{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2024,9,5]],"date-time":"2024-09-05T00:43:38Z","timestamp":1725497018789},"edition-number":"1","reference-count":18,"publisher":"Wiley","isbn-type":[{"type":"print","value":"9780471383932"},{"type":"electronic","value":"9780470050118"}],"license":[{"start":{"date-parts":[[2009,3,16]],"date-time":"2009-03-16T00:00:00Z","timestamp":1237161600000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/doi.wiley.com\/10.1002\/tdm_license_1.1"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"abstract":"<jats:title>Abstract<\/jats:title><jats:p>With the enormous quantity of sensitive information (financial and personal data, medical records) that is being stored inside computer\u2010based systems on a daily basis, the survival of our modern economy depends critically on the storage of these data and the intergrity of the transactions that operate on it. When trying to analyze whether a certain computer\u2010based system is \u201csecure,\u201d engineers typically question the authentication, message authentication, intergrity, and access control, In this article, we discuss each concept in detail with special attention paid to their actual implementation in real\u2010world software systems.<\/jats:p>","DOI":"10.1002\/9780470050118.ecse028","type":"other","created":{"date-parts":[[2009,3,9]],"date-time":"2009-03-09T17:48:02Z","timestamp":1236620882000},"page":"1-12","source":"Crossref","is-referenced-by-count":0,"title":["Authentication, Access Control, and Information Flow"],"prefix":"10.1002","author":[{"given":"Arnab","family":"Ray","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"311","published-online":{"date-parts":[[2009,3,16]]},"reference":[{"key":"e_1_2_6_2_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-1-4615-1467-1"},{"volume-title":"Practical Unix and Internet Security","year":"1996","author":"Garfinkel S.","key":"e_1_2_6_3_1"},{"key":"e_1_2_6_4_1","unstructured":"CERT Advisory Available:http:\/\/www.cert.org\/advisories\/CA\u20101992\u201013.html."},{"volume-title":"Cryptography and Network Security: Principles and Practice","year":"2002","author":"Stallings W.","key":"e_1_2_6_5_1"},{"volume-title":"Handbook of Applied Cryptography","year":"1996","author":"Menezes A. J.","key":"e_1_2_6_6_1"},{"volume-title":"From Passwords to Public Keys","year":"2001","author":"Smith R. E.","key":"e_1_2_6_7_1"},{"key":"e_1_2_6_8_1","doi-asserted-by":"publisher","DOI":"10.1145\/359340.359342"},{"key":"e_1_2_6_9_1","doi-asserted-by":"publisher","DOI":"10.1109\/TIT.1985.1057074"},{"volume-title":"Kerberos: A Network Authentication System","year":"1999","author":"Tung B.","key":"e_1_2_6_10_1"},{"volume-title":"Windows NT Security Handbook","year":"1996","author":"Sheldon T.","key":"e_1_2_6_11_1"},{"key":"e_1_2_6_12_1","unstructured":"National Security Institute \u2010 5200.28\u2010STD Trusted Computer System Evaluation Criteria 1985."},{"key":"e_1_2_6_13_1","unstructured":"L. J.LaPadula The basic security theorem of bell and lapadula revisited Cipher 1999."},{"key":"e_1_2_6_14_1","unstructured":"D. F.Ferraiolo andD. R.Kuhn Role\u2010based access controls Proc. of the 15th NIST\u2010NSA National Computer Security Conference Baltimore MD 1992."},{"key":"e_1_2_6_15_1","doi-asserted-by":"publisher","DOI":"10.1145\/356850.356852"},{"key":"e_1_2_6_16_1","unstructured":"J. A.Goguen andJ.Meseguer Security policies and security models Proc. of the IEEE Symposium on Security and Privacy 1992."},{"key":"e_1_2_6_17_1","doi-asserted-by":"publisher","DOI":"10.1109\/JSAC.2002.806121"},{"key":"e_1_2_6_18_1","doi-asserted-by":"crossref","unstructured":"K.VenkatasubramanianandS.Gupta Security for pervasive health monitoring applications Proc. International Conference on Intelligent Sensing and Information Processing 2006.","DOI":"10.1109\/ICISIP.2006.4286096"},{"key":"e_1_2_6_19_1","doi-asserted-by":"crossref","unstructured":"B.Hicks D.King P.McDaniel Jifclipse: development tools for security\u2010typed languages Proc. 2nd Workshop on Programming Languages and Analysis for Security (PLAS) 2007 pp.1\u201310.","DOI":"10.1145\/1255329.1255331"}],"container-title":["Wiley Encyclopedia of Computer Science and Engineering"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/onlinelibrary.wiley.com\/doi\/pdf\/10.1002\/9780470050118.ecse028","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,3,11]],"date-time":"2024-03-11T05:48:24Z","timestamp":1710136104000},"score":1,"resource":{"primary":{"URL":"https:\/\/onlinelibrary.wiley.com\/doi\/10.1002\/9780470050118.ecse028"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2009,3,16]]},"ISBN":["9780471383932","9780470050118"],"references-count":18,"alternative-id":["10.1002\/9780470050118.ecse028","10.1002\/9780470050118"],"URL":"https:\/\/doi.org\/10.1002\/9780470050118.ecse028","archive":["Portico"],"relation":{},"subject":[],"published":{"date-parts":[[2009,3,16]]}}}