Verifying a hardware security architecture
Joshua D. Guttman, Hankyeong Ko · 1990
The verification work reported had three goals: (1) to develop a method for specifying components, which may be either software processes or hardware components, in terms of their possible event histories (also called traces); (2) to develop a method of verifying systems built from such components; and (3) to use these techniques to prove security properties about a realistic and substantial design. The approach to specification and verification is described. Although they do not yet have robust enough automated support to aid in the application described, the authors have devoted considerable attention to rigorously defining the logic suited to the method and exploring the type of software support needed. The main part of this study describes the use of the approach to specify and verify the security of the hardware architecture level of a hypothetical secure computing system. As far as the authors know, verification methods already in use are not suited to this sort of problem.>