<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Policies | DIPr Lab at PSU</title><link>https://diprlab.github.io/tag/policies/</link><atom:link href="https://diprlab.github.io/tag/policies/index.xml" rel="self" type="application/rss+xml"/><description>Policies</description><generator>Hugo Blox Builder (https://hugoblox.com)</generator><language>en-us</language><lastBuildDate>Wed, 26 Nov 2025 00:00:00 +0000</lastBuildDate><image><url>https://diprlab.github.io/media/logo_hu_b20e6a1540b35ad9.png</url><title>Policies</title><link>https://diprlab.github.io/tag/policies/</link></image><item><title>PaPrica-PS: Fine-Grained, Dynamic Access Control Policy Enforcement for Pub/Sub Systems</title><link>https://diprlab.github.io/project/pubsubcontrol/</link><pubDate>Wed, 26 Nov 2025 00:00:00 +0000</pubDate><guid>https://diprlab.github.io/project/pubsubcontrol/</guid><description>&lt;p&gt;High-volume publish/subscribe (pub/sub) systems include collections
of hardware and software components such as IoT sensors and the protocols
that connect them. Many of these have heretofore lacked robust security
and privacy controls by default despite there being significant security,
safety, and privacy implications driving the need to control access to
the data they generate and manage.&lt;/p&gt;
&lt;p&gt;Examples of such pub/sub-based systems are those which power critical systems
from smart buildings
and factories to full city-wide device networks.
In this project, we are developing a
fine-grained access control model and enforcement mechanism to
address this gap. Our proposed FGAC model builds upon
Attribute-Based Access Control (ABAC) defining access rules based
on the MQTT protocol message &amp;ldquo;topics&amp;rdquo;, attributes of the subscribers
and publishers to those topics, as well as
ephemeral and per-message context information.&lt;/p&gt;
&lt;p&gt;Our framework is platform-agnostic and we implement the prototype for our
experiments based on an off-the-shelf open source MQTT pub/sub
system without altering the base code of that server itself.&lt;/p&gt;</description></item><item><title>Sieve</title><link>https://diprlab.github.io/project/sieve/</link><pubDate>Sat, 01 Jun 2024 00:00:00 +0000</pubDate><guid>https://diprlab.github.io/project/sieve/</guid><description>&lt;p&gt;SIEVE is a versatile middleware that enhances access control in DBMS, enabling efficient query processing even with a large number of access control policies. We&amp;rsquo;re currently integrating caching to further improve query performance. Additionally, we&amp;rsquo;ve developed a workload generator that simulates various scenarios to test policy models and ensure access control compliance, reflecting real-world conditions.&lt;/p&gt;</description></item></channel></rss>