A description is given of the application of formal specification and verification methods to two microprocessor-based cryptographic devices: a `smart token' system that controls access to a network of workstations, and a message authentication device implementing the ANSI X9.9 message authentication standard. Formal specification and verification were found to be practical, cost-effective tools for detecting potential security weaknesses, and helped to significantly strengthen the security of the access control system
Published in:
Computer Security Applications Conference, 1990., Proceedings of the Sixth Annual
Date of Conference: 3-7 Dec 1990