{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,11,27]],"date-time":"2025-11-27T13:55:26Z","timestamp":1764251726022,"version":"build-2065373602"},"reference-count":35,"publisher":"MDPI AG","issue":"19","license":[{"start":{"date-parts":[[2021,9,29]],"date-time":"2021-09-29T00:00:00Z","timestamp":1632873600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Sensors"],"abstract":"<jats:p>The substantial advancements in information technologies have brought unprecedented concepts and challenges to provide solutions and integrate advanced and self-ruling systems in critical and heterogeneous structures. The new generation of networking environments (e.g., the Internet of Things (IoT), cloud computing, etc.) are dynamic and ever-evolving environments. They are composed of various private and public networks, where all resources are distributed and accessed from everywhere. Protecting resources by controlling access to them is a complicated task, especially with the presence of cybercriminals and cyberattacks. What makes this reality also challenging is the diversity and the heterogeneity of access control (AC) models, which are implemented and integrated with a countless number of information systems. The evolution of ubiquitous computing, especially the concept of Industry 4.0 and IoT applications, imposes the need to enhance AC methods since the traditional methods are not able to answer the increasing demand for privacy and security standards. To address this issue, we propose a Hierarchical, Extensible, Advanced, and Dynamic (HEAD) AC metamodel for dynamic and heterogeneous structures that is able to encompass the heterogeneity of the existing AC models. Various AC models can be derived, and different static and dynamic AC policies can be generated using its components. We use Eclipse (xtext) to define the grammar of our AC metamodel. We illustrate our approach with several successful instantiations for various models and hybrid models. Additionally, we provide some examples to show how some of the derived models can be implemented to generate AC policies.<\/jats:p>","DOI":"10.3390\/s21196507","type":"journal-article","created":{"date-parts":[[2021,10,8]],"date-time":"2021-10-08T21:26:20Z","timestamp":1633728380000},"page":"6507","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":4,"title":["HEAD Metamodel: Hierarchical, Extensible, Advanced, and Dynamic Access Control Metamodel for Dynamic and Heterogeneous Structures"],"prefix":"10.3390","volume":"21","author":[{"given":"Nadine","family":"Kashmar","sequence":"first","affiliation":[{"name":"D\u00e9partement de Math\u00e9matiques, Informatique et G\u00e9nie, Universit\u00e9 du Qu\u00e9bec \u00e0 Rimouski, 300 All\u00e9e des Ursulines, Rimouski, QC G5L 3A1, Canada"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5327-1758","authenticated-orcid":false,"given":"Mehdi","family":"Adda","sequence":"additional","affiliation":[{"name":"D\u00e9partement de Math\u00e9matiques, Informatique et G\u00e9nie, Universit\u00e9 du Qu\u00e9bec \u00e0 Rimouski, 300 All\u00e9e des Ursulines, Rimouski, QC G5L 3A1, Canada"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9177-2967","authenticated-orcid":false,"given":"Hussein","family":"Ibrahim","sequence":"additional","affiliation":[{"name":"Institut Technologique de Maintenance Industrielle, 175 Rue de la V\u00e9rendrye, Sept-\u00celes, QC G4R 5B7, Canada"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1968","published-online":{"date-parts":[[2021,9,29]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","unstructured":"Zhang, Y., Nakanishi, R., Sasabe, M., and Kasahara, S. (2021). Combining IOTA and Attribute-Based Encryption for Access Control in the Internet of Things. Sensors, 21.","DOI":"10.3390\/s21155053"},{"key":"ref_2","doi-asserted-by":"crossref","unstructured":"Cruz-Piris, L., Rivera, D., Marsa-Maestre, I., De La Hoz, E., and Velasco, J.R. (2018). Access control mechanism for IoT environments based on modelling communication procedures as resources. Sensors, 18.","DOI":"10.3390\/s18030917"},{"key":"ref_3","doi-asserted-by":"crossref","unstructured":"Kalsoom, T., Ramzan, N., Ahmed, S., and Ur-Rehman, M. (2020). Advances in sensor technologies in the era of smart factory and industry 4.0. Sensors, 20.","DOI":"10.3390\/s20236783"},{"key":"ref_4","doi-asserted-by":"crossref","unstructured":"Kashmar, N., Adda, M., Atieh, M., and Ibrahim, H. (2021). Access Control in Cybersecurity and Social Media. Cybers\u00e9curit\u00e9 M\u00e9dias Sociaux, 69\u2013105.","DOI":"10.1515\/9782763753294-005"},{"key":"ref_5","doi-asserted-by":"crossref","first-page":"445","DOI":"10.1016\/j.procs.2021.03.056","article-title":"A review of access control metamodels","volume":"184","author":"Kashmar","year":"2021","journal-title":"Procedia Comput. Sci."},{"key":"ref_6","doi-asserted-by":"crossref","unstructured":"Kashmar, N., Adda, M., and Atieh, M. (2019). From Access Control Models to Access Control Metamodels: A Survey. Future of Information and Communication Conference, Springer.","DOI":"10.1007\/978-3-030-12385-7_61"},{"key":"ref_7","doi-asserted-by":"crossref","unstructured":"Rajpoot, Q.M., Jensen, C.D., and Krishnan, R. (2015). Attributes enhanced role-based access control model. International Conference on Trust and Privacy in Digital Business, Springer.","DOI":"10.1007\/978-3-319-22906-5_1"},{"key":"ref_8","doi-asserted-by":"crossref","unstructured":"Servos, D., and Osborn, S.L. (2014). HGABAC: Towards a formal model of hierarchical attribute-based access control. International Symposium on Foundations and Practice of Security, Springer.","DOI":"10.1007\/978-3-319-17040-4_12"},{"key":"ref_9","doi-asserted-by":"crossref","first-page":"303","DOI":"10.1016\/j.procs.2019.08.044","article-title":"HoBAC: Toward a higher-order attribute-based access control model","volume":"155","author":"Aliane","year":"2019","journal-title":"Procedia Comput. Sci."},{"key":"ref_10","doi-asserted-by":"crossref","first-page":"887","DOI":"10.1016\/j.procs.2021.03.111","article-title":"Access control metamodel for policy specification and enforcement: From conception to formalization","volume":"184","author":"Kashmar","year":"2021","journal-title":"Procedia Comput. Sci."},{"key":"ref_11","doi-asserted-by":"crossref","unstructured":"Kashmar, N., Adda, M., and Ibrahim, H. (2021). Access Control Metamodels: Review, Critical Analysis, and Research Issues. J. Ubiquitous Syst. Pervasive Netw., 3, in press.","DOI":"10.1016\/j.procs.2021.03.056"},{"key":"ref_12","doi-asserted-by":"crossref","unstructured":"Ja\u00efdi, F., Labbene Ayachi, F., and Bouhoula, A. (2018). A methodology and toolkit for deploying reliable security policies in critical infrastructures. Secur. Commun. Netw., 2018.","DOI":"10.1155\/2018\/7142170"},{"key":"ref_13","doi-asserted-by":"crossref","unstructured":"Myrbakken, H., and Colomo-Palacios, R. (2017). DevSecOps: A multivocal literature review. International Conference on Software Process Improvement and Capability Determination, Springer.","DOI":"10.1007\/978-3-319-67383-7_2"},{"key":"ref_14","doi-asserted-by":"crossref","unstructured":"Mao, R., Zhang, H., Dai, Q., Huang, H., Rong, G., Shen, H., Chen, L., and Lu, K. (2020, January 11\u201314). Preliminary findings about devsecops from grey literature. Proceedings of the 2020 IEEE 20th International Conference on Software Quality, Reliability and Security (QRS), Macau, China.","DOI":"10.1109\/QRS51102.2020.00064"},{"key":"ref_15","doi-asserted-by":"crossref","first-page":"85","DOI":"10.1109\/MC.2015.33","article-title":"Attribute-based access control","volume":"48","author":"Hu","year":"2015","journal-title":"Computer"},{"key":"ref_16","doi-asserted-by":"crossref","first-page":"38","DOI":"10.1109\/2.485845","article-title":"Access control models","volume":"29","author":"Sandhu","year":"2013","journal-title":"IEEE Comput."},{"key":"ref_17","doi-asserted-by":"crossref","unstructured":"Kashmar, N., Adda, M., Atieh, M., and Ibrahim, H. (2019, January 25\u201331). A new dynamic smart-AC model methodology to enforce access control policy in IoT layers. Proceedings of the 2019 IEEE\/ACM 1st International Workshop on Software Engineering Research & Practices for the Internet of Things (SERP4IoT), Montreal, QC, Canada.","DOI":"10.1109\/SERP4IoT.2019.00011"},{"key":"ref_18","unstructured":"Sun, K., and Yin, L. (2014). Attribute-role-based hybrid access control in the internet of things. Asia-Pacific Web Conference, Springer."},{"key":"ref_19","doi-asserted-by":"crossref","unstructured":"Hasiba, B.A., Kahloul, L., and Benharzallah, S. (2017, January 5\u20137). A new hybrid access control model for multi-domain systems. Proceedings of the 2017 4th International Conference on Control, Decision and Information Technologies (CoDIT), Barcelona, Spain.","DOI":"10.1109\/CoDIT.2017.8102687"},{"key":"ref_20","doi-asserted-by":"crossref","first-page":"79","DOI":"10.1109\/MC.2010.155","article-title":"Adding attributes to role-based access control","volume":"43","author":"Kuhn","year":"2010","journal-title":"Computer"},{"key":"ref_21","doi-asserted-by":"crossref","unstructured":"Aftab, M.U., Qin, Z., Hundera, N.W., Ariyo, O., Son, N.T., and Dinh, T.V. (2019). Permission-based separation of duty in dynamic role-based access control model. Symmetry, 11.","DOI":"10.3390\/sym11050669"},{"key":"ref_22","doi-asserted-by":"crossref","first-page":"763","DOI":"10.1016\/j.infsof.2014.02.003","article-title":"Building hybrid access control by configuring RBAC and MAC features","volume":"56","author":"Kim","year":"2014","journal-title":"Inf. Softw. Technol."},{"key":"ref_23","doi-asserted-by":"crossref","unstructured":"Li, H., Wang, S., Tian, X., Wei, W., and Sun, C. (2015). A survey of extended role-based access control in cloud computing. Proceedings of the 4th International Conference on Computer Engineering and Networks, Springer.","DOI":"10.1007\/978-3-319-11104-9_95"},{"key":"ref_24","doi-asserted-by":"crossref","unstructured":"Nguyen, P.H., Nain, G., Klein, J., Mouelhi, T., and Le Traon, Y. (2013). Model-driven adaptive delegation. AOSD\u201913: Proceedings of the 12th Annual International Conference on Aspect-Oriented Software Development, ACM.","DOI":"10.1145\/2451436.2451445"},{"key":"ref_25","doi-asserted-by":"crossref","first-page":"5927","DOI":"10.1007\/s12652-020-02102-y","article-title":"HoBAC: Fundamentals, principles, and policies","volume":"11","author":"Adda","year":"2020","journal-title":"J. Ambient. Intell. Humaniz. Comput."},{"key":"ref_26","doi-asserted-by":"crossref","unstructured":"Slimani, N., Khambhammettu, H., Adi, K., and Logrippo, L. (2011, January 7\u201310). UACML: Unified access control modeling language. Proceedings of the 2011 4th IFIP International Conference on New Technologies, Mobility and Security, Paris, France.","DOI":"10.1109\/NTMS.2011.5721143"},{"key":"ref_27","doi-asserted-by":"crossref","unstructured":"Barker, S. (2009). The next 700 access control models or a unifying meta-model?. SACMAT\u201909: Proceedings of the 14th ACM symposium on Access Control Models and Technologies, ACM.","DOI":"10.1145\/1542207.1542238"},{"key":"ref_28","doi-asserted-by":"crossref","first-page":"187","DOI":"10.1016\/j.ic.2014.07.009","article-title":"A metamodel of access control for distributed environments: Applications and properties","volume":"238","author":"Bertolissi","year":"2014","journal-title":"Inf. Comput."},{"key":"ref_29","doi-asserted-by":"crossref","first-page":"784","DOI":"10.17706\/\/jsw.10.7.784-797","article-title":"A Metamodel for Hybrid Access Control Policies","volume":"10","author":"Logrippo","year":"2015","journal-title":"J. Softw."},{"key":"ref_30","doi-asserted-by":"crossref","unstructured":"Alves, S., Degtyarev, A., and Fern\u00e1ndez, M. (2014). Access control and obligations in the category-based metamodel: A rewrite-based semantics. International Symposium on Logic-Based Program Synthesis and Transformation, Springer.","DOI":"10.1007\/978-3-319-17822-6_9"},{"key":"ref_31","doi-asserted-by":"crossref","unstructured":"Khamadja, S., Adi, K., and Logrippo, L. (2013, January 26\u201328). Designing flexible access control models for the cloud. Proceedings of the 6th International Conference on Security of Information and Networks, Aksaray, Turkey.","DOI":"10.1145\/2523514.2527005"},{"key":"ref_32","unstructured":"Xia, T., Washizaki, H., Kato, T., Kaiya, H., Ogata, S., Fernandez, E.B., Kanuka, H., Yoshino, M., Yamamoto, D., and Okubo, T. (2018, January 22\u201324). Cloud security and privacy metamodel. Proceedings of the 6th International Conference on Model-Driven Engineering and Software Development, Funchal, Portugal."},{"key":"ref_33","doi-asserted-by":"crossref","unstructured":"Mart\u00ednez, S., Garcia-Alfaro, J., Cuppens, F., Cuppens-Boulahia, N., and Cabot, J. (2013). Towards an access-control metamodel for web content management systems. International Conference on Web Engineering, Springer.","DOI":"10.1007\/978-3-319-04244-2_14"},{"key":"ref_34","doi-asserted-by":"crossref","first-page":"162","DOI":"10.1016\/j.procs.2020.10.024","article-title":"Deriving access control models based on generic and dynamic metamodel architecture: Industrial use case","volume":"177","author":"Kashmar","year":"2020","journal-title":"Procedia Comput. Sci."},{"key":"ref_35","doi-asserted-by":"crossref","first-page":"417","DOI":"10.1016\/j.procs.2019.08.058","article-title":"Smart-ac: A new framework concept for modeling access control policy","volume":"155","author":"Kashmar","year":"2019","journal-title":"Procedia Comput. Sci."}],"container-title":["Sensors"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1424-8220\/21\/19\/6507\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,11]],"date-time":"2025-10-11T07:07:16Z","timestamp":1760166436000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1424-8220\/21\/19\/6507"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,9,29]]},"references-count":35,"journal-issue":{"issue":"19","published-online":{"date-parts":[[2021,10]]}},"alternative-id":["s21196507"],"URL":"https:\/\/doi.org\/10.3390\/s21196507","relation":{},"ISSN":["1424-8220"],"issn-type":[{"type":"electronic","value":"1424-8220"}],"subject":[],"published":{"date-parts":[[2021,9,29]]}}}