{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,28]],"date-time":"2026-06-28T05:45:11Z","timestamp":1782625511902,"version":"3.54.5"},"reference-count":111,"publisher":"Association for Computing Machinery (ACM)","issue":"6","license":[{"start":{"date-parts":[[2022,12,7]],"date-time":"2022-12-07T00:00:00Z","timestamp":1670371200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Comput. Surv."],"published-print":{"date-parts":[[2023,7,31]]},"abstract":"<jats:p>There any many different access-control systems, yet a commonality is that they provide flexible mechanisms to enforce different access levels. Their importance in organisations to adequately restrict resources, coupled with their use in a dynamic environment, mandates the need to routinely perform policy analysis. The aim of performing analysis is often to identify potential problematic permissions, which have the potential to be exploited and could result in data theft and unintended modification. There is a vast body of published literature on analysing access-control systems, yet as performing analysis has a strong end-user motivation and is grounded in security challenges faced in real-world systems, it is important to understand how research is developing, what are the common themes of interest, and to identify key challenges that should be addressed in future work. To the best of the authors\u2019 knowledge, no survey has been performed to gain an understanding of empirical access-control analysis, focussing on how techniques are evaluated and how they align to the needs of real-world analysis tasks. This article provides a systematic literature review, identifying and summarising key works. Key findings are identified and discussed as areas of future work.<\/jats:p>","DOI":"10.1145\/3533703","type":"journal-article","created":{"date-parts":[[2022,4,28]],"date-time":"2022-04-28T06:33:09Z","timestamp":1651127589000},"page":"1-28","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":46,"title":["A Survey on Empirical Security Analysis of Access-control Systems: A Real-world Perspective"],"prefix":"10.1145","volume":"55","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-1747-9914","authenticated-orcid":false,"given":"Simon","family":"Parkinson","sequence":"first","affiliation":[{"name":"University of Huddersfield, Queensgate, Huddersfield, West Yorkshire, UK"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8613-8200","authenticated-orcid":false,"given":"Saad","family":"Khan","sequence":"additional","affiliation":[{"name":"University of Huddersfield, Queensgate, Huddersfield, West Yorkshire, UK"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2022,12,7]]},"reference":[{"key":"e_1_3_2_2_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.jii.2021.100200"},{"key":"e_1_3_2_3_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2014.01.002"},{"key":"e_1_3_2_4_2","article-title":"Extensible access control markup language (XACML) version 1.0","author":"Anderson Anne","year":"2003","unstructured":"Anne Anderson, Anthony Nadalin, B. Parducci, D. Engovatov, H. Lockhart, M. Kudo, P. Humenn, S. Godik, S. Anderson, S. Crocker, et\u00a0al. 2003. Extensible access control markup language (XACML) version 1.0. OASIS (2003). http:\/\/docs.oasis-open.org\/xacml\/access_control-xacml-2.0-core-spec-cd-02.pdf.","journal-title":"OASIS"},{"issue":"1","key":"e_1_3_2_5_2","first-page":"157","article-title":"A tool for access control policy validation","volume":"19","author":"Aqmocanuib Muhammad","year":"2018","unstructured":"Muhammad Aqmocanuib and Riaz Ahmed Shaikh. 2018. A tool for access control policy validation. J. Internet Technol. 19, 1 (2018), 157\u2013166.","journal-title":"J. Internet Technol."},{"key":"e_1_3_2_6_2","first-page":"17","volume-title":"Proceedings of the International Workshop on Security and Trust Management","author":"Armando Alessandro","year":"2010","unstructured":"Alessandro Armando and Silvio Ranise. 2010. Automated symbolic analysis of ARBAC-policies. In Proceedings of the International Workshop on Security and Trust Management. Springer, 17\u201334."},{"key":"e_1_3_2_7_2","doi-asserted-by":"publisher","DOI":"10.1007\/s10207-019-00448-9"},{"key":"e_1_3_2_8_2","doi-asserted-by":"publisher","DOI":"10.12694\/scpe.v17i3.1180"},{"key":"e_1_3_2_9_2","doi-asserted-by":"publisher","DOI":"10.1111\/j.1467-8640.1995.tb00052.x"},{"key":"e_1_3_2_10_2","doi-asserted-by":"publisher","DOI":"10.1145\/1952982.1952984"},{"key":"e_1_3_2_11_2","doi-asserted-by":"publisher","DOI":"10.1145\/2875491.2875497"},{"key":"e_1_3_2_12_2","doi-asserted-by":"publisher","DOI":"10.1145\/501978.501979"},{"key":"e_1_3_2_13_2","unstructured":"Matt Bishop. 2005. Introduction to Computer Security (1st ed.). Addison-Wesley Boston."},{"key":"e_1_3_2_14_2","doi-asserted-by":"publisher","DOI":"10.1145\/1774088.1774503"},{"key":"e_1_3_2_15_2","first-page":"131","volume-title":"Proceedings of the 22nd USENIX Security Symposium (USENIX Security\u201913)","author":"Bugiel Sven","year":"2013","unstructured":"Sven Bugiel, Stephen Heuser, and Ahmad-Reza Sadeghi. 2013. Flexible and fine-grained mandatory access control on Android for diverse security and privacy policies. In Proceedings of the 22nd USENIX Security Symposium (USENIX Security\u201913). 131\u2013146."},{"key":"e_1_3_2_16_2","doi-asserted-by":"publisher","DOI":"10.1109\/CSF.2012.29"},{"key":"e_1_3_2_17_2","doi-asserted-by":"publisher","DOI":"10.1109\/CSF.2015.10"},{"key":"e_1_3_2_18_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-15618-7_1"},{"key":"e_1_3_2_19_2","doi-asserted-by":"publisher","DOI":"10.1109\/CSF.2016.39"},{"key":"e_1_3_2_20_2","doi-asserted-by":"publisher","DOI":"10.1109\/IRI.2019.00047"},{"key":"e_1_3_2_21_2","doi-asserted-by":"publisher","DOI":"10.1145\/2857705.2857716"},{"key":"e_1_3_2_22_2","article-title":"The next 700 policy miners: A universal method for building policy miners","author":"Cotrini Carlos","year":"2019","unstructured":"Carlos Cotrini, Luca Corinzia, Thilo Weghorn, and David Basin. 2019. The next 700 policy miners: A universal method for building policy miners. arXiv preprint arXiv:1908.05994 (2019).","journal-title":"arXiv preprint arXiv:1908.05994"},{"key":"e_1_3_2_23_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICIS.2005.103"},{"key":"e_1_3_2_24_2","doi-asserted-by":"publisher","DOI":"10.1145\/1210263.1210265"},{"key":"e_1_3_2_25_2","first-page":"161","volume-title":"Proceedings of the USENIX Security Symposium","author":"Das Tathagata","year":"2010","unstructured":"Tathagata Das, Ranjita Bhagwan, and Prasad Naldurg. 2010. Baaz: A system for detecting access control misconfigurations. In Proceedings of the USENIX Security Symposium. 161\u2013176."},{"key":"e_1_3_2_26_2","doi-asserted-by":"publisher","DOI":"10.1002\/spe.513"},{"key":"e_1_3_2_27_2","first-page":"2031","article-title":"Mandatory access control\u2014Problems in it and propose a model which overcomes them","volume":"4","author":"Dholakia Yash","year":"2017","unstructured":"Yash Dholakia. 2017. Mandatory access control\u2014Problems in it and propose a model which overcomes them. Int. Res. J. Eng. Technol. 4 (2017), 2031.","journal-title":"Int. Res. J. Eng. Technol."},{"key":"e_1_3_2_28_2","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2019.2905846"},{"key":"e_1_3_2_29_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.1985.10014"},{"key":"e_1_3_2_30_2","doi-asserted-by":"publisher","DOI":"10.1007\/11908739_29"},{"key":"e_1_3_2_31_2","first-page":"548","volume-title":"Proceedings of the Clustering-based Approach for Anomaly Detection in XACML Policies","author":"Hadj Maryem Ait El","year":"2017","unstructured":"Maryem Ait El Hadj, Meryeme Ayache, Yahya Benkaouz, Ahmed Khoumsi, and Mohammed Erradi. 2017. Clustering-based approach for anomaly detection in XACML policies. In Proceedings of the Clustering-based Approach for Anomaly Detection in XACML Policies. 548\u2013553."},{"issue":"16","key":"e_1_3_2_32_2","first-page":"e3","article-title":"Formal approach to detect and resolve anomalies while clustering ABAC policies","volume":"5","author":"Hadj Maryem Ait El","year":"2018","unstructured":"Maryem Ait El Hadj, Ahmed Khoumsi, Yahya Benkaouz, and Mohammed Erradi. 2018. Formal approach to detect and resolve anomalies while clustering ABAC policies. ICST Trans. Secur. Safet. 5, 16 (2018), e3.","journal-title":"ICST Trans. Secur. Safet."},{"key":"e_1_3_2_33_2","first-page":"836","volume-title":"Proceedings of the International Conference on Soft Computing and Pattern Recognition","author":"Hadj Maryem Ait El","year":"2020","unstructured":"Maryem Ait El Hadj, Ahmed Khoumsi, Yahya Benkaouz, and Mohammed Erradi. 2020. A log-based method to detect and resolve efficiently conflicts in access control policies. In Proceedings of the International Conference on Soft Computing and Pattern Recognition. 836\u2013846."},{"key":"e_1_3_2_34_2","doi-asserted-by":"publisher","DOI":"10.1145\/2875491.2875496"},{"key":"e_1_3_2_35_2","doi-asserted-by":"publisher","DOI":"10.5555\/861998"},{"key":"e_1_3_2_36_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-08867-9_12"},{"key":"e_1_3_2_37_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-36742-7_30"},{"key":"e_1_3_2_38_2","doi-asserted-by":"publisher","DOI":"10.1145\/1809842.1809851"},{"key":"e_1_3_2_39_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2019.01.005"},{"key":"e_1_3_2_40_2","doi-asserted-by":"publisher","DOI":"10.1145\/1866898.1866908"},{"key":"e_1_3_2_41_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-00768-2_4"},{"key":"e_1_3_2_42_2","doi-asserted-by":"publisher","DOI":"10.1145\/3078861.3078879"},{"key":"e_1_3_2_43_2","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2013.42"},{"key":"e_1_3_2_44_2","doi-asserted-by":"publisher","DOI":"10.1145\/1998441.1998472"},{"key":"e_1_3_2_45_2","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2013.18"},{"key":"e_1_3_2_46_2","doi-asserted-by":"publisher","DOI":"10.1109\/MC.2015.33"},{"key":"e_1_3_2_47_2","first-page":"192","article-title":"Verification and test methods for access control policies\/models","volume":"800","author":"Hu Vincent C.","year":"2017","unstructured":"Vincent C. Hu, Rick Kuhn, and Dylan Yaga. 2017. Verification and test methods for access control policies\/models. NIST Spec. Public. 800 (2017), 192.","journal-title":"NIST Spec. Public."},{"key":"e_1_3_2_48_2","doi-asserted-by":"publisher","DOI":"10.3923\/itj.2009.726.734"},{"key":"e_1_3_2_49_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-91908-9_19"},{"key":"e_1_3_2_50_2","doi-asserted-by":"publisher","DOI":"10.1145\/3295749"},{"key":"e_1_3_2_51_2","doi-asserted-by":"publisher","DOI":"10.2200\/S00126ED1V01Y200808SPT001"},{"key":"e_1_3_2_52_2","doi-asserted-by":"publisher","DOI":"10.1145\/2046707.2046727"},{"key":"e_1_3_2_53_2","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2007.70225"},{"key":"e_1_3_2_54_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2014.08.001"},{"key":"e_1_3_2_55_2","first-page":"5013","volume-title":"Proceedings of the IEEE International Conference on Systems, Man and Cybernetics","author":"Jiang Yixin","year":"2004","unstructured":"Yixin Jiang, Chuang Lin, Hao Yin, and Zhangxi Tan. 2004. Security analysis of mandatory access control model. In Proceedings of the IEEE International Conference on Systems, Man and Cybernetics. IEEE, 5013\u20135018."},{"key":"e_1_3_2_56_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-31540-4_4"},{"key":"e_1_3_2_57_2","doi-asserted-by":"publisher","DOI":"10.1145\/2517881.2517891"},{"key":"e_1_3_2_58_2","doi-asserted-by":"publisher","DOI":"10.1145\/2620728.2620773"},{"key":"e_1_3_2_59_2","doi-asserted-by":"publisher","DOI":"10.1145\/775412.775435"},{"key":"e_1_3_2_60_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.cosrev.2010.02.002"},{"key":"e_1_3_2_61_2","first-page":"96","volume-title":"Proceedings of the IEEE Symposium on Security and Privacy (S&P\u201905)","author":"Li Ninghui","year":"2005","unstructured":"Ninghui Li and Mahesh V. Tripunitara. 2005. On safety in discretionary access control. In Proceedings of the IEEE Symposium on Security and Privacy (S&P\u201905). IEEE, 96\u2013109."},{"key":"e_1_3_2_62_2","doi-asserted-by":"publisher","DOI":"10.1145\/1187441.1187442"},{"key":"e_1_3_2_63_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICDCSW.2012.23"},{"key":"e_1_3_2_64_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2019.101632"},{"key":"e_1_3_2_65_2","doi-asserted-by":"publisher","DOI":"10.1016\/0020-0190(85)90065-1"},{"key":"e_1_3_2_66_2","doi-asserted-by":"publisher","DOI":"10.1145\/2871148"},{"key":"e_1_3_2_67_2","first-page":"124","volume-title":"Proceedings of the 18th International Multiconference","author":"Mocanu Decebal","year":"2015","unstructured":"Decebal Mocanu, Fatih Turkmen, Antonio Liotta, et\u00a0al. 2015. Towards ABAC policy mining from logs with deep learning. In Proceedings of the 18th International Multiconference. 124\u2013128."},{"key":"e_1_3_2_68_2","doi-asserted-by":"publisher","DOI":"10.1145\/1542207.1542224"},{"key":"e_1_3_2_69_2","doi-asserted-by":"publisher","DOI":"10.1145\/2295136.2295145"},{"key":"e_1_3_2_70_2","doi-asserted-by":"publisher","DOI":"10.1145\/1542207.1542214"},{"key":"e_1_3_2_71_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2010.09.002"},{"key":"e_1_3_2_72_2","doi-asserted-by":"publisher","DOI":"10.3390\/s140814786"},{"key":"e_1_3_2_73_2","doi-asserted-by":"publisher","DOI":"10.1145\/354876.354878"},{"key":"e_1_3_2_74_2","doi-asserted-by":"publisher","DOI":"10.1109\/.2006.1629440"},{"key":"e_1_3_2_75_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.jisa.2016.04.004"},{"key":"e_1_3_2_76_2","doi-asserted-by":"publisher","DOI":"10.1186\/s42400-019-0031-1"},{"key":"e_1_3_2_77_2","unstructured":"Simon Parkinson Saad Khan and Luk\u00e1 Chrpa. 2020. Automated planning for administrating role-based access control. (2020). https:\/\/icaps20subpages.icaps-conference.org\/wp-content\/uploads\/2020\/10\/SPARK-2020_paper_6.pdf."},{"key":"e_1_3_2_78_2","doi-asserted-by":"publisher","DOI":"10.1186\/s42400-022-00112-1"},{"key":"e_1_3_2_79_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.eswa.2016.02.027"},{"key":"e_1_3_2_80_2","article-title":"Detecting incompleteness, conflicting and unreachability XACML policies using answer set programming","author":"Ramli Carroline Dewi Puspa Kencana","year":"2015","unstructured":"Carroline Dewi Puspa Kencana Ramli. 2015. Detecting incompleteness, conflicting and unreachability XACML policies using answer set programming. arXiv preprint arXiv:1503.02732 (2015).","journal-title":"arXiv preprint arXiv:1503.02732"},{"key":"e_1_3_2_81_2","doi-asserted-by":"publisher","DOI":"10.1145\/2613087.2613102"},{"key":"e_1_3_2_82_2","doi-asserted-by":"publisher","DOI":"10.3233\/JCS-15756"},{"key":"e_1_3_2_83_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2005.06.007"},{"key":"e_1_3_2_84_2","doi-asserted-by":"publisher","DOI":"10.1007\/s10207-018-0421-5"},{"key":"e_1_3_2_85_2","doi-asserted-by":"crossref","unstructured":"Ravi S. Sandhu. 1995. Rationale for the RBAC96 family of access control models. In Proceedings of the First ACM Workshop on Role-Based Access Control (RBAC\u201995) C. E. Youman R. S. Sandhu and E. J. Coyne (Eds.). ACM Press New York NY.","DOI":"10.1145\/270152.270167"},{"key":"e_1_3_2_86_2","doi-asserted-by":"publisher","DOI":"10.1145\/300830.300839"},{"key":"e_1_3_2_87_2","doi-asserted-by":"publisher","DOI":"10.1109\/2.485845"},{"key":"e_1_3_2_88_2","doi-asserted-by":"publisher","DOI":"10.1109\/35.312842"},{"key":"e_1_3_2_89_2","doi-asserted-by":"publisher","DOI":"10.1109\/CSFW.2006.22"},{"key":"e_1_3_2_90_2","doi-asserted-by":"publisher","DOI":"10.1145\/373256.373257"},{"key":"e_1_3_2_91_2","doi-asserted-by":"publisher","DOI":"10.1145\/3007204"},{"key":"e_1_3_2_92_2","doi-asserted-by":"publisher","DOI":"10.1007\/s10207-016-0317-1"},{"key":"e_1_3_2_93_2","doi-asserted-by":"publisher","DOI":"10.1109\/POLICY.2009.22"},{"key":"e_1_3_2_94_2","first-page":"1","article-title":"A role-based administrative model for administration of heterogeneous access control policies and its security analysis","author":"Singh Mahendra Pratap","year":"2021","unstructured":"Mahendra Pratap Singh, Shamik Sural, Jaideep Vaidya, and Vijayalakshmi Atluri. 2021. A role-based administrative model for administration of heterogeneous access control policies and its security analysis. Inf. Syst. Front. (2021), 1\u201318.","journal-title":"Inf. Syst. Front."},{"key":"e_1_3_2_95_2","doi-asserted-by":"publisher","DOI":"10.1145\/2854065.2854079"},{"key":"e_1_3_2_96_2","unstructured":"OASIS Standard. 2005. Extensible access control markup language (XACML) version 2.0."},{"key":"e_1_3_2_97_2","doi-asserted-by":"publisher","DOI":"10.1109\/ARES.2016.22"},{"key":"e_1_3_2_98_2","doi-asserted-by":"publisher","DOI":"10.1145\/1315245.1315300"},{"key":"e_1_3_2_99_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-27189-2_2"},{"key":"e_1_3_2_100_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-662-46666-7_7"},{"key":"e_1_3_2_101_2","doi-asserted-by":"publisher","DOI":"10.1145\/2295136.2295169"},{"issue":"1","key":"e_1_3_2_102_2","first-page":"22","article-title":"An optimized firewall anomaly resolution.","volume":"10","author":"Valenza Fulvio","year":"2020","unstructured":"Fulvio Valenza and Manuel Cheminod. 2020. An optimized firewall anomaly resolution.J. Internet Serv. Inf. Secur. 10, 1 (2020), 22\u201337.","journal-title":"J. Internet Serv. Inf. Secur."},{"key":"e_1_3_2_103_2","article-title":"The EU General Data Protection Regulation (GDPR)","author":"Voigt Paul","year":"2017","unstructured":"Paul Voigt and Axel Von dem Bussche. 2017. The EU General Data Protection Regulation (GDPR). A Practical Guide,1st ed. Springer International Publishing, Cham.","journal-title":"A Practical Guide,"},{"key":"e_1_3_2_104_2","doi-asserted-by":"publisher","DOI":"10.1145\/3059009.3059031"},{"key":"e_1_3_2_105_2","doi-asserted-by":"publisher","DOI":"10.1145\/2295136.2295146"},{"key":"e_1_3_2_106_2","first-page":"1","volume-title":"Proceedings of the 10th International Conference and Expo on Emerging Technologies for a Smarter World (CEWIT)","author":"Xu Zhongyuan","year":"2013","unstructured":"Zhongyuan Xu and Scott D. Stoller. 2013. Mining attribute-based access control policies from RBAC policies. In Proceedings of the 10th International Conference and Expo on Emerging Technologies for a Smarter World (CEWIT). IEEE, 1\u20136."},{"key":"e_1_3_2_107_2","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2014.2369048"},{"key":"e_1_3_2_108_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-662-43936-4_18"},{"key":"e_1_3_2_109_2","doi-asserted-by":"publisher","DOI":"10.5555\/2746188.2746189"},{"key":"e_1_3_2_110_2","doi-asserted-by":"publisher","DOI":"10.23919\/TST.2017.8030537"},{"key":"e_1_3_2_111_2","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2018.2825289"},{"key":"e_1_3_2_112_2","doi-asserted-by":"publisher","DOI":"10.1109\/WETICE.2008.34"}],"container-title":["ACM Computing Surveys"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3533703","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3533703","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T19:00:18Z","timestamp":1750186818000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3533703"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,12,7]]},"references-count":111,"journal-issue":{"issue":"6","published-print":{"date-parts":[[2023,7,31]]}},"alternative-id":["10.1145\/3533703"],"URL":"https:\/\/doi.org\/10.1145\/3533703","relation":{},"ISSN":["0360-0300","1557-7341"],"issn-type":[{"value":"0360-0300","type":"print"},{"value":"1557-7341","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022,12,7]]},"assertion":[{"value":"2019-11-23","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2022-04-25","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2022-12-07","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}