Mingping Qi

dblp:209/2036 · DBLP profile ↗
← Back
12ranked-venue papers
12as first author
10since 2021 · last 2026
0000-0001-8118-3723ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 5 · 5 first-author · 5 since 2021Computer networks · 3 · 3 first-author · 3 since 2021Security and privacy · 2 · 2 first-author · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 2 first-author
YearPublicationVenuePosition
2026 VTBSAE: Provably Secure Verifier-Based Password Authenticated Key Exchange for IIoT
abstract
Password-authenticated key exchange (PAKE) has gained widespread adoption in prominent platforms such as iCloud to provide realistic security assurance. It offers robust security by enabling mutual authentication and strong session key establishment between two parties via a low-entropy password. This paper presents an efficient verifier-based PAKE protocol called VTBSAE(Verifier-based Two-Basis Simultaneous Authentication of Equals)based on the well-known SAE protocol, aiming to provide light, reliable, and scalable security assurances for Industrial Internet of Things (IIoT). The primary technological innovation lies in the utilization of two distinct bases over the underlying group to implement the Hash-to-Curve (H2C) function employed in SAE, and transform the symmetric SAE protocol into a verifier-based PAKE protocol, thereby enhancing its resilience against server compromise attacks. Moreover, adopting the widely accepted BPR (Bellare-Pointcheval-Rogaway) security model with further considering the perfect forward secrecy, VTBSAE’s security is formally proved under the standard CDH security assumption. This solid foundation provides VTBSAE with certain security advantages over some existing verifier-based PAKE protocols whose security proofs rely on some stronger security assumptions. VTBSAE can work over both the multiplicative and elliptic curve additive groups. Particularly, in the elliptic curve setting, VTBSAE requires no reliance on the H2C function, which is often challenging to implement securely over the commonly used elliptic curve parameters such as the secp256r1. Therefore, VTBSAE demonstrates significant improvements in ease of secure implementation compared to the existing verifierbased PAKE protocols that rely on the H2C function.
Mingping Qi
IEEE Internet Things J.1
2025 TBSAE: Tightly Secure One-Round SAE Variant for Securing Peer-to-Peer Networks
Mingping Qi, Wei Hu 0008, Yu Tai
IEEE Internet Things J.1
2025 HPQKE: Hybrid Post-Quantum Key Exchange Protocol for SSH Transport Layer From CSIDH
abstract
Secure Shell (SSH) is a robust cryptographic network protocol designed to establish a secure and encrypted connection over potentially insecure networks, which is typically used for remote login and command-line execution on remote systems. As its core foundation, SSH Transport Layer Protocol relies on the classic (Elliptic Curve) Diffie-Hellman ((EC)DH) key exchange protocol to achieve session key establishment, whose security is essentially based on the (EC) discrete logarithm problem ((EC)DLP). However, the classic (EC)DLP problem could be broken using sufficiently powerful quantum computers when it comes to the post-quantum era, which implies that the traditional SSH protocol will be insecure against the quantum computer attacks. To this end, this paper presents a hybrid post-quantum alternative for the SSH Transport Layer Protocol, called as HPQKE, which combines the supersingular isogeny based post-quantum CSIDH (Commutative Supersingular Isogeny Diffie-Hellman) and the classic ECDH key exchange protocols together. The security of each individual key exchange protocol within the presented HPQKE operates independently, ensuring that the overall security of the HPQKE remains at least as robust as the most secure key exchange protocol employed during its key exchange processes. Moreover, we formally prove that if the used MAC scheme is EUF-CMA secure, then (1) HPQKE is a post-quantum secure key exchange protocol if the CSIDH based Gap Computational Diffie-Hellman (CSI-GDH) security assumption holds, and (2) HPQKE is a classically secure key exchange protocol if the traditional GDH security assumption holds. In addition, we provide a prototype implementation for the HPQKE in a real network environment, and the corresponding experimental results intuitively demonstrate its practical feasibility.
Mingping Qi
IEEE Trans. Inf. Forensics Secur.1
2024 Provably Secure Asymmetric PAKE Protocol for Protecting IoT Access
abstract
Pake allows two parties who share a memorable password to securely establish a strong secret key. It has been deployed in many applications around us, such as iCloud service, Wi-Fi access, etc., to provide security assurance for us. In this article, we present a secure and efficient asymmetric PAKE (aPAKE) protocol for protecting the access to the resource-constraint Internet of Things (IoT). Besides the general passive and active attacks, the new aPAKE protocol provides resilience to the offline dictionary attack, and the server compromise attack such that an adversary cannot impersonate the client to the server even if it has compromised the corresponding server and obtained the stored password file. The new aPAKE protocol is detailed in the elliptic curve setting in this article, while it is also compatible with the multiplicative group over a finite field. The security proof for the new aPAKE protocol is carried out in the widely accepted acrshort BPR security model under the basic acrshort CDH security assumption, which implies that our new aPAKE protocol has certain security advantages over some others whose security proofs need to be based on some stronger security assumptions. In addition, the new aPAKE protocol has computational efficiency and ease-of-implementation advantages over some existing aPAKE protocols whose constructions require the use of the hash-to-curve (H2C) function, and the performance evaluation results have definitely shown this fact.
Mingping Qi, Wei Hu 0008
IEEE Internet Things J.1
2024 VSPAKE: Provably secure verifier-based PAKE protocol for client/server model in TLS ciphersuite
Mingping Qi
J. Syst. Archit.1
2024 SAE+: One-Round Provably Secure Asymmetric SAE Protocol for Client-Server Model
abstract
SAE, short for Simultaneous Authentication of Equals, is a password-authenticated key exchange (PAKE) protocol, by which the two involved parties can achieve mutual authentication and derive high-entropy keys via a memorable password. Currently, the SAE protocol has been standardized and integrated into the latest WPA3 (Wi-Fi Protected Access 3) specifications for protecting Wi-Fi network access. Whereas, SAE is a symmetric PAKE protocol unable to resist the server compromise attacks, and it involves explicit key confirmation flows which may be redundant for usage in existing protocols such as the TLS 1.3, etc. So, we naturally wonder that if we can construct a provably secure one-round asymmetric PAKE from the distinguished SAE. This paper affirms this by presenting an efficient asymmetric variant of SAE, called SAE+, and backing it up with a formal security proof under the widely accepted BPR security model. The new SAE+ is designed to enable a single round-trip execution, with the client initiating the communication, making it an ideal fit for integration into IETF protocols such as TLS 1.3. This feature aligns with the requirements set forth in the “Usage of PAKE with TLS 1.3" document. The SAE+ is secure against the off-line dictionary and server compromise attacks, and supports the desired forward secrecy, i.e., compromising the long-term secret password does not compromise the secrecy of the previously established session keys. In addition, the performance evaluation results presented in this paper demonstrate that the new SAE+ has comparable computational efficiency with some existing outstanding PAKE protocols while outperforms many of them in terms of communication flows.
Mingping Qi, Wei Hu 0008, Yu Tai
IEEE Trans. Inf. Forensics Secur.1
2023 TBVPAKE: An efficient and provably secure verifier-based PAKE protocol for IoT applications
Mingping Qi, Zhiyao Cui, Gaowei Liang
J. Syst. Archit.1
2022 Authentication and key establishment protocol from supersingular isogeny for mobile environments
Mingping Qi, Jianhua Chen 0002
J. Supercomput.1
2022 Provably secure post-quantum authenticated key exchange from supersingular isogenies
Mingping Qi, Jianhua Chen 0002
J. Supercomput.1
2021 Secure authenticated key exchange for WSNs in IoT applications
Mingping Qi, Jianhua Chen 0002
J. Supercomput.1
2019 Anonymous biconf/www/WuJZJLHW19 conf/ccis/WuWFZHLDJ18 ometrics-based authentication with key agreement scheme for multi-server environment using ECC
Mingping Qi, Jianhua Chen 0002
Multim. Tools Appl.1
2018 New robust biometrics-based mutual authentication scheme with key agreement using elliptic curve cryptography
Mingping Qi, Jianhua Chen 0002
Multim. Tools Appl.1