EDBT 2026 Demo / reviewers in the wild / expert
Jatinder Singh
dblp:53/3181
· DBLP profile ↗
35ranked-venue papers
6as first author
15since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Human-computer interaction and ubiquitous computing · 12 · 10 since 2021Computer networks · 5 · 1 first-author · 1 since 2021Security and privacy · 4 · 1 first-author · 1 since 2021Artificial intelligence and machine learning · 3 · 2 since 2021Databases, data management, data science and information retrieval · 2 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 2Systems, architecture and hardware · 1Software engineering, systems software and programming languages · 1 · 1 first-authorGraphics, computer vision, multimedia, augmented reality and games · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Who Does What? Archetypes of Roles Assigned to LLMs During Human-AI Decision-MakingabstractLLMs are increasingly supporting decision-making across high-stakes domains, requiring critical reflection on the socio-technical factors that shape how humans and LLMs are assigned roles and interact during human-in-the-loop decision-making. This paper introduces the concept of human-LLM archetypes – defined as recurring socio-technical interaction patterns that structure the roles of humans and LLMs in collaborative decision-making. We describe 17 human-LLM archetypes derived from a scoping literature review and thematic analysis of 113 LLM-supported decision-making papers. Then, we evaluate these diverse archetypes across real-world clinical diagnostic cases to examine the potential effects of adopting distinct human-LLM archetypes on LLM outputs and decision outcomes. Finally, we present relevant tradeoffs and design choices across human-LLM archetypes, including decision control, social hierarchies, cognitive forcing strategies, and information requirements. Through our analysis, we show that selection of human-LLM interaction archetype can influence LLM outputs and decisions, bringing important risks and considerations for the designers of human-AI decision-making systems. Shreya Chappidi, Jatinder Singh, Andra Valentina Krauze |
CHI | 2 |
| 2026 | "It's Just a Wild, Wild West": Harnessing Public Procurement as an AI Governance MechanismabstractPublic sector AI has the potential to harm citizens, with risks increasing as its use expands. Recent work positions public procurement as a way to shape public sector AI in line with public interests, using the state’s purchasing power to influence which AI systems are procured and under what conditions. This paper examines how this potential can be realised in practice by drawing on semi-structured interviews with UK and EU buyers, providers, and procurement experts. Our findings result in six promising procurement practices that enable the public sector to shape AI in line with public interests, alongside concrete mechanisms to support their uptake. Further, we find that AI-specific procurement approaches remain immature and systems often enter through informal channels with less scrutiny. We provide directions for both research and practice on how public procurement can be used as a governance mechanism for better aligning AI with public interests. Anna Ida Hudig, Emma Kallina, Jatinder Singh |
CHI | 3 |
| 2026 | The Limits of Stakeholder Participation in Safety-Critical Contexts: Lessons from Air Traffic ControlabstractCalls for participatory AI development often assume that stakeholders can and should be empowered to substantially shape the system. However, competing demands of e.g. safety-critical contexts might limit this. Exploring this tension, we conducted a case study of Air Traffic Control (ATC) system development. Interviews with ATC operators (n=11) and a focus group including R&D employees (n=11) uncovered that controllers were dissatisfied: their input was confined to small changes; major decisions were made through opaque processes. Further, safety-related considerations often limited the extent to which their input could be incorporated. Importantly, controllers acknowledged that safety should take priority over e.g. their usability needs, instead calling for more transparency over decision-making processes and considered factors. Our findings highlight how general calls for empowerment might not align with safety-critical (and other) requirements. Therefore it is important to engage a wide range of stakeholders to explore conflicting demands before aligning/prioritising these in light of the application context. We outline ways forward for participatory practices with implications for the CHI/responsible AI communities. Emma Kallina, Constanze M. Leeb, Jatinder Singh |
CHI | 3 |
| 2026 | Who Controls the Conversation? User Perspectives on Generative AI (LLM) System PromptsabstractSystem prompts—instructions that shape the behaviour of generative AI systems—strongly influence system outputs and users’ experiences. They define the model’s guidelines, ‘personality’, and guardrails, taking precedence over user inputs. Despite their influence, transparency is limited: system prompts are generally not made public and most platforms instruct models to conceal them, leaving users disconnected from and unaware of a key mechanism guiding and governing their AI interactions. Anna Neumann, Yulu Pi, Jatinder Singh |
CHI | 3 |
| 2025 | Intimate Data Sharing: Enhancing Transparency and Control in Fertility TrackingabstractFertility trackers are popular for self-monitoring menstrual cycles and managing other aspects of reproductive or sexual health. However, the intimate nature of fertility tracking raises particular concerns about potential data (mis)use. Our study deepens understandings of fertility tracker data sharing and presents co-created mechanisms to enhance user agency over their data in intimate contexts. To achieve this, we first analysed the network transmissions from eight fertility tracker products, observing that many data transmissions appear to be tied to particular uses of the tracker and that the products communicate with endpoints associated with various organisations across different countries. This raises concerns about how intimate data is governed, used, and shared. To understand user attitudes towards data sharing in intimate contexts, we then conducted a survey exploring factors influencing user data sharing preferences. Our findings reveal that users desire transparency and control mechanisms and that their willingness to share data is influenced by contextual factors, including the third parties involved, the purposes of data collection, and the sensitivity of the data. Building on these findings, we worked with users to co-design ten concrete mechanisms for enhancing data transparency and control throughout fertility tracker product usage lifecycles. In all, our mixed-method study provides an in-depth understanding of fertility tracker data flows and preferences and proposes actionable mechanisms designers can utilise to support and protect data rights in intimate data ecosystems. Anna Ida Hudig, Jatinder Singh |
CHI | 2 |
| 2025 | Adaptive Control Policies for Core Network Autoscaling with Meta-RL
Shantanu Verma, Jatinder Singh, José Manuel Sánchez-Vílchez, Guillaume Fraysse |
CNSM | 3 |
| 2024 | Mind The Gap: Designers and Standards on Algorithmic System Transparency for UsersabstractMany call for algorithmic systems to be more transparent, yet it is often unclear for designers how to do so in practice. Standards are emerging that aim to support designers in building transparent systems, e.g by setting testable transparency levels, but their efficacy in this regard is not yet understood. In this paper, we use the ‘Standard for Transparency of Autonomous Systems’ (IEEE 7001) to explore designers’ understanding of algorithmic system transparency, and the degree to which their perspectives align with the standard’s recommendations. Our mixed-method study reveals participants consider transparency important, difficult to implement, and welcome support. However, despite IEEE 7001’s potential, many did not find its recommendations particularly appropriate. Given the importance and increased attention on transparency, and because standards like this purport to guide system design, our findings reveal the need for ‘bridging the gap’, through (i) raising designers’ awareness about the importance of algorithmic system transparency, alongside (ii) better engagement between stakeholders (i.e. standards bodies, designers, users). We further identify opportunities towards developing transparency best practices, as means to help drive more responsible systems going forward. Bianca G. S. Schor, Chris Norval, Ellen Charlesworth, Jatinder Singh |
CHI | 4 |
| 2024 | A Room With an Overview: Toward Meaningful Transparency for the Consumer Internet of ThingsabstractAs our physical environments become ever-more connected, instrumented, and automated, it can be increasingly difficult for users to understand what is happening within them and why. This warrants attention; with the pervasive and physical nature of the Internet of Things (IoT) comes risks of data misuse, privacy, surveillance, and even physical harm. Such concerns come amid increasing calls for more transparency surrounding technologies (in general), as a means for supporting scrutiny and accountability. This article explores the practical dimensions to transparency mechanisms within the consumer IoT. That is, we consider how smart homes might be made more meaningfully transparent, so as to support users in gaining greater understanding, oversight, and control. Through a series of three user-centric studies, we: 1) survey prospective smart home users to gain a general understanding of what meaningful transparency within smart homes might entail; 2) identify categories of user-derived requirements and design elements (design features for supporting smart home transparency) that have been created through two co-design workshops; and 3) validate these through an evaluation with an altogether new set of participants. In all, these categories of requirements and interface design elements provide a foundation for understanding how meaningful transparency might be achieved within smart homes, and introduces several wider considerations for doing so. Chris Norval, Jatinder Singh |
IEEE Internet Things J. | 2 |
| 2023 | Out of Context: Investigating the Bias and Fairness Concerns of "Artificial Intelligence as a Service"abstract“AI as a Service” (AIaaS) is a rapidly growing market, offering various plug-and-play AI services and tools. AIaaS enables its customers (users)—who may lack the expertise, data, and/or resources to develop their own systems—to easily build and integrate AI capabilities into their applications. Yet, it is known that AI systems can encapsulate biases and inequalities that can have societal impact. This paper argues that the context-sensitive nature of fairness is often incompatible with AIaaS’ ‘one-size-fits-all’ approach, leading to issues and tensions. Specifically, we review and systematise the AIaaS space by proposing a taxonomy of AI services based on the levels of autonomy afforded to the user. We then critically examine the different categories of AIaaS, outlining how these services can lead to biases or be otherwise harmful in the context of end-user applications. In doing so, we seek to draw research attention to the challenges of this emerging area. Kornel Lewicki, Michelle Seng Ah Lee, Jennifer Cobbe, Jatinder Singh |
CHI | 4 |
| 2023 | Integrating state prediction into the Deep Reinforcement Learning for the Autoscaling of Core Network FunctionsabstractReinforcement Learning (RL)-based scaling methods have been proposed to automatically scale in or out Network Functions (NFs) according to their traffic load. However, the scaling operation of NFs in real systems has significant scaling process delay which is the time difference between the moment the scaling of a NF is executed and the moment a new instance is ready to handle the incoming traffic, which leads to degrading the performance of basic RL-based approach. In this paper, we propose a Deep Reinforcement Learning (DRL)-based scaling method which integrates state prediction to deal with this delay. The proposed method was evaluated on a testbed based on the Open-Source Magma project that was automated to perform scaling actions of NF. The results show that the proposed method enables to handle a higher load and improves CPU and memory usage by approximately 14% when compared to the baselineDRL-based method. Yoichi Matsuo, Jatinder Singh, Shantanu Verma, Guillaume Fraysse |
NOMS | 2 |
| 2023 | Autoscaling Packet Core Network Functions with Deep Reinforcement LearningabstractThe scalability problem for Network Functions (NFs) is the scaling of cloud resources allocated to NFs according to the workload to guarantee the Quality of Service (QoS). This work investigates how Deep Reinforcement Learning (DRL) can be applied as a proactive solution to this problem and performance is evaluated on a testbed running an Open-Source packet core NF, provided by the Magma project. Dueling Double Deep Q-network (D3QN) algorithm is considered for the DRL method, with a reward function that considers resources usages and workload. Performance of the DRL method is compared to the traditional threshold-based approach on the testbed. Results show DRL-based scaling methods improve the QoS by reducing the number of dropped sessions by a factor of up to 100 while keeping resources usage in a defined range. Jatinder Singh, Shantanu Verma, Yoichi Matsuo, Francesca Fossati, Guillaume Fraysse |
NOMS | 1 |
| 2021 | Monitoring AI Services for MisuseabstractGiven the surge in interest in AI, we now see the emergence of Artificial Intelligence as a Service (AIaaS). AIaaS entails service providers offering remote access to ML models and capabilities at arms-length', through networked APIs. Such services will grow in popularity, as they enable access to state-of-the-art ML capabilities, 'on demand', 'out of the box', at low cost and without requiring training data or ML expertise. However, there is much public concern regarding AI. AIaaS raises particular considerations, given there is much potential for such services to be used to underpin and drive problematic, inappropriate, undesirable, controversial, or possibly even illegal applications. A key way forward is through service providers monitoring their AI services to identify potential situations of problematic use. Towards this, we elaborate the potential for 'misuse indicators' as a mechanism for uncovering patterns of usage behaviour warranting consideration or further investigation. We introduce a taxonomy for describing these indicators and their contextual considerations, and use exemplars to demonstrate the feasibility analysing AIaaS usage to highlight situations of possible concern. We also seek to draw more attention to AI services and the issues they raise, given AIaaS' increasing prominence, and the general calls for the more responsible and accountable use of AI. Seyyed Ahmad Javadi, Chris Norval, Richard Cloete, Jatinder Singh |
AIES | 4 |
| 2021 | Risk Identification Questionnaire for Detecting Unintended Bias in the Machine Learning Development LifecycleabstractUnintended biases in machine learning (ML) models have the potential to introduce undue discrimination and exacerbate social inequalities. The research community has proposed various technical and qualitative methods intended to assist practitioners in assessing these biases. While frameworks for identifying the risks of harm due to unintended biases have been proposed, they have not yet been operationalised into practical tools to assist industry practitioners. Michelle Seng Ah Lee, Jatinder Singh |
AIES | 2 |
| 2021 | The Landscape and Gaps in Open Source Fairness ToolkitsabstractWith the surge in literature focusing on the assessment and mitigation of unfair outcomes in algorithms, several open source ‘fairness toolkits’ recently emerged to make such methods widely accessible. However, little studied are the differences in approach and capabilities of existing fairness toolkits, and their fit-for-purpose in commercial contexts. Towards this, this paper identifies the gaps between the existing open source fairness toolkit capabilities and the industry practitioners’ needs. Specifically, we undertake a comparative assessment of the strengths and weaknesses of six prominent open source fairness toolkits, and investigate the current landscape and gaps in fairness toolkits through an exploratory focus group, a semi-structured interview, and an anonymous survey of data science/machine learning (ML) practitioners. We identify several gaps between the toolkits’ capabilities and practitioner needs, highlighting areas requiring attention and future directions towards tooling that better support ‘fairness in practice.’ Michelle Seng Ah Lee, Jatinder Singh |
CHI | 2 |
| 2021 | Artificial intelligence as a service: Legal responsibilities, liabilities, and policy challenges
Jennifer Cobbe, Jatinder Singh |
Comput. Law Secur. Rev. | 2 |
| 2020 | Monitoring Misuse for Accountable 'Artificial Intelligence as a Service'abstractAI is increasingly being offered 'as a service' (AIaaS). This entails service providers offering customers access to pre-built AI models and services, for tasks such as object recognition, text translation, text-to-voice conversion, and facial recognition, to name a few. The offerings enable customers to easily integrate a range of powerful AI-driven capabilities into their applications. Customers access these models through the provider's APIs, sending particular data to which models are applied, the results of which returned. Seyyed Ahmad Javadi, Richard Cloete, Jennifer Cobbe, Michelle Seng Ah Lee, Jatinder Singh |
AIES | 5 |
| 2020 | A Call for Auditable Virtual, Augmented and Mixed RealityabstractXR (Virtual, Augmented and Mixed Reality) technologies are growing in prominence. However, they are increasingly being used in sectors and in situations that can result in harms. As such, this paper argues the need for auditability to become a key consideration of XR systems. Auditability entails capturing information of a system’s operation to enable oversight, inspection or investigation. Things can and will go wrong, and information that helps unpack situations of failure or harm, and that enables accountability and recourse, will be crucial to XR’s adoption and acceptance. In drawing attention to the urgent need for auditability, we illustrate some risks associated with XR technology and their audit implications, and present some initial findings from a survey with developers indicating the current ‘haphazard’ approach towards such concerns. We also highlight some challenges and considerations of XR audit in practice, as well as areas of future work for taking this important area of research forward. Richard Cloete, Chris Norval, Jatinder Singh |
VRST | 3 |
| 2020 | Reviewable Automated Decision-Making
Jennifer Cobbe, Jatinder Singh |
Comput. Law Secur. Rev. | 2 |
| 2019 | SGX-PySpark: Secure Distributed Data AnalyticsabstractData analytics is central to modern online services, particularly those data-driven. Often this entails the processing of large-scale datasets which may contain private, personal and sensitive information relating to individuals and organisations. Particular challenges arise where cloud is used to store and process the sensitive data. In such settings, security and privacy concerns become paramount, as the cloud provider is trusted to guarantee the security of the services they offer, including data confidentiality. Therefore, the issue this work tackles is “How to securely perform data analytics in a public cloud?” Do Le Quoc, Franz Gregor, Jatinder Singh, Christof Fetzer |
WWW | 3 |
| 2018 | Data provenance to audit compliance with privacy policy in the Internet of Things
Thomas Pasquier, Jatinder Singh, Julia E. Powles, David M. Eyers, Margo I. Seltzer, Jean Bacon |
Pers. Ubiquitous Comput. | 2 |
| 2017 | Internet of Things Ecosystems: Unpacking Legal Relationships and LiabilitiesabstractThis paper provides a survey of key legal questions arising from the development of Internet of Things ecosystems. We analyse in particular the types of relationships and liabilities that are likely to emerge as Internet of Things ecosystems evolve and we consider implications for both organisations and individuals by reference to specific legal and regulatory considerations. In terms of jurisdictional scope, our main focus is the EU but we also provide examples from other parts of the world. Christopher Millard, W. Kuan Hon, Jatinder Singh |
IC2E | 3 |
| 2017 | Camflow: Managed Data-Sharing for Cloud ServicesabstractA model of cloud services is emerging whereby a few trusted providers manage the underlying hardware and communications whereas many companies build on this infrastructure to offer higher level, cloud-hosted PaaS services and/or SaaS applications. From the start, strong isolation between cloud tenants was seen to be of paramount importance, provided first by virtual machines (VM) and later by containers, which share the operating system (OS) kernel. Increasingly it is the case that applications also require facilities to effect isolation and protection of data managed bythose applications. They also require flexible data sharingwith other applications, often across the traditional cloud-isolation boundaries; for example, when government, consisting of different departments, provides services to its citizens through a common platform. These concerns relate to the management of data. Traditional access control is application and principal/role specific, applied at policy enforcement points, after which there is no subsequent control over where data flows;a crucial issue once data has left its owner's control by cloud-hosted applications andwithin cloud-services. Information Flow Control (IFC), in addition, offers system-wide, end-to-end, flow control based on the properties of the data. We discuss the potential of clouddeployed IFC for enforcingowners' data flow policy with regard to protection and sharing, aswell as safeguarding against malicious or buggy software. In addition, the audit log associated with IFC provides transparency and offers system-wide visibility over data flows. This helps those responsible to meet their data management obligations, providing evidence of compliance, and aids in the identification ofpolicy errors and misconfigurations. We present our IFC model and describe and evaluate our IFC architecture and implementation (CamFlow). This comprises an OS level implementation of IFC with support for application management, together with an IFC-enabled middleware. Thomas Pasquier, Jatinder Singh, David M. Eyers, Jean Bacon |
IEEE Trans. Cloud Comput. | 2 |
| 2017 | Fuzzy Based Advanced Hybrid Intrusion Detection System to Detect Malicious Nodes in Wireless Sensor NetworksabstractIn this paper, an Advanced Hybrid Intrusion Detection System (AHIDS) that automatically detects the WSNs attacks is proposed. AHIDS makes use of cluster-based architecture with enhanced LEACH protocol that intends to reduce the level of energy consumption by the sensor nodes. AHIDS uses anomaly detection and misuse detection based on fuzzy rule sets along with the Multilayer Perceptron Neural Network. The Feed Forward Neural Network along with the Backpropagation Neural Network are utilized to integrate the detection results and indicate the different types of attackers (i.e., Sybil attack, wormhole attack, and hello flood attack). For detection of Sybil attack, Advanced Sybil Attack Detection Algorithm is developed while the detection of wormhole attack is done by Wormhole Resistant Hybrid Technique. The detection of hello flood attack is done by using signal strength and distance. An experimental analysis is carried out in a set of nodes; 13.33% of the nodes are determined as misbehaving nodes, which classified attackers along with a detection rate of the true positive rate and false positive rate. Sybil attack is detected at a rate of 99,40%; hello flood attack has a detection rate of 98, 20%; and wormhole attack has a detection rate of 99, 20%. Rupinder Singh, Jatinder Singh, Ravinder Singh |
Wirel. Commun. Mob. Comput. | 2 |
| 2016 | Information Flow Audit for PaaS CloudsabstractWith the rapid increase in uptake of cloud services, issues of data management are becoming increasingly prominent. There is a clear, outstanding need for the ability for specified policy to control and track data as it flows throughout cloud infrastructure, to ensure that those responsible for data are meeting their obligations. This paper introduces Information Flow Audit, an approach for tracking information flows within cloud infrastructure. This builds upon CamFlow (Cambridge Flow Control Architecture), a prototype implementation of our model for data-centric security in PaaS clouds. CamFlow enforces Information Flow Control policy both intra-machine at the kernel-level, and inter-machine, on message exchange. Here we demonstrate how CamFlow can be extended to provide data-centric audit logs akin to provenance metadata in a format in which analyses can easily be automated through the use of standard graph processing tools. This allows detailed understanding of the overall system. Combining a continuously enforced data-centric security mechanism with meaningful audit empowers tenants and providers to both meet and demonstrate compliance with their data management obligations. Thomas Pasquier, Jatinder Singh, Jean Bacon, David M. Eyers |
IC2E | 2 |
| 2016 | Big ideas paper: Policy-driven middleware for a legally-compliant Internet of Things
Jatinder Singh, Thomas Pasquier, Jean Bacon, Julia E. Powles, Raluca Diaconu, David M. Eyers |
Middleware | 1 |
| 2016 | Data-Centric Access Control for Cloud ComputingabstractThe usual approach to security for cloud-hosted applications is strong separation. However, it is often the case that the same data is used by different applications, particularly given the increase in data-driven (`big data' and IoT) applications. We argue that access control for the cloud should no longer be application-specific but should be data-centric, associated with the data that can flow between applications. Indeed, the data may originate outside cloud services from diverse sources such as medical monitoring, environmental sensing etc. Information Flow Control (IFC) potentially offers data-centric, system-wide data access control. It has been shown that IFC can be provided at operating system level as part of a PaaS offering, with an acceptable overhead. Thomas Pasquier, Jean Bacon, Jatinder Singh, David M. Eyers |
SACMAT | 3 |
| 2016 | Twenty Security Considerations for Cloud-Supported Internet of ThingsabstractTo realize the broad vision of pervasive computing, underpinned by the “Internet of Things” (IoT), it is essential to break down application and technology-based silos and support broad connectivity and data sharing; the cloud being a natural enabler. Work in IoT tends toward the subsystem, often focusing on particular technical concerns or application domains, before offloading data to the cloud. As such, there has been little regard given to the security, privacy, and personal safety risks that arise beyond these subsystems; i.e., from the wide-scale, cross-platform openness that cloud services bring to IoT. In this paper, we focus on security considerations for IoT from the perspectives of cloud tenants, end-users, and cloud providers, in the context of wide-scale IoT proliferation, working across the range of IoT technologies (be they things or entire IoT subsystems). Our contribution is to analyze the current state of cloud-supported IoT to make explicit the security considerations that require further work. Jatinder Singh, Thomas Pasquier, Jean Bacon, Hajoon Ko, David M. Eyers |
IEEE Internet Things J. | 1 |
| 2015 | Managing Big Data with Information Flow ControlabstractConcern about data leakage is holding back more widespread adoption of cloud computing by companies and public institutions alike. To address this, cloud tenants/applications are traditionally isolated in virtual machines or containers. But an emerging requirement is for cross-application sharing of data, for example, when cloud services form part of an IoT architecture. Information Flow Control (IFC) is ideally suited to achieving both isolation and data sharing as required. IFC enhances traditional Access Control by providing continuous, data-centric, cross-application, end-to-end control of data flows. However, large-scale data processing is a major requirement of cloud computing and is infeasible under standard IFC. We present a novel, enhanced IFC model that subsumes standard models. Our IFC model supports `Big Data' processing, while retaining the simplicity of standard IFC and enabling more concise, accurate and maintainable expression of policy. Thomas Pasquier, Jatinder Singh, Jean Bacon, Olivier Hermant |
CLOUD | 2 |
| 2015 | Clouds of Things Need Information Flow Control with Hardware Roots of TrustabstractThere is a clear, outstanding need for new security mechanisms that allow data to be managed and controlled within the cloud-enabled Internet of Things. Towards this, we propose an approach based on Information Flow Control (IFC) that allows: (1) the continuous, end-to-end enforcement of data flow policy, and (2) the generation of provenance-like audit logs to demonstrate policy adherence and contractual/regulatory compliance. Further, we discuss the role of Trusted Platform Modules (TPMs) in supporting such a system, by providing hardware roots of trust. TPMs can be leveraged to validate software configurations, including the IFC enforcement mechanism, both in the cloud and externally via remote attestation. Thomas Pasquier, Jatinder Singh, Jean Bacon |
CloudCom | 2 |
| 2015 | Information Flow Control for Strong Protection with Flexible Sharing in PaaSabstractThe need to share data across applications is becoming increasingly evident. Current cloud isolation mechanisms focus solely on protection, such as containers that isolate at the OS-level, and virtual machines that isolate through the hypervisor. However, by focusing rigidly on protection, these approaches do not provide for controlled sharing. This paper presents how Information Flow Control (IFC) offers a flexible alternative. As a data-centric mechanism it enables strong isolation when required, while providing continuous, fine grained control of the data being shared. An IFC-enabled cloud platform would ensure that policies are enforced as data flows across all applications, without requiring any special sharing mechanisms. Thomas Pasquier, Jatinder Singh, Jean Bacon |
IC2E | 2 |
| 2015 | Integrating Messaging Middleware and Information Flow ControlabstractSecurity is an ongoing challenge in cloud computing. Currently, cloud consumers have few mechanisms for managing their data within the cloud provider's infrastructure. Information Flow Control (IFC) involves attaching labels to data, to govern its flow throughout a system. We have worked on kernel-level IFC enforcement to protect data flows within a virtual machine (VM). This paper makes the case for, and demonstrates the feasibility of an IFC-enabled messaging middleware, to enforce IFC within and across applications, containers, VMs, and hosts. We detail how such middleware can integrate with local (kernel) enforcement mechanisms, and highlight the benefits of separating data management policy from application/service-logic. Jatinder Singh, Thomas Pasquier, Jean Bacon, David M. Eyers |
IC2E | 1 |
| 2014 | Information Flow Control for Secure Cloud ComputingabstractSecurity concerns are widely seen as an obstacle to the adoption of cloud computing solutions. Information Flow Control (IFC) is a well understood Mandatory Access Control methodology. The earliest IFC models targeted security in a centralised environment, but decentralised forms of IFC have been designed and implemented, often within academic research projects. As a result, there is potential for decentralised IFC to achieve better cloud security than is available today. In this paper we describe the properties of cloud computing-Platform-as-a-Service clouds in particular-and review a range of IFC models and implementations to identify opportunities for using IFC within a cloud computing context. Since IFC security is linked to the data that it protects, both tenants and providers of cloud services can agree on security policy, in a manner that does not require them to understand and rely on the particulars of the cloud software stack in order to effect enforcement. Jean Bacon, David M. Eyers, Thomas Pasquier, Jatinder Singh, Ioannis Papagiannis, Peter R. Pietzuch |
IEEE Trans. Netw. Serv. Manag. | 4 |
| 2011 | Managing Health Information Flows with a Reconfigurable Component-Based MiddlewareabstractHealthcare is becoming increasingly pervasive. Improvements in sensor and mobile communication technologies allow for the constant monitoring of patients and their environment. Infrastructure supporting care services must enable such data to flow to the relevant parties as appropriate to the circumstances. This paper describes our initial work on a policy driven, component-based middleware, illustrating how it manages information flows (through reconfiguration) to account for the dynamic nature of healthcare provisioning. Jatinder Singh, Jean Bacon |
Mobile Data Management (2) | 1 |
| 2007 | Dynamic trust domains for secure, private, technology-assisted livingabstractLarge scale distributed systems comprising many administration domains have been well-researched. An example is a national health service, with domains such as primary care practices, hospitals, specialist clinics, etc. A new and relatively unexplored scenario is technology-assisted living, in which domains are small, dynamically created, and is associated with units of personal living. There is a great deal of commercial interest in providing technology to support assisted living, but services are created in isolation. We explore how such services could be integrated with a system that can ensure security and privacy. We propose to audit both system behaviour and the actions of principals, holding particular regard to the fulfillment of their obligations, to establish a computational expression of the trust to be associated with each principal Jatinder Singh, Jean Bacon, Ken Moody |
ARES | 1 |
| 2004 | Augmenting overlay trees for failure resiliencyabstractOverlay trees typically use directed trees as efficient structures for disseminating information, but their single-path structure means that just one node failure results in the disconnection of all descendants, possibly a significant portion of the graph. The addition of extra "backup" links to a directed tree can provide alternate data paths that significantly reduce the number of nodes disconnected when some set of nodes are removed from the graph. We investigate several deterministic and randomized algorithms for adding such backup links to a directed tree and analyze the connectedness of the resulting graphs when nodes in the network fail with some random probability. We present closed-form approximations and simulation measurements for the connectivity of these augmented trees in networks ranging from hundreds to hundreds of thousands of nodes. We also identify and measure the costs of adding backup links, using simulations and real-world measurements from overlays constructed using PlanetLab latency data. We find that, with node failure rates up to 10%, deterministic backup link selection policies offer comparable resiliency to random backup links with significantly lower overhead and resource usage. Jeremy Silber, Sambit Sahu, Jatinder Singh, Zhen Liu 0001 |
GLOBECOM | 3 |