|
|
|
|
|
|
|
|
¨ |
Demonstration
that, for all adjacent
|
|
|
|
abstractions
of representation, the less
|
|
|
|
abstract
representation correctly refines the
|
|
|
more abstract
representation
|
|
|
¨ |
Goal
is to attain confidence that the least
|
|
|
|
abstract
representation of the TSF is a
|
|
|
|
complete
and correct realization of the ST
|
|
|
|
security
functional requirements
|
|