EDBT 2026 Demo / reviewers in the wild / expert
Shijie Jia 0001
dblp:51/10138-1
· DBLP profile ↗
37ranked-venue papers
4as first author
22since 2021 · last 2026
0000-0002-4262-9478ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 22 · 4 first-author · 12 since 2021Computer networks · 13 · 8 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Systems, architecture and hardware · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | FBRoT: Transforming Flash Memory into Root of Trust for IoT Terminals
Yuewu Wang, Lingguang Lei, Shijie Jia 0001, Jiwu Jing |
SECON | 5 |
| 2026 | CryptoBinaryRz: a binary detection framework based on regional centralization dynamic analysis of cryptographic misuseabstractAbstract The correct application of cryptography is crucial for protecting confidentiality, integrity, and sensitive information in modern software systems. However, cryptographic APIs are frequently misused in practice because they are difficult to apply correctly and their security implications are often highly context dependent. Existing misuse detection research mainly targets source code, while binary-level detection remains underexplored despite its ability to access concrete runtime states and validate misuse conditions more directly. Binary analysis for cryptographic misuse faces three major challenges: severe path explosion, difficult parameter provenance recovery, and limited credibility of purely static results. To address these challenges, we present CryptoBinaryRz, a binary-level cryptographic misuse detection framework that combines locality-based region construction, context-aware dynamic provenance, path reuse-aware state management, and constraint-based misuse verification. Our method constrains analysis to sink-centered local regions, recovers parameter influence through symbolic mutation, restores nearby cryptographic calling environments through role abstraction, and reuses semantically equivalent paths during layered provenance expansion. In this way, the framework improves both scalability and semantic precision without relying on full control-flow graph construction. We also reformulate cryptographic misuse rules under a dynamic analysis setting so that runtime contexts and local calling environments can be jointly considered during verification. Experiments on 175 samples with isolated cryptographic behaviors and 11 real-world GitHub projects show that CryptoBinaryRz achieves over 95% detection accuracy and identifies 204 misuse instances, while substantially reducing the analysis cost associated with large binaries. These results suggest that binary-level analysis can provide richer and more trustworthy evidence for cryptographic misuse detection than source-level inspection alone. Zecheng Zhang, Lihua Yin, Shijie Jia 0001, Runda Huang |
Cybersecur. | 4 |
| 2025 | An RPKI Certificate Validator for Formal Correctness
Yajun Teng, Wei Wang 0314, Jingqiang Lin 0001, Shijie Jia 0001, Xiaoqi Jia |
ISPEC | 4 |
| 2025 | Malicious Node Detection Scheme in WSN Based on Secure Computation of Spatially Parallel Straight-Line DistanceabstractWith the wide applications of wireless sensor networks (WSN) in the fields of smart transportation and industrial internet of things (IIoT), there is an increasing demand for their security and trustworthiness. To solve the problem of WSN’s malicious nodes such as identity forgery attacks, node spoofing, and man-in-the-middle attacks, this paper proposes a scheme that detects malicious nodes by securely computing spatially parallel straight-line distance (SPSLD) and combining it with secure multi-party computation (MPC). This scheme uses the NTRU encryption algorithm with the additive homomorphism to design the SPSLD secure computation protocol under the semi-honest model, and for the malicious attack behaviors present in it, the secure protocol under the malicious model is proposed with the cut-and-choose method. The correctness of the protocol under different models is analyzed, and the security is proved by real/ideal model paradigm. Performance comparison and experimental simulation results indicate that, while ensuring security: The computational complexity of the semi-honest model protocol is reduced by at least 85% compared to Paillier-based schemes, with execution time shortened by 32-46%. The malicious model protocol is 12% faster than similar attack-resistant schemes, effectively defending against malicious adversary attacks, although additional overhead is introduced, its execution efficiency remains within an acceptable range for WSN environments, providing an efficient solution for enhancing the security and reliability of WSN. Xin Liu 0013, Huize Gao, Lanying Liang, Likai Jia, Shijie Jia 0001, Gang Xu 0006, Yu Gu 0010, Baohua Zhang 0004 |
IEEE Internet Things J. | 7 |
| 2025 | Revisiting Prediction-Based Min-Entropy Estimation: Toward Interpretability, Reliability, and Applicability
Dongchi Han, Tianyu Chen 0016, Shijie Jia 0001, Fangyu Zheng, Xianhui Lu |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2025 | SnifferDog: Comprehensively Learning Heterogeneous Features of Network Traffic to Identify Malicious FlowsabstractDeep learning has recently attracted significant attention in the field of network intrusion detection. Despite a substantial number of efforts have been made, previous works struggle to comprehensively learn the features of network traffic, resulting in inconsistent performance across various environments and attacks. To address these limitation, this study presents SnifferDog, a novel network attack detection system that takes raw packets as input and rationally extracts and integrates heterogeneous features involved in packets, flows and topology. It formats the packets and flows concurrently to achieve a high-level throughout for feature learning. Then, a flow pretraining model consisting of a LSTM, a self-attention and cross-attention layers is developed to learn both sequential and nonsequential inter packet relation features as initial flow vectors. Subsequently, a node-to-node and a node-to-edge attention layers are implemented to enhance an inductive GNN model that dynamically embeds the flow-to-flow and flow-to-topology relation features into the flow vectors. The resulting flow vectors involve comprehensive information of packet-to-packet, flow-to-flow and flow-to-topology relations, enabling high detection performance. In-lab experiments across eight datasets from diverse environments demonstrate SnifferDog’s superior effectiveness over existing solutions. A scalable prototype deployed in our institute’s network achieves a false positive rate of only 0.08%, validating SnifferDog’s practicality in real-world scenarios. Lihua Yin, Zeyan Liu, Shijie Jia 0001, Bo Luo, Hongli Xiang |
IEEE Trans. Inf. Forensics Secur. | 6 |
| 2024 | CryptoPyt: Unraveling Python Cryptographic APIs Misuse with Precise Static Taint AnalysisabstractCryptographic APIs are essential for ensuring the security of software systems. However, many research studies have revealed that the misuse of cryptographic APIs is commonly widespread. Detecting such misuse in Python poses challenges due to its intricate features, including dynamic features and pass-by-object-reference. Existing tools lack the precision and accuracy to tackle these challenges, leading to both high false positives and false negatives. In this work, we propose a specific Python Cryptographic Abstract Syntax Tree (PCAST) to represent the structure of source code, which rewrites AST nodes to handle complex Python features. Based on PCAST, we design and implement CryptoPyt, a static code analysis tool that leverages precise taint analysis and 17 cryptographic misuse rules to automatically identify potential cryptographic APIs misuse in Python projects. We conduct an in-depth analysis of all the APIs within the popular 21 Python cryptographic libraries and design five kinds of taint detectors to perform intra-procedural and inter-function analysis on the APIs and arguments. To demonstrate the effectiveness of CryptoPyt, we conduct experiments with six state-of-the-art tools (i.e., Cryptolation, LICMA, Bandit, Dlint, Semgrep and CodeQL) on both the labeled benchmark PyCryptoBench and the real-world Python cryptographic projects datasets PCAMD. Our evaluations show that CryptoPyt achieves an F1 score of 0.80 on PyCryptoBench and a recall rate of 99.08% on PCAMD. Furthermore, we disclose the discovered critical issues to the developers and seven high-level CVE IDs have been assigned to these findings. Our tool contributes to enhancing the security of Python cryptographic software. Xiangxin Guo, Shijie Jia 0001, Jingqiang Lin 0001, Fangyu Zheng, Guangzheng Li, Yueqiang Cheng, Kailiang Ji |
ACSAC | 2 |
| 2024 | Gopher: High-Precision and Deep-Dive Detection of Cryptographic API Misuse in the Go EcosystemabstractThe complexity of cryptographic APIs and developers' expertise gaps often leads to their improper use, seriously threatening information security. Existing cryptographic API misuse detection tools that rely on black/white-list methods require experts to manually establish detection rules. They struggle to dynamically update rules and scale to cover numerous unofficial cryptographic libraries. Furthermore, as these tools are primarily aimed at non-Go languages, they have limited applicability and accuracy in the Go ecosystem, which is extensively used for security-centric applications. To mitigate these challenges, we present Gopher, a novel cryptographic misuse detection framework, that excels in encapsulated API and cross-library detection. In this framework, we have designed CryDict to convert rules into unified and standardized constraints, capable of deriving new usage rules and elucidating implicit knowledge during scanning. Gopher leverages CryDict to create a logical separation between rule formulation and Detector detection, enabling dynamic updating of constraints and enhancing detection capabilities. This significantly improves the Gopher 's compatibility and scalability. Utilizing Gopher, we have conducted an extensive analysis of the Go ecosystem, examining 19,313 Go projects. In our rigorous testing, Gopher demonstrated a remarkable 98.9% accuracy rate and identified 64.1% of previously undetected misuses. This scrutiny has surfaced numerous hidden security vulnerabilities, and highlighted misuse tendencies across diverse project categories. Yuexi Zhang, Bingyu Li 0003, Jingqiang Lin 0001, Linghui Li 0001, Jia-Ju Bai, Shijie Jia 0001, Qianhong Wu |
CCS | 6 |
| 2024 | TLTracer: Dynamically Detecting Cache Side Channel Attacks with a Timing Loop TracerabstractRecently, cache side-channel attacks have gained increasing attention due to the significant threat they pose to data security. As research advances, these attacks have become more covert and their impact has been widened. To mitigate the threat posed by cache side-channel attacks, numerous de-tection approaches have been proposed. However, they struggle to capture runtime features or depend heavily on hardware performance counters (HPCs), resulting in a significant number of false negatives or false positives. To address this issue, this paper proposes a broadly applicable runtime feature for identifying cache side-channel attack programs and introduces a dynamic binary analysis approach, TLTracer. TLTracer is runtime trace-based, independent of HPCs and capable of scanning and detecting whether a binary program is malicious before it is deployed in the real world. We implement a prototype of TLTracer and evaluate it with a set of malicious and benign programs. The results show that it can effectively detect the latest cache side-channel attacks without false positives, and offer increased resilience against adversarial evasion compared to other detection tools. Lingjia Meng, Fangyu Zheng, Jingqiang Lin 0001, Shijie Jia 0001, Haoling Fan |
ICC | 5 |
| 2024 | TF-Timer: Mitigating Cache Side-Channel Attacks in Cloud through a Targeted Fuzzy TimerabstractCache side-channel attacks pose a significant threat to the data security of multi-tenant public clouds. However, currently proposed defenses either lack transparency (requiring user involvement) or incur a significant performance penalty. This paper is motivated by our insightful observation for the behavior of cache side-channel attackers who employ rdtsc/rdtscp instructions for timing purposes. We have discerned a behavior pattern that enables comprehensive identification of potential attackers. Building upon this observation, we introduce TF -timer, which operates on the core principle of inspecting cache side-channel attacks using the pre-identified behavior pattern while obscuring the return values of rdtsc/rdtscp instructions. Our proposed technique preserves the properties of rdtsc/rdtscp, only blurring the attacker's timing to minimize the impact on other applications. We have implemented the prototype of TF-timer at the hypervisor layer. It is completely transparent to users and requires no hardware modifications. Our evaluation results demonstrate that TF -timer efficiently and precisely miti-gates cache side-channel attacks that exploit rdtsc/rdtscp for timing, with performance penalties within 1 %. Shijie Jia 0001, Fangyu Zheng, Jingqiang Lin 0001, Lingjia Meng, Ziqiang Ma |
WCNC | 2 |
| 2024 | CAG-Malconv: A Byte-Level Malware Detection Method With CBAM and Attention-GRUabstractWith the rise of generative artificial intelligence, malware creation has become more accessible, leading to a surge in malware and its variants. Traditional detection methods struggle to keep pace with this evolution. Dynamic analysis, though detailed, is resource intensive and susceptible to variations in computer hardware and simulation environments. Static analysis, on the other hand, faces the challenge of discerning valuable features from an extensive pool, especially for software across diverse architectures. To tackle these issues, we propose a binary sample classification approach based on raw bytes, named CAG-Malconv, which incorporates Convolutional Block Attention Module (CBAM) and Bidirectional Gated Recurrent Unit (BiGRU) to extract byte-level features. We evaluated it on two datasets with 48,000 samples of different file types and families. It outperforms state-of-the-art methods based on advanced features and raw bytes in terms of accuracy (ACC), Area Under the Curve (AUC), F1 score, and recall. Furthermore, it allows for the visualization of raw samples, facilitating the precise identification of malicious components like C&C URLs and encryption loops by analyzing activation patterns in hidden layers, thus streamlining malware investigative procedures. Honghui Fan, Lihua Yin, Shijie Jia 0001, Kaiyan Zhao |
IEEE Trans. Netw. Serv. Manag. | 4 |
| 2023 | XPORAM: A Practical Multi-client ORAM Against Malicious Adversaries
Biao Gao, Shijie Jia 0001, Jiankuo Dong, Peixin Ren |
Inscrypt (1) | 2 |
| 2023 | JWTKey: Automatic Cryptographic Vulnerability Detection in JWT Applications
Shijie Jia 0001, Jingqiang Lin 0001, Fangyu Zheng, Xiaozhuo Gu |
ESORICS (3) | 2 |
| 2023 | Hydamc: A Hybrid Detection Approach for Misuse of Cryptographic Algorithms in Closed-Source SoftwareabstractCryptographic algorithms are fundamental to secure software development, but security vulnerabilities can arise during implementation, usage, and when calling third-party libraries. As security standards continue to evolve, software updates have become an inevitable trend, and detecting cryptographic algorithm misuse is crucial to ensure compliance with these standards during the update process. However, closed-source software presents challenges in detecting cryptographic algorithm misuse. To enhance the security ecosystem of software, we designed a hybrid detection approach for detecting misuses in closed-source software related to weak cryptographic algorithms, short keys, insecure working modes, and insecure padding modes. Our hybrid detection tool uses both static and dynamic detection methods to collect log information through a logging mechanism in binary executable files. The collected data is cleaned using a data cleaning strategy and analyzed to extract key features, generating test reports to help developers and experts identify cryptographic algorithm security issues. We tested 24 software applications from app stores and found that 62.5% had weak algorithm implementations or usage, 83.3% supported short keys, and 50% supported insecure padding modes. Finally, we provided actionable recommendations to mitigate identified issues. Haoling Fan, Fangyu Zheng, Jingqiang Lin 0001, Lingjia Meng, Shijie Jia 0001 |
TrustCom | 7 |
| 2023 | A Design of High-Efficiency Coherent Sampling Based TRNG With On-Chip Entropy AssuranceabstractTrue Random Number Generator (TRNG) is indispensable in cryptographic algorithms and protocols, and the quality of randomness directly influences the security of cryptographic applications. Multiple theoretical or offline entropy estimation methods have been proposed to evaluate the security of TRNGs, while their ideal assumptions commonly cannot be satisfied due to the perturbation of operating conditions at runtime, which makes it difficult to achieve sufficient entropy for the output of TRNGs in practice. Moreover, the output bitrate of TRNG is another fundamental concern during TRNG practical applications, while popular elementary oscillator-based structure commonly has relatively low output bitrate due to the inherent low sensitivity of entropy extraction to jitter (source of randomness). In this paper, we aim to design a TRNG satisfying both practical security (i.e., on-chip entropy assurance) and high output bitrate simultaneously. In particular, an improved stochastic model and a measurement method are established to quantify the entropy of coherent sampling based TRNG. Moreover, an on-chip entropy assurance module is provided to realize the robustness of the proposed design under various operating conditions. We implement the proposed TRNG in a simulation platform and ASIC chips (with SMIC 130 nm CMOS technology). Experimental results indicate that the generated data has sufficient entropy ($\geq 0.999$per bit) under various operating conditions. In addition, all the output can pass the NIST SP800-22 and AIS 31 statistical tests with an output bitrate of 4.2 Mbps, which is equivalent to 2 orders of magnitude faster than that of the elementary oscillator-based TRNG. Tianyu Chen 0016, Shijie Jia 0001, Yuan Cao 0003, Wei Wang 0314, Jing Yang 0032, Jingqiang Lin 0001 |
IEEE Trans. Circuits Syst. I Regul. Pap. | 2 |
| 2022 | CryptoGo: Automatic Detection of Go Cryptographic API MisusesabstractCryptographic algorithms act as essential ingredients of all secure systems. However, the expected security guarantee from cryptographic algorithms often falls short in practice due to various cryptographic application programming interfaces (API) misuses. While many research studies target cryptographic API misuses in the cases of Java, C/C++ and Python, similar issues within the Go domain are still uncovered. Shijie Jia 0001, Fangyu Zheng, Jingqiang Lin 0001 |
ACSAC | 2 |
| 2022 | An Empirical Study on the Quality of Entropy Sources in Linux Random Number GeneratorabstractRandom numbers are essential for communications security, as they are widely employed as secret keys and other critical parameters of cryptographic algorithms. The Linux random number generator (LRNG) is the most popular open-source software-based random number generator (RNG). The security of LRNG is influenced by the overall design, especially the quality of entropy sources. Therefore, it is necessary to assess and quantify the quality of the entropy sources which contribute the main randomness to RNGs. In this paper, we perform an empirical study on the quality of entropy sources in LRNG with Linux kernel 5.6, and provide the following two findings. We first analyze two important entropy sources: jiffies and cycles, and propose a method to predict jiffies by cycles with high accuracy. The results indicate that, the jiffies can be correctly predicted thus contain almost no entropy in the condition of knowing cycles. The other important finding is the failure of interrupt cycles during system boot. The lower bits of cycles caused by interrupts contain little entropy, which is contrary to our traditional cognition that lower bits have more entropy. We believe these findings are of great significance to improve the efficiency and security of the RNG design on software platforms. Mingshu Du, Tianyu Chen 0016, Shijie Jia 0001, Fangyu Zheng |
ICC | 5 |
| 2022 | You Cannot Fully Trust Your Device: An Empirical Study of Client-Side Certificate Validation in WPA2-Enterprise NetworksabstractWPA2-Enterprise networks offer access to the Internet widely for multifarious client devices. Certificate-based authentication is adopted on the client-side to authenticate the server during network connection. Due to a lack of professional knowledge, client users commonly fully trust the devices, which may result in insecure network connection and user credential leakage. Previous works commonly focus on the security vulnerabilities due to the design weaknesses of the user interfaces from mainstream operating systems, while the built-in certificate validation implementations, which act as a block box for users to validate the received certificates, are not taken into consideration.In this paper, we design a series of comprehensive testings to evaluate the built-in certificate validation implementations of mainstream client devices for the first time. Moreover, we investigate the configuration options provided by the devices from different vendors, which may downgrade the security of the certificate validation. We select both Windows and Android (from vendors with the largest five market share) devices as our empirical study target. The results show that more than one security vulnerability exists in the built-in certificate validation implementations of the selected devices, and all the selected devices provide a certain option which may downgrade the security of certificate validation. We also conduct a real Evil Twin attack, which reveals that the user credentials can be cracked due to the discovered security vulnerabilities. Our findings have been responsibly disclosed to the relevant device vendors, and we received an assortment of responses, meanwhile many vendors (e.g., Huawei) have already positively acknowledged our findings. Qiongxiao Wang, Shijie Jia 0001, Jingqiang Lin 0001, Linli Lu, Yanduo Fu |
TrustCom | 3 |
| 2022 | Approach then connect: A Physical Location-based Wi-Fi Password Dynamic Update SchemeabstractLarge-scale organizations usually deploy Wi-Fi to offer wireless network services for the target users, and password-based authentication is the most commonly adopted to identify Wi-Fi network users. However, multiple security issues occur in the password-based authentication schemes, such as using static passwords, unauthorized user access, and etc. To solve these problems, we propose a dynamic Wi-Fi password scheme updating passwords according to the location-based physical access controls, which is compatible with IEEE 802.11i protocols without introducing extra equipment or user efforts. We reuse the available location based resources in IEEE 802.11 to broadcast dynamic salt values for password updating and implement a prototype system. The experimental results illustrate that the introduced overhead is acceptable (i.e., the disconnection due to password update lasts less than 320ms). Qiongxiao Wang, Jingqiang Lin 0001, Shijie Jia 0001, Yingjiu Li, Yikai Chen |
WCNC | 4 |
| 2022 | MDEFTL: Incorporating Multi-Snapshot Plausible Deniability into Flash Translation LayerabstractConventional encryption solutions cannot defend against a coercive attacker who can capture the device owner, and force the owner to disclose keys used for decrypting sensitive data. To defend against such a coercive adversary, Plausibly Deniable Encryption (PDE) was introduced to allow the device owner to deny the very existence of sensitive data. The existing PDE systems built for computing devices equipped with flash storage media, are problematic, since they cannot defend against multi-snapshot adversaries, who may have access to the storage medium of a user's device at different points of time. In this article, we propose MDEFTL, a secure multi-snapshot PDE system for mobile devices which incorporates plausible deniability into Flash Translation Layer (FTL). MDEFTL is the first practical design which integrates multi-snapshot PDE into FTL, a pervasively deployed layer in literally all the current mobile devices. A salient advantage of MDEFTL lies in its capability of achieving multi-snapshot plausible deniability while being able to accommodate the special nature of NAND flash as well as eliminate deniability compromises from it. We implemented MDEFTL using an open-source NAND flash controller. The experimental results show that, compared to conventional encryption which does not provide deniability, our MDEFTL only incurs a small overhead. Shijie Jia 0001, Qionglu Zhang, Luning Xia, Jiwu Jing, Peng Liu 0005 |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2021 | Exploring Sequential and Collaborative Contexts for Next Point-of-Interest Recommendation
Shijie Jia 0001 |
KSEM | 4 |
| 2021 | P-Shake: Towards Secure Authentication and Communication between Mobile DevicesabstractUbiquitous mobile device applications exchange information through wireless channels (e.g., Bluetooth). However, the nature of the wireless channel raises multiple security communication problems (e.g., Man-in-the-Middle attack).In this paper, we propose P-Shake, a mechanism to achieve secure authentication and communication between mobile devices over insecure wireless channels, without any prior knowledge and synchronizing the internal clocks. In P-Shake, we first introduce the moving average filter and high-pass filter to mitigate the impacts of both tiny and relative movements of the mobile devices on the original acceleration data from accelerometers. Second, we employ Pearson correlation coefficient to authenticate the mobile devices by measuring the overall correlation of the acquired smoothed acceleration data. Third, we extract the common secrets between mobile devices to generate high-entropy session key. We make security analysis and extensive experiments to evaluate the security and performance of P-Shake. The results illustrate that P-Shake could achieve secure authentication and communication with higher feasibility than previous works. Shijie Jia 0001 |
WCNC | 3 |
| 2020 | Splitter: An Efficient Scheme to Determine the Geolocation of Cloud Data PubliclyabstractOutsourcing data to the cloud has become a trend, and the geolocation of cloud data attracts public attention in recent years, which is relevant to data availability (e.g., disaster tolerant), data security and policies (e.g. USA Patrio Act). Unfortunately, cloud service providers are not fully trusted to the data owners. This is because the data owners lose the physical control over the cloud data, and cloud service providers have the ability and motivation to change the geolocation of cloud data between different data centers. Therefore, designing a scheme to determine the geolocation of cloud data for data owners is an urgent problem to be solved.In this paper, we propose Splitter, an efficient scheme to determine the geolocation of cloud data publicly. In Splitter, we first design a splitting method, which breaks up the challenge and proof, and only considers the response delay resulting from the general operations (i.e., addition and multiplication) to obtain the accurate response delay. Second, we combine random forest algorithm and improved triangulation method to determine the geolocation accurately. Third, we take a series of theoretical comparison and extensive experiments to evaluate our scheme. The results illustrate the efficiency and practicality of our scheme. Dongzheng Jia, Shijie Jia 0001, Jingqiang Lin 0001 |
ICCCN | 3 |
| 2020 | Supporting Efficient Dynamic Update in Public Integrity Verification of Cloud DataabstractCloud storage is an increasingly popular service of cloud computing, which can provide convenient on-demand data outsourcing services and release the burden of maintaining local data for both individuals and organizations. However, the cloud service providers are not fully trusted by the users. The reason is that the users lose physical control of their cloud data, and the cloud service providers may conceal the status of the data when encountering data loss accidents for reputation. Therefore, it is critical for users to efficiently verify the integrity of cloud data.In this paper, we propose a public integrity verification scheme to support efficient dynamic update of cloud data based on Merkle Hash Tree linked list (MHT-list), which is a novel two-dimensional data structure we designed. This structure utilizes multiple merkle hash trees (MHTs) and a linked list to record data information at the cloud service provider side. Meanwhile, we exploit the structural advantages of the MHT-list to make our scheme more efficient in dynamic update and integrity verification than existing works. Moreover, we formally prove the security of the proposed scheme and evaluate the performance of our scheme by concrete extensive experiments. The results demonstrate that our proposed scheme achieves dynamic update effectively in public integrity verification of cloud data, and outperforms the previous works in computation and communication overhead. Jiawei Wan, Shijie Jia 0001 |
IPCCC | 2 |
| 2020 | DPVGeo: Delay-based Public Verification of Cloud Data GeolocationabstractKnowing the geolocation of cloud data becomes an urgent problem, which relates to cloud user equity (e.g., service compliance), service performance (e.g., disaster tolerance) and government regulations (e.g., GDPR). Unfortunately, data owners lose physical control after outsourcing data to the cloud service providers, while cloud service providers have the motivation (reducing economic costs and maximizing profits) and ability to move the data to other data centers in different geolocations. As a consequence, verifying whether the cloud data are in a specific geolocation is worthy of concern.In this paper, we propose a novel cloud data public verification scheme, DPVGeo, which allows any entity to verify the actual geolocation of cloud data remotely. In DPVGeo, we first design an atomic proof method, which divides the proof into several minimum computation units (i.e., atomic proof), and subtly only considers the normal operations (i.e., addition and multiplication), ignoring the time-consuming exponentiation operations, to obtain accurate response delay. Second, we utilize a thresholdbased closest-shortest approach to verify the geolocation of cloud data based on the response delay with high accuracy. Besides, we select both blocks and sectors randomly during each challenge to defend against the potential attacks (e.g., outsourcing attack, generation attack and replay attack). Finally, we perform a series of prototype implementations in real network environment to validate the performance of our design. The experimental results and security analysis show that our scheme is efficient and secure against semi-honest cloud service providers. Dongzheng Jia, Shijie Jia 0001, Jingqiang Lin 0001 |
ISCC | 3 |
| 2020 | SASAK: Shrinking the Attack Surface for Android Kernel with Stricter "seccomp" RestrictionsabstractThe following topics are dealt with: learning (artificial intelligence); mobile computing; security of data; Internet of Things; optimisation; resource allocation; data privacy; protocols; and cloud computing. Yingjiao Niu, Lingguang Lei, Yuewu Wang, Shijie Jia 0001, Chunjing Kou |
MSN | 5 |
| 2019 | eHIFS: An Efficient History Independent File SystemabstractSecurely deleting obsolete data is of significant importance, as reserving them may not only endanger data owners' privacy, but also violate data protection regulations like GDPR, SOX and HIPPA. However, completely eliminating data is extremely challenging in modern computer systems. One reason is the past existence of the deleted data may leave artifacts in the layout of a storage system at all layers, and such structural artifacts may be utilized by the adversary to derive sensitive information about the data having been deleted. A novel security notion, history independence, can ensure that memory representation of a data structure is independent of the operation sequences leading to it. Therefore, history independence can be utilized to remove the structural artifacts created by the deleted data, making it possible to achieve secure deletion guarantee. In this work, leveraging history independence, we build history independent systems. The existing history independent file system (HIFS) suffers from a significant degradation compared to the regular file system, rendering it impractical for real-world applications. A fundamental reason for such a degradation is, HIFS simply re-locates the entire data in a history independent manner for each single write. This is unfortunately unnecessary since a multi-snapshot adversary has observed a previous snapshot, and relocating data appearing in this old snapshot is vain and incurs unnecessary overhead. This will be exacerbated when the file system load factor is large. We thus design eHIFS, the first efficient History Independent File System, in which we smartly take advantage of knowledge on the adversary's observations and eliminate those unnecessary re-locations. Security analysis and experimental evaluation show that, compared to HIFS, eHIFS can achieve a similar history independence guarantee, with a 33X write throughput improvement when the file system load factor is 90%. Biao Gao, Bo Chen 0028, Shijie Jia 0001, Luning Xia |
AsiaCCS | 3 |
| 2019 | MimosaFTL: Adding Secure and Practical Ransomware Defense Strategy to Flash Translation LayerabstractRansomware attacks have become prevalent nowadays due to sudden flourish of cryptocurrencies. Most existing defense strategies for ransomware, however, are vulnerable to privileged ransomware who can compromise the operating system and hence any backup data stored locally. The out-of-place-update and the isolation nature of flash memory storage, for the first time, makes it possible to design a defense strategy which is secure against the privileged ransomware. In this work, we propose MimosaFTL, a secure and practical ransomware defense strategy for mobile computing devices equipped with flash memory as external storage. MimosaFTL is secure against the privileged malware by taking advantage of unique characteristics of flash storage. In addition, it is more practical (compared to prior work) for real-world deployments by: 1) incorporating a fine-grained detection scheme which can detect presence of ransomware accurately; and 2) allowing the victim to efficiently restore the infected external storage to the exact point when the malware starts to perform corruption. Experimental evaluation shows that, MimosaFTL can mitigate ransomware attacks effectively with a small negative impact on both I/O performance and lifetime of flash storage. Peiying Wang, Shijie Jia 0001, Bo Chen 0028, Luning Xia, Peng Liu 0005 |
CODASPY | 2 |
| 2019 | VoteGeo: An IoT-based Voting Approach to Verify the Geographic Location of Cloud HostsabstractWe propose VoteGeo, an IoT-based voting approach, to verify the geographic location of the cloud hosts in moderately connected networks, where the correlation between the network delay and the distance is weak. We motive our work by showing that: 1) existing solutions, based on end-to-end delay measurement from a group of landmarks with known locations, are only workable when the relationship between the delay and the distance is strong, and 2) such landmark-based schemes are limited by landmark distribution and deployment costs. In our scheme, to enhance the verification accuracy, we develop a vote-based closest-shortest approach to determine the location of the target cloud host, which utilizes the adjacent landmarks with the shortest delays. In order to reduce deployment costs, we adopt random IoT devices (i.e., IP cameras) as landmarks, which are widely distributed and considerable. To reduce the measurement cost, we design a two-level probing method to determine the geographic location of the target cloud hosts step by step, eventually to the city-level. We introduce a delay threshold method, which does not rely on the IP address of the target cloud hosts, to defend against the middlebox-bypass attacks and the delay attacks (i.e., delay-shortening attacks and delay-adding attacks). The evaluation results show that VoteGeo outperforms existing schemes such as GeoGet [1] and CBG [2]. Dongzheng Jia, Shijie Jia 0001, Jingqiang Lin 0001 |
IPCCC | 3 |
| 2018 | Ensuring data confidentiality via plausibly deniable encryption and secure deletion - a surveyabstractEnsuring confidentiality of sensitive data is of paramount importance, since data leakage may not only endanger data owners’ privacy, but also ruin reputation of businesses as well as violate various regulations like HIPPA and Sarbanes-Oxley Act. To provide confidentiality guarantee, the data should be protected when they are preserved in the personal computing devices (i.e., confidentiality during their lifetime ); and also, they should be rendered irrecoverable after they are removed from the devices (i.e., confidentiality after their lifetime ). Encryption and secure deletion are used to ensure data confidentiality during and after their lifetime, respectively. This work aims to perform a thorough literature review on the techniques being used to protect confidentiality of the data in personal computing devices, including both encryption and secure deletion. Especially for encryption, we mainly focus on the novel plausibly deniable encryption (PDE), which can ensure data confidentiality against both a coercive (i.e., the attacker can coerce the data owner for the decryption key) and a non-coercive attacker. Qionglu Zhang, Shijie Jia 0001, Bing Chang, Bo Chen 0028 |
Cybersecur. | 2 |
| 2017 | Supporting Transparent Snapshot for Bare-metal Malware Analysis on Mobile DevicesabstractThe increasing growth of cybercrimes targeting mobile devices urges an efficient malware analysis platform. With the emergence of evasive malware, which is capable of detecting that it is being analyzed in virtualized environments, bare-metal analysis has become the definitive resort. Existing works mainly focus on extracting the malicious behaviors exposed during bare-metal analysis. However, after malware analysis, it is equally important to quickly restore the system to a clean state to examine the next sample. Unfortunately, state-of-the-art solutions on mobile platforms can only restore the disk, and require a time-consuming system reboot. In addition, all of the existing works require some in-guest components to assist the restoration. Therefore, a kernel-level malware is still able to detect the presence of the in-guest components. Le Guan, Shijie Jia 0001, Bo Chen 0028, Fengwei Zhang, Bo Luo, Jingqiang Lin 0001, Peng Liu 0005, Xinyu Xing 0001, Luning Xia |
ACSAC | 2 |
| 2017 | DEFTL: Implementing Plausibly Deniable Encryption in Flash Translation LayerabstractMobile devices today have been increasingly used to store and process sensitive information. To protect sensitive data, mobile operating systems usually incorporate a certain level of encryption to protect sensitive data. However, conventional encryption cannot defend against a coercive attacker who can capture the device owner, and force the owner to disclose keys used for decrypting sensitive information. To defend against such a coercive adversary, Plausibly Deniable Encryption (PDE) was introduced to allow the device owner to deny the very existence of sensitive data stored on his/her device. The existing PDE systems, built on flash storage devices, are problematic, since they either neglect the special nature of the underlying storage medium (which is usually NAND flash), or suffer from deniability compromises. Shijie Jia 0001, Luning Xia, Bo Chen 0028, Peng Liu 0005 |
CCS | 1 |
| 2016 | Sanitizing data is not enough!: towards sanitizing structural artifacts in flash media
Bo Chen 0028, Shijie Jia 0001, Luning Xia, Peng Liu 0005 |
ACSAC | 2 |
| 2016 | NFPS: Adding Undetectable Secure Deletion to Flash Translation LayerabstractSecurely removing data from modern computing systems is challenging, as past existence of the deleted data may leave artifacts in the layout at all layers of a computing system, which can be utilized by the adversary to infer information about the deleted data. Conventional overwriting-based and encryption-based solutions are not sufficient, as they cannot remove these artifacts. In this work, we aim to securely remove data from NAND flash-based block devices. We observed that completely removing the aforementioned artifacts from NAND flash is expensive, as it may require re-organizing the entire flash layout. We thus approach this security goal from a new angle. We investigate undetectable secure deletion, a novel security notion which can 1) remove the deleted data from flash devices, such that the adversary cannot have access to the deleted data once they have been removed, and 2) conceal the deletion history, such that the adversary cannot find out there was a deletion in the past. We design NAND Flash Partial Scrubbing (NFPS), the first undetectable secure deletion scheme for NAND flash-based block devices. We propose partial page reprogramming and partial block erasure methods to sanitize data from NAND flash. In addition, we incorporate NFPS to typical Flash Translation Layer (FTL) algorithms. Finally, we implement NFPS and experimentally evaluate its effectiveness. Shijie Jia 0001, Luning Xia, Bo Chen 0028, Peng Liu 0005 |
AsiaCCS | 1 |
| 2016 | Physical-Layer Identification of HF RFID Cards Based on RF Fingerprinting
Guozhu Zhang, Luning Xia, Shijie Jia 0001, Yafei Ji |
ISPEC | 3 |
| 2015 | Chameleon: A Lightweight Method for Thwarting Relay Attacks in Near Field Communication
Yafei Ji, Luning Xia, Jingqiang Lin 0001, Guozhu Zhang, Shijie Jia 0001 |
ICICS | 6 |
| 2015 | Extracting Robust Keys from NAND Flash Physical Unclonable Functions
Shijie Jia 0001, Luning Xia, Jingqiang Lin 0001, Guozhu Zhang, Yafei Ji |
ISC | 1 |