Bangdao Chen

dblp:60/9687 · also Chen Bangdao · DBLP profile ↗
← Back
13ranked-venue papers
2as first author
8since 2021 · last 2024
0000-0003-3225-4286ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 7 · 1 first-author · 4 since 2021Computer networks · 4 · 1 first-author · 3 since 2021Systems, architecture and hardware · 1Software engineering, systems software and programming languages · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2024 Traceable ring signature schemes based on SM2 digital signature algorithm and its applications in the data sharing scheme
Hong Lei 0001, Qinghao Wang, Ning Lu 0005, Bangdao Chen, Qiuling Yue
Frontiers Comput. Sci.7
2024 PACTA: An IoT Data Privacy Regulation Compliance Scheme Using TEE and Blockchain
abstract
Despite the existence of data privacy regulations, such as the general data protection regulation (GDPR), data leaks in the Internet of Things (IoT) still occur and cause significant harm due to the noncompliance of data users. To address this issue, a notable solution involves recording the process in an open, immutable blockchain and utilizing the trusted execution environment (TEE) for reliable compliance verification. Although substantial progress has been made in designing compliance schemes in recent years, current approaches suffer from various limitations, including compliance incompleteness, regulation faultiness, and privacy leak. This article introduces PACTA, an IoT data privacy regulation compliance scheme that leverages TEE and blockchain technology. In the protocol, PACTA efficiently handles both dynamic and static consent of data owners and utilizes TEE for compliance analysis of requests and processes. By storing encrypted critical data, the blockchain facilitates privacy-preserving audits of the entire compliance process. Additionally, we have designed a challenge–response protocol to address the silent behavior of the TEE. We demonstrate that PACTA effectively enforces regulation compliance while safeguarding privacy. We thoroughly evaluate our implementation’s efficiency and effectiveness using Ethereum and Intel SGX platforms.
Hong Lei 0001, Zijian Bao, Ning Lu 0005, Bangdao Chen
IEEE Internet Things J.7
2024 Proof of Finalization: A Self-Fulfilling Function of Blockchain
abstract
Blockchain has been widely used in various industries for providing trustworthy data. On-chain data can be regarded as trusted after it is finalized by blockchain consensus, namely after the data is believed to be immutable. Unfortunately, nodes with poor/isolated network conditions are still susceptible to data spoofing attacks of blockchain view, spawning kinds of severe attacks. For example, a light node newly joining a blockchain network may request the blockchain view from a malicious full node and accept a spoof view, leading to a double spending attack. Besides, a Trusted Execution Environment (TEE), the network stack of which is fully controlled by its host, may be fed spoofed blockchain data as input, undermining the trustworthiness of TEE-based computation by cheating inputs. To resist data spoofing, existing methods rely on a trusted authority to identify trusted data, or timely provide sufficient confirmation blocks for a block b to prove the finalization of b (since the adversary holding less hash power than the honest blockchain node cannot generate the confirmation blocks timely). These methods either suffer the risks caused by centralized trust base or are only PoW-oriented and high-latency. As promising blockchains including Ethereum migrate to energy-saving consensus, e.g., PoS, designing consensus-agnostic approaches against data spoofing becomes an urgent need of the industries. In this paper, we introduce a Proof of Finalization (PoF) problem for proving the finalization of blockchain to prevent data spoofing attacks of blockchain. We also contrive a novel PoF scheme, which leverages the chain quality property of blockchain to establish a trustworthy committee for proof generation. The scheme is chain-agnostic, non-interactive, non-authority-involved, and with negligible latency. Once blockchain data is finalized, the latency of proof generation in our scheme is only 106 milliseconds. Therefore, our scheme paves the way for any system, e.g., light nodes, cross-chain bridges, and layer-2 systems, to read blockchains with various consensus securely.
Aixian Deng, Qian Ren, Yingjun Wu, Hong Lei 0001, Bangdao Chen
IEEE Trans. Inf. Forensics Secur.5
2024 DeCloak: Enable Secure and Cheap Multi-Party Transactions on Legacy Blockchains by a Minimally Trusted TEE Network
abstract
The crucial blockchain privacy and scalability demand has boosted off-chain contract execution frameworks for years. Some have recently extended their capabilities to transition blockchain states by off-chain multi-party computation while ensuring public verifiability. This new capability is defined as acrfull mpt. However, existing MPT solutions lack at least one of the following properties crucially valued by communities: data availability, financial fairness, delivery fairness, and delivery atomicity. This paper proposes a novel MPT-enabled off-chain contract execution framework, Decloak. Using TEEs, Decloak solves identified properties with lower gas costs and a weaker assumption. Notably, Decloak is the first to achieve data availability and also achieve all of the above properties. This achievement is coupled with its ability to tolerate all-but-one Byzantine parties and TEE executors. Evaluating 10 MPTs in different businesses, Decloak reduces the gas cost of the SOTA, Cloak, by 65.6%. This efficiency advantage further amplifies with an increasing number of MPT’s parties. Consequently, we establish an elevated level of secure and cheap MPT, being the first to demonstrate the feasibility of achieving gas costs comparable to Ethereum transactions while evaluating MPTs.
Qian Ren, Yue Li 0037, Yingjun Wu, Hong Lei 0001, Lei Wang 0031, Bangdao Chen
IEEE Trans. Inf. Forensics Secur.7
2023 OWL: A data sharing scheme with controllable anonymity and integrity for group users
Zijian Bao, Qinghao Wang, Ning Lu 0005, Bangdao Chen, Hong Lei 0001
Comput. Commun.6
2022 Cloak: Transitioning States on Legacy Blockchains Using Secure and Publicly Verifiable Off-Chain Multi-Party Computation
abstract
In recent years, the confidentiality of smart contracts has become a fundamental requirement for practical applications. While many efforts have been made to develop architectural capabilities for enforcing confidential smart contracts, a few works arise to extend confidential smart contracts to Multi-Party Computation (MPC), i.e., multiple parties jointly evaluate a transaction off-chain and commit the outputs on-chain without revealing their secret inputs/outputs to each other. However, existing solutions lack public verifiability and require O(n) transactions to enable negotiation or resist adversaries, thus suffering from inefficiency and compromised security.
Qian Ren, Yingjun Wu, Han Liu 0010, Yue Li 0037, Anne Victor, Hong Lei 0001, Lei Wang 0031, Bangdao Chen
ACSAC8
2022 Committable: A Decentralised and Trustless Open-Source Protocol
abstract
Collaborative development in open-source software (OSS) has long been limited by the lack of participation, i.e., A project is often maintained by an insufficient number of developers, especially for small- and medium-size projects. To establish a sustainable ecosystem for global developers and projects, we propose a decentralised and trustless open-source protocol Committable for all OSS software. The key insight behind Committable is an accountable and trusted tokenisation technology on blockchain that creates the CMT software assets for a variety of artefacts (e.g., document, code, testcase, makefile etc..) across the whole development lifecycle. A CMT token defines an abstraction of commits to OSS and systematically models the contribution from developers, therefore is far more comprehensive than a commit hash that are commonly used to identify software versions. In further, Committable introduces the Problem-Solution-Risk (PSR) framework to evaluate and reward a given set of CMT in an unbiased manner based on their contributions to a project. Owners of CMT are allowed to trade their tokens in the marketplace on blockchain established by Committable. The trading of CMT leads to transfer of token rights (e.g., sell, earn PSR rewards etc.), and more importantly, royalty to the developer for his or her original contribution. This demonstration proposal will introduce Committable on the test net of Ethereum and describe a preliminary case study with the OpenZeppelin project.
Han Liu 0010, Huafeng Zhang, Bangdao Chen, A. W. Roscoe 0001
ICBC3
2022 SorTEE: Service-Oriented Routing for Payment Channel Networks With Scalability and Privacy Protection
abstract
Payment channel networks (PCNs) are emerged as the most widely deployed solution to mitigate the scalability problem of permissionless cryptocurrencies, allowing vast payments to be carried out off-chain. Routing, which finds feasible paths between the senders and receivers, is critical for PCNs. However, existing solutions either fail to achieve high scalability that can maintain low storage/computation/network communication overhead, or they are susceptible to privacy disclosure. In this paper, we propose SorTEE, a service-oriented routing solution for PCNs, which adopts a set of service nodes to alleviate the per-user burden of routing and achieves more comprehensive privacy guarantees than the state-of-the-art by leveraging trusted execution environments (TEEs). SorTEE demands users communicate with the TEE by the secure channel to protect the privacy of transaction value. Then, an oblivious path mechanism is designed to construct redundant paths with the pseudo senders and receivers generated by TEEs to confuse its untrusted controller. Further, we report a novel attack that allows malicious service nodes to drop the valid paths for profit, and design a feedback mechanism to relieve it. Moreover, SorTEE hides the identities of the senders/receivers for the intermediate nodes of payment paths by introducing a novel identity information transfer scheme called encrypted identity chain. Based on security analysis and performance evaluation, our results demonstrate that SorTEE is able to achieve sufficient privacy-preserving payment and low per-user overhead.
Qinghao Wang, Zijian Bao, Hong Lei 0001, Han Liu 0010, Bangdao Chen
IEEE Trans. Netw. Serv. Manag.7
2020 SafePay on Ethereum: A Framework For Detecting Unfair Payments in Smart Contracts
abstract
Smart contracts on the Ethereum blockchain are notoriously known as vulnerable to external attacks. Many of their issues led to a considerably large financial loss as they resulted from broken payments by digital assets, e.g., cryptocurrency. Existing research focused on specific patterns to find such problems, e.g., reentrancy bug, nondeterministic recipient etc., yet may lead to false alarms or miss important issues. To mitigate these limitations, we designed the SafePay analysis framework to find unfair payments in Ethereum smart contracts. Compared to existing analyzers, SafePay can detect potential blockchain transactions with feasible exploits thus effectively avoid false reports. Specifically, the detection is driven by a systematic search for violations on fair value exchange (FVE), i.e., a new security invariant introduced in SafePay to indicate that each party “fairly” pays to others. The preliminary evaluation validated the efficacy of SafePay by reporting previously unknown issues and decreasing the number of false alarms.
Yue Li 0037, Han Liu 0010, Qian Ren, Lei Wang 0031, Bangdao Chen
ICDCS6
2020 Protect Your Smart Contract Against Unfair Payment
abstract
While smart contracts have enabled a wide range of applications in many public blockchains, e.g., Ethereum, their security issues have been raising an increasing number of threats on the stability of blockchain ecosystem. In practice, many external attacks on smart contracts result from broken payments with digital assets, e.g., cryptocurrencies. While an increasing number of research works have been focusing on such problems, many of them adopted pattern-based heuristics (e.g., reentrancy) to find payment-related attacks thus can incur a considerably large portion of both false positives and negatives. To overcome these limitations and achieve better payment security on blockchain, we introduced a new class of payment attacks in this paper, i.e., unfair payment (UP). Compared to existing heuristics, UP semantically captures a wider range of payment attacks. Furthermore, we highlighted the general framework SAFEPAY to systematically detect UP. The key insight behind is a novel security invariant, i.e., fair value exchange (FVE), which models the fairness for blockchain payments between multiple parties. More specifically, SAFEPAY systematically explores the transaction space of a given smart contract and generates a bounded set of transaction sequences. For each of the sequence, SAFEPAY reports a UP attack once a violation on FVE is confirmed. We have further instantiated SAFEPAY for Ethereum and applied it in real-world smart contracts. In the empirical evaluation, SAFEPAY managed to identify previously unreported UP attacks and effectively avoid false alarms compared to analyzers in the literature as well.
Yue Li 0037, Han Liu 0010, Qian Ren, Lei Wang 0031, Bangdao Chen
SRDS7
2013 Human interactive secure key and identity exchange protocols in body sensor networks
abstract
A body sensor network (BSN) is typically a wearable wireless sensor network. Security protection is critical to BSNs, since they collect sensitive personal information. Generally speaking, security protection of BSN relies on identity (ID) and key distribution protocols. Most existing protocols are designed to run in general wireless sensor networks, and are not suitable for BSNs. After carefully examining the characteristics of BSNs, the authors propose human interactive empirical channel‐based security protocols, which include an elliptic curve Diffie–Hellman version of symmetric hash commitment before knowledge protocol and an elliptic curve Diffie–Hellman version of hash commitment before knowledge protocol. Using these protocols, dynamically distributing keys and IDs become possible. As opposite to present solutions, these protocols do not need any pre‐deployment of keys or secrets. Therefore compromised and expired keys or IDs can be easily changed. These protocols exploit human users as temporary trusted third parties. The authors, thus, show that the human interactive channels can help them to design secure BSNs.
Xin Huang 0005, Bangdao Chen, Andrew Markham, Qinghua Wang 0001, Zheng Yan 0002, A. W. Roscoe 0001
IET Inf. Secur.2
2013 Reverse Authentication in Financial Transactions and Identity Management
Bangdao Chen, Long Hoang Nguyen 0001, A. W. Roscoe 0001
Mob. Networks Appl.1
2011 Mobile Electronic Identity: Securing Payment on Mobile Phones
Bangdao Chen, A. W. Roscoe 0001
WISTP1