A Separation Kernel Formal Security Policy in PVS

Greve, Wilding, and Vanfleet [GWV03] present an ACL2 formalization of a security policy for a separation kernel, and validate its utility by using it to support the verification of a simple application. This note reworks their development in PVS and uses the exercise to offer some comparisonns between PVS and ACL2.