EDBT 2026 Demo / reviewers in the wild / expert
Jiwu Jing
dblp:70/3282
· DBLP profile ↗
105ranked-venue papers
0as first author
29since 2021 · last 2026
0000-0002-3409-6149ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 86 · 17 since 2021Systems, architecture and hardware · 11 · 8 since 2021Computer networks · 4 · 2 since 2021Software engineering, systems software and programming languages · 2 · 1 since 2021Databases, data management, data science and information retrieval · 2Artificial intelligence and machine learning · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Classical and Quantum Full Plaintext Recovery for Low-Round Feistel-Type Designs
Peng Wang 0009, Jiwu Jing, Shuping Mao, Gang Liu 0044 |
CRYPTO (5) | 3 |
| 2026 | FBRoT: Transforming Flash Memory into Root of Trust for IoT Terminals
Yuewu Wang, Lingguang Lei, Shijie Jia 0001, Jiwu Jing |
SECON | 6 |
| 2025 | ML-Cube: Accelerating Module-Lattice-Based Cryptography using Machine Learning Accelerators with a Memory-Less DesignabstractThe rapid advancement of AI technologies has led to a dramatic surge in computational demands, driving significant breakthroughs in ML accelerators. The powerful performance of these accelerators has attracted the attention of cryptography researchers, and recent studies have begun to explore their use in accelerating cryptographic operations. However, treating these accelerators as black boxes leads to high latency, and strict concurrency requirements, which hinder their practical deployment. In this paper, we go beyond the black-box treatment of ML accelerators and introduce ML-Cube (ML3), a novel memory-less framework that leverages ML accelerators to implement module-lattice-based PQC, FIPS 203 ML-KEM, and FIPS 204 ML-DSA. The performance benefits of ML-Cube arise from our thorough analysis of ML accelerator internals. Rather than treating the accelerators as black boxes, we dissect their operating mechanisms and design tailored mathematical transformations for cryptographic acceleration. This enables memory-less (I)NTT and polynomial multiplication that minimizes external memory dependencies and reduces latency. We further address the high latency and excessive parallelism demands of traditional SIMT-based implementations by fully parallelizing both ML-KEM and ML-DSA schemes. Our experiments show that our Tensor Core-based (I)NTT achieves a 2.03x--3.56x speedup over a highly-optimized CUDA-core implementation. Moreover, our memory-less polynomial multiplication attains a 10x speedup, and the full ML-KEM reaches up to a 3.58x speedup with only less than one-tenth of the latency compared with SOTA approach (CHES '24). Additionally, our enhanced ML-DSA implementation offers a 30% to 55% throughput improvement over the previous SOTA methods (TDSC '24) under the server-oriented model. Importantly, by confining core computations within registers, our approach inherently mitigates memory disclosure and cache-based side-channel attacks, thereby enhancing overall security. Fangyu Zheng, Zhuoyu Xie, Wenxu Tang, Guang Fan 0001, Yijing Ning, Yi Bian 0001, Jingqiang Lin 0001, Jiwu Jing |
CCS | 9 |
| 2025 | How to Recover the Full Plaintext of XCB
Peng Wang 0009, Shuping Mao, Ruozhou Xu, Jiwu Jing, Yuewu Wang |
CRYPTO (5) | 4 |
| 2025 | DEBridge: Towards Secure and Practical Plausibly Deniable Encryption Based on USB Bridge Controller
Chongyu Long, Yuewu Wang, Lingguang Lei, Haoyang Xing, Jiwu Jing |
ESORICS (2) | 5 |
| 2025 | CapAssess: An Endeavor to Assess and Enhance Linux Capabilities UtilizationabstractThe Linux capabilities mechanism divides the root privileges to provide more fine-grained access control, but its effectiveness depends on proper implementation and configuration. The scattered enforcement of capabilities in the kernel and its sporadic usage in programs pose challenges in gathering assessment information. To address this, we propose three tools for diagnosing potential problems in its design, implementation, and utilization. First, we employ LLVM/Clang to examine the capabilities enforcement in the kernel to map capabilities checks to files. This is the first attempt to explore the interaction between capabilities and other mechanisms, such as UGO. Second, We propose a pattern-based method to identify the sensitive kernel functions protected by capabilities, quanti-fying the overlap problem of capabilities. Third, we employ a customized fuzzing approach to determine the minimal set of capabilities required by programs, offering insight for secure usage. Additionally, Our study is further guided by international access management standards, providing structured criteria for the assessment. Leveraging data collected by our tools, we identify imperfections of capabilities and reported to stakeholders. To the best of our knowledge, this is the first systematic assessment of Linux capabilities. Jingzi Meng, Yuewu Wang, Lingguang Lei, Jiwu Jing, Pingjian Wang, Chunjing Kou, Peng Wang 0009 |
SANER | 4 |
| 2025 | T-VAE: Transformer-Based Variational AutoEncoder for Perceiving Anomalies in Multivariate Time Series DataabstractABSTRACT Anomaly perception in multivariate time series data has crucial applications in various domains such as industrial control and intrusion detection. In real‐world scenarios, the sequence information in multivariate time series data, which encompasses the temporal order and dependencies among high‐dimensional samples and features, can be complex and nonlinear. Additionally, the time series data often exhibit high volatility and are interspersed with noise data. These factors make anomaly perception in multivariate time series challenging. Despite the recent development of deep learning methods, only a few are able to address all of these challenges. In this paper, we propose a Transformer‐based Variational AutoEncoder (T‐VAE) for anomaly perception in multivariate time series data. The T‐VAE consists of two sub‐networks, the Representation Network and the Memory Network, and achieves end‐to‐end jointly optimisation. The Representation Network leverages self‐attention mechanisms and residual network structures to capture sequence information and metaphorical patterns from multivariate time series data. The Memory Network employs a Variational AutoEncoder to learn the distribution of normal data. It employs Maximum Mean Discrepancy to approximate the distribution of high‐volatility and noisy data to the distribution of the normal data. We evaluate T‐VAE on five datasets, showing superior performance and validating its effectiveness and robustness through comprehensive ablation studies and sensitivity analyses. Chai Kiat Yeo, Jiwu Jing, Chun Long |
Expert Syst. J. Knowl. Eng. | 3 |
| 2025 | AsyncGBP${}^{+}$+: Bridging SSL/TLS and Heterogeneous Computing Power With GPU-Based ProvidersabstractThe rapid evolution of GPUs has emerged as a promising solution for accelerating the worldwide used SSL/TLS, which faces performance bottlenecks due to its underlying heavy cryptographic computations. Nevertheless, substantial structural adjustments from the parallel mode of GPUs to the serial mode of the SSL/TLS stack are imperative, potentially constraining the practical deployment of GPUs. In this paper, we propose AsyncGBP${}^{+}$, a three-level framework that facilitates the seamless conversion of cryptographic requests from synchronous to asynchronous mode. We conduct an in-depth analysis of the OpenSSL provider and cryptographic primitive features relevant to GPU implementations, aiming to fully exploit the potential of GPUs. Notably, AsyncGBP${}^{+}$supports three working settings (offline/online/hybrid), finely tailored for various public key cryptographic primitives, including traditional ones like X25519, Ed25519, ECDSA, and the quantum-safe CRYSTALS-Kyber. A comprehensive evaluation demonstrates that AsyncGBP${}^{+}$can efficiently achieve an improvement of up to 137.8$\times$compared to the default OpenSSL provider (for X25519, Ed25519, ECDSA) and 113.30$\times$compared to OpenSSL-compatibleliboqs(for CRYSTALS-Kyber) in a single-process setting. Furthermore, AsyncGBP${}^{+}$surpasses the current fastest commercial-off-the-shelf OpenSSL-compatible TLS accelerator with a 5.3$\times$to 7.0$\times$performance improvement. Yi Bian 0001, Fangyu Zheng, Yuewu Wang, Lingguang Lei, Jiankuo Dong, Guang Fan 0001, Jiwu Jing |
IEEE Trans. Computers | 9 |
| 2025 | GIF-FHE: A Comprehensive Implementation and Evaluation of GPU-Accelerated FHE With Integer and Floating-Point Computing PowerabstractFully Homomorphic Encryption (FHE) allows computations on encrypted data without revealing the plaintext, garnering significant interest from both academic and industrial communities. However, its broader adoption has been hindered by performance limitations. Consequently, researchers have turned to GPUs for efficient FHE implementation. Nevertheless, most have predominantly favored integer units due to their ease of use, overlooking the considerable computational potential of floating-point units in GPUs. Recognizing this untapped floating-point computational power, our paper introducesGIF-FHE, an extensive exploration and implementation of FHE, leveraging GPUs' integer and floating-point instructions for FHE acceleration. We develop a comprehensive suite of low-level and middle-level FHE primitives, offering multiple implementation variants with support for three word size configurations ($64/52/32$-bit). Particularly, we make innovative use of floating-point implementations, employing a novel methodology to efficiently leverage the floating-point unit's fused multiply-add (FMA) instructions. This represents the pioneering integration of floating-point units into FHE acceleration. To bridge our highly-optimized FHE primitives with practical applications, this paper also provides a high-level FHE implementation and interfaces that can be directly applied by upper-level applications such as neural network inference. Finally, we undertake a comprehensive experiment evaluation and comparison involving three types of arithmetic: FP64/INT64/INT32 with varying word size configurations and computation units. Notably, our fundamental function implementations consistently outperform counterparts on the same platform, achieving speedups ranging from$2.0\times$to$4.2\times$. In the context of CKKS FHE schemes, our homomorphic operation implementation surpasses the state-of-the-art GPU-based solution with a speedup of up to$3.8\times$, and exceeds the performance of the widely adopted CPU-based library, SEAL, with a remarkable speedup of over$300\times$. Fangyu Zheng, Guang Fan 0001, Wenxu Tang, Yuan Zhao 0015, Jiankuo Dong, Jingqiang Lin 0001, Shoumeng Yan, Jiwu Jing |
IEEE Trans. Parallel Distributed Syst. | 10 |
| 2024 | DPad-HE: Towards Hardware-friendly Homomorphic Evaluation using 4-Directional ManipulationabstractModule Learning with Errors (MLWE) based approaches for Fully Homomorphic Encryption (FHE) have garnered attention due to their potential to enhance hardware-friendliness and implementation efficiency. However, despite these advantages, their overall performance still trails behind traditional schemes based on Ring Learning with Errors (RLWE). This indicates that while MLWE-based constructions hold promise, there remain significant challenges to overcome in bridging the performance gap with RLWE-based FHE schemes. By uncovering the reasons for the unsatisfactory performance of prior schemes and pinpointing the fundamental differences in the design of MLWE-based FHE compared to traditional approaches, the paper introduces DPad-HE with a novel design incorporating manipulation in the module rank dimension. The newly introduced operations, rank-up, and rank-down, effectively regulate the scale of gadget decomposition, reducing the computational workload of key-switching by several times. Taking CKKS as a case study, the evaluation showcases the comprehensive advantages of DPad-HE over the state-of-the-art MLWE-based scheme, resulting in a performance boost of 1.26× to 5.71×, a reduction in key size from 1/3 to 3/4, with enhanced noise control. To test the hardware-friendliness of the solution, DPad-HE is also implemented on GPU. Notably, DPad-HE demonstrates that, for the first time, the execution latency of MLWE-based schemes can achieve comparable performance with traditional RLWE ones, especially on the GPU platform where a speedup up to 1.41× is witnessed. Additionally, this paper provides a lightweight conversion method between RLWE and MLWE ciphertexts, allowing for flexible selection of RLWE and MLWE settings during a single complete evaluation process. This opens up new possibilities for both RLWE-based and MLWE-based FHEs. Wenxu Tang, Fangyu Zheng, Guang Fan 0001, Jingqiang Lin 0001, Jiwu Jing |
CCS | 6 |
| 2024 | HiddenStor: A Steganographic Storage System Built on Secret Sharing
Yuewu Wang, Chunjing Kou, Peng Wang 0009, Jiwu Jing |
Inscrypt (1) | 6 |
| 2024 | ARPSSO: An OIDC-Compatible Privacy-Preserving SSO Scheme Based on RP Anonymization
Junlin He, Lingguang Lei, Yuewu Wang, Pingjian Wang, Jiwu Jing |
ESORICS (2) | 5 |
| 2024 | TensorPolyMul: Accelerating Polynomial Multiplication in NTT-unfriendly Lattice-based Cryptography Using Tensor CoresabstractThe urgent demand for computing power in Artificial intelligence (AI) technology has driven the rapid development of dedicated accelerators. Meanwhile, the threat posed by quantum computing to traditional public-key cryptography has prompted the emergence of post-quantum algorithms, such as lattice-based cryptography. However, performance issues with these algorithms have raised concerns within the industry about the transition to quantum-safe solutions. In this paper, we propose a novel universal framework for NTT-unfriendly lattice-based post-quantum algorithms, leveraging NVIDIA’s AI accelerator Tensor Core to address this challenge. By employing techniques such as polynomial matrixization and multi-precision representation, we effectively transform the primary workload (i.e., polynomial multiplication) into a series of small-coefficient matrix multiplications that can be directly accelerated by Tensor Cores. This approach effectively bridges the gap between typical Tensor Core workloads and the core workloads of lattice-based post-quantum cryptography. As a case study, we implemented a prototype called TensorPolyMul to provide an implementation of Saber, a quantum-safe Key Encapsulation Mechanism (KEM). The experiments showcase that TensorPolyMul surpasses the state-of-the-art Tensor Core-based work, achieving remarkable speed-ups of $1.53 \times 1.33 \times, 1.62 \times$, and $1.22 \times$ for Inner Product, MatrixVecMul, Encaps, and Decaps, respectively. Yi Bian 0001, Fangyu Zheng, Jiwu Jing |
ICPADS | 3 |
| 2024 | CacheIEE: Cache-Assisted Isolated Execution Environment on ARM Multi-Core PlatformsabstractARM TrustZone technology has been widely used to create Trusted Execution Environments (TEEs) for enhancing the security of applications. However, the increasing number of installed security-sensitive applications in the secure world will inevitably enlarge the trusted computing base (TCB) of TEE systems. To minimize the TCB of the secure world and increase application portability, Isolated Execution Environments (IEEs) are proposed to protect applications in enclaves created in the normal world. However, existing IEE systems cannot provide the same level of security as the TEE systems, particularly, on resolving the multi-vector attacks that include both physical memory disclosure attacks and software attacks. In this article, we develop a new cache-assisted IEE system called CacheIEE that creates enclaves in the L1 data cache of the normal world to protect sensitive data against multi-vector attacks. First, by always storing the sensitive data in the L1 data cache, CacheIEE can effectively prevent physical memory disclosure attacks. Second, we protect the L1 data cache against untrusted rich OS running in other cores. To support more applications, CacheIEE can process large-size sensitive data in the L1 data cache with constrained capacity. We implement a system prototype of CacheIEE and verify its security and practicability. Jie Wang 0138, Kun Sun 0001, Lingguang Lei, Yuewu Wang, Jiwu Jing, Shengye Wan, Qi Li 0002 |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2024 | Condo: Enhancing Container Isolation Through Kernel Permission Data ProtectionabstractContainer technology is widely adopted due to its features such as light weight and ease of rapid deployment. However, as an OS-level virtualization mechanism, container isolation relies on the kernel’s security mechanisms and the kernel permission data (usually non-control flow data) used by these mechanisms. None of the existing mitigation schemes for non-control flow data attacks provide an effective and practical solution to container security since they either trigger too much overhead, have limited effectiveness over attacks launched in specific ways, or can only be used to protect some specific kernel data. In addition, none of them accurately identify the kernel data associated with container isolation. In this paper, we provide a solution called Condo that enhances container isolation by protecting the associated kernel permission data. We first present a generic non-control flow kernel data protection mechanism that protects different types of kernel data uniformly with low overhead and is not limited by attack methods or data types. We then demystify the models of various kernel access control mechanisms in the container environment, and identify the subject and object permission data that are critical to container isolation. Finally, we provide a solution named Condo to enhance container isolation, which is completely transparent to the existing container ecosystem, including containerized applications and container management/orchestration tools such as Docker. Experimental results show that Condo can effectively reduce the compromises of container isolation due to memory corruption attacks with an acceptable overhead. Shouyin Xu, Yuewu Wang, Lingguang Lei, Kun Sun 0001, Jiwu Jing, Jie Wang 0138 |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2023 | AsyncGBP: Unleashing the Potential of Heterogeneous Computing for SSL/TLS with GPU-based ProviderabstractThe proliferation of IoT and 5G technologies has led to an explosion of data traffic that data centers must handle while ensuring secure transmission via SSL/TLS. The high volume of cryptographic operations required imposes performance bottlenecks. The GPU-based cryptographic accelerator is one of the competitive solutions. However, significant structural differences with practical applications confine their capacities to specific domains, such as offline cryptanalysis, undermining their potential for real-world cryptographic acceleration. Yi Bian 0001, Fangyu Zheng, Yuewu Wang, Lingguang Lei, Jiankuo Dong, Jiwu Jing |
ICPP | 7 |
| 2023 | New cryptanalysis of LowMC with algebraic techniquesabstractAbstract LowMC is a family of block ciphers proposed by Albrecht et al. at EUROCRYPT 2015, which is tailored specifically for FHE and MPC applications. At ToSC 2018, a difference enumeration attack was given for the cryptanalysis of low-data instances of full LowMCv2 with few applied S-boxes per round. Recently at CRYPTO 2021, an efficient algebraic technique was proposed to attack 4-round LowMC adopting a full S-box layer. Following these works, we present a new difference enumeration attack framework, which is based on our new observations on the LowMC S-box, to analyze LowMC instances with a full S-box layer. As a result, with only 3 chosen plaintexts, we can attack 4-round LowMC instances which adopt a full S-box layer with block size of 129, 192, and 255 bits, respectively. We show that all these attacks have either a lower time complexity or a higher success probability than those reported in the CRYPTO paper. Wenxiao Qiao, Hailun Yan, Siwei Sun, Lei Hu 0003, Jiwu Jing |
Des. Codes Cryptogr. | 5 |
| 2023 | Low-Cost Shuffling Countermeasures Against Side-Channel Attacks for NTT-Based Post-Quantum CryptographyabstractLattice-based cryptography (LBC) schemes are promising candidates in the post-quantum cryptography (PQC) standardization process. Number theoretic transform (NTT), as a crucial technique, is widely used to accelerate LBC implementations on computer systems. However, existing side-channel attacks can recover the secret key in real-world cryptographic devices bypassing mathematical problems. The motivation of this work is to provide a low-cost security-enhanced architecture for NTT-based PQC processors. We convert the nested loops in NTT to a hardware-friendly single-level loop. The corresponding architecture instantiates a unified shuffling controller to schedule the order of independent basic operations. We propose the coefficient index randomization and the NTT network randomization schemes against existing power attacks and template attacks. We further achieve high performance and efficiency on the off-the-shelf FPGAs. The shuffling schemes have a negligible impact on performance, and the resource overhead is only 9%. Jiwu Jing |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 3 |
| 2022 | Secure zero-effort two-factor authentication based on time-frequency audio analysis
Shen Yan 0007, Jiwu Jing |
Int. J. Inf. Comput. Secur. | 4 |
| 2022 | MDEFTL: Incorporating Multi-Snapshot Plausible Deniability into Flash Translation LayerabstractConventional encryption solutions cannot defend against a coercive attacker who can capture the device owner, and force the owner to disclose keys used for decrypting sensitive data. To defend against such a coercive adversary, Plausibly Deniable Encryption (PDE) was introduced to allow the device owner to deny the very existence of sensitive data. The existing PDE systems built for computing devices equipped with flash storage media, are problematic, since they cannot defend against multi-snapshot adversaries, who may have access to the storage medium of a user's device at different points of time. In this article, we propose MDEFTL, a secure multi-snapshot PDE system for mobile devices which incorporates plausible deniability into Flash Translation Layer (FTL). MDEFTL is the first practical design which integrates multi-snapshot PDE into FTL, a pervasively deployed layer in literally all the current mobile devices. A salient advantage of MDEFTL lies in its capability of achieving multi-snapshot plausible deniability while being able to accommodate the special nature of NAND flash as well as eliminate deniability compromises from it. We implemented MDEFTL using an open-source NAND flash controller. The experimental results show that, compared to conventional encryption which does not provide deniability, our MDEFTL only incurs a small overhead. Shijie Jia 0001, Qionglu Zhang, Luning Xia, Jiwu Jing, Peng Liu 0005 |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2022 | Blockchain-Based Certificate Transparency and Revocation TransparencyabstractTraditional X.509 public key infrastructures (PKIs) depend on trusted certification authorities (CAs) to sign certificates, used in SSL/TLS to authenticate web servers and establish secure channels. However, recent security incidents indicate that CAs may (be compromised to) sign fraudulent certificates. In this article, we propose blockchain-based certificate transparency (CT) and revocation transparency (RT) to balance the absolute authority of CAs. Our scheme is compatible with X.509 PKIs but significantly reinforces the security guarantees of a certificate. The CA-signed certificates and their revocation status information of an SSL/TLS web server are published by the subject (i.e., the web server) as a transaction in the global certificate blockchain. The certificate blockchain acts as append-only public logs to monitor CAs’ certificate signing and revocation operations, and an SSL/TLS web server is granted with the cooperative control on its certificates. A browser compares the certificate received in SSL/TLS negotiations with the ones in the public certificate blockchain, and accepts it only if it is published and not revoked. We implement the prototype system with Firefox and Nginx, and the experimental results show that it introduces reasonable overheads. Jingqiang Lin 0001, Quanwei Cai 0001, Qiongxiao Wang, Daren Zha, Jiwu Jing |
IEEE Trans. Dependable Secur. Comput. | 6 |
| 2022 | TrustSAMP: Securing Streaming Music Against Multivector Attacks on ARM PlatformabstractStreaming music has dominated the digital music industry in recent years, which allows users to enjoy a huge music library online with a low subscription price. Terminal-side audio DRM (Digital Right Management) is very critical for streaming music industry, compromising of which will cause unrestricted listening, dumping and unauthorized secondary distribution. However, existing DRM protection schemes mainly focus on defeating software attacks but lack complete shielding against the physical memory disclosure attacks, which may even be launched by the owner of the terminal device. In this paper, we propose a terminal-side audio DRM solution called TrustSAMP to protect the copyrighted audio data against both software attacks and physical memory disclosure attacks. The basic idea is to process the audio data plaintext only in certain on-SoC components secured by ARM TrustZone. To minimize the TCB (Trusted Computing Base) of the secure world, we separate the control flow and the data flow of the Linux audio subsystem and port only the codes used for audio data decryption and plaintext transfer into the secure world. Moreover, we leave most driver codes of the audio-associated on-SoC components in the rich OS (i.e., in the normal world), and introduce a tiny proxy in the secure world to control the associated registers according to the requests from the normal-world drivers. The prototype implemented on real hardware shows that TrustSAMP can play a variety of wav-format audio with very small overhead and negligible loss of audio quality. Yanchu Li, Lingguang Lei, Yuewu Wang, Jiwu Jing |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2022 | The Invisible Side of Certificate Transparency: Exploring the Reliability of Monitors in the WildabstractTo detect fraudulent TLS server certificates and improve the accountability of certification authorities (CAs), certificate transparency (CT) is proposed to record certificates in publicly-visible logs, from which the monitors fetch all certificates and watch for suspicious ones. However, if the monitors, either domain owners themselves or third-party services, fail to return a complete set of certificates issued for a domain of interest, potentially fraudulent certificates may not be detected and then the CT framework becomes less reliable. This paper presents the first systematic study on CT monitors. We analyze the data in 88 public logs and the services of 5 active third-party monitors regarding 3,000,431 certificates of 6,000 selected Alexa Top-1M websites. We find that although CT allows ordinary domain owners to act as monitors, it is impractical for them to perform reliable processing by themselves, due to the rapidly increasing volume of certificates in public logs (e.g., on average about 5 million records or 28.29 GB daily for the minimal set of logs that need to be monitored in 2018, or more than 7 million records per day in 2020, according to the Chrome CT policy). Moreover, our study discloses that (${a}$) none of the third-party monitors guarantees to return the complete set of certificates for a domain, and (${b}$) for some domains, even the union of the certificates returned by the five third-party monitors can probably be incomplete. As a result, the certificates accepted by CT-enabled browsers are not actually visible to the claimed domain owners, even when CT is adopted with well-functioning logs. The risk of invisible fraudulent certificates in public logs raises doubts on the reliability of CT in practice. Bingyu Li 0003, Jingqiang Lin 0001, Fengjun Li, Qiongxiao Wang, Wei Wang 0314, Qi Li 0002, Guangshen Cheng, Jiwu Jing, Congli Wang |
IEEE/ACM Trans. Netw. | 8 |
| 2021 | An Efficient Non-Profiled Side-Channel Attack on the CRYSTALS-Dilithium Post-Quantum SignatureabstractPost-quantum digital signature is a critical primitive of computer security in the era of quantum hegemony. As a finalist of the post-quantum cryptography standardization process, the theoretical security of the CRYSTALS-Dilithium (Dilithium) signature scheme has been quantified to withstand classical and quantum cryptanalysis. However, there is an inherent power side-channel information leakage in its implementation instance due to the physical characteristics of hardware.This work proposes an efficient non-profiled Correlation Power Analysis (CPA) strategy on Dilithium to recover the secret key by targeting the underlying polynomial multiplication arithmetic. We first develop a conservative scheme with a reduced key guess space, which can extract a secret key coefficient with a 99.99% confidence using 157 power traces of the reference Dilithium implementation. However, this scheme suffers from the computational overhead caused by the large modulus in Dilithium signature. To further accelerate the CPA run-time, we propose a fast two-stage scheme that selects a smaller search space and then resolves false positives. We finally construct a hybrid scheme that combines the advantages of both schemes. Real-world experiment on the power measurement data shows that our hybrid scheme improves the attack’s execution time by 7.77×. Emre Karabulut, Aydin Aysu, Jiwu Jing |
ICCD | 5 |
| 2021 | High-performance area-efficient polynomial ring processor for CRYSTALS-Kyber on FPGAs
Tianyu Chen 0016, Jingqiang Lin 0001, Jiwu Jing |
Integr. | 5 |
| 2021 | A Lightweight Full Entropy TRNG With On-Chip Entropy AssuranceabstractTrue random number generator (TRNG) as one essential hardware primitive is widely used in cryptography, Monte Carlo simulation, and gambling. To evaluate the security of TRNG, the entropy of the TRNG’s output is usually estimated by the stochastic model in theory or measured off-chip after fabrication. However, the sufficiency of entropy is difficult to be guaranteed in practice due to the facts: 1) the inaccuracy of the model-based jitter measurement method; 2) the variations of the chip manufacturing process and operating environments (such as supply voltage and temperature); and 3) malicious attacks. In this work, we design a novel TRNG architecture with on-chip entropy assurance to properly solve practical security problems. In the design, we propose an on-chip entropy estimator for measuring independent jitter to quantify true randomness, which enables continuous monitoring of TRNG at runtime. Furthermore, with the cooperation of the proposed on-chip entropy estimator and a rational self-adaptive mechanism, the designed TRNG can steadily generate bitstreams with sufficient entropy (≥ 0.999 per bit) against PVT variations. We implement the TRNG architecture in FPGAs with different technology nodes (45 and 65 nm) and SMIC 130 nm chips. Experimental results validate that the designed TRNG has an excellent performance in terms of technology independence and environmental robustness. The generated bitstreams pass the NIST SP800-22 and Diehard statistical test suites successfully without any post-processing. Tianyu Chen 0016, Jingqiang Lin 0001, Yuan Cao 0003, Jiwu Jing |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 6 |
| 2021 | Vulnerable Service Invocation and CountermeasuresabstractBefore Android 5.0, the services in Android applications can be invoked either explicitly or implicitly. However, since the implicit service invocations may suffer service hijacking attacks and thus lead to sensitive data leakage, they have been forbidden since Android 5.0. Thereafter the Android system will simply throw an exception and crash the applications that still invokes services implicitly, so that it was expected that application developers will be forced to convert the implicit service invocations to explicit ones. In this paper, we develop a static analysis framework called ISA to analyze the effectiveness of forbidden policy on removing the vulnerable service invocations. We collect two datasets containing common 1390 apps downloaded 1 to 3 months before the forbidden policy is enforced and 30 months after the forbidden policy is enforced, respectively. Our preliminary analysis indicates a 82.58% reduction in the number of vulnerable service invocations due to the enforcement of forbidden policy. However, upon further investigation, we discover that the forbidden policy fails to resolve service hijacking attacks. We find that 36 popular applications are still vulnerable to service hijacking attacks, which can lead to the leakage of sensitive information such as user login credential. Finally, we analyze the reasons of the residue vulnerable invocations and then propose two countermeasures. Lingguang Lei, Kun Sun 0001, Yuewu Wang, Jiwu Jing, Yi He 0020, Pingjian Wang |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2021 | Mimosa: Protecting Private Keys Against Memory Disclosure Attacks Using Hardware Transactional MemoryabstractCryptography is essential for computer and network security. When cryptosystems are deployed in computing or communication systems, it is extremely critical to protect the cryptographic keys. In practice, keys are loaded into the memory as plaintext during cryptographic computations. Therefore, the keys are subject to memory disclosure attacks that read unauthorized data from RAM. Such attacks could be performed through software exploitations, such as OpenSSL Heartbleed, even when the integrity of the victim system's binaries is maintained. They could also be done through physical methods, such as cold-boot attacks, even if the system is free of software vulnerabilities. This paper presents Mimosa, to protect RSA private keys against both software-based and physical memory disclosure attacks. Mimosa uses hardware transactional memory (HTM) to ensure that (a) whenever a malicious thread other than Mimosa attempts to read the plaintext private key, the transaction aborts and all sensitive data are automatically cleared with hardware, due to the strong atomicity guarantee of HTM; and (b) all sensitive data, including private keys and intermediate states, appear as plaintext only within CPU-bound caches, and are never loaded to RAM chips. To the best of our knowledge, Mimosa is the first solution to use transactional memory to protect sensitive data against memory attacks. However, the fragility of TSX transactions introduces extra cache-clogging denial-of-service (DoS) threats, and attackers could sharply degrade the performance by concurrent memory-intensive tasks. To mitigate the DoS threats, we further partition an RSA private-key computation into multiple transactional parts by analyzing the distribution of aborts, while (sensitive) intermediate results are still protected across transactional parts. Through extensive experiments, we show that Mimosa effectively protects cryptographic keys against attacks that attempt to read sensitive data in memory, and introduces only a small performance overhead, even with concurrent cache-clogging workloads. Congwu Li, Le Guan, Jingqiang Lin 0001, Bo Luo, Quanwei Cai 0001, Jiwu Jing |
IEEE Trans. Dependable Secur. Comput. | 6 |
| 2021 | Locally-Centralized Certificate Validation and its Application in Desktop Virtualization SystemsabstractTo validate a certificate, a user needs to install the certificate of the root certification authority (CA) and download the certificate revocation information (CRI). Although operating systems and browsers manage the certificate trust list (CTL) of publicly-trusted root CAs for global users, locally-trusted root CAs still play an important role and it is difficult for a user to manage its CTL properly by itself. Meanwhile, the CRI access is inefficient, sometimes even unavailable, and causes privacy leakage. We revisit these problems by analyzing the TLS sessions within an organization. To the best of our knowledge, we are the first to analyze CTL management and CRI access on the scale of medium-sized organizations. Based on the analysis, a locally-centralized design is proposed to manage the CTLs of all users by IT administrators and access the CRI services for all users, within an organization. We apply this design to desktop virtualization systems to demonstrate its applicability, and build vCertGuard with oVirt and KVM-QEMU. In vCertGuard, the CTLs of all virtual machines (VMs) are managed in the VM monitors (VMMs). In the CTL, the self-signed certificates of publicly-trusted root CAs are properly configured, while each locally-trusted certificate chain is specified one by one. vCertGuard accesses the CRI services for all VMs, and the downloaded CRI is cached and shared among VMs. Because most TLS servers are visited by multiple users of an organization, it reduces the cost of CRI access. Experimental results of the prototype system show that vCertGuard maintains the CTLs with a negligible overhead, and significantly improves the performance of CRI access. Bingyu Li 0003, Jingqiang Lin 0001, Qiongxiao Wang, Jiwu Jing |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2020 | Towards Efficient Kyber on FPGAs: A Processor for Vector of PolynomialsabstractKyber is a promising candidate in post-quantum cryptography standardization process. In this paper, we propose a targeted optimization strategy and implement a processor for Kyber on FPGAs. By merging the operations, we cut off 29.4% clock cycles for Kyber512 and 33.3% for Kyber1024 compared with the textbook implementations. We utilize Gentlemen-Sande (GS) butterfly to optimize the Number-Theoretic Transform (NTT) implementation. The bottleneck of memory access is broken taking advantage of a dual-column sequential scheme. We further propose a pipeline architecture for better performance. The optimizations help the processor achieve 31684 NTT operations per second using only 477 LUTs, 237 FFs and 1 DSP. Our strategy is at least 3x more efficient than the state-of-the-art module for NTT with a similar security level. Tianyu Chen 0016, Jingqiang Lin 0001, Jiwu Jing |
ASP-DAC | 5 |
| 2020 | Cache-in-the-Middle (CITM) Attacks: Manipulating Sensitive Data in Isolated Execution EnvironmentsabstractThe traditional usage of ARM TrustZone has difficulty on solving the conflicts between the manufacturers that want to minimize the trusted computing base by constraining the installation of third-party applications in the secure world and the third-party application developers who prefer to have the freedom of installing their applications into the secure world. To address this issue, researchers propose to create Isolated Execution Environments (called IEEs) in the normal world to protect the security-sensitive applications. In this paper, we perform a systematic study on the IEE data protection models and the ARM cache attributes, and discover three cache-based attacks called CITM that can be leveraged to manipulate the sensitive data protected in IEEs. Specifically, due to the inefficient and incoherent security measures on the cache that maps to the IEE memory (i.e., memory designated for IEEs), attackers in the normal world may compromise the security of IEE data by manipulating the IEE memory during concurrent execution, bypassing the security measures enforced when a security-sensitive application is suspended or finished, or misusing the incomplete security measures during IEE's context switching processes. We conduct case studies of CITM attacks on three well-known IEE systems including SANCTUARY, Ginseng, and TrustICE to illustrate the feasibility to exploit them on real hardware testbeds. Finally, we analyze the root causes of the CITM attacks and propose a countermeasure to defeat them. The experimental results show that our defense scheme has a small overhead. Jie Wang 0138, Kun Sun 0001, Lingguang Lei, Shengye Wan, Yuewu Wang, Jiwu Jing |
CCS | 6 |
| 2020 | Deduplication-Friendly Watermarking for Multimedia Data in Public Clouds
Weijing You, Jiwu Jing |
ESORICS (1) | 4 |
| 2020 | TrustICT: an efficient trusted interaction interface between isolated execution domains on ARM multi-core processorsabstractThe Trusted Execution Environment (TEE) has been widely used to protect the security-sensitive sensing systems on Internet-of-Thing (IoT) devices. In the TEE systems, the execution environment is securely divided into a normal domain and a higher privileged secure domain which executing sensing systems through hardware. One common way to achieve the protection is implementing the sensitive functions of the sensing systems as trusted applications (TAs) in the well-isolated secure domain. Users in rich OS have to call TAs through the client applications (CAs), and the invocations must pass through the rich OS kernel. However, an untrusted rich OS may launch man-in-the-middle attacks on the communication between the CAs and TAs, and the misuse of cross-domain communication channel is becoming one severe threat on the TEE systems. In this paper, we develop a defense system named TrustICT to construct a lightweight trusted interaction channel between CAs and TAs without modifying existing TEE architecture. The main idea is to block attacks on the cross-domain interactions via dynamically setting the access permission of domain-shared memory, locking it from kernel mode and unlocking it only to legal CAs in the user mode. Particularly, we propose a multi-core scheduling strategy to defeat potential attacks from all privileged cores. Compared to existing cryptography-based methods, TrustICT dramatically reduces the system overhead since it does not require time-consuming cryptographic computation or sophisticated real-time kernel protection. We implement a prototype of TrustICT on a Freescale i.MX6Quad platform with the OP-TEE software system and evaluate its impacts on rich OS and the cross-domain transactions. Jie Wang 0138, Yuewu Wang, Lingguang Lei, Kun Sun 0001, Jiwu Jing |
SenSys | 5 |
| 2020 | SecureESFS: Sharing Android External Storage Files in A Securer WayabstractAs an essential component on Android devices, External Storage is frequently used for sharing files between different apps. Therefore, compared to Internal Storage, the access control on the External Storage is usually very loose. However, a lot of sensitive files might be stored on the External Storage, which makes it an attractive target for the attackers. Since Android 10, a security mechanism named Scoped Storage has been introduced to protect the sensitive files on the External Storage. However, this mechanism is mainly used to protect the app-specific files, and can't support the sharing of sensitive files between trusted apps in a secure and flexible way. In this paper, we present a secure External Storage sensitive file sharing solution named SecureESFS. It first extends a Linux kernel security mechanism named ACL on the SDCardFS filesystem to protect the External Storage. With different ACL policy settings, the user can dynamically share sensitive files between trusted apps according to specific business needs. We also enforce the integrity protection on the ACL policies by checking the hash message authentication codes (HMAC) of these policies. Moreover, we design a transparent encryption mechanism in SecureESFS to protect the sensitive files on the External Storage, when the Android devices are physically accessed by the attackers, such as removing the SD card. For versions lower than Android 10, SecureESFS can provide independent protection and secure sharing for the sensitive files on the External Storage. For versions higher than Android 10, SecureESFS can achieve the secure sharing of sensitive files while Scoped Storage provides protection for the app-specific files. SecureESFS may also be used to enhance the security of the Scoped Storage mechanism. Experiments conducted on a prototype show that SecureESFS works well and incurs acceptable overhead. Yuewu Wang, Lingguang Lei, Jiwu Jing |
TrustCom | 4 |
| 2020 | High-Efficiency Min-Entropy Estimation Based on Neural Network for Random Number GeneratorsabstractRandom number generator (RNG) is a fundamental and important cryptographic element, which has made an outstanding contribution to guaranteeing the network and communication security of cryptographic applications in the Internet age. In reality, if the random number used cannot provide sufficient randomness (unpredictability) as expected, these cryptographic applications are vulnerable to security threats and cause system crashes. Min-entropy is one of the approaches that are usually employed to quantify the unpredictability. The NIST Special Publication 800-90B adopts the concept of min-entropy in the design of its statistical entropy estimation methods, and the predictive model-based estimators added in the second draft of this standard effectively improve the overall capability of the test suite. However, these predictors have problems on limited application scope and high computational complexity, e.g., they have shortfalls in evaluating random numbers with long dependence and multivariate due to the huge time complexity (i.e., high-order polynomial time complexity). Fortunately, there has been increasing attention to using neural networks to model and forecast time series, and random numbers are also a type of time series. In our work, we propose several new and efficient approaches for min-entropy estimation by using neural network technologies and design a novel execution strategy for the proposed entropy estimation to make it applicable to the validation of both stationary and nonstationary sources. Compared with the 90B’s predictors officially published in 2018, the experimental results on various simulated and real-world data sources demonstrate that our predictors have a better performance on the accuracy, scope of applicability, and execution efficiency. The average execution efficiency of our predictors can be up to 10 times higher than that of the 90B’s for 10 6 sample size with different sample spaces. Furthermore, when the sample space is over 2 2 and the sample size is over 10 8 , the 90B’s predictors cannot give estimated results. Instead, our predictors can still provide accurate results. Copyright© 2019 John Wiley & Sons, Ltd. Tianyu Chen 0016, Shuangyi Zhu, Jing Yang 0032, Jiwu Jing, Jingqiang Lin 0001 |
Secur. Commun. Networks | 6 |
| 2020 | Erratum to "High-Efficiency Min-Entropy Estimation Based on Neural Network for Random Number Generators"
Tianyu Chen 0016, Shuangyi Zhu, Jing Yang 0032, Jiwu Jing, Jingqiang Lin 0001 |
Secur. Commun. Networks | 6 |
| 2020 | On the Analysis and Improvement of Min-Entropy Estimation on Time-Varying DataabstractWidely used as fundamental security components in most cryptographic applications, random number generators (RNGs) rely mainly on randomness provided by entropy sources. If the provided randomness is less than expected, RNGs may be compromised and thus impair the security of the whole cryptographic applications. However, the common assumptions (e.g., outputs are independent and identically distributed, i.e., IID) may not always hold. For example, many entropy sources are based on some physical phenomena that are fragile and sensitive to external factors (e.g., temperature), which means the distributions of these entropy sources' outputs are continuously changing. As important tools to measure the quality of entropy sources, existing entropy estimation methods may provide false estimations against these time-varying data, because they cannot detect the changes of data distributions. In this paper, we firstly review and analyze the existing typical entropy estimators including the NIST SP 800-90B (90B for short) estimators and the lately proposed neural network based (NN-based) estimators, especially, their limitations on the aforementioned time-varying data. Second, we propose an entropy estimation framework adopting change detection techniques to address this problem. In contrast to the NN-based estimators, the proposed estimator under this framework employs a change detection method to preprocess the tested data and adds additional distribution features to each data sample, which makes it possible to learn the distribution changes and estimate the entropy more accurately. Finally, we evaluate the performance of our estimator using various kinds of simulated data and real world data, and compare our estimator with the 90B estimators and the NN-based estimators. Extensive evaluations demonstrate that the proposed estimator provides similar or more accurate entropy estimation than the other estimators, especially for time-varying data. Shuangyi Zhu, Jing Yang 0032, Jingqiang Lin 0001, Jiwu Jing |
IEEE Trans. Inf. Forensics Secur. | 6 |
| 2019 | Certificate Transparency in the Wild: Exploring the Reliability of MonitorsabstractTo detect fraudulent TLS server certificates and improve the accountability of certification authorities (CAs), certificate transparency (CT) is proposed to record certificates in publicly-visible logs, from which the monitors fetch all certificates and watch for suspicious ones. However, if the monitors, either domain owners themselves or third-party services, fail to return a complete set of certificates issued for a domain of interest, potentially fraudulent certificates may not be detected and then the CT framework becomes less reliable. This paper presents the first systematic study on CT monitors. We analyze the data in 88 public logs and the services of 5 active third-party monitors regarding 3,000,431 certificates of 6,000 selected Alexa Top-1M websites. We find that although CT allows ordinary domain owners to act as monitors, it is impractical for them to perform reliable processing by themselves, due to the rapidly increasing volume of certificates in public logs (e.g., on average 5 million records or 28.29 GB daily for the minimal set of logs that need to be monitored). Moreover, our study discloses that (a) none of the third-party monitors guarantees to return the complete set of certificates for a domain, and (b) for some domains, even the union of the certificates returned by the five third-party monitors can probably be incomplete. As a result, the certificates accepted by CT-enabled browsers are not absolutely visible to the claimed domain owners, even when CT is adopted with well-functioning logs. The risk of invisible fraudulent certificates in public logs raises doubts on the reliability of CT in practice. Bingyu Li 0003, Jingqiang Lin 0001, Fengjun Li, Qiongxiao Wang, Qi Li 0002, Jiwu Jing, Congli Wang |
CCS | 6 |
| 2019 | Evaluating the Cache Side Channel Attacks Against ECDSA
Ziqiang Ma, Quanwei Cai 0001, Jingqiang Lin 0001, Jiwu Jing, Dingfeng Ye, Lingjia Meng |
Inscrypt | 4 |
| 2019 | OCRAM-Assisted Sensitive Data Protection on ARM-Based Platform
Dawei Chu, Yuewu Wang, Lingguang Lei, Yanchu Li, Jiwu Jing, Kun Sun 0001 |
ESORICS (2) | 5 |
| 2019 | Towards the optimal performance of integrating Warm and Delay against remote cache timing side channels on block ciphersabstractCache timing side channels allow a remote attacker to disclose the cryptographic keys, by repeatedly invoking the encryption/decryption functions and measuring the execution time. Warm and Delay are two algorithm-independent and implementation-transparent countermeasures against remote cache-based timing side channels for block ciphers. They destroy the relationship between the execution time and the cache misses/hits which are determined by the secret key, but bring remarkable performance overhead. In this paper, we investigate the performance of cryptographic functions protected by Warm and Delay, and attempt to find the best strategy to integrate these two countermeasures with the optimal performance while effectively eliminate remote cache timing side channels for block ciphers implementations with lookup tables. To the best of our knowledge, this work is the first to systematically analyze the performance of integrating Warm and Delay against cache side channels.We derive the optimal scheme to integrate Warm and Delay, and apply it to AES. It is proven that the integration scheme achieves the optimal performance with the least extra operations on commodity systems. Finally, we implement it on Linux with Intel CPUs. Experimental results confirm that, ( a) the execution time does not leak information on cache access, ( b) the scheme outperforms other integration strategies of Warm and Delay, and ( c) the implementation works without any privileged operations on the computer. Ziqiang Ma, Quanwei Cai 0001, Jingqiang Lin 0001, Bo Luo, Jiwu Jing |
J. Comput. Secur. | 5 |
| 2019 | Entropy Estimation for ADC Sampling-Based True Random Number GeneratorsabstractTrue random number generators (TRNGs) are widely used in cryptographic systems, and their security is the base of many cryptographic algorithms and protocols. At present, entropy estimation based on a stochastic model is a well-recommended approach to evaluate the security of a specific TRNG structure. Besides, the generation speed is also an important property for TRNGs. For this purpose, an analog-to-digital converter (ADC) can be employed to sample the noisy signal to achieve high bit rate. However, no research focuses on the entropy estimation on the basis of the stochastic model toward ADC sampling. In this paper, we propose an entropy estimation for the ADC sampling-based TRNG through extending an existing model. In particular, we present an equivalent model to estimate the entropy of any single bit in the converted sample obtained by the ADC sampling. Furthermore, we propose a method of the entropy estimation for the multi-bit ADC output, which provides the lower bound of the entropy. By conducting simulations and hardware experiments on this type of TRNG, we confirm the correctness of the proposed entropy estimation theory. The prototype chip is fabricated in the SMIC 65-nm process, and the consumed power is 34 mW. The random bit sequences compatible with the AIS 31 standard are generated at a speed of 132.3 Mb/s. The sequences are able to pass the rigorous statistical test suites, including NIST SP 800-22, Diehard, and TestU01 (containing the Big Crush test), after simple post-processing at a bit rate of around 33 Mb/s. Tianyu Chen 0016, Jingqiang Lin 0001, Jing Yang 0032, Jiwu Jing |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2018 | A Measurement Study on Linux Container Security: Attacks and CountermeasuresabstractLinux container mechanism has attracted a lot of attention and is increasingly utilized to deploy industry applications. Though it is a consensus that the container mechanism is not secure due to the kernel-sharing property, it lacks a concrete and systematical evaluation on its security using real world exploits. In this paper, we collect an attack dataset including 223 exploits that are effective on the container platform, and classify them into different categories using a two-dimensional attack taxonomy. Then we evaluate the security of existing Linux container mechanism using 88 typical exploits filtered out from the dataset. We find 50 (56.82%) exploits can successfully launch attacks from inside the container with the default configuration. Since the privilege escalation exploits can completely disable the container protection mechanism, we conduct an in-depth analysis on these exploits. We find the kernel security mechanisms such as Capability, Seccomp, and MAC play a more important role in preventing privilege escalation than the container isolation mechanisms (i.e., Namespace and Cgroup). However, the interdependence and mutual-influence relationship among these kernel security mechanisms may make them fall into the "short board effect" and impair their protection capability. By studying the 11 exploits that still can successfully break the isolation provided by container and achieve privilege escalation, we identify a common 4-step attack model followed by all 11 exploits. Finally, we propose a defense mechanism to effectively defeat those identified privilege escalation attacks. Lingguang Lei, Yuewu Wang, Jiwu Jing, Kun Sun 0001 |
ACSAC | 4 |
| 2018 | Copker: A Cryptographic Engine Against Cold-Boot AttacksabstractCryptosystems are essential for computer and communication security, e.g., RSA or ECDSA in PGP Email clients and AES in full disk encryption. In practice, the cryptographic keys are loaded and stored in RAM as plain-text, and therefore vulnerable to cold-boot attacks exploiting the remanence effect of RAM chips to directly read memory data. To tackle this problem, we propose Copker, a cryptographic engine that implements asymmetric cryptosystems entirely within the CPU, without storing any plain-text sensitive data in RAM. Copker supports the popular asymmetric cryptosystems (i.e., RSA and ECDSA), and deterministic random bit generators (DRBGs) used in ECDSA signing. In its active mode, Copker stores kilobytes of sensitive data, including the private key, the DRBG seed and intermediate states, only in on-chip CPU caches (and registers). Decryption/signing operations are performed without storing any sensitive information in RAM. In the suspend mode, Copker stores symmetrically-encrypted private keys and DRBG seeds in memory, while employs existing solutions to keep the key-encryption key securely in CPU registers. Hence, Copker releases the system resources in the suspend mode. We implement Copker with the support of multiple private keys. With security analyses and intensive experiments, we demonstrate that Copker provides cryptographic services that are secure against cold-boot attacks and introduce reasonable overhead. Le Guan, Jingqiang Lin 0001, Ziqiang Ma, Bo Luo, Luning Xia, Jiwu Jing |
IEEE Trans. Dependable Secur. Comput. | 6 |
| 2017 | Vulnerable Implicit Service: A RevisitabstractThe services in Android applications can be invoked either explicitly or implicitly before Android 5.0. However, since the implicit service invocations suffer service hijacking attacks and thus lead to sensitive information leakage, they have been forbidden since Android 5.0. Thereafter since the Android system will simply throw an exception and crash the application that still invokes services implicitly, it was expected that application developers will be forced to convert the implicit service invocations to explicit ones by specifying the package name of the service to be called. Lingguang Lei, Yi He 0020, Kun Sun 0001, Jiwu Jing, Yuewu Wang, Qi Li 0002, Jian Weng 0001 |
CCS | 4 |
| 2017 | On the Entropy of Oscillator-Based True Random Number Generators
Jingqiang Lin 0001, Jiwu Jing |
CT-RSA | 3 |
| 2017 | Utilizing the Double-Precision Floating-Point Computing Power of GPUs for RSA AccelerationabstractAsymmetric cryptographic algorithm (e.g., RSA and Elliptic Curve Cryptography) implementations on Graphics Processing Units (GPUs) have been researched for over a decade. The basic idea of most previous contributions is exploiting the highly parallel GPU architecture and porting the integer-based algorithms from general-purpose CPUs to GPUs, to offer high performance. However, the great potential cryptographic computing power of GPUs, especially by the more powerful floating-point instructions, has not been comprehensively investigated in fact. In this paper, we fully exploit the floating-point computing power of GPUs, by various designs, including the floating-point-based Montgomery multiplication/exponentiation algorithm and Chinese Remainder Theorem (CRT) implementation in GPU. And for practical usage of the proposed algorithm, a new method is performed to convert the input/output between octet strings and floating-point numbers, fully utilizing GPUs and further promoting the overall performance by about 5%. The performance of RSA-2048/3072/4096 decryption on NVIDIA GeForce GTX TITAN reaches 42,211/12,151/5,790 operations per second, respectively, which achieves 13 times the performance of the previous fastest floating-point-based implementation (published in Eurocrypt 2009). The RSA-4096 decryption precedes the existing fastest integer-based result by 23%. Jiankuo Dong, Fangyu Zheng, Wuqiong Pan, Jingqiang Lin 0001, Jiwu Jing, Yuan Zhao 0015 |
Secur. Commun. Networks | 5 |
| 2017 | An Efficient Elliptic Curve Cryptography Signature Server With GPU AccelerationabstractOver the Internet, digital signature has been an indispensable approach to securing e-commerce and other online transactions requiring authentication. Concerning the computing costs of signature generation and verification, it has become a more and more common practice for security practitioners to outsource such computations from heavily loaded application servers called tenants to dedicated proxies like signature servers in the enterprise private cloud. In this paper, we present our high-performance signature server called Guess. It implements the elliptic curve digital signature algorithm (ECDSA) with 256-b key size on a Linux-powered commodity computer, harnessing a desktop graphics processing unit as a featured cryptographic accelerator. We demonstrate our experience in maximizing the computing power of Guess and also its capability to deliver such power to the tenants, which includes down-to-earth customization and optimization considering various hardware and software factors. Our comprehensive implementation of ECDSA is tested against intensive network traffic. Field experiments show that Guess achieves Ts= 8.71 × 106operations per second (OPS) for signature generation or Tv= 9.29 × 105OPS for verification, which is significantly faster than existent prototypes and products. Guess is a universal server that readily supports various categories of elliptic curve cryptographic schemes, such as digital signature, key agreement, and encryption. Wuqiong Pan, Fangyu Zheng, Wen Tao Zhu, Jiwu Jing |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2016 | More Powerful and Reliable Second-Level Statistical Randomness Tests for NIST SP 800-22
Shuangyi Zhu, Jingqiang Lin 0001, Jia Zhuang, Jiwu Jing |
ASIACRYPT (1) | 5 |
| 2016 | HPAZ: A high-throughput pipeline architecture of ZUC in hardware
Zongbin Liu, Cunqing Ma, Changting Li, Jiwu Jing |
DATE | 5 |
| 2016 | Extracting More Entropy for TRNGs Based on Coherent Sampling
Jing Yang 0032, Tianyu Chen 0016, Jingqiang Lin 0001, Jiwu Jing |
SecureComm | 5 |
| 2015 | TrustOTP: Transforming Smartphones into Secure One-Time Password TokensabstractTwo-factor authentication has been widely used due to the vulnerabilities associated with traditional text-based password. One-time password (OTP) plays an indispensable role on authenticating mobile users to critical web services that demand a high level of security. As the smartphones are increasingly gaining popularity nowadays, software-based OTP generators have been developed and installed into smartphones as software apps, which bring great convenience to the users without introducing extra burden. However, software-based OTP solutions cannot guarantee the confidentiality of the generated passwords or even the seeds when the mobile OS is compromised. Moreover, they also suffer from denial-of-service attacks when the mobile OS crashes. Hardware-based OTP tokens can solve these security problems in the software-based OTP solutions; however, it is inconvenient for the users to carry physical tokens with them, particularly, when there are more than one token to be carried. In this paper, we present TrustOTP, a secure one-time password solution that can achieve both the flexibility of software tokens and the security of hardware tokens by using ARM TrustZone technology. TrustOTP can not only protect the confidentiality of the OTPs against a malicious mobile OS, but also guarantee reliable OTP generation and trusted OTP display when the mobile OS is compromised or even crashes. It is flexible to integrate multiple OTP algorithms and instances for different application scenarios on the same smartphone platform without modifying the mobile OS. We develop a prototype of TrustOTP on Freescale i.MX53 QSB. The experimental results show that TrustOTP has small impacts on the mobile OS and its power consumption is low. He Sun 0005, Kun Sun 0001, Yuewu Wang, Jiwu Jing |
CCS | 4 |
| 2015 | How Your Phone Camera Can Be Used to Stealthily Spy on You: Transplantation Attacks against Android Camera ServiceabstractBased on the observations that spy-on-user attacks by calling Android APIs will be detected out by Android API auditing, we studied the possibility of a "transplantation attack", through which a malicious app can take privacy-harming pictures to spy on users without the Android API auditing being aware of it. Usually, to take a picture, apps need to call APIs of Android Camera Service which runs in mediaserver process. Transplantation attack is to transplant the picture taking code from mediaserver process to a malicious app process, and the malicious app can call this code to take a picture in its own address space without any IPC. As a result, the API auditing can be evaded. Our experiments confirm that transplantation attack indeed exists. Also, the transplantation attack makes the spy-on-user attack much more stealthy. The evaluation result shows that nearly a half of 69 smartphones (manufactured by 8 vendors) tested let the transplantation attack discovered by us succeed. Moreover, the attack can evade 7 Antivirus detectors, and Android Device Administration which is a set of APIs that can be used to carry out mobile device management in enterprise environments. The transplantation attack inspires us to uncover a subtle design/implementation deficiency of the Android security. Zhongwen Zhang, Peng Liu 0005, Ji Xiang, Jiwu Jing, Lingguang Lei |
CODASPY | 4 |
| 2015 | An Efficiency Optimization Scheme for the On-the-Fly Statistical Randomness TestabstractThe randomness of random number generators (RNGs) significantly influences the security of cryptographic systems. Although RNGs are allowed to adopt in practical systems only after strict analysis and security evaluation, the randomness of generated sequences may degrade due to aging effects of electronic devices, change of temperature and humidity, or even malicious attacks. Therefore, before the generated sequence being used (as a secret key or any other critical cryptography parameter), it is necessary to execute the on-the-fly statistical randomness test (on-the-fly test) on the candidate sequence to ensure the security. On-the-fly test should be finished efficiently; otherwise, it would impact the cryptographic systems' performance. In this paper, we propose a scheme to optimize the efficiency of randomness test suites, that is, provide an optimized order of the tests in the test suite, so that an unqualified sequence can be rejected as early as possible. We apply this optimization scheme on the NIST test suite (SP 800-22) [1] as an instance. Experimental results of 128- and 256- bit sequence, demonstrate that the optimized efficiency approximates to the theoretical optimum and the scheme can be quickly implemented. Tianyu Chen 0016, Jingqiang Lin 0001, Jiwu Jing |
CSCloud | 5 |
| 2015 | TrustICE: Hardware-Assisted Isolated Computing Environments on Mobile DevicesabstractMobile devices have been widely used to process sensitive data and perform important transactions. It is a challenge to protect secure code from a malicious mobile OS. ARM TrustZone technology can protect secure code in a secure domain from an untrusted normal domain. However, since the attack surface of the secure domain will increase along with the size of secure code, it becomes arduous to negotiate with OEMs to get new secure code installed. We propose a novel TrustZone-based isolation framework named TrustICE to create isolated computing environments (ICEs) in the normal domain. TrustICE securely isolates the secure code in an ICE from an untrusted Rich OS in the normal domain. The trusted computing base (TCB) of TrustICE remains small and unchanged regardless of the amount of secure code being protected. Our prototype shows that the switching time between an ICE and the Rich OS is less than 12 ms. He Sun 0005, Kun Sun 0001, Yuewu Wang, Jiwu Jing, Haining Wang 0001 |
DSN | 4 |
| 2015 | Bit Error Probability Evaluation of RO PUFs
Zongbin Liu, Cunqing Ma, Jiwu Jing |
ISC | 4 |
| 2015 | DeepDroid: Dynamically Enforcing Enterprise Policy on Android Devices
Xueqiang Wang, Kun Sun 0001, Yuewu Wang, Jiwu Jing |
NDSS | 4 |
| 2015 | Protecting Private Keys against Memory Disclosure Attacks Using Hardware Transactional MemoryabstractCryptography plays an important role in computer and communication security. In practical implementations of cryptosystems, the cryptographic keys are usually loaded into the memory as plaintext, and then used in the cryptographic algorithms. Therefore, the private keys are subject to memory disclosure attacks that read unauthorized data from RAM. Such attacks could be performed through software methods (e.g., Open SSL Heart bleed) even when the integrity of the victim system's executable binaries is maintained. They could also be performed through physical methods (e.g., Cold-boot attacks on RAM chips) even when the system is free of software vulnerabilities. In this paper, we propose Mimosa that protects RSA private keys against the above software-based and physical memory attacks. When the Mimosa service is in idle, private keys are encrypted and reside in memory as cipher text. During the cryptographic computing, Mimosa uses hardware transactional memory (HTM) to ensure that (a) whenever a malicious process other than Mimosa attempts to read the plaintext private key, the transaction aborts and all sensitive data are automatically cleared with hardware mechanisms, due to the strong atomicity guarantee of HTM, and (b) all sensitive data, including private keys and intermediate states, appear as plaintext only within CPU-bound caches, and are never loaded to RAM chips. To the best of our knowledge, Mimosa is the first solution to use transactional memory to protect sensitive data against memory disclosure attacks. We have implemented Mimosa on a commodity machine with Intel Core i7 Haswell CPUs. Through extensive experiments, we show that Mimosa effectively protects cryptographic keys against various attacks that attempt to read sensitive data from memory, and it only introduces a small performance overhead. Le Guan, Jingqiang Lin 0001, Bo Luo, Jiwu Jing |
IEEE Symposium on Security and Privacy | 4 |
| 2015 | RIKE+ : using revocable identities to support key escrow in public key infrastructures with flexibilityabstractPublic key infrastructures (PKIs) are proposed to provide various security services. Some security services such as confidentiality require key escrow in certain scenarios, whereas some others such as non‐repudiation and authentication usually prohibit key escrow. Moreover, these two conflicting requirements can coexist for one PKI user. The popular solution in which each user has two different certificates and an escrow authority backs up all escrowed private keys faces the problems of efficiency and scalability. In this study, a novel key management infrastructure called RIKE + is proposed to integrate the ‘inherent key escrow’ of identity‐based encryption (IBE) into PKIs. In RIKE+, (the hash value of) a user's PKI certificate also serves as a ‘revocable identity’ to derive the user's IBE public key, and the revocation of this IBE key pair is achieved by the certificate revocation of PKIs. Therefore the certificate binds the user with two key pairs, one of which is escrowed inherently and the other is not. Furthermore, RIKE+ employs chameleon hash to flexibly control the relationship between the certificate and the IBE key pair. In the case of certificate renewal and revocation, chameleon hash enables RIKE+ to manipulate the hash value of the new certificate, so the user's IBE key pair is not unconditionally changed unless it is necessary. RIKE+ is an effective certificate‐based solution compatible with traditional PKIs and can be built on existing X.509 PKIs. Jingqiang Lin 0001, Wen Tao Zhu, Qiongxiao Wang, Jiwu Jing, Neng Gao |
IET Inf. Secur. | 5 |
| 2015 | Reliable and Trustworthy Memory Acquisition on SmartphonesabstractWith the wide usage of smartphones in our daily life, new malware is emerging to compromise the mobile OS and then steal or manipulate sensitive data from mobile applications. Forensic analysis tools demand a reliable and trustworthy memory acquisition of the operating systems running on the smartphones for further digital forensic analysis. However, a compromised OS may launch denial of service attacks to prevent a valid memory acquisition by forensic examiners. In this paper, we develop a TrustZone-based memory acquisition mechanism called TrustDump that is capable of reliably and securely obtaining the RAM memory and CPU registers of the mobile OS even if the OS has crashed or been compromised. TrustDump is isolated from the mobile OS by TrustZone. Instead of using a hypervisor to ensure the isolation between the OS and the memory acquisition tool, we rely on ARM TrustZone to achieve a hardware-assisted isolation with a small trusted computing base. TrustDump can include basic online analysis modules to catch malware in an early stage. Moreover, the acquired memory and register data can be sent to a remote server through a fast Micro-USB port for real-time forensics analysis when the OS runs or a slow serial port for further forensic analysis when the OS has crashed. A trusted graphical user interface is integrated in the TrustZone to authenticate the user and prevent the misuse of our memory acquisition tool. We build a TrustDump prototype on Freescale i.MX53 QSB. He Sun 0005, Kun Sun 0001, Yuewu Wang, Jiwu Jing |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2014 | A High-Throughput Unrolled ZUC Core for 100Gbps Data Transmission
Zongbin Liu, Ji Xiang, Jiwu Jing |
ACISP | 5 |
| 2014 | Once Root Always a Threat: Analyzing the Security Threats of Android Permission System
Zhongwen Zhang, Yuewu Wang, Jiwu Jing, Qiongxiao Wang, Lingguang Lei |
ACISP | 3 |
| 2014 | Remotely wiping sensitive data on stolen smartphonesabstractSmartphones are playing an increasingly important role in personal life and carrying massive private data. Unfortunately, once the smartphones are stolen, all the sensitive information, such as contacts, messages, photos, credit card information and passwords, may fall into the hands of malicious people. In order to protect the private data, remote deletion mechanism is required to allow owners to wipe the sensitive data on the stolen phone remotely. Existing remote deletion techniques rely on the availability of either WiFi for Internet connection or SIM card for cellular network connection; however, these requirements may not be satisfied when the phones are stolen by some sophisticated adversaries. In this paper, we propose a new remote deletion mechanism that allows the phone owner to delete the private data remotely even if the WiFi is disabled and the SIM card is unplugged. The basic idea is to use emergency call mechanisms to establish a communication connection with a service provider to verify the state of the phone and perform remote deletion. We present a case study of our mechanism with the Universal Mobile Telecommunications System (UMTS) network. Xingjie Yu, Kun Sun 0001, Wen Tao Zhu, Neng Gao, Jiwu Jing |
AsiaCCS | 6 |
| 2014 | Entropy Evaluation for Oscillator-Based True Random Number Generators
Jingqiang Lin 0001, Tianyu Chen 0016, Changwei Xu, Zongbin Liu, Jiwu Jing |
CHES | 6 |
| 2014 | TrustDump: Reliable Memory Acquisition on Smartphones
He Sun 0005, Kun Sun 0001, Yuewu Wang, Jiwu Jing, Sushil Jajodia |
ESORICS (1) | 4 |
| 2014 | RootkitDet: Practical End-to-End Defense against Kernel Rootkits in a Cloud Environment
Lingchen Zhang, Sachin Shetty, Peng Liu 0005, Jiwu Jing |
ESORICS (2) | 4 |
| 2014 | MobiHydra: Pragmatic and Multi-level Plausibly Deniable Encryption Storage for Mobile Devices
Xingjie Yu, Bing Chang, Wen Tao Zhu, Jiwu Jing |
ISC | 6 |
| 2014 | Exploiting the Floating-Point Computing Power of GPUs for RSA
Fangyu Zheng, Wuqiong Pan, Jingqiang Lin 0001, Jiwu Jing, Yuan Zhao 0015 |
ISC | 4 |
| 2014 | Copker: Computing with Private Keys without RAM
Le Guan, Jingqiang Lin 0001, Bo Luo, Jiwu Jing |
NDSS | 4 |
| 2014 | virtio-ct: A Secure Cryptographic Token Service in Hypervisors
Le Guan, Fengjun Li, Jiwu Jing, Ziqiang Ma |
SecureComm (2) | 3 |
| 2013 | Time evolving graphical password for securing mobile devicesabstractIncreasingly widespread use of mobile devices for processing monetary transactions and accessing business secrets has created a great demand on securing mobile devices. Poorly designed authentication mechanisms (e.g., screen lock and SIM card lock) on mobile devices either make users feel a hassle to lock the devices, or are vulnerable to attacks, such as shoulder surfing and smudge attack. Jiwu Jing, Liang Li 0003 |
AsiaCCS | 2 |
| 2013 | TerraCheck: Verification of Dedicated Cloud Storage
Kun Sun 0001, Sushil Jajodia, Jiwu Jing |
DBSec | 4 |
| 2013 | Fingerprint Embedding: A Proactive Strategy of Detecting Timing Channels
Peng Liu 0005, Le Guan, Jiwu Jing |
ICICS | 5 |
| 2013 | A High-Speed Elliptic Curve Cryptographic Processor for Generic Curves over \mathrm p
Zongbin Liu, Wuqiong Pan, Jiwu Jing |
Selected Areas in Cryptography | 4 |
| 2013 | Special issue on "security and privacy in pervasive and ubiquitous computing and communication systems"abstractSpecial issue on "security and privacy in pervasive and ubiquitous computing and communication systems"Pervasive computing and communications are emerging rapidly as an exciting new paradigm to provide data collection, computing, and communication services all the time and everywhere.As new pervasive and ubiquitous computing applications are launched, new security threats emerge, and new security and privacy measures are in urgent need before the corresponding cyber attacks make these new applications too risky to run or use.This special issue focuses on addressing the emerging security threats in pervasive and ubiquitous computing and communication systems.In particular, this special issue contains substantially extended versions of four outstanding papers selected from the program of the 4th International Conference on Security and Privacy in Communication Networks (SecureComm), which received 124 submissions.The review process is rigorous.Every submission is reviewed by at least three reviewers.Based on the review comments, most of the accepted papers have gone through two rounds of revision to achieve best quality.The richness of this special issue comes from the fact that the four papers address different emerging security threats.In particular, paper "DISA: Detection and Isolation of Sneaky Attackers in Locally-Monitored Multi-hop Wireless Networks" addresses an emerging threat in wireless networks, paper "Architecture and Performance Evaluation of a Hybrid Intrusion Detection System for IP Telephony" addresses the emerging threats in IP telephony networks, paper "Attacking the Kad Network -Real World Evaluation and High Fidelity Simulation using DVN" studies a new attack in peer-to-peer file sharing networks, paper "Agent-Based Modeling of Malware Dynamics in Heterogeneous Environments" presents an emulation framework for studying emerging malware, and paper "SMM Rootkits: A New Breed of OS Independent Malware" addresses a new rootkit threat.This special issue was successful, thanks to the efforts of a host of individuals who volunteered their time and energy in putting it together.We are thus grateful to all the reviewers for all their effort and patience in the paper evaluation.We are also grateful to Editor-in-Chief Prof. Peng Liu 0005, Refik Molva, Jiwu Jing |
Secur. Commun. Networks | 3 |
| 2013 | Impossibility of finding any third family of server protocols integrating Byzantine quorum systems with threshold signature schemesabstractABSTRACT To tolerate servers' Byzantine failures, a distributed storage service of self‐verifying data needs to make three security properties be Byzantine fault tolerant (BFT): data consistency, data availability, and confidentiality of the signing service's private key. Building such systems demands the integration of Byzantine quorum systems (BQSs), which only make data consistency and availability be BFT, and threshold signature schemes (TSSs), which only make confidentiality of the private key be BFT. Two families ofvalidTSS‐BQS systems (of which the server protocols carry all the design options) have been proposed in the literature. Motivated by the failures in finding a third family of valid server protocols, we study the reverse problem and formally prove that it isimpossibleto find any third family of valid TSS‐BQS systems. To obtain this proof, we develop avalidity theoryon server protocols of TSS‐BQS systems. It is shown that the only two families of valid server protocols, “predicted” (or deduced) by the validity theory, precisely match the existing protocols. Copyright © 2012 John Wiley & Sons, Ltd. Jingqiang Lin 0001, Peng Liu 0005, Jiwu Jing, Qiongxiao Wang |
Secur. Commun. Networks | 3 |
| 2012 | RIKE: Using Revocable Identities to Support Key Escrow in PKIs
Jingqiang Lin 0001, Jiwu Jing, Neng Gao |
ACNS | 3 |
| 2012 | Improving Virtualization Security by Splitting Hypervisor into Smaller Components
Wuqiong Pan, Meng Yu 0001, Jiwu Jing |
DBSec | 4 |
| 2012 | Disk storage isolation and verification in cloudabstractMulti-tenancy of the cloud maximizes the utility of computation and storage resources by multiplexing the underlying hardware infrastructure amongst cloud customers; however, it also introduces significant security issues such as information leakage between two virtual machines (VMs) even if certain access control policy (e.g., Chinese Wall security policy) has been deployed in the cloud. Physical resource isolation between VMs is an effective mechanism to remove the covert channels in the cloud and prevent information leakage; however, due to economic concerns or negligence, some cheap-and-lazy cloud providers are not motivated to enforce the physical resource isolation as they promised. In this paper, we first develop a mechanism to check the co-residency of two files on local hard disk(s) by measuring the file access time, and then extend our mechanism to check data storage co-residency on Amazon S3 cloud storage. Kun Sun 0001, Sushil Jajodia, Jiwu Jing |
GLOBECOM | 4 |
| 2012 | Hardware Performance Optimization and Evaluation of SM3 Hash Algorithm on FPGA
Luning Xia, Jingqiang Lin 0001, Jiwu Jing, Zongbin Liu, Xingjie Yu |
ICICS | 4 |
| 2012 | Towards Fine-Grained Access Control on Browser Extensions
Lei Wang 0135, Ji Xiang, Jiwu Jing, Lingchen Zhang |
ISPEC | 3 |
| 2012 | GRADE: Graceful Degradation in Byzantine Quorum SystemsabstractDistributed storage systems are expected to provide correct services in the presence of Byzantine failures, which do not have any assumptions about the behavior of faulty servers and clients. In designing such systems, we often encounter the paradox of fault tolerance vs. performance (or efficiency), because better fault tolerance usually requires a tradeoff of system performance. In this paper, we present GRADE, a Byzantine-fault-tolerant (BFT) distributed storage system that enables graceful degradation. Two Byzantine quorum systems (BQSs) are supported on each GRADE server: a masking BQS storing generic data and a dissemination BQS storing self-verifying ones. Based on the system status and the environment, servers dynamically and seamlessly switch between two BQSs, without converting the stored data. Therefore, GRADE provides high performance in a normal running-state, and degrades performance to maintain high fault tolerance in emergency situations. The computation and communication costs of the running-state switch are very low, and the switch is completely transparent to clients. Our performance analysis and experimental results demonstrate that GRADE provides a balance between performance and fault tolerance. Jingqiang Lin 0001, Bo Luo, Jiwu Jing |
SRDS | 3 |
| 2012 | A Scalable Anonymity Scheme Based on DHT Distributed InquiryabstractTwo key factors in the design of anonymity schemes are the scalability and the security of the relay node selection. In this paper, a scalable, secure anonymity scheme based on DHT inquiry mechanism is presented. Unlike the most existing schemes, every relay node's routing information (RRI) is stored as normal data in DHT overlay. The routing information can be inquired just with corresponding relay node's Relay ID (RID).All RID is maintained by SA to fill a dynamic range. So, user only needs to get the range of RID to select relay nodes, which is a datum with constant size. Such a mechanism significantly improve the scalability of scheme. Furthermore, RID assigned by SA also provides a more stable and provable relationship between relay nodes, which can be used to help validation of RRI storage. With this innovation, security measures are introduced. The framework of the scheme, key technical details and security analysis are described in this paper. In addition, simulation experiments are conducted to validate the effectiveness of this scheme. Yuewu Wang, Jiwu Jing, Zhongwen Zhang |
TrustCom | 3 |
| 2012 | Evaluating the Optimized Implementations of SNOW3G and ZUC on FPGAabstractSNOW 3G and ZUC are both the heart of secure algorithm sets in 3GPP LTE-Advanced, which is the potential candidate for 4G mobile broadband communication standard. In this paper, we optimize the implementation of the SNOW 3G and ZUC on FPGA, and also evaluate their performance. Our implementation of SNOW 3G reaches a little higher throughput than that of the best commercial IP core. Our optimized implementation of ZUC gives 40% performance improvement, compared with the best reported methods in terms of area-throughput ratio. Especially, compared with the ASIC implementation of ZUC in the most recent work in INDOCRYT 2011, the critical path of our architecture is 20% shorter than theirs. Our evaluation results show that both SNOW 3G and ZUC are flexible to balance different throughput with consumed area. Lingchen Zhang, Luning Xia, Zongbin Liu, Jiwu Jing |
TrustCom | 4 |
| 2012 | Privacy Preserving Social Network Publication on Bipartite Graphs
Jiwu Jing, Ji Xiang, Lei Wang 0135 |
WISTP | 2 |
| 2011 | An Efficient RSA Implementation without Precomputation
Wuqiong Pan, Jiwu Jing, Luning Xia, Zongbin Liu, Meng Yu 0001 |
Inscrypt | 2 |
| 2011 | Evaluating Optimized Implementations of Stream Cipher ZUC Algorithm on FPGA
Lei Wang 0135, Jiwu Jing, Zongbin Liu, Lingchen Zhang, Wuqiong Pan |
ICICS | 2 |
| 2011 | An Efficient Group-Based Secret Sharing Scheme
Chunli Lv, Xiaoqi Jia, Jingqiang Lin 0001, Jiwu Jing, Lijun Tian |
ISPEC | 4 |
| 2011 | A Tiny RSA Coprocessor based on Optimized Systolic Montgomery Architecture
Zongbin Liu, Luning Xia, Jiwu Jing, Peng Liu 0005 |
SECRYPT | 3 |
| 2011 | eHCBAC: Flexible Column Based Access Control for Electronic Healthcare SystemsabstractAn electronic healthcare (e-Health) system is a database system that collects patients' medical data from participating organizations such as hospitals, clinics and insurance companies, and facilitates services for these organizations. Though e-Health system transforms healthcare services with great savings in terms of efficiency and cost, it also triggers great privacy concerns as all patients' data are maintained in a centralized system which may be accessed and misused by unauthorized parties. One of the most important features of an e-Health system is that the sensitive data mainly distribute in certain columns. Thus, we propose a column based access control scheme for an e-Health database system (eHCBAC scheme), which protects the data by means of imposing access control policies on sensitive columns. Furthermore, we design algorithms to achieve eHCBAC for different SQL statements, and implement an prototype system by adding column based access control module into an open-source DBMS kernel. Experimental results demonstrate the effectiveness and efficiency of the prototype system. Ge Fu, Jiwu Jing |
TrustCom | 3 |
| 2011 | Launching Return-Oriented Programming Attacks against Randomized Relocatable ExecutablesabstractSince the day it was proposed, return-oriented programming has shown to be an effective and powerful attack technique against the write or execute only (W ⊕ X) protection. However, a general belief in the previous research is, systems deployed with address space randomization where the executables are also randomized at run-time are able to defend against return-oriented programming, as the addresses of all instructions are randomized. In this paper, we show that due to the weakness of current address space randomization technique, there are still ways of launching return-oriented programming attacks against those well-protected systems efficiently. We demonstrate and evaluate our attacks with existing typical web server applications and discuss possible methods of mitigating such threats. Jin Han 0002, Debin Gao, Jiwu Jing, Daren Zha |
TrustCom | 4 |
| 2011 | CLOUD SHREDDER: Removing the Laptop On-road Data Disclosure Threat in the Cloud Computing EraabstractData Disclosure due to laptop loss, especially in travel, is a top threat to businesses, governments, and non- profit organizations. An effective protection against this threat should guarantee the data confidentiality, even if the adversary has physically possessed the laptop. Current technology does not satisfy this requirement. This paper proposes a novel approach to remove the threat under the emerging condition of ubiquitous internet access and cloud computing. We name this approach "Cloud Shredder", implying that the confidential files are shredded and hidden in the semi-trusted cloud storage service. Cloud Shredder is a generic and transparent security service that allows legitimate user access the files in exactly the same way as with commodity file systems, whereas the attackers only get meaningless junk even if they have obtained every byte on the hard drive. Rather than the traditional encryption-based protection, Cloud Shredder limits the attacker's opportunity in a short time window. We implemented a prototype that is compatible with the typical cloud storage service, Amazon S3, and supports two popular document applications, Acrobat Reader and Open Office. Our experiments show that the influence on file access performance is reasonable and should not ruin the user experience. Cloud Shredder is also applicable to smart phone, netbook and other computing devices with internet connection. Nan Zhang 0018, Jiwu Jing, Peng Liu 0005 |
TrustCom | 2 |
| 2011 | PEDA: Comprehensive Damage Assessment for Production Environment Server SystemsabstractAnalyzing the intrusion to production servers is an onerous and error-prone work for system security technicians. Existing tools or techniques are quite limited. For instance, system events tracking lacks completeness of intrusion propagation, while dynamic taint tracking is not feasible to be deployed due to significant runtime overhead. Thus, we propose production environment damage assessment (PEDA), a systematic approach to do postmortem intrusion analysis for production workload servers. PEDA replays the “has-been-infected” execution with high fidelity on a separate analyzing instrumentation platform to conduct the heavy workload analysis. Though the replayed execution runs atop the instrumentation platform (i.e., binary-translation-based virtual machine), PEDA allows the first-run execution to run atop the hardware-assisted virtual machine to ensure minimum runtime overhead. Our evaluation demonstrates the efficiency of the PEDA system with a runtime overhead as low as 5%. The real-life intrusion studies show the advantage of PEDA intrusion analysis over existing techniques. Shengzhi Zhang, Xiaoqi Jia, Peng Liu 0005, Jiwu Jing |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2010 | Cross-layer comprehensive intrusion harm analysis for production workload server systemsabstractAnalyzing the (harm of) intrusion to enterprise servers is an onerous and error-prone work. Though dynamic taint tracking enables automatic fine-grained intrusion harm analysis for enterprise servers, the significant runtime overhead introduced is generally intolerable in the production workload environment. Thus, we propose PEDA (Production Environment Damage Analysis) system, which decouples the onerous analysis work from the online execution of the production servers. Once compromised, the "has-been-infected" execution is analyzed during high fidelity replay on a separate instrumentation platform. The replay is implemented based on the heterogeneous virtual machine migration. The servers' online execution runs atop fast hardware-assisted virtual machines (such as Xen for near native speed), while the infected execution is replayed atop binary instrumentation virtual machines (such as Qemu for the implementation of taint analysis). From identified intrusion symptoms, PEDA is capable of locating the fine-grained taint seed by integrating the backward system call dependency tracking and one-step-forward taint information flow auditing. Started with the fine-grained taint seed, PEDA applies dynamic taint analysis during the replayed execution. Evaluation demonstrates the efficiency of PEDA system with runtime overhead as low as 5%. The real-life intrusion studies successfully show the comprehensiveness and the precision of PEDA's intrusion harm analysis. Shengzhi Zhang, Xiaoqi Jia, Peng Liu 0005, Jiwu Jing |
ACSAC | 4 |
| 2010 | Proactive Identification and Prevention of Unexpected Future Rule Conflicts in Attribute Based Access Control
Daren Zha, Jiwu Jing, Peng Liu 0005, Jingqiang Lin 0001, Xiaoqi Jia |
ICCSA (4) | 2 |
| 2010 | Using Purpose Capturing Signatures to Defeat Computer Virus Mutating
Xiaoqi Jia, Jiwu Jing, Peng Liu 0005 |
ISPEC | 3 |
| 2010 | Rate-Based Watermark Traceback: A New Approach
Zongbin Liu, Jiwu Jing, Peng Liu 0005 |
ISPEC | 2 |
| 2010 | Mitigating the Malicious Trust Expansion in Social Network Service
Daren Zha, Jiwu Jing |
ISPEC | 2 |
| 2010 | Efficient Ideal Threshold Secret Sharing Schemes Based on EXCLUSIVE-OR OperationsabstractMost of secret sharing schemes have to be computed in a Galois field, such as Shamir's scheme, which have relatively heavy computational cost. Kurihara et al. recently proposed a fast secret sharing scheme using only Exclusive-OR(XOR) operations to make shares and recover the secret. Their proposed scheme was shown to be hundreds of times faster than Shamir's (in GF(q=264)) in terms of both distribution and recovery with a 4.5 MB secret when k=3 and n=11. However, some steps in their scheme still need to be improved. Their security proofs were too complex and difficult to be understood and verified intuitively. In this paper, we present a conciser, cleaner, faster scheme which is also based on XOR. Moreover, we give two geometric explanations of making shares in both our and Kurihara's schemes respectively, which would help to easier and further understand how the shares are made in the two schemes. Chunli Lv, Xiaoqi Jia, Lijun Tian, Jiwu Jing, Mingli Sun |
NSS | 4 |
| 2010 | Impossibility of Finding Any Third Family of Server Protocols Integrating Byzantine Quorum Systems with Threshold Signature Schemes
Jingqiang Lin 0001, Peng Liu 0005, Jiwu Jing, Qiongxiao Wang |
SecureComm | 3 |
| 2010 | PWC: a proactive worm containment solution for enterprise networksabstractAbstract We propose PWC, a proactive worm containment solution for enterprises. PWC can stop—instead of just slow down—an infected host from releasing worm scans as early as after merely four scans. Motivated by the observation that a worm uses a sustained outgoing packet rate, PWC gains infection awareness seconds before a signature or filter can be generated. To overcome denial‐of‐service possibly caused by such characteristic indicators of infection, PWC/,develops two new white detection (detecting who are uninfected) techniques: (a) the vulnerability time window lemma, and (b) the relaxation analysis. PWC does not rely on contents‐based signatures thus it can defend against polymorphic worms timely in containment. PWC is also resilient to containment evading. PWC is not sensitive to worm scan rate, and not protocol specific. Due to white detection, PWC causes minimal denial‐of‐service. Evaluation based on real traces and worm simulations demonstrates that PWC significantly outperforms Virus Throttle in terms of number of released worm scans, number of hosts infected by local scans, and denial‐of‐service effects. Copyright © 2009 John Wiley & Sons, Ltd. Yoon-chan Jhi, Peng Liu 0005, Lunquan Li, Qijun Gu, Jiwu Jing, George Kesidis |
Secur. Commun. Networks | 5 |
| 2009 | A Novel Contagion-Like Patch Dissemination Mechanism against Peer-to-Peer File-Sharing Worms
Xiaofeng Nie, Jiwu Jing, Yuewu Wang |
Inscrypt | 2 |
| 2008 | An Improved Method of Hybrid Worm SimulationabstractThe large-scaled worm infestation promotes the investigation of worm character. The current research of worm character can be classified into three categories: mathematical modeling of worm, emulation based on testbed, and package level worm simulation. However, in spite of the higher accuracy, the latter two methods require a high power of memory and computation, which poses a challenge to the large-scaled worm simulation. To solve this problem, a hybrid model of simulation was proposed with a selective abstraction. The hybrid worm simulation is a combination of mathematics analysis and package level simulation, achieving a better compromise between accuracy and efficiency. However, existing hybrid simulation framework still has some limitations, because the mathematic model of it can not consider the effect of defense and network congestion very well. In order to improve the accuracy of hybrid worm simulation, the current study proposes a novel method based on a two-factor model and provides experimental evidence of the higher accuracy of simulation by using the new method. Jiwu Jing, Yuewu Wang |
WAIM | 2 |
| 2007 | Framework for Intrusion Tolerant Certification Authority System EvaluationabstractVarious intrusion tolerant certification authority (CA) systems have been recently proposed to provide attack resistant certificate update/query services. However, it is difficult to compare them against each other directly due to diversity in system organizations, threshold cryptography schemes, protocols and usage scenarios. We present a framework for intrusion tolerant CA system evaluation, which consists of three components, namely, an intrusion tolerant CA model, a threat model and a metric for comparative evaluation. The framework covers system organizations, protocols, usage scenarios, period of certificate validity, revocation rate and mean time to recovery (MTTR). Based on the framework, four representative CA systems are evaluated and compared in three typical usage scenarios, producing reasonable and insightful results. The inter-dependency between usage scenarios and system characteristics is investigated, providing a guideline to design better systems for different usage scenarios. The proposed framework provides an effective method to evaluate intrusion tolerant CA systems quantitatively. Moreover, the comparison results offer valuable insights to further improve the attack resilience of intrusion tolerant CA systems. Jingqiang Lin 0001, Jiwu Jing, Peng Liu 0005 |
SRDS | 2 |
| 2004 | The Design and Implementation of a Self-Healing Database System
Peng Liu 0005, Jiwu Jing, Pramote Luenam, Lunquan Li, Supawadee Ingsriswang |
J. Intell. Inf. Syst. | 2 |