Runnan Zhang

dblp:180/6678 · DBLP profile ↗
← Back
7ranked-venue papers
4as first author
3since 2021 · last 2024
0000-0002-7537-0546ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 4 · 2 first-author · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2024 Anonymity in Attribute-Based Access Control: Framework and Metric
abstract
Anonymous access is an effective method for preserving privacy in access control. This study assumes that anonymous access control requires both frameworks and policies. Numerous solutions have been proposed for anonymous access at the framework level. In this study, these solutions are analyzed and quantified using a unified attribute-based access control (ABAC) anonymous access reference framework. Anonymous access at the framework level is the first line of defense, and inappropriate policies may undermine subject anonymity. An anonymity metric is proposed at the policy level to prevent authorization authority from re-identification using specific attributes and policies. The anonymity metric evaluates the risk of re-identifying a subject due to inappropriate access requests, as well as subject attribute assignment schemes and policies. This study is the first to focus on anonymity at the policy level in ABAC. Furthermore, a formal definition of anonymity suitable for ABAC is proposed. The feasibility of the proposed anonymity metric is verified through simulations.
Runnan Zhang, Gang Liu 0006, Hongzhaoning Kang, Quan Wang 0006, Bo Wan 0002, Nan Luo
IEEE Trans. Dependable Secur. Comput.1
2021 ABSAC: Attribute-Based Access Control Model Supporting Anonymous Access for Smart Cities
abstract
Smart cities require new access control models for Internet of Things (IoT) devices that preserve user privacy while guaranteeing scalability and efficiency. Researchers believe that anonymous access can protect the private information even if the private information is not stored in authorization organization. Many attribute-based access control (ABAC) models that support anonymous access expose the attributes of the subject to the authorization organization during the authorization process, which allows the authorization organization to obtain the attributes of the subject and infer the identity of the subject. The ABAC with anonymous access proposed in this paper called ABSAC strengthens the identity-less of ABAC by combining homomorphic attribute-based signatures (HABSs) which does not send the subject attributes to the authorization organization, reducing the risk of subject identity re-identification. It is a secure anonymous access framework. Tests show that the performance of ABSAC implementation is similar to ABAC’s performance.
Runnan Zhang, Gang Liu 0006, Shancang Li, Yongheng Wei, Quan Wang 0006
Secur. Commun. Networks1
2021 Improved Bell-LaPadula Model With Break the Glass Mechanism
abstract
The Bell-LaPadula (BLP) model is a widely used access control model for the multilevel security system. The researchers proposed many modified BLP models to express privileges that cannot be expressed by the BLP model. However, these models are not compatible with the BLP model, leading to the transportation cost-prohibitive and difficult to be practically applied. In this article, an improved BLP model incorporated the break the glass (BTG) mechanism is proposed to overcome the limitations of the standard BLP and other modified BLP models. The improved model inherits some of the advantages of BTG, such as policy dynamic modification and fine-grained access control, which gives it wide availability. Additionally, in the implementation, BTG is used as an independent function attached to the original BLP; the proposed BLP model can be easily implemented in systems where BLP models have been implemented. The results of the analysis and simulations showed that the proposed BLP model improves the ability of expressing policy of BLP and achieves fine-grained access control without compromise in security. Compared with other modified BLP models, the proposed BLP model could express policy more effectively and is compatible with the original BLP model.
Runnan Zhang, Gang Liu 0006, Hongzhaoning Kang, Quan Wang 0006, Yumin Tian
IEEE Trans. Reliab.1
2020 Policy Evaluation and Dynamic Management Based on Matching Tree for XACML
abstract
As a widely recognized policy language of access control, the eXtensible Access Control Markup Language (XACML) is widely used with its fine-grained and easy-to-read. With the application of XACML, researchers find that the XACML based policy evaluation and policy management methods can no longer meet the current large-scale requests for efficient access and dynamic management requirements. To improve the performance of policy evaluation based on XACML, we propose a policy evaluation method based on the matching tree to search policy efficiently and avoid the extra consumption of invalid policy participation. Furthermore, we propose a policy dynamic management method based on the matching tree to reduce the scale of the policy to be disabled for management, by adding locks in the tree node and the information mapping table. Through theoretical derivation and the factors that may affect its evaluation performance, we verify the improvement of evaluation efficiency. The simulation also shows the improvement of the evaluation engine based on the matching tree compared with OuenAz.
Hongzhaoning Kang, Gang Liu 0006, Quan Wang 0006, Runnan Zhang, Zichao Zhong, Yumin Tian
TrustCom4
2019 Light Field Retrieval via Focus Variation
Runnan Zhang, Jiasong Sun, Chao Zuo 0001
ICIG (2)1
2017 An improved blp model with response blind area eliminated
abstract
Bell-LaPadula model is the most classical multilevel security access control model, however, the existence of the response blind area in Bell-LaPadula model is a great threat for system. In this paper we propose an improved Bell-LaPadula model combining with obligation mechanism. Response mechanism is also introduced in the improved model which can resolve the disadvantage of response blind area. Furthermore, the security of the improved model and covert channel is analyzed in detail.
Gang Liu 0006, Guofang Zhang, Runnan Zhang, Juan Cui, Quan Wang 0005, Shaomin Ji
ISNCC3
2016 Ts-RBAC: A RBAC model with transformation
Gang Liu 0006, Runnan Zhang, Huimin Song
Comput. Secur.2