“…Namely, conventional testing or simulation is not sufficient to demonstrate the safety of an industrial-sized I&C system [112]. As an option, formal methods are widely used for these purposes, such as, for example, model checking, which has been successfully applied to verify the control logic of NPPs [107,114,3,97], railway systems [100], avionics [44,145], and automotive driving [136,68,41]. It allows for a rigorous check of a system as a whole and provides mathematical proof of the computed result.…”