Modelling Non--Deterministic Systems in HOL
Abstract:
When developing the specifications of computer system components, it is often necessary or desirable to include non--deterministic behavior into the specification. Unfortunately this non--determinism can cause difficulty when we try to verify properties of the specification. In this paper we present a method for modelling non--determinism in a way that allows the verifier to isolate it from other aspects of the system component.
Citations
| 2762 | R.: Communication and Concurrency – Milner - 1989 |
| 2677 | Communicating Sequential Processes – Hoare - 1978 |
| 432 | Security policy and security models – Goguen, Meseguer - 1982 |
| 394 | Secure computer systems: Unified exposition and MULTICS interpretation – Bell, LaPadula - 1976 |
| 206 | C.: HOL: A proof generating system for Higher-Order Logic – Gordon - 1988 |
| 118 | Unwinding and inference control – Goguen, Meseguer - 1984 |
| 81 | Specifications for multi-level security and a hook-up property – McCullough - 1987 |
| 68 | Noninterference and the composability of security properties – McCullough - 1988 |
| 16 | Abstract theories in hol – Windley - 1992 |
| 7 | Foundations of Ulysses: The theory of security – McCullough - 1988 |
| 6 | Mechanical verification of secure distributed systems in higher order logic – Alves-Foss, Levitt - 1991 |
| 3 | Implementing a verification methodology for mccullough security – Rosenthal - 1989 |
| 3 | Security models for priority buffering and interrupt handling – Rosenthal - 1990 |

