•SDL differentiates between process definition and process instance
•Defined process
activation mechanism
•Receiver process
instance
• (1
receiverprocess start
•
((ackid . nil) (frameid . nil) (self . 1)
• (sender . nil) (parent . 0) (offspring .
nil)
• ((start …)) nil)
•Correctness property:
defined a recognizer for valid instances
of a system
• (defthm
activate-makes-instance
•
(implies (wf-type S)
• (wf-instance (activate S) S)))