The University of Tokyo · 컴퓨터과학
Yepeng Ding 교수의 연구실은 분산원장 기반 기술을 핵심으로 하여 데이터 보안, 개인정보 보호, 신원 관리의 탈중앙화를 추구하는 연구를 수행하고 있습니다. 특히 스마트 헬스케어, 분산 데이터베이스, 탈중앙화된 데이터 집계 및 자가주권 신원(SI) 기반의 신뢰 기반 시스템 구축에 초점을 맞추고 있으며, 블록체인과 고도화된 암호화 기법을 융합한 혁신적 아키텍처를 개발하고 있습니다. 연구는 실생활 적용 가능성을 고려해 실용성과 보안성을 동시에 확보하는 데 중점을 두고 있습니다.
표시된 성과는 수집된 데이터 기준으로 산출되며, 일부 차이가 있을 수 있습니다.
Smart health has attracted a huge amount of attention nowadays with the advancement of information and communications technology. Meanwhile, the medical data is imperative to support smart health techniques. However, the storage of medical data faces serious security and privacy issues from the hacktivists, cloud service providers and even medical institutions. Therefore, we propose a novel data repository named Derepo to address these issues by securing the storage with the decentralized access
Access control plays a crucial role in constructing trust in a system. Particularly, it is imperative to enforce a fine-grained access control mechanism to make the access control framework flexible due to the high complexity of untrustworthy environments such as the Internet of Things (IoT) environments. However, traditional access control techniques can be hardly trusted on account of their centralized enforcements and improper distributed computing mechanisms while facing diverse and intricat
Self-sovereign identity (SSI) has gained a large amount of interest. It enables physical entities to retain ownership and control of their digital identities, forming a conceptually decentralized architecture. With the support of distributed ledger technology (DLT), it is possible to implement this conceptually decentralized architecture in practice and further bring technical advantages such as privacy protection, security enhancement, and high availability. However, developing such a relativel
As the infrastructure to provide support for distributed database management systems, the distributed database platform is very important to unify the management of data distributed in intricate environments. However, a traditional distributed database platform with centralized entities faces diverse and serious threats when the central entity is compromised. Consensus mechanisms in distributed ledger technology (DLT) can enhance the capability of defending threats by decentralizing the platform
Data aggregation has been widely implemented as an infrastructure of data-driven systems. However, a centralized data aggregation model requires a set of strong trust assumptions to ensure security and privacy. In recent years, decentralized data aggregation has become realizable based on distributed ledger technology. Nevertheless, the lack of appropriate centralized mechanisms like identity management mechanisms carries risks such as impersonation and unauthorized access. In this paper, we pro
Data aggregation management is paramount in data-driven distributed systems. Conventional solutions premised on centralized networks grapple with security challenges concerning authenticity, confidentiality, integrity, and privacy. Recently, distributed ledger technology has gained popularity for its decentralized nature to facilitate overcoming these challenges. Nevertheless, insufficient identity management introduces risks like impersonation and unauthorized access. In this paper, we propose
Decentralized systems have been widely developed and applied to address security and privacy issues in centralized systems, especially since the advancement of distributed ledger technology. However, it is challenging to ensure their correct functioning with respect to their designs and minimize the technical risk before the delivery. Although formal methods have made significant progress over the past decades, a feasible solution based on formal methods from a development process perspective ha
Best practices of self-sovereign identity (SSI) are being intensively explored in academia and industry. Reusable solutions obtained from best practices are generalized as architectural patterns for systematic analysis and design reference, which significantly boosts productivity and increases the dependability of future implementations. For security-sensitive projects, architects make architectural decisions with careful consideration of security issues and solutions based on formal analysis an
Formal methods are crucial in program specification and verification. Instead of building cases to test functionalities, formal methods specify functionalities as properties and mathematically prove them. Nevertheless, the applicability of formal methods is limited in most development processes due to the requirement of mathematical knowledge for developers. To promote the application of formal methods, we formulate formalism-driven development (FDD), which is an iterative and incremental develo
Decentralized finance (DeFi) is revolutionizing the traditional centralized finance paradigm with its attractive features such as high availability, transparency, and tamper-proofing. However, attacks targeting DeFi services have severely damaged the DeFi market, as evidenced by our investigation of 80 real-world DeFi incidents from 2017 to 2022. Existing methods, based on symbolic execution, model checking, semantic analysis, and fuzzing, fall short in identifying the most DeFi vulnerability ty
Nowadays, numerous services based on large-scale distributed systems have been developed to boost the convenience of human life. On the other side, it becomes a significant challenge to ensure the correctness and properties of these systems due to the complex and nested architecture. Although concurrent separation logic (CSL) has partially tackled the problem by specifying systems and verifying the correctness of them, it faces modularity issues. In this paper, we propose an extended concurrent
Event-driven decentralized systems trigger off-chain functions upon consuming events emitted by decentralized applications deployed on blockchains. However, ensuring dependable, cost-efficient, and flexible event consumption is challenging due to the consensus mechanisms inherent in blockchains. Meanwhile, the need for dependable event consumption has become increasingly critical with the rise of decentralized finance. In this paper, we propose Emer, a reputation-based event consumer that adopts