{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,3,26]],"date-time":"2025-03-26T07:22:36Z","timestamp":1742973756328,"version":"3.40.3"},"publisher-location":"Berlin, Heidelberg","reference-count":34,"publisher":"Springer Berlin Heidelberg","isbn-type":[{"type":"print","value":"9783642191244"},{"type":"electronic","value":"9783642191251"}],"license":[{"start":{"date-parts":[[2011,1,1]],"date-time":"2011-01-01T00:00:00Z","timestamp":1293840000000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2011]]},"DOI":"10.1007\/978-3-642-19125-1_16","type":"book-chapter","created":{"date-parts":[[2011,1,24]],"date-time":"2011-01-24T10:55:45Z","timestamp":1295866545000},"page":"209-220","source":"Crossref","is-referenced-by-count":1,"title":["Authorization Enforcement Usability Case Study"],"prefix":"10.1007","author":[{"given":"Steffen","family":"Bartsch","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","reference":[{"key":"16_CR1","doi-asserted-by":"crossref","unstructured":"Ahn, G.J., Zhang, L., Shin, D., Chu, B.: Authorization management for role-based collaboration. In: IEEE International Conference on Systems, Man and Cybernetics, vol.\u00a05, pp. 4128\u20134134 (October 2003)","DOI":"10.1109\/ICSMC.2003.1245633"},{"key":"16_CR2","unstructured":"Anderson, J.P.: Computer security technology planning study. Tech. Rep. ESD-TR-73-51, Deputy for Command and Management Systems, L.G. Hanscom Field, Bedford, MA (October 1972)"},{"key":"16_CR3","volume-title":"Fourth International Workshop on Secure Software Engineering (SecSE 2010)","author":"S. Bartsch","year":"2010","unstructured":"Bartsch, S.: Supporting authorization policy modification in agile development of Web applications. In: Fourth International Workshop on Secure Software Engineering (SecSE 2010). IEEE Computer Society, Los Alamitos (2010)"},{"key":"16_CR4","volume-title":"3rd International Workshop on Trusted Collaboration (TrustCol-2008)","author":"S. Bartsch","year":"2009","unstructured":"Bartsch, S., Sohr, K., Bormann, C.: Supporting Agile Development of Authorization Rules for SME Applications. In: 3rd International Workshop on Trusted Collaboration (TrustCol-2008). Springer, Heidelberg (2009)"},{"issue":"1","key":"16_CR5","doi-asserted-by":"publisher","first-page":"65","DOI":"10.1145\/300830.300837","volume":"2","author":"E. Bertino","year":"1999","unstructured":"Bertino, E., Ferrari, E., Atluri, V.: The specification and enforcement of authorization constraints in workflow management systems. ACM Trans. Inf. Syst. Secur.\u00a02(1), 65\u2013104 (1999)","journal-title":"ACM Trans. Inf. Syst. Secur."},{"key":"16_CR6","doi-asserted-by":"crossref","unstructured":"Beznosov, K., Deng, Y., Blakley, B., Barkley, J.: A resource access decision service for corba-based distributed systems. In: Computer Security Applications Conference, Annual, p. 310 (1999)","DOI":"10.1109\/CSAC.1999.816041"},{"issue":"9","key":"16_CR7","doi-asserted-by":"publisher","first-page":"835","DOI":"10.1002\/spe.691","volume":"35","author":"S. Brostoff","year":"2005","unstructured":"Brostoff, S., Sasse, M.A., Chadwick, D.W., Cunningham, J., Mbanaso, U.M., Otenko, S.: \u2019R-What?\u2019 development of a role-based access control policy-writing tool for e-scientists. Softw., Pract. Exper.\u00a035(9), 835\u2013856 (2005)","journal-title":"Softw., Pract. Exper."},{"key":"16_CR8","doi-asserted-by":"publisher","DOI":"10.1017\/CBO9780511814570","volume-title":"Research methods for human-computer interaction","author":"P. Cairns","year":"2008","unstructured":"Cairns, P., Cox, A.L.: Research methods for human-computer interaction. Cambridge Univ. Press, Cambridge (2008)"},{"key":"16_CR9","unstructured":"Clarke, S.: Measuring API usability. Dr. Dobb\u2019s Journal (May 2004)"},{"key":"16_CR10","doi-asserted-by":"crossref","unstructured":"Consel, C., Marlet, R.: Architecture software using: A methodology for language development. In: Palamidessi, C., Glaser, H., Meinke, K. (eds.) ALP 1998 and PLILP 1998. LNCS, vol.\u00a01490, pp. 170\u2013194. Springer, Heidelberg (1998)","DOI":"10.1007\/BFb0056614"},{"key":"16_CR11","unstructured":"De Win, B., Piessens, F., Joosen, W., Verhanneman, T.: On the importance of the separation-of-concerns principle in secure software engineering. In: ACSA Workshop on the Application of Engineering Principles to System Security Design (2003)"},{"key":"16_CR12","unstructured":"Ferraiolo, D., Kuhn, R.: Role-based access controls. In: 15th NIST-NCSC National Computer Security Conference, pp. 554\u2013563 (1992)"},{"key":"16_CR13","doi-asserted-by":"crossref","unstructured":"Goguen, J.A., Meseguer, J.: Security policies and security models. In: IEEE Symposium on Security and Privacy, p. 11 (1982)","DOI":"10.1109\/SP.1982.10014"},{"key":"16_CR14","volume-title":"Inside Java(TM) 2 Platform Security: Architecture, API Design, and Implementation","author":"L. Gong","year":"2003","unstructured":"Gong, L., Ellison, G.: Inside Java(TM) 2 Platform Security: Architecture, API Design, and Implementation. Pearson Education, London (2003)"},{"issue":"8","key":"16_CR15","doi-asserted-by":"publisher","first-page":"461","DOI":"10.1145\/360303.360333","volume":"19","author":"M.A. Harrison","year":"1976","unstructured":"Harrison, M.A., Ruzzo, W.L., Ullman, J.D.: Protection in operating systems. ACM Commun.\u00a019(8), 461\u2013471 (1976)","journal-title":"ACM Commun."},{"key":"16_CR16","doi-asserted-by":"publisher","first-page":"296","DOI":"10.1007\/0-387-33406-8_25","volume-title":"Security and Privacy in Dynamic Environments (SEC)","author":"A. Herzog","year":"2006","unstructured":"Herzog, A., Shahmehri, N.: A usability study of security policy management. In: Security and Privacy in Dynamic Environments (SEC), vol.\u00a0201, pp. 296\u2013306. Springer, Heidelberg (2006)"},{"key":"16_CR17","first-page":"77","volume-title":"Proceedings of the 4th Symposium on Usable Privacy and Security, SOUPS 2008","author":"P. Inglesant","year":"2008","unstructured":"Inglesant, P., Sasse, M.A., Chadwick, D., Shi, L.L.: Expressions of expertness: the virtuous circle of natural language for access control policy specification. In: Proceedings of the 4th Symposium on Usable Privacy and Security, SOUPS 2008, pp. 77\u201388. ACM, New York (2008)"},{"issue":"2","key":"16_CR18","doi-asserted-by":"publisher","first-page":"175","DOI":"10.1145\/996943.996944","volume":"7","author":"T. Jaeger","year":"2004","unstructured":"Jaeger, T., Edwards, A., Zhang, X.: Consistency analysis of authorization hook placement in the linux security modules framework. ACM Trans. Inf. Syst. Secur.\u00a07(2), 175\u2013205 (2004)","journal-title":"ACM Trans. Inf. Syst. Secur."},{"key":"16_CR19","doi-asserted-by":"crossref","unstructured":"Johnson, M., Bellovin, S., Reeder, R., Schechter, S.: Laissez-faire file sharing. In: New Security Paradigms Workshop 2009 (2009)","DOI":"10.1145\/1719030.1719032"},{"key":"16_CR20","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"220","DOI":"10.1007\/BFb0053381","volume-title":"ECOOP \u201997 - Object-Oriented Programming","author":"G. Kiczales","year":"1997","unstructured":"Kiczales, G., Lamping, J., Mendhekar, A., Maeda, C., Lopes, C., Loingtier, J.M., Irwin, J.: Aspect-oriented programming. In: Liu, Y., Auletta, V. (eds.) ECOOP 1997. LNCS, vol.\u00a01241, pp. 220\u2013242. Springer, Heidelberg (1997)"},{"key":"16_CR21","first-page":"344","volume-title":"Proceedings of the 29th International Conference on Software Engineering, ICSE 2007","author":"A.J. Ko","year":"2007","unstructured":"Ko, A.J., DeLine, R., Venolia, G.: Information needs in collocated software development teams. In: Proceedings of the 29th International Conference on Software Engineering, ICSE 2007, pp. 344\u2013353. IEEE Computer Society, Washington, DC (2007)"},{"issue":"9","key":"16_CR22","doi-asserted-by":"publisher","first-page":"1060","DOI":"10.1109\/PROC.1980.11805","volume":"68","author":"M.M. Lehman","year":"1980","unstructured":"Lehman, M.M.: Programs, life cycles, and laws of software evolution. Proceedings of the IEEE\u00a068(9), 1060\u20131076 (1980)","journal-title":"Proceedings of the IEEE"},{"key":"16_CR23","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"449","DOI":"10.1007\/3-540-48743-3_21","volume-title":"ECOOP \u201999 - Object-Oriented Programming","author":"R. Pandey","year":"1999","unstructured":"Pandey, R., Hashii, B.: Providing fine-grained access control for java programs. In: Guerraoui, R. (ed.) ECOOP 1999. LNCS, vol.\u00a01628, pp. 449\u2013473. Springer, Heidelberg (1999)"},{"issue":"2","key":"16_CR24","doi-asserted-by":"publisher","first-page":"237","DOI":"10.1006\/ijhc.2000.0410","volume":"54","author":"J.F. Pane","year":"2001","unstructured":"Pane, J.F., Ratanamahatana, C.A., Myers, B.A.: Studying the language and structure in non-programmers\u2019 solutions to programming problems. International Journal of Human-Computer Studies\u00a054(2), 237\u2013264 (2001)","journal-title":"International Journal of Human-Computer Studies"},{"key":"16_CR25","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"141","DOI":"10.1007\/978-3-540-74800-7_11","volume-title":"Human-Computer Interaction \u2013 INTERACT 2007","author":"R.W. Reeder","year":"2007","unstructured":"Reeder, R.W., Karat, C.M., Karat, J., Brodie, C.: Usability challenges in security and privacy policy-authoring interfaces. In: Baranauskas, M.C.C., Palanque, P.A., Abascal, J., Barbosa, S.D.J. (eds.) INTERACT 2007. LNCS, vol.\u00a04663, pp. 141\u2013155. Springer, Heidelberg (2007)"},{"issue":"7","key":"16_CR26","doi-asserted-by":"publisher","first-page":"101","DOI":"10.1145\/792704.792706","volume":"46","author":"J. Rees","year":"2003","unstructured":"Rees, J., Bandyopadhyay, S., Spafford, E.H.: Pfires: a policy framework for information security. ACM Commun.\u00a046(7), 101\u2013106 (2003)","journal-title":"ACM Commun."},{"key":"16_CR27","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"137","DOI":"10.1007\/3-540-45608-2_3","volume-title":"Foundations of Security Analysis and Design","author":"P. Samarati","year":"2001","unstructured":"Samarati, P., de Capitani di Vimercati, S.: Access control: Policies, models, and mechanisms. In: Focardi, R., Gorrieri, R. (eds.) FOSAD 2000. LNCS, vol.\u00a02171, pp. 137\u2013196. Springer, Heidelberg (2001)"},{"key":"16_CR28","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"70","DOI":"10.1007\/978-3-642-11747-3_6","volume-title":"Engineering Secure Software and Systems","author":"K. Sohr","year":"2010","unstructured":"Sohr, K., Berger, B.: Idea: Towards architecture-centric security analysis of software. In: Massacci, F., Wallach, D., Zannone, N. (eds.) ESSoS 2010. LNCS, vol.\u00a05965, pp. 70\u201378. Springer, Heidelberg (2010)"},{"key":"16_CR29","volume-title":"Proceedings of the International Conference on Availability, Reliability and Security (ARES 2010)","author":"B. Stepien","year":"2010","unstructured":"Stepien, B., Matwin, S., Felty, A.: Strategies for reducing risks of inconsistencies in access control policies. In: Proceedings of the International Conference on Availability, Reliability and Security (ARES 2010). IEEE Computer Society, Los Alamitos (2010)"},{"key":"16_CR30","unstructured":"Stylos, J., Clarke, S., Myers, B.: Comparing API design choices with usability studies: A case study and future directions. In: Proceedings of the 18th Workshop of the Psychology of Programming Interest Group (2006)"},{"issue":"8","key":"16_CR31","doi-asserted-by":"publisher","first-page":"44","DOI":"10.1109\/2.402076","volume":"28","author":"A. von Mayrhauser","year":"1995","unstructured":"von Mayrhauser, A., Vans, A.M.: Program comprehension during software maintenance and evolution. Computer\u00a028(8), 44\u201355 (1995)","journal-title":"Computer"},{"key":"16_CR32","unstructured":"Whitten, A.: Making Security Usable. Ph.D. thesis, CMU, cMU-CS-04-135 (2004)"},{"key":"16_CR33","doi-asserted-by":"crossref","first-page":"149","DOI":"10.1145\/775412.775431","volume-title":"Proceedings of the Eighth ACM Symposium on Access Control Models and Technologies, SACMAT 2003","author":"X. Zhang","year":"2003","unstructured":"Zhang, X., Oh, S., Sandhu, R.: PBDM: a flexible delegation model in RBAC. In: Proceedings of the Eighth ACM Symposium on Access Control Models and Technologies, SACMAT 2003, pp. 149\u2013157. ACM, New York (2003)"},{"key":"16_CR34","volume-title":"IEEE Symposium on Security and Privacy","author":"M.E. Zurko","year":"1999","unstructured":"Zurko, M.E., Simon, R., Sanfilippo, T.: A user-centered, modular authorization service built on an RBAC foundation. In: IEEE Symposium on Security and Privacy. IEEE Computer Society, Los Alamitos (1999)"}],"container-title":["Lecture Notes in Computer Science","Engineering Secure Software and Systems"],"original-title":[],"link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-642-19125-1_16","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,3,2]],"date-time":"2025-03-02T03:31:11Z","timestamp":1740886271000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-642-19125-1_16"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2011]]},"ISBN":["9783642191244","9783642191251"],"references-count":34,"URL":"https:\/\/doi.org\/10.1007\/978-3-642-19125-1_16","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2011]]}}}