{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,9]],"date-time":"2026-06-09T08:45:42Z","timestamp":1780994742072,"version":"3.54.1"},"publisher-location":"Berlin, Heidelberg","reference-count":52,"publisher":"Springer Berlin Heidelberg","isbn-type":[{"value":"9783540206323","type":"print"},{"value":"9783540409656","type":"electronic"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2003]]},"DOI":"10.1007\/978-3-540-40965-6_15","type":"book-chapter","created":{"date-parts":[[2011,1,7]],"date-time":"2011-01-07T15:52:14Z","timestamp":1294415534000},"page":"224-242","source":"Crossref","is-referenced-by-count":20,"title":["Paradigm Regained: Abstraction Mechanisms for Access Control"],"prefix":"10.1007","author":[{"given":"Mark S.","family":"Miller","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Jonathan S.","family":"Shapiro","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","reference":[{"key":"15_CR1","volume-title":"Structure and Interpretation of Computer Programs","author":"H. Abelson","year":"1986","unstructured":"Abelson, H., Sussman, G.: Structure and Interpretation of Computer Programs. MIT Press, Cambridge (1986)"},{"key":"15_CR2","unstructured":"Bell, D.E., LaPadula, L.: Secure Computer Systems. ESD-TR-83-278, Mitre Corporation, vI and II (November 1973), vIII (April 1974)"},{"key":"15_CR3","doi-asserted-by":"crossref","unstructured":"Bishop, M., Snyder, L.: The Transfer of Information and Authority in a Protection System. In: SOSP 1979, pp. 45\u201354 (1979)","DOI":"10.1145\/800215.806569"},{"key":"15_CR4","unstructured":"Boebert, W.E.: On the Inability of an Unmodified Capability Machine to Enforce the *-Property. In: Proceedings of 7th DoD\/NBS Computer Security Conference, September 1984, pp. 291\u2013293 (1984), http:\/\/zesty.ca\/capmyths\/boebert.html"},{"key":"15_CR5","unstructured":"(Comments on [Miller03]) http:\/\/www.eros-os.org\/pipermail\/cap-talk\/2003-March\/ 001133.html"},{"key":"15_CR6","doi-asserted-by":"crossref","unstructured":"Cartwright, R., Fagan, M.: Soft Typing. In: Proceedings of the SIGPLAN 1991 Conference on Programming Language Design and Implementation (1991)","DOI":"10.1145\/113445.113469"},{"key":"15_CR7","doi-asserted-by":"crossref","unstructured":"Chander, A., Dean, D., Mitchell, J.C.: A State-Transition Model of Trust Management and Access Control. In: Proceedings of the 14th Computer Security Foundations Workshop, June 2001, pp. 27\u201343 (2001)","DOI":"10.1109\/CSFW.2001.930134"},{"key":"15_CR8","unstructured":"Crockford, D.: Personal Communications (1997)"},{"issue":"3","key":"15_CR9","doi-asserted-by":"publisher","first-page":"143","DOI":"10.1145\/365230.365252","volume":"9","author":"J.B. Dennis","year":"1966","unstructured":"Dennis, J.B., Van Horn, E.C.: Programming Semantics for Multiprogrammed Computations. Communications of the ACM\u00a09(3), 143\u2013155 (1966)","journal-title":"Communications of the ACM"},{"key":"15_CR10","doi-asserted-by":"crossref","unstructured":"Donnelley, J.E.: A Distributed Capability Computing System. In: Third International Conference on Computer Communication, Toronto, Canada (1976)","DOI":"10.17487\/rfc0712"},{"key":"15_CR11","doi-asserted-by":"crossref","unstructured":"van Doorn, L., Abadi, M., Burrows, M., Wobber, E.P.: Secure Network Objects. In: Proceedings of the 1996 IEEE Symposium on Security and Privacy, pp. 211\u2013221 (1996)","DOI":"10.1109\/SECPRI.1996.502683"},{"issue":"7","key":"15_CR12","doi-asserted-by":"publisher","first-page":"403","DOI":"10.1145\/361011.361070","volume":"17","author":"R.S. Fabry","year":"1974","unstructured":"Fabry, R.S.: Capability-based addressing. Communications of the ACM\u00a017(7), 403\u2013412 (1974)","journal-title":"Communications of the ACM"},{"key":"15_CR13","unstructured":"Goldberg, A., Kay, A.: Smalltalk-72 instruction manual. Technical Report SSL 76-6, Learning Research Group, Xerox Palo, Alto Research Center (1976), http:\/\/www.spies.com\/~aek\/pdf\/xerox\/alto\/Smalltalk72_Manual.pdf"},{"key":"15_CR14","doi-asserted-by":"crossref","unstructured":"Gong, L.: A Secure Identity-Based Capability System. In: Proceedings of the 1989 IEEE Symposium on Security and Privacy, pp. 56\u201365 (1989)","DOI":"10.1109\/SECPRI.1989.36277"},{"key":"15_CR15","doi-asserted-by":"crossref","unstructured":"Hardy, N.: The KeyKOS Architecture. ACM Operating Systems Review, pp. 8\u201325 (September 1985), http:\/\/www.agorics.com\/Library\/KeyKos\/architecture.html","DOI":"10.1145\/858336.858337"},{"key":"15_CR16","unstructured":"Hardy, N.: U.S. Patent 4,584,639: Computer Security System,"},{"issue":"8","key":"15_CR17","doi-asserted-by":"publisher","first-page":"461","DOI":"10.1145\/360303.360333","volume":"19","author":"M.A. Harrison","year":"1976","unstructured":"Harrison, M.A., Ruzzo, M.L., Ullman, J.D.: Protection in operating systems. Communications of the ACM\u00a019(8), 461\u2013471 (1976)","journal-title":"Communications of the ACM"},{"key":"15_CR18","unstructured":"Hewitt, C., Bishop, P., Stieger, R.: A Universal Modular Actor Formalism for Artificial Intelligence. In: Proceedings of the 1973 International Joint Conference on Artificial Intelligence, pp. 235\u2013246 (1973)"},{"key":"15_CR19","doi-asserted-by":"crossref","unstructured":"Jones, A.K., Lipton, R.J., Snyder, L.: A Linear Time Algorithm for Deciding Security. FOCS, 33\u201341 (1976)","DOI":"10.1109\/SFCS.1976.1"},{"key":"15_CR20","volume-title":"Ecology of Computation","author":"K. Kahn","year":"1988","unstructured":"Kahn, K., Miller, M.S.: Language Design and Open Systems. In: Huberman, B. (ed.) Ecology of Computation. Elsevier Science Publishers, North-Holland (1988)"},{"key":"15_CR21","doi-asserted-by":"crossref","unstructured":"Kain, R.Y., Landwehr, C.E.: On Access Checking in Capability-Based Systems. In: IEEE Symposium on Security and Privacy (1987)","DOI":"10.21236\/ADA462757"},{"key":"15_CR22","doi-asserted-by":"crossref","unstructured":"Karger, P.A., Herbert, A.J.: An Augmented Capability Architecture to Support Lattice Security and Traceability of Access. In: Proc. of the 1984 IEEE Symposium on Security and Privacy, pp. 2\u201312 (1984)","DOI":"10.1109\/SP.1984.10001"},{"key":"15_CR23","unstructured":"Kelsey, R., Clinger, W., Rees, J. (eds.): Revised5\u0302 Report on the Algorithmic Language Scheme. ACM Sigplan Notices (1998)"},{"key":"15_CR24","doi-asserted-by":"crossref","unstructured":"Lampson, B.W.: A Note on the Confinement Problem. CACM on Operating Systems\u00a016(10) (October 1973)","DOI":"10.1145\/362375.362389"},{"key":"15_CR25","volume-title":"Concurrent Prolog: Collected Papers","author":"M.S. Miller","year":"1987","unstructured":"Miller, M.S., Bobrow, D.G., Tribble, E.D., Levy, J.: Logical Secrets. In: Shapiro, E. (ed.) Concurrent Prolog: Collected Papers. MIT Press, Cambridge (1987)"},{"key":"15_CR26","volume-title":"Market-based Control, A Paradigm for Distributed Resource Allocation","author":"M.S. Miller","year":"1996","unstructured":"Miller, M.S., Krieger, D., Hardy, N., Hibbert, C., Tribble, E.D.: An Automatic Auction in ATM Network Bandwidth. In: Clearwater, S.H. (ed.) Market-based Control, A Paradigm for Distributed Resource Allocation. World Scientific, Palo Alto (1996)"},{"key":"15_CR27","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"349","DOI":"10.1007\/3-540-45472-1_24","volume-title":"Financial Cryptography","author":"M.S. Miller","year":"2001","unstructured":"Miller, M.S., Morningstar, C., Frantz, B.: Capability-based Financial Instruments. In: Frankel, Y. (ed.) FC 2000. LNCS, vol.\u00a01962, p. 349. Springer, Heidelberg (2001), http:\/\/www.erights.org\/elib\/capability\/ode\/index.html"},{"key":"15_CR28","unstructured":"Miller, M.S., Yee, K. -P., Shapiro, J. S.: Capability Myths Demolished, HP Labs Technical Report (in preparation), http:\/\/zesty.ca\/capmyths\/usenix.pdf"},{"issue":"1","key":"15_CR29","doi-asserted-by":"crossref","first-page":"15","DOI":"10.1145\/361932.361937","volume":"16","author":"J.H. Morris","year":"1973","unstructured":"Morris, J.H.: Protection in Programming Languages. CACM\u00a016(1), 15\u201321 (1973), http:\/\/www.erights.org\/history\/morris73.pdf","journal-title":"CACM"},{"key":"15_CR30","unstructured":"Motwani, R., Panigrahy, R., Saraswat, V., Venkatasubramanian, S.: On the Decidability of Accessibility Problems. AT&T Labs \u2013 Research, http:\/\/www.research.att.com\/~suresh\/Papers\/java.pdf"},{"key":"15_CR31","unstructured":"Neumann, P.G., Boyer, R.S., Feiertag, R.J., Levitt, K.N., Robinson, L.: A Provably Secure Operating System: The System, Its Applications, and Proofs, CSL-116, Computer Science Laboratory, SRI International, Inc. (May 1980)"},{"key":"15_CR32","doi-asserted-by":"crossref","unstructured":"Parnas, D.: On the Criteria To Be Used in Decomposing Systems into Modules. CACM\u00a015(12) (December 1972), http:\/\/www.acm.org\/classics\/may96\/","DOI":"10.1145\/361598.361623"},{"key":"15_CR33","unstructured":"Rajunas, S.A.: The KeyKOS\/KeySAFE System Design. Key Logic, Inc., SEC009-01 (March 1989)"},{"key":"15_CR34","unstructured":"Redell, D.D.: Naming and Protection in Extendible Operating Systems. Project MAC TR-140, MIT (Ph. D. thesis.) (November 1974)"},{"key":"15_CR35","volume-title":"A Security Kernel Based on the Lambda-Calculus. MIT AI Memo No. 1564","author":"J. Rees","year":"1996","unstructured":"Rees, J.: A Security Kernel Based on the Lambda-Calculus. MIT AI Memo No. 1564. MIT, Cambridge (1996), http:\/\/mumble.net\/jar\/pubs\/secureos\/"},{"key":"15_CR36","first-page":"271","volume-title":"Information Processing 1986","author":"M. Safra","year":"1986","unstructured":"Safra, M., Shapiro, E.Y.: Meta Interpreters for Real. In: Kugler, H.-J. (ed.) Information Processing 1986, pp. 271\u2013278. North-Holland, Amsterdam (1986)"},{"issue":"9","key":"15_CR37","doi-asserted-by":"publisher","first-page":"1278","DOI":"10.1109\/PROC.1975.9939","volume":"63","author":"J.H. Saltzer","year":"1975","unstructured":"Saltzer, J.H., Schroeder, M.D.: The Protection of Information in Computer Systems. Proceedings of the IEEE\u00a063(9), 1278\u20131308 (1975)","journal-title":"Proceedings of the IEEE"},{"key":"15_CR38","doi-asserted-by":"crossref","unstructured":"Sansom, R.D., Julian, D.P., Rashid, R.: Extending a Capability Based System Into a Network Environment. Research sponsored by DOD, pp. 265\u2013274 (1986)","DOI":"10.1145\/1013812.18202"},{"key":"15_CR39","unstructured":"Saraswat, V., Jagadeesan, R.: Static support for capability-based programming in Java, http:\/\/www.cse.psu.edu\/~araswat\/neighborhood.pdf"},{"key":"15_CR40","doi-asserted-by":"crossref","unstructured":"Shapiro, J.S., Smith, J.M., Farber, D.J.: EROS: A Fast Capability System. In: Proceedings of the 17th ACM Symposium on Operating Systems Principles, December 1999, pp. 170\u2013185 (1999)","DOI":"10.1145\/319151.319163"},{"key":"15_CR41","doi-asserted-by":"crossref","unstructured":"Shapiro, J.S., Weber, S.: Verifying the EROS Confinement Mechanism. In: Proceedings of the 2000 IEEE Symposium on Security and Privacy, pp. 166\u2013176 (2000)","DOI":"10.1109\/SECPRI.2000.848454"},{"key":"15_CR42","unstructured":"Sitaker, K.: Thoughts on Capability Security on the Web, http:\/\/lists.canonical.org\/pipermail\/kragen-tol\/2000-August\/000619.html"},{"key":"15_CR43","unstructured":"Stiegler, M., Miller, M.: A Capability Based Client: The DarpaBrowser, http:\/\/www.combex.com\/papers\/darpa-report\/index.html"},{"key":"15_CR44","unstructured":"Tanenbaum, A.S., Mullender, S.J., van Renesse, R.: Using Sparse Capabilities in a Distributed Operating System. In: Proceedings of 6th International Conference on Distributed Computing Systems, pp. 558\u2013563 (1986)"},{"key":"15_CR45","unstructured":"Tribble, E.D., Miller, M.S., Hardy, N., Krieger, D.: Joule: Distributed Application Foundations (1995), http:\/\/www.agorics.com\/joule.html"},{"key":"15_CR46","unstructured":"Van Roy, P., Haridi, S.: Concepts, Techniques, and Models of Computer Programming. MIT Press, Cambridge (in preparation), http:\/\/www.info.ucl.ac.be\/people\/PVR\/book.html"},{"key":"15_CR47","unstructured":"Wagner, D., Tribble, D.: A Security Analysis of the Combex DarpaBrowser Architecture, http:\/\/www.combex.com\/papers\/darpa-review\/index.html"},{"key":"15_CR48","doi-asserted-by":"crossref","unstructured":"Wallach, D.S., Balfanz, D., Dean, D., Felten, E.W.: Extensible Security Architectures for Java. In: Proceedings of the 16th Symposium on Operating Systems Principles, pp. 116\u2013128 (1997), http:\/\/www.cs.princeton.edu\/sip\/pub\/sosp97.html","DOI":"10.1145\/269005.266668"},{"key":"15_CR49","volume-title":"The Cambridge CAP Computer and its Operating System","author":"M.V. Wilkes","year":"1979","unstructured":"Wilkes, M.V., Needham, R.M.: The Cambridge CAP Computer and its Operating System. Elsevier North Holland, Amsterdam (1979)"},{"issue":"6","key":"15_CR50","doi-asserted-by":"publisher","first-page":"337","DOI":"10.1145\/355616.364017","volume":"17","author":"W.A. Wulf","year":"1974","unstructured":"Wulf, W.A., Cohen, E.S., Corwin, W.M., Jones, A.K., Levin, R., Pierson, C., Pollack, F.J.: HYDRA: The Kernel of a Multiprocessor Operating System. Communications of the ACM\u00a017(6), 337\u2013345 (1974)","journal-title":"Communications of the ACM"},{"key":"15_CR51","volume-title":"HYDRA\/C.mmp: An Experimental Computer System","author":"W.A. Wulf","year":"1981","unstructured":"Wulf, W.A., Levin, R., Harbison, S.P.: HYDRA\/C.mmp: An Experimental Computer System. McGraw Hill, New York (1981)"},{"key":"15_CR52","unstructured":"Yee, K.-P., Miller, M.S.: Auditors: An Extensible, Dynamic Code Verification Mechanism, http:\/\/www.erights.org\/elang\/kernel\/auditors\/index.html"}],"container-title":["Lecture Notes in Computer Science","Advances in Computing Science \u2013 ASIAN 2003. Progamming Languages and Distributed Computation Programming Languages and Distributed Computation"],"original-title":[],"link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-540-40965-6_15","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,6,7]],"date-time":"2019-06-07T17:44:56Z","timestamp":1559929496000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-540-40965-6_15"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2003]]},"ISBN":["9783540206323","9783540409656"],"references-count":52,"URL":"https:\/\/doi.org\/10.1007\/978-3-540-40965-6_15","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2003]]}}}