Lingjia Meng

dblp:262/2893 · DBLP profile ↗
← Back
11ranked-venue papers
2as first author
9since 2021 · last 2025
0000-0002-6130-3668ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 8 · 1 first-author · 6 since 2021Computer networks · 2 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2025 HTM-PQC: Hardening Cryptography Keys Under the Trend of Post-Quantum Cryptography Migration on Industrial Internet
abstract
With the rapid expansion of Industry 4.0 technology, the proliferation of large-scale devices faces increasingly severe cyber threats, underscoring the critical importance of cryptographic technology for secure communication and authentication. However, cryptographic systems, as the bedrock of security, have faced a barrage of attacks in recent years, including potential threats from quantum computing and memory disclosure vulnerabilities. In this article, we focus on enhancing the security of two standard quantum-safe cryptographic algorithms, Dilithium and eXtended Merkle signature scheme (XMSS), by leveraging hardware transactional memory (HTM) to create a secure operational environment. Unlike traditional cryptography such as Rivest–Shamir–Adleman (RSA) and elliptic curve cryptography (ECC), Dilithium, and XMSS involve more and larger sensitive variables, rendering conventional solutions inadequate. By conducting a comprehensive sensitivity analysis of variables within the abovementioned algorithms, we confine sensitive operations to transactional execution regions and employ transaction-splitting technology for efficiency. Our prototype, utilizing Intel transactional synchronization extension (TSX), demonstrates robust protection against memory disclosure attacks with acceptable performance overheads. Notably, our security-enhanced Dilithium and XMSS software implementations, recommended by NIST, achieve an average throughput factor of 0.75 compared to the (unprotected) reference implementations.
Lingjia Meng, Yu Fu 0007, Fangyu Zheng, Ziqiang Ma, Jiankuo Dong, Jingqiang Lin 0001
IEEE Trans. Ind. Informatics1
2024 TLTracer: Dynamically Detecting Cache Side Channel Attacks with a Timing Loop Tracer
abstract
Recently, cache side-channel attacks have gained increasing attention due to the significant threat they pose to data security. As research advances, these attacks have become more covert and their impact has been widened. To mitigate the threat posed by cache side-channel attacks, numerous de-tection approaches have been proposed. However, they struggle to capture runtime features or depend heavily on hardware performance counters (HPCs), resulting in a significant number of false negatives or false positives. To address this issue, this paper proposes a broadly applicable runtime feature for identifying cache side-channel attack programs and introduces a dynamic binary analysis approach, TLTracer. TLTracer is runtime trace-based, independent of HPCs and capable of scanning and detecting whether a binary program is malicious before it is deployed in the real world. We implement a prototype of TLTracer and evaluate it with a set of malicious and benign programs. The results show that it can effectively detect the latest cache side-channel attacks without false positives, and offer increased resilience against adversarial evasion compared to other detection tools.
Lingjia Meng, Fangyu Zheng, Jingqiang Lin 0001, Shijie Jia 0001, Haoling Fan
ICC2
2024 TF-Timer: Mitigating Cache Side-Channel Attacks in Cloud through a Targeted Fuzzy Timer
abstract
Cache side-channel attacks pose a significant threat to the data security of multi-tenant public clouds. However, currently proposed defenses either lack transparency (requiring user involvement) or incur a significant performance penalty. This paper is motivated by our insightful observation for the behavior of cache side-channel attackers who employ rdtsc/rdtscp instructions for timing purposes. We have discerned a behavior pattern that enables comprehensive identification of potential attackers. Building upon this observation, we introduce TF -timer, which operates on the core principle of inspecting cache side-channel attacks using the pre-identified behavior pattern while obscuring the return values of rdtsc/rdtscp instructions. Our proposed technique preserves the properties of rdtsc/rdtscp, only blurring the attacker's timing to minimize the impact on other applications. We have implemented the prototype of TF-timer at the hypervisor layer. It is completely transparent to users and requires no hardware modifications. Our evaluation results demonstrate that TF -timer efficiently and precisely miti-gates cache side-channel attacks that exploit rdtsc/rdtscp for timing, with performance penalties within 1 %.
Shijie Jia 0001, Fangyu Zheng, Jingqiang Lin 0001, Lingjia Meng, Ziqiang Ma
WCNC6
2023 Protecting Private Keys of Dilithium Using Hardware Transactional Memory
Lingjia Meng, Yu Fu 0007, Fangyu Zheng, Ziqiang Ma, Dingfeng Ye, Jingqiang Lin 0001
ISC1
2023 Hydamc: A Hybrid Detection Approach for Misuse of Cryptographic Algorithms in Closed-Source Software
abstract
Cryptographic algorithms are fundamental to secure software development, but security vulnerabilities can arise during implementation, usage, and when calling third-party libraries. As security standards continue to evolve, software updates have become an inevitable trend, and detecting cryptographic algorithm misuse is crucial to ensure compliance with these standards during the update process. However, closed-source software presents challenges in detecting cryptographic algorithm misuse. To enhance the security ecosystem of software, we designed a hybrid detection approach for detecting misuses in closed-source software related to weak cryptographic algorithms, short keys, insecure working modes, and insecure padding modes. Our hybrid detection tool uses both static and dynamic detection methods to collect log information through a logging mechanism in binary executable files. The collected data is cleaned using a data cleaning strategy and analyzed to extract key features, generating test reports to help developers and experts identify cryptographic algorithm security issues. We tested 24 software applications from app stores and found that 62.5% had weak algorithm implementations or usage, 83.3% supported short keys, and 50% supported insecure padding modes. Finally, we provided actionable recommendations to mitigate identified issues.
Haoling Fan, Fangyu Zheng, Jingqiang Lin 0001, Lingjia Meng, Shijie Jia 0001
TrustCom4
2022 MoLE: Mitigation of Side-channel Attacks against SGX via Dynamic Data Location Escape
abstract
Numerous works have experimentally shown that Intel Software Guard eXtensions (SGX) is vulnerable to side-channel attacks (SCAs) and related threats, including transient execution attacks. These threats compromise the security of SGX-protected apps. Obfuscating data access patterns is a realistic way to guard against these threats. However, existing defenses impose either too much performance overhead or additional usage restrictions (such as multi-threading). Furthermore, these obfuscation schemes may no longer work if the attacker has the capacity to single-step the target application.
Fan Lang, Wei Wang 0314, Lingjia Meng, Jingqiang Lin 0001, Qiongxiao Wang, Linli Lu
ACSAC3
2021 SMCOS: Fast and Parallel Modular Multiplication on ARM NEON Architecture for ECC
Wei Wang 0314, Jingqiang Lin 0001, Yu Fu 0007, Lingjia Meng, Qiongxiao Wang
Inscrypt5
2021 VIRSA: Vectorized In-Register RSA Computation with Memory Disclosure Resistance
Yu Fu 0007, Wei Wang 0314, Lingjia Meng, Qiongxiao Wang, Yuan Zhao 0015, Jingqiang Lin 0001
ICICS (1)3
2021 Informer: Protecting Intel SGX from Cross-Core Side Channel Threats
Fan Lang, Wei Wang 0314, Lingjia Meng, Qiongxiao Wang, Jingqiang Lin 0001
ICICS (1)3
2019 Elaphurus: Ensemble Defense Against Fraudulent Certificates in TLS
Bingyu Li 0003, Wei Wang 0314, Lingjia Meng, Jingqiang Lin 0001, Xuezhong Liu, Congli Wang
Inscrypt3
2019 Evaluating the Cache Side Channel Attacks Against ECDSA
Ziqiang Ma, Quanwei Cai 0001, Jingqiang Lin 0001, Jiwu Jing, Dingfeng Ye, Lingjia Meng
Inscrypt6