{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,20]],"date-time":"2026-07-20T14:13:26Z","timestamp":1784556806381,"version":"3.55.0"},"publisher-location":"Berlin, Heidelberg","reference-count":32,"publisher":"Springer Berlin Heidelberg","isbn-type":[{"value":"9783540898610","type":"print"},{"value":"9783540898627","type":"electronic"}],"license":[{"start":{"date-parts":[[2008,1,1]],"date-time":"2008-01-01T00:00:00Z","timestamp":1199145600000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2008]]},"DOI":"10.1007\/978-3-540-89862-7_24","type":"book-chapter","created":{"date-parts":[[2008,12,3]],"date-time":"2008-12-03T09:01:00Z","timestamp":1228294860000},"page":"287-302","source":"Crossref","is-referenced-by-count":23,"title":["HyDRo \u2013 Hybrid Development of Roles"],"prefix":"10.1007","author":[{"given":"Ludwig","family":"Fuchs","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"G\u00fcnther","family":"Pernul","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","reference":[{"key":"24_CR1","volume-title":"Role-Based Access Control","author":"D.F. Ferraiolo","year":"2007","unstructured":"Ferraiolo, D.F., Kuhn, R.D., Chandramouli, R.: Role-Based Access Control. Artech House, Boston (2007)"},{"key":"24_CR2","doi-asserted-by":"publisher","first-page":"165","DOI":"10.1145\/1099435.1099472","volume-title":"Proc. of the 33rd annual ACM SIGUCCS conference on User services (SIGUCCS 2005)","author":"E.A. Larsson","year":"2005","unstructured":"Larsson, E.A.: A case study: Implementing Novell Identity Management at Drew University. In: Proc. of the 33rd annual ACM SIGUCCS conference on User services (SIGUCCS 2005), pp. 165\u2013170. ACM, New York (2005)"},{"issue":"2","key":"24_CR3","doi-asserted-by":"publisher","first-page":"165","DOI":"10.1016\/S0167-4048(01)00209-7","volume":"20","author":"G. Dhillon","year":"2001","unstructured":"Dhillon, G.: Violation of Safeguards by Trusted Personnel and Understanding Related Information Security Concerns. Computers & Security\u00a020(2), 165\u2013172 (2001)","journal-title":"Computers & Security"},{"key":"24_CR4","doi-asserted-by":"publisher","first-page":"374","DOI":"10.1109\/ARES.2007.145","volume-title":"Proc. of the 2nd Int. Conference on Availability, Reliability and Security (ARES 2007)","author":"L. Fuchs","year":"2007","unstructured":"Fuchs, L., Pernul, G.: Supporting Compliant and Secure User Handling \u2013 a Structured Approach for In-house Identity Management. In: Proc. of the 2nd Int. Conference on Availability, Reliability and Security (ARES 2007), pp. 374\u2013384. IEEE Computer Society, Los Alamitos (2007)"},{"key":"24_CR5","unstructured":"Gallaher, M.P., O\u2019Connor, A.C., Kropp, B.: The economic impact of role-based access control. Planning report 02-1, National Institute of Standards and Technology, Gaithersburg, MD (2002), \n                    \n                      http:\/\/www.nist.gov\/director\/prog-ofc\/report02-1.pdf"},{"key":"24_CR6","volume-title":"Proc. of the 17th Annual Computer Security Applications Conference (ACSAC 2001)","author":"P. Epstein","year":"2001","unstructured":"Epstein, P., Sandhu, R.: Engineering of Role\/Permission Assignments. In: Proc. of the 17th Annual Computer Security Applications Conference (ACSAC 2001). IEEE Computer Society, Washington (2001)"},{"key":"24_CR7","doi-asserted-by":"publisher","first-page":"175","DOI":"10.1145\/1266840.1266870","volume-title":"Proc. of the 12th ACM Symp. on Access Control Models and Technologies (SACMAT 2007)","author":"J. Vaidya","year":"2007","unstructured":"Vaidya, J., Atluri, V., Guo, Q.: The role mining problem: finding a minimal descriptive set of roles. In: Proc. of the 12th ACM Symp. on Access Control Models and Technologies (SACMAT 2007), pp. 175\u2013184. ACM, New York (2007)"},{"key":"24_CR8","doi-asserted-by":"publisher","first-page":"103","DOI":"10.1145\/344287.344308","volume-title":"Proc. of the 5th ACM workshop on Role-based access control","author":"H. Roeckle","year":"2000","unstructured":"Roeckle, H., Schimpf, G., Weidinger, R.: Process-oriented approach for role-finding to implement role-based security administration in a large industrial organization. In: Proc. of the 5th ACM workshop on Role-based access control, pp. 103\u2013110. ACM, New York (2000)"},{"key":"24_CR9","unstructured":"Crook, R., Ince, D., Nuseibeh, B.: Towards an Analytical Role Modelling Framework for Security Requirements (2002), \n                    \n                      http:\/\/mcs.open.ac.uk\/ban25\/papers\/refsq02.pdf"},{"key":"24_CR10","doi-asserted-by":"crossref","unstructured":"Colantonio, A., Di Pietro, R., Ocello, A.: Leveraging Lattices to Improve Role Mining. In: Proc. of the 23rd Int. Information Security Conference (SEC 2008) (2008)","DOI":"10.1007\/978-0-387-09699-5_22"},{"key":"24_CR11","unstructured":"Fuchs, L., Pernul, G.: proROLE: A Process-oriented Lifecycle Model for Role Systems. In: Proc. of the 16th European Conference on Information Systems (ECIS), Galway, Ireland (2008)"},{"key":"24_CR12","first-page":"169","volume-title":"Proc. of the 8th ACM Symp. on Access Control Models and Technologies (SACMAT 2003)","author":"D. Shin","year":"2003","unstructured":"Shin, D., Ahn, G., Cho, S., Jin, S.: On modeling system-centric information for role engineering. In: Proc. of the 8th ACM Symp. on Access Control Models and Technologies (SACMAT 2003), pp. 169\u2013178. ACM, New York (2003)"},{"key":"24_CR13","volume-title":"Proc. of the 1st ACM Workshop on Role-based access control","author":"E.J. Coyne","year":"1996","unstructured":"Coyne, E.J.: Role Engineering. In: Proc. of the 1st ACM Workshop on Role-based access control. ACM, New York (1996)"},{"issue":"2","key":"24_CR14","doi-asserted-by":"publisher","first-page":"39","DOI":"10.1109\/2.485845","volume":"29","author":"R.S. Sandhu","year":"1996","unstructured":"Sandhu, R.S., Coyne, E.J., Feinstein, H.L., Youman, C.E.: Role-Based Access Control Models. IEEE Computer\u00a029(2), 39\u201347 (1996)","journal-title":"IEEE Computer"},{"key":"24_CR15","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"280","DOI":"10.1007\/978-3-540-45221-8_24","volume-title":"\u00abUML\u00bb 2003 - The Unified Modeling Language. Modeling Languages and Applications","author":"I. Sadahiro","year":"2003","unstructured":"Sadahiro, I.: A Critique of UML\u2019s Definition of the Use-Case Class. In: Stevens, P., Whittle, J., Booch, G. (eds.) UML 2003. LNCS, vol.\u00a02863, pp. 280\u2013294. Springer, Heidelberg (2003)"},{"key":"24_CR16","first-page":"33","volume-title":"Proc. of the 7th ACM Symp. on Access Control Models and Technologies","author":"G. Neumann","year":"2002","unstructured":"Neumann, G., Strembeck, M.: A scenario-driven role engineering process for functional RBAC roles. In: Proc. of the 7th ACM Symp. on Access Control Models and Technologies, pp. 33\u201342. ACM, New York (2002)"},{"key":"24_CR17","unstructured":"Strembeck, M.: A Role Engineering Tool for Role-Based Access Control. In: Proc. of the Symp. on Requirements Engineering for Information Security (SREIS), Paris, France (2005)"},{"key":"24_CR18","doi-asserted-by":"publisher","first-page":"81","DOI":"10.1109\/ENABL.2004.9","volume-title":"Proc. of the 13th IEEE International Workshop on Enabling Technologies: Infrastructures for Collaborative Enterprises (WETICE)","author":"J. Mendling","year":"2004","unstructured":"Mendling, J., Strembeck, M., Stermsek, G., Neumann, G.: An Approach to Extract RBAC Models from BPEL4WS Processes. In: Proc. of the 13th IEEE International Workshop on Enabling Technologies: Infrastructures for Collaborative Enterprises (WETICE), pp. 81\u201386. IEEE Computer Society, Washington (2004)"},{"key":"24_CR19","first-page":"168","volume-title":"Proc. of the 10th ACM Symp. on Access Control Models and Technologies (SACMAT 2005)","author":"J. Schlegelmilch","year":"2005","unstructured":"Schlegelmilch, J., Steffens, U.: Role mining with ORCA. In: Proc. of the 10th ACM Symp. on Access Control Models and Technologies (SACMAT 2005), pp. 168\u2013176. ACM, New York (2005)"},{"key":"24_CR20","first-page":"179","volume-title":"Proc. of the 8th ACM Symp. on Access Control Models and Technologies (SACMAT 2003)","author":"M. Kuhlmann","year":"2003","unstructured":"Kuhlmann, M., Shohat, D., Schimpf, G.: Role mining - revealing business roles for security administration using data mining technology. In: Proc. of the 8th ACM Symp. on Access Control Models and Technologies (SACMAT 2003), pp. 179\u2013186. ACM, New York (2003)"},{"key":"24_CR21","first-page":"43","volume-title":"Proc. of the 7th ACM Symp. on Access Control Models and Technologies (SACMAT 2002)","author":"A. Kern","year":"2002","unstructured":"Kern, A., Kuhlmann, M., Schaad, A., Moffett, J.: Observations on the role life-cycle in the context of enterprise security management. In: Proc. of the 7th ACM Symp. on Access Control Models and Technologies (SACMAT 2002), pp. 43\u201351. ACM, New York (2002)"},{"key":"24_CR22","first-page":"144","volume-title":"Proc. of the 13th ACM Conf. on Computer and Communications Security (CCS 2006)","author":"J. Vaidya","year":"2006","unstructured":"Vaidya, J., Atluri, V., Warner, J.: RoleMiner: mining roles using subset enumeration. In: Proc. of the 13th ACM Conf. on Computer and Communications Security (CCS 2006), pp. 144\u2013153. ACM, New York (2006)"},{"key":"24_CR23","doi-asserted-by":"publisher","first-page":"2129","DOI":"10.1145\/1363686.1364198","volume-title":"Proc. of the 2008 ACM Symp. on Applied Computing","author":"A. Colantonio","year":"2008","unstructured":"Colantonio, A., Di Pietro, R., Ocello, A.: A cost-driven approach to role engineering. In: Proc. of the 2008 ACM Symp. on Applied Computing, pp. 2129\u20132136. ACM, New York (2008)"},{"key":"24_CR24","volume-title":"Proc. of the 13th ACM Symp. on Access Control Models and Technologies (SACMAT 2008)","author":"I. Molloy","year":"2008","unstructured":"Molloy, I., Chen, H., Li, T., Wang, Q., Li, N., Bertino, E., Calo, S., Lobo, J.: Mining roles with semantic meanings. In: Proc. of the 13th ACM Symp. on Access Control Models and Technologies (SACMAT 2008). ACM, New York (2008)"},{"key":"24_CR25","volume-title":"Proc. of the 13th ACM Symp. on Access Control Models and Technologies (SACMAT 2008)","author":"J. Vaidya","year":"2008","unstructured":"Vaidya, J., Atluri, V., Guo, Q., Adam, N.: Migrating to optimal RBAC with minimal perturbation. In: Proc. of the 13th ACM Symp. on Access Control Models and Technologies (SACMAT 2008). ACM, New York (2008)"},{"key":"24_CR26","doi-asserted-by":"publisher","first-page":"1295","DOI":"10.1145\/1066677.1066971","volume-title":"Proc. of the 2005 ACM Symposium on Applied Computing","author":"C. Braun","year":"2005","unstructured":"Braun, C., Wortmann, F., Hafner, M., Winter, R.: Method Construction \u2013 A Core Approach to Organizational Engineering. In: Proc. of the 2005 ACM Symposium on Applied Computing, pp. 1295\u20131299. ACM, New York (2005)"},{"key":"24_CR27","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-52405-9","volume-title":"Das CC RIM-Referenzmodell f\u00fcr den Entwurf von betrieblichen, transaktionsorientierten Informationssystemen","author":"T. Gutzwiller","year":"1994","unstructured":"Gutzwiller, T.: Das CC RIM-Referenzmodell f\u00fcr den Entwurf von betrieblichen, transaktionsorientierten Informationssystemen. Physica-Verlag, Heidelberg (1994)"},{"key":"24_CR28","doi-asserted-by":"publisher","first-page":"275","DOI":"10.1016\/0950-5849(95)01059-9","volume":"38","author":"S. Brinkkemper","year":"1996","unstructured":"Brinkkemper, S.: Method engineering: engineering of information systems development methods and tools. Information and Software Technology\u00a038, 275\u2013280 (1996)","journal-title":"Information and Software Technology"},{"key":"24_CR29","doi-asserted-by":"crossref","unstructured":"Fuchs, L., Preis, A.: BusiROLE: A Model for Integrating Business Roles into Identity Management. In: Proc of the 5th Int. Conference on Trust, Privacy, and Security in Digital Business (TrustBus), Torino, Italy (2008)","DOI":"10.1007\/978-3-540-85735-8_13"},{"key":"24_CR30","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-56927-2","volume-title":"Self-Organizing Maps","author":"T. Kohonen","year":"2001","unstructured":"Kohonen, T.: Self-Organizing Maps. Springer, Berlin (2001)"},{"key":"24_CR31","unstructured":"The SOMLib Digital Library Project, Information & Software Engineering Group, Vienna University of Technology, \n                    \n                      http:\/\/www.ifs.tuwien.ac.at\/~andi\/somlib\/index.html"},{"key":"24_CR32","unstructured":"Pries-Heje, J., Baskerville, R., Venable, J.: Strategies for Design Science Research Evaluation. In: Proc. of the 16th European Conference on Information Systems (ECIS), Galway, Ireland (2008)"}],"container-title":["Lecture Notes in Computer Science","Information Systems Security"],"original-title":[],"link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-540-89862-7_24","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,3,4]],"date-time":"2019-03-04T08:20:01Z","timestamp":1551687601000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-540-89862-7_24"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2008]]},"ISBN":["9783540898610","9783540898627"],"references-count":32,"URL":"https:\/\/doi.org\/10.1007\/978-3-540-89862-7_24","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2008]]}}}