A formal method for early spacecraft design verification | IEEE Conference Publication | IEEE Xplore