{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,15]],"date-time":"2026-05-15T01:18:59Z","timestamp":1778807939391,"version":"3.51.4"},"reference-count":41,"publisher":"Association for Computing Machinery (ACM)","issue":"1","license":[{"start":{"date-parts":[[2014,8,1]],"date-time":"2014-08-01T00:00:00Z","timestamp":1406851200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Inf. Syst. Secur."],"published-print":{"date-parts":[[2014,8]]},"abstract":"<jats:p>\n            Access control policies define what resources can be accessed by which subjects and under which conditions. It is, however, often not possible to anticipate all subjects that should be permitted access and the conditions under which they should be permitted. For example, predicting and correctly encoding all emergency and exceptional situations is impractical. Traditional access control models simply deny all requests that are not permitted, and in doing so may cause unpredictable and unacceptable consequences. To overcome this issue, break-glass access control models permit a subject to override an access control denial if he accepts a set of obligatory actions and certain override conditions are met. Existing break-glass models are limited in how the override decision is specified. They either grant overrides for a predefined set of exceptional situations, or they grant unlimited overrides to selected subjects, and as such, they suffer from the difficulty of correctly encoding and predicting all override situations and permissions. To address this, we develop Rumpole, a novel break-glass language that explicitly represents and infers\n            <jats:italic>knowledge gaps<\/jats:italic>\n            and\n            <jats:italic>knowledge conflicts<\/jats:italic>\n            about the subject's attributes and the contextual conditions, such as emergencies. For example, a Rumpole policy can distinguish whether or not it is known that an emergency holds. This leads to a more informed decision for an override request, whereas current break-glass languages simply assume that there is no emergency if the evidence for it is missing. To formally define Rumpole, we construct a novel many-valued logic programming language called Beagle. It has a simple syntax similar to that of Datalog, and its semantics is an extension of Fitting's bilattice-based semantics for logic programs. Beagle is a knowledge non-monotonic langauge, and as such, is strictly more expressive than current many-valued logic programming languages.\n          <\/jats:p>","DOI":"10.1145\/2629502","type":"journal-article","created":{"date-parts":[[2014,8,12]],"date-time":"2014-08-12T13:53:48Z","timestamp":1407851628000},"page":"1-32","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":18,"title":["Rumpole"],"prefix":"10.1145","volume":"17","author":[{"given":"Srdjan","family":"Marinovic","sequence":"first","affiliation":[{"name":"ETH Zurich"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Naranker","family":"Dulay","sequence":"additional","affiliation":[{"name":"Imperial College London"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Morris","family":"Sloman","sequence":"additional","affiliation":[{"name":"Imperial College London"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2014,8,15]]},"reference":[{"key":"e_1_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.5555\/1947337.1947345"},{"key":"e_1_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2010.07.001"},{"key":"e_1_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-70567-3_20"},{"key":"e_1_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1016\/S0004-3702(98)00032-0"},{"key":"e_1_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2006.32"},{"key":"e_1_2_1_6_1","volume-title":"Modern Uses of Multiple-Valued Logics","author":"Belnap N. D."},{"key":"e_1_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.5555\/1287369.1287413"},{"key":"e_1_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1145\/1542207.1542239"},{"key":"e_1_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1109\/CSF.2008.10"},{"key":"e_1_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1007\/s10207-007-0017-y"},{"key":"e_1_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1109\/69.43410"},{"key":"e_1_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1145\/2462410.2462423"},{"key":"e_1_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-28641-4_21"},{"key":"e_1_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1145\/502807.502810"},{"key":"e_1_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1145\/1266840.1266843"},{"key":"e_1_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1109\/ACSAC.2009.12"},{"key":"e_1_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1109\/ISMVL.1990.122627"},{"key":"e_1_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1016\/0743-1066(91)90014-G"},{"key":"e_1_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1111\/j.1467-8640.1988.tb00280.x"},{"key":"e_1_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1109\/PERCOM.2006.19"},{"key":"e_1_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1145\/1966913.1966944"},{"key":"e_1_2_1_22_1","unstructured":"HHS. 2003. Summary of the HIPAA Privacy Rule. United States Department of Health & Human Services (2003). http:\/\/www.hhs.gov\/ocr\/privacy\/hipaa\/understanding\/summary.  HHS. 2003. Summary of the HIPAA Privacy Rule. United States Department of Health & Human Services (2003). http:\/\/www.hhs.gov\/ocr\/privacy\/hipaa\/understanding\/summary."},{"key":"e_1_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1145\/1180405.1180423"},{"key":"e_1_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1145\/2295136.2295174"},{"key":"e_1_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1145\/1180337.1180342"},{"key":"e_1_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1145\/1542207.1542229"},{"key":"e_1_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1145\/344287.344304"},{"key":"e_1_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1145\/1998441.1998453"},{"key":"e_1_2_1_29_1","unstructured":"NEMA. 2004. Break-Glass: An Approach to Granting Emergency Access to Healthcare Systems. White Paper Joint NEMA\/COCIR\/JIRA Security and Privacy Committee (SPC).  NEMA. 2004. Break-Glass: An Approach to Granting Emergency Access to Healthcare Systems. White Paper Joint NEMA\/COCIR\/JIRA Security and Privacy Committee (SPC)."},{"key":"e_1_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1145\/1377836.1377857"},{"key":"e_1_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1145\/984334.984339"},{"key":"e_1_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1145\/335169.335188"},{"key":"e_1_2_1_33_1","volume-title":"Proceedings of the 7th National Conference on Artifical Intelligence (AAAI). 444--448","author":"Przymusinski Teodor C.","year":"1988"},{"key":"e_1_2_1_34_1","volume-title":"Proceedings of the 5th International Conference and Symposium on Logic Programming (ICLP\/SLP). 1081--1096","author":"Przymusinski Teodor C.","year":"1988"},{"key":"e_1_2_1_36_1","doi-asserted-by":"crossref","unstructured":"Erik Rissanen Babak Sadighi Firozabadi and Marek J. Sergot. 2004. Discretionary overriding of access control in the privilege calculus. In Formal Aspects in Security and Trust 219--232.  Erik Rissanen Babak Sadighi Firozabadi and Marek J. Sergot. 2004. Discretionary overriding of access control in the privilege calculus. In Formal Aspects in Security and Trust 219--232.","DOI":"10.1007\/0-387-24098-5_16"},{"key":"e_1_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.1016\/S0304-3975(96)00125-9"},{"key":"e_1_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.1007\/BF01536398"},{"key":"e_1_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.1109\/69.755623"},{"key":"e_1_2_1_40_1","doi-asserted-by":"publisher","DOI":"10.2140\/pjm.1955.5.285"},{"key":"e_1_2_1_41_1","doi-asserted-by":"publisher","DOI":"10.1109\/POLICY.2008.10"},{"key":"e_1_2_1_42_1","doi-asserted-by":"publisher","DOI":"10.1145\/116825.116838"}],"container-title":["ACM Transactions on Information and System Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2629502","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/2629502","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T07:01:18Z","timestamp":1750230078000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2629502"}},"subtitle":["An Introspective Break-Glass Access Control Language"],"short-title":[],"issued":{"date-parts":[[2014,8]]},"references-count":41,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2014,8]]}},"alternative-id":["10.1145\/2629502"],"URL":"https:\/\/doi.org\/10.1145\/2629502","relation":{},"ISSN":["1094-9224","1557-7406"],"issn-type":[{"value":"1094-9224","type":"print"},{"value":"1557-7406","type":"electronic"}],"subject":[],"published":{"date-parts":[[2014,8]]},"assertion":[{"value":"2013-07-01","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2014-05-01","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2014-08-15","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}