This booklet constitutes the refereed court cases of 4 workshops co-located with SAFECOMP 2016, the thirty fifth overseas convention on machine protection, Reliability, and protection, held in Trondheim, Norway, in September 2016.

The 30 revised complete papers awarded including four brief and five invited papers have been conscientiously reviewed and chosen from a variety of submissions. This year’s workshop are: guarantee 2016 - insurance situations for Software-intensive structures; DECSoS 2016 - EWICS/ERCIM/ARTEMIS responsible Cyber-physical platforms and Systems-of-Systems Workshop; SASSUR 2016 - subsequent new release of procedure coverage ways for Safety-Critical structures; and counsel 2016 – Timing functionality in security Engineering.

We use the same environment restrictions and CBMC settings to perform the functional verification and to generate test cases. We use mbeddr because it features a user friendly integration of CBMC. In the following, we present our experience with the verification of three software components, which implement critical functionality. The purpose of our experiments is to investigate the extent to which bounded model checking verification can achieve better coverage than classical testing on software components.

Cˆ arlan et al. In both cases, only a part of the space of behaviors is covered by the model checker. Consequently, there are behaviors possible in the environment of the component which are specified by the requirement (Env SwC ), but not captured in the verification environment (Env BM C ). Thus, the assurance deficits caused by incomplete verification must be accompanied by additional evidence in a confidence argument. In the following section, we elaborate on the assurance deficits of incomplete bounded model checking verification and how to compensate for this deficits.

