{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,23]],"date-time":"2026-06-23T12:12:21Z","timestamp":1782216741066,"version":"3.54.5"},"reference-count":42,"publisher":"MDPI AG","issue":"1","license":[{"start":{"date-parts":[[2022,2,14]],"date-time":"2022-02-14T00:00:00Z","timestamp":1644796800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["JCP"],"abstract":"<jats:p>Access control (AC) policies are a set of rules administering decisions in systems and they are increasingly used for implementing flexible and adaptive systems to control access in today\u2019s internet services, networks, security systems, and others. The emergence of the current generation of networking environments, with digital transformation, such as the internet of things (IoT), fog computing, cloud computing, etc., with their different applications, bring out new trends, concepts, and challenges to integrate more advanced and intelligent systems in critical and heterogeneous structures. This fact, in addition to the COVID-19 pandemic, has prompted a greater need than ever for AC due to widespread telework and the need to access resources and data related to critical domains such as government, healthcare, industry, and others, and any successful cyber or physical attack can disrupt operations or even decline critical services to society. Moreover, various declarations have announced that the world of AC is changing fast, and the pandemic made AC feel more essential than in the past. To minimize security risks of any unauthorized access to physical and logical systems, before and during the pandemic, several AC approaches are proposed to find a common specification for security policy where AC is implemented in various dynamic and heterogeneous computing environments. Unfortunately, the proposed AC models and metamodels have limited features and are insufficient to meet the current access control requirements. In this context, we have developed a Hierarchical, Extensible, Advanced, and Dynamic (HEAD) AC metamodel with substantial features that is able to encompass the heterogeneity of AC models, overcome the existing limitations of the proposed AC metamodels, and follow the various technology progressions. In this paper, we explain the distinct design of the HEAD metamodel, starting from the metamodel development phase and reaching to the policy enforcement phase. We describe the remaining steps and how they can be employed to develop more advanced features in order to open new opportunities and answer the various challenges of technology progressions and the impact of the pandemic in the domain. As a result, we present a novel approach in five main phases: metamodel development, deriving models, generating policies, policy analysis and assessment, and policy enforcement. This approach can be employed to assist security experts and system administrators to design secure systems that comply with the organizational security policies that are related to access control.<\/jats:p>","DOI":"10.3390\/jcp2010004","type":"journal-article","created":{"date-parts":[[2022,2,14]],"date-time":"2022-02-14T03:46:00Z","timestamp":1644810360000},"page":"42-64","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":3,"title":["HEAD Access Control Metamodel: Distinct Design, Advanced Features, and New Opportunities"],"prefix":"10.3390","volume":"2","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-0080-1778","authenticated-orcid":false,"given":"Nadine","family":"Kashmar","sequence":"first","affiliation":[{"name":"D\u00e9partement de Math\u00e9matiques, Informatique et G\u00e9nie, Universit\u00e9 du Qu\u00e9bec \u00e0 Rimouski, 300 All\u00e9e des Ursulines, Rimouski, QC G5L 3A1, Canada"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5327-1758","authenticated-orcid":false,"given":"Mehdi","family":"Adda","sequence":"additional","affiliation":[{"name":"D\u00e9partement de Math\u00e9matiques, Informatique et G\u00e9nie, Universit\u00e9 du Qu\u00e9bec \u00e0 Rimouski, 300 All\u00e9e des Ursulines, Rimouski, QC G5L 3A1, Canada"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9177-2967","authenticated-orcid":false,"given":"Hussein","family":"Ibrahim","sequence":"additional","affiliation":[{"name":"Institut Technologique de Maintenance Industrielle, 175 Rue de la V\u00e9rendrye, Sept-\u00celes, QC G4R 5B7, Canada"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2022,2,14]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","first-page":"638","DOI":"10.3390\/jcp1040032","article-title":"Insights into Organizational Security Readiness: Lessons Learned from Cyber-Attack Case Studies","volume":"1","author":"Quader","year":"2021","journal-title":"J. Cybersecur. Priv."},{"key":"ref_2","doi-asserted-by":"crossref","first-page":"597","DOI":"10.3390\/jcp1040030","article-title":"A Security and Privacy Scoring System for Contact Tracing Apps","volume":"1","author":"Krehling","year":"2021","journal-title":"J. Cybersecur. Priv."},{"key":"ref_3","doi-asserted-by":"crossref","unstructured":"Kashmar, N., Adda, M., and Ibrahim, H. (2021). HEAD Metamodel: Hierarchical, Extensible, Advanced, and Dynamic Access Control Metamodel for Dynamic and Heterogeneous Structures. Sensors, 21.","DOI":"10.3390\/s21196507"},{"key":"ref_4","doi-asserted-by":"crossref","first-page":"887","DOI":"10.1016\/j.procs.2021.03.111","article-title":"Access Control Metamodel for Policy Specification and Enforcement: From Conception to Formalization","volume":"184","author":"Kashmar","year":"2021","journal-title":"Procedia Comput. Sci."},{"key":"ref_5","doi-asserted-by":"crossref","first-page":"445","DOI":"10.1016\/j.procs.2021.03.056","article-title":"A Review of Access Control Metamodels","volume":"184","author":"Kashmar","year":"2021","journal-title":"Procedia Comput. Sci."},{"key":"ref_6","doi-asserted-by":"crossref","unstructured":"Kashmar, N., Adda, M., and Atieh, M. (2019). From Access Control Models to Access Control Metamodels: A Survey. Future of Information and Communication Conference, Springer.","DOI":"10.1007\/978-3-030-12385-7_61"},{"key":"ref_7","doi-asserted-by":"crossref","first-page":"784","DOI":"10.17706\/\/jsw.10.7.784-797","article-title":"A Metamodel for Hybrid Access Control Policies","volume":"10","author":"Logrippo","year":"2015","journal-title":"J. Softw."},{"key":"ref_8","doi-asserted-by":"crossref","first-page":"299","DOI":"10.1016\/j.cose.2012.01.004","article-title":"A methodology for integrating access control policies within database development","volume":"31","author":"Abramov","year":"2012","journal-title":"Comput. Secur."},{"key":"ref_9","first-page":"2","article-title":"Access Control Metamodels: Review, Critical Analysis, and Research Issues","volume":"16","author":"Kashmar","year":"2021","journal-title":"J. Ubiquitous Syst. Pervasive Netw."},{"key":"ref_10","unstructured":"Wolfe, C. (Security Distributing and Marketing (SDM) Magazine, 2021). State of the Market: Access Control, Security Distributing and Marketing (SDM) Magazine."},{"key":"ref_11","unstructured":"Al Kukhun, D. (2012). Steps Towards Adaptive Situation and Context-Aware Access: A Contribution to the Extension of Access Control Mechanisms within Pervasive Information Systems. [Ph.D. Thesis, Universit\u00e9 de Toulouse]."},{"key":"ref_12","doi-asserted-by":"crossref","first-page":"162","DOI":"10.1016\/j.procs.2020.10.024","article-title":"Deriving Access Control Models based on Generic and Dynamic Metamodel Architecture: Industrial Use Case","volume":"177","author":"Kashmar","year":"2020","journal-title":"Procedia Comput. Sci."},{"key":"ref_13","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3209668","article-title":"The challenge of access control policies quality","volume":"10","author":"Bertino","year":"2018","journal-title":"J. Data Inf. Qual."},{"key":"ref_14","doi-asserted-by":"crossref","unstructured":"Soltani, N., and Jalili, R. (2017, January 6\u20137). Enforcing Access Control Policies over Data Stored on Untrusted Server. Proceedings of the 2017 14th International ISC (Iranian Society of Cryptology) Conference on Information Security and Cryptology (ISCISC), Shiraz, Iran.","DOI":"10.1109\/ISCISC.2017.8488365"},{"key":"ref_15","doi-asserted-by":"crossref","unstructured":"Kashmar, N., Adda, M., Atieh, M., and Ibrahim, H. (2021). Access Control in Cybersecurity and Social Media. Cybers\u00e9curit\u00e9 et M\u00e9dias Sociaux, Presses de l\u2019Universit\u00e9. Chapter 4.","DOI":"10.1515\/9782763753294-005"},{"key":"ref_16","doi-asserted-by":"crossref","unstructured":"Hasiba, B.A., Kahloul, L., and Benharzallah, S. (2017, January 5\u20137). A new hybrid access control model for multi-domain systems. Proceedings of the 2017 4th International Conference on Control, Decision and Information Technologies (CoDIT), Barcelona, Spain.","DOI":"10.1109\/CoDIT.2017.8102687"},{"key":"ref_17","doi-asserted-by":"crossref","unstructured":"Rajpoot, Q.M., Jensen, C.D., and Krishnan, R. (2015, January 13). Integrating attributes into role-based access control. Proceedings of the IFIP Annual Conference on Data and Applications Security and Privacy, Fairfax, VA, USA.","DOI":"10.1007\/978-3-319-20810-7_17"},{"key":"ref_18","doi-asserted-by":"crossref","unstructured":"Kaiwen, S., and Lihua, Y. (2014, January 5). Attribute-role-based hybrid access control in the internet of things. Proceedings of the Asia-Pacific Web Conference, Cham, Switzerland.","DOI":"10.1007\/978-3-319-11119-3_31"},{"key":"ref_19","doi-asserted-by":"crossref","unstructured":"Oh, S. (2007). Permission-Centric Hybrid Access Control. Advances in Web and Network Technologies, and Information Management, Springer.","DOI":"10.1007\/978-3-540-72909-9_76"},{"key":"ref_20","doi-asserted-by":"crossref","first-page":"763","DOI":"10.1016\/j.infsof.2014.02.003","article-title":"Building hybrid access control by configuring RBAC and MAC features","volume":"56","author":"Kim","year":"2014","journal-title":"Inf. Softw. Technol."},{"key":"ref_21","first-page":"3","article-title":"Study of access control models","volume":"2","author":"Ennahbaoui","year":"2013","journal-title":"Proc. World Congr. Eng."},{"key":"ref_22","doi-asserted-by":"crossref","first-page":"303","DOI":"10.1016\/j.procs.2019.08.044","article-title":"HoBAC: Toward a higher-order attribute-based access control model","volume":"155","author":"Aliane","year":"2019","journal-title":"Procedia Comput. Sci."},{"key":"ref_23","doi-asserted-by":"crossref","unstructured":"Servos, D., and Osborn, S.L. (2014). HGABAC: Towards a formal model of hierarchical attribute-based access control. International Symposium on Foundations and Practice of Security, Springer.","DOI":"10.1007\/978-3-319-17040-4_12"},{"key":"ref_24","unstructured":"Layouni, F., and Pollet, Y. (2009, January 27). Fi-orbac: A model of access control for federated identity platform. Proceedings of the IADIS International Conference Information Systems, Barcelona, Spain."},{"key":"ref_25","doi-asserted-by":"crossref","unstructured":"Nguyen, P.H., Nain, G., Klein, J., Mouelhi, T., and Le Traon, Y. (2013, January 24). Model-driven adaptive delegation. Proceedings of the 12th Annual International Conference on Aspect-Oriented Software Development, New York, NY, USA.","DOI":"10.1145\/2451436.2451445"},{"key":"ref_26","doi-asserted-by":"crossref","unstructured":"Klarl, H., Molitorisz, K., Emig, C., Klinger, K., and Abeck, S. (2009, January 18\u201323). Extending Role-based Access Control for Business Usage. Proceedings of the 2009 Third International Conference on Emerging Security Information, Systems and Technologies, Athens, Greece.","DOI":"10.1109\/SECURWARE.2009.28"},{"key":"ref_27","doi-asserted-by":"crossref","first-page":"5927","DOI":"10.1007\/s12652-020-02102-y","article-title":"HoBAC: Fundamentals, principles, and policies","volume":"11","author":"Adda","year":"2020","journal-title":"J. Ambient. Intell. Humaniz. Comput."},{"key":"ref_28","doi-asserted-by":"crossref","unstructured":"Barker, S. (2009, January 3). The next 700 access control models or a unifying meta-model?. Proceedings of the 14th ACM Symposium on Access Control Models and Technologies, New York, NY, USA.","DOI":"10.1145\/1542207.1542238"},{"key":"ref_29","doi-asserted-by":"crossref","first-page":"187","DOI":"10.1016\/j.ic.2014.07.009","article-title":"A metamodel of access control for distributed environments: Applications and properties","volume":"238","author":"Bertolissi","year":"2014","journal-title":"Inf. Comput."},{"key":"ref_30","doi-asserted-by":"crossref","unstructured":"Khamadja, S., Adi, K., and Logrippo, L. (2013, January 26\u201328). Designing flexible access control models for the cloud. Proceedings of the 6th International Conference on Security of Information and Networks, Aksaray, Turkey.","DOI":"10.1145\/2523514.2527005"},{"key":"ref_31","doi-asserted-by":"crossref","unstructured":"Trnini\u0107, B., Sladi\u0107, G., Milosavljevi\u0107, G., Milosavljevi\u0107, B., and Konjovi\u0107, Z. (2013, January 22\u201324). Policydsl: Towards generic access control management based on a policy metamodel. Proceedings of the 2013 IEEE 12th International Conference on Intelligent Software Methodologies, Tools and Techniques (SoMeT), Budapest, Hungary.","DOI":"10.1109\/SoMeT.2013.6645665"},{"key":"ref_32","doi-asserted-by":"crossref","unstructured":"Slimani, N., Khambhammettu, H., Adi, K., and Logrippo, L. (2011, January 7\u201310). UACML: Unified access control modeling language. Proceedings of the 2011 4th IFIP International Conference on New Technologies, Mobility and Security, Paris, France.","DOI":"10.1109\/NTMS.2011.5721143"},{"key":"ref_33","doi-asserted-by":"crossref","unstructured":"Alves, S., Degtyarev, A., and Fern\u00e1ndez, M. (2014). Access control and obligations in the category-based metamodel: A rewrite-based semantics. International Symposium on Logic-Based Program Synthesis and Transformation, Springer.","DOI":"10.1007\/978-3-319-17822-6_9"},{"key":"ref_34","first-page":"1","article-title":"Modeling enterprise authorization: A unified metamodel and initial validation","volume":"7","author":"Korman","year":"2016","journal-title":"Complex Syst. Inform. Model. Q."},{"key":"ref_35","doi-asserted-by":"crossref","unstructured":"Ferraiolo, D., Chandramouli, R., Kuhn, R., and Hu, V. (2016, January 11). Extensible access control markup language (XACML) and next generation access control (NGAC). Proceedings of the 2016 ACM International Workshop on Attribute Based Access Control, New Orleans, LA, USA.","DOI":"10.1145\/2875491.2875496"},{"key":"ref_36","doi-asserted-by":"crossref","unstructured":"Bertino, E., Jabal, A.A., Calo, S., Makaya, C., Touma, M., Verma, D., and Williams, C. (2017, January 25\u201330). Provenance-based analytics services for access control policies. Proceedings of the 2017 IEEE World Congress on Services (SERVICES), Honolulu, HI, USA.","DOI":"10.1109\/SERVICES.2017.24"},{"key":"ref_37","doi-asserted-by":"crossref","unstructured":"Hu, V.C., Kuhn, D.R., and Xie, T. (2008, January 17\u201320). Property verification for generic access control models. Proceedings of the 2008 IEEE\/IFIP International Conference on Embedded and Ubiquitous Computing, Shanghai, China.","DOI":"10.1109\/EUC.2008.22"},{"key":"ref_38","doi-asserted-by":"crossref","unstructured":"Hu, V.C., Kuhn, R., and Yaga, D. (2017). Verification and Test Methods for Access Control Policies\/Models, NIST Special Publication.","DOI":"10.6028\/NIST.SP.800-192"},{"key":"ref_39","doi-asserted-by":"crossref","unstructured":"Vanickis, R., Jacob, P., Dehghanzadeh, S., and Lee, B. (2018, January 21\u201322). Access control policy enforcement for zero-trust-networking. Proceedings of the 2018 29th Irish Signals and Systems Conference (ISSC), Belfast, UK.","DOI":"10.1109\/ISSC.2018.8585365"},{"key":"ref_40","doi-asserted-by":"crossref","unstructured":"Norman, T. (2014). 5-Electronics Elements (High-Level Discussion). Integrated Security Systems Design, Butterworth-Heinemann. [2nd ed.].","DOI":"10.1016\/B978-0-12-800022-9.00005-X"},{"key":"ref_41","doi-asserted-by":"crossref","first-page":"237","DOI":"10.1016\/j.comnet.2016.11.007","article-title":"Access control in the Internet of Things: Big challenges and new opportunities","volume":"112","author":"Ouaddah","year":"2017","journal-title":"Comput. Netw."},{"key":"ref_42","doi-asserted-by":"crossref","first-page":"79","DOI":"10.1016\/j.jnca.2019.06.017","article-title":"Access control in Internet-of-Things: A survey","volume":"144","author":"Ravidas","year":"2019","journal-title":"J. Netw. Comput. Appl."}],"container-title":["Journal of Cybersecurity and Privacy"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/2624-800X\/2\/1\/4\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,10]],"date-time":"2025-10-10T22:18:55Z","timestamp":1760134735000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/2624-800X\/2\/1\/4"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,2,14]]},"references-count":42,"journal-issue":{"issue":"1","published-online":{"date-parts":[[2022,3]]}},"alternative-id":["jcp2010004"],"URL":"https:\/\/doi.org\/10.3390\/jcp2010004","relation":{},"ISSN":["2624-800X"],"issn-type":[{"value":"2624-800X","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022,2,14]]}}}