Weikeng Chen

dblp:160/1002 · DBLP profile ↗
← Back
11ranked-venue papers
4as first author
4since 2021 · last 2023
0000-0003-0068-1793ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 6 · 2 first-author · 4 since 2021Computer networks · 2 · 1 first-authorDatabases, data management, data science and information retrieval · 2 · 1 first-authorSoftware engineering, systems software and programming languages · 1
YearPublicationVenuePosition
2023 MPCAuth: Multi-factor Authentication for Distributed-trust Systems
abstract
Systems with distributed trust have attracted growing research attention and seen increasing industry adoptions. In these systems, critical secrets are distributed across N servers, and computations are performed privately using secure multi-party computation (SMPC). Authentication for these distributed-trust systems faces two challenges. The first challenge is ease-of-use. Namely, how can an authentication protocol maintain its user experience without sacrificing security? To avoid a central point of attack, a client needs to authenticate to each server separately. However, this would require the client to authenticate N times for each authentication factor, which greatly hampers usability. The second challenge is privacy, as the client’s sensitive profiles are now exposed to all N servers under different trust domains, which creates N times the attack surface for the profile data.We present MPCAuth, a multi-factor authentication system for distributed-trust applications that address both challenges. Our system enables a client to authenticate to N servers independently with the work of only one authentication. In addition, our system is profile hiding, meaning that the client’s authentication profiles such as her email username, phone number, passwords, and biometric features are not revealed unless all servers are compromised. We propose secure and practical protocols for an array of widely adopted authentication factors, including email passcodes, SMS messages, U2F, security questions/passwords, and biometrics. Our system finds practical applications in the space of cryptocurrency custody and collaborative machine learning, and benefits future adoptions of distributed-trust applications.
Sijun Tan, Weikeng Chen, Ryan Deng, Raluca A. Popa
SP2
2023 HOLMES: Efficient Distribution Testing for Secure Collaborative Learning
Ian Chang, Katerina Sotiraki, Weikeng Chen, Murat Kantarcioglu, Raluca A. Popa
USENIX Security Symposium3
2022 Titanium: A Metadata-Hiding File-Sharing System with Malicious Security
Weikeng Chen, Thang Hoang, Jorge Guajardo, Attila A. Yavuz
NDSS1
2021 Cerebro: A Platform for Multi-Party Cryptographic Collaborative Learning
Wenting Zheng, Ryan Deng, Weikeng Chen, Raluca A. Popa, Aurojit Panda, Ion Stoica
USENIX Security Symposium3
2020 Metal: A Metadata-Hiding File-Sharing System
Weikeng Chen, Raluca A. Popa
NDSS1
2020 TAFC: Time and Attribute Factors Combined Access Control for Time-Sensitive Data in Public Cloud
abstract
The new paradigm of outsourcing data to the cloud is a double-edged sword. On the one hand, it frees data owners from the technical management, and is easier for data owners to share their data with intended users. On the other hand, it poses new challenges on privacy and security protection. To protect data confidentiality against the honest-but-curious cloud service provider, numerous works have been proposed to support fine-grained data access control. However, till now, no schemes can support both fine-grained access control and time-sensitive data publishing. In this paper, by embedding timed-release encryption into Ciphertext-Policy Attribute-based Encryption (CP-ABE), we propose a new time and attribute factors combined access control on time-sensitive data for public cloud storage (named TAFC). Based on the proposed scheme, we further propose an efficient approach to design access policies faced with diverse access requirements for time-sensitive data. Extensive security and performance analysis shows that our proposed scheme is highly efficient and satisfies the security requirements for time-sensitive data storage in public cloud.
Jianan Hong, Kaiping Xue, Yingjie Xue, Weikeng Chen, David S. L. Wei, Nenghai Yu, Peilin Hong
IEEE Trans. Serv. Comput.4
2018 Combining Data Owner-Side and Cloud-Side Access Control for Encrypted Cloud Storage
abstract
People endorse the great power of cloud computing, but cannot fully trust the cloud providers to host privacy-sensitive data, due to the absence of user-to-cloud controllability. To ensure confidentiality, data owners outsource encrypted data instead of plaintexts. To share the encrypted files with other users, ciphertext-policy attribute-based encryption (CP-ABE) can be utilized to conduct fine-grained and owner-centric access control. But this does not sufficiently become secure against other attacks. Many previous schemes did not grant the cloud provider the capability to verify whether a downloader can decrypt. Therefore, these files should be available to everyone accessible to the cloud storage. A malicious attacker can download thousands of files to launch economic denial of sustainability (EDoS) attacks, which will largely consume the cloud resource. The payer of the cloud service bears the expense. Besides, the cloud provider serves both as the accountant and the payee of resource consumption fee, lacking the transparency to data owners. These concerns should be resolved in real-world public cloud storage. In this paper, we propose a solution to secure encrypted cloud storages from EDoS attacks and provide resource consumption accountability. It uses CP-ABE schemes in a black-box manner and complies with arbitrary access policy of the CP-ABE. We present two protocols for different settings, followed by performance and security analysis.
Kaiping Xue, Weikeng Chen, Jianan Hong, Peilin Hong
IEEE Trans. Inf. Forensics Secur.2
2017 A privacy-preserving and real-time traceable power request scheme for smart grid
abstract
Smart grid facilitates reliable and efficient power generation and transmission by integrating information and communication technologies. By collecting users' power demands in advance, the control center (power operator) can adjust the amount of electricity generated to reduce the excess power, which can increase the profit of the power operator. However, on the one hand, user's privacy becomes a critical issue, since it may leak out a user's life habits, which may make user's safety and belongings under threat. On the other hand, the system needs to arm the capability to avoid diverse adversaries' attacks and trace misbehaving users (who request power irresponsibly). In this paper, we propose a privacy-preserving and real-time traceable power request scheme to fulfill the security requirements. We utilize aggregator as a proxy between users and the control center, which verifies the messages and aggregates multiple users' requests together to preserve their privacy. More importantly, this privacy-preserving mechanism has no effect for the control center to whether charge each user, or trace the misbehaving users in real time. The performance analysis shows that our scheme is efficient in terms of computation and storage overhead.
Qingyou Yang, Jianan Hong, Kaiping Xue, Weikeng Chen, Hao Yue 0001
ICC4
2017 Exploring a service-based normal behaviour profiling system for botnet detection
abstract
Effective detection of botnet traffic becomes difficult as the attackers use encrypted payload and dynamically changing port numbers (protocols) to bypass signature based detection and deep packet inspection. In this paper, we build a normal profiling-based botnet detection system using three unsupervised learning algorithms on service-based flow-based data, including self-organizing map, local outlier, and k-NN outlier factors. Evaluations on publicly available botnet data sets show that the proposed system could reach up to 91% detection rate with a false alarm rate of 5%.
Weikeng Chen, Xiao Luo 0002, Nur Zincir-Heywood
IM1
2016 Crowdsourced Query Processing on Microblogs
Weikeng Chen, Zhou Zhao 0001, Xinyu Wang 0020, Wilfred Ng
DASFAA (1)1
2015 Crowd-Selection Query Processing in Crowdsourcing Databases: A Task-Driven Approach
abstract
Crowd-selection is essential to crowdsourcing applications, since choosing the right workers with particular expertise to carry out specific crowdsourced tasks is extremely important. The central problem is simple but tricky: given a crowdsourced task, who is the right worker to ask? Currently, most existing work has mainly studied the problem of crowd-selection for simple crowdsourced tasks such as decision making and sentiment analysis. Their crowd-selection procedures are based on the trustworthiness of workers. However, for some complex tasks such as document review and question answering, selecting workers based on the latent category of tasks is a better solution. In this paper, we formulate a new problem of task-driven crowd-selection for complex tasks. We first develop a Bayesian generative model to exploit "who knows what" for the workers in the crowdsourcing environment. The model provides a principle and natural framework for capturing the latent skills of workers as well as the latent categories of crowdsourced tasks. The inference of the latent skills of workers is based on past resolved crowdsourced tasks with feedback scores. We assume that the feedback scores can illustrate the performance of the workers for the tasks. We then devise a variational algorithm that transforms the latent skill inference with the proposed model into a standard optimization problem, which can be solved efficiently. We verify the performance of our method through extensive experiments on the data collected from three well-known crowdsourcing platforms for question answering tasks such as Quora, Yahoo! Answer and Stack Overflow.
Zhou Zhao 0001, Furu Wei, Ming Zhou 0001, Weikeng Chen, Wilfred Ng
EDBT4