Handong Cui

dblp:225/1422 · DBLP profile ↗
← Back
10ranked-venue papers
4as first author
8since 2021 · last 2025
0000-0002-2799-4709ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 9 · 3 first-author · 7 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2025 DIDO+: Data Provenance From Restricted TLS 1.3 Websites With Selective Disclosure
abstract
Public data can be authenticated via TLS from trustworthy websites, while private data, such as user profiles, is generally restricted. Users cannot share their username and password to access private data (e.g., addresses) from restricted sites (e.g., utility companies). DECO (CCS 2020) presents a TLS 1.2-based solution that facilitates data liberation without imposing excessive trust assumptions or requiring server-side modifications. In our previous work, DIDO (ISPEC 2023), we proposed an optimized solution for TLS 1.3 websites. We addressed several open problems, including support for X25519 key exchange, the design of round-optimal three-party key exchange, the architecture of 2 PC for TLS 1.3 key scheduling, and circuit design optimized for 2 PC. Our implementation was tested on real-world websites. In this work, DIDO+, we provide a comparison with recent concurrent efforts and offer additional details about DIDO. We also present the NIZK proofs utilized in three-party key exchange under malicious settings. Finally, we introduce a new protocol called selective disclosure, which allows for the disclosure of specific portions of plaintext to the verifier, instead of the entirety.
Kwan Yin Chan, Handong Cui, Tsz Hon Yuen, Siu-Ming Yiu
IEEE Trans. Dependable Secur. Comput.2
2024 Bandwidth-Efficient Zero-Knowledge Proofs For Threshold ECDSA
abstract
Abstract In most threshold Elliptic Curve Digital Signature Algorithm (ECDSA) signatures using additively homomorphic encryption, the zero-knowledge (ZK) proofs related to the ciphertext or the message space are the bottleneck in terms of bandwidth as well as computation time. In this paper, we propose a compact ZK proof for relations related to the Castagnos–Laguillaumie (CL) encryption, which is 33% shorter and 29% faster than the existing work in PKC 2021. We also give new ZK proofs for relations related to homomorphic operations over the CL ciphertext. These new ZK proofs are useful to construct a bandwidth-efficient universal composable-secure threshold ECDSA without compromising the proactive security and the non-interactivity. In particular, we lowered the communication and computation cost of the key refresh algorithm in the Paillier-based counterpart from $O(n^3)$ to $O(n^2)$. Considering a 5-signer setting, the bandwidth is better than the Paillier-based counterpart for up to 99, 95 and 35% for key generation, key refreshment and pre-signing, respectively.
Handong Cui, Kwan Yin Chan, Tsz Hon Yuen, Xin Kang 0001, Cheng-Kang Chu
Comput. J.1
2023 Efficient Multiplicative-to-Additive Function from Joye-Libert Cryptosystem and Its Application to Threshold ECDSA
abstract
Threshold ECDSA receives interest lately due to its widespread adoption in blockchain applications. A common building block of all leading constructions involves a secure conversion of multiplicative shares into additive ones, which is called the multiplicative-to-additive (MtA) function. MtA dominates the overall complexity of all existing threshold ECDSA constructions. Specifically, O(n2) invocations of MtA are required in the case of n active signers. Hence, improvement of MtA leads directly to significant improvements for all state-of-the-art threshold ECDSA schemes.
Haiyang Xue, Man Ho Au, Mengling Liu, Kwan Yin Chan, Handong Cui, Tsz Hon Yuen, Chengru Zhang
CCS5
2023 DIDO: Data Provenance from Restricted TLS 1.3 Websites
Kwan Yin Chan, Handong Cui, Tsz Hon Yuen
ISPEC2
2022 Multi-signatures for ECDSA and Its Applications in Blockchain
Shimin Pan, Kwan Yin Chan, Handong Cui, Tsz Hon Yuen
ACISP3
2021 A Trustless GQ Multi-signature Scheme with Identifiable Abort
Handong Cui, Tsz Hon Yuen
ACISP1
2021 Efficient Online-friendly Two-Party ECDSA Signature
abstract
Two-party ECDSA signatures have received much attention due to their widespread deployment in cryptocurrencies. Depending on whether or not the message is required, we could divide two-party signing into two different phases, namely, offline and online. Ideally, the online phase should be made as lightweight as possible. At the same time, the cost of the offline phase should remain similar to that of a normal signature generation. However, the existing two-party protocols of ECDSA are not optimal: either their online phase requires decryption of a ciphertext, or their offline phase needs at least two executions of multiplicative-to-additive conversion which dominates the overall complexity. This paper proposes an online-friendly two-party ECDSA with a lightweight online phase and a single multiplicative-to-additive function in the offline phase. It is constructed by a novel design of a re-sharing of the secret key and a linear sharing of the nonce. Our scheme significantly improves previous protocols based on either oblivious transfer or homomorphic encryption. We implement our scheme and show that it outperforms prior online-friendly schemes (i.e., those have lightweight online cost) by a factor of roughly 2 to 9 in both communication and computation. Furthermore, our two-party scheme could be easily extended to the 2-out-of-n threshold ECDSA.
Haiyang Xue, Man Ho Au, Tsz Hon Yuen, Handong Cui
CCS5
2021 Security on SM2 and GOST Signatures against Related Key Attacks
abstract
The US Standard (EC)DSA is currently almost the most popular digital signature scheme. Chinese and Russian governments also proposed their counterparts: SM2 and GOST R 34.10 (GOST). Nowadays, there are already many industrial applications supporting SM2 and GOST digital signatures. Unfortunately, the existing analyses for SM2 and GOST are rather limited when compared to ECDSA. This paper focuses on the security of SM2 and GOST from the viewpoints of RKA security (related-key attack) and sKRKA security (strong known related key attack). RKA captures the real attacks of tampering and fault injection in hardware-stored secret keys. sKRKA, a recently proposed security model modified from RKA, captures the real attacks in the BIP-32 HD wallet and the stealth address used in Monero. It was proved that ECDSA is insecure in the RKA model (ICISC 2015) and but secure in the sKRKA model (NSS 2019). In this work, we proved that GOST is insecure in both RKA and skRKA models, but SM2 is secure in both RKA and sKRKA models. This result well differentiates the security of ECDSA, SM2 and GOST, and demonstrates that Chinese SM2 is capable to construct secure cryptocurrency systems using BIP-32 HD wallet or stealth address, as secure as ECDSA, but outperforms ECDSA in resisting tampering or fault injection attacks.
Handong Cui, Xianrui Qin, Cailing Cai, Tsz Hon Yuen
TrustCom1
2020 LPPRS: New Location Privacy Preserving Schemes Based on Ring Signature over Mobile Social Networks
Cailing Cai, Tsz Hon Yuen, Handong Cui, Mingli Wu 0002, Siu-Ming Yiu
Inscrypt3
2020 Address-based Signature
Handong Cui, Tsz Hon Yuen
TrustCom1