A Formal Statement of the MMS Security Model
John McLean, Carl E. Landwehr, Constance Heitmeyer · 1984
To provide a firm foundation for proofs about the security properties of a system specification or implementation, a formal statement of its security model is needed. This paper presents a formal model that corresponds to an informal, application-based security model for military message systems (MMS) that has been documented elsewhere. Following the formal statement, some considerations that led to its present form are discussed. The paper concludes with the statement of a "Basic Security Theorem" for the model.