{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,21]],"date-time":"2026-03-21T23:28:29Z","timestamp":1774135709242,"version":"3.50.1"},"reference-count":44,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[2016,8,15]],"date-time":"2016-08-15T00:00:00Z","timestamp":1471219200000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/creativecommons.org\/licenses\/by\/4.0"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["EURASIP J. on Info. Security"],"published-print":{"date-parts":[[2016,12]]},"DOI":"10.1186\/s13635-016-0043-2","type":"journal-article","created":{"date-parts":[[2016,8,15]],"date-time":"2016-08-15T13:08:37Z","timestamp":1471266517000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":13,"title":["Adaptive identity and access management\u2014contextual data based policies"],"prefix":"10.1186","volume":"2016","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-3864-4608","authenticated-orcid":false,"given":"Matthias","family":"Hummer","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Michael","family":"Kunz","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Michael","family":"Netter","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Ludwig","family":"Fuchs","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"G\u00fcnther","family":"Pernul","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2016,8,15]]},"reference":[{"issue":"1","key":"43_CR1","first-page":"42","volume":"25","author":"A Hovav","year":"2009","unstructured":"A Hovav, R Berger, Tutorial: identity management systems and secured access control. Commun. Assoc. Inf. Syst.25(1), 42 (2009).","journal-title":"Commun. Assoc. Inf. Syst."},{"key":"43_CR2","first-page":"174","volume-title":"Enterprise Business-Process and Information Systems Modeling. Lecture Notes in Business Information Processing","author":"A Cleven","year":"2009","unstructured":"A Cleven, R Winter, in Enterprise Business-Process and Information Systems Modeling. Lecture Notes in Business Information Processing, ed. by T Halpin, J Krogstie, S Nurcan, E Proper, R Schmidt, P Soffer, and R Ukor. Regulatory Compliance in Information Systems Research \u2013 Literature Analysis and Research Agenda, vol. 29 (SpringerBerlin Heidelberg, 2009), pp. 174\u2013186."},{"key":"43_CR3","unstructured":"United States Code, Sarbanes-Oxley Act of 2002, PL 107-204, 116 Stat 745 (2002). https:\/\/www.sec.gov\/about\/laws\/soa2002.pdf . Accessed 11 Aug 2016."},{"key":"43_CR4","unstructured":"Basel Committee on Banking Supervision, Basel III - A global regulatory framework for more resilient banks and banking systems (2011). https:\/\/www.bis.org\/publ\/bcbs189.pdf . Accessed 11 Aug 2016."},{"key":"43_CR5","doi-asserted-by":"publisher","first-page":"374","DOI":"10.1109\/ARES.2007.145","volume-title":"The Second International Conference on Availability, Reliability and Security, 2007: ARES 2007","author":"L Fuchs","year":"2007","unstructured":"L Fuchs, G Pernul, in The Second International Conference on Availability, Reliability and Security, 2007: ARES 2007. Supporting compliant and secure user handling\u2014a structured approach for in-house identity management (IEEE Computer SocietyLos Alamitos, 2007), pp. 374\u2013384."},{"key":"43_CR6","unstructured":"L Fuchs, M Kunz, G Pernul, in European Conference on Information Systems (ECIS). Role model optimization for secure role-based identity management, (2014)."},{"key":"43_CR7","first-page":"83","volume-title":"Proceedings of the First International Conference on Design Science Research in Information Systems and Technology (DESRIST 2006)","author":"K Peffers","year":"2006","unstructured":"K Peffers, T Tuunanen, CE Gengler, M Rossi, W Hui, V Virtanen, J Bragge, in Proceedings of the First International Conference on Design Science Research in Information Systems and Technology (DESRIST 2006). The design science research process: a model for producing and presenting information systems research (M. E. Sharpe, Inc.Armonk, 2006), pp. 83\u2013106."},{"issue":"1","key":"43_CR8","doi-asserted-by":"crossref","first-page":"75","DOI":"10.2307\/25148625","volume":"28","author":"AR Hevner","year":"2004","unstructured":"AR Hevner, ST March, J Park, S Ram, Design science in information systems research. MIS Q.28(1), 75\u2013105 (2004).","journal-title":"MIS Q."},{"key":"43_CR9","first-page":"403","volume-title":"Proceedings of the IFIP\/FIDIS summer school on \u201cThe future of identity in the information society","author":"D Royer","year":"2008","unstructured":"D Royer, in Proceedings of the IFIP\/FIDIS summer school on \u201cThe future of identity in the information society. Enterprise identity management\u2014what\u2019s in it for organisations (SpringerBerlin Heidelberg, 2008), pp. 403\u2013416."},{"issue":"8","key":"43_CR10","doi-asserted-by":"publisher","first-page":"748","DOI":"10.1016\/j.cose.2011.08.002","volume":"30","author":"L Fuchs","year":"2011","unstructured":"L Fuchs, G Pernul, R Sandhu, Roles in information security\u2014a survey and classification of the research area. Comput. Secur.30(8), 748\u2013769 (2011).","journal-title":"Comput. Secur."},{"issue":"8","key":"43_CR11","doi-asserted-by":"publisher","first-page":"847","DOI":"10.1002\/sec.314","volume":"5","author":"L Fuchs","year":"2012","unstructured":"L Fuchs, G Pernul, Minimizing insider misuse through secure identity management. Secur. Commun. Netw.5(8), 847\u2013862 (2012).","journal-title":"Secur. Commun. Netw."},{"key":"43_CR12","doi-asserted-by":"publisher","first-page":"142","DOI":"10.1007\/978-3-540-77010-7_15","volume-title":"Web Information Systems Engineering\u2013WISE 2007 Workshops","author":"C Wolter","year":"2007","unstructured":"C Wolter, A Schaad, C Meinel, in Web Information Systems Engineering\u2013WISE 2007 Workshops. Deriving XACML policies from business process models (SpringerBerlin Heidelberg, 2007), pp. 142\u2013153."},{"key":"43_CR13","doi-asserted-by":"publisher","first-page":"81","DOI":"10.1109\/ENABL.2004.9","volume-title":"Enabling Technologies: Infrastructure for Collaborative Enterprises, 2004. WET ICE 2004. 13 th IEEE International Workshops on","author":"J Mendling","year":"2004","unstructured":"J Mendling, M Strembeck, G Stermsek, G Neumann, in Enabling Technologies: Infrastructure for Collaborative Enterprises, 2004. WET ICE 2004. 13 th IEEE International Workshops on. An approach to extract rbac models from BPel4Ws processes (IEEE Computer SocietyLos Alamitos, 2004), pp. 81\u201386."},{"key":"43_CR14","unstructured":"A Baumgrass, S Schefer-Wenzl, M Strembeck, in IEEE. Deriving process-related RBAC models from process execution histories, (2012), pp. 421\u2013426."},{"issue":"2","key":"43_CR15","first-page":"38","volume":"29","author":"RS Sandhu","year":"1996","unstructured":"RS Sandhu, EJ Coyne, HL Feinstein, CE Youman, Role-based access control models. IEEE Commun.29(2), 38\u201347 (1996). doi: 10.1109\/2.485845 .","journal-title":"IEEE Commun."},{"issue":"5","key":"43_CR16","doi-asserted-by":"publisher","first-page":"330","DOI":"10.1109\/TSE.2006.49","volume":"32","author":"R Bhatti","year":"2006","unstructured":"R Bhatti, E Bertino, A Ghafoor, X-federate: a policy engineering framework for federated access management. IEEE Trans. Softw. Eng.32(5), 330\u2013346 (2006). doi: 10.1109\/TSE.2006.49 .","journal-title":"IEEE Trans. Softw. Eng."},{"key":"43_CR17","first-page":"37","volume-title":"IEEE 9th International Symposium on Dependable, Autonomic and Secure Computing","author":"C Bailey","year":"2011","unstructured":"C Bailey, DW Chadwick, R de Lemos, in IEEE 9th International Symposium on Dependable, Autonomic and Secure Computing. Self-adaptive authorization framework for policy based RBAC\/ABAC Models (IEEE Computer SocietyLos Alamitos, 2011), pp. 37\u201344."},{"key":"43_CR18","doi-asserted-by":"crossref","first-page":"276","DOI":"10.1007\/978-3-662-43936-4_18","volume-title":"Data and Applications Security and Privacy XXVIII","author":"Z Xu","year":"2014","unstructured":"Z Xu, SD Stoller, in Data and Applications Security and Privacy XXVIII. Mining Attribute-Based Access Control Policies from Logs (SpringerBerlin Heidelberg, 2014), pp. 276\u2013291."},{"key":"43_CR19","doi-asserted-by":"publisher","first-page":"667","DOI":"10.1109\/ARES.2011.104","volume-title":"Availability, Reliability and Security (ARES), 2011 Sixth International Conference On","author":"A Baumgrass","year":"2011","unstructured":"A Baumgrass, in Availability, Reliability and Security (ARES), 2011 Sixth International Conference On. Deriving current state RBAC models from event logs (IEEE Computer SocietyLos Alamitos, 2011), pp. 667\u2013672."},{"key":"43_CR20","first-page":"133","volume-title":"9th International Conference on Information Systems Security","author":"H Safaa","year":"2013","unstructured":"H Safaa, C Fr\u00e9d\u00e9ric, C-B Nora, A Vijay, M St\u00e9phane, in 9th International Conference on Information Systems Security, ed. by A Bagchi, I Ray. Policy Mining: a Bottom-Up Approach Toward a Model Based Firewall Management (SpringerBerlin Heidelberg, 2013), pp. 133\u2013147."},{"issue":"7","key":"43_CR21","doi-asserted-by":"publisher","first-page":"578","DOI":"10.1016\/j.cose.2004.06.013","volume":"23","author":"J Lopez","year":"2004","unstructured":"J Lopez, R Oppliger, G Pernul, Authentication and authorization infrastructures (AAIs): a comparative survey. Comput. Secur.23(7), 578\u2013590 (2004).","journal-title":"Comput. Secur."},{"key":"43_CR22","first-page":"162","volume":"800","author":"VC Hu","year":"2014","unstructured":"VC Hu, D Ferraiolo, R Kuhn, A Schnitzer, K Sandlin, R Miller, K Scarfone, Guide to attribute based access control (ABAC) definition and considerations. NIST Spec. Publ.800:, 162 (2014).","journal-title":"NIST Spec. Publ."},{"key":"43_CR23","first-page":"1","volume-title":"Emerging Technologies for a Smarter World (CEWIT), 2013 10th International Conference and Expo on","author":"Z Xu","year":"2013","unstructured":"Z Xu, SD Stoller, in Emerging Technologies for a Smarter World (CEWIT), 2013 10th International Conference and Expo on. Mining attribute-based access control policies from RBAC policies (IEEE Computer SocietyPiscataway, 2013), pp. 1\u20136."},{"issue":"3","key":"43_CR24","doi-asserted-by":"publisher","first-page":"245","DOI":"10.1007\/s12599-009-0052-5","volume":"1","author":"D-W-ID Royer","year":"2009","unstructured":"D-W-ID Royer, M Meints, Enterprise identity management\u2014towards a decision support framework based on the balanced scorecard approach. Bus. Inf. Syst. Eng.1(3), 245\u2013253 (2009).","journal-title":"Bus. Inf. Syst. Eng."},{"key":"43_CR25","doi-asserted-by":"publisher","first-page":"134","DOI":"10.1109\/NOMSW.2010.5486588","volume-title":"Network Operations and Management Symposium Workshops (NOMS Wksps), 2010 IEEE\/IFIP","author":"MC Mont","year":"2010","unstructured":"MC Mont, Y Beresnevichiene, D Pym, S Shiu, in Network Operations and Management Symposium Workshops (NOMS Wksps), 2010 IEEE\/IFIP. Economics of identity and access management: providing decision support for investments (IEEE Computer SocietyPiscataway, 2010), pp. 134\u2013141."},{"issue":"3","key":"43_CR26","doi-asserted-by":"publisher","first-page":"189","DOI":"10.1007\/s11623-008-0029-4","volume":"32","author":"D Royer","year":"2008","unstructured":"D Royer, M Meints, Planung und Bewertung von, Enterprise identity managementsystemen. Datenschutz und Datensicherheit-DuD. 32(3), 189\u2013193 (2008).","journal-title":"Datenschutz und Datensicherheit-DuD"},{"key":"43_CR27","volume-title":"Identity Management: Setting Context","author":"J Pato","year":"2003","unstructured":"J Pato, OC Center, Identity Management: Setting Context (Hewlett-Packard, Cambridge, 2003)."},{"key":"43_CR28","volume-title":"Engineering of Dynamic Policy-Based Systems: A Policy Engineering of Dynamic Policy-Based Systems: Language Based Approach","author":"M Strembeck","year":"2008","unstructured":"M Strembeck, Engineering of Dynamic Policy-Based Systems: A Policy Engineering of Dynamic Policy-Based Systems: Language Based Approach (Habilitation Thesis, WU-Wien, 2008)."},{"issue":"1","key":"43_CR29","doi-asserted-by":"publisher","first-page":"4","DOI":"10.1007\/s007790170019","volume":"5","author":"AK Dey","year":"2001","unstructured":"AK Dey, Understanding and using context. Pers. Ubiquit. Comput.5(1), 4\u20137 (2001).","journal-title":"Pers. Ubiquit. Comput."},{"key":"43_CR30","doi-asserted-by":"crossref","first-page":"558","DOI":"10.1007\/978-3-540-74255-5_42","volume-title":"Proceedings of the 6 th International and Interdisciplinary Conference on Modeling and Using Context, CONTEXT\u201907","author":"A Zimmermann","year":"2007","unstructured":"A Zimmermann, A Lorenz, R Oppermann, in Proceedings of the 6 th International and Interdisciplinary Conference on Modeling and Using Context, CONTEXT\u201907. An Operational Definition of Context (SpringerBerlin Heidelberg, 2007), pp. 558\u2013571."},{"key":"43_CR31","doi-asserted-by":"publisher","first-page":"122","DOI":"10.1109\/ARES.2009.154","volume-title":"Availability, Reliability and Security, 2009. ARES\u201909. International Conference On","author":"L Fuchs","year":"2009","unstructured":"L Fuchs, C Broser, G Pernul, in Availability, Reliability and Security, 2009. ARES\u201909. International Conference On. Different approaches to in-house identity management\u2014justification of an assumption (IEEE Computer SocietyPiscataway, 2009), pp. 122\u2013129."},{"issue":"4","key":"43_CR32","doi-asserted-by":"publisher","first-page":"715","DOI":"10.1016\/j.dss.2010.08.022","volume":"50","author":"A Colantonio","year":"2011","unstructured":"A Colantonio, R Di Pietro, A Ocello, NV Verde, A new role mining framework to elicit business roles and to mitigate enterprise risk. Decis. Support. Syst.50(4), 715\u2013731 (2011).","journal-title":"Decis. Support. Syst."},{"key":"43_CR33","unstructured":"J MacQueen, et al, in Proceedings of the Fifth Berkeley Symposium on Mathematical Statistics and Probability. Some methods for classification and analysis of multivariate observations, vol. 1 (Oakland, 1967), pp. 281\u2013297."},{"issue":"1","key":"43_CR34","doi-asserted-by":"publisher","first-page":"3","DOI":"10.1016\/0893-6080(88)90020-2","volume":"1","author":"T Kohonen","year":"1988","unstructured":"T Kohonen, An introduction to neural computing. Neural Netw.1(1), 3\u201316 (1988).","journal-title":"Neural Netw."},{"issue":"9","key":"43_CR35","doi-asserted-by":"publisher","first-page":"1278","DOI":"10.1109\/PROC.1975.9939","volume":"63","author":"JH Saltzer","year":"1975","unstructured":"JH Saltzer, MD Schroeder, The protection of information in computer systems. Proc. IEEE. 63(9), 1278\u20131308 (1975).","journal-title":"Proc. IEEE"},{"issue":"5","key":"43_CR36","doi-asserted-by":"publisher","first-page":"533","DOI":"10.1109\/TDSC.2014.2369048","volume":"12","author":"Z Xu","year":"2015","unstructured":"Z Xu, SD Stoller, Mining attribute-based access control policies. IEEE Trans. Dependable Secure Comput.12(5), 533\u2013545 (2015).","journal-title":"IEEE Trans. Dependable Secure Comput."},{"key":"43_CR37","first-page":"285","volume-title":"Sicherheit 2005: Sicherheit - Schutz und Zuverl\u00e4ssigkeit, Beitr\u00e4ge der 2. Jahrestagung des Fachbereichs Sicherheit der Gesellschaft F\u00fcr Informatik e.V. (GI), 5.-8. April 2005 in Regensburg","author":"T Priebe","year":"2005","unstructured":"T Priebe, W Dobmeier, B Muschall, G Pernul, in Sicherheit 2005: Sicherheit - Schutz und Zuverl\u00e4ssigkeit, Beitr\u00e4ge der 2. Jahrestagung des Fachbereichs Sicherheit der Gesellschaft F\u00fcr Informatik e.V. (GI), 5.-8. April 2005 in Regensburg. ABAC - Ein Referenzmodell f\u00fcr attributbasierte Zugriffskontrolle (GIBonn, 2005), pp. 285\u2013296."},{"key":"43_CR38","doi-asserted-by":"publisher","first-page":"85","DOI":"10.1016\/j.is.2014.04.006","volume":"46","author":"L Garc\u00eda-Ba\u00f1uelos","year":"2014","unstructured":"L Garc\u00eda-Ba\u00f1uelos, M Dumas, M La Rosa, J De Weerdt, CC Ekanayake, Controlled automated discovery of collections of business process models. Inf. Syst.46:, 85\u2013101 (2014).","journal-title":"Inf. Syst."},{"issue":"4","key":"43_CR39","doi-asserted-by":"publisher","first-page":"318","DOI":"10.1109\/TLT.2012.11","volume":"5","author":"K Verbert","year":"2012","unstructured":"K Verbert, N Manouselis, X Ochoa, M Wolpers, H Drachsler, I Bosnic, E Duval, Context-aware recommender systems for learning: a survey and future challenges. IEEE Trans. Learn. Technol.5(4), 318\u2013335 (2012).","journal-title":"IEEE Trans. Learn. Technol."},{"key":"43_CR40","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/978-0-387-85820-3_1","volume-title":"Recommender Systems Handbook","author":"F Ricci","year":"2011","unstructured":"F Ricci, L Rokach, B Shapira, in Recommender Systems Handbook. Introduction to recommender systems handbook (SpringerBerlin Heidelberg, 2011), pp. 1\u201335."},{"key":"43_CR41","first-page":"14","volume":"1","author":"G Pernul","year":"2010","unstructured":"G Pernul, L Fuchs, Reducing the risk of insider misuse by revising identity management and user account data. J. Wirel. Mob. Netw. Ubiquit. Comput. Dependable Appl (JoWUA). 1:, 14\u201328 (2010).","journal-title":"J. Wirel. Mob. Netw. Ubiquit. Comput. Dependable Appl (JoWUA)"},{"key":"43_CR42","unstructured":"B f\u00fcr Sicherheit in der Informationstechnik, BSI-Grundschutz Katalog (1996). https:\/\/www.bsi.bund.de\/EN\/Topics\/ITGrundschutz\/itgrundschutz_node.html . Accessed 11 Aug 2016."},{"key":"43_CR43","volume-title":"Dynamic Trust-based Recertifications in Identity and Access Management","author":"C Richthammer","year":"2015","unstructured":"C Richthammer, M Kunz, J S\u00e4nger, M Hummer, G Pernul, Dynamic Trust-based Recertifications in Identity and Access Management (IEEE Computer Society, Piscataway, 2015)."},{"issue":"1","key":"43_CR44","first-page":"100","volume":"28","author":"JA Hartigan","year":"1979","unstructured":"JA Hartigan, MA Wong, Algorithm AS 136: A k-means clustering algorithm. J. R. Stat. Soc. Ser. C (Appl. Stat.)28(1), 100\u2013108 (1979).","journal-title":"J. R. Stat. Soc. Ser. C (Appl. Stat.)"}],"container-title":["EURASIP Journal on Information Security"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1186\/s13635-016-0043-2.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/article\/10.1186\/s13635-016-0043-2\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1186\/s13635-016-0043-2","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1186\/s13635-016-0043-2.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2020,9,25]],"date-time":"2020-09-25T05:27:12Z","timestamp":1601011632000},"score":1,"resource":{"primary":{"URL":"https:\/\/jis-eurasipjournals.springeropen.com\/articles\/10.1186\/s13635-016-0043-2"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2016,8,15]]},"references-count":44,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2016,12]]}},"alternative-id":["43"],"URL":"https:\/\/doi.org\/10.1186\/s13635-016-0043-2","relation":{},"ISSN":["1687-417X"],"issn-type":[{"value":"1687-417X","type":"electronic"}],"subject":[],"published":{"date-parts":[[2016,8,15]]},"article-number":"19"}}