EDBT 2026 Demo / reviewers in the wild / expert
Qiudong Xia
dblp:224/0937
· DBLP profile ↗
8ranked-venue papers
1as first author
3since 2021 · last 2022
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 7 · 1 first-author · 3 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Network and information security
3 papers |
Cryptographic primitives and cryptanalysis · 54% Authentication and access control · 29% Network security · 13% | |
| Computer networks
3 papers |
Internet architecture and protocols · 100% |
Topics — the 11 heaviest of 11, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Internet architecture and protocols
information-centric networking |
1.3 | 3 | 2022 | SCD2: Secure Content Delivery and Deduplication With Multiple Content Providers in Information Centric Networking · IEEE/ACM Trans. Netw. 2022 A Secure, Efficient, and Accountable Edge-Based Access Control Framework for Information Centric Networks · IEEE/ACM Trans. Netw. 2019 SEAF: A Secure, Efficient and Accountable Access Control Framework for Information Centric Networking · INFOCOM 2018 |
Cryptographic primitives and cryptanalysis › functional encryption
attribute-based encryption |
0.6 | 1 | 2022 | SCD2: Secure Content Delivery and Deduplication With Multiple Content Providers in Information Centric Networking · IEEE/ACM Trans. Netw. 2022 |
Cryptographic primitives and cryptanalysis › functional encryption › attribute-based encryption
key-policy attribute-based encryption |
0.6 | 1 | 2022 | SCD2: Secure Content Delivery and Deduplication With Multiple Content Providers in Information Centric Networking · IEEE/ACM Trans. Netw. 2022 |
Cryptographic primitives and cryptanalysis › public-key cryptography › digital signatures
group signature |
0.5 | 2 | 2019 | A Secure, Efficient, and Accountable Edge-Based Access Control Framework for Information Centric Networks · IEEE/ACM Trans. Netw. 2019 SEAF: A Secure, Efficient and Accountable Access Control Framework for Information Centric Networking · INFOCOM 2018 |
Internet architecture and protocols › network security
access control |
0.4 | 1 | 2019 | A Secure, Efficient, and Accountable Edge-Based Access Control Framework for Information Centric Networks · IEEE/ACM Trans. Netw. 2019 |
Authentication and access control
anonymous authentication |
0.4 | 1 | 2019 | A Secure, Efficient, and Accountable Edge-Based Access Control Framework for Information Centric Networks · IEEE/ACM Trans. Netw. 2019 |
Network security › attack strategy
denial-of-service attack |
0.4 | 1 | 2019 | A Secure, Efficient, and Accountable Edge-Based Access Control Framework for Information Centric Networks · IEEE/ACM Trans. Netw. 2019 |
Internet architecture and protocols › information-centric networking
in-network caching |
0.3 | 1 | 2018 | SEAF: A Secure, Efficient and Accountable Access Control Framework for Information Centric Networking · INFOCOM 2018 |
Authentication and access control
access control |
0.3 | 1 | 2018 | SEAF: A Secure, Efficient and Accountable Access Control Framework for Information Centric Networking · INFOCOM 2018 |
Authentication and access control › access control
fine-grained access control |
0.2 | 1 | 2022 | SCD2: Secure Content Delivery and Deduplication With Multiple Content Providers in Information Centric Networking · IEEE/ACM Trans. Netw. 2022 |
Privacy and data protection
anonymity |
0.1 | 1 | 2019 | A Secure, Efficient, and Accountable Edge-Based Access Control Framework for Information Centric Networks · IEEE/ACM Trans. Netw. 2019 |
Methods — techniques the papers use, named apart from their topics
hash chain · 1.4group signature · 1.4key management · 1.1attribute-based encryption · 1.1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2022 | CSEVP: A Collaborative, Secure, and Efficient Content Validation Protection Framework for Information Centric NetworkingabstractAs a new architecture of Internet infrastructure, Information-Centric Networking (ICN) is mainly designed to effectively handle the rapidly increasing user demand for content delivery through in-network caching. While facilitating the dissemination of content to users and making better use of the network resources, ICN is also vulnerable in that attackers can inject poisoned content into the network and isolate users from valid content sources. The introduction of signature verification in each router can effectively prevent this attack, but it also introduces great computation overhead. Existing schemes in ICN reduce verification overhead from a single routing perspective but do not consider integrating resources within ICN for collaborative content authentication and cyber self-defense. In this paper, we propose a collaborative, secure, and efficient content validation protection framework, named CSEVP, to implement a multi-router collaborative defense mechanism for ICN. On the one hand, we conduct content verification by probabilistically choosing one router involved in the transmission path to offload the computation overhead of content verification from a single router to multiple ones. On the other hand, we adopt bloom filters for routers to record and share verification results to further facilitate a more efficient content validity verification. The security and efficiency analysis shows that our proposed CSEVP can achieve efficient content validity verification among multiple routers with acceptable low communication and storage overhead. Kaiping Xue, Qiudong Xia, David S. L. Wei, Jian Li 0031, Qibin Sun, Jun Lu 0001 |
IEEE Trans. Netw. Serv. Manag. | 3 |
| 2022 | SCD2: Secure Content Delivery and Deduplication With Multiple Content Providers in Information Centric NetworkingabstractAs one of the promising next generation network architectures, information centric networking (ICN) is highly anticipated to improve the bandwidth usage of the Internet and reduce duplicate traffic. Since contents in ICN are disseminated in the whole network, ICN is much more vulnerable and the issue of how to deliver contents securely has been intensively discussed. However, the scalability of the existing schemes is limited. A scalable scheme is expected to be able to achieve fine-grained access control and at the same time also support multiple content providers scenario with efficient key management at user side. Besides, different content providers may publish some identical contents and these contents may be cached in the same intermediate routers, which causes high data redundancy and in turn exerts an adverse impact on the performance of ICN. In this paper, we propose a Secure Content Delivery and Deduplication scheme, called SCD2, to achieve secure and efficient fine-grained access control in ICN with multiple content providers. We first propose a scalable key-policy attribute-based encryption (SKP-ABE) to provide fine-grained access control and allow different attribute authorities to share some public attributes to simplify the key management. Furthermore, based on SKP-ABE, we design a simple but effective mechanism to conduct content deduplication. Finally, we implement a prototype of SCD2 to test its performance and compare it with some existing schemes. The results show that SCD2 has lower storage overhead, a higher degree of deduplication, and better retrieval efficiency. Kaiping Xue, Peixuan He, Qiudong Xia, David S. L. Wei |
IEEE/ACM Trans. Netw. | 4 |
| 2021 | FASE: Fine-Grained Accountable and Space-Efficient Access Control for Multimedia Content With In-Network CachingabstractTo reduce the duplicated traffic and improve the performance of distributing massive volumes of multimedia contents, in-network caching has been proposed recently. However, as in-network content caching can be directly utilized to respond users’ requests, multimedia content retrieval is beyond content providers’ control and makes it hard for them to implement access control and service accounting. In this paper, we propose a Fine-grained Accountable and Space-Efficient access control scheme, called FASE, for multimedia content distribution. FASE allows content providers to be fully offline while making the best of in-network caching. In FASE, the attribute-based encryption at multimedia content provider side and access policy based authentication at the edge router side jointly ensure secure fine-grained access control. Our scheme is efficient in both space and time. By designing one time chameleon signature (OTCS), users can keep anonymous during the authentication, and their privileges can be conveniently revoked when needed. Besides, secure service accounting is implemented by letting edge routers collect service credentials generated during users’ request process. Through formal security analysis, we prove the security of our scheme. Simulation results demonstrate that our scheme is efficient with acceptable overhead. Peixuan He, Kaiping Xue, Qiudong Xia, Jianqing Liu, David S. L. Wei |
IEEE Trans. Netw. Serv. Manag. | 4 |
| 2019 | TSLS: Time Sensitive, Lightweight and Secure Access Control for Information Centric NetworkingabstractInformation Centric Networking (ICN), a new paradigm of Internet infrastructure, aims to better accommodate users' rapid growing demand for content delivery and optimize bandwidth utilization. Although the in-network cache feature of ICN facilitates the dissemination of content to users, it also poses new challenges on access control for content and network resource. Moreover, it is common that the access privilege of content dynamically change over time. However, existing access control mechanisms in ICN cannot support the publication and distribution of such time-sensitive content. In this paper, we propose a time- sensitive, lightweight, and secure access control mechanism, called TSLS, to solve this problem. We introduce broadcast encryption combined with time tokens for content providers to protect content confidentiality, and only authorized users satisfying the time limitation have capability to decrypt and access the content. Besides, a fast lightweight challenge-response verification is implemented at the edge routers to block unauthorized request from injecting into the network. The responses of authorized users are forwarded to content providers for pre-distribute popular content at in-network caches in advance. Our security analysis shows that TSLS possesses the properties of data confidentiality, unforgeability, anonymity, and DoS/DDoS attacks resistance. Our simulation results indicate that our proposed TSLS is an efficient mechanism with low computation cost and network delay. Qiudong Xia, Peixuan He, Kaiping Xue, Jiangping Han, David S. L. Wei, Hao Yue 0001 |
GLOBECOM | 1 |
| 2019 | Attribute-Based Accountable Access Control for Multimedia Content with In-Network CachingabstractNowadays, multimedia content retrieval has become the major service requirement of the Internet and the traffic of these contents has dominated the IP traffic. To reduce the duplicated traffic and improve the performance of distributing massive volumes of multimedia contents, in-network caching has been proposed recently. However, because in-network content caching can be directly utilized to respond users' requests, multimedia content retrieval is beyond content providers' control and makes it hard for them to implement access control and service accounting. In this paper, we propose an attribute-based accountable access control scheme for multimedia content distribution while making the best of in-network caching, in which content providers can be fully offline. In our scheme, the attribute-based encryption at multimedia content provider side and access policy based authentication at the edge router side jointly ensure the secure access control, which is also efficient in both space and time. Besides, secure service accounting is implemented by letting edge routers collect service credentials generated during users' request process. Through the informal security analysis, we prove the security of our scheme. Simulation results demonstrate that our scheme is efficient with acceptable overhead. Peixuan He, Kaiping Xue, Jie Xu 0031, Qiudong Xia, Jianqing Liu, Hao Yue 0001 |
ICME | 4 |
| 2019 | A Secure, Efficient, and Accountable Edge-Based Access Control Framework for Information Centric NetworksabstractInformation centric networking (ICN) has been regarded as an ideal architecture for the next-generation network to handle users' increasing demand for content delivery with in-network cache. While making better use of network resources and providing better service delivery, an effective access control mechanism is needed due to the widely disseminated contents. However, in the existing solutions, making cache-enabled routers or content providers authenticate users' requests causes high computation overhead and unnecessary delay. Also, the straight-forward utilization of advanced encryption algorithms makes the system vulnerable to DoS attacks. Besides, privacy protection and service accountability are rarely taken into account in this scenario. In this paper, we propose SEAF, a secure, efficient, and accountable edge-based access control framework for ICN, in which authentication is performed at the network edge to block unauthorized requests at the very beginning. We adopt group signature to achieve anonymous authentication and use hash chain technique to reduce greatly the overhead when users make continuous requests for the same file. At the same time, we provide an efficient revocation method to make our framework more robust. Furthermore, the content providers can affirm the service amount received from the network and extract feedback information from the signatures and hash chains. By formal security analysis and the comparison with related works, we show that SEAF achieves the expected security goals and possesses more useful features. The experimental results also demonstrate that our design is efficient for routers and content providers and bring in only slight delay for users' content retrieval. Kaiping Xue, Peixuan He, Qiudong Xia, David S. L. Wei, Hao Yue 0001, Feng Wu 0001 |
IEEE/ACM Trans. Netw. | 4 |
| 2018 | LASA: Lightweight, Auditable and Secure Access Control in ICN with Limitation of Access TimesabstractInformation Centric Networking (ICN), a future network architecture candidate, aims to alleviate the problem of insufficient bandwidth in traditional IP network. In ICN, contents are distributed in the whole network, so access control becomes more intractable. As we know, almost all of existing solutions consider it as a "Yes or No" problem, where a user either has the permission to access the corresponding content or not. However, in many practical situations, a content provider doesn't expect a single authorized user has the ability to access its repertory without times limitation when taking copyright protection into account. In this paper, we propose LASA, a lightweight, auditable and secure solution where legitimate users are limited to access a content provider's data within pre-designate times. In LASA, each content provider sets maximum access times for each legitimate user and edge routers perform authentication and audit based on users' signatures attached to interest packets. Once a legitimate user attempts to exceed his/her limited access times, his/her secret key will be leaked and the dishonest behavior will be detected. Our security analysis shows that LASA can provide signature unforgeability, data confidentiality and other security features. Experiment results show that our scheme LASA brings a little computational cost. Peixuan He, Yinxin Wan, Qiudong Xia, Shaohua Li 0002, Jianan Hong, Kaiping Xue |
ICC | 3 |
| 2018 | SEAF: A Secure, Efficient and Accountable Access Control Framework for Information Centric NetworkingabstractInformation Centric Networking (ICN) has been regarded as an ideal architecture for the next-generation network to handle users' increasing demand for content delivery with in-network cache. While making better use of network resources and providing better delivery service, an effective access control mechanism is needed due to wide dissemination of contents. However, in the existing solutions, making cache-enabled routers or content providers authenticate users' requests causes high computation overhead and unnecessary delay. Also, straightforward utilization of advanced encryption algorithms increases the opportunities for DoS attacks. Besides, privacy protection and service accountability are rarely taken into account in this scenario. In this paper, we propose a secure, efficient, and accountable access control framework, called SEAF, for ICN, in which authentication is performed at the network edge to block unauthorized requests at the very beginning. We adopt group signature to achieve anonymous authentication, and use hash chain technique to greatly reduce the overhead when users make continuous requests for the same file. Furthermore, the content providers can affirm the service amount received from the network and extract feedback information from the signatures and hash chains. By formal security analysis and the comparison with related works, we show that SEAF achieves the expected security goals and possesses more useful features. The experimental results also demonstrate that our design is efficient for routers and content providers, and introduces only slight delay for users' content retrieval. Kaiping Xue, Qiudong Xia, David S. L. Wei, Hao Yue 0001, Feng Wu 0001 |
INFOCOM | 3 |