{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2024,9,5]],"date-time":"2024-09-05T09:17:29Z","timestamp":1725527849346},"reference-count":28,"publisher":"Elsevier BV","issue":"7","license":[{"start":{"date-parts":[[2013,7,1]],"date-time":"2013-07-01T00:00:00Z","timestamp":1372636800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/tdm\/userlicense\/1.0\/"},{"start":{"date-parts":[[2017,7,1]],"date-time":"2017-07-01T00:00:00Z","timestamp":1498867200000},"content-version":"vor","delay-in-days":1461,"URL":"https:\/\/www.elsevier.com\/open-access\/userlicense\/1.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Science of Computer Programming"],"published-print":{"date-parts":[[2013,7]]},"DOI":"10.1016\/j.scico.2012.04.003","type":"journal-article","created":{"date-parts":[[2012,4,25]],"date-time":"2012-04-25T21:04:08Z","timestamp":1335387848000},"page":"828-842","source":"Crossref","is-referenced-by-count":28,"title":["The Metr\u00f4 Rio case study"],"prefix":"10.1016","volume":"78","author":[{"given":"Alessio","family":"Ferrari","sequence":"first","affiliation":[]},{"given":"Alessandro","family":"Fantechi","sequence":"additional","affiliation":[]},{"given":"Gianluca","family":"Magnani","sequence":"additional","affiliation":[]},{"given":"Daniele","family":"Grasso","sequence":"additional","affiliation":[]},{"given":"Matteo","family":"Tempestini","sequence":"additional","affiliation":[]}],"member":"78","reference":[{"key":"10.1016\/j.scico.2012.04.003_br000005","unstructured":"A. Faivre, P. Benoit, Safety critical software of meteor developed with the B formal method and the vital coded processor, in: Proc. of WCRR\u201999, 1999, pp. 84\u201389."},{"key":"10.1016\/j.scico.2012.04.003_br000010","series-title":"Proc. 12th Int. Conf. on Software Engineering","first-page":"186","article-title":"Sacem software validation","author":"Guiho","year":"1990"},{"key":"10.1016\/j.scico.2012.04.003_br000015","series-title":"FM 2009: Formal Methods","first-page":"708","article-title":"Automated property verification for large scale b models","volume":"vol. 5850","author":"Leuschel","year":"2009"},{"key":"10.1016\/j.scico.2012.04.003_br000020","series-title":"FM 2006: Formal Methods","first-page":"179","article-title":"A story about formal methods adoption by a railway signaling manufacturer","volume":"vol. 4085","author":"Bacherini","year":"2006"},{"key":"10.1016\/j.scico.2012.04.003_br000025","unstructured":"A. Ferrari, A. Fantechi, S. Bacherini, N. Zingoni, Modeling guidelines for code generation in the railway signaling context, in: Proc. 1st NFM Symposium, 2009, pp. 166\u2013170."},{"key":"10.1016\/j.scico.2012.04.003_br000030","unstructured":"Mathworks Automotive Advisory Board (MAAB), Control Algorithm Modeling Guidelines Using Matlab, Simulink and Stateflow, Version 2.0, 2007."},{"issue":"2","key":"10.1016\/j.scico.2012.04.003_br000035","first-page":"42","article-title":"Adoption of model-based testing and abstract interpretation by a railway signalling manufacturer","volume":"2","author":"Ferrari","year":"2011","journal-title":"IJERTCS"},{"key":"10.1016\/j.scico.2012.04.003_br000040","series-title":"Formal Methods for Industrial Critical Systems","first-page":"1","article-title":"The Metr\u00f4 Rio ATP case study","volume":"vol. 6371","author":"Ferrari","year":"2010"},{"key":"10.1016\/j.scico.2012.04.003_br000045","doi-asserted-by":"crossref","unstructured":"A. Ferrari, A. Fantechi, M. Papini, D. Grasso, An industrial application of formal model based development: the Metr\u00f4 Rio ATP case, in: Proc. 2nd Int. Workshop on Software Engineering for Resilient Systems, SERENE\u201910, 2010.","DOI":"10.1145\/2401736.2401744"},{"key":"10.1016\/j.scico.2012.04.003_br000050","doi-asserted-by":"crossref","first-page":"231","DOI":"10.1016\/0167-6423(87)90035-9","article-title":"Statecharts: a visual formalism for complex systems","volume":"8","author":"Harel","year":"1987","journal-title":"Sci. Comput. Program."},{"issue":"5\u20136","key":"10.1016\/j.scico.2012.04.003_br000055","doi-asserted-by":"crossref","first-page":"447","DOI":"10.1007\/s10009-007-0049-7","article-title":"An operational semantics for Stateflow","volume":"9","author":"Hamon","year":"2007","journal-title":"Int. J. on Software Tools for Technology Transfer (STTT)"},{"key":"10.1016\/j.scico.2012.04.003_br000060","series-title":"Proc. 5th ACM int. conf. on Embedded software, EMSOFT\u201905","first-page":"164","article-title":"A denotational semantics for Stateflow","author":"Hamon","year":"2005"},{"key":"10.1016\/j.scico.2012.04.003_br000065","series-title":"Proc. 4th ACM Int. Conf. on Embedded Software","first-page":"259","article-title":"Defining and translating a safe subset of Simulink\/Stateflow into Lustre","author":"Scaife","year":"2004"},{"key":"10.1016\/j.scico.2012.04.003_br000070","series-title":"Proc. 4th ACM SIGACT-SIGPLAN Symposium on Principles of Programming Languages","first-page":"238","article-title":"Abstract interpretation: a unified lattice model for static analysis of programs by construction or approximation of fixpoints","author":"Cousot","year":"1977"},{"key":"10.1016\/j.scico.2012.04.003_br000075","unstructured":"European Committee for Electrotechnical Standardization, CENELEC EN50128, Railway Applications \u2014 Software for Railway Control and Protection Systems, 1997."},{"key":"10.1016\/j.scico.2012.04.003_br000080","doi-asserted-by":"crossref","first-page":"389","DOI":"10.1007\/s10703-009-0082-0","article-title":"Testing-based translation validation of generated code in the context of IEC 61508","volume":"35","author":"Conrad","year":"2009","journal-title":"Form. Methods Syst. Des."},{"key":"10.1016\/j.scico.2012.04.003_br000085","series-title":"Proc. 4th Int. Conf. on Tools and Algorithms for the Construction and Analysis of Systems","first-page":"151","article-title":"Translation validation","volume":"vol. 1384","author":"Pnueli","year":"1998"},{"key":"10.1016\/j.scico.2012.04.003_br000090","unstructured":"A. Baresel, M. Conrad, S. Sadeghipour, J. Wegener, The interplay between model coverage and code coverage, in: Proc. 11th Eur. Int. Conf. on Software Testing, Analysis and Review, EuroSTAR\u201903, 2003."},{"key":"10.1016\/j.scico.2012.04.003_br000095","unstructured":"A. Deutsch, Static verification of dynamic properties \u2014 Polyspace white paper, 2004."},{"key":"10.1016\/j.scico.2012.04.003_br000100","doi-asserted-by":"crossref","first-page":"1512","DOI":"10.1145\/186025.186051","article-title":"Model checking and abstraction","volume":"16","author":"Clarke","year":"1994","journal-title":"ACM Trans. Program. Lang. Syst."},{"key":"10.1016\/j.scico.2012.04.003_br000105","series-title":"Symbolic Logic and Mechanical Theorem Proving","author":"Chang","year":"1997"},{"key":"10.1016\/j.scico.2012.04.003_br000110","doi-asserted-by":"crossref","unstructured":"P.A. Abdulla, J. Deneux, G. St\u00e5lmarck, H. \u00c5gren, O. \u00c5kerlund, Designing safe, reliable systems using scade, in: ISoLA, 2004, pp. 115\u2013129.","DOI":"10.1007\/11925040_8"},{"key":"10.1016\/j.scico.2012.04.003_br000115","doi-asserted-by":"crossref","first-page":"7","DOI":"10.1023\/A:1011276507260","article-title":"Bounded model checking using satisfiability solving","volume":"19","author":"Clarke","year":"2001","journal-title":"Form. Methods Syst. Des."},{"key":"10.1016\/j.scico.2012.04.003_br000120","series-title":"Formal Methods in Computer-Aided Design","first-page":"127","article-title":"Checking safety properties using induction and a SAT-solver","volume":"vol. 1954","author":"Sheeran","year":"2000"},{"key":"10.1016\/j.scico.2012.04.003_br000125","unstructured":"A. Ferrari, G. Magnani, D. Grasso, A. Fantechi, Model checking interlocking control tables, in: Proc. 8th FORMS\/FORMAT Symposium, 2009."},{"key":"10.1016\/j.scico.2012.04.003_br000130","first-page":"18","article-title":"Model checking flight control systems: the Airbus experience","author":"Bochot","year":"2009","journal-title":"ICSE Companion"},{"issue":"2","key":"10.1016\/j.scico.2012.04.003_br000135","doi-asserted-by":"crossref","first-page":"58","DOI":"10.1145\/1646353.1646372","article-title":"Software model checking takes off","volume":"53","author":"Miller","year":"2010","journal-title":"Commun. ACM"},{"key":"10.1016\/j.scico.2012.04.003_br000140","series-title":"NASA Formal Methods","first-page":"24","article-title":"Lessons learnt from the adoption of formal model-based development","volume":"vol. 7226","author":"Ferrari","year":"2012"}],"container-title":["Science of Computer Programming"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S0167642312000676?httpAccept=text\/xml","content-type":"text\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S0167642312000676?httpAccept=text\/plain","content-type":"text\/plain","content-version":"vor","intended-application":"text-mining"}],"deposited":{"date-parts":[[2019,6,27]],"date-time":"2019-06-27T23:13:06Z","timestamp":1561677186000},"score":1,"resource":{"primary":{"URL":"https:\/\/linkinghub.elsevier.com\/retrieve\/pii\/S0167642312000676"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2013,7]]},"references-count":28,"journal-issue":{"issue":"7","published-print":{"date-parts":[[2013,7]]}},"alternative-id":["S0167642312000676"],"URL":"https:\/\/doi.org\/10.1016\/j.scico.2012.04.003","relation":{},"ISSN":["0167-6423"],"issn-type":[{"value":"0167-6423","type":"print"}],"subject":[],"published":{"date-parts":[[2013,7]]}}}