EDBT 2026 Demo / reviewers in the wild / expert
Songtao Fu
dblp:215/0694
· DBLP profile ↗
10ranked-venue papers
4as first author
9since 2021 · last 2026
0000-0002-1396-1076ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 6 · 2 first-author · 6 since 2021Systems, architecture and hardware · 2 · 1 first-author · 1 since 2021Security and privacy · 2 · 1 first-author · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | OCEAN: Optional Capability-Based En Route Acknowledgement in Network LayerabstractHigh security and low latency are important in mission-critical data transmission, such as the end-to-end transmission in Industrial IoT (IIoT). However, existing schemes often struggle to simultaneously meet these demanding requirements due to hardware limitations and the lack of a packet lossless forwarding protocol in the network layer data plane. To address this challenge, we propose OCEAN (Optional Capability-based En route Acknowledgement in Network layer). OCEAN includes (1) an in-network caching hardware, which is a programmable Application Specific Integrated Circuit (ASIC) integrated with a Field Programmable Gate Array (FPGA), and (2) a packet lossless forwarding protocol in the network layer data plane. In OCEAN, each packet was generated by an authorized end device, while each en route node verifies the packet, and caches it until receiving the acknowledgment from the next en route node. It incurs negligible latency to packet forwarding when there is no packet loss while retransmitting the packet at the en route node after a short timeout, which reduces the packet forwarding latency. Besides that, the per-packet verification guarantees that the adversary could not subvert the forwarding protocol. Our simulation in the BMv2 environment confirms its functionality, and the hardware implementation demonstrates that it can process packets at line rate with a total processing latency ranging from 2519 ns to 6160 ns, which is negligible in end-to-end transmission. Su Yao, Songtao Fu, Qi Li 0002, Zhuotao Liu, Yinchao Zhang, Ke Xu 0002 |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2025 | PIPE: Identity-Aware Privacy-Enhanced Source and Path Verification for Strengthened Network AccountabilityabstractNetwork-layer security threats have become increasingly sophisticated, exposing significant vulnerabilities in the current Internet architecture. Despite various proposed solutions, the field faces fundamental challenges in balancing user privacy with network security and achieving practical deployment. This paper presents a novel approach called PIPE (Privacy-preserving Identity and Path Enhancement), which leverages a distributed infrastructure of Key Distribution Servers (KDS) to integrate Decentralized Identity (DID) with source and path verification. Our solution binds user identity, address, path, and data while maintaining privacy through encryption and per-hop address transformation. By embedding DID information in address and implementing encrypted path verification, we achieve enhanced network accountability without compromising privacy. Experimental results demonstrate PIPE’s practicality and advantages over existing approaches in terms of deployment flexibility and security guarantees. Our work contributes to the evolution of secure network architectures by balancing accountability requirements with privacy protection while ensuring practical deployability. Jianfeng Guan, Kexian Liu, Su Yao, Ye Qin, Songtao Fu, Ke Xu 0002 |
ICNP | 7 |
| 2025 | Secure Fault Localization in Path Aware NetworkingabstractSecure data forwarding is critical for users to meet their requirements. In this paper, we propose D3 (Demon Detector in Data Plane), a source-driven, secure fault localization mechanism, which empowers the source to localize faulty link in Path Aware Networking, thus circumventing faulty link to guarantee secure data forwarding. D3 utilizes the source to instruct the on-path routers, thus empowering it to detect whether the on-path routers forward the packet as expected. Compared with existing schemes that are difficult to be deployed in practice due to the heavy storage, computation, and communication overhead, D3 offloads most of the on-path router's storage and computation overhead, thus dramatically improving the deployment efficiency. Particularly, the length of the additional packet header in D3 is 2-5 times less than the state-of-the-art mechanisms, thus having a low communication overhead. Besides that, the destination in D3 could keep stateless processing, thus having backward compatibility and eliminating the opportunity for DoS attacks toward a stateful destination. The BMv2 and Barefoot Tofino hardware evaluations show that D3 could achieve high fault localization accuracy and process the packet at line rate. Songtao Fu, Qi Li 0002, Xiaoliang Wang 0004, Su Yao, Xuewei Feng, Xinle Du, Kao Wan, Ke Xu 0002 |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2024 | SR-SL: A Secure and Low-Cost Path Validation Based on SRv6abstractThe authenticity of cloud computing forwarding paths is an important guarantee of Internet security and the foundation of a Path-aware network (PAN). Although related research has achieved remarkable results, designing practical path validation is still challenging due to additional overhead and protocol compatibility. The current rapid development of SRv6 may provide a new opportunity to solve the above problems. In this paper, we propose SR-SL, a new mechanism based on SRv6 that supports forwarding path validation. SR-SL designs low overhead generation and verification for cryptographic labels to sequentially encode path information into the segment list. Routers use the segment list to add and verify labels to ensure the authenticity of the forwarding path. We set up a test bed on BMv2 to evaluate the performance of SR-SL, and the results show that SR-SL can provide a path authenticity guarantee with little additional overhead. Xiaotian Ge, Songtao Fu |
ICC | 3 |
| 2024 | Toward Practical Inter-Domain Source Address ValidationabstractThe Internet Protocol (IP) is the most fundamental building block of the Internet. However, it provides no explicit notion of packet-level authenticity. Such a weakness allows malicious actors to spoof IP packet headers and launch a wide variety of attacks. Meanwhile, the highly decentralized management of Internet infrastructure makes large-scale source address validation challenging in terms of overhead, validity, and flexibility. This paper presents a practical anti-spoofing approach, Source Address Validation Architecture eXternal (SAVA-X). SAVA-X introduces the concept of Address Domain to enable address validation in finer, prefix-level granularity. The address domains are organized in nested hierarchies to provide higher scalability and lower maintenance costs for partial deployment. We implement SAVA-X on commercial backbone routers and the P4 platform. The experiments indicate that the hardware implementation of SAVA-X can achieve 98% throughput on 100 Gbps links and close to the native IP forwarding in per-packet overhead, with less than 10 microseconds additional processing latency. Xiaoliang Wang 0004, Ke Xu 0002, Yangfei Guo, Songtao Fu, Qi Li 0002 |
IEEE/ACM Trans. Netw. | 5 |
| 2023 | MASK: Practical Source and Path Verification Based on Multi-AS-KeyabstractThe source and path verification in Path-Aware Networking considers the two critical issues: (1) end hosts could verify that the network follows their forwarding decisions, and (2) both on-path routers and destination host could authenticate the source of packets and filter the malicious traffic. Unfortunately, the state-of-the-art mechanisms require heavy communication overhead in the network and computation overhead in the router; moreover, it is difficult to meet the dynamic requirements of the end host. We propose a user-driven mechanism, source and path verification based on Multi-AS-Key (MASK). MASK decreases the communication overhead by a short additional packet header and reduces the computation overhead by separating the control and data plane in terms of the cryptographic operation. Furthermore, it utilizes the stateful user to instruct the stateless routers to process the packet with a user-driven policy, thus satisfying the user’s requirements such as detecting the packet drop and replay attack. With the plausible design, the communication overhead for realistic path lengths is 1/2 to 1/10 compared with the state-of-the-art mechanisms. We implement MASK in the BMv2 environment and commodity Barefoot Tofino programmable switch, testify that MASK introduces significantly less overhead than the state-of-the-art mechanisms, and demonstrate that MASK could achieve the verification in the programmable switch at line rate. Songtao Fu, Qi Li 0002, Xiaoliang Wang 0004, Su Yao, Yangfei Guo, Xinle Du, Ke Xu 0002 |
IEEE/ACM Trans. Netw. | 1 |
| 2022 | DIP: unifying network layer innovations using shared L3 core functionsabstractThe IP protocol has made a great contribution to the development of the Internet and has become the narrow waist of the Internet. However, the fixed packet processing of IP hinders the functional expansion and evolution of the Internet. In order to solve the rigidity of the Internet, our community has proposed various new L3 protocols to better support various network functions at the network layer. In this paper, we propose DIP (Dynamic Internet Protocol), a novel primitive to unify these protocols. DIP builds a common network function core shared by these L3 protocols based on a new L3 function core primitive, named Field Operation (FN). With FNs, each standalone L3 protocol can be decomposed into a combination of multiple FNs, and meanwhile it is feasible to compose various FNs to realize new (derived) L3 protocols. We demonstrate the feasibility of DIP by realizing five radically different network layer protocols1: the canonical IP forwarding, NDN [41], XIA [12], OPT [16], and NDN+OPT (a derived L3 protocol combining the merits of both NDN and OPT). We implement a prototype of DIP and evaluate its forwarding performance. Zhuotao Liu, Xiaoliang Wang 0004, Songtao Fu, Ke Xu 0002 |
HotNets | 4 |
| 2022 | D3: Lightweight Secure Fault Localization in Edge CloudabstractIn pursuit of high-performance applications, the cloud is moving out of the data center and towards the edge. Secure data forwarding is critical for the users between the edge and the remote cloud. In this paper, we propose D3 (Demon Detector in Data Plane), a lightweight, secure fault localization mechanism, which can enable the users in the edge cloud to localize faulty links and thus avoid the faulty links to guarantee secure data forwarding along the path to the remote cloud. D3 utilizes the user to instruct the transit routers, thus empowering the user to detect whether the transit routers forward the packet as expected. Compared with existing schemes that are difficult to be deployed in practice due to the incurred heavy storage, computation, and communication overhead, D3 offloads most of the transit router’s storage and computation overhead, thus dramatically improving the deployment efficiency. Particularly, the length of the additional packet header in D3 is 2-5 times less than the state-of-the-art mechanisms, and the extra control packet overhead is ten times less while keeping a little constant storage overhead in the data plane. The evaluations in BMv2 and Barefoot Tofino hardware show that D3 could achieve high fault localization accuracy and efficiency. Songtao Fu, Qi Li 0002, Xiaoliang Wang 0004, Su Yao, Xuewei Feng, Xinle Du, Kao Wan, Ke Xu 0002 |
ICDCS | 1 |
| 2021 | MASK: Practical Source and Path Verification based on Multi-AS-KeyabstractThe source and path verification in path-aware Internet consider the two critical issues: (1) end hosts could verify that their forwarding decisions followed by the network, (2) both intermediate routers and destination host could authenticate the source of packets and filter the malicious traffic. Unfortunately, the current verification mechanism requires validation operations in each router on the path in an inter-domain environment, thus requiring high communication and computation overhead, reducing its usefulness; besides, it is also difficult to meet the dynamic requirements of the end host. Ideally, the verification should be secure and provide the customized capability to meet the end host’s requirements. We propose a new mechanism called source and path verification based on Multi-AS-Key (MASK). Instead of each packet verified and marked at each router on the path, MASK improves the verification by empowering the end hosts to instruct the routers to achieve the verification, thus decreasing the router’s overhead while ensuring security performance to meet the end host’s requirements. With the plausible design, the communication overhead for realistic path lengths is 3–8 times smaller than the state-of-the-art mechanisms. The computation overhead in the routers is 2-5 times smaller. We implement our design in the BMv2 environment and commodity Barefoot Tofino programmable switch, demonstrating that MASK introduces significantly less overhead than the existing mechanisms. Songtao Fu, Ke Xu 0002, Qi Li 0002, Xiaoliang Wang 0004, Su Yao, Yangfei Guo, Xinle Du |
IWQoS | 1 |
| 2016 | Modeling DC circuit breaker in MTDC for wind farms based on delay slope methodabstractIn a multi-terminal high-voltage direct current based on voltage source converter, the proactive hybrid HVDC breaker is an important component in DC grids to isolate a DC fault. From the DC breaker design point, it is crucial to realize a fast fault current breaking. Hybrid HVDC breaker based on delay slope method for breaking signal has more fast action. Especially for overhead lines of DC grid, automatic reclosing control method is adopted in this paper. A wind farm ring topology model, 8-terminal HDC based on voltage source converter, is build on PSCAD/EMTDC simulation platform. Simulations are given to demonstrate effectiveness of the delay slope method and automatic reclosing control strategies. In last, it is pointed out the existing problems in automatic reclosing of Hybrid HVDC breaker. Xunwen Su, Songtao Fu, Jiaoxia Hao, Xiaomeng Kang, Zeping Yu, Rongfeng Yang |
IECON | 2 |