“…(e-mail: psd@cs.unc.edu). a model checking tool [5], [31], [34], [35] is employed to verify a system with respect to a safety specification. A safety specification is satisfied if all executions of a system avoid the set of states labelled as unsafe.…”