title: Developing Mode-Rich Satellite Software by Refinement in Event B creator: Iliasov, Alexei creator: Troubitsyna, Elena creator: Laibinis, Linas creator: Romanovsky, Alexander creator: Varpaaniemi, Kimmo creator: Ilic, Dubravka creator: Latvala, Timo subject: Event-B subject: Space subject: Composition and reuse subject: Resilience subject: Model construction subject: Rodin plug-ins description: To ensure dependability of on-board satellite systems, the designers should, in particular, guarantee correct implementation of the mode transition scheme, i.e., ensure that the states of the system components are consistent with the global system mode. However, there is still a lack of scalable approaches to formal verification of correctness of complex mode transitions. In this paper we present a formal development of an Attitude and Orbit Control System (AOCS) undertaken within the ICT DEPLOY project. AOCS is a complex mode-rich system, which has an intricate mode-transition scheme. We show that re�finement in Event B provides the engineers with a scalable formal technique that enables both development of mode-rich systems and proof-based verification of their mode consistency. date: 2010 type: Conference or Workshop Item type: PeerReviewed format: application/pdf identifier: http://deploy-eprints.ecs.soton.ac.uk/240/1/FMICS_CR.pdf relation: https://es.fbk.eu/events/fmics2010/index.php identifier: Iliasov, Alexei and Troubitsyna, Elena and Laibinis, Linas and Romanovsky, Alexander and Varpaaniemi, Kimmo and Ilic, Dubravka and Latvala, Timo (2010) Developing Mode-Rich Satellite Software by Refinement in Event B. In: 15th International Workshop on Formal Methods for Industrial Critical Systems (FMICS 2010), September 20-21, 2010, Antwerp, Belgium. (In Press) relation: http://deploy-eprints.ecs.soton.ac.uk/240/