EDBT 2026 Demo / reviewers in the wild / expert
Yiran Han
dblp:326/2529
· DBLP profile ↗
7ranked-venue papers
3as first author
7since 2021 · last 2026
0000-0002-6523-0080ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 3 · 2 first-author · 3 since 2021Security and privacy · 3 · 1 first-author · 3 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | A Secure and Efficient Handover Authentication and Key Agreement Protocol in Fog Computing
Yiran Han, Jianwei Liu 0001, Hua Guo 0001, Zongxiao Li, Shanyao Ren |
SACMAT | 1 |
| 2026 | An ultra-lightweight PUF and ASCON-based authentication and key agreement protocol for UAV-ground station and UAV-UAV communicationabstractAbstract Unmanned aerial vehicles (UAVs) have been increasingly integrated into diverse domains such as environmental monitoring, intelligent transportation, border surveillance, and military reconnaissance, giving rise to the broader concept of the Internet of Drones (IoD). However, this rapid proliferation also underscores the urgent need for secure and efficient communication mechanisms, as UAVs typically operate over public channels that are highly vulnerable to various security and privacy threats. To address these issues, authentication and key agreement (AKA) protocols have been introduced to enhance secure communication. However, most of the existing AKA protocols either incur high computation cost due to complex cryptographic primitives, or fail to provide resilience against attacks such as replay, impersonation, and ephemeral secret leakage. In this paper, we propose an ultra-lightweight AKA protocol that integrates physical unclonable function (PUF) with the lightweight authenticated encryption with associated data (AEAD) primitive ASCON. The protocol supports UAV registration over open channels, achieves mutual authentication between UAV and ground station, and extends to secure UAV-UAV communication with the assistance of the ground station. A formal proof under the real-or-random (ROR) model demonstrates the semantic security of the proposed protocol, while informal analysis confirms robustness against diverse attacks. Comprehensive performance evaluation shows that the total computation cost of the proposed protocol is approximately 2.391 ms, which is the lowest among the compared schemes. Specifically, it reduces computation cost by up to 69.0% compared with representative IoD authentication protocols and remains approximately 10.9% lower than existing ultra-lightweight designs. These results demonstrate that the proposed protocol achieves a superior balance between security strength and resource efficiency, making it particularly suitable for resource-constrained IoD environments. Hua Guo 0001, Jianwei Liu 0001, Yiran Han, Hutao Song |
Cybersecur. | 4 |
| 2026 | A resource-efficient authentication and key agreement protocol for smart gridabstractAbstract Smart grid (SG) facilitates our lives by providing more reliable electricity and enabling better integration of renewable energy sources. Currently, numerous authentication and key agreement (AKA) protocols have been proposed to secure SG communication. However, these solutions often result in considerable cost, making them inappropriate for resource-constrained SG environment. In this paper, we propose a secure and resource-efficient AKA protocol by employing lightweight cryptography primitives including authenticated encryption with associated data (AEAD) primitive ASCON, hash function and XOR operation. The ASCON primitive simultaneously provides data confidentiality, integrity and authenticity with low computation cost, making it suitable for employing in resource-constrained SG environment. The secret intermediate values in the protocol are designed as hash values that incorporate both long-term and short-term secrets, thereby providing enhanced security while further reducing cost. Moreover, a dynamic indexing method is deployed in the protocol to resist de-synchronization attack. The designed protocol performs secure mutual authentication and session key establishment between entities without relying on a central trusted authority. The proposed protocol is proven secure through rigorous security proof under the real-or-random model and formally verified by AVISPA tool. Theoretical performance analysis and simulation results indicate that the proposed protocol outperforms other related protocols due to its lightweight nature and adherence to all fundamental security attributes, making it suitable for deployment in smart grid environment. Hua Guo 0001, Hutao Song, Yapeng Wu, Jianwei Liu 0001, Yiran Han |
Cybersecur. | 6 |
| 2026 | Some Flaws of Authentication and Key Agreement Protocols Against Ephemeral Secret Leakage Attack for Smart GridabstractThe increasing complexity of the smart grid raises significant concerns regarding the security of smart grid communication. As a countermeasure, authentication and key agreement (AKA) protocol ensures the secure transmission of sensitive information between legitimate entities by achieving mutual authentication and establishing session keys. One of the most urgent and critical security threats in AKA protocol concerns ephemeral secret leakage (ESL) attack, due to its threat to session key secrecy. However, there remains a lack of systematic understanding of how to resist ESL attacks in smart grid environment. Therefore, we categorize the ESL attack into three different types, then conduct an in-depth analysis of their root causes and propose corresponding recommendations to mitigate it. To further illustrate the effectiveness of the recommendations, we design a secure and efficient AKA protocol based on elliptic curve cryptography accordingly. The proposed protocol is proven secure through rigorous security proof under the random oracle model and formally verified by AVISPA tool. Performance comparisons indicate that the proposed protocol outperforms other related protocols due to its lightweight nature and adherence to all fundamental security attributes, making it well-suited for deployment in resource-constrained smart grid environment. Hua Guo 0001, Jianwei Liu 0001, Yiran Han, Hutao Song |
IEEE Internet Things J. | 4 |
| 2026 | An Efficient and Secure Authentication and Key Agreement Protocol for Multi-Device Scenarios in Fog ComputingabstractThe fog computing paradigm enables mobile users to seamlessly interact with crowds of nearby IoT devices for low-latency services. However, existing authentication and key agreement (AKA) protocols suffer from critical limitations in this mobile context. While existing AKA schemes are optimized for mobile edge environments, they incur substantial overhead in multi-device scenarios: they require repeated authentication for each device and generate distinct session keys per user-device pair, leading to high key management complexity at scale. Furthermore, traditional one-to-many protocols are unsuitable for distributed fog environments due to their reliance on trusted central nodes (e.g., gateways or servers) and incompatible communication models. To address these issues, this paper proposes an efficient and secure authentication protocol for fog computing that integrates elliptic curve cryptography with secret sharing. Our solution enables a user to authenticate an entire group of devices managed by a semi-trusted fog node (honest-but-curious) through a single protocol execution, effectively eliminating the authentication bottleneck caused by scaling devices. Formal security proof under the Real-Or-Random (ROR) model is provided, along with informal analysis, demonstrating the protocol ensures forward secrecy, user anonymity, and resistance to a comprehensive set of attacks, including ephemeral secret leakage, key compromise impersonation, and replay attacks. Performance analysis confirms the scheme maintains low communication and computational overhead while achieving comprehensive security. Yiran Han, Jianwei Liu 0001, Hua Guo 0001, Zongxiao Li, Shanyao Ren |
IEEE Trans. Mob. Comput. | 1 |
| 2024 | An Enhanced Multifactor Authentication and Key Agreement Protocol in Industrial Internet of ThingsabstractThe Industrial Internet of Things (IIoT) is the application of the Internet of Things (IoT) in the industrial field. IIoT allows users to remotely access industrial equipment and the data in it, which also brings certain challenges to the security of industrial data. Authentication and key agreement protocols are very effective security technologies in the matter of protecting industrial data. There is a large amount of research work on authentication protocols in IIoT, but most of the protocols have security weaknesses. Recently, Rafique et al. proposed a multi-factor protocol in IIoT that can accomplish authentication and session key establishment through a gateway. Rafique et al. claimed that their protocol is secure, unfortunately, we carefully analyze the protocol of Rafique et al. and find some security flaws, i.e., it is vulnerable to insider attack and known session-specific temporary information (KSSTI) attack, and unable to provide forward security. We explore the factors of insecurity and propose an enhanced multi-factor secure authentication and key agreement protocol in IIoT. The new protocol improves the security of the protocol while using only symmetric cryptography, hash function, and XOR operation. Formal security analysis and informal security discussions demonstrate that the new protocol is resistant to a variety of known attacks. After performance analysis, our protocol has lower computational cost, and increases no significant communication cost, while providing more secure and robust properties. Yiran Han, Hua Guo 0001, Jianwei Liu 0001, Brou Bernard Ehui, Yapeng Wu |
IEEE Internet Things J. | 1 |
| 2024 | A Security-Enhanced Authentication and Key Agreement Protocol in Smart GridabstractWith the enablement of Internet of Things technology, the electrical grid is currently undergoing a drastic revolution, which is known as smart grid. Since massive sensitive data and control commands transmitted via public channels, the smart grid is challenged by various cyber threats. Authenticated key agreement protocols in smart grid effectively ensure the confidentiality and authentication of communication through mutual authentication and establishing session keys. In this article, we review the existing elliptic curve cryptography (ECC)-based authentication and key agreement protocols in smart gird and perform a security analysis of Hu et al.’s protocol. We exhibit that the protocol fails to resist key compromise impersonation (KCI) attack and cannot provide untraceability. Furthermore, we propose a security-enhanced authentication and key agreement protocol based on ECC, which performs registration, authentication, and key agreement phases over public channels to enable mutual authentication and to establish session keys. The protocol is also proved to be security-enhanced by formal proof and informal analysis. The performance analysis results demonstrate that the proposed protocol is comparable to other existing protocols while achieving enhanced security. Therefore, the protocol satisfies the deployment requirements for resource-constrained smart grid. Yapeng Wu, Hua Guo 0001, Yiran Han, Jianwei Liu 0001 |
IEEE Trans. Ind. Informatics | 3 |