Attribute-Based Access Control in Cloud–Edge Industrial IoT Networks via Deep Reinforcement Learning
The fourth industrial revolution drives AI-powered smart manufacturing through cloud-edge computing, enabling intelligent production processes and data-driven automation. To handle security concerns arising from massive IoT deployments, attribute-based access control (ABAC) has become essential for smart factories. It offers flexibility in dynamic environments by utilizing attributes of users, devices, and contextual conditions to decide whether an access request should be permitted or denied. However, the proliferation of IoT devices drastically increases the number of attributes, causing exponential growth in policy complexity and severe decision latency at resource-constrained edge nodes. To address this issue, we propose ABAC-Prune, a cloud–edge collaborative framework for ABAC policy pruning. The framework adaptively determines pruning strategies based on the real-time security state of the factory. Specifically, it employs deep reinforcement learning (DRL) for coarse-grained control in highly dynamic environments, while switching to a Deterministic Policy Optimizer (DPO) for fine-grained adjustment under quasi-static conditions. The pruned lightweight ABAC policy subset is then deployed on edge nodes for real-time access decisions. By continuously monitoring factory conditions and analyzing historical access requests, ABAC-Prune dynamically adjusts pruning strategies. Simulation results on our containerized digital-twin testbed show that ABAC-Prune reduces security response latency by 22% and improves operational efficiency by 30%, while maintaining robust security with anomaly rates consistently below 10%.