| Butler, W.R. and Johnson, S.C., "Formal Methods for Life-Critical Software," Proc: AIAA Computing in Aerospace 9, San Diego CA, pp. 319-329, Oct. 1993. |
....these accidents with the Therac 25 the reader is referred to [LT93] Formal methods, the term with which the variety of mathematical modelling techniques that are applicable to computer system design is meant, are often advocated as a way of increasing confidence in computer based systems. Many [BS92, BH95b, BS93b, BBL93, BH95a, BS93a, Bow93, But93, CGR93, CG92, GCR94, Hal90, Kem90, Nic91, RvH93, Rus94, WW93] believe that the use of formal methods currently offers the only intellectually defensible method for handling the software crisis which increasingly affects the world of embedded systems. In this report we shall mainly concentrate on safety critical software design. Formal methods can be applied ....
R.W. Butler. Formal methods for life-critical software. In AIAA Computing in Aerospace 9 Conference, pages 319--329, San Diego, October 19-21 1993.
....PVS. This requirements capture process is discussed in detail. All of the PVS language features that are used are explained thoroughly to make the paper self contained. More detailed information about PVS can be obtained from [9, 8, 14] Also, several tutorial introductions to PVS are available [6, 3, 16, 4, 11, 15]. 2 Example Application The techniques of formal specification and verification of an avionics subsystem will be demonstrated on a very simplified example of a mode control panel. An informal, English language specification of the mode control panel representative of what software developers ....
Butler, Ricky W.; and Johnson, Sally C.: Formal Methods For Life-Critical Software. In Computing in Aerospace 9 Conference, San Diego, CA, Oct. 1993, pp. 319--329.
....strategy. Although a complete formal verification of a large complex system is impractical at this time, a great increase in confidence in the system can be obtained by the use of formal methods at key locations in the system. For more information on the basic principles of formal methods, see [16]. 2 Goals of Our Program, Strategy, and Research Team The major goals of the NASA Langley research program are to make formal methods practical for use on high integrity systems developed in the United States, to orchestrate the transfer of this technology to industry through use of carefully ....
....Director System (AFDS) and (5) military and commercial Global Positioning (GPS) Systems. The first phase of the project consisted of the formal specification of the AAMP5 instruction set and microarchitecture using SRI s PVS [98, 97, 125] Several tutorial introductions to PVS are available [30, 11, 129, 16, 101, 128]. While formally specifying the microprocessor, two design errors were discovered in the microcode. These errors were uncovered as a result of questions raised by the formal methods researchers at Collins and SRI while seeking to formally specify the behavior of the microprocessor[82, 133] The ....
Butler, Ricky W.; and Johnson, Sally C.: Formal Methods For Life-Critical Software. In Computing in Aerospace 9 Conference, San Diego, CA, Oct. 1993, pp. 319--329.
....strategy. Although a complete formal verification of a large complex system is impractical at this time, a great increase in confidence in the system can be obtained by the use of formal methods at key locations in the system. For more information on the basic principles of formal methods, see [16]. 2 Goals of Our Program, Strategy, and Research Team The major goals of the NASA Langley research program are to make formal methods practical for use on life critical systems developed in the United States, and to orchestrate the transfer of this technology to industry through use of carefully ....
....Flight Director System (AFDS) 5. military and commercial Global Positioning (GPS) Systems. The first phase of the project consisted of the formal specification of the AAMP5 instruction set and microarchitecture using SRI s PVS [85, 84, 108] Several tutorial introductions to PVS are available [26, 11, 112, 16, 87, 111]. While formally specifying the microprocessor, two design errors were discovered in the microcode. These errors were uncovered as a result of questions raised by the formal methods researchers at Collins and SRI while seeking to formally specify the behavior of the microprocessor[72, 115] The ....
Butler, Ricky W.; and Johnson, Sally C.: Formal Methods For Life-Critical Software. In Computing in Aerospace 9 Conference, San Diego, CA, Oct. 1993, pp. 319--329.
....strategy. Although a complete formal verification of a large complex system is impractical at this time, a great increase in confidence in the system can be obtained by the use of formal methods at key locations in the system. For more information on the basic principles of formal methods, see [17]. 2 Goals of Our Program, Strategy, and Research Team The major goals of the NASA Langley research program are to make formal methods practical for use on life critical systems developed in the United States, and to orchestrate the transfer of this technology to industry through use of ....
Ricky W. Butler and Sally C. Johnson, "Formal methods for life-critical software", in Computing in Aerospace 9 Conference, pp. 319--329, San Diego, CA, Oct. 1993.
No context found.
Butler, W.R. and Johnson, S.C., "Formal Methods for Life-Critical Software," Proc: AIAA Computing in Aerospace 9, San Diego CA, pp. 319-329, Oct. 1993.
Online articles have much greater impact More about CiteSeer.IST Add search form to your site Submit documents Feedback
CiteSeer.IST - Copyright Penn State and NEC