|
|
|
题名
|
作者
|
年代
|
出处
|
被引量
|
| 1 | Research on trusted computing and its development显示文摘Trusted computing is a novel technology of information system security. It has become a new tide in worldwide information security area and achieved inspiring accomplishment. In China, the initiative research of trusted computing is not late, and the achievements are plentiful and substantial. Our country is in the front rank of the world in trusted computing. This paper comprehensively illustrates the recent development in theory and technology of trusted computing, introduces some improvements in trusted computing in our country, and proposes our opinions and viewpoints towards the existing problems in trusted computing and its future development. | SHEN ChangXiang ZHANG HuanGuo WANG HuaiMin WANG Ji ZHAO Bo YAN Fei YU FaJiang ZHANG LiQiang XU MingDi | 2010 | Science China(Information Sciences)2010,53,3: | 37 |
| 2 | Extended multivariate public key cryptosystems with secure encryption function显示文摘Advances in quantum computers pose great threats on the currently used public key cryptographic algorithms such as RSA and ECC. As a promising candidate secure against attackers equipped with quantum computational power, multivariate public key cryptosystems (MPKCs) have attracted increasing attention in recently years. Unfortunately, the existing MPKCs can only be used as a multivariate signature scheme, and it remains unknown how to construct an efficient MPKC enabling secure encryption. Furthermore, some multivariate signature schemes have been shown insecure in recent years, and it is also not trivial to build MPKC which can serve as a secure signature scheme. By employing the basic MQ-trapdoors, this paper proposes a novel MPKC and shows how it can be used as a multivariate signature scheme and a multivariate encryption scheme, respectively. The goal is achieved by incorporating our new hash authentication techniques and some modification methods such as the Shamir's minus method. Thorough analysis shows that our schemes are secure and efficient. Our MPKC gives a positive response to the challenges in multivariate public key cryptography. | WANG HouZhen 1,2 , ZHANG HuanGuo 1,2 , WANG ZhangYi 1,2 & TANG Ming 1,2 1 The Key Laboratory of Aerospace Information Security and Trusted Computing, Ministry of Education, School of Computer, Wuhan University, Wuhan 430079, China 2 State Key Laboratory of Software Engineering, Wuhan University, Wuhan 430072, China | 2011 | Science China(Information Sciences)2011,54,6: | 26 |
| 3 | Survey on cyberspace security显示文摘Along with the rapid development and wide application of information technology, human society has entered the information era. In this era, people live and work in cyberspace. Cyberspace is the collection of all information systems; it is the information environment for human survival. Therefore, it is necessary to ensure the security of cyberspace. This paper gives a comprehensive introduction to research and development in this field, with a description of existing problems and some currently active research topics in the areas of cyberspace itself, cyberspace security, cryptography, network security, information system security and information content security. | ZHANG HuanGuo HAN WenBao LAI XueJia LIN DongDai MA JianFeng LI JianHua | 2015 | Science China(Information Sciences)2015,58,11: | 15 |
| 4 | A new perturbation algorithm and enhancing security of SFLASH signature scheme显示文摘This paper introduces the concept of noise factor and noise operation, and constructs a noise group. We present a new perturbation algorithm for enhancing security of multivariate public key cryptosystems (MPKCs). European Consortium SFLASH which derives from Matsumoto-Imai scheme is a fast signature scheme intended for low cost smart cards. It was broken with the differential cryptanalysis by Dubois et al. in 2007. Taking Matsumoto-Imai system as an example, security analysis shows that the new algorithm can powerfully demolish its potential mathematical properties of the public key, and effectively avoid differential cryptanalysis without lowering the effciency of the original algorithm. | WANG HouZhen ZHANG HuanGuo GUAN HaiMing HAN HaiQing | 2010 | Science China(Information Sciences)2010,53,4: | 12 |
| 5 | Static Extracting Method of Software Intended Behavior Based on API Functions Invoking显示文摘The method of extracting and describing the intended behavior of software precisely has become one of the key points in the fields of software behavior's dynamic and trusted authentica-tion. In this paper,the author proposes a specified measure of ex-tracting SIBDS (software intended behaviors describing sets) statically from the binary executable using the software's API functions invoking,and also introduces the definition of the struc-ture used to store the SIBDS in detail. Experimental results dem-onstrate that the extracting method and the storage structure defi-nition offers three strong properties: (i) it can describe the soft-ware's intended behavior accurately; (ii) it demands a small stor-age expense; (iii) it provides strong capability to defend against mimicry attack. | PENG Guojun PAN Xuanchen FU Jianming ZHANG Huanguo | 2008 | Wuhan University Journal of Natural Sciences2008,13,5: | 11 |
| 6 | Capability of evolutionary cryptosystems against differential cryptanalysis显示文摘The evolutionary cryptosystem is a new cryptosystem.This paper studies its security level resisting against differential cryptanalysis.It is shown that the evolutionary cryptosystem possesses higher resistance than its initial fixed cryptosystem against differential cryptanalysis.On the basis of the relationship among the data complexity,the bit advantage and the success rate of differential cryptanalysis,it is proven that more data is needed for attacking the evolutionary cryptosystem when the bit advantage and success rate are identical.Moreover,it is shown that the time complexity for attacking the evolutionary cryptosystem is higher than that of differential attacking its initial fixed cryptosystem with the same amount of plaintext-ciphertext pairs.The research indicates that the evolutionary cryptosystem is more robust than its initial fixed cryptosystem against differential cryptanalysis. | ZHANG HuanGuo 1,2 ,LI ChunLei 1,2 & TANG Ming 1,2 1 School of Computer,Wuhan University,Wuhan 430072,China 2 Key Laboratory of Aerospace Information Security and Trusted Computing of Ministry of Education,Wuhan University,Wuhan 430072,China | 2011 | Science China(Information Sciences)2011,54,10: | 11 |
| 7 | A Resistant Quantum Key Exchange Protocol and Its Corresponding Encryption Scheme显示文摘The emergence of quantum computer will threaten the security of existing public-key cryptosystems,including the Diffie Hellman key exchange protocol,encryption scheme and etc,and it makes the study of resistant quantum cryptography very urgent.This motivate us to design a new key exchange protocol and encryption scheme in this paper.Firstly,some acknowledged mathematical problems was introduced,such as ergodic matrix problem and tensor decomposition problem,the two problems have been proved to NPC hard.From the computational complexity prospective,NPC problems have been considered that there is no polynomial-time quantum algorithm to solve them.From the algebraic structures prospective,non-commutative cryptography has been considered to resist quantum.The matrix and tensor operator we adopted also satisfied with this non-commutative algebraic structures,so they can be used as candidate problems for resisting quantum from perspective of computational complexity theory and algebraic structures.Secondly,a new problem was constructed based on the introduced problems in this paper,then a key exchange protocol and a public key encryption scheme were proposed based on it.Finally the security analysis,efficiency,recommended parameters,performance evaluation and etc.were also been given.The two schemes has the following characteristics,provable security,security bits can be scalable,to achieve high efficiency,quantum resistance,and etc. | MAO Shaowu ZHANG Huanguo WU Wanqing LIU Jinhui LI Shuanbao Wang Houzhen | 2014 | China Communications2014,11,9: | 11 |
| 8 | Lattice-Based Double-Authentication-Preventing Ring Signature for Security and Privacy in Vehicular Ad-Hoc Networks显示文摘Amidst the rapid development of the Internet of Things (loT), Vehicular Ad-Hoc NETwork (VANET), a typical loT application, are bringing an ever-larger number of intelligent and convenient services to the daily lives of individuals. However, there remain challenges for VANETs in preserving privacy and security. In this paper, we propose the first lattice-based Double-Authentication-Preventing Ring Signature (DAPRS) and adopt it to propose a novel privacy-preserving authentication scheme for VANETs, offering the potential for security against quantum computers. The new construction is proven secure against chosen message attacks. Our scheme is more efficient than other ring signature in terms of the time cost of the message signing phase and verification phase, and also in terms of signature length. Analyses of security and efficiency demonstrate that our proposed scheme is provably secure and efficient in the application. | Jinhui Liu Yong Yu Jianwei Jia Shijia Wang Peiru Fan Houzhen Wang Huanguo Zhang | 2019 | Tsinghua Science and Technology2019,24,5: | 10 |
| 9 | A Behavior-Based Remote Trust Attestation Model显示文摘While remote trust attestation is a useful concept to detect unauthorized changes to software, the current mechanism only ensures authenticity at the start of the operating system and cannot ensure the action of running software. Our approach is to use a behavior-based monitoring agent to make remote attestation more flexible, dynamic, and trustworthy. This approach was mostly made possible by extensive use of process information which is readily available in Unix. We also made use of a behavior tree to effectively record predictable behaviors of each process. In this paper, we primarily focus on building a prototype implementation of such framework, presenting one example built on it, successfully find potential security risks in the run time of a ftp program and then evaluate the performance of this model. | ZHANG Huanguo WANG Fan | 2006 | Wuhan University Journal of Natural Sciences2006,11,6: | 10 |
| 10 | Design theory and method of multivariate hash function显示文摘This paper proposes a novel hash algorithm whose security is based on the multivariate nonlinear polynomial equations of NP-hard problem over a finite field and combines with HAIFA iterative framework. Over the current widely used hash algorithms, the new algorithm has the following advantages: its security is based on a recognized difficult mathematical problem; the hash length can be changed freely; its design can be automated such that users may construct specific hash function meeting the actual needs. Furthermore, we discuss the security, efficiency and performance of the new algorithm. Under some related difficult mathematical assumptions and theoretical analysis, the new algorithm is proven practical by the experiment results, and capable of achieving security of an ideal hash function by choosing suitable parameters. In addition, it can also be used as a pseudo-random number generator for the good randomness of its output. | WANG HouZhen ZHANG HuanGuo WU QianHong ZHANG Yu LI ChunLei ZHANG XinYu | 2010 | Science China(Information Sciences)2010,53,10: | 8 |
| 11 | Survey on Key Technology Development and Application in Trusted Computing显示文摘Trusted computing,which can effectively increase the credibility of information system,has made great achievements and is in continuous development. For country who is going to strengthen network construction like China,it is an important fundamental supporting technology worth researching. China is in the international forefront in the field of trusted computing. This paper gives comprehensive introductions to the new development and application of key technologies in trusted computing,such as various trusted platform modules(TPM、TCM、TPCM),TCG Software Stack(TSS),trusted cloud server and Trusted Execution Environment(TEE). We illustrate the progressing and application extension of these technologies and also point out some key problems worth studying in the future. | Juan Wang Yuan Shi Guojun Peng Huanguo Zhang Bo Zhao Fei Yan Fajiang Yu Liqiang Zhang | 2016 | China Communications2016,13,11: | 7 |
| 12 | A public key cryptosystem based on data complexity under quantum environment显示文摘Since the Shor algorithm showed that a quantum algorithm can efficiently calculate discrete logarithms and factorize integers, it has been used to break the RSA, EIGamal, and ECC classical public key cryptosystems. This is therefore a significant issue in the context of ensuring communication security over insecure channels. In this paper, we prove that there are no polynomial-size quantum circuits that can compute all Boolean functions(of which there are 22ncases) in the standard quantum oracle model. Based on this,we propose the notion of data complexity under a quantum environment and suggest that it can be used as a condition for post-quantum computation. It is generally believed that NP-complete problems cannot be solved in polynomial time even with quantum computers. Therefore, a public key cryptosystem and signature scheme based on the difficulty of NP-complete problems and the notion of data complexity are presented here. Finally,we analyze the security of the proposed encryption and signature schemes. | WU WanQing ZHANG HuanGuo WANG HouZhen MAO ShaoWu JIA JianWei LIU JinHui | 2015 | Science China(Information Sciences)2015,58,11: | 6 |
| 13 | A Security-Improved Scheme for Virtual TPM Based on KVM显示文摘Virtual trusted platform module(vTPM) is an important part in building trusted cloud environment. Aiming at the remediation of lack of effective security assurances of vTPM instances in the existing virtual TPM architecture, this paper presents a security-improved scheme for virtual TPM based on kernel-based virtual machine(KVM). By realizing the TPM 2.0 specification in hardware and software, we add protection for vTPM's secrets using the asymmetric encryption algorithm of TPM. This scheme supports the safety migration of a TPM key during VM-vTPM migration and the security association for different virtual machines(VMs) with vTPM instances. We implement a virtual trusted platform with higher security based on KVM virtual infrastructure. The experiments show that the proposed scheme can enhance the security of virtual trusted platform and has fewer additional performance loss for the VM migration with vTPM. | SHI Yuan ZHAO Bo YU Zhao ZHANG Huanguo | 2015 | Wuhan University Journal of Natural Sciences2015,20,6: | 6 |
| 14 | Analysis of affinely equivalent Boolean functions显示文摘By some basic transforms and invariant theory, we give two results: 1) an algorithm, which can be used to judge if two Boolean functions are affinely equivalent and to obtain the equivalence relationship if they are equivalent. This is useful in studying Boolean functions and in engineering. For example, we classify all 8-variable homogeneous bent functions of degree 3 into two classes; 2) Reed-Muller codes R(4,6)/R(1,6), R(3,7)/R(1,7) are classified efficiently. | MENG QingShu ZHANG HuanGuo YANG Min WANG ZhangYi | 2007 | Science in China(Series F)2007,50,3: | 5 |
| 15 | Toward an RSU-unavailable Lightweight Certificateless Key Agreement Scheme for VANETs显示文摘Vehicle ad-hoc networks have developed rapidly these years,whose security and privacy issues are always concerned widely.In spite of a remarkable research on their security solutions,but in which there still lacks considerations on how to secure vehicleto-vehicle communications,particularly when infrastructure is unavailable.In this paper,we propose a lightweight certificateless and oneround key agreement scheme without pairing,and further prove the security of the proposed scheme in the random oracle model.The proposed scheme is expected to not only resist known attacks with less computation cost,but also as an efficient way to relieve the workload of vehicle-to-vehicle authentication,especially in no available infrastructure circumstance.A comprehensive evaluation,including security analysis,efficiency analysis and simulation evaluation,is presented to confirm the security and feasibility of the proposed scheme. | SONG Jun HE Chunjiao ZHANG Lei TANG Shanyu ZHANG Huanguo | 2014 | China Communications2014,11,9: | 5 |
| 16 | Evolutionary cryptography theory based generating method for a secure Koblitz elliptic curve and its improvement by a hidden Markov models显示文摘Considering potential attacks from cloud-computing and quantum-computing,it is becoming nec-essary to provide higher security elliptic curves.The hidden Markov models are introduced for designing the trace-vector computation algorithm to accelerate the search for elliptic curve (EC) base-points.We present a new algorithm for secure Koblitz EC generation based on evolutionary cryptography theory.The algorithm is tested by selecting a secure Koblitz EC over the field F(2 2000),with experiments showing that both the base field and base point of the secure curve generated exceed the parameter range for Koblitz curves recommended by NIST.The base fields generated go beyond 1900 bits,which is higher than the 571 bits recommended by NIST.We also find new secure curves in the range F(2 163)-F(2 571) recommended by NIST.We perform a detailed security analysis of those secure curves,showing that those we propose satisfy the same security criteria as NIST. | WANG Chao ZHANG HuanGuo LIU LiLi | 2012 | Science China(Information Sciences)2012,55,4: | 5 |
| 17 | Evolutionary cryptography against multidimensional linear cryptanalysis显示文摘The evolutionary cryptosystem is a new cryptosystem proposed by a Chinese researcher recently. This paper studies its security level resisting against multidimensional linear cryptanalysis in this paper. It is shown that the evolutionary cryptosystem possesses higher resistance than its initial fixed cryptosystem does for resisting against multidimensional linear cryptanalysis. Multidimensional generalizations of Matsui's Algorithm 1 and Algorithm 2 based on log-likelihood ratio (LLR) statistics are introduced. By the relationship among the data complexity N , the bit advantage a and the success rate P S of these two multidimensional generalized algorithms, it is proven that more data is needed for attacking the evolutionary cryptosystem than that is needed for attacking its initial fixed cryptosystem when the bit advantage and success rate are identical. Moreover, it is shown that both time complexity and memory complexity for attacking the evolutionary cryptosystem are higher than that of attacking its initial fixed cryptosystem with the same data complexity. The research indicates that the evolutionary cryptosystem is more robust than its initial fixed cryptosystem against the multidimensional linear cryptanalysis. | ZHANG HuanGuo LI ChunLei TANG Ming | 2011 | Science China(Information Sciences)2011,54,12: | 5 |
| 18 | Research on Android Malware Detection and Interception Based on Behavior Monitoring显示文摘Focusing on the sensitive behaviors of malware, such as privacy stealing and money costing, this paper proposes a new method to monitor software behaviors and detect malicious applications on Android platform. According to the theory and implementation of Android Binder interprocess communication mechanism, a prototype system that integrates behavior monitoring and intercepting, malware detection, and identification is built in this work. There are 50 different kinds of samples used in the experiment of malware detection, including 40 normal samples and 10 malicious samples. The theoretical analysis and experimental result demonstrate that this system is effective in malware detection and interception, with a true positive rate equal to 100% and a false positive rate less than 3%. | PENG Guojun SHAO Yuru WANG Taige ZHAN Xian ZHANG Huanguo | 2012 | Wuhan University Journal of Natural Sciences2012,17,5: | 5 |
| 19 | XEN Virtual Machine Technology and Its Security Analysis显示文摘This paper interprets the essence of XEN and hardware virtualization technology, which make the virtual machine tech- nology become the focus of people’s attention again because of its impressive performance. The security challenges of XEN are mainly researched from the pointes of view: security bottleneck, security isolation and share, life-cycle, digital copyright protection, trusted virtual machine and managements, etc. These security problems significantly affect the security of the virtual machine system based on XEN. At the last, these security measures are put forward, which will be a useful instruction on enhancing XEN security in the future. | XUE Haifeng QING Sihan ZHANG Huanguo | 2007 | Wuhan University Journal of Natural Sciences2007,12,1: | 4 |
| 20 | Toward reverse engineering on secret S-boxes in block ciphers显示文摘It has been widely accepted that the security cryptosystems should be only dependent on the security of their secret keys.However,there are still secret ciphers with unknown components in their commercial applications due to various reasons.The existing reverse engineering analyzes are developed for analyzing specific ciphers,and cannot cope with secret algorithms with diferent structures.By looking into the common characteristics of the secret algorithms of ciphers implemented with unknown S-boxes,we proposed a novel reverse engineering analysis approach referred to as Signed Reverse Engineering based on Diferential Power Analysis(SREDPA).It is a generic reverse engineering analysis and can recover the parameters of the secret S-boxes of the block ciphers in typical structures such as SPN,Feistel,and XFeistel(eXtended Feistel).By identifying the bias of the diferential power analysis(DPA)traces,we build the theoretical model of SREDPA and prove its efectiveness.Experiments are performed on secret algorithms in diferent structures and further validate our SREDPA experimentally.The complexity of SREDPA only relies on the size of S-boxes and the reverse engineering analysis is efcient.As shown in the theoretical analysis and the conducted experiments,our SREDPA approach is readily to be extended for analyzing other secret ciphers with unknown S-boxes.This renders a new challenge on the design and implementation of secret ciphers. | TANG Ming QIU ZhenLong PENG HongBo HU XiaoBo YI Mu ZHANG HuanGuo | 2014 | Science China(Information Sciences)2014,57,3: | 4 |