Meijia Xu

dblp:279/8535 · DBLP profile ↗
← Back
6ranked-venue papers
3as first author
5since 2021 · last 2026
0000-0002-7165-0292ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 2 · 1 first-author · 1 since 2021Security and privacy · 2 · 1 first-author · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Systems, architecture and hardware · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2026 Understanding Ephemeral Secret Leakage Attacks in Password-Based Multi-Factor Authentication for Mobile Devices
abstract
As the first defense for system security, multi-factor authentication has been deployed in various security-critical applications with mobile devices (e.g., smart grid, e-health, and Industrial Internet of Things). After three decades of intensive research, the question of how to design a secure multi-factor authentication protocol is still unsettled. In recent years, the ephemeral secret leakage (ESL) attack, originally used to cryptanalyze the authenticated key exchange (AKE) schemes, has been introduced into the field of multi-factor authentication. Considerable efforts have been made to resist the ESL attack, and it has also been listed as one of the common attacks that a secure multi-factor authentication scheme should resist. As one of the capabilities of an ESL attacker, she can obtain the ephemeral secret of public-key techniques adopted by multi-factor authentication schemes. However, public-key techniques have been proven indispensable for password-based protocols to resist offline password guessing attacks. Now a question arises:Is it possible to build a secure password-based multi-factor authentication protocol resistant to ESL attacks and offline password guessing attacks?This paper aims to answer this fundamental question. More specifically, we first revisit more than 100 multi-factor authentication schemes involving ESL attacks and present a comprehensive cryptanalysis of three representative protocols. Then, we reveal the relationship between ESL attacks and the failure of each representative protocol. mikablue Finally, we conduct a large-scale comprehensive comparative measurement of 41 multi-factor authentication schemes. Comparison results show thatallthese multi-factor authentication schemes considering ESL attacks do not perform better than those not. The above comprehensive approach leads to the key insight: ESL attacks areunsuitable/unrealisticfor evaluating password-based multi-factor authentication schemes because the leaked ephemeral secrets will lead to unavoidable offline password guessing attacks launched by ESL attackers, and the security of all these schemes would be compromised. We further conclude that employing hardware-protected devices (e.g., smart cards) as possession-based authentication factors can naturally resist ESL attacks, as the premise for ESL attackers to obtain ephemeral secrets is blocked. mikablue We believe our findings are general and also provide valuable guidance for defending against ESL attacks in multi-factor authentication protocols for non-mobile device environments as well.
Ding Wang 0002, Meijia Xu, Qingxuan Wang
IEEE Trans. Dependable Secur. Comput.2
2025 PQ3FAKE: Postquantum Three-Factor Authentication Against Server Compromise in Mobile Cloud Computing
abstract
The rapid advancement of mobile cloud computing has prompted users and commercial entities to increasingly access and utilize cloud resources for executing resource-intensive operations, which requires strong three-factor authentication and key exchange (3FAKE) protocols to ensure secure interactions in cloud environments. However, the current 3FAKE protocols not only primarily rely on traditional public-key cryptosystems that are vulnerable to quantum attacks, but lack sufficient protection for sensitive information of cloud users as well. To this end, this paper proposes a post-quantum 3FAKE (PQ3FAKE) protocol employing identity-based oblivious pseudorandom function (IBOPRF). Specifically, an IBOPRF from module learning with errors is instantiated to achieve a better balance between efficiency and security. Next, PQ3FAKE is built upon this IBOPRF to protect password from server compromise. We conduct an extensive evaluation and comparison with existing typical protocols in terms of computational overhead and security, demonstrating that the proposed PQ3FAKE achieves higher security while maintaining expected performance.
Xue Yang 0017, Qi Jiang 0001, Meng Li 0006, Meijia Xu, Ding Wang 0002, Jianfeng Ma 0001
IEEE Internet Things J.4
2025 Practical Two-Factor Authentication Protocol for Real-Time Data Access in WSNs
abstract
With the rapid development of sensors and communication technologies, the Internet of Things (IoT) paradigm has increasingly expanded to cover various daily, industrial, and military applications. As a core component of the IoT responsible for environmental sensing and data collection, wireless sensor networks (WSNs) face significant security threats. The design of multi-factor authentication schemes to secure real-time data transmission in WSNs has garnered considerable research efforts. However, a common trend in existing multi-factor authentication protocols is emphasizing performance and security benefits, while possible limitations are rarely subjected to thorough analysis. To fill this gap, we first select two representative multi-factor authentication schemes (i.e., Chaudhry et al.'s scheme at ACM ToIT'21 and Jabbari-Mohasef's scheme at IEEE TII'22) as case studies, and point out that both schemes are vulnerable to offline password guessing and node capture attacks, and fail to achieve forward secrecy. We then investigate the fundamental causes of these weaknesses underlying the schemes and propose corresponding solutions. After rethinking previous schemes, we present a new robust two-factor authentication scheme for WSNs and formally prove its security under the Random Oracle Model. Furthermore, we compare our scheme with 18 state-of-the-art protocols using the widely accepted evaluation framework. The comparison results show that our protocol outperforms its foremost counterparts.
Meijia Xu, Ding Wang 0002
IEEE Trans. Dependable Secur. Comput.1
2024 Enhancing depression detection: A multimodal approach with text extension and content fusion
abstract
Abstract Background With ubiquitous social media platforms, people express their thoughts and emotions, making social media data valuable for studying and detecting depression symptoms. Objective First, we detect depression by leveraging textual, visual, and auxiliary features from the Weibo social media platform. Second, we aim to comprehend the reasons behind the model's results, particularly in medicine, where trust is crucial. Methods To address challenges such as varying text lengths and abundant social media data, we employ a text extension technique to standardize text length, enhancing model robustness and semantic feature learning accuracy. We utilize tree‐long short‐term memory and bidirectional gate recurrent unit models to capture long‐term and short‐term dependencies in text data, respectively. To extract emotional features from images, the integration of optical character recognition (OCR) technology with an emotion lexicon is employed, addressing the limitations of OCR technology in accuracy when dealing with complex or blurred text. In addition, auxiliary features based on social behaviour are introduced. These modalities’ output features are fed into an attention fusion network for effective depression indicators. Results Extensive experiments validate our methodology, showing a precision of 0.987 and recall rate of 0.97 in depression detection tasks. Conclusions By leveraging text, images, and auxiliary features from Weibo, we develop text picture sentiment auxiliary (TPSA), a novel depression detection model. we ascertained that the emotional features extracted from images and text play a pivotal role in depression detection, providing valuable insights for the detection and assessment of the psychological disorder.
Shuxian Liu, Meijia Xu
Expert Syst. J. Knowl. Eng.3
2021 Understanding security failures of anonymous authentication schemes for cloud environments
Meijia Xu, Ding Wang 0002, Qingxuan Wang, Qiaowen Jia
J. Syst. Archit.1
2020 Security Analysis on "Anonymous Authentication Scheme for Smart Home Environment with Provable Security"
abstract
As an important application of the Internet of Things, smart home has greatly facilitated our life. Since the communication channels of smart home are insecure and the transmitted data are usually sensitive, a secure and anonymous user authentication scheme is required. Numerous attempts have been taken to design such authentication schemes. Recently, Shuai et al. (Computer & Security 86(2019):132146) designed an anonymous authentication scheme for smart home using elliptic curve cryptography. They claimed that the proposed scheme is secure against various attacks and provides ideal attributes. However, we show that their scheme cannot resist inside attack and offline dictionary attack and also fails to achieve forward secrecy. Furthermore, we give some suggestions to enhance the security of the scheme. These suggestions also apply to other user authentication schemes with similar flaws.
Meijia Xu, Qiying Dong, Mai Zhou, Chenyu Wang 0002
Wirel. Commun. Mob. Comput.1