VLDB 2026 Research / reviewers in the wild / expert
Wei Wang 0314
dblp:35/7092-314
· DBLP profile ↗
29ranked-venue papers
1as first author
23since 2021 · last 2025
0000-0002-1484-0313ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 16 · 1 first-author · 12 since 2021Computer networks · 10 · 8 since 2021Systems, architecture and hardware · 2 · 2 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Octopus: Fast Homomorphic Convolution for Secure Neural Network InferenceabstractSecure two-party neural network (2PC-NN) inference is a privacy-preserving inference method that protects the client's input and the server's model parameters. While addressing privacy concerns, it also incurs considerable over-heads. In this work, we propose Octopus, a faster and more communication-efficient 2PC-NN system than prior works. Octopus designs an optimized encoding method for fast homomorphic convolution, and further constructs homomorphic encryption-based convolutional computation protocol. Compared with the original coefficient encoding proposed by Cheetah, our method significantly reduces the resulting ciphertexts through packing output channels, thereby saving the communication cost and end-to-end execution time. Moreover, Octopus proposes an encoding-motivated fine tuning technique for convolutional neural networks, which fully utilizes the feature of coefficient encoding to adaptively adjust the neural network structure to maximize performance with negligible accuracy loss. We apply Octopus to the widely used model ResNet on CIFAR-10 and ImageNet dataset. Experiments illustrate that Octopus has obvious improvement compared with the state-of-the-art approaches, achieving a speedup of up to 2.75×, and reduces communication overhead by up to 7.19× for convolutions. As for secure inference, compared with Cheetah (resp., CrypTFlow2), Octopus demonstrates 1.41× (resp., 13.20×) lower communication cost and 1.25× (resp., 7.03×) faster execution time under a WAN setting. Yu Fu 0007, Tianshi Xu, Cheng Hong 0001, Meng Li 0004, Wei Wang 0314, Dengguo Feng, Jingqiang Lin 0001 |
ACSAC | 6 |
| 2025 | Exploring the Root Store Usage in TLS-Based Applications
Yuxiang Shen, Wei Wang 0314, Shushang Wen, Yu Fu 0007, Yunhao Jia, Jingqiang Lin 0001 |
Inscrypt (2) | 2 |
| 2025 | An RPKI Certificate Validator for Formal Correctness
Yajun Teng, Wei Wang 0314, Jingqiang Lin 0001, Shijie Jia 0001, Xiaoqi Jia |
ISPEC | 2 |
| 2024 | Certificate Transparency Revisited: The Public Inspections on Third-party Monitors
Aozhuo Sun, Jingqiang Lin 0001, Wei Wang 0314, Zeyan Liu, Bingyu Li 0003, Shushang Wen, Qiongxiao Wang, Fengjun Li |
NDSS | 3 |
| 2024 | Efficient and Accurate Min-entropy Estimation Based on Decision Tree for Random Number Generators
Maosen Sun, Wei Wang 0314, Tianyu Chen 0016, Dongchi Han |
TrustCom | 3 |
| 2023 | Curveball+: Exploring Curveball-Like Vulnerabilities of Implicit Certificate Validation
Yajun Teng, Wei Wang 0314, Jun Shao 0001, Huiqing Wan, Jingqiang Lin 0001 |
ESORICS (2) | 2 |
| 2023 | Fast and Parallel Modular Multiplication without Borrow for ECC on ARM-NEONabstractFast reduction is a powerful modular reduction method for many ECC curves using NIST-style prime modulus. Based on fast reduction, existing vectorized modular multiplication schemes (such as MR and SMCOS) were constructed in succession. However, these schemes are only applicable to those NIST-style primes with just subtraction items. The vector design on fast reduction for ones with addition items (including certain well-known curves, NIST P-256 and SM2, etc.) rarely holds in practice because of the possible borrow situation. In this work, we fill this gap and propose a pipelined and vectorized fast reduction that, with the aid of pre-processing and post-processing, eliminates all potential borrow during the reduction. Based on the proposed reduction, we successfully construct a vectorized modular multiplication, namely Borrowless, which works with all NIST-style primes, including the ones with addition items. Using NIST P-256, SM2, and NIST P-224 curves as case studies, on the 32-bit ARM NEON platform, we demonstrate the effectiveness of Borrowless and its significant performance advantage over existing vector designs (e.g., CICOS and MR) and widely-used algorithm libraries (e.g., OpenSSL and GMP). Wei Wang 0314, Jingqiang Lin 0001, Lina Shang, Fan Lang, Dingfeng Ye |
ICC | 2 |
| 2023 | HPVES: High Performance Video Encryption Scheme with Cryptographic USB KeyabstractReal time streaming data accounts for a growing proportion of Internet traffic. The demand for security is accordingly increasing, which poses severe burdens on the performance of terminal processing streaming data. In this paper, a high performance video encryption scheme (HPVES) is proposed to speed up cryptographic operations for streaming media data based on cryptographic USB key. In our scheme, the cryptographic key is stored and used in USB key, a dedicated hardware security module (HSM), which avoids the leakage of cryptographic key even when the terminal is compromised. We modify the cos (chip operating system) driver of USB key which is then called HPUK to accelerate data transmission between computer and its' peripherals. A flow control mechanism is also proposed to balance the throughput of keystream and media stream which could (1) make data encryption/decryption maintain at a constant throughput in regardless of the data size and (2) save storage space. We have implemented the proposed scheme and evaluated the performance on different devices. The evaluation demonstrates that HPUK almost doubles the throughput of original USB key on resource-constrained devices at small packet size (no more than 1.5 KB, which suits for real-time UDP transmission). Field experiments also show that HPVES could provide continuous and stable keystream with throughput of 4 MBps. Pengyi Wu, Qiongxiao Wang, Fan Lang, Wei Wang 0314 |
ICC | 4 |
| 2023 | Semi-CT: Certificates Transparent to Identity Owners but Opaque to SnoopersabstractCertificate Transparency (CT) enables timely detection of problematic certification authorities (CAs) by publicly recording all CA-issued certificates. This transparency inevitably leaks the privacy of identity owners (IdOs) through the identity information bound in certificates. In response to the privacy leakage, several privacy-preserving schemes have been proposed that transform/hash/encrypt the privacy-carrying part in certificates. However, these certificates conceal identity while also making it opaque to the IdO, which defeats the purpose of CT. To address the contradiction between transparency and privacy, we propose Semi-CT, a semi-transparency mechanism that makes the certificates transparent to IdOs but opaque to snoopers. Inspired by public-key encryption with keyword search (PEKS), Semi-CT based on bilinear pairing enables trapdoor-holding IdOs to retrieve certificates associated with their identity. Semi-CT also addresses protocol deviation detection and trapdoor protection in the malicious model. Finally, through theoretical and experimental analysis, we prove the security and feasibility of Semi-CT for practical applications. Aozhuo Sun, Bingyu Li 0003, Qiongxiao Wang, Huiqing Wan, Jingqiang Lin 0001, Wei Wang 0314 |
ISCC | 6 |
| 2023 | A Design of High-Efficiency Coherent Sampling Based TRNG With On-Chip Entropy AssuranceabstractTrue Random Number Generator (TRNG) is indispensable in cryptographic algorithms and protocols, and the quality of randomness directly influences the security of cryptographic applications. Multiple theoretical or offline entropy estimation methods have been proposed to evaluate the security of TRNGs, while their ideal assumptions commonly cannot be satisfied due to the perturbation of operating conditions at runtime, which makes it difficult to achieve sufficient entropy for the output of TRNGs in practice. Moreover, the output bitrate of TRNG is another fundamental concern during TRNG practical applications, while popular elementary oscillator-based structure commonly has relatively low output bitrate due to the inherent low sensitivity of entropy extraction to jitter (source of randomness). In this paper, we aim to design a TRNG satisfying both practical security (i.e., on-chip entropy assurance) and high output bitrate simultaneously. In particular, an improved stochastic model and a measurement method are established to quantify the entropy of coherent sampling based TRNG. Moreover, an on-chip entropy assurance module is provided to realize the robustness of the proposed design under various operating conditions. We implement the proposed TRNG in a simulation platform and ASIC chips (with SMIC 130 nm CMOS technology). Experimental results indicate that the generated data has sufficient entropy ($\geq 0.999$per bit) under various operating conditions. In addition, all the output can pass the NIST SP800-22 and AIS 31 statistical tests with an output bitrate of 4.2 Mbps, which is equivalent to 2 orders of magnitude faster than that of the elementary oscillator-based TRNG. Tianyu Chen 0016, Shijie Jia 0001, Yuan Cao 0003, Wei Wang 0314, Jing Yang 0032, Jingqiang Lin 0001 |
IEEE Trans. Circuits Syst. I Regul. Pap. | 6 |
| 2023 | RegKey: A Register-based Implementation of ECC Signature Algorithms Against One-shot Memory DisclosureabstractTo ensure the security of cryptographic algorithm implementations, several cryptographic key protection schemes have been proposed to prevent various memory disclosure attacks. Among them, the register-based solutions do not rely on special hardware features and offer better applicability. However, due to the size limitation of register resources, the performance of register-based solutions is much worse than conventional cryptosystem implementations without security enhancements. This paper presents RegKey, an efficient register-based implementation of ECC (elliptic curve cryptography) signature algorithms. Different from other schemes that protect the whole cryptographic operations, RegKey only uses CPU registers to execute simple but critical operations, significantly reducing the usage of register resources and performance overheads. To achieve this goal, RegKey splits the ECC signing into two parts, (1) complex elliptic curve group operations on non-sensitive data in main memory as normal implementations, and (2) simple prime field operations on sensitive data inside CPU registers. RegKey guarantees the plaintext private key and random number used for signing only appear in registers to effectively resist one-shot memory disclosure attacks such as cold-boot attacks and warm-boot attacks, which are usually launched by physically accessing the victim machine to acquire partial or even entire memory data but only once. Compared with existing cryptographic key protection schemes, the performance of RegKey is greatly improved. Regkey is applicable to different platforms because it does not rely on special CPU hardware features. Since RegKey focuses on one-shot memory disclosure instead of persistent software-based attacks, it works as a choice suitable for embedded devices or offline machines where physical attacks are the main threat. Yu Fu 0007, Jingqiang Lin 0001, Dengguo Feng, Wei Wang 0314 |
ACM Trans. Embed. Comput. Syst. | 4 |
| 2022 | MoLE: Mitigation of Side-channel Attacks against SGX via Dynamic Data Location EscapeabstractNumerous works have experimentally shown that Intel Software Guard eXtensions (SGX) is vulnerable to side-channel attacks (SCAs) and related threats, including transient execution attacks. These threats compromise the security of SGX-protected apps. Obfuscating data access patterns is a realistic way to guard against these threats. However, existing defenses impose either too much performance overhead or additional usage restrictions (such as multi-threading). Furthermore, these obfuscation schemes may no longer work if the attacker has the capacity to single-step the target application. Fan Lang, Wei Wang 0314, Lingjia Meng, Jingqiang Lin 0001, Qiongxiao Wang, Linli Lu |
ACSAC | 2 |
| 2022 | LiTIV: A Lightweight Traceable Data Integrity Verification Scheme for Version Control Systems
Wei Wang 0314, Jingqiang Lin 0001, Zhen Yang 0015, Haoling Fan, Qiongxiao Wang |
ICCCN | 2 |
| 2022 | $\mu AFL$: Non-intrusive Feedback-driven Fuzzing for Microcontroller FirmwareabstractFuzzing is one of the most effective approaches to finding software flaws. However, applying it to microcontroller firmware incurs many challenges. For example, rehosting-based solutions cannot accurately model peripheral behaviors and thus cannot be used to fuzz the corresponding driver code. In this work, we present μAFL, a hardware-in-the-loop approach to fuzzing microcontroller firmware. It leverages debugging tools in existing embedded system development to construct an AFL-compatible fuzzing framework. Specifically, we use the debug dongle to bridge the fuzzing environment on the PC and the target firmware on the microcontroller device. To collect code coverage information without costly code instrumentation, μAFL relies on the ARM ETM hardware debugging feature, which transparently collects the instruction trace and streams the results to the PC. However, the raw ETM data is obscure and needs enormous computing resources to recover the actual instruction flow. We therefore propose an alternative representation of code coverage, which retains the same path sensitivity as the original AFL algorithm, but can directly work on the raw ETM data without matching them with disassembled instructions. To further reduce the workload, we use the DWT hardware feature to selectively collect runtime information of interest. We evaluated μAFL on two real evaluation boards from two major vendors: NXP and STMicroelectronics. With our prototype, we discovered ten zero-day bugs in the driver code shipped with the SDK of STMicroelectronics and three zero-day bugs in the SDK of NXP. Eight CVEs have been allocated for them. Considering the wide adoption of vendor SDKs in real products, our results are alarming. Jiameng Shi, Fengjun Li, Jingqiang Lin 0001, Wei Wang 0314, Le Guan |
ICSE | 5 |
| 2022 | ABLE: Zero-effort Two-factor Authentication Exploiting BLE Co-locationabstractTwo-factor authentication (2FA) offers very important security enhancement to traditional username-password authentication, while in many cases incurring undesirable user burdens (e.g., entering a one-time verification code sent to a phone via SMS). Some zero-effort authentication techniques (e.g., Sound-Proof) have been proposed to relieve such burdens without degrading security, but are vulnerable to prediction attacks and co-existence attacks. This paper proposes ABLE, a zero-effort 2FA approach based on co-location detection leveraging environmental Bluetooth Low Energy (BLE) signal characteristics. In this approach, a laptop on which the user tries to authenticate to a web server, and the user’s smartphone placed nearby which is trusted by the server, both collect and send a record of environmental BLE signal characteristics to the server. The server decides whether the two devices are co-located by evaluating the similarity of the two records, and makes the authentication decision. ABLE is constructed based on the fact that only two devices in close proximity share similar environmental signal characteristics, which distinguishes a legitimate user device from potential adversaries. Due to its location-sensitive nature, combining favorable features brought with the BLE protocol, ABLE is gifted with good resistance to attacks that threaten existing zero-effort authentication schemes. ABLE is not only immune to remote attackers, but also achieves an accuracy over 90% even against co-present attackers. Yaxi He, Wei Wang 0314, Yajun Teng, Qiongxiao Wang, Jingqiang Lin 0001 |
WCNC | 2 |
| 2022 | The Invisible Side of Certificate Transparency: Exploring the Reliability of Monitors in the WildabstractTo detect fraudulent TLS server certificates and improve the accountability of certification authorities (CAs), certificate transparency (CT) is proposed to record certificates in publicly-visible logs, from which the monitors fetch all certificates and watch for suspicious ones. However, if the monitors, either domain owners themselves or third-party services, fail to return a complete set of certificates issued for a domain of interest, potentially fraudulent certificates may not be detected and then the CT framework becomes less reliable. This paper presents the first systematic study on CT monitors. We analyze the data in 88 public logs and the services of 5 active third-party monitors regarding 3,000,431 certificates of 6,000 selected Alexa Top-1M websites. We find that although CT allows ordinary domain owners to act as monitors, it is impractical for them to perform reliable processing by themselves, due to the rapidly increasing volume of certificates in public logs (e.g., on average about 5 million records or 28.29 GB daily for the minimal set of logs that need to be monitored in 2018, or more than 7 million records per day in 2020, according to the Chrome CT policy). Moreover, our study discloses that (${a}$) none of the third-party monitors guarantees to return the complete set of certificates for a domain, and (${b}$) for some domains, even the union of the certificates returned by the five third-party monitors can probably be incomplete. As a result, the certificates accepted by CT-enabled browsers are not actually visible to the claimed domain owners, even when CT is adopted with well-functioning logs. The risk of invisible fraudulent certificates in public logs raises doubts on the reliability of CT in practice. Bingyu Li 0003, Jingqiang Lin 0001, Fengjun Li, Qiongxiao Wang, Wei Wang 0314, Qi Li 0002, Guangshen Cheng, Jiwu Jing, Congli Wang |
IEEE/ACM Trans. Netw. | 5 |
| 2021 | Privacy Preserving OpenPGP Public Key Distribution with Spamming Resistance
Wei Wang 0314, Jingqiang Lin 0001, Qiongxiao Wang |
Inscrypt | 2 |
| 2021 | SMCOS: Fast and Parallel Modular Multiplication on ARM NEON Architecture for ECC
Wei Wang 0314, Jingqiang Lin 0001, Yu Fu 0007, Lingjia Meng, Qiongxiao Wang |
Inscrypt | 2 |
| 2021 | Certificate Transparency for ECQV Implicit CertificatesabstractECQV implicit certificates are special public-key certificates, proposed for smaller size and faster verification. In resource-constrained environments such as Internet of Things (IoT), it’s common to replace X.509 certificates with ECQV implicit certificates for better efficiency. Google’s Certificate Transparency (CT) makes the certificate issuance be publicly-visible to everyone, to enhance the trustworthiness of Public Key Infrastructure (PKI). However, the conventional CT approach based on Signed Certificate Timestamp (SCT) will be a burden for ECQV certificate verifiers in resource-constrained environments. In this paper, we propose an efficient scheme, named ECQV Implicit Certificate Transparency (EICT), to integrate CT with implicit certificates following the same assumption and approach of ECQV implicit certificates. EICT obtains better performance than CT applied in traditional X.509 PKIs. We also conduct the security analysis and performance evaluation of the proposed scheme. Wanling Huang, Jingqiang Lin 0001, Qiongxiao Wang, Yajun Teng, Huiqing Wan, Wei Wang 0314 |
ICC | 6 |
| 2021 | VIRSA: Vectorized In-Register RSA Computation with Memory Disclosure Resistance
Yu Fu 0007, Wei Wang 0314, Lingjia Meng, Qiongxiao Wang, Yuan Zhao 0015, Jingqiang Lin 0001 |
ICICS (1) | 2 |
| 2021 | Informer: Protecting Intel SGX from Cross-Core Side Channel Threats
Fan Lang, Wei Wang 0314, Lingjia Meng, Qiongxiao Wang, Jingqiang Lin 0001 |
ICICS (1) | 2 |
| 2021 | SCB: Flexible and Efficient Asymmetric Computations Utilizing Symmetric Cryptosystems Implemented with Intel SGXabstractThe wide spread of cloud computing and the rapid growth of online activities raise the demand for privacy enhancing cryptography, such as identity-based encryption (IBE), attribute-based encryption (ABE), and group/ring signature, which are mostly asymmetric. However, implementing a practical asymmetric cryptosystem with privacy enhancing functionalities faces the big challenge of large computing overhead that stems from the hard mathematical problems they are based on, which in reality hinders the further deployment of such cryptosystems.In this paper, we propose "SGX Cipher Box" (SCB), a method of constructing flexible and efficient asymmetric computations by encapsulating symmetric algorithms into Intel SGX enclaves. Two types of enclaves are designed for serving computations with the public key and the private key, respectively. The security assumptions of asymmetric algorithms can be achieved in SCB based on guarantees offered by SGX. SCB is of great flexibility that it facilitates implementing various asymmetric computations with limited enclaves. We present four SCB-based cryptosystems, provisioning asymmetric primitives, IBE, ABE, and ring signature, respectively. The four prototype cryptosystems are implemented and benchmarked in terms of computing efficiency. Experimental results show that SCB surpasses conventional asymmetric cryptosystem implementations in performance. Wenyi Ouyang, Qiongxiao Wang, Wei Wang 0314, Jingqiang Lin 0001, Yaxi He |
IPCCC | 3 |
| 2021 | Old Habits Die Hard: A Sober Look at TLS Client Certificates in the Real WorldabstractCertificates play a key role in TLS, which is by far the most widely used security protocol for protecting network traffic. Studies have shown that inappropriate usage of certificates may incur security and privacy risks, most of which are focused on the server-side certificates. However, with the rapid development of the Internet of Things that interconnects countless nodes over the world, as well as the Zero Trust philosophy that stresses authentication of every entity, the adoption of client certificates could be a lot more vital. According to our observation, many practical problems and security risks still exist in the deployment and use of client certificates. In this paper, we present a passive measurement of over 24 million client certificates, collected by a framework deployed on the CSTNET, one of the major academic backbone networks in China. By performing a comprehensive analysis of the large scale real-world data, we give a big picture of the client certificates usage in current network, and disclose implementation flaws of these certificates which may possibly harm transport layer security and user privacy. As many as 342,699 defective client certificates are unearthed, which is an important reminder that never should we neglect the correct use of certificates on the client side. Wei Wang 0314, Gang Xiong 0001, Gaopeng Gou, Zhen Li 0011 |
TrustCom | 2 |
| 2020 | E-SGX: Effective Cache Side-Channel Protection for Intel SGX on Untrusted OS
Fan Lang, Huorong Li, Wei Wang 0314, Jingqiang Lin 0001, Fengwei Zhang, Wuqiong Pan, Qiongxiao Wang |
Inscrypt | 3 |
| 2020 | P2A: Privacy Preserving Anonymous Authentication Based on Blockchain and SGX
Tianlin Song, Wei Wang 0314, Fan Lang, Wenyi Ouyang, Qiongxiao Wang, Jingqiang Lin 0001 |
Inscrypt | 2 |
| 2020 | Traceable Revocable Anonymous Registration Scheme with Zero-knowledge Proof on BlockchainabstractUser registration is the beginning of the life cycle of an account for most information systems. Some registration servers have special requirements for the validity of the registrant's identity and attributes, and thus demand his real-life identity and raw attributes for verification, which poses a great threat to privacy. However, the exposure of the registrant's real-life identity and raw attributes is not necessary, as long as he can prove to the server that he is associated with a real-life identity (RId) that fulfills the requirements. In this paper, we propose the concept of anonymous registration, with which a user can register an anonymous identity (AId) without privacy leakage. Anonymous registration has two basic features, i.e. privacy and verifiability, and two extended features, i.e. traceability and revocability. We design and implement an anonymous registration scheme with the above features, named Traceable Revocable Anonymous Registration Scheme (TRARS) based on Blockchain. In the proposed registration process, the user can calculate a zero-knowledge proof for a self-generated AId, which can prove to the registration server that the AId is associated with a valid RId and the RId's attributes meet the server's requirements, without leaking any privacy. We also introduce an identity revocation coordinator, with which evil identities can be tracked and outdated AIds can be revoked timely. Tianlin Song, Jingqiang Lin 0001, Wei Wang 0314, Quanwei Cai 0001 |
ICC | 3 |
| 2019 | Elaphurus: Ensemble Defense Against Fraudulent Certificates in TLS
Bingyu Li 0003, Wei Wang 0314, Lingjia Meng, Jingqiang Lin 0001, Xuezhong Liu, Congli Wang |
Inscrypt | 2 |
| 2018 | A Fast Secure Outsourcing of Ridge Regression Based on Singular-Value DecompositionabstractIn modern science and engineering practices, regression analysis is widely used to deal with large-scale and sensitive data, such as personal credit information. When executing such tasks, it is preferable for a resource-constrained client, like a mobile phone, to outsource part of its expensive computation. However, it is challenging to outsource the computation to an untrusted cloud server without leak of sensitive information. In this paper, we propose a fast ridge regression outsourcing scheme FaSORR with a series of disguise techniques. Our scheme is based on singular-value decomposition(SVD), which is non-iterative and highly efficient with light workload at the client side. Moreover, we update the perturbation method and offer more protection to the original data than previous works. Experiment results show that the computing load at the client side decreases dramatically after the adoption of FaSORR. We analyze the performance of our scheme and compare it with previous works. Shiran Pan, Wei Wang 0314, Qiongxiao Wang |
IPCCC | 3 |
| 2015 | vBox: Proactively Establishing Secure Channels Between Wireless Devices Without Prior Knowledge
Wei Wang 0314, Jingqiang Lin 0001, Luning Xia |
ESORICS (2) | 1 |