EDBT 2026 Demo / reviewers in the wild / expert
Feng Bao 0001
dblp:46/1953-1
· DBLP profile ↗
152ranked-venue papers
21as first author
0since 2021 · last 2017
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 95 · 15 first-authorComputer networks · 31 · 3 first-authorGraphics, computer vision, multimedia, augmented reality and games · 6Systems, architecture and hardware · 4 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 4 · 1 first-authorDatabases, data management, data science and information retrieval · 3Artificial intelligence and machine learning · 2Theory of computation · 1
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Network and information security
13 papers |
Cryptographic primitives and cryptanalysis · 30% Network security · 23% Cryptographic protocols and secure computation · 15% | |
| Computer architecture, parallel and distributed computing, and storage systems
2 papers |
Storage systems · 100% | |
| Theoretical computer science
2 papers |
Coding theory · 100% |
Topics — the 30 heaviest of 44, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Network security › attack resilience › attack mitigation › denial-of-service defense
client puzzles |
0.2 | 1 | 2015 | Software Puzzle: A Countermeasure to Resource-Inflated Denial-of-Service Attacks · IEEE Trans. Inf. Forensics Secur. 2015 |
Network security › attack strategy
denial-of-service attack |
0.2 | 1 | 2015 | Software Puzzle: A Countermeasure to Resource-Inflated Denial-of-Service Attacks · IEEE Trans. Inf. Forensics Secur. 2015 |
Cryptographic primitives and cryptanalysis › public-key cryptography › public-key encryption
chosen-ciphertext security |
0.1 | 1 | 2010 | CCA-secure unidirectional proxy re-encryption in the adaptive corruption model without random oracles · Sci. China Inf. Sci. 2010 |
Systems and software security
database security |
0.1 | 1 | 2010 | Shifting Inference Control to User Side: Architecture and Protocol · IEEE Trans. Dependable Secur. Comput. 2010 |
Privacy and data protection › statistical database privacy
inference control |
0.1 | 1 | 2010 | Shifting Inference Control to User Side: Architecture and Protocol · IEEE Trans. Dependable Secur. Comput. 2010 |
Cryptographic primitives and cryptanalysis
proxy re-encryption |
0.1 | 1 | 2010 | CCA-secure unidirectional proxy re-encryption in the adaptive corruption model without random oracles · Sci. China Inf. Sci. 2010 |
Hardware security and side channels › trusted execution environments
remote attestation |
0.1 | 1 | 2010 | Shifting Inference Control to User Side: Architecture and Protocol · IEEE Trans. Dependable Secur. Comput. 2010 |
Hardware security and side channels
trusted execution environments |
0.1 | 1 | 2010 | Shifting Inference Control to User Side: Architecture and Protocol · IEEE Trans. Dependable Secur. Comput. 2010 |
Storage systems › storage reliability
erasure coding |
0.1 | 2 | 2005 | New Efficient MDS Array Codes for RAID Part II: Rabin-Like Codes for Tolerating Multiple (greater than or equal to 4) Disk Failures · IEEE Trans. Computers 2005 New Efficient MDS Array Codes for RAID Part I: Reed-Solomon-Like Codes for Tolerating Three Disk Failures · IEEE Trans. Computers 2005 |
Storage systems › storage reliability › erasure coding
MDS array codes |
0.1 | 2 | 2005 | New Efficient MDS Array Codes for RAID Part II: Rabin-Like Codes for Tolerating Multiple (greater than or equal to 4) Disk Failures · IEEE Trans. Computers 2005 New Efficient MDS Array Codes for RAID Part I: Reed-Solomon-Like Codes for Tolerating Three Disk Failures · IEEE Trans. Computers 2005 |
Storage systems › storage reliability
RAID |
0.1 | 2 | 2005 | New Efficient MDS Array Codes for RAID Part II: Rabin-Like Codes for Tolerating Multiple (greater than or equal to 4) Disk Failures · IEEE Trans. Computers 2005 New Efficient MDS Array Codes for RAID Part I: Reed-Solomon-Like Codes for Tolerating Three Disk Failures · IEEE Trans. Computers 2005 |
Storage systems
storage reliability |
0.1 | 2 | 2005 | New Efficient MDS Array Codes for RAID Part II: Rabin-Like Codes for Tolerating Multiple (greater than or equal to 4) Disk Failures · IEEE Trans. Computers 2005 New Efficient MDS Array Codes for RAID Part I: Reed-Solomon-Like Codes for Tolerating Three Disk Failures · IEEE Trans. Computers 2005 |
Coding theory › error-correcting codes › block codes
array codes |
0.1 | 2 | 2005 | New Efficient MDS Array Codes for RAID Part II: Rabin-Like Codes for Tolerating Multiple (greater than or equal to 4) Disk Failures · IEEE Trans. Computers 2005 New Efficient MDS Array Codes for RAID Part I: Reed-Solomon-Like Codes for Tolerating Three Disk Failures · IEEE Trans. Computers 2005 |
Coding theory › error-correcting codes › block codes
MDS codes |
0.1 | 2 | 2005 | New Efficient MDS Array Codes for RAID Part II: Rabin-Like Codes for Tolerating Multiple (greater than or equal to 4) Disk Failures · IEEE Trans. Computers 2005 New Efficient MDS Array Codes for RAID Part I: Reed-Solomon-Like Codes for Tolerating Three Disk Failures · IEEE Trans. Computers 2005 |
Cryptographic primitives and cryptanalysis › public-key cryptography
digital signatures |
0.1 | 2 | 2005 | Designated Verifier Signature Schemes: Attacks, New Security Notions and a New Construction · ICALP 2005 Comments on "A Practical (t, n) Threshold Proxy Signature Scheme Based on the RSA Cryptosystem" · IEEE Trans. Knowl. Data Eng. 2004 |
Cryptographic protocols and secure computation
fair exchange |
0.1 | 2 | 2004 | Colluding Attacks to a Payment Protocol and Two Signature Exchange Schemes · ASIACRYPT 2004 Efficient and Practical Fair Exchange Protocols with Off-Line TTP · S&P 1998 |
Blockchain and cryptocurrency security › consensus protocol
proof-of-work |
0.1 | 1 | 2015 | Software Puzzle: A Countermeasure to Resource-Inflated Denial-of-Service Attacks · IEEE Trans. Inf. Forensics Secur. 2015 |
Authentication and access control › password authentication
dictionary attack resistance |
0.1 | 1 | 2006 | A Practical Password-Based Two-Server Authentication and Key Exchange System · IEEE Trans. Dependable Secur. Comput. 2006 |
Cryptographic protocols and secure computation
key exchange |
0.1 | 1 | 2006 | A Practical Password-Based Two-Server Authentication and Key Exchange System · IEEE Trans. Dependable Secur. Comput. 2006 |
Cryptographic protocols and secure computation › key exchange › authenticated key exchange
password-authenticated key exchange |
0.1 | 1 | 2006 | A Practical Password-Based Two-Server Authentication and Key Exchange System · IEEE Trans. Dependable Secur. Comput. 2006 |
Authentication and access control
password authentication |
0.1 | 1 | 2006 | A Practical Password-Based Two-Server Authentication and Key Exchange System · IEEE Trans. Dependable Secur. Comput. 2006 |
Authentication and access control › password authentication
two-server authentication |
0.1 | 1 | 2006 | A Practical Password-Based Two-Server Authentication and Key Exchange System · IEEE Trans. Dependable Secur. Comput. 2006 |
Cryptographic primitives and cryptanalysis › public-key cryptography › digital signatures › non-transferable signatures
designated verifier signature |
0.1 | 1 | 2005 | Designated Verifier Signature Schemes: Attacks, New Security Notions and a New Construction · ICALP 2005 |
Cryptographic primitives and cryptanalysis › symmetric cryptography › cipher design
cellular automata based cipher |
0.0 | 1 | 2004 | Cryptanalysis of a Partially Known Cellular Automata Cryptosystem · IEEE Trans. Computers 2004 |
Cryptographic primitives and cryptanalysis › cryptographic foundations › cryptographic models
chosen-plaintext attack |
0.0 | 1 | 2004 | Cryptanalysis of a Partially Known Cellular Automata Cryptosystem · IEEE Trans. Computers 2004 |
Network security › attack strategy
collusion attack |
0.0 | 1 | 2004 | Colluding Attacks to a Payment Protocol and Two Signature Exchange Schemes · ASIACRYPT 2004 |
Digital forensics and information hiding › fingerprinting
collusion attack analysis |
0.0 | 1 | 2004 | Collusion attack on a multi-key secure video proxy scheme · ACM Multimedia 2004 |
Cryptographic primitives and cryptanalysis › public-key cryptography › digital signatures
proxy signature |
0.0 | 1 | 2004 | Comments on "A Practical (t, n) Threshold Proxy Signature Scheme Based on the RSA Cryptosystem" · IEEE Trans. Knowl. Data Eng. 2004 |
Cryptographic protocols and secure computation
secure payment |
0.0 | 1 | 2004 | Colluding Attacks to a Payment Protocol and Two Signature Exchange Schemes · ASIACRYPT 2004 |
Cryptographic primitives and cryptanalysis › public-key cryptography › digital signatures › proxy signature
threshold proxy signature |
0.0 | 1 | 2004 | Comments on "A Practical (t, n) Threshold Proxy Signature Scheme Based on the RSA Cryptosystem" · IEEE Trans. Knowl. Data Eng. 2004 |
Methods — techniques the papers use, named apart from their topics
trusted computing · 0.2software puzzle generation · 0.2formal protocol verification · 0.2circular permutation matrices · 0.2XOR operations · 0.2GPU translation resistance · 0.2security analysis · 0.2countermeasure design · 0.1protocol design · 0.1two-server architecture · 0.1RSA cryptosystem · 0.0CEMBS · 0.0
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2017 | Evolving privacy: From sensors to the Internet of Things
Javier López 0001, Ruben Rios, Feng Bao 0001, Guilin Wang |
Future Gener. Comput. Syst. | 3 |
| 2015 | Software Puzzle: A Countermeasure to Resource-Inflated Denial-of-Service AttacksabstractDenial-of-service (DoS) and distributed DoS (DDoS) are among the major threats to cyber-security, and client puzzle, which demands a client to perform computationally expensive operations before being granted services from a server, is a well-known countermeasure to them. However, an attacker can inflate its capability of DoS/DDoS attacks with fast puzzle-solving software and/or built-in graphics processing unit (GPU) hardware to significantly weaken the effectiveness of client puzzles. In this paper, we study how to prevent DoS/DDoS attackers from inflating their puzzle-solving capabilities. To this end, we introduce a new client puzzle referred to as software puzzle. Unlike the existing client puzzle schemes, which publish their puzzle algorithms in advance, a puzzle algorithm in the present software puzzle scheme is randomly generated only after a client request is received at the server side and the algorithm is generated such that: 1) an attacker is unable to prepare an implementation to solve the puzzle in advance and 2) the attacker needs considerable effort in translating a central processing unit puzzle software to its functionally equivalent GPU version such that the translation cannot be done in real time. Moreover, we show how to implement software puzzle in the generic server-browser model. Yongdong Wu, Feng Bao 0001, Robert H. Deng |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2014 | Collaborative agglomerative document clustering with limited information disclosureabstractABSTRACT Document clustering is a practical and powerful data mining technique to analyze large amount of documents and large sets of text or hypertext documents. However, it also brings the problem of sensitive information leaking in disregard of privacy, especially when it is executed in distributed environment. In this paper, we propose a cryptography‐based framework to realize privacy‐preserving document clustering among the users under the distributed environment; there are two parties, each having his private document database, want to collaboratively execute agglomerative document clustering without disclosing their private contents. We provide two implementations of such a framework, one is with more precision and stronger security but requires more computational resources. The other is a simplified version with less computational complexity and achieves higher processing speed. Additionally, we provide the security proofs and experimental analysis of precision and scalability of our proposal. Copyright © 2013 John Wiley & Sons, Ltd. Chunhua Su, Jianying Zhou 0001, Feng Bao 0001, Tsuyoshi Takagi, Kouichi Sakurai |
Secur. Commun. Networks | 3 |
| 2013 | Launching Generic Attacks on iOS with Approved Third-Party Applications
Jin Han 0002, Su Mon Kywe, Qiang Yan 0001, Feng Bao 0001, Robert H. Deng, Debin Gao, Yingjiu Li, Jianying Zhou 0001 |
ACNS | 4 |
| 2013 | Insured access: an approach to ad-hoc information sharing for virtual organizationsabstractA virtual organization (VO) is a group of organizations that have banded together to achieve a common goal. Often a VO could function more effectively if its members were willing to share certain information. However, a typical VO member will not want to share its own information because the member will not benefit directly from the information's reuse, yet will be blamed if the reuse turns out badly. Naoki Tanaka, Marianne Winslett, Adam J. Lee, David K. Y. Yau, Feng Bao 0001 |
CODASPY | 5 |
| 2012 | Detecting node replication attacks in wireless sensor networks: A survey
Wen Tao Zhu, Jianying Zhou 0001, Robert H. Deng, Feng Bao 0001 |
J. Netw. Comput. Appl. | 4 |
| 2012 | Detecting node replication attacks in mobile sensor networks: theory and approachesabstractABSTRACT A wireless sensor network composed of a number of sensor nodes is often deployed in unattended and harsh environments to perform various monitoring tasks. Due to cost concerns, usually, sensor nodes are not made tamper‐resistant, and a captured node may be easily compromised by an adversary. With the revealed secret credentials, the adversary can create many duplicate nodes that are seemingly legitimate, and deploy them into the network to cripple the monitoring applications. Defending against node replication attacks has become an important research topic in sensor network security, but so far, not many solutions have been proposed, most of which adopt a stationary network model where sensor nodes are fixed and immobile. In this work, we address the problem of detecting node replication attacks in a mobile sensor network, where each sensor node freely and randomly roams in the sensing region all the time, and one node meets with another in an occasional and unpredictable manner. For replication attacks where the replicas do not conspire, we employ very lightweight token‐based authentication as a detection approach. In case the replicas conspire by communicating with each other in an efficient manner, we harness the random encounters between physical nodes and propose a detection method based on statistics. Compared with existent solutions, our detections have the nice feature that sensor nodes are freed from the fragile assumption that they can correctly obtain their geographic positions, and that even loose time synchronization may be unnecessary. Copyright © 2011 John Wiley & Sons, Ltd. Wen Tao Zhu, Jianying Zhou 0001, Robert H. Deng, Feng Bao 0001 |
Secur. Commun. Networks | 4 |
| 2011 | Hierarchical Identity-Based Chameleon Hash and Its Applications
Feng Bao 0001, Robert H. Deng, Xuhua Ding, Junzuo Lai, Yunlei Zhao |
ACNS | 1 |
| 2011 | Applying Time-Bound Hierarchical Key Assignment in Wireless Sensor Networks
Wen Tao Zhu, Robert H. Deng, Jianying Zhou 0001, Feng Bao 0001 |
ICICS | 4 |
| 2011 | Better security enforcement in trusted computing enabled heterogeneous wireless sensor networksabstractAbstract A wireless sensor network (WSN) is anad hocwireless network composed of a large number of small sensor nodes. Sensor nodes are usually severely resource limited and power constrained, and as such security enforcement in WSNs is a challenging task. To facilitate security enforcement, we propose a heterogeneous architecture for WSNs, where a WSN is partitioned into clusters, each having a high‐end cluster head. The cluster heads are further equipped with trusted computing technology (TC), such that they act as online trusted parties, thereby expected to help enforce security in a more effective manner. To show this, we discuss various examples on both content security and context security. Copyright © 2010 John Wiley & Sons, Ltd. Yanjiang Yang, Jianying Zhou 0001, Robert H. Deng, Feng Bao 0001 |
Secur. Commun. Networks | 4 |
| 2010 | Towards practical anonymous password authenticationabstractThe conventional approach for anonymous password authentication incurs O(N) server computation, linear to the total number of users. In ACSAC'09, Yang et al. proposed a new approach for anonymous password authentication, breaking this lower bound. However, Yang et al.'s scheme has not considered membership withdrawal and online guessing attacks, two issues must be addressed before anonymous password authentication is acceptable for practical use. Thus our main thrust in this work is to provide solutions to these issues. We do not just work upon Yang et al.'s scheme; rather, we use a set of different primitives, and as a result, our scheme has much better performance. We prove the security of our scheme. Furthermore, we empirically evaluate the efficiency of our scheme, and implement a proof-of-concept prototype. Yanjiang Yang, Jianying Zhou 0001, Jun Wen Wong, Feng Bao 0001 |
ACSAC | 4 |
| 2010 | Practical ID-based encryption for wireless sensor networkabstractIn this paper, we propose a new practical identity-based encryption scheme which is suitable for wireless sensor network (WSN). We call it Receiver-Bounded Online/Offline Identity-based Encryption (RB-OOIBE). It splits the encryption process into two parts -- the offline and the online part. In the offline part, all heavy computations are done without the knowledge of the receiver's identity and the plaintext message. In the online stage, only light computations such as modular operation and symmetric key encryption are required, together with the receiver's identity and the plaintext message. Moreover, since each offline ciphertext can be re-used for the same receiver, the number of offline ciphertexts the encrypter holds only confines the number of receivers instead of the number of messages to be encrypted. In this way, a sensor node (with limited computation power and limited storage) in WSN can send encrypted data easily: A few offline ciphertexts can be computed in the manufacturing stage while the online part is light enough for the sensor to process. Cheng-Kang Chu, Joseph K. Liu, Jianying Zhou 0001, Feng Bao 0001, Robert H. Deng |
AsiaCCS | 4 |
| 2010 | Error-free, Multi-bit Non-committing Encryption with Constant Round Complexity
Huafei Zhu, Feng Bao 0001 |
Inscrypt | 2 |
| 2010 | A Secure RFID Ticket System for Public Transport
Feng Bao 0001 |
DBSec | 2 |
| 2010 | Blocking Foxy Phishing Emails with Historical InformationabstractUnlike most of the spams targeting for advertisements only, phishing spams try to cheat the email recipients with bogus sender addresses so as to obtain confidential information of the recipients. This paper presents a Sender Authentication Protocol (SAP) which aims to filter out this kind of crafty spoofing emails. To this end, SAP challenges the claimed-sender with the historical emails so as to verify the authenticity of the sender. As it does not change the email protocol, and is able to be embedded into the off-the-shelf email software such as Microsoft OutlookTM, SAP is not only easy to be deployed, but also fully compatible with other anti-spam technologies. To illustrate its feasibility, we develop a SAP add-in for enhancing Microsoft OutlookTM. The SAP add-in will be started automatically as long as Outlook is started. As the enhanced OutlookTMhas the same user interface as the original one, the add-in is transparent and friendly to the users. Yongdong Wu, Feng Bao 0001 |
ICC | 4 |
| 2010 | Efficient Multiplicative Homomorphic E-Voting
Feng Bao 0001 |
ISC | 2 |
| 2010 | Efficient Proof of Validity of Votes in Homomorphic E-VotingabstractA special membership proof technique is applied to the efficiency bottleneck of homomorphic e-voting, vote validity check. Although the special membership proof technique has some limitations such that so far few appropriate applications have been found for it, it is suitable for homomorphic e-voting. As so far no efficient and secure solution has been found for vote validity check in homomorphic e-voting, this new method is very useful. It greatly improves efficiency of homomorphic e-voting. Feng Bao 0001 |
NSS | 2 |
| 2010 | Formal and Precise Analysis of Soundness of Several Shuffling Schemes
Feng Bao 0001 |
ProvSec | 2 |
| 2010 | Vulnerability of a Non-membership Proof Scheme
Feng Bao 0001 |
SECRYPT | 2 |
| 2010 | Efficiency Improvement of Homomorphic E-Auction
Feng Bao 0001 |
TrustBus | 2 |
| 2010 | Private Searching on MapReduce
Huafei Zhu, Feng Bao 0001 |
TrustBus | 2 |
| 2010 | CCA-secure unidirectional proxy re-encryption in the adaptive corruption model without random oracles
Jian Weng 0001, Min-Rong Chen, Yanjiang Yang, Robert H. Deng, Kefei Chen, Feng Bao 0001 |
Sci. China Inf. Sci. | 6 |
| 2010 | Shifting Inference Control to User Side: Architecture and ProtocolabstractInference has been a longstanding issue in database security, and inference control, aiming to curb inference, provides an extra line of defense to the confidentiality of databases by complementing access control. However, in traditional inference control architecture, database server is a crucial bottleneck, as it enforces highly computation-intensive auditing for all users who query the protected database. As a result, most auditing methods, though rigorously studied, are not practical for protecting large-scale real-world database systems. In this paper, we shift this paradigm by proposing a new inference control architecture, entrusting inference control to each user's platform that is equipped with trusted computing technology. The trusted computing technology is designed to attest the state of a user's platform to the database server, so as to assure the server that inference control could be enforced as prescribed. A generic protocol is proposed to formalize the interactions between the user's platform and database server. The authentication property of the protocol is formally proven. Since inference control is enforced in a distributed manner, our solution avoids the bottleneck in the traditional architecture, thus can potentially support a large number of users making queries. Yanjiang Yang, Yingjiu Li, Robert H. Deng, Feng Bao 0001 |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2009 | A New Approach for Anonymous Password AuthenticationabstractAnonymous password authentication reinforces password authentication with the protection of user privacy. Considering the increasing concern of individual privacy nowadays, anonymous password authentication represents a promising privacy-preserving authentication primitive. However, anonymous password authentication in the standard setting has several inherent weaknesses, making its practicality questionable. In this paper, we propose a new and efficient approach for anonymous password authentication. Our approach assumes a different setting where users do not register their passwords to the server; rather, they use passwords to protect their authentication credentials. We present a concrete scheme, and get over a number of challenges in securing password-protected credentials against off-line guessing attacks. Our experimental results confirm that conventional anonymous password authentication does not scale well, while our new scheme demonstrates very good performance. Yanjiang Yang, Jianying Zhou 0001, Jian Weng 0001, Feng Bao 0001 |
ACSAC | 4 |
| 2009 | A Lightweight Fast Handover Authentication Scheme in Mobile NetworksabstractWhen a mobile node roams in the mobile networks, its access router and routing path keeps changing. Hence the mobile node needs to authenticate the new access router and establish a new key for secure communication. To this motivation, this paper proposes a lightweight, efficient and scalable protocol to establish and update the authentication key in the mobile IPv6 networks. Feng Bao 0001, Yongdong Wu, Yanjiang Yang |
ICC | 2 |
| 2009 | Tracing Stateful Pirate DecodersabstractMost traitor tracing schemes in the literature assume that pirate decoders are stateless. This stateless assumption, however, is unrealistic especially in case of hardware decoders. Any tracing algorithm based on the above assumption may draw a wrong detecting conclusion. The present approach converts a tracing algorithm for stateless decoder into a tracing algorithm for stateful decoder. By employing a robust watermarking scheme, the proposed approach ensures that tracing processes and normal broadcast processes are indistinguishable for pirate decoders. This in turn allows a tracer to incriminate at least one traitor from a pirate decoder. Since the communication overhead for conversion is merely linear to the number of traitors and independent of the number of users, our approach is more efficient than the techniques in. Yongdong Wu, Feng Bao 0001 |
ICC | 2 |
| 2009 | Computationally Secure Hierarchical Self-healing Key Distribution for Heterogeneous Wireless Sensor Networks
Yanjiang Yang, Jianying Zhou 0001, Robert H. Deng, Feng Bao 0001 |
ICICS | 4 |
| 2009 | Adaptive and Composable Oblivious Transfer Protocols (Short Paper)
Huafei Zhu, Feng Bao 0001 |
ICICS | 2 |
| 2009 | Efficient Conditional Proxy Re-encryption with Chosen-Ciphertext Security
Jian Weng 0001, Yanjiang Yang, Qiang Tang 0001, Robert H. Deng, Feng Bao 0001 |
ISC | 5 |
| 2009 | Private handshakes with optional accountabilityabstractNowadays, users are increasingly concerned about individual privacy in cyberspace and Internet. In this paper, we propose the concept of private handshakes with optional accountability, which allows the two users in handshaking to decide real time whether or not to make their interactions accountable. Such optionally accountable private handshaking protocols are a more flexible privacy-preserving authentication primitive than unlink-able secret handshakes and private handshakes. We formulate a formal definition for optionally accountable private handshakes, and propose a concrete scheme based on bilinear pairings. Yanjiang Yang, Feng Bao 0001, Jian Weng 0001 |
LCN | 2 |
| 2009 | Self-enforcing Private Inference Control
Yanjiang Yang, Yingjiu Li, Jian Weng 0001, Jianying Zhou 0001, Feng Bao 0001 |
ProvSec | 5 |
| 2009 | Hierarchical Self-healing Key Distribution for Heterogeneous Wireless Sensor Networks
Yanjiang Yang, Jianying Zhou 0001, Robert H. Deng, Feng Bao 0001 |
SecureComm | 4 |
| 2009 | n PAKE+: A Tree-Based Group Password-Authenticated Key Exchange Protocol Using Different Passwords
Zhiguo Wan, Robert H. Deng, Feng Bao 0001, Bart Preneel, Ming Gu 0001 |
J. Comput. Sci. Technol. | 3 |
| 2009 | Privacy-preserving rental services using one-show anonymous credentialsabstractAbstract Rental services play an important part in our daily life and the trend has been towards digital transactions. Rental records contain lots of sensitive information on individuals, so if abused by rental service providers, users' privacy could be jeopardized. To mitigate this concern, we present privacy‐preserving rental services where interests of both the users and the service provider are protected. Specifically, our system enables normal users to engage in a rental service in an anonymous manner, whereas users with overdue items are subject to anonymity revocation by the rental service provider; moreover, the rental service provider enforces a rental limit which caps the number of rentals per user under a prescribed limit. We propose a novel one‐show anonymous credential scheme to realize the above design objectives. While this scheme is tailored to the scenario of online credential issuing in the proposed rental services, we believe that it is of independent interest and may find its use in other applications. Copyright © 2009 John Wiley & Sons, Ltd. Yanjiang Yang, Robert H. Deng, Feng Bao 0001 |
Secur. Commun. Networks | 3 |
| 2008 | A New Scheme for Distributed Density Estimation based Privacy-Preserving ClusteringabstractThe sensitive information leakage and security risk is a problem from which both individual and enterprise suffer in massive data collection and the information retrieval by the distrusted parties. In this paper, we focus on the privacy issue of data clustering and point out some security risks in the existing data mining algorithms. Associated with cryptographic techniques, we initiate an application of random data perturbation (RDP) which has been widely used for preserving the privacy of individual records in statistical database for the distributed data clustering scheme. Our scheme applies linear transformation of Gaussian distribution perturbed data and general additional data perturbation (GADP) schemes to preserve the privacy for distributed kernel density estimation with the help of any trusted third party. We also show that our scheme is more secure against the random matrix-based filtering attack which is based on analysis of the distribution of the eigenvalues by using two RDP methods. Chunhua Su, Feng Bao 0001, Jianying Zhou 0001, Tsuyoshi Takagi, Kouichi Sakurai |
ARES | 2 |
| 2008 | Generic Constructions of Stateful Public Key Encryption and Their Applications
Joonsang Baek, Jianying Zhou 0001, Feng Bao 0001 |
ACNS | 3 |
| 2008 | Batch ZK Proof and Verification of OR Logic
Feng Bao 0001 |
Inscrypt | 2 |
| 2008 | Correction, Optimisation and Secure and Efficient Application of PBD Shuffling
Feng Bao 0001 |
Inscrypt | 2 |
| 2008 | Robust and Reliable Broadcast Protocols in the Stand-Alone and Simulation-Based FrameworksabstractThe research on reliable communication in distributed networks has a rich history due to its fundamental importance. In this paper, an efficient implementation of reliable broadcast communications in the stand-alone and simulation- based framework is formalized and analyzed by means of sequential aggregate signatures. A reliable broadcast problem is called stand-alone if the security of broadcast protocols can be efficiently reduced to the security of the underlying digital signatures. A reliable broadcast is called secure in the simulation- based framework if it is provably secure in the universally composable paradigm. Our reliable broadcast protocol works in the unknown fixed-identity networks where no public key infrastructure (PKI) exists. We show that our implementation is robust in the sense that the proposed broadcast protocol can resist against up to k adversaries assuming that the underlying network is (2k + l)-vertex connected and individual signatures are secure against adaptive chosen-message attack. Huafei Zhu, Feng Bao 0001, Robert H. Deng |
ICC | 2 |
| 2008 | Optimizing the capacity of distortion-freewatermarking on palette imagesabstractIn a palette image file, each color is pointed by at least one palette entry and each pixel is represented with one of the color pointers. Since many palette images use a portion of palette entries only, this paper presents a distortion-free watermarking on palette images by exploiting the unused entries. It allocates x palette entries to one color such that each pixel of the color is able to embed log2x bits. In order to achieve high embedding capacity, we formulate the relationship among embedding capacity, color occurrence, and unused palette entries. By solving the formula and allocating the palette entries in a sub-optimal manner, the present scheme provides a roughly optimal capacity. Our experiment demonstrates that the present scheme is of high watermarking capacity. Yongdong Wu, Feng Bao 0001 |
ICME | 3 |
| 2008 | Private Query on Encrypted Data in Multi-user Settings
Feng Bao 0001, Robert H. Deng, Xuhua Ding, Yanjiang Yang |
ISPEC | 1 |
| 2008 | An Efficient PIR Construction Using Trusted Hardware
Yanjiang Yang, Xuhua Ding, Robert H. Deng, Feng Bao 0001 |
ISC | 4 |
| 2008 | Minimizing SSO Effort in Verifying SSL Anti-phishing Indicators
Yongdong Wu, Haixia Yao, Feng Bao 0001 |
SEC | 3 |
| 2007 | Forgery Attack to an Asymptotically Optimal Traitor Tracing Scheme
Yongdong Wu, Feng Bao 0001, Robert H. Deng |
ACISP | 2 |
| 2007 | Enhanced Security by OS-Oriented Encapsulation in TPM-Enabled DRM
Yongdong Wu, Feng Bao 0001, Robert H. Deng, Marc Mouffron, Frederic Rousseau 0002 |
Inscrypt | 2 |
| 2007 | Light-Weight Encryption Schemes for Multimedia Data and High-Speed NetworksabstractDue to the pervasiveness of high-speed networks and multimedia communications and storage, the demand for highspeed cryptosystems is ever increasing. It is widely believed that there is a tradeoff between speed and security in cryptosystem design. No existing encryption algorithms are both fast enough for high-speed operation and sufficiently secure to withstand powerful cryptanalysis. In this paper, we propose and analyze a generic construction of high-speed encryption schemes. Our solution is based on the fact that there exist secure but relatively slow block ciphers, e. g. AES, and super-fast but relatively weaker stream ciphers. We then combine a secure block cipher with a super-fast stream cipher such that the resulting encryption scheme possesses both the speed of the stream cipher and the security of the block cipher. We show the results our security analysis as well as our experiment on a 2.1 GHz Pentium VI processor. Feng Bao 0001, Robert H. Deng |
GLOBECOM | 1 |
| 2007 | Oblivious Keyword Search Protocols in the Public Database ModelabstractDatabases associated with keywords, can be public, private or hybrid, as a result the solutions to keyword search protocols for each type are different. In this paper, we study the problem of privacy-preserving keyword search in the public database model where the data-item is public but a client wishes to retrieve some data-item or search data-item, without revealing to the server which item it is. The contribution of this paper is of three fold. In the first fold, an efficient implementation of oblivious linear function evaluation protocols for secure two-party computation of a linear function over a finite field that does not emulate the circuit for computing oblivious linear function while at the same time it is provably secure against malicious adversary is presented. We show our implementation is provably secure assuming that the underlying Fujisaki-Okamoto's commitment scheme is informational hiding and computational binding as well Paillier's encryption scheme is semantically secure in the common reference string model. In the second fold, we further extend the techniques to non-linear polynomials and thus provide a secure reduction of OPE protocols of a polynomial of degree m, to m OPEs of linear polynomials. In the third fold, we use the OPEs for solving the oblivious keyword search problem along the Ogata and Kurosawa's ad hoc methodology, and show that our implementation is provably secure assuming that the underlying Fujisaki-Okamoto's commitment scheme is informational hiding and computational binding, Paillier's encryption scheme is semantically secure, G is a pseudo-random function in the common reference string model. Huafei Zhu, Feng Bao 0001 |
ICC | 2 |
| 2007 | Light-Weight Fair-Dealing Infrastructures (FADIS) for M-CommerceabstractAn important issue in mobile commerce (m-commerce) is to exchange digital data between two distributed parties in an efficient and fair manner. In this paper, a lightweight stand-alone and setup-free verifiably committed signature based on Schnorr signature scheme which aims to achieve efficiency and fairness for m-commerce is proposed. The idea behind of our construction is to encrypt the salt of a partial signature rather than to encrypt the whole partial signature. As a result, our construction is more efficient and thus more suitable for mobile environment compared with the best results in the literature. We further show that our scheme is provably secure in the random oracle model assuming that the Schnorr's signature scheme is secure against adaptive chosen message attack and Paillier's encryption scheme is one-way. Huafei Zhu, Feng Bao 0001 |
ICC | 2 |
| 2007 | Price Negotiation Systems for M-commerceabstractAs content delivery to wireless devices becomes faster and scalable, it is likely that mobile commerce will constitute a significant portion of digital commerce. In markets, business activities are coordinated through prices- values businesses assigns to resources. Since different businesses usually assign different values to the same resource, the parties involved need to negotiate a mutually acceptable agreement, the agreement details both sensitive and valuable and should be well protected. Although numerous implementations of fair-exchange protocols have been proposed, research addressing secure yet efficient price negotiation systems has not been reported. In this paper, we propose a novel price negotiation protocol. We make three contributions to price negotiation protocols for M-commerce. Firstly, we propose a new notion called revealable ring-signatures and formalize it. Using revealable ring-signatures, we derive our price negotiation protocols. Secondly,we provide an efficient implementation of revealable ring-signatures by allowing an individual party to generate a committed string so that a real signer can be traced when the committed string is revealed. Finally, we show that our implementation is provably secure in the random oracle model assuming that discrete logarithm over Z*pis hard. Huafei Zhu, Feng Bao 0001, A. Lakshminarayanan |
ICC | 2 |
| 2007 | Firewall for Dynamic IP Address in Mobile IPv6
Feng Bao 0001, Jianying Zhou 0001 |
ICICS | 2 |
| 2007 | n PAKE + : A Hierarchical Group Password-Authenticated Key Exchange Protocol Using Different Passwords
Zhiguo Wan, Robert H. Deng, Feng Bao 0001, Bart Preneel |
ICICS | 3 |
| 2007 | Evaluating Ouda's Tamper-Localization Watermarking SchemeabstractThis paper evaluates Ouda and El-Sakka scheme (OE for short) which is a tamper-localization watermarking. OE is a public block-wise scheme which enables everyone to identify the tampered regions. However, we point out OE scheme may identify a forge blocked to be intact, and accuse an intact block to be corrupted. Yongdong Wu, Feng Bao 0001 |
ICME | 3 |
| 2007 | Two-Party Privacy-Preserving Agglomerative Document Clustering
Chunhua Su, Jianying Zhou 0001, Feng Bao 0001, Tsuyoshi Takagi, Kouichi Sakurai |
ISPEC | 3 |
| 2007 | Privacy-Preserving Credentials Upon Trusted Computing Augmented Servers
Yanjiang Yang, Robert H. Deng, Feng Bao 0001 |
ISPEC | 3 |
| 2007 | Computing of Trust in Complex EnvironmentsabstractIn this paper, a novel information theoretical model for trust metrics in complex environments is proposed and analyzed. The contribution of this paper is two folds. In the first fold, syntax of actions is introduced and formalized in the context of disjunctive normal form over multiple Boolean variables, and random variables for describing an agent's behavior is formalized based on the notion of actions and auxiliary information (and auxiliary functions). The notion of trust is then formalized as a combination of a predicator and an evaluator of the current auxiliary information. In the second fold, we model contribution of a recommender's by a well studied notion - mutual information of variables of behavior and variables of auxiliary information. We show that our trust metrics is sound in the sense that - the definition of trust metrics is transitive; if a node (form the point view of the subject) in a recommendation path is not trusted by the subject, the contribution of this recommendation path is zero; the longer the size of a recommendation path, the less trust value should be computed from individual recommenders along the path. The proposed trust evaluation system is useful in reputation systems, risk management, collaborative filtering and social networking services. Huafei Zhu, Feng Bao 0001 |
PIMRC | 2 |
| 2007 | Securing Mobile Auctions in the Presence of Malicious AdversariesabstractThis paper studies practical auction systems for allocating resources in the wireless environments. The contribution of this paper is two-fold. In the first fold, a novel solution to mobile auction (m-auction) systems is presented based on the notion of convertibly undeniable signatures which in turn, can be viewed as a light-weight version of verifiably encrypted signatures in the bulletin board model. The idea behind of our construction is simple yet useful - we view salts that are used to mask convertibly undeniable signatures as public keys for authenticating bidding flows in m-auction systems. As a result, the cost of communication and computation for refreshing auxiliary information is zero and thus our systems are suitable for mobile devices whose computation resources are limited. In the second fold, we show that our implementation enjoys the following nice features: (i) it is provably secure in the standard intractability paradigm;(ii) it is provably secure against signature forgery attack; (iii) it is indistinguishable (addressing the stand-alone property of convertible signatures). Huafei Zhu, Feng Bao 0001 |
PIMRC | 3 |
| 2007 | Or-protocols for Anonymous Membership Proofs in Ad-hoc NetworksabstractAd-hoc networks formed by peers without relying on any preexisting infrastructure, have been a very attractive field of academic and industrial research in recent years due to their potential applications. An ad-hoc network allows a peer node further to form a task-driven sub-network such that each node in the generated sub-network may exchange data with each other but any other non-member node is prohibited to access the subnetwork. As a result, a task-driven subnetwork generated by a peer node definitely requires membership proof mechanism (in the scenario of anonymous communications, anonymous membership proof systems are required). In this paper, we provide a novel mechanism for anonymous access control (anonymous membership proof systems) in ad- hoc networks based on a new notion which we call or-protocols in the common reference string model. An or-protocol in essence is a three move zero-knowledge proof system that allows a peer node to prove its membership of a given set which is publicly verifiable. Our protocol is of constant size, i.e., the length of a proof is independent with number of users in a given set, and thus is suitable for practice. Furthermore we show that our protocol is provably secure assuming that the discrete logarithm problem defined over prime field is hard. Huafei Zhu, Feng Bao 0001 |
PIMRC | 3 |
| 2007 | Security Remarks on a Convertible Nominative Signature Scheme
Guilin Wang, Feng Bao 0001 |
SEC | 2 |
| 2007 | Securing RFID Tags: Authentication Protocols with Completeness, Soundness, and Non-TraceabilityabstractAlthough radio frequency identification (RFID) technology is promising, it is vulnerable and subject to a wide range of attacks due to possible tags compromise, difficulty in physical protection, absence of infrastructure and so on. Generally speaking, the threat to RFID systems mainly comes from the illegal reader's attempt to compromise tag identity. In order to protect the tag carries' privacy (intuitively, privacy for RFID tags means that the communication of a tag does not allow an adversary to determine the identity of the tag (non-traceability), however the reader should be able to determine whether the tag it reads is valid (completeness) and only such tags (soundness)), a security model that supports the analytical argument of properties, addressing both security and performance issues for RFID tags is introduced and formalized in this paper. The significant feature of our model is that a back-end database for a reader is explicitly introduced which allows the reader to search key-index set used by individual tags more efficiently, and describe the protocols in a unique way, where properties can be isolated and analyzed. We then propose an authentication protocol for securing RFID tags, and show that our implementation is completeness, soundness and non-traceability in the independent random oracle model. Huafei Zhu, Feng Bao 0001 |
WCNC | 2 |
| 2007 | Quantifying Trust Metrics of Recommendation Systems in Ad-Hoc NetworksabstractThe performance of ad-hoc networks depends on trust among distributed nodes. To enhance security in ad-hoc networks, it is important to evaluate trustworthiness of other nodes without centralized authorities. This paper studies trust metrics of recommendation systems in ad-hoc networks and makes the following three contributions: 1. the notion of action is formalized by means of disjunctive normal form (DNF) over Boolean variables and then the notion of trust is formalized in terms of action via transitive disclosure graphs; 2. a new trust metrics is formalized by means of mutual information, and we show that our trust metrics enjoys the following nice features: if a subject does not trust an intermediate node in a path, then trust value of the recommendation along the path is not trusted at all; the longer of a recommendation path, the less trust value along the path; and the trust reserves the transitivity; 3. our trust metrics satisfies Yao's Minmax principle. As a result, the expected running time of the optimal deterministic algorithm for an arbitrary chosen input distribution of auxiliary information is a lower bound on the expected running time of the optimal randomized algorithm for trust metrics. To the best of our knowledge, the ideas using mutual information to quantify trust and using maxmin to calculate trust established through multiple recommendation paths are first proposed in this paper. Since the claimed properties of our metrics cover all axioms of (Sun et al., 2006) and (Sun et al., 2006), it follows that our trust metrics can be viewed as a dynamic metrics of Sun et al's measurement while the later should be viewed as a static trust metrics where no recommendation is allowed. Finally, the efficiency of our maxmin mechanism for computing of trust may render it to be a highly reliable tool for stimulating cooperative behavior in ad-hoc networks. Huafei Zhu, Feng Bao 0001 |
WCNC | 2 |
| 2007 | Access control protocols with two-layer architecture for wireless networks
Zhiguo Wan, Robert H. Deng, Feng Bao 0001, Akkihebbal L. Ananda |
Comput. Networks | 3 |
| 2006 | More on Stand-Alone and Setup-Free Verifiably Committed Signatures
Huafei Zhu, Feng Bao 0001 |
ACISP | 2 |
| 2006 | Oblivious Scalar-Product Protocols
Huafei Zhu, Feng Bao 0001 |
ACISP | 2 |
| 2006 | Fortifying password authentication in integrated healthcare delivery systemsabstractIntegrated Delivery Systems (IDSs) now become a primary means of care provision in healthcare domain. However, existing password systems (under either the single-server model or the multi-server model) do not provide adequate security when applied to IDSs. We are thus motivated to present a practical password authentication system built upon a novel two-server model. We generalize the two-server model to an architecture of a single control server supporting multiple service servers, tailored to the organizational structure of IDSs. The underlying user authentication and key exchange protocols we propose are password-only, neat, efficient, and robust against off-line dictionary attacks mounted by both servers. Yanjiang Yang, Robert H. Deng, Feng Bao 0001 |
AsiaCCS | 3 |
| 2006 | Practical private data matching deterrent to spoofing attacksabstractPrivate data matching between the data sets of two potentially distrusted parties has a wide range of applications. However, existing solutions have substantial weaknesses and do not meet the needs of many practical application scenarios. In particular, practical private data matching applications often require discouraging the matching parties from spoofing their private inputs. In this paper, we address this challenge by forcing the matching parties to "escrow" the data they use for matching to an auditorial agent, and in the "after-the-fact" period, they undertake the liability to attest the genuineness of the escrowed data. Yanjiang Yang, Robert H. Deng, Feng Bao 0001 |
CIKM | 3 |
| 2006 | Batch Decryption of Encrypted Short Messages and Its Application on Concurrent SSL Handshakes
Yongdong Wu, Feng Bao 0001 |
Inscrypt | 2 |
| 2006 | Stand-Alone and Setup-Free Verifiably Committed Signatures
Huafei Zhu, Feng Bao 0001 |
CT-RSA | 2 |
| 2006 | Private Information Retrieval Using Trusted Hardware
Shuhong Wang 0001, Xuhua Ding, Robert H. Deng, Feng Bao 0001 |
ESORICS | 4 |
| 2006 | Cryptanalysis of Timestamp-Based Password Authentication Schemes Using Smart Cards
Guilin Wang, Feng Bao 0001 |
ICICS | 2 |
| 2006 | The Fairness of Perfect Concurrent Signatures
Guilin Wang, Feng Bao 0001, Jianying Zhou 0001 |
ICICS | 2 |
| 2006 | Preventing Web-Spoofing with Automatic Detecting Security Indicator
Fang Qi, Feng Bao 0001, Tieyan Li, Weijia Jia 0001, Yongdong Wu |
ISPEC | 2 |
| 2006 | More on Shared-Scalar-Product Protocols
Huafei Zhu, Feng Bao 0001, Tieyan Li |
ISPEC | 2 |
| 2006 | Privacy-Preserving Shared-Additive-Inverse Protocols and Their Applications
Huafei Zhu, Tieyan Li, Feng Bao 0001 |
SEC | 3 |
| 2006 | An Anonymous Routing Protocol with The Local-repair Mechanism for Mobile Ad Hoc NetworksabstractIn this paper, we first define the requirements on anonymity and security properties of the routing protocol in mobile ad hoc networks, and then propose a new anonymous routing protocol with the local-repair mechanism. Detailed analysis shows that our protocol achieves both anonymity and security properties defined. A major challenge in designing anonymous routing protocols is to reduce computation and communication costs. To overcome this challenge, our protocol is design to require neither asymmetric nor symmetric encryption/decryption while updating the flooding route requests; more importantly, once a route is broken, instead of re-launching a new costly flooding route discovery process like previous work, our protocol provides a local-repair mechanism to fix broken parts of a route without compromising anonymity Bo Zhu 0001, Sushil Jajodia, Mohan Kankanhalli, Feng Bao 0001, Robert H. Deng |
SECON | 4 |
| 2006 | Using Certificate-based Binding Update Protocol to Hide the Movement of Mobile Nodes in MIPv6abstractWhen a mobile node roams, its location information can be revealed from the IP prefix information of its care-of address. This paper proposes a technique for hiding a mobile node's care-of address from its correspondent node and its home address from an eavesdropper using reverse tunneling mode. In the protocol, any two real addresses regarding route optimization will never be included in a traffic packet. Hence the movement of mobile node can be hided from third party monitoring. Jianying Zhou 0001, Feng Bao 0001, Robert H. Deng |
VTC Spring | 3 |
| 2006 | Efficient key tree construction for group key agreement in ad hoc networksabstractIn this paper, we propose a highly efficient key agreement scheme based on a novel key tree construction for ad hoc networks. The key tree is constructed taking into consideration of the multicast tree which represents the underlying network topology. Our scheme greatly reduces the communications and computation cost for group key agreement and has high flexibility in having dynamic group memberships. We implement our scheme in ns-2 and evaluate its performance in terms of overhead and communication cost. The simulation results show that our scheme enjoys great advantages over other schemes in the literature Zhiguo Wan, Bo Zhu 0001, Robert H. Deng, Feng Bao 0001, Akkihebbal L. Ananda |
WCNC | 4 |
| 2006 | Compact routing discovery protocol with lower communication complexityabstractIn this paper, we first propose almost optimal sequential aggregate signatures in the simulation-based paradigm. We then provide an immediate application of the new primitive to construct compact routing discovery protocols Huafei Zhu, Feng Bao 0001, Chunxiao Chigan |
WCNC | 2 |
| 2006 | Turing assessor: a new tool for cyber security quantificationabstractIn this paper, a novel system level methodology for evaluating functionalities of network systems within general security model is introduced and formalized. We first decompose the entire system into a collection of subsystems each associated with a functionality. Thereafter, a new model for evaluating security properties of individual subsystem is built, which intends to implement a functionality by allowing an adversary to learn information and obtain knowledge from the correspondent subsystem via oracle queries. We further define evaluation and security metrics for security qualifications which is shown to be complete and robust within our model Huafei Zhu, Chunxiao Chigan, Feng Bao 0001 |
WCNC | 3 |
| 2006 | Routing optimization security in mobile IPv6
Kui Ren 0001, Wenjing Lou, Kai Zeng 0001, Feng Bao 0001, Jianying Zhou 0001, Robert H. Deng |
Comput. Networks | 4 |
| 2006 | Three architectures for trusted data dissemination in edge computing
Shen-Tat Goh, HweeHwa Pang, Robert H. Deng, Feng Bao 0001 |
Data Knowl. Eng. | 4 |
| 2006 | A Practical Password-Based Two-Server Authentication and Key Exchange SystemabstractMost password-based user authentication systems place total trust on the authentication server where cleartext passwords or easily derived password verification data are stored in a central database. Such systems are, thus, by no means resilient against offline dictionary attacks initiated at the server side. Compromise of the authentication server by either outsiders or insiders subjects all user passwords to exposure and may have serious legal and financial repercussions to an organization. Recently, several multiserver password systems were proposed to circumvent the single point of vulnerability inherent in the single-server architecture. However, these multiserver systems are difficult to deploy and operate in practice since either a user has to communicate simultaneously with multiple servers or the protocols are quite expensive. In this paper, we present a practical password-based user authentication and key exchange system employing a novel two-server architecture. Our system has a number of appealing features. In our system, only a front-end service server engages directly with users while a control server stays behind the scene; therefore, it can be directly applied to strengthen existing single-server password systems. In addition, the system is secure against offline dictionary attacks mounted by either of the two servers. Yanjiang Yang, Robert H. Deng, Feng Bao 0001 |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2006 | Analysis of a secure conference scheme for mobile communicationabstractDynamic participation is a feature of the secure conference schemes that allows new conferees to join and the old conferees to leave. The conferees who have left should not be able to decrypt the secure conference communication anymore. A secure conference scheme with dynamic participation was proposed in M.S. Hwang and W.P. Yang (1995) and later it was modified with the self-encryption mechanism in K.F. Hwang and C.C. Chang (2003) for a better performance. In this paper we analyze both the original scheme and the modified version. We show that both of them are subject to the active and passive attacks presented in this paper. Our active attack works in the way that a colluding group of attackers can still obtain the conference key even after they all leave the conference. The passive attack does not need any attacker to ever participate the conference. The conference key can be compromised with a large probability as long as the number of conferees is large. Feng Bao 0001 |
IEEE Trans. Wirel. Commun. | 1 |
| 2006 | Security analysis on a conference scheme for mobile communicationsabstractThe conference key distribution scheme (CKDS) enables three or more parties to derive a common conference key to protect the conversation content in their conference. Designing a conference key distribution scheme for mobile communications is a difficult task because wireless networks are more susceptible to attacks and mobile devices usually obtain low power and limited computing capability. In this paper we study a conference scheme for mobile communications and find that the scheme is insecure against the replay attack. With our replay attack, an attacker with a compromised conference key can cause the conferees to reuse the compromised conference key, which in turn completely reveals subsequent conversation content. Zhiguo Wan, Feng Bao 0001, Robert H. Deng, Akkihebbal L. Ananda |
IEEE Trans. Wirel. Commun. | 2 |
| 2005 | Security Analysis and Fix of an Anonymous Credential System
Yanjiang Yang, Feng Bao 0001, Robert H. Deng |
ACISP | 2 |
| 2005 | A Fast Correlation Attack on the Shrinking Generator
Bin Zhang 0003, Hongjun Wu 0001, Dengguo Feng, Feng Bao 0001 |
CT-RSA | 4 |
| 2005 | Augmented Oblivious Polynomial Evaluation Protocol and Its Applications
Huafei Zhu, Feng Bao 0001 |
ESORICS | 2 |
| 2005 | Designated Verifier Signature Schemes: Attacks, New Security Notions and a New Construction
Helger Lipmaa, Guilin Wang, Feng Bao 0001 |
ICALP | 3 |
| 2005 | Batching SSL/TLS Handshake Improved
Fang Qi, Weijia Jia 0001, Feng Bao 0001, Yongdong Wu |
ICICS | 3 |
| 2005 | Cryptanalysis of a Forward Secure Blind Signature Scheme with Provable Security
Shuhong Wang 0001, Feng Bao 0001, Robert H. Deng |
ICICS | 2 |
| 2005 | Generic, Optimistic, and Efficient Schemes for Fair Certified Email Delivery
Guilin Wang, Feng Bao 0001, Kenji Imamoto, Kouichi Sakurai |
ICICS | 2 |
| 2005 | Sequential Aggregate Signatures Working over Independent Homomorphic Trapdoor One-Way Permutation Domains
Huafei Zhu, Feng Bao 0001, Robert H. Deng |
ICICS | 2 |
| 2005 | Providing efficient certification services against active attacks in ad hoc networksabstractMost of previous research work in key management can only resist passive attacks, such as dropping the certificate request, and are vulnerable under active attacks, such as returning a fake reply to the node requesting the certification service. In this paper, we propose two algorithms to address both security and efficiency issues of certification services in ad hoc networks. Both of the algorithms can resist active attacks. In addition, simulation results show that, compared to the previous works, our second algorithm is not only much faster in a friendly environment, but it also works well in a hostile environment in which existing schemes work poorly. Furthermore, the process of generating partial certificates in our second algorithm is extremely fast. Such advantage is critical in ad hoc networks where by nature the less help a node requests from its neighbors, the higher is the chance of obtaining the help. Consequently, using our second algorithm, a node can easily find enough neighboring nodes which provide the certification service. Bo Zhu 0001, Guilin Wang, Zhiguo Wan, Mohan Kankanhalli, Feng Bao 0001, Robert H. Deng |
IPCCC | 5 |
| 2005 | Anonymous DoS-Resistant Access Control Protocol Using Passwords for Wireless NetworksabstractWireless networks have gained overwhelming popularity over their wired counterpart due to their great flexibility and convenience, but access control of wireless networks has been a serious problem because of the open medium. Passwords remain the most popular way for access control as well as authentication and key exchange. But existing password-based access control protocols are not satisfactory in that they do not provide DoS-resistance or anonymity. In this paper we analyze the weaknesses of an access control protocol using passwords for wireless networks in IEEE LCN 2001, and propose a different access control protocol using passwords for wireless networks. Our new protocol avoids the weaknesses of the previous protocol, and the client can anonymously authenticate himself to the server with a human-memorable password, while the server is free of DoS attacks. We also present detailed security and performance analysis for our protocols, and show that our protocol is both secure and efficient for access control in wireless networks Zhiguo Wan, Akkihebbal L. Ananda, Robert H. Deng, Feng Bao 0001 |
LCN | 4 |
| 2005 | An efficient certified e-mail scheme suitable for wireless mobile environmentsabstractAs security enhanced systems for standard e-mail, certified e-mail schemes guarantee the fair exchange of a digital message with the corresponding receipt between two mistrusted parties. That is, the intended receiver gets the e-mail content if and only if the e-mail sender obtains an irrefutable receipt issued by the receiver, which could be used to prove that the message has been delivered to the receiver. A number of such protocols have been proposed in recent years. However, most of them are not suitable for mobile networks, since many intricate cryptographic primitives are involved so that considerable overheads are introduced. In this paper, we present a novel simple protocol for certified e-mail delivery. Technical discussions are provided to show that our new solution is both secure and very efficient so that it is truly suitable for wireless mobile users, where the available devices usually have limited resources on computation, communication, storage, and power supply. Guilin Wang, Feng Bao 0001, Jianying Zhou 0001, Robert H. Deng |
PIMRC | 2 |
| 2005 | Provably secure public key management protocols for self-organized ad hoc networksabstractIn traditional public key infrastructures, centralized certification authorities are indispensable for managing public key certificates that are used to provide the witness of certain NP relations. However, it is difficult to deploy centralized certification authorities in ad hoc networks due to the lack of infrastructure and other central services. Nevertheless, public key management protocols-the fundamental security issues, should be proposed to nodes in a self-organized ad hoc network so that each node within this group can collaborate to others to compute certain tasks if its certificate is valid. In this paper, a secure yet efficient group signature scheme is first constructed which is provably secure within our model assuming that the strong RSA problem defined over Z/sub n/*, together with the decisional Diffie-Hellman defined over the quadruple residue QR/sub N//spl epsi/Z/sub N/* is hard. We then propose a public key management protocol for self-organized ad hoc networks by simply assuming that a group manager issues certificates to the nodes who want to join in and at the same time it revokes the certificates related those who are leaving. The technique presented in this paper is universal, and it can be used to numerous applications, e.g., the construction of anonymous routing protocols and incentive-based services in social networks, and so on. Huafei Zhu, Feng Bao 0001 |
PIMRC | 2 |
| 2005 | Secure Person-To-Person Communications Based on Biometrics Signals
Yongdong Wu, Feng Bao 0001, Robert H. Deng |
SEC | 2 |
| 2005 | A New Architecture for User Authentication and Key Exchange Using Password for Federated Enterprises
Yanjiang Yang, Feng Bao 0001, Robert H. Deng |
SEC | 2 |
| 2005 | A Novel Construction of Two-Party Private Bidding Protocols from Yao's Millionaires Problem
Huafei Zhu, Feng Bao 0001 |
TrustBus | 2 |
| 2005 | DoS-resistant access control protocol with identity confidentiality for wireless networksabstractIn this paper, we review a PKC (public key cryptosystem) based protocol, referred to as the Stanford protocol, aimed at overcoming several security deficiencies in IEEE 802.1X and to provide access control in both wireless and wired networks. One main objective of the Stanford protocol is to provide DoS resistance for the wireless network. Meanwhile, in the wireless environment, identity confidentiality of the mobile user is especially important since the disclosed identity could be used to locate the user and track his movement. But our analysis shows that the Stanford protocol fails to fulfill these requirements. So we propose a new PKC-based protocol that not only provides DoS resistance and perfect forward secrecy, but also provides identity anonymity for the clients. We also present detailed security and performance analysis for our protocol, and show that our protocol is secure and efficient for access control in wireless networks. Zhiguo Wan, Bo Zhu 0001, Robert H. Deng, Feng Bao 0001, Akkihebbal L. Ananda |
WCNC | 4 |
| 2005 | Sequential aggregate signatures for wireless routing protocolsabstractSequential aggregate signature, first introduced and formalized by A. Lysyanskaya et al. (see EUROCRYPT 2004, p.74-90, 2004), is emerging as a useful tool to ensure routing security and at the same time to improve performance. We propose a new mechanism to construct sequential aggregate signatures based on the cipher block chaining (CBC) mode, which is different from previous known results. We then construct an efficient sequential aggregate signature scheme and show that our construction is provably secure in the random oracle paradigm, assuming that the RSA problem is hard. Finally, we propose an interesting aggregate routing protocol for wireless ad hoc networks as an immediate application of our protocol. Huafei Zhu, Feng Bao 0001, Tieyan Li, Yongdong Wu |
WCNC | 2 |
| 2005 | Protocols that hide user's preferences in electronic transactions
Feng Bao 0001, Robert H. Deng |
Comput. Networks | 1 |
| 2005 | Efficient and robust key management for large mobile ad hoc networks
Bo Zhu 0001, Feng Bao 0001, Robert H. Deng, Mohan Kankanhalli, Guilin Wang |
Comput. Networks | 2 |
| 2005 | New Efficient MDS Array Codes for RAID Part I: Reed-Solomon-Like Codes for Tolerating Three Disk FailuresabstractThis paper presents a class of binary maximum distance separable (MDS) array codes for tolerating disk failures in redundant arrays of inexpensive disks (RAID) architecture based on circular permutation matrices. The size of the information part is m/spl times/n, the size of the parity-check part is m/spl times/3, and the minimum distance is 4, where n is the number of information disks, the number of parity-check disks is 3, and (m+1) is a prime integer. In practical applications, m can be very large and n is from 20 to 50. The code rate is R=n/(n+3). These codes can be used for tolerating three disk failures. The encoding and decoding of the Reed-Solomon-like codes are very fast. There need to be 3mn XOR operations for encoding and (3mn+9(m+1)) XOR operations for decoding. Gui Liang Feng, Robert H. Deng, Feng Bao 0001, Jia-Chen Shen |
IEEE Trans. Computers | 3 |
| 2005 | New Efficient MDS Array Codes for RAID Part II: Rabin-Like Codes for Tolerating Multiple (greater than or equal to 4) Disk FailuresabstractFor pt.1 see ibid., vol.54, no.9, p.1071-1080 (2005). A new class of binary maximum distance separable (MDS) array codes which are based on circular permutation matrices are introduced in this paper. These array codes are used for tolerating multiple (/spl ges/ 4) disk failures in redundant arrays of inexpensive disks (RAID) architecture. The size of the information part is m /spl times/ n, where n is the number of information disks and (m + 1) is a prime integer; the size of the parity-check part is m /spl times/ r, the minimum distance is r + 1, and the number of parity-check disks is r. In practical applications, m can be very large and n ranges from 20 to 50. The code rate is R = n/(n+r). These codes can be used for tolerating up to r disk failures, with very fast encoding and decoding. The complexities of encoding and decoding algorithms are O(rmn) and O(m/sup 3/r/sup 4/), respectively. When r = 4, there need to be 9mn XOR operations for encoding and (9n + 95)(m + 1) XOR operations for decoding. Gui Liang Feng, Robert H. Deng, Feng Bao 0001, Jia-Chen Shen |
IEEE Trans. Computers | 3 |
| 2005 | Tailored reversible watermarking schemes for authentication of electronic clinical atlasabstractIt is accepted that digital watermarking is quite relevant in medical imaging. However, due to the special nature of clinical practice, it is often required that watermarking not introduce irreversible distortions to medical images. The electronic clinical atlas has such a need of "lossless" watermarking. We present two tailored reversible watermarking schemes for the clinical atlas by exploiting its inherent characteristics. We have implemented the schemes and our experimental results look very promising. Feng Bao 0001, Robert H. Deng, Beng Chin Ooi, Yanjiang Yang |
IEEE Trans. Inf. Technol. Biomed. | 1 |
| 2004 | Analysis of a Conference Scheme Under Active and Passive Attacks
Feng Bao 0001 |
ACISP | 1 |
| 2004 | Analysis and Improvement of Micali's Fair Contract Signing Protocol
Feng Bao 0001, Guilin Wang, Jianying Zhou 0001, Huafei Zhu |
ACISP | 1 |
| 2004 | Cryptanalysis of Two Anonymous Buyer-Seller Watermarking Protocols and an Improvement for True Anonymity
Bok-Min Goi, Raphael C.-W. Phan, Yanjiang Yang, Feng Bao 0001, Robert H. Deng, Mohammad Umar Siddiqi |
ACNS | 4 |
| 2004 | Cryptanalysis of a Knapsack Based Two-Lock Cryptosystem
Bin Zhang 0003, Hongjun Wu 0001, Dengguo Feng, Feng Bao 0001 |
ACNS | 4 |
| 2004 | Colluding Attacks to a Payment Protocol and Two Signature Exchange Schemes
Feng Bao 0001 |
ASIACRYPT | 1 |
| 2004 | Security Analysis of the Generalized Self-shrinking Generator
Bin Zhang 0003, Hongjun Wu 0001, Dengguo Feng, Feng Bao 0001 |
ICICS | 4 |
| 2004 | On Security Notions of Steganographic Systems
Kisik Chang, Robert H. Deng, Feng Bao 0001, Sangjin Lee 0002, HyungJun Kim |
IWDW | 3 |
| 2004 | Anonymous Secure Routing in Mobile Ad-Hoc NetworksabstractAlthough there are a large number of papers on secure routing in mobile ad-hoc networks, only a few consider the anonymity issue. We define more strict requirements on the anonymity and security properties of the routing protocol, and notice that previous research works only provide weak location privacy and route anonymity, and are vulnerable to specific attacks. Therefore, we propose the anonymous secure routing (ASR) protocol that can provide additional properties on anonymity, i.e. identity anonymity and strong location privacy, and at the same time ensure the security of discovered routes against various passive and active attacks. Detailed analysis shows that ASR can achieve both anonymity and security properties, as defined in the requirements, of the routing protocol in mobile ad-hoc networks. Bo Zhu 0001, Zhiguo Wan, Mohan Kankanhalli, Feng Bao 0001, Robert H. Deng |
LCN | 4 |
| 2004 | Collusion attack on a multi-key secure video proxy schemeabstractIn ACM Multimedia'2002, a video proxy scheme was proposed for secure video delivery. In the scheme, a video is cached in proxies in encrypted form so that it remains non-disclosed even if the proxies are compromised. The proxies re-encrypt the video before its distribution, and different clients would receive different keys for the protected video. In this paper we present a security analysis on the scheme and show that the scheme is subject to collusion attack. Two or more clients working together can find out video server's secret keys and hence compromise the system. The countermeasure to the collusion attack is presented. Yongdong Wu, Feng Bao 0001 |
ACM Multimedia | 2 |
| 2004 | A scheme of digital ticket for personal trusted deviceabstractWe propose a digital ticket scheme for PTD (personal trusted device). The ticket here is in a broad sense such that all the valuable digital tokens such as event ticket, digital money (both digital cash and digital check), digital coupon, etc. are all included. We discuss various features of digital ticket and propose a uniform ticket format for PTD. We also propose a ticket content display scheme such that it matches the small screen of PTD. Feng Bao 0001 |
PIMRC | 1 |
| 2004 | Mobile personal firewallabstractMore and more activities (such as, e-commerce, e-learning, e-chat, etc.) rely on mobile devices. It is an important issue on how to protect mobile users engaged in mobile services. Unfortunately, the conventional firewalls are inappropriate for mobile networks because of the limited computing and communication capabilities of mobile devices. Furthermore, with a conventional firewall, a guardian is not able to monitor/control dynamically the mobile node's activities when the mobile node roams. In this paper, we introduce a new concept of mobile personal firewall and propose a concrete scheme that matches mobile environment and exploits mobile network facilities. When a mobile node (MN) roams into a foreign network managed by a mobility anchor point (MAP), the home agent (HA) will authorize the MAP to serve as a security proxy. The HA will negotiate with the MAP on the security association and then transfer to the MAP the defined security rules that will be applied on all communications to the MN (via the MAP). The MAP could send the MVs traffic logs to the HA. The MVs guardian could dynamically monitor the MVs activities by retrieving the MVs traffic logs through the HA. If necessary, the MVs guardian could update the security rules so that the MVs activities could be controlled dynamically. All the operations are transparent to the MN, and the MN will be served in the way specified by his guardian no matter where he roams. Jianying Zhou 0001, Feng Bao 0001 |
PIMRC | 3 |
| 2004 | Protecting all traffic channels in mobile IPv6 networkabstractIn this paper, we propose a comprehensive security solution for mobile IPv6 networks including secure binding update, secure fast handover, user authentication and session key management for data security. In our proposal, one of the home agent's functions is to act as a security proxy for its mobile nodes. The authentication is based on the home agent's certificate and the secret session keys are generated by strong cryptosystems. Since these session keys are long term, it is more suitable for fast handover in mobile network. In addition, as the major operations are deployed on the fixed and wired machines, i.e., the home agents of mobile nodes, it keeps well the balance between the strong security requirements for e-commerce and the weak capability of mobile devices in terms of computing power and communicating speed. Our proposal avoids many security obstacles in the return routability protocol and provides a simple, integrated and efficient security solution for mobile communication. Jianying Zhou 0001, Feng Bao 0001 |
WCNC | 3 |
| 2004 | Highly reliable trust establishment scheme in ad hoc networks
Kui Ren 0001, Tieyan Li, Zhiguo Wan, Feng Bao 0001, Robert H. Deng, Kwangjo Kim |
Comput. Networks | 4 |
| 2004 | New efficient user identification and key distribution scheme providing enhanced security
Yanjiang Yang, Shuhong Wang 0001, Feng Bao 0001, Jie Wang 0038, Robert H. Deng |
Comput. Secur. | 3 |
| 2004 | Cryptanalysis of a Partially Known Cellular Automata CryptosystemabstractCellular automata provide simple discrete deterministic mathematical models for physical, biological, and computational systems. Despite their simple construction, cellular automata are shown to be capable of complicated behavior and to generate complex and random patterns. There have been constant efforts to exploit cellular automata for cryptography since the very beginning of the research on cellular automata. Unfortunately, most of the previous cryptosystems based on cellular automata are either insecure or inefficient. In ICICS'0.2, Sen et al. made a new effort in cellular automata cryptosystems (CACs) design, where the affine cellular automata are combined with nonaffine transformations. It is claimed that the weakness in some of the previous CACs due to the affine property is removed. In this paper, we show that the new CAC is still insecure. It can be broken by a chosen-plaintext attack. The attack is very efficient, requiring only hundreds of chosen plaintexts and a small computation amount. We also consider the possibility of modifying the new CAC. Our results show, however, that it is not easy to secure the scheme by minor modifications. Feng Bao 0001 |
IEEE Trans. Computers | 1 |
| 2004 | A smart-card-enabled privacy preserving E-prescription systemabstractWithin the overall context of protection of health care information, privacy of prescription data needs special treatment. First, the involvement of diverse parties, especially nonmedical parties in the process of drug prescription complicates the protection of prescription data. Second, both patients and doctors have privacy stakes in prescription, and their privacy should be equally protected. Third, the following facts determine that prescription should not be processed in a truly anonymous manner: certain involved parties conduct useful research on the basis of aggregation of prescription data that are linkable with respect to either the patients or the doctors; prescription data has to be identifiable in some extreme circumstances, e.g., under the court order for inspection and assign liability. In this paper, we propose an e-prescription system to address issues pertaining to the privacy protection in the process of drug prescription. In our system, patients' smart cards play an important role. For one thing, the smart cards are implemented to be portable repositories carrying up-to-date personal medical records and insurance information, providing doctors instant data access crucial to the process of diagnosis and prescription. For the other, with the secret signing key being stored inside, the smart card enables the patient to sign electronically the prescription pad, declaring his acceptance of the prescription. To make the system more realistic, we identify the needs for a patient to delegate his signing capability to other people so as to protect the privacy of information housed on his card. A strong proxy signature scheme achieving technologically mutual agreements on the delegation is proposed to implement the delegation functionality. Yanjiang Yang, Xiaoxi Han, Feng Bao 0001, Robert H. Deng |
IEEE Trans. Inf. Technol. Biomed. | 3 |
| 2004 | Comments on "A Practical (t, n) Threshold Proxy Signature Scheme Based on the RSA Cryptosystem"abstractIn a (t, n) threshold proxy signature scheme, the original signer can delegate his/her signing capability to n proxy signers such that any t or more proxy signers can sign messages on behalf of the former, but t-1 or less of them cannot do the same thing. Such schemes have been suggested for use in a number of applications, particularly, in distributed computing where delegation of rights is quite common. Based on the RSA cryptosystem, [M. -S. Hwang et al. (2003) recently proposed an efficient (t, n) threshold proxy signature scheme. We identify several security weaknesses in their scheme and show that their scheme is insecure. Guilin Wang, Feng Bao 0001, Jianying Zhou 0001, Robert H. Deng |
IEEE Trans. Knowl. Data Eng. | 2 |
| 2003 | Cryptanalysis of a New Cellular Automata Cryptosystem
Feng Bao 0001 |
ACISP | 1 |
| 2003 | Making the Key Agreement Protocol in Mobile ad hoc Network More Efficient
Kui Ren 0001, Feng Bao 0001, Robert H. Deng, Dengguo Feng |
ACNS | 3 |
| 2003 | An improved personal CA for personal area networksabstractA personal certification authority (CA) for personal area networks (PANs) was presented in (C. Gehrmann, et al., (2002)). In this paper, we propose an improved version of the Personal CA which is more robust and secure than the original system. Robert H. Deng, Feng Bao 0001 |
GLOBECOM | 2 |
| 2003 | An invertible watermarking scheme for authentication of Electronic Clinical Brain AtlasabstractThe difficulty in watermarking medical imagery for authentication lies in the fact that watermarking itself should not introduce even one bit of alteration to the images. To this point, the recent invertible watermarking technique can help. However, the existing invertible watermarking schemes are not adaptable to the Electronic Clinical Brain Atlas (Nowinski et al. (1998)), a kind of "unnatural" palette images with respect to their uncorrelated contents. We develop an invertible watermarking scheme exclusively for authentication of the Electronic Clinical Brain Atlas. What makes our scheme special consists of the candidate points chosen for embedding and the encoding scheme to encode a bitstream. Furthermore, we present a general framework for invertible authentication watermarking, which encompasses virtually all existing schemes and more importantly, provides higher security over them. As an example, the proposed invertible scheme follows faithfully the framework. Our scheme really solves what others cannot. Yanjiang Yang, Feng Bao 0001 |
ICASSP (3) | 2 |
| 2003 | Variations of Diffie-Hellman Problem
Feng Bao 0001, Robert H. Deng, Huafei Zhu |
ICICS | 1 |
| 2003 | Security Remarks on a Group Signature Scheme with Member Deletion
Guilin Wang, Feng Bao 0001, Jianying Zhou 0001, Robert H. Deng |
ICICS | 2 |
| 2003 | An Efficient Known Plaintext Attack on FEA-M
Hongjun Wu 0001, Feng Bao 0001, Robert H. Deng |
ICICS | 2 |
| 2003 | An Efficient Public-Key Framework
Jianying Zhou 0001, Feng Bao 0001, Robert H. Deng |
ICICS | 2 |
| 2003 | The security flaws in some authentication watermarking schemesabstractWatermarking technology was originally proposed for copyright protection. Recently it has been applied to media authentication so that a proof of authenticity is inserted into the media instead of being appended to the media as a separated attachment. However, security requirements of the authentication are overlooked in some authentication watermark schemes. In this paper we analyze three authentication watermarking schemes and point out their security flaws. The first scheme is the color authentication scheme in [S.C. Byun et al., 2002]. The scheme is not secure in the sense that as long as an attacker obtains one authenticated image, he is able to forge authentic images without the secret key. The second scheme [Ping Wah Wing, et al., 2001] is an authentication scheme but it is extended for ownership incorrectly. The third one, the robust invertible watermarking scheme [J. Friedrich et al., 2002], employs a multiple of secret random sequences to produce a watermark. However these sequences are independent of the original images, i.e., they remain invariable for different images. An adversary, having sufficient number of original images, can reconstruct the secret sequences by solving simultaneous equations. With these reconstructed sequences, the attacker can forge authentic image freely. The attack can be thwarted with content related sequences generated from both the secret key and the original image. Yongdong Wu, Feng Bao 0001, Changsheng Xu |
ICME | 2 |
| 2003 | Security Analysis of a Password Authenticated Key Exchange Protocol
Feng Bao 0001 |
ISC | 1 |
| 2003 | Validating Digital Signatures without TTP's Time-Stamping and Certificate Revocation
Jianying Zhou 0001, Feng Bao 0001, Robert H. Deng |
ISC | 2 |
| 2003 | Flexible authentication of images
Yanjiang Yang, Feng Bao 0001, Robert H. Deng |
VCIP | 2 |
| 2002 | Cryptanalysis of Stream Cipher COS(2, 128) Mode I
Hongjun Wu 0001, Feng Bao 0001 |
ACISP | 2 |
| 2002 | Security Analysis and Improvement of the Global Key Recovery System
Yanjiang Yang, Feng Bao 0001, Robert H. Deng |
ACISP | 2 |
| 2002 | Defending against redirect attacks in mobile IPabstractThe route optimization operation in Mobile IP Version 6 (MIPv6) allows direct routing from any correspondent node to any mobile node and thus eliminates the problem of "triangle routing" present in the base Mobile IP Version 4 (MIPv4) protocol. Route optimization, however, requires that a mobile node constantly inform its correspondent nodes about its new care-of addresses by sending them binding update messages. Unauthenticated or malicious binding updates open the door for intruders to perform redirect attacks, i.e., malicious acts which redirect traffic from correspondent nodes to locations chosen by intruders. How to protect binding update messages to defend against redirect attacks is a challenging problem given the open environment in which MIPv6 operates. In this paper, we first look at two solutions proposed by the IETF Mobile IP Working Group and point out their weaknesses. We then present a new protocol for securing binding update messages. We also show that our protocol achieves strong security and at the same time is highly scalable to wide spread deployment. Robert H. Deng, Jianying Zhou 0001, Feng Bao 0001 |
CCS | 3 |
| 2001 | Secure and Private Distribution of Online Video and Some Related Cryptographic Issues
Feng Bao 0001, Robert H. Deng, Peirong Feng, Hongjun Wu 0001 |
ACISP | 1 |
| 2001 | Privacy Protection for Transactions of Digital Goods
Feng Bao 0001, Robert H. Deng |
ICICS | 1 |
| 2000 | Cryptanalysis of the m-Permutation Protection Schemes
Hongjun Wu 0001, Feng Bao 0001, Dingfeng Ye, Robert H. Deng |
ACISP | 2 |
| 2000 | Cryptanalysis of Polynominal Authentication and Signature Scheme
Hongjun Wu 0001, Feng Bao 0001, Dingfeng Ye, Robert H. Deng |
ACISP | 2 |
| 2000 | Introducing Decryption Authority into PKIabstractIt is well-known that CA plays the central role in PKI. We introduce a new component into PKI, DA (decryption authority), which decrypts important and sensitive messages for clients under certain conditions. A PKI with DA provides solutions to many security problems in e-commerce and online transactions. If we consider that public key cryptography provides both digital signature and asymmetric encryption technologies, DA completes PKI by adding the missing half function. More importantly, DA can greatly increase PKI implementation service revenue. We describe the application background and technical principle of DA, give a general explanation on how DA serves clients, and review some relevant research work. We believe that the PKI with DA has great potential to lead to a killing product for e-commerce security. Feng Bao 0001 |
ACSAC | 1 |
| 2000 | Electronic Payment Systems with Fair On-line Verification
Feng Bao 0001, Robert H. Deng, Jianying Zhou 0001 |
SEC | 1 |
| 2000 | Multicast Internet protocol
X.-K. Wang, Robert H. Deng, Feng Bao 0001 |
Comput. Commun. | 3 |
| 1999 | Evolution of Fair Non-repudiation with TTP
Jianying Zhou 0001, Robert H. Deng, Feng Bao 0001 |
ACISP | 3 |
| 1999 | Zero-Knowledge Proofs of Possession of Digital Signatures and Its Applications
Khanh Quoc Nguyen, Feng Bao 0001, Yi Mu 0001, Vijay Varadharajan |
ICICS | 2 |
| 1998 | Cryptanalysis of Rijmen-Preneel Trapdoor Ciphers
Hongjun Wu 0001, Feng Bao 0001, Robert H. Deng, Qin-Zhong Ye |
ASIACRYPT | 2 |
| 1998 | Improved Truncated Differential Attacks on SAFER
Hongjun Wu 0001, Feng Bao 0001, Robert H. Deng, Qin-Zhong Ye |
ASIACRYPT | 2 |
| 1998 | An Efficient Verifiable Encryption Scheme for Encryption of Discrete Logarithms
Feng Bao 0001 |
CARDIS | 1 |
| 1998 | Efficient and Practical Fair Exchange Protocols with Off-Line TTPabstractWe present protocols for fair exchange of electronic data (digital signatures, payment and confidential data) between two parties A and B. Novel properties of the proposed protocols include: 1) offline trusted third party (TTP), i.e., TTP does not take part in the exchange unless one of the parties behaves improperly; 2) only three message exchanges are required in the normal situation; 3) true fair exchange, i.e., either A and B obtain each other's data or no party receives anything useful; no loss can be incurred to a party no matter how maliciously the other party behaves during the exchange. This last property is in contrast to previously proposed protocols with offline TTP ([1] and [21]), where a misbehaving party may get another party's data while refusing to send his document to the other party, and the TTP can provide affidavits attesting to what happened during the exchange. To our knowledge, the protocols presented here are the first exchange protocols which use offline TTP and at the same time guarantee true fair exchange of digital messages. We introduce a novel cryptographic primitive, called the Certificate of Encrypted Message Being a Signature (CEMBS), as the basic building block of the fair exchange protocols. It is used to prove that an encrypted message is a certain party's signature on a public file, without revealing the signature. We also give two examples to show in detail how the certificate can be constructed. Feng Bao 0001, Robert H. Deng, Wenbo Mao |
S&P | 1 |
| 1997 | Design and Analyses of Two Basic Protocols for Use in TTP-Based Key Escrow
Feng Bao 0001, Robert H. Deng, Yongfei Han, Albert B. Jeng |
ACISP | 1 |
| 1997 | RSA-type Signatures in the Presence of Transient Faults
Marc Joye, Jean-Jacques Quisquater, Feng Bao 0001, Robert H. Deng |
IMACC | 3 |