PVS: A prototype verification system S Owre, JM Rushby, N Shankar International Conference on Automated Deduction, 748-752, 1992 | 2465 | 1992 |
Formal verification for fault-tolerant architectures: Prolegomena to the design of PVS S Owre, J Rushby, N Shankar, F Von Henke IEEE Transactions on Software Engineering 21 (2), 107-125, 1995 | 814 | 1995 |
PVS: Combining specification, proof checking, and model checking S Owre, S Rajan, JM Rushby, N Shankar, M Srivas International Conference on Computer Aided Verification, 411-414, 1996 | 726 | 1996 |
Design and verification of secure systems JM Rushby ACM SIGOPS Operating Systems Review 15 (5), 12-21, 1981 | 722 | 1981 |
Noninterference, transitivity, and channel-control security policies J Rushby SRI International, Computer Science Laboratory, 1992 | 539 | 1992 |
A tutorial introduction to PVS J Crow, S Owre, J Rushby, N Shankar, M Srivas WIFT, 1995 | 464 | 1995 |
Bus architectures for safety-critical embedded systems J Rushby International Workshop on Embedded Software, 306-323, 2001 | 401 | 2001 |
SAL 2 L De Moura, S Owre, H Rueß, J Rushby, N Shankar, M Sorea, A Tiwari International Conference on Computer Aided Verification, 496-500, 2004 | 374 | 2004 |
Partitioning in avionics architectures: Requirements, mechanisms, and assurance J Rushby SRI INTERNATIONAL MENLO PARK CA COMPUTER SCIENCE LAB, 2000 | 343 | 2000 |
PVS language reference S Owre, N Shankar, JM Rushby, DWJ Stringer-Calvert Computer Science Laboratory, SRI International, Menlo Park, CA 1 (2), 21, 1999 | 327 | 1999 |
Using model checking to help discover mode confusions and other automation surprises J Rushby Reliability Engineering & System Safety 75 (2), 167-177, 2002 | 307 | 2002 |
Formal methods and the certification of critical systems J Rushby SRI International, Computer Science Laboratory, 1993 | 293 | 1993 |
An overview of SAL S Bensalem, V Ganesh, Y Lakhnech, C Munoz, S Owre, H Rueß, ... Proceedings of the 5th NASA Langley Formal Methods Workshop, 2000 | 257 | 2000 |
Critical system properties: Survey and taxonomy J Rushby Reliability Engineering & System Safety 43 (2), 189-219, 1994 | 257 | 1994 |
PVS prover guide N Shankar, S Owre, JM Rushby, DWJ Stringer-Calvert Computer Science Laboratory, SRI International, Menlo Park, CA 1, 11-12, 2001 | 227 | 2001 |
Subtypes for specifications: Predicate subtyping in PVS J Rushby, S Owre, N Shankar IEEE Transactions on Software Engineering 24 (9), 709-720, 1998 | 224 | 1998 |
Formal methods and their role in the certification of critical systems J Rushby Safety and Reliability of Software Based Systems, 1-42, 1997 | 219 | 1997 |
The PVS proof checker: A reference manual (beta release) N Shankar, S Owre, JM Rushby Computer Science Laboratory, SRI International, Menlo Park, CA, 1993 | 213 | 1993 |
PVS system guide S Owre, N Shankar, JM Rushby, DWJ Stringer-Calvert Computer Science Laboratory, SRI International, Menlo Park, CA 1 (5), 7, 1999 | 209 | 1999 |
A Distributed Secure System B Randell, JM Rushby Computer 16 (7), 55-67, 1983 | 203* | 1983 |