EDBT 2026 Demo / reviewers in the wild / expert
Chaojing Tang
dblp:57/1674
· DBLP profile ↗
33ranked-venue papers
0as first author
15since 2021 · last 2026
0000-0002-9025-2791ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 14 · 8 since 2021Computer networks · 6 · 1 since 2021Software engineering, systems software and programming languages · 5 · 3 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 3 · 1 since 2021Artificial intelligence and machine learning · 1Databases, data management, data science and information retrieval · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | OSmartPro: a large language model-assisted option fuzzing approachabstractAbstract Program options provide flexible software functionality control but complicate fuzz testing, as triggering many behaviors require specific option combinations. Although existing option-aware fuzzing approaches attempt to mutate options as inputs or leverage AI technologies to extract option relationships from documentation, these methods have limitations. Documentation is often incomplete, and some option dependencies are embedded deeply within program logic via data or control flows, making these methods challenging to detect all possible dependencies. This paper introduces OSmartPro , an advanced option-fuzzing approach that directly extracts options and infers option dependencies from source code. Given LLM’s capabilities to interpret program semantics, OSmartPro employs LLM-assisted static analysis to handle diverse option-parsing structures and extract comprehensive options. Through control and data dependency analysis, it constructs option impact graph , which it uses to guide fuzzing strategies. The tool successfully extracted complete options from all 59 programs in our test set, uncovering undocumented options in over 66% of them. Additionally, OSmartPro inferred 14,701 option combinations, identified 45.03% more execution paths compared to AFL++, and uncovered 54 zero-day vulnerabilities, of which 18 awarded CVE IDs. Lastly, in a benchmark comparison against four option-aware fuzzers, OSmartPro achieved higher line coverage in 66.7% (20 out of 30) of the programs. Kelin Wang, Mengda Chen, Liang He 0011, Purui Su, Jiongyi Chen, Yan Cai 0001, Chao Feng 0002, Chaojing Tang, Guojun Peng |
Cybersecur. | 10 |
| 2025 | SVRM: Composing Various Network Service Fuzzing Corpus with One Single ModelabstractDiscovering vulnerabilities in network service is of great significance. Currently, coverage-guided fuzzing (CGF) is widely regarded as the most effective method. However, the efficiency of CGF depends on the quality of initial corpus. The initial corpus is a set of valid input examples used to initiate the fuzzing process. Constructing high-quality initial corpus typically requires manual efforts to understand the implementation details and corresponding protocol specifications, making it difficult to generalize across different protocol implementations.To generate high-quality corpus tailored to service under test (SUT), this paper proposes a protocol-independent smart generation method. The paper introduces a novel service communication model and utilizes active learning algorithms to automatically construct the model. By analyzing the minimum spanning tree of the model, we achieve automatic generation of high-quality corpus that adapts to the SUT.We conduct experiment by generating adaptive corpus for 6 targets of 6 different protocols in ProFuzzBench. Compared to the corpus provided by ProFuzzBench, the corpus generated by our system improve the state coverage of modern protocol fuzzers by 37.1% and discover known real protocol vulnerabilities at a speed 2.47x faster. Wenfeng Lin, Zhiyuan Jiang, Fangliang Xu, Yunfei Su, Lingchu Mao, Chaojing Tang |
ICASSP | 7 |
| 2025 | ProAnalyzer: Inferring Network Service's Fuzzing Format with Grey-Box Metric
Wenfeng Lin, Yunfei Su, Chaojing Tang |
ICIC (4) | 4 |
| 2025 | Practical Object-Level Sanitizer with Aggregated Memory Access and Custom AllocatorabstractTo mitigate potential memory safety vulnerabilities, recently there have been significant advances in sanitizers for pre-production bug detection. However, the limited inability to balance performance and detection accuracy still holds. The main reason is due to excessive reliance on shadow memory and a large number of memory access checks at runtime, incurring a significant performance overhead (if fine-grained memory safety detection is performed, the overhead will be even greater). In this paper, we propose a novel Object-Level Address Sanitizer OLASan to reduce performance overhead further while implementing accurate memory violations (including intra-object overflow) detection. Unlike previous sanitizers ignoring the correlation between memory access and objects, OLASan aggregates multiple memory accesses of same object at function level to perform on-demand targeted sanitization, thus avoiding examining most memory accesses at runtime. Specifically, OLASan characterizes various memory access patterns to identify those which can be aggregated, and implements memory safety checks with customized memory tagging. We implement OLASan atop the LLVM framework and evaluate it on SPEC CPU benchmarks. Evaluations show that OLASan outperforms the state-of-the-art methods with 51.18%, 25.20% and 6.52% less runtime overhead than ASan, ASan-- and GiantSan respectively. Moreover, aided by customized memory tagging, OLASan achieves zero false negatives for the first time when testing Juliet suites. Finally, we confirm that OLASan also offers comparable detection capabilities on real bugs. Ruilin Li 0002, Chao Feng 0002, Chaojing Tang |
ICSE | 5 |
| 2025 | Chat4seed: Semantic-Awareness Highly Structured Seed Generation for FuzzingabstractFuzzing, one of the most popular methods for enhancing software security and quality, relies heavily on the quality of its initial seed corpus to effectively uncover vulnerabilities. Traditional methods for generating initial seed corpora, whether crawl-based or generation-based, struggle with programs that handle highly structured formats with complex semantics, leading to low testing coverage and reduced fuzzer effectiveness. Although researchers have proposed leveraging Large Language Models (LLMs) to create high-quality seed corpora, current approaches are limited to text-based seed files, such as JavaScript code. To address the limitations, we propose Chat4Seed, a novel approach that extends the capabilities of LLMs to produce not only text but also highly-structured binary seed files. Chat4Seed leverages LLMs to extract and interpret the semantic constraints embedded within formatspecific branches of programs. While existing approaches focus solely on generating text-based seeds, Chat4Seed goes further by utilizing LLMs to generate functional library invocation code to produce binary seeds. It also employs binarylevel manipulation to handle unsupported corner cases, achieving robust seed generation for both text and binary formats. Our experiments and evaluations on 12 real-world programs demonstrate that after 48 hours of fuzz testing using AFL++, the seed corpus generated by Chat4Seed achieves an average increase in coverage of 28.78% compared to traditional crawl-based methods and 39.98% compared to generation-based methods. Additionally, it facilitates the discovery of 84.24% and 392.7% more crashes than seed corpus generated by traditional approaches, respectively, underscoring the potential of Chat4Seed to enhance the efficacy of fuzzing. Jiarui Chen, Jiongyi Chen, Runhao Li, Chaojing Tang |
QRS | 5 |
| 2025 | RPFUZZ: Efficient network service fuzzing via pruning redundant mutationabstractCoverage-guided fuzzing (CGF) has proven its outstanding performance on vulnerability detection. However, existing approaches exhibit limitations when handling network service. Restricted by network I/O duration and chronology, long packet sequences crafted by fuzzers incur a substantial execution cost. Test cases with such non-coverage-improving mutations (i.e. redundant mutation) can significantly reduce fuzzing throughput and compromise vulnerability discovery. To address this issue, we propose RPFUZZ, a novel network fuzzing framework designed to systematically reduce redundant mutations: (1) We propose redundant mutation pruning for network service fuzzing. By early terminating redundant mutations’ execution, RPFUZZ can achieve higher throughput. (2) To detect redundant mutation, we propose redundant mutation oracle. This oracle dynamically judges whether a test case is redundant according to current code coverage and value of service-related variables (SRVs). (3)To identify SRVs, we propose an integrated approach combining dynamic call stack analysis with static value-flow graph (VFG) analysis. To evaluate the performance of RPFUZZ, we implement a prototype on top of NYX-NET. We conduct thorough experiments on ProFuzzBench, a benchmark that consists of 12 real-world network services. The results indicate that RPFUZZ achieves over 185% improvement in throughput and 1.02% rise in code coverage compared with NYX-NET. Besides, RPFUZZ has successfully uncovered 1753 unique crashes across 6 network services, including an unreported vulnerability (assigned to CVE-2024-57392) in ProFTPD, which has been well tested. • We propose redundant mutation pruning technique for network service fuzzing. By pruning mutated suffix packet sequence which is non-coverage-improving, network service fuzzer can achieve higher throughout. This is achieved by redundant mutation oracle, which leverage code coverage and identified service-related variables’ (SRVs) value to decide whether continuing current execution is advisable. • To precisely identify SRVs in network services, we propose an identification method combining with call stack analysis and value-flow graph analysis. This method is based on SRV’s programming features, which can be applied in various network service. • Based on technique above, We implement RPFUZZ. RPFUZZ achieved more than 185.92% (average 56.39%) throughput enhancement over NYX-NET, while improving maximum 4.27% code coverage (average +1.02%). It successfully identified 1753 unique crashes across 6 targets without ASAN and a buffer overflow vulnerability in ProFTPD (assigned CVE-2024-57392). Wenfeng Lin, Fangliang Xu, Zhiyuan Jiang, Chaojing Tang |
Comput. Secur. | 6 |
| 2024 | OSmart: Whitebox Program Option FuzzingabstractProgram options are ubiquitous and serve as a fundamental mechanism for configuring and customizing software behaviors. Given their widespread use, testing program options becomes essential to ensure that the software behaves as expected across various configurations. Existing option-aware fuzzers either mutate options as if they were standard program inputs or employ NLP techniques to deduce relationships among options from the documentation. However, there has not been a whitebox approach that generates option combinations by capturing the inherent execution logic of the program. Kelin Wang, Mengda Chen, Liang He 0011, Purui Su, Yan Cai 0001, Jiongyi Chen, Chao Feng 0002, Chaojing Tang |
CCS | 9 |
| 2023 | Towards Automatic and Precise Heap Layout Manipulation for General-Purpose Programs
Runhao Li, Jiongyi Chen, Wenfeng Lin, Chao Feng 0002, Chaojing Tang |
NDSS | 6 |
| 2023 | Automated Exploitable Heap Layout Generation for Heap Overflows Through Manipulation Distance-Guided Fuzzing
Jiongyi Chen, Runhao Li, Chao Feng 0002, Ruilin Li 0002, Chaojing Tang |
USENIX Security Symposium | 6 |
| 2022 | Evocatio: Conjuring Bug Capabilities from a Single PoCabstractThe popularity of coverage-guided greybox fuzzers has led to a tsunami of security-critical bugs that developers must prioritize and fix. Knowing the capabilities a bug exposes (e.g., type of vulnerability, number of bytes read/written) enables prioritization of bug fixes. Unfortunately, understanding a bug's capabilities is a time consuming process, requiring (a) an understanding of the bug's root cause, (b) an understanding how an attacker may exploit the bug, and (c) the development of a patch mitigating these threats. This is a mostly-manual process that is qualitative and arbitrary, potentially leading to a misunderstanding of the bug's capabilities. Zhiyuan Jiang, Shuitao Gan, Adrian Herrera, Flavio Toffalini, Lucio Romerio, Chaojing Tang, Manuel Egele, Chao Zhang 0008, Mathias Payer |
CCS | 6 |
| 2022 | Default: Mutual Information-based Crash Triage for Massive CrashesabstractWith the considerable success achieved by modern fuzzing infrastructures, more crashes are produced than ever before. To dig out the root cause, rapid and faithful crash triage for large numbers of crashes has always been attractive. However, hindered by the practical difficulty of reducing analysis imprecision without compromising efficiency, this goal has not been accomplished. Jiongyi Chen, Chao Feng 0002, Ruilin Li 0002, Wenrui Diao, Kehuan Zhang, Jing Lei 0001, Chaojing Tang |
ICSE | 8 |
| 2022 | Pusher: an augmented fuzzer based on the connection between input and comparison operand
Jiaxi Ye, Ruilin Li 0002, Chao Feng 0002, Yunfei Su, Chaojing Tang |
Frontiers Comput. Sci. | 6 |
| 2021 | Igor: Crash Deduplication Through Root-Cause ClusteringabstractFuzzing has emerged as the most effective bug-finding technique. The output of a fuzzer is a set of proof-of-concept (PoC) test cases for all observed "unique'' crashes. It costs developers substantial efforts to analyze each crashing test case. This, mostly manual, process has lead to the number of reported crashes out-pacing the number of bug fixes. Automatic crash deduplication techniques, which mostly rely on coverage profiles and stack hashes, are supposed to alleviate these pressures. However, these techniques both inflate actual bug counts and falsely conflate unrelated bugs. This hinders, rather than helps, developers, and calls for more accurate techniques. Zhiyuan Jiang, Xiyue Jiang, Ahmad Hazimeh, Chaojing Tang, Chao Zhang 0008, Mathias Payer |
CCS | 4 |
| 2021 | Reducing Test Cases with Attention Mechanism of Neural Networks
Jiongyi Chen, Chao Feng 0002, Ruilin Li 0002, Yunfei Su, Jing Lei 0001, Chaojing Tang |
USENIX Security Symposium | 8 |
| 2021 | Low-complexity sphere decoding for MIMO-SCMA systemsabstractAbstract Multiple‐input multiple‐output‐sparse code multiple access, a non‐trivial integration of sparse code multiple access and multiple‐input multiple‐output techniques, is able to achieve high spectrum efficiency and massive user connections. However, this integration also increases the complexity of signal detection. Here, the signal detection problem of multiple‐input multiple‐output sparse code multiple access is transformed into a tree search problem and use sphere decoding to detect the signal. By setting the initial radius to positive infinity, sphere decoding can achieve optimal maximum likelihood performance while the complexity is high. In order to further reduce the complexity of sphere decoding, a block‐wise sorted QR decomposition algorithm is proposed. Based on block‐wise sorted QR decomposition, the improved sphere decoding, namely block‐wise sorted QR decomposition‐sphere decoding, is able to make the tree search more efficient. Since only the detection order of each user's signal has been changed, block‐wise sorted QR decomposition‐sphere decoding can maintain the optimal maximum likelihood performance. Simulation results and complexity analysis show that block‐wise sorted QR decomposition‐sphere decoding can achieve optimal performance and both hard‐output and soft‐output block‐wise sorted QR decomposition‐sphere decoding have much lower complexity than joint message passing algorithm. Furthermore, given the same signal‐to‐noise ratio, the complexity of block‐wise sorted QR decomposition‐sphere decoding decreases with the increase of receiving antennas, while the complexity of joint message passing algorithm increases linearly. Zhipeng Pan, Jing Lei 0001, Lei Wen, Chaojing Tang, Zhongfeng Wang 0001 |
IET Commun. | 4 |
| 2018 | A real-time inversion attack on the GMR-2 cipher used in the satellite phones
Jiao Hu, Ruilin Li 0002, Chaojing Tang |
Sci. China Inf. Sci. | 3 |
| 2018 | Discover deeper bugs with dynamic symbolic execution and coverage-based fuzz testingabstractCoverage‐based fuzz testing and dynamic symbolic execution are both popular program testing techniques. However, on their own, both techniques suffer from scalability problems when considering the complexity of modern software. Hybrid testing methods attempt to mitigate these problems by leveraging dynamic symbolic execution to assist fuzz testing. Unfortunately, the efficiency of such methods is still limited by specific program structures and the schedule of seed files. In this study, the authors introduce a novel lazy symbolic pointer concretisation method and a symbolic loop bucket optimisation to mitigate path explosion caused by dynamic symbolic execution in hybrid testing. They also propose a distance‐based seed selection method to rearrange the seed queue of the fuzzer engine in order to achieve higher coverage. They implemented a prototype and evaluate its ability to find vulnerabilities in software and cover new execution paths. They show on different benchmarks that it can find more crashes than other off‐the‐shelf vulnerability detection tools. They also show that the proposed method can discover 43% more unique paths than vanilla fuzz testing. Chao Feng 0002, Adrian Herrera, Vitaly Chipounov, George Candea, Chaojing Tang |
IET Softw. | 6 |
| 2018 | An Exploitability Analysis Technique for Binary Vulnerability Based on Automatic Exception SuppressionabstractTo quickly verify and fix vulnerabilities, it is necessary to judge the exploitability of the massive crash generated by the automated vulnerability mining tool. While the current manual analysis of the crash process is inefficient and time-consuming, the existing automated tools can only handle execute exceptions and some write exceptions but cannot handle common read exceptions. To address this problem, we propose a method of determining the exploitability based on the exception type suppression. This method enables the program to continue to execute until an exploitable exception is triggered. The method performs a symbolic replay of the crash sample, constructing and reusing data gadget, to bypass the complex exception, thereby improving the efficiency and accuracy of vulnerability exploitability analysis. The testing of typical CGC/RHG binary software shows that this method can automatically convert a crash that cannot be judged by existing analysis tools into a different crash type and judge the exploitability successfully. Zhiyuan Jiang, Chao Feng 0002, Chaojing Tang |
Secur. Commun. Networks | 3 |
| 2017 | Area-Dividing Route Mutation in Moving Target Defense Based on SDN
Huiting Tan, Chaojing Tang, Shaolei Wang |
NSS | 2 |
| 2017 | Automatic Reverse Engineering of Private Flight Control Protocols of UAVsabstractThe increasing use of civil unmanned aerial vehicles (UAVs) has the potential to threaten public safety and privacy. Therefore, airspace administrators urgently need an effective method to regulate UAVs. Understanding the meaning and format of UAV flight control commands by automatic protocol reverse-engineering techniques is highly beneficial to UAV regulation. To improve our understanding of the meaning and format of UAV flight control commands, this paper proposes a method to automatically analyze the private flight control protocols of UAVs. First, we classify flight control commands collected from a binary network trace into clusters; then, we analyze the meaning of flight control commands by the accumulated error of each cluster; next, we extract the binary format of commands and infer field semantics in these commands; and finally, we infer the location of the check field in command and the generator polynomial matrix. The proposed approach is validated via experiments on a widely used consumer UAV. Jian Wang 0020, Chaojing Tang, Ruilin Li 0002 |
Secur. Commun. Networks | 3 |
| 2016 | Detecting integer overflow in Windows binary executables based on symbolic executionabstractThe integer overflow vulnerabilities exist in Windows binary executables still take up a large proportion of software security vulnerabilities. As integer overflow could lead to a serious buffer overflow sometimes, so once the integer overflow to buffer overflow vulnerability is exploited by attackers, our computer system may be exposed to critical threaten. In this paper, we present the design and implementation of a dynamic method to detect integer overflow to buffer overflow vulnerabilities. Our method first utilizes static analysis to find integer sensitive code region with the help of the characteristics of integer overflow to buffer overflow vulnerability. Then we leverage selective symbolic execution to explore these code regions and check the secure condition on each sink point to find secure bugs. Once we find a suspicious integer overflow to buffer overflow point, our method can generate POC automatically so that we can validate this overflow warning easily and accurately. We evaluate our method on 104 integer overflow to buffer overflow programs in Juliet test suite, and the result shows that our method does not produce any false positive and false negative. We also test our method on real-world binary software and the result shows our method could detect the vulnerability efficiently and generate POCs successfully. Chao Feng 0002, Chaojing Tang |
SNPD | 4 |
| 2015 | Diversity gain of lattice constellation-based joint orthogonal space-time block codingabstractIt is generally thought that space‐time block codes (STBCs) can obtain no more than full space diversity. In this study, the authors propose a new construction method of joint orthogonal STBCs based on M ‐dimensional lattice constellations for obtaining space and time diversities simultaneously. By deriving the Chernoff bound of error probability, they prove the exact diversity gain of the proposed code is M times of that in traditional STBCs. This is a valuable scheme as diversity gain is usually the primary factor to determine the ability of anti‐fading. Moreover, the maximum‐likelihood decoder for the proposed code just requires joint decoding of M real symbols, whose complexity is acceptable as M , usually, needs not to be too big. Numerical results show that the proposed code has remarkable improvement of performance compared with some typical STBCs under the comparable low decoding complexity. Wei Liu 0013, Jing Lei 0001, Muhammad Ali Imran 0001, Chaojing Tang |
IET Commun. | 4 |
| 2014 | Efficient centralized track initiation method for multistatic radar
Shiyou Xu, Chaojing Tang, Peiliang Jing, Zengping Chen |
FUSION | 2 |
| 2014 | RFID seeking: Finding a lost tag rather than only detecting its missing
Lei Xie 0004, Qiang Wang 0020, Chaojing Tang |
J. Netw. Comput. Appl. | 7 |
| 2014 | TOA: a tag-owner-assisting RFID authentication protocol toward access control and ownership transferabstractABSTRACT This paper addresses radio frequency identification (RFID) authentication and ownership transfer in offline scenarios. Four typical related works are reviewed in detail. A series of shortcomings and vulnerabilities of them are pointed out. A new RFID authentication protocol based on a novel tag‐owner‐assisting architecture is proposed, making a tag's owner an essential participant of the RFID authentication process. The proposed protocol is distinguished from existing works in providing ownership transfer, access control, and mutual authentication without any centralized database neither on a backend server nor in a reader. The security of the proposed protocol is verified by using automated validation of Internet security protocols and applications tool. The proposed protocol is server‐less, simple, scalable, untraceable, and device‐independent. These features are simultaneously achieved in a single RFID authentication protocol for the first time. Copyright © 2014 John Wiley & Sons, Ltd. Lei Xie 0004, Qiang Wang 0020, Chaojing Tang |
Secur. Commun. Networks | 6 |
| 2012 | Completely decoupled space-time block codes with low-rate feedbackabstractIn this paper, we propose a class of full diversity rate one space-time block codes (STBC) satisfying the generalized orthogonal constraint (GOC). First an explicit construction of completely decoupled STBC is proposed to obtain a rate one STBC with linear decoding complexity for any number of transmit antennas. Then we propose an adaptation strategy for the codes to achieve full diversity by utilizing partial phase information of the channel obtained via a feedback link. With a few feedback bits, the proposed rate one code has full diversity while reserving the same decoding complexity as Orthogonal STBCs. Moreover, the full diversity can be still achieved even if the simple zero-forced decoding is used at the receiver. Wei Liu 0013, Mathini Sellathurai, Jing Lei 0001, Jibo Wei, Chaojing Tang |
ISIT | 5 |
| 2011 | Key Privacy in McEliece Public Key CryptosystemabstractThe research on the anonymity of original McEliece PKC points out that the original McEliece PKC fails to hold the property of key privacy. A novel semantically secure variant of McEliece PKC is proposed, and proved its anonymity formally in standard model. As far as we know, this is the first attempt to investigate the property of key privacy in McEliece PKC in literature. Qiang Wang 0020, Xue Qiu, Chaojing Tang |
TrustCom | 4 |
| 2010 | A Cyclotomic Lattice Based Quasi-Orthogonal STBC for Eight Transmit AntennasabstractIn this letter, we propose a lattice-based full diversity design for rate-one quasi-orthogonal space time block codes (QSTBC) to obtain an improved diversity product for eight transmit antennas where the information bits are mapped into 4-D lattice points instead of the common modulation constellations. Particularly, the diversity product of the proposed code is directly determined by the minimum Euclidean distance of the used lattice and can be improved by using the lattice packing. We show analytically and by using simulation results that the proposed code achieves a larger diversity product than the rate-one QSTBCs reported previously. Wei Liu 0013, Mathini Sellathurai, Jibo Wei, Chaojing Tang |
IEEE Signal Process. Lett. | 4 |
| 2009 | Improved design of two and four-group decodable STBCs with larger diversity product for eight transmit antennasabstractRecently, full rate and full diversity two-group (2Gp) and four-group (4Gp) decodable space-time block codes (STBC) derived from quasi-orthogonal STBC (QSTBC) and designed under diversity product maximization criterion have been proposed. In this paper, we derive an upper bound of diversity product for those STBCs and discover that the diversity product of the current 2Gp-QSTBC and 4Gp-QSTBC has the potential to approach the upper bound for 8 transmit antennas. To this end, we propose an improved design of 2Gp and 4Gp STBC with increased diversity product for 8 transmit antennas by allowing sufficient number of dimensions for constellation rotation. The diversity product of the proposed two-group decodable STBC achieves the derived upper bound. Wei Liu 0013, Mathini Sellathurai, Pei Xiao 0001, Chaojing Tang, Jibo Wei |
ICASSP | 4 |
| 2009 | Low Complexity Variational Bayes Iterative Receiver for MIMO-OFDM SystemsabstractA low complexity iterative receiver is proposed in this paper for MIMO-OFDM systems in time-varying multi-path channel based on the variational Bayes (VB) method. According to the VB method, the estimation algorithms of the signal distribution and the channel distribution are derived for the receiver. With the aid of the soft-output QRD-M algorithm, whose complexity is fixed and relatively low, the signal distribution can be obtained conveniently. In particular, a sequential channel estimation algorithm, which completely avoids the computation of matrix inversion and multiplication, is introduced for the channel distribution estimation. Moreover, the distribution estimations of the signals and the channels are performed in a cyclical iteration way. The simulation results show that the performance loss of the proposed receiver is only ldB for fast varying channels and less than 0.5 dB for slow varying channels at the bit error rate of 10-4after 3 iterations, compared with the optimum receiver with perfect channel state information. Chun-lin Xiong, Jibo Wei, Chaojing Tang |
ICC | 5 |
| 2009 | Recursive channel estimation algorithms for iterative receiver in MIMO-OFDM systemsabstractA practical variational Bayes (VB) iterative receiver with joint signal detection and channel estimation is proposed in this paper for MIMO-OFDM systems in time-varying multipath channel. Since the VB method provides distribution-estimates of the parameters, the soft-input soft-output (SISO) QRD-M algorithm is exploited to estimate the signal distribution, and several channel estimation algorithms including the low complexity recursive channel estimation (LCRCE) algorithm are derived for the channel distribution estimation. It is noted that the LCRCE algorithm not only completely avoids computation of matrix inversion and matrix multiplication, but also greatly reduces the recursion numbers. The simulation results show that the performance loss of the proposed receiver is only ldB for fast varying channels and less than 0.5 dB for slow varying channels at the bit error rate of 10 4 after 3 iterations, compared with the optimal receiver with perfect channel state information. Chun-lin Xiong, De-Gang Wang, Jibo Wei, Chaojing Tang |
WCNC | 5 |
| 2009 | Application and performance analysis of various AEAD techniques for space telecommand authenticationabstractSecure communications in the context of civil space missions gained a major attention in the last few years, mainly thanks to the activities promoted in this field by the Consultative Committee for Space Data Systems. Risk analyses performed by several space agencies have provided indications of the impact of different security threats on several categories of space missions. As a result, to ensure a minimum level of security, at least Telecommand authentication should be applied to all missions. Besides standard and well known algorithms, alternative authentication solutions are to be considered, and tested for possible adoption in the space context, in order to provide a scalable and flexible authentication framework. To this aim, this paper focuses on some Authenticated Encryption with Associated Data techniques, and on their thorough evaluation by a detailed model of the space Telecommand channel and protocol stack, in order to achieve an optimal selection for application in the real space communication environment. Lei Zhang 0064, Susanna Spinsante, Chaojing Tang, Ennio Gambi |
IEEE Trans. Wirel. Commun. | 3 |
| 2005 | On the Security of Two Key-Updating Signature Schemes
Xingyang Guo, Chaojing Tang |
ACISP | 3 |