VLDB 2026 Research / reviewers in the wild / expert
Yihe Duan
dblp:348/2260
· DBLP profile ↗
4ranked-venue papers
2as first author
4since 2021 · last 2026
0000-0001-7908-6860ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 4 · 2 first-author · 4 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Credential Extraction Attacks Against Compromised Credential Checking Services of Password Managers
Yihe Duan, Ding Wang 0002 |
SP | 1 |
| 2026 | HP-OTP: One-Time Password Scheme Based on Hardened PasswordabstractMobile devices enable the widespread adoption of One-Time Passwords (OTPs) as a crucial component of Two-Factor Authentication (2FA). The impact of OTP leakage is relatively manageable compared to static passwords. However, existing OTP standards, such as S/key, HOTP, and TOTP are vulnerable to key-compromise impersonation attacks, desynchronization attacks, and “small n” attacks. These vulnerabilities allow adversaries to bypass 2FA by exploiting pre-shared symmetric keys once either the device or the server is compromised. Furthermore, asymmetric (chain-based) OTP schemes incur high computational overhead and require periodic initialization, which limits their usability. In this work, we propose HP-OTP, a challenge-response OTP scheme that achieves password hardening without modifying password-OTP implementation architectures. Password hardening on the device side allows the server to store only a non-reversible verification credential used to generate challenges. The device's response OTP integrates the candidate password, possession factor, and a random salt. By redefining the role of OTPs in 2FA from representing only the device to jointly representing both the password and the device, HP-OTP prevents adversaries from bypassing the possession factor or exploiting compromises of either the device or the server. Comprehensive security and performance evaluation demonstrate the security of HP-OTP, with verification taking less than 5 milliseconds. Zixuan Ding, Yihe Duan, Ding Wang 0002 |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2025 | Security Analysis of Master-Password-Protected Password Management ProtocolsabstractPassword managers (PMs) are useful tools that help users manage their login credentials, alleviating the burden of memorizing an ever-increasing number of passwords. Master-password-protected password management (M3PM) protocols characterize the interaction between the client and the PM's server. In this protocol, the client uses the master password for authentication, and the server assists in retrieving credentials across devices. Given the ongoing PM data breaches and users' concerns about potential server misuse, it is crucial for the server to remain oblivious to both the master password and the credentials. The pivotal role of M3PM protocols underscores the need for a systematic and formal security analysis. In this paper, we, for the first time, present an extensive formal analysis of M3PM protocols. We identify the de facto M3PM protocols from 43 PMs in industry and academia by defining a methodology that includes documentation analysis, traffic analysis, and reverse engineering. To formalize the security properties of M3PM protocols, we propose a set of ideal functionalities within the universal composability (UC) framework. We categorize offline guessing attacks on master passwords into four types based on the knowledge of the adversary. Our analysis shows that 38 of the 43 PMs are vulnerable to at least one type of offline guessing attack, demonstrating the circumstances under which various M3PM protocols with single master password protection fail to resist such attacks. Additionally, we identify an oracle attack where a corrupted server can learn the encryption key of the well-known open-source Passbolt, and demonstrate that 1Password's dual-key mechanism provides strong protection for users' master passwords and credentials. Yihe Duan, Ding Wang 0002, Yanduo Fu |
SP | 1 |
| 2023 | Secure and Lightweight User Authentication Scheme for Cloud-Assisted Internet of ThingsabstractCloud-assisted Internet of Things (IoT) overcomes the resource-constrained nature of the traditional IoT and is developing rapidly in such fields as smart grids and intelligent transportation. In a cloud-assisted IoT system, users can remotely control the IoT devices and send specific instructions to them. If the users’ identities are not verified, adversaries can pretend as legitimate users to send fake and malicious instructions to IoT devices, thereby compromising the security of the entire system. Thus, a sound authentication mechanism is indispensable to ensure security. At the same time, it should be noted that a gateway may connect to massive IoT devices with the exponential growth of interconnected devices in a cloud-assisted IoT system. The efficiency of authentication schemes is easily impacted by the computation capability of the gateway. Recently, several schemes have been designed for cloud-assisted IoT systems, but they have problems of one kind or another, making them not very suitable for cloud-assisted IoT systems. In this paper, we take a typical scheme (proposed at IEEE TDSC 2020) as an example to identify the common weaknesses and challenges of designing a user authentication scheme for cloud-assisted IoT systems. In addition, we propose a new secure user authentication scheme with lightweight computation on gateways. The proposed scheme provides secure access between remote users and IoT devices with many ideal attributions, such as forward secrecy and multi-factor security. Meanwhile, the security of this scheme is proved under the random-oracle model, heuristic analysis, the ProVerif tool and BAN logic. Compared with ten state-of-the-art schemes in security and performance, the proposed scheme achieves all the listed twelve security requirements with minimum computation and storage costs on gateways. Chenyu Wang 0002, Ding Wang 0002, Yihe Duan, Xiaofeng Tao 0001 |
IEEE Trans. Inf. Forensics Secur. | 3 |