Shipei Qu

dblp:362/2312 · DBLP profile ↗
← Back
5ranked-venue papers
2as first author
5since 2021 · last 2026
0009-0005-3324-0021ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 4 · 1 first-author · 4 since 2021Systems, architecture and hardware · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2026 Teamwork Makes TEE Work: Open and Resilient Remote Attestation on Decentralized Trust
abstract
Remote Attestation (RA) enables the integrity and authenticity of applications in Trusted Execution Environment (TEE) to be verified. Existing TEE RA designs employ a centralized trust model where they rely on a single provisioned secret key and a centralized verifier to establish trust for remote parties. This model is however brittle and can be untrusted under advanced attacks nowadays. Besides, most designs only have fixed procedures once deployed, making them hard to adapt to different emerging situations and provide resilient functionalities. Therefore, we proposeJanus, an open and resilient TEE RA scheme. To decentralize trust, we, on one hand, introduce Physically Unclonable Function (PUF) as an intrinsic root of trust (RoT) in TEE to directly provide physical trusted measurements. On the other hand, we design novel decentralized verification functions on smart contract with result audits and RA session snapshot. Furthermore, we design an automated switch mechanism that allowsJanusto remain resilient and offer flexible RA services under various situations. We provide a UC-based security proof and demonstrate the scalability and generality ofJanusby implementing an complete prototype.
Kailun Qin, Shipei Qu, Chi Zhang 0061, Dawu Gu
IEEE Trans. Dependable Secur. Comput.3
2025 End-to-End Non-profiled Side-Channel Analysis on Long Raw Traces
Jintong Yu, Shipei Qu, Yipeng Shi, Pei Cao 0002, Xiangjun Lu, Chi Zhang 0061, Dawu Gu
ESORICS (3)3
2025 Find the Clasp of the Chain: Efficiently Locating Cryptographic Procedures in SoC Secure Boot by Semi-automated Side-Channel Analysis
Shipei Qu, Jintong Yu, Chi Zhang 0061, Dawu Gu
ICICS (3)1
2025 Mind the Faulty Keccak: A Practical Fault Injection Attack Scheme Applied to All Phases of ML-KEM and ML-DSA
Jintong Yu, Shipei Qu, Chi Zhang 0061, Dawu Gu
IEEE Trans. Inf. Forensics Secur.3
2024 Trapped by Your WORDs: (Ab)using Processor Exception for Generic Binary Instrumentation on Bare-metal Embedded Devices
abstract
Analyzing the security of closed-source drivers and libraries in embedded systems holds significant importance, given their fundamental role in the supply chain. Unlike x86, embedded platforms lack comprehensive binary manipulating tools, making it difficult for researchers and developers to effectively detect and patch security issues in such closed-source components. Existing works either depend on full-fledged operating system features or suffer from tedious corner cases, restricting their application to bare-metal firmware prevalent in embedded environments.
Shipei Qu, Chi Zhang 0061, Dawu Gu
DAC1