Proceedings, IEEE Aerospace Conference
DOI: 10.1109/aero.2002.1036832
|View full text |Cite
|
Sign up to set email alerts
|

Using SPIN model checking for flight software verification

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
2
1
1
1

Citation Types

0
15
0

Publication Types

Select...
3
3
2

Relationship

0
8

Authors

Journals

citations
Cited by 43 publications
(15 citation statements)
references
References 9 publications
0
15
0
Order By: Relevance
“…6 separately shows how performance varies with state size for a fixed transition delay of 2 3 time units and the graph on the lower right repeats this experiment for a larger transition delay of 2 13 time units. Note that, in the latter case, performance becomes almost completely independent of state size, likely because it is now dominated by the transition delay itself.…”
Section: A Reference Modelmentioning
confidence: 86%
See 1 more Smart Citation
“…6 separately shows how performance varies with state size for a fixed transition delay of 2 3 time units and the graph on the lower right repeats this experiment for a larger transition delay of 2 13 time units. Note that, in the latter case, performance becomes almost completely independent of state size, likely because it is now dominated by the transition delay itself.…”
Section: A Reference Modelmentioning
confidence: 86%
“…We consider six large applications. The first (DS1) is a verification of a large model with embedded C code taken from NASA's Deep Space 1 mission, as described in [13]. The second application (DEOS) is a verification model of the DEOS Operating System kernel developed at Honeywell Laboratories, a variant of which is also discussed in [33].…”
Section: Larger Verification Modelsmentioning
confidence: 99%
“…The test-harness that the user prepares now drives the thread executions directly, selecting the proper level of granularity of execution. The application we studied in [5] is of this type, and could be adapted to use the new method of data abstraction we have discussed here. The capability to redefine how state information is to be represented, or abstracted, is also similar to the view function in TLC [11].…”
Section: Discussionmentioning
confidence: 98%
“…Modex takes C code and creates Promela models by processing all basic actions and conditions of the program with respect to a set of rules. A case study of Modex involving NASA legacy flight software is described by Glück & Holzmann (2002). Modex's approach effectively moves the effort from manual modeling to specifying patterns that match the C statements that should be included in the model (Promela allows for including C statements) and what to ignore.…”
Section: Timing Analysis With Model Checkingmentioning
confidence: 99%