Paper: https://www.cl.cam.ac.uk/research/security/ctsrd/pdfs/201406...
"Motivated by contemporary security challenges, we reevaluate and refine capability-based addressing for the RISC era. We present CHERI, a hybrid capability model that extends the 64-bit MIPS ISA with byte-granularity memory protection."
Capability-based addressing https://en.wikipedia.org/wiki/Capability-based_addressing is hardware that implements 'fat pointers' that point to ranges of memory so its not possible for a program to address memory it shouldn't. Basically, it forces programs to be 'memory safe' https://en.wikipedia.org/wiki/Memory_safety even if written in memory-unsafe languages such as C.
http://www.cs.washington.edu/homes/levy/capabook/index.html
The surviving, capability architecture is System/38 -> AS/400 -> IBM i. A side effect of better architecture is that they are also incredibly reliable. One person here described them as the tanks of their company's servers.