{"id":"https://openalex.org/W1989021503","doi":"https://doi.org/10.1145/1809100.1809108","title":"Towards formal specification and verification of a role-based authorization engine using JML","display_name":"Towards formal specification and verification of a role-based authorization engine using JML","publication_year":2010,"publication_date":"2010-05-02","ids":{"openalex":"https://openalex.org/W1989021503","doi":"https://doi.org/10.1145/1809100.1809108","mag":"1989021503"},"language":"en","primary_location":{"is_oa":false,"landing_page_url":"https://doi.org/10.1145/1809100.1809108","pdf_url":null,"source":null,"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":false},"type":"article","type_crossref":"proceedings-article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5063539879","display_name":"Tanveer Mustafa","orcid":null},"institutions":[{"id":"https://openalex.org/I180437899","display_name":"University of Bremen","ror":"https://ror.org/04ers2y35","country_code":"DE","type":"funder","lineage":["https://openalex.org/I180437899"]}],"countries":["DE"],"is_corresponding":false,"raw_author_name":"Tanveer Mustafa","raw_affiliation_strings":["Universit\u00e4t Bremen, Germany"],"affiliations":[{"raw_affiliation_string":"Universit\u00e4t Bremen, Germany","institution_ids":["https://openalex.org/I180437899"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5048791316","display_name":"Michael Drouineaud","orcid":null},"institutions":[{"id":"https://openalex.org/I180437899","display_name":"University of Bremen","ror":"https://ror.org/04ers2y35","country_code":"DE","type":"funder","lineage":["https://openalex.org/I180437899"]}],"countries":["DE"],"is_corresponding":false,"raw_author_name":"Michael Drouineaud","raw_affiliation_strings":["Universit\u00e4t Bremen, Germany"],"affiliations":[{"raw_affiliation_string":"Universit\u00e4t Bremen, Germany","institution_ids":["https://openalex.org/I180437899"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5052280722","display_name":"Karsten Sohr","orcid":"https://orcid.org/0000-0001-6781-4226"},"institutions":[{"id":"https://openalex.org/I180437899","display_name":"University of Bremen","ror":"https://ror.org/04ers2y35","country_code":"DE","type":"funder","lineage":["https://openalex.org/I180437899"]}],"countries":["DE"],"is_corresponding":false,"raw_author_name":"Karsten Sohr","raw_affiliation_strings":["Universit\u00e4t Bremen, Germany"],"affiliations":[{"raw_affiliation_string":"Universit\u00e4t Bremen, Germany","institution_ids":["https://openalex.org/I180437899"]}]}],"institution_assertions":[],"countries_distinct_count":1,"institutions_distinct_count":1,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":0.793,"has_fulltext":true,"fulltext_origin":"ngrams","cited_by_count":4,"citation_normalized_percentile":{"value":0.82177,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":77,"max":79},"biblio":{"volume":null,"issue":null,"first_page":"50","last_page":"57"},"is_retracted":false,"is_paratext":false,"primary_topic":{"id":"https://openalex.org/T10927","display_name":"Access Control and Trust","score":0.9995,"subfield":{"id":"https://openalex.org/subfields/3312","display_name":"Sociology and Political Science"},"field":{"id":"https://openalex.org/fields/33","display_name":"Social Sciences"},"domain":{"id":"https://openalex.org/domains/2","display_name":"Social Sciences"}},"topics":[{"id":"https://openalex.org/T10927","display_name":"Access Control and Trust","score":0.9995,"subfield":{"id":"https://openalex.org/subfields/3312","display_name":"Sociology and Political Science"},"field":{"id":"https://openalex.org/fields/33","display_name":"Social Sciences"},"domain":{"id":"https://openalex.org/domains/2","display_name":"Social Sciences"}},{"id":"https://openalex.org/T11424","display_name":"Security and Verification in Computing","score":0.9984,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10126","display_name":"Logic, programming, and type systems","score":0.9944,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/design-by-contract","display_name":"Design by contract","score":0.44153804}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.8350366},{"id":"https://openalex.org/C527821871","wikidata":"https://www.wikidata.org/wiki/Q228502","display_name":"Access control","level":2,"score":0.64133656},{"id":"https://openalex.org/C45567728","wikidata":"https://www.wikidata.org/wiki/Q1702839","display_name":"Role-based access control","level":3,"score":0.63429224},{"id":"https://openalex.org/C116253237","wikidata":"https://www.wikidata.org/wiki/Q1437424","display_name":"Formal specification","level":2,"score":0.5480955},{"id":"https://openalex.org/C199360897","wikidata":"https://www.wikidata.org/wiki/Q9143","display_name":"Programming language","level":1,"score":0.5109312},{"id":"https://openalex.org/C55439883","wikidata":"https://www.wikidata.org/wiki/Q360812","display_name":"Correctness","level":2,"score":0.49505988},{"id":"https://openalex.org/C201677973","wikidata":"https://www.wikidata.org/wiki/Q1209840","display_name":"Specification language","level":2,"score":0.4905538},{"id":"https://openalex.org/C75606506","wikidata":"https://www.wikidata.org/wiki/Q1049183","display_name":"Formal methods","level":2,"score":0.49038243},{"id":"https://openalex.org/C115903868","wikidata":"https://www.wikidata.org/wiki/Q80993","display_name":"Software engineering","level":1,"score":0.46811336},{"id":"https://openalex.org/C548217200","wikidata":"https://www.wikidata.org/wiki/Q251","display_name":"Java","level":2,"score":0.45178446},{"id":"https://openalex.org/C80291951","wikidata":"https://www.wikidata.org/wiki/Q1200691","display_name":"Design by contract","level":5,"score":0.44153804},{"id":"https://openalex.org/C529173508","wikidata":"https://www.wikidata.org/wiki/Q638608","display_name":"Software development","level":3,"score":0.32867986},{"id":"https://openalex.org/C2777904410","wikidata":"https://www.wikidata.org/wiki/Q7397","display_name":"Software","level":2,"score":0.3280155},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.2566129},{"id":"https://openalex.org/C186846655","wikidata":"https://www.wikidata.org/wiki/Q3398377","display_name":"Software construction","level":4,"score":0.10012981}],"mesh":[],"locations_count":1,"locations":[{"is_oa":false,"landing_page_url":"https://doi.org/10.1145/1809100.1809108","pdf_url":null,"source":null,"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":false}],"best_oa_location":null,"sustainable_development_goals":[{"id":"https://metadata.un.org/sdg/17","score":0.44,"display_name":"Partnerships for the goals"}],"grants":[],"datasets":[],"versions":[],"referenced_works_count":15,"referenced_works":["https://openalex.org/W1509562505","https://openalex.org/W1551782231","https://openalex.org/W1559377248","https://openalex.org/W1583826417","https://openalex.org/W1606010048","https://openalex.org/W1964830323","https://openalex.org/W1993836075","https://openalex.org/W2084963982","https://openalex.org/W2094160561","https://openalex.org/W2103317919","https://openalex.org/W2109879514","https://openalex.org/W2134167896","https://openalex.org/W2144973245","https://openalex.org/W2166602595","https://openalex.org/W2798338883"],"related_works":["https://openalex.org/W4252905370","https://openalex.org/W4251666556","https://openalex.org/W2607268704","https://openalex.org/W2238880588","https://openalex.org/W2204176978","https://openalex.org/W2156223462","https://openalex.org/W2049993111","https://openalex.org/W2044067585","https://openalex.org/W2034589735","https://openalex.org/W1916258364"],"abstract_inverted_index":{"Employing":[0],"flexible":[1,108],"access":[2,32,43,48,74],"control":[3,33,44,49],"mechanisms,":[4],"formally":[5],"specifying":[6,162],"and":[7,13,60,70,177],"correctly":[8],"implementing":[9],"relevant":[10],"security":[11],"properties,":[12],"ensuring":[14],"that":[15,34,87,114],"the":[16,25,36,42,46,73,79,96,99,163,167,187,190,193],"implementation":[17,191],"satisfies":[18],"its":[19,197],"formal":[20,109],"specification,":[21],"are":[22],"some":[23],"of":[24,38,68,78,82,145,166,189,192],"important":[26,80],"aspects":[27,81],"towards":[28,185],"achieving":[29],"higher-level":[30,62],"organization-wide":[31],"maintains":[35],"characteristics":[37],"software":[39,127],"quality.":[40],"In":[41,131],"arena,":[45],"role-based":[47,147],"(RBAC)":[50],"has":[51,104],"emerged":[52],"as":[53,66,106,118,137,174],"a":[54,107,119,138,143,146],"powerful":[55],"model":[56],"for":[57,71,125],"laying":[58],"out":[59],"developing":[61,126],"organizational":[63,93],"rules":[64],"such":[65,92,173],"separation":[67],"duty,":[69],"simplifying":[72],"management":[75],"process.":[76],"One":[77],"RBAC":[83],"is":[84],"authorization":[85,148,168,175,194],"constraints":[86,172,176],"allow":[88],"one":[89],"to":[90,141],"express":[91],"rules.":[94],"On":[95],"other":[97],"hand,":[98],"Java":[100],"Modeling":[101],"Language":[102],"(JML)":[103],"evolved":[105],"behavioral":[110],"interface":[111],"specification":[112],"language":[113],"can":[115,156],"be":[116,158],"used":[117,159],"Design":[120],"by":[121],"Contract":[122],"(DBC)":[123],"approach":[124,140],"written":[128],"in":[129,160],"Java.":[130],"this":[132],"paper,":[133],"we":[134],"adopt":[135],"JML":[136,155,183,198],"DBC":[139],"implement":[142],"prototype":[144],"engine.":[149],"We":[150,180],"specifically":[151],"focus":[152],"on":[153],"how":[154],"effectively":[157],"precisely":[161],"functional":[164],"behavior":[165],"engine,":[169],"including":[170],"various":[171],"integrity":[178],"constraints.":[179],"employ":[181],"few":[182],"tools":[184],"verifying":[186],"correctness":[188],"engine":[195],"against":[196],"specification.":[199]},"abstract_inverted_index_v3":null,"cited_by_api_url":"https://api.openalex.org/works?filter=cites:W1989021503","counts_by_year":[{"year":2018,"cited_by_count":1},{"year":2017,"cited_by_count":1}],"updated_date":"2025-03-15T21:16:18.701961","created_date":"2016-06-24"}