Shufan Fei

dblp:300/1448 · DBLP profile ↗
← Back
5ranked-venue papers
2as first author
5since 2021 · last 2026
0000-0001-7257-6832ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 2 · 2 first-author · 2 since 2021Security and privacy · 2 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2026 TMAS: A threshold multi-auditor auditing scheme for weakly trusted cloud-fog collaboration
Hui Tian 0002, Haiju Wang, Shufan Fei, Hanyu Quan
Comput. Secur.3
2026 EnduraTrust: Achieving Sustained Trust Through a Decentralized Root of Trust for Blockchain Oracles
abstract
Blockchain oracles are essential for enabling smart contracts to access and interact with off-chain data, where its security and trustworthiness are crucial for preserving the overall reliability and integrity of blockchain-based systems. However, existing reputation-based blockchain oracles are vulnerable to Sybil and collusion attacks. To address these issues, trusted execution environments (TEEs) have been leveraged to construct blockchain oracles. While these TEE-enabled oracles provide resistance against the above attacks, they typically depend on a centralized Root of Trust (RoT), which introduces risks such as root key pre-provision risks and single points of failure. Moreover, they often struggle to maintain trust over time, making them unsuitable for application scenarios that require long-term guaranteed trust. In this paper, we propose EnduraTrust, a highly secure blockchain oracle network empowered by a decentralized Root of Trust (DRoT), which can overcome single points of failure, offer trust sustainability, minimize the security risk of root key pre-provision, and provide essential participation incentive. Concretely, it adopts Physically Unclonable Functions (PUFs) to generate device-specific root keys, eliminating the risks associated with centralized key pre-provision. To confront mobile attacks and ensure sustained trust, it employs an off-chain process to generate attestation reports, which are then verified onchain through a non-interactive protocol. This protocol ensures robust integrity verification for Individual Root of Trust (IRoT) nodes while minimizing latency and overhead. In addition, we design a fair and secure IRoT node selection algorithm to form a trustworthy oracle committee to offer oracle services, protecting against Sybil and collusion attacks to which existing oracles are prone. Particularly, we apply an incentive mechanism to encourage oracle node participation and reliable behavior. We validate EnduraTrust through formal security analysis and performance evaluation based on prototype implementation. Our results show that EnduraTrust enhances root key security, realizes decentralization, offers fair oracle node selection, ensures sustained trust, exhibits strong robustness, and provides participation incentive. It surpasses existing decentralized attestation schemes in multiple dimensions, including security, contract execution efficiency, attestation protocol performance, and scalability. Besides, its performance regarding oracle response aggregation and aggregated response verification confirming its effectiveness.
Shufan Fei, Zheng Yan 0002, Haoxin He, Elisa Bertino
IEEE Trans. Netw.1
2025 B5G-NFM: Blockchain-Based 5G Network Function Management With Enhanced Security and Privacy
abstract
Within the 5G Service-Based Architecture (SBA), the prevalent centralized frameworks, particularly those managing public key certificates and Network Function (NF) services, face significant security and privacy vulnerabilities due to their reliance on centralized Certificate Authorities (CAs) and Network Repository Functions (NRFs). This centralization in current 5G standards poses two critical issues. One is the risk of single points of failure associated with CAs and NRFs. The other is a substantial risk of privacy leakage in cross-domain NF access authorization. These issues underscore the demand for decentralized NF management with enhanced security and privacy. However, existing related schemes still suffer from such drawbacks as poor security and privacy, low efficiency, and a lack of automation in the management of NF certificates. In this paper, we propose B5G-NFM, a pioneering Blockchain-based 5G Network Function Management scheme designed to bolster security and privacy. B5G-NFM integrates a blockchain middleware network function, a decentralized protocol for managing NF public key certificates, and a decentralized mechanism for NF service discovery coupled with a privacy-preserving NF access authorization protocol. Our thorough security and performance assessment verifies that B5G-NFM not only meets its security and privacy goals, but also aligns with efficiency demand, marking a substantial progress in strengthening 5G network infrastructure.
Shufan Fei, Zheng Yan 0002, Haomeng Xie, Tieyan Li
IEEE Trans. Netw.1
2023 A Survey on Cross-chain Technologies
abstract
Blockchain has attracted more and more attention of academia, industry, and government in recent decades. Different usage demands have inspired various blockchain designs, forming different blockchain systems, which leads to information islands. Many cross-chain technologies have been proposed to link different blockchains together and expand the utility of blockchain. Nevertheless, the cross-chain technology is still in its infancy, which faces many problems that retard its wide application, for example, the issues related to security, privacy, and effectiveness. In order to further investigate cross-chain technologies, it is essential to understand its current state of arts. Although there are some surveys about cross-chain technologies driven by specific demands, the literature still lacks a comprehensive survey focusing on security, privacy, and effectiveness of cross-chain technologies. In this paper, we provide a review on existing cross-chain technologies based on a comprehensive set of criteria on security, privacy, and other performance. We first propose a blockchain interoperability architecture for the purpose of analyzing potential threats and problems regarding security, privacy, and effectiveness. We then summarize a set of criteria regarding these quality attributes. Next, we comprehensively review the representative works on cross-chain technologies according to a taxonomy based on applied types of techniques and cross-chain purposes. In each work review, we provide a serious discussion on its pros and cons by employing our proposed criteria. Finally, based on our review and analysis, we figure out a number of open issues and step ahead to direct future research directions on cross-chain technologies.
Panpan Han, Zheng Yan 0002, Wenxiu Ding, Shufan Fei, Zhiguo Wan
Distributed Ledger Technol. Res. Pract.4
2023 SofitMix: A Secure Offchain-Supported Bitcoin-Compatible Mixing Protocol
abstract
Privacy preservation is highly expected in the Bitcoin Network. However, only applying pseudonyms cannot completely ensure anonymity/unlinkability between payers and payees. Current approaches mainly depend on a mixer service, which obfuscates payer-payee relationships of transactions. While the mixer service improves transaction privacy, it still suffers from some severe security threats (e.g., DoS attack and collusion attack), and does not support effective and reliable off-chain payment in a parallel mode. In this article, we propose a mixing protocol for the Bitcoin Network based on zero-knowledge proof, called SofitMix. It is the first mixing protocol that can effectively resist both the DoS attack and the collusion attack. It can also support a set of parallel off-chain payments in a reliable way no matter whether some payers abort a transaction. We analyze and prove SofitMix security following the Universal Composability model with regard to fair exchange, unlinkability, collusion-resistance, DoS-resistance and Sybil-resistance. Through a proof-of-concept implementation, we demonstrate its validity and fairness. We also show its advance on off-chain payment reliability and DoS attack resistance, compared to TumbleBit.
Haomeng Xie, Shufan Fei, Zheng Yan 0002, Yang Xiao 0010
IEEE Trans. Dependable Secur. Comput.2