{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,13]],"date-time":"2026-06-13T06:34:11Z","timestamp":1781332451301,"version":"3.54.1"},"publisher-location":"Cham","reference-count":30,"publisher":"Springer Nature Switzerland","isbn-type":[{"value":"9783031651748","type":"print"},{"value":"9783031651755","type":"electronic"}],"license":[{"start":{"date-parts":[[2024,1,1]],"date-time":"2024-01-01T00:00:00Z","timestamp":1704067200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2024,1,1]],"date-time":"2024-01-01T00:00:00Z","timestamp":1704067200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2024]]},"DOI":"10.1007\/978-3-031-65175-5_26","type":"book-chapter","created":{"date-parts":[[2024,7,25]],"date-time":"2024-07-25T14:43:01Z","timestamp":1721918581000},"page":"367-380","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":3,"title":["Cognition Behind Access Control: A\u00a0Usability Comparison of\u00a0Rule- and Category-Based Mechanisms"],"prefix":"10.1007","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-8822-2932","authenticated-orcid":false,"given":"Denis","family":"Obrezkov","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2024,7,26]]},"reference":[{"key":"26_CR1","doi-asserted-by":"crossref","unstructured":"The menlo report: IEEE Security & Privacy 10(2), 71\u201375 (2012)","DOI":"10.1109\/MSP.2012.52"},{"key":"26_CR2","doi-asserted-by":"crossref","unstructured":"Anwar, M., Fong, P.W.: A visualization tool for evaluating access control policies in facebook-style social network systems. In: Proceedings of the 27th Annual ACM Symposium on Applied Computing, pp. 1443\u20131450 (2012)","DOI":"10.1145\/2245276.2232007"},{"key":"26_CR3","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"106","DOI":"10.1007\/978-3-642-11207-2_9","volume-title":"Data Privacy Management and Autonomous Spontaneous Security","author":"M Anwar","year":"2010","unstructured":"Anwar, M., Fong, P.W.L., Yang, X.-D., Hamilton, H.: Visualizing privacy implications of access control policies in social network systems. In: Garcia-Alfaro, J., Navarro-Arribas, G., Cuppens-Boulahia, N., Roudier, Y. (eds.) DPM\/SETOP -2009. LNCS, vol. 5939, pp. 106\u2013120. Springer, Heidelberg (2010). https:\/\/doi.org\/10.1007\/978-3-642-11207-2_9"},{"key":"26_CR4","doi-asserted-by":"publisher","DOI":"10.1017\/CBO9780511759185","volume-title":"Remembering: A Study in Experimental and Social Psychology","author":"FC Bartlett","year":"1995","unstructured":"Bartlett, F.C., Bartlett, F.C.: Remembering: A Study in Experimental and Social Psychology. Cambridge University Press, Cambridge (1995)"},{"key":"26_CR5","doi-asserted-by":"crossref","unstructured":"Bell, D.E., La Padula, L.J.: Secure computer system: Unified exposition and multics interpretation. Technical report, MITRE CORP BEDFORD MA (1976)","DOI":"10.21236\/ADA023588"},{"key":"26_CR6","doi-asserted-by":"crossref","unstructured":"Bruns, G., Fong, P.W., Siahaan, I., Huth, M.: Relationship-based access control: its expression and enforcement through hybrid logic. In: Proceedings of the second ACM conference on Data and Application Security and Privacy, pp. 117\u2013124 (2012)","DOI":"10.1145\/2133601.2133616"},{"key":"26_CR7","doi-asserted-by":"crossref","unstructured":"Cao, X., Iverson, L.: Intentional access management: making access control usable for end-users. In: Proceedings of the Second Symposium on Usable Privacy and Security, pp. 20\u201331 (2006)","DOI":"10.1145\/1143120.1143124"},{"key":"26_CR8","doi-asserted-by":"crossref","unstructured":"Eysenck, M.W., Brysbaert, M.: Fundamentals of Cognition. Routledge (2018)","DOI":"10.4324\/9781315617633"},{"key":"26_CR9","unstructured":"Eysenck, M.W., Keane, M.T.: Cognitive Psychology: A Student\u2019s Handbook. Taylor & Francis (2005)"},{"issue":"1","key":"26_CR10","doi-asserted-by":"publisher","first-page":"34","DOI":"10.1145\/300830.300834","volume":"2","author":"DF Ferraiolo","year":"1999","unstructured":"Ferraiolo, D.F., Barkley, J.F., Kuhn, D.R.: A role-based access control model and reference implementation within a corporate intranet. ACM Trans. Inf. Syst. Secur. (TISSEC) 2(1), 34\u201364 (1999)","journal-title":"ACM Trans. Inf. Syst. Secur. (TISSEC)"},{"key":"26_CR11","doi-asserted-by":"crossref","unstructured":"Fong, P.W., Siahaan, I.: Relationship-based access control policies and their policy languages. In: Proceedings of the 16th ACM Symposium on Access Control Models and Technologies, pp. 51\u201360 (2011)","DOI":"10.1145\/1998441.1998450"},{"key":"26_CR12","unstructured":"Gentner, D., Kurtz, K.J.: Relational categories (2005)"},{"issue":"3","key":"26_CR13","doi-asserted-by":"publisher","first-page":"359","DOI":"10.1016\/j.cognition.2010.10.009","volume":"118","author":"MB Goldwater","year":"2011","unstructured":"Goldwater, M.B., Markman, A.B., Stilwell, C.H.: The empirical case for role-governed categories. Cognition 118(3), 359\u2013376 (2011)","journal-title":"Cognition"},{"key":"26_CR14","doi-asserted-by":"crossref","unstructured":"Hart, S.G., Staveland, L.E.: Development of NASA-TLX (task load index): Results of empirical and theoretical research. In: Advances in Psychology, vol.\u00a052, pp. 139\u2013183. Elsevier (1988)","DOI":"10.1016\/S0166-4115(08)62386-9"},{"key":"26_CR15","doi-asserted-by":"crossref","unstructured":"Krishnan, V., Tripunitara, M.V., Chik, K., Bergstrom, T.: Relating declarative semantics and usability in access control. In: Proceedings of the Eighth Symposium on Usable Privacy and Security, pp. 1\u201313 (2012)","DOI":"10.1145\/2335356.2335375"},{"key":"26_CR16","doi-asserted-by":"crossref","unstructured":"Neale, D.C., Carroll, J.M.: Chapter 20 - the role of metaphors in user interface design. In: Helander, M.G., Landauer, T.K., Prabhu, P.V. (eds.) Handbook of Human-Computer Interaction (Second Edition), pp. 441\u2013462. North-Holland, Amsterdam, second edition edn. (1997)","DOI":"10.1016\/B978-044481862-1\/50086-8"},{"key":"26_CR17","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"3","DOI":"10.1007\/978-3-031-57540-2_1","volume-title":"FPS 2023","author":"D Obrezkov","year":"2023","unstructured":"Obrezkov, D., Sohr, K.: UCAT: the uniform categorization for access control. In: S\u00e9des, F., Tawbi, N., Ahmed, T., Boulahia-Cuppens, N., Garcia-Alfaro, J. (eds.) FPS 2023. LNCS, vol. 14552, pp. 3\u201314. Springer, Cham (2023). https:\/\/doi.org\/10.1007\/978-3-031-57540-2_1"},{"key":"26_CR18","doi-asserted-by":"crossref","unstructured":"Obrezkov, D., Sohr, K., Malaka, R.: \"Do metaphors influence the usability of access control?\u201d: a gamified survey. In: Proceedings of Mensch Und Computer 2022, pp. 472\u2013476. MuC 2022, Association for Computing Machinery, New York, NY, USA (2022)","DOI":"10.1145\/3543758.3547559"},{"key":"26_CR19","doi-asserted-by":"crossref","unstructured":"Reeder, R.W., Bauer, L., Cranor, L.F., Reiter, M.K., Vaniea, K.: More than skin deep: measuring effects of the underlying model on access-control system usability. In: Proceedings of the SIGCHI Conference on Human Factors in Computing Systems, pp. 2065\u20132074 (2011)","DOI":"10.1145\/1978942.1979243"},{"key":"26_CR20","doi-asserted-by":"crossref","unstructured":"Sauro, J., Dumas, J.S.: Comparison of three one-question, post-task usability questionnaires. In: Proceedings of the SIGCHI Conference on Human Factors in Computing Systems, pp. 1599\u20131608 (2009)","DOI":"10.1145\/1518701.1518946"},{"issue":"5","key":"26_CR21","doi-asserted-by":"publisher","first-page":"64","DOI":"10.1109\/MSP.2004.78","volume":"2","author":"OS Saydjari","year":"2004","unstructured":"Saydjari, O.S.: Multilevel security: reprise. IEEE Secur. Priv. 2(5), 64\u201367 (2004)","journal-title":"IEEE Secur. Priv."},{"key":"26_CR22","doi-asserted-by":"crossref","unstructured":"Smetters, D.K., Good, N.: How users use access control. In: Proceedings of the 5th Symposium on Usable Privacy and Security, pp. 1\u201312 (2009)","DOI":"10.1145\/1572532.1572552"},{"issue":"10","key":"26_CR23","doi-asserted-by":"publisher","first-page":"2355","DOI":"10.1016\/j.neubiorev.2012.09.003","volume":"36","author":"JD Smith","year":"2012","unstructured":"Smith, J.D., et al.: Implicit and explicit categorization: a tale of four species. Neurosci. Biobehav. Rev. 36(10), 2355\u20132369 (2012)","journal-title":"Neurosci. Biobehav. Rev."},{"key":"26_CR24","doi-asserted-by":"crossref","unstructured":"Thorleuchter, D., Van Den\u00a0Poel, D.: High granular multi-level-security model for improved usability. In: 2011 International Conference on System science, Engineering design and Manufacturing informatization, vol.\u00a01, pp. 191\u2013194. IEEE (2011)","DOI":"10.1109\/ICSSEM.2011.6081180"},{"key":"26_CR25","unstructured":"Vermeulen, S.: SELinux System Administration. Packt Publishing Ltd (2016)"},{"key":"26_CR26","doi-asserted-by":"crossref","unstructured":"Wang, L., Wijesekera, D., Jajodia, S.: A logic-based framework for attribute based access control. In: Proceedings of the 2004 ACM Workshop on Formal Methods in Security Engineering, pp. 45\u201355 (2004)","DOI":"10.1145\/1029133.1029140"},{"issue":"4","key":"26_CR27","doi-asserted-by":"publisher","first-page":"34","DOI":"10.1145\/1330311.1330320","volume":"51","author":"R West","year":"2008","unstructured":"West, R.: The psychology of security. Commun. ACM 51(4), 34\u201340 (2008)","journal-title":"Commun. ACM"},{"key":"26_CR28","unstructured":"Whitten, A., Tygar, J.D.: Why Johnny can\u2019t encrypt: a usability evaluation of PGP 5.0. In: USENIX security symposium, vol.\u00a0348, pp. 169\u2013184 (1999)"},{"key":"26_CR29","doi-asserted-by":"crossref","unstructured":"Zhang, W., Li, H., Zhang, M., Lv, Z.: Privacy-aware risk-adaptive access control in health information systems using topic models. In: Proceedings of the 23nd ACM on Symposium on Access Control Models and Technologies, pp. 61\u201367 (2018)","DOI":"10.1145\/3205977.3205991"},{"key":"26_CR30","doi-asserted-by":"crossref","unstructured":"Zurko, M.E., Simon, R.T.: User-centered security. In: Proceedings of the 1996 Workshop on New Security Paradigms, pp. 27\u201333 (1996)","DOI":"10.1145\/304851.304859"}],"container-title":["IFIP Advances in Information and Communication Technology","ICT Systems Security and Privacy Protection"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-031-65175-5_26","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,7,25]],"date-time":"2024-07-25T14:47:16Z","timestamp":1721918836000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-031-65175-5_26"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024]]},"ISBN":["9783031651748","9783031651755"],"references-count":30,"URL":"https:\/\/doi.org\/10.1007\/978-3-031-65175-5_26","relation":{},"ISSN":["1868-4238","1868-422X"],"issn-type":[{"value":"1868-4238","type":"print"},{"value":"1868-422X","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024]]},"assertion":[{"value":"26 July 2024","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"SEC","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"IFIP International Conference on ICT Systems Security and Privacy Protection","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Edinburgh","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"United Kingdom","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2024","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"12 June 2024","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"14 June 2024","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"39","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"sec2024","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/ifipsec2024.co.uk\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}