Development and Evaluation of an Authentication-Based Access Control Framework for Secure Web-Based Ebook Distribution
Abstract
The increasing use of digital learning resources has created a growing demand for secure ebook distribution systems. However, many existing ebook platforms remain vulnerable to unauthorized access, credential sharing, and uncontrolled digital content distribution. This study proposes an Authentication-Based Access Control Framework for secure web-based ebook distribution by integrating authentication, role-based authorization, session management, transaction validation, and ebook access protection within a unified security architecture.
The research employed the Waterfall software development model consisting of requirement analysis, system design, implementation, testing, and deployment. The proposed framework was implemented using PHP and MySQL and evaluated through functional and security testing.
The implementation results demonstrate that the developed system successfully manages 153 registered users, 151 ebook transactions, and six published ebook collections while maintaining controlled access to digital content. Functional testing achieved a 100% success rate across authentication, authorization, session validation, and ebook protection scenarios. The session management mechanism effectively prevented concurrent account usage and unauthorized access attempts.
The novelty of this study lies in the integration of authentication, authorization, session validation, and ebook access protection within a dedicated framework specifically designed for ebook distribution. The proposed framework provides a practical, scalable, and cost-effective alternative for educational institutions and digital content providers seeking secure digital resource distribution without relying on complex Digital Rights Management (DRM) infrastructures.
Downloads
References
OECD, OECD Digital Education Outlook 2023: Towards an Effective Digital Education Ecosystem. Paris, France: OECD Publishing, 2023, doi: 10.1787/c827b81a-en.
R. Pitt, “Open Textbooks in Higher Education Teaching,” in Distributed Learning Ecosystems: Concepts, Resources, and Repositories, Wiesbaden, Germany: Springer VS, 2023, pp. 97–113, doi: 10.1007/978-3-658-38703-7_6.
World Intellectual Property Organization, Completion Report of the Project on Copyright and the Distribution of Content in the Digital Environment, CDIP/31/6, Geneva, Switzerland, 2023. [Online]. Available: https://www.wipo.int/meetings/en/doc_details.jsp?doc_id=620344. [Accessed: Jun. 10, 2026].
World Intellectual Property Organization, “Copyright in the Digital Environment,” WIPO, 2026. [Online]. Available: https://www.wipo.int/en/web/copyright/activities/digital. [Accessed: Jun. 10, 2026].
W. M. Volckmann II, “A model of digital rights management with user disutility,” Journal of Industrial and Management Optimization, vol. 20, no. 1, pp. 282–310, 2024, doi: 10.3934/jimo.2023069.
R. S. Sandhu, E. J. Coyne, H. L. Feinstein, and C. E. Youman, “Role-based access control models,” Computer, vol. 29, no. 2, pp. 38–47, 1996, doi: 10.1109/2.485845.
V. C. Hu, D. Ferraiolo, R. Kuhn, A. Schnitzer, K. Sandlin, R. Miller, and K. Scarfone, Guide to Attribute Based Access Control (ABAC) Definition and Considerations, NIST Special Publication 800-162, 2014, doi: 10.6028/NIST.SP.800-162.
Joint Task Force, Security and Privacy Controls for Information Systems and Organizations, NIST Special Publication 800-53 Rev. 5, 2020, doi: 10.6028/NIST.SP.800-53r5.
I. Gamayanto, D. Kurniawan, and R. Prasetyo, “Security evaluation of Keycloak-based role-based access control in microservice architectures using the OWASP ASVS framework,” Journal of Applied Informatics and Computing, vol. 9, no. 6, 2025. [Online]. Available: https://jurnal.polibatam.ac.id/index.php/JAIC/article/view/11604.
Y. Yuricha and I. K. Phan, “Penerapan role based access control dalam sistem supply chain management berbasis cloud,” MALCOM: Indonesian Journal of Machine Learning and Computer Science, vol. 3, no. 2, pp. 339–348, 2023, doi: 10.57152/malcom.v3i2.1259.
OWASP Foundation, “Authentication Cheat Sheet,” OWASP Cheat Sheet Series, 2025. [Online]. Available: https://cheatsheetseries.owasp.org/cheatsheets/Authentication_Cheat_Sheet.html. [Accessed: Jun. 10, 2026].
OWASP Foundation, “Session Management Cheat Sheet,” OWASP Cheat Sheet Series, 2025. [Online]. Available: https://cheatsheetseries.owasp.org/cheatsheets/Session_Management_Cheat_Sheet.html. [Accessed: Jun. 10, 2026].
R. Galluzzo, A. Regenscheid, D. Temoshok, and C. LaSalle, Incorporating Syncable Authenticators Into NIST SP 800-63B, NIST Special Publication 800-63Bsup1, 2024, doi: 10.6028/NIST.SP.800-63Bsup1.
OWASP Foundation, “A01:2025 Broken Access Control,” OWASP Top 10, 2025. [Online]. Available: https://owasp.org/Top10/2025/A01_2025-Broken_Access_Control/. [Accessed: Jun. 10, 2026].
OWASP Foundation, OWASP Application Security Verification Standard 5.0.0, 2025. [Online]. Available: https://owasp.org/www-project-application-security-verification-standard/. [Accessed: Jun. 10, 2026].
A. Mohamed, D. Auer, D. Hofer, and J. Küng, “A systematic literature review of authorization and access control requirements and current state of the art for different database models,” International Journal of Web Information Systems, vol. 20, no. 1, pp. 1–23, 2024, doi: 10.1108/IJWIS-04-2023-0072.
A. Anas, S. Elgamal, and B. Youssef, “Survey on detecting and preventing web application broken access control attacks,” International Journal of Electrical and Computer Engineering, vol. 14, no. 1, pp. 772–781, 2024, doi: 10.11591/ijece.v14i1.pp772-781.
J. Han, Q. Li, Y. Xu, Y. Zhu, and B. Wu, “Design of a trusted content authorization security framework for social media,” Applied Sciences, vol. 14, no. 4, Art. no. 1643, 2024, doi: 10.3390/app14041643.
OWASP Foundation, Web Security Testing Guide, 2025. [Online]. Available: https://owasp.org/www-project-web-security-testing-guide/. [Accessed: Jun. 10, 2026].
OWASP Foundation, “WSTG: Session Management Testing,” OWASP Web Security Testing Guide, 2025. [Online]. Available: https://owasp.org/www-project-web-security-testing-guide/latest/4-Web_Application_Security_Testing/06-Session_Management_Testing/README. [Accessed: Jun. 10, 2026].
OWASP Foundation, “Testing for Session Management Schema,” OWASP Web Security Testing Guide, 2025. [Online]. Available: https://owasp.org/www-project-web-security-testing-guide/latest/4-Web_Application_Security_Testing/06-Session_Management_Testing/01-Testing_for_Session_Management_Schema. [Accessed: Jun. 10, 2026].
P. A. Grassi, J. L. Fenton, E. M. Newton, R. A. Perlner, A. R. Regenscheid, W. E. Burr, J. P. Richer, N. B. Lefkovitz, J. M. Danker, Y.-Y. Choong, K. K. Greene, and M. F. Theofanos, Digital Identity Guidelines: Authentication and Lifecycle Management, NIST Special Publication 800-63B, 2020, doi: 10.6028/NIST.SP.800-63B.
OWASP Foundation, “Authorization Cheat Sheet,” OWASP Cheat Sheet Series, 2025. [Online]. Available: https://cheatsheetseries.owasp.org/cheatsheets/Authorization_Cheat_Sheet.html. [Accessed: Jun. 10, 2026].
OWASP Foundation, “Testing for Bypassing Authorization Schema,” OWASP Web Security Testing Guide, 2025. [Online]. Available: https://owasp.org/www-project-web-security-testing-guide/latest/4-Web_Application_Security_Testing/05-Authorization_Testing/02-Testing_for_Bypassing_Authorization_Schema. [Accessed: Jun. 10, 2026].
OWASP Foundation, “Testing for Insecure Direct Object References,” OWASP Web Security Testing Guide, 2025. [Online]. Available: https://owasp.org/www-project-web-security-testing-guide/latest/4-Web_Application_Security_Testing/05-Authorization_Testing/04-Testing_for_Insecure_Direct_Object_References. [Accessed: Jun. 10, 2026].
R. S. Pressman and B. R. Maxim, Software Engineering: A Practitioner’s Approach, 9th ed. New York, NY, USA: McGraw-Hill, 2020.
S. H. Putri and H. Prasetiya, “Pengujian software testing sistem ERP PT XYZ dengan metode black box testing,” Kurawal: Jurnal Teknologi, Informasi dan Industri, vol. 6, no. 1, pp. 15–29, 2023, doi: 10.33479/kurawal.v6i1.604.
Copyright (c) 2026 Lingga Kurnia Ramadhani, Bajeng Nurul Widyaningrum, Wahyu Wijaya Widiyanto

This work is licensed under a Creative Commons Attribution-NonCommercial 4.0 International License.















