Libin Xia

dblp:286/4539 · DBLP profile ↗
← Back
5ranked-venue papers
2as first author
5since 2021 · last 2026
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 2 · 1 first-author · 2 since 2021Security and privacy · 1 · 1 first-author · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Heimdall: A Decentralized Access Control Scheme With Time-Based Secret Management and Private Access Policies
abstract
Decentralized Access Control (DAC) manages access through multiple entities, consisting of two modules: decentralized secret management and access policies. However, existing DAC schemes lack support for managing secrets with time-based conditions, such as triggering secret release after a certain time bound. In this case, users may gain access to information before the designated time, which is undesirable in scenarios involving time-sensitive data. Moreover, current DAC schemes mainly focus on identity confidentiality and lack support for policy confidentiality, which may lead to leakage of sensitive information in access policies. To address these challenges, we propose Heimdall, a decentralized access control scheme with time-based secret management and private access policies. The core of our solution is the dhNIZK protocol, an efficient non-interactive zero-knowledge protocol designed for the verifiable incorporation of time conditions into threshold cryptosystems. We utilize this dhNIZK protocol and homomorphic time-lock puzzles to enable time-based secret management, improving the efficiency of secret reconstruction through batch puzzle-solving techniques. Furthermore, we enhance the garbling scheme’s encoding algorithm to ensure policy confidentiality while maintaining identity confidentiality. Finally, we implement Heimdall and present experimental results demonstrating its superior performance compared to the state-of-the-art solutions.
Libin Xia, Yue Li 0037, Jiashuo Zhang 0001, Jianbo Gao 0003, Zhi Guan, Zhong Chen 0001
IEEE Trans. Inf. Forensics Secur.1
2026 Web3ID: A Privacy-Preserving and DApp-Oriented Decentralized Identity Framework for Web3.0
abstract
With the development of Web3.0, decentralized identity and other blockchain-based identity empower users with control, forming the foundational infrastructure for Web3.0 ecosystems. However, existing identity frameworks remain inadequate in addressing critical challenges such as on-chain privacy during identity management and utilization. While prior works like CanDID, Hades, and CertChain explore blockchain-based identity solutions, they fail to meet the specific reqirements of DApps. Moreover, users on blockchain always store their identity data and digital assets across multiple accounts and DApps, but current identity schemes cannot support the cross-account and DApp identity privacy-preserving utilization. To bridge this gap, we propose Web3ID, the first fully DApp-oriented identity framework. By analyzing Ethereum identity proposals and user behavior patterns, we design the Web3ID featuring: on-chain privacy-preserving identity aggregation protocol, provably secure attribute-based access control model, and zk-rollup enhanced off-chain identity management. Experiments demonstrate that Web3ID enables privacy-preserving identity management and authentication on-chain, and guaranteeing access control completeness. The prototype system achieves a 100× improvement in proof/verification efficiency and reduces storage overhead by 85× compared to pure on-chain implementation through off-chain optimization techniques. Moreover, in comparison with other identity privacy solutions, Web3ID exhibits the lowest gas consumption during on-chain utilization and shows strong scalability. As a fully decentralized identity framework supporting end-to-end DApp integration, Web3ID advances Web3.0’s vision of user sovereignty, decentralization, and interoperability. This work establishes both theoretical and practical foundations for on-chain identity systems in Web3.0 ecosystems.
Jiakun Hao, Jianbo Gao 0003, Libin Xia, Zhi Guan, Zhong Chen 0001
ACM Trans. Web5
2025 A sharding blockchain-based UAV system for search and rescue missions
Xihan Zhang, Jiashuo Zhang 0001, Jianbo Gao 0003, Libin Xia, Zhi Guan, Zhong Chen 0001
Frontiers Comput. Sci.4
2024 ContractTinker: LLM-Empowered Vulnerability Repair for Real-World Smart Contracts
abstract
Smart contracts are susceptible to being exploited by attackers, especially when facing real-world vulnerabilities. To mitigate this risk, developers often rely on third-party audit services to identify potential vulnerabilities before project deployment. Nevertheless, repairing the identified vulnerabilities is still complex and laborintensive, particularly for developers lacking security expertise. Moreover, existing pattern-based repair tools mostly fail to address real-world vulnerabilities due to their lack of high-level semantic understanding. To fill this gap, we propose ContractTinker, a Large Language Models (LLMs)-empowered tool for real-world vulnerability repair. The key insight is our adoption of the Chain-of-Thought approach to break down the entire generation task into subtasks. Additionally, to reduce hallucination, we integrate program static analysis to guide the LLM. We evaluate ContractTinker on 48 high-risk vulnerabilities. The experimental results show that among the patches generated by ContractTinker, 23 (48%) are valid patches that fix the vulnerabilities, while 10 (21%) require only minor modifications. A video of ContractTinker is available at https://youtu.be/HWFVi-YHcPE.
Jiashuo Zhang 0001, Jianbo Gao 0003, Libin Xia, Zhi Guan, Zhong Chen 0001
ASE4
2024 Cryptcoder: An Automatic Code Generator for Cryptographic Tasks in Ethereum Smart Contracts
abstract
Cryptographic APIs provided by Ethereum are widely adopted in decentralized applications (DApps) for cryptographic operations. However, developers who lack expertise in cryptography frequently encounter difficulties when working with low-level cryptographic APIs, thereby producing insecure code. To address this issue, we introduce Cryptcoder, an automatic code generator designed to bridge the gap between low-level cryptographic APIs and high-level cryptographic tasks in Ethereum. The fundamental component of Cryptcoder is Cryptlang, a Solidity-compatible domain-specific language (DSL) designed for cryptographic tasks. Developers can utilize Cryptlang for the straightforward and secure implementation of cryptographic tasks, such as signatures and commitments, and employ Cryptcoder for the automatic conversion into Solidity code. The evaluation of Cryptcoder demonstrates both its functionality in generating Solidity code and an acceptable overhead, evidenced by a mere 4% average increase in gas costs compared to the reference code. A demonstration video of Cryptcoder is available at https://youtu.be/AxhCdGiu7dw.
Libin Xia, Jiashuo Zhang 0001, Zezhong Tan, Jianbo Gao 0003, Zhi Guan, Zhong Chen 0001
SANER1