VLDB 2026 Research / reviewers in the wild / expert
Hongfeng Zhu
dblp:91/6245 · also Hong-Feng Zhu
· DBLP profile ↗
10ranked-venue papers
5as first author
7since 2021 · last 2025
0000-0001-9910-3197ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 10 · 5 first-author · 7 since 2021Software engineering, systems software and programming languages · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Optimal-round semi-honest-quantum PAKE protocol with chaotic maps
Chaonan Wang, Hongfeng Zhu |
Int. J. Inf. Comput. Secur. | 3 |
| 2025 | A novel mutual quantum identity authentication of two-party protocol with chaotic systemsabstractIn order to ensure the security of communications, it is often necessary to legally verify the identity of the user before formal communications can take place. Usually, one party provides evidence to prove the identity, and the other party verifies the provided evidence and determines whether the identity is legitimate or not. Given the growing and dramatic interest in quantum computing, it will be necessary to design mutual quantum authentication schemes implemented using quantum resources. In this paper, we design a two-party mutual authentication quantum identity authentication (QIA) protocol based on GHZ-like state quantum resources and chaotic map theory. On the one hand, we ensure the true randomness of the authentication parameters, and on the other hand, we ensure the true randomness with fast propagation, so as to achieve the nature of fast true randomness. The scheme is able to make the authentication process complete the authentication in a shorter time while ensuring security. Chaonan Wang, Hongfeng Zhu |
Int. J. Inf. Comput. Secur. | 4 |
| 2024 | A novel blockchain consensus protocol with quantum private comparison for internet of vehiclesabstractConsensus protocols are a key feature in decentralised systems/networks which aims to obtain and agree on a shared state among multiple unreliable nodes with diverse applications. Therefore, that integrated design with new technologies will become a difficult and hot research topic, especially in combining new fields such as quantum information and blockchain. Spontaneously, we propose a new consensus protocol in combination with quantum private comparison (QPC) in internet of vehicles (IoV) using practical Byzantine fault tolerance (PBFT) to achieve security and efficiency at higher levels. Through multi-node collaborative computing, different vehicles can quickly reach a consensus. More importantly, we have added quantum technology in the identity authentication and consensus phase, which can make our integrated network more robust and prevent malicious attacks. In other words, our protocol adopts QPC to make it impossible for any malicious node to maliciously disturb the order between nodes in the consensus phase, thus improving security. Finally, compared with the recent related literature, our consensus protocol has strong practicability and universality and can be well applied in the IoV environment. Kefan Cheng, Hongfeng Zhu |
Int. J. Inf. Comput. Secur. | 4 |
| 2024 | Efficient multi-party quantum key agreement protocol based on new bell state encoding modeabstractAlthough there are many quantum key agreement protocols currently in existence, they cannot be merged in terms of resource utilisation, efficiency, security, and other aspects, and there are also significant differences in the nature of two and more parties. Therefore, it is necessary to design a quantum key agreement protocol that can balance efficiency and security and is suitable for multiple participants. In view of this, this paper proposes a multi-party quantum key agreement protocol based on a new coding mode of bell state: temporary session keys are negotiated between adjacent participants, and then shared keys for all participants are negotiated through the exchange, conversion, and computation of quantum resources. During the implementation of the protocol, not only can the identity of the participants be authenticated, but also the quantum resources used are single, and the quantum operations performed are simple. Moreover, efficiency is fixed and does not decrease due to the increase of participants or quantum resources. In addition, the protocol also allows participants to dynamically join and leave. In terms of security, the protocol can resist most common quantum attacks. Under the existing quantum technology, this protocol is completely feasible. Kefan Cheng, Hongfeng Zhu |
Int. J. Inf. Comput. Secur. | 4 |
| 2024 | IDMS quantum password-authenticated key exchange protocolsabstractIn this paper, we design an ID-based M-server quantum password-authenticated key exchange scheme, where the client computes a strong key from its password and splits the key into m portions, and then encrypts them and sends them to m servers to be used as the basis for encryption and decryption in the subsequent key exchange process. The adoption of multiple servers can effectively prevent third-party attacks on the server and ensure the security of the key information, which is just like a complex secret sharing mechanism in traditional computational cryptography, for example, secret sharing (m, n) threshold scheme, but our new quantum fusion technology to realise the secret sharing mechanism is more efficient and simpler. Finally, through analysis, our scheme can meet most of the security requirements and perform well. It is feasible to implement the protocol under the existing quantum technology. Yingfei Xu, Hongfeng Zhu |
Int. J. Inf. Comput. Secur. | 4 |
| 2022 | A N-party authenticated group key distribution protocol using quantum-reflection architecture
Hongfeng Zhu, Zhiqin Du, Yuanle Zhang |
Int. J. Inf. Comput. Secur. | 1 |
| 2022 | Security analysis and improvements of a universal construction for a round-optimal password authenticated key exchange protocol
Hongfeng Zhu, Yeh-Cheng Chen |
Int. J. Inf. Comput. Secur. | 1 |
| 2015 | One-time identity-password authenticated key agreement scheme based on biometricsabstractAuthenticated key agreement protocols, aiming at solving the problems to set up a secure channel over public Internet, can achieve authentication of the corresponding participants and confidentiality of data transmission. Nowadays, most of the authenticated key agreement protocols focus on security, efficiency, and user experience at the same time. One-time password authenticated algorithm, which is that a hash chain can update by itself smoothly and securely through capturing the secure bit of the tip, has the feature of high-efficient. In addition, biometrics-based algorithm can make the scheme more secure and more amiable for users. The combination of aforementioned algorithms can lead to a high practical scheme in the universal client/server architecture. Based on these motivations, the paper firstly proposed the new concept of one-time identity-password OTIP, which means the identity and the password can be used only once. Then, a new robust biometrics-based OTIP authenticated key agreement protocol is given based on the OTIP. Security of the protocol is based on the biometric authentication, a secure symmetric encryption and a secure one-way hash function with the hash chain. At the same time, the proposed protocol can not only refrain from many consuming algorithms but also robust to many kinds of attacks and owns much excellent features. Finally, we provide the secure proof and the efficiency analysis about our proposed scheme. Copyright © 2015 John Wiley & Sons, Ltd. Hongfeng Zhu |
Secur. Commun. Networks | 1 |
| 2015 | Cryptanalysis and provable improvement of a chaotic maps-based mobile dynamic ID authenticated key agreement schemeabstractIn recent years, due to the wide applications of client-server architecture, the problem of only legal users have access to use the various remote services has attracted much attention. Consequently, many chaotic maps-based authenticated key agreement schemes using static ID have been widely used. However, static ID authentication schemes cannot provide user anonymity. It is a better choice to utilize dynamic ID authentication scheme. Recently, Lin proposed a chaotic maps-based mobile dynamic ID authenticated key agreement scheme and proved that it was secure against existential active attacks. Unfortunately, in this paper, we show that Lin's scheme cannot resist dictionary attack, user spoofing attack, and denial of service attack. Moreover, the paper first proposed an attack method called exclusive-or operation with pad operation leaking attack, which can lead to the worst case scenario: an adversary can get the session key without being detected. In addition, in the password-change phase of Lin's scheme, there is no authenticated process for the user. In other words, even if anyone else inputs the two uncorrelated passwords, the mobile device will continue to update the password, which leads to the consequence that the legal user cannot log in forever. Finally, we proposed an improved protocol based on chaotic maps with provable security under the random oracle model. Compared with previous related works, the improved protocol not only can withstand existential active attacks, but also has better computational efficiency. Copyright © 2015 John Wiley & Sons, Ltd. Hongfeng Zhu |
Secur. Commun. Networks | 1 |
| 2007 | An Efficient Client-to-Client Password-Authenticated Key Exchange Resilient to Server CompromiseabstractWith rapid changes in the modern communication environment such as ad hoc networks and ubiquitous computing, it is necessary to construct a secure end-to-end channel between clients. The fundamental security goal of PAKE is security against dictionary attacks. The protocols for verifier-based PAKE are additionally required to be secure against server compromise. This paper presents a new password authentication and key-exchange protocol suitable for client-to-client without a server public key in different realms to agree on a common session key using different passwords over an untrusted network. The proposed protocol's security, simplicity, and speed make it ideal for a wide range of real-world applications in which secure password authentication is required. Hongfeng Zhu, Tianhua Liu, Guiran Chang |
PRDC | 1 |