Abstract
We report on a case study in applying formal methods to model and validate a digital signature system. We use PROMELA (PROcess MEta LAnguage) to model the system implemented on top of DARMA which enable two different operationg systems to work on the same computer simultaneously. Afterwards, we use the Spin model checker to validate integrity properties. We describe here our modeling approach and the benefits gained from our analysis.