01507nas a2200217 4500000000100000000000100001000000100002008004100003260000900044653001900053653002900072653003300101653001900134653001700153100001700170700001700187245007000204300001200274490000700286520099600293 2012 d c201210aFormal methods10asafety-critical software10asoftware development process10asoftware tools10averification1 aMark Lawford1 aAlan Wassyng00aFormal Verification of Nuclear Systems: Past, Present, and Future a223-2350 v283 a

In this paper we review the Systematic Design Verification Process used on the computer controlled shutdown systems of the Darlington Nuclear Generating Station Shutdown Systems. The Software Requirements Specification (SRS) made extensive use of tabular expressions to document the requirements as did the Software Design Description (SDD). Systematic Design Verification was then performed based upon the 4-Variable Model to verify that the design was correct with respect to its requirements. Custom tools were developed to process the SRS and SDD documents to produce “block theorems” for the PVS theorem prover that were used to verify the majority of the functional requirements. We discuss how the formal methods were integrated into the forward going software development process and techniques that were used to manage the complexity of the verification task. We offer some lessons learned in the process and discuss the future of formal verification for nuclear systems.