
Extending ABAC Authorisation for Complex Applications: Negative Permissions, Hierarchical Attribute Values, Break Glass Override
DOI:
https://doi.org/10.30564/jeis.v8i2.13211Abstract
Much of the commercial and research writings on healthcare Real-Time Location Systems (RTLS) have concentrated on the considerable benefits of this technology for locating assets, patients and staff, with many applications developed, particularly for asset tracking. Less has been written about who is authorised to query and analyse healthcare RTLS data, including historical location data. We categorise use cases for the interactions which have been proposed and indicate further desirable authorisations which could be provided by extending Attribute Based Access Control (ABAC). The ABAC extensions we propose are: to authorise access to information protected at increasing levels of security by invoking break-glass overrides; to enable the denial of access through the use of separately-specified negative permissions, possibly at different levels of security; and supporting hierarchically-structured attribute values for users (e.g., teams and roles), operations and protected objects. We describe algorithms for rule selection and processing, largely at the conceptual level. They take account of architect-specified attribute weightings, the order of rule evaluation, and query modification if the database forms the basis for implementation. We show that our sorting strategy can reduce rule search space by over 90% compared to a naïve policy evaluation, while enabling fine-grained emergency access that current ABAC frameworks lack. We illustrate with an example of technician teams locating and maintaining sophisticated medical equipment in a large healthcare setting. Privacy, confidentiality and security become especially sensitive if technicians need to inspect medical data produced by the equipment, maybe in emergency situations. When fully implemented, our approach does not require additional application programming to provide the extended authorisation functionality described.
Keywords:
Real Time Location System; Attribute Based Access Control; Patient Privacy; Healthcare Information SystemsReferences
[1] Kashani, M.H., Madanipour, M., Nikravan, M., et al., 2021. A systematic review of IoT in healthcare: Applications, techniques, and trends. Journal of Network and Computer Applications. 192, 103164.
[2] Opinion Editor, 2022. Why hospitals can no longer afford to ignore IoT. Available from: https://www.htworld.co.uk/news/why-hospitals-can-no-longer-afford-to-ignore-iot/ (cited 6 February 2026).
[3] CenTrak, 2024. The Power of IoT Location Technology in Hospitals. Available from: https://www.iotforall.com/the-power-of-iot-location-technology-in-hospitals (cited 6 February 2026).
[4] Natgunanathan, I., Mehmood, A., Xiang, Y., et al., 2018. Location Privacy Protection in Smart Health Care System. IEEE Internet of Things Journal. 6(2), 3055–3069.
[5] Yang, X., Gao, L., Zheng, J., et al., 2020. Location Privacy Preservation Mechanism for Location-Based Service with Incomplete Location Data. IEEE Access. 8, 95843–95854.
[6] Abu Rrub, J., Al-Jabi, J., El-Khatib, K., 2012. Security model for real time tracking system (RTLS) in the healthcare sector. In Proceedings of the 2012 International Conference on Communications and Information Technology (ICCIT), Hammamet, Tunisia, 26–28 June 2012; pp. 369–373. DOI: https://doi.org/10.1109/ICCITechnol.2012.6285828
[7] Pulkkis, G., Karlsson, J., Westerlund, M., et al., 2017. Secure and Reliable Internet of Things Systems for Healthcare. In Proceedings of the 2017 IEEE 5th International Conference on Future Internet of Things and Cloud (FiCloud), Prague, Czech, 21–23 August 2017; pp. 169–176.
[8] Kumar, A., Jain, A.K., Dua, M., 2021. A comprehensive taxonomy of security and privacy issues in RFID. Complex & Intelligent Systems. 7(3), 1327–1347. DOI: https://doi.org/10.1007/s40747-021-00280-6
[9] Osman, M.S., Azizan, A., Hassan, K.N., et al., 2021. BLE-based Real-time Location System Integration with Hospital Information System to Reduce Patient Waiting Time. In Proceedings of the 2021 International Conference on Electrical, Communication, and Computer Engineering (ICECCE), Kuala Lumpur, Malaysia, 12–13 June 2021; pp. 1–6. DOI: https://doi.org/10.1109/ICECCE52056.2021.9514248
[10] Longstaff, J., 2019. On Citizens Controlling Access to Their Health and Social Care Data for Direct Care. Teesside University: Middlesbrough, UK. Available from: https://research.tees.ac.uk/en/publications/on-citizens-controlling-access-to-their-health-and-social-care-da
[11] Blackstock, G., 2023. Families raise fears over vulnerable patients leaving wards. Available from: https://www.bbc.co.uk/news/uk-scotland-65855353 (cited 6 February 2026).
[12] Holt, A., 2022. Police investigate alleged killing of grandmother at care home. Available from: https://www.bbc.co.uk/news/uk-63471059 (cited 6 February 2026).
[13] BBC, 2022. Hundreds of patients dying due to A&E delays, doctors say. Available from: https://www.bbc.co.uk/news/uk-scotland-60865799 (cited 6 February 2026).
[14] McCracken, N., 2023. Northern Ireland medical negligence costs double in a year. Available from: https://www.bbc.co.uk/news/uk-northern-ireland-65352193 (cited 6 February 2026).
[15] Hu, V.C., Ferraiolo, D.F., Chandramouli, R., et al., 2017. Attribute-Based Access Control. Artech House Publishers: Norwood, MA, USA.
[16] Rissanen, E. (Ed.), 2017. [XACML-V3.0-Errata01] eXtensible Access Control Markup Language (XACML) Version 3.0 Plus Errata 01. OASIS eXtensible Access Control Markup Language (XACML) TC: Burlington, MA, USA.
[17] Axiomatics, 2023. Solution Brief: Orchestrated Authorisation. Axiomatics: Stockholm, Sweden. Available from: https://axiomatics.com/wp-content/uploads/2023/02/orchestrated-authorization-solution-brief-axiomatics-2-15-2023.pdf
[18] Talegaon, S., Batra, G., Atluri, V., et al., 2022. Contemporaneous Update and Enforcement of ABAC Policies. In Proceedings of the ACM Symposium on Access Control Models and Technologies (SACMAT'22), New York, NY, USA, 8–10 June 2022; pp. 31–42. DOI: https://doi.org/10.1145/3532105.3535021
[19] Vrielynck, P.-J., Van hamme, T., Ghostin, R., et al., 2024. A Self-Sovereign Identity Approach to Decentralized Access Control with Transitive Delegations. In Proceedings of the 29th ACM Symposium on Access Control Models and Technologies (SACMAT'24), San Antonio, TX, USA, 15–17 May 2024; pp. 139–147. DOI: https://doi.org/10.1145/3649158.3657045
[20] Ruiz, J.A., Narendran, P., Masoumzadeh, A., et al., 2024. Converting Rule-Based Access Control Policies: From Complemented Conditions to Deny Rules. In Proceedings of the 29th ACM Symposium on Access Control Models and Technologies (SACMAT'24), San Antonio, TX, USA, 15–17 May 2024; pp. 159–169. DOI: https://doi.org/10.1145/3649158.3657040
[21] Longstaff, J., Noble, J., 2016. Attribute Based Access Control for Big Data applications by Query Modification. In Proceedings of the IEEE Second International Conference on Big Data Computing Service and Applications, Oxford, UK, 29 March–1 April 2016; pp. 58–65. DOI: https://doi.org/10.1109/BigDataService.2016.35
[22] Longstaff, J., Howitt, A., 2014. Tees Confidentiality Model (TCM2): Supporting dynamic authorisation and overrides in Attribute Based Access Control. In: Issac, B., Israr, N. (Eds.). Case Studies in Secure Computing: Achievements and Trends. Auerbach Publications: New York, NY, USA.
[23] Nath, R., Das, S., Sural, S., et al., 2019. PolTree: A Data Structure for Making Efficient Access Decisions in ABAC. In Proceedings of the ACM Symposium on Access Control Models and Technologies (SACMAT); Toronto, ON, Canada, 3–6 June 2019; pp. 25–35. DOI: https://doi.org/10.1145/3322431.3325102
[24] Liu, M., Yang, C., Li, H., et al., 2020. An Efficient Attribute-Based Access Control (ABAC) Policy Retrieval Method Based on Attribute and Value Levels in Multimedia Networks. Sensors. 20(6), 1741. DOI: https://doi.org/10.3390/s20061741
[25] Servos, D., Osborn, S., 2017. Current Research and Open Problems in Attribute-Based Access Control. ACM Computing Surveys. 49(4), 65. DOI: https://doi.org/10.1145/3007204
[26] Xu, Z., Stoller, S.D., 2015. Mining Attribute-Based Access Control Policies. IEEE Transactions on Dependable and Secure Computing. 12(5), 533–545.
[27] Mulrine, S., Murtagh, M., Minion, J., 2018. Great North Care Record Public Engagement Report. Teesside University: Middlesbrough, UK. Available from: https://www.greatnorthcarerecord.org.uk/wp-content/uploads/2018/09/GNCR-public-engagement-report-FINAL.pdf
[28] NIST Information Technology Laboratory Computer Security Resource Center, n.d. Access Control. Available from: https://csrc.nist.gov/glossary/term/access_control (cited 6 February 2026).
[29] ANSI INCITS 359-2012 (R2022). 2012. Information Technology—Role Based Access Control.
[30] Gupta, M., Patwa, F., Sandhu, R., 2018. An Attribute-Based Access Control Model for Secure Big Data Processing in Hadoop Ecosystem. In Proceedings of the Third ACM Workshop on Attribute-Based Access Control Ecosystem (ABAC'18), Tempe, AZ, USA, 21 March 2018; pp. 13–24. DOI: https://doi.org/10.1145/3180457.3180463
[31] NIST SP 800-178. 2016. A Comparison of Attribute Based Access Control (ABAC) Standards for Data Service Applications: Extensible Access Control Markup Language (XACML) and Next Generation Access Control (NGAC).
[32] NIST SP 800-162. 2019. Guide to Attribute Based Access Control (ABAC) Definition and Considerations.
[33] Gupta, E., Sural, S., Vaidya, J., et al., 2022. Enabling Attribute-Based Access Control in NoSQL Databases. IEEE Transactions on Emerging Topics in Computing. 11(1), 208–223. DOI: https://doi.org/10.1109/TETC.2022.3193577
[34] Brossard, D., Gebel, G., Berg, M., 2017. A Systematic Approach to Implementing ABAC. In Proceedings of the CODASPY'17: Seventh ACM Conference on Data and Application Security and Privacy, Scottsdale, AZ, USA, 24 March 2017; pp. 53–59. DOI: https://doi.org/10.1145/3041048.3041051
[35] Huang, J., Nicol, D.M., Bobba, R., et al., 2012. A Framework Integrating Attribute-based Policies into Role-Based Access Control. In Proceedings of the ACM Symposium on Access Control Models and Technologies (SACMAT'12), Newark, NJ, USA, 20–22 June 2012; pp. 187–196.
[36] Qiao, Z., Liang, S., Davis, S., et al., 2014. Survey of attribute based encryption. In Proceedings of the 15th IEEE/ACIS International Conference on Software Engineering, Artificial Intelligence, Networking and Parallel/Distributed Computing (SNPD), Las Vegas, NV, USA, 30 June–2 July 2014; pp. 1–6. DOI: https://doi.org/10.1109/SNPD.2014.6888687
[37] ASCLEPIOS Consortium, 2019. D3.1—ASCLEPIOS Security and Policies Model. ICCS: Athina, Greece. Available from: https://zenodo.org/records/4022334
[38] Ullah, S., Oleshchuk, V., Gardiyawasam Pussewalage, H.S., 2023. A survey on blockchain envisioned attribute based access control for internet of things: Overview, comparative analysis, and open research challenges. Computer Networks. 235, 109994. DOI: https://doi.org/10.1016/j.comnet.2023.109994
[39] Wu, N., Xu, L., Zhu, L., 2023. A blockchain based access control scheme with hidden policy and attribute. Future Generation Computer Systems. 141, 186–196.
[40] Bui, T., Stoller, S., Le, H., 2019. Efficient and Extensible Policy Mining for Relationship-Based Access Control. In Proceedings of the SACMAT'19: The 24th ACM Symposium on Access Control Models and Technologies, Toronto, ON, Canada, 3–6 June 2019; pp. 161–172. DOI: https://doi.org/10.1145/3322431.3325106
[41] Pang, R., Cáceres, R., Burrows, M., et al., 2019. Zanzibar: Google’s Consistent, Global Authorization System. In Proceedings of the 2019 USENIX Annual Technical Conference, Renton, WA, USA, 10–12 July 2019.
[42] Xiao, M., Li, H., Huang, Q., et al., 2022. Attribute-Based Hierarchical Access Control With Extendable Policy. IEEE Transactions on Information Forensics and Security. 17, 1868–1883.
[43] Servos, D., Osborn, S.L., 2015. HGABAC: Towards a Formal Model of Hierarchical Attribute-Based Access Control. In: Cuppens, F., Garcia-Alfaro, J., Zincir Heywood, N., et al. (Eds.). Foundations and Practice of Security (FPS 2014), Lecture Notes in Computer Science, Vol. 8930. Springer: Cham, Switzerland. pp. 187–204.
[44] Axiomatics, n.d. Confidently scale authorization policies across your organization with externalized architecture. Available from: https://axiomatics.com/solutions/scale-authorization-externalized-architecture (cited 6 February 2026).
[45] Xu, M., Stoller, S.D., 2013. Mining Attribute-Based Access Control (ABAC) Policies from RBAC policies. In Proceedings of the 2013 10th International Conference and Expo on Emerging Technologies for a Smarter World (CEWIT), Melville, NY, USA, 21–22 October 2013; pp. 1–6. DOI: https://doi.org/10.1109/CEWIT.2013.6713753
[46] Lawal, S., Zhao, X., Rios, A., et al., 2024. Translating Natural Language Specifications into Access Control Policies by Leveraging Large Language Models. In Proceedings of the 2024 IEEE 6th International Conference on Trust, Privacy and Security in Intelligent Systems, and Applications (TPS-ISA), Washington, DC, USA, 28–31 October 2024; pp. 361–370. DOI: https://doi.org/10.1109/TPS-ISA62245.2024.00048
[47] Tripathi, A., Rajan, K., Kumar, V., et al., 2024. Real Time Adaptive Access Control with Behavioral Analytics for Enhanced Cybersecurity in IoT and Cloud Systems. In: Solanki, V.K., Tan, T.D., Kumar, P., et al. (Eds.). Proceedings of the Ninth International Conference on Research in Intelligent Computing in Engineering. Polish Information Processing Society (PTI): Warszawa, Poland. pp. 151–155.
[48] Amour, S., Gudes, E., 2025. Predictive Enhancement of ABACPolicies Using Access Log Analytics. In Proceedings of the 30th ACM Symposium on Access Control Models and Technologies (SACMAT’25), Stony Brook, NY, USA, 8–10 July 2025; pp. 16–21. DOI: https://doi.org/10.1145/3734436.3734455
Downloads
How to Cite
Issue
Article Type
License
Copyright © 2026 Jo Noble, Jim Longstaff

This is an open access article under the Creative Commons Attribution-NonCommercial 4.0 International (CC BY-NC 4.0) License.




Jo Noble