Page 453 - 《软件学报》2026年第2期
P. 453
932 软件学报 2026 年第 37 卷第 2 期
Proc. of the 3rd VLDB Workshop on Secure Data Management. Seoul: Springer, 2006. 75–83. [doi: 10.1007/11844662_6]
[23] Zhang XL, Gu DW, Zhang C. Issues of identity verification of typical applications over mobile terminal platform. Chinese Journal of
Network and Information Security, 2020, 6(6): 137–151 (in Chinese with English abstract). [doi: 10.11959/j.issn.2096-109x.2020081]
[24] Baum C, Frederiksen T, Hesse J, Lehmann A, Yanai A. PESTO: Proactively secure distributed single sign-on, or how to trust a hacked
server. In: Proc. of the 2020 IEEE European Symp. on Security and Privacy. Genoa: IEEE, 2020. 587–606. [doi: 10.1109/EuroSP48549.
2020.00044]
[25] Wang D, Li WT, Wang P. Crytanalysis of three anonymous authentication schemes for multi-server environment. Ruan Jian Xue
Bao/Journal of Software, 2018, 29(7): 1937–1952 (in Chinese with English abstract). http://www.jos.org.cn/1000-9825/5361.htm [doi: 10.
13328/j.cnki.jos.005361]
[26] Song YQ, Zhang Y, Xu CX, Li SY, Yang AJ, Cheng N. Edge-cloud-assisted certificate revocation checking: An efficient solution against
irresponsible service providers. IEEE Internet of Things Journal, 2023, 10(17): 15563–15580. [doi: 10.1109/JIOT.2023.3264682]
[27] Song YQ, Xu CX, Zhang Y, Li SY. Hardening password-based credential databases. IEEE Trans. on Information Forensics and Security,
2024, 19: 469–484. [doi: 10.1109/TIFS.2023.3324326]
[28] Lamport L. Password authentication with insecure communication. Communications of the ACM, 1981, 24(11): 770–772. [doi: 10.1145/
358790.358797]
[29] Chang CC, Wu TC. Remote password authentication with smart cards. IEE Proc. E (Computers and Digital Techniques), 1991, 138(3):
165–168. [doi: 10.1049/ip-e.1991.0022]
[30] Tsaur WJ. A flexible user authentication scheme for multi-server Internet services. In: Proc. of the 1st Int’l Conf. on Networking. Colmar:
Springer, 2001. 174–183. [doi: 10.1007/3-540-47728-4_18]
[31] Alwen J, Chen B, Pietrzak K, Reyzin L, Tessaro S. Scrypt is maximally memory-hard. In: Proc. of the 36th Int’l Conf. on the Theory and
Applications of Cryptographic Techniques. Paris: Springer, 2017. 33–62. [doi: 10.1007/978-3-319-56617-7_2]
[32] Alwen J, Chen B, Kamath C, Kolmogorov V, Pietrzak K, Tessaro S. On the complexity of scrypt and proofs of space in the parallel
random oracle model. In: Proc. of the 35th Int’l Conf. on the Theory and Applications of Cryptographic Techniques. Vienna: Springer,
2016. 358–387. [doi: 10.1007/978-3-662-49896-5_13]
[33] Klein DV. “Foiling the cracker”: A survey of, and improvements to, password security. In: Proc. of the 1990 USENIX Security
Workshop. Boston, 1990. 5–14.
[34] Wei FS, Ma JF, Li GS, Ma CG. Efficient three-party password-based authenticated key exchange protocol in the standard model. Ruan
Jian Xue Bao/Journal of Software, 2016, 27(9): 2389–2399 (in Chinese with English abstract). http://www.jos.org.cn/1000-9825/4861.
htm [doi: 10.13328/j.cnki.jos.004861]
[35] Everspaugh A, Chaterjee R, Scott S, Juels A, Ristenpart T. The pythia PRF service. In: Proc. of the 24th USENIX Conf. on Security
Symp. Washington: USENIX Association, 2015. 547–562.
[36] Lai RWF, Egger C, Schröder D, Chow SSM. Phoenix: Rebirth of a cryptographic password-hardening service. In: Proc. of the 26th
USENIX Conf. on Security Symp. Vancouver: USENIX Association, 2017. 899–916.
[37] Agrawal S, Miao PH, Mohassel P, Mukherjee P. PASTA: Password-based threshold authentication. In: Proc. of the 2018 ACM SIGSAC
Conf. on Computer and Communications Security. Toronto: ACM, 2018. 2042–2059. [doi: 10.1145/3243734.3243839]
[38] Meadows C. A more efficient cryptographic matchmaking protocol for use in the absence of a continuously available third party. In: Proc.
of the 1986 IEEE Symp. on Security and Privacy. Oakland: IEEE, 1986. 134–137. [doi: 10.1109/SP.1986.10022]
[39] Freedman MJ, Nissim K, Pinkas B. Efficient private matching and set intersection. In: Proc. of the Advances in Cryptology—EUR-
OCRYPT 2004. Interlaken: Springer, 2004. 1–19. [doi: 10.1007/978-3-540-24676-3_1]
[40] Chor B, Kushilevitz E, Goldreich O, Sudan M. Private information retrieval. Journal of the ACM, 1998, 45(6): 965–981. [doi: 10.1145/
293347.293350]
[41] Goh EJ. Secure indexes. Cryptology ePrint Archive, 2003.
[42] Chang YC, Mitzenmacher M. Privacy preserving keyword searches on remote encrypted data. In: Proc. of the 3rd Int’l Conf. on Applied
Cryptography and Network Security. New York: Springer, 2005. 442–455. [doi: 10.1007/11496137_30]
[43] Curtmola R, Garay J, Kamara S, Ostrovsky R. Searchable symmetric encryption: Improved definitions and efficient constructions. In:
Proc. of the 13th ACM Conf. on Computer and Communications Security. Alexandria: ACM, 2006. 79–88. [doi: 10.1145/1180405.
1180417]
[44] Li SY, Zhang Y, Xu CX, Cheng N, Liu Z, Du YC, Shen XM. HealthFort: A cloud-based ehealth system with conditional forward
transparency and secure provenance via blockchain. IEEE Trans. on Mobile Computing, 2023, 22(11): 6508–6525. [doi: 10.1109/TMC.
2022.3199048]
[45] He XY, Zhang Y, Li SY, Song YQ, Li HW. Privacy-driven fine-grained data trading. In: Proc. of the 34th Annual Int’l Symp. on

