Joonsang Baek

dblp:36/5899 · DBLP profile ↗
← Back
55ranked-venue papers
21as first author
17since 2021 · last 2026
0000-0003-2613-2127ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 44 · 15 first-author · 13 since 2021Computer networks · 4 · 1 first-author · 3 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 4 first-authorArtificial intelligence and machine learning · 1 · 1 since 2021Systems, architecture and hardware · 1 · 1 first-authorSoftware engineering, systems software and programming languages · 1Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
YearPublicationVenuePosition
2026 CCA-Droid: Context-Aware Cryptographic API Misuse Detection in Android Apps
abstract
We present CCA-Droid, a static analysis tool designed to detect cryptographic misuse related to chosen-ciphertext attacks (CCA) and chosen-plaintext attacks (CPA). CCA-Droid utilizes three key techniques: domain-specific slicing optimization to reduce analysis noise, crypto-state-aware call graph construction to capture indirect data flows via member variables, and conditional constant propagation for improved path sensitivity. Our evaluation demonstrates that CCA-Droid achieves 100% accuracy on CryptoAPI-Bench, surpassing CryptoGuard (72.3%), and maintains 94.8% accuracy on mutated code. Evaluations on the Ghera benchmark further confirm CCA-Droid's effectiveness, achieving 100% recall and 81.8% accuracy. On 16,284 real-world Android apps, CCA-Droid analyzed 96.4%, significantly outperforming existing tools such as CryptoGuard (80.4%) and QARK (40.0%). It identified cryptographic vulnerabilities in 12,678 apps (77.9%), with IV reuse, hardcoded keys, and missing authenticated encryption being the most prevalent issues.
Minwook Lee, Eunsoo Kim, Sanghak Oh, Joonsang Baek, Willy Susilo, Hyoungshick Kim
AsiaCCS4
2026 5G-AKA-HPQC: Hybrid Postquantum Cryptography Protocol for Quantum-Resilient 5G Primary Authentication With Forward Secrecy
abstract
5G serves as a catalyst for transformative digital innovation by enabling convergence with various services in our daily lives. The success of this paradigm shift undeniably hinges on robust security measures, with primary authentication— securing access to the 5G network—being paramount. Two protocols, 5G Authentication and Key Agreement (5G-AKA) and the Extensible Authentication Protocol for Authentication and Key Agreement Prime (EAP-AKA’), have been standardized for this purpose, with the former designed for 3rd Generation Partnership Project (3GPP) devices and the latter for non-3GPP devices. However, recent studies have exposed vulnerabilities in the 5G-AKA protocol, rendering it susceptible to security breaches, including linkability attacks. Furthermore, the advent of quantum computing poses significant quantum threats, underscoring the urgent need for the adoption of quantum-resistant cryptographic mechanisms. Although post-quantum cryptography (PQC) is being standardized, the lack of real-world deployment limits its proven robustness. In contrast, conventional cryptographic schemes have demonstrated reliability over decades of practical application. To address this gap, the Internet Engineering Task Force (IETF) has initiated the standardization of hybrid PQC algorithms (HPQC), combining classical and quantum-resistant techniques. Consequently, ensuring forward secrecy and resilience to quantum threats in the 5G-AKA protocol is critical. To address these security challenges, we propose the 5G-AKA-HPQC protocol. Our protocol is designed to maintain compatibility with existing standards while enhancing security by combining keys negotiated via the Elliptic Curve Integrated Encryption Scheme (ECIES) with those derived from a PQC-Key Encapsulation Mechanism (KEM). To rigorously and comprehensively validate the security of 5G-AKA-HPQC, we employ formal verification tools such as SVO Logic and ProVerif. The results confirm the protocol’s security and correctness. Furthermore, performance evaluations highlight the computational and communication overheads inherent to 5G-AKA-HPQC. With only average of 56.5 millisecond(+112.32%) on a total authentication time, proposed protocol provides its advantages. Also, on a environment of multiple UE registration, compared to single UE registration, the difference of increased rate of average authentication time is only 0.01%. The negligible difference 0.01% indicates that the addition of PQC does not lead to increased overhead in multi-UE registration environments, demonstrating its scalability and practical feasibility. In conclusion, our research provides significant insights into the design of secure, quantum-safe authentication protocols and lays the groundwork for the future standardization of secure authentication and key agreement protocols for mobile telecommunications.
Yongho Ko, I Wayan Adi Juliawan Pawana, Hoseok Kwon, SeongHan Shin, Jongkil Kim, Joonsang Baek, Ilsun You
IEEE Internet Things J.6
2025 Efficient One-Pass Private Set Intersection from Pairings with Offline Preprocessing
Joonsang Baek, Seongbong Choi, Willy Susilo, Partha Sarathi Roy 0001, Hyung Tae Lee
ESORICS (2)1
2025 AudioMarkNet: Audio Watermarking for Deepfake Speech Detection
Wei Zong, Yang-Wai Chow, Willy Susilo, Joonsang Baek, Seyit Ahmet Çamtepe
USENIX Security Symposium4
2025 How to Terminate Service Requests in Outsourcing: A Seamless Solution From Withdrawable Signatures
abstract
Outsourcing is an essential strategy for enterprises, and leveraging it can offer advantages such as saving costs, improving efficiency, and allowing them to concentrate on their primary business activities. Therefore, announcing and managing service requests is paramount for obtaining suitable quotes and partnering with the right outsourcing service providers. To achieve this, enterprises can employ digital signatures to ensure the authenticity and security of these service requests. However, the irrevocable nature of traditional digital signatures poses challenges, particularly when canceling the service requests is necessary. A withdrawable signature scheme provides a novel property for signers to initially create “withdrawable” signatures, which they can later confirm into additional conventional signatures. Withdrawable signatures can be regarded as withdrawn when the signer has not confirmed them yet. This property provided by the withdrawable signature mechanism can then be adopted as a solution to this problem, allowing the enterprise to retract announced signatures on service requests. However, to meet the demands in the outsourcing system, existing approaches on withdrawable signatures require further development since they only allow signers in outsourcing systems to confirm withdrawable signatures on service requests. This limitation prevents enterprises from accepting quotes for service requests simply by confirming the withdrawable signature. This paper focuses on this problem by applying the withdrawable signature to the outsourcing framework, identifying the limitations of existing withdrawable signature schemes, and proposing solutions. We demonstrate how revisiting of withdrawable signatures can lead to flexible outsourcing systems that ensure the cancellation of announced service requests. Additionally, we provide a performance evaluation demonstrating that our revised withdrawable signature scheme achieves acceptable efficiency and security within the outsourcing system.
Xin Liu 0074, Willy Susilo, Joonsang Baek
IEEE Trans. Inf. Forensics Secur.3
2024 IPRemover: A Generative Model Inversion Attack against Deep Neural Network Fingerprinting and Watermarking
abstract
Training Deep Neural Networks (DNNs) can be expensive when data is difficult to obtain or labeling them requires significant domain expertise. Hence, it is crucial that the Intellectual Property (IP) of DNNs trained on valuable data be protected against IP infringement. DNN fingerprinting and watermarking are two lines of work in DNN IP protection. Recently proposed DNN fingerprinting techniques are able to detect IP infringement while preserving model performance by relying on the key assumption that the decision boundaries of independently trained models are intrinsically different from one another. In contrast, DNN watermarking embeds a watermark in a model and verifies IP infringement if an identical or similar watermark is extracted from a suspect model. The techniques deployed in fingerprinting and watermarking vary significantly because their underlying mechanisms are different. From an adversary's perspective, a successful IP removal attack should defeat both fingerprinting and watermarking. However, to the best of our knowledge, there is no work on such attacks in the literature yet. In this paper, we fill this gap by presenting an IP removal attack that can defeat both fingerprinting and watermarking. We consider the challenging data-free scenario whereby all data is inverted from the victim model. Under this setting, a stolen model only depends on the victim model. Experimental results demonstrate the success of our attack in defeating state-of-the-art DNN fingerprinting and watermarking techniques. This work reveals a novel attack surface that exploits generative model inversion attacks to bypass DNN IP defenses. This threat must be addressed by future defenses for reliable IP protection.
Wei Zong, Yang-Wai Chow, Willy Susilo, Joonsang Baek, Jongkil Kim, Seyit Ahmet Çamtepe
AAAI4
2024 Generic Construction of Withdrawable Signature from Hash-Then-One-Way Signature
Xin Liu 0074, Willy Susilo, Joonsang Baek
ProvSec (1)3
2024 Attribute-Based Proxy Re-Encryption With Direct Revocation Mechanism for Data Sharing in Clouds
abstract
Cloud computing, which provides adequate storage and computation capability, has been a prevalent information infrastructure. Secure data sharing is a basic demand when data was outsourced to a cloud server. Attribute-based proxy re-encryption has been a promising approach that allows secure encrypted data sharing on clouds. With attribute-based proxy re-encryption, a delegator can designate a set of shared users through issuing a re-encryption key which will be used by the cloud server to transform the delegator's encrypted data to the shared users’. However, the existing attribute-based proxy re-encryption schemes lack a mechanism of revoking users from the sharing set which is critical for data sharing systems. Therefore, in this article, we propose a concrete attribute-based proxy re-encryption with direct revocation mechanism (ABPRE-DR) for encrypted data sharing that enables the cloud server to directly revoke users from the original sharing set involved in the re-encryption key. We implemented the new schemes and evaluated its performance. The experimental results show that the proposed ABPRE-DR scheme is efficient and practical.
Chunpeng Ge 0001, Willy Susilo, Zhe Liu 0001, Joonsang Baek, Xiapu Luo, Liming Fang 0001
IEEE Trans. Dependable Secur. Comput.4
2023 Hyron: A New Approach for Automating the Network ACL Delivery Pipeline
abstract
Automated Access Control List (ACL) configuration has remained an area of research interest for a significant period. However, previous research has not addressed the challenges associated with ACL automation in the context of a complex and evolving industry landscape. We examine the existing research literature on this topic and identify a series of key requirements (“success criteria”) that any new system must achieve to be considered an improvement over the status quo. We then design, develop, and demonstrate an approach to ACL automation that embodies these characteristics by combining model-driven ACL synthesis with a modern DevOps-style deployment system. We explain the rationale that drove the design decisions behind the Hyron ACL generation toolkit and how it can enable a fully automated ACL delivery pipeline when integrated with standard developer tools. In contrast to previous research, our design approach reflects automation trends in the industry to ensure mainstream engineers readily adopt our solution. We provide an analysis comparing our approach's benefits to those of previous research.
Jacob Neil Taylor, Ngoc-Thuy Le, Joonsang Baek, Willy Susilo
ICCCN3
2023 Withdrawable Signature: How to Call Off a Signature
Xin Liu 0074, Joonsang Baek, Willy Susilo
ISC2
2023 PCSF: Privacy-Preserving Content-Based Spam Filter
abstract
The purpose of privacy-preserving spam filtering is to inspect email while preserving the privacy of its detection rules and the email content. Although many solutions have emerged, they suffer from the following: 1) Theprivacyprovided is insufficient as the email content or detection rules may be exposed to third parties; 2) Due to improper use of encryption, exhaustive word search attacks are possible, potentially breaking theconfidentialityof encrypted emails; 3) When spam filtering is outsourced, email is given to the outsource, whereuser privacy may be compromisedif privacy protection measures are not properly put in place; 4) Confirmation of whether the encrypted email is spam is only determinedafterthe receiver receives the email, which can lead to a situation in which spam is loaded to the memory of the receiver’s terminal for spam filtering. This can be harmful, for example, when an attacker inserts a web browser vulnerability into the body of an email to lure users to a phishing site simply by reading the email; 5)Computationally expensive operationsare unavoidable to provide required features of privacy-preserving spam filtering. We present Privacy-preserving Content-based Spam Filter (PCSF), which is a spam filter system that does not suffer from the aforementioned issues. Additionally, our system providespre-validationbefore the receiver reads the email. We provide an implementation of our system based on the Naive Bayes spam filter and prove its security.
Intae Kim, Willy Susilo, Joonsang Baek, Jongkil Kim, Yang-Wai Chow
IEEE Trans. Inf. Forensics Secur.3
2022 Revocable Attribute-Based Encryption With Data Integrity in Clouds
abstract
Cloud computing enables enterprises and individuals to outsource and share their data. This way, cloud computing eliminates the heavy workload of local information infrastructure. Attribute-based encryption has become a promising solution for encrypted data access control in clouds due to the ability to achieve one-to-many encrypted data sharing. Revocation is a critical requirement for encrypted data access control systems. After outsourcing the encrypted attribute-based ciphertext to the cloud, the data owner may want to revoke some recipients that were authorized previously, which means that the outsourced attribute-based ciphertext needs to be updated to a new one that is under the revoked policy. The integrity issue arises when the revocation is executed. When a new ciphertext with the revoked access policy is generated by the cloud server, the data recipient cannot be sure that the newly generated ciphertext guarantees to be decrypted to the same plaintext as the originally encrypted data, since the cloud server is provided by a third party, which is not fully trusted. In this article, we consider a new security requirement for the revocable attribute-based encryption schemes: integrity. We introduce a formal definition and security model for the revocable attribute-based encryption with data integrity protection (RABE-DI). Then, we propose a concrete RABE-DI scheme and prove its confidentiality and integrity under the defined security model. Finally, we present an implementation result and provide performance evaluation which shows that our scheme is efficient and practical.
Chunpeng Ge 0001, Willy Susilo, Joonsang Baek, Zhe Liu 0001, Jinyue Xia, Liming Fang 0001
IEEE Trans. Dependable Secur. Comput.3
2022 A Verifiable and Fair Attribute-Based Proxy Re-Encryption Scheme for Data Sharing in Clouds
abstract
To manage outsourced encrypted data sharing in clouds, attribute-based proxy re-encryption (ABPRE) has become an elegant primitive. In ABPRE, a cloud server can transform an original recipient’s ciphertext to a new one of a shared user’s. As the transformation is computation consuming, a malicious cloud server may return an incorrect re-encrypted ciphertext to save its computation resources. Moreover, a shared user may accuse the cloud server of returning an incorrect re-encrypted ciphertext to refuse to pay the cost of using the cloud service. However, existing ABPRE schemes do not support a mechanism to achieve verifiability and fairness. In this article, a novel verifiable and fair attribute-based proxy re-encryption (VF-ABPRE) scheme is introduced to support verifiability and fairness. The verifiability enables a shared user to verify whether the re-encrypted ciphertext returned by the server is correct and the fairness ensures a cloud server escape from malicious accusation if it has indeed conducted the re-encryption operation honestly. Additionally, we conduct a performance experiment to show the efficiency and practicality of the new VF-ABPRE scheme.
Chunpeng Ge 0001, Willy Susilo, Joonsang Baek, Zhe Liu 0001, Jinyue Xia, Liming Fang 0001
IEEE Trans. Dependable Secur. Comput.3
2022 Harnessing Policy Authenticity for Hidden Ciphertext Policy Attribute-Based Encryption
abstract
The field of cryptography has endeavored to solve numerous security problems. However, a common premise of many of those problems is that the encryptor always generates the ciphertext correctly. Around 10 years ago, this premise was not a problem. However, due to the rapid development and the use of the cloud, which has introduced various access policies and functionalities to provide higher security, it is not correct to assume that this premise is always applied. A “Fake Policy Attack”, which we introduce in this article, is an attack that incorrectly sets the access policy of the ciphertext against the system rules so that users who do not meet the rules can decrypt the ciphertext. In other words, it is an attack that ignores the rules of the system and eventually breaks the security and leaks information. This attack can be more critical for the application environments that require strong security not to leak any related information about ciphertext. In this article, we demonstrate the possible threat of the Fake Policy Attack by providing two relevant examples. Then, we propose a scheme called Policy Authenticable ABE (PA-ABE) to resolve this issue. We provide a formal security analysis of the proposed scheme and performance evaluation results based on our implementation.
Intae Kim, Willy Susilo, Joonsang Baek, Jongkil Kim
IEEE Trans. Dependable Secur. Comput.3
2022 Security Analysis of "SMAKA: Secure Many-to-Many Authentication and Key Agreement Scheme for Vehicular Networks"
abstract
In the above article, Zhanget al.(2021) proposed a many-to-many authentication and key agreement scheme named SMAKA for secure authentication and key agreement between multiple vehicles and cloud service providers (CSPs) in a vehicular network. However, we identify a security flaw in the design of Zhanget al.’s scheme, which allows an attacker to hijack an authentication session between a vehicle and a CSP and impersonate the vehicle to establish a shared key with the CSP with a high chance.
Willy Susilo, Joonsang Baek
IEEE Trans. Inf. Forensics Secur.3
2021 P2DPI: Practical and Privacy-Preserving Deep Packet Inspection
abstract
The amount of encrypted Internet traffic almost doubles every year thanks to the wide adoption of end-to-end traffic encryption solutions such as IPSec, TLS and SSH. Despite all the benefits of user privacy the end-to-end encryption provides, the encrypted internet traffic blinds intrusion detection system (IDS) and makes detecting malicious traffic hugely difficult. The resulting conflict between the user's privacy and security has demanded solutions for deep packet inspection (DPI) over encrypted traffic. The approach of those solutions proposed to date is still restricted in that they require intensive computations during connection setup or detection. For example, BlindBox, introduced by Sherry et al. (SIGCOMM 2015) enables inspection over the TLS-encrypted traffic without compromising users' privacy, but its usage is limited due to a significant delay on establishing an inspected channel. PrivDPI, proposed more recently by Ning et al. (ACM CCS 2019), improves the overall efficiency of BlindBox and makes the inspection scenario more viable. Despite the improvement, we show in this paper that the user privacy of Ning et al.'s PrivDPI can be compromised entirely by the rule generator without involving any other parties, including the middlebox. Having observed the difficulties of realizing efficiency and security in the previous work, we propose a new DPI system for encrypted traffic, named "Practical and Privacy-Preserving Deep Packet Inspection (P2DPI)''. P2DPI enjoys the same level of security and privacy that BlindBox provides. At the same time, P2DPI offers fast setup and encryption and outperforms PrivDPI. Our results are supported by formal security analysis. We implemented our P2DPI and comparable PrivDPI and performed extensive experimentation for performance analysis and comparison.
Jongkil Kim, Seyit Ahmet Çamtepe, Joonsang Baek, Willy Susilo, Josef Pieprzyk, Surya Nepal
AsiaCCS3
2021 Utilizing QR codes to verify the visual fidelity of image datasets for machine learning
Yang-Wai Chow, Willy Susilo, Jianfeng Wang 0001, Richard Buckland, Joonsang Baek, Jongkil Kim, Nan Li 0007
J. Netw. Comput. Appl.5
2020 Efficient Anonymous Multi-group Broadcast Encryption
Intae Kim, Seong Oun Hwang, Willy Susilo, Joonsang Baek, Jongkil Kim
ACNS (1)4
2020 Inspecting TLS Anytime Anywhere: A New Approach to TLS Interception
abstract
Transport Layer Security (TLS) is one of the most widely-used security protocols for the modern internet. However, TLS does not differentiate regular users from threat actors who want to evade detection through the privacy provided by TLS. For this reason, organizations have been increasingly interested in middlebox technology whereby encrypted TLS traffic can be filtered and inspected.
Joonsang Baek, Jongkil Kim, Willy Susilo
AsiaCCS1
2019 Ciphertext-Delegatable CP-ABE for a Dynamic Credential: A Modular Approach
Jongkil Kim, Willy Susilo, Joonsang Baek, Surya Nepal, Dongxi Liu
ACISP3
2019 A New Encoding Framework for Predicate Encryption with Non-linear Structures in Prime Order Groups
Jongkil Kim, Willy Susilo, Fuchun Guo, Joonsang Baek, Nan Li 0007
ACNS4
2019 Identity-Based Broadcast Encryption with Outsourced Partial Decryption for Hybrid Security Models in Edge Computing
abstract
Each layer of nodes and communication networks in edge computing, from cloud to the end device (i.e, often considered as resource-constrained IoT devices), exhibits a different level of trust for each stakeholder - e.g., edge nodes may not be fully trusted by IoT devices and the cloud. Moreover, asymmetric nature of resources between layers makes it hard to establish a balance between security and performance - e.g., lightweight cryptography may degrade security level against untrusted nodes while heavyweight ones may not be feasible for the light-weight end devices. An advanced encryption scheme such as the Identity-Based Broadcast Encryption (IBBE) is a popular technique to reduce storage and communication overhead. However, IBBE requires heavy computation to the end devices and still does not fully satisfy the security requirements that exist in the layers of edge computing. This paper presents a new IBBE with outsourced partial decryption for hybrid security models that each layer in edge computing requires. It balances the computational overhead based on asymmetric nature that nodes in each layer have. Particularly, with new schemes, the ciphertext can be transformed from its initial format. The cloud encrypts their data for multiple end devices and store them in the edge nodes, but those interim nodes can blindly transform the ciphertext from the cloud into a form which (i) is decryptable by only an authorized end device, and (ii) imposes smaller decryption and data transmission burden to end devices, regardless of the number of recipients. Our security analysis shows that new schemes are selectively and adaptively secure. We implement our solution and show that new schemes reduce the communication overhead from an edge node to end devices and the computation overhead on the end devices, compared to the original IBBE schemes.
Jongkil Kim, Seyit Ahmet Çamtepe, Willy Susilo, Surya Nepal, Joonsang Baek
AsiaCCS5
2017 Covert QR Codes: How to Hide in the Crowd
Yang-Wai Chow, Willy Susilo, Joonsang Baek
ISPEC3
2017 How to Protect ADS-B: Confidentiality Framework and Efficient Realization Based on Staged Identity-Based Encryption
abstract
Automatic Dependent Surveillance-Broadcast (ADS-B) is one of the key technologies for future “e-Enabled” aircrafts. ADS-B uses avionics in the e-Enabled aircrafts to broadcast essential flight data such as call sign, altitude, heading, and other extra positioning information. On the one hand, ADS-B brings significant benefits to the aviation industry, but, on the other hand, it could pose security concerns as channels between ground controllers and aircrafts for the ADS-B communication are not secured, and ADS-B messages could be captured by random individuals who own ADS-B receivers. In certain situations, ADS-B messages contain sensitive information, particularly when communications occur among mission-critical civil airplanes. These messages need to be protected from any interruption and eavesdropping. The challenge here is to construct an encryption scheme that is fast enough for very frequent encryption and that is flexible enough for effective key management. In this paper, we propose a Staged Identity-Based Encryption (SIBE) scheme, which modifies Boneh and Franklin's original IBE scheme to address those challenges, that is, to construct an efficient and functional encryption scheme for ADS-B system. Based on the proposed SIBE scheme, we provide a confidentiality framework for future e-Enabled aircraft with ADS-B capability.
Joonsang Baek, Eman Hableel, Young-Ji Byon, Duncan S. Wong, Kitae Jang, Hwasoo Yeo
IEEE Trans. Intell. Transp. Syst.1
2017 A New ADS-B Authentication Framework Based on Efficient Hierarchical Identity-Based Signature with Batch Verification
abstract
Automatic dependent surveillance-broadcast (ADS-B) has become a crucial part of next generation air traffic surveillance technology and will be mandatorily deployed for most of the airspaces worldwide by 2020. Each aircraft equipped with an ADS-B device keeps broadcasting plaintext messages to other aircraft and the ground station controllers once or twice per second. The lack of security measures in ADS-B systems makes it susceptible to different attacks. Among the various security issues, we investigate the integrity and authenticity of ADS-B messages. We propose a new framework for providing ADS-B with authentication based on three-level hierarchical identity-based signature (HIBS) with batch verification. Previous signature-based ADS-B authentication protocols focused on how to generate signatures efficiently, while our schemes can also significantly reduce the verification cost, which is critical to ADS-B systems, since at any time an ADS-B receiver may receive lots of signatures. We design two concrete schemes. The basic scheme supports partial batch verification and the extended scheme provides full batch verification. We give a formal security proof for the extended scheme. Experiment results show that our schemes with batch verification are tremendously more efficient in batch verifying n signatures than verifying n signatures independently. For example, the running time of verifying 100 signatures is 502 and 484 ms for the basic scheme and the extended scheme respectively, while the time is 2500 ms if verifying the signatures independently.
Anjia Yang, Xiao Tan 0003, Joonsang Baek, Duncan S. Wong
IEEE Trans. Serv. Comput.3
2016 Lightweight Encryption for Smart Home
abstract
Smart home is one of the most popular IoT (Internet of Things) applications, which connects a wide variety of objects and home appliances in a single logical network. Smart home applications have benefited from interactions and data transmissions among different devices over the integrated network with or without human interventions. However, like other technologies, smart home likely introduces new security vulnerabilities due to its dynamic and open nature of connectivity with heterogeneous features. Among such vulnerabilities, is the breach of confidentiality which needs to be addressed urgently as data exchanged between smart home devices can contain crucial information related to user's privacy and safety. However, some of the challenges in providing smart home system with confidentiality service are the flexibility of key management and efficiency of computation and communication. These challenges should be addressed carefully as many small and resource-constrained devices are usually involved in smart home systems. In this paper, we address these challenges by proposing a lightweight encryption scheme for smart homes. This scheme will provide users and smart objects with confidentiality service without incurring much overhead cost associated with computation and communication. Our proposed scheme also supports flexible public key management through adopting identity-based encryption, which does not require complex certificate handling. We provide a formal security analysis of our scheme and a performance simulation study. The simulation shows that our scheme provides favorable level of efficiency in terms of overhead cost associated with computation and communication.
Sanaah Al Salami, Joonsang Baek, Khaled Salah 0001, Ernesto Damiani
ARES2
2016 Efficient Generic Construction of CCA-Secure Identity-Based Encryption from Randomness Extraction
abstract
We propose a generic construction that yields efficient identity-based encryption (IBE) schemes secure against chosen ciphertext attack (CCA) in the standard model. Our construction extends Kiltz et al.'s (Eurocrypt '09) method of constructing CCA-secure public-key encryption schemes via randomness extraction to the identity-based setting. The main idea of our construction is to transform ‘|$\epsilon _1$|-almost |$\kappa $|-entropic’ and valid/invalid ciphertext indistinguishable (VI-IND) identity-based hash proof system to the one that satisfies the stronger ‘|$\epsilon _2$|-universal’ and VI-IND property. This transformation is realized by a randomness extractor based on the 4-wise hash function. We demonstrate that our generic construction can produce CCA-secure IBE schemes whose efficiency is comparable with the most efficient but non-generic CCA-secure IBE schemes without random oracles in the literature.
Joonsang Baek, Duncan S. Wong, Jin Li 0002, Man Ho Au
Comput. J.1
2015 On the Power Consumption of Cryptographic Processors in Civil Microdrones
abstract
In this paper we analyze the security requirements of civil microdrones and propose a hardware architecture to meet these requirements. While hardware solutions are usually used to accelerate cryptographic operations and reduce their power consumption, we show that the latter aspect needs to be reviewed in the context of civil drones. Specifcally, adding cryptgraphic hardware to a flying device increases its weight and, thus, the power needed to fly this device. Depending on the relative weight of the added cryptographic processor, the computational power advantage of the hardware solution may be undone by the additional hadrware weight. This aspect is analyzed for the proposed hardware solution.
Abdulhadi Shoufan, Hassan Alnoon, Joonsang Baek
ICISSP3
2015 Making air traffic surveillance more reliable: a new authentication framework for automatic dependent surveillance-broadcast (ADS-B) based on online/offline identity-based signature
abstract
Abstract Automatic dependent surveillance‐broadcast is an emerging surveillance technology for the future “e‐enabled” aircrafts, which will make it possible for aircrafts to share their location data with neighboring aircrafts, ground controllers, and other interested parties. In order to provide the automatic dependent surveillance‐broadcast communications with a high level of accuracy and integrity, a reliable authentication mechanism is required. So far, however, very few cryptographic solutions have been offered to achieve this in the literature. Even existing solutions have faced the following challenges: (i) the authentication solutions based on regular digital signature require complex management of public‐key infrastructureell; and (ii) signing messages exchanged or broadcast frequently in aircraft‐to‐aircraft and aircraft‐to‐ground communication modes can cause a computational bottleneck easily. In order to address these challenges, we take a fresh approach to building up an authentication framework by introducing a new online/offline identity‐based signature scheme. Our scheme will resolve the public‐key infrastructure management issue by using the identities of aircrafts as public keys and will achieve a high efficiency through online/offline signature generation. Copyright © 2014 John Wiley & Sons, Ltd.
Joonsang Baek, Young-Ji Byon, Eman Hableel, Mahmoud Al-Qutayri
Secur. Commun. Networks1
2015 A Secure Cloud Computing Based Framework for Big Data Information Management of Smart Grid
abstract
Smart grid is a technological innovation that improves efficiency, reliability, economics, and sustainability of electricity services. It plays a crucial role in modern energy infrastructure. The main challenges of smart grids, however, are how to manage different types of front-end intelligent devices such as power assets and smart meters efficiently; and how to process a huge amount of data received from these devices. Cloud computing, a technology that provides computational resources on demands, is a good candidate to address these challenges since it has several good properties such as energy saving, cost saving, agility, scalability, and flexibility. In this paper, we propose a secure cloud computing based framework for big data information management in smart grids, which we call “Smart-Frame.” The main idea of our framework is to build a hierarchical structure of cloud computing centers to provide different types of computing services for information management and big data analysis. In addition to this structural framework, we present a security solution based on identity-based encryption, signature and proxy re-encryption to address critical security issues of the proposed framework.
Joonsang Baek, Quang Hieu Vu, Joseph K. Liu, Xinyi Huang 0001, Yang Xiang 0001
IEEE Trans. Cloud Comput.1
2013 Public key infrastructure for UAE: a case study
abstract
Establishing online services can bring significant advantages for users and for the businesses. However, it has many issues related to integrity and confidentiality. Adopting public key cryptography is important to provide high level of confidentiality and authentication services for online transactions, but it needs a trusted way of distributing public keys. Public Key Infrastructure (PKI) is a solution for assuring the authenticity of public keys via qualified digital certificates. The first part of this paper covers the basic concept of PKI and overview of its implementation, and the related issues on digital certificates and X.509 standard. The second part covers the case study of UAE's implementation of the PKI focusing on the Emirate ID's smart card experience. Finally, this paper discusses about the attacks that threaten the PKI.
Eman Hableel, Young-Ji Byon, Joonsang Baek
SIN3
2013 Stateful Public-Key Encryption Schemes Forward-Secure Against State Exposure
abstract
We put forward a notion of forward security for stateful public-key encryption against state exposure and chosen ciphertext attack. This new notion is important in mobile applications in which small devices that perform ‘stateful encryptions’ are vulnerable to attacks which can result in the compromise of internal states. We precisely formulate a security definition and propose two efficient schemes which are provably secure under standard computational assumptions.
Joonsang Baek, Quang Hieu Vu, Abdulhadi Shoufan, Andrew Jones 0002, Duncan S. Wong
Comput. J.1
2012 Efficient Generic Construction of Forward-Secure Identity-Based Signature
abstract
We propose an efficient generic construction of forward-secure identity-based signature (FSIBS) that ensures unforgeability of past signatures in spite of the exposure of the current signing key. Our construction, supported by formal security analysis, brings about concrete FSIBS schemes which are more efficient than existing schemes in the literature. Especially, one of our instantiations of FSIBS based on discrete-log primitive turns out to be the most efficient among existing ones. As a secondary contribution, we refine the definition of security of FSIBS in such a way that users in the system can freely specify time periods over which their signing keys evolve.
Noura Al Ebri, Joonsang Baek, Abdulhadi Shoufan, Quang Hieu Vu
ARES2
2011 Compact identity-based encryption without strong symmetric cipher
abstract
In order to construct a CCA-secure (i.e. secure against chosen ciphertext attack) public key encryption scheme using the usual KEM/DEM (Key Encapsulation Mechanism/Data Encapsulation Mechanism) framework, one needs KEM and DEM schemes, both of which are CCA-secure. A CCA-secure DEM scheme can be constructed in a various way, but in order to construct a hybrid scheme producing ciphertexts of compact size, the DEM scheme needs to be a length-preserving symmetric cipher. However, it has been pointed out in the recent literature that the length-preserving symmetric cipher is in fact fairly expensive to realize because one needs strong PRP (pseudo random permutation) which is complex. As alternatives to the KEM/DEM framework for constructing compact hybrid encryption have been introduced in the public key (non identity-based) setting. In this paper, as contributions to this line of research, we construct hybrid identity-based encryption schemes which produce compact ciphertexts while providing both efficiency and strong security without resorting to the strong length-preserving symmetric cipher. In particular, all of the proposed schemes incur only one group element ciphertext expansion (defined as the size of the ciphertext minus the size of the plaintext message) and do not depend on the strong PRP. We provide security analysis of our schemes against chosen ciphertext attack under the well-known computational assumptions, in the random oracle model. We believe that our schemes are suitable for implementing on small devices.
Joonsang Baek, Jianying Zhou 0001
AsiaCCS1
2011 On the security of the identity-based encryption based on DHIES from ASIACCS 2010
abstract
In ASIACCS 2010, Chen, Charlemagne, Guan, Hu and Chen proposed an interesting construction of identity-based encryption based on DHIES, whose key extraction algorithm makes use of the multivariate quadratic equation. They proved that their scheme is selective-ID secure against chosen ciphertext attack, i.e. secure in the sense of IND-sID-CCA. Unfortunately, in this paper, we demonstrate that Chen et al.'s scheme is insecure in the sense of IND-sID-CCA by showing that the private key extraction algorithm of their scheme can be exploited to apply XL algorithm, which is to solve the multivariate quadratic (MQ) problem (under certain conditions).
Willy Susilo, Joonsang Baek
AsiaCCS2
2011 On Shortening Ciphertexts: New Constructions for Compact Public Key and Stateful Encryption Schemes
Joonsang Baek, Cheng-Kang Chu, Jianying Zhou 0001
CT-RSA1
2010 Online/Offline Identity-Based Signcryption Revisited
Joseph K. Liu, Joonsang Baek, Jianying Zhou 0001
Inscrypt2
2009 A New Variant of the Cramer-Shoup KEM Secure against Chosen Ciphertext Attack
Joonsang Baek, Willy Susilo, Joseph K. Liu, Jianying Zhou 0001
ACNS1
2009 Certificate-based sequential aggregate signature
abstract
In this paper, we propose a new notion called Certificate-Based Sequential Aggregate Signature. Certificate-based cryptography proposed by Gentry [8] combines the merit of traditional public key cryptography and identity based cryptography, without use of the costly certificate chain verification process and the removal of key escrow security concern. Under this paradigm, we propose a first sequential aggregate signature. An aggregate signature scheme produces a short string that convinces any verifier that there are $n$ messages signed by $n$ parties, all of which may be distinct. The length of the string is a constant which is independent of $n$. Its compactness makes it particularly suitable to be employed in those environments where communication bandwidth is very limited, such as wireless network scenarios (e.g. MANETS, cellular networks, sensor networks, satellite communication). We provide a concrete construction of this new notion and prove its security in the random oracle model.
Joseph K. Liu, Joonsang Baek, Jianying Zhou 0001
WISEC2
2008 Generic Constructions of Stateful Public Key Encryption and Their Applications
Joonsang Baek, Jianying Zhou 0001, Feng Bao 0001
ACNS1
2008 Public Key Encryption with Keyword Search Revisited
Joonsang Baek, Reihaneh Safavi-Naini, Willy Susilo
ICCSA (1)1
2008 Certificate-Based Signature Schemes without Pairings or Random Oracles
Joseph K. Liu, Joonsang Baek, Willy Susilo, Jianying Zhou 0001
ISC2
2008 Realizing Stateful Public Key Encryption in Wireless Sensor Network
Joonsang Baek, Han Chiang Tan, Jianying Zhou 0001, Jun Wen Wong
SEC1
2007 Strongly Secure Certificateless Public Key Encryption Without Pairing
Yinxia Sun, Futai Zhang, Joonsang Baek
CANS3
2007 New constructions of fuzzy identity-based encryption
abstract
In this paper we construct two new fuzzy identity-based encryption (IBE) schemes in the random oracle model. Not only do our schemes provide public parameters whose size is independent of the number of attributes in each identity (used as public key) but they also have useful structures which result in more efficient key extraction and/or encryption than the random oracle version of Sahai and Water's fuzzy IBE scheme, considered recently by Pirretti et al. We prove that the confidentiality of the proposed schemes is relative to the Bilinear Decisional Bilinear Diffie-Hellman problem.
Joonsang Baek, Willy Susilo, Jianying Zhou 0001
AsiaCCS1
2007 Concurrently-secure credential ownership proofs
abstract
We address the case in credential systems where a credential owner wants to show her credential to a verifier without taking the risk that the ability to prove ownership of the same (and any other) credential is transferred to the verifier. We define credential ownership proof protocols for credentials signed by standard signature schemes. We also propose proper security definitions for the protocol, aiming to protect the security of both the credential issuer and the credential owner against concurrent attacks. We give two generic constructions of credential ownership proofs based on identity-based encryption and identity-based identification schemes. Furthermore, we show that signatures with credential ownership proofs are equivalent to identity-based identification schemes, in the sense that any secure construction of each implies a secure construction of the other. Finally, we show that the GQ identification protocol yields an efficient credential ownership proof for credentials signed by the RSA-FDH signature scheme of Bellare and Rogaway and prove the protocol concurrently-secure.
Siamak F. Shahandashti, Reihaneh Safavi-Naini, Joonsang Baek
AsiaCCS3
2007 Formal Proofs for the Security of Signcryption
Joonsang Baek, Ron Steinfeld, Yuliang Zheng 0001
J. Cryptol.1
2006 Self-organised group key management for ad hoc networks
abstract
We propose a fully distributed group key distribution protocol for ad hoc networks. The protocol uses a key pre-distribution step that is performed by each node independently and generates secure links between nodes in a neighbourhood. The key pre-distribution step also allows formation of an initiator group who will generate a session key that will be distributed to all nodes using the secure links between nodes obtained in key pre-distribution stage. We describe efficient protocols for join of new nodes and revocation of compromised nodes. We analyse the system by calculating probability of success of each operation. We evaluate security of the system against outside eavesdroppers and discuss its security against an adversary that corrupts the nodes of the network. Finally we compare our system with two competing systems and show its superior performance in some scenarios.
Reihaneh Safavi-Naini, Joonsang Baek, Willy Susilo
AsiaCCS3
2006 On the Integration of Public Key Data Encryption and Public Key Encryption with Keyword Search
Joonsang Baek, Reihaneh Safavi-Naini, Willy Susilo
ISC1
2005 Universal Designated Verifier Signature Proof (or How to Efficiently Prove Knowledge of a Signature)
Joonsang Baek, Reihaneh Safavi-Naini, Willy Susilo
ASIACRYPT1
2005 Token-Controlled Public Key Encryption
Joonsang Baek, Reihaneh Safavi-Naini, Willy Susilo
ISPEC1
2005 Certificateless Public Key Encryption Without Pairing
Joonsang Baek, Reihaneh Safavi-Naini, Willy Susilo
ISC1
2003 Simple and efficient threshold cryptosystem from the Gap Diffie-Hellman group
abstract
In this paper, we construct a new threshold cryptosystem from the Gap Diffie-Hellman (GDH) group. The proposed scheme enjoys all the most important properties that a robust and practical threshold cryptosystem should possess, that is, it is noninteractive, computationally efficient and provably secure against adaptive chosen ciphertext attacks. In addition, thanks to the elegant structure of the GDH group, the proposed threshold cryptosystem has shorter decryption shares as well as ciphertexts when compared with other schemes proposed in the literature.
Joonsang Baek, Yuliang Zheng 0001
GLOBECOM1
2002 On the Necessity of Strong Assumptions for the Security of a Class of Asymmetric Encryption Schemes
Ron Steinfeld, Joonsang Baek, Yuliang Zheng 0001
ACISP2
2000 Secure Length-Saving ElGamal Encryption under the Computational Diffie-Hellman Assumption
Joonsang Baek, Byoungcheon Lee, Kwangjo Kim
ACISP1