Role-based access control models
1996/01/01 by R.S. Sandhu, Ravi Sandhu, Edward J. Coyne +4 · 5,850 citations
Computer Science · Social Sciences · #Access Control and Trust #Access control #Computer science #Computer security #Implementation #Information and Cyber Security #Role-based access control #Security and Verification in Computing #Software engineering
paper · doi:10.1109/2.485845
published in Computer 29(2), 38-47 (IEEE Computer Society)
openalex publication_date 1996/01/01 · openalex created_date 2025/10/10 · openalex updated_date 2026/08/04
Abstract
Security administration of large systems is complex, but it can be simplified by a role-based access control approach. This article explains why RBAC is receiving renewed attention as a method of security administration and review, describes a framework of four reference models developed to better understand RBAC and categorizes different implementations, and discusses the use of RBAC to manage itself.
Cited by
- A Smart Contract-Based Access Control Framework For Smart Healthcare Systems
- Benchmarking Text-to-SQL under Role-Based Access Control
- Prezta: Provable Remote Execution of Zero-Trust Authorization using SNARKs
- A Non-Intrusive Traffic Analysis Framework for Authorization Risk Detection and Coordinated Response in Web Applications
- Dive into Claude Code: The Design Space of Today's and Future AI Agent Systems
- Decentralized Granular Access Control for Agentic AI Systems in Critical Infrastructure
- Implementing Advanced RBAC Administration Functionality with USE
- Private Virtual Tree Networks for Secure Multi-Tenant Environments Based on the VIRGO Overlay Network
- Automated Validation of Security-sensitive Web Services specified in BPEL and RBAC (Extended Version)
- Conflicts in policy-based distributed systems management
- Train While You Fight -- Technical Requirements for Advanced Distributed Learning Platforms
- Towards Harnessing the Power of LLMs for ABAC Policy Mining
- Proposal of an AI-Based Support Assistant for the ALICE-FIT Detector Setup at CERN
- Comparative Security Performance of Workday Cloud ERP Across Key Dimensions
- Reflections on the design, applications and implementations of the normative specification language eFLINT
- Security Constraints in Temporal Role-Based Access-Controlled Workflows (Extended Version)
- The Authorization Policy Existence Problem
- Conceptualizing Smart City Applications: Requirements, Architecture, Security Issues and Emerging Trends
- Uncertainty-Aware, Risk-Adaptive Access Control for Agentic Systems using an LLM-Judged TBAC Model
- Extended Role Based Access Control with Blob Service on Cloud
- Agentic-AI Healthcare: Multilingual, Privacy-First Framework with MCP Agents
- An MDA Framework Supporting OCL
- Aspect-Oriented Programming in Secure Software Development: A Case Study of Security Aspects in Web Applications
- Towards a General Framework for Modelling Roles
- ESPOONERBAC: Enforcing Security Policies In Outsourced Environments
- Insider Threats in Emerging Mobility-as-a-Service Scenarios
- A Policy Model and Framework for Context-Aware Access Control to Information Resources
- A Technical Look At The Indian Personal Data Protection Bill
- Protecting Personal Data using Smart Contracts
- Mining Attribute-based Access Control Policies
- A Federated Capability-based Access Control Mechanism for Internet of Things (IoTs)
- Automated Symbolic Analysis of ARBAC-Policies (Extended Version)
- Access Control Threatened by Quantum Entanglement
- Event Systems and Access Control
- Doppelganger Method: Breaking Role Consistency in LLM Agent via Prompt-based Transferable Adversarial Attack
- Quantifying Azure RBAC Wildcard Overreach
- Adaptive ABAC Policy Learning: A Reinforcement Learning Approach
- Verifying Access Control in Statecharts
- Relationship-Based Access Control for OpenMRS
- Zero Trust Cybersecurity: Procedures and Considerations in Context
- Secure Cloud Assisted Smart Cars Using Dynamic Groups and Attribute Based Access Control
- Analysis of Privacy Policies to Enhance Informed Consent (Extended Version)
- HCAP: A History-Based Capability System for IoT Devices
- "I Apologize For Not Understanding Your Policy": Exploring the Specification and Evaluation of User-Managed Access Control Policies by AI Virtual Assistants
- DataProVe: A Data Protection Policy and System Architecture Verification Tool
- HONEYBEE: Efficient Role-based Access Control for Vector Databases via Dynamic Partitioning[Technical Report]
- ChaMAILeon: Exploring the Usability of a Privacy Preserving Email Sharing System
- An intelligent agent based framework for secure Web Services
- Severity Level of Permissions in Role-Based Access Control
- Guide to Attribute Based Access Control (ABAC) Definition and Considerations
- Peer-to-peer access control architecture using trusted computing technology
- TOMOYO Linux: A Mandatory Access Control Method Based on Application Execution State
- The economics of information security investment
- Security for Enterprise Resource Planning Systems
- Toward a Science of Intent: Closure Gaps and Delegation Envelopes for Open-World AI Agents
- Controlled Query Evaluation for Datalog and OWL 2 Profile Ontologies
- Ontology-based Access Control in Open Scenarios: Applications to Social\n Networks and the Cloud
- Access control management for e-Healthcare in cloud environment
- Blockchain Enabled Metaverse: Development and Applications
- Common Representation of Information Flows for Dynamic Coalitions
- Relational access control with bivalent permissions in a social Web/collaboration architecture
- From Siloed Algorithms to Compliance-First Agentic Platforms: A Multi-Layered Architecture for Hospital AI Systems
- A Framework for Context Sensitive Risk-Based Access Control in Medical Information Systems. [europepmc]
- Access Control Mechanism for IoT Environments Based on Modelling Communication Procedures as Resources. [europepmc]
- Registered access: authorizing data access. [europepmc]
- Identity Management Systems for the Internet of Things: A Survey Towards Blockchain Solutions. [europepmc]
- Integrated Management of Energy, Wellbeing and Health in the Next Generation of Smart Homes. [europepmc]
- A Secure and Efficient Digital-Data-Sharing System for Cloud Environments. [europepmc]
- eHealth Cloud Security Challenges: A Survey. [europepmc]
- Exploiting Smart Contracts for Capability-Based Access Control in the Internet of Things. [europepmc]
- A Survey of Context-Aware Access Control Mechanisms for Cloud and Fog Networks: Taxonomy and Open Research Issues. [europepmc]
- RESPOnSE-A Framework for Enforcing Risk-Aware Security Policies in Constrained Dynamic Environments. [europepmc]
- A Privacy-Preserving Key Management Scheme with Support for Sybil Attack Detection in VANETs. [europepmc]
- What Do You Think About Your Company's Leaks? A Survey on End-Users Perception Toward Data Leakage Mechanisms. [europepmc]
- On automated RBAC assessment by constructing a centralized perspective for microservice mesh. [europepmc]
- Being (In)Visible: Privacy, Transparency, and Disclosure in the Self-Management of Bipolar Disorder. [europepmc]
- Combining IOTA and Attribute-Based Encryption for Access Control in the Internet of Things. [europepmc]
- HEAD Metamodel: Hierarchical, Extensible, Advanced, and Dynamic Access Control Metamodel for Dynamic and Heterogeneous Structures. [europepmc]
- Enabling Context-Aware Data Analytics in Smart Environments: An Open Source Reference Implementation. [europepmc]
- Work-Based Access Control Model for Cooperative Healthcare Environments: Formal Specification and Verification. [europepmc]
- Research and Design of Docker Technology Based Authority Management System. [europepmc]
- Blockchain-Based Access Control and Behavior Regulation System for IoT. [europepmc]
- An Access Control System Based on Blockchain with Zero-Knowledge Rollups in High-Traffic IoT Environments. [europepmc]
- A Blockchain-Based Trustworthy Model Evaluation Framework for Deep Learning and Its Application in Moving Object Segmentation. [europepmc]
- Self-Aware Cybersecurity Architecture for Autonomous Vehicles: Security through System-Level Accountability. [europepmc]
- IHIBE: A Hierarchical and Delegated Access Control Mechanism for IoT Environments. [europepmc]
- ACHealthChain blockchain framework for access control and privacy preservation in healthcare. [europepmc]
Related