Specification and verification of the UCLA Unix security kernel
Bruce J. Walker, Richard A. Kemmerer, Gerald J. Popek · Communications of the ACM · 1980
Data Secure Unix, a kernel structured operating system, was constructed as part of an ongoing effort at UCLA to develop procedures by which operating systems can be produced and shown secure.Program verification methods were extensively applied as a constructive means of demonstrating security enforcement.Here we report the specification and verification experience in producing a secure operating system.The work represents a significant attempt to verify a largescale, production level software system, including all aspects from initial specification to verification of implemented code.