{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,31]],"date-time":"2026-07-31T08:51:18Z","timestamp":1785487878726,"version":"3.56.0"},"reference-count":64,"publisher":"Association for Computing Machinery (ACM)","issue":"3","license":[{"start":{"date-parts":[[2011,11,1]],"date-time":"2011-11-01T00:00:00Z","timestamp":1320105600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/100000181","name":"Air Force Office of Scientific Research","doi-asserted-by":"publisher","award":["FA9550-08-1-0265"],"award-info":[{"award-number":["FA9550-08-1-0265"]}],"id":[{"id":"10.13039\/100000181","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100000143","name":"Division of Computing and Communication Foundations","doi-asserted-by":"publisher","award":["IIS-0814027IIS-0814027CCR-0325951CCF-0524010CNS-0964710CNS-0716750"],"award-info":[{"award-number":["IIS-0814027IIS-0814027CCR-0325951CCF-0524010CNS-0964710CNS-0716750"]}],"id":[{"id":"10.13039\/100000143","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100000001","name":"National Science Foundation","doi-asserted-by":"publisher","award":["IIS-0814027IIS-0814027CCR-0325951CCF-0524010CNS-0964710CNS-0716750"],"award-info":[{"award-number":["IIS-0814027IIS-0814027CCR-0325951CCF-0524010CNS-0964710CNS-0716750"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100000144","name":"Division of Computer and Network Systems","doi-asserted-by":"publisher","award":["IIS-0814027IIS-0814027CCR-0325951CCF-0524010CNS-0964710CNS-0716750"],"award-info":[{"award-number":["IIS-0814027IIS-0814027CCR-0325951CCF-0524010CNS-0964710CNS-0716750"]}],"id":[{"id":"10.13039\/100000144","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100004926","name":"Texas Higher Education Coordinating Board","doi-asserted-by":"publisher","award":["010115-0037-2007"],"award-info":[{"award-number":["010115-0037-2007"]}],"id":[{"id":"10.13039\/100004926","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100000145","name":"Division of Information and Intelligent Systems","doi-asserted-by":"publisher","award":["IIS-0814027IIS-0814027CCR-0325951CCF-0524010CNS-0964710CNS-0716750"],"award-info":[{"award-number":["IIS-0814027IIS-0814027CCR-0325951CCF-0524010CNS-0964710CNS-0716750"]}],"id":[{"id":"10.13039\/100000145","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Inf. Syst. Secur."],"published-print":{"date-parts":[[2011,11]]},"abstract":"<jats:p>Group-Centric Secure Information Sharing (g-SIS) envisions bringing users and objects together in a group to facilitate agile sharing of information brought in from external sources as well as creation of new information within the group. We expect g-SIS to be orthogonal and complementary to authorization systems deployed within participating organizations. The metaphors \u201csecure meeting room\u201d and \u201csubscription service\u201d characterize the g-SIS approach.<\/jats:p>\n          <jats:p>\n            The focus of this article is on developing the foundations of isolated g-SIS models. Groups are\n            <jats:italic>isolated<\/jats:italic>\n            in the sense that membership of a user or an object in a group does not affect their authorizations in other groups. Present contributions include the following: formal specification of core properties that at once help to characterize the family of g-SIS models and provide a \u201csanity check\u201d for full policy specifications; informal discussion of policy design decisions that differentiate g-SIS policies from one another with respect to the authorization semantics of group operations; formalization and verification of a specific member of the family of g-SIS models; demonstration that the core properties are logically consistent and mutually independent; and identification of several directions for future extensions.\n          <\/jats:p>\n          <jats:p>The formalized specification is highly abstract. Besides certain well-formedness requirements that specify, for instance, a user cannot leave a group unless she is a member, it constrains only whether user-level read and write operations are authorized and it does so solely in terms of the history of group operations; join and leave for users and add, create, and remove for objects. This makes temporal logic one of the few formalisms in which the specification can be clearly and concisely expressed. The specification serves as a reference point that is the first step in deriving authorization-system component specifications from which a programmer with little security expertise could implement a high-assurance enforcement system for the specified policy.<\/jats:p>","DOI":"10.1145\/2043621.2043623","type":"journal-article","created":{"date-parts":[[2011,12,6]],"date-time":"2011-12-06T19:05:23Z","timestamp":1323198323000},"page":"1-29","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":18,"title":["Group-Centric Secure Information-Sharing Models for Isolated Groups"],"prefix":"10.1145","volume":"14","author":[{"given":"Ram","family":"Krishnan","sequence":"first","affiliation":[{"name":"University of Texas at San Antonio"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Jianwei","family":"Niu","sequence":"additional","affiliation":[{"name":"University of Texas at San Antonio"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Ravi","family":"Sandhu","sequence":"additional","affiliation":[{"name":"University of Texas at San Antonio"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"William H.","family":"Winsborough","sequence":"additional","affiliation":[{"name":"University of Texas at San Antonio"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2011,11]]},"reference":[{"key":"e_1_2_2_1_1","volume-title":"Proceedings of the National Computer Security Conference.","author":"Abrams M.","unstructured":"Abrams , M. , Heaney , J. , King , O. , LaPadula , L. , Lazear , M. , and Olson , I . 1991. Generalized framework for access control: Towards prototyping the ORGCON Policy . In Proceedings of the National Computer Security Conference. Abrams, M., Heaney, J., King, O., LaPadula, L., Lazear, M., and Olson, I. 1991. Generalized framework for access control: Towards prototyping the ORGCON Policy. In Proceedings of the National Computer Security Conference."},{"key":"e_1_2_2_2_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.jnca.2005.08.004"},{"key":"e_1_2_2_3_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-30555-2_43"},{"key":"e_1_2_2_4_1","volume-title":"Proceedings of the IEEE Symposium on Security and Privacy (SP\u201995)","author":"Badger L.","unstructured":"Badger , L. , Sterne , D. F. , Sherman , D. L. , Walker , K. M. , and Haghighat , S. A . 1995. Practical domain and type enforcement for UNIX . In Proceedings of the IEEE Symposium on Security and Privacy (SP\u201995) . IEEE Computer Society, Los Alamitos, CA, 66. Badger, L., Sterne, D. F., Sherman, D. L., Walker, K. M., and Haghighat, S. A. 1995. Practical domain and type enforcement for UNIX. In Proceedings of the IEEE Symposium on Security and Privacy (SP\u201995). IEEE Computer Society, Los Alamitos, CA, 66."},{"key":"e_1_2_2_5_1","doi-asserted-by":"crossref","unstructured":"Ballardie A. 1996. Scalable multicast key distribution. http:\/\/rsync.tools.ietf.org\/html.rfc1949. Ballardie A. 1996. Scalable multicast key distribution. http:\/\/rsync.tools.ietf.org\/html.rfc1949.","DOI":"10.17487\/rfc1949"},{"key":"e_1_2_2_6_1","volume-title":"Proceedings of the Symposium on Network and Distributed System Security.","author":"Ballardie T.","unstructured":"Ballardie , T. and Crowcroft , J . 1995. Multicast-specific security threats and counter-measures . In Proceedings of the Symposium on Network and Distributed System Security. Ballardie, T. and Crowcroft, J. 1995. Multicast-specific security threats and counter-measures. In Proceedings of the Symposium on Network and Distributed System Security."},{"key":"e_1_2_2_7_1","doi-asserted-by":"publisher","DOI":"10.1145\/1179601.1179609"},{"key":"e_1_2_2_8_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2006.32"},{"key":"e_1_2_2_9_1","volume-title":"Secure computer systems: Unified exposition and multics interpretation. Tech. rep. ESD-TR-75-306","author":"Bell D.","unstructured":"Bell , D. and La Padula , L. 1975. Secure computer systems: Unified exposition and multics interpretation. Tech. rep. ESD-TR-75-306 , MITRE Corp . Bell, D. and La Padula, L. 1975. Secure computer systems: Unified exposition and multics interpretation. Tech. rep. ESD-TR-75-306, MITRE Corp."},{"key":"e_1_2_2_10_1","doi-asserted-by":"publisher","DOI":"10.5555\/1754868.1754932"},{"key":"e_1_2_2_11_1","doi-asserted-by":"publisher","DOI":"10.1145\/191177.191202"},{"key":"e_1_2_2_12_1","doi-asserted-by":"publisher","DOI":"10.1145\/501978.501979"},{"key":"e_1_2_2_13_1","doi-asserted-by":"publisher","DOI":"10.1145\/1463342.1463343"},{"key":"e_1_2_2_14_1","doi-asserted-by":"publisher","DOI":"10.1109\/32.31350"},{"key":"e_1_2_2_15_1","doi-asserted-by":"crossref","unstructured":"Cimatti A. Clarke E. Giunchiglia F. and Roveri M. 2000. NuSMV: A new symbolic model checker. J. Softw. Tools Tech. Transfer 410--425. Cimatti A. Clarke E. Giunchiglia F. and Roveri M. 2000. NuSMV: A new symbolic model checker. J. Softw. Tools Tech. Transfer 410--425.","DOI":"10.1007\/s100090050046"},{"key":"e_1_2_2_16_1","doi-asserted-by":"publisher","DOI":"10.1145\/507711.507727"},{"key":"e_1_2_2_17_1","volume-title":"Broadcast Encryption. In Proceedings of Crypto\u201993","author":"Fiat A.","unstructured":"Fiat , A. and Naor , M . 1994 . Broadcast Encryption. In Proceedings of Crypto\u201993 . 480--491. Fiat, A. and Naor, M. 1994. Broadcast Encryption. In Proceedings of Crypto\u201993. 480--491."},{"key":"e_1_2_2_18_1","volume-title":"Proceedings of the 22nd International Conference on Distributed Computing Systems (ICDCS\u201902)","author":"Freudenthal E.","unstructured":"Freudenthal , E. , Pesin , T. , Port , L. , Keenan , E. , and Karamcheti , V . 2002. drbac: Distributed role-based access control for dynamic coalition environments . In Proceedings of the 22nd International Conference on Distributed Computing Systems (ICDCS\u201902) . IEEE Computer Society, Los Alamitos, CA, 411. Freudenthal, E., Pesin, T., Port, L., Keenan, E., and Karamcheti, V. 2002. drbac: Distributed role-based access control for dynamic coalition environments. In Proceedings of the 22nd International Conference on Distributed Computing Systems (ICDCS\u201902). IEEE Computer Society, Los Alamitos, CA, 411."},{"key":"e_1_2_2_19_1","volume-title":"Proceedings of the USENIX Security Symposium.","author":"Gong L.","year":"1996","unstructured":"Gong , L. 1996 . Enclaves: Enabling secure collaboration over the internet . In Proceedings of the USENIX Security Symposium. Gong, L. 1996. Enclaves: Enabling secure collaboration over the internet. In Proceedings of the USENIX Security Symposium."},{"key":"e_1_2_2_20_1","volume-title":"Proceedings of the 12th National Computer Security Conference. 296--304","author":"Graubart R.","year":"1989","unstructured":"Graubart , R. 1989 . On the need for a third form of access control . In Proceedings of the 12th National Computer Security Conference. 296--304 . Graubart, R. 1989. On the need for a third form of access control. In Proceedings of the 12th National Computer Security Conference. 296--304."},{"key":"e_1_2_2_21_1","volume-title":"RFC","author":"Harney H.","year":"2094","unstructured":"Harney , H. , Muckenhirn , C. , and Rivers , T . 1997. Group key management protocol (GKMP) architecture. Tech. rep ., RFC 2094 , SPARTA Inc. Harney, H., Muckenhirn, C., and Rivers, T. 1997. Group key management protocol (GKMP) architecture. Tech. rep., RFC 2094, SPARTA Inc."},{"key":"e_1_2_2_22_1","doi-asserted-by":"publisher","DOI":"10.1145\/360303.360333"},{"key":"e_1_2_2_23_1","doi-asserted-by":"publisher","DOI":"10.1145\/501963.501966"},{"key":"e_1_2_2_24_1","doi-asserted-by":"publisher","DOI":"10.1109\/TKDE.2005.1"},{"key":"e_1_2_2_25_1","doi-asserted-by":"publisher","DOI":"10.1109\/ENABL.2004.4"},{"key":"e_1_2_2_26_1","volume-title":"Proceedings of the 22nd International Conference on Distributed Computing Systems. 429","author":"Khurana H.","unstructured":"Khurana , H. , Gligor , V. , and Linn , J . 2002. Reasoning about joint administration of access policies for coalition resources . In Proceedings of the 22nd International Conference on Distributed Computing Systems. 429 . Khurana, H., Gligor, V., and Linn, J. 2002. Reasoning about joint administration of access policies for coalition resources. In Proceedings of the 22nd International Conference on Distributed Computing Systems. 429."},{"key":"e_1_2_2_27_1","doi-asserted-by":"publisher","DOI":"10.1145\/352600.352638"},{"key":"e_1_2_2_28_1","doi-asserted-by":"publisher","DOI":"10.1145\/1266840.1266863"},{"key":"e_1_2_2_29_1","doi-asserted-by":"publisher","DOI":"10.1145\/1533057.1533111"},{"key":"e_1_2_2_30_1","volume-title":"Proceedings of IEEE International Conference on Collaborative Computing.","author":"Krishnan R.","unstructured":"Krishnan , R. , Sandhu , R. , Niu , J. , and Winsborough , W . 2009b. Towards a framework for group-centric secure collaboration . In Proceedings of IEEE International Conference on Collaborative Computing. Krishnan, R., Sandhu, R., Niu, J., and Winsborough, W. 2009b. Towards a framework for group-centric secure collaboration. In Proceedings of IEEE International Conference on Collaborative Computing."},{"key":"e_1_2_2_31_1","doi-asserted-by":"publisher","DOI":"10.1145\/1542207.1542227"},{"key":"e_1_2_2_32_1","unstructured":"Krishnan R. Niu J. Sandhu R. and Winsborough W. 2010. Model checking code for proofs of small carrier cases. http:\/\/profsandhu.com\/ram_krishnan\/tissec_sacmat\/index.html. Krishnan R. Niu J. Sandhu R. and Winsborough W. 2010. Model checking code for proofs of small carrier cases. http:\/\/profsandhu.com\/ram_krishnan\/tissec_sacmat\/index.html."},{"key":"e_1_2_2_33_1","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.1977.229904"},{"key":"e_1_2_2_34_1","doi-asserted-by":"publisher","DOI":"10.1145\/362375.362389"},{"key":"e_1_2_2_35_1","volume-title":"Proceedings of the IEEE Symposium on Security and Privacy.","author":"Li N.","unstructured":"Li , N. , Mitchell , J. C. , and Winsborough , W. H . 2002. Design of a role-based trust-management framework . In Proceedings of the IEEE Symposium on Security and Privacy. Li, N., Mitchell, J. C., and Winsborough, W. H. 2002. Design of a role-based trust-management framework. In Proceedings of the IEEE Symposium on Security and Privacy."},{"key":"e_1_2_2_36_1","doi-asserted-by":"publisher","DOI":"10.1145\/322017.322025"},{"key":"e_1_2_2_37_1","volume-title":"Proceedings of the IEEE Symposium on Security and Privacy. 190--200","author":"McCollum C.","unstructured":"McCollum , C. , Messing , J. , and Notargiacomo , L . 1990. Beyond the pale of MAC and DAC: Defining new forms of access control . In Proceedings of the IEEE Symposium on Security and Privacy. 190--200 . McCollum, C., Messing, J., and Notargiacomo, L. 1990. Beyond the pale of MAC and DAC: Defining new forms of access control. In Proceedings of the IEEE Symposium on Security and Privacy. 190--200."},{"key":"e_1_2_2_38_1","doi-asserted-by":"publisher","DOI":"10.1145\/263105.263179"},{"key":"e_1_2_2_39_1","volume-title":"Proceedings of the International Workshop on Databases and Expert System Applications.","author":"Mont M. C.","unstructured":"Mont , M. C. , Pearson , S. , and Bramhall , P . 2003. Towards accountable management of identity and privacy: Sticky policies and enforceable tracing services . In Proceedings of the International Workshop on Databases and Expert System Applications. Mont, M. C., Pearson, S., and Bramhall, P. 2003. Towards accountable management of identity and privacy: Sticky policies and enforceable tracing services. In Proceedings of the International Workshop on Databases and Expert System Applications."},{"key":"e_1_2_2_40_1","unstructured":"ODRL. 2005. The open digital rights language initiative. www.odrl.net. ODRL . 2005. The open digital rights language initiative. www.odrl.net."},{"key":"e_1_2_2_41_1","doi-asserted-by":"publisher","DOI":"10.1145\/507711.507726"},{"key":"e_1_2_2_42_1","doi-asserted-by":"publisher","DOI":"10.1109\/SFCS.1977.32"},{"key":"e_1_2_2_43_1","doi-asserted-by":"publisher","DOI":"10.1145\/937503.937506"},{"key":"e_1_2_2_44_1","doi-asserted-by":"publisher","DOI":"10.1109\/PROC.1975.9939"},{"key":"e_1_2_2_45_1","doi-asserted-by":"publisher","DOI":"10.1145\/361011.361067"},{"key":"e_1_2_2_46_1","doi-asserted-by":"publisher","DOI":"10.1145\/42282.42286"},{"key":"e_1_2_2_47_1","doi-asserted-by":"publisher","DOI":"10.1145\/42186.42187"},{"key":"e_1_2_2_48_1","doi-asserted-by":"publisher","DOI":"10.5555\/882488.884182"},{"key":"e_1_2_2_49_1","doi-asserted-by":"publisher","DOI":"10.1145\/270152.270163"},{"key":"e_1_2_2_50_1","doi-asserted-by":"publisher","DOI":"10.4108\/ICST.COLLABORATECOM2009.8382"},{"key":"e_1_2_2_51_1","volume-title":"Proceedings of the IEEE Symposium on Security and Privacy.","author":"Sandhu R. S.","unstructured":"Sandhu , R. S. and Share , M. E . 1986. Some owner based schemes with dynamic groups in the schematic protection model . In Proceedings of the IEEE Symposium on Security and Privacy. Sandhu, R. S. and Share, M. E. 1986. Some owner based schemes with dynamic groups in the schematic protection model. In Proceedings of the IEEE Symposium on Security and Privacy."},{"key":"e_1_2_2_52_1","doi-asserted-by":"publisher","DOI":"10.1109\/2.485845"},{"key":"e_1_2_2_53_1","doi-asserted-by":"publisher","DOI":"10.1145\/300830.300839"},{"key":"e_1_2_2_54_1","doi-asserted-by":"publisher","DOI":"10.1145\/1128817.1128820"},{"key":"e_1_2_2_55_1","volume-title":"Proceedings of the 5th International Conference, on Mathematical Methods, Models, and Architectures for Computer Network Security (MMM-ACNS\u201910)","author":"Sandhu R.","unstructured":"Sandhu , R. , Krishnan , R. , Niu , J. , and Winsborough , W . 2010. Group-centric models for secure and agile information sharing . In Proceedings of the 5th International Conference, on Mathematical Methods, Models, and Architectures for Computer Network Security (MMM-ACNS\u201910) . Springer. Sandhu, R., Krishnan, R., Niu, J., and Winsborough, W. 2010. Group-centric models for secure and agile information sharing. In Proceedings of the 5th International Conference, on Mathematical Methods, Models, and Architectures for Computer Network Security (MMM-ACNS\u201910). Springer."},{"key":"e_1_2_2_56_1","doi-asserted-by":"publisher","DOI":"10.1145\/501963.501964"},{"key":"e_1_2_2_57_1","doi-asserted-by":"publisher","DOI":"10.1023\/A:1008268610932"},{"key":"e_1_2_2_58_1","unstructured":"TCG. 2007. TCG specification architecture overview. http:\/\/www.trustedcomputinggroup.org. TCG . 2007. TCG specification architecture overview. http:\/\/www.trustedcomputinggroup.org."},{"key":"e_1_2_2_59_1","doi-asserted-by":"publisher","DOI":"10.1145\/1266840.1266877"},{"key":"e_1_2_2_60_1","doi-asserted-by":"publisher","DOI":"10.5555\/1488734.1490083"},{"key":"e_1_2_2_61_1","unstructured":"Wikipedia. 2009. Analog hole. Wikipedia . 2009. Analog hole."},{"key":"e_1_2_2_62_1","doi-asserted-by":"publisher","DOI":"10.1109\/90.836475"},{"key":"e_1_2_2_63_1","unstructured":"XrML. 2001. eXtensible rights Markup Language. www.xrml.org. XrML . 2001. eXtensible rights Markup Language. www.xrml.org."},{"key":"e_1_2_2_64_1","volume-title":"et al","author":"Zeilenga K.","year":"2006","unstructured":"Zeilenga , K. , Ed. et al . 2006 . Lightweight Directory Access Protocol (LDAP): Tech . Spec. Road Map . http:\/\/www.potaroo.net\/ietf\/idref\/draft-zeilenga-ldap-assert\/. Zeilenga, K., Ed. et al. 2006. Lightweight Directory Access Protocol (LDAP): Tech. Spec. Road Map. http:\/\/www.potaroo.net\/ietf\/idref\/draft-zeilenga-ldap-assert\/."}],"container-title":["ACM Transactions on Information and System Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2043621.2043623","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/2043621.2043623","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T09:54:19Z","timestamp":1750240459000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2043621.2043623"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2011,11]]},"references-count":64,"journal-issue":{"issue":"3","published-print":{"date-parts":[[2011,11]]}},"alternative-id":["10.1145\/2043621.2043623"],"URL":"https:\/\/doi.org\/10.1145\/2043621.2043623","relation":{},"ISSN":["1094-9224","1557-7406"],"issn-type":[{"value":"1094-9224","type":"print"},{"value":"1557-7406","type":"electronic"}],"subject":[],"published":{"date-parts":[[2011,11]]},"assertion":[{"value":"2010-03-01","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2011-02-01","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2011-11-01","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}