Demonstration venue · read-only. Every page can be browsed; the buttons that would change it are switched off. Create an account to run TaxoReview on your own data.

Han Zhang 0037

dblp:26/4189-37 · DBLP profile ↗
← Back
6ranked-venue papers
5as first author
4since 2021 · last 2022
0000-0001-8740-6502ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 3 · 3 first-author · 2 since 2021Security and privacy · 1 · 1 first-author · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Network and information security
2 papers
Cyber-physical and IoT security · 51% Authentication and access control · 49%
Computer networks
1 paper
Internet of things and sensor networks · 100%
Computer architecture, parallel and distributed computing, and storage systems
1 paper
Embedded and real-time systems · 100%

Topics — the 4 heaviest of 5, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Cyber-physical and IoT security
iot privacy
1.122022
Protecting user data through ephemeral ownership of IoT devices · MobiSys 2022
TEO: ephemeral ownership for IoT devices to provide granular data control · MobiSys 2022
Authentication and access control › access control
data access control
0.722022
TEO: ephemeral ownership for IoT devices to provide granular data control · MobiSys 2022
Protecting user data through ephemeral ownership of IoT devices · MobiSys 2022
Internet of things and sensor networks › iot resource management
iot device management
0.512021
Capture: Centralized Library Management for Heterogeneous IoT Devices · USENIX Security Symposium 2021
Authentication and access control › access control › permission management
access revocation
0.322022
Protecting user data through ephemeral ownership of IoT devices · MobiSys 2022
TEO: ephemeral ownership for IoT devices to provide granular data control · MobiSys 2022

Methods — techniques the papers use, named apart from their topics

symbolic protocol verification · 0.6proverif · 0.6protocol design · 0.6
YearPublicationVenuePosition
2022 TEO: ephemeral ownership for IoT devices to provide granular data control
abstract
As Internet-of-Things (IoT) devices rapidly gain popularity, they raise significant privacy concerns given the breadth of sensitive data they can capture. These concerns are amplified by the fact that in many situations, IoT devices collect data about people other than their owner or administrator, and these stakeholders have no say in how that data is managed, used, or shared. To address this, we propose a new model of ownership, IoT Ephemeral Ownership (TEO). TEO allows stakeholders to quickly register with an IoT device for a limited period, and thus claim co-ownership over the sensitive data that the device generates. Device admins retain the ability to decide who may become an ephemeral owner, but no longer have access or control to the private data generated by the device. The encrypted data in TEO is accessible only by entities after seeking explicit permission from the different co-owners of that data. We verify the key security properties of our protocol underpinning TEO in the symbolic model using ProVerif. We also implement a cross-platform prototype of TEO for mobile phones and embedded devices, and integrate it into three real-world application case studies. Our evaluation shows that the latency and battery impact of TEO is typically small, adding ≤ 187 ms onto one-time operations, and introducing limited (<25%) overhead on recurring operations like private data storage.
Han Zhang 0037, Yuvraj Agarwal, Matt Fredrikson
MobiSys1
2022 Protecting user data through ephemeral ownership of IoT devices
abstract
This demonstration presents a working prototype of TEO, a new model of device ownership that divides traditional owners into "admin" and "ephemeral owners". TEO addresses the challenge that users have no say in how their data are managed when the device is controlled by third parties, such as in rental and shared spaces. We design a complete protocol suite to address several practical issues, including preserving data ownership after users stop using the device, minimizing trusts with untrusted storage providers, enabling access control and revocation, and supporting groups of owners. Our cross-platform prototype implementation enables us to demonstrate the operational flow for managing ephemeral ownership of TEO-enabled devices in a representative setup with mobile phones, embedded devices, and Linux servers.
Han Zhang 0037, Yuvraj Agarwal, Matt Fredrikson
MobiSys1
2021 Capture: Centralized Library Management for Heterogeneous IoT Devices
Han Zhang 0037, Abhijith Anilkumar, Matt Fredrikson, Yuvraj Agarwal
USENIX Security Symposium1
2021 Netter: Probabilistic, Stateful Network Models
Han Zhang 0037, Arthur Azevedo de Amorim, Yuvraj Agarwal, Matt Fredrikson, Limin Jia 0001
VMCAI1
2020 Affording Extremes: Incivility, Social Media and Democracy in the Indian Context
abstract
In this mixed-methods study of political discourse, we study the affordances of Twitter in the context of free speech in India. We critically examine specific cases of the legal prosecution of free speech and the use of extreme speech in attacks on people to document the risks to citizens when they engage in antagonistic online discourse, particularly against the state or political institutions. We follow this up with quantitative study of the use of extreme speech through 477 hashtags used by a random sample of thousand political actors on Twitter and find that politicians are rewarded, through higher retweet rates, when they engage in extreme or uncivil messaging. We contextualize these findings to the postcolonial history of India and the laws and institutions that enable differential consequences for engaging in various forms of speech. In conclusion, we propose that the affordances of new ICTs like social media need to be carefully considered for their unintended consequences, and that functional access to free speech may differ dramatically based on one's access to institutions.
Anmol Panda, Sunandan Chakraborty, Noopur Raval, Han Zhang 0037, Mugdha Mohapatra, Syeda Zainab Akbar, Joyojeet Pal
ICTD4
2016 Towards Comprehensive Repositories of Opinions
abstract
Despite the popularity of recommendation services (such as Yelp, Healthgrades, and Angie’s List), for a majority of entities listed on these services, one has to rely on opinions shared by a few users. We argue that this paucity of reviews for most entities stems from the fact that the vast majority of users largely consume opinions shared by others but seldom post reviews themselves. Therefore, leveraging the trend that services are increasingly accessed from a client-side app rather than over the Web, we propose augmenting recommendation services to implicitly infer any user’s opinions based on observations of the user’s activities. Implicit inference of many of a user’s recommendations are feasible due to the rich sensory capabilities of smartphones and wearables as well as the digital footprints left behind by many activities in the physical world. However, implicit inference of opinions is inherently uncertain and automated sharing of inferences raises significant privacy and security concerns. In this paper, we discuss how to tackle these challenges so that users looking for recommendations can draw upon a more comprehensive set of opinions than is the case today.
Han Zhang 0037, Kasra Edalat Nejad, Amir Rahmati, Harsha V. Madhyastha
HotNets1