A system architecture for flexible control of downloaded executable content

We present an architecture that enables developers to build applications that can flexibly control downloaded executable content. The architecture includes an access control model for representing security requirements and a browser service for deriving application requirements from signed content messages and executing content in limited domains.