Page 453 - 《软件学报》2026年第2期
P. 453

932                                                        软件学报  2026  年第  37  卷第  2  期


                     Proc. of the 3rd VLDB Workshop on Secure Data Management. Seoul: Springer, 2006. 75–83. [doi: 10.1007/11844662_6]
                 [23]   Zhang XL, Gu DW, Zhang C. Issues of identity verification of typical applications over mobile terminal platform. Chinese Journal of
                     Network and Information Security, 2020, 6(6): 137–151 (in Chinese with English abstract). [doi: 10.11959/j.issn.2096-109x.2020081]
                 [24]   Baum C, Frederiksen T, Hesse J, Lehmann A, Yanai A. PESTO: Proactively secure distributed single sign-on, or how to trust a hacked
                     server. In: Proc. of the 2020 IEEE European Symp. on Security and Privacy. Genoa: IEEE, 2020. 587–606. [doi: 10.1109/EuroSP48549.
                     2020.00044]
                 [25]   Wang  D,  Li  WT,  Wang  P.  Crytanalysis  of  three  anonymous  authentication  schemes  for  multi-server  environment.  Ruan  Jian  Xue
                     Bao/Journal of Software, 2018, 29(7): 1937–1952 (in Chinese with English abstract). http://www.jos.org.cn/1000-9825/5361.htm [doi: 10.
                     13328/j.cnki.jos.005361]
                 [26]   Song YQ, Zhang Y, Xu CX, Li SY, Yang AJ, Cheng N. Edge-cloud-assisted certificate revocation checking: An efficient solution against
                     irresponsible service providers. IEEE Internet of Things Journal, 2023, 10(17): 15563–15580. [doi: 10.1109/JIOT.2023.3264682]
                 [27]   Song YQ, Xu CX, Zhang Y, Li SY. Hardening password-based credential databases. IEEE Trans. on Information Forensics and Security,
                     2024, 19: 469–484. [doi: 10.1109/TIFS.2023.3324326]
                 [28]   Lamport L. Password authentication with insecure communication. Communications of the ACM, 1981, 24(11): 770–772. [doi: 10.1145/
                     358790.358797]
                 [29]   Chang CC, Wu TC. Remote password authentication with smart cards. IEE Proc. E (Computers and Digital Techniques), 1991, 138(3):
                     165–168. [doi: 10.1049/ip-e.1991.0022]
                 [30]   Tsaur WJ. A flexible user authentication scheme for multi-server Internet services. In: Proc. of the 1st Int’l Conf. on Networking. Colmar:
                     Springer, 2001. 174–183. [doi: 10.1007/3-540-47728-4_18]
                 [31]   Alwen J, Chen B, Pietrzak K, Reyzin L, Tessaro S. Scrypt is maximally memory-hard. In: Proc. of the 36th Int’l Conf. on the Theory and
                     Applications of Cryptographic Techniques. Paris: Springer, 2017. 33–62. [doi: 10.1007/978-3-319-56617-7_2]
                 [32]   Alwen J, Chen B, Kamath C, Kolmogorov V, Pietrzak K, Tessaro S. On the complexity of scrypt and proofs of space in the parallel
                     random oracle model. In: Proc. of the 35th Int’l Conf. on the Theory and Applications of Cryptographic Techniques. Vienna: Springer,
                     2016. 358–387. [doi: 10.1007/978-3-662-49896-5_13]
                 [33]   Klein  DV.  “Foiling  the  cracker”:  A  survey  of,  and  improvements  to,  password  security.  In:  Proc.  of  the  1990  USENIX  Security
                     Workshop. Boston, 1990. 5–14.
                 [34]   Wei FS, Ma JF, Li GS, Ma CG. Efficient three-party password-based authenticated key exchange protocol in the standard model. Ruan
                     Jian Xue Bao/Journal of Software, 2016, 27(9): 2389–2399 (in Chinese with English abstract). http://www.jos.org.cn/1000-9825/4861.
                     htm [doi: 10.13328/j.cnki.jos.004861]
                 [35]   Everspaugh A, Chaterjee R, Scott S, Juels A, Ristenpart T. The pythia PRF service. In: Proc. of the 24th USENIX Conf. on Security
                     Symp. Washington: USENIX Association, 2015. 547–562.
                 [36]   Lai RWF, Egger C, Schröder D, Chow SSM. Phoenix: Rebirth of a cryptographic password-hardening service. In: Proc. of the 26th
                     USENIX Conf. on Security Symp. Vancouver: USENIX Association, 2017. 899–916.
                 [37]   Agrawal S, Miao PH, Mohassel P, Mukherjee P. PASTA: Password-based threshold authentication. In: Proc. of the 2018 ACM SIGSAC
                     Conf. on Computer and Communications Security. Toronto: ACM, 2018. 2042–2059. [doi: 10.1145/3243734.3243839]
                 [38]   Meadows C. A more efficient cryptographic matchmaking protocol for use in the absence of a continuously available third party. In: Proc.
                     of the 1986 IEEE Symp. on Security and Privacy. Oakland: IEEE, 1986. 134–137. [doi: 10.1109/SP.1986.10022]
                 [39]   Freedman MJ, Nissim K, Pinkas B. Efficient private matching and set intersection. In: Proc. of the Advances in Cryptology—EUR-
                     OCRYPT 2004. Interlaken: Springer, 2004. 1–19. [doi: 10.1007/978-3-540-24676-3_1]
                 [40]   Chor B, Kushilevitz E, Goldreich O, Sudan M. Private information retrieval. Journal of the ACM, 1998, 45(6): 965–981. [doi: 10.1145/
                     293347.293350]
                 [41]   Goh EJ. Secure indexes. Cryptology ePrint Archive, 2003.
                 [42]   Chang YC, Mitzenmacher M. Privacy preserving keyword searches on remote encrypted data. In: Proc. of the 3rd Int’l Conf. on Applied
                     Cryptography and Network Security. New York: Springer, 2005. 442–455. [doi: 10.1007/11496137_30]
                 [43]   Curtmola R, Garay J, Kamara S, Ostrovsky R. Searchable symmetric encryption: Improved definitions and efficient constructions. In:
                     Proc.  of  the  13th  ACM  Conf.  on  Computer  and  Communications  Security.  Alexandria:  ACM,  2006.  79–88.  [doi:  10.1145/1180405.
                     1180417]
                 [44]   Li  SY,  Zhang  Y,  Xu  CX,  Cheng  N,  Liu  Z,  Du  YC,  Shen  XM.  HealthFort:  A  cloud-based  ehealth  system  with  conditional  forward
                     transparency and secure provenance via blockchain. IEEE Trans. on Mobile Computing, 2023, 22(11): 6508–6525. [doi: 10.1109/TMC.
                     2022.3199048]
                 [45]   He  XY,  Zhang  Y,  Li  SY,  Song  YQ,  Li  HW.  Privacy-driven  fine-grained  data  trading.  In:  Proc.  of  the  34th  Annual  Int’l  Symp.  on
   448   449   450   451   452   453   454   455   456   457   458