Capabilities

[Google Scholar] [Wikipedia]

Notes: CHERI architecture
Papers: nienhuis:secpriv:2020, woodruff:isca:2014, skorstengaard:esop:2018, skorstengaard:popl:2019

A capability is an unforgeable access token.

todo: noted feature is that it solves the “confused deputy” problem.


CHERI architecture