• Home
  • Search
  • Frameworks for Attribute-Based Access Control (ABAC) Policy Engineering
  • https://doi.org/10.12794/metadc1707241Copy DOI Icon

Frameworks for Attribute-Based Access Control (ABAC) Policy Engineering

  • Aug 1, 2020
  • Manar Alohaly
Show More
  • Abstract
  • Literature Map
  • References
  • Similar Papers
Abstract

In this disseration we propose semi-automated top-down policy engineering approaches for attribute-based access control (ABAC) development. Further, we propose a hybrid ABAC policy engineering approach to combine the benefits and address the shortcomings of both top-down and bottom-up approaches. In particular, we propose three frameworks: (i) ABAC attributes extraction, (ii) ABAC constraints extraction, and (iii) hybrid ABAC policy engineering. Attributes extraction framework comprises of five modules that operate together to extract attributes values from natural language access control policies (NLACPs); map the extracted values to attribute keys; and assign each key-value pair to an appropriate entity. For ABAC constraints extraction framework, we design a two-phase process to extract ABAC constraints from NLACPs. The process begins with the identification phase which focuses on identifying the right boundary of constraint expressions. Next is the normalization phase, that aims at extracting the actual elements that pose a constraint. On the other hand, our hybrid ABAC policy engineering framework consists of 5 modules. This framework combines top-down and bottom-up policy engineering techniques to overcome the shortcomings of both approaches and to generate policies that are more intuitive and relevant to actual organization policies. With this, we believe that our work takes essential steps towards a semi-automated ABAC policy development experience.

Similar Papers
  • Conference Article
  • Citations4

A System for Centralized ABAC Policy Administration and Local ABAC Policy Decision and Enforcement in Host Systems using Access Control Lists

  • Mar 14, 2018
  • David Ferraiolo +2
  • Conference Article

Formalizing and Conformance Testing ABAC Policies in Process Logs via an ABAC Metamodel

  • Nov 06, 2025
  • Duc-Hieu Nguyen
  • Research Article
  • Citations11

Contemporaneous Update and Enforcement of ABAC Policies.

  • Jun 07, 2022
  • Proceedings of the ... ACM symposium on access control models and technologies. ACM Symposium on Access Control Models and Technologies
  • Samir Talegaon +4
  • Research Article
  • Citations1

[formula omitted]: A blockchain-based secure access control management for the Internet of Things

  • Oct 30, 2024
  • Journal of Information Security and Applications
  • Utsa Roy +1
  • Research Article
  • Citations2

Semantically Correct Policy Mining and Enforcement for Attribute based Access Control.

  • May 23, 2025
  • ACM transactions on Internet technology
  • Gunjan Batra +4
  • Research Article
  • Citations121

Towards Blockchain-Based Secure Storage and Trusted Data Sharing Scheme for IoT Environment

  • Jan 01, 2022
  • IEEE Access
  • Zia Ullah +4
  • Book Chapter
  • Citations5

Graphical Interface for Ontology Mapping with Application to Access Control

  • Jan 01, 2017
  • Michał Drozdowicz +3
  • PDF
  • Research Article
  • Citations8

Formal Approach to Detect and Resolve Anomalies while Clustering ABAC Policies

  • Dec 11, 2018
  • ICST Transactions on Security and Safety
  • Maryem Ait El Hadj +3
  • Supplementary Content

Digital Provenance Techniques and Applications

  • Aug 13, 2020
  • Figshare
  • Amani M Abu Jabal
  • Research Article
  • Citations1

Securing Cloud Data: An Enhanced Approach through Attribute-Based Access Control Mechanism

  • Oct 30, 2023
  • International Journal on Recent and Innovation Trends in Computing and Communication
  • Et Al K Raja
  • Conference Article
  • Citations11

Challenges of “operationalizing” dynamic system access control: Transitioning from ABAC to RAdAC

  • Mar 01, 2012
  • Bassam Farroha +1
  • Book Chapter
  • Citations4

Chapter 23 - Policies, Access Control, and Formal Methods

  • Jan 01, 2012
  • Handbook on Securing Cyber-Physical Critical Infrastructure
  • Elisa Bertino
  • Research Article
  • Citations11

Enhancing Healthcare Security: A Unified RBAC and ABAC Risk-Aware Access Control Approach

  • Jun 14, 2025
  • Future Internet
  • Hany F Atlam +1
  • Research Article
  • Citations5

A Combination of Semantic and Attribute based Access Control Model for Virtual Organizations

  • Aug 05, 2015
  • Isecure.
  • Morteza Amini +1
  • Book Chapter
  • Citations9

Security Analysis of Unified Access Control Policies

  • Jan 01, 2020
  • Mahendra Pratap Singh +3
Cactus Communications logo

Copyright 2026 Cactus Communications. All rights reserved.