VLDB 2026 Research / reviewers in the wild / expert
Shanshan Li 0004
dblp:66/5479-4
· DBLP profile ↗
11ranked-venue papers
9as first author
9since 2021 · last 2026
0000-0002-2120-4278ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 8 · 7 first-author · 6 since 2021Systems, architecture and hardware · 1 · 1 since 2021Computer networks · 1 · 1 first-author · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | A secure encrypted data access scheme based on hardware tokens
Shanshan Li 0004, Mengfan Ma, Meiqi Xue |
J. Inf. Secur. Appl. | 1 |
| 2026 | Password-Based Outsourced Data Protection for Cloud Storage Against Backdoor AttacksabstractUpdatable oblivious key management (UOKMS) allow users to outsource encrypted data along with a symmetric key-generating token to a cloud server. The designated recipient uses this token and interacts with multiple key servers to derive the decryption key and then access the data. To ensure secure access and prevent impersonation attacks, users must authenticate to each key server using distinct credentials during key derivation. This introduces computational overhead that scales linearly with the number of key servers, especially posing challenges for resource-constrained devices. Moreover, UOKMS assumes that users' devices are fully trustworthy, but real-world cases show that they may be embedded with backdoors that covertly exfiltrate cryptographic secrets. To address these challenges, we propose a secure re-randomized password-derived public/secret key pairs generation mechanism that protects the symmetric key-generating token, eliminates interactive authentication with key servers, and resists password-guessing attacks. Our design incorporates a protocol-aware reverse firewall that mitigates backdoor threats by generating unbiased randomness and transforming interactive messages through re-randomization and de-randomization. Building on this, we develop ATTEST, a password-based data protection scheme for cloud storage against backdoor attacks. Security and performance evaluations demonstrate that ATTEST offers strong security with practical efficiency. Shanshan Li 0004, Mengfan Ma, Chunxiang Xu |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2026 | SE-ASSO: A Security-Enhanced Anonymous Single-Sign-On Authentication SchemeabstractAnonymous Single-Sign-On (ASSO) enables users to authenticate with an identity server and obtain a master token that grants anonymous access to multiple services. We analyze existing password-based ASSO schemes and identify two fundamental security vulnerabilities. First, an adversary may enumerate potential passwords of a target user and forge valid authentication requests to the identity server. By analyzing the master tokens returned by the identity server using a designated equation, the adversary can recover the user’s password.We refer to this attack as Master Token Password Inference Attacks (MT-PIA). Second, a malicious manufacturer may embed a biased randomness source in users’ devices, causing cryptographic operations to produce predictable outputs. This enables the manufacturer to efficiently recover users’ secrets, which is known as subversion attacks. To mitigate MT-PIA, we propose a secure master token generation mechanism that protects users’ master tokens using two factors: a password and a security key. This mechanism prevents adversaries from forging valid authentication requests and ensures that, even if they intercept master tokens from the identity server, they cannot infer users’ passwords without users’ associated security keys. To counter subversion attacks, we design a cryptographic reverse firewall–based randomness generation mechanism. In this design, a reverse firewall is deployed between each user’s device and the external to assist in generating uniformly distributed randomness. Leveraging these two mechanisms, we develop a security-enhanced ASSO scheme, referred to as SE-ASSO, and conduct a comprehensive evaluation demonstrating its strong security and practicality for real-world deployment. Shanshan Li 0004, Mengfan Ma, Yunxia Han |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2025 | Towards subversion-resistant password-protected encryption for deduplicated cloud storage
Shanshan Li 0004, Mengfan Ma, Yunxia Han, Chunxiang Xu |
J. Inf. Secur. Appl. | 1 |
| 2023 | Backdoor-Resistant Public Data Integrity Verification Scheme Based on Smart ContractsabstractThis article analyzes existing smart contract-based public data integrity verification schemes and identifies certain weaknesses. First, the fair arbitration mechanism deployed in these schemes fails to meet the users’ requirements as it may not promptly notify users of data corruption or loss. Second, to ensure outsourced data confidentiality, existing data integrity schemes use a conventional encrypted method, where each user randomly selects a key to encrypt the outsourced data. Such a method results in varying ciphertexts for the same data by different users, leading to additional storage costs for the cloud server. Third, users’ devices, if poorly designed or even intentionally backdoored, can potentially exfiltrate secrets and compromise the security of schemes. To address these issues, we propose the first backdoor-resistant public data integrity verification scheme based on smart contracts (ASSIST). The key idea is to introduce a new entity (a whistleblower) to periodically monitor the state of verification results recorded in the blockchain. This allows for timely notification of data corruption to users. ASSIST requires users to encrypt their data with a cryptographic primitive called message-locked encryption (MLE), which motivates different users to produce the same ciphertext for the same data and reduces storage costs for cloud servers. We also deploy a cryptographic reverse firewall between users’ devices and the external to rerandomize interactive messages, making the exfiltration impossible. We provide rigorous security proofs to demonstrate the security of ASSIST. The performance evaluation shows that ASSIST is efficient regarding computation and communication costs. Shanshan Li 0004, Chunxiang Xu, Yuan Zhang 0006, Yicong Du, Anjia Yang, Xinsheng Wen, Kefei Chen |
IEEE Internet Things J. | 1 |
| 2023 | ttPAKE: Typo tolerance password-authenticated key exchange
Yunxia Han, Chunxiang Xu, Shanshan Li 0004, Changsong Jiang, Kefei Chen |
J. Inf. Secur. Appl. | 3 |
| 2023 | Blockchain-Based Transparent Integrity Auditing and Encrypted Deduplication for Cloud StorageabstractIn this paper, we introduce a concept of transparent integrity auditing and propose a concrete scheme based on the blockchain, which goes one step beyond existing public auditing schemes, since the auditing does not rely on third-party auditors while freeing users from heavy communication costs on auditing the data integrity. Then we construct a secure transparent deduplication scheme based on the blockchain that supports deduplication over encrypted data and enables users to attest the deduplication pattern on the cloud server. Such a scheme allows users to directly benefit from data deduplication and protects data content against anyone who does not own the data. Finally, we integrate the proposed transparent integrity auditing scheme and transparent deduplication scheme into one system, dubbed BLIND. We evaluate BLIND from security and efficiency, which demonstrates that BLIND achieves a strong security guarantee with high efficiency. Shanshan Li 0004, Chunxiang Xu, Yuan Zhang 0006, Yicong Du, Kefei Chen |
IEEE Trans. Serv. Comput. | 1 |
| 2022 | On the Security of Verifiable Searchable Encryption SchemesabstractWith cloud services, data users can retrieve encrypted data while preserving data confidentiality. However, this new paradigm suffers from many security concerns. A major concern is how to avoid insider Keyword-Guessing Attacks (KGA), which implies that the internal attackers can guess the candidate keywords successfully in an off-line manner. To address this issue, recently, two verifiable searchable encryption schemes (published in IEEE Transactions on Cloud Computing, doi: 10.1109/TCC.2020.2989296) in cloud storage were proposed which enjoys many desirable features. In this letter, we demonstrate that the schemes are insecure against insider keyword-guessing attack. Specifically, we show that the adversary can derive the keywords in an off-line manner. Chuang Li 0008, Chunxiang Xu, Shanshan Li 0004, Kefei Chen, Yinbin Miao |
IEEE Trans. Cloud Comput. | 3 |
| 2022 | A Secure Two-Factor Authentication Scheme From Password-Protected Hardware TokensabstractWe investigate existing “password+hardware token”-based authentication schemes deployed in real-world applications and observe that they are vulnerable to critical threats. Specifically, a compromised manufacturer may issue a backdoored hardware token to a user and later recover the user’s secret, which is well known as backdoor attacks. Additionally, an authentication credential in these schemes consists of two parts: the one is derived from the password, the other one is derived from the hardware token. However, since the two parts are independent of each other, if an adversary can physically access the hardware token of a victim, he is able to break security of these schemes by performing dictionary-guessing attacks (DGA), which is called mislaying-then-DGA. In this paper, we design a non-interactively re-randomizable reverse firewall signature mechanism for securing hardware tokens, such that the user’s secret is well protected even if a backdoor is embedded. We also utilize a servers-aided password-based encryption mechanism to harden hardware tokens, so as to “seamlessly” integrate the two factors into one credential. Based on the above mechanisms, we develop a secure two-factor authentication scheme, dubbed ATTACH. We evaluate ATTACH in terms of security and efficiency to demonstrate it achieves a strong security guarantee with high efficiency. Shanshan Li 0004, Chunxiang Xu, Yuan Zhang 0006, Jianying Zhou 0001 |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2020 | Blockchain-Based Efficient Public Integrity Auditing for Cloud Storage Against Malicious Auditors
Shanshan Li 0004, Chunxiang Xu, Yuan Zhang 0006, Anjia Yang, Xinsheng Wen, Kefei Chen |
Inscrypt | 1 |
| 2019 | CSED: Client-Side encrypted deduplication scheme based on proofs of ownership for cloud storage
Shanshan Li 0004, Chunxiang Xu, Yuan Zhang 0006 |
J. Inf. Secur. Appl. | 1 |