| 2005 | Middleware | Securing Publish/Subscribe for Multi-domain Systems. | Jean Bacon, David M. Eyers, Ken Moody, Lauri I. W. Pesonen |
| 2004 | SACMAT | Using trust and risk in role-based access control policies. | Nathan Dimmock, Andrs Belokosztolszki, David M. Eyers, Jean Bacon, Ken Moody |
| 2003 | DBSEC | Persistent versus Dynamic Role Membership. | Jean Bacon, David W. Chadwick, Alexander Otenko, Ken Moody |
| 2003 | WETICE | Policy Storage for Role-Based Access Control Systems. | Andrs Belokosztolszki, David M. Eyers, Wei Wang, Ken Moody |
| 2001 | Middleware | Access Control and Trust in the Use of Widely Distributed Services. | Jean Bacon, Ken Moody, Walt Yao |
| 2001 | SACMAT | A model of OASIS role-based access control and its support for active security. | Walt Yao, Ken Moody, Jean Bacon |
| 2001 | SSDBM | Using Association Rules to Add or Eliminate Query Constraints Automatically. | Agathoniki Trigoni, Ken Moody |
| 2000 | DBSEC | Coordinating Policy for Federated Applications. | Ken Moody |
| 2000 | Middleware | An Architecture for Distributed OASIS Services. | John H. Hine, Walt Yao, Jean Bacon, Ken Moody |
| 1998 | SP | Access Control in an Open Distributed Environment. | Richard Hayton, Jean Bacon, Ken Moody |
| 1997 | ICDCS | An Open Architecture for Secure Interworking Services. | Richard Hayton, Ken Moody |