EDBT 2026 Demo / reviewers in the wild / expert
Rui Song 0010
dblp:01/2743-10
· DBLP profile ↗
19ranked-venue papers
5as first author
12since 2021 · last 2026
0000-0003-0797-5831ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 5 · 1 first-author · 2 since 2021Security and privacy · 4 · 4 since 2021Software engineering, systems software and programming languages · 4 · 1 first-authorSystems, architecture and hardware · 3 · 2 first-author · 3 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | ChainCred: Enforcing Comprehensive Credential Disclosure in WEB3 Systems
Rui Song 0010, Bin Xiao 0001 |
ICDCS | 1 |
| 2026 | Flexible and Privacy-Preserving Access Control Framework for Decentralized Identity SystemsabstractDecentralized identity systems have emerged as a transformative paradigm, granting users unprecedented data sovereignty and privacy-preserving capabilities, fueling critical innovations in Web3 ecosystems. However, these systems primarily serve as identity-layer solutions, forcing verifiers to design special cryptographic protocols for access control deployment, which is an error-prone and expert-dependent process. Moreover, existing approaches fail to effectively combat credential fraud (e.g., credential theft and revoked credential reuse) without compromising privacy guarantees. This paper presents FRAC (Flexible Fraud-Resistant Access Control), an efficient decentralized access control framework that achieves two paradigm shifts: 1) Streamlined access control deployment: a logic-centric paradigm encodes access criteria through declarative verification rules, eliminating manual cryptographic protocol design while enabling instant verifier onboarding and efficient presentation generation; 2) Provable fraud resistance: a format-agnostic defensive mechanism based on Merkle trees prevents malicious credential use, requiring only lightweight hash operations and signature verification instead of computation-intensive operations. We conduct rigorous security analysis based on universally composable security and evaluate the performance, demonstrating FRAC’s security and efficiency. Bin Xie 0006, Rui Song 0010, Zecheng Li 0001, Xiaotie Deng, Bin Xiao 0001 |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2026 | Achieving Flexible and Secure Authentication With Strong Privacy in Decentralized Networks
Bin Xie 0006, Rui Song 0010, Xuyuan Cai, Bin Xiao 0001 |
IEEE Trans. Netw. | 2 |
| 2025 | PSP: A Privacy-Preserving Self-certify Pseudonym Protocol for V2X
Xuyuan Cai, Rui Song 0010, Bin Xie 0006, Qingjun Xiao, Bin Xiao 0001 |
AsiaCCS | 2 |
| 2025 | Mining Attack with Zero Knowledge in the Blockchain
Jiaping Yu, Shang Gao 0006, Rui Song 0010, Zhiping Cai, Bin Xiao 0001 |
AsiaCCS | 3 |
| 2024 | MoDID: Decentralized Identity Management for Multiple OwnersabstractIdentity management plays a critical role in Web3 applications. Decentralized Identity (DID) offers a privacy-preserving solution, giving users full control over their identity information. Existing research on DID primarily focuses on single-owner scenarios, where owners have complete privileges for owner management and credentials. However, in multi-owner cases, current coarse-grained identity management approaches lead to serious privacy and security problems, such as identity impersonation and high key recovery overhead. Little work has been done on identity management for multiple owners. In this paper, we propose MoDID, a fine-grained identity management scheme for multiple owners, which complies with the DID standard proposed by W3C. First, our solution allows multiple owners to control DID subjects flexibly and reliably through hierarchical owner management. Additionally, we design a secure key recovery scheme to reduce the risk of identity loss while introducing lower overhead. Finally, we implement MoDID on the Sepolia Ethereum Test Network to evaluate the effectiveness of our proposed scheme. The result demonstrates that our system allows multiple owners to manage a single identity with lower gas consumption and time consumption than the state-of-the-art. Huijiong Yang, Rui Song 0010, Yubo Song, Bin Xiao 0001 |
ICC | 2 |
| 2023 | A Survey of Blockchain-Based Schemes for Data Sharing and ExchangeabstractData immutability, transparency and decentralization of blockchain make it widely used in various fields, such as Internet of things, finance, energy and healthcare. With the advent of the Big Data era, various companies and organizations urgently need data from other parties for data analysis and mining to provide better services. Therefore, data sharing and data exchange have become an enormous industry. Traditional centralized data platforms face many problems, such as privacy leakage, high transaction costs and lack of interoperability. Introducing blockchain into this field can address these problems, while providing decentralized data storage and exchange, access control, identity authentication and copyright protection. Although many impressive blockchain-based schemes for data sharing or data exchange scenarios have been presented in recent years, there is still a lack of review and summary of work in this area. In this paper, we conduct a detailed survey of blockchain-based data sharing and data exchange platforms, discussing the latest technical architectures and research results in this field. In particular, we first survey the current blockchain-based data sharing solutions and provide a detailed analysis of system architecture, access control, interoperability, and security. We then review blockchain-based data exchange systems and data marketplaces, discussing trading process, monetization, copyright protection and other related topics. Rui Song 0010, Bin Xiao 0001, Yubo Song, Songtao Guo, Yuanyuan Yang 0001 |
IEEE Trans. Big Data | 1 |
| 2023 | Enabling Privacy-Preserving and Efficient Authenticated Graph Queries on Blockchain-Assisted CloudsabstractPrior research has introduced a new scenario of blockchain-assisted clouds where the data owner outsources original data to cloud servers and stores some metadata on the blockchain. Despite some research on key-value query and range query in this hybrid-storage scenario, other more complicated data types are not yet supported. In this article, we conduct pioneering research on authenticated queries for graph data, which is a popular data type such as the knowledge graph data, on the blockchain-assisted cloud. The primary challenge is how to design an authenticated data structure (ADS) that supports authenticated queries and can be easily maintained by the blockchain. To this end, we propose a novel ADS, named PAGB, based on the RSA accumulator and completeness set. It can also prevent the original data from being revealed to the public through blockchain or irrelevant queries. We further optimize our design to be more efficient in terms of communication and computation. The effectiveness and efficiency of PAGB are verified through theoretical analysis and extensive experiments. Haotian Wu 0001, Zecheng Li 0001, Rui Song 0010, Bin Xiao 0001 |
IEEE Trans. Knowl. Data Eng. | 3 |
| 2022 | : A Traceable and Privacy-Preserving Data Exchange Scheme based on Non-Fungible Token and Zero-KnowledgeabstractWith the advent of the Big Data era, industry, business and academia have developed various data exchange schemes to make data more economically beneficial. Unfortunately, most of the existing systems provide only one-time data exchanges without the ability to track the provenance and transformations of datasets. In addition, existing systems encrypt the data to protect data privacy, which hinders demanders from verifying the correctness of the data and evaluating its value.To provide data traceability and privacy while ensuring fairness during data exchanges, we design and implement ZKDET, a traceable data exchange scheme based on non-fungible token and zero-knowledge, which is able to (i) track all transformations of data during their lifecycle and record them on the blockchain; (ii) provide zero-knowledge proofs to securely guarantee that all complex transformations and data contents are correct and meet specific requirements; and (iii) warrant exchange fairness and data privacy in public storage platforms. Security analysis and evaluations on ZKDET show that it can support traceable data exchange while preserving data privacy and maintaining high throughput despite large data volumes. Rui Song 0010, Shang Gao 0006, Yubo Song, Bin Xiao 0001 |
ICDCS | 1 |
| 2022 | Slicer: Verifiable, Secure and Fair Search over Encrypted Numerical Data Using BlockchainabstractVerifiable Searchable Symmetric Encryption (SSE) enables reliable search over encrypted, privacy-preserving data on untrusted clouds. Most existing SSE designs only focus on keyword-file search. However, a more difficult but useful search, range search over encrypted numerical values remains unsolved. Moreover, the fairness of search in the mutual distrusted scenario without public verification, where data users may maliciously deny the results after the local result verification, is not well addressed yet. In this paper, we take the first step to study the public verification problem atop the blockchain for encrypted numerical search. We design a novel verifiable SSE scheme named Slicer based on a Succinct Order-Revealing Encryption (SORE) scheme to achieve range search on numerical data. Our search results are verifiable, updated and privacy-preserving by SSE and maintaining the forward security. We illustrate the security and practicality of our design through rigorous analysis and extensive evaluations respectively. Haotian Wu 0001, Rui Song 0010, Kai Lei, Bin Xiao 0001 |
ICDCS | 2 |
| 2022 | Reducing Gas Consumption of Tornado Cash and Other Smart Contracts in EthereumabstractEthereum, the largest blockchain for running smart contracts, has been widely used, especially in financial and cryptocurrency exchange applications. Among them, Tornado Cash is a typical financial application that protects the privacy of users with anonymous transactions. However, users need to pay prohibitively high gas (transaction fees for smart contract calls) for anonymous transactions, which hinders Tornado Cash from wide applications. To address this issue, we introduced a new approach that shifts the high gas-consuming operations on smart contracts to local users. Furthermore, we use zero-knowledge proofs to ensure the operations are properly executed. The smart contract only needs to verify and update the results, which significantly reduces the gas fees of Tornado Cash. To validate our approach, we implemented a prototype and showed that our proposed method could save more than 61% of gas consumption of current operations while maintaining the privacy feature of Tornado Cash. Finally, we discussed further applications and open problems of our approach. Jingyan Yang, Shang Gao 0006, Guyue Li, Rui Song 0010, Bin Xiao 0001 |
TrustCom | 4 |
| 2021 | Data desensitization mechanism of Android application based on differential privacyabstractIn recent years, the mining and analysis of user data by Android applications have posed the risk of privacy breaches. However excessive permission control can affect the usability of applications. A mechanism that balances security and usability is urgently needed. In this paper, a data desensitization mechanism for Android applications based on differential privacy techniques is proposed. The mechanism can address the privacy protection of data flows generated by the interaction between users and Android applications. In order to solve the problem of constraints on the basic functions of the application caused by privacy security technique, this paper introduces a differential privacy mechanism based on Gaussian process. The mechanism performs hyperparametric optimization methods that combine sparse approximations and classification results. Also, by specifying the global sensitivity of the differential privacy budget specific randomization algorithm, the mechanism selects parameters with a specific probability to obtain the most effective parameter combination. Experimental results show that the differential privacy technique based on Gaussian process further enhances the availability of Android application data while obtaining the same privacy protection effect compared with ordinary differential privacy mechanisms. Xinzao Jiang, Yubo Song, Rui Song 0010, Aiqun Hu |
VTC Fall | 3 |
| 2020 | ClickGuard: Exposing Hidden Click Fraud via Mobile Sensor Side-channel AnalysisabstractAdvertising income depends on the amount of clicks by users of websites and mobile applications. However, the emergence of click fraud greatly reduces the real benefits of the advertisement. Most existing researches focus on detecting click fraud by analyzing properties and patterns of click data streams, but attackers can construct data that looks legitimate by replaying former data streams. In this paper, we propose a novel system called ClickGuard to detect click fraud attacks. ClickGuard takes advantage of motion sensor signals from mobile devices, since the pattern of motion signals is completely different under real click events and fraud events. To prevent attackers from bypassing the system by faking the time-domain statistical characteristics of original signals, we introduce the MFCC algorithm in feature extraction phase. MFCC algorithm can extract frequency-domain features of original signals in specific frequency bands which are hardly constructed out of thin air. Classifiers are finally constructed using these features and several machine learning algorithms. Experiments show that ClickGuard can achieve the accuracy of 96.71% in general environment and 84.16% when attackers modify the time-domain statistical characteristics of raw data. Congcong Shi, Rui Song 0010, Xinyu Qi, Yubo Song, Bin Xiao 0001, Sanglu Lu |
ICC | 2 |
| 2018 | I Know What You Type: Leaking User Privacy via Novel Frequency-Based Side-Channel AttacksabstractSmartphone sensors have been applied to record the movement of users for healthy use. However, the motion sensor readings recorded by malicious applications can be utilized as a side-channel to leak user privacy by keystroke inference. Most existing approaches use time-domain statistical characteristics for keystroke inference. Their systems are poor to show the subtle changes in short time period, since the time- domain statistical features can only reflect the characteristics in a long-time interval. In this paper, we propose a novel framework to perform keystroke inference on smartphones. This framework introduces an improved MFCC algorithm to extract frequency- domain features for more comprehensive use of raw data. Since the frequency-domain energy distribution of motion signals is concentrated, and the specificity of signals is strong, MFCC can improve the inference accuracies under complex scenarios. Based on this framework, we present a prototype called FreqKey, which is an inference system to leak user privacy such as PINs and passwords. FreqKey collects motion sensor readings during keystroke events and constructs classification models with machine learning algorithms. Experimental results show that FreqKey improves the performance in a variety of complex scenarios. Especially, even in web platform whose sampling rate is lower than 80Hz, FreqKey can achieve relatively high accuracy of 74.6%. To mitigate the frequency-based side-channel attack and protect user privacy, we propose a defense solution which contains sensor- activity monitoring, malicious program identification and interference signal injection. Rui Song 0010, Yubo Song, Shang Gao 0006, Bin Xiao 0001, Aiqun Hu |
GLOBECOM | 1 |
| 2014 | PHAT: A Preference and Honesty Aware Trust Model for Web ServicesabstractTrust is one of the most critical factors for a service requestor when selecting a service from a large pool of candidate services. However, existing web service trust models either do not consider users' preferences for different quality of service (QoS) attributes, or ignore the impact of vicious ratings on trust evaluation. To address these gaps, PHAT, a dynamic trust evaluation model with dual consideration of users' preferences and false ratings, is proposed in this paper. The model introduces an approach to automatically mine users' preferences from their requirements. The preferences are then used to determine the weight of each QoS attribute when integrating trust into multi-dimensional QoS attributes. The “local” trust on a service is derived by combining the trust on QoS attributes and the user's subjective ratings. Then, the users are divided into different groups according to their QoS preferences, and the honesty of each group is assessed by filtering out dishonest users based on a hybrid approach combining rating consistency clustering with an average method. Finally, the weight on ratings is dynamically adjusted according to the results of honesty assessment when calculating the global trustworthiness, namely, the reputation of a service. The proposed model is evaluated with real-world QoS data, and the results indicate that PHAT works well on personalized evaluation of trust, and can effectively dilute the influence of malicious ratings. Bixin Li, Hareton K. N. Leung, Rui Song 0010 |
IEEE Trans. Netw. Serv. Manag. | 4 |
| 2012 | Data Depedency Based Trust Evaluation for BPEL ProcessesabstractComposite services implement value-added functionality by composing service components with smaller granularity. Trust is an important criterion to judge whether a composite service can behave as expected. A feasible trust evaluation method for composite services is needed, which can guide service selection for users and the trust-based optimization and evolution for composite services. In this paper, a data dependency based trust evaluation approach for composite services in Business Process Execution Language (BPEL) is proposed. Firstly, we derive define-use pairs of variables to describe data dependency between service components in BPEL processes modeled by extensible BPEL Flow Graph (XBFG), in addition, dependency links including both direct and indirect data dependencies are used to evaluate the trust values of these service components, furthermore, on the basis of BPEL structure and XBFG, reduction rules are proposed to evaluate the global trust values of BPEL processes. Experiment results demonstrate that the proposed approach is effective for the trust evaluation of BPEL composite services and stable enough with the growing number of service components in BPEL. Cuicui Liu, Bixin Li, ShanShan Qi, Xiaona Wu, Rui Song 0010 |
APSEC | 5 |
| 2012 | A Trust Impact Analysis Model for Composite Service EvolutionabstractChanges to a composite service need to be well analyzed in order to ensure the trust of it. The analysis can be driven by identifying the impact caused by the changes on the trust of other component services as well as the composite service. In this paper, we propose a trust impact analysis model to analyze the impact of two kinds of evolution operations performed on a composite service: binding changes and business process changes. First, trust dependency graph is introduced to analyze the impact on the trust of component services. It not only identifies the affected component services but also quantifies the impact degree on the trust of them. Then we introduce control flow graph to evaluate the impact on the trust of the composite service. Three metrics are introduced to evaluate the impact of these evolution operations. The case study shows how these evolution operations affect the trust of other component services and the composite service which provides a foundation for the evaluation of composite service evolution. ShanShan Qi, Bixin Li, Cuicui Liu, Xiaona Wu, Rui Song 0010 |
APSEC | 5 |
| 2012 | A Preference and Honesty Aware Trust Model for Web ServicesabstractTrust is one of the most critical factors for a service requestor when selecting the best one from a large pool of services. However, existing web service trust models either do not focus on satisfying customer's preference for different quality of service (QoS) attributes, or do not pay enough attention to the impact of malicious ratings on trust evaluation. To address these gaps, a dynamic trust evaluation model considering customer's preference and false ratings is proposed in this paper. The model introduces an approach automatically mining customer's preference from their requirements. The preference is used to determine the weights on each QoS attribute when integrating trust of the multi-dimensional QoS attributes. The local trust of a service for the customer is derived by combining trust of QoS attributes and customer's ratings. Then, the customers are divided into different groups according to their preferences, and the honesty of each group is assessed by filtering out dishonest customers based on a hybrid approach combining rating consistency clustering and average method. Finally, the weight on ratings is dynamically adjusted according to the results of honesty assessment when calculating the global trustworthiness of a service for the user group. The simulation results indicate that the model works well on personalized evaluation of trust, and it can effectively dilute the influence of malicious ratings. Rui Song 0010, Bixin Li, Xiaona Wu, Cuicui Liu, ShanShan Qi |
APSEC | 1 |
| 2012 | Trust-Based Service Composition and OptimizationabstractAs an important method for creating value-added services by composing existing services, Web service composition technology has attracted an increasing attention in recent years. Most current service composition and optimization methods utilize quality of service (QoS) attributes to decide which concrete services to invoke. However, trust which is of critical importance to service composition processes is ignored in these methods. To solve the problem, a trust-based service composition and optimization method is proposed in this paper. First, the trust of service composition is defined in terms of the trust of component service selection processes, composition processes and optimal binding plans. Second, a framework is proposed to guarantee the trust of service composition. In the framework, the trust of component service selection processes is guaranteed by filtration, and the trust of composition processes is guaranteed by interface-based service clustering methods. In order to find a trustworthy binding plan, a trust evaluation method is also included in the framework. Finally, a case study based on real Web services is presented, and the experimental results show that the framework can effectively guarantee the trust of service composition and optimization processes. Xiaona Wu, Bixin Li, Rui Song 0010, Cuicui Liu, ShanShan Qi |
APSEC | 3 |