Issue No. 07 - July (1982 vol. 31)
P.M. Melliar-Smith , Computer Science Laboratory, SRI International
This paper describes the formal specification and proof methodology employed to demonstrate that the SIFT computer meets its requirements. The hierarchy of design specifications is shown, from very abstract descriptions of system function down to the implementation. The most abstract design specifications are simple and easy to understand, almost all details of the realization having been abstracted out, and can be used to ensure that the system functions reliably and as intended. A succession of lower level specifications refine these specifications into more detailed and more complex views of the system design, culminating in the Pascal implementation. The paper describes the rigorous mechanical proof that the abstract specifications are satisfied by the actual implementation.
verification, Distributed systems, fault tolerance, reliability, SIFT, specification
R. Schwartz and P. Melliar-Smith, "Formal Specification and Mechanical Verification of SIFT: A Fault-Tolerant Flight Control System," in IEEE Transactions on Computers, vol. 31, no. , pp. 616-630, 1982.