On the Formal Veri cation of the TCAS Con ictResolution Algorithms 1

TCAS is an on-board protocol for detecting connicts between aircraft and providing resolution advisories to the pilots. Because of its safety-critical role the TCAS software should ideally be \veriied" before it can be deployed. The veriication task is challenging, due to the complexity of the TCAS code and the hybrid nature of the system. We show how the essence of this very complicated problem can be captured by a relatively simple hybrid model, amenable to formal analysis. We then outline a methodology for establishing conditions under which the advisories issued by TCAS are safe.