{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,11,21]],"date-time":"2025-11-21T11:29:53Z","timestamp":1763724593379,"version":"3.41.0"},"publisher-location":"New York, NY, USA","reference-count":30,"publisher":"ACM","license":[{"start":{"date-parts":[[2022,6,7]],"date-time":"2022-06-07T00:00:00Z","timestamp":1654560000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"name":"Telus Communications, under Industrial Research Chair Grant scheme"},{"name":"Natural Sciences and Engineering Research Council of Canada"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2022,6,7]]},"DOI":"10.1145\/3532105.3535014","type":"proceedings-article","created":{"date-parts":[[2022,6,8]],"date-time":"2022-06-08T14:29:57Z","timestamp":1654698597000},"page":"195-206","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":6,"title":["A Capability-based Distributed Authorization System to Enforce Context-aware Permission Sequences"],"prefix":"10.1145","author":[{"given":"Adrian Shuai","family":"Li","sequence":"first","affiliation":[{"name":"Purdue University, West Lafayette, IN, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Reihaneh","family":"Safavi-Naini","sequence":"additional","affiliation":[{"name":"University of Calgary, Calgary, AB, Canada"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Philip W. L.","family":"Fong","sequence":"additional","affiliation":[{"name":"University of Calgary, Calgary, AB, Canada"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2022,6,8]]},"reference":[{"key":"e_1_3_2_2_1_1","unstructured":"Auth0. jsonwebtoken. https:\/\/www.npmjs.com\/package\/jsonwebtoken. Accessed on Jan 2022.  Auth0. jsonwebtoken. https:\/\/www.npmjs.com\/package\/jsonwebtoken. Accessed on Jan 2022."},{"key":"e_1_3_2_2_2_1","unstructured":"BeyondTrust. What Is Least Privilege and Why Do You Need It? https:\/\/www.beyondtrust.com\/blog\/entry\/what-is-least-privilege. Accessed on Feb 2022.  BeyondTrust. What Is Least Privilege and Why Do You Need It? https:\/\/www.beyondtrust.com\/blog\/entry\/what-is-least-privilege. Accessed on Feb 2022."},{"key":"e_1_3_2_2_3_1","volume-title":"Macaroons: Cookies with contextual caveats for decentralized authorization in the cloud","author":"Birgisson A.","year":"2014","unstructured":"A. Birgisson , J. G. Politz , U. Erlingsson , A. Taly , M. Vrable , and M. Lentczner . Macaroons: Cookies with contextual caveats for decentralized authorization in the cloud . 2014 . A. Birgisson, J. G. Politz, U. Erlingsson, A. Taly, M. Vrable, and M. Lentczner. Macaroons: Cookies with contextual caveats for decentralized authorization in the cloud. 2014."},{"key":"e_1_3_2_2_4_1","doi-asserted-by":"publisher","DOI":"10.1145\/2660267.2660323"},{"key":"e_1_3_2_2_5_1","doi-asserted-by":"publisher","DOI":"10.1109\/JSEN.2014.2361406"},{"key":"e_1_3_2_2_6_1","doi-asserted-by":"publisher","DOI":"10.3233\/JCS-2001-9402"},{"key":"e_1_3_2_2_7_1","doi-asserted-by":"publisher","DOI":"10.1145\/365230.365252"},{"key":"e_1_3_2_2_8_1","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978385"},{"key":"e_1_3_2_2_9_1","doi-asserted-by":"publisher","DOI":"10.1109\/SECPRI.1989.36277"},{"key":"e_1_3_2_2_10_1","volume-title":"A capability-based security approach to manage access control in the internet of things. Mathematical and Computer Modelling, 58(5--6):1189--1205","author":"Gusmeroli S.","year":"2013","unstructured":"S. Gusmeroli , S. Piccione , and D. Rotondi . A capability-based security approach to manage access control in the internet of things. Mathematical and Computer Modelling, 58(5--6):1189--1205 , 2013 . S. Gusmeroli, S. Piccione, and D. Rotondi. A capability-based security approach to manage access control in the internet of things. Mathematical and Computer Modelling, 58(5--6):1189--1205, 2013."},{"key":"e_1_3_2_2_11_1","volume-title":"The OAuth 2.0 authorization framework. https:\/\/tools.ietf.org\/html\/rfc6749","author":"Hardt D.","year":"2012","unstructured":"D. Hardt . The OAuth 2.0 authorization framework. https:\/\/tools.ietf.org\/html\/rfc6749 , 2012 . D. Hardt. The OAuth 2.0 authorization framework. https:\/\/tools.ietf.org\/html\/rfc6749, 2012."},{"key":"e_1_3_2_2_12_1","volume-title":"Guide to attribute based access control (ABAC) definition and considerations (draft). NIST special publication, 800(162)","author":"Hu V. C.","year":"2013","unstructured":"V. C. Hu , D. Ferraiolo , R. Kuhn , A. R. Friedman , A. J. Lang , M. M. Cogdell , A. Schnitzer , K. Sandlin , R. Miller , K. Scarfone , Guide to attribute based access control (ABAC) definition and considerations (draft). NIST special publication, 800(162) , 2013 . V. C. Hu, D. Ferraiolo, R. Kuhn, A. R. Friedman, A. J. Lang, M. M. Cogdell, A. Schnitzer, K. Sandlin, R. Miller, K. Scarfone, et al. Guide to attribute based access control (ABAC) definition and considerations (draft). NIST special publication, 800(162), 2013."},{"key":"e_1_3_2_2_13_1","unstructured":"M. Jafari. Using JSON to Model Complex OAuth Scopes. https:\/\/medium.com\/@jafarim\/using-json-to-model-complex-oauth-scopes-fa8a054b2a28. Accessed on Jan 2022.  M. Jafari. Using JSON to Model Complex OAuth Scopes. https:\/\/medium.com\/@jafarim\/using-json-to-model-complex-oauth-scopes-fa8a054b2a28. Accessed on Jan 2022."},{"key":"e_1_3_2_2_14_1","volume-title":"JSON Web Token (JWT). https:\/\/tools.ietf.org\/html\/rfc7519","author":"Jones M.","year":"2012","unstructured":"M. Jones , P. Tarjan , Y. Goland , N. Sakimura , J. Bradley , J. Panzer , and D. Balfanz . JSON Web Token (JWT). https:\/\/tools.ietf.org\/html\/rfc7519 , 2012 . M. Jones, P. Tarjan, Y. Goland, N. Sakimura, J. Bradley, J. Panzer, and D. Balfanz. JSON Web Token (JWT). https:\/\/tools.ietf.org\/html\/rfc7519, 2012."},{"key":"e_1_3_2_2_15_1","doi-asserted-by":"publisher","DOI":"10.3389\/fict.2015.00009"},{"key":"e_1_3_2_2_16_1","unstructured":"A. Labs. The Untold Story of the Target Attack Step by Step. https:\/\/aroundcyber.files.wordpress.com\/2014\/09\/aorato-target-report.pdf. Accessed on Feb 2022.  A. Labs. The Untold Story of the Target Attack Step by Step. https:\/\/aroundcyber.files.wordpress.com\/2014\/09\/aorato-target-report.pdf. Accessed on Feb 2022."},{"key":"e_1_3_2_2_17_1","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.1977.229904"},{"key":"e_1_3_2_2_18_1","volume-title":"Science","author":"Li S.","year":"2020","unstructured":"S. Li . A Capability-based System to Enforce Context-aware Permission Sequence. Master's thesis , Science , 2020 . S. Li. A Capability-based System to Enforce Context-aware Permission Sequence. Master's thesis, Science, 2020."},{"key":"e_1_3_2_2_19_1","unstructured":"T. Lodderstedt. Transaction Authorization or why we need to re-think OAuth scopes. https:\/\/medium.com\/oauth-2\/transaction-authorization-or-why-we-need-to-re-think-oauth-scopes-2326e2038948. Accessed on Jan 2022.  T. Lodderstedt. Transaction Authorization or why we need to re-think OAuth scopes. https:\/\/medium.com\/oauth-2\/transaction-authorization-or-why-we-need-to-re-think-oauth-scopes-2326e2038948. Accessed on Jan 2022."},{"key":"e_1_3_2_2_20_1","volume-title":"User-managed access (UMA) profile of OAuth 2.0. https:\/\/docs.kantarainitiative.org\/uma\/wg\/rec-oauth-uma-grant-2.0.html","author":"Maler E.","year":"2018","unstructured":"E. Maler , D. Catalano , M. Machulak , and T. Hardjono . User-managed access (UMA) profile of OAuth 2.0. https:\/\/docs.kantarainitiative.org\/uma\/wg\/rec-oauth-uma-grant-2.0.html , 2018 . E. Maler, D. Catalano, M. Machulak, and T. Hardjono. User-managed access (UMA) profile of OAuth 2.0. https:\/\/docs.kantarainitiative.org\/uma\/wg\/rec-oauth-uma-grant-2.0.html, 2018."},{"key":"e_1_3_2_2_21_1","unstructured":"J. Mott. Crypto-js. https:\/\/code.google.com\/archive\/p\/crypto-js. Accessed on Jan 2022.  J. Mott. Crypto-js. https:\/\/code.google.com\/archive\/p\/crypto-js. Accessed on Jan 2022."},{"key":"e_1_3_2_2_22_1","doi-asserted-by":"publisher","DOI":"10.1515\/9780804772891"},{"key":"e_1_3_2_2_23_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-39749-4_2"},{"key":"e_1_3_2_2_24_1","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243817"},{"key":"e_1_3_2_2_25_1","doi-asserted-by":"publisher","DOI":"10.1109\/ISCC.2017.8024606"},{"key":"e_1_3_2_2_26_1","volume-title":"Authentication and Authorization for Constrained Environments (ACE) using the OAuth 2.0 Framework (ACE-OAuth). https:\/\/tools.ietf.org\/html\/draft-ietf-ace-oauth-authz-27","author":"Seitz L.","year":"2019","unstructured":"L. Seitz , G. Selander , E. Wahlstroem , S. Erdtman , and H. Tschofenig . Authentication and Authorization for Constrained Environments (ACE) using the OAuth 2.0 Framework (ACE-OAuth). https:\/\/tools.ietf.org\/html\/draft-ietf-ace-oauth-authz-27 , 2019 . IETF Internet Draft. Accessed on Nov 2021. L. Seitz, G. Selander, E. Wahlstroem, S. Erdtman, and H. Tschofenig. Authentication and Authorization for Constrained Environments (ACE) using the OAuth 2.0 Framework (ACE-OAuth). https:\/\/tools.ietf.org\/html\/draft-ietf-ace-oauth-authz-27, 2019. IETF Internet Draft. Accessed on Nov 2021."},{"key":"e_1_3_2_2_27_1","doi-asserted-by":"publisher","DOI":"10.1109\/MobServ.2014.15"},{"key":"e_1_3_2_2_28_1","doi-asserted-by":"publisher","DOI":"10.3390\/s18113868"},{"key":"e_1_3_2_2_29_1","doi-asserted-by":"publisher","DOI":"10.1145\/2382196.2382238"},{"key":"e_1_3_2_2_30_1","doi-asserted-by":"publisher","DOI":"10.1145\/3205977.3205978"}],"event":{"name":"SACMAT '22: The 27th ACM Symposium on Access Control Models and Technologies","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"],"location":"New York NY USA","acronym":"SACMAT '22"},"container-title":["Proceedings of the 27th ACM on Symposium on Access Control Models and Technologies"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3532105.3535014","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3532105.3535014","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T18:09:14Z","timestamp":1750183754000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3532105.3535014"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,6,7]]},"references-count":30,"alternative-id":["10.1145\/3532105.3535014","10.1145\/3532105"],"URL":"https:\/\/doi.org\/10.1145\/3532105.3535014","relation":{},"subject":[],"published":{"date-parts":[[2022,6,7]]},"assertion":[{"value":"2022-06-08","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}