Journal Article
Refinement Types for Logical Frameworks and Their Interpretation as Proof Irrelevance
Refinement Types for Logical Frameworks and Their Interpretation as Proof Irrelevance
A Logical Representation of Common Rules for Controlling Access to Classified Information
Consumable Credentials in Logic-Based Access-Control Systems
Invited talk: Subtyping and intersection types revisited