Zhong Chen 0001

dblp:70/2509-1 · DBLP profile ↗
← Back
115ranked-venue papers
0as first author
36since 2021 · last 2026
0000-0002-5785-2912ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 32 · 5 since 2021Databases, data management, data science and information retrieval · 22 · 1 since 2021Software engineering, systems software and programming languages · 19 · 13 since 2021Computer networks · 15 · 6 since 2021Artificial intelligence and machine learning · 11 · 5 since 2021Systems, architecture and hardware · 9 · 3 since 2021Applied, interdisciplinary, general and emerging computing · 9 · 5 since 2021Human-computer interaction and ubiquitous computing · 3 · 1 since 2021
YearPublicationVenuePosition
2026 GALUPA: Gossiping Aggregated Locking and Output Proofs for Accountability in BFT
Huiping Sun, Zhong Chen 0001
ICDCS3
2026 Towards Secure Oracle Usage: Understanding and Detecting the Vulnerabilities in Oracle Contracts
Yue Li 0037, Jiashuo Zhang 0001, Jianbo Gao 0003, Jiakun Hao, Anming Xie, Zhi Guan, Zhong Chen 0001
SANER9
2026 Heimdall: A Decentralized Access Control Scheme With Time-Based Secret Management and Private Access Policies
abstract
Decentralized Access Control (DAC) manages access through multiple entities, consisting of two modules: decentralized secret management and access policies. However, existing DAC schemes lack support for managing secrets with time-based conditions, such as triggering secret release after a certain time bound. In this case, users may gain access to information before the designated time, which is undesirable in scenarios involving time-sensitive data. Moreover, current DAC schemes mainly focus on identity confidentiality and lack support for policy confidentiality, which may lead to leakage of sensitive information in access policies. To address these challenges, we propose Heimdall, a decentralized access control scheme with time-based secret management and private access policies. The core of our solution is the dhNIZK protocol, an efficient non-interactive zero-knowledge protocol designed for the verifiable incorporation of time conditions into threshold cryptosystems. We utilize this dhNIZK protocol and homomorphic time-lock puzzles to enable time-based secret management, improving the efficiency of secret reconstruction through batch puzzle-solving techniques. Furthermore, we enhance the garbling scheme’s encoding algorithm to ensure policy confidentiality while maintaining identity confidentiality. Finally, we implement Heimdall and present experimental results demonstrating its superior performance compared to the state-of-the-art solutions.
Libin Xia, Yue Li 0037, Jiashuo Zhang 0001, Jianbo Gao 0003, Zhi Guan, Zhong Chen 0001
IEEE Trans. Inf. Forensics Secur.6
2026 Web3ID: A Privacy-Preserving and DApp-Oriented Decentralized Identity Framework for Web3.0
abstract
With the development of Web3.0, decentralized identity and other blockchain-based identity empower users with control, forming the foundational infrastructure for Web3.0 ecosystems. However, existing identity frameworks remain inadequate in addressing critical challenges such as on-chain privacy during identity management and utilization. While prior works like CanDID, Hades, and CertChain explore blockchain-based identity solutions, they fail to meet the specific reqirements of DApps. Moreover, users on blockchain always store their identity data and digital assets across multiple accounts and DApps, but current identity schemes cannot support the cross-account and DApp identity privacy-preserving utilization. To bridge this gap, we propose Web3ID, the first fully DApp-oriented identity framework. By analyzing Ethereum identity proposals and user behavior patterns, we design the Web3ID featuring: on-chain privacy-preserving identity aggregation protocol, provably secure attribute-based access control model, and zk-rollup enhanced off-chain identity management. Experiments demonstrate that Web3ID enables privacy-preserving identity management and authentication on-chain, and guaranteeing access control completeness. The prototype system achieves a 100× improvement in proof/verification efficiency and reduces storage overhead by 85× compared to pure on-chain implementation through off-chain optimization techniques. Moreover, in comparison with other identity privacy solutions, Web3ID exhibits the lowest gas consumption during on-chain utilization and shows strong scalability. As a fully decentralized identity framework supporting end-to-end DApp integration, Web3ID advances Web3.0’s vision of user sovereignty, decentralization, and interoperability. This work establishes both theoretical and practical foundations for on-chain identity systems in Web3.0 ecosystems.
Jiakun Hao, Jianbo Gao 0003, Libin Xia, Zhi Guan, Zhong Chen 0001
ACM Trans. Web7
2025 Automated Test Generation For Smart Contracts via On-Chain Test Case Augmentation and Migration
abstract
Pre-deployment testing has become essential to ensure the functional correctness of smart contracts. However, since smart contracts are stateful programs integrating many different functionalities, manually writing test cases to cover all potential usages requires significant effort from developers, leading to insufficient testing and increasing risks in practice. Although several testing techniques for smart contracts have been proposed, they primarily focus on detecting common low-level vulnerabilities such as re-entrancy, rather than generating expressive and function-relevant test cases that can reduce manual testing efforts. To bridge the gap, we propose Solmigrator, an automated technique designed to generate expressive and representative test cases for smart contracts. To our knowledge, Solmigrator is the first migration-based test generation technique for smart contracts, which extracts test cases from real-world usages of on-chain contracts and migrates them to test newly developed smart contracts with similar functionalities. Given a target smart contract to be tested and an on-chain similar source smart contract, Solmigrator first transforms the on-chain usage of the source contract into off-chain executable test cases based on on-chain transaction replay and dependency analysis. It then employs fine-grained static analysis to migrate the augmented test cases from the source to the target smart contract. We built a prototype of Solmigrator and have evaluated it on real-world smart contracts within the two most popular categories, ERC20 and ERC721. Our evaluation results demonstrate that Solmigrator effectively extracts test cases from existing on-chain smart contracts and accurately migrates them across different smart contracts, achieving an average precision of 96.3% and accuracy of 93.6%. Furthermore, the results indicate that these migrated test cases effectively cover common key functionalities of the target smart contracts. This provides promising evidence that real-world usages of existing smart contracts can be transformed into effective test cases for other newly developed smart contracts.
Jiashuo Zhang 0001, Jiachi Chen, John C. Grundy, Jianbo Gao 0003, Yanlin Wang 0001, Ting Chen 0002, Zhi Guan, Zhong Chen 0001
ICSE8
2025 Demystifying and Detecting Cryptographic Defects in Ethereum Smart Contracts
abstract
Ethereum has officially provided a set of system-level cryptographic APIs to enhance smart contracts with cryptographic capabilities. These APIs have been utilized in over 10% of Ethereum transactions, motivating developers to implement various on-chain cryptographic tasks, such as digital signatures. However, since developers may not always be cryptographic experts, their ad-hoc and potentially defective implementations could compromise the theoretical guarantees of cryptography, leading to real-world security issues. To mitigate this threat, we conducted the first study aimed at demystifying and detecting cryptographic defects in smart contracts. Through the analysis of 2,406 real-world security reports, we defined nine types of cryptographic defects in smart contracts with detailed descriptions and practical detection patterns. Based on this categorization, we proposed Crysol, a fuzzing-based tool to automate the detection of cryptographic defects in smart contracts. It combines transaction replaying and dynamic taint analysis to extract fine-grained crypto-related semantics and employs crypto-specific strategies to guide the test case generation process. Furthermore, we collected a large-scale dataset containing 25,745 real-world crypto-related smart contracts and evaluated CRYSOL's effectiveness on it. The result demonstrated that CRySOL achieves an overall precision of 95.4% and a recall of 91.2%. Notably, CRySOL revealed that 5,847 (22.7%) out of 25,745 smart contracts contain at least one crvptographic defect” hiahlighting the prevalence of these defects.
Jiashuo Zhang 0001, Jiachi Chen, Jianzhong Su, Yanlin Wang 0001, Ting Chen 0002, Jianbo Gao 0003, Zhong Chen 0001
ICSE8
2025 Information entropy peaks clustering using dynamic reverse nearest neighbor sequence and 3D decision graph
Jianyun Lu, Zhong Chen 0001, Junming Shao, Chunling Wu
Expert Syst. Appl.2
2025 A sharding blockchain-based UAV system for search and rescue missions
Xihan Zhang, Jiashuo Zhang 0001, Jianbo Gao 0003, Libin Xia, Zhi Guan, Zhong Chen 0001
Frontiers Comput. Sci.7
2025 AI-Auditor: A Data Auditing Framework for Enhancing the Trustworthiness of AI Models
abstract
Artificial intelligence (AI) is now widely adopted across fields, prompting AI companies to deploy models to the cloud for cost, resource, and scalability benefits. However, these cloud-hosted models face security and credibility challenges. Equipment failures or network attacks may compromise data integrity, while commercial interests might cause AI companies or cloud providers to deploy models deviating from their stated specifications, such as version or copyright details. To address these issues, we introduce AI-auditor, a novel data auditing framework that verifies both data integrity and model alignment with declared specifications. Using a challenge-response approach, AI-auditor maintains constant bandwidth usage and O(1) verification efficiency, regardless of file size. It also features a multikey management server mechanism to generate user keys, minimizing risks of single-point failures and trust issues. Analysis and simulations confirm AI-auditor’s correctness, security, and high execution efficiency.
Lipeng Wang 0001, Laurence T. Yang, Xinfang Sun, Zhong Chen 0001
IEEE Trans. Ind. Informatics5
2025 When Crypto Fails: Demystifying Cryptographic Defects in Ethereum Smart Contracts
abstract
Ethereum has officially provided a set of system-level cryptographic APIs to enhance smart contracts with cryptographic capabilities. These APIs have been utilized in over 13.8% of Ethereum transactions, motivating developers to implement various on-chain cryptographic tasks, such as digital signatures. However, since developers may not always be cryptographic experts, their ad-hoc and potentially defective implementations could compromise the theoretical guarantees of cryptography, leading to real-world security issues. To mitigate this threat, we conducted a comprehensive study aimed at demystifying and detecting cryptographic defects in smart contracts. Through the analysis of 3,762 real-world security reports, we defined 12 types of cryptographic defects in smart contracts with detailed descriptions and practical detection patterns. Based on this categorization, we proposedCryptoScan, the first static analyzer to automate the pre-deployment detection of cryptographic defects in smart contracts.CryptoScanutilizes cross-contract and inter-procedure static analysis to identify crypto-related execution paths and employs taint analysis to extract fine-grained crypto-specific semantics for defect detection. Furthermore, we collected a large-scale dataset containing 79,598 real-world crypto-related smart contracts and evaluatedCryptoScan's effectiveness on it. The results demonstrated thatCryptoScanachieves an overall precision of 96.1% and a recall of 93.3%. Notably,CryptoScanrevealed that 19,707 (24.8%) out of 79,598 smart contracts contain at least one cryptographic defect. Although not all defects directly cause financial losses, they indicate prevalent non-standard cryptographic implementations that should be addressed in real-world practices.
Jiashuo Zhang 0001, Jiachi Chen, Tao Zhang 0001, Yanlin Wang 0001, Ting Chen 0002, Jianbo Gao 0003, Zhong Chen 0001
IEEE Trans. Software Eng.8
2024 When Contracts Meets Crypto: Exploring Developers' Struggles with Ethereum Cryptographic APIs
abstract
To empower smart contracts with the promising capabilities of cryptography, Ethereum officially introduced a set of cryptographic APIs that facilitate basic cryptographic operations within smart contracts, such as elliptic curve operations. However, since developers are not necessarily cryptography experts, requiring them to directly interact with these basic APIs has caused real-world security issues and potential usability challenges. To guide future research and solutions to these challenges, we conduct the first empirical study on Ethereum cryptographic practices. Through the analysis of 91,484,856 Ethereum transactions, 500 crypto-related contracts, and 483 StackExchange posts, we provide the first in-depth look at cryptographic tasks developers need to accomplish and identify five categories of obstacles they encounter. Furthermore, we conduct an online survey with 78 smart contract practitioners to explore their perspectives on these obstacles and elicit the underlying reasons. We find that more than half of practitioners face more challenges in cryptographic tasks compared to general business logic in smart contracts. Their feedback highlights the gap between low-level cryptographic APIs and high-level tasks they need to accomplish, emphasizing the need for improved cryptographic APIs, task-based templates, and effective assistance tools. Based on these findings, we provide practical implications for further improvements and outline future research directions.
Jiashuo Zhang 0001, Jiachi Chen, Zhiyuan Wan, Ting Chen 0002, Jianbo Gao 0003, Zhong Chen 0001
ICSE6
2024 Understanding and Detecting Privacy Leakage Vulnerabilities in Hyperledger Fabric Chaincodes
abstract
The application on a blockchain cannot maintain secrecy because its data is replicated across all peers in the network. To remedy this problem, Hyperledger Fabric introduces private data collection (PDC) into its smart contract (i.e. chaincode) to facilitate applications that require privacy. However, recent studies have revealed that PDC is too complex for chaincode developers to fully understand and use correctly, leading to privacy leaks vulnerabilities. In this paper, we present an empirical study on the prevalence of PDC misuse in chaincodes by extracting privacy leakage cases from StackOverflow posts and Hyperledger Fabric repositories on GitHub. Subsequently, we systematically categorize the misuse of PDC into three categories of vulnerabilities resulting in the leakage of private data and provide formal definitions for them. Furthermore, we develop PDChecker, an automated security analysis framework for identifying the privacy and security vulnerabilities in Fabric chaincodes. We evaluated PDChecker on 956 real-world chaincodes applying PDC and found that 67.78% of them contain at least one privacy leakage vulnerability. In addition, PDChecker uncovered 10 zero-day vulnerabilities documented by the China National Vulnerability Database.
Yue Li 0037, Jianbo Gao 0003, Jiashuo Zhang 0001, Ke Wang 0061, Jian-bin Hu, Zhi Guan, Zhong Chen 0001
ISSRE8
2024 SolaSim: Clone Detection for Solana Smart Contracts via Program Representation
abstract
The open-source nature of smart contracts provides the facility for developers to clone contracts and introduces the risk of vulnerability proliferation as well. Despite intensive research on smart contract clone detection in recent years, existing techniques are still unsatisfactory in detecting Solana smart contracts. To fill this gap, in this paper, we designed a clone detection tool SolaSim for Solana smart contracts and conducted an empirical study to understand the code reuse in the Solana ecosystem. Specifically, SolaSim is based on the semantic metadata extractor and the similarity checker. For each contract, the semantic metadata extractor generates an instruction-level weighted Attributed Control Flow Graph (ACFG) and its semantic metadata (i.e., a combination of high-level semantic and structure information) based on Rust Mid-level Intermediate Representation. The similarity checker adopts a combinatorial optimization algorithm to compute the statistical similarity of a pair of contracts. The evaluation results demonstrated the effectiveness of SolaSim in identifying clones with 94.3% accuracy and it can identify up to Type-3 clone level. Notably, we found there are over 50% clone ratios in the Solana smart contracts ecosystem, in which most of them are cloned from famous open-sourced projects.
Yue Li 0037, Jianbo Gao 0003, Ke Wang 0061, Jiashuo Zhang 0001, Zhi Guan, Zhong Chen 0001
ICPC7
2024 ContractTinker: LLM-Empowered Vulnerability Repair for Real-World Smart Contracts
abstract
Smart contracts are susceptible to being exploited by attackers, especially when facing real-world vulnerabilities. To mitigate this risk, developers often rely on third-party audit services to identify potential vulnerabilities before project deployment. Nevertheless, repairing the identified vulnerabilities is still complex and laborintensive, particularly for developers lacking security expertise. Moreover, existing pattern-based repair tools mostly fail to address real-world vulnerabilities due to their lack of high-level semantic understanding. To fill this gap, we propose ContractTinker, a Large Language Models (LLMs)-empowered tool for real-world vulnerability repair. The key insight is our adoption of the Chain-of-Thought approach to break down the entire generation task into subtasks. Additionally, to reduce hallucination, we integrate program static analysis to guide the LLM. We evaluate ContractTinker on 48 high-risk vulnerabilities. The experimental results show that among the patches generated by ContractTinker, 23 (48%) are valid patches that fix the vulnerabilities, while 10 (21%) require only minor modifications. A video of ContractTinker is available at https://youtu.be/HWFVi-YHcPE.
Jiashuo Zhang 0001, Jianbo Gao 0003, Libin Xia, Zhi Guan, Zhong Chen 0001
ASE6
2024 Cryptcoder: An Automatic Code Generator for Cryptographic Tasks in Ethereum Smart Contracts
abstract
Cryptographic APIs provided by Ethereum are widely adopted in decentralized applications (DApps) for cryptographic operations. However, developers who lack expertise in cryptography frequently encounter difficulties when working with low-level cryptographic APIs, thereby producing insecure code. To address this issue, we introduce Cryptcoder, an automatic code generator designed to bridge the gap between low-level cryptographic APIs and high-level cryptographic tasks in Ethereum. The fundamental component of Cryptcoder is Cryptlang, a Solidity-compatible domain-specific language (DSL) designed for cryptographic tasks. Developers can utilize Cryptlang for the straightforward and secure implementation of cryptographic tasks, such as signatures and commitments, and employ Cryptcoder for the automatic conversion into Solidity code. The evaluation of Cryptcoder demonstrates both its functionality in generating Solidity code and an acceptable overhead, evidenced by a mere 4% average increase in gas costs compared to the reference code. A demonstration video of Cryptcoder is available at https://youtu.be/AxhCdGiu7dw.
Libin Xia, Jiashuo Zhang 0001, Zezhong Tan, Jianbo Gao 0003, Zhi Guan, Zhong Chen 0001
SANER7
2024 CFAuditChain: Audit BlockChain Based On Cuckoo Filter
abstract
Abstract Log blockchain can be used to ensure the integrity of log data. However, current methods are facing the problems of throughput mismatch and rough audit granularity. Packaging multiple logs to generate integrity proofs improves throughput but reduces audit granularity, and the auditor can only locate the tampering log packet instead of specific records. This paper proposes CFAuditChain, an audit blockchain based on a cuckoo filter, where the proof of existence (PoE) of the single log is calculated while calculating the integrity proof of packet logs. The PoE is saved in the cuckoo filter and stored using blockchain for immutability. Therefore, the auditor can verify the credibility of each log based on the filter when the integrity proof of a log packet does not match. The theoretical analysis and experimental results show that CFAuditChain provides the granularity of audit logs down to the records level at an acceptable cost.
Shiyi Tan, Wei Liang 0005, Huiping Sun, Zhong Chen 0001
Comput. J.6
2024 FedTop: a constraint-loosed federated learning aggregation method against poisoning attack
Zhenhao Wu, Jianbo Gao 0003, Jiashuo Zhang 0001, Junjie Xia, Zhi Guan, Zhong Chen 0001
Frontiers Comput. Sci.8
2024 Accelerating block lifecycle on blockchain via hardware transactional memory
abstract
The processing of block lifecycles is essential to the efficiency of a blockchain, which consists of four steps: creation, execution, consensus, and validation. The permissionless blockchain systems typically had very limited transaction throughput because of the performance bottleneck of consensus protocols. With recent advances in consensus protocols, the execution and validation of transactions have become the new performance bottleneck. We propose a novel framework, called FastBlock, to speed up the execution and validation steps by introducing fine-grained concurrency. Our early design of FastBlock supported three key modules: (1) a symbolic execution-based analyzer that automatically identifies minimal atomic sections in each transaction; (2) a concurrent execution step that executes possibly conflicting transactions in parallel using hardware transactional memory; (3) a concurrent validation step that introduces a happen-before relation to deterministically re-execute transactions. The improved FastBlock presented in this article supports the nonce mechanism to schedule concurrent transactions from the same account. Moreover, we empirically study the impact of concurrency on Ethereum except for performance and shed light on potential optimizations of FastBlock. Finally, we implemented FastBlock and then evaluated the performance of FastBlock. Our result shows that the FastBlock outperforms state-of-art solutions significantly in performance: the execution step and validation step speed up to 3.0x and 2.3x on average over the original serial model, respectively, with eight concurrent threads. In addition, we evaluated the impact of the nonce mechanism, and the result shows that the performance loss caused by this mechanism is acceptable in practice.
Yue Li 0037, Han Liu 0010, Jianbo Gao 0003, Jiashuo Zhang 0001, Zhi Guan, Zhong Chen 0001
J. Parallel Distributed Comput.6
2024 SStore: An Efficient and Secure Provable Data Auditing Platform for Cloud
abstract
As more internet users opt to store their data in cloud storage, ensuring data integrity becomes a paramount concern. The emerging provable data possession (PDP) scheme enables auditors to verify data integrity with reduced bandwidth consumption compared to hash-based alternatives. Nevertheless, most existing PDP variants rely on a centralized node for generating or maintaining user keys, creating a potential single point of failure. Moreover, previous PDP schemes could only detect whether challenged data blocks were corrupted, lacking the ability to pinpoint affected blocks precisely. To tackle these challenges, we propose a novel PDP scheme that eliminates the necessity for a key management center and supports the localization of corrupted data blocks. In our scheme, users no longer need to retain private keys once they cease performing data dynamic operations, thus liberating them from reliance on external entities for key maintenance. Moreover, the new scheme utilizes existing authenticators in the cloud to identify corrupted file blocks, eliminating the necessity of storing hash values for these data blocks as seen in most of existing implementations. This effectively reduces required storage space. Furthermore, we introduce SStore, a decentralized cloud storage platform that incorporates the new PDP scheme to verify data integrity. SStore facilitates public auditing of user data, thereby enhancing transparency in the data verification procedure. Moreover, SStore leverages basic algebraic operations for data auditing, significantly increasing its efficiency. We analyze the security of the new PDP scheme, and evaluate the performance of both the PDP scheme and SStore to demonstrate their efficiency.
Lipeng Wang 0001, Zhijuan Jia, Zhi Guan, Zhong Chen 0001
IEEE Trans. Inf. Forensics Secur.5
2023 Hades: Practical Decentralized Identity with Full Accountability and Fine-grained Sybil-resistance
abstract
Decentralized identity (DID), the idea of giving users complete control over their identity-related data, is being used to solve the privacy tension in the identity management of decentralized applications (Dapps). While existing approaches do an excellent job of solving the privacy tension, they have not adequately addressed the accountability and Sybil-resistance issues. Moreover, these approaches have a considerable gas overhead, making them impractical for Dapps.
Ke Wang 0061, Jianbo Gao 0003, Jiashuo Zhang 0001, Yue Li 0037, Zhi Guan, Zhong Chen 0001
ACSAC7
2023 Metaverse Services: The Way of Services Towards the Future
abstract
With the emergence of new generation of digital technologies, e.g., artificial intelligence, blockchain, cloud computing, big data, edge computing, 5G/6G, VR/AR/MR, and the Internet of Things, an exciting era of metaverse is coming. Interacted and linked with the physical world, metaverse offers a platform of a new social ecosystem, dealing with digital twins and empowering virtual-reality symbiosis. In metaverse, social activities and business processes are performed based on the sequences of workflow or service processes. Bridging both the virtual space and the real world, such metaverse services are more complicated and present many new challenges and research topics. In this paper, the concept and characteristics of metaverse services are presented, the key technologies and typical use cases are reviewed, and the future challenges and opportunities of metaverse services are also discussed.
Xiaofei Xu 0001, Quan Z. Sheng, Boualem Benatallah, Zhong Chen 0001, Robert Gazda, Abdulmotaleb El Saddik, Munindar P. Singh
ICWS4
2023 TDID: Transparent and Efficient Decentralized Identity Management with Blockchain
abstract
Decentralized identity (DID) is an identity management framework aiming to return the ownership of an identity to its corresponding user. Recent studies propose to store the identifiers of DID issuers and implement identity management systems based on blockchain. However, existing systems cannot avoid identity tampering and verifiable credential abuse of decentralized identities, which makes the identity management opaque. In this paper, we propose TDID, a Transparent and efficient Decentralized IDentity management system with blockchain. The key insight behind TDID is to manage the registration and authentication of DIDs via smart contracts, and design Structured Merkle Patricia Tree (SMPT) as an underlying data structure to store identity data on blockchain. The smart contract based processes can improve transparency of decentralized identity management, while the SMPT data structure can realize efficient storage of DID data. We implement and evaluate TDID on different identity management operations, and the experimental results show that TDID can achieve about 3.1 times for write operation and 6.3 times for read operation while improving the transparency of DID management.
Jiakun Hao, Jianbo Gao 0003, Jiashuo Zhang 0001, Zhong Chen 0001
SMC7
2023 DFHelper: Help clients to participate in federated learning tasks
Zhenhao Wu, Jianbo Gao 0003, Jiashuo Zhang 0001, Yue Li 0037, Qingshan Li, Zhi Guan, Zhong Chen 0001
Appl. Intell.7
2023 Enabling Integrity and Compliance Auditing in Blockchain-Based GDPR-Compliant Data Management
abstract
The general data protection regulation (GDPR) is a European Union (EU) data protection and privacy law. According to the GDPR, the data on a hosting platform must meet semantic consistency and data integrity requirements. Semantic consistency means that the data operation should comply with the GDPR, while data integrity is meant to ensure that the outsourcing data should be intact. The two terms are not interchangeable. For example, if a cloud service provider migrates data to foreign storage nodes without authorization of the data owner, the data integrity requirement of the GDPR is met but the semantic consistency requirement is not. How to ensure data integrity and compliance is the main challenge for a GDPR-compliant data supervision platform. To achieve this aim, we leverage a blockchain-based data management framework to check the data compliance, which can break the black box of the data hosting platform and demonstrate its logic to data owners, allowing for inspection. We propose a new provable data possession (PDP) scheme for the aforementioned framework that can check for semantic consistency and data integrity simultaneously. The verifier does not need to hold any audited data, which can reduce bandwidth usage. The verification result can be regarded as the proof for subsequent data recovery and accountability. Experimental results show higher efficiency of the PDP scheme.
Lipeng Wang 0001, Zhi Guan, Zhong Chen 0001
IEEE Internet Things J.3
2023 sChain: An Efficient and Secure Solution for Improving Blockchain Storage
abstract
Emerging blockchain technology has become the cornerstone of many applications providing trusted data services. However, existing blockchain platforms cannot meet the growing demand for big data storage. Blockchain should duplicate both transactions and other user-defined data across nodes for integrity assurance. The rapid expansion of data on blockchain (on-chain data) increases the difficulty of deploying a full node, resulting in decreasing the degree of decentralization and adding the risk of broken data. To tackle these problems, we propose sChain, a novel framework for improving blockchain storage capacity, which does not revise blockchain implementation and can be applied to almost all the existing blockchain platforms. sChain outsources the user data to storage devices that are structurally external to the blockchain network. In theory, a user can outsource unlimited data to sChain. However, those off-chain data may suffer from corruption. To verify the data integrity, we propose a new provable data possession (PDP) scheme, which does not need a centralized entity to maintain any secret keys and therefore eliminates a single point of failure. What is more, we also design a prototype to accelerate the proposed PDP scheme through Intel SGX technology and parallel processing. Security analysis and evaluation results show that sChain can protect data security and effectively improve the blockchain storage capacity, respectively.
Lipeng Wang 0001, Zhi Guan, Zhong Chen 0001
IEEE Trans. Inf. Forensics Secur.3
2022 ESUM: an efficient UTXO schedule model
abstract
The current size of UTXO set in Bitcoin is large and continues to grow, resulting in high memory usage. This paper proposes an efficient UTXO schedule model to lower memory usage based on the observation of UTXO lifespan. Full nodes with the UTXO schedule model store the full UTXO set in disk database and schedule a subset of full UTXO set in memory, converting UTXO querying and accessing into multi-layer activities. Machine learning methods are applied to train a well-performed model based on historical transaction data and market trade data. Experiment results indicate that the UTXO schedule model could reduce nearly 90% memory usage compared to original Bitcoin nodes, allowing more nodes with different memory capability to participate in the blockchain.
Meilin Lv, Kangjian Wei, Henry Kao, Huiping Sun, Zhong Chen 0001
ICBC5
2022 DPLogChain: A Dynamic Packaging LogChain based on Random Witness
abstract
The log blockchain utilizes the append-only and tamper-proof characteristics of the blockchain to ensure the consistency and credibility of log data. However, the mismatch between log system and log blockchain in throughput and storage limits the extensive use of log blockchain. This paper proposed DPLogChain, a dynamic packaging log blockchain based on random witness, which randomly packages log data with different granularity according to its security level to match the throughput of both systems and then stores proof data on chain. Meanwhile, the real-time processing avoids the possibility of collusion and tampering between log system and log storage.
Shiyi Tan, Huiping Sun, Zhong Chen 0001
ICC5
2022 TBFT: Efficient Byzantine Fault Tolerance Using Trusted Execution Environment
abstract
With the rapid development of blockchain, Byzantine fault-tolerant protocols have attracted revived interest recently. To overcome the theoretical bounds of Byzantine fault tolerance, many protocols attempt to use Trusted Execution Environment (TEE) to prevent equivocation and improve fault tolerance from less than 1/3 to minority. However, due to the broken quorum intersection assumption caused by the reduction of replica number, most improvements introduce higher communication complexity or more protocol phases, which affects the performance and scalability of existing TEE-based protocols and prevents them to be applied to large-scale blockchain systems. In this paper, we propose TBFT, an efficient Byzantine fault-tolerant protocol in the partial synchrony setting, which has O(n) message complexity and only two protocol phases in normal-case. The key insight behind TBFT is introducing novel TEE-assisted primitives to limit malicious behaviors of replicas including not only equivocation but also message log forgery and message history forgery, therefore both the communication complexity and protocol phases can be reduced. We have implemented TBFT and evaluated it through systematic analysis and experiments, and the results show that TBFT has better performance and scalability compared to other protocols.
Jiashuo Zhang 0001, Jianbo Gao 0003, Ke Wang 0061, Zhenhao Wu, Yue Li 0037, Zhi Guan, Zhong Chen 0001
ICC7
2022 Xscope: Hunting for Cross-Chain Bridge Attacks
abstract
Cross-Chain bridges have become the most popular solution to support asset interoperability between heterogeneous blockchains. However, while providing efficient and flexible cross-chain asset transfer, the complex workflow involving both on-chain smart contracts and off-chain programs causes emerging security issues. In the past year, there have been more than ten severe attacks against cross-chain bridges, causing billions of loss. With few studies focusing on the security of cross-chain bridges, the community still lacks the knowledge and tools to mitigate this significant threat. To bridge the gap, we conduct the first study on the security of cross-chain bridges. We document three new classes of security bugs and propose a set of security properties and patterns to characterize them. Based on those patterns, we design Xscope, an automatic tool to find security violations in cross-chain bridges and detect real-world attacks. We evaluate Xscope on four popular cross-chain bridges. It successfully detects all known attacks and finds suspicious attacks unreported before. A video of Xscope is available at https://youtu.be/vMRO_qOqtXY.
Jiashuo Zhang 0001, Jianbo Gao 0003, Yue Li 0037, Zhi Guan, Zhong Chen 0001
ASE6
2022 Smifier: A Smart Contract Verifier for Composite Transactions
abstract
Ensuring functional correctness of smart contracts is a pressing security concern to blockchain-based systems.With the development of blockchain application, the trading scenarios and function implementation of smart contracts have become increasing complex, containing several interacted contracts or related functions.However, the existing contracts verifiers for proving functional correctness focus on verifying isolated contract or function but ignore the interactions between them, which makes it difficult to verify correctness of composite transactions, i.e., complex transaction scenarios that invoke multiple contracts or trigger a set of transactions.In this paper, we present SMIFIER, a formal verification tool for smart contracts to prove functional properties in composite transactions.SMIFIER defines a set of specifications for composite transactions and can automatically specify properties in these multiple complex transactions.Based on states extraction and mapping, SMIFIER translates annotated Solidity program into Boogie program and verifies relations between functions and properties for interacted contracts.Our experimental evaluation on 12 real-world projects and 65 properties, demonstrates that SMIFIER is practically effective in ensuring functional correctness of properties in composite transactions.
Yue Li 0037, Dongqi Cui, Jianbo Gao 0003, Zhi Guan, Zhong Chen 0001
SEKE6
2022 Make aspect-based sentiment classification go further: step into the long-document-level
Zhenhao Wu, Jianbo Gao 0003, Qingshan Li, Zhi Guan, Zhong Chen 0001
Appl. Intell.5
2021 FASTBLOCK: Accelerating Blockchains via Hardware Transactional Memory
abstract
The efficiency of block lifecycle determines the performance of blockchain, which is critically affected by the execution, mining and validation steps in blockchain lifecycle. To accelerate blockchains, many works focus on optimizing the mining step while ignoring other steps. In this paper, we propose a novel blockchain framework-FastBlock to speed up the execution and validation steps by introducing efficient concurrency. To efficiently prevent the potential concurrency violations, FastBlock utilizes symbolic execution to identify minimal atomic sections in each transaction and guarantees the atomicity of these sections in execution step via an efficient concurrency control mechanism-hardware transactional memory (HTM). To enable a deterministic validation step, FastBlock concurrently re-executes transactions based on a happen-before graph without increasing block size. Finally, we implement FastBlock and evaluate it in terms of conflicting transactions rate, number of transactions per block, and varying thread number. Our results indicate that FastBlock is efficient: the execution step and validation step speed up to 3.0x and 2.3x on average over the original serial model respectively with eight concurrent threads.
Yue Li 0037, Han Liu 0010, Yuanliang Chen, Jianbo Gao 0003, Zhenhao Wu, Zhi Guan, Zhong Chen 0001
ICDCS7
2021 Associated Lattice-BERT for Spoken Language Understanding
Ye Zou, Huiping Sun, Zhong Chen 0001
ICONIP (6)3
2021 OverlapShard: Overlap-based Sharding Mechanism
abstract
The sharding-based protocols provide an effective solution on scaling decentralized blockchains. However, the performance of a sharding-based blockchain protocol can be greatly degraded by the existence of cross-shard transactions. This paper proposes an overlap-based sharding mechanism for sharding protocols, OverlapShard, to weaken the adverse impact of cross-shard transactions by mapping each node into multiple actual shards. The virtual shards composed of overlapping nodes can be used to process cross-shard transactions. The results of empirical analysis show that when a transaction contains 2 inputs and 2 outputs, the consensus overheads of OverlapShard account for 25% of that of the nonoverlapping mechanism, and OverlapShard's communication overheads are reduced by about 33.3 %. The evaluation results show that the average communication overhead of OverlapShard is reduced by 63.30%. And the average cross-shard transaction ratio of overlap-based sharding model with 3-layer virtual shard structure is 43.76% lower than that of the non-overlapping sharding model.
Huiping Sun, Xu Song, Zhong Chen 0001
ISCC4
2021 Correction to: A digital rights management system based on a scalable blockchain
Abba Garba, Ashutosh Dhar Dwivedi, Mohsin Kamal, Gautam Srivastava 0001, Muhammad Tariq 0001, M. Anwar Hasan, Zhong Chen 0001
Peer-to-Peer Netw. Appl.7
2021 A digital rights management system based on a scalable blockchain
Abba Garba, Ashutosh Dhar Dwivedi, Mohsin Kamal, Gautam Srivastava 0001, Muhammad Tariq 0001, M. Anwar Hasan, Zhong Chen 0001
Peer-to-Peer Netw. Appl.7
2020 Kaya: A Testing Framework for Blockchain-based Decentralized Applications
abstract
In recent years, many decentralized applications based on blockchain (DApp) have been developed. Some development tools provide testing functions, but only for developers to write unit tests for smart contracts rather than test DApp as a whole. Moreover, due to the difficulty for testers to understand the implementation details of smart contracts, insufficient functional testing causes some DApps not to meet functional design expectations. The inherent complexity of DApp, inconvenient pre-state setting, and not-so-readable logs make DApp testing challenging. In this paper, we propose Kaya, a testing framework for DApps to bridge these gaps. Firstly, Kaya formulate automatically executed test cases that cover both front-end behaviors and back-end logics with simple setting. Secondly, Kaya provides a flexible and convenient way for test engineers to set the blockchain pre-states. Thirdly, Kaya transforms incomprehensible addresses into readable variables for easier comprehension. Besides, to fit the various application environments, we provide both GUI and CLI for test engineers to use Kaya. Our case study and preliminary human study demonstrates the potential of Kaya in helping test engineers to test DApps more easily. A demo video is at https://youtu.be/7DyI_EpVZFw.
Zhenhao Wu, Jiashuo Zhang 0001, Jianbo Gao 0003, Yue Li 0037, Qingshan Li, Zhi Guan, Zhong Chen 0001
ICSME7
2020 EShield: protect smart contracts against reverse engineering
abstract
Smart contracts are the back-end programs of blockchain-based applications and the execution results are deterministic and publicly visible. Developers are unwilling to release source code of some smart contracts to generate randomness or for security reasons, however, attackers still can use reverse engineering tools to decompile and analyze the code. In this paper, we propose EShield, an automated security enhancement tool for protecting smart contracts against reverse engineering. EShield replaces original instructions of operating jump addresses with anti-patterns to interfere with control flow recovery from bytecode. We have implemented four methods in EShield and conducted an experiment on over 20k smart contracts. The evaluation results show that all the protected smart contracts are resistant to three different reverse engineering tools with little extra gas cost.
Wentian Yan, Jianbo Gao 0003, Zhenhao Wu, Yue Li 0037, Zhi Guan, Qingshan Li, Zhong Chen 0001
ISSTA7
2019 Understanding Out of Gas Exceptions on Ethereum
Chao Liu 0032, Jianbo Gao 0003, Yue Li 0037, Zhong Chen 0001
BlockSys4
2019 AuthLedger: A Novel Blockchain-based Domain Name Authentication Scheme
abstract
International audience
Zhi Guan, Abba Garba, Anran Li 0006, Zhong Chen 0001, Nesrine Kaaniche
ICISSP4
2019 Towards automated testing of blockchain-based decentralized applications
abstract
Blockchain-based decentralized applications (DApp) have been widely adopted in different areas and trusted by more and more users due to the fact that the back end code of a DApp is publicly run on the blockchain and cannot be modified implicitly. However, there are few effective methods and tools for testing DApps and bugs can be easily introduced by inexperienced developers. The existing testing techniques either focus on testing front-end programs or back-end code but ignore the interaction between them, which makes it difficult to apply the techniques directly on DApp. In this paper, we present an automated testing technique for DApps which works in a two-phase manner. First, we employ random events to infer an abstract relation between browser-side events and blockchain-side contracts. Second, our technique generates a set of test cases under the guidance of inferred relations and orders the test cases based on a read-write graph. We also use taint analysis to track data flow of the smart contract and feed it to the generation procedure for following test cases. We have developed a tool called Sungari to implement our approach, and evaluated it on representative real-world DApps. The preliminary evaluation results demonstrated the potential of Sungari in achieving a significant optimization compared to random testing approaches.
Jianbo Gao 0003, Han Liu 0010, Yue Li 0037, Chao Liu 0032, Qingshan Li, Zhi Guan, Zhong Chen 0001
ICPC8
2017 Exploring the Network of Real-World Passwords: Visualization and Estimation
Xiujia Guo, Zhong Chen 0001
SecureComm3
2015 Trustworthy Collaborative Filtering through Downweighting Noise and Redundancy
Qiuxiang Dong, Zhi Guan, Zhong Chen 0001
APWeb3
2015 A Secure Route Optimization Mechanism for Expressive Internet Architecture (XIA) Mobility
Hongwei Meng, Zhong Chen 0001, Ziqian Meng, Chuck Song
ICICS2
2015 Attribute-Based Keyword Search Efficiency Enhancement via an Online/Offline Approach
abstract
Searchable encryption is a primitive, which not only protects data privacy of data owners but also enables data users to search over the encrypted data. Most existing searchable encryption schemes are in the single-user setting. There are only few schemes in the multiple data users setting, i.e., encrypted data sharing. Among these schemes, most of the early techniques depend on a trusted third party with interactive search protocols or need cumbersome key management. To remedy the defects, the most recent approaches borrow ideas from attribute-based encryption to enable attribute-based keyword search (ABKS). However, all these schemes incur high computational costs and are not suitable for mobile devices, such as mobile phones, with power consumption constraints. In this paper, we develop new techniques that split the computation for the keyword encryption and trapdoor/token generation into two phases: a preparation phase that does the vast majority of the work to encrypt a keyword or create a token before it knows the keyword or the attribute list/access control policy that will be used. A second phase then rapidly assembles an intermediate ciphertext or trapdoor when the specifics become known. The preparation work can be performed while the mobile device is plugged into a power source, then it can later rapidly perform keyword encryption or token generation operations on the move without significantly draining the battery. We name our scheme Online/Offline ABKS. To the best of our knowledge, this is the first work on constructing efficient multi-user searchable encryption scheme for mobile devices through moving the majority of the cost of keyword encryption and token generation into an offline phase.
Qiuxiang Dong, Zhi Guan, Zhong Chen 0001
ICPADS3
2015 Accelerating RSA with Fine-Grained Parallelism Using GPU
Zhi Guan, Huiping Sun, Zhong Chen 0001
ISPEC4
2015 PassApp: My App is My Password!
abstract
Existing graphical passwords require users to proactively memorize their secrets and meanwhile these schemes are vulnerable to shoulder surfing attacks. We propose a novel graphical password scheme, PassApp, which utilizes users' everyday memory about installed apps on mobile devices as shared secrets. As the registration stage is no longer needed, PassApp exempts users from additional memory burden and greatly enhances user experience. Additionally, PassApp owns a large password set and only a small part of passwords may be exposed during a login. Therefore, PassApp has a natural advance on effectively resisting guessing attacks and shoulder surfing attacks. Our user studies demonstrate that PassApp performs well with a reasonable login time (7.27s) and a high success rate (95.48%). Our security analysis shows PassApp can effectively withstand one-time shoulder surfing attacks and on average 30 times of shoulder surfing are necessary to expose all passwords.
Huiping Sun, Ke Wang 0061, Nan Qin, Zhong Chen 0001
MobileHCI5
2015 Location Semantics Protection Based on Bayesian Inference
Zhengang Wu, Zhong Chen 0001, Huiping Sun, Zhi Guan
WAIM2
2014 Protecting Elliptic Curve Cryptography Against Memory Disclosure Attacks
Zhi Guan, Zhe Liu 0001, Zhong Chen 0001
ICICS4
2014 PUF-Based RFID Ownership Transfer Protocol in an Open Environment
abstract
In the supply chain, RFID tags are deployed more widely. In the life of the supply chain, the owner of the tag will change frequently. Ownership transfer protocol can achieve the purpose that the access rights of the tag are transferred from the original owner to the new owner, and protect the privacy of the original owner and the new owner. To resist cloning attack and side channel analysis attack, physical unclonable function (PUF) has been proposed to enhance the security of the tags. Since the PUF of each tag is unique and different, it is difficult to be forged. However, most of PUF-based authentication protocols need the response value previously stored in the readers. On the other hand, most of the ownership transfer protocols assume the original owner and the new owner has a secure channel. However, in an open environment, due to time and space constraints, such a channel is often unable to quickly established. In this paper, we studied the ownership transfer protocols in an open environment and proposed a PUF-based RFID ownership transfer protocols, PROTP. The new protocol is the first ownership transfer protocol based on the PUF in an open environment. The new protocol does not need to store the respond values of the PUF. To utilize the randomness of the PUF, it replaces the pseudo-random generator. Meanwhile, PROTP can protect the privacy of the original owner and the new owner. In terms of efficiency, since the protocol is designed to satisfy the requirement in an open environment, the total cost of the computation is more than others protocols. However, due to the new protocol utilizes the PUF to replace the pseudo-random generator, the each step of the authentication messages achieves a better optimization in computational cost.
Qingshan Li, Zhong Chen 0001
PDCAT3
2014 Edges Protection in Multiple Releases of Social Network Data
Liangwen Yu, Zhengang Wu, Jian-bin Hu, Zhong Chen 0001
WAIM6
2014 Automated enforcement for relaxed information release with reference points
Cong Sun 0001, Ning Xi 0002, Sheng Gao 0002, Zhong Chen 0001, Jianfeng Ma 0001
Sci. China Inf. Sci.4
2014 Certificate-free ad hoc anonymous authentication
Zhiguang Qin, Hu Xiong, Guobin Zhu, Zhong Chen 0001
Inf. Sci.4
2013 An Efficient Privacy-Preserving RFID Ownership Transfer Protocol
Zhi Guan, Tao Yang 0015, Huiping Sun, Zhong Chen 0001
APWeb5
2013 MisDis: An Efficent Misbehavior Discovering Method Based on Accountability and State Machine in VANET
Tao Yang 0015, Liangwen Yu, Jian-bin Hu, Zhong Chen 0001
APWeb6
2013 CQArank: jointly model topics and expertise in community question answering
abstract
Community Question Answering (CQA) websites, where people share expertise on open platforms, have become large repositories of valuable knowledge. To bring the best value out of these knowledge repositories, it is critically important for CQA services to know how to find the right experts, retrieve archived similar questions and recommend best answers to new questions. To tackle this cluster of closely related problems in a principled approach, we proposed Topic Expertise Model (TEM), a novel probabilistic generative model with GMM hybrid, to jointly model topics and expertise by integrating textual content model and link structure analysis. Based on TEM results, we proposed CQARank to measure user interests and expertise score under different topics. Leveraging the question answering history based on long-term community reviews and voting, our method could find experts with both similar topical preference and high topical expertise. Experiments carried out on Stack Overflow data, the largest CQA focused on computer programming, show that our method achieves significant improvement over existing methods on multiple metrics.
Liu Yang 0005, Minghui Qiu, Swapna Gottipati, Feida Zhu 0001, Jing Jiang 0001, Huiping Sun, Zhong Chen 0001
CIKM7
2013 Accelerating AES in JavaScript with WebGL
Zhi Guan, Qiuxiang Dong, Zhong Chen 0001
ICICS5
2013 Fuzzy Keyword Search over Encrypted Data in the Public Key Setting
Qiuxiang Dong, Zhi Guan, Liang Wu 0011, Zhong Chen 0001
WAIM4
2013 Sensitive Edges Protection in Social Networks
Liangwen Yu, Tao Yang 0015, Zhengang Wu, Jian-bin Hu, Zhong Chen 0001
WAIM6
2013 Authenticating Users of Recommender Systems Using Naive Bayes
Zhengang Wu, Liangwen Yu, Huiping Sun, Zhi Guan, Zhong Chen 0001
WISE (1)5
2013 Finding and fixing vulnerabilities in several three-party password authenticated key exchange protocols without server public keys
Hu Xiong, Zhi Guan, Zhong Chen 0001
Inf. Sci.4
2013 An efficient certificateless aggregate signature with constant pairing computations
Hu Xiong, Zhi Guan, Zhong Chen 0001, Fagen Li
Inf. Sci.3
2013 New identity-based three-party authenticated key agreement protocol with provable security
Hu Xiong, Zhong Chen 0001, Fagen Li
J. Netw. Comput. Appl.2
2013 Semantic web services publication and OCT-based discovery in structured P2P network
Huayou Si, Zhong Chen 0001
Serv. Oriented Comput. Appl.2
2012 PUF-Based RFID Authentication Protocol against Secret Key Leakage
Yongming Jin, Huiping Sun, Zhong Chen 0001
APWeb4
2012 P2P-Based Publication and Sharing of Axioms in OWL Ontologies for SPARQL Query Processing in Distributed Environment
Huayou Si, Zhong Chen 0001
APWeb2
2012 A Privacy-Preserving Path-Checking Solution for RFID-Based Supply Chains
Huiping Sun, Tao Yang 0015, Zhi Guan, Zhong Chen 0001
ICICS5
2012 Privacy Protection in Social Networks Using l-Diversity
Liangwen Yu, Zhengang Wu, Tao Yang 0015, Jian-bin Hu, Zhong Chen 0001
ICICS6
2012 Permission-Based Abnormal Application Detection for Android
Zhi Guan, Liangwen Yu, Huiping Sun, Zhong Chen 0001
ICICS6
2012 P2P-based Publication and Location of Web Ontology for Knowledge Sharing in Virtual Communities
Huayou Si, Zhong Chen 0001
SEKE2
2012 RGH: An Efficient RSU-Aided Group-Based Hierarchical Privacy Enhancement Protocol for VANETs
Tao Yang 0015, Lingbo Kong, Liangwen Yu, Jian-bin Hu, Zhong Chen 0001
WAIM5
2012 Bidder-anonymous English auction protocol based on revocable ring signature
Hu Xiong, Zhong Chen 0001, Fagen Li
Expert Syst. Appl.2
2012 Exploiting Consumer Reviews for Product Feature Ranking
Suke Li, Zhi Guan, Liyong Tang, Zhong Chen 0001
J. Comput. Sci. Technol.4
2012 Efficient privacy-preserving authentication protocol for vehicular communications with trustworthy
abstract
ABSTRACT In this paper, we introduce an efficient and trustworthy conditional privacy‐preserving communication protocol for VANETs based on proxy re‐signature. The proposed protocol is characterized by the trusted authority (TA) designating the roadside units to translate signatures computed by the on‐board units into one that are valid with respect to TA's public key. In addition, the proposed protocol offers both a priori and a posteriori countermeasures: it can not only provide fast anonymous authentication and privacy tracking, but also guarantee message trustworthiness for vehicle‐to‐vehicle communications. Furthermore, it reduces the communication overhead and offers fast message authentication and low storage requirements. We use extensive analysis to demonstrate the merits of the proposed protocol and to contrast it with previously proposed solutions. Copyright © 2012 John Wiley & Sons, Ltd.
Hu Xiong, Zhong Chen 0001, Fagen Li
Secur. Commun. Networks2
2012 Information-theoretic modeling of false data filtering schemes in wireless sensor networks
abstract
False data filtering schemes are designed to filter out false data injected by malicious sensors; they keep the network immune to bogus event reports. Theoretic understanding of false data filtering schemes and guidelines to further improve their designs are still lacking. This article first presents an information-theoretic model of false data filtering schemes. From the information-theoretic view, we define the scheme's filtering capacity C F i as the uncertainty-reduction ratio of the target input variable, given the output. This metric not only performs better than existing metrics but also implies that only by optimizing the false negative rate and false positive rate simultaneously, can we promote a scheme's overall performance. Based on the investigation from the modeling efforts, we propose HiFi , a hybrid authentication-based false data filtering scheme. HiFi leverages the benefits of both symmetric and asymmetric cryptography and achieves a high filtering capacity, as well as low computation and communication overhead. Performance analysis demonstrates that our proposed metric is rational and useful, and that HiFi is effective and energy efficient.
Zhi Guan, Zhong Chen 0001
ACM Trans. Sens. Networks4
2011 Need for Symmetry: Addressing Privacy Risks in Online Social Networks
abstract
Private attributes of Online Social Network (OSN) users can be inferred from other information (which is usually from users' friends and group information). To address this, social networking sites allow users to hide their friend lists and group lists, so that general public cannot see them. However, if a user doesn't make his friend list public, but his friends have public friend list where we can find him, we can do reverse lookup to extend the friend lists of the user. Furthermore, many social networks allow non-group members to list the members of public groups (e.g., Face book). These are strong violations of OSN users' privacy, and can be considered as privacy risks caused by the asymmetric configuration of settings in OSNs. In this paper we present the privacy risks due to the lack of symmetric configurations, which exist in most of the OSNs. To make our idea more clear, we propose a inference attack and show that it can be used to infer users' private information, even users already made their friend list private. We theoretically analyze the risk of proposed privacy issues, and evaluate the risk using experiments based on real-world OSN data. We show that it is not sufficient to only disable friend list and group list to guarantee privacy, and propose methods to mitigate these privacy issues.
Cong Tang, Hu Xiong, Tao Yang 0015, Jian-bin Hu, Qingni Shen, Zhong Chen 0001
AINA7
2011 A Traceable Certificateless Threshold Proxy Signature Scheme from Bilinear Pairings
Tao Yang 0015, Hu Xiong, Jian-bin Hu, Biao Xiao, Zhong Chen 0001
APWeb7
2011 A New Leakage-Resilient IBE Scheme in the Relative Leakage Model
Yu Chen 0003, Zhong Chen 0001
DBSec3
2011 Lightweight RFID Mutual Authentication Protocol against Feasible Problems
Yongming Jin, Huiping Sun, Zhong Chen 0001
ICICS5
2011 A Variant of Boyen-Waters Anonymous IBE Scheme
Qingni Shen, Yongming Jin, Yu Chen 0003, Zhong Chen 0001, Sihan Qing
ICICS5
2011 A Multi-compositional Enforcement on Information Flow Security
Cong Sun 0001, Ennan Zhai, Zhong Chen 0001, Jianfeng Ma 0001
ICICS3
2011 Sitab: Combating Spam in Tagging Systems via Users' Implicit Tagging Behavior
abstract
Resisting spam in tagging system is very challenging. This paper presents Sitab, a novel spam-resistant tagging system which can significantly diminish spam in tag search results based on users' implicit tagging behavior. Sitab is trained to obtain the weights of the client's each type of implicit tagging behavior. For each tag search, Sitab ranks each resource in the results list according to its relevance degree which is calculated by the client's implicit tagging behavior with respect to that resource. Experimental results show that Sitab can effectively resist tag spam and work better than existing tag search schemes, especially in systems with large amount of spam tags.
Longzhi Du, Jian-bin Hu, Zhong Chen 0001
ISPA4
2011 Mobile Browser as a Second Factor for Web Authentication
abstract
People's increasingly relying on web applications to manage their digital assets makes web authentication a critical security issue. As most websites today still authenticate a user with only username and password, the authentication credentials can be easily compromised in a vulnerable browsing environment without the owner's notice. Considering the browsing in mobile devices is more secure than personal computers, in this paper we explore the One-Time Password web application running inside mobile browsers as a second authentication factor for high value websites in hostile browsing environments. We discuss the security and efficiency of this authentication method from both theory and practice. An implementation with performance evaluation is also provided to prove our concept.
Zhi Guan, Hu Xiong, Suke Li, Zhong Chen 0001
ISPA4
2011 Generic Methods to Achieve Tighter Security Reductions for a Category of IBE Schemes
Yu Chen 0003, Liqun Chen 0002, Zhong Chen 0001
ISPEC3
2011 New Fully Secure Hierarchical Identity-Based Encryption with Constant Size Ciphertexts
Yu Chen 0003, Jian-bin Hu, Zhong Chen 0001
ISPEC4
2011 Toward Pairing-Free Certificateless Authenticated Key Exchanges
Hu Xiong, Qianhong Wu, Zhong Chen 0001
ISC3
2011 Sorcery: Overcoming deceptive votes in P2P content sharing systems
Ennan Zhai, Huiping Sun, Sihan Qing, Zhong Chen 0001
Peer-to-Peer Netw. Appl.4
2010 Generating Tags for Service Reviews
Suke Li, Jinmei Hao, Zhong Chen 0001
ADMA (2)3
2010 Survey of Authentication in Mobile IPv6 Network
abstract
Mobile IPv6 is a very important part in the mobile computing for global Internet. However, there are some vulnerability and attacks in the current mobile IPv6 such binding update and MITM. Therefore, the safe and flexible model to authenticate every entity is required. This paper studies the existing security problems in the current mobile IPv6; meanwhile, we summary and analyze the existing authentication technology, protocols, infrastructures in the current mobile IPv6 and give the overview of this area.
Huiping Sun, Junde Song, Zhong Chen 0001
CCNC3
2010 Identity-based encryption based on DHIES
abstract
Most traditional public key cryptosystems are constructed upon algebraically rich structures, which makes their key pairs combinable, i.e., the combination of some private keys and their corresponding public keys could form a new key pair. Exploring such combinable property, this paper proposes a novel Identity-Based Encryption (IBE) scheme based on the Diffie-Hellman Integrated Encryption Scheme (DHIES) with quadratic key combination structure from bilinear maps. The new scheme has a number of advantages over other IBE schemes. First, it uses DHIES to fulfill encryption, thus naturally obtains the security against adaptive chosen ciphertext attack from DHIES. Second, it is interoperable with existing security systems based on DHIES. Third, compared to many pairing-based IBE schemes, it only requires pairing computation during public key generation and there is no need for special hash function. We prove that our scheme is selective identity chosen ciphertext secure in the random oracle model assuming DHIES is chosen ciphertext secure. Additionally, the extract algorithm of our scheme also implies an identity-based short signature scheme.
Yu Chen 0003, Manuel Charlemagne, Zhi Guan, Jian-bin Hu, Zhong Chen 0001
AsiaCCS5
2010 When ABE Meets RSS
Yu Chen 0003, Hyunsung Kim 0001, Jian-bin Hu, Zhong Chen 0001
DBSec4
2010 New construction of identity-based proxy re-encryption
abstract
A proxy re-encryption (PRE) scheme involves three parties: Alice, Bob, and a proxy. PRE allows the proxy to translate a ciphertext encrypted under Alice's public key into one that can be decrypted by Bob's secret key. We present a general method to construct an identity-based proxy re-encryption scheme from an existing identity-based encryption scheme. The transformed scheme satisfies the properties of PRE, such as unidirectionality, non-interactivity and multi-use. Moreover, the proposed scheme has master key security, allows the encryptor to decide whether the ciphertext can be re-encrypted.
Jian-bin Hu, Zhong Chen 0001
Digital Rights Management Workshop3
2010 An Adjacency Matrixes-Based Model for Network Security Analysis
abstract
To protect our networks against malicious intrusions, we need to evaluate these networks security. Previous works on attack graphs have provided meaningful conclusions on security measurement. However, large attack graphs are still hard to be understood vividly, and few suggestions have been proposed to prevent inside malicious attackers from attacking networks. To address these problems, we propose a novel approach to evaluate network security based on adjacency matrixes, which are constructed from existing attack graphs. With our model, we use gray scale images to show overall security vividly, and get quantitative evaluation scores. Moreover, we create a prioritized list of potential threatening hosts, which can help network administrators to harden network step by step. Analysis on computation cost shows that the upper bound computation cost of our measurement methodology is O(N3), which could be completed in real time. We also give an example to show how to put our methods in practice.
Anmin Xie, Cong Tang, Nike Gui, Zhuhua Cai, Jian-bin Hu, Zhong Chen 0001
ICC6
2010 Ciphertext Policy Attribute-Based Proxy Re-encryption
Jian-bin Hu, Zhong Chen 0001
ICICS3
2010 DSpam: Defending Against Spam in Tagging Systems via Users' Reliability
abstract
Resisting spam in tagging system is very challenging. This paper presents DSpam, a novel spam-resistant tagging system which can significantly diminish spam in tag search results with users’ reliabilities. DSpam client groups other users into unfamiliar users and interacted users according to the fact whether the client has interacted with such users. For an unfamiliar user, the client computes his reliability by tagging behavior-based mechanism which reflects correlation of annotations between them. For an interacted user, the reliability includes two parts: feedback-based reliability, which indicates direct interactions between that user and the client, and recommendation reliability, which indicates the evaluation about that user from the client’s friends. The client ranks search result with the average reliabilities of himself with respect to annotators of each result. Experimental results show DSpam can effectively resist tag spam and work better than existing tag search schemes.
Ennan Zhai, Cui Cao, Yongqiang Xie, Zhaojun Wang, Jian-bin Hu, Zhong Chen 0001
ICPADS7
2010 Implementing Attribute-Based Encryption in Web Services
abstract
Web services are now widely used in web-based applications. To protect the information in web services, many security specifications have been proposed. Attribute-based Encryption (ABE) provides us a brand new cryptographic primitive for access control. This paper sets out to examine an unexplored area to date - how attribute-based encryption might be used to provide privacy and security for web services. We try to implement ABE in web services. The implementation and performance evaluation demonstrate that ABE is efficient and feasible in web services.
Jian-bin Hu, Zhong Chen 0001
ICWS3
2010 PDUS: P2P-Based Distributed UDDI Service Discovery Approach
abstract
With the widespread deployment of web services, many challenges of the technology have emerged. Among them, the most important one is how to effectively find out the services, which can meet the requestor's requirement, for the traditional UDDI-based centralized approach always suffers from single point of failure and performance bottlenecks. Therefore, this paper takes advantage of P2P technology and proposes a novel P2P-based Distributed UDDI Web Service Discovery (PDUS) approach to overcome these deficiencies. Besides, the paper illustrates this approach through a simple example for PDUS.
Yulin Ni, Huayou Si, Weiping Li 0002, Zhong Chen 0001
ICSS4
2010 SWORDS: Improving Sensor Networks Immunity under Worm Attacks
Nike Gui, Ennan Zhai, Jian-bin Hu, Zhong Chen 0001
WAIM4
2010 Towards Risk Evaluation of Denial-of-Service Vulnerabilities in Security Protocols
Zhi Guan, Zhong Chen 0001, Jian-bin Hu, Liyong Tang
J. Comput. Sci. Technol.3
2009 Evaluating Network Security With Two-Layer Attack Graphs
abstract
Attack graphs play important roles in analyzing network security vulnerabilities, and previous works have provided meaningful conclusions on the generation and security measurement of attack graphs. However, it is still hard for us to understand attack graphs in a large network, and few suggestions have been proposed to prevent inside malicious attackers from attacking networks. To address these problems, we propose a novel approach to generate and describe attack graphs. Firstly, we construct a two-layer attack graph, where the upper layer is a hosts access graph and the lower layer is composed of some host-pair attack graphs. Compared with previous works, our attack graph has simpler structures, and reaches the best upper bound of computation cost in O(N2). Furthermore, we introduce the adjacency matrix to efficiently evaluate network security, with overall evaluation results presented by gray scale images vividly. Thirdly, by applying prospective damage and important weight factors on key hosts with crucial resources, we can create prioritized lists of potential threatening hosts and stepping stones, both of which can help network administrators to harden network security. Analysis on computation cost shows that the upper bound computation cost of our measurement methodology is O(N3), which could also be completed in real time. Finally, we give some examples to show how to put our methods in practice.
Anmin Xie, Zhuhua Cai, Cong Tang, Jian-bin Hu, Zhong Chen 0001
ACSAC5
2009 Filtering Spam in Social Tagging System with Dynamic Behavior Analysis
abstract
Spam in social tagging systems introduced by some malicious participants has become a serious problem for its global popularizing. Some studies which can be deduced to static user data analysis have been presented to combat tag spam, but either they do not give an exact evaluation or the algorithms' performances are not good enough. In this paper, we proposed a novel method based on analysis of dynamic user behavior data for the notion that users' behaviors in social tagging system can reflect the quality of tags more accurately. Through modeling the different categories of participants' behaviors, we extract tag-associated actions which can be used to estimate whether tag is spam, and then present our algorithm that can filter the tag spam in the results of social search. The experiment results show that our method indeed outperforms the existing methods based on static data and effectively defends against the tag spam in various spam attacks.
Ennan Zhai, Huiping Sun, Yelu Chen, Zhong Chen 0001
ASONAM5
2009 SpamResist: Making Peer-to-Peer Tagging Systems Robust to Spam
abstract
Tagging systems are known to be particularly vulnerable to tag spam. Due to the self-organization and self-maintenance nature of Peer-to-Peer (P2P) overlay networks, users in the P2P tagging systems are more vulnerable to tag spam than the centralized ones. This paper proposes SpamResist, a novel social reliability-based mechanism. For each tag search, SpamResist client groups the search respondents into two categories, namely unfamiliar peers and interacted peers according to the fact whether the client has interacted with such respondents. For the two different categories of peers, the client computes their reliability degrees, and then utilizes these reliability degrees as weights to rank search results. To obtain higher quality search results, we propose a socially-enhanced mechanism, considering social friends can share their previous experience and help improve both the performance and convergence of SpamResist. Finally, the experimental results illustrate that SpamResist can effectively defend against tag spam and work better than the existing search models in P2P tagging systems.
Ennan Zhai, Ruichuan Chen, Eng Keong Lua, Long Zhang 0003, Huiping Sun, Zhuhua Cai, Sihan Qing, Zhong Chen 0001
GLOBECOM8
2009 Trusted Isolation Environment: An Attestation Architecture with Usage Control Model
Anbang Ruan, Qingni Shen, Liang Gu, Yahui Yang, Zhong Chen 0001
ICICS7
2009 Sorcery: Could We Make P2P Content Sharing Systems Robust to Deceivers?
abstract
Deceptive behaviors of peers in peer-to-peer (P2P) content sharing systems have become a serious problem due to the features of P2P overlay networks such as anonymity, self-organization, etc. This paper presents Sorcery, a novel active challenge-response mechanism based on the notion that one side of interaction with dominant information can detect whether the other side is telling a lie. To make each client obtain the dominant information, our approach introduces social network to the P2P content sharing system; thus, the client can establish friend-relationships with peers who are either acquaintances in reality or those reliable online friends. Using the confidential voting histories of friends as own dominant information, the client can challenge the content providers with the overlapping votes of both his friends and the content provider, thus detecting whether the content provider is a deceiver. Moreover, Sorcery provides the punishment mechanism which can reduce the impact brought by deceptive behaviors, and our work also discusses some key practical issues. The experimental results illustrate that Sorcery can effectively address the problem of deceptive behaviors, and work better than the existing reputation models.
Ennan Zhai, Ruichuan Chen, Zhuhua Cai, Long Zhang 0003, Eng Keong Lua, Huiping Sun, Sihan Qing, Liyong Tang, Zhong Chen 0001
Peer-to-Peer Computing9
2008 Scalable Byzantine Fault Tolerant Public Key Authentication for Peer-to-Peer Networks
Ruichuan Chen, Wenjia Guo, Liyong Tang, Jian-bin Hu, Zhong Chen 0001
Euro-Par5
2008 WebIBC: Identity Based Cryptography for Client Side Security in Web Applications
abstract
The growing popularity of web applications in the last few years has led users to give the management of their data to online application providers, which will endanger the security and privacy of the users. In this paper, we present WebIBC, which integrates public key cryptography into web applications without any browser plugins. The public key of WebIBC is provided by identity based cryptography, eliminating the need of public key and certificate online retrieval; the private key is supplied by the fragment identifier of the URL inspired by BeamAuth. The implementation and performance evaluation demonstrate that WebIBC is secure and efficient both in theory and practice.
Zhi Guan, Ruichuan Chen, Zhong Chen 0001, Xianghao Nan
ICDCS5
2008 Pseudo-randomness Inside Web Browsers
Zhi Guan, Long Zhang 0003, Zhong Chen 0001, Xianghao Nan
ICICS3
2008 Securing Peer-to-Peer Content Sharing Service from Poisoning Attacks
abstract
Poisoning attacks in the Peer-to-Peer (P2P) content sharing service have become a serious security problem on the global Internet due to the features of P2P systems such as self-organization, self-maintenance, etc. In this paper, we propose a novel poisoning-resistant security framework based on the notion that the content providers would be the only trusted sources to verify the integrity of the requested content. To provide the mechanisms of availability and scalability, a content provider publishes the information of his shared contents to a group of content maintainers self-organized in a security overlay, so that a content requestor can verify the integrity of the requested content from the associated content maintainers. Two defense functions are first carried out - filtering out malicious activities and selecting the authentic content version. Then, the content requestor can perform the content integrity verification while downloading and take prompt protection actions to handle content poisoning attacks. To further enhance the system performance, we devise a scalable probabilistic verification scheme. The evaluation results illustrate that our framework can effectively and efficiently defend against content poisoning in various scenarios.
Ruichuan Chen, Eng Keong Lua, Jon Crowcroft, Wenjia Guo, Liyong Tang, Zhong Chen 0001
Peer-to-Peer Computing6
2007 LENO: LEast Rotation Near-Optimal Cluster Head Rotation Strategy in Wireless Sensor Networks
abstract
Cluster-based self-organization scheme is attracting tremendous research interest in the studies of the wireless sensor networks (WSN), because it meets the critical runtime requirement of the WSN based applications: working in self-organized and energy efficient way. Whereas, an important problem in the cluster scheme remains seldom studied, that the cluster heads depletes energy very fast and the rotation strategy of the cluster head is needed to prolong the system's lifetime. In this paper, the cluster head rotation problem is studied with the dynamic programming method. An energy first cluster head rotation strategy is proposed and is proved to be the optimal in the means of the cluster lifetime. Further, the upper bound and the lower bound of the cluster lifetime are derived based on the law of conservation of energy. We show that the optimal strategy is not unique, which can be accomplished in different ways. Based on the analysis, a practical, LEast-rotation, near-optimal cluster head rotation algorithm (LENO) is proposed to practice the inner cluster rotation. The validity of LENO is verified with the node level simulation tool PowerTOSSIM. Near optimal cluster lifetime is obtained as desired, which is much better than the performances of Leach and EDAC etc.
Zhong Chen 0001, Yongcai Wang
AINA2
2007 CuboidTrust: A Global Reputation-Based Trust Model in Peer-to-Peer Networks
Ruichuan Chen, Liyong Tang, Jian-bin Hu, Zhong Chen 0001
ATC5
2007 Hybrid Overlay Structure Based on Virtual Node
abstract
Current peer-to-peer architectures generally can be grouped into three categories: centralized architectures that utilize central directory servers to process queries, decentralized structured architectures that accurately build an underlying topology to support distributed hash table efficiently, and decentralized unstructured architectures that impose no structure on the topology and typically propagate queries to neighbors for searching. Aiming at integrating the flexibility of unstructured architectures with the regularity of structured architectures, we propose a hybrid overlay structure based on virtual node. Especially, the hybrid architecture utilizes virtual nodes to build a distributed ring with random links. We can use the distributed ring to perform short jumps, and apply random links to long jumps. With our hybrid design, keyword searching, even multi-keyword searching, can be performed efficiently; both popular and rare keywords can be quickly located. Furthermore, our architecture is robust to the change of system scale, and it can work well with low maintenance cost in the dynamic environment.
Ruichuan Chen, Wenjia Guo, Liyong Tang, Jian-bin Hu, Zhong Chen 0001
ISCC5
2007 An Economical Model for the Risk Evaluation of DoS Vulnerabilities in Cryptography Protocols
Zhi Guan, Zhong Chen 0001, Jian-bin Hu, Liyong Tang
ISPEC3
2006 Feedback: Towards Dynamic Behavior and Secure Routing forWireless Sensor Networks
abstract
Wireless sensor networks, due to their potentially wide application perspectives, may proliferate in future. Two major stumbling blocks are the dynamic variance of network topology caused by the energy constraint of sensor nodes and uncertainties of wireless links, and the security routing in this severe security environment. Therefore adaptable and defendable routing mechanism is in urgent need for the deployment of these networks. In this paper we propose FBSR, a novel feedback based secure routing protocol. Feedback from both the nearby neighbors and base stations, serves as the dynamic information of the current network with which sensor nodes make forwarding decision in a secure and energy aware manner. We present both mathematical analysis and simulation results to show the efficiency of FBSR
Jian-bin Hu, Zhong Chen 0001, Maoxing Xu
AINA (2)3
2006 C4W: An Energy Efficient Public Key Cryptosystem for Large-Scale Wireless Sensor Networks
abstract
With hardware support and software optimization, public key cryptography (PKC) has been announced feasible on micro sensors recently. A number of experiments proved that the elliptic curve cryptography (ECC) is more suitable for resource constraint motes compared with RSA, But even ECC based protocols still cost too much energy. In this paper, we propose C4W, an identity-based public key infrastructure specially designed for wireless sensor networks (WSNs), in which all nodes can generate other's ECC public keys directly from their identities. Without certificates, no energy will be consumed for certificates communication and verification, which makes C4W especially energy efficient. C4W uses a protocol without certificates to realize mutual authentication and key agreement. Compared with a simplified SSL (SSSL) protocol using an abbreviated certificate, C4W consumes lower than 35% energy, and the communication consumption of C4W is only 28.5% of that consumed by SSSL. Furthermore, the energy analysis of C4W illuminates that the expensive public key computational cost is almost neglectable compared with the heavy communication consumption in a large-scale WSNs, which gives the asymmetric key management in WSNs a bright future
Jian-bin Hu, Zhong Chen 0001
MASS3
2005 A Formal Language for Access Control Policies in Distributed Environment
abstract
Although several access control policies have been proposed for securing access to resources, they focused on security of distributed environments that were rather static. Nowadays, distributed environment becomes open and dynamic. In this paper, we propose a formal language for access control policies in open and dynamic environment. The language is based on description logic program and generalized courteous logic program supporting classical negation, prioritized conflict handling and mutual exclusion constraints. The language allows the specification of positive and negative authorization, privilege delegation and revocation, prioritized conflict resolution and mutual authorization exclusions.
Jian-bin Hu, Zhong Chen 0001
Web Intelligence3