東京大学 · 情報科学
Yepeng Ding教授の研究室は、分散型台帳技術(DLT)を基盤に、スマートヘルス、分散型データベース、自己所有型アイデンティティ(SSI)の分野におけるセキュリティとプライバシーの課題に取り組んでいます。特に、ホモomorphic暗号や分散アクセス制御を活用した信頼性の高いデータ管理フレームワークの構築が主な研究テーマです。また、中央集権的信頼に依存しない分散型データアグリゲーションや、自己所有型アイデンティティを活用したセキュアな情報共有基盤の実現を目指しています。
Figures are computed from collected data and may differ slightly.
Smart health has attracted a huge amount of attention nowadays with the advancement of information and communications technology. Meanwhile, the medical data is imperative to support smart health techniques. However, the storage of medical data faces serious security and privacy issues from the hacktivists, cloud service providers and even medical institutions. Therefore, we propose a novel data repository named Derepo to address these issues by securing the storage with the decentralized access
Access control plays a crucial role in constructing trust in a system. Particularly, it is imperative to enforce a fine-grained access control mechanism to make the access control framework flexible due to the high complexity of untrustworthy environments such as the Internet of Things (IoT) environments. However, traditional access control techniques can be hardly trusted on account of their centralized enforcements and improper distributed computing mechanisms while facing diverse and intricat
Self-sovereign identity (SSI) has gained a large amount of interest. It enables physical entities to retain ownership and control of their digital identities, forming a conceptually decentralized architecture. With the support of distributed ledger technology (DLT), it is possible to implement this conceptually decentralized architecture in practice and further bring technical advantages such as privacy protection, security enhancement, and high availability. However, developing such a relativel
As the infrastructure to provide support for distributed database management systems, the distributed database platform is very important to unify the management of data distributed in intricate environments. However, a traditional distributed database platform with centralized entities faces diverse and serious threats when the central entity is compromised. Consensus mechanisms in distributed ledger technology (DLT) can enhance the capability of defending threats by decentralizing the platform
Data aggregation has been widely implemented as an infrastructure of data-driven systems. However, a centralized data aggregation model requires a set of strong trust assumptions to ensure security and privacy. In recent years, decentralized data aggregation has become realizable based on distributed ledger technology. Nevertheless, the lack of appropriate centralized mechanisms like identity management mechanisms carries risks such as impersonation and unauthorized access. In this paper, we pro
Data aggregation management is paramount in data-driven distributed systems. Conventional solutions premised on centralized networks grapple with security challenges concerning authenticity, confidentiality, integrity, and privacy. Recently, distributed ledger technology has gained popularity for its decentralized nature to facilitate overcoming these challenges. Nevertheless, insufficient identity management introduces risks like impersonation and unauthorized access. In this paper, we propose
Decentralized systems have been widely developed and applied to address security and privacy issues in centralized systems, especially since the advancement of distributed ledger technology. However, it is challenging to ensure their correct functioning with respect to their designs and minimize the technical risk before the delivery. Although formal methods have made significant progress over the past decades, a feasible solution based on formal methods from a development process perspective ha
Best practices of self-sovereign identity (SSI) are being intensively explored in academia and industry. Reusable solutions obtained from best practices are generalized as architectural patterns for systematic analysis and design reference, which significantly boosts productivity and increases the dependability of future implementations. For security-sensitive projects, architects make architectural decisions with careful consideration of security issues and solutions based on formal analysis an
Formal methods are crucial in program specification and verification. Instead of building cases to test functionalities, formal methods specify functionalities as properties and mathematically prove them. Nevertheless, the applicability of formal methods is limited in most development processes due to the requirement of mathematical knowledge for developers. To promote the application of formal methods, we formulate formalism-driven development (FDD), which is an iterative and incremental develo
Decentralized finance (DeFi) is revolutionizing the traditional centralized finance paradigm with its attractive features such as high availability, transparency, and tamper-proofing. However, attacks targeting DeFi services have severely damaged the DeFi market, as evidenced by our investigation of 80 real-world DeFi incidents from 2017 to 2022. Existing methods, based on symbolic execution, model checking, semantic analysis, and fuzzing, fall short in identifying the most DeFi vulnerability ty
Nowadays, numerous services based on large-scale distributed systems have been developed to boost the convenience of human life. On the other side, it becomes a significant challenge to ensure the correctness and properties of these systems due to the complex and nested architecture. Although concurrent separation logic (CSL) has partially tackled the problem by specifying systems and verifying the correctness of them, it faces modularity issues. In this paper, we propose an extended concurrent
Event-driven decentralized systems trigger off-chain functions upon consuming events emitted by decentralized applications deployed on blockchains. However, ensuring dependable, cost-efficient, and flexible event consumption is challenging due to the consensus mechanisms inherent in blockchains. Meanwhile, the need for dependable event consumption has become increasingly critical with the rise of decentralized finance. In this paper, we propose Emer, a reputation-based event consumer that adopts
Open papers in the app to read, cite, and organize with AI.