<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: The Tokeneer Project</title>
	<atom:link href="http://www.adacore.com/home/products/sparkpro/tokeneer/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.adacore.com</link>
	<description>AdaCore technology and news</description>
	<lastBuildDate>Mon, 06 Feb 2012 18:59:19 -0500</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Microsoft Research: 2011 Verified Software Milestone Award Winners - Ada Resource Association</title>
		<link>http://www.adacore.com/home/products/sparkpro/tokeneer/comment-page-1/#comment-14074</link>
		<dc:creator>Microsoft Research: 2011 Verified Software Milestone Award Winners - Ada Resource Association</dc:creator>
		<pubDate>Thu, 07 Apr 2011 14:58:43 +0000</pubDate>
		<guid isPermaLink="false">#comment-14074</guid>
		<description>[...] From the announcement: We are delighted to announce that the recipients of the inaugural Microsoft Research Verified Software Milestone Award are Janet Barnes and Rod Chapman for the Tokeneer Project (http://www.altran-praxis.com/security.aspx). [...]</description>
		<content:encoded><![CDATA[<p>[...] From the announcement: We are delighted to announce that the recipients of the inaugural Microsoft Research Verified Software Milestone Award are Janet Barnes and Rod Chapman for the Tokeneer Project (<a href="http://www.altran-praxis.com/security.aspx" rel="nofollow">http://www.altran-praxis.com/security.aspx</a>). [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Links &#187; Useful Security</title>
		<link>http://www.adacore.com/home/products/sparkpro/tokeneer/comment-page-1/#comment-6301</link>
		<dc:creator>Links &#187; Useful Security</dc:creator>
		<pubDate>Sun, 16 Aug 2009 14:59:49 +0000</pubDate>
		<guid isPermaLink="false">#comment-6301</guid>
		<description>[...] Michael asked &#8220;what about Tokeneer?&#8221; [...]</description>
		<content:encoded><![CDATA[<p>[...] Michael asked &#8220;what about Tokeneer?&#8221; [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Open source and certified systems &#124; carlodaffara.conecta.it</title>
		<link>http://www.adacore.com/home/products/sparkpro/tokeneer/comment-page-1/#comment-3566</link>
		<dc:creator>Open source and certified systems &#124; carlodaffara.conecta.it</dc:creator>
		<pubDate>Thu, 16 Apr 2009 07:58:31 +0000</pubDate>
		<guid isPermaLink="false">#comment-3566</guid>
		<description>[...] FIPS standard, common criteria Evaluation Assurance Level EAL4+ (and in one case, meet or exceed EAL5), civil engineering (where the product is used for the stability computations for EDF nuclear [...]</description>
		<content:encoded><![CDATA[<p>[...] FIPS standard, common criteria Evaluation Assurance Level EAL4+ (and in one case, meet or exceed EAL5), civil engineering (where the product is used for the stability computations for EDF nuclear [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ada for C++ Developers: Development Environments &#171; The Global Engineer&#8217;s Notebook</title>
		<link>http://www.adacore.com/home/products/sparkpro/tokeneer/comment-page-1/#comment-3498</link>
		<dc:creator>Ada for C++ Developers: Development Environments &#171; The Global Engineer&#8217;s Notebook</dc:creator>
		<pubDate>Fri, 27 Mar 2009 05:20:09 +0000</pubDate>
		<guid isPermaLink="false">#comment-3498</guid>
		<description>[...] of PR about Ada in the news these days revolves around SPARK, such as the NSA Tokeneer [DrDobbs, AdaCore] project. From the vendor&#8217;s web page: SPARK gives confidence in the correctness of code – [...]</description>
		<content:encoded><![CDATA[<p>[...] of PR about Ada in the news these days revolves around SPARK, such as the NSA Tokeneer [DrDobbs, AdaCore] project. From the vendor&#8217;s web page: SPARK gives confidence in the correctness of code – [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ANN: SPARK Proof - Tutorials and Tools &#124; keyongtech</title>
		<link>http://www.adacore.com/home/products/sparkpro/tokeneer/comment-page-1/#comment-3476</link>
		<dc:creator>ANN: SPARK Proof - Tutorials and Tools &#124; keyongtech</dc:creator>
		<pubDate>Mon, 23 Mar 2009 15:07:28 +0000</pubDate>
		<guid isPermaLink="false">#comment-3476</guid>
		<description>[...] Re: SPARK Proof - Tutorials and Tools   Thank you Phil,  It is the best documentation and &quot;how to use guide&quot; ever made on this subject.    That is a long overdue and great clarification on the SPARK purpose, constraints and limitations.  (i.e.: Proof of Absence of Run-time Error).    &quot;The Simplifier does not prove all provable Verification Conditions (a provable VC is one where the conclusions can be shown to be logical consequences of the hypotheses). Any VCs remaining after simplification may be provable (but beyond the capability of the Simplifier to prove) or unprovable.&quot;    That&#039;s start to make sense.    Mathematical approximations sometimes don&#039;t deal easily with computer calculation errors.  I was assuming that is a flight trajectory/airspace intersection instability risk that SPARK or Praxis&#039;s Correctness by construction can&#039;t easily evaluate.    I think that shall confirm SPARK as one programming insurance tool (doing it right), and don&#039;t compromise the use of Ada like a Computer Assisted Engineering tool (doing the right thing).    Now, about knowing what we are doing, did you suggest the proof must be elaborated once the functional behaviour has been thoroughly tested (unit, non-regression, integration, verification, (validation) testing - all the kit indeed)?  i.e.: &quot;Proof Checker, (This option may lead to proofs that are difficult to maintain.)&quot;    Indeed, that is what could have prevented the Praxis&#039;s iFACTS project from entering the wall. (see above for a plausible explanation)    And about project as complex and big than iFACTS, (I have another similar in mind, and mind a responsible answer) would you suggest SPARK could still be an affordable option, e.g.: taking into account the overhead that annotations and proofs shall require (quite twice of the project&#039;s level of effort, as I would figure - learning curve not entirely included)    Cheers,    Michael,  Vancouver, British Columbia    Praxis&#039;s Tokeneer demo is also available - example is still instructive, but SPARK usage and limitations are poorly documented:  http://www.adacore.com/home/products/gnatpro/tokeneer/ [...]</description>
		<content:encoded><![CDATA[<p>[...] Re: SPARK Proof &#8211; Tutorials and Tools   Thank you Phil,  It is the best documentation and &quot;how to use guide&quot; ever made on this subject.    That is a long overdue and great clarification on the SPARK purpose, constraints and limitations.  (i.e.: Proof of Absence of Run-time Error).    &quot;The Simplifier does not prove all provable Verification Conditions (a provable VC is one where the conclusions can be shown to be logical consequences of the hypotheses). Any VCs remaining after simplification may be provable (but beyond the capability of the Simplifier to prove) or unprovable.&quot;    That&#8217;s start to make sense.    Mathematical approximations sometimes don&#8217;t deal easily with computer calculation errors.  I was assuming that is a flight trajectory/airspace intersection instability risk that SPARK or Praxis&#8217;s Correctness by construction can&#8217;t easily evaluate.    I think that shall confirm SPARK as one programming insurance tool (doing it right), and don&#8217;t compromise the use of Ada like a Computer Assisted Engineering tool (doing the right thing).    Now, about knowing what we are doing, did you suggest the proof must be elaborated once the functional behaviour has been thoroughly tested (unit, non-regression, integration, verification, (validation) testing &#8211; all the kit indeed)?  i.e.: &quot;Proof Checker, (This option may lead to proofs that are difficult to maintain.)&quot;    Indeed, that is what could have prevented the Praxis&#8217;s iFACTS project from entering the wall. (see above for a plausible explanation)    And about project as complex and big than iFACTS, (I have another similar in mind, and mind a responsible answer) would you suggest SPARK could still be an affordable option, e.g.: taking into account the overhead that annotations and proofs shall require (quite twice of the project&#8217;s level of effort, as I would figure &#8211; learning curve not entirely included)    Cheers,    Michael,  Vancouver, British Columbia    Praxis&#8217;s Tokeneer demo is also available &#8211; example is still instructive, but SPARK usage and limitations are poorly documented:  <a href="http://www.adacore.com/home/products/gnatpro/tokeneer/" rel="nofollow">http://www.adacore.com/home/products/gnatpro/tokeneer/</a> [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>

