NSA edges into the open source realm with Tokeneer

By Angela Gunn | Published October 6, 2008, 6:15 PM

Components of a National Security Agency case study designed to demonstrate that open source, high security and cost effectiveness can all co-exist have been turned over to the open source community.

Tokeneer manages access control for a biometric ID verification tool. It's based on the SPARK subset of Ada developed by the UK's Praxis and was funded by the US National Security Agency, which chose to make information on the development and research available.

Praxis CEO Rod Chapman has described Spark, his company's product, as being unique in providing a decidable, sound information flow analysis framework. (Spark, essentially, mandates good design principles, not to mention squeaky-clean Ada code.) Such an IFA framework allows rigid separation of security levels.

In addition to serving as proof that an open source project can meet stringent security requirements, Tokeneer had timeliness and cost-of-development goals. According to Praxis, the project required 260 days from start to release, and contains 9939 lines of code. Since delivery of Tokeneer, one code defect has been unearthed.

Some observers on Monday were skeptical. On Slashdot, one member whose handle is "Wulfstan" grumbled that though Tokeneer has been released as open source, the SPARK tool chain is not itself governed by open source rules.

Downloads of Tokeneer and pertinent information are available from AdaCore.

Tokeneer has been in the works for several years. A paper on the project as it relates to high-assurance software development was presented in March at Microsoft's Cambridge research facility.

View comments by with a score of at least

It's the US vs. the EU over Oracle+Sun and the meaning of 'open source'

Now that the EU is a virtual country, the US Justice Dept. is taking a stand in favor of its view -- and against the EC's -- that MySQL will survive under Oracle.

Qualcomm: $1.3 billion Samsung licensing deal unrelated to fair trade violations

Samsung has come to a 15-year licensing deal with Qualcomm over 3G and 4G wireless technology.

Firefox turns five: Thanks for giving us a choice

Carmi Levy | Wide Angle Zoom: No longer the phoenix rising from the ashes, Mozilla has carried on more than just Netscape's legacy.

If Microsoft sites lead time online, pigs can fly

How can people spend more time at Microsoft sites, when the measure of success is Windows Live Messenger, which sits on the desktop?

European ministers approve watered-down 'neutral net' language

The latest provision in the EU's telecoms regulatory framework would let businesses cancel individuals' Internet access, if they go to court first.

Snow Leopard and Windows 7 still can't crack the netbook problem

Apple has killed Atom support in OS X 10.6.2 and Windows 7 Starter Edition is stripped of "basic" functionality.

Microsoft's Top 3 advances in Exchange Server 2010

The latest round of changes launched today will impact how admins deliver services to e-mail recipients, and how much companies will pay along the way.

Nokia's 'limited number' of recalled chargers exceeds 14 million

Today, the Finnish phone maker has begun a recall of mobile phone chargers that are a shock hazard.

Ubuntu 9.10 upgraders report frustration

For those Wine aficionados out there, beware of the remote possibility that your Linux system could be infected by Windows-seeking malware.

Supreme Court considers patentability of abstract methods today

Can software that executes a formula for a business process qualify for federal patents? An appeals court already said no, and inventors are making their case.

Thanks, iPhone: Google buys mobile advertiser AdMob for $750 million

AdMob came to thrive thanks to the iPhone's popularity, now Google has bought it.