<?xml version="1.0" encoding="ISO-8859-1"?><article xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance">
<front>
<journal-meta>
<journal-id>1405-5546</journal-id>
<journal-title><![CDATA[Computación y Sistemas]]></journal-title>
<abbrev-journal-title><![CDATA[Comp. y Sist.]]></abbrev-journal-title>
<issn>1405-5546</issn>
<publisher>
<publisher-name><![CDATA[Instituto Politécnico Nacional, Centro de Investigación en Computación]]></publisher-name>
</publisher>
</journal-meta>
<article-meta>
<article-id>S1405-55462004000300004</article-id>
<title-group>
<article-title xml:lang="es"><![CDATA[Especificación y Análisis de Sistemas de Tiempo Real en Teoría de Tipos]]></article-title>
<article-title xml:lang="en"><![CDATA[Specification and Analysis of Real Time Systems in Type Theory]]></article-title>
</title-group>
<contrib-group>
<contrib contrib-type="author">
<name>
<surname><![CDATA[Luna]]></surname>
<given-names><![CDATA[Carlos Daniel]]></given-names>
</name>
<xref ref-type="aff" rid="A01"/>
</contrib>
</contrib-group>
<aff id="A01">
<institution><![CDATA[,Univ. de la República Facultad de Ingeniería Instituto de Computación]]></institution>
<addr-line><![CDATA[Montevideo ]]></addr-line>
<country>Uruguay</country>
</aff>
<pub-date pub-type="pub">
<day>00</day>
<month>09</month>
<year>2004</year>
</pub-date>
<pub-date pub-type="epub">
<day>00</day>
<month>09</month>
<year>2004</year>
</pub-date>
<volume>8</volume>
<numero>1</numero>
<fpage>24</fpage>
<lpage>45</lpage>
<copyright-statement/>
<copyright-year/>
<self-uri xlink:href="http://www.scielo.org.mx/scielo.php?script=sci_arttext&amp;pid=S1405-55462004000300004&amp;lng=en&amp;nrm=iso"></self-uri><self-uri xlink:href="http://www.scielo.org.mx/scielo.php?script=sci_abstract&amp;pid=S1405-55462004000300004&amp;lng=en&amp;nrm=iso"></self-uri><self-uri xlink:href="http://www.scielo.org.mx/scielo.php?script=sci_pdf&amp;pid=S1405-55462004000300004&amp;lng=en&amp;nrm=iso"></self-uri><abstract abstract-type="short" xml:lang="es"><p><![CDATA[Para el análisis de sistemas de tiempo real se destacan dos enfoques formales: la verificación de modelos y el análisis deductivo basado en asistentes de pruebas. El primero se caracteriza por ser completamente automatizable pero presenta dificultades al tratar sistemas con un gran número de estados o que tienen parámetros no acotados. El segundo permite tratar con sistemas arbitrarios pero requiere la interacción del usuario. Este trabajo explora una metodología que permite compatibilizar el uso de un verificador de modelos como Kronos y el asistente de pruebas Coq en el análisis de sistemas de tiempo real. Un especial énfasis es puesto en el análisis de un caso de estudio, considerado como benchmark en diferentes trabajos: el control de un paso a nivel de tren.]]></p></abstract>
<abstract abstract-type="short" xml:lang="en"><p><![CDATA[Two formal approaches arise as the most used for the analysis of real time systems: model checking and deductive analysis based on proof assistants. The former is characterized by its fully automatization but it presents some difficulties when dealing with systems that involve a great number of states or unbound parameters. The latter, on the other hand, turns out to be appropriate for working with arbitrary systems, though user's interaction is required. This work explores a methodology that combines the use of a model checker like Kronos and the proof assistant Coq for the analysis of real time systems. We specially emphasize the analysis of the railroad crossing example, a case study considered a benchmark by different works in this field.]]></p></abstract>
</article-meta>
</front><body><![CDATA[ <p align="center"><font face="verdana" size="4"><b>Especificaci&oacute;n y An&aacute;lisis de Sistemas de Tiempo Real en Teor&iacute;a de Tipos <a href="#nota">1</a></b></font></p>     <p align="center"><font face="verdana" size="2">&nbsp;</font></p>     <p align="center"><font face="verdana" size="3"><b><i>Specification and Analysis of Real Time Systems in Type Theory</i></b></font></p>     <p align="center"><font face="verdana" size="2">&nbsp;</font></p>     <p align="center"><font face="verdana" size="2"><b>Carlos Daniel Luna</b></font></p>     <p align="justify"><font face="verdana" size="2">&nbsp;</font></p>     <p align="justify"><font face="verdana" size="2"><i>Instituto de Computaci&oacute;n (InCo). Facultad de Ingenier&iacute;a. Univ. de la Rep&uacute;blica. Montevideo, Uruguay Casilla de Correo 16120, Distrito 6, Montevideo, Uruguay E&#150;mail: <a href="mailto:cluna@fing.edu.uy">cluna@fing.edu.uy</a> ; Web: <a href="http://www.fing.edu.uy/~cluna/" target="_blank">http://www.fing.edu.uy/~cluna</a></i></font></p>     <p align="justify"><font face="verdana" size="2">&nbsp;</font></p>     <p align="justify"><font face="verdana" size="2">Art&iacute;culo recibido en abril 27, 2001    <br> Aceptado en agosto 8, 2004 </font></p>     ]]></body>
<body><![CDATA[<p align="justify"><font face="verdana" size="2">&nbsp;</font></p>     <p align="justify"><font face="verdana" size="2"><b>Resumen</b></font></p>     <p align="justify"><font face="verdana" size="2">Para el an&aacute;lisis de sistemas de tiempo real se destacan dos enfoques formales: la verificaci&oacute;n de modelos y el an&aacute;lisis deductivo basado en asistentes de pruebas. El primero se caracteriza por ser completamente automatizable pero presenta dificultades al tratar sistemas con un gran n&uacute;mero de estados o que tienen par&aacute;metros no acotados. El segundo permite tratar con sistemas arbitrarios pero requiere la interacci&oacute;n del usuario. Este trabajo explora una metodolog&iacute;a que permite compatibilizar el uso de un verificador de modelos como <i>Kronos </i>y el asistente de pruebas <i>Coq </i>en el an&aacute;lisis de sistemas de tiempo real. Un especial &eacute;nfasis es puesto en el an&aacute;lisis de un caso de estudio, considerado como <i>benchmark </i>en diferentes trabajos: <i>el control de un paso a nivel de tren.</i></font></p>     <p align="justify"><font face="verdana" size="2">&nbsp;</font></p>     <p align="justify"><font face="verdana" size="2"><b>Abstract</b></font></p>     <p align="justify"><font face="verdana" size="2">Two formal approaches arise as the most used for the analysis of real time systems: model checking and deductive analysis based on proof assistants. The former is characterized by its fully automatization but it presents some difficulties when dealing with systems that involve a great number of states or unbound parameters. The latter, on the other hand, turns out to be appropriate for working with arbitrary systems, though user's interaction is required. This work explores a methodology that combines the use of a model checker like <i>Kronos </i>and the proof assistant <i>Coq </i>for the analysis of real time systems. We specially emphasize the analysis of the railroad crossing example, a case study considered a benchmark by different works in this field.</font></p>     <p align="justify"><font face="verdana" size="2">&nbsp;</font></p>     <p align="justify"><font face="verdana" size="2"><a href="/pdf/cys/v8n1/v8n1a4.pdf" target="_blank">DESCARGAR ART&Iacute;CULO EN FORMATO PDF</a></font></p>     <p align="justify"><font face="verdana" size="2">&nbsp;</font></p>     <p align="justify"><font face="verdana" size="2"><b>Referencias</b></font></p>     ]]></body>
<body><![CDATA[<!-- ref --><p align="justify"><font face="verdana" size="2">1. <b>J. Armstrong </b>and<b> L. Barroca. </b>"Specification and verification of reactive systems behaviour: The railroad crossing example". <i>Real&#150;Time Systems, </i>10:143&#150;178, 1996.</font>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;[&#160;<a href="javascript:void(0);" onclick="javascript: window.open('/scielo.php?script=sci_nlinks&ref=2037171&pid=S1405-5546200400030000400001&lng=','','width=640,height=500,resizable=yes,scrollbars=1,menubar=yes,');">Links</a>&#160;]<!-- end-ref --><!-- ref --><p align="justify"><font face="verdana" size="2">2. <b>R. Alur, C.   Courcoubetis, </b>and<b> D. Dill. </b>"Model&#150;checking for real&#150;time systems". In <i>Proc. 5<sup>th</sup> Symp on Logics in Computer </i><i>Science, </i>pages 414&#150;425. IEEE Computer Society Press, 1990.</font>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;[&#160;<a href="javascript:void(0);" onclick="javascript: window.open('/scielo.php?script=sci_nlinks&ref=2037172&pid=S1405-5546200400030000400002&lng=','','width=640,height=500,resizable=yes,scrollbars=1,menubar=yes,');">Links</a>&#160;]<!-- end-ref --><!-- ref --><p align="justify"><font face="verdana" size="2">3. <b>R. Alur </b>and<b> D. Dill. </b>"A theory of timed automata". <i>Theorical Computer Science, </i>126:183&#150;235, 1994. </font>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;[&#160;<a href="javascript:void(0);" onclick="javascript: window.open('/scielo.php?script=sci_nlinks&ref=2037173&pid=S1405-5546200400030000400003&lng=','','width=640,height=500,resizable=yes,scrollbars=1,menubar=yes,');">Links</a>&#160;]<!-- end-ref --><!-- ref --><p align="justify"><font face="verdana" size="2">4. <b>R. Alur </b>and<b> T. Henzinger. </b>"Logics and models of real time: A survey". In J. W. de Bakker, K. Huizing, W.&#150;P. de Roever, and G. Rozenberg, editors, <i>Real Time Theory in Practice, LNCS </i>600, pages 74&#150;106. Springer&#150;Verlag, 1992. </font>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;[&#160;<a href="javascript:void(0);" onclick="javascript: window.open('/scielo.php?script=sci_nlinks&ref=2037174&pid=S1405-5546200400030000400004&lng=','','width=640,height=500,resizable=yes,scrollbars=1,menubar=yes,');">Links</a>&#160;]<!-- end-ref --><!-- ref --><p align="justify"><font face="verdana" size="2">5. <b>R. Alur </b>and<b> T. Henzinger. </b>"A Really Temporal Logic". <i>Journal of the ACM, </i>41(1): 181&#150;204, 1994. </font>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;[&#160;<a href="javascript:void(0);" onclick="javascript: window.open('/scielo.php?script=sci_nlinks&ref=2037175&pid=S1405-5546200400030000400005&lng=','','width=640,height=500,resizable=yes,scrollbars=1,menubar=yes,');">Links</a>&#160;]<!-- end-ref --><!-- ref --><p align="justify"><font face="verdana" size="2">6. <b>R. Alur. </b><i>Techniques for automatic verification of real&#150;time systems. </i>PhD thesis, Stanford University, 1991. </font>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;[&#160;<a href="javascript:void(0);" onclick="javascript: window.open('/scielo.php?script=sci_nlinks&ref=2037176&pid=S1405-5546200400030000400006&lng=','','width=640,height=500,resizable=yes,scrollbars=1,menubar=yes,');">Links</a>&#160;]<!-- end-ref --><!-- ref --><p align="justify"><font face="verdana" size="2">7<b>. </b><b>A. Asarin, O Maler, </b>and<b> A. Pnueli. </b>"On the discretization of delays in timed automata and digital circuits". In R. de Simone and D. Sangiorgi (Eds.), <i>Proc. Concur'98, LNCS </i>1466, pages 470&#150;484, Springer&#150;Verlag, 1998. </font>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;[&#160;<a href="javascript:void(0);" onclick="javascript: window.open('/scielo.php?script=sci_nlinks&ref=2037177&pid=S1405-5546200400030000400007&lng=','','width=640,height=500,resizable=yes,scrollbars=1,menubar=yes,');">Links</a>&#160;]<!-- end-ref --><!-- ref --><p align="justify"><font face="verdana" size="2">8. <b>B. Alpern and F. Schneider. </b>"Defining liveness". <i>Information Processing Letters, </i>21(4): 181&#150;185, 1985. </font>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;[&#160;<a href="javascript:void(0);" onclick="javascript: window.open('/scielo.php?script=sci_nlinks&ref=2037178&pid=S1405-5546200400030000400008&lng=','','width=640,height=500,resizable=yes,scrollbars=1,menubar=yes,');">Links</a>&#160;]<!-- end-ref --><!-- ref --><p align="justify"><font face="verdana" size="2">9. <b>B. Barras, S. Boutin, C. Cornes, J. Courant, Y. Coscoy, D. Delahaye, D. de Rauglaudre, J&#150;C. Filli&acirc;tre, E. Gim&eacute;nez, H. Herbelin, G. Huet, H. Laulh&egrave;re, C. Mu&ntilde;oz, Ch. Murthy, C. Parent&#150;Vigouroux, P. Loiseleur, Ch. Paulin&#150;Mohring, A. Sa&iuml;bi, </b>and<b> B. Werner. </b>"The Coq Proof Assistant. Reference Manual, Versi&oacute;n 6.2.4". <i>INRIA, </i>1999. </font>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;[&#160;<a href="javascript:void(0);" onclick="javascript: window.open('/scielo.php?script=sci_nlinks&ref=2037179&pid=S1405-5546200400030000400009&lng=','','width=640,height=500,resizable=yes,scrollbars=1,menubar=yes,');">Links</a>&#160;]<!-- end-ref --><!-- ref --><p align="justify"><font face="verdana" size="2">10. <b>N. S. Bj&oslash;rner, A. Browne, </b>and<b> Z. Manna. </b>"Automatic generation of invariants and intermediate assertions". <i>Theorical </i><i>Computer Science, </i>173(1):49&#150;87, 1997.</font>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;[&#160;<a href="javascript:void(0);" onclick="javascript: window.open('/scielo.php?script=sci_nlinks&ref=2037180&pid=S1405-5546200400030000400010&lng=','','width=640,height=500,resizable=yes,scrollbars=1,menubar=yes,');">Links</a>&#160;]<!-- end-ref --><!-- ref --><p align="justify"><font face="verdana" size="2">11. <b>S. Bensalem </b>and<b> Y. Lakhench. </b>"Automatic generation of invariants". To appear in <i>Formal Methods, </i>1999.</font>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;[&#160;<a href="javascript:void(0);" onclick="javascript: window.open('/scielo.php?script=sci_nlinks&ref=2037181&pid=S1405-5546200400030000400011&lng=','','width=640,height=500,resizable=yes,scrollbars=1,menubar=yes,');">Links</a>&#160;]<!-- end-ref --><!-- ref --><p align="justify"><font face="verdana" size="2">12. <b>N. Bj&oslash;rner, Z. Manna, H. Spima, </b>and<b> T. Uribe. </b>"Deductive Verification of Real&#150;time Systems Using SteP". <i>ARTS&#150;97, </i>vol. 1231 of LNCS, pp. 22&#150;43, Springer&#150;Verlag, 1997. </font>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;[&#160;<a href="javascript:void(0);" onclick="javascript: window.open('/scielo.php?script=sci_nlinks&ref=2037182&pid=S1405-5546200400030000400012&lng=','','width=640,height=500,resizable=yes,scrollbars=1,menubar=yes,');">Links</a>&#160;]<!-- end-ref --><!-- ref --><p align="justify"><font face="verdana" size="2">13. <b>M. Bozga, O. Maler, </b>and<b> S. Tripakis. </b>"Efficient verification of timed automata using dense and discrete time semantics". In L. Pierre and T. Kropf (Eds.),<i>Proc CHARME'99, </i>Springer&#150;Verlag, 1999. </font>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;[&#160;<a href="javascript:void(0);" onclick="javascript: window.open('/scielo.php?script=sci_nlinks&ref=2037183&pid=S1405-5546200400030000400013&lng=','','width=640,height=500,resizable=yes,scrollbars=1,menubar=yes,');">Links</a>&#160;]<!-- end-ref --><!-- ref --><p align="justify"><font face="verdana" size="2">14. <b>J. Burch. </b>"Combining CTL, trace theory and timing models", <i>Automatic Verification Methods for Finite State Systems, LNCS </i>407, 1989.</font>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;[&#160;<a href="javascript:void(0);" onclick="javascript: window.open('/scielo.php?script=sci_nlinks&ref=2037184&pid=S1405-5546200400030000400014&lng=','','width=640,height=500,resizable=yes,scrollbars=1,menubar=yes,');">Links</a>&#160;]<!-- end-ref --><!-- ref --><p align="justify"><font face="verdana" size="2">15. <b>E.  Clarke, E. Emerson, </b>and<b> A.  Sistla. </b>"Automatic verification of finite&#150;state concurrent systems using temporal logic specifications". <i>ACM Transactions on Programming Languages and Systems, </i>8(2):244&#150;263, 1986. </font>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;[&#160;<a href="javascript:void(0);" onclick="javascript: window.open('/scielo.php?script=sci_nlinks&ref=2037185&pid=S1405-5546200400030000400015&lng=','','width=640,height=500,resizable=yes,scrollbars=1,menubar=yes,');">Links</a>&#160;]<!-- end-ref --><!-- ref --><p align="justify"><font face="verdana" size="2">16. <b>T. Coquand </b>and<b> G. Huet. </b>"The calculus of constructions". <i>Information and Computation, </i>76(2/3), 1988. </font>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;[&#160;<a href="javascript:void(0);" onclick="javascript: window.open('/scielo.php?script=sci_nlinks&ref=2037186&pid=S1405-5546200400030000400016&lng=','','width=640,height=500,resizable=yes,scrollbars=1,menubar=yes,');">Links</a>&#160;]<!-- end-ref --><!-- ref --><p align="justify"><font face="verdana" size="2">17. <b>Z. Chaochen, C. Hoare, </b>and<b> A. Ravn. </b>"A calculus of durations". <i>Inform. Processing Letters, </i>40(5):269&#150;276, 1992.</font>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;[&#160;<a href="javascript:void(0);" onclick="javascript: window.open('/scielo.php?script=sci_nlinks&ref=2037187&pid=S1405-5546200400030000400017&lng=','','width=640,height=500,resizable=yes,scrollbars=1,menubar=yes,');">Links</a>&#160;]<!-- end-ref --><!-- ref --><p align="justify"><font face="verdana" size="2">18. <b>T. Coquand. </b>"Metamathematical investigations of a calculus of constructions". INRIA and Cambridge Univ., 1986.</font>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;[&#160;<a href="javascript:void(0);" onclick="javascript: window.open('/scielo.php?script=sci_nlinks&ref=2037188&pid=S1405-5546200400030000400018&lng=','','width=640,height=500,resizable=yes,scrollbars=1,menubar=yes,');">Links</a>&#160;]<!-- end-ref --><!-- ref --><p align="justify"><font face="verdana" size="2">19. <b>T. Coquand. </b>"Infinite objects in type theory". In H. Barendregt and T. Nipkow, editors, <i>Workshop on Types for Proofs and </i><i>Programs, </i>number 806 in LNCS, pages 62&#150;78. Springer&#150;Verlag, 1993. </font>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;[&#160;<a href="javascript:void(0);" onclick="javascript: window.open('/scielo.php?script=sci_nlinks&ref=2037189&pid=S1405-5546200400030000400019&lng=','','width=640,height=500,resizable=yes,scrollbars=1,menubar=yes,');">Links</a>&#160;]<!-- end-ref --><!-- ref --><p align="justify"><font face="verdana" size="2">20. <b>C. Daws </b>and<b> S. Yovine. </b>"Verification of multirate timed automata with KRONOS: two exemples". Technical Report Spectre&#150;95&#150; 06, VERIMAG, 1995.</font>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;[&#160;<a href="javascript:void(0);" onclick="javascript: window.open('/scielo.php?script=sci_nlinks&ref=2037190&pid=S1405-5546200400030000400020&lng=','','width=640,height=500,resizable=yes,scrollbars=1,menubar=yes,');">Links</a>&#160;]<!-- end-ref --><!-- ref --><p align="justify"><font face="verdana" size="2">21. <b>E. Emerson. </b>"Automated temporal reasoning about rective systems". <i>In Logics for Concurrency, </i>1995. </font>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;[&#160;<a href="javascript:void(0);" onclick="javascript: window.open('/scielo.php?script=sci_nlinks&ref=2037191&pid=S1405-5546200400030000400021&lng=','','width=640,height=500,resizable=yes,scrollbars=1,menubar=yes,');">Links</a>&#160;]<!-- end-ref --><!-- ref --><p align="justify"><font face="verdana" size="2">22. <b>E. Emerson, A. Mok, A. Sistla, </b>and<b> J. Srinivasan. </b>"Quantitative temporal reasoning". <i>Workshop on Automatic Verification </i><i>Methods for Finite State Systems, </i>Grenoble, France, 1989. </font>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;[&#160;<a href="javascript:void(0);" onclick="javascript: window.open('/scielo.php?script=sci_nlinks&ref=2037192&pid=S1405-5546200400030000400022&lng=','','width=640,height=500,resizable=yes,scrollbars=1,menubar=yes,');">Links</a>&#160;]<!-- end-ref --><!-- ref --><p align="justify"><font face="verdana" size="2">23. <b>E. Gim&eacute;nez. </b><i>A Calculus of Infinite Constructions and its application to the verification of communicating systems. </i>PhD thesis, Ecole Normale Sup&eacute;rieure de Lyon, 1996, Unit&eacute; de Recherche Associ&eacute;e au CNRS No. 1398, 1996. </font>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;[&#160;<a href="javascript:void(0);" onclick="javascript: window.open('/scielo.php?script=sci_nlinks&ref=2037193&pid=S1405-5546200400030000400023&lng=','','width=640,height=500,resizable=yes,scrollbars=1,menubar=yes,');">Links</a>&#160;]<!-- end-ref --><!-- ref --><p align="justify"><font face="verdana" size="2">24. <b>E. Gim&eacute;nez. </b>"Two Approaches to the Verification of Concurrent Programs in Coq". To appear, 1999. </font>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;[&#160;<a href="javascript:void(0);" onclick="javascript: window.open('/scielo.php?script=sci_nlinks&ref=2037194&pid=S1405-5546200400030000400024&lng=','','width=640,height=500,resizable=yes,scrollbars=1,menubar=yes,');">Links</a>&#160;]<!-- end-ref --><!-- ref --><p align="justify"><font face="verdana" size="2">25. <b>M. Gordon</b>. <i>Introduction to HOL: a theorem proving environment based for higher order logic. </i>Cambridge University, Press, 1993.</font>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;[&#160;<a href="javascript:void(0);" onclick="javascript: window.open('/scielo.php?script=sci_nlinks&ref=2037195&pid=S1405-5546200400030000400025&lng=','','width=640,height=500,resizable=yes,scrollbars=1,menubar=yes,');">Links</a>&#160;]<!-- end-ref --><!-- ref --><p align="justify"><font face="verdana" size="2">26. <b>A. G&ouml;ll&uuml;, A. Puri, </b>and<b> P. Varaiya. </b>"Discretization of timed automata". <i>Proc. 33<sup>rd</sup> CDC, </i>Orlando, Florida, 1994. </font>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;[&#160;<a href="javascript:void(0);" onclick="javascript: window.open('/scielo.php?script=sci_nlinks&ref=2037196&pid=S1405-5546200400030000400026&lng=','','width=640,height=500,resizable=yes,scrollbars=1,menubar=yes,');">Links</a>&#160;]<!-- end-ref --><!-- ref --><p align="justify"><font face="verdana" size="2">27. <b>D. Gries. </b><i>The science of programming, </i>Springer&#150;Verlag New York Inc., 1981. </font>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;[&#160;<a href="javascript:void(0);" onclick="javascript: window.open('/scielo.php?script=sci_nlinks&ref=2037197&pid=S1405-5546200400030000400027&lng=','','width=640,height=500,resizable=yes,scrollbars=1,menubar=yes,');">Links</a>&#160;]<!-- end-ref --><!-- ref --><p align="justify"><font face="verdana" size="2">28. <b>T. Henzinger, P.&#150;H. Ho, </b>and<b> H. Wong&#150;Toi. </b>"Hytech: a model checker for hybrid systems". <i>Software Tools for Technology </i><i>Transfer, </i>1997. </font>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;[&#160;<a href="javascript:void(0);" onclick="javascript: window.open('/scielo.php?script=sci_nlinks&ref=2037198&pid=S1405-5546200400030000400028&lng=','','width=640,height=500,resizable=yes,scrollbars=1,menubar=yes,');">Links</a>&#160;]<!-- end-ref --><!-- ref --><p align="justify"><font face="verdana" size="2">29. <b>C. Heitmeyer, R. Jeffords, </b>and<b> B. Labaw. </b>"A benchmark for comparing different approaches for specifying real&#150;time systems". <i>Real Time: Theory and Practice, LNCS </i>600, REX Workshop, Mook, The Netherlands, 1991. </font>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;[&#160;<a href="javascript:void(0);" onclick="javascript: window.open('/scielo.php?script=sci_nlinks&ref=2037199&pid=S1405-5546200400030000400029&lng=','','width=640,height=500,resizable=yes,scrollbars=1,menubar=yes,');">Links</a>&#160;]<!-- end-ref --><!-- ref --><p align="justify"><font face="verdana" size="2">30. <b>T. Henzinger </b>and<b> O. Kopke. </b>"Verification methods for the divergent runs of clock systems". In <i>FTRTFT'94: Formal </i><i>Techniques in Real&#150;time and Fault&#150;tolerant Systems, </i>volume 863 <i>of LNCS, </i>pages 351&#150;372, 1994. </font>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;[&#160;<a href="javascript:void(0);" onclick="javascript: window.open('/scielo.php?script=sci_nlinks&ref=2037200&pid=S1405-5546200400030000400030&lng=','','width=640,height=500,resizable=yes,scrollbars=1,menubar=yes,');">Links</a>&#160;]<!-- end-ref --><!-- ref --><p align="justify"><font face="verdana" size="2">31. <b>T. Henzinger, Z. Manna, </b>and<b> A. Pnueli. </b>"What good are digital clocks?". In <i>W. Kuich, editor, ICALP 92: Automata, Languages </i><i>and Programming, LNCS </i>623, pages 545&#150;558. Springer&#150;Verlag, 1992. </font>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;[&#160;<a href="javascript:void(0);" onclick="javascript: window.open('/scielo.php?script=sci_nlinks&ref=2037201&pid=S1405-5546200400030000400031&lng=','','width=640,height=500,resizable=yes,scrollbars=1,menubar=yes,');">Links</a>&#160;]<!-- end-ref --><!-- ref --><p align="justify"><font face="verdana" size="2">32. <b>T. Henzinger, X. Nicollin, J. Sifakis, </b>and<b> S. Yovine. </b>"Symbolic model&#150;checking for real&#150;time systems". In <i>Proc. 7<sup>th</sup> Symp on </i><i>Logics in Computer Science. </i>IEEE Computer Society Press, 1992. </font>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;[&#160;<a href="javascript:void(0);" onclick="javascript: window.open('/scielo.php?script=sci_nlinks&ref=2037202&pid=S1405-5546200400030000400032&lng=','','width=640,height=500,resizable=yes,scrollbars=1,menubar=yes,');">Links</a>&#160;]<!-- end-ref --><!-- ref --><p align="justify"><font face="verdana" size="2">33. <b>K. Havelund </b>and<b> N. Shankar. </b>"Experiments in Theorem Proving Model Checking for Protocol Verification". In <i>proceedings of </i><i>FME'96, </i>Oxford. <i>LNCS </i>1051, pages 662&#150;681, 1996. </font>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;[&#160;<a href="javascript:void(0);" onclick="javascript: window.open('/scielo.php?script=sci_nlinks&ref=2037203&pid=S1405-5546200400030000400033&lng=','','width=640,height=500,resizable=yes,scrollbars=1,menubar=yes,');">Links</a>&#160;]<!-- end-ref --><!-- ref --><p align="justify"><font face="verdana" size="2">34. <b>Y. Kesten, A. Klein, A. Pnueli, </b>and<b> G. Raanan. </b>"A Perfecto Verification: combining model checking with deductive analysis to verify real&#150;life software". <i>In FM' 99, </i>Toulouse, France. <i>LNCS </i>1709, pages 173&#150;194, 1999.</font>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;[&#160;<a href="javascript:void(0);" onclick="javascript: window.open('/scielo.php?script=sci_nlinks&ref=2037204&pid=S1405-5546200400030000400034&lng=','','width=640,height=500,resizable=yes,scrollbars=1,menubar=yes,');">Links</a>&#160;]<!-- end-ref --><!-- ref --><p align="justify"><font face="verdana" size="2">35. <b>Z. Luo </b>and<b> R. Pollack. </b>"Lego proof development system: User's manual". <i>T. Rep. </i>ECS&#150;LFCS&#150;92&#150;211, LFCS, 1992.</font>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;[&#160;<a href="javascript:void(0);" onclick="javascript: window.open('/scielo.php?script=sci_nlinks&ref=2037205&pid=S1405-5546200400030000400035&lng=','','width=640,height=500,resizable=yes,scrollbars=1,menubar=yes,');">Links</a>&#160;]<!-- end-ref --><!-- ref --><p align="justify"><font face="verdana" size="2">36. <b>K. Larsen, P. Pettersson, </b>and<b> W. Yi. </b>"Uppaal in a nutshell". <i>Software Tools for Technology Transfer, </i>1997. </font>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;[&#160;<a href="javascript:void(0);" onclick="javascript: window.open('/scielo.php?script=sci_nlinks&ref=2037206&pid=S1405-5546200400030000400036&lng=','','width=640,height=500,resizable=yes,scrollbars=1,menubar=yes,');">Links</a>&#160;]<!-- end-ref --><!-- ref --><p align="justify"><font face="verdana" size="2">37. <b>C. Luna. </b><i>Especificaci&oacute;n y an&aacute;lisis de sistemas de tiempo real en teor&iacute;a de tipos. Caso de estudio: the railroad crossing example. </i>Master thesis, Technical Report 00&#150;01, InCo, PEDECIBA Inform&aacute;tica, Fac. de Ingenier&iacute;a, U. de la Rep&uacute;blica, Uruguay, Febrero de 2000. Disponible tambi&eacute;n en <a href="http://www.fing.edu.uy/~cluna/" target="_blank">http://www.fing.edu.uy/~cluna</a>. </font>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;[&#160;<a href="javascript:void(0);" onclick="javascript: window.open('/scielo.php?script=sci_nlinks&ref=2037207&pid=S1405-5546200400030000400037&lng=','','width=640,height=500,resizable=yes,scrollbars=1,menubar=yes,');">Links</a>&#160;]<!-- end-ref --><!-- ref --><p align="justify"><font face="verdana" size="2">38. <b>L. Magnusson. </b><i>The implementation of ALF &#150; a proof editor based on Matin L&ouml;f's Monomorphic Type Theory with Explicit </i><i>Substitution. </i>PhD thesis, Chalmers University of G&ouml;teborg, 1994.</font>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;[&#160;<a href="javascript:void(0);" onclick="javascript: window.open('/scielo.php?script=sci_nlinks&ref=2037208&pid=S1405-5546200400030000400038&lng=','','width=640,height=500,resizable=yes,scrollbars=1,menubar=yes,');">Links</a>&#160;]<!-- end-ref --><!-- ref --><p align="justify"><font face="verdana" size="2">39. <b>D. Mandrioli, Carlo Ghezzi, </b>and<b> Mehdi Jazayeri. </b><i>Fundamentals of Software Engineering. </i>Prentice Hall, 1991.</font>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;[&#160;<a href="javascript:void(0);" onclick="javascript: window.open('/scielo.php?script=sci_nlinks&ref=2037209&pid=S1405-5546200400030000400039&lng=','','width=640,height=500,resizable=yes,scrollbars=1,menubar=yes,');">Links</a>&#160;]<!-- end-ref --><!-- ref --><p align="justify"><font face="verdana" size="2">40. <b>Olaf M&uuml;ller </b>and<b> T. Nipkow. </b>"Combining Model Checking and Deduction for I/O&#150;Automata". In <i>Tools and Algorithms for the </i><i>Construction and Analysis of Systems, LNCS </i>1019, pages 1&#150;16, 1995.</font>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;[&#160;<a href="javascript:void(0);" onclick="javascript: window.open('/scielo.php?script=sci_nlinks&ref=2037210&pid=S1405-5546200400030000400040&lng=','','width=640,height=500,resizable=yes,scrollbars=1,menubar=yes,');">Links</a>&#160;]<!-- end-ref --><!-- ref --><p align="justify"><font face="verdana" size="2">41. <b>Z. Manna </b>and<b> A. Pnueli. </b>"Completing the temporal picture". In <i>Theoretical Computer Science, </i>83(1):97&#150;130,1991. </font>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;[&#160;<a href="javascript:void(0);" onclick="javascript: window.open('/scielo.php?script=sci_nlinks&ref=2037211&pid=S1405-5546200400030000400041&lng=','','width=640,height=500,resizable=yes,scrollbars=1,menubar=yes,');">Links</a>&#160;]<!-- end-ref --><!-- ref --><p align="justify"><font face="verdana" size="2">42. <b>A. Olivero. </b><i>Mod&eacute;lisation et Analyse de Syst&egrave;mes Temporis&eacute;s et Hybrides. </i>PhD thesis, Institut National Polyt&eacute;chnique de Grenoble. France, 1994. </font>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;[&#160;<a href="javascript:void(0);" onclick="javascript: window.open('/scielo.php?script=sci_nlinks&ref=2037212&pid=S1405-5546200400030000400042&lng=','','width=640,height=500,resizable=yes,scrollbars=1,menubar=yes,');">Links</a>&#160;]<!-- end-ref --><!-- ref --><p align="justify"><font face="verdana" size="2">43. <b>S. Owre, J. Rushby, </b>and<b> N. Shankar. </b>"PVS: A prototype verification system". In Deepak Kapur, editor, <i>11<sup>th</sup> International </i><i>Conference on Automated Deduction (CADE). LNIA </i>607, Saratoga, NY, 1992. Springer Verlag. </font>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;[&#160;<a href="javascript:void(0);" onclick="javascript: window.open('/scielo.php?script=sci_nlinks&ref=2037213&pid=S1405-5546200400030000400043&lng=','','width=640,height=500,resizable=yes,scrollbars=1,menubar=yes,');">Links</a>&#160;]<!-- end-ref --><!-- ref --><p align="justify"><font face="verdana" size="2">44. <b>J. Ostroff. </b><i>Temporal logic of real&#150;time systems, </i>Ph.D. thesis, Univ. of Toronto, 1987. </font>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;[&#160;<a href="javascript:void(0);" onclick="javascript: window.open('/scielo.php?script=sci_nlinks&ref=2037214&pid=S1405-5546200400030000400044&lng=','','width=640,height=500,resizable=yes,scrollbars=1,menubar=yes,');">Links</a>&#160;]<!-- end-ref --><!-- ref --><p align="justify"><font face="verdana" size="2">45. <b>L. Paulson. </b>"Co&#150;induction and Co&#150;recursion in Higher&#150;order Logic". <i>Technical Report </i>304, Computer Laboratory, University of Cambridge, 1993.</font>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;[&#160;<a href="javascript:void(0);" onclick="javascript: window.open('/scielo.php?script=sci_nlinks&ref=2037215&pid=S1405-5546200400030000400045&lng=','','width=640,height=500,resizable=yes,scrollbars=1,menubar=yes,');">Links</a>&#160;]<!-- end-ref --><!-- ref --><p align="justify"><font face="verdana" size="2">46. <b>L. Paulson. </b>"The Isabelle reference manual". <i>Technical Report </i>283, Computer Laboratory, University, 1993. </font>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;[&#160;<a href="javascript:void(0);" onclick="javascript: window.open('/scielo.php?script=sci_nlinks&ref=2037216&pid=S1405-5546200400030000400046&lng=','','width=640,height=500,resizable=yes,scrollbars=1,menubar=yes,');">Links</a>&#160;]<!-- end-ref --><!-- ref --><p align="justify"><font face="verdana" size="2">47. <b>A. Pnueli </b>and<b> L. Lamport. </b>"An old&#150;fashioned recipe for real&#150;time". In J. W. De Baker, K. Huizing, W. P. De Roever, and G. Rozenberg, editors, <i>Real Time: Theory in Practice, LNCS </i>600, Springer&#150;Verlag, 1992. </font>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;[&#160;<a href="javascript:void(0);" onclick="javascript: window.open('/scielo.php?script=sci_nlinks&ref=2037217&pid=S1405-5546200400030000400047&lng=','','width=640,height=500,resizable=yes,scrollbars=1,menubar=yes,');">Links</a>&#160;]<!-- end-ref --><!-- ref --><p align="justify"><font face="verdana" size="2">48. <b>C. Paulin&#150;Mohring. </b>"Inductive definitions in the system Coq &#150; rules and properties". In M. Bezem and J. Groote, editors, <i>Proceeedings of the conference Typed Lambda Calculi and Aplications, LNCS </i>664, 1993. </font>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;[&#160;<a href="javascript:void(0);" onclick="javascript: window.open('/scielo.php?script=sci_nlinks&ref=2037218&pid=S1405-5546200400030000400048&lng=','','width=640,height=500,resizable=yes,scrollbars=1,menubar=yes,');">Links</a>&#160;]<!-- end-ref --><!-- ref --><p align="justify"><font face="verdana" size="2">49. <b>A. Pnueli. </b>"The temporal logic of programs". <i>Teorical Computer Science, </i>1981. </font>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;[&#160;<a href="javascript:void(0);" onclick="javascript: window.open('/scielo.php?script=sci_nlinks&ref=2037219&pid=S1405-5546200400030000400049&lng=','','width=640,height=500,resizable=yes,scrollbars=1,menubar=yes,');">Links</a>&#160;]<!-- end-ref --><!-- ref --><p align="justify"><font face="verdana" size="2">50. <b>A. Pnueli. </b>"Linear and branching structures in the semantics and logics of reactive systems". In <i>Proc. 12<sup>th</sup> ICALP, Nafplion, </i><i>LNCS 194, </i>1985. </font>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;[&#160;<a href="javascript:void(0);" onclick="javascript: window.open('/scielo.php?script=sci_nlinks&ref=2037220&pid=S1405-5546200400030000400050&lng=','','width=640,height=500,resizable=yes,scrollbars=1,menubar=yes,');">Links</a>&#160;]<!-- end-ref --><!-- ref --><p align="justify"><font face="verdana" size="2">51. <b>S. Rajan, N. Shankar, </b>and<b> M. Srivas. </b>"An integration of model checking with automated proof checking". In <i>Computer&#150;Aided </i><i>Verification, CAV'95. LNCS </i>939, Belgium, 1995.</font>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;[&#160;<a href="javascript:void(0);" onclick="javascript: window.open('/scielo.php?script=sci_nlinks&ref=2037221&pid=S1405-5546200400030000400051&lng=','','width=640,height=500,resizable=yes,scrollbars=1,menubar=yes,');">Links</a>&#160;]<!-- end-ref --><!-- ref --><p align="justify"><font face="verdana" size="2">52. <b>N. Shankar. </b>"Verification of real&#150;time systems using PVS". In <i>CAV'93, </i>Greece. <i>LNCS </i>697, pages 280&#150;291, 1993. </font>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;[&#160;<a href="javascript:void(0);" onclick="javascript: window.open('/scielo.php?script=sci_nlinks&ref=2037222&pid=S1405-5546200400030000400052&lng=','','width=640,height=500,resizable=yes,scrollbars=1,menubar=yes,');">Links</a>&#160;]<!-- end-ref --><!-- ref --><p align="justify"><font face="verdana" size="2">53. <b>H. Sa&iuml;di </b>and<b> N. Shankar. </b>"Abstract and model Check while you prove". In <i>CAV'99, </i>Trento, Italy, 1999. </font>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;[&#160;<a href="javascript:void(0);" onclick="javascript: window.open('/scielo.php?script=sci_nlinks&ref=2037223&pid=S1405-5546200400030000400053&lng=','','width=640,height=500,resizable=yes,scrollbars=1,menubar=yes,');">Links</a>&#160;]<!-- end-ref --><!-- ref --><p align="justify"><font face="verdana" size="2">54. <b>H. Wong&#150;Toi </b>and<b> P. Ho. </b>"Automated analysis of an audio control protocol". <i>In Proc. in Computer Aided Verification, </i>1995. </font>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;[&#160;<a href="javascript:void(0);" onclick="javascript: window.open('/scielo.php?script=sci_nlinks&ref=2037224&pid=S1405-5546200400030000400054&lng=','','width=640,height=500,resizable=yes,scrollbars=1,menubar=yes,');">Links</a>&#160;]<!-- end-ref --><!-- ref --><p align="justify"><font face="verdana" size="2">55. <b>S. Yovine. </b>"Kronos: A verification tool for real&#150;time systems". <i>Software Tools for Technology Transfer, </i>1997.</font>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;[&#160;<a href="javascript:void(0);" onclick="javascript: window.open('/scielo.php?script=sci_nlinks&ref=2037225&pid=S1405-5546200400030000400055&lng=','','width=640,height=500,resizable=yes,scrollbars=1,menubar=yes,');">Links</a>&#160;]<!-- end-ref --><p align="justify"><font face="verdana" size="2">&nbsp;</font></p>     <p align="justify"><font face="verdana" size="2"><b><a name="nota"></a>Nota</b></font></p>     <p align="justify"><font face="verdana" size="2"><sup>1</sup> La versi&oacute;n completa de este trabajo es el reporte 37.</font></p>      ]]></body><back>
<ref-list>
<ref id="B1">
<label>1</label><nlm-citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Armstrong]]></surname>
<given-names><![CDATA[J]]></given-names>
</name>
<name>
<surname><![CDATA[Barroca]]></surname>
<given-names><![CDATA[L]]></given-names>
</name>
</person-group>
<article-title xml:lang="en"><![CDATA[Specification and verification of reactive systems behaviour: The railroad crossing example]]></article-title>
<source><![CDATA[Real-Time Systems]]></source>
<year>1996</year>
<numero>10</numero>
<issue>10</issue>
<page-range>143-178</page-range></nlm-citation>
</ref>
<ref id="B2">
<label>2</label><nlm-citation citation-type="confpro">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Alur]]></surname>
<given-names><![CDATA[R]]></given-names>
</name>
<name>
<surname><![CDATA[Courcoubetis]]></surname>
<given-names><![CDATA[C]]></given-names>
</name>
<name>
<surname><![CDATA[Dill]]></surname>
<given-names><![CDATA[D]]></given-names>
</name>
</person-group>
<article-title xml:lang="en"><![CDATA[Model-checking for real-time systems]]></article-title>
<source><![CDATA[]]></source>
<year>1990</year>
<conf-name><![CDATA[ Proc. 5th Symp on Logics in Computer Science]]></conf-name>
<conf-loc> </conf-loc>
<page-range>414-425</page-range><publisher-name><![CDATA[IEEE Computer Society Press]]></publisher-name>
</nlm-citation>
</ref>
<ref id="B3">
<label>3</label><nlm-citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Alur]]></surname>
<given-names><![CDATA[R]]></given-names>
</name>
<name>
<surname><![CDATA[Dill]]></surname>
<given-names><![CDATA[D]]></given-names>
</name>
</person-group>
<article-title xml:lang="en"><![CDATA[A theory of timed automata]]></article-title>
<source><![CDATA[Theorical Computer Science]]></source>
<year>1994</year>
<numero>126</numero>
<issue>126</issue>
<page-range>183-235</page-range></nlm-citation>
</ref>
<ref id="B4">
<label>4</label><nlm-citation citation-type="book">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Alur]]></surname>
<given-names><![CDATA[R]]></given-names>
</name>
<name>
<surname><![CDATA[Henzinger]]></surname>
<given-names><![CDATA[T]]></given-names>
</name>
</person-group>
<article-title xml:lang="en"><![CDATA[Logics and models of real time: A survey]]></article-title>
<person-group person-group-type="editor">
<name>
<surname><![CDATA[de Bakker]]></surname>
<given-names><![CDATA[J. W.]]></given-names>
</name>
<name>
<surname><![CDATA[Huizing]]></surname>
<given-names><![CDATA[K]]></given-names>
</name>
<name>
<surname><![CDATA[de Roever]]></surname>
<given-names><![CDATA[W.-P.]]></given-names>
</name>
<name>
<surname><![CDATA[Rozenberg]]></surname>
<given-names><![CDATA[G]]></given-names>
</name>
</person-group>
<source><![CDATA[Real Time Theory in Practice]]></source>
<year>1992</year>
<volume>600</volume>
<page-range>74-106</page-range><publisher-name><![CDATA[LNCSSpringer-Verlag]]></publisher-name>
</nlm-citation>
</ref>
<ref id="B5">
<label>5</label><nlm-citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Alur]]></surname>
<given-names><![CDATA[R]]></given-names>
</name>
<name>
<surname><![CDATA[Henzinger]]></surname>
<given-names><![CDATA[T]]></given-names>
</name>
</person-group>
<article-title xml:lang="en"><![CDATA[A Really Temporal Logic]]></article-title>
<source><![CDATA[Journal of the ACM]]></source>
<year>1994</year>
<volume>41</volume>
<numero>1</numero>
<issue>1</issue>
<page-range>181-204</page-range></nlm-citation>
</ref>
<ref id="B6">
<label>6</label><nlm-citation citation-type="">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Alur]]></surname>
<given-names><![CDATA[R]]></given-names>
</name>
</person-group>
<source><![CDATA[Techniques for automatic verification of real-time systems]]></source>
<year></year>
</nlm-citation>
</ref>
<ref id="B7">
<label>7</label><nlm-citation citation-type="confpro">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Asarin]]></surname>
<given-names><![CDATA[A]]></given-names>
</name>
<name>
<surname><![CDATA[Maler]]></surname>
<given-names><![CDATA[O]]></given-names>
</name>
<name>
<surname><![CDATA[Pnueli]]></surname>
<given-names><![CDATA[A]]></given-names>
</name>
</person-group>
<article-title xml:lang="en"><![CDATA[On the discretization of delays in timed automata and digital circuits]]></article-title>
<person-group person-group-type="editor">
<name>
<surname><![CDATA[de Simone]]></surname>
<given-names><![CDATA[R]]></given-names>
</name>
<name>
<surname><![CDATA[Sangiorgi]]></surname>
<given-names><![CDATA[D]]></given-names>
</name>
</person-group>
<source><![CDATA[]]></source>
<year>1998</year>
<volume>1466</volume>
<conf-name><![CDATA[ Proc. Concur'98]]></conf-name>
<conf-loc> </conf-loc>
<page-range>470-484</page-range><publisher-name><![CDATA[LNCSSpringer-Verlag]]></publisher-name>
</nlm-citation>
</ref>
<ref id="B8">
<label>8</label><nlm-citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Alpern]]></surname>
<given-names><![CDATA[B]]></given-names>
</name>
<name>
<surname><![CDATA[Schneider]]></surname>
<given-names><![CDATA[F]]></given-names>
</name>
</person-group>
<article-title xml:lang="en"><![CDATA[Defining liveness]]></article-title>
<source><![CDATA[Information Processing Letters]]></source>
<year>1985</year>
<volume>21</volume>
<numero>4</numero>
<issue>4</issue>
<page-range>181-185</page-range></nlm-citation>
</ref>
<ref id="B9">
<label>9</label><nlm-citation citation-type="book">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Barras]]></surname>
<given-names><![CDATA[B]]></given-names>
</name>
<name>
<surname><![CDATA[Boutin]]></surname>
<given-names><![CDATA[S]]></given-names>
</name>
<name>
<surname><![CDATA[Cornes]]></surname>
<given-names><![CDATA[C]]></given-names>
</name>
<name>
<surname><![CDATA[Courant]]></surname>
<given-names><![CDATA[J]]></given-names>
</name>
<name>
<surname><![CDATA[Coscoy]]></surname>
<given-names><![CDATA[Y]]></given-names>
</name>
<name>
<surname><![CDATA[Delahaye]]></surname>
<given-names><![CDATA[D]]></given-names>
</name>
<name>
<surname><![CDATA[de Rauglaudre]]></surname>
<given-names><![CDATA[D]]></given-names>
</name>
<name>
<surname><![CDATA[Filliâtre]]></surname>
<given-names><![CDATA[J-C]]></given-names>
</name>
<name>
<surname><![CDATA[Giménez]]></surname>
<given-names><![CDATA[E]]></given-names>
</name>
<name>
<surname><![CDATA[Herbelin]]></surname>
<given-names><![CDATA[H]]></given-names>
</name>
<name>
<surname><![CDATA[Huet]]></surname>
<given-names><![CDATA[G]]></given-names>
</name>
<name>
<surname><![CDATA[Laulhère]]></surname>
<given-names><![CDATA[H]]></given-names>
</name>
<name>
<surname><![CDATA[Muñoz]]></surname>
<given-names><![CDATA[C]]></given-names>
</name>
<name>
<surname><![CDATA[Murthy]]></surname>
<given-names><![CDATA[Ch]]></given-names>
</name>
<name>
<surname><![CDATA[Parent-Vigouroux]]></surname>
<given-names><![CDATA[C]]></given-names>
</name>
<name>
<surname><![CDATA[Loiseleur]]></surname>
<given-names><![CDATA[P]]></given-names>
</name>
<name>
<surname><![CDATA[Paulin-Mohring]]></surname>
<given-names><![CDATA[Ch]]></given-names>
</name>
<name>
<surname><![CDATA[Saïbi]]></surname>
<given-names><![CDATA[A]]></given-names>
</name>
<name>
<surname><![CDATA[Werner]]></surname>
<given-names><![CDATA[B]]></given-names>
</name>
</person-group>
<source><![CDATA[The Coq Proof Assistant: Reference Manual, Versión 6.2.4]]></source>
<year>1999</year>
<publisher-name><![CDATA[INRIA]]></publisher-name>
</nlm-citation>
</ref>
<ref id="B10">
<label>10</label><nlm-citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Bjørner]]></surname>
<given-names><![CDATA[N. S.]]></given-names>
</name>
<name>
<surname><![CDATA[Browne]]></surname>
<given-names><![CDATA[A]]></given-names>
</name>
<name>
<surname><![CDATA[Manna]]></surname>
<given-names><![CDATA[Z]]></given-names>
</name>
</person-group>
<article-title xml:lang="en"><![CDATA[Automatic generation of invariants and intermediate assertions]]></article-title>
<source><![CDATA[Theorical Computer Science]]></source>
<year>1997</year>
<volume>173</volume>
<numero>1</numero>
<issue>1</issue>
<page-range>49-87</page-range></nlm-citation>
</ref>
<ref id="B11">
<label>11</label><nlm-citation citation-type="">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Bensalem]]></surname>
<given-names><![CDATA[S]]></given-names>
</name>
<name>
<surname><![CDATA[Lakhench]]></surname>
<given-names><![CDATA[Y]]></given-names>
</name>
</person-group>
<source><![CDATA[Automatic generation of invariants: To appear in Formal Methods]]></source>
<year>1999</year>
</nlm-citation>
</ref>
<ref id="B12">
<label>12</label><nlm-citation citation-type="book">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Bjørner]]></surname>
<given-names><![CDATA[N]]></given-names>
</name>
<name>
<surname><![CDATA[Manna]]></surname>
<given-names><![CDATA[Z]]></given-names>
</name>
<name>
<surname><![CDATA[Spima]]></surname>
<given-names><![CDATA[H]]></given-names>
</name>
<name>
<surname><![CDATA[Uribe]]></surname>
<given-names><![CDATA[T]]></given-names>
</name>
</person-group>
<source><![CDATA[Deductive Verification of Real-time Systems Using SteP]]></source>
<year>1997</year>
<volume>1231</volume>
<page-range>22-43</page-range><publisher-name><![CDATA[LNCSSpringer-Verlag]]></publisher-name>
</nlm-citation>
</ref>
<ref id="B13">
<label>13</label><nlm-citation citation-type="confpro">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Bozga]]></surname>
<given-names><![CDATA[M]]></given-names>
</name>
<name>
<surname><![CDATA[Maler]]></surname>
<given-names><![CDATA[O]]></given-names>
</name>
<name>
<surname><![CDATA[Tripakis]]></surname>
<given-names><![CDATA[S]]></given-names>
</name>
</person-group>
<article-title xml:lang="en"><![CDATA[Efficient verification of timed automata using dense and discrete time semantics]]></article-title>
<person-group person-group-type="editor">
<name>
<surname><![CDATA[Pierre]]></surname>
<given-names><![CDATA[L]]></given-names>
</name>
<name>
<surname><![CDATA[Kropf]]></surname>
<given-names><![CDATA[T]]></given-names>
</name>
</person-group>
<source><![CDATA[]]></source>
<year>1999</year>
<conf-name><![CDATA[ Proc CHARME'99]]></conf-name>
<conf-loc> </conf-loc>
<publisher-name><![CDATA[Springer-Verlag]]></publisher-name>
</nlm-citation>
</ref>
<ref id="B14">
<label>14</label><nlm-citation citation-type="book">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Burch]]></surname>
<given-names><![CDATA[J]]></given-names>
</name>
</person-group>
<source><![CDATA[Combining CTL, trace theory and timing models: Automatic Verification Methods for Finite State Systems]]></source>
<year>1989</year>
<volume>407</volume>
<publisher-name><![CDATA[LNCS]]></publisher-name>
</nlm-citation>
</ref>
<ref id="B15">
<label>15</label><nlm-citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Clarke]]></surname>
<given-names><![CDATA[E]]></given-names>
</name>
<name>
<surname><![CDATA[Emerson]]></surname>
<given-names><![CDATA[E]]></given-names>
</name>
<name>
<surname><![CDATA[Sistla]]></surname>
<given-names><![CDATA[A]]></given-names>
</name>
</person-group>
<article-title xml:lang="en"><![CDATA[Automatic verification of finite-state concurrent systems using temporal logic specifications]]></article-title>
<source><![CDATA[ACM Transactions on Programming Languages and Systems]]></source>
<year>1986</year>
<volume>8</volume>
<numero>2</numero>
<issue>2</issue>
<page-range>244-263</page-range></nlm-citation>
</ref>
<ref id="B16">
<label>16</label><nlm-citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Coquand]]></surname>
<given-names><![CDATA[T]]></given-names>
</name>
<name>
<surname><![CDATA[Huet]]></surname>
<given-names><![CDATA[G]]></given-names>
</name>
</person-group>
<article-title xml:lang="en"><![CDATA[The calculus of constructions]]></article-title>
<source><![CDATA[Information and Computation]]></source>
<year>1988</year>
<volume>76</volume>
<numero>2/3</numero>
<issue>2/3</issue>
</nlm-citation>
</ref>
<ref id="B17">
<label>17</label><nlm-citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Chaochen]]></surname>
<given-names><![CDATA[Z]]></given-names>
</name>
<name>
<surname><![CDATA[Hoare]]></surname>
<given-names><![CDATA[C]]></given-names>
</name>
<name>
<surname><![CDATA[Ravn]]></surname>
<given-names><![CDATA[A]]></given-names>
</name>
</person-group>
<article-title xml:lang="en"><![CDATA[A calculus of durations]]></article-title>
<source><![CDATA[Inform. Processing Letters]]></source>
<year>1992</year>
<volume>40</volume>
<numero>5</numero>
<issue>5</issue>
<page-range>269-276</page-range></nlm-citation>
</ref>
<ref id="B18">
<label>18</label><nlm-citation citation-type="book">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Coquand]]></surname>
<given-names><![CDATA[T]]></given-names>
</name>
</person-group>
<source><![CDATA[Metamathematical investigations of a calculus of constructions]]></source>
<year>1986</year>
<publisher-name><![CDATA[INRIA and Cambridge Univ.]]></publisher-name>
</nlm-citation>
</ref>
<ref id="B19">
<label>19</label><nlm-citation citation-type="book">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Coquand]]></surname>
<given-names><![CDATA[T]]></given-names>
</name>
</person-group>
<article-title xml:lang="en"><![CDATA[Infinite objects in type theory]]></article-title>
<person-group person-group-type="editor">
<name>
<surname><![CDATA[Barendregt]]></surname>
<given-names><![CDATA[H]]></given-names>
</name>
<name>
<surname><![CDATA[Nipkow]]></surname>
<given-names><![CDATA[T]]></given-names>
</name>
</person-group>
<source><![CDATA[Workshop on Types for Proofs and Programs]]></source>
<year>1993</year>
<page-range>62-78</page-range><publisher-name><![CDATA[Springer-Verlag]]></publisher-name>
</nlm-citation>
</ref>
<ref id="B20">
<label>20</label><nlm-citation citation-type="book">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Daws]]></surname>
<given-names><![CDATA[C]]></given-names>
</name>
<name>
<surname><![CDATA[Yovine]]></surname>
<given-names><![CDATA[S]]></given-names>
</name>
</person-group>
<source><![CDATA[Verification of multirate timed automata with KRONOS: two exemples]]></source>
<year>1995</year>
<publisher-name><![CDATA[VERIMAG]]></publisher-name>
</nlm-citation>
</ref>
<ref id="B21">
<label>21</label><nlm-citation citation-type="">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Emerson]]></surname>
<given-names><![CDATA[E]]></given-names>
</name>
</person-group>
<article-title xml:lang="en"><![CDATA[Automated temporal reasoning about rective systems]]></article-title>
<source><![CDATA[Logics for Concurrency]]></source>
<year>1995</year>
</nlm-citation>
</ref>
<ref id="B22">
<label>22</label><nlm-citation citation-type="">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Emerson]]></surname>
<given-names><![CDATA[E]]></given-names>
</name>
<name>
<surname><![CDATA[Mok]]></surname>
<given-names><![CDATA[A]]></given-names>
</name>
<name>
<surname><![CDATA[Sistla]]></surname>
<given-names><![CDATA[A]]></given-names>
</name>
<name>
<surname><![CDATA[Srinivasan]]></surname>
<given-names><![CDATA[J]]></given-names>
</name>
</person-group>
<source><![CDATA[Quantitative temporal reasoning: Workshop on Automatic Verification Methods for Finite State Systems]]></source>
<year>1989</year>
<publisher-loc><![CDATA[Grenoble ]]></publisher-loc>
</nlm-citation>
</ref>
<ref id="B23">
<label>23</label><nlm-citation citation-type="book">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Giménez]]></surname>
<given-names><![CDATA[E]]></given-names>
</name>
</person-group>
<source><![CDATA[A Calculus of Infinite Constructions and its application to the verification of communicating systems]]></source>
<year>1996</year>
<volume>1398</volume>
<publisher-name><![CDATA[Unité de Recherche Associée au CNRS]]></publisher-name>
</nlm-citation>
</ref>
<ref id="B24">
<label>24</label><nlm-citation citation-type="">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Giménez]]></surname>
<given-names><![CDATA[E]]></given-names>
</name>
</person-group>
<source><![CDATA[Two Approaches to the Verification of Concurrent Programs in Coq]]></source>
<year>1999</year>
</nlm-citation>
</ref>
<ref id="B25">
<label>25</label><nlm-citation citation-type="book">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Gordon]]></surname>
<given-names><![CDATA[M]]></given-names>
</name>
</person-group>
<source><![CDATA[Introduction to HOL: a theorem proving environment based for higher order logic]]></source>
<year>1993</year>
<publisher-name><![CDATA[Cambridge University, Press,]]></publisher-name>
</nlm-citation>
</ref>
<ref id="B26">
<label>26</label><nlm-citation citation-type="confpro">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Göllü]]></surname>
<given-names><![CDATA[A]]></given-names>
</name>
<name>
<surname><![CDATA[Puri]]></surname>
<given-names><![CDATA[A]]></given-names>
</name>
<name>
<surname><![CDATA[Varaiya]]></surname>
<given-names><![CDATA[P]]></given-names>
</name>
</person-group>
<source><![CDATA[Discretization of timed automata]]></source>
<year>1994</year>
<conf-name><![CDATA[ Proc. 33rd CDC]]></conf-name>
<conf-loc>Orlando Florida</conf-loc>
</nlm-citation>
</ref>
<ref id="B27">
<label>27</label><nlm-citation citation-type="book">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Gries]]></surname>
<given-names><![CDATA[D]]></given-names>
</name>
</person-group>
<source><![CDATA[The science of programming]]></source>
<year>1981</year>
<publisher-name><![CDATA[Springer-Verlag New York Inc.]]></publisher-name>
</nlm-citation>
</ref>
<ref id="B28">
<label>28</label><nlm-citation citation-type="book">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Henzinger]]></surname>
<given-names><![CDATA[T]]></given-names>
</name>
<name>
<surname><![CDATA[Ho]]></surname>
<given-names><![CDATA[P.-H.]]></given-names>
</name>
<name>
<surname><![CDATA[Wong-Toi]]></surname>
<given-names><![CDATA[H]]></given-names>
</name>
</person-group>
<source><![CDATA[Hytech: a model checker for hybrid systems]]></source>
<year>1997</year>
<publisher-name><![CDATA[Software Tools for Technology Transfer]]></publisher-name>
</nlm-citation>
</ref>
<ref id="B29">
<label>29</label><nlm-citation citation-type="book">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Heitmeyer]]></surname>
<given-names><![CDATA[C]]></given-names>
</name>
<name>
<surname><![CDATA[Jeffords]]></surname>
<given-names><![CDATA[R]]></given-names>
</name>
<name>
<surname><![CDATA[Labaw]]></surname>
<given-names><![CDATA[B]]></given-names>
</name>
</person-group>
<source><![CDATA[A benchmark for comparing different approaches for specifying real-time systems: Real Time: Theory and Practice]]></source>
<year>1991</year>
<volume>600</volume>
<publisher-loc><![CDATA[The Netherlands ]]></publisher-loc>
<publisher-name><![CDATA[LNCS]]></publisher-name>
</nlm-citation>
</ref>
<ref id="B30">
<label>30</label><nlm-citation citation-type="confpro">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Henzinger]]></surname>
<given-names><![CDATA[T]]></given-names>
</name>
<name>
<surname><![CDATA[Kopke]]></surname>
<given-names><![CDATA[O]]></given-names>
</name>
</person-group>
<article-title xml:lang="en"><![CDATA[Verification methods for the divergent runs of clock systems]]></article-title>
<source><![CDATA[]]></source>
<year>1994</year>
<volume>863</volume>
<conf-name><![CDATA[ FTRTFT'94: Formal Techniques in Real-time and Fault-tolerant Systems]]></conf-name>
<conf-loc> </conf-loc>
<page-range>351-372</page-range><publisher-name><![CDATA[LNCS]]></publisher-name>
</nlm-citation>
</ref>
<ref id="B31">
<label>31</label><nlm-citation citation-type="confpro">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Henzinger]]></surname>
<given-names><![CDATA[T]]></given-names>
</name>
<name>
<surname><![CDATA[Manna]]></surname>
<given-names><![CDATA[Z]]></given-names>
</name>
<name>
<surname><![CDATA[Pnueli]]></surname>
<given-names><![CDATA[A]]></given-names>
</name>
</person-group>
<article-title xml:lang="en"><![CDATA[What good are digital clocks?]]></article-title>
<person-group person-group-type="editor">
<name>
<surname><![CDATA[Kuich]]></surname>
<given-names><![CDATA[W]]></given-names>
</name>
</person-group>
<source><![CDATA[]]></source>
<year>1992</year>
<volume>623</volume>
<conf-name><![CDATA[ ICALP 92: Automata, Languages and Programming]]></conf-name>
<conf-loc> </conf-loc>
<page-range>545-558</page-range><publisher-name><![CDATA[LNCSSpringer-Verlag]]></publisher-name>
</nlm-citation>
</ref>
<ref id="B32">
<label>32</label><nlm-citation citation-type="confpro">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Henzinger]]></surname>
<given-names><![CDATA[T]]></given-names>
</name>
<name>
<surname><![CDATA[Nicollin]]></surname>
<given-names><![CDATA[X]]></given-names>
</name>
<name>
<surname><![CDATA[Sifakis]]></surname>
<given-names><![CDATA[J]]></given-names>
</name>
<name>
<surname><![CDATA[Yovine]]></surname>
<given-names><![CDATA[S]]></given-names>
</name>
</person-group>
<article-title xml:lang="en"><![CDATA[Symbolic model-checking for real-time systems]]></article-title>
<source><![CDATA[]]></source>
<year>1992</year>
<conf-name><![CDATA[ Proc. 7th Symp on Logics in Computer Science]]></conf-name>
<conf-loc> </conf-loc>
<publisher-name><![CDATA[IEEE Computer Society Press]]></publisher-name>
</nlm-citation>
</ref>
<ref id="B33">
<label>33</label><nlm-citation citation-type="confpro">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Havelund]]></surname>
<given-names><![CDATA[K]]></given-names>
</name>
<name>
<surname><![CDATA[Shankar]]></surname>
<given-names><![CDATA[N]]></given-names>
</name>
</person-group>
<article-title xml:lang="en"><![CDATA[Experiments in Theorem Proving Model Checking for Protocol Verification]]></article-title>
<source><![CDATA[]]></source>
<year>1996</year>
<volume>1051</volume>
<conf-name><![CDATA[ proceedings of FME'96]]></conf-name>
<conf-loc>Oxford </conf-loc>
<page-range>662-681</page-range><publisher-name><![CDATA[LNCS]]></publisher-name>
</nlm-citation>
</ref>
<ref id="B34">
<label>34</label><nlm-citation citation-type="confpro">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Kesten]]></surname>
<given-names><![CDATA[Y]]></given-names>
</name>
<name>
<surname><![CDATA[Klein]]></surname>
<given-names><![CDATA[A]]></given-names>
</name>
<name>
<surname><![CDATA[Pnueli]]></surname>
<given-names><![CDATA[A]]></given-names>
</name>
<name>
<surname><![CDATA[Raanan]]></surname>
<given-names><![CDATA[G]]></given-names>
</name>
</person-group>
<article-title xml:lang="en"><![CDATA[A Perfecto Verification: combining model checking with deductive analysis to verify real-life software]]></article-title>
<source><![CDATA[]]></source>
<year>1999</year>
<volume>1709</volume>
<conf-name><![CDATA[ FM' 99]]></conf-name>
<conf-loc>Toulouse </conf-loc>
<page-range>173-194</page-range><publisher-name><![CDATA[LNCS]]></publisher-name>
</nlm-citation>
</ref>
<ref id="B35">
<label>35</label><nlm-citation citation-type="book">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Luo]]></surname>
<given-names><![CDATA[Z]]></given-names>
</name>
<name>
<surname><![CDATA[Pollack]]></surname>
<given-names><![CDATA[R]]></given-names>
</name>
</person-group>
<source><![CDATA[Lego proof development system: User's manual]]></source>
<year>1992</year>
<publisher-name><![CDATA[LFCS]]></publisher-name>
</nlm-citation>
</ref>
<ref id="B36">
<label>36</label><nlm-citation citation-type="book">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Larsen]]></surname>
<given-names><![CDATA[K]]></given-names>
</name>
<name>
<surname><![CDATA[Pettersson]]></surname>
<given-names><![CDATA[P]]></given-names>
</name>
<name>
<surname><![CDATA[Yi]]></surname>
<given-names><![CDATA[W]]></given-names>
</name>
</person-group>
<source><![CDATA[Uppaal in a nutshell]]></source>
<year>1997</year>
<publisher-name><![CDATA[Software Tools for Technology Transfer]]></publisher-name>
</nlm-citation>
</ref>
<ref id="B37">
<label>37</label><nlm-citation citation-type="book">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Luna]]></surname>
<given-names><![CDATA[C]]></given-names>
</name>
</person-group>
<source><![CDATA[Especificación y análisis de sistemas de tiempo real en teoría de tipos: Caso de estudio: the railroad crossing example]]></source>
<year>2000</year>
<publisher-name><![CDATA[InCo, PEDECIBA Informática, Fac. de Ingeniería, U. de la República,]]></publisher-name>
</nlm-citation>
</ref>
<ref id="B38">
<label>38</label><nlm-citation citation-type="">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Magnusson]]></surname>
<given-names><![CDATA[L]]></given-names>
</name>
</person-group>
<source><![CDATA[The implementation of ALF - a proof editor based on Matin Löf's Monomorphic Type Theory with Explicit Substitution]]></source>
<year></year>
</nlm-citation>
</ref>
<ref id="B39">
<label>39</label><nlm-citation citation-type="book">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Mandrioli]]></surname>
<given-names><![CDATA[D]]></given-names>
</name>
<name>
<surname><![CDATA[Ghezzi]]></surname>
<given-names><![CDATA[Carlo]]></given-names>
</name>
<name>
<surname><![CDATA[Jazayeri]]></surname>
<given-names><![CDATA[Mehdi]]></given-names>
</name>
</person-group>
<source><![CDATA[Fundamentals of Software Engineering]]></source>
<year>1991</year>
<publisher-name><![CDATA[Prentice Hall]]></publisher-name>
</nlm-citation>
</ref>
<ref id="B40">
<label>40</label><nlm-citation citation-type="book">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Müller]]></surname>
<given-names><![CDATA[Olaf]]></given-names>
</name>
<name>
<surname><![CDATA[Nipkow]]></surname>
<given-names><![CDATA[T]]></given-names>
</name>
</person-group>
<article-title xml:lang="en"><![CDATA[Combining Model Checking and Deduction for I/O-Automata]]></article-title>
<source><![CDATA[Tools and Algorithms for the Construction and Analysis of Systems]]></source>
<year>1995</year>
<volume>1019</volume>
<page-range>1-16</page-range><publisher-name><![CDATA[LNCS]]></publisher-name>
</nlm-citation>
</ref>
<ref id="B41">
<label>41</label><nlm-citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Manna]]></surname>
<given-names><![CDATA[Z]]></given-names>
</name>
<name>
<surname><![CDATA[Pnueli]]></surname>
<given-names><![CDATA[A]]></given-names>
</name>
</person-group>
<article-title xml:lang="en"><![CDATA[Completing the temporal picture]]></article-title>
<source><![CDATA[Theoretical Computer Science]]></source>
<year>1991</year>
<volume>83</volume>
<numero>1</numero>
<issue>1</issue>
<page-range>97-130</page-range></nlm-citation>
</ref>
<ref id="B42">
<label>42</label><nlm-citation citation-type="">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Olivero]]></surname>
<given-names><![CDATA[A]]></given-names>
</name>
</person-group>
<source><![CDATA[Modélisation et Analyse de Systèmes Temporisés et Hybrides]]></source>
<year></year>
</nlm-citation>
</ref>
<ref id="B43">
<label>43</label><nlm-citation citation-type="confpro">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Owre]]></surname>
<given-names><![CDATA[S]]></given-names>
</name>
<name>
<surname><![CDATA[Rushby]]></surname>
<given-names><![CDATA[J]]></given-names>
</name>
<name>
<surname><![CDATA[Shankar]]></surname>
<given-names><![CDATA[N]]></given-names>
</name>
</person-group>
<article-title xml:lang="en"><![CDATA[PVS: A prototype verification system]]></article-title>
<person-group person-group-type="editor">
<name>
<surname><![CDATA[Deepak]]></surname>
<given-names><![CDATA[Kapur]]></given-names>
</name>
</person-group>
<source><![CDATA[]]></source>
<year>1992</year>
<volume>607</volume>
<conf-name><![CDATA[ 11th International Conference on Automated Deduction (CADE)]]></conf-name>
<conf-loc> </conf-loc>
<publisher-loc><![CDATA[SaratogaNY ]]></publisher-loc>
<publisher-name><![CDATA[LNIASpringer Verlag]]></publisher-name>
</nlm-citation>
</ref>
<ref id="B44">
<label>44</label><nlm-citation citation-type="">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Ostroff]]></surname>
<given-names><![CDATA[J]]></given-names>
</name>
</person-group>
<source><![CDATA[Temporal logic of real-time systems]]></source>
<year></year>
</nlm-citation>
</ref>
<ref id="B45">
<label>45</label><nlm-citation citation-type="book">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Paulson]]></surname>
<given-names><![CDATA[L]]></given-names>
</name>
</person-group>
<source><![CDATA[Co-induction and Co-recursion in Higher-order Logic]]></source>
<year>1993</year>
<publisher-name><![CDATA[Computer Laboratory, University of Cambridge,]]></publisher-name>
</nlm-citation>
</ref>
<ref id="B46">
<label>46</label><nlm-citation citation-type="book">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Paulson]]></surname>
<given-names><![CDATA[L]]></given-names>
</name>
</person-group>
<source><![CDATA[The Isabelle reference manual]]></source>
<year>1993</year>
<publisher-name><![CDATA[Computer Laboratory, University,]]></publisher-name>
</nlm-citation>
</ref>
<ref id="B47">
<label>47</label><nlm-citation citation-type="book">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Pnueli]]></surname>
<given-names><![CDATA[A]]></given-names>
</name>
<name>
<surname><![CDATA[Lamport]]></surname>
<given-names><![CDATA[L]]></given-names>
</name>
</person-group>
<article-title xml:lang="en"><![CDATA[An old-fashioned recipe for real-time]]></article-title>
<person-group person-group-type="editor">
<name>
<surname><![CDATA[De Baker]]></surname>
<given-names><![CDATA[J. W.]]></given-names>
</name>
<name>
<surname><![CDATA[Huizing]]></surname>
<given-names><![CDATA[K]]></given-names>
</name>
<name>
<surname><![CDATA[De Roever]]></surname>
<given-names><![CDATA[W. P.]]></given-names>
</name>
<name>
<surname><![CDATA[Rozenberg]]></surname>
<given-names><![CDATA[G]]></given-names>
</name>
</person-group>
<source><![CDATA[Real Time: Theory in Practice]]></source>
<year>1992</year>
<volume>600</volume>
<publisher-name><![CDATA[LNCSSpringer-Verlag]]></publisher-name>
</nlm-citation>
</ref>
<ref id="B48">
<label>48</label><nlm-citation citation-type="book">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Paulin-Mohring]]></surname>
<given-names><![CDATA[C]]></given-names>
</name>
</person-group>
<article-title xml:lang="en"><![CDATA[Inductive definitions in the system Coq - rules and properties]]></article-title>
<person-group person-group-type="editor">
<name>
<surname><![CDATA[Bezem]]></surname>
<given-names><![CDATA[M]]></given-names>
</name>
<name>
<surname><![CDATA[Groote]]></surname>
<given-names><![CDATA[J]]></given-names>
</name>
</person-group>
<source><![CDATA[Proceeedings of the conference Typed Lambda Calculi and Aplications]]></source>
<year>1993</year>
<volume>664</volume>
<publisher-name><![CDATA[LNCS]]></publisher-name>
</nlm-citation>
</ref>
<ref id="B49">
<label>49</label><nlm-citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Pnueli]]></surname>
<given-names><![CDATA[A]]></given-names>
</name>
</person-group>
<article-title xml:lang="en"><![CDATA[The temporal logic of programs]]></article-title>
<source><![CDATA[Teorical Computer Science]]></source>
<year>1981</year>
</nlm-citation>
</ref>
<ref id="B50">
<label>50</label><nlm-citation citation-type="confpro">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Pnueli]]></surname>
<given-names><![CDATA[A]]></given-names>
</name>
</person-group>
<article-title xml:lang="en"><![CDATA[Linear and branching structures in the semantics and logics of reactive systems]]></article-title>
<source><![CDATA[]]></source>
<year>1985</year>
<volume>194</volume>
<conf-name><![CDATA[ Proc. 12th ICALP]]></conf-name>
<conf-loc>Nafplion </conf-loc>
<publisher-name><![CDATA[LNCS]]></publisher-name>
</nlm-citation>
</ref>
<ref id="B51">
<label>51</label><nlm-citation citation-type="confpro">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Rajan]]></surname>
<given-names><![CDATA[S]]></given-names>
</name>
<name>
<surname><![CDATA[Shankar]]></surname>
<given-names><![CDATA[N]]></given-names>
</name>
<name>
<surname><![CDATA[Srivas]]></surname>
<given-names><![CDATA[M]]></given-names>
</name>
</person-group>
<article-title xml:lang="en"><![CDATA[An integration of model checking with automated proof checking]]></article-title>
<source><![CDATA[Computer-Aided Verification]]></source>
<year>1995</year>
<volume>939</volume>
<conf-name><![CDATA[ CAV'95]]></conf-name>
<conf-loc> </conf-loc>
<publisher-name><![CDATA[LNCS]]></publisher-name>
</nlm-citation>
</ref>
<ref id="B52">
<label>52</label><nlm-citation citation-type="confpro">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Shankar]]></surname>
<given-names><![CDATA[N]]></given-names>
</name>
</person-group>
<article-title xml:lang="en"><![CDATA[Verification of real-time systems using PVS]]></article-title>
<source><![CDATA[]]></source>
<year>1993</year>
<volume>697</volume>
<conf-name><![CDATA[ CAV'93]]></conf-name>
<conf-loc> </conf-loc>
<page-range>280-291</page-range><publisher-name><![CDATA[LNCS]]></publisher-name>
</nlm-citation>
</ref>
<ref id="B53">
<label>53</label><nlm-citation citation-type="confpro">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Saïdi]]></surname>
<given-names><![CDATA[H]]></given-names>
</name>
<name>
<surname><![CDATA[Shankar]]></surname>
<given-names><![CDATA[N]]></given-names>
</name>
</person-group>
<article-title xml:lang="en"><![CDATA[Abstract and model Check while you prove]]></article-title>
<source><![CDATA[]]></source>
<year></year>
<conf-name><![CDATA[ CAV'99]]></conf-name>
<conf-date>1999</conf-date>
<conf-loc>Trento </conf-loc>
</nlm-citation>
</ref>
<ref id="B54">
<label>54</label><nlm-citation citation-type="confpro">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Wong-Toi]]></surname>
<given-names><![CDATA[H]]></given-names>
</name>
<name>
<surname><![CDATA[Ho]]></surname>
<given-names><![CDATA[P]]></given-names>
</name>
</person-group>
<article-title xml:lang="en"><![CDATA[Automated analysis of an audio control protocol]]></article-title>
<source><![CDATA[]]></source>
<year></year>
<conf-name><![CDATA[ Proc. in Computer Aided Verification]]></conf-name>
<conf-date>1995</conf-date>
<conf-loc> </conf-loc>
</nlm-citation>
</ref>
<ref id="B55">
<label>55</label><nlm-citation citation-type="book">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Yovine]]></surname>
<given-names><![CDATA[S]]></given-names>
</name>
</person-group>
<source><![CDATA[Kronos: A verification tool for real-time systems]]></source>
<year>1997</year>
<publisher-name><![CDATA[Software Tools for Technology Transfer]]></publisher-name>
</nlm-citation>
</ref>
</ref-list>
</back>
</article>
