EDBT 2026 Demo / reviewers in the wild / expert
Christopher J. P. Newton
dblp:121/5010 · also Chris J. P. Newton
· DBLP profile ↗
13ranked-venue papers
0as first author
12since 2021 · last 2025
0000-0003-1262-2192ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 11 · 10 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | An Improved Vector Commitment Construction with Applications to SignaturesabstractAll-but-one Vector Commitments (AVCs) randomly opens all but one of the committed vector values. Typically AVCs are instantiated using Goldwasser-Goldreich-Micali (GGM) trees. Generating these trees comprises a significant computational cost for AVCs due to a large number of hash function calls. Correlated GGM (cGGM) trees have been proposed to halve the number of hash calls and Batched AVCs (BAVCs) using a single GGM tree were integrated in the FAEST signature scheme, which improves efficiency and reduces the signature sizes. This paper proposes BACON, a BAVC with aborts that leverages a single cGGM tree. BACON executes multiple instances of AVC in a single batch and enables an abort mechanism to probabilistically reduce the commitment size. We prove that BACON is secure under the ideal cipher model and the random oracle model. We also discuss the possible application of the proposed BACON and show the theoretical efficiency compared to state-of-the-art. Yalan Wang, Bryan Kumara, Harsh Kasyap, Liqun Chen 0002, Sumanta Sarkar, Christopher J. P. Newton, Carsten Maple, Ugur-Ilker Atmaca |
TrustCom | 6 |
| 2025 | Who Pays Whom? Anonymous EMV-Compliant Contactless Payments
Charles Olivier-Anclin, Ioana Boureanu, Liqun Chen 0002, Christopher J. P. Newton, Tom Chothia, Anna Clee, Andreas Kokkinis, Pascal Lafourcade 0001 |
USENIX Security Symposium | 4 |
| 2025 | AVPEU: anonymous verifiable presentations with extended usabilityabstractAbstract The World Wide Web Consortium (W3C) has established standards for decentralized identities (DIDs) and verifiable credentials (VCs). A DID serves as a unique identifier for an entity, while a VC validates specific attributes associated with the DID holder. To prove ownership of credentials, users generate verifiable presentations (VPs). To enhance privacy, the W3C standards advocate for randomizable signatures in VC creation and zero-knowledge proofs for VP generation. However, these standards face a significant limitation: they cannot effectively verify cross-domain credentials while maintaining anonymity. In this paper, we present Anonymous Verifiable Presentations with Extended Usability (AVPEU), a novel framework that addresses this limitation through the introduction of a notary system. At the technical core of AVPEU lies our proposed randomizable message-hiding signature scheme. We provide both a generic construction of AVPEU and specific implementations based on Boneh–Boyen–Shacham, Camenisch–Lysyanskaya, and Pointcheval–Sanders signature. Our experimental results demonstrate the feasibility of these schemes. Yalan Wang, Liqun Chen 0002, Yangguang Tian, Long Meng, Christopher J. P. Newton |
Comput. J. | 5 |
| 2024 | A New Hash-Based Enhanced Privacy ID Signature Scheme
Liqun Chen 0002, Changyu Dong, Nada El Kassem, Christopher J. P. Newton, Yalan Wang |
PQCrypto (1) | 4 |
| 2024 | VCaDID: Verifiable Credentials with Anonymous Decentralized IdentitiesabstractConcerns about how third parties manage personal information have led to the development of decentralized identities (DIDs) and verifiable credentials (VCs). The World Wide Web Consortium (W3C) working group has been developing standards for DIDs and VCs. In the W3C standards, a DID identifies an entity (a DID holder) and a VC confirms that this DID holder has some associated attributes. A DID holder can obtain many VCs and confirm any number of these VCs to others (verifiers) in verifiable presentations (VPs). In order to keep a holder’s identity and attributes private, it is necessary to achieve anonymous VPs that allows this information to be kept confidential. The W3C working group recommends using randomizable signatures to create VCs with zero-knowledge proofs for this purpose. However, the anonymous VPs provided by the this method are limited that in the real world, credentials in cross domains cannot be universally verified. To overcome this limitation, in this paper, we propose a new scheme, called Verifiable Credentials with anonymous DIDs (VCaDID), which aims to achieve anonymous VPs in cross-domain settings. The main technique in our VCaDID scheme is a ring signature with multiple attributes by hiding a holder’s public key among a ring of holders. In our scheme, we set private keys associated with the holder’s DID and attributes, which allow the holder to anonymously present these credentials in a verifiable way. We also prove that the proposed VCaDID scheme satisfies correctness, anonymity and unforgeability under security assumptions of discrete log and random oracle model. Finally, we implement our scheme to demonstrate its feasibility. Yalan Wang, Liqun Chen 0002, Long Meng, Christopher J. P. Newton |
TrustCom | 4 |
| 2024 | How To Bind A TPM's Attestation Keys With Its Endorsement KeyabstractAbstract A trusted platform module is identified by its endorsement key, while it uses an attestation key to provide attestation services, for example, signing a set of platform configuration registers, providing a timestamp or certifying another of its keys. This paper addresses the problem of how a certificate authority binds the endorsement and attestation keys together. This is necessary for the authority to be able to reliably certify the attestation key. This key binding also enables the authority to revoke the attestation key should the endorsement key be compromised. We study all of the existing solutions and show that they either do not solve the problem or cannot be implemented with a real trusted platform module (or both). We propose a new solution which addresses this problem. We develop a security model for our solution and provide a rigorous security proof under this model. We have also implemented the solution using a real trusted platform module, and our implementation results show that this solution is feasible and efficient. Liqun Chen 0002, Nada El Kassem, Christopher J. P. Newton |
Comput. J. | 3 |
| 2024 | Sphinx-in-the-Head: Group Signatures from Symmetric PrimitivesabstractGroup signatures and their variants have been widely used in privacy-sensitive scenarios such as anonymous authentication and attestation. In this paper, we present a new post-quantum group signature scheme from symmetric primitives. Using only symmetric primitives makes the scheme less prone to unknown attacks than basing the design on newly proposed hard problems whose security is less well-understood. However, symmetric primitives do not have rich algebraic properties, and this makes it extremely challenging to design a group signature scheme on top of them. It is even more challenging if we want a group signature scheme suitable for real-world applications, one that can support large groups and require few trust assumptions. Our scheme is based on MPC-in-the-head non-interactive zero-knowledge proofs, and we specifically design a novel hash-based group credential scheme, which is rooted in the SPHINCS+ signature scheme but with various modifications to make it MPC (multi-party computation) friendly. The security of the scheme has been proved under the fully dynamic group signature model. We provide an implementation of the scheme and demonstrate the feasibility of handling a group size as large as 2 60 . This is the first group signature scheme from symmetric primitives that supports such a large group size and meets all the security requirements. Liqun Chen 0002, Changyu Dong, Christopher J. P. Newton, Yalan Wang |
ACM Trans. Priv. Secur. | 3 |
| 2023 | DRoT: A Decentralised Root of Trust for Trusted Networks
Loganathan Parthipan, Liqun Chen 0002, Christopher J. P. Newton, Yunpeng Li 0001 |
ICICS | 3 |
| 2023 | Hash-Based Direct Anonymous Attestation
Liqun Chen 0002, Changyu Dong, Nada El Kassem, Christopher J. P. Newton, Yalan Wang |
PQCrypto | 4 |
| 2022 | The 5G Key-Establishment Stack: In-Depth Formal Verification and ExperimentationabstractWe formally analyse the security of each 5G authenticated key- establisment (AKE) procedures: the 5G registration, the 5G authentication and key agreement (AKA) and 5G handovers. We also study the security of their composition, which we call the 5GAKE_stack. Our security analysis focuses on aspects of multi-party AKEs that occur in the 5GAKE_stack. We also look at the consequences this AKE (in)security has over critical mobile-networks' objects such as the Protocol Data Unit (PDU) sessions, which are used to bill sub- scribers and ensure quality of service as per their contracts/plans. Rhys Miller, Ioana Boureanu, Stephan Wesemeyer, Christopher J. P. Newton |
AsiaCCS | 4 |
| 2022 | Practical EMV Relay ProtectionabstractRelay attackers can forward messages between a contactless EMV bank card and a shop reader, making it possible to wirelessly pickpocket money. To protect against this, Apple Pay requires a user’s fingerprint or Face ID to authorise payments, while Mastercard and Visa have proposed protocols to stop such relay attacks. We investigate transport payment modes and find that we can build on relaying to bypass the Apple Pay lock screen, and illicitly pay from a locked iPhone to any EMV reader, for any amount, without user authorisation. We show that Visa’s proposed relay-countermeasure can be bypassed using rooted smart phones. We analyse Mastercard’s relay protection, and show that its timing bounds could be more reliably imposed at the ISO 14443 protocol level, rather than at the EMV protocol level. With these insights, we propose a new relay-resistance protocol (L1RP) for EMV. We use the Tamarin prover to model mobile-phone payments with and without user authentication, and in different payment modes. We formally verify solutions to our attack suggested by Apple and Visa, and used by Samsung, and we verify that our proposed protocol provides protection from relay attacks. Andreea-Ina Radu, Tom Chothia, Christopher J. P. Newton, Ioana Boureanu, Liqun Chen 0002 |
SP | 3 |
| 2021 | Direct Anonymous Attestation With Optimal TPM Signing EfficiencyabstractDirect Anonymous Attestation (DAA) is an anonymous signature scheme, which allows the Trusted Platform Module (TPM), a small chip embedded in a host computer, to attest to the state of the host system, while preserving the privacy of the user. DAA provides two signature modes: fully anonymous signatures and pseudonymous signatures. One main goal of designing DAA schemes is to reduce the TPM signing workload as much as possible, as the TPM has only limited resources. In an optimal DAA scheme, the signing workload on the TPM will be no more than that required for a normal signature like ECSchnorr. To date, no scheme has achieved the optimal signing efficiency for both signature modes. In this paper, we propose the first DAA scheme which achieves the optimal TPM signing efficiency for both signature modes. In this scheme, the TPM takes only a single exponentiation to generate a signature, and this single exponentiation can be pre-computed. Our scheme can be implemented using the existing TPM 2.0 commands, and thus is compatible with the TPM 2.0 specification. We benchmarked the TPM 2.0 commands needed for three DAA use cases on an Infineon TPM 2.0 chip, and also implemented the host signing and verification algorithm for our DAA scheme on a laptop with 1.80GHz Intel Core i7-8550U CPU. Our experimental results show that our DAA scheme obtains a total signing time of about 144 ms for either signature mode, while with pre-computation we can obtain a signing time of about 65 ms. Based on our benchmark results for the pseudonymous signature mode, our scheme is roughly$2\times $(resp.,$5\times $) faster than the existing DAA schemes supported by TPM 2.0 in terms of total (resp., online) signing efficiency. Kang Yang 0002, Liqun Chen 0002, Zhenfeng Zhang, Christopher J. P. Newton, Bo Yang 0003, Li Xi |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2020 | Formal Analysis and Implementation of a TPM 2.0-based Direct Anonymous Attestation SchemeabstractDirect Anonymous Attestation (Daa) is a set of cryptographic schemes used to create anonymous digital signatures. To provide additional assurance, Daa schemes can utilise a Trusted Platform Module (Tpm) that is a tamper-resistant hardware device embedded in a computing platform and which provides cryptographic primitives and secure storage. We extend Chen and Li's Daa scheme to support: 1) signing a message anonymously, 2) self-certifying Tpm keys, and 3) ascertaining a platform's state as recorded by the Tpm's platform configuration registers (PCR) for remote attestation, with explicit reference to Tpm2.0 API calls. We perform a formal analysis of the scheme and are the first symbolic models to explicitly include the low-level Tpm call details. Our analysis reveals that a fix pro-posed by Whitefield et al. to address an authentication attack on an Ecc-Daa scheme is also required by our scheme. Developing a fine-grained, formal model of a Daa scheme contributes to the growing body of work demonstrating the use of formal tools in supporting security analyses of cryptographic protocols. We additionally provide and benchmark an open-source C++implementation of this Daa scheme supporting both a hardware and a software Tpm and measure its performance. Stephan Wesemeyer, Christopher J. P. Newton, Helen Treharne, Liqun Chen 0002, Ralf Sasse, Jorden Whitefield |
AsiaCCS | 2 |