HERMES Security Design
James R. Miller · 1979
Abstract : In this paper, we describe two successive attempts to develop a version of the Hermes Message System that represent a workable compromise between the goals of security policy, the fact that computer software cannot in general be trusted (or proven correct) and the need for good human factors in an interactive system. Our conclusions are that acceptable human factors must be designed into the system. Intensive efforts should be made to develop effective software verification techniques or other means for making it possible to trust as much of the software as possible.