@inproceedings{deploy239, booktitle = {The 29th International Conference on Computer Safety, Reliability and Security (Safecomp 2010)}, title = {Verifying Mode Consistency for On-Board Satellite Software}, author = {Alexei Iliasov and Elena Troubitsyna and Linas Laibinis and Alexander Romanovsky and Kimmo Varpaaniemi and Pauli V{\"a}is{\"a}nen and Dubravka Ilic and Timo Latvala}, year = {2010}, url = {http://deploy-eprints.ecs.soton.ac.uk/239/}, abstract = {Space satellites are examples of complex embedded systems. Dynamic behaviour of such systems is typically described in terms of operational modes that correspond to the different stages of a mission and states of the components. Components are susceptible to various faults that complicate the mode transition scheme. Yet the success of a mission depends on the correct implementation of mode changes. In this paper we propose a formal approach that ensures consistency of mode changes while developing a system architecture by refinement. The approach relies on recursive application of modelling and refinement patterns that enforce correctness while implementing the mode transition scheme. The proposed approach is exemplified by the development of an Attitude and Orbit Control System undertaken within the ICT DEPLOY project.} }