Call For Paper September 2026

Research Article | Open Access | Download PDF
Volume 13 | Issue 9 | Year 2026 | Article Id. IJECE-V13I9P108 | DOI : https://doi.org/10.14445/23488549/IJECE-V13I9P108

A Risk-Adaptive Attribute-Based Access Control Framework with Ternary Decision Logic for Context-Aware IoT Security


Rashmin Prajapati, Sweta S. Panchal, Neha Soni, Sandipkumar R. Panchal

Received Revised Accepted Published
16 Jun 2026 08 Sep 2026 11 Sep 2026 29 Sep 2026

Citation :

Rashmin Prajapati, Sweta S. Panchal, Neha Soni, Sandipkumar R. Panchal, "A Risk-Adaptive Attribute-Based Access Control Framework with Ternary Decision Logic for Context-Aware IoT Security," International Journal of Electronics and Communication Engineering, vol. 13, no. 9, pp. 120-146, 2026. Crossref, https://doi.org/10.14445/23488549/IJECE-V13I9P108

Abstract

As the Internet of Things (IoT) grows rapidly, security concerns are rising, as these devices are diverse, the operating environments change constantly and data are exchanged continuously. This paper is an extension of our previous published machine-learning based Risk-Adaptive Attribute-Based Access Control (RAd-ABAC) system where contextual risk estimation and Permit–Review–Deny authorization were introduced. The present study builds upon this in an implementation-oriented architecture including a Contextual Attribute Collector, Risk Evaluation Engine, and Decision Management Engine. These attributes of the user (role, location, time, device) are converted to a normalized risk indicator and weighted through a mechanism of risk aggregation. The contextual risk score is then fed into two decision thresholds to ultimately determine access rules (Permit, Review, Deny). Three publicly available IoT security datasets—IoT-23, TON_IoT, and IoT Intrusion Detection dataset—were used to evaluate the framework. These datasets were used to map network, temporal, behavioral and device attributes to access-control attributes. The models were built and tested with a 70:30 train–test split. Logistic Regression and Random Forest models were trained and tested with a 70:30 training-testing split. The accuracy, precision, recall, F1 score, confusion matrix, receiver operating characteristic curve, area under the curve and false-positive and false-negative rates were measured. The Random Forest model outperformed Logistic Regression with precision and recall values closer to each other, with an accuracy of over 96%. The intermediate Review state allowed indefinite access requests to be reviewed again before granting or denying access, which helped to decrease false dichotomy decisions. The present study introduces a modular processing architecture, explicit contextual-attribute transformation, quantitative validation of the processing across three heterogeneous datasets, and expanded. These developments provide greater visibility, flexibility and utility of context-aware access control in diverse IoT environments.

Keywords

Attribute-Based Access Control (ABAC), Context-Aware Access Control, Internet of Things (IoT) Security, Machine Learning in Security, Risk-Adaptive Access Control (RAdAC), Ternary Decision Logic.

References

  1. Nikhil Sharma, and Prashant Giridhar Shambharkar, “Enhancing Internet of Medical Things Security: A Multi-Layered Approach using Dynamic Adaptive Deep Reinforcement Learning and Blockchain,” Computers and Electrical Engineering, vol. 129, pp. 1-37, 2026.
    [
    CrossRef] [Google Scholar] [Publisher Link]
  2. Ferhat Mecerhed et al., “Robust Attribute-Based Access Control Protocol Over Data-Centric IoT–NDN Networking,” Ad Hoc Networks, vol. 182, 2026.
    [
    CrossRef] [Google Scholar] [Publisher Link]
  3. Osman Abul, and Melike Burakgazi Bilgen, “Jointly Achieving Smart Homes Security and Privacy through Bidirectional Trust,” EURASIP Journal on Information Security, vol. 2025, no. 1, pp. 1-20, 2025.
    [
    CrossRef] [Google Scholar] [Publisher Link]
  4. Zhaoqian Zhang, Di Wu, and Shang Gao, “Attribute-Based Access Control with Credible Outsourcing and Collusion-Resistant Revocation Based on Blockchain for Iomt,” Concurrency and Computation: Practice and Experience, vol. 37, no. 12-14, 2025.
    [
    CrossRef] [Google Scholar] [Publisher Link]
  5. Sujoy Roy, Alok Kumar, and Udai Pratap Rao, “FTBAC: Fuzzy Trust based Access Control for Healthcare Cross-Domain Environment,” Soft Computing, vol. 29, no. 7, pp. 3349-3366, 2025.
    [
    CrossRef] [Google Scholar] [Publisher Link]
  6. Maede Ashouri-Talouki et al., “A Revocable Attribute-based Access Control with Non-Monotonic Access Structure,” Annals of Telecommunications, vol. 79, no. 11, pp. 833-842, 2024.
    [
    CrossRef] [Google Scholar] [Publisher Link]
  7. Rashmin Prajapati et al., “Machine Learning-Based Risk-Adaptive Attribute- Based Access Control Framework for Secure IoT Networks,” International Research Journal of Multidisciplinary Technovation, vol. 8, no. 3, pp. 495-519, 2026.
    [
    CrossRef] [Publisher Link]
  8. Zenghui Yang et al., “An Attribute-based Access Control Scheme using Blockchain Technology for IoT Data Protection,” High-Confidence Computing, vol. 4, no. 3, pp. 1-10, 2024.
    [
    CrossRef] [Google Scholar] [Publisher Link]
  9. Melike Burakgazi Bilgen, Osman Abul, and Kemal Bicakci, “Authentication-Enabled Attribute-based Access Control for Smart Homes,” International Journal of Information Security, vol. 22, no. 2, pp. 479-495, 2023.
    [
    CrossRef] [Google Scholar] [Publisher Link]
  10. Himan Namdari et al., “Enhanced Trust in IoT Environments: Utilizing Perfect Bayesian Equilibrium, Exponential Smoothing, and Machine Learning,” Cluster Computing, vol. 28, no. 9, 2025.
    [
    CrossRef] [Google Scholar] [Publisher Link]
  11. Devesh Srivastava et al., “Auto-Scaling of Cloud Applications Using Machine Learning,” 2025 International Conference on Next Generation of Green Information and Emerging Technologies (GIET), Gunupur, India, pp. 1-6, 2025.
    [
    CrossRef] [Google Scholar] [Publisher Link]
  12. M. Ashwin Shenoy et al., “Self-Healing and Optimization in Mesh Networks Using Glowworm Swarm Optimization,” 2025 Second International Conference on Networks and Soft Computing (ICNSoC), Vadlamudi, India, pp. 569-574, 2025.
    [
    CrossRef] [Google Scholar] [Publisher Link]
  13. Zahid Mahmood et al., “User-Trust Centric Lightweight Access Control for Smart IoT Crowd Sensing Applications in Healthcare Systems,” Personal and Ubiquitous Computing, vol. 29, no. 1, pp. 31-44, 2025.
    [
    CrossRef] [Google Scholar] [Publisher Link]
  14. S. M. Rajesh, and R. Prabha, “ICDAC: Intelligent Contracts Driven Access Control Model for IoT Device Communication,” SN Computer Science, vol. 5, no. 8, 2024.
    [
    CrossRef] [Google Scholar] [Publisher Link]
  15. SooHyun Shin et al., “Architecture for Enhancing Communication Security with RBAC IoT Protocol-Based Microgrids,” Sensors, vol. 24, no. 18, pp. 1-18, 2024.
    [
    CrossRef] [Google Scholar] [Publisher Link]
  16. Vahid Bakhtiary et al., “Combo-Chain: Towards a Hierarchical Attribute-based Access Control System for IoT with Smart Contract and Sharding Technique,” Internet of Things, vol. 25, 2024.
    [
    CrossRef] [Google Scholar] [Publisher Link]
  17. Pooja Choksy et al., “Attribute based Access Control (ABAC) Scheme with a Fully Flexible Delegation Mechanism for IoT Healthcare,” Peer-to-Peer Networking and Applications, vol. 16, no. 3, pp. 1445-1467, 2023.
    [
    CrossRef] [Google Scholar] [Publisher Link]
  18. G. Guna et al., “Multi-Objective Genetic Algorithms for Dynamic Resource Optimization in Cloud Computing,” 2025 International Conference on Networks and Cryptology (NETCRYPT), New Delhi, India, pp. 876-881, 2025.
    [
    CrossRef] [Google Scholar] [Publisher Link]
  19. Pietro Colombo, Elena Ferrari, and Engin Deniz Tümer, “Efficient ABAC based Information Sharing within MQTT Environments under Emergencies,” Computers & Security, vol. 120, pp. 1-21, 2022.
    [
    CrossRef] [Google Scholar] [Publisher Link]
  20. Seyed Farhad Aghili et al., “MLS-ABAC: Efficient Multi-Level Security Attribute-based Access Control Scheme,” Future Generation Computer Systems, vol. 131, pp. 75-90, 2022.
    [
    CrossRef] [Google Scholar] [Publisher Link]
  21. Safwa Ameer, James Benson, and Ravi Sandhu, “An Attribute-based Approach Toward a Secured Smart-Home IoT Access Control and a Comparison with a Role-based Approach,” Information, vol. 13, no. 2, pp. 1-33, 2022.
    [
    CrossRef] [Google Scholar] [Publisher Link]
  22. Elham A. Shammar, Ammar T. Zahary, and Asma A. Al-Shargabi, “An Attribute-Based Access Control Model for Internet of Things Using Hyperledger Fabric Blockchain,” Wireless Communications and Mobile Computing, vol. 2022, no. 1, pp. 1-25, 2022.
    [
    CrossRef] [Google Scholar] [Publisher Link]
  23. Syed Yawar Abbas Zaidi et al., “An Attribute-Based Access Control for IoT Using Blockchain and Smart Contracts,” Sustainability, vol. 13, no. 19, pp. 1-26, 2021.
    [
    CrossRef] [Google Scholar] [Publisher Link]
  24. Zhenghao Xin, Liang Liu, and Gerhard Hancke, “AACS: Attribute-based Access Control Mechanism for Smart Locks,” Symmetry, vol. 12, no. 6, pp. 1-18, 2020.
    [
    CrossRef] [Google Scholar] [Publisher Link]
  25. Meiping Liu et al., “An Efficient Attribute-Based Access Control (ABAC) Policy Retrieval Method based on Attribute and Value Levels in Multimedia Networks,” Sensors, vol. 20, no. 6, pp. 1-15, 2020.
    [
    CrossRef] [Google Scholar] [Publisher Link]
  26. Yan Zhang et al., “An Attribute-Based Collaborative Access Control Scheme Using Blockchain for IoT Devices,” Electronics, vol. 9, no. 2, pp. 1-22, 2020.
    [
    CrossRef] [Google Scholar] [Publisher Link]
  27. I. Sudha et al., “Wireless Sensor Network-Driven Human Intrusion Detection Using RT-DETR for Real-Time Perimeter Protection,” 2025 International Conference on Networks and Cryptology (NETCRYPT), New Delhi, India, pp. 195-200, 2025.
    [
    CrossRef] [Google Scholar] [Publisher Link]
  28. Shengmin Xu et al., “A Secure IoT Cloud Storage System with Fine-Grained Access Control and Decryption Key Exposure Resistance,” Future Generation Computer Systems, vol. 97, pp. 284-294, 2019.
    [
    CrossRef] [Google Scholar] [Publisher Link]
  29. Jingpei Wang et al., “An Access Control Method Against Unauthorized and Noncompliant behaviors of Real-Time Data in Industrial IoT,” IEEE Internet of Things Journal, vol. 11, no. 1, pp. 708-727, 2024.
    [
    CrossRef] [Google Scholar] [Publisher Link]
  30. George Suciu et al., “SAMGRID: Security Authorization and Monitoring Module Based on SealedGRID Platform,” Sensors, vol. 22, no. 17, pp. 1-16, 2022.
    [
    CrossRef] [Google Scholar] [Publisher Link]
  31. Bruno Cremonezi et al., “Improving the Attribute Retrieval on ABAC using Opportunistic Caches for Fog-based IoT Networks,” Computer Networks, vol. 213, 2022.
    [
    CrossRef] [Google Scholar] [Publisher Link]
  32. Rudri Kalaria et al., “Adaptive Context-Aware Access Control for IoT Environments Leveraging Fog Computing,” International Journal of Information Security, vol. 23, pp. 3089-3107, 2024.
    [
    CrossRef] [Google Scholar] [Publisher Link]
  33. Ronghua Xu et al., “BlendCAC: A Smart Contract Enabled Decentralized Capability-Based Access Control Mechanism for the IoT,” Computers, vol. 7, no. 3, pp. 1-27, 2018.
    [
    CrossRef] [Google Scholar] [Publisher Link]
  34. Hany F. Atlam et al., “Risk-Based Access Control Model: A Systematic Literature Review,” Future Internet, vol. 12, no. 6, pp. 1-23, 2020.
    [
    CrossRef] [Google Scholar] [Publisher Link]
  35. Bhaveshkumar Kathiriya et al., “Optimizing Fuzzy Decision Systems with the Jaya Algorithm for Enhanced Data Transfer in Multi-Hop CRNs,” Franklin Open, vol. 16, pp. 1-10, 2026.
    [
    CrossRef] [Google Scholar] [Publisher Link]
  36. Haewon Byeon et al., “An In-Depth Analysis of Security Flaws in Advanced Authentication Protocols for the Internet of Medical Things,” International Journal of Advanced Computer Science & Applications, vol. 16, no. 7, pp. 426-431, 2025.
    [
    CrossRef] [Google Scholar] [Publisher Link]
  37. Zeyad Ghaleb Al-Mekhlaf et al., “A Quantum-Resilient Lattice-Based Security Framework for Internet of Medical things in Healthcare Systems,” Journal of King Saud University Computer and Information Sciences, vol. 37, no. 6, pp. 1-19, 2025.
    [
    CrossRef] [Google Scholar] [Publisher Link]
  38. Jaime Pérez Díaz, and Florina Almenares Mendoza, “Authorization Models for IoT Environments: A Survey,” Internet of Things, vol. 29, pp. 1-28, 2025.
    [
    CrossRef] [Google Scholar] [Publisher Link]
  39. Abubakar Wakili, and Sara Bakkali, “Privacy-Preserving Security of IoT Networks: A Comparative Analysis of Methods and Applications,” Cyber Security and Applications, vol. 3, pp. 1-15, 2025.
    [
    CrossRef] [Google Scholar] [Publisher Link]
  40. G. Gandhimathi et al., “A Use of Fuzzy Logic Based Decision Making tree for Developing Smart Healthcare System,” 2024 4th International Conference on Advance Computing and Innovative Technologies in Engineering (ICACITE), Greater Noida, India, pp. 298-300, 2024.
    [
    CrossRef] [Google Scholar] [Publisher Link]