EDBT 2026 Demo / reviewers in the wild / expert
Bingyu Li 0003
dblp:49/1389-3
· DBLP profile ↗
27ranked-venue papers
4as first author
20since 2021 · last 2026
0000-0001-5925-1638ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 18 · 3 first-author · 12 since 2021Computer networks · 7 · 1 first-author · 6 since 2021Systems, architecture and hardware · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Starlink in the Wild: Multi-Perspective Measurements via DNSabstractStarlink, the low-Earth orbit (LEO) satellite constellation developed by SpaceX, has rapidly become the world's largest commercial satellite network and a key component of the global Internet infrastructure. Despite its growing prominence, critical aspects of its terrestrial operations, including its internal network architecture, user behavior patterns, and potentially vulnerable exposed services, remain largely unexamined. This paper presents a multi-perspective measurement that characterizes Starlink's ground-side infrastructure and ecosystem from a DNS-centric viewpoint. First, we leverage internal DNS leakage to infer the structure of Starlink's private networks. Second, we analyze passive DNS data to identify user behavior patterns and service usage trends. Finally, we perform large-scale active scanning of Starlink's IP address space to evaluate its service deployment and security posture, utilizing DNS records to isolate infrastructure-related IPs from those of end-users. Collectively, our findings provide novel insights into the architecture, operation, and security of Starlink's terrestrial network. Ruoxuan Xia, Bingyu Li 0003, Pengyu Yuan, Jingqiang Lin 0001 |
WWW | 2 |
| 2026 | Black-Box Adaptation for Deepfake Detection via Local Relation Guided AUC OptimizationabstractDeepfake technologies pose a growing threat to the Internet of Things (IoT), enabling identity spoofing and the spread of misinformation. Although numerous face forgery detectors have been developed to counter these risks, their realworld deployment is often limited by inherent dataset biases. Existing domain adaptation techniques offer potential remedies, but typically rely on access to raw source data and employ data-dependent alignment strategies under a transductive learning paradigm, raising substantial privacy concerns for source domain individuals. This study revisits the problem from the perspective of black-box domain adaptation and introduces a detection framework that leverages only the predictions from the source model. The method is grounded in a local relation-guided AUC optimization strategy, which leverages the robustness of AUC-based objectives in noisy environments while addressing the limitations of conventional AUC optimization, particularly its vulnerability to confirmation bias and reliance on a fixed decision threshold. To this end, two key components are introduced. First, a nearest-neighbor calibration mechanism is presented, where the local relation feature (LRF), a parameter-free representation, captures differences between real and fake images without favoring specific forgery types, thereby reducing bias inherited from the source model. Second, a GMM-based adaptive thresholding scheme is employed to address asymmetric predictions by dynamically determining the optimal decision boundary for real and fake images. Experiments across multiple datasets show that our approach achieves superior generalization compared to state-of-the-art methods. Moreover, the framework is compatible with a broad range of source and target model configurations to enhance detection performance. Xiaotian Si, Linghui Li 0001, Bingyu Li 0003, Ziduo Guo, Kaiguo Yuan, Qi Tian 0001 |
IEEE Internet Things J. | 3 |
| 2026 | Quality-Agnostic Deepfake Detection With Saliency-Guided Restoration and Adaptive FusionabstractDeepfake technology poses a significant threat to the Internet of Things by enabling identity spoofing and the dissemination of misinformation. Although numerous face forgery detectors have been developed to counter the risks of facial deepfakes, detecting forgeries across varying quality levels, particularly under extreme degradations, remains a critical challenge. Current face forgery detection methods largely rely on identifying low-level artifacts, which are highly susceptible to distortions introduced by image degradation. Recognizing that restoration can recover critical forensic cues from severely degraded forgeries, this study proposes a quality-agnostic deepfake detection framework that leverages a blind face restoration model to enhance robustness. The framework incorporates an auxiliary restoration branch alongside the original detection pathway. While the original branch operates directly on the degraded input, the restoration branch performs detection on facial images restored by a blind face restoration model. In addition, a Saliency-Guided Restoration objective is introduced to enhance alignment between the restoration and detection tasks. A Restoration Similarity-Aware Fusion mechanism is further designed to adaptively integrate predictions from both branches based on input quality. To assess the robustness of our approach under extreme degradation, we establish a specialized, real-world-inspired benchmark that simulates diverse degradation scenarios. Comprehensive experiments on both the proposed and existing benchmarks demonstrate that our method consistently achieves superior robustness in various degradation scenarios. Xiaotian Si, Linghui Li 0001, Zhihao Tang 0002, Bingyu Li 0003, Kaiguo Yuan, Hong Liu 0009, Qi Tian 0001 |
IEEE Internet Things J. | 4 |
| 2026 | PlainDrop: Practical Asynchronous Proactive Secret Sharing With Silent SetupabstractDynamic Proactive Secret Sharing (DPSS) is essential for distributed systems, enabling long-term key escrow, BFT protocol reconfiguration, and confidential state machine replication. Yet existing asynchronous schemes, while crucial for realistic settings, suffer from high communication overhead and poor practicality, limiting real-world deployment. We propose PlainDrop, a concise and efficient DPSS protocol designed specifically for asynchronous networks. PlainDrop achieves optimized communication complexity ofO(n2) via commitment–share decoupling combined with homomorphic threshold encryption techniques. PlainDrop also eliminates the need for expensive distributed key generation and complex bivariate polynomial structures by introducing a lightweight silent setup framework and employing direct share processing based on univariate polynomials. We formally prove that PlainDrop provides secrecy, integrity, and termination in asynchronous networks against a mobile adversary corrupting up to one third of the parties. We implement PlainDrop and evaluate it on Amazon EC2 with up to 100 nodes. Our experimental results demonstrate average reductions of 37% and 67% in completion time, and 61% and 89% in communication volume, compared to DyCAPS and LongLive, respectively. Yang Yang 0062, Bingyu Li 0003, Qin Wang 0008, Qianhong Wu, Willy Susilo |
IEEE Internet Things J. | 2 |
| 2025 | FlexiADKG: A Flexible Asynchronous Distributed Key Generation Protocol with Constant Round Complexity
Yang Yang 0062, Bingyu Li 0003, Zhenyang Ding, Qianhong Wu, Qin Wang 0008 |
ACISP (1) | 2 |
| 2025 | Automatic Insecurity: Exploring Email Auto-configuration in the Wild
Shushang Wen, Yiming Zhang 0009, Yuxiang Shen, Bingyu Li 0003, Hai-Xin Duan, Jingqiang Lin 0001 |
NDSS | 4 |
| 2025 | DCARL: Decoupled-Curriculum for Adversarial Robustness Learning under Long-Tailed DistributionsabstractDeep neural networks are highly susceptible to adversarial attacks. Although adversarial training is an effective defense, its efficacy in long-tailed settings remains limited. Current methods are constrained in long-tailed scenarios by early representation bias, imbalanced optimization, and insufficient class-aware adaptivity. To address these challenges, we propose Decoupled-Curriculum Adversarial Robustness Learning, a two-stage framework. The Initial Representation and Balancing stage employs inter-class margin adjustment via LDAM with a Deferred Re-weighting schedule to build balanced, transferable representations. The Adaptive Correctness-Aware Robustness Learning stage adapts the per-class PGD perturbation budget using class-wise correctness signals and optimizes a balanced loss that combines mean, medium-class protection, and tail-class reinforcement components, aligning robust learning across head, medium, and tail classes. Experiments on standard long-tailed benchmarks validate the effectiveness of our approach, yielding consistent improvements in both natural and robust performance. Linghui Li 0001, Kaiguo Yuan, Bingyu Li 0003 |
TrustCom | 5 |
| 2025 | R2E: A Decentralized Scheme for Rewarding Tor Relays With CryptocurrenciesabstractTor's original design does not have an incentive mechanism but relies on volunteers to maintain their relay nodes for free, eventually leading to the current situation of centralization and lack of relay nodes. Current incentive schemes designed for Tor generally rely on centralized roles, thus presenting a risk of destroying Tor's anonymity. This paper proposes R2E, a decentralized scheme that treats Tor relay services as cryptocurrency mining and rewards the relays with generated tokens while addressing the challenge of how to design decentralized protocols that quantify workload while ensuring fairness and anonymity. We construct the Proof-of-Relay protocol in R2E that enforces random circuit selection, limits the number of nonce attempts, and exploits one-time keys and zero-knowledge proofs to protect participants' identities. We implemented a prototype of R2E based on Ethereum and conducted the trial operation and several confirmation experiments involving$2^{20}$clients,$2^{10}$to$2^{16}$nodes, and 256 circuits for each client to demonstrate its applicability. Analysis and experimental results show that R2E can effectively ensure the anonymity of participants' identities and fairness of incentive allocation while showing good performance in overhead and scalability, making it easy to be quickly applied in practical deployments. Xiaopeng Dai, Qianhong Wu, Bingyu Li 0003, Jialiang Fan, Fuyang Deng, Mingzhe Zhai |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2025 | RandFlash: Breaking the Quadratic Barrier in Large-Scale Distributed Randomness BeaconsabstractRandom beacons are of paramount importance in distributed systems (e.g., blockchain, electronic voting, governance). The sheer scale of nodes inherent in distributed environments necessitates minimizing communication overhead per node while ensuring protocol availability, particularly under adversarial conditions. Existing solutions have managed to reduce the optimistic overhead to a minimum ofO(n2), wherenrepresents the node count of the system. In this paper, we step further by proposing and implementing RandFlash, a leaderless random beacon protocol that achieves an optimistic communication complexity ofO(nlogn). Evaluation results demonstrate that RandFlash outperforms existing constructions, RandPiper (CCS’21) and OptRand (NDSS’23), in terms of the number of random beacons generated within largescale networks comprising 64 nodes or more (e.g., in sizes of 80 and 128). Furthermore, RandFlash exhibits resilience, capable of withstanding up to one-third of the nodes acting maliciously, all without the need for strongly trusted setups (i.e., embedding a secret trapdoor by trusted third parties). We also provide formal security proofs validating all properties upheld by this lineage. Yang Yang 0062, Bingyu Li 0003, Qianhong Wu, Qin Wang 0008, Shihong Xiong, Willy Susilo |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2024 | FreeAuth: Privacy-Preserving Email Ownership Authentication with Verification-Email-FreeabstractElectronic mail, as one of the most widely used identifiers, is extensively utilized for account registration and recovery, two-factor authentication, and organizational identification. Traditional email ownership authentication is typically achieved through verification codes or links sent via email, which leads to full disclosure of a user’s email address.We propose FreeAuth, an innovative and universal email ownership authentication scheme that enhances privacy by allowing users to selectively disclose email-related information. FreeAuth distinguishes itself from precedents by eschewing verification emails, thus avoiding spam marking and online behavior tracking. It establishes an authentication interaction paradigm based on widely deployed email transmission protocols, such as SMTP, IMAP, and POP3, ensuring legacy compatibility and server obliviousness. Meanwhile, it utilizes TLS Oracle schemes to protect data privacy by disclosing only the authentication outcome of the interaction, rather than revealing the full email address. FreeAuth can be integrated as an alternative to traditional email ownership authentication schemes.We present details of FreeAuth architecture and instantiations of prototype systems, along with three tailored examples of selective email address disclosures to align with various scenario requirements. The experimental analysis indicates that FreeAuth is compatible with up to 96% of existing email providers, and it is notably efficient, requiring only 2.5 seconds of online time to complete ownership authentication in our wide area network settings. Yijia Fang, Bingyu Li 0003, Jiale Xiao, Zhijintong Zhang, Qianhong Wu |
ACSAC | 2 |
| 2024 | Gopher: High-Precision and Deep-Dive Detection of Cryptographic API Misuse in the Go EcosystemabstractThe complexity of cryptographic APIs and developers' expertise gaps often leads to their improper use, seriously threatening information security. Existing cryptographic API misuse detection tools that rely on black/white-list methods require experts to manually establish detection rules. They struggle to dynamically update rules and scale to cover numerous unofficial cryptographic libraries. Furthermore, as these tools are primarily aimed at non-Go languages, they have limited applicability and accuracy in the Go ecosystem, which is extensively used for security-centric applications. To mitigate these challenges, we present Gopher, a novel cryptographic misuse detection framework, that excels in encapsulated API and cross-library detection. In this framework, we have designed CryDict to convert rules into unified and standardized constraints, capable of deriving new usage rules and elucidating implicit knowledge during scanning. Gopher leverages CryDict to create a logical separation between rule formulation and Detector detection, enabling dynamic updating of constraints and enhancing detection capabilities. This significantly improves the Gopher 's compatibility and scalability. Utilizing Gopher, we have conducted an extensive analysis of the Go ecosystem, examining 19,313 Go projects. In our rigorous testing, Gopher demonstrated a remarkable 98.9% accuracy rate and identified 64.1% of previously undetected misuses. This scrutiny has surfaced numerous hidden security vulnerabilities, and highlighted misuse tendencies across diverse project categories. Yuexi Zhang, Bingyu Li 0003, Jingqiang Lin 0001, Linghui Li 0001, Jia-Ju Bai, Shijie Jia 0001, Qianhong Wu |
CCS | 2 |
| 2024 | Certificate Transparency Revisited: The Public Inspections on Third-party Monitors
Aozhuo Sun, Jingqiang Lin 0001, Wei Wang 0314, Zeyan Liu, Bingyu Li 0003, Shushang Wen, Qiongxiao Wang, Fengjun Li |
NDSS | 5 |
| 2023 | IKE: Threshold Key Escrow Service with Intermediary Encryption
Yang Yang 0062, Bingyu Li 0003, Shihong Xiong, Yan Zhu 0023, Haibin Zheng, Qianhong Wu |
ICA3PP (3) | 2 |
| 2023 | Semi-CT: Certificates Transparent to Identity Owners but Opaque to SnoopersabstractCertificate Transparency (CT) enables timely detection of problematic certification authorities (CAs) by publicly recording all CA-issued certificates. This transparency inevitably leaks the privacy of identity owners (IdOs) through the identity information bound in certificates. In response to the privacy leakage, several privacy-preserving schemes have been proposed that transform/hash/encrypt the privacy-carrying part in certificates. However, these certificates conceal identity while also making it opaque to the IdO, which defeats the purpose of CT. To address the contradiction between transparency and privacy, we propose Semi-CT, a semi-transparency mechanism that makes the certificates transparent to IdOs but opaque to snoopers. Inspired by public-key encryption with keyword search (PEKS), Semi-CT based on bilinear pairing enables trapdoor-holding IdOs to retrieve certificates associated with their identity. Semi-CT also addresses protocol deviation detection and trapdoor protection in the malicious model. Finally, through theoretical and experimental analysis, we prove the security and feasibility of Semi-CT for practical applications. Aozhuo Sun, Bingyu Li 0003, Qiongxiao Wang, Huiqing Wan, Jingqiang Lin 0001, Wei Wang 0314 |
ISCC | 2 |
| 2023 | TGCN-DA: A Temporal Graph Convolutional Network with Data Augmentation for High Accuracy Insider Threat DetectionabstractInsider threats present a formidable challenge to cybersecurity, as insiders possess the privileges and information necessary to execute diverse attacks. A comprehensive analysis of user behavior, including behavioral features, sequences, and inter-user relationships, is required for effective insider threat detection. However, few existing methods consider these features in an integrated manner, which could result in high false positives. To further improve the accuracy of insider threat detection, we propose a novel framework for insider threat detection based on a temporal graph convolutional network with data augmentation (referred to as TGCN-DA), which integrates the exploration of structural information among users and simultaneously captures the behavior temporal dependencies. In particular, we introduce an edge predictor to encode user structural information and strengthen intra-class edges among users based on the representation of users’ behavior. Additionally, the GCN with temporal feature mechanism is leveraged to learn dynamic changes in users’ behavior to capture behavior temporal dependence. Extensive experiments demonstrate that our proposed TGCN-DA outperforms other state-of-the-art methods and achieves higher accuracy in the task of insider threat detection. Ximing Li 0005, Linghui Li 0001, Xiaoyong Li 0003, Binsi Cai, Bingyu Li 0003 |
TrustCom | 5 |
| 2023 | The Broken Verifying: Inspections at Verification Tools for Windows Code-Signing SignaturesabstractTerminal users can deploy verification tools to verify Windows code-signing signatures and check their details (signing time, certificate chain, etc). Some representative verification tools are also adopted in related studies, which take tools’ outputs as contributing factors to analyse malicious software or certificate ecosystems. However, as code-signing signature verification is related to multiple dimensions, such as certificate status and system policies, getting accurate signature status and details is essential but rather complicated. And performance of different tools in verifications has not been well studied and compared with.We provide a novel methodology to inspect Windows code-signing verification tools, checking that if they print consistent results and details. We choose four representative tools to verify massive samples (more than 26 million) and collect their outputs. During the verification, we deploy a two-step verification method, which efficiently excludes 78.8% of samples (not signed). We write scripts to read each line of outputs, learning tools’ output structures. Then we can precisely locate and extract interested code-signing fields from outputs. After that, we compare these essential fields from different tools, and analyze inconsistent cases. Finally, we present three types of inconsistent cases: verifying neglect, timestamp disturbance, and compatibility/robustness issues. We find some verification tools may assert code-signing signatures as invalid due to external factors, such as unexpected signing or invalid timestamp. Guangqi Liu, Qiongxiao Wang, Cunqing Ma, Jingqiang Lin 0001, Yanduo Fu, Bingyu Li 0003, Dingfeng Ye |
TrustCom | 6 |
| 2023 | Covert channels in blockchain and blockchain based covert communication: Overview, state-of-the-art, and future directions
Tao Zhang 0105, Bingyu Li 0003, Yan Zhu 0023, Tianxu Han, Qianhong Wu |
Comput. Commun. | 2 |
| 2023 | Reaching consensus for membership dynamic in secret sharing and its application to cross-chainabstractThe communication efficiency optimization, censorship resilience, and generation of shared randomness are inseparable from the threshold cryptography in the existing Byzantine Fault Tolerant (BFT) consensus. The membership in consensus in a blockchain scenario supports dynamic changes, which effectively prevents the corruption of consensus participants. Especially in cross-chain protocols, the dynamic access to different blockchains will inevitably bring about the demand for member dynamic. Most existing threshold cryptography schemes rely on redefined key shares, leading to a static set of secret sharing participants. In this paper, we propose a general approach to coupling blockchain consensus and dynamic secret sharing. The committee performs consensus confirmation of both dynamic secret sharing and transaction proposals. Our scheme facilitates threshold cryptography membership dynamic, thus underlying support for membership dynamic of threshold cryptography-based BFT consensus schemes. We instantiate a dynamic HotStuff consensus to demonstrate the effectiveness of the scheme. After the correctness and security proof, our scheme achieves the secrecy and integrity of the threshold key shares while ensuring consensus liveness and safety. Experimental results prove that our scheme obtains dynamic membership with negligible overhead. Yan Zhu 0023, Bingyu Li 0003, Zhenyang Ding, Yang Yang 0062, Qianhong Wu, Haibin Zheng |
High Confid. Comput. | 2 |
| 2022 | The Invisible Side of Certificate Transparency: Exploring the Reliability of Monitors in the WildabstractTo detect fraudulent TLS server certificates and improve the accountability of certification authorities (CAs), certificate transparency (CT) is proposed to record certificates in publicly-visible logs, from which the monitors fetch all certificates and watch for suspicious ones. However, if the monitors, either domain owners themselves or third-party services, fail to return a complete set of certificates issued for a domain of interest, potentially fraudulent certificates may not be detected and then the CT framework becomes less reliable. This paper presents the first systematic study on CT monitors. We analyze the data in 88 public logs and the services of 5 active third-party monitors regarding 3,000,431 certificates of 6,000 selected Alexa Top-1M websites. We find that although CT allows ordinary domain owners to act as monitors, it is impractical for them to perform reliable processing by themselves, due to the rapidly increasing volume of certificates in public logs (e.g., on average about 5 million records or 28.29 GB daily for the minimal set of logs that need to be monitored in 2018, or more than 7 million records per day in 2020, according to the Chrome CT policy). Moreover, our study discloses that (${a}$) none of the third-party monitors guarantees to return the complete set of certificates for a domain, and (${b}$) for some domains, even the union of the certificates returned by the five third-party monitors can probably be incomplete. As a result, the certificates accepted by CT-enabled browsers are not actually visible to the claimed domain owners, even when CT is adopted with well-functioning logs. The risk of invisible fraudulent certificates in public logs raises doubts on the reliability of CT in practice. Bingyu Li 0003, Jingqiang Lin 0001, Fengjun Li, Qiongxiao Wang, Wei Wang 0314, Qi Li 0002, Guangshen Cheng, Jiwu Jing, Congli Wang |
IEEE/ACM Trans. Netw. | 1 |
| 2021 | Locally-Centralized Certificate Validation and its Application in Desktop Virtualization SystemsabstractTo validate a certificate, a user needs to install the certificate of the root certification authority (CA) and download the certificate revocation information (CRI). Although operating systems and browsers manage the certificate trust list (CTL) of publicly-trusted root CAs for global users, locally-trusted root CAs still play an important role and it is difficult for a user to manage its CTL properly by itself. Meanwhile, the CRI access is inefficient, sometimes even unavailable, and causes privacy leakage. We revisit these problems by analyzing the TLS sessions within an organization. To the best of our knowledge, we are the first to analyze CTL management and CRI access on the scale of medium-sized organizations. Based on the analysis, a locally-centralized design is proposed to manage the CTLs of all users by IT administrators and access the CRI services for all users, within an organization. We apply this design to desktop virtualization systems to demonstrate its applicability, and build vCertGuard with oVirt and KVM-QEMU. In vCertGuard, the CTLs of all virtual machines (VMs) are managed in the VM monitors (VMMs). In the CTL, the self-signed certificates of publicly-trusted root CAs are properly configured, while each locally-trusted certificate chain is specified one by one. vCertGuard accesses the CRI services for all VMs, and the downloaded CRI is cached and shared among VMs. Because most TLS servers are visited by multiple users of an organization, it reduces the cost of CRI access. Experimental results of the prototype system show that vCertGuard maintains the CTLs with a negligible overhead, and significantly improves the performance of CRI access. Bingyu Li 0003, Jingqiang Lin 0001, Qiongxiao Wang, Jiwu Jing |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2019 | Certificate Transparency in the Wild: Exploring the Reliability of MonitorsabstractTo detect fraudulent TLS server certificates and improve the accountability of certification authorities (CAs), certificate transparency (CT) is proposed to record certificates in publicly-visible logs, from which the monitors fetch all certificates and watch for suspicious ones. However, if the monitors, either domain owners themselves or third-party services, fail to return a complete set of certificates issued for a domain of interest, potentially fraudulent certificates may not be detected and then the CT framework becomes less reliable. This paper presents the first systematic study on CT monitors. We analyze the data in 88 public logs and the services of 5 active third-party monitors regarding 3,000,431 certificates of 6,000 selected Alexa Top-1M websites. We find that although CT allows ordinary domain owners to act as monitors, it is impractical for them to perform reliable processing by themselves, due to the rapidly increasing volume of certificates in public logs (e.g., on average 5 million records or 28.29 GB daily for the minimal set of logs that need to be monitored). Moreover, our study discloses that (a) none of the third-party monitors guarantees to return the complete set of certificates for a domain, and (b) for some domains, even the union of the certificates returned by the five third-party monitors can probably be incomplete. As a result, the certificates accepted by CT-enabled browsers are not absolutely visible to the claimed domain owners, even when CT is adopted with well-functioning logs. The risk of invisible fraudulent certificates in public logs raises doubts on the reliability of CT in practice. Bingyu Li 0003, Jingqiang Lin 0001, Fengjun Li, Qiongxiao Wang, Qi Li 0002, Jiwu Jing, Congli Wang |
CCS | 1 |
| 2019 | Elaphurus: Ensemble Defense Against Fraudulent Certificates in TLS
Bingyu Li 0003, Wei Wang 0314, Lingjia Meng, Jingqiang Lin 0001, Xuezhong Liu, Congli Wang |
Inscrypt | 1 |
| 2019 | Analyzing the Browser Security Warnings on HTTPS ErrorsabstractHTTPS provides authentication, data confidentiality, and integrity for secure web applications in the Internet. In order to establish secure connections with the target website but not a man-in-the-middle or impersonation attacker, a browser shows security warnings to users, when different HTTPS errors happen (e.g., it fails to build a valid certificate chain, or the certificate subject does not match the domain visited). Each browser implements its own design of warnings on HTTPS errors, to balance security and usability. This paper presents a list of common HTTPS errors, and we investigate the browser behaviors on each error. Our study discloses browser defects on handling HTTPS errors in terms of cryptographic algorithm, certificate verification, name validation, HPKP, and HSTS. Congli Wang, Jingqiang Lin 0001, Bingyu Li 0003, Qi Li 0002, Qiongxiao Wang |
ICC | 3 |
| 2018 | PoS: Constructing Practical and Efficient Public Key Cryptosystems Based on Symmetric Cryptography with SGX
Huorong Li, Jingqiang Lin 0001, Bingyu Li 0003, Wangzhao Cheng |
ICICS | 3 |
| 2018 | Building Your Private Cloud Storage on Public Cloud Service Using Embedded GPUs
Wangzhao Cheng, Fangyu Zheng, Wuqiong Pan, Jingqiang Lin 0001, Huorong Li, Bingyu Li 0003 |
SecureComm (1) | 6 |
| 2017 | High-Performance Symmetric Cryptography Server with GPU Acceleration
Wangzhao Cheng, Fangyu Zheng, Wuqiong Pan, Jingqiang Lin 0001, Huorong Li, Bingyu Li 0003 |
ICICS | 6 |
| 2017 | SSUKey: A CPU-Based Solution Protecting Private Keys on Untrusted OS
Huorong Li, Wuqiong Pan, Jingqiang Lin 0001, Wangzhao Cheng, Bingyu Li 0003 |
ICICS | 5 |