Shunfang Hu

dblp:264/4655 · DBLP profile ↗
← Back
7ranked-venue papers
2as first author
7since 2021 · last 2026
0000-0002-6772-5896ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 4 · 1 first-author · 4 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Security and privacy · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2026 Lightweight anonymous authentication and key agreement protocol resistant to desynchronization attacks
abstract
Abstract Wireless Medical Sensor Networks (WMSNs) are crucial for remote medical monitoring, yet they face significant challenges in terms of data security and privacy protection. Authentication and Key Agreement (AKA) protocols are effective technologies for safeguarding privacy; however, existing solutions often struggle to resist desynchronization attacks or sacrifice untraceability in the pursuit of anonymity. Additionally, the adoption of public-key cryptography substantially increases both computational and communication costs. To address these issues, this paper proposes a lightweight protocol based on the RD-UT List (Resistance to Desynchronization and Untraceability List) synchronization mechanism, which can resist desynchronization attacks and ensure untraceability. This mechanism functions by generating and periodically updating temporary identity credentials and hash chain values, ensuring reliable authentication and key agreement among users, servers, and sensor nodes. During data transmission, the mechanism not only achieves anonymity and untraceability but also effectively defends against desynchronization attacks. Compared with existing solutions, this protocol significantly improves both computational and communication efficiency: it reduces computational overhead by at least 65.01% and cuts communication costs by at least 22.22%. Its security has been fully validated through formal proofs and informal analysis. Furthermore, on an experimental platform simulating sensor nodes using Raspberry Pi 5, the protocol successfully achieves mutual authentication and session key agreement between users and sensors, verifying its practicality in resource-constrained WMSNs environments. In summary, this protocol provides an efficient and tailored solution for data protection in WMSNs environments.
Shenjin Wang, Shunfang Hu, Kaixuan Ma
Cybersecur.2
2026 Efficient and Secure-Enhanced Anonymous Authentication and Key Agreement Scheme for the Internet of Things
Shunfang Hu, Yuanyuan Zhang 0007, Liangyin Chen, Yanru Chen 0001
IEEE Internet Things J.1
2026 Blockchain and Certificate-Based Cross-Domain Authentication and Key Agreement Protocol for the Internet of Things
Mingyue Jiang, Guoding Duan, Jianzhou Zhao, Lanyu Ma, Shunfang Hu
IEEE Internet Things J.7
2026 LBCAK: A Lightweight Blockchain-Assisted Anonymous Cross-Domain Authentication and Key Agreement Scheme for the Industrial Internet
abstract
Secure authentication and key agreement across heterogeneous trust domains is essential for reliable collaboration in the Industrial Internet. However, existing cross-domain AKA schemes still face certificate-management overhead, key-escrow risk, insufficient identity privacy, and high computational cost. To address these issues, this paper proposes LBCAK, a lightweight blockchain-assisted anonymous cross-domain AKA scheme. LBCAK combines a certificateless-style key construction with AuthLedger-based public-state coordination, where the blockchain maintains current registration states for cross-domain credential validation while online authentication and session-key establishment remain off-chain. Credential-state-specific protected identifiers are further used to reduce on-chain linkability without exposing raw identities or private credential materials. Security is analyzed under an eCK-style leakage model in the random-oracle setting and further examined using ProVerif, showing that LBCAK provides mutual authentication, identity privacy, untraceability, forward secrecy, and resistance to major active and key-leakage attacks. Performance evaluation shows that LBCAK reduces computational and communication overheads by 14.3% and 4.2%, respectively, demonstrating its practicality for resource-constrained Industrial Internet deployments.
Wang Zhong, Shunfang Hu, Yuanyuan Zhang 0007, Liangyin Chen, Yanru Chen 0001
IEEE Internet Things J.2
2024 Digital Twin-Enabled Delay Diagnosis Traceability and Propagation Process for Airport Flight Ground Service
abstract
The emergence of digital twin technology offers a promising solution to address the limitations of traditional methods on early diagnosis and accurate propagation analysis of flight ground service delays. However, the application of digital twin technology in the civil aviation domain still stays at the lower maturity of the L2 level, which focuses on physical assets, operational data, and maintenance planning at airports, and failed to achieve the integration of flight ground operation mechanism and real‐time data, making it difficult to realize timely delay diagnosis. The simulation model is also limited to the offline simulation technology, which cannot connect to real‐time data for simulation from intermediate processes. In this work, we developed an advanced L3‐level airport digital twin system for flight ground service processes delay diagnosis and propagation, which focused on real‐time data‐driven simulation models and machine learning applications to meet the timely and precision requirements. First, we used the Unity3D platform to construct static three‐dimensional models of flight ground service objects on the airport cloud server. By parsing these behavioral state interfaces and mapping real‐time dynamic data from the airport sensing and business systems, we achieved accurate visualization of the airport’s dynamic operational processes. Then, a vehicle delay tree–based Bayesian diagnostic model was proposed in the digital twin system to analyze the relationships between multiple flights and service processes, which enables proactive diagnosis of the operation status and provides delay warning information. To improve the accuracy of propagation analysis, we proposed a “breakpoint” simulation method that enables real‐time simulation starting from an intermediate moment, facilitating the inference of flight ground service delays since the early warning moment. In addition, two delay tracing and propagation algorithms were proposed to identify delays and investigate propagation paths. Leveraging real‐time operational information, our approach provides valuable feedback for decision‐making, empowering the airport manager to formulate precise optimization strategies. Experiments on real‐world airport data have validated the effectiveness of our proposed method and provided practical recommendations for airport managers to reduce aircraft delays and improve airport operation efficiency.
Chang Liu 0087, Yuanyuan Zhang 0007, Yanru Chen 0001, Shijia Liu, Shunfang Hu, Liangyin Chen
Int. J. Intell. Syst.5
2023 ECC-Based Authenticated Key Agreement Protocol for Industrial Control System
abstract
Nowadays, Industrial Internet of Things (IIoT) technology has made a great progress and the industrial control systems (ICSs) have been used extensively, which has brought more and more serious information security threats to the ICS at the same time. The authenticated key agreement (AKA) protocol is a common method to ensure the communication security. This work proposes a lightweight AKA protocol based on the elliptic curve cryptography (ECC) algorithm to adapt to the resource-constrained environment. We only employ hash operation, XOR operation, and ECC algorithm to encrypt the data in the authentication and key agreement phase, and avoid involving the register center while proceeding the key agreement, to give consideration to both performance and security. The security analyses indicate that our protocol can meet nine critical security requirements, more than all of the existing protocols, and the performance analysis carried out indicates that our protocol has less computational and communication overheads in contrast to other corelative protocols.
Yanru Chen 0001, Fengming Yin, Shunfang Hu, Limin Sun 0001, Yang Li 0010, Liangyin Chen, Bing Guo 0003
IEEE Internet Things J.3
2023 Provably Secure ECC-Based Authentication and Key Agreement Scheme for Advanced Metering Infrastructure in the Smart Grid
abstract
Advanced metering infrastructure (AMI) is a vital component of the smart grid (SG) for real-time data access and bidirectional communication. An authentication and key agreement (AKA) protocol is needed for AMI systems to ensure the confidentiality and integrity of communication data. Since the devices are connected to the open network and generally deployed outdoors with limited computation, communication, and storage, designing a suitable AKA protocol is a challenging task. Researchers are still looking for good ways to make the SG secure and efficient simultaneously. To remedy the situation, in this article, we advance a security-enhanced elliptic-curve-cryptography-based AKA protocol, and the security has been proven rigorously under the random oracle model and verified with the ProVerif tool. Furthermore, performance comparison validates the proposed protocol in affording improved security features with lower computation and communication cost. In addition, the proposed scheme is implemented practically on a testbed, which is deployed usingRaspberry Pi 3 Model B+for smart meters.
Shunfang Hu, Yanru Chen 0001, Yilong Zheng, Yang Li 0010, Le Zhang 0004, Liangyin Chen
IEEE Trans. Ind. Informatics1