Fei Yan 0008

dblp:52/4851-8 · DBLP profile ↗
← Back
11ranked-venue papers
0as first author
4since 2021 · last 2025
0000-0003-0492-3278ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 5 · 3 since 2021Security and privacy · 5 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1
YearPublicationVenuePosition
2025 MinMaxEntropy: Bound Model Errors for Side-Channel Leakages From Information Theory
abstract
Side-channel attacks and evaluations have been incessantly pursuing an accurate leakage model and try to address the following question: “How good is my leakage model?” However, the existing works do not well alleviate the attackers and evaluators from model assumption error and estimation error. The recent work named maximum entropy distribution (MED) model does not depend on any assumptions but uses nonlinear programming Newton-Raphson method to fit the leakage distribution, thus avoiding assumption error and making the estimation error arbitrarily small. It tries to address a more fundamental problem: “How to achieve the optimal leakage model?,” but still have to face with two issues: 1) the large deviation of MED model from leakage distribution and 2) the difficulty in determining the moments required in model profiling. In this article, we first introduce the nonlinear programming optimizations Levenberg-Marquardt and Conjugate Gradient methods to tackle the first issue. We then exploit Hopfield neural network to solve the minimum entropy for leakage model. Unlike the MED indicating the theoretically most unbiased, objective and reasonable leakage model, the minimum entropy corresponds to the theoretically most biased, subjective and unreasonable leakage model. This facilitates us to build a MinMaxEntropy bound from the maximum entropy and minimum entropy for estimation errors in leakage model, which theoretically represents the amount of information contained on unused higher moments. This bound well provides theoretical support for the moments constraints required to profile the MED model, thus well tackling the second issue. Experimental results fully demonstrate the superiority of our above schemes.
Changhai Ou, Zhenfang Qiu, Xingshuo Han, Fan Zhang 0010, Shihui Zheng, Fei Yan 0008
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst.6
2023 SvTPM: SGX-Based Virtual Trusted Platform Modules for Cloud Computing
abstract
Virtual Trusted Platform Modules (vTPMs) are widely used in commercial cloud platforms (e.g., VMware Cloud, Google Cloud, and Microsoft Azure) to provide virtual root-of-trust and security services for virtual machines. Unfortunately, current state-of-the-art vTPM implementations for cloud computing cannot provide strong protection for vTPMs at run-time and suffer from poor performance under binding vTPMs to a physical TPM. In this paper, we propose SvTPM, an SGX-based virtual trusted platform module, which provides complete life cycle protection of vTPMs in the cloud and does not rely on the physical TPM. SvTPM provides strong isolation protection so malicious cloud tenants or even cloud administrators cannot access vTPM's private keys or any other sensitive data. In this paper, we implement a prototype of SvTPM, which identifies and solves a couple of critical security challenges for vTPM protection with SGX, such as NVRAM rollback attacks, NVRAM binding attacks, and vTPM rollback attacks. SvTPM also shows how to establish trust between vTPM and SGX Platform. Our performance evaluation shows that the NVRAM launch time of SvTPM is$1700\times$faster than vTPM built upon hardware TPM. In TPM standard command evaluation, we find that SvTPM incurs negligible performance overhead while providing strong isolation and protection. To our knowledge, SvTPM is the first practical work to solve the critical security challenges of securing vTPM using SGX.
Juan Wang 0006, Jie Wang 0006, Chengyang Fan, Fei Yan 0008, Yueqiang Cheng, Yinqian Zhang, Mengda Yang, Hongxin Hu
IEEE Trans. Cloud Comput.4
2022 TECS: A Trust Model for VANETs Using Eigenvector Centrality and Social Metrics
abstract
Vehicular Ad Hoc Networks (VANETs) rely heavily on trustworthy message exchanges between vehicles to enhance traffic efficiency and transport safety. Although cryptography-based methods are capable of alleviating threats from unauthenticated attackers, they can not prevent attacks from those legitimate network participants. This paper proposes a trust model to deal with attackers from the latter case, who can tamper with their received messages and deliberately decrease the trust value of benign vehicles. The trust evaluation process is formed by two stages: (i) the local trust evaluation at vehicles and (ii) trust aggregation on Road Side Units (RSUs). In the local trust evaluation stage, vehicles detect attacks and calculate the trust value for others in a distributed manner. Also, the social metrics of vehicles are calculated based on interaction records and trajectories. In the trust aggregation stage, each RSU collects local data from nearby vehicles and derives aggregation weights from the eigenvector centrality of the local trust network and social metrics. Then the RSU broadcasts the aggregated trust value towards vehicles in proximity. These vehicles can thus obtain a more accurate and comprehensive view. Vehicles with trust value below a preset threshold will be considered malicious. Extensive simulations based on the ONE simulator show that the proposed model (TECS) outperforms another benchmark model (IWOT-V) regarding the malicious vehicle detection and the delivery rate of authentic messages.
Yue Cao 0002, Xuefeng Ren, Fei Yan 0008
TrustCom6
2022 The devil is in the detail: Generating system call whitelist for Linux seccomp
Yunlong Xing, Jiahao Cao 0001, Kun Sun 0001, Fei Yan 0008, Shengye Wan
Future Gener. Comput. Syst.4
2020 Table Recomputation-Based Higher-Order Masking Against Horizontal Attacks
abstract
Masking is a class of well-known countermeasure against side-channel analysis by employing the idea of secret sharing. The theoretical security proof model of higher-order masking was initiated by Ishai, Sahai, and Wagner, and Barthe et al. pushed forward it by proposing a more refine security definition named as t-SNI security. In CHES 2016, a new attack called horizontal side-channel attacks (HSCAs) came forward and successfully broke the Rivain-Prouff countermeasure, which has been proved to satisfy the t-SNI security. It presents a dilemma: instead of more secure, masking with higher-order may be more vulnerable due to the HSCA. Although there already exists an effective countermeasure for the Rivain-Prouff scheme, it is quite difficult to apply this method in the table recomputation-based higher-order masking schemes, such as the scheme introduced by Coron in EUROCRYPT 2014. To fill this gap, we propose a new table recomputation-based higher-order masking scheme, named as table compression masking (TCM) scheme. While meeting the t-SNI security, our new countermeasure is also secure against the HSCA. We give the formal security proof under the t-SNI security definition, as well as a heuristic security analysis considering the HSCA. Our analysis shows that, by dividing the full lookup table into many distinct parts and shifting them by refreshed shares, the same share will never be manipulated for more than twice in TCM scheme. This feature gives a heuristic security against HSCA. To our best knowledge, our countermeasure is the first solution for table recomputation-based higher-order masking to resist HSCA.
Zhipeng Guo 0002, Ming Tang 0002, Emmanuel Prouff, Maixing Luo, Fei Yan 0008
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst.5
2019 Detecting and Mitigating Target Link-Flooding Attacks Using SDN
abstract
DDoS attacks have caused very serious damage to enterprise networks. Recently, a new kind of DDoS attack called link-flooding attack (LFA), has surfaced and is already being used by attackers to flood and congest network critical links. LFA is very difficult to detect since adversaries often utilize large-scale legitimate low-speed flows and rolls target links to isolate target areas for launching attacks. To address such a critical security problem, we design and implement a novel LFA defense system called LFADefender that leverages some key features, such as programmability, network-wide view, and flow traceability, of an emerging network technology, Software-Defined Networking (SDN), to effectively detect and migrate LFA. In LFADefender, we propose a LFA target link selection approach and design a LFA congestion monitoring mechanism to effectively detect LFA. In addition, we present a multiple optional paths rerouting method to temporarily mitigate links congestion caused by LFA. We further propose a malicious traffic blocking approach to radically mitigate LFA. Our evaluation results show that LFADefender can accurately detect and rapidly mitigate LFA, but only imposes minimal overhead in the communication channels between network controllers and data planes.
Juan Wang 0006, Ru Wen, Jiangqi Li, Fei Yan 0008, Bo Zhao 0023, Fajiang Yu
IEEE Trans. Dependable Secur. Comput.4
2018 Leak Point Locating in Hardware Implementations of Higher-Order Masking Schemes
abstract
Secure masking schemes have been proven in theory to be secure countermeasures against side-channel attacks. The security framework proposed by Ishai, Sahai and Wagner, known as the Ishai-Sahai-Wagner scheme, is one of the most acceptable secure models of the existing dth-order masking schemes, where d represents the masking order and plays the role of a security parameter. However, a gap may exist between scheme and design. Several analyses have determined that the glitch has been regarded as the main challenge of masking in hardware designs. A practical method of locating the precise position of leakage points (LPs) in the original hardware design is very rare. Existing research on this glitch mainly focuses on the first-order leakages; however, higher-order analysis can combine several shares to recover the secret key. In this paper, we propose a practical method, sensitive glitch location (SGL) method to locate the less order leakage in hardware design. Specifically, the SGL method can locate any-order of LP in the hardware implementation of dth-order masking schemes. We conducted experiments and verified that the time complexity of SGL on the dth-order masking schemes is O(nm), where m is the number of signals and n is the number of shares in masking scheme. It can therefore be regarded as an efficient tool for the masking designs. In addition, we analyzed the dth-order masking scheme proposed by Rivain and Prouff (2010) along with the SecMult algorithm from the Rivain-Prouff countermeasure, which has been analyzed by our SGL. The experimental results verified that a higher-order leakage may exist in certain hardware designs, even the masking scheme has been proven as a secure countermeasure. To the best of our knowledge, SGL is the first tool that can be used to locate any-order of power/electromagnetic LP in hardware designs. It thus shows the weakness in the original design file of hardware implementations. This property can help designers directly improve the real security of the designs. Moreover, SGL returns the path of the leakages, which can elucidate the original cause and propagation of the weakness.
Ming Tang 0002, Yanbin Li 0001, Dongyan Zhao 0002, Yuguang Li, Fei Yan 0008, Huanguo Zhang
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst.5
2017 CHAOS: An SDN-Based Moving Target Defense System
abstract
Moving target defense (MTD) has provided a dynamic and proactive network defense to reduce or move the attack surface that is available for exploitation. However, traditional network is difficult to realize dynamic and active security defense effectively and comprehensively. Software-defined networking (SDN) points out a brand-new path for building dynamic and proactive defense system. In this paper, we propose CHAOS, an SDN-based MTD system. Utilizing the programmability and flexibility of SDN, CHAOS obfuscates the attack surface including host mutation obfuscation, ports obfuscation, and obfuscation based on decoy servers, thereby enhancing the unpredictability of the networking environment. We propose the Chaos Tower Obfuscation (CTO) method, which uses the Chaos Tower Structure (CTS) to depict the hierarchy of all the hosts in an intranet and define expected connection and unexpected connection. Moreover, we develop fast CTO algorithms to achieve a different degree of obfuscation for the hosts in each layer. We design and implement CHAOS as an application of SDN controller. Our approach makes it very easy to realize moving target defense in networks. Our experimental results show that a network protected by CHAOS is capable of decreasing the percentage of information disclosure effectively to guarantee the normal flow of traffic.
Huanguo Zhang, Juan Wang 0006, Daochen Zha, Hongxin Hu, Fei Yan 0008, Bo Zhao 0023
Secur. Commun. Networks8
2016 A formal analysis of Trusted Platform Module 2.0 hash-based message authentication code authorization under digital rights management scenario
abstract
Abstract Trusted Platform Module (TPM) is the “root of trust” of the whole trusted computing platform. The TPM's own security assurance is very important. This paper describes the TPM 2.0 hash‐based message authentication code (HMAC) authorization scheme as a security protocol and makes a detail comparison of the TPM 2.0 authorization to the TPM 1.2 “Object‐Independent Authorization Protocol” and the “Object‐Specific Authorization Protocol.” Then the authors use the typed pi calculus to describe the TPM 2.0 HMAC authorization and its security properties under the Digital Rights Management (DRM) scenario and use ProVerify to reason that the key handle manipulation attack for TPM 1.2 does not exist any more in TPM 2.0, because the access entity unique name has been linked to the HMAC value, but the vulnerability of key blob substitution still exists in TPM 2.0. Copyright © 2015 John Wiley & Sons, Ltd.
Fajiang Yu, Huanguo Zhang, Bo Zhao 0023, Juan Wang 0006, Fei Yan 0008, Zhenlin Chen
Secur. Commun. Networks6
2014 POSTER: An E2E Trusted Cloud Infrastructure
abstract
In this paper, a framework of end to end (E2E) trusted cloud infrastructure is proposed. On one end of the cloud provider, the trusted chain is extended to VMM and VM by trusted measurement and remote attestation, which can assure the trust of VMM and VM. On another end of the cloud terminal, the trusted mechanism is used to protect the terminal security. For the trust of cloud network, trusted network connect (TNC) is leveraged to protect the security of communication between the loud provider and the cloud terminal. The E2E trusted cloud infrastructure provides an E2E trusted protection for cloud computing. In addition, it can support the Chinese cryptographic algorithm (SMx) based on TPM 2.0.
Juan Wang 0006, Bo Zhao 0023, Huanguo Zhang, Fei Yan 0008, Fajiang Yu, Hongxin Hu
CCS4
2010 Research on trusted computing and its development
Changxiang Shen, Huanguo Zhang, Bo Zhao 0023, Fei Yan 0008, Fajiang Yu, Mingdi Xu
Sci. China Inf. Sci.6