Home / Current Issue / Paper 1708524
Advances in Role-Based Access Control for Cloud-Enabled Operational Platforms
Subject area: Science,Engineering and Technology · Area of research: Cloud Security
Abstract
The rapid adoption of cloud computing across industries has transformed the way operational platforms are designed, deployed, and managed. As organizations increasingly rely on cloud-enabled environments to streamline operations, enhance scalability, and ensure business continuity, the need for robust and dynamic access control mechanisms has become paramount. Role-Based Access Control (RBAC) has long served as a foundational security model by assigning permissions to users based on predefined roles. However, traditional RBAC models face significant limitations in modern, cloud-native ecosystems characterized by multi-tenancy, dynamic resource provisioning, and distributed architectures. This paper presents a systematic review and critical analysis of recent advances in RBAC tailored to the demands of cloud-enabled operational platforms. We explore next-generation RBAC frameworks that integrate context-aware policies, attribute-based enhancements, and machine learning-driven access decisions to improve granularity and adaptability. Innovations such as dynamic role assignment, real-time auditing, and policy automation are discussed in the context of their contributions to reducing insider threats and ensuring regulatory compliance. Additionally, we highlight hybrid models combining RBAC with Attribute-Based Access Control (ABAC) to address fine-grained access needs in cloud-native microservices architectures. The study also examines cloud service providers' implementation of RBAC?particularly in platforms like AWS, Azure, and Google Cloud?revealing the importance of scalable identity management, permission boundaries, and centralized governance in operational efficiency and cybersecurity. Emerging trends such as Zero Trust Architecture (ZTA) and policy-as-code further illustrate the evolution of RBAC from static rule sets to dynamic, intelligent systems capable of adapting to evolving threat landscapes. By synthesizing academic literature, industry case studies, and platform-specific innovations, this paper offers a comprehensive framework for understanding and implementing advanced RBAC models in cloud-enabled operational environments. The insights contribute to a broader understanding of secure cloud operations and provide actionable recommendations for cybersecurity practitioners, cloud architects, and enterprise IT strategists aiming to fortify access control in complex digital infrastructures.
Keywords
Role-Based Access Control (RBAC), Cloud Security, Operational Platforms, Attribute-Based Access Control (ABAC), Zero Trust Architecture, Identity and Access Management (IAM), Policy Automation, Cloud Computing.
References
[1] Ahmed, A. and Zhang, N. (2009). Towards the realisation of context-risk-aware access control in pervasive computing. Telecommunication Systems, 45(2-3), 127-137. https://doi.org/10.1007/s11235-009-9240-3
[2] Alramadhan, M., & Sha, K. (2017, July). An overview of access control mechanisms for internet of things. In 2017 26th international conference on computer communication and networks (ICCCN) (pp. 1-6). IEEE.
[3] AL-Shboul, M. (2018). Towards better understanding of determinants logistical factors in smes for cloud erp adoption in developing economies. Business Process Management Journal, 25(5), 887-907. https://doi.org/10.1108/bpmj-01-2018-0004
[4] Al‐Zewairi, M., Alqatawna, J., & Atoum, J. (2015). Risk adaptive hybrid rfid access control system. Security and Communication Networks, 8(18), 3826-3835. https://doi.org/10.1002/sec.1303
[5] Bechini, A., Cimino, M., Marcelloni, F., & Tomasi, A. (2008). Patterns and technologies for enabling supply chain traceability through collaborative e-business. Information and Software Technology, 50(4), 342-359. https://doi.org/10.1016/j.infsof.2007.02.017
[6] Bethencourt, J., Sahai, A., & Waters, B. (2007). Ciphertext-policy attribute-based encryption., 321-334. https://doi.org/10.1109/sp.2007.11
[7] Bhatt, S., Patwa, F., & Sandhu, R. (2017). Abac with group attributes and attribute hierarchies utilizing the policy machine.. https://doi.org/10.1145/3041048.3041053
[8] Carrión, A., Caballer, M., Blanquer, I., Kotowski, N., Jardim, R., & Dávila, A. (2017). Managing workflows on top of a cloud computing orchestrator for using heterogeneous environments on e-science. International Journal of Web and Grid Services, 13(4), 375. https://doi.org/10.1504/ijwgs.2017.087326
[9] Cho, Y., Choi, J., & Yoe, H. (2012). A framework for smart workflow services in agricultural environments. Journal of the Chinese Institute of Engineers, 35(5), 515-522. https://doi.org/10.1080/02533839.2012.679053
[10] Choi, J., Kang, D., Jang, H., & Eom, Y. (2008). Adaptive access control scheme utilizing context awareness in pervasive computing environments., 491-498. https://doi.org/10.1109/pccc.2008.4745089
[11] Covington, M., Long, W., Srinivasan, S., Dev, A., Ahamad, M., & Abowd, G. (2001). Securing context-aware applications using environment roles.. https://doi.org/10.1145/373256.373258
[12] DUAN, Y. and Han, K. (2017). Research on access control security in cloud computing environment. Destech Transactions on Computer Science and Engineering, (cst). https://doi.org/10.12783/dtcse/cst2017/12596
[13] Dutta, A., Peng, G., & Choudhary, A. (2013). Risks in enterprise cloud computing: the perspective of it experts. Journal of Computer Information Systems, 53(4), 39-48. https://doi.org/10.1080/08874417.2013.11645649
[14] El Sibai, R., Gemayel, N., Bou Abdo, J., & Demerjian, J. (2020). A survey on access control mechanisms for cloud computing. Transactions on Emerging Telecommunications Technologies, 31(2), e3720.
[15] Emden, Z., Calantone, R., & Dröge, C. (2006). Collaborating for new product development: selecting the partner with maximum potential to create value. Journal of Product Innovation Management, 23(4), 330-341. https://doi.org/10.1111/j.1540-5885.2006.00205.x
[16] Emig, C., Brandt, F., Abeck, S., Biermann, J., & Klarl, H. (2007). An access control metamodel for web service-oriented architecture., 57-57. https://doi.org/10.1109/icsea.2007.15
[17] Ene, A., Horne, W., Milosavljević, N., Rao, P., Schreiber, R., & Tarjan, R. (2008). Fast exact and heuristic methods for role minimization problems.. https://doi.org/10.1145/1377836.1377838
[18] Faizi, S. and Rahman, S. (2019). Securing cloud computing through it governance. SSRN Electronic Journal. https://doi.org/10.2139/ssrn.3360869
[19] Ferreira, P., Shamsuzzoha, A., Toscano, C., & Cunha, P. (2012). Framework for performance measurement and management in a collaborative business environment. International Journal of Productivity and Performance Management, 61(6), 672-690. https://doi.org/10.1108/17410401211249210
[20] Frank, M., Streich, A., Basin, D., & Buhmann, J. (2009). A probabilistic approach to hybrid role mining.. https://doi.org/10.1145/1653662.1653675
[21] Frías-Martínez, V., Sherrick, J., Stolfo, S., & Keromytis, A. (2009). A network access control mechanism based on behavior profiles.. https://doi.org/10.1109/acsac.2009.10
[22] Gomez, L., Moraru, L., Simplot‐Ryl, D., & Wrona, K. (2005). Using sensor and location information for context-aware access control.. https://doi.org/10.1109/eurcon.2005.1629860
[23] Habib, S., Ries, S., & Mühlhäuser, M. (2010). Cloud computing landscape and research challenges regarding trust and reputation., 410-415. https://doi.org/10.1109/uic-atc.2010.48
[24] Harnal, S. and Chauhan, R. (2018). Efficient and flexible role-based access control (efrbac) mechanism for cloud. Icst Transactions on Scalable Information Systems, 0(0), 161438. https://doi.org/10.4108/eai.13-7-2018.161438
[25] Hendrikx, F. and Bubendorfer, K. (2013). Malleable access rights to establish and enable scientific collaboration.. https://doi.org/10.1109/escience.2013.26
[26] Hinkelmann, K., Gerber, A., Karagiannis, D., Thoenssen, B., Merwe, A., & Woitsch, R. (2016). A new paradigm for the continuous alignment of business and it: combining enterprise architecture modelling and enterprise ontology. Computers in Industry, 79, 77-86. https://doi.org/10.1016/j.compind.2015.07.009
[27] Hoegl, M. and Gemuenden, H. (2001). Teamwork quality and the success of innovative projects: a theoretical concept and empirical evidence. Organization Science, 12(4), 435-449. https://doi.org/10.1287/orsc.12.4.435.10635
[28] Huang, L., Liu, F., & Liu, C. (2013). Design and research on collaborative learning program based on cloud-services. Advanced Materials Research, 756-759, 1199-1203. https://doi.org/10.4028/www.scientific.net/amr.756-759.1199
[29] Idris, A. A., Asokere, A. S., Ajemunigbohun, S. S., Oreshile, A. S., & Olutade, E. O. (2012). An empirical study of the efficacy of marketing communication mix elements in selected insurance companies in Nigeria. Australian Journal of Business and Management Research, 2(5), 8.
[30] Indu, I., Anand, P. R., & Bhaskar, V. (2018). Identity and access management in cloud environment: Mechanisms and challenges. Engineering science and technology, an international journal, 21(4), 574-588.
[31] Jincui, C. and Jiang, L. (2011). Role-based access control model of cloud computing. Energy Procedia, 13, 1056-1061. https://doi.org/10.1016/j.egypro.2011.11.146
[32] Ke, C., Chang, S., & Lin, Z. (2013). An adaptive e-service for bridging the cloud services by an optimal selection approach. Journal of Software, 8(9). https://doi.org/10.4304/jsw.8.9.2122-2126
[33] Kuijper, W. and Ermolaev, V. (2014). Sorting out role based access control.. https://doi.org/10.1145/2613087.2613101
[34] Law, K., Cheng, J., Fruchter, R., & Sriram, R. (2016). Engineering applications of the cloud., 489-504. https://doi.org/10.1002/9781118821930.ch40
[35] Li, B., Tian, M., Zhang, Y., & Lv, S. (2013). Strategy of domain and cross-domain access control based on trust in cloud computing environment., 791-798. https://doi.org/10.1007/978-3-319-01766-2_91
[36] Li, C., Yang, C., Qin, L., & Yang, Y. (2009). Intergrating role-based access control model with web server.. https://doi.org/10.1109/icadiwt.2009.5273955
[37] Li, H., Wang, S., Tian, X., Wei, W., & Sun, C. (2015). A survey of extended role-based access control in cloud computing., 821-831. https://doi.org/10.1007/978-3-319-11104-9_95
[38] Li, N., Byun, J., & Bertino, E. (2007). A critique of the ansi standard on role-based access control. Ieee Security & Privacy, 5(6), 41-49. https://doi.org/10.1109/msp.2007.158
[39] Li, W., Wan, H., Ren, X., & Li, S. (2012). A refined rbac model for cloud computing.. https://doi.org/10.1109/icis.2012.13
[40] Li, X. and Jin, Z. (2015). Resource and role based access control model.. https://doi.org/10.2991/icmii-15.2015.94
[41] Luftman, J. (2003). Assessing it - business alignment.. https://doi.org/10.1201/9781420031393.ch1
[42] Luo, J., Ni, X., & Yong, J. (2009). A trust degree based access control in grid environments. Information Sciences, 179(15), 2618-2628. https://doi.org/10.1016/j.ins.2009.01.039
[43] Lupu, E. and Sloman, M. (1997). Reconciling role based management and role based access control., 135-141. https://doi.org/10.1145/266741.266770
[44] Madani, M., Erradi, M., & Benkaouz, Y. (2015). Access control in a collaborative session in multi tenant environment.. https://doi.org/10.1109/isias.2015.7492757
[45] Manikandasaran, S. S. (2016). Cloud computing with data confidentiality issues. International Journal of Advanced Research in Computer and Communication Engineering, 5(1), 97-100.
[46] Mateo, R., Yang, H., & Lee, J. (2012). Collaboration framework based on social semantic web for cloud systems. Journal of Internet Computing and Services, 13(1), 65-74. https://doi.org/10.7472/jksii.2012.13.1.65
[47] McGregor, C. and Schiefer, J. (2004). A web-service based framework for analyzing and measuring business performance. Information Systems and E-Business Management, 2(1). https://doi.org/10.1007/s10257-003-0027-x
[48] Melander, L. (2017). Achieving sustainable development by collaborating in green product innovation. Business Strategy and the Environment, 26(8), 1095-1109. https://doi.org/10.1002/bse.1970
[49] Milosevic, D. and Srivannaboon, S. (2006). A theoretical framework for aligning project management with business strategy. Project Management Journal, 37(3), 98-110. https://doi.org/10.1177/875697280603700310
[50] Min, L., Zhao, D., & Yu, Y. (2015). Toe drivers for cloud transformation: direct or trust-mediated?. Asia Pacific Journal of Marketing and Logistics, 27(2), 226-248. https://doi.org/10.1108/apjml-03-2014-0040
[51] Mohamed, M., Stankosky, M., & Murray, A. (2004). Applying knowledge management principles to enhance cross‐functional team performance. Journal of Knowledge Management, 8(3), 127-142. https://doi.org/10.1108/13673270410541097
[52] Molloy, I., Li, N., Li, T., Mao, Z., Wang, Q., & Lobo, J. (2009). Evaluating role mining algorithms., 95-104. https://doi.org/10.1145/1542207.1542224
[53] Momm, C., Gebhart, M., & Abeck, S. (2009). A model-driven approach for monitoring business performance in web service compositions., 343-350. https://doi.org/10.1109/iciw.2009.57
[54] Musca, C., Ion, A., Leordeanu, C., & Cristea, V. (2013). Secure access to cloud resources.. https://doi.org/10.1109/3pgcic.2013.95
[55] Mustapha, S. D., Adeoye, B. A. I., & AbdulWahab, R. (2017). Estimation of drivers’ critical gap acceptance and follow-up time at four-legged unsignalized intersection. CARD International Journal of Science and Advanced Innovative Research, 1(1), 98-107. CARD International Journal of Science and Advanced Innovative Research.
[56] Norta, A. and Grefen, P. (2007). Discovering patterns for inter-organizational business process collaboration. International Journal of Cooperative Information Systems, 16(03n04), 507-544. https://doi.org/10.1142/s0218843007001664
[57] Nussbaumer, N. and Liu, X. (2013). Cloud migration for smes in a service oriented approach., 457-462. https://doi.org/10.1109/compsacw.2013.71
[58] Oh, W., & Pinsonneault, A. (2007). On the Assessment of the Strategic Value of Information Technologies: Conceptual and Analytical Approaches. MIS Quarterly, 31(2), 239–265. https://doi.org/10.2307/25148790
[59] Olamijuwon, O. J. (2020). Real-time Vision-based Driver Alertness Monitoring using Deep Neural Network Architectures (Master's thesis, University of the Witwatersrand, Johannesburg (South Africa)).
[60] Olutade, E. O. (2020). Social media as a marketing strategy to influence young consumers' attitude towards fast-moving consumer goods: a comparative study (Doctoral dissertation, North-West University (South Africa)).
[61] Olutade, E. O., & Chukwuere, J. E. (2020). Greenwashing as Influencing Factor to Brand Switching Behavior Among Generation Y in the Social Media Age. In Green Marketing as a Positive Driver Toward Business Sustainability (pp. 219-248). IGI Global Scientific Publishing.
[62] Olutade, E. O., Potgieter, M., & Adeogun, A. W. (2019). Effect of social media platforms as marketing strategy of achieving organisational marketing goals and objectives aong innovative consumers: Acomparative study. International Journal of Business and Management Studies, 8(1), 213-228.
[63] Omicini, A., Ricci, A., & Viroli, M. (2005). Rbac for organisation and security in an agent coordination infrastructure. Electronic Notes in Theoretical Computer Science, 128(5), 65-85. https://doi.org/10.1016/j.entcs.2004.11.045
[64] Oprins, R., Frijns, H., & Stettina, C. (2019). Evolution of scrum transcending business domains and the future of agile project management., 244-259. https://doi.org/10.1007/978-3-030-19034-7_15
[65] Osborn, S., Sandhu, R., & Munawer, Q. (2000). Configuring role-based access control to enforce mandatory and discretionary access control policies. Acm Transactions on Information and System Security, 3(2), 85-106. https://doi.org/10.1145/354876.354878
[66] Oxley, J. and Pandher, G. (2015). Equity‐based incentives and collaboration in the modern multibusiness firm. Strategic Management Journal, 37(7), 1379-1394. https://doi.org/10.1002/smj.2392
[67] Paletta, M. and Herrero, P. (2010). An awareness-based learning model to deal with service collaboration in cloud computing., 85-100. https://doi.org/10.1007/978-3-642-15034-0_6
[68] Pan, H., Wu, C., & Lin, S. (2013). The preliminary discussion about key problems of cross-organizational business process collaboration. Applied Mechanics and Materials, 411-414, 2148-2151. https://doi.org/10.4028/www.scientific.net/amm.411-414.2148
[69] Panagiotou, G. and Wijnen, R. (2005). The “telescopic observations” framework: an attainable strategic tool. Marketing Intelligence & Planning, 23(2), 155-171. https://doi.org/10.1108/02634500510589912
[70] Park, J., An, G., & Chandra, D. (2007). Trusted p2p computing environments with role-based access control. Iet Information Security, 1(1), 27-35. https://doi.org/10.1049/iet-ifs:20060084
[71] Park, J., An, G., & Chandra, D. (2007). Trusted p2p computing environments with role-based access control. Iet Information Security, 1(1), 27-35. https://doi.org/10.1049/iet-ifs:20060084
[72] Pavlou, P. and Sawy, O. (2011). Understanding the elusive black box of dynamic capabilities. Decision Sciences, 42(1), 239-273. https://doi.org/10.1111/j.1540-5915.2010.00287.x
[73] Pearson, S. and Benameur, A. (2010). Privacy, security and trust issues arising from cloud computing., 693-702. https://doi.org/10.1109/cloudcom.2010.66
[74] Pellathy, D., Mollenkopf, D., Stank, T., & Autry, C. (2019). Cross‐functional integration: concept clarification and scale development. Journal of Business Logistics, 40(2), 81-104. https://doi.org/10.1111/jbl.12206
[75] Pérez, A., Moltó, G., Caballer, M., & Calatrava, A. (2018). Serverless computing for container-based architectures. Future Generation Computer Systems, 83, 50-59. https://doi.org/10.1016/j.future.2018.01.022
[76] Petrillo, A., Bona, G., Forcina, A., & Silvestri, A. (2018). Building excellence through the agile reengineering performance model (arpm). Business Process Management Journal, 24(1), 128-157. https://doi.org/10.1108/bpmj-03-2016-0071
[77] Poberschnigg, T., Pimenta, M., & Hilletofth, P. (2020). How can cross-functional integration support the development of resilience capabilities? the case of collaboration in the automotive industry. Supply Chain Management an International Journal, 25(6), 789-801. https://doi.org/10.1108/scm-10-2019-0390
[78] Pope-Ruark, R. (2014). Introducing agile project management strategies in technical and professional communication courses. Journal of Business and Technical Communication, 29(1), 112-133. https://doi.org/10.1177/1050651914548456
[79] Prange, C. and Hennig, A. (2019). From strategic planning to strategic agility patterns. Journal of Creating Value, 5(2), 111-123. https://doi.org/10.1177/2394964319867778
[80] Rajpoot, Q., Jensen, C., & Krishnan, R. (2015). Attributes enhanced role-based access control model., 3-17. https://doi.org/10.1007/978-3-319-22906-5_1
[81] Rajpoot, Q., Jensen, C., & Krishnan, R. (2015). Attributes enhanced role-based access control model., 3-17. https://doi.org/10.1007/978-3-319-22906-5_1
[82] Rajpoot, Q., Jensen, C., & Krishnan, R. (2015). Integrating attributes into role-based access control., 242-249. https://doi.org/10.1007/978-3-319-20810-7_17
[83] Rajpoot, Q., Jensen, C., & Krishnan, R. (2015). Integrating attributes into role-based access control., 242-249. https://doi.org/10.1007/978-3-319-20810-7_17
[84] Redmond, J. and Walker, E. (2008). A new approach to small business training: community based education. Education + Training, 50(8/9), 697-712. https://doi.org/10.1108/00400910810917073
[85] Ruotsala, R. (2014). Developing a tool for cross-functional collaboration: the trajectory of an annual clock. Outlines Critical Practice Studies, 15(2), 31-53. https://doi.org/10.7146/ocps.v15i2.16830
[86] S., M. (2016). Cloud computing with data confidentiality issues. Ijarcce, 5(1), 97-100. https://doi.org/10.17148/ijarcce.2016.5123
[87] Sabherwal, R. and Chan, Y. (2001). Alignment between business and is strategies: a study of prospectors, analyzers, and defenders. Information Systems Research, 12(1), 11-33. https://doi.org/10.1287/isre.12.1.11.9714
[88] Sabherwal, R., Hirschheim, R., & Goles, T. (2001). The dynamics of alignment: insights from a punctuated equilibrium model. Organization Science, 12(2), 179-197. https://doi.org/10.1287/orsc.12.2.179.10113
[89] Saini, H., Upadhyaya, A., & Khandelwal, M. (2019). Benefits of cloud computing for business enterprises: a review. SSRN Electronic Journal. https://doi.org/10.2139/ssrn.3463631
[90] Salah, A., Ramadan, N., & Ahmed, H. (2017). Towards a hybrid approach for software project management using ontology alignment. International Journal of Computer Applications, 168(6), 12-19. https://doi.org/10.5120/ijca2017914438
[91] Sanders, N. (2007). An empirical study of the impact of e‐business technologies on organizational collaboration and performance. Journal of Operations Management, 25(6), 1332-1347. https://doi.org/10.1016/j.jom.2007.01.008
[92] Sandhu, R., Bhamidipati, V., Coyne, E., Ganta, S., & Youman, C. (1997). The arbac97 model for role-based administration of roles., 41-50. https://doi.org/10.1145/266741.266752
[93] Sandhu, R., Bhamidipati, V., Coyne, E., Ganta, S., & Youman, C. (1997). The arbac97 model for role-based administration of roles., 41-50. https://doi.org/10.1145/266741.266752
[94] Sandhu, R., Coyne, E., Feinstein, H., & Youman, C. (1996). Role-based access control models. Computer, 29(2), 38-47. https://doi.org/10.1109/2.485845
[95] Sandhu, R., Coyne, E., Feinstein, H., & Youman, C. (1996). Role-based access control models. Computer, 29(2), 38-47. https://doi.org/10.1109/2.485845
[96] Sandhu, R., Ferraiolo, D., & Kühn, R. (2000). The nist model for role-based access control.. https://doi.org/10.1145/344287.344301
[97] Sandhu, R., Ferraiolo, D., & Kühn, R. (2000). The nist model for role-based access control.. https://doi.org/10.1145/344287.344301
[98] Sarin, S. and McDermott, C. (2003). The effect of team leader characteristics on learning, knowledge application, and performance of cross‐functional new product development teams. Decision Sciences, 34(4), 707-739. https://doi.org/10.1111/j.1540-5414.2003.02350.x
[99] Schiffman, J., Sun, Y., Vijayakumar, H., & Jaeger, T. (2013). Cloud verifier: verifiable auditing service for iaas clouds.. https://doi.org/10.1109/services.2013.37
[100] Senarathna, I., Wilkin, C., Warren, M., Yeoh, W., & Salzman, S. (2018). Factors that influence adoption of cloud computing: an empirical study of australian smes. Australasian Journal of Information Systems, 22. https://doi.org/10.3127/ajis.v22i0.1603
[101] Shepperd, M. and Schofield, C. (1997). Estimating software project effort using analogies. Ieee Transactions on Software Engineering, 23(11), 736-743. https://doi.org/10.1109/32.637387
[102] Skafi, M., Yunis, M., & Zekri, A. (2020). Factors influencing smes’ adoption of cloud computing services in lebanon: an empirical analysis using toe and contextual theory. Ieee Access, 8, 79169-79181. https://doi.org/10.1109/access.2020.2987331
[103] Sow, M. and Aborbie, S. (2018). Impact of leadership on digital transformation. Business and Economic Research, 8(3), 139. https://doi.org/10.5296/ber.v8i3.13368
[104] Subashini, S. and Kavitha, V. (2011). A survey on security issues in service delivery models of cloud computing. Journal of Network and Computer Applications, 34(1), 1-11. https://doi.org/10.1016/j.jnca.2010.07.006
[105] Swink, M. and Schoenherr, T. (2014). The effects of cross‐functional integration on profitability, process efficiency, and asset productivity. Journal of Business Logistics, 36(1), 69-87. https://doi.org/10.1111/jbl.12070
[106] Tereso, A., Ribeiro, P., Fernandes, G., Loureiro, I., & Ferreira, M. (2018). Project management practices in private organizations. Project Management Journal, 50(1), 6-22. https://doi.org/10.1177/8756972818810966
[107] Trent, R. and Monczka, R. (1994). Effective cross‐functional sourcing teams: critical success factors. International Journal of Purchasing and Materials Management, 30(3), 2-11. https://doi.org/10.1111/j.1745-493x.1994.tb00267.x
[108] Vrieze, P. and Xu, L. (2015). An analysis of resilience of a cloud based incident notification process., 110-121. https://doi.org/10.1007/978-3-319-24141-8_10
[109] Wainer, J. and Kumar, A. (2005). A fine-grained, controllable, user-to-user delegation method in rbac., 59-66. https://doi.org/10.1145/1063979.1063991
[110] Wang, X., Sun, J., Yang, X., Huang, C., & Wu, D. (2008). Security violation detection for rbac based interoperation in distributed environment. Ieice Transactions on Information and Systems, E91-D(5), 1447-1456. https://doi.org/10.1093/ietisy/e91-d.5.1447
[111] Wells, H. (2012). How effective are project management methodologies? an explorative evaluation of their benefits in practice. Project Management Journal, 43(6), 43-58. https://doi.org/10.1002/pmj.21302
[112] Wilson, B., Khazaei, B., & Hirsch, L. (2016). Towards a cloud migration decision support system for small and medium enterprises in tamil nadu.. https://doi.org/10.1109/cinti.2016.7846430
[113] Wu, D., Thames, J., Rosen, D., & Schaefer, D. (2012). Towards a cloud-based design and manufacturing paradigm: looking backward, looking forward., 315-328. https://doi.org/10.1115/detc2012-70780
[114] Xu, Y., Gao, W., Zeng, Q., Wang, G., Ren, J., & Zhang, Y. (2018). A feasible fuzzy-extended attribute-based access control technique. Security and Communication Networks, 2018, 1-11. https://doi.org/10.1155/2018/6476315
[115] Yigitbasioglu, O. (2015). The role of institutional pressures and top management support in the intention to adopt cloud computing solutions. Journal of Enterprise Information Management, 28(4), 579-594. https://doi.org/10.1108/jeim-09-2014-0087
[116] Yu, S., Wang, C., Ren, K., & Lou, W. (2010). Achieving secure, scalable, and fine-grained data access control in cloud computing.. https://doi.org/10.1109/infcom.2010.5462174
[117] Zdravković, J. & Johanesson, P. (2004). Cooperation of processes through message level agreement., 564-579. https://doi.org/10.1007/978-3-540-25975-6_40
[118] Zhou, L., Varadharajan, V., & Hitchens, M. (2015). Trust enhanced cryptographic role-based access control for secure cloud data storage. Ieee Transactions on Information Forensics and Security, 10(11), 2381-2395. https://doi.org/10.1109/tifs.2015.2455952
How to cite this paper
@article{1708524,
author = {Ejielo Ogbuefi, Samuel Owoade, Bright Chibunna Ubanadu, Andrew Ifesinachi Daraojimba, Oyinomomo-emi Emmanuel Akpe},
title = {Advances in Role-Based Access Control for Cloud-Enabled Operational Platforms},
journal = {Iconic Research And Engineering Journals},
year = {2020},
volume = {4},
number = {2},
pages = {159-176},
issn = {2456-8880},
url = {https://www.irejournals.com/formatedpaper/1708524.pdf},
abstract = {The rapid adoption of cloud computing across industries has transformed the way operational platforms are designed, deployed, and managed. As organizations increasingly rely on cloud-enabled environments to streamline operations, enhance scalability, and ensure business continuity, the need for robust and dynamic access control mechanisms has become paramount. Role-Based Access Control (RBAC) has long served as a foundational security model by assigning permissions to users based on predefined roles. However, traditional RBAC models face significant limitations in modern, cloud-native ecosystems characterized by multi-tenancy, dynamic resource provisioning, and distributed architectures. This paper presents a systematic review and critical analysis of recent advances in RBAC tailored to the demands of cloud-enabled operational platforms. We explore next-generation RBAC frameworks that integrate context-aware policies, attribute-based enhancements, and machine learning-driven access decisions to improve granularity and adaptability. Innovations such as dynamic role assignment, real-time auditing, and policy automation are discussed in the context of their contributions to reducing insider threats and ensuring regulatory compliance. Additionally, we highlight hybrid models combining RBAC with Attribute-Based Access Control (ABAC) to address fine-grained access needs in cloud-native microservices architectures. The study also examines cloud service providers' implementation of RBAC?particularly in platforms like AWS, Azure, and Google Cloud?revealing the importance of scalable identity management, permission boundaries, and centralized governance in operational efficiency and cybersecurity. Emerging trends such as Zero Trust Architecture (ZTA) and policy-as-code further illustrate the evolution of RBAC from static rule sets to dynamic, intelligent systems capable of adapting to evolving threat landscapes. By synthesizing academic literature, industry case studies, and platform-specific innovations, this paper offers a comprehensive framework for understanding and implementing advanced RBAC models in cloud-enabled operational environments. The insights contribute to a broader understanding of secure cloud operations and provide actionable recommendations for cybersecurity practitioners, cloud architects, and enterprise IT strategists aiming to fortify access control in complex digital infrastructures.},
keywords = {Role-Based Access Control (RBAC), Cloud Security, Operational Platforms, Attribute-Based Access Control (ABAC), Zero Trust Architecture, Identity and Access Management (IAM), Policy Automation, Cloud Computing.},
month = {August},
}