Search arXiv⌕ Search

arXiv subjects

Donna O'Shea

Publications and source records attributed to Donna O'Shea.

3 recordsLinked to original sources

Beyond Centralized Policy Decision Points: Decentralized Sticky Policy Authorization through Evidence Quorums

Sticky policies remain attached to protected data so that access restrictions can persist across systems, yet request-time authorization often still depends on a centralized Trusted Authority or Policy Decision Point (PDP). This paper presents SPEAR-Q, a decentralized framework in which independent Policy Authority Nodes (PANs) evaluate the active sticky policy using local context, consent, and risk information and generate signed authorization evidence. A strict-majority Evidence quorum determines the global Permit or Deny decision, while a committed policy becomes active only after the required PAN majority applies it. SPEAR-Q was deployed across physically separated hosts in the Airbus Cyber Security Simulation Platform and evaluated using a healthcare workload derived from MIMIC-IV. Across 9,000 performance requests, all requests completed without execution failure or timeout. Latency increased and throughput saturated as cluster size and concurrency grew, with PAN evidence waiting and PAN-local processing dominating under load and credential validation forming the main PAN-side cost. Policy-activation experiments confirmed majority-based activation. Quorum experiments showed that correctly signed false-Permit evidence from fewer compromised PANs than the required quorum could not produce a global Permit or resource release, while authorization remained fail-closed when reachable PANs fell below the required quorum. Compared with prior approaches that decentralize policy management, credential authority, or threshold-based release separately, SPEAR-Q integrates persistent sticky policy enforcement, independent request-time evidence, majority-based policy activation, and explicit quorum-bounded authorization within one decentralized framework. Under the evaluated conditions, SPEAR-Q supports decentralized sticky-policy authorization without relying on a centralized decision authority.

cs.CR↗

Preemption Aware Task Scheduling for Priority and Deadline Constrained DNN Inference Task Offloading in Homogeneous Mobile-Edge Networks

This paper addresses the computational offloading of Deep Neural Networks (DNNs) to nearby devices with similar processing capabilities, to avoid the larger communication delays incurred for cloud offloading. We present a preemption aware scheduling approach for priority and deadline constrained task offloading in homogeneous edge networks. Our scheduling approach consists of two distinct scheduling algorithms, designed to accommodate the differing requirements of high and low priority tasks. To satisfy a task's deadline, our scheduling approach considers the availability of both communication and computational resources in the network when making placements in both the current time-slot and future time-slots. The scheduler implements a deadline-aware preemption mechanism to guarantee resource access to high priority tasks. When low-priority tasks are selected for preemption, the scheduler will attempt to reallocate them if possible before their deadline. We implement this scheduling approach into a task offloading system which we evaluate empirically in the real-world on a network of edge devices composed of four Raspberry Pi 2 Model B's. We evaluate this system under against a version without a task preemption mechanism as well as workstealing approaches to compare the impact on high priority task completion and the ability to complete overall frames. These solutions are evaluated under a workload of 1296 frames. Our findings show that our scheduling approach allows for 99\% of high-priority tasks to complete while also providing a 3 - 8\% increase in the number of frames fully classified end-to-end over both workstealing approaches and systems without a preemption mechanism.

cs.DC↗

Performance Analysis of Zero-Trust multi-cloud

Zero Trust security model permits to secure cloud native applications while encrypting all network communication, authenticating, and authorizing every request. The service mesh can enable Zero Trust using a side-car proxy without changes to the application code. To the best of our knowledge, no previous work has provided a performance analysis of Zero Trust in a multi-cloud environment. This paper proposes a multi-cloud framework and a testing workflow to analyze performance of the data plane under load and the impact on the control plane, when Zero Trust is enabled. The results of preliminary tests show that Istio has reduced latency variability in responding to sequential HTTP requests. Results also reveal that the overall CPU and memory usage can increase based on service mesh configuration and the cloud environment.

cs.CR↗