VLDB 2026 Research / reviewers in the wild / expert
Qingfeng Cheng
dblp:48/7085
· DBLP profile ↗
41ranked-venue papers
5as first author
34since 2021 · last 2026
0000-0001-6149-4807ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 20 · 3 first-author · 17 since 2021Computer networks · 10 · 1 first-author · 8 since 2021Applied, interdisciplinary, general and emerging computing · 8 · 1 first-author · 8 since 2021Systems, architecture and hardware · 2Software engineering, systems software and programming languages · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Meet-LWE with Hints: Solving Ternary LWE with Information Leakage
Jinzheng Cao, Rongmao Chen, Haodong Jiang, Qingfeng Cheng |
ACISP (1) | 4 |
| 2026 | PAMA: Provable-Secure Anonymous Multifactor Authentication With Postquantum Security for IoT-Enabled E-Healthcare SystemsabstractThe booming technologies of the Internet of Things (IoT) enable various applications and develop well. E-healthcare system is one of the successful examples, where people manage their healthcare information, diagnosis data, physical examination results, and so on. These types of sensitive information cause crucial security risks, posing threats to the security of the lives and property of the people. Given this concern, safeguard measures, such as authentication and encryption, are necessary. However, due to the openness of the wireless networks, authentication protocols for IoT-enabled e-healthcare systems are usually vulnerable to serious attacks. Furthermore, the quantum era is around the corner, urging authentication protocols to possess post-quantum security properties. In this paper, we propose a multi-factor password authentication scheme, named PAMA, with post-quantum security for the e-healthcare system. The lattice cryptography is adopted for post-quantum security. We formally prove the proposed PAMA scheme to be secure, and also informally verify the security against common attacks. Furthermore, we compare the performance of the communication efficiency of the PAMA scheme with other related works from both theoretical and experimental aspects. The efficiency comparison results demonstrate that our PAMA scheme approximately reduces the computation cost by 37.59% and the energy consumption by 37.5%, compared to the related post-quantum schemes. In summary, the PAMA scheme has a great advantage in secure authentication and agreement on a session key in the e-healthcare system. Yuqian Ma, Yongliu Ma, Zhiquan Liu 0001, Qi Jiang 0001, Qingfeng Cheng |
IEEE Internet Things J. | 5 |
| 2026 | 2PCLGA: Privacy-Preserving and Provable-Secure Certificateless Group Key Agreement Scheme for the Distributed Learning-Based MEC NetworksabstractMachine learning is a rapidly evolving field with applications in all aspects of human life. Utilizing the decentralized computing architecture can alleviate the high training and computational burden of central servers and improve service accuracy. However, the inherent properties of decentralized networks pose great challenges to communication security. It is urgent to design novel and appropriate security schemes, as malicious adversaries are curious about user private information, sensing data, and service demands. Furthermore, end devices always cooperate to accomplish the service targets, which means that group security schemes are needed to protect transmissions among them. In this paper, a certificateless-based group authentication and key agreement (CL-GAKA) scheme is proposed, named 2PCLGA, for distributed learning-based mobile edge computing (DL-MEC) networks. The proposed scheme establishes a session key among the end device group with the group leader MEC server based on the elliptic curve cryptography. Besides, the 2PCLGA scheme adopts dynamic pseudonym identity technology to realize the anonymity. The provable security analysis under the random oracle model, the formal analysis tool, and the informal analysis are adopted. The performance of 2PCLGA is also evaluated with the benchmarks, and the results show that the 2PCLGA scheme is greatly applicable to the resource-constrained circumstance. Yuqian Ma, Qingfeng Cheng, Zhiquan Liu 0001, Xiangyang Luo 0001, Xiaofeng Chen 0001 |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2025 | Refined Attack on LWE with Hints: Constructing Lattice via Gaussian Elimination
Jinzheng Cao, Haodong Jiang, Qingfeng Cheng |
CRYPTO (1) | 3 |
| 2025 | Fault attacks on multi-prime RSA signatures
Chunzhi Zhao, Jinzheng Cao, Qingfeng Cheng |
Des. Codes Cryptogr. | 4 |
| 2025 | LB3AS: Lightweight Blockchain-Assisted Anonymous Authentication Scheme for Fog-Cloud-Based Internet of Medical ThingsabstractThe flourishing development of the Internet of Medical Things (IoMT) is bringing personalized and timely healthcare to an increasing number of people. Fog-cloud-based IoMT pushes computing and data processing to the edge network, enabling low latency and real-time response. However, the heterogeneity of IoMT and medical data privacy make designing secure and efficient authentication schemes a highly challenging task. In this article, we first design a blockchain-assisted fog-cloud-based IoMT authentication architecture, leveraging blockchain technology to enhance the security and efficiency of medical data sharing. Additionally, we propose a novel anonymous authentication scheme that utilizes lightweight cryptographic primitives, physically unclonable functions, and fuzzy extractors suitable for resource-constrained IoMT devices. We use formal and informal security analysis to prove the security of the proposed scheme. Furthermore, we evaluate the performance of the proposed scheme from the perspectives of computation, communication, energy, average delay time, and smart contract resource consumption. Compared to five related schemes, our scheme achieves higher security while maintaining low resource consumption. Yuqian Ma, Qingfeng Cheng, Xiaofeng Chen 0001, Xiangyang Luo 0001 |
IEEE Internet Things J. | 3 |
| 2025 | An Improved Anonymous Authentication Protocol in Wireless Body Area NetworksabstractWireless body area networks (WBANs) are technologies that create wireless networks around the human body by embedding sensors into wearable devices to collect health data. WBANs are mainly used for real-time health monitoring, motion tracking, and emergency medical services, with advantages, such as low energy consumption, short-range communication, and high data security. However, user privacy protection and communication security during transmission are important considerations in the design of WBANs communication. To address the aforementioned issues, this article presents a secure authentication key agreement protocol in WBANs. Through Scyther software analysis, it demonstrates the protocol satisfies security attributes, such as user anonymity, known session key security, forward security, resistance to ephemeral key leakage attacks, and resistance to impersonation attacks. The protocol has also been verified to be secure within the eCK model. Moreover, this article compares the security attributes, computation cost, communication consumption, energy consumption, and average delay time of the proposed protocol with other authentication key agreement protocols. It is found that the proposed protocol has excellent performance while ensuring communication security, and strikes a balance between security effectiveness and resource overhead. Yongliu Ma, Yuqian Ma, Qingfeng Cheng |
IEEE Internet Things J. | 4 |
| 2025 | A novel blockchain-based anonymous roaming authentication scheme for VANET
Qingfeng Cheng |
J. Inf. Secur. Appl. | 2 |
| 2025 | CSAP-IoD: A Chaotic Map-Based Secure Authentication Protocol for Internet of DronesabstractInternet of Drones (IoD) provides a new mode of information collection and data transmission. With the assistance of 6G mobile communication facilities and artificial intelligence technology, the IoD system progressively enables real-time communication among remote users, ground control centers and drone clusters. At the same time, the dynamically updated, open, and interoperable communication environment also poses some risks to the IoD system’s security and privacy. The security attributes of the IoD system are insufficiently met by the authentication schemes currently in use. In light of the aforementioned factors, this paper suggests CSAP-IoD, a lightweight secure communication protocol for anonymous interactions that uses the initial value sensitivity and orbital unpredictability of chaotic map. It utilizes fuzzy verifier technology to achieve three-factor security and facilitates mutual authentication and key agreement among the three-party communicating entities of IoD. Real-or-Random (ROR) model, informal security analysis, and the Scyther tool are used to assess the protocol’s security in multiple dimensions, and it has been demonstrated that CSAP-IoD can withstand a variety of attacks. Based on simulation results and a detailed comparison with state-of-the-art IoD communication protocols in terms of security features, computation cost, communication cost, and energy consumption, CSAP-IoD shows the optimal security performance while emphasizing the efficiency advantage, offering a dependable solution to guarantee the information security of IoD system communication. Jintian Zhang, Qingfeng Cheng, Xiaofeng Chen 0001, Xiangyang Luo 0001 |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2025 | A Blockchain-Based Cross-Domain Data Transmission Scheme for Industrial Internet of Things With Edge-Cloud ComputingabstractThe rapid evolution of the Industrial Internet of Things (IIoT) and widespread adoption of smart devices have profoundly reshaped traditional industrial production and management. Facilitated cross-domain data transmission between these devices has greatly boosted intelligence and efficiency in IIoT. Yet despite progress in cross-domain transmission, existing schemes still face severe challenges: complex hierarchical architectures, cross-domain trust issues, and high computational costs. To tackle these problems, we propose a blockchain based cross-domain data transmission scheme for IIoT, integrated with edge-cloud computing. First, we enhance crossdomain transmission in edge-cloud environments by developing a lightweight blockchain-assisted framework, which cuts down redundant entity interactions. Second, we address inter-domain trust in IIoT by establishing trust relationships and computing relationship keys. Finally, we introduce a lightweight blockchain based authentication and key agreement protocol to simplify cross-domain data transmission between smart devices. Security analysis shows the proposed scheme achieves strong security in the real-or-random model, effectively resisting various potential threats. Performance analysis and blockchain simulations further confirm its practical applicability for IIoT deployment Qingfeng Cheng, Xiaofeng Chen 0001, Xiangyang Luo 0001 |
IEEE Trans. Serv. Comput. | 2 |
| 2024 | A survey on the application of blockchain in cryptographic protocolsabstractAbstract With the continuous development of network technology, cryptographic protocols are facing diverse and complex security challenges. Blockchain technology, as a solution incorporating decentralization, traceability, programmability, and immutability, effectively enhances the security, trustworthiness, operational efficiency, and ensures the security and integrity of data storage in traditional cryptographic protocols. Consequently, it has gradually emerged as a focal point of research in cryptographic protocols. This manuscript delves into the ongoing research concerning the application of blockchain technology in cryptographic protocols. First, this manuscript introduces the background of blockchain research in cryptographic protocols and the corresponding basic knowledge. Secondly, we delve into the main concerns of traditional cryptographic protocols, with a particular focus on security and performance. Thirdly, according to the main classification of cryptographic protocols, the latest research results of blockchain in authentication protocols, authentication and key agreement protocols, and e-commerce protocols are presented. Finally, the research directions of blockchain technology in cryptographic protocols are summarized based on the existing research, and the future development trend is also prospected. Qingfeng Cheng |
Cybersecur. | 4 |
| 2024 | An anonymous authentication and secure data transmission scheme for the Internet of Things based on blockchain
Qingfeng Cheng |
Frontiers Comput. Sci. | 2 |
| 2024 | Provable secure authentication key agreement for wireless body area networks
Yuqian Ma, Xinghua Li 0001, Qingfeng Cheng |
Frontiers Comput. Sci. | 4 |
| 2024 | SEA: Secure and Efficient Public Auditing for Edge-Assisted IoT Aggregated Data Sharing
Ning Lu 0005, Yihong Wen, Qingfeng Cheng |
Mob. Networks Appl. | 4 |
| 2024 | A Blockchain-Based Secure Covert Communication Method via Shamir Threshold and STC MappingabstractCovert communication is a crucial technology that hides information in the redundant structure of the file and transmission through public channel to achieve the secure delivery of information. The blockchain network, with the characteristics of anonymity, decentralization and tamper-proofing, can make up for the shortcomings of multimedia-based covert communication, which include the easy exposure of the identity for both parties, the vulnerability to destruction during communication and the weak robustness of the channel. Therefore, the blockchain network is an ideal channel for covert communication. Nevertheless, the existing covert communication methods face certain challenges based on blockchain, such as the lack of a secure channel for transferring the master key, low embedding capacity, and weak detection resistance. In view of this, this paper proposes a covert communication method based on Shamir threshold and STC mapping, which is suitable for public chain networks. The proposed method first decomposes the master key into sub-keys by introducing Shamir scheme, and the sub-keys are shared with the help of transaction amounts on a blockchain. Then, a mapping relation is established to ensure that the transaction amounts carrying the secret are evenly distributed. Finally, secret information is hidden in the mapping relationship and the transaction amount is interwoven, which is published to the blockchain through transactions to complete covert communication. The introduction of Shamir threshold breaks the limitation that master key cannot be safely transmitted due to the lack of a secure channel in the research of covert communication based on blockchain, thereby enhances the security of the method. Meanwhile, Shamir threshold scheme based on public chain, can solve the issue that the master key cannot be reconstructed due to dishonest participants providing invalid subkeys on traditional network. In addition, the proposed STC mapping can not only improve the detection resistance but also increase the embedding capacity. A series of experimental results illustrate that the proposed method is more resistant to detection, and the embedding efficiency is enhanced by 27.56 times compared with existing public chain-based covert communication methods, effectively reducing the number of transactions and saving resource consumption. Qingfeng Cheng, Mingliang Zhang 0001, Xiangyang Luo 0001 |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2023 | Quantum Augmented Lattice Attack on NTRU with Side Information
Qingfeng Cheng, Jinzheng Cao |
Inscrypt (2) | 1 |
| 2023 | Improved Herrmann-May's Attack with Merging Variables and Lower LLL Bound
Qingfeng Cheng, Chunzhi Zhao, Jinzheng Cao, Fushan Wei |
Inscrypt (2) | 1 |
| 2023 | Generalized attack on ECDSA: known bits in arbitrary positions
Jinzheng Cao, Jian Weng 0001, Yanbin Pan 0001, Qingfeng Cheng |
Des. Codes Cryptogr. | 4 |
| 2023 | A fine-grained privacy protection data aggregation scheme for outsourcing smart grid
Xinghua Li 0001, Qingfeng Cheng |
Frontiers Comput. Sci. | 3 |
| 2023 | 2PCLA: Provable Secure and Privacy Preserving Enhanced Certificateless Authentication Scheme for Distributed LearningabstractDistributed learning (DL) emerges as machine learning and the Internet of Things develop quickly and widely. As edge servers pre-process and pre-learn the statistics, global servers can reduce costs, improve efficiency and output more precise results. However, to acquire high-quality and adequate data, servers should collect information from a number of end devices, which naturally leads to confidentiality and privacy problems during information transmission. If the private information or the data are compromised by malicious attackers, the users’ security and the network operation will all be in danger. To resolve this thorny challenge, numerous schemes have been put forward, adopting different cryptography technologies and aiming at aspects of security. However, many state-of-the-art schemes can hardly satisfy the security demands and are pointed out to be defective. Lately, Jiang et al. made an effort and proposed a certificateless signature scheme, as well as an authentication scheme for the purpose of solving the privacy issues. Unfortunately, in this paper, we point out that their schemes can hardly resist forgery attacks and ephemeral key leakage attacks. Further, we will propose an improved scheme noted as 2PCLA and change the method of generating the session key. Theoretical analysis and formal security analysis utilizing Tamarin analysis tool are provided to prove the security of 2PCLA scheme. Performance evaluation has been done from both theoretical and experimental perspectives. The assessment results illustrate that 2PCLA can balance security properties with execution efficiency relatively well. Yuqian Ma, Qingfeng Cheng, Xiangyang Luo 0001 |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2022 | Handle the Traces: Revisiting the Attack on ECDSA with EHNP
Jinzheng Cao, Yanbin Pan 0001, Qingfeng Cheng, Xinghua Li 0001 |
ACISP | 3 |
| 2022 | BS: Blockwise Sieve Algorithm for Finding Short Vectors from Sublattices
Jinzheng Cao, Qingfeng Cheng, Xinghua Li 0001, Yanbin Pan 0001 |
ICICS | 2 |
| 2022 | An anonymous key agreement protocol with robust authentication for smart grid infrastructure
Qingfeng Cheng, Xinghua Li 0001 |
Sci. China Inf. Sci. | 2 |
| 2022 | Improvement on a batch authenticated key agreement scheme
Qingfeng Cheng, Siqi Ma 0001, Xinghua Li 0001 |
Frontiers Comput. Sci. | 1 |
| 2022 | An efficient and authenticated key establishment scheme based on fog computing for healthcare system
Xinghua Li 0001, Qingfeng Cheng, Jianfeng Ma 0001 |
Frontiers Comput. Sci. | 3 |
| 2022 | A Lightweight and Verifiable Access Control Scheme With Constant Size Ciphertext in Edge-Computing-Assisted IoTabstractAs an extension of cloud computing, edge computing has attracted the attention of academia and industry because of its characteristics of low latency, high bandwidth, and low energy consumption. However, due to limited terminal resources and insufficient security design, the edge computing environment still faces many challenges in terms of data security and privacy protection. Among them, how to effectively control access to outsourced data is one of the main issues. In this article, we propose a lightweight and verifiable ciphertext-policy attribute-based encryption (CP-ABE)-based multiauthority access control scheme for edge computing-assisted Internet of Things (IoT), which adopts the method of outsourcing decryption to mitigate the computational cost of data users with limited resources. In addition, our scheme realizes the feature of attribute revocation, and the design of the multiauthority mechanism enables our scheme to avoid the problem of key escrow. Therefore, our proposed scheme not only ensures data confidentiality but also can resist the collusion attack. Besides, our scheme is secure against the chosen plaintext attack in the random oracle model under the decision$q$-BDHE assumption. Finally, we compared our scheme with some related work in performance, and the results demonstrate that our scheme is efficient in computation and communication. Because our scheme greatly mitigates the overhead of data users, it is very suitable for edge computing supported IoT applications with restricted computation resources. Xiong Li 0002, Chaoyang Chen 0001, Qingfeng Cheng, Xiaosong Zhang 0001, Neeraj Kumar 0001 |
IEEE Internet Things J. | 4 |
| 2022 | A Certificateless Authentication and Key Agreement Scheme for Secure Cloud-assisted Wireless Body Area Network
Qingfeng Cheng, Xinghua Li 0001 |
Mob. Networks Appl. | 1 |
| 2022 | A Novel Covert Communication Method Based on Bitcoin TransactionabstractWith the global promotion and application of 5G technology, the data transmitted on the network show explosive growth, and the secure sharing of its important data is still one of the research hotspots. Steganography embeds the data that needs to be shared into digital carrier files and transmits it through open channels, which has important applications in protecting data sharing and realizing covert communication. However, the encrypted files generated by traditional steganography are susceptible to compression, cropping, geometric attacks, and man-made destruction in the process of open channel transmission, resulting in data loss, making it difficult for the receiver to correctly extract secret message. Currently, covert communication on blockchain can solve the above problems, but it also brings some new problems such as high computational complexity, low transmission efficiency, and nondetection resistance. Therefore, in this article, a covert communication method based on Bitcoin transactions is proposed. The proposed method first designs the index matrix of the transaction address. Then, the address interaction relationship that carries the secret message through the transaction index matrix is constructed. Finally, the address interaction relationship that carries the secret message is combined with the transaction amount to complete the covert transmission of the secret message on the blockchain environment. The proposed method improves the security and embedding efficiency of covert communication, reduces the number of transactions, and ensures the integrity of extracting secret message. A series of experimental results show that under the condition of ensuring the necessary security, the proposed method retains the strong robustness of the existing blockchain steganography and has strong resistance to detection. Xiangyang Luo 0001, Mingliang Zhang 0001, Hao Li 0087, Qingfeng Cheng |
IEEE Trans. Ind. Informatics | 5 |
| 2021 | A Lattice Reduction Algorithm Based on Sublattice BKZ
Jinzheng Cao, Yanbin Pan 0001, Qingfeng Cheng |
ProvSec | 3 |
| 2021 | An enhanced key exchange protocol exhibiting key compromise impersonation attacks resistance in mobile commerce environment
Xinghua Li 0001, Qingfeng Cheng |
Sci. China Inf. Sci. | 3 |
| 2021 | Smart Applications in Edge Computing: Overview on Authentication and Data SecurityabstractAs a new computing paradigm, edge computing has appeared in the public field of vision recently. Owing to its advantages of low delay and fast response, edge computing has become an important assistant of cloud computing and has brought new opportunities for diverse smart applications like the smart grid, the smart home, and the smart transportation. However, the accompanying security issues, which have always been the focus of users' concern, still cannot be ignored. Therefore, we focus on the security issues in this overview. We first introduce some related definitions of edge computing and present the architecture for edge computing-based smart applications. After illustrating the smart applications, from the perspective of identity authentication and data security, we analyze the security protection requirements of these smart applications in the edge computing environment. Next, we review some state-of-the-art works on them. Furthermore, we present the extended discussions on the applicability of these current works in the edge computing environment. Finally, we briefly discuss the future work on authentication and data security of edge computing-based smart applications. Xinghua Li 0001, Qingfeng Cheng, Siqi Ma 0001, Jianfeng Ma 0001 |
IEEE Internet Things J. | 3 |
| 2021 | Privacy-Preserving Implicit Authentication Protocol Using Cosine Similarity for Internet of ThingsabstractInternet of Things provides complicated value-added services to mobile intelligent terminal users. Different sensors collect various data from the users and transmit the data to the mobile intelligent terminal for storage. Consequently, a great amount of personal and sensitive information related to these rich and colorful applications is stored in the mobile intelligent terminal. Mobile intelligent terminals have become the prominent target of network attackers. Security breach and privacy leakage severely thread the application development of the Internet of Things. We present a privacy-preserving implicit authentication framework using users' behavior features sensed by the mobile intelligent terminal based on the artificial intelligence methodology. More precisely, we first summarize the security and privacy requirements for the security authentication of the mobile intelligent terminal. Then, we present a privacy-preserving implicit authentication framework using the cosine similarity and partial homomorphic public-key encryption scheme. Finally, a performance evaluation of the proposed protocol is conducted. The result shows that the communication and computation efficiency of our protocol is more efficient than other related protocols. Fushan Wei, Pandi Vijayakumar, Neeraj Kumar 0001, Qingfeng Cheng |
IEEE Internet Things J. | 5 |
| 2021 | Security Analysis of a Lightweight Identity-Based Two-Party Authenticated Key Agreement Protocol for IIoT EnvironmentsabstractInternet of Things brings convenience to the social life, at the same time, putting forward higher requirements for the security of data transmission and storage. Security incidents based on industrial Internet of Things have occurred frequently recently, which should be given full consideration. The identity-based authenticated key agreement protocol can solve these security threats to a certain extent. Recently, a lightweight identity-based authenticated key agreement protocol for Industrial Internet of Things, called ID-2PAKA protocol, was claimed to achieve secure authentication and meet security properties. In this paper, we show that the ID-2PAKA protocol is insecure in identity authentication and cannot resisting ephemeral key compromise impersonation attack. Qingfeng Cheng |
Secur. Commun. Networks | 2 |
| 2021 | Fast and Universal Inter-Slice Handover Authentication with Privacy Protection in 5G NetworkabstractIn a 5G network-sliced environment, mobility management introduces a new form of handover called inter-slice handover among network slices. Users can change their slices as their preferences or requirements vary over time. However, existing handover-authentication mechanisms cannot support inter-slice handover because of the fine-grained demand among network slice services, which could cause challenging issues, such as the compromise of service quality, anonymity, and universality. In this paper, we address these issues by introducing a fast and universal inter-slice (FUIS) handover authentication framework based on blockchain, chameleon hash, and ring signature. To address these issues, we introduce an anonymous service-oriented authentication protocol with a key agreement for inter-slice handover by constructing an anonymous ticket with the trapdoor collision property of chameleon hash functions. In order to reduce the computation overhead of the user side in the process of authentication, a privacy-preserving ticket validation with a ring signature is designed to finish in the consensus phase of the blockchain in advance. Thanks to the edge computing capabilities in 5G, distributed edge nodes help to store the anonymous ticket information, which guarantees that the legal users can finish authentication swiftly during handover. Our scheme's performance is evaluated through simulation experiments to testify the efficiency and feasibility in a 5G network-sliced environment. The results show that compared to other authentication schemes of the same type, the overall inter-slice handover delay has been reduced by 97.94%. Zhe Ren, Xinghua Li 0001, Qi Jiang 0001, Qingfeng Cheng, Jianfeng Ma 0001 |
Secur. Commun. Networks | 4 |
| 2020 | Opcode sequence analysis of Android malware by a convolutional neural networkabstractSummary The number of malware has exploded due to the openness of the Android platform, and the endless stream of malware poses a threat to the privacy, tariffs, and device of mobile phone users. A novel Android mobile malware detection system is proposed, which employs an optimized deep convolutional neural network to learn from opcode sequences. The optimized convolutional neural network is trained multiple times by the raw opcode sequences extracted from the decompiled Android file, so that the feature information can be effectively learned and the malicious program can be detected more accurately. More critically, the k‐max pooling method with better results is adopted in the pooling operation phase, which improves the detection effect of the proposed method. The experimental results show that the detection system achieved the accuracy of 99%, which is 2%‐11% higher than the accuracy of the machine learning detection algorithms when using the same data set. It also ensures that the indicators, such as F1‐score, recall, and precision, are maintained above 97%. Based on the detection system, a multi–data set comparison experiment is carried out. The introduced k‐max pooling is deeply studied, and the effect of k of k‐max pooling on the overall detection effect is observed. Dan Li 0028, Lichao Zhao, Qingfeng Cheng, Ning Lu 0005 |
Concurr. Comput. Pract. Exp. | 3 |
| 2020 | An Efficient Anonymous Authentication Scheme for Mobile Pay-TV SystemsabstractAs a component of mobile communication, the pay-TV system has attracted a lot of attention. By using mobile devices, users interact with the head end system in service providers to acquire TV services. With the growth of mobile users, how to protect the privacy of users while improving efficiency of the network has become an issue worthy of attention. Anonymous authentication schemes for mobile pay-TV systems came into being. In this paper, we analyze the shortcomings of the existing authentication protocol and then propose an improved one, which is secure against stored set attack and user traceability attack. The proposed scheme is proved to be secure. Moreover, our new scheme performs better in efficiency and storage, compared with several other schemes. Qingfeng Cheng, Jinzheng Cao |
Wirel. Commun. Mob. Comput. | 2 |
| 2019 | IP Geolocation based on identification routers and local delay distribution similarityabstractSummary IP geolocation is usually used in fog computing to avoid high latency and discriminate malicious requests by judging the location of users. Existing delay measurement‐based IP geolocation approaches are not applicable to the network that has hierarchical topology and weak connectivity, and the precision of the classical Street‐Level Geolocation (SLG) method will decrease dramatically when the common routers are anonymous. In this paper, an IP geolocation method based on identification routers and local delay distribution similarity is proposed. The target IP's location at city‐level is firstly derived by matching its routing path with the identification routers that only forward packets to the same city. After that, the target IP's local delay between the nearest common router and the target IP is gathered, and the landmarks' are obtained at the same time. Finally, the location of the landmark that has the most similar local delay distribution with the target IP is taken as the geolocation result. Theoretical analysis and experimental results show that the proposed method can derive reliably geolocation results at city‐level for the target IP in the network with hierarchical architecture. Moreover, the geolocation accuracy of classical SLG method is improved obviously when the common routers are anonymous. Fan Zhao 0002, Xiangyang Luo 0001, Yong Gan, Shuodi Zu, Qingfeng Cheng, Fenlin Liu |
Concurr. Comput. Pract. Exp. | 5 |
| 2018 | Hydra-Bite: Static Taint Immunity, Split, and Complot Based Information Capture Method for Android DeviceabstractIn order to attract attention to the malicious use of large‐scale operation of applications, Hydra‐Bite, an Android device privacy leak path implemented by splitting traditional malicious application and restructuring to a collaborative application group, is proposed in this paper. For Hydra‐Bite, firstly, traditional privacy stealing Trojan is analyzed to obtain the permission set. And the permission set redundancy elimination splitting algorithm is subsequently adopted to extract the simplest key permission set and split the set by functions so as to form the collaborative application group. Then, a covert channel is adopted for the intergroup Apps to remove the information’s taint tagged by security methods. Meanwhile, a communication medium selection algorithm and an information normalization coding method are proposed to improve the efficiency and the concealing property for taints removal. Finally, collaborative external transmission of information is realized on the basis of intragroup Apps’ communication. The experimental results show that Hydra‐Bite could resist the detecting and killing of about 60 security engines such as Kaspersky, McAfee, and Qihoo‐360 in VirusTotal platform and capture the privacy information of the devices of different versions from Android 4.0 to Android 7.0. Hydra‐Bite can resist the killing of the following two methods, the typical detection tool Androguard based on “permission‐API” and the typical static taint tracking tool FlowDroid. Compared with traditional privacy stealing Trojan, Hydra‐Bite has higher information capture rate and stronger antikilling performance. Ziru Peng, Xiangyang Luo 0001, Fan Zhao 0002, Qingfeng Cheng, Fenlin Liu |
Wirel. Commun. Mob. Comput. | 4 |
| 2016 | Attacking OpenSSL Implementation of ECDSA with a Few SignaturesabstractIn this work, we give a lattice attack on the ECDSA implementation in the latest version of OpenSSL, which implement the scalar multiplication by windowed Non-Adjacent Form method. We propose a totally different but more efficient method of extracting and utilizing information from the side-channel results, remarkably improving the previous attacks. First, we develop a new efficient method, which can extract almost all information from the side-channel results, obtaining 105.8 bits of information per signature on average for 256-bit ECDSA. Then in order to make the utmost of our extracted information, we translate the problem of recovering secret key to the Extended Hidden Number Problem, which can be solved by lattice reduction algorithms. Finally, we introduce the methods of elimination, merging, most significant digit recovering and enumeration to improve the attack. Our attack is mounted to the {series secp256k1} curve, and the result shows that only 4 signatures would be enough to recover the secret key if the Flush+Reload attack is implemented perfectly without any error,which is much better than the best known result needing at least 13 signatures. Shuqin Fan, Qingfeng Cheng |
CCS | 3 |
| 2009 | A New Efficient and Strongly Secure Authenticated Key Exchange ProtocolabstractIn 2007, LaMacchia et al.proposed the extended Canetti-Krawczyk (eCK) model for authenticated key exchange (AKE) protocols. In this paper, we first modify the eCK model by adding a new query to make the adversary can reveal all ephemeral secret information. Then we propose a new efficient and strongly secure AKE protocol in the asymmetric setting, called E-NETS (enhanced NETS) protocol, and prove its security in the modified eCK (meCK) model under the random oracle assumption and the gap Diffie-Hellman assumption. Qingfeng Cheng, Guangguo Han, Chuangui Ma |
IAS | 1 |
| 2009 | Password Authenticated Key Exchange Based on RSA in the Three-Party Settings
E. Dongna, Qingfeng Cheng, Chuangui Ma |
ProvSec | 2 |