A design is only completed when we have proved it meets its specification, and to do this we need to prove an equivalence between specification and design. In more specific terms, we must prove, before implementation, that our designs meet their requirements (satisfy their specifications) and only those requirements (no over-specification).
KeywordsExternal Action Internal Action Successor State Formal Design Derivation Tree
Unable to display preview. Download preview PDF.