  1. James B. D. Joshi, Walid G. Aref, Arif Ghafoor and Eugene H. Spafford, "Security models for web-based applications", Communications of the ACM , 44, 2 (Feb. 2001), Page 38-44. (PDF version).
  2. Ravi S. Sandhu, Pierangela Samarati, “Access Control: Principles and Practice”, IEEE Communications Magazine, September 1994. (PDF version)
  3. S. Osborn, R. Sandhu, Q. Munawer, “Configuring Role-Based Access Control to Enforce Mandatory and Discretionary Access Control Policies”, ACM Transaction on Information and System Security, May 2000. (PDF version)

