{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,5,13]],"date-time":"2025-05-13T02:43:34Z","timestamp":1747104214755},"publisher-location":"Cham","reference-count":34,"publisher":"Springer International Publishing","isbn-type":[{"type":"print","value":"9783319935232"},{"type":"electronic","value":"9783319935249"}],"license":[{"start":{"date-parts":[[2018,1,1]],"date-time":"2018-01-01T00:00:00Z","timestamp":1514764800000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2018]]},"DOI":"10.1007\/978-3-319-93524-9_4","type":"book-chapter","created":{"date-parts":[[2018,6,20]],"date-time":"2018-06-20T02:37:00Z","timestamp":1529462220000},"page":"56-72","update-policy":"http:\/\/dx.doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":15,"title":["JACPoL: A Simple but Expressive JSON-Based Access Control Policy Language"],"prefix":"10.1007","author":[{"given":"Hao","family":"Jiang","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Ahmed","family":"Bouabdallah","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2018,6,21]]},"reference":[{"key":"4_CR1","doi-asserted-by":"crossref","unstructured":"Yavatkar, R., Pendarakis, D., Guerin, R.: A Framework for Policy-Based Admission Control. IETF, RFC 2753, January 2000","DOI":"10.17487\/rfc2753"},{"key":"4_CR2","doi-asserted-by":"crossref","unstructured":"Borders, K., Zhao, X., Prakash, A.: CPOL: high-performance policy evaluation. In: The 12th ACM Conference on Computer and Communications Security. ACM (2005)","DOI":"10.1145\/1102120.1102142"},{"key":"4_CR3","unstructured":"reTHINK Project Testbed: Deliverable D6.1: Testbed Specification (2016). https:\/\/bscw.rethink-project.eu\/pub\/bscw.cgi\/d35657\/D6.1%20Testbed%20specific-ation.pdf . Accessed 17 May 2017"},{"key":"4_CR4","doi-asserted-by":"crossref","unstructured":"He, L., Qiu, X., Wang, Y., Gao, T.: Design of policy language expression in SIoT. In: Wireless and Optical Communication Conference, pp. 321\u2013326. IEEE (2013)","DOI":"10.1109\/WOCC.2013.6676386"},{"key":"4_CR5","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"18","DOI":"10.1007\/3-540-44569-2_2","volume-title":"Policies for Distributed Systems and Networks","author":"N Damianou","year":"2001","unstructured":"Damianou, N., Dulay, N., Lupu, E., Sloman, M.: The ponder policy specification language. In: Sloman, M., Lupu, E.C., Lobo, J. (eds.) POLICY 2001. LNCS, vol. 1995, pp. 18\u201338. Springer, Heidelberg (2001). https:\/\/doi.org\/10.1007\/3-540-44569-2_2"},{"key":"4_CR6","unstructured":"Ashley, P., Hada, S., Karjoth, G., Powers, C., Schunter, M.: Enterprise privacy authorization language (EPAL). IBM Research, March 2003"},{"issue":"2","key":"4_CR7","doi-asserted-by":"publisher","first-page":"187","DOI":"10.1145\/1065545.1065547","volume":"8","author":"R Bhatti","year":"2005","unstructured":"Bhatti, R., Ghafoor, A., Bertino, E., Joshi, J.B.: X-GTRBAC: an XML-based policy specification framework and architecture for enterprise-wide access control. ACM Trans. Inf. Syst. Secur. (TISSEC) 8(2), 187\u2013227 (2005)","journal-title":"ACM Trans. Inf. Syst. Secur. (TISSEC)"},{"key":"4_CR8","unstructured":"OASIS XACML Technical Committee: eXtensible access control markup language (XACML) Version 3.0. Oasis Standard, OASIS (2013). http:\/\/docs.oasis-open.org\/xacml\/3.0\/xacml-3.0-core-spec-os-en.html . Accessed 17 May 2017"},{"key":"4_CR9","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"390","DOI":"10.1007\/978-3-642-28641-4_21","volume-title":"Principles of Security and Trust","author":"J Crampton","year":"2012","unstructured":"Crampton, J., Morisset, C.: PTaCL: a language for attribute-based access control in open systems. In: Degano, P., Guttman, J.D. (eds.) POST 2012. LNCS, vol. 7215, pp. 390\u2013409. Springer, Heidelberg (2012). https:\/\/doi.org\/10.1007\/978-3-642-28641-4_21"},{"key":"4_CR10","unstructured":"Crockford, D.: JSON \u2013 The fat-free alternative to XML, vol. 2006. http:\/\/www.json.org\/fatfree.html . Accessed 17 May 2017"},{"key":"4_CR11","doi-asserted-by":"crossref","unstructured":"El-Aziz, A.A., Kannan, A.: JSON encryption. In: 2014 International Conference on Computer Communication and Informatics (ICCCI). IEEE (2014)","DOI":"10.1109\/ICCCI.2014.6921719"},{"key":"4_CR12","doi-asserted-by":"crossref","unstructured":"Griffin, L., Butler, B., de Leastar, E., Jennings, B., Botvich, D.: On the performance of access control policy evaluation. In: 2012 IEEE International Symposium on Policies for Distributed Systems and Networks (POLICY), pp. 25\u201332. IEEE (2012)","DOI":"10.1109\/POLICY.2012.15"},{"key":"4_CR13","unstructured":"W3schools: JSON vs XML. www.w3schools.com\/js\/js_json_xml.asp . Accessed 24 May 2017"},{"key":"4_CR14","unstructured":"Ferraiolo, D.F., Kuhn, D.R.: Role-based Access Controls. arXiv preprint arXiv: 0903.2171 , 12 March 2009"},{"key":"4_CR15","doi-asserted-by":"crossref","unstructured":"Hu, V.C., Ferraiolo, D., Kuhn, R., et al.: Guide to attribute based access control (ABAC) definition and considerations. NIST Special Publication 800.162 (2013)","DOI":"10.6028\/NIST.SP.800-162"},{"key":"4_CR16","unstructured":"Empower ID: Best practices in enterprise authorization: The RBAC\/ABAC hybrid approach. Empower ID, White paper (2013)"},{"issue":"3","key":"4_CR17","doi-asserted-by":"publisher","first-page":"0014","DOI":"10.1109\/MITP.2013.37","volume":"15","author":"E Coyne","year":"2013","unstructured":"Coyne, E., Weil, T.R.: ABAC and RBAC: scalable, flexible, and auditable access management. IT Prof. 15(3), 0014\u201316 (2013)","journal-title":"IT Prof."},{"key":"4_CR18","unstructured":"David, B.: JSON Profile of XACML 3.0 Version 1.0. XACML Committee Specification 01, 11 December 2014. http:\/\/docs.oasis-open.org\/xacml\/xacml-json-http\/v1.0\/cs01\/xacml-json-http-v1.0-cs01.pdf . Accessed 26 May 2017"},{"key":"4_CR19","unstructured":"Steven, D., Bernard, B., Leigh, G.: JSON-encoded ABAC (XACML) policies. FAME project of Waterford Institute of Technology. Presentation to OASIS XACML TC concerning JSON-encoded XACML policies, 30 May 2013"},{"key":"4_CR20","unstructured":"Amazon Web Services: AWS Identity and Access Management (IAM) User Guide. http:\/\/docs.aws.amazon.com\/IAM\/latest\/UserGuide\/introduction.html . Accessed 27 May 2017"},{"key":"4_CR21","unstructured":"ECMA International: ECMA-404 The JSON Data Interchange Standard. http:\/\/www.json.org\/ . Accessed 27 May 2017"},{"key":"4_CR22","doi-asserted-by":"crossref","unstructured":"Ferraiolo, D., et al.: Extensible access control markup language (XACML) and next generation access control (NGAC). In: Proceedings of the 2016 ACM International Workshop on Attribute Based Access Control. ACM (2016)","DOI":"10.1145\/2875491.2875496"},{"key":"4_CR23","unstructured":"reTHINK Project. github.com\/reTHINK-project\/ . Accessed 27 May 2017"},{"key":"4_CR24","unstructured":"reTHINK CSP Policy Engine. github.com\/reTHINK-project\/dev-msg-node-nodejs\/tree\/master\/src\/main\/components\/policyEngine . Accessed 27 May 2017"},{"key":"4_CR25","unstructured":"reTHINK Deliverable 6.4: Assessment Report, reTHINK H2020 Project"},{"key":"4_CR26","doi-asserted-by":"crossref","unstructured":"Obrsta, L., McCandlessb, D., Ferrella, D.: Fast semantic attribute-role-based access control (ARBAC) in a collaborative environment. In: 2012 8th International Conference on Collaborative Computing: Networking, Applications and Worksharing (CollaborateCom), Pittsburgh, PA, USA, 14\u201317 October 2012","DOI":"10.4108\/icst.collaboratecom.2012.250750"},{"key":"4_CR27","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"84","DOI":"10.1007\/978-3-642-33704-8_8","volume-title":"Computer Network Security","author":"X Jin","year":"2012","unstructured":"Jin, X., Sandhu, R., Krishnan, R.: RABAC: role-centric attribute-based access control. In: Kotenko, I., Skormin, V. (eds.) MMM-ACNS 2012. LNCS, vol. 7531, pp. 84\u201396. Springer, Heidelberg (2012). https:\/\/doi.org\/10.1007\/978-3-642-33704-8_8"},{"issue":"6","key":"4_CR28","doi-asserted-by":"publisher","first-page":"79","DOI":"10.1109\/MC.2010.155","volume":"43","author":"DR Kuhn","year":"2010","unstructured":"Kuhn, D.R., Coyne, E.J., Weil, T.R.: Adding attributes to role-based access control. Computer 43(6), 79\u201381 (2010)","journal-title":"Computer"},{"key":"4_CR29","doi-asserted-by":"crossref","unstructured":"Kagal, L., Finin, T., Joshi, A.: A policy language for a pervasive computing environment. In: IEEE 4th International Workshop on Proceedings of Policies for Distributed Systems and Networks, POLICY 2003. IEEE (2003)","DOI":"10.1109\/POLICY.2003.1206958"},{"key":"4_CR30","unstructured":"Hada, S., Kudo, M.: XML Access Control Language: provisional authorization for XML documents (2000)"},{"key":"4_CR31","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"16","DOI":"10.1007\/978-3-540-24747-0_2","volume-title":"Trust Management","author":"A Uszok","year":"2004","unstructured":"Uszok, A., Bradshaw, J.M., Jeffers, R.: KAoS: a policy and domain services framework for grid computing and semantic web services. In: Jensen, C., Poslad, S., Dimitrakos, T. (eds.) iTrust 2004. LNCS, vol. 2995, pp. 16\u201326. Springer, Heidelberg (2004). https:\/\/doi.org\/10.1007\/978-3-540-24747-0_2"},{"key":"4_CR32","doi-asserted-by":"crossref","unstructured":"Jajodia, S., Samarati, P., Subrahmanian, V.S.: A logical language for expressing authorizations. In: Proceedings of IEEE Symposium on Security and Privacy. IEEE (1997)","DOI":"10.1109\/SECPRI.1997.601312"},{"key":"4_CR33","unstructured":"Neuhaus, C., Polze, A., Chowdhuryy, M.M.: Survey on healthcare IT systems: standards, regulations and security. No. 45. Universit\u00e4tsverlag Potsdam (2011)"},{"key":"4_CR34","doi-asserted-by":"crossref","unstructured":"Jiang, H., Bouabdallah, A.: Towards A JSON-Based Fast Policy Evaluation Framework. Work in progress","DOI":"10.1007\/978-3-319-69459-7_2"}],"container-title":["Lecture Notes in Computer Science","Information Security Theory and Practice"],"original-title":[],"link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-319-93524-9_4","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,10,19]],"date-time":"2019-10-19T14:26:38Z","timestamp":1571495198000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-319-93524-9_4"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2018]]},"ISBN":["9783319935232","9783319935249"],"references-count":34,"URL":"https:\/\/doi.org\/10.1007\/978-3-319-93524-9_4","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2018]]}}}