VLDB 2026 Research / reviewers in the wild / expert
Zhi Guan
dblp:78/7008
· DBLP profile ↗
46ranked-venue papers
4as first author
21since 2021 · last 2026
0000-0002-6144-4815ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 13 · 2 first-author · 4 since 2021Software engineering, systems software and programming languages · 11 · 8 since 2021Databases, data management, data science and information retrieval · 8 · 1 since 2021Systems, architecture and hardware · 5 · 2 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 2 since 2021Artificial intelligence and machine learning · 3 · 3 since 2021Computer networks · 3 · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Towards Secure Oracle Usage: Understanding and Detecting the Vulnerabilities in Oracle Contracts
Yue Li 0037, Jiashuo Zhang 0001, Jianbo Gao 0003, Jiakun Hao, Anming Xie, Zhi Guan, Zhong Chen 0001 |
SANER | 8 |
| 2026 | Heimdall: A Decentralized Access Control Scheme With Time-Based Secret Management and Private Access PoliciesabstractDecentralized Access Control (DAC) manages access through multiple entities, consisting of two modules: decentralized secret management and access policies. However, existing DAC schemes lack support for managing secrets with time-based conditions, such as triggering secret release after a certain time bound. In this case, users may gain access to information before the designated time, which is undesirable in scenarios involving time-sensitive data. Moreover, current DAC schemes mainly focus on identity confidentiality and lack support for policy confidentiality, which may lead to leakage of sensitive information in access policies. To address these challenges, we propose Heimdall, a decentralized access control scheme with time-based secret management and private access policies. The core of our solution is the dhNIZK protocol, an efficient non-interactive zero-knowledge protocol designed for the verifiable incorporation of time conditions into threshold cryptosystems. We utilize this dhNIZK protocol and homomorphic time-lock puzzles to enable time-based secret management, improving the efficiency of secret reconstruction through batch puzzle-solving techniques. Furthermore, we enhance the garbling scheme’s encoding algorithm to ensure policy confidentiality while maintaining identity confidentiality. Finally, we implement Heimdall and present experimental results demonstrating its superior performance compared to the state-of-the-art solutions. Libin Xia, Yue Li 0037, Jiashuo Zhang 0001, Jianbo Gao 0003, Zhi Guan, Zhong Chen 0001 |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2026 | Web3ID: A Privacy-Preserving and DApp-Oriented Decentralized Identity Framework for Web3.0abstractWith the development of Web3.0, decentralized identity and other blockchain-based identity empower users with control, forming the foundational infrastructure for Web3.0 ecosystems. However, existing identity frameworks remain inadequate in addressing critical challenges such as on-chain privacy during identity management and utilization. While prior works like CanDID, Hades, and CertChain explore blockchain-based identity solutions, they fail to meet the specific reqirements of DApps. Moreover, users on blockchain always store their identity data and digital assets across multiple accounts and DApps, but current identity schemes cannot support the cross-account and DApp identity privacy-preserving utilization. To bridge this gap, we propose Web3ID, the first fully DApp-oriented identity framework. By analyzing Ethereum identity proposals and user behavior patterns, we design the Web3ID featuring: on-chain privacy-preserving identity aggregation protocol, provably secure attribute-based access control model, and zk-rollup enhanced off-chain identity management. Experiments demonstrate that Web3ID enables privacy-preserving identity management and authentication on-chain, and guaranteeing access control completeness. The prototype system achieves a 100× improvement in proof/verification efficiency and reduces storage overhead by 85× compared to pure on-chain implementation through off-chain optimization techniques. Moreover, in comparison with other identity privacy solutions, Web3ID exhibits the lowest gas consumption during on-chain utilization and shows strong scalability. As a fully decentralized identity framework supporting end-to-end DApp integration, Web3ID advances Web3.0’s vision of user sovereignty, decentralization, and interoperability. This work establishes both theoretical and practical foundations for on-chain identity systems in Web3.0 ecosystems. Jiakun Hao, Jianbo Gao 0003, Libin Xia, Zhi Guan, Zhong Chen 0001 |
ACM Trans. Web | 6 |
| 2025 | Automated Test Generation For Smart Contracts via On-Chain Test Case Augmentation and MigrationabstractPre-deployment testing has become essential to ensure the functional correctness of smart contracts. However, since smart contracts are stateful programs integrating many different functionalities, manually writing test cases to cover all potential usages requires significant effort from developers, leading to insufficient testing and increasing risks in practice. Although several testing techniques for smart contracts have been proposed, they primarily focus on detecting common low-level vulnerabilities such as re-entrancy, rather than generating expressive and function-relevant test cases that can reduce manual testing efforts. To bridge the gap, we propose Solmigrator, an automated technique designed to generate expressive and representative test cases for smart contracts. To our knowledge, Solmigrator is the first migration-based test generation technique for smart contracts, which extracts test cases from real-world usages of on-chain contracts and migrates them to test newly developed smart contracts with similar functionalities. Given a target smart contract to be tested and an on-chain similar source smart contract, Solmigrator first transforms the on-chain usage of the source contract into off-chain executable test cases based on on-chain transaction replay and dependency analysis. It then employs fine-grained static analysis to migrate the augmented test cases from the source to the target smart contract. We built a prototype of Solmigrator and have evaluated it on real-world smart contracts within the two most popular categories, ERC20 and ERC721. Our evaluation results demonstrate that Solmigrator effectively extracts test cases from existing on-chain smart contracts and accurately migrates them across different smart contracts, achieving an average precision of 96.3% and accuracy of 93.6%. Furthermore, the results indicate that these migrated test cases effectively cover common key functionalities of the target smart contracts. This provides promising evidence that real-world usages of existing smart contracts can be transformed into effective test cases for other newly developed smart contracts. Jiashuo Zhang 0001, Jiachi Chen, John C. Grundy, Jianbo Gao 0003, Yanlin Wang 0001, Ting Chen 0002, Zhi Guan, Zhong Chen 0001 |
ICSE | 7 |
| 2025 | A sharding blockchain-based UAV system for search and rescue missions
Xihan Zhang, Jiashuo Zhang 0001, Jianbo Gao 0003, Libin Xia, Zhi Guan, Zhong Chen 0001 |
Frontiers Comput. Sci. | 5 |
| 2024 | Understanding and Detecting Privacy Leakage Vulnerabilities in Hyperledger Fabric ChaincodesabstractThe application on a blockchain cannot maintain secrecy because its data is replicated across all peers in the network. To remedy this problem, Hyperledger Fabric introduces private data collection (PDC) into its smart contract (i.e. chaincode) to facilitate applications that require privacy. However, recent studies have revealed that PDC is too complex for chaincode developers to fully understand and use correctly, leading to privacy leaks vulnerabilities. In this paper, we present an empirical study on the prevalence of PDC misuse in chaincodes by extracting privacy leakage cases from StackOverflow posts and Hyperledger Fabric repositories on GitHub. Subsequently, we systematically categorize the misuse of PDC into three categories of vulnerabilities resulting in the leakage of private data and provide formal definitions for them. Furthermore, we develop PDChecker, an automated security analysis framework for identifying the privacy and security vulnerabilities in Fabric chaincodes. We evaluated PDChecker on 956 real-world chaincodes applying PDC and found that 67.78% of them contain at least one privacy leakage vulnerability. In addition, PDChecker uncovered 10 zero-day vulnerabilities documented by the China National Vulnerability Database. Yue Li 0037, Jianbo Gao 0003, Jiashuo Zhang 0001, Ke Wang 0061, Jian-bin Hu, Zhi Guan, Zhong Chen 0001 |
ISSRE | 7 |
| 2024 | SolaSim: Clone Detection for Solana Smart Contracts via Program RepresentationabstractThe open-source nature of smart contracts provides the facility for developers to clone contracts and introduces the risk of vulnerability proliferation as well. Despite intensive research on smart contract clone detection in recent years, existing techniques are still unsatisfactory in detecting Solana smart contracts. To fill this gap, in this paper, we designed a clone detection tool SolaSim for Solana smart contracts and conducted an empirical study to understand the code reuse in the Solana ecosystem. Specifically, SolaSim is based on the semantic metadata extractor and the similarity checker. For each contract, the semantic metadata extractor generates an instruction-level weighted Attributed Control Flow Graph (ACFG) and its semantic metadata (i.e., a combination of high-level semantic and structure information) based on Rust Mid-level Intermediate Representation. The similarity checker adopts a combinatorial optimization algorithm to compute the statistical similarity of a pair of contracts. The evaluation results demonstrated the effectiveness of SolaSim in identifying clones with 94.3% accuracy and it can identify up to Type-3 clone level. Notably, we found there are over 50% clone ratios in the Solana smart contracts ecosystem, in which most of them are cloned from famous open-sourced projects. Yue Li 0037, Jianbo Gao 0003, Ke Wang 0061, Jiashuo Zhang 0001, Zhi Guan, Zhong Chen 0001 |
ICPC | 6 |
| 2024 | ContractTinker: LLM-Empowered Vulnerability Repair for Real-World Smart ContractsabstractSmart contracts are susceptible to being exploited by attackers, especially when facing real-world vulnerabilities. To mitigate this risk, developers often rely on third-party audit services to identify potential vulnerabilities before project deployment. Nevertheless, repairing the identified vulnerabilities is still complex and laborintensive, particularly for developers lacking security expertise. Moreover, existing pattern-based repair tools mostly fail to address real-world vulnerabilities due to their lack of high-level semantic understanding. To fill this gap, we propose ContractTinker, a Large Language Models (LLMs)-empowered tool for real-world vulnerability repair. The key insight is our adoption of the Chain-of-Thought approach to break down the entire generation task into subtasks. Additionally, to reduce hallucination, we integrate program static analysis to guide the LLM. We evaluate ContractTinker on 48 high-risk vulnerabilities. The experimental results show that among the patches generated by ContractTinker, 23 (48%) are valid patches that fix the vulnerabilities, while 10 (21%) require only minor modifications. A video of ContractTinker is available at https://youtu.be/HWFVi-YHcPE. Jiashuo Zhang 0001, Jianbo Gao 0003, Libin Xia, Zhi Guan, Zhong Chen 0001 |
ASE | 5 |
| 2024 | Cryptcoder: An Automatic Code Generator for Cryptographic Tasks in Ethereum Smart ContractsabstractCryptographic APIs provided by Ethereum are widely adopted in decentralized applications (DApps) for cryptographic operations. However, developers who lack expertise in cryptography frequently encounter difficulties when working with low-level cryptographic APIs, thereby producing insecure code. To address this issue, we introduce Cryptcoder, an automatic code generator designed to bridge the gap between low-level cryptographic APIs and high-level cryptographic tasks in Ethereum. The fundamental component of Cryptcoder is Cryptlang, a Solidity-compatible domain-specific language (DSL) designed for cryptographic tasks. Developers can utilize Cryptlang for the straightforward and secure implementation of cryptographic tasks, such as signatures and commitments, and employ Cryptcoder for the automatic conversion into Solidity code. The evaluation of Cryptcoder demonstrates both its functionality in generating Solidity code and an acceptable overhead, evidenced by a mere 4% average increase in gas costs compared to the reference code. A demonstration video of Cryptcoder is available at https://youtu.be/AxhCdGiu7dw. Libin Xia, Jiashuo Zhang 0001, Zezhong Tan, Jianbo Gao 0003, Zhi Guan, Zhong Chen 0001 |
SANER | 6 |
| 2024 | FedTop: a constraint-loosed federated learning aggregation method against poisoning attack
Zhenhao Wu, Jianbo Gao 0003, Jiashuo Zhang 0001, Junjie Xia, Zhi Guan, Zhong Chen 0001 |
Frontiers Comput. Sci. | 7 |
| 2024 | Accelerating block lifecycle on blockchain via hardware transactional memoryabstractThe processing of block lifecycles is essential to the efficiency of a blockchain, which consists of four steps: creation, execution, consensus, and validation. The permissionless blockchain systems typically had very limited transaction throughput because of the performance bottleneck of consensus protocols. With recent advances in consensus protocols, the execution and validation of transactions have become the new performance bottleneck. We propose a novel framework, called FastBlock, to speed up the execution and validation steps by introducing fine-grained concurrency. Our early design of FastBlock supported three key modules: (1) a symbolic execution-based analyzer that automatically identifies minimal atomic sections in each transaction; (2) a concurrent execution step that executes possibly conflicting transactions in parallel using hardware transactional memory; (3) a concurrent validation step that introduces a happen-before relation to deterministically re-execute transactions. The improved FastBlock presented in this article supports the nonce mechanism to schedule concurrent transactions from the same account. Moreover, we empirically study the impact of concurrency on Ethereum except for performance and shed light on potential optimizations of FastBlock. Finally, we implemented FastBlock and then evaluated the performance of FastBlock. Our result shows that the FastBlock outperforms state-of-art solutions significantly in performance: the execution step and validation step speed up to 3.0x and 2.3x on average over the original serial model, respectively, with eight concurrent threads. In addition, we evaluated the impact of the nonce mechanism, and the result shows that the performance loss caused by this mechanism is acceptable in practice. Yue Li 0037, Han Liu 0010, Jianbo Gao 0003, Jiashuo Zhang 0001, Zhi Guan, Zhong Chen 0001 |
J. Parallel Distributed Comput. | 5 |
| 2024 | SStore: An Efficient and Secure Provable Data Auditing Platform for CloudabstractAs more internet users opt to store their data in cloud storage, ensuring data integrity becomes a paramount concern. The emerging provable data possession (PDP) scheme enables auditors to verify data integrity with reduced bandwidth consumption compared to hash-based alternatives. Nevertheless, most existing PDP variants rely on a centralized node for generating or maintaining user keys, creating a potential single point of failure. Moreover, previous PDP schemes could only detect whether challenged data blocks were corrupted, lacking the ability to pinpoint affected blocks precisely. To tackle these challenges, we propose a novel PDP scheme that eliminates the necessity for a key management center and supports the localization of corrupted data blocks. In our scheme, users no longer need to retain private keys once they cease performing data dynamic operations, thus liberating them from reliance on external entities for key maintenance. Moreover, the new scheme utilizes existing authenticators in the cloud to identify corrupted file blocks, eliminating the necessity of storing hash values for these data blocks as seen in most of existing implementations. This effectively reduces required storage space. Furthermore, we introduce SStore, a decentralized cloud storage platform that incorporates the new PDP scheme to verify data integrity. SStore facilitates public auditing of user data, thereby enhancing transparency in the data verification procedure. Moreover, SStore leverages basic algebraic operations for data auditing, significantly increasing its efficiency. We analyze the security of the new PDP scheme, and evaluate the performance of both the PDP scheme and SStore to demonstrate their efficiency. Lipeng Wang 0001, Zhijuan Jia, Zhi Guan, Zhong Chen 0001 |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2023 | Hades: Practical Decentralized Identity with Full Accountability and Fine-grained Sybil-resistanceabstractDecentralized identity (DID), the idea of giving users complete control over their identity-related data, is being used to solve the privacy tension in the identity management of decentralized applications (Dapps). While existing approaches do an excellent job of solving the privacy tension, they have not adequately addressed the accountability and Sybil-resistance issues. Moreover, these approaches have a considerable gas overhead, making them impractical for Dapps. Ke Wang 0061, Jianbo Gao 0003, Jiashuo Zhang 0001, Yue Li 0037, Zhi Guan, Zhong Chen 0001 |
ACSAC | 6 |
| 2023 | DFHelper: Help clients to participate in federated learning tasks
Zhenhao Wu, Jianbo Gao 0003, Jiashuo Zhang 0001, Yue Li 0037, Qingshan Li, Zhi Guan, Zhong Chen 0001 |
Appl. Intell. | 6 |
| 2023 | Enabling Integrity and Compliance Auditing in Blockchain-Based GDPR-Compliant Data ManagementabstractThe general data protection regulation (GDPR) is a European Union (EU) data protection and privacy law. According to the GDPR, the data on a hosting platform must meet semantic consistency and data integrity requirements. Semantic consistency means that the data operation should comply with the GDPR, while data integrity is meant to ensure that the outsourcing data should be intact. The two terms are not interchangeable. For example, if a cloud service provider migrates data to foreign storage nodes without authorization of the data owner, the data integrity requirement of the GDPR is met but the semantic consistency requirement is not. How to ensure data integrity and compliance is the main challenge for a GDPR-compliant data supervision platform. To achieve this aim, we leverage a blockchain-based data management framework to check the data compliance, which can break the black box of the data hosting platform and demonstrate its logic to data owners, allowing for inspection. We propose a new provable data possession (PDP) scheme for the aforementioned framework that can check for semantic consistency and data integrity simultaneously. The verifier does not need to hold any audited data, which can reduce bandwidth usage. The verification result can be regarded as the proof for subsequent data recovery and accountability. Experimental results show higher efficiency of the PDP scheme. Lipeng Wang 0001, Zhi Guan, Zhong Chen 0001 |
IEEE Internet Things J. | 2 |
| 2023 | sChain: An Efficient and Secure Solution for Improving Blockchain StorageabstractEmerging blockchain technology has become the cornerstone of many applications providing trusted data services. However, existing blockchain platforms cannot meet the growing demand for big data storage. Blockchain should duplicate both transactions and other user-defined data across nodes for integrity assurance. The rapid expansion of data on blockchain (on-chain data) increases the difficulty of deploying a full node, resulting in decreasing the degree of decentralization and adding the risk of broken data. To tackle these problems, we propose sChain, a novel framework for improving blockchain storage capacity, which does not revise blockchain implementation and can be applied to almost all the existing blockchain platforms. sChain outsources the user data to storage devices that are structurally external to the blockchain network. In theory, a user can outsource unlimited data to sChain. However, those off-chain data may suffer from corruption. To verify the data integrity, we propose a new provable data possession (PDP) scheme, which does not need a centralized entity to maintain any secret keys and therefore eliminates a single point of failure. What is more, we also design a prototype to accelerate the proposed PDP scheme through Intel SGX technology and parallel processing. Security analysis and evaluation results show that sChain can protect data security and effectively improve the blockchain storage capacity, respectively. Lipeng Wang 0001, Zhi Guan, Zhong Chen 0001 |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2022 | TBFT: Efficient Byzantine Fault Tolerance Using Trusted Execution EnvironmentabstractWith the rapid development of blockchain, Byzantine fault-tolerant protocols have attracted revived interest recently. To overcome the theoretical bounds of Byzantine fault tolerance, many protocols attempt to use Trusted Execution Environment (TEE) to prevent equivocation and improve fault tolerance from less than 1/3 to minority. However, due to the broken quorum intersection assumption caused by the reduction of replica number, most improvements introduce higher communication complexity or more protocol phases, which affects the performance and scalability of existing TEE-based protocols and prevents them to be applied to large-scale blockchain systems. In this paper, we propose TBFT, an efficient Byzantine fault-tolerant protocol in the partial synchrony setting, which has O(n) message complexity and only two protocol phases in normal-case. The key insight behind TBFT is introducing novel TEE-assisted primitives to limit malicious behaviors of replicas including not only equivocation but also message log forgery and message history forgery, therefore both the communication complexity and protocol phases can be reduced. We have implemented TBFT and evaluated it through systematic analysis and experiments, and the results show that TBFT has better performance and scalability compared to other protocols. Jiashuo Zhang 0001, Jianbo Gao 0003, Ke Wang 0061, Zhenhao Wu, Yue Li 0037, Zhi Guan, Zhong Chen 0001 |
ICC | 6 |
| 2022 | Xscope: Hunting for Cross-Chain Bridge AttacksabstractCross-Chain bridges have become the most popular solution to support asset interoperability between heterogeneous blockchains. However, while providing efficient and flexible cross-chain asset transfer, the complex workflow involving both on-chain smart contracts and off-chain programs causes emerging security issues. In the past year, there have been more than ten severe attacks against cross-chain bridges, causing billions of loss. With few studies focusing on the security of cross-chain bridges, the community still lacks the knowledge and tools to mitigate this significant threat. To bridge the gap, we conduct the first study on the security of cross-chain bridges. We document three new classes of security bugs and propose a set of security properties and patterns to characterize them. Based on those patterns, we design Xscope, an automatic tool to find security violations in cross-chain bridges and detect real-world attacks. We evaluate Xscope on four popular cross-chain bridges. It successfully detects all known attacks and finds suspicious attacks unreported before. A video of Xscope is available at https://youtu.be/vMRO_qOqtXY. Jiashuo Zhang 0001, Jianbo Gao 0003, Yue Li 0037, Zhi Guan, Zhong Chen 0001 |
ASE | 5 |
| 2022 | Smifier: A Smart Contract Verifier for Composite TransactionsabstractEnsuring functional correctness of smart contracts is a pressing security concern to blockchain-based systems.With the development of blockchain application, the trading scenarios and function implementation of smart contracts have become increasing complex, containing several interacted contracts or related functions.However, the existing contracts verifiers for proving functional correctness focus on verifying isolated contract or function but ignore the interactions between them, which makes it difficult to verify correctness of composite transactions, i.e., complex transaction scenarios that invoke multiple contracts or trigger a set of transactions.In this paper, we present SMIFIER, a formal verification tool for smart contracts to prove functional properties in composite transactions.SMIFIER defines a set of specifications for composite transactions and can automatically specify properties in these multiple complex transactions.Based on states extraction and mapping, SMIFIER translates annotated Solidity program into Boogie program and verifies relations between functions and properties for interacted contracts.Our experimental evaluation on 12 real-world projects and 65 properties, demonstrates that SMIFIER is practically effective in ensuring functional correctness of properties in composite transactions. Yue Li 0037, Dongqi Cui, Jianbo Gao 0003, Zhi Guan, Zhong Chen 0001 |
SEKE | 5 |
| 2022 | Make aspect-based sentiment classification go further: step into the long-document-level
Zhenhao Wu, Jianbo Gao 0003, Qingshan Li, Zhi Guan, Zhong Chen 0001 |
Appl. Intell. | 4 |
| 2021 | FASTBLOCK: Accelerating Blockchains via Hardware Transactional MemoryabstractThe efficiency of block lifecycle determines the performance of blockchain, which is critically affected by the execution, mining and validation steps in blockchain lifecycle. To accelerate blockchains, many works focus on optimizing the mining step while ignoring other steps. In this paper, we propose a novel blockchain framework-FastBlock to speed up the execution and validation steps by introducing efficient concurrency. To efficiently prevent the potential concurrency violations, FastBlock utilizes symbolic execution to identify minimal atomic sections in each transaction and guarantees the atomicity of these sections in execution step via an efficient concurrency control mechanism-hardware transactional memory (HTM). To enable a deterministic validation step, FastBlock concurrently re-executes transactions based on a happen-before graph without increasing block size. Finally, we implement FastBlock and evaluate it in terms of conflicting transactions rate, number of transactions per block, and varying thread number. Our results indicate that FastBlock is efficient: the execution step and validation step speed up to 3.0x and 2.3x on average over the original serial model respectively with eight concurrent threads. Yue Li 0037, Han Liu 0010, Yuanliang Chen, Jianbo Gao 0003, Zhenhao Wu, Zhi Guan, Zhong Chen 0001 |
ICDCS | 6 |
| 2020 | Kaya: A Testing Framework for Blockchain-based Decentralized ApplicationsabstractIn recent years, many decentralized applications based on blockchain (DApp) have been developed. Some development tools provide testing functions, but only for developers to write unit tests for smart contracts rather than test DApp as a whole. Moreover, due to the difficulty for testers to understand the implementation details of smart contracts, insufficient functional testing causes some DApps not to meet functional design expectations. The inherent complexity of DApp, inconvenient pre-state setting, and not-so-readable logs make DApp testing challenging. In this paper, we propose Kaya, a testing framework for DApps to bridge these gaps. Firstly, Kaya formulate automatically executed test cases that cover both front-end behaviors and back-end logics with simple setting. Secondly, Kaya provides a flexible and convenient way for test engineers to set the blockchain pre-states. Thirdly, Kaya transforms incomprehensible addresses into readable variables for easier comprehension. Besides, to fit the various application environments, we provide both GUI and CLI for test engineers to use Kaya. Our case study and preliminary human study demonstrates the potential of Kaya in helping test engineers to test DApps more easily. A demo video is at https://youtu.be/7DyI_EpVZFw. Zhenhao Wu, Jiashuo Zhang 0001, Jianbo Gao 0003, Yue Li 0037, Qingshan Li, Zhi Guan, Zhong Chen 0001 |
ICSME | 6 |
| 2020 | EShield: protect smart contracts against reverse engineeringabstractSmart contracts are the back-end programs of blockchain-based applications and the execution results are deterministic and publicly visible. Developers are unwilling to release source code of some smart contracts to generate randomness or for security reasons, however, attackers still can use reverse engineering tools to decompile and analyze the code. In this paper, we propose EShield, an automated security enhancement tool for protecting smart contracts against reverse engineering. EShield replaces original instructions of operating jump addresses with anti-patterns to interfere with control flow recovery from bytecode. We have implemented four methods in EShield and conducted an experiment on over 20k smart contracts. The evaluation results show that all the protected smart contracts are resistant to three different reverse engineering tools with little extra gas cost. Wentian Yan, Jianbo Gao 0003, Zhenhao Wu, Yue Li 0037, Zhi Guan, Qingshan Li, Zhong Chen 0001 |
ISSTA | 5 |
| 2019 | AuthLedger: A Novel Blockchain-based Domain Name Authentication SchemeabstractInternational audience Zhi Guan, Abba Garba, Anran Li 0006, Zhong Chen 0001, Nesrine Kaaniche |
ICISSP | 1 |
| 2019 | Towards automated testing of blockchain-based decentralized applicationsabstractBlockchain-based decentralized applications (DApp) have been widely adopted in different areas and trusted by more and more users due to the fact that the back end code of a DApp is publicly run on the blockchain and cannot be modified implicitly. However, there are few effective methods and tools for testing DApps and bugs can be easily introduced by inexperienced developers. The existing testing techniques either focus on testing front-end programs or back-end code but ignore the interaction between them, which makes it difficult to apply the techniques directly on DApp. In this paper, we present an automated testing technique for DApps which works in a two-phase manner. First, we employ random events to infer an abstract relation between browser-side events and blockchain-side contracts. Second, our technique generates a set of test cases under the guidance of inferred relations and orders the test cases based on a read-write graph. We also use taint analysis to track data flow of the smart contract and feed it to the generation procedure for following test cases. We have developed a tool called Sungari to implement our approach, and evaluated it on representative real-world DApps. The preliminary evaluation results demonstrated the potential of Sungari in achieving a significant optimization compared to random testing approaches. Jianbo Gao 0003, Han Liu 0010, Yue Li 0037, Chao Liu 0032, Qingshan Li, Zhi Guan, Zhong Chen 0001 |
ICPC | 7 |
| 2015 | Trustworthy Collaborative Filtering through Downweighting Noise and Redundancy
Qiuxiang Dong, Zhi Guan, Zhong Chen 0001 |
APWeb | 2 |
| 2015 | Attribute-Based Keyword Search Efficiency Enhancement via an Online/Offline ApproachabstractSearchable encryption is a primitive, which not only protects data privacy of data owners but also enables data users to search over the encrypted data. Most existing searchable encryption schemes are in the single-user setting. There are only few schemes in the multiple data users setting, i.e., encrypted data sharing. Among these schemes, most of the early techniques depend on a trusted third party with interactive search protocols or need cumbersome key management. To remedy the defects, the most recent approaches borrow ideas from attribute-based encryption to enable attribute-based keyword search (ABKS). However, all these schemes incur high computational costs and are not suitable for mobile devices, such as mobile phones, with power consumption constraints. In this paper, we develop new techniques that split the computation for the keyword encryption and trapdoor/token generation into two phases: a preparation phase that does the vast majority of the work to encrypt a keyword or create a token before it knows the keyword or the attribute list/access control policy that will be used. A second phase then rapidly assembles an intermediate ciphertext or trapdoor when the specifics become known. The preparation work can be performed while the mobile device is plugged into a power source, then it can later rapidly perform keyword encryption or token generation operations on the move without significantly draining the battery. We name our scheme Online/Offline ABKS. To the best of our knowledge, this is the first work on constructing efficient multi-user searchable encryption scheme for mobile devices through moving the majority of the cost of keyword encryption and token generation into an offline phase. Qiuxiang Dong, Zhi Guan, Zhong Chen 0001 |
ICPADS | 2 |
| 2015 | Accelerating RSA with Fine-Grained Parallelism Using GPU
Zhi Guan, Huiping Sun, Zhong Chen 0001 |
ISPEC | 2 |
| 2015 | Location Semantics Protection Based on Bayesian Inference
Zhengang Wu, Zhong Chen 0001, Huiping Sun, Zhi Guan |
WAIM | 5 |
| 2014 | Protecting Elliptic Curve Cryptography Against Memory Disclosure Attacks
Zhi Guan, Zhe Liu 0001, Zhong Chen 0001 |
ICICS | 2 |
| 2013 | An Efficient Privacy-Preserving RFID Ownership Transfer Protocol
Zhi Guan, Tao Yang 0015, Huiping Sun, Zhong Chen 0001 |
APWeb | 2 |
| 2013 | Accelerating AES in JavaScript with WebGL
Zhi Guan, Qiuxiang Dong, Zhong Chen 0001 |
ICICS | 2 |
| 2013 | Fuzzy Keyword Search over Encrypted Data in the Public Key Setting
Qiuxiang Dong, Zhi Guan, Liang Wu 0011, Zhong Chen 0001 |
WAIM | 2 |
| 2013 | Authenticating Users of Recommender Systems Using Naive Bayes
Zhengang Wu, Liangwen Yu, Huiping Sun, Zhi Guan, Zhong Chen 0001 |
WISE (1) | 4 |
| 2013 | Finding and fixing vulnerabilities in several three-party password authenticated key exchange protocols without server public keys
Hu Xiong, Zhi Guan, Zhong Chen 0001 |
Inf. Sci. | 3 |
| 2013 | An efficient certificateless aggregate signature with constant pairing computations
Hu Xiong, Zhi Guan, Zhong Chen 0001, Fagen Li |
Inf. Sci. | 2 |
| 2012 | A Privacy-Preserving Path-Checking Solution for RFID-Based Supply Chains
Huiping Sun, Tao Yang 0015, Zhi Guan, Zhong Chen 0001 |
ICICS | 4 |
| 2012 | Permission-Based Abnormal Application Detection for Android
Zhi Guan, Liangwen Yu, Huiping Sun, Zhong Chen 0001 |
ICICS | 2 |
| 2012 | Exploiting Consumer Reviews for Product Feature Ranking
Suke Li, Zhi Guan, Liyong Tang, Zhong Chen 0001 |
J. Comput. Sci. Technol. | 2 |
| 2012 | Information-theoretic modeling of false data filtering schemes in wireless sensor networksabstractFalse data filtering schemes are designed to filter out false data injected by malicious sensors; they keep the network immune to bogus event reports. Theoretic understanding of false data filtering schemes and guidelines to further improve their designs are still lacking. This article first presents an information-theoretic model of false data filtering schemes. From the information-theoretic view, we define the scheme's filtering capacity C F i as the uncertainty-reduction ratio of the target input variable, given the output. This metric not only performs better than existing metrics but also implies that only by optimizing the false negative rate and false positive rate simultaneously, can we promote a scheme's overall performance. Based on the investigation from the modeling efforts, we propose HiFi , a hybrid authentication-based false data filtering scheme. HiFi leverages the benefits of both symmetric and asymmetric cryptography and achieves a high filtering capacity, as well as low computation and communication overhead. Performance analysis demonstrates that our proposed metric is rational and useful, and that HiFi is effective and energy efficient. Zhi Guan, Zhong Chen 0001 |
ACM Trans. Sens. Networks | 3 |
| 2011 | Mobile Browser as a Second Factor for Web AuthenticationabstractPeople's increasingly relying on web applications to manage their digital assets makes web authentication a critical security issue. As most websites today still authenticate a user with only username and password, the authentication credentials can be easily compromised in a vulnerable browsing environment without the owner's notice. Considering the browsing in mobile devices is more secure than personal computers, in this paper we explore the One-Time Password web application running inside mobile browsers as a second authentication factor for high value websites in hostile browsing environments. We discuss the security and efficiency of this authentication method from both theory and practice. An implementation with performance evaluation is also provided to prove our concept. Zhi Guan, Hu Xiong, Suke Li, Zhong Chen 0001 |
ISPA | 1 |
| 2010 | Identity-based encryption based on DHIESabstractMost traditional public key cryptosystems are constructed upon algebraically rich structures, which makes their key pairs combinable, i.e., the combination of some private keys and their corresponding public keys could form a new key pair. Exploring such combinable property, this paper proposes a novel Identity-Based Encryption (IBE) scheme based on the Diffie-Hellman Integrated Encryption Scheme (DHIES) with quadratic key combination structure from bilinear maps. The new scheme has a number of advantages over other IBE schemes. First, it uses DHIES to fulfill encryption, thus naturally obtains the security against adaptive chosen ciphertext attack from DHIES. Second, it is interoperable with existing security systems based on DHIES. Third, compared to many pairing-based IBE schemes, it only requires pairing computation during public key generation and there is no need for special hash function. We prove that our scheme is selective identity chosen ciphertext secure in the random oracle model assuming DHIES is chosen ciphertext secure. Additionally, the extract algorithm of our scheme also implies an identity-based short signature scheme. Yu Chen 0003, Manuel Charlemagne, Zhi Guan, Jian-bin Hu, Zhong Chen 0001 |
AsiaCCS | 3 |
| 2010 | Towards Risk Evaluation of Denial-of-Service Vulnerabilities in Security Protocols
Zhi Guan, Zhong Chen 0001, Jian-bin Hu, Liyong Tang |
J. Comput. Sci. Technol. | 2 |
| 2008 | WebIBC: Identity Based Cryptography for Client Side Security in Web ApplicationsabstractThe growing popularity of web applications in the last few years has led users to give the management of their data to online application providers, which will endanger the security and privacy of the users. In this paper, we present WebIBC, which integrates public key cryptography into web applications without any browser plugins. The public key of WebIBC is provided by identity based cryptography, eliminating the need of public key and certificate online retrieval; the private key is supplied by the fragment identifier of the URL inspired by BeamAuth. The implementation and performance evaluation demonstrate that WebIBC is secure and efficient both in theory and practice. Zhi Guan, Ruichuan Chen, Zhong Chen 0001, Xianghao Nan |
ICDCS | 1 |
| 2008 | Pseudo-randomness Inside Web Browsers
Zhi Guan, Long Zhang 0003, Zhong Chen 0001, Xianghao Nan |
ICICS | 1 |
| 2007 | An Economical Model for the Risk Evaluation of DoS Vulnerabilities in Cryptography Protocols
Zhi Guan, Zhong Chen 0001, Jian-bin Hu, Liyong Tang |
ISPEC | 2 |