Dianqi Han

dblp:227/8113 · DBLP profile ↗
← Back
18ranked-venue papers
5as first author
15since 2021 · last 2026
0000-0002-0105-5869ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 13 · 3 first-author · 10 since 2021Security and privacy · 4 · 1 first-author · 4 since 2021Systems, architecture and hardware · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2026 TagStroke: Stealthy Keystroke Inference via Passive RFID Arrays Beneath Keyboards
Jiawei Li 0010, Yan Zhang 0091, Dianqi Han, Ang Li 0013, Tao Li 0042
INFOCOM3
2026 RIS-CLA: Reviving CSI-Based Continuous Location Authentication With Reconfigurable Intelligent Surfaces
Yan Zhang 0091, Jiawei Li 0010, Dianqi Han, Aditya Shekhawat, George Trichopoulos
SP4
2024 WaveKey: Secure Mobile Ad Hoc Access to RFID-Protected Systems
abstract
This paper presents the design and evaluation of WaveKey, a cross-modal deep learning-based method to enable mobile ad hoc in-situ access to RFID- protected cyber systems. Built upon the ever-growing popularity of user-carried mobile devices and RFID technologies, WaveKey is motivated by the need for secure and user-friendly data access in various application contexts. WaveKey explores a random gesture performed by the mobile user to induce correlated IMU data and RFID signals at the involved mobile device and RFID server, adopts deep learning techniques to extract the complex cross-modal correlation, and devises an Oblivious Transfer-based key-agreement protocol to-ward secure and efficient key establishment. Theoretical analysis and experimental human-based evaluation confirmed the high security and efficiency of WaveKey. In particular, WaveKey shows very high key-establishment success rates consistently exceeding 98 % across all evaluated settings and renders extremely low success rates below 0.5 % for all evaluated common attacks.
Dianqi Han, Ang Li 0013, Jiawei Li 0010, Yan Zhang 0091, Tao Li 0042
ICDCS1
2023 PhyAuth: Physical-Layer Message Authentication for ZigBee Networks
Ang Li 0013, Jiawei Li 0010, Dianqi Han, Yan Zhang 0091, Tao Li 0042, Ting Zhu 0001
USENIX Security Symposium3
2023 SmartMagnet: Proximity-Based Access Control for IoT Devices With Smartphones and Magnets
abstract
Ubiquitous smartphones can be powerful tools to access IoT devices. Proximity-based access control (PBAC) is needed such that IoT devices only allow data access by legitimate users in close proximity. Traditional smartphone-based authentication techniques do not satisfy the PBAC requirements. This paper presents SmartMagnet, a novel scheme that combines smartphones and cheap magnets to achieve PBAC for IoT devices. SmartMagnet explores a few cheap, tiny commodity magnets which we propose to attach to or embed into IoT devices, as well as the magnetometer and attitude sensor on commodity smartphones. Each legitimate user performs a self-chosen 3D password gesture near the target IoT device with the enrolled smartphone. Then the system server uses the IoT device’s confidential magnet configuration parameters to reconstruct the user gesture from the magnetometer and attitude sensor data submitted by the smartphone. If the reconstructed gesture matches the stored template of the purported user, the smartphone user is deemed legitimate and allowed access to the IoT device. Extensive experiments confirm the high usability of SmartMagnet and its strong resilience to lost/stolen smartphones and also remote attacks via signal relaying.
Yan Zhang 0091, Dianqi Han, Ang Li 0013, Jiawei Li 0010, Tao Li 0042
IEEE Trans. Mob. Comput.2
2023 MagAuth: Secure and Usable Two-Factor Authentication With Magnetic Wrist Wearables
abstract
Secure and usable user authentication is the first line of defense against cyber attacks on smart end-user devices. Advanced hacking techniques pose severe threats to the traditional authentication systems based on the password/PIN/fingerprint. We propose MagAuth, a secure and usable two-factor authentication scheme with commercial off-the-shelf (COTS) wrist wearables with magnetic strap bands to enhance the security and usability of password-based authentication for mobile touchscreen devices. In MagAuth, a user enrolls a self-chosen unlock pattern or touch gesture into his touchscreen device by performing it with the same hand the magnetic wrist wearable is on. The chosen unlock pattern or touch gesture serves as the first authentication factor, and the user’s behavioral features manifested in the magnetic field changes during his finger movement correspond to the second factor. The user can unlock his touchscreen device only when both authentication factors can be validated. Comprehensive user experiments confirm the high security and usability of MagAuth. In particular, MagAuth achieves an average true-positive rate up to 96.3 percent and a false-positive rate no larger than 8.4 percent. Moreover, we show that MagAuth is highly resilient to various attacks.
Yan Zhang 0091, Dianqi Han, Ang Li 0013, Tao Li 0042
IEEE Trans. Mob. Comput.2
2023 Rhythmic RFID Authentication
abstract
Passive RFID technology is widely used in user authentication and access control. We propose RF-Rhythm, a secure and usable two-factor RFID authentication system with strong resilience to lost/stolen/cloned RFID cards. In RF-Rhythm, each legitimate user performs a sequence of taps on his/her RFID card according to a self-chosen secret melody. Such rhythmic taps can induce phase changes in the backscattered signals, which the RFID reader can detect to recover the user’s tapping rhythm. In addition to verifying the RFID card’s identification information as usual, the backend server compares the extracted tapping rhythm with what it acquires in the user enrollment phase. The user passes authentication checks if and only if both verifications succeed. We also propose a novel phase-hopping protocol in which the RFID reader emits Continuous Wave (CW) with random phases for extracting the user’s secret tapping rhythm. Our protocol can prevent a capable adversary from extracting and then replaying a legitimate tapping rhythm from sniffed RFID signals. Comprehensive user experiments confirm the high security and usability of RF-Rhythm with false-positive and false-negative rates close to zero.
Jiawei Li 0010, Ang Li 0013, Dianqi Han, Yan Zhang 0091, Jinhang Zuo, Rui Zhang 0007, Lei Xie 0004
IEEE/ACM Trans. Netw.4
2023 Secure UHF RFID Authentication With Smart Devices
abstract
Commodity ultra-high-frequency (UHF) RFID authentication systems only provide weak user authentication, as RFID tags can be easily stolen, lost, or cloned by attackers. This paper presents the design and evaluation of SmartRFID, a novel UHF RFID authentication system to promote commodity crypto-less UHF RFID tags for security-sensitive applications. SmartRFID explores extremely popular smart devices and requires a legitimate user to enroll his smart device along with his RFID tag. Besides authenticating the RFID tag as usual, SmartRFID verifies whether the user simultaneously possesses the associated smart device with both feature-based machine learning and deep learning techniques. The user is considered authentic if and only if passing the dual verifications. Comprehensive user experiments on commodity smartwatches and RFID devices confirmed the high security and usability of SmartRFID. In particular, SmartRFID achieves a true acceptance rate of above 97.5% and a false acceptance rate of less than 0.7% based on deep learning. In addition, SmartRFID can achieve an average authentication latency of less than 2.21 s, which is comparable to inputting a PIN on a door keypad or smartphone.
Ang Li 0013, Jiawei Li 0010, Yan Zhang 0091, Dianqi Han, Tao Li 0042
IEEE Trans. Wirel. Commun.4
2022 WearRF-CLA: Continuous Location Authentication with Wrist Wearables and UHF RFID
abstract
Continuous location authentication (CLA) seeks to continuously and automatically verify the physical presence of legitimate users in a protected indoor area. CLA can play an important role in contexts where access to electrical or physical resources must be limited to physically present legitimate users. In this paper, we present WearRF-CLA, a novel CLA scheme built upon increasingly popular wrist wearables and UHF RFID systems. WearRF-CLA explores the observation that human daily routines in a protected indoor area comprise a sequence of human-states (e.g., walking and sitting) that follow predictable state transitions. Each legitimate WearRF-CLA user registers his/her RFID tag and also wrist wearable during system enrollment. After the user enters a protected area, WearRF-CLA continuously collects and processes the gyroscope data of the wrist wearable and the phase data of the RFID tag signals to verify three factors to determine the user's physical presence/absence without explicit user involvement: (1) the tag ID as in a traditional RFID authentication system, (2) the validity of the human-state chain, and (3) the continuous coexistence of the paired wrist wearable and RFID tag with the user. The user passes CLA if and only if all three factors can be validated. Extensive user experiments on commodity smartwatches and UHF RFID devices confirm the very high security and low authentication latency of WearRF-CLA.
Ang Li 0013, Jiawei Li 0010, Dianqi Han, Yan Zhang 0091, Tao Li 0042
AsiaCCS3
2022 RCID: Fingerprinting Passive RFID Tags via Wideband Backscatter
abstract
Tag cloning and spoofing pose great challenges to RFID applications. This paper presents the design and evaluation of RCID, a novel system to fingerprint RFID tags based on the unique reflection coefficient of each tag circuit. Based on a novel OFDM-based fingerprint collector, our system can quickly acquire and verify each tag’s RCID fingerprint which are independent of the RFID reader and measurement environment. Our system applies to COTS RFID tags and readers after a firmware update at the reader. Extensive prototyped experiments on 600 tags confirm that RCID is highly secure with the authentication accuracy up to 97.15% and the median authentication error rate equal to 1.49%. RCID is also highly usable because it only takes about 8 s to enroll a tag and 2 ms to verify an RCID fingerprint with a fully connected multi-class neural network. Finally, empirical studies demonstrate that the entropy of an RCID fingerprint is about 202 bits over a bandwidth of 20 MHz in contrast to the best prior result of 17 bits, thus offering strong theoretical resilience to RFID cloning and spoofing.
Jiawei Li 0010, Ang Li 0013, Dianqi Han, Yan Zhang 0091, Tao Li 0042
INFOCOM3
2022 (In)secure Acoustic Mobile Authentication
abstract
Acoustic fingerprinting aims to identify a mobile device based on its internal microphone(s) and speaker(s) which are unique due to manufacturing imperfection. This paper seeks a thorough understanding of the (in)security of exploring acoustic fingerprints for achieving distributed mobile authentication. Our contributions are threefold. First, we present a new acoustic fingerprint-emulation attack and demonstrate that it is a common vulnerability of acoustic mobile authentication systems. Second, we propose a dynamic challenge-response defense to secure acoustic mobile authentication systems against the acoustic fingerprint-emulation attack. Finally, we thoroughly investigate existing acoustic fingerprinting schemes and identify the best option for accurate, secure, and deployable acoustic mobile authentication systems.
Dianqi Han, Ang Li 0013, Tao Li 0042, Yan Zhang 0091, Jiawei Li 0010, Rui Zhang 0007
IEEE Trans. Mob. Comput.1
2022 SpecKriging: GNN-Based Secure Cooperative Spectrum Sensing
abstract
Cooperative spectrum sensing (CSS) adopted by spectrum-sensing providers (SSPs) plays a key role for dynamic spectrum access and is essential for avoiding interference with licensed primary users (PUs). A typical SSP system consists of geographically distributed spectrum sensors which can be compromised to submit fake spectrum-sensing reports. In this paper, we propose SpecKriging, a new spatial-interpolation technique based on Inductive Graph Neural Network Kriging (IGNNK) for secure CSS. In SpecKriging, we first pretrain a graphical neural network (GNN) model with the historical sensing records of a few trusted anchor sensors. During system runtime, we use the trained model to evaluate the trustworthiness of non-anchor sensors’ data and also use them along with anchor sensors’ new data to retrain the model. SpecKriging outputs trustworthy sensor reports for spectrum-occupancy detection. To the best of our knowledge, SpecKriging is the first work that explores GNNs for trustworthy CSS and also incorporates the hardware heterogeneity of spectrum sensors. Extensive experiments confirm the high efficacy and efficiency of SpecKriging for trustworthy spectrum-occupancy detection even when malicious spectrum sensors constitute the majority.
Yan Zhang 0091, Ang Li 0013, Jiawei Li 0010, Dianqi Han, Tao Li 0042, Rui Zhang 0007
IEEE Trans. Wirel. Commun.4
2021 DroneKey: A Drone-Aided Group-Key Generation Scheme for Large-Scale IoT Networks
abstract
The Internet of Things (IoT) networks are finding massive applications in mission-critical contexts. A group key is needed to encrypt and authenticate broadcast/multicast messages commonly seen in large-scale wireless networks. In this paper, we propose DroneKey, a novel drone-aided PHY-based Group-Key Generation (GKG) scheme for large-scale IoT networks. In DroneKey, a drone is dispatched to fly along random 3D trajectories and keep broadcasting standard wireless signals to refresh the group keys in the whole network. Every IoT device receives the broadcast signals from which to extract the Channel State Information (CSI) stream which captures the dynamic variations of the individual wireless channel between the IoT device and the drone. DroneKey explores a deep-learning approach to extract the hidden correlation among the CSI streams to establish a common group key. We thoroughly evaluate DroneKey with a prototype in both indoor and outdoor environments. We show that DroneKey can achieve a high key-generation rate of 89.5 bit/sec for 10 devices in contrast to 40 bit/sec in the state-of-art prior work. In addition, DroneKey is much more scalable and can support 100 devices in contrast to 10 nodes in the state-of-art prior work with comparable key-generate rates.
Dianqi Han, Ang Li 0013, Jiawei Li 0010, Yan Zhang 0091, Tao Li 0042
CCS1
2021 Your Home is Insecure: Practical Attacks on Wireless Home Alarm Systems
abstract
Wireless home alarm systems are being widely deployed, but their security has not been well studied. Existing attacks on wireless home alarm systems exploit the vulnerabilities of networking protocols while neglecting the problems arising from the physical component of IoT devices. In this paper, we present new event-eliminating and event-spoofing attacks on commercial wireless home alarm systems by interfering with the reed switch in almost all COTS alarm sensors. In both attacks, the external adversary uses his own magnet to control the state of the reed switch in order to either eliminate legitimate alarms or spoof false alarms. We also present a new battery-depletion attack with programmable electromagnets to deplete the alarm sensor's battery quickly and stealthily in hours which is expected to last a few years. The efficacy of our attacks is confirmed by detailed experiments on a representative Ring alarm system.
Tao Li 0042, Dianqi Han, Jiawei Li 0010, Ang Li 0013, Yan Zhang 0091, Rui Zhang 0007
INFOCOM2
2021 Deep Learning-Guided Jamming for Cross-Technology Wireless Networks: Attack and Defense
abstract
Wireless networks of different technologies may interfere with each other when they are deployed at proximity. Such cross-technology interference (CTI) has become prevalent with the surge of IoT devices. In this paper, we exploit CTI in coexisting WiFi-Zigbee networks and propose DeepJam, a new stealthy jamming strategy, to jam Zigbee traffic. DeepJam relies on deep learning techniques to capture the temporal pattern of the past wireless traffic and predict the future wireless traffic. By only jamming the victim’s transmissions that are not disrupted by CTI, DeepJam can significantly reduce the victim’s throughput with far fewer jamming signals and is thus much more stealthy than conventional jamming strategies. Detailed evaluations show that DeepJam can converge within 10 sec and achieve the jamming-efficiency gains of up to 742% and 285% over conventional random and reactive jamming strategies, respectively, in practical scenarios. We also propose a simple yet effective countermeasure against DeepJam.
Dianqi Han, Ang Li 0013, Yan Zhang 0091, Jiawei Li 0010, Tao Li 0042, Ting Zhu 0001
IEEE/ACM Trans. Netw.1
2020 RF-Rhythm: Secure and Usable Two-Factor RFID Authentication
abstract
Passive RFID technology is widely used in user authentication and access control. We propose RF-Rhythm, a secure and usable two-factor RFID authentication system with strong resilience to lost/stolen/cloned RFID cards. In RF-Rhythm, each legitimate user performs a sequence of taps on his/her RFID card according to a self-chosen secret melody. Such rhythmic taps can induce phase changes in the backscattered signals, which the RFID reader can detect to recover the user’s tapping rhythm. In addition to verifying the RFID card’s identification information as usual, the backend server compares the extracted tapping rhythm with what it acquires in the user enrollment phase. The user passes authentication checks if and only if both verifications succeed. We also propose a novel phase-hopping protocol in which the RFID reader emits Continuous Wave (CW) with random phases for extracting the user’s secret tapping rhythm. Our protocol can prevent a capable adversary from extracting and then replaying a legitimate tapping rhythm from sniffed RFID signals. Comprehensive user experiments confirm the high security and usability of RF-Rhythm with false-positive and false-negative rates close to zero.
Jiawei Li 0010, Ang Li 0013, Dianqi Han, Yan Zhang 0091, Jinhang Zuo, Rui Zhang 0007, Lei Xie 0004
INFOCOM4
2020 IndoorWaze: A Crowdsourcing-Based Context-Aware Indoor Navigation System
abstract
Indoor navigation systems are very useful in large complex indoor environments such as shopping malls. Current systems focus on improving indoor localization accuracy and must be combined with an accurate labeled floor plan to provide usable indoor navigation services. Such labeled floor plans are often unavailable or involve a prohibitive cost to manually obtain. In this paper, we present IndoorWaze, a novel crowdsourcing-based context-aware indoor navigation system that can automatically generate an accurate context-aware floor plan with labeled indoor POIs for the first time in literature. IndoorWaze combines the Wi-Fi fingerprints of indoor walkers with the Wi-Fi fingerprints and POI labels provided by POI employees to produce a high-fidelity labeled floor plan. As a lightweight crowdsourcing-based system, IndoorWaze involves very little effort from indoor walkers and POI employees. We prototype IndoorWaze on Android smartphones and evaluate it in a large shopping mall. Our results show that IndoorWaze can generate a high-fidelity labeled floor plan, in which all the stores are correctly labeled and arranged, all the pathways and crossings are correctly shown, and the median estimation error for the store dimension is below 12%.
Tao Li 0042, Dianqi Han, Yimin Chen 0004, Rui Zhang 0007, Terri Hedgpeth
IEEE Trans. Wirel. Commun.2
2018 Proximity-Proof: Secure and Usable Mobile Two-Factor Authentication
abstract
Mobile two-factor authentication (2FA) has become commonplace along with the popularity of mobile devices. Current mobile 2FA solutions all require some form of user effort which may seriously affect the experience of mobile users, especially senior citizens or those with disability such as visually impaired users. In this paper, we propose Proximity-Proof, a secure and usable mobile 2FA system without involving user interactions. Proximity-Proof automatically transmits a user's 2FA response via inaudible OFDM-modulated acoustic signals to the login browser. We propose a novel technique to extract individual speaker and microphone fingerprints of a mobile device to defend against the powerful man-in-the-middle (MiM) attack. In addition, Proximity-Proof explores two-way acoustic ranging to thwart the co-located attack. To the best of our knowledge, Proximity-Proof is the first mobile 2FA scheme resilient to the MiM and co-located attacks. We empirically analyze that Proximity-Proof is at least as secure as existing mobile 2FA solutions while being highly usable. We also prototype Proximity-Proof and confirm its high security, usability, and efficiency through comprehensive user experiments.
Dianqi Han, Yimin Chen 0004, Tao Li 0042, Rui Zhang 0007, Terri Hedgpeth
MobiCom1