VLDB 2026 Research / reviewers in the wild / expert
Junbeom Hur
dblp:21/1967
· DBLP profile ↗
79ranked-venue papers
11as first author
34since 2021 · last 2026
0000-0002-4823-4194ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 24 · 1 first-author · 18 since 2021Computer networks · 18 · 5 first-author · 3 since 2021Applied, interdisciplinary, general and emerging computing · 9 · 2 since 2021Systems, architecture and hardware · 7 · 2 first-author · 3 since 2021Software engineering, systems software and programming languages · 6 · 4 since 2021Databases, data management, data science and information retrieval · 6 · 3 first-author · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 6 · 1 since 2021Artificial intelligence and machine learning · 4 · 4 since 2021Human-computer interaction and ubiquitous computing · 2Theory of computation · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Abortection: Robust TSX-Based Detection of Cache Side-Channel Attacks on Modern Intel CPUs with Non-Inclusive LLCsabstractCache side-channel attacks such as Flush+Reload and Prime+Probe continue to threaten isolation across mutually untrusted processes. Although many attack detection mechanisms have been proposed, recent Intel processors introduce non-inclusive last-level caches and directory-based coherence. These architectural changes give rise to new attack behaviors that have not been examined by previous detection methods, which predominantly focus on inclusive cache hierarchies. As a result, real-time techniques that can account for both flush-based and directory-based eviction patterns without relying on assumptions specific to individual attack types remain largely underexplored. Hyungjung Joo, Hodong Kim, Junbeom Hur |
AsiaCCS | 3 |
| 2026 | SPCA: Stream Parser Confusion Attack for Web Application Firewall Evasion in HTTP/2abstractWeb Application Firewalls (WAFs) are widely deployed as a primary defense mechanism against injection-based web attacks by inspecting HTTP traffic for malicious patterns. However, structural inconsistencies in HTTP/2 stream parsing introduce a protocol-level attack surface that remains insufficiently examined. We propose the Stream Parser Confusion Attack (SPCA), a novel evasion technique that exploits discrepancies between WAFs and backend HTTP/2 servers in processing stream dependencies and priorities. SPCA operates without altering payload content, relying solely on RFC-compliant manipulation of stream priority weights and dependency trees to deliver unmodified malicious inputs past WAF inspection. To evaluate the feasibility and generality of SPCA, we design three well-defined stream topologies—skewed, k-ary, and unbalanced—each capturing unique structural traits observed in real-world HTTP/2 scheduling patterns. Each topology's dataset consists of 500 structurally distinct requests, derived by embedding 100 malicious test cases across five distinct priority levels. We transmit these requests against 13 commercial and open-source WAFs and 20 backend web frameworks in a black-box setting. Each topology individually achieves a bypass success rate of 49.66% for the skewed tree, 44.62% for the k-ary tree, and 46.38% for the unbalanced tree. Under the concurrent attack with three topologies, the overall success rate exceeds 89% on average against the open-source and commercial WAFs. These findings demonstrate that structure-only protocol-compliant manipulation is sufficient to systematically bypass modern WAFs, revealing critical blind spots in HTTP/2-aware traffic inspection. We responsibly disclosed the identified issues to all affected vendors and received acknowledgments of the disclosures. Kyungrok Choi, Woonghee Lee 0004, Junbeom Hur |
WWW | 3 |
| 2026 | A domain-specific knowledge graph for reasoning over AI security threats and defenses
Samaneh Shamshiri, Danial Javaheri, Mahdi Fahmideh, Junbeom Hur |
Knowl. Based Syst. | 4 |
| 2026 | Decoupled and Privacy-Preserving Key Generation in ABE Under the Minimal Disclosure PrincipleabstractAttribute-Based Encryption (ABE) enables fine-grained access control over outsourced data, but its key generation process typically requires users to disclose their complete attribute sets, introducing significant privacy risks. Existing privacy-preserving approaches—such as those based on zero-knowledge proofs or tightly coupled interactive protocols—suffer from limited scalability, high communication costs, and insufficient support for selective attribute disclosure. To address these limitations, we propose a privacy-enhancing key generation protocol guided by the principle ofMinimal Disclosure, which ensures that users disclose only the minimally necessary subset of attributes required for authorization. Our protocol decouples attribute verification from key issuance: users first obtain cryptographically verifiable attribute tokens, and later issue blinded key requests over selectively chosen attributes. This design enables selective disclosure, supports reusable attribute credentials, and enhances user autonomy. To improve scalability, we introduce a lightweight batch verification mechanism that reduces computation and communication overhead for the attribute authority. We prove that our protocol achieves thebindingandhidingproperties under standard cryptographic assumptions, and we formally verify these guarantees in the symbolic model using the ProVerif tool. In addition, we propose two privacy metrics—AttributeInference Gain (AIG) andPrivacy Gain (PG)—alongside an entropy-based analysis to quantify resistance against attribute inference attacks. Experimental results show that our scheme effectively mitigates inference leakage while offering substantial efficiency gains compared to existing schemes. Youwen Zhu, Xiaodong Yang 0006, Changhee Hahn, Jian Wang 0038, Junbeom Hur |
IEEE Trans. Inf. Forensics Secur. | 7 |
| 2025 | Deep Dive into In-app Browsers: Uncovering Hidden Pitfalls in Certificate ValidationabstractWhile providing a seamless user experience by enabling web access within the app, in-app browsers raise security concerns, particularly in certificate validation, which can leave users vulnerable to Man-In-The-Middle (MITM) or phishing attacks unless appropriately implemented.In this paper, we systematically evaluated the certificate validation mechanisms of in-app browsers, also known as WebView, focusing on how effectively they comply with X.509 certificate standards and support advanced certificate extensions related to revocation and Certificate Transparency (CT). To ensure reproducibility and enable platform-specific trust anchor control which is particularly challenging on Android 14 and later, we developed a unified framework called FAITH using physical devices for iOS and Android emulators. Using FAITH and 115 crafted certificate chains—including 87 non-compliant chains and 28 designed to test advanced certificate extensions—we tested 20 popular Android and iOS apps, as well as desktop and mobile browsers. Android WebView apps accepted 77.0% of non-compliant chains and all non-compliant intermediate CA certificate tests, significantly higher than mainstream browsers and iOS apps. We identified the root cause in Android WebView's reliance on the system-level certificate validation handler, which performs minimal checks and lacks support for extensions such as OCSP Must-Staple and Precertificate. Additionally, we found that cached intermediate CA certificates are reused during validation in Android WebView, which exposes the process to unintended bypass of certificate checks. To demonstrate its real-world impact, we constructed a detailed CA caching attack scenario, and disclosed it to responsible vendors including Google. The reported bug was subsequently acknowledged as a valid security vulnerability. Finally, we conclude by providing recommendations to improve WebView's certificate validation behavior. Woonghee Lee 0004, Junbeom Hur, Hyunsoo Kwon |
CCS | 2 |
| 2025 | T-Time: A Fine-Grained Timing-Based Controlled-Channel Attack Against Intel TDX
Woomin Lee, Seunghee Shin, Junbeom Hur, Young-joo Shin |
ESORICS (3) | 4 |
| 2025 | UTRA: Universal Token Reusability Attack and Token Unforgeable Delegatable Order-Revealing Encryption
Jaehwan Park, Hyeonbum Lee, Junbeom Hur, Jae Hong Seo, Doowon Kim |
ESORICS (2) | 3 |
| 2025 | Follow Your Hidden Traces: Underground Forum-Based Darknet Market Sybil DetectionabstractA darknet market is an online marketplace where illicit goods or criminal services are provided. Because of the explosive development in the popularity of such marketplaces, there is a recognized requirement for automated analysis of cybercriminal activities in the darknet markets. However, the vendor's multiple accounts (Sybil accounts) make it difficult to identify the actual relationship between vendors. Recent studies proposed darknet market-based Sybil detection methods using images and item descriptions. However, relying solely on market information presents limitations, as it should depend on profiles and product data uploaded by vendors for inferring similarity and identifying Sybil accounts. This study introduces a novel forum-based model to complement market-based approaches, enhancing Sybil account detection by uncovering multiple accounts not easily detectable through market data alone. The proposed model filters Sybil-relevant posts, extracts vital information about Sybil vendors from forum posts, and validates vendors' presence in the marketplace. Evaluations on real-world datasets from major darknet markets show that 98 % accuracy in Sybil-related post classification and 93% accuracy in extracting information about vendors' multiple accounts are achieved. Our method successfully identifies a significant number of additional multiaccount pairs in comparison to the state-of-the-art market-based models, uncovering 541 Sybil pairs, a substantial 92 % of which are newly discovered multi-accounts not previously detected by existing models. To the best of our knowledge, this is the first study that utilizes forum data and demonstrates its efficacy for Sybil detection in the real world. Yerim Kim, Junbeom Hur |
ICWS | 3 |
| 2025 | Scaling SCIERA: A Journey Through the Deployment of a Next-generation NetworkabstractThe SCION Next-Generation Network (NGN) architecture has expanded steadily since 2017, with today 20+ ISPs offering SCION connectivity. In production, IP-to-SCION-to-IP translation by SCION-IP-Gateways (SIGs) is used, such that applications are unaware of the NGN communication. To accelerate innovation and deployments, our aim is to increase the number of native SCION use cases, where the application is fully SCION-aware and optimizes communication across all path choices offered by the network. We set out to achieve two core objectives: (1) facilitating simple native connectivity for applications, and (2) enhancing the scalability of SCION deployment at academic sites. François Wirz, Marten Gartner, Jelte van Bommel, Elham Ehsani Moghadam, Grace H. Cimaszewski, Anxiao He, Yizhe Zhang 0006, Henry Birge-Lee, Felix Kottmann, Cyrill Krähenbühl, Jonghoon Kwon, Kyveli Mavromati, Liang Wang 0054, Daniel Bertolo, Marco Canini, Buseung Cho, Ronaldo A. Ferreira, Simon Peter Green, David Hausheer, Junbeom Hur, Xiaohua Jia, Heejo Lee, Prateek Mittal, Omo Oaiya, Chanjin Park, Adrian Perrig, Jerry Sobieski, Yixin Sun 0004, Cong Wang 0001, Klaas Wierenga |
SIGCOMM | 20 |
| 2025 | A Lightweight and Generic Access Rights Update Mechanism for Attribute-Based Encryption in cloud storage
Youwen Zhu, Jian Wang 0038, Junbeom Hur |
J. Syst. Archit. | 5 |
| 2025 | Design and Optimization of Hybrid End-to-end Encryption Architecture for a Secure Web Application SystemabstractWith the rapid development of web engineering technology, modern web applications face unprecedented security challenges in data transmission and cloud processing. The traditional transport layer encryption mechanism still has server-side data processing and storage vulnerabilities. This paper proposes an end-to-end encryption (E2EE) system architecture designed for a web application environment, combining asymmetric elliptic curve encryption (ECC) with AES-GCM symmetric encryption through a new hybrid protocol. Our scheme employs a three-layer protection model, covering network-layer packet encryption, application-layer payload security, and session-level key management. The architecture introduces an optimised key distribution mechanism based on ECDH key exchange and HKDF derivation, which reduces computational overhead and achieves 128-bit security equivalent to that of 3072-bit RSA. Experiments conducted under a typical web server configuration demonstrate that, compared to the traditional RSA solution, the handshake completion speed is 12.3% higher, and the continuous throughput of AES-GCM on the Node.js platform reaches 8.2 MB/s. The system achieves forward confidentiality through the use of temporary key pairs and employs certificate locking and OCSP binding to enhance authentication integrity. Performance benchmarks show that cryptographic latency is reduced by 40% compared to a single encryption method, while meeting W3C web security standards. This study presents a secure development model for distributed web architecture, striking a balance between computing efficiency and data confidentiality. Xiyuan Ma, Junbeom Hur, Mulin Gu, Ning Du |
J. Web Eng. | 2 |
| 2025 | DeepRadar: A cyber-defence interceptor for early warning and defusing malware injection attacksabstractMalware injection attacks are among the most sophisticated and elusive threats in cybersecurity, characterised by their capacity for privilege escalation, obfuscation, and the ability to deceive antivirus software. This paper introduces a multi-layer architecture, featuring innovative deep neural networks, fast Fourier convolution , and association rule mining strategies, designed for the early detection and defusal of malware injection attacks. We then propose a proactive AI-enabled malware detection platform, DeepRadar , as a novel real-world defence mechanism. This early warning functionality capable of anticipating the attack a few cycles before occurrence represents a novel idea and unique approach to detecting malware injection attacks. The experimental results validate DeepRadar’s superior performance compared to not only previous related studies but also a standard benchmark of well-reputed antivirus applications under various scenarios and accredited datasets, including heavily obfuscated emerging malware variants and adversarial samples. It demonstrates higher Accuracy, F-score, ROC, and AUC metrics in early detection and classification of malware injection attacks while DeepRadar consumes significantly fewer system resources, including processor and memory during long-term scalable operation. The proposed early warning system succeeded in repelling up to 97.2% of attacks before malware could complete their malicious sequence. Lastly, the evaluation results were substantiated by formal statistical analysis using Friedman and Wilcoxon tests. The findings of this research and DeepRadar’s runtime scanner provide vital early warnings against stealthy malware and injection attacks, offering robust protection for sensitive systems and critical infrastructure. Danial Javaheri, Hassan Chizari, Mahdi Fahmideh, Mohammad-Hossein Nadimi-Shahraki, Junbeom Hur |
Knowl. Based Syst. | 5 |
| 2024 | Beneath the Phishing Scripts: A Script-Level Analysis of Phishing Kits and Their Impact on Real-World Phishing WebsitesabstractPhishing kits have become increasingly popular among cybercriminals because they offer an easy-to-use and efficient way for phishing attackers to build phishing websites. Prior work on phishing kits has focused on analyzing specific behavioral features (e.g., evasion techniques), and measuring their effectiveness on the anti-phishing mechanisms. Unfortunately, such prior studies provide a limited perspective, either targeting specific phishing kits or not fully addressing the server-side strategies at the script level that offer insights into the phishing attacker's view. Woonghee Lee 0004, Junbeom Hur, Doowon Kim |
AsiaCCS | 2 |
| 2024 | PhishinWebView: Analysis of Anti-Phishing Entities in Mobile Apps with WebView Targeted PhishingabstractDespite the relentless efforts on developing anti-phishing techniques, phishing attacks continue to proliferate, often incorporating evasion techniques to bypass detection. While recent studies have continuously enhanced our understanding of their evasion techniques in desktop environments, few studies have been conducted to explore how the phishing attack is being handled in mobile environments, specifically WebView. Yoonjung Choi, Woonghee Lee 0004, Junbeom Hur |
WWW | 3 |
| 2024 | Cybersecurity threats in FinTech: A systematic review
Danial Javaheri, Mahdi Fahmideh, Hassan Chizari, Pooia Lalbakhsh, Junbeom Hur |
Expert Syst. Appl. | 5 |
| 2024 | $\gamma$γ-Knife: Extracting Neural Network Architecture Through Software-Based Power Side-ChannelabstractSeveral side-channel attacks exploiting timing, cache, or power side channels have recently been proposed to obtain private information of a neural network. However, the hardware-based attacks require physical access to the system, using high-precision equipment to measure physical system behaviors such as power consumption or electromagnetic emanations, to exploit them as side channels. Whereas, the previous software-based side-channel attacks on neural networks can extract their model information only when the target architecture is known. In this paper, we propose the$\gamma$-Knife attack, a software-based power side-channel attack on a neural network, which can extract its architecture without any physical access or high-precision measuring equipment. Our work demonstrates that side-channels can be formed that leak architecture of neural networks by utilizing statistical metrics without high-resolution power data. The$\gamma$-Knife attack can reduce the search space of candidate architectures by obtaining private information such as filter size, depth of convolutional layer, and activation functions in the target architecture, as accurately as hardware-based power side-channel attacks even when the target neural network is totally unknown. We demonstrated the efficacy of the$\gamma$-Knife attack by implementing the attack on the well-known neural networks VGGNet, ResNet, GoogleNet, and MobileNet, using the Pytorch library on Intel CPUs and AMD CPUs. The$\gamma$-Knife attack could identify the target neural network architecture with an accuracy of approximately 90%, and efficiently extract its private information, by significantly reducing the search space of the target architecture. Dohyun Ryu, Yerim Kim, Junbeom Hur |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2024 | Deep Learning-Based Detection for Multiple Cache Side-Channel AttacksabstractA cache side-channel attack retrieves victim’s sensitive information from a system by exploiting shared cache of CPUs. Since conventional cache side-channel attacks such as FLUSH+RELOAD and PRIME+PROBE are likely to incur numerous cache events, such as cache hits and misses, many previous strategies have focused on monitoring cache events for attack detection. However, as recently proposed attacks such as PRIME+ABORT have exploited the other events as side-channels, it has become challenging to detect them by monitoring only cache events. In this paper, we investigate PRIME+ABORT attack and identifies Intel TSX hardware events are tightly coupled with it as well as cache events. Based on our finding, we propose a novel deep learning-based cache side-channel attack detection method called FRIME. It can concurrently detect not only the conventional attacks such as FLUSH+RELOAD, PRIME+PROBE, but also PRIME+ABORT by leveraging both event types. In order to demonstrate the efficacy of our cache side-channel attack detection scheme in diverse workload conditions in the real world, we implement it using MLP, RNN, and LSTM deep learning models, demonstrating LSTM-based method outperforms the other implementations in terms of detection accuracy. Hodong Kim, Changhee Hahn, Hyunwoo J. Kim, Young-joo Shin, Junbeom Hur |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2023 | A Honey postMessage, but a Heart of Gall: Exploiting Push Service in Service Workers Via postMessageabstractProgressive web app (PWA) is a kind of web apps, which is designed to enhance users’ browsing experience by combining the advantages of a web app’s reachability and a native app’s diverse functionalities. PWA sites have a special JavaScript file, service worker, which is executed in a different thread from the browser’s main page. It thus can support unique functionalities such as offline usage and push service even after the browser is closed. Because of these features, the service worker has been a main target of many web attacks such as a DDOS attack, or abused to generate illegal sites such as darknet sites. However, previous attacks exploiting the push service have limitations in that they need the pre-installation of a malicious service worker or only can passively utilize the existing push notification from the legitimate site (e.g., hijacking the push notification to track users’ location). Yeomin Jeong, Woonghee Lee 0004, Junbeom Hur |
AsiaCCS | 3 |
| 2023 | DevIOus: Device-Driven Side-Channel Attacks on the IOMMUabstractModern computer systems take advantage of Input/Output Memory Management Unit (IOMMU) to protect memory from DMA attacks, or to achieve strong isolation in virtualization. Despite its promising benefits, the IOMMU could be a new source of security threats. Like the MMU, the IOMMU also has Translation Lookaside Buffer (TLB) named IOTLB, an address translation cache that keeps the recent translations. Accordingly, the IOTLB can be a target of a timing side-channel attack, revealing victim’s secret. In this paper, we present DevIOus, a novel device-driven side-channel attack exploiting the IOTLB. DevIOus employs DMA-capable PCIe devices, such as GPU and RDMA-enabled NIC (RNIC), to deliver the attack. Thus, our attack has no influence on CPU caches or TLB in a victim’s machine. Implementing DevIOus is not trivial as microarchitectural internals of the IOTLB of Intel processors are hidden. We overcome this by reverse-engineering the IOTLB and disclose its hidden architectural properties. Based on this, we construct two IOTLB-based timing attack primitives using a GPU and an RNIC. Then, we demonstrate practical attacks that target co-located VMs under hardware-assisted isolation, and remote machines connected over the RDMA network. We also discuss possible mitigations against the proposed side-channel attack. Hyeongjin Park, Seokmin Lee, Seunghee Shin, Junbeom Hur, Young-joo Shin |
SP | 5 |
| 2023 | Did the Shark Eat the Watchdog in the NTP Pool? Deceiving the NTP Pool's Monitoring System
Jonghoon Kwon, Jeonggyu Song, Junbeom Hur, Adrian Perrig |
USENIX Security Symposium | 3 |
| 2023 | Detect Your Fingerprint in Your Photographs: Photography-based Multi-Feature Sybil DetectionabstractA darknet market is an online marketplace typically implemented over Tor, where vendors sell illegal products or criminal services. Due to dramatic growth in the popularity of such markets, there is a recognized need for automatic investigation of the market’s ecosystem and identification of anonymous vendors. However, as they often create multiple accounts (or Sybil accounts) within or across different marketplaces, detecting Sybil accounts becomes the key to understanding the ecosystem of darknet markets and identifying the actual relationship between the vendors. This study presents a novel Sybil detection method that extracts multiple features of vendors from photographs in a fine-grained level (e.g., image similarity, main category, subcategory, and text data), and reveals the multiple Sybil accounts of them simultaneously. Each feature is extracted from multiple rich sources using an image hash algorithm, Deep Neural Network (DNN) classifier, image restoration, and text recognition tool; and merged using a weighted feature embedding model. The matching score of each vendor is then calculated to identify not only the exact Sybil accounts, but multiple potential accounts suspected of being associated to a single operator. We evaluate the efficacy of our method using real-world datasets from four large darknet markets (i.e., SilkRoad2, Agora, Evolution, Alphabay) from 2014 to 2015. Because of the anonymity of darknet market, we construct the ground-truth of Sybil accounts by randomly splitting the dataset of vendors into two even parts. We used the first set to train the model, and linked the second set to the original vendor in the first set to evaluate performance. Our experimental results demonstrated that the proposed method outperforms the existing photography-based system with an accuracy of 98%, identifying up to 700% more candidate Sybil accounts than prior work. Additionally, our method detects multiple Sybil accounts for 90% of evaluated test cases, presenting a very different picture of darknet marketplace dynamics than methods that can only detect a single Sybil account for each target vendor. Due to its fine-grained multiple feature extraction from photographs, our method can be more generically applied to various darknet markets for Sybil detection regardless of their languages or categories of items. Yerim Kim, Myungjae Chung, Junbeom Hur |
Proc. Priv. Enhancing Technol. | 4 |
| 2023 | VerSA: Verifiable Secure Aggregation for Cross-Device Federated LearningabstractIn privacy-preserving cross-device federated learning, users train a global model on their local data and submit encrypted local models, while an untrusted central server aggregates the encrypted models to obtain an updated global model. Prior work has demonstrated how to verify the correctness of aggregation in such a setting. However, such verification relies on strong assumptions, such as a trusted setup among all users under unreliable network conditions, or it suffers from expensive cryptographic operations, such as bilinear pairing. In this paper, we scrutinize the verification mechanism of prior work and propose a model recovery attack, demonstrating that most local models can be leaked within a reasonable time (e.g.,$98\%$of encrypted local models are recovered within 21 h). Then, we proposeVerSA, a verifiable secure aggregation protocol for cross-device federated learning.VerSAdoes not require any trusted setup for verification between users while minimizing the verification cost by enabling both the central server and users to utilize only a lightweight pseudorandom generator to prove and verify the correctness of model aggregation. We experimentally confirm the efficiency ofVerSAunder diverse datasets, demonstrating thatVerSAis orders of magnitude faster than verification in prior work. Changhee Hahn, Hodong Kim, Minjae Kim 0008, Junbeom Hur |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2023 | Certificate Transparency With Enhanced PrivacyabstractDigital certificates play an important role in the authentication of communicating parties for transport layer security. Recently, however, frequent incidents such as the illegal issuance of fake certificates by a compromised certificate authority have raised concerns about the legacy certificate system. Certificate Transparency (CT) mitigates such issues by employing a log server to audit issued certificates publicly, making the certificate issuance and verification processes transparent. Unfortunately, the legacy CT ecosystem suffers from log server compromises and user browsing information leakage. Furthermore, the data structure for the certificate management in the legacy CT system incurs computation overhead linear to the number of registered certificates in the log. In this paper, we propose a secure CT scheme by leveraging a shared value tree (SVT), a novel log structure specifically designed to address the log server compromise and browsing information leakage problems. The verification time of SVT remains constant regardless of the number of registered certificates in the log. We analyze our scheme on the legacy CT system to demonstrate its incremental deployability, guaranteeing a smooth transition toward a more secure web ecosystem. Hyunsoo Kwon, Sangtae Lee, Minjae Kim 0008, Changhee Hahn, Junbeom Hur |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2023 | Multi-Key Similar Data Search on Encrypted Storage With Secure Pay-Per-QueryabstractMany commercial cloud service providers (CSPs) adopt pay-per-query pricing models, in which data owners are charged based on the amount of data scanned by each query. In such a data sharing model, not only the privacy preservation for the data and queries but also the trustworthiness of the underlying billing system is of the utmost importance. In this paper, we revisit multi-key searchable encryption (MKSE), an efficient and secure data search algorithm allowing a data owner to grant users the ability to retrieve data of interest over the outsourced, encrypted datasets. We first investigate which factor in existing MKSE schemes renders authorized users over-privileged such that, without risking their credits (e.g., leaking the private keys and/or the passwords for their accounts associated with a project where the shared data resides), they can allow unauthorized users to make valid queries. Unfortunately, this concern may be devastating because the queries made by unauthorized users would incur unexpected financial damage to the owner in practical pay-per-query models. We then propose a novel multi-key data search scheme that is resilient to unauthorized queries. The proposed scheme features a novel user authorization mechanism that carefully limits user privilege such that even an authorized user cannot illegally invite unauthorized users to query unless he entirely leaks his credit. We demonstrate the proposed scheme is comparable to prior work in terms of performance while achieving a higher level of security. Changhee Hahn, Hyundo Yoon, Junbeom Hur |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2023 | Delegatable Order-Revealing Encryption for Reliable Cross-Database QueryabstractCloud service providers adopt pay-per-query pricing models to charge data owners based on the amount of data scanned by each query. In such models, the trustworthiness of the underlying billing system is as important as the privacy preservation for the data and queries. In this paper, we revisit delegatable order-revealing encryption (DORE), a range query algorithm allowing authorized users to retrieve data of specific ranges across multiple databases encrypted under different secret keys. We first investigate which factor in the authorization mechanism of DORE can lead to overprivileged users and let them allow any unauthorized user to query over the database of the victim without risking their credits, such as leaking the secret keys. Unfortunately, such unauthorized queries would incur unexpected financial damage to the victim in practical pay-per-query models. We then propose SEDORE, a secure order-revealing encryption scheme with resilience to unauthorized queries across databases. SEDORE features a novel user authorization mechanism limiting user privileges carefully. Consequently, the authorized users cannot illegally invite any unauthorized user to query unless they entirely leak their credits. We demonstrate that the performance of SEDORE is comparable to that of DORE while achieving a higher security level. Changhee Hahn, Junbeom Hur |
IEEE Trans. Serv. Comput. | 2 |
| 2022 | BLAP: Bluetooth Link Key Extraction and Page Blocking AttacksabstractSecure Simple Pairing (SSP) and Link Manager Protocol (LMP) authentication are two main authentication mechanisms in Bluetooth specification. In this paper, we present two novel attacks, called link key extraction and page blocking attacks, breaking LMP authentication and SSP authentication, respectively. Link key extraction attack allows attackers to extract link keys of Bluetooth devices generated during the SSP procedure by exploiting Bluetooth HCI dump. Page blocking attacks by man-in-the-middle (MITM) attackers enforce Blue-tooth connections, enabling subsequent SSP downgrade attacks to bypass the SSP authentication challenge. In order to demonstrate the efficacy, we implement our attacks on various real-world devices and show that (1) a target link key is dumped into a log and extracted efficiently, possibly leading to the subsequent impersonation attack, and (2) malicious MITM connections can be established with 100% success rate, enabling subsequent SSP downgrade attack. We investigate the root causes for the vulnerabilities and present mitigations. Changseok Koh, Jonghoon Kwon, Junbeom Hur |
DSN | 3 |
| 2022 | Adversarial Attack on Semantic Segmentation Preprocessed with Super ResolutionabstractComputer vision tasks, such as image classification, semantic segmentation, and super resolution, are broadly utilized in many applications. Recent studies revealed that machine learning-based models for the computer vision tasks are vulnerable to adversarial attacks. Since the adversarial attack can disturb the computer vision models in real-world systems, many countermeasures have been proposed against the adversarial attacks, such as denoising, resizing, and machine learning-based super resolution model as a preprocessing. Recently, a prior work demonstrated that the super resolution model as a preprocessing can be vulnerable to the adversarial attack targeted to the preprocessing itself, only when the perturbation is inactive before the preprocessing. However, we also found that the perturbation before the preprocessing can be another serious threat if the super resolution model is used for a mitigation of adversarial attacks. In this paper, we propose Layered Adversary Generation (LAG) that generates the adversarial example by recursively injecting noises to clean image in white-box environment. We then show that LAG is effective to attack a semantic segmentation model even if the super resolution models with/without two countermeasures as auxiliary methods such as resizing and denoising are adopted to mitigate the adversarial attacks. Furthermore, we demonstrate that LAG is transferable across other super resolution models. Lastly, we discuss our attack method in gray-box and black-box environments, and suggests a mitigation for robust preprocessing. Gyeongsup Lim, Junbeom Hur |
ICPR | 3 |
| 2022 | Analysis of NTP pool monitoring system based on multiple monitoring stationsabstractThe Network Time Protocol (NTP) is a server-client-based time synchronization protocol that transmits time information over a network, and is used in various applications on the Internet. Especially, the NTP Pool Project is designed to connect NTP servers that provide accurate time to millions of clients, and balance the load on the NTP servers using the NTP pool. The NTP pool operates the NTP pool monitor system to evaluate the time accuracy and availability of the NTP servers registered with the NTP pool. There are currently two operating environments for monitoring systems in practice: one is a single monitoring system, which is officially operating, and the other is a multiple-monitoring system, which is now under beta testing. In this study, we investigate the NTP pool monitoring system based on multiple monitoring stations, which is expected to be deployed soon in the real world. We then discuss possible threats and their security implications when the current single monitoring system extends to the multiple-monitoring system. Jeonggyu Song, Jonghoon Kwon, Junbeom Hur |
MobiHoc | 3 |
| 2022 | Exploiting Metaobjects to Reinforce Data Leakage AttacksabstractReflective features in modern programming languages allow programs to introspect and modify their own structures and behavior during runtime. As these self-referential capabilities are frequently adopted in practice, security of the reflective systems becomes crucial. In this paper, we explore an adversary against reflective systems with access to a data leakage channel, which has previously been considered impractical to pose a realistic threat. In particular, we show that a crucial component of reflection, referred to as metaobjects, can be exploited to reinforce these data leakage channels. We introduce a novel attack strategy that exploits certain metaobjects as in-memory gadgets to leak data in a selective and target-oriented manner, consequentially eliminating the unnecessary sampling procedures inevitable in naive data leakage attacks. Such approach significantly optimizes the data space subject to extraction, elevating the practicality of the underlying data leakage channel. As an instantiation of our strategy, we propose and demonstrate SMDL, a framework that exploits reflection to reinforce Meltdown-type attacks to steal valuable data from the victim’s memory. To demonstrate the efficacy of our attack, we implement SMDL against two different target applications, cryptographic library and deep learning service, and show that the secret key and neural network can be extracted with high accuracy and efficiency. Finally, we suggest metaobject obfuscation techniques to mitigate such exploitation. Hoyong Jeong, Hodong Kim, Junbeom Hur |
RAID | 3 |
| 2022 | Efficient IoT Management With Resilience to Unauthorized Access to Cloud StorageabstractCloud-based Internet of Things (IoT) management services are a promising means of ingesting data from globally dispersed devices. In this setting, it is important to regulate access to data managed by potentially untrusted cloud servers. Attribute-based encryption (ABE) is a highly effective tool for access control. However, applying ABE to IoT environments shows limitations in the following three aspects: First, the demands for storage resources increase in proportion to the complexity of the access control policies. Second, the computation cost of ABE is onerous for resource-limited devices. Lastly, ABE alone is intractable to prevent illegal key-sharing which leads to unauthorized access to data. In this article, we propose an efficient and secure cloud-based IoT data management scheme using ABE. First, we remove the storage-side dependency on the complexity of the access control policies. Second, a substantial part of computationally intensive operations is securely outsourced to the cloud servers. Lastly, unauthorized access to data via illegal key-sharing is strictly forbidden. Our security analysis and experimental results show the security and practicability of the proposed scheme. Changhee Hahn, Jongkil Kim, Hyunsoo Kwon, Junbeom Hur |
IEEE Trans. Cloud Comput. | 4 |
| 2022 | Secure and Efficient Hybrid Data Deduplication in Edge ComputingabstractAs an extension of cloud computing, edge computing introduces additional intermediate devices, called edge nodes near clients, providing computing services on behalf of the central cloud more efficiently. Although edge computing brings several benefits such as low latency and bandwidth savings on the edge side, rapid increase in the amount of data transmitted to the central cloud hinders efficient utilization of the storage system on the central cloud side especially when the data from edge devices are encrypted. To mitigate this issue in a privacy-preserving manner, data deduplication techniques for encrypted data have been extensively studied to enhance both the security and efficiency in the conventional cloud system with two different approaches. A server-side secure deduplication approach protects data privacy but impairs network efficiency by allowing duplicate uploads, while a client-side one improves network efficiency but suffers from potential information leakage due to its vulnerability to the side-channel attack. In this article, we propose a hybrid secure deduplication scheme for edge computing, which guarantees both advantages of the aforementioned two approaches. Specifically, our scheme guarantees data privacy by applying the server-side deduplication technique between the client and the edge nodes and maximizes network efficiency through the client-side deduplication technique between the edge nodes and the cloud. In addition, we devise a novel additively homomorphic encryption for efficient deduplication operations in the resource-limited edge nodes. Based on our experimental results, the proposed scheme reduces the communication costs by approximately 2.5 times for a storage server when the duplicate ratio is 50%, and the response time is reduced by about 2 times when the data size is 16 MB. Hyungjune Shin, Dongyoung Koo, Junbeom Hur |
ACM Trans. Internet Techn. | 3 |
| 2022 | Enabling Fast Public Auditing and Data Dynamics in Cloud ServicesabstractPublic auditing enables efficient integrity checks of data assigned to cloud servers. In this article, we revisit the public auditing for encrypted data, in which a major concern is how to effectively support data dynamics, i.e., data modification, insertion, and deletion. We first determine which factor in existing auditing schemes most limits data dynamics from a cost perspective. We then propose a novel public auditing scheme that provides data dynamics that are orders of magnitude faster than previous methods. Our auditing challenge-response protocol reduces the computation cost of the third-party auditor (TPA) significantly, thus increasing the verification speed for the auditing results. Performance and security analysis demonstrates that the proposed scheme generates minimal computation costs while guaranteeing data integrity and privacy against an untrusted cloud. Changhee Hahn, Hyunsoo Kwon, Daeyeong Kim, Junbeom Hur |
IEEE Trans. Serv. Comput. | 4 |
| 2021 | Efficient Fully Anonymous Public-Key Trace and Revoke with Adaptive IND-CCA Security
Mriganka Mandal, Ramprasad Sarkar, Junbeom Hur, Koji Nuida |
ISPEC | 3 |
| 2021 | Enabling Fast Public Auditing and Data Dynamics in Cloud ServicesabstractHosting data in the cloud minimizes maintenance requirements, allowing users to easily access their data on cloud servers. However, cloud servers have full control over outsourced data, which raises security concerns about data integrity. The cloud, for example, might have the financial incentive to discard rarely accessed data, freeing up valuable storage space to, say, host other data-centric applications. Therefore, users need to confirm periodically that their data is intact but this has become increasingly onerous due to the ever-growing volume of data being outsourced. Changhee Hahn, Hyunsoo Kwon, Junbeom Hur |
SERVICES | 4 |
| 2020 | Forward Secure Public Key Encryption with Keyword Search for Cloud-assisted IoTabstractThe Internet of Things (IoT) features a mechanism that extends connectivity to diverse computing devices, such as smart phones, commodity sensors, and appliances. Due to the huge quantity of data generated by the IoT devices, they are likely to be stored and managed by the cloud these days. However, because of the privacy concern about the sensitive data, encryption techniques are typically adopted by the cloud. In order to enable searching over encrypted data for multiple data senders in the cloud, public key encryption with keyword search (PEKS) has been proposed as one variant of searchable encryption (SE). Unfortunately, existing PEKS schemes are vulnerable to adaptive file-injection attack due to the lack of forward privacy. In this paper, we propose a forward secure PEKS scheme based on hierarchical identity-based encryption for cloud-assisted IoT environments. While the existing schemes incur to the data receiver a storage overhead that increases linearly with the number of data senders, our scheme incurs only a constant cost. The experimental analysis with Amazon EC2 and Raspberri Pi shows that our scheme is two to five times more efficient than the previous schemes, which makes our scheme more suitable for multiple data senders in the cloud-assisted IoT environments. Hyeongseob Kim, Changhee Hahn, Junbeom Hur |
CLOUD | 3 |
| 2020 | Return of version downgrade attack in the era of TLS 1.3abstractTransport Layer Security (TLS) protocol is often vulnerable to version downgrade attacks, where a man-in-the-middle attacker interferes with the handshake protocol and leads the communicating parties to fall back from a higher version of TLS to lower ones, which are typically provided for backward compatibility. Sangtae Lee, Young-joo Shin, Junbeom Hur |
CoNEXT | 3 |
| 2020 | Inferring Firewall Rules by Cache Side-channel Analysis in Network Function VirtualizationabstractNetwork function virtualization takes advantage of virtualization technology to achieve flexibility in network service provisioning. However, it comes at the cost of security risks caused by cache side-channel attacks on virtual machines. In this study, we investigate the security impact of these attacks on virtualized network functions. In particular, we propose a novel cache-based reconnaissance technique against virtualized Linux-based firewalls. The proposed technique has significant advantages in the perspective of attackers. First, it enhances evasiveness against intrusion detection owing to the ability of source spoofing. Second, it allows inference on a wide variety of filtering rules. During experiment in VyOS, the proposed method could infer the firewall rules with an accuracy of more than 90% by using only a few dozen packets. We also present countermeasures to mitigate cache-based attacks on virtualized network functions. Young-joo Shin, Dongyoung Koo, Junbeom Hur |
INFOCOM | 3 |
| 2020 | Toward Serverless and Efficient Encrypted Deduplication in Mobile Cloud Computing EnvironmentsabstractWith the proliferation of new mobile devices, mobile cloud computing technology has emerged to provide rich computing and storage functions for mobile users. The explosive growth of mobile data has led to an increased demand for solutions that conserve storage resources. Data deduplication is a promising technique that eliminates data redundancy for storage. For mobile cloud storage services, enabling the deduplication of encrypted data is of vital importance to reduce costs and preserve data confidentiality. However, recently proposed solutions for encrypted deduplication lack the desired level of security and efficiency. In this paper, we propose a novel scheme for serverless efficient encrypted deduplication (SEED) in mobile cloud computing environments. Without the aid of additional servers, SEED ensures confidentiality, data integrity, and collusion resistance for outsourced data. The absence of dedicated servers increases the effectiveness of SEED for mobile cloud storage services, in which user mobility is essential. In addition, noninteractive file encryption with the support of lazy encryption greatly reduces latency in the file-upload process. The proposed indexing structure (D-tree) supports the deduplication algorithm and thus makes SEED much more efficient and scalable. Security and performance analyses prove the efficiency and effectiveness of SEED for mobile cloud storage services. Young-joo Shin, Junbeom Hur, Dongyoung Koo, Joobeom Yun |
Secur. Commun. Networks | 2 |
| 2020 | (In-)Security of Cookies in HTTPS: Cookie Theft by Removing Cookie FlagsabstractHyperText Transfer Protocol (HTTP) cookies are widely used on the web to enhance communication efficiency between a client and a server by storing stateful information. However, cookies may contain private and sensitive information about users. Thus, in order to guarantee the security of cookies, most web browsers and servers support not only Transport Layer Security (TLS) but also other mechanisms such as HTTP Strict Transport Security and cookie flags. However, a recent study has shown that it is possible to circumvent cookie flags in HTTPS by exploiting a vulnerability in HTTP software that allows message truncation. In this paper, we propose a novel cookie hijacking attack called rotten cookie which deactivates cookie flags even if they are protected by TLS by exploiting a weakness in HTTP in terms of integrity checks. According to our investigation, all major browsers ignore uninterpretable sections of the header of HTTP response messages and accept incorrect formats without any rejection. We demonstrate that, when combined with TLS or application vulnerabilities, this form of attack can obtain private cookies by removing cookie flags. Thus, the attacker can impersonate a legitimate user in the eyes of the server when cookies are used as an authentication token. We prove the practicality of our attack by demonstrating that our attack can lead five major web browsers to accept a cookie without any cookie flags. We thus present a mitigation strategy for the transport layer to preserve cookie security against our attack. Hyunsoo Kwon, Hyunjae Nam, Sangtae Lee, Changhee Hahn, Junbeom Hur |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2020 | Decentralized Server-Aided Encryption for Secure Deduplication in Cloud StorageabstractCloud storage provides scalable and low cost resources featuring economies of scale based on multi-tenant architecture. As the amount of data outsourced grows explosively, data deduplication, a technique that eliminates data redundancy, becomes essential. However, deduplication leads to problems with data confidentiality, thereby necessitating secure deduplication solutions. Server-aided encryption schemes have been proposed to achieve the strongest confidentiality but with the cost of managing a key server (KS). Previous schemes, however, are based on a centralized KS that uses only a single secret key assuming a single KS in the system. In cloud storage where multi-tenancy and scalability are crucial, such schemes degrade not only the effectiveness of deduplication but also the scalability with increasing users. In this paper, we extend server-aided encryption to a decentralized setting that consists of multiple KSs. The key idea of our proposed scheme is to construct an inter-KS deduplication algorithm, by which a cloud storage service provider can perform deduplication over ciphertexts from different KSs within a tenant or across tenants. This way, our scheme simultaneously offers flexibility of KS management and cross-tenant deduplication over encrypted data. The novelty of the approach is using a decentralized architecture that does not require any centralized entities for the coordination or pre-sharing of secrets among KSs. Therefore, it allows cloud storage services to offer high deduplication efficiency and scalability while preserving strong data confidentiality. We show the result of performance analysis on the proposed scheme by conducting extensive experiments. In addition, our security analysis demonstrate that the proposed scheme satisfies all desired security properties. Young-joo Shin, Dongyoung Koo, Joobeom Yun, Junbeom Hur |
IEEE Trans. Serv. Comput. | 4 |
| 2019 | Password typographical error resilience in honey encryption
Hoyul Choi, Jongmin Jeong, Simon S. Woo, Kyungtae Kang, Junbeom Hur |
Comput. Secur. | 5 |
| 2019 | A reliable adaptive forwarding approach in named data networking
Zeinab Rezaeifar, Jian Wang 0003, Heekuck Oh, Suk-Bok Lee, Junbeom Hur |
Future Gener. Comput. Syst. | 5 |
| 2019 | Trustworthy Delegation Toward Securing Mobile Healthcare Cyber-Physical SystemsabstractAttribute-based encryption (ABE) offers a promising solution for flexible access control over sensitive personal health records in a mobile healthcare system on top of a public cloud infrastructure. However, ABE cannot be simply applied to lightweight devices due to its substantial computation cost during decryption. This problem could be alleviated by delegating significant parts of the decryption operations to computationally powerful parties, such as cloud servers, but the correctness of the delegated computation would be at stake. Thus, previous works enabled users to validate the partial decryption by employing a cryptographic commitment or message authentication code (MAC). This paper demonstrates that the previous commitment or MAC-based schemes cannot support verifiability in the presence of potentially malevolent cloud servers. We propose two concrete attacks on previous commitment or MAC-based schemes. We propose an effective countermeasure scheme for securing resource-limited mobile healthcare systems and provide a rigorous security proof in the standard model, demonstrating that the proposed scheme is secure against our attacks. The experimental analysis shows that the proposed scheme provides the similar performance compared with the previous commitment-based schemes and outperforms the MAC-based scheme. Changhee Hahn, Hyunsoo Kwon, Junbeom Hur |
IEEE Internet Things J. | 3 |
| 2019 | Secure deduplication with reliable and revocable key management in fog computing
Hyunsoo Kwon, Changhee Hahn, Kyungtae Kang, Junbeom Hur |
Peer-to-Peer Netw. Appl. | 4 |
| 2018 | Toward Trustworthy Delegation: Verifiable Outsourced Decryption with Tamper-Resistance in Public Cloud StorageabstractFor building a secure cloud storage service on top of a public cloud infrastructure, attribute-based encryption (ABE) has been a preferred solution due to its flexible access control. ABE, however, incurs heavy computation cost on users during decryption. Thus, previous studies solved this problem by enabling cloud servers to perform a part of decryption operations on behalf of the users. In order to empower users to verify the correctness of the delegated decryption by the cloud, they employed a cryptographic commitment or message authentication code (MAC) to enable users to check the correctness of partial decryption of the cloud. However, the previous schemes fail to ensure the correctness of computation in the presence of malicious cloud servers. In this paper, we propose a novel and generic commitment scheme for ABE, which is secure against tampering attacks by malicious cloud servers. According to the performance analysis, the proposed scheme is only 0.5 ms slower on average than the previous commitment-based schemes and two to three times faster than the MAC-based scheme. Changhee Hahn, Hyunsoo Kwon, Junbeom Hur |
IEEE CLOUD | 3 |
| 2018 | Privacy-Preserving and Updatable Block-Level Data Deduplication in Cloud Storage ServicesabstractTo achieve high storage saving, data deduplication techniques are widely used in many practical cloud storage services, which removes redundant data and keeps only a single copy of them. However, secure data deduplication over encrypted data is challenging since encryption may result in different ciphertexts even when the original messages are the same. Thus, message-locked encryption (MLE) is proposed to solve this issue and demonstrates that it is secure under the unpredictable message set. Since block-level deduplication can achieve more fine-grained storage saving, several block-level deduplication schemes that support updatability are also vividly proposed. However, the previous updatable block-level MLE schemes are vulnerable against brute-force attack when the message set is predictable. Since the size of a block is typically much less than an arbitrary size of a file, the predictability problem is a very important pragmatic concern which should be addressed in the block-level deduplication literature. In this paper, thus, we propose a novel secure block-level deduplication scheme that guarantees efficient data update and brute-force attack resilience even when messages are predictable with the rigorous security proof. Also, our performance evaluation shows that additional time and bandwidth usage can be minimized as the size of a block increases. Hyungjune Shin, Dongyoung Koo, Young-joo Shin, Junbeom Hur |
IEEE CLOUD | 4 |
| 2018 | Unveiling Hardware-based Data Prefetcher, a Hidden Source of Information LeakageabstractData prefetching is a hardware-based optimization mechanism used in most of the modern microprocessors. It fetches data to the cache before it is needed. In this paper, we present a novel microarchitectural attack that exploits the prefetching mechanism. Our attack targets Instruction pointer (IP)-based stride prefetching in Intel processors. Stride prefetcher detects memory access patterns with a regular stride, which are likely to be found in lookup table-based cryptographic implementations. By monitoring the prefetching activities near the lookup table, attackers can extract sensitive information such as secret keys from victim applications. This kind of leakage from prefetching has never been considered in the design of constant time algorithm to prevent side-channel attacks. We show the potential of the proposed attack by applying it against the Elliptic Curve Diffie-Hellman (ECDH) algorithm built upon the latest version of OpenSSL library. To the best of our knowledge, this is the first microarchitectural side-channel attack exploiting the hardware prefetching of modern microprocessors. Young-joo Shin, Hyung Chan Kim, Dokeun Kwon, Ji-Hoon Jeong, Junbeom Hur |
CCS | 5 |
| 2018 | Privacy-preserving deduplication of encrypted data with dynamic ownership management in fog computing
Dongyoung Koo, Junbeom Hur |
Future Gener. Comput. Syst. | 2 |
| 2017 | Scalable and Reliable Key Management for Secure Deduplication in Cloud StorageabstractSecure deduplication using convergent encryption eliminates duplicate data and stores only one copy to save storage costs while preserving the security of the outsourced data. However, convergent encryption produces a number of encryption keys, of which size is linear to the number of different data. Although a deduplication scheme has been proposed for efficient convergent key management recently, it has drawbacks in terms of scalability and key management security. In order to solve these problems, we propose a novel secure deduplication scheme with scalable and reliable key management based on paring-based cryptography. The proposed scheme does not require additional secure channels to distribute key components while still guaranteeing secure key management as opposed to the previous schemes. Hyunsoo Kwon, Changhee Hahn, Dongyoung Koo, Junbeom Hur |
CLOUD | 4 |
| 2017 | Secure Data Deduplication with Dynamic Ownership Management in Cloud StorageabstractIn cloud services, deduplication technology is commonly used to reduce the space and bandwidth requirements services by eliminating redundant data and storing only single copy. Deduplication is most effective when multiple users outsource the same data to the cloud storage, but raises issues relating to security and ownership. Proof-of-ownership schemes allow any owner of the same data to prove to the cloud storage server that he owns the data in a robust way. However, if encrypted data is outsourced into the cloud storage and the ownership changes dynamically, deduplication would be hampered. Thus, we propose a secure deduplication scheme that supports dynamic ownership management based on randomized convergent encryption in this study. Junbeom Hur, Dongyoung Koo, Young-joo Shin, Kyungtae Kang |
ICDE | 1 |
| 2017 | An Online Data-Oriented Authentication Based on Merkle Tree with Improved ReliabilityabstractIn this paper, we examine the online authentication method based on Merkle (hash) tree focusing on its reliability. Coming from side channels in online authentication, the effectiveness runs into danger in the long run. With consideration of effectiveness, we present a Merkle tree based online authentication resilient against side channels by obfuscating authentication proofs. Security and efficiency are analyzed to demonstrate the practicality of the proposed approach. Dongyoung Koo, Young-joo Shin, Joobeom Yun, Junbeom Hur |
ICWS | 4 |
| 2017 | Novel hybrid CNN-SVM model for recognition of functional magnetic resonance imagesabstractThis paper proposes a novel hybrid model that integrates the synergy of two superior classifiers for functional magnetic resonance imaging (fMRI) recognition, namely, convolutional neural networks (CNNs) and support vector machines (SVMs), both of which have proven results in the field of image recognition. In the proposed model, the CNN functions as a trainable feature extractor and the SVM functions as a recognizer. This hybrid model extracts features from raw images and generates predictions for fMRI recognition. We conducted experiments on Haxby's 2001 fMRI dataset. Comparisons with Haxby's study using the same database indicated that the proposed fusion achieved superior recognition accuracy of 99.5% compared to the Haxby's approach. Further, when the CNN was used as a feature extractor, the SVM classifier was demonstrated to be the best combining counterpart, providing the best synergy effect in terms of accuracy. This is compared with other classifiers based on learning algorithms such as decision tree, neural network, K-nearest neighbor, random forest, and AdaBoost. Xiaolong Sun, Juyoung Park, Kyungtae Kang, Junbeom Hur |
SMC | 4 |
| 2017 | Trapfetch: A breakpoint-based prefetcher for both launch and run-timeabstractTrapFetch is trained by monitoring the read requests issued by an application. It detects bursts of disk reads, determines the appropriate addresses at which breakpoints should be inserted in the application and library codes prior to the bursts of reads, and then logs this information with the data requested during the interval between each consecutive pair of breakpoints. When the application and library codes are loaded from the disk into memory, TrapFetch inserts breakpoints at the designated addresses based on the logs. During subsequent runs, TrapFetch is invoked at each breakpoint when it prefetches the corresponding data into the page cache. This approach is effective during both launch and run-time. TrapFetch operates at the user level, thus avoiding interference with other applications. In experiments on five popular applications (FlightGear, SpeedDreams 2, Pillars of Eternity, Eclipse, and VegaStrike), TrapFetch reduced the time for launch by up to 39.7% and time for run-time data-loading by up to 63.7%. Jiwoong Won, Oseok Kwon, Junhee Ryu, Junbeom Hur, Insup Lee 0001, Kyungtae Kang |
SMC | 4 |
| 2017 | Secure deduplication for multimedia data with user revocation in cloud storage
Hyunsoo Kwon, Changhee Hahn, Junbeom Hur |
Multim. Tools Appl. | 4 |
| 2017 | Secure authentication using ciphertext policy attribute-based encryption in mobile multi-hop networks
Hyunsoo Kwon, Daeyeong Kim, Changhee Hahn, Junbeom Hur |
Multim. Tools Appl. | 4 |
| 2017 | Secure proof of storage with deduplication for cloud storage systems
Young-joo Shin, Dongyoung Koo, Junbeom Hur, Joobeom Yun |
Multim. Tools Appl. | 3 |
| 2016 | POSTER: Towards Privacy-Preserving Biometric Identification in Cloud ComputingabstractWang et al. recently proposed a privacy-preserving biometric identification scheme. However, the security assumption of the scheme does not capture practical aspects of real world attacks. In this paper, we consider a practical attack model which results in the leakage of biometric data in Wang et al.'s scheme. We first show the feasibility of our attack model and demonstrate how an attacker is able to recover the biometric data. Then, we propose a new biometric identification scheme that is secure against the attack model. Changhee Hahn, Junbeom Hur |
CCS | 2 |
| 2016 | A Hybrid Deduplication for Secure and Efficient Data Outsourcing in Fog ComputingabstractWith prevalence of remote storage services, data privacy issues become more serious owing to loss of control to outsourced data. In the meanwhile, the service providers tend to minimize storage utility costs. To minimize the storage costs while preserving data privacy, secure deduplication techniques have been proposed, which are categorized into client-side or server-side approaches. Client-side approach achieves storage and bandwidth savings at the same time but allows external adversaries to know existence of duplicates in the remote storage. On the contrary, server-side one prevents the adversaries from getting acknowledged but sacrifices network bandwidth savings. In fog computing, however, which is a new computing paradigm extending the cloud computing by outsourcing a centralized workload of the cloud to geographically distributed fog devices located at the edge of the networks, the previous deduplication schemes cannot guarantee efficiency improvement and privacy preservation simultaneously. In this paper, we present a simple but nontrivial solution of these contradictory issues in fog storage. The proposed hybrid secure deduplication protocol combines client-and server-side deduplications by taking untrustworthy fog storage environments into account. The client-side deduplication is applied in inter-network (i.e., cloud-fog network) communications to prevent network congestion at the network core, while the server-side deduplication is adopted in intra-network (i.e., user-fog network) communications to prevent information leakage via side channels for maximal data privacy. Performance and security analyses demonstrate the comparable efficiency of the proposed scheme with security enhancement. Dongyoung Koo, Young-joo Shin, Joobeom Yun, Junbeom Hur |
CloudCom | 4 |
| 2016 | SEED: Enabling Serverless and Efficient Encrypted Deduplication for Cloud StorageabstractData deduplication is a technique that removes redundancy of data on the storage. For cloud storage services, enabling deduplication over encrypted data is of vital importance to achieve both cost savings and keeping data confidentiality simultaneously. Recently proposed solutions are not sufficient because of lacking desired level of security and efficiency. In this paper, we propose SEED, a novel scheme for serverless and efficient encrypted deduplication. Without aid of any additional servers, SEED provides strong confidentiality to the outsourced data. In addition, its non-interactive file encryption with support of lazy encryption greatly reduces latency in file uploading process. Security analysis and performance evaluations show the superior efficiency and effectiveness of SEED for cloud storage services. Young-joo Shin, Dongyoung Koo, Joobeom Yun, Junbeom Hur |
CloudCom | 4 |
| 2016 | Enhanced authentication for outsourced educational contents through provable block possession
Changhee Hahn, Hyunsoo Kwon, Junbeom Hur |
Multim. Tools Appl. | 4 |
| 2016 | Privacy-preserving public auditing for educational multimedia data in cloud computing
Daeyeong Kim, Hyunsoo Kwon, Changhee Hahn, Junbeom Hur |
Multim. Tools Appl. | 4 |
| 2016 | Secure Data Deduplication with Dynamic Ownership Management in Cloud StorageabstractIn cloud storage services, deduplication technology is commonly used to reduce the space and bandwidth requirements of services by eliminating redundant data and storing only a single copy of them. Deduplication is most effective when multiple users outsource the same data to the cloud storage, but it raises issues relating to security and ownership. Proof-of-ownership schemes allow any owner of the same data to prove to the cloud storage server that he owns the data in a robust way. However, many users are likely to encrypt their data before outsourcing them to the cloud storage to preserve privacy, but this hampers deduplication because of the randomization property of encryption. Recently, several deduplication schemes have been proposed to solve this problem by allowing each owner to share the same encryption key for the same data. However, most of the schemes suffer from security flaws, since they do not consider the dynamic changes in the ownership of outsourced data that occur frequently in a practical cloud storage service. In this paper, we propose a novel server-side deduplication scheme for encrypted data. It allows the cloud server to control access to outsourced data even when the ownership changes dynamically by exploiting randomized convergent encryption and secure ownership group key distribution. This prevents data leakage not only to revoked users even though they previously owned that data, but also to an honest-but-curious cloud storage server. In addition, the proposed scheme guarantees data integrity against any tag inconsistency attack. Thus, security is enhanced in the proposed scheme. The efficiency analysis results demonstrate that the proposed scheme is almost as efficient as the previous schemes, while the additional computational overhead is negligible. Junbeom Hur, Dongyoung Koo, Young-joo Shin, Kyungtae Kang |
IEEE Trans. Knowl. Data Eng. | 1 |
| 2014 | A Privacy Threat in 4th Generation Mobile Telephony and Its Countermeasure
Changhee Hahn, Hyunsoo Kwon, Kyungtae Kang, Junbeom Hur |
WASA | 5 |
| 2014 | Secure Device-to-Device Authentication in Mobile Multi-hop Networks
Hyunsoo Kwon, Changhee Hahn, Kyungtae Kang, Junbeom Hur |
WASA | 5 |
| 2014 | Secure Data Retrieval for Decentralized Disruption-Tolerant Military NetworksabstractMobile nodes in military environments such as a battlefield or a hostile region are likely to suffer from intermittent network connectivity and frequent partitions. Disruption-tolerant network (DTN) technologies are becoming successful solutions that allow wireless devices carried by soldiers to communicate with each other and access the confidential information or command reliably by exploiting external storage nodes. Some of the most challenging issues in this scenario are the enforcement of authorization policies and the policies update for secure data retrieval. Ciphertext-policy attribute-based encryption (CP-ABE) is a promising cryptographic solution to the access control issues. However, the problem of applying CP-ABE in decentralized DTNs introduces several security and privacy challenges with regard to the attribute revocation, key escrow, and coordination of attributes issued from different authorities. In this paper, we propose a secure data retrieval scheme using CP-ABE for decentralized DTNs where multiple key authorities manage their attributes independently. We demonstrate how to apply the proposed mechanism to securely and efficiently manage the confidential data distributed in the disruption-tolerant military network. Junbeom Hur, Kyungtae Kang |
IEEE/ACM Trans. Netw. | 1 |
| 2013 | Design and QoS of a Wireless System for Real-Time Remote ElectrocardiographyabstractQuality of service (QoS) and, in particular, reliability and a bounded low latency are essential attributes of safety-critical wireless systems for medical applications. However, wireless links are typically prone to bursts of errors, with characteristics which vary over time.We propose a wireless system suitable for real-time remote patient monitoring in which the necessary reliability and guaranteed latency are both achieved by an efficient error control scheme. We have paired an example remote electrocardiography application to this wireless system. We also developed a tool chain that uses a formal description of the proposed wireless medical system architecture in the architecture analysis and design language to assess various combinations of system parameters: we can determine the QoS in terms of packet-delivery ratio and the service latency, and also the size of jitter buffer required for seamless ECG monitoring. A realistic assessment, based on data from the MIT-BIT arrhythmia database, shows that the proposed wireless system can achieve an appropriate level of QoS for real-time ECG monitoring if link-level error control is correctly implemented. Additionally, we present guidelines for the design of energy-efficient link-level error control, derived from energy data, obtained from simulations. Kyungtae Kang, Junhee Ryu, Junbeom Hur, Lui Sha |
IEEE J. Biomed. Health Informatics | 3 |
| 2013 | Improving Security and Efficiency in Attribute-Based Data SharingabstractWith the recent adoption and diffusion of the data sharing paradigm in distributed systems such as online social networks or cloud computing, there have been increasing demands and concerns for distributed data security. One of the most challenging issues in data sharing systems is the enforcement of access policies and the support of policies updates. Ciphertext policy attribute-based encryption (CP-ABE) is becoming a promising cryptographic solution to this issue. It enables data owners to define their own access policies over user attributes and enforce the policies on the data to be distributed. However, the advantage comes with a major drawback which is known as a key escrow problem. The key generation center could decrypt any messages addressed to specific users by generating their private keys. This is not suitable for data sharing scenarios where the data owner would like to make their private data only accessible to designated users. In addition, applying CP-ABE in the data sharing system introduces another challenge with regard to the user revocation since the access policies are defined only over the attribute universe. Therefore, in this study, we propose a novel CP-ABE scheme for a data sharing system by exploiting the characteristic of the system architecture. The proposed scheme features the following achievements: 1) the key escrow problem could be solved by escrow-free key issuing protocol, which is constructed using the secure two-party computation between the key generation center and the data-storing center, and 2) fine-grained user revocation per each attribute could be done by proxy encryption which takes advantage of the selective attribute group key distribution on top of the ABE. The performance and security analyses indicate that the proposed scheme is efficient to securely manage the data distributed in the data sharing system. Junbeom Hur |
IEEE Trans. Knowl. Data Eng. | 1 |
| 2013 | Attribute-Based Secure Data Sharing with Hidden Policies in Smart GridabstractSmart grid uses intelligent transmission and distribution networks to deliver electricity. It aims to improve the electric system's reliability, security, and efficiency through two-way communication of consumption data and dynamic optimization of electric-system operations, maintenance, and planning. The smart grid systems use fine-grained power grid measurements to provide increased grid stability and reliability. Key to achieving this is securely sharing the measurements among grid entities over wide area networks. Typically, such sharing follows policies that depend on data generator and consumer preferences and on time-sensitive contexts. In smart grid, as well as the data, policies for sharing the data may be sensitive because they directly contain sensitive information, and reveal information about underlying data protected by the policy, or about the data owner or recipients. In this study, we propose an attribute-based data sharing scheme in smart grid. Not only the data but also the access policies are obfuscated in grid operators' point of view during the data sharing process. Thus, the data privacy and policy privacy are preserved in the proposed scheme. The access policy can be expressed with any arbitrary access formula. Thus, the expressiveness of the policy is enhanced. The security is also improved such that the unauthorized key generation center or the grid manage systems that store the data cannot decrypt the data to be shared. The computation overhead of recipients are also reduced by delegating most of the laborious decryption operations to the more powerful grid manage systems. Junbeom Hur |
IEEE Trans. Parallel Distributed Syst. | 1 |
| 2013 | Cross-layer analysis of protocol delay in mobile devices receiving BCMCS
Kyungtae Kang, Juyoung Park, Junbeom Hur |
Wirel. Networks | 3 |
| 2012 | Dependable and secure computing in medical information systems
Junbeom Hur, Kyungtae Kang |
Comput. Commun. | 1 |
| 2012 | Using a dynamic backbone for efficient data delivery in solar-powered WSNs
Dong Kun Noh, Junbeom Hur |
J. Netw. Comput. Appl. | 2 |
| 2012 | Fine-grained user access control in ciphertext-policy attribute-based encryptionabstractABSTRACT Key revocation is one of the most challenging and open issues in attribute‐based encryption (ABE). The previous revocable ABE schemes feature a mechanism that revokes the attribute key periodically without any consideration of the user membership associated with the attribute. Thus, non‐revoked users are enforced to access the key authority periodically to receive keying materials in order to update the current key. This is due to the fact that the revocation is done only on the attribute level, which results in security and scalability problems. In this paper, we propose a fine‐grained user revocation scheme without affecting any non‐revoked users who share the same attributes in ciphertext‐policy ABE; it does not require the users to access the key authority and to update keys periodically. The proposed scheme improves the efficiency compared with previous revocable schemes and enhances the security in terms of the backward/forward secrecy on any membership changes in the ciphertext‐policy ABE system. Copyright © 2011 John Wiley & Sons, Ltd. Junbeom Hur, Chanil Park, Seong Oun Hwang |
Secur. Commun. Networks | 1 |
| 2012 | Scalable and efficient approach for secure group communication using proxy cryptography
Young-joo Shin, Junbeom Hur |
Wirel. Networks | 2 |
| 2011 | Attribute-Based Access Control with Efficient Revocation in Data Outsourcing SystemsabstractSome of the most challenging issues in data outsourcing scenario are the enforcement of authorization policies and the support of policy updates. Ciphertext-policy attribute-based encryption is a promising cryptographic solution to these issues for enforcing access control policies defined by a data owner on outsourced data. However, the problem of applying the attribute-based encryption in an outsourced architecture introduces several challenges with regard to the attribute and user revocation. In this paper, we propose an access control mechanism using ciphertext-policy attribute-based encryption to enforce access control policies with efficient attribute and user revocation capability. The fine-grained access control can be achieved by dual encryption mechanism which takes advantage of the attribute-based encryption and selective group key distribution in each attribute group. We demonstrate how to apply the proposed mechanism to securely manage the outsourced data. The analysis results indicate that the proposed scheme is efficient and secure in the data outsourcing systems. Junbeom Hur, Dong Kun Noh |
IEEE Trans. Parallel Distributed Syst. | 1 |
| 2011 | Fine-grained data access control for distributed sensor networks
Junbeom Hur |
Wirel. Networks | 1 |
| 2010 | A Multi-service Group Key Management Scheme for Stateless Receivers in Wireless Mesh Networks
Junbeom Hur, Hyunsoo Yoon |
Mob. Networks Appl. | 1 |
| 2009 | Bandwidth efficient key distribution for secure multicast in dynamic wireless mesh networksabstractIn the near future, various multicast based services will be provided over wireless mesh networks. For secure multicast services, various tree based group key management schemes have been introduced until now. Traditional tree based approaches mainly focus on reducing the number of rekeying messages transmitted by the key distribution center. However, they do not consider the network bandwidth used for transmitting each rekeying message. We propose a bandwidth efficient key tree management scheme for dynamic wireless mesh networks where membership changes occur frequently. Simulation results show that our scheme effectively reduces the bandwidth consumption used for rekeying compared to existing key tree schemes. Seungjae Shin 0001, Junbeom Hur, Hanjin Lee, Hyunsoo Yoon |
WCNC | 2 |
| 2009 | Improved batch exponentiation
Byungchun Chung, Junbeom Hur, Heeyoul Kim, Seong-Min Hong 0001, Hyunsoo Yoon |
Inf. Process. Lett. | 2 |
| 2008 | Security Considerations for Handover Schemes in Mobile WiMAX NetworksabstractIEEE 802.16e uses EAP-based authentication and key management for link layer security. Due to the lack of ability to support mobility, however, EAP-based key management becomes a principal impediment to the achievement of an efficient and secure handover in IEEE 802.16e mobile WiMAX networks. In this paper, an overview of the EAP-based handover procedures of the latest IEEE 802.16e standard is given and their security flaws are analyzed. Possible solutions for secure handover in IEEE 802.16e networks are also proposed in this paper. The proposed handover protocol guarantees a backward/forward secrecy while gives little burden over the previous handover protocols. Junbeom Hur, HyeongSeop Shim, Pyung Kim, Hyunsoo Yoon, Nah-Oak Song |
WCNC | 1 |