Title :
Research directions for automated software verification: using trusted hardware
Author :
Devanbu, Prem ; Stubblebine, Stuart
Author_Institution :
Inf. Syst. & Services Res. Center, AT&T Labs.-Res., Florham, NJ, USA
Abstract :
Service providers hosting software on servers at the request of content providers need assurance that the hosted software has no undesirable properties. This problem applies to browsers which host applets, networked software which can host software agents, etc. The hosted software´s properties are currently verified by testing and/or verification processes by the hosting computer. This increases cost, causes delay, and leads to difficulties in version control. By furnishing content providers with a physically secure computing device with an embedded certified private key, such properties can be verified and/or enforced by the secure computing device at the content provider´s site; the secure device can verify such properties, statically whenever possible, and by inserting checks into the executable binary when necessary. The resulting binary is attested by a trusted signature, and can be hosted with confidence. The position paper is a preliminary report that outlines scientific and engineering goals in this project
Keywords :
computer networks; configuration management; program testing; program verification; security of data; applets; automated software verification; browsers; checks; content providers; embedded certified private key; engineering goals; executable binary; hosted software; hosting computer; networked software; physically secure computing device; scientific goals; servers; service providers; software agents; testing; trusted hardware; trusted signature; version control; Costs; Formal verification; Hardware; Information systems; Java; Network servers; Runtime environment; Software agents; Software safety; Software testing;
Conference_Titel :
Automated Software Engineering, 1997. Proceedings., 12th IEEE International Conference
Print_ISBN :
0-8186-7961-1
DOI :
10.1109/ASE.1997.632848