Liqun Chen 0002

dblp:22/150-2 · DBLP profile ↗
← Back
112ranked-venue papers
34as first author
35since 2021 · last 2025
0000-0003-2680-4907ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 83 · 28 first-author · 27 since 2021Applied, interdisciplinary, general and emerging computing · 7 · 1 first-author · 5 since 2021Systems, architecture and hardware · 6 · 1 since 2021Databases, data management, data science and information retrieval · 6 · 1 first-author · 1 since 2021Computer networks · 5 · 2 first-author · 1 since 2021Software engineering, systems software and programming languages · 2Theory of computation · 2 · 1 first-authorArtificial intelligence and machine learning · 1 · 1 first-authorHuman-computer interaction and ubiquitous computing · 1
YearPublicationVenuePosition
2025 Attribute-Based Key Exchange with Optimal Efficiency
Liqun Chen 0002, Long Meng, Mark Manulis, Yangguang Tian
CANS1
2025 SPARK: Secure Privacy-Preserving Anonymous Swarm Attestation for In-Vehicle Networks
abstract
In recent years, vehicles have evolved into cyberphysical autonomous systems that rely on sensor data from various sources within the vehicle. With the emergence of Vehicle-to-Everything (V2X) technology, the scope of the collaborative functionality in vehicles is now expanding to the inter-vehicular level. To support these modern capabilities, the complexity of the Electronic Control Units (ECUs) and the In-Vehicle Network (IVN) architecture is rapidly increasing. As a result, IVNs are now swarms of devices that communicate safety-critical data. Unfortunately, current vehicular networks lack security, opening the path to numerous cyberattacks. A typical solution for verifying the integrity of multiple devices is swarm attestation. However, in a typical IVN setting, only the Original Equipment Manufacturer (OEM) has access to the legitimate configuration of the ECUs and does not want to disclose this information due to intellectual property and security concerns. Therefore, state- of-the-art swarm attestation schemes, which do not provide privacy guarantees, are unsuitable for IVNs.This paper proposes Secure Privacy Preserving Anonymous Swarm Attestation for In-Vehicle Networks (SPARK), which builds upon a novel group signature scheme to enable privacy-preserving, anonymous, and traceable swarm attestation of IVNs. We validate SPARK through a proof-of-concept implementation using a standardized hardware Trusted Platform Module (TPM 2.0) and representative hardware platforms. The results demonstrate the real-world applicability of SPARK.
Wouter Hellemans, Nada El Kassem, Md Masoom Rabbani, Edlira Dushku, Liqun Chen 0002, An Braeken, Bart Preneel, Nele Mentens
EuroS&P5
2025 PRIVÉ: Towards Privacy-Preserving Swarm Attestation
abstract
In modern large-scale systems comprising multiple heterogeneous devices, the introduction of swarm attestation schemes aims to alleviate the scalability and efficiency issues of traditional single-Prover and single-Verifier attestation. In this paper, we propose PRIVÉ, a privacy-preserving, scalable, and accountable swarm attestation scheme that addresses the limitations of existing solutions. Specifically, we eliminate the assumption of a trusted Verifier, which is not always applicable in real-world scenarios, as the need for the devices to share identifiable information with the Verifier may lead to the expansion of the attack landscape. To this end, we have designed an enhanced variant of the Direct Anonymous Attestation (DAA) protocol, offering traceability and linkability whenever needed. This enables PRIVÉ to achieve anonymous, privacy-preserving attestation while also providing the capability to trace a failed attestation back to the compromised device. To the best of our knowledge, this paper presents the first Universally Composable (UC) security model for swarm attestation accompanied by mathematical UC security proofs, as well as experimental benchmarking results that highlight the efficiency and scalability of the proposed scheme.
Nada El Kassem, Wouter Hellemans, Ioannis Siachos, Edlira Dushku, Stefanos Vasileiadis, Dimitrios S. Karas, Liqun Chen 0002, Constantinos Patsakis, Thanassis Giannetsos
SECRYPT7
2025 An Improved Vector Commitment Construction with Applications to Signatures
abstract
All-but-one Vector Commitments (AVCs) randomly opens all but one of the committed vector values. Typically AVCs are instantiated using Goldwasser-Goldreich-Micali (GGM) trees. Generating these trees comprises a significant computational cost for AVCs due to a large number of hash function calls. Correlated GGM (cGGM) trees have been proposed to halve the number of hash calls and Batched AVCs (BAVCs) using a single GGM tree were integrated in the FAEST signature scheme, which improves efficiency and reduces the signature sizes. This paper proposes BACON, a BAVC with aborts that leverages a single cGGM tree. BACON executes multiple instances of AVC in a single batch and enables an abort mechanism to probabilistically reduce the commitment size. We prove that BACON is secure under the ideal cipher model and the random oracle model. We also discuss the possible application of the proposed BACON and show the theoretical efficiency compared to state-of-the-art.
Yalan Wang, Bryan Kumara, Harsh Kasyap, Liqun Chen 0002, Sumanta Sarkar, Christopher J. P. Newton, Carsten Maple, Ugur-Ilker Atmaca
TrustCom4
2025 Who Pays Whom? Anonymous EMV-Compliant Contactless Payments
Charles Olivier-Anclin, Ioana Boureanu, Liqun Chen 0002, Christopher J. P. Newton, Tom Chothia, Anna Clee, Andreas Kokkinis, Pascal Lafourcade 0001
USENIX Security Symposium3
2025 AVPEU: anonymous verifiable presentations with extended usability
abstract
Abstract The World Wide Web Consortium (W3C) has established standards for decentralized identities (DIDs) and verifiable credentials (VCs). A DID serves as a unique identifier for an entity, while a VC validates specific attributes associated with the DID holder. To prove ownership of credentials, users generate verifiable presentations (VPs). To enhance privacy, the W3C standards advocate for randomizable signatures in VC creation and zero-knowledge proofs for VP generation. However, these standards face a significant limitation: they cannot effectively verify cross-domain credentials while maintaining anonymity. In this paper, we present Anonymous Verifiable Presentations with Extended Usability (AVPEU), a novel framework that addresses this limitation through the introduction of a notary system. At the technical core of AVPEU lies our proposed randomizable message-hiding signature scheme. We provide both a generic construction of AVPEU and specific implementations based on Boneh–Boyen–Shacham, Camenisch–Lysyanskaya, and Pointcheval–Sanders signature. Our experimental results demonstrate the feasibility of these schemes.
Yalan Wang, Liqun Chen 0002, Yangguang Tian, Long Meng, Christopher J. P. Newton
Comput. J.2
2025 PRISM: PSI and Voronoi diagram based Automated Exposure Notification with location privacy
Jiezhen Tang, Hui Zhu 0001, Liqun Chen 0002, Fengwei Wang, Hui Li 0006
J. Netw. Comput. Appl.3
2025 Multi-client functional encryption for set intersection with non-monotonic access structures in federated learning
Ruyuan Zhang, Jinguang Han, Liqun Chen 0002, Yiheng Wei
J. Syst. Archit.3
2025 Privacy-Preserving Decentralized Signature-Based Access Control
Jinguang Han, Liqun Chen 0002, Willy Susilo
IEEE Trans. Dependable Secur. Comput.2
2025 Highly-Secure and Efficient Certificateless AKA for Vehicular Access Networks
abstract
This paper proposes a highly secure and efficient certificateless authenticated key agreement (CL-AKA) scheme, which is particularly apt for deployment in vehicular access networks, as it improves not only communication but also computational efficiency in real-world scenarios where multiple vehicles concurrently access the internet via a limited number of base stations. The cornerstone of our CL-AKA scheme stems from an improved certificateless signature (CLS). Specifically, we re-design the key structure of CLS, allowing signers to locally maintain a single public key (instead of two public keys in most state-of-the-art works) as well as two private keys after key generation. With such a novel key structure, the proposed CLS facilitates pairing-free signature generation and verification and realizes efficient batch verification on the verifier’s end. Moreover, a signer only needs to disseminate one public key to verifiers, thus saving communication bandwidth. In addition to the advanced CLS, we develop a CL-AKA scheme that efficiently handles network access requests from multiple vehicles at base stations. To resist physical attacks and achieve highly secure key management, we further integrate the Physical Unclonable Function (PUF) into our scheme. Formal security proofs demonstrate that the proposed CL-AKA scheme is secure against conventional attacks and preserves common security properties such as forward secrecy and session key independence. Finally, we develop a proof-of-concept prototype and conduct extensive experiments to demonstrate the efficiency and practicality of our scheme.
Suhui Liu, Cheng Huang 0001, Liqun Chen 0002, Liquan Chen, Jiguo Yu
IEEE Trans. Intell. Transp. Syst.3
2024 Reconstructing Chameleon Hash: Full Security and the Multi-Party Setting
abstract
Chameleon hash (CH) function differs from a classical hash function in a way that a collision can be found with the knowledge of a trapdoor secret key. CH schemes have been used in various cryptographic applications such as sanitizable signatures and redactable blockchains. In this work, we reconstruct CH to ensure advanced security and usability. Our contributions are four-fold. First, we propose the first CH scheme, which supports full security, meaning the inclusion of both full indistinguishability and full collision-resistance. These two properties are required in the strongest CH security model in the literature. We achieve this by our innovative design of removing the CH public key during the computation of the hash value. Second, we investigate the security of CH in the multi-party setting and introduce the new properties of claimability and deniability under this setting. Third, we present and implement two instantiations of our CH scheme: an ECC-based one and a post-quantum lattice-based one. Our implementation demonstrates their practicality. Finally, we discuss the possible use cases in the blockchain.
Kwan Yin Chan, Liqun Chen 0002, Yangguang Tian, Tsz Hon Yuen
AsiaCCS2
2024 FABESA: Fast (and Anonymous) Attribute-Based Encryption under Standard Assumption
abstract
Attribute-Based Encryption (ABE) provides fine-grained access control to encrypted data and finds applications in various domains. The practicality of ABE schemes hinges on the balance between security and efficiency. The state-of-the-art adaptive secure ABE scheme, proven to be adaptively secure under standard assumptions (FAME, CCS'17), is less efficient compared to the fastest one (FABEO, CCS'22) which is only proven secure under the Generic Group Model (GGM). These traditional ABE schemes focus solely on message privacy. To address scenarios where attribute value information is also sensitive, Anonymous ABE (A2BE) ensures the privacy of both the message and attributes. However, most A2BE schemes suffer from intricate designs with low efficiency, and the security of the fastest key-policy A2BE (proposed in FEASE, USENIX'24) relies on the GGM.
Long Meng, Liqun Chen 0002, Yangguang Tian, Mark Manulis
CCS2
2024 Owl: An Augmented Password-Authenticated Key Exchange Scheme
Feng Hao 0001, Samiran Bag, Liqun Chen 0002, Paul C. van Oorschot
FC (2)3
2024 A New Hash-Based Enhanced Privacy ID Signature Scheme
Liqun Chen 0002, Changyu Dong, Nada El Kassem, Christopher J. P. Newton, Yalan Wang
PQCrypto (1)1
2024 VCaDID: Verifiable Credentials with Anonymous Decentralized Identities
abstract
Concerns about how third parties manage personal information have led to the development of decentralized identities (DIDs) and verifiable credentials (VCs). The World Wide Web Consortium (W3C) working group has been developing standards for DIDs and VCs. In the W3C standards, a DID identifies an entity (a DID holder) and a VC confirms that this DID holder has some associated attributes. A DID holder can obtain many VCs and confirm any number of these VCs to others (verifiers) in verifiable presentations (VPs). In order to keep a holder’s identity and attributes private, it is necessary to achieve anonymous VPs that allows this information to be kept confidential. The W3C working group recommends using randomizable signatures to create VCs with zero-knowledge proofs for this purpose. However, the anonymous VPs provided by the this method are limited that in the real world, credentials in cross domains cannot be universally verified. To overcome this limitation, in this paper, we propose a new scheme, called Verifiable Credentials with anonymous DIDs (VCaDID), which aims to achieve anonymous VPs in cross-domain settings. The main technique in our VCaDID scheme is a ring signature with multiple attributes by hiding a holder’s public key among a ring of holders. In our scheme, we set private keys associated with the holder’s DID and attributes, which allow the holder to anonymously present these credentials in a verifiable way. We also prove that the proposed VCaDID scheme satisfies correctness, anonymity and unforgeability under security assumptions of discrete log and random oracle model. Finally, we implement our scheme to demonstrate its feasibility.
Yalan Wang, Liqun Chen 0002, Long Meng, Christopher J. P. Newton
TrustCom2
2024 FEASE: Fast and Expressive Asymmetric Searchable Encryption
Long Meng, Liqun Chen 0002, Yangguang Tian, Mark Manulis, Suhui Liu
USENIX Security Symposium2
2024 How To Bind A TPM's Attestation Keys With Its Endorsement Key
abstract
Abstract A trusted platform module is identified by its endorsement key, while it uses an attestation key to provide attestation services, for example, signing a set of platform configuration registers, providing a timestamp or certifying another of its keys. This paper addresses the problem of how a certificate authority binds the endorsement and attestation keys together. This is necessary for the authority to be able to reliably certify the attestation key. This key binding also enables the authority to revoke the attestation key should the endorsement key be compromised. We study all of the existing solutions and show that they either do not solve the problem or cannot be implemented with a real trusted platform module (or both). We propose a new solution which addresses this problem. We develop a security model for our solution and provide a rigorous security proof under this model. We have also implemented the solution using a real trusted platform module, and our implementation results show that this solution is feasible and efficient.
Liqun Chen 0002, Nada El Kassem, Christopher J. P. Newton
Comput. J.1
2024 Privacy-Preserving Transformation Used in Verifiable (Outsourced) Computation, Revisited
abstract
Recently, a privacy-preserving technique called Privacy-Preserving Matrix Transformation (PPMT) is widely used to construct efficient privacy-preserving Verifiable (outsourced) Computation (VC) protocols for specific functions. This technique is first proposed and formalized by Salinas et al. in 2015, and it enjoys provable privacy and high efficiency. Although it seems that Salinas et al.'s PPMT scheme and the further modified scheme are elegant, we still need to take a step back and precisely discuss whether the PPMT schemes are suitable choices for VC protocols. Since Salinas et al. gave two concrete PPMT schemes to achieve the matrix-related VC in data protection and proved that their schemes are private (in terms of indistinguishability), and Zhou et al. devised a new type of PPMT scheme for the same purpose, we focus on exploring privacy of these three types of PPMT schemes. In this paper, to achieve our object, we first propose the concept of a linear distinguisher and two constructions of the linear distinguisher algorithms. In particular, the linear distinguisher is a polynomial-time algorithm employed by an adversary to explore the privacy property of a cryptographic primitive. Then, we take these three PPMT schemes (including Salinas et al.'s original work, Yu et al.'s generalization and Zhou et al.'s variant) as targets and analyze their privacy property by letting an adversary make use of our linear distinguisher algorithms. The analysis results show that all these three types of transformations do not hold privacy even against passive eavesdropping (i.e., a ciphertext-only attack), and subsequently, the privacy-preserving VC protocols, based on any of these PPMT schemes, also do not hold the same privacy.
Liang Zhao 0020, Liqun Chen 0002
IEEE Trans. Dependable Secur. Comput.2
2024 Privacy-Preserving Decentralized Functional Encryption for Inner Product
abstract
To support secure data mining and privacy-preserving computation, partial access and selective computation on encrypted data are desirable. Functional encryption (FE) is a new paradigm of public-key encryption and allows authorized users to compute specific functions on encrypted data without knowing the data. However, in some FE schemes, a trusted central authority (CA) is required to generate secret keys for users according to the description of functions. In this paper, to reduce trust on the CA and protect users' privacy, a privacy-preserving decentralised FE for inner product (PPDFEIP) scheme is proposed where multiple authorities co-exist and work independently without any interaction. Especially, to resist collusion attacks, all secret keys of the same user are tied to his/her global identifier (GID), but authorities cannot know any information of the GID even if they collaborate. We formalize the definition and security model of our PPFEIP scheme, and propose a concrete construction. Furthermore, the proposed scheme is implemented and evaluated. Finally, the security of our PPDFEIP scheme is reduced to well-known complexity assumptions. The novelty is to reduce trust on the CA, protect users' privacy and enable authorized users to compute inner product on encrypted data without compromising confidentiality.
Jinguang Han, Liqun Chen 0002, Aiqun Hu, Liquan Chen, Jiguo Li 0001
IEEE Trans. Dependable Secur. Comput.2
2024 On the Privacy of Elementary Matrices Masking-Based Verifiable (Outsourced) Computation
abstract
Privacy-preserving Verifiable (outsourced) Computation (PVC) for face recognition is a significant research topic in the information security community. Recently, an efficient elementary matrices masking-based PVC protocol for face recognition has been published in IEEE Transactions on Dependable and Secure Computing [2]. In this paper, we analyze the privacy property of this protocol, and demonstrate that the output distribution of the problem generation algorithm in this protocol is not computationally indistinguishable from the uniform distribution over a matrix set, which breaks the original consequence (see Theorem 1). We introduce a formal definition of a privacy model for a PVC protocol and prove that the targeted PVC protocol does not hold privacy under this model. We then present our experimental results to support our theoretical analyses.
Liang Zhao 0020, Liqun Chen 0002
IEEE Trans. Dependable Secur. Comput.4
2024 Integrated and Accountable Data Sharing for Smart Grids With Fog and Dual-Blockchain Assistance
abstract
Combining a fog layer to aggregate and process data for smart grids is a straightforward approach, yet it inevitably leads to trust issues and audition difficulty. Most existing data-sharing architectures did not consider the copious meter–fog communication and fog–cloud bulk data transmission simultaneously, or they relay the trustworthiness of the fog nodes on a single center. In this article, we design a meter–fog–cloud-blockchain data-sharing architecture for smart grids where the fog nodes are not only data relay stations but also semitrusted local data processing points, and the dual blockchains are responsible for device key management and data integrity audit, respectively. Moreover, a certificateless aggregate signcryption between fog and smart meters is designed, and the data sharing between servers is based on an authenticated key agreement mechanism to achieve optimal efficiency overall. Detailed security proofs are demonstrated and performance results show the practicality and efficiency of our data-sharing scheme.
Suhui Liu, Liquan Chen, Liqun Chen 0002, Jianchang Lai
IEEE Trans. Ind. Informatics3
2024 Sphinx-in-the-Head: Group Signatures from Symmetric Primitives
abstract
Group signatures and their variants have been widely used in privacy-sensitive scenarios such as anonymous authentication and attestation. In this paper, we present a new post-quantum group signature scheme from symmetric primitives. Using only symmetric primitives makes the scheme less prone to unknown attacks than basing the design on newly proposed hard problems whose security is less well-understood. However, symmetric primitives do not have rich algebraic properties, and this makes it extremely challenging to design a group signature scheme on top of them. It is even more challenging if we want a group signature scheme suitable for real-world applications, one that can support large groups and require few trust assumptions. Our scheme is based on MPC-in-the-head non-interactive zero-knowledge proofs, and we specifically design a novel hash-based group credential scheme, which is rooted in the SPHINCS+ signature scheme but with various modifications to make it MPC (multi-party computation) friendly. The security of the scheme has been proved under the fully dynamic group signature model. We provide an implementation of the scheme and demonstrate the feasibility of handling a group size as large as 2 60 . This is the first group signature scheme from symmetric primitives that supports such a large group size and meets all the security requirements.
Liqun Chen 0002, Changyu Dong, Christopher J. P. Newton, Yalan Wang
ACM Trans. Priv. Secur.1
2023 DRoT: A Decentralised Root of Trust for Trusted Networks
Loganathan Parthipan, Liqun Chen 0002, Christopher J. P. Newton, Yunpeng Li 0001
ICICS2
2023 BAHS: A Blockchain-Aided Hash-Based Signature Scheme
Yalan Wang, Liqun Chen 0002, Long Meng, Yangguang Tian
ISPEC2
2023 Hash-Based Direct Anonymous Attestation
Liqun Chen 0002, Changyu Dong, Nada El Kassem, Christopher J. P. Newton, Yalan Wang
PQCrypto1
2023 Achieving Higher Level of Assurance in Privacy Preserving Identity Wallets
abstract
Recent advances in Decentralized Digital Identity solutions, revolving around the use of Verifiable Credentials towards identity sovereignty, are centered around Identity Wallets for ensuring that identity data control remains with the user. However, such schemes still lack the capabilities to provide higher Level of Assurance (LoA) guarantees, for identity verification, which restricts their full potential. In this paper, we design and showcase DOOR; a library that enables Identity Wallets to leverage hardware Roots-of-Trust (RoT) for binding user authentication factors to HW-based keys, thus, allowing for both proof of (User) identity and (Wallet) integrity, bringing them in alignment with emerging regulations and standards that require higher LoA for services (e.g. eIDAS). At the same time, we make sure that privacy-enhancing properties like selective-disclosure are fully supported in order to make the Wallet compliant with privacy regulations (e.g. GDPR). To achieve all the above, we have designed an enhanced variant of Attribute-based Direct Anonymous Attestation (DAA-A) crypto protocol for offering anonymity, unlinkability, and unforgeability, while being the first to offer strong guarantees on the Wallet’s integrity when constructing attribute attestations. We formally prove the security properties of DOOR, offered by the underlying crypto primitives used to enable selective disclosure of attributes, by describing their construction while also benchmarking their computational footprint and comparing them with other widespread cryptographic mechanisms (adopted by the standards) in terms of performance, size of the associated verifiable presentations while safeguarding user anonymous authentication and unlinkability.
Benjamin Larsen, Nada El Kassem, Thanassis Giannetsos, Ioannis Krontiris, Stefanos Vasileiadis, Liqun Chen 0002
TrustCom6
2023 DFE-IP: Delegatable functional encryption for inner product
Jinguang Han, Liqun Chen 0002, Willy Susilo, Liquan Chen, Ge Wu 0001
Inf. Sci.2
2022 An Optimized GHV-Type HE Scheme: Simpler, Faster, and More Versatile
Liang Zhao 0020, Liqun Chen 0002, Xinyi Huang 0001
ACNS3
2022 A Blockchain-Based Long-Term Time-Stamping Scheme
Long Meng, Liqun Chen 0002
ESORICS (1)2
2022 Practical EMV Relay Protection
abstract
Relay attackers can forward messages between a contactless EMV bank card and a shop reader, making it possible to wirelessly pickpocket money. To protect against this, Apple Pay requires a user’s fingerprint or Face ID to authorise payments, while Mastercard and Visa have proposed protocols to stop such relay attacks. We investigate transport payment modes and find that we can build on relaying to bypass the Apple Pay lock screen, and illicitly pay from a locked iPhone to any EMV reader, for any amount, without user authorisation. We show that Visa’s proposed relay-countermeasure can be bypassed using rooted smart phones. We analyse Mastercard’s relay protection, and show that its timing bounds could be more reliably imposed at the ISO 14443 protocol level, rather than at the EMV protocol level. With these insights, we propose a new relay-resistance protocol (L1RP) for EMV. We use the Tamarin prover to model mobile-phone payments with and without user authentication, and in different payment modes. We formally verify solutions to our attack suggested by Apple and Visa, and used by Samsung, and we verify that our proposed protocol provides protection from relay attacks.
Andreea-Ina Radu, Tom Chothia, Christopher J. P. Newton, Ioana Boureanu, Liqun Chen 0002
SP5
2022 Security Analysis and Improvement of a Redactable Consortium Blockchain for Industrial Internet-of-Things
abstract
Abstract A redactable consortium blockchain (RCB) can build a trust layer for industrial internet of things (IIoT) so as to enable IIoT to resist certain powerful attacks resulting in improper block content. The redactability is particularly important for blockchains applied in IIoT with valuable or sensitive activities such as financial IoT or energy-trading IoT. Huang et al. proposed a threshold chameleon hash (TCH) scheme and then constructed an accountable-and-sanitizable chameleon signature scheme based on TCH. These two primitives are further used as fundamental modules to build an RCB, which empowers IIoT devices to operate the blockchain in a controllable way. However, our paper shows that Huang et al.’s RCB suffers from a security problem that weakens the crucial redactability. Specifically, we find out that if a transaction in a given block is legally redacted by all authorized sensors who collectively hold the private redacting key, anyone (without any private information) can further redact this redacted transaction and delete any transaction within this redacted block and, meanwhile, any sensor user with a private signing (not redacting) key can insert a forged transaction into this redacted block. We further address this threat by replacing the TCH module in Huang et al.’s RCB with our designed TCH.
Wei Gao 0007, Liqun Chen 0002, Chunming Rong, Kaitai Liang, Xianghan Zheng, Jiangshan Yu
Comput. J.2
2022 Securing emergent behaviour in swarm robotics
Liqun Chen 0002, Siaw-Lynn Ng
J. Inf. Secur. Appl.1
2021 Analysis of Client-Side Security for Long-Term Time-Stamping Services
Long Meng, Liqun Chen 0002
ACNS (1)2
2021 Privacy-Preserving Electronic Ticket Scheme with Attribute-Based Credentials
abstract
Users accessing services are often required to provide personal information, for example, age, profession and location, in order to satisfy access polices. This personal information is evident in the application of e-ticketing where discounted access is granted to visitor attractions or transport services if users satisfy policies related to their age or disability or other defined over attributes. We propose a privacy-preserving electronic ticket scheme using attribute-based credentials to protect users' privacy. The benefit of our scheme is that the attributes of a user are certified by a trusted third party so that the scheme can provide assurances to a seller that a user's attributes are valid. The scheme makes the following contributions: (1) users can buy different tickets from ticket sellers without releasing their exact attributes; (2) two tickets of the same user cannot be linked; (3) a ticket cannot be transferred to another user; (4) a ticket cannot be double spent. The novelty of our scheme is to enable users to convince ticket sellers that their attributes satisfy the ticket policies and buy discounted tickets anonymously. This is a step towards identifying an e-ticketing scheme that captures user privacy requirements in transport services. The security of our scheme is proved and reduced to a well-known complexity assumption. The scheme is also implemented and its performance is empirically evaluated.
Jinguang Han, Liqun Chen 0002, Steve A. Schneider, Helen Treharne, Stephan Wesemeyer
IEEE Trans. Dependable Secur. Comput.2
2021 Direct Anonymous Attestation With Optimal TPM Signing Efficiency
abstract
Direct Anonymous Attestation (DAA) is an anonymous signature scheme, which allows the Trusted Platform Module (TPM), a small chip embedded in a host computer, to attest to the state of the host system, while preserving the privacy of the user. DAA provides two signature modes: fully anonymous signatures and pseudonymous signatures. One main goal of designing DAA schemes is to reduce the TPM signing workload as much as possible, as the TPM has only limited resources. In an optimal DAA scheme, the signing workload on the TPM will be no more than that required for a normal signature like ECSchnorr. To date, no scheme has achieved the optimal signing efficiency for both signature modes. In this paper, we propose the first DAA scheme which achieves the optimal TPM signing efficiency for both signature modes. In this scheme, the TPM takes only a single exponentiation to generate a signature, and this single exponentiation can be pre-computed. Our scheme can be implemented using the existing TPM 2.0 commands, and thus is compatible with the TPM 2.0 specification. We benchmarked the TPM 2.0 commands needed for three DAA use cases on an Infineon TPM 2.0 chip, and also implemented the host signing and verification algorithm for our DAA scheme on a laptop with 1.80GHz Intel Core i7-8550U CPU. Our experimental results show that our DAA scheme obtains a total signing time of about 144 ms for either signature mode, while with pre-computation we can obtain a signing time of about 65 ms. Based on our benchmark results for the pseudonymous signature mode, our scheme is roughly$2\times $(resp.,$5\times $) faster than the existing DAA schemes supported by TPM 2.0 in terms of total (resp., online) signing efficiency.
Kang Yang 0002, Liqun Chen 0002, Zhenfeng Zhang, Christopher J. P. Newton, Bo Yang 0003, Li Xi
IEEE Trans. Inf. Forensics Secur.2
2020 Provable-Security Model for Strong Proximity-based Attacks: With Application to Contactless Payments
abstract
In Mastercard's contactless payment protocol called RRP (Relay Resistant Protocol), the reader is measuring the round-trip times of the message-exchanges between itself and the card, to see if they do not take too long. If they do take longer than expected, a relay attack would be suspected and the transaction should be dropped. A recent paper of Financial Crypto 2019 (FC19) raises some questions w.r.t. this type of relay-protection in contactless payments. Namely, the authors point out that the reader has no incentive to protect against relaying, as it stands to gain from illicit payments. The paper defines the notion of such a rogue reader colluding with a MiM attacker, specifically in the context of contactless payments; the paper dubs this as collusive relaying. Two new protocols, PayBCR and PayCCR, which are closely based on Mastercard's RRP and aim to achieve resistance against collusive relaying, are presented therein. Yet, in the FC19 paper, there is no formal treatment of the collusive-relaying notion or of the security of the protocols. In this paper, we first lift the FC19 notions out of the specifics of RRP-based payments - to the generic case of distance bounding. Thus, we set to answer the wider question of what it would mean to catch if RTT-measuring parties (readers, cards, or others) cheat and collude with proximity-based attackers (i.e., relayers or other types). To this end, we give a new distance-bounding primitive (validated distance-bounding) and two new security notions: strong relaying and strong distance-fraud. We also provide a formal model that, for the first time in distance-bounding, caters for dishonest RTT-measurers. In this model, we prove that the new contactless payments in the FC19 paper, PayBCR and PayCCR attain secuity w.r.t. strong relaying. Finally, we define one other primitive (validated and audited distance-bounding), which, in fact, emulates more closely the PayCCR protocol in the Financial Crypto 2019 paper; this is because, contrary to the line introducing them, we note that PayBCR and PayCCR in fact differ in construction and security guarantees especially in those that go past relaying and into authentication.
Ioana Boureanu, Liqun Chen 0002, Sam Ivey
AsiaCCS2
2020 Formal Analysis and Implementation of a TPM 2.0-based Direct Anonymous Attestation Scheme
abstract
Direct Anonymous Attestation (Daa) is a set of cryptographic schemes used to create anonymous digital signatures. To provide additional assurance, Daa schemes can utilise a Trusted Platform Module (Tpm) that is a tamper-resistant hardware device embedded in a computing platform and which provides cryptographic primitives and secure storage. We extend Chen and Li's Daa scheme to support: 1) signing a message anonymously, 2) self-certifying Tpm keys, and 3) ascertaining a platform's state as recorded by the Tpm's platform configuration registers (PCR) for remote attestation, with explicit reference to Tpm2.0 API calls. We perform a formal analysis of the scheme and are the first symbolic models to explicitly include the low-level Tpm call details. Our analysis reveals that a fix pro-posed by Whitefield et al. to address an authentication attack on an Ecc-Daa scheme is also required by our scheme. Developing a fine-grained, formal model of a Daa scheme contributes to the growing body of work demonstrating the use of formal tools in supporting security analyses of cryptographic protocols. We additionally provide and benchmark an open-source C++implementation of this Daa scheme supporting both a hardware and a software Tpm and measure its performance.
Stephan Wesemeyer, Christopher J. P. Newton, Helen Treharne, Liqun Chen 0002, Ralf Sasse, Jorden Whitefield
AsiaCCS4
2020 Adversarial Perturbation with ResNet
abstract
Most of security issues in deep learning are based on human-imperceptible adversarial perturbation, which can fool image recognition models of deep learning and bring a serious security threats to many practical applications. However, how to construct a universal adversarial perturbation for images is still an open question. In this paper, we make fully use of a residual network to get a universal perturbation, and then utilize a loss network to perform the similarity measure of images to carry out the adversarial attack. Experiment results on the CIFAR-10 dataset show that our scheme can get an 89% attack success rate.
Linzhi Jiang, Jian Xu 0004, Dexin Wu, Liqun Chen 0002
ACM Great Lakes Symposium on VLSI5
2020 Privacy preserving search services against online attack
Yi Zhao 0011, Jianting Ning, Kaitai Liang, Yanqi Zhao, Liqun Chen 0002, Bo Yang 0003
Comput. Secur.5
2020 On the Privacy of Matrix Masking-Based Verifiable (Outsourced) Computation
abstract
Privacy-preserving verifiable (outsourced) computation (PPVC) is a useful technique for a resource-constrained client to outsource computationally heavy but sensitive tasks to a computationally powerful but untrusted worker and to obtain expected correct results from the worker. In this paper, we analyze the privacy property of three matrix masking-based PPVC protocols, which have recently been published in IEEE Transactions on Cloud Computing [2] , [3] . To do this, we present a formal definition of a privacy model for a PPVC protocol (see Definition 1 ), and then prove that neither of those three PPVC protocols holds privacy under this model. We also review the comments by Cao et al. [1] on two of the three protocols and show an issue in their comments.
Liang Zhao 0020, Liqun Chen 0002
IEEE Trans. Cloud Comput.2
2020 Sparse Matrix Masking-Based Non-Interactive Verifiable (Outsourced) Computation, Revisited
abstract
A Privacy-preserving Verifiable (outsourced) Computation (PVC) protocol enables a resource-constrained client to outsource expensive and sensitive workloads to computationally powerful but possibly untrusted service providers (called workers) and to verify the correctness of the results. In a PVC protocol, the inputs and outputs of the computation are hidden, so that the worker is unable to determine them. This is referred to as the privacy property. A Non-interactive PVC (NPVC) protocol is a PVC protocol without communications between a client and worker, apart from distributing the workloads and results. In the literature, Sparse Matrices (SMs) have been used in NPVC protocols to efficiently hide the inputs and outputs from the worker. However, to the best of our knowledge, how the low density of an SM affects privacy in such NPVC protocols has not been formally analyzed. In this work, we first propose a formal definition of the privacy property of an NPVC protocol with respect to matrix density. We use this definition to demonstrate that all of the SM masking-based NPVC protocols that we know of do not hold this privacy property under the ciphertext-only attack model. We then propose an SM masking construction to modify two of those protocols, chosen because they are state-of-the-art, and prove that the modified protocols hold the privacy property under the chosen-plaintext attack model. Our modifications do not require the client operating matrix inversion, and they are able to keep the same level of high performance and all other properties as the originals.
Liang Zhao 0020, Liqun Chen 0002
IEEE Trans. Dependable Secur. Comput.2
2020 Anonymous Single Sign-On With Proxy Re-Verification
abstract
An anonymous single sign-on (ASSO) scheme allows users to access multiple services anonymously using one credential. We propose a new ASSO scheme, where users can access services anonymously through the use of anonymous credentials and unlinkably through the provision of designated verifiers. Notably, verifiers cannot link a user's service requests even if they collude. The novelty is that when a designated verifier is unavailable, a central authority can authorize new verifiers to authenticate the user on behalf of the original verifier. Furthermore, a central verifier can also be authorized to de-anonymize users and trace their service requests. We formalize the scheme along with a security proof and provide an empirical evaluation of its performance. This scheme can be applied to smart ticketing where minimizing the collection of personal information of users is increasingly important to transport organizations due to privacy regulations such as general data protection regulations (GDPRs).
Jinguang Han, Liqun Chen 0002, Steve A. Schneider, Helen Treharne, Stephan Wesemeyer
IEEE Trans. Inf. Forensics Secur.2
2019 A Symbolic Analysis of ECC-Based Direct Anonymous Attestation
abstract
Direct Anonymous Attestation (DAA) is a cryptographic scheme that provides Trusted Platform Module TPM-backed anonymous credentials. We develop Tamarin modelling of the ECC-based version of the protocol as it is standardised and provide the first mechanised analysis of this standard. Our analysis confirms that the scheme is secure when all TPMs are assumed honest, but reveals a break in the protocol's expected authentication and secrecy properties for all TPMs even if only one is compromised. We propose and formally verify a minimal fix to the standard. In addition to developing the first formal analysis of ECC-DAA, the paper contributes to the growing body of work demonstrating the use of formal tools in supporting standardisation processes for cryptographic protocols.
Jorden Whitefield, Liqun Chen 0002, Ralf Sasse, Steve A. Schneider, Helen Treharne, Stephan Wesemeyer
EuroS&P2
2019 A Lattice-Based Enhanced Privacy ID
Nada El Kassem, Luís Fiolhais, Paulo Martins 0002, Liqun Chen 0002, Leonel Sousa
WISTP4
2019 Attribute-Based Information Flow Control
abstract
Abstract Information flow control (IFC) regulates where information is permitted to travel within information systems. To enforce IFC, access control encryption (ACE) was proposed to support both the no read-up rule and the no write-down rule. There are some problems in existing schemes. First, the communication cost is linear with the number of receivers. Second, senders are not authenticated, namely an unauthorized sender can send a message to a receiver. To reduce communication cost and implement sender authentication, we propose an attribute-based IFC (ABIFC) scheme by introducing attribute-based systems into IFC. Our ABIFC scheme captures the following features: (i) flexible IFC policies are defined over a universal set of descriptive attributes; (ii) both the no read-up rule and the no write-down rule are supported; (iii) the communication cost is linear with the number of required attributes, instead of receivers; (iv) receivers can outsource heavy computation to a server without compromising data confidentiality; (v) authorized senders can control release their attributes when sending messages to receivers. To the best of our knowledge, it is the first IFC scheme where flexible policies are defined over descriptive attributes and outsourced computation is supported.
Jinguang Han, Maoxuan Bei, Liqun Chen 0002, Yang Xiang 0001, Jie Cao 0001, Fuchun Guo, Weizhi Meng 0001
Comput. J.3
2019 REWARDS: Privacy-preserving rewarding and incentive schemes for the smart electricity grid and other loyalty systems
Tassos Dimitriou, Thanassis Giannetsos, Liqun Chen 0002
Comput. Commun.3
2019 More efficient, provably-secure direct anonymous attestation from lattices
Nada El Kassem, Liqun Chen 0002, Rachid El Bansarkhani, Ali El Kaafarani, Jan Camenisch, Patrick Hough, Paulo Martins 0002, Leonel Sousa
Future Gener. Comput. Syst.2
2019 Toward Practical Privacy-Preserving Processing Over Encrypted Data in IoT: An Assistive Healthcare Use Case
abstract
With the advancement of Internet of Things (IoT), a large number of electronic devices are connected to the Internet. These connected electronic devices acquire and transmit information, and respond to any received actions. In the medical ecosystem, hospitals can implement medical diagnosis (MD) with medical sensors, especially for remote auxiliary MD. But, in this context, patients' privacy (PP) is of paramount importance, and confidentiality of medical data is crucial. Therefore, the main challenge ahead is how to realize remote auxiliary MD while protecting confidentiality of the medical data and ensuring PP. In this article, based on somewhat homomorphic encryption (SHE) scheme addressed by Junfeng Fan and Frederik Vercauteren (FV), we provide the first instance of a new efficient SHE scheme for homomorphic evaluation over single instruction multiple data (SIMD). We also implement a new set of efficient SIMD homomorphic comparison and division schemes. Based on these findings, we implement efficient privacy preserving and SIMD homomorphic surf and multiretina-image matching schemes. Offered functionalities include SIMD homomorphic feature point detection, multiretina-image matching, and lesion detection for the encrypted retinal image of diabetic retinopathy. Finally, we provide a proof-of-concept application implementation toward remote auxiliary diagnosis systems for diabetes in order to showcase the core security and privacy pillars of our solution. In the meantime, our IoT system designed with lattice-based cryptography preserves data confidentiality under quantum computation and quantum computers.
Linzhi Jiang, Liqun Chen 0002, Thanassis Giannetsos, Bo Luo, Kaitai Liang, Jinguang Han
IEEE Internet Things J.2
2019 Fine-grained information flow control using attributes
Jinguang Han, Liqun Chen 0002, Willy Susilo, Xinyi Huang 0001, Aniello Castiglione, Kaitai Liang
Inf. Sci.2
2019 Efficient threshold password-authenticated secret sharing protocols for cloud computing
Xun Yi, Zahir Tari, Feng Hao 0001, Liqun Chen 0002, Joseph K. Liu, Xuechao Yang, Kwok-Yan Lam, Ibrahim Khalil 0001, Albert Y. Zomaya
J. Parallel Distributed Comput.4
2019 CCA Secure Public Key Encryption against After-the-Fact Leakage without NIZK Proofs
abstract
In leakage resilient cryptography, there is a seemingly inherent restraint on the ability of the adversary that it cannot get access to the leakage oracle after the challenge. Recently, a series of works made a breakthrough to consider a postchallenge leakage. They presented achievable public key encryption (PKE) schemes which are semantically secure against after-the-fact leakage in the split-state model. This model puts a more acceptable constraint on adversary’s ability that the adversary cannot query the leakage of secret states as a whole but the functions of several parts separately instead of prechallenge query only. To obtain security against chosen ciphertext attack (CCA) for PKE schemes against after-the-fact leakage attack (AFL), existing works followed the paradigm of “double encryption” which needs noninteractive zero knowledge (NIZK) proofs in the encryption algorithm. We present an alternative way to achieve AFL-CCA security via lossy trapdoor functions (LTFs) without NIZK proofs. First, we formalize the definition of LTFs secure against AFL (AFLR-LTFs) and all-but-one variants (ABO). Then, we show how to realize this primitive in the split-state model. This primitive can be used to construct AFLR-CCA secure PKE scheme in the same way as the method of “CCA from LTFs” in traditional sense.
Yi Zhao 0011, Kaitai Liang, Bo Yang 0003, Liqun Chen 0002
Secur. Commun. Networks4
2018 A Linear Distinguisher and its Application for Analyzing Privacy-Preserving Transformation Used in Verifiable (Outsourced) Computation
abstract
A distinguisher is employed by an adversary to explore the privacy property of a cryptographic primitive. If a cryptographic primitive is said to be private, there is no distinguisher algorithm that can be used by an adversary to distinguish the encodings generated by this primitive with non-negligible advantage. Recently, two privacy-preserving matrix transformations first proposed by Salinas et al. have been widely used to achieve the matrix-related verifiable (outsourced) computation in data protection. Salinas et al. proved that these transformations are private (in terms of indistinguishability). In this paper, we first propose the concept of a linear distinguisher and two constructions of the linear distinguisher algorithms. Then, we take those two matrix transformations (including Salinas et al.$'$s original work and Yu et al.$'$s modification) as example targets and analyze their privacy property when our linear distinguisher algorithms are employed by the adversaries. The results show that those transformations are not private even against passive eavesdropping.
Liang Zhao 0020, Liqun Chen 0002
AsiaCCS2
2018 Anonymous Single-Sign-On for n Designated Services with Traceability
Jinguang Han, Liqun Chen 0002, Steve A. Schneider, Helen Treharne, Stephan Wesemeyer
ESORICS (1)2
2018 Certificateless Public Key Signature Schemes from Standard Algorithms
Zhaohui Cheng, Liqun Chen 0002
ISPEC2
2018 A foggy research future: Advances and future opportunities in fog computing research
Kim-Kwang Raymond Choo, Rongxing Lu, Liqun Chen 0002, Xun Yi
Future Gener. Comput. Syst.3
2017 One TPM to Bind Them All: Fixing TPM 2.0 for Provably Secure Anonymous Attestation
abstract
The Trusted Platform Module (TPM) is an international standard for a security chip that can be used for the management of cryptographic keys and for remote attestation. The specification of the most recent TPM 2.0 interfaces for direct anonymous attestation unfortunately has a number of severe shortcomings. First of all, they do not allow for security proofs (indeed, the published proofs are incorrect). Second, they provide a Diffie-Hellman oracle w.r.t. the secret key of the TPM, weakening the security and preventing forward anonymity of attestations. Fixes to these problems have been proposed, but they create new issues: they enable a fraudulent TPM to encode information into an attestation signature, which could be used to break anonymity or to leak the secret key. Furthermore, all proposed ways to remove the Diffie-Hellman oracle either strongly limit the functionality of the TPM or would require significant changes to the TPM 2.0 interfaces. In this paper we provide a better specification of the TPM 2.0 interfaces that addresses these problems and requires only minimal changes to the current TPM 2.0 commands. We then show how to use the revised interfaces to build q-SDH-and LRSW-based anonymous attestation schemes, and prove their security. We finally discuss how to obtain other schemes addressing different use cases such as key-binding for U-Prove and e-cash.
Jan Camenisch, Liqun Chen 0002, Manu Drijvers, Anja Lehmann, David Novick, Rainer Urian
IEEE Symposium on Security and Privacy2
2017 Private reputation retrieval in public - a privacy-aware announcement scheme for VANETs
abstract
An announcement scheme is a system that facilitates vehicles to broadcast road‐related information in vehicular ad hoc networks (VANETs) in order to improve road safety and efficiency. Here, the authors propose a new cryptographic primitive for public updating of reputation score based on the Boneh–Boyen–Shacham short group signature scheme. This allows private reputation score retrieval without a secure channel. Using this, the authors devise a privacy‐aware announcement scheme using reputation systems which is reliable, auditable, and robust.
Liqun Chen 0002, Qin Li 0017, Keith M. Martin, Siaw-Lynn Ng
IET Inf. Secur.1
2016 Efficient, XOR-Based, Ideal (t, n)- threshold Schemes
Liqun Chen 0002, Thalia M. Laing, Keith M. Martin
CANS1
2015 Du-Vote: Remote Electronic Voting with Untrusted Computers
abstract
Du-Vote is a new remote electronic voting protocol that eliminates the often-required assumption that voters trust general-purpose computers. Trust is distributed in Du-Vote between a simple hardware token issued to the voter, the voter's computer, and a server run by election authorities. Verifiability is guaranteed with high probability even if all these machines are controlled by the adversary, and privacy is guaranteed as long as at least either the voter's computer, or the server and the hardware token, are not controlled by the adversary. The design of the Du-Vote protocol is presented in this paper. A new non-interactive zero-knowledge proof is employed to verify the server's computations. Du-Vote is a step towards tackling the problem of internet voting on user machines that are likely to have malware. We anticipate that the methods of Du-Vote can be used in other applications to find ways of achieving malware tolerance, that is, ways of securely using platforms that are known or suspected to have malware.
Gurchetan S. Grewal, Mark Ryan 0001, Liqun Chen 0002, Michael R. Clarkson
CSF3
2015 Practical Threshold Password-Authenticated Secret Sharing Protocol
abstract
Threshold password-authenticated secret sharing (TPASS) protocols allow a client to secret-share a secret s among n servers and protect it with a password $$\mathsf {pw}$$ , so that the client can later recover s from any subset of t of the servers using the password $$\mathsf {pw}$$ , but so that no coalition smaller than t learns anything about s or can mount an offline dictionary attack on the password $$\mathsf {pw}$$ . Some TPASS protocols have appeared in the literature recently. The protocol by Bagherzandi et al. (CCS 2011) leaks the password if a client mistakenly executes the protocol with malicious servers. The first t-out-of-n TPASS protocol for any $$n>t$$ that does not suffer from this shortcoming was given by Camenisch et al. (CRYPTO 2014). This protocol, proved to be secure in the UC framework, requires the client to involve in many communication rounds so that it becomes impractical for the client. In this paper, we present a practical TPASS protocol which is in particular efficient for the client, who only needs to send a request and receive a response. In addition, we have provided a rigorous proof of security for our protocol in the standard model.
Xun Yi, Feng Hao 0001, Liqun Chen 0002, Joseph K. Liu
ESORICS (1)3
2015 Assessing Attack Surface with Component-Based Package Dependency
Xinwen Zhang, Xinming Ou, Liqun Chen 0002, Nigel Edwards
NSS4
2015 Formal analysis of privacy in Direct Anonymous Attestation schemes
Ben Smyth, Mark Ryan 0001, Liqun Chen 0002
Sci. Comput. Program.3
2015 Short Dynamic Group Signature Scheme Supporting Controllable Linkability
abstract
The controllable linkability of group signatures introduced by Hwanget al.enables an entity who has a linking key to find whether or not two group signatures were generated by the same signer, while preserving the anonymity. This functionality is very useful in many applications that require the linkability but still need the anonymity, such as sybil attack detection in a vehicular ad hoc network and privacy-preserving data mining. In this paper, we present a new group signature scheme supporting the controllable linkability. The major advantage of this scheme is that the signature length is very short, even shorter than this in the best-known group signature scheme without supporting the linkability. We have implemented our scheme in both a Linux machine with an Intel Core2 Quad and an iPhone4. We compare the results with a number of existing group signature schemes. We also prove security features of our scheme, such as anonymity, traceability, nonframeability, and linkability, under a random oracle model.
Jung Yeon Hwang, Liqun Chen 0002, Hyun Sook Cho, DaeHun Nyang
IEEE Trans. Inf. Forensics Secur.2
2014 Attribute-Based Signatures with User-Controlled Linkability
Ali El Kaafarani, Liqun Chen 0002, Essam Ghadafi, James H. Davenport
CANS2
2014 Balancing Societal Security and Individual Privacy: Accountable Escrow System
abstract
Privacy is a core human need, but society sometimes has the requirement to do targeted, proportionate investigations in order to provide security. To reconcile individual privacy and societal security, we explore whether we can have surveillance in a form that is verifiably accountable to citizens. This means that citizens get verifiable proofs of the quantity and nature of the surveillance that actually takes place. In our scheme, governments are held accountable for the extent to which they exercise their surveillance power, and political parties can pledge in election campaigns their intention about reducing (or increasing) this figure. We propose a general idea of accountable escrow to reconciling and balancing the requirements of individual privacy and societal security. We design a balanced crypto system for asynchronous communication (e.g., email). We propose a novel method for escrowing the decryption capability in public-key cryptography. A government can decrypt it in order to conduct targeted surveillance, but doing so necessarily puts records in a public log against which the government is held accountable.
Jia Liu 0003, Mark Ryan 0001, Liqun Chen 0002
CSF3
2014 A Fast Single Server Private Information Retrieval Protocol with Low Communication Cost
Changyu Dong, Liqun Chen 0002
ESORICS (1)2
2014 A Fast Secure Dot Product Protocol with Application to Privacy Preserving Association Rule Mining
Changyu Dong, Liqun Chen 0002
PAKDD (1)2
2014 Cross-Domain Password-Based Authenticated Key Exchange Revisited
abstract
We revisit the problem of secure cross-domain communication between two users belonging to different security domains within an open and distributed environment. Existing approaches presuppose that either the users are in possession of public key certificates issued by a trusted certificate authority (CA), or the associated domain authentication servers share a long-term secret key. In this article, we propose a generic framework for designing four-party password-based authenticated key exchange (4PAKE) protocols. Our framework takes a different approach from previous work. The users are not required to have public key certificates, but they simply reuse their login passwords, which they share with their respective domain authentication servers. On the other hand, the authentication servers, assumed to be part of a standard PKI, act as ephemeral CAs that certify some key materials that the users can subsequently use to exchange and agree on as a session key. Moreover, we adopt a compositional approach. That is, by treating any secure two-party password-based key exchange (2PAKE) protocol and two-party asymmetric-key/symmetric-key-based key exchange (2A/SAKE) protocol as black boxes, we combine them to obtain generic and provably secure 4PAKE protocols.
Liqun Chen 0002, Hoon Wei Lim, Guomin Yang
ACM Trans. Inf. Syst. Secur.1
2013 Flexible and scalable digital signatures in TPM 2.0
abstract
Trusted Platform Modules (TPM) are multipurpose hardware chips, which provide support for various cryptographic functions. Flexibility, scalability and high performance are critical features for a TPM. In this paper, we present the new method for implementing digital signatures that has been included in TPM version 2.0. The core part of this method is a single TPM signature primitive, which can be called by different software programmes, in order to implement signature schemes and cryptographic protocols with different security and privacy features. We prove security of the TPM signature primitive under the static Diffie-Hellman assumption and the random oracle model. We demonstrate how to call this TPM signature primitive to implement anonymous signatures (Direct Anonymous Attestation), pseudonym systems (U-Prove), and conventional signatures (the Schnorr signature). To the best of our knowledge, this is the first signature primitive implemented in a limited hardware environment capable of supporting various signature schemes without adding additional hardware complexity compared to a hardware implementation of a conventional signature scheme.
Liqun Chen 0002, Jiangtao Li 0001
CCS1
2013 When private set intersection meets big data: an efficient and scalable protocol
abstract
Large scale data processing brings new challenges to the design of privacy-preserving protocols: how to meet the increasing requirements of speed and throughput of modern applications, and how to scale up smoothly when data being protected is big. Efficiency and scalability become critical criteria for privacy preserving protocols in the age of Big Data. In this paper, we present a new Private Set Intersection (PSI) protocol that is extremely efficient and highly scalable compared with existing protocols. The protocol is based on a novel approach that we call oblivious Bloom intersection. It has linear complexity and relies mostly on efficient symmetric key operations. It has high scalability due to the fact that most operations can be parallelized easily. The protocol has two versions: a basic protocol and an enhanced protocol, the security of the two variants is analyzed and proved in the semi-honest model and the malicious model respectively. A prototype of the basic protocol has been built. We report the result of performance evaluation and compare it against the two previously fastest PSI protocols. Our protocol is orders of magnitude faster than these two protocols. To compute the intersection of two million-element sets, our protocol needs only 41 seconds (80-bit security) and 339 seconds (256-bit security) on moderate hardware in parallel mode.
Changyu Dong, Liqun Chen 0002, Zikai Wen
CCS2
2013 Fair Private Set Intersection with a Semi-trusted Arbiter
Changyu Dong, Liqun Chen 0002, Jan Camenisch, Giovanni Russello
DBSec2
2013 Cross-domain password-based authenticated key exchange revisited
abstract
We revisit the problem of cross-domain secure communication between two users belonging to different security domains within an open and distributed environment. Existing approaches presuppose that either the users are in possession of public key certificates issued by a trusted certificate authority (CA), or the associated domain authentication servers share a long-term secret key. In this paper, we propose a four-party password-based authenticated key exchange (4PAKE) protocol that takes a different approach from previous work. The users are not required to have public key certificates, but they simply reuse their login passwords they share with their respective domain authentication servers. On the other hand, the authentication servers, assumed to be part of a standard PKI, act as ephemeral CAs that “certify” some key materials that the users can subsequently exchange and agree on a session key. Moreover, we adopt a compositional approach. That is, by treating any secure two-party password-based key exchange protocol and two-party asymmetric-key based key exchange protocol as black boxes, we combine them to obtain a generic and provably secure 4PAKE protocol.
Liqun Chen 0002, Hoon Wei Lim, Guomin Yang
INFOCOM1
2012 An historical examination of open source releases and their vulnerabilities
abstract
This paper examines historical releases of Sendmail, Postfix, Apache httpd and OpenSSL by using static source code analysis and the entry-rate in the Common Vulnerabilities and Exposures dictionary (CVE) for a release, which we take as a measure of the rate of discovery of exploitable bugs. We show that the change in number and density of issues reported by the source code analyzer is indicative of the change in rate of discovery of exploitable bugs for new releases --- formally we demonstrate a statistically significant correlation of moderate strength. The strength of the correlation is an artifact of other factors such as the degree of scrutiny: the number of security analysts investigating the software. This also demonstrates that static source code analysis can be used to make some assessment of risk even when constraints do not permit human review of the issues identified by the analysis.
Nigel Edwards, Liqun Chen 0002
CCS2
2012 Ring Group Signatures
abstract
In many applications of group signatures, not only a signer's identity but also which group the signer belongs to is sensitive information regarding signer privacy. In this paper, we study these applications and combine a group signature with a ring signature to create a ring group signature, which specifies a set of possible groups without revealing which member of which group produced the signature. The main contributions of this paper are a formal definition of a ring group signature scheme and its security model, a generic construction and a concrete example of such a scheme. Both the construction and concrete scheme are provably secure if the underlying group signature and ring signature schemes are secure.
Liqun Chen 0002
TrustCom1
2011 End-to-End Policy-Based Encryption and Management of Data in the Cloud
abstract
This paper introduces and discusses a data management solution to provide accountability within the cloud as well as addressing privacy issues. The central idea is as follows: Customers allow cloud (service) providers to have access to specific data based on agreed policies and by forcing interactions with interchangeable independent third parties called Trust Authorities. The access to data can be as fine-grained as necessary, based on policy definitions, underlying encryption mechanisms (supporting the stickiness of policies to the data) and a related key management approach that allows (sets of) data attribute(s) to be encrypted specifically based on the policy. Access to data is mediated by a Trust Authority that checks for compliance to policies in order to release decryption keys. By these means users can be provided with fine-grained control over access and usage of their data within the cloud, even in public cloud models.
Siani Pearson, Marco Casassa Mont, Liqun Chen 0002, Archie Reed
CloudCom3
2011 Publicly posted composite documents with identity based encryption
abstract
Recently-introduced Publicly Posted Composite Documents (PPCDs) enable composite documents with different formats and differential access control to participate in cross-organizational workflows distributed over potentially non-secure channels. The original PPCD design was based on a Public Key Infrastructure, requiring each workflow participant to own a pair of public and private keys. This solution also required the document master to know the corresponding valid public keys (certificates) of all participants prior to commencement of the workflow. Using Identity Based Encryption (IBE), a recently described cryptographic technique, we eliminate the requirement for the prior knowledge and distribution of the workflow participants' keys. The required public keys for each workflow participant are calculated based on user identities and other relevant factors at workflow onset. The generation of corresponding private keys can be delayed up until the workflow step, when the corresponding workflow participants require access to the document. The solution presented provides automatic workflow order enforcement and the ability to impose multiple document release dates real-time.
Helen Balinsky, Liqun Chen 0002, Steven J. Simske
ACM Symposium on Document Engineering2
2011 Generic Methods to Achieve Tighter Security Reductions for a Category of IBE Schemes
Yu Chen 0003, Liqun Chen 0002, Zhong Chen 0001
ISPEC2
2011 The n-Diffie-Hellman Problem and Its Applications
Liqun Chen 0002, Yu Chen 0003
ISC1
2011 Premature silent workflow termination in publicly posted composite documents
abstract
Publicly Posted Composite Documents (PPCDs) address the problem of composite documents with different formats and varied sensitivity participating in cross-organizational workflows distributed over potentially non-secure channels. An early version of the PPCD, however, is susceptible to silent workflow termination, wherein a document shipped by one workflow participant is never received by the subsequent participant, causing the workflow to terminate without notification. In the current paper, we extend the PPCD solution to provide an early detection mechanism for a potential workflow termination, to provide workflow recovery procedures, and to provide for the often mandatory document logging and audit information.
Helen Balinsky, Liqun Chen 0002, Steven J. Simske
SMC2
2011 Publicly Posted Composite Documents in Variably Ordered Workflows
abstract
Recently-introduced Publicly Posted Composite Documents (PPCDs) address the problem of composite documents with different formats and differential access control participating in cross-organizational workflows distributed over potentially non-secure channels. An early version of the PPCD only considered two simplest workflow types: ordered and unordered. In real life, however, fragments of such pure types are likely to be combined into mixed workflows with interleaved ordered and unordered workflow steps. In the current paper, we introduce a payload matrix for a generic mixed workflow. We provide a computationally beneficial solution for enforcing access in ordered workflows by reducing the volume of data that needs to be encrypted and then subsequently decrypted. Furthermore, we address the problem of enforcing order in transitions between different types of workflow steps: from an unordered step to ordered steps and vice versa, and from one unordered step to another. This prevents the participants of any workflow step from being able to access a PPCD document prior to their workflow step.
Helen Balinsky, Liqun Chen 0002, Steven J. Simske
TrustCom2
2011 Extended KCI attack against two-party key establishment protocols
Qiang Tang 0001, Liqun Chen 0002
Inf. Process. Lett.2
2011 Threshold Anonymous Announcement in VANETs
abstract
Vehicular ad hoc networks (VANETs) allow wireless communications between vehicles without the aid of a central server. Reliable exchanges of information about road and traffic conditions allow a safer and more comfortable travelling environment. However, such profusion of information may allow unscrupulous parties to violate user privacy. On the other hand, a degree of auditability is desired for law enforcement and maintenance purposes. In this paper we propose a Threshold Anonymous Announcement service using direct anonymous attestation and one-time anonymous authentication to simultaneously achieve the seemingly contradictory goals of reliability, privacy and auditability.
Liqun Chen 0002, Siaw-Lynn Ng, Guilin Wang
IEEE J. Sel. Areas Commun.1
2010 On the Design and Implementation of an Efficient DAA Scheme
Liqun Chen 0002, Dan Page, Nigel P. Smart
CARDIS1
2010 Security of the TCG Privacy-CA Solution
abstract
The privacy-CA solution (PCAS) is a protocol designed by the Trusted Computing Group (TCG) as an alternative to the Direct Anonymous Attestation scheme for anonymous authentication of Trusted Platform Module (TPM). The protocol has been specified in TPM Specification Version 1.2. In this paper we offer a rigorous security analysis of the protocol. We first design an appropriate security model that captures the level of security offered by PCAS. The model is justified via the expected uses of the protocol in real applications. We then prove, assuming standard security notions for the underlying primitives that the protocol indeed meets the security notion we design. Our analysis sheds some light on the design of the protocol. Finally, we propose a strengthened protocol that meets a stronger notion of security where the adversary is allowed to adaptively corrupt TPMs.
Liqun Chen 0002, Bogdan Warinschi
EUC1
2010 Lightweight Anonymous Authentication with TLS and DAA for Embedded Mobile Devices
Christian Wachsmann, Liqun Chen 0002, Kurt Dietrich, Hans Löhr, Ahmad-Reza Sadeghi, Johannes Winter
ISC2
2010 A note on the Chen-Morrissey-Smart DAA scheme
Liqun Chen 0002, Jiangtao Li 0001
Inf. Process. Lett.1
2009 Security Notions and Generic Constructions for Client Puzzles
Liqun Chen 0002, Paul Morrissey, Nigel P. Smart, Bogdan Warinschi
ASIACRYPT1
2009 A DAA Scheme Requiring Less TPM Resources
Liqun Chen 0002
Inscrypt1
2009 Certificate-Free Attribute Authentication
Dalia Khader, Liqun Chen 0002, James H. Davenport
IMACC2
2009 Anti-counterfeiting Using Memory Spots
Helen Balinsky, Edward McDonnell, Liqun Chen 0002, Keith A. Harrison
WISTP3
2008 Property-Based Attestation without a Trusted Third Party
Liqun Chen 0002, Hans Löhr, Mark Manulis, Ahmad-Reza Sadeghi
ISC1
2008 Pairings in Trusted Computing
Liqun Chen 0002, Paul Morrissey, Nigel P. Smart
Pairing1
2008 On Proofs of Security for DAA Schemes
Liqun Chen 0002, Paul Morrissey, Nigel P. Smart
ProvSec1
2008 A pairing SW implementation for Smart-Cards
Guido Bertoni, Luca Breveglieri, Liqun Chen 0002, Pasqualina Fragneto, Keith A. Harrison, Gerardo Pelosi
J. Syst. Softw.3
2007 General and Efficient Certificateless Public Key Encryption Constructions
Zhaohui Cheng, Liqun Chen 0002, Richard Comley
Pairing2
2006 Identity-Based Key Agreement with Unilateral Identity Privacy Using Pairings
Zhaohui Cheng, Liqun Chen 0002, Richard Comley, Qiang Tang 0001
ISPEC2
2005 Security Proof of Sakai-Kasahara's Identity-Based Encryption Scheme
Liqun Chen 0002, Zhaohui Cheng
IMACC1
2004 Direct anonymous attestation
abstract
This paper describes the direct anonymous attestation scheme (DAA). This scheme was adopted by the Trusted Computing Group (TCG) as the method for remote authentication of a hardware module, called Trusted Platform Module (TPM), while preserving the privacy of the user of the platform that contains the module. DAA can be seen as a group signature without the feature that a signature can be opened, i.e., the anonymity is not revocable. Moreover, DAA allows for pseudonyms, i.e., for each signature a user (in agreement with the recipient of the signature) can decide whether or not the signature should be linkable to another signature. DAA furthermore allows for detection of "known" keys: if the DAA secret keys are extracted from a TPM and published, a verifier can detect that a signature was produced using these secret keys. The scheme is provably secure in the random oracle model under the strong RSA and the decisional Diffie-Hellman assumption.
Ernie Brickell, Jan Camenisch, Liqun Chen 0002
CCS3
2004 Concurrent Signatures
Liqun Chen 0002, Caroline Kudla, Kenneth G. Paterson
EUROCRYPT1
2003 Identity Based Authenticated Key Agreement Protocols from Pairings
abstract
We investigate a number of issues related to identity based authenticated key agreement protocols in the Diffie-Hellman family enabled by the Weil or Tate pairings. These issues include how to make protocols efficient; to avoid key escrow by a Trust Authority (TA) who issues identity based private keys for users, and to allow users to use different TAs. We describe a few authenticated key agreement (AK) protocols and AK with key confirmation (AKC) protocols by modifying Smart's AK protocol (2002). We discuss the security of these protocols heuristically and give formal proofs of security for our AK and AKC protocols (using a security model based on the model defined in (Blake-Wilson et al., 1997)). We also prove that our AK protocol has the key compromise impersonation property. We also show that our second protocol has the TA forward secrecy property (which we define to mean that the compromise of the TA's private key will not compromise previously established session keys), and we note that this also implies that it has the perfect forward secrecy property.
Liqun Chen 0002, Caroline Kudla
CSFW1
2002 Certification of Public Keys within an Identity Based System
Liqun Chen 0002, Keith Harrison, Andrew Moss, David Soldera, Nigel P. Smart
ISC1
2001 An Auditable Metering Scheme for Web Advertisement Applications
Liqun Chen 0002, Wenbo Mao
ISC1
2001 A trusted process to digitally sign a document
abstract
This paper describes a method of increasing the trust in open computing platforms, such that a person can have confidence in producing a digital signature using open platforms.The process of using a digital signature to sign a digital document is well understood. Most descriptions assume the correctness of the process of signing a document within a computing platform. In an increasing connected world, this assumption is no longer true when open computing platforms are used. This paper proposes the signing of a document in a general-purpose computing platform using a trusted process. That trusted process creates a signature over a digital image that represents the document and uses a trusted display controller in the platform plus a smart card owned by the prospective signer. The trusted display controller is part of the video processing path, and can display video data on a monitor without interference or subversion by any software components at the platform. The smart card is able to authenticate the trusted display controller, and demonstrate to the signer the results of that authentication using the trusted display controller.The most unusual aspects of the method are: (1) a thumbnail image is stored in the smart card, and used as a surround or background for an image (on a display) that is to be signed; (2) the smart card signs image data on the authority of the trusted display controller, without direct authorisation from the signer.
Boris Balacheff, Liqun Chen 0002, David Plaquin, Graeme Proudler
NSPW2
2000 Securing Intelligent Adjuncts Using Trusted Computing Platform Technology
Boris Balacheff, Liqun Chen 0002, Siani Pearson, Graeme Proudler
CARDIS3
2000 On enhancing biometric authentication with data protection
abstract
This paper describes a method for biometric identification based user authentication in distributed environments, which makes use of trusted computing platforms (CPs) combined with smart cards (SCs) and trusted biometric readers (BRs) for protection of biometric data. With this authentication method, a user can establish a trust relationship with an accessed CP, and the user can trust that the CP will not disclose his/her sensitive biometric information to any unauthorised entity.
Liqun Chen 0002, Siani Pearson, A. Vamvakas
KES1
2000 Computing Platform Security in Cyberspace
Boris Balacheff, Liqun Chen 0002, Siani Pearson, Graeme Proudler
Inf. Secur. Tech. Rep.2
1998 Efficient Fair Exchange with Verifiable Confirmation of Signatures
Liqun Chen 0002
ASIACRYPT1
1997 Secret Sharing with Reusable Polynomials
Liqun Chen 0002, Dieter Gollmann, Chris J. Mitchell, Peter R. Wild
ACISP1
1997 An anonymous and undeniable payment scheme
Liqun Chen 0002, Chris J. Mitchell
ICICS1
1996 Tailoring authentication protocols to match underlying mechanisms
Liqun Chen 0002, Dieter Gollmann, Chris J. Mitchell
ACISP1
1995 Key distribution without individual trusted authentification servers
abstract
Some recent research on key distribution systems has focussed on analysing trust in authentication servers, and constructing key distribution protocols which operate using a number of authentication servers, which have the property that a minority of them may be untrustworthy. This paper proposes two key distribution protocols with multiple authentication servers using a cross checksum scheme. Both protocol are based on the use of symmetric encryption for verifying the origin and integrity of messages. In these protocols it is not necessary for clients to trust an individual authentication server. A minority of malicious and colluding servers cannot compromise security and can be detected. The first 'parallel' protocol can prevent a minority of servers disrupting the service. The second 'cascade' protocol has to work with other security mechanisms in order to prevent a server breaking the procedure by refusing to cooperate. As compared with other proposed protocols with similar properties these two protocols require less exchanged messages.
Liqun Chen 0002, Dieter Gollmann, Chris J. Mitchell
CSFW1
1995 Distributing Trust Amongst Multiple Authentication Servers
abstract
Some recent research on key distribution systems has focussed on analysing trust in authentication servers, and constructing key distribution protocols which operate using a number of authentication servers, a minority of them may be untrusted. This
Liqun Chen 0002, Dieter Gollmann, Chris J. Mitchell
J. Comput. Secur.1