Jie Chen 0093

dblp:92/6289-93 · DBLP profile ↗
← Back
5ranked-venue papers
3as first author
5since 2021 · last 2026
0000-0003-4887-4244ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 4 · 3 first-author · 4 since 2021Computer networks · 1 · 1 since 2021
YearPublicationVenuePosition
2026 DAAPS: Distributed anonymous access control for pervasive edge computing services
Jie Chen 0093, Wenhao Li 0005, Shuai Wang 0079, Huamin Jin, Changsong Jiang
Comput. Secur.1
2026 HACEC: Efficient and Auditable Anonymous Access Control for Edge Computing Services
abstract
In recent years, edge computing has undergone significant growth, but ensuring anonymity, efficiency, and auditability in service utilization remains challenging. This paper proposes HACEC, an efficient and auditable anonymous access control scheme for edge computing. HACEC utilizes a dual-token mechanism to achieve anonymity and efficient service utilization. It allows users to access services using temporary identities, without exposing their real identities. We integrate the Trusted Execution Environment (TEE) and threshold cryptography into this mechanism to prevent several attacks. This mechanism not only protects users' identity privacy but also avoids reliance on an always-online cloud, thereby addressing the issue of a single point of failure. Additionally, HACEC proposes an auditable Multi-Authority Attribute-Based Encryption (MABE) scheme and a hierarchical audit mechanism to achieve efficiency and security in audit. The system separates the audit process into data audit and identity tracing. Data audit would not expose users' identities and is performed efficiently through the MABE scheme. Once malicious behaviors are detected, identity tracing can be performed in a threshold manner to retrieve the identities. As a result, HACEC achieves a trade-off between efficiency, security, and auditability. We provide a comprehensive security analysis and performance evaluation to demonstrate the security and efficiency of HACEC.
Jie Chen 0093, Shuai Wang 0079, Huamin Jin
IEEE Trans. Dependable Secur. Comput.1
2026 Online Traffic Camouflage Against Network Analyzers via Deep Reinforcement Learning
abstract
Traffic analysis plays a pivotal role in network management. However, despite the prevalence of encryption, attackers are still able to deduce privacy elements such as user behavior and OS identification through advanced learning-based methods that exploit side-channel features. Existing defense strategies, which manipulate feature distribution to evade traffic analyzers, are often hampered by the need for impractical decoder deployment across all routes in symmetric framework methods. Moreover, reversing feature distribution modifications to real-time traffic, especially through dummy packet crafting or padding, is a complex task. In response to these challenges, we propose Veil, a novel and practical defender designed to protect live connections against encrypted network traffic analyzers. Leveraging an asymmetric deployment structure, Veil is capable of reconstructing live streams at the packet-block level, thereby allowing for seamless deployment on any connection node while enforcing transmission constraints. By employing a traffic-customized DQN framework, Veil not only reverses statistical feature perturbations back to the traffic space but also directs the distribution towards a target class. Extensive experiments conducted on real-world datasets validate the efficacy of Veil in efficiently evading analyzers in both targeted and untargeted modes, outperforming existing defense mechanisms. Notably, Veil addresses the key issues of impractical decoder deployment and complex real-time traffic manipulation, offering a more viable solution for network traffic privacy protection. The source code is publicly available at https://github.com/SecTeamPolaris/Veil, facilitating further research and application in the field of network security.
Wenhao Li 0005, Jie Chen 0093, Zhaoxuan Li, Shuai Wang 0079, Huamin Jin, Xiaoyu Zhang 0002
IEEE Trans. Netw. Serv. Manag.2
2025 Device-Enhanced Password-Based Threshold Single-Sign-On Authentication
abstract
Password-based threshold single-sign-on authentication (PbTA) allows multiple identity servers to in a threshold manner authenticate a user and issue a token, with which the user accesses relevant services. We analyze existing PbTA schemes and reveal a potential threat: vulnerability against perpetual credential leakage, in which “perpetual” adversaries could perpetually attempt to compromise long-lived credential databases maintained by identity servers. Compromising a threshold number of credential databases enables the adversaries to launch offline dictionary guessing attacks (DGA) or illegally obtain users’ tokens. To address these issues, we first propose a basic device-enhanced PbTA scheme (DE-PbTA), where an auxiliary device collaborates with identity servers in hardening a user’s password during authentication, such that perpetual adversaries cannot learn the password from compromised credentials via offline DGA. Using the hardened password, a private key can be derived to decrypt ciphertexts from identity servers for token construction, which protects the user’s tokens against perpetual adversaries. Then, we extend basic DE-PbTA to support dynamic usage of multiple devices, where a user can actively choose$t^{\prime } $devices out of$n^{\prime } $for authentication. Provable security and high efficiency of the basic/enhanced DE-PbTA scheme are demonstrated by comprehensive analysis and experimental evaluations.
Changsong Jiang, Chunxiang Xu, Guomin Yang, Zhao Zhang 0026, Jie Chen 0093
IEEE Trans. Inf. Forensics Secur.5
2023 A secure recharge scheme for blockchain payment channels
abstract
The payment channel is a prominent solution to scale the throughput of decentralized blockchain ledgers. It reduces the load on-chain by enabling off-chain micropayments without exhausting blockchain resources. However, the balance of a channel could become depleted due to payments going in one direction, making subsequent payments in that direction impossible. Several solutions have been proposed in recent years to address this issue. Nevertheless, ensuring both privacy and efficiency while maintaining applicability to edge nodes remains a challenging task. In this paper, we present PCRECHARGE, a solution to revive a depleted payment channel. Its key idea is to recharge the channel by conducting an on-chain payment and a reverse off-chain payment. The main challenge of this solution is to ensure that both payments must be performed atomically. To address this challenge, we conceive a pay-or-refund mechanism and integrate it into PCRECHARGE. It introduces another two transactions pay and refund , enabling an honest party to publish one of them to get his coins back. The most prominent feature of this mechanism lies in its independence from specific scripting and its avoidance of costly cryptographic tools, making it suitable for wide deployment. We provide comprehensive analyses and experimental evaluations to demonstrate the security and high efficiency of PCRECHARGE. Compared to reconstructing a channel, our approach reduces the transaction size by 66% in the honest case and addresses the limitations of current solutions, particularly their poor application to edge nodes.
Jie Chen 0093, Shuai Wang 0079, Huamin Jin
J. Inf. Secur. Appl.1