1. (2012): EASA Certification Memo CM-SWCEH-002 Software Aspects of Certification. Technical Report EASA CM-SWCEH002 Issue 01 Revision 1. European Aviation Safety Agency.
  2. ANSI/ISO C Specification Language. Available at
  3. Patrick Baudin, Loic Correnson & Zaynah Dargaye (2013): WP Plug-in Manual. Version 0.7 for Fluorine-20130601. CEA LIST.
  4. Patrick Baudin, Pascal Cuoq, Jean-Christophe Filliâtre, Claude Marché, Benjamin Monate, Yannick Moy & Virgile Prevosto (2013): ACSL: ANSI/ISO C Specification Language. Version 1.7. Technical Report. CEA LIST, Software Reliability Laboratory. Available at
  5. C. Baumann, T. Bormer, H. Blasum & S. Tverdyshev (2011): Proving Memory Separation in a Microkernel by Code Level Verification. In: Object/Component/Service-Oriented Real-Time Distributed Computing Workshops (ISORCW), 2011 14th IEEE International Symposium on, pp. 25–32, doi:10.1109/ISORCW.2011.14.
  6. Christoph Baumann, Bernhard Beckert, Holger Blasum & Thorsten Bormer (2009): Better Avionics Software Reliability by Code Verification – A Glance at Code Verification Methodology in the Verisoft XT Project. In: Embedded World 2009 Conference. Franzis Verlag, Nuremberg, Germany.
  7. Holger Blasum, Frank Dordowsky, Bruno Langenstein & Andreas Nonnengart (2012): DO-178C Compliance of Verisoft Formal Methods. In: Proceedings of the Embedded Real Time Software and Systems Conference, 1. - 3. February, Toulouse.
  8. Jochen Burghardt, Jens Gerlach amd Liangliang Gu, Kerstin Hartig, Hans Pohl, Juan Soto & Kim V¨ollinger (2011): ACSL By Example. Towards a Verified C Standard Library. Technical Report. Fraunhofer FIRST.
  9. (2007): Common Criteria for Information Technology Security Evaluation. Part 3: Security Assurance Components.
  10. Loïc Correnson, Pascal Cuoq, Florent Kirchner, Virgile Prevosto, Armand Puccetti, Julien Signoles & Boris Yakobowski (2013): Frama-C User Manual. Release Fluorine-20130601. Available at
  11. (2011): RTCA DO-178C Software Considerations in Airborne Systems and Equipment Certification.
  12. (2011): RTCA DO-333 Formal Methods Supplement to DO-178C and DO-278A.
  13. Frama-C Software Analyzers. Available at
  14. John Rushby (1993): Formal Methods and the Certification of Critical Systems. Technical Report SRI-CSL-93-7. Computer Science Laboratory, SRI International, Menlo Park, CA.
  15. Jean Souyris, Virginie Wiels, David Delmas & Hervé Delseny (2009): Formal Verification of Avionics Software Products. In: Ana Cavalcanti & Dennis Dams: FM 2009: Formal Methods, Lecture Notes in Computer Science 5850. Springer Berlin / Heidelberg, pp. 532–546, doi:10.1007/978-3-642-05089-3_34.
  16. J. M. Spivey (1998): The Z Notation: A Reference Manual, 2nd edition edition. Prentice Hall International (UK) Ltd.
  17. Susan Stepney, Fiona Polack & Ian Toyn (2003): A Z Patterns Catalogue I: Specification and Refactorings. Technical Report YCS-2003-349. Department of Computer Science, University of York.
  18. Nicolas Stouls & Virgile Prevosto (2015): Aorai Plugin Tutorial. Technical Report. INRIA. Available at
  19. Samuel H. Valentine, Susan Stepney & Ian Toyn (2004): A Z Patterns Catalogue II: Definitions and Laws. Technical Report YCS-2004-383. Department of Computer Science, University of York.
  20. VCC Website. Available at
  21. L.M.G. de Vries (1996): Applying Formal Methods in the DO-178B Certification Process. Technical Report NLR TP 95547. National Aerospace Laboratory NLR, Amsterdam, The Netherlands.

Comments and questions to:
For website issues: