Yifei Chen 0005

dblp:75/5017-5 · DBLP profile ↗
← Back
10ranked-venue papers
1as first author
8since 2021 · last 2025
0000-0002-5256-3249ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 10 · 1 first-author · 8 since 2021
YearPublicationVenuePosition
2025 Artemis: Decentralized, Secure, and Efficient Safety Monitoring with Dynamic Trajectories
Meng Li 0006, Zhuangwei Li, Yifei Chen 0005, Yan Qiao 0001, Mauro Conti
ICICS (1)3
2025 Accurate, Secure, and Efficient Semi-Constrained Navigation Over Encrypted City Maps
abstract
Navigation services enable users to find the shortest path from a starting point$S$to a destination$D$, reducing time, gas, and traffic congestion. Still, navigation users risk the exposure of their sensitive location data. Our motivation arises from how users can accurately, securely, and efficiently navigate from$S$to$D$while passing through$k$unordered stops, i.e., midway locations with a non-fixed visiting order. In this work, we formally define Semi-Constrained Navigation (SCN) and present a novel scheme Hermes to achieve accurate, secure, and efficient SCN. Specifically, we propose a divide-and-conquer approach to strike a good balance between accuracy and efficiency. It recursively depth-first-searches the whole area (a navigation tree) and invokes five carefully-crafted strategies stop-by-stop to compute three subpaths in three sequential subareas. We construct a path-distance oracle to encrypt the road graph and securely implement the strategies by using homomorphic encryption and garble circuits. We formally prove the security in the random oracle model and analyze the search complexity to be less than$O(k^{2})$. We experiment over a real-world city map and compare with six baselines. Results show that path search with$k=4$among$N=1000$intersections requires 5.58 seconds with a 3.2% distance deviation rate and an 82.5% path similarity.
Meng Li 0006, Yifei Chen 0005, Jingyu Wu, Zijian Zhang 0001, Jialing He, Liehuang Zhu, Mauro Conti, Xiaodong Lin 0001
IEEE Trans. Dependable Secur. Comput.2
2025 Trust in a Decentralized World: Data Governance From Faithful, Private, Verifiable, and Traceable Data Feeds
abstract
Blockchain technology autonomously executes smart contracts that require external data to facilitate specific applications, underscoring the necessity for Authenticated Data Feeds (ADF). Existing solutions fall short in providing genuine authentication of data, lack private and verifiable computations across multiple data sources, and overlook data traceability, rendering current systems inadequate for complex applications. We present WuKong (WK), a data governance system that offers authenticated, privately verifiable, and traceable data feeds. WK enables a server to collect faithful data through an oracle committee and to prove computation correctness in zero-knowledge proofs, and empowers legal entities to trace a leakage source conditionally. We formally define and prove the security of WK in the universal composability framework. We implement three applications that seamlessly integrate with WK. Experimental results indicate that WK effectively liberates sensitive data from distributed, untrusted, and anonymous providers, making it accessible to various services and establishing trust in a decentralized world.
Meng Li 0006, Yifei Chen 0005, Yan Qiao 0001, Guixin Ye, Zijian Zhang 0001, Liehuang Zhu, Mauro Conti
IEEE Trans. Inf. Forensics Secur.2
2025 Threshold Signatures With Verifiably Timed Combining and Message-Dependent Tracing
Meng Li 0006, Hanni Ding, Yifei Chen 0005, Yan Qiao 0001, Zijian Zhang 0001, Liehuang Zhu, Mauro Conti
IEEE Trans. Inf. Forensics Secur.3
2023 Eunomia: Anonymous and Secure Vehicular Digital Forensics Based on Blockchain
abstract
Vehicular Digital Forensics (VDF) is essential to enable liability cognizance of accidents and fight against crimes. Ensuring the authority to timely gather, analyze, and trace data promotes vehicular investigations. However, adversaries crave the identity of the data provider/user, damage the evidence, violate evidence jurisdiction, and leak evidence. Therefore, protecting privacy and evidence accountability while guaranteeing access control and traceability in VDF is no easy task. To address the above-mentioned issues, we propose Eunomia: an anonymous and secure VDF scheme based on blockchain. It preserves privacy with decentralized anonymous credentials without trusted third parties. Vehicular data and evidence are uploaded by data providers to the blockchain and stored in distributed data storage. Each investigation is modeled as a finite state machine with state transitions being executed by smart contracts. Eunomia achieves fine-grained evidence access control via ciphertext-policy attribute-based encryption and Bulletproofs. A user must hold specific attributes and a temporary-and-unexpired token/warrant to retrieve data from the blockchain. Finally, a secret key is embedded into data to trace the traitor if any evidence breach happens. We use a formal analysis to demonstrate the strong privacy and security properties of Eunomia. Moreover, we build a prototype in a WiFi-based Ethereum test network to evaluate its performance.
Meng Li 0006, Yifei Chen 0005, Chhagan Lal, Mauro Conti, Mamoun Alazab, Donghui Hu
IEEE Trans. Dependable Secur. Comput.2
2023 Nereus: Anonymous and Secure Ride-Hailing Service Based on Private Smart Contracts
abstract
Security and privacy issues have become a major hindrance to the broad adoption of Ride-Hailing Services (RHSs). In this article, we introduce a new collusion attack initiated by the Ride-Hailing Service Provider (RHSP) and a driver that could easily link the real riders and their anonymous requests (credentials). Besides this attack, existing work requires heavy computations to execute user matching, and it is challenging for riders to verify matching results. Meanwhile, a malicious driver may cancel an assigned ride order due to its short distance. To address these issues, we present a RHS system named Nereus to support collusion resistance, efficiency, verifiability, and accountability. First, we integrate a smart contract into a Software Guard Extensions (SGX) enclave to establish aprivate smart contractfor collusion resistance. We use a Bloom filter to achieve efficient matching. Second, we leverage privacy-preserving range query and Merkle proofs to make matching results verifiable. Meanwhile, we adopt short group signatures to provide anonymous authentication and deposit commitments to hold the runaway driver accountable. We formally state and prove the security and privacy of Nereus. We build a prototype based on Ethereum and SGX to conduct extensive performance analysis in regard to gas costs, computational costs, and communication overhead. Experimental results show that Nereus significantly improves over existing schemes in terms of computational costs.
Meng Li 0006, Yifei Chen 0005, Chhagan Lal, Mauro Conti, Fabio Martinelli, Mamoun Alazab
IEEE Trans. Dependable Secur. Comput.2
2023 Astraea: Anonymous and Secure Auditing Based on Private Smart Contracts for Donation Systems
abstract
Many regions are in urgent need of facial masks for slowing down the spread of COVID-19. To fight the pandemic, people are contributing masks through donation systems. Most existing systems are built on a centralized architecture which is prone to the single point of failure and lack of transparency. Blockchain-based solutions neglect fundamental privacy concerns (donation privacy) and security attacks (collusion attack, stealing attack). Moreover, current auditing solutions are not designed to achieve donation privacy, thus not appropriate in our context. In this work, we design a decentralized, anonymous, and secure auditing frameworkAstraeabased on private smart contracts for donation systems. Specifically, we integrate a Distribute Smart Contract (DiSC) with an SGX Enclave to distribute donations, prove the integrity of donation number (intention) and donation sum while preserving donation privacy. With DiSC, we design a Donation Smart Contract to refund deposits and defend against the stealing attack the collusion attack from malicious collector and transponder. We formally define and prove the privacy and security of Astraea by using security reduction. We build a prototype of Astraea to conduct extensive performance analysis. Experimental results demonstrate that Astraea is practically efficient in terms of both computation and communication.
Meng Li 0006, Yifei Chen 0005, Liehuang Zhu, Zijian Zhang 0001, Jianbing Ni, Chhagan Lal, Mauro Conti
IEEE Trans. Dependable Secur. Comput.2
2022 Privacy-Preserving Navigation Supporting Similar Queries in Vehicular Networks
abstract
Traffic-sensitive navigation systems in vehicular networks help drivers avoid traffic jams by providing several realtime navigation routes. However, drivers still encounter privacy concerns because their sensitive locations, i.e., their start point and endpoint, are submitted to an honest-but-curious navigation service provider (NSP). Previous privacy-preserving studies exhibit serious deficiencies under similar queries: if a driver makes several similar queries, i.e., periodically makes requests for the same start point and endpoint to the NSP, these requests will eventually reveal the areas of the two points as well as the route. In this paper, we present a novel privacy-preserving navigation scheme PiSim, which supports similar queries in navigation services. Intuitively, we transform the typical navigation approach into a traffic congestion querying approach. Instead of sending two locations to the NSP and awaiting a navigation route, drivers query the traffic congestion along the navigation route. Specifically, PiSim is characterized by extending anonymous authentication, facilitating privacy-preserving multi-keyword fuzzy search, and constructing weighted proximity graphs. Our scheme protects location privacy and route privacy, and defends against multiple requesting, spurious reporting, and collusion attacks from malicious drivers. Finally, a detailed analysis confirms the privacy and security properties of PiSim. Extensive experiments are conducted to demonstrate the feasibility, performance, and privacy protection level.
Meng Li 0006, Yifei Chen 0005, Shuli Zheng, Donghui Hu, Chhagan Lal, Mauro Conti
IEEE Trans. Dependable Secur. Comput.2
2020 One-Time, Oblivious, and Unlinkable Query Processing Over Encrypted Data on Cloud
Yifei Chen 0005, Meng Li 0006, Shuli Zheng, Donghui Hu, Chhagan Lal, Mauro Conti
ICICS1
2020 Privacy-Preserving Ride-Hailing with Verifiable Order-Linking in Vehicular Networks
abstract
Ride-hailing is a favored vehicular service model where drivers can deliver convenient rides to waiting riders via responding to a road-side unit or a ride-hailing service provider. However, previous works did not consider the order-linking function where a rider Cathy waving for a ride will be matched to a driver Bob in service with rider Alice whose destination is close to the start point of Cathy. Furthermore, a malicious matching executor could collude with an appointed driver to interfere with the matching process, which causes service unfairness and has not been addressed before. To mitigate these limitations, we first propose a privacy-preserving ride-hailing scheme OLink with the verifiable order-linking property. Specifically, we adopt road network partitioning and range query to achieve basic user matching. The user matching process supports range conditions and protects users' privacy. Next, a Proof-of-Linking protocol is designed based on the zero-knowledge succinct non-interactive argument of knowledge, zero-knowledge proof, and Bloom filters to enable the driver in service to generate three consecutive proofs for linking a current order to the next rider's order in advance; the proofs will be released such that anyone can verify the proofs and matching fairness is guaranteed. Finally, we formally prove the privacy and security of OLink, and then evaluate its performance with PySNARK to demonstrate feasibility and efficiency.
Meng Li 0006, Yifei Chen 0005, Jingcheng Zhao, Mamoun Alazab
TrustCom3