{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,8,24]],"date-time":"2025-08-24T01:32:18Z","timestamp":1755999138010,"version":"3.41.0"},"publisher-location":"Cham","reference-count":29,"publisher":"Springer International Publishing","isbn-type":[{"type":"print","value":"9783319498058"},{"type":"electronic","value":"9783319498065"}],"license":[{"start":{"date-parts":[[2016,1,1]],"date-time":"2016-01-01T00:00:00Z","timestamp":1451606400000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2016]]},"DOI":"10.1007\/978-3-319-49806-5_6","type":"book-chapter","created":{"date-parts":[[2016,11,23]],"date-time":"2016-11-23T12:34:29Z","timestamp":1479904469000},"page":"109-130","source":"Crossref","is-referenced-by-count":5,"title":["Collaborative Access Decisions: Why Has My Decision Not Been Enforced?"],"prefix":"10.1007","author":[{"given":"Jerry","family":"den Hartog","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Nicola","family":"Zannone","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2016,11,24]]},"reference":[{"key":"6_CR1","unstructured":"Ashley, P., Hada, S., Karjoth, G., Powers, C., Schunter, M.: Enterprise Privacy Authorization Language (EPAL 1.2) (2003)"},{"key":"6_CR2","doi-asserted-by":"crossref","unstructured":"Backes, M., Karjoth, G., Bagga, W., Schunter, M.: Efficient comparison of enterprise privacy policies. In: Proceedings of Symposium on Applied Computing, pp. 375\u2013382. ACM (2004)","DOI":"10.1145\/967900.967983"},{"key":"6_CR3","doi-asserted-by":"crossref","unstructured":"Carminati, B., Ferrari, E.: Collaborative access control in on-line social networks. In: Proceedings of International Conference on Collaborative Computing, pp. 231\u2013240 (2011)","DOI":"10.4108\/icst.collaboratecom.2011.247109"},{"key":"6_CR4","doi-asserted-by":"crossref","unstructured":"Costante, E., den Hartog, J.I., Petkovic, M.: On-line trust perception: what really matters. In: Proceedings of Workshop on Socio-Technical Aspects in Security and Trust, pp. 52\u201359. IEEE (2011)","DOI":"10.1109\/STAST.2011.6059256"},{"issue":"2","key":"6_CR5","doi-asserted-by":"crossref","first-page":"327","DOI":"10.1111\/coin.12025","volume":"31","author":"E Costante","year":"2015","unstructured":"Costante, E., den Hartog, J.I., Petkovic, M.: Understanding perceived trust to reduce regret. Comput. Intell. 31(2), 327\u2013347 (2015)","journal-title":"Comput. Intell."},{"key":"6_CR6","doi-asserted-by":"crossref","unstructured":"Damen, S., den Hartog, J., Zannone, N.: CollAC: collaborative access control. In: Proceedings of International Conference on Collaboration Technologies and Systems, pp. 142\u2013149. IEEE (2014)","DOI":"10.1109\/CTS.2014.6867557"},{"key":"6_CR7","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"121","DOI":"10.1007\/978-3-319-06811-4_16","volume-title":"Secure Data Management","author":"S Damen","year":"2014","unstructured":"Damen, S., Zannone, N.: Privacy implications of privacy settings and tagging in facebook. In: Jonker, W., Petkovi\u0107, M. (eds.) SDM 2013. LNCS, vol. 8425, pp. 121\u2013138. Springer, Heidelberg (2014). doi: 10.1007\/978-3-319-06811-4_16"},{"key":"6_CR8","doi-asserted-by":"crossref","unstructured":"Fisler, K., Krishnamurthi, S., Meyerovich, L.A., Tschantz, M.C.: Verification and change-impact analysis of access-control policies. In: Proceedings of International Conference on Software Engineering, pp. 196\u2013205. ACM (2005)","DOI":"10.1109\/ICSE.2005.1553562"},{"key":"6_CR9","doi-asserted-by":"crossref","unstructured":"Fong, P.W.: Relationship-based access control: protection model and policy language. In: Proceedings of Conference on Data and Application Security and Privacy, pp. 191\u2013202. ACM (2011)","DOI":"10.1145\/1943513.1943539"},{"key":"6_CR10","doi-asserted-by":"crossref","unstructured":"Ghai, S.K., Nigam, P., Kumaraguru, P.: Cue: a framework for generating meaningful feedback in XACML. In: Proceedings of Workshop on Assurable and Usable Security Configuration, pp. 9\u201316. ACM (2010)","DOI":"10.1145\/1866898.1866901"},{"issue":"2","key":"6_CR11","doi-asserted-by":"crossref","first-page":"337","DOI":"10.1016\/j.infsof.2008.04.004","volume":"51","author":"P Guarda","year":"2009","unstructured":"Guarda, P., Zannone, N.: Towards the development of privacy-aware systems. Inf. Softw. Technol. 51(2), 337\u2013350 (2009)","journal-title":"Inf. Softw. Technol."},{"key":"6_CR12","doi-asserted-by":"crossref","unstructured":"den Hartog, J., Zannone, N.: A policy framework for data fusion and derived data control. In: Proceedings of the ACM International Workshop on Attribute Based Access Control, pp. 47\u201357. ACM (2016)","DOI":"10.1145\/2875491.2875492"},{"issue":"7","key":"6_CR13","first-page":"1614","volume":"25","author":"H Hu","year":"2013","unstructured":"Hu, H., Ahn, G.J., Jorgensen, J.: Multiparty access control for online social networks: model and mechanisms. TKDE 25(7), 1614\u20131627 (2013)","journal-title":"TKDE"},{"key":"6_CR14","doi-asserted-by":"crossref","unstructured":"Hughes, G., Bultan, T.: Automated verification of access control policies using a SAT solver. Int. J. Softw. Tools Technol. Transf. 10(6), 503\u2013520 (2008)","DOI":"10.1007\/s10009-008-0087-9"},{"issue":"2","key":"6_CR15","doi-asserted-by":"crossref","first-page":"214","DOI":"10.1145\/383891.383894","volume":"26","author":"S Jajodia","year":"2001","unstructured":"Jajodia, S., Samarati, P., Sapino, M.L., Subrahmanian, V.S.: Flexible support for multiple access control policies. ACM Trans. Database Syst. 26(2), 214\u2013260 (2001)","journal-title":"ACM Trans. Database Syst."},{"key":"6_CR16","doi-asserted-by":"crossref","unstructured":"Kaluvuri, S.P., Egner, A.I., den Hartog, J., Zannone, N.: SAFAX - an extensible authorization service for cloud environments. Front. ICT 2(9) (2015)","DOI":"10.3389\/fict.2015.00009"},{"key":"6_CR17","doi-asserted-by":"crossref","unstructured":"Kapadia, A., Sampemane, G., Campbell, R.H.: KNOW why your access was denied: regulating feedback for usable security. In: Proceedings of Conference on Computer and Communications Security, pp. 52\u201361. ACM (2004)","DOI":"10.1145\/1030083.1030092"},{"issue":"5","key":"6_CR18","doi-asserted-by":"crossref","first-page":"580","DOI":"10.1007\/BF01211870","volume":"6","author":"L Lamport","year":"1994","unstructured":"Lamport, L.: How to write a long formula. Formal Aspects Comput. 6(5), 580\u2013584 (1994)","journal-title":"Formal Aspects Comput."},{"key":"6_CR19","doi-asserted-by":"crossref","unstructured":"Li, N., Wang, Q., Qardaji, W., Bertino, E., Rao, P., Lobo, J., Lin, D.: Access control policy combining: theory meets practice. In: Proceedings of SACMAT, pp. 135\u2013144. ACM (2009)","DOI":"10.1145\/1542207.1542229"},{"key":"6_CR20","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"199","DOI":"10.1007\/978-3-319-41483-6_15","volume-title":"Data and Applications Security and Privacy XXX","author":"R Mahmudlu","year":"2016","unstructured":"Mahmudlu, R., Hartog, J., Zannone, N.: Data governance and transparency for collaborative systems. In: Ranise, S., Swarup, V. (eds.) DBSec 2016. LNCS, vol. 9766, pp. 199\u2013216. Springer, Heidelberg (2016). doi: 10.1007\/978-3-319-41483-6_15"},{"key":"6_CR21","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"133","DOI":"10.1007\/978-3-642-35890-6_10","volume-title":"Data Privacy Management and Autonomous Spontaneous Security","author":"I Matteucci","year":"2013","unstructured":"Matteucci, I., Mori, P., Petrocchi, M.: Prioritized execution of privacy policies. In: Pietro, R., Herranz, J., Damiani, E., State, R. (eds.) DPM\/SETOP -2012. LNCS, vol. 7731, pp. 133\u2013145. Springer, Heidelberg (2013). doi: 10.1007\/978-3-642-35890-6_10"},{"key":"6_CR22","unstructured":"OASIS XACML Technical Committee: eXtensible Access Control Markup Language (XACML) Version 2.0 (2005)"},{"key":"6_CR23","unstructured":"OASIS XACML Technical Committee: eXtensible Access Control Markup Language (XACML) Version 3.0 (2013)"},{"key":"6_CR24","doi-asserted-by":"crossref","unstructured":"Paci, F., Zannone, N.: Preventing information inference in access control. In: Proceedings of Symposium on Access Control Models and Technologies, pp. 87\u201397. ACM (2015)","DOI":"10.1145\/2752952.2752971"},{"key":"6_CR25","unstructured":"Reeder, R.W., Bauer, L., Cranor, L.F., Reiter, M.K., Vaniea, K.: Effects of access-control policy conflict-resolution methods on policy-authoring usability. CyLab, p. 12 (2009)"},{"issue":"1\u20132","key":"6_CR26","doi-asserted-by":"crossref","first-page":"21","DOI":"10.1007\/s12243-013-0371-x","volume":"69","author":"AC Squicciarini","year":"2014","unstructured":"Squicciarini, A.C., Paci, F., Sundareswaran, S.: PriMa: a comprehensive approach to privacy protection in social network sites. Annales des T\u00e9l\u00e9communications 69(1\u20132), 21\u201336 (2014)","journal-title":"Annales des T\u00e9l\u00e9communications"},{"issue":"3","key":"6_CR27","first-page":"293","volume":"14","author":"D Trivellato","year":"2014","unstructured":"Trivellato, D., Zannone, N., Etalle, S.: GEM: a distributed goal evaluation algorithm for trust management. TPLP 14(3), 293\u2013337 (2014)","journal-title":"TPLP"},{"key":"6_CR28","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"115","DOI":"10.1007\/978-3-662-46666-7_7","volume-title":"Principles of Security and Trust","author":"F Turkmen","year":"2015","unstructured":"Turkmen, F., Hartog, J., Ranise, S., Zannone, N.: Analysis of XACML policies with SMT. In: Focardi, R., Myers, A. (eds.) POST 2015. LNCS, vol. 9036, pp. 115\u2013134. Springer, Heidelberg (2015). doi: 10.1007\/978-3-662-46666-7_7"},{"key":"6_CR29","doi-asserted-by":"crossref","unstructured":"Winsborough, W.H., Seamons, K.E., Jones, V.E.: Automated trust negotiation. In: Proceedings of DARPA Information Survivability Conference, pp. 88\u2013102 (2000)","DOI":"10.1109\/DISCEX.2000.824965"}],"container-title":["Lecture Notes in Computer Science","Information Systems Security"],"original-title":[],"link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-319-49806-5_6","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,12]],"date-time":"2025-06-12T20:41:45Z","timestamp":1749760905000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-319-49806-5_6"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2016]]},"ISBN":["9783319498058","9783319498065"],"references-count":29,"URL":"https:\/\/doi.org\/10.1007\/978-3-319-49806-5_6","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2016]]}}}