Articles
Formal methods, in the vocabulary of equipment engineers
The biggest barrier to formal methods is not difficulty — it is unfamiliarity. In a survey of 130 experts, 71.5% named a lack of engineer education as the leading adoption barrier. So we put explanation before the sales pitch.
Read in order, the series runs from the verification gap in equipment software through to how formal methods close it. Starting anywhere is fine.
-
Why equipment software cannot run the right-hand side of the V-model
The field has run on "if the machine moves, it's fine" for decades — not because anyone was cutting corners, but because unit testing was structurally impossible.
8 min read -
What comes after "design with models"
The world has already begun designing with models rather than documents. But no tool answers whether the model is correct. This article is about that gap.
8 min read -
What is the difference between testing and formal methods?
Testing checks the range you tried. Formal methods check every state that can occur. That difference matters for one family of bugs — the ones that do not appear in test and do appear on site.
9 min read -
What a counterexample is
When design verification finds a problem, what comes back is not a warning but a concrete sequence of events that reproduces the violation. This is about how to use that in the field.
7 min read -
Why safety standards ask for formal methods
Formal methods are not a new sales pitch. IEC 61508 and DO-178C both name them once the safety integrity level rises. This is why.
8 min read -
Who actually uses this
The organisations that actually use formal methods, and how they use them. Together with a plain account of how far adoption has not progressed.
7 min read
Try it on your own design.
The articles are general explanation. What comes out of your design is a different question — and one diagnosis answers it.