{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,4]],"date-time":"2026-08-04T04:12:31Z","timestamp":1785816751847,"version":"3.56.0"},"reference-count":53,"publisher":"Association for Computing Machinery (ACM)","issue":"1","license":[{"start":{"date-parts":[[2011,5,1]],"date-time":"2011-05-01T00:00:00Z","timestamp":1304208000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/100000006","name":"Office of Naval Research","doi-asserted-by":"publisher","award":["N00014-01-1-0968N00014-09-1-0652"],"award-info":[{"award-number":["N00014-01-1-0968N00014-09-1-0652"]}],"id":[{"id":"10.13039\/100000006","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100006602","name":"Air Force Research Laboratory","doi-asserted-by":"publisher","award":["F9550-06-0019"],"award-info":[{"award-number":["F9550-06-0019"]}],"id":[{"id":"10.13039\/100006602","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100000143","name":"Division of Computing and Communication Foundations","doi-asserted-by":"publisher","award":["04301610964409CCF-0424422"],"award-info":[{"award-number":["04301610964409CCF-0424422"]}],"id":[{"id":"10.13039\/100000143","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100000181","name":"Air Force Office of Scientific Research","doi-asserted-by":"publisher","award":["F9550-06-0019"],"award-info":[{"award-number":["F9550-06-0019"]}],"id":[{"id":"10.13039\/100000181","id-type":"DOI","asserted-by":"publisher"}]},{"name":"NICECAP","award":["FA8750-07-2-0037"],"award-info":[{"award-number":["FA8750-07-2-0037"]}]},{"DOI":"10.13039\/100000001","name":"National Science Foundation","doi-asserted-by":"publisher","award":["04301610964409CCF-0424422"],"award-info":[{"award-number":["04301610964409CCF-0424422"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Inf. Syst. Secur."],"published-print":{"date-parts":[[2011,5]]},"abstract":"<jats:p>Nexus Authorization Logic (NAL) provides a principled basis for specifying and reasoning about credentials and authorization policies. It extends prior access control logics that are based on \u201csays\u201d and \u201cspeaks for\u201d operators. NAL enables authorization of access requests to depend on (i) the source or pedigree of the requester, (ii) the outcome of any mechanized analysis of the requester, or (iii) the use of trusted software to encapsulate or modify the requester. To illustrate the convenience and expressive power of this approach to authorization, a suite of document-viewer applications was implemented to run on the Nexus operating system. One of the viewers enforces policies that concern the integrity of excerpts that a document contains; another viewer enforces confidentiality policies specified by labels tagging blocks of text.<\/jats:p>","DOI":"10.1145\/1952982.1952990","type":"journal-article","created":{"date-parts":[[2011,6,6]],"date-time":"2011-06-06T11:51:38Z","timestamp":1307361098000},"page":"1-28","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":38,"title":["Nexus authorization logic (NAL)"],"prefix":"10.1145","volume":"14","author":[{"given":"Fred B.","family":"Schneider","sequence":"first","affiliation":[{"name":"Cornell University, Ithaca, NY"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Kevin","family":"Walsh","sequence":"additional","affiliation":[{"name":"Cornell University, Ithaca, NY"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Emin G\u00fcn","family":"Sirer","sequence":"additional","affiliation":[{"name":"Cornell University, Ithaca, NY"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2011,6,6]]},"reference":[{"key":"e_1_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.entcs.2007.02.002"},{"key":"e_1_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-70525-3_9"},{"key":"e_1_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1145\/155183.155225"},{"key":"e_1_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1145\/319709.319718"},{"key":"e_1_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1145\/1357054.1357143"},{"key":"e_1_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1007\/11556992_31"},{"key":"e_1_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2005.9"},{"key":"e_1_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1109\/CSF.2007.18"},{"key":"e_1_2_1_10_1","volume-title":"Proceedings of the European Symposium on Research in Computer Security. 203--218","author":"Becker M. Y.","unstructured":"Becker , M. Y. and Nanz , S . 2007. A logic for state-modifying authorization policies . In Proceedings of the European Symposium on Research in Computer Security. 203--218 . Becker, M. Y. and Nanz, S. 2007. A logic for state-modifying authorization policies. In Proceedings of the European Symposium on Research in Computer Security. 203--218."},{"key":"e_1_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.5555\/1009380.1009672"},{"key":"e_1_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1145\/224056.224077"},{"key":"e_1_2_1_13_1","volume-title":"Secure Internet Programming: Security Issues for Mobile and Distributed Objects. Lecture Notes in Computer Science","volume":"1603","author":"Blaze M.","unstructured":"Blaze , M. , Feigenbaum , J. , Ioannidis , J. , and Keromytis , A. D . 1999. The role of trust management in distributed systems security . Secure Internet Programming: Security Issues for Mobile and Distributed Objects. Lecture Notes in Computer Science , vol. 1603 . Springer, Berlin, Germany, 185--210. Blaze, M., Feigenbaum, J., Ioannidis, J., and Keromytis, A. D. 1999. The role of trust management in distributed systems security. Secure Internet Programming: Security Issues for Mobile and Distributed Objects. Lecture Notes in Computer Science, vol. 1603. Springer, Berlin, Germany, 185--210."},{"key":"e_1_2_1_14_1","volume-title":"Proceedings of the Security Protocols Workshop. 59--63","author":"Blaze M.","unstructured":"Blaze , M. , Feigenbaum , J. , and Keromytis , A. D . 1998. KeyNote: Trust management for public-key infrastructures . In Proceedings of the Security Protocols Workshop. 59--63 . Blaze, M., Feigenbaum, J., and Keromytis, A. D. 1998. KeyNote: Trust management for public-key infrastructures. In Proceedings of the Security Protocols Workshop. 59--63."},{"key":"e_1_2_1_15_1","volume-title":"Proceedings of the IEEE Conference on Security and Privacy. IEEE Computer Society Press","author":"Blaze M.","unstructured":"Blaze , M. , Feigenbaum , J. , and Lacy , J . 1996. Decentralized trust management . In Proceedings of the IEEE Conference on Security and Privacy. IEEE Computer Society Press , Los Alamitos, CA, 164--173. Blaze, M., Feigenbaum, J., and Lacy, J. 1996. Decentralized trust management. In Proceedings of the IEEE Conference on Security and Privacy. IEEE Computer Society Press, Los Alamitos, CA, 164--173."},{"key":"e_1_2_1_16_1","doi-asserted-by":"crossref","unstructured":"Blaze M. Feigenbaum J. and Strauss M. 1998. Compliance checking in the PolicyMaker trust management system. In Financial Cryptography. Springer-Verlag Berlin Germany 254--274. Blaze M. Feigenbaum J. and Strauss M. 1998. Compliance checking in the PolicyMaker trust management system. In Financial Cryptography. Springer-Verlag Berlin Germany 254--274.","DOI":"10.1007\/BFb0055488"},{"key":"e_1_2_1_17_1","volume-title":"Proceedings of the Network and Distributed System Security Symposium. Internet Society","author":"Bowers K. D.","unstructured":"Bowers , K. D. , Bauer , L. , Garg , D. , Pfenning , F. , and Reiter , M. K . 2007. Consumable credentials in logic-based access-control systems . In Proceedings of the Network and Distributed System Security Symposium. Internet Society , Reston, VA, 143--157. Bowers, K. D., Bauer, L., Garg, D., Pfenning, F., and Reiter, M. K. 2007. Consumable credentials in logic-based access-control systems. In Proceedings of the Network and Distributed System Security Symposium. Internet Society, Reston, VA, 143--157."},{"key":"e_1_2_1_18_1","unstructured":"Cameron K. 2005. The laws of identity. http:\/\/www.identitybloc.com\/. Cameron K. 2005. The laws of identity. http:\/\/www.identitybloc.com\/."},{"key":"e_1_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.5555\/275079.275092"},{"key":"e_1_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1145\/360051.360056"},{"key":"e_1_2_1_21_1","first-page":"28","article-title":"Trusted computer security evaluation criteria (TCSEC)","volume":"5200","author":"Department of Defense.","year":"1985","unstructured":"Department of Defense. 1985 . Trusted computer security evaluation criteria (TCSEC) , DoD 5200 . 28 -STD. http:\/\/csrc.nist.gov\/publications\/history\/dod85.pdf. Department of Defense. 1985. Trusted computer security evaluation criteria (TCSEC), DoD 5200.28-STD. http:\/\/csrc.nist.gov\/publications\/history\/dod85.pdf.","journal-title":"DoD"},{"key":"e_1_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.5555\/829514.830540"},{"key":"e_1_2_1_23_1","doi-asserted-by":"crossref","unstructured":"Ellison C. Frantz B. Lampson B. Rivest R. Thomas B. and Ylonen T. 1999. SPKI certificate theory. Internet Engineering Task Force. RFC 2693. www.ietf.org. Ellison C. Frantz B. Lampson B. Rivest R. Thomas B. and Ylonen T. 1999. SPKI certificate theory. Internet Engineering Task Force. RFC 2693. www.ietf.org.","DOI":"10.17487\/rfc2693"},{"key":"e_1_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1145\/335169.335201"},{"key":"e_1_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1007\/11863908_19"},{"key":"e_1_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1109\/CSFW.2006.18"},{"key":"e_1_2_1_27_1","volume-title":"Proceedings of the Usenix Security Symposium.","author":"Goldberg I.","unstructured":"Goldberg , I. , Wagner , D. , Thomas , R. , and Brewer , E. A . 1996. A secure environment for untrusted helper applications: Confining the wily hacker . In Proceedings of the Usenix Security Symposium. Goldberg, I., Wagner, D., Thomas, R., and Brewer, E. A. 1996. A secure environment for untrusted helper applications: Confining the wily hacker. In Proceedings of the Usenix Security Symposium."},{"key":"e_1_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1145\/74850.74870"},{"key":"e_1_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.1109\/CSF.2008.8"},{"key":"e_1_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1145\/1134744.1134748"},{"key":"e_1_2_1_32_1","unstructured":"Howell J. and Kotz D. 2000. End-to-end authorization. In Operating System Design &amp; Implementation. USENIX Association Berkeley CA 151--164. Howell J. and Kotz D. 2000. End-to-end authorization. In Operating System Design &amp; Implementation. USENIX Association Berkeley CA 151--164."},{"key":"e_1_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.5555\/882495.884431"},{"key":"e_1_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1145\/138873.138874"},{"key":"e_1_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1145\/1315245.1315299"},{"key":"e_1_2_1_36_1","doi-asserted-by":"publisher","DOI":"10.1145\/605434.605438"},{"key":"e_1_2_1_37_1","volume-title":"Proceedings of the IEEE Conference on Security and Privacy. IEEE Computer Society Press","author":"Li N.","unstructured":"Li , N. , Mitchell , J. C. , and Winsborough , W. H . 2002. Design of a role-based trust-management framework . In Proceedings of the IEEE Conference on Security and Privacy. IEEE Computer Society Press , Los Alamitos, CA, 114--130. Li, N., Mitchell, J. C., and Winsborough, W. H. 2002. Design of a role-based trust-management framework. In Proceedings of the IEEE Conference on Security and Privacy. IEEE Computer Society Press, Los Alamitos, CA, 114--130."},{"key":"e_1_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.1145\/263699.263712"},{"key":"e_1_2_1_39_1","volume-title":"Web services security: SOAP message security 1.0 (WS-Security","author":"Organization for the Advancement of Structured Information Standards (OASIS). 2004.","year":"2004","unstructured":"Organization for the Advancement of Structured Information Standards (OASIS). 2004. Web services security: SOAP message security 1.0 (WS-Security 2004 ). http:\/\/docs.oasis-open.org\/wss\/2004\/01\/oasis-200401-wss-soap-message-security-1.0.pdf. Organization for the Advancement of Structured Information Standards (OASIS). 2004. Web services security: SOAP message security 1.0 (WS-Security 2004). http:\/\/docs.oasis-open.org\/wss\/2004\/01\/oasis-200401-wss-soap-message-security-1.0.pdf."},{"key":"e_1_2_1_40_1","volume-title":"Proceedings of the International Conference on Automated Deduction. Springer-Verlag","author":"Pfenning F.","unstructured":"Pfenning , F. and Sch\u00fcrmann , C . 1999. System description: Twelf\u2014a meta-logical framework for deductive systems . In Proceedings of the International Conference on Automated Deduction. Springer-Verlag , Berlin, Germany, 202--206. Pfenning, F. and Sch\u00fcrmann, C. 1999. System description: Twelf\u2014a meta-logical framework for deductive systems. In Proceedings of the International Conference on Automated Deduction. Springer-Verlag, Berlin, Germany, 202--206."},{"key":"e_1_2_1_41_1","doi-asserted-by":"publisher","DOI":"10.1007\/11737414_10"},{"key":"e_1_2_1_42_1","unstructured":"Rivest R. and Lampson B. 1996. SDSI\u2014a simple distributed security infrastructure. http:\/\/theory.lcs.mit.edu\/cis\/sdsi.html. Rivest R. and Lampson B. 1996. SDSI\u2014a simple distributed security infrastructure. http:\/\/theory.lcs.mit.edu\/cis\/sdsi.html."},{"key":"e_1_2_1_43_1","doi-asserted-by":"publisher","DOI":"10.1109\/PROC.1975.9939"},{"key":"e_1_2_1_44_1","doi-asserted-by":"publisher","DOI":"10.1109\/2.241422"},{"key":"e_1_2_1_45_1","unstructured":"Schneider F. B. Walsh K. and Sirer E. G. 2009. Nexus authorization logic (NAL): Design rationale and applications. Tech. rep. Cornell University Ithaca NY http:\/\/hdl.handle.net\/1813\/13679. Schneider F. B. Walsh K. and Sirer E. G. 2009. Nexus authorization logic (NAL): Design rationale and applications. Tech. rep. Cornell University Ithaca NY http:\/\/hdl.handle.net\/1813\/13679."},{"key":"e_1_2_1_46_1","doi-asserted-by":"publisher","DOI":"10.1145\/1095810.1118613"},{"key":"e_1_2_1_47_1","doi-asserted-by":"publisher","DOI":"10.1145\/319151.319165"},{"key":"e_1_2_1_48_1","volume-title":"Proceedings of the World Congress on Formal Methods in the Development of Computing Systems. Springer-Verlag","author":"Syverson P. F.","unstructured":"Syverson , P. F. and Stubblebine , S. G . 1999. Group principals and the formalization of anonymity . In Proceedings of the World Congress on Formal Methods in the Development of Computing Systems. Springer-Verlag , Berlin, Germany, 814--833. Syverson, P. F. and Stubblebine, S. G. 1999. Group principals and the formalization of anonymity. In Proceedings of the World Congress on Formal Methods in the Development of Computing Systems. Springer-Verlag, Berlin, Germany, 814--833."},{"key":"e_1_2_1_49_1","series-title":"Studies in Logic and the Foundations of Mathematics Series","volume-title":"Constructivism in Mathematics","author":"Troelstra A. S.","unstructured":"Troelstra , A. S. and van Dalen , D. 1988. Constructivism in Mathematics . Studies in Logic and the Foundations of Mathematics Series , vol. 121 , J. Barwise et al., Eds. Elsevier , Amsterdam, The Netherlands. Troelstra, A. S. and van Dalen, D. 1988. Constructivism in Mathematics. Studies in Logic and the Foundations of Mathematics Series, vol. 121, J. Barwise et al., Eds. Elsevier, Amsterdam, The Netherlands."},{"key":"e_1_2_1_50_1","volume-title":"Logic and Structure","author":"van Dalen D.","unstructured":"van Dalen , D. 2004. Logic and Structure , 4 th ed. Springer , Berlin, Germany . van Dalen, D. 2004. Logic and Structure, 4th ed. Springer, Berlin, Germany.","edition":"4"},{"key":"e_1_2_1_51_1","doi-asserted-by":"publisher","DOI":"10.1145\/168619.168635"},{"key":"e_1_2_1_53_1","doi-asserted-by":"publisher","DOI":"10.1145\/1478559.1478574"},{"key":"e_1_2_1_54_1","doi-asserted-by":"publisher","DOI":"10.1145\/174613.174614"},{"key":"e_1_2_1_55_1","doi-asserted-by":"crossref","unstructured":"Wobber T. Rodeheffer T. L. and Terry D. B. 2009. Policy-based access control for weakly consistent replication. Tech. rep. MSR--TR--2009--15. Microsoft Research Redmonds WA. Wobber T. Rodeheffer T. L. and Terry D. B. 2009. Policy-based access control for weakly consistent replication. Tech. rep. MSR--TR--2009--15. Microsoft Research Redmonds WA.","DOI":"10.1145\/1755913.1755943"},{"key":"e_1_2_1_56_1","unstructured":"World Wide Web Consortium. 2007. Web services policy 1.5 - framework (WS-Policy). http:\/\/www.w3.org\/TR\/ws-policy\/. World Wide Web Consortium. 2007. Web services policy 1.5 - framework (WS-Policy). http:\/\/www.w3.org\/TR\/ws-policy\/."}],"container-title":["ACM Transactions on Information and System Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1952982.1952990","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/1952982.1952990","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T10:59:41Z","timestamp":1750244381000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1952982.1952990"}},"subtitle":["Design rationale and applications"],"short-title":[],"issued":{"date-parts":[[2011,5]]},"references-count":53,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2011,5]]}},"alternative-id":["10.1145\/1952982.1952990"],"URL":"https:\/\/doi.org\/10.1145\/1952982.1952990","relation":{},"ISSN":["1094-9224","1557-7406"],"issn-type":[{"value":"1094-9224","type":"print"},{"value":"1557-7406","type":"electronic"}],"subject":[],"published":{"date-parts":[[2011,5]]},"assertion":[{"value":"2009-09-01","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2009-12-01","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2011-06-06","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}