Hongsong Shi

dblp:91/5830 · DBLP profile ↗
← Back
9ranked-venue papers
4as first author
2since 2021 · last 2022
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 7 · 2 first-author · 2 since 2021Theory of computation · 1 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 1 · 1 first-author
YearPublicationVenuePosition
2022 Lattice-Based Fault Attacks on Deterministic Signature Schemes of ECDSA and EdDSA
Weiqiong Cao, Hongsong Shi, Hua Chen 0011, Jiazhe Chen, Limin Fan, Wenling Wu
CT-RSA2
2021 Lattice-Based Weak Curve Fault Attack on ECDSA
Weiqiong Cao, Hongsong Shi, Hua Chen 0011, Jiazhe Chen
SEC2
2020 x-only coordinate: with application to secp256k1 " >Chosen base-point side-channel attack on Montgomery ladder with x-only coordinate: with application to secp256k1
abstract
This study revisits the side‐channel security of the elliptic curve cryptography (ECC) scalar multiplication implemented with Montgomery ladder. Focusing on a specific implementation that does not use the y ‐coordinate for point addition (ECADD) and point doubling (ECDBL), the authors show that Montgomery ladder on Weierstrass curves is vulnerable to a chosen base‐point attack. Unlike the normal implementation with y ‐coordinate, in the scenario of this study, the chosen base‐point strategy will not lead to operations with two same inputs during the ECADD and/or ECDBL. Instead, by choosing a suitable base‐point, one will find that there are operations that share a common operand; while it is not the case if the base‐point is not chosen correctly. This results in the recovery of the secret (fixed) scalar. They also experiment the methods of shared operand detection on a real‐world SoC, where a secp256k1 dedicated Montgomery ladder scalar multiplication with x ‐only coordinate is implemented, to show the efficiency of the scalar recovery attack. Naturally, the attack can be generalised to other Weierstrass curves when they contain special points.
Congming Wei, Jiazhe Chen, An Wang 0001, Hongsong Shi, Xiaoyun Wang 0001
IET Inf. Secur.5
2015 Mind Your Nonces Moving: Template-Based Partially-Sharing Nonces Attack on SM2 Digital Signature Algorithm
abstract
This paper gives a partially-sharing nonces attack on SM2 Digital Signature Algorithm (SM2DSA). Templates, which are built in the scenario of no secrets known, are used to detect the collisions on the Most Significant Byte of the Nonces (MSBN). Targeting a real world smartcard with 8-bit precharged bus, the power consumption of data moving procedure after the random number generation is focused, on which the template building and matching phases are based. With the templates, we obtain a number of pairs of nonces whose first bytes are collided, then a lattice attack on SM2DSA is proposed to recover the private key. Experiments show that our attack works smoothly; our attack is the first implemented lattice attack on SM2DSA in a smartcard, which can also be extended to the other ECC algorithms like ECDSA.
Jiazhe Chen, Hexin Li, Hongsong Shi
AsiaCCS4
2011 Optimal message transmission protocols with flexible parameters
abstract
In Secure message transmission (SMT) protocols two nodes in a network want to communicate securely, given that some of the nodes in the network are corrupted by an adversary with unlimited computational power. An SMT protocol uses multiple paths between the sender and a receiver to guarantee privacy and reliability of the message transmission. An (e, δ)-SMT protocol bounds the adversary's success probability of breaking privacy and reliability to e and δ, respectively. Rate optimal SMT protocols have the smallest transmission rate (amount of communication per one bit of message). Rate optimal protocols have been constructed for a restricted set of parameters.In this paper we use wire virtualization method to construct new optimal protocols for a wide range of parameters using previously known optimal protocols. In particular, we design, for the first time, an optimal 1-round (0, δ)-SMT protocol for n = (2 + c)t, c ≥ 1/t, where n is the number of paths between the sender and the receiver, up to t of which are controlled by the adversary. We also design an optimal 2-round (0, 0)-SMT protocol for n = (2 + c)t, c ≥ 1/t, with communication cost better than the known protocols. The wire virtualization method can be used to construct other protocols with provable properties from component protocols.
Reihaneh Safavi-Naini, Mohammed Ashraful Tuhin, Hongsong Shi
AsiaCCS3
2011 On Optimal Secure Message Transmission by Public Discussion
abstract
In a secure message transmission (SMT) scenario, a sender wants to send a message in a private and reliable way to a receiver. Sender and receiver are connected by n wires, t of which can be controlled by an adaptive adversary with unlimited computational resources. In Eurocrypt 2008, Garay and Ostrovsky considered an SMT scenario where sender and receiver have access to a public discussion channel and showed that secure and reliable communication is possible when n ≥ t + 1. In this paper, we will show that a secure protocol requires at least three rounds of communication and two rounds invocation of the public channel and hence give a complete answer to the open question raised by Garay and Ostrovsky. We also describe a round optimal protocol that has constant transmission rate over the public channel.
Hongsong Shi, Shaoquan Jiang, Reihaneh Safavi-Naini, Mohammed Ashraful Tuhin
IEEE Trans. Inf. Theory1
2010 More efficient DDH pseudorandom generators
Hongsong Shi, Shaoquan Jiang, Zhiguang Qin
Des. Codes Cryptogr.1
2009 Optimal secure message transmission by public discussion
abstract
Secure message transmission assumes n channels between a sender and a receiver such that up to t channels are under the control of a computationally unlimited adversary. In secure message transmission by public discussion protocol, sender and receiver have access to a public authenticated channel. In this paper we show that if n ¿ t + 1, a secure protocol requires at least 3 rounds of communication and 2 rounds invocation of the public channel. This gives a complete answer to a question raised by Garay and Ostrovsky in Eurocrypt 2008. We also describe a round optimal protocol that has constant transmission rate over the public channel.
Hongsong Shi, Shaoquan Jiang, Reihaneh Safavi-Naini, Mohammed Ashraful Tuhin
ISIT1
2006 Authenticated and Communication Efficient Group Key Agreement for Clustered Ad Hoc Networks
Hongsong Shi, Mingxing He, Zhiguang Qin
CANS1