{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,12]],"date-time":"2026-06-12T09:58:44Z","timestamp":1781258324018,"version":"3.54.1"},"publisher-location":"Cham","reference-count":57,"publisher":"Springer International Publishing","isbn-type":[{"value":"9783319488684","type":"print"},{"value":"9783319488691","type":"electronic"}],"license":[{"start":{"date-parts":[[2016,1,1]],"date-time":"2016-01-01T00:00:00Z","timestamp":1451606400000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2016]]},"DOI":"10.1007\/978-3-319-48869-1_2","type":"book-chapter","created":{"date-parts":[[2016,11,7]],"date-time":"2016-11-07T03:41:52Z","timestamp":1478490112000},"page":"8-26","source":"Crossref","is-referenced-by-count":57,"title":["Specification: The Biggest Bottleneck in Formal Methods and Autonomy"],"prefix":"10.1007","author":[{"given":"Kristin Yvonne","family":"Rozier","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2016,11,8]]},"reference":[{"key":"2_CR1","doi-asserted-by":"crossref","unstructured":"Alur, R., Henzinger, T.A.: Real-time logics: complexity and expressiveness. In: LICS, pp. 390\u2013401. IEEE (1990)","DOI":"10.1109\/LICS.1990.113764"},{"key":"2_CR2","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"19","DOI":"10.1007\/978-3-319-40648-0_2","volume-title":"NASA Formal Methods","author":"JD Backes","year":"2016","unstructured":"Backes, J.D., Whalen, M.W., Gacek, A., Komp, J.: On implementing real-time specification patterns using observers. In: Rayadurgam, S., Tkachuk, O. (eds.) NFM 2016. LNCS, vol. 9690, pp. 19\u201333. Springer, Heidelberg (2016). doi: 10.1007\/978-3-319-40648-0_2"},{"key":"2_CR3","series-title":"Lecture Notes in Computer Science","volume-title":"NASA Formal Methods","year":"2014","unstructured":"Badger, J., Rozier, K.Y. (eds.): NFM 2014. LNCS, vol. 8430. Springer, Heidelberg (2014)"},{"key":"2_CR4","doi-asserted-by":"crossref","unstructured":"Badger, J., Rozier, K.Y.: Panel: future directions of specifications for formal methods. In: Badger, J., Rozier, K.Y. (eds.) NFM. LNCS, vol. 8430, pp. XX-XXI. Springer, May 2014","DOI":"10.1007\/978-3-319-06200-6"},{"key":"2_CR5","doi-asserted-by":"crossref","unstructured":"Badger, J., Throop, D., Claunch, C.: Vared: verification and analysis of requirements and early designs. In: Requirements Engineering, pp. 325\u2013326. IEEE (2014)","DOI":"10.1109\/RE.2014.6912279"},{"issue":"1","key":"2_CR6","doi-asserted-by":"crossref","first-page":"45","DOI":"10.1007\/s00165-015-0348-9","volume":"28","author":"J Barnat","year":"2016","unstructured":"Barnat, J., Bauch, P., Bene\u0161, N., Brim, L., Beran, J., Kratochv\u00edla, T.: Analysing sanity of requirements for avionics systems. Formal Aspects Comput. 28(1), 45\u201363 (2016)","journal-title":"Formal Aspects Comput."},{"issue":"2","key":"2_CR7","doi-asserted-by":"crossref","first-page":"141","DOI":"10.1023\/A:1008779610539","volume":"18","author":"I Beer","year":"2001","unstructured":"Beer, I., Ben-David, S., Eisner, C., Rodeh, Y.: Efficient detection of vacuity in ACTL formulas. Formal Methods Syst. Des. 18(2), 141\u2013162 (2001)","journal-title":"Formal Methods Syst. Des."},{"key":"2_CR8","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"425","DOI":"10.1007\/978-3-642-14295-6_37","volume-title":"Computer Aided Verification","author":"R Bloem","year":"2010","unstructured":"Bloem, R., Cimatti, A., Greimel, K., Hofferek, G., K\u00f6nighofer, R., Roveri, M., Schuppan, V., Seeber, R.: RATSY \u2013 a new requirements analysis tool with synthesis. In: Touili, T., Cook, B., Jackson, P. (eds.) CAV 2010. LNCS, vol. 6174, pp. 425\u2013429. Springer, Heidelberg (2010). doi: 10.1007\/978-3-642-14295-6_37"},{"key":"2_CR9","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"652","DOI":"10.1007\/978-3-642-31424-7_45","volume-title":"Computer Aided Verification","author":"A Bohy","year":"2012","unstructured":"Bohy, A., Bruy\u00e8re, V., Filiot, E., Jin, N., Raskin, J.-F.: Acacia+, a tool for LTL synthesis. In: Madhusudan, P., Seshia, S.A. (eds.) CAV 2012. LNCS, vol. 7358, pp. 652\u2013657. Springer, Heidelberg (2012). doi: 10.1007\/978-3-642-31424-7_45"},{"key":"2_CR10","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"316","DOI":"10.1007\/978-3-642-38613-8_22","volume-title":"Integrated Formal Methods","author":"KC Castillos","year":"2013","unstructured":"Castillos, K.C., Dadeau, F., Julliand, J., Kanso, B., Taha, S.: A compositional automata-based semantics for property patterns. In: Johnsen, E.B., Petre, L. (eds.) IFM 2013. LNCS, vol. 7940, pp. 316\u2013330. Springer, Heidelberg (2013). doi: 10.1007\/978-3-642-38613-8_22"},{"key":"2_CR11","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"66","DOI":"10.1007\/3-540-44585-4_7","volume-title":"Computer Aided Verification","author":"H Chockler","year":"2001","unstructured":"Chockler, H., Kupferman, O., Kurshan, R.P., Vardi, M.Y.: A practical approach to coverage in model checking. In: Berry, G., Comon, H., Finkel, A. (eds.) CAV 2001. LNCS, vol. 2102, pp. 66\u201378. Springer, Heidelberg (2001). doi: 10.1007\/3-540-44585-4_7"},{"key":"2_CR12","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"52","DOI":"10.1007\/978-3-540-78163-9_9","volume-title":"Verification, Model Checking, and Abstract Interpretation","author":"A Cimatti","year":"2008","unstructured":"Cimatti, A., Roveri, M., Schuppan, V., Tchaltsev, A.: Diagnostic information for realizability. In: Logozzo, F., Peled, D.A., Zuck, L.D. (eds.) VMCAI 2008. LNCS, vol. 4905, pp. 52\u201367. Springer, Heidelberg (2008). doi: 10.1007\/978-3-540-78163-9_9"},{"key":"2_CR13","doi-asserted-by":"crossref","unstructured":"Dallmeier, V., Knopp, N., Mallon, C., Hack, S., Zeller, A.: Generating test cases for specification mining. In: ISSTA, pp. 85\u201396. ACM (2010)","DOI":"10.1145\/1831708.1831719"},{"key":"2_CR14","doi-asserted-by":"crossref","unstructured":"Dwyer, M.B., Avrunin, G.S., Corbett, J.C.: Property specification patterns for finite-state verification. In: FMSP, pp. 7\u201315. ACM (1998)","DOI":"10.1145\/298595.298598"},{"key":"2_CR15","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"7","DOI":"10.1007\/978-3-642-01702-5_7","volume-title":"Hardware and Software: Verification and Testing","author":"D Fisman","year":"2009","unstructured":"Fisman, D., Kupferman, O., Sheinvald-Faragy, S., Vardi, M.Y.: A framework for inherent vacuity. In: Chockler, H., Hu, A.J. (eds.) HVC 2008. LNCS, vol. 5394, pp. 7\u201322. Springer, Heidelberg (2009). doi: 10.1007\/978-3-642-01702-5_7"},{"key":"2_CR16","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"3","DOI":"10.1007\/978-3-319-41540-6_1","volume-title":"Computer Aided Verification","author":"M Gario","year":"2016","unstructured":"Gario, M., Cimatti, A., Mattarei, C., Tonetta, S., Rozier, K.Y.: Model checking at scale: automated air traffic control design space exploration. In: Chaudhuri, S., Farzan, A. (eds.) CAV 2016. LNCS, vol. 9780, pp. 3\u201322. Springer, Heidelberg (2016). doi: 10.1007\/978-3-319-41540-6_1"},{"key":"2_CR17","doi-asserted-by":"crossref","unstructured":"Gario, M., Cimatti, A., Mattarei, C., Tonetta, S., Rozier, K.Y.: Model checking at scale: automated air traffic control design space exploration. Presentation: https:\/\/es-static.fbk.eu\/projects\/nasa-aac\/download\/CAV2016_presentation.pdf#21 (2016-07-22)","DOI":"10.1007\/978-3-319-41540-6_1"},{"key":"2_CR18","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"215","DOI":"10.1007\/978-3-319-11164-3_18","volume-title":"Runtime Verification","author":"J Geist","year":"2014","unstructured":"Geist, J., Rozier, K.Y., Schumann, J.: Runtime observer pairs and Bayesian Network reasoners on-board FPGAs: flight-certifiable system health management for embedded systems. In: Bonakdarpour, B., Smolka, S.A. (eds.) RV 2014. LNCS, vol. 8734, pp. 215\u2013230. Springer, Heidelberg (2014). doi: 10.1007\/978-3-319-11164-3_18"},{"key":"2_CR19","unstructured":"Gheorghiu, M., Gurfinkel, A., Chechik, M.: VaqUoT: a tool for vacuity detection. In: Posters & Research Tools Track, FM 2006 (2006)"},{"key":"2_CR20","doi-asserted-by":"crossref","unstructured":"Ghosh, S., Shankar, N., Lincoln, P., Elenius, D., Li, W., Steiener, W.: Automatic Requirements Specification Extraction from Natural Language (ARSENAL). Technical report, DTIC Document (2014)","DOI":"10.21236\/ADA611691"},{"key":"2_CR21","doi-asserted-by":"crossref","unstructured":"Gross, K.H., Fifarek, A.W., Hoffman, J.A.: Incremental formal methods based design approach demonstrated on a coupled tanks control system. In: HASE, pp. 181\u2013188. IEEE (2016)","DOI":"10.1109\/HASE.2016.16"},{"key":"2_CR22","doi-asserted-by":"crossref","unstructured":"Gundy-Burlet, K.: Validation and verification of LADEE models and software. In: 51st AIAA Aerospace Sciences Meeting Including the New Horizons Forum and Aerospace Exposition (2013)","DOI":"10.2514\/6.2013-592"},{"issue":"1","key":"2_CR23","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/2071368.2071369","volume":"13","author":"A Gurfinkel","year":"2012","unstructured":"Gurfinkel, A., Chechik, M.: Robust vacuity for branching temporal logic. ACM Trans. Comput. Logic (TOCL) 13(1), 1 (2012)","journal-title":"ACM Trans. Comput. Logic (TOCL)"},{"issue":"3","key":"2_CR24","doi-asserted-by":"crossref","first-page":"231","DOI":"10.1145\/234426.234431","volume":"5","author":"C Heitmeyer","year":"1996","unstructured":"Heitmeyer, C., Jeffords, R., Labaw, B.: Automated consistency checking of requirements specifications. ACM Trans. Softw. Eng. Methodol. 5(3), 231\u2013261 (1996)","journal-title":"ACM Trans. Softw. Eng. Methodol."},{"key":"2_CR25","unstructured":"Hoffman, J.A.: Utilizing assume guarantee contracts to construct verifiable simulink model blocks. S5 (2015). http:\/\/mys5.org\/Proceedings\/2015\/Day_1\/2015-S5-Day1_1255_Hoffman.pdf"},{"key":"2_CR26","unstructured":"Hoffman, J.A.: V&V of Autonomy: UxV Challenge Problem (UCP). S5 (2016). http:\/\/mys5.org\/Proceedings\/2016\/Day_3\/2016-S5-Day3_0805_Hoffman.pdf"},{"key":"2_CR27","unstructured":"Jackson, C.: Face it: The engineering V is outdated (2014). https:\/\/www.linkedin.com\/pulse\/20140721140340-5687591-face-it-the-engineering-v-is-outdated"},{"key":"2_CR28","doi-asserted-by":"crossref","unstructured":"Jafer, S., Chhaya, B., Durak, U., Gerlach, T.: Formal scenario definition language for aviation: aircraft landing case study. In: AIAA MST (2016)","DOI":"10.2514\/6.2016-3521"},{"key":"2_CR29","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"29","DOI":"10.1007\/978-3-642-19583-9_8","volume-title":"Hardware and Software: Verification and Testing","author":"R K\u00f6nighofer","year":"2011","unstructured":"K\u00f6nighofer, R., Hofferek, G., Bloem, R.: Debugging unrealizable specifications with model-based diagnosis. In: Barner, S., Harris, I., Kroening, D., Raz, O. (eds.) HVC 2010. LNCS, vol. 6504, pp. 29\u201345. Springer, Heidelberg (2011). doi: 10.1007\/978-3-642-19583-9_8"},{"key":"2_CR30","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"37","DOI":"10.1007\/11817949_3","volume-title":"CONCUR 2006 \u2013 Concurrency Theory","author":"O Kupferman","year":"2006","unstructured":"Kupferman, O.: Sanity checks in formal verification. In: Baier, C., Hermanns, H. (eds.) CONCUR 2006. LNCS, vol. 4137, pp. 37\u201351. Springer, Heidelberg (2006). doi: 10.1007\/11817949_3"},{"issue":"2","key":"2_CR31","doi-asserted-by":"crossref","first-page":"224","DOI":"10.1007\/s100090100062","volume":"4","author":"O Kupferman","year":"2003","unstructured":"Kupferman, O., Vardi, M.: Vacuity detection in temporal model checking. J. Softw. Tools Technol. Transf. (STTT) 4(2), 224\u2013233 (2003)","journal-title":"J. Softw. Tools Technol. Transf. (STTT)"},{"key":"2_CR32","unstructured":"Kurshan, R.: FormalCheck User\u2019s Manual. Cadence Design, Inc. (1998)"},{"key":"2_CR33","doi-asserted-by":"crossref","unstructured":"Li, J., Zhang, L., Pu, G., Vardi, M.Y., He, J.: LTL satisfiability checking revisited. In: TIME, pp. 91\u201398. IEEE (2013)","DOI":"10.1109\/TIME.2013.19"},{"key":"2_CR34","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"209","DOI":"10.1007\/978-3-319-26287-1_13","volume-title":"Hardware and Software: Verification and Testing","author":"J Li","year":"2015","unstructured":"Li, J., Zhu, S., Pu, G., Vardi, M.Y.: SAT-based explicit LTL reasoning. In: Piterman, N. (ed.) HVC 2015. LNCS, vol. 9434, pp. 209\u2013224. Springer, Heidelberg (2015). doi: 10.1007\/978-3-319-26287-1_13"},{"key":"2_CR35","doi-asserted-by":"crossref","unstructured":"Li, W., Dworkin, L., Seshia, S.A.: Mining assumptions for synthesis. In: MEMOCODE, pp. 43\u201350. IEEE (2011)","DOI":"10.1109\/MEMCOD.2011.5970509"},{"key":"2_CR36","volume-title":"The Temporal Logic of Reactive and Concurrent Systems: Specification","author":"Z Manna","year":"2012","unstructured":"Manna, Z., Pnueli, A.: The Temporal Logic of Reactive and Concurrent Systems: Specification. Springer Science & Business Media, New York (2012)"},{"key":"2_CR37","doi-asserted-by":"crossref","unstructured":"Mattarei, C., Cimatti, A., Gario, M., Tonetta, S., Rozier, K.Y.: Comparing different functional allocations in automated air traffic control design. In: FMCAD. IEEE\/ACM (2015)","DOI":"10.1109\/FMCAD.2015.7542260"},{"issue":"4","key":"2_CR38","doi-asserted-by":"crossref","first-page":"235","DOI":"10.1007\/s11334-013-0223-x","volume":"9","author":"L Pike","year":"2013","unstructured":"Pike, L., Wegmann, N., Niller, S., Goodloe, A.: Copilot: monitoring embedded systems. Innov. Syst. Softw. Eng. 9(4), 235\u2013255 (2013)","journal-title":"Innov. Syst. Softw. Eng."},{"key":"2_CR39","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"364","DOI":"10.1007\/11609773_24","volume-title":"Verification, Model Checking, and Abstract Interpretation","author":"N Piterman","year":"2005","unstructured":"Piterman, N., Pnueli, A., Sa\u2019ar, Y.: Synthesis of reactive(1) designs. In: Emerson, E.A., Namjoshi, K.S. (eds.) VMCAI 2006. LNCS, vol. 3855, pp. 364\u2013380. Springer, Heidelberg (2005). doi: 10.1007\/11609773_24"},{"key":"2_CR40","doi-asserted-by":"crossref","unstructured":"Pnueli, A., Rosner, R.: On the synthesis of a reactive module. In: POPL, pp. 179\u2013190 (1989)","DOI":"10.1145\/75277.75293"},{"key":"2_CR41","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"357","DOI":"10.1007\/978-3-642-54862-8_24","volume-title":"Tools and Algorithms for the Construction and Analysis of Systems","author":"T Reinbacher","year":"2014","unstructured":"Reinbacher, T., Rozier, K.Y., Schumann, J.: Temporal-logic based runtime observer pairs for system health management of real-time systems. In: \u00c1brah\u00e1m, E., Havelund, K. (eds.) TACAS 2014. LNCS, vol. 8413, pp. 357\u2013372. Springer, Heidelberg (2014). doi: 10.1007\/978-3-642-54862-8_24"},{"key":"2_CR42","unstructured":"Rodriguez, M.A., Neubauer, P.: The graph traversal pattern. arXiv preprint arXiv:1004.1001 (2010)"},{"key":"2_CR43","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"149","DOI":"10.1007\/978-3-540-73370-6_11","volume-title":"Model Checking Software","author":"KY Rozier","year":"2007","unstructured":"Rozier, K.Y., Vardi, M.Y.: LTL satisfiability checking. In: Bo\u0161na\u010dki, D., Edelkamp, S. (eds.) SPIN 2007. LNCS, vol. 4595, pp. 149\u2013167. Springer, Heidelberg (2007). doi: 10.1007\/978-3-540-73370-6_11"},{"issue":"2","key":"2_CR44","doi-asserted-by":"crossref","first-page":"123","DOI":"10.1007\/s10009-010-0140-3","volume":"12","author":"K Rozier","year":"2010","unstructured":"Rozier, K., Vardi, M.: LTL satisfiability checking. Int. J. Softw. Tools Technol. Transf. (STTT) 12(2), 123\u2013137 (2010)","journal-title":"Int. J. Softw. Tools Technol. Transf. (STTT)"},{"key":"2_CR45","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"417","DOI":"10.1007\/978-3-642-21437-0_31","volume-title":"FM 2011: Formal Methods","author":"KY Rozier","year":"2011","unstructured":"Rozier, K.Y., Vardi, M.Y.: A multi-encoding approach for LTL symbolic satisfiability checking. In: Butler, M., Schulte, W. (eds.) FM 2011. LNCS, vol. 6664, pp. 417\u2013431. Springer, Heidelberg (2011). doi: 10.1007\/978-3-642-21437-0_31"},{"key":"2_CR46","unstructured":"RTCA: DO-178B: Software Considerations in Airborne Systems and Equipment Certification (1992). http:\/\/www.rtca.org"},{"key":"2_CR47","unstructured":"RTCA: DO-254: Design assurance guidance for airborne electronic hardware, April 2000"},{"key":"2_CR48","unstructured":"RTCA: DO-178C\/ED-12C: Software considerations in airborne systems and equipment certification (2012). http:\/\/www.rtca.org"},{"key":"2_CR49","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"233","DOI":"10.1007\/978-3-319-23820-3_15","volume-title":"Runtime Verification","author":"J Schumann","year":"2015","unstructured":"Schumann, J., Moosbrugger, P., Rozier, K.Y.: R2U2: monitoring and diagnosis of security threats for unmanned aerial systems. In: Bartocci, E., Majumdar, R. (eds.) RV 2015. LNCS, vol. 9333, pp. 233\u2013249. Springer, Heidelberg (2015). doi: 10.1007\/978-3-319-23820-3_15"},{"key":"2_CR50","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"504","DOI":"10.1007\/978-3-319-46982-9_35","volume-title":"Runtime Verification","author":"J Schumann","year":"2016","unstructured":"Schumann, J., Moosbrugger, P., Rozier, K.Y.: Runtime analysis with R2U2: a tool exhibition report. In: Falcone, Y., S\u00e1nchez, C. (eds.) RV 2016. LNCS, vol. 10012, pp. 504\u2013509. Springer, Heidelberg (2016). doi: 10.1007\/978-3-319-46982-9_35"},{"issue":"1","key":"2_CR51","first-page":"1","volume":"6","author":"J Schumann","year":"2015","unstructured":"Schumann, J., Rozier, K.Y., Reinbacher, T., Mengshoel, O.J., Mbaya, T., Ippolito, C.: Towards real-time, on-board, hardware-supported sensor and software health management for Unmanned Aerial Systems. IJPHM 6(1), 1\u201327 (2015)","journal-title":"IJPHM"},{"key":"2_CR52","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"2","DOI":"10.1007\/978-3-540-87873-5_2","volume-title":"Verified Software: Theories, Tools, Experiments","author":"MY Vardi","year":"2008","unstructured":"Vardi, M.Y.: From verification to synthesis. In: Shankar, N., Woodcock, J. (eds.) VSTTE 2008. LNCS, vol. 5295, pp. 2\u20132. Springer, Heidelberg (2008). doi: 10.1007\/978-3-540-87873-5_2"},{"key":"2_CR53","doi-asserted-by":"crossref","unstructured":"Whalen, M.W., Rayadurgam, S., Ghassabani, E., Murugesan, A., Sokolsky, O., Heimdahl, M.P., Lee, I.: Hierarchical multi-formalism proofs of cyber-physical systems. In: MEMOCODE, pp. 90\u201395. IEEE (2015)","DOI":"10.1109\/MEMCOD.2015.7340474"},{"key":"2_CR54","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"2","DOI":"10.1007\/978-3-642-20398-5_2","volume-title":"NASA Formal Methods","author":"A Zeller","year":"2011","unstructured":"Zeller, A.: Specifications for free. In: Bobaru, M., Havelund, K., Holzmann, G.J., Joshi, R. (eds.) NFM 2011. LNCS, vol. 6617, pp. 2\u201312. Springer, Heidelberg (2011). doi: 10.1007\/978-3-642-20398-5_2"},{"key":"2_CR55","unstructured":"Zhao, Y., Rozier, K.Y.: Formal specification and verification of a coordination protocol for an automated air traffic control system. In: AVoCS. Electronic Communications of the EASST, vol.\u00a053 (2012)"},{"issue":"3","key":"2_CR56","first-page":"337","volume":"96","author":"Y Zhao","year":"2014","unstructured":"Zhao, Y., Rozier, K.Y.: Formal specification and verification of a coordination protocol for an automated air traffic control system. SCP J. 96(3), 337\u2013353 (2014)","journal-title":"SCP J."},{"key":"2_CR57","doi-asserted-by":"crossref","unstructured":"Zhao, Y., Rozier, K.Y.: Probabilistic model checking for comparative analysis of automated air traffic control systems. In: ICCAD, pp. 690\u2013695. IEEE\/ACM (2014)","DOI":"10.1109\/ICCAD.2014.7001427"}],"container-title":["Lecture Notes in Computer Science","Verified Software. Theories, Tools, and Experiments"],"original-title":[],"link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-319-48869-1_2","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,9,15]],"date-time":"2019-09-15T05:59:49Z","timestamp":1568527189000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-319-48869-1_2"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2016]]},"ISBN":["9783319488684","9783319488691"],"references-count":57,"URL":"https:\/\/doi.org\/10.1007\/978-3-319-48869-1_2","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2016]]}}}