VLDB 2026 Research / reviewers in the wild / expert
Tianyuan Luo
dblp:206/0822
· DBLP profile ↗
4ranked-venue papers
1as first author
4since 2021 · last 2025
0009-0002-3234-4230ORCID · reported
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 2 · 2 since 2021Systems, architecture and hardware · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | An Obfuscator for Securing Ring Confidential Transactions' Signing Keys of CryptocurrenciesabstractRing Confidential Transaction (RingCT) protocols are widely used in cryptocurrencies to protect user privacy. Consequently, a corresponding digital signature scheme, such as a ring signature scheme that hides the signers’ identities, is required. Accordingly, the security of a RingCT protocol depends on the confidentiality of the secret signing keys of the underlying ring signature scheme. However, existing solutions like hardware wallets, Trusted Execution Environments (TEEs), and threshold signature schemes have limitations such as specified expensive hardware, targeting attacks at CPUs on insufficiently secure hardware, and overheads caused by multiple parties. On the contrary, program obfuscation for signature schemes offers advantages over these existing approaches. Concretely, we propose a novel obfuscator that secures the secret keys of the concise linkable spontaneous anonymous group (CLSAG) signature scheme, which is the latest ring signature scheme used in Monero’s RingCT protocol. To achieve enhanced security, the proposed obfuscator leverages Paillier homomorphic encryption to transform secret keys into an obfuscated form resistant to attacks. The security of the proposed obfuscator has been formally proved. Computational efficiency has been both theoretically analyzed and experimentally evaluated with positive results on various testing platforms. Yang Shi 0002, Minyu Teng, Tianyuan Luo, Wenyuan Jiang, Jiayao Gao, Man Ho Au |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2024 | Space-Hard Obfuscation Against Shared Cache Attacks and its Application in Securing ECDSA for Cloud-Based BlockchainsabstractIn cloud computing environments, virtual machines (VMs) running on cloud servers are vulnerable to shared cache attacks, such as Spectre and Foreshadow. By exploiting memory sharing among VMs, these attacks can compromise cryptographic keys in software modules. Program obfuscation serves as a promising countermeasure against key compromises by transforming a program into an unintelligent form while preserving its functionality. Unfortunately, for certain cryptographic algorithms such as the digital signature schemes, it is extremely difficult to construct provably secure obfuscators using traditional obfuscation approaches. To address such a challenge, this study proposes a novel approach to construct obfuscators for cryptographic algorithms named space-hard obfuscation, which can mitigate the threats from adversaries with the capability of acquiring a limited size of memory in shared cache attacks. Considering the extensive use of the Elliptic Curve Digital Signature Algorithm (ECDSA) in cloud-based Blockchain-as-a-Service (BaaS) and its potential vulnerability to shared cache attacks, we construct an exemplary scheme with provable security using space-hard obfuscation for ECDSA. Experimental results have demonstrated the scheme's high efficiency on cloud servers, as well as its successful integration with Hyperledger Fabric and Ethereum, two widely used blockchain systems. Yang Shi 0002, Tianyuan Luo, Xiong Jiang, Bowen Du 0002, Hongfei Fan |
IEEE Trans. Cloud Comput. | 3 |
| 2024 | Obfuscating Verifiable Random Functions for Proof-of-Stake BlockchainsabstractBlockchain systems, such as Bitcoin and Ethereum, enable new applications, such as cryptocurrencies and smart contracts, using decentralized consensus without trusted authorities. Since the most widely used technique, proof-of-work, suffers from the costs of high latency and huge energy consumption, a number of blockchain systems based on proof-of-stake techniques have been proposed in recent years, many of which use verifiable random functions as fundamental building blocks, such as Ouroboros, Algorand, and Dfinity, etc. The secret key of a verifiable random function scheme, similar to that of a digital signature scheme, is critical to the security of a verifiable random function and the entire blockchain system built on it. To protect the secret keys of verifiable random functions and maintain the efficiency of the proof-of-stake protocol, we extend the objective of cryptographic program obfuscation to verifiable random functions and propose a novel obfuscatable verifiable random function scheme. In particular, we propose an obfuscator that can transform the implementation of the scheme's random string generation algorithm and the given secret key into an unintelligible form. Obfuscated implementations of the random string generation algorithm are deployed on peers of a blockchain for supporting normal routines of the proof-of-stake protocol. Even if a hacker has controlled a peer's host, the owner's secret key will not be compromised because the key has been hardwired into the obfuscated implementation in an “encrypted manner”. We formally prove the correctness and the security of the proposed verifiable random function and obfuscator. Since the proposed scheme supports the general semantics of verifiable random functions, it can be used as a building block for all blockchain systems that adopt proof-of-stake protocols based on Verifiable Random Functions (VRFs). The extensive experimental result indicated that the scheme performs well on various platforms, such as cloud servers, workstations, PCs, smartphones, and embedded devices. Yang Shi 0002, Tianyuan Luo, Jingwen Liang, Man Ho Au, Xiapu Luo |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2022 | Efficiently Obfuscating Proxy Signature for Protecting Signing Keys on Untrusted Cloud ServersabstractNowadays, with the development and massive use of cloud services, protecting the information security on untrusted cloud servers is becoming an important issue. Since the signing key is one of the most important parts of secret information and the Schnorr signature is frequently used in on-cloud systems, this study proposes an obfuscatable proxy signature scheme based on the Schnorr signature and the Elgamal encryption, and presents a provably secure obfuscator for the scheme. Moreover, the application scenario of the proposed scheme for untrusted cloud servers has been discussed. Experimental results have indicated that the proposed scheme is computationally efficient. Tianyuan Luo, Yang Shi 0002 |
CSCWD | 1 |