Xuhua Ding

dblp:99/1702 · DBLP profile ↗
← Back
74ranked-venue papers
10as first author
19since 2021 · last 2025
0000-0003-3974-590XORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 56 · 6 first-author · 16 since 2021Computer networks · 6 · 3 first-author · 1 since 2021Databases, data management, data science and information retrieval · 5Systems, architecture and hardware · 3 · 1 first-author · 1 since 2021Software engineering, systems software and programming languages · 2 · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2Artificial intelligence and machine learning · 1Theory of computation · 1
YearPublicationVenuePosition
2025 PRISM: To Fortify Widget Based User-App Data Exchanges Using Android Virtualization Framework
YingTat Ng, Haiqing Qiu, Xuhua Ding
AsiaCCS4
2025 A System Framework to Symbolically Explore Intel TDX Module Execution
abstract
We present TDXplorer, the first dynamic symbolic analysis system for Intel's TDX Module, the software trusted computing base of TDX. Without using TDX hardware, an analyzer function on top of TDXplorer can not only apply dynamic analysis to control and instrument the TDX Module's execution, but also carry out symbolic execution for path exploration as well as security and functionality reasoning. The two types of analysis are seamlessly integrated in a way that symbolic execution is conducted directly upon the TDX Module's binary code and runtime states, which are shaped by using dynamic analysis techniques. We implement TDXplorer on Linux and measure its performance and correctness against executions on a TDX platform. Our case studies on symbolic modeling of secure EPT creation and KeyHole region management demonstrate that TDXplorer is a versatile and capable tool supporting various analysis tasks.
Pansilu Pitigalaarachchi, Xuhua Ding
CCS2
2025 SCRUTINIZER: Towards Secure Forensics on Compromised TrustZone
Yiming Zhang 0030, Fengwei Zhang, Xiapu Luo, Rui Hou 0001, Xuhua Ding, Zhenkai Liang, Shoumeng Yan, Tao Wei 0002, Zhengyu He
NDSS5
2025 Oblivious Digital Tokens
Mihael Liskij, Xuhua Ding, Gene Tsudik, David A. Basin
USENIX Security Symposium2
2025 TETD: Trusted Execution in Trust Domains
Zhanbo Wang, Jiaxin Zhan, Xuhua Ding, Fengwei Zhang
USENIX Security Symposium3
2025 Enhancing the Security of One-Tap Authentication Services via Dynamic Application Identification
abstract
The One-Tap Authentication (OTAuth) service enables users to quickly log in or sign up for app accounts using their phone number. OTAuth provides a more secure and convenient alternative to password-based and Short Message Service (SMS)-based authentication schemes. Consequently, the OTAuth service has been adopted by numerous Mobile Network Operators (MNOs) worldwide. However, a high severity vulnerability remains unaddressed in the OTAuth service, which allows an attacker to access a victim’s various app accounts, posing a significant risk to user privacy and data security. In this paper, we present LoadShow, which, to the best of our knowledge, is the first security-enhanced OTAuth scheme to address this vulnerability. We propose a novel dynamic application identification technique that aims to address the root cause of this vulnerability, i.e., the inability of MNOs to distinguish between different applications on the same device. Specifically, application identification is based on the hardware load side-channel and captures the unique CPU and GPU load characteristics of applications through the sequence of timing values of fingerprinting functions. We evaluate the effectiveness of LoadShow by accuracy, False Positive Rate (FPR), and True Positive Rate (TPR). We also evaluate its multi-platform compatibility on devices with different architectures and models. LoadShow achieves over 90% accuracy, with a TPR exceeding 90% and an FPR below 1%. The evaluation results demonstrate LoadShow’s capability to effectively differentiate between applications on a device, defend against app impersonation attacks, and reliably identify legitimate applications.
Di Liu 0019, Dawei Li 0009, Ruinan Hu, Jianwei Liu 0001, Song Bian 0001, Xuhua Ding, Yizhong Liu, Zhenyu Guan 0002
IEEE Trans. Inf. Forensics Secur.8
2024 ESem: To Harden Process Synchronization for Servers
abstract
Process synchronization primitives lubricate server computing involving a group of processes as they ensure those processes to properly coordinate their executions for a common purpose such as provisioning a web service. A malfunctioned synchronization due to attacks causes friction among processes and leads to unexpected, and often hard-to-detect, application transaction errors. Unfortunately, synchronization primitives are not naturally protected by existing hardware-assisted isolation techniques e.g., SGX, because their process-oriented isolation conflicts with the primitive's demand for cross-process operations.
Zhanbo Wang, Jiaxin Zhan, Xuhua Ding, Fengwei Zhang
AsiaCCS3
2024 Hardware-Assisted Live Kernel Function Updating on Intel Platforms
abstract
Traditional kernel updates such as perfective maintenance and vulnerability patching requires shutting the system down, disrupting continuous execution of applications. Enterprises and researchers have proposed various live updating techniques to patch the kernel with lower downtime to reduce the loss of useful uptime. However, existing kernel live update techniques either rely on specific support from the target OS, or are deployed in virtualized environments (i.e., systems running in virtual machines). In this paper we presentKShot, a hardware-assisted live and secure kernel function update mechanism for native operating systems. By leveraging x86 SMM and Intel SGX,KShotruns in hardware-assisted Trusted Execution Environments and updates kernel functions at the binary-level without relying on the underlying OS support. We demonstrate the applicability ofKShotby successfully patching critical kernel vulnerabilities, upgrading base kernel functions and drivers nearly instantly and transparently. Our experimental results show thatKShotincurs merely 70 microseconds downtime to update a one kilobyte binary and 18 MB memory overhead.
Lei Zhou 0023, Fengwei Zhang, Kevin Leach, Xuhua Ding, Zhenyu Ning, Guojun Wang 0001, Jidong Xiao
IEEE Trans. Dependable Secur. Comput.4
2024 Concretely Mapped Symbolic Memory Locations for Memory Error Detection
abstract
Memory allocation is a fundamental operation for managing memory objects in many programming languages. Misusing allocated memory objects (e.g.,buffer overflowanduse-after-free) can have catastrophic consequences. Symbolic execution-based approaches have been used to detect such memory errors, benefiting from their capabilities in automatic path exploration and test case generation. However, existing symbolic execution engines still suffer from fundamental limitations in modeling dynamic memory layouts; they either represent the locations of memory objects as concrete addresses and thus limit their analyses only to specific address layouts and miss errors that may only occur when the objects are located at special addresses, or represent the locations as simple symbolic variables without sufficient constraints and thus suffer from memory state explosion when they execute read/write operations involving symbolic addresses. Such limitations hinder the existing symbolic execution engines from effectively detecting certain memory errors. In this study, we proposeSymLoc, a symbolic execution-based approach that uses concretely mapped symbolic memory locations to alleviate the limitations mentioned above. Specifically, a new integration of three techniques is designed inSymLoc: (1) the symbolization of addresses and encoding of symbolic addresses into path constraints, (2) the symbolic memory read/write operations using a symbolic-concrete memory map, and (3) the automatic tracking of the uses of symbolic memory locations. We buildSymLocon top of the well-known symbolic execution engine KLEE and demonstrate its benefits in terms of memory error detection and code coverage capabilities. Our evaluation results show that: for address-specific spatial memory errors,SymLoccan detect 23 more errors inGNU Coreutils,Make, andm4programs that are difficult for other approaches to detect, and cover 15% and 48% more unique lines of code in the programs than two baseline approaches; for temporal memory errors,SymLoccan detect 8%-64% more errors in the Juliet Test Suite than various existing state-of-the-art memory error detectors. We also present two case studies to show sample memory errors detected bySymLocalong with their root causes and implications.
Haoxin Tu, Lingxiao Jiang, Jiaqi Hong, Xuhua Ding, He Jiang 0001
IEEE Trans. Software Eng.4
2023 KRover: A Symbolic Execution Engine for Dynamic Kernel Analysis
abstract
We present KRover, a novel kernel symbolic execution engine catered for dynamic kernel analysis such as vulnerability analysis and exploit generation. Different from existing symbolic execution engines, KRover operates directly upon a live kernel thread's virtual memory and weaves symbolic execution into the target's native executions. KRover is compact as it neither lifts the target binary to an intermediary representation nor uses QEMU or dynamic binary translation. Benchmarked against S2E, our performance experiments show that KRover is up to 50 times faster but with one tenth to one quarter of S2E memory cost. As shown in our four case studies, KRover is noise free, has the best-possible binary intimacy and does not require prior kernel instrumentation. Moreover, a user can develop her kernel analyzer that not only uses KRover as a symbolic execution library but also preserves its independent capabilities of reading/writing/controlling the target runtime. Namely, the resulting analyzer on top of KRover integrates symbolic reasoning and conventional dynamic analysis and reaps the benefits of their reinforcement to each other.
Pansilu Pitigalaarachchi, Xuhua Ding, Haiqing Qiu, Haoxin Tu, Jiaqi Hong, Lingxiao Jiang
CCS2
2023 DScope: To Reliably and Securely Acquire Live Data from Kernel-Compromised ARM Devices
Haiqing Qiu, Xuhua Ding
ESORICS (4)3
2023 T-Counter: Trustworthy and Efficient CPU Resource Measurement Using SGX in the Cloud
abstract
As cloud services have become popular, and their adoption is growing, consumers are becoming more concerned about the cost of cloud services. Cloud Service Providers (CSPs) generally use a pay-per-use billing scheme in the cloud services model: consumers use resources as they needed and are billed for their resource usage. However, CSPs are untrusted and privileged; they have full control of the entire operating system (OS) and may tamper with bills to cheat consumers. So, how to provide a trusted solution that can keep track of and verify the consumers’ resource usage has been a challenging problem. In this article, we propose a T-Counter framework based on Intel SGX. The T-Counter allows applications to construct a trusted solution to measure its CPU usage by itself in cloud computing. These constructed applications are instrumented with counters in basic blocks and added three components in trusted parts to count instructions and defend against malicious CSPs’ manipulations. We propose two algorithms which selectively instrument counters in the CFG. T-Counter is implemented as an extension of the LLVM framework and integrated with the SGX SDK. Theoretical analyses and evaluations show that T-Counter can effectively measure CPU usage and defend against malicious CSPs’ manipulations.
Chuntao Dong, Qingni Shen, Xuhua Ding, Daoqing Yu, Wu Luo, Pengfei Wu 0003, Zhonghai Wu
IEEE Trans. Dependable Secur. Comput.3
2022 ScriptChecker: To Tame Third-party Script Execution With Task Capabilities
Wu Luo, Xuhua Ding, Pengfei Wu 0003, Qingni Shen, Zhonghai Wu
NDSS2
2022 FastKLEE: faster symbolic execution via reducing redundant bound checking of type-safe pointers
abstract
Symbolic execution (SE) has been widely adopted for automatic program analysis and software testing. Many SE engines (e.g., KLEE or Angr) need to interpret certain Intermediate Representations (IR) of code during execution, which may be slow and costly. Although a plurality of studies proposed to accelerate SE, few of them consider optimizing the internal interpretation operations. In this paper, we propose FastKLEE, a faster SE engine that aims to speed up execution via reducing redundant bound checking of type-safe pointers during IR code interpretation. Specifically, in FastKLEE, a type inference system is first leveraged to classify pointer types (i.e., safe or unsafe) for the most frequently interpreted read/write instructions. Then, a customized memory operation is designed to perform bound checking for only the unsafe pointers and omit redundant checking on safe pointers. We implement FastKLEE on top of the well-known SE engine KLEE and combined it with the notable type inference system CCured. Evaluation results demonstrate that FastKLEE is able to reduce by up to 9.1% (5.6% on average) as the state-of-the-art approach KLEE in terms of the time to explore the same number (i.e., 10k) of execution paths. FastKLEE is opensourced at https://github.com/haoxintu/FastKLEE. A video demo of FastKLEE is available at https://youtu.be/fjV_a3kt-mo.
Haoxin Tu, Lingxiao Jiang, Xuhua Ding, He Jiang 0001
ESEC/SIGSOFT FSE3
2022 Smile: Secure Memory Introspection for Live Enclave
abstract
SGX enclaves prevent external software from accessing their memory. This feature conflicts with legitimate needs for enclave memory introspection, e.g., runtime stack collection on an enclave under a return-oriented-programming attack. We propose SMILE for enclave owners to acquire live enclave contents with the assistance of a semi-trusted agent installed by the host platform’s vendor as a plug-in of the System Management Interrupt handler. SMILE authenticates the enclave under introspection without trusting the kernel nor depending on the SGX attestation facility. SMILE is enclave security preserving as breaking of SMILE does not undermine enclave security. It allows a cloud server to provide the enclave introspection service. We have implemented a SMILE prototype and run various experiments to read enclave code, heap, stack and SSA frames. The total cost for introspecting one page is less than 300 microseconds.
Lei Zhou 0023, Xuhua Ding, Fengwei Zhang
SP2
2021 Catch You With Cache: Out-of-VM Introspection to Trace Malicious Executions
abstract
Out-of-VM introspection is an imperative part of security analysis. The legacy methods either modify the system, introducing enormous overhead, or rely heavily on hardware features, which are neither available nor practical in most cloud environments. In this paper, we propose a novel analysis method, named as Catcher, that utilizes CPU cache to perform out-of-VM introspection. Catcher does not make any modifications to the target program and its running environment, nor demands special hardware support. Implemented upon Linux KVM, it natively introspects the target's virtual memory. More importantly, it uses the cache-based side channel to infer the target control flow. To deal with the inherent limitations of the side channel, we propose several heuristics to improve the accuracy and stability of Catcher. Our experiments against various malware armored with packing techniques show that Catcher can recover the control flow in real time with around 67% to 97% accuracy scores. Catcher incurs a negligible overhead to the system and can be launched at anytime to monitor an ongoing attack inside a virtual machine.
Chao Su 0001, Xuhua Ding, Qingkai Zeng 0002
DSN2
2021 On the Root of Trust Identification Problem
abstract
Trusted Execution Environments (TEEs) are becoming ubiquitous and are currently used in many security applications: from personal IoT gadgets to banking and databases. Prominent examples of such architectures are Intel SGX, ARM TrustZone, and Trusted Platform Modules (TPMs). A typical TEE relies on a dynamic Root of Trust (RoT) to provide security services such as code/data confidentiality and integrity, isolated secure software execution, remote attestation, and sensor auditing. Despite their usefulness, there is currently no secure means to determine whether a given security service or task is being performed by the particular RoT within a specific physical device. We refer to this as the Root of Trust Identification (RTI) problem and discuss how it inhibits security for applications such as sensing and actuation.
Ivan Oliveira Nunes, Xuhua Ding, Gene Tsudik
IPSN2
2021 A Novel Dynamic Analysis Infrastructure to Instrument Untrusted Execution Flow Across User-Kernel Spaces
abstract
Code instrumentation and hardware based event trapping are two primary approaches used in dynamic malware analysis systems. In this paper, we propose a new approach called Execution Flow Instrumentation (EFI) where the analyzer execution flow is interleaved with the target flow in user- and kernel-mode, at junctures flexibly chosen by the analyzer at runtime. We also propose OASIS as the system infrastructure to realize EFI with virtues of the current two approaches, however without their drawbacks. Despite being securely and transparently isolated from the target, the analyzer introspects and controls it in the same native way as instrumentation code. We have implemented a prototype of OASIS and rigorously evaluated it with various experiments including performance and anti-analysis benchmark tests. We have also conducted two EFI case studies. The first is a cross-space control flow tracer and the second includes two EFI tools working in tandem with Google Syzkaller. One tool makes a dynamic postmortem analysis according to a kernel crash report; and the other explores the behavior of a malicious kernel space device driver which evades Syzkaller logging. The studies show that EFI analyzers are well-suited for fine-grained on-demand dynamic analysis upon a malicious thread in user or kernel mode. It is easy to develop agile EFI tools as they are user-space programs.
Jiaqi Hong, Xuhua Ding
SP2
2021 A Coprocessor-Based Introspection Framework Via Intel Management Engine
abstract
During the past decade, virtualization-based (e.g., virtual machine introspection) and hardware-assisted approaches (e.g., x86 SMM and ARM TrustZone) have been used to defend against low-level malware such as rootkits. However, these approaches either require a large Trusted Computing Base (TCB) or they must share CPU time with the operating system, disrupting normal execution. In this article, we propose an introspection framework called Nighthawk that transparently checks system integrity and monitor the runtime state of target system. Nighthawk leverages the Intel Management Engine (IME), a co-processor that runs in isolation from the main CPU. By using the IME, our approach has a minimal TCB and incurs negligible overhead on the host system on a suite of indicative benchmarks. We use Nighthawk to introspect the system software and firmware of a host system at runtime. The experimental results show that Nighthawk can detect real-world attacks against the OS, hypervisors, and System Management Mode while mitigating several classes of evasive attacks. Additionally, Nighthawk can monitor the runtime state of host system against the suspicious applications running in target machine.
Lei Zhou 0023, Fengwei Zhang, Jidong Xiao, Kevin Leach, Westley Weimer, Xuhua Ding, Guojun Wang 0001
IEEE Trans. Dependable Secur. Comput.6
2018 To Detect Stack Buffer Overflow with Polymorphic Canaries
abstract
Stack Smashing Protection (SSP) is a simple and highly efficient technique widely used in practice as the front line defense against stack buffer overflow attacks. Unfortunately, SSP is known to be vulnerable to the so-called byte-by-byte attack. Although several remedy schemes are proposed in the recent literature, their security is achieved at the price of practicality, because their complex logics ruin SSP's simplicity and high-efficiency. In this paper, we present an elegant solution named as Polymorphic SSP (P-SSP) that attains the same security without sacrificing SSP's strengths. We also propose three extensions of the basic scheme for better compatibility, stronger security, and local variable protection, respectively. We have implemented both a compiler plugin and a binary instrumentation tool for deploying P-SSP. Their respective runtime overheads are only 0.24% and 1.01%. We have also experimented with our extensions and compared their pros and cons with the basic scheme.
Xuhua Ding, Chengbin Pang, Bing Mao 0001
DSN2
2018 Initializing trust in smart devices via presence attestation
Xuhua Ding, Gene Tsudik
Comput. Commun.1
2018 FIMCE: A Fully Isolated Micro-Computing Environment for Multicore Systems
abstract
Virtualization-based memory isolation has been widely used as a security primitive in various security systems to counter kernel-level attacks. In this article, our in-depth analysis on this primitive shows that its security is significantly undermined in the multicore setting when other hardware resources for computing are not enclosed within the isolation boundary. We thus propose to construct a fully isolated micro-computing environment (FIMCE) as a new primitive. By virtue of its architectural niche, FIMCE not only offers stronger security assurance than its predecessor, but also features a flexible and composable environment with support for peripheral device isolation, thus greatly expanding the scope of applications. In addition, FIMCE can be integrated with recent technologies such as Intel Software Guard Extensions (SGX) to attain even stronger security guarantees. We have built a prototype of FIMCE with a bare-metal hypervisor. To show the benefits of using FIMCE as a building block, we have also implemented four applications which are difficult to construct using the existing memory isolation method. Experiments with these applications demonstrate that FIMCE imposes less than 1% overhead on single-threaded applications, while the maximum performance loss on multithreaded applications is bounded by the degree of parallelism at the processor level.
Siqi Zhao, Xuhua Ding
ACM Trans. Priv. Secur.2
2017 Presence Attestation: The Missing Link in Dynamic Trust Bootstrapping
abstract
Many popular modern processors include an important hardware security feature in the form of a DRTM (Dynamic Root of Trust for Measurement) that helps bootstrap trust and resists software attacks. However, despite substantial body of prior research on trust establishment, security of DRTM was treated without involvement of the human user, who represents a vital missing link. The basic challenge is: how can a human user determine whether an expected DRTM is currently active on her device?
Zhangkai Zhang, Xuhua Ding, Gene Tsudik, Jinhua Cui 0002, Zhoujun Li 0001
CCS2
2017 On the Effectiveness of Virtualization Based Memory Isolation on Multicore Platforms
abstract
Virtualization based memory isolation has been widely used as a security primitive in many security systems. This paper firstly provides an in-depth analysis of its effectiveness in the multicore setting, a first in the literature. Our study reveals that memory isolation by itself is inadequate for security. Due to the fundamental design choices in hardware, it faces several challenging issues including page table maintenance, address mapping validation and thread identification. As demonstrated by our attacks implemented on XMHF and BitVisor, these issues undermine the security of memory isolation. Next, we propose a new isolation approach that is immune to the aforementioned problems. In our design, the hypervisor constructs a fully isolated micro computing environment (FIMCE) that exposes a minimal attack surface to an untrusted OS on a multicore platform. By virtue of its architectural niche, FIMCE offers stronger assurance and greater versatility than memory isolation. We have built a prototype of FIMCE and measured its performance. To show the benefits of using FIMCE as a building block, we have also implemented several practical applications which cannot be securely realized by using memory isolation alone.
Siqi Zhao, Xuhua Ding
EuroS&P2
2017 Seeing Through The Same Lens: Introspecting Guest Address Space At Native Speed
Siqi Zhao, Xuhua Ding, Dawu Gu
USENIX Security Symposium2
2017 Secure server-aided top-k monitoring
HweeHwa Pang, Yanjiang Yang, Xuhua Ding
Inf. Sci.4
2017 Adaptable key-policy attribute-based encryption with time interval
Siqi Ma 0001, Junzuo Lai, Robert H. Deng, Xuhua Ding
Soft Comput.4
2016 Attribute-Based Encryption with Granular Revocation
Hui Cui 0001, Robert H. Deng, Xuhua Ding, Yingjiu Li
SecureComm3
2016 H-Binder: A Hardened Binder Framework on Android Systems
Dong Shen 0001, Zhangkai Zhang, Xuhua Ding, Zhoujun Li 0001, Robert H. Deng
SecureComm3
2015 Efficient Virtualization-Based Application Protection Against Untrusted Operating System
abstract
Commodity monolithic operating systems are abundant with vulnerabilities that lead to rootkit attacks. Once an operating system is subverted, the data and execution of user applications are fully exposed to the adversary, regardless whether they are designed and implemented with security considerations. Existing application protection schemes have various drawbacks, such as high performance overhead, large Trusted Computing Base (TCB), or hardware modification. In this paper, we present the design and implementation of AppShield, a hypervisor-based approach that reliably safeguards code, data and execution integrity of a critical application, in a more efficient way than existing systems. The protection overhead is localized to the protected application only, so that unprotected applications and the operating system run without any performance loss. In addition to the performance advantage, AppShield tackles several newly identified threats in this paper which are not systematically addressed previously. We build a prototype of AppShield with a tiny hypervisor, and experiment with AppShield by running several off-the-shelf applications on a Linux platform. The results testify to AppShield's low performance costs in terms of CPU computation, disk I/O and network I/O.
Yueqiang Cheng, Xuhua Ding, Robert H. Deng
AsiaCCS2
2015 On Security of Content-Based Video Stream Authentication
abstract
Content-based authentication (CBA) schemes are used to authenticate multimedia streams while allowing content-preserving manipulations such as bit-rate transcoding. In this paper, we survey and classify existing transform-domain CBA schemes for videos into two categories, and point out that in contrary to CBA for images, there exists a common design flaw in these schemes. We present the principles (based on video coding concept) on how the flaw can be exploited to mount semantic-changing attacks in the transform domain that cannot be detected by existing CBA schemes. We show attack examples including content removal, modification and insertion attacks. Noting that these CBA schemes are designed at the macroblock level, we discuss, from the attacker’s point of view, the conditions in attacking content-based authenticated macroblocks.
Swee-Won Lo, Zhuo Wei, Robert H. Deng, Xuhua Ding
ESORICS (1)4
2015 Hardware-Assisted Fine-Grained Code-Reuse Attack Detection
Pinghai Yuan, Qingkai Zeng 0002, Xuhua Ding
RAID3
2015 SuperCall: A Secure Interface for Isolated Execution Environment to Dynamically Use External Services
Yueqiang Cheng, Xuhua Ding, Qingni Shen
SecureComm4
2014 ROPecker: A Generic and Practical Approach For Defending Against ROP Attacks
Yueqiang Cheng, Zongwei Zhou, Xuhua Ding, Robert H. Deng
NDSS4
2014 Technique for authenticating H.264/SVC and its performance evaluation over wireless mobile networks
Swee-Won Lo, Robert H. Deng, Xuhua Ding
J. Comput. Syst. Sci.4
2014 Efficient block-based transparent encryption for H.264/SVC bitstreams
Robert H. Deng, Xuhua Ding, Yongdong Wu, Zhuo Wei
Multim. Syst.2
2014 Efficient authentication and access control of scalable multimedia streams over packet-lossy networks
abstract
ABSTRACT Securing scalable multimedia streams becomes an important issue with the emergence of various scalable multimedia coding standards and their wide spread applications. In this paper, we first propose two novel schemes for authenticating scalable multimedia streams over packet‐lossy networks. The first scheme uses a digital signature to protect the integrity of a group of frames and uses erasure correction coding to combat packet loss. The second scheme employs message authentication code to protect integrity of individual frames, which is completely resilient to packet loss and greatly improves computational efficiency compared with the first scheme. With the second authentication scheme, we further present a scheme that provides both authentication and access control to scalable multimedia streams over packet‐lossy networks. This third scheme uses symmetric encryption to enforce access control by allowing authorized users to decrypt substreams corresponding to their privileges and uses attribute‐based encryption to disseminate secret keys to users. For the first two schemes, we analyze their performance in terms of computation cost, communication overhead, buffer size, and probability of successful authentication, whereas for the third scheme, we demonstrate its application to H.264 scalable video coding encoded streams. Copyright © 2013 John Wiley & Sons, Ltd.
Robert H. Deng, Xuhua Ding, Swee-Won Lo
Secur. Commun. Networks2
2014 A Hybrid Scheme for Authenticating Scalable Video Codestreams
abstract
A scalable video coding (SVC) codestream consists of one base layer and possibly several enhancement layers. The base layer, which contains the lowest quality and resolution images, is the foundation of the SVC codestream and must be delivered to recipients, whereas enhancement layers contain richer contour/texture of images in order to supplement the base layer in resolution, quality, and temporal scalabilities. This paper presents a novel hybrid authentication (HAU) scheme. The HAU employs both cryptographic authentication and content-based authentication techniques to ensure integrity and authenticity of the SVC codestreams. Our analysis and experimental results indicate that the HAU is able to detect malicious manipulations and locate the tampered image regions while is robust to content-preserving manipulations for enhancement layers. Although our focus in this paper is on authenticating H.264/SVC codestreams, the proposed technique is also applicable to authenticate other scalable multimedia contents such as MPEG-4 fine grain scalability and JPEG2000 codestreams.
Zhuo Wei, Yongdong Wu, Robert H. Deng, Xuhua Ding
IEEE Trans. Inf. Forensics Secur.4
2014 Privacy-Preserving Ad-Hoc Equi-Join on Outsourced Data
abstract
In IT outsourcing, a user may delegate the data storage and query processing functions to a third-party server that is not completely trusted. This gives rise to the need to safeguard the privacy of the database as well as the user queries over it. In this article, we address the problem of running ad hoc equi-join queries directly on encrypted data in such a setting. Our contribution is the first solution that achieves constant complexity per pair of records that are evaluated for the join. After formalizing the privacy requirements pertaining to the database and user queries, we introduce a cryptographic construct for securely joining records across relations. The construct protects the database with a strong encryption scheme. Moreover, information disclosure after executing an equi-join is kept to the minimum—that two input records combine to form an output record if and only if they share common join attribute values. There is no disclosure on records that are not part of the join result. Building on this construct, we then present join algorithms that optimize the join execution by eliminating the need to match every record pair from the input relations. We provide a detailed analysis of the cost of the algorithms and confirm the analysis through extensive experiments with both synthetic and benchmark workloads. Through this evaluation, we tease out useful insights on how to configure the join algorithms to deliver acceptable execution time in practice.
HweeHwa Pang, Xuhua Ding
ACM Trans. Database Syst.2
2013 Verifiable and private top-k monitoring
abstract
In a data streaming model, records or documents are pushed from a data owner, via untrusted third-party servers, to a large number of users with matching interests. The match in interest is calculated from the correlation between each pair of document and user query. For scalability and availability reasons, this calculation is delegated to the servers, which gives rise to the need to protect the privacy of the documents and user queries. In addition, the users need to guard against the eventuality of a server distorting the correlation score of the documents to manipulate which documents are highlighted to certain users.
Xuhua Ding, HweeHwa Pang, Junzuo Lai
AsiaCCS1
2013 Accountable Trapdoor Sanitizable Signatures
Junzuo Lai, Xuhua Ding, Yongdong Wu
ISPEC2
2013 Self-blindable Credential: Towards Anonymous Entity Authentication Upon Resource Constrained Devices
Yanjiang Yang, Xuhua Ding, Haibing Lu, Jian Weng 0001, Jianying Zhou 0001
ISC2
2013 Achieving Revocable Fine-Grained Cryptographic Access Control over Cloud Data
Yanjiang Yang, Xuhua Ding, Haibing Lu, Zhiguo Wan, Jianying Zhou 0001
ISC2
2013 DriverGuard: Virtualization-Based Fine-Grained Protection on I/O Flows
abstract
Most commodity peripheral devices and their drivers are geared to achieve high performance with security functions being opted out. The absence of strong security measures invites attacks on the I/O data and consequently posts threats to those services feeding on them, such as fingerprint-based biometric authentication. In this article, we present a generic solution called DriverGuard, which dynamically protects the secrecy of I/O flows such that the I/O data are not exposed to the malicious kernel. Our design leverages a composite of cryptographic and virtualization techniques to achieve fine-grained protection without using any extra devices and modifications on user applications. We implement the DriverGuard prototype on Xen by adding around 1.7K SLOC. DriverGuard is lightweight as it only needs to protect around 2% of the driver code’s execution. We measure the performance and evaluate the security of DriverGuard with three input devices (keyboard, fingerprint reader and camera) and three output devices (printer, graphic card, and sound card). The experiment results show that DriverGuard induces negligible overhead to the applications.
Yueqiang Cheng, Xuhua Ding, Robert H. Deng
ACM Trans. Inf. Syst. Secur.2
2012 A Generic Construction of Accountable Decryption and Its Applications
Xuhua Zhou, Xuhua Ding, Kefei Chen
ACISP2
2012 Coercion resistance in authentication responsibility shifting
abstract
To meet the demand of scalability and usability, many real-world authentication systems have adopted the idea of responsibility shifting, explicitly or implicitly, where a user's responsibility of authentication is shifted to another entity, usually in case of failure of the primary authentication method. One example of responsibility shifting is in the fourth-factor authentication [1] whereby a user gets the crucial authentication assistance from a helper who takes over the responsibility. In the fourth-factor authentication system [1], subverting/coercing the helper (trustee) allows the adversary to log in without capturing the password of the user.
Payas Gupta, Xuhua Ding, Debin Gao
AsiaCCS2
2012 STC 2012: the seventh ACM workshop on scalable trusted computing
abstract
Trusted computing plays a pivotal role to facilitate a party to evaluate the integrity of others or to ensure desired security assurance, which is a very challenging task in large-scale and heterogeneous computing environments. Built upon the success from 2006 to 2011, the seventh ACM Workshop on Scalable Trusted Computing continues to serve as a forum for researchers as well as practitioners to disseminate and discuss recent advances and emerging issues. This proceedings includes selected papers that focus on system architectures, enabling mechanisms, and novel applications of trusted computing.
Xinwen Zhang, Xuhua Ding
CCS2
2012 A Generic Approach for Providing Revocation Support in Secret Handshake
Yanjiang Yang, Haibing Lu, Jian Weng 0001, Xuhua Ding, Jianying Zhou 0001
ICICS4
2012 An Improved Authentication Scheme for H.264/SVC and Its Performance Evaluation over Non-stationary Wireless Mobile Networks
Swee-Won Lo, Robert H. Deng, Xuhua Ding
NSS4
2012 A scalable and format-compliant encryption scheme for H.264/SVC bitstreams
Zhuo Wei, Yongdong Wu, Xuhua Ding, Robert H. Deng
Signal Process. Image Commun.3
2011 Hierarchical Identity-Based Chameleon Hash and Its Applications
Feng Bao 0001, Robert H. Deng, Xuhua Ding, Junzuo Lai, Yunlei Zhao
ACNS3
2011 DriverGuard: A Fine-Grained Protection on I/O Flows
Yueqiang Cheng, Xuhua Ding, Robert H. Deng
ESORICS2
2011 Lightweight Delegated Subset Test with Privacy Protection
Xuhua Zhou, Xuhua Ding, Kefei Chen
ISPEC2
2011 Database Access Pattern Protection Without Full-Shuffles
abstract
Privacy protection is one of the fundamental security requirements for database outsourcing. A major threat is information leakage from database access patterns generated by query executions. The standard private information retrieval (PIR) schemes, which are widely regarded as theoretical solutions, entailO(n) computational overhead per query for a database withnitems. Recent works propose to protect access patterns by introducing a trusted component with constant storage size. The resulting privacy assurance is as strong as PIR, though withO(1) online computation cost, they still haveO(n) amortized cost per query due to periodically full database shuffles. In this paper, we design a novel scheme in the same model with provable security, which only shuffles a portion of the database. The amortized server computational complexity is reduced toO(√{nlogn/k}). With a secure storage storing thousands of items, our scheme can protect the access pattern privacy of databases of billions of entries, at a lower cost than those using ORAM-based poly-logarithm algorithms.
Xuhua Ding, Yanjiang Yang, Robert H. Deng
IEEE Trans. Inf. Forensics Secur.1
2010 A Hybrid Method to Detect Deflation Fraud in Cost-Per-Action Online Advertising
Xuhua Ding
ACNS1
2010 Embellishing Text Search Queries To Protect User Privacy
abstract
Users of text search engines are increasingly wary that their activities may disclose confidential information about their business or personal profiles. It would be desirable for a search engine to perform document retrieval for users while protecting their intent. In this paper, we identify the privacy risks arising from semantically related search terms within a query, and from recurring high-specificity query terms in a search session. To counter the risks, we propose a solution for a similarity text retrieval system to offer anonymity and plausible deniability for the query terms, and hence the user intent, without degrading the system's precision-recall performance. The solution comprises a mechanism that embellishes each user query with decoy terms that exhibit similar specificity spread as the genuine terms, but point to plausible alternative topics. We also provide an accompanying retrieval scheme that enables the search engine to compute the encrypted document relevance scores from only the genuine search terms, yet remain oblivious to their distinction from the decoys. Empirical evaluation results are presented to substantiate the effectiveness of our solution.
HweeHwa Pang, Xuhua Ding, Xiaokui Xiao
Proc. VLDB Endow.2
2010 Efficient processing of exact top-k queries over disk-resident sorted lists
HweeHwa Pang, Xuhua Ding, Baihua Zheng
VLDB J.2
2009 Conditional proxy re-encryption secure against chosen-ciphertext attack
abstract
In a proxy re-encryption (PRE) system [4], a proxy, authorized by Alice, can convert a ciphertext for Alice into a ciphertext for Bob without seeing the underlying plaintext. PRE has found many practical applications requiring delegation. However, it is inadequate to handle scenarios where a fine-grained delegation is demanded. To overcome the limitation of existing PRE systems, we introduce the notion of conditional proxy re-encryption (C-PRE), whereby only ci-phertext satisfying a specific condition set by Alice can be transformed by the proxy and then decrypted by Bob. We formalize its security model and propose an efficient C-PRE scheme, whose chosen-ciphertext security is proven under the 3-quotient bilinear Diffie-Hellman assumption. We further extend the construction to allow multiple conditions with a slightly higher overhead.
Jian Weng 0001, Robert H. Deng, Xuhua Ding, Cheng-Kang Chu, Junzuo Lai
AsiaCCS3
2009 Privacy-Preserving Querying in Sensor Networks
abstract
Wireless sensor networks (WSNs) provide sensing and monitoring services by means of many tiny autonomous devices equipped with wireless radio transceivers. With large-scale WSNs being deployed on a long-term basis, not only security but also privacy issues must be taken into account. Furthermore, when network operators offer on-demand access to sensor measurements to their clients, query mechanisms should ideally leak neither client interests nor query patterns. In this paper, we present a privacy-preserving WSN query mechanism that uses standard cryptographic techniques. Besides preventing unauthorized entities from accessing sensor readings, it minimizes leakage of (potentially sensitive) information about users' query targets and patterns.
Emiliano De Cristofaro, Xuhua Ding, Gene Tsudik
ICCCN2
2009 Leak-free mediated group signatures
abstract
Group signatures are a useful cryptographic construct for privacy-preserving non-repudiable authentication, and there have been many group signature schemes. In this paper, we introduce a variant of group signatures that offers two new security properties called leak-freedom and immediate-revocation. Intuitively, the former ensures that an insider (i.e., an authorized but malicious signer) be unable to convince an outsider (e.g., a signature receiver) that she indeed signed a certain message; whereas the latter ensures that the authorization for a user to issue group signatures can be immediately revoked whenever the need arises (temporarily or permanently). These properties are not offered in existing group signature schemes, nor captured by their security definitions. However, these properties might be crucial to a large class of enterprise-centric applications because they are desirable from the perspective of the enterprises who adopt group signatures or are the group signatures liability-holders (i.e., will be held accountable for the consequences of group signatures). In addition to introducing these new security properties, we present a scheme that possesses both traditional and these newly introduced properties. Our scheme is constructed using an architectural approach where a mediation server is exploited to trade on-line communications for the extra security properties, which explains why the resulting scheme is called “leak-free mediated group signatures”.
Xuhua Ding, Gene Tsudik, Shouhuai Xu
J. Comput. Secur.1
2009 Tuning On-Air Signatures for Balancing Performance and Confidentiality
abstract
In this paper, we investigate the trade off between performance and confidentiality in signature-based air indexing schemes for wireless data broadcast. Two metrics, namely, false drop probability and false guess probability, are defined to quantify the filtering efficiency and confidentiality loss of a signature scheme. Our analysis reveals that false drop probability and false guess probability share a similar trend as the tuning parameters of a signature scheme change and it is impossible to achieve a low false drop probability and a high false guess probability simultaneously. In order to balance the performance and confidentiality, we perform an analysis to provide a guidance for parameter settings of the signature schemes to meet different system requirements. In addition, we propose the jump pointer technique and the XOR signature scheme to further improve the performance and confidentiality. A comprehensive simulation has been conducted to validate our findings.
Baihua Zheng, Wang-Chien Lee, Peng Liu 0005, Dik Lun Lee, Xuhua Ding
IEEE Trans. Knowl. Data Eng.5
2008 A Dynamic Trust Management Scheme to Mitigate Malware Proliferation in P2P Networks
abstract
The surge of peer-to-peer (P2P) networks consisting of thousands of of hosts makes them a breeding ground for malware proliferation. Although some existing studies have shown that malware proliferation can pose significant threats to P2P networks, defending against such an attack is largely an open problem. This paper aims to develop the countermeasure that can effectively mitigate the malware proliferation while preserving P2P networks' performance. To this end, we propose a dynamic trust management scheme based upon localized trust evaluation and alert propagation which prevents innocent peers from downloading files from infected peers. Our analysis and experimental results show that our approach can effectively reduce the malware proliferation rate.
Xuhua Ding, Wei Yu 0002
ICC1
2008 Private Query on Encrypted Data in Multi-user Settings
Feng Bao 0001, Robert H. Deng, Xuhua Ding, Yanjiang Yang
ISPEC3
2008 An Efficient PIR Construction Using Trusted Hardware
Yanjiang Yang, Xuhua Ding, Robert H. Deng, Feng Bao 0001
ISC2
2007 Protecting RFID communications in supply chains
abstract
Recent years have seen much growing attention on RFID security. However, little work has been performed to address the security issues in the context of supply chain management, which is exactly the major field for RFID applications. Existing RFID solutions cannot be applied directly in this field because of a set of special RFID security requirements to be addressed for supply chain management. The major contribution of this paper is to identify the unique set of security requirements in supply chains and to propose a practical design of RFID communication protocols that satisfy the security requirements.
Yingjiu Li, Xuhua Ding
AsiaCCS2
2007 Equipping smart devices with public key signatures
abstract
One of the major recent trends in computing has been towards so-called smart devices, such as PDAs, cell phones and sensors. Such devices tend to have a feature in common: limited computational capabilities and equally limited power, as most operate on batteries. This makes them ill-suited for public key signatures. This article explores practical and conceptual implications of using Server-Aided Signatures (SAS) for these devices. SAS is a signature method that relies on partially-trusted servers for generating (normally expensive) public key signatures for regular users. Although the primary goal is to aid small, resource-limited devices in signature generation, SAS also offers fast certificate revocation, signature causality and reliable timestamping. It also has some interesting features such as built-in attack detection for users and DoS resistance for servers. Our experimental results also validate the feasibility of deploying SAS on smart devices.
Xuhua Ding, Daniele Mazzocchi, Gene Tsudik
ACM Trans. Internet Techn.1
2006 Anomaly Based Web Phishing Page Detection
abstract
Many anti-phishing schemes have recently been proposed in literature. Despite all those efforts, the threat of phishing attacks is not mitigated. One of the main reasons is that phishing attackers have the adaptability to change their tactics with little cost. In this paper, we propose a novel approach, which is independent of any specific phishing implementation. Our idea is to examine the anomalies in Web pages, in particular, the discrepancy between a Web site's identity and its structural features and HTTP transactions. It demands neither user expertise nor prior knowledge of the Web site. The evasion of our phishing detection entails high cost to the adversary. As shown by the experiments, our phishing detector functions with low miss rate and low false-positive rate
Xuhua Ding
ACSAC2
2006 Private Information Retrieval Using Trusted Hardware
Shuhong Wang 0001, Xuhua Ding, Robert H. Deng, Feng Bao 0001
ESORICS2
2005 Multiplex Encryption: A Practical Approach to Encrypting Multi-recipient Emails
Xuhua Ding, Kefei Chen
ICICS2
2004 Leak-Free Group Signatures with Immediate Revocation
abstract
Group signatures are an interesting and appealing cryptographic construct with many promising potential applications. This work is motivated by attractive features of group signatures, particularly, their potential to serve as foundation for anonymous credential systems. We reexamine the entire notion of group signatures from a systems perspective and identify two new security requirements: leak-freedom and immediate-revocation, which are crucial for a large class of applications. We then present a new group signature scheme that achieves all identified properties. Our scheme is based on the so-called systems architecture approach. It is more efficient than the state-of-the-art and facilitates easy implementation. Moreover, it reflects the well-known separation-of-duty principle. Another benefit of our scheme is the obviated reliance on underlying anonymous communication channels, which are necessary in previous schemes.
Xuhua Ding, Gene Tsudik, Shouhuai Xu
ICDCS1
2004 Fine-grained control of security capabilities
abstract
We present a new approach for fine-grained control over users' security privileges (fast revocation of credentials) centered around the concept of an on-line semi-trusted mediator (SEM). The use of a SEM in conjunction with a simple threshold variant of the RSA cryptosystem (mediated RSA) offers a number of practical advantages over current revocation techniques. The benefits include simplified validation of digital signatures, efficient certificate revocation for legacy systems and fast revocation of signature and decryption capabilities. This paper discusses both the architecture and the implementation of our approach as well as its performance and compatibility with the existing infrastructure. Experimental results demonstrate its practical aspects.
Dan Boneh, Xuhua Ding, Gene Tsudik
ACM Trans. Internet Techn.2
2003 Simple Identity-Based Cryptography with Mediated RSA
Xuhua Ding, Gene Tsudik
CT-RSA1
2002 Experimenting with Server-Aided Signatures
Xuhua Ding, Daniele Mazzocchi, Gene Tsudik
NDSS1
2001 A Method for Fast Revocation of Public Key Certificates and Security Capabilities
Dan Boneh, Xuhua Ding, Gene Tsudik, Chi-Ming Wong
USENIX Security Symposium2