{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,18]],"date-time":"2026-06-18T22:52:49Z","timestamp":1781823169951,"version":"3.54.5"},"reference-count":33,"publisher":"SAGE Publications","issue":"4","license":[{"start":{"date-parts":[[2026,3,5]],"date-time":"2026-03-05T00:00:00Z","timestamp":1772668800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/journals.sagepub.com\/page\/policies\/text-and-data-mining-license"}],"content-domain":{"domain":["journals.sagepub.com"],"crossmark-restriction":true},"short-container-title":["Journal of Computer Security"],"published-print":{"date-parts":[[2026,7]]},"abstract":"<jats:p>The increasing presence of smart mobile devices in sensitive environments raises significant security and privacy concerns, particularly due to the unauthorized usage of built-in sensors such as cameras and microphones. However, space owners currently have limited means to enforce restrictions on mobile devices within their premises. To address this issue, we propose a novel location-based access control system utilizing bluetooth low energy (BLE) beacons to dynamically enforce security policies. The proposed system introduces the jumbo beacon concept, which enables fragmented transmission and reassembly of signed access control policies, overcoming BLE payload limitations. Unlike centralized enforcement models, our approach is fully decentralized, eliminating the need for a trusted central server and providing a flexible, scalable mechanism for enforcing fine-grained access policies. The system is implemented as a native security module within the Android operating system, ensuring tamper-resistant enforcement of policies while preventing unauthorized modifications. A proof-of-concept implementation demonstrates the system\u2019s effectiveness, highlighting its real-time policy enforcement capabilities and resilience against adversarial threats. The results indicate that our approach offers a lightweight, scalable, and secure solution for enforcing location-based access control in dynamic environments.<\/jats:p>","DOI":"10.1177\/0926227x261428667","type":"journal-article","created":{"date-parts":[[2026,3,11]],"date-time":"2026-03-11T18:35:50Z","timestamp":1773254150000},"page":"301-319","update-policy":"https:\/\/doi.org\/10.1177\/sage-journals-update-policy","source":"Crossref","is-referenced-by-count":0,"title":["Location-based access control system for mobile devices using bluetooth low energy technology"],"prefix":"10.1177","volume":"34","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-1002-6218","authenticated-orcid":false,"given":"Ahmed","family":"Khalil Abdulla","sequence":"first","affiliation":[{"name":"Division of Information and Computing Technology, College of Science and Engineering, Hamad Bin Khalifa University, Doha, Qatar"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9637-0430","authenticated-orcid":false,"given":"Gabriele","family":"Oligeri","sequence":"additional","affiliation":[{"name":"Division of Information and Computing Technology, College of Science and Engineering, Hamad Bin Khalifa University, Doha, Qatar"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8964-0746","authenticated-orcid":false,"given":"Spiridon","family":"Bakiras","sequence":"additional","affiliation":[{"name":"Singapore Institute of Technology"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"179","published-online":{"date-parts":[[2026,3,5]]},"reference":[{"key":"e_1_3_3_2_2","unstructured":"How to detect and prevent corporate espionage 2025. https:\/\/www.mimecast.com\/blog\/what-is-corporate-espionage-and-prevention-techniques."},{"key":"e_1_3_3_3_2","unstructured":"Blanton S. Iot security risks: Stats and trends to know in 2025 2025. https:\/\/jumpcloud.com\/blog\/iot-security-risks-stats-and-trends-to-know-in-2025."},{"key":"e_1_3_3_4_2","unstructured":"Waltham M. Unauthorised access to employee mobile devices leads to more than half of organisations experiencing a data breach new report finds 2024. https:\/\/www.imprivata.com\/uk\/company\/press\/unauthorized-access-employee-mobile-devices-leads-more-half-organizations."},{"key":"e_1_3_3_5_2","doi-asserted-by":"publisher","DOI":"10.1145\/3756423.3756567"},{"key":"e_1_3_3_6_2","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2025.3533145"},{"key":"e_1_3_3_7_2","unstructured":"Chowdary TN Raj PP Anupama C et\u00a0al. Location & user profile based mobile application access. In: International conference on informatics and analytics. Association for Computing Machinery. ISBN 9781450347563."},{"key":"e_1_3_3_8_2","doi-asserted-by":"crossref","unstructured":"Roesner F Molnar D Moshchuk A et\u00a0al. World-driven access control for continuous sensing. In: ACM conference on computer and communications security. Association for Computing Machinery. ISBN 9781450329576 p.1169\u20131181.","DOI":"10.1145\/2660267.2660319"},{"key":"e_1_3_3_9_2","doi-asserted-by":"crossref","unstructured":"Rubio-Medrano CE Jogani S Leitner M et\u00a0al. Effectively enforcing authorization constraints for emerging space-sensitive technologies. In: ACM symposium on access control models and technologies. association for computing machinery. ISBN 9781450367530 p.195\u2013206.","DOI":"10.1145\/3322431.3325109"},{"key":"e_1_3_3_10_2","doi-asserted-by":"publisher","DOI":"10.1109\/JSYST.2022.3202698"},{"key":"e_1_3_3_11_2","doi-asserted-by":"crossref","unstructured":"Bertino E Kirkpatrick MS. Location-based access control systems for mobile users: Concepts and research directions. In: ACM International workshop on security and privacy in GIS and LBS. Association for Computing Machinery. ISBN 9781450310321 p.49\u201352.","DOI":"10.1145\/2071880.2071890"},{"key":"e_1_3_3_12_2","unstructured":"The bluetooth\u00aelow energy primer 2025. https:\/\/www.bluetooth.com\/bluetooth-le-primer."},{"key":"e_1_3_3_13_2","doi-asserted-by":"crossref","unstructured":"Oluwatimi O Midi D Bertino E. A context-aware system to secure enterprise content. In: ACM symposium on access control models and technologies. Association for Computing Machinery. ISBN 9781450338028 p.63\u201372.","DOI":"10.1145\/2914642.2914648"},{"key":"e_1_3_3_14_2","doi-asserted-by":"crossref","unstructured":"Martin PD Rushanan M Tantillo T et\u00a0al. Applications of secure location sensing in healthcare. In: ACM International conference on bioinformatics computational biology and health informatics. Association for Computing Machinery. ISBN 9781450342254 p.58\u201367.","DOI":"10.1145\/2975167.2975173"},{"key":"e_1_3_3_15_2","doi-asserted-by":"crossref","unstructured":"Kirkpatrick MS Damiani ML Bertino E. Prox-rbac: A proximity-based spatially aware RBAC. In: ACM international symposium on advances in geographic information systems. Association for Computing Machinery. ISBN 9781450310314 p.339\u2013348.","DOI":"10.1145\/2093973.2094018"},{"key":"e_1_3_3_16_2","unstructured":"Cruz IF Gjomemo R Lin B et\u00a0al. A location aware role and attribute based access control system. In: International symposium on advances in geographic information systems. Association for Computing Machinery. ISBN 9781605583235."},{"key":"e_1_3_3_17_2","doi-asserted-by":"crossref","unstructured":"Kirkpatrick MS Bertino E. Enforcing spatial constraints for mobile RBAC systems. In: ACM symposium on access control models and technologies. Association for Computing Machinery. ISBN 9781450300490 p.99\u2013108.","DOI":"10.1145\/1809842.1809860"},{"key":"e_1_3_3_18_2","doi-asserted-by":"crossref","unstructured":"Hsu AC Ray I. Specification and enforcement of location-aware attribute-based access control for online social networks. In: ACM international workshop on attribute based access control. Association for Computing Machinery. ISBN 9781450340793 p.25\u201334.","DOI":"10.1145\/2875491.2875495"},{"key":"e_1_3_3_19_2","doi-asserted-by":"crossref","unstructured":"Zhu Y Ma D Huang D et\u00a0al. Enabling secure location-based services in mobile cloud computing. In: ACM SIGCOMM workshop on mobile cloud computing. Association for Computing Machinery. ISBN 9781450321808 p.27\u201332.","DOI":"10.1145\/2491266.2491272"},{"key":"e_1_3_3_20_2","doi-asserted-by":"crossref","unstructured":"Hengartner U Steenkiste P. Implementing access control to people location information. In: ACM symposium on access control models and technologies. Association for Computing Machinery. ISBN 1581138725 p.11\u201320.","DOI":"10.1145\/990036.990039"},{"key":"e_1_3_3_21_2","doi-asserted-by":"crossref","unstructured":"Karimi L Palanisamy B Joshi J. A dynamic privacy aware access control model for location based services. In: IEEE international conference on collaboration and internet computing. pp.554\u2013557. DOI: 10.1109\/CIC.2016.084.","DOI":"10.1109\/CIC.2016.084"},{"key":"e_1_3_3_22_2","unstructured":"Mainali P Shepherd C Petitcolas FA. Privacy-enhancing context authentication from location-sensitive data. In: International conference on availability reliability and security. Association for Computing Machinery. ISBN 9781450371643."},{"key":"e_1_3_3_23_2","doi-asserted-by":"crossref","unstructured":"Ardagna CA Cremonini M Damiani E et\u00a0al. Supporting location-based conditions in access control policies. In: ACM symposium on information computer and communications security. Association for Computing Machinery. ISBN 1595932720 p.212\u2013222.","DOI":"10.1145\/1128817.1128850"},{"key":"e_1_3_3_24_2","doi-asserted-by":"crossref","unstructured":"Abdou A Matrawy A van Oorschot PC. Accurate manipulation of delay-based internet geolocation. In: ACM on asia conference on computer and communications security. Association for Computing Machinery. ISBN 9781450349444 p.887\u2013898.","DOI":"10.1145\/3052973.3052993"},{"key":"e_1_3_3_25_2","doi-asserted-by":"crossref","unstructured":"Cleeff A Pieters W Wieringa R. Benefits of location-based access control: A literature study. In: IEEE\/ACM international conference on green computing and communications international conference on cyber physical and social computing. pp.739\u2013746. DOI: 10.1109\/GreenCom-CPSCom.2010.148.","DOI":"10.1109\/GreenCom-CPSCom.2010.148"},{"key":"e_1_3_3_26_2","doi-asserted-by":"crossref","unstructured":"Decker M. Requirements for a location-based access control model. In: ACM International conference on advances in mobile computing and multimedia. Association for Computing Machinery. ISBN 9781605582696 p.346\u2013349.","DOI":"10.1145\/1497185.1497259"},{"key":"e_1_3_3_27_2","unstructured":"Android architecture 2025. https:\/\/source.android.com\/docs\/core\/architecture."},{"key":"e_1_3_3_28_2","unstructured":"Altbeacon protocol specification v1.0 2015. https:\/\/github.com\/AltBeacon\/spec."},{"key":"e_1_3_3_29_2","unstructured":"Java \u2014 oracle. https:\/\/www.java.com\/en\/ 2021."},{"key":"e_1_3_3_30_2","unstructured":"Feasycom fsc-bp104d: Bluetooth 5.1 waterproof ip67 beacon \u2014 10-year battery life \u2014 ibeacon eddystone altbeacon support 2025. https:\/\/www.feasycom.com\/product\/fsc-bp104d."},{"key":"e_1_3_3_31_2","doi-asserted-by":"publisher","DOI":"10.1145\/3301285"},{"key":"e_1_3_3_32_2","doi-asserted-by":"crossref","unstructured":"Aldoseri A Chothia T Moreira J et\u00a0al. Symbolic modelling of remote attestation protocols for device and app integrity on android. In: Proceedings of the 2023 ACM Asia conference on computer and communications security. ASIA CCS \u201923 New York NY USA: Association for Computing Machinery. ISBN 9798400700989 p. 218\u2013231. DOI: 10.1145\/3579856.3582812.","DOI":"10.1145\/3579856.3582812"},{"key":"e_1_3_3_33_2","doi-asserted-by":"crossref","unstructured":"Ibrahim M Imran A Bianchi A. Safetynot: on the usage of the safetynet attestation api in android. In: Proceedings of the 19th annual international conference on mobile systems applications and services. MobiSys \u201921 New York NY USA: Association for Computing Machinery. ISBN 9781450384438 p.150\u2013162. DOI: 10.1145\/3458864.3466627.","DOI":"10.1145\/3458864.3466627"},{"key":"e_1_3_3_34_2","unstructured":"Overview of the Play Integrity API |\u00a0 Android Developers \u00a02025.\u00a0https:\/\/developer.android.com\/google\/play\/integrity\/overview."}],"container-title":["Journal of Computer Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/journals.sagepub.com\/doi\/pdf\/10.1177\/0926227X261428667","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/journals.sagepub.com\/doi\/full-xml\/10.1177\/0926227X261428667","content-type":"application\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/journals.sagepub.com\/doi\/pdf\/10.1177\/0926227X261428667","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,6,18]],"date-time":"2026-06-18T22:17:16Z","timestamp":1781821036000},"score":1,"resource":{"primary":{"URL":"https:\/\/journals.sagepub.com\/doi\/10.1177\/0926227X261428667"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,3,5]]},"references-count":33,"journal-issue":{"issue":"4","published-print":{"date-parts":[[2026,7]]}},"alternative-id":["10.1177\/0926227X261428667"],"URL":"https:\/\/doi.org\/10.1177\/0926227x261428667","relation":{},"ISSN":["0926-227X","1875-8924"],"issn-type":[{"value":"0926-227X","type":"print"},{"value":"1875-8924","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,3,5]]}}}