EDBT 2026 Demo / reviewers in the wild / expert
Feng Hao 0001
dblp:37/2189-1
· DBLP profile ↗
54ranked-venue papers
11as first author
21since 2021 · last 2026
0000-0002-8664-5074ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 39 · 9 first-author · 15 since 2021Systems, architecture and hardware · 6 · 1 first-author · 1 since 2021Computer networks · 4 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 3 since 2021Artificial intelligence and machine learning · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | CP-SuperSpartan: commit-and-prove SNARKs for customizable constraint systems
Zibo Zhou, Zongyang Zhang, Feng Hao 0001, Jianwei Liu 0001 |
Frontiers Comput. Sci. | 3 |
| 2025 | QV-net: Decentralized Self-Tallying Quadratic Voting with Maximal Ballot SecrecyabstractDecentralized e-voting enables secure and transparent elections without relying on trusted authorities, with blockchain emerging as a popular platform. It has compelling applications in Decentralized Autonomous Organizations (DAOs), where governance relies on voting with blockchain-issued tokens. Quadratic voting (QV), a mechanism that mitigates the dominance of large token holders, has been adopted by many DAO elections to enhance fairness. However, current QV systems deployed in practice publish voters' choices in plaintext with digital signatures. The open nature of all ballots comprises voter privacy, potentially affecting voters' honest participation. Prior research proposes using cryptographic techniques to encrypt QV ballots, but they work in a centralized setting, relying on a trusted group of tallying authorities to administrate an election. However, in DAO voting, there is no trusted third party. Zibo Zhou, Zongyang Zhang, Feng Hao 0001, Zulkarnaim Masyhur |
CCS | 3 |
| 2025 | SoK: Security of EMV Contactless Payment SystemsabstractThe widespread adoption of EMV (Europay, Mastercard, and Visa) contactless payment systems has greatly improved convenience for both users and merchants. However, this growth has also exposed significant security challenges. This SoK provides a comprehensive analysis of security vulnerabilities in EMV contactless payments, particularly within the open-loop systems used by Visa and Mastercard. We categorize attacks into seven attack vectors across three key areas: application selection, cardholder authentication, and transaction authorization. We replicate the attacks on Visa and Mastercard protocols using our experimental platform to determine their practical feasibility and offer insights into the current security landscape of contactless payments. Our study also includes a detailed evaluation of the underlying protocols, along with a comparative analysis of Visa and Mastercard, highlighting vulnerabilities and recommending countermeasures. Mahshid Mehr Nezhad, Feng Hao 0001, Gregory Epiphaniou, Carsten Maple, Timur Yunusov |
EuroS&P | 2 |
| 2025 | Privacy-Preserving and Traceable Functional Encryption for Inner Product in Cloud ComputingabstractCloud computing is a distributed infrastructure that centralizes server resources on a platform in order to provide services over the internet. Traditional public-key encryption protects data confidentiality in cloud computing, while functional encryption provides a more fine-grained decryption method, which only reveals a function of the encrypted data. However, functional encryption in cloud computing faces the problem of key sharing. In order to trace malicious users who share keys with others, traceable FE-IP (TFE-IP) schemes were proposed where the key generation center (KGC) knows users’ identities and binds them with different secret keys. Nevertheless, existing schemes fail to protect the privacy of users’ identities. The fundamental challenge to construct a privacy-preserving TFE-IP scheme is that KGC needs to bind a key with a user's identity without knowing the identity. To balance privacy and accountability in cloud computing, we propose the concept of privacy-preserving traceable functional encryption for inner product (PPTFE-IP) and give a concrete construction which offers the features: (1) To prevent key sharing, both a user's identity and a vector are bound together in the key; (2) The KGC and a user execute a two-party secure computing protocol to generate a key without the former knowing anything about the latter's identity; (3) Each user can ensure the integrity and correctness of his/her key through verification; (4) The inner product of the two vectors embedded in a ciphertext and in his/her key can be calculated by an authorized user; (5) Only the tracer can trace the identity embedded in a key. We formally reduce the security of the proposed PPTFE-IP to well-known complexity assumptions, and conduct an implementation to evaluate its efficiency. The novelty of our scheme is to protect the user's privacy and provide traceability if required. Muyao Qiu, Jinguang Han, Feng Hao 0001, Ge Wu 0001 |
IEEE Trans. Cloud Comput. | 3 |
| 2024 | Camel: E2E Verifiable Instant Runoff Voting without Tallying AuthoritiesabstractInstant Runoff Voting (IRV) is one example of ranked-choice voting. It provides many known benefits when used in elections, such as minimising vote splitting, ensuring few votes are wasted, and providing resistance to strategic voting. However, the voting and tallying procedures for IRV are much more complicated than those of plurality and are both error-prone and tedious. Many automated systems have been proposed to simplify these procedures in IRV. Some of these also employ cryptographic techniques to protect the secrecy of ballots and enable verification of the tally. Nearly all of these cryptographic systems require a set of trustworthy tallying authorities (TAs) to perform the decryption of votes and/or running of mix servers, which adds significant complexity to the implementation and election management. We address this issue by proposing Camel: an E2E verifiable solution for IRV that requires no TAs. Camel employs a novel representation and a universally verifiable shifting procedure for ballots that facilitate the elimination of candidates as required in an IRV election. We combine these with a homomorphic encryption scheme and zero-knowledge proofs to protect the secrecy of the ballots and enable any party to verify the well-formedness of the ballots and the correctness of the tally in an IRV election. We examine the security of Camel and prove it maintains ballot secrecy by limiting the learned information (namely the tally) against a set of colluding voters. Luke Harrison, Samiran Bag, Feng Hao 0001 |
AsiaCCS | 3 |
| 2024 | Owl: An Augmented Password-Authenticated Key Exchange Scheme
Feng Hao 0001, Samiran Bag, Liqun Chen 0002, Paul C. van Oorschot |
FC (2) | 1 |
| 2024 | A Publicly Verifiable Optimistic Fair Exchange Protocol Using Decentralized CP-ABEabstractAbstract Fair exchange is a challenging problem for two mutually distrusting players. It is widely known that fair exchange is impossible without a trusted third party (TTP). However, relying on a single TTP can cause a single-point failure. An intuitive idea is to adopt multiple TTPs to distribute trust. This paper constructs a two-party optimistic fair exchange (OFE) protocol using decentralized ciphertext-policy attribute-based encryption (CP-ABE), achieving decentralized TTPs. This is achievable because decentralized CP-ABE ciphertext supports a nested access control policy. A nested access control policy fits perfectly in a fair exchange protocol which contains multiple roles (i.e. players and TTPs). Further, we apply non-interactive zero knowledge proofs to prove the well-formedness of ciphertexts, so as to enforce players to follow the protocol specification honestly. Consequently, we construct an OFE protocol in which each player’s operations are publicly verifiable without revealing secret information. Also, we obtain decentralized TTPs with optimism (i.e. the TTPs are involved only when arbitration is required), autonomy (i.e. the TTPs do not need to interact with each other), statelessness (i.e. the TTPs do not need to store data for the exchange protocol) and verifiability (i.e. the TTPs are publicly verifiable). Compared with previous work, our protocol assumes only a public communication channel and each party’s operations are publicly verifiable. Besides, it achieves a favorable $O(n)$ verification complexity in the normal case, where $n$ is the number of TTPs. Finally, we present a proof-of-concept implementation to demonstrate the feasibility. Liang Zhang 0043, Haibin Kan, Feiyang Qiu, Feng Hao 0001 |
Comput. J. | 4 |
| 2024 | On the feasibility of E2E verifiable online voting - A case study from Durga Puja trialabstractIndia is the largest democracy by population and has one of the largest deployments of e-voting in the world for national elections. However, the e-voting machines used in India are not end-to-end (E2E) verifiable. The inability to verify the tallying integrity of an election by the public leaves the outcome open to disputes. E2E verifiable e-voting systems are commonly regarded as the most promising solution to address this problem, but they had not been implemented or trialed in India. It was unclear whether such systems would be usable and practical to the Indian people. Previous works such as Helios require a set of tallying authorities (TAs) to perform the decryption and tallying operations, but finding and managing TAs can prove difficult. This paper presents a TA-free E2E verifiable online voting system based on the DRE-ip protocol. In collaboration with the local authority of New Town, Kolkata, India, we conducted an online voting trial as part of the 2022 Durga Puja festival celebration, during which residents of New Town were invited to use mobile phones to vote for their favorite pujas (festival decorations) in an E2E verifiable manner. 543 participants attended the Durga Puja trial and 95 of them provided feedback by filling in an anonymous survey after voting. Based on the voter feedback, participants generally found the system easy to use. This was the first time that an E2E online voting system had been built and tested in India, suggesting its feasibility for non-statutory voting scenarios. Horia Druliac, Matthew Bardsley, Chris Riches, Christian Dunn, Luke Harrison, Bimal K. Roy, Feng Hao 0001 |
J. Inf. Secur. Appl. | 7 |
| 2024 | Spoofing Against Spoofing: Toward Caller ID Verification in Heterogeneous Telecommunication SystemsabstractCaller ID spoofing is a global industry problem and often acts as a critical enabler for telephone fraud. To address this problem, the Federal Communications Commission has mandated telecom providers in the U.S. to implement STIR/SHAKEN, an industry-driven solution based on digital signatures. STIR/SHAKEN relies on a public key infrastructure (PKI) to manage digital certificates, but scaling up this PKI for the global telecom industry is extremely difficult, if not impossible. Furthermore, it only works with IP-based systems (e.g., SIP), leaving the traditional non-IP systems (e.g., SS7) unprotected. So far the alternatives to the STIR/SHAKEN have not been sufficiently studied. In this article, we propose a PKI-free solution, called Caller ID Verification (CIV). CIV authenticates the caller ID based on a challenge-response process instead of digital signatures, hence requiring no PKI. It supports both IP and non-IP systems. Perhaps counter-intuitively, we show that number spoofing can be leveraged, in conjunction with Dual-tone Multi-frequency, to efficiently implement the challenge-response process, i.e., using spoofing to fight against spoofing. We implement CIV for Voice over Internet Protocol, cellular, and landline phones across heterogeneous networks (SS7/SIP) by only updating the software on the user’s phone. This is the first caller ID authentication solution with working prototypes for all three types of telephone systems in the current telecom architecture. Finally, we show how the implementation of CIV can be optimized by integrating it into telecom clouds as a service, which users may subscribe to. Shen Wang 0008, Mahshid Delavar, Muhammad Ajmal Azad, Farshad Nabizadeh, Feng Hao 0001 |
ACM Trans. Priv. Secur. | 6 |
| 2024 | ECF-IDS: An Enhanced Cuckoo Filter-Based Intrusion Detection System for In-Vehicle NetworkabstractWith the rapid advancement of vehicle connectivity and intelligent technologies, an increasing number of vehicles are now connected to the Internet. However, these connected vehicles are vulnerable to malicious attacks, posing serious security events. In particular, the in-vehicle controller area network (CAN) bus has witnessed a rise in incidents involving various network attacks, such as denial of service (DoS), fuzzy attacks, and gear attacks. In response, this paper proposes an enhanced cuckoo filter-based intrusion detection system (ECF-IDS) for in-vehicle network. The ECF-IDS builds on an enhanced version of the cuckoo filter. It first utilizes the cuckoo filter to establish two lists (a normal list and an intrusion list) based on the labeled dataset using Car Hacking Dataset (CHD) and can-train-and-test dataset. Then, the input CAN traffic is sequentially compared with these two lists, where the conflicting traffic is further identified using a BERT-based model. The ECF-IDS is experimentally validated using the CHD and can-train-and-test dataset, demonstrating higher detection efficiency, lower resource consumption, and detection success exceeding 99% compared to other algorithms presented in previous studies. Furthermore, we conducted real in-vehicle environment testing on the ECF-IDS model, and its detection performance proved to be excellent. Yue Cao 0002, Hassan Jalil Hadi, Feng Hao 0001 |
IEEE Trans. Netw. Serv. Manag. | 4 |
| 2023 | Spying on the Spy: Security Analysis of Hidden Cameras
Samuel Herodotou, Feng Hao 0001 |
NSS | 2 |
| 2023 | Security Analysis of Mobile Point-of-Sale Terminals
Mahshid Mehr Nezhad, Elliot Laidlaw, Feng Hao 0001 |
NSS | 3 |
| 2022 | SoK: Password-Authenticated Key Exchange - Theory, Practice, Standardization and Real-World LessonsabstractPassword-authenticated key exchange (PAKE) is a major area of cryptographic protocol research and practice. Many PAKE proposals have emerged in the 30 years following the original 1992 Encrypted Key Exchange (EKE), some accompanied by new theoretical models to support rigorous analysis. To reduce confusion and encourage practical development, major standards bodies including IEEE, ISO/IEC and the IETF have worked towards standardizing PAKE schemes, with mixed results. Challenges have included contrasts between heuristic protocols and schemes with security proofs, and subtleties in the assumptions of such proofs rendering some schemes unsuitable for practice. Despite initial difficulty identifying suitable use cases, the past decade has seen PAKE adoption in numerous large-scale applications such as Wi-Fi, Apple's iCloud, browser synchronization, e-passports, and the Thread network protocol for Internet of Things devices. Given this backdrop, we consolidate three decades of knowledge on PAKE protocols, integrating theory, practice, standardization and real-world experience. We provide a thorough and systematic review of the field, a summary of the state-of-the-art, a taxonomy to categorize existing protocols, and a comparative analysis of protocol performance using representative schemes from each taxonomy category. We also review real-world applications, summarize lessons learned, and highlight open research problems related to PAKE protocols. Feng Hao 0001, Paul C. van Oorschot |
AsiaCCS | 1 |
| 2022 | VERICONDOR: End-to-End Verifiable Condorcet Voting without Tallying AuthoritiesabstractCondorcet voting, first proposed by Marquis de Condorcet in the 18th century, chooses a winner of an election as one that defeats every other candidate by a simple majority. According to Condorcet's criterion, a Condorcet winner is the socially optimal choice in a multi-candidate election. However, despite the crucial importance of this voting system in social-choice theory, it has not been widely used in practical applications. This is partly due to the complex tallying procedure, and also the fact that several candidates may form a tie. Existing systems that provide online Condorcet voting services in the real world try to speed up the tallying process by collecting and tallying Condorcet ballots in a digital form. However, they require voters to completely trust the server. In this paper, we propose VERICONDO, the first end-to-end verifiable Condorcet e-voting system without any tallying authorities. Our system allows a voter to fully verify the tallying integrity without involving any trustworthy tallying authorities and provides strong protection of the ballot secrecy. One main challenge in our work lies in proving the well-formedness of an encrypted ballot while being able to tally the ballots in a publicly verifiable yet privacy-preserving manner. We overcome this challenge by adopting a pairwise comparison matrix and applying a novel vector-sum technique to achieve exceptional efficiency. The overall computational cost per ballot is O (n2) where n is the number of candidates. This is probably the best that one may hope for given the use of a n x n matrix to record a Condorcet ballot. In case of a tie, we show how to apply known Condorcet methods to break the tie in a publicly verifiable manner. Finally, we present a prototype implementation and benchmark performance to show the feasibility of our system. Luke Harrison, Samiran Bag, Hang Luo 0001, Feng Hao 0001 |
AsiaCCS | 4 |
| 2022 | A New Leakage Resilient Symmetric Searchable Encryption Scheme for Phrase SearchabstractSymmetric searchable encryption (SSE) schemes are preferred over asymmetric ones for their lower computational cost. Owing to the big data size of most of the cloud applications, SSE with keyword search often yields a large number of search results matching the search criterion, but only a small portion of them is of actual interest. This results in unnecessary increase of network traffic. A customized search against a phrase instead of keywords can yield more specific and relevant search results and can reduce the network traffic. This motivates the idea of phrase search in SSE. Most of the existing symmetric key searchable encryption schemes either do not support phrase search or have unwanted leakage associated with them. In this paper, we propose a symmetric key searchable encryption scheme for phrase search that minimizes the leakage of information from search pattern and access pattern. We propose a probabilistic trapdoor generation algorithm for phrase search and thereby preve nt the leakage due to search pattern. In earlier SSE based schemes, an honest-but-curious server could always learn about the position of the sentences and keywords in the encrypted text after the search operation is performed. This is referred to as the leakage from access pattern. This may turn out to be a significant security concern owing to the prior knowledge of positions of certain sentences and keywords in certain documents. In this paper, we provide the access pattern secure encryption scheme such that, an honest-but-curious cloud server could not learn anything about the position of the phrase in the sentence even after the search. We implement a prototype of our scheme and validate it against commercial data and provide security and performance analysis to demonstrate its practicality. Samiran Bag, Indranil Ghosh Ray, Feng Hao 0001 |
SECRYPT | 3 |
| 2022 | 1-Round Distributed Key Generation With Efficient Reconstruction Using Decentralized CP-ABEabstractDistributed key generation (DKG) is widely used in multi-party computation and decentralized applications. DKG has two phases, namely sharing and reconstruction. Most of the prior DKG protocols need at least 2 rounds for the sharing phase, in case some party raises a dispute. The existing 1-round DKG protocol [Fouqueet al., PKC’01], built based on a publicly verifiable secret sharing (PVSS) scheme, assumes a static adversary model and its reconstruction phase requires$O(n^{2})$communication complexity. Motivated by the observation that a ciphertext-policy attribute-based encryption (CP-ABE) scheme hides secret sharing (SS) in ciphertext, we utilize decentralized CP-ABE to achieve the first adaptively secure 1-round DKG protocol. Firstly, a CP-ABE scheme enables the ciphertexts in DKG to be externally decrypted, making our protocol superior to the PVSS-based DKG protocol in reconstruction. The communication and computation complexities are both lowered to$O(n)$thanks to the constant-sized decryption key and the proposed batch decryption. The use of CP-ABE also makes our DKG protocol storage-friendly, i.e., the parties store no ciphertext after the sharing phase. Secondly, we add non-interactive zero-knowledge (NIZK) proofs to make the CP-ABE ciphertext publicly verifiable by leveraging the sigma protocol and the Fiat-Shamir heuristic. Thirdly, we demonstrate our protocol’s feasibility by presenting a proof-of-concept implementation over Ethereum, which is used as a public channel and a trustworthy computation platform. The implementation is a non-trivial task due to Ethereum’s incompatibility with the bilinear mapping group. Liang Zhang 0043, Feiyang Qiu, Feng Hao 0001, Haibin Kan |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2021 | OPay: an Orientation-based Contactless Payment Solution Against Passive AttacksabstractThe usage of contactless payment has surged in recent years, especially during the Covid19 pandemic. A Passive relay (PR) attack against a contactless card is a well-known threat, which has been extensively studied in the past with many solutions available. However, with the mass deployment of mobile point-of-sale (mPoS) devices, there emerges a new threat, which we call mPoS-based passive (MP) attacks. In an MP attack, the various components required in a PR attack, including an NFC reader, a wireless link, a remote card emulator, and a remote payment terminal, are conveniently combined into one compact device, hence the attack becomes much easier. Since the attacker and the victim are in the same location, the previous distance bounding or ambient sensor-based solutions are no longer effective. In this paper, we propose a new orientation-based payment solution called OPay. OPay builds on the observation that when a user makes a legitimate contactless payment, the card and the terminal surface are naturally aligned, but in an attack scenario, this situation is less likely to occur. This allows us to distinguish the legitimate payments from passive attacks based on measuring the alignment of orientations. We build a concrete prototype using two Arduino boards embedded with NFC and motion sensors to act as a card and a payment terminal respectively. To evaluate the feasibility, we recruited twenty volunteers in a user study. Participants generally find OPay easy to use, fast and reliable. Experiments show that OPay can substantially reduce the attack success rate by 85-99% with little inconvenience to real users. To our best knowledge, OPay is the first solution that can prevent both the PR and MP attacks, while preserving the existing usage model in contactless payment. Mahshid Mehr Nezhad, Feng Hao 0001 |
ACSAC | 2 |
| 2021 | Sharing is Caring: A collaborative framework for sharing security alerts
Muhammad Ajmal Azad, Samiran Bag, Feng Hao 0001 |
Comput. Commun. | 4 |
| 2021 | Formal modelling and security analysis of bitcoin's payment protocol
Paolo Modesti, Siamak F. Shahandashti, Patrick McCorry, Feng Hao 0001 |
Comput. Secur. | 4 |
| 2021 | Privacy-preserving Crowd-sensed Trust Aggregation in the User-centeric Internet of People NetworksabstractToday we are relying on Internet technologies for numerous services, for example, personal communication, online businesses, recruitment, and entertainment. Over these networks, people usually create content, a skillful worker profile, and provide services that are normally watched and used by other users, thus developing a social network among people termed as the Internet of People. Malicious users could also utilize such platforms for spreading unwanted content that could bring catastrophic consequences to a social network provider and the society, if not identified on time. The use of trust management over these networks plays a vital role in the success of these services. Crowd-sensing people or network users for their views about certain content or content creators could be a potential solution to assess the trustworthiness of content creators and their content. However, the human involvement in crowd-sensing would have challenges of privacy preservation and preventing intentional assignment of the fake high score given to certain user/content. To address these challenges, in this article, we propose a novel trust model that evaluates the aggregate trustworthiness of the content creator and the content without compromising the privacy of the participating people in a crowdsource group. The proposed system has inherent properties of privacy protection of participants, performs operations in the decentralized setup, and considers the trust weights of participants in a private and secure way. The system ensures privacy of participants under the malicious and honest-but-curious adversarial models. We evaluated the performance of the system by developing a prototype and applying it to different real data from different online social networks. Muhammad Ajmal Azad, Charith Perera, Samiran Bag, Mahmoud Barhamgi, Feng Hao 0001 |
ACM Trans. Cyber Phys. Syst. | 5 |
| 2021 | Anti-Counterfeiting for Polymer Banknotes Based on Polymer Substrate FingerprintingabstractPolymer banknotes are the trend for printed currency and have been adopted by more than fifty countries worldwide. However, over the past years, the quantity of polymer counterfeits has been increasing, so has the quality of counterfeits. This shows that the initial advantage of bringing a new polymer technology to fight against counterfeiting is reducing. To maintain one step ahead of counterfeiters, we propose a novel anti-counterfeiting technique called Polymer Substrate Fingerprinting (PSF). Our technique is built based on the observation that the opacity coating, a critical step during the production of polymer notes, is a stochastic manufacturing process, leaving uneven thickness in the coating layer and the random dispersion of impurities from the ink. The imperfections in the coating layer result in random translucent patterns when a polymer banknote is back-lit by a light source. We show these patterns can be reliably captured by a commodity negative-film scanner and processed into a compact fingerprint to uniquely identify each banknote. Using an extensive dataset of 6,200 sample images collected from 340 UK banknotes, we show that our method can reliably authenticate banknotes, and is robust against rough daily handling of banknotes. Furthermore, we show the extracted fingerprints contain around 900 bits of entropy, which makes it extremely scalable to identify every polymer note circulated globally. As compared with previous or existing anti-counterfeiting mechanisms for banknotes, our method has a distinctive advantage: it ensures that even in the extreme case when counterfeiters have procured the same printing equipment and ink as used by a legitimate government, counterfeiting banknotes remains infeasible because of the difficulty to replicate a stochastic manufacturing process. Shen Wang 0008, Ehsan Toreini, Feng Hao 0001 |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2020 | Decentralized Self-Enforcing Trust Management System for Social Internet of ThingsabstractThe Internet of Things (IoT) is the network of connected computing devices that have the ability to transfer valued data between each other via the Internet without requiring human intervention. In such a connected environment, the social IoT (SIoT) has become an emerging trend where multiple IoT devices owned by users support communication within a social circle. Trust management in the SIoT network is imperative as trusting the information from compromised devices could lead to serious compromises within the network. It is important to have a mechanism where the devices and their users evaluate the trustworthiness of other devices and users before trusting the information sent by them. The privacy preservation, decentralization, and self-enforcing management without involving trusted third parties are the fundamental challenges in designing a trust management system for SIoT. To fulfill these challenges, this article presents a novel framework for computing and updating the trustworthiness of participants in the SIoT network in a self-enforcing manner without relying on any trusted third party. The privacy of the participants in the SIoT is protected by using homomorphic encryption in the decentralized setting. To achieve the properties of self-enforcement, the trust score of each device is automatically updated based on its previous trust score and the up-to-date tally of the votes by its peers in the network with zero-knowledge proofs (ZKPs) to enforce that every participant follows the protocol honestly. We evaluate the performance of the proposed scheme and present evaluation benchmarks by prototyping the main functionality of the system. The performance results show that the system has a linear increase in computation and communication overheads with more participants in the network. Furthermore, we prove the correctness, privacy, and security of the proposed system under a malicious adversarial model. Muhammad Ajmal Azad, Samiran Bag, Feng Hao 0001, Andrii Shalaginov |
IEEE Internet Things J. | 3 |
| 2020 | SEAL: Sealed-Bid Auction Without AuctioneersabstractWe propose the first auctioneer-free sealed-bid auction protocol with a linear computation and communication complexity O(c), c being the bit length of the bid price. Our protocol, called Self-Enforcing Auction Lot (SEAL), operates in a decentralized setting, where bidders jointly compute the maximum bid while preserving the privacy of losing bids. In our protocol, we do not require any secret channels between participants. All operations are publicly verifiable; everyone including third-party observers is able to verify the integrity of the auction outcome. Upon learning the highest bid, the winner comes forward with a proof to prove that she is the real winner. Based on the proof, everyone is able to check if there is only one winner or there is a tie. While our main protocol works with the first-price sealed-bid, it can be easily extended to support the second-price sealed-bid (also known as the Vickrey auction), revealing only the winner and the second highest bid, while keeping the highest bid and all other bids secret. To the best of our knowledge, this work establishes to date the best computation and communication complexity for sealed-bid auction schemes without involving any auctioneer. Samiran Bag, Feng Hao 0001, Siamak F. Shahandashti, Indranil Ghosh Ray |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2020 | Authentic Caller: Self-Enforcing Authentication in a Next-Generation NetworkabstractThe Internet of Things (IoT) or the cyber-physical system (CPS) is the network of connected devices, things, and people that collect and exchange information using the emerging telecommunication networks (4G, 5G IP-based LTE). These emerging telecommunication networks can also be used to transfer critical information between the source and destination, informing the control system about the outage in the electrical grid, or providing information about the emergency at the national express highway. This sensitive information requires authorization and authentication of source and destination involved in the communication. To protect the network from unauthorized access and to provide authentication, the telecommunication operators have to adopt the mechanism for seamless verification and authorization of parties involved in the communication. Currently, the next-generation telecommunication networks use a digest-based authentication mechanism, where the call-processing engine of the telecommunication operator initiates the challenge to the request-initiating client or caller, which is being solved by the client to prove his credentials. However, the digest-based authentication mechanisms are vulnerable to many forms of known attacks, e.g., the man-in-the-middle (MITM) attack and the password guessing attack. Furthermore, the digest-based systems require extensive processing overheads. Several public-key infrastructure (PKI)-based and identity-based schemes have been proposed for the authentication and key agreements. However, these schemes generally require a smart card to hold long-term private keys and authentication credentials. In this article, we propose a novel self-enforcing authentication protocol for the session-initiation-protocol-based next-generation network, based on a low-entropy shared password without relying on any PKI or the trusted third party system. The proposed system shows effective resistance against various attacks, e.g., MITM, replay attack, password guessing attack, etc. We analyze the security properties of the proposed scheme in comparison to the state of the art. Muhammad Ajmal Azad, Samiran Bag, Charith Perera, Mahmoud Barhamgi, Feng Hao 0001 |
IEEE Trans. Ind. Informatics | 5 |
| 2019 | E2E Verifiable Borda Count Voting System without Tallying AuthoritiesabstractAn end-to-end verifiable (E2E) voting system enables candidates, voters and observers to monitor the integrity of an election process and verify the results without relying on trusted systems. In this paper, we propose a DRE-based Borda count e-voting system called DRE-Borda. The proposed system is E2E verifiable without involving any tallying authorities. Furthermore, it outputs only the total score a candidate gets without revealing any other information such as the breakdown of scores with respect to different ranks. This reduces the information leakage from the tallying result to the minimum, hence effectively preventing Italian attacks. When the DRE machine is completely compromised, the integrity of the tallying result is still preserved and what an adversary can learn from a compromised machine is strictly limited to the partial tally at the time of compromise. Samiran Bag, Muhammad Ajmal Azad, Feng Hao 0001 |
ARES | 3 |
| 2019 | SSR'19: The 5th Conference on Security Standardisation ResearchabstractThe 5th conference on Security Standardisation Research (SSR'19) is in London, UK, on 11 November 2019, co-located with the ACM Conference on Computer and Communications Security 2019 (CCS'19). This conference aims to provide a preferred venue for the discussion of all topics related to security standardisation, covering both theory and practice. This year's program includes two invited keynote addresses to shed light on security standardisation from both industrial and academic perspectives, a panel discussion on blockchain standardisation and the presentation of seven original research papers selected from twenty submissions. The SSR'19 Conference Proceedings are available in the ACM DL at: https://dl.acm.org/citation.cfm?id=3338500. Maryam Mehrnezhad, Thyla van der Merwe, Feng Hao 0001 |
CCS | 3 |
| 2019 | Consumer-facing technology fraud: Economics, attack methods and potential solutions
Mohammed Aamir Ali, Muhammad Ajmal Azad, Mario Parreño Centeno, Feng Hao 0001, Aad P. A. van Moorsel |
Future Gener. Comput. Syst. | 4 |
| 2019 | PriVeto: a fully private two-round veto protocolabstractIn 2006, Hao and Zieliński presented a two‐round veto protocol named anonymous veto network (AV‐net), which is exceptionally efficient in terms of the number of rounds, computation and bandwidth usage. However, AV‐net has two generic issues: (i) a participant who has submitted a veto can find out whether she is the only one who vetoed; (ii) the last participant who submits her input can pre‐compute the Boolean‐OR result before submission, and may amend her input based on that knowledge. These two issues generally apply to any multi‐round veto protocol where participants commit their input in the last round. In this study, the authors propose a novel solution to address both issues within two rounds, which are the best possible round efficiency for a veto protocol. Their new private veto protocol, called PriVeto, has similar system complexities to AV‐net, but it binds participants to their inputs in the very first round, eliminating the possibility of runtime changes to any of the inputs. At the end of the protocol, participants are strictly limited to learning nothing more than the output of the Boolean‐OR function and their own inputs. Samiran Bag, Muhammad Ajmal Azad, Feng Hao 0001 |
IET Inf. Secur. | 3 |
| 2019 | TrustVote: Privacy-Preserving Node Ranking in Vehicular NetworksabstractThe Internet of Vehicles is the network of connected vehicles and transport infrastructure units [roadside units (RSUs)], which utilizes emerging wireless systems (4G, 5G, LTE) for the communication and sharing of information. The network of connected vehicles enables users to disseminate critical information about events happening on the road (for example, accidents, traffic congestions, and hazards). The exchange of information between vehicles and RSUs could improve the driving experience and road safety, as well as help drivers to identify the hazardous and safe routes in a timely manner. The sharing of critical information between vehicles is advantageous to the driver; however, at the same time, malicious actors could mislead drivers by spreading fraudulent and fake messages. Fraudulent messages can have a negative impact on the infrastructure, and more significantly, have potential to cause threats to life. It is, therefore, essential that vehicles can evaluate the credibility of those who send messages (vehicles or RSUs) before taking any action. In this paper, we present TrustVote, a collaborative crowdsourcing-based vehicle reputation system that enables vehicles to evaluate the credibility of other vehicles in a connected vehicular network. The TrustVote system allows participating vehicles to hide their rating/feedback scores and the list of interacted vehicles under a homomorphic cryptographic layer, which can only be unfolded as an aggregate. The proposed approach also considers the trust weight of a vehicle providing the rating scores while computing the aggregate reputation of the vehicles. A prototype of TrustVote is developed and its performance is evaluated in terms of the computational and communication overheads. Muhammad Ajmal Azad, Samiran Bag, Simon Parkinson, Feng Hao 0001 |
IEEE Internet Things J. | 4 |
| 2019 | Efficient threshold password-authenticated secret sharing protocols for cloud computing
Xun Yi, Zahir Tari, Feng Hao 0001, Liqun Chen 0002, Joseph K. Liu, Xuechao Yang, Kwok-Yan Lam, Ibrahim Khalil 0001, Albert Y. Zomaya |
J. Parallel Distributed Comput. | 3 |
| 2018 | M2M-REP: Reputation system for machines in the internet of things
Muhammad Ajmal Azad, Samiran Bag, Feng Hao 0001, Khaled Salah 0001 |
Comput. Secur. | 3 |
| 2018 | A privacy-aware decentralized and personalized reputation system
Samiran Bag, Muhammad Ajmal Azad, Feng Hao 0001 |
Comput. Secur. | 3 |
| 2018 | PrivBox: Verifiable decentralized reputation system for online marketplaces
Muhammad Ajmal Azad, Samiran Bag, Feng Hao 0001 |
Future Gener. Comput. Syst. | 3 |
| 2018 | Analyzing and Patching SPEKE in ISO/IECabstractSimple password exponential key exchange (SPEKE) is a well-known password authenticated key exchange protocol that has been used in Blackberry phones for secure messaging and Entrust's TruePass end-to-end web products. It has also been included into international standards such as ISO/IEC 11770-4 and IEEE P1363.2. In this paper, we analyze the SPEKE protocol as specified in the ISO/IEC and IEEE standards. We identify that the protocol is vulnerable to two new attacks: an impersonation attack that allows an attacker to impersonate a user without knowing the password by launching two parallel sessions with the victim, and a key-malleability attack that allows a man-in-the-middle to manipulate the session key without being detected by the end users. Both attacks have been acknowledged by the technical committee of ISO/IEC SC 27 and ISO/IEC 11770-4 revised as a result. We propose a patched SPEKE called P-SPEKE and present a formal analysis in the Applied Pi Calculus using ProVerif to show that the proposed patch prevents both attacks. The proposed patch has been included into the latest revision of ISO/IEC 11770-4 published in 2017. Feng Hao 0001, Roberto Metere, Siamak F. Shahandashti, Changyu Dong |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2017 | M2M-REP: Reputation of Machines in the Internet of ThingsabstractThe Internet of Things (IoT) is the integration of a large number of autonomous heterogeneous devices that report information from the physical environment to the monitoring system for analytics and meaningful decisions. The compromised machines in the IoT network may not only be used for spreading unwanted content such as spam, malware, viruses etc, but can also report incorrect information about the physical world that might have a disastrous consequence. The challenge is to design a collaborative reputation system that calculates trustworthiness of machines in the IoT-based machine-to-machine network without consuming high system resources and breaching the privacy of participants. To address the challenge of privacy preserving reputation system for the decentralized IoT environment, this paper presents a novel M2M-REP (Machine to Machine Reputation) system that computes global reputation of the machine by aggregating the encrypted local feedback provided by machines in a fully decentralized and secure way. The privacy of participating machines is well protected such that machines or analyst would not learn any information about the feedback score provided by the participating machines other than the final aggregated statistical score. We present a decentralized reputation aggregation system for two scenarios: a semi-honest (honest-but-curious) setup where machines are trustworthy in providing feedback but are curious to learn sensitive information about the collaborating machines, and the malicious model where machines not only try to learn the sensitive information of participants but also do not follow the protocol specification in providing feedback. We analyzed the security and privacy properties of the M2M-REP system for different adversarial models. Muhammad Ajmal Azad, Samiran Bag, Feng Hao 0001 |
ARES | 3 |
| 2017 | Erratum to "On the Privacy of Private Browsing - A Forensic Approach" [JISA 19/1(2014), 88-100]
Kiavash Satvat, Matthew Forshaw, Feng Hao 0001, Ehsan Toreini |
J. Inf. Secur. Appl. | 3 |
| 2017 | Texture to the Rescue: Practical Paper Fingerprinting Based on Texture PatternsabstractIn this article, we propose a novel paper fingerprinting technique based on analyzing the translucent patterns revealed when a light source shines through the paper. These patterns represent the inherent texture of paper, formed by the random interleaving of wooden particles during the manufacturing process. We show that these patterns can be easily captured by a commodity camera and condensed into a compact 2,048-bit fingerprint code. Prominent works in this area (Nature 2005, IEEE S8P 2009, CCS 2011) have all focused on fingerprinting paper based on the paper “surface.” We are motivated by the observation that capturing the surface alone misses important distinctive features such as the noneven thickness, random distribution of impurities, and different materials in the paper with varying opacities. Through experiments, we demonstrate that the embedded paper texture provides a more reliable source for fingerprinting than features on the surface. Based on the collected datasets, we achieve 0% false rejection and 0% false acceptance rates. We further report that our extracted fingerprints contain 807 degrees of freedom (DoF), which is much higher than the 249 DoF with iris codes (that have the same size of 2,048 bits). The high amount of DoF for texture-based fingerprints makes our method extremely scalable for recognition among very large databases; it also allows secure usage of the extracted fingerprint in privacy-preserving authentication schemes based on error correction techniques. Ehsan Toreini, Siamak F. Shahandashti, Feng Hao 0001 |
ACM Trans. Priv. Secur. | 3 |
| 2016 | Towards Bitcoin Payment Networks
Patrick McCorry, Malte Möser, Siamak F. Shahandashti, Feng Hao 0001 |
ACISP (1) | 4 |
| 2016 | DRE-ip: A Verifiable E-Voting Scheme Without Tallying Authorities
Siamak F. Shahandashti, Feng Hao 0001 |
ESORICS (2) | 2 |
| 2016 | Editorial of special issue on security and privacy in cloud computing
Feng Hao 0001, Xun Yi, Elisa Bertino |
J. Inf. Secur. Appl. | 1 |
| 2016 | TouchSignatures: Identification of user touch actions and PINs based on mobile sensor data via JavaScript
Maryam Mehrnezhad, Ehsan Toreini, Siamak F. Shahandashti, Feng Hao 0001 |
J. Inf. Secur. Appl. | 4 |
| 2016 | ID2S Password-Authenticated Key Exchange ProtocolsabstractIn a two-server password-authenticated key exchange (PAKE) protocol, a client splits its password and stores two shares of its password in the two servers, respectively, and the two servers then cooperate to authenticate the client without knowing the password of the client. In case one server is compromised by an adversary, the password of the client is required to remain secure. In this paper, we present two compilers that transform any two-party PAKE protocol to a two-server PAKE protocol on the basis of the identity-based cryptography, called ID2S PAKE protocol. By the compilers, we can construct ID2S PAKE protocols which achieve implicit authentication. As long as the underlying two-party PAKE protocol and identity-based encryption or signature scheme have provable security without random oracles, the ID2S PAKE protocols constructed by the compilers can be proven to be secure without random oracles. Compared with the Katz et al.'s two-server PAKE protocol with provable security without random oracles, our ID2S PAKE protocol can save from 22 to 66 percent of computation in each server. Xun Yi, Fang-Yu Rao, Zahir Tari, Feng Hao 0001, Elisa Bertino, Ibrahim Khalil 0001, Albert Y. Zomaya |
IEEE Trans. Computers | 4 |
| 2016 | Deleting Secret Data with Public VerifiabilityabstractExisting software-based data erasure programs can be summarized as following the same one-bit-return protocol: the deletion program performs data erasure and returns either success or failure. However, such a one-bit-return protocol turns the data deletion system into a black box-the user has to trust the outcome but cannot easily verify it. This is especially problematic when the deletion program is encapsulated within a Trusted Platform Module (TPM), and the user has no access to the code inside. In this paper, we present a cryptographic solution that aims to make the data deletion process more transparent and verifiable. In contrast to the conventional black/white assumptions about TPM (i.e., either completely trust or distrust), we introduce a third assumption that sits in between: namely, “trust-but-verify”. Our solution enables a user to verify the correct implementation of two important operations inside a TPM without accessing its source code: i.e., the correct encryption of data and the faithful deletion of the key. Finally, we present a proof-of-concept implementation of the SSE system on a resource-constrained Java card to demonstrate its practical feasibility. To our knowledge, this is the first systematic solution to the secure data deletion problem based on a “trust-but-verify” paradigm, together with a concrete prototype implementation. Feng Hao 0001, Dylan Clarke, Avelino Francisco Zorzo |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2015 | TouchSignatures: Identification of User Touch Actions based on Mobile Sensors via JavaScriptabstractConforming to the recent W3C specifications (www.w3.org/TR/orientation-event), modern mobile web browsers generally allow JavaScript code in a web page to access motion and orientation sensor data without the user's permission. The associated risks to user privacy are however not considered in W3C specifications. In this work, for the first time, we show how user privacy can be compromised using device motion and orientation sensor data available in-browser, despite the fact that the data rate is 5 to 10 times slower than what is attainable in-app. We examine different browsers on the Android and iOS platforms and study their policies in granting permissions to JavaScript code with respect to access to motion and orientation sensor data and identify multiple vulnerabilities. Based on our findings, we propose TouchSignatures, implementation of an attack in which malicious JavaScript code on an inactive tab listens to such sensor data measurements. Based on these streams, TouchSignatures is able to distinguish the user's touch actions (e.g., tap, scroll, hold, and zoom) on an active tab, allowing the remote website to learn the client-side user activities. Finally, we demonstrate the practicality of this attack by collecting real-world user data and reporting high success rates using our proof-of-concept implementation. Maryam Mehrnezhad, Ehsan Toreini, Siamak F. Shahandashti, Feng Hao 0001 |
AsiaCCS | 4 |
| 2015 | Practical Threshold Password-Authenticated Secret Sharing ProtocolabstractThreshold password-authenticated secret sharing (TPASS) protocols allow a client to secret-share a secret s among n servers and protect it with a password $$\mathsf {pw}$$ , so that the client can later recover s from any subset of t of the servers using the password $$\mathsf {pw}$$ , but so that no coalition smaller than t learns anything about s or can mount an offline dictionary attack on the password $$\mathsf {pw}$$ . Some TPASS protocols have appeared in the literature recently. The protocol by Bagherzandi et al. (CCS 2011) leaks the password if a client mistakenly executes the protocol with malicious servers. The first t-out-of-n TPASS protocol for any $$n>t$$ that does not suffer from this shortcoming was given by Camenisch et al. (CRYPTO 2014). This protocol, proved to be secure in the UC framework, requires the client to involve in many communication rounds so that it becomes impractical for the client. In this paper, we present a practical TPASS protocol which is in particular efficient for the client, who only needs to send a request and receive a response. In addition, we have provided a rigorous proof of security for our protocol in the standard model. Xun Yi, Feng Hao 0001, Liqun Chen 0002, Joseph K. Liu |
ESORICS (1) | 2 |
| 2014 | ID-Based Two-Server Password-Authenticated Key Exchange
Xun Yi, Feng Hao 0001, Elisa Bertino |
ESORICS (2) | 2 |
| 2014 | Cryptanalysis of the dragonfly key exchange protocolabstractDragonfly is a password authenticated key exchange protocol that has been submitted to the Internet engineering task force as a candidate standard for general internet use. The authors analysed the security of this protocol and devised an attack that is capable of extracting both the session key and password from an honest party. This attack was then implemented and experiments were performed to determine the time‐scale required to successfully complete the attack. Dylan Clarke, Feng Hao 0001 |
IET Inf. Secur. | 2 |
| 2014 | On the privacy of private browsing - A forensic approach
Kiavash Satvat, Matthew Forshaw, Feng Hao 0001, Ehsan Toreini |
J. Inf. Secur. Appl. | 3 |
| 2012 | Security Analysis of a Multi-factor Authenticated Key Exchange Protocol
Feng Hao 0001, Dylan Clarke |
ACNS | 1 |
| 2010 | Anonymous voting by two-round public discussionabstractIn 2006, Hao and Zieliński proposed a two-round anonymous veto protocol (called AV-net), which provided exceptional efficiency compared to related techniques. In this study, the authors add a self-tallying function to the AV-net, making it a general-purpose voting protocol. The new protocol works in the same setting as the AV-net – it requires no trusted third parties or private channels, and participants execute the protocol by sending two-round public messages. Compared with related voting protocols in past work, this is significantly more efficient in terms of the number of rounds, computational cost and bandwidth usage. Feng Hao 0001, Peter Y. A. Ryan |
IET Inf. Secur. | 1 |
| 2008 | A Fast Search Algorithm for a Large Fuzzy DatabaseabstractIn this paper, we propose a fast search algorithm for a large fuzzy database that stores iris codes or data with a similar binary structure. The fuzzy nature of iris codes and their high dimensionality render many modern search algorithms, mainly relying on sorting and hashing, inadequate. The algorithm that is used in all current public deployments of iris recognition is based on a brute force exhaustive search through a database of iris codes, looking for a match that is close enough. Our new technique, Beacon Guided Search (BGS), tackles this problem by dispersing a multitude of “beacons” in the search space. Despite random bit errors, iris codes from the same eye are more likely to collide with the same beacons than those from different eyes. By counting the number of collisions, BGS shrinks the search range dramatically with a negligible loss of precision. We evaluate this technique using 632 500 iris codes enrolled in the United Arab Emirates (UAE) border control system, showing a substantial improvement in search speed with a negligible loss of accuracy. In addition, we demonstrate that the empirical results match theoretical predictions. Feng Hao 0001, John Daugman |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2006 | Combining Crypto with Biometrics EffectivelyabstractWe propose the first practical and secure way to integrate the iris biometric into cryptographic applications. A repeatable binary string, which we call a biometric key, is generated reliably from genuine iris codes. A well-known difficulty has been how to cope with the 10 to 20 percent of error bits within an iris code and derive an error-free key. To solve this problem, we carefully studied the error patterns within iris codes and devised a two-layer error correction technique that combines Hadamard and Reed-Solomon codes. The key is generated from a subject's iris image with the aid of auxiliary error-correction data, which do not reveal the key and can be saved in a tamper-resistant token, such as a smart card. The reproduction of the key depends on two factors: the iris biometric and the token. The attacker has to procure both of them to compromise the key. We evaluated our technique using iris samples from 70 different eyes, with 10 samples from each eye. We found that an error-free key can be reproduced reliably from genuine iris codes with a 99.5 percent success rate. We can generate up to 140 bits of biometric key, more than enough for 128-bit AES. The extraction of a repeatable binary string from biometrics opens new possible applications, where a strong binding is required between a person and cryptographic operations. For example, it is possible to identify individuals without maintaining a central database of biometric templates, to which privacy objections might be raised. Feng Hao 0001, Ross J. Anderson, John Daugman |
IEEE Trans. Computers | 1 |
| 2003 | Online signature verification using a new extreme points warping technique
Feng Hao 0001, Chan Choong Wah |
Pattern Recognit. Lett. | 1 |
| 2002 | Private key generation from on-line handwritten signaturesabstractn recent years, public key infrastructure (PKI) has emerged as co‐existent with the increasing demand for digital security. A digital signature is created using existing public key cryptography technology. This technology will permit commercial transactions to be carried out across insecure networks without fear of tampering or forgery. The relative strength of digital signatures relies on the access control over the individual’s private key. The private key storage, which is usually password‐protected, has long been a weak link in the security chain. In this paper, we describe a novel and feasible system – BioPKI cryptosystem – that dynamically generates private keys from users’ on‐line handwritten signatures. The BioPKI cryptosystem eliminates the need of private key storage. The system is secure, reliable, convenient and non‐invasive. In addition, it ensures non‐repudiation to be addressed on the maker of the transaction instead of the computer where the transaction occurs. Feng Hao 0001, Chan Choong Wah |
Inf. Manag. Comput. Secur. | 1 |