EDBT 2026 Demo / reviewers in the wild / expert
Qinghua Wang 0001
dblp:03/6624-1
· DBLP profile ↗
7ranked-venue papers
5as first author
3since 2021 · last 2026
0000-0002-8032-6291ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 5 · 3 first-author · 3 since 2021Computer networks · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | A provider-agnostic security framework for PKI-based electronic identity systems: A Swedish case studyabstractThis article develops a provider-agnostic security framework for public key infrastructure (PKI)-based electronic identity (eID) systems and applies it to two mature Swedish deployments, BankID and Freja eID. We formalize the canonical user journeys—same-device and cross-device authentication and signing—as compact state-machine models, including a middleware variant. From these models, we derive three protocol-level invariants that govern semantically correct execution: freshness of challenges and results, strict session/origin binding, and dynamic linking of user-approved authorization content. We then evaluate how platform features and relying-party integrations enforce these invariants and analyze documented incidents through the same lens. The results show that both ecosystems rely on robust PKI foundations and provide the technical means to satisfy the invariants; real-world harm arises primarily from intent deception, lifecycle abuse, integration weaknesses, and incomplete verifier-side enforcement rather than cryptographic failure. The proposed framework explains these patterns, clarifies which controls are essential, and offers a reusable analytical tool applicable beyond the Swedish context to other PKI-based electronic identity systems. • A provider-agnostic eID operation model is formalized using state machines. • Three security invariants are derived from a structured attacker taxonomy. • A unified threat–invariant–control mapping clarifies end-to-end eID risks. • Real incidents are interpreted through protocol invariants and governance properties, not cryptographic breakage. • The framework generalizes to PKI-based national eID systems and supports future design evaluation. Qinghua Wang 0001, Omar Zarifa, Nedim Kanat |
Comput. Secur. | 1 |
| 2025 | Requirements framework for IoT device authentication using behavioral fingerprintingabstractThe Internet of Things (IoT) has more and more been integrated into our work and life. However, besides the benefits brought by the recent advancements, there is an increasing challenge for securing IoT devices and networks. A common security mechanism is authentication. However, IoT devices are often resource-constrained which make the use of state-of-the-art encryption technologies infeasible. Therefore, researchers are trying to develop lightweight authentication methods. A promising example of this is the use of behavioral device fingerprinting. Still, the remaining problem with this technology is that it is unclear which feature sets are most feasible to implement device fingerprinting schemes in practical systems. In short, the current research body lacks clearly defined requirements. To overcome this issue, this research aims to design a requirements framework for IoT authentication schemes using behavioral device fingerprinting. To do so, Design Science Research is used, incorporating a systematic literature review. In the end, a requirements framework for behavioral device fingerprinting authentication is presented. The proposed framework features 20 requirements in the four categories High-level IoT, Fingerprint sophistication, Machine learning sophistication, and Attack resistance. We have demonstrated the application of the requirements framework in this article. It is believed that the proposed framework will help researchers and practitioners to develop better IoT authentication solutions. • Device fingerprinting. • Requirements framework. • Design science research methodology. Ole Höfener, Qinghua Wang 0001 |
Comput. Secur. | 2 |
| 2021 | Defending wireless communication against eavesdropping attacks using secret spreading codes and artificial interferenceabstractThe broadcast nature of wireless communication makes it intrinsically vulnerable to eavesdropping attacks. This article suggests the using of secret spreading codes (i.e. only a legitimate receiver knows the spreading sequence) and artificial interference (i.e. by intentionally adding noise to the broadcast channel) on countering eavesdropping attacks. We have made a theoretical analysis on the potential performance degradation at the eavesdropper and at the legitimate receiver for a point-to-point wireless communication system using direct-sequence spread spectrum (DSSS) with coherent phase-shift keying (PSK) modulation. We have also proposed a lightweight non-cryptographic secret code generation scheme which leads to low correlation between the spreading codes used at the transmitter and at the eavesdropper. Simulation results confirms the good anti-eavesdropping performance on using the proposed non-cryptographic secret code generation scheme. Simulation results also conform with the theoretical analysis and motivate the using of artificial interference on countering eavesdropping attacks. Qinghua Wang 0001 |
Comput. Secur. | 1 |
| 2013 | Human interactive secure key and identity exchange protocols in body sensor networksabstractA body sensor network (BSN) is typically a wearable wireless sensor network. Security protection is critical to BSNs, since they collect sensitive personal information. Generally speaking, security protection of BSN relies on identity (ID) and key distribution protocols. Most existing protocols are designed to run in general wireless sensor networks, and are not suitable for BSNs. After carefully examining the characteristics of BSNs, the authors propose human interactive empirical channel‐based security protocols, which include an elliptic curve Diffie–Hellman version of symmetric hash commitment before knowledge protocol and an elliptic curve Diffie–Hellman version of hash commitment before knowledge protocol. Using these protocols, dynamically distributing keys and IDs become possible. As opposite to present solutions, these protocols do not need any pre‐deployment of keys or secrets. Therefore compromised and expired keys or IDs can be easily changed. These protocols exploit human users as temporary trusted third parties. The authors, thus, show that the human interactive channels can help them to design secure BSNs. Xin Huang 0005, Bangdao Chen, Andrew Markham, Qinghua Wang 0001, Zheng Yan 0002, A. W. Roscoe 0001 |
IET Inf. Secur. | 4 |
| 2010 | Fair Energy Allocation in Wireless Sensor Networks: Theory and PracticeabstractThis paper deals with the energy allocation in multi-hop wireless sensor networks. Because the traffic loads are not evenly distributed in a multi-hop wireless sensor network, different sensor nodes usually experience different energy consumption rates. We present Routing Independent Fair Energy-Allocation Scheme (RIFES), which allocates the available energy resource to a sensor node according to its pre-estimated traffic load. Because traffic load is the dominating source of energy consumption, RIFES optimizes the network's lifetime by equalizing all individual nodes' expected energy exhaustion times. Due to the fact that a node's real experienced traffic load may differ to its pre-estimated traffic load in practice, it is hard for RIFES to achieve its theoretical optimal performance. To bridge this gap between theory and practice, this paper also presents several distributed routing algorithms, the use of which prolongs the network's lifetime by balancing the real-experienced traffic loads among neighboring nodes. Qinghua Wang 0001 |
GLOBECOM | 1 |
| 2008 | An Effort to Understand the Optimal Routing Performance in Wireless Sensor NetworkabstractWireless sensor network is remarkable for its promising use on human-unattended information collection, such as forest fire monitoring. In order to support efficient communication, many routing algorithms specially designed for such networks have been proposed. However, there is no idea about whether these proposed routing algorithms are already good enough or still have a long way to become "perfect", since there is currently a lack of understanding about the optimal routing performance. This paper makes a progress in the understanding of the optimal routing performance. Metrics here used to measure the routing performance are the network lifetime finally acquired and the total information finally collected. The condition used to judge the network's death is defined by the user's requirement on the guaranteed network information collecting ability. Optimization models based on the metrics and death condition mentioned above are proposed. Experiments show some existing routing proposals already work well when the user's requirement is strict, but few of them satisfy when the user's requirement is loose. Qinghua Wang 0001, Stefan Pettersson |
AINA | 1 |
| 2008 | Sec-SNMP: Policy-based Security Management for Sensor Networks
Qinghua Wang 0001 |
SECRYPT | 1 |