{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,24]],"date-time":"2026-07-24T06:07:37Z","timestamp":1784873257353,"version":"3.55.0"},"reference-count":43,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[2019,5,21]],"date-time":"2019-05-21T00:00:00Z","timestamp":1558396800000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"},{"start":{"date-parts":[[2019,5,21]],"date-time":"2019-05-21T00:00:00Z","timestamp":1558396800000},"content-version":"vor","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"funder":[{"DOI":"10.13039\/100010665","name":"H2020 Marie Sk\u0142odowska-Curie Actions","doi-asserted-by":"publisher","award":["675320"],"award-info":[{"award-number":["675320"]}],"id":[{"id":"10.13039\/100010665","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100007601","name":"Horizon 2020","doi-asserted-by":"publisher","award":["830929"],"award-info":[{"award-number":["830929"]}],"id":[{"id":"10.13039\/501100007601","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100011033","name":"Agencia Estatal de Investigaci\u00f3n","doi-asserted-by":"publisher","award":["TIN2016-79095-C2-1-R"],"award-info":[{"award-number":["TIN2016-79095-C2-1-R"]}],"id":[{"id":"10.13039\/501100011033","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Int. J. Inf. Secur."],"published-print":{"date-parts":[[2020,2]]},"DOI":"10.1007\/s10207-019-00438-x","type":"journal-article","created":{"date-parts":[[2019,5,22]],"date-time":"2019-05-22T11:15:59Z","timestamp":1558523759000},"page":"111-127","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":31,"title":["TrUStAPIS: a trust requirements elicitation method for IoT"],"prefix":"10.1007","volume":"19","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-3035-3774","authenticated-orcid":false,"given":"Davide","family":"Ferraris","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Carmen","family":"Fernandez-Gago","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2019,5,21]]},"reference":[{"issue":"9","key":"438_CR1","doi-asserted-by":"publisher","first-page":"51","DOI":"10.1109\/MC.2011.291","volume":"44","author":"R Roman","year":"2011","unstructured":"Roman, R., Najera, P., Lopez, J.: Securing the internet of things. Computer 44(9), 51\u201358 (2011)","journal-title":"Computer"},{"key":"438_CR2","doi-asserted-by":"publisher","first-page":"72","DOI":"10.1016\/j.ins.2017.02.039","volume":"396","author":"C Fernandez-Gago","year":"2017","unstructured":"Fernandez-Gago, C., Moyano, F., Lopez, J.: Modelling trust dynamics in the internet of things. Inf. Sci. 396, 72\u201382 (2017). \nhttps:\/\/doi.org\/10.1016\/j.ins.2017.02.039","journal-title":"Inf. Sci."},{"key":"438_CR3","unstructured":"Haskins, C., Forsberg, K., Krueger, M., Walden, D., Hamelin, D.: Systems engineering handbook, INCOSE (2006)"},{"issue":"4","key":"438_CR4","doi-asserted-by":"publisher","first-page":"153","DOI":"10.1016\/j.csi.2010.01.006","volume":"32","author":"D Mellado","year":"2010","unstructured":"Mellado, D., Blanco, C., Sanchez, L.E., Fernandez-Medina, E.: A systematic review of security requirements engineering. Comput. Stand. Interfaces 32(4), 153\u2013165 (2010)","journal-title":"Comput. Stand. Interfaces"},{"issue":"3","key":"438_CR5","doi-asserted-by":"publisher","first-page":"203","DOI":"10.1023\/B:AGNT.0000018806.20944.ef","volume":"8","author":"P Bresciani","year":"2004","unstructured":"Bresciani, P., Perini, A., Giorgini, P., Giunchiglia, F., Mylopoulos, J.: Tropos: an agent-oriented software development methodology. Auton. Agents Multi-Agent Syst. 8(3), 203\u2013236 (2004)","journal-title":"Auton. Agents Multi-Agent Syst."},{"key":"438_CR6","doi-asserted-by":"publisher","first-page":"147","DOI":"10.1007\/978-3-642-05183-8_6","volume-title":"Advances in Intelligent Information Systems","author":"Fabio Massacci","year":"2010","unstructured":"Massacci, F., Mylopoulos, J., Zannone, N.: Security requirements engineering: the SI* modeling language and the secure tropos methodology. In: Advances in Intelligent Information Systems. Springer, Berlin, pp. 147\u2013174 (2010)"},{"issue":"02","key":"438_CR7","doi-asserted-by":"publisher","first-page":"285","DOI":"10.1142\/S0218194007003240","volume":"17","author":"H Mouratidis","year":"2007","unstructured":"Mouratidis, H., Giorgini, P.: Secure tropos: a security-oriented extension of the tropos methodology. Int. J. Softw. Eng. Knowl. Eng. 17(02), 285\u2013309 (2007)","journal-title":"Int. J. Softw. Eng. Knowl. Eng."},{"key":"438_CR8","unstructured":"Yu, E.S.-K.: Modelling strategic relationships for process reengineering, Ph.D. thesis, University of Toronto (1995)"},{"key":"438_CR9","doi-asserted-by":"publisher","first-page":"123","DOI":"10.1016\/j.datak.2015.07.007","volume":"98","author":"E Paja","year":"2015","unstructured":"Paja, E., Dalpiaz, F., Giorgini, P.: Modelling and reasoning about security requirements in socio-technical systems. Data Knowl. Eng. 98, 123\u2013143 (2015)","journal-title":"Data Knowl. Eng."},{"issue":"7","key":"438_CR10","doi-asserted-by":"publisher","first-page":"94","DOI":"10.1145\/1139922.1139924","volume":"49","author":"LJ Hoffman","year":"2006","unstructured":"Hoffman, L.J., Lawson-Jenkins, K., Blum, J.: Trust beyond security: an expanded trust model. Commun. ACM 49(7), 94\u2013101 (2006)","journal-title":"Commun. ACM"},{"key":"438_CR11","unstructured":"Pavlidis, M.: Designing for trust. CAiSE (Doctoral Consortium), pp. 3\u201314 (2011)"},{"key":"438_CR12","doi-asserted-by":"crossref","unstructured":"Rios, R., Fernandez-Gago, C., Lopez, J.: Modelling privacy-aware trust negotiations. Comput. Secur. (2017)","DOI":"10.1016\/j.cose.2017.09.015"},{"key":"438_CR13","doi-asserted-by":"crossref","unstructured":"Ferraris, D., Fernandez-Gago, C., Lopez, J.: A trust by design framework for the internet of things. In: NTMS\u20192018\u2014Security Track (NTMS 2018 Security Track). France, Paris (2018)","DOI":"10.1109\/NTMS.2018.8328674"},{"key":"438_CR14","doi-asserted-by":"publisher","first-page":"120","DOI":"10.1016\/j.jnca.2014.01.014","volume":"42","author":"Z Yan","year":"2014","unstructured":"Yan, Z., Zhang, P., Vasilakos, A.V.: A survey on trust management for internet of things. J. Netw. Comput. Appl. 42, 120\u2013134 (2014)","journal-title":"J. Netw. Comput. Appl."},{"issue":"2","key":"438_CR15","doi-asserted-by":"publisher","first-page":"618","DOI":"10.1016\/j.dss.2005.05.019","volume":"43","author":"A J\u00f8sang","year":"2007","unstructured":"J\u00f8sang, A., Ismail, R., Boyd, C.: A survey of trust and reputation systems for online service provision. Decis. Support Syst. 43(2), 618\u2013644 (2007)","journal-title":"Decis. Support Syst."},{"key":"438_CR16","unstructured":"McKnight, D.H., Chervany, N.L.: The meanings of trust. Technical Report MISRC Working Paper Series 96-04 (1996)"},{"issue":"6","key":"438_CR17","doi-asserted-by":"publisher","first-page":"2225","DOI":"10.19026\/rjaset.5.4776","volume":"5","author":"R Baharuddin","year":"2013","unstructured":"Baharuddin, R., Singh, D., Razali, R.: Usability dimensions for mobile applications: a review. Res. J. Appl. Sci. Eng. Technol. 5(6), 2225\u20132231 (2013)","journal-title":"Res. J. Appl. Sci. Eng. Technol."},{"key":"438_CR18","doi-asserted-by":"publisher","first-page":"430","DOI":"10.1007\/978-3-642-14478-3_43","volume-title":"Recent Trends in Network Security and Applications","author":"Parikshit Mahalle","year":"2010","unstructured":"Mahalle, P., Babar, S., Prasad, N. R., Prasad, R.: Identity management framework towards internet of things (IoT): roadmap and key challenges. In: International Conference on Network Security and Applications, Springer, Berlin, pp. 430\u2013439 (2010)"},{"key":"438_CR19","doi-asserted-by":"publisher","first-page":"98","DOI":"10.1007\/978-3-319-46598-2_7","volume-title":"Security and Trust Management","author":"Ruben Rios","year":"2016","unstructured":"Rios, R., Fernandez-Gago, C., Lopez, J.: Privacy-aware trust negotiation. In: International Workshop on Security and Trust Management. Springer, Berlin, pp. 98\u2013105 (2016)"},{"key":"438_CR20","first-page":"219","volume-title":"Lecture Notes in Business Information Processing","author":"Orestis Mavropoulos","year":"2016","unstructured":"Mavropoulos, O., Mouratidis, H., Fish, A., Panaousis, E., Kalloniatis, C.: Apparatus: reasoning about security requirements in the internet of things. In: International Conference on Advanced Information Systems Engineering, Springer, Berlin, pp. 219\u2013230 (2016)"},{"key":"438_CR21","unstructured":"IEEE Computer Society: Software Engineering Standards Committee. IEEE-SA Standards Board. IEEE Recommended Practice for Software Requirements Specifications. Institute of Electrical and Electronics Engineers (1998)"},{"issue":"3","key":"438_CR22","first-page":"353","volume":"11","author":"A Alonso-Nogueira","year":"2017","unstructured":"Alonso-Nogueira, A., Estevez-Fernandez, H., Garcia, I.: Jrem: an approach for formalising models in the requirements phase with JSON and NoSQL databases. World Acad. Sci. Eng. Technol. Int. J. Comput. Electr. Autom. Control Inf. Eng. 11(3), 353\u2013358 (2017)","journal-title":"World Acad. Sci. Eng. Technol. Int. J. Comput. Electr. Autom. Control Inf. Eng."},{"key":"438_CR23","first-page":"430","volume-title":"Social Media: The Good, the Bad, and the Ugly","author":"Wafa Abdelghani","year":"2016","unstructured":"Abdelghani, W., Zayani, C. A., Amous, I., Sedes, F.: Trust management in social internet of things: a survey. In: Conference on e-Business, e-Services and e-Society. Springer, Berlin, pp. 430\u2013441 (2016)"},{"key":"438_CR24","first-page":"1","volume-title":"Computer Security \u2014 ESORICS 94","author":"Thomas Beth","year":"1994","unstructured":"Beth, T., Borcherding, M., Klein, B.: Valuation of trust in open networks. In: European Symposium on Research in Computer Security. Springer, Berlin, pp. 1\u201318 (1994)"},{"key":"438_CR25","doi-asserted-by":"crossref","unstructured":"Chang, J., Wang, H., Gang, Y.: A dynamic trust metric for p2p systems. In: 2006 Fifth International Conference on Grid and Cooperative Computing Workshops, IEEE, pp. 117\u2013120 (2006)","DOI":"10.1109\/GCCW.2006.5"},{"key":"438_CR26","doi-asserted-by":"publisher","first-page":"171","DOI":"10.1007\/3-540-62494-5_16","volume-title":"Security Protocols","author":"Bruce Christianson","year":"1997","unstructured":"Christianson, B., Harbison, W. S.: Why isn\u2019t trust transitive? In: International Workshop on Security Protocols. Springer, Berlin, pp. 171\u2013176 (1996)"},{"issue":"4","key":"438_CR27","doi-asserted-by":"publisher","first-page":"2","DOI":"10.1109\/COMST.2000.5340804","volume":"3","author":"T Grandison","year":"2000","unstructured":"Grandison, T., Sloman, M.: A survey of trust in internet applications. IEEE Commun. Surv. Tutor. 3(4), 2\u201316 (2000)","journal-title":"IEEE Commun. Surv. Tutor."},{"key":"438_CR28","unstructured":"Marsh, S.P.: Formalising trust as a computational concept, Ph.D. thesis, Department of Computing Science and Mathematics, University of Stirling (1994)"},{"issue":"5","key":"438_CR29","doi-asserted-by":"publisher","first-page":"1253","DOI":"10.1109\/TKDE.2013.105","volume":"26","author":"M Nitti","year":"2014","unstructured":"Nitti, M., Girau, R., Atzori, L.: Trustworthiness management in the social internet of things. IEEE Trans. Knowl. Data Eng. 26(5), 1253\u20131266 (2014)","journal-title":"IEEE Trans. Knowl. Data Eng."},{"key":"438_CR30","doi-asserted-by":"publisher","first-page":"290","DOI":"10.4018\/978-1-59904-804-8.ch013","volume-title":"Computer Security, Privacy and Politics","author":"Zheng Yan","year":"2008","unstructured":"Yan, Z., Holtmanns, S.: Trust modeling and management: from social trust to digital trust. IGI Global, pp. 290\u2013323 (2008)"},{"key":"438_CR31","doi-asserted-by":"crossref","unstructured":"Mahmoud, R., Yousuf, T., Aloul, F., Zualkernan, I.: Internet of things (IoT) security: current status, challenges and prospective measures. In: 2015 10th International Conference for Internet Technology and Secured Transactions (ICITST), pp. 336\u2013341 (2015)","DOI":"10.1109\/ICITST.2015.7412116"},{"issue":"7","key":"438_CR32","first-page":"1","volume":"111","author":"MU Farooq","year":"2015","unstructured":"Farooq, M.U., Waseem, M., Khairi, A., Mazhar, S.: A critical analysis on the security concerns of internet of things (IoT). Int. J. Comput. Appl. 111(7), 1\u20136 (2015)","journal-title":"Int. J. Comput. Appl."},{"key":"438_CR33","doi-asserted-by":"publisher","first-page":"163","DOI":"10.1007\/978-3-642-40403-0_8","volume-title":"Enabling Things to Talk","author":"Martin Bauer","year":"2013","unstructured":"Bauer, M., Boussard, M., Bui, N., De Loof, J., Magerkurth, C., Meissner, S., Walewski, J.W.: IoT reference architecture. In: Enabling Things to Talk, pp. 163\u2013211. Springer, Berlin (2013)"},{"key":"438_CR34","unstructured":"Pfitzmann, A., Hansen, M.: A terminology for talking about privacy by data minimization: anonymity, unlinkability, undetectability, unobservability, pseudonymity, and identity management (2010)"},{"key":"438_CR35","unstructured":"Ligett, K., Neel, S., Roth, A., Waggoner, B., Wu, S.Z.: Accuracy first: selecting a differential privacy level for accuracy constrained erm. In: Advances in Neural Information Processing Systems, pp. 2566\u20132576 (2017)"},{"issue":"2","key":"438_CR36","doi-asserted-by":"publisher","first-page":"99","DOI":"10.1109\/MSP.2015.39","volume":"13","author":"M Lesk","year":"2015","unstructured":"Lesk, M.: Safety risks-human error or mechanical failure?: Lessons from railways. IEEE Secur. Priv. 13(2), 99\u2013102 (2015)","journal-title":"IEEE Secur. Priv."},{"key":"438_CR37","doi-asserted-by":"crossref","unstructured":"Singh, S., Singh, N.: Internet of things (IoT): security challenges, business opportunities and reference architecture for E-commerce. In: 2015 International Conference on Green Computing and Internet of Things (ICGCIoT), pp. 1577\u20131581 (2015)","DOI":"10.1109\/ICGCIoT.2015.7380718"},{"key":"438_CR38","doi-asserted-by":"crossref","unstructured":"Gou, Q., Yan, L., Liu, Y., Li, Y.: Construction and strategies in IoT security system. In: 2013 IEEE International Conference on Green Computing and Communications and IEEE Internet of Things and IEEE Cyber, Physical and Social Computing (pp. 1129\u20131132) (2013)","DOI":"10.1109\/GreenCom-iThings-CPSCom.2013.195"},{"key":"438_CR39","doi-asserted-by":"crossref","unstructured":"Ferraris, D., Fernandez-Gago, C., Daniel, J., Lopez, J.: A segregated architecture for a trust-based network of internet of things. In: 2019 16th IEEE Annual Consumer Communications and Networking Conference (CCNC), pp. 1\u20136 (2019)","DOI":"10.1109\/CCNC.2019.8651703"},{"key":"438_CR40","volume-title":"A Practical Guide to SysML: The Systems Modeling Language","author":"S Friedenthal","year":"2014","unstructured":"Friedenthal, S., Moore, A., Steiner, R.: A Practical Guide to SysML: The Systems Modeling Language. Morgan Kaufmann, Los Altos (2014)"},{"key":"438_CR41","doi-asserted-by":"crossref","unstructured":"Kissel, R.L., Stine, K.M., Scholl, M.A., Rossman, H., Fahlsing, J., Gulick, J.: Security considerations in the system development life cycle (No. Special Publication (NIST SP)-800-64 Rev 2) (2008)","DOI":"10.6028\/NIST.SP.800-64r2"},{"key":"438_CR42","doi-asserted-by":"crossref","unstructured":"Geisser, M., Hildenbrand, T.: A method for collaborative requirements elicitation and decision-supported requirements analysis. In: IFIP World Computer Congress, TC 2 (pp. 108\u2013122). Springer, Boston (2006)","DOI":"10.1007\/978-0-387-34831-5_9"},{"key":"438_CR43","doi-asserted-by":"crossref","unstructured":"Saaty, T.L.: Analytic hierarchy process. Encyclopedia of Biostatistics, 1, (2005)","DOI":"10.1002\/0470011815.b2a4a002"}],"container-title":["International Journal of Information Security"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s10207-019-00438-x.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/article\/10.1007\/s10207-019-00438-x\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s10207-019-00438-x.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2020,5,19]],"date-time":"2020-05-19T23:22:46Z","timestamp":1589930566000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/s10207-019-00438-x"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2019,5,21]]},"references-count":43,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2020,2]]}},"alternative-id":["438"],"URL":"https:\/\/doi.org\/10.1007\/s10207-019-00438-x","relation":{},"ISSN":["1615-5262","1615-5270"],"issn-type":[{"value":"1615-5262","type":"print"},{"value":"1615-5270","type":"electronic"}],"subject":[],"published":{"date-parts":[[2019,5,21]]},"assertion":[{"value":"21 May 2019","order":1,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Compliance with ethical standards"}},{"value":"All authors declare that they have no conflict of interest.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Conflict of interest"}},{"value":"This article does not contain any studies with human participants or animals performed by any of the authors.","order":3,"name":"Ethics","group":{"name":"EthicsHeading","label":"Ethical approval"}}]}}