{"id":"https://openalex.org/W3164231686","doi":"https://doi.org/10.1142/s0218194021500182","title":"VeRA: Verifying RBAC and Authorization Constraints Models of Web Applications","display_name":"VeRA: Verifying RBAC and Authorization Constraints Models of Web Applications","publication_year":2021,"publication_date":"2021-05-01","ids":{"openalex":"https://openalex.org/W3164231686","doi":"https://doi.org/10.1142/s0218194021500182","mag":"3164231686"},"language":"en","primary_location":{"is_oa":false,"landing_page_url":"https://doi.org/10.1142/s0218194021500182","pdf_url":null,"source":{"id":"https://openalex.org/S131442419","display_name":"International Journal of Software Engineering and Knowledge Engineering","issn_l":"0218-1940","issn":["0218-1940","1793-6403"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319815","host_organization_name":"World Scientific","host_organization_lineage":["https://openalex.org/P4310319815"],"host_organization_lineage_names":["World Scientific"],"type":"journal"},"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":false},"type":"article","type_crossref":"journal-article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5041192196","display_name":"Thanh-Nhan Luong","orcid":"https://orcid.org/0000-0001-7063-3434"},"institutions":[{"id":"https://openalex.org/I2801894621","display_name":"Hai phong University Of Medicine and Pharmacy","ror":"https://ror.org/034y0z725","country_code":"VN","type":"education","lineage":["https://openalex.org/I2801894621"]}],"countries":["VN"],"is_corresponding":false,"raw_author_name":"Thanh-Nhan Luong","raw_affiliation_strings":["Haiphong University of Medicine and Pharmacy, 72A Nguyen Binh Khiem Street, Ngo Quyen, Hai Phong 180000, Vietnam"],"affiliations":[{"raw_affiliation_string":"Haiphong University of Medicine and Pharmacy, 72A Nguyen Binh Khiem Street, Ngo Quyen, Hai Phong 180000, Vietnam","institution_ids":["https://openalex.org/I2801894621"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5112644304","display_name":"Hanh-Phuc Nguyen","orcid":null},"institutions":[{"id":"https://openalex.org/I73685970","display_name":"Vietnam Maritime University","ror":"https://ror.org/03z9fzp04","country_code":"VN","type":"education","lineage":["https://openalex.org/I73685970"]}],"countries":["VN"],"is_corresponding":false,"raw_author_name":"Hanh-Phuc Nguyen","raw_affiliation_strings":["Vietnam Maritime University, 484 Lach Tray Street, Le Chan, Hai Phong 180000, Vietnam"],"affiliations":[{"raw_affiliation_string":"Vietnam Maritime University, 484 Lach Tray Street, Le Chan, Hai Phong 180000, Vietnam","institution_ids":["https://openalex.org/I73685970"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5071986836","display_name":"Ninh-Thuan Truong","orcid":null},"institutions":[{"id":"https://openalex.org/I177233841","display_name":"Vietnam National University, Hanoi","ror":"https://ror.org/02jmfj006","country_code":"VN","type":"education","lineage":["https://openalex.org/I177233841"]}],"countries":["VN"],"is_corresponding":false,"raw_author_name":"Ninh-Thuan Truong","raw_affiliation_strings":["University of Engineering and Technology, Vietnam National University, Hanoi, 144 Xuan Thuy, Cau Giay, Hanoi, Vietnam"],"affiliations":[{"raw_affiliation_string":"University of Engineering and Technology, Vietnam National University, Hanoi, 144 Xuan Thuy, Cau Giay, Hanoi, Vietnam","institution_ids":["https://openalex.org/I177233841"]}]}],"institution_assertions":[],"countries_distinct_count":1,"institutions_distinct_count":3,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":0.0,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":{"value":0.0,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":0,"max":57},"biblio":{"volume":"31","issue":"05","first_page":"655","last_page":"675"},"is_retracted":false,"is_paratext":false,"primary_topic":{"id":"https://openalex.org/T10927","display_name":"Access Control and Trust","score":0.9999,"subfield":{"id":"https://openalex.org/subfields/3312","display_name":"Sociology and Political Science"},"field":{"id":"https://openalex.org/fields/33","display_name":"Social Sciences"},"domain":{"id":"https://openalex.org/domains/2","display_name":"Social Sciences"}},"topics":[{"id":"https://openalex.org/T10927","display_name":"Access Control and Trust","score":0.9999,"subfield":{"id":"https://openalex.org/subfields/3312","display_name":"Sociology and Political Science"},"field":{"id":"https://openalex.org/fields/33","display_name":"Social Sciences"},"domain":{"id":"https://openalex.org/domains/2","display_name":"Social Sciences"}},{"id":"https://openalex.org/T12479","display_name":"Web Application Security Vulnerabilities","score":0.9953,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11424","display_name":"Security and Verification in Computing","score":0.9923,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/permission","display_name":"Permission","score":0.49619848},{"id":"https://openalex.org/keywords/security-policy","display_name":"Security Policy","score":0.46114096}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.79627657},{"id":"https://openalex.org/C45567728","wikidata":"https://www.wikidata.org/wiki/Q1702839","display_name":"Role-based access control","level":3,"score":0.7614025},{"id":"https://openalex.org/C527821871","wikidata":"https://www.wikidata.org/wiki/Q228502","display_name":"Access control","level":2,"score":0.74123305},{"id":"https://openalex.org/C55439883","wikidata":"https://www.wikidata.org/wiki/Q360812","display_name":"Correctness","level":2,"score":0.5539076},{"id":"https://openalex.org/C115903868","wikidata":"https://www.wikidata.org/wiki/Q80993","display_name":"Software engineering","level":1,"score":0.5295768},{"id":"https://openalex.org/C44415380","wikidata":"https://www.wikidata.org/wiki/Q17008721","display_name":"Computer access control","level":3,"score":0.5078555},{"id":"https://openalex.org/C2779089604","wikidata":"https://www.wikidata.org/wiki/Q7169333","display_name":"Permission","level":2,"score":0.49619848},{"id":"https://openalex.org/C154908896","wikidata":"https://www.wikidata.org/wiki/Q2167404","display_name":"Security policy","level":2,"score":0.46114096},{"id":"https://openalex.org/C77088390","wikidata":"https://www.wikidata.org/wiki/Q8513","display_name":"Database","level":1,"score":0.4575147},{"id":"https://openalex.org/C118643609","wikidata":"https://www.wikidata.org/wiki/Q189210","display_name":"Web application","level":2,"score":0.42288792},{"id":"https://openalex.org/C136764020","wikidata":"https://www.wikidata.org/wiki/Q466","display_name":"World Wide Web","level":1,"score":0.37794933},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.35992444},{"id":"https://openalex.org/C199360897","wikidata":"https://www.wikidata.org/wiki/Q9143","display_name":"Programming language","level":1,"score":0.15774041},{"id":"https://openalex.org/C17744445","wikidata":"https://www.wikidata.org/wiki/Q36442","display_name":"Political science","level":0,"score":0.0},{"id":"https://openalex.org/C199539241","wikidata":"https://www.wikidata.org/wiki/Q7748","display_name":"Law","level":1,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"is_oa":false,"landing_page_url":"https://doi.org/10.1142/s0218194021500182","pdf_url":null,"source":{"id":"https://openalex.org/S131442419","display_name":"International Journal of Software Engineering and Knowledge Engineering","issn_l":"0218-1940","issn":["0218-1940","1793-6403"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319815","host_organization_name":"World Scientific","host_organization_lineage":["https://openalex.org/P4310319815"],"host_organization_lineage_names":["World Scientific"],"type":"journal"},"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":false}],"best_oa_location":null,"sustainable_development_goals":[{"id":"https://metadata.un.org/sdg/16","display_name":"Peace, justice, and strong institutions","score":0.48}],"grants":[],"datasets":[],"versions":[],"referenced_works_count":22,"referenced_works":["https://openalex.org/W130803915","https://openalex.org/W1486178352","https://openalex.org/W1600862691","https://openalex.org/W160365122","https://openalex.org/W1963887709","https://openalex.org/W2007720112","https://openalex.org/W2010173096","https://openalex.org/W2022941584","https://openalex.org/W2099684947","https://openalex.org/W2130083901","https://openalex.org/W2154765153","https://openalex.org/W2166602595","https://openalex.org/W2404280374","https://openalex.org/W2589805430","https://openalex.org/W2603532866","https://openalex.org/W2618682089","https://openalex.org/W2734506003","https://openalex.org/W2765679703","https://openalex.org/W2954769155","https://openalex.org/W4236669998","https://openalex.org/W4255651273","https://openalex.org/W4256644207"],"related_works":["https://openalex.org/W4255992492","https://openalex.org/W318167434","https://openalex.org/W2382286253","https://openalex.org/W2374393728","https://openalex.org/W2148952798","https://openalex.org/W2124367090","https://openalex.org/W2106208683","https://openalex.org/W2105261429","https://openalex.org/W2094052616","https://openalex.org/W1596015467"],"abstract_inverted_index":{"The":[0,35,124,206],"software":[1,11,32],"security":[2,15,29],"issue":[3],"is":[4,208],"being":[5],"paid":[6],"great":[7],"attention":[8],"from":[9,152],"the":[10,41,47,57,67,99,113,117,120,133,138,141,146,153,156,167,172,180,183,190,203,219],"development":[12],"community":[13],"as":[14],"violations":[16],"have":[17],"emerged":[18],"variously.":[19],"Developers":[20],"often":[21],"use":[22],"access":[23,43,51,73,83,168,215],"control":[24,44,74,84],"techniques":[25],"to":[26,31,40,49,97,112,165,178,200],"restrict":[27],"some":[28],"breaches":[30],"systems\u2019":[33,72],"resources.":[34],"addition":[36],"of":[37,59,70,101,119,137,155,171,182,214],"authorization":[38],"constraints":[39],"role-based":[42],"model":[45],"increases":[46],"ability":[48],"express":[50],"rules":[52],"in":[53,104,129,132,189,218],"real-world":[54],"problems.":[55],"However,":[56],"complexity":[58],"combining":[60],"components,":[61],"libraries":[62],"and":[63,150,186],"programming":[64],"languages":[65],"during":[66],"implementation":[68,100,135],"stage":[69],"web":[71,105,157],"policies":[75,85],"may":[76],"arise":[77],"potential":[78],"flaws":[79,131],"that":[80],"make":[81],"applications\u2019":[82],"inconsistent":[86],"with":[87,211],"their":[88],"specifications.":[89],"In":[90],"this":[91],"paper,":[92],"we":[93,194],"introduce":[94],"an":[95],"approach":[96,125,142],"review":[98],"these":[102],"models":[103],"applications":[106],"written":[107],"by":[108],"Java":[109],"EE":[110],"according":[111],"MVC":[114],"architecture":[115],"under":[116],"support":[118,202],"Spring":[121],"Security":[122],"framework.":[123],"can":[126],"help":[127],"developers":[128],"detecting":[130],"assignment":[134],"process":[136],"models.":[139],"First,":[140],"focuses":[143],"on":[144],"extracting":[145],"information":[147],"about":[148],"users":[149],"roles":[151],"database":[154],"application.":[158,173],"We":[159],"then":[160],"analyze":[161],"policy":[162],"configuration":[163],"files":[164],"establish":[166],"analysis":[169],"tree":[170],"Next,":[174],"algorithms":[175],"are":[176],"introduced":[177],"validate":[179],"correctness":[181],"implemented":[184],"user-role":[185],"role-permission":[187],"assignments":[188],"application":[191],"system.":[192,223],"Lastly,":[193],"developed":[195],"a":[196,212],"tool":[197,207],"called":[198],"VeRA,":[199],"automatically":[201],"verification":[204],"process.":[205],"also":[209],"experimented":[210],"number":[213],"violation":[216],"scenarios":[217],"medical":[220],"record":[221],"management":[222]},"cited_by_api_url":"https://api.openalex.org/works?filter=cites:W3164231686","counts_by_year":[],"updated_date":"2024-12-06T03:46:52.156608","created_date":"2021-06-07"}