Tieyan Li

dblp:20/1256 · DBLP profile ↗
← Back
54ranked-venue papers
16as first author
7since 2021 · last 2025
0000-0003-4688-2697ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 26 · 9 first-author · 2 since 2021Computer networks · 11 · 2 first-author · 2 since 2021Systems, architecture and hardware · 7 · 2 first-author · 2 since 2021Artificial intelligence and machine learning · 2 · 1 first-authorHuman-computer interaction and ubiquitous computing · 2Databases, data management, data science and information retrieval · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1
YearPublicationVenuePosition
2025 IB-SC: Simplify Key Management to Enable Quick Start for Short-session Path Validation
abstract
In the current Internet architecture, path validation protocols enable the source host to accurately trace the forwarding path of packets, thereby preventing degradation in the quality and security of network services. However, these protocols typically rely on Public Key Infrastructure (PKI), which can theoretically result in a storage overhead of at least 64 PB. To address this issue, we propose an Identity-Based Path Validation Protocol (IB-SC). This protocol leverages a trusted third party equipped with a public-private key pair to distribute identity keys to network nodes. The identities of these nodes, along with the public key of the third party, are used to validate packet signatures. Furthermore, we designed a Source Commitment (SC) mechanism that commits to parameters of future packets to further enhance the performance of the IB-SC protocol. Evaluation results demonstrate that the IB-SC protocol eliminates the overhead associated with PKI and session key management. Compared to the Atomos protocol, which provides similar security levels, IB-SC reduces the signature space overhead by 73.4%, the packet construction and processing delay by 8.4% and 62.1%.
Keji Miao, Xinghai Wei, Jie Yuan 0001, Tieyan Li
ICDCS8
2025 CCRPS: Customized cross-domain routing with privacy preservation and stable quality-of-experience based on deep reinforcement learning
Zheng Yan 0002, Tieyan Li
Inf. Sci.4
2025 B5G-NFM: Blockchain-Based 5G Network Function Management With Enhanced Security and Privacy
abstract
Within the 5G Service-Based Architecture (SBA), the prevalent centralized frameworks, particularly those managing public key certificates and Network Function (NF) services, face significant security and privacy vulnerabilities due to their reliance on centralized Certificate Authorities (CAs) and Network Repository Functions (NRFs). This centralization in current 5G standards poses two critical issues. One is the risk of single points of failure associated with CAs and NRFs. The other is a substantial risk of privacy leakage in cross-domain NF access authorization. These issues underscore the demand for decentralized NF management with enhanced security and privacy. However, existing related schemes still suffer from such drawbacks as poor security and privacy, low efficiency, and a lack of automation in the management of NF certificates. In this paper, we propose B5G-NFM, a pioneering Blockchain-based 5G Network Function Management scheme designed to bolster security and privacy. B5G-NFM integrates a blockchain middleware network function, a decentralized protocol for managing NF public key certificates, and a decentralized mechanism for NF service discovery coupled with a privacy-preserving NF access authorization protocol. Our thorough security and performance assessment verifies that B5G-NFM not only meets its security and privacy goals, but also aligns with efficiency demand, marking a substantial progress in strengthening 5G network infrastructure.
Shufan Fei, Zheng Yan 0002, Haomeng Xie, Tieyan Li
IEEE Trans. Netw.6
2024 DePTVM: Decentralized Pseudonym and Trust Value Management for Integrated Networks
abstract
Evaluating and sharing user equipment (UE) trust across multiple network domains can greatly support security and trust management of future integrated heterogeneous networks. But the dilemma between identity privacy preservation and trust evaluation efficacy causes a big challenge in pseudonym and trust value management. Most existing approaches either rely on a trusted third party (TTP) and non-collusive parties, or deploy trusted execution environments (TEEs). They cannot be applied directly into a trustless heterogeneous network environment, where network domains do not trust with each other and it is hard to setup a fully trusted party. In this article, we propose DePTVM, a decentralized pseudonym and trust value management scheme for integrated heterogeneous networks, where different network operators jointly maintain a list of$< $pseudonym, trust value$>$pairs by employing verifiable shuffling and trust obfuscation based on blockchain in order to support anonymous trust evaluation and ensure pseudonym unlinkability. We analyze DePTVM with respect to correctness, unforgeability, anonymity and unlinkability, and evaluate its performance through simulations. Experimental results show that trust synchronization can be achieved across domains within 9 seconds with our experimental settings and the time taken by the most complex operation (i.e., verifiable shuffling) of operator agent increases linearly with the scale of maintained list. Analysis and experimental results imply DePTVM's potential in practical applications.
Gao Liu, Zheng Yan 0002, Tieyan Li
IEEE Trans. Dependable Secur. Comput.5
2023 CustTest: An Effective Testbed for Testing Customized Routing in Integrated Heterogeneous Networks
abstract
With the rapid development of the internet and the increasing demand for communication, customized routing has become one of the hot research topics in future network. In order to better meet various communication requirements, it is necessary to test and evaluate existing customized routing algorithms to optimize and explore better customized algorithms. However, existing research on customized routing simulation testing cannot provide a customized routing testbed that supports universality, stability, efficiency, and reliability to test and evaluate different customized routing algorithms. To address this issue, we proposes a testbed called CustTest. CustTest is designed based on Software Defined Network (SDN) and Network Simulator 3 (NS3), and consists of two sub platforms: a customized routing calculation platform and a customized routing simulation platform. The customized routing calculation platform is used to calculate customized routes and distribute routing tables. This platform can not only flexibly deploy different customized routing algorithms, but also calculate customized routes based on user needs and convert these routes into customized routing tables. The customized routing simulation platform can effectively evaluate the performance of different customized routing algorithms using statistical analysis tools in NS3. We ensure the stability, efficiency, and reliability of CustTest by adding a pool structure and daemons. In addition, we conduct functional and performance tests on CustTest to demonstrate its ability to effectively execute customized routing calculations and its excellent performance in high concurrency environments, as well as the effectiveness of testing the performance of different customized routing algorithms.
Xiaoxuan Xie, Zheng Yan 0002, Tieyan Li
ICPADS5
2023 XAuth: Secure and Privacy-Preserving Cross-Domain Handover Authentication for 5G HetNets
abstract
Fifth generation (5G) networks are highly heterogeneous, with ultradense base stations (BSs), due to the low penetration of millimeter waves and the availability of different access technologies. However, the continuous heterogeneity and densification of 5G networks pose great challenges to network security, especially for user mobility support. In the process of user handover between BSs or between different network domains, user access authentication and security session establishment are far riskier compared to 4G networks. On the one hand, the overhead of handover authentication increases significantly as handovers become more frequent in an ultradense network. On the other hand, the differentiation of security schemes in heterogeneous networks (HetNets) poses a big challenge to handover authentication. Successfully designing a secure, privacy preserving, and efficient handover authentication protocol for heterogeneous and ultradense 5G networks would substantially expand the prospects of future 5G network applications. Although numerous solutions (e.g., challenge-response-based, public key cryptography-based, physical-layer information-based, and blockchain-based solutions) have been proposed to solve the cross-domain handover authentication problem, most of them surfer from security and privacy vulnerabilities and unreasonable performance overhead. In this article, we propose XAuth, a secure and privacy-preserving authentication protocol for both intradomain and interdomain handover in 5G HetNets based on blockchain. The proposed protocol can achieve mutual authentication, key agreement between user equipment (UE) and target network, and is characterized by forward secrecy, backward secrecy, user anonymity, and conditional privacy preservation. Formal security analysis and comprehensive performance evaluation demonstrate the security and effectiveness of the proposed protocol.
Zheng Yan 0002, Tieyan Li
IEEE Internet Things J.5
2022 Towards Secure and Trustworthy Flash Loans: A Blockchain-Based Trust Management Approach
Yining Xie, Xin Kang 0001, Tieyan Li, Cheng-Kang Chu
NSS3
2016 Authenticated CAN Communications Using Standardized Cryptographic Techniques
Zhuo Wei, Yanjiang Yang, Tieyan Li
ISPEC3
2015 Automatic Accident Detection and Alarm System
abstract
Accident detection and alarm system is very important to detect possible accidents or dangers for the peoples using their mobile devices while walking, i.e., distracted walking. In this paper, we introduce an automatic accident detection and alarm system, called AutoADAS, which is fully implemented and tested on the real mobile devices. The proposed system can be activated either manually or automatically when user walks. Under the manual mode, user activates the system before distracted walking while under the automatic mode, a "user behaviour profiling" module is used to recognize (distracted) walking behaviours and an "object detection" module is activated. Using image processing and camera field of view (FOV), the distance and angle between the user and detected objects are estimated and then applied to identify whether any potential accidents can happen. The "accident analysis and prediction" module includes: temporal alarm that inputs the user's walking speed and distance with respect to the detected objects and outputs temporal accident prediction; spatial alarm that inputs the user's walking direction and angle with respect to the detected objects and outputs spatial accident prediction. Once the proposed system positively predicts a potential accident, the "alarm and suggestion" module alerts the user with text, sound or vibration.
Zhuo Wei, Swee-Won Lo, Tieyan Li, Jialie Shen 0001, Robert H. Deng
ACM Multimedia4
2012 Data synchronization with conflict resolution for RFID-based track and trace
abstract
In an RFID-assisted track and trace information network, the same set of data may be stored in distributed locations. Data conflicts occur when the values of distributed data copies are modified locally with different values causing data inconsistency. In order to restore data consistency, the values of distributed data copies have to be synchronized to the same value by resolving the conflicts. The conventional conflict resolutions do not consider the unique characteristics of RFID data and therefore are not able to maximize the benefit of information users or may even provide erroneous resolution result. In this paper, a data synchronization method with conflict resolution accommodated to RFID applications is proposed. The method resolves the conflicts based on multiple RFID data attributes and takes the dependent relationship between data into account. Simulations confirm the efficiency of the algorithm.
Yintai Ao, Xiao Xue Jian, NengSheng Zhang, Xiao Wendong, Tieyan Li
ETFA7
2011 A software-based root-of-trust primitive on multicore platforms
abstract
Software-based root-of-trust has been proposed to overcome the disadvantage of hardware-based root-of-trust, which is the high cost in deployment and upgrade (when vulnerabilities are discovered). However, prior research on software-based root-of-trust only focuses on uniprocessor platforms. The essential security properties of such software-based root-of-trust, as analyzed and demonstrated in our paper, can be violated on multicore platforms. Since multicore processors are becoming increasingly popular, it is imperative to explore the feasibility of software-based root-of-trust on them.
Qiang Yan 0001, Jin Han 0002, Yingjiu Li, Robert H. Deng, Tieyan Li
AsiaCCS5
2011 Secure and Practical Key Distribution for RFID-Enabled Supply Chains
Tieyan Li, Yingjiu Li, Guilin Wang
SecureComm1
2011 Analyzing a Family of Key Protection Schemes against Modification Attacks
abstract
Protecting cryptographic keys in hardware devices is challenging. In this work, we reinvestigate a family of key protection schemes proposed by Fung, Golin and Gray (2001), which use permutations to protect keys stored in Electrically Erasable Programmable Read-Only Memory (EEPROM). Our analysis discovers vulnerabilities in the use of mathematical permutations. Specifically, we successfully identify two practical attacks-batch card attack and relative probing attack-which allow an adversary to discover the secret key stored in the EEPROM. Contrary to the claims of Fung et al., these attacks are realizable with a relatively small number of probes. Moreover, we examine the rationale of their security assumptions, which are mainly based on the modification attack described by Anderson and Kuhn (1997), and conclude that recent advances in hardware security (w.r.t. both attacks and countermeasures) suggest a stronger adversary model on designing such secure devices.
Tieyan Li, Guilin Wang
IEEE Trans. Dependable Secur. Comput.1
2010 Quasi-Linear Cryptanalysis of a Secure RFID Ultralightweight Authentication Protocol
Pedro Peris-Lopez, Julio César Hernández Castro, Raphael C.-W. Phan, Juan Tapiador, Tieyan Li
Inscrypt5
2010 Vulnerability analysis of RFID protocols for tag ownership transfer
Pedro Peris-Lopez, Julio César Hernández Castro, Juan Tapiador, Tieyan Li, Yingjiu Li
Comput. Networks4
2009 RFID privacy: relation between two notions, minimal condition, and efficient construction
abstract
Privacy of RFID systems is receiving increasing attention in the RFID community. Basically, there are two kinds of RFID privacy notions: one based on the indistinguishability of two tags, denoted as ind-privacy, and the other based on the unpredictability of the output of a protocol, denoted as unp-privacy. In this paper, the definition of unp-privacy is refined and the relation between the two notions is clarified: it is proven that ind-privacy is weaker than unp-privacy. Moreover, the minimal (necessary and sufficient)condition on RFID tags to achieve unp-privacy is determined. It is shown that if an RFID system has strong (or weak) unp-privacy then the computational power of an RFID tag can be used to construct a pseudorandom function family provided that the RFID system is complete and sound. On the other hand, if each tag is able to compute a pseudorandom function, then the tags can be used to construct an RFID system with strong (or weak) unp-privacy. In this sense, a pseudorandom function family is the minimal requirement on an RFID tag's computational power for enforcing strong RFID system privacy. Finally, a new RFID protocol is proposed to satisfy the minimal requirement, which also outperforms the state-of-the-art RFID protocols in terms of computational cost and communication overhead.
Changshe Ma, Yingjiu Li, Robert H. Deng, Tieyan Li
CCS4
2009 Weaknesses in Two Recent Lightweight RFID Authentication Protocols
Pedro Peris-Lopez, Julio César Hernández Castro, Juan Tapiador, Tieyan Li, Jan C. A. van der Lubbe
Inscrypt4
2009 A Solution for Integrated Track and Trace in Supply Chain based on RFID & GPS
abstract
The RFID and positioning system technologies are the key enablers for logistics supply chain visibility and tracking. While RFID is useful for inventory and material handling processes in warehouses, as soon as the RFID-tagged goods leave the warehouses, one often lose track of them until the next loading docks. In-between the sending and receiving points, there is often no tracking of the cargo which may be at risk of missing, off-loading and delay especially if the cargo is critical or perishable. The positioning system such as GPS (Global Positioning System) is usually used to track the vehicle; however it only provides a geographical location without associating business process info. The present research targets at a total solution architecture for seamless, global wide, track and trace system for logistics supply chain using an integrated RFID and positioning system technologies. The research involves development of a new solution for track and trace using both RFID and GPS, integrated information management models and web-based services. It can integrate RFID events with geographical location information and associate them with the cargo, so that the cargo can be seamlessly tracked and traced.
Eng Leong Tan, Eng Wah Lee, Tieyan Li
ETFA4
2009 Enabling Secure Secret Updating for Unidirectional Key Distribution in RFID-Enabled Supply Chains
Shaoying Cai, Tieyan Li, Changshe Ma, Yingjiu Li, Robert H. Deng
ICICS2
2009 Ensuring Dual Security Modes in RFID-Enabled Supply Chain Systems
Shaoying Cai, Tieyan Li, Yingjiu Li, Robert H. Deng
ISPEC2
2009 Attacks and improvements to an RIFD mutual authentication protocol and its extensions
abstract
In WiSec'08, Song and Mitchell proposed an RFID mutual authentication protocol. Song also extended this protocol for RFID tag ownership transfer. These two protocols are designed to have the most security properties in the literature. We discover that, however, the mutual authentication protocol is vulnerable to both tag impersonation attack and reader impersonation attack, which enable an adversary to impersonate any legitimate reader or tag. We also discover that the ownership transfer protocol is vulnerable to a de-synchronization attack, which prevents a legitimate reader from authenticating a legitimate tag, and vice versa. We analyze the vulnerabilities of these protocols and propose our revisions to eliminate the vulnerabilities with comparable storage and computational requirements.
Shaoying Cai, Yingjiu Li, Tieyan Li, Robert H. Deng
WISEC3
2009 Practical attacks on a mutual authentication scheme under the EPC Class-1 Generation-2 standard
Pedro Peris-Lopez, Tieyan Li, Julio César Hernández Castro, Juan Tapiador
Comput. Commun.2
2008 A Security and Performance Evaluation of Hash-Based RFID Protocols
Tong-Lee Lim, Tieyan Li, Yingjiu Li
Inscrypt2
2008 Secure RFID Identification and Authentication with Triggered Hash Chain Variants
abstract
In this paper, we propose two RFID identification and authentication schemes based on the previously proposed triggered hash chain scheme by Henrici and Muller. The schemes are designed to mitigate the shortcomings observed in the triggered hash chain scheme and to ensure privacy preserving identification, tag-reader mutual authentication, as well as forward-privacy in the case of RFID tags that have been compromised. The first scheme uses a challenge-response mechanism to defend against an obvious weakness of the triggered hash chain scheme. The second scheme uses an authenticated monotonic counter to defend against a session linking attack that the first scheme is vulnerable to. We compare the level of security offered by our proposed schemes against other previous schemes and find that the schemes perform well, while keeping within reasonable overheads in terms of computational, storage and communication requirements.
Tong-Lee Lim, Tieyan Li, Tao Gu 0001
ICPADS2
2008 Randomized Bit Encoding for Stronger Backward Channel Protection in RFID Systems
abstract
In this paper, we introduce a randomized bit encoding scheme that can strengthen the privacy protection on RFID tags. This scheme is used together with the backward channel protection method proposed by Choi and Roh (2006), which serves to protect the unique identifier of an RFID tag from disclosure to close-range eavesdroppers. Choi and Roh's method faces the 'same-bit' problem, in which some bits of the unique identifier could be disclosed, thereby revealing critical information. Our proposed scheme alleviates the 'same-bit' problem to a negligible level. Furthermore, we propose an enhanced system model that can protect the unique tag identifier from disclosure not only against eavesdroppers, but against unauthorized interrogators as well. A metric based on entropy was defined and used to measure the amount of protection offered by the scheme. A method to construct an optimal randomized n-bit encoding scheme was also described. In addition, theoretical analysis and simulations were conducted, which show that the proposed encoding scheme provides significant improvement (achieving almost twice the entropy) over no encoding.
Tong-Lee Lim, Tieyan Li, Sze-Ling Yeo
PerCom2
2008 Exposing an effective denial of information attack from the misuse of EPCglobal standards in an RFID authentication scheme
abstract
In this paper, we expose a denial of information attack that is possible due to the misuse of the kill password (specified under the EPC Class-1 Gen-2 standard [1]) in a previously proposed RFID tag-reader mutual authentication scheme [2]. We show how a passive eavesdropper can obtain useful information by monitoring the authentication session involving a target tag and correlating the information received. By repeating the process over a few authentication sessions, the eavesdropper can collect enough information about the kill password to launch a successful attack to kill and disable the tag. From our simulation analysis, we find that the attack can be carried out effectively using only three to five eavesdropped sessions in most cases. In addition, we discuss the implications of this attack and describe a few other weaknesses that we have observed in the scheme.
Tong-Lee Lim, Tieyan Li
PIMRC2
2008 Employing Lightweight Primitives on Low-Cost RFID Tags for Authentication
abstract
Radio frequency identification (RFID) systems have been aggressively deployed in a variety of applications. RFID security and privacy issues have been intensively studied in the research field, of which the authentication between RFID reader and tag is the fundamental theme. Most of the existing authentication protocols draw assumptions on classic cryptographic primitives. However, for extremely resource constraint RFID tags, only lightweight primitives can be incorporated. In this paper, we propose an RFID mutual authentication protocol employing ultra-lightweight mathematic primitives to achieve secure tag/reader authentication. The proposed scheme is secure in sense of tag anonymity, man-in-the-middle resistance, and forgery prevention that are shown in our analysis. The scheme is also efficient due to fast calculation on reduced hardware implementation.
Tieyan Li
VTC Fall1
2008 Flexible Privacy Protection for RFID Tags via Selective Identifier Masking
abstract
In this paper, we propose a selective identifier masking scheme to prevent eavesdropping or unauthorized reading of the unique identifier of RFID tags. In our system, we differentiate between tags that require privacy protection (private tags) and tags that do not require protection (public tags). Under an environment whereby private and public tags co-exist, the proposed scheme uses an active RFID device to selectively transmit a secret mask when a tag identifier is reported to a reader. This induces bit collisions between the tag identifier and the mask. An eavesdropper or an unauthorized interrogator would not be able to resolve the collided bits without knowledge of the secret mask. Hence, the tag identifier is protected against disclosure. Simulations were conducted to investigate the overhead incurred under the scheme. In addition, theoretical analyses were carried out to examine the 'same-bit' problem and its effects on the scheme. In general, we find that our proposed scheme is simple, practical and secure under a realistic threat model as compared to other similar approaches.
Tong-Lee Lim, Tieyan Li
WCNC2
2008 A cross-layer framework for privacy enhancement in RFID systems
Tong-Lee Lim, Tieyan Li, Sze-Ling Yeo
Pervasive Mob. Comput.2
2008 The security and improvement of an ultra-lightweight RFID authentication protocol
abstract
Abstract It is very challenging on designing cryptographically strong security functions that can be incorporated into low‐cost radio frequency identification (RFID) tags. Some RFID authentication protocols were proposed using only ultra‐lightweight primitives, while the security of them must be scrutinized before being put forth into any real application. In this paper, we present two effective attacks, namelyde‐synchronization attackandfull‐disclosure attack, against an efficient ultra‐lightweight RFID mutual authentication protocol: LMAP 2 , which is recently proposed by Peris‐Lopezet al. These active attacks are so serious as they cannot only disable the authentication capability of an RFID tag by destroying synchronization between the tag and the RFID reader, but also disclose all secret values stored in the tag. We point out the design flaws of the protocol and based on that, we improve the protocol with a stateful variant (SLMAP). The improved protocol is more secure in sense of tag anonymity, man‐in‐the‐middle (MITM) resistance, and forgery prevention as shown in our analysis, and is more compact due to reduced operations and memory usage on implementing such a tag. Copyright © 2008 John Wiley & Sons, Ltd.
Tieyan Li, Robert H. Deng, Guilin Wang
Secur. Commun. Networks1
2007 Vulnerability Analysis of EMAP-An Efficient RFID Mutual Authentication Protocol
abstract
In this paper, we analyze the security vulnerabilities of EMAP, an efficient RFID mutual authentication protocol recently proposed by Peris-Lopez et al. (2006). We present two effective attacks, a de-synchronization attack and a full-disclosure attack, against the protocol. The former permanently disables the authentication capability of a RFID tag by destroying synchronization between the tag and the RFID reader. The latter completely compromises a tag by extracting all the secret information stored in the tag. The de-synchronization attack can be carried out in just round of interaction in EMAP while the full-disclosure attack is accomplished across several runs of EMAP. We also discuss ways to counter the attacks
Tieyan Li, Robert H. Deng
ARES1
2007 Addressing the Weakness in a Lightweight RFID Tag-Reader Mutual Authentication Scheme
abstract
A lightweight radio frequency identification (RFID) tag-reader mutual authentication scheme was recently proposed as an improvement over the original authentication protocol specified under the EPC Class 1 Generation 2 UHF RFID Protocol Standard (otherwise known as the "EPC Gen2" standard in short). The improved scheme seeks to protect the access password of the RFID tag against exposure to adversaries. In this paper, we show the weakness in this scheme by launching an attack that effectively exposes the access password. Thereafter, we propose some possible fixes to the scheme to protect it against the attack. We also present some experiment results, which show that the fixed schemes provide greater resistance against exposure of the access password. Based on insights gained from this work, we find that designing a secure authentication scheme by relying only on the minimal features available on an RFID tag is an extremely challenging task. Furthermore, we also stress on the need to put a proposed scheme through stringent tests to ascertain its effectiveness and resistance against attacks.
Tong-Lee Lim, Tieyan Li
GLOBECOM2
2007 Resilient Aggregation Scheme for Confidential Sensor Reports
abstract
Aggregating sensor reports can significantly reduce sensor network traffics, but to provide confidentiality to these reports might disable meaningful aggregation. This paper tackles the problem by proposing a resilient aggregation scheme RAS that achieves 2-level aggregation at cluster and network respectively. Cluster aggregation collects local sensing reports, then authenticates and encrypts the aggregated report. Encrypted reports, while traversing the network to base station, are further processed by network aggregators. Upon receiving an encrypted report, a network aggregator matches it with the stored keywords and then processes the report based on certain policies such as forwarding to the next hop, updating it or simply dropping it on detecting duplicates. The reports are only decrypted at their destinations. We ensure the confidentiality of the reports, as the intermediate aggregators learn nothing about them except several encrypted keywords. We analyze the resilience and overhead of the RAS scheme with the simulation results showing that the scheme is resilient against node compromise attack with reasonable performance overhead. Our analysis show that the scheme is secure, resilient and efficient.
Tieyan Li, Yongdong Wu
ICC1
2007 Security Analysis of Two Ultra-Lightweight RFID Authentication Protocols
Tieyan Li, Guilin Wang
SEC1
2007 Adaptive Stream Authentication for Wireless Multimedia Communications
abstract
Wireless communications typically feature narrow-bandwidth, error-prone and are more vulnerable than the wired counterparts. Numerous packet based stream authentication schemes are proposed for authenticating stream transmitted over erasure wireless channel. However, by fixing the packets in transmission, any packet manipulation will cause authentication failure. In this paper, we assume a more flexible scenario where a gateway, between a producer and a receiver, is able to make adaptation operations over a stream to better fit in the wireless channel. Our adaptive scheme enables packet manipulation by committing the changes, while previous schemes are simply unapplicable. We elaborate the adaptive authentication scheme based on layered structure of a video stream as well as its encoding, packing, amortizing and verifying methods in this paper. The security is analyzed in terms of authentication probability, in which higher authentication rate (95%) is achieved with less overhead per packet. The performance analysis show that our scheme reduces more than 56% of the overhead per packet compared with that of packet based schemes.
Tieyan Li, Yongdong Wu
WCNC1
2006 Preventing Web-Spoofing with Automatic Detecting Security Indicator
Fang Qi, Feng Bao 0001, Tieyan Li, Weijia Jia 0001, Yongdong Wu
ISPEC3
2006 More on Shared-Scalar-Product Protocols
Huafei Zhu, Feng Bao 0001, Tieyan Li
ISPEC3
2006 Privacy-Preserving Shared-Additive-Inverse Protocols and Their Applications
Huafei Zhu, Tieyan Li, Feng Bao 0001
SEC2
2006 An Efficient Scheme for Encrypted Data Aggregation on Sensor Networks
abstract
It is an open problem of how to protect the traffics and at the same time, to support In-network processing in sensor networks. This paper tackles the problem by proposing an efficient model of categorizing encrypted data transmitted on sensor networks. An aggregator, an intermediate sensor node in our setting, is embedded with a set of searching in encrypted format. Upon receiving an encrypted message it matches the message with the keywords and then processes the message based on certain policies such as forwarding the original message to the next hop updating it and forwarding or simply dropping it on detecting duplicates. The messages are encrypted before being sent out and decrypted only at their destination. Although the intermediate classifiers can categorize the messages they learn nothing about the encrypted messages except several encrypted keywords even the statistic information. The secure and efficient aggregation SEA scheme uses Bloom filter to further reduce transmission cost. The performance analysis shows that the computational cost and communication cost are well balanced.
Tieyan Li, Yongdong Wu, Huafei Zhu
VTC Spring1
2006 Video stream authentication in lossy networks
abstract
It is well known that packets may be lost when video stream is transmitted over wireless network. To authenticate real time multicast streams with less overhead but at higher probabilities, most of previous stream authentication schemes insert packet hashes into the packet bodies explicitly. The present scheme enables to remove the packet hashes from the packet overhead in lossy networks. It encodes the packet data with single encoding operation and only encapsulates the parity symbols into the packets overhead. Thus, it reduces the communication overhead as well as encoding time
Yongdong Wu, Tieyan Li
WCNC2
2005 Multi-Source Stream Authentication Framework in Case of Composite MPEG-4 Stream
Tieyan Li, Huafei Zhu, Yongdong Wu
ICICS1
2005 Provably secure anonymous identification protocols for ad-hoc access structures
abstract
Anonymous routing protocols must be equipped with secure anonymous identification protocols for ad-hoc access, otherwise, successive nodes cannot he convinced that the request messages are from a specified set in which each node will provide service for path discovery requests. In this paper, we study anonymous identification schemes in the setting where each participant generates its public key and maintains the correspondent secret key independently. The presented scheme is efficient as we separate soundness and honest verifier zero-knowledge from the hardness of any problem. The security of our construction can be rigorously proved by simply assuming that each challenge string is chosen uniformly at random by the honest verifier. Finally, we provide alternative construction by reducing the 3-move protocol to 2-move protocol assuming that the RSA problem is hard.
Huafei Zhu, Tieyan Li
PIMRC2
2005 Protecting Group Dynamic Information in Large Scale Multicast Groups
Yongdong Wu, Tieyan Li, Robert H. Deng
SEC2
2005 Sequential aggregate signatures for wireless routing protocols
abstract
Sequential aggregate signature, first introduced and formalized by A. Lysyanskaya et al. (see EUROCRYPT 2004, p.74-90, 2004), is emerging as a useful tool to ensure routing security and at the same time to improve performance. We propose a new mechanism to construct sequential aggregate signatures based on the cipher block chaining (CBC) mode, which is different from previous known results. We then construct an efficient sequential aggregate signature scheme and show that our construction is provably secure in the random oracle paradigm, assuming that the RSA problem is hard. Finally, we propose an interesting aggregate routing protocol for wireless ad hoc networks as an immediate application of our protocol.
Huafei Zhu, Feng Bao 0001, Tieyan Li, Yongdong Wu
WCNC3
2004 Flexible Verification of MPEG-4 Stream in Peer-to-Peer CDN
Tieyan Li, Yongdong Wu, Di Ma 0001, Huafei Zhu, Robert H. Deng
ICICS1
2004 Dynamic Access Control for Multi-privileged Group Communications
Di Ma 0001, Robert H. Deng, Yongdong Wu, Tieyan Li
ICICS4
2004 Highly reliable trust establishment scheme in ad hoc networks
Kui Ren 0001, Tieyan Li, Zhiguo Wan, Feng Bao 0001, Robert H. Deng, Kwangjo Kim
Comput. Networks2
2003 Trust on Web Browser: Attack vs. Defense
Tieyan Li, Yongdong Wu
ACNS1
2003 A-peer: An Agent Platform Integrating Peer-to-Peer Network
abstract
Peer-to-Peer (p2p), as an emerging technology, is exerting huge influence on various application scenarios. Meanwhile, agents, assisting applications in traditional paradigm with intelligent ways, have to fit in this new trend. Observing the potential benefits of combining agent and p2p technologies, we propose a novel platform- "A-peer" in our approach. A-peer is an agent based secure p2p platform which empowers agents to be deployed in p2p environment. In this paper, we define the agent properties and mainly describe its protocol design, essentially agent transmission protocol, agent discovery protocol and agent messaging protocol. We also discuss the security aspect of the platform. Our implementation is based on Aglets system [2] and JXTA platform [1]. A-peer could be efficient for agent based p2p programming for distributed computing, decentralized collaboration, information searching and retrieval, and E-business.
Tieyan Li, Zhi-Gang Zhao, Si-Zhen Yo
CCGRID1
2003 A Novel Two-Level Trust Model for Grid
Tieyan Li, Huafei Zhu, Kwok-Yan Lam
ICICS1
2003 Secure Route Structures for the Fast Dispatch of Large-Scale Mobile Agents
Yan Wang 0002, Chihung Chi, Tieyan Li
ICICS3
2003 Efficient Key Assignment Scheme for Mobile Agent Systems
abstract
Agent security is always a key concern to many mobile agent systems such as distributed intrusion detection systems (DIDS), where an attacker might turn to the mobile agent directory server if he fails to locate the critical IDS hosts/agents. Previous work on mobile agent security (e.g. Volker and Mehrdad's scheme, 1998) often suffers from large code size of the agent and the high computational cost. In this paper, we would like to address these two issues with a new RSA-based key assignment scheme. Both the details of the scheme and its implementation are given. Our analysis shows that not only the above two issues are improved significantly, but the scheme also provides agent's adaptability through dynamic key management and access control strategy.
Wai-Meng Chew, Chihung Chi, Tieyan Li
ICTAI3
2001 A Secure Group Solution for Multi-Agent EC System
abstract
Mobile agent technology applied into EC is facing many problems. Security should be the first concern. But in large scale multi-agent systems, the most challenging problems encountered are locating and communicating of these autoprocessing agents. Some approaches have used several different methods to solve these problems. But unfortunately, they were not satisfied either for their complexity, poor performance or their lack of applicability. In our approach, we propose a secure group communication solution toward the security, locating and communication problems. We differentiated the ”Agent-Based” Multicast concept from the traditional ”Host-Based” Multicast. We then described the requirements for providing secure group services and introduce the key distribution method. A cryptographic method is complemented for further protect the agents. Finally, we analyzed the security and performance issues and conclude our solution.
Tieyan Li, Kwok-Yan Lam
IPDPS1
2000 A Secure Route Structure for Information Gathering Agent
Tieyan Li, Chuk-Yang Seng, Kwok-Yan Lam
PRIMA1