**Author details**

22 Will-be-set-by-IN-TECH

CONTEXT. The first theorem th1 can be interpreted as whenever the system in state S\_MTA and Select Team1 is true, transition holds, the system will probably in S\_MTPS state. The

SALenv also contains a Bounded Model Checker called sal-bmc. This model checker only supports LTL formulas, and it is basically used for refutation, although it can produce proofs

Remark: The default behavior is to look for counterexample up to depth 10. The option -depth=<num> can be used to control the depth of the search. The option -iterative forces the model checker to use iterative deepening, and it is useful to find the shortest counterexample for a given property. Before proving a liveness property, we must check if the transition relation is total, that is, if every state has at least one successor. The model checker may produce unsound result when the transition relation is not total. The totality property can be

The liveness theorem can be interpreted as always, the quantity of stock of piece is not null in the two teams. Now, we use sal-smc to check the property liveness with the following

The Boundedness theorem can be interpreted as always, the state space system is bounded. Now, we use sal-bmc to check the property Boundedness with the following command line:

In this chapter we showed that HMAS is well adapted to analyse and design an IMC holarchy. The meta-model utilized can be exploited in the implantation stage with the advantage of having formally validated its structure and its behaviour by using Heterogeneous formal specification based on Stochastic Petri Nets and Object-Z. For the moment, we are now refining our SPNOZ tool to establish a semantic-based in Markov chain isomorphic to SPN. This semantic seems best adapted to be transformed into Transition systems. Our future works will focus on a finer analysis of this system type and on a formal modelling of the various scenarios associated with the analysis stage. The notion of multi-views should be integrated. Indeed, the search for and the choice of strategy depends on the point of view of the person or the team required to take decisions according not only the constraints linked to the system but also to their environments. At the same time, it will be interesting to use HMAS which proposes multi-view holarchy introduced in [29] and consequently integrate it

by induction of safety properties. The following command line is used:

verified using the sal-deadlock-checker. The following command line is used:

following command line is used:

no counterexample between depths [0, 10]

/sal-deadlock-checker IMC IMC-Part

./sal-smc -v 3 IMC-Part liveness

./sal-bmc IMC Boundedness

no counterexample between depths [0, 10]

in the different existing meta-models.

Ok (module does NOT contain deadlock state).

./sal-smc IMC th1

./sal-bmc IMC th1

command line:

**5. Conclusion**

proved.

proved.

Belhassen Mazigh *Faculty of sciences, Department of Computer Sciences, 5000, Monastir, Tunisia*

Abdeljalil Abbas-Turki *Laboratoire SET, Université de Technologie de Belfort Montbéliard, Belfort, France*
