• DocumentCode
    3467409
  • Title

    SCR: a practical approach to building a high assurance COMSEC system

  • Author

    Kirby, James, Jr. ; Archer, Myla ; Heitmeyer, Constance

  • Author_Institution
    Naval Res. Lab., Washington, DC, USA
  • fYear
    1999
  • fDate
    1999
  • Firstpage
    109
  • Lastpage
    118
  • Abstract
    To date, the tabular based SCR (Software Cost Reduction) method has been applied mostly to the development of embedded control systems. The paper describes the successful application of the SCR method, including the SCR* toolset, to a different class of system, a COMSEC (Communications Security) device called CD that must correctly manage encrypted communications. The paper summarizes how the tools in SCR* were used to validate and to debug the SCR specification and to demonstrate that the specification satisfies a set of critical security properties. The development of the CD specification involved many tools in SCR*: a specification editor, a consistency checker, a simulator, the TAME interface to the theorem prover PVS, and various other analysis tools. Our experience provides evidence that use of the SCR* toolset to develop high quality requirements specifications of moderately complex COMSEC systems is both practical and low cost
  • Keywords
    cryptography; formal specification; software cost estimation; telecommunication computing; telecommunication security; theorem proving; CD specification; COMSEC; Communications Security device; SCR method; SCR specification; SCR* toolset; Software Cost Reduction; TAME interface; analysis tools; consistency checker; critical security properties; embedded control systems; encrypted communications; high assurance COMSEC system; high quality requirements specifications; moderately complex COMSEC systems; practical approach; specification editor; tabular based SCR; theorem prover PVS; Analytical models; Application software; Communication system control; Communication system security; Control systems; Cryptography; Hardware; Laboratories; Software systems; Thyristors;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Computer Security Applications Conference, 1999. (ACSAC '99) Proceedings. 15th Annual
  • Conference_Location
    Phoenix, AZ
  • ISSN
    1063-9527
  • Print_ISBN
    0-7695-0346-2
  • Type

    conf

  • DOI
    10.1109/CSAC.1999.816018
  • Filename
    816018