Xiaozhuo Gu

dblp:91/2533 · DBLP profile ↗
← Back
21ranked-venue papers
5as first author
4since 2021 · last 2025
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 10 · 2 first-author · 3 since 2021Systems, architecture and hardware · 5 · 1 first-authorComputer networks · 3 · 1 first-authorArtificial intelligence and machine learning · 1Software engineering, systems software and programming languages · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2025 Speedy Error Reconciliation
Kaibo Liu, Xiaozhuo Gu, Peixin Ren, Xuwen Nie, Yunlv Lv
Inscrypt (1)2
2023 JWTKey: Automatic Cryptographic Vulnerability Detection in JWT Applications
Shijie Jia 0001, Jingqiang Lin 0001, Fangyu Zheng, Xiaozhuo Gu
ESORICS (3)7
2023 Efficient module learning with errors-based post-quantum password-authenticated key exchange
abstract
Abstract Password‐authenticated key exchange ( PAKE ) is a cryptographic primitive that can establish secure remote communications between the client and the server, especially with the advantage of amplifying memorable passwords into strong session keys. However, the arrival of the quantum computing era has brought new challenges to traditional PAKE protocols. Thus, designing an efficient post‐quantum PAKE scheme becomes an open research question. In this paper, the authors construct a quantum‐safe PAKE protocol, which is a horizontal extension of the password‐authenticated key (PAK) protocol in the field of module lattices. Subsequently, the authors accompany the proposed protocol with a rigorous security proof in the random oracle model with two adaptions: applying the CDF‐Zipf model to characterise the ability of the adversary and using the pairing with errors assumption to simplify the proof. Taking the flexibility of the module learning with errors ( MLWE ) problem, the authors elaborately select three parameter sets to meet different application scenarios. Specifically, the authors’ Recommended‐PAKE implementation achieves 177‐bit post‐quantum security with a generous margin to cope with later improvement in cryptanalysis. The performance results indicate that the authors’ MLWE‐PAKE is quite practical: compared with the latest Yang‐PAK , the authors’ Recommended‐PAK reduces the communication cost and the running time by 36.8% and 13.8%, respectively.
Peixin Ren, Xiaozhuo Gu
IET Inf. Secur.2
2021 A Certificateless Searchable Public Key Encryption Scheme for Multiple Receivers
abstract
Security, efficiency and availability are three key factors that affect the application of searchable encryption schemes in mobile cloud computing environments. In order to meet the above characteristics, this paper proposes a certificateless public key encryption with a keyword search (CLPEKS) scheme. In this scheme, a CLPEKS generation method and a Trapdoor generation method are designed to support multiple receivers to query. Based on the elliptic curve scalar multiplication, the efficiencies of encrypting keywords, generating Trapdoors, and testing are improved. By adding a random number factor to the Trapdoor generation, the scheme can resist the internal keyword guessing attacks. Under the random oracle model, it is proved that the scheme can resist keyword guessing attacks. Theoretical analyses and implementation show that the proposed scheme is more efficient than the existing schemes.
Xiaozhuo Gu, Maomao Fu, Peixin Ren
ICWS1
2020 Saber on ESP32
Xiaozhuo Gu, Yingshan Yang
ACNS (1)2
2020 A Supervised Anonymous Issuance Scheme of Central Bank Digital Currency Based on Blockchain
Wenhao Dai, Xiaozhuo Gu, Yajun Teng
ICA3PP (3)2
2020 PIV4DB: Probabilistic Integrity Verification for Cloud Database
abstract
Many organizations and enterprises use cloud databases to store data to improve management efficiency and save costs. However, cloud service providers may hide the fact that data integrity has been compromised for protecting their business reputation. Thus, how to verify the data integrity of cloud database in an effective way is very important for data owner. Existing integrity verification methods usually require cloud service provider to develop additional interfaces which are hard to be actually deployed. In addition, they cannot effectively detect tampering and deletion of a small amount of data. This paper presents a novel probabilistic integrity verification scheme (called PIV4DB) to address above challenges. Different from traditional methods, PIV4DB efficiently verifies the data integrity of cloud database by randomly selecting part of groups of tuples instead of querying all the tuples. Experimental results demonstrated that with validating 0.5% among 100k groups, PIV4DB could detect the corruption with 99% probability when the integrity of 920 out of billions of tuples are compromised. In addition, PIV4DB does not need extra cooperation with cloud service provider by just adding a new column of random numbers to the database and only using standard SQL statements to verify integrity.
Pingjian Wang, Xiaozhuo Gu, Yuewu Wang, Jingqiang Lin 0001
ISCC3
2019 Efficient Password-Authenticated Key Exchange from RLWE Based on Asymmetric Key Consensus
Yingshan Yang, Xiaozhuo Gu, Taizhong Xu
Inscrypt2
2019 Secure Multi-receiver Communications: Models, Proofs, and Implementation
Maomao Fu, Xiaozhuo Gu, Wenhao Dai, Jingqiang Lin 0001
ICA3PP (1)2
2017 Splitting Third-Party Libraries' Privileges from Android Apps
Jiawei Zhan, Xiaozhuo Gu, Yuewu Wang, Yingjiao Niu
ACISP (2)3
2017 Enforcing ACL Access Control on Android Platform
Xiaohai Cai, Xiaozhuo Gu, Yuewu Wang, Zhenhuan Cao
ISC2
2016 A Practical Scheme for Data Secure Transport in VoIP Conferencing
Dali Zhu, Renjun Zhang, Xiaozhuo Gu
ICICS3
2016 Combining Statistics-Based and CNN-Based Information for Sentence Classification
abstract
Sentence classification, serving as the foundation of the subsequent text-based processing, continues attracting researchers attentions. Recently, with the great success of deep learning, convolutional neural network (CNN), a kind of common architecture of deep learning, has been widely used to this filed and achieved excellent performance. However, most CNN-based studies focus on using complex architectures to extract more effective category information, requiring more time in training models. With the aim to get better performance with less time cost on classification, this paper proposes two simple and effective methods by fully combining information both extracted from statistics and CNN. The first method is S-SFCNN, which combines statistical features and CNN-based probabilistic features of classification to build feature vectors, and then the vectors are used to train the logistic regression classifiers. And the second method is C-SFCNN, which combines CNN-based features and statistics-based probabilistic features of classification to build feature vectors. In the two methods, the Naive Bayes log-count ratios are selected as the text statistical features and the single-layer and single channel CNN is used as our CNN architecture. The testing results executed on 7 tasks show that our methods can achieve better performance than many other complex CNN models with less time cost. In addition, we summarized the main factors influencing the performance of our methods though experiment.
Zhining Lang, Xiaozhuo Gu, Taizhong Xu
ICTAI2
2009 Huffman-based join-exit-tree scheme for contributory key management
Xiaozhuo Gu, Jianzu Yang, Julong Lan, Zhenhuan Cao
Comput. Secur.1
2008 An Efficient Conference Key Updating Scheme with the Knowledge of Group Dynamics
abstract
Conference key management requires relatively heavy-weight modular exponentiation operations and additional communications among group members. So time efficiency of key update for conference key management is the key problem many literatures strived to address. In this paper, we propose a Huffman-based join-exit-tree (HJET) key agreement to achieve better time efficiency in key update. Compared with JET scheme of Mao et al., HJET has two major improvements. First, the join algorithm inserting the new node into the root of the join tree makes the join cost minimal and constant. Second, Huffman coding is used to form the exit tree with the information of users' withdrawal probabilities, and therefore has optimal average leave cost. Performance analysis and simulation results demonstrate that HJET is efficient in key update and achieves the asymptotic time cost of O(1) for join event and nearly O(1) for leave events.
Xiaozhuo Gu, Jianzu Yang, Xiangjie Ma, Julong Lan
GLOBECOM1
2008 Join-Tree-Based Contributory Group Key Management
abstract
With emergence of group-oriented applications needing content confidentiality, secure group communications have drawn more attention. To provide this service in large groups with highly dynamic memberships, a secure group key management efficient in key establishment and update is the foundation. In this paper, we present a join-tree-based contributory group key management (JDH) to achieve better time efficiency, and propose using the notion "sequential exponentiations" as the evaluation metric for time efficiency. First, a new key tree topology comprised of main tree and join tree is put forward, with the join tree locating close to the root of the key tree and serving as the temporary buffer for sequential joining users. Then, a new join algorithm in the join tree is presented to reduce the time complexity. Last, optimal capacity of the join tree is selected through an optimization method. Theoretical analysis shows that the asymptotic average join time is sharply reduced to from previous, where is the group size. Our analytical comparison with existing managements and experiments demonstrate that JDH is time and communication efficient in group key establishment and update.
Xiaozhuo Gu, Jianzu Yang, Julong Lan
HPCC1
2008 Performance Study on the MPMS Fabric: A Novel Parallel and Distributed Switching System Architecture
abstract
As Internet grows exponentially, scalable routers on backbone are required to provide more number of ports, higher line-rates, and larger capacity under acceptable complexity. Until now, most routers are implemented on the centralized single crossbar as the switched backplane fabric. In terms of crosspoint number, however, the complexity of a single Crossbar is unacceptable with large number of ports, which is increased with O(N2). Distributed multiple-stage Clos network and Parallel Packet Switching fabric were proposed to provide large number of ports and high line-card rate, respectively. To obtain both goals simultaneously, we study a novel multiple-plane and multiple-stage (MPMS) switching fabric in this paper. We first bring out a graphic model for the MPMS fabric based on its topological architecture. Then we study the internal connectivity of the MPMS fabric through the concepts of vertex in-degree, vertex out-degree and vertex mux degree. Lastly, we analyze the performance of the MPMS fabric including its maximum number of ports, line-rate, switching capacity and complexity of crosspoints by comparison to that of the single-stage crossbar fabric.
Xiangjie Ma, Xiaozhuo Gu, Lei He 0008, Julong Lan, Baisheng Zhang
HPCC2
2008 Study on a Novel Scheduling Algorithm ofthe Multiple-Plane and Multiple-Stage Switching Fabric
abstract
The multiple-plane and multiple-stage (MPMS) switching fabrics are the next step in scaling current crossbar fabrics to many hundreds or few thousands of ports. However, scheduling cells in the MPMS fabric is complex. With the recent blooming of bandwidth sensitive Internet traffic, scheduling cells with guaranteed bandwidth is becoming an urgent demand. The CRRD algorithm delivers high throughput under uniform traffic pattern, but it does not work well under nonuniform traffic and does not provide any bandwidth guarantees. In this paper, we analyze the graphic model of the MPMS fabric, and propose a novel bandwidth-guaranteed scheduling algorithm based on CRRD. Simulation results show that it delivers 100% throughput under uniform traffic, and achieves much higher throughput than that of CRRD under nonuniform traffic, and keeps its implementation complexity low without internal expansion and allocates the output-link bandwidth fairly for the reserved flows in the overloaded case.
Xiangjie Ma, Lei He 0008, Xiaozhuo Gu, Julong Lan, Baisheng Zhang
HPCC3
2008 Compensation Buffer Sizing for Providing User-Level QoS Guarantee of Media Flows
abstract
When transferred in a packet-switched network, the temporal structure of continuous media may be damaged by delay and delay jitter. Compensation buffering is a well-known method to absorb the delay jitter. However, added buffering increases the latency, which may degrade the interactivity between users. As delay and delay jitter are both perceived QoS parameters to users, changing compensation buffer size may result in completely opposite effect on user-level QoS. How to set the buffer size to provide both delay and delay jitter guarantee with preferable user-level QoS? To answer the question, we investigate the effect of buffer size on maintaining the temporal structure of media flows. By performing QoS mapping from network-level to user-level, we prove that there is an optimal buffer size to provide the optimal user-level QoS and obtain the optimal buffer size by differentiating approach. Experiment results validate our studies on the effect of the buffer size.
Han Qiu 0004, Yufeng Li 0002, Xiaozhuo Gu
ICC4
2007 Design and Buffer Sizing of TCAM-Based Pipelined Forwarding Engines
abstract
The ever increasing line speed and the continuous growing demands of various functions support(for example QoS, multicast and security) have interact- tively made it harder for forwarding engines to process packets at line speed, and this will increasingly make the forwarding engines call for additional buffers to accommodate the burst transmission and decrease the packet loss rate. In this paper, a high-speed pipeline designed for TCAM-based forwarding engines is presented, and its buffer analysis model is also given, then, the buffer requirement of the forwarding engine is analyzed under two conditions: the forwarding rate is not less than and less than the input rate. Our analysis results and experiments both show that, the proposed forwarding pipeline is of high performance, and just one pipeline can easily deal with the data transfer rate of 30 Gb/s or even higher; the pipelined forwarding engine only need to buffer a several packets, then the loss rate will be an acceptable value or even zero, further increasing the buffer size will have little effect on reducing the loss rate.
Yufeng Li 0002, Han Qiu 0004, Xiaozhuo Gu, Julong Lan, Jianwen Yang
AINA3
2006 Hardware-and-Software-Based Security Architecture for Broadband Router (Short Paper)
Xiaozhuo Gu, Jianzu Yang, Julong Lan
ICICS1