1. W. R. Bevier, W. D. Young. The proof of correctness of a fault-tolerant circuit design. Second IFIP Conference on Dependable Computing For Critical Applications, Tucson, Arizona, February 1991, pp. 107-114.
2. R. W. Butler, J. L. Caldwell, B. L. Di Vito. Design strategy for a formally verified reliable computing platform. 6th Annual Conference on Computer Assurance (COMPASS 91), Gaithersburg, MD, June 1991.
3. R. W. Butler, B. L. Di Vito. Formal design and verification of a reliable computing platform for real-time control (phase 2 results). NASA Technical Memorandum 104196, January 1992.
4. B. L. Di Vito, R. W. Butler, J. L. Caldwell. High level design proof of a reliable computing platform. Dependable Computing for Critical Applications 2, Dependable Computing and Fault-Tolerant Systems, Springer Verlag, Wien New York, 1992, pp. 279–306. Also presented at 2nd IFIP Working Conference on Dependable Computing for Critical Applications, Tucson, AZ, Feb. 18–20, 1991, pp. 124-136.
5. B. L. Di Vito, R. W. Butler, J. L. Caldwell, II. Formal design and verification of a reliable computing platform for real-time control (phase 1 results). NASA Technical Memorandum 102716, October 1990.