Related Topics
Articles published on Access Control Model
Authors
Select Authors
Journals
Select Journals
Duration
Select Duration
1430 Search results
Sort by Recency
- Research Article
- 10.55041/ijsrem61275
- Apr 27, 2026
- INTERNATIONAL JOURNAL OF SCIENTIFIC RESEARCH IN ENGINEERING AND MANAGEMENT
- Vinnakota Devaki + 3 more
Abstract—Cloud computing has emerged as a pillar of the contemporary digital infrastructure, with the capacity to scale, low costs, and the ability to access data and services everywhere. Nevertheless, the sheer embrace of cloud platforms has come with a major challenge pertaining to the issue of data security, privacy and trust. The current paper outlines a more detailed method of how to improve data protection in the cloud computing setting, entailing the combination of sophisticated cryptographic algorithms, intelligent access control systems, and the use of AI and detector models. The framework proposed covers such key security issues as unauthorized access, data leakage, data breaches, and insider threats. The paper identifies encryption schemes such as symmetric and asymmetric cryptography, homomorphic encryption and secure multi-party computation, as the means to maintain the confidentiality of data stored and relayed. Also, the role-based access control (RBAC) and attribute-based access control (ABAC) models are included to implement fine-grained authorization policies. To build on this added protection, blockchain is proposed to audit data using secure and tamper-proof demonstrations, increasing transparency and accountability to the cloud systems. An important work in this regard is the incorporation of machine learning and artificial intelligence algorithms in real- time threat detection and tracking of anomalies. These models process high-traffic volumes of network traffic and user behavior patterns in order to proactively predict potential security threats and prevent attacks including the Distributed Denial of Service (DDoS), phishing and malware injections. The data integrity verification based on the use of hashing techniques and digital signatures is also a priority in the proposed system. The experimental findings indicate that the proposed scheme is significantly effective in enhancing the metrics of data security, such as low chances of breach, improved detection rates, and less time taken to respond to threats as compared to the traditional methods of security. Also, the framework will guarantee the adherence to data protection policies and assist in achieving cloud security on the multi-cloud environment data sharing. Finally, this study suggests that a multi-layered security approach that uses a combination of encryption, access control, blockchain, and AI-based monitoring are essential in protecting Identify applicable funding agency here. If none, delete this. sensitive data in cloud computing. The next-generation work will aim to enhance computational overhead optimization, scalability, and investigate quantum-resistant cryptographic methods to meet new security demands in the next-generation cloud infrastruc- ture. Index Terms—component, formatting, style, styling, insert
- Research Article
- 10.1038/s41598-026-45550-w
- Apr 3, 2026
- Scientific Reports
- Adiah Qazi + 2 more
Enterprise Resource Planning (ERP) systems serve as critical infrastructure for modern organizations, yet their security assessment lacks standardized evaluation frameworks. This study develops and applies a structured Security Maturity Assessment Framework (SMAF) grounded in NIST Cybersecurity Framework (CSF) 2.0 and ISO/IEC 27001:2022 standards to evaluate eleven cloud-based and hybrid ERP platforms, including both full-suite ERP systems and widely adopted inventory and manufacturing management systems that serve as ERP alternatives for SMEs. Using a weighted multi-criteria decision analysis (MCDA) approach validated by expert surveys (n=47) and vendor documentation analysis, we assess security across five domains: authentication mechanisms, encryption protocols, access control models, vulnerability management, and compliance certifications. Our framework introduces quantifiable security maturity scores ranging from 1 (basic) to 5 (advanced), enabling objective comparison across platforms. Results indicate that enterprise-grade solutions (Oracle NetSuite OneWorld, SAP Business One Professional, Microsoft Dynamics 365) achieve consistently higher security maturity scores (mu =4.63, sigma =0.17) compared to SME-targeted solutions (mu =2.76, sigma =0.39), though small per-segment sample sizes (n=3–4) limit formal statistical inference. We extend our analysis to emerging security paradigms including Zero-Trust Architecture (ZTA) integration, federated learning for privacy-preserving analytics, blockchain-based audit trails, and digital twin implementations for Industry 5.0 alignment. The proposed SMAF provides organizations with an evidence-based methodology for ERP security evaluation, addressing a critical gap in both academic literature and practitioner guidance.
- Research Article
- 10.34216/2587-6147-2026-1-71-40-47
- Apr 2, 2026
- Technologies & Quality
- Maria V Isaeva + 2 more
The article is devoted to the design and implementation of the subsystem of identification and access control in the information management system of design and educational intensive students. The JSON Web Tokens technology has been chosen as the basic authentication mechanism, which ensures secure data transfer without the need to store session status on the server, which complies with the principles of a RESTful architecture and increases the scalability of the system. The paper describes in detail the logic of the module, including the authentication process on the client side using RTK Query. Special attention is paid to the role-based access control model implemented within the system. The concept of the user’s “current role” has been introduced, which allows for the correct handling of scenarios with multiple roles, for which a special permission class has been developed in the Django REST Framework.
- Research Article
- 10.1016/j.aej.2026.03.017
- Apr 1, 2026
- Alexandria Engineering Journal
- Ming Xie + 1 more
A multimodal reinforcement learning-based access control model for power systems under zero-trust architecture
- Research Article
- 10.3389/fbloc.2026.1781539
- Mar 23, 2026
- Frontiers in Blockchain
- Juan Manuel Sobral + 3 more
Blockchain technology continues to promise transformative impact across domains such as supply chains, finance, and the Internet of Things (IoT). However, the rapid growth and increasing heterogeneity of blockchain platforms have made architectural decision-making progressively more complex for software architects. This study extends and updates a previous Multivocal Literature Review (MLR) to systematically identify and characterize active blockchain networks across foundational protocol layers. We analyze key architectural dimensions including consensus mechanisms, decentralization and access control models, smart contract support, block and ledger structures, interoperability features, and architectural lineage. Drawing on both academic and gray literature, we characterize a total of 147 blockchain networks spanning Layers-0 through-2. Our findings reveal an ecosystem largely driven by industrial innovation, with limited consolidation in the formal academic literature. The resulting architectural mappings aim to support software architects in making informed, evidence-based decisions when integrating blockchain technologies into software-intensive systems.
- Research Article
- 10.3389/fbloc.2026.1806905
- Mar 19, 2026
- Frontiers in Blockchain
- Obadah Hammoud + 1 more
Correction: A scaling distributed access control model for blockchain-based file storage systems
- Research Article
- 10.3390/computers15030187
- Mar 13, 2026
- Computers
- Harris Wang
Modern enterprise information systems must simultaneously support complex organizational structures, ensure robust security, and remain scalable and maintainable over time. Traditional Role-Based Access Control (RBAC) models, while effective for permission management, operate primarily as post-design security layers and do not provide a unified methodology for structuring system architecture. This paper introduces the Zoned Role-Based (ZRB) model, a mathematically formalized and comprehensive framework that integrates organizational modeling, system design, implementation, access control, and long-term maintenance. ZRB models an organization as a hierarchy of zones, each containing its own roles, applications, operations, and users, forming a recursive Zone Tree that directly mirrors real organizational semantics. Through formally defined role hierarchies, zone-scoped permission sets, and inter-zone inheritance mappings, ZRB provides a context-aware permission calculus that unifies authentication and authorization across all zones. The paper presents the theoretical foundations of ZRB, a multi-phase engineering methodology for constructing integrated enterprise systems, and a complete implementation architecture with permission inference, navigation design, administrative subsystems, and deployment models. Primary validation and evaluations across several developed systems demonstrate significant improvements in permission accuracy, administrative efficiency, scalability, and maintainability. ZRB thus offers a rigorously defined and practically validated framework for building secure, scalable, and organizationally aligned enterprise information systems.
- Research Article
- 10.1016/j.cose.2025.104799
- Mar 1, 2026
- Computers & Security
- Ruijun Zhang + 3 more
An 〈entity, organization〉 integrated access control model
- Research Article
- 10.1007/s10207-025-01130-z
- Feb 26, 2026
- International Journal of Information Security
- Azan Hamad Alkhorem + 3 more
Abstract Zero Trust is an approach allowing for increased security by providing an object or a subject with the three CIA (Confidentiality, Integrity, Availability) security aspects. To comply with the CIA criteria, access control models need to support functionalities such as: a) safer permission grant and authorization processes, b) policy decision delivery to single or multiple users, and c) policy decision delivery to single or multiple actions or objects. In addition, we need to consider redundancy, conflict detection, different types of permissions to delegate, delegation, and the separation of duties (SoD) with different types. Extensive literature exists with respect to delegation operations on access control models, but most of them do not consider redundancy or partial conflict detection with regard to the standard policies. We address the positive and negative policies resolution as a precursor to the delegation request resolution. We address the resolutions in context of the standard policies that allow or deny an action on the object to a single or multiple subjects. We provide an analysis via multiple case studies using a Python implementation of the HPol (Hierarchical Policy) model. Our analysis demonstrates the ability of the HPol model to handle access control resolution issues discussed, with proof of results in context of the positive and negative (YES & NO) policy requests.
- Research Article
- 10.1177/0926227x261421496
- Feb 26, 2026
- Journal of Computer Security
- Duc-Hieu Nguyen + 3 more
Access control policies (ACPs) are essential for creating a secure access control system. ACPs are often studied and specified based on access control models, such as attribute-based access control (ABAC). Moreover, the execution of business process instances is typically recorded in a business process event log. Ensuring conformance with ABAC policies for the process log at the time of post-execution is crucial. To perform conformance testing of ABAC policies for event logs, it is necessary to formalize the ABAC policies. However, this formalization is typically carried out manually, leading to low efficiency and maintainability, as well as a high risk of errors and difficulty in detecting them. Also, the top-down approach for ABAC policy engineering is often less feasible due to the challenges and costs associated with manually developing ABAC policies, which makes it difficult to document security requirements. Besides, there is a lack of an ABAC metamodel that supports the formalization and conformance testing of ABAC policies, and little attention is paid to constructing ABAC policies from existing event logs. This paper presents a fine-grained and highly automated model-driven framework enabling the formalization and conformance testing of ABAC policies for business processes. In our approach, an ABAC metamodel and its patterns are proposed to solve the problems mentioned above. The approach is experimented with and evaluated on three business processes: One simulated and two real-world processes.
- Research Article
- 10.1145/3771556
- Feb 19, 2026
- ACM Transactions on the Web
- Jiakun Hao + 6 more
With the development of Web3.0, decentralized identity and other blockchain-based identity empower users with control, forming the foundational infrastructure for Web3.0 ecosystems. However, existing identity frameworks remain inadequate in addressing critical challenges such as on-chain privacy during identity management and utilization. While prior works like CanDID, Hades, and CertChain explore blockchain-based identity solutions, they fail to meet the specific reqirements of DApps. Moreover, users on blockchain always store their identity data and digital assets across multiple accounts and DApps, but current identity schemes cannot support the cross-account and DApp identity privacy-preserving utilization. To bridge this gap, we propose Web3ID, the first fully DApp-oriented identity framework. By analyzing Ethereum identity proposals and user behavior patterns, we design the Web3ID featuring: on-chain privacy-preserving identity aggregation protocol, provably secure attribute-based access control model, and zk-rollup enhanced off-chain identity management. Experiments demonstrate that Web3ID enables privacy-preserving identity management and authentication on-chain, and guaranteeing access control completeness. The prototype system achieves a 100× improvement in proof/verification efficiency and reduces storage overhead by 85× compared to pure on-chain implementation through off-chain optimization techniques. Moreover, in comparison with other identity privacy solutions, Web3ID exhibits the lowest gas consumption during on-chain utilization and shows strong scalability. As a fully decentralized identity framework supporting end-to-end DApp integration, Web3ID advances Web3.0’s vision of user sovereignty, decentralization, and interoperability. This work establishes both theoretical and practical foundations for on-chain identity systems in Web3.0 ecosystems.
- Research Article
- 10.63331/upalaw/36/13
- Feb 15, 2026
- Anuarul Universitatii Petre Andrei din Iasi - Fascicula: Drept, Stiinte Economice, Stiinte Politice
- Liliana Cojocaru + 1 more
An access control system is a collection of rules used to restrict the visibility, access, and usage of the data resources in an institutional environment. When implemented, these rules provide a policy for achieving the security of the institution, establishing a hierarchy of the employees depending on their rights over the institution’s data resouces. An access control system is based on two fundamental concepts: authentication (that verifyies the user's identity) and authorization (that provides a hierarchy of the employees according to their access rights over the institutional resources). Among the most commonly used access control models we recall Role-Based Access Control (RBAC), in which users with the same role have equal access rights to data resources, Discretionary Access Control (DAC), in which the system owner decides which user has access to system resources, and Mandatory Access Control (MAC), in which a series of rules, with a high level of security established by a predefined authority, are used. In this article, we will study the last two models, namely DAC and MAC, along with their main implementations: Access Control Matrix and the Take-Grant models for DAC, BIBA and Bell-LaPadula for MAC.
- Research Article
- 10.1038/s41598-026-39415-5
- Feb 15, 2026
- Scientific Reports
- Rabia Latif + 4 more
The rapid digitisation of healthcare services presents challenges in guaranteeing safe, scalable, and privacy-preserving access to sensitive medical information. This article presents BBAS, a blockchain-based authentication system for e-Health. BBAS incorporates a multi-factor authentication (MFA) framework that includes password hashing, one-time passwords (OTP), and biometric verification, with a hybrid access control model that combines role-based access control (RBAC) and attribute-based access control (ABAC). To guarantee enduring security, BBAS utilises post-quantum digital signatures (CRYSTALS-Dilithium) and exploits the InterPlanetary file system (IPFS) for off-chain data storage, assuring tamper-resistance and scalability. We implemented the system using solidity smart contracts on a permissioned Ethereum network and assessed via 500 authentication iterations. Results show BBAS outperforms benchmark models across all critical metrics: authentication success rate (ASR: 98.6%), latency (0.05 s), throughput (19,000 req/s), gas cost (35,000 gas/req), block confirmation time (10 s), and storage overhead (0.03 KB/record). Biometric error rates—false acceptance rate (FAR: 0.5%), false rejection rate (FRR: 1.2%), and equal error rate (EER: 0.85%)—are markedly decreased, therefore improving both security and usability. This research validates BBAS as a reliable, scalable, and quantum-resistant authentication framework for contemporary e-Health systems.
- Research Article
- 10.1007/s10207-026-01227-z
- Feb 13, 2026
- International Journal of Information Security
- Clara Bertolissi + 2 more
Abstract In multi-user cooperative systems such as social networks, personal data is often jointly created and shared among multiple users. The sensitivity of such data depends on the preferences and relationships of all parties involved, making access control decisions inherently complex and dynamic. This complexity is further exacerbated because such data often forms compound objects, such as photos with multiple tagged users or comments, where access to one object can affect access to related objects. Traditional access control models lack the expressiveness needed to capture joint ownership, evolving social relationships, and time-dependent constraints, which can lead to privacy violations and unintended disclosures. In this work, we propose a fine-grained access control model for multi-user cooperative systems and apply it to social networks. Our model extends attribute-based access control with provenance information to enforce additional constraints and explicitly models compound objects to reflect the interrelated nature of social data. A key contribution is the introduction of temporal constraints in access decision-making, enabling dynamic authorizations based on time-sensitive conditions. We implemented a prototype of the proposed model and conducted an experimental evaluation to assess its feasibility. Our results show that incorporating temporal constraints has minimal impact on performance, demonstrating the practicality of our approach in existing social network environments.
- Research Article
- 10.59022/ijlp.501
- Jan 30, 2026
- International Journal of Law and Policy
- Anna Ubaydullaeva + 1 more
Access management and authentication are central to protecting sensitive information in modern legal practice. As legal services increasingly rely on cloud platforms, remote access, and digital workflows, law firms and legal departments face growing risks of unauthorized access, privilege misuse, and data breaches. This article analyzes access management and authentication in legal environments through an interdisciplinary lens that integrates cybersecurity standards, professional ethics, and regulatory compliance. Drawing on recognized international frameworks, the study systematizes access control models, multi-factor authentication, identity and access management, privileged access management, secure client portals, mobile and cloud access governance, continuous authentication, and e-discovery access controls. The results highlight that effective access governance in legal practice requires a risk-based approach that combines technical safeguards with organizational accountability and ethical duties. The article offers a structured set of best-practice recommendations to strengthen confidentiality, maintain compliance, and reinforce client trust.
- Research Article
- 10.69554/ahry5983
- Jan 14, 2026
- Cyber Security: A Peer-Reviewed Journal
- Vatsal Gupta
In large organisations, managing user access reviews for hundreds of disconnected applications (applications not integrated with central identity governance and administration [IGA] solutions) remains a daunting challenge. Traditional role-based access control models ensure authorisation but often fail to maintain least privilege for disconnected systems due to integration complexities.1 This paper proposes a scalable and customisable framework for user access reviews for disconnected applications that bypasses the time-consuming and arduous task of application integration. The framework is split into pre-certification, certification and post-certification stages and leverages Python scripts to streamline reviews. The tool is deployable with or without an IGA solution, reduces risk and meets audit needs, offering identity and access management practitioners an efficient path to govern access across diverse systems. This article is also included in The Business & Management Collection which can be accessed at https://hstalks.com/business/.
- Research Article
- 10.63282/3050-9262.ijaidsml-v7i2p119
- Jan 1, 2026
- International Journal of Artificial Intelligence, Data Science, and Machine Learning
- Sriramakrishna Vadlamudi
Compliance platforms in regulated environments must enforce granular, auditable access controls that adapt to dynamic investigative workflows. Static role-based access control (RBAC) models are insufficient for modern compliance operations where permissions must evolve with workflow state, case context, and regulatory constraints. This paper proposes a role-aware security model embedded within workflow engines that combines RBAC with contextual policy evaluation and decision-state tracking. The framework introduces workflow-bound authorization, segregation-of-duties enforcement, and comprehensive audit logging aligned with regulatory expectations. A hybrid low-code and pro-code architecture is presented to enable scalable implementation across enterprise systems while preserving governance and performance (Vadlamudi, 2026). The approach enhances transparency, reduces operational risk, and supports regulator-ready evidence reconstruction.
- Research Article
2
- 10.1016/j.jisa.2025.104261
- Jan 1, 2026
- Journal of Information Security and Applications
- Sarra Namane + 1 more
The increasing reliance on smart plugs and smart meters in modern electricity grids introduces significant security vulnerabilities, as unauthorized access can compromise grid reliability and stability. Traditional access control models are ill-suited for smart grids’ decentralized and dynamic nature. This paper introduces BACS-HP, a novel Blockchain-Based Access Control Model for Smart Grids that enhances security by incorporating privilege levels and peak hour attributes. Privilege levels prioritize access to critical devices during energy constraints, while the peak hour attribute enables adaptive decision-making to optimize energy allocation during periods of high demand. Unlike existing blockchain-based access control solutions, BACS-HP uniquely combines these context-aware attributes to provide fine-grained access control tailored to the specific needs of smart grids. The model leverages blockchain technology to ensure the secure and decentralized storage of access rights and enforces policies via smart contracts, mitigating single points of failure. Empirical results demonstrate that BACS-HP achieves low-latency security rule updates (between 42 ms and 46 ms), rapid access request processing (between 21 ms and 46 ms), and a high acceptance rate (60%) for critical devices during power outages, outperforming standard ABAC implementations in terms of responsiveness and prioritization. BACS-HP contributes to advancing access control mechanisms in smart grids and highlights the potential of blockchain to meet the security and performance demands of modern energy systems.
- Research Article
- 10.1109/access.2026.3667843
- Jan 1, 2026
- IEEE Access
- Dong Feng + 4 more
Access control is a critical security mechanism in power systems. Role-Based Access Control (RBAC) is widely adopted due to its simplicity and interpretability, but it struggles to adapt to dynamic user behavior and evolving security risks. Although context-aware access control models extend RBAC by incorporating predefined contextual conditions, they still rely heavily on explicit context modeling, which is difficult to maintain under complex and evolving operational scenarios. In this paper, we propose a context-aware access control framework that integrates Large Language Models (LLMs) with Retrieval-Augmented Generation (RAG) on top of an RBAC backbone. Unlike conventional context-aware approaches that depend on manually defined context attributes or rules, the proposed framework infers implicit, behavior-derived contextual semantics by reasoning over unstructured access logs and retrieving relevant historical behavior records. This design enables more flexible and adaptive authorization decisions while preserving the interpretability of RBAC. Experimental results on a synthetic power system access control dataset demonstrate that theRAG-enhanced framework consistently outperforms static RBAC baselines, particularly in handling ambiguous or borderline access requests. The results highlight the effectiveness of LLM-based contextual reasoning as a complementary mechanism for enhancing access control in dynamic power system environments.
- Research Article
- 10.51584/ijrias.2026.110400057
- Jan 1, 2026
- International Journal of Research and Innovation in Applied Science
- Maduabuchukwu Christopher + 2 more
This study presents an Intelligent Role-Based Access Control model enhanced with Risk-Based Multi-Factor Authentication (R-MFA) to overcome the limitations of traditional Role-Based Access Control (RBAC) and standard role-based access control with Multi-Factor Authentication (MFA) approaches. The model combines structured authorization with adaptive, context-aware authentication to achieve a better balance between security and system performance. Its effectiveness was assessed by comparing it with traditional role-based access control and role-based access control integrated with multi-factor authentication using key performance metrics such as authentication time, access success rate, false acceptance rate (FAR), system throughput, and security strength index. The findings reveal that traditional role-based access control offers the fastest authentication time (1.2 seconds) and highest throughput (120 requests per second), but suffers from weaker security, with a 6.5% FAR and a security strength index of 68.0%. The introduction of standard multi-factor authentication improves security, increasing the success rate to 96.2% and reducing FAR to 3.1%, although it leads to higher authentication time (3.8 seconds) and lower throughput (95 requests per second). In contrast, the Intelligent role-based access control model enhanced with risk-based multi-factor authentication achieves a more balanced outcome, delivering a 97.8% success rate, a low FAR of 1.2%, moderate authentication time of 2.4 seconds, throughput of 110 requests per second, and the highest security strength index of 94.2%. Overall, the results highlight the model’s ability to enhance security without significantly compromising system efficiency.