Extensible access control with authorization contracts

Scott Moore, Christos Dimoulas, Robert Bruce Findler, Matthew Flatt, Stephen Chong

Research output: Contribution to journalArticlepeer-review

5 Scopus citations


Existing programming language access control frameworks do not meet the needs of all software components. We propose an expressive framework for implementing access control monitors for components. The basis of the framework is a novel concept: the authority environment. An authority environment associates rights with an execution context. The building blocks of access control monitors in our framework are authorization contracts: software contracts that manage authority environments. We demonstrate the expressiveness of our framework by implementing a diverse set of existing access control mechanisms and writing custom access control monitors for three realistic case studies.

Original languageEnglish (US)
Pages (from-to)214-233
Number of pages20
JournalACM SIGPLAN Notices
Issue number10
StatePublished - Oct 19 2016


  • access control
  • authorization logic
  • contracts

ASJC Scopus subject areas

  • Computer Science(all)


Dive into the research topics of 'Extensible access control with authorization contracts'. Together they form a unique fingerprint.

Cite this