Verification of parameterized protocols is of great interest in the area of formal verification, mainly due to the practical importance of such systems. Explicit-state model checking is an essential approach in which states for a system are maintained in explicit form, as are all state transitions. In order to reduce the search space to a minimum, we propose a local search strategy. In detail, first, heuristic functions are designed to guide the searching of bugs more effectively, which exploits information extracted from invariants and rulesets, to improve the calculation of a distance between two states. Second, candidate solutions with poor scores are dropped for further compression of the state space explored. Especially, we apply successfully our local search algorithm to the reachable analysis of a real-world implementation of TileLink protocol.
Read full abstract