Hui Li 0070

dblp:66/3387-70 · DBLP profile ↗
← Back
11ranked-venue papers
2as first author
8since 2021 · last 2025
0000-0003-3629-0233ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 7 · 1 first-author · 6 since 2021Computer networks · 3 · 1 first-author · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1Human-computer interaction and ubiquitous computing · 1
YearPublicationVenuePosition
2025 5G-RNAKA : A Random Number-based Authentication and Key Agreement Protocol for 5G Systems
abstract
The 5G-AKA protocol, defined by 3GPP for authentication and key agreement in 5G networks, remains vulnerable to linkability, synchronization failure, and Sequence Number (SQN) exposure attacks. These issues threaten user privacy and service availability. Existing improvements often retain these flaws or cause high overhead due to continued use of the legacy SQN mechanism from 3G. In this paper, we propose 5G-RNAKA, a secure and efficient AKA protocol for 5G systems. Unlike 5G-AKA, 5G-RNAKA eliminates SQN counters and instead utilizes random numbers generated by the Universal Subscriber Identity Module (USIM) in 5G User Equipment (UE) for session identification. This random number is embedded in the reply message from the service network (SN) to prevent replay attacks against the UE. Additionally, by removing the SQN mechanism, 5G-RNAKA enhances user privacy by preventing attackers from linking challenge-response sessions. It also enables the UE to authenticate the SN, effectively mitigating the risk of SN impersonation. We formally verify that 5G-RNAKA achieves its security goals of privacy, authentication, and secrecy using the state-of-the-art formal verification tool, Tamarin Prover. Our implementation and evaluation further demonstrate that 5G-RNAKA improves communication efficiency and reduces storage overhead. While primarily designed for 5G, 5G-RNAKA's features align with emerging trends in 6G authentication, suggesting its potential for adaptation to future 6G architectures.
Hui Li 0070, Jingjing Guan, Junchi Zeng, Haonan Feng, Ziming Zhao 0001
CCS1
2025 Formally Verifying the State Machine of TLS 1.3 Handshake in OpenSSL
Jingjing Guan, Hui Li 0070, Binghan Wang, Qiuye Wang, Shengchao Qin, Mengda He, Md. Armanuzzaman, Ziming Zhao 0001
INFOCOM2
2025 PUF-Based Lightweight Group Authentication for Massive IoT Access With Insecure Channel
abstract
The massive access in Internet of Things (IoT) introduces significant communication and computation overheads. Besides, the widespread IoT terminals placed in unattended area and with limited capabilities are vulnerable to various attacks such as physical attack. To alleviate the huge communication and computation overheads and to resist physical attacks, we propose a physically unclonable function (PUF)-based group authentication protocol in this paper, where a pre-stored PUF challenge scheme with PUF acting as the root key is proposed to limit the size of signalings in a group. Different from existing work with assumptions on secure communication channels and trusted group leader (GL), we consider untrusted GL and insecure communication channels among the device, the GL, and the home network (HN) and propose a simplified PUF-based device-to-device authentication scheme to perform mutual authentication and key sharing between the devices and the untrusted GL. Finally, the proposed protocol is evaluated with formal security analysis, where a novel threat model is presented for the physical attacker to overhear the secret in device’s memory. Results show that the proposed protocol can achieve desired authentication and confidentiality goals even the GL is under physical attacks and the communication channels are insecure. Further, simulations are demonstrated to show the outperformance of the proposed protocol in communication overhead, computation overhead, and security, compared with baseline solutions.
Huici Wu, Xiaofeng Tao 0001, Zhiqing Wei, Chenyu Wang 0002, Hui Li 0070
IEEE Internet Things J.6
2024 A Formal Analysis of Data Distribution Service Security
abstract
The Data Distribution Service (DDS) constructs a highly available data transmission middleware based on the publish-subscribe model, widely used in the Internet of Things environment. To improve the security of DDS, the Object Management Group formulated the DDS Security, which provides security mechanisms for DDS in the form of security plugins. However, the security of the DDS Security protocol has not been fully analyzed. We analyze DDS Security through formal methods. We model the security goals and protocol flow of the DDS Security using ProVerif and evaluate whether its security goals can be met in different scenarios. Our analysis confirms previously manually identified vulnerabilities in an automated way and reveals new attacks. We discovered the permission file impersonation attack, the denial of service attack, the degradation attack, and the privacy leakage attack guided by the formal analysis result. For these threats, we propose corresponding mitigation measures and recommendations.
Binghan Wang, Hui Li 0070, Jingjing Guan
AsiaCCS2
2024 Formal Analysis of WAPI Authentication and Key Agreement Protocol
Zhongqi Lv, Hui Li 0070, Haisong Ye, Jingjing Guan
Inscrypt (2)2
2023 FIDO Gets Verified: A Formal Analysis of the Universal Authentication Framework Protocol
abstract
The FIDO protocol suite aims at allowing users to log in to remote services with a local and trusted authenticator. With FIDO, relying services do not need to store user-chosen secrets or their hashes, which eliminates a major attack surface for e-business. Given its increasing popularity, it is imperative to formally analyze whether the security promises of FIDO hold. In this paper, we present a comprehensive and formal verification of the FIDO UAF protocol by formalizing its security assumptions and goals and modeling the protocol under different scenarios in ProVerif. Our analysis identifies the minimal security assumptions required for each of the security goals of FIDO UAF to hold. We confirm previously manually discovered vulnerabilities in an automated way and disclose several new attacks. Guided by the formal verification results, we also discovered two practical attacks on two popular Android FIDO apps, which we responsibly disclosed to the vendors. In addition, we offer several concrete recommendations to fix the identified problems and weaknesses in the protocol.
Haonan Feng, Jingjing Guan, Hui Li 0070, Xuesong Pan, Ziming Zhao 0001
IEEE Trans. Dependable Secur. Comput.3
2022 A Formal Analysis of the FIDO2 Protocols
Jingjing Guan, Hui Li 0070, Haisong Ye, Ziming Zhao 0001
ESORICS (3)2
2021 A Formal Analysis of the FIDO UAF Protocol
Haonan Feng, Hui Li 0070, Xuesong Pan, Ziming Zhao 0001
NDSS2
2020 Authenticator Rebinding Attack of the UAF Protocol on Mobile Devices
abstract
We present a novel attack named “Authenticator Rebinding Attack,” which aims at the Fast IDentity Online (FIDO) Universal Authentication Framework (UAF) protocol implemented on mobile devices. The presented Authenticator Rebinding Attack rebinds the victim’s identity to the attacker’s authenticator rather than the victim’s authenticator being verified by the service in the UAF protocol, allowing the attacker to bypass the UAF protocol local authentication mechanism by imitating the victim to perform sensitive operations such as transfer and payment. The lack of effective authentication between entities in the implementations of the UAF protocol used in the actual system causes the vulnerability to the Authenticator Rebinding Attack. In this paper, we implement this attack on the Android platform and evaluate its implementability, where results show that the proposed attack is implementable in the actual system and Android applications using the UAF protocol are prone to such attack. We also discuss the possible countermeasures against the threats posed by Authenticator Rebinding Attack for different stakeholders implementing UAF on the Android platform.
Hui Li 0070, Xuesong Pan, Xinluo Wang, Haonan Feng, Chengjie Shi
Wirel. Commun. Mob. Comput.1
2018 Secure Display for FIDO Transaction Confirmation
abstract
FIDO protocols enable online services to leverage native authenticators of end-user computing devices including fingerprint readers for authentication to replace or complement passwords. FIDO protocols also offer support for prompting a user to confirm a specific transaction. However, due to the lack of a trusted display module in most Authenticators, operating systems of user devices display transaction contents directly on the main screen. In the paper, we demonstrate an attack on FIDO transaction confirmation in which malicious applications leverage the disparity between the displayed and actual transaction contents to trick users into confirming falsified transactions. In addition, we propose a lightweight secure display mechanism for FIDO transaction confirmations on mobile devices by leveraging the ARM TrustZone technology.
Yongxian Zhang, Xinluo Wang, Ziming Zhao 0001, Hui Li 0070
CODASPY4
2008 An Efficient Remote User Authentication Scheme with Strong Anonymity
abstract
Many remote authentication schemes attempt to preserve user anonymity from the eavesdropper. However, authentication schemes in many e-commerce transactions require not only anonymous to the eavesdropper but also to the authentication server. In this paper, we propose a remote authentication scheme using smart card to fulfill both of the requirements. The proposed scheme achieves mutual authentication and allows users to choose and change their own passwords freely and securely. We only use one-way hash function and bitwise XOR operation in the proposed scheme and so the scheme has a low computational complexity. By using timestamp and random numbers, the proposed scheme can resist the denial of service attack and the replay attack. Also, the scheme is secure against guessing attack, insider attack, stolen-verifier attack, reflection attack, and impersonation attack.
Ziming Zhao 0001, Hui Li 0070, Qun Luo, Yixian Yang
CW3