| |
| | TLA Papers |
 | | Theorem proving, while not bound by the same computational constraints, may not be feasible for routinely coping with the complex, low-level details of a real multiplier. |
 | | Input to the system consists of the correctness properties, expressed in TLA (the temporal logic of actions), and their proofs, written in a humanly readable, hierarchically structured form. |
 | | Checking is now done by LP (the Larch Prover), using two different translations--one for action reasoning and one for temporal reasoning. |
| research.microsoft.com /users/lamport/tla/papers.html (1630 words) |
|