Skip to content

Capability-based addressing

In computer science, capability-based addressing is a scheme used by some computers to control access to memory as an efficient implementation of capability-based security.

Core Idea

Capability-based addressing is treated here as the recurring computerscienceandinformation identity summarized by this source-grounded definition: In computer science, capability-based addressing is a scheme used by some computers to control access to memory as an efficient implementation of capability-based security. In computer science, capability-based addressing is a scheme used by some computers to control access to memory as an efficient implementation of capability-based security. Under a capability-based addressing scheme, pointers are replaced by protected objects (named capabilities) which specify both a location in memory, along with access rights which define the set of operations which can.

How would you explain it like I'm…

Memory Tickets

In some computers, a program can't just point at any spot in the computer's memory. Instead it has to hold a special ticket that says which spot it may use and what it may do there, like 'you may look but not change.' Only the computer's boss part can make or change tickets, so a program can't make a fake one.

Tokens Instead of Addresses

A computer's memory is like a huge set of numbered boxes. Normally a program uses a plain address, called a pointer, to reach a box. With capability-based addressing, a program must instead use a protected token called a capability, which says both which place in memory it may reach and what it is allowed to do there, such as read or write. Only the most trusted part of the system, the kernel, can create or change these tokens. This way each program can reach only the memory it truly needs, and the computer does not have to switch between separate memory spaces to keep programs apart.

Pointers That Carry Permissions

Capability-based addressing is a way for computers to control which parts of memory a program can use. Ordinary pointers are replaced by capabilities: protected objects that hold both a memory location and a set of access rights, like read-only or read-write. Capabilities can be created or modified only by privileged instructions that the kernel, or another authorized privileged process, may run, so programs cannot forge them. This lets the kernel limit each program to the minimum memory it needs without giving each program its own separate address space, which would require costly context switches on access. One hardware trick is to add an extra tag bit to memory, writable only in supervisor mode, that marks which words are capabilities.

 

Capability-based addressing is a memory-access scheme that implements capability-based security efficiently in hardware or low-level system software. Instead of raw pointers, code holds capabilities: protected references that combine a memory location with access rights specifying which operations are permitted on it. The integrity of the scheme rests on the rule that capabilities can be created or altered only by privileged instructions available to the kernel or another authorized privileged process, so user code cannot fabricate or amplify them. Because protection travels with the reference itself, the kernel can confine applications and subsystems to the minimum necessary memory, and can withhold write access, without isolating them in separate address spaces and paying for a context switch on each cross-domain access. A common implementation extends each memory word with a tag bit, writable only in supervisor mode, that marks the word as a capability. That technique generalizes the tag bits used to protect segment descriptors in the Burroughs Large Systems and was used to protect capabilities in the IBM System/38. A system counts as using this scheme only if memory access is actually mediated by such unforgeable location-plus-rights references, not merely if it uses the vocabulary of capabilities.

Scope of Application

  • Practical implementations. This is a generalization of the use of tag bits to protect segment descriptors in the Burroughs Large Systems, and it was used to protect capabilities in the IBM System/38.

  • Documented setting. In computer science, capability-based addressing is a scheme used by some computers to control access to memory as an efficient implementation of capability-based security.

  • Documented setting. Thus, a kernel can limit application code and other subsystems access to the minimum necessary portions of memory (and disable write access where appropriate), without the need to use separate address.

  • Practical implementations. Require capabilities to be stored in a particular area of memory that cannot be written to by the process that will use them.

  • Practical implementations. For example, the Plessey System 250 required that all capabilities be stored in capability-list segments.

Clarity

A clear use of Capability-based addressing names the carrier, the operative relation, and the conditions under which the source treats the identity as present. The minimal definition is In computer science, capability-based addressing is a scheme used by some computers to control access to memory as an efficient implementation of capability-based security.

Manages Complexity

Capability-based addressing compresses multiple computerscienceandinformation details into a stable diagnostic relation. The source shows both the central mechanism—require capabilities to be stored in a particular area of memory that cannot be written to by the process that will use them.—and the practical consequence—in computer science, capability-based addressing is a scheme used by some computers to control access to memory as an efficient implementation of capability-based security.

Abstract Reasoning

  1. Type the carrier. Identify the computerscienceandinformation entities to which the claim applies.
  2. State the relation. Use the source-grounded identity: In computer science, capability-based addressing is a scheme used by some computers to control access to memory as an efficient implementation of capability-based security.
  3. Check operation and conditions. Both types of pointer could only be manipulated using privileged instructions, and differed by whether object authorizations (i.e. access rights) were encoded in the contents of the pointer.
  4. Demand recognition evidence.

Knowledge Transfer

Within the home domain. Knowledge about Capability-based addressing transfers literally when a new case preserves the same carrier type, relation, and recognition test. This is a generalization of the use of tag bits to protect segment descriptors in the Burroughs Large Systems, and it was used to protect capabilities in the IBM System/38. In computer science, capability-based addressing is a scheme used by some computers to control access to memory as an efficient implementation of capability-based security. Beyond the home domain. No canonical parent is asserted for Capability-based addressing.

Neighborhood in Abstraction Space

Capability-based addressing sits in a moderately populated region (45th percentile for distinctiveness): it has near-neighbors but no dense thicket of look-alikes.

Family — Unclustered & Miscellaneous (2551 abstractions)

Nearest neighbors

Computed from structural-signature embeddings · 2026-10-08