VLDB 2026 Research / reviewers in the wild / expert
Nan Li 0007
dblp:84/3795-7
· DBLP profile ↗
29ranked-venue papers
11as first author
12since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 14 · 6 first-author · 3 since 2021Applied, interdisciplinary, general and emerging computing · 5 · 2 first-author · 4 since 2021Systems, architecture and hardware · 4 · 3 first-author · 1 since 2021Computer networks · 3 · 2 since 2021Human-computer interaction and ubiquitous computing · 2 · 2 since 2021Theory of computation · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Improved Tightly Secure (ID-Based) Signatures in the AGM
Yanzibo Zhou, Fuchun Guo, Willy Susilo, Nan Li 0007 |
ACISP (1) | 4 |
| 2025 | Diverging Assessment: A Student PerspectiveabstractDiverging assessment maintains a common question set for all students but varies the input data so that each student has a unique problem to solve. It is an approach in student assessment that offers a unique and authentic learning experience. Although such assessments have been implemented in computing courses, their effectiveness and students' perceptions in different contexts remain unexplored. In this paper, we investigate student perspectives on diverging assessment. We surveyed students in four courses across three different universities. Each surveyed student was enrolled in one of the four courses on networking, operation systems, digital forensics or ethical hacking. Each course featured at least one diverging assessment. The students' overall perceptions about diverging assessments and three different aspects of diverging assessment, namely authenticity, assessment-as-learning, and academic integrity, are surveyed, reported, and analyzed. William Billingsley, Ljiljana Brankovic, Nan Li 0007, David J. Paul, Amin Sakzad, Matthew P. Skerritt, Judithe Sheard |
ITiCSE (1) | 3 |
| 2025 | STPCH: strongly traceable policy-based chameleon hash for blockchain rewritingabstractAbstract Policy-based chameleon hash (PCH) is a useful primitive in blockchain rewriting. It allows a party to compute a chameleon hash based on an access policy, and another party who possesses sufficient privileges satisfying the access policy to rewrite the hashed object. However, PCH lacks strong traceability. The chameleon trapdoor holder may abuse their rewriting privilege and maliciously rewrite the hashed object without being identified. In this paper, we introduce a new primitive called strongly traceable policy-based chameleon hash (STPCH for short). We first present a generic framework of STPCH. Then, we present a practical instantiation, show its practicality through implementation and evaluation analysis. Nan Li 0007, Yingjiu Li, Yangguang Tian |
Comput. J. | 1 |
| 2024 | Mitigation of Gradient Inversion Attacks in Federated Learning with Private Adaptive Optimization
Cody Lewis, Vijay Varadharajan, Nasimul Noman, Udaya Kiran Tupakula, Nan Li 0007 |
ICDCS | 5 |
| 2024 | Diverging assessments: What, Why, and ExperiencesabstractIn this experience paper, we introduce the concept of 'diverging assessments', process-based assessments designed so that they become unique for each student while all students see a common skeleton. We present experiences with diverging assessments in the contexts of computer networks, operating systems, ethical hacking, and software development. All the given examples allow the use of generative-AI-based tools, are authentic, and are designed to generate learning opportunities that foster students' meta-cognition. Finally, we reflect upon these experiences in five different courses across four universities, showing how diverging assessments enhance students' learning while respecting academic integrity. Amin Sakzad, David J. Paul, Judithe Sheard, Ljiljana Brankovic, Matthew P. Skerritt, Nan Li 0007, Sepehr Minagar, Simon, William Billingsley |
SIGCSE (1) | 6 |
| 2024 | Practical and secure policy-based chameleon hash for redactable blockchainsabstractAbstract Policy-based chameleon hash functions have been widely proposed for its use in blockchain rewriting systems. They allow anyone to create a mutable transaction associated with an access policy, while an authorized user who possesses sufficient rewriting privileges from a trusted authority satisfying the access policy can rewrite the mutable transaction. However, existing chameleon hash functions lack certain fundamental security guarantees, including forward security and backward security. In this paper, we introduce a new primitive called forward/backward-secure policy-based chameleon hash (FB-PCH for short). We present a practical instantiation. We prove that the proposed scheme achieves forward/backward-secure collision-resistance, and show its practicality through implementation and evaluation analysis. Nan Li 0007, Yingjiu Li, Mark Manulis, Yangguang Tian, Guomin Yang |
Comput. J. | 1 |
| 2024 | Policy-Based Remote User Authentication From Multi-BiometricsabstractAbstract In this paper, we introduce the first generic framework of policy-based remote user authentication from multiple biometrics. The proposed framework allows an authorized user to remotely authenticate herself to an authentication server using her multiple biometrics, which enhances both the security and usability of user authentications. The authentication server approves a user’s authentication request if and only if the user’s multiple biometrics satisfies an authentication policy. In particular, the authentication policy can be dynamically updated to satisfy different security and usability requirements in practice. We implement an instantiation of the proposed framework and report its performance under various authentication policies. Yangguang Tian, Yingjiu Li, Robert H. Deng, Guomin Yang, Nan Li 0007 |
Comput. J. | 5 |
| 2024 | OLBS: Oblivious Location-Based ServicesabstractWith the growing use of mobile devices, location-based services (LBS) are becoming increasingly popular. BLS deliver accurate services to individuals according to their geographical locations, but privacy issues have been the primary concerns of users. Privacy-preserving LBS (PPLBS) were proposed to protect location privacy, but there are still some problems: 1) a semi-trusted third party (STTP) is required to blur users’ locations; 2) both the computation and communication costs of generating a query are linear with the size of queried areas; 3) the schemes were not formally treated, in terms of definition, security model, security proof, etc. In this paper, to protect location privacy and improve query efficiency, an oblivious location-based services (OLBS) scheme is proposed. Our scheme captures the following features: 1) an STTP is not required; 2) users can query services without revealing their exact location information; 3) the service provider only knows the size of queried areas and nothing else; and 4) both the computation and communication costs of generating a query is constant, instead of linear with the size of queried areas. We formalise both the definition and security model of our OLBS scheme, and propose a concrete construction. Furthermore, the implementation is conducted to show its efficiency. The security of our scheme is reduced to well-known complexity assumptions. The novelty is to reduce the computation and communication costs of generating a query and enable the service provider to obliviously generate decrypt keys for queried services. This contributes to the growing work of formalising PPLBS schemes and improving query efficiency. Jinguang Han, Willy Susilo, Nan Li 0007, Xinyi Huang 0001 |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2023 | A Practical Forward-Secure DualRing
Nan Li 0007, Yingjiu Li, Atsuko Miyaji, Yangguang Tian, Tsz Hon Yuen |
CANS | 1 |
| 2023 | Revocable Policy-Based Chameleon Hash for Blockchain RewritingabstractAbstract Policy-based chameleon hash is a useful primitive for blockchain rewriting systems. It allows a user to create a mutable transaction associated with an access policy, whereas a modifier who possesses sufficient rewriting privileges from a trusted authority satisfying the access policy can rewrite the mutable transaction. However, it lacks a revocation mechanism. The modifiers can always rewrite the mutable transactions even if their given rewriting privileges are compromised. In this work, we introduce revocable policy-based chameleon. The property of revocation allows some modifiers’ rewriting privileges to be revoked, regardless of whether their rewriting privileges are compromised or not. Yangguang Tian, Atsuko Miyaji, Koki Matsubara, Hui Cui 0001, Nan Li 0007 |
Comput. J. | 5 |
| 2023 | Targeted Context-Based Attacks on Trust Management Systems in IoTabstractTrust management systems (TMSs) play an important role in Internet of Things (IoT) by providing a means of finding whether a given device can provide a service to a satisfactory level, and for identifying potentially malicious devices in the network. Context awareness extends trust models by allowing a trustor to filter and aggregate evidence by their relevance to the current situation. Context awareness is important in the formulation of trust in IoT networks due to their heterogeneity and due to the dynamic changes in the capabilities of IoT devices. In this article, we have proposed a new type of attack on context-aware trust models for IoT systems, context-based attacks. In this attack, an adversary manipulates the context to impact a target group of IoT devices, while other devices in nontargeted groups are not even aware of the attack. We have demonstrated the effectiveness of this new type of attack on seven previously proposed trust models through practical simulations and theoretical proofs. This article also proposes a new TMS that can mitigate such context-based attacks. Cody Lewis, Nan Li 0007, Vijay Varadharajan |
IEEE Internet Things J. | 2 |
| 2021 | Utilizing QR codes to verify the visual fidelity of image datasets for machine learning
Yang-Wai Chow, Willy Susilo, Jianfeng Wang 0001, Richard Buckland, Joonsang Baek, Jongkil Kim, Nan Li 0007 |
J. Netw. Comput. Appl. | 7 |
| 2020 | Policy-based Chameleon Hash for Blockchain Rewriting with Black-box AccountabilityabstractPolicy-based chameleon hash is a useful primitive for blockchain rewriting. It allows a party to create a transaction associated with an access policy, while another party who possesses enough rewriting privileges satisfying the access policy can rewrite the transaction. However, it lacks accountability. The chameleon trapdoor holder may abuse his/her rewriting privilege and maliciously rewrite the hashed object in the transaction without being identified. In this paper, we introduce policy-based chameleon hash with black-box accountability (PCHBA). Black-box accountability allows an attribute authority to link modified transactions to responsible transaction modifiers in case of dispute, in which any public user identifies those transaction modifiers from interacting with an access device/blackbox. We first present a generic framework of PCHBA. Then, we present a practical instantiation, showing its practicality through implementation and evaluation analysis. Yangguang Tian, Nan Li 0007, Yingjiu Li, Pawel Szalachowski, Jianying Zhou 0001 |
ACSAC | 2 |
| 2020 | A New Construction for Linkable Secret HandshakeabstractAbstract In this paper, we introduce a new construction for linkable secret handshake that allows authenticated users to perform handshake anonymously within allowable times. We define formal security models for the new construction, and prove that it can achieve session key security, anonymity, untraceability and linkable affiliation-hiding. In particular, the proposed construction ensures that (i) anyone can trace the real identities of dishonest users who perform handshakes for more than k times; and (ii) an optimal communication cost between authorized users is achieved by exploiting the proof of knowledges. Yangguang Tian, Yingjiu Li, Robert H. Deng, Nan Li 0007, Guomin Yang, Zheng Yang 0001 |
Comput. J. | 4 |
| 2020 | A new framework for privacy-preserving biometric-based remote user authenticationabstractIn this paper, we introduce the first general framework for strong privacy-preserving biometric-based remote user authentication based on oblivious RAM (ORAM) protocol and computational fuzzy extractors. We define formal security models for the general framework, and we prove that it can achieve user authenticity and strong privacy. In particular, the general framework ensures that: (1) a strong privacy and a log-linear time-complexity are achieved by using a new tree-based ORAM protocol; (2) a constant bandwidth cost is achieved by exploiting computational fuzzy extractors in the challenge-response phase of remote user authentications. Yangguang Tian, Yingjiu Li, Robert H. Deng, Nan Li 0007, Pengfei Wu 0003, Anyi Liu |
J. Comput. Secur. | 4 |
| 2020 | Leakage-resilient biometric-based remote user authentication with fuzzy extractors
Yangguang Tian, Yingjiu Li, Binanda Sengupta, Nan Li 0007, Chunhua Su |
Theor. Comput. Sci. | 4 |
| 2019 | A New Encoding Framework for Predicate Encryption with Non-linear Structures in Prime Order Groups
Jongkil Kim, Willy Susilo, Fuchun Guo, Joonsang Baek, Nan Li 0007 |
ACNS | 5 |
| 2019 | Anonymous Asynchronous Payment Channel from k-Time Accountable Assertion
Yangguang Tian, Yingjiu Li, Binanda Sengupta, Nan Li 0007, Yong Yu 0002 |
CANS | 4 |
| 2019 | Context-Aware Trust Management System for IoT Applications with Multiple DomainsabstractThe Internet of Things (IoT) provides connectivity between heterogeneous devices in different applications, such as smart wildlife, supply chain and traffic management. Trust management system (TMS) assesses the trustworthiness of service with respect to its quality. Under different context information, a service provider may be trusted in one context but not in another. The existing context-aware trust models usually store trust values under different contexts and search the closest (to a given context) record to evaluate the trustworthiness of a service. However, it is not suitable for distributed resource-constrained IoT devices which have small memory and low power. Reputation systems are applied in many trust models where trustor obtains recommendations from others. In context-based trust evaluation, it requires interactive queries to find relevant information from remote devices. The communication overhead and energy consumption are issues in low power networks like 6LoWPAN. In this paper, we propose a new context-aware trust model for lightweight IoT devices. The proposed model provides a trustworthiness overview of a service provider without storing past behavior records, that is, constant size storage. The proposed model allows a trustor to decide the significance of context items. This could result in distinctive decisions under the same trustworthiness record. We also show the performance of the proposed model under different attacks. Nan Li 0007, Vijay Varadharajan, Surya Nepal |
ICDCS | 1 |
| 2019 | Privacy-Preserving and Undeniable Authentication for Mobile RFID TagsabstractRadio Frequency IDentification (RFID) is a technology that has been widely employed in many applications requiring automatic object identification. Security and privacy are critical issues that must be addressed when the technology is deployed in security sensitive applications. The prior RFID protocols based on symmetric and asymmetric (or public) key cryptography have limitations in either security or practicality. In particular, public key based RFID protocols can achieve stronger security but are also more expensive in terms of the computation cost. In this paper, we propose a new public key based RFID protocol that incurs much less computation cost compared with the prior protocols. The novelty behind our protocol is to securely reuse public key operations across different sessions so that in most of the sessions only symmetric key operations are required. We show that our protocol can achieve mutual authentication, strong anonymity, forward privacy and non-deniability with low computation and communication cost. Jiannan Wei, Nan Li 0007 |
WOWMOM | 2 |
| 2018 | DSH: Deniable Secret Handshake Framework
Yangguang Tian, Yingjiu Li, Yinghui Zhang 0002, Nan Li 0007, Guomin Yang, Yong Yu 0002 |
ISPEC | 4 |
| 2018 | Privacy-Preserving Biometric-Based Remote User Authentication with Leakage Resilience
Yangguang Tian, Yingjiu Li, Rongmao Chen, Nan Li 0007, Ximeng Liu, Bing Chang, Xingjie Yu |
SecureComm (1) | 4 |
| 2017 | Fuzzy Extractors for Biometric IdentificationabstractFuzzy extractor provides key generation from biometrics and other noisy data. The generated key is seamlessly usable for any cryptographic applications because its information entropy is sufficient for security. Biometric authentication offers natural and passwordless user authentication in various systems where fuzzy extractors can be used for biometric information security. Typically, a biometric system operates in two modes: verification and identification. However, existing fuzzy extractors does not support efficient user identification. In this paper, we propose a succinct fuzzy extractor scheme which enables efficient biometric identification as well as verification that it satisfies the security requirements. We show that the proposed scheme can be easily used in both verification and identification modes. To the best of our knowledge, we propose the first fuzzy extractor based biometric identification protocol. The proposed protocol is able to identify a user with constant computational cost rather than linear-time computation required by other fuzzy extractor schemes. We also provide security analysis of proposed schemes to show their security levels. The implementation shows that the performance of proposed identification protocol is constant and it is close to that of verification protocols. Nan Li 0007, Fuchun Guo, Yi Mu 0001, Willy Susilo, Surya Nepal |
ICDCS | 1 |
| 2017 | Lightweight Mutual Authentication for IoT and Its ApplicationsabstractThe Internet of Things (IoT) provides transparent and seamless incorporation of heterogeneous and different end systems. It has been widely used in many applications including smart cities such as public water system, power grid, water management, and vehicle traffic control system. In these smart city applications, a large number of IoT devices are deployed that can sense, communicate, compute, and potentially actuate. The uninterrupted and accurate functioning of these devices are critical to smart city applications as crucial decisions will be made based on the data received. One of the challenging tasks is to assure the authenticity of the devices so that we can rely on the decision making process with a very high confidence. One of the characteristics of IoT devices deployed in such applications is that they have limited battery power. A challenge is to design a secure mutual authentication protocol which is affordable to resource constrained devices. In this paper, we propose a lightweight mutual authentication protocol based on a novel public key encryption scheme for smart city applications. The proposed protocol takes a balance between the efficiency and communication cost without sacrificing the security. We evaluate the performance of our protocol in software and hardware environments. On the same security level, our protocol performance is significantly better than existing RSA and ECC based protocols. We also provide security analysis of the proposed encryption scheme and the mutual authentication protocol. Nan Li 0007, Dongxi Liu, Surya Nepal |
IEEE Trans. Sustain. Comput. | 1 |
| 2015 | Anonymous Yoking-Group ProofsabstractYoking-proofs show an interesting application in Radio Frequency Identification (RFID) that a verifier can check whether two tags are simultaneously scanned by a reader. We consider a scenario that multi-group of tags can be proved to be scanned simultaneously. Grouping-proof, which is an extension of yoking-proofs, allows multiple tags to be proved together, while existing protocols cannot support multiple groups. In this paper, we introduce a novel concept called "yoking-group proofs". Additionally, we propose an anonymous yoking-proof protocol and an anonymous yoking-group proof protocol and prove their security in Universal Composability framework. Nan Li 0007, Yi Mu 0001, Willy Susilo, Vijay Varadharajan |
AsiaCCS | 1 |
| 2015 | Vulnerabilities of an ECC-based RFID authentication schemeabstractRadio frequency identification (RFID) authentication is an indispensable part of RFID applications, which allows a reader to identify objects in an authenticated manner. Recently, Liao and Hsiao proposed a very interesting elliptic curve cryptography-based RFID authentication scheme with ID-verifier transfer protocol. They claimed that the proposed protocol is secure against many attacks and satisfies essential security requirements of RFID systems. However, in this paper, we demonstrate that the protocol suffers from several attacks, in contrast to their original claims in the paper. Furthermore, we also propose a repaired version of the authentication protocol against identified attacks, and we provide formal security proofs. Nan Li 0007, Yi Mu 0001, Willy Susilo, Fuchun Guo, Vijay Varadharajan |
Secur. Commun. Networks | 1 |
| 2013 | Secure RFID Ownership Transfer Protocols
Nan Li 0007, Yi Mu 0001, Willy Susilo, Vijay Varadharajan |
ISPEC | 1 |
| 2011 | Self-certified ring signaturesabstractWe present a new notion, Self-certified Ring Signature (SCRS), to provide an alternative solution to the certificate management problem in ring signatures and eliminate private key escrow problem in identity based ring signatures. Our scheme captures all features of ring signatures and exhibits the advantages such as low storage, communication and computation cost. The main contribution of this paper is a precise definition of self-certified ring signatures along with a concrete construction. We also provide a security model of SCRS and a security proof of our scheme. Nan Li 0007, Yi Mu 0001, Willy Susilo, Fuchun Guo |
AsiaCCS | 1 |
| 2011 | Efficient Self-certified Signatures with Batch Verification
Nan Li 0007, Yi Mu 0001, Willy Susilo |
Inscrypt | 1 |