{"id":"https://openalex.org/W2006652217","doi":"https://doi.org/10.1145/2133601.2133611","title":"On practical specification and enforcement of obligations","display_name":"On practical specification and enforcement of obligations","publication_year":2012,"publication_date":"2012-02-07","ids":{"openalex":"https://openalex.org/W2006652217","doi":"https://doi.org/10.1145/2133601.2133611","mag":"2006652217"},"language":"en","primary_location":{"id":"doi:10.1145/2133601.2133611","is_oa":false,"landing_page_url":"https://doi.org/10.1145/2133601.2133611","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the second ACM conference on Data and Application Security and Privacy","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5101471208","display_name":"Ninghui Li","orcid":"https://orcid.org/0000-0001-8207-9717"},"institutions":[{"id":"https://openalex.org/I219193219","display_name":"Purdue University West Lafayette","ror":"https://ror.org/02dqehb95","country_code":"US","type":"education","lineage":["https://openalex.org/I219193219"]}],"countries":["US"],"is_corresponding":true,"raw_author_name":"Ninghui Li","raw_affiliation_strings":["Purdue University, West Lafayette, IN, USA"],"affiliations":[{"raw_affiliation_string":"Purdue University, West Lafayette, IN, USA","institution_ids":["https://openalex.org/I219193219"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5063727322","display_name":"Hai\u2010Ning Chen","orcid":"https://orcid.org/0000-0003-0104-8498"},"institutions":[{"id":"https://openalex.org/I219193219","display_name":"Purdue University West Lafayette","ror":"https://ror.org/02dqehb95","country_code":"US","type":"education","lineage":["https://openalex.org/I219193219"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Haining Chen","raw_affiliation_strings":["Purdue University, West Lafayette, IN, USA"],"affiliations":[{"raw_affiliation_string":"Purdue University, West Lafayette, IN, USA","institution_ids":["https://openalex.org/I219193219"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5061694501","display_name":"Elisa Bertino","orcid":"https://orcid.org/0000-0002-4029-7051"},"institutions":[{"id":"https://openalex.org/I219193219","display_name":"Purdue University West Lafayette","ror":"https://ror.org/02dqehb95","country_code":"US","type":"education","lineage":["https://openalex.org/I219193219"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Elisa Bertino","raw_affiliation_strings":["Purdue University, West Lafayette, IN, USA"],"affiliations":[{"raw_affiliation_string":"Purdue University, West Lafayette, IN, USA","institution_ids":["https://openalex.org/I219193219"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":3,"corresponding_author_ids":["https://openalex.org/A5101471208"],"corresponding_institution_ids":["https://openalex.org/I219193219"],"apc_list":null,"apc_paid":null,"fwci":12.6019,"has_fulltext":false,"cited_by_count":30,"citation_normalized_percentile":{"value":0.98174536,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":89,"max":98},"biblio":{"volume":null,"issue":null,"first_page":"71","last_page":"82"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10927","display_name":"Access Control and Trust","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/3312","display_name":"Sociology and Political Science"},"field":{"id":"https://openalex.org/fields/33","display_name":"Social Sciences"},"domain":{"id":"https://openalex.org/domains/2","display_name":"Social Sciences"}},"topics":[{"id":"https://openalex.org/T10927","display_name":"Access Control and Trust","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/3312","display_name":"Sociology and Political Science"},"field":{"id":"https://openalex.org/fields/33","display_name":"Social Sciences"},"domain":{"id":"https://openalex.org/domains/2","display_name":"Social Sciences"}},{"id":"https://openalex.org/T11424","display_name":"Security and Verification in Computing","score":0.9980000257492065,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T13999","display_name":"Digital Rights Management and Security","score":0.9977999925613403,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/xacml","display_name":"XACML","score":0.9807697534561157},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.7741918563842773},{"id":"https://openalex.org/keywords/access-control","display_name":"Access control","score":0.6932947039604187},{"id":"https://openalex.org/keywords/markup-language","display_name":"Markup language","score":0.6045858860015869},{"id":"https://openalex.org/keywords/obligation","display_name":"Obligation","score":0.5548025965690613},{"id":"https://openalex.org/keywords/enforcement","display_name":"Enforcement","score":0.5306032299995422},{"id":"https://openalex.org/keywords/architecture","display_name":"Architecture","score":0.4515385925769806},{"id":"https://openalex.org/keywords/xml","display_name":"XML","score":0.4294503927230835},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.4258069097995758},{"id":"https://openalex.org/keywords/software-engineering","display_name":"Software engineering","score":0.3865607976913452},{"id":"https://openalex.org/keywords/world-wide-web","display_name":"World Wide Web","score":0.2807677388191223}],"concepts":[{"id":"https://openalex.org/C2779886121","wikidata":"https://www.wikidata.org/wiki/Q288682","display_name":"XACML","level":3,"score":0.9807697534561157},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7741918563842773},{"id":"https://openalex.org/C527821871","wikidata":"https://www.wikidata.org/wiki/Q228502","display_name":"Access control","level":2,"score":0.6932947039604187},{"id":"https://openalex.org/C45874996","wikidata":"https://www.wikidata.org/wiki/Q37045","display_name":"Markup language","level":3,"score":0.6045858860015869},{"id":"https://openalex.org/C2778447849","wikidata":"https://www.wikidata.org/wiki/Q2648051","display_name":"Obligation","level":2,"score":0.5548025965690613},{"id":"https://openalex.org/C2779777834","wikidata":"https://www.wikidata.org/wiki/Q4202277","display_name":"Enforcement","level":2,"score":0.5306032299995422},{"id":"https://openalex.org/C123657996","wikidata":"https://www.wikidata.org/wiki/Q12271","display_name":"Architecture","level":2,"score":0.4515385925769806},{"id":"https://openalex.org/C8797682","wikidata":"https://www.wikidata.org/wiki/Q2115","display_name":"XML","level":2,"score":0.4294503927230835},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.4258069097995758},{"id":"https://openalex.org/C115903868","wikidata":"https://www.wikidata.org/wiki/Q80993","display_name":"Software engineering","level":1,"score":0.3865607976913452},{"id":"https://openalex.org/C136764020","wikidata":"https://www.wikidata.org/wiki/Q466","display_name":"World Wide Web","level":1,"score":0.2807677388191223},{"id":"https://openalex.org/C153349607","wikidata":"https://www.wikidata.org/wiki/Q36649","display_name":"Visual arts","level":1,"score":0.0},{"id":"https://openalex.org/C142362112","wikidata":"https://www.wikidata.org/wiki/Q735","display_name":"Art","level":0,"score":0.0},{"id":"https://openalex.org/C199539241","wikidata":"https://www.wikidata.org/wiki/Q7748","display_name":"Law","level":1,"score":0.0},{"id":"https://openalex.org/C17744445","wikidata":"https://www.wikidata.org/wiki/Q36442","display_name":"Political science","level":0,"score":0.0}],"mesh":[],"locations_count":3,"locations":[{"id":"doi:10.1145/2133601.2133611","is_oa":false,"landing_page_url":"https://doi.org/10.1145/2133601.2133611","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the second ACM conference on Data and Application Security and Privacy","raw_type":"proceedings-article"},{"id":"pmh:oai:docs.lib.purdue.edu:ccpubs-1452","is_oa":false,"landing_page_url":"https://docs.lib.purdue.edu/ccpubs/459","pdf_url":null,"source":{"id":"https://openalex.org/S4377196310","display_name":"Purdue e-Pubs (Purdue University System)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I2801333002","host_organization_name":"Purdue University System","host_organization_lineage":["https://openalex.org/I2801333002"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"Cyber Center Publications","raw_type":"text"},{"id":"pmh:oai:docs.lib.purdue.edu:ccpubs-1486","is_oa":false,"landing_page_url":"https://docs.lib.purdue.edu/ccpubs/479","pdf_url":null,"source":{"id":"https://openalex.org/S4377196310","display_name":"Purdue e-Pubs (Purdue University System)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I2801333002","host_organization_name":"Purdue University System","host_organization_lineage":["https://openalex.org/I2801333002"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"Cyber Center Publications","raw_type":"text"}],"best_oa_location":null,"sustainable_development_goals":[{"display_name":"Peace, Justice and strong institutions","score":0.800000011920929,"id":"https://metadata.un.org/sdg/16"}],"awards":[],"funders":[{"id":"https://openalex.org/F4320306076","display_name":"National Science Foundation","ror":"https://ror.org/021nxhr62"},{"id":"https://openalex.org/F4320333591","display_name":"Multidisciplinary University Research Initiative","ror":null},{"id":"https://openalex.org/F4320338279","display_name":"Air Force Office of Scientific Research","ror":"https://ror.org/011e9bt93"}],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":21,"referenced_works":["https://openalex.org/W152476282","https://openalex.org/W308036227","https://openalex.org/W1504714130","https://openalex.org/W1544658515","https://openalex.org/W1986789244","https://openalex.org/W2017960359","https://openalex.org/W2042065342","https://openalex.org/W2065076704","https://openalex.org/W2068189899","https://openalex.org/W2080649936","https://openalex.org/W2095881341","https://openalex.org/W2106465551","https://openalex.org/W2115853608","https://openalex.org/W2121381561","https://openalex.org/W2128121494","https://openalex.org/W2139850616","https://openalex.org/W2162737732","https://openalex.org/W2163595397","https://openalex.org/W2164441047","https://openalex.org/W2168884369","https://openalex.org/W2900489216"],"related_works":["https://openalex.org/W2298494124","https://openalex.org/W2125405387","https://openalex.org/W2351416088","https://openalex.org/W3144583911","https://openalex.org/W2349247816","https://openalex.org/W2198182223","https://openalex.org/W2114574764","https://openalex.org/W1552878720","https://openalex.org/W130718849","https://openalex.org/W2348423860"],"abstract_inverted_index":{"Obligations":[0],"are":[1,140],"an":[2,86,121],"important":[3],"and":[4,20,90,109,112,120,134,152],"indispensable":[5],"part":[6,72],"of":[7,73,200],"many":[8],"access":[9,32,63,125,149],"control":[10,33,64,126,150],"policies,":[11,65],"such":[12,44],"as":[13,70,80,142],"those":[14],"in":[15,29,102,177],"DRM":[16],"(Digital":[17],"Rights":[18],"Management)":[19],"healthcare":[21],"information":[22],"systems.":[23],"To":[24],"be":[25,183],"able":[26],"use":[27],"obligations":[28,69,78,139,191],"a":[30,38,45,71,104,115,164],"real-world":[31],"system,":[34],"there":[35],"must":[36],"exist":[37],"language":[39,46,116],"for":[40,61,107,117,123,192],"specifying":[41,62,84,108,118],"obligations.":[42],"However,":[43],"is":[47,175],"currently":[48],"lacking.":[49],"XACML":[50,172],"(eXtensible":[51],"Access":[52],"Control":[53],"Markup":[54],"Language),":[55],"the":[56,100,148,153,186,197],"current":[57],"de":[58],"facto":[59],"standard":[60],"seems":[66],"to":[67,92,188],"integrate":[68],"it,":[74],"but":[75],"it":[76],"treats":[77],"largely":[79],"black":[81],"boxes,":[82],"without":[83],"what":[85],"obligation":[87,180],"should":[88],"include":[89],"how":[91],"handle":[93,189],"them.":[94],"In":[95,136],"this":[96],"paper":[97],"we":[98],"examine":[99],"challenges":[101],"designing":[103],"practical":[105],"approach":[106],"handling":[110,124],"obligations,":[111,119,130],"then":[113],"propose":[114],"architecture":[122],"policies":[127],"with":[128,147],"these":[129],"extending":[131],"XACML's":[132],"specification":[133],"architecture.":[135],"our":[137,161,201],"design,":[138],"modeled":[141],"state":[143],"machines":[144],"which":[145,195],"communicate":[146],"system":[151,166,187],"outside":[154],"world":[155],"via":[156],"events.":[157],"We":[158],"further":[159],"implement":[160],"design":[162],"into":[163,185],"prototype":[165],"named":[167],"ExtXACML,":[168],"based":[169],"on":[170],"SUN's":[171],"implementation.":[173],"ExtXACML":[174],"extensible":[176],"that":[178],"new":[179],"modules":[181],"can":[182],"added":[184],"various":[190],"different":[193],"applications,":[194],"shows":[196],"strong":[198],"power":[199],"design.":[202]},"counts_by_year":[{"year":2025,"cited_by_count":1},{"year":2024,"cited_by_count":2},{"year":2023,"cited_by_count":4},{"year":2022,"cited_by_count":2},{"year":2020,"cited_by_count":1},{"year":2018,"cited_by_count":3},{"year":2017,"cited_by_count":2},{"year":2016,"cited_by_count":2},{"year":2015,"cited_by_count":4},{"year":2014,"cited_by_count":2},{"year":2013,"cited_by_count":4},{"year":2012,"cited_by_count":3}],"updated_date":"2026-03-20T23:20:44.827607","created_date":"2025-10-10T00:00:00"}
