120 likes | 246 Views
Bundesamt für Sicherheit in der Informationstechnik (BSI). Bundesamt für Sicherheit in der Informationstechnik. BSI. Motivation und Zielsetzung des VSE-Projektes Markus Ullmann Bundesamt für Sicherheit in der Informationstechnik Postfach 200363 53133 Bonn ullmann/vse@bsi.de.
E N D
Bundesamt für Sicherheitin der Informationstechnik (BSI) Bundesamt für Sicherheitin der Informationstechnik BSI Motivation und Zielsetzung des VSE-Projektes Markus Ullmann Bundesamt für Sicherheit in der Informationstechnik Postfach 200363 53133 Bonn ullmann/vse@bsi.de
Policy of the BSI IT-Sicherheit im Sinne des BSIG • Promotion of IT-security • Tasks • evaluation and certification of it-systems • fundamentals (evaluation-criteria, development- and evaluation methods, etc.) • design of cryptograhic devices for national use • advisory services in all security-areas
Dependability of Systems • Problems • reliable, available, safe and secure systems • Areas with high dependability demands and system approval • security • safety (avionics, nuclear powerplants, control systems, railway systems,etc.)
Security Criteria (and Safety-Standards) for Systems • IT-security (history) • USA 1980: Trusted Computer System Evaluation Criteria ("Orange Book") • BRD 1989: IT-Security-Criteria ("Green Book") • EC/BRD 1991: Information Technology Security Evaluation Criteria (ITSEC) • EC/USA/CAN 1997: Common Criteria (CC) • IT-safety • MSR: Functional Safety: safety related systems (IEC 1508) • Railway systems: Railway applications software for railway control and protection systems (prEN 50128) • ...
Demands of the Security Criteria in the highest Assurance Level
Verification Support Environment (VSE) • VSE-method and tool development, casestudies, pilot projects • Project duration: 1991-1995 VSE 1.0 • Consortium • DASA • Deutsches Forschungszentrum für Künstliche Intelligenz • innovative software technologie • Universität Ulm
Demands for VSE (1) • Development process • uniform development method (top down development structured specification with stepwise implementation based on preliminary specification) [specification language VSE-SL] • generation of proof obligations • deduction support (heuristics) • code generation • reusability of specifications
Demands for VSE (2) • Industrial requirements • uniform graphical user interface • documentation (development and verification) • management of the verification process -------------------------------------------------------------- • commercial availiability • technical support (evaluation license, guarantee, debugging), training etc.
Demands for VSE (3) • Security evaluation requirements • formalisation and proof of security properties • support of refinement steps • replay of proofs
VSE- Perspective (1) • Industry takes formal methods more serious -> real industrial projects (security/safety) • Specification and verification technology • project "VSE-II" (reactive and concurrent systems, reuse of proof) • Integration • project "Quest": combination of the VSE verification technology (theorem proving) with model checking and validation technologies
VSE- Perspective (2) • VSE-research license • VSE-support • Deutsches Forschungszentrum für Künstliche Intelligenz (Dr. Stephan) • innovative software technologie (Dr. Baur) • Universität Ulm (Prof. Reif)