學者揭手機社交網漏洞 黑客遙控語音功能盜私隱

中文大學兩名信息工程學系教授研究發現,智能手機系統 Android的內置語音「助手」功能,及不少社交平台授權第三方獲取用戶資料的系統,均有保安漏洞。黑客可透過Android這個漏洞獲取用戶的行事日 程、電話簿,甚至冒認用家發短訊、打電話或傳電郵。而社交網站的授權系統則容許黑客假裝成應用程式,竊取用戶的個人資料。學者指不少機構收到報告後已有修 正,但仍建議市民不要將敏感資料上傳到社交網站。

Date: 
Friday, July 10, 2015
Media: 
Ming Pao Daily News

Information Engineering Professors Revealed Sweeping Security Loopholes in Mobile Devices and Social Media

Date: 
2015-07-09
Thumbnail: 
Body: 

Research teams of the Department of Information Engineering have recently revealed serious security loopholes in Android devices and social media.  The findings, which have been released in the ACM Conference on Computer and Communications Security 2014 and Black Hat USA 2014, have drawn wide attention in the research community, industry and media. 

Security Loophole in Android Voice Assistant 

Professor ZHANG Kehuan, Assistant Professor, Department of Information Engineering and his research team have identified a serious vulnerability lying in the Android built-in voice assistant module. A zero-permission malware installed on a user's smartphone could bring the Google Voice Search to the foreground and play some voice commands in the background.  Through voice feedback from Google Voice Search, a remote attacker could steal a user's private data without being noticed.  This attack method bypasses the Android permission protection mechanism.  It is estimated that over 550 million Android phones and tablets users are under threat. 

Professor Zhang’s team found that the zero-permission malware, named VoicEmployer,  once installed on a user's device, could invoke the Voice Dialer mode of Google Voice Search even though the device is locked with a password.  Through voice dialing commands, VoicEmployer can make phone calls to any arbitrary numbers.  The attacker can even send voice commands to make the victim's device send SMS/email and steal the user's private data (such as voicemail, calendar, location, etc.). For example, the attacker can send a voice command: ‘what is my next meeting?’, Google Voice Search, after recognizing the command, may give a voice feedback such as ‘your next calendar entry is ...’, 

Professor Zhang said, ‘We have reported this vulnerability and the corresponding attack schemes to the Google Security Team. The problem has been partly fixed in the subsequent versions of Google Voice Search.  We suggest smartphone users to use applications provided by the official stores only and not to install applications from untrusted sources.’ 

Security Problems in Authentication Protocol of Social Media

Professor LAU Wing-cheong, Associate Professor, Department of Information Engineering and his graduate students, HU Pili and YANG Ronghai, have revealed a series of security problems with the design, implementation and practical deployment of the Open Authentication protocol (OAuth 2.0) which is widely adopted by various online social networks (OSN) worldwide. Exploiting the vulnerabilities, hackers can pass themselves off as application developers to embezzle personal data from over 100 million users within a short period of time. 

OAuth 2.0 protocol has been widely adopted by OSN providers since its inception. Professor Lau’s team has recently discovered that it is vulnerable to the so-called App impersonation attack due to its provision of multiple authorization flows and token types.  Based on their study on 12 major OSN providers, the team found that App impersonation via OAuth 2.0, when combined with additional application-programming interface (API) design features or deficiencies, will enable large-scale exploitation and privacy leaks.  For example, it becomes possible for an attacker to completely crawl an OSN with more than 100 million users within a short period of time and harvest data like the status lists and friend lists which are expected to be private information. 

Professor Lau’s team has developed an automatic testing tool, OAuthTester, to systematically test the safety levels of various applications and social media. It is found that OAuth-related vulnerabilities have been widely spread.  Professor Lau said, ‘Our findings show that it is urgent for industrial practitioners to review their OAuth system design to protect users’ privacy. We have informed all the affected OSN providers and proposed solutions that can be readily deployed.’ 

CUHK Named World’s Most Impactful Research Institution in Telecoms 

The CUHK has recently been named by Thomson Reuters as one of the 10 research institutions in the world with the most impact on telecommunications. Amongst US and European universities, it is the only Asian institution on the list. The recognition was given to 10 institutions having the highest citation impact (research papers being the most highly cited by peers thereby indicating global influence) from 2004 to 2014. Details of the ranking are available in Thomson Reuters’ global innovation report ‘The Future Is Open: 2015 State of Innovation’. 

CUHK embarked on telecommunications research in 1970 when former Vice-Chancellor Professor Charles KAO founded the Department of Electronic Engineering. Professor Kao was the innovator of the ground breaking optical fibre communication that changed the world, and at the same time, he built a long-term research strategy focusing on electronic engineering, as well as information and communications technologies at CUHK. Today, both the departments of Electronic Engineering and Information Engineering have been making great strides in both theories and applications of telecommunications and network research, including but not limited to fiber-optic communications, wireless communications, network coding and network security.

Prof. LAU Wing-cheong (left) and Prof. ZHANG Kehuan revealed sweeping security loopholes in mobile devices and social media.

 

Filter: Dept: 
Faculty
IE
Media Release

中大電訊研究列全球十大

中大最近獲湯森路透社評選為全球十大在電訊研究方面最具影響力的大學之一,更同時是亞太地區唯一入選的大學。湯森路透社根據2004至2014年間各研究機構在電訊領域所發表論文之影響力作評選指標,入選機構之學術研究皆獲同儕學者所廣泛引用。 楊偉豪續指,特別是數據傳輸方面,他與信息工程學系教授劉紹強成功合作開發了兩項創新網絡編碼技術,解決數據傳輸過程中受電磁波干擾及無線傳輸

Date: 
Tuesday, July 7, 2015
Media: 
Hong Kong Commercial Daily

University makes right connections in communications

The Chinese University of Hong Kong has been named one of the world's top 10 research institutions with the most impact on communications.  Its department of information engineering was the only Asian institution on the Thomson Reuters list that published research papers that are the most highly cited by peers.  "I am very pleased to see that our research performance and applications in telecommunications are outstanding and well above international standards," said department chairman Chiu Dah-ming.  Chiu said that the faculty has always been committed to strengthening research in fiber-optic communications, wireless communications, digital signal processing and information theory.

Date: 
Friday, July 3, 2015
Media: 
The Standard

以工程科學探究及修復生命建構

生命構造精密美妙,從器官宏觀的解剖生理學,到細胞納米結構的分子生物學,令人嘆為觀止的例子比比皆是。  舉一個例子 -- 關節的力學設計。一般人走路時,下肢關節 (如臗關節) 受力經常高至體重力的三倍。跑、轉、頓、上、下、蹲等日常生活常做的動作,牽涉複雜的運動力學,關節載荷更可高達體重力的五、六倍。

Date: 
Wednesday, June 17, 2015
Media: 
eTVonline

Best Student Paper Award Featured in WiOpt 2015

Date: 
2015-07-01
Thumbnail: 
Body: 

A Game-Theoretic Analysis of User Behaviors in Crowdsourced Wireless Community Networks

The Network Communications and Economics Lab (NCEL) led by Prof. Jianwei Huang, Department of Information Engineering, CUHK, has recently made a comprehensive analysis of the user behaviors in crowd-sourced Wi-Fi community networks. The research team co-authored by Miss Qian MA, Dr. Lin GAO, and Prof. Jianwei Huang demonstrated that such a novel Wi-Fi network scenario can help to expand the Wi-Fi coverage with a low cost, by incentivizing individual users share their private home Wi-Fi Access Points (APs) with each other. This work won the Best Student Paper Award in IEEE WiOpt 2015, a leading wireless conference focusing on modeling and optimization of wireless networks. 

Driven by the explosive growth of smart mobile device (such as smartphones and tablets) and bandwidth-hunger applications (such as mobile video streaming and Web/File/VoIP), Wi-Fi networks are playing an increasingly important role in carrying a significant amount of mobile data traffic. According to the forecast of Cisco VNI, by the year of 2019, the amount of traffic from smartphones carried by Wi-Fi networks will be 54%, and the amount of traffic from tablets carried by Wi-Fi networks will be 70%.The fast growth of Wi-Fi technology and network is due to several factors, including the low costs of Wi-Fi APs, simple installation, easy management, and high transmission data rates. However, the deployment of large-scale and seamless Wi-Fi networks is often restricted by the limited coverage of each single Wi-Fi AP (typically tens of meters indoors). Hence, despite of the low cost of each Wi-Fi AP, it is often very expensive to deploy enough Wi-Fi APs to entirely cover a large area such as a city or a nation.

The crowd-sourced Wi-Fi community network turns out as a promising solution to expand the Wi-Fi coverage with a low cost. The key idea is to encourage individuals (users) to share their private owned Wi-Fi APs with each other, hence crowdsource the coverage of these private Wi-Fi APs. Such a novel network scenario can fully utilize the capacity of millions of private Wi-Fi APs already installed, hence reducing the requirement of new installations by any single operator. Meanwhile, each user also benefits from joining such a community network, as he can use not only his own AP when staying at home, but also other users' APs when traveling.

One prominent commercial example of such a Wi-Fi community networks is FON, the world largest Wi-Fi operator, which has more than 15 million member Wi-Fi APs globally by May 2015. In FON, the operator incentivizes its customers (users) to share their private home APs with others, by using two different incentive schemes, corresponding to two kinds of memberships: Linus and Bill. As a Linus, a user can use other FON members' APs free of charge, and cannot receive any compensation when other users access his AP. As a Bill, a user needs to pay for using other APs, and meanwhile can receive certain compensation when other users access his AP. Moreover, the above community network is also open for users without owning APs, often called Aliens, who needs to pay for using any AP in the FON network.

Clearly, the success of such a crowd-sourced Wi-Fi network greatly depends on the active participations and contributions of many individual users with private Wi-Fi APs, and hence requires the careful design of a proper economic incentive mechanism. Through the study of user behaviors in crowd-sourced wireless community networks, Prof. Jianwei Huang and his team hope to reveal insight into the underlying economic principles in the crowd-sourced wireless community networks, provide some guideline for the operator to design pricing and incentive mechanism, and eventually promote the long-term and sustainable development of such a novel network scenario.

User Behavior Analysis in the Crowd-sourced Wi-Fi Community Network

A comprehensive analysis of user behaviors is essential for the success of a crowd-sourced Wi-Fi community network. The CUHK research team proposes a two-stage dynamic game model to study user behaviors, where stage I is the users’ membership selections and stage II is the users’ Wi-Fi connection time decisions. In this two-stage dynamic game model proposed by Prof. Huang and his team, users choose the memberships of Linus or Bill in stage I, by comparing the achievable benefits under the two different memberships. Then in stage II, users decide the Wi-Fi connection time on each Wi-Fi AP that he is traveling, taking the network congestion into consideration. The study explores how different users choose different decisions in their membership selections and network connections. The results show that a user with a more popular home location, a smaller travel time, or a smaller network access evaluation is more likely to choose the Bill membership type. The results also show that the Wi-Fi AP with a larger data rate or a smaller price will attract users to connect to it for a longer time.

Through the two-stage dynamic game model, users are able to make the best choices of their memberships when joining the crowd-sourced network, and the best choices of their Wi-Fi connection times when roaming at others’ APs considering the network congestion level. The community network operator is able to design the best pricing and incentive mechanism, hence achieving a win-win situation.

About Network Communications and Economics Lab

The Network Communications and Economics Lab (NCEL) was formed in 2007 by Prof. Jianwei Huang, focusing on the interdisciplinary research among communications, networking, and economics.  The NCEL team has published around 180 papers in top international journals and conferences, with a total citation of around 5000 times. The NCEL's research results have received 8 Best Papers Awards in international venues, including the 2011 IEEE Marconi Prize Paper Award in Wireless Communications from IEEE Communications Society and IEEE Signal Processing Society. Four papers from NCEL are among the ESI Highly Cited Papers in the field of Computer Science, which are the 1% top papers in terms of citations within the field according to Essential Science Indicators from Web of Science. 

The co-authors of this awarding winning work also include Ms. Qian Ma, Dr. Lin Gao, and Prof. Yafeng Liu (from Chinese Academy of Science). Ms. Ma is a PhD student under the supervision of Prof. Jianwei Huang. Dr. Lin Gao is a Postdoc Research Fellow in Prof. Jianwei Huang’s team, and received the Best Paper Awards from IEEE WiOpt in 2015, 2014, and 2013.

 

 

(from left) Prof. Jianwei Huang, Miss Qian Ma, and Dr. Lin Gao

 

Filter: Dept: 
Faculty
IE

Innovative Network Coding Techniques Revolutionize Wireless Communications

Date: 
2015-07-02
Thumbnail: 
Body: 

The university has recently been named by Thomson Reuters as one of the 10 research institutions in the world with the most impact on telecommunications. Amongst US and European universities, it is the only Asian institution on the list. The recognition was given to 10 institutions having the highest citation impact (research papers being the most highly cited by peers thereby indicating global influence) from 2004 to 2014. Details of the ranking is available in Thomson Reuters’ global innovation report ‘The Future Is Open: 2015 State of Innovation’. 

CUHK embarked on telecommunications research in 1970 when former Vice-Chancellor Prof. Charles KAO founded the Department of Electronic Engineering. Professor Kao innovated the groundbreaking optical fibre communication that changed the world, and at the same time, he built a long-term research strategy focusing on electronic engineering, as well as information and communications technologies at CUHK. Today, both the departments of Electronic Engineering and Information Engineering have been making great strides in both theories and applications of telecommunications and network research, including but not limited to fiber-optic communications, wireless communications, network coding and network security. 

Prof. TSANG Hon-ki, Chairman, Department of Electronic Engineering, CUHK, said, ‘The recognition given by Thomson Reuters is a reflection on the hard work and contributions of many of our professors in terms of research papers and patents in telecommunications. Our cutting-edge research also ensures that our students receive the most updated education in engineering.’ 

Prof. CHIU Dah-ming, Chairman, Department of Information Engineering, CUHK, said, ‘We are very pleased to see that our research performance and applications in telecommunications are outstanding and well above international standards. The Faculty has always been committed to strengthening the research in fiber-optic communications, wireless communications, digital signal processing and information theory.’ 

CUHK Pioneers Network Coding Technologies 

The network coding theory originated at CUHK is a major breakthrough in information sciences. Its fundamental concept was introduced in the late 1990s, largely due to the work of Prof. YEUNG Wai-ho Raymond, Choh-Ming Li Professor of Information Engineering, and Co-Director, Institute of Network Coding, CUHK, and his research team. Network coding is a technique that replaces routers with coders that transmit ‘evidence’ of a message instead of sending the message itself. The receiver can deduce the original message by the evidence collected, making network communications more efficient, reliable, stable and secure. 

The textbook authored by Professor Yeung ‘Information Theory and Network Coding’ has been widely adopted in top research institutes including MIT, Caltech, Stanford University and University of California, Berkeley. Professor Yeung and his collaborators have recently been granted the prestigious 2016 IEEE Eric E. Sumner Award for their pioneering contributions to the field of network coding. They are the first research team in Asia Pacific to receive this honour. 

Latest Network Coding Technique Tackles Data Loss

Professor Yeung’s research team has recently put forward the BATched Sparse Code (BATS code), one of the most mature network coding techniques in the world. It overcomes the problem of data loss during wireless transmission and offers higher speed, reliability and stability. Compared with conventional random linear network coding, BATS codes offer a lower encoding and decoding complexity, and require a much smaller buffer size at the intermediate nodes. For example, for a multihop network with 20% rate loss per link, BATS code can increase the transmission rate by 56% and reduce the loss rate by 29%.  BATS has already obtained a number of patents from different countries and the team is now working towards its future applications in 5G wireless communications, satellite communications, Internet of Things, and wireless sensor/mesh networks. 

Addressing the Interference Bottleneck Problem

In conventional wireless networks, mutual interferences among wireless devices are viewed as hindrances to efficient communications. For instance, when many people at a time use the free Wi-Fi network at the airport, the internet speed will be very slow due to concurrent access and mutual interference among the users’ devices.  Having devoted 10 years of time, Prof. LIEW Soung-chang, Division Head of Information Engineering, and Co-Director, Institute of Network Coding, CUHK, and his research team have successfully developed and prototyped the revolutionary Physical-layer Network Coding (PNC) as a promising technique that can significantly improve the capacity and energy efficiency of wireless networks by tackling the wireless interference problem. PNC turns interferences from a disadvantage to an advantage by efficiently harnessing the hidden useful information contained in the interferences. 

Professor Liew said, ‘Compared with conventional schemes, PNC can accommodate a larger number of wireless devices in a wireless network without sacrificing the speed. The essence of PNC is to harness multi-user interferences and allows multiple devices to transmit their messages simultaneously. PNC efficiently addresses the interference bottleneck problem in wireless networks, leading to a dramatically improved system throughput by 100%.’ PNC has immense application potential, including earth-to-space communications. The new communication paradigm brought forth by PNC has attracted much attention of researchers in the field of wireless communications and networking. To date, many international journals and academic workshops have been studying the new research outcomes of PNC. 

A Hong Kong Success Story 

CUHK established The Institute of Network Coding (INC) in 2010 with a funding of over HK$80 million from the University Grants Committee. Led by Professor Yeung and others, the Institute conducts cutting-edge research on the theory of network coding and its various applications in Internet communications, wireless communications, information security, data storage and bioinformatics. Professor Yeung hopes to further enhance Hong Kong’s leading position in network coding, adding another chapter to this particular Hong Kong success story, and building in Hong Kong a world-leading network coding centre by maintaining a world-class research team with comprehensive expertise covering all areas of Network Coding. He also hopes in the long term the INC will continue to attract overseas investors to set up research institutes and to develop related industries in Hong Kong, which will have a positive impact on the local economy. 

‘Originated at CUHK, network coding theory has now been developed into an important research field. I am very honoured by this, and I hope our research results will bring  significant impact to the world,’ said Prof. Yeung.

(from left) Prof. CHIU Dah-ming, Chairman, Department of Information Engineering; Prof. LIEW Soung-chang, Division Head of Information Engineering, and Co-Director of Institute of Network Coding; Prof. YEUNG Wai-ho Raymond, Choh-Ming Li Professor of Information Engineering, and Co-Director of Institute of Network Coding; Prof. TSANG Hon-ki, Chairman, Department of Electronic Engineering, CUHK

 

Filter: Dept: 
Faculty
EE
IE
Media Release

與生活息息相關的「無線射頻識別」(RFID)

「嘟」, 相信普遍香港市民對這聲音都不會陌生。每天乘搭交通工具,我們都會拿出「八達通」拍一拍,聽一聽這令旅途暢通無阻的聲音。如果聽不到,那便要煩惱哪裡找出 零錢來繳付車費了。「八達通」其實是運用了RFID (Radio Frequency Identification 無線射頻識別)技術來操作。在適當的距離下,即使沒有物理接觸亦能讀取卡中的資料。

Date: 
Wednesday, May 20, 2015
Media: 
eTVonline

工程設計及應用

工程設計是一個結合系統化與智慧的進程。其中設計者為了革新性地得到不同的設備、器械或系統,從而去創造、具體定義和評估各種設計,務求使這些設計的外形、材料和功能在符合某些特定的限制條件下,實現委託人的目的,以及滿足使用者的需要。工程設計及應用(Engineering Design and Applications)這個課程主要讓學生對工程設計的基礎、過程和步驟有初步概念,並對設計項目的規劃、管理和後期評估有整體的認識。透過學習不同 的設計方法,例如SolidWorks及AutoCAD等繪圖軟件、3D打印等加工技術,來加強學生的創新能力。

Date: 
Thursday, May 7, 2015
Media: 
eTVonline

Pages