Formal verification is increasingly recognised as the strongest approach for establishing trust in the correctness, security and safety of software systems. Yet, certification frameworks, compliance schemes, and public policy are still resisting to mandate it in a meaningful way.
As with any innovation not yet widely used, authorities are careful to change a well established requirement for a newer one with less known consequences, thus increasing their responsibility in assessing them. Regulators also face legitimate concerns in mandating an approach where the surrounding ecosystem of tools, training, services and qualified practitioners has not yet reached sufficient maturity.
This can lead to a deadlock where investments in maturing the technology will not happen as long as there is no market for it. The market will not develop as long as the technology is not mandated by authorities. And authorities won’t mandate the technology as long as it is not mature enough.
This panel will explore how this cycle can be broken. Drawing on the experiences of experts in certification, compliance and policy, we will discuss where efforts to influence certification frameworks are most worthwhile, which barriers are realistically addressable and what actions can have the greatest impact.
Darren Cofer, Principal Fellow, Collins Aerospace
Darren Cofer is a Principal Fellow at Collins Aerospace. He earned his PhD in
Electrical and Computer Engineering from The University of Texas at Austin.
His area of expertise is developing and applying advanced analysis methods and
tools for verification and certification of high-integrity systems. His
background includes work with formal methods for system and software analysis,
the design of real-time embedded systems for safety-critical applications, and
the development of nuclear propulsion systems in the U.S. Navy. Dr. Cofer has
served as principal investigator on many government-sponsored research
programs, developing and using formal methods for verification of safety and
security properties. He served on RTCA committee SC-205 developing new
certification guidance for airborne software (DO-178C) and was one of the
developers of the Formal Methods Supplement (DO-333). He is currently a member
of SAE committee G-34 developing certification guidance for the use of machine
learning technologies onboard aircraft.
Peter Davies, Technical Director, Thales e-Security
Peter Davies is a Security Expert operating at the convergence of Safety and Security. An honorary Fellow with Imperial College’s Institute for Security Science & Technology and chair of the AESIN Security Workstream. He is a leading expert on countering Cyber Attacks, targeted Supply Chain Infiltration and Cyber Physical Attacks. A well as being part of the design of many of the largest scale global security systems he has led the Cyber Security aspects of over 20 research activities including in Communications, Connected and Automated Vehicles, IoT and IIoT and has 30+ years of verifying security systems in hardware and software. Peter likes to say that he does security where it can’t afford to fail. Peter is sought after by organizations for his advice on their legal position with respect to cyber-attacks.
Jonathan Marshall, SafeShark
Over a 25+ year career spanning broadcast media, cybersecurity, adtech, and media measurement, Jonathan has bridged the gap between technology and commercial execution. From pioneering BAFTA-winning interactive services at BBC R&D to building multi-million-pound hybrid TV platforms, he has consistently focused on developing innovative, high-performance systems built for the future.
Jonathan founded SafeShark in April 2016 and is responsible for driving the company's strategic business development. He collaborates with key stakeholders, monitors market trends, identifies emerging risks, and helps shape SafeShark's long-term direction. He is also a frequent presenter at industry events, including Infosecurity, CYBER, ISE, and IoTSF.
Anjana Rajan, CEO & Co-Founder, Atalanta
Anjana Rajan is the co-founder and CEO of Atalanta. She previously served as the Assistant National Cyber Director for Technology Security at the White House, where she led national security policy on formal methods. She is an applied cryptographer whose prior work focused on human rights missions, including as CTO of Polaris, the largest anti-human trafficking organization in the United States, and co-founder and CTO of Callisto, a cryptography company protecting survivors of sexual assault. She began her career in the forward deployed engineering organization at Palantir. Anjana holds bachelor's and master's degrees in engineering from Cornell University, and is a former elite triathlete who competed for Team USA at two world championships.
James Sharp, Senior Principal Scientist, Defence Science and Technology Laboratory (Dstl)
Dr James Sharp is a Senior Principal Scientist at Defence Science and Technology Laboratory (Dstl), the UK Ministry of Defence’s in-government S&T organisation. He has previously provided independent technical evaluation to UK Defence Aerospace, and has over a decade of experience on the use of software and complex electronic hardware in safety and mission critical systems. Presently, he leads the UK’s Future of Compute for Defence project that canvases, identifies, and assesses emerging novel and unconventional hardware accelerators, and their supportive software stacks. James works across UK government to coherently advance the UK’s skills sector alongside its full stack compute research portfolios. He maintains active research into assurance frameworks and verification techniques for both existing and new/novel hardware devices and software approaches. This research is driven by the need to ensure that UK Defence is able to securely and robustly exploit the latest advancements in compute into modern warfighting, providing a technological advantage.
Martin Dehnel-Wild, Chief Scientist, Kry10
Dr Martin Dehnel-Wild is Chief Scientist of Kry10, where he leads R&D and heads up Kry10’s UK & European office. He has a DPhil (PhD) in Computer Science from the University of Oxford, where he researched interactive and automated theorem proving for security protocols. Prior to Kry10 he set up and led the UK Government’s formal methods (“provable security”) team, bringing rigorous, automated assurance tooling and techniques to the UK’s most critical and highest security systems. Most of his work over the last 10+ years has focussed on pulling formal-methods based tools for software, hardware, and cryptography through to use by regular developers, promoting uptake and use across industry, government, and academia.