Yixin Jiang

dblp:26/5034 · DBLP profile ↗
← Back
66ranked-venue papers
15as first author
10since 2021 · last 2026
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 43 · 12 first-author · 2 since 2021Systems, architecture and hardware · 7 · 1 first-author · 3 since 2021Security and privacy · 7 · 3 since 2021Applied, interdisciplinary, general and emerging computing · 6 · 2 first-author · 2 since 2021Human-computer interaction and ubiquitous computing · 4 · 1 first-authorDatabases, data management, data science and information retrieval · 2Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
YearPublicationVenuePosition
2026 LLM-Empowered Discovery of Windows APIs Exploitable for Persistent Storage in Fileless Attacks
Shu Meng, Haitao Xu 0002, Shuai Hao 0001, Yixin Jiang
DSN6
2026 CHAMELEOSCAN: Demystifying and Detecting iOS Chameleon Apps via LLM-Powered UI Exploration
Haitao Xu 0002, Yanchen Lu, Mengxia Ren, Shuai Hao 0001, Chuan Yue, Zhao Li 0007, Fan Zhang 0010, Yixin Jiang
NDSS10
2025 A BERT-Assisted LLM Framework for Knowledge Graph Construction
abstract
In knowledge graph construction, traditional NLP models suffer from poor cross-domain adaptability, while large language models (LLMs) face issues of hallucinations and data shift in information extraction. To address these challenges, we propose a collaborative framework for LLM-based triple extraction that integrates dynamic prompt generation and BERT assistance, effectively combining the entity recognition strengths of traditional models with the end-to-end reasoning capabilities of LLMs. On one hand, the framework uses the K-nearest neighbor (KNN) algorithm to vectorize text entity types. It matches highly relevant examples and generates dynamic prompts with progressive reasoning chain-of-thought (CoT) templates, enhancing LLMs' ability to adapt to task features and perform logical reasoning. On the other hand, it fine-tunes pre-trained BERT models to achieve accurate recognition and type annotation of text entities, alleviating LLM hallucinations by enhancing the structured representation of input text. Experimental validation on 3 cross-domain and cross-lingual datasets shows that when few-shot learning is combined with the CoT strategy, the triple extraction F1 score of Qwen2.5-14B increases from 0.1718 to 0.5856 (a 240.9 % relative improvement), demonstrating a performance breakthrough from strategy integration. After introducing BERT assistance, the F1 score of DeepSeek-V3 reaches 0.7426, and Qwen2.5-14B achieves a 277.3 % relative improvement compared to the zero-shot baseline, which verifies the effectiveness of cross-model collaboration. Compared with the traditional NLP model, it significantly enhances LLMs' knowledge transfer capability and domain adaptability. It provides an innovative paradigm for intelligent knowledge graph construction through the collaboration of traditional NLP techniques and prompt engineering, effectively compensating for the inherent limitations of LLMs.
Yixin Jiang, Kaitian Huang, Yiwei Yang 0003, Peiming Xu, Leyu Bi
ICPADS1
2025 HF-IDS: A Hybrid Method for Fine-Grained Known/Unknown Intrusion Detection
Tianming Zheng, Yixin Jiang, Feiyang Huang
NSS2
2025 Learning-based robust direction-of-arrival estimation with array imperfections
Jiajing Chen, Yixin Jiang, Qingjiang Shi, Xiang Cheng 0001, Xuesong Cai
Signal Process.3
2025 Multiparty Computation for Privacy Preserving Multisource Data Mining in Industrial IoT
abstract
Within the context of the Industrial Internet of Things (IIoT), interorganizational collaboration and data interchange enable enhanced data analytics and extraction. The joint data mining yields improved data access, analytical precision, and uncovers concealed patterns. However, during the process of joint data mining, there are data privacy concerns such as data leakage and misuse, necessitating the protection of data privacy. In this article, we propose a secure multiparty computation (MPC) approach, aiming to achieve the separation of data ownership and usage which ensures that multiple parties can perform computations without revealing sensitive inputs. Additionally, we utilize Beaver triples to reduce polynomial degrees and lower communication costs. Furthermore, we demonstrate consistency checks and computation verification to attest to the result consistency and data confidentiality under the semihonest adversary model. When evaluated with 20 parties on an Intel i7-10700 CPU, a single 128-bit field multiplication transmits 2.6 KB and completes in 21 ms over a 1 Mbps link. Even at 500 parties the budget remains 62.6 kB (490 ms). Compared with six representative MPC and homomorphic schemes, the proposed design achieves the lowest overall communication cost and competitive computation time. Integrated into a privacy-preserving DBSCAN implementation, the framework clusters 1000 2-D points with plaintext-level accuracy in millisecond-level, demonstrating practical applicability to multisource data mining.
Hongjian Yin, Yixin Jiang, Lei Zhang 0115, Huaqing Wang, Guanglai Guo, Yinfeng Hao
IEEE Trans. Ind. Informatics2
2024 Blockchain-assisted secure multi-party computation with verification and auditing
abstract
Under the rapid development of big data and cloud computing, emerging applications have seen significant improvements in efficiency and service quality. Nevertheless, the conflict between data sharing and privacy preservation remains a major obstacle to the advancement of big data technology. Addressing this issue, this study introduces a solution tailored to the big data environment, which achieves privacy protection and auditability in data sharing and processing. This approach separates data ownership, usage, and validation to mitigate privacy breaches and improper computing behaviors. Leveraging blockchain technology, a transparent governance platform is constructed to identify and track illegal data and computing activities. Furthermore, the solution integrates noninteractive zero-knowledge proofs for publicly verifying data consistency and computing validity on the blockchain. Experimental analysis on computational latency, communication costs, and encryption parameters confirms the feasibility and efficacy of this approach.
Yixin Jiang, Hongjian Yin, Yakun Niu, Yinfeng Hao
ISPA2
2024 Joint Optimization of UAV Deployment and Directional Antenna Orientation for Multi-UAV Cooperative Sensing System
abstract
Unmanned aerial vehicle (UAV) swarm-based sensing technology has become increasingly important due to its exceptional maneuverability, versatile coverage capabilities, and reliable line-of-sight (LoS) connectivity. However, the sensing accuracy improvement by exploiting resource coordination strategy poses a new challenge on multi-UAV sensing system. In this paper, we consider the problem of cooperative sensing via a system of multi-UAV, where each UAV is equipped with a directional antenna to cooperatively conduct energy detection for several targets of interest. To measure the perception ability of the system, we choose the energy detection probability as the metric, aiming to maximize the sum detection probability of the network by jointly optimizing UAVs’ deployment, as well as the directional antenna orientations. By virtue of the specific problem structure, we recast the formulation into an equivalent yet more tractable form with the aid of auxiliary vectors. Subsequently, we propose an efficient iterative algorithm for the solution based on the alternating direction penalty method (ADPM), which decomposes the formulated non-convex problem into multiple subproblems and solves them alternately. Extensive simulations validate the efficacy of the proposed algorithm and provide valuable insights for practical system design.
Wenqiang Pu, Yixin Jiang, Rongqing Zhang 0001, Qingjiang Shi
IEEE Trans. Wirel. Commun.3
2023 Deep-Reinforcement-Learning-Based IRS for Cooperative Jamming Networks Under Edge Computing
abstract
Effective energy design and secure communications are critical in the Internet of Things (IoT). A cooperative jamming (CJ) scheme based on deep reinforcement learning (DRL) is proposed for intelligent reflecting surface (IRS) aided secure cooperative network with eavesdroppers. Our goal is to maximize the average secrecy rate, or energy efficiency with secrecy constraints by jointly optimizing the transmit, jamming beamforming matrices, and IRS phase-shift matrix. In order to figure out the challenging nonconvex optimization problem, the deep deterministic policy gradient (DDPG) optimization algorithm is proposed to solve the energy efficiency maximization problem. In order to speed up task processing and reduce service delay, the edge computing server is employed for DRL training to improve computing speed and promote secure communication efficiency. By taking advantages of the features of proximity to end devices and computing resources, the edge devices provide a low latency efficient training support to the legal users and real-time control to the IRS units. By this way, a high security and low energy consumption IoT system is built. Numerical results show that the novel scheme improves the secrecy rate and energy efficiency compared with the benchmark scheme.
Tengyue Zhang 0002, Hong Wen 0001, Yixin Jiang, Jie Tang 0005
IEEE Internet Things J.3
2021 Temporal Mapping of Grassland Aboveground Biomass in Qinghai Province from Landsat 8 and Sentinel-2
abstract
Aboveground biomass (AGB) is an important indicator of grassland state. Remote sensing estimation method of grassland biomass can provide important decision support for decision-makers and relevant personnel on grassland management, such as the rational development and utilization of grassland resources, the local ecological environment protection and the rational development of animal husbandry. In this study, based on Landsat 8 and Sentinel-2 A/B satellites data, PROSAILH radiative transfer model (RTM) and look up table (LUT) algorithm were applied to temporally retrieve and map the grassland AGB in Qinghai Province from September 2019 to August 2020, an important graziery region in China. Further analysis on the relation between the AGB and meteorological data showes that the precipitation and air temperature in Qinghai is consistent with the average biomass dynamic, indicating the considerable effect of the meteorological factors on the AGB in this region.
Yixin Jiang, Peng Kong, Xingwen Quan, Binbin He
IGARSS1
2020 Scalable and Accurate Binary Search Method based on Simhash and Partial Trace
abstract
Binary code search has received much attention recently due to its impactful applications, e.g., plagiarism detection, malware detection and software vulnerability auditing. However, developing an effective binary code search tool is challenging due to the gigantic syntax and structural differences in binaries resulted from different compilers, compiler options and malware family. In this paper, we propose a scalable and accurate binary search engine which performs syntactic matching by combining a set of key techniques to address the challenges above. The key contribution is binary code searching technique which combined function filtering and partial trace method to match the function code relatively quick and accurate. In addition, a simhash and basic information based function filtering is proposed to dramatically reduce the irrelevant target functions. Besides, we introduce a partial trace method for matching the shortlisted function accurately. The experimental results show that our method can find similar functions, even with the presence of program structure distortion, in a scalable manner.
Yunan Zhang 0002, Aidong Xu, Yixin Jiang
TrustCom3
2020 A P2P network based edge computing smart grid model for efficient resources coordination
Wenjing Hou, Yixin Jiang, Wenxin Lei, Aidong Xu, Hong Wen 0001, Songling Chen
Peer-to-Peer Netw. Appl.2
2019 Analysis of the physical layer security enhancing of wireless communication system under the random mobile
abstract
User mobility is a major feature of wireless networks. At present, physical layer security research rarely considers the impact of user mobility on the physical layer security performance in the network. In this study, the authors propose a random mobile user physical layer security model and study the impact of random waypoint movement users on the security performance of the physical layer in wireless networks, in which an artificial noise security scheme under the multi‐antenna transmission model is considered. They derive the closed expression of positive secrecy capacity probability and secrecy outage probability under this model. The results prove that system security is enhanced because of the users’ mobility.
Tengyue Zhang 0002, Hong Wen 0001, Jie Tang 0005, Huanhuan Song 0001, Runfa Liao, Yixin Jiang
IET Commun.7
2019 A Modified Hierarchical Attribute-Based Encryption Access Control Method for Mobile Cloud Computing
abstract
Cloud computing is an Internet-based computing pattern through which shared resources are provided to devices on-demand. It is an emerging but promising paradigm to integrating mobile devices into cloud computing, and the integration performs in the cloud based hierarchical multi-user data-shared environment. With integrating into cloud computing, security issues such as data confidentiality and user authority may arise in the mobile cloud computing system, and it is concerned as the main constraints to the developments of mobile cloud computing. In order to provide safe and secure operation, a hierarchical access control method using modified hierarchical attribute-based encryption (M-HABE) and a modified three-layer structure is proposed in this paper. In a specific mobile cloud computing model, enormous data which may be from all kinds of mobile devices, such as smart phones, functioned phones and PDAs and so on can be controlled and monitored by the system, and the data can be sensitive to unauthorized third party and constraint to legal users as well. The novel scheme mainly focuses on the data processing, storing and accessing, which is designed to ensure the users with legal authorities to get corresponding classified data and to restrict illegal users and unauthorized legal users get access to the data, which makes it extremely suitable for the mobile cloud computing paradigms.
Yuanpeng Xie, Hong Wen 0001, Bin Wu 0002, Yixin Jiang, Jiaxiao Meng
IEEE Trans. Cloud Comput.4
2017 Cooperative Jamming Aided Secrecy Enhancement in Wireless Networks with Multiple Eavesdroppers
abstract
In this paper, we investigate cooperative security in wireless networks, where a source (Alice) intends to transmit a confidential message to a legitimate destination (Bob), with the help of a cooperative node (Charlie), in the presence of multiple independent eavesdroppers (Eves). In particular, cooperative jamming (CJ) is explored to enhance secure communication between Alice and Bob. We provide a transmit design to maximize the secrecy rate, subject to a secrecy outage probability (SOP) constraint. Specifically, we establish a condition under which positive secrecy rate can be guaranteed. In addition to secrecy rate performance, we also pay attention to the secure energy efficiency, defined as the ratio of secrecy rate to total power consumption. Numerical results validate the effectiveness and energy efficiency of our proposed CJ scheme.
Lin Hu 0002, Hong Wen 0001, Bin Wu 0002, Jie Tang 0005, Zhengguang Zhang 0001, Yixin Jiang, Aidong Xu
VTC Fall7
2017 Physical Layer Security Assisted 5G Network Security
abstract
After 4G network becomes a global commercial success, the researchers are now looking at the future 5G technologies, both in standardization bodies and in research projects. Researchers find that the security architecture used in 4G can not satisfy the needs of 5G. Some researchers proposed a kind of unified network security architecture which we find it inflexible. In this paper, we will propose a more flexible hierarchical security architecture which can be adjusted to the needs of the application scenarios of 5G-eMBB, mMTC and URLLC. Under this architecture, we will introduce a cross-layer light weight authentication scheme and a novel physical layer security assisted encryption scheme which is based on both the key streams and the channel information in f-OFDM system.
Yixin Jiang, Hong Wen 0001, Runfa Liao, Aidong Xu
VTC Fall2
2015 Three-Layers Secure Access Control for Cloud-Based Smart Grids
abstract
Cloud computing is an Internet-based computing paradigm which may share resources to provide on-demand services to devices. Integrating smart grid into cloud computing is emerging and promising, and this integration may execute in the cloud based hierarchical multi-user data-shared environment, where security issues such as data confidentiality and manager authority may arise in the smart grid system. In order to provide safe and secure grid operations, a hierarchical access control method using modified hierarchical attribute-based encryption (M-HABE) and a modified three layers structure are proposed in this paper. In power grids, the system can be controlled and monitored by the enormous sensitive data which may be from sensor nodes, smart measurement units and soon on. The novel scheme mainly focus on the data process, storage and access to ensure the managers with legal authorities to get corresponding sensitive data and restrict illegal managers and unauthorized legal managers from accessing the data.
Yuanpeng Xie, Hong Wen 0001, Jinsong Wu 0001, Yixin Jiang, Jiaxiao Meng, Xiaobin Guo, Aidong Xu, Zewu Guan
VTC Fall4
2014 A tentative comparison on CDN and NDN
abstract
With the pretty prompt growth in Internet content, future Internet is emerging as the main usage shifting from traditional host-to-host model to content dissemination model, e.g. video makes up more than half of Internet traffic. ISPs, content providers and other third parties have widely deployed content delivery networks (CDNs) to support digital content distribution. Though CDN is an ad-hoc solution to the content dissemination problem, there are still big challenges, such as complicated control plane. By contrast, as a wholly new designed network architecture, named data networking (NDN) incorporates content delivery function in its network layer, its stateful routing and forwarding plane can effectively detect and adapt to the dynamic and ever-changing Internet. In this paper, we try to explore the similarities and differences between CDN and NDN. Hence, we evaluate the distribution efficiency, network security and protocol overhead between CDN and NDN. Especially in the implementation phase, we conduct their testbeds separately with the same topology to derive their performance of content delivery. Finally, summarizing our main results, we gather that: 1) NDN has its own advantage on lots of aspects, including security, scalability and quality of service (QoS); 2) NDN make full use of surrounding resources and is more adaptive to the dynamic and ever-changing Internet; 3) though CDN is a commercial and mature architecture, in some scenarios, NDN can perform better than CDN under the same topology and caching storage. In a word, NDN is practical to play an even greater role in the evolution of the Internet based on the massive distribution and retrieval in the future.
Ge Ma, Zhen Chen 0001, Zhenhua Guo 0001, Yixin Jiang, Xiaobin Guo
SMC5
2014 BreadZip: a combination of network traffic data and bitmap index encoding algorithm
abstract
Nowadays, rapid evolution of computers and mobile devices has caused the explosive increase in network traffic. So it becomes more and more necessary to archive network traffic for analyzing network events and a lot of emerging applications. Compression is fundamental for traffic archival solution to save the storage space, and indexing is effective to accelerate search queries for archive of traffic data. In this paper, we propose BreadZip (blocks row-reordering and adaptive index zip), a combination of initial traffic data and index compression. BreadZip has three main advantages. 1) to improve compressing efficiency and reduce memory footprint, traffic data is reordered in sequence and divided into fixed-size blocks; 2) to accelerate queries, an improved bitmap indexes with smaller volume than traditional will be introduced; 3) to save space, both traffic blocks and bitmap indexes are compressed in different simple run-length encoding methods respectively. Finally, our empirical results on network traffic from CAIDA (Cooperative Association for Internet Data Analysis) show that our solution can significantly reduce the volume of traffic data, while simultaneously preserving the ability to perform selectively queries with response times in seconds.
Ge Ma, Zhenhua Guo 0001, Xiu Li 0001, Zhen Chen 0001, Yixin Jiang, Xiaobin Guo
SMC6
2014 A Lightweight Encryption Scheme for Network-Coded Mobile Ad Hoc Networks
abstract
Energy saving is an important issue in Mobile Ad Hoc Networks (MANETs). Recent studies show that network coding can help reduce the energy consumption in MANETs by using less transmissions. However, apart from transmission cost, there are other sources of energy consumption, e.g., data encryption/decryption. In this paper, we study how to leverage network coding to reduce the energy consumed by data encryption in MANETs. It is interesting that network coding has a nice property of intrinsic security, based on which encryption can be done quite efficiently. To this end, we propose P-Coding, a lightweight encryption scheme to provide confidentiality for network-coded MANETs in an energy-efficient way. The basic idea of P-Coding is to let the source randomly permute the symbols of each packet (which is prefixed with its coding vector), before performing network coding operations. Without knowing the permutation, eavesdroppers cannot locate coding vectors for correct decoding, and thus cannot obtain any meaningful information. We demonstrate that due to its lightweight nature, P-Coding incurs minimal energy consumption compared to other encryption schemes.
Peng Zhang 0011, Chuang Lin 0002, Yixin Jiang, Yanfei Fan, Xuemin Shen
IEEE Trans. Parallel Distributed Syst.3
2012 Enforcing scalable and dynamic hierarchical access control in cloud computing
abstract
In cloud computing, the sensitive data are required to be encrypted before being outsourced to the server, which introduce a heavy computation overhead for key derivation and data management when dynamic hierarchical access control is desired. In this paper, we address this challenging problem by delegating the computation intensive task, such as data re-encryption, key distribution and derivation to cloud servers. Only bilinear pairing and random padding are used in our construction. Extensive analysis shows that the proposed scheme achieves scalability and dynamic simultaneously, and is proved to be secure formally.
Chuang Lin 0002, Yixin Jiang
ICC3
2012 ANOC: Anonymous Network-Coding-Based Communication with Efficient Cooperation
abstract
Practical wireless network coding (e.g., COPE) is a promising technique that can enhance the throughput of wireless networks. However, such a technique also bears a serious security drawback: it breaks the current privacy-preserving protocols (e.g., Onion Routing), since their operations conflict each other. As user privacy in wireless networks is highly valued nowadays, a new privacy-preserving scheme that can function with wireless network coding becomes indispensable. To address such a challenge, we apply the idea of cooperative networking and design a novel anonymity scheme named ANOC, which can function in network-coding-based wireless mesh networks. ANOC is built upon the classic Onion Routing protocol, and resolves its conflict with network coding by introducing efficient cooperation among relay nodes. Using ANOC, we can perform network coding to achieve a higher throughput, while still preserving user privacy in wireless mesh networks. We formally show how ANOC achieves the property of relationship anonymity, and conduct extensive experiments via nsclick to demonstrates its feasibility and efficiency when integrated with network coding.
Peng Zhang 0011, Chuang Lin 0002, Yixin Jiang, Patrick P. C. Lee, John C. S. Lui
IEEE J. Sel. Areas Commun.3
2012 A Distributed Fault/Intrusion-Tolerant Sensor Data Storage Scheme Based on Network Coding and Homomorphic Fingerprinting
abstract
Recently, distributed data storage has gained increasing popularity for reliable access to data through redundancy spread over unreliable nodes in wireless sensor networks (WSNs). However, without any protection to guarantee the data integrity and availability, the reliable data storage cannot be achieved since sensor nodes are prone to various failures, and attackers may compromise sensor nodes to pollute or destroy the stored data. Therefore, how to design a robust sensor data storage scheme to efficiently guarantee the data integrity and availability becomes a critical issue for distributed sensor storage networks. In this paper, we propose a distributed fault/intrusion-tolerant data storage scheme based on network coding and homomorphic fingerprinting in volatile WSNs environments. For high data availability, the proposed scheme uses network coding to encode the source data and distribute encoded fragments with original data pieces. With secure, compact, and efficient homomorphic fingerprinting, our scheme can fast locate incorrect fragments and then initialize data maintenance. Extensive theoretical analysis and simulative results demonstrate the efficacy and efficiency of the proposed scheme.
Rongfei Zeng, Yixin Jiang, Chuang Lin 0002, Yanfei Fan, Xuemin Shen
IEEE Trans. Parallel Distributed Syst.2
2012 Dependability Analysis of Control Center Networks in Smart Grid Using Stochastic Petri Nets
abstract
As an indispensable infrastructure for the future life, smart grid is being implemented to save energy, reduce costs, and increase reliability. In smart grid, control center networks have attracted a great deal of attention, because their security and dependability issues are critical to the entire smart grid. Several studies have been conducted in the field of smart grid security, but few work focuses on the dependability analysis of control center networks. In this paper, we adopt a concise mathematic tool, stochastic Petri nets (SPNs), to analyze the dependability of control center networks in smart grid. We present the general model of control center networks by considering different backup strategies of critical components. With the general SPNs model, we can measure the dependability from two metrics, i.e., the reliability and availability, through analyzing the transient and steady-state probabilities simultaneously. To avoid the state-space explosion problem in computing, the state-space explosion avoidance method is proposed as well. Finally, we study a specific case to demonstrate the feasibility and efficiency of the proposed model in the dependability analysis of control center networks in smart grid.
Rongfei Zeng, Yixin Jiang, Chuang Lin 0002, Xuemin Shen
IEEE Trans. Parallel Distributed Syst.2
2011 An Authorization Model without Central Authority for Service Collaboration
abstract
In the service-oriented computing, a single transaction initiated by a client might invoke many different services in other administrative domains. Existing models for authorizing the access assume that all services involved in collaboration are managed by the central authority, which is not always a realistic premise. In this paper, we propose a novel authorization model for dynamic service collaboration. With the authorization discovery process, the client can discover the needed authorization for service access available in other autonomous domains. With extensions to SoD relationship, the conflicts of client interests can be formalized and expressed as constraints. The authorization problems are formalized to choose the optimal access path for each task. At last, the example and experiments show the practicality and the effectiveness of our scheme.
Chuang Lin 0002, Yixin Jiang, Xiaowen Chu 0001
GLOBECOM3
2011 Trust Based Access Control in Infrastructure-Centric Environment
abstract
The rapid development of applications running on global information infrastructure poses the problem of securing information sharing among domain collaborations. Existing access control models are defective in dynamic authorization based on user's trustworthiness and do not take full advantages of the infrastructure in implementing access control system. In this work, we propose a trust and role based access control model and the corresponding framework in infrastructure-centric environment. With the extension to RBAC model, trust level requirements, which dictate that the roles in the privilege context must be activated by the trustworthy user, can be specified. The comprehensive trust model, which calculates the user's trust level in multiple trust contexts based on behavior histories, is proposed. Moreover, by taking advantages of the infrastructure services, our scheme is flexible and scalable in that system administrators are free to choose custom scoring functions while the infrastructure trust evaluation services are relieved of the heavy burdens of history record maintenance and trust level update.
Chuang Lin 0002, Yixin Jiang, Xiaowen Chu 0001
ICC3
2011 Padding for orthogonality: Efficient subspace authentication for network coding
abstract
Network coding provides a promising alternative to traditional store-and-forward transmission paradigm. However, due to its information-mixing nature, network coding is notoriously susceptible to pollution attacks: a single polluted packet can end up corrupting bunches of good ones. Existing authentication mechanisms either incur high computation/bandwidth overheads, or cannot resist the tag pollution proposed recently. This paper presents a novel idea termed “padding for orthogonality” for network coding authentication. Inspired by it, we design a public-key based signature scheme and a symmetric-key based MAC scheme, which can both effectively contain pollution attacks at forwarders. In particular, we combine them to propose a unified scheme termed MacSig, the first hybrid-key cryptographic approach to network coding authentication. It can thwart both normal pollution and tag pollution attacks in an efficient way. Simulative results show that our MacSig scheme has a low bandwidth overhead, and a verification process 2–4 times faster than typical signature-based solutions in some circumstances.
Peng Zhang 0011, Yixin Jiang, Chuang Lin 0002, Hongyi Yao, Albert Wasef, Xuemin Shen
INFOCOM2
2011 A scalable and robust key pre-distribution scheme with network coding for sensor data storage
Rongfei Zeng, Yixin Jiang, Chuang Lin 0002, Yanfei Fan, Xuemin Shen
Comput. Networks2
2011 Efficient dynamic task scheduling in virtualized data centers with fuzzy prediction
Chuang Lin 0002, Yixin Jiang, Xiaowen Chu 0001
J. Netw. Comput. Appl.3
2011 Network Coding Based Privacy Preservation against Traffic Analysis in Multi-Hop Wireless Networks
abstract
Privacy threat is one of the critical issues in multi-hop wireless networks, where attacks such as traffic analysis and flow tracing can be easily launched by a malicious adversary due to the open wireless medium. Network coding has the potential to thwart these attacks since the coding/mixing operation is encouraged at intermediate nodes. However, the simple deployment of network coding cannot achieve the goal once enough packets are collected by the adversaries. On the other hand, the coding/mixing nature precludes the feasibility of employing the existing privacy-preserving techniques, such as Onion Routing. In this paper, we propose a novel network coding based privacy-preserving scheme against traffic analysis in multi-hop wireless networks. With homomorphic encryption on Global Encoding Vectors (GEVs), the proposed scheme offers two significant privacy-preserving features, packet flow untraceability and message content confidentiality, for efficiently thwarting the traffic analysis attacks. Moreover, the proposed scheme keeps the random coding feature, and each sink can recover the source packets by inverting the GEVs with a very high probability. Theoretical analysis and simulative evaluation demonstrate the validity and efficiency of the proposed scheme.
Yanfei Fan, Yixin Jiang, Haojin Zhu, Jiming Chen 0001, Xuemin Shen
IEEE Trans. Wirel. Commun.2
2010 An Efficient Privacy-Preserving Publish-Subscribe Service Scheme for Cloud Computing
abstract
Cloud computing provides a novel computing paradigm for enterprises to store programs and data in the Cloud in a transparent manner, which poses the challenge of security and privacy. In this paper, based on homomorphic cryptography and Zero-Knowledge Proof, we present a novel privacy-preserving scheme for Cloud publish/subscribe service, which achieve efficient privacy-preserving authentication, data integrity, and publish-subscribe confidentiality. The performance evaluation and security analysis demonstrate the practice and validity of the proposed scheme.
Yanping Xiao, Chuang Lin 0002, Yixin Jiang, Xiaowen Chu 0001, Fangqin Liu
GLOBECOM3
2010 Performance Analysis of Data Management in Sensor Data Storage via Stochastic Petri Nets
abstract
Recently, sensor data storage has gained increasing popularity for reliable access to data through redundancy spread over unreliable nodes in wireless sensor networks. In storage-centric sensor networks, several schemes have been proposed to optimize the performance of data management in terms of data availability, repair bandwidth, etc. However, few works have been undertaken to study the performance of these data management schemes from a comprehensive point of view. In this paper, we adopt a concise graphic model, i.e., Stochastic Petri Nets (SPNs), to analyze the performance of three representative data management schemes. From the steady state probability matrix of the SPNs models, we can easily get the average energy consumption, repair bandwidth, reliability and data availability. Based on numerical results, we provide guidelines for designing sensor data storage systems. The results also demonstrate that our proposed models are suitable for analyzing data management schemes in sensor data storage.
Rongfei Zeng, Chuang Lin 0002, Yixin Jiang, Xiaowen Chu 0001, Fangqin Liu
GLOBECOM3
2010 An Efficient Recovery and Survival Scheme against Malware Attacks
abstract
Intricate malware can result in the failure of on-line Comprehensive Protection (CP) in distributed systems, and place the system in an unsafe state which is difficult to recover from. There lacks an effective scheme to defend against this extreme attack. In this paper, based on the Two-layer Protection and Cooperative Recovery (TPCRS) mechanism, we propose an efficient survivable scheme against malware attacks in distributed systems. The basic strategy is to deploy an Emergency Response/Recovery (ER) agent at each node to recognize the state of the system whenever the CP fails, and to carry out cooperative security among multiple nodes so that the infected nodes can be rapidly recovered. Furthermore, a Preventive Maintenance (PM) model is adopted to enhance the reliability of the distributed system. Simulation results demonstrate the practicality and efficiency of the proposed schemes.
Xianjun Sun, Chuang Lin 0002, Yixin Jiang, Weidong Liu 0001, Xiaowen Chu 0001
ICC3
2010 Reputation-Based QoS Provisioning in Cloud Computing via Dirichlet Multinomial Model
abstract
In Cloud computing, users with different service requirements often need to negotiate with service provider via Service Level Agreement (SLA). The unique pay-as-you-go billing way in Cloud computing challenges resource provisioning for service providers. In this paper, based on the Dirichlet multinomial model, we present an efficient reputation-based QoS provisioning scheme, which can minimize the cost of computing resources, while satisfying the desired QoS metrics. Unlike the previous counterparts, we consider the statistical probability of the response time as a practical metric rather than the typical mean response time. Numerical results show the efficiency and effectiveness of the proposed scheme.
Yanping Xiao, Chuang Lin 0002, Yixin Jiang, Xiaowen Chu 0001, Xuemin Shen
ICC3
2010 P-Coding: Secure Network Coding against Eavesdropping Attacks
abstract
Though providing an intrinsic secrecy, network coding is still vulnerable to eavesdropping attacks, by which an adversary may compromise the confidentiality of message content. Existing studies mainly deal with eavesdroppers that can intercept a lim-ited number of packets. However, real scenarios often consist of more capable adversaries, e.g., global eavesdroppers, which can defeat these techniques. In this paper, we propose P-Coding, a novel security scheme against eavesdropping attacks in network coding. With the lightweight permutation encryption performed on each message and its coding vector, P-Coding can efficiently thwart global eavesdroppers in a transparent way. Moreover, P-Coding is also featured in scalability and robustness, which enable it to be integrated into practical network coded systems. Security analysis and simulation results demonstrate the efficacy and efficiency of the P-Coding scheme.
Peng Zhang 0011, Yixin Jiang, Chuang Lin 0002, Yanfei Fan, Xuemin Shen
INFOCOM2
2010 Measurements, analysis and modeling of private tracker sites
abstract
BitTorrent plays a very important role in the current Internet content distribution. When BitTorrent public tracker sites are suffering from free-riding problem, private tracker sites (PTs) work very well because of Share Ratio Enforcement (SRE) which is an auxiliary effective incentive mechanism. Understanding PTs is essential to content distribution. We have crawled and traced 15 tracker sites with over 3.5 million torrents for 7 months. We first provide taxonomy of PTs, and then present measurement study on the characteristics of PTs from the user viscosity, torrents evolution, user behaviors, and content distribution. Some of the features are apparently different from public trackers. Furthermore, we analyze SRE mechanism and auxiliary credit system, and use game theory to study effectiveness of SRE mechanism. There exists “uploading starvation” phenomenon in private trackers. We model SRE mechanism and propose an improved SRE mechanism to further incent the users and enhance the performance of private trackers.
Xiaowei Chen 0001, Xiaowen Chu 0001, Yixin Jiang, Fengyuan Ren
IWQoS3
2010 Measurements, Analysis and Modeling of Private Trackers
abstract
BitTorrent plays a very important role in the current Internet content distribution. The enormous impact of public and private trackers should not be overlooked. Public trackers are suffering from free-riding problem, but private trackers are becoming more and more popular and they run very well in terms of an effective Share Ratio Enforcement (SRE) which is an auxiliary incentive mechanism. In this paper, we have crawled and traced 15 trackers with 3.5 million torrents for over 6 months. We first provide taxonomy of private trackers, and then present in breadth and depth measurement from the user viscosity, torrents evolution, user behaviors, content distribution and other metrics. Some features are apparently different from public trackers. Furthermore, we analyze SRE mechanism and point/credit system, and use game theory to study the effectiveness of SRE. There exists "uploading starvation" phenomenon in private trackers. We model SRE mechanism and preliminary propose an improved SRE mechanism to further incent users and enhance the performance of private trackers.
Xiaowei Chen 0001, Yixin Jiang, Xiaowen Chu 0001
Peer-to-Peer Computing2
2010 An efficient dynamic-identity based signature scheme for secure network coding
Yixin Jiang, Haojin Zhu, Minghui Shi, Xuemin Shen, Chuang Lin 0002
Comput. Networks1
2010 Providing key recovery capability for mobile communications
abstract
Abstract In this paper, we propose a novel security scheme with key recovery capability for mobile communications. The proposed key recovery mechanism offers a “backdoor” for an authorized agency to monitor suspected communications while protecting legal users from unauthorized disclosure of their data privacy. All the features form a unitary security scheme with monitoring service. The performance analysis shows that our scheme has a low‐computational complexity and it can be practically deployed on contemporary mobile devices. Copyright © 2009 John Wiley & Sons, Ltd.
Xiaowen Chu 0001, Yixin Jiang, Chuang Lin 0002, Bo Li 0001
Secur. Commun. Networks2
2010 PIE: cooperative peer-to-peer information exchange in network coding enabled wireless networks
abstract
In this paper, we study the issue of scheduling transmission opportunities among nodes (peers) to achieve higher network throughput and lower transmission delay for network coding enabled wireless networks. By conducting an in-depth investigation on the scheduling principles, we propose a cooperative Peer-to-peer Information Exchange (PIE) scheme with an efficient and light-weight scheduling algorithm. PIE can not only fully exploit the broadcast nature of wireless channels, but also take advantage of cooperative peer-to-peer information exchange. Qualitative analysis and extensive simulations demonstrate the effectiveness and efficiency of PIE.
Yanfei Fan, Yixin Jiang, Haojin Zhu, Xuemin Shen
IEEE Trans. Wirel. Commun.2
2009 Cooperative Peer-to-Peer Information Exchange via Wireless Network Coding
abstract
Network coding has been widely recognized as a promising information dissemination approach for wireless networks. However, in practical wireless networks enabled with network coding, different peer sending sequences make significant impact on overall network throughput and transmission delay. In this paper, we study the peer scheduling problem, which is defined as how to intelligently schedule the sending sequence among a group of peers to maximize the wireless coding gain. By conducting an in-depth investigation on the peer scheduling principles in wireless network coding, we propose a cooperative Peer-to-peer Information Exchange (PIE) scheme with an efficient and light-weight peer scheduling algorithm. The PIE scheme can not only fully exploit the broadcast nature of wireless channels, but also utilize the advantage of cooperative peer-to-peer information exchange. Finally, the effectiveness and efficiency of the PIE scheme are demonstrated through qualitative analysis and extensive simulations.
Yanfei Fan, Yixin Jiang, Haojin Zhu, Xuemin Shen
GLOBECOM2
2009 An Effective Early Warning Scheme against Pollution Dissemination for BitTorrent
abstract
BitTorrent is one of the most popular P2P file sharing systems. However, chunk-based file sharing mode makes it difficult to detect content pollution and prevent pollution dissemination during downloading process. In this paper, we propose an early warning scheme against pollution dissemination for BitTorrent. Our idea is to build an early cooperative warning mechanism and rapidly spread alert message among peers in the swarm when pollution is detected at the early stage, which is called "early warning, quickly reacting". The performance evaluation based on fluid model shows the necessity and effectiveness of our scheme, which effectively reduces the traffic abusement and restricts pollution dissemination in BitTorrent-like P2P networks. Another advantage of our solution is that it can handle cheating behaviors made by malicious or unconscious peers, which shows the robustness of our solution.
An'an Luo, Chuang Lin 0002, Yixin Jiang, Xiaowen Chu 0001, Hongkun Yang
GLOBECOM3
2009 Speeding Up Homomorpic Hashing Using GPUs
abstract
Homomorphic hash functions (HHFs) have been applied into peer-to-peer networks with erasure coding or network coding to defend against pollution attacks. Unfortunately HHFs are computationally expensive for contemporary CPUs, This paper to exploit the computing power of graphic processing units (GPUs) for homomorphic hashing. Specifically, we demonstrate how to use NVIDIA GPUs and the computer unified device architecture (CUDA) programming model to achieve 38 times of speedup over the CPU counterpart. We also develop a multi-precision modular arithmetic library on CUDA platform, which is not only key to our specific application, but also very useful for a large number of cryptographic applications.
Kaiyong Zhao, Xiaowen Chu 0001, Mea Wang, Yixin Jiang
ICC4
2009 An Efficient Privacy-Preserving Scheme against Traffic Analysis Attacks in Network Coding
abstract
Privacy threat is one of the critical issues in network coding, where attacks such as traffic analysis can be easily launched by a malicious adversary once enough encoded packets are collected. Furthermore, the encoding/mixing nature of network coding precludes the feasibility of employing the existing privacy-preserving techniques, such as Onion routing, in network coding enabled networks. In this paper, we propose a novel privacy-preserving scheme against traffic analysis in network coding. With homomorphic encryption operation on global encoding vectors (GEVs), the proposed scheme offers two significant privacy-preserving features, packet flow untraceability and message content confidentiality, for efficiently thwarting the traffic analysis attacks. Moreover, the proposed scheme keeps the random coding feature, and each sink can recover the source packets by inverting the GEVs with a very high probability. Theoretical analysis and simulative evaluation demonstrate the validity and efficiency of the proposed scheme.
Yanfei Fan, Yixin Jiang, Haojin Zhu, Xuemin Shen
INFOCOM2
2009 ELCP: An Effort-Based Least Cost Path Scheme for MANETs
abstract
To weaken the selfish behavior of nodes in mobile ad hoc networks, many payment-based incentive schemes have been proposed recently, yet it is still far from achieving the expected efficiency to encourage node cooperation. In these schemes, source node selects a Least Cost Routing (LCP) for data transmission according to the forwarding cost reported by intermediate nodes and rewards them with some virtual money before or after successful packet forwarding. However, as a result of information asymmetry between source and relay nodes, nodes on LCP may degrade their efforts promised in the previous routing discovery stage if there is no enough motivation for them to work hard, which exercises a negative influence on the forwarding efficiency of LCP schemes. Therefore, the actual transmission efforts of intermediate nodes must be considered by the source node in the processes of route selecting and packet forwarding. In this paper, with adoption of principal-agent theory of economics, we propose a novel LCP scheme (ELCP) based on the intermediate nodes' effort to stimulate nodes cooperation, in which both source and relay nodes can maximize their profits and ensure routing efficiency simultaneously.
Chuang Lin 0002, Yixin Jiang, Yuanzhuo Wang, Zhen Chen 0001
MSN3
2009 A self-adaptive probabilistic packet filtering scheme against entropy attacks in network coding
Yixin Jiang, Yanfei Fan, Xuemin Shen, Chuang Lin 0002
Comput. Networks1
2009 BAT: A robust signature scheme for vehicular networks using Binary Authentication Tree
abstract
In this paper, we propose a robust and efficient signature scheme for vehicle-to-infrastructure communications, called binary authentication tree (BAT). The BAT scheme can effectively eliminate the performance bottleneck when verifying a mass of signatures within a rigorously required interval, even under adverse scenarios with bogus messages. Given any n received messages with k ges 1 bogus ones, the computation cost to verify all these messages only requires approximately (k + 1) ldr log(n/k) + 4k - 2 time-consuming pairing operations. The BAT scheme can also be gracefully transplanted to other similar batch signature schemes. In addition, it offers the other conventional security for vehicular networks, such as identity privacy and traceability. Theoretical analysis and simulation results demonstrate the validity and practicality of the BAT scheme.
Yixin Jiang, Minghui Shi, Xuemin Shen, Chuang Lin 0002
IEEE Trans. Wirel. Commun.1
2009 Homonymous role in role-based discretionary access control
abstract
Abstract The access control model is a core aspect of trusted information systems. Based on the role based access control (RBAC) model, we put forward the concept of thehomonymous role, which extends the role control categories in RBAC, balances the control granularity and the storage space requirements, and executes the fine‐grained access control. Instead of the traditional global access control policies (GACP), we propose thehomonymous control domain(HCD) mechanism to enable the coexistence of multiple types of access control policies in a single system, thereby improving the control granularity and flexibility. The HCD mechanism facilitates the discretionary supporting of independent access control policies for its homonymous user. The HCD mechanism and the traditional access control mechanism can be linked to construct a two‐layer access control policy mechanism for a system. Notably, we also consider the temporal characteristic in HCD, which is a critical feature of modern access control models. Furthermore, we analyze the conflicts between the HCD and GACP mechanisms. Finally, we design and implement our HCD on FreeBSD to demonstrate the advantages of the two‐layer access control mechanism. Copyright © 2008 John Wiley & Sons, Ltd.
Xiaowen Chu 0001, Kai Ouyang, Hsiao-Hwa Chen, Jiangchuan Liu, Yixin Jiang
Wirel. Commun. Mob. Comput.5
2008 An Efficient Privacy-Preserving Scheme for Wireless Link Layer Security
abstract
In this paper, we propose an efficient privacy-preserving scheme for secure packet transmission at wireless link layer. The proposed scheme is constructed by using hash values in reverse hash chains as interface identifiers. It can successfully and efficiently resist the Media Access Control (MAC) address based attacks, such as flow tracking and traffic analysis, which are launched by either outside or even inside attackers. In addition, some optimization techniques are also introduced to further improve the efficiency of the proposed scheme. The extensive analysis and simulations demonstrate the enhanced security and efficiency of the proposed scheme.
Yanfei Fan, Bin Lin 0001, Yixin Jiang, Xuemin Shen
GLOBECOM3
2008 A Tree-Based Signature Scheme for VANETs
abstract
In this paper, we propose a robust and efficient signature scheme for vehicle-to-infrastructure communications, which can effectively eliminate the performance bottleneck when verifying a mass of signatures within a rigorously required interval, even under adverse scenarios with bogus messages. In addition, our scheme offers the other conventional security features for vehicular networks, such as identity privacy and traceability.
Yixin Jiang, Minghui Shi, Xuemin Shen, Chuang Lin 0002
GLOBECOM1
2008 ECMV: Efficient Certificate Management Scheme for Vehicular Networks
abstract
In this paper, we propose an Efficient Certificate Management scheme for Vehicular networks (ECMV). The proposed scheme offers a flexible interoperability for certificate management in different administrative authorities, and an efficient way for any On-Board Units (OBUs) to update its certificate anywhere at anytime. In addition, an efficient time-limited certificate revocation for OBUs is introduced. It is demonstrated that the ECMV scheme can decrease the complexity of certificate management, and achieves excellent security and efficiency for vehicular communications.
Albert Wasef, Yixin Jiang, Xuemin Shen
GLOBECOM2
2008 Efficient Re-Keying Scheme for Group Key Distribution
abstract
In this paper, we propose a communication-efficient re-keying scheme by using a polynomial-based efficient code method. Compared with the previous schemes, the re-keying cost is significantly reduced, since no extra re-keying message header is needed. In addition, the computation overhead is also lightweight since only 2logn hash operations are required for each re-keying. Therefore, the proposed scheme is more suitable for deploying in the group application scenarios with both high dynamic memberships and limited communication channel capacity.
Yixin Jiang, Minghui Shi, Xuemin Shen, Chuang Lin 0002
WCNC1
2008 User authentication and undeniable billing support for agent-based roaming service in WLAN/cellular integrated mobile networks
Minghui Shi, Xuemin Shen, Jon W. Mark, Dongmei Zhao, Yixin Jiang
Comput. Networks5
2008 A mutual authentication and privacy mechanism for WLAN security
abstract
Abstract IEEE 802.11 wireless local area networks (WLAN) has been increasingly deployed in various locations because of the convenience of wireless communication and decreasing costs of the underlying technology. However, the existing security mechanisms in wireless communication are vulnerable to be attacked and seriously threat the data authentication and confidentiality. In this paper, we mainly focus on two issues. First, the vulnerabilities of security protocols specified in IEEE 802.11 and 802.1X standards are analyzed in detail. Second, a new mutual authentication and privacy scheme for WLAN is proposed to address these security issues. The proposed scheme improves the security mechanisms of IEEE 802.11 and 802.1X by providing a mandatory mutual authentication mechanism between mobile station and access point (AP) based on public key infrastructure (PKI), offering data integrity check and improving data confidentiality with symmetric cipher block chain (CBC) encryption. In addition, this scheme also provides some other new security mechanisms, such as dynamic session key negotiation and multicast key notification. Hence, with these new security mechanisms, it should be much more secure than the original security scheme. Copyright © 2006 John Wiley & Sons, Ltd.
Yixin Jiang, Chuang Lin 0002, Zhen Chen 0001
Wirel. Commun. Mob. Comput.1
2007 On the Homonymous Role in Role-Based Discretionary Access Control
Kai Ouyang, Xiaowen Chu 0001, Yixin Jiang, Hsiao-Hwa Chen, Jiangchuan Liu
ATC3
2007 Self-healing group key distribution with time-limited node revocation for wireless sensor networks
Yixin Jiang, Chuang Lin 0002, Minghui Shi, Xuemin Shen
Ad Hoc Networks1
2007 A DoS and fault-tolerant authentication protocol for group communications in ad hoc networks
Yixin Jiang, Chuang Lin 0002, Minghui Shi, Xuemin Shen, Xiaowen Chu 0001
Comput. Commun.1
2006 Self-certified Mutual Authentication and Key Exchange Protocol for Roaming Services
Xiaowen Chu 0001, Yixin Jiang, Chuang Lin 0002, Fujun Feng
ATC2
2006 AntiWorm NPU-based Parallel Bloom filters in Giga-Ethernet LAN
abstract
In this paper, an AntiWorm system based on the Intel IXP Network Processor was implemented using the Parallel Bloom filters technique. The AntiWorm system consists of two components: Bloom filters and Exact Matching engines. The Parallel Bloom filters can identify the suspicious traffic quickly and effectively, and then dispatch them to Exact Matching engines for further investigation. Both the principles and the implementation of the AntiWorm system are introduced in detail. With the consideration of the system performance parameters, two feasible implementation solutions are investigated and the advantages and disadvantages are also compared. The selections of configuration parameters of the AntiWorm system are also discussed. A hash scheme based on MD5's function is proposed for implementing fast hash functions. To test the performance of the AntiWorm system, such as throughput and delay, some experiments are carried out with different simulated traffic condition. The internal statistics of IXP network processor are also collected and analyzed for optimizing the system performance. To demonstrate the operation of the AntiWorm system, assaults by Worm Blaster are used in the test bed, and the experimental results prove the effectiveness of the AntiWorm system. The Software Package WormDetector1.0 is also provided as a software release from the research.
Zhen Chen 0001, Chuang Lin 0002, Jia Ni, Dong-Hua Ruan, Bo Zheng 0007, Zhangxi Tan, Yixin Jiang, Xuehai Peng, An'an Luo, Yao Yue, Yang Wang 0018, Peter D. Ungsunan, Fengyuan Ren
ICC7
2006 Multiple Key Sharing and Distribution Scheme With (n, t) Threshold for NEMO Group Communications
abstract
In this paper, a novel secure key sharing and distribution scheme for network mobility (NEMO) group communications is proposed. The scheme offers the capability of multiple key sharing and distribution for current and future application scenarios, and a threshold mechanism that effectively improves flexibility and robustness of the key sharing and distribution process. Both forward and backward secrecy are guaranteed by compulsive key refreshment and automatic key refreshment mechanisms, which provide dynamic in-progress group communication joining/leaving and periodic keys renewal, respectively. Security and performance analysis are presented to demonstrate that the proposed scheme meets the special security requirements for NEMO group communications and is competent for key sharing and distribution service.
Yixin Jiang, Chuang Lin 0002, Minghui Shi, Xuemin Shen
IEEE J. Sel. Areas Commun.1
2006 Mutual Authentication and Key Exchange Protocols for Roaming Services in Wireless Mobile Networks
abstract
Two novel mutual authentication and key exchange protocols with anonymity are proposed for different roaming scenarios in the global mobility network. The new features in the proposed protocols include identity anonymity and one-time session key renewal. Identity anonymity protects mobile users privacy in the roaming network environment. One-time session key progression frequently renews the session key for mobile users and reduces the risk of using a compromised session key to communicate with visited networks. It has demonstrated that the computation complexity of the proposed protocols is similar to the existing ones, while the security has been significantly improved.
Yixin Jiang, Chuang Lin 0002, Xuemin Shen, Minghui Shi
IEEE Trans. Wirel. Commun.1
2005 A self-encryption authentication protocol with identity anonymity for teleconference services
abstract
A novel authentication protocol for teleconference service is proposed. The main features of the proposed protocol include identity anonymity, one-time PID (pseudonym identity) renewal and location intractability. Identity anonymity is achieved by concealing the real identity of a mobile conferee in a prearranged pseudonym identity. One-time PID renewal mechanism, in which the mobile conferee's PID is frequently updated communicating with the network centre, is introduced to offer location intractability. It is shown that the security has been significantly enhanced, while the computation complexity is similar to the existing one appeared in the literature.
Yixin Jiang, Chuang Lin 0002, Minghui Shi, Xuemin Shen
GLOBECOM1
2005 AntiWorm NPU-based Parallel Bloom Filters for TCP/IP Content Processing in Giga-Ethernet LAN
abstract
TCP/IP protocol suite carries most application data in Internet. TCP flow retrieval has more security meanings than the IP packet payload. Hence, monitoring the TCP flow has more strength than only monitoring the IP packet payload in the AntiWorm system. The main idea of this paper is to use the flexibility and high performance of network processors to scan TCP flow for locating worm's binary codes, and cut off their propagation. A stateful TCP flow inspection engine is implemented based on IXP network processor, which can monitor about 512K flows. The performance issues about IXP network processors are evaluated and collected, and an analysis is made for further optimizing the system performance. The system is also demonstrated and proved by using the Internet traces and real assaults of Worms. Software Package TCPScanner 1.0 is also given as a software release of the research
Zhen Chen 0001, Chuang Lin 0002, Jia Ni, Dong-Hua Ruan, Bo Zheng 0007, Yixin Jiang
LCN6
2005 Mutual Authentication and Key Exchange Protocols with Anonymity Property for Roaming Services
Yixin Jiang, Chuang Lin 0002, Xuemin Shen, Minghui Shi
NETWORKING1
2003 An authentication model for multilevel security domains
abstract
A large network is composed of many autonomous security domains. Based on the definition of security domain, a lattice model of security domains is described. Subsequently, a model of multilevel security domains combined with the multilevel security is derived. Another important concept tied up with multilevel security domains is authentication. According to the trust relationships between different security domains, an authentication architecture and two authentication protocols suitable for multilevel security domains are proposed in this paper. At last, the authentication protocol is formally analyzed with the aid of the BAN logic.
Yixin Jiang, Chuang Lin 0002, Zhangxi Tan
SMC1
2003 Optimization and benchmark of cryptographic algorithms on network processors
abstract
With the increasing needs of security, cryptographic functions have been exploited in network devices. Besides time consuming, security protocols are flexible in algorithm selections. Fortunately, network processors, which serve as the backbone of intelligent network devices, hold performance and flexibility at the same time. In this article, we investigate several principles that can be used with implementing and optimizing cryptographic algorithms on network processors. Also, these principles are applied in real life algorithms, including stream ciphers, block ciphers and digital signatures. Related experiments and benchmark results on Intel IXP1200 network processor are provided.
Zhangxi Tan, Chuang Lin 0002, Yixin Jiang
SMC4