EDBT 2026 Demo / reviewers in the wild / expert
Qionglu Zhang
dblp:237/1429
· DBLP profile ↗
7ranked-venue papers
1as first author
6since 2021 · last 2026
0000-0002-0927-0678ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 4 · 1 first-author · 3 since 2021Computer networks · 2 · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Tlcp hardening with formal analysis and post-quantum designabstractAbstract Transport Layer Cryptography Protocol (TLCP) is a secure communication protocol developed in China, featuring a dual-certificate architecture and incorporating ShangMi cryptographic algorithms. It has been widely deployed in security-critical domains such as finance, government, and energy. Despite its practical significance, TLCP did not undergo comprehensive formal analysis during its standardization process, leaving potential design-level vulnerabilities insufficiently explored. Moreover, the advent of quantum computing poses fundamental challenges to the classical cryptographic primitives employed by TLCP, motivating the need for both systematic security evaluation and post-quantum enhancements. To address these gaps, we first construct the comprehensive formal model of TLCP, covering certificate-based and identity-based cipher suites as well as its distinctive dual-certificate mechanism, under a realistic threat model and security assumptions that capture both classical and quantum adversaries. Based on this model, we conduct an automated security analysis using ProVerif, identifying nine potential attack vectors and deriving five concrete mitigation recommendations. Finally, motivated by the analysis results and the limitations of incremental fixes against quantum threats, we propose KEMTLCP, a post-quantum secure variant of TLCP that leverages key encapsulation mechanisms (KEMs) for both key exchange and authentication while preserving TLCP’s architectural principles through a novel explicit authentication mechanism. We further provide a security proof for the core authentication mechanism, show that KEMTLCP effectively mitigates the majority of identified vulnerabilities through formal analysis, and evaluate its practical performance. Jingnan He, Jiangxia Ge, Zhaoxuan Li, Qionglu Zhang, Li Zhou 0013, Xianhui Lu, Senlin Liu, Wenhua Gao |
Cybersecur. | 5 |
| 2024 | Telemedicine data secure sharing scheme based on heterogeneous federated learningabstractAbstract The forward triage characteristic of telemedicine highlights its importance again in the COVID-19 pandemic. Telemedicine can provide timely emergency response in the case of environmental or biological hazards, and the patient’s medical privacy data generated in this process can also accelerate the establishment of models for preventing and treating infectious diseases. However, the reuse process of telemedicine user privacy data based on federated learning also faces significant challenges. Differences in regions, economic levels, and grades lead to heterogeneous data and resource-constrained environments, seriously damaging the federated learning process. Besides, the weak password authentication of medical terminals and eavesdropping attacks on transmission channels may cause illegal access to terminals and platforms and leakage of sensitive data. This paper proposed a telemedicine data secure-sharing scheme based on heterogeneous federated learning. Specifically, we proposed a heterogeneous federated learning scheme with model alignment to guide telemedicine practice through the reuse of telemedicine data; in addition, we designed an SM9 threshold identity authentication scheme to guarantee that the patient’s medical privacy data is protected from leakage during the federated learning process. We evaluated our scheme using two third-party medical datasets. The evaluation results indicate that this scheme can still assist the federated learning process in resisting data heterogeneity and resource constraints with almost no performance cost. Nansen Wang, Ju Huang, Wei Ou, Wenbao Han, Qionglu Zhang |
Cybersecur. | 6 |
| 2023 | A data sharing method for remote medical system based on federated distillation learning and consortium blockchainabstractWith the development of Medical Internet of Things (MIoT) technology and the global COVID-19 pandemic, hospitals gain access to patients’ health data from remote wearable medical equipment. Federated learning (FL) addresses the difficulty of sharing data in remote medical systems. However, some key issues and challenges persist, such as heterogeneous health data stored in hospitals, which leads to high communication cost and low model accuracy. There are many approaches of federated distillation (FD) methods used to solve these problems, but FD is very vulnerable to poisoning attacks and requires a centralised server for aggregation, which is prone to single-node failure. To tackle this issue, we combine FD and blockchain to solve data sharing in remote medical system called FedRMD. FedRMD use reputation incentive to defend against poisoning attacks and store reputation values and soft labels of FD in Hyperledger Fabric. Experimenting on COVID-19 radiography and COVID-Chestxray datasets shows our method can reduce communication cost, and the performance is higher than FedAvg, FedDF, and FedGen. In addition, the reputation incentive can reduce the impact of poisoning attacks. Chengyu Zhu, Wei Ou, Wenbao Han, Qionglu Zhang |
Connect. Sci. | 6 |
| 2023 | A zero trust and blockchain-based defense model for smart electric vehicle chargersabstractElectric vehicles (EVs) have rapidly developed over the last decade due to their environmental benefits. As a key component of EVs, electric vehicle chargers are becoming increasingly digital and intelligent. However, due to the vast attack surface and the lack of systematic study, EV chargers and charging management cloud platforms are facing cyber security problems. These problems include weak cryptographic mechanisms, insecure data communication, and malicious firmware attacks. Through specific vulnerabilities, attackers can tamper with the data communication or replay network requests between EV chargers and cloud platforms. It will cause threats such as user-level privacy leakage, power fluctuations in the smart grid, and damage to Electric vehicles, damaging public life and property safety. Given the above, this paper proposes a security protection scheme incorporating blockchain, zero trust, and ShangMi cryptographic (SM) algorithms. The scheme uses Hyperledger Fabric for key management and trust evaluation event storage to guarantee the authenticity, non-repudiation, and tamper-proof of keys and events. In addition, zero trust is applied to secure valuable resources and enforce identity and access management (IAM) for accessing entities. We adopt the dynamic trust evaluation method to assess the trustworthiness of accessing entities in real time to implement dynamic authorization. Furthermore, the SM algorithms SM2, SM3, and SM4 are used to protect data confidentiality, integrity, and authenticity. Experimental results demonstrate that our scheme can effectively resist replay and tampering attacks, securing data communication between EV chargers and cloud platforms. And the performance of the cryptographic algorithm, blockchain system, and Secure Sockets Layer (SSL) meets Chinese national and industry standards. Peirong Li, Wei Ou, Haozhe Liang, Wenbao Han, Qionglu Zhang |
J. Netw. Comput. Appl. | 5 |
| 2022 | An overview on cross-chain: Mechanism, platforms, challenges and advancesabstractAfter years of in-depth development of blockchain, various blockchains with different characteristics and suitable for different application scenarios coexist in large numbers. Due to the isolation of blockchains and the high degree of heterogeneity between chains, value transfer and data communication between existing blockchains are facing unprecedented challenges, and the phenomenon of value isolated island is gradually emerging. The cross-chain technology of blockchain is an important technical means to realize the interconnection of blockchains and improve the interoperability and scalability of blockchains. In this paper, the development and application of blockchain cross-chain technology are studied, the background and significance of cross-chain technology are described, the research status of cross-chain technology is expounded, the current mainstream cross-chain technologies and cross-chain projects are introduced, the mentioned cross-chain technologies and cross-chain projects are analyzed and compared. In addition, this paper also summarizes the difficulties existing in the current cross-chain technology and provides solutions for reference, so as to lead to the discussion of the development trend of cross-chain technology, and finally complete the summary of the research content of the full text and the prospect of cross-chain technology. It is hoped that the relevant summary results can help relevant researchers and practitioners quickly grasp the research progress in the field of blockchain interoperability, and obtain relevant knowledge and application methods in this field. Wei Ou, Shiying Huang, Qionglu Zhang, Wenbao Han |
Comput. Networks | 4 |
| 2022 | MDEFTL: Incorporating Multi-Snapshot Plausible Deniability into Flash Translation LayerabstractConventional encryption solutions cannot defend against a coercive attacker who can capture the device owner, and force the owner to disclose keys used for decrypting sensitive data. To defend against such a coercive adversary, Plausibly Deniable Encryption (PDE) was introduced to allow the device owner to deny the very existence of sensitive data. The existing PDE systems built for computing devices equipped with flash storage media, are problematic, since they cannot defend against multi-snapshot adversaries, who may have access to the storage medium of a user's device at different points of time. In this article, we propose MDEFTL, a secure multi-snapshot PDE system for mobile devices which incorporates plausible deniability into Flash Translation Layer (FTL). MDEFTL is the first practical design which integrates multi-snapshot PDE into FTL, a pervasively deployed layer in literally all the current mobile devices. A salient advantage of MDEFTL lies in its capability of achieving multi-snapshot plausible deniability while being able to accommodate the special nature of NAND flash as well as eliminate deniability compromises from it. We implemented MDEFTL using an open-source NAND flash controller. The experimental results show that, compared to conventional encryption which does not provide deniability, our MDEFTL only incurs a small overhead. Shijie Jia 0001, Qionglu Zhang, Luning Xia, Jiwu Jing, Peng Liu 0005 |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2018 | Ensuring data confidentiality via plausibly deniable encryption and secure deletion - a surveyabstractEnsuring confidentiality of sensitive data is of paramount importance, since data leakage may not only endanger data owners’ privacy, but also ruin reputation of businesses as well as violate various regulations like HIPPA and Sarbanes-Oxley Act. To provide confidentiality guarantee, the data should be protected when they are preserved in the personal computing devices (i.e., confidentiality during their lifetime ); and also, they should be rendered irrecoverable after they are removed from the devices (i.e., confidentiality after their lifetime ). Encryption and secure deletion are used to ensure data confidentiality during and after their lifetime, respectively. This work aims to perform a thorough literature review on the techniques being used to protect confidentiality of the data in personal computing devices, including both encryption and secure deletion. Especially for encryption, we mainly focus on the novel plausibly deniable encryption (PDE), which can ensure data confidentiality against both a coercive (i.e., the attacker can coerce the data owner for the decryption key) and a non-coercive attacker. Qionglu Zhang, Shijie Jia 0001, Bing Chang, Bo Chen 0028 |
Cybersecur. | 1 |