EDBT 2026 Demo / reviewers in the wild / expert
Birou Gao
dblp:377/1838
· DBLP profile ↗
4ranked-venue papers
2as first author
4since 2021 · last 2025
0009-0009-0718-3130ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 3 · 2 first-author · 3 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Practical and veritable threshold multi-factor authentication for mobile devicesabstractAbstract Multi-factor authentication (MFA) is extensively employed in mobile applications to enhance security, including Internet of Vehicles, healthcare systems, smart homes, etc. Traditional MFA requires users to present specific factors, which can be inconvenient if certain factors are unavailable. To address this, $ (t, n) $-threshold MFA (T-MFA) allows users to select any $ t $ out of $ n $ registered factors for authentication. However, existing T-MFA solutions face four key issues: (i) reliance on $ n-1 $ devices, which may be impractical; (ii) susceptibility to denial of service when the mandatory factor fails; (iii) limited factor types, reducing user flexibility; and (iv) increasing client-side computational costs with higher $ t $. In this work, we propose a veritable $ (t, n) $-threshold multi-factor authenticated key exchange protocol that addresses these challenges. Utilizing oblivious programmable pseudorandom functions (OPPRF) as main tools, we eliminate dependence on multiple devices, mandatory factors, and restricted factor types, achieving what we called veritable. We present a new construction of batched OPPRF to reduce client-side costs from $ O(t) $ to $ O(1) $, with 2 exponentiations cost by the client and $ t+1 $ by the server. We implement it with JavaScript to validate its flexibility and efficiency, making it highly suitable for mobile device applications. Shihan Qin, Yansen Xin, Birou Gao, Rui Zhang 0002 |
Comput. J. | 4 |
| 2025 | Cocoon: certificateless blockchain wallet supporting both stealth address and revocationabstractAbstract The breaches of the blockchain wallet keys greatly harm the security of blockchain transactions. To protect the secret keys, the known solutions, such as hierarchical deterministic wallets proposed in BIP32 or stealth addresses adopted in Monero, have been extensively researched. However, most of the existing works assume the key is safe, in the sense that it cannot be stolen or damaged, which is not true in practice. Moreover, current key revocation mechanisms either rely on centralized authorities, compromising decentralization, or require economic incentives to ensure nodes remain consistantly online. In this paper, we introduce Cocoon, the first blockchain wallet scheme that supports stealth addresses and provides a wallet revocation mechanism without the need for certificates. Cocoon not only ensures the privacy of wallet secret keys but also can individually revoke compromised keys with high performance. Our contributions are three-fold: First, we present the formal model and the related security definitions. Next, we give a generic construction based on the hierarchical identity-based signature, identity-based key encapsulation mechanism and non-interactive zero-knowledge proof. We then extend the scheme to the hierarchical setting for diverse scenarios. Finally, we give the implementation, and the results show that the scheme is practical. Birou Gao, Rui Zhang 0002, Yang Tao 0001, Shihan Qin |
Cybersecur. | 1 |
| 2024 | NEST: Strong Key-Insulated Password-Based Shared-Custodial Blockchain Wallets
Birou Gao, Huan Zou |
Inscrypt (1) | 1 |
| 2024 | Designated confirmer threshold signature and its applications in blockchainsabstractAbstract The non-transferability of a designated confirmer signature scheme allows a signer to control the verification ability of a signature, hence protecting the signer’s privacy. However, a designated confirmer signature is insufficient when the secret keys are damaged and incapable of collaborative signature generation. In this paper, we circumvent these limitations by introducing the notion of designated confirmer threshold signature. First, we present a formal security model, then give a generic construction, which utilizes threshold signature schemes, encryption schemes and $$\Sigma$$ Σ -protocols. Instantiating this generic construction, we have two specific schemes, based on threshold Schnorr and threshold ECDSA, respectively. We further design two efficient $$\Sigma$$ Σ -protocols for efficient proofs. We also implement these schemes, and the experiment results show that our schemes are practical with rich functionalities. Finally, we demonstrate interesting applications for blockchains, such as verifiable asset auctions in blockchain and traditional electronic bidding. Yunfeng Ji, Rui Zhang 0002, Yang Tao 0001, Birou Gao |
Cybersecur. | 4 |