EDBT 2026 Demo / reviewers in the wild / expert
Hongyu Jin 0001
dblp:157/2937-1
· DBLP profile ↗
10ranked-venue papers
8as first author
4since 2021 · last 2025
0000-0003-2022-3976ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 7 · 7 first-author · 3 since 2021Computer networks · 1 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Privacy-enhancing Interleaved Pseudonym Distribution for Vehicular Communication SystemsabstractVehicular Communication Systems (VCSs) enhance safety by enabling communication among vehicles and road-side infrastructure. To provide secure communication and privacy, a Vehicular Public-Key Infrastructure (VPKI) distributes long-term and temporary credentials (pseudonyms) to validate Cooperative Awareness Messages (CAMs) and other communication by registered vehicles. However, improperly designed pseudonym-based privacy techniques are still vulnerable to pseudonym linking based on their issuer, i.e., a specific Pseudonymous Certification Authority (PCA) that signed the pseudonyms in one batch, in the presence of PCAs. As each PCA digitally signs pseudonyms, the presence of distinct PCAs makes linking pseudonyms easier. We propose two strategies, Interleaved Pseudonym Distribution (IPD) and Random Interleaved Pseudonym Distribution (RIPD), to mitigate linking. Multi-PCA collaboration allows distributing interleaved pseudonyms (issued by different PCAs), reducing linkability. To assess our scheme privacy enhancement, a PCAid-based pseudonym linking algorithm is developed utilizing a Kalman filter and road information to track vehicles. Simulation results show that IPD provides a moderate improvement in pseudonym confusion, while RIPD significantly disrupts PCAid-based linking, enhancing vehicle privacy. The proof-of-concept implementation of our scheme shows the efficiency of our scheme, compared to the baseline that a single PCA issues all pseudonyms within one request. Keyao Huang, Hongyu Jin 0001, Panagiotis Papadimitratos |
VTC2025-Fall | 2 |
| 2025 | Accountable, Scalable and DoS-resilient Secure Vehicular CommunicationabstractStandardized Vehicular Communication (VC), mainly Cooperative Awareness Messages (CAMs) and Decentralized Environmental Notification Messages (DENMs), is paramount to vehicle safety, carrying vehicle status information and reports of traffic/road-related events respectively. Broadcasted CAMs and DENMs are pseudonymously authenticated for security and privacy protection, with each node needing to have all incoming messages validated within an expiration deadline. This creates an asymmetry that can be easily exploited by external adversaries to launch a clogging Denial of Service (DoS) attack: each forged VC message forces all neighboring nodes to cryptographically validate it; at increasing rates, easy to generate forged messages gradually exhaust processing resources and severely degrade or deny timely validation of benign CAMs/DENMs. The result can be catastrophic when awareness of neighbor vehicle positions or critical reports are missed. We address this problem making the standardized VC pseudonymous authentication DoS-resilient . We propose efficient cryptographic constructs, which we term message verification facilitators , to prioritize processing resources for verification of potentially valid messages among bogus messages and verify multiple messages based on one signature verification. Any message acceptance is strictly based on public-key based message authentication/verification for accountability , i.e., non-repudiation is not sacrificed, unlike symmetric key based approaches. This further enables drastic misbehavior detection , also exploiting the newly introduced facilitators, based on probabilistic signature verification and cross-checking over multiple facilitators verifying the same message; while maintaining verification latency low even when under attack, trading off modest communication overhead. Our facilitators can also be used for efficient discovery and verification of DENM or any event-driven message , including misbehavior evidence used for our scheme. Even when vehicles are saturated by adversaries mounting a clogging DoS attack, transmitting high-rate bogus CAMs/DENMs, our scheme achieves an average 50 m s verification delay with message expiration ratio less than 1% - a huge improvement over the current standard that verifies every message signature in a First-Come First-Served (FCFS) manner and suffers from having 50% to nearly 100% of the received benign messages expiring. Hongyu Jin 0001, Panagiotis Papadimitratos |
Comput. Secur. | 1 |
| 2024 | Future-proofing Secure V2V Communication against Clogging DoS AttacksabstractClogging Denial of Service (DoS) attacks have disrupted or disabled various networks, in spite of security mechanisms. External adversaries can severely harm networks, especially when high-overhead security mechanisms are deployed in resource-constrained systems. This can be especially true in the emerging standardized secure Vehicular Communication (VC) systems: mandatory message signature verification can be exploited to exhaust resources and prevent validating incoming messages sent by neighboring vehicles, information that is critical, often, for transportation safety. Efficient message verification schemes and better provisioned devices could serve as potential remedies, but existing solutions have limitations. We point out those and identify, challenges to address for scalable and resilient secure Vehicular Communication (VC) systems, and, most notably, the need for integrating defense mechanisms against clogging Denial of Service (DoS) attacks. We take the position that existing secure Vehicular Communication (VC) protocols are vulnerable to clogging Denial of Service (DoS) attacks and recommend symmetric key chain based pre-validation with mandatory signature verification to thwart clogging Denial of Service (DoS) attacks, while maintaining all key security properties, including non-repudiation to enable accountability. Hongyu Jin 0001, Panagiotis Papadimitratos |
ARES | 1 |
| 2024 | Over-the-Air Runtime Wi-Fi MAC Address Re-randomizationabstractMedium Access Control (MAC) address randomization is a key component for privacy protection in Wi-Fi networks. Current proposals periodically change the mobile device MAC addresses when it disconnects from the Access Point (AP). This way frames cannot be linked across changes, but the mobile device presence is exposed as long as it remains connected: all its communication is trivially linkable by observing the randomized yet same MAC address throughout the connection. Our runtime MAC re-randomization scheme addresses this issue, reducing or eliminating Wi-Fi frames linkability without awaiting for or requiring a disconnection. Our MAC re-randomization is practically 'over-the-air': MAC addresses are re-randomized just before transmission, while the protocol stacks (at the mobile and the AP) maintain locally the original connection MAC addresses - making our MAC layer scheme transparent to upper layers. With an implementation and a set of small-scale experiments with off-the-shelf devices, we show the feasibility of our scheme and the potential towards future deployment. Hongyu Jin 0001, Panagiotis Papadimitratos |
WISEC | 1 |
| 2019 | DoS-resilient cooperative beacon verification for vehicular communication systems
Hongyu Jin 0001, Panagiotis Papadimitratos |
Ad Hoc Networks | 1 |
| 2019 | Resilient Privacy Protection for Location-Based Services through DecentralizationabstractLocation-Based Services (LBSs) provide valuable services, with convenient features for mobile users. However, the location and other information disclosed through each query to the LBS erodes user privacy. This is a concern especially because LBS providers can be honest-but-curious , collecting queries and tracking users’ whereabouts and infer sensitive user data. This motivated both centralized and decentralized location privacy protection schemes for LBSs: anonymizing and obfuscating LBS queries to not disclose exact information, while still getting useful responses. Decentralized schemes overcome disadvantages of centralized schemes, eliminating anonymizers, and enhancing users’ control over sensitive information. However, an insecure decentralized system could create serious risks beyond private information leakage. More so, attacking an improperly designed decentralized LBS privacy protection scheme could be an effective and low-cost step to breach user privacy. We address exactly this problem, by proposing security enhancements for mobile data sharing systems. We protect user privacy while preserving accountability of user activities, leveraging pseudonymous authentication with mainstream cryptography. We show our scheme can be deployed with off-the-shelf devices based on an experimental evaluation of an implementation in a static automotive testbed. Hongyu Jin 0001, Panagiotis Papadimitratos |
ACM Trans. Priv. Secur. | 1 |
| 2018 | Expedited Beacon Verification for VANETabstractSafety beaconing is a basic, yet essential component in secure Vehicular Communication systems. Safety beacons, broadcasted periodically, provide real-time vehicle status to surrounding vehicles, which can be used to provide spatial and mobility awareness. However, secure and privacy-preserving beacons incur high computation overhead, especially when the vehicle density is high or in the presence of adversarial nodes. Here, we show through experimental evaluation how to significantly decrease beacon verification delay. Hongyu Jin 0001, Panagiotis Papadimitratos |
WISEC | 1 |
| 2018 | SECMACE: Scalable and Robust Identity and Credential Management Infrastructure in Vehicular Communication SystemsabstractSeveral years of academic and industrial research efforts have converged to a common understanding on fundamental security building blocks for the upcoming vehicular communication (VC) systems. There is a growing consensus toward deploying a special-purpose identity and credential management infrastructure, i.e., a vehicular public-key infrastructure (VPKI), enabling pseudonymous authentication, with standardization efforts toward that direction. In spite of the progress made by standardization bodies (IEEE 1609.2 and ETSI) and harmonization efforts [Car2Car Communication Consortium (C2C-CC)], significant questions remain unanswered toward deploying a VPKI. Deep understanding of the VPKI, a central building block of secure and privacy-preserving VC systems, is still lacking. This paper contributes to the closing of this gap. We present SECMACE, a VPKI system, which is compatible with the IEEE 1609.2 and ETSI standards specifications. We provide a detailed description of our state-of-the-art VPKI that improves upon existing proposals in terms of security and privacy protection, and efficiency. SECMACE facilitates multi-domain operations in the VC systems and enhances user privacy, notably preventing linking pseudonyms based on timing information and offering increased protection even against honest-but-curious VPKI entities. We propose multiple policies for the vehicle-VPKI interactions and two large-scale mobility trace data sets, based on which we evaluate the full-blown implementation of SECMACE. With very little attention on the VPKI performance thus far, our results reveal that modest computing resources can support a large area of vehicles with very few delays and the most promising policy in terms of privacy protection can be supported with moderate overhead. Mohammad Khodaei, Hongyu Jin 0001, Panagiotis Papadimitratos |
IEEE Trans. Intell. Transp. Syst. | 2 |
| 2017 | Resilient privacy protection for location-based services through decentralizationabstractLocation-based Services (LBSs) provide valuable features but can also reveal sensitive user information. Decentralized privacy protection removes the need for a so-called anonymizer, but relying on peers is a double-edged sword: adversaries could mislead with fictitious responses or even collude to compromise their peers' privacy. We address here exactly this problem: we strengthen the decentralized LBS privacy approach, securing peer-to-peer (P2P) interactions. Our scheme can provide precise timely P2P responses by passing proactively cached Point of Interest (POI) information. It reduces the exposure both to the honest-but-curious LBS servers and peer nodes. Our scheme allows P2P responses to be validated with very low fraction of queries affected even if a significant fraction of nodes are compromised. The exposure can be kept very low even if the LBS server or a large set of colluding curious nodes collude with curious identity management entities. Hongyu Jin 0001, Panagiotis Papadimitratos |
WISEC | 1 |
| 2017 | Bloom filter based certificate validation for VANET: posterabstractSecurity and privacy are important properties that have to be considered for the adoption of Vehicular Ad-hoc Networks (VANETs). Short-lived credentials, termed pseudonyms, are used to ensure message integrity and authentication while preserving vehicle (thus, their passengers') privacy. However, this introduces extra communication and computation overhead: pseudonyms have to be attached to the messages and signatures on pseudonyms and messages need to be verified before they can be accepted. In this poster, we are concerned with computation overhead for pseudonym validation. We preload vehicular On-Board Units (OBUs) with a Bloom Filter (BF) to facilitate pseudonym validation while traditional approach (i.e., signature verification on pseudonyms) can still be preserved as a fallback approach. We evaluate our scheme on automotive testbed with a preliminary implementation. Our scheme provides low processing delay for pseudonym validation at a cost of communication overhead for pre-downloading the BF. Hongyu Jin 0001, Panagiotis Papadimitratos |
WISEC | 1 |