| 2011 | Rumpole: a flexible break-glass access control model. | Srdjan Marinovic, Robert Craven, Jiefei Ma, Naranker Dulay |
| 2011 | Data-centric multi-layer usage control enforcement: a social network example. | Enrico Lovat, Alexander Pretschner |
| 2011 | Validation of security policies by the animation of Z specifications. | Yves Ledru, Nafees Qamar, Akram Idani, Jean-Luc Richier, Mohamed-Amine Labiadh |
| 2011 | An integrated approach for identity and access management in a SOA context. | Waldemar Hummer, Patrick Gaubatz, Mark Strembeck, Uwe Zdun, Schahram Dustdar |
| 2011 | Access control for a federated police information system. | Matthew Hudnall, Maury Mitchell, Allen S. Parrish |
| 2011 | Anomaly discovery and resolution in web access control policies. | Hongxin Hu, Gail-Joon Ahn, Ketan Kulkarni |
| 2011 | Relationship-based access control policies and their policy languages. | Philip W. L. Fong, Ida Sri Rejeki Siahaan |
| 2011 | An authorization scheme for version control systems. | Sitaram Chamarty, Hiren D. Patel, Mahesh V. Tripunitara |
| 2011 | Transforming provenance using redaction. | Tyrone Cadenhead, Vaibhav Khadilkar, Murat Kantarcioglu, Bhavani Thuraisingham |
| 2011 | Program synthesis in administration of higher-order permissions. | Glenn Bruns, Michael Huth, Kumar Avijit |
| 2011 | An approach to modular and testable security models of real-world health-care applications. | Achim D. Brucker, Lukas Brgger, Paul J. Kearney, Burkhart Wolff |
| 2011 | Deriving role engineering artifacts from business processes and scenario models. | Anne Baumgrass, Mark Strembeck, Stefanie Rinderle-Ma |
| 2011 | A decade of model-driven security. | David A. Basin, Manuel Clavel, Marina Egea |
| 2011 | Security validation tool for business processes. | Wihem Arsac, Luca Compagna, Samuel Paul Kaluvuri, Serena Elisa Ponta |
| 2011 | xDAuth: a scalable and lightweight framework for cross domain access control and delegation. | Masoom Alam, Xinwen Zhang, Kamran Khan, Gohar Ali |
| 2010 | Role-based access control (RBAC) in Java via proxy objects using annotations. | Jeff Zarnett, Mahesh V. Tripunitara, Patrick Lam |
| 2010 | Privacy-preserving trust verification. | Jaideep Vaidya, Vijayalakshmi Atluri, Basit Shafiq, Nabil R. Adam |
| 2010 | Access control in practice: pain points. | Mahesh V. Tripunitara, Praerit Garg, Bob Bocchino, Fred Frye, Divya Sundaram |
| 2010 | StateMiner: an efficient similarity-based approach for optimal mining of role hierarchy. | Hassan Takabi, James B. D. Joshi |
| 2010 | Modular context-aware access control for medical sensor networks. | Oscar Garca Morchon, Klaus Wehrle |
| 2010 | Mining roles with noisy data. | Ian M. Molloy, Ninghui Li, Yuan (Alan) Qi, Jorge Lobo, Luke Dickens |
| 2010 | Role mining based on weights. | Xiaopu Ma, Ruixuan Li, Zhengding Lu |
| 2010 | Data protection models for service provisioning in the cloud. | Dan Lin, Anna Cinzia Squicciarini |
| 2010 | Access control policy translation and verification within heterogeneous data federations. | Gregory Leighton, Denilson Barbosa |
| 2010 | Enforcing spatial constraints for mobile RBAC systems. | Michael S. Kirkpatrick, Elisa Bertino |