英文部分:
1. Simon Godik, Tim Moses, ”OASIS eXtensible Access Control Markup Language(XACML)”, OASIS, December 2002
2. ”Information technology – Open Systems Interconnection – Security Framework for Open Sytem: Access Control Framework”, ISOI/IEC 10181-3(1996), 1996
3. Ravi Sandhu, Edward J. Coyne, Hal L. Feinstein, and Charles E. Youman. ”Role-Based Access Control Model”, IEEE Computer, 29(2):38-47, February 1996.
4. Michiharu Kudo, ” XACML Use Case for XML Fine-grained Access Control”, OASIS, March 2002
5. Rebecca Wirfs-Brock, Alan McKean, ”Object Design Roles, Responsibilities, and Collaborations”, Addison Wesley, November 2002
6. Craig Larman, ”Applying UML and Patterns”, PHPTR, 2002
7. George T. Heineman, William T. Councill, ”Component-Based Software Engineering” , Addison Wesley, May 2001
8. Mohamed E. Fayad, Douglas C. Schmidt, Ralph E. Johnson, ”Building Application Frameworks” , John Wiley & Sons, 1999
9. Ernesto Damiani, Sabrina De Capitani Di Vimecati, Stefano Paraboshi, Pierangela Samarati, “A Fine-Grained Access Control System for XML Documents”, ACM Transactions on Information and System Security, Vol.5, No. 2,Page 169-202, May 2002
10. Carlisle Adams, Zahid Ahmed , etc., ”OASIS Security Services TC:Glossary”, OASIS, 30 Mar 2002
11. Satoshi Hada, Michiharu Kudo,”XML Access Control Language:Provisional Authorization for XML Documents”, Tokyo Research Laboratory, IBM Research, 16 October 2000
12. Ernesto Daminani, Sabrina De Capitani Di Vimercti, etc., “XML Access Control : A Fine-Grained Access Control System”, http://seclab.dti.unimi.it/~xml-sec/Dr PhillipM. Hallam-Baker, “Web Services Security Standards Forum”, VeriSign Inc.
14. G.S.Grabam and P.J.Denning. “Protection – principlesand practice.”, Proc.Spring Jt. Computer Conf., 40:417-429, 1972.
15. Ravi Sandhu, David Ferraiolo and Richard Kuhn, “The NIST Model for Role-Based Access Control : Towards A Unified Standard”, In Proceedings of the fifth ACM Workshop on Role-Based Access Control, Berlin Germany, pages 47-63, July 26-28 2000. ACM
中文部分
16. 劉興華、黃景彰,”執行權管制系統的設計標準 – ISO/IEC 10181-3”,中華民國資訊學會通訊,pp.13-20,民八十八年九月17. 樊國楨、陳祥輝、蔡敦仁,”資料庫濫用軌跡塑模”,電腦與通訊,pp.62-69,民八十九年十二月18. 施淵仁,”具流程管理機制之工作存取權限控制模型之研究”,私立元智大學電機暨資訊工程研究所碩士論文, 民八十九年六月19. 張淑惠,”職位基礎執行權管制模式之系統設計及實作研究 – 以銀行放款業務為例”,國立交通大學資訊管理研究所碩士論文,民九十年七月20. 洪敏翔,”使用XML設計執行權管制資訊流”,國立交通大學資訊管理研究所碩士論文,民九十年七月21. 俞正宏,”應用XML/XACML於工作流程管理系統之授權管制研究”,國立中央大學資訊管理研究所碩士論文,民九十一年六月22. 張裕益譯,”UML使用手冊”,博碩文化,民九十年十一月
23. 巫坤品、曾志光譯,”密碼學與網路安全-原理與實務”,碁峰,民九十年九月
24. 侯捷、王建興譯,”Thinking in Java 中文版”,碁峰,民九十一年七月
25. 高煥堂、王克明,“跨Subsystem的大型系統開發實務”,MISOO物件導向雜誌,pp.115-149,民九十一年七月
26. 葉秉哲譯,”物件導向設計模式”,培生,民九十年二月