloud servers, workstations, and embedded devices, to evaluate the computational efficiency and energy consumption of the scheme. Experimental results indicate that the scheme achieves high efficiency on various platforms and economical energy consumption on typical embedded devices with constrained resources. Minyu Teng, Jingxuan Han, Jintao Xie, Jiayao Gao, Yang Shi 0002 |
ACM Trans. Sens. Networks | 4 |
| 2021 | A Novel Model-Based Security Scheme for LoRa Key GenerationabstractPhysical layer key generation has attracted considerable attention in the past decade since it provides an alternative solution for the key establishment in wireless networks using channel reciprocity. In this paper we explore the possibility of physical layer key generation for emerging Low Power Wide Area Networks (LPWAN) such as LoRa (Long Range). However, due to the lower transmission rates of LPWANs compared to Wi-Fi and Zigbee, the channel reciprocity is relatively low, which makes timely key generation challenging. To address this problem, we propose a novel information-theoretic key generation scheme that can operate at all data rate settings, featuring a model-based key generation method. Furthermore, we derive an optimal window size to calculate the parameters of the channel model based on a random waypoint model to balance the channel reciprocity and entropy. Extensive evaluations on a campus testbed show that our method can achieve up to 13.8 bps key generation rate. Compared to state-of-the-art methods, the proposed method improves key generation rate by 3x to 5x. We also analyzed the security of the proposed approach and demonstrated it to be resilient to eavesdropping attacks. Jiayao Gao, Weitao Xu, Salil S. Kanhere, Sanjay K. Jha, Jun Young Kim, Walter Huang, Wen Hu 0001 |
IPSN | 1 |
| 2021 | Seirios: leveraging multiple channels for LoRaWAN indoor and outdoor localizationabstractLocalization is important for a large number of Internet of Things (IoT) endpoint devices connected by LoRaWAN. Due to the bandwidth limitations of LoRaWAN, existing localization methods without specialized hardware (e.g., GPS) produce poor performance. To increase the localization accuracy, we propose a super-resolution localization method, called Seirios, which features a novel algorithm to synchronize multiple non-overlapped communication channels by exploiting the unique features of the radio physical layer to increase the overall bandwidth. By exploiting both the original and the conjugate of the physical layer, Seirios can resolve the direct path from multiple reflectors in both indoor and outdoor environments. We design a Seirios prototype and evaluate its performance in an outdoor area of 100 m × 60 m, and an indoor area of 25 m × 15 m, which shows that Seirios can achieve a median error of 4.4 m outdoors (80% samples < 6.4 m), and 2.4 m indoors (80% samples < 6.1 m), respectively. The results show that Seirios produces 42% less localization error than the baseline approach. Our evaluation also shows that, different to previous studies in Wi-Fi localization systems that have wider bandwidth, time-of-fight (ToF) estimation is less effective for LoRaWAN localization systems with narrowband radio signals. Jun Liu 0074, Jiayao Gao, Sanjay K. Jha, Wen Hu 0001 |
MobiCom | 2 |
| 2020 | PhD Forum Abstract: Key Generation Scheme for LPWAN IoT devicesabstractInternet of Things (IoT) devices are almost everywhere around us, whether you are aware of them or not. Although the devices are usually tiny, due to the considerable amount, they store and send enormous data, many of which are critical. That high-value information, together with impoverished computation power, resulting in the weak security methods, makes IoT devices the ideal targets for attackers.Taking the advantages of reciprocity and randomness of wireless fading channels, key generation via physical layer is attracting more attention. It becomes a remarkable solution for wireless IoT communication in recent years. However, the feasibility under long range and low data rate scenarios of narrow band low power wide area network (LPWAN) lacks proper studies.To address the above issue, I propose to develop a novel key generation architecture that can apply to IoT communications especially under low power wide area scenarios. The system should also be resilient to various kinds of attacks that may be applied to the IoT devices. Finally, the proposed method will be implemented on devices and validated on practical application scenarios. Jiayao Gao |
IPSN | 1 |
| 2020 | Poster Abstract: A Novel Modeling Involved Security Approach for LoRa Key GenerationabstractTaking the advantages of reciprocity and randomness of wireless fading channels, key generation via physical layer is attracting more attention. It becomes a remarkable solution for wireless communication in recent years. However, the feasibility under long-range and low data rate scenarios of narrow band low power wide area network (LPWAN) lacks proper studies. In this poster, we introduce a novel modeling method for Long Range Wide Area Network (LoRaWAN) key generation. The approach combines several signal processing techniques and using measured real-time Received Signal Strength Indicator (RSSI) to improve the applicability of key generation as well as increasing key generation rate (KGR) significantly. Jiayao Gao, Weitao Xu, Salil S. Kanhere, Sanjay K. Jha, Wen Hu 0001 |
IPSN | 1 |
| 2018 | Intrusion-Resilient Undetachable Digital Signature for Mobile-Agent-Based Collaborative Business SystemsabstractMobile agents are useful in collaborative business systems due to their mobility and autonomy, which can roam over the Internet to purchase goods and services on behalf of their owners. However, given attacks from a malicious host, it is a challenge to securely sign a contract on behalf of the owner (the original signer). In this paper, we propose an intrusion-resilient undetachable digital signature (IR-UDS) approach to mitigate the security risk of signing key leakage on the signer's host, base device, and potentially malicious remote hosts, as well as the risk of misusing the signing algorithm on remote hosts. An attacker will be unable to forge the past and future signatures as long as the base device is secure, even if the current signing key of the original signer has been gained. When the base device is compromised, although the future signatures could be forged, all past signatures remain secure. Furthermore, the encrypted signing function has been combined with the original signer's requirement to prevent the misuse of signing algorithm and the exposure of original signing key on malicious hosts. Security analysis has indicated that our scheme can defeat a variety of attacks, and experimental evaluations have demonstrated the good performance of the scheme. Yang Shi 0002, Jingwen Liang, Jingxuan Han, Jiayao Gao, Guoyue Xiong, Hongfei Fan |
CSCWD | 4 |
| 2017 | An Obfuscatable Aggregatable Signcryption Scheme for Unattended Devices in IoT SystemsabstractSigncryption is a cryptographic technique for simultaneously performing both digital signature and data encryption. It is effective for protecting the confidentiality and unforgeability of communications in Internet of Things (IoT) systems, especially when a number of generated ciphertexts can be aggregated into a compact form. However, device capture attacks are commonly threatening the implementations of signcryption on unattended devices by enabling an attacker to extract the cryptographic key from a captured device. Motivated by this issue, we propose a novel and specialized obfuscatable aggregatable signcryption scheme (OASC) together with an obfuscator for the signcryption algorithm, which has been designed by taking into account that the computational and communication costs should be sufficiently small (light-weighted) to fit applications in resource-constrained embedded devices. The proposed obfuscator can protect signcryption programs from key-extraction attacks by transforming the programs into unintelligible obfuscated programs. To the best of our knowledge, this is the first OASC in the community. The scheme's security features with respect to obfuscation, confidentiality, and unforgeability have been theoretically proved. Moreover, in comparison with other (nonobfuscatable) aggregatable signcryption schemes, the scheme's computational efficiency is positioned at a medium level while the communication cost is also relatively small, with extra unique security features benefiting from obfuscation. Experiments on different devices indicated that the proposed scheme performs reasonably well as expected. The scheme is widely applicable for various scenarios of IoT, where information is sent from unattended leaf nodes to a sink point. Yang Shi 0002, Jingxuan Han, Jiayao Gao, Hongfei Fan |
IEEE Internet Things J. | 4 |