Open Access. Powered by Scholars. Published by Universities.®
- Discipline
-
- Databases and Information Systems (148)
- Software Engineering (105)
- Artificial Intelligence and Robotics (40)
- Business (37)
- Engineering (33)
-
- Computer Engineering (29)
- Medicine and Health Sciences (27)
- OS and Networks (24)
- Data Storage Systems (22)
- Social and Behavioral Sciences (20)
- Numerical Analysis and Scientific Computing (19)
- Theory and Algorithms (16)
- Graphics and Human Computer Interfaces (13)
- Health Information Technology (13)
- Finance and Financial Management (11)
- E-Commerce (10)
- Law (9)
- Public Affairs, Public Policy and Public Administration (9)
- Management Information Systems (7)
- Programming Languages and Compilers (7)
- Transportation (7)
- Asian Studies (5)
- International and Area Studies (5)
- Science and Technology Law (5)
- Systems Architecture (5)
- Technology and Innovation (5)
- Communication (4)
- Keyword
-
- Privacy (49)
- Cloud computing (41)
- Access control (39)
- Security (36)
- Authentication (34)
-
- Blockchain (28)
- Encryption (28)
- Privacy-preserving (28)
- Searchable encryption (24)
- Attribute-based encryption (21)
- Data privacy (21)
- Servers (19)
- Cloud storage (18)
- Cryptography (18)
- Anonymity (16)
- RFID (16)
- Revocation (15)
- Cybersecurity (14)
- Homomorphic encryption (14)
- Android (13)
- Protocols (13)
- Machine learning (12)
- Keyword search (11)
- Digital signature (10)
- Information security (10)
- Proxy re-encryption (10)
- Bitcoin (9)
- Cloud Computing (9)
- Data outsourcing (9)
- Data sharing (9)
- Publication Year
- Publication
-
- Research Collection School Of Computing and Information Systems (1051)
- Dissertations and Theses Collection (Open Access) (16)
- Research Collection Yong Pung How School Of Law (7)
- Perspectives@SMU (6)
- Research Collection School Of Accountancy (4)
-
- Dissertations and Theses Collection (2)
- LARC Research Publications (2)
- Research Collection Lee Kong Chian School Of Business (2)
- Research Collection School Of Economics (2)
- Research@SMU: Connecting the Dots (2)
- Asian Management Insights (1)
- Centre for AI & Data Governance (2019-2025) (1)
- MITB Thought Leadership Series (1)
- PhD Student’s Publications Collection (1)
- Research Collection College of Integrative Studies (1)
- Research Collection Library (1)
- Research Collection School of Computing and Information Systems (1)
- SMU Press Releases and News (1)
- Publication Type
Articles 31 - 60 of 1102
Full-Text Articles in Information Security
Fl-Cdf: Collaborative Defense Framework For Backdoor Mitigation In Federated Learning, Haiyan Zhang, Xinghua Li, Yinbin Miao, Shunjie Yuan, Mengyao Zhu, Ximeng Liu, Robert H. Deng
Fl-Cdf: Collaborative Defense Framework For Backdoor Mitigation In Federated Learning, Haiyan Zhang, Xinghua Li, Yinbin Miao, Shunjie Yuan, Mengyao Zhu, Ximeng Liu, Robert H. Deng
Research Collection School Of Computing and Information Systems
Federated learning (FL) is vulnerable to backdoor attacks due to its distributed nature. Existing unilateral defense mechanisms often fail against persistent attack strategies, primarily due to their limited perspectives. To address the challenge of model misclassification on the server side caused by overlooked model similarity drift, and gradient misjudgment on the client side caused by semantic learning imbalances across classes, this paper proposes a collaborative defense framework for federated learning, termed FL-CDF. FL-CDF establishes an end-to-end defense through a bidirectional client-server collaboration mechanism. Specifically: (1) On the client side, an adversarial perturbation-based malicious neuron detection module is introduced. This module …
Accuracy-Enabling Differential Privacy-Preserving Truth Discovery, Man Zhang, Xinghua Li, Yinbin Miao, Bin Luo, Siqi Ma, Robert H. Deng
Accuracy-Enabling Differential Privacy-Preserving Truth Discovery, Man Zhang, Xinghua Li, Yinbin Miao, Bin Luo, Siqi Ma, Robert H. Deng
Research Collection School Of Computing and Information Systems
Perturbation-based privacy-preserving truth discovery requires the Service Provider (SP) to calculate the truthful aggregation result from perturbed data of the Data Sources (DSs), which inevitably damages the aggregation accuracy due to perturbation noise added in the data. Thus, the existing works attempt to relieve the perturbation errors by reducing noise amounts or adjusting aggregation weights of DSs. However, the former sacrifices DSs’ privacy preservation and the latter has the limited accuracy recovery performance. Aiming at it, we propose an accuracy-enabling differential privacy-preserving truth discovery consisting of an independence-guaranteed data perturbation module and a progressive-private noise elimination module. Specifically, in the …
Security Modelling For Cyber-Physical Systems: A Systematic Literature Review, Shao Fei Huang, Christopher M. Poskitt, Lwin Khin Shar
Security Modelling For Cyber-Physical Systems: A Systematic Literature Review, Shao Fei Huang, Christopher M. Poskitt, Lwin Khin Shar
Research Collection School Of Computing and Information Systems
Cyber-physical systems are at the intersection of digital technology and engineering domains, rendering them high-value targets of sophisticated and well-funded cybersecurity threat actors. Prominent cybersecurity attacks on CPS have brought attention to the vulnerability of these systems and the inherent weaknesses of critical infrastructure reliant on them. Security modelling for CPS is an important mechanism to systematically identify and assess vulnerabilities, threats, and risks throughout system life cycles, and to ultimately ensure system resilience, safety, and reliability. This survey delves into state-of-the-art research on CPS security modelling, encompassing both threat and attack modelling. While these terms are sometimes used interchangeably, …
Disc: Decentralized Identity System With Self-Sovereign Credential Aggregation, Yang Yang, Wai Keung Ching, Minming Huang, Supachate Innet, Guomin Yang, Hwee Hwa Pang, Robert H. Deng
Disc: Decentralized Identity System With Self-Sovereign Credential Aggregation, Yang Yang, Wai Keung Ching, Minming Huang, Supachate Innet, Guomin Yang, Hwee Hwa Pang, Robert H. Deng
Research Collection School Of Computing and Information Systems
The evolution of decentralized identity (DID) and self-sovereign identity (SSI) frameworks, as endorsed by W3C Verifiable Credentials (VC) and eIDAS 2.0, underscores the need for secure, efficient, and privacy-preserving credential management. However, existing credential systems often depend on centralized issuers, lack efficient aggregation mechanisms, or fail to ensure unlinkability across authentication sessions. To address these challenges, we propose DISC (Decentralized Identity System with Self-Sovereign Credential Aggregation), a novel credential system that enables multi-authority credential issuance, user-controlled credential aggregation, and unlinkable authentication. DISC allows users to aggregate credentials from multiple issuers while maintaining constant-size authentication tokens and supporting batch verification for …
Spd: Shallow Backdoor Protecting Deep Backdoor Against Backdoor Detection, Shunjie Yuan, Xinghua Li, Xuelin Cao, Haiyan Zhang, Mengyao Zhu, Robert H. Deng
Spd: Shallow Backdoor Protecting Deep Backdoor Against Backdoor Detection, Shunjie Yuan, Xinghua Li, Xuelin Cao, Haiyan Zhang, Mengyao Zhu, Robert H. Deng
Research Collection School Of Computing and Information Systems
Backdoor attacks have revealed the vulnerability of deep neural networks (DNNs), which motivates the development of secure deep learning systems. However, existing backdoor attacks often fail to bypass backdoor detection and human visual inspection, resulting in the exposure of the backdoor implanted in DNNs, which can subsequently be significantly mitigated through pruning or fine-tuning on benign data. To address this issue, in this paper, we propose a novel backdoor attack called SPD (Shallow Protecting Deep), which consists of a deep backdoor in the frequency domain and a shallow backdoor in the pixel domain, where the shallow backdoor acts as a …
Conditional Attribute-Based Pre: Definition And Construction From Lwe, Lisha Yao, Jian Weng, Pengfei Wu, Guofeng Tang, Guomin Yang, Haiyang Xue, Robert H. Deng
Conditional Attribute-Based Pre: Definition And Construction From Lwe, Lisha Yao, Jian Weng, Pengfei Wu, Guofeng Tang, Guomin Yang, Haiyang Xue, Robert H. Deng
Research Collection School Of Computing and Information Systems
Attribute-based proxy re-encryption (AB-PRE) is a crucial variant of proxy re-encryption. It allows a proxy with a re-encryption key to transform a delegator’s ciphertext associated with an access policy into another ciphertext associated with a new access policy, enabling delegatees with matching attributes to decrypt the transformed ciphertext. However, a key limitation of AB-PRE is that the delegator cannot control which ciphertexts are transformed. As a result, the proxy, once given the re-encryption key, indiscriminately transforms all ciphertexts, effectively switching their underlying policies—an issue known as the all-or-nothing problem. It limits the system’s flexibility and practicality in real-world use cases.In …
A System Framework To Symbolically Explore Intel Tdx Module Execution, Pansilu Pitigalaarachchillage, Xuhua Ding
A System Framework To Symbolically Explore Intel Tdx Module Execution, Pansilu Pitigalaarachchillage, Xuhua Ding
Research Collection School Of Computing and Information Systems
We present TDXplorer, the first dynamic symbolic analysis system for Intel's TDX Module, the software trusted computing base of TDX. Without using TDX hardware, an analyzer function on top of TDXplorer can not only apply dynamic analysis to control and instrument the TDX Module's execution, but also carry out symbolic execution for path exploration as well as security and functionality reasoning. The two types of analysis are seamlessly integrated in a way that symbolic execution is conducted directly upon the TDX Module's binary code and runtime states, which are shaped by using dynamic analysis techniques. We implement TDXplorer on Linux …
Ivycross: A Privacy-Preserving And Concurrency Control Framework For Blockchain Interoperability, Ming Li, Jian Weng, Jia-Si Weng, Yi Li, Yongdong Wu, Dingcheng Li, Guowen Xu, Deng, Robert H.
Ivycross: A Privacy-Preserving And Concurrency Control Framework For Blockchain Interoperability, Ming Li, Jian Weng, Jia-Si Weng, Yi Li, Yongdong Wu, Dingcheng Li, Guowen Xu, Deng, Robert H.
Research Collection School Of Computing and Information Systems
Interoperability is a fundamental challenge for long-envisioned blockchain applications. A mainstream approach is using Trusted Execution Environment (TEE) to support interoperable off-chain execution. However, this incurs multiple TEE configured with non-trivial storage capabilities running on fragile concurrent processing environments, rendering current strategies based on TEE far from being practical. This paper aims to fill this gap and design a practical interoperability mechanism with simplified TEE as the underlying architecture. Specifically, we present IvyCross, a TEE-based framework that achieves low-cost, privacy-preserving, and race-free blockchain interoperability. IvyCross allows running arbitrary smart contracts across heterogeneous blockchains atop two distributed TEE-powered hosts. We design …
Boosting Symbolic Execution For Vulnerability Detection, Haoxin Tu
Boosting Symbolic Execution For Vulnerability Detection, Haoxin Tu
Dissertations and Theses Collection (Open Access)
Software systems written by humans tend to be unreliable and insecure, hence, bugs or vulnerabilities in them are inevitable. Symbolic execution has shown considerable potential in detecting diverse types of software bugs and also vulnerabilities that have severe security implications. However, existing symbolic execution engines still suffer from at least three fundamental limitations in memory modeling, path exploration, and structured input generation, which significantly impede existing engines from efficiently and effectively detecting software bugs and vulnerabilities.
The objective of this dissertation is to boost existing symbolic execution engines by designing a new memory model, two new path exploration strategies, and …
An Efficient Security-Enhanced Accountable Access Control For Named Data Networking, Jianfei Sun, Yuxian Li, Xuehuan Yang, Guomin Yang, Robert H. Deng
An Efficient Security-Enhanced Accountable Access Control For Named Data Networking, Jianfei Sun, Yuxian Li, Xuehuan Yang, Guomin Yang, Robert H. Deng
Research Collection School Of Computing and Information Systems
Named Data Networking (NDN) is embraced as the crucial implementation of Information-Centric Networking (ICN), enhancing content distribution and caching efficiency through edge routers. However, existing NDN architectures face significant security and privacy challenges, including: (a) a lack of secure and efficient access control; (b) inadequate support for flexible and selective content management by content publishers; (c) insufficient implementation of accountability and privilege revocation mechanisms. To handle these challenges, we propose ESAS, the first-ever Efficient Security-enhanced Accountable Access Control Scheme for NDN. Specifically, our ESAS incorporates anonymous authentication using group signatures at network routers to prevent unauthorized access, employs key-aggregation-based access …
Shortcuts Everywhere And Nowhere: Exploring Multi-Trigger Backdoor Attacks, Yige Li, Jiabo He, Hanxun Huang, Jun Sun, Xingjun Ma, Yu-Gang Jiang
Shortcuts Everywhere And Nowhere: Exploring Multi-Trigger Backdoor Attacks, Yige Li, Jiabo He, Hanxun Huang, Jun Sun, Xingjun Ma, Yu-Gang Jiang
Research Collection School Of Computing and Information Systems
Backdoor attacks have become a significant threat to the pre-training and deployment of deep neural networks (DNNs). Although numerous methods for detecting and mitigating backdoor attacks have been proposed, most rely on identifying and eliminating the “shortcut” created by the backdoor, which links a specific source class to a target class. However, these approaches can be easily circumvented by designing multiple backdoor triggers that create shortcuts everywhere and therefore nowhere specific. In this study, we explore the concept of Multi-Trigger Backdoor Attacks (MTBAs), where multiple adversaries leverage different types of triggers to poison the same dataset. By proposing and investigating …
Privacy-Preserving Ridge Regression Over Encrypted Data Under Multiple Keys, Yanling Li, Junzuo Lai, Meng Sun, Beibei Song, Robert H. Deng
Privacy-Preserving Ridge Regression Over Encrypted Data Under Multiple Keys, Yanling Li, Junzuo Lai, Meng Sun, Beibei Song, Robert H. Deng
Research Collection School Of Computing and Information Systems
With the increase of private data being collected by data owners, it has been a trend for data owners to store the data on cloud computing platforms. The huge amounts of data in cloud servers bring fresh development opportunities to machine learning, which is applied to build a high-quality machine learning model based on a large training dataset. However, to ensure the privacy of data and facilitate retrieval, data owners often upload encrypted data under their public keys. But it creates new challenges for machine learning to learn a predictive model over these encrypted data under different keys. Most existing …
Achilles: A Formal Framework Of Leaking Secrets From Signature Schemes Via Rowhammer, Junkai Liang, Zhi Zhang, Xin Zhang, Qingni Sheng, Yansong Gao, Xinliang Yuan, Haiyang Xue, Pengfei Wu, Zhonghai. Wu
Achilles: A Formal Framework Of Leaking Secrets From Signature Schemes Via Rowhammer, Junkai Liang, Zhi Zhang, Xin Zhang, Qingni Sheng, Yansong Gao, Xinliang Yuan, Haiyang Xue, Pengfei Wu, Zhonghai. Wu
Research Collection School Of Computing and Information Systems
Signature schemes are a fundamental component of cyber-security infrastructure. While they are designed to be mathematically secure against cryptographic attacks, they are vulnerable to Rowhammer fault-injection attacks. Since all existing attacks are ad-hoc in that they target individual parameters of specific signature schemes, it remains unclear about the impact of Rowhammer on signature schemes as a whole.In this paper, we present Achilles, a formal framework that aids in leaking secrets in various real-world signature schemes via Rowhammer. Particularly, Achilles can be used to find potentially more vulnerable parameters in schemes that have been studied before and also new schemes that …
Collisionrepair: First‑Aid And Automated Patching For Storage Collision Vulnerabilities In Smart Contracts, Yu Pan, Wanjing Han, Yue Duan, Mu Zhang
Collisionrepair: First‑Aid And Automated Patching For Storage Collision Vulnerabilities In Smart Contracts, Yu Pan, Wanjing Han, Yue Duan, Mu Zhang
Research Collection School Of Computing and Information Systems
Storage collision vulnerabilities, a significant security risk in upgradeable smart contracts, often arise when a user-facing proxy contract and a backend logic contract share storage space. While static analysis techniques can detect such issues, they often over-approximate program states, leading to false positives and requiring developers to manually verify each issue, giving attackers time to exploit any overlooked vulnerabilities. To address this, we propose COLLISIONREPAIR, an automated patching technique for mitigating storage collision risks. COLLISIONREPAIR monitors storage access sequences between proxy and logic contracts by defining an "ownership" property for storage locations. It then replays historical transactions to recover existing …
Prism: To Fortify Widget Based User‑App Data Exchanges Using Android Virtualization Framework, Yingtat Ng, Zhe Chen, Haiqing Qiu, Xuhua Ding
Prism: To Fortify Widget Based User‑App Data Exchanges Using Android Virtualization Framework, Yingtat Ng, Zhe Chen, Haiqing Qiu, Xuhua Ding
Research Collection School Of Computing and Information Systems
We present Prism, an UI hardening technique for an Android app to safeguard its widgets against a corrupted kernel. Prism ensures secure interface rendering and allows for visual authentication, which developers could use to enable user intent confidentiality protection. Our design leverages the recent Android Virtualization Framework with minimal changes to the existing UI framework and graphics subsystem. It is much easier to deploy and use Prism on Android phones than TrustZone-based secure UI schemes, because the apps are not admitted to the Secure World and retain their full rights to manage and control their own interfaces. We have implemented …
Oblivious Digital Tokens, Mihael Liskij, Xuhua Ding, Gene Tsudik, David A. Basin
Oblivious Digital Tokens, Mihael Liskij, Xuhua Ding, Gene Tsudik, David A. Basin
Research Collection School Of Computing and Information Systems
A computing device typically identifies itself by exhibiting unique measurable behavior or by proving its knowledge of a secret. In both cases, the identifying device must reveal information to a verifier. Considerable research has focused on protecting identifying entities (provers) and reducing the amount of leaked data. However, little has been done to conceal the fact that the verification occurred.We show how this problem naturally arises in the context of digital emblems, which were recently proposed by the International Committee of the Red Cross to protect digital resources during cyber-conflicts. To address this new and important open problem, we define …
Improved Secure Two-Party Computation From A Geometric Perspective, Hao Guo, Liqiang Peng, Haiyang Xue, Li Peng, Weiran Liu, Zhe Liu, Lei. Hu
Improved Secure Two-Party Computation From A Geometric Perspective, Hao Guo, Liqiang Peng, Haiyang Xue, Li Peng, Weiran Liu, Zhe Liu, Lei. Hu
Research Collection School Of Computing and Information Systems
Multiplication and other non-linear operations are widely recognized as the most costly components of secure two-party computation (2PC) based on linear secret sharing. Moreover, the comparison protocol (or Wrap protocol) is essential for various operations such as truncation, signed extension, and signed non-uniform multiplication. This paper aims to optimize these protocols by avoiding invoking the costly comparison protocol, thereby improving their efficiency.We propose a novel approach to study 2PC from a geometric perspective. Specifically, we interpret the two shares of a secret as the horizontal and vertical coordinates of a point in a Cartesian coordinate system, with the secret itself …
Tetd: Trusted Execution In Trust Domains, Zhanbo Wang, Jiaxin Zhan, Xuhua Ding, Fengwei Zhang, Ning Hu
Tetd: Trusted Execution In Trust Domains, Zhanbo Wang, Jiaxin Zhan, Xuhua Ding, Fengwei Zhang, Ning Hu
Research Collection School Of Computing and Information Systems
Intel TDX empowers cloud service providers to construct confidential virtual machines called trust domains (TDs) on x86 platforms. Similar to its counterparts from AMD and Arm, TDX's hardware based protection over integrity and secrecy of virtual machine memory and vCPU states inevitably hinders legitimate virtual machine management such as introspection. At the presence of compromised high-privileged software (e.g., the guest kernel), neither the cloud service provider nor the TD owner can securely carry out a task within the TD. To tackle this problem, we propose TETD, an in-TD trusted execution technique without trusting any TD system software. Our design does …
A Comprehensive Analysis Of Evolving Permission Usage In Android Apps: Trends, Threats, And Ecosystem Insights, Ali Alkinoon, Trung Cuong Dang, Ahod Alghuried, Abdulaziz Alghamdi, Soohyeon Choi, Manar Mohaisen, An Wang, Saeed Salem, David Mohaisen
A Comprehensive Analysis Of Evolving Permission Usage In Android Apps: Trends, Threats, And Ecosystem Insights, Ali Alkinoon, Trung Cuong Dang, Ahod Alghuried, Abdulaziz Alghamdi, Soohyeon Choi, Manar Mohaisen, An Wang, Saeed Salem, David Mohaisen
Research Collection School Of Computing and Information Systems
The proper use of Android app permissions is crucial to the success and security of these apps. Users must agree to permission requests when installing or running their apps. Despite official Android platform documentation on proper permission usage, there are still many cases of permission abuse. This study provides a comprehensive analysis of the Android permission landscape, highlighting trends and patterns in permission requests across various applications from the Google Play Store. By distinguishing between benign and malicious applications, we uncover developers’ evolving strategies, with malicious apps increasingly requesting fewer permissions to evade detection, while benign apps request more to …
A Review: The Beauty Of Serendipity Between Integrated Circuit Security And Artificial Intelligence, Chen Dong, Decheng Qiu, Bolun Li, Yang Yang, Chenxi Lyu, Dong Cheng, Hao Zhang, Zhenyi. Chen
A Review: The Beauty Of Serendipity Between Integrated Circuit Security And Artificial Intelligence, Chen Dong, Decheng Qiu, Bolun Li, Yang Yang, Chenxi Lyu, Dong Cheng, Hao Zhang, Zhenyi. Chen
Research Collection School Of Computing and Information Systems
Integrated circuits are the core of a cyber-physical system, where tens of billions of components are integrated into a tiny silicon chip to conduct complex functions. To maximize utilities, the design and manufacturing life cycle of integrated circuits rely on numerous untrustworthy third parties, forming a global supply chain model. At the same time, this model produces unpredictable and catastrophic issues, threatening the security of individuals and countries. As for guaranteeing the security of ultra-highly integrated chips, detecting slight abnormalities caused by malicious behavior in the current and voltage is challenging, as is achieving computability within a reasonable time and …
Practical Keyword Private Information Retrieval From Key-To-Index Mappings, Meng Hao, Weiran Liu, Liqiang Peng, Cong Zhang, Pengfei Wu, Lei Zhang, Hongwei Li, Deng, Robert H.
Practical Keyword Private Information Retrieval From Key-To-Index Mappings, Meng Hao, Weiran Liu, Liqiang Peng, Cong Zhang, Pengfei Wu, Lei Zhang, Hongwei Li, Deng, Robert H.
Research Collection School Of Computing and Information Systems
This paper introduces practical schemes for keyword Private Information Retrieval (keyword PIR), enabling private queries on public databases using keywords. Unlike standard indexbased PIR, keyword PIR presents greater challenges, since the query’s position within the database is unknown and the domain of keywords is vast. Our key insight is to construct an efficient and compact key-to-index mapping, thereby reducing the keyword PIR problem to standard PIR. To achieve this, we propose three constructions incorporating several new techniques. The high-level approach involves (1) encoding the server’s key-value database into an indexable database with a key-to-index mapping and (2) invoking standard PIR …
Akma+: Security And Privacy-Enhanced And Standard-Compatible Akma For 5g Communication, Guomin Yang, Guomin Yang, Yingjiu Li, Minming Huang, Zilin Shen, Imtiaz Karim, Ralf Sasse, David Basin, Elisa Bertino, Jian Weng, Hwee Hwa Pang, Deng, Robert H.
Akma+: Security And Privacy-Enhanced And Standard-Compatible Akma For 5g Communication, Guomin Yang, Guomin Yang, Yingjiu Li, Minming Huang, Zilin Shen, Imtiaz Karim, Ralf Sasse, David Basin, Elisa Bertino, Jian Weng, Hwee Hwa Pang, Deng, Robert H.
Research Collection School Of Computing and Information Systems
The Authentication and Key Management for Applications (AKMA) protocol is a fundamental building block for security and privacy of 5G cellular networks. Therefore, it is critical that the protocol is free of vulnerabilities that can be exploited by attackers. Unfortunately, based on a detailed analysis of AKMA, we show that AKMA has several vulnerabilities that may lead to security and privacy breaches.We define AKMA+, an enhanced protocol for 5G communication that protects against security and privacy breaches while maintaining compatibility with existing standards. AKMA+ includes countermeasures for protecting communication between the user equipment (UE) and application functions (AFs) from attackers, …
Unbounded Multi-Hop Proxy Re-Encryption With Hra Security: An Lwe-Based Optimization, Xiaohan Wan, Yang Wang, Haiyang Xue, Mingqiang Wang
Unbounded Multi-Hop Proxy Re-Encryption With Hra Security: An Lwe-Based Optimization, Xiaohan Wan, Yang Wang, Haiyang Xue, Mingqiang Wang
Research Collection School Of Computing and Information Systems
Proxy re-encryption (PRE) schemes enable a semi-honest proxy to transform a ciphertext of one user i to another user j while preserving the privacy of the underlying message. Multi-hop PRE schemes allow a legal ciphertext to undergo multiple transformations, but for lattice-based multi-hop PREs, the number of transformations is typically bounded due to the increase of error terms. Recently, Zhao et al. (ESORICS 2024) introduced a lattice-based unbounded multi-hop (homomorphic) PRE scheme that supports an unbounded number of hops. Nevertheless, their scheme only achieves the selective CPA security. In contrast, Fuchsbauer et al. (PKC 2019) proposed a generic framework for …
An Incentive Mechanism For Privacy Preserved Data Trading With Verifiable Data Disturbance, Man Zhang, Xinghua Li, Bin Luo, Yanbing Ren, Yinbin Miao, Ximeng Liu, Robert H. Deng
An Incentive Mechanism For Privacy Preserved Data Trading With Verifiable Data Disturbance, Man Zhang, Xinghua Li, Bin Luo, Yanbing Ren, Yinbin Miao, Ximeng Liu, Robert H. Deng
Research Collection School Of Computing and Information Systems
To motivate data owners’ (DOs’) trading willingness, the existing incentive mechanisms allow DOs to independently disturb data following data consumer's (DC’s) availability requirement. However, they cannot motivate DOs’ honest disturbance, which is attributed to DOs’ independent disturbance without any supervision. Thus, we implement an incentive mechanism for privacy preserved data trading with verifiable data disturbance where an honest-but-curious disturbance generator (DG) is additionally introduced to supervise DOs’ local disturbance and assist disturbance verification between DOs and DC. Specifically, DG generates the disturbance strategies and secretly distributes to DOs following private information retrieval, guaranteeing DOs's local disturbance's privacy and verifiability with …
Leakage-Resilient Easily Deployable And Efficiently Searchable Encryption (Edese), Jiaming Yuan, Yingjiu Li, Jun Li, Daoyuan Wu, Jianting Ning, Yangguang Tian, Robert H. Deng
Leakage-Resilient Easily Deployable And Efficiently Searchable Encryption (Edese), Jiaming Yuan, Yingjiu Li, Jun Li, Daoyuan Wu, Jianting Ning, Yangguang Tian, Robert H. Deng
Research Collection School Of Computing and Information Systems
Easily Deployable and Efficiently Searchable Encryption (EDESE) is a cryptographic primitive designed for practical searchable applications, offering efficient search and easy deployment. However, it remains vulnerable to Leakage-Abuse attacks, allowing adversaries to exploit keyword-matching processes to extract sensitive information. To address these vulnerabilities, we introduce Leakage-Resilient EDESE (LR-EDESE) with k-indistinguishability and controlled leakage functions. We then propose Volume Leakage-Resilient EDESE (VLR-EDESE), a new scheme to protect against both query and document volume leakage. Our experimental results demonstrate that at k = 5000 (maximum security setting), VLR-EDESE incurs an overhead of 63× compared to the baseline EDESE without leakage protection, outperforming …
Sanitizable Cross-Domain Access Control With Policy-Driven Dynamic Authorization, Jianfei Sun, Guowen Xu, Hongwei Li, Tianwei Zhang, Cong Wu, Xuehuan Yang, Robert H. Deng
Sanitizable Cross-Domain Access Control With Policy-Driven Dynamic Authorization, Jianfei Sun, Guowen Xu, Hongwei Li, Tianwei Zhang, Cong Wu, Xuehuan Yang, Robert H. Deng
Research Collection School Of Computing and Information Systems
The increasing demand for secure and efficient data sharing has underscored the importance of developing robust cryptographic schemes. However, many existing endeavors have overlooked the following critical issues: (1) unauthorized access resulting from malicious information leakage by senders; (2) absence of constraints on write and read permissions for participants; (3) and inflexibility of strategies to dynamically designate ciphertexts to multiple recipients. In this paper, we present SCPA, a cross-domain access control scheme imbued with sanitization features and propelled by policy-driven dynamic authorization, tailored for cloud-based data sharing. This scheme not only facilitates access controls, including regulations for no-read and no-write …
Understanding The Bad Development Practices Of Android Custom Permissions In The Wild, Xiaohan Zhang, Zhiyuan Yu, Xinghua Li, Cen Zhang, Cong Sun, Ning Zhang, Robert H. Deng
Understanding The Bad Development Practices Of Android Custom Permissions In The Wild, Xiaohan Zhang, Zhiyuan Yu, Xinghua Li, Cen Zhang, Cong Sun, Ning Zhang, Robert H. Deng
Research Collection School Of Computing and Information Systems
Android system provides application developers with the ability to define custom permissions, which serve to moderate the sharing of resources and interactions with other applications. However, poor development practices of developers can render the permission mechanism ineffective, weakening the system protection. This paper presents a comprehensive examination of the problematic practices surrounding custom permissions employed by developers, referred to as Bad Practices of Custom Permissions (BPCP issues). To accomplish this, we conducted an empirical study and identified nine common BPCP issue patterns that can lead to various adverse consequences, such as installation failures, crashes, or even component hijacking. To automatically …
Verify All Traffic: Towards Zero-Trust In-Network Intrusion Detection Against Multipath Routing, Ziming Zhao, Zhaoxuan Li, Xiaofei Xie, Zhipeng Liu, Tingting Li, Jiongchi Yu, Fan Zhang, Binbin Chen
Verify All Traffic: Towards Zero-Trust In-Network Intrusion Detection Against Multipath Routing, Ziming Zhao, Zhaoxuan Li, Xiaofei Xie, Zhipeng Liu, Tingting Li, Jiongchi Yu, Fan Zhang, Binbin Chen
Research Collection School Of Computing and Information Systems
With the popularity of encryption protocols, machine learning (ML)-based traffic analysis technologies have attracted widespread attention. To adapt to modern high-speed bandwidth, recent research is dedicated to advancing zero-trust intrusion detection by offloading feature extraction and model inference into the network dataplane. Especially, with the rise of programmable switches, achieving line-speed ML inference becomes promising. However, existing research only considers a single switch node as a relay to conduct evaluation. This is far from real-world deployments involving multiple switches (given that zero-trust security assumes that threats can originate from anywhere, including within the network), particularly the multipath routing phenomenon that …
Acccred: Improved Accountable Anonymous Credentials With Dynamic Triple-Hiding Committees, Sijiang Xie, Rui Shi, Yang Yang, Huiqin Xie, Yingjiu Li, Robert H. Deng
Acccred: Improved Accountable Anonymous Credentials With Dynamic Triple-Hiding Committees, Sijiang Xie, Rui Shi, Yang Yang, Huiqin Xie, Yingjiu Li, Robert H. Deng
Research Collection School Of Computing and Information Systems
Accountable anonymous credentials protect user privacy while holding the accountability of ill-intentioned individuals, which is a critical feature for applications such as online payments and other financial services. Existing accountable anonymous credentials rely on a public committee of trustworthy members who are assumed not to collude and are well protected to perform privacy revocation. However, this assumption is unsound in blockchain-based cryptocurrency systems because the selected committees may involve nodes with significant stakes, and public nodes serving as committee members are vulnerable against targeted attacks from high-computing power adversaries. In this paper, we propose an improved accountable anonymous credential called …
Sigscope: Detecting And Understanding Off‑Chain Message Signing‑Related Vulnerabilities In Decentralized Applications, Sajad Meisami, Hugo Dabadie, Song Li, Yuzhe Tang, Yue Duan
Sigscope: Detecting And Understanding Off‑Chain Message Signing‑Related Vulnerabilities In Decentralized Applications, Sajad Meisami, Hugo Dabadie, Song Li, Yuzhe Tang, Yue Duan
Research Collection School Of Computing and Information Systems
In Web 3.0, an emerging paradigm of building decentralized applications or DApps is off-chain message signing, which has advantages in performance, cost efficiency, and usability compared to conventional transaction-signing schemes. However, message signing burdens DApp developers with extra coding complexity and message designing, leading to new security risks.This paper presents the first systematic study to uncover and characterize the security issues in off-chain message signing schemes and the DApps built atop them. We present a holistic static-analysis framework, SigScope, that uniquely combines the insights extracted from DApp front-end code (HTML and Javascript) off-chain and back-end smart contracts on-chain. We evaluate …