| 2007 | PolicyMorph: interactive policy transformations for a logical attribute-based access control framework. | Michael LeMay, Omid Fatemieh, Carl A. Gunter |
| 2007 | Lightweight cnsistency enforcement schemes for distributed proofs with hidden subtrees. | Adam J. Lee, Kazuhiro Minami, Marianne Winslett |
| 2007 | PEI models towards scalable, usable and high-assurance information sharing. | Ram Krishnan, Ravi S. Sandhu, Kumar Ranganathan |
| 2007 | Mesh: secure, lightweight grid middleware using existing SSH infrastructure. | Paul Z. Kolano |
| 2007 | Chinese-wall process confinement for practical distributed coalitions. | Yasuharu Katsuno, Yuji Watanabe, Sanehiro Furuichi, Michiharu Kudo |
| 2007 | A note on the formalisation of UCON. | Helge Janicke, Antonio Cau, Hussein Zedan |
| 2007 | Managing the risk of covert information flows in virtual machine systems. | Trent Jaeger, Reiner Sailer, Yogesh Sreenivasan |
| 2007 | A logical specification and analysis for SELinux MLS policy. | Boniface Hicks, Sandra Julieta Rueda, Luke St. Clair, Trent Jaeger, Patrick D. McDaniel |
| 2007 | Formalizing XML access control for update operations. | Irini Fundulaki, Sebastian Maneth |
| 2007 | Multilevel filesystems in solaris trusted extensions. | Glenn Faden |
| 2007 | A posteriori compliance control. | Sandro Etalle, William H. Winsborough |
| 2007 | Inter-domain role mapping and least privilege. | Liang Chen, Jason Crampton |
| 2007 | Distributed access control: a privacy-conscious approach. | Bogdan Cautis |
| 2007 | Enforcing access control over data streams. | Barbara Carminati, Elena Ferrari, Kian-Lee Tan |
| 2007 | Action-status access control. | Steve Barker |
| 2007 | Towards realizing a formal RBAC model in real systems. | Gail-Joon Ahn, Hongxin Hu |
| 2006 | A usage-based authorization framework for collaborative computing systems. | Xinwen Zhang, Masayuki Nakae, Michael J. Covington, Ravi S. Sandhu |
| 2006 | Inter-instance authorization constraints for secure workflow management. | Janice Warner, Vijayalakshmi Atluri |
| 2006 | Delegation in the role graph model. | He Wang, Sylvia L. Osborn |
| 2006 | Towards reasonability properties for access-control policy languages. | Michael Carl Tschantz, Shriram Krishnamurthi |
| 2006 | Access control, confidentiality and privacy for video surveillance databases. | Bhavani Thuraisingham, Gal Lavee, Elisa Bertino, Jianping Fan, Latifur Khan |
| 2006 | Data-centric security: role analysis and role typestates. | Vugranam C. Sreedhar |
| 2006 | Information flow property preserving transformation of UML interaction diagrams. | Fredrik Seehusen, Ketil Stlen |
| 2006 | A model-checking approach to analysing organisational controls in a loan origination process. | Andreas Schaad, Volkmar Lotz, Karsten Sohr |
| 2006 | Security in enterprise resource planning systems and service-oriented architectures. | Andreas Schaad |