{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,6]],"date-time":"2026-06-06T21:58:53Z","timestamp":1780783133561,"version":"3.54.1"},"reference-count":60,"publisher":"MDPI AG","issue":"6","license":[{"start":{"date-parts":[[2020,6,11]],"date-time":"2020-06-11T00:00:00Z","timestamp":1591833600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Future Internet"],"abstract":"<jats:p>Most current access control models are rigid, as they are designed using static policies that always give the same outcome in different circumstances. In addition, they cannot adapt to environmental changes and unpredicted situations. With dynamic systems such as the Internet of Things (IoT) with billions of things that are distributed everywhere, these access control models are obsolete. Hence, dynamic access control models are required. These models utilize not only access policies but also contextual and real-time information to determine the access decision. One of these dynamic models is the risk-based access control model. This model estimates the security risk value related to the access request dynamically to determine the access decision. Recently, the risk-based access control model has attracted the attention of several organizations and researchers to provide more flexibility in accessing system resources. Therefore, this paper provides a systematic review and examination of the state-of-the-art of the risk-based access control model to provide a detailed understanding of the topic. Based on the selected search strategy, 44 articles (of 1044 articles) were chosen for a closer examination. Out of these articles, the contributions of the selected articles were summarized. In addition, the risk factors used to build the risk-based access control model were extracted and analyzed. Besides, the risk estimation techniques used to evaluate the risks of access control operations were identified.<\/jats:p>","DOI":"10.3390\/fi12060103","type":"journal-article","created":{"date-parts":[[2020,6,12]],"date-time":"2020-06-12T05:02:24Z","timestamp":1591938144000},"page":"103","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":42,"title":["Risk-Based Access Control Model: A Systematic Literature Review"],"prefix":"10.3390","volume":"12","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-4142-6377","authenticated-orcid":false,"given":"Hany F.","family":"Atlam","sequence":"first","affiliation":[{"name":"Electronic and Computer Science Department, University of Southampton, Southampton SO17 1BJ, UK"},{"name":"Computer Science and Engineering Department, Faculty of Electronic Engineering, Menoufia University, Menouf 32952, Egypt"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Muhammad Ajmal","family":"Azad","sequence":"additional","affiliation":[{"name":"Department of Engineering and Technology, University of Derby, Derby DE22 1GB, UK"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9919-8368","authenticated-orcid":false,"given":"Madini O.","family":"Alassafi","sequence":"additional","affiliation":[{"name":"Department of Information Technology, Faculty of Computing and IT, King Abdulaziz University, Jeddah 21589, Saudi Arabia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9815-0319","authenticated-orcid":false,"given":"Abdulrahman A.","family":"Alshdadi","sequence":"additional","affiliation":[{"name":"Department of Information Systems and Technology, College of Computer Science and Engineering, University of Jeddah, Jeddah 23218, Saudi Arabia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Ahmed","family":"Alenezi","sequence":"additional","affiliation":[{"name":"Electronic and Computer Science Department, University of Southampton, Southampton SO17 1BJ, UK"},{"name":"Computer Science Department, Faculty of Computing and Information Technology, Northern Border University, Arar 9280, Saudi Arabia"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2020,6,11]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","unstructured":"Dos Santos, D.R., Westphall, C.M., and Westphall, C.B. (2014, January 5\u20139). A dynamic risk-based access control architecture for cloud computing. Proceedings of the IEEE\/IFIP NOMS 2014\u2014IEEE\/IFIP Network Operation and Managment Symposioum, Krakow, Poland.","DOI":"10.1109\/NOMS.2014.6838319"},{"key":"ref_2","doi-asserted-by":"crossref","first-page":"484","DOI":"10.1109\/TIFS.2015.2493983","article-title":"Fine-Grained Two-Factor Access Control for Web-Based Cloud Computing Services","volume":"11","author":"Liu","year":"2016","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"ref_3","doi-asserted-by":"crossref","first-page":"11","DOI":"10.1007\/978-3-642-27201-1_2","article-title":"A Survey on Access Control Deployment","volume":"Volume 259","author":"Kim","year":"2011","journal-title":"Communications in Computer and Information Science"},{"key":"ref_4","doi-asserted-by":"crossref","unstructured":"Chen, P., Pankaj, C., Karger, P.A., Wagner, G.M., and Schuett, A. (2007, January 20\u201323). Fuzzy Multi\u2014Level Security: An Experiment on Quantified Risk\u2014Adaptive Access Control. Proceedings of the 2007 IEEE Symposium on Security and Privacy (SP\u201907), Ouckland, CA, USA.","DOI":"10.1109\/SP.2007.21"},{"key":"ref_5","doi-asserted-by":"crossref","first-page":"447","DOI":"10.1016\/j.cose.2012.02.006","article-title":"Dynamic risk-based decision methods for access control systems","volume":"31","author":"Shaikh","year":"2012","journal-title":"Comput. Secur."},{"key":"ref_6","doi-asserted-by":"crossref","first-page":"86","DOI":"10.1016\/j.cose.2013.03.010","article-title":"A framework for risk assessment in access control systems","volume":"39","author":"Khambhammettu","year":"2013","journal-title":"Comput. Secur."},{"key":"ref_7","unstructured":"Hulsebosch, R.J., Bargh, M.S., Lenzini, G., Ebben, P.W.G., and Iacob, S.M. (2007). Context Sensitive Adaptive Authentication, Springer."},{"key":"ref_8","unstructured":"Houlis, P. (2019, March 09). The History and Future of Access Control Credentials 2018. Available online: https:\/\/www.ifsecglobal.com\/global\/history-future-access-control-credentials\/."},{"key":"ref_9","doi-asserted-by":"crossref","unstructured":"Atlam, H.F., Alassafi, M.O., Alenezi, A., Walters, R.J., and Wills, G.B. (2018, January 19\u201321). XACML for Building Access Control Policies in Internet of Things. Proceedings of the 3rd International Conference on Internet of Things, Big Data and Security (IoTBDS 2018), Madeira, Portugal.","DOI":"10.5220\/0006725102530260"},{"key":"ref_10","unstructured":"Metoui, N. (2018). Privacy-Aware Risk-Based Access Control Systems. [Ph.D. Thesis, University of Trento]."},{"key":"ref_11","unstructured":"Bugiel, S., Heuser, S., and Sadeghi, A.-R. (2013, January 14\u201316). Flexible and fine-grained mandatory access control on Android for diverse security and privacy policies. Proceedings of the 22nd USENIX Security Symposium, Washington, DC, USA."},{"key":"ref_12","doi-asserted-by":"crossref","unstructured":"Hulsebosch, R.J., Salden, A.H., Bargh, M.S., Ebben, P.W.G., and Reitsma, J. (2005, January 1\u20133). Context sensitive access control. Proceedings of the Tenth ACM Symposium on Access Control Models and Technologies, Stockholm, Sweden.","DOI":"10.1145\/1063979.1064000"},{"key":"ref_13","doi-asserted-by":"crossref","unstructured":"Bijon, K.Z., Krishnan, R., and Sandhu, R. (2013, January 14\u201316). A framework for risk-aware role based access control. Proceedings of the IEEE Conference on Communications and Network Security, National Harbor, MD, USA.","DOI":"10.1109\/CNS.2013.6682761"},{"key":"ref_14","doi-asserted-by":"crossref","first-page":"53","DOI":"10.1145\/567331.567336","article-title":"Context sensitivity in role-based access control","volume":"36","author":"Kumar","year":"2002","journal-title":"Oper. Syst. Rev."},{"key":"ref_15","doi-asserted-by":"crossref","unstructured":"Wang, Q., and Jin, H. (2011, January 22\u201324). Quantified risk-adaptive access control for patient privacy protection in health information systems. Proceedings of the 6th ACM Symposium on Information, Computer and Communications Security\u2014ASIACCS \u201911, Hong Kong, China.","DOI":"10.1145\/1966913.1966969"},{"key":"ref_16","first-page":"263","article-title":"Security Vulnerability Analysis in Virtualized Computing Environments","volume":"3","author":"Brooks","year":"2012","journal-title":"Int. J. Intell. Comput. Res."},{"key":"ref_17","doi-asserted-by":"crossref","unstructured":"Li, Y., Sun, H., Chen, Z., Ren, J., and Luo, H. (2008, January 13\u201315). Using Trust and Risk in Access Control for Grid Environment. Proceedings of the Security Technology, Hainan Island, China.","DOI":"10.1109\/SecTech.2008.50"},{"key":"ref_18","unstructured":"Elky, S. (2006). An Introduction to Information System Risk Management, Sans Institute."},{"key":"ref_19","first-page":"1","article-title":"Fog computing and the internet of things: A review","volume":"2","author":"Atlam","year":"2018","journal-title":"Big Data Cogn. Comput."},{"key":"ref_20","doi-asserted-by":"crossref","unstructured":"Diep, N.N., Hung, L.X., Zhung, Y., Lee, S., Lee, Y., and Lee, H. (2007, January 14\u201316). Enforcing Access Control Using Risk Assessment. Proceedings of the Fourth European Conference on Universal Multiservice Networks, Toulouse, France.","DOI":"10.1109\/ECUMN.2007.19"},{"key":"ref_21","unstructured":"Kitchenham, B., and Charters, S. (2007). Guidelines for Performing Systematic Literature Reviews in Software Engineering, University of Durham."},{"key":"ref_22","first-page":"1","article-title":"A Framework and Risk Assessment Approaches for Risk-based Access Control in the Cloud","volume":"74","author":"Ricardo","year":"2016","journal-title":"J. Netw. Comput. Appl."},{"key":"ref_23","doi-asserted-by":"crossref","first-page":"265132","DOI":"10.1155\/2015\/265132","article-title":"A Framework for Context Sensitive Risk-Based Access Control in Medical Information Systems","volume":"2015","author":"Choi","year":"2015","journal-title":"Comput. Math. Methods Med."},{"key":"ref_24","doi-asserted-by":"crossref","unstructured":"Li, J., Bai, Y., and Zaman, N. (2013, January 16\u201318). A fuzzy modeling approach for risk-based access control in eHealth cloud. Proceedings of the 12th IEEE International Conference on Trust, Security and Privacy in Computing and Communications, Melbourne, Australia.","DOI":"10.1109\/TrustCom.2013.66"},{"key":"ref_25","doi-asserted-by":"crossref","first-page":"513","DOI":"10.1007\/s10922-012-9244-2","article-title":"A metric-based approach to assess risk for \u2018On cloud\u2019 federated identity management","volume":"20","year":"2012","journal-title":"J. Netw. Syst. Manag."},{"key":"ref_26","doi-asserted-by":"crossref","first-page":"237","DOI":"10.1016\/j.cose.2013.08.001","article-title":"An adaptive risk management and access control framework to mitigate insider threats","volume":"39","author":"Baracaldo","year":"2013","journal-title":"Comput. Secur."},{"key":"ref_27","doi-asserted-by":"crossref","unstructured":"Kandala, S., Sandhu, R., and Bhamidipati, V. (2011, January 22\u201326). An Attribute Based Framework for Risk-Adaptive Access Control Models. Proceedings of the Sixth International Conference on Availability, Reliability and Security, Vienna, Austria.","DOI":"10.1109\/ARES.2011.41"},{"key":"ref_28","first-page":"406","article-title":"Contextual Risk-based access control","volume":"2007","author":"Lee","year":"2007","journal-title":"Secur. Manag."},{"key":"ref_29","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1016\/j.iot.2019.100052","article-title":"An efficient security risk estimation technique for Risk-based access control model for IoT","volume":"6","author":"Atlam","year":"2019","journal-title":"Internet Things"},{"key":"ref_30","doi-asserted-by":"crossref","first-page":"321","DOI":"10.1016\/j.future.2014.10.012","article-title":"Dynamic counter-measures for risk-based access control systems: An evolutive approach","volume":"55","year":"2016","journal-title":"Futur. Gener. Comput. Syst."},{"key":"ref_31","unstructured":"Namitha, S., Gopalan, S., Sanjay, H.N., and Chandrashekaran, K. (2015, January 8\u201310). Risk Based Access Control In Cloud Computing. Proceedings of the International Conference on Green Computing and Internet of Things (ICGCloT), Delhi, India."},{"key":"ref_32","unstructured":"McGraw, R. (2009). Risk-Adaptable Access Control (RAdAC)."},{"key":"ref_33","doi-asserted-by":"crossref","unstructured":"Molloy, I., Dickens, L., Morisset, C., Cheng, P., Lobo, J., and Russo, A. (2011). IBM Research Report Risk-Based Access Control Decisions under Uncertainty, IBM.","DOI":"10.1145\/2133601.2133622"},{"key":"ref_34","doi-asserted-by":"crossref","unstructured":"Ni, Q., Bertino, E., and Lobo, J. (2010, January 13). Risk-based access control systems built on fuzzy inferences. Proceedings of the 5th ACM Symposium on Information, Computer and Communications Security, Beijing, China.","DOI":"10.1145\/1755688.1755719"},{"key":"ref_35","doi-asserted-by":"crossref","unstructured":"Abie, H., and Balasingham, I. (2012, January 24\u201326). Risk-Based Adaptive Security for Smart IoT in eHealth. Proceedings of the 7th International Conference on Body Area Networks, Oslo, Norway.","DOI":"10.4108\/icst.bodynets.2012.250235"},{"key":"ref_36","doi-asserted-by":"crossref","unstructured":"Shaikh, R.A., Adi, K., Logrippo, L., and Mankovski, S. (2011, January 19\u201321). Risk-based decision method for access control systems. Proceedings of the PST 2011: 9th International Conference on Privacy, Security and Trust, Montreal, QC, Canada.","DOI":"10.1109\/PST.2011.5971982"},{"key":"ref_37","unstructured":"Ricardo dos Santos, D., Westphall, C.M., and Westphall, C.B. (2013, January 25\u201331). Risk-based Dynamic Access Control for a Highly Scalable Cloud Federation. Proceedings of the Seventh International Conference on Emerging Security Information, Systems and Technologies (SECUREWARE 2013), Barcelona, Spain."},{"key":"ref_38","doi-asserted-by":"crossref","unstructured":"Molloy, I., Dickens, L., Lobo, J., Morisset, C., and Russo, A. (2012). Risk-Based Security Decisions Under Uncertainty Categories and Subject Descriptors. Data Appl. Secur. Priv., 157\u2013168.","DOI":"10.1145\/2133601.2133622"},{"key":"ref_39","doi-asserted-by":"crossref","unstructured":"Rajbhandari, L., and Snekkenes, E.A. (2011). Using game theory to analyze risk to privacy: An initial insight. Privacy and Identity Management for Life, Springer.","DOI":"10.1007\/978-3-642-20769-3_4"},{"key":"ref_40","doi-asserted-by":"crossref","unstructured":"Sharma, M., Bai, Y., Chung, S., and Dai, L. (2012, January 25\u201327). Using risk in access control for cloud-assisted ehealth. Proceedings of the 2012 IEEE  14th International Conference on High Performance Computing and Communication & 2012 IEEE 9th International Conference on Embedded Software and Systems, Liverpool, UK.","DOI":"10.1109\/HPCC.2012.153"},{"key":"ref_41","doi-asserted-by":"crossref","unstructured":"Atlam, H.F., Alenezi, A., Walters, R.J., Wills, G.B., and Daniel, J. (2017, January 21\u201323). Developing an adaptive Risk-based access control model for the Internet of Things. Proceedings of the 2017 IEEE International Conference on Internet of Things (iThings) and IEEE Green Computing and Communications (GreenCom) and IEEE Cyber, Physical and Social Computing (CPSCom) and IEEE Smart Data (SmartData), Exeter, UK.","DOI":"10.1109\/iThings-GreenCom-CPSCom-SmartData.2017.103"},{"key":"ref_42","first-page":"26","article-title":"Validation of an Adaptive Risk-based Access Control Model for the Internet of Things","volume":"10","author":"Atlam","year":"2018","journal-title":"Int. J. Comput. Netw. Inf. Secur."},{"key":"ref_43","doi-asserted-by":"crossref","unstructured":"Atlam, H.F., Alenezi, A., Walters, R.J., and Wills, G.B. (2017, January 24\u201326). An overview of risk estimation techniques in risk-based access control for the internet of things. Proceedings of the 2nd International Conference on Internet of Things, Big Data and Security, Porto, Portugal.","DOI":"10.5220\/0006292602540260"},{"key":"ref_44","doi-asserted-by":"crossref","unstructured":"Molloy, I., Cheng, P.C., and Rohatgi, P. (2009, January 8\u201311). Trading in risk: Using markets to improve access control. Proceedings of the New Security Paradigms Workshop, Oxford, UK.","DOI":"10.1145\/1595676.1595694"},{"key":"ref_45","doi-asserted-by":"crossref","first-page":"157","DOI":"10.1016\/j.procs.2015.06.018","article-title":"Prevention of Insider Attacks by Integrating Behavior Analysis with Risk based Access Control Model to Protect Cloud","volume":"54","author":"Babu","year":"2015","journal-title":"Procedia Comput. Sci."},{"key":"ref_46","unstructured":"Clark, J.A., Tapiador, J.E., McDermid, J., Cheng, P.-C., Agrawal, D., Ivanic, N., and Slogget, D. (2010, January 26\u201328). Risk based access control with uncertain and time-dependent sensitivity. Proceedings of the 2010 International Conference on Security and Cryptography (SECRYPT), Athens, Greece."},{"key":"ref_47","first-page":"2254","article-title":"Trust and risk based access control and access control constraints","volume":"5","author":"Helil","year":"2011","journal-title":"KSII Trans. Internet Inf. Syst."},{"key":"ref_48","doi-asserted-by":"crossref","unstructured":"Badar, N., Vaidya, J., Atluri, V., and Shafiq, B. (2013). Risk based access control using classification. Automated Security Management, Springer International Publishing.","DOI":"10.1007\/978-3-319-01433-3_5"},{"key":"ref_49","first-page":"285","article-title":"Trust and risk-based access control for privacy preserving threat detection systems","volume":"Volume 10018 LNCS","author":"Metoui","year":"2016","journal-title":"Lecture Notes in Computer Science (Including Subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)"},{"key":"ref_50","doi-asserted-by":"crossref","unstructured":"Chun, S.A., and Atluri, V. (2008). Risk-Based Access Control for Personal Data Services. Algorithms, Architectures and Information Systems Security, World Scientific.","DOI":"10.1142\/9789812836243_0012"},{"key":"ref_51","doi-asserted-by":"crossref","unstructured":"Rahmati, A., Fernandes, E., Eykholt, K., and Prakash, A. (October, January 30). Tyche: A risk-based permission model for smart homes. Proceedings of the 2018 IEEE Cybersecurity Development Conference, SecDev 2018, Cambridge, MA, USA.","DOI":"10.1109\/SecDev.2018.00012"},{"key":"ref_52","first-page":"1","article-title":"Risk-based privacy-aware access control for threat detection systems","volume":"Volume 10720 LNCS","author":"Metoui","year":"2017","journal-title":"Lecture Notes in Computer Science (Including Subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)"},{"key":"ref_53","doi-asserted-by":"crossref","unstructured":"Burnett, C., Chen, L., Edwards, P., and Norman, T.J. (2014, January 23\u201324). TRAAC: Trust and risk aware access control. Proceedings of the 2014 Twelfth Annual International Conference on Privacy, Security and Trust, Toronto, ON, Canada.","DOI":"10.1109\/PST.2014.6890962"},{"key":"ref_54","doi-asserted-by":"crossref","first-page":"231","DOI":"10.1016\/j.jbi.2017.01.012","article-title":"A risk-based framework for biomedical data sharing","volume":"66","author":"Dankar","year":"2017","journal-title":"J. Biomed. Inform."},{"key":"ref_55","doi-asserted-by":"crossref","unstructured":"Abomhara, M., Koien, G., Oleschchuk, V., and Hamid, M. (2018, January 22\u201324). Towards Risk-aware Access Control Framework for Healthcare Information Sharing. Proceedings of the 4th International Conference on Information Systems Security and Privacy, Funchal, Madeira, Portugal.","DOI":"10.5220\/0006608103120321"},{"key":"ref_56","first-page":"660","article-title":"Balancing trust and risk in access control","volume":"Volume 9415","author":"Armando","year":"2015","journal-title":"Lecture Notes in Computer Science (Including Subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)"},{"key":"ref_57","first-page":"140","article-title":"Risk-aware role-based access control","volume":"Volume 7170 LNCS","author":"Chen","year":"2012","journal-title":"Lecture Notes in Computer Science (Including Subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)"},{"key":"ref_58","doi-asserted-by":"crossref","unstructured":"Atlam, H.F., Walters, R.J., Wills, G.B., and Daniel, J. (2019). Fuzzy Logic with Expert Judgment to Implement an Adaptive Risk-Based Access Control Model for IoT. Mob. Netw. Appl., 1\u201313.","DOI":"10.1007\/s11036-019-01214-w"},{"key":"ref_59","doi-asserted-by":"crossref","first-page":"2618","DOI":"10.1016\/j.ins.2009.01.039","article-title":"A trust degree based access control in grid environments","volume":"179","author":"Luo","year":"2009","journal-title":"Inf. Sci. N. Y."},{"key":"ref_60","unstructured":"Habib, K., and Leister, W. (2015, January 24\u201329). Context-Aware Authentication for the Internet of Things. Proceedings of the Eleventh International Conference on Autonomic and Autonomous Systems Fined, Rome, Italy."}],"container-title":["Future Internet"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1999-5903\/12\/6\/103\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,11]],"date-time":"2025-10-11T09:37:59Z","timestamp":1760175479000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1999-5903\/12\/6\/103"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2020,6,11]]},"references-count":60,"journal-issue":{"issue":"6","published-online":{"date-parts":[[2020,6]]}},"alternative-id":["fi12060103"],"URL":"https:\/\/doi.org\/10.3390\/fi12060103","relation":{},"ISSN":["1999-5903"],"issn-type":[{"value":"1999-5903","type":"electronic"}],"subject":[],"published":{"date-parts":[[2020,6,11]]}}}