{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,28]],"date-time":"2026-03-28T09:30:52Z","timestamp":1774690252252,"version":"3.50.1"},"publisher-location":"Cham","reference-count":46,"publisher":"Springer International Publishing","isbn-type":[{"value":"9783030914301","type":"print"},{"value":"9783030914318","type":"electronic"}],"license":[{"start":{"date-parts":[[2021,1,1]],"date-time":"2021-01-01T00:00:00Z","timestamp":1609459200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"},{"start":{"date-parts":[[2021,1,1]],"date-time":"2021-01-01T00:00:00Z","timestamp":1609459200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2021]]},"DOI":"10.1007\/978-3-030-91431-8_13","type":"book-chapter","created":{"date-parts":[[2021,11,17]],"date-time":"2021-11-17T16:13:29Z","timestamp":1637165609000},"page":"204-220","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":2,"title":["ThunQ: A Distributed and Deep Authorization Middleware for Early and Lazy Policy Enforcement in Microservice Applications"],"prefix":"10.1007","author":[{"given":"Martijn","family":"Sauwens","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Emad","family":"Heydari Beni","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Kristof","family":"Jannes","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Bert","family":"Lagaisse","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Wouter","family":"Joosen","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2021,11,18]]},"reference":[{"key":"13_CR1","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"573","DOI":"10.1007\/978-3-030-04771-9_43","volume-title":"Software Technologies: Applications and Foundations","author":"M Ahmadvand","year":"2018","unstructured":"Ahmadvand, M., Pretschner, A., Ball, K., Eyring, D.: Integrity protection against insiders in microservice-based infrastructures: from threats to a security framework. In: Mazzara, M., Ober, I., Sala\u00fcn, G. (eds.) STAF 2018. LNCS, vol. 11176, pp. 573\u2013588. Springer, Cham (2018). https:\/\/doi.org\/10.1007\/978-3-030-04771-9_43"},{"issue":"1","key":"13_CR2","first-page":"2","volume":"2","author":"E Bertino","year":"2005","unstructured":"Bertino, E., Sandhu, R.: Database security-concepts, approaches, and challenges. IEEE TDSC 2(1), 2\u201319 (2005)","journal-title":"IEEE TDSC"},{"key":"13_CR3","doi-asserted-by":"crossref","unstructured":"Bogaerts, J., Lagaisse, B., Joosen, W.: Sequoia: a middleware supporting policy-based access control for search and aggregation in data-driven applications. IEEE TDSC 18(1) (2021)","DOI":"10.1109\/TDSC.2018.2889309"},{"key":"13_CR4","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"177","DOI":"10.1007\/978-3-319-59665-5_13","volume-title":"Distributed Applications and Interoperable Systems","author":"S Brenner","year":"2017","unstructured":"Brenner, S., Hundt, T., Mazzeo, G., Kapitza, R.: Secure cloud micro services using intel SGX. In: Chen, L.Y., Reiser, H.P. (eds.) DAIS 2017. LNCS, vol. 10320, pp. 177\u2013191. Springer, Cham (2017). https:\/\/doi.org\/10.1007\/978-3-319-59665-5_13"},{"key":"13_CR5","unstructured":"Brewer, D., Nash, M.: The Chinese wall security policy. In: Proceedings of IEEE S&P 1989 (1989)"},{"key":"13_CR6","unstructured":"Bystr, C., Heyman, J., Hamr\u00e9n, J., Heyman, H., Holmberg, L.: Locust. https:\/\/locust.io\/"},{"key":"13_CR7","doi-asserted-by":"crossref","unstructured":"Chen, J., Huang, H., Chen, H.: Informer: irregular traffic detection for containerized microservices RPC in the real world. In: Proceedings of SEC 2019. ACM (2019)","DOI":"10.1145\/3318216.3363375"},{"key":"13_CR8","unstructured":"De Win, B., Piessens, F., Joosen, W., Verhanneman, T.: On the importance of the separation-of-concerns principle in secure software engineering. In: ACSAC - WAEPSSD (2003)"},{"key":"13_CR9","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"344","DOI":"10.1007\/978-3-642-34321-6_23","volume-title":"Service-Oriented Computing","author":"A Faravelon","year":"2012","unstructured":"Faravelon, A., Chollet, S., Verdier, C., Front, A.: Configuring private data management as access restrictions: from design to enforcement. In: Liu, C., Ludwig, H., Toumani, F., Yu, Q. (eds.) ICSOC 2012. LNCS, vol. 7636, pp. 344\u2013358. Springer, Heidelberg (2012). https:\/\/doi.org\/10.1007\/978-3-642-34321-6_23"},{"key":"13_CR10","doi-asserted-by":"crossref","unstructured":"Guo, C.J., Sun, W., Huang, Y., Wang, Z.H., Gao, B.: A framework for native multi-tenancy application development and management. In: CEC-EEE (2007)","DOI":"10.1109\/CEC-EEE.2007.4"},{"key":"13_CR11","doi-asserted-by":"crossref","unstructured":"Hannousse, A., Yahiouche, S.: Securing microservices and microservice architectures: a systematic mapping study. Comput. Sci. Rev. 41, 100415 (2021)","DOI":"10.1016\/j.cosrev.2021.100415"},{"key":"13_CR12","doi-asserted-by":"crossref","unstructured":"Hu, V., et al.: Guide to attribute based access control (ABAC) definition and consideration. Technical report, NIST (2014)","DOI":"10.6028\/NIST.SP.800-162"},{"key":"13_CR13","unstructured":"Jin, H., Li, Z., Zou, D., Yuan, B.: Dseom: a framework for dynamic security evaluation and optimization of MTD in container-based cloud. IEEE TDSC 18(3) (2021)"},{"key":"13_CR14","unstructured":"Li, X., Chen, Y., Lin, Z., Wang, X., Chen, J.H.: Automatic policy generation for inter-service access control of microservices. In: USENIX Security 21. USENIX Association (2021)"},{"key":"13_CR15","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"285","DOI":"10.1007\/978-3-030-18419-3_19","volume-title":"Foundations and Practice of Security","author":"A Nehme","year":"2019","unstructured":"Nehme, A., Jesus, V., Mahbub, K., Abdallah, A.: Fine-grained access control for microservices. In: Zincir-Heywood, N., Bonfante, G., Debbabi, M., Garcia-Alfaro, J. (eds.) FPS 2018. LNCS, vol. 11358, pp. 285\u2013300. Springer, Cham (2019). https:\/\/doi.org\/10.1007\/978-3-030-18419-3_19"},{"issue":"2","key":"13_CR16","first-page":"1","volume":"5","author":"L Opyrchal","year":"2011","unstructured":"Opyrchal, L., Cooper, J., Poyar, R., Lenahan, B., Daniel, Z.: Bouncer: policy-based fine grained access control in large databases. IJSIA 5(2), 1\u201316 (2011)","journal-title":"IJSIA"},{"key":"13_CR17","doi-asserted-by":"crossref","unstructured":"Osman, A., Bruckner, P., Salah, H., Fitzek, F.H.P., Strufe, T., Fischer, M.: Sandnet: towards high quality of deception in container-based microservice architectures. In: IEEE ICC (2019)","DOI":"10.1109\/ICC.2019.8761171"},{"key":"13_CR18","unstructured":"Parducci, B., Lockhart, H.: Extensible access control markup language (XACML) version 3.0. Standard, OASIS (2013)"},{"key":"13_CR19","doi-asserted-by":"publisher","first-page":"102200","DOI":"10.1016\/j.cose.2021.102200","volume":"103","author":"A Pereira-Vale","year":"2021","unstructured":"Pereira-Vale, A., Fernandez, E.B., Monge, R., Astudillo, H., M\u00e1rquez, G.: Security in microservice-based systems: a multivocal literature review. Comput. Secur. 103, 102200 (2021)","journal-title":"Comput. Secur."},{"key":"13_CR20","doi-asserted-by":"crossref","unstructured":"Preuveneers, D., Joosen, W.: Towards multi-party policy-based access control in federations of cloud and edge microservices. In: IEEE Euro S&PW (2019)","DOI":"10.1109\/EuroSPW.2019.00010"},{"key":"13_CR21","doi-asserted-by":"crossref","unstructured":"Ranjbar, A., Komu, M., Salmela, P., Aura, T.: Synaptic: secure and persistent connectivity for containers. In: IEEE\/ACM CCGRID (2017)","DOI":"10.1109\/CCGRID.2017.62"},{"key":"13_CR22","doi-asserted-by":"crossref","unstructured":"Ravichandiran, R., Bannazadeh, H., Leon-Garcia, A.: Anomaly detection using resource behaviour analysis for autoscaling systems. In: NetSoft and Workshops (2018)","DOI":"10.1109\/NETSOFT.2018.8460025"},{"key":"13_CR23","unstructured":"Richardson, C.: Microservices Patterns. Manning Publications Co. (2018)"},{"key":"13_CR24","doi-asserted-by":"crossref","unstructured":"Rizvi, S., Mendelzon, A., Sudarshan, S., Roy, P.: Extending query rewriting techniques for fine-grained access control. In: Proceedings of SIGMOD 2004. ACM (2004)","DOI":"10.1145\/1007568.1007631"},{"key":"13_CR25","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"137","DOI":"10.1007\/3-540-45608-2_3","volume-title":"Foundations of Security Analysis and Design","author":"P Samarati","year":"2001","unstructured":"Samarati, P., de Vimercati, S.C.: Access control: policies, models, and mechanisms. In: Focardi, R., Gorrieri, R. (eds.) FOSAD 2000. LNCS, vol. 2171, pp. 137\u2013196. Springer, Heidelberg (2001). https:\/\/doi.org\/10.1007\/3-540-45608-2_3"},{"key":"13_CR26","unstructured":"Sandall, T.: Partial evaluation. https:\/\/blog.openpolicyagent.org\/partial-evaluation-162750eaf422"},{"issue":"11","key":"13_CR27","doi-asserted-by":"publisher","first-page":"9","DOI":"10.1109\/2.241422","volume":"26","author":"RS Sandhu","year":"1993","unstructured":"Sandhu, R.S.: Lattice-based access control models. Computer 26(11), 9\u201319 (1993)","journal-title":"Computer"},{"issue":"2","key":"13_CR28","doi-asserted-by":"publisher","first-page":"38","DOI":"10.1109\/2.485845","volume":"29","author":"RS Sandhu","year":"1996","unstructured":"Sandhu, R.S., Coyne, E.J., Feinstein, H.L., Youman, C.E.: Role-based access control models. Computer 29(2), 38\u201347 (1996)","journal-title":"Computer"},{"key":"13_CR29","doi-asserted-by":"crossref","unstructured":"ShuLin, Y., JiePing, H.: Research on unified authentication and authorization in microservice architecture. In: IEEE ICCT (2020)","DOI":"10.1109\/ICCT50939.2020.9295931"},{"key":"13_CR30","doi-asserted-by":"crossref","unstructured":"da Silva, M.S.L., de Oliveira Silva, F.F., Brito, A.: Squad: a secure, simple storage service for SGX-based microservices. In: LADC (2019)","DOI":"10.1109\/LADC48089.2019.8995723"},{"key":"13_CR31","doi-asserted-by":"crossref","unstructured":"Sun, Y., Nanda, S., Jaeger, T.: Security-as-a-service for microservices-based cloud applications. In: IEEE CloudCom (2015)","DOI":"10.1109\/CloudCom.2015.93"},{"key":"13_CR32","doi-asserted-by":"crossref","unstructured":"Taibi, T., Lenarduzzi, V., Pahl, C.: Architectural patterns for microservices: a systematic mapping study. In: Proceedings of CLOSER. SciTePress (2018)","DOI":"10.5220\/0006798302210232"},{"key":"13_CR33","doi-asserted-by":"crossref","unstructured":"Torkura, K.A., Sukmana, M.I., Kayem, A.V., Cheng, F., Meinel, C.: A cyber risk based moving target defense mechanism for microservice architectures. In: IEEE BDCloud (2018)","DOI":"10.1109\/BDCloud.2018.00137"},{"key":"13_CR34","unstructured":"Verhanneman, T., Piessens, F., De Win, B., Joosen, W.: Uniform application-level access control enforcement of organizationwide policies. In: ACSAC 2005 (2005)"},{"key":"13_CR35","unstructured":"Westk\u00e4mper, T., Dijkstra, R., Tims, J., Bain, R.: Querydsl. http:\/\/www.querydsl.com\/"},{"issue":"5","key":"13_CR36","first-page":"533","volume":"12","author":"Z Xu","year":"2015","unstructured":"Xu, Z., Stoller, S.D.: Mining attribute-based access control policies. IEEE TDSC 12(5), 533\u2013545 (2015)","journal-title":"IEEE TDSC"},{"key":"13_CR37","doi-asserted-by":"crossref","unstructured":"Zaheer, Z., Chang, H., Mukherjee, S., Van der Merwe, J.: Eztrust: network-independent zero-trust perimeterization for microservices. In: Proceedings of SOSR 2019. ACM (2019)","DOI":"10.1145\/3314148.3314349"},{"key":"13_CR38","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"294","DOI":"10.1007\/978-3-642-37804-1_30","volume-title":"Service-Oriented Computing - ICSOC 2012 Workshops","author":"G Zhang","year":"2013","unstructured":"Zhang, G., Liu, J., Liu, J., et al.: Protecting sensitive attributes in attribute based access control. In: Ghose, A. (ed.) ICSOC 2012. LNCS, vol. 7759, pp. 294\u2013305. Springer, Heidelberg (2013). https:\/\/doi.org\/10.1007\/978-3-642-37804-1_30"},{"key":"13_CR39","unstructured":"Keycloak. https:\/\/www.keycloak.org\/"},{"key":"13_CR40","unstructured":"Rego. https:\/\/www.openpolicyagent.org\/docs\/latest\/policy-language\/"},{"key":"13_CR41","unstructured":"Open policy agent. https:\/\/www.openpolicyagent.org\/"},{"key":"13_CR42","unstructured":"Spring boot. https:\/\/spring.io\/projects\/spring-boot"},{"key":"13_CR43","unstructured":"Spring data. https:\/\/spring.io\/projects\/spring-data"},{"key":"13_CR44","unstructured":"Spring cloud gateway. https:\/\/spring.io\/projects\/spring-cloud-gateway"},{"key":"13_CR45","unstructured":"Thunq. https:\/\/distrinet.cs.kuleuven.be\/software\/thunq"},{"key":"13_CR46","unstructured":"Zuul. https:\/\/github.com\/Netflix\/zuul"}],"container-title":["Lecture Notes in Computer Science","Service-Oriented Computing"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-030-91431-8_13","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2021,11,19]],"date-time":"2021-11-19T00:05:05Z","timestamp":1637280305000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-030-91431-8_13"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021]]},"ISBN":["9783030914301","9783030914318"],"references-count":46,"URL":"https:\/\/doi.org\/10.1007\/978-3-030-91431-8_13","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2021]]},"assertion":[{"value":"18 November 2021","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"ICSOC","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Service-Oriented Computing","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Dubai","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"United Arab Emirates","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2021","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"22 November 2021","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"25 November 2021","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"19","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"icsoc2021","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"http:\/\/icsoc.org\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Double-blind","order":1,"name":"type","label":"Type","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"EasyChair","order":2,"name":"conference_management_system","label":"Conference Management System","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"189","order":3,"name":"number_of_submissions_sent_for_review","label":"Number of Submissions Sent for Review","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"39","order":4,"name":"number_of_full_papers_accepted","label":"Number of Full Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"28","order":5,"name":"number_of_short_papers_accepted","label":"Number of Short Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"21% - The value is computed by the equation \"Number of Full Papers Accepted \/ Number of Submissions Sent for Review * 100\" and then rounded to a whole number.","order":6,"name":"acceptance_rate_of_full_papers","label":"Acceptance Rate of Full Papers","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"3","order":7,"name":"average_number_of_reviews_per_paper","label":"Average Number of Reviews per Paper","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"4","order":8,"name":"average_number_of_papers_per_reviewer","label":"Average Number of Papers per Reviewer","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"No","order":9,"name":"external_reviewers_involved","label":"External Reviewers Involved","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}}]}}