By Władysław M. Turski (auth.), Prof. Flaviu Cristian, Gerard Le Lann, Teresa Lunt (eds.)

This quantity comprises the articles awarded on the Fourth InternationallFIP operating convention on liable Computing for severe purposes held in San Diego, California, on January 4-6, 1994. in line with the former 3 meetings held in August 1989 at Santa Barbara (USA), in February 1991 at Tucson (USA), and in September 1992 at Mondello (Italy), the convention was once desirous about a huge uncomplicated query: will we depend upon computers for severe functions? This convention, like its predecessors, addressed quite a few facets of dependability, a vast time period outlined because the measure of belief which may justifiably be positioned in a system's reliability, availability, defense, defense and function. as a result of its vast scope, a chief objective was once to give a contribution to a unified figuring out and integration of those techniques. this system Committee chosen 21 papers for presentation from a complete of ninety five submissions at a September assembly in Menlo Park, California. The ensuing software represents a wide spectrum of pursuits, with papers from universities, organizations and govt organisations in 8 nations. the choice procedure used to be significantly facilitated by way of the diligent paintings of this system committee individuals, for which we're so much thankful. As a operating convention, this system was once designed to advertise the trade of principles by way of huge discussions. All paper classes ended with a 30 minute dialogue interval at the issues coated by way of the consultation. additionally, 3 panel periods were organizcd.

Extra info for Dependable Computing for Critical Applications 4

Example text

This situation will improve as feedback from design case-studies appears (so we should take heart from the growing industrial interest in the Lambda' system, for example), but there are also fundamental difficulties. The argument for plurality means that a combination of tools are needed to approach realistic designs and safety assessments. Ensuring that the tools supporting diverse modelling paradigms sit together comfortably within a coherent semantic framework is delicate. It is essential to work towards providing clean, mathematically precise, interfaces so that tools can communicate, so that different specification and verification styles can be brought to bear alongside more traditional methods based on logic analysis, testing and simulation.

Dur approach is to capture the relevant policy and encode it as resolution roles so that the system can automatically make an appropriate tradeoff when necessary. In particular, the scheduling-covert-channeI 16 bandwidth limits can be adjusted dynamically in accordance with mission goals. For example, if the destination of a flight is classified, but the classification is automatically reduced upon arrival, the resolution mechanism could be configured to ease restrictions on the scheduling covert channel bandwidth when the ßight arrives within some threshold distance from the destination.

Combining the Fault-Tolerance, Security and Real-Time Aspects of Computing Toward a Multilevel-Secure, Best-Effort Real-Time Scheduler Peter K. Boucher*, Raymond K. Clarkt, Ira B. Greenberg*, E. Douglas Jensen:j:, Douglas M. A. Abstract Some real-time missions that manage classified data are so critical that mission faHure might be more damaging to national security than compromising the data. The confticts between computer security requirements and timeliness requirements are described in the context oflarge, distributed, supervisorycontrol systems that are intended for use in such critical missions.

