<?xml version="1.0" encoding="utf-8"?>
<!DOCTYPE raweb PUBLIC "-//INRIA//DTD " "raweb2.dtd">
<raweb xmlns:html="http://www.w3.org/1999/xhtml" xmlns:xlink="http://www.w3.org/1999/xlink" xml:lang="en" year="2011">
  <identification id="proval" isproject="true">
    <shortname>PROVAL</shortname>
    <projectName>Proofs of programs</projectName>
    <theme-de-recherche>Programs, Verification and Proofs</theme-de-recherche>
    <domaine-de-recherche>Algorithmics, Programming, Software and Architecture</domaine-de-recherche>
    <UR name="Saclay"/>
    <keywords>
      <term>Proofs Of Programs</term>
      <term>Automated Theorem Proving</term>
      <term>Interactive Theorem Proving</term>
      <term>Safety</term>
      <term>Floating-Point Numbers</term>
    </keywords>
    <moreinfo>
      <p>The Proval project-team is a research team common to INRIA - Saclay Île-de-France, CNRS and Université Paris-Sud. Researchers are also members of the LRI (Laboratoire de Recherche en
      Informatique, UMR 8623).</p>
    </moreinfo>
  </identification>
  <team id="uid1">
    <person key="proval-2008-idm220575009344">
      <firstname>Christine</firstname>
      <lastname>Paulin-Mohring</lastname>
      <affiliation>UnivFr</affiliation>
      <categoryPro>Enseignant</categoryPro>
      <research-centre>Saclay</research-centre>
      <moreinfo>Team Leader, Professor Université Paris-Sud</moreinfo>
      <hdr>oui</hdr>
    </person>
    <person key="proval-2006-idm410174325056">
      <firstname>Claude</firstname>
      <lastname>Marché</lastname>
      <affiliation>INRIA</affiliation>
      <categoryPro>Chercheur</categoryPro>
      <research-centre>Saclay</research-centre>
      <moreinfo>Team Vice-Leader, Senior Researcher</moreinfo>
      <hdr>oui</hdr>
    </person>
    <person key="proval-2008-idm220574999376">
      <firstname>Régine</firstname>
      <lastname>Bricquet</lastname>
      <affiliation>INRIA</affiliation>
      <categoryPro>Assistant</categoryPro>
      <research-centre>Saclay</research-centre>
      <moreinfo>TR</moreinfo>
    </person>
    <person key="proval-2009-idm423378972704">
      <firstname>Alain</firstname>
      <lastname>Mebsout</lastname>
      <affiliation>INRIA</affiliation>
      <categoryPro>Technique</categoryPro>
      <research-centre>Saclay</research-centre>
      <moreinfo>Junior Engineer, until August</moreinfo>
    </person>
    <person key="proval-2006-idm410174308976">
      <firstname>Sylvie</firstname>
      <lastname>Boldo</lastname>
      <affiliation>INRIA</affiliation>
      <categoryPro>Chercheur</categoryPro>
      <research-centre>Saclay</research-centre>
      <moreinfo>Junior Researcher</moreinfo>
    </person>
    <person key="proval-2006-idm410174301040">
      <firstname>Sylvain</firstname>
      <lastname>Conchon</lastname>
      <affiliation>UnivFr</affiliation>
      <categoryPro>Enseignant</categoryPro>
      <research-centre>Saclay</research-centre>
      <moreinfo>Associate Professor Université Paris-Sud, delegation INRIA</moreinfo>
    </person>
    <person key="proval-2006-idm410174306336">
      <firstname>Évelyne</firstname>
      <lastname>Contejean</lastname>
      <affiliation>CNRS</affiliation>
      <categoryPro>Chercheur</categoryPro>
      <research-centre>Saclay</research-centre>
      <moreinfo>Junior Researcher CNRS</moreinfo>
    </person>
    <person key="proval-2006-idm410174303696">
      <firstname>Jean-Christophe</firstname>
      <lastname>Filliâtre</lastname>
      <affiliation>CNRS</affiliation>
      <categoryPro>Chercheur</categoryPro>
      <research-centre>Saclay</research-centre>
      <moreinfo>Junior Researcher CNRS</moreinfo>
      <hdr>oui</hdr>
    </person>
    <person key="arenaire-2006-idm111960255408">
      <firstname>Guillaume</firstname>
      <lastname>Melquiond</lastname>
      <affiliation>INRIA</affiliation>
      <categoryPro>Chercheur</categoryPro>
      <research-centre>Saclay</research-centre>
      <moreinfo>Junior Researcher</moreinfo>
    </person>
    <person key="proval-2009-idm423378947776">
      <firstname>Andrei</firstname>
      <lastname>Paskevich</lastname>
      <affiliation>UnivFr</affiliation>
      <categoryPro>Enseignant</categoryPro>
      <research-centre>Saclay</research-centre>
      <moreinfo>Associate Professor Université Paris-Sud</moreinfo>
    </person>
    <person key="proval-2009-idm423378944592">
      <firstname>Xavier</firstname>
      <lastname>Urbain</lastname>
      <affiliation>UnivFr</affiliation>
      <categoryPro>Enseignant</categoryPro>
      <research-centre>Saclay</research-centre>
      <moreinfo>Associate Professor ENSIIE, Deleg. INRIA until Aug.</moreinfo>
      <hdr>oui</hdr>
    </person>
    <person key="proval-2007-idm172231421920">
      <firstname>Romain</firstname>
      <lastname>Bardou</lastname>
      <affiliation>UnivFr</affiliation>
      <categoryPro>PhD</categoryPro>
      <research-centre>Saclay</research-centre>
      <moreinfo>Université Paris-Sud, until Aug.</moreinfo>
    </person>
    <person key="proval-2008-idm220574959120">
      <firstname>François</firstname>
      <lastname>Bobot</lastname>
      <affiliation>UnivFr</affiliation>
      <categoryPro>PhD</categoryPro>
      <research-centre>Saclay</research-centre>
      <moreinfo>Université Paris-Sud</moreinfo>
    </person>
    <person key="proval-2011-idm383373667744">
      <firstname>Claire</firstname>
      <lastname>Dross</lastname>
      <affiliation>EtablissementPrive</affiliation>
      <categoryPro>PhD</categoryPro>
      <research-centre>Saclay</research-centre>
      <moreinfo>CIFRE Adacore</moreinfo>
    </person>
    <person key="gallium-2009-idm362141100192">
      <firstname>Paolo</firstname>
      <lastname>Herms</lastname>
      <affiliation>AutreEtablissementPublic</affiliation>
      <categoryPro>PhD</categoryPro>
      <research-centre>Saclay</research-centre>
      <moreinfo>CEA grant</moreinfo>
    </person>
    <person key="proval-2009-idm423378923200">
      <firstname>Mohamed</firstname>
      <lastname>Iguernelala</lastname>
      <affiliation>UnivFr</affiliation>
      <categoryPro>PhD</categoryPro>
      <research-centre>Saclay</research-centre>
      <moreinfo>Université Paris-Sud</moreinfo>
    </person>
    <person key="proval-2009-idm423378972704">
      <firstname>Alain</firstname>
      <lastname>Mebsout</lastname>
      <affiliation>UnivFr</affiliation>
      <categoryPro>PhD</categoryPro>
      <research-centre>Saclay</research-centre>
      <moreinfo>Université Paris-Sud, since Sep.</moreinfo>
    </person>
    <person key="proval-2011-idm383373655520">
      <firstname>Catherine</firstname>
      <lastname>Lelay</lastname>
      <affiliation>INRIA</affiliation>
      <categoryPro>PhD</categoryPro>
      <research-centre>Saclay</research-centre>
      <moreinfo>INRIA Digiteo grant, since Oct.</moreinfo>
    </person>
    <person key="proval-2006-idm410173274400">
      <firstname>Stéphane</firstname>
      <lastname>Lescuyer</lastname>
      <affiliation>INRIA</affiliation>
      <categoryPro>PhD</categoryPro>
      <research-centre>Saclay</research-centre>
      <moreinfo>INRIA, on leave from X-Mines, until Jan.</moreinfo>
    </person>
    <person key="proval-2009-idm423378000896">
      <firstname>Thi-Minh-Tuyen</firstname>
      <lastname>Nguyen</lastname>
      <affiliation>INRIA</affiliation>
      <categoryPro>PhD</categoryPro>
      <research-centre>Saclay</research-centre>
      <moreinfo>INRIA Digiteo grant</moreinfo>
    </person>
    <person key="proval-2009-idm423377994816">
      <firstname>Asma</firstname>
      <lastname>Tafat Bouzid</lastname>
      <affiliation>UnivFr</affiliation>
      <categoryPro>PhD</categoryPro>
      <research-centre>Saclay</research-centre>
      <moreinfo>Université Paris-Sud</moreinfo>
    </person>
    <person key="proval-2006-idm410174273712">
      <firstname>Wendi</firstname>
      <lastname>Urribarrí</lastname>
      <affiliation>UnivFr</affiliation>
      <categoryPro>PhD</categoryPro>
      <research-centre>Saclay</research-centre>
      <moreinfo>ATER Université Paris-Sud 11 until Sep.</moreinfo>
    </person>
    <person key="parsifal-2006-idm465379746128">
      <firstname>David</firstname>
      <lastname>Baelde</lastname>
      <affiliation>CNRS</affiliation>
      <categoryPro>PostDoc</categoryPro>
      <research-centre>Saclay</research-centre>
      <moreinfo>Post-doc CNRS</moreinfo>
    </person>
    <person key="logical-2006-idm356512372048">
      <firstname>Denis</firstname>
      <lastname>Cousineau</lastname>
      <affiliation>INRIA</affiliation>
      <categoryPro>PostDoc</categoryPro>
      <research-centre>Saclay</research-centre>
      <moreinfo>Post-doc FUI Grant Hi-Lite, since Sep.</moreinfo>
    </person>
    <person key="proval-2009-idm423377985664">
      <firstname>Krishnamani</firstname>
      <lastname>Kalyanasundaram</lastname>
      <affiliation>INRIA</affiliation>
      <categoryPro>PostDoc</categoryPro>
      <research-centre>Saclay</research-centre>
      <moreinfo>Post-doc ANR grant, until Aug.</moreinfo>
    </person>
    <person key="logical-2006-idm356512379888">
      <firstname>Evgeny</firstname>
      <lastname>Makarov</lastname>
      <affiliation>INRIA</affiliation>
      <categoryPro>PostDoc</categoryPro>
      <research-centre>Saclay</research-centre>
      <moreinfo>Post-doc ANR grant, May-October</moreinfo>
    </person>
    <person key="marelle-2007-idm161779222944">
      <firstname>Cody</firstname>
      <lastname>Roux</lastname>
      <affiliation>INRIA</affiliation>
      <categoryPro>PostDoc</categoryPro>
      <research-centre>Saclay</research-centre>
      <moreinfo>Post-doc ANR grant, since May</moreinfo>
    </person>
    <person key="proval-2011-idm383373624928">
      <firstname>Daisuke</firstname>
      <lastname>Ishii</lastname>
      <affiliation>UnivEtrangere</affiliation>
      <categoryPro>Visiteur</categoryPro>
      <research-centre>Saclay</research-centre>
      <moreinfo>National Institute of Informatics, Japan, since May</moreinfo>
    </person>
    <person key="proval-2011-idm383373655520">
      <firstname>Catherine</firstname>
      <lastname>Lelay</lastname>
      <affiliation>UnivFr</affiliation>
      <categoryPro>AutreCategorie</categoryPro>
      <research-centre>Saclay</research-centre>
      <moreinfo>Univ Paris 7, Master intern, May to Sep.</moreinfo>
    </person>
    <person key="proval-2011-idm383373618768">
      <firstname>Nuno</firstname>
      <lastname>Gaspar</lastname>
      <affiliation>UnivEtrangere</affiliation>
      <categoryPro>AutreCategorie</categoryPro>
      <research-centre>Saclay</research-centre>
      <moreinfo>Univ do Minho, Portugal, Master intern,until Sep.</moreinfo>
    </person>
    <person key="proval-2011-idm383373615680">
      <firstname>Shuai</firstname>
      <lastname>Yuan</lastname>
      <affiliation>UnivEtrangere</affiliation>
      <categoryPro>AutreCategorie</categoryPro>
      <research-centre>Saclay</research-centre>
      <moreinfo>Zhejiang University, China, since Oct.</moreinfo>
    </person>
  </team>
  <presentation id="uid2">
    <bodyTitle>Overall Objectives</bodyTitle>
    <subsection id="uid3" level="1">
      <bodyTitle>Introduction</bodyTitle>
      <p>Critical software applications in the domain of transportation, telecommunication or electronic transactions are put on the market within very short delays. In order to guarantee a
      dependable behavior, it is mandatory for a large part of the validation of the system to be done in a mechanical way.</p>
      <p>The ProVal team addresses this question and consequently participates to the INRIA major scientific priorities: “Programming: Security and Reliability of Computing Systems”.</p>
      <p>Our approach uses 
      <i>Type Theory</i>as a theoretical basis, a formalism which gives a clear semantics for representing, on a computer, both computation and deduction.</p>
      <p>Type theory is a natural formalism for the specification and proof of 
      <i>higher-order functional programs</i>, but we also use it as the kernel for 
      <i>deductive verification of imperative programs</i>. It serves as a support for modeling activities (e.g. pointer programs, random computations, floating-point arithmetic, semantics).</p>
      <p>Verification conditions (VCs) generated from programs annotated with specifications can often be expressed in simple formalisms (fragments of first-order logic) and consequently be solved
      using 
      <i>automated deduction</i>. Building specialized tools for solving VCs, integrating different proof technologies, in particular interactive and automated ones, are important activities in our
      group.</p>
      <p>When sophisticated tools are used for analyzing safety-critical code, their reliability is an important question: in an industrial setting, there is often a certification process. This
      certification is based on an informal satisfaction of development rules. We believe that decision procedures, compilers or verification condition generators (VCGs) should not act as black boxes
      but should be themselves specified and proved, or should produce evidence of the correctness of their output. This choice is influential in the design of our tools and is also a good challenge
      for them.</p>
      <p>The project develops a generic environment (
      <i>Why</i>) for proving programs. 
      <i>Why</i>generates sufficient conditions for a program to meet its expected behavior, that can be solved using interactive or automatic provers. On top of this tool, we have built dedicated
      environments for proving C (
      <i>Frama-C</i>/
      <i>Jessie</i>) or Java (
      <i>Krakatoa</i>) programs.</p>
      <p>With the arrival of Sylvie Boldo in 2005 and Guillaume Melquiond in 2008 as junior researchers, the team is developing a strong expertise in the area of formal verification of floating-point
      arithmetic.</p>
      <p>Our research activities are detailed further, following the three themes:</p>
      <simplelist>
        <li id="uid4">
          <p noindent="true">Interactive proofs of programs,</p>
        </li>
        <li id="uid5">
          <p noindent="true">Proof of imperative and object-oriented programs,</p>
        </li>
        <li id="uid6">
          <p noindent="true">Automated deduction for program proof.</p>
        </li>
      </simplelist>
      <p>Development of tools and applications is an important transversal activity for these four themes.</p>
    </subsection>
    <subsection id="uid7" level="1">
      <bodyTitle>Highlights</bodyTitle>
      <p>A new trend emerging in 2010-2011 is the construction of international program verification benchmarks and program verification competitions. Benchmarks include the VACID0 challenges (
      <ref xlink:href="http://vacid.codeplex.com/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://
      <allowbreak/>vacid.
      <allowbreak/>codeplex.
      <allowbreak/>com/
      <allowbreak/></ref>  
      <ref xlink:href="#proval-2011-bid0" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>) and the VerifyThis collection (
      <ref xlink:href="http://verifythis.cost-ic0701.org/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://
      <allowbreak/>verifythis.
      <allowbreak/>cost-ic0701.
      <allowbreak/>org/
      <allowbreak/></ref>). We took our part in these efforts by proposing our own gallery of verified programs (
      <ref xlink:href="http://proval.lri.fr/gallery/index.en.html" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://
      <allowbreak/>proval.
      <allowbreak/>lri.
      <allowbreak/>fr/
      <allowbreak/>gallery/
      <allowbreak/>index.
      <allowbreak/>en.
      <allowbreak/>html</ref>). Regarding competitions, we proposed our own solutions to the first (informal) VSTTE competition (
      <ref xlink:href="http://proval.lri.fr/gallery/vscomp2010.en.html" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://
      <allowbreak/>proval.
      <allowbreak/>lri.
      <allowbreak/>fr/
      <allowbreak/>gallery/
      <allowbreak/>vscomp2010.
      <allowbreak/>en.
      <allowbreak/>html</ref>), we participated to the first FoVeOOS competition (Turin, Italy, Sep. 2011) and were ranked as first, ex-aequo with two other teams (
      <ref xlink:href="http://proval.lri.fr/gallery/cost11comp.en.html" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://
      <allowbreak/>proval.
      <allowbreak/>lri.
      <allowbreak/>fr/
      <allowbreak/>gallery/
      <allowbreak/>cost11comp.
      <allowbreak/>en.
      <allowbreak/>html</ref>) and last but not least, we indeed organized the first formal VSTTE program verification competition (November 2011, 
      <ref xlink:href="https://sites.google.com/site/vstte2012/compet" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://
      <allowbreak/>sites.
      <allowbreak/>google.
      <allowbreak/>com/
      <allowbreak/>site/
      <allowbreak/>vstte2012/
      <allowbreak/>compet</ref>).</p>
      <p>A paper by S. Conchon, E. Contejean and M. Iguernelala 
      <ref xlink:href="#proval-2011-bid1" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>presenting their work on automated reasoning modulo
      associative-commutative theories got the best theoretical paper award of ETAPS Conferences 
      <ref xlink:href="http://www.eatcs.org/index.php/best-etaps-paper" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://
      <allowbreak/>www.
      <allowbreak/>eatcs.
      <allowbreak/>org/
      <allowbreak/>index.
      <allowbreak/>php/
      <allowbreak/>best-etaps-paper</ref>.</p>
      <best>
        <ref xlink:href="#proval-2011-bid1" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>
      </best>
    </subsection>
  </presentation>
  <fondements id="uid8">
    <bodyTitle>Scientific Foundations</bodyTitle>
    <subsection id="uid9" level="1">
      <bodyTitle>Interactive proofs of programs</bodyTitle>
      <participants>
        <person key="proval-2006-idm410174308976">
          <firstname>Sylvie</firstname>
          <lastname>Boldo</lastname>
        </person>
        <person key="proval-2006-idm410174306336">
          <firstname>Évelyne</firstname>
          <lastname>Contejean</lastname>
        </person>
        <person key="proval-2006-idm410174303696">
          <firstname>Jean-Christophe</firstname>
          <lastname>Filliâtre</lastname>
        </person>
        <person key="arenaire-2006-idm111960255408">
          <firstname>Guillaume</firstname>
          <lastname>Melquiond</lastname>
        </person>
        <person key="proval-2008-idm220575009344">
          <firstname>Christine</firstname>
          <lastname>Paulin-Mohring</lastname>
        </person>
      </participants>
      <p>Higher-order strongly typed programming languages such as Objective Caml help improving the quality of software development. Static typing automatically detects possible execution errors.
      Higher-order functions, polymorphism, modules and functors are powerful tools for the development of generic reusable libraries. Our general goal is to enrich such a software environment with a
      language of annotations as well as libraries for datatypes, abstract notions and associated theorems which can express logical properties of programs and ease the possibility to automatically
      and interactively develop proofs of correctness of the programs.</p>
      <p>In the past, we made contributions to the 
      <i>Coq</i>proof assistant by adding functionalities for improving the development of formally proved functional programs. A first contribution is a new method to extract OCaml modular code from
      
      <i>Coq</i>proofs (P. Letouzey PhD thesis 
      <ref xlink:href="#proval-2011-bid2" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>, 
      <ref xlink:href="#proval-2011-bid3" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>). This extraction mechanism is an original feature for the 
      <i>Coq</i>system, and has been used by several teams around the world in order to get efficient certified code  
      <ref xlink:href="#proval-2011-bid4" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>. Another contribution (M. Sozeau PhD thesis  
      <ref xlink:href="#proval-2011-bid5" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>, 
      <ref xlink:href="#proval-2011-bid6" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>) is an extension of the 
      <i>Coq</i>input language for building programs with strong specifications by writing only the computational part and generating separately proof obligations (which are usually solved by
      tactics) and also a mechanism generalizing Type Classes à la Haskell which gives overloading in programs and proofs and facilitates the development of generic tactics..</p>
      <p>We are using the capability of the 
      <i>Coq</i>system to model both computation and deduction in order to explore different classes of applications. These examples involve the development of large reusable 
      <i>Coq</i>libraries and suggest domain-specific specification and proof strategies.</p>
      <subsection id="uid10" level="2">
        <bodyTitle>Randomized algorithms</bodyTitle>
        <p>C. Paulin in collaboration with Ph. Audebaud from ENS Lyon, proposed a method for modeling probabilistic programs in 
        <i>Coq</i>  
        <ref xlink:href="#proval-2011-bid7" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>. The method is based on a monadic interpretation of probabilistic
        programs as probability measures. A large 
        <i>Coq</i>library has been developed and made publicly available (see also Section 
        <ref xlink:href="#uid41" location="intern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>). D. Baelde has been using this library to formally prove the security of
        Watermarking algorithms (see also section 
        <ref xlink:href="#uid44" location="intern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>).</p>
      </subsection>
      <subsection id="uid11" level="2">
        <bodyTitle>Floating-point programs</bodyTitle>
        <p>Many industrial programs (weather forecasts, plane trajectories, simulations...) use floating-point computations, typically double precision floating-point numbers  
        <ref xlink:href="#proval-2011-bid8" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>. Even if each computation is as good as it can be (except for
        elementary functions like sine, or exponential), the final result may be very wrong with no warnings, or the program will produce unexpected behaviors (like division by zero). This is the
        reason why guarantees should be provided to the user. We mean to guarantee for example that, for all or part of the possible inputs, the result obtained is correct (or near enough) and that
        no exceptional behavior will occur  
        <ref xlink:href="#proval-2011-bid9" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>.</p>
        <p>A high level of guarantee is obtained by formal proofs in 
        <i>Coq</i>. We maintain and develop large 
        <i>Coq</i>libraries for floating-point arithmetic: core definitions, axiomatic and computational rounding operations, high-level properties. It provides a framework for developers to formally
        certify numerical applications. A new such library is described in Section 
        <ref xlink:href="#uid38" location="intern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>.</p>
      </subsection>
      <subsection id="uid12" level="2">
        <bodyTitle>Certification of tools</bodyTitle>
        <p>Certifying the result of tools for analysing programs is a good challenge in the domain of proofs of higher-order functional programs. We obtained several results concerning formal proofs
        in 
        <i>Coq</i>corresponding to automated deduction. These results are described in Section 
        <ref xlink:href="#uid17" location="intern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>.</p>
        <p>A PhD thesis started in Sep. 2009 has for main objective the development of a certified version the Frama-C/Jessie/Why verification chain.</p>
      </subsection>
    </subsection>
    <subsection id="uid13" level="1">
      <bodyTitle>Proof of Imperative and Object-Oriented programs</bodyTitle>
      <participants>
        <person key="proval-2007-idm172231421920">
          <firstname>Romain</firstname>
          <lastname>Bardou</lastname>
        </person>
        <person key="proval-2008-idm220574959120">
          <firstname>François</firstname>
          <lastname>Bobot</lastname>
        </person>
        <person key="proval-2006-idm410174308976">
          <firstname>Sylvie</firstname>
          <lastname>Boldo</lastname>
        </person>
        <person key="proval-2006-idm410174303696">
          <firstname>Jean-Christophe</firstname>
          <lastname>Filliâtre</lastname>
        </person>
        <person key="proval-2006-idm410174325056">
          <firstname>Claude</firstname>
          <lastname>Marché</lastname>
        </person>
        <person key="proval-2009-idm423378000896">
          <firstname>Tuyen</firstname>
          <lastname>Nguyen</lastname>
        </person>
        <person key="proval-2009-idm423378947776">
          <firstname>Andrei</firstname>
          <lastname>Paskevich</lastname>
        </person>
        <person key="proval-2008-idm220575009344">
          <firstname>Christine</firstname>
          <lastname>Paulin-Mohring</lastname>
        </person>
        <person key="PASUSERID">
          <firstname>Asma</firstname>
          <lastname>Tafat</lastname>
        </person>
        <person key="proval-2006-idm410174273712">
          <firstname>Wendi</firstname>
          <lastname>Urribarrí</lastname>
        </person>
      </participants>
      <p>A foundation step of the project is the PhD thesis of Jean-Christophe Filliâtre 
      <ref xlink:href="#proval-2011-bid10" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>that proposes to establish soundness of a program with imperative
      features (assignments, while loops, but also exceptions and exception handlers) by means of a translation into an equivalent purely functional program with logical annotations. Such an
      annotated functional program is very well-suited to be expressed in 
      <i>Coq</i>'s type theory, hence this approach allowed for the first time to prove imperative programs with 
      <i>Coq</i>  
      <ref xlink:href="#proval-2011-bid11" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>.</p>
      <p>Following this thesis, a new tool called 
      <i>Why</i>was developed. It takes as input an imperative program and a specification that this program is expected to fulfil. It produces on one hand a set of 
      <i>verification conditions</i>(VCs): logical formulas which have to be proved in the 
      <i>Coq</i>system ; and on the other hand a 
      <i>Coq</i>-term which contains a functional translation of the imperative program and a proof of correctness of this program based on the VCs. It was early remarked that this tool was
      independent of 
      <i>Coq</i>, because the VCs can be validated in other interactive tools or with automatic provers. This multi-prover architecture is a powerful feature of 
      <i>Why</i>: it spreads this technology well beyond the 
      <i>Coq</i>community.</p>
      <object id="uid14">
        <table>
          <tr>
            <td>
              <ressource xlink:href="IMG/why_frama_c2-mps.png" type="float" width="427.0pt" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest" media="WEB"/>
            </td>
          </tr>
        </table>
        <caption>Architecture of certification chains: Frama-C, Why, Why3 and back-end provers</caption>
      </object>
      <subsection id="uid15" level="2">
        <bodyTitle>The 
        <i>Why</i>platform</bodyTitle>
        <p>Since 2002, we tackle programs written in mainstream programming languages. We first considered Java source code annotated with JML (Java Modeling Language). This method was implemented in
        a new tool called 
        <i>Krakatoa</i> 
        <ref xlink:href="#proval-2011-bid12" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>. The approach is based on a translation from annotated Java
        programs into the specific language of 
        <i>Why</i>, we then can reuse 
        <i>Why</i>'s VCG mechanism and choose between different provers for establishing these VCs. From 2003, we followed the same approach for programs written in ANSI C 
        <ref xlink:href="#proval-2011-bid13" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>.</p>
        <p>The combination of the 
        <i>Why</i>VC generator and the front-ends dealing with C or Java form a tool box for program verification, called the 
        <i>Why</i>platform. Its overall architecture is shown on Figure 
        <ref xlink:href="#uid14" location="intern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>. Nowadays, the front-end for C is in fact integrated in the Frama-C
        environment for static analysis of C programs (
        <ref xlink:href="http://www.frama-c.cea.fr/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://
        <allowbreak/>www.
        <allowbreak/>frama-c.
        <allowbreak/>cea.
        <allowbreak/>fr/
        <allowbreak/></ref>), which was developed by the CEA-List in collaboration with us. Frama-C has an open architecture, structured as plugins around a shared kernel, and deductive verification
        of C code can be done using Why via the Jessie plugin. The annotation language for C source is also designed in collaboration with CEA, and called ACSL  
        <ref xlink:href="#proval-2011-bid14" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>.</p>
        <p>The central issue for the design of our platform is the modeling of memory heap for Java and C programs, handling possible aliasing (two different pointer or object expressions
        representing the same memory location): the 
        <i>Why</i>VC generator does not handle aliasing by itself, indeed it does not support any form of complex data structures like objects, structures, pointers. On the other hand, it supports
        declaration of a kind of algebraic specifications: abstract data types specified by first-order functions, predicates and axioms. As a consequence, there is a general approach for using 
        <i>Why</i>as a target language for 
        <i>programming the semantics</i>of higher-level programming languages  
        <ref xlink:href="#proval-2011-bid15" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>. The 
        <i>Krakatoa</i>and the Jessie memory models are inspired by the `component-as-array' representation due to Bornat, following an old idea from Burstall, and commonly used to verify pointers
        programs  
        <ref xlink:href="#proval-2011-bid16" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>. Each field declaration 
        <formula type="inline"><math xmlns="http://www.w3.org/1998/Math/MathML" overflow="scroll"><mi>f</mi></math></formula>in a Java class or a C structure introduces a 
        <i>Why</i>variable 
        <formula type="inline"><math xmlns="http://www.w3.org/1998/Math/MathML" overflow="scroll"><msub><mi>M</mi><mi>f</mi></msub></math></formula>in the model, which is a map (or an array) indexed by addresses. We extended this idea to handle Java arrays and JML annotations 
        <ref xlink:href="#proval-2011-bid12" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>and pointer arithmetic in C 
        <ref xlink:href="#proval-2011-bid13" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>.</p>
        <p>An important difficulty with programs handling pointers is to specify side-effects of a function or a method. The annotation languages offer the 
        <i>assigns</i>clauses in specifications in order to delimitate the part of memory which is modified by a function or a method. We proposed an original modeling for such clauses  
        <ref xlink:href="#proval-2011-bid17" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/> 
        <ref xlink:href="#proval-2011-bid13" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>.</p>
        <p>This kind of memory model does not scale up well for large programs. We designed an improved modeling of memory heap incorporating ideas from static analysis of memory separation, and from
        Reynolds' separation logic. Experiments on a C code proposed by Dassault Aviation were successful  
        <ref xlink:href="#proval-2011-bid18" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>, 
        <ref xlink:href="#proval-2011-bid19" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>.</p>
        <p>The use of 
        <i>Why</i>as intermediate language opens interesting new approaches for reasoning on programs. We studied the specification of global properties, by reuse of the validation term of 
        <i>Why</i>in order to define a model of each function, and then express and prove properties of functions composition. Such an approach was investigated by J. Andronick in the framework
        of proofs of security properties on smart cards  
        <ref xlink:href="#proval-2011-bid20" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>, 
        <ref xlink:href="#proval-2011-bid21" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>. We also proposed a way to handle the Java Card transaction
        mechanism (a specificity of Java Card memory with both persistent and volatile parts), by indeed generating a 
        <i>Why</i>model 
        <i>on-the-fly</i>for each Java Card applet  
        <ref xlink:href="#proval-2011-bid22" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>, thanks again to the flexibility of the approach using 
        <i>Why</i>as an intermediate language.</p>
      </subsection>
      <subsection id="uid16" level="2">
        <bodyTitle>Applications and case studies</bodyTitle>
        <p>The techniques we are developing can be naturally applied in domains which require to develop critical software for which there is a high need of certification.</p>
        <p>The 
        <i>Krakatoa</i>tool was successfully used for the formal verification of a commercial smart card applet  
        <ref xlink:href="#proval-2011-bid23" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>proposed by Gemalto. This case study have been conducted in
        collaboration with LOOP and Jive groups. Banking applications are concerned with security problems that can be the confidentiality and protection of data, authentication, etc. The translation
        of such specifications into assertions in the source code of the program is an essential problem. We have been working on a Java Card applet for an electronic purse Demoney  
        <ref xlink:href="#proval-2011-bid24" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>developed by the company Trusted Logic for experimental purpose.
        Other Java Card case studies have been conducted in collaboration with Gemalto by J. Andronick and N. Rousset, in particular on global properties and Java Card transactions  
        <ref xlink:href="#proval-2011-bid20" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>, 
        <ref xlink:href="#proval-2011-bid22" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>.</p>
        <p>To illustrate the effectiveness of the approach on C programs, T. Hubert and C. Marché performed a full verification of a C implementation of the Schorr-Waite algorithm 
        <ref xlink:href="#proval-2011-bid25" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>, using 
        <i>Coq</i>for the proofs. This is an allocation-free graph-marking algorithm used in garbage collectors, which is considered as a benchmark for verification tools. Other industrial case
        studies have been investigated by T. Hubert (with Dassault Aviation)  
        <ref xlink:href="#proval-2011-bid19" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>and by Y. Moy (with France Telecom)  
        <ref xlink:href="#proval-2011-bid26" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>, 
        <ref xlink:href="#proval-2011-bid27" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>.</p>
        <p>Since the beginning of 2011, we propose on the web a 
        <i>Gallery of Verified programs</i>(
        <ref xlink:href="http://proval.lri.fr/gallery/index.en.html" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://
        <allowbreak/>proval.
        <allowbreak/>lri.
        <allowbreak/>fr/
        <allowbreak/>gallery/
        <allowbreak/>index.
        <allowbreak/>en.
        <allowbreak/>html</ref>) which provides a large set of examples of programs that we proved correct, using various techniques. The gallery can be browsed using different criteria: by topics,
        by reference to benchmarks, by tools.</p>
      </subsection>
    </subsection>
    <subsection id="uid17" level="1">
      <bodyTitle>Automated deduction</bodyTitle>
      <participants>
        <person key="proval-2006-idm410174301040">
          <firstname>Sylvain</firstname>
          <lastname>Conchon</lastname>
        </person>
        <person key="proval-2006-idm410174306336">
          <firstname>Évelyne</firstname>
          <lastname>Contejean</lastname>
        </person>
        <person key="proval-2011-idm383373667744">
          <firstname>Claire</firstname>
          <lastname>Dross</lastname>
        </person>
        <person key="proval-2009-idm423378923200">
          <firstname>Mohamed</firstname>
          <lastname>Iguernelala</lastname>
        </person>
        <person key="proval-2006-idm410173274400">
          <firstname>Stéphane</firstname>
          <lastname>Lescuyer</lastname>
        </person>
        <person key="proval-2006-idm410174325056">
          <firstname>Claude</firstname>
          <lastname>Marché</lastname>
        </person>
        <person key="proval-2009-idm423378972704">
          <firstname>Alain</firstname>
          <lastname>Mebsout</lastname>
        </person>
        <person key="proval-2009-idm423378947776">
          <firstname>Andrei</firstname>
          <lastname>Paskevich</lastname>
        </person>
        <person key="proval-2009-idm423378944592">
          <firstname>Xavier</firstname>
          <lastname>Urbain</lastname>
        </person>
      </participants>
      <p>Our group has a long tradition of research on automated reasoning, in particular on equational logic, rewriting, and constraint solving. The main topics that have been under study in recent
      years are termination proofs techniques, the issue of combination of decision procedures, and generation of proof traces. Our theoretical results are mainly materialized inside our two
      automated provers CiME and 
      <i>Alt-Ergo</i>.</p>
      <subsection id="uid18" level="2">
        <bodyTitle>Termination</bodyTitle>
        <p>On the termination topic, we have studied new techniques which can be automated. A fundamental result of ours is a criterion for checking termination 
        <i>modularly</i>and 
        <i>incrementally</i>  
        <ref xlink:href="#proval-2011-bid28" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>, and further generalizations  
        <ref xlink:href="#proval-2011-bid29" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>. These criteria and methods have been implemented into the CiME2
        rewrite toolbox  
        <ref xlink:href="#proval-2011-bid30" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>. Around 2002, several projects of development of termination tools
        arose in the world. We believe we have been pioneer in this growth, and indeed we organized in 2004 the first competition of such tools.</p>
        <p>A direction of research on termination techniques was also to apply our new approaches (for rewriting) to other computing formalisms, first to Prolog programs 
        <ref xlink:href="#proval-2011-bid31" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>and then to membership equational programs  
        <ref xlink:href="#proval-2011-bid32" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>, a paradigm used in the 
        <i>Maude</i>system  
        <ref xlink:href="#proval-2011-bid33" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>.</p>
      </subsection>
      <subsection id="uid19" level="2">
        <bodyTitle>Decision Procedures</bodyTitle>
        <subsection id="uid20" level="3">
          <bodyTitle>Combination</bodyTitle>
          <p>Our research related to combination of decision procedures was initiated by a result 
          <ref xlink:href="#proval-2011-bid34" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>obtained in collaboration with Shankar's group at
          SRI-international who develops the PVS environment, showing how decision procedures for disjoint theories can be combined as soon as each of them provides a so-called “canonizer” and a
          “solver”. Existing combination methods in the literature are generally not very well understood, and S. Conchon had a major contribution, in collaboration with Sava Krstić from OGI School
          of Science and Engineering (Oregon Health and Science University, USA), which is a uniform description of combination of decision procedures, by means of a system of inference rules,
          clearly distinguished from their strategy of application, allowing much clearer proofs of soundness and completeness 
          <ref xlink:href="#proval-2011-bid35" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>, 
          <ref xlink:href="#proval-2011-bid36" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>.</p>
        </subsection>
        <subsection id="uid21" level="3">
          <bodyTitle>Polymorphic Logics</bodyTitle>
          <p>In the specific domain of program verification, the goals to be proved are given as formulae in a polymorphic multi-sorted first-order logic. Some of the sorts, such as integers and
          arrays, are built-in as they come from the usual data-types of programming languages. Polymorphism is used as a convenience for defining the memory models of C and Java programs and is
          handled at the level of the 
          <i>Why</i>tool.</p>
          <p>In order to be able to use all the available automated theorem provers (Simplify, SMT provers), including those which handle only untyped formulae (Simplify), one has to provide a way to
          get rid of polymorphism.</p>
          <p>S. Conchon and É. Contejean have proposed an encoding of polymorphic multi-sorted logic (PSL) into unsorted logic based on term transformation, rather than addition of sort
          predicates which was used till then. This approach was extended further by S. Lescuyer  
          <ref xlink:href="#proval-2011-bid37" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>, J.-F. Couchot  
          <ref xlink:href="#proval-2011-bid38" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>, N. Stouls  
          <ref xlink:href="#proval-2011-bid39" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>.</p>
        </subsection>
        <subsection id="uid22" level="3">
          <bodyTitle>The 
          <i>Alt-Ergo</i>theorem prover</bodyTitle>
          <p>It would be more convenient to deal with polymorphism directly in the theorem prover. There was no such prover available at the beginning of 2006, that is why S. Conchon and
          É. Contejean decided to develop a new tool called 
          <i>Alt-Ergo</i>which is dedicated to the resolution of polymorphic and multi-sorted proof obligations and takes as input the 
          <i>Why</i>syntax. In 2011, 
          <i>Alt-Ergo</i>is still the only existing prover dealing with parametric polymorphism.</p>
          <p><i>Alt-Ergo</i>is based on CC(
          <formula type="inline"><math xmlns="http://www.w3.org/1998/Math/MathML" overflow="scroll"><mi>X</mi></math></formula>) 
          <ref xlink:href="#proval-2011-bid40" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>, a generic congruence closure algorithm developed in the team,
          for deciding ground formulas in the combination of the theory of equality with uninterpreted symbols and an arbitrary built-in solvable theory 
          <formula type="inline"><math xmlns="http://www.w3.org/1998/Math/MathML" overflow="scroll"><mi>X</mi></math></formula>. Currently, CC(
          <formula type="inline"><math xmlns="http://www.w3.org/1998/Math/MathML" overflow="scroll"><mi>X</mi></math></formula>) can be instantiated by the empty equational theory, by the linear arithmetics and the theory of constructors.</p>
          <p><i>Alt-Ergo</i>contains also a Fourier-Motzkin decision procedure for linear arithmetics inequalities, a home-made SAT-solver and an instantiation mechanism.</p>
          <p>The architecture of 
          <i>Alt-Ergo</i>is modular: each part is described by a small set of inference rules and is implemented as an OCaml functor. Moreover, the code is short (
          <formula type="inline"><math xmlns="http://www.w3.org/1998/Math/MathML" overflow="scroll"><mo>∼</mo></math></formula>10000 lines).</p>
        </subsection>
      </subsection>
      <subsection id="uid23" level="2">
        <bodyTitle>Automated proofs and certificates</bodyTitle>
        <p>A common issue to both termination techniques and decision procedures is that automatic provers use complex algorithms for checking validity of formula or termination of a computation, but
        when they answer that the problem is solved, they do not give any more useful information. It is highly desirable that they give a 
        <i>proof trace</i>, that is some kind of certificate that could be double-checked by a third party, such as an interactive proof assistant like 
        <i>Coq</i>. Indeed 
        <i>Coq</i>is based on a relatively small and stable kernel, so that when it checks that a proof is valid, it can be trusted. Morevoer, a subpart of Coq has been proven correct in Coq  
        <ref xlink:href="#proval-2011-bid41" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>.</p>
        <subsection id="uid24" level="3">
          <bodyTitle>Coccinelle and CiME's traces</bodyTitle>
          <p>In addition to efficient termination techniques, CiME implements in particular a semi-decision procedure for the equality modulo a set of axioms, based on ordered completion. In 2005,
          the former human readable proof traces have been replaced by 
          <i>Coq</i>certificates, based on reified proof objects for a FOL logic modelled inside 
          <i>Coq</i>  
          <ref xlink:href="#proval-2011-bid42" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>.</p>
          <p>É. Contejean, A. Paskevich, X. Urbain and the Cédric participants of the A3PAT project, Pierre Courtieu, Olivier Pons (CNAM), and Julien Forest, (ENSIIE) develop the new version of
          the CiME tool, CiME 3, associated with a 
          <i>Coq</i>library called Coccinelle developed by É. Contejean. A trace generator outputs a trace for 
          <i>Coq</i>in the unified framework provided by the Coccinelle library 
          <ref xlink:href="#proval-2011-bid43" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>
          <ref xlink:href="#proval-2011-bid44" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>. Coccinelle contains the corresponding modelling of terms
          algebras and rewriting statements, and also some generic theorems which are needed for establishing a rewriting property from a trace. For example, in order to produce a certificate of
          termination for a rewriting system, one may provide as a trace an ordering that contains the rewrite system, but it is also needed to have a proof that this ordering is well-founded. Such a
          proof (for RPO for instance) is part of Coccinelle as a generic property. Coccinelle also contains as generic theorems some powerful criteria of termination: dependency pairs 
          <ref xlink:href="#proval-2011-bid45" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>, the main modularity theorem for termination presented in the
          thesis of Urbain 
          <ref xlink:href="#proval-2011-bid28" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>as well as innermost termination, dependency pairs for it and its
          equivalence with standard termination in some specific cases 
          <ref xlink:href="#proval-2011-bid46" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>.</p>
          <p>The main improvement over the previous approach  
          <ref xlink:href="#proval-2011-bid42" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>is that the 
          <i>Coq</i>development is parameterized with respect to the equality predicate (instead of using the 
          <i>Coq</i>native equality). This allows to deal uniformly with equality modulo a set of axioms, with termination of a set of rewrite rules, and with rewriting modulo a set of equations,
          such as associativity-commutativity.</p>
          <p>Certifying termination proofs gained interest in the term rewriting community. Groups are either developing their own certifier, or producing traces for other's, thanks to a shared XML
          format. Since 2007, the termination competition has a category for certified termination proofs.</p>
          <p>Further note that our efforts are not limited to termination proofs, and to date CiME 3 is the only tool able to prove and to certify 
          <i>confluence</i>of term rewriting systems 
          <ref xlink:href="#proval-2011-bid47" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>.</p>
        </subsection>
        <subsection id="uid25" level="3">
          <bodyTitle>The 
          <tt>ergo</tt>tactics</bodyTitle>
          <p>In his thesis 
          <ref xlink:href="#proval-2011-bid48" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>, S. Lescuyer proposed new automation capabilities for the Coq
          proof assistant. He obtains this mechanization via an integration into Coq of decision procedures for propositional logic, equality reasoning and linear arithmetic which make up the core of
          the Alt-Ergo SMT solver. This integration is achieved through the reflection technique, which consists in implementing and formally proving these algorithms in Coq in order to execute them
          directly in the proof assistant. Because the algorithms formalized in Coq are exactly those in use in Alt-Ergo's kernel, this work significantly increases our trust in the solver. In
          particular, it embeds an original algorithm for combining equality modulo theory reasoning, called CC(X) and inspired by the Shostak combination algorithm, and whose justification is quite
          complex.</p>
          <p>The Coq implementation of S. Lescuyer is available in the form of tactics which allow one to automatically solve formulae combining propositional logic, equality and arithmetic. In order
          to make these tactics as efficient as may be, he has taken special care with performance in his implementation, in particular through the use of classical efficient data structures, which
          we provide as a separate library.</p>
        </subsection>
      </subsection>
    </subsection>
  </fondements>
  <domaine id="uid26">
    <bodyTitle>Application Domains</bodyTitle>
    <subsection id="uid27" level="1">
      <bodyTitle>Panorama</bodyTitle>
      <p>Many systems in telecommunication, banking or transportation involve sophisticated software for controlling critical operations. One major problem is to get a high-level of confidence in the
      algorithms or protocols that have been developed inside the companies or by partners.</p>
      <p>Many smartcards in mobile phones are based on a (small) Java virtual machine. The card is supposed to execute applets that are loaded dynamically. The operating system itself is written in
      C, it implements security functions in order to preserve the integrity of data on the card or to offer authentication mechanisms. Applets are developed in Java, compiled, and then the byte-code
      is loaded and executed on the card. Applets or the operating systems are relatively small programs but they need to behave correctly and to be certified by an independent entity.</p>
      <p>If the user expresses the expected behavior of the program as a formal specification, it is possible for a tool to check whether the program actually behaves according to the
      requirements.</p>
      <p>Avionics or more generally transportation systems are another area were there are critical algorithms involved, for instance in Air Traffic control. We have collaborations in this domain
      with Dassault-Aviation and National Institute of Aerospace (NIA, Hampton, USA). Since 2011, we started a new collaboration with Mitsubishi Electric R&amp;D Centre Europe (Rennes), on the
      construction of certified software for railroad transportation. We also recently started a collaboration with Adacore for a new environment for proving Ada source code, which has applications
      in transportation systems including aerospace.</p>
    </subsection>
  </domaine>
  <logiciels id="uid28">
    <bodyTitle>Software</bodyTitle>
    <subsection id="uid29" level="1">
      <bodyTitle>The CiME rewrite toolbox</bodyTitle>
      <participants>
        <person key="proval-2006-idm410174306336">
          <firstname>Évelyne</firstname>
          <lastname>Contejean</lastname>
          <moreinfo>contact</moreinfo>
        </person>
        <person key="proval-2006-idm410174325056">
          <firstname>Claude</firstname>
          <lastname>Marché</lastname>
        </person>
        <person key="proval-2009-idm423378947776">
          <firstname>Andrei</firstname>
          <lastname>Paskevich</lastname>
        </person>
        <person key="proval-2009-idm423378944592">
          <firstname>Xavier</firstname>
          <lastname>Urbain</lastname>
        </person>
      </participants>
      <p>CiME is a rewriting toolbox. Distributed since 1996 as open source, at URL 
      <ref xlink:href="http://cime.lri.fr" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://
      <allowbreak/>cime.
      <allowbreak/>lri.
      <allowbreak/>fr</ref>. Beyond a few dozens of users, CiME is used as back-end for other tools such as the TALP tool developed by Enno Ohlebusch at Bielefeld university for termination of logic
      programs; the MU-TERM tool (
      <ref xlink:href="http://www.dsic.upv.es/~slucas/csr/termination/muterm/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://
      <allowbreak/>www.
      <allowbreak/>dsic.
      <allowbreak/>upv.
      <allowbreak/>es/
      <allowbreak/>~slucas/
      <allowbreak/>csr/
      <allowbreak/>termination/
      <allowbreak/>muterm/
      <allowbreak/></ref>) for termination of context-sensitive rewriting; the CARIBOO tool (developed at INRIA Nancy Grand-Est) for termination of rewriting under strategies; and the MTT tool (
      <ref xlink:href="http://www.lcc.uma.es/~duran/MTT/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://
      <allowbreak/>www.
      <allowbreak/>lcc.
      <allowbreak/>uma.
      <allowbreak/>es/
      <allowbreak/>~duran/
      <allowbreak/>MTT/
      <allowbreak/></ref>) for termination of Maude programs. CiME2 is no longer maintained, and the currently developed version is CiME3, available at 
      <ref xlink:href="http://a3pat.ensiie.fr/pub" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://
      <allowbreak/>a3pat.
      <allowbreak/>ensiie.
      <allowbreak/>fr/
      <allowbreak/>pub</ref>. The main new feature of CiME3 is the production of traces for 
      <i>Coq</i>. CiME3 is also developed by the participants of the A3PAT project at the CNAM, and is distributed under the Cecill-C license.</p>
    </subsection>
    <subsection id="uid30" level="1">
      <bodyTitle>The 
      <i>Why</i>platform</bodyTitle>
      <participants>
        <person key="proval-2006-idm410174325056">
          <firstname>Claude</firstname>
          <lastname>Marché</lastname>
          <moreinfo>contact</moreinfo>
        </person>
        <person key="proval-2007-idm172231421920">
          <firstname>Romain</firstname>
          <lastname>Bardou</lastname>
        </person>
        <person key="proval-2008-idm220574959120">
          <firstname>François</firstname>
          <lastname>Bobot</lastname>
        </person>
        <person key="proval-2006-idm410174303696">
          <firstname>Jean-Christophe</firstname>
          <lastname>Filliâtre</lastname>
        </person>
        <person key="arenaire-2006-idm111960255408">
          <firstname>Guillaume</firstname>
          <lastname>Melquiond</lastname>
        </person>
        <person key="proval-2009-idm423378947776">
          <firstname>Andrei</firstname>
          <lastname>Paskevich</lastname>
        </person>
      </participants>
      <p>Criteria for Software Self-Assessment 
      <footnote id="uid31" id-text="1">self-evaluation following the guidelines (
      <ref xlink:href="http://www.inria.fr/content/download/11783/409665/version/4/file/SoftwareCriteria-V2-CE.pdf" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://
      <allowbreak/>www.
      <allowbreak/>inria.
      <allowbreak/>fr/
      <allowbreak/>content/
      <allowbreak/>download/
      <allowbreak/>11783/
      <allowbreak/>409665/
      <allowbreak/>version/
      <allowbreak/>4/
      <allowbreak/>file/
      <allowbreak/>SoftwareCriteria-V2-CE.
      <allowbreak/>pdf</ref>) of the Software Working Group of INRIA Evaluation Committee( 
      <ref xlink:href="http://www.inria.fr/institut/organisation/instances/commission-d-evaluation" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://
      <allowbreak/>www.
      <allowbreak/>inria.
      <allowbreak/>fr/
      <allowbreak/>institut/
      <allowbreak/>organisation/
      <allowbreak/>instances/
      <allowbreak/>commission-d-evaluation</ref>)</footnote>: A-3, SO-4, SM-3, EM-2, SDL-5-down, OC-4.</p>
      <p>The 
      <i>Why</i>platform is a set of tools for deductive verification of Java and C source code. In both cases, the requirements are specified as annotations in the source, in a special style of
      comments. For Java (and Java Card), these specifications are given in JML and are interpreted by the 
      <i>Krakatoa</i>tool. Analysis of C code must be done using the external 
      <i>Frama-C</i>environment, and its Jessie plugin which is distributed in 
      <i>Why</i>.</p>
      <p>The platform is distributed as open source, under GPL license, at 
      <ref xlink:href="http://why.lri.fr/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://
      <allowbreak/>why.
      <allowbreak/>lri.
      <allowbreak/>fr/
      <allowbreak/></ref>. The internal VC generator and the translators to external provers are no longer under active development, as superseded by the 
      <i>Why</i>3 system described below.</p>
      <p>The 
      <i>Krakatoa</i>and 
      <i>Jessie</i>front-ends are still maintained, although using now by default the 
      <i>Why</i>3 VC generator. These front-ends are described in a specific web page 
      <ref xlink:href="http://krakatoa.lri.fr/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://
      <allowbreak/>krakatoa.
      <allowbreak/>lri.
      <allowbreak/>fr/
      <allowbreak/></ref>. They are used for teaching (University of Evry, Ecole Polytechnique, etc.), used by several research groups in the world, e.g at Fraunhofer Institute in Berlin  
      <ref xlink:href="#proval-2011-bid49" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>, and at Universidade do Minho in Portugal  
      <ref xlink:href="#proval-2011-bid50" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>.</p>
    </subsection>
    <subsection id="uid32" level="1">
      <bodyTitle>The 
      <i>Why</i>3 system</bodyTitle>
      <participants>
        <person key="proval-2006-idm410174303696">
          <firstname>Jean-Christophe</firstname>
          <lastname>Filliâtre</lastname>
          <moreinfo>contact</moreinfo>
        </person>
        <person key="proval-2008-idm220574959120">
          <firstname>François</firstname>
          <lastname>Bobot</lastname>
        </person>
        <person key="proval-2006-idm410174325056">
          <firstname>Claude</firstname>
          <lastname>Marché</lastname>
        </person>
        <person key="arenaire-2006-idm111960255408">
          <firstname>Guillaume</firstname>
          <lastname>Melquiond</lastname>
        </person>
        <person key="proval-2009-idm423378947776">
          <firstname>Andrei</firstname>
          <lastname>Paskevich</lastname>
        </person>
      </participants>
      <p>Criteria for Software Self-Assessment: A-3-up, SO-4, SM-4, EM-4, SDL-4, OC-4.</p>
      <p><i>Why</i>3 is the next generation of 
      <i>Why</i>. 
      <i>Why</i>3 clearly separates the purely logical specification part from generation of verification conditions for programs. It features a rich library of proof task transformations that can be
      chained to produce a suitable input for a large set of theorem provers, including SMT solvers, TPTP provers, as well as interactive proof assistants.</p>
      <p>It is distributed as open source, under GPL license, at 
      <ref xlink:href="http://why3.lri.fr/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://
      <allowbreak/>why3.
      <allowbreak/>lri.
      <allowbreak/>fr/
      <allowbreak/></ref>.</p>
      <p><i>Why</i>3 is used as back-end of our own tools 
      <i>Krakatoa</i>and 
      <i>Jessie</i>, but also as back-end of the GNATprove tool (Adacore company), and in a near future of the WP plugin of Frama-C. 
      <i>Why</i>3 has been used to develop and prove a significant part of the programs of our team gallery 
      <ref xlink:href="http://proval.lri.fr/gallery/index.en.html" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://
      <allowbreak/>proval.
      <allowbreak/>lri.
      <allowbreak/>fr/
      <allowbreak/>gallery/
      <allowbreak/>index.
      <allowbreak/>en.
      <allowbreak/>html</ref>, and will be used soon for teaching (Master Parisien de Recherche en Informatique).</p>
    </subsection>
    <subsection id="uid33" level="1">
      <bodyTitle>The 
      <i>Alt-Ergo</i>theorem prover</bodyTitle>
      <participants>
        <person key="proval-2006-idm410174301040">
          <firstname>Sylvain</firstname>
          <lastname>Conchon</lastname>
          <moreinfo>contact</moreinfo>
        </person>
        <person key="proval-2006-idm410174306336">
          <firstname>Évelyne</firstname>
          <lastname>Contejean</lastname>
        </person>
        <person key="proval-2006-idm410173274400">
          <firstname>Stéphane</firstname>
          <lastname>Lescuyer</lastname>
        </person>
        <person key="proval-2009-idm423378972704">
          <firstname>Alain</firstname>
          <lastname>Mebsout</lastname>
        </person>
        <person key="proval-2009-idm423378923200">
          <firstname>Mohamed</firstname>
          <lastname>Iguernelala</lastname>
        </person>
      </participants>
      <p>Criteria for Software Self-Assessment: A-3-up, SO-4, SM-4-up, EM-4, SDL-5, OC-4.</p>
      <p><i>Alt-Ergo</i>is an automatic, little engine of proof dedicated to program verification, whose development started in 2006. It is fully integrated in the program verification tool chain
      developed in our team. It solves goals that are directly written in the 
      <i>Why</i>'s annotation language; this means that 
      <i>Alt-Ergo</i>fully supports first order polymorphic logic with quantifiers. 
      <i>Alt-Ergo</i>also supports the standard  
      <ref xlink:href="#proval-2011-bid51" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>defined by the SMT-lib initiative.</p>
      <p>It is currently used in our team to prove correctness of C and Java programs as part of the 
      <i>Why</i>platform and the new 
      <i>Why</i>3 system. 
      <i>Alt-Ergo</i>is also called as an external prover by the Pangolin tool developed by Y. Regis Gianas, INRIA project-team Gallium 
      <ref xlink:href="http://code.google.com/p/pangolin-programming-language/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://
      <allowbreak/>code.
      <allowbreak/>google.
      <allowbreak/>com/
      <allowbreak/>p/
      <allowbreak/>pangolin-programming-language/
      <allowbreak/></ref>. Alt-Ergo is usable as a back-end prover in the SPARK verifier for ADA programs, since Oct 2010. It is planed to be integrated in next generation of Airbus development
      process.</p>
      <p><i>Alt-Ergo</i>is distributed as open source, under the CeCILL-C license, at URL 
      <ref xlink:href="http://alt-ergo.lri.fr/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://
      <allowbreak/>alt-ergo.
      <allowbreak/>lri.
      <allowbreak/>fr/
      <allowbreak/></ref>.</p>
    </subsection>
    <subsection id="uid34" level="1">
      <bodyTitle>Bibtex2html</bodyTitle>
      <participants>
        <person key="proval-2006-idm410174303696">
          <firstname>Jean-Christophe</firstname>
          <lastname>Filliâtre</lastname>
          <moreinfo>contact</moreinfo>
        </person>
        <person key="proval-2006-idm410174325056">
          <firstname>Claude</firstname>
          <lastname>Marché</lastname>
        </person>
      </participants>
      <p>Criteria for Software Self-Assessment: A-5, SO-3, SM-3, EM-3, SDL-5, OC-4.</p>
      <p>Bibtex2html is a generator of HTML pages of bibliographic references. Distributed as open source since 1997, under the GPL license, at 
      <ref xlink:href="http://www.lri.fr/~filliatr/bibtex2html/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://
      <allowbreak/>www.
      <allowbreak/>lri.
      <allowbreak/>fr/
      <allowbreak/>~filliatr/
      <allowbreak/>bibtex2html/
      <allowbreak/></ref>. We estimate that between 10000 and 100000 web pages have been generated using Bibtex2html.</p>
      <p>Bibtex2html is also distributed as a package in most Linux distributions. Package popularity contests show that it is among the 20% most often installed packages.</p>
    </subsection>
    <subsection id="uid35" level="1">
      <bodyTitle>OCamlgraph</bodyTitle>
      <participants>
        <person key="proval-2006-idm410174303696">
          <firstname>Jean-Christophe</firstname>
          <lastname>Filliâtre</lastname>
          <moreinfo>contact</moreinfo>
        </person>
        <person key="proval-2006-idm410174301040">
          <firstname>Sylvain</firstname>
          <lastname>Conchon</lastname>
        </person>
      </participants>
      <p>OCamlgraph is a graph library for Objective Caml. It features many graph data structures, together with many graph algorithms. Data structures and algorithms are provided independently of
      each other, thanks to OCaml module system. OCamlgraph is distributed as open source, under the LGPL license, at 
      <ref xlink:href="http://ocamlgraph.lri.fr/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://
      <allowbreak/>ocamlgraph.
      <allowbreak/>lri.
      <allowbreak/>fr/
      <allowbreak/></ref>. It is also distributed as a package in several Linux distributions. OCamlgraph is now widely spread among the community of OCaml developers.</p>
    </subsection>
    <subsection id="uid36" level="1">
      <bodyTitle>Mlpost</bodyTitle>
      <participants>
        <person key="proval-2006-idm410174303696">
          <firstname>Jean-Christophe</firstname>
          <lastname>Filliâtre</lastname>
          <moreinfo>contact</moreinfo>
        </person>
        <person key="proval-2006-idm410173274400">
          <firstname>Stéphane</firstname>
          <lastname>Lescuyer</lastname>
        </person>
        <person key="proval-2007-idm172231421920">
          <firstname>Romain</firstname>
          <lastname>Bardou</lastname>
        </person>
        <person key="proval-2008-idm220574959120">
          <firstname>François</firstname>
          <lastname>Bobot</lastname>
        </person>
      </participants>
      <p>Mlpost is a tool to draw scientific figures to be integrated in 
      <LaTeX/>documents. Contrary to other tools such as TikZ or MetaPost, it does not introduce a new programming language; it is instead designed as a library of an existing programming language,
      namely Objective Caml. Yet it is based on MetaPost internally and thus provides high-quality PostScript figures and powerful features such as intersection points or clipping. Mlpost is
      distributed as open source, under the LGPL license, at 
      <ref xlink:href="http://mlpost.lri.fr/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://
      <allowbreak/>mlpost.
      <allowbreak/>lri.
      <allowbreak/>fr/
      <allowbreak/></ref>. Mlpost was presented at JFLA'09  
      <ref xlink:href="#proval-2011-bid52" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>.</p>
    </subsection>
    <subsection id="uid37" level="1">
      <bodyTitle>Functory</bodyTitle>
      <participants>
        <person key="proval-2006-idm410174303696">
          <firstname>Jean-Christophe</firstname>
          <lastname>Filliâtre</lastname>
          <moreinfo>contact</moreinfo>
        </person>
        <person key="PASUSERID">
          <firstname>Kalyan</firstname>
          <lastname>Krishnamani</lastname>
        </person>
      </participants>
      <p>Functory is a distributed computing library for Objective Caml. The main features of this library include (1) a polymorphic API, (2) several implementations to adapt to different deployment
      scenarios such as sequential, multi-core or network, and (3) a reliable fault-tolerance mechanism. Functory was presented at JFLA 2011 
      <ref xlink:href="#proval-2011-bid53" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>and at TFP 2011 
      <ref xlink:href="#proval-2011-bid54" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>.</p>
    </subsection>
    <subsection id="uid38" level="1">
      <bodyTitle>The Flocq library</bodyTitle>
      <participants>
        <person key="proval-2006-idm410174308976">
          <firstname>Sylvie</firstname>
          <lastname>Boldo</lastname>
          <moreinfo>contact</moreinfo>
        </person>
        <person key="arenaire-2006-idm111960255408">
          <firstname>Guillaume</firstname>
          <lastname>Melquiond</lastname>
        </person>
      </participants>
      <p>Criteria for Software Self-Assessment: A-2, SO-3, SM-3, EM-3, SDL-4, OC-4.</p>
      <p>The Flocq library for the 
      <i>Coq</i>proof assistant is a comprehensive formalization of floating-point arithmetic: core definitions, axiomatic and computational rounding operations, high-level properties 
      <ref xlink:href="#proval-2011-bid55" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>. It provides a framework for developers to formally certify
      numerical applications.</p>
      <p>It is distributed as open source, under a LGPL license, at 
      <ref xlink:href="http://flocq.gforge.inria.fr/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://
      <allowbreak/>flocq.
      <allowbreak/>gforge.
      <allowbreak/>inria.
      <allowbreak/>fr/
      <allowbreak/></ref>. It was first released in 2010.</p>
    </subsection>
    <subsection id="uid39" level="1">
      <bodyTitle>The Gappa tool</bodyTitle>
      <participants>
        <person key="arenaire-2006-idm111960255408">
          <firstname>Guillaume</firstname>
          <lastname>Melquiond</lastname>
          <moreinfo>contact</moreinfo>
        </person>
      </participants>
      <p>Criteria for Software Self-Assessment: A-3, SO-4, SM-4, EM-3, SDL-4, OC-4.</p>
      <p>Given a logical property involving interval enclosures of mathematical expressions, Gappa tries to verify this property and generates a formal proof of its validity. This formal proof can be
      machine-checked by an independent tool like the 
      <i>Coq</i>proof-checker, so as to reach a high level of confidence in the certification  
      <ref xlink:href="#proval-2011-bid56" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/> 
      <ref xlink:href="#proval-2011-bid57" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>.</p>
      <p>Since these mathematical expressions can contain rounding operators in addition to usual arithmetic operators, Gappa is especially well suited to prove properties that arise when certifying
      a numerical application, be it floating-point or fixed-point. Gappa makes it easy to compute ranges of variables and bounds on absolute or relative roundoff errors.</p>
      <p>Gappa is being used to certify parts of the mathematical libraries of several projects, including CRlibm, FLIP, and CGAL. It is distributed as open source, under a Cecill-B / GPL
      dual-license, at 
      <ref xlink:href="http://gappa.gforge.inria.fr/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://
      <allowbreak/>gappa.
      <allowbreak/>gforge.
      <allowbreak/>inria.
      <allowbreak/>fr/
      <allowbreak/></ref>. Part of the work on this tool was done while in the Arénaire team (INRIA Rhône-Alpes), until 2008.</p>
    </subsection>
    <subsection id="uid40" level="1">
      <bodyTitle>The Interval package for 
      <i>Coq</i></bodyTitle>
      <participants>
        <person key="arenaire-2006-idm111960255408">
          <firstname>Guillaume</firstname>
          <lastname>Melquiond</lastname>
          <moreinfo>contact</moreinfo>
        </person>
      </participants>
      <p>Criteria for Software Self-Assessment: A-3, SO-4, SM-3, EM-3, SDL-4, OC-4.</p>
      <p>The Interval package provides several tactics for helping a 
      <i>Coq</i>user to prove theorems on enclosures of real-valued expressions. The proofs are performed by an interval kernel which relies on a computable formalization of floating-point arithmetic
      in 
      <i>Coq</i>.</p>
      <p>It is distributed as open source, under a LGPL license, at 
      <ref xlink:href="http://www.lri.fr/~melquion/soft/coq-interval/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://
      <allowbreak/>www.
      <allowbreak/>lri.
      <allowbreak/>fr/
      <allowbreak/>~melquion/
      <allowbreak/>soft/
      <allowbreak/>coq-interval/
      <allowbreak/></ref>. Part of the work on this library was done while in the Mathematical Components team (Microsoft Research–INRIA Joint Research Center).</p>
      <p>In 2010, the Flocq library was used to straighten and fill the floating-point proofs of the Interval package.</p>
    </subsection>
    <subsection id="uid41" level="1">
      <bodyTitle>The Alea library for randomized algorithms</bodyTitle>
      <participants>
        <person key="proval-2008-idm220575009344">
          <firstname>Christine</firstname>
          <lastname>Paulin-Mohring</lastname>
          <moreinfo>contact</moreinfo>
        </person>
        <person key="parsifal-2006-idm465379746128">
          <firstname>David</firstname>
          <lastname>Baelde</lastname>
        </person>
      </participants>
      <p>Criteria for Software Self-Assessment: A-2, SO-3, SM-2, EM-3, SDL-4, OC-4.</p>
      <p>The ALEA library is a 
      <i>Coq</i>development for modeling randomized functional programs as distributions using a monadic transformation. It contains an axiomatisation of the real interval 
      <formula type="inline"><math xmlns="http://www.w3.org/1998/Math/MathML" overflow="scroll"><mrow><mo>[</mo><mn>0</mn><mo>,</mo><mn>1</mn><mo>]</mo></mrow></math></formula>and its extension to positive real numbers. It introduces definition of distributions and general rules for approximating the probability that a program satisfies a given
      property.</p>
      <p>It is distributed as open source, at 
      <ref xlink:href="http://www.lri.fr/~paulin/ALEA" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://
      <allowbreak/>www.
      <allowbreak/>lri.
      <allowbreak/>fr/
      <allowbreak/>~paulin/
      <allowbreak/>ALEA</ref>. It is currently used as a basis of the Certicrypt environment (MSR-INRIA joint research center, Imdea Madrid, INRIA Sophia-Antipolis) for formal proofs for
      computational cryptography  
      <ref xlink:href="#proval-2011-bid58" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>. It is also experimented in LABRI as a basis to study formal proofs
      of probabilistic distributed algorithms.</p>
    </subsection>
    <subsection id="uid42" level="1">
      <bodyTitle>The Coccinelle library for term rewriting</bodyTitle>
      <participants>
        <person key="proval-2006-idm410174306336">
          <firstname>Évelyne</firstname>
          <lastname>Contejean</lastname>
          <moreinfo>contact</moreinfo>
        </person>
      </participants>
      <p>Coccinelle is a Coq library for term rewriting. Besides the usual definitions and theorems of term algebras, term rewriting and term ordering, it also models some of the algorithms
      implemented in the CiME toolbox, such a matching, matching modulo associativity-commutativity, computation of the one-step reducts of a term, RPO comparison between two terms, etc. The RPO
      algorithm can effectively be run inside Coq, and is used in the Color developement (
      <ref xlink:href="http://color.inria.fr/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://
      <allowbreak/>color.
      <allowbreak/>inria.
      <allowbreak/>fr/
      <allowbreak/></ref>) as well as for certifying Spike implicit induction theorems in Coq (Sorin Stratulat).</p>
      <p>Coccinelle is developed by Évelyne Contejean, available at (
      <ref xlink:href="http://www.lri.fr/~contejea/Coccinelle" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://
      <allowbreak/>www.
      <allowbreak/>lri.
      <allowbreak/>fr/
      <allowbreak/>~contejea/
      <allowbreak/>Coccinelle</ref>), and is distributed under the Cecill-C license.</p>
    </subsection>
  </logiciels>
  <resultats id="uid43">
    <bodyTitle>New Results</bodyTitle>
    <subsection id="uid44" level="1">
      <bodyTitle>Models of Programming</bodyTitle>
      <simplelist>
        <li id="uid45">
          <p noindent="true">P. Herms, together with C. Marché and B. Monate (CEA List), developed a certified VC generator, using Coq. The program for VC calculus and its
          specifications are both written in Coq, but the code is crafted so that it can be extracted automatically into a stand-alone executable. It is also designed in a way that allows the use of
          arbitrary first-order theorem provers to discharge the generated obligations 
          <ref xlink:href="#proval-2011-bid59" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>. This is a first step towards a certified VC generator for C
          programs annotated with ACSL  
          <ref xlink:href="#proval-2011-bid14" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>.</p>
        </li>
        <li id="uid46">
          <p noindent="true">Until now, we only considered the proof of sequential programs. However the rely/guarantee approach give a natural way to extend deductive verification to concurrent
          programs. During his internship supervised by C. Paulin, N. Gaspar explored this idea. He formalised in Coq the axiomatic semantics of a simple concurrent language using the rely-guarranty
          approach 
          <ref xlink:href="#proval-2011-bid60" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>and proposed a translation of this language into 
          <i>Why</i>programs in order to automatically generate the proof obligations.</p>
        </li>
        <li id="uid47">
          <p noindent="true">W. Urribarrí, together with C. Paulin, proposed an extension of the 
          <i>Why</i>language with modules and functors together with a refinement calculus in order to organise large developments in a structured and abstract way. She built a prototype
          implementation of this calculus.</p>
        </li>
        <li id="uid48">
          <p noindent="true">D. Baelde, in cooperation with P. Courtieu (CNAM), D. Gross-Amblard (U. Bourgogne and Rennes), C. Paulin and X. Urbain proposed a formal proof of security for two
          watermarking algorithms. The proof uses a reduction of an arbitrary attack unmarking the data to the discovery of a secret key. It has been fully formalized in Coq using the ALEA library.
          This work has been presented at the conference TYPES 2011 and a paper is in preparation.</p>
        </li>
        <li id="uid49">
          <p noindent="true">Generating multimedia streams, such as in a netradio, is a task which is complex and difficult to adapt to every users' needs. D. Baelde, in cooperation with R. Beauxis
          (Tulane University, LA, USA) and S. Mimram (CEA List) introduce a novel approach, based on a dedicated high-level functional programming language, called Liquidsoap, for generating,
          manipulating and broadcasting multimedia streams 
          <ref xlink:href="#proval-2011-bid61" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>. Unlike traditional approaches, which are based on configuration
          files or static graphical interfaces, it also allows the user to build complex and highly customized systems. This language is based on a model for streams and contains operators and
          constructions, which make it adapted to the generation of streams. The interpreter of the language also ensures many properties concerning the good execution of the stream generation.</p>
        </li>
      </simplelist>
    </subsection>
    <subsection id="uid50" level="1">
      <bodyTitle>Proofs of Imperative Programs</bodyTitle>
      <simplelist>
        <li id="uid51">
          <p noindent="true">The Why3 reimplementation of the 
          <i>Why</i>platform, started in 2010, was publicly released in 2011 
          <ref xlink:href="#proval-2011-bid62" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>. The main developers are A. Paskevich,
          J.-C. Filliâtre, F. Bobot, and C. Marché. The language of 
          <i>Why</i>, both programming and annotation parts, was significantly extended: algebraic types, records, pattern matching, recursive logical definitions are now supported. These logical
          declarations are structured in modules (a.k.a. theories). The module language comes with an original mechanism for reusing theories in specialized contexts using partial instantiations.
          These new features have been presented at the first international workshop on intermediate verification languages (BOOGIE 2011) 
          <ref xlink:href="#proval-2011-bid63" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>and will be presented at VSTTE 2012  
          <ref xlink:href="#proval-2011-bid64" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>.</p>
        </li>
        <li id="uid52">
          <p noindent="true">A. Tafat and C. Marché used the Why3 system to perform a complete proof of the “Binary Heaps” challenge 
          <ref xlink:href="#proval-2011-bid65" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>from the VACID-0 international collection  
          <ref xlink:href="#proval-2011-bid0" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>. Solving this challenge is a case study for a general approach of
          abstract interfaces for C programs, currently under development by A. Tafat, based on initial ideas described together with S. Boulmé which were published in a 2011 in a special
          issue 
          <ref xlink:href="#proval-2011-bid66" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>.</p>
        </li>
        <li id="uid53">
          <p noindent="true">In 2011, we set up a web gallery to publicly expose the programs that we specified and proved. This is the so-called ProVal collection of verified programs, and available
          at URL 
          <ref xlink:href="http://proval.lri.fr/gallery/index.en.html" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://
          <allowbreak/>proval.
          <allowbreak/>lri.
          <allowbreak/>fr/
          <allowbreak/>gallery/
          <allowbreak/>index.
          <allowbreak/>en.
          <allowbreak/>html</ref>.</p>
        </li>
        <li id="uid54">
          <p noindent="true">K. Krishnamani and C. Marché proposed a technique for automatically generating loop invariants in C programs. It is based on the well-known predicate
          abstraction approach, which is adapted to take into account pre-existing specifications, and to proceed modularly, that is each function of a program is processed independently, with its
          own sets of predicates. The approach is also extended in order to generate universally quantified invariants 
          <ref xlink:href="#proval-2011-bid67" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>. The prototype is available as a Frama-C plugin at URL 
          <ref xlink:href="http://proval.lri.fr/agen" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://
          <allowbreak/>proval.
          <allowbreak/>lri.
          <allowbreak/>fr/
          <allowbreak/>agen</ref>.</p>
        </li>
        <li id="uid55">
          <p noindent="true">C. Dross, together with Y. Moy (Adacore) and J.-C. Filliâtre, addressed the problem of verifying programs involving 
          <i>containers</i>. Containers such as lists, vectors, sets or maps are an attractive alternative to ad-hoc data structures based on pointers. C. Dross gave a definition of containers
          whose aim is to facilitate their use in certified software, using modern proof technology and novel specification languages. Correct usage of containers and user-provided correctness
          properties can be checked either by execution during testing or by formal proof with an automatic prover. It relies on a formal semantics for containers and an axiomatization of this
          semantics targeted at automatic provers. C. Dross proved in Coq that the formal semantics is consistent and that the axiomatization thereof is correct. This work was presented at TAP
          2011 
          <ref xlink:href="#proval-2011-bid68" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>.</p>
        </li>
        <li id="uid56">
          <p noindent="true">Proving that pointer programs preserve data invariants, in a modular way, is known to be a challenge. R. Bardou and C. Marché designed a new approach based on
          advanced static typing systems (based on memory regions and permissions) to control memory updates and ownership of data 
          <ref xlink:href="#proval-2011-bid69" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>. A prototype implementation is built, called Capucine, available
          for download at 
          <ref xlink:href="http://romain.bardou.fr/capucine" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://
          <allowbreak/>romain.
          <allowbreak/>bardou.
          <allowbreak/>fr/
          <allowbreak/>capucine</ref>. To demonstrate the ability of this approach, the challenge “sparse arrays” of the VACID-0 benchmarks  
          <ref xlink:href="#proval-2011-bid0" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>has been certified 
          <ref xlink:href="#proval-2011-bid70" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>.</p>
        </li>
        <li id="uid57">
          <p noindent="true">Separation logic has shown to be an elegant way to deal with programs which use data-structures with pointers. However it requires a specific logical language, provers,
          and specific reasoning techniques. In his PhD. F. Bobot introduced a technique to express ideas from separation logic in the traditional framework of deductive verification 
          <ref xlink:href="#proval-2011-bid71" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>. He proposed to derive “separation predicates” from
          user-supplied inductive definitions. These predicates come with suitable axiomatization, including frame rules, expressed in usual first-order logic. This translation takes special care to
          ensure the best use of automated theorem provers.</p>
        </li>
      </simplelist>
    </subsection>
    <subsection id="uid58" level="1">
      <bodyTitle>Automated Deduction</bodyTitle>
      <simplelist>
        <li id="uid59">
          <p noindent="true">In his thesis 
          <ref xlink:href="#proval-2011-bid48" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>, S. Lescuyer formalized and designed purely reflexive tactics
          for automated deduction in Coq.</p>
        </li>
        <li id="uid60">
          <p noindent="true">É. Contejean, together with Pierre Courtieu, Julien Forest, Olivier Pons and Xavier Urbain (Cedric Laboratory, CNAM &amp; ENSIIE) presented the last version of the
          rewriting toolkit CiME3 at RTA 2011 
          <ref xlink:href="#proval-2011-bid47" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>. Amongst other original features, this version enjoys two kinds
          of engines: to handle and discover proofs of various properties of rewriting systems, and to generate Coq scripts from proof traces given in certification problem format in order to certify
          them with a skeptical proof assistant like Coq. Thus, these features open the way for using CiME3 to add automation to proofs of termination or confluence in a formal development in the Coq
          proof assistant.</p>
        </li>
        <li id="uid61">
          <p noindent="true">In their TACAS paper 
          <ref xlink:href="#proval-2011-bid1" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>, S. Conchon, É. Contejean and M. Iguernelala present a modular
          extension of ground AC-completion for deciding formulas in the combination of the theory of equality with user-defined AC symbols, uninterpreted symbols and an arbitrary signature disjoint
          Shostak theory X.</p>
        </li>
        <li id="uid62">
          <p noindent="true">F. Bobot and A. Paskevich studied translation from a first-order logic with polymorphic types à la ML (which is the base logic of the 
          <i>Why</i>platform and the 
          <i>Alt-Ergo</i>theorem prover) to a many-sorted or one-sorted logic implemented in mainstream automated theorem provers. They devised a three-stage scheme where the last stage eliminates
          polymorphic types while adding the necessary “annotations” to preserve soundness, and the first two stages serve to protect certain terms so that they can keep their original types and
          unannotated form. Such protection allows to make use of provers' built-in theories and operations. This work generalizes the previous study by S. Lescuyer and J.-F. Couchot 
          <ref xlink:href="#proval-2011-bid38" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>onto arbitrary monomorphic types, e.g. array types. It was
          presented at FroCoS 2011 
          <ref xlink:href="#proval-2011-bid72" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>(see also an extended version with full proofs 
          <ref xlink:href="#proval-2011-bid73" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>). These results are part of F. Bobot's PhD thesis 
          <ref xlink:href="#proval-2011-bid71" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>.</p>
        </li>
      </simplelist>
    </subsection>
    <subsection id="uid63" level="1">
      <bodyTitle>Floating-Point and Numerical Programs</bodyTitle>
      <simplelist>
        <li id="uid64">
          <p noindent="true">T. Nguyen and C. Marché have worked on how to prove floating-point programs while taking into account architecture- and compiler-dependent features such as the
          use of the x87 stack in Intel micro-processors. This is done by analyzing the assembly code generated by the compiler 
          <ref xlink:href="#proval-2011-bid74" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>, 
          <ref xlink:href="#proval-2011-bid75" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/></p>
        </li>
        <li id="uid65">
          <p noindent="true">S. Boldo and C. Marché published a survey article on the proofs of numerical C programs using both automatic provers and Coq 
          <ref xlink:href="#proval-2011-bid76" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>.</p>
        </li>
        <li id="uid66">
          <p noindent="true">S. Boldo and T. Nguyen have worked on how to prove numerical programs on multiple architectures and compilers 
          <ref xlink:href="#proval-2011-bid77" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>. More precisely, it covers all the compiler choices about the
          use of extended registers, FMA, and reorganization of additions.</p>
        </li>
        <li id="uid67">
          <p noindent="true">S. Boldo and J.-M. Muller (CNRS, Arénaire, LIP, ÉNS Lyon) have worked on new floating-point algorithms for computing the exact and approximated errors of the
          FMA (fused multiply-and-add) 
          <ref xlink:href="#proval-2011-bid78" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>.</p>
        </li>
        <li id="uid68">
          <p noindent="true">S. Boldo and G. Melquiond have developed in Coq a comprehensive formalization of floating-point arithmetic: core definitions, axiomatic and computational
          rounding operations, high-level properties 
          <ref xlink:href="#proval-2011-bid55" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>. It provides a framework for developers to formally certify
          numerical applications.</p>
        </li>
        <li id="uid69">
          <p noindent="true">G. Melquiond, in collaboration with F. de Dinechin (Arénaire, LIP, ÉNS Lyon) and C. Lauter (Intel Hillsboro), has improved the methodology for formally
          proving floating-point mathematical functions when their correctness depends on relative errors 
          <ref xlink:href="#proval-2011-bid57" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>.</p>
        </li>
        <li id="uid70">
          <p noindent="true">S. Boldo, J.-C. Filliâtre and G. Melquiond, in collaboration with F. Clément (Estime, INRIA Paris-Rocquencourt) and M. Mayero (University Paris
          13) have finished a full formal proof of a program solving a partial differential equation (the wave equation) using a finite difference scheme 
          <ref xlink:href="#proval-2011-bid79" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>. This proof includes both the mathematical convergence proof
          (method error)  
          <ref xlink:href="#proval-2011-bid80" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>, a tricky floating-point proof  
          <ref xlink:href="#proval-2011-bid81" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>and proofs of the absence of runtime errors.</p>
        </li>
        <li id="uid71">
          <p noindent="true">C. Lelay, under the supervision of S. Boldo and G. Melquiond, has worked on differentiability in Coq. The goal was to prove the existence of a solution to
          the wave equation thanks to D'Alembert's formula and to automatize the process as much as possible 
          <ref xlink:href="#proval-2011-bid82" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>
          <ref xlink:href="#proval-2011-bid83" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>.</p>
        </li>
        <li id="uid72">
          <p noindent="true">G. Melquiond, in collaboration with W. G. Nowak (Institute of Mathmatics, Austria) and P. Zimmermann (Caramel, INRIA Nancy-Lorraine), has designed new
          methods for computing guaranteed enclosures of the Masser-Gramain constant, a two-dimensional analogue of the Euler-Mascheroni constant  
          <ref xlink:href="#proval-2011-bid84" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>.</p>
        </li>
        <li id="uid73">
          <p noindent="true">G. Melquiond, in collaboration with J-M. Muller (CNRS, Arénaire, LIP, ÉNS Lyon) and E. Martin-Dorel (Arénaire, LIP, ÉNS Lyon), has worked on weakening the
          assumptions floating-point error-free transformations rely on 
          <ref xlink:href="#proval-2011-bid85" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>.</p>
        </li>
      </simplelist>
    </subsection>
  </resultats>
  <contrats id="uid74">
    <bodyTitle>Contracts and Grants with Industry</bodyTitle>
    <subsection id="uid75" level="1">
      <bodyTitle>Systematic: Hi-Lite</bodyTitle>
      <participants>
        <person key="proval-2006-idm410174325056">
          <firstname>Claude</firstname>
          <lastname>Marché</lastname>
          <moreinfo>contact</moreinfo>
        </person>
        <person key="proval-2006-idm410174303696">
          <firstname>Jean-Christophe</firstname>
          <lastname>Filliâtre</lastname>
        </person>
        <person key="proval-2006-idm410174301040">
          <firstname>Sylvain</firstname>
          <lastname>Conchon</lastname>
        </person>
        <person key="proval-2006-idm410174306336">
          <firstname>Evelyne</firstname>
          <lastname>Contejean</lastname>
        </person>
        <person key="proval-2009-idm423378947776">
          <firstname>Andrei</firstname>
          <lastname>Paskevich</lastname>
        </person>
        <person key="proval-2009-idm423378972704">
          <firstname>Alain</firstname>
          <lastname>Mebsout</lastname>
        </person>
        <person key="proval-2009-idm423378923200">
          <firstname>Mohamed</firstname>
          <lastname>Iguernelala</lastname>
        </person>
        <person key="logical-2006-idm356512372048">
          <firstname>Denis</firstname>
          <lastname>Cousineau</lastname>
        </person>
      </participants>
      <p>The Hi-Lite project (
      <ref xlink:href="http://www.open-do.org/projects/hi-lite/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://
      <allowbreak/>www.
      <allowbreak/>open-do.
      <allowbreak/>org/
      <allowbreak/>projects/
      <allowbreak/>hi-lite/
      <allowbreak/></ref>) is a project in the SYSTEMATIC Paris Region French cluster in complex systems design and management 
      <ref xlink:href="http://www.systematic-paris-region.org" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://
      <allowbreak/>www.
      <allowbreak/>systematic-paris-region.
      <allowbreak/>org</ref>.</p>
      <p>Hi-Lite is a project aiming at popularizing formal methods for the development of high-integrity software. It targets ease of adoption through a loose integration of formal proofs with
      testing and static analysis, that allows combining techniques around a common expression of specifications. Its technical focus is on modularity, that allows a divide-and-conquer approach to
      large software systems, as well as an early adoption by all programmers in the software life cycle.</p>
      <p>Our involvements in that project include the use of the Alt-Ergo prover as back-end to already existing tools for SPARK/ADA, and the design of a verification chain for an extended SPARK/ADA
      language to verification conditions, via the 
      <i>Why</i>VC generator.</p>
      <p>This project is funded by the french ministry of industry (FUI), the Île-de-France region and the Essonne general council for 36 months from September 2010.</p>
    </subsection>
    <subsection id="uid76" level="1">
      <bodyTitle>CEA-Airbus contract</bodyTitle>
      <participants>
        <person key="proval-2006-idm410174301040">
          <firstname>Sylvain</firstname>
          <lastname>Conchon</lastname>
          <moreinfo>contact</moreinfo>
        </person>
        <person key="proval-2006-idm410174306336">
          <firstname>Évelyne</firstname>
          <lastname>Contejean</lastname>
        </person>
        <person key="proval-2006-idm410174325056">
          <firstname>Claude</firstname>
          <lastname>Marché</lastname>
        </person>
      </participants>
      <p>In conjunction with the INRIA funding of ADT Alt-Ergo, a specific support contract has started in Sep 09, between INRIA, CEA Saclay and Airbus France at Toulouse. This is to support our
      efforts for the maintainance and to feature updates of Alt-Ergo, for its use at Airbus software development and certification of avionics critical code.</p>
    </subsection>
    <subsection id="uid77" level="1">
      <bodyTitle>Airbus contract</bodyTitle>
      <participants>
        <person key="proval-2006-idm410174301040">
          <firstname>Sylvain</firstname>
          <lastname>Conchon</lastname>
          <moreinfo>contact</moreinfo>
        </person>
      </participants>
      <p>This 2 years support contract has started in Sep 10, between INRIA and Airbus France at Toulouse. This is to support our efforts for the DO-178B qualification of Alt-Ergo.</p>
    </subsection>
  </contrats>
  <international id="uid78">
    <bodyTitle>Partnerships and Cooperations</bodyTitle>
    <subsection id="uid79" level="1">
      <bodyTitle>Regional Initiatives</bodyTitle>
      <subsection id="uid80" level="2">
        <bodyTitle>Hisseo</bodyTitle>
        <participants>
          <person key="proval-2006-idm410174308976">
            <firstname>Sylvie</firstname>
            <lastname>Boldo</lastname>
            <moreinfo>contact</moreinfo>
          </person>
          <person key="proval-2006-idm410174325056">
            <firstname>Claude</firstname>
            <lastname>Marché</lastname>
          </person>
          <person key="arenaire-2006-idm111960255408">
            <firstname>Guillaume</firstname>
            <lastname>Melquiond</lastname>
          </person>
          <person key="proval-2009-idm423378000896">
            <firstname>Thi-Minh-Tuyen</firstname>
            <lastname>Nguyen</lastname>
          </person>
        </participants>
        <p>Hisseo is a 3 years Digiteo project that started in September 2008. 
        <ref xlink:href="http://hisseo.saclay.inria.fr" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://
        <allowbreak/>hisseo.
        <allowbreak/>saclay.
        <allowbreak/>inria.
        <allowbreak/>fr</ref></p>
        <p>The Hisseo project focuses on the problems related to the treatment of floating-point computations in the compilation process, especially in the case of the compilation of critical C
        code.</p>
        <p>Partners: CEA List (Saclay), INRIA Paris-Rocquencourt (Team Gallium).</p>
      </subsection>
      <subsection id="uid81" level="2">
        <bodyTitle>Coquelicot</bodyTitle>
        <participants>
          <person key="proval-2006-idm410174308976">
            <firstname>Sylvie</firstname>
            <lastname>Boldo</lastname>
            <moreinfo>contact</moreinfo>
          </person>
          <person key="proval-2011-idm383373655520">
            <firstname>Catherine</firstname>
            <lastname>Lelay</lastname>
          </person>
          <person key="arenaire-2006-idm111960255408">
            <firstname>Guillaume</firstname>
            <lastname>Melquiond</lastname>
          </person>
        </participants>
        <p>Coquelicot is a 3 years Digiteo project that started in September 2011. 
        <ref xlink:href="http://coquelicot.saclay.inria.fr" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://
        <allowbreak/>coquelicot.
        <allowbreak/>saclay.
        <allowbreak/>inria.
        <allowbreak/>fr</ref>. S. Boldo is the principal investigator of this project.</p>
        <p>The Coquelicot project aims at creating a modern formalization of the real numbers in Coq, with a focus on practicality. This is sorely needed to ease the verification of numerical
        applications, especially those involving advanced mathematics.</p>
        <p>Partners: LIX (Palaiseau), University Paris 13</p>
      </subsection>
      <subsection id="uid82" level="2">
        <bodyTitle>Pactole</bodyTitle>
        <participants>
          <person key="proval-2006-idm410174306336">
            <firstname>Évelyne</firstname>
            <lastname>Contejean</lastname>
          </person>
          <person key="proval-2006-idm410174303696">
            <firstname>Jean-Christophe</firstname>
            <lastname>Filliâtre</lastname>
          </person>
          <person key="proval-2009-idm423378944592">
            <firstname>Xavier</firstname>
            <lastname>Urbain</lastname>
            <moreinfo>contact</moreinfo>
          </person>
        </participants>
        <p>Pactole is a 3 year Digiteo project which started in October 2009.</p>
        <p>The Pactole project focuses on automation and formal verification for ubiquitous, large scale environments. Tasks include proof automation techniques for distributed systems, verification
        conditions for fault tolerant distributed systems, specification and design of fundamental services for mobile sensor networks. The principal investigator of Pactole is Xavier Urbain.</p>
        <p>Partners: CÉDRIC (CNAM/ENSIIE), LIP6 (UPMC).</p>
      </subsection>
    </subsection>
    <subsection id="uid83" level="1">
      <bodyTitle>National initiatives</bodyTitle>
      <subsection id="uid84" level="2">
        <bodyTitle>U3CAT</bodyTitle>
        <participants>
          <person key="proval-2006-idm410174303696">
            <firstname>Jean-Christophe</firstname>
            <lastname>Filliâtre</lastname>
          </person>
          <person key="proval-2006-idm410174325056">
            <firstname>Claude</firstname>
            <lastname>Marché</lastname>
            <moreinfo>contact</moreinfo>
          </person>
          <person key="arenaire-2006-idm111960255408">
            <firstname>Guillaume</firstname>
            <lastname>Melquiond</lastname>
          </person>
          <person key="PASUSERID">
            <firstname>Kalyan</firstname>
            <lastname>Krishnamani</lastname>
          </person>
          <person key="PASUSERID">
            <firstname>Asma</firstname>
            <lastname>Tafat</lastname>
          </person>
          <person key="gallium-2009-idm362141100192">
            <firstname>Paolo</firstname>
            <lastname>Herms</lastname>
          </person>
        </participants>
        <p>U3CAT (Unification of Critical C Code Analysis Techniques) is a project funded by ANR within its programme “Systèmes Embarqués et Grandes Infrastructures - ARPEGE”. It aims at verification
        techniques of C programs, and is partly a follow-up of the former CAT project. It started in January 2009 and will end in 2012.</p>
        <p>The main goal of the project is to integrate various analysis techniques in a single framework, and make them cooperate in a sound way. We address the following general issues:</p>
        <simplelist>
          <li id="uid85">
            <p noindent="true">Verification techniques for floating-point programs;</p>
          </li>
          <li id="uid86">
            <p noindent="true">Specification and verification of dynamic or temporal properties;</p>
          </li>
          <li id="uid87">
            <p noindent="true">Combination of static analysis techniques;</p>
          </li>
          <li id="uid88">
            <p noindent="true">Management of verification sessions and activities;</p>
          </li>
          <li id="uid89">
            <p noindent="true">Certification of the tools chains for compilation and for verification.</p>
          </li>
        </simplelist>
        <p>Partners: CEA-List (Saclay, project leader), Lande team (INRIA Rennes), Gallium team (INRIA Rocquencourt), Dassault Aviation (Saint-Cloud), Airbus France (Toulouse), ATOS Origin
        (Toulouse), CNAM Cedric laboratory (Evry), CS Communication &amp; Systems (Toulouse), Hispano-Suiza/Safran (Moissy-Cramayel).</p>
      </subsection>
      <subsection id="uid90" level="2">
        <bodyTitle>INRIA ADT Alt-Ergo</bodyTitle>
        <participants>
          <person key="proval-2006-idm410174301040">
            <firstname>Sylvain</firstname>
            <lastname>Conchon</lastname>
            <moreinfo>contact</moreinfo>
          </person>
          <person key="proval-2006-idm410174306336">
            <firstname>Evelyne</firstname>
            <lastname>Contejean</lastname>
          </person>
          <person key="proval-2006-idm410174325056">
            <firstname>Claude</firstname>
            <lastname>Marché</lastname>
          </person>
          <person key="proval-2009-idm423378972704">
            <firstname>Alain</firstname>
            <lastname>Mebsout</lastname>
          </person>
          <person key="proval-2009-idm423378923200">
            <firstname>Mohamed</firstname>
            <lastname>Iguernelala</lastname>
          </person>
        </participants>
        <p>The 
        <i>ADT</i>(Action de Développement Technologique) Alt-Ergo is a 2-years project funded by INRIA, started in September 2009.</p>
        <p>The goal is the maturation of the Alt-Ergo prover towards its use in an industrial context in particular for avionics. The expected outcomes of this ADT are the following:</p>
        <simplelist>
          <li id="uid91">
            <p noindent="true">improving the efficiency of Alt-Ergo;</p>
          </li>
          <li id="uid92">
            <p noindent="true">fine tuning of Alt-Ergo for the SMT competition;</p>
          </li>
          <li id="uid93">
            <p noindent="true">generation of counter-examples;</p>
          </li>
          <li id="uid94">
            <p noindent="true">the qualification of Alt-Ergo for the norm DO-178B.</p>
          </li>
        </simplelist>
        <p>External Collaborators: Airbus France (Toulouse), Dassault Aviation (Saint-Cloud), team Typical (INRIA, École Polytechnique).</p>
      </subsection>
      <subsection id="uid95" level="2">
        <bodyTitle>FOST</bodyTitle>
        <participants>
          <person key="proval-2006-idm410174308976">
            <firstname>Sylvie</firstname>
            <lastname>Boldo</lastname>
            <moreinfo>contact</moreinfo>
          </person>
          <person key="proval-2006-idm410174303696">
            <firstname>Jean-Christophe</firstname>
            <lastname>Filliâtre</lastname>
          </person>
          <person key="arenaire-2006-idm111960255408">
            <firstname>Guillaume</firstname>
            <lastname>Melquiond</lastname>
          </person>
        </participants>
        <p>FOST (Formal prOofs of Scientific compuTation programs) is a 3 years ANR “Blanc” project started in January 2009. S. Boldo is the principal investigator of this project. 
        <ref xlink:href="http://fost.saclay.inria.fr" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://
        <allowbreak/>fost.
        <allowbreak/>saclay.
        <allowbreak/>inria.
        <allowbreak/>fr</ref></p>
        <p>The FOST project follows CerPAN's footprints as it aims at developing new methods to bound the global error of a numerical program. These methods will be very generic in order to prove a
        large range of numerical analysis programs. Moreover, FOST aims at providing reusable methods that are understandable by non-specialists of formal methods.</p>
        <p>Partners: University Paris 13, INRIA Paris - Rocquencourt (Estime).</p>
      </subsection>
      <subsection id="uid96" level="2">
        <bodyTitle>SCALP</bodyTitle>
        <participants>
          <person key="proval-2008-idm220575009344">
            <firstname>Christine</firstname>
            <lastname>Paulin-Mohring</lastname>
            <moreinfo>contact</moreinfo>
          </person>
          <person key="parsifal-2006-idm465379746128">
            <firstname>David</firstname>
            <lastname>Baelde</lastname>
          </person>
          <person key="proval-2009-idm423378944592">
            <firstname>Xavier</firstname>
            <lastname>Urbain</lastname>
          </person>
        </participants>
        <p>This project is funded by ANR (program SESUR). 
        <ref xlink:href="http://scalp.gforge.inria.fr/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://
        <allowbreak/>scalp.
        <allowbreak/>gforge.
        <allowbreak/>inria.
        <allowbreak/>fr/
        <allowbreak/></ref></p>
        <p>It started on january 2008 for 4 years; the coordinator is Yassine Lakhnech from VERIMAG.</p>
        <p>The SCALP project (Security of Cryptographic Algorithms with Probabilities) aims at developing automated tools for the verification of cryptographic systems.</p>
        <p>Partners: Verimag, INRIA Sophia-Antipolis(Everest then Marelle team), ENS Lyon, LRI, CNAM.</p>
      </subsection>
      <subsection id="uid97" level="2">
        <bodyTitle>DECERT</bodyTitle>
        <participants>
          <person key="proval-2006-idm410174301040">
            <firstname>Sylvain</firstname>
            <lastname>Conchon</lastname>
          </person>
          <person key="proval-2006-idm410174306336">
            <firstname>Évelyne</firstname>
            <lastname>Contejean</lastname>
          </person>
          <person key="proval-2006-idm410173274400">
            <firstname>Stéphane</firstname>
            <lastname>Lescuyer</lastname>
          </person>
        </participants>
        <p>DECERT (DEduction and CERTification) is an ANR “Domaines Emergents” project. It started on January 2009 for 3 years; the coordinator is Thomas Jensen from the Lande team of IRISA/INRIA
        Rennes.</p>
        <p>The goal of the project DECERT is to design and implement new efficient cooperating decision procedures (in particular for fragments of arithmetics), to standardize output interfaces based
        on certificates proof objects and to integrate SMT provers with skeptical proof assistants and larger verification contexts such as the Rodin tool for B and the Frama-C/Jessie tool chain for
        verifying C programs.</p>
        <p>The partners are: CEA List, LORIA/INRIA Nancy - Grand Est, IRISA/INRIA Rennes - Bretagne Atlantique, INRIA Sophia Antipolis - Méditerranée, Systerel</p>
      </subsection>
    </subsection>
    <subsection id="uid98" level="1">
      <bodyTitle>European Initiatives</bodyTitle>
      <subsection id="uid99" level="2">
        <bodyTitle>Collaborations in European Programs, except FP7</bodyTitle>
        <subsection id="uid100" level="3">
          <bodyTitle>FoVeOOS</bodyTitle>
          <participants>
            <person key="proval-2006-idm410174325056">
              <firstname>Claude</firstname>
              <lastname>Marché</lastname>
              <moreinfo>contact</moreinfo>
            </person>
            <person key="proval-2007-idm172231421920">
              <firstname>Romain</firstname>
              <lastname>Bardou</lastname>
            </person>
            <person key="proval-2008-idm220574959120">
              <firstname>François</firstname>
              <lastname>Bobot</lastname>
            </person>
            <person key="PASUSERID">
              <firstname>Asma</firstname>
              <lastname>Tafat</lastname>
            </person>
          </participants>
          <sanspuceslist>
            <li id="uid101">
              <p noindent="true">Program: COST (European Cooperation in the field of Scientific and Technical Research, 
              <ref xlink:href="http://www.cost.esf.org/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://
              <allowbreak/>www.
              <allowbreak/>cost.
              <allowbreak/>esf.
              <allowbreak/>org/
              <allowbreak/></ref>)</p>
            </li>
            <li id="uid102">
              <p noindent="true">Project acronym: FoVeOOS (IC-0701, 
              <ref xlink:href="http://www.cost-ic0701.org/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://
              <allowbreak/>www.
              <allowbreak/>cost-ic0701.
              <allowbreak/>org/
              <allowbreak/></ref>)</p>
            </li>
            <li id="uid103">
              <p noindent="true">Project title: Formal Verification of Object-Oriented Software</p>
            </li>
            <li id="uid104">
              <p noindent="true">Duration: May 2008 - April 2012</p>
            </li>
            <li id="uid105">
              <p noindent="true">Coordinator: B. Beckert, University Karlsruhe, Germany</p>
            </li>
            <li id="uid106">
              <p noindent="true">Other partners: 40 academic groups among 18 countries in Belgium, Denmark, Estonia, France, Germany, Ireland, Israel, Italy, The Netherlands, New Zealand, Norway,
              Poland, Portugal, Romania, Spain, Sweden, Switzerland and United Kingdom.</p>
            </li>
            <li id="uid107">
              <p noindent="true">Abstract: The aim of this action is to develop verification technology with the reach and power to assure dependability of object-oriented programs on industrial
              scale.</p>
            </li>
          </sanspuceslist>
        </subsection>
      </subsection>
    </subsection>
    <subsection id="uid108" level="1">
      <bodyTitle>International Initiatives</bodyTitle>
      <subsection id="uid109" level="2">
        <bodyTitle>Visits of International Scientists</bodyTitle>
        <simplelist>
          <li id="uid110">
            <p noindent="true">D. Ishii (National Institute of Informatics, Japan) visited the team for 8 months to work on applying program verification methods to hybrid systems.</p>
          </li>
        </simplelist>
      </subsection>
      <subsection id="uid111" level="2">
        <bodyTitle>Supervision of Post-docs and Internships</bodyTitle>
        <simplelist>
          <li id="uid112">
            <p noindent="true">S. Boldo supervised the 6-month post-doc intern of E. Makarov (from University of Vermont, USA) about numerical analysis proofs in higher dimensions.</p>
          </li>
          <li id="uid113">
            <p noindent="true">C. Marché supervised the post-doc intern of K. Krishnamani (from University of Trento, Italy) until August: predicate abstraction techniques for critical C
            programs (
            <ref xlink:href="#proval-2011-bid67" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>
            <ref xlink:href="http://proval.lri.fr/agen" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://
            <allowbreak/>proval.
            <allowbreak/>lri.
            <allowbreak/>fr/
            <allowbreak/>agen</ref>).</p>
          </li>
          <li id="uid114">
            <p noindent="true">S. Conchon and G. Melquiond supervise the post-doc intern of Cody Roux since May 2011: integration of the Gappa theorem prover in the Alt-Ergo SMT solver.</p>
          </li>
          <li id="uid115">
            <p noindent="true">S. Conchon supervises the post-doc intern of D. Cousineau since October 2011: interpretation of Alt-Ergo's proof traces in the Coq proof assistant.</p>
          </li>
          <li id="uid116">
            <p noindent="true">C. Paulin supervised the internship of N. Gaspar (Universidade da Beira Interior, Portugal) from January to September 2011. He studied the formal proof of concurrent
            programs using a rely-guarantee approach.</p>
          </li>
          <li id="uid117">
            <p noindent="true">E. Contejean, together with V. Benzaken (LRI), supervise the internship of S. Yuan (Zhejiang University, China) from October 2011 to March 2012: Automated constraints
            verification for databases with SMT solvers.</p>
          </li>
        </simplelist>
      </subsection>
      <subsection id="uid118" level="2">
        <bodyTitle>Participation In International Programs</bodyTitle>
        <p>C. Paulin is the representative of Univ. Paris-Sud for the education part of the EIT KIC ICT Labs. She contributed to the proposition of two master programs as well as the action on
        weaving Innovation and Entrepreneurship in Doctoral programs and the preparation of the SummerSchool “Imagine the future in ICT”.</p>
      </subsection>
    </subsection>
  </international>
  <diffusion id="uid119">
    <bodyTitle>Dissemination</bodyTitle>
    <subsection id="uid120" level="1">
      <bodyTitle>Animation of the scientific community</bodyTitle>
      <subsection id="uid121" level="2">
        <bodyTitle>Event organization</bodyTitle>
        <simplelist>
          <li id="uid122">
            <p noindent="true">At the VSTTE 2010 conference was organized a first and informal program verification competition (
            <ref xlink:href="http://www.macs.hw.ac.uk/vstte10/Competition.html" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://
            <allowbreak/>www.
            <allowbreak/>macs.
            <allowbreak/>hw.
            <allowbreak/>ac.
            <allowbreak/>uk/
            <allowbreak/>vstte10/
            <allowbreak/>Competition.
            <allowbreak/>html</ref>), as a prelude to more formal competitions in the future. It lasted for 2 hours, and participants had to submit solutions to five simple verification problems.
            There were 11 participants, and most of them solved only 2 problems.</p>
            <p>On behalf of the VSTTE 2012 conference (Philadelphia, USA, January 2012), A. Paskevich and J.-C. Filliâtre organized the first formal VSTTE program verification competition (
            <ref xlink:href="https://sites.google.com/site/vstte2012/compet" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://
            <allowbreak/>sites.
            <allowbreak/>google.
            <allowbreak/>com/
            <allowbreak/>site/
            <allowbreak/>vstte2012/
            <allowbreak/>compet</ref>). This time it lasted for 48 hours, from November 8 to November 10. A set of five verification problems was proposed to the participants. The problems to solve
            were significantly harder than those of 2010. Each problem consisted of an algorithm given in pseudocode, together with a set of properties to be mechanically proved. A total of 29 teams
            (79 participants) sent solutions, which is considered an excellent success. These solutions are currently under examination. Results will be announced at the conference.</p>
          </li>
        </simplelist>
      </subsection>
      <subsection id="uid123" level="2">
        <bodyTitle>Editorial boards</bodyTitle>
        <simplelist>
          <li id="uid124">
            <p noindent="true">S. Boldo is member of the editorial committee of the popular science web site 
            <i>interstices</i>, 
            <ref xlink:href="http://interstices.info/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://
            <allowbreak/>interstices.
            <allowbreak/>info/
            <allowbreak/></ref>.</p>
          </li>
          <li id="uid125">
            <p noindent="true">J.-C. Filliâtre is member of the editorial board of the 
            <i>Journal of Functional Programming</i>.</p>
          </li>
          <li id="uid126">
            <p noindent="true">C. Marché co-edited with B. Beckert a special issue of Elsevier Lectures Notes in Computer Science devoted to selected papers of the conference FoVeOOS'10 
            <ref xlink:href="#proval-2011-bid86" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>.</p>
          </li>
          <li id="uid127">
            <p noindent="true">C. Paulin is member of the editorial board of the 
            <i>Journal of Formalized Reasoning</i>.</p>
          </li>
          <li id="uid128">
            <p noindent="true">J.-C. Filliâtre edited a special issue of Software Tools for Technology Transfer devoted to selected papers of the workshop VSTTE 2009. This includes an
            introduction paper on deductive software verification 
            <ref xlink:href="#proval-2011-bid87" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>.</p>
          </li>
        </simplelist>
      </subsection>
      <subsection id="uid129" level="2">
        <bodyTitle>Learned societies</bodyTitle>
        <simplelist>
          <li id="uid130">
            <p noindent="true">J.-C. Filliâtre is a member of IFIP Working Group 1.9/2.15 (Verified Software)</p>
          </li>
        </simplelist>
      </subsection>
      <subsection id="uid131" level="2">
        <bodyTitle>Program committees</bodyTitle>
        <simplelist>
          <li id="uid132">
            <p noindent="true">S. Conchon, program chair of the Journées Francophones des Langages Applicatifs (JFLA 2011), La Bresse, France, January 2011.</p>
          </li>
          <li id="uid133">
            <p noindent="true">S. Boldo, member of the program committee of JFLA 2011, and the Fourth International Workshop on Numerical Software Verification (NSV 2011, affiliated to CAV).</p>
          </li>
          <li id="uid134">
            <p noindent="true">D. Baelde, G. Melquiond, members of the program committee of JFLA 2012.</p>
          </li>
          <li id="uid135">
            <p noindent="true">É. Contejean is a member of program committees of the ACM SIGPLAN 2011 Workshop on Partial Evaluation and Program Manipulation (PEPM 2011, co-located with POPL, Austin,
            Texas), the International Workshop on Proof Search in Axiomatic Theories and Type Theories (PSATTT 20011, affiliated to CADE, Wroclaw, Poland).</p>
          </li>
          <li id="uid136">
            <p noindent="true">C. Marché, member of program committees of the 2nd International Conference on Formal Verification of Object-Oriented Software (FoVeOOS 2011, Turin, Italy), the 23rd
            International Conference on Automated Deduction (CADE 2011, Wroclaw, Poland), and the the first International Workshop on Intermediate Verification Languages (BOOGIE 2011, affiliated to
            CADE).</p>
          </li>
          <li id="uid137">
            <p noindent="true">C. Paulin, member of the program committee of the second and third conference on Interactive Theorem Proving (ITP 2011 &amp; 2012), and the Fifth ACM SIGPLAN Workshop
            on Programming Languages meets Program Verification (PLPV 2011), affiliated to POPL.</p>
          </li>
          <li id="uid138">
            <p noindent="true">J.-C. Filliâtre, member of the program committee of the second conference on Interactive Theorem Proving (ITP 2011), the workshop “Analyze to Compile, Compile to
            Analyze” (ACCA 2011), and the conference Verified Software: Theories, Tools and Experiments (VSTTE 2012).</p>
          </li>
        </simplelist>
      </subsection>
      <subsection id="uid139" level="2">
        <bodyTitle>Participation to Thesis Committees</bodyTitle>
        <simplelist>
          <li id="uid140">
            <p noindent="true">C. Marché: president of PhD committee of Diego Caminha Barbosa de Oliveira (University Nancy 2, March 14th, 2011)</p>
          </li>
          <li id="uid141">
            <p noindent="true">C. Marché: reviewer, PhD of Beatriz Alarcón (University of Valencia, Spain, May 26th, 2011)</p>
          </li>
          <li id="uid142">
            <p noindent="true">C. Marché: reviewer, PhD of Mauricio Alba Castro (University of Valencia, Spain, Nov 25th, 2011)</p>
          </li>
          <li id="uid143">
            <p noindent="true">C. Marché: reviewer, PhD of Séverine Maingaud (University Paris 7, Dec 13th, 2011)</p>
          </li>
          <li id="uid144">
            <p noindent="true">C. Paulin: examinator, PhD of Mathias Krieger (University Paris-Sud 11, Dec 9th, 2011)</p>
          </li>
        </simplelist>
      </subsection>
      <subsection id="uid145" level="2">
        <bodyTitle>Invited Presentations</bodyTitle>
        <simplelist>
          <li id="uid146">
            <p noindent="true">S. Boldo, “Contours de la communauté”, invited talk at the 
            <i>4es Rencontres Arithmétique de l'Informatique Mathématique</i>(RAIM'11) in Perpignan. (Collected data about the outline of the computer arithmetic community in France: sites, themes,
            fundings...).</p>
          </li>
          <li id="uid147">
            <p noindent="true">J.-C. Filliâtre, “Memo Tables”, invited at the IFIP Working Group 2.8 
            <i>Functional Programming</i>(Marble Falls, Texas, USA, March 7–11, 2011).</p>
          </li>
          <li id="uid148">
            <p noindent="true">P. Herms, “Certification of a Verification Condition Generator in Coq”, seminar of the Gallium-Moscova teams, Rocquencourt, June 20th.</p>
          </li>
          <li id="uid149">
            <p noindent="true">C. Marché, “Verifying Behavioral Specifications of Programs: the Why Approach”, seminar of the ELP team, Departamento de Sistemas Informáticos y Computación,
            Universidad Politécnica de Valencia, Spain, March 25th.</p>
          </li>
          <li id="uid150">
            <p noindent="true">T. Nguyen, “Hardware-independent proofs of numerical programs ”, seminar of the Arenaire team, Lyon, January 20th.</p>
          </li>
          <li id="uid151">
            <p noindent="true">C. Paulin, “About Inductive-Recursive Definitions in Coq”, invited speaker at the workshop on Proofs and Programs, Gothenburg, Sweden, Oct. 22th.</p>
          </li>
        </simplelist>
      </subsection>
    </subsection>
    <subsection id="uid152" level="1">
      <bodyTitle>Interaction with the scientific community</bodyTitle>
      <subsection id="uid153" level="2">
        <bodyTitle>Prizes and distinctions</bodyTitle>
        <simplelist>
          <li id="uid154">
            <p noindent="true">S. Conchon, E. Contejean and M. Iguernelala got the award 2011 of the European Association for Theoretical Computer Science 
            <ref xlink:href="http://www.eatcs.org/index.php/best-etaps-paper" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://
            <allowbreak/>www.
            <allowbreak/>eatcs.
            <allowbreak/>org/
            <allowbreak/>index.
            <allowbreak/>php/
            <allowbreak/>best-etaps-paper</ref>for the best theoretical paper of all ETAPS Conferences 
            <ref xlink:href="#proval-2011-bid1" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>.</p>
          </li>
          <li id="uid155">
            <p noindent="true">C. Paulin received an honorary doctorate from the University of Gothenburg in Sweden on October 21, 2011.</p>
          </li>
        </simplelist>
      </subsection>
      <subsection id="uid156" level="2">
        <bodyTitle>Collective responsibilities within INRIA</bodyTitle>
        <simplelist>
          <li id="uid157">
            <p noindent="true">S. Boldo, elected member of the Inria Evaluation Committee.</p>
          </li>
          <li id="uid158">
            <p noindent="true">S. Boldo, member of the CLHS ,
            <i>comité local hygiène et sécurité</i>and member of the CLFP, 
            <i>comité local de formation permanente</i>.</p>
          </li>
          <li id="uid159">
            <p noindent="true">S. Boldo, member of the committee for the monitoring of PhD students (
            <i>commission de suivi des doctorants</i>).</p>
          </li>
          <li id="uid160">
            <p noindent="true">S. Boldo, member of the MECSI group for networking about computer science popularization inside INRIA.</p>
          </li>
          <li id="uid161">
            <p noindent="true">C. Paulin participates to the board of INRIA Saclay - Île-de-France Comité des Projets (assembly of Team leaders).</p>
          </li>
          <li id="uid162">
            <p noindent="true">C. Paulin is a member of the “Commission Scientifique” (in charge of selecting PhD students, post-doc, invited researchers funded by INRIA Saclay -
            Île-de-France).</p>
          </li>
        </simplelist>
      </subsection>
      <subsection id="uid163" level="2">
        <bodyTitle>Collective responsibilities outside INRIA</bodyTitle>
        <simplelist>
          <li id="uid164">
            <p noindent="true">E. Contejean and C. Marché, nominated members of the 
            <i>“conseil du laboratoire”</i>of LRI since April 2010.</p>
          </li>
          <li id="uid165">
            <p noindent="true">C. Marché, French National Coordinator for the COST action “Formal Verification of Object-Oriented Programs” (2008-2012).</p>
          </li>
          <li id="uid166">
            <p noindent="true">C. Marché (since April 2007) and C. Paulin (since Sep. 2010) , members of the program committee of Digiteo Labs, the world-class research park in 
            <i>Île-de-France</i>region dedicated to information and communication science and technology, 
            <ref xlink:href="http://www.digiteo.fr/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://
            <allowbreak/>www.
            <allowbreak/>digiteo.
            <allowbreak/>fr/
            <allowbreak/></ref>.</p>
          </li>
          <li id="uid167">
            <p noindent="true">C. Marché, member of the selection committee of the “DIM Logiciels et Systèmes Complexes”, providing grants to research projects, funded by 
            <i>Île-de-France</i>regional council and Digiteo cluster, 
            <ref xlink:href="http://www.dimlsc.fr/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://
            <allowbreak/>www.
            <allowbreak/>dimlsc.
            <allowbreak/>fr/
            <allowbreak/></ref>.</p>
          </li>
          <li id="uid168">
            <p noindent="true">G. Melquiond, elected officer of the IEEE-1788 standardization committee on interval arithmetic since 2008.</p>
          </li>
          <li id="uid169">
            <p noindent="true">G. Melquiond, C. Paulin, members of the 
            <i>“commission consultative de spécialistes de l'université”</i>, Section 27, University Paris-Sud since April 2010.</p>
          </li>
          <li id="uid170">
            <p noindent="true">G. Melquiond is an examiner for the computer science entrance exam to École Normale Supérieure since 2010.</p>
          </li>
          <li id="uid171">
            <p noindent="true">C. Paulin, director of the Graduate school in Computer Science at University Paris Sud 
            <ref xlink:href="http://edips.lri.fr/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://
            <allowbreak/>edips.
            <allowbreak/>lri.
            <allowbreak/>fr/
            <allowbreak/></ref>.</p>
          </li>
          <li id="uid172">
            <p noindent="true">C. Paulin is deputy director of the LRI.</p>
          </li>
          <li id="uid173">
            <p noindent="true">C. Paulin was the president of an hiring committee for a professor position at University Paris-Sud. She participated to two hiring commitees (professor position at
            ENSEEIHT Toulouse and assistant professor for the PPS laboratory at University Paris Diderot)</p>
          </li>
          <li id="uid174">
            <p noindent="true">C. Paulin participated to the review panels for the German Excellence Initiative proposals for Graduate Schools in informatics.</p>
          </li>
          <li id="uid175">
            <p noindent="true">J.-C. Filliâtre is 
            <i>correcteur au concours d'entrée à l'École Polytechnique</i>(computer science examiner for the entrance exam at École Polytechnique) since 2008.</p>
          </li>
          <li id="uid176">
            <p noindent="true">X. Urbain, hiring committee for an assistant professor position at École Centrale, Paris (Spring 2011).</p>
          </li>
          <li id="uid177">
            <p noindent="true">X. Urbain is an elected member of the board (
            <i>“conseil d'administration”</i>) of École Nationale Supérieure d'Informatique pour l'Industrie et l'Entreprise (ENSIIE). Since July he is head of the teaching departement of ENSIIE.</p>
          </li>
        </simplelist>
      </subsection>
    </subsection>
    <subsection id="uid178" level="1">
      <bodyTitle>Industrial Dissemination</bodyTitle>
      <simplelist>
        <li id="uid179">
          <p noindent="true">Alt-Ergo is now used in the Spark Pro toolset, developed by Altran-Praxis, for the engineering of high-assurance software. Alt-Ergo can be used by customers as an
          alternate prover for automatically proving verification conditions.</p>
        </li>
        <li id="uid180">
          <p noindent="true">As part of the qualification process of Alt-Ergo with Airbus industry (DO-178B), the technical documents (functional specifications and benchmark suite) have been
          accepted by Airbus. These documents will be submitted by Airbus to the certification authorities in 2012.</p>
        </li>
        <li id="uid181">
          <p noindent="true">S. Conchon has started a collaboration with S. Krstic and A. Goel (Intel Strategic Cad Labs in Hillsboro, OR, USA) that aims in the development of an
          SMT-based model checker. With A. Mebsout and F. Zaidi (ForTesSe, LRI), they implement the Cubicle model checker which uses the Alt-Ergo theorem prover to discharge its proof
          obligations.</p>
        </li>
        <li id="uid182">
          <p noindent="true">The Adacore company (Paris) implements a new tool GnatProve which aims at formal verification of Ada programs. They translate annotated Ada code into the 
          <i>Why</i>3 intermediate language and then use the 
          <i>Why</i>3 system to generate proof obligations and discharge them with available back-end provers.</p>
        </li>
        <li id="uid183">
          <p noindent="true">J.-C. Filliâtre and C. Marché have started a collaboration with D. Mentré at Mitsubishi Electric R&amp;D Centre Europe (Rennes), about the use of the 
          <i>Why</i>3 environment and its back-end provers as an alternative to the built-in prover of Atelier B.</p>
        </li>
      </simplelist>
    </subsection>
    <subsection id="uid184" level="1">
      <bodyTitle>Popularization</bodyTitle>
      <p>Since April 2008, S. Boldo is member of the editorial committee of the popular science web site )i(: 
      <ref xlink:href="http://interstices.info/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://
      <allowbreak/>interstices.
      <allowbreak/>info/
      <allowbreak/></ref>.</p>
      <p>Since July 2009, S. Boldo is elected member of the board of the Animath association that promotes mathematics among young people.</p>
      <p>S. Boldo, in collaboration with T. Viéville (INRIA Nancy Grand-Est) wrote two chapters of the book “Introduction à la science informatique”, edited by G. Dowek 
      <ref xlink:href="#proval-2011-bid88" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>, 
      <ref xlink:href="#proval-2011-bid89" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>. This book aims at helping the secondary school teachers for the
      incoming computer science teaching.</p>
    </subsection>
    <subsection id="uid185" level="1">
      <bodyTitle>Teaching</bodyTitle>
      <sanspuceslist>
        <li id="uid186">
          <p noindent="true">Licence (DUT): “Programmation Java” (L2), “Projet professionnel et Personnel” (L1), “Architecture” (L1), “Bases de données” (L2), A. Tafat (64h, “moniteur”
          position), Université Paris-Sud (IUT d'Orsay), France</p>
        </li>
        <li id="uid187">
          <p noindent="true">Licence (DUT): “Systèmes d'exploitation” (L1), “Architecture des ordinateurs” (L1), M. Iguernelala (64h, “moniteur” position), Université Paris-Sud (IUT d'Orsay),
          France</p>
        </li>
        <li id="uid188">
          <p noindent="true">Licence (DUT): “Systèmes d'exploitation” (L1 and L2), “Réseaux” (L2), A. Paskevich (156h), Université Paris-Sud (IUT d'Orsay), France</p>
        </li>
        <li id="uid189">
          <p noindent="true">Licence : “Mathématiques pour l'Informatique” (L2), C. Paulin (50h), D. Baelde (20h), Université Paris-Sud, France</p>
        </li>
        <li id="uid190">
          <p noindent="true">Licence professionnelle: “Programmation concurrente” (L3), A. Paskevich (36h), Université Paris-Sud (IUT d'Orsay), France</p>
        </li>
        <li id="uid191">
          <p noindent="true">Licence: “Langages de programmation et compilation” (L3), J.-C. Filliâtre (24h), École Normale Supérieure, France</p>
        </li>
        <li id="uid192">
          <p noindent="true">Licence: “INF421” (L3) et “INF431” (L3), J.-C. Filliâtre (70h), École Polytechnique, France</p>
        </li>
        <li id="uid193">
          <p noindent="true">Licence: “Programmation fonctionnelle” (L3), S. Conchon (50h), Université Paris-Sud, France</p>
        </li>
        <li id="uid194">
          <p noindent="true">Licence: “Programmation fonctionnelle” (L3), “Projet de programmation” (L3), F. Bobot (64h, “moniteur” position), Université Paris-Sud, France</p>
        </li>
        <li id="uid195">
          <p noindent="true">Master: “Compilation” (M1), C. Paulin (50h), D. Baelde (28h), Université Paris-Sud, France</p>
        </li>
        <li id="uid196">
          <p noindent="true">Master: “Projet de compilation” (M1), R. .Bardou (64h, “moniteur” position), Université Paris-Sud, France</p>
        </li>
        <li id="uid197">
          <p noindent="true">Master Parisien de Recherche en Informatique (MPRI) 
          <ref xlink:href="http://mpri.master.univ-paris7.fr/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://
          <allowbreak/>mpri.
          <allowbreak/>master.
          <allowbreak/>univ-paris7.
          <allowbreak/>fr/
          <allowbreak/></ref>: “Proof assistants” (M2), G. Melquiond (9h), C. Paulin (6h), Université Paris 7, France</p>
        </li>
        <li id="uid198">
          <p noindent="true">Master Parisien de Recherche en Informatique (MPRI) 
          <ref xlink:href="http://mpri.master.univ-paris7.fr/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://
          <allowbreak/>mpri.
          <allowbreak/>master.
          <allowbreak/>univ-paris7.
          <allowbreak/>fr/
          <allowbreak/></ref>: “Automated deduction” (M2), É. Contejean (12h), X. Urbain (12h), Université Paris 7, France</p>
        </li>
        <li id="uid199">
          <p noindent="true">Master Parisien de Recherche en Informatique (MPRI) 
          <ref xlink:href="http://mpri.master.univ-paris7.fr/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://
          <allowbreak/>mpri.
          <allowbreak/>master.
          <allowbreak/>univ-paris7.
          <allowbreak/>fr/
          <allowbreak/></ref>: “Foundations of proof system” (M2), S. Boldo (2h), Université Paris 7, France</p>
        </li>
        <li id="uid200">
          <p noindent="true">8th LASER Summer School on Software Engineering 
          <ref xlink:href="http://laser.inf.ethz.ch/2011/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://
          <allowbreak/>laser.
          <allowbreak/>inf.
          <allowbreak/>ethz.
          <allowbreak/>ch/
          <allowbreak/>2011/
          <allowbreak/></ref>: “Tools for Practical Software Verification”, C. Paulin (4h)</p>
        </li>
      </sanspuceslist>
      <p>Supervision of internships</p>
      <sanspuceslist>
        <li id="uid201">
          <p noindent="true">S. Boldo and G. Melquiond supervised the internship of C. Lelay about differentiability in Coq 
          <ref xlink:href="#proval-2011-bid82" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>(Master Logique Mathématique et Fondements de l'Informatique,
          Univ. Paris Diderot).</p>
        </li>
      </sanspuceslist>
      <p>PhD &amp; HdR:</p>
      <sanspuceslist>
        <li id="uid202">
          <p noindent="true">HDR: J.-C. Filliâtre, Deductive Program Verification 
          <ref xlink:href="#proval-2011-bid90" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>, Université Paris-Sud, Dec. 2nd 2011</p>
        </li>
        <li id="uid203">
          <p noindent="true">PhD: S. Lescuyer, Formalizing and Implementing a Reflexive Tactic for Automated Deduction in Coq 
          <ref xlink:href="#proval-2011-bid48" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>, Université Paris-Sud, Jan. 4th 2011, S. Conchon and É.
          Contejean</p>
        </li>
        <li id="uid204">
          <p noindent="true">PhD: R. Bardou, Verification of Pointer Programs Using Regions and Permissions 
          <ref xlink:href="#proval-2011-bid69" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>, Université Paris-Sud, Oct. 14th 2011, C. Marché</p>
        </li>
        <li id="uid205">
          <p noindent="true">PhD: F. Bobot, Logique de séparation et vérification déductive 
          <ref xlink:href="#proval-2011-bid71" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>, Université Paris-Sud, Dec. 12 2011, J.-C. Filliâtre</p>
        </li>
        <li id="uid206">
          <p noindent="true">PhD in progress: T. Nguyen, Formal Proof of Numerical Programs with respect to Architecture and Compiler, since February 2009, S. Boldo, C. Marché</p>
        </li>
        <li id="uid207">
          <p noindent="true">PhD in progress: M. Iguernelala, Forward and Backward Strategies in SMT solvers, since September 2009, S. Conchon, É. Contejean</p>
        </li>
        <li id="uid208">
          <p noindent="true">PhD in progress: A. Tafat, Modular Verification of Pointer Programs, since September 2009, C. Marché</p>
        </li>
        <li id="uid209">
          <p noindent="true">PhD in progress: P. Herms, Certification of a Tool Chain for Verification of C programs, since October 2009, C. Marché, B. Monate (CEA List)</p>
        </li>
        <li id="uid210">
          <p noindent="true">PhD in progress: C. Dross, Theories and Techniques for Automated Proof of programs, since January 2011, S. Conchon, C. Marché, A. Paskevich, and industrial
          supervisors Y. Moy and J. Kanig from AdaCore company.</p>
        </li>
        <li id="uid211">
          <p noindent="true">PhD in progress: Alain Mebsout, SMT-based Model-Checking, since September 2011, F. Zaidi, S. Conchon</p>
        </li>
        <li id="uid212">
          <p noindent="true">PhD in progress: C. Lelay, Real numbers for the Coq proof assistant, since October 2011, S. Boldo, G. Melquiond.</p>
        </li>
        <li id="uid213">
          <p noindent="true">PhD in progress: A. J. Compaore, Rewriting Techniques for (Space and Time) Simulation of Biological Processes, since November 2007, defence in Feb. 2012, X. Urbain and P.
          Le Gall (ECP &amp; Université Évry).</p>
        </li>
        <li id="uid214">
          <p noindent="true">PhD in progress: Z. Bouzid, Models and Algorithms for Emerging Systems, since October 2009, X. Urbain and S. Tixeuil, M. Gradinariu Potop-Butucaru (Université Paris
          6).</p>
        </li>
        <li id="uid215">
          <p noindent="true">PhD stopped: W. Urribarrí, Towards certified libraries, from Nov. 2006 to Sep. 2011. W. Urribarrí is now an engineer “development of secure software” at ClearSy.</p>
        </li>
      </sanspuceslist>
    </subsection>
  </diffusion>
  <biblio id="bibliography" html="bibliography" numero="10" titre="Bibliography">
    <biblStruct id="proval-2011-bid93" type="inproceedings" rend="refer" n="refercite:boldo09icalp">
      <analytic>
        <title level="a">Floats &amp; Ropes: a case study for formal numerical program verification</title>
        <author>
          <persName key="proval-2006-idm410174308976">
            <foreName>Sylvie</foreName>
            <surname>Boldo</surname>
            <initial>S.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-international-audience="yes" x-proceedings="yes">
        <title level="m">36th International Colloquium on Automata, Languages and Programming</title>
        <loc>Rhodos, Greece</loc>
        <title level="s">Lecture Notes in Computer Science - ARCoSS</title>
        <imprint>
          <biblScope type="volume">5556</biblScope>
          <publisher>
            <orgName>Springer</orgName>
          </publisher>
          <dateStruct>
            <month>July</month>
            <year>2009</year>
          </dateStruct>
          <biblScope type="pages">91–102</biblScope>
        </imprint>
      </monogr>
    </biblStruct>
    <biblStruct id="proval-2011-bid91" type="inproceedings" rend="refer" n="refercite:BoldoFilliatre07">
      <analytic>
        <title level="a">Formal Verification of Floating-Point Programs</title>
        <author>
          <persName key="proval-2006-idm410174308976">
            <foreName>Sylvie</foreName>
            <surname>Boldo</surname>
            <initial>S.</initial>
          </persName>
          <persName key="proval-2006-idm410174303696">
            <foreName>Jean-Christophe</foreName>
            <surname>Filliâtre</surname>
            <initial>J.-C.</initial>
          </persName>
        </author>
      </analytic>
      <monogr>
        <title level="m">18th IEEE International Symposium on Computer Arithmetic</title>
        <loc>Montpellier, France</loc>
        <imprint>
          <dateStruct>
            <month>June</month>
            <year>2007</year>
          </dateStruct>
          <biblScope type="pages">187-194</biblScope>
          <ref xlink:href="http://www.lri.fr/~filliatr/ftp/publis/caduceus-floats.pdf" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://
          <allowbreak/>www.
          <allowbreak/>lri.
          <allowbreak/>fr/
          <allowbreak/>~filliatr/
          <allowbreak/>ftp/
          <allowbreak/>publis/
          <allowbreak/>caduceus-floats.
          <allowbreak/>pdf</ref>
        </imprint>
      </monogr>
    </biblStruct>
    <biblStruct id="proval-2011-bid40" type="inproceedings" rend="refer" n="refercite:conchon08entcs">
      <analytic>
        <title level="a">CC(X): Semantical Combination of Congruence Closure with Solvable Theories</title>
        <author>
          <persName key="proval-2006-idm410174301040">
            <foreName>Sylvain</foreName>
            <surname>Conchon</surname>
            <initial>S.</initial>
          </persName>
          <persName key="proval-2006-idm410174306336">
            <foreName>Évelyne</foreName>
            <surname>Contejean</surname>
            <initial>É.</initial>
          </persName>
          <persName key="proval-2006-idm410173277088">
            <foreName>Johannes</foreName>
            <surname>Kanig</surname>
            <initial>J.</initial>
          </persName>
          <persName key="proval-2006-idm410173274400">
            <foreName>Stéphane</foreName>
            <surname>Lescuyer</surname>
            <initial>S.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-international-audience="yes" x-proceedings="yes">
        <title level="m">Post-proceedings of the 5th International Workshop on Satisfiability Modulo Theories (SMT 2007)</title>
        <title level="s">Electronic Notes in Computer Science</title>
        <imprint>
          <biblScope type="volume">198-2</biblScope>
          <publisher>
            <orgName>Elsevier Science Publishers</orgName>
          </publisher>
          <dateStruct>
            <year>2008</year>
          </dateStruct>
          <biblScope type="pages">51–69</biblScope>
        </imprint>
      </monogr>
    </biblStruct>
    <biblStruct id="proval-2011-bid44" type="inproceedings" rend="refer" n="refercite:contejean07frocos">
      <analytic>
        <title level="a">Certification of automated termination proofs</title>
        <author>
          <persName key="proval-2006-idm410174306336">
            <foreName>Évelyne</foreName>
            <surname>Contejean</surname>
            <initial>É.</initial>
          </persName>
          <persName key="toccata-2012-idm273573193936">
            <foreName>Pierre</foreName>
            <surname>Courtieu</surname>
            <initial>P.</initial>
          </persName>
          <persName key="everest-2006-idm306718578960">
            <foreName>Julien</foreName>
            <surname>Forest</surname>
            <initial>J.</initial>
          </persName>
          <persName>
            <foreName>Olivier</foreName>
            <surname>Pons</surname>
            <initial>O.</initial>
          </persName>
          <persName key="proval-2009-idm423378944592">
            <foreName>Xavier</foreName>
            <surname>Urbain</surname>
            <initial>X.</initial>
          </persName>
        </author>
      </analytic>
      <monogr>
        <editor role="editor">
          <persName>
            <foreName>Boris</foreName>
            <surname>Konev</surname>
            <initial>B.</initial>
          </persName>
          <persName>
            <foreName>Frank</foreName>
            <surname>Wolter</surname>
            <initial>F.</initial>
          </persName>
        </editor>
        <title level="m">6th International Symposium on Frontiers of Combining Systems (FroCos 07)</title>
        <loc>Liverpool,UK</loc>
        <title level="s">Lecture Notes in Artificial Intelligence</title>
        <imprint>
          <biblScope type="volume">4720</biblScope>
          <publisher>
            <orgName>Springer</orgName>
          </publisher>
          <dateStruct>
            <month>September</month>
            <year>2007</year>
          </dateStruct>
          <biblScope type="pages">148–162</biblScope>
        </imprint>
      </monogr>
    </biblStruct>
    <biblStruct id="proval-2011-bid92" type="article" rend="refer" n="refercite:contejean05jar">
      <identifiant type="doi" value="10.1007/s10817-005-9022-x"/>
      <analytic>
        <title level="a">Mechanically proving termination using polynomial interpretations</title>
        <author>
          <persName key="proval-2006-idm410174306336">
            <foreName>Évelyne</foreName>
            <surname>Contejean</surname>
            <initial>É.</initial>
          </persName>
          <persName key="proval-2006-idm410174325056">
            <foreName>Claude</foreName>
            <surname>Marché</surname>
            <initial>C.</initial>
          </persName>
          <persName>
            <foreName>Ana Paula</foreName>
            <surname>Tomás</surname>
            <initial>A. P.</initial>
          </persName>
          <persName key="proval-2009-idm423378944592">
            <foreName>Xavier</foreName>
            <surname>Urbain</surname>
            <initial>X.</initial>
          </persName>
        </author>
      </analytic>
      <monogr>
        <title level="j">Journal of Automated Reasoning</title>
        <imprint>
          <biblScope type="volume">34</biblScope>
          <biblScope type="number">4</biblScope>
          <dateStruct>
            <year>2005</year>
          </dateStruct>
          <biblScope type="pages">325–363</biblScope>
          <ref xlink:href="http://dx.doi.org/10.1007/s10817-005-9022-x" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://
          <allowbreak/>dx.
          <allowbreak/>doi.
          <allowbreak/>org/
          <allowbreak/>10.
          <allowbreak/>1007/
          <allowbreak/>s10817-005-9022-x</ref>
        </imprint>
      </monogr>
    </biblStruct>
    <biblStruct id="proval-2011-bid10" type="article" rend="refer" n="refercite:Filliatre03jfp">
      <analytic>
        <title level="a">Verification of Non-Functional Programs using Interpretations in Type Theory</title>
        <author>
          <persName key="proval-2006-idm410174303696">
            <foreName>Jean-Christophe</foreName>
            <surname>Filliâtre</surname>
            <initial>J.-C.</initial>
          </persName>
        </author>
      </analytic>
      <monogr>
        <title level="j">Journal of Functional Programming</title>
        <imprint>
          <biblScope type="volume">13</biblScope>
          <biblScope type="number">4</biblScope>
          <dateStruct>
            <month>July</month>
            <year>2003</year>
          </dateStruct>
          <biblScope type="pages">709–745</biblScope>
          <ref xlink:href="http://www.lri.fr/~filliatr/ftp/publis/jphd.pdf" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://
          <allowbreak/>www.
          <allowbreak/>lri.
          <allowbreak/>fr/
          <allowbreak/>~filliatr/
          <allowbreak/>ftp/
          <allowbreak/>publis/
          <allowbreak/>jphd.
          <allowbreak/>pdf</ref>
        </imprint>
      </monogr>
    </biblStruct>
    <biblStruct id="proval-2011-bid13" type="inproceedings" rend="refer" n="refercite:filliatre04icfem">
      <analytic>
        <title level="a">Multi-Prover Verification of C Programs</title>
        <author>
          <persName key="proval-2006-idm410174303696">
            <foreName>Jean-Christophe</foreName>
            <surname>Filliâtre</surname>
            <initial>J.-C.</initial>
          </persName>
          <persName key="proval-2006-idm410174325056">
            <foreName>Claude</foreName>
            <surname>Marché</surname>
            <initial>C.</initial>
          </persName>
        </author>
      </analytic>
      <monogr>
        <editor role="editor">
          <persName>
            <foreName>Jim</foreName>
            <surname>Davies</surname>
            <initial>J.</initial>
          </persName>
          <persName>
            <foreName>Wolfram</foreName>
            <surname>Schulte</surname>
            <initial>W.</initial>
          </persName>
          <persName>
            <foreName>Mike</foreName>
            <surname>Barnett</surname>
            <initial>M.</initial>
          </persName>
        </editor>
        <title level="m">6th International Conference on Formal Engineering Methods</title>
        <loc>Seattle, WA, USA</loc>
        <title level="s">Lecture Notes in Computer Science</title>
        <imprint>
          <biblScope type="volume">3308</biblScope>
          <publisher>
            <orgName>Springer</orgName>
          </publisher>
          <dateStruct>
            <month>November</month>
            <year>2004</year>
          </dateStruct>
          <biblScope type="pages">15–29</biblScope>
          <ref xlink:href="http://www.lri.fr/~filliatr/ftp/publis/caduceus.ps.gz" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://
          <allowbreak/>www.
          <allowbreak/>lri.
          <allowbreak/>fr/
          <allowbreak/>~filliatr/
          <allowbreak/>ftp/
          <allowbreak/>publis/
          <allowbreak/>caduceus.
          <allowbreak/>ps.
          <allowbreak/>gz</ref>
        </imprint>
      </monogr>
    </biblStruct>
    <biblStruct id="proval-2011-bid25" type="inproceedings" rend="refer" n="refercite:hubert05sefm">
      <analytic>
        <title level="a">A case study of C source code verification: the Schorr-Waite algorithm</title>
        <author>
          <persName key="proval-2006-idm410174292368">
            <foreName>Thierry</foreName>
            <surname>Hubert</surname>
            <initial>T.</initial>
          </persName>
          <persName key="proval-2006-idm410174325056">
            <foreName>Claude</foreName>
            <surname>Marché</surname>
            <initial>C.</initial>
          </persName>
        </author>
      </analytic>
      <monogr>
        <editor role="editor">
          <persName>
            <foreName>Bernhard K.</foreName>
            <surname>Aichernig</surname>
            <initial>B. K.</initial>
          </persName>
          <persName>
            <foreName>Bernhard</foreName>
            <surname>Beckert</surname>
            <initial>B.</initial>
          </persName>
        </editor>
        <title level="m">3rd IEEE International Conference on Software Engineering and Formal Methods (SEFM'05)</title>
        <loc>Koblenz, Germany</loc>
        <imprint>
          <publisher>
            <orgName>IEEE Comp. Soc. Press</orgName>
          </publisher>
          <dateStruct>
            <month>September</month>
            <year>2005</year>
          </dateStruct>
          <ref xlink:href="http://www.lri.fr/~marche/hubert05sefm.ps" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://
          <allowbreak/>www.
          <allowbreak/>lri.
          <allowbreak/>fr/
          <allowbreak/>~marche/
          <allowbreak/>hubert05sefm.
          <allowbreak/>ps</ref>
        </imprint>
      </monogr>
    </biblStruct>
    <biblStruct id="proval-2011-bid35" type="article" rend="refer" n="refercite:krstic-conchon-05">
      <analytic>
        <title level="a">Canonization for disjoint unions of theories</title>
        <author>
          <persName>
            <foreName>Sava</foreName>
            <surname>Krstić</surname>
            <initial>S.</initial>
          </persName>
          <persName key="proval-2006-idm410174301040">
            <foreName>Sylvain</foreName>
            <surname>Conchon</surname>
            <initial>S.</initial>
          </persName>
        </author>
      </analytic>
      <monogr>
        <title level="j">Information and Computation</title>
        <imprint>
          <biblScope type="volume">199</biblScope>
          <biblScope type="number">1-2</biblScope>
          <dateStruct>
            <month>May</month>
            <year>2005</year>
          </dateStruct>
          <biblScope type="pages">87–106</biblScope>
        </imprint>
      </monogr>
    </biblStruct>
    <biblStruct id="proval-2011-bid12" type="article" rend="refer" n="refercite:marche04jlap">
      <analytic>
        <title level="a">The 
        <span class="smallcap" align="left">Krakatoa</span>Tool for Certification of 
        <span class="smallcap" align="left">Java/JavaCard</span>Programs annotated in 
        <span class="smallcap" align="left">JML</span></title>
        <author>
          <persName key="proval-2006-idm410174325056">
            <foreName>Claude</foreName>
            <surname>Marché</surname>
            <initial>C.</initial>
          </persName>
          <persName key="proval-2008-idm220575009344">
            <foreName>Christine</foreName>
            <surname>Paulin-Mohring</surname>
            <initial>C.</initial>
          </persName>
          <persName key="proval-2009-idm423378944592">
            <foreName>Xavier</foreName>
            <surname>Urbain</surname>
            <initial>X.</initial>
          </persName>
        </author>
      </analytic>
      <monogr>
        <title level="j">Journal of Logic and Algebraic Programming</title>
        <imprint>
          <biblScope type="volume">58</biblScope>
          <biblScope type="number">1–2</biblScope>
          <dateStruct>
            <year>2004</year>
          </dateStruct>
          <biblScope type="pages">89–106</biblScope>
          <ref xlink:href="http://krakatoa.lri.fr" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://
          <allowbreak/>krakatoa.
          <allowbreak/>lri.
          <allowbreak/>fr</ref>
        </imprint>
      </monogr>
    </biblStruct>
    <biblStruct dedoublkey="5563" id="proval-2011-bid86" type="proceedings" rend="year" n="cite:postfoveoos10">
      <monogr x-international-audience="yes" x-proceedings="yes">
        <title level="m">Formal Verification of Object-Oriented Software, Revised Selected Papers Presented at the International Conference, FoVeOOS 2010</title>
        <title level="s">Lecture Notes in Computer Science</title>
        <editor role="editor">
          <persName>
            <foreName>Bernhard</foreName>
            <surname>Beckert</surname>
            <initial>B.</initial>
          </persName>
          <persName key="proval-2006-idm410174325056">
            <foreName>Claude</foreName>
            <surname>Marché</surname>
            <initial>C.</initial>
          </persName>
        </editor>
        <imprint>
          <biblScope type="volume">6528</biblScope>
          <publisher>
            <orgName>Springer</orgName>
          </publisher>
          <dateStruct>
            <month>January</month>
            <year>2011</year>
          </dateStruct>
        </imprint>
      </monogr>
      <affiliation>
        <country>DE</country>
      </affiliation>
    </biblStruct>
    <biblStruct dedoublkey="5544" id="proval-2011-bid69" type="phdthesis" rend="year" n="cite:bardou11phd">
      <monogr>
        <title level="m">Verification of Pointer Programs Using Regions and Permissions</title>
        <author>
          <persName key="proval-2007-idm172231421920">
            <foreName>Romain</foreName>
            <surname>Bardou</surname>
            <initial>R.</initial>
          </persName>
        </author>
        <imprint>
          <publisher>
            <orgName type="school">Université Paris-Sud</orgName>
          </publisher>
          <dateStruct>
            <month>October</month>
            <year>2011</year>
          </dateStruct>
          <ref xlink:href="http://romain.bardou.fr/thesis/bardou11phd.pdf" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://
          <allowbreak/>romain.
          <allowbreak/>bardou.
          <allowbreak/>fr/
          <allowbreak/>thesis/
          <allowbreak/>bardou11phd.
          <allowbreak/>pdf</ref>
        </imprint>
      </monogr>
      <note type="typdoc">Thèse de Doctorat</note>
    </biblStruct>
    <biblStruct dedoublkey="5407" id="proval-2011-bid71" type="phdthesis" rend="year" n="cite:bobot11these">
      <monogr>
        <title level="m">Logique de séparation et vérification déductive</title>
        <author>
          <persName key="proval-2008-idm220574959120">
            <foreName>François</foreName>
            <surname>Bobot</surname>
            <initial>F.</initial>
          </persName>
        </author>
        <imprint>
          <publisher>
            <orgName type="school">Université Paris-Sud</orgName>
          </publisher>
          <dateStruct>
            <month>December</month>
            <year>2011</year>
          </dateStruct>
        </imprint>
      </monogr>
      <note type="typdoc">Thèse de Doctorat</note>
    </biblStruct>
    <biblStruct dedoublkey="2000" id="proval-2011-bid90" type="hdrthesis" rend="year" n="cite:filliatre11hdr">
      <monogr>
        <title level="m">Deductive Program Verification</title>
        <author>
          <persName key="proval-2006-idm410174303696">
            <foreName>Jean-Christophe</foreName>
            <surname>Filliâtre</surname>
            <initial>J.-C.</initial>
          </persName>
        </author>
        <imprint>
          <publisher>
            <orgName type="school">Université Paris-Sud</orgName>
          </publisher>
          <dateStruct>
            <month>December</month>
            <year>2011</year>
          </dateStruct>
        </imprint>
      </monogr>
      <note type="typdoc">Thèse d'habilitation</note>
    </biblStruct>
    <biblStruct dedoublkey="5365" id="proval-2011-bid48" type="phdthesis" rend="year" n="cite:lescuyer11these">
      <monogr>
        <title level="m">Formalisation et développement d'une tactique réflexive pour la démonstration automatique en Coq</title>
        <author>
          <persName key="proval-2006-idm410173274400">
            <foreName>Stéphane</foreName>
            <surname>Lescuyer</surname>
            <initial>S.</initial>
          </persName>
        </author>
        <imprint>
          <publisher>
            <orgName type="school">Université Paris-Sud</orgName>
          </publisher>
          <dateStruct>
            <month>January</month>
            <year>2011</year>
          </dateStruct>
        </imprint>
      </monogr>
      <note type="typdoc">Thèse de Doctorat</note>
    </biblStruct>
    <biblStruct dedoublkey="0743" id="proval-2011-bid76" type="article" rend="year" n="cite:boldo11mcs">
      <analytic>
        <title level="a">Formal verification of numerical programs: from C annotated programs to mechanical proofs</title>
        <author>
          <persName key="proval-2006-idm410174308976">
            <foreName>Sylvie</foreName>
            <surname>Boldo</surname>
            <initial>S.</initial>
          </persName>
          <persName key="proval-2006-idm410174325056">
            <foreName>Claude</foreName>
            <surname>Marché</surname>
            <initial>C.</initial>
          </persName>
        </author>
      </analytic>
      <monogr id="rid01491" x-editorial-board="yes" x-international-audience="yes">
        <idno type="issn">1661-8270</idno>
        <title level="j">Mathematics in Computer Science</title>
        <imprint>
          <dateStruct>
            <year>2011</year>
          </dateStruct>
        </imprint>
      </monogr>
    </biblStruct>
    <biblStruct dedoublkey="0679" id="proval-2011-bid78" type="article" rend="year" n="cite:boldo10-tc">
      <identifiant type="hal" value="inria-00429617"/>
      <analytic>
        <title level="a">Exact and Approximated error of the FMA</title>
        <author>
          <persName key="proval-2006-idm410174308976">
            <foreName>Sylvie</foreName>
            <surname>Boldo</surname>
            <initial>S.</initial>
          </persName>
          <persName key="arenaire-2006-idm111960283664">
            <foreName>Jean-Michel</foreName>
            <surname>Muller</surname>
            <initial>J.-M.</initial>
          </persName>
        </author>
      </analytic>
      <monogr id="rid00804" x-editorial-board="yes" x-international-audience="yes">
        <idno type="issn">0018-9340</idno>
        <title level="j">IEEE Transactions on Computers</title>
        <imprint>
          <biblScope type="volume">60</biblScope>
          <biblScope type="number">2</biblScope>
          <dateStruct>
            <month>February</month>
            <year>2011</year>
          </dateStruct>
          <biblScope type="pages">157–164</biblScope>
          <ref xlink:href="http://hal.inria.fr/inria-00429617/en/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://
          <allowbreak/>hal.
          <allowbreak/>inria.
          <allowbreak/>fr/
          <allowbreak/>inria-00429617/
          <allowbreak/>en/
          <allowbreak/></ref>
        </imprint>
      </monogr>
    </biblStruct>
    <biblStruct dedoublkey="1327" id="proval-2011-bid77" type="article" rend="year" n="cite:boldo11-isse">
      <analytic>
        <title level="a">Proofs of numerical programs when the compiler optimizes</title>
        <author>
          <persName key="proval-2006-idm410174308976">
            <foreName>Sylvie</foreName>
            <surname>Boldo</surname>
            <initial>S.</initial>
          </persName>
          <persName key="cqfd-2007-idm193413639296">
            <foreName>Thi Minh Tuyen</foreName>
            <surname>Nguyen</surname>
            <initial>T. M. T.</initial>
          </persName>
        </author>
      </analytic>
      <monogr id="rid00910" x-editorial-board="yes" x-international-audience="yes">
        <idno type="issn">1614-5046</idno>
        <title level="j">Innovations in Systems and Software Engineering</title>
        <imprint>
          <biblScope type="volume">7</biblScope>
          <dateStruct>
            <year>2011</year>
          </dateStruct>
          <biblScope type="pages">151-160</biblScope>
        </imprint>
      </monogr>
    </biblStruct>
    <biblStruct dedoublkey="2205" id="proval-2011-bid88" type="incollection" rend="year" n="cite:Boldo11livrea">
      <analytic>
        <title level="a">Représentation numérique de l'information</title>
        <author>
          <persName key="proval-2006-idm410174308976">
            <foreName>Sylvie</foreName>
            <surname>Boldo</surname>
            <initial>S.</initial>
          </persName>
          <persName key="odyssee-2006-idm405611886032">
            <foreName>Thierry</foreName>
            <surname>Viéville</surname>
            <initial>T.</initial>
          </persName>
        </author>
      </analytic>
      <monogr>
        <editor role="editor">
          <persName key="logical-2006-idm356512403456">
            <foreName>Gilles</foreName>
            <surname>Dowek</surname>
            <initial>G.</initial>
          </persName>
        </editor>
        <title level="m">Introduction à la science informatique</title>
        <title level="s">Repères pour agir</title>
        <imprint>
          <publisher>
            <orgName>CRDP Académie de Paris</orgName>
          </publisher>
          <dateStruct>
            <month>July</month>
            <year>2011</year>
          </dateStruct>
          <biblScope type="pages">23–72</biblScope>
          <ref xlink:href="http://crdp.ac-paris.fr/Introduction-a-la-science" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://
          <allowbreak/>crdp.
          <allowbreak/>ac-paris.
          <allowbreak/>fr/
          <allowbreak/>Introduction-a-la-science</ref>
        </imprint>
      </monogr>
    </biblStruct>
    <biblStruct dedoublkey="2231" id="proval-2011-bid89" type="incollection" rend="year" n="cite:Boldo11livreb">
      <analytic>
        <title level="a">Structuration et contrôle de l'information</title>
        <author>
          <persName key="proval-2006-idm410174308976">
            <foreName>Sylvie</foreName>
            <surname>Boldo</surname>
            <initial>S.</initial>
          </persName>
          <persName key="odyssee-2006-idm405611886032">
            <foreName>Thierry</foreName>
            <surname>Viéville</surname>
            <initial>T.</initial>
          </persName>
        </author>
      </analytic>
      <monogr>
        <editor role="editor">
          <persName key="logical-2006-idm356512403456">
            <foreName>Gilles</foreName>
            <surname>Dowek</surname>
            <initial>G.</initial>
          </persName>
        </editor>
        <title level="m">Introduction à la science informatique</title>
        <title level="s">Repères pour agir</title>
        <imprint>
          <publisher>
            <orgName>CRDP Académie de Paris</orgName>
          </publisher>
          <dateStruct>
            <month>July</month>
            <year>2011</year>
          </dateStruct>
          <biblScope type="pages">281–308</biblScope>
          <ref xlink:href="http://crdp.ac-paris.fr/Introduction-a-la-science" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://
          <allowbreak/>crdp.
          <allowbreak/>ac-paris.
          <allowbreak/>fr/
          <allowbreak/>Introduction-a-la-science</ref>
        </imprint>
      </monogr>
    </biblStruct>
    <biblStruct dedoublkey="0393" id="proval-2011-bid57" type="article" rend="year" n="cite:dinechin10tc">
      <identifiant type="hal" value="inria-00533968"/>
      <analytic>
        <title level="a">Certifying the floating-point implementation of an elementary function using Gappa</title>
        <author>
          <persName key="arenaire-2006-idm111960277216">
            <foreName>Florent</foreName>
            <surname>de Dinechin</surname>
            <initial>F.</initial>
          </persName>
          <persName key="arenaire-2006-idm111960258368">
            <foreName>Christoph</foreName>
            <surname>Lauter</surname>
            <initial>C.</initial>
          </persName>
          <persName key="arenaire-2006-idm111960255408">
            <foreName>Guillaume</foreName>
            <surname>Melquiond</surname>
            <initial>G.</initial>
          </persName>
        </author>
      </analytic>
      <monogr id="rid00804" x-editorial-board="yes" x-international-audience="yes">
        <idno type="issn">0018-9340</idno>
        <title level="j">IEEE Transactions on Computers</title>
        <imprint>
          <biblScope type="volume">60</biblScope>
          <biblScope type="number">2</biblScope>
          <dateStruct>
            <year>2011</year>
          </dateStruct>
          <biblScope type="pages">242–253</biblScope>
          <ref xlink:href="http://hal.inria.fr/inria-00533968/en/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://
          <allowbreak/>hal.
          <allowbreak/>inria.
          <allowbreak/>fr/
          <allowbreak/>inria-00533968/
          <allowbreak/>en/
          <allowbreak/></ref>
        </imprint>
      </monogr>
      <affiliation>
        <country>US</country>
      </affiliation>
    </biblStruct>
    <biblStruct dedoublkey="0540" id="proval-2011-bid87" type="article" rend="year" n="cite:filliatre11sttt">
      <identifiant type="doi" value="10.1007/s10009-011-0211-0"/>
      <analytic>
        <title level="a">Deductive Software Verification</title>
        <author>
          <persName key="proval-2006-idm410174303696">
            <foreName>Jean-Christophe</foreName>
            <surname>Filliâtre</surname>
            <initial>J.-C.</initial>
          </persName>
        </author>
      </analytic>
      <monogr id="rid01093" x-editorial-board="yes" x-international-audience="yes">
        <idno type="issn">1433-2779</idno>
        <title level="j">International Journal on Software Tools for Technology Transfer (STTT)</title>
        <imprint>
          <biblScope type="volume">13</biblScope>
          <biblScope type="number">5</biblScope>
          <dateStruct>
            <month>August</month>
            <year>2011</year>
          </dateStruct>
          <biblScope type="pages">397-403</biblScope>
          <ref xlink:href="http://dx.doi.org/10.1007/s10009-011-0211-0" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://
          <allowbreak/>dx.
          <allowbreak/>doi.
          <allowbreak/>org/
          <allowbreak/>10.
          <allowbreak/>1007/
          <allowbreak/>s10009-011-0211-0</ref>
        </imprint>
      </monogr>
    </biblStruct>
    <biblStruct dedoublkey="3740" id="proval-2011-bid61" type="inproceedings" rend="year" n="cite:baelde11sofsem">
      <analytic>
        <title level="a">Liquidsoap: A High-Level Programming Language for Multimedia Streaming</title>
        <author>
          <persName key="parsifal-2006-idm465379746128">
            <foreName>David</foreName>
            <surname>Baelde</surname>
            <initial>D.</initial>
          </persName>
          <persName key="comete-2006-idm52895098256">
            <foreName>Romain</foreName>
            <surname>Beauxis</surname>
            <initial>R.</initial>
          </persName>
          <persName>
            <foreName>Samuel</foreName>
            <surname>Mimram</surname>
            <initial>S.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-international-audience="yes" x-proceedings="yes">
        <editor role="editor">
          <persName>
            <foreName>Ivana</foreName>
            <surname>Cerná</surname>
            <initial>I.</initial>
          </persName>
          <persName>
            <foreName>Tibor</foreName>
            <surname>Gyimóthy</surname>
            <initial>T.</initial>
          </persName>
          <persName>
            <foreName>Juraj</foreName>
            <surname>Hromkovic</surname>
            <initial>J.</initial>
          </persName>
          <persName>
            <foreName>Keith G.</foreName>
            <surname>Jeffery</surname>
            <initial>K. G.</initial>
          </persName>
          <persName>
            <foreName>Rastislav</foreName>
            <surname>Královic</surname>
            <initial>R.</initial>
          </persName>
          <persName>
            <foreName>Marko</foreName>
            <surname>Vukolic</surname>
            <initial>M.</initial>
          </persName>
          <persName>
            <foreName>Stefan</foreName>
            <surname>Wolf</surname>
            <initial>S.</initial>
          </persName>
        </editor>
        <title level="m">37th Conference on Current Trends in Theory and Practice of Computer Science (SOFSEM'11)</title>
        <loc>Nový Smokovec, Slovakia</loc>
        <title level="s">Lecture Notes in Computer Science</title>
        <imprint>
          <biblScope type="volume">6543</biblScope>
          <publisher>
            <orgName>Springer</orgName>
          </publisher>
          <dateStruct>
            <month>January</month>
            <year>2011</year>
          </dateStruct>
        </imprint>
        <meeting id="cid46980">
          <title>Conference on Current Trends in Theory and Practice of Computer Science</title>
          <num>37</num>
          <abbr type="sigle">SOFSEM</abbr>
        </meeting>
      </monogr>
      <affiliation>
        <country>SK</country>
      </affiliation>
    </biblStruct>
    <biblStruct dedoublkey="4181" id="proval-2011-bid70" type="inproceedings" rend="year" n="cite:bardou11jfla">
      <analytic>
        <title level="a">Perle de preuve: les tableaux creux</title>
        <author>
          <persName key="proval-2007-idm172231421920">
            <foreName>Romain</foreName>
            <surname>Bardou</surname>
            <initial>R.</initial>
          </persName>
          <persName key="proval-2006-idm410174325056">
            <foreName>Claude</foreName>
            <surname>Marché</surname>
            <initial>C.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-international-audience="no" x-proceedings="yes">
        <editor role="editor">
          <persName key="proval-2006-idm410174301040">
            <foreName>Sylvain</foreName>
            <surname>Conchon</surname>
            <initial>S.</initial>
          </persName>
        </editor>
        <title level="m">Vingt-deuxièmes Journées Francophones des Langages Applicatifs</title>
        <loc>La Bresse, France</loc>
        <imprint>
          <publisher>
            <orgName>INRIA</orgName>
          </publisher>
          <dateStruct>
            <month>January</month>
            <year>2011</year>
          </dateStruct>
        </imprint>
        <meeting id="cid344980">
          <title>Journées Francophones des Langages Applicatifs</title>
          <num>22</num>
          <abbr type="sigle">JFLA</abbr>
        </meeting>
      </monogr>
    </biblStruct>
    <biblStruct dedoublkey="5022" subtype="nonparu" id="proval-2011-bid63" type="inproceedings" rend="year" n="cite:boogie11why3">
      <analytic>
        <title level="a">Why3: Shepherd Your Herd of Provers</title>
        <author>
          <persName key="proval-2008-idm220574959120">
            <foreName>François</foreName>
            <surname>Bobot</surname>
            <initial>F.</initial>
          </persName>
          <persName key="proval-2006-idm410174303696">
            <foreName>Jean-Christophe</foreName>
            <surname>Filliâtre</surname>
            <initial>J.-C.</initial>
          </persName>
          <persName key="proval-2006-idm410174325056">
            <foreName>Claude</foreName>
            <surname>Marché</surname>
            <initial>C.</initial>
          </persName>
          <persName key="proval-2009-idm423378947776">
            <foreName>Andrei</foreName>
            <surname>Paskevich</surname>
            <initial>A.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-international-audience="yes" x-proceedings="yes">
        <title level="m">Boogie 2011: First International Workshop on Intermediate Verification Languages</title>
        <loc>Wrocław, Poland</loc>
        <imprint>
          <dateStruct>
            <month>August</month>
            <year>2011</year>
          </dateStruct>
          <ref xlink:href="http://proval.lri.fr/submissions/boogie11.pdf" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://
          <allowbreak/>proval.
          <allowbreak/>lri.
          <allowbreak/>fr/
          <allowbreak/>submissions/
          <allowbreak/>boogie11.
          <allowbreak/>pdf</ref>
        </imprint>
        <meeting id="cid468483">
          <title>International Workshop on Intermediate Verification Languages</title>
          <num>1</num>
          <abbr type="sigle">Boogie</abbr>
        </meeting>
      </monogr>
    </biblStruct>
    <biblStruct dedoublkey="3294" id="proval-2011-bid72" type="inproceedings" rend="year" n="cite:BobotPaskevich2011frocos">
      <analytic>
        <title level="a">Expressing Polymorphic Types in a Many-Sorted Language</title>
        <author>
          <persName key="proval-2008-idm220574959120">
            <foreName>François</foreName>
            <surname>Bobot</surname>
            <initial>F.</initial>
          </persName>
          <persName key="proval-2009-idm423378947776">
            <foreName>Andrei</foreName>
            <surname>Paskevich</surname>
            <initial>A.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-international-audience="yes" x-proceedings="yes">
        <editor role="editor">
          <persName>
            <foreName>Cesare</foreName>
            <surname>Tinelli</surname>
            <initial>C.</initial>
          </persName>
          <persName>
            <foreName>Viorica</foreName>
            <surname>Sofronie-Stokkermans</surname>
            <initial>V.</initial>
          </persName>
        </editor>
        <title level="m">Frontiers of Combining Systems, 8th International Symposium, Proceedings</title>
        <loc>Saarbrücken, Germany</loc>
        <title level="s">Lecture Notes in Computer Science</title>
        <imprint>
          <biblScope type="volume">6989</biblScope>
          <dateStruct>
            <month>October</month>
            <year>2011</year>
          </dateStruct>
        </imprint>
        <meeting id="cid326437">
          <title>International Workshop on Frontiers of Combining Systems</title>
          <num>8</num>
          <abbr type="sigle">FROCOS</abbr>
        </meeting>
      </monogr>
    </biblStruct>
    <biblStruct dedoublkey="3361" id="proval-2011-bid55" type="inproceedings" rend="year" n="cite:BolMel11">
      <analytic>
        <title level="a">Flocq: A Unified Library for Proving Floating-point Algorithms in Coq</title>
        <author>
          <persName key="proval-2006-idm410174308976">
            <foreName>Sylvie</foreName>
            <surname>Boldo</surname>
            <initial>S.</initial>
          </persName>
          <persName key="arenaire-2006-idm111960255408">
            <foreName>Guillaume</foreName>
            <surname>Melquiond</surname>
            <initial>G.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-international-audience="yes" x-proceedings="yes">
        <editor role="editor">
          <persName>
            <foreName>Elisardo</foreName>
            <surname>Antelo</surname>
            <initial>E.</initial>
          </persName>
          <persName>
            <foreName>David</foreName>
            <surname>Hough</surname>
            <initial>D.</initial>
          </persName>
          <persName>
            <foreName>Paolo</foreName>
            <surname>Ienne</surname>
            <initial>P.</initial>
          </persName>
        </editor>
        <title level="m">Proceedings of the 20th IEEE Symposium on Computer Arithmetic</title>
        <loc>Tübingen, Germany</loc>
        <imprint>
          <dateStruct>
            <year>2011</year>
          </dateStruct>
          <biblScope type="pages">243–252</biblScope>
          <ref xlink:href="http://www.lri.fr/~melquion/doc/11-arith20-article.pdf" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://
          <allowbreak/>www.
          <allowbreak/>lri.
          <allowbreak/>fr/
          <allowbreak/>~melquion/
          <allowbreak/>doc/
          <allowbreak/>11-arith20-article.
          <allowbreak/>pdf</ref>
        </imprint>
        <meeting id="cid94252">
          <title>IEEE Symposium on Computer Arithmetic</title>
          <num>20</num>
          <abbr type="sigle">ARITH</abbr>
        </meeting>
      </monogr>
    </biblStruct>
    <biblStruct id="proval-2011-bid1" type="inproceedings" rend="best" n="cite:conchon11tacas">
      <analytic>
        <title level="a">Canonized Rewriting and Ground AC Completion Modulo Shostak Theories</title>
        <author>
          <persName key="proval-2006-idm410174301040">
            <foreName>Sylvain</foreName>
            <surname>Conchon</surname>
            <initial>S.</initial>
          </persName>
          <persName key="proval-2006-idm410174306336">
            <foreName>Évelyne</foreName>
            <surname>Contejean</surname>
            <initial>É.</initial>
          </persName>
          <persName key="proval-2009-idm423378923200">
            <foreName>Mohamed</foreName>
            <surname>Iguernelala</surname>
            <initial>M.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-international-audience="yes" x-proceedings="yes">
        <editor role="editor">
          <persName>
            <foreName>Parosh A.</foreName>
            <surname>Abdulla</surname>
            <initial>P. A.</initial>
          </persName>
          <persName>
            <foreName>K. Rustan M.</foreName>
            <surname>Leino</surname>
            <initial>K. R. M.</initial>
          </persName>
        </editor>
        <title level="m">Tools and Algorithms for the Construction and Analysis of Systems</title>
        <loc>Saarbrücken, Germany</loc>
        <title level="s">Lecture Notes in Computer Science</title>
        <imprint>
          <publisher>
            <orgName>Springer</orgName>
          </publisher>
          <dateStruct>
            <month>April</month>
            <year>2011</year>
          </dateStruct>
        </imprint>
        <meeting id="cid302988">
          <title>International Conference on Tools and Algorithms for the Construction and Analysis of Systems</title>
          <num>18</num>
          <abbr type="sigle">TACAS</abbr>
        </meeting>
      </monogr>
    </biblStruct>
    <biblStruct dedoublkey="2732" id="proval-2011-bid47" type="inproceedings" rend="year" n="cite:contejean11rta">
      <analytic>
        <title level="a">Automated Certified Proofs with CiME3</title>
        <author>
          <persName key="proval-2006-idm410174306336">
            <foreName>Évelyne</foreName>
            <surname>Contejean</surname>
            <initial>É.</initial>
          </persName>
          <persName key="toccata-2012-idm273573193936">
            <foreName>Pierre</foreName>
            <surname>Courtieu</surname>
            <initial>P.</initial>
          </persName>
          <persName key="everest-2006-idm306718578960">
            <foreName>Julien</foreName>
            <surname>Forest</surname>
            <initial>J.</initial>
          </persName>
          <persName>
            <foreName>Olivier</foreName>
            <surname>Pons</surname>
            <initial>O.</initial>
          </persName>
          <persName key="proval-2009-idm423378944592">
            <foreName>Xavier</foreName>
            <surname>Urbain</surname>
            <initial>X.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-international-audience="yes" x-proceedings="yes">
        <editor role="editor">
          <persName>
            <foreName>Manfred</foreName>
            <surname>Schmidt-Schauß</surname>
            <initial>M.</initial>
          </persName>
        </editor>
        <title level="m">22nd International Conference on Rewriting Techniques and Applications (RTA 11)</title>
        <loc>Novi Sad, Serbia</loc>
        <title level="s">Leibniz International Proceedings in Informatics (LIPIcs)</title>
        <imprint>
          <biblScope type="volume">10</biblScope>
          <publisher>
            <orgName>Schloss Dagstuhl–Leibniz-Zentrum fuer Informatik</orgName>
          </publisher>
          <dateStruct>
            <year>2011</year>
          </dateStruct>
          <biblScope type="pages">21–30</biblScope>
          <ref xlink:href="http://drops.dagstuhl.de/opus/volltexte/2011/3119" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://
          <allowbreak/>drops.
          <allowbreak/>dagstuhl.
          <allowbreak/>de/
          <allowbreak/>opus/
          <allowbreak/>volltexte/
          <allowbreak/>2011/
          <allowbreak/>3119</ref>
        </imprint>
        <meeting id="cid298736">
          <title>International Conference on Rewriting Techniques and Applications</title>
          <num>22</num>
          <abbr type="sigle">RTA</abbr>
        </meeting>
      </monogr>
    </biblStruct>
    <biblStruct dedoublkey="3011" id="proval-2011-bid68" type="inproceedings" rend="year" n="cite:dross11tap">
      <analytic>
        <title level="a">Correct Code Containing Containers</title>
        <author>
          <persName key="proval-2011-idm383373667744">
            <foreName>Claire</foreName>
            <surname>Dross</surname>
            <initial>C.</initial>
          </persName>
          <persName key="proval-2006-idm410174303696">
            <foreName>Jean-Christophe</foreName>
            <surname>Filliâtre</surname>
            <initial>J.-C.</initial>
          </persName>
          <persName key="proval-2006-idm410174289696">
            <foreName>Yannick</foreName>
            <surname>Moy</surname>
            <initial>Y.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-international-audience="yes" x-proceedings="yes">
        <title level="m">5th International Conference on Tests and Proofs (TAP'11)</title>
        <loc>Zurich</loc>
        <imprint>
          <dateStruct>
            <month>June</month>
            <year>2011</year>
          </dateStruct>
        </imprint>
        <meeting id="cid302532">
          <title>International Conference on Tests and Proofs</title>
          <num>5</num>
          <abbr type="sigle">TAP</abbr>
        </meeting>
      </monogr>
    </biblStruct>
    <biblStruct dedoublkey="3421" id="proval-2011-bid54" type="inproceedings" rend="year" n="cite:filliatre11tfp">
      <analytic>
        <title level="a">Functory: A Distributed Computing Library for Objective Caml</title>
        <author>
          <persName key="proval-2006-idm410174303696">
            <foreName>Jean-Christophe</foreName>
            <surname>Filliâtre</surname>
            <initial>J.-C.</initial>
          </persName>
          <persName key="proval-2009-idm423377985664">
            <foreName>K.</foreName>
            <surname>Kalyanasundaram</surname>
            <initial>K.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-international-audience="yes" x-proceedings="yes">
        <title level="m">Trends in Functional Programming</title>
        <loc>Madrid, Spain</loc>
        <imprint>
          <dateStruct>
            <month>May</month>
            <year>2011</year>
          </dateStruct>
        </imprint>
        <meeting id="cid365808">
          <title>Symposium on Trends in Functional Programming</title>
          <num>9</num>
          <abbr type="sigle">TFP</abbr>
        </meeting>
      </monogr>
    </biblStruct>
    <biblStruct dedoublkey="4890" id="proval-2011-bid53" type="inproceedings" rend="year" n="cite:filliatre11jfla">
      <analytic>
        <title level="a">Une bibliothèque de calcul distribué pour Objective Caml</title>
        <author>
          <persName key="proval-2006-idm410174303696">
            <foreName>Jean-Christophe</foreName>
            <surname>Filliâtre</surname>
            <initial>J.-C.</initial>
          </persName>
          <persName key="proval-2009-idm423377985664">
            <foreName>Krishnamani</foreName>
            <surname>Kalyanasundaram</surname>
            <initial>K.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-international-audience="no" x-proceedings="yes">
        <editor role="editor">
          <persName key="proval-2006-idm410174301040">
            <foreName>Sylvain</foreName>
            <surname>Conchon</surname>
            <initial>S.</initial>
          </persName>
        </editor>
        <title level="m">Vingt-deuxièmes Journées Francophones des Langages Applicatifs</title>
        <loc>La Bresse, France</loc>
        <imprint>
          <publisher>
            <orgName>INRIA</orgName>
          </publisher>
          <dateStruct>
            <month>January</month>
            <year>2011</year>
          </dateStruct>
          <ref xlink:href="http://www.lri.fr/~filliatr/publis/jfla-2011.pdf" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://
          <allowbreak/>www.
          <allowbreak/>lri.
          <allowbreak/>fr/
          <allowbreak/>~filliatr/
          <allowbreak/>publis/
          <allowbreak/>jfla-2011.
          <allowbreak/>pdf</ref>
        </imprint>
        <meeting id="cid344980">
          <title>Journées Francophones des Langages Applicatifs</title>
          <num>22</num>
          <abbr type="sigle">JFLA</abbr>
        </meeting>
      </monogr>
    </biblStruct>
    <biblStruct dedoublkey="3490" id="proval-2011-bid75" type="inproceedings" rend="year" n="cite:nguyen11cpp">
      <analytic>
        <title level="a">Hardware-Dependent Proofs of Numerical Programs</title>
        <author>
          <persName key="cqfd-2007-idm193413639296">
            <foreName>Thi Minh Tuyen</foreName>
            <surname>Nguyen</surname>
            <initial>T. M. T.</initial>
          </persName>
          <persName key="proval-2006-idm410174325056">
            <foreName>Claude</foreName>
            <surname>Marché</surname>
            <initial>C.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-international-audience="yes" x-proceedings="yes">
        <editor role="editor">
          <persName key="logical-2006-idm356512386880">
            <foreName>Jean-Pierre</foreName>
            <surname>Jouannaud</surname>
            <initial>J.-P.</initial>
          </persName>
          <persName>
            <foreName>Zhong</foreName>
            <surname>Shao</surname>
            <initial>Z.</initial>
          </persName>
        </editor>
        <title level="m">Certified Programs and Proofs</title>
        <title level="s">Lecture Notes in Computer Science</title>
        <imprint>
          <publisher>
            <orgName>Springer</orgName>
          </publisher>
          <dateStruct>
            <month>December</month>
            <year>2011</year>
          </dateStruct>
        </imprint>
        <meeting id="cid196878">
          <title>International Conference on Certified Programs and Proofs</title>
          <num>1</num>
          <abbr type="sigle">CPP</abbr>
        </meeting>
      </monogr>
    </biblStruct>
    <biblStruct dedoublkey="2632" id="proval-2011-bid66" type="inproceedings" rend="year" n="cite:tafat11foveoos">
      <analytic>
        <title level="a">A Refinement Methodology for Object-Oriented Programs</title>
        <author>
          <persName>
            <foreName>Asma</foreName>
            <surname>Tafat</surname>
            <initial>A.</initial>
          </persName>
          <persName>
            <foreName>Sylvain</foreName>
            <surname>Boulmé</surname>
            <initial>S.</initial>
          </persName>
          <persName key="proval-2006-idm410174325056">
            <foreName>Claude</foreName>
            <surname>Marché</surname>
            <initial>C.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-international-audience="yes" x-proceedings="yes">
        <editor role="editor">
          <persName>
            <foreName>Bernhard</foreName>
            <surname>Beckert</surname>
            <initial>B.</initial>
          </persName>
          <persName key="proval-2006-idm410174325056">
            <foreName>Claude</foreName>
            <surname>Marché</surname>
            <initial>C.</initial>
          </persName>
        </editor>
        <title level="m">Formal Verification of Object-Oriented Software, Revised Selected Papers Presented at the International Conference, FoVeOOS 2010</title>
        <title level="s">Lecture Notes in Computer Science</title>
        <imprint>
          <biblScope type="volume">6528</biblScope>
          <publisher>
            <orgName>Springer</orgName>
          </publisher>
          <dateStruct>
            <month>January</month>
            <year>2011</year>
          </dateStruct>
          <biblScope type="pages">153–167</biblScope>
        </imprint>
        <meeting id="cid389998">
          <title>International Conference on Formal Verification of Object-Oriented Software</title>
          <num>2</num>
          <abbr type="sigle">FoVeOOS</abbr>
        </meeting>
      </monogr>
      <affiliation>
        <country>DE</country>
      </affiliation>
    </biblStruct>
    <biblStruct dedoublkey="5047" id="proval-2011-bid62" type="manual" rend="year" n="cite:bobot11why3">
      <monogr>
        <title level="m">The Why3 platform</title>
        <author>
          <persName key="proval-2008-idm220574959120">
            <foreName>François</foreName>
            <surname>Bobot</surname>
            <initial>F.</initial>
          </persName>
          <persName key="proval-2006-idm410174303696">
            <foreName>Jean-Christophe</foreName>
            <surname>Filliâtre</surname>
            <initial>J.-C.</initial>
          </persName>
          <persName key="proval-2006-idm410174325056">
            <foreName>Claude</foreName>
            <surname>Marché</surname>
            <initial>C.</initial>
          </persName>
          <persName key="proval-2009-idm423378947776">
            <foreName>Andrei</foreName>
            <surname>Paskevich</surname>
            <initial>A.</initial>
          </persName>
        </author>
        <edition>version 0.64</edition>
        <imprint>
          <publisher>
            <orgName type="organisation">LRI, CNRS &amp; Univ. Paris-Sud &amp; INRIA Saclay</orgName>
          </publisher>
          <dateStruct>
            <month>February</month>
            <year>2011</year>
          </dateStruct>
        </imprint>
      </monogr>
    </biblStruct>
    <biblStruct dedoublkey="6125" id="proval-2011-bid79" type="techreport" rend="year" n="cite:BCFMMW11rr">
      <identifiant type="hal" value="hal-00649240"/>
      <monogr>
        <title level="m">Wave Equation Numerical Resolution: Mathematics and Program</title>
        <author>
          <persName key="proval-2006-idm410174308976">
            <foreName>Sylvie</foreName>
            <surname>Boldo</surname>
            <initial>S.</initial>
          </persName>
          <persName key="estime-2006-idm273297399856">
            <foreName>Francois</foreName>
            <surname>Clement</surname>
            <initial>F.</initial>
          </persName>
          <persName key="proval-2006-idm410174303696">
            <foreName>Jean-Christophe</foreName>
            <surname>Filliâtre</surname>
            <initial>J.-C.</initial>
          </persName>
          <persName key="arenaire-2009-idm499614616432">
            <foreName>Micaela</foreName>
            <surname>Mayero</surname>
            <initial>M.</initial>
          </persName>
          <persName key="arenaire-2006-idm111960255408">
            <foreName>Guillaume</foreName>
            <surname>Melquiond</surname>
            <initial>G.</initial>
          </persName>
          <persName key="estime-2008-idm141604596704">
            <foreName>Pierre</foreName>
            <surname>Weis</surname>
            <initial>P.</initial>
          </persName>
        </author>
        <imprint>
          <biblScope type="number">RR-7826</biblScope>
          <publisher>
            <orgName type="institution">INRIA</orgName>
          </publisher>
          <dateStruct>
            <month>December</month>
            <year>2011</year>
          </dateStruct>
          <ref xlink:href="http://hal.inria.fr/hal-00649240/en/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://
          <allowbreak/>hal.
          <allowbreak/>inria.
          <allowbreak/>fr/
          <allowbreak/>hal-00649240/
          <allowbreak/>en/
          <allowbreak/></ref>
        </imprint>
      </monogr>
      <note type="typdoc">Rapport de recherche</note>
    </biblStruct>
    <biblStruct dedoublkey="5589" id="proval-2011-bid59" type="techreport" rend="year" n="cite:herms11rr">
      <identifiant type="hal" value="hal-00639977"/>
      <monogr>
        <title level="m">A Certified Multi-prover Verification Condition Generator</title>
        <author>
          <persName key="gallium-2009-idm362141100192">
            <foreName>Paolo</foreName>
            <surname>Herms</surname>
            <initial>P.</initial>
          </persName>
          <persName key="proval-2006-idm410174325056">
            <foreName>Claude</foreName>
            <surname>Marché</surname>
            <initial>C.</initial>
          </persName>
          <persName>
            <foreName>Benjamin</foreName>
            <surname>Monate</surname>
            <initial>B.</initial>
          </persName>
        </author>
        <imprint>
          <biblScope type="number">7793</biblScope>
          <publisher>
            <orgName type="institution">INRIA</orgName>
          </publisher>
          <dateStruct>
            <year>2011</year>
          </dateStruct>
          <ref xlink:href="http://hal.inria.fr/hal-00639977/en/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://
          <allowbreak/>hal.
          <allowbreak/>inria.
          <allowbreak/>fr/
          <allowbreak/>hal-00639977/
          <allowbreak/>en/
          <allowbreak/></ref>
        </imprint>
      </monogr>
      <note type="typdoc">Research Report</note>
    </biblStruct>
    <biblStruct dedoublkey="5659" id="proval-2011-bid67" type="techreport" rend="year" n="cite:kalyan11rr">
      <identifiant type="hal" value="inria-00615623"/>
      <monogr>
        <title level="m">Automated Generation of Loop Invariants using Predicate Abstraction</title>
        <author>
          <persName key="proval-2009-idm423377985664">
            <foreName>K.</foreName>
            <surname>Kalyanasundaram</surname>
            <initial>K.</initial>
          </persName>
          <persName key="proval-2006-idm410174325056">
            <foreName>Claude</foreName>
            <surname>Marché</surname>
            <initial>C.</initial>
          </persName>
        </author>
        <imprint>
          <biblScope type="number">7714</biblScope>
          <publisher>
            <orgName type="institution">INRIA</orgName>
          </publisher>
          <dateStruct>
            <month>August</month>
            <year>2011</year>
          </dateStruct>
          <ref xlink:href="http://hal.inria.fr/inria-00615623/en/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://
          <allowbreak/>hal.
          <allowbreak/>inria.
          <allowbreak/>fr/
          <allowbreak/>inria-00615623/
          <allowbreak/>en/
          <allowbreak/></ref>
        </imprint>
      </monogr>
      <note type="typdoc">Research Report</note>
    </biblStruct>
    <biblStruct dedoublkey="6042" id="proval-2011-bid85" type="techreport" rend="year" n="cite:MarMelMul11">
      <identifiant type="hal" value="ensl-00644408"/>
      <monogr>
        <title level="m">Some issues related to double roundings</title>
        <author>
          <persName key="arenaire-2009-idm499614619456">
            <foreName>Érik</foreName>
            <surname>Martin-Dorel</surname>
            <initial>É.</initial>
          </persName>
          <persName key="arenaire-2006-idm111960255408">
            <foreName>Guillaume</foreName>
            <surname>Melquiond</surname>
            <initial>G.</initial>
          </persName>
          <persName key="arenaire-2006-idm111960283664">
            <foreName>Jean-Michel</foreName>
            <surname>Muller</surname>
            <initial>J.-M.</initial>
          </persName>
        </author>
        <imprint>
          <dateStruct>
            <year>2011</year>
          </dateStruct>
          <ref xlink:href="http://hal-ens-lyon.archives-ouvertes.fr/ensl-00644408/en/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://
          <allowbreak/>hal-ens-lyon.
          <allowbreak/>archives-ouvertes.
          <allowbreak/>fr/
          <allowbreak/>ensl-00644408/
          <allowbreak/>en/
          <allowbreak/></ref>
        </imprint>
      </monogr>
      <note type="typdoc">Technical report</note>
    </biblStruct>
    <biblStruct dedoublkey="5979" id="proval-2011-bid74" type="techreport" rend="year" n="cite:nguyen11rr">
      <identifiant type="hal" value="inria-00602266"/>
      <monogr>
        <title level="m">Proving Floating-Point Numerical Programs by Analysis of their Assembly Code</title>
        <author>
          <persName key="cqfd-2007-idm193413639296">
            <foreName>Thi Minh Tuyen</foreName>
            <surname>Nguyen</surname>
            <initial>T. M. T.</initial>
          </persName>
          <persName key="proval-2006-idm410174325056">
            <foreName>Claude</foreName>
            <surname>Marché</surname>
            <initial>C.</initial>
          </persName>
        </author>
        <imprint>
          <biblScope type="number">7655</biblScope>
          <publisher>
            <orgName type="institution">INRIA</orgName>
          </publisher>
          <dateStruct>
            <year>2011</year>
          </dateStruct>
          <ref xlink:href="http://hal.inria.fr/inria-00602266/en/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://
          <allowbreak/>hal.
          <allowbreak/>inria.
          <allowbreak/>fr/
          <allowbreak/>inria-00602266/
          <allowbreak/>en/
          <allowbreak/></ref>
        </imprint>
      </monogr>
      <note type="typdoc">Research Report</note>
    </biblStruct>
    <biblStruct dedoublkey="5668" id="proval-2011-bid65" type="techreport" rend="year" n="cite:tafat11rr">
      <identifiant type="hal" value="inria-00636083"/>
      <monogr>
        <title level="m">Binary Heaps Formally Verified in Why3</title>
        <author>
          <persName>
            <foreName>Asma</foreName>
            <surname>Tafat</surname>
            <initial>A.</initial>
          </persName>
          <persName key="proval-2006-idm410174325056">
            <foreName>Claude</foreName>
            <surname>Marché</surname>
            <initial>C.</initial>
          </persName>
        </author>
        <imprint>
          <biblScope type="number">7780</biblScope>
          <publisher>
            <orgName type="institution">INRIA</orgName>
          </publisher>
          <dateStruct>
            <month>October</month>
            <year>2011</year>
          </dateStruct>
          <ref xlink:href="http://hal.inria.fr/inria-00636083/en/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://
          <allowbreak/>hal.
          <allowbreak/>inria.
          <allowbreak/>fr/
          <allowbreak/>inria-00636083/
          <allowbreak/>en/
          <allowbreak/></ref>
        </imprint>
      </monogr>
      <note type="typdoc">Research Report</note>
    </biblStruct>
    <biblStruct dedoublkey="5129" id="proval-2011-bid73" type="misc" rend="year" n="cite:BobotPaskevich2011">
      <monogr>
        <title level="m">Expressing Polymorphic Types in a Many-Sorted Language</title>
        <author>
          <persName key="proval-2008-idm220574959120">
            <foreName>François</foreName>
            <surname>Bobot</surname>
            <initial>F.</initial>
          </persName>
          <persName key="proval-2009-idm423378947776">
            <foreName>Andrei</foreName>
            <surname>Paskevich</surname>
            <initial>A.</initial>
          </persName>
        </author>
        <imprint>
          <dateStruct>
            <year>2011</year>
          </dateStruct>
        </imprint>
      </monogr>
    </biblStruct>
    <biblStruct dedoublkey="5164" id="proval-2011-bid60" type="misc" rend="year" n="cite:gasparcoq2011">
      <monogr>
        <title level="m">Mechanized Semantics into Concurrent Program verification</title>
        <author>
          <persName key="proval-2011-idm383373618768">
            <foreName>Nuno</foreName>
            <surname>Gaspar</surname>
            <initial>N.</initial>
          </persName>
        </author>
        <imprint>
          <dateStruct>
            <month>September</month>
            <year>2011</year>
          </dateStruct>
        </imprint>
      </monogr>
      <note type="howpublished">http://www.lri.fr/~gaspar/rgcoq.html</note>
    </biblStruct>
    <biblStruct dedoublkey="5056" id="proval-2011-bid82" type="mastersthesis" rend="year" n="cite:lelay11master">
      <monogr>
        <title level="m">Étude de la différentiabilité et de l'intégrabilité en Coq : Application à la formule de d'Alembert pour l'équation des ondes</title>
        <author>
          <persName key="proval-2011-idm383373655520">
            <foreName>Catherine</foreName>
            <surname>Lelay</surname>
            <initial>C.</initial>
          </persName>
        </author>
        <imprint>
          <publisher>
            <orgName type="school">Université Paris 7</orgName>
          </publisher>
          <dateStruct>
            <year>2011</year>
          </dateStruct>
        </imprint>
      </monogr>
      <note type="typdoc">Masters thesis</note>
    </biblStruct>
    <biblStruct id="proval-2011-bid21" type="phdthesis" rend="foot" n="footcite:andronick06these">
      <monogr>
        <title level="m">Modélisation et vérification formelles de systèmes embarqués dans les cartes à microprocessur. Plateforme Java Card et Système d'exploitation</title>
        <author>
          <persName key="proval-2006-idm410174297664">
            <foreName>June</foreName>
            <surname>Andronick</surname>
            <initial>J.</initial>
          </persName>
        </author>
        <imprint>
          <publisher>
            <orgName type="school">Université Paris-Sud</orgName>
          </publisher>
          <dateStruct>
            <month>March</month>
            <year>2006</year>
          </dateStruct>
          <ref xlink:href="http://ssrg.nicta.com.au/publications/papers/Andronick:phd.abstract?bib=login" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://
          <allowbreak/>ssrg.
          <allowbreak/>nicta.
          <allowbreak/>com.
          <allowbreak/>au/
          <allowbreak/>publications/
          <allowbreak/>papers/
          <allowbreak/>Andronick:phd.
          <allowbreak/>abstract?bib=login</ref>
        </imprint>
      </monogr>
      <note type="typdoc">Thèse de Doctorat</note>
    </biblStruct>
    <biblStruct id="proval-2011-bid20" type="inproceedings" rend="foot" n="footcite:andronick05">
      <analytic>
        <title level="a">Formal Verification of Security Properties of Smart Card Embedded Source Code</title>
        <author>
          <persName key="proval-2006-idm410174297664">
            <foreName>June</foreName>
            <surname>Andronick</surname>
            <initial>J.</initial>
          </persName>
          <persName>
            <foreName>Boutheina</foreName>
            <surname>Chetali</surname>
            <initial>B.</initial>
          </persName>
          <persName key="proval-2008-idm220575009344">
            <foreName>Christine</foreName>
            <surname>Paulin-Mohring</surname>
            <initial>C.</initial>
          </persName>
        </author>
      </analytic>
      <monogr>
        <editor role="editor">
          <persName>
            <foreName>John</foreName>
            <surname>Fitzgerald</surname>
            <initial>J.</initial>
          </persName>
          <persName>
            <foreName>Ian J.</foreName>
            <surname>Hayes</surname>
            <initial>I. J.</initial>
          </persName>
          <persName>
            <foreName>Andrzej</foreName>
            <surname>Tarlecki</surname>
            <initial>A.</initial>
          </persName>
        </editor>
        <title level="m">International Symposium of Formal Methods Europe (FM'05)</title>
        <loc>Newcastle,UK</loc>
        <title level="s">Lecture Notes in Computer Science</title>
        <imprint>
          <biblScope type="volume">3582</biblScope>
          <publisher>
            <orgName>Springer</orgName>
          </publisher>
          <dateStruct>
            <month>July</month>
            <year>2005</year>
          </dateStruct>
          <ref xlink:href="http://www.springerlink.com/content/eulj9pbgm2875cer/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://
          <allowbreak/>www.
          <allowbreak/>springerlink.
          <allowbreak/>com/
          <allowbreak/>content/
          <allowbreak/>eulj9pbgm2875cer/
          <allowbreak/></ref>
        </imprint>
      </monogr>
    </biblStruct>
    <biblStruct id="proval-2011-bid45" type="article" rend="foot" n="footcite:arts2000tcs">
      <analytic>
        <title level="a">Termination of term rewriting using dependency pairs</title>
        <author>
          <persName>
            <foreName>Thomas</foreName>
            <surname>Arts</surname>
            <initial>T.</initial>
          </persName>
          <persName>
            <foreName>Jürgen</foreName>
            <surname>Giesl</surname>
            <initial>J.</initial>
          </persName>
        </author>
      </analytic>
      <monogr>
        <title level="j">Theoretical Computer Science</title>
        <imprint>
          <biblScope type="volume">236</biblScope>
          <dateStruct>
            <year>2000</year>
          </dateStruct>
          <biblScope type="pages">133–178</biblScope>
        </imprint>
      </monogr>
    </biblStruct>
    <biblStruct id="proval-2011-bid7" type="article" rend="foot" n="footcite:audebaud07scp">
      <identifiant type="hal" value="inria-00431771"/>
      <analytic>
        <title level="a">Proofs of Randomized Algorithms in Coq</title>
        <author>
          <persName key="marelle-2006-idm415677239888">
            <foreName>Philippe</foreName>
            <surname>Audebaud</surname>
            <initial>P.</initial>
          </persName>
          <persName key="proval-2008-idm220575009344">
            <foreName>Christine</foreName>
            <surname>Paulin-Mohring</surname>
            <initial>C.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-editorial-board="yes" x-international-audience="yes">
        <title level="j">Science of Computer Programming</title>
        <imprint>
          <biblScope type="volume">74</biblScope>
          <biblScope type="number">8</biblScope>
          <dateStruct>
            <year>2009</year>
          </dateStruct>
          <biblScope type="pages">568–589</biblScope>
          <ref xlink:href="http://hal.inria.fr/inria-00431771/en/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://
          <allowbreak/>hal.
          <allowbreak/>inria.
          <allowbreak/>fr/
          <allowbreak/>inria-00431771/
          <allowbreak/>en/
          <allowbreak/></ref>
        </imprint>
      </monogr>
    </biblStruct>
    <biblStruct id="proval-2011-bid50" type="inproceedings" rend="foot" n="footcite:filliatre10-opencert">
      <analytic>
        <title level="a">A Deductive Verification Platform for Cryptographic Software</title>
        <author>
          <persName>
            <foreName>M.</foreName>
            <surname>Barbosa</surname>
            <initial>M.</initial>
          </persName>
          <persName key="proval-2006-idm410174303696">
            <foreName>Jean-Christophe</foreName>
            <surname>Filliâtre</surname>
            <initial>J.-C.</initial>
          </persName>
          <persName>
            <foreName>J. Sousa</foreName>
            <surname>Pinto</surname>
            <initial>J. S.</initial>
          </persName>
          <persName>
            <foreName>B.</foreName>
            <surname>Vieira</surname>
            <initial>B.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-international-audience="yes" x-proceedings="yes">
        <title level="m">4th International Workshop on Foundations and Techniques for Open Source Software Certification (OpenCert 2010)</title>
        <loc>Pisa, Italy</loc>
        <imprint>
          <biblScope type="volume">33</biblScope>
          <publisher>
            <orgName>Electronic Communications of the EASST</orgName>
          </publisher>
          <dateStruct>
            <month>September</month>
            <year>2010</year>
          </dateStruct>
          <ref xlink:href="http://journal.ub.tu-berlin.de/index.php/eceasst/article/view/461" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://
          <allowbreak/>journal.
          <allowbreak/>ub.
          <allowbreak/>tu-berlin.
          <allowbreak/>de/
          <allowbreak/>index.
          <allowbreak/>php/
          <allowbreak/>eceasst/
          <allowbreak/>article/
          <allowbreak/>view/
          <allowbreak/>461</ref>
        </imprint>
      </monogr>
      <affiliation>
        <country>PT</country>
      </affiliation>
    </biblStruct>
    <biblStruct id="proval-2011-bid52" type="inproceedings" rend="foot" n="footcite:mlpost09jfla">
      <analytic>
        <title level="a">Faire bonne figure avec Mlpost</title>
        <author>
          <persName key="proval-2007-idm172231421920">
            <foreName>Romain</foreName>
            <surname>Bardou</surname>
            <initial>R.</initial>
          </persName>
          <persName key="proval-2006-idm410174303696">
            <foreName>Jean-Christophe</foreName>
            <surname>Filliâtre</surname>
            <initial>J.-C.</initial>
          </persName>
          <persName key="proval-2006-idm410173277088">
            <foreName>Johannes</foreName>
            <surname>Kanig</surname>
            <initial>J.</initial>
          </persName>
          <persName key="proval-2006-idm410173274400">
            <foreName>Stéphane</foreName>
            <surname>Lescuyer</surname>
            <initial>S.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-international-audience="no" x-proceedings="yes">
        <title level="m">Vingtièmes Journées Francophones des Langages Applicatifs</title>
        <loc>Saint-Quentin sur Isère</loc>
        <imprint>
          <publisher>
            <orgName>INRIA</orgName>
          </publisher>
          <dateStruct>
            <month>January</month>
            <year>2009</year>
          </dateStruct>
          <ref xlink:href="http://www.lri.fr/~filliatr/ftp/publis/mlpost-fra.pdf" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://
          <allowbreak/>www.
          <allowbreak/>lri.
          <allowbreak/>fr/
          <allowbreak/>~filliatr/
          <allowbreak/>ftp/
          <allowbreak/>publis/
          <allowbreak/>mlpost-fra.
          <allowbreak/>pdf</ref>
        </imprint>
      </monogr>
    </biblStruct>
    <biblStruct id="proval-2011-bid41" type="inproceedings" rend="foot" n="footcite:barras98types">
      <analytic>
        <title level="a">Verification of the Interface of a Small Proof System in Coq</title>
        <author>
          <persName key="logical-2006-idm356512393168">
            <foreName>Bruno</foreName>
            <surname>Barras</surname>
            <initial>B.</initial>
          </persName>
        </author>
      </analytic>
      <monogr>
        <editor role="editor">
          <persName>
            <foreName>Eduardo</foreName>
            <surname>Giménez</surname>
            <initial>E.</initial>
          </persName>
          <persName key="proval-2008-idm220575009344">
            <foreName>Christine</foreName>
            <surname>Paulin-Mohring</surname>
            <initial>C.</initial>
          </persName>
        </editor>
        <title level="m">Types for Proofs and Programs, International Workshop TYPES'96, Aussois, France, December 15-19, 1996, Selected Papers</title>
        <title level="s">Lecture Notes in Computer Science</title>
        <imprint>
          <biblScope type="volume">1512</biblScope>
          <publisher>
            <orgName>Springer</orgName>
          </publisher>
          <dateStruct>
            <year>1998</year>
          </dateStruct>
          <biblScope type="pages">28-45</biblScope>
        </imprint>
      </monogr>
    </biblStruct>
    <biblStruct id="proval-2011-bid58" type="inproceedings" rend="foot" n="footcite:barthe09popl">
      <analytic>
        <title level="a">Formal certification of code-based cryptographic proofs</title>
        <author>
          <persName key="everest-2006-idm306718613568">
            <foreName>Gilles</foreName>
            <surname>Barthe</surname>
            <initial>G.</initial>
          </persName>
          <persName key="everest-2006-idm306718606528">
            <foreName>Benjamin</foreName>
            <surname>Grégoire</surname>
            <initial>B.</initial>
          </persName>
          <persName>
            <foreName>Santiago Zanella</foreName>
            <surname>Béguelin</surname>
            <initial>S. Z.</initial>
          </persName>
        </author>
      </analytic>
      <monogr>
        <editor role="editor">
          <persName>
            <foreName>Zhong</foreName>
            <surname>Shao</surname>
            <initial>Z.</initial>
          </persName>
          <persName>
            <foreName>Benjamin C.</foreName>
            <surname>Pierce</surname>
            <initial>B. C.</initial>
          </persName>
        </editor>
        <title level="m">POPL</title>
        <loc>Savannah, GA, USA</loc>
        <imprint>
          <publisher>
            <orgName>ACM Press</orgName>
          </publisher>
          <dateStruct>
            <month>January</month>
            <year>2009</year>
          </dateStruct>
          <biblScope type="pages">90-101</biblScope>
        </imprint>
      </monogr>
    </biblStruct>
    <biblStruct id="proval-2011-bid14" type="manual" rend="foot" n="footcite:baudin09acsl">
      <monogr>
        <title level="m">ACSL: ANSI/ISO C Specification Language, version 1.4</title>
        <author>
          <persName>
            <foreName>Patrick</foreName>
            <surname>Baudin</surname>
            <initial>P.</initial>
          </persName>
          <persName key="proval-2006-idm410174303696">
            <foreName>Jean-Christophe</foreName>
            <surname>Filliâtre</surname>
            <initial>J.-C.</initial>
          </persName>
          <persName key="proval-2006-idm410174325056">
            <foreName>Claude</foreName>
            <surname>Marché</surname>
            <initial>C.</initial>
          </persName>
          <persName>
            <foreName>Benjamin</foreName>
            <surname>Monate</surname>
            <initial>B.</initial>
          </persName>
          <persName key="proval-2006-idm410174289696">
            <foreName>Yannick</foreName>
            <surname>Moy</surname>
            <initial>Y.</initial>
          </persName>
          <persName key="gallium-2006-idm16698250064">
            <foreName>Virgile</foreName>
            <surname>Prevosto</surname>
            <initial>V.</initial>
          </persName>
        </author>
        <imprint>
          <dateStruct>
            <year>2009</year>
          </dateStruct>
          <ref xlink:href="http://frama-c.cea.fr/acsl.html" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://
          <allowbreak/>frama-c.
          <allowbreak/>cea.
          <allowbreak/>fr/
          <allowbreak/>acsl.
          <allowbreak/>html</ref>
        </imprint>
      </monogr>
    </biblStruct>
    <biblStruct id="proval-2011-bid9" type="inproceedings" rend="foot" n="footcite:Bol06">
      <analytic>
        <title level="a">Pitfalls of a full floating-point proof: example on the formal proof of the Veltkamp/Dekker algorithms</title>
        <author>
          <persName key="proval-2006-idm410174308976">
            <foreName>Sylvie</foreName>
            <surname>Boldo</surname>
            <initial>S.</initial>
          </persName>
        </author>
      </analytic>
      <monogr>
        <editor role="editor">
          <persName>
            <foreName>Ulrich</foreName>
            <surname>Furbach</surname>
            <initial>U.</initial>
          </persName>
          <persName>
            <foreName>Natarajan</foreName>
            <surname>Shankar</surname>
            <initial>N.</initial>
          </persName>
        </editor>
        <title level="m">Third International Joint Conference on Automated Reasoning</title>
        <loc>Seattle, USA</loc>
        <title level="s">Lecture Notes in Computer Science</title>
        <imprint>
          <biblScope type="volume">4130</biblScope>
          <publisher>
            <orgName>Springer</orgName>
          </publisher>
          <dateStruct>
            <month>August</month>
            <year>2006</year>
          </dateStruct>
          <biblScope type="pages">52-66</biblScope>
          <ref xlink:href="http://www.springerlink.com/content/524v5246177t0877/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://
          <allowbreak/>www.
          <allowbreak/>springerlink.
          <allowbreak/>com/
          <allowbreak/>content/
          <allowbreak/>524v5246177t0877/
          <allowbreak/></ref>
        </imprint>
      </monogr>
    </biblStruct>
    <biblStruct id="proval-2011-bid81" type="inproceedings" rend="foot" n="footcite:boldo09icalp">
      <analytic>
        <title level="a">Floats &amp; Ropes: a case study for formal numerical program verification</title>
        <author>
          <persName key="proval-2006-idm410174308976">
            <foreName>Sylvie</foreName>
            <surname>Boldo</surname>
            <initial>S.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-international-audience="yes" x-proceedings="yes">
        <title level="m">36th International Colloquium on Automata, Languages and Programming</title>
        <loc>Rhodos, Greece</loc>
        <title level="s">Lecture Notes in Computer Science - ARCoSS</title>
        <imprint>
          <biblScope type="volume">5556</biblScope>
          <publisher>
            <orgName>Springer</orgName>
          </publisher>
          <dateStruct>
            <month>July</month>
            <year>2009</year>
          </dateStruct>
          <biblScope type="pages">91–102</biblScope>
        </imprint>
      </monogr>
    </biblStruct>
    <biblStruct id="proval-2011-bid80" type="inproceedings" rend="foot" n="footcite:boldo10-itp">
      <identifiant type="hal" value="inria-00450789"/>
      <analytic>
        <title level="a">Formal Proof of a Wave Equation Resolution Scheme: the Method Error</title>
        <author>
          <persName key="proval-2006-idm410174308976">
            <foreName>Sylvie</foreName>
            <surname>Boldo</surname>
            <initial>S.</initial>
          </persName>
          <persName key="estime-2006-idm273297399856">
            <foreName>François</foreName>
            <surname>Clément</surname>
            <initial>F.</initial>
          </persName>
          <persName key="proval-2006-idm410174303696">
            <foreName>Jean-Christophe</foreName>
            <surname>Filliâtre</surname>
            <initial>J.-C.</initial>
          </persName>
          <persName key="arenaire-2009-idm499614616432">
            <foreName>Micaela</foreName>
            <surname>Mayero</surname>
            <initial>M.</initial>
          </persName>
          <persName key="arenaire-2006-idm111960255408">
            <foreName>Guillaume</foreName>
            <surname>Melquiond</surname>
            <initial>G.</initial>
          </persName>
          <persName key="estime-2008-idm141604596704">
            <foreName>Pierre</foreName>
            <surname>Weis</surname>
            <initial>P.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-international-audience="yes" x-proceedings="yes">
        <editor role="editor">
          <persName>
            <foreName>Matt</foreName>
            <surname>Kaufmann</surname>
            <initial>M.</initial>
          </persName>
          <persName>
            <foreName>Lawrence C.</foreName>
            <surname>Paulson</surname>
            <initial>L. C.</initial>
          </persName>
        </editor>
        <title level="m">Proceedings of the first Interactive Theorem Proving Conference</title>
        <loc>Edinburgh, Scotland</loc>
        <title level="s">LNCS</title>
        <imprint>
          <biblScope type="volume">6172</biblScope>
          <publisher>
            <orgName>Springer</orgName>
          </publisher>
          <dateStruct>
            <month>July</month>
            <year>2010</year>
          </dateStruct>
          <biblScope type="pages">147–162</biblScope>
          <ref xlink:href="http://hal.inria.fr/inria-00450789/en/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://
          <allowbreak/>hal.
          <allowbreak/>inria.
          <allowbreak/>fr/
          <allowbreak/>inria-00450789/
          <allowbreak/>en/
          <allowbreak/></ref>
        </imprint>
      </monogr>
    </biblStruct>
    <biblStruct id="proval-2011-bid16" type="inproceedings" rend="foot" n="footcite:bornat00mpc">
      <analytic>
        <title level="a">Proving Pointer Programs in Hoare Logic</title>
        <author>
          <persName>
            <foreName>Richard</foreName>
            <surname>Bornat</surname>
            <initial>R.</initial>
          </persName>
        </author>
      </analytic>
      <monogr>
        <title level="m">Mathematics of Program Construction</title>
        <imprint>
          <dateStruct>
            <year>2000</year>
          </dateStruct>
          <biblScope type="pages">102–126</biblScope>
        </imprint>
      </monogr>
    </biblStruct>
    <biblStruct id="proval-2011-bid24" type="techreport" rend="foot" n="footcite:chaudhary04demoney">
      <monogr>
        <title level="m">The Krakatoa tool for certification of Java/JavaCard programs annotated in JML : A Case Study</title>
        <author>
          <persName>
            <foreName>Vikrant</foreName>
            <surname>Chaudhary</surname>
            <initial>V.</initial>
          </persName>
        </author>
        <imprint>
          <publisher>
            <orgName type="institution">IIT internship report</orgName>
          </publisher>
          <dateStruct>
            <month>July</month>
            <year>2004</year>
          </dateStruct>
        </imprint>
      </monogr>
      <note type="typdoc">Technical report</note>
    </biblStruct>
    <biblStruct id="proval-2011-bid36" type="article" rend="foot" n="footcite:conchon06tcs">
      <analytic>
        <title level="a">Strategies for Combining Decision Procedures</title>
        <author>
          <persName key="proval-2006-idm410174301040">
            <foreName>Sylvain</foreName>
            <surname>Conchon</surname>
            <initial>S.</initial>
          </persName>
          <persName>
            <foreName>Sava</foreName>
            <surname>Krstić</surname>
            <initial>S.</initial>
          </persName>
        </author>
      </analytic>
      <monogr>
        <title level="j">Theoretical Computer Science</title>
        <imprint>
          <biblScope type="volume">354</biblScope>
          <biblScope type="number">2</biblScope>
          <dateStruct>
            <year>2006</year>
          </dateStruct>
          <biblScope type="pages">187–210</biblScope>
        </imprint>
      </monogr>
    </biblStruct>
    <biblStruct id="proval-2011-bid42" type="inproceedings" rend="foot" n="footcite:contejean05cade">
      <analytic>
        <title level="a">Reflecting Proofs in First-Order Logic with Equality</title>
        <author>
          <persName key="proval-2006-idm410174306336">
            <foreName>Évelyne</foreName>
            <surname>Contejean</surname>
            <initial>É.</initial>
          </persName>
          <persName>
            <foreName>Pierre</foreName>
            <surname>Corbineau</surname>
            <initial>P.</initial>
          </persName>
        </author>
      </analytic>
      <monogr>
        <editor role="editor">
          <persName>
            <foreName>Robert</foreName>
            <surname>Nieuwenhuis</surname>
            <initial>R.</initial>
          </persName>
        </editor>
        <title level="m">20th International Conference on Automated Deduction (CADE-20)</title>
        <loc>Tallinn, Estonia</loc>
        <title level="s">Lecture Notes in Artificial Intelligence</title>
        <imprint>
          <biblScope type="volume">3632</biblScope>
          <publisher>
            <orgName>Springer</orgName>
          </publisher>
          <dateStruct>
            <month>July</month>
            <year>2005</year>
          </dateStruct>
          <biblScope type="pages">7–22</biblScope>
        </imprint>
      </monogr>
    </biblStruct>
    <biblStruct id="proval-2011-bid43" type="techreport" rend="foot" n="footcite:contejean07rr">
      <monogr>
        <title level="m">Certification of automated termination proofs</title>
        <author>
          <persName key="proval-2006-idm410174306336">
            <foreName>Évelyne</foreName>
            <surname>Contejean</surname>
            <initial>É.</initial>
          </persName>
          <persName key="toccata-2012-idm273573193936">
            <foreName>Pierre</foreName>
            <surname>Courtieu</surname>
            <initial>P.</initial>
          </persName>
          <persName key="everest-2006-idm306718578960">
            <foreName>Julien</foreName>
            <surname>Forest</surname>
            <initial>J.</initial>
          </persName>
          <persName>
            <foreName>Olivier</foreName>
            <surname>Pons</surname>
            <initial>O.</initial>
          </persName>
          <persName key="proval-2009-idm423378944592">
            <foreName>Xavier</foreName>
            <surname>Urbain</surname>
            <initial>X.</initial>
          </persName>
        </author>
        <imprint>
          <biblScope type="number">1185</biblScope>
          <publisher>
            <orgName type="institution">CEDRIC</orgName>
          </publisher>
          <dateStruct>
            <month>May</month>
            <year>2007</year>
          </dateStruct>
        </imprint>
      </monogr>
      <note type="typdoc">Research Report</note>
    </biblStruct>
    <biblStruct id="proval-2011-bid30" type="article" rend="foot" n="footcite:contejean05jar">
      <identifiant type="doi" value="10.1007/s10817-005-9022-x"/>
      <analytic>
        <title level="a">Mechanically proving termination using polynomial interpretations</title>
        <author>
          <persName key="proval-2006-idm410174306336">
            <foreName>Évelyne</foreName>
            <surname>Contejean</surname>
            <initial>É.</initial>
          </persName>
          <persName key="proval-2006-idm410174325056">
            <foreName>Claude</foreName>
            <surname>Marché</surname>
            <initial>C.</initial>
          </persName>
          <persName>
            <foreName>Ana Paula</foreName>
            <surname>Tomás</surname>
            <initial>A. P.</initial>
          </persName>
          <persName key="proval-2009-idm423378944592">
            <foreName>Xavier</foreName>
            <surname>Urbain</surname>
            <initial>X.</initial>
          </persName>
        </author>
      </analytic>
      <monogr>
        <title level="j">Journal of Automated Reasoning</title>
        <imprint>
          <biblScope type="volume">34</biblScope>
          <biblScope type="number">4</biblScope>
          <dateStruct>
            <year>2005</year>
          </dateStruct>
          <biblScope type="pages">325–363</biblScope>
          <ref xlink:href="http://dx.doi.org/10.1007/s10817-005-9022-x" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://
          <allowbreak/>dx.
          <allowbreak/>doi.
          <allowbreak/>org/
          <allowbreak/>10.
          <allowbreak/>1007/
          <allowbreak/>s10817-005-9022-x</ref>
        </imprint>
      </monogr>
    </biblStruct>
    <biblStruct id="proval-2011-bid39" type="techreport" rend="foot" n="footcite:couchot08report">
      <identifiant type="hal" value="inria-00339847"/>
      <monogr>
        <title level="m">Graph-based Reduction of Program Verification Conditions</title>
        <author>
          <persName key="cassis-2006-idm380671539728">
            <foreName>Jean-François</foreName>
            <surname>Couchot</surname>
            <initial>J.-F.</initial>
          </persName>
          <persName key="cassis-2006-idm380671564848">
            <foreName>Alain</foreName>
            <surname>Giorgetti</surname>
            <initial>A.</initial>
          </persName>
          <persName key="proval-2007-idm172231445184">
            <foreName>Nicolas</foreName>
            <surname>Stouls</surname>
            <initial>N.</initial>
          </persName>
        </author>
        <imprint>
          <biblScope type="number">6702</biblScope>
          <publisher>
            <orgName type="institution">INRIA Saclay – Île-de-France</orgName>
          </publisher>
          <dateStruct>
            <month>October</month>
            <year>2008</year>
          </dateStruct>
          <ref xlink:href="http://hal.inria.fr/inria-00339847/en/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://
          <allowbreak/>hal.
          <allowbreak/>inria.
          <allowbreak/>fr/
          <allowbreak/>inria-00339847/
          <allowbreak/>en/
          <allowbreak/></ref>
        </imprint>
      </monogr>
      <note type="typdoc">Research Report</note>
    </biblStruct>
    <biblStruct id="proval-2011-bid38" type="inproceedings" rend="foot" n="footcite:couchot07cade">
      <analytic>
        <title level="a">Handling Polymorphism in Automated Deduction</title>
        <author>
          <persName key="cassis-2006-idm380671539728">
            <foreName>Jean-François</foreName>
            <surname>Couchot</surname>
            <initial>J.-F.</initial>
          </persName>
          <persName key="proval-2006-idm410173274400">
            <foreName>Stéphane</foreName>
            <surname>Lescuyer</surname>
            <initial>S.</initial>
          </persName>
        </author>
      </analytic>
      <monogr>
        <title level="m">21th International Conference on Automated Deduction (CADE-21)</title>
        <loc>Bremen, Germany</loc>
        <title level="s">LNCS (LNAI)</title>
        <imprint>
          <biblScope type="volume">4603</biblScope>
          <dateStruct>
            <month>July</month>
            <year>2007</year>
          </dateStruct>
          <biblScope type="pages">263–278</biblScope>
        </imprint>
      </monogr>
    </biblStruct>
    <biblStruct id="proval-2011-bid56" type="article" rend="foot" n="footcite:daumas09toms">
      <identifiant type="hal" value="inria-00534350"/>
      <analytic>
        <title level="a">Certification of bounds on expressions involving rounded operators</title>
        <author>
          <persName>
            <foreName>Marc</foreName>
            <surname>Daumas</surname>
            <initial>M.</initial>
          </persName>
          <persName key="arenaire-2006-idm111960255408">
            <foreName>Guillaume</foreName>
            <surname>Melquiond</surname>
            <initial>G.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-editorial-board="yes" x-international-audience="yes">
        <title level="j">Transactions on Mathematical Software</title>
        <imprint>
          <biblScope type="volume">37</biblScope>
          <biblScope type="number">1</biblScope>
          <dateStruct>
            <year>2010</year>
          </dateStruct>
          <ref xlink:href="http://hal.archives-ouvertes.fr/inria-00534350/fr/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://
          <allowbreak/>hal.
          <allowbreak/>archives-ouvertes.
          <allowbreak/>fr/
          <allowbreak/>inria-00534350/
          <allowbreak/>fr/
          <allowbreak/></ref>
        </imprint>
      </monogr>
    </biblStruct>
    <biblStruct id="proval-2011-bid32" type="inproceedings" rend="foot" n="footcite:duran04pepm">
      <analytic>
        <title level="a">Proving Termination of Membership Equational Programs</title>
        <author>
          <persName>
            <foreName>Francisco</foreName>
            <surname>Durán</surname>
            <initial>F.</initial>
          </persName>
          <persName>
            <foreName>Salvador</foreName>
            <surname>Lucas</surname>
            <initial>S.</initial>
          </persName>
          <persName>
            <foreName>José</foreName>
            <surname>Meseguer</surname>
            <initial>J.</initial>
          </persName>
          <persName key="proval-2006-idm410174325056">
            <foreName>Claude</foreName>
            <surname>Marché</surname>
            <initial>C.</initial>
          </persName>
          <persName key="proval-2009-idm423378944592">
            <foreName>Xavier</foreName>
            <surname>Urbain</surname>
            <initial>X.</initial>
          </persName>
        </author>
      </analytic>
      <monogr>
        <title level="m">ACM SIGPLAN 2004 Symposium on Partial Evaluation and Program Manipulation</title>
        <loc>Verona, Italy</loc>
        <imprint>
          <publisher>
            <orgName>ACM Press</orgName>
          </publisher>
          <dateStruct>
            <month>August</month>
            <year>2004</year>
          </dateStruct>
        </imprint>
      </monogr>
    </biblStruct>
    <biblStruct id="proval-2011-bid11" type="article" rend="foot" n="footcite:filliatre99c">
      <analytic>
        <title level="a">Formal Proof of a Program: Find</title>
        <author>
          <persName key="proval-2006-idm410174303696">
            <foreName>Jean-Christophe</foreName>
            <surname>Filliâtre</surname>
            <initial>J.-C.</initial>
          </persName>
        </author>
      </analytic>
      <monogr>
        <title level="j">Science of Computer Programming</title>
        <imprint>
          <biblScope type="volume">64</biblScope>
          <dateStruct>
            <year>2006</year>
          </dateStruct>
          <biblScope type="pages">332–240</biblScope>
          <ref xlink:href="http://www.lri.fr/~filliatr/ftp/publis/find.pdf" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://
          <allowbreak/>www.
          <allowbreak/>lri.
          <allowbreak/>fr/
          <allowbreak/>~filliatr/
          <allowbreak/>ftp/
          <allowbreak/>publis/
          <allowbreak/>find.
          <allowbreak/>pdf</ref>
        </imprint>
      </monogr>
    </biblStruct>
    <biblStruct id="proval-2011-bid64" type="inproceedings" rend="foot" n="footcite:filliatre12vstte">
      <analytic>
        <title level="a">Verifying Two Lines of C with Why3: an Exercise in Program Verification</title>
        <author>
          <persName key="proval-2006-idm410174303696">
            <foreName>Jean-Christophe</foreName>
            <surname>Filliâtre</surname>
            <initial>J.-C.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-international-audience="yes" x-proceedings="yes">
        <title level="m">Verified Software: Theories, Tools and Experiments (VSTTE)</title>
        <loc>Philadelphia, USA</loc>
        <imprint>
          <dateStruct>
            <month>January</month>
            <year>2012</year>
          </dateStruct>
          <ref xlink:href="http://why3.lri.fr/queens/queens.pdf" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://
          <allowbreak/>why3.
          <allowbreak/>lri.
          <allowbreak/>fr/
          <allowbreak/>queens/
          <allowbreak/>queens.
          <allowbreak/>pdf</ref>
        </imprint>
      </monogr>
    </biblStruct>
    <biblStruct id="proval-2011-bid34" type="inproceedings" rend="foot" n="footcite:filliatr01icscav">
      <analytic>
        <title level="a">ICS: Integrated Canonization and Solving (Tool presentation)</title>
        <author>
          <persName key="proval-2006-idm410174303696">
            <foreName>Jean-Christophe</foreName>
            <surname>Filliâtre</surname>
            <initial>J.-C.</initial>
          </persName>
          <persName>
            <foreName>Sam</foreName>
            <surname>Owre</surname>
            <initial>S.</initial>
          </persName>
          <persName>
            <foreName>Harald</foreName>
            <surname>Rueß</surname>
            <initial>H.</initial>
          </persName>
          <persName>
            <foreName>Natarajan</foreName>
            <surname>Shankar</surname>
            <initial>N.</initial>
          </persName>
        </author>
      </analytic>
      <monogr>
        <editor role="editor">
          <persName key="indes-2009-idm16396292736">
            <foreName>G.</foreName>
            <surname>Berry</surname>
            <initial>G.</initial>
          </persName>
          <persName>
            <foreName>H.</foreName>
            <surname>Comon</surname>
            <initial>H.</initial>
          </persName>
          <persName>
            <foreName>A.</foreName>
            <surname>Finkel</surname>
            <initial>A.</initial>
          </persName>
        </editor>
        <title level="m">Proceedings of CAV'2001</title>
        <title level="s">Lecture Notes in Computer Science</title>
        <imprint>
          <biblScope type="volume">2102</biblScope>
          <publisher>
            <orgName>Springer</orgName>
          </publisher>
          <dateStruct>
            <year>2001</year>
          </dateStruct>
          <biblScope type="pages">246–249</biblScope>
        </imprint>
      </monogr>
    </biblStruct>
    <biblStruct id="proval-2011-bid49" type="inproceedings" rend="foot" n="footcite:gerlach10prefoveoos">
      <analytic>
        <title level="a">An Experience Report on the Verification of Algorithms in the C++ Standard Library using Frama-C</title>
        <author>
          <persName>
            <foreName>Jens</foreName>
            <surname>Gerlach</surname>
            <initial>J.</initial>
          </persName>
          <persName>
            <foreName>Jochen</foreName>
            <surname>Burghardt</surname>
            <initial>J.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-international-audience="yes" x-proceedings="yes">
        <editor role="editor">
          <persName>
            <foreName>Bernhard</foreName>
            <surname>Beckert</surname>
            <initial>B.</initial>
          </persName>
          <persName key="proval-2006-idm410174325056">
            <foreName>Claude</foreName>
            <surname>Marché</surname>
            <initial>C.</initial>
          </persName>
        </editor>
        <title level="m">Formal Verification of Object-Oriented Software, Papers Presented at the International Conference</title>
        <loc>Paris, France</loc>
        <title level="s">Karlsruhe Reports in Informatics</title>
        <imprint>
          <dateStruct>
            <month>June</month>
            <year>2010</year>
          </dateStruct>
          <biblScope type="pages">191–204</biblScope>
        </imprint>
      </monogr>
      <affiliation>
        <country>DE</country>
      </affiliation>
    </biblStruct>
    <biblStruct id="proval-2011-bid46" type="inproceedings" rend="foot" n="footcite:gramlich96rta">
      <analytic>
        <title level="a">On Proving Termination by Innermost Termination</title>
        <author>
          <persName>
            <foreName>Bernhard</foreName>
            <surname>Gramlich</surname>
            <initial>B.</initial>
          </persName>
        </author>
      </analytic>
      <monogr>
        <editor role="editor">
          <persName>
            <foreName>Harald</foreName>
            <surname>Ganzinger</surname>
            <initial>H.</initial>
          </persName>
        </editor>
        <title level="m">7th International Conference on Rewriting Techniques and Applications</title>
        <loc>New Brunswick, NJ, USA</loc>
        <title level="s">Lecture Notes in Computer Science</title>
        <imprint>
          <biblScope type="volume">1103</biblScope>
          <publisher>
            <orgName>Springer</orgName>
          </publisher>
          <dateStruct>
            <month>July</month>
            <year>1996</year>
          </dateStruct>
          <biblScope type="pages">93–107</biblScope>
        </imprint>
      </monogr>
    </biblStruct>
    <biblStruct id="proval-2011-bid19" type="phdthesis" rend="foot" n="footcite:hubert2008these">
      <monogr>
        <title level="m">Analyse Statique et preuve de Programmes Industriels Critiques</title>
        <author>
          <persName key="proval-2006-idm410174292368">
            <foreName>Thierry</foreName>
            <surname>Hubert</surname>
            <initial>T.</initial>
          </persName>
        </author>
        <imprint>
          <publisher>
            <orgName type="school">Université Paris-Sud</orgName>
          </publisher>
          <dateStruct>
            <month>June</month>
            <year>2008</year>
          </dateStruct>
          <ref xlink:href="http://www.lri.fr/~marche/hubert08these.pdf" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://
          <allowbreak/>www.
          <allowbreak/>lri.
          <allowbreak/>fr/
          <allowbreak/>~marche/
          <allowbreak/>hubert08these.
          <allowbreak/>pdf</ref>
        </imprint>
      </monogr>
      <note type="typdoc">Thèse de Doctorat</note>
    </biblStruct>
    <biblStruct id="proval-2011-bid18" type="inproceedings" rend="foot" n="footcite:hubert07hav">
      <analytic>
        <title level="a">Separation Analysis for Deductive Verification</title>
        <author>
          <persName key="proval-2006-idm410174292368">
            <foreName>Thierry</foreName>
            <surname>Hubert</surname>
            <initial>T.</initial>
          </persName>
          <persName key="proval-2006-idm410174325056">
            <foreName>Claude</foreName>
            <surname>Marché</surname>
            <initial>C.</initial>
          </persName>
        </author>
      </analytic>
      <monogr>
        <title level="m">Heap Analysis and Verification (HAV'07)</title>
        <loc>Braga, Portugal</loc>
        <imprint>
          <dateStruct>
            <month>March</month>
            <year>2007</year>
          </dateStruct>
          <biblScope type="pages">81–93</biblScope>
          <ref xlink:href="http://www.lri.fr/~marche/hubert07hav.pdf" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://
          <allowbreak/>www.
          <allowbreak/>lri.
          <allowbreak/>fr/
          <allowbreak/>~marche/
          <allowbreak/>hubert07hav.
          <allowbreak/>pdf</ref>
        </imprint>
      </monogr>
    </biblStruct>
    <biblStruct id="proval-2011-bid23" type="inproceedings" rend="foot" n="footcite:jacobs04amast">
      <analytic>
        <title level="a">Formal Verification of a Commercial Smart Card Applet with Multiple Tools</title>
        <author>
          <persName>
            <foreName>Bart</foreName>
            <surname>Jacobs</surname>
            <initial>B.</initial>
          </persName>
          <persName key="proval-2006-idm410174325056">
            <foreName>Claude</foreName>
            <surname>Marché</surname>
            <initial>C.</initial>
          </persName>
          <persName>
            <foreName>Nicole</foreName>
            <surname>Rauch</surname>
            <initial>N.</initial>
          </persName>
        </author>
      </analytic>
      <monogr>
        <title level="m">Algebraic Methodology and Software Technology</title>
        <loc>Stirling, UK</loc>
        <title level="s">Lecture Notes in Computer Science</title>
        <imprint>
          <biblScope type="volume">3116</biblScope>
          <publisher>
            <orgName>Springer</orgName>
          </publisher>
          <dateStruct>
            <month>July</month>
            <year>2004</year>
          </dateStruct>
        </imprint>
      </monogr>
    </biblStruct>
    <biblStruct id="proval-2011-bid0" type="inproceedings" rend="foot" n="footcite:leino10vstte">
      <analytic>
        <title level="a">VACID-0: Verification of Ample Correctness of Invariants of Data-structures, Edition 0</title>
        <author>
          <persName>
            <foreName>K. Rustan M.</foreName>
            <surname>Leino</surname>
            <initial>K. R. M.</initial>
          </persName>
          <persName>
            <foreName>Michał</foreName>
            <surname>Moskal</surname>
            <initial>M.</initial>
          </persName>
        </author>
      </analytic>
      <monogr>
        <title level="m">Proceedings of Tools and Experiments Workshop at VSTTE</title>
        <imprint>
          <dateStruct>
            <year>2010</year>
          </dateStruct>
        </imprint>
      </monogr>
    </biblStruct>
    <biblStruct id="proval-2011-bid83" type="inproceedings" rend="foot" n="footcite:lelay12jfla">
      <identifiant type="hal" value="hal-00642206"/>
      <analytic>
        <title level="a">Différentiabilité et intégrabilité en Coq. Application à la formule de d'Alembert</title>
        <author>
          <persName key="proval-2011-idm383373655520">
            <foreName>Catherine</foreName>
            <surname>Lelay</surname>
            <initial>C.</initial>
          </persName>
          <persName key="arenaire-2006-idm111960255408">
            <foreName>Guillaume</foreName>
            <surname>Melquiond</surname>
            <initial>G.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-international-audience="no" x-proceedings="yes">
        <title level="m">Vingt-troisièmes Journées Francophones des Langages Applicatifs</title>
        <loc>Carnac, France</loc>
        <imprint>
          <dateStruct>
            <month>February</month>
            <year>2012</year>
          </dateStruct>
          <ref xlink:href="http://hal.inria.fr/hal-00642206/fr/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://
          <allowbreak/>hal.
          <allowbreak/>inria.
          <allowbreak/>fr/
          <allowbreak/>hal-00642206/
          <allowbreak/>fr/
          <allowbreak/></ref>
        </imprint>
      </monogr>
    </biblStruct>
    <biblStruct id="proval-2011-bid4" type="inproceedings" rend="foot" n="footcite:leroy2006popl">
      <analytic>
        <title level="a">Formal certification of a compiler back-end, or: programming a compiler with a proof assistant</title>
        <author>
          <persName key="gallium-2006-idm16698282864">
            <foreName>Xavier</foreName>
            <surname>Leroy</surname>
            <initial>X.</initial>
          </persName>
        </author>
      </analytic>
      <monogr>
        <title level="m">Conference Record of the 33rd Symposium on Principles of Programming Languages</title>
        <loc>Charleston, South Carolina</loc>
        <imprint>
          <publisher>
            <orgName>ACM Press</orgName>
          </publisher>
          <dateStruct>
            <month>January</month>
            <year>2006</year>
          </dateStruct>
        </imprint>
      </monogr>
    </biblStruct>
    <biblStruct id="proval-2011-bid37" type="mastersthesis" rend="foot" n="footcite:lescuyer06master">
      <monogr>
        <title level="m">Codage de la logique du premier ordre polymorphe multi-sortée dans la logique sans sortes</title>
        <author>
          <persName key="proval-2006-idm410173274400">
            <foreName>Stéphane</foreName>
            <surname>Lescuyer</surname>
            <initial>S.</initial>
          </persName>
        </author>
        <imprint>
          <publisher>
            <orgName type="school">Master Parisien de Recherche en Informatique</orgName>
          </publisher>
          <dateStruct>
            <year>2006</year>
          </dateStruct>
        </imprint>
      </monogr>
      <note type="typdoc">Masters thesis</note>
    </biblStruct>
    <biblStruct id="proval-2011-bid2" type="inproceedings" rend="foot" n="footcite:letouzey2002types">
      <analytic>
        <title level="a">A New Extraction for Coq</title>
        <author>
          <persName key="pi.r2-2009-idm66870531760">
            <foreName>Pierre</foreName>
            <surname>Letouzey</surname>
            <initial>P.</initial>
          </persName>
        </author>
      </analytic>
      <monogr>
        <editor role="editor">
          <persName>
            <foreName>Herman</foreName>
            <surname>Geuvers</surname>
            <initial>H.</initial>
          </persName>
          <persName>
            <foreName>Freek</foreName>
            <surname>Wiedijk</surname>
            <initial>F.</initial>
          </persName>
        </editor>
        <title level="m">TYPES 2002</title>
        <title level="s">Lecture Notes in Computer Science</title>
        <imprint>
          <biblScope type="volume">2646</biblScope>
          <publisher>
            <orgName>Springer</orgName>
          </publisher>
          <dateStruct>
            <year>2003</year>
          </dateStruct>
        </imprint>
      </monogr>
    </biblStruct>
    <biblStruct id="proval-2011-bid3" type="phdthesis" rend="foot" n="footcite:letouzey2004phd">
      <monogr>
        <title level="m">Programmation fonctionnelle certifiée: l'extraction de programmes dans l'assistant Coq</title>
        <author>
          <persName key="pi.r2-2009-idm66870531760">
            <foreName>Pierre</foreName>
            <surname>Letouzey</surname>
            <initial>P.</initial>
          </persName>
        </author>
        <imprint>
          <publisher>
            <orgName type="school">Université Paris-Sud</orgName>
          </publisher>
          <dateStruct>
            <month>July</month>
            <year>2004</year>
          </dateStruct>
        </imprint>
      </monogr>
      <note type="typdoc">Thèse de Doctorat</note>
    </biblStruct>
    <biblStruct id="proval-2011-bid17" type="inproceedings" rend="foot" n="footcite:marche05tphols">
      <analytic>
        <title level="a">Reasoning about Java Programs with Aliasing and Frame Conditions</title>
        <author>
          <persName key="proval-2006-idm410174325056">
            <foreName>Claude</foreName>
            <surname>Marché</surname>
            <initial>C.</initial>
          </persName>
          <persName key="proval-2008-idm220575009344">
            <foreName>Christine</foreName>
            <surname>Paulin-Mohring</surname>
            <initial>C.</initial>
          </persName>
        </author>
      </analytic>
      <monogr>
        <editor role="editor">
          <persName>
            <foreName>J.</foreName>
            <surname>Hurd</surname>
            <initial>J.</initial>
          </persName>
          <persName>
            <foreName>T.</foreName>
            <surname>Melham</surname>
            <initial>T.</initial>
          </persName>
        </editor>
        <title level="m">18th International Conference on Theorem Proving in Higher Order Logics</title>
        <title level="s">Lecture Notes in Computer Science</title>
        <imprint>
          <biblScope type="volume">3603</biblScope>
          <publisher>
            <orgName>Springer</orgName>
          </publisher>
          <dateStruct>
            <month>August</month>
            <year>2005</year>
          </dateStruct>
          <biblScope type="pages">179–194</biblScope>
          <ref xlink:href="http://www.lri.fr/~marche/marche05tphols.ps" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://
          <allowbreak/>www.
          <allowbreak/>lri.
          <allowbreak/>fr/
          <allowbreak/>~marche/
          <allowbreak/>marche05tphols.
          <allowbreak/>ps</ref>
        </imprint>
      </monogr>
    </biblStruct>
    <biblStruct id="proval-2011-bid22" type="inproceedings" rend="foot" n="footcite:marche06sefm">
      <analytic>
        <title level="a">Verification of Java Card Applets Behavior with respect to Transactions and Card Tears</title>
        <author>
          <persName key="proval-2006-idm410174325056">
            <foreName>Claude</foreName>
            <surname>Marché</surname>
            <initial>C.</initial>
          </persName>
          <persName key="proval-2006-idm410174281664">
            <foreName>Nicolas</foreName>
            <surname>Rousset</surname>
            <initial>N.</initial>
          </persName>
        </author>
      </analytic>
      <monogr>
        <editor role="editor">
          <persName>
            <foreName>Dang Van</foreName>
            <surname>Hung</surname>
            <initial>D. V.</initial>
          </persName>
          <persName>
            <foreName>Paritosh</foreName>
            <surname>Pandya</surname>
            <initial>P.</initial>
          </persName>
        </editor>
        <title level="m">4th IEEE International Conference on Software Engineering and Formal Methods (SEFM'06)</title>
        <loc>Pune, India</loc>
        <imprint>
          <publisher>
            <orgName>IEEE Comp. Soc. Press</orgName>
          </publisher>
          <dateStruct>
            <month>September</month>
            <year>2006</year>
          </dateStruct>
        </imprint>
      </monogr>
    </biblStruct>
    <biblStruct id="proval-2011-bid29" type="article" rend="foot" n="footcite:marche2004jsc">
      <analytic>
        <title level="a">Modular and Incremental Proofs of AC-Termination</title>
        <author>
          <persName key="proval-2006-idm410174325056">
            <foreName>Claude</foreName>
            <surname>Marché</surname>
            <initial>C.</initial>
          </persName>
          <persName key="proval-2009-idm423378944592">
            <foreName>Xavier</foreName>
            <surname>Urbain</surname>
            <initial>X.</initial>
          </persName>
        </author>
      </analytic>
      <monogr>
        <title level="j">Journal of Symbolic Computation</title>
        <imprint>
          <biblScope type="volume">38</biblScope>
          <dateStruct>
            <year>2004</year>
          </dateStruct>
          <biblScope type="pages">873–897</biblScope>
          <ref xlink:href="http://authors.elsevier.com/sd/article/S074771710400029X" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://
          <allowbreak/>authors.
          <allowbreak/>elsevier.
          <allowbreak/>com/
          <allowbreak/>sd/
          <allowbreak/>article/
          <allowbreak/>S074771710400029X</ref>
        </imprint>
      </monogr>
    </biblStruct>
    <biblStruct id="proval-2011-bid15" type="hdrthesis" rend="foot" n="footcite:marche05hdr">
      <monogr>
        <title level="m">Preuves mécanisées de Propriétés de Programmes</title>
        <author>
          <persName key="proval-2006-idm410174325056">
            <foreName>Claude</foreName>
            <surname>Marché</surname>
            <initial>C.</initial>
          </persName>
        </author>
        <imprint>
          <publisher>
            <orgName type="school">Université Paris 11</orgName>
          </publisher>
          <dateStruct>
            <month>December</month>
            <year>2005</year>
          </dateStruct>
        </imprint>
      </monogr>
      <note type="typdoc">Thèse d'habilitation</note>
    </biblStruct>
    <biblStruct id="proval-2011-bid33" type="misc" rend="foot" n="footcite:maude">
      <monogr>
        <title level="m">The MAUDE System</title>
        <imprint/>
      </monogr>
    </biblStruct>
    <biblStruct id="proval-2011-bid84" type="article" rend="foot" n="footcite:MelNowZim12">
      <identifiant type="hal" value="hal-00644166"/>
      <analytic>
        <title level="a">Numerical Approximation of the Masser-Gramain Constant to Four Decimal Digits: delta=1.819...</title>
        <author>
          <persName key="arenaire-2006-idm111960255408">
            <foreName>Guillaume</foreName>
            <surname>Melquiond</surname>
            <initial>G.</initial>
          </persName>
          <persName>
            <foreName>Werner Georg</foreName>
            <surname>Nowak</surname>
            <initial>W. G.</initial>
          </persName>
          <persName key="spaces-2006-idm18803823456">
            <foreName>Paul</foreName>
            <surname>Zimmermann</surname>
            <initial>P.</initial>
          </persName>
        </author>
      </analytic>
      <monogr>
        <title level="j">Mathematics of Computation</title>
        <imprint>
          <dateStruct>
            <year>2012</year>
          </dateStruct>
          <ref xlink:href="http://hal.inria.fr/hal-00644166/en/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://
          <allowbreak/>hal.
          <allowbreak/>inria.
          <allowbreak/>fr/
          <allowbreak/>hal-00644166/
          <allowbreak/>en/
          <allowbreak/></ref>
        </imprint>
      </monogr>
    </biblStruct>
    <biblStruct id="proval-2011-bid27" type="article" rend="foot" n="footcite:moy10jsc">
      <identifiant type="hal" value="inria-00534331"/>
      <analytic>
        <title level="a">Modular Inference of Subprogram Contracts for Safety Checking</title>
        <author>
          <persName key="proval-2006-idm410174289696">
            <foreName>Yannick</foreName>
            <surname>Moy</surname>
            <initial>Y.</initial>
          </persName>
          <persName key="proval-2006-idm410174325056">
            <foreName>Claude</foreName>
            <surname>Marché</surname>
            <initial>C.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-editorial-board="yes" x-international-audience="yes">
        <title level="j">Journal of Symbolic Computation</title>
        <imprint>
          <biblScope type="volume">45</biblScope>
          <dateStruct>
            <year>2010</year>
          </dateStruct>
          <biblScope type="pages">1184-1211</biblScope>
          <ref xlink:href="http://hal.inria.fr/inria-00534331/en/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://
          <allowbreak/>hal.
          <allowbreak/>inria.
          <allowbreak/>fr/
          <allowbreak/>inria-00534331/
          <allowbreak/>en/
          <allowbreak/></ref>
        </imprint>
      </monogr>
    </biblStruct>
    <biblStruct id="proval-2011-bid26" type="phdthesis" rend="foot" n="footcite:moy09phd">
      <monogr>
        <title level="m">Automatic Modular Static Safety Checking for C Programs</title>
        <author>
          <persName key="proval-2006-idm410174289696">
            <foreName>Yannick</foreName>
            <surname>Moy</surname>
            <initial>Y.</initial>
          </persName>
        </author>
        <imprint>
          <publisher>
            <orgName type="school">Université Paris-Sud</orgName>
          </publisher>
          <dateStruct>
            <month>January</month>
            <year>2009</year>
          </dateStruct>
          <ref xlink:href="http://www.lri.fr/~marche/moy09phd.pdf" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://
          <allowbreak/>www.
          <allowbreak/>lri.
          <allowbreak/>fr/
          <allowbreak/>~marche/
          <allowbreak/>moy09phd.
          <allowbreak/>pdf</ref>
        </imprint>
      </monogr>
      <note type="typdoc">Ph. D. Thesis</note>
    </biblStruct>
    <biblStruct id="proval-2011-bid31" type="inproceedings" rend="foot" n="footcite:ohlebusch00rta">
      <analytic>
        <title level="a">TALP: A Tool for the Termination Analysis of Logic Programs</title>
        <author>
          <persName>
            <foreName>Enno</foreName>
            <surname>Ohlebusch</surname>
            <initial>E.</initial>
          </persName>
          <persName>
            <foreName>Claus</foreName>
            <surname>Claves</surname>
            <initial>C.</initial>
          </persName>
          <persName key="proval-2006-idm410174325056">
            <foreName>Claude</foreName>
            <surname>Marché</surname>
            <initial>C.</initial>
          </persName>
        </author>
      </analytic>
      <monogr>
        <editor role="editor">
          <persName>
            <foreName>Leo</foreName>
            <surname>Bachmair</surname>
            <initial>L.</initial>
          </persName>
        </editor>
        <title level="m">11th International Conference on Rewriting Techniques and Applications</title>
        <loc>Norwich, UK</loc>
        <title level="s">Lecture Notes in Computer Science</title>
        <imprint>
          <biblScope type="volume">1833</biblScope>
          <publisher>
            <orgName>Springer</orgName>
          </publisher>
          <dateStruct>
            <month>July</month>
            <year>2000</year>
          </dateStruct>
          <biblScope type="pages">270–273</biblScope>
        </imprint>
      </monogr>
    </biblStruct>
    <biblStruct id="proval-2011-bid51" type="misc" rend="foot" n="footcite:RanTin-SMTLIB">
      <monogr>
        <title level="m">The Satisfiability Modulo Theories Library (SMT-LIB)</title>
        <author>
          <persName key="cassis-2006-idm380671579984">
            <foreName>Silvio</foreName>
            <surname>Ranise</surname>
            <initial>S.</initial>
          </persName>
          <persName>
            <foreName>Cesare</foreName>
            <surname>Tinelli</surname>
            <initial>C.</initial>
          </persName>
        </author>
        <imprint>
          <dateStruct>
            <year>2006</year>
          </dateStruct>
        </imprint>
      </monogr>
      <note type="howpublished">http://www.smtcomp.org</note>
    </biblStruct>
    <biblStruct id="proval-2011-bid5" type="inproceedings" rend="foot" n="footcite:sozeau07icfp">
      <analytic>
        <title level="a">Program-ing Finger Trees in Coq</title>
        <author>
          <persName key="proval-2006-idm410174276352">
            <foreName>Matthieu</foreName>
            <surname>Sozeau</surname>
            <initial>M.</initial>
          </persName>
        </author>
      </analytic>
      <monogr>
        <editor role="editor">
          <persName>
            <foreName>Ralf</foreName>
            <surname>Hinze</surname>
            <initial>R.</initial>
          </persName>
          <persName>
            <foreName>Norman</foreName>
            <surname>Ramsey</surname>
            <initial>N.</initial>
          </persName>
        </editor>
        <title level="m">12th ACM SIGPLAN International Conference on Functional Programming, ICFP 2007</title>
        <loc>Freiburg, Germany</loc>
        <imprint>
          <publisher>
            <orgName>ACM Press</orgName>
          </publisher>
          <dateStruct>
            <year>2007</year>
          </dateStruct>
          <biblScope type="pages">13–24</biblScope>
        </imprint>
      </monogr>
    </biblStruct>
    <biblStruct id="proval-2011-bid6" type="phdthesis" rend="foot" n="footcite:sozeau08these">
      <monogr>
        <title level="m">Un environnement pour la programmation avec types dépendants</title>
        <author>
          <persName key="proval-2006-idm410174276352">
            <foreName>Matthieu</foreName>
            <surname>Sozeau</surname>
            <initial>M.</initial>
          </persName>
        </author>
        <imprint>
          <publisher>
            <orgName type="school">Université Paris-Sud</orgName>
          </publisher>
          <dateStruct>
            <month>December</month>
            <year>2008</year>
          </dateStruct>
        </imprint>
      </monogr>
      <note type="typdoc">Thèse de Doctorat</note>
    </biblStruct>
    <biblStruct id="proval-2011-bid8" type="article" rend="foot" n="footcite:ste81ieee">
      <analytic>
        <title level="a">A proposed standard for binary floating point arithmetic</title>
        <author>
          <persName>
            <foreName>David</foreName>
            <surname>Stevenson</surname>
            <initial>D.</initial>
          </persName>
        </author>
      </analytic>
      <monogr>
        <title level="j">IEEE Computer</title>
        <imprint>
          <biblScope type="volume">14</biblScope>
          <biblScope type="number">3</biblScope>
          <dateStruct>
            <year>1981</year>
          </dateStruct>
          <biblScope type="pages">51-62</biblScope>
        </imprint>
      </monogr>
    </biblStruct>
    <biblStruct id="proval-2011-bid28" type="phdthesis" rend="foot" n="footcite:urbain01these">
      <monogr>
        <title level="m">Approche incrémentale des preuves automatiques de terminaison</title>
        <author>
          <persName key="proval-2009-idm423378944592">
            <foreName>Xavier</foreName>
            <surname>Urbain</surname>
            <initial>X.</initial>
          </persName>
        </author>
        <imprint>
          <publisher>
            <orgName type="school">Université Paris-Sud</orgName>
            <address>
              <addrLine>Orsay, France</addrLine>
            </address>
          </publisher>
          <dateStruct>
            <month>October</month>
            <year>2001</year>
          </dateStruct>
          <ref xlink:href="http://www.lri.fr/~urbain/textes/these.ps.gz" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://
          <allowbreak/>www.
          <allowbreak/>lri.
          <allowbreak/>fr/
          <allowbreak/>~urbain/
          <allowbreak/>textes/
          <allowbreak/>these.
          <allowbreak/>ps.
          <allowbreak/>gz</ref>
        </imprint>
      </monogr>
      <note type="typdoc">Thèse de Doctorat</note>
    </biblStruct>
  </biblio>
</raweb>
