Formal verification of a fault tolerant computer | IEEE Conference Publication | IEEE Xplore