Abstract
Risk-aware access control is an important mechanism for protecting sensitive resources in dynamic information systems. However, existing access-control models still face limitations in modeling behavioral uncertainty, integrating multi-dimensional risk evidence, and adjusting permissions after authorization. Therefore, this paper proposes a risk-aware access-control model based on multi-attribute behavior modeling and fuzzy inference. First, multi-source access signals are transformed into seven risk indicators covering subject, behavior, and environment dimensions. Then, IT2FS, constrained-blended CRITIC, TOPSIS, and supervised calibration are integrated to model uncertainty, compute objective risk weights, and generate calibrated risk levels. Finally, the calibrated risk state is mapped to dynamic access-control actions, enabling adaptive permission adjustment and audit-oriented decision support. Experimental results show that the proposed full model achieves an Accuracy of 0.9820, a Macro-F1 of 0.9639, and a high-risk AUC of 0.9986 on the controlled labeled access-request dataset, outperforming traditional RiskBAC and most fuzzy-, TOPSIS-, and dynamic access-control baselines. External validation on UNSW-NB15 and LANL authentication logs further demonstrates the transferability and robustness of the proposed framework, indicating its potential applicability to dynamic access-control scenarios such as cloud computing, IoT, and enterprise information systems.
References
Ali M, Khan SU, Vasilakos AV (2015) Security in cloud computing: Opportunities and challenges. Inf Sci 305:357–383. https://doi.org/10.1007/s11227-025-07299-3
Ravinder Reddy B, Anil Kumar A (2019) Survey on access control mechanisms in cloud environments. In: International Conference on Advances in Computational Intelligence and Informatics, 141–149. https://doi.org/10.1007/978-981-15-3338-9_18 Springer
Wang S, Luo N, Xing B, Sun Z, Zhang H, Sun C (2024) Blockchain-based proxy re-encryption access control method for biological risk privacy protection of agricultural products. Sci Rep 14(1):20048. https://doi.org/10.1038/s41598-024-70533-0
Albalawi N (2025) Dynamic computational offloading approaches for iot devices in cloud computing. J Supercomput 81(9):1075. https://doi.org/10.1007/s11227-025-07551-w
Osborn S, Sandhu R, Munawer Q (2000) Configuring role-based access control to enforce mandatory and discretionary access control policies. ACM Trans Inf Syst Secur (TISSEC) 3(2):85–106. https://doi.org/10.1145/354876.354878
Jin X, Krishnan R, Sandhu R (2012) A unified attribute-based access control model covering dac, mac and rbac. In: Data and Applications Security and Privacy XXVI: 26th Annual IFIP WG 11.3 Conference, DBSec 2012, Paris, France, July 11-13, 2012. Proceedings 26, pp. 41–55. https://doi.org/10.1007/978-3-642-31540-4_4 Springer
Tan L, Shi N, Yang C, Yu K (2020) A blockchain-based access control framework for cyber-physical-social system big data. IEEE Access 8:77215–77226. https://doi.org/10.1109/ACCESS.2020.2988951
Sandhu RS (1998) Role-based access control. In: Zelkowitz, M.V. (ed.) Advances in Computers vol. 46, pp. 237–286. Academic Press, San Diego, CA, USA. https://doi.org/10.1016/S0065-2458(08)60206-5
Ni Q, Bertino E, Lobo J (2010) Risk-based access control systems built on fuzzy inferences. In: Proceedings of the 5th ACM Symposium on Information, Computer and Communications Security, pp 250–260. https://doi.org/10.1145/1755688.1755719
Atlam HF, Azad MA, Alassafi MO, Alshdadi AA, Alenezi A (2020) Risk-based access control model: A systematic literature review. Future Internet 12(6):103. https://doi.org/10.3390/fi12060103
Savinov S (2017) A dynamic risk-based access control approach: model and implementation
Huang H-D, Lee C-S, Wang M-H, Kao H-Y (2014) It2fs-based ontology with soft-computing mechanism for malware behavior analysis. Soft Comput 18(2):267–284. https://doi.org/10.1007/s00500-013-1056-0
Behzadian M, Otaghsara SK, Yazdani M, Ignatius J (2012) A state-of the-art survey of topsis applications. Expert Syst Appl 39(17):13051–13069. https://doi.org/10.1016/j.eswa.2012.05.056
Sahani GJ, Thaker CS, Shah SM (2022) Scalable rbac model for large-scale applications with automatic user-role assignment. Int J Commun Netw Distrib Syst 28(1):76–102. https://doi.org/10.1504/IJCNDS.2022.120294
Zhao B, Zheng G, Gao Y, Zhao Y (2022) Access-control model of super business system based on business entity. Electronics 11(19):3073. https://doi.org/10.3390/electronics11193073
Rao KR, Nayak A, Ray IG, Rahulamathavan Y, Rajarajan M (2021) Role recommender-rbac: Optimizing user-role assignments in rbac. Comput Commun 166:140–153. https://doi.org/10.1016/j.comcom.2020.12.006
Shin S, Park M, Kim T, Yang H (2024) Architecture for enhancing communication security with rbac iot protocol-based microgrids. Sensors 24(18):6000. https://doi.org/10.3390/s24186000
Abushmmala FF, AbuSamra A (2023) Blockchain-based secure smart health iot solution using rbac architecture. J Eng Res Technol 10(2) https://doi.org/10.33976/JERT.10.2/2023/1
Wang J, Wang Z, Song J, Cheng H (2023) Attribute and user trust score-based zero trust access control model in iov. Electronics 12(23):4825. https://doi.org/10.3390/electronics12234825
Picard N, Colin J-N, Zampunieris D (2018) Context-aware and attribute-based access control applying proactive computing to iot system. In: SPBDIoT 2018–Special Session on Recent Advances on Security, Privacy, Big Data and Internet of Things at the 3rd International Conference on Internet of Things, Big Data and Security (IoTBDS 2018). https://doi.org/10.5220/0006815803330339 SCITEPRESS
Shan F, Wang Z, Liu M, Zhang M (2024) Automatic generation of attribute-based access control policies from natural language documents. Comput, Mater Continua 80(3) https://doi.org/10.32604/cmc.2024.055167
Namane S, Ben Dhaou I (2022) Blockchain-based access control techniques for iot applications. Electronics 11(14):2225. https://doi.org/10.3390/electronics11142225
Shaikh RA, Adi K, Logrippo L (2012) Dynamic risk-based decision methods for access control systems. Comput Security 31(4):447–464. https://doi.org/10.1016/j.cose.2012.02.006
Chen J, Hengartner U, Khan H (2024) Mraac: a multi-stage risk-aware adaptive authentication and access control framework for android. ACM Trans Privacy Security 27(2):1–30. https://doi.org/10.1145/3648372
Lytvyn V, Bakurova A, Zaritskyi O, Gritskevich A, Hrynchenko P, Tereschenko E, Shyrokorad D (2024) Fuzzy logic-based methodology for building access control systems based on fuzzy logic. MoDaST, pp 104–120
Yang C, Liang J, Chen X (2023) Distributed event-based h8 consensus filtering for 2-d ts fuzzy systems over sensor networks subject to dos attacks. Inf Sci 641:119079. https://doi.org/10.1016/j.ins.2023.119079
Shen H, Liu X, Xia J, Chen X, Wang J (2021) Finite-time energy-to-peak fuzzy filtering for persistent dwell-time switched nonlinear systems with unreliable links. Inf Sci 579:293–309. https://doi.org/10.1016/j.ins.2021.07.081
Xu J, Sui Y, Yu T, Ding R, Dai T, Zheng M (2024) A new fuzzy bayesian inference approach for risk assessments. Symmetry 16(7):786. https://doi.org/10.3390/sym16070786
Jiang R, Han S, Zhang Y, Chen T, Song J (2022) Medical big data access control model based on uphfpr and evolutionary game. Alex Eng J 61(12):10659–10675. https://doi.org/10.1016/j.aej.2022.03.075
Vafaei Nejad F, Gilanian Sadeghi MM, Rezvani MH (2025) Secure routing in rpl-based iot networks considering behavioral trust and energy requirements. J Supercomput 81(8):891. https://doi.org/10.1007/s11227-025-07299-3
Farshadinia H, Barati A, Barati H (2025) A secure and energy-efficient architecture in internet of things–cloud computing network by enhancing and combining three cryptographic techniques via defining new features, areas, and entities: H. farshadinia et al. J Supercomput 81(8):944 https://doi.org/10.1007/s11227-025-07390-9
Dwivedi A, Agarwal R, Yahya M, Alduaiji N, Shukla PK (2025) A blockchain-enabled encrypted neural network framework for trust-aware key management and node authentication in industrial internet of things. J Supercomput 81(9):1059. https://doi.org/10.1007/s11227-025-07566-3
Zhu X, Zhou W, Han Q-L, Ma W, Wen S, Xiang Y (2025) When software security meets large language models: A survey. IEEE/CAA J Automat Sin 12(2):317–334. https://doi.org/10.1109/JAS.2024.124971
Zhou W, Zhu X, Han Q-L, Li L, Chen X, Wen S, Xiang Y (2024) The security of using large language models: A survey with emphasis on chatgpt. IEEE/CAA J Automat Sin 12(1):1–26. https://doi.org/10.1109/JAS.2024.124983
Moustafa N, Slay J (2015) Unsw-nb15: a comprehensive data set for network intrusion detection systems (unsw-nb15 network data set). In: 2015 Military Communications and Information Systems Conference (MilCIS), pp 1–6. https://doi.org/10.1109/MilCIS.2015.7348942 IEEE
Kent AD (2015) Comprehensive, multi-source cyber-security events data set. Technical report, Los Alamos National Lab. (LANL), Los Alamos, NM (United States), https://doi.org/10.17021/1179829
Ma Y-W, Chiu P-H (2025) A novel risk-based access control engine in zero trust architecture for iot network. Int J Inf Secur 24(3):124. https://doi.org/10.1007/s10207-025-01030-2
Jiang R, Han S, Yu Y, Ding W (2023) An access control model for medical big data based on clustering and risk. Inf Sci 621:691–707. https://doi.org/10.1016/j.ins.2022.11.102
Wang R, Li C, Zhang K, Tu B (2025) Zero-trust based dynamic access control for cloud computing. Cybersecurity 8(1):12. https://doi.org/10.1186/s42400-024-00320-x
Ribeiro MT, Singh S, Guestrin C (2016) “ why should i trust you?” explaining the predictions of any classifier. In: Proceedings of the 22nd ACM SIGKDD International Conference on Knowledge Discovery and Data Mining, pp 1135–1144. https://doi.org/10.1145/2939672.2939778
Lundberg SM, Lee S-I (2017) A unified approach to interpreting model predictions. Adv Neu Info Process Sys. p 30
Funding
This work is supported by the Natural Science Foundation of Shandong Province [fund number ZR2023MF090, ZR2020MF029].
Author information
Authors and Affiliations
Corresponding authors
Ethics declarations
Conflict of interest
The authors declare no conflict of interest.
Additional information
Publisher's Note
Springer Nature remains neutral with regard to jurisdictional claims in published maps and institutional affiliations.
Rights and permissions
Springer Nature or its licensor (e.g. a society or other partner) holds exclusive rights to this article under a publishing agreement with the author(s) or other rightsholder(s); author self-archiving of the accepted manuscript version of this article is solely governed by the terms of such publishing agreement and applicable law.
About this article
Cite this article
Ye, C., Li, Y., Gao, Y. et al. A risk-aware access-control model based on multi-attribute behavior modeling and fuzzy inference. J Supercomput 82, 667 (2026). https://doi.org/10.1007/s11227-026-08822-w
Received:
Accepted:
Published:
Version of record:
DOI: https://doi.org/10.1007/s11227-026-08822-w
Facts Only
* The proposed model is based on multi-attribute behavior modeling and fuzzy inference for risk-aware access control.
* Multi-source access signals are transformed into seven risk indicators covering subject, behavior, and environment dimensions.
* IT2FS, constrained-blended CRITIC, TOPSIS, and supervised calibration are integrated to model uncertainty and compute objective risk weights.
* The calibrated risk state is mapped to dynamic access-control actions for permission adjustment.
* Experimental results showed an Accuracy of 0.9820, a Macro-F1 of 0.9639, and a high-risk AUC of 0.9986 on the labeled dataset.
* The framework was externally validated using UNSW-NB15 and LANL authentication logs.
* The research pertains to dynamic access control in scenarios like cloud computing, IoT, and enterprise systems.
Executive Summary
Full Take
Sentinel — Human
This text exhibits the structure, density of technical detail, and specific citation patterns strongly indicative of a formal academic research paper authored by human experts.
