A security model for distributed critical systems
This document presents a security architecture model for critical, distributed systems. As a model, it is a good tool to simplify analysis on complex systems, and is useful both in assessing existing systems, where divergence from the model points to probable security issues, and building new systems, where fitting in the model guarantees past experience is taken into account.



