Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Hardware Security”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 271 records · Page 15

Rattlesnake Vibration Controller v.2.0

SAND2021-7300 O The Rattlesnake Vibration Controller is a combined-environments, multiple input/multiple output control system for dynamic excitation of structures under test. It provides capabilities to control multiple responses on the part using multiple exciters and control strategies. Rattlesnake is written in the Python programming language to facilitate multiple input/multiple output vibration research by allowing users to prescribe custom control laws to the controller. Rattlesnake can target multiple hardware devices, or even perform synthetic control to simulate a test virtually. Rattlesnake has been used to execute control problems with up to 200 response channels and 12 drives. Sandia National Laboratories is a multimission laboratory managed and operated by National Technology & Engineering Solutions of Sandia, LLC, a wholly owned subsidiary of Honeywell International Inc., for the U.S. Department of Energy’s National Nuclear Security Administration under contract DE-NA0003525.

Rohe, Daniel↗

Inventory Management Improvement Project

The Lawrence Livermore National Laboratory (LLNL) conducts research and development for the National Nuclear Security Agency (NNSA) and its affiliates. The Polymer AM team at LLNL conducts research and development in 3D printing, specifically direct-ink-write, in accordance with LLNL and NNSA missions. The team is composed of machine operators, chemists, testing engineers, and project engineers across multiple lab spaces with one shared storage area at LLNL. The operations use a variety of different consumables and hardware to conduct research applications for LLNL and NNSA. These items are critical to performing operation tasks; if an item is out of stock, operations associated with the respective item could be suspended for weeks. As such, the Polymer AM team manages an inventory of spare consumables and hardware to ensure these items are always available. However, the current management system, an excel sheet managed by the project engineer group, is not intuitive in providing inventory information despite the high labor utilization needed to maintain the system. As such, the team is looking to improve their inventory management that can send notifications regarding inventory needs, accessible to other team members, provide all relevant information to a specific item, and store historical information for budget and operation planning. The proposed solution is a Computer Maintenance Management System (CMMS): a web-based management software that stores inventory information and provides automated notifications. The system will store information on each item including quantity in stock, technical information, supplier information, costs, lead times, and expiration date. The system has a notifications function that can send notifications to the respective team member’s when an item needs to be counted, item inventory is low, or an item is approaching their expiration date. Information for each item can be tracked over time creating data to be used for budget planning and process improvement purposes. Due to its web-based source, the system can be accessed by the respective team member viewing technical information, quantity, and purchasing information.

42 ENGINEERING↗

Securing Grid-interactive Efficient Buildings (GEB) through Cyber Defense and Resilient System (CYDRES)

The DOE CYDRES project is driven by the urgent need to address critical research gaps in the domain of cyber-physical security of smart buildings, including Grid-interactive Efficient Buildings (GEBs). CYDRES, a real-time advanced building resilient platform, aims to enhance the cyber-attack-immune capabilities of buildings through multi-layered prevention, detection, and adaptation mechanisms. CYDRES consists of five key modules: a multi-layer network analyzer, an Automatic Fault Detection, Diagnosis, and Prognosis (AFDDP) framework, an intelligent mode selector, a cyber-resilient control framework, and a situation awareness platform. The Network Analyzer employs a data-driven framework that includes a protocol state learning tool and a CRF (Conditional Random Field) command validator. In Hardware-In-the-Loop (HIL) testbeds, it achieved 100% detection accuracy with a false alarm rate of 3%, validating its efficacy in identifying selected cyber-attacks. The AFDDP framework leverages pattern matching, PCA (Principal Component Analysis)-based strategies, and a DBN (Dynamic Bayesian Network)-based fault diagnosis approach to pinpoint the causes of physical system abnormalities using Building Automation System (BAS) data. In HIL experiments, the AFDDP module attained a detection accuracy of over 95% with a false alarm rate below 7%. Additionally, the fault detector utilized machine learning (Random Forest) and deep learning (Multi-Layer Perceptron) methods with acoustic sensor data to achieve a 100% fault detection accuracy in Heating, Ventilation, and Air-Conditioning (HVAC) equipment. The Mode Selector offered real-time impact analysis, allowing immediate actions to protect BASs in the face of emerging threats. The cyber-resilient control framework included an adaptive Model Predictive Control (MPC) and a measurement compensator, reducing temperature violations by up to 94% and improving the total demand flexibility by up to 70% in HIL experiments. Such HIL experiments covered a cyber-attack case and a physical fault case, showcasing CYDRES’ efficiency in maintaining operational continuity during threats. The situation awareness platform in Grafana enhanced real-time threat detection and response visualization, augmenting the operational awareness for building operators. CYDRES demonstrated high technical effectiveness in various test scenarios, particularly in HIL environments. The project's phased development approach ensured efficient use of resources, highlighting its practical feasibility and readiness for commercialization. By enhancing the security and resilience of building operations, CYDRES represents a significant advance in mitigating risks associated with cyber-physical systems, thereby enhancing public confidence in the safety of modern building infrastructure. Future directions for the project include expanding testing protocols, refining AFDDP methodologies, exploring more comprehensive resilient control strategies, and testing in real commercial buildings.

42 ENGINEERING↗

Python Robust Phase Estimation (PyRPE)

Robust Phase Estimation (RPE) is a quantum algorithm to determine the relative phases of eigenstates of a unitary operator. This code implements the classical portion of the RPE algorithm, useful both in simulation (e.g., Sandia's pyGSTi or IBM's Qiskit simulators) and on actual quantum hardware (e.g., IBM's Qiskit Quantum Experience). It additionally implements improvements in these dependent software packages, for both required core function of the RPE and improved usability. SAND2020-12547 M Sandia National Laboratories is a multimission laboratory managed and operated by National Technology & Engineering Solutions of Sandia, LLC, a wholly owned subsidiary of Honeywell International Inc., for the U.S. Department of Energy's National Nuclear Security Administration under contract DE-NA0003525.

Russo, Antonio↗

High-throughput terahertz imaging: progress and challenges

Abstract Many exciting terahertz imaging applications, such as non-destructive evaluation, biomedical diagnosis, and security screening, have been historically limited in practical usage due to the raster-scanning requirement of imaging systems, which impose very low imaging speeds. However, recent advancements in terahertz imaging systems have greatly increased the imaging throughput and brought the promising potential of terahertz radiation from research laboratories closer to real-world applications. Here, we review the development of terahertz imaging technologies from both hardware and computational imaging perspectives. We introduce and compare different types of hardware enabling frequency-domain and time-domain imaging using various thermal, photon, and field image sensor arrays. We discuss how different imaging hardware and computational imaging algorithms provide opportunities for capturing time-of-flight, spectroscopic, phase, and intensity image data at high throughputs. Furthermore, the new prospects and challenges for the development of future high-throughput terahertz imaging systems are briefly introduced.

36 MATERIALS SCIENCE↗

Towards a New Supply Chain Cybersecurity Risk Analysis Technique

Supply chain cyber-attacks, such as the SolarWinds Orion attack, are occurring with greater frequency. These attacks compromise a digital device before it is sent to customers, bypassing traditional security controls to remain persistent and undetected in operational environments. While supply chain attacks are prevalent, methods for analyzing the risk of these attacks are currently unavailable. This paper proposes new supply chain cyber-attack difficulty and risk metrics to evaluate the relative risk of an attack throughout the supply chain lifecycle. Difficulty metrics for each stakeholder in a digital device’s supply chain (e.g., hardware manufacturing, firmware development, software development, storage, and distribution entities) are calculated using scores from cybersecurity maturity questionnaires in a Bayesian Network leaky Noisy-MAX model. These difficulty metrics are then used to calculate an overall supply chain cyber-attack risk. Vulnerability and recoverability metrics are also proposed to evaluate the relative stakeholder influence in the attack risk. These proposed relative risk metrics enable continuous supply chain monitoring, provide decision-makers with information necessary for improved supplier selection, and help drive improvements in the cybersecurity posture of the stakeholders in their supply chain.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Supporting ARPA-E Power Grid Optimization (Final Report)

Pacific Northwest National Laboratory (PNNL), Arizona State University (ASU), Georgia Institute of Technology (Georgia Tech), Los Alamos National Laboratory (LANL), National Renewable Energy Laboratory (NREL), Texas A&M University (TAMU), The University of Texas at Austin (UT), and the University of Wisconsin-Madison (UW-M) supported the ARPA-E Grid Optimization (GO) Competition by providing a common problem formulation, data format, datasets, evaluation mechanism, scoring, rules, and results that resulted in the awarding of $\$9.24$ million dollars to teams from academia, industry, and national labs for solving three sets of increasingly difficult non-linear, security- constrained AC Optimal Powerflow (AC-OPF) optimization problems in order to increase the efficiency of the US Electric Grid. It is estimated that a 1% increase in efficiency can save $\$1$ billion. Current industry practices typically use a linear DC model (DC-OPF) in order solve the OPF problem within the time constraints of the operation schedule. The GO Competition challenges the best power engineers, mathematicians, and computer scientists to make possible operational decisions based on accurate physical models. To accomplish this, the GO Competition created a series of Challenges and funded teams to produce the best solver. Challenge 1 was to solve the security constrained Alternating Current Optimal Power Flow (ACOPF) problem. Challenge 2 extended that to by adding adjustable transformer tap ratios, phase shifting transformers, switchable shunts, price-responsive demand, ramp rate constrained generators and loads, and fast-start unit commitment (UC). Furthermore, Challenge 2 was a maximization problem while Challenge 1 was a minimization problem. While Challenge 3 was being developed, the entrants were invited to find better solutions to the Challenge 2 synthetic datasets with no restrictions on time, hardware, or algorithms. The Challenge 2 solutions turned out to be very good. Challenge 3 expanded the Challenge 2 problem further by using multiperiod dynamic markets, including advisory models for extreme weather events, day-ahead markets, and the real-time markets with an extended look-ahead. These problems included active bid-in demand and topology optimization. Together the Challenges used nearly 30 million CPU hours. Since each team was working on the same problem, using the same data, and running on the same hardware, fair comparisons could be drawn as to the best solver. The datasets were varied enough, however, that the best solver for one dataset was not necessarily the best at another, so cumulative scores were used. The process was managed by the PNNL maintained website https://GOCompetition.energy.gov, where Entrants could find information about the problem, the data, the rules, submit their solver for evaluation, and see the scores of all the competing teams on a Leaderboard. Interest was world-wide but only American teams were eligible for prizes. The Competition has produced 34 journal articles 115 papers and been cited over 500 times in the literature, including 12 dissertations (4 from foreign countries; Columbia (2), Germany, and Italy) and 3 from the DOE ExaScale project. Software developed by Pearl Street Technologies for Challenges 1 and 2 is now deployed by Southwest Power Pool (SPP) and Midcontinent Independent Service Operator (MISO). Other teams have received inquiries from venture capitalists. Google DeepMind has thanked the Competition for making the datasets developed for the Competition public. They are using it to train machine learning models. The larger datasets have billions of unknowns to be solved for, but only a small percent matter in the final solution. Knowing what unknowns are important can dramatically speedup the solution.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Hybrid Data-Driven Physics-Based Model Framework Implementation: Towards a Secure Cyber-Physical Operation of the Smart Grid

False data injection cyber-attack detection models on smart grid operation have been much explored recently, considering analytical physics-based and data-driven solutions. Recently, a hybrid data-driven physics-based model framework for monitoring the smart grid is developed. However, the framework has not been implemented in real-time environment yet. In this paper, the framework of the hybrid model is developed within a real-time simulation environment. OPAL-RT real-time simulator is used to enable Hardware-in-the-Loop testing of the framework. IEEE 9-bus system is considered as a testing grid for gaining insight. The process of building the framework and the challenges faced during development are presented. The performance of the framework is investigated under various false data injection attacks.

false data injection attack, machine learning, sta↗

IEEE P2988: Recommended Practice of Use and Functions of Virtual Synchronous Machines

Power systems are going through a paradigm shift from centralized generation to distributed generation. This brings unprecedented challenges to power systems stability, reliability, and security. Operating power electronic converters as Virtual Synchronous Machines (VSMs) can bring backward compatibility to power systems, unify and harmonize the integration and interaction of future power systems players, and improve power system stability, reliability, and security. This is vital for the large-scale adoption of distributed energy resources, the advancement of sustainability, and the development of a low-carbon economy. This IEEE 2988 Recommended Practice will define the fundamental principles, mandatory functions, and optional functions of a VSM, i.e., a power electronic converter that is operated to behave like conventional synchronous machines. It will not describe or specify power semiconductor devices, hardware topologies, or micro-controllers that are used to build a VSM. This talk will discuss the activities and development plan for IEEE 2988 with the aim to engaging broad stakeholders and widening participation.

Zhong, Qing-Chang↗

TorchDendrite

SAND2025-11595O The TorchDendrite library implements hardware-informed dendrites using PyTorch and SNNTorch as backends. It allows the integration of dendrite-inspired neurons into machine learning networks built with both SNNTorch and PyTorch. TorchDendrite will be available on Github. Sandia National Laboratories is a multimission laboratory managed and operated by National Technology & Engineering Solutions of Sandia, LLC, a wholly owned subsidiary of Honeywell International Inc., for the U.S. Department of Energy’s National Nuclear Security Administration under contract DE-NA0003525.

Chance, Frances↗

Tracking and Positioning System for Floating Solar (CRADA Abstract)

The project goal is to develop a floating solar photovoltaics (FPV) tracking & position system that: (1) increases annual energy production of FPV projects by >10%, (2) lowers levelized cost of energy (LCOE) for FPV by >10%, and (3) leverages U.S. contract supply chain & manufacturing. The outcome of the project will be a certified tracking product that has undergone extensive field testing and is ready for commercial sales. The primary objectives for each budget period are: • BP1: Define product requirements, develop initial controls architecture and design other sub-components, complete small-scale pilot testing, install a larger-scale pilot, secure sites for commercial pilots, and develop the beta-version of a user portal. • BP2: complete control system and sub-component design, successful demonstration and testing at a commercial pilot, certification & bankability, finalize user portal, and complete various commercialization activities related to supply chain, customer acquisition, and sales. PNNL will provide support during both project phases for prototype development and testing of the controls architecture, software, and hardware components of the tracking and positioning system. PNNL will provide support during both project phases for prototype development and testing of the controls architecture, software, and hardware components of the tracking and positioning system. This effort represents PNNL’s first opportunity to support the floating solar photovoltaics (FPV) industry with capabilities, facilities, and personnel developed to contribute to the marine energy (e.g., wave and tidal energy) sector. This portfolio expansion leverages internal and DOE EERE investments and the growing visibility of PNNL-Sequim’s Marine and Coastal Research Laboratory (MCRL) and our marine research capabilities, in general. The development of effective and low-cost FPV platforms is a potential way to increase the nation’s set of tools for providing emission-free electricity without utilizing valuable terrestrial resources. Successful commercialization of such a project may lead to economic benefits through job creation, supply chain creation, and access to a cheaper source of electricity.

14 SOLAR ENERGY↗

CAN-D: A Modular Four-Step Pipeline for Comprehensively Decoding Controller Area Network Data

Controller area networks (CANs) are a broadcast protocol for real-time communication of critical vehicle subsystems. Original equipment manufacturers of passenger vehicles hold secret their mappings of CAN data to vehicle signals, and these definitions vary according to make, model, and year. Without these mappings, the wealth of real-time vehicle information hidden in the CAN packets is uninterpretable, severely impeding vehicle-related research, including CAN cybersecurity and privacy studies, aftermarket tuning, efficiency and performance monitoring, and fault diagnosis to name a few. Guided by the four-part CAN signal definition, we present CAN-D (CAN-Decoder), a modular, four-step pipeline for identifying each signal's boundaries (start bit and length), endianness (byte ordering), signedness (bit-to-integer encoding), and by leveraging diagnostic standards, augmenting a subset of the extracted signals with meaningful, physical interpretation. En route to CAN-D, we provide a comprehensive review of the CAN signal reverse engineering research. All previous methods ignore endianness and signedness, rendering them incapable of decoding many standard CAN signal definitions. Incorporating endianness grows the search space from 128 to 4.72E21 signal tokenizations and introduces a web of changing dependencies. In response, we formulate, formally analyze, and provide an efficient solution to an optimization problem, allowing identification of the optimal set of signal boundaries and byte orderings. In addition, we provide two novel, state-of-the-art signal boundary classifiers—both of which are superior to previous approaches in precision and recall in three different test scenarios—and the first signedness classification algorithm, which exhibits a $>$ 97% F-score. Altogether, CAN-D is the only solution with the potential to extract any CAN signal that is also the state of the art. In evaluation on 10 vehicles of different makes, CAN-D's average $\ell ^1$ error is five times better (81% less) than all previous methods and exhibits lower average error, even when considering only signals that meet prior methods’ assumptions. Finally, CAN-D is implemented in lightweight hardware, allowing for an on-board diagnostic (OBD-II) plugin for real-time in-vehicle CAN decoding.

42 ENGINEERING↗

Launching to the Moon, Mars, and Beyond

America is returning to the Moon in preparation for the first human footprint on Mars, guided by the U.S. Vision for Space Exploration. This presentation will discuss NASA's mission today, the reasons for returning to the Moon and going to Mars, and how NASA will accomplish that mission. The primary goals of the Vision for Space Exploration are to finish the International Space Station, retire the Space Shuttle, and build the new spacecraft needed to return people to the Moon and go to Mars. Unlike the Apollo program of the 1960s, this phase of exploration will be a journey, not a race. In 1966, the NASA's budget was 4 percent of federal spending. Today, with 6/10 of 1 percent of the budget, NASA must incrementally develop the vehicles, infrastructure, technology, and organization to accomplish this goal. Fortunately, our knowledge and experience are greater than they were 40 years ago. NASA's goal is a return to the Moon by 2020. The Moon is the first step to America's exploration of Mars. Many questions about the Moon's history and how its history is linked to that of Earth remain even after the brief Apollo explorations of the 1960s and 1970s. This new venture will carry more explorers to more diverse landing sites with more capable tools and equipment. The Moon also will serve as a training ground in several respects before embarking on the longer, more perilous trip to Mars. The journeys to the Moon and Mars will require a variety of vehicles, including the Ares I Crew Launch Vehicle, the Ares V Cargo Launch Vehicle, the Orion Crew Exploration Vehicle, and the Lunar Surface Access Module. The architecture for the lunar missions will use one launch to ferry the crew into orbit on the Ares I and a second launch to orbit the lunar lander and the Earth Departure Stage to send the lander and crew vehicle to the Moon. In order to reach the Moon and Mars within a lifetime and within budget, NASA is building on proven hardware and decades of experience derived from the Apollo Saturn, Space Shuttle, and contemporary commercial launch vehicle programs. Less than one year after the Exploration Launch Projects Office was formed at NASA's Marshall Space Flight Center, engineers are testing engine components, firing test rocket motors, refining vehicle designs in wind tunnel tests, and building hardware for the first flight test of Ares I, scheduled for spring 2009. The Vision for Exploration will require this nation to develop tools, machines, materials, and processes never before invented, technologies and capabilities that can be turned over to the private sector to benefit nearly all aspects of life on Earth. This new pioneering venture, as did the Apollo Program before it, will contribute to America's economic leadership, national security, and technological global competitiveness and serve as an inspiration for all its citizens.

Sumrall, John P.↗

National Security Programs - Cyber: MMAREJBLIGE – Modular Multi Agent Grid Emulation for Joined Breakdowns in Linked Generative Emulations - 23-0644

Modular Multi Agent Grid Emulations for Joined Breakdowns in Linked Generative Emulations (MMAREJBLIGE) introduces an agent-based modeling framework into real-time cyber-physical emulation to achieve a context-aware environment that introduces operator/attacker/external-condition variability to improve emulation fidelity and testing rigor. We detail our agent framework design, internal communication via message passing, and time synchronization, as well as the individual components of the system. We include a brief analysis of several scenarios run on a real-time, hardware-in-the-loop, Industrial Control Systems (ICS) test-bed which include normal operation, physical disruption, disruption with mitigation, and disruption with mitigation during a cyber denial-of-service (DOS) attack.

42 ENGINEERING↗

A Robust Method to Secure Multi-Inverter Grid Tied PV and Battery Energy Storage Systems Against Cyber Intrusions

This paper details a robust method to secure a multi-inverter grid tied system that interfaces photovoltaic (PV) and battery energy storage against potential cyber-attacks. The method can be applied to any third-party inverter systems without a need to modify their internal controls. A small random private excitation signal termed "watermark" is injected into the DC input voltage terminals (via a series transformer) connected to the PV/battery inverter system. An external robust cyber intrusion detector (CID) hardware consisting of a digital signal processor (DSP) generates the "watermark" and also receives the sensor signals that control the setpoints of the PV/battery grid tied system. The CID algorithm is shown to detect all possible cyber intrusions (such as false data injection(FDI)) on external sensor signals such as P and Q measured by a smart meter that control the overall system operation. The proposed CID computes online system ID and two variance tests in real time on each sensor signal and is able pinpoint intrusion location in a multi-inverter system. Results on a hardware in the loop (HIL) of a two-inverter grid connected system demonstrate effectiveness of the proposed CID system for FDI and unobservable FDI. Test results on a laboratory prototype will be discussed in the conference presentation.

Ibrahim, Hasan↗

Neuromorphic Processing and Sensing for Interception

Interception of a moving and potentially evading target can be a challenging problem, in particular for conditions in which the target may be moving at high speeds and difficult to detect. We have proposed to merge two Sandia LDRD efforts, the SPARR Spiking/Processing Array (neuromorphic event-driven sensing) and the Dragonfly-Inspired Algorithms for Intercept- Trajectory Planning (neural-inspired algorithms for interception) toward a unified system with direct application to national security. Neuromorphic systems demonstrate the most potential for speed and efficiency gains when communication is event-driven and computations are simple but parallelizable. Accordingly, we anticipate fully realizing potential benefits from a neuromorphic interception system if event-driven sensing is combined with processing and acting also implemented on event-driven (spiking) systems. We have successfully translated a neural-inspired interception algorithm to a neural network architecture for evaluation on neuromorphic hardware. Preliminary implementations of the neural network designed for implementation on the Loihi chip are still too immature for conclusive evaluation, but the results of this effort have demonstrated a viable path for a previously developed dragonfly-inspired interception algorithm to be implemented on neuromorphic hardware.

97 MATHEMATICS AND COMPUTING↗

Reliability modeling of fault-tolerant computer based systems

Digital fault-tolerant computer-based systems have become commonplace in military and commercial avionics. These systems hold the promise of increased availability, reliability, and maintainability over conventional analog-based systems through the application of replicated digital computers arranged in fault-tolerant configurations. Three tightly coupled factors of paramount importance, ultimately determining the viability of these systems, are reliability, safety, and profitability. Reliability, the major driver affects virtually every aspect of design, packaging, and field operations, and eventually produces profit for commercial applications or increased national security. However, the utilization of digital computer systems makes the task of producing credible reliability assessment a formidable one for the reliability engineer. The root of the problem lies in the digital computer's unique adaptability to changing requirements, computational power, and ability to test itself efficiently. Addressed here are the nuances of modeling the reliability of systems with large state sizes, in the Markov sense, which result from systems based on replicated redundant hardware and to discuss the modeling of factors which can reduce reliability without concomitant depletion of hardware. Advanced fault-handling models are described and methods of acquiring and measuring parameters for these models are delineated.

Bavuso, Salvatore J.↗

Automated Theorem Proving in High-Quality Software Design

The amount and complexity of software developed during the last few years has increased tremendously. In particular, programs are being used more and more in embedded systems (from car-brakes to plant-control). Many of these applications are safety-relevant, i.e. a malfunction of hardware or software can cause severe damage or loss. Tremendous risks are typically present in the area of aviation, (nuclear) power plants or (chemical) plant control. Here, even small problems can lead to thousands of casualties and huge financial losses. Large financial risks also exist when computer systems are used in the area of telecommunication (telephone, electronic commerce) or space exploration. Computer applications in this area are not only subject to safety considerations, but also security issues are important. All these systems must be designed and developed to guarantee high quality with respect to safety and security. Even in an industrial setting which is (or at least should be) aware of the high requirements in Software Engineering, many incidents occur. For example, the Warshaw Airbus crash, was caused by an incomplete requirements specification. Uncontrolled reuse of an Ariane 4 software module was the reason for the Ariane 5 disaster. Some recent incidents in the telecommunication area, like illegal "cloning" of smart-cards of D2GSM handies, or the extraction of (secret) passwords from German T-online users show that also in this area serious flaws can happen. Due to the inherent complexity of computer systems, most authors claim that only a rigorous application of formal methods in all stages of the software life cycle can ensure high quality of the software and lead to real safe and secure systems. In this paper, we will have a look, in how far automated theorem proving can contribute to a more widespread application of formal methods and their tools, and what automated theorem provers (ATPs) must provide in order to be useful.

Schumann, Johann↗