| 2004 | Using trust and risk in role-based access control policies. | Nathan Dimmock, Andrs Belokosztolszki, David M. Eyers, Jean Bacon, Ken Moody |
| 2004 | Succinct specifications of portable document access policies. | Marina Bykova, Mikhail J. Atallah |
| 2004 | Towards a credential-based implementation of compound access control policies. | Joachim Biskup, Sandra Wortmann |
| 2004 | X-GTRBAC admin: a decentralized administration model for enterprise wide access control. | Rafae Bhatti, James Joshi, Elisa Bertino, Arif Ghafoor |
| 2004 | Security for grid-based computing systems issues and challenges. | Elisa Bertino, Bruno Crispo, James Joshi, Wengliang (Kevin) Du, Ravi S. Sandhu |
| 2004 | On the role of roles: from role-based to role-sensitive access control. | Xuhui Ao, Naftaly H. Minsky |
| 2003 | PBDM: a flexible delegation model in RBAC. | Xinwen Zhang, Sejong Oh, Ravi S. Sandhu |
| 2003 | Cooperative role-based administration. | Horst F. Wedde, Mario Lischka |
| 2003 | Dynamic and risk-aware network access management. | Lawrence Teo, Gail-Joon Ahn, Yuliang Zheng |
| 2003 | On modeling system-centric information for role engineering. | Dongwan Shin, Gail-Joon Ahn, Sangrae Cho, Seunghun Jin |
| 2003 | Role-based access control for collaborative enterprise in peer-to-peer computing environments. | Joon S. Park, Junseok Hwang |
| 2003 | A methodology for managing roles in legacy systems. | Sylvia L. Osborn, Yan Han, Jun Liu |
| 2003 | An approach to engineer and enforce context constraints in an RBAC environment. | Gustaf Neumann, Mark Strembeck |
| 2003 | Dynamic access control: preserving safety and trust for network defense operations. | Prasad Naldurg, Roy H. Campbell |
| 2003 | On context in authorization policy. | Patrick D. McDaniel |
| 2003 | The tees confidentiality model: an authorisation model for identities and roles. | Jim J. Longstaff, Mike A. Lockyer, John Nicholas |
| 2003 | Role mining - revealing business roles for security administration using data mining technology. | Martin Kuhlmann, Dalia Shohat, Gerhard Schimpf |
| 2003 | An administration concept for the enterprise role-based access control model. | Axel Kern, Andreas Schaad, Jonathan D. Moffett |
| 2003 | Dependencies and separation of duty constraints in GTRBAC. | James Joshi, Basit Shafiq, Arif Ghafoor, Elisa Bertino |
| 2003 | An access control model for dynamic client-side content. | Adam Hess, Kent E. Seamons |
| 2003 | Cryptographic access control in a distributed file system. | Anthony Harrington, Christian Damsgaard Jensen |
| 2003 | The role control center: features and case studies. | David F. Ferraiolo, Ramaswamy Chandramouli, Gail-Joon Ahn, Serban I. Gavrila |
| 2003 | Specifying and enforcing constraints in role-based access control. | Jason Crampton |
| 2003 | An infrastructure for managing secure update operations on XML data. | Elisa Bertino, Giovanni Mella, Gianluca Correndo, Elena Ferrari |
| 2003 | A stratification-based approach for handling conflicts in access control. | Salem Benferhat, Rania El Baida, Frdric Cuppens |