Demonstration venue · read-only. Every page can be browsed; the buttons that would change it are switched off. Create an account to run TaxoReview on your own data.

Jia Xu 0006

dblp:95/3616-6 · DBLP profile ↗
← Back
18ranked-venue papers
6as first author
4since 2021 · last 2022
0000-0001-7887-5913ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 12 · 6 first-author · 1 since 2021Computer networks · 3 · 1 since 2021Systems, architecture and hardware · 2 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 1

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Network and information security
3 papers
Cryptographic primitives and cryptanalysis · 51% Privacy and data protection · 38% Hardware security and side channels · 11%
Computer architecture, parallel and distributed computing, and storage systems
2 papers
GPUs and heterogeneous computing · 46% Parallel and multicore computing · 46% Cloud and datacenter computing · 9%

Topics — the 10 heaviest of 11, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Cryptographic primitives and cryptanalysis › post-quantum cryptography
key encapsulation mechanism
0.612022
cuNH: Efficient GPU Implementations of Post-Quantum KEM NewHope · IEEE Trans. Parallel Distributed Syst. 2022
Cryptographic primitives and cryptanalysis
post-quantum cryptography
0.612022
cuNH: Efficient GPU Implementations of Post-Quantum KEM NewHope · IEEE Trans. Parallel Distributed Syst. 2022
GPUs and heterogeneous computing
GPU computing
0.612022
cuNH: Efficient GPU Implementations of Post-Quantum KEM NewHope · IEEE Trans. Parallel Distributed Syst. 2022
Parallel and multicore computing › data parallelism
SIMD vectorization
0.612022
cuNH: Efficient GPU Implementations of Post-Quantum KEM NewHope · IEEE Trans. Parallel Distributed Syst. 2022
Privacy and data protection
privacy-preserving data sharing
0.412020
PrivateLink: Privacy-Preserving Integration and Sharing of Datasets · IEEE Trans. Inf. Forensics Secur. 2020
Hardware security and side channels
leakage analysis
0.412019
Passive Attacks Against Searchable Encryption · IEEE Trans. Inf. Forensics Secur. 2019
Privacy and data protection
query privacy
0.412019
Passive Attacks Against Searchable Encryption · IEEE Trans. Inf. Forensics Secur. 2019
Cryptographic primitives and cryptanalysis
searchable encryption
0.412019
Passive Attacks Against Searchable Encryption · IEEE Trans. Inf. Forensics Secur. 2019
Cryptographic primitives and cryptanalysis › post-quantum cryptography
lattice-based cryptography
0.212022
cuNH: Efficient GPU Implementations of Post-Quantum KEM NewHope · IEEE Trans. Parallel Distributed Syst. 2022
Cloud and datacenter computing › cloud storage
encrypted data search
0.112019
Passive Attacks Against Searchable Encryption · IEEE Trans. Inf. Forensics Secur. 2019

Methods — techniques the papers use, named apart from their topics

SIMD parallelization · 1.1NTT · 1.1inference attack · 0.8frequency analysis · 0.8multistreaming · 0.6multi-streaming · 0.6real-ideal simulation paradigm · 0.4data randomization · 0.4
YearPublicationVenuePosition
2022 PSI-Stats: Private Set Intersection Protocols Supporting Secure Statistical Functions
Jason H. M. Ying, Shuwei Cao 0002, Geong Sen Poh, Jia Xu 0006, Hoon Wei Lim
ACNS4
2022 Machine-Learning-Based Attestation for the Internet of Things Using Memory Traces
abstract
The advent of 4G and 5G mobile networks has made the Internet of Things (IoT) devices an essential part of smart nation drives. Firmware integrity is crucial to the security of IoT systems. Most of the existing techniques for firmware attestation require a legitimate copy of an IoT device’s firmware. However, firmware is considered an intellectual property (IP) of the manufacturer and may not be available. To solve this issue, this article proposes a software-based attestation technique where remote verifiers use machine learning (ML) classifiers on an IoT device’s memory dump to verify the integrity of an IoT device’s internal state. The experimental results from an actual prototype show that the proposed technique not only successfully detects attacks with high accuracy but also results in about 96% lower latency as compared to existing techniques. All this is achieved with high availability, low computational complexity, and without requiring a legitimate copy of the device’s original firmware.
Muhammad Naveed Aman, Mohamed Haroon Basheer, Jun Wen Wong, Jia Xu 0006, Hoon Wei Lim, Biplab Sikdar 0001
IEEE Internet Things J.4
2022 cuNH: Efficient GPU Implementations of Post-Quantum KEM NewHope
abstract
Post-quantum cryptography was proposed in the past years due to the foreseeable emergence of quantum computers that are able to break the conventional public key cryptosystems at acceptable costs. However, post-quantum schemes are usually less efficient than conventional ones, which makes them less practical in scenarios with limited resources or high concurrency. Server-side applications always feature multiple users, therefore requiring efficient execution of batch tasks. GPU is intrinsically well-suited to batch tasks owing to its SIMD/SIMT execution fashion, so it naturally helps to achieve high performance. However, a naive GPU-based implementation cannot make the best use of hardware resources of the GPU regardless of task loads. In this article, we propose SIMD parallelization paradigms for fine-grained GPU implementations and then apply them to a post-quantum key encapsulation algorithm called NewHope, where we carefully design every module, especially NTT and inverse NTT, to fit into the SIMD parallelization paradigms. In addition, we employ multi-streaming to improve performance in user's perspective. Finally, our evaluations are made on two testbeds with GPU accelerators NVIDIA GeForce MX150 and GeForce GTX 1650, respectively. The experimental results show that the fine-grained implementations save up to 98 percent latency at low task loads, and their throughputs increase by up to 86 percent at high task loads, when compared with the naive ones in kernel's perspective, and the multi-streaming implementations greatly reduce the latency overhead percentage at high task loads by up to 86 percent, when compared with the fine-grained implementation in user's perspective. Moreover, our fine-grained implementation and multi-streaming implementation are respectively 51.5 and 45.5 percent faster than Gupta et al.'s implementations when compared with it under reasonable assumptions. Furthermore, as lattice-based post-quantum schemes have similar operations, our proposal also easily applies to other lattice-based post-quantum schemes.
Yiwen Gao 0001, Jia Xu 0006
IEEE Trans. Parallel Distributed Syst.2
2021 Lightweight and Privacy-Preserving Delegatable Proofs of Storage with Data Dynamics in Cloud Storage
abstract
Cloud storage has been in widespread use nowadays, which alleviates users' burden of local data storage. Meanwhile, how to ensure the security and integrity of the outsourced data stored in a cloud storage server has also attracted enormous attention from researchers. Proofs of storage (POS) is the main technique introduced to address this problem. Publicly verifiable POS allowing a third party to verify the data integrity on behalf of the data owner significantly improves the scalability of cloud service. However, most of existing publicly verifiable POS schemes are extremely slow to compute authentication tags for all data blocks due to many expensive group exponentiation operations, even much slower than typical network uploading speed, and thus it becomes the bottleneck of the setup phase of the POS scheme. In this article, we propose a new variant formulation called “Delegatable Proofs of Storage (DPOS)”. Then, we construct a lightweight privacy-preserving DPOS scheme, which on one side is as efficient as private POS schemes, and on the other side can support third party auditor and can switch auditors at anytime, close to the functionalities of publicly verifiable POS schemes. Compared to traditional publicly verifiable POS schemes, we speed up the tag generation process by at least several hundred times, without sacrificing efficiency in any other aspect. In addition, we extend our scheme to support fully dynamic operations with high efficiency, reducing the computation of any data update to O(log n) and simultaneously only requiring constant communication costs. We prove that our scheme is sound and privacy preserving against auditor in the standard model. Experimental results verify the efficient performance of our scheme.
Anjia Yang, Jia Xu 0006, Jian Weng 0001, Jianying Zhou 0001, Duncan S. Wong
IEEE Trans. Cloud Comput.2
2020 HAtt: Hybrid Remote Attestation for the Internet of Things With High Availability
abstract
The critical and sensitive nature of data that the Internet-of-Things (IoT) devices produce makes them an attractive target for cyber attacks. Among the various types of attacks, malware is becoming a major concern for the IoT device. This article proposes a remote attestation protocol, hybrid remote attestation, which ensures the high availability of IoT devices during the software attestation process. The proposed attestation technique uses a randomized approach to attest different parts of an IoT device's memory. We use physical unclonable functions (PUFs) to protect the secrets of an IoT device from physical attacks. The security analysis shows that the proposed attestation technique can effectively detect roving malware. Implementation of the proposed protocol on Raspberry Pi and AVR/ARM-based ATMEL microcontrollers and comparison with existing techniques shows that the proposed protocol results in significantly higher availability and lower energy consumption.
Muhammad Naveed Aman, Mohamed Haroon Basheer, Siddhant Dash, Jun Wen Wong, Jia Xu 0006, Hoon Wei Lim, Biplab Sikdar 0001
IEEE Internet Things J.5
2020 PrivateLink: Privacy-Preserving Integration and Sharing of Datasets
abstract
In privacy-enhancing technology, it has been inevitably challenging to strike a reasonable balance between privacy, efficiency, and usability (utility). To this, we propose a highly practical solution for the privacy-preserving integration and sharing of datasets among a group of participants. At the heart of our solution is a new interactive protocol, PrivateLink. Through PrivateLink, each participant is able to randomize his/her dataset via an independent and untrusted third party, such that the resulting dataset can be merged with other randomized datasets contributed by other participants in a privacy-preserving manner. Our approach does not require key sharing among participants in order to integrate different datasets. This, in turn, leads to a user-friendly and scalable solution. Moreover, the correctness of a randomized dataset returned by the third party can be securely verified by the participant. We further demonstrate PrivateLink's general utilities: using it to construct a structure-preserving data integration protocol. This is particularly useful for private, fine-grained integration of network traffic data. We state the security of our protocols under the well-established real-ideal simulation paradigm and demonstrate practicality by a prototype implementation on: 1) healthcare datasets and 2) DNS and NetFlow datasets.
Hoon Wei Lim, Geong Sen Poh, Jia Xu 0006, Varsha Chittawar
IEEE Trans. Inf. Forensics Secur.3
2019 Passive Attacks Against Searchable Encryption
abstract
Searchable encryption (SE) provides a privacy-preserving mechanism for data users to search over encrypted data stored on a remote server. Researchers have designed a number of SE schemes with high efficiency yet allowing some degree of leakage profile to the remote server. The leakage, however, should be further measured to allow us to understand what types of attacks an SE scheme would encounter. This paper considers passive attacks that make inferences based on prior knowledge and observations on queries issued by users. This is in contrast to previously studied active attacks that adaptively inject files and queries. We consider several assumptions on the types or prior knowledge the attacker possessed and propose a few passive attacks. In particular, under the “full-fledged” assumption, the keyword recovery rate of our attack is optimal in the sense that it is equal to the theoretical upper bound. We further present several enhanced attacks under other weaker assumptions on various levels of the prior knowledge that the attacker can obtain, in which the keyword recovery rates are optimal or nearly optimal (i.e., approaching the theoretical upper bound). In addition, we provide extensive experiments to show the “power” of our passive attacks. This paper highlights the importance of minimizing the prior knowledge of a server and the leakage of search queries. It also shows that simply distorting the frequency of the keyword to hold against our passive attacks may not scale well.
Jianting Ning, Jia Xu 0006, Kaitai Liang, Fan Zhang 0010, Ee-Chien Chang
IEEE Trans. Inf. Forensics Secur.2
2018 Virtually Isolated Network: A Hybrid Network to Achieve High Level Security
Jia Xu 0006, Jianying Zhou 0001
DBSec1
2017 A New Functional Encryption for Multidimensional Range Query (Short Paper)
Jia Xu 0006, Ee-Chien Chang, Jianying Zhou 0001
ISPEC1
2016 Lightweight Delegatable Proofs of Storage
Jia Xu 0006, Anjia Yang, Jianying Zhou 0001, Duncan S. Wong
ESORICS (1)1
2014 Leakage Resilient Proofs of Ownership in Cloud Storage, Revisited
Jia Xu 0006, Jianying Zhou 0001
ACNS1
2013 Weak leakage-resilient client-side deduplication of encrypted data in cloud storage
abstract
Recently, Halevi et al. (CCS '11) proposed a cryptographic primitive called proofs of ownership (PoW) to enhance security of client-side deduplication in cloud storage. In a proof of ownership scheme, any owner of the same file F can prove to the cloud storage that he/she owns file F in a robust and efficient way, in the bounded leakage setting where a certain amount of efficiently-extractable information about file F is leaked. Following this work, we propose a secure client-side deduplication scheme, with the following advantages: our scheme protects data confidentiality (and some partial information) against both outside adversaries and honest-but-curious cloud storage server, while Halevi et al. trusts cloud storage server in data confidentiality; our scheme is proved secure w.r.t. any distribution with sufficient min-entropy, while Halevi et al. (the last and the most practical construction) is particular to a specific type of distribution (a generalization of "block-fixing" distribution) of input files.
Jia Xu 0006, Ee-Chien Chang, Jianying Zhou 0001
AsiaCCS1
2012 Towards efficient proofs of retrievability
abstract
Proofs of Retrievability (POR) is a cryptographic formulation for remotely auditing the integrity of files stored in the cloud, without keeping a copy of the original files in local storage. In a POR scheme, a user Alice backups her data file together with some authentication data to a potentially dishonest cloud storage server Bob. Later, Alice can periodically and remotely verify the integrity of her data file using the authentication data, without retrieving back the data file. Besides security, performances in communication, storage overhead and computation are major considerations. Shacham and Waters (Asiacrypt '08) gave a fast scheme with O(sλ) bits communication cost and a factor of 1/s file size expansion where λ is the security parameter. In this paper, we incorporate a recent construction of constant size polynomial commitment scheme (Kate, Zaverucha and Goldberg, Asiacrypt '10) into Shacham and Waters scheme. The resulting scheme requires O(λ) communication bits (particularly, 920 bits if a 160 bits elliptic curve group is used or 3512 bits if a 1024 bits modulo group is used) per verification and a factor of 1/s file size expansion. Experiment results show that our proposed scheme is indeed efficient and practical. Our security proof is based on Strong Diffie-Hellman Assumption.
Jia Xu 0006, Ee-Chien Chang
AsiaCCS1
2011 ID Repetition in Structured P2P Networks
abstract
Identity (ID) uniqueness is essential in distributed hash table (DHT)-based systems, as peer lookup and resource searching rely on ID matching. However, many DHT implementations in the wild, such as Kad and Mainline, do not enforce such uniqueness. Most previous works and measurements on DHTs do not take into account that IDs among peers may not be unique. Unfortunately, we observe that a significant portion of peers, i.e. 19.5% of the peers in Kad and 4.0% of the peers in Mainline, do not have unique IDs. These repetitions would mislead the measurements and modeling on those networks. We further focus on investigating the repetition in Kad considering its wider usage and more serious situation of repetition. We observe that there are a large number of peers that frequently change their UDP ports, and there are a few IDs that repeat for a large number of times and all peers with these IDs do not respond to Kad protocol. We also analyze the effects of ID repetitions under simplified settings and find that the current repetition degrades Kad's performance on publishing and searching, but has insignificant effect on lookup process. These measurement and analysis are useful to further determine the sources of repetitions and are also useful for finding suitable parameters in publishing and searching processes in DHT networks without compulsive ID uniqueness.
Jie Yu 0008, Zhoujun Li 0001, Chengfang Fang, Jia Xu 0006, Ee-Chien Chang
Comput. J.5
2010 A chameleon encryption scheme resistant to known-plaintext attack
abstract
From a ciphertext and a secret key assigned to a user, the decryption of a Chameleon encryption scheme produces a message which is the plaintext embedded with a watermark associated to the user. Most existing constructions of Chameleon encryption scheme are LUT (lookup table)-based, where a secret LUT plays the role of the master key and each user has a noisy version of the secret LUT. LUT-based methods have the limitation that the secrecy of the master key, under known-plaintext attack (KPA), relies on the difficulty in solving large linear system. In other words, with some knowledge of the plaintext, a dishonest user is able to derive the LUT, or an approximation of the LUT by solving a linear system. Resistance to such attack is crucial in the context of multimedia encryption since multimedia objects inherently contain high redundancies. Furthermore, for efficiency in decryption, the underlying linear system is likely to be sparse or not overly large, and hence can be solved using reasonable computing resource. In our experiment, a desktop PC is able to find a LUT (with 216 entries) within 2 hours. We propose a scheme that is resistant to KPA. The core of the scheme is a MUTABLE-PRNG (Pseudo Random Number Generator) whereby different but similar sequences are generated from related seeds. We generate such sequence from multiple pseudo random sequences based on majority-vote, and enhance its performance using error-correcting code. The proposed scheme is very simple and it is easy to show that it is resistant to KPA under reasonable cryptographic assumptions. However, it is not clear how much information on the original plaintext is leaked from the watermarked copies. We analyze the scheme and quantify the information loss using average conditional entropy.
Ee-Chien Chang, Chengfang Fang, Jia Xu 0006
Digital Rights Management Workshop3
2009 Short Redactable Signatures Using Random Trees
Ee-Chien Chang, Chee Liang Lim, Jia Xu 0006
CT-RSA3
2009 ID Repetition in Kad
abstract
ID uniqueness is essential in DHT-based systems as peer lookup and resource searching rely on ID-matching. Many previous works and measurements on Kad do not take into account that IDs among peers may not be unique. We observe that a significant portion of peers, 19.5% of the peers in routing tables and 4.5% of the active peers (those who respond to Kad protocol), do not have unique IDs. These repetitions would mislead the measurements of Kad network. We further observe that there are a large number of peers that frequently change their UDP ports, and there are a few IDs that repeat for a large number of times and all peers with these IDs do not respond to Kad protocol. We analyze the effects of ID repetitions under simplified settings and find that ID repetition degrades Kad's performance on publishing and searching, but has insignificant effect on lookup process. These measurement and analysis are useful in determining the sources of repetitions and are also useful in finding suitable parameters for publishing and searching.
Jie Yu 0008, Chengfang Fang, Jia Xu 0006, Ee-Chien Chang, Zhoujun Li 0001
Peer-to-Peer Computing3
2008 Remote Integrity Check with Dishonest Storage Server
Ee-Chien Chang, Jia Xu 0006
ESORICS2