The University of Tokyo · Computer Science
Professor Yepeng Ding's research lab specializes in decentralized systems and privacy-preserving technologies, focusing on building secure, trustworthy, and scalable infrastructure for data management in distributed environments. The lab explores the integration of distributed ledger technology (DLT), self-sovereign identity (SSI), and homomorphic encryption to address critical challenges in access control, data privacy, and identity management. Key research directions include decentralized database platforms, secure data aggregation frameworks, and privacy-preserving smart health systems.
Figures are computed from collected data and may differ slightly.
Smart health has attracted a huge amount of attention nowadays with the advancement of information and communications technology. Meanwhile, the medical data is imperative to support smart health techniques. However, the storage of medical data faces serious security and privacy issues from the hacktivists, cloud service providers and even medical institutions. Therefore, we propose a novel data repository named Derepo to address these issues by securing the storage with the decentralized access
Access control plays a crucial role in constructing trust in a system. Particularly, it is imperative to enforce a fine-grained access control mechanism to make the access control framework flexible due to the high complexity of untrustworthy environments such as the Internet of Things (IoT) environments. However, traditional access control techniques can be hardly trusted on account of their centralized enforcements and improper distributed computing mechanisms while facing diverse and intricat
Self-sovereign identity (SSI) has gained a large amount of interest. It enables physical entities to retain ownership and control of their digital identities, forming a conceptually decentralized architecture. With the support of distributed ledger technology (DLT), it is possible to implement this conceptually decentralized architecture in practice and further bring technical advantages such as privacy protection, security enhancement, and high availability. However, developing such a relativel
As the infrastructure to provide support for distributed database management systems, the distributed database platform is very important to unify the management of data distributed in intricate environments. However, a traditional distributed database platform with centralized entities faces diverse and serious threats when the central entity is compromised. Consensus mechanisms in distributed ledger technology (DLT) can enhance the capability of defending threats by decentralizing the platform
Data aggregation has been widely implemented as an infrastructure of data-driven systems. However, a centralized data aggregation model requires a set of strong trust assumptions to ensure security and privacy. In recent years, decentralized data aggregation has become realizable based on distributed ledger technology. Nevertheless, the lack of appropriate centralized mechanisms like identity management mechanisms carries risks such as impersonation and unauthorized access. In this paper, we pro
Data aggregation management is paramount in data-driven distributed systems. Conventional solutions premised on centralized networks grapple with security challenges concerning authenticity, confidentiality, integrity, and privacy. Recently, distributed ledger technology has gained popularity for its decentralized nature to facilitate overcoming these challenges. Nevertheless, insufficient identity management introduces risks like impersonation and unauthorized access. In this paper, we propose
Decentralized systems have been widely developed and applied to address security and privacy issues in centralized systems, especially since the advancement of distributed ledger technology. However, it is challenging to ensure their correct functioning with respect to their designs and minimize the technical risk before the delivery. Although formal methods have made significant progress over the past decades, a feasible solution based on formal methods from a development process perspective ha
Best practices of self-sovereign identity (SSI) are being intensively explored in academia and industry. Reusable solutions obtained from best practices are generalized as architectural patterns for systematic analysis and design reference, which significantly boosts productivity and increases the dependability of future implementations. For security-sensitive projects, architects make architectural decisions with careful consideration of security issues and solutions based on formal analysis an
Formal methods are crucial in program specification and verification. Instead of building cases to test functionalities, formal methods specify functionalities as properties and mathematically prove them. Nevertheless, the applicability of formal methods is limited in most development processes due to the requirement of mathematical knowledge for developers. To promote the application of formal methods, we formulate formalism-driven development (FDD), which is an iterative and incremental develo
Decentralized finance (DeFi) is revolutionizing the traditional centralized finance paradigm with its attractive features such as high availability, transparency, and tamper-proofing. However, attacks targeting DeFi services have severely damaged the DeFi market, as evidenced by our investigation of 80 real-world DeFi incidents from 2017 to 2022. Existing methods, based on symbolic execution, model checking, semantic analysis, and fuzzing, fall short in identifying the most DeFi vulnerability ty
Nowadays, numerous services based on large-scale distributed systems have been developed to boost the convenience of human life. On the other side, it becomes a significant challenge to ensure the correctness and properties of these systems due to the complex and nested architecture. Although concurrent separation logic (CSL) has partially tackled the problem by specifying systems and verifying the correctness of them, it faces modularity issues. In this paper, we propose an extended concurrent
Event-driven decentralized systems trigger off-chain functions upon consuming events emitted by decentralized applications deployed on blockchains. However, ensuring dependable, cost-efficient, and flexible event consumption is challenging due to the consensus mechanisms inherent in blockchains. Meanwhile, the need for dependable event consumption has become increasingly critical with the rise of decentralized finance. In this paper, we propose Emer, a reputation-based event consumer that adopts
Open papers in the app to read, cite, and organize with AI.