EDBT 2026 Demo / reviewers in the wild / expert
Hong Lei 0001
dblp:20/5237-1
· DBLP profile ↗
14ranked-venue papers
2as first author
12since 2021 · last 2026
0000-0002-6564-1568ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 6 · 2 first-author · 4 since 2021Computer networks · 5 · 5 since 2021Systems, architecture and hardware · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Pontis: A decentralized framework for unifying remote attestation and enabling interoperability between heterogeneous TEEsabstractIn modern decentralized information systems, establishing verifiable trust in remote computing environments has emerged as a critical challenge for secure cross-domain collaboration. Hardware-based Trusted Execution Environments (TEEs) such as Intel SGX and ARM TrustZone offer a promising foundation for addressing this challenge through cryptographically verifiable execution guarantees, but their incompatible Remote Attestation (RA) mechanisms create fundamental barriers to cross-platform trust establishment. Current solutions either focus on single-vendor ecosystems or introduce prohibitive architectural complexity, failing to address the critical need for lightweight, decentralized interoperability. This paper presents Pontis, a decentralized blockchain-based framework that solves unified RA and cross-platform communication challenges for heterogeneous TEEs through three key innovations: (1) a distributed off-chain Coordinator that normalizes vendor-specific attestation protocols, combined with blockchain-anchored decentralized identifiers that provide immutable distributed identities for TEE instances; (2) blockchain-based smart contracts implementing Registration, Attestation, and Management functions for immutable trust status propagation; and (3) secure cross-TEE communication channels built on the Noise protocol framework. Pontis reduces attestation complexity from O ( n 2 ) → O ( n ), achieving up to 99% reduction in required attestations for large-scale deployments. Comprehensive evaluations on heterogeneous TEE platforms, including Intel SGX and ARM TrustZone, demonstrate that Pontis maintains an attestation latency of 60 ms with over 10,000 TEE instances, while establishing a trusted channel between heterogeneous TEEs requires only 5 ms. These results demonstrate the robustness and feasibility of Pontis, establishing a robust foundation for secure, scalable, and flexible cross-platform collaboration in demanding heterogeneous computing environments. Hong Lei 0001, Xinman Luo, Pengxu Shen, Jieren Cheng |
Inf. Process. Manag. | 2 |
| 2025 | BECAAC: A Blockchain and Edge Computing-Assisted Access Control Scheme for Medical Data SharingabstractSecuring the sharing of medical data has become a critical issue in the field of medical informatics. Although existing IoMT-based medical data sharing systems prioritize data security, anonymity, and operational efficiency during transmission, they still exhibit significant shortcomings in preventing unauthorized access and establishing effective accountability mechanisms. Therefore, a solution is urgently needed to ensure fine-grained access control and accountability during data sharing. This paper proposes a novel data sharing system, BECAAC, which is based on blockchain and edge computing. By employing an edge computing-assisted, contract-based access control strategy and proxy re-encryption technology, the system reduces the computational overhead on hospitals and edge nodes while ensuring that only authorized entities can access medical data. Additionally, a blockchain-based verifiable and traceable anonymization scheme has been developed, utilizing group signature technology to ensure patient identity anonymity. By integrating the decentralization, transparency, and immutability features of a consortium blockchain, this approach enhances accountability for malicious behavior. Experiments conducted using Hyperledger Fabric and EdgeCloudSim were performed to evaluate the performance and simulate the proposed solution. The results indicate that BECAAC effectively meets the requirements of real-world medical data sharing environments. Kejie Zhao, Zijian Bao, Hong Lei 0001 |
IEEE Internet Things J. | 4 |
| 2024 | Traceable ring signature schemes based on SM2 digital signature algorithm and its applications in the data sharing scheme
Hong Lei 0001, Qinghao Wang, Ning Lu 0005, Bangdao Chen, Qiuling Yue |
Frontiers Comput. Sci. | 2 |
| 2024 | One IOTA of Countless Legions: A Next-Generation Botnet Premises Design Substrated on Blockchain and Internet of ThingsabstractAlthough botnet had been at the top of the list of main threats to the cyber world for an extended period of time, its harmfulness has been constrained nowadays due to the development of kaleidoscopic network security enforcing tools and people’s increasing awareness. And the underlying technology of the botnet has been stagnant ascribing to many drawbacks such as inadequate protection of the identity of the Botmaster and weak resilience of the botnet’s infrastructure. In this article, we first introduce a new classification of the botnet based on botnets’ underlying network, then briefly analyze the main flaws of the traditional botnet and some looming Blockchain-based botnets, with pros and cons of leveraging Blockchain to construct botnets. Furthermore, we propose one IOTA of countless legions (OICL), a newfangled versatile botnet infrastructure that overcomes the bottlenecks that other contemporaries cannot eliminate. It leverages Blockchain, also known as distributed ledger technology (DLT), to be its premises and uses many advantages of it without paying too many tradeoffs. Also, we invent a whole set of communication protocols for OICL and a novel scheme called Proof of Honest (PoH) to identify the espionage infiltrated into the botnet to further promote the robustness. In addition, we discover and propose a mechanism called collateral damage binding (CDB), which proves that the botnet has it such as OICL is far more robust than those who do not. Performance evaluations show that OICL is effective, more cost-saving, and fast-responding compared with the Bitcoin-based botnets as baselines. Leixiao Li, Hong Lei 0001, Hao Lin 0003, Jianxiong Wan |
IEEE Internet Things J. | 3 |
| 2024 | PACTA: An IoT Data Privacy Regulation Compliance Scheme Using TEE and BlockchainabstractDespite the existence of data privacy regulations, such as the general data protection regulation (GDPR), data leaks in the Internet of Things (IoT) still occur and cause significant harm due to the noncompliance of data users. To address this issue, a notable solution involves recording the process in an open, immutable blockchain and utilizing the trusted execution environment (TEE) for reliable compliance verification. Although substantial progress has been made in designing compliance schemes in recent years, current approaches suffer from various limitations, including compliance incompleteness, regulation faultiness, and privacy leak. This article introduces PACTA, an IoT data privacy regulation compliance scheme that leverages TEE and blockchain technology. In the protocol, PACTA efficiently handles both dynamic and static consent of data owners and utilizes TEE for compliance analysis of requests and processes. By storing encrypted critical data, the blockchain facilitates privacy-preserving audits of the entire compliance process. Additionally, we have designed a challenge–response protocol to address the silent behavior of the TEE. We demonstrate that PACTA effectively enforces regulation compliance while safeguarding privacy. We thoroughly evaluate our implementation’s efficiency and effectiveness using Ethereum and Intel SGX platforms. Hong Lei 0001, Zijian Bao, Ning Lu 0005, Bangdao Chen |
IEEE Internet Things J. | 3 |
| 2024 | Proof of Finalization: A Self-Fulfilling Function of BlockchainabstractBlockchain has been widely used in various industries for providing trustworthy data. On-chain data can be regarded as trusted after it is finalized by blockchain consensus, namely after the data is believed to be immutable. Unfortunately, nodes with poor/isolated network conditions are still susceptible to data spoofing attacks of blockchain view, spawning kinds of severe attacks. For example, a light node newly joining a blockchain network may request the blockchain view from a malicious full node and accept a spoof view, leading to a double spending attack. Besides, a Trusted Execution Environment (TEE), the network stack of which is fully controlled by its host, may be fed spoofed blockchain data as input, undermining the trustworthiness of TEE-based computation by cheating inputs. To resist data spoofing, existing methods rely on a trusted authority to identify trusted data, or timely provide sufficient confirmation blocks for a block b to prove the finalization of b (since the adversary holding less hash power than the honest blockchain node cannot generate the confirmation blocks timely). These methods either suffer the risks caused by centralized trust base or are only PoW-oriented and high-latency. As promising blockchains including Ethereum migrate to energy-saving consensus, e.g., PoS, designing consensus-agnostic approaches against data spoofing becomes an urgent need of the industries. In this paper, we introduce a Proof of Finalization (PoF) problem for proving the finalization of blockchain to prevent data spoofing attacks of blockchain. We also contrive a novel PoF scheme, which leverages the chain quality property of blockchain to establish a trustworthy committee for proof generation. The scheme is chain-agnostic, non-interactive, non-authority-involved, and with negligible latency. Once blockchain data is finalized, the latency of proof generation in our scheme is only 106 milliseconds. Therefore, our scheme paves the way for any system, e.g., light nodes, cross-chain bridges, and layer-2 systems, to read blockchains with various consensus securely. Aixian Deng, Qian Ren, Yingjun Wu, Hong Lei 0001, Bangdao Chen |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2024 | DeCloak: Enable Secure and Cheap Multi-Party Transactions on Legacy Blockchains by a Minimally Trusted TEE NetworkabstractThe crucial blockchain privacy and scalability demand has boosted off-chain contract execution frameworks for years. Some have recently extended their capabilities to transition blockchain states by off-chain multi-party computation while ensuring public verifiability. This new capability is defined as acrfull mpt. However, existing MPT solutions lack at least one of the following properties crucially valued by communities: data availability, financial fairness, delivery fairness, and delivery atomicity. This paper proposes a novel MPT-enabled off-chain contract execution framework, Decloak. Using TEEs, Decloak solves identified properties with lower gas costs and a weaker assumption. Notably, Decloak is the first to achieve data availability and also achieve all of the above properties. This achievement is coupled with its ability to tolerate all-but-one Byzantine parties and TEE executors. Evaluating 10 MPTs in different businesses, Decloak reduces the gas cost of the SOTA, Cloak, by 65.6%. This efficiency advantage further amplifies with an increasing number of MPT’s parties. Consequently, we establish an elevated level of secure and cheap MPT, being the first to demonstrate the feasibility of achieving gas costs comparable to Ethereum transactions while evaluating MPTs. Qian Ren, Yue Li 0037, Yingjun Wu, Hong Lei 0001, Lei Wang 0031, Bangdao Chen |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2023 | OWL: A data sharing scheme with controllable anonymity and integrity for group users
Zijian Bao, Qinghao Wang, Ning Lu 0005, Bangdao Chen, Hong Lei 0001 |
Comput. Commun. | 7 |
| 2022 | Cloak: Transitioning States on Legacy Blockchains Using Secure and Publicly Verifiable Off-Chain Multi-Party ComputationabstractIn recent years, the confidentiality of smart contracts has become a fundamental requirement for practical applications. While many efforts have been made to develop architectural capabilities for enforcing confidential smart contracts, a few works arise to extend confidential smart contracts to Multi-Party Computation (MPC), i.e., multiple parties jointly evaluate a transaction off-chain and commit the outputs on-chain without revealing their secret inputs/outputs to each other. However, existing solutions lack public verifiability and require O(n) transactions to enable negotiation or resist adversaries, thus suffering from inefficiency and compromised security. Qian Ren, Yingjun Wu, Han Liu 0010, Yue Li 0037, Anne Victor, Hong Lei 0001, Lei Wang 0031, Bangdao Chen |
ACSAC | 6 |
| 2022 | Traceable Ring Signature Schemes Based on SM2 Digital Signature Algorithm and Its Applications in the Evidence-Storage System
Qinghao Wang, Ning Lu 0005, Hong Lei 0001 |
BlockSys | 5 |
| 2022 | SorTEE: Service-Oriented Routing for Payment Channel Networks With Scalability and Privacy ProtectionabstractPayment channel networks (PCNs) are emerged as the most widely deployed solution to mitigate the scalability problem of permissionless cryptocurrencies, allowing vast payments to be carried out off-chain. Routing, which finds feasible paths between the senders and receivers, is critical for PCNs. However, existing solutions either fail to achieve high scalability that can maintain low storage/computation/network communication overhead, or they are susceptible to privacy disclosure. In this paper, we propose SorTEE, a service-oriented routing solution for PCNs, which adopts a set of service nodes to alleviate the per-user burden of routing and achieves more comprehensive privacy guarantees than the state-of-the-art by leveraging trusted execution environments (TEEs). SorTEE demands users communicate with the TEE by the secure channel to protect the privacy of transaction value. Then, an oblivious path mechanism is designed to construct redundant paths with the pseudo senders and receivers generated by TEEs to confuse its untrusted controller. Further, we report a novel attack that allows malicious service nodes to drop the valid paths for profit, and design a feedback mechanism to relieve it. Moreover, SorTEE hides the identities of the senders/receivers for the intermediate nodes of payment paths by introducing a novel identity information transfer scheme called encrypted identity chain. Based on security analysis and performance evaluation, our results demonstrate that SorTEE is able to achieve sufficient privacy-preserving payment and low per-user overhead. Qinghao Wang, Zijian Bao, Hong Lei 0001, Han Liu 0010, Bangdao Chen |
IEEE Trans. Netw. Serv. Manag. | 5 |
| 2021 | Demo: Cloak: A Framework For Development of Confidential Blockchain Smart ContractsabstractIn recent years, as blockchain adoption has been expanding across a wide range of domains, e.g., digital asset, supply chain finance, etc., the confidentiality of smart contracts is now a fundamental demand for practical applications. However, while new privacy protection techniques keep coming out, how existing ones can best fit development settings is little studied. Suffering from limited architectural support in terms of programming interfaces, state-of-the-art solutions can hardly reach general developers. In this paper, we proposed the CLOAK framework for developing confidential smart contracts. The key capability of Cloak is allowing developers to implement and deploy practical solutions to multi-party transaction (MPT) problems, i.e., transact with secret inputs and states owned by different parties by simply specifying it. To this end, CLOAK introduced a domain-specific annotation language for declaring privacy specifications and further automatically generating confidential smart contracts to be deployed with trusted execution environment (TEE) on blockchain. In our evaluation on both simple and real-world applications, developers managed to deploy business services on blockchain in a concise manner by only developing CLOAK smart contracts whose size is less than 30% of the deployed ones. Qian Ren, Han Liu 0010, Yue Li 0037, Hong Lei 0001 |
ICDCS | 4 |
| 2020 | SDABS: A Secure Cloud Data Auditing Scheme Based on Blockchain and SGX
Hong Lei 0001, Zijian Bao, Qinghao Wang |
BlockSys | 1 |
| 2020 | A Survey on the Application of SGX in Blockchain Area
Hong Lei 0001, Qinghao Wang, Zijian Bao |
BlockSys | 1 |