To avoid hidden safety problems in future large scale systems, we must be able to identify the crucial assumptions underlying the development of their components and to enunciate straightforward rules for safe component interconnection. Keyword Codes: K.4.1; K.6.5; J.7
Carl E. Landwehr