Formal verification for fault-tolerant architectures: prolegomena to the design of PVS | IEEE Journals & Magazine | IEEE Xplore