bmc’03 - jkufmv.jku.at/papers/bmc03-preliminary-proceedings.pdfbmc’03 boulder, colorado, usa....

104
13 July, 2003 First International Workshop on Bounded Model Checking BMC’03 Boulder, Colorado, USA

Upload: vuongcong

Post on 16-Apr-2018

223 views

Category:

Documents


4 download

TRANSCRIPT

Page 1: BMC’03 - JKUfmv.jku.at/papers/bmc03-preliminary-proceedings.pdfBMC’03 Boulder, Colorado, USA. ... Alessandro Cimatti (IRST, Italy) Raanan Fraer (Intel, Israel) Danny Geist (IBM

13 July, 2003

First International Workshop on

Bounded Model Checking

BMC’03

Boulder, Colorado, USA

Page 2: BMC’03 - JKUfmv.jku.at/papers/bmc03-preliminary-proceedings.pdfBMC’03 Boulder, Colorado, USA. ... Alessandro Cimatti (IRST, Italy) Raanan Fraer (Intel, Israel) Danny Geist (IBM
Page 3: BMC’03 - JKUfmv.jku.at/papers/bmc03-preliminary-proceedings.pdfBMC’03 Boulder, Colorado, USA. ... Alessandro Cimatti (IRST, Italy) Raanan Fraer (Intel, Israel) Danny Geist (IBM

Preface

This binderincludesthepreliminaryproceedingsof thefirst internationalworkshopon BoundedModel Checking(BMC’03) that was held on July 13th, 2003 in Boulder, Colorado.The finalproceedingswill bepublishedin issue4, Volume89 of ElectronicNotesin TheoreticalComputerScience(ENTCS),togetherwith otherCAV’03 affiliated workshops.

Sinceits introductionin 1999,BoundedModel Checkinghasbeenadoptedby mostrelevantcompaniesasacomplementarytechniqueto themoretraditionalBDD-basedunboundedsymbolicmodelchecking.Largely dueto theadvancesin SAT technologyin the last few years,it becamea leadingtool in detectionof relatively shallow logical errors,outperformingBDD basedtools inmostof thesecases.Thelargeinterestin thistechnologyhascreatedaconstantstreamof new ideasandimprovementsthatmakethis techniquemoreandmoreuseful.It alsoled to aneffort, reportedin theinvited talk of thisworkshop,to usethepowerof SAT solversfor standard,i.e.,unbounded,modelchecking.

Theaim of theworkshopwasto provide a forum for presentingnew results,both theoreticalandexperimental,in BoundedModel Checking.This is thefirst workshopto concentrateon thistopic,andwehopethatit will befollowedby similar meetingsannually.

Eachof thepapersselectedto this workshophasbeenreviewedandrecommendedby at leastthree(typically four) programcommitteemembers.We thank the programcommitteemembersfor their effort in evaluatingthe articles.We alsothankthe organizersof the hostingconference(CAV’03), W. Hunt andF. Somenzi.

OferStrichman Armin BiereCarnegie-MellonUniversity ETH Zurich

July2003

Page 4: BMC’03 - JKUfmv.jku.at/papers/bmc03-preliminary-proceedings.pdfBMC’03 Boulder, Colorado, USA. ... Alessandro Cimatti (IRST, Italy) Raanan Fraer (Intel, Israel) Danny Geist (IBM

Organizers

OferStrichman (Carnegie-MellonUniversity, USA)Armin Biere (ETH Zurich,Switzerland)

Program committee

David Basin (ETH Zurich,Switzerland)Armin Biere (ETH Zurich,Switzerland)PerBjesse (Synopsys,USA)AlessandroCimatti (IRST, Italy)RaananFraer (Intel, Israel)Danny Geist (IBM - HRL, Israel)Alan Hu (Univ. of British Columbia,Canada)JamesKukula (Synopsys,USA)KenMcMillan (Cadence,USA)SharadMalik (PrincetonUniv., USA)Mary Sheeran (ChalmersUniv. of Technology, Sweden)JoaoM. Silva (TechnicalUniv. of Lisbon,Portugal)OferStrichman (Carnegie Mellon Univ., USA)TobyWalsh (Univ. of York, UK)YunshanZhu (Synopsys,USA)

Page 5: BMC’03 - JKUfmv.jku.at/papers/bmc03-preliminary-proceedings.pdfBMC’03 Boulder, Colorado, USA. ... Alessandro Cimatti (IRST, Italy) Raanan Fraer (Intel, Israel) Danny Geist (IBM

Program

Invited talk

KenMcMillan

FromBoundedto UnboundedModelChecking

Lectures

NiklasEen,NiklasSorensson

Temporal Inductionby IncrementalSAT Solving

Toni Jussila,Keijo Heljanko, Ilkka Niemela

BMCvia On-the-FlyDeterminization

ParthasarathyMadhusudan,WonhongNam,Rajeev Alur

SymbolicComputationalTechniquesfor SolvingGames

ZurabKhasidashvili,ZiyadHanna

SAT-basedMethodsfor SequentialHardwareEquivalenceVerificationWithoutSynchronization

Bing Li, FabioSomenzi

A Satisfiability-BasedApproach to AbstractionRefinementin ModelChecking

GianpieroCabodi,Alex Kondratiev, Sergio Nocco,StefanoQuer, YosinoriWatanabe

A BMC-Formulationfor theSchedulingProblemin Highly ConstrainedHardware Systems

Page 6: BMC’03 - JKUfmv.jku.at/papers/bmc03-preliminary-proceedings.pdfBMC’03 Boulder, Colorado, USA. ... Alessandro Cimatti (IRST, Italy) Raanan Fraer (Intel, Israel) Danny Geist (IBM
Page 7: BMC’03 - JKUfmv.jku.at/papers/bmc03-preliminary-proceedings.pdfBMC’03 Boulder, Colorado, USA. ... Alessandro Cimatti (IRST, Italy) Raanan Fraer (Intel, Israel) Danny Geist (IBM

������� ��� � � ����������������������� ��� �

!#"%$'&)(+*-,/.10325456�798;:�(+2=<?>@032�7%*A"%$'"%2+8B,/.1CEDF!CG(+. H�:2GI

J�KML�NPORQGS1TUWV%X J�KML�NPORQGY%Z[R\�UWV Q�Q []V^`_�a�b ced�fhgjiRkmlon�d�fhg lqpqr�sPt�uWdwv�_xkWs�byswz�r {�|m}�dw~xd�k

�m��� �����3�����������R�����m���P�������R� �m�

�/�R���� �m����G���w�� ¡)�� ¡£¢%¤���¥w¦¨§¨ �©�����ª�§¨ �©m«y¬®­�¢�ªw«y �¯¨ª� °¢%ªM¦�±®«²­�¢�³m§¨ �©���¥h¯/´�µA¶¸·M�� �³y¤���¥���¯m¢�¹®³y���-«yªª� º�� �³y¤��»¢¼����¥h«y���- �½`¥w��³²¢�ª���©?´�µA¶¸·M«²¯m��ªw¢�¯m­����-��¾e­�«y��¯xªw³y¦�¿A�G�»¢�±m±®³y¦¨ªw�m«²��«²©���¢°ª� º­h����­wÀ�«²¯�Á�w¢�½o��ªM¦Â±m¥w �±3��¥wªw«y���»¹�¦Â§¨��¢�¯m�° �½ pMd�c9Ã�s�f�a�b¸lokW~�Ämv�pqlÅs�kmÆ ¢?ª���­h�m¯m«²Ç�È��e��ª�¥w �¯�Á�³y¦G¥w��³²¢�ª���©Âª� É s�Ä�kW~xdw~jcÊs�~xd�b¸v�_�dwv�Ë lok�z ¿¨�G�ʽqÈ�¥wªw����¥»Á�«y¤��e¢?§¨ �¥w�¨��¾e­�«y��¯xª%¡¸¢�¦E �½¸­� �¯m��ª�¥h¢�«²¯m«²¯�Á�ªw�����Ì�ª���¯m©���©e«²¯m©mÈm­�ªw«y �¯Ê�x¦�±3 �ªw�����w«²��ª� ¼�� ¼­�¢�³²³y��© bys�shÃWÍ t fwdhd ±®¢�ªw�m��¿A�G���m¢�¤���¢�³²�� °±3��¥w½o �¥h§¨��©ªw����¬m¥h��ª¨­� �§¨±m¥w������¯m�w«y¤�����Ì�±3��¥h«²§¨��¯xªw¢�³���¤�¢�³²Èm¢�ªw«y �¯Î �½�«²¯m©mÈm­�ªw«y �¯5§¨��ªw�� �©m�º½o �¥e�w¢�½o��ªM¦x·­h����­wÀ�«²¯�Á�¿

Ï ÐmÑ�Ò3Ó�Ô%ÕÊÖº×RÒ�ØwÔ�ÑÙ�Ú1Û Ü Ý Ü Ú�Þjß�Ü�à�Û á â»ã®ä;å�æ�ç�à�á Ü èêéjÜÞ�ë3ì®è3á�íîì�Û+ë�à�Û èWï�à�Û ÜÂð�Ü Û ñóò�Ý�àxÞ�ñoì�Úôë�à�ð�Ü�ç`Ü Ý ì�éjÜà�ÚÂñoéjõ`ì�ÛhÞ�à�Ú�Þ�Ý ì�éjõ3öoÜ éjÜ Ú�Þ»Þ�ì+Þ�Û�à�è3ñóÞ�ñoì�Ú�à�öR÷�ø¨ø°æ�ç�à�á Ü èÂéjì®è3Ü ö]Ý�ë3Ü Ý�ùmñoÚ3ú3û�ã®Üð�Ü Û�à�öéjÜÞ�ë3ì®è3á%ë�à�ð�Üeõ3Û ì�ð�Ü Ú5Þ�ë3Ü ñoÛ»ü3á Üíîü3öoÚ3Ü á á¼ì�Ú5à?Úmü3é�ç`Ü Û%ì�í¸ñoÚ3è3ü3áhÞ�Û ñqà�öAà�õ3õ3öoñoÝ�àxÞ�ñoì�Ú3á âñoÚ+õ�à�ÛhÞ�ñoÝ ü3öqà�Û»ý�þxÿ���������� þ������� ��������������M÷�������� ÷������ �!�Wâ ÷��#"$� �!�Wâ%�#&'&)(+*-,�. û¸Ù�ÚÞ�ë3ñoá¨õ�à�õ`Ü Ûºï�Ü?ï%ñoöoö-íîì®Ý ü3á¨ì�ü3ÛeàxÞ Þ�Ü Ú�Þ�ñoì�Ú ì�Ú ë3ì�ï ã®ä;å�æ�ç�à�á Ü è)ð�Ü Û ñóò�Ý�àxÞ�ñoì�ÚÎõ3Û ì®Ý Ü�æè3ü3Û Ü áeÝ�à�Ú£ç`Üjñoéjõ3öoÜ éjÜ Ú�Þ�Ü è)éjì�Û Ü?Ü�/jÝ ñoÜ Ú�Þ�öóß ç�ߣàGÞ�ñoú�ë�Þ�Ü ÛÊñoÚ�Þ�Ü ú�Û�àxÞ�ñoì�ÚÎï%ñóÞ�ë)Þ�ë3Üü3Ú3è3Ü Û öóß®ñoÚ3ú ã®ä;å�æ�á ì�öóð�Ü Û û

å»ë3Ü Û Ü?à�Û Ü/Þ�ë3Û Ü Ü�é à�ñoÚ Ý ì�Ú�Þ�Û ñoç3üWÞ�ñoì�Ú3á¼ì�í;Þ�ë3Ü�õ�à�õ`Ü Û û0&�ñoÛ áhÞ�öóß�â�ï�Ü+á ë3ì�ï ë3ì�ï àÚmü3é�ç`Ü Û-ì�í�á ñoéjñoöqà�Û�ã®ä;å�æ�ñoÚ3áhÞ�à�Ú3Ý Ü á�Ý�à�Ú�ç`Ü�á ì�öóð�Ü è�ñoÚ3Ý Û Ü éjÜ Ú�Þ�à�öoöóߨç�ß/à%ð�Ü Ûhß�éjì®è3Ü áhÞéjì®è3ñóò�Ý�àxÞ�ñoì�Ú ì�í¨à éjì®è3Ü Û Ú1��ë�à�2�æ�öoñoù�Ü5ã®ä;å�æ�á ì�öóð�Ü Û3� ��� *-,4. û å»ë3Ü�Þ�Ü Ý�ë3Ú3ñ65mü3ÜÂï�Üõ3Û ì�õ`ì�á ÜEñoá�á ñoéjõ3öoÜ ÛeÞ�ë�à�Úôõ3Û Üð®ñoì�ü3á?àxÞ Þ�Ü éjõWÞ�á7� 8:9eã-*-,4. â;ï%ë3ñoöoÜ áhÞ�ñoöoö9ì�çWÞ�à�ñoÚ3ñoÚ3ú àõ`Ü Ûhíîì�Û é à�Ú3Ý Ü�ñoÚ3Ý Û Ü�à�á Ü?ì�íBÞ�ë3Ü?á�à�éjÜ+é à�ú�Ú3ñóÞ�ü3è3Ü�û+ã®Ü Ý ì�Ú3è3öóß�â]ï�Üjè3Ü éjì�Ú3áhÞ�Û�àxÞ�Ü�Þ�ë3ÜñoÚ3Ý Û Ü éjÜ Ú�Þ�à�ö;Þ�Ü Ý�ë3Ú3ñ65mü3ÜGì�Ú1;<���$=�þ�>@?AB������ÿ���;C� þ��D� ã3ã3ã-*!*A. â¸à5éjÜÞ�ë3ì®è£ì�í%Ý�ë3Ü Ý�ùmñoÚ3úá�àxíîÜÞ�ßGõ3Û ì�õ`Ü ÛhÞ�ñoÜ á%ì�ÚFEB����;<�HG�;I?A;<���J?��� ����K��GL�C&;ãM����ûM8£ÜÊá ë3ì�ï Þ�ë3ÜÊñoéjõ�à�ÝÞ»ì�í�Þ�ë3ÜñoÚ3Ý Û Ü éjÜ Ú�Þ�à�ö¨à�õ3õ3Û ì�à�Ý�ë ÜONWõ`Ü Û ñoéjÜ Ú�Þ�à�öoöóß�â°ç`ì�Þ�ë íîì�ÛGõ3Û ì�ð®ñoÚ3ú1Ý ì�Û Û Ü ÝÞ�Ú3Ü á á5à�Ú3è íîì�Ûò�Ú3è3ñoÚ3ú?Ý ì�ü3Ú�Þ�Ü Ûwæ�ÜON3à�éjõ3öoÜ á û

P-QSR%TUR%TWV)X!Y[ZI\ R ]#R ^AV�Y`_0a�ZIYITCRcb�^�dUP-Q!ZWeS^AV�\fa�ZIYITCRcb�^0g�R \ \�hiZ XMj�h�\ R%TCQ!Z@k�R ^lf\cZ@m@noY[b�^SRomUp'bn�Z<TUR ^FP-Q!Zqb�Y[Z�noRom<V�\frfb�]BXMjSn�ZIYtsAmuRcZI^vm[Z

w-xWy�z{�{�{f| � � ����}x����� | �x��~���4���O���4~� ��S� �

Page 8: BMC’03 - JKUfmv.jku.at/papers/bmc03-preliminary-proceedings.pdfBMC’03 Boulder, Colorado, USA. ... Alessandro Cimatti (IRST, Italy) Raanan Fraer (Intel, Israel) Danny Geist (IBM

����S�F�������K���� �S���@� � �

���M�6�@�M�o�!�W�����@�����M�J���M�L�J�����M�����A���4�M�@ M�@�6�M¡3¢4�!�J£M�6�����4�M�4�@�0�`�!�¤���4�J£��!��¥A�)�6��¦�M M¢����6�!� §¨���M�3�q��¥A�M��¥A�@�1�J�����M���©���!�@ª���«v�¬�@�4­� M�6�@�6�M¡®¥A�6���q��¥����4�L�6�©���M�3�6�M�M M¢O¦���6�!�¯�v��£��A���M�4�@�6�+���7«���°�±�²C³4°�´�§Fµ¶�¯¥��@�6�J£M�6�·¥A��¥A�o���@�6�H�A�¶���M�J¸)¹Mº®�K���L¥A�@�F¥A«M�6������O»-¢4�6 M�M�·�@�!�J�¼�q��¥����O¦I½A¥A�@�¾¥A«M�6�4�¿�`�@�!�À���M�· M�M�6­� M�4�M�4�@�¤¢4�!�M�q����¥A�6�v���4�U�@�4�@ M�o���6�M¡��6��q���@�!�M¡!�4�·�@�4­� M�6�@�4�J�4�v���4§¬���M�6�·�L¥�Á�O»-£��!�M�4�v���¾¥A�6�o���@�4�M M¢4�7���M�7�6�M�M M¢����6�!�Á�M�4£-����M�4�4�M�4� §�Â��0£M�@�i½!������¥������M�6�¿�q���@�4�M¡A���M�4�M�6�M¡L�6�¿�@�! M�M� §�Ã$�M�M�o���6�!��¥A�6�o�!�������M�4�J�!��¦�q����¥����7¥¯�@£��4�4��¦< M£¬«v�©¥A�M�M�6�M¡¯���M�� M�M�6­� M�7�q��¥����4�F�@�4­� M�6�@�4�J�4�v�J�-����¥A�J�6¢¥A�6�o�Ä�`�!��!�M�o�L���M�!�@�¤£�¥A�6�@���A�Å�q��¥����4�����M�4�@�0�o���6���M�4�4�M�4� §

���M�#�O»-£��4�@�6�J�4�v���t���#��¥½!��£��4�q�`�!�@�J�4�0���o���¼�! M�Å£M�@�A���A�<��£��¶�����!�!Æ�Ç`ȼ�@�M�i�©����¥���L¥A�v�3£M�@�!£��4�q���6�4�+¢¥A�Ä«��F£M�@�i½!�4��¥��¤�@£��4�4�M�¤¢4�!�J£�¥A��¥A«M�6�������L¥��� M�@�Fµ#É+É¿¦<«�¥A�@�4������!�6�#�@ M¢���¥A�#Ê�ËHÌBÍiÎ�ÏWÍ·ÐfÑ1ÒÓ¥A�M��Ê+Ñ1ÔÕÐfÑ1ÒL§

Ö ×®Ø�ÙtÚqÛqÜÝÛqÞHß)ØfÛ[ÙWà

á<�¯���M�6�+£�¥A£��4�4�U���F¢4�!�M�@�6�M�4�¼âãqä´�åCæ¼ç�è�é�ç�´�èOåC²u´�âJ�!�7êB±�²�å<´�â�åIãAå<´JëJã�ì�í�²�±K´�â3îC¸)¹Mº�ïO§���M�¯�q��¥����4���A�¤���M�ĸ)¹Mºð¥A�@�3½!�4¢����!�@�7�A�0«����!�6�¥A�M�4���M�����M�6�M¡Á���M�3½A¥A�6 M�4���A�¤���M�â�åIãAå<´¼ñ�ãAèO²Cãvò4ó6´�â�§�Â��·¥A�@�@ M�J�0���M�·¸)¹Mºô������¥½!�F¥L�@���H�A�B�6�4¡v¥A�B²�±�²�åC²CãAóUâ�åIãAå<´�â�� ¥A�M����M�F��¥��`���<�Ä£M�@�!£��4�q�<�¯���õ«��F�@£��4¢4�o���4�ö¥A�0¥7£M�@�!£��!�@�o���6�!��¥A�t�`�!�@�¼ M�¾¥��i½!�4�¤���M�J�q��¥����½A¥A�@�¾¥A«M�6�4�4§+µ¶��è�´�ã�ì�íMãvò4ó6´0â�åIãAå<´�â<çMã�ì�´����·�J�¥A�Ä¥A�6�W�q��¥����4�+�A�B���M�·¸)¹Mº÷�@�¥A¢���¥A«M�6��`�@�!�ø���M���6�M�o���¾¥A� �q��¥����4�4§+ùH M����¥A�@ª7�6�¿���L£M�@�i½!������¥��¿���M��£M�@�!£��4�q�<�3�M�!�6�M���`�!�¿�¥A¢���q��¥����¤�6�����M�¤�@�¥A¢���¥A«M�6�¤�q��¥����¤�@£�¥A¢4�A§

á<�Á¥3�q��¥A�M��¥A�@�ö�L¥A�M�M�4�4�Å���L���6�6�B¥A�@�@ M�J�L���M�J����¥A�M�@�o���6�!�M�0�A�#���M��¸)¹Mºú����«���@�4£M�@�4�@�4�v���4�Ä«v�¯¥L£M�@�!£��!�@�o���6�!��¥A� �`�!�@�¼ M�¾¥Jû3îuüUýOüMþcïO�����M�¼�@���+�A�B�6�M�o���¾¥A� �q��¥����4�H«v��¥�`�!�@�¼ M�¾¥7ÿ-îuü�ïO�'¥A�M�ö�` M�q���M�4���M�4�M�A���L���M�L��¥��`���<��£M�@�!£��4�q�<��«v���3îuüfïO§õÂ��L���6�6�) M�@�ü��Ä�����M�4�M�A���·���M�·�q��¥����¼½A¥A�@�¾¥A«M�6�4�$�A�B���6�J���q���4£��Á¥A�M�Ä�6�v���@���M M¢4�¼���M�·�@�M�!�q����¥A�M��M�A��¥����6�!��ÿ�������-��¥A�M�3û�¼�`�!��ÿ-îuü��KïO���3îuü��KïO��¥A�M�3û3îuü��WýOü��� �ïO§����� � í�´���� � ç�è�é!ò4ó6´�ë�U�����Héié�óÅ�M�4�M�A���0���M��òOéié�ó6´�ãA±¯�M�!�L¥A�6�����-ý�� ����¥A�M�"!�ãAè�â$#&%'��(*)!ý+( ,vý+(�-�ý�.�.�./�·«��0¥���M�o���¤�@���H�A�)«����!�6�¥A��½A¥A�@�¾¥A«M�6�4�4§#ÃÝó ²�å<´�è@ãAó'�6�¿¥J«����!�6�¥A�7½A¥A�@�¾¥A«M�6�10�2Å�!�$¥J�M�4¡v¥����4�«����!�6�¥A�7½A¥A�@�¾¥A«M�6� 0�2<§�ÃÀì�óoãA°vâi´��6�$¥J�@���+�A�)�6�o���4��¥A�6�4���6�J£M�6�6¢4�o���o�J�M�6��3@�!�6�M�4� §�Ã4��� �²�±-â�åIãA±Kì�´��6�·¥¯�@���F�A�$¢4�¾¥A M�@�4�4�¶�6�J£M�6�6¢4�o���o��¢4�!�53@�!�6�M�4� §�à ñ�ãAó °MãAåC²ué�±¨�6�·¥��` M�M¢����6�!�!�ãAè�â768�Héié�óI§�à �6�o���4��¥A�90�2'�6�¿��¥A�6�7���L«��0��¥����6�q���4��«v�3¥F½A¥A�6 �¥����6�!�7�o�Å�o����½A¥A�@�¾¥A«M�6��6�0�L¥A£M£��4�ö���:�*;¶¥3�6�o���4��¥A� 0�2��o���o���¤½A¥A�@�¾¥A«M�6�J�6���L¥A£M£��4�������-§�à ¢4�¾¥A M�@���6����¥A�6�����«�����¥����6�q���4�©�o�¿¥��¼�6�¥A�q�·�!�M���A���o���¼�6�o���4��¥A�6�¤�6�¼��¥����6�q���4� §Äà ëLé�<�´�ó0î`��¥����6�q�����6�M¡¥A�@�@�6¡!�M�J�4�v�Oï��`�!�H¥�¹�Ã)� �6�M�q��¥A�M¢4�¼�6�H¥J½A¥A�6 �¥����6�!�7���M�4�@�F¥A�6�W¢4�¾¥A M�@�4�+¥A�@�¼��¥����6�q���4� §���M�$��� � ç�è�é!ò4ó6´�ëø�6�����·���M�3¥·�J���M�4�K�`�!��¥·¡!�o½!�4�õ�@���¿�A�Å¢4�¾¥A M�@�4�4§

���=� > é�±�ñA´�èOåC²�±�?�äé�èOë·°�óoãSâ¤å<é@��� ����M�4�@�Ä¥A�@���@��½!�4��¥A�H�#¥���7�A�¤����¥A�M�@�¾¥����6�M¡ö¥ö£M�@�!£��!�@�o���6�!��¥A���`�!�@�¼ M�¾¥®�6�v���ö¢4�¾¥A M�@�4�4��6�Á�@ M¢��¨¥3�#¥�Á����¥��F��¥����6�q�f¥A«M�6�6�o�<�®�6�¼£M�@�4�@�4�q½!�4� §¬���M�6�·�6�¼�<��£M�6¢¥A�6�o���M�!�M��«v�Á�6��¦���@���M M¢4�6�M¡3¥A �»-�6�6�¾¥A�q�3½A¥A�@�¾¥A«M�6�4�¤¡!�o½��6�M¡õ��¥A�J�4�¤���3�@�!�J�J�!��¥A�6�)�@ M«-�`�!�@�¼ M�¾¥A�4�t���M�4�¡!�4�M�4��¥����6�M¡¿¢4�¾¥A M�@�4�t����¥��t�4�q��¥A«M�6�6�@�¼¥¿�M�����M�o���6�!��¥A�!�@�4�¾¥����6�!�0«����<���4�4�¼���M�¶�6�v���@���M M¢4�4�½A¥A�@�¾¥A«M�6�4�#¥A�M�����M�$���@ -����¦I½A¥A�6 M�4�#�A�W���M�4�6�#�@�4�@£��4¢����o½!�+�@ M«-�`�!�@�¼ M�¾¥A�4§)Ã$�v���J���M�4���`�!�

A

Page 9: BMC’03 - JKUfmv.jku.at/papers/bmc03-preliminary-proceedings.pdfBMC’03 Boulder, Colorado, USA. ... Alessandro Cimatti (IRST, Italy) Raanan Fraer (Intel, Israel) Danny Geist (IBM

BDCE5F@G�FIHKJ9LM�N E5F�OPO M FQSRUTVQSWSX YUZP[\X�QST^]`_UWPa*bU[=T^ced�fgRUh=i+RKi^a*Y�Q+X h=YUZjcka*WPTgl X WPh\X bU[=T^Z+m R�X ZnQSRUT1_UWPa*_oT^WpQrq@QSR�X�QhsQSZtWPT^ZpQSWPh=iuQSh=a*YvQSa1QSRUTwa*WPh=x*h=Y�X [IZPTuQya z{l X WPh\X bU[=T^Z|q�h=T^[=]UZ X�cka�]UT^[Iz}a*WtQSRUTwa*WPh=x*h=Y�X [�z}a*W�~cv�U[\X��|��TX ZPZP�UckT�QSRUT�T���h=ZpQST^YUi^T�a z|ZP�Ui+R�X7QSWSX YUZP[\X�QSh=a*Y�QST^i+RUYUh=�I�UTX YU]Kh=Y�QSWPa�]U�Ui^TQSRUT�z}a*[=[=a�fgh=YUxDYUa Q+X�QSh=a*Y��

�K�����|���5�}�o�y��� q�� ��� ��fjT�]UT^YUa QSTKX�ZPTuQva zwi^[\X �UZPT^ZD]UTu��YUh=YUx���ZP�Ui+R:QSR�X�QV�h=ZVQSRUTv[=hsQST^WSX [�WPT^_UWPT^ZPT^Y�QSh=YUxKQSRUTvQSWP��QSR�~ l X [=�UTDa z QSRUTDfgRUa*[=TDz}a*WPcv�U[\X�����Tvi�X [=[�:QSRUT�¡I¢}£y¤�¥�¦§¥©¨�¤«ª/¥�¦r¢u¬P­ ªga z��n��®��UWpQSRUT^W^¯tfjT`fgWPhsQST�� ���wX Z$X�ZPRUa*WpQ$R�X YU]:z}a*W� ��� �j°�±+��²I�®�a*W9T��UX ck_U[=TV� ³9´�µI� �yc�X�q1boT�QSWSX YUZP[\X�QST^]�h=Y�QSa¶QSRUT i^[\X �UZPT^Z ±g± �¸·P³¸²I·^± ��·Sµ{²I·^±+�¸· ³¸· µU²V²I�¹�º\» ¼ ¢u½�¾�¨�¬P­ ª�¿�¤o¡ À�Áu¦§¥©¨�¤Â RUh=Z�ZPT^iuQSh=a*YÃbUWPh=TuÄUqÅZP�Uckc�X WPh=Æ^T^ZÇQSRUT�l*T^WPhs��i�X�QSh=a*YÅQST^i+RUYUh=�I�UTȦr¢u½�¾�¨�¬P­ ª�¥�¤o¡ À�Áuɦ§¥©¨�¤È_UWPT^ZPT^Y�QST^]�h=YÊ� ËUËUË�Ì*Ì �©��Í Â RUTÇfja*WP]ÏÎ�QST^ck_oa*WSX [=Ð�ZP�Ux*x*T^ZpQSZ@QSR�X�Q@QSRUT�h=YU]U�Ui�~QSh=a*YKh=Zwi�X WPWPh=T^]Ça*��Qga�l*T^WgQSRUT�QSh=ckT1ZpQST^_UZVa z|QSRUT7® ËUÑ��{Ò¸h=Ó TX$ZpQ+X YU]�X WP]�h=YU]U�UiuQSh=a*Y_UWPa�a z�¯�XQST^ck_oa*WSX [�h=YU]U�UiuQSh=a*Yk_UWPa�a z¸i^a*YUZPh=ZpQSZna z�Qrfjav_�X WpQSZ^�tQSRUT�b�X ZPT�~ri�X ZPT1X YU]�QSRUTh=YU]U�UiuQSh=a*Y�~rZpQST^_��ÕÔrYÖhsQSZDZPh=ck_U[=T^ZpQDz}a*WPc�¯|QSRUT`b�X ZPT�~ri�X ZPTKZpQ+X�QST^ZvQSR�X�QDQSRUT`_UWPa*_oT^WpQrqZPRUa*�U[=]�RUa*[=]�h=YKQSRUT7h=YUhsQSh\X [9ZpQ+X�QST^Z^×9X YU]ÇQSRUT7h=YU]U�UiuQSh=a*Y�~rZpQST^_�ZpQ+X�QST^ZgQSR�X�QVQSRUT7_UWPa*_�~T^WpQrq�ZPRUa*�U[=]�boTk_UWPT^ZPT^Wpl*T^]:b�q�QSRUT@QSWSX YUZPhsQSh=a*YUZ1a zjQSRUTk® ËUÑ��|Øt��_UWPT^ZPZPh=YUx�QSRUT@Qrfja_�X WpQSZva zwQSRUT`h=YU]U�UiuQSh=a*Y:_UWPa�a zVX Z@Ë�Ù Â ~r_UWPa*bU[=T^ckZDh=ZvZpQSWSX h=x*R�Qp~ z}a*Wpf¶X WP]IÚ�ZpQSh=[=[©¯¸QSRUTWPT^ZP�U[sQSh=YUxKckTuQSRUa�]�h=ZX [=WPT�X ]�q�X Y�h=Y�QST^WPT^ZpQSh=YUxÇi^a*ck_U[=T^ckT^Y�Q1QSa �¶Û�Û ~rb�X ZPT^]�l*T^WPhs��~i�X�QSh=a*Y:ckTuQSRUa�]UZ^¯nT^ZP_oT^i^h\X [=[sq�z}a*W$Zpq�ZpQST^ckZ$fgRUT^WPTKQSRUT`QSWSX YUZPhsQSh=a*Y:WPT^[\X�QSh=a*Y:R�X Z$YUaZP�Ui^i^h=YUiuQ �¶Û�Û ~rWPT^_UWPT^ZPT^Y�Q+X�QSh=a*Y���ÜVa�fjTul*T^W^¯�QSRUTgckTuQSRUa�]@h=Z YUa Qyi^a*ck_U[=TuQST ¯�ZPh=YUi^TwQSRUTh=YU]U�UiuQSh=a*Y�~rZpQST^_Çckh=x*R�QwYUa QgboT_UWPa�l X bU[=T�Tul*T^Y�QSRUa*�Ux*RÇQSRUT_UWPa*_oT^WpQrqKh=Z¶QSWP�UT � a`c�X Ó TDQSRUTvckTuQSRUa�]Õi^a*ck_U[=TuQST ¯{QSRUTvh=YU]U�UiuQSh=a*Y�~rZpQST^_Õh=Z�ZpQSWPT^YUx QSRUT^YUT^]�h=Y�Qrfjaf¶X�q�Z^�Ï®th=WPZpQS[sq*¯¶QSRUT�_UWPa*_oT^WpQrqÝh=ZKX ZPZP�UckT^]ÈQSaÖRUa*[=]Ýz}a*WKX:_�X�QSRÈa z7ÞÃZP�Ui^i^T^ZPZPhsl*TZpQ+X�QST^Z^¯gWSX�QSRUT^WkQSR�X Y�ßP�UZpQ`a*YUT �  RUh=Z�ckT�X YUZ�QSR�X�QKX�[=a*YUx*T^Wkb�X ZPT�~ri�X ZPT�cv�UZpQ`boT_UWPa�l*T^Y��jË�T^i^a*YU]U[sq*¯UQSRUTZpQ+X�QST^ZVa z|QSRUT�_�X�QSR�X WPTX ZPZP�UckT^]ÇQSa@boT�UYUh=�I�UT �yÔ Qwz}a*[=[=a�fgZh=ckckT^]Uh\X�QST^[sqvz}WPa*cà��YUhsQST^YUT^ZPZ¶QSR�X�Q¶QSRUT1ZPT^i^a*YU]�ZpQSWPT^YUx QSRUT^YUh=YUx$c�X Ó T^Z¶QSRUT�ckTuQSRUa�]i^a*ck_U[=TuQSTvh=Y�QSRUT@ZPT^YUZPT@QSR�X�Q�QSRUT^WPTkh=ZX [sf¶X�q�Z7XK[=T^YUx QSR�z}a*W1fgRUh=i+R�QSRUT@h=YU]U�UiuQSh=a*Y�~ZpQST^_�h=Zg_UWPa�l X bU[=T �wË�a*�UYU]UYUT^ZPZ1h=ZwQSWPT�X�QST^]�h=Y�]UTuQ+X h=[¸h=Y�ZPT^iuQSh=a*Y�áU�wÒ¸TuQ��UZgz}a*WPc�X [=h=Æ^TQSRUTZpQSWPT^YUx QSRUT^YUT^]�h=YU]U�UiuQSh=a*YÇb�qK]UTu��YUh=YUx@QSRUT�z}a*[=[=a�fgh=YUx7z}a*WPcv�U[\X Z^�

âvã�ä^�Iå �&æèçué«´ëêId}ì7é�´�í7é�m�´�î�î�î�´ïd}ì å�ð Í ´�í å�ð Í mpñò´ ì åó ���Iô å �&æ ê�d}ì7ét´�í7éum�´�î�î�î�´ïd}ì å ´�í å mpñõ´ ì å�ö Í÷Ç�|�§ø�ù�� å �&æ úû=ü ý+ü å d©þ�ÿ��æÃþ�������m æ úû=ü ý+ü å

��� d� û���� ý��

mÙ�Y«h=Y�QST^WP_UWPTuQ+X�QSh=a*YÖa zgQSRUT^ZPTKz}a*WPcv�U[\X Zvh=Zv]UT^_Uh=iuQST^] h=Y���������� ���Va QST`QSR�X�Q$fgRUT^Y_UWPa�l�h=YUxki^a*WPWPT^iuQSYUT^ZPZ�fjTDZPRUa�f"QSR�X�QVQSRUTz}a*WPcv�U[\X ZgX WPTkÀ�¤ ��­ ¦§¥��}£j­"!^ª=¢u�jÔrY�QSRUT7b�X ZPT�~i�X ZPT�fjTX ZPZP�UckT�QSR�X�QgX [=[{ZPRUa*WpQST^Wwb�X ZPT�~ri�X ZPT^ZwR�X�l*T�boT^T^YK_UWPa�l*T^]�X [=WPT�X ]�q*¯�X YU]ÇX ]U]#%$'&)(+*-,/.�&)0�123,�24(+0�5)6 7�.�&)(98:0�1;=<4> 5�;/,�?@.�> 0�5�AB> 5C.�&)>D2FE)1�(G24(H5I.*J.�> 0�5LK�M),/.�&�*ON�(�6D*J.�(H1�*�;/0�E/.�(G;.�&)(P.�(H1�QR<S.�(HQTEU0�1*-6"> 5�;/,�?@.�> 0�5�AT*-5�;V,�24(G;�> .W> 5C0-.�&)(H1W?�0�5I.�(�XY.2HZ

[

Page 10: BMC’03 - JKUfmv.jku.at/papers/bmc03-preliminary-proceedings.pdfBMC’03 Boulder, Colorado, USA. ... Alessandro Cimatti (IRST, Italy) Raanan Fraer (Intel, Israel) Danny Geist (IBM

\^]_)`%ab`Lced:fgbh _)`biGi g `

T T T TT

P P P ¬PI, P

P P PP

T T T TT T

¬PP

Base−case

Induction−step

j'kml"n'oYnqpsrut�v)w+xzy�t�v|{}O~H���4�}O~H�q�D�W�)�����Jt��D�S�U�-�)� w��U� tP�4v)���)�D���Uw+��wG�����������'v)wH��w9w��/�D�St�W�)��xzy��St�wH����Jt�v�t��V���St�Jt�w+�Y� ���D�Jt�� �)�Bt�v)w+�)�����UwH�4tS���z�����4�)�T� �)�Bt�v)w+�)�����UwH�4tS�Vv)���D�)�Wt�v)w9����St�x��=�q�St�wH���H� �psr�t�v)wqxzy�t�v%�m�z�J ���¡���¢J���s~@¡��s£¤�D���)�����Jt��D�S�U�-�)� w��z� t��4v)���)�D���Uwq��wG���¥������¦)��� � �J§3� �)���-�¥xzy��St�wH��t����¨�w§3v)wH��w�t�v)w��)�����UwH�4tS�Bv)���D�)�H�Yt�v)wH��w�w��/�D�St�'�)�T�)w��YtF�St�Jt�w�§3v)wH��wP� t3r��-� �D���)�©Oª¬«%­¬®G¯z­°«I®H©@±²©O¯³«Y´UµJª�¶H©J´�©O«·´U¶�©Oª¬¸�¶C©O«I¹¬º¬¶¥©O¯³»|´U¼U«¤©Oª¬«%®G«I¶G½¬¾�©O¸�¹¬¿ÁÀbÂ�ÃqÄ@­¬®G¯zŬ¾�«I»«Y´U¶G¸�«I®IÆ�Çȸ�©Oª¤©Oª¬«I¶G«�º¬«�Éu¹¬¸�©O¸�¯z¹¬¶IÊ"Ëq«�µY´U¹·¹¬¯/Ë̶H©J´�©O«V´U¹|´U¾�¿z¯z®G¸�©Oª¬»R©Oªu´�©+¸�¹"©O«I®H©@Ë�¸�¹¬«I¶¾�¯b¯z¼L¸�¹¬¿�ÍS¯z®PŬ½¬¿z¶�¯UÍ°¾�¯z¹¬¿z«I®�´U¹¬º%¾�¯z¹¬¿z«I®P¾�«I¹¬¿U©Oª¬¶IÊ"´U¹¬º¤©O®H±b¸�¹¬¿C©O¯�­¬®G¯/Îz«B©Oª¬«B­¬®G¯z­°«I®H©@±Å"±eº¬«I«I­°«I®V´U¹¬º³º¬«I«I­°«I®�¸�¹¬º¬½¬µ�©O¸�¯z¹bÄ@¶H©O«I­¬¶IÏ

ÐÒÑ�ÓbÔbÕYÖ�×IØ:ÙÛÚLÜ·Ý)Þ�ßzÙÁàWÔbÕIábÑFâ-ã°ä'å°æ/×IÖ�Ô ã°ç'Üè ÔbÕVé³ê³ë nmn ì ä:ÔÖ èÒí4îJï/ðsñ�î�ò�ï�óOôöõUí@÷ ø áLù-ßzú)ûsü@üÕIß�×Iå°ÕYãþýLÿ��°ý��Lÿ������ �����Ö èÒí��FîJï/ðsñ�î�ò�ï�óOôöõUí@÷ � ×�ßUà ú û�� ÷ � ã:Ö���å°ß ú ûsü@üÕIß�×Iå°ÕYãþýLÿ��°ý��Lÿ�������������

� ´U®G¸s´�©O¸�¯z¹¬¶B¯UÍP©Oª¬¸�¶V´U¾�¿z¯z®G¸�©Oª¬» ´U®G«^´U¾�¶G¯|»·«Y´U¹¬¸�¹¬¿UÍS½¬¾�Æ �u¯z®�¸�¹¬¶H©J´U¹¬µI«UÊ°µJª¬«IµJ¼L¸�¹¬¿e¯z¹¬¾�±©Oª¬« Åu´U¶G«-Ä@µY´U¶G«�¿z¸�Îz«I¶²´�­¬½¬®G«�Ŭ½¬¿�Ä@ªL½¬¹"©O¸�¹¬¿ ´U¾�¿z¯z®G¸�©Oª¬»ÁÊ�Ë�ª¬¸�µJª º¬«I¾�¸�Îz«I®G¶þµI¯z½¬¹"©O«I®�Ä«"!¬´U»·­¬¾�«I¶³»·¯z®G«$#L½¬¸�µJ¼L¾�±zÆ&%+± ´U¾�©O«I®G¸�¹¬¿�©Oª¬« ÍS¯z®G»Ò½¬¾s´ ¯UÍ ©Oª¬« Åu´U¶G«-Ä@µY´U¶G«�¶G¾�¸�¿zª"©O¾�±zʸ�©�¸�¶�­°¯z¶G¶G¸�Ŭ¾�«�©O¯|¶H©J´U®H©V´�©C´%ª¬¸�¿zª¬«I®('�´U¹¬ºÁ©J´U¼L¸�¹¬¿·Å¬¸�¿z¿z«I®B¾�«Y´U­¬¶�©Oªu´U¹*)zÆ,+qª¬«IµJ¼L¸�¹¬¿«�Îz«I®H±·¶G¸�-I«�¯UÍ.'Á»|´Y±%Å°«�½¬¹¬¹¬«IµI«I¶G¶O´U®G¸�¾�±%µI¯z¶H©O¾�±zÆ0/Í'©Oª¬«�Ŭ½¬¿^¯z®9­¬®G¯b¯UÍ'¸�¶9º¬«I«I­'Êb©J´U¼L¸�¹¬¿Å¬¸�¿z¿z«I®C¾�«Y´U­¬¶¥»·«Y´U¹¬¶¥¶G¯z¾�Îb¸�¹¬¿=ÍS«�Ëq«I®ÒÀbÂ�ÃqÄ@­¬®G¯zŬ¾�«I»·¶IÆ21�¯/Ëq«�Îz«I®IÊ�¸�Í+©Oª¬«I®G«%¸�¶ ´eŬ½¬¿¬Ê354 6�7�8"9;:;<�=?>A@ ´U¶P¶H©J´�©O«Iº BFË�¸�¾�¾b´U¾�ËT´Y±b¶PÉu¹¬º%´C¶Gª¬¯z®H©O«I¶H©9µI¯z½¬¹"©O«I®�Ä@«"!¬´U»·­¬¾�«UÆ�ÃBª¬¸�¶P»|´Y±Å°«¤¸�»·­°¯z®H©J´U¹"©YÆC/@¹ ©Oª¬«%®G«I»|´U¸�¹¬º¬«I®C¯UÍ+©Oª¬«·´U®H©O¸�µI¾�«UÊ'Ëq«¤Ë�¸�¾�¾P¶Gª¬¯/Ë ª¬¯/Ë ©Oª¬«%µI¯z¶H© ¯U͸�¹¬µI®G«I»·«I¹"©O¸�¹¬¿D'³Å"±%¯z¹¬¾�±E)�µY´U¹·Å°«�¿z®G«Y´�©O¾�±Ò®G«Iº¬½¬µI«Iº|Å"±%¶G¯z¾�Îb¸�¹¬¿�©Oª¬«VÀbÂ�ÃqÄ@­¬®G¯zŬ¾�«I»·¶¸�¹¬µI®G«I»·«I¹"©J´U¾�¾�±zÆF G�HJILKNMPOQMPHSR�TVUXW5Y$Z

 ©@±b­¬¸�µY´U¾W¶H©J´U¹¬ºbÄ�´U¾�¯z¹¬« ÀbÂ�ÃqÄ@¶G¯z¾�Îz«I®V´UµIµI«I­ ©O¶C´%­¬®G¯zŬ¾�«I» ¸�¹¬¶H©J´U¹¬µI«^´U¶�¸�¹¬­¬½ ©YÊu¶G¯z¾�Îz«I¶¸�©YÊ3´U¹¬º ¯z½ ©O­¬½ ©O¶¥´e»·¯bº¬«I¾�¯z®¥´U¹\[^]�¹¬¶O´�©O¸�¶HÉ�´UŬ¾�«`_e¶H©J´�©O«I»·«I¹"© ´U¶�®G«I¶G½¬¾�©YÆÒÃBª¬¸�¶�µY´U¹Å°«�¸�¹u´Uº¬«`#L½u´�©O«V¸�Í:±z¯z½=Ë�¸�¶Gª·©O¯^¶G¯z¾�Îz«V»|´U¹"±·¶G¸�»·¸�¾s´U®9ÀbÂ�ÃqÄ@¸�¹¬¶H©J´U¹¬µI«I¶IÆ�ÃBª¬«C»·¯z¶H©q¯zÅbÄÎb¸�¯z½¬¶+¯/Îz«I®Gª¬«Y´Uº³¸�¶+®G«-Ä@­u´U®G¶G¸�¹¬¿ ©Oª¬« @ ´U¾�»·¯z¶H©"BP¶O´U»·«VµI¾s´U½¬¶G«V¶G«�©B¯/Îz«I®B´U¹¬º=¯/Îz«I®B´U¿"´U¸�¹'Æ%q½ ©¥»·¯z®G«¤¸�»·­°¯z®H©J´U¹"©O¾�±zÊ:©Oª¬«%¶O´U»·«UÊW¯UÍ�©O«I¹ «"! ­°«I¹¬¶G¸�Îz«UÊ�¸�¹ ÍS«I®G«I¹¬µI«I¶¥»|´Y± Å°«%µY´U®G®G¸�«Iº¯z½ ©·¯/Îz«I®|´U¹¬º ¯/Îz«I®|´U¿"´U¸�¹'Æbac#L½¬¸�­¬­¬¸�¹¬¿ ©Oª¬«²ÀbÂ�ÃqÄ@¶G¯z¾�Îz«I®%Ë�¸�©Oª ´U¹�¸�¹"©O«I®HÍ4´UµI«e©Oªu´�©

d

Page 11: BMC’03 - JKUfmv.jku.at/papers/bmc03-preliminary-proceedings.pdfBMC’03 Boulder, Colorado, USA. ... Alessandro Cimatti (IRST, Italy) Raanan Fraer (Intel, Israel) Danny Geist (IBM

egfhjilk�i�mon�pq�r hji�s^s q i

t�u�u�vxw(y5z|{�}l~�}"��z����c�S����~�y�z�t�~��`}�z|vX��}ly^��}`�`���N}`�*��~��`�^}`�2}`~�z�t�u�u������^v���z|{�}l�`���^�^}`~�z� y^v�u���}`� ����~�y�z�t�~��`}gw(��u�uP�`}`��z�t���~�u����^}`�2vx��}Cz|{�}C�Nt��^y^��~��E���^v���u�}`��������zD��t����^}`�����`}z|{�}�~����C��}`�(v�� ��~���}`�^}`~��`}`y,z|v�v�¡

¢ }o��v��`��y�v�~£z|{�}oz�����}Xv��5y^v�u���}`����~�z|�^v������`}`�b���¥¤ ¦A��§�§�¨©�ª�Nt�y^}`�bv�~¬«�­�®�¯S°©«²±³ ® ³�´¶µx· ° · t�~��¸« ´�³�¹�·xºJ»|º «�­ »^¼ °;®�½�¡^¾X������{Xtgy^v�u���}`�S���2��u�}`�2}`~�z|yªtC¿DÀVÁÂÁ���y�z���u�}5�Nt���Ã��z|�|t���Ã���~��y^}�t��^��{Ä���^v��`}`�����^}*¤ ¿DÁÂÁÂÅ�Æx¨©¡Ç�,{�}X����}�tA��}`{���~��bt������2}`~�z|��~��Az|{�}o�Nt�y^������^v��`}`�����^}�w(��z|{��`v�~�ÈN���²z5t�~Nt�u���y^��y(��y,z|{Nt�z���v��(}²��}`�����`v�~�ÈN���²z���}²z|}`�²z|}`������^��~��lz|{�}y^}�t��^��{.�cy^v��2}2}²É�v���zC��yÊy^��}`~�z�v�~*�N~�����~��At »|º|³j· ­�®£��v���z|{�}E�`v�~�ÈN���²zÊz|{Nt�zC��t�~Ç��}}`~��`v���}`�Ët�y�t��`uÌt���y^}Et�~��Ët�����}`�Çz|v�z|{�}E�`uÌt���y^}�y^}²z�¡�,{�} »|º «�­ »^¼�º|¼ �`uÌt���y^}`yCw(��u�uy^}`����},t�yct���t���{�}S��v��Pz|{�}Sy|t��2}ªz�����} v��N�`v�~�ÈN���²z|y0��~guÌt�z|}`�P�Nt���z|y v��Nz|{�}Sy^}�t��^��{���y^�Nt��`}�¡Í v��c}"��t��2��u�}������.t�y^y^���2��~���ÎXt�~���ÏCz|vÊ��}(z|�^��}�u�}`�lz|vCt��`v�~�ÈN���²z���z|{�}��`uÌt���y^}�Ð ÎPÑ Ï�Ò��t��*��}X�^}`�`v��^��}`�.¡£�5y^y^���2��~��}`��z|{�}`�CÎÄv���ϸz|v$��}Ez|�^��}X��~£y^v��2}ouÌt�z|}`�C�Nt���zlv��z|{�}Dy^}�t��^��{��Óz|�^}`}���w(��u�u����2�2}`���Ìt�z|}`u��l������}5z|{�}����2��u���}`�2��t�u���}5z|v�z|{�}Dv�z|{�}`� ��t��^�Ìt���u�}��t���v�������~��¸�^}`��}²z|��z|��v�~Ëv��Jz|{�}���v�y^y^����u��Ëu�}`~���z|{��Ë��}`�^����t�z|��v�~.¡Ä�,{�}�}²É�}`�²z|����}`~�}`y^yov��z|{���yS����}�tg{Nt�y ��}`}`~X}`�2�����^����t�u�u���}`y�z�t���u���y^{�}`�E���E��t�~��Et���z|{�v��^y`¡c�¬�2v�z|����t�z|��v�~l��v����~��`�^}`�2}`~�z�t�uP���c�Ô��y,z|{Nt�z�z|{�}Ê�^}`�`v��^��}`�A�`uÌt���y^}`y5��t��X~�v�z�v�~�u��X��}Ê��y^}²����uP��~�uÌt�z|}`��Nt���z|y(v�� z|{�}Êy^}�t��^��{��Óz|�^}`}gv��0z|{�} ·�³�Õ�º ���c�S����~�y�z�t�~��`}�� ����zJt�u�y^vl��~�t2uÌt�z|}`� · ° Õ ° ´�³�»���c�S����~�y�z�t�~��`}�¡

�Pv���}`y^�`�^����}5z|{�}D����É�}`�^}`~�z,��}`y^����~o��y^y^��}`y }`~��`v���~�z|}`�^}`�Xw({�}`~X���2��u�}`�2}`~�z|��~��gt�~��~��`�^}`�2}`~�z�t�u����c�S��y���y�z|}`����wS}Jt���v���zSt�~2v���Ö^}`�²z���v��^��}`~�z|}`�2����}²w�����y^��~��gt · ­ ´¶×�º²» ­�Ø`ÙÚ º «²±Dw({�����{£y�z|v��^}`ygz|{�}lÛ » ­�Ø ´�º²Õ « ´�³�¹�·xº�· � z|{�}��`���^�^}`~�z����c�S����~�y�z�t�~��`}x�Êt�ygwS}`u�uSt�yz|{�} ´�º|³�» ®N±ª« ´�³�¹�·xº�· � z|{�}5�^}`�`v��^��}`�X�`uÌt���y^}`y��"¡V�,{�}Jy^v�u���}`� {Nt�y �2}²z|{�v���yª��v��S�2v������;�����~���t�~��Ay^v�u�����~��2z|{�}g�`���^�^}`~�z����c�S����~�y�z�t�~��`}�¡5�,{�}gy^���2��u�}`y�z5����t�����~Nt���u�}J��~�z|}`���Üt��`}wSv���u��X�`v�~�z�t���~oz|{�}D��v�u�u�vxw(��~��C�2}²z|{�v���y`Ý

Þjßjß�à�á¶Þ�â�ã"äæåÜçJè�é�ê�ë"ìgí²î ïgðLñ�á�á�Þjßjß�ÞCò�á¶Þ�â�ã"ä�ó�ôCó�õ�äJò�á¶Þ�â�ã"äJßjÞxó�Þ�ö÷Þ`ã"ä"øã�ô�á ùxä ïgðLñ�á�áNã�ô�á ùxä5ó�õ�äJò�â�ú^ú÷ä|û�óPñ�û�ã|ó�Þ�û�ò^ä"ø

ü y^��~��(z|{���yP��~�z|}`���Üt��`}���z|{�}ª��y^}`� ��y t�u�u�vxwS}`��z|vJt����g�`uÌt���y^}`y ��~�z|��u�{�}ª{Nt�y y^��}`�`���N}`�gz|{�}�N�^y�z,���c�S�����^v���u�}`��¡0ý�}(��t�~2z|{�}`~���y^} · ­ ´¶×�º z|vÊ��{�}`��Ã2����z|{�}����^v���u�}`�þ��yVy|t�z|��y�� t���u�}v��C~�v�z�¡*ÿÓ�5��z���y`�V{�}o��t��Çt����Ë�2v��^}o�`uÌt���y^}`yCz|v$�`v�~�y�z|�|t���~Çz|{�}o���^v���u�}`� ������z|{�}`�t�~��$�^}"���^��~ · ­ ´¶×�º ¡Ê�,{���yD���^v��`}`�����^}l��t�~$��}��^}`��}�t�z|}`�¸��~�z|��uct�u�u0���c� ��~�y�z�t�~��`}`y�v����~�z|}`�^}`y�z�{Nt���}X��}`}`~Ëy^v�u���}`�.¡¸�V��������t�u�u��$z|{�}ouÌt�y�zC��~�y�z�t�~��`}o��yg��~�y|t�z|��y�� t���u�}��0���^v��w({�����{���v���~�z,~�v2}"��z|}`~�y^��v�~���t�~���}�y|t�z|��y�� t���u�}�¡

�,{���yct������^v�t���{�z|vD��~��`�^}`�2}`~�z�t�uN���c�D����~�z|�^v������`}`����~�¤ ý�v�Ã�§ � ¨©����y0u����2��z|}`�gt�y0z|{�}��y^}`�g��t�~*~�}²��}`�C�^}`�2vx��}Et�~���z|{���~��At�����}`�.¡�¦�t�~��¸��~�z|}`�^}`y�z|��~�����~��`�^}`�2}`~�z�t�uS���c�S����^v���u�}`�2yc�^}��������^}`yªy^v��2}(��v��^�þv��.�`uÌt���y^}(�^}`�2vx��t�u©¡ �,{�}`�^}²��v��^}C¤ ¢�� �����`¨�y^������}`y�z|}`�z|{�}D��v�u�u�vxw(��~��g��~�z|}`���Üt��`}Dz|v�z|{�}�y^v�u���}`�`Ý

Þjßjß�à�á¶Þ�â�ã"ä åÜçJè�é�ê�ë"ìCí²îú÷ä�ô�ùxäjà�á¶Þ�â�ã"ä åÜçJè�é�ê�ë"ìCí²î ïgðLñ�á�á ú÷ä�ô�ùxäDÞ�û�ä��xñ�ã|óÌñ�û� Cò�á¶Þ�â�ã"ä��^ú�ô�þó�õ�äã�ô�á ùxä ò�á¶Þ�â�ã"äJßjÞxó�Þ�ö÷Þ`ã"ä"ø

����������� ����� �!#"$�&%#'��&()�+*,� -,"/.0�1�+ ��0�32,�/46587�91:;�<�=,9?>�@A<B6CED�91F/FG<#HJILKMKM9?>6<�NJO#7�PQKMILRS<#2T��!SUV��"2T #UV��*,.0�/W�*YXZ�[�+*,� -,"/.0�Z=,9?>#R�ILP\2T��![=,9?>#B�@1@A]

^

Page 12: BMC’03 - JKUfmv.jku.at/papers/bmc03-preliminary-proceedings.pdfBMC’03 Boulder, Colorado, USA. ... Alessandro Cimatti (IRST, Italy) Raanan Fraer (Intel, Israel) Danny Geist (IBM

_a`b�cedQc?f\g&hiQj b�cQk$k i c

lMmonp6qsrtqsuGnv�w/x+y�z�v�{|y�uGm}r$v,n�~�x�w$v���y�nv����6w$~J�6�sv��trtz�y�u��Ev�r$~J���Jv���qsu6z�w$v��tv�uGnYy��s��mJ���~#�Sv,�Jv�w�{&np6vay��6qs�sq�n�m�n~�w$v��t~#�Jvaz���y��6r$v�r�z���y�r$p6v�r��|q�np�z�~Ju���qsz,n�z���y��6r$vaw$v�z�~Jw$�6qsu6�6��3p6v[z�~Ju���qsz,n3y�u�y���mQr$qsrMqsrS�J��y�wy�uGnv�v���n~��6w$~Q�6�6z�v�z���y��6r$v�rSnp�y�n3y�w$v�qs�t�6�sqsv��t�Gmtnp6v�6w$~J�6�sv���z���y��6r$vtr$v,n��Anp?�6r�y��6�6qsu6��np6v�r$v�z���y��6r$v�raz�y�u�u6v,�Jv�w�z�y��6r$v��6u6r$~J�6u6�6u6v�r$r��lS��n�w$v��t~#�Qqsu6�t�6w$~J�6�sv���z���y��6r$v�r���y�m�r$�6�6�6v�u6��m�w$v�u6�6v�w�w$v�z�~Jw$�6v���z���y��6r$v�r�qsuG��y��sqs���� �6v,nYy�qs�sv����6v��Ev�u6�6v�u6z,m y�u�y���mQr$qsr[���6r/n�np6v�w$v,x¡~Jw$v¢�Ev¢z�y�w$w$qsv���~J��n�n~\w$v��t~#�Jv¢np6vqsuG��y��sqs�[z���y��6r$v�r�{��|p6qszYp£qsu�n�6w$u£��y�m[w$v�¤?�6qsw$v¥vT¦Qnwy|�E~Q~J§J¨�§�v�v��6qsu6�|�6�6w$qsu6�©np6vMy�z,n��y��r$~J���Qqsu6�¢�6w$~Qz�v�r$r��Sª�~Jw3ye�s~Ju6�Jv�wSnw$v�y�n�tv�uGn�~�x�np6qsr|y��6�6w$~Gy�zYp�r$v�v�« ¬�­¯®�°�±�²V�

³�u´z�~JuGnwy�r/n�{[�Svµ�6w$~J�E~Jr$v¶np6v¶x¡~J�s�s~#�|qsu6�oqsuGnv�w/x+y�z�v��|p6qszYp·~Ju6��m¸v�u�y��6�sv�r�np6vw$v��t~#��y���~�xZ�6u6q�nMz���y��6r$v�r��A�3p6v[�t~�nq���y�nqs~Ju¢qsrAnp�y�nSq�nMqsr�¹�º,»T¼¢r$qs�t�6�sv©n~aqs�t�6�sv��tv�uGn½V¾ �sqsu6v�ra~�x|z�~Q�6v�qsu�~J�6w�r$~J���Jv�wY¿T{À�|p6qs�svt�Ev�qsu6��vT¦��6w$v�r$r$q��Jv�v�u6~J�6�Jp�n~�v�u6z�~J�t��y�r$rr$v,�Jv�wy��AqsuGnv�w$v�r/nqsu6�\qsu6z�w$v��tv�uGnYy��A® � �S¨��6w$~J�6�sv��tr[u6~�n�vT¦��6w$v�r$r$qs�6�sv¢�Gm�np6v¢~Jw$qs�Jqsu�y��qsuGnv�w/x+y�z�v�Á

Â�Ã�Ã?Ä&ÅÆÂ�Ç�ÈTÉËÊ+Ì[ÍsÎQÏEÐTÑaÒ,ÓÈYÔ�Å Õ#É Ê)Í�ÖsÐY×�Ø�ÙÀÖ�×,Ñ�Ú�ÎQÍ)ÛÝÜ#Þ�Þ�ß?à�á?â�ãÆä�å?Þ$Ó

�3p6vevT¦Qnwy��sqsr/n[~�xS�sq�nv�wy��sr���y�r$r$v�� n~�æ#ç�èƹ�ºer$p6~J�6�s�¶�Ev¢�Qqsv,�Sv��µy�r£�6u6q�n£z���y��6r$v�r�n~�Ev¢y��6�6v��¶�6�6w$qsu6��np6qsr[��y�w/nqsz��6��y�w�r$~J���Qqsu6�6{Enp6v�u¶w$v��t~#�Jv��¶�6�E~Ju¶w$v,n�6w$u�x¡w$~J�énp6vr$~J���Jv�w��À�3p6v�w$v�y�r$~Jutnp�y�n¥np6qsrSy��6�6w$~Gy�zYp�qsr¥r$qs�t�6�sv�wAqsrAnp�y�n�ê�è)è&�sv�y�w$u6v���z���y��6r$v�rSy�w$vry�x¡v[n~¢§�v�v���{Ey�u6�\np?�6r|u6~¢vT¦Qnwye�E~Q~J§J¨�§�v�v��6qsu6�¢qsr3u6v�v��6v����M��~¢r$v�v��|pGm�q�n©qsr3ry�x¡v�{u6~�nvtnp�y�nanp6v�vT¦Qnwy��6u6q�n�z���y��6r$v�r�z�y�u��Ev�r$v�v�u ½ y�u6��qs�t�6�sv��tv�uGnv��1¿£y�raqsuGnv�w$u�y��y�r$r$�6�t��nqs~Ju6r��Gm�np6ver$v�y�w$zYpµ�6w$~Qz�v��6�6w$v�{Ýy�u6�¶np�y�n£q�n£qsr£y�u qsu6p6v�w$v�uGn¯�6w$~J�Ev�w/n�m¶~�xz�~Ju���qsz,n�z���y��6r$v�rtnp�y�ntnp6v,m�y�w$v�qsu6�6v��Ev�u6�6v�uGn\~�x[np6v�y�r$r$�6�t��nqs~Ju6r��6u6�6v�wt�|p6qszYpnp6v,m\~Qz�z��6w��$ë

ì í?î[ïZð�ñ�òóñ�îSô6õ¥ö�í?î[÷£ø[ï&ô�ù�úSî

³�u¶r$v�z,nqs~JuµûQ� ü��Svery��ýy\r/nwy�qs�JpGn/¨0x¡~Jw/�©y�w$�¶y��s�J~Jw$q�np6�þx¡~Jw��6w$~#�Qqsu6�\~Jw��6qsr$�6w$~#�Qqsu6�ry�x¡v,n�m¶�6w$~J�Ev�w/nqsv�r£�Gm qsu6�6�6z,nqs~Ju��e¬µve�6w$v�y�§�np6qsr¯y��s�J~Jw$q�np6�ÿqsuGn~\n��S~���y�w/nr�{8np6v� ê�æ#º����ê�æ#º ½�� �6�6��¨���u6�6v�w�?¿Sy�u6��np6v� ����������Vç����Væ���º�� ½�� �6�6�Ev�w�¨��E~J�6u6�\�6w$~#�Jv�w�?¿T{�y�u6�r$p6~#� p6~#�·np6v,m�z�y�u��Ev¯qs�t�6�sv��tv�uGnv���qsu6z�w$v��tv�uGnYy��s��m��6r$qsu6�enp6v�® � �S¨�qsuGnv�w/x+y�z�v¯~�xr$v�z,nqs~Ju�ü��

��� ������ �!�"�!$#&%('*)�+$%-,�%.�&%.+��0/21 ��!$%.+����� 3%( .�0�54�%(6�1 '87&/9�:!$%�;<!$)=�>/9�0+$,�%-%3?@!$%.��!�ACBED<1 ��6�%.+�!$1 �&,!$#&%* 3/9�07�6�%GF�HJILKNMO"J�0��;NP���6$6�1 �&, H=��6Q�0�>��6$6�7&'*PR!$1 )��N/ 1 !$%.+��0/S"UTE%*�� �#&1 %.V�%W!$#&%X6$�0'*%8%3YZ%� �![��61 ��6�%.+�!$1 �&,*MOA�\]6$6�%.+�!$1 �&,8H-!$)84�%]!$+$7&%^�:�_!$%.+$T2�0+�;&6`Ta1 / /Z'X�0b�%L!$#&%^ 3/9�07�6�%L!$+$7&%]�c)�+$%.V�%.+�"��0��;G1 !2Ta1 / /4�%L+$%.'*):V�%�;[�c+$)�'d!$#&%] 3/9�07�6�%L;&�:!��04���6�%a4@D8!$#&%a!$)�PRef/ %.V�%./�6�1 '*P&/ 1 g� .�:!$1 )��XP&+$)R 3%�;R7&+$%a)0�Z!$#&%]6�)�/ V�%.+�A

h

Page 13: BMC’03 - JKUfmv.jku.at/papers/bmc03-preliminary-proceedings.pdfBMC’03 Boulder, Colorado, USA. ... Alessandro Cimatti (IRST, Italy) Raanan Fraer (Intel, Israel) Danny Geist (IBM

i>jk&l<mnlJoCpEqrns k&lnt�t r lu�vSwnxny@z�{�|E}�~��R�O��{��Z���2zf��w<�E�J�0���2��&�&�J�E�_�@���0������� �:�:�f�� xny��C���Z�_� � �Ex

�&�&�J�E�_�@���0������� ¡X¢U� £0¤���:¥@� ¦R����§ ¨n¢n©@�z � ��ª¬«J­¬®f¯0°�®�«�±¬²�³n�y���{�´�y@�¶µJ·¹¸�µ ³ · ­nº»°:«`®S²�¯�&�&�J�E�_�@���0����§�¨n¢¬©@��&�&�J�E�_�@���0������� ¼G¢Z�f�

u�vSwnxny@z�{�|E} ½¾�R�O��{��Z���2zf��wC�:{���¿E�2��&�&�J�E�_�@���0������� ¡G���f�� xny����ÁÀ.Â@�_�cÃO�Ä�Ex

�:¥@� ¦R����§R©@�z � �ÆÅ-Ç�¯:«J­¬®f¯0°�®�«�±¬²�³n�y���{�´�y@� ®SÇ`È]ÉX¯0­¹³ µÁÊ�¸ ²�ÈE¯�&�&�J�E�_�@���0������� ¼G¢Z�f��&�&�J�E�_�@���0������� ¡X¢U�f�� xny�ËL�C�Z�_� �¬Ì�ÂG�Ex

�&�&�J�E�_�@���0������� ÍRÎÐÏÑ ÍRÒ¹�f�ÓÕÔ�Ö�×.ØNÙZÚ¹×�Û�Ö.Ü�Ý�ØßÞSÙZà�ÙZàáØßâ¹Û�×�Û<Ý�ãSäZÙZÖ�Þ�Øßâ¹å�×ÐÞS×-Øßâ�Ý�Ø�Øßâ¹Û�æáÚ¹ç¹ÞSãSè¶Øßâ¹Û�ØßÖßÝ�é�Û�Ù�ê8×.Ø:Ý�ØßÛ�×Ö�Û�ãfÝ�ØßÛ�è(ÚUæ�Øßâ¹Û^ØßÖßÝ�à¹×�Þ�ØßÞSÙZà�Ö�Û�ãfÝ�ØßÞSÙZà�ÞSà(è¹Þ�ëEÛ�Ö�Û�àUØLè¹ÞSÖ�Û�é�ØßÞSÙZà¹×[ìÆí=ÞS×2è¹Û�é�Ö�Û�å�Û�àUØßÛ�è>ÞSà�Øßâ¹Û×.ØßÛ�î`ï0ð8ñ(Ö�ÙRòGÞSà¹äNØßâ¹ÛÐØßÖßÝ�é�ÛGêÆÙZÖ.ò*Ý�Ö�è¹×OÞSà�Øßâ¹ÛÐÚ�Ý�×�Û0ó�é@Ý�×�Û(Ý�ãSãSÙRòG×[ç¹×8ØßÙ>ô�Û�Û�îÁØßâ¹ÛÐÙ�ê ØßÛ�à×.ØßÖ�ÙZà¹ä�êÆÙZÖ�å�ç¹ãfÝ=õ � Ô¬ö¬Û�èáÞSà�Øßâ¹Û=÷nÓWøOó�×�ÙZã�ÜZÛ�Ö�ðGùOç¹ÞSãSè¹ÞSà¹ä�Øßâ¹ÛúØßÖßÝ�é�ÛúÞSà�Øßâ¹Û>ÙZî¹î�ÙZ×�Þ�ØßÛè¹ÞSÖ�Û�é�ØßÞSÙZàCòOÙZç¹ãSèûêÆÙZÖ�é�Ûúç¹×GØßÙ�î¹ç¬ØÐØßâ¹ÛúÞSà¹Þ�ØßÞfÝ�ãE×.Ø:Ý�ØßÛúé�ÙZà¹×.ØßÖßÝ�ÞSàUØß×-Ý�×-Ý�àáÝ�×�×�ç¹å�î¬ØßÞSÙZàãSÞ�ØßÛ�ÖßÝ�ã�ØßÙ5ü:ýRþ�ÿ������ � òGâ¹ÞSé:âúòGÞSãSã�â�Ý@ÜZÛ8Øßâ¹Û[ç¹à¹è¹Û�×�ÞSÖßÝ�Ú¹ãSÛ[Û�ëEÛ�é�ØQÙ�ê¬å5Ý�ôJÞSà¹äÐÝ�àUæ(Ö�Û�é�ÙZÖ�è¹Û�èé�ÙZà���ÞSé�Ø]é�ãfÝ�ç¹×�Û8è¹Û�î�Û�à¹è¹ÞSà¹ä�ÙZàNØßâ¹ÛOÞSà¹Þ�ØßÞfÝ�ã�×.Ø:Ý�ØßÛ8ÞSà¹Û�ëEÛ�é�ØßÞ�ÜZÛOÞSàú×�ç¹é�é�Û�×�×�Þ�ÜZÛXÞ�ØßÛ�ÖßÝ�ØßÞSÙZà¹×�ð÷nÞSå�ÞSãfÝ�Ö�ã�æ-ÞSà>Øßâ¹Û*×.ØßÛ�î � äZÖ�ÙRòGÞSà¹ä-Øßâ¹Û*ØßÖßÝ�é�Û*Ú�Ý�é:ôUò*Ý�Ö�è¹×Wå5Ý�ô�Û�×WÞ�ØQç¹à¹à¹Û�é�Û�×�×ßÝ�Ö.æ=ØßÙ�ç¹×�ÛÝ�àUæûÝ�×�×�ç¹å�î¬ØßÞSÙZàûãSÞ�ØßÛ�ÖßÝ�ãaÝ�Ø-Ý�ãSã � òGâ¹ÞSé:âáÝ�äUÝ�ÞSà�î¹Ö�ÙZå�Ù�ØßÛ�×GÖ�Û�ç¹×�Û>Ù�ê^Ö�Û�é�ÙZÖ�è¹Û�èáé�ãfÝ�ç¹×�Û�×Ú�Û�Ø�òOÛ�Û�à¶Þ�ØßÛ�ÖßÝ�ØßÞSÙZà¹×�ð Þ�ëEÛ�Ö�Û�àUØ�ØßÙZînó�ãSÛ�ÜZÛ�ãW×.ØßÖßÝ�ØßÛ�äZÞSÛ�×�êÆÙZÖ�â¹ÙRòÕØßÙ�é�ÙZå�Ú¹ÞSà¹Û>Øßâ¹Û=Ø�òOÙûÝ�ãSäZÙZÖ�Þ�Øßâ¹å�×ÐØßÙ�Ý

×ßÝ�êÆÛ�Ø�æUó�é:â¹Û�é:ôJÞSà¹äúî¹Ö�Ùné�Û�è¹ç¹Ö�ÛÐÝ�Ö�Û*î�ÙZ×�×�ÞSÚ¹ãSÛ�ðQø]Ù(Û�å�ç¹ãfÝ�ØßÛ�-ÿ �Jþ� ����������5Ù�ê�×�Û�é�ØßÞSÙZà��nð � �Øßâ¹ÛNÝ�ãSäZÙZÖ�Þ�Øßâ¹å�×8é�ÙZç¹ãSèCÚ�Û(Ö�ç¹à�ÞSàCî�Ý�ÖßÝ�ãSãSÛ�ã � Û@Ý�é:â�òGÞ�ØßâCÞ�Øß×XÙRòGà�×�ÙZã�ÜZÛ�ÖXÞSà¹×.Ø:Ý�à¹é�Û�ð[Ó-××�ÙnÙZà Ý�×>Øßâ¹Û5ÞSà¹è¹ç¹é�ØßÞSÙZànó�×.ØßÛ�î ×�ç¹é�é�Û�Û�è¹×=êÆÙZÖ>ݶî�Ý�Ö.ØßÞSé�ç¹ãfÝ�ÖNãSÛ�à¹ä�Øßâ � Ý�à ç¹à¹×ßÝ�ØßÞS×.Ô`Ý�Ú¹ãSÛÚ�Ý�×�Û0ó�é@Ý�×�Û8Ù�ê¬Øßâ�Ý�Ø]ãSÛ�à¹ä�Øßâ(òGÞSãSãZé�ÙZà¹×.ØßÞ�Øßç¬ØßÛ8ÝGî¹Ö�ÙnÙ�ê¬Ù�ê¬Øßâ¹Û8×ßÝ�êÆÛ�Ø�æNî¹Ö�ÙZî�Û�Ö.Ø�æZð��ÐÙRòOÛ�ÜZÛ�Ö �Þ�Ø(ÞS×NÝ�ãS×�ÙCî�ÙZ×�×�ÞSÚ¹ãSÛ�ØßÙ�å�Þcö¶Øßâ¹Û=Ø�òOÙ¶Ý�ãSäZÙZÖ�Þ�Øßâ¹å�×-ÞSàUØßÙ�ÙZà¹Û�ð�� Û=òGÞSãSã]Øßâ¹Û�àdâ�Ý@ÜZÛ<ØßÙÚ¹Ö�Û@Ý�ô»Øßâ¹ÛÁà�Ý�Øßç¹ÖßÝ�ãOè¹ÞSÖ�Û�é�ØßÞSÙZà Ù�êGÚ¹ç¹ÞSãSè¹ÞSà¹äûØßâ¹Û5ØßÖßÝ�é�Û5êÆÙZÖ>Û�Þ�Øßâ¹Û�Ö>Øßâ¹ÛÁÚ�Ý�×�Û0ó�é@Ý�×�ÛCÙZÖØßâ¹ÛNÞSà¹è¹ç¹é�ØßÞSÙZànó�×.ØßÛ�î2ð�� ÛúÝ�Ö�Ú¹Þ�ØßÖßÝ�Ö�ÞSã�æ<é:â¹ÙZ×�ÛNØßÙ<×ßÝ�é�Ö�Þ�Ô�é�ÛNØßâ¹ÛNÞSà¹è¹ç¹é�ØßÞSÙZànó�×.ØßÛ�î2ð

u�vSwnxny@z�{�|E} � ��!]zSw#"%$&�Jwn�2��&�&�J�E�_�@���0������� �:�:�'&�� (*)�+��-,/.U�����10324+1,1+ ¥�2Á� +1,��65��@��7:¥�5O�:�� xny-�����Z�_� �Ä�Ex

�&�&�J�E�_�@���0������� ¡X¢U� £0¤�� (8¨n¢8+��-,/.U�����10324+1,1+ ¥�2C� +1,��65��@��7:¥�58¡X¢�:¥@� ¦R����§ ¨n¢n©@� (ú�6,��:9<;X�&¥=2¬¥>,?+/2�@:� �J���8�:�z � �ÆÅ-Ç�¯:«J­¬®f¯0°�®�«�±¬²�³n� (�¡X¢BA����6,3.Z¥@�_�DCy���{�´�y@�¶µJ·¹¸�µ ³ · ­nº Ê�¸ ²�ÈE¯�:¥@� ¦R����§E)#F ¨n¢¬©@� (HG3���0�6IJ@.���0��;K+/2�@:� �J���8�:�z � ��ª¬«J­¬®f¯0°�®�«�±¬²�³n� (L@.¥@�M2�,��65NI3�PO���AQ9¬�c�?7:¥@�M2¬�DC

y���{�´�y@�¶µJ·¹¸�µ ³ · ­nº�°:«`®S²�¯�&�&�J�E�_�@���0����§�¨n¢¹©@� (=���.�0�656,2¡X¢*7N5�¥�AR2¬¥�S ¥�2�&�&�J�E�_�@���0������� ¼G¢Z�f� (=���.�0�656,?,15���2U�N+1,1+ ¥�2T7N5�¥�A ÍRÒ3,Æ¥NÍRÒ�UWV� xny�ËL�C�Z�_� �ZÀ.ÂÐ�Ex (=�&�&�>�M24+�X:�n�62¹���.�-@.¥�2U�6,15���+/2�,S�

�&�&�J�E�_�@���0������� ÍRÎÐÏÑ ÍRÒ��f�øXâ¹Û�Ö�Û@Ý�×�ÙZà êÆÙZÖ=×.Ø:Ý�ØßÞSà¹ä�Øßâ¹ÞS×<Ý�ãSäZÙZÖ�Þ�Øßâ¹å ÞS×=î�Ý�Ö.Øßã�æ ØßÙd×�â¹ÙRò Øßâ�Ý�Ø=Øßâ¹Û�Ö�ÛûÞS×=å5Ý�àUæî�ÙZ×�×�ÞSÚ¹ãSÛ(ò*Ý@æn×�Ù�ê^Û�à¹é�Ùnè¹ÞSà¹ä�Øßâ¹Ûú×ßÝ�êÆÛ�Ø�æUó�é:â¹Û�é:ôJÞSà¹ä�î¹Ö�Ùné�Û�è¹ç¹Ö�Û>ÞSà¹é�Ö�Û�å�Û�àUØ:Ý�ãSã�æZðQ� Þ�Øßâ

Y

Page 14: BMC’03 - JKUfmv.jku.at/papers/bmc03-preliminary-proceedings.pdfBMC’03 Boulder, Colorado, USA. ... Alessandro Cimatti (IRST, Italy) Raanan Fraer (Intel, Israel) Danny Geist (IBM

Z\[]D^H_�^4`Bacbd�e ]D^�fNf d ^

g6hji/kQl�m/nMoMpNi'g6hjqsr�g6hjt*u�vWwyxJkNoMm'zMt{pQi/kyl�m/m/o>|yt{}Hg6o=kNh<l�pNt�~{oM���<i/~EgQ~{m1l��jkNt{ky��tEgJ|yt{t{�8g6hjt�<l�kNt�xJ~�l�kNt�l��j}�g6hjt8i/�j}j�j~Eg6i/oM��xJk%g6t{��rW|�hji/~�h�q�l�����t8��t{�jtE�<~{i1l�m�����tBi/�j~{m/�j}jt�g6hjtl�m/nMoMpNi'g6hjq�i/��oM�jp���t{�j~�hjq�l�pN�8kNt{~Eg6i/oM���

�������T�/�>�E�#���E�������t*|�i/m/mc�jo>|�g6p%�8g6oL}jp6l�| lLq�l��Bo>zMt{p���oMkNkNi/�jm/t*i/�j}j�j~Eg6i/oM�B�<l�kNt{}sk6l�¡¢tEgJ�#xJ~�hjt{~��4i/�jnl�m/nMoMpNi'g6hjq£k{�?¤¥tEg��jkK�jkNt*g6hjt�g6t{pNq§¦�¨#© �Eª ¨ ªJ« ¡¢oMp�l\k%g�l�g6t�|yt{pNt*g6hjt¬k6l�¡¢tEgJ���jpNoM��t{p%gJ�}jo�t{ks�jo�g­hjoMm/}��¯®°g­i/k�nMt{�jt{p6l�m/m'�±oM�jkNt{p%zMt{}²g6h<l�g­~�hjt{~��4i/�jn³k6l�¡¢tEgJ���jpNoM��t{p%g6i/t{ksi/kk%��q£q£tEg6pNi/~�|�i'g6h´pNt{kN��t{~Eg\g6o�g6hjt£i/�ji'g6i1l�m?k%g�l�g6t{k�l��j}µg6hjt£�<l�}�k%g�l�g6t{k{�B¶�zMt{p%�4g6hji/�jn�jpNt{kNt{�#g6t{}��j�´g6o�g6hji/kT��oMi/�#g=~{oM�jm/}´h<l�zMt���t{t{��~�l�pNpNi/t{}´oM��g=�<l�~��#|Kl�pN}jk{r�|�i'g6hµg6hjtpNoMm/t{k�o�¡�i/�ji'g6i1l�m·k%g�l�g6t{k£l��j}¸�<l�}¸k%g�l�g6t{kHt�¹�~�h<l��jnMt{}�rKl��j}�g6hjtBg6p6l��jkNi'g6i/oM��pNt{m1l�g6i/oM�i/�#zMt{p%g6t{}��W��t=l�pNtTnMoMi/�jn�g6o£l�}joM��g�g6hji/k�k%��q£q£tEg6pNi/~�l�m�z�i/tE|º¡¢pNoMq»�jo>|²oM���®J�£g6hji/kWz�i/tE|Tr4|yt-pNt{n#l�pN}£g6hjt�i/�j}j�j~Eg6i/oM��xJk%g6t{��l�kylTq£tEg6hjo�}£o�¡c�<�j}ji/�jn\l����j�j��t{p

��oM�j�j}¸oM��g6hjtBm/t{�jn�g6h�o�¡*l¼kNhjoMp%g6t{k%g£~{oM�j�#g6t{pPxJt�¹jl�q£�jm/t�ryl��j}�g6hjtB�<l�kNt�xJ~�l�kNtsl�kHl|Kl��¼o�¡Q�jpNo�}j�j~{i/�jn8g6hjtL~{oM�j�#g6t{pPxJt�¹jl�q£�jm/t��\½-o>|Tr¥|�h<l�g¬q��jk%g=l8kNhjoMp%g6t{k%g=~{oM�j�#g6t{pPxt�¹jl�q£�jm/t-m/o�oM�Lm/i/��t>¾�®°g�h<l�kQg6o�k%g�l�p%g�i/�8l��8i/�ji'g6i1l�m<k%g�l�g6t�r�i'gyh<l�kyg6o�t{�j}B�j�Bi/�8l\�<l�}k%g�l�g6t�r�l��j}£g6hjt-k%g�l�g6t{kQi/�£��tEgJ|yt{t{�Bq��jk%gQ�jo�gy��t�t{i'g6hjt{pQi/�ji'g6i1l�m�oMpQ�<l�}¼¿¢o�g6hjt{p%|�i/kNt-i'g~{oM�jm/}­�jo�g���t�l£kNhjoMp%g6t{k%g¬~{oM�j�#g6t{pPxJt�¹jl�q£�jm/t>À��-Á-kNi/�jn8Âÿ¢�<l�}ÄÀK¡¢oMp Å»|yt�~�l��­z�i/tE|g6hjtTkNtEg-o�¡?��oMkNkNi/�jm/t¬kNhjoMp%g6t{k%g-~{oM�j�#g6t{pPxJt�¹jl�q£�jm/t{k-�ji/~Eg6oMpNi1l�m/m'��Æ

Ç «E��È�ª�ɼÊMË Ì ÂÇ «E��È�ª�É­�#Ë Ì Â ÍÎ Ì ÂÇ «E��È�ª�É�Ï�Ë Ì Â ÍÎ Ì Â ÍÎ Ì ÂÇ «E��È�ª�ÉsÐ4Ë Ì Â ÍÎ Ì Â ÍÎ Ì Â ÍÎ Ì Â

Ñ�Ñ�ÑÇ «E��È�ª�É���Ë Ì Â ÍÎ Ì Â ÍÎ Ì Â ÍÎ Ñ�Ñ�Ñ ÍÎ Ì Â ÍÎ Ì Â

¶·l�~�hHm/i/�jtK}jt{�ji/~Eg6i/�jnTlH¿¢kNhjoMp%g6t{k%g�À�~{oM�j�#g6t{pPxJt�¹jl�q£�jm/t�~{oMpNpNt{kN��oM�j}jkWg6o=l*~{oM�DÒN�j�j~Eg6i/oM�o�¡3~{oM�jk%g6p6l�i/�#g6kT¿ ÌEÓ�Ô8Õ=Ó�Ô Â£Ö Ô Ì Ö Ô8Õ Ö Ô Ñ�Ñ�Ñ À��Ww�hjt{pNt¬i/kKl�m/o�gyo�¡3kNh<l�pNi/�jn���tEgJ|yt{t{�g6hjt=~{oM�j�#g6t{pPxJt�¹jl�q£�jm/t{k-o�¡�}ji'×ct{pNt{�#g�m/t{�jn�g6hjk{r�l��j}­i/�j}jt{t{}­i'¡?|yt\pNt{q£o>zMt=t{i'g6hjt{p�g6hjti/�ji'g6i1l�m Ì oMpKg6hjt¬�<�<l�m3»¡¢pNoMqØg6hjtTÙÄx°g6hs~{oM�j�#g6t{p�t�¹jl�q£�jm/t�r<i�� t��'Æ

¿PÚDÀ  ÍÎ Ì Â ÍÎ Ñ�Ñ�Ñ ÍÎ Ì Â ÍÎ Ì Â

��Û ¿�ÜMÀ Ì Â ÍÎ Ì Â ÍÎ Ñ�Ñ�Ñ ÍÎ Ì Â ÍÎ Ìg6hjt{��l��#�L~{oM�j�#g6t{pPxJt�¹jl�q£�jm/t�o�¡cm/t{�jn�g6hHÙ�oMp Ç ����È4«EÛ |�i/m/mji/�j~{m/�j}jt�l�m/m�g6hjt�~{oM�jk%g6p6l�i/�#g6ko�¡£¿PÚDÀHl��j}Ý¿�ÜMÀ���w�hji/k�q£t�l��jk£g6h<l�g�i'¡¬t{i'g6hjt{p£g6hjt­~{oM�jk%g6p6l�i/�#g6k�o�¡�¿PÚDÀLoMp�¿�ÜMÀ�r�oMpl��#� �E� ¦ �>«Eª o�¡Wg6hjt{kNt�rc��i/t{m/}jk*l����j�jk6l�g6i/k%�Äl��jm/t\�jpNoM�jm/t{qsrÄg6hjt{��kNo�|�i/m/mK¨ Ç�Ç ��oMkNkNi/�jm/tkNhjoMp%g6t{k%gL~{oM�j�#g6t{pPxJt�¹jl�q£�jm/t{kLo�¡�m/oM�jnMt{p\m/t{�jn�g6hjk{��w�h4�jk�|ytBh<l�zMt8¡¢oM�j�j}¸l����j�j��t{p��oM�j�j}�oM��g6hjtTkNhjoMp%g6t{k%g-~{oM�j�#g6t{pPxJt�¹jl�q£�jm/t��w�hjtT�ji/~Eg6�jpNt¬l���o>zMtT}jo�t{k��jo�g�~{oM�#g�l�i/��l�m/mc~{oM�jk%g6p6l�i/�#g6k�}jt{pNi'z�l��jm/t�¡¢pNoMq�g6hjt*¡:l�~Eg

Þ

Page 15: BMC’03 - JKUfmv.jku.at/papers/bmc03-preliminary-proceedings.pdfBMC’03 Boulder, Colorado, USA. ... Alessandro Cimatti (IRST, Italy) Raanan Fraer (Intel, Israel) Danny Geist (IBM

ß\àáDâHã�â4äBåcæç�è áDâ�éNé ç â

ê6ë<ì�ê·íyî*ì�ïNî�ð{ñMòjóNô/õjî{ïNô/òjö\ìL÷�ø<ù�ú�ûJü�÷EûWð{ñMýjò#ê6î{ïPþJî�ÿjì������/î�����î-ð�ì�ò�¢ýjï%ê6ëjî{ïyð{ñMòjð�/ýjõjî��� �� yîEêJíyî{î{ò¼òjñHêJíyñ£ó%ê�ì�ê6î{ó�ô/ó�ê6ëjî{ïNî=ìLóNëjñMï%ê6î{ï��<ì�ê6ë��

ù�ú��yü����#üEú����� yîEêJíyî{î{ò¼òjñHêJíyñ£òjñMò�þJòjî{ô/öMë���ñMïNó�ô/óKê6ëjî{ïNî\ì�ê6ï6ì�òjóNô'ê6ô/ñMò� ì�òjõ�ê6ëjî��1ì�ó%ê�ó%ê�ì�ê6îTô/ó�ýjòjô��4ýjî! "�

ù�ú��yü����#üEú$#%��&-ñHêJíyñ£ó%ê�ì�ê6î{ó�ì�ïNî*ê6ëjîTó6ì��£î��' ò)(�ñ� ê6ëjî{óNî�:ì�ðEê6ó�ð�ì�ò*��îTýjóNî{õsí�ëjî{ò*�jïNñ!+�ô/òjö�ì�òsý�����î{ï���ñMýjòjõ�� ' ó��/ñMòjö£ì�ó�íyî, î{î��ì�õjõjô/òjöBð{ñMòjó%ê6ï6ì�ô/ò#ê6ó¬ê6ë<ì�ê���ýjó%ê-��î.¢ý��0/1���/î{õ2�)(�óNëjñMï%ê6î{ó%ê\ð{ñMýjò#ê6î{ïPþJî�ÿjì������/î{ó3ì�ò)(�ð{ñMò#ê6ï6ì�õjô/ðEê6ô/ñMòµïNî�ì�ð�ëjî{õ4�£î�ì�òjó¬íyî£ë<ì5+Mî�î{ó%ê�ì����/ô/óNëjî{õ�ì�ò´ý�����î{ï-��ñMýjòjõ���6�ëjîïNî�ì�óNñMò7¢ñMï£ó%ê�ì�ê6ô/òjö´íyî�ì , î{ï8+Mî{ïNóNô/ñMòjó8ñ�*ê6ëjî¼óNëjñMï%ê6î{ó%ê%þ9�<ì�ê6ë³ïNî�4ýjô/ïNî�£î{ò#ê8ô/óHê6ë<ì�êê6ëjî{óNî*+Mî{ïNóNô/ñMòjó8ð�ì�ò:��î­ô������/î�£î{ò#ê6î{õ;�£ñMïNî­î=<£ð{ô/î{ò#ê��0(>�@?<ýjï%ê6ëjî{ïA�£ñMïNî�3Kíyî¼ë<ì5+Mîì��/ïNî�ì�õ%(�òjñ�ê6î{õ8ê6ë<ì�ê�ê6ëjî*ê6ëjô/ïNõ8ð{ñMòjõjô'ê6ô/ñMò8ô/óKî{òjñMýjöMëBê6ñB��ì , î*ê6ëjî��jïNñ�ð{î{õjýjïNî¬ð{ñ>�Lþ���/îEê6î��DCJòTê6ëjî·òjî�ÿ�ê?óNî{ðEê6ô/ñMòTíyîQõjî{óNð{ïNô���îQëjñ>í�ê6ëjîQô������/î�£î{ò#ê�ì�ê6ô/ñMò*ñ��ê6ëjô/ó3ð{ñMòjõjô'ê6ô/ñMòð�ì�òE��îTô����jïNñ!+Mî{õ��

6?ì , ô/òjö´ê6ëjô/ó�óNý��jóNîEê%þJñ�1þJð{ñMýjò#ê6î{ïPþJî�ÿjì������/îF+�ô/îEí�3Kê6ëjî­ô/òjõjýjðEê6ô/ñMò�þJó%ê6î� íyî¼ë<ì5+MîýjóNî{õ´ô/òµñMýjïTì��/öMñMïNô'ê6ë��£ó�ð�ì�ò´òjñ>íG��î.+�ô/îEíyî{õ�ì�ó¬óNî�/î{ðEê6ô/òjö�ê6ëjîLóNý��jóNîEê\ñ� � � �òjñ�êð{ñMò#ê�ì�ô/òjô/òjö8ì�ò)( H�� óI�jý�ê¬ô/òjð�/ýjõjô/òjö£ê6ëjîLýjòjô��4ýjî{òjî{óNóTð{ñMòjó%ê6ï6ì�ô/ò#ê6ó*õjô/ðEê�ì�ê6î{õ2�)(­ð{ñMò�þõjô'ê6ô/ñMòJ#%�LK@6�ëjïNñMýjöMë�î�ÿ%��î{ïNô��£î{ò#ê6ó8íyî2¢ñMýjòjõ±ê6ë<ì�êBê6ëjô/óBð�ëjñMô/ð{î¼íyñMï , î{õ�íyî���*ô/ò�jï6ì�ðEê6ô/ð{î��

MON�P$QSRUTOV�RUT�W �EX�ùZY T ûJüEú"[NüA\���]_^O`/üCaWê6ëjîLýjóNî{ï , òjñ>í�ó¬ñMï*ë<ì�ó*ïNî�ì�óNñMò�ê6ñb��î�/ô/î=+Mî\ê6ë<ì�ê*ê6ëjî.�jïNñ>��î{ï%ê9(¼ô/ó_:ì��/óNî�3cëjî.��ì5(íKì�ò#ê-ê6ñ£ïNýjò.cNýjó%ê-ê6ëjî��<ì�óNî�þJð�ì�óNî=ê6ñ��4ýjô/ð , �0(d�jïNñ�õjýjð{î\ìHð{ñMýjò#ê6î{ïPþJî�ÿjì������/î��eCJòsê6ëjô/óð�ì�óNî�3cô'ê-ô/óf�/î{óNó�ð�/î�ì�ï-ô0·ì�ò)(sî�ÿ�ê6ï6ì�ð{ñMòjó%ê6ï6ì�ô/ò#ê6ó�óNëjñMý��/õg��î\ì�õjõjî{õ¼ê6ñ£ê6ëjî=ê6ï6ì�ð{î��fCJòh ` W ù�ú R û�ø�]ji8ì�òjõ P íyî�ð�ëjñMóNî�ê6ñ=ì�õjõlkE�nmsñMïNî�ð{ñMòjó%ê6ï6ì�ô/ò#ê6ón�£î�ì�òl�£ñMïNîKð�1ì�ýjóNî{ó·ô/òê6ëjîyóNñ>�0+Mî{ï3�í�ëjô/ð�ëB�/î�ì�õjó ê6ñ*óA�/ñ>íyî{ïo�jïNñ>�<ì�ö#ì�ê6ô/ñMò�3Z�jý�ê·ì��/óNñ-ê6ñ¬ì�óA��ì����/î{ï3óNî�ì�ïNð�ë�þ°ê6ïNî{î��� ëjô/ð�ë�ñ� ê6ëjî¬êJíyñ£î=pcî{ðEê6ó�ô/óq�jïNî{õjñ>�£ô/ò<ì�ò#ê�ô/ò�ìB�<ì�ï%ê6ô/ð{ý��1ì�ïKð�ì�óNîTô/ó�ë<ì�ïNõBê6ñ_cNýjõjöMî��CJò�öMî{òjî{ï6ì��r3Äì�õjõjô/òjö�íyî�ì , ð{ñMòjó%ê6ï6ì�ô/ò#ê6ó�ô/ó�óNî�/õjñ>� ìLöMñ�ñ�õ�ô/õjî�ì%�

s ïNî{óNî{ò#êd qmgt�ê6ñ�ñ>�/óLð�ì�ò ñ>��ê6ô/ñMò<ì����0(u�jïNñ�õjýjð{î­ìuv ' 6yþ9�jïNñ>���/î� ó%ê�ì�ê6ô/òjö�ê6ë<ì�êê6ëjî��jïNñ>��î{ï%ê9(2:ì�ô��/ó=ì��£ñMòjöBê6ëjîl/<ïNó%ê.w ó%ê6î�jó\ï6ì�ê6ëjî{ïTê6ë<ì�ò�ìZ�ê6î{ïTî�ÿjì�ðEê��0(xw ó%ê6î�jó�tKì�ïNî_��ýjó%êe��î-ê�ì , î{òd��î=¢ñMïNî*ì�õjõjô/òjö=î�ÿ�ê6ï6ì\ð{ñMòjó%ê6ï6ì�ô/ò#ê6óyê6ñ\óNýjð�ëb¢ñMïA��ý��1ì�ê6ô/ñMòjó�o?<ñMïô/òjó%ê�ì�òjð{î�3?ñMòjî�ð�ì�ò�òjñg�/ñMòjöMî{ïTïNî�4ýjô/ïNî£ê6ëjî�ó%ê�ì�ê6î{ó=ê6ñ*��î£ýjòjô��4ýjî��gy*òjî8��ýjó%ê�ì��/óNñì�óNóNý��£î � ñMï��£ñ�õjô0U(� \ê6ëjîsê6ï6ì�òjóNô'ê6ô/ñMò¸ïNî�1ì�ê6ô/ñMò¸ê6ñ�ì��'íKì5(�ó�ë<ì5+Mî¼ì�òjî�ÿ�ê8ó%ê�ì�ê6î�z�ñMïïNô/ó , öMîEêNê6ô/òjöHì�òBýjòjó6ì�ê6ô/óL/Äì����/îI�jïNñ>���/î�¯õjýjî*ê6ñLõjî�ì�õ��/ñ�ð , 3jî=+Mî{òsô/ò8ê6ëjî��jïNî{óNî{òjð{î=ñ�ì*�jýjö�� ' ð{ñ>���<ì�ïNô/óNñMò4��îEêJíyî{î{ò�ê6ëjô/ó2{%ñMòjî�þJóNëjñ�ê�|g�£îEê6ëjñ�õ�ì�òjõ�ê6ëjî�ô/òjð{ïNî�£î{ò#ê�ì���<ì�óNî�þJð�ì�óNîTô/ó�ô/òjð�/ýjõjî{õsô/òBñMýjï�î�ÿ%��î{ïNô��£î{ò#ê6ó�

MON~}�� ]_^�ú6ùZ� RUT�W û�ø<ü*� T1R�� Y<ü��Äûa��ûJü�÷���ü � Y R ú6ü=]�ü T û6�ëjî=ýjòjô��4ýjî{òjî{óNó�ð{ñMòjó%ê6ï6ì�ô/ò#ê6ó-õjî{óNð{ïNô���î{õ­ô/ò�óNî{ðEê6ô/ñMò2��� #Hì�òjõ­ýjóNî{õ­ô/ò h ` W ù�ú R û�ø�]�i��} ì�òjõ M ïNî�4ýjô/ïNî�î�ì�ð�ë4�<ì�ô/ï=ñ��ó%ê�ì�ê6î{ó=ê6ñ*��î�õjô0pcî{ïNî{ò#ê5�E6�ëjî{óNî8ïNî�4ýjô/ïNî�£î{ò#ê6ó�ì�ïNî�������q�r�a���!�9�r���>�a�����0���q���U���e� ��r�r�! !¡Z¢��A _� �B£ ¤¦¥§¥§¨>©=©�ª%¢L«"��¬�� ­®� ¯°«"�r¯ ±�²��n³5� �L´µ�A I«=¬µ�r���S¬�¡�²Z¬����¢��=��a«"� ��� ��¶e�=��¯ ±q�r���S·I¸ ¬��r�=¶=���r���L�§´§� �r�I¡����°¹¡��L���A¬r¬¦¢��=�Z¬º�r�a«"� ��a¬L»

¼

Page 16: BMC’03 - JKUfmv.jku.at/papers/bmc03-preliminary-proceedings.pdfBMC’03 Boulder, Colorado, USA. ... Alessandro Cimatti (IRST, Italy) Raanan Fraer (Intel, Israel) Danny Geist (IBM

½¿¾À�ÁlÂ�Á�ÃdĵÅÆ�Ç À�Á�ÈAÈ Æ Á

É=ÊaË�Ê�ÌrÍ�Ë�ÎUÎÐÏ.Ñ�Ò�Ò�ÓÒ�Ô�Ñ�Õ�ÒlÖ�×�ÓØ�ÙnÕ�Ú�Û.ÜOÓÙnÝ�Ø�Þ�Þ%ß>ÙAà!Ý:á�Ú1Ñ�Ò�Ù�ÑZÖ�Ø�â5Ñ�Þ�Þ0ã¿Ø�ÕBÖ�×�Ó�Þ�ÓÕ�ß�Ö�×là�äOÖ�×�ÓØ�Õ�Ò�Ú�â=Ö�Ø�à>Õ�å9æLÖ�Óç�èoé1à>Ùoç�ÙAà>Ü�Þ�ÓÛ�æ�ÙAÓá�Ú�Ø�ÙAØ�Õ�ß_×�Ø�ß>×BØ�Õ�Ò�Ú�â=Ö�Ø�à>Õ¿Þ�ÓÕ�ß�Ö�×�Ô�Ö�×�ÓÙAÓqØ�æ�ÑIÙAØ�æAê-à�äÑ�Ò�Ò�Ø�Õ�ßIÕ�Ú�Û�ÓÙAà>Ú�æ�çOà>æAæAØ�Ü�Þ0ã-æAÚ�çOÓÙLë1Ú�à>Ú�æSâà>Õ�æLÖ�Ù�Ñ�Ø�Õ)Ö�æoÖ�×1ÑZÖ�Ý�Ø�Þ�Þ)Ö�Ñ�ì¿Ö�×�Ófí�înïeå9æAà>Þ0ð>ÓÙ×�Ó5Ñ5ð�Ø�Þ0ã>è�ñuÓlç�ÙAà>çOà>æAÓlÑóò�ÏZôOË�õBÌrÍBÑ�ç�ç�ÙAà)Ñ�â�×2Ý�×�ÓÙAÓBÖ�×�ÓlÛ�à�Ò�ÓÞ�æ_ÙAÓ=Ö�Ú�ÙAÕ�ÓÒxÜ)ãgÖ�×�ÓæAà>Þ0ð>ÓÙ�Ø�ÕdÖ�×�Ó-Ø�Õ�Ò�Ú�â=Ö�Ø�à>Õ�å9æLÖ�Óç*Ñ�ÙAÓ�Ó"ì�Ñ�Û�Ø�Õ�ÓÒ�ÔöÑ�Õ�ÒFà>Õ�Þ0ãdØ0äDÖ9Ýeà�æLÖ�ÑZÖ�Óæ_Ñ�ÙAÓ¿Ñ�â=Ö�Ú1Ñ�Þ�Þ0ãÓá�Ú1Ñ�ÞrÔöÑlâà>Õ�æLÖ�Ù�Ñ�Ø�Õ)Ö_æLÖ�ÑZÖ�Ø�Õ�ßBÖ�×1ÑZÖ�Ö�×�Ó=ãFæA×�à>Ú�Þ�ÒFÜOÓ�Ò�Ø0÷µÓÙAÓÕ)Ö_Ø�æfÑ�Ò�Ò�ÓÒ�èeïq×�Ó¿æAà>Þ0ð>ÓÙÛ.Ú�æLÖ¦Ö�×�ÓÕ-ÜOÓSÙAÚ�Õ.Ñ�ß)Ñ�Ø�Õ�Ô5Ý�×�Ø�â�׿Û8Ñ5ãIçOà>æAæAØ�Ü�Þ0ã�âà>æLÖDÛ�à>ÙAÓ�Ö�×1Ñ�Õ¿Ñ�Ò�Ò�Ø�Õ�ßfæAÚ�çOÓÙLë1Ú�à>Ú�æâà>Õ�æLÖ�Ù�Ñ�Ø�Õ)Ö�æÔ�Ü�Ú%Öq×�à>çOÓ=äºÚ�Þ�Þ0ã�Ö�×�ÓIØ�Õ�âÙAÓÛ�ÓÕ)Ö�Ñ�Þ�Ø0Ö9ã�à�ä¦Ö�×�Ó�Ñ�ç�ç�ÙAà)Ñ�â�×EÛ�Ó5Ñ�Õ�æeÖ�×1ÑZÖfÑ�Õ)ãÙAÓ"å9ÙAÚ�Õ.Ø�æoð>ÓÙLã.á�Ú�Ø�â�êöèoñuÓeð>ÓÙAØ0ø1ÓÒBÓ"ì%çOÓÙAØ�Û�ÓÕ)Ö�Ñ�Þ�Þ0ã�Ö�×1ÑZÖoÖ�×�Ó®Û�Ó=Ö�×�à�Ò.Ø�Õ�Ò�ÓÓÒBæAÓÓÛ�æÖ�àlçOÓÙLäºà>ÙAÛùÜOÓ=ÖAÖ�ÓÙ�Ø�ÕEß>ÓÕ�ÓÙ�Ñ�Þrè

î:á�Ú�ÓæLÖ�Ø�à>Õ.Ö�×1ÑZÖ�×1Ñ�ænÕ�à�Ö�ÜOÓÓÕBÖ�ÙAÓ5ÑZÖ�ÓÒBæAÚ%ú�âØ�ÓÕ)Ö�Þ0ã¿Ø�Õ.Ó5Ñ�ÙAÞ�Ø�ÓÙoç�ÙAÓæAÓÕ)Ö�ÑZÖ�Ø�à>Õ�æ�à>ÕØ�Õ�Ò�Ú�â=Ö�Ø�à>ÕEØ�æqÝ�×1ÑZÖfð�Ñ�ÙAØ~Ñ�Ü�Þ�Óæ�æA×�à>Ú�Þ�ÒFÜOÓ-Ø�Õ�âÞ�Ú�Ò�ÓÒFØ�ÕEÖ�×�Ó-Ú�Õ�Ø�á�Ú�ÓÕ�ÓæAæIâà>Õ�æLÖ�Ù�Ñ�Ø�Õ)Ö�æèû ÖqØ�æeÕ�à�ÖqÚ�Õ�Ú�æAÚ1Ñ�ÞµÖ�à.Ò�ÓæAâÙAØ�ÜOÓIÖ�×�Ó�éní�üýØ�Õ8Ö�×�ÓIäºà>ÙAÛjà�äoÑ¿æAÓá�Ú�ÓÕ)Ö�Ø~Ñ�Þ�âØ�ÙAâÚ�Ø0Ö5è�ïq×�ÓæLÖ�Ñ�Õ�Ò1Ñ�ÙAÒgØ�Õ)Ö�ÓÙAç�ÙAÓ=Ö�ÑZÖ�Ø�à>Õgà�ä�Ñ8âØ�ÙAâÚ�Ø0Ö_Ø�æfÖ�àbâà>Õ�æAØ�Ò�ÓÙ_ÜOà�Ö�×gÖ�×�Ó¿Þ~ÑZÖ�â�×�ÓælþUÖ�×�Ó.æLÖ�ÑZÖ�Ó×�à>Þ�Ò�Ø�Õ�ß�ÓÞ�ÓÛ�ÓÕ)Ö�æ�ÿSÑ�Õ�Ò�Ö�×�ÓfØ�Õ�ç�Ú%Ö�æ®Ñ�æqÉ=ÊaË�Ê����ZË��"Ì�Ë��Î���É_à�ä�Ö�×�Ó_éní�üxèfà!ÝeÓ=ð>ÓÙÔ�Ø0Ö�Ø�æä�Ñ�Ø�ÙAÞ0ã�âÞ�Ó5Ñ�Ù�Ö�×1ÑZÖ�Ö�×�ÓÙAÓSØ�æ�Õ�à�Õ�ÓÓÒ�Ö�à�Ø�Õ�âÞ�Ú�Ò�Ó�Ø�Õ�ç�Ú%Ö�æ§Ø�ÕIÖ�×�ÓnÚ�Õ�Ø�á�Ú�ÓÕ�ÓæAæDâà>Õ�æLÖ�Ù�Ñ�Ø�Õ)Ö�æèû äöÖ9Ýeà�æLÖ�ÑZÖ�ÓæSÑ�ÙAÓ®Óá�Ú1Ñ�Þ�Ó"ì%âÓç%ÖSäºà>ÙoÖ�×�Ó®Ø�Õ�ç�Ú%Ö�æÔ>Ý�×1ÑZÖ�Ó=ð>ÓÙnð�Ñ�Þ�Ú�ÓeÖ�×�Ó®Ø�Õ�ç�Ú%Ö�æSÑ�æAæAÚ�Û�ÓØ�Õ¿Ö�×�ÓqæAÓâà>Õ�Ò�æLÖ�ÑZÖ�Ó�Ô)Ö�×�Ó=ã.âà>Ú�Þ�ÒB×1Ñ5ð>ÓfÑ�æAæAÚ�Û�ÓÒ�Ø�Õ.Ö�×�Ó®ø1ÙAæLÖ5è û ÖnØ�æoÖ�×�ÓÙAÓ=äºà>ÙAÓ�æ�ÑZäºÓ®Ö�àÙAÓá�Ú�Ø�ÙAÓ®à>Õ�Þ0ã�Ö�×�Ó®Þ~ÑZÖ�â�×�åað�Ñ�ÙAØ~Ñ�Ü�Þ�ÓæDÒ�à�ÜOÓ®Ò�Ø0÷µÓÙAÓÕ)Ö�� Ñ_Û.Ú�â�×læLÖ�ÙAà>Õ�ß>ÓÙ�âà>Õ�Ò�Ø0Ö�Ø�à>Õ�è û Õä�Ñ�â=Ö5Ô>Ö�×�Ø�ænØ�ænà�äUÖ�ÓÕBÝ�×1ÑZÖ�Ø�ænØ�Û�ç�Þ�ÓÛ�ÓÕ)Ö�ÓÒ� �qí�����rè��fà�Ö�Ó®Ö�×1ÑZÖnä�Ñ�Ø�Þ�Ø�Õ�ß_Ö�à�ÙAÓÛ�à!ð>ÓqÖ�×�ÓæAÚ�çOÓÙLë1Ú�à>Ú�æSæLÖ�ÑZÖ�Óeð�Ñ�ÙAØ~Ñ�Ü�Þ�ÓæoäºÙAà>Û Ö�×�ÓqÚ�Õ�Ø�á�Ú�ÓÕ�ÓæAæSâà>Õ�æLÖ�Ù�Ñ�Ø�Õ)Ö�ænß>Ø0ð>ÓæSÑ�ÕBØ�Õ�Ó=÷µÓâ=Ö�Ø0ð>ÓØ�Õ�Ò�Ú�â=Ö�Ø�à>Õ�Ñ�Þ�ß>à>ÙAØ0Ö�×�ÛFÔ>Ñ�æSÓ5Ñ�â�×8Ó"ì�Ö�Ù�Ñ-æLÖ�ÑZÖ�Ó�ð�Ñ�ÙAØ~Ñ�Ü�Þ�Ó®×1Ñ�æSÖ�×�Ó�çOà�Ö�ÓÕ)Ö�Ø~Ñ�Þ1à�ä�Ò�à>Ú�Ü�Þ�Ø�Õ�ßÖ�×�Ó�Ò�Óç%Ö�×FÕ�ÓÓÒ�ÓÒFÖ�àlç�ÙAà!ð>Ó�Ö�×�Ó�æLÖ�Óç�è

û ä§à>Õ8Ö�×�Ó_à�Ö�×�ÓÙ�×1Ñ�Õ�Ò8Ö�×�ÓIéní�ü�Ø�æ�ß>Ø0ð>ÓÕbÑ�æ�Ö9Ýeà.ç�ÙAà>çOà>æAØ0Ö�Ø�à>Õ1Ñ�Þ�äºà>ÙAÛ.Ú�Þ~Ñ�æ���Ñ�Õ�Ò� Ø0Ö_Ø�æfÞ�ÓæAæ_âÞ�Ó5Ñ�Ù�Ý�×1ÑZÖfð�Ñ�ÙAØ~Ñ�Ü�Þ�Óæfâ5Ñ�ÕgÜOÓ-Ó"ì%âÞ�Ú�Ò�ÓÒ�è��óñuÓ¿ç�ÙAà>çOà>æAÓ-Ö�×�Ó-äºà>Þ�Þ�à!Ý�Ø�Õ�ßæAà>Þ�Ú%Ö�Ø�à>Õ��

� è û Õ�âÞ�Ú�Ò�Ó�à>Õ�Þ0ã�ð�Ñ�ÙAØ~Ñ�Ü�Þ�Óæ®à�ââÚ�ÙAÙAØ�Õ�ß�� �ZÊ"!EØ�ÕdÖ�×�Ó�âÚ�ÙAÙAÓÕ)ÖIÑ�Õ�ÒdÖ�×�Ó�Õ�Ó"ì�ÖfæLÖ�ÑZÖ�Óà�äDÖ�×�Ó�Ö�Ù�Ñ�Õ�æAØ0Ö�Ø�à>ÕdÙAÓÞ~ÑZÖ�Ø�à>Õ�è

# è%$Ià8Õ�à�Ö�Ñ�Ò�ÒgÚ�Õ�Ø�á�Ú�ÓÕ�ÓæAæ�âà>Õ�æLÖ�Ù�Ñ�Ø�Õ)Ö�æIØ�Õ�âÞ�Ú�Ò�Ø�Õ�ßlÖ�×�Ó¿ø1ÙAæLÖIà>ÙfÖ�×�Ó¿Þ~Ñ�æLÖIæLÖ�ÑZÖ�Óà�äDÖ�×�Ó�Ö�Ù�Ñ�âÓ�è

ñuÓ¿ÙAÓ=äºÓÙ_Ö�à8Ú�Õ�Ø�á�Ú�ÓÕ�ÓæAæ�âà>Õ�æLÖ�Ù�Ñ�Ø�Õ)Ö�æ_à!ð>ÓÙ_Ö�×�Ø�æ_ÙAÓÒ�Ú�âÓÒóæAÓ=Ö�à�äSæLÖ�ÑZÖ�Ó-ð�Ñ�ÙAØ~Ñ�Ü�Þ�Óæ_Ñ�æÉ=Ê&�'�Zô)(+*�ô1Ì&,-*.�=ô/��É�É=è

021 0 3 ��� �'��Í=Ê�ô/��É�ÉñuÓ-Ý�Ø�Þ�Þ§Õ�à!Ý ç�ÙAà!ð>Ó¿Ö�×1ÑZÖfÖ�ÓÛ�çOà>Ù�Ñ�Þ¦Ø�Õ�Ò�Ú�â=Ö�Ø�à>ÕFÝ�Ø0Ö�×*æLÖ�ÙAà>Õ�ßbÚ�Õ�Ø�á�Ú�ÓÕ�ÓæAæIØ�æfæAà>Ú�Õ�Ò�è4 Óâ5Ñ�Þ�Þ�Ö�×1ÑZÖSÖ�×�ÓfØ�Õ�Ò�Ú�â=Ö�Ø�à>Õ�å9æLÖ�Óç�â5Ñ�Õ8ÜOÓfæLÖ�ÙAÓÕ�ß�Ö�×�ÓÕ�ÓÒdÜ)ã�Ñ�Õ)ã�Ö�×�Ø�Õ�ß-Ö�×1ÑZÖ�×�à>Þ�Ò�æSäºà>ÙÑbæA×�à>ÙLÖ�ÓæLÖ¿âà>Ú�Õ)Ö�ÓÙ�å9Ó"ì�Ñ�Û�ç�Þ�Ó�è û Ö�Ö�×�ÓÕxæAÚ%ú�âÓæ�Ö�àEæA×�à!Ý Ö�×1ÑZÖ-Ñdâà>Ú�Õ)Ö�ÓÙ�å9Ó"ì�Ñ�Û�ç�Þ�ÓÖ�×1ÑZÖeØ�æeÕ�à�ÖeæLÖ�ÙAà>Õ�ß>Þ0ã�Ú�Õ�Ø�á�Ú�Ó_â5Ñ�Õ�Õ�à�Ö®ÜOÓ_æA×�à>ÙLÖ�ÓæLÖ5è65§Ó=Ö®Ú�æ®Ø�Õ)Ö�ÙAà�Ò�Ú�âÓfÖ�×�Ófäºà>Þ�Þ�à!Ý�Ø�Õ�ßÕ�à�Ö�ÑZÖ�Ø�à>Õ��

798�:<;>=?;�@&A<B CED FG�H =I@&J K<LMH KONQP9RTS�B ;�D FUC?;VKWB ;�H'XY;�@/ZYDYA%[\J C?:^]_A�@_CEC?:<J`@Va

� �

Page 17: BMC’03 - JKUfmv.jku.at/papers/bmc03-preliminary-proceedings.pdfBMC’03 Boulder, Colorado, USA. ... Alessandro Cimatti (IRST, Italy) Raanan Fraer (Intel, Israel) Danny Geist (IBM

bdce<fhg)fjilk/mn)o e<f)p�p n f

Ti−1

Ti

. . . . . .

Ti−1

. . .. . . . . .

Tj

sini−1

si−1reg

souti

sregj+1

soutj+1

sinjsin

i−1

si−1reg sreg

i

souti

sinj

sregj sreg

j+1

soutj+1

sregi

qsr tqut

v�wUx�y/z�yh{�|<}�~<�`���?�<�?}��&|<�Q�E���?|<}%���Y�-�?�I�Y���?� �Y��� ���?|<}����Y�<�-�?}V�&��}��<� �M~<� }����?�O�����%{�|<}%�_�I�Q�?}� � �?�`� �<� }������Y���_�?�I� � �<}��������?|<}>�?�I� ���&� �?� �Y���?}V�`�Q�?� �Y�����Q���?|<}�~��Y� �-�E� ���&�Y� �<� �<�- ^� �?}>~<�?� �-�?}��%� ���?|<}���'�¡}��V¢-�?|<}��?}V��� � �<� �<�^�?�I�Y��}>�`���?}V~<�?}��&}V�-�?}��%�����?|<}£�V¤V¤V¤  <�

¥�¦V§ ¨U©�ª «`¬ ­�®�¯'°)±&²O³_´\µ¶¥�¦ ¥�¦�· ¸ «`¬ ¥�¦V§ ¨U©�ª.¹%¥�¦Vº"· »I¼Vª¥�¦ º"· »I¼Vª «`¬ ­�®�¯'°)±&²O³�½.¾�´\µ¶¥�¦ ¥�¦V¿�À ª «`¬ ¥�¦ º"· »I¼Vª ¹%¥�¦ § ¨U©�ª

¥�¦ º�¨Á» «`¬ ¥�¦ § ¨U©�ª µ¶¥�¦ º"· »I¼VªÂ\ÃYÄ�Å Æ2ãÄ'ÇÈÃOÉ+Ê)ËÈÃ-Ì�Ê�Í>ÎÏÍ_Ê�Ð�ÉÒÑÈÌ�ÎdÃ-ÓÈÔ-Ê)ËÈÕ�ÓÈÖ+ÎhÔ-Ê�ÑÈÓ�Ä'Ã-Ð�×�à ØÈÎ�É+ÙÈÌ�ãÊ�Í�ËÈÃ-ÙÄ'Ç�Ú «

Å Û ¬ ÜYÝTÞß²�ÝTÞ߲ϾàÞâá�á�á¡Þß²Oã�½.¾àÞßädãåæàÃÏÓÈÊ¡çéè�ÇÈÊ¡çêÆ�ëìÔ-Ê�ÓÈèVÄ'Ð�ÑÈÔYÄ'Õ�Ê�ÓìÄ'Ç.Î�Ä£Õ�Í6Å Û ¬í±?¥�¦Vº�¨Á»Ò¬î¥�ï�º�¨Á»¡´ Í_Ê�ÐWè�Ê�É+Ãhð�ñóò�ñô ñõÚ ± Å Õ�èdÓÈÊ�ÄÏèVÄ'Ð�Ê�ÓÈÖ�Ì�ëâÑÈÓÈÕ�öjÑÈà ´ Ä'ÇÈÃ-Ó÷Ä'ÇÈÃ-Ð�ÃøÕ�èÒζè�ÇÈÊ�ÐVÄ'Ã-ÐÒÔ-Ê�ÑÈÓ�Ä'Ã-Ð�×�à ØÈÎ�É+ÙÈÌ�à åùWÃYú.ÓÈÃOÅüûýÊ¡þ�Ã-ÐOÿ ¥�����á�á�á�� ¥���� ï��/¦ ��� Î�è�Í_Ê�Ì�Ì�Ê¡ç�è «

Åüû ±?¥���´ ¬ Å ±?¥���´ ��� ñ òÅüû ±?¥���´ ¬ Å ±?¥����� ï��/¦ ��´ ����� òÅüû ±?¥�¦ · ¸ ´ ¬ Å ±?¥�ï · ¸ ´Å û ±?¥�¦ ¿�À ª?´ ¬ Å ±?¥�¦ ¿�À ªI´Åüû ±?¥�¦ º�¨Á» ´ ¬ Å ±?¥�¦ º�¨Á» ´

Åüû�ÓÈÊ¡çTÔ-Ê�ÓÈèVÄ'Õ�Ä'ÑÄ'Ã-è�Î%Ô-Ê�ÑÈÓ�Ä'Ã-Ð�×�à ØÈÎ�É+ÙÈÌ�Ã6Ê�ÍÈËÈÃ-ÙÄ'ÇÒÚ�� ± ô �Oò ´ å æàÃ6Ç.Î�þ�Ã^Ô-Ê�Ó�Ä'Ð'Î�ÔYÄ'Ã-ËÄ'ÇÈÃ�Ô-Ê�ÑÈÓ�Ä'Ã-Ð�×�à ØÈÎ�É+ÙÈÌ�Ã�Æ�ëOè�Õ�É+ÙÈÌ�ë�Ð�Ã-É+Ê¡þ)Õ�ÓÈÖ�Î�Ì�Ì�èVÄQÎ�Ä'Ã-è Æ2ÃYÄ�ç^Ã-Ã-ÓÒò2Î�ÓÈË ô ± ËÈÃ-ÙÈÕ�ÔYÄ'Ã-ËdÕ�Ó�������! ´ å#" ÇÈÃ6Ê�ÓÈÌ�ëWÙ2Ê�Ä'Ã-Ó�Ä'Õ�Î�Ì�ÙÈÐ�Ê�ÆÈÌ�Ã-É Ì�Õ�Ã-è�Õ�Ó£Ä'ÇÈÃ%$VÖ�Ì�ÑÈÕ�ÓÈÖ�&MÊ�ÍÄ'ÇÈÃ�ÇÈÃ�Î�ËdÎ�ÓÈË£Ä'ÇÈÃ�ÄQÎ�Õ�ÌÎ�Ä%èVÄQÎ�Ä'Ã�ò å(' Ê¡ç^ÃYþ�Ã-Ð�)2Ä'ÇÈÃ�Ê�ÓÈÌ�ëlÔ-Ê�ÓÈèVÄ'Ð'Î�Õ�Ó�Ä'è%Ô-Ê�Ó�ÄQÎ�Õ�ÓÈÕ�ÓÈÖ ¥�¦ Î�Ð�à ²O³�½.¾ Î�ÓÈË ²O³Iå(* ÑIJO³�½.¾ ËÈÊ)Ã-è�ÓÈÊ�Ä�Ô-Ê�Ó�ÄQÎ�Õ�Ó�Î�Ó�ëøþ�Î�Ð�Õ�Î�ÆÈÌ�Ã-è^Í_Ð�Ê�É ¥�¦ · ¸ )Èè�Ê+Ì�ÃYÄ�Ä'Õ�ÓÈÖÒÅ ±?¥�¦ · ¸ ´,+¬ Åüû ±?¥�¦ · ¸ ´Ô�Î�ÓÈÓÈÊ�ÄOÉ9Î.-�à ²O³�½.¾ Í&Î�Ì�è�ÃÏÕ�ÓìÅüû å0/ Õ�É+Õ�Ì�Î�Ð�Ì�ëøÍ_Ê�Ð ²O³ ç�ÇÈÕ�ÔQÇâËÈÊ)Ã-è£ÓÈÊ�ÄOÔ-Ê�Ó�ÄQÎ�Õ�ÓâÎ�Ó�ëþ�Î�Ð�Õ�Î�ÆÈÌ�Ã-è%Í_Ð�Ê�É ¥�¦�¿�À ª å21 Õ�Ó.Î�Ì�Ì�ë Å ±?¥�¦ º�¨Á» ´�¬ Å ±?¥�ï º�¨Á» ´ )\è�Ê�Õ�ÓÈËÈÃ-Ã-Ë ÅüûEÉÒÑÈèVÄOÆ2ÃhÎÉ+Ê)ËÈÃ-Ì/Í_Ê�ÐMÄ'ÇÈÃOÔ-Ê�ÓÈèVÄ'Ð'Î�Õ�Ó�Ä'è ²O³�½.¾ Î�ÓÈË ²O³Iå 3

" ÇÈÃhÙÈÐ�Ê)Ê�Í^Ô�Î�ÓâÃ�Î�è�Õ�Ì�ëìÆ2Ãhà Ø)Ä'Ã-ÓÈËÈÃ-ËâÄ'Ê�Ã-èVÄQÎ�ÆÈÌ�Õ�è�ÇìÄ'Ç.Î�ÄOÄ'ÇÈÃhà ØÔ-Ì�ÑÈè�Õ�Ê�ÓâÊ�Í6Ä'ÇÈÃhú.Ð�èVÄÎ�ÓÈËlÄ'ÇÈÃOÌ�Î�èVÄ�èVÄQÎ�Ä'ÃOÕ�èMè�ÑÈÙ2Ã-Ð54.ÑÈÊ�ÑÈè%Õ�Í�Î�Ì�Ì/þ�Î�Ð�Õ�Î�ÆÈÌ�Ã-è^Ê�Í Ü Ê)Ô-Ô-ÑÈÐ�Õ�ÓøÄ'ÇÈÃOÓÈà Ø)Ä%èVÄQÎ�Ä'ÃOÊ�Ͳ Î�ÓÈË�Î�Ì�Ì2þ�Î�Ð�Õ�Î�ÆÈÌ�Ã-è�Ê�Í ä Ê)Ô-Ô-ÑÈÐ�Õ�ÓlÄ'ÇÈÃOÔ-ÑÈÐ�Ð�Ã-Ó�Ä%èVÄQÎ�Ä'ÃOÊ�Í ² å

6�6

Page 18: BMC’03 - JKUfmv.jku.at/papers/bmc03-preliminary-proceedings.pdfBMC’03 Boulder, Colorado, USA. ... Alessandro Cimatti (IRST, Italy) Raanan Fraer (Intel, Israel) Danny Geist (IBM

7%89;:0<�:�=�>@?A�B 9;:�C�C A :D EGFIH%J!K�L5MNJ#OQPSRUTWVXJ!YSZ,T[PSY\^]S_a`cbS_�d.eWfSg�_�e�_�h�ij_�bX`chkij]S`celfmd.fn_�gloQ_�g�_p`cqlfSrc_�ql_�h�ij_�bk`chkij]S_afSg�s.ijs.iut�fn_vijs�s�rwQx y�z o{]S`c|}]~o(d.el`ch�ij_���gjd�ij_�b�o{`�ij]�ij]S_a����\Q�ue�s�r���_�g������������{����rcr(�n_�hS|}]SqWd.g���eoQ_�g�_�fn_�g5� s�g�ql_�b�s�h�dk�~�������#_�h�ij`c�Sq ��o{`�ij]¢¡�£;��¤a¥¦s.�§ql_�qls�g5t¨g��ShShS`chS�©�`ch���ª@�§«¬_2e�_­i�ij]S_�ij`cql_®�us���i�� s�g�d.rcr#r¯d.�ShS|}]S_�e,ijs�£�°±ql`ch���ij_�e�²!d.hSb³ij]S_2ql_�qls�g5trc`cql`�iUijs2��°�°0¤a¥��S\^]S_��n_�hS|}]SqWd.g���e(oQ_�g�_�|�s�rcrc_�|­ij_�b±� g�s�q´e�_­��_�gjd.r�e�s��Sg�|�_�e���µuh�ij]S_i}d.�Src_�e�²S_�d.|}]a�n_�hS|}]SqWd.g��±hmd.ql_,`ce(i}d.����_�b�o{`�ij]Gij]S_�e�s��Sg�|�_�s.�#ij]S_�fSg�s��Src_�qv¶

·j¸�¹�º­»@·}º½¼¿¾ ªSd.qlfSrc_,Àmrc_�e(� g�s�qÁij]S_IÂ^�IÃUÄ�Å%Æ!Ä2��ÇÉÈÊbS`ce5ijg�`c�S��ij`cs�hË�·­Ì2Í ¼¿¾ ªSd.qlfSrc_,Àmrc_�e(� g�s�qÁij]S_IÂ,ÇÉÎÏ��ÇÉÈÊbS`ce5ijg�`c�S��ij`cs�hË�Ð º­» ¼ �S¤GÑÒ|�d.e�_�e5ij�SbS`c_�e^� g�s�qÔÓ,_�hp¤v|�¤v`crcr¯d.hËÕ eQoQ_����ufmd.��_.�»mÍ�Ö­Ì2× ¼¿¾ ªSd.qlfSrc_,Àmrc_�e(� g�s�qÁij]S_IØlÙ{��ÇÉȦbS`ce5ijg�`c�S��ij`cs�hË�×�ÚcÖ ¼¿¾ ªSd.qlfSrc_,Àmrc_�e(� g�s�qÁij]S_IÈ�Û��ÜbS`ce5ijg�`c�S��ij`cs�hË�Ý º�Þ�¸;Ö ¼ \^]S_�ß º�Þ�¸;Ö§àSá0⮺­»@·}ã�Ìl¸.ä Ð Ö � g�s�qÊ¥Q_�g��._�rc_­två�hS`���_�g�e�`�iut��º­Ú æ Ð ¼ µ5�SçQ�,�nÕ è�éle�_�ê��S_�h�ij`¯d.r!_�ê��S`��.d.rc_�hS|�_,|}]S_�|}��`chS�l� g�s�qìë ¾ ` í���é�è;îï�ÚðäjÖ Ý ¼ ��g�s��Src_�qle(� g�s�q´ij]S_%¤vs�bS_�r#çQ]S_�|}��`chS���,g�s��Sfvd�i{µòñ���\,�

��rcr@fSg�s��Src_�qle(oQ_�g�_�|�s�h���_�g5ij_�bvijs2ó�d�i(��ÇÉÈ��[� s�g�qWd�i�o{`�ij]Gs�hSr�t±�ns�s�rc_�d.hW�.d.g�`¯d.�Src_�ed.hSbvhSsle��S���uqls�bS�Src_�e���ôms�g^_�d.|}]afSg�s��Src_�qv²�ij]S_�ejd�� _­iutvfSg�s�fn_�g5ij`c_�e(oQ_�g�_%_®ª�ijgjd.|­ij_�bË�µuhõij]S`ce�fSg�s�|�_�e�e�²�çQ\{©¨� s�g�q��Sr¯d.evö ¾ ô�÷GoQ_�g�_W|}]md.hS��_�bÜ`ch�ijsÉö5���§ø÷pd.hSbÜd.rcr��ùd.`cgò�hS_�e�e�|�s�hSe5ijgjd.`ch�ije,oQ_�g�_0g�_�qls���_�bË�0úI`�û@_�g�_�h�i�fSg�s�fn_�g5ij`c_�eI� s�gIij]S_2ejd.ql_2e5t�e5ij_�qìd.g�_`chSbS`c|�d�ij_�b���tvd2e��S�Se�|�g�`cf�i�d��ðij_�g^ij]S_�e5t�e5ij_�qÔhmd.ql_.�

çQs��Sh�ij`chS�l_�d.|}]afSg�s�fn_�g5iutvd.e�d0e�_�fmd.gjd�ij_§`chSe5i}d.hS|�_.²nd2ijs.i}d.rËs.�(£�è�¡�fSg�s��Src_�qÊ`ch��e5i}d.hS|�_�eQoQ_�g�_I|�s�rcrc_�|­ij_�bË���eQs��SgUÀmg�e5i^_®ª�fn_�g�`cql_�h�i�²�oQ_Igjd.h wQx y ²�Â^�IÃUÄ�Å%Æ!Ä���ÇÉÈW²Â,ÇÉÎü��ÇÉÈW²Sd.hSb2ØlÙ{��ÇÉÈÏs�hl_�d.|}]ls.�nij]S_�e�_�`chSe5i}d.hS|�_�e�����rcr�ijs�s�rce�oQ_�g�_�g��Sh0o{`�ij]d2bS_­�ùd.�Sr�i{e�_­i�s.��s�f�ij`cs�hSe�²SfSg�s���`cbS`chS�0hSs0fSg�s��Src_�qÊe�fn_�|�`�Àm|,�.d.g�`¯d.�Src_Is�g�bS_�g�`chS�S¶

ýnþ�ÿ ��� º­»n¸.ÌWº��������� ��� º­»n¸.ÌWº�� ��������������������� ��� º­»n¸.ÌWº� ������ ���������������� þ�� � � � þ ��� º­»n¸.ÌWº

µuhSe5i}d.hS|�_�e�e�s�r���_�bG`chGrc_�e�e(ij]md.h�£�e�_�|�s�hSbv��tGd.rcrnijs�s�rceQoQ_�g�_§|�s�hSe�`cbS_�g�_�bGijg�`���`¯[email protected]�_�qls���_�b˲mrc_�d���`chS�G£;¡.è2`chSe5i}d.hS|�_�e��

!�"$# %'& Ì)(S¸.ä®ÚcÖ & »+*�Ú Ý ã-,/. .10 Ý &2& � Ö\^]S_±g�_�e��Sr�i�s.�^ij]S_±|�s�qlfmd.gjd�ij`���_W_®ª�fn_�g�`cql_�h�i�`ce%fSg�_�e�_�h�ij_�bk`ch436587�9;:=<.�p\^]S_±bS_®��ùd.�Sr�i,e5ijgjd�ij_��.t³s.� wQx y g��ShSe,ij]S_0�md.e�_®�u|�d.e�_Wd.hSb³ij]S_0`chSbS�S|­ij`cs�h��ue5ij_�f�fSg�_�e�_�h�ij_�bÜ`ch> � ? & ä®Ú Ý ã�ÌA@ d.hSbCB¨`chÜfmd.gjd.rcrc_�rï²�_�d.|}]�o{`�ij]�`�ije�s�o{h~e�s�r���_�g2`chSe5i}d.hS|�_.�õ\^]S_�iuoQsd.rc��s�g�`�ij]SqleQd.g�_,��`���_�hG_�ê��md.r!d.qls��Sh�i^s.��ç(�Uå ij`cql_.²��Sh�ij`crnij]S_�fns�`ch�i(o{]S_�g�_�_�`�ij]S_�gij]S_l�md.e�_®�u|�d.e�_l�ùd.`crce�²!d.hSbÜdG|�s��Sh�ij_�gò�u_®ªSd.qlfSrc_l`ce�� s��ShSb˲#s�g,ij]S_l`chSbS�S|­ij`cs�h��ue5ij_�f¬`ceDFEHG�I/JLKMKONQP�RTSUJLG�IWV2X�EQY$Z[KON \OI^]'_O`�a2b�c6cedgf�hidgN N6j�I^f�klG�mndg]Lo2Zqp�Z[Irhts ftJLG�suZ'dg][JLsukvN Ink^dgfij�Ih2Kxwyf�N KzdOh2Irhn{T]LKOm}|M~�~ ��� �O�������������^���l|��x� �n�v�l�^� �^�$���/�l�v�g�

£;�

Page 19: BMC’03 - JKUfmv.jku.at/papers/bmc03-preliminary-proceedings.pdfBMC’03 Boulder, Colorado, USA. ... Alessandro Cimatti (IRST, Italy) Raanan Fraer (Intel, Israel) Danny Geist (IBM

�t����������-�Q���� �����r� � �

�8�r�2 �¡z¢H£�¤�¢8¥-¦¨§8¡1�r¡z©ª¤�«�¢8«�¢8¬®­�¤�¯r¡g°�±M¤�¯r¡z¯i²;«´³µ¤�¢�¶8·n¤��r¡1�8�r�2 �¡z¥¹¸º«´¦¨§¼»2½�½�¾À¿/Á�ÂÄÃÅ §8¡ �8Æ8�r����¯r¡ ��³H¦¨§8¡ ¡gÇ��¡z�r«�©È¡z¢�¦É¸/¤�¯É¦¨�i�r¡zÊˤ�¦¨¡º¦¨§8¡ ��¡z�^³;���r©ª¤�¢8±z¡)��³y«�¢8¥8Æ8±O¦¨«���¢

¦¨�1«�¢8¥8Æ8¯^¦¨�r«Ë¤�Ê�Ê´¶Ä¤��8�8Ê�«�¡z¥�©È¡O¦¨§8��¥8¯z£�¤�¢8¥®¦¨�1¯r§8�2¸}¦¨§8¡t²;Êˤ�±xÌt��³x·µ±z���r�r¡zÊˤ�¦¨«���¢i­�¡O¦�¸É¡z¡z¢§�¤��r¥8¢8¡z¯r¯/³;���/Í/ÎÏÎW°�­�¤�¯r¡z¥-©È¡O¦¨§8��¥8¯n¤�¢8¥-§�¤��r¥8¢8¡z¯r¯/³;���/«�¢8¥8Æ8±O¦¨«���¢�°�­�¤�¯r¡z¥Ð©È¡O¦¨§8��¥8¯zÃÑÉÒ;Ó ¸/¤�¯q¤�­8Ê�¡�¦¨� ¯r��Ê´ �¡/ÔW«�¢8¯^¦x¤�¢8±z¡z¯µ¸º§8¡z�r¡nÍ/ÎÏÎW°�­�¤�¯r¡z¥Ä �¡z�r«´Õ�±M¤�¦¨«���¢Ä³[¤�«�Ê�¡z¥H£�¯r§8�2¸º«�¢8¬¦¨§�¤�¦º«�¢8¥8Æ8±O¦¨«���¢-©ª¤M¶-­�¡Ä¤i �¤�Ê�Æ�¤�­8Ê�¡ ±z��©È�8Ê�¡z©È¡z¢�¦x¤��^¶Ð©È¡O¦¨§8��¥HèÖ

×�Ø�ÙÛÚ�Ü ÝxÞOßnàváÏâ$ãQÞOä¨ÝOåªÝOã�ßlæ�ç�â$ß[èÅ §8¡)¯r¡z±z��¢8¥=¡gÇ��¡z�r«�©È¡z¢�¦É¸É¡ ��¡z�^³;���r©È¡z¥È¸/¤�¯n¤Ä±z��©È��¤��r«�¯r��¢ª��³êé ç ë�à�ägâ$ß$ì�åíÙ ¤�¢8¥ïîÆ8¯r«�¢8¬t¦¨§8¡ «�¢8±z�r¡z©È¡z¢�¦x¤�ÊQ«�¢�¦¨¡z�^³[¤�±z¡ ��³�ð�ñyòóqô'ôõ¤�¢8¥-Æ8¯r«�¢8¬ið�ñyòóqô'ôõ¤�¯n¤�¢-¡gÇ�¦¨¡z�r¢�¤�ʯr��Ê´ �¡z�zõö�¢®¦¨§8«�¯µ¡gÇ��¡z�r«�©È¡z¢�¦M£�¸É¡nÆ8¯r¡z¥���¢8Ê´¶Ä�8�r��­8Ê�¡z©÷«�¢8¯^¦x¤�¢8±z¡z¯ø¸º§8¡z�r¡/¦¨§8¡/�8�r����¡z�^¦�¶§8¡zÊ�¥Hà Š§8¡1�r¡z¯rÆ8Ê´¦W«�¯n�8�r¡z¯r¡z¢�¦¨¡z¥ù«�¢eú6û8ü�ý;þ ÿ�ÃÅ §8¡ ¡gÇ��¡z�r«�©È¡z¢�¦ ¡z¯^¦x¤�­8Ê�«�¯r§8¡z¯ ¤C¯rÆ8­8¯^¦x¤�¢�¦¨«Ë¤�Ê®¯r��¡z¡z¥�°�Æ8� ­�¶ ¦¨§8¡ «�¢8±z�r¡z©È¡z¢�¦x¤�Ê

¤��8�8�r��¤�±x§HÃFÂW¢8¯rÆ8�r�8�r«�¯r«�¢8¬�Ê´¶�£)¦¨§8¡ ¬�¤�«�¢ ¸/¤�¯+Êˤ��r¬�¡z�-³;���¹«�¢8¯^¦x¤�¢8±z¡z¯=¸º§8¡z�r¡ ¤ Ê���¢8¬«�¢8¥8Æ8±O¦¨«���¢�°�¯^¦¨¡z�-¸/¤�¯º¢8¡z¡z¥8¡z¥¹¦¨�È�8�r�2 �¡Ï¦¨§8¡1�8�r����¡z�^¦�¶�Ã

� �r��© ¦¨§8¡n¦x¤�­8Ê�¡É¸É¡W±M¤�¢È¤�Ê�¯r�ϯr¡z¡n¦¨§�¤�¦q¦¨§8¡º«�¢8¥8Æ8±O¦¨«���¢�°�¯^¦¨¡z�®Æ8¯rÆ�¤�Ê�Ê´¶t¦x¤�Ì�¡z¯�Ê���¢8¬�¡z�¦¨�¼�8�r�2 �¡=¦¨§�¤�¢ ¦¨§8¡=­�¤�¯r¡g°�±M¤�¯r¡�Ã�� ¡=��­8¯r¡z�^ �¡z¥ ¦¨§8¡=¯¨¤�©È¡=­�¡z§�¤M �«����i³;���®«�¢8¯^¦x¤�¢8±z¡z¯¸º§8¡z�r¡�¦¨§8¡È�8�r����¡z�^¦�¶ï³[¤�«�Ê�¡z¥ ²[¤�Ê´¦¨§8��Æ8¬�§ ¢8��¦Ä�8�r¡z¯r¡z¢�¦¨¡z¥e§8¡z�r¡2·gà Š§8«�¯1«�¯Ï¦¨§8¡È�r¡M¤�¯r��¢¦¨§8¡Ï¥8¡O³[¤�Æ8Ê´¦/¯^¦¨�¨¤�¦¨¡z¬�¶-��³ ÑÉÒ;Ó ¥8��¡z¯n¢8��¦º«�¢8±z�r¡M¤�¯r¡ ¦¨§8¡ÏÊ�¡z¢8¬�¦¨§8¯/��³ ¦¨§8¡Ï¯^¦¨¡z�+¤�¢8¥-­�¤�¯r¡¡O �¡z¢8Ê´¶�£�­8Ʀq«�¢8¯^¦¨¡M¤�¥i¥8¡O ���¦¨¡z¯q¦¨§8¡/¯¨¤�©È¡/¤�©È��Æ8¢�¦ø��³Q¿/Á� ¦¨� ¡M¤�±x§HÃ��)¦¨§8¡z�^¸º«�¯r¡�£�­8Æ8¬�¯©ª¤M¶Ð¢8��¦º­�¡Ï³;��Æ8¢8¥¹¥8Æ8¡Ï¦¨��§�¤��r¥e²[¤�¢8¥=³;Ʀ¨«�Ê�¡2·�«�¢8¥8Æ8±O¦¨«���¢�°�¯^¦¨¡z�8¯zÃ

×�Ø î � ãQÝ��2à�ç�ÝOäÏâ$ã��Oßlæ�ãQÞxÝià�ä1ß �ÉàÅ §8¡ï¦¨§8«��r¥ ¡gÇ��¡z�r«�©È¡z¢�¦=±z��©È��¤��r¡z¥õé ç ë�à�ägâ$ß$ì�å�� ²����Q«�¬�°��H¤�¬���·®Æ8¯r«�¢8¬ ��¢8¡¼¯r��Ê´ �¡z�«�¢8¯^¦x¤�¢8±z¡Ð¦¨�ï�rÆ8¢8¢8«�¢8¬ï¦¨§8¡-«�¢8¥8Æ8±O¦¨«���¢�°�¯^¦¨¡z� ¤�¢8¥ ¦¨§8¡-­�¤�¯r¡g°�±M¤�¯r¡=«�¢ ¯r¡z��¤��¨¤�¦¨¡=¯r��Ê´ �¡z�«�¢8¯^¦x¤�¢8±z¡z¯zà ²��rÎ Æ�¤�Ê���·gÃ+ö�¢e¦¨§8«�¯i¡gÇ��¡z�r«�©È¡z¢�¦M£ø¦¨§8¡Ð¯^¦¨¡z� ¤�¢8¥e¦¨§8¡Ð­�¤�¯r¡Ð¸É¡z�r¡-«�¢8±z�r¡g°©È¡z¢�¦¨¡z¥Ð¡O �¡z¢8Ê´¶ª¯r�i¦¨§�¤�¦É­���¦¨§Ð©È¡O¦¨§8��¥8¯'¸É��Æ8Ê�¥Ð¯r��Ê´ �¡)��¢8Ê´¶�¦¨§8¡)©È«�¢8«�©ª¤�Ê8¢�Æ8©i­�¡z�/��³��� Å °�«�¢8¯^¦x¤�¢8±z¡z¯zÃ�� ¡Ð¤�Ê�¯r�+«�¢8±zÊ�Æ8¥8¡�¦¨§8¡ª¯^¦x¤�¢8¥�¤��r¥e«�©È�8Ê�¡z©È¡z¢�¦x¤�¦¨«���¢¼��³Ä²;±z��©È�8Ê�¡O¦¨¡2·«�¢8¥8Æ8±O¦¨«���¢=¤�¯º�8�r¡z¯r¡z¢�¦¨¡z¥ù«�¢�� ����� ½�½ �Là Š§8¡Ä�r¡z¯rÆ8Ê´¦¨¯W¤��r¡1¤�Ê�¯r��«�¢eú6û8ü�ý;þ ÿ�ÃÅ §8¡ª¡gÇ��¡z�r«�©È¡z¢�¦i¯rÆ8¬�¬�¡z¯^¦¨¯t¦¨§�¤�¦t¯r¡z��¤��¨¤�¦¨¡Ð¯r��Ê´ �¡z�t«�¢8¯^¦x¤�¢8±z¡z¯Ä³;���1¦¨§8¡ª­�¤�¯r¡Ð¤�¢8¥

¦¨§8¡)¯^¦¨¡z�-«�¯'³[¤M ����¨¤�­8Ê�¡�à � �r��© ¦¨§8¡W¦x¤�­8Ê�¡W¸É¡ ±M¤�¢-¤�Ê�¯r�i¯r¡z¡)¦¨§�¤�¦É¦¨§8¡)«�¢8±z�r¡z©È¡z¢�¦x¤�Ê�«�©®°�8Ê�¡z©È¡z¢�¦x¤�¦¨«���¢-��³µ«�¢8¥8Æ8±O¦¨«���¢-±zÊ�¡M¤��rÊ´¶Ð��Ʀ¨��¡z�^³;���r©È¯/¦¨§8¡1¯^¦x¤�¢8¥�¤��r¥¹«�©È�8Ê�¡z©È¡z¢�¦x¤�¦¨«���¢HÃ

×�Ø � !#"%$&$'à�å('8æ�ägâ��2à�ãö�¢Ï¦¨§8¡q³;��Æ8�^¦¨§1¡gÇ��¡z�r«�©È¡z¢�¦M£2¸É¡�±z��©È��¤��r¡z¥1«�¢8±z�r¡z©È¡z¢�¦x¤�Ê�¯r¡M¤��r±x§Ä³;���H±z��Æ8¢�¦¨¡z�v°�¡gÇ8¤�©È�8Ê�¡¦¨�Ц¨§8¡)�^��¢8¡g°�¯r§8��¦��=¤��8�8�r��¤�±x§¼¥8¡z¯r±z�r«�­�¡z¥¼«�¢ï¯r¡z±O¦¨«���¢+*8ô»�à Š§8¡®�r¡z¯rÆ8Ê´¦1«�¯ �8�r¡z¯r¡z¢�¦¨¡z¥«�¢¼ú6û8ü�ý;þ(,�à Š§8¡ ¡gÇ��¡z�r«�©È¡z¢�¦/¯r§8�2¸º¯/¦¨§�¤�¦/��³$¦¨¡z¢ª¶���Æ-©iÆ8¯^¦/Ì�¢8�2¸C¦¨§8¡ ¡gÇ8¤�±O¦nÊ�¡z¢8¬�¦¨§��³ø¤®¯r§8���^¦¨¡z¯^¦)±z��Æ8¢�¦¨¡z�v°�¡gÇ8¤�©È�8Ê�¡ ³;���/¦¨§8¡1��¢8¡g°�¯r§8��¦W©È¡O¦¨§8��¥-¦¨��­�¡Ä¤�¥ �¤�¢�¦x¤�¬�¡z��Æ8¯zÃ

-/.103254 27638:9<;3= 2�>?4A@B2�8:2DCE= =BF:.HGBI7JLK KNMO638:9<;3= 2�>?4QPR8:9<>TS:032BUWVHXZY\[^]`_a4NS:8:_ ;3b`S:_ 9<ced`9<8:_ f<_ c CE= = gb 4 25]h_ ciF:jW9`]`2�=�GA0325kmln_ c3f?o�CE8:f<2pJn9EPSN@1CE8:2pJn6q25kr_ sqk�CZS:_ 9<c 4:M�t GBIHu1v<w�xzy

»`{

Page 20: BMC’03 - JKUfmv.jku.at/papers/bmc03-preliminary-proceedings.pdfBMC’03 Boulder, Colorado, USA. ... Alessandro Cimatti (IRST, Italy) Raanan Fraer (Intel, Israel) Danny Geist (IBM

|~}�3�����e���B���� �3���5� � �

���n�<� �n�<� �<�5����� �<�3�p� �� �E�1���E����� �<� �n� �3��A Q¡£¢`¤1¥e¢h¦Z§\¨ �5©3� �ª�«R¬ ­�® ¯�£§\°²± ¦Z§\¨ ­<³ ³´Wµ ¦Z§\¨ ¶ © ³

·B¸n¹�º»+¼n½¿¾�ÀEÀnÁ(Â�ÀnÃOÄÆÅnÇ5ÈÊÉZÀnË�Ì/·�Íƻκ»ZÏ�ÐÒÑ�Ó3ºRÔeÕ×Ö%ØrÍÆÓ<ÙOØÒÐrÍÆ»�ÐÚÓ`Ðr¸`ºhÖqÔeÕh¹�»ZÛÒÓ`Ï�ØÚÓ3ºÜ`»EÝÞ ÖeØÚÐr¸`ÖeÑ�»EØOÙ Þ ÐrÍ Þ ÖμZßàÕ Þ ÖqÔÆÐÚ»EØZ½á·�ÍÆ»hÛ Þâ Í Ð#Ñ�Ó3ºRÔeÕ×ÖãØrÍÆÓ<Ù�ÍÆÓ<Ù�Õ׸`Ö ä�Ó`Ï�ÐrÍÆ»EØÚ» Þ ÖeØÚÐr¸`ÖeÑ�»EØÖÆÓãÓ`ÐrÍÆ»ZÛ(ÐÚÓqÓ3ºHÑ�Ó3ÔeºRÝ�ØÚÓ3ºÜ`»`½�å7æ�çéèqêDëQèÎì�íïîð»�ñÆÑ�»EºRº»EÝιqä�òeÛrÓ<Ü Þ Ö â\ó`óãÞ ÖeØÚÐr¸`ÖeÑ�»EØLÐrÍe¸nÐÖÆ» Þ ÐrÍÆ»ZÛOÓ`Ï�ÐrÍÆ»(Ð Ù7ÓàÓ`ÐrÍÆ»ZÛhôÆõ�ö#ØáÑ�Ó3ÔeºRÝãòeÛrÓ<Ü`»`÷£¸`ÖeÝiø`ù~ÕWÓ`Ûr» Þ ÖeØÚÐr¸`ÖeÑ�»EØáÐrÍe¸`Öãú£ûzüB½LôqÐ Þ ºRºÓ3Öeºä�ý Þ ÖeØÚÐr¸`ÖeÑ�»EØOÙ7»ZÛr»(ÔeÖ ÞRþ ÔÆ»`÷�¸`Øáú£ûzü�ØÚÓ3ºÜ`»EÝ\Õ׸`Ö äÒÓ`Ï�ÐrÍÆ»hòeÛrÓ`¹�º»EÕ×Ø�ÙOÍÆ»ZÛr»Lÿ���ì�íïî¸`ÖeÝÒåáí����mì�íïî&Ïz¸ Þ º»EÝ£÷�ò�ºRÔeØ���ÐrÍe¸nÐ�å7æ�çéèqêDëQèÒì�íïî Ý Þ ÝàÖÆÓ`ÐOØÚÓ3ºÜ`»`½

���#� �e��� �� :����� ���ï�� :��������� ���<� ��� �������<� ������� !��E�#"q� �$"%�E� �� m�$& � �')(+*-, �q��.:� �`�`�0/ ­ ¶ ¶ ³21 ¶43 5769898;: �5³21 ¶ ��< ��1 � �<³21 ­ 3 5769898;:=3 5769898;:>)? @;A%, �3®E³<��/ ®<�E­ <�<��21 ³ 3 5769898;: 3 5769898;:B3 5769898;: 3 5769898;:C3 5769898;:=3 5769898;:>)? @;A%, �3®E³<�E� ®<�E� <��<©21 ® 3 5769898;: 3 5769898;:B3 5769898;: 3 5769898;: �E¯�<�1 ® 3 5769898;:>)? @;A%, �3®E³<� ®<�E­ <�©<¯21 ¶43 5769898;: 3 5769898;:B3 5769898;: 3 5769898;: �E³<©21 ¶D3 5769898;:>)? @;A%, �3®E­<� �E­ ® ¶ 1 ¶43 5769898;: ©�<�1 ­ ­<¯21 ® ¯�®$1 ­ ©3�5¯21 � 3 5769898;:>)? @;A%, �3�`�5³ �<� �$1 ® �21 ³ ³21 � ³21 ­ �$1 ­ ¶ 1 < �5³21 �>)? @;A%, �`��®E³ ��® ¯21 � ®<®$1 ­ ¯21 < ��®$1 � ��®$1 ¯ ®E³21 ® ©<³21 �>)? @;A%, �`�<©�® ��® ¶ 1 ¯ ®E�21 ® �$1 � ��®$1 ­ �5©21 < ®<�$1 � ©��$1 ®>)? @;A%, �`­��E© � ��1 ¶ <�1 ® ³21 � ³21 ® ��1 ­ <�1 ® <�1 <A�>)EF, �n���%G ©<³ ©<­21 < 3 5769898;: ³21 © ¶ 1 < ©<­21 ­ <�­�®$1 ³ ®<�H<�1 ³E�*JI9(+K�, ��!3�a�2�E��/r�HG �<� ®$1 � �5³21 ® ³21 � ©21 < ©21 � ©21 ­ �<��1 �E�*JI9(+K�, ��!3�a�2�E��/r��L ®E� ��®E³21 © 3 5769898;: ©3���$1 ³ 3 5769898;: <�©<�21 ­ 3 5769898;:=3 5769898;:E�*JI9(+K�, M/��<�;N ¶ ��1 © ©21 � ³21 ® ³21 © ��1 � ��1 ­ <�1 ©E�*JI9(+K�, M/��<�;O ¯ ��1 © ©21 © ³21 ³ ³21 � ��1 © ��1 � ©21 ®P >;QJR�I�, ����.m� �5�TS`�;N < ��®$1 ® �5©21 � ³21 ® ³21 ® ��<�1 ¶ ��®$1 � ¶ 1 �K�?0I�, �2.:�`�2/r��� �UGVN ©<³ ®<�E¯21 ¯ 3 5769898;: �<��®$1 � <�<n�$1 � ©<¯ ¶ 1 © 3 5769898;:=3 5769898;:K�?0I�, �2.:�`�2/r��� �UGVO ­ <�1 ¯ ��®$1 < ³21 � ³21 ¯ <�1 � ©21 ¶ ��<�1 ¶K�?0I�, �2.:�`�2/r��� �UG�W � ¶ ©3��1 © �5���$1 � ¶ 1 © ��<�1 ® ©<�21 ¶ �<®$1 © ®`�5­21 ­K�?0I�, �2.:�`�2/r��� �UGVX ®H< �5³<­21 © 3 5769898;: ®E©21 ³ �<³21 � �5©�®$1 < ®`�5¯21 ¶D3 5769898;:K�?0I�, �2.:�`�2/r��� �UGVY ¯ ®$1 � <�1 � ³21 ³ ³21 � ®$1 � ��1 ® <�1 ¶K�?0I�, �2.:�`�2/r��� �UGVL ®E� ®`�<��1 © 3 5769898;: �<®$1 < ® ¶<¶ 1 � ®E¯��$1 ³ 3 5769898;:=3 5769898;:K�?0I�, �2.:�`�2/r��� �UGVZ ��< ®`��1 < �<� ¶ 1 ­ ³21 < ©21 ® ®`��1 � ®E�21 ¯ ��®E�21 ­K�?0I�, �2.:�`�2/r��� �UGV[ ®E© ¯3��1 ¯ <n� ¶ 1 ³ ®E©21 < �<¯21 ³ ���$1 ³ � ¶ �21 � 3 5769898;:K�?0I�, �2.:�`�2/r��� �0NTW ©<� ©<­3��1 ­ 3 5769898;: 3 5769898;:B3 5769898;: 3 5769898;:C3 5769898;:=3 5769898;:

·B¸n¹�º» ó ½�\^]5Ä-_�Ç5È�Ã`_�ËbaNÅnÁ�Ç)_5É�c�Á0a�É�dZÀnÇ�afeg_h_jik_rÂ�aOÀMd�È�Ë�ÂZÇ)_�Ã`_�ËbaNÅnÁ7l%mL¾onEÉZÌ�_)]2aT_�Ç5Ë�ÅnÁ7l%mL¾1Ìp ºRº�Ð Þ ÕW»EØp¸nÛr» Þ ÖàØÚ»EÑ�Ó3ÖeÝeØZ½H·�ÍÆ»á»�ñ�ò�»ZÛ Þ ÕW»EÖ Ð Þ ÖeÑZºRÔeÝÆ»EØ7¸`ºRº Þ ÖeØÚÐr¸`ÖeÑ�»EØDÙOÍÆ»ZÛr»#ÐrÍÆ»#òeÛrÓ`ò�»ZÛrÐ äÙD¸`Ø(òeÛrÓ<Ü`»EÝ ÐÚÓiÍÆÓ3ºRÝ Þ Ö Þ ÖÎÐrÍÆ»rqeÛ�ØÚÐh»�ñ�ò�»ZÛ Þ ÕW»EÖ ÐZ½tsA¸`ÔeÖeÑ�ÍÆ»EØhÙOÍÆ»ZÛr»~¸`ºRº7ÕW»ZÐrÍÆÓ�ÝeØhÐÚÓqÓ$uº»EØrØ�ÐrÍe¸`Ö)øiØÚ»EÑ�Ó3ÖeÝeØ×Íe¸EÜ`»�¹�»Z»EÖﺻZÏ�ÐWÓ3ÔÆÐZ½wv9x#Ôe¸`ºUy�ØÚÐr¸`ÖeÝeØWÏ�Ó`ÛWÛ�ÔeÖeÖ Þ Ö â Ó3ÖÆ» Þ ÐÚ»ZÛ�¸nÐ Þ Ó3ÖÓ`ÏzmáÁ { ÌU|θ`ÖeÝ}máÁ { Ì�~ Þ Ö ÐÚ»ZÛ�Ñ�Íe¸`Ö â »E¸n¹�ºäF��v�� Þâ ��¸ â y²Ûr»ZÏ�»ZÛ�ØOÐÚÓ#máÁ { Ì ���v�ôqÐrÝg�mÖeÝ-y²ØÚÐr¸`ÖeÝeØOÏ�Ó`ÛØÚÐr¸`ÖeÝe¸nÛ�Ý Þ ÖeÝeÔeÑ�Ð Þ Ó3ÖÎÙ Þ ÐrÍ ¸`ºRº7ÔeÖ ÞRþ ÔÆ»EÖÆ»EØrØhÑ�Ó3ÖeØÚÐÚÛ�¸ Þ Ö ÐrØWØÚÐr¸nÐ Þ ÑZ¸`ºRºä�¸`ÝeÝÆ»EÝ ¸`ÖeÝ ÔeØ Þ Ö â ¸`Ö»�ñ�ÐÚ»ZÛ�Öe¸`ºBô p ·z� ØÚÓ3ºÜ`»ZÛE½

�J�

Page 21: BMC’03 - JKUfmv.jku.at/papers/bmc03-preliminary-proceedings.pdfBMC’03 Boulder, Colorado, USA. ... Alessandro Cimatti (IRST, Italy) Raanan Fraer (Intel, Israel) Danny Geist (IBM

�r��2�#�b�-�}����b� �2�b��� � �

����k� �-���2���;� �����)�;���k�����M���  ¡���T¢U���9� £�¤�¥�¦j§�¨©�ªr« ¬®­2��¯;¯ ¬®­2��¯;¯

°�±J²9³+´�µ �M����¯9¶ ·�· ¸2¹ º ¸2¹ » ¤$¹ ¼°�±J²9³+´�µ �M����¯T½ ·�¤ ¾2¹ » ¾2¹ » ·�¿2¹ £°�±J²9³+´�µ �M����¯;À £HÁ Á�¿2¹ » Á�¼2¹ · ·�£�¤$¹ £°�±J²9³+´�µ �M����¯; ·H» ·�¸2¹ º ·�¸2¹ ¤ ¸�¿2¹ £Ã�Ä;ÅJÆ ²�µ Ç ���M¯T��¯TÈ$¯9¶ ·�¼ ¾2¹ ¸ ¼2¹ ¿ ·�¹ ·Ã�Ä;ÅJÆ ²�µ Ç ���M¯T��¯TÈ$¯;É ¾ ¸2¹ ¸ ¼2¹ » ¼2¹ ¾Ã�Ä;ÅJÆ ²�µ �VÊ�§�¦ Ç �;§$��Ë ·�º Á�¹ » ·�¹ ¼ £$¹ ¾Ã�Ä;ÅJÆ ²�µ �VÊ�§�¦ Ç �;§$�)½ £�¼ £�¼2¹ ¾ ·�¹ ¿ ¾2¹ ·´�Ì0²�µ ��Í0¯T���JÎ����;� £�¼ £�¼2¹ » ·�¿2¹ · »H¾2¹ ·

Ï�ÐJÑbÒÔÓzÕ�Ö^×^Ø�Ù-Ú�Û�ÜfÝ`Ú�ÞbßVàJágÛ)Ú�â�ã%á0ß$äHåJÛzÜfÞFæHÛ)Ú�Ý`Ú�ÞbßVàJá�çzèêétë�âHìgí%îðïòñ;ÜfÞgâ�ßVàJÞFæ�Ú�âóåMäFô�Ø�Ú)õöáUÚ�Þ�÷2ßfø%ìù ÒUÒbú)ûUü�Ó�ý®ÐJþ)ÓkûUÿrý9Ó����2ÿ��-ýHÖ����ÓHþ�fÓ���ú ���gÓ�ý)ý�� ü�Ó�Ð$ÿ-ý®ú��gÓ�� ù Ï��TûUÿ-ý9ú)Ð$ÿ���Ó+Ó�ÿ������gÓ��Mú��gÓHþ)ÓkûUýÐ�Ñ�������7ÒÔÓ�ÿ��$ú��������! "�gÓHþ)Ó#�hûUýzú��gÓ ÒÔÓ�ÿ��$ú������ú��gÓðý����$þ)ú9Ó�ý9ú"���$�-ÿ�ú9ÓHþ�VÓ�%gÐ$ü!&bÒÔÓ$Ö#��'�($)#��+*,�#ü�Ó�Ð$ÿ-ý-�}ûUýðü-�-ÒÔú)û.&bÒUûÔÓ�� Ñ0/21+3 '�(�Ö�4òÐ��-ÿ��5�gÓ�ý� "�gÓHþ)Ó Ð$ÒUÒ7ü�ÓHú������-ýöú�0��6 ÒÔÓ�ý)ýöú��-Ð$ÿ Õý9Ó����2ÿ��-ý7�-Ð�8$Ó Ñ¡ÓHÓ�ÿ ÒÔÓ9fú7�$�gúHÖ

����k� �-��� :�Í �k��;<:�Í �k��= ©����0; ©����0= «ò�0��­0; «ò�0��­0= «ò§��$¢>; «ò§��$¢>=

?)³+±-µ Ç ���;Í §�@$Í0� ¾J» »H¼2¹ » ·�£�¼2¹ Á ¼ Á�º�¤�º ÁJ¤�¤9A ¾�¼�¿�A ·�¤9A ·�ÁBAÄ Ì CED%µ F £�¼�¿ £�¤�¾ Á�¸�º2¹ » G HJIKKEL £�¤�¿MG H�NKKKKEL ·�¿�º�A ¦ »Hº�A ¦Ä Ì CED%µ F £�¾�¿ ¤�¾ £�»J¹ » º�º2¹ º ·�·�Á ·�º�¤�¸ º�¾�A £�¾�º�A £HÁBA £�¤9AD Ä °Fµ §J§ Ç ¶ ¸�¼ ¸�¾2¹ Á ¤�¼2¹ Á ·�·�¸ Á�¼�º ºJ»�A ·�¼2·5A ¸�£9A ¸�¼�A°�±J²9³+´�µ ��­2ÍO@2�����)�QP £�¿ ·�£�¼2¹ ¸ º�º2¹ ¾ ¼ ¸J»H¿ ·�¤$·5A £�»Hº�A ¤�º�A £�¿�A´�Ì0²�µ Ç �;§�@2�)��� �U¶VË ¸�¼ £�¤�º2¹ º £�¤�£$¹ » ¼ Á�¼�º ¸�Á�º�A Á�¸�¾�A Á�¿�A Á�¸�A´�Ì0²�µ Ç �;§�@2�)��� �U¶�½ ·H» ¸2·�¹ ¸ Á�·�¹ » ¼ ·�£�¼ ·�¿�¾�A £$·H»�A ·�·5A ·�¸�A´�Ì0²�µ Ç �;§�@2�)��� �U¶VÀ £HÁ ·�¼�¾2¹ ¸ ·�¸�Á�¹ ¸ ¼ £�¤�¸ £�»H¸�A ¸�¸�¼�A £�¾�A £�¾�A´�Ì0²�µ Ç �;§�@2�)��� �U¶RP £�¿ £$·�·�¹ ¸ £�¤�¸2¹ º ¼ ¸�¤$· ¸�£�£9A Á�¼�¼�A ÁJ¤9A Á�º�A´�Ì0²�µ Ç �;§�@2�)��� �U¶RS ·�Á £$·�¹ Á £�¤$¹ ¤ ¼ »H¿ ·�¤�¸�A ·H»J·5A ·�¼�A ·�¼�A´�Ì0²�µ Ç �;§�@2�)��� �U¶RT £�¸ º2·�¹ º »J·�¹ ¾ ¼ £�¸2· £�º�¼�A ¸2·�·5A ·�¿�A ·�¿�A´�Ì0²�µ Ç �;§�@2�)��� �0ËT½ ¸�¿ ¸�¾2·�¹ ¾ Á�¾�¼2¹ · ¼ º�º�º Á�Á�¼�A ¤�¿�¿�A º�¼�A º2·5A

Ï�ÐJÑbÒÔÓ-UgÖ�×^Ø�Ù-Ú�Û�ÜfÝ`Ú�ÞbßVàJá7Û)Ú�â�ã%á0ßfâ�äHåJÛ õ+VJÞFàJÝ Ü�æ`ë�âHì^â�ßVà$ßjÜ�æ ã%Þ-ÜXWHãbÚ�Þ¡Ú�â�â�æ�åJÞgâ�ßjÛ9àJÜfÞbßfâ ÜfÞ�ßføgÚÜfÞFõJã-æ�ßjÜ�åJÞ-ñTâ�ßTÚTÙ ì ù ÒUÒ�ú)ûUü�Ó�ýkÐJþ)Ó�ûUÿ ý9Ó����2ÿ��-ýHÖ#4òÐ��-ÿ��5�gÓ�ýkú)Ð+6%ûUÿ��hÒÔÓ�ý)ýkú��-Ð$ÿ219Y ý9Ó����2ÿ��-ý��$þ�-Ð�8%ûUÿ��rý����$þ)ú9ÓHþkÒÔÓ�ÿ��$ú��tú��-Ð$ÿZ([�-Ð$ý Ñ¡ÓHÓ�ÿtÒÔÓ9fú �$�gúHÖ ù ý���&¡ÓHþ�ý���þ�û.&-ú\����rü�Ó�Ð$ÿ-ý���/%ÿ-Ð$ü û]�^ �2ÿ_�gÓ�ü Ð$ÿ��a` Ð����-ûUÿ��b����-ÿ-û]c0�gÓ�ÿgÓ�ý)ýd���2ÿ-ý9ú9þ�Ð$ûUÿ�ú)ýHÖ ù ý���&¡ÓHþ�ý���þ�û.&-úe�9ý��êü�Ó�Ð$ÿ-ý ý9ú)ÐJú)û]�Ð����-ûUÿ��[��,�-ÿ-û]c0�gÓ�ÿgÓ�ý)ý7���2ÿ-ý9ú9þ�Ð$ûUÿ�ú)ý+Ñ¡ÓHúf ®ÓHÓ�ÿ}Ð$ÒUÒg&bÐ$ûÔþ�ý7��®ý9ú)ÐJú9Ó�ýHÖh�izÐ$ÿ�� ûUý ú��gÓ ÿ0�-ü Ñ¡ÓHþ������2ÿ-ý9ú9þ�Ð$ûUÿ�ú)ý`Ð����gÓ�� ^ ÑbÐ$ÿ-ÿ-ûUÿ�� úf j� ý9ú)ÐJú9Ó�ý[fþ��2ü Ñ¡Ó�ûUÿ�� Ó�c0�-Ð$Ò>`�Ök�5lzÒUÐ����}ûUý ú��gÓnmbÿ-Ð$Òÿ0�-ü Ñ¡ÓHþg����HÒUÐ��-ý9Ó�ý�ûUÿðú��gÓ®ý�2Ò.8$ÓHþ�Ö��5lj�2ÿ���+ûUý ú��gÓú�$ú)Ð$Ò%ÿ0�-ü Ñ¡ÓHþg������2ÿ�obû]��ú)ý�ûUÿðú��gÓzý9Ó�ÐJþ5�5���ú9þ)ÓHÓ!��®ú��gÓ�ý�2Ò.8$ÓHþ�Ö\pkÿ-Ò./#ú��gþ)ÓHÓ!&-þ��$ÑbÒÔÓ�ü ýkÐ���ú��-Ð$ÒUÒ./tÿgÓHÓ��gÓ����-ÿ-û]c0�gÓ�ÿgÓ�ý)ý ���2ÿ-ý9ú9þ�Ð$ûUÿ�ú)ýöú�Ñ¡Ó#&-þ��B8JÐJÑbÒÔÓ�q Ð$ÿ��tûUÿtÐ$ÒUü!�2ý9úkÐ$ÒUÒg�$ú��gÓHþr�HÐ$ý9Ó�ýöûÔúkûUÿ��9�gþ)þ)Ó��#Ð����2ý9úkú� Ð���� ú��gÓ�ü Örs��$þkú��gÓú��gþ)ÓHÓt�HÐ$ý9Ó�ýJ "�gÓHþ)Ózú��gÓt���2ÿ-ý9ú9þ�Ð$ûUÿ�ú)ýu ®ÓHþ)Ó�ÿgÓ���Ó�ý)ý)ÐJþ�/�q�Ð����-ûUÿ�� ú��gÓ�üv��/%ÿ-Ð$ü û]�HÐ$ÒUÒ./ðÒÔÓ�Ð�� ú�ðÐý&¡ÓHÓ����f��& Öuw ûÔú����$�gút�-ÿ-û]c0�gÓ�ÿgÓ�ý)ýj���2ÿ-ý9ú9þ�Ð$ûUÿ�ú)ýzú��gÓ�ý9Óöú��gþ)ÓHÓr&-þ��$ÑbÒÔÓ�ü ÐJþ)Óðÿ��$út&-þ��B8JÐJÑbÒÔÓkÑ0/ûUÿ�������ú)û.�2ÿ Ö�Ï7�gÓt��/%ÿ-Ð$ü û]��ü�ÓHú������ ú��0�-ý^ý)Ð�8$Ó�ýú��gÓ7�-ý9ÓHþxfþ��2üv�$�gÓ�ý)ý)ûUÿ��r>�$þ^Ó�Ð��5�\&-þ��$ÑbÒÔÓ�üû.y�-ÿ-û]c0�gÓ�ÿgÓ�ý)ý����2ÿ-ý9ú9þ�Ð$ûUÿ�ú)ý ý����$�-Ò]�rÑ¡Ó��-ý9Ó����$þ+ÿ��$út ûÔú����$�gúóûUÿ��9�gþ)þ�ûUÿ�� Ð$ÿz/hÓ�%%ú9þ�Ð\���2ý9úHÖ

{$|

Page 22: BMC’03 - JKUfmv.jku.at/papers/bmc03-preliminary-proceedings.pdfBMC’03 Boulder, Colorado, USA. ... Alessandro Cimatti (IRST, Italy) Raanan Fraer (Intel, Israel) Danny Geist (IBM

}d~�$�n�������y���� �$���Q� � �

���X� �x���f�����B�y�9�9���9�z�a�B�f�Q�0�X���X���n�����r�����0 ���¡a¢g��£Q¤>¥¦�����+§�¨ �#©5��ª�«�¤>��«n�����#�B¬y��­B�"®0¯J�0«�«�¤>��°\ª���¤>±�ª�������©Q© ­�®���©5��£��0¤>����©«a²����0¥¦¤>­+�0 > ³²´�0��«k©5�9�z��¤>­+�0 > ³²�§#¤>��­� >ª�«�¤>��°¶µg®0���k¤>��©5�9�0��­���©·¨�����£Q�¸�����¸­�®���©5��£��0¤>����©¥�ª�©5�Zµg�2�0«�«���«u§��0��«¹¤>��©5�9�0��­���©º¨���¤>­9�v�0£Q�b¢�£Q®�»0�0µ� >�·¨�¤³����®�ªa�Zª���¤>±�ª�������©Q©Z­�®���¼©5��£��0¤>����©�½t¾r���[£Q��©Qª� ³��¤>©r¢�£Q��©Q��������«2¤>�¶¿ÁÀ�ÂzÃRÄ!Å�½

¾r���¸�B¬y��­B�e®0¯[©Q���0£Q¢g����¤>��°Æ�����¸­�®���©5��£��0¤>����©�µ�²v£Q��¥¦®�»�¤>��°¶»0�0£Q¤Ç�0µ� >��©��0£Q�È��®0�¢�£Q��©Q��������«u§r�0©h¤³�n¤>©h­� >�+�0£Q ³²¶�0«a»0�0���9�0°���®�ª�©�½_ÉÊ©5��ª�«a²_®0¯#�����´Ë �B� Ì�ÍaÎ ��±�ª�¤³»0�0 >����­��­9����­9Ï�¤>��°¶¢�£Q®�µ� >��¥¦©�§ ¨�����£Q�ÈÐ�®�ªa�º®0¯hÑ�Ò�������«vª���¤>±�ª�������©Q©Z­�®���©5��£��0¤>����©�§r©Q��®�¨ ��«�����z� �y�z�y� ®0¯t������©Q�h­�®�ª� >«Èµg�d©Q®� ³»���«È¨�¤³����¤>�e�����d��¤>¥¦��¼µg®�ª���«e¨�¤³����®�ªa��ª�©Q¤>��°Z�����©Q���0£Q¢g����¤>��°�½

Ó ÔvÕ,Ö�×jØ�ÕxÙÛÚÝÜ"Þ�ß

���­�£Q��¥¦�����9�0 �àrá2âã¨��0©t¤>��«���¢g����«������� ³²d¤>����£Q®�«�ª�­���«hµ�²hä-¯R��£7å���£Q¤>­9��¥º�0��¤>��æ å���£Q¤ÇçaÑBè�0��«¹åa�0Ïz�0 > Ç�0�_�B�+½"�0 E½é¤>�êæ ëkì[åaçaÑ�èE½íä�ª�£¦�0¢�¢�£Q®��0­9�´«�¤³¬y��£Q©n¯R£Q®�¥î¢�£Q�B»�¤>®�ª�©º�z�5¼����¥¦¢a��©�¤>�Z�����z��¨ �!Ï0����¢b�0 > y­� Ç�0ª�©Q��©�¯R£Q®�¥ï¢�£Q�B»�¤>®�ª�©r¤³����£��z��¤>®���©!ðR¤>��­� >ª�«�¤>��°d­�®��añ�¤>­B�­� Ç�0ª�©Q��©9ò�½eáe®�£Q��®�»���£�§j¨ �Z­�®�¥¦¢� >�B���h�����¦¥¦�B����®�«�¨�¤³����¤>��­�£Q��¥¦�����9�0 t����¥¦¢g®�£��0 t¤>��¼«�ª�­B��¤>®��u½"å���£Q¤>­9��¥º�0�uó © ¨ ®�£QϺ¯Rª�£5������£�¤>��­� >ª�«���©r©Q�B»���£��0 J����­9����¤>±�ª���©���®h�������0��­��\�����å�Ét¾ ¼©Q®� ³»�¤>��°�®0¯ àrá2âô¢�£Q®�µ� >��¥¦©�§J¤>��­� >ª�«�¤>��° �X����B���g�0õ"�9�z�a�B�f�Q�0�X���X�h���ögõ.�E���0�f�E�z� ¯R®�£­�®�¢�²�¤>��°ã¤>��»0�0£Q¤Ç�0���¦­�®��añ�¤>­B�Z­� Ç�0ª�©Q��©ºµg�B�¨ �����¹�����e��¤>¥¦�·©5����¢�©Z®0¯������e��£��0­��0§��0��«àrá2âí©Q¢g��­�¤³��­!»0�0£Q¤Ç�0µ� >��«���­�¤>©Q¤>®��·©5��£��z����°�¤>��©dæ å���£Q¤Çç�ç$èE½

÷ ø Ü ù�úxÖ5û�ü�ý�Ü ù�ü

¾,��¥¦¢g®�£��0 �¤>��«�ª�­B��¤>®��_���0©¦µg�����´ª�©Q��«´µg�B¯R®�£Q�·��®�¢�£Q®�»��eª�¢�¢g��£¦µg®�ª���«�©n¯R®�£nàrá2âæ å�å�åaç�çzèE½t��º������©Q�!�B¬y®�£5��©�§������!�0ªa����®�£Q©���©5�9�0µ� >¤>©Q����«Z¤³� ��®�®d­�®�©5�� ³²¦��®�°�£��0«�ª��0 > ³²h¤>��¼­�£Q�+�0©Q��������«���¢a���h®0¯Á������¤>��«�ª�­B��¤>®���¢�£Q®�®0¯Áª�©Q¤>��°!�0�h��¡�����£Q���0 Áå�Ét¾ ¼©Q®� ³»���£�½jëã�����+»��©Q��®�¨��h�����z�t¤>������°�£��z��¤>��°#�����#å�Ét¾ ¼©Q®� ³»���£7�0��«������r¤>��«�ª�­B��¤>®���¢�£Q®�­���«�ª�£Q�r®�»���£Q­�®�¥¦��©����¤>©r­�®�©5�+½�þ�ª�£5������£Q¥¦®�£Q�0§a¨ �d©Q���0£Q¢g������«e�����\ª���¤>±�ª���¼©5�9�z����©#­�®���©5��£��0¤>����©#µ�²e�n©5²���¼�9�0­B��¤>­#�0���0 ³²�©Q¤>©7®��¦�����#��£��0��©Q¤³��¤>®��n£Q�� Ç�z��¤>®��uÿ��0�º¤>¥¦¢�£Q®�»���¥¦�����"�����z�"¨��0©��0µ�©Q®� >ªa���� ³²����­���©Q©��0£5²·¯R®�£r¥º�0��²Z®0¯j®�ª�£�µg����­9��¥º�0£QÏ�©r��®¦°�®h����£Q®�ª�°��u½

à"²ã��¡�������©Q¤³»��Z����©5��¤>��°b¨ �º¯Rª�£5������£�£Q��¤>�a¯R®�£Q­���«ã�����º»�¤>�B¨ �����z��¤>��«�ª�­B��¤>®��¶¤>©d�0�¤>¥¦¢g®�£5�9�0���"­�®�¥¦¢� >��¥¦�����"��®hà����#¼µ��0©Q��«º¥¦�B����®�«�©"¯R®�£ ©��z¯R�B�²�¼­9����­9Ï�¤>��°�½7¾r����­�®�¥h¼µ�¤>���z��¤>®�� ®0¯\����­9����¤>±�ª���©�¢�£Q��©Q��������«k¤>�´����¤>©º¢��0¢g��£Z£Q��©Qª� ³��©Z¤>�´¨����z�Z�����È�0ªa����®�£Q©µg�� >¤>�B»�����®\µg�������r��£Q©5�"���¦­�¤>����� �0��«¦­�®�¥¦¢� >�B����¤>��«�ª�­B��¤>®��nµ��0©Q��«¦­9����­9Ï0��£ ¢�£Q®�«�ª�­���«µ�²b�0­+�0«���¥¦¤Ç�a½��t���0µ� >��«bµ�²e�����[¤>��­�£Q��¥¦�����9�0 �å�Ét¾ ¼¤>������£5¯f�0­��0§Á¨ �d��¡a¢� >®�£Q��«È�0�b®���¼ >¤>���d¥¦�B����®�«¸®0¯ �0«�«�¤>��°·ª���¤>±�ª�������©Q©[­�®���©5��£��0¤>����©!®��¸«���¥º�0��«u½�¾,®e�� Ç�0£Q°�����¡��������������¥¦�B����®�«�©��+»���©t������ª�©Q��£�¯R£Q®�¥ô«���­�¤>«�¤>��°�¥º�0��ª��0 > ³²!¨����B������£t®�£���®0����®!�0«�«�������©Q�­�®���©5��£��0¤>����©�§�¥º�0Ï�¤>��°�����¥¦¢g®�£��0 y¤>��«�ª�­B��¤>®��e�h¥¦®�£Q�!¢�ª�©Q��¼µ�ªa�Q��®��·����­9����¤>±�ª��0½

É-©���©Q¤>«���¼�B¬y��­B��®0¯x¤>¥¦¢� >��¥¦������¤>��°[����¥¦¢g®�£��0 g¤>��«�ª�­B��¤>®��Z¤>��­�£Q��¥¦�����9�0 > ³²�§�¨ �\°�®0��0�d¤>��­�£Q��¥¦�����9�0 �àrá2â�¯R®�£x©��z¯R�B�²[¢�£Q®�¢g��£5��¤>��©�½j¾r��� �B¬y®�£5��©,®��d¤>��­�£Q��¥¦�����9�0 �àrá2âãµ�²æ å���£Q¤ÇçaÑz§ ëkì[åaçaÑ�è7¨��0©[µ��0©Q��«ã®�����¡�������©Q¤³»��Z�0«��0¢a�9�z��¤>®��¸®0¯ �����nª���«���£Q Ç�+²�¤>��°2å�Ét¾ ¼©Q®� ³»���£�½jëã�#���+»��-©Q��®�¨��º�����z�"£Q��©Qª� ³��©"®0¯y�����#©��0¥¦��¥º�0°���¤³��ª�«��r­+�0�ºµg�#�0­9��¤>�B»���«Zµ�²�h¥�ª�­9�b©Q¥º�0 > >��£�¥¦®�«�¤³��­+�z��¤>®��Z®0¯j�����\©Q®� ³»���£�½"Éô©5�9�0��«��0£Q«e¨��+²·®0¯t�0¢�¢� ³²�¤>��°nàrá2â

�

Page 23: BMC’03 - JKUfmv.jku.at/papers/bmc03-preliminary-proceedings.pdfBMC’03 Boulder, Colorado, USA. ... Alessandro Cimatti (IRST, Italy) Raanan Fraer (Intel, Israel) Danny Geist (IBM

�� ��������������� ������ � �

���� "!$#&%(')%(*"+, "%�+-����')#&.�%�/�0214365)*�!&7).�%(89%('):(!�;)��')#� "<)%�5)*�%(��%('):(%=!?>2+-7)@)#-AB�C "<)��'ED "��8-%B�F "%(5)�(GIHJ%K<L+NM&%O:(!&8-5L+?*�%(;- "<)���P8-%� "<)!�;- "!��C "%(*"+, "��')#Q@)5- "!RD-��'):(*�%(8-%('S T+?.�.CU+?');E>V!&@)');E "<L+, � "<)%=��'):(*�%(8-%('S T+?.I+?5)5)*�!S+?:T<WA�+?�O>X+?�F "%(*���'W8-!&�F O:N+?��%(�(YZ%�M&%('[�C>4DA�+?����5\%(:(�C]L%(;^+?��:(.�!&��%_+?�a`&b&cd+?7\!M&%O "<)%_.�%(')#? "<�!?>I+=��<)!&*F "%(�F a:(!&@)'S "%(*e36%gf)+?8-5).�%?G

h i�jakLjOlLmonqpPlLr

1�<)%�����')#&.�%O8-!&�F �����#&')�C]L:N+?'S �>X+?:� "!&*4>V!&*4 "<)%_��@):(:(%(���a!?>s "%(8-5\!&*"+?.���');)@):� "��!&'t���� "<)%��');)@):� "��!&'[;)%(5u "<v')%(%(;)%(;wGxHJ%- "<)%(*�%�>V!&*�%-7\%(.���%�M&%- "<)%-8-!&�F ���8-5\!&*F T+?'S _;)��*�%(:� "��!&'!?>y*�%(��%N+?*�:T<E���� "!A�+?*�;)�a8-%� "<)!�;)�B!?>I+?@u "!&8$+, "��:N+?.�.CU-�F "*�%(')#? "<)%(')��')#� "<)%Q��');)@):� "��!&'�3�F "%(5v��'v!&*�;)%(*Q "!^*�%(;)@):(%$ "<)����;)%(5u "<wG^0z��@):(:(%(���F>V@).�8-%� "<)!�;v+?:T<)��%�M���')#^ "<)���_A�+?�5)*�%(��%('S "%(;���'-{ |2� }�~��&�uY �����&�,��Gs�� �A4!&*�~��Z7SUO]L');)��')#B��'SM?+?*���+?'S w%(��@)�CM?+?.�%('):(%(�Z!&*���8-5).���3:N+, "��!&')�B7\%� 6A4%(%('E "<)%Q�F T+, "%QM?+?*���+?7).�%(�a+?');^��'S "%(*�'L+?.�5\!&��'S "�(Ga��+?�F "��')#� "<)���a8-%� "<)!�;��'S "!�!&@)*���'):(*�%(8-%('S T+?.��FU��F "%(8�.�!�!&~��RM&%(*FU�5)*�!&8-������')#)G�/� "*�!&')#&%(*-:(!&')�F "*"+?��'S "��!&' "<)%���<L+?5\%=!?>�+$��<)!&*F "%(�F �:(!&@)'S "%(*e36%gf)+?8-5).�%QA4%(*�%R��@)#&#&%(�F "%(;W��'�{ /)/)/u�&�?��Y�7)@u O<L+NM&%')!? OU&%� _7\%(%('���@):(:(%(���F>V@).�.CU�+?5)5).���%(;wG�HJ%�A4!&@).�;�.���~?%Q "!���'SM&%(�F "��#S+, "%R�C>P+t;uU�'L+?8-��:+?5)5)*�!S+?:T<�����8-��.�+?*2 "!= "<L+, �A4%�@)��%(;�>V!&*�@)')����@)%(')%(���B:(!&')�F "*"+?��'S "��8-��#&<S �7\%O<)%(.�5u>V@).�G

� ��'L+?.�.CU&Y� "<)%(*�%$+?*�%�8$+?'SU�5\!&������7).�%=A�+NU��=!?>P "@)')��')#x "<)%t/�021436��!&.CM&%(*_ "!���'):(*�%g38-%('S T+?.? "%(8-5\!&*"+?.?��');)@):� "��!&'wGZ�6'_5L+?*F "��:(@).�+?*(YNA4%2AB����<� "!B%gfu5).�!&*�%2'L+, "�CM&%2@)')����@)%(')%(���:(!&')�F "*"+?��'S "�(YL+?�4A4%(.�.�+?�� "<)%�8-%� "<)!�;)��5)*�%(��%('S "%(;^��'�{ /� "*����&��Y�/� "*����u����>V!&*���5\%(:(��+?.����(%(;M?+?*���+?7).�%K!&*�;)%(*���')#&�a+?');x:(!&')�F "*"+?��'S a*�%(5).���:N+, "��!&'wG

��� ra�Ops���emZ���4 ¡ms�4k)¢

HJ%BA4!&@).�;$.���~?%� "!Q "<L+?')~�£s%(*���}�%(����%�+?');�¤^+?*FUt/�<)%(%(*"+?'->V!&*� "<)%(��*�:N+?*�%�>V@).\*�%N+?;)��')#+?');�M?+?.�@L+?7).�%O:(*��C "��:(����8d!?>y "<)%_8$+?'�@)��:(*���5u �>V!&*� "<)����5L+?5\%(*(G

¥ mZ¦gmZlLms� � mZ¢

§ ¨�©Iªª(«)¬�­P¨¯®6°g±e±6°²P³�­4©I´�µN°g±e±6°g¶L­¸·?¹¯º�»�¼F½�¾�¿gÀ?ÁÃÂBÀ?ÄNÅCÆwÇ�¾SÈ(Å�ÉuÊÌË�ÅCÈ(Í\ÉuίÈ�¹)È�¾SÈ�À¹LÏ�¾�Ç�ÀлyÄ(¾,ÑuÀ?Ä(¿g¾�Ò�Ó Ô�¶ÖÕ¯×NØ�Ù_ÚNÛ�Ü�ÝTÞ�ß&×gà(á�â�ãÌä�×NÙPåuæSÞXÝ"Ø�çVè4âéà,Ýeà�êOÝ�á�âìëã�²í\î ©�ïuð�ñgòó(ôS²)ï?õ�öFÔ�¶S÷°Tö6øVù�°TöF´�µN÷QúNªªª&­

§ ¨�©�©�ûLòò�«uüa­�¨IÔì°Töe°²�üa­s©IÔ�ý_µNþ6þeÔé²�ÿ�­��x­s©I´�µNö��°²�µ¶����O­sû��L­�·?¹�� t½ZÉuÒ�Å�Ç� �ÉLÁ�À&ÒÇNÍ\À?Ç��¯Å�Ê��ÃË�ÅCÈ(Í\ÉuίÈ������R¿gÓ Ô�¶��IØ6×������! #"�$Fã�Þ%�tä�×Nã�&!�=×Nã('�×g×NÛ á[ÚNãuàè4Û ë,×NØ�â�Þ�ß,ÙKá)&T×NØ=Þ�ßSÝ�ä�×NãSá"Þ�Ø�æ��gÞ�âé×NãvÚNãuà-è4ãuÚNÛ *(á�âCáR×+&-,�*(á"ÞXÝ"ÙKá�² í\î ©�ïuð�ñgó/.Nò?²ï?õ�öFÔ�¶S÷°Tö6øVù�°TöF´�µN÷Rñgòòò?­

§ ¨�©10�ûLòò�«uüa­�¨IÔì°Töe°²�ÿ�­ �x­K©I´�µNö��°²20B­30PµÔ�ý_Ôé²4µ¶��4�O­aû��L­ ·NÂBÀ?ÄNÅ65%�\Å�Ê�� ¿g¾�5XÀ,È7�Ï�Ä(É�ÏZÀ?Ä�È(Å�À?¿vÉ85�¾:94É?ËOÀ?Ä�9�;�< È� >=? ^Å�Ç�Ä(É�Ï�Ä(ÉLÇ�À?¿g¿gÉ�Ä Î\¿�Å�Ê�� ¿!�� t½ZÉuÒ�Å�Ç �ÉLÁ�À&Ò[ÇNÍ\À?Ç��¯Å�Ê�� Ë�ÅCÈ(Í\ÉuίÈ@�����R¿gÓ Ô�¶A�IØ6×����>B/BC #"D$Fã�Þ%�Wä�×Nã�&!��×Nãä�×NÙPåuæSÞXÝ"Ø�è4âéà,ÝeàFE�Ý"Ø�â GH�FÚÞ�âé×Nã�² í\î ©�ïuð�ñ�IKJKJ?²Lï?õ�öFÔ�¶S÷°Tö6øVù�°TöF´�µN÷Rñgòòò?­

§ ¨yö�LNMKI�«0B­ ÿ�­K¨yö�L�µ¶,þT­ ·�O=Ä(¾�ÏwÍL¼F½�¾�¿gÀ?Á ¾�Ò6��É�ÄNÅCÈ(ÍP �¿Q5XÉ�Ä ½ZÉLÉuÒ�À?¾�ÊR5�Î�Ê\ÇÈ(Å�ÉuÊ �¾�Ê�Å�ÏwÎ�Ò�¾SÈ(Å�ÉuÊ\ÓvÔ�¶S$UTVTVT:'SØ6ÚNãSá!�s×Nã�ä�×NÙPåuæSÞXÝ"ØFá�²¯©søWJóNXYM/ZF²uü)S÷S­\ñgòKMKI?­

�/[

Page 24: BMC’03 - JKUfmv.jku.at/papers/bmc03-preliminary-proceedings.pdfBMC’03 Boulder, Colorado, USA. ... Alessandro Cimatti (IRST, Italy) Raanan Fraer (Intel, Israel) Danny Geist (IBM

\^]_/`ba8`�cedPfg8h _/`8i7i g `

j k1l)monKp�qsrutvk1w�xKyvz8{|t }Nt8l)y�~N�!���U�/yvz8�PtsmH��xK���Kz��st8m1�N��y��!z8�Ht�b��~��N�/yN�Nz8��ts���K�U���#yvz}Nt ��t�{��!���U���/�u�v�P���|�������� �¡£¢�¤�¥H¦�§�¤8�©¨v�8ª%«7¬�¦�§��­¨v®����¯¡±°²�/¦N«�¡6�s¢�³�´A�#yµU¶V¶V¶:·N¸U¹»ºs¼V½»º¿¾s½+ÀCÁ£ÂV¹»¸�ÃĶ1º�ÅKÆ6ºÃ�ÃC¸7Æ6º�Å�Ç�È8É%ÊKË z}/��ÌYtvÍ�nKnKp

j k1�²��Î2ÏNÍ7qs�Ht2kH�KÐ��ÒÑKz�Ó�t��²�ÕÔz�{|t��N��x»�!��z)Ö�t)×2�#��y�Ø�w��Ù�/Ì#�#x�z�×�t�Ú|xK�Ûw��YzolÄt�ÜPxKØ!Ø�wN��Ì#Ì#x�z�>t Ý�t¿Þ�x»��~��Yt �Kß���¢��¯°P«�³à�8ªDá��sâP¢��P���äã��v�P�����»������ �¡£¢�¤å¦N«à¦8¢¡£¢��²â�³!«�§»¡6¦8�1³��¯«�«�¡£¢�¤8´u�#y?æ ¸U½�ç�¼VèKé!ê#ëSµ�º8Á%¼�ìí½»º�À�ÃC¸�ÃCºsç7Ã�½»º�ìí½»î�ïsðNÁÒÃC¸|ñ)ÆYò¯Ã�òó8ÃC¸7Æ ôHç�¹KÁ£ÆY½»º z8Ó��3k��sõ Ç Í!Ï Ç z Ç ÏKÏNÍ»t

j k���ÏKÏ�qsÚ�t�k1Ì#x»�����U��yvz��>t-��wN�!�!��xKyvtö�/÷ùø1â�«��8§»¡6¦8�F�s¢R¥H¦¯úN¦vû�÷ýüS¦�§���¬�¦�§��þ ��³��/§»¡6®�«�¡6�s¢�¦8¢��Qÿ|��§»¡±°²�/¦N«�¡6�s¢�¨���³!«���ã�´ x»��� ÁYÁ ï�� ���8ÂíÂíÂV¼6ç�!¼6ç � ¹� î-ÃC¸��¼ ��Ã������K½�ÃCº�����¹��»¹ z Ç ÏKÏKÏ

j �2Ó�Ó�� Ç qv�>t��2x����#�!z��>t�Ó��K�/�ÛxKyvz���t�Ó����K��Ì#xKy�~vtö�/÷ ã�¦��»�P¡£¢�� ®P§��8¤8§�¦8ã ªÒ�8§«������8§���ã ®P§���ú�¡£¢�¤8´4�#y ìí½»î�î�ð�º�ÆYç�¹KÁ£ÆY½»º���½+ÀÄÁ � Ã3ñ�ì�� z��K�/Ì ��z�Í�n�� Ç t

j ÖV� !U�NnKp�qvk)t lÄt }Nt"�»xKy¿ÖV� !U�stÛ��¨v�$#�â���¢s«�¡6¦8�o�$#�âP¡±úN¦8�6��¢��/�>�»������ �¡£¢�¤­¬^¡±«����sâ�«�³!«�¦N«��³�®P¦��/� «�§�¦¯ús��§�³�¦8�6´à�#yFæ ¸U½�ç�¼�ìí½»º�À!¼�½»º&%�Ã��7ÆÙÅKº�'oñ)ðNÁ%½»îÛ¹KÁ£ÆY½»º�¹»ºsò�·sÃ��CÁ�Æ6º¶1ð�¸U½�ï�à z�Í�nKnKp�t

j (��K�Nn�)�qv}Nt �Ät�(����K�K�!�F��¨v�s�±ú�¡£¢�¤¿«����+*�¢��/§���ã���¢s«�¦8�H¨v¦N«�¡6³!°²¦�Ს£�£¡±«��&,|§��8á²�6��ã�´ �#y-N½»ð�¸7ºs¹�P½+À.��½�ÅKÆYç æ ¸U½�ÅK¸U¹»î�î�Æ6º�Å z��K�/Ì�Í���z�Í�nKn�)�t

j �¿�NnKn�qv}Nt �Pt��Sx»��/��N���10+���#Ì �»x�zÚ�t lÄt���x»�»xKÌ#Ì#xKwvtb�$243�÷b¨�,�ûo÷ ¨v��¦�§��»�u÷��6¤8�8§»¡±«��PãªÒ�8§5,|§��8®��8³�¡±«�¡6�s¢�¦8� ¨v¦N«�¡6³!°²¦�Ს£�£¡±«���´ �#y µU¶V¶V¶ ·N¸U¹»º��!¹/ç�Á£ÆY½»º�� ½»ºìí½»î�ïsðNÁÒÃC¸�� z"�K�/Ì È p�zPÍ�nKnKn�t

j �76ÏNÍ7qv�>t rutv�b�/�U�K�98��#Ø:Kz�k)t �Ht�SxK~��Ù�/xKyvz�Ý�t�6w�x»�NzsÓ�t�6w�xKyN�Nz�sts�SxKÌ#�Ù�:������¦�;�û< ¢�¤s¡£¢�����§»¡£¢�¤©¦8¢ <>= �¯¡6��¢s«¿¨�÷3ø ¨v�s�±ús��§�´@�#yeæ ¸U½�ç�¼1½+À�Á � ÃÛé�?!ê#ë7%�Ã��7ÆÙÅKºñ)ðNÁ%½»îÛ¹KÁ£ÆY½»º©ìí½»º�À�ÃC¸�ÃCºsç7à z Ç ÏKÏNÍ»t

j ���U���#ÏKÏ�q�@�t����U���#Ø�w��ÛxKy �/ø1âP¢P¡£¢�¤ ¨�÷3ø �»������ 8��§�³ ªÒ�8§ ß��sâP¢��P��� �u�v�P����������� �¡£¢�¤8´ �#yÛæ ¸U½�ç�¼�½+À�è�A�ê#ë�µ�º8ÁBÙ¼íìí½»º�À!¼v½»º>ìí½»î�ïsðNÁÒÃC¸1ñ)ÆYò¯Ã�ò?ó8ÃC¸7Æ ôHç�¹KÁ£ÆY½»º zÓ��3k��sõ#Í�p�����z��Ð����#yN�K�!�C0%Þí�!��Ì#x»� Ç ÏKÏKÏ

j ���U���#ÏNÍ7q�@�t����U���#Ø�w��ÛxKy ��,|§»âP¢P¡£¢�¤­«����»�P¢P¡D#�â���³�ªÒ�8§�«���� ¨�÷3øFE�áP¦�³���� ß��sâP¢��P����u�v�P���v�������� �¡£¢�¤G,|§��8á²�6��ã�´©�#y�æ ¸U½�ç�¼8è/èCê#ë�ñ�ò��»¹»ºsç7Ã�òIH�Ã���Ã�¹»¸Uç �7J ½»¸���Æ6º�Åìí½»º�À!¼í½»º�ìí½»¸7¸�Ã�ç�Á�KĹ»¸Uò»ÂV¹»¸�ÃL%�Ã��7ÆÙÅKºe¹»ºsò ó8ÃC¸7Æ ôHç�¹KÁ£ÆY½»ºM��Ã!Á � ½�òN� z Ç ÏKÏNÍ»t

j ������ÏKÏ�qs�>tH��wN�!�!��xKyvzV�stH���#yN�/wvz�×�tH����OxKÌ#�Ûx»��Ø��stQ���������� �¡£¢�¤u³�¦�ªÒ�¯«�� ®P§��8®���§�«�¡6��³â�³�¡£¢�¤S¡£¢��²â��K«�¡6�s¢>¦8¢��>¦S¨�÷3øFE�³��s�±ús��§�´ �#yQP ½»¸7îÛ¹�R��Ã!Á � ½�òN��Æ6ºeìí½»î�ïsðNÁÒÃC¸ñ)ÆYò¯Ã�òS%�Ã��7ÆÙÅKº z�Ó��3k��sõ#Í�n�� È zv��Ð����#yN�K�!�C0%Þí�!��Ì#x»� Ç ÏKÏKÏ�t

j r Ú���ÏNÍ7q}NtKr w��Ù�U�U�����K���Kz�}Nt¯Ú|�#��zKÚ�t���x»�»xKÌ#Ì#xKwvt2��¨�÷3øL*93 < ûv÷UTS�¯¬V*�¢��/§���ã���¢s«�¦8�¨v¦N«�¡6³!°²¦�Ს£�£¡±«�� < ¢�¤s¡£¢���´ �#y æ ¸U½�ç�¼Äé�?/Á � ìí½»º�À!¼Ä½»ºW%�Ã��7ÆÙÅKº ñ)ðNÁ%½»îÛ¹KÁ£ÆY½»º zl�ko� ��������� Ç ÏKÏNÍ»t

X�Y

Page 25: BMC’03 - JKUfmv.jku.at/papers/bmc03-preliminary-proceedings.pdfBMC’03 Boulder, Colorado, USA. ... Alessandro Cimatti (IRST, Italy) Raanan Fraer (Intel, Israel) Danny Geist (IBM

Z�[4\^] _�`.aNbNcNd�eCf�eCg�h�b�ikj�c�b�lNem�g

nporq sktNu5vxwMy{z}|k~�y���������~Iz�~�����t�w&t�SuSz}t��+w

�����}�L���}�������1�G��� ��� �x���{�¡ ��£¢¤�{�¡ �����¥¦�G§R� ��� ¨ª©��«¥¬¥ �®­k�«�{¯£�{��°�G��� �

±S²´³µ ¶�·D¸�¹N·Fº�¸R·D»�³¼�¶�·B½B¾4¿1À�Á{³ÃÂÄŸ{¿�µ ¿ÃÆ�¾Ç�ÈÅÉ ¿�¼ È ½Ê¿�¼�¾�À9¿�¼4Á�Ä�³Ã¿�¼Ã³9½B·ËÂ È µ}̦¿�ÍIÎ{Ï�½«³¼LÐ{Â9·Ê³¸{Â�³Ñ�Ò«Ó�Ò�Ô ¿�Õ+Ö9×{Ø�Ø�Ù�Ú�ÛCÜFÝÃØNÞ�Ø�ß�ÖG²+º�Á�Ù�Ú�·D¸Rµ È ¸{à

á º�¸R·D»�³¼�¶�·B½B¾�¿1À�Ð"½BÏ�½Ë½âÆ È ¼½Û�¸�¶½B·B½BÏ�½«³¬À9¿�¼FÚ�¿�¼�Í È µ�ãk³9½DÄ�¿�àN¶L·D¸ä̦¿�ÍIÎ{Ï�½«³¼LÐ{Â9·Ê³¸{Â�³º�¸R·D»�³¼�¶�·B½�åÈ ½D¶�¶½B¼ ÒFæ�ç Ù�è�ÝéNØ�ÖÅê�ë�Ð"½BÏ�½Ë½âÆ È ¼½DÙ.ì�³¼�Í È ¸R¾

í�î�ï9ð�ñNòRó�ðô�õ�ö^÷"ø�÷�ö9ù¦ú�ö9û�ö�ü ý�÷"þ�ÿ�ý�û�ö�ü���ý��RÿRú�ö�ú���ý�ú�ö�ü���õ�ö����âÿ��� Cö���õRÿ������ö�þ��Dý�ù¦üâø���ö�üâü ö�ú� Cù�ø�ÿRþ� ý�ÿþ���þ� Cö��Qþ��Gô�õ�öQø����âþ� Cý�âÿ��ùÃö�ø�þCö Ãõ�öQö�!"�� ö�ÿ��#�Mý��%$%&(')���Mö#*�÷"ü ý�� âÿ��+ Ãõ�ö"âÿRõ�ö9ùÃö�ÿ, �ý�ÿ�����ùÃùÃö�ÿ��#��âÿ� Ãõ�ö�÷RùÃý�ú����# �ý��.-�ô0/�þ�âÿLý�ù�ú�ö9ù1 Cý2�ý�û�ö9ù3��ý�ùÃö�ö#*�ö����� ý�ÿRþ�ý��4 Ãõ�ö�÷RùÃý�ú����# 5 � Ãõ�âÿSø2�� û�ö�ÿ ��ý��RÿRú6��ô�õ�âþ1âþ¬ú�ý�ÿ�ö7���8�ý�ÿRþâú�ö9ù9âÿ���ø�ÿ�ý�ÿ�:«þ� Ãø�ÿRúRø�ù�úQö#*�ö����� ý�ÿ"��ý�ú�ö�ü<;þ� Cö9÷�ö#*�ö����� ý�ÿRþ�; 5 õ�ö9ùÃö=���Rü� ÷"ü öGø��# ý�ÿRþ>�9ø�ÿ? Ãø���ö+÷"üâø��ö4þ����Rü� Ãø�ÿ�ö9ý��RþÃü��7ø�ÿRú 5 õ�ö9ùÃö�ý���÷�ý�ÿ�ö�ÿ, �-�ô0/�þ.ø�ùÃöSú�ö� Cö9ù9� âÿ��@9ö�ú ý�ÿ�:A Ãõ�ö#:AB���;C<� ö���;�ø+�ý���÷�ý�ÿ�ö�ÿ, ��Qø�����ö�âÿMø4þCö� .ý��þ� Ãø� Cö�þ�âÿ ø4þ� Cö9÷DâÿRþ� Cö�ø�ú ý��3âÿ>E�Rþ� >ý�ÿ�öSø�þ�âÿMþ� Ãø�ÿRúRø�ù�úFâÿ, Cö9ù�ü ö�ø�û�âÿ��Gö#*�ö����� ý�ÿRþ��2/� Cö9÷ö#*�ö����� ý�ÿRþG�9ø�ÿ+��ö0�H��ù Ãõ�ö9ù^ùÃö�þ� Cù9��# Cö�ú= Cý�øSþ���6�9üâø�þÃþI�9ø�üâü ö�ú�÷RùÃý��ö�þÃþ^ö#*�ö����� ý�ÿRþ 5 � Ãõ�ý��� ü ý$ý�þâÿ�� ùÃö�ø���õRø��"ü ö þ� Ãø� Cö�þ��KJ�ý�ù=��ý��RÿRú�ö�úL��ý�ú�ö�ü7��õ�ö����âÿ��ký��FùÃö�ø���õRø��4âü�� M��÷RùÃý�÷�ö9ù ö�þý��� Ãõ�ö7÷RùÃý�ú����# �ý���-�ô0/�þ= Ãõ�ö7÷"ø�÷�ö9ù4÷RùÃö�þCö�ÿ, Ãþ+ Cù�ø�ÿRþÃüâø� ý�ÿ þ��õ�ö���ö�þ+�DùÃý��N-�ô0/�þ= Cýäø�ý�ÿRþ� Cù�ø�âÿ�ö�ú $^ý$ý�ü ö�ø�ÿ"�� ù9����� ¦þ����õ ÃõRø� ¬þÃø� âþ��O��âÿ��.û�ø�ü��Rø� ý�ÿRþ¦ý��P Ãõ�öQ�� ù9����� 1�ý�ùÃùÃö�þC÷�ý�ÿRú Cýkþ� Cö9÷SRD÷RùÃý��ö�þÃþUT´ö#*�ö����� ý�ÿRþ�ý��0 Ãõ�ö ÷RùÃý�ú����# �� ô�õ�öV Cù�ø�ÿRþÃüâø� ý�ÿ þ��õ�ö���ö�þGõRø�û�ö���ö9ö�ÿ���÷"ü ö���ö�ÿ, Cö�ú ø�ÿRú þCý���ö ö#*�÷�ö9ù9���ö�ÿ, Ãø�ü��ý���÷"ø�ù9âþCý�ÿRþ4÷�ö9ù�Dý�ù9��ö�ú6� ô�õ�ö ùÃö�þ�Rü� Ãþ4þÃõ�ý 5 ÃõRø� Q Ãõ�ö2��ý��RÿRú ÿ�ö9ö�ú�ö�úW�Dý�ù>þ� Cö9÷7ø�ÿRú+÷RùÃý��ö�þÃþ�ö#*�ö����� ý�ÿRþ0âþ7âÿ���ý�þ� Q�9ø�þCö�þ.ü ý 5 ö9ùQ ÃõRø�ÿâÿXâÿ, Cö9ù�ü ö�ø�û�âÿ��7ö#*�ö����� ý�ÿRþQø�ÿRúL ÃõRø� 8 Ãõ�ö+ù9�RÿRÿ�âÿ��� ���ö+ý��0 Ãõ�öW��ý�ú�ö�ü%��õ�ö����ö9ù+�Rþâÿ��÷RùÃý��ö�þÃþ�ö#*�ö����� ý�ÿRþ�âþ�þ�Qø�üâü ö9ùY ÃõRø�ÿ>�Rþâÿ��>þ� Cö9÷"þ��Z& ý�ùÃö9ý�û�ö9ù�;, Ãõ�ö�÷�ö9ù�Dý�ù9�Qø�ÿ��öG�ý���÷"ø�ùÃö�þ�Bø�û�ý�ù�ø��"ü��L Cý�økþ� Ãø� Cö#:Êý��[:A Ãõ�ö#:«ø�ù �âÿ, Cö9ù�ü ö�ø�û�âÿ��\$%&(']���÷"ü ö���ö�ÿ, Ãø� ý�ÿ^âÿ^ Ãõ�ö(_0�./�&W`þ���þ� Cö��V�

aWb�c�dYe,f � f,gh ��i,jMk�l�l�monMpPq�nrmosutZmov h �Gw�mok f,x ��p h m f � f,x�yZd izj h f v h�{ n1� x kÅ��p dZ|�g}c m�moi�m�q4~�mos�l�k�p d n|�gh d9f,gd � f,x>�Cf��oh f�d9d n h f��0h j � n1��p d q�k�i i �L� g v f m��1i dUx��odUx���Fb�c�d�e,f � f,gh ��i�jMk�l�l�monMp.q�nrmos?p c�d1�3g � x�d sQ�%m�q�w h f i¡� f,x��[� nrm�� dUg pC��¨o�o���o� h j � n1��p d q�k�i i �}� g v f m��1i �dUx��odUx�Fb�c�d%e,f � f,gh ��i.jMk�l�l�monMpZq�nrmosKp c�d0�3g � x�d sQ��m�q�w h f i¡� f,xV��� n1� f pZq�monZn d j d ��n g}c �YmonrvL��§�nrmN� x � h j� n1��p d q�k�i i ��� g v f m��1i dUx��odUx

�.���z�1�z�Z�%����}� � ��� �����A�"���}�}�M���#�4�1�.���Z ������C���}�}�M���#�"¡6� � ��¢����P£,¢�� �z�M���U¤�� �¥C���U¦U§[��#���[¦1¨G��§<���1� �W�.���9�#��#§[�[¦����C©C�#�7�P£�§<�}�3ª�¦r���}��¦�«.¬Z­�®�¯o¯o¯C° cNdNl9c�±Åec�b ° gÅdo²�d�m�³�h�´�c�²�c�g�´�³Nl

Page 26: BMC’03 - JKUfmv.jku.at/papers/bmc03-preliminary-proceedings.pdfBMC’03 Boulder, Colorado, USA. ... Alessandro Cimatti (IRST, Italy) Raanan Fraer (Intel, Israel) Danny Geist (IBM

µ,¶4·U·9¸�¹oºF»�¼Wº4¹�½

¾ ¿�À0ÁPÂ6Ã2Ä Å>ÆYÁ6ÇÃ0À

È0É�ÊPËPÌPÍ�Ì+Î�É4ÌPÍ�Ï4Ð�ÑPÍ�Ð�Ò�ÓOËPÔ�ÕMÈ�ÖX×�Ø3ÓOÙIÚ�Û�Í�ÜUÓ[Ý6Ð�Ú,Þ#ÓOÉ�Ë"Þ#Í�Ð�ÑPËPÓOß�ÊPÍ0Þ#Ñ6Ú,ÞGÐ�É�ËPÙUÓOÌPÍ�ÜUÙGÉ�ËPÏ[àÍ�á.Í�Ð�Ê.Þ#ÓOÉ�ËPÙ2É�â3ã�É�ÊPËPÌPÍ�Ì\ÏOÍ�ËPÔ�Þ#ÑDÉ�â3Þ#ÑPÍ8Ð�ÑPÉ�ÙUÍ�Ë\âAÉ�ÜUÎFÚ�ÏOÓOÙUÎåä�æ�çrè7é�ÑPÍ8Ô�Í�ËPÍ�Ü#Ú�Ï1Î�É4ÌPÍ�ÏÐ�ÑPÍ�Ð�Ò�ÓOËPÔDêPÜUÉ�ãPÏOÍ�ÎëâAÉ�Ü�ÏOÓOËPÍ�Ú�Ü2Þ#Í�Î�ê�É�Ü#Ú�ÏZÏOÉ�Ô�ÓOÐFÕMì4é2ì3Ø2ÓOÙ�Ò�ËPÉ�í2ËLÞ#ÉFã�Í+îVï�î�ð(ñ=ò�óÐ�É�Î�êPÏOÍoÞ#Í�ô�ãPÊ.ÞZÞ#ÑPÍ7ã�É�ÊPËPÌPÍ�Ì"Ð�Ú�ÙUÍQÓOÙ1ÓOË"õ\îöÕMÚ�ÙUÙUÊPÎ�ÓOËPÔ�Þ#ÑPÍ7ÊPÙUÍ�Ì"ã�É�ÊPËPÌ Þ#É2ã�Í7Ô�Ó[Û�Í�ËÓOËWÊPË6Ú�Ü9àVÍ�ËPÐ�É4ÌPÓOËPÔ�Ø�èGé�ÑPÍ2Û�Í�Ü9àWÓOÌPÍ�Ú8ÓOÙ%Þ#É"Ð�É�Î�êPÓOÏOÍ0Þ#ÑPÍ2Ù9à4Ù9Þ#Í�Î�ÊPËPÌPÍ�Ü7Û�Í�ÜUÓ[Ý6Ð�Ú,Þ#ÓOÉ�Ë�ôÞ#ÑPÍ8êPÜUÉ�ê�Í�Ü9Þ�àFÞ#ÉVã�Í>Û�Í�ÜUÓ[Ý6Í�Ì?Ú�ËPÌ÷ÚVã�É�ÊPËPÌ\ø(É�ËDÞ#ÑPÍ8ÏOÍ�ËPÔ�Þ#ÑDÉ�âZÞ#ÑPÍ8Í�á.Í�Ð�Ê.Þ#ÓOÉ�ËDÞ#ÉWÚêPÜUÉ�ê�É�ÙUÓ[Þ#ÓOÉ�Ë6Ú�Ï�âAÉ�ÜUÎ+ÊPÏHÚ�Ñ6Ú�Û4ÓOËPÔ"Ú>Î�É4ÌPÍ�Ï4Ó[ùFÞ#ÑPÍ�Ù9à4Ù9Þ#Í�ÎúÑ6Ú�Ù%Ú�ËWÍ�á.Í�Ð�Ê.Þ#ÓOÉ�ËWÉ�â�ÏOÍ�ËPÔ�Þ#ÑøDÞ#Ñ6Ú,Þ�Û4ÓOÉ�ÏHÚ,Þ#Í�Ù2Þ#ÑPÍ=êPÜUÉ�ê�Í�Ü9Þ�à�è2é�ÑPÍ+Î�ÍoÞ#ÑPÉ4ÌPÉ�ÏOÉ�Ô�àDÑ6Ú�Ù�ã�Í�Í�ËLÙUÊPÐ�Ð�Í�ÙUÙ9âAÊPÏOÏ[à?Ú�êPêPÏOÓOÍ�ÌÓOËDÓOËPÌPÊPÙ9Þ#ÜUÓHÚ�Ï�ÙUÍoÞUÞ#ÓOËPÔ?ä û4ô ü,çrèé�ÑPÍ�Ú�ÓOÎåÉ�â7Þ#ÑPÍVê6Ú�ê�Í�Ü8ÓOÙ�Þ#É÷ÌPÍoÛ�Í�ÏOÉ�ê^Íoý�Ð�ÓOÍ�Ë�Þ=È�ÖX×öÞ#Í�Ð�ÑPËPÓOß�ÊPÍ�Ù8âAÉ�Ü8Ù9à4Ù9Þ#Í�Î�Ù

Î�É4ÌPÍ�ÏOÍ�ÌVÚ�ÙGêPÜUÉ4ÌPÊPÐoÞ#Ù%É�â�ÏHÚ�ã�Í�ÏOÍ�Ì=Þ#Ü#Ú�ËPÙUÓ[Þ#ÓOÉ�Ë+Ù9à4Ù9Þ#Í�Î�Ù�ÕMì4é�þ4Ù�ØIã�àVÍ�á.êPÏOÉ�Ó[Þ#ÓOËPÔ�Þ#ÑPÍ�ÓOË4óÑPÍ�ÜUÍ�Ë�Þ0Ð�É�ËPÐ�ÊPÜUÜUÍ�ËPÐoàFÓOËWÞ#ÑPÍ�Ù9à4Ù9Þ#Í�Î�Ù�è%é�ÑPÍ�ã6Ú�ÙUÓOÐ2ÓOÌPÍ�Ú ÓOÙ%Þ#É"Ð�É�Û�Í�Ü0Î�É�ÜUÍ2Í�á.Í�Ð�Ê.Þ#ÓOÉ�ËPÙÉ�âZÚ"Ù9à4Ù9Þ#Í�Î�í2Ó[Þ#ÑPÓOË(Ú"Ô�Ó[Û�Í�ËFã�É�ÊPËPÌ(ÓOË(Ú í�Ú�à�Þ#Ñ6Ú,ÞQÞ#ÑPÍ�ÙUÓOÿ�Í�É�â�Þ#ÑPÍ�Í�ËPÐ�É4ÌPÓOËPÔ=ÓOÙQËPÉ�ÞÙUÊPãPÙ9Þ�Ú�Ë�Þ#ÓHÚ�ÏOÏ[à�ÓOËPÐ�ÜUÍ�Ú�ÙUÍ�Ì�ô6Órè Í�è[ô.Ó[Þ�ÜUÍ�ÎFÚ�ÓOËPÙ�ÏOÓOËPÍ�Ú�ÜQí è Ü�è Þ�è%Þ#ÑPÍ8ã�É�ÊPËPÌ�è%é�ÑPÍ Ù9Þ�Ú�ËPÌ6Ú�ÜUÌÚ�êPêPÜUÉ�Ú�Ð�ÑWÞ#É"È�ÖX×KÓOÙGÞ#É"ÊPÙUÍ�ÓOË�Þ#Í�ÜUÏOÍ�Ú�Û4ÓOËPÔ8Í�á.Í�Ð�Ê.Þ#ÓOÉ�ËPÙ7í2ÑPÍ�ÜUÍ�Í�áPÚ�ÐoÞ#Ï[àWÉ�ËPÍ�Ú�ÐoÞ#ÓOÉ�ËWÓOÙÉ4Ð�Ð�ÊPÜUÜUÓOËPÔ(Ú,Þ8Ú�Þ#ÓOÎ�Í�è���Í�ÜUÍ=Þ#ÑPÍ+ÓOÌPÍ�ÚFÓOÙ2Þ#É(Í�ËPÐ�É4ÌPÍ+ÓOË�Þ#Í�ÜUÏOÍ�Ú�Û4ÓOËPÔFÍ�á.Í�Ð�Ê.Þ#ÓOÉ�ËPÙ8Î�É�ÜUÍÐ�É�Î�ê6Ú�ÐoÞ#Ï[à=ã�àWÚ�ÏOÏOÉ�í2ÓOËPÔ�Î+ÊPÏ[Þ#ÓOêPÏOÍ0É4Ð�Ð�ÊPÜUÜUÍ�ËPÐ�Í�ÙQÉ�â�Ú�ÐoÞ#ÓOÉ�ËPÙGÓOËVÌPÓ[ùYÍ�ÜUÍ�Ë�ÞQÐ�É�Î�ê�É�ËPÍ�Ë�Þ#ÙÉ�âIÞ#ÑPÍ=Ù9à4Ù9Þ#Í�ÎåÙUÓOÎ+ÊPÏ[Þ�Ú�ËPÍ�É�ÊPÙUÏ[à�è�é�ÑPÓOÙ�Ò�ÓOËPÌ?É�â7Ú�ËXÚ�êPêPÜUÉ�Ú�Ð�Ñ?Ñ6Ú�Ù>Ú�ÏOÜUÍ�Ú�Ì.à÷ã�Í�Í�Ë?ÓOË4óÛ�Í�Ù9Þ#ÓOÔ�Ú,Þ#Í�ÌWÊPÙUÓOËPÔVæoó�Ù#Ú,âAÍ��3ÍoÞ#ÜUÓ6ËPÍoÞ#Ù7Ú�ÙGÞ#ÑPÍ�Ù9à4Ù9Þ#Í�Î Î�É4ÌPÍ�ÏPÚ�ËPÌWÍ�Î�êPÏOÉ�à4ÓOËPÔ>Ù9Þ#Í�ê�Ú�ËPÌêPÜUÉ4Ð�Í�ÙUÙ2Í�á.Í�Ð�Ê.Þ#ÓOÉ�ËPÙ�É�â��3ÍoÞ#ÜUÓZËPÍoÞ#Ù�í2Ó[Þ#Ñ÷Í�ËPÐ�É�ÊPÜ#Ú�Ô�ÓOËPÔWÜUÍ�ÙUÊPÏ[Þ#Ù=ä�æ��.ô �,çrèé�ÑPÍLËPÉ�Û�Í�Ï[Þ�à ÓOËSÞ#ÑPÓOÙ(ê6Ú�ê�Í�Ü(ÓOÙDÚuÞ#Í�Ð�ÑPËPÓOß�ÊPÍLÞ#Ñ6Ú,ÞDÍ�á.êPÏOÉ�Ó[Þ#Ù(ÓOËPÌPÍ�ê�Í�ËPÌPÍ�ËPÐ�Í^É�â

Ú�ÐoÞ#ÓOÉ�ËPÙVÓOË Þ#ÑPÍ÷Ù9à4ËPÐ�ÑPÜUÉ�ËPÓOÿ�ÓOËPÔuêPÜUÉ4ÌPÊPÐoÞ�É�â>ì4é�þ4Ù�ÙUÉ^Þ#Ñ6Ú,Þ�Î+ÊPÏ[Þ#ÓOêPÏOÍFÓOËPÌPÍ�ê�Í�ËPÌPÍ�Ë�ÞÚ�ÐoÞ#ÓOÉ�ËPÙ\Ð�Ú�Ë Þ�Ú�Ò�ÍuêPÏHÚ�Ð�ÍuÓOË ÌPÓ[ùYÍ�ÜUÍ�Ë�ÞXÐ�É�Î�ê�É�ËPÍ�Ë�ÞLì4é�þ4Ù?ÙUÓOÎ+ÊPÏ[Þ�Ú�ËPÍ�É�ÊPÙUÏ[à�è é�ÑPÓOÙÞ#Í�Ð�ÑPËPÓOß�ÊPÍXÓOÙWâAÊPÜ9Þ#ÑPÍ�ÜFÐ�É�Î+ãPÓOËPÍ�ÌKí2Ó[Þ#Ñ Ú�ËSÉ�Ë4ó}Þ#ÑPÍ�ó�PàKÌPÍoÞ#Í�ÜUÎ�ÓOËPÓOÿ�Ú,Þ#ÓOÉ�ËKÐ�É�ËPÙ9Þ#ÜUÊPÐ�óÞ#ÓOÉ�Ë+í2ÑPÍ�ÜUÍ2âAÉ�Ü7Í�Ú�Ð�ÑFÐ�É�Î�ê�É�ËPÍ�Ë�ÞQÚ ÙUÍoÞ0É�âYÙ9Þ�Ú,Þ#Í�ÙQÓOËVí2ÑPÓOÐ�ÑWÞ#Ñ6Ú,ÞQÐ�É�Î�ê�É�ËPÍ�Ë�ÞQÐ�Ú�Ë�ã�ÍÓOÙ"ÎFÚ�ÓOË�Þ�Ú�ÓOËPÍ�Ì�èDÈQà ÊPÙUÓOËPÔ?ÌPÍoÞ#Í�ÜUÎ�ÓOËPÓOÿ�Ú,Þ#ÓOÉ�ËLÞ#ÑPÍFË�ÊPÎ+ã�Í�Ü=É�â�ÌPÓ[ùYÍ�ÜUÍ�Ë�Þ+Í�á.Í�Ð�Ê.Þ#ÓOÉ�ËPÙÞ#ÑPÍ\êPÜUÉ4ÌPÊPÐoÞ(Ð�Ú�ËSÑ6Ú�Û�ÍXÓOÙ�ê�É�Þ#Í�Ë�Þ#ÓHÚ�ÏOÏ[à ÌPÜ#Ú�ÎFÚ,Þ#ÓOÐ�Ú�ÏOÏ[àuÜUÍ�ÌPÊPÐ�Í�Ì�ô�Ú�ËPÌSâAÊPÜ9Þ#ÑPÍ�ÜUÎ�É�ÜUÍÓOË�Û4ÓOÙUÓOãPÏOÍ"Þ#Ü#Ú�ËPÙUÓ[Þ#ÓOÉ�ËPÙ>ÌPÉDËPÉ�Þ Ð�É�Ë�Þ#ÜUÓOãPÊ.Þ#Í+Þ#ÉDÞ#ÑPÍVÏOÍ�ËPÔ�Þ#Ñ^É�â0Ú�Ë^Í�á.Í�Ð�Ê.Þ#ÓOÉ�Ë�è��Ë^Þ#ÑPÓOÙí0É�ÜUÒCô0Þ#ÑPÍ?Ð�É�ËPÐ�ÊPÜUÜUÍ�Ë�Þ(Í�á.Í�Ð�Ê.Þ#ÓOÉ�ËPÙFÉ�â8ÓOËPÌPÍ�ê�Í�ËPÌPÍ�Ë�ÞDÚ�ÐoÞ#ÓOÉ�ËPÙ�Ð�É�Î+ãPÓOËPÍ�Ì í2Ó[Þ#ÑSÉ�Ë4óÞ#ÑPÍ�ó�PàSÌPÍoÞ#Í�ÜUÎ�ÓOËPÓOÿ�Ú,Þ#ÓOÉ�ËKÉ�â Ð�É�Î�ê�É�ËPÍ�Ë�Þ#ÙDÚ�ÜUÍXÐ�Ú�ÏOÏOÍ�Ì ������������������������� �oè"! Ó[Þ#ÑPÉ�Ê.ÞÐ�É�Î�êPÜUÉ�Î�ÓOÙUÓOËPÔ?ÜUÍ�Ú�Ð�Ñ6Ú�ãPÏOÍDÙ9Þ�Ú,Þ#Í�Ù�ôQÙ9Þ#Í�êKÍ�á.Í�Ð�Ê.Þ#ÓOÉ�ËPÙWÐ�Ú�ËKã�Í(âAÊPÜ9Þ#ÑPÍ�ÜVÜUÍ�Ù9Þ#ÜUÓOÐoÞ#Í�Ì Þ#É�$#%���������&����������������� ��Ù#Ú,Þ#ÓOÙ9â<à4ÓOËPÔ Ú�ËWÍ�á4Þ#Ü#Ú Ð�É�ËPÌPÓ[Þ#ÓOÉ�ËVÉ�ËVÛ4ÓOÙUÓOãPÏOÍ�Ú�ÐoÞ#ÓOÉ�ËPÙGÞ�Ú�Ò�ÓOËPÔ8êPÏHÚ�Ð�ÍÙUÓOÎ+ÊPÏ[Þ�Ú�ËPÍ�É�ÊPÙUÏ[à�èÈ�Ú�ÙUÍ�ÌFÉ�ËWÞ#ÑPÍ�ÙUÍ�ÓOÌPÍ�Ú�ÙQÚ>Þ#Í�Ð�ÑPËPÓOß�ÊPÍ�âAÉ�Ü%ã�É�ÊPËPÌPÍ�ÌFÎ�É4ÌPÍ�ÏPÐ�ÑPÍ�Ð�Ò�ÓOËPÔ=É�â�ÜUÍ�Ú�Ð�Ñ6Ú�ãPÓOÏ�ó

Ó[Þ�à\êPÜUÉ�ê�Í�Ü9Þ#ÓOÍ�Ù>É�â%Þ#ÑPÍ+Ù9à4ËPÐ�ÑPÜUÉ�ËPÓOÿ�ÓOËPÔDêPÜUÉ4ÌPÊPÐoÞ8É�âQì4é�þ4Ù8ÓOÙ�ÌPÍoÛ�Í�ÏOÉ�ê�Í�Ì^ã�àXÌPÍoÛ4ÓOÙUÓOËPÔÚ Þ#Ü#Ú�ËPÙUÏHÚ,Þ#ÓOÉ�ËWÙUÐ�ÑPÍ�Î�Í�âAÜUÉ�Î Þ#ÑPÍ>ì4é�þ4ÙQÞ#É+Ú"Ð�É�ËPÙ9Þ#Ü#Ú�ÓOËPÍ�ÌDÈ0É4É�ÏOÍ�Ú�Ë�Ð�ÓOÜUÐ�ÊPÓ[Þ>ä�æ�û�çYÙUÊPÐ�ÑÞ#Ñ6Ú,Þ Ù#Ú,Þ#ÓOÙ9â<à4ÓOËPÔ(Û�Ú�ÏOÊ6Ú,Þ#ÓOÉ�ËPÙ>É�â7Þ#ÑPÍWÐ�ÓOÜUÐ�ÊPÓ[Þ8Ð�É�ÜUÜUÍ�ÙUê�É�ËPÌ^Þ#É÷Ù9Þ#Í�êuÍ�á.Í�Ð�Ê.Þ#ÓOÉ�ËPÙ É�âQÞ#ÑPÍêPÜUÉ4ÌPÊPÐoÞ�è(' Î�ÓOËPÉ�Ü8Í�á4Þ#Í�ËPÙUÓOÉ�Ë É�â0Þ#ÑPÍFÎFÚ�êPêPÓOËPÔ÷Ñ6Ú�ËPÌPÏOÍ�Ù=êPÜUÉ4Ð�Í�ÙUÙ=Í�á.Í�Ð�Ê.Þ#ÓOÉ�ËPÙ�è)�Ëã�É�Þ#Ñ÷Ð�Ú�ÙUÍ�Ù2Þ#ÑPÍ ÙUÓOÿ�Í É�âIÞ#ÑPÍ Í�ËPÐ�É4ÌPÓOËPÔWÓOÙ�ÏOÓOËPÍ�Ú�Ü0í è Ü�è Þ�è7Þ#ÑPÍ ã�É�ÊPËPÌ�è+*6É�Ü�Þ#ÑPÍ Í�ËPÐ�É4Ì4óÓOËPÔPôPÈ0É4É�ÏOÍ�Ú�ËDÐ�ÓOÜUÐ�ÊPÓ[Þ#Ù2Ú�ÜUÍ8Í�Î�êPÏOÉ�à�Í�Ì÷âAÉ�Ü�Ð�ÏHÚ�ÜUÓ[Þ�à(Ú�ËPÌ\Ð�É�Î�ê6Ú�ÐoÞ#ËPÍ�ÙUÙ�è0þ4ÊPÐ�Ñ?Ð�ÓOÜUÐ�ÊPÓ[Þ#ÙÐ�Ú�Ë\ã�Í8Þ#Ü#Ú�ËPÙUÏHÚ,Þ#Í�ÌDÞ#É�êPÜUÉ�ê�É�ÙUÓ[Þ#ÓOÉ�Ë6Ú�Ï�âAÉ�ÜUÎ+ÊPÏHÚ�Í>ÓOË?×-,�* í2Ó[Þ#Ñ?ÚVÏOÓOËPÍ�Ú�Ü�ãPÏOÉ�í�ó�ÊPê÷ã�àÓOË�Þ#ÜUÉ4ÌPÊPÐ�ÓOËPÔVÚ�ÌPÌPÓ[Þ#ÓOÉ�Ë6Ú�Ï�êPÜUÉ�ê�É�ÙUÓ[Þ#ÓOÉ�Ë6Ú�ÏCÛ�Ú�ÜUÓHÚ�ãPÏOÍ�Ù�ÊPÙUÓOËPÔVÙ9Þ�Ú�ËPÌ6Ú�ÜUÌ÷Þ#Í�Ð�ÑPËPÓOß�ÊPÍ�Ù=ä�æ�û�çrè

û

Page 27: BMC’03 - JKUfmv.jku.at/papers/bmc03-preliminary-proceedings.pdfBMC’03 Boulder, Colorado, USA. ... Alessandro Cimatti (IRST, Italy) Raanan Fraer (Intel, Israel) Danny Geist (IBM

.�/�0�02143�576�895�3;:

<�=?>�@;A?A?B�CD@;E�=7=F@;GIH$>J>JKL@;A?A?MONO>JPRQ%CS@TG�>�Q+C;UV>XW?@;YZA?MO>JG+@;K?P9Q%=?>[PF@�Q�@TC\H Q�@;NOK?>JP]�^ G2Q%N_Ua`bQ%=?>ZUcC\MOMOC�deNOK?f)A$C\NOKDQ%GJgihjNOB�G2Q%M_`\klQ%=?>7H$C ^ K?PmK?>J>JP?>JPnUcC\BoG2Q%>JAn@;K?PmA?B�C�EJ>JG�G>XW >JE ^ Q%NOC\K?GoNOGpNOKqYZC\G2QTEr@;G�>JGoMOC�ds>JBpQ%=F@;KtNOKbQ%=?>9Q%B%@;P?N_Q%NOC\KF@;MuNOKDQ%>JB�MO>r@rv�NOK?f)YZC�P?>JM�gw >JEJC\K?P?M_`\klQ%=?>9B ^ K?K?NOK?f)Q%NOYZ>JG ^ G�NOK?fiA?B�C�EJ>JG�Go>XW >JE ^ Q%NOC\K?G�@;B�>9C;UaQ%>JKtG�Y7@;MOMO>JB�Q%=F@;K^ G�NOK?f7G2Q%>JA?GJgphjNOKF@;MOM_`\k?Q%=?>�B�>JG ^ M_Q%G�EJC\YZAF@;B�>oU�@rv\C\B%@;H?M_`(Q%C7Q%=?>SB ^ K?K?NOK?f7Q%NOYZ>JG[C;UI@G2Q�@�Q%>Xx�C;UyxQ%=?>Xxz@;B2Q�NOKDQ%>JB�MO>r@rv�NOK?f9{�|~}�NOYZA?MO>JYZ>JKDQ�@�Q%NOC\Kb� ����g

<�=?>eAF@;A$>JBINOG�C\B�fD@;K?NO�J>JP9@;G�UcC\MOMOC�deGJg w >JE�Q%NOC\KL�&NOKDQ%B�C�P ^ EJ>JG�Q%=?>�UcC\B�Y7@;MONOG�Y ^ G�>JP@;GRQ%=?>iYZC�P?>JMONOK?fbMy@;K?f ^ @;f\>)@;K?P w >JE�Qrg+�t{sC�C\MO>r@;K�EJNOB�E ^ N_Q%GJg w >JE�Q%NOC\K��tA?B�>JG�>JKDQ%GQ%=?>S>JK?EJC�P?NOK?f7G�E�=?>JYZ>JG�UcC\B[H$C;Q%=~>XW >JE ^ Q%NOC\K~YZC�P?>JMOGJg w >JE�Q%NOC\Kb�9f\N_v\>JG[Q%>JG2QpB�>JG ^ M_Q%GEJC\YZAF@;B�NOK?fbG2Q%>JA�@;K?P�A?B�C�EJ>JG�GZ>XW >JE ^ Q%NOC\K?GZQ%C�� ^ w |)��� ��k ����@;K?P��FKF@;MOM_` w >JE�Qrg+�EJC\K?EJM ^ P?>JGJg

� �e�[���?�u� ���e�p�u�2 2¡&¢¤£&�+¥¦�¨§I�2 z�?�

}sC\K?E ^ B�B�>JKDQ�G2`�G2Q%>JYZG-G�A$>JEJN_�F>JP)@;GsMy@;H$>JMOMO>JPRQ%B%@;K?G�N_Q%NOC\K7G2`�G2Q%>JYZGT©�ª�< w?« @;B�>�G2Q ^ P?NO>JPNOK�Q%=?NOGIAF@;A$>JBJg�<�=?B�>J>[>XW >JE ^ Q%NOC\KZYZC�P?>JMOG�UcC\B�Q%=?>eG2`�K?E�=?B�C\K?NO�J>JP7A?B�C�P ^ E�Q+C;U­¬iª�< w G@;B�>SNOKDQ%B�C�P ^ EJ>JPVgT<�=?>S�FB�G2QTNOG[Q%=?>�G2Q�@;K?PF@;B�PbNOKDQ%>JB�MO>r@rv�NOK?fLG�>JY7@;KDQ%NOEJGJgp<�=?>JB�>r@�UaQ%>JBJkQ%=?>)G2Q%>JA�@;K?P�A?B�C�EJ>JG�GZYZC�P?>JMOG9@;MOMOC�deNOK?f~NOK?P?>JA$>JK?P?>JKDQL@;E�Q%NOC\K?G�Q%CbQ�@;®;>iA?My@;EJ>(G�N¯xY ^ M_Q�@;K?>JC ^ G�M_`°@;B�>RP?>��FK?>JPVg�<�=?>RG�>JE�Q%NOC\Kq>JK?P?GpdeN_Q%=q@;Kt@;KF@;M_`�G�NOG&C\K~Q%=?>RB�>JMy@�Q%NOC\KH$>�Q�ds>J>JKiQ%=?>TP?N_±­>JB�>JKDQ[YZC�P?>JMOGJg

²(³D´�µu¶a·�¶c¸$µº¹V»�¼º½�Kiª�< w NOG[@R��xQ ^ A?MO>p¾n¿À©�ÁjÂ%æÂ�Ä�Â�Å « de=?>JB�>

Æ Á�NOG[@RK?C\K�x�>JYZA Q�`(G�>�Q[C;UjG2Q�@�Q%>JGJkÆ ÃLÇ�Á�NOGe@9K?C\K�x�>JYZA Q�`LG�>�Q�C;UsÈaÉFÈaÊ�È�Ë;ÌuG2Q�@�Q%>JGJkÆ Ä�NOGe@RK?C\K�x�>JYZA Q�`(G�>�Q[C;Uuv�NOG�NOH?MO>p@;E�Q%NOC\K?GJk¦@;K?PÆ ÅÍÇ�Á�Ît©�ÄRÏiÐ�Ñ­Ò « ÎiÁ-k NOG+Q%=?>�Ê�Ó�Ë;É Ô�ÈaÊ�È�Õ�É°Ó%Ö�Ì_Ë;Ê�È�Õ�ÉFk�Q%=?>&>JMO>JYZ>JKDQ%G-C;U×de=?NOE�=)@;B�>Er@;MOMO>JP(Q%B%@;K?G�N_Q%NOC\K?G-C;U�¾�k?de=?>JB�>TÑiNOG-Q%=?>TNOKDv�NOG�NOH?MO>p@;E�Q%NOC\KVgØ N_v\>JKZ¬iª�< w G+¾sÙ�Â�¾�Ú�ÂrÛrÛrÛ�Â�¾�Ü k­©�¾sÙ�ÝjÛrÛrÛ�Ý�¾�Ü « NOG ^ G�>JPZQ%CTP?>JK?C;Q%>eQ%=?>JNOBsÔ�Þ�É­ß�à�Ó%Õ�á

ÉFÈ_â�Ö%ãpä$Ó%Õrã;åFß�Ê×P?>��FK?>JP~NOK(Q%=?>oG2Q�@;K?PF@;B�Pid-@r`\k¦G�>J>o>;g f?gj� �;�×de=?>JB�>TQ%=?>oG2Q�@�Q%>JG[C;UjQ%=?>A?B�C�P ^ E�Q�@;B�>s¬¦xQ ^ A?MO>JGuC;U?Q%=?>sG2Q�@�Q%>JGjC;U?Q%=?>sEJC\YZA$C\K?>JKDQ%G�@;K?Pode=?>JB�>�@ev�NOG�NOH?MO>+@;E�Q%NOC\KEr@;K)C�EJE ^ B�N_±~@;MOM$Q%=?>pEJC\YZA$C\K?>JKDQ%G�EJC\KDQ�@;NOK?NOK?f�Q%=F@�Qe@;E�Q%NOC\K(AF@;B2Q%NOEJNOAF@�Q%>;g�æ[C�ds>�v\>JBJkNOKZQ%=?NOG+dsC\B�®9Q%=?>&NOKDQ%>JB�>JG2Q�NOG+NOK7Q%=?>��FK?N_Q%>�>XW >JE ^ Q%NOC\K?G-C;U×Q%=?>�A?B�C�P ^ E�QrgIhjNOB�G2Q%M_`\k�Q%=?>G2Q�@;K?PF@;B�PiYZC�P?>JMVC;UjNOKDQ%>JB�MO>r@rv�NOK?fR>XW >JE ^ Q%NOC\K?G�@;B�>pP?>��FK?>JPVg

²(³D´�µu¶a·�¶c¸$µº¹V»O¹çª×>�Q�¾n¿À©�¾sÙ�ÝjÛrÛrÛ�Ý�¾�Ü « H$>+Q%=?>+G2`�K?E�=?B�C\K?NO�J>JPRA?B�C�P ^ E�Q�C;UF¬7ª�< w GJg½è©a�FK?N_Q%> « NOKDQ%>JB�MO>r@rv�NOK?f7>XW >JE ^ Q%NOC\Kbé?ê�UcB�C\Yë@7G2Q�@�Q%>9ì�ÙeQ%C(@7G2Q�@�Q%>Rì�íïî�ð$Ù�ñIC;U+¾ NOG�@G�>Jò ^ >JK?EJ>

ì�ÙSó�ôõ ìrÚlö�ö�ö ó�÷õ ì íïî�ð$Ù�ñ©zø «G ^ E�=iQ%=F@�Qe>r@;E�=bìJùV¿À©�ì Ùù ÂrÛrÛrÛJÂXì Üù « ÂXì�ú ù�û Á ú kFN�g >;g_k?>r@;E�=bì�ú ù NOGe@9G2Q�@�Q%>TC;U�ª�< w ¾ ú @;K?Pü ù û ÄjÙ×Ïtö�ö�ö�Ï°ÄVÜ[ÏbÐ�Ñ­Ò�gIý�K°@;P?P?N_Q%NOC\K

Æ UcC\B�>r@;E�=~ª�< w ¾ ú ÂXì�ú Ù û à ú k�

Page 28: BMC’03 - JKUfmv.jku.at/papers/bmc03-preliminary-proceedings.pdfBMC’03 Boulder, Colorado, USA. ... Alessandro Cimatti (IRST, Italy) Raanan Fraer (Intel, Israel) Danny Geist (IBM

þ�ÿ������������ ����������������������������� "!�#�$%�� "&('�)+*�,.-0/1�2�%#�$43657-+��8"9: (��8"9:��9;��!��<������ "!��2������ =?> - $:@ #�$ @ > - A $CBED?F?G 3IH;-0/1����8"9:��J���!�9�/ > - A $CBED?F.K > - $ /1�� "&�������L�����E���������� "!L#�$M/��2��#�$ KON ��8"9: P��8"9:��9Q��!L�� R'�)+*,.-S!�T"�U8R��81�V� =?> - $ @ N @ > - A $CBED?F G 3,.-W�� "&R�������� YX�����8"9:��'�)+*�,[Z @U\L]K_^ @ > Z A $CBED?F K > Z$M`'�9���a1b =�c"d G &"9: "����9S��8"9S�:�� "�e�V��9: 1�V������ f���E��8"9hg���!���i"��9S���������� "!j�� c"d �� <��8"9S����&"9:�k �� "&1�V��9:&�iYX c"d `l !��U�V��9 >:m ��!!�����&_���niE9o��9e���U81��i"��9p�2q >:m ��!r�� "9p���W��8"9p�� "�2���s���h!��U�V��9:!Pt Kt0D[u6vevevwuRt�x<���y��8"9:��9W��!h�� R9{z|9:�:T|������ c ����� k �� R�� "�2���s���1!��U�V��9 > ��� >:m ` l !��U�V��9 >:m��!��(}w~��Y}|�����U�P!��U�V��9;�2qp�2����!S��9e���U81��i"��9��� "&���8"9:��9;��!S "�f������ "!��2������ =?> m @ # @ > m m G 36H `

�R�Y�j�4���0���E������� '�9���, K =?� @ t @ 5 @ H G �� "& �%mj��� ` )S8"9 N�� �:����!�T"��9f��� �%m ��!���8"9!�9��Q���j!��U�V��9:! �%m m���� !�T"�U8o��81�V� > 3 �%m m �2q > 3 �%m ���S��8"9:��9���!Q�� (9{z|9:�:T|������ (����� k!�� k 9W!��U�V��9;�� �%m ��� > �:�� Y�U���� "�� "�f�� "�2X N�� ������ "!��2������ "! `

)S8"9f����������J��� "�P&"9��1 "�2������ 6�"��9:!�9: Y��!;��8"9 !���9:��9{z|9:�:T|������ "!;���y��8"9f!�X� "�U8"���� "���:9:&�"����&"T"���Q���j�n'�)+*�! ` )S8"9 k ��&"9:����!+!�T"�U8o��81�V�+J�8"����9;���E9:���V���� "�r�� o�E��!�!���i"�2X� "�� �&"9���9:� k �� "��!�������'�)+*�!%�2�.&"9���9:� k �� "���:9:!.��8"9 k �� � ��8"9 �¡  X ` )S8"9:��9�������9�/��� �9e���U8<�E��!��2������ �� r��8"9Q9{z|9:�:T|������ P9e���U8R�:� k �E�� "9: Y� k �eX iE9Q�� P��!�9��S����!��U�V��9:!h�� "!���9e��&���|¢�T"!��h�� "9 `�R�Y�j�4���0���E�����C£ '�9��j, K = ,LD0¤%¥�¥�¥0¤�,jx G iE9���8"9y!�X� "�U8"���� "���:9:&f�"����&"T"���%���1�'�)+*�! `l �1 "�2��9<¦�§M~M¨69{z|9:�:T|������ c7© ���j,_��!��f!�9:ªwT"9: "�:9

« DS¬7­® «1¯ vevev «1° ¬"±® « A ° BED?F=?² G!�T"�U8���81�V�+9e���U8 « $.��!��� (� � ��T"�"��9 =?� D$ @ vevev @ � x$ G / � -$ �³� -0/�´�µ ^ µO�%/1� ` 9 ` /"9e���U8 � -$��!+� !�9��Q���[!��U�V��9:!+���['�)+*(,.-;�� "&o9e���U8p¶P·³¸+$ � 5%D4¹�¥�¥�¥0¹o5�x `hº p��&"&"�2������ R��8"9����������J��� "�»�:�� "&"�2������ "!S8"����&�¼� º « Dh9�g�9:��X � - D ��!h��8"9 N�� �:����!�T"��9;���%t�- `�o½1����9e���U8¾¸+$S�� "&¾,.-0/+¿ ¸+$�ÀÁ57-�¿jµÂ´�/j� ` 9 ` /%�� Ã9e���U8¾!���9:�Ä�V� k ��!��»�� "9rg���!���i"��9���������� ���!S9{z|9:�:T|��9:&o����� k 9e���U8o'�)+* `�o½1���j9e���U8 ¸+$¡/Y�2�E#3p¸+$M/���8"9: f�����j9e���U8,.-y!�T"�U8 ��81�V��#3657-���8"9:��9S��![�Q������ "!��2������ =?> - @ # @ >:m- G 3ÅH;-�!�T"�U8Æ��81�V� > -f3 � -$ ` ½1T"����8"9:� k ����9 � - A $CBED?F ��!Q��8"9 N�� �:����!�T"��9f�����8"9�!�9�� ���Q!��U�V��9:! ��9e���U8"9:&Äg��s�Æ�����y��8"9P������ "!��2������ "! =?>:m @ # @ >:m m G 3ÇH;-!�T"�U8Ä��81�V�>:m 3 � -$ `�o½1���S9e���U8(¸+$%�� "&o,.- @ �2�%¸+$|Ào57- K ¶ ��8"9: � - A $CBED?F K � -$�`)S8"9(��9: "����8Ä��� c7© /y&"9: "����9:&_iYXÈ¿ c7© ¿�/L��!rÉ ` '�9�� \�Ê � =�c7© G &"9: "����9���8"9�!�9����������h�E��!�!���i"��9R���� "9e�������e�V������ "!<��� c7© /L� ` 9 ` /y��8"9(!�9�����Q!������� "��!#|D�# ¯ vevevU# ° !�T"�U8Ë��81�V�#�$%3 \�Ê � = ¸+$ G /"������9e���U8 Ê K ´ @ vevev @ ÉPJ�8"9:��9 \�Ê � = ¸+$ G ��!S��8"9�!�9��Q���j!������� "��!���i|�U���� "9:&iYXR�:�� "�e�V��9: 1�V���� "�f��8"9;9:��9 k 9: Y��!��� �¸+$4�� (�� YXR����&"9:� `

�R�Y�j�4���0���E������Ì '�9��h, K = ,LD�¤%¥�¥�¥V¤�,jx G / > K =?> D @ vevev @ > x G �� "& « K =?�%mD @ vevev @ �%mx G /> -f3 � -0/ �%m- ��� -�/�´Pµ ^ µÍ� `fÎ 9��1 "9 >PÏ « ��� k 9e�� 6��81�V�;9e���U8 > - 3 �%m- @ ´Pµ^ µO� `

Ð

Page 29: BMC’03 - JKUfmv.jku.at/papers/bmc03-preliminary-proceedings.pdfBMC’03 Boulder, Colorado, USA. ... Alessandro Cimatti (IRST, Italy) Raanan Fraer (Intel, Israel) Danny Geist (IBM

ÑVÒ�Ó�Ó�Ô�Õ�Ö×�Ø Ö�Õ�ÙÚSÛ"Ü;Ý�Þ�ß�ß�Þ�à�á�â"ã»ä�Û"Ü:Þ�å�Ü:ærç�èUÛ1é�å�é�è�ä�Ü:å�á�ê:Ü;Û"Þ�àÈá�âYä�Ü:å�ß�Üeéeë�á�â"ã é�â"ì(ç�ä�Ü:íoÜ{î|Ü:è:ï|ä�á�Þ�â"ç

å�Ü:ßséVä�Ü�ä�Þ Üeé�èUÛ(Þ�ä�Û"Ü:å:ð�ÚSÛ"Ü�ñ(é�ç�ç�ï"ærÜ�ò¾óõôöòL÷�ø%ùeùeùVø�òjúYû{ðü»ý.þwÿ��0þ�������� ��������������������� �!��"�#�$��%&����'�()�+*��-,�.��/�102�3�54�(6057 ò ���98;: ���-: ó=<�>?�@ ���A� @ ��"$�B�CD��C��!�!E;�+*��-,�.��/�102�F��G

H�÷JI1K-L�MN H O.ùeùeù-H P I1KRQSMN HUTVP WE÷1Xô/YYû057 ò C�. , @ � @ ���[Z ÷ Z O.ùeùeù Z P7ó]\ ^"ô ��� û$_[`[ab< ���98Dc TVd-WE÷1XfebHUTVP WE÷1X+>ü»ý.þwÿ��0þ������hgi ������Gj���k�lC��!�!Em�+*��-,�.��/�102��057 ò "$�$�n, @ ����' H TVd-WE÷1X >o?�@ ���p7q02"p��%���"�rC������!�sc ebH TVd-WE÷1Xt� @ ��"$�u�CB������� �!��"�#�$��%&����'v�+*��-,�.��/�102�v���s057 ò "$�$�n, @ ����'wcDC�. , @ � @ ���\ ^"ô ��� ûyxz`�{1|[ô ��G û}>~ ÿ��0ÿ9�/�����&������i��C������!�wcA057 òOó ôöòL÷0ø%ùeùeù0ø�òjúYû �CD"$�$�n, @ ���}#�j� ��� @ ��"$�o�C���C��!�!E�+*��-,�.��/�102� H�÷�� LN H Ok���N ùeùeù ���N H TVd-WE÷1XtC�. , @ � @ ���fc ebH TVd-WE÷1X�7q02"kC&02��� <�>ÚSÛ"Ü�ç�Ü�äyÞ�Ý�ç�ä�Ü:írÜ{î|Ü:è:ï|ä�á�Þ�â"ç[Ý�Þ�å�éWç�ñ�ç�ä�Ü:æ�è:Þ�âYäUé�á�â"ç�á�âfærÞ�ç�ä�èeé�ç�Ü:ç�ì"áS��Ü:å�Ü:âYäyÜ:ß�Ü��

ærÜ:âYä�çLá�âYä�ï"á2ä�á2ë�Ü:ß2ñfè:Þ�å�å�Ü:ç�íEÞ�â"ì"á�â"ã�ä�Þ�ä�Û"ÜQç�é�ærÜQè:Þ�â"è:ï"å�å�Ü:âYä��EÜ:Û1éeë�á�Þ�å:ðjÚSÛ"Ü+Ý�Þ�ß�ß�Þ�ày�á�â"ã é�ì"ì"á2ä�á�Þ�âPä�Þv��Ü��1â"á2ä�á�Þ�â���ð � ß�á�ærá2ä�çyä�Û"Ü;ç�á�ê:ÜWà�á2ä�Û"Þ�ï|ä�è:Þ�ærí"å�Þ�ærá�ç�á�â"ã<å�Üeé�èUÛ1é��"ß�Üç�äUéVä�Ü:ç:ð� þ��f��������ÿ9������3 ¡E9"$0&,-�-C-C Ü{î|Ü:è:ï|ä�á�Þ�ârÞ�Ý�ò�á�ç�éWç�ä�Ü:írÜ{î|Ü:è:ï|ä�á�Þ�ârÞ�Ý�òÆÝ�ï"ßS�1ß�ß�á�â"ã+ä�Û"ÜÝ�Þ�ß�ß�Þ�à�á�â"ã»è:Þ�â"ì"á2ä�á�Þ�⢤£ Û"Ü:â"Ü�ë�Ü:å Z¦¥ xz§ ¥�¨ {J©3ª�ä�Û"Ü:âPä�Û"Ü:å�ÜWá�çhé�⤫�Úp¬Rò ­kx6òÄç�ï"èUÛ�ä�Û1éVä Z¦¥ xz®�­+é�â"ìä�Û"Ü:å�Ü;á�ç+é�â(é�è�ä�á�Þ�â Z dlxA§ ¥¯ ÷ °�®�­0ð  ç�ä�Ü:í¾Ü{î|Ü:è:ï|ä�á�Þ�âÃä�Û1éVä»á�ç�â"Þ�ä<é(í"å�Þ�è:Ü:ç�ç»Ü{î|Ü:è:ï|ä�á�Þ�âÃàLÞ�ï"ß�ì±�EÜrèUÛ1é�å�é�è�ä�Ü:å�á�ê:Ü:ì�Yñoä�Û"Ü<Ýöé�è�ä�ä�Û1éVä;á�âpç�Þ�ærÜfã�ß�Þ¦�1é�ß4ç�äUéVä�ÜfÜ�ë�Ü:å�ñ²«�Úp¬pí1é�å�ä�á�è:á�í1éVä�á�â"ãá�âÆé�âÆé�è�ä�á�Þ�â Z

àLÞ�ï"ß�ìv�EÜ�á�âré;ç�äUéVä�Ü�à�Û"Ü:å�Ü+á2ä�è:Þ�ï"ß�ì äUé�³�Ü�í"ßsé�è:Ü�ðf´¡ä�àLÞ�ï"ß�ìrâ"Þ�äqµYä�Û"Þ�ï"ã�Û�µn�EÜ+èUÛ"Þ�ç�Ü:âÝ�Þ�å»á�ærærÜ:ì"áséVä�Ü Ü{î|Ü:è:ï|ä�á�Þ�â�µJ�"ï|äfä�Û"ÜPå�Ü:ß�Ü�ë�é�âYäfè:Þ�æríEÞ�â"Ü:âYä�ç<àLÞ�ï"ß�ì¾å�Ü:æé�á�âÃá�ânä�Û"Üç�é�ærÜWç�äUéVä�Ü:çSÝ�Þ�å�ç�Þ�ærÜWç�ä�Ü:í"çQé�â"ì(Þ�â"ß2ñä�Û"Ü:â(Ü{î|Ü:è:ï|ä�Ü Z ðü»ý.þwÿ��0þ������/¶n·¸ ������Gv���pC��!�!E6�+*��-,�.��/�102�z057u"$�$�n, @ ����'wC������!� HF>�?�@ ���¤� @ ��"$�l�CB�E9"$0&,-�-C-CD�+*��-,�.��/�102�F��¹6"$�$�n, @ ����' H C�. , @ � @ ���p: ��¹�: a : ��G�: >~ ÿ��0ÿ9�/�����&�����/¶�¶º�»C������!�mc¼057 ò óÁôöòL÷0ø%ùeùeùVø�òjúYû �Cz"$�$�n, @ ���}#�A� �=� @ ��"$�z�C)�E9"$0&,-�-C-CD�+*��-,�.��/�102� H�÷�� LN H Ok���N ùeùeù ���N H TVd-WE÷1XtC�. , @ � @ ���fc ebH TVd-WE÷1X�7q02"kC&02��� <�>

´MâYä�ï"á2ä�á2ë�Ü:ß2ñWä�Û"ÜLí"å�Þ�è:Ü:ç�çjÜ{î|Ü:è:ï|ä�á�Þ�â"çjé�å�ÜLç�ä�Ü:í<Ü{î|Ü:è:ï|ä�á�Þ�â"ç%à�Û"á�èUÛfé�å�ÜLá�â»éQè:Ü:å�äUé�á�âèeé�â"Þ�â"á�èeé�ß�â"Þ�å�æé�ßVÝ�Þ�å�æ(ð�´Mâ;Ýöé�è�äqµeä�Û"á�ç�èeé�â"Þ�â"á�èeé�ß�â"Þ�å�æé�ßVÝ�Þ�å�æ è:Þ�å�å�Ü:ç�íEÞ�â"ì"ç.Ü{î"é�è�ä�ß2ñä�Þ�ä�Û"Ü�ç�Þ�èeé�ß�ß�Ü:ì�½1ÞYéVäUé�â"Þ�å�æé�ß�Ý�Þ�å�濾 À2Á"Ý�å�Þ�æ ä�Û"ÜSä�Û"Ü:Þ�å�ñfÞ�Ý�Âoé�ê:ï"å+³wá�Ü�à�á�è:êSä�å�é�è:Ü:ç}µé�â"ìré�ß�ç�ÞWä�Þ�é;í1é�å�ä�ásé�ß|Þ�å�ì"Ü:å�ç�Ü:æé�âYä�á�è:ç[Ý�Þ�å�ª��Mç�éVÝ�ÜsÃ4Ü�ä�å�á7â"Ü�ä�çyèeé�ß�ß�Ü:ìfí"å�Þ�è:Ü:ç�ç�Ü:ç:ðĽ1Þ�åærÞ�å�Ü�Þ�â�ä�Û"á�çSè:Þ�â"â"Ü:è�ä�á�Þ�â�µ1ç�Ü:ÜF¾ Å2Á.é�â"ì�Ý�ï"å�ä�Û"Ü:å�å�Ü�Ý�Ü:å�Ü:â"è:Ü:ç�ä�Û"Ü:å�Ü�ð

½%á�ã"ð[ªrã�á2ë�Ü:çWäMàLÞA«�Úp¬�ç}µ��EÞ�ä�Û�Û1éeë�á�â"ãRä�Û"Ü ë�á�ç�á�"ß�Üfé�è�ä�á�Þ�â"çw®%÷Wó�®�O<óÇÆ Z ¨-ÈqÉ ðÚSÛ"Ü�ñ»à�á�ß�ß��EÜhï"ç�Ü:ìé�ç[é�å�ï"â"â"á�â"ã�Ü{î"é�ærí"ß�ÜLà�Û"Ü:âfä�Û"ÜSÜ:ß�Ü:ærÜ:âYä�çjÞ�Ý7ä�Û"ÜhÜ:â"è:Þ�ì"á�â"ã;é�å�Üí"å�Ü:ç�Ü:âYä�Ü:ì�ðyÚSÛ"Ü;Ü:â"è:Þ�ì"á�â"ã é�ç�ç�ï"ærÜ:ç}µ"à�á2ä�Û"Þ�ï|äSß�Þ�ç�çhÞ�Ý%ã�Ü:â"Ü:å�é�ß�á2äMñ ä�Û1éVä�Üeé�èUÛRë�á�ç�á�"ß�Üä�å�é�â"ç�á2ä�á�Þ�â6á�çWã�á2ë�Ü:âÃéRï"â"áÊwï"Ü ßsé��EÜ:ß?ðD´MâÆä�Û"Üo�1ã�ï"å�Ü�µ.ä�Û1éVä;ßsé��EÜ:ßjá�çWã�á2ë�Ü:âÆä�Þ�ã�Ü�ä�Û"Ü:åà�á2ä�ÛRä�Û"Ü�é�è�ä�á�Þ�â�é�ç�ç�Þ�è:áséVä�Ü:ì�à�á2ä�ÛRä�Û"ÜWä�å�é�â"ç�á2ä�á�Þ�â�ð

Ë

Page 30: BMC’03 - JKUfmv.jku.at/papers/bmc03-preliminary-proceedings.pdfBMC’03 Boulder, Colorado, USA. ... Alessandro Cimatti (IRST, Italy) Raanan Fraer (Intel, Israel) Danny Geist (IBM

Ì2Í�Î+ÎRÏÑÐ�Ò�Ó&Ô�Ò�Ð�ÕÖ�×+Ø�ÙRÚUÛ Ü Ö9Ý�Ø�ÙRÞUÛÜßßßß àá ×$â1ã ä ä ä ä!å

á Ý�â1ã

æ

áÑç â1ã èáÑé â1ãÜÙ × ÜÙ Ý ÜÙ é

ä ä ä ä!åê

ßßßß à êëá Þ â�ì

èáÑí â�ìÜÙ ç ÜÙ í

î�ïÑð�ñ9òqñ�óÄônõnõnïöõ�ðu÷�ø�ù&úlû�üÑýþ ÿ������������� ������� ����

���������! �"#��$&%' �(*)+�+,.-�$&%!,�/�"102��%4365!�87!�:94$&�;02$294 ��&<=9>02�+,?02%A@�%!%'<*�B94 ?"+(*$&"+/�(C02�+DE����(*��&�+"102(*%' GF8H�94�&�+,I%' J02���?-�$&�+�&�+ K0#9>02(*%' I%43MLONQPSRTF8(* K02$&%!,�/�"+�+�M02���?"+%' �"+�+-U0A94 �,V02���94�&�&%!"+(=9>02�+,W02�+$&XY(* �%'<*%'Z4�'D�[]\_^S^>`*a2b4ced1fhg2d1i!fhjk(*�:9l,�(*$&�+"102�+,m94"1�!"+<*(*"�Z'$294-��on����+$&�02���k �%!,��+�894$&��"B94<*<*�+,qpKb4jra#s1Dt�����kZK9>02�+��"B94 AHu�k,�(Cv!(*,��+,w02%x02��$&�+�:"B9>02�+Z'%'$&(*�+�+yz fhc4{ui!j|pKb4jra#s602��9>0}��9Bv'�� �%~(* �"+%'XY(* �Z��+,�Z'�+�} �%'$}94 x94�&�&%!"+(=9>02�+,;@�%!%'<*�B94 k3�/� �"102(*%' GFz (* K02�+$&XY�+,�(=9>02��ZK9>02�+�M02��9>0l��9Bv'�oHu%402�I(* �"+%'XY(* �Z�94 �,I%'/U02Z'%'(* �Z��+,�Z'�+�A94 �,�94 94�&�&%!"+(=9>02�+,q@�%!%'<*�B94 M3�/� �"102(*%' A94 �,

z ^>i!jO{ui!j6pKb4jra#sxn�(C02�W(* �"+%'XY(* �Z��+,�Z'�+�:94 �,W94 o94�&�&%!"+(=9>02�+,W@�%!%'<*�B94 �3�/� �"102(*%' ?H�/U0 �%Y%'/U02Z'%'(* �Zx�+,�Z'�+�+D[]j�g�i!jh�o�>b4`Oi�b4j�fT^>c.3�%'$�9w"+(*$&"+/�(C0_n�(C02�WZK9>02�+����(*�k9�3�/� �"102(*%' ?��yu�����S02$&/��4F

3�94<*�&�>��D[�v494<*/�9>02(*%' w(*�;d#^>cUs1f*s1jra1c�j�n�(C02�w02���:"+(*$&"+/�(C0�(C3������U�������h�����K�2���B�B�B�1�&�����>�S�&�3�%'$�B94"#�w �%' !�r(* �-�/U0�ZK9>02�8�;n����+$&�k�l(*�t02���_@�%!%'<*�B94 �3�/� �"102(*%' M94�&�&%!"+(=9>02�+,Y02%E��94 �,�K���B�B�B�+�2�Q�E94$&�802���~ZK9>02�+��n�(C02���+,�Z'�+��02%E�|D�������d#^>cUs1j�g&b4fhc�a2 EsBb4j�f*s�¡�bK¢+fh`Ofhj�£�{ug2^'¢+`*a1¤3�%'$�@�%!%'<*�B94 Y"+(*$&"+/�(C02�(*�3�%'$&X;/�<=9>02�+,Y94�3�%'<*<*%Sn��+y}Z'(Cv'�+ Y02��9>0�ZK9>02�+��¥1¦W§V�¨X;/���0�Hu�02$&/���94 �,.¥B©e§ª�«X;/���0kHu�x3�94<*�&�4F¬(*�_02���+$&�Y9l"+%' ��&(*��02�+ K0kv494<*/�9>02(*%' q02��9>0k$&�+�&-u�+"102�02���+�&��"+%' ���02$294(* K02�+F4(TD �4DCF>(*�¬02���+$&�69��29>02(*��3h�!(* �Z�v494<*/�9>02(*%' |­Y������"+%' ���02$294(* ��+,E@�%!%'<*�B94 "+(*$&"+/�(C0Y�29>02(*��®|94H�(*<*(C0r��-�$&%'H�<*�+X¯(*�Y%'HKv!(*%'/��&<C�J°A±��r"+%'XY-�<*�102�l/� �,��+$�02���q-�<=94/��&(*H�<*�94�&�&/�XY-U02(*%' ¨02��9>0w�B94"#��@�%!%'<*�B94 ¨3�/� �"102(*%' J(* J02�������!��02�+X²"B94 IHu���1v494<*/�9>02�+,V(* -u%'<C�! �%'XY(=94<|02(*XY�4D�����x�+ �"+%!,�(* �Zw(* �02���;-�$&�+�&�+ K0kn�%'$&³?94-�-�<*(*�+�_@�%!%'<*�B94 �"+(*$&"+/�(C02�~n����+$&�;02���;3�%'<´�

<*%Sn�(* �ZE��0#94 �,�94$&,l@�%!%'<*�B94 Y3�/� �"102(*%' ��694-�-u�B94$�94��ZK9>02�+�+y�µ��� ��+ZK9>02(*%' |��F�¶I��,�(*�h·&/� �"��02(*%' |��F�¸¹��"+%' Q·&/� �"102(*%' |��Ft94 �,��º��(*XY-�<*(*"B9>02(*%' |��D�»r �94,�,�(C02(*%' Wn���/��&�w9A3�/� �"102(*%' "+$#¼½ ���K���B�B�B�+�2�>�S��n���(*"#�w(*�02$&/��_(* M9kv494<*/�9>02(*%' ��M(C¾l3�%'$�02���~"B94$&,�(* �94<*(C0r��¥�%43G02���~�&�10�S�����U�k�¿02$&/��WÀu�mÁ��Q�K�1�B�B�B�+�2�>�Q�K�w��%'<*,��k02��9>0EÂÄÿ¥wÃÆÅ¿n����+$&�MÂ�94 �,eÅÇ94$&�®UÈU�+,?"+%' ���0#94 K02��ÉwÃ�Â�êÅED_�����E3�/� �"102(*%' q"+$ ¼½ $&�+-�$&�+�&�+ K02�k94"102/�94<*<C�A9Y3�94XY(*<C�w%433�/� �"102(*%' ��%43Gn���(*"#�Y02����3�%'<*<*%Sn�(* �Z_0rn�%E3�%'$&XY�94$&�8/��&�+,M(* �02���8-�94-u�+$+y�"+$ �Ê ��9>0�XY%'��0%' ��_02$&/��S��94 �,A"+$ �� ����È�94"102<C�w%' ���02$&/��S��D

Ë Ì _�¬��Ík �_Î

����(*�~�&�+"102(*%' �-�$&�+�&�+ K02�_02���;��02$&/�"102/�$&�;%43t02���x@�%!%'<*�B94 A"+(*$&"+/�(C02�~�+ �"+%!,�(* �Z�02���E��02�+-94 �,A-�$&%!"+�+�&�~��ÈU�+"+/U02(*%' ��8%43}02���:���! �"#��$&%' �(*)+�+,�-�$&%!,�/�"108%43�Ï.5!�87!�+D6Ð�%'$�$&�+-�$&�+�&�+ !�0#9>02(*%' �94<t-�/�$&-u%'�&�+�E02����ZK9>02�+�:02��9>0;94-�-u�B94$;94$&��Z'(Cv'�+ ."+�+$�0#94(* m(*<*<*/���02$29>02(Cv'�x �94XY�+�

Ñ

Page 31: BMC’03 - JKUfmv.jku.at/papers/bmc03-preliminary-proceedings.pdfBMC’03 Boulder, Colorado, USA. ... Alessandro Cimatti (IRST, Italy) Raanan Fraer (Intel, Israel) Danny Geist (IBM

Ò>Ó!Ô&Ô�ÕOÖ1×�ØSÙ�×!Ö4Ú

Û�Ü&Ý*Þ1ß�àlÞ�áUâ�ã=ä4Ý*å�Þ+æqÝ*åqç}ä4Û�ã*ÞYè'é�ê~å�Ý*å!ëræ�Þ+âUì2íqæ�Þ+î&ï+Ü&Ý*âUì2Ý*ð'åqð4ñ�ì2í�Þ+ò]ñ�ð'ã*ã*ðSó�î�Ý*åqî&ô�Û!ëî&Þ+õ�ô�Þ+åKì�î&Þ+ï1ì2Ý*ð'å�îEó�ÝCì2ímÜ&Þ1ñ�Þ+Ü&Þ+å�ï+Þ+îxì2ðqö�÷'ô�Ü&Þ+îxð4ñ�÷Kä>ì2Þ+îEæ�Ü2äBó�å�ñ�Ü&ð'òøì2í�ÞMÜ&ô�å�å�Ý*å�÷Þ�á�ä4òYâ�ã*Þ4é

ù�úBû!üOýkþùuÿ�ú�����ü´ú���������ÿ�ý� ����#ú��rý��

������� ����������� � ��� !#"$&%�')(+*-,-. / �0��� !#" ( � ���01 ����2 ����34������� 56� ,87 � "9�92 �;:������#<=)> '?#*-,-. @ 1 ����2 ��� !#"A� ��� "B�-�8����� ? ������� 56� , <?&CD')E�*-,-. F !#56��!#"9��"�� E ���8G9��3929H ��3I������� 56� , <$&%�')J*-,-. K �8�D"9��� ��� !#" J � ���01 ����2 ����34������� 56� , <L�M+')E�*�,-. N "9� OP29��Q � ��� R9H �����8�D"9��� ��� !#"BS ��!#5 E ���;��� 56� , <>T= ' ,-. ��� �8�DR9H ��� 39H � "9:U������� 56� , <$ >�VDW ')(+*-,-. @ 1 ����2 ��� !#"A!DSX�D�0��� !#" ( � 56�9H � ���Y��G+����� ��� ����"+�DR9H ��3I������� 56� , <$ > ')(+*�,-. / �0��� !#" ( � ����"+�DR9H ��3I������� 56� , <

ç�í�ÞMÞ+å�ï+ð!æ�Ý*å�÷?ä4î&î&ô�òYÞ+î;ì2í�ä>ìEì2í�Þ[Z!ç]\!î;æ�ð�å�ð4ìxí�ä�^'ÞMã*ð!ð'â�îEï+ð'åKì#ä4Ý*å�Ý*å�÷qð'å�ãCà_ ë�ì2Ü2ä4å�î&ÝCì2Ý*ð'å�îxÝ*å`^'ð'ã-^!Ý*å�÷WòYð'Ü&ÞMì2í�ä4å¨ð'å�Þlî�ì#ä>ì2Þ4éba�ñ~ì2í�ä>ìYÝ*îxì2í�ÞAïBä4î&Þdc�ì2í�Þlï+ð'Ü&Ü&Þ�ëî&âuð'å�æ�Ý*å�÷;ï+ð'òYâuð'å�Þ+åKì�ïBä4ålÛuÞ_â�Ü&Þ+â�Ü&ð!ï+Þ+î&î&Þ+æAî&ð;ì2í�ä>ì6ì2í�Þ�Ü&Þ+î&ô�ãCì2Ý*å�÷�Z!ç]\�î&Ý*ò;ô�ã=ä>ì2Þ+îä4ã*ã|ì2í�Þ_Þ�áUÞ+ï+ôUì2Ý*ð'å�î�ð4ñ�ì2í�Þ_ð'Ü&Ý*÷'Ý*å�ä4ãTé�ç�í�Þ�â�Ü&Þ+â�Ü&ð!ï+Þ+î&î&Ý*å�÷�î�ì2Þ+âlï+ð'òYâ�ôUì2Þ+î6ì2í�Þ_ò�äQáUÝ´ëò�ä4ã¬î�ì2Ü&ð'å�÷'ãCàlï+ð'å�å�Þ+ï1ì2Þ+æ?ï+ð'òYâuð'å�Þ+åKì2îfe = ð4ñ�ì2í�ÞgZ!ç]\AÜ&Þ+î�ì2Ü&Ý*ï1ì2Þ+æqì2ð _ ë�ì2Ü2ä4å�î&ÝCì2Ý*ð'å�îä4å�æJÜ&Þ+â�ã=ä4ï+Þ+îMÞBä4ï#íhe = ó�ÝCì2íVä.î&Ý*å�÷'ã*Þqî�ì#ä>ì2Þ�í�ä�^!Ý*å�÷�ä4îMÝ*å�ï+ð'òYÝ*å�÷.ä4å�æVð'ôUì2÷'ð'Ý*å�÷ì2Ü2ä4å�î&ÝCì2Ý*ð'å�î�ì2í�Þkô�å�Ý*ð'ålð4ñ�ì2í�ð'î&ÞkÝ*åwì2í�Þkî&Þ1ì8ð4ñ�î�ì#ä>ì2Þ+î�Ý*åie = éç�í�Þ;Ü&Þ+â�Ü&Þ+î&Þ+åKì#ä>ì2Ý*ð'å�ñ�ð'ã*ã*ðSó�î8ï+Þ+Ü�ì#ä4Ý*å�ï+ð'å`^'Þ+åKì2Ý*ð'å�î+ékç�í�Þg^4ä4Ü&Ý=ä4Û�ã*ÞkjAÝ*î~ô�î&Þ+æ?ì2ð

æ�Þ+å�ð4ì2ÞMì2í�Þwã*Þ+å�÷4ì2í�ð4ñ�ì2í�ÞwÞ�áUÞ+ï+ôUì2Ý*ð'åeä4å�æ�ì2í�Þl^4ä4Ü&Ý=ä4Û�ã*Þ+î�mYcIn�cpo.ä4å�ærq8ä4Ü&Þwô�î&Þ+æì2ð;æ�Þ+î&ï+Ü&Ý*ÛuÞkä4Ü&Û�ÝCì2Ü2ä4Ü�à�î�ì#ä>ì2Þ+îTc�âuð'î&ÝCì2Ý*ð'å�î�Ý*å�ì2í�Þ_Þ�áUÞ+ï+ôUì2Ý*ð'åUc�ä4ï1ì2Ý*ð'å�î�ä4å�æMì2Ü2ä4å�î&ÝCì2Ý*ð'åã=ä4ÛuÞ+ã*îTcKÜ&Þ+î&âuÞ+ï1ì2Ý-^'Þ+ãCà'é4s6ä4î&Þ+æMð'åYì2í�Þ~æ�Ý-^!Ý*î&Ý*ð'å�ð4ñ¬÷Kä>ì2Þ+î�÷'Ý-^'Þ+åMÝ*ål\!Þ+ï1ìBé�t�c�ì2í�Þ8ï+Ý*Ü&ï+ô�ÝCìÝ*î�ï+ð'òYâuð'î&Þ+æxä4î�ñ�ð'ã*ã*ðSó�î+évu}Ý*Ü&î�ì2ãCàYc>î&ð'òYÞ�÷Kä>ì2Þ+îTc'å�ä4òYÞ+ãCà�ì2í�ð'î&Þ�ã=ä4ÛuÞ+ã*ã*Þ+ækó�ÝCì2í�wTxvy&o{z n |ä4ï1ì}ä4î�Ý*å�â�ôUì2î+é�ç�í�Ý*î�î&âuÞ+ï+Ý=ä4ãKÜ&ð'ã*ÞtÝ*î�ò�ä4Ü }4Þ+ækó�ÝCì2í�ìró�ð~ï+ð'å�ï+Þ+åKì2Ü&Ý*ï�ï+Ý*Ü&ï+ã*Þ+î+éA\!Þ+ï+ð'å�æ�ãCàYcì2í�ÞYã=ä4ÛuÞ+ã*î~wTxvy0n��z n |:ä4å�æ�m��dy&��z n |�ä4Ü&Þ�ä>ì&ì#ä4ï#í�Þ+æ.ì2ðAÝ*åKì2Þ+Ü&òYÞ+æ�Ý=ä>ì2Þ�÷Kä>ì2Þ+î+éMç�í�Ý*Ü&æ�ãCàYcì2í�Þk÷Kä>ì2Þ+î�����y&��z n |6ä4å�æi���+y0n |�ä4Ü&Þkð'ôUì2â�ôUì2î�ï+ð'å�î�ì2Ü2ä4Ý*å�Þ+ælì2ðxì2Ü&ô�Þ4éç�í�Ý*î�Ý*î�Ü&Þ1ß�Þ+ï1ì2Þ+æÝ*åqì2í�Þ;ö�÷'ô�Ü&Þ+îkÝ*åqó�í�Ý*ï#í?ì2í�Þ1àWä4â�âuÞBä4Ü_ÛKàqì2í�Þxî�à!ò;Ûuð'ãI�Æä4â�âuÞBä4Ü&Ý*å�÷wð'å�ì2í�ÞxÜ&Ý*÷'íKìî&Ý*æ�Þ�ð4ñ�ì2í�Þk÷Kä>ì2Þ4éç�í�Þ�÷Kä>ì2Þ+î6ã=ä4ÛuÞ+ã*ã*Þ+æ����Iy�mYz n |�ïBä4ålä4â�âuÞBä4Ü6Ý*åwæ�Ý-��Þ+Ü&Þ+åKì�Ü&ð'ã*Þ+î6Û�ä4î&Þ+ælð'åMì2í�Þf^4ä4ã*ô�Þ

ð4ñ�n�é��kä>ì2Þ+î;æ�Þ+î&ï+Ü&Ý*Û�Ý*å�÷qì2í�ÞMÝ*å�ÝCì2Ý=ä4ãtî�ì#ä>ì2Þ+îTctÝTé Þ4é����Iy�mYzBè|Eä4Ü&Þ�Ý*å�â�ôUì2î;ï+ð'å�î�ì2Ü2ä4Ý*å�Þ+æì2ð�ì2Ü&ô�Þlä4å�æmñ�ä4ã*î&ÞMæ�Þ+âuÞ+å�æ�Ý*å�÷Wð'åmó�í�Þ1ì2í�Þ+ÜYä?î�ì#ä>ì2Þ�mlÝ*îxä4å�Ý*å�ÝCì2Ý=ä4ãî�ì#ä>ì2Þwð'Ü;å�ð4ìBéu�ð'Ü�âuð'î&ÝCì2Ý*ð'å�îkè���n]��jlì2í�Þ:÷Kä>ì2Þ+î_ä4Ü&Þ:Ý*åKì2Þ+Ü&òYÞ+æ�Ý=ä>ì2Þ:ä4å�æqñ�ð'Ü�ì2í�Þkö�å�ä4ã�âuð'î&ÝCì2Ý*ð'åUcÝTé Þ4é-c4���Iy�mYz�j�� è|:ì2í�Þ1à�ä4Ü&Þwð'ôUì2â�ôUì�÷Kä>ì2Þ+î+é��Ií�Þ+å�ì2í�ÞMì2Ü2ä4å�î&ã=ä>ì2Ý*ð'åmî&ï#í�Þ+òYÞAÝ*îä4ô�÷'òYÞ+åKì2Þ+æMó�ÝCì2íwä;ï+Ý*Ü&ï+ô�ÝCì�æ�Þ1ì2Þ+ï1ì2Ý*å�÷xÜ&ÞBä4ï#í�ä4Û�Ý*ã*ÝCìràYâ�Ü&ð'âuÞ+Ü�ì2Ý*Þ+îTc!ì2í�Þ+î&Þ�÷Kä>ì2Þ+î�ä4Ü&Þ_ÝCì2îÝ*å�â�ôUì2î+é�ç�í�ÞEñ�ð'ã*ã*ðSó�Ý*å�÷�î&ô�Û�î&Þ+ï1ì2Ý*ð'å�î_â�Ü&Þ+î&Þ+åKì_ì2í�ÞEÜ&ÞBä4î&ð'å�Ý*å�÷Yñ�ð'Ü_ä4ã*ãGì2í�ÞE÷Kä>ì2Þ+î_ä4å�æì2í�Þkî&Þ+ï1ì2Ý*ð'ålÝ*î�ï+ð'å�ï+ã*ô�æ�Þ+æqÛKàläxï+ð'òYâ�ã*Þ1ì2Þ_ì2Ü2ä4å�î&ã=ä>ì2Ý*ð'ålä4ã*÷'ð'Ü&ÝCì2í�òAé

Page 32: BMC’03 - JKUfmv.jku.at/papers/bmc03-preliminary-proceedings.pdfBMC’03 Boulder, Colorado, USA. ... Alessandro Cimatti (IRST, Italy) Raanan Fraer (Intel, Israel) Danny Geist (IBM

�X�;� �P��¡ �¢�£¤ ;�d¥¦¨§0© ªp«X¬{­&®9«X¯¨°4¯�«X±²{³Y´¶µT·�¸T³;¹�º�·�»�¼9½�µ¾¸T³Y·`¼9´ ³Y¿IÀ{³�Á³dÃļ9½�µ�Å;Æ]Ç;È~¼9½�µ¾º�¹�µ�É�º�ȶ¼9½{ÉX¼~¼9½�µ¾Ê�ËIÌ�ÍYÎ Ï Ð¶»`ÉX¼9µTÈÈ µT´PÑYµ�¼9³�Ò�´ ³�Ñ;º�¹�µ�º�·�Ã�³Y´ Ó�ÉX¼9º�³Y·Ô´ µT»`Éd´ ¹�º�·�»Õ¼9½�µ�Ò�´ ³Y»Y´ µTÈ Èl³dÃ~µ�Ö�µT¸T×�¼9º�³Y·UØÙ²{³Y´lÉd·`Úº�·�º-¼9º8Éd¿�ÈP¼+ÉX¼9µgÍ~³dÃvÉd·iÅ;Æ]Ç[Ê�ËIÌ�ÍYÎ�ÛÐܺ�È�Éd·�º�·�Ò�×�¼�»`ÉX¼9µ~Éd·�¹�º�È�ÉdÈ È µT´P¼9µT¹i¼9´ ×�µdØIÆ�½�º�È�º�Ⱥ�·kÉd¸T¸T³Y´ ¹{Éd·�¸TµÜÁ�º-¼9½g¼9½�µpÃ&Éd¸¡¼v¼9½{ÉX¼Aº�·Ý¼9½�µÄ³Y×�¼9È µ¡¼A¼9½�µÜµ�Ö�µT¸T×�¼9º�³Y·�º�·gµ�Éd¸+½�¸T³YÓ¾Ò¨³Y·�µT·`¼º�Èܺ�·¾¼9½�µfº�·�º-¼9º8Éd¿{ÈP¼+ÉX¼9µTÈTØ4Þ#·[»YµT·�µT´9Éd¿�ß�¼9½�µfµ�Ö�µT¸T×�¼9º�³Y·[Ó�É�Ú�ਵáº�·lÈ ³YÓ¾µáÈP¼+ÉX¼9µ¶ÉX¼Ä¼9º�Ó¾µÏ6âãÛ~º-äå³Y·�µ~³dÃB¼9½�µ¶Ã�³Y¿�¿�³�Á�º�·�»k¸�ÉdÈ µTÈ]º�Èļ9´ ×�µdØæ Æ�½�µÝÈP¼+ÉX¼9µ¶ÁÄÉdÈ�´ µ�Éd¸+½�µT¹�Éd¿�´ µ�Éd¹�Ú[ÉX¼�Ï�Éd·�¹i·�³d¼�¿�µ¡Ã0¼�º�·�ÈP¼9µTÒ�Ï�Øæ Æ�½�µçÈP¼+ÉX¼9µåº�È[´ µ�Éd¸+½�µT¹è¹�×�µ�¼9³Ôº-¼[ਵT¿�³Y·�»Yº�·�»�¼9³�¼9½�µåé;ê#¸T¿�³YÈ ×�´ µå³dÃgÈ ³YÓ¾µ�ÈP¼+ÉX¼9µ´ µ�Éd¸+½�µT¹iÑ;º8ɤÉd¸¡¼9º�³Y·�È�º�·�ÈP¼9µTÒ�Ï�Øæ Æ�½�µlÈP¼+ÉX¼9µ�º�ÈÝ´ µ�Éd¸+½�µT¹Ôà`Ú�¼+Édë�º�·�»ìÈ ³YÓ¾µ�³dÃ�º-¼9Èݺ�·�¸T³YÓ¾º�·�»�Ñ;º�È º�à�¿�µ�¼9´9Éd·�È º-¼9º�³Y·�Èݺ�·ÈP¼9µTÒiÏ�Ø

Æ�½�º�ÈIÒ�´ ³�Ñ;º�¹�µTÈI¼9½�µ�à{ÉdÈ º�ÈAÃ�³Y´v¼9½�µ�¹�µ¡í{·�º-¼9º�³Y·�³dÃ�¼9½�µ�»`ÉX¼9µÄÊ�ËIÌ�ÍYÎ Ïdâ�ÛÐIÉd·¤º�·�ÈP¼+Éd·�¸Tµ³dÃ�Á�½�º�¸+½gº�Èî·�µTµT¹�µT¹gÃ�³Y´BÉd¿�¿d¼9½�µp¿�³;¸�Éd¿YÈP¼+ÉX¼9µTÈBÃ�³Y´BÉd¿�¿dÑdÉd¿�×�µTÈ4ÛÝïbÏÄïhð¨ØBÆ�½�µÜÈP¼9´ ×�¸¡¼9×�´ µ³dè¼9½�µ]»`ÉX¼9µ�º�È4»Yº-ÑYµT·�º�·¾²vº�»�Ø�ñ¶Ã�³Y´A¼9½�µ]ÈP¼+ÉX¼9µfÍ�òܳdÃ�¼9½�µ�´ ×�·�·�º�·�»Ýµ�Ö�ÉdÓ¾Ò�¿�µdØAÞD¼pÈ ½�³Y×�¿�¹à¨µ¶·�³d¼9µT¹�¼9½{ÉX¼�é;êD¼9´9Éd·�È º-¼9º�³Y·�ÈÜÃ�´ ³YÓóÉ�ÈP¼+ÉX¼9µ¶¼9³¤º-¼9È µT¿-ÃB¸�Éd·ÕÌ&Éd·�¹�È ½�³Y×�¿�¹�ÐÜਵ~º�»Y·�³Y´ µT¹º�·l¼9½�µ~¹�µ¡í{·�º-¼9º�³Y·UØ ô�õö ÷�ø ù8ú�û-ü9ývþ�ÿ

� � �� � � ���

������� ��ô

�ô õ ô õ

�� ��

� � � �� � � � � �� �ôö ÷�ø ù� Dû-ü9ýBþ�ÿ

ôö ÷�ø ù���û-ü9ýBþ�ÿ

ô��� ø � ú#û-üÿ

ô��� ø � �Pû�üÿô

ö ÷�ø ù8ú�û�üÿ

ô�ô

ù��&ø �� Dû�üÿ�������! "�$#&%(')�)%(*,+(+-').$/0'21435%('267��6�'98

Æ�½�µì¹�µ¡í{·�º-¼9º�³Y·rÓ�ÉdëdµTȾ×�È µì³dÃf¼9½�µ�Í):dÌ<;�Î Ï Ð¤Éd·�¹>=�?vÌ<@#Î Ï Ð�»`ÉX¼9µTÈTØ�Æ�½�µiÃ�³Y´ Ó¾µT´¸�ÉdÒ�¼9×�´ µTÈݼ9½�µ¾Ã&Éd¸¡¼Ý¼9½{ÉX¼�Éi¸T³YÓ¾Ò¨³Y·�µT·`¼A; º�ÈÝÈ ¸+½�µT¹�×�¿�µT¹Ôº-ärÉ�Ñ;º�È º�à�¿�µ¾Éd¸¡¼9º�³Y·Õº�·Õº-¼9ÈÉd¿�Ò�½{Édਵ¡¼�º�È�µ�Ö�µT¸T×�¼9µT¹UØÆ�½�µÜ´ µ�ÉdÈ ³Y·�º�·�»]ਵT½�º�·�¹Ý¼9½�µp¿8ÉX¼ ¼9µT´Tß�¼9½�µB=�?vÌ<@#Î Ï Ð6»`ÉX¼9µdßXº�ÈvÉdÈîÃ�³Y¿�¿�³�Á�ÈTØ&CÔ¼9´9Éd·�È º-¼9º�³Y·º�È6¼9´9É�ÑYµT´ È µT¹�º�·gÒ¨³YÈ º-¼9º�³Y·¶Ï6º-ä�¼9½�µÄÉd¸¡¼9º�³Y·Ýº-¼Bº�ÈB¿8ÉdਵT¿�µT¹~Á�º-¼9½Ýº�ÈBµ�Ö�µT¸T×�¼9µT¹�º�·gÒ¨³YÈ º-¼9º�³Y·¶ÏÉd·�¹Ý¼9½�µp¸T³Y·`¼9´ ³Y¿`À{³�ÁÔº�Èîº�·Ýº-¼9ÈBÈ ³Y×�´ ¸TµÜÈP¼+ÉX¼9µdØvÞD¼vÈ ½�³Y×�¿�¹gਵp·�³d¼9µT¹Ý¼9½{ÉX¼B¼9½�µp¹�µ¡í{·�º-¼9º�³Y·º�Èf·�³d¼~¸Tº�´ ¸T×�¿8Éd´TßUà�×�¼¶¼9½�µ¤¸T³Y·`¼9´ ³Y¿vÀ{³�Á º�·åÒ¨³YÈ º-¼9º�³Y·ìÏá¼9³Y»Yµ¡¼9½�µT´fÁ�º-¼9½å¼9½�µ�µ�Ö�µT¸T×�¼9µT¹¼9´9Éd·�È º-¼9º�³Y·�È�¹�µ¡í{·�µÝ¼9½�µg¸T³Y·`¼9´ ³Y¿6À{³�ÁÙº�·ìÒ¨³YÈ º-¼9º�³Y·[ÏBâhÛYØ�Æ�½�µgÒ�º�¸¡¼9×�´ µÝ³Y·i¼9½�µg´ º�»Y½`¼

ôDE<FHGJI þHKMLMN

� �� � �

���� �

OôP<QRGJS K�LMN

OôP<QRGJT KMLMN

ôP<QRGJU V K�LMNXW

� ��� �

���� �

OôP<QRGJT KMLMN

ôYJZ G�E\[ K�LMN

ôF^] þ_`,abGJI þ5K�LMN c

� ��� �

���� �

OôP<QRGJS KMLMN

OôP<QRGJT K�LMN

ôDZ�Y G LMN c

� �� � �

���� �

ôO

P<QRGJS K�LMNôOP<QRGJT KMLMN

�������ed"�$f$6�*,gh*,143(+-iH6j6jkl+535%nmR3(�j1��of$1lpq'srl�j1��o.�%('2gutvkl1l1l�j1��ofxw�m)ghye6�*z

Page 33: BMC’03 - JKUfmv.jku.at/papers/bmc03-preliminary-proceedings.pdfBMC’03 Boulder, Colorado, USA. ... Alessandro Cimatti (IRST, Italy) Raanan Fraer (Intel, Israel) Danny Geist (IBM

{4|e}~}n���9���)���e�"������0�������A���������n�q�q�4�q�����q�������4�q�o���s�B�q���h�q�q�"���~�M�q���s�����������q�����~�������������, ��"¡£¢����"�

¤ �h�<�"��¥"�q���¦�~��§©¨����~¨����M�q�-¢��~���~�����q��ª����R«s�¬§©�����£ª��9­����M�q���s���®�"�©�q���¦������¡£�����q�-���~��ª���¯�q���°����¨��eª��������h±$���"¨b�����9«s�A¨��s�~�~���~¢©�s��ª�����¨��A²¬�M�q�³�n�q��¢´�"��ªµ���4�q���¶¢��~�e¨����~�h�, !�,·¨��!�q���s���v�"ª�ª��M�q���s���"��¨��s���n�q�q�"�����q�¸������ª��q�¹§©����¡£¢©�s�~��ª��0º»�n�q��¢µ¼�¢��~�e¨����~�b½¸�, !��¨��!�q���s����"�B�q���h¢��~�s¢©���n�5¾��q���4�¬�s���M¾X�A�~�����s����«e���~��§����h�"¨9�q���s�����¦�"�����)²���ªX�q�°�b�"¿"��¢����"¨��o������~�����s���h¨��s¡£¢©�s�����������¯�R�"¨b�À�n�q��¢��B±¦���Á�"�~�q�"���s��¡£�����¬�q�£���"��ª����h�q�����¬���¬§�¾����~�������¨R�"�~ª������"���M�5¾Á¨��s���n�q�q�"�������"�~�~���n�q��ª£�q�~���"�®º¶�£�����n�b�"��¨������-�s�M«s���£���£�0��������¼^�q���¬�~��¨��s��ª�s���o���~�s¡Â�q�����~���s���,½,�

±¦��������¨��eª������À¡��R¾Ã§©�������n�q�����Á�������"��¨���ªÄ²¬�M�q�Ä�¯���4�q���q���4�°ª����q�"§������¹��ª����������Å ���~��¨b�Ä�����4�q�A�������"�¹�"ª�ª���ª�¥&�q�����~���~���M�q������¨����~¨����M�h����¨��eª����¹�n�q��¢Æ�, !��¨��!�q���s���¹��¢�q�¯Ç¯²¬�����~�R�"�h²¬�M�q�µ�M�¶�q���A�, !��¨��!�q���s���¹�"�~�°�"�v¢��~��¨����~���M¾³�������"�q�ÃÇ©�¹±¦�l���h�q���°���4�q�����¡£�M�q�A�q���´�~�R�"�~¨b�»�~¢��"¨��"�Ⱥ¶���ɪ��)²¬���~��ª��´�~���s�n��ª��R�"ª����e¨b¿l��¡��R¾Ê§©�µ¡£���~�~��ª>�M��q���A«s���~�M­�¨R�4�q���s�´¢��~�e¨����~�¹���h�n�b�"�n�q��ª´²¬�M�q�µ�q�e�����"�~�s�A��§©�s����ª�� Å ª������������hª����q�"§�����ª�MËÊ�~�s¡£�X«e���~��§������"¨9�q���s�É���A�, !��¨��!�q��ª�¥����s�°�q�����~�����������µ�, ��"¡£¢����X�q�������4�q�����°�q����~���s���q¡£�s�n�¦���¯�0�������!�

Ì©Í�ÎÐÏ7Ñ4ÒÔÓbÕeÖq×4Ò�ØMÙ)Ú"Û<Ø\×4Ò±¦���h�n¾e��¨b���~�s����ÜR�4�q���s���"�0Ýe± ¤ �¦¡��"��ª��4�q���B�q���4�¬�Á«e���~��§����o�"¨9�q���s�X¡��R¾�§©�h�, !��¨��!�q��ª�MË��9«s���n¾XÝe± ¤ ²¬���s�~�¶�"��¢����"§©�9�v¨��s���b�"�����¸�q���¶�"¨9�q���s�£¢��"�n�q��¨���¢��4�q����� ¤ �¹�<�"��¥��q�����¸���"����"�¶§©�����³�~�9Þ���¨9�q��ªµ�����q���Á�~��§©¨����~¨����M�q�¶¨��s���b�"�����������q���¹����¢��!�¶���4�q���oß�à0¼<á�â~ã~½,�¬±¦���¨��s��ª��M�q���s�µ���h��¡£¢�����¡£�����q��ªµ§�¾´ª���¡��"��ª��������q���4�h�q�����, !��¨��!�q��ªÉ�"¨9�q���s�´���h�����"§�����ª���À�R�"¨b�´¨��s¡£¢©�s�������o���R«e�������q���4�h���"§©���&���³�M�q�o�"��¢����"§©�9�R�¶º¶�´�"¨9�q���s�³á����¶�����"§�����ª���³�X¨��s¡£¢©�s�������o�MËÆ�M�¶���o���À�~�s¡£�°�n�b�4�q�Á²¬�M�q�µ�"�µ�s�!�q�s�s�����£�q�q�"���~�M�q���s�À���"§©��������ªÀá��±¦�����~�M�q���4�q���s�X���s�B�q�����~�������������, ��"¡£¢����h���¦���������n�q�q�4�q��ª����¯�0�����!ä��

å�æç<èRéHê9ëJìbíMîMï ðñ ññ ñ ò

óóóó ô

õåç<öRëJìbíMîMï

å4÷

ñ ñññ ò

óóóó ô

åç<è4ëJìbí�ølùHí�îMï

åç<è4ëJìbí�øsúníMîMï

å,ûç<è4ëJìbí�ølùHí�îMï ü

åý è4ë�þ<ÿ~íMîMï

å ðæ���~ë��\í�îMïñ ññ ñ ò

óóóó ô

õåç<öRë��\íMîMï

å û

ñ ñññ ò

óóóó ô

åþ��HëJø"ÿ~íMî��\ï

åþ��HëJølùHí�î���\ï

�� ��������������������! � "�� "���#�%$�&�'(��)+*��-,. /��&0�#132�&�45��6�78 "9�9�2�&�:; ���9=<>��45���!?� "���.@A?!$�&09�*�2" "���B15�! ���$C�D:

Ì©Í3E F�Ö~Ú"Ò;GIHMÚ"Û<Ø\×4ÒKJBH Ll×4Ö,Ø^Û^Õ+MONR×4ÖhÏ7Û�P�QSRUT+PbÓIVeÛ<Ø\×4Ò;Gº¶�~�~��¡£�XWZY ¼�W �[�\�\�\�[ W è ½A�"��ª �´�s�M«s��� §©�s����ª Ç©� ±¦����� �q���¯�"���s�s�~�M�q��¡ ¨��s�e·�n�q�~��¨9�q�����Ã�^]��e�s���R�"�ɨ����~¨����M������¨��eª������Ã�n�q��¢ �, !��¨��!�q���s���£�"�_W �"�¶�������"�q�ÊÇÉ�����"����s�����)²¬��`¼��^½X±$��¨R�"¢!�q���~�Á�q���Á�~��al�����~��¡£�����o�q���4�¶�R�"¨b�bW ý ���¶���¯�q���dce·5¨����s�~���~�Á�"�¸�M�q�������M�q���"��n�b�4�q�������^e �"ª�ªµ�q���A���4�q�gfih-¼ijsâ/k2½����s���"���0�n�b�4�q���lj£�"��ªÃ¨��s���n�q�q�"���µ�q����¡ �q�

�q�~���h�M�$�q���¹�"§©�)«s��¨��s��ª��M�q���s�����s��ª����"��ª��<�"���~�h�"�q�����n²¬���~�"�m

Page 34: BMC’03 - JKUfmv.jku.at/papers/bmc03-preliminary-proceedings.pdfBMC’03 Boulder, Colorado, USA. ... Alessandro Cimatti (IRST, Italy) Raanan Fraer (Intel, Israel) Danny Geist (IBM

nCo+pDp!q�rIsut�vws+ryxz|{/}�~5�#�K���� �

�� �� zz� ���� �����C���A�#�"���B�I�� �C�A�"���=�I����� ~3�#�X�y�  z ¡z ¡z � � � �

z z z z ¢£~3�¤�X�y�� � � ��� ��¥¤¦ ~¨§y©(���  z ¡z ¡z ªA« �A�#�"���¬®­ ��¯��°>± ��¯��

�� ��� � ��� z ¡z ¡z� � � �z z z z ¢£~3���� � � �

z z z z ¢£~�²��� � � ��� ��¥¤¦ ~¨§y©!���  z ¡z ¡z ªA« �A�#�5�I�¬®­ �¨³i�°>± �¨³i�

�� ��� � ��� z ¡z ¡z� � � �z z z z ¢£~i�y�

´�µ�¶�·+¸y·U¹Aº!»�¼0½8¾/¿%µ"ºÀ.µ"¾/¶�Á!¾�½ÃÂ�Ä�¿%»�¼BÅUµ�Á!º�Æ�µ�¿

Ç�È5ÈÊÉÌË�ÍAÎ�ÏyÐ5Ð�ÑÒÍAÓDȨÔ�È5ÍAÕ®Ó=Ö8×ÙØ.×ÛÚÒÜ�ÏyÝ®ÝÞÔ�ß®à_á�ÍAÐ5Ð5Í�âÈ5Õ®ãäÓDå®æÒç�È5ÎDç�å®È¨Ô�Ó�èÇ�Ï�ÉÞË�ÍAÎ.ÏyÐ5ÐÒÓ!Ô�ÏCÔ�à�Óédêbë ³Òìîí/í/íIì ëÒï;Ü;È5Õ®ç�Ð5å®Ý®àðÔ�ß®à_ÓDå®æÒç�È5ÎDç�å®È¨Ô£á�ÍAΣñiò¤ÇiéAóDØÒôõÖ�É0öÇ�æ÷ÉÞË�ÍAÎÏyÐ5ÐÒÔ�ß®à8ç�ÍAøùÑÒÍAÕ®à�Õ�Ô�Óðú�û�Ü÷ÏyÝ®ÝKÔ�ß®à8ÓDå®æÒç�È5ÎDç�å®È¨Ô�á�ÍAÎðé�üyÇ�ú�û�óDØDÉ0öÇ�ç�ÉÞË�ÍAÎwÏyÐ5ÐýÔ�Î�ÏyÕ®ÓDȨÔ�È5ÍAÕ®ÓäâȨÔ�ßÿþ+È5ÓDÈ5æ®Ð5àÞÏyçIÔ�È5ÍAÕ®Ó��gê�� ³£ì í/í/í;ì �äï®Ü£ÏyÝ®Ý Ô�ß®àÓDå®æÒç�È5ÎDç�å®È¨Ô�á�ÍAÎ�����Ç���óDØDÉ0öÇ�Ý÷ÉÞË�ÍAÎ.à/Ïyç�ß��� Þú�û�Ü�ÏyÝ®ÝÞÔ�ß®à_ÓDå®æÒç�È5ÎDç�å®È¨Ô�á�ÍAÎ���� Ç�ú�û�óDØDÉ.ÏyÕ®ÝÞç�ÍAÕ®Ó!Ô�Î�ÏyÈ5ÕÞȨÔ�Ô�ÍÔ�ÎDå®àyöÇ�à�É��BÝ®ÝÞÔ�ß®à8ç�È5ÎDç�å®È¨Ô.á�ÍAÎ�ò ñ�ÇÊØDÉ�ÏyÕ®ÝXç�ÍAÕ®Ó!Ô�Î�ÏyÈ5ÕÞȨÔ�Ô�ÍgÔ�ÎDå®àyöÇÊá�ÉÞË�ÍAÎäÏyÐ5Фþ+È5ÓDÈ5æ®Ð5àÌÏyçIÔ�È5ÍAÕ®Ó���Ü#ÏyÝ®Ý Ô�ß®àÌÓDå®æÒç�È5ÎDç�å®È¨Ôlá�ÍAÎ��/ò��yÚ�Ç���óDØDÉäÏyÕ®Ý ç�ÍAÕ��Ó!Ô�Î�ÏyÈ5ÕÞȨÔ.Ô�ÍgÔ�ÎDå®àyöÇ�ã�ÉÞË�ÍAÎdÏyÐ5Фç�ÍAøùÑÒÍAÕ®à�Õ�Ô�Ólú�û�Ü�ÏyÝ®Ý^Ô�ß®àùÓDå®æÒç�È5ÎDç�å®È¨Ôdá�ÍAÎ��/ò¤Ç���ó�ú�û�óDØDÉ=á�ÍAÎdÏyÐ5ФȨÔ�Óþ+È5ÓDÈ5æ®Ð5à_ÏyçIÔ�È5ÍAÕ®Ó�ö��ß®àBÓ!Ô�ÎDå®çIÔ�å®ÎDàðÍyá�Ô�ß®àðç�È5ÎDç�å®È¨Ô#È5Ó#ÓDç�ß®à�øuÏCÔ�È5ç/ÏyÐ5Ð��gãAȨþAà�ÕùÈ5ÕuË�È5ã®ö���ö���ÕùÔ�ß®àðæÒÍyÔDÔ�ÍAøÈ5ÓðÔ�ß®àäÈ5ծȨÔ�È3ÏyÐ�Ó!Ô�ÏCÔ�à� uÇ%Ö�ÉBÏyÕ®ÝSÍAÕ Ô�ß®àlÔ�ÍAÑ Ô�ß®àäÐ3ÏyÓ!Ô=Ó!Ô�ÏCÔ�à! uÇiÚäôOÖ�ÉBÏyÕ®ÝbÏuç�È5ÎDç�å®È¨Ôá�ÍAÎuÝ®à/ÏyÝ®Ð5Í+ç#"õÝ®àIÔ�à�çIÔ�È5ÍAÕÃÇ�È5Õ�Ô�ÎDÍ+Ý®å®ç�à�ÝÙÈ5Õ$ +à�çIÔ/ö&%®ö'�AÉ0ö(��ß®à å®Õ®ç�ÍAÕ®Ó!Ô�Î�ÏyÈ5Õ®à�Ý�È5ծѮå;Ô

ã�ÏCÔ�à�Ó=ÏyÑ®ÑÒà/ÏyÎðÍAÕîÔ�ß®àlÐ5àIáÊÔ=ÏyÕ®ÝîÔ�ß®àlç�ÍAÕ®Ó!Ô�Î�ÏyÈ5Õ®à�Ý ÍAå;Ô�Ñ®å;Ô�ÓBÍAÕîÔ�ß®àlÎDÈ5ãAß�Ô/Ü�Ô�ß®àäÐ3ÏyæÒà�Ð5Óç/ÏyѮȨÔ�ÏyÐ5È*)�à�ÝuÔ�ÍùÈ5ծݮÈ5ç/ÏCÔ�àBÔ�ß�ÏCÔ�Ô�ß®à+�ÞÝ®à�Õ®ÍyÔ�à8ÓDàIþAà�Î�ÏyÐ�ÏyçIÔ�å�ÏyÐ�ã�ÏCÔ�à�Ó�ö-àIÔ8ë�,uÇ�ú�ó0Ú®ÉæÒàlÔ�ß®àÞÇ�Ó!Ô�à�Ñ÷Éðç�È5ÎDç�å®È¨ÔBÍAæ;Ô�ÏyÈ5Õ®à�Ý æ-�XÔ�ß®àlÔ�Î�ÏyÕ®ÓDÐ3ÏCÔ�È5ÍAÕîÏyÐ5ãAÍAÎDȨÔ�ß®øXö

. ȨþAà�ÕÛÏ Ó�ÏCÔ�È5Ó!á/�+È5Õ®ãÿÔ�ÎDå;Ô�ß�þyÏyÐ5å�ÏCÔ�È5ÍAÕ$0 á�ÍAÎXë�,uÇ�ú�ó0Ú®ÉÌç/ÏyÐ5Ð_ÏyÕ102��à43;à�ç�å;Ô�È5ÍAÕ�Ô�ß®àà43;à�ç�å;Ô�È5ÍAÕ� ³

5�67 í/í/í5987 ��¯��Ò³i� âß®à�ÎDà#Ô�ß®à#à�Ð5à�øùà�Õ�Ô�Ó-È5Õ8à/Ïyç�ß� 9:;ÏyÎDàUÔ�ß®à#Ó!Ô�ÏCÔ�à�Ó�é#âȨÔ�ß0.Ç�ñiò¤ÇiéAó�ñ�ÉDÉ<; Ô�ÎDå®àùÏyÕ®ÝbÔ�ß®àgà�Ð5à�øùà�Õ�Ô�Ó8È5Õ>=�:¤Ô�ß®àùÏyçIÔ�È5ÍAÕ®Ó?�Xß�Ï/þ+È5Õ®ã@0.Ç�����Ç���ó�ñ�ÉDÉA;

Ô�ÎDå®àyöBDCFEHG�IJE�KMLFN�O$P/QSR/TVU&WAXYX[Z*U]\_^�`+a/b]`+c�a/R ë�,uÇ�ú�ó0Ú®É T9\Jd�\Ade\_R�a*dfQ4g[a/^�h?R�b4c�R/T!i[\_Zjc9\_R�akX[^0�l R/TVU+^mR/TVU+b]U�a*dD\_^ 0on Uqp�U#`+c�R�akX[^ ³

5�67 í/í/í5987 ¯��Ò³?r T�ak`#Tsa*dD\�d+RtUtuvUqp�U#`+c�R�akX[^xw

BDCFEHG�IJE�KMLFN*y(P/Q ³5�67 í/í/í

5987 ¯��Ò³ a*dz\vd+RtUtu{Uqp�U#`+c�R�akX[^�X|Q ú&l a/R!a*dz\_^ 0onUqp�U#`+c�R�akX[^DQeX[bAdYX[}~UAde\_R�a*dfQ4g[a/^�h!i[\_Zjc9\_R�akX[^ 0 X|Q ë�,uÇ�ú�ó0Ú®É w

ÖY�

Page 35: BMC’03 - JKUfmv.jku.at/papers/bmc03-preliminary-proceedings.pdfBMC’03 Boulder, Colorado, USA. ... Alessandro Cimatti (IRST, Italy) Raanan Fraer (Intel, Israel) Danny Geist (IBM

�[���q���j�+�~�Y�����_�

�x� � �&�]�Y�#�#�#�A�����#�+�����k�[����<�A�e�_�>�x ¡�q � ��m¢f£q¤¦¥¨§A +©V�9ª�«]ª*¤¦�9�­¬�® ¯s�_�9°z¬�® ±~«]²9 �°9ª�³´ �£q ��9�� ¡�x +«tµ& � ��z��«] �¶·�_�9°¶9£q¤��� ��q�D 4¸� ���¹�«]ª*¤¦�9��ª*��£]�[«]²9 �£��qª*¥!¶9º* _®!»t�9°9 � �°�¼½«]²9 !£q ��q¹9º�«]ª*�9¾@��ª*£q��¹9ª�«?�9 � �°9��¤¦�9º�¿¤¦�9 ��_°9°9ª�«]ª*¤¦�V�_º2 �º* �¥! ��-«e®<À<�_¥! �º�¿¦¼�ª�¢Á�_�m�_�+«]ª*¤¦�ª*�� 4¸� ���¹�«] �°·�[«<ÂÄÃ1Ŧ¼�«]²9 ��Æ�q¤¦¥! ¶V�_£�«]ª*��ª*¶V�[«]ª*�9¾?��¤¦¥!¶x¤¦�9 ��-«�²V�_°~«]¤��x A�q�#²9 �°9¹9º* �°sª*�Ç��«] �¶ÇÂ4®oÈA�~«]²9 A£qª*¾¦²-«Sª*�Çɽª*¾9®H¯ª*���_�sª*�9��«#�_�9�� ­¢f£q¤¦¥Ê«]²9 ?£q¹9�9�9ª*�9¾� 4¸9�_¥!¶9º* ~Ëf 4¸� ���¹�«]ª*�9¾~�_�+«]ª*¤¦�sÌ<ª*�s��«] �¶m¬¦Í4®

Î ²9 ? ��9��¤�°9ª*�9¾~�_º*¾¦¤¦£qª�«]²9¥Ï�9 � �°9��«]²9 ­¢f¤¦º*º*¤Yµ�ª*�9¾¡�_°9°9ª�«]ª*¤¦�Ç¢f¤¦£��_º*º½Å�ÐÑÂSÒÔÓx®Ëf²�ÍsÉV¤¦£��_º*º�«]²9 �Õ�ª*�qª*�9º* ��_�+«]ª*¤¦�9�ÁÖ~×>Ø�Ù-Ú¡ÛeÛeÛ�Ú�ØoÜ��_°9°¡«]²9 ��q¹9�x��ª*£q��¹9ª�«2ÝVÞ9Ë�ÖVßqÂqÍ

�_�9°s��¤¦�9��«]£]�_ª*�@ª�«S«]¤¡«]£q¹9 _®É½ª*¾¦¹9£q ·àáª*º*º*¹9��«]£]�[«] ��~«]²9 ·��ª*£q��¹9ª�«Ç¢f¤¦£s��«] �¶Ô 4¸� ���¹�«]ª*¤¦�9��®ãâ�£q¤��� ��q�@ 4¸� ���¹�«]ª*¤¦�9�

µ&¤¦¹9º*°>�x ¡¥!¤�°9 �º* �°m�-¿>�_°9°9ª*�9¾Ç«]²9 !ä�å�Ë/ÂqÍ�Õ¦ ��+«]¤¦£­«]¤�«]²9 ¡£qª*¾¦²-«?²V�_�9°>�qª*°9 ¡¤_¢o«]²9 ©V¾¦¹9£q _®zæ2 +«�ä�å�Ë�ç�ß4Ó9Í��x Ç«]²9 ·Ëf¶9£q¤��� ��q�#ÍD��ª*£q��¹9ª�«�¤¦��«#�_ª*�9 �°áµ�ª�«]²á«]²9 s�_¹9¾¦¥! ��-«] �°�_º*¾¦¤¦£qª�«]²9¥@®èDéFêHë�ìJê�íMîFï*ð(ñ/ò �/óV�oôA�Y�[õ*�]ö_�Ç�+�/�]�+���/� ä�å�Ë�ç�ß4Ó9Í ó9öJ��ö<�eö_���*� ò4÷ �/��ø­���4���/ó�ù[ö_õj�9ö_���k�[�ú�û �/óV�+�s�/óV�+�]�A�*�?ö_� úoü �q���#�+�����k�[�~ý Ù�þ�ÿ� ÛeÛeÛ þ��� ý���� Ù�� ó��k�#ó~�*�?ö�x�]�Y�#�#�#�?�q���#�+�����k�[�x�èDéFêHë�ìJê�íMîFï î�ñ/ò ý Ù�þ�ÿ� ÛeÛeÛ þ��� ý���� Ù �*�söx�]�Y�#�#�#�s�q���#�+�����k�[� � ò ç û �/�­�*�sö_� úoü�q���#�+�����k�[� ò �[�A�Y���~�A�eö_���*� ò4÷ �/��ø!ù[ö_õj�9ö_���k�[� ú � ò ä�å�Ë�ç�ß4Ó9Í �

�x�� ����]öH�#ó9ö����/õj�/� ÷ �&�]��V�+�4���k�#�»t���&¤¦£q¤¦º*º �_£qª* ���¬�® �~�_�9°m¬�®�ŦÅ�ª�«�ª*����«#�[«] �°@«]²V�[«<�x¤_«]²@��«] �¶m�_�9°¶9£q¤��� ��q�< 4¸� ���¹�«]ª*¤¦�9�¶9£q ��q �£�Õ¦ <«]²9 �©V�V�_ºV��«#�[«] ��&¤_¢´«]²9 � 4¸� ���¹�«]ª*¤¦�9��® Î ²9 �£q +¢f¤¦£q _¼��_�-¿!��«#�[«] �¶9£q �°9ª*�e�[«] ���¤¦����� �£q�9ª*�9¾@�q¹9�#²á�s��«#�[«] !�e�_�·�x !��«]¹9°9ª* �°>µ�ª�«]²>«]²9 !¶9£q ��q ��-«] �°v�_¶9¶9£q¤-�_�#²�®�� �Ï°9 e�_°��º*¤�����¼_ªk®  _®�¼-�A��«#�[«] &µ�ª�«]²��9¤­¤¦¹�«]¾¦¤¦ª*�9¾�«]£]�_�9�qª�«]ª*¤¦�9��¼_ª*���<¶V�_£�«]ª*��¹9º �_£qº�¿?ª*�-«] �£q ���«]ª*�9¾A�e�_�q �_¥!¤¦�9¾¡�q¹9�#²¶9£q¤¦¶x �£�«]ª* ���®

Î ²9 ���¿��9�#²9£q¤¦�9ª��� �°·¶9£q¤�°9¹9�+«­¤_¢oæ Î�� �A�e�_�m°9 e�_°9º*¤�����_�­�~��¤¦¥��9ª*�V�[«]ª*¤¦�@¤_¢Á«tµ&¤��¤¦�9°9ª�«]ª*¤¦�9��®&ɽª*£q��«]º�¿¦¼9��¤¦¥!¶x¤¦�9 ��-«]�<¥~�e¿� ��9°¹9¶ª*�@��«#�[«] ���µ�ª�«]²@�9¤~¤¦¹�«]¾¦¤¦ª*�9¾¡«]£]�_����qª�«]ª*¤¦�9��® �  ���¤¦�9°9º�¿¦¼��qª*�9¾¦º* ���¤¦¥!¶x¤¦�9 ��-«]�o¥~�e¿�ª*�9°9 � �°~�x <�_�9º* �«]¤D¶9£q¤��� � �°�¼��9¹�«o«]²9 �ª*£��¿��9�#²9£q¤¦�9ª���ª*�9¾­��¤¦¹9�-«] �£q¶V�_£�«]�Á�_£q Sª*����«#�[«] ���µ�²9 �£q ���¿��9�#²9£q¤¦�9ª��e�[«]ª*¤¦�¡ª*�½�9¤_«�¶x¤¦�q�qª*�9º* _®

Î ²H¹9���s°9 e�_°9º*¤����m��¤¦¹9º*°>�x !°9 +«] ��+«] �°zµ�ª�«]²·��ª*£q��¹9ª�«]�? ��9��¤�°9ª*�9¾@�q¹9�#²á°9 �¥~�_�9°9�¤¦�9º�¿��V�_�q �°Ç¤¦�~«]²9 ��! �Ë!"¦ß4Ó�ÃvÅJÍ�¾-�[«] ���® Î ²9 <¢f¤¦£q¥! �£Á��¤¦�9°9ª�«]ª*¤¦�~ª*�o�qª*¥!¶9º* _¼-ª�«&�e�_�Ç�x °9 +«] ��+«] �°m�-¿��«#�[«]ª*�D�_�V�_º�¿��qª*��® Î ²9 �º �[«q«] �£�ª*��¥!¤¦£q �°9ª$#!��¹9º�«�«]¤~ ��9��¤�°9 ���¤¦¥!¶V�_�+«]º�¿¦®Î ²9 �£q +¢f¤¦£q _¼_°9 e�_°9º*¤����­°9 +«] ��+«]ª*¤¦�Dª*�Fª*¥!¶9º* �¥! ��-«] �°��-¿?ª*�-«]£q¤�°9¹9��ª*�9¾<���9 +µ ª*�9¶9¹�«Ä¾-�[«] _¼ò � Ë!"¦ß#çoÍ4¼�¢f¤¦£¡ e�_�#²Ñ��¤¦¥!¶x¤¦�9 ��-«~ç �_�9°Ñ e�_�#²Ñ��«#�[«] %"�µ�ª�«]² ¤¦�9º�¿zÕ�ª*�qª*�9º* Ç¤¦¹�«]¾¦¤¦ª*�9¾�_�+«]ª*¤¦�9��®

Î ²9 z ��9��¤�°9ª*�9¾Ñª*�s�V�_�q �° ¤¦�$«]²9 z£q e�_�q¤¦�9ª*�9¾ «]²V�[«@ª�¢D«]²9 �£q ·ª*�� °9 e�_°9º*¤����Hª*�9¾ª*�-«] �£qº* e�eÕ�ª*�9¾� 4¸� ���¹�«]ª*¤¦��¼�«]²9 ��Ç«]²9 <�q +«�¤_¢2��«#�[«] ��S£q e�_�#²9 �°sª*�!«]²9 ­�_�q�q¤���ª �[«] �°Ç��«] �¶�¤¦£&')(+*�,!*.-0/�12/43+576!8 *9-0/!/43+*):9(+-0;<(=/4(+>?3+80@A5B*)C+>D6!*E@�F�')(+*)G+,!*E/4*�CH6!*E@I6!,<1DC�/4801�6!- >?CKJ=*L6!(+>7@K1?/!/43+J=*E/6!(+*�MN>?8 8 >�:9- C+O�PQ- M7- CR19/S6<1�6!*.T�6!(+*U/S6<1�6!*�G+,!*E@7-0;�1�6!*�6!>V5B*U/S6!3�@7- *E@2(+>?80@+/Q6!(+*�CI- CR1D8 8H/S6<1�6!*E/�,!*E1?;<(�1D5+8 *MN,!>?JWTA5YX�3�/4- C+O�>?C+8 X�ZY[\J=>�]?*E/96!(+*AG+,!*E@7-0;�1�6!*A1D80/4>^(+>?80@+/�_B-�F *?FVX?>?3`;�1DC+C+>D6aO?*L6b>?376a>DMU1dc45�1?@+e/S6<1�6!*K5YXf3�/4- C+O�>?C+8 XfZY[\J=>�]?*E/�FIg\M)/4>?J=*AZY[\J=>�]?*E/b@7>�C+>D6I,!*E/4GB*E;h6b6!(+-0/bG+,!>?GB*�,46SX?_B6!(+*�X`JA3�/S625B*;L>?CY]?*�,46!*E@i6!>=]Y-0/4- 5+8 *R1?;h6!- >?C�/.5B*LMN>?,!*26!(+*I]?*�,!- jB;�1�6!- >?C�-0/9/S6<1D,46!*E@�F

ŦÅ

Page 36: BMC’03 - JKUfmv.jku.at/papers/bmc03-preliminary-proceedings.pdfBMC’03 Boulder, Colorado, USA. ... Alessandro Cimatti (IRST, Italy) Raanan Fraer (Intel, Israel) Danny Geist (IBM

k�l�mEm�npo?qsr7tuq�oBv

w�xEy�zH{H|E|`{D}~{HzH�~����yQ��xE{Y�Bz���{H|���|�������{s�.�0���U�!�K|E��z����������f����{u��{Y�B����y�z���������|�������{s����|� {������.�0���U�!�L�2�i��{���{?������w��~�K������{�zY�Bw~����xE{H|i��|E�����Q��{^xE{Hw�xE{H|E{H���������$�Q{��H�~ SxEyQ¡¢{Y�Bz��zHyQ¡�wUyQ��{H���f£W|Eys���������$ 2����{�������{�¤�¥�¦!�H�\§�£A¨^{?�B�B��������{H|���ys��xE��{�����{�|�������{d�H�)��|�����{xE{Hw�xE{H|E{H���������$�Q{` SxEyQ¡©����{`zHyQ¡�wUyQ��{H����£ª���%�.�0���U�!�h�

�i��{u������{u���B|f��y � {dzHyQ��|���x��B����{H����������{d SyQ����y7�^�����s�=�Y«Q��¬b��xE|����$«Q­V�B�®y � ����yQ��||EyQ��������{H|E|�zHxE�$��{HxE��yQ�¯��|����������°|�������{±���B|d��y � {����²�.�0���U�!�� SyQxd�$����y � {±��zY�B�����N³������{B��´�{HzHyQ�����$«Q­)��y�¡s�B��������{�����{dzHyQ����{Hz?����yQ�%yB Rµ����B�b|�������{H|���y � {u�s|�������{dyB R����{������{HxE��{Y�Y�������{D}~{HzH�~����yQ��|H­)����{?«����Y�Q{���y � {dzHyQ��|���x��B����{H�°��y�w�xE{HzH��|E{H�$«°yQ��{d���°{Y�Bz��zHyQ¡�wUyQ��{H���Y�·¶h��|����B��zH{H|s SxEyQ¡¸����{¹zHyQ¡�wUyQ��{H���£ � yB �����{¹xE�����������º{D}��B¡�w���{¹�BxE{�Q�$�Q{H�±���¹¬b������»~�E¼

½\¾¿\À�Á< �pÃ4ÄEÅ�Æ�Ç!� È

É ÉÉ É Ê

ËËËË Ì

ͽ¿\À �pÃ4ÄEÅ�Æ�Ç!�

½Î0Ï �pÃ4Ä�Å\�����!�

½ Ð�Ñ ÇÇÒ ¿\À �0Æ�Ç!� È

É ÉÉÉ Ê

ËËËË Ì

ͽ¿\À �pÃ4ÄEÅ�Æ�Ç!�

ͽ¿\À �pÃ4ÓEÅ�Æ�Ç4�

½DÔ¿�Õ4Ö �0×E�

É ÉÉÉ Ê

ËËËË Ì

½¿�Õ4Ö �0×�Å\Æ�Ç!�

½¿�Õ4Ö �0×�Å\ÆQØ<�

½DÔÙLÚ �0�Û���!� ÈÜ Ü~ÝßÞÞà½�á ½Dáâ â½

¿�Õ4Ö �0×E�½¿�Õ4Ö �0ãS�

ä)åpæ�ç~èBç2éBêLëYêhì�íVîLìDï�åNð�ëYêhì�ñ\òKìDë7ï�ópôQðLõ�öI÷Kø�ë7ópùQúLåNú

û �Y����������{?µ���{H�¹����{^¤�¥�������{H|��d��{Y�B����y�z���zY�B� � {���{?��{Hz?��{H� � «±����{��B���B�$«�|E��|^yB {H��� � ��{H�s�Bz?����yQ��|A���u����{^µ����B�Û|�������{B�I�i����|A��|R��yQ��{ � «���{?µ����������i¤Yü?ý2¦4þ�§�£A¨I������{^ SyQx�B���.����{`����|E� � ��{`�Bz?����yQ��|�þ��B���%zHyQ¡�wUyQ��{H����|�£ª���Y������������{^¤�¥�¦!�Q§�£A¨=������{H|^ SyQx^|�������{������£W�^�$���°yQ�~���QyQ��������x��B��|E�$����yQ��|��\� � {H��{H�°þ¹�B|�����w��~��|H��ÿ��®�Bz?����yQ��þ±��|��Q��y � �B���$«{H��� � ��{H�����u����{^µ����B�Û|�������{^���±�$�R��|R{H��� � ��{H�s���s�B����w��Bx�����zH��w����������fzHyQ¡�wUyQ��{H���A��������{������{R¤Yü?ý2¦4þ�¨R{?�B�B��������{H|A��y���xE��{B�R¬b�����B���$«Q­�����{Y�B����y�z��u��|K��|�������{��^��{HxE{f��yd�Bz?����yQ�s��|�Q��y � �B���$«{H��� � ��{H�)���i��{�zY�B|E{� SyQx��Bz?����yQ�°þ±���¹����{�xE�����������{D}��B¡�w���{���|���������|���x�����{H�yQ�����{fxE���Q���=���±¬b�����~»���yQ�Q{?����{HxK�^�$�������{f��{Y�B����y�z��s��{?��{Hz?����yQ��������{� SyQxK����{f{H������xE{{D}��B¡�w���{B�

¶<�=|E��yQ����� � {���yB��{H�s�������KzHyQ¡�w��BxE{H����y�����{�������{HxE��{Y�Y��������¡�y���{H�!­�|���{Hw��B���w�xEy�³zH{H|E|`{D}~{HzH�~����yQ��|f¡s�Y«%��yQ|E{�|EyQ¡�{�yB R����{d������{HxE¡�{H���\����{�|�������{H|H� û y7�K{?�Q{HxH­V�$�f��|���yB���¡�wUyQ|E|E� � ��{A��y`xE{Y�B|EyQ��� � yQ�~�I����{H¡¹­�w�xEy7������{H�u�������A�B���~|�������{^z����B���Q{H|AyB .������{HxE{H|��R��y��|�zY�B� � {�y � |E{Hx��Q{H�°����xEyQ���Q�¹����{�y�zHzH��xExE{H��zH{H|�yB b����|E� � ��{��Bz?����yQ��|H�=�i��{�{D}��Bz?����{D³���B����|RyB )����{� SyQ����y7�^�����`zHyQ��|���xE��z?����yQ���BxE{���{? ��A SyQxA S��x�����{HxA�KyQxE�Û­~��{HxE{��E��|��K����{�¡s�B�������{Y�B|��BxE{�|E�B{?��z���{H�)��ÿ��°�B�����$����yQ���B�9zHyQ¡�wUyQ��{H���Y­ÛzY�B����{H�%�B�°y � |E{Hx��Q{Hx��B�~��yQ¡s����yQ�)­zY�B� � {s�B����{H����y¹����{�|�«�|���{H¡¹�±¶<��y � |E{Hx��Q{H|�����{u����|E� � ��{��Bz?����yQ��|`���B�������¹w��\�BzH{ � «���Y�������s�B���)yB b����{H¡ ���¹�$��|��B��w���� � {?�Y����y7� �B��«±|����~�E��{HxE�����������B�BxE�\�B���^|��� S{?�h«¹w�xEyQw�³{Hx��h«¯¦��^����z���zY�B� � {�{D}~w�xE{H|E|E{H�º�B|f�sxE{H�Q���\�Bx��\�B���Q���B�Q{7¨izY�B� � {�xE{H����zH{H�®������ys����{����{H|�����yQ��yB R�^��{?����{Hx�����{�y � |E{Hx��B������yQ�®�B�~��yQ¡s����yQ�°zY�B��xE{Y�Bz����sw��Bx�����zH���\�Bx�|�������{B�¬�yQx`����{s|��� S{?�h«º|E� � |E{?�uyB ���� ����­b����{������{Y�Bxf��{H¡�wUyQx��B�A��yQ�Q��z���� �^�$����yQ�~������{��{D}���³<����¡�{�yQwU{Hx�����yQx��¯­Û��µ����$��{`�B�~��yQ¡s����yQ��zHyQ��|���xE��z?����yQ�±��y�yQ�)��|^�Y�B�B���\� � ��{��������!�

����� �"!#�"$&%('*),+�-/. %(!0!1� 2 -'43525',65!879':70% ;<)/=?> � 25':70� )/2�;@',2�>�%A.5!1%($�70)�;<)/=�B5'/;C706 D�%@25;<)&$&% ',E0> � 70E9',E0D!879':70%*B E0%($&�";@':70%(!@F

� G

Page 37: BMC’03 - JKUfmv.jku.at/papers/bmc03-preliminary-proceedings.pdfBMC’03 Boulder, Colorado, USA. ... Alessandro Cimatti (IRST, Italy) Raanan Fraer (Intel, Israel) Danny Geist (IBM

H5IKJ(J@L�M/N�O&PQNKM�RS TVUAW�XZY[UAW#\^]9X#W

_a`(b/c�d�efcgbh`@c�i�j�`(bh`Vklj�`Qmnbhbhopj�q#dsrtcgbhque8v(dswyx z {|c:j�}�~�o#��cgk#ds`(b�i�j�`(bh`V}�o#d&��opcgdq#b�j�q#��dKi:}���|k#b^cgbh`@c�i�j�`(bh`fj�v(b�r#v(d&�K~�q#bhq�j�`f�K�f����e8`gj��,�l�v(dswVbh��j�j�o#q��#����`(rnbhih~��� i�j5cg~�dso#`�cgk��#`�v(bho#q#bhv(~�o#��cgk#b^ihdswVrlj�v(~�`(dso�c:j�`(}�e8b�j�`(~�m#��b��*�|k#b�v(bh`(�#��cg`|d�e4cgk#b�cgbh`@cg`j�v(b^�s~��sbho�~�o���j�m#��b¡ ¢��~�cgk£cgk#b^e8ds����d&��~�o#�¤ihds���#wVo#`h¥¦ �v(dsm#��bhw§~�o#`@c:j�o#ihb��¦ ��c��©¨n��mnds�#o#q©e8dsv¤`@cgbhrub,ªtbhih�tcg~�dso#`h��~0� b����cgk#b�`(w�j�����bh`@c¤o��#w¤mnbhv�d�ef`@cgbhr#`Q`(�#i:kcgklj5cfjQq#b�j�q#��dKi:}�~�`|v(b�j�i:k#bhq��

¦ ��c���«s�#v(�#o#o#~�o#��cg~�wVb�e8dsv|`@cgbhr�b,ªtbhih�tcg~�dso#`�j�`�wVb�j�`(�#v(bhq�m�¬�­ ®n¯5°#­ ±³²�´�­5µn²h¶�·#�¦ �vh��¨£j�o#q¸�vh��«s�#`(~�wV~���j�v(��¬�e8dsv|r#v(dKihbh`(`fb,ªtbhih�tcg~�dso#`h�¦ �#���¹¨�j�o#q��#���¹«s�#mnds�#o#q¸j�o#q�cg~�wVb�e8dsv�ºf���#���¹»|��¼½x ¾5{0�¦ �#����mnq#q��lv(�#o#o#~�o#��cg~�wVb�e8dsv�ºf���#���½»�¿^¿Àx Á {0�

�|k#b¸cgbh`@cg`���bhv(b�i�j�v(v(~�bhqZds�tc���~�cgkÂj�oZ_^�¸¿Ã_�cgk#��dsoZw�j�i:k#~�o#b���~�cgk[jpÄ�Å�ÆsÆ�¸ÇfÈ�¼���ÉÀj�o#quÄ£Ê^~���j�m�¬�cgbQd�e�wVbhwVdsv@¬�v(�#o#o#~�o#��cgk#b�� ~�o��Kª�dsrnbhvgj5cg~�o#��`@¬K`@cgbhw��Ë ~�cgk�cgk#b�r#v(dsm#��bhwÌ¿^j�v@cgbh`h��o#d�v(bh`(�#��cg`¢ihds�#��qÍmnb�dsmtc:j�~�o#bhq���~�cgk#~�oÍj�v(b�j�`(dsolj�m#��bcg~�wVb|��~�wV~�cf�<Ä�k#ds�#v:��#`(~�o#�¢bh~�cgk#bhv�ºf���#���λ|��¼pdsv�ºf���#���Ï»�¿^¿¤�scgk#bhv(b/e8dsv(bfcgk#bbho�cgv(~�bh`fj�v(b^d�e4cgk#b^e8dsv(waº�Ð5_¢�

�|k#b¤v(bh`(�#��cg`fe8dsv�cgk#b�»�dKds��b�j�o�ih~�v(ih�#~�cg`���bhv(b�dsmtc:j�~�o#bhq¸m�¬¸�#`(~�o#��jVcgdKds��x�Ä&Ñ5{4cgdcgvgj�o#`(��j5cgb?�K�f�K`�cgd�»�dKds��b�j�o¡ih~�v(ih�#~�cg`4j�o#q¢cgk#bho¤�#`(~�o#�fcgk#b�»|¼|Ò ¼�Çf_�Ó*Ó�`@¬K`@cgbhwax�ÄsÄ/{��k#~�i:k � v(`@c�cgvgj�o#`(��j5cgbh`�jVih~�v(ih�#~�cfcgd£¼�º�Óp¿�Ô@��_f¼|��e8dsv(wÕx�ÄsÄ/{*j�o#q�cgk#bho�`(ds���sbh`�~�c��~�cgk�È&¼�klj5Ö×�sbhv(`(~�dso× �ÆsÆtÄs�" K��Ä z�x�Ä&¾5{0���|k#b¡e1j�i/c�cgklj5c�mnd�cgk�cgk#b¡r#v(bh`(bho�cgbhq�wVb/cgk#dKqj�o#q�ºf���#���Ø»|��¼Ù�#`(b�È&¼�klj5ÖÚj�`�cgk#b¤mlj�i:}�bho#q×j�q#q#`�ihv(bhq#~�m#~���~�cC¬£cgd�cgk#bh~�v�ihdsw��rlj�v(~�`(dso����|k#b¤v(�#o#o#~�o#��cg~�wVb¡e8dsv�cgk#b¤`@cgbhr�j�o#q�r#v(dKihbh`(`^b,ªtbhih�tcg~�dso#`�~�`fcgk#b¤`(�#wÛd�e�sbho#bhvgj5cg~�o#��cgk#b�»�dKds��b�j�o�ih~�v(ih�#~�c�e8v(dswÜcgk#bV`(rnbhih~ � i�j5cg~�dso#`¢j�o#qÍ`(ds���K~�o#��~�c�e8dsv�cgk#b�s~��sbho¸mnds�#o#q��|�|k#b¢v(�#o#o#~�o#�Vcg~�wVb^e8dsvfºf���#���Ý»|��¼Þ~�`fihdswVrnds`(bhq¸d�e�sbho#bhvgj5cg~�o#�cgk#b¢¼�º�ÓÚ~�o#`@c:j�o#ihb¡j�o#q�`(ds���K~�o#��~�e4e8dsv|b,ª#j�i/cg��¬�cgk#b��s~��sbho�mnds�#o#q��

ß �sbho£cgk#ds�#�sk�cgk#bfcgbh`@c|i�j�`(bh`�q#d¤o#d�c�klj��sb�j¡��d�c�d�eAo#dsoK�Cq#b/cgbhv(wV~�o#~�`(wÝ~�c�i�j�o�mnb`(bhbho�cgklj5c�cgk#bQo#dsoK�C`@c:j�o#qlj�v(qÍb,ªtbhih�tcg~�dsoÍwVdKq#bh��`^ihdswVrlj�v(b¤e1j��sdsvgj�m#��¬�~�o×cgbhv(wV`�d�ecgk#b�mnds�#o#q�j�o#q×v(�#o#o#~�o#��cg~�wVb¢cgd£cgk#ds`(b�d�e�ºf���#���Ø»|��¼��4¼�dswVrlj�v(bhq�cgd�»�¿^¿f�mlj�`(bhq�wVdKq#bh�³i:k#bhi:}�~�o#�Qcgk#b�v(bh`(�#��cg`|v(bh~�cgbhvgj5cgb�cgk#b�e1j�i/c|cgklj5c�»|��¼Â~�`|j5c|~�cg`|mnbh`@c�~�o� o#q#~�o#�Q`(k#dsv@cfq#b�j�q#��dKi:}�`h�

ß ªtrnbhv(~�wVbho�cg`f~�o#q#~�i�j5cgb�cgklj5c���~�cgk�cgk#bh`(b¢b,ª#j�wVr#��bh`�~�cf`(dswVb/cg~�wVbh`�c:j�}�bh`�È&¼�klj5Öe1j�v���dso#�sbhv�cgd¤r#v(d&�sb¡j¢e8dsv(w¤�#��j¡�#o#`gj5cg~�` � j�m#��b�cgklj�o � o#q�j¤`gj5cg~�`@e�¬K~�o#�¤cgv(�tcgk�j�`(`(~��soK�wVbho�cf��~�cgk¸~�o#`@c:j�o#ihbh`�d�eihdswVrlj�vgj�m#��b�`(~�Èhbh`h���|k#b¢r#k#bho#dswVbho#dso�~�`�wVds`@c�j�r#rlj�v(bho�c~�o�cgk#b¤b,ª#j�wVr#��b¤à^b/¬��8Å�����k#bhv(b¤cgk#b¢cg~�wVb¡��~�wV~�c�d�e�dso#b¤k#ds�#v�~�`�b,ªtihbhbhq#bhq×��~�cgk�j�o�#o#`gj5cg~�` � j�m#��b�~�o#`@c:j�o#ihb�wVdKq#bh��~�o#��r#v(dKihbh`(`b,ªtbhih�tcg~�dso#`d�e���bho#��cgkQ �át�4�|k#b�cgbh`@ci�j�`(bh`j�o#q�cgk#b¢cgdKds�Acgvgj�o#`(��j5cg~�o#���K�f�K`�cgd�»�dKds��b�j�o¸ih~�v(ih�#~�cg`^j�v(b�j���j�~���j�m#��b^e8dsv�q#d&��o#��d�j�qj5c¢x�Ä&Ñ {0�

Ä&Ñ

Page 38: BMC’03 - JKUfmv.jku.at/papers/bmc03-preliminary-proceedings.pdfBMC’03 Boulder, Colorado, USA. ... Alessandro Cimatti (IRST, Italy) Raanan Fraer (Intel, Israel) Danny Geist (IBM

â5ãKä(ä@å�æ/ç�è&éQçKæ�êë³ì�íKî�ïfð

ënï,ñCò?ó�ï,ñ<ô�î�ò<ñ�õ�ö�÷�ø�÷*ù�ú�û�ûAüý�þ�ÿ���� ��� ��� � ����� ý�þ��� ý�þ� � ������� ������� ����������������9þ������ �� !� " �� "� #�� $�%'& $�%'& $�%'&�tý)(� �!* "� "�!�+ "� "�!�+ ,-+ +���" "� �!. � �0/1(� '* � "� "�#�2 � "� "��43 + �� " "� "�#. � �0/1(5!* # "� �2 # "� � � �� "� '6. � �0/1(5�* 6 "� 3! 6 "� !6 �3 3� �" "� 243. � �0/1( 37* 8 � 2 8 "� 6'3 '6 �!�" !� 69��0:1(5!* ��# #� �" ��# !�"�" ,-��" !� �"�" "� �"9��0:1(5�* ��2 !�"�" ��2 64+�" ,-!� !64"�" "� !69��0:1( 37* �6 �" �6 � ,; �8 ��!�"�" "� 64�9��0:1(5#* ��+ �# ��+ �3" ,; �+ �8�"�" �� !�<�>=4��(5�* 6 "� ��! 6 "� !�8 �" �3 "� ���<�>=4��( 37* + "� 6�6 + "� ��# �! 64� "� !�#? (� '* 8 "� !�# 8 "� !�# ,; � �#�"�" !� "@A�9þ���(5!�#* #�" � ! #�" "� 67 #� 67 " "� �!@A�9þ���(5#�"* �"�" #� �"�" �� �"� ���" "� #43@A�9þ���(B64#* �#�" �! �#�" 67 2 �#� 8�8�" � 8@A�9þ���(� �"�"* !�"�" !�! !�"�" �# !�"� 3+�"�" #� #�7��C��������(5!�#* ��� "� 2�� ��� "� 6 ��+ 3� ! "� �!�7��C��������(5#�"* #�+ !� #�+ !� � 2�� 3" "� 3#�7��C��������(B64#* +�� 3� # +�� #� +�+ !�!�" � #�7��C��������(� �"�"* �"�+ +� " �"�+ +� � � �� 8�+�" 3� 2���4D�(� �#* ! "� "� �3 ! "� "� �3 � "� !6 "� � �7EF����GH(� '* 3 "� "���+ 3 "� "���" 6 "� �� "� "6

I JLKNMPORQ7SPT�UKNMPTWVXMPY[Z]\^QV�_�\RYa`bKdcfe

gih�jlkfm knjHoqp7r�s�t�u�jHpwvnx�s�y�t�jHt{z|x)t�jH}�~�h�jH~���u�y���x ��o�j�m ~�hfm v�u�}�u�r���k�o�x�knjHo7r�u�jHpwx ��mp7�)p7r�jHz[o�jHk�o�jHp�jHy�r�jHt�m p�m�k�o�x)t�s�~1r�x �d�)g-�)pH��g��Nxwy�x�y�p7r�m y�tfm o�tljF�AjH~HsAr�u�x�ylz|x)t)�jH}�pH��p7r�jHklm y�t�k�o�x)~HjHp�p;jF�AjH~HsAr�u�x�y�pH�>m o�j�k�o�x�knx�p�jHt�r�x�~�m kAr�s�o�j�p�j1r�pPx �Xu�y�r�jHo�}�j�m��)u�y��jF�AjH~HsAr�u�x�y�p�u�y�m�~Hx�z|kfm ~1r���x�o�z��

gih�j;kfm knjHoik�o�jHp�jHy�r�p�r��Nx�r�o�m y�p�}�m�r�u�x�y�p�~�h�jHz|jHpi��o�x�z�m yw�)g-�)pir�x��Nx)x�}�j�m y�~Hu�o�~Hs�u�r�pH�� �y¡r�h�jw¢fo�p7r�~�m p�j �Nr�h�j�o�jHp�s�}�r�u�y��£~Hu�o�~Hs�u�r|jHy�~Hx)t�jHp�k�o�jH~Hu�p�jH}��Lr�h�j�p7r�jHkWjF���jH~HsAr�u�x�y�p�x ��r�h�jqk�o�x)t�s�~1r�x ���)g-�)p�s�y�t�jHo�~Hx�y�p�u�t�jHo�m�r�u�x�y¤m y�t¥u�yLr�h�jqp�jH~Hx�y�t¥r�h�jk�o�x)~HjHp�p�jF�AjH~HsAr�u�x�y�pH�Xgih�j;jHy�~Hx)t�u�y���u�pN~Hx�z|kfm ~1r�}�j�m t�u�y���r�x�m�~Hu�o�~Hs�u�rN}�u�y�j�m odu�y�r�h�jp�u�¦Hjix �nr�h�jivnx�s�y�t�§n��z|x�o�jik�o�jH~Hu�p�jH}��|¨w©�©'ªW« ©�¬ ­ « ¬�®L¬ ¯ « ¬�®L¬ ° « ¬ ±�±)²§�±^��h�jHo�jP­ « ��¯ «m y�t�° « m o�j�r�h�j�p7r�m�r�j�p�kfm ~Hj ��r�o�m y�p�u�r�u�x�y³o�jH}�m�r�u�x�y³m y�t³�)u�p�u�v�}�j�m ~1r�u�x�y�p�x �d�)g-�³´ « �o�jHp�knjH~1r�u���jH}�����gih�j�jHy�~Hx)t�u�y���s�p�jHpP�Nx)x�}�j�m yw��s�y�~1r�u�x�y�p-x�sAr�p�u�t�j�r�o�m t�u�r�u�x�yfm }µk�o�x�knx��p�u�r�u�x�yfm }�}�x���u�~ �Ayfm z|jH}���~�m o�t�u�yfm }�u�r���~Hx�y�p7r�o�m u�y�r�p�x ��r�h�j;��x�o�z·¶F¸ " m y�t³¶F¸ �fv�sAr-r�h�jvnx�s�y�t�h�x�}�t�p��NjHo�j�r�h�j�s�p�j�x �¹r�h�jHzºt�u�p�m }�}�x»�NjHtµ�P�)s�~�hlm���s�y�~1r�u�x�y³��u�r�h³u�y�t�jH��o�jHj¼ ~�m yqyfm z|jH}��|vnjPp�u�z�s�}�m�r�jHt�s�p�u�y��|¨w© ¼ ±Ny�j1�¾½�¿FÀ¡m y�t�Á¤��m�r�jHpH�¹gih�j�m k�k�o�x�m ~�hwu�pvfm ~�� jHtqv���m�p�j1r�x �µr�jHp7r�~�m p�jHp�p�h�x»��u�y���r�hfm�rdr�h�j�o�s�y|r�u�z|jHpd~Hx�z|kfm o�j���m���x�o�m v�}���r�x

Â�Ã

Page 39: BMC’03 - JKUfmv.jku.at/papers/bmc03-preliminary-proceedings.pdfBMC’03 Boulder, Colorado, USA. ... Alessandro Cimatti (IRST, Italy) Raanan Fraer (Intel, Israel) Danny Geist (IBM

Ä�Å)Æ�Æ7ÇBÈ1É�Ê»Ë�É)È Ì

Í�Î7Ï�Í�Ï�ÐFÑ�Ò Ó�Ñ4Ï�Ô�ÐFÑÍ Õ7ÏiÖ�×�Ï�ÐHÕ�Ø�Ð�Í�Ù)Ö�×�Ú|ÛiÜ�ÝÞÖ�ß|à�Ø�ÐHß|ÐH×�Ï�Í�Ï�Ö�Ò�×�Ö�×qÏ�Ô�Ð�á-âäã�ÜwåæÎ7ç)Î7Ï�ÐHß�èé Ô�Ð;à�Õ�ÐHÎ�ÐH×�Ï�ÐHê�Í à�à�Õ�Ò�Í ë�ÔwÖ�Î�ëHÒ�×�Î�Ö�ê�ÐHÕ�ÐHê�Ò�×�Ø�ç|Ó�Ò�Õ�ß|Ò)ê�ÐHØ�Îdì�Ô�ÐHÕ�Ð;Ï�Ô�Ð�í é ã)Î�Í Õ�Ð

à�Õ�ÐHÎ�ÐH×�Ï�ÐHê£ÐFîAà�Ø�Ö�ëHÖ�Ï�Ø�ç�è é Õ�Í ×�Î�Ø�Í�Ï�Ö�Ò�×�Î-Ó�Õ�Ò�ßïÎ7ç)ß�ðnÒ�Ø�Ö�ë�Í Ø^Õ�ÐHà�Õ�ÐHÎ�ÐH×�Ï�Í�Ï�Ö�Ò�×�ÎHñ>Ø�Ö�ò Ð�ã�Üwåß|Ò)ê�ÐHØ�ÎHñAÖ�Î�Í ×�Ö�×�Ï�ÐHÕ�ÐHÎ7Ï�Ö�×�Ú�Õ�ÐHÎ�Ð�Í Õ�ë�Ô³à�Õ�Ò�ð�Ø�ÐHßóÓ�Ò�Õ�Ó�âAÏ�â�Õ�Ð;ìNÒ�Õ�òäè

é Ô�ÐPÖ�ê�Ð�Í�Ó�Ò�ÕdÏ�Ô�Ð�àfÍ ànÐHÕ�Í Õ�Ò�Î�Ð;Í Î�Í�ëHÒ�ß|àfÍ Õ�Ö�Î�Ò�×|Ï�Ò�Ï�Ô�Ð�ìNÒ�Õ�ò|ê�Ò�×�Ð�Ö�×lô õ�ö'è é Ô�ÐàfÍ ànÐHÕ-à�Õ�ÐHÎ�ÐH×�Ï�Î;Í�ÛiÜ�Ý{à�Õ�Ò)ëHÐHê�â�Õ�Ð�Ï�Ò�Õ�Ð�Í ë�ÔfÍ ð�Ö�Ø�Ö�Ï�çqë�Ô�ÐHë�ò�÷1Ñ�Î�Í�Ó�Ð�ø^Ð1Ï�Õ�Ö^×�Ð1Ï�Î�ì�Ö�Ï�ÔÎ7Ï�ÐHà£Í ×�êlà�Õ�Ò)ëHÐHÎ�Î�Î�ÐHß�Í ×�Ï�Ö�ëHÎHè�ù�×£Í ê�ê�Ö�Ï�Ö�Ò�׳Ï�ÒqÏ�Ô�Ð�ê�Ö�ú�ÐHÕ�ÐH×�Ï�ß|Ò)ê�ÐHØ�Ö�×�Ú�Ó�Ò�Õ�ß�Í Ø�Ö�Î�ßÏ�Ô�Ð�Í à�à�Õ�Ò�Í ë�Ô£Ö�Î;ê�Ð1Ï�ÐHÕ�ß|Ö�×�Ö�Î7Ï�Ö�ë�Í ×�êlê�Ò)ÐHÎ�×�Ò Ï�ÐFîAà�Ø�Ò�Ö�ÏPÏ�Ô�Ð�Ö�×�Ô�ÐHÕ�ÐH×�Ï�ëHÒ�×�ëHâ�Õ�Õ�ÐH×�ë1çÍ ÎXÐ1ú�ÐHë1Ï�Ö�Ù�ÐHØ�ç�è é Ô�Ð�àfÍ ànÐHÕXëHÒ�×�Î�Ö�ê�ÐHÕ�ÎNÎ�Ò�ß|Ð�Ò Ó�Ï�Ô�Ð-Î�Í ß|Ð-ÐFî�Í ß|à�Ø�ÐHÎXà�Õ�ÐHÎ�ÐH×�Ï�ÐHêqÔ�ÐHÕ�Ð èû Ò»ìNÐ1Ù�ÐHÕHñnÍ�ê�Ö�Õ�ÐHë1Ï�ëHÒ�ß|àfÍ Õ�Ö�Î�Ò�×�ì�Í Î�Ò�ß|Ö�Ï�Ï�ÐHê�ê�â�Ð;Ï�Ò�Î�Ò�ß|Ð;Ö�×�ëHÒ�×�Î�Ö�Î7Ï�ÐH×�ëHÖ�ÐHÎiÖ�×qÏ�Ô�ÐÎ7Ï�Í�Ï�Ð�Î�àfÍ ëHÐHÎ;Ò Ó¹Ï�Ô�Ð�Ó�Î�Í�Í ×�ê¤÷1Ñ�Î�Í�Ó�Ð�ø^Ð1Ï�Õ�Ö<×�Ð1ÏPß|Ò)ê�ÐHØ�ÎHè é Ô�Ð�ê�Ö�ú�ÐHÕ�ÐH×�ëHÐHÎ;ëHÒ�â�Ø�ê�ðnÐÏ�Õ�Í ëHÐHêwÏ�Ò�Ï�Ô�Ð;Ó�Î�Í�Ï�Ò�÷1Ñ�Î�Í�Ó�Ð�ø^Ð1Ï�Õ�Ö>×�Ð1Ï-ëHÒ�×�Ù�ÐHÕ�Î�Ö�Ò�׳ànÐHÕ7Ó�Ò�Õ�ß|ÐHêwÖ�×�ôB÷ýüýö'è

ã)Ò�Ó�Í ÕHñ)Ò�×�Ø�ç�Ï�Ô�Ð-Ù�ÐHÕ�Ö�þfë�Í�Ï�Ö�Ò�×�Ò Ó>Õ�Ð�Í ë�ÔfÍ ð�Ö�Ø�Ö�Ï�ç�à�Õ�Ò�ànÐHÕ7Ï�Ö�ÐHÎdÔfÍ ÎNðnÐHÐH×�ëHÒ�×�Î�Ö�ê�ÐHÕ�ÐHêµñì�Ô�ÐHÕ�Ð�Í Î�ÿ��µÿ���� ß|Ò)ê�ÐHØ�ë�Ô�ÐHë�ò�Ö�×�Ú³Ö�Î;Ø�Ð1Ó0ÏPÓ�Ò�Õ�Ó�âAÏ�â�Õ�Ð�ìNÒ�Õ�òäè�ù�×�ôB÷���öXÍ�Ï�Õ�Í ×�Î�Ø�Í�Ï�Ö�Ò�×Ò ÓXÿ��µÿ����]Ó�Ò�ÕiÎ7Ï�ÐHà�Î�ÐHß�Í ×�Ï�Ö�ëHÎ�Ö�ÎiÚ�Ö�Ù�ÐH×�â�Î�Ö�×�Ú|Í�Ø�Ò�Ú�Ö�ë�à�Õ�Ò�Ú�Õ�Í ß|ß|Ö�×�Ú�Í à�à�Õ�Ò�Í ë�Ôµè

� �������������������������

é Ô�Ð�Í âAÏ�Ô�Ò�Õ�Î�ìNÒ�â�Ø�ê�Ø�Ö�ò Ð�Ï�Ò�ì�Í Õ�ß|Ø�çwÏ�ÔfÍ ×�ò é è! �è�" â�×�Ï�Ï�Ö�Ø�Í�Ó�Ò�Õ�ëHÕ�Ð�Í�Ï�Ö�×�Ú�Ï�Ô�Ð�Ï�Ò)Ò�ØÛiÝ$#>Ý û �%&%NñfÍ ×�êwÓ�Ò�Õ�Ó�Õ�â�Ö�Ï�Ó�â�صê�Ö�Î�ëHâ�Î�Î�Ö�Ò�×�ÎHè

' ��()��*+�������,

-/.1032�465&798;:�8�<=2�4?>&7A@CBEDFD�7G<IHJ4?>&KABE:�L�8�<6B�M�NCO�4?PRQ6S+4�T6U=@�VRWXKA7AYJ@�W=N?8)K�YZQ?8)Y�L=7AM?[]\�79D�Q?WXS?D5&^_^_`;4�abMdcfe)eEg h]iEj3k�l�g mIeEn1oqpsrIt]h�u;eEnvpsr?wyx�eEj?hzpqn1{�|)pqoGeEj}iEj3k�l�j3iEg ~�h1o�h�ebu$��~�hzp�wzt]h1<� WXKAS�@�8�.)�X�E��W�����w�|)pq{=n�wC��e�p�w1hCosj�x�eEt��3{?p�wzn��3|;o�wzj3|1wz< �fBE[�8)`y.)���)�=�E�I�I4�T6��:Z7AM?[�8;:)<.)�����64

- ��032�4�5&798;:�8�<�HJ4�>&KABE:�L�8�<��v4���B�7A@C7G<�B�M�N�O�4�PRQ6S+4���8;:Z79�sU=7AM?[�`�BE�s8;D�U���:�W��R8;:�D�798)`]W��_B� W�\�8;: � >�@C7AYz:�W���:�W=Yz8)`�`FW�:yS�`�7AM?[�`FU=@�VRWXKA7AY�@�W=N?8)K�YZQ?8)Y�L=7AM?[�\�79D�Q?WXS?Dy5&^_^_`;4 abM¡ eEn1tCiEg�¢£w;psr=e)k�h�osj�x�eEt��3{?p�wzn�l�oGkIw�k¥¤�w1h1o9m�j�< � WXKAS�@�8�.)¦�����W�����w�|)pq{=n�w���e�p�w1h�osjx�eEt��3{?p�wzn��3|;o�wzj3|1wz<?�fBE[�8)`�¦E���?�6.E4 T6��:Z7AM?[�8;:)<=§�W � 8)@�VR8;:$�E�����=4

- ��0 � 4�5 ¨F8)`�`F8�<�©$4�ª 8;WXM�BE:ZN+<)B�M�Nv2�4�«�W�L6L�8)N?8)@�4­¬­7AM�N�7AM?[&VfS?[X`+7AMv2�K9�fQ�B&@C7AYz:�W���:�W=Yz8)`�`FW�:S�`�7AM?[�`�BED�7A`F®fBEVf7AKA79D�UC`FWXK � 8;:Z`;4�abM�¯&nFe)|1wZw�kEosj6mEh�ebuvpsr?w�°�±Xpsry²Zjfp�wzn1j3i�pqoGeEj3iEg&x�eEj)u)wzn�wzj3|1webu�x�eEt��3{?p�wzn1³�l�oGkIw�kµ´fwzn1o ¶�|Zi�pqoGeEj�< � WXKAS�@�8·�=.;�X�¸W�����w�|)pq{=n�w¹��e�p�w1h¹osjºx�eEt��3{?p�wzn�3|;o�wzj3|1wz<?�fBE[�8)`J»I��»��I»I¦�»?4�T6��:Z7AM?[�8;:)<?�E���?.E4

- »E035�4]5�:ZBE:ZN+<v5&7AN?WX79D�«}49<�¬­7AM?L�8)K�2�<�ª�BE:�WXS�`�`�7AM�798�¬�49< � 8;D�79D£2�49< � 8;DF:ZS�Y;Y;7�ª�49< � Q+4T=YZQ�M?W68;VR8)K98)M+<�B�M�N�«�Y;¼$8)M?½)798 � 4¾��~�hzp�wzt]h·iEj3k��3ebuzpq¿�iEn�w ´fwzn1o ¶�|Zi�pqoGeEjÀ³�¢}e)kIwzg ³x�r?w�|zÁ�osj6m}c3w�|zrIj�oGÂ;{fw1h�iEj3k}cfe)eEg h14�T6��:Z7AM?[�8;:)<?�E���?.E4

- ��032�4I>&7A@CBEDFD�7G<EHJ4X«}4I>&KABE:�L�8�<�HJ4IÃ_7AS�M�YZQ�79[XKA7AB=<�¬�46Ã_7AS�M�YZQ�79[XKA7AB=<�«}4 � 7A`FDFW�:�8�<X«}4��JW � 8;:Z7G<�v4!T68;VfB�`FD�7AB�M�7G< B�M�N·2�4�©!B�Y;YZQ?8)KAKAB=4�§�S3T?«��Ä�6Å�2�M·W��R8)M�`FWXS?:ZYz8�DFW6WXK��sW�:�`FU=@�VRWXKA7AY@�W=N?8)K�YZQ?8)Y�L=7AM?[?4ÆabMǯ&nFe)|1wZw�kEosj6mÈebu�psr?w�°;É�psr¾²Zjfp�wzn1j3i�pqoGeEj3iEgdx�eEj)u)wzn�wzj3|1wµeEjx�eEt��3{?p�wzn1³�l�oGkIw�k¾´fwzn1o ¶�|Zi�pqoGeEj¾Ê1x l]´�Ë Ì=ÍXÍ�Ì;Î�< � WXKAS�@�8���»X�E»ÏW��¥��w�|)pq{=n�w£��e�p�w1h}osjx�eEt��3{?p�wzn��3|;o�wzj3|1wz<?�fBE[�8)`������)�=��¦�»?4�T6��:Z7AM?[�8;:)<?ÐXS�K9U¥�E���X�64

÷ýü

Page 40: BMC’03 - JKUfmv.jku.at/papers/bmc03-preliminary-proceedings.pdfBMC’03 Boulder, Colorado, USA. ... Alessandro Cimatti (IRST, Italy) Raanan Fraer (Intel, Israel) Danny Geist (IBM

ÑIÒfÓ1ÓZÔ9Õ�Ö¹×�Ø�ÖfÕ6Ù

Ú Û�Ü3Ý�Þ+ß&àAáCâEãFã�àGäfå}Þ3æ�àAçFãFè�é�ê�äRå}Þ3ëJè�ì�ê;éZàGä3â�í�î�ëvÞ+ï6ê;ðfâ�çFã�àAâ�í�àGÞ�ñbíIãFê;ò�éZâEã�àAí?òyó&ô_ô�õ�ðfâ�çFê)îâ�í�î�ï=Ý�ö&õ�ðfâ�çFê)î}çF÷=á�ðRèXøAàAù�á�è=î?ê)ø�ùZú?ê)ù�û=àAí?ò?Þ�ñbí�ü&ýFþ)ÿ������������¥þ ���������������zý��������Gþ������� þEý������=þ��¸þ��! RýFþ������"�zý���þ �$#�þ�%'&(�������$)�*+�(���(%,�1äfÝ.-�éZàAø0/�1�12/6Þ

Ú 3)Ü54?Þ�ß�Þ�ß�è�é�ðRê;ãFã;Þ76�ìEâ�ø98�âEã�àAí?ò]î?ê)â�î�ø9è=ù�û�î?ê;ãFê)ùzã�à9èXí�á�ê;ã�ú?è=î�ç;:sè�é�ùzèXí�ù<8?é�é�ê)íIã&çFè�:sã�=&âEé�ê�Þ�?>@>@>BA?ý?���C�<�XÿD���Gþ��C�Cþ���)3þ �(��E@�Eý���>F�����5���zý�����ä�/�/CGIH2JZäLKDM�M�Û6Þ

Ú N�Ü�O]Þ+ô_à9ê;û�ê;é�ã$â�í�îQP�Þ åSRê;ã�à9ì=à9ê;é)Þvæ­âEé�ã�àAâ�ø­ùzèXáCá,8?ã�âEã�à9èXí·â�í�î¹ãFéZâ�ùzê)ç;ÞvñbíUTV�����W&�þ)þ+��þ ��;þEý�%X���Y�Z����[��D����\^]�þ��Z_a`�ä�-fâEò�ê)çcbWd23<efd�H+b?Þ�ï-�éZàAí?ò�ê;é)ä=ó�ê;éZøAàAí+ägKDM�M23IÞ

Ú M�Ü�h�Þji�ê)ø k�â�í?û�è?Þ ó�è28�í�î?ê)îºé�ê)â�ùZú�âEðfàAøAà9ã�÷ºùZú?ê)ù�û=àAí?òl=�à9ã�úm-�é�è=ùzê)ç�ç�çFê)áCâ�íIã�àAù;ç;Þ ñbíü&ýFþ)ÿ�������������þ �n���C�.o�pW���V�������zý��������Gþ������L#�þ��D�D�zý��(�3ÿ���þ��q#�þ��3ÿ<[=ý1ý��(�3ÿ<*$A0�C��þEý�*Eä�-fâEò�ê)ç/fKDNDef/�H�/6ä+Ýr8?ò28�çFã./�1�1CKEÞ

ÚsK<1�Ü�h�Þfi�ê)ø k�â�í?û�è�â�í�î�ñ1Þft�à9ê)á�ê)ø�uâ=Þ�ó�è28�í�î?ê)î$v=öcv�á�è=î?ê)ø3ùZú?ê)ù�û=àAí?ò,=�à9ã�úyçFã�âEðfø9ê�á�è=î?ê)øAç;ÞA0�C��þEý�*m�����Àü&ý?�XÿD���Gÿ�� þ �xw þ���Gÿ ü&ýFþ��ý?��%^%^���zy(A+ü@w�üL{�äX/�1�12H6Þ Ý�ù;ùzê<-�ãFê)î|:sè�é-�8?ðføAàAù;âEã�à9èXí+ÞgG�ß�èXë�ë�}fâEé�~_à9ì�} ù;ç;Þ v����+12H�12d�1�b21WJZÞ

ÚsK�K1Ü3ö$Þ�Ý�Þ;428�íIãFã�àAøAâ=Þ�ó�è6èXø9ê)â�í ù;à9éZù<8�à9ã�ãFè6èXøAç;ä�å�â)÷�/�1�12H6Þx�C��2�c�?������n�����f���I��C�F�����W�� �C����C����W��f��������5������Þ

ÚsKD/�Ü3ö$Þ�Ý�Þj428�íIãFã�àAøAâÀâ�í�îºñ1Þ^t�à9ê)á�ê)ø�uâ=Þ ö�è�=&âEéZî�ç�â�íºê<��ù;à9ê)íIã¸ã�âEðfø9ê)â�8 á�ê;ã�ú?è=îm:sè�éðRè6èXø9ê)â�í¹ù;à9éZù<8�à9ã�ç�âEã�àAç?�fâEðfàAøAà9ã�÷¥ãFê)çFã�àAí?ò?Þ�ñbíS#�þ�%.��[C�"�����Gþ�������w þ���GÿX�^#0wSpf�2�2���; 7�sý��(��������zý���������������#�þ��D�D�zý��(�3ÿ��zä�ì�èXø98�á�ê�KDN�ÛfK�è�:gwY��ÿD��[=ý��n��þ������n���X��ý(��� ��ÿ<�I����������(��� �Z�(�3ÿ��zä-fâEò�ê)çrd�d�HDefd�Û23Iägv èXí�î?èXí+äC�rh�ä�428�ø9÷�/�1�1�1=Þ+ï-�éZàAí?ò�ê;é)ä=ó�ê;éZøAàAí+Þ

ÚsKDH�Ü3ö$Þ�428�ç�ç�àAøAâ=Þ Ý ó�å�ß ãFè6èXø�ãFéZâ�í�ç�øAâEã�àAí?ò v=ö�ï=ç¹ãFè�ðRè6èXø9ê)â�í ù;à9éZù<8�à9ã�ç;ä$å�â)÷l/�1�12H6Þ�C��2�c�?������n�����f���I��C�F�����W� � �f���g��2�W�¡W�W¢2�f��Þ

ÚsK(bEÜ3öJàAá�è�v�âEãFìEâ�øAâ=Þ767��ù;à9ê)íIã�á�è=î?ê)ø�ùZú?ê)ù�û=àAí?ò�è�:+ç�â�:sê;ã�÷j-�é�è�-Rê;é�ã�à9ê)ç;Þ!ñbí$£}þD�W�(��#Y�C��ÿ(�+���)3þ �(��E@�Eý��D_7oW�����$�������zý��������Gþ������Y)=ü@�?� � þEý������=þ��3äfì�èXø98�á�ê�/�Û+bWN�è�:awY��ÿD��[=ý�����þ������¤���#�þ�%.��[C���zýV)3ÿ<�"�(�3ÿ��zäC-fâEò�ê)ç¤3�b+efN�N6Þ ï-�éZàAí?ò�ê;é)äC/�1�12H6Þ

ÚsKDd�Ü+ï3ÞIå�ê)øZ¥;ê;é�â�í�îyï3ÞXë,uèXá�ê;é)Þ­ô�ê)â�î�ø9è=ù�û�ùZú?ê)ù�û=àAí?òV8�ç�àAí?ò$í?ê;ã78�íC:sèXøAî�àAí?òXç;Þ ñbí�ü&ýFþ)ÿ����������þ �§¦����S�������zý��������Gþ������¨#�þ��D�D�zý��(�3ÿ���þ��©#�þ�%.��[C���zýU�r�I�W���ª]��zý�� ��ÿ������Gþ��©y�#0�,]r« ¦C¬ {�äì�èXø98�á�êQKD/�d+b�è�:.wY��ÿD��[=ý��X��þ������X��� #�þ�%.��[C���zý')3ÿ<�"�(�3ÿ��zä0-fâEò�ê)ç^H�d�/DefH�Û�H6Þ�ï-�éZàAí?ò�ê;é)ä428�í?êjKDM�M23IÞ

ÚsK)Û�ÜRå}Þ�å�èXçFû�ê<=�àAù(¥�ä�P�Þ�å�â�î�à9òXâ�í+ä+v�Þ�­Rú�âEè?ä2­Rú�â�í?ò.v�Þ9äEâ�í�î�å�â�øAà9û�ï3Þ�ß&ú�â+®�}+6�í?òXàAí?ê;ê;éZàAí?òâ�í�ê<��ù;à9ê)íIã_ï=Ý�ö çFèXø9ì�ê;é)Þ�ñbíq`W¦�����¯^�����Z��¨�r[C��þ�%X�����Gþ��°#�þ��D�D�zý��(�3ÿ��zä5428�ø9÷$/�1�1CKEÞ

±�²

Page 41: BMC’03 - JKUfmv.jku.at/papers/bmc03-preliminary-proceedings.pdfBMC’03 Boulder, Colorado, USA. ... Alessandro Cimatti (IRST, Italy) Raanan Fraer (Intel, Israel) Danny Geist (IBM

³a´Uµ7¶ ·�¸j¹�º�»�¼�½�¾½�¿�À<º�Á§Â�»<º2Ã�½<Ä(¿

ŧÆ!ÇÉÈ°Ê�Ë+Ì+ÍÏÎÐÊ�ÇÒѧӧÔ7Õ�Ô7Ì+Ê�Ö§Õ�Ë ×mØ�ÍcÙ§Ö§Ì+Ú!Ó§Ø�ÛÝÜWÊ�ÞŧÊ�Ë+ß!Ì+Ö§àâáãÕ�ÇÒØ�Û

ä�åVæèç�énê@ënì2ënénç�ínî;ïñð�ínênð�ínòôó§ç�õöç�ínéª÷UçLø�ù�ù�úèû§ü�ënýcþÿ�������������� ���������������������������������������������! �"�������"#�

$%� �'&(����)#�'�*+��-,.��� � )#*%/ &(��� ���,10���/ �����2/ ��0�����34,65738$% 5:9

;�<>=@?BA�C D�?E�FHG:IKJ�FHL�I�M J�IKN'M OQPSRTG:UWV M OSFHL�J�XYIKZKPS[ ZKFH\�PSUHR]FHR VTFHR FHOS^WJ�PSJ_UHN`J�^WJ�\�IKG:J�a>b IKL�I:\�b I:V PSJ�c\�PSR ZK\�PSUHRdFHG:UHR eT\�b IfZ#b UHPSZKIKJgZKUHRW\�L�UHOSOSIKVihW^jV PSklIKL�IKRW\:ZKUHG:XYUHR IKRW\�JnmoN'UHL�PSR J�\�FHR ZKIKp-\�b IJ�^WJ�\�IKGqFHR V�PS\�J4IKRWrWPSL�UHR G:IKRW\�s1PSJ1G:FHV ItIKuWX OSPSZKPS\�v�w@R�\�b PSJ1X FHXYIKL�p a4ItN'UHL�G_M OSFH\�I7FHR V:ZKUHG:cX FHL�I8r�FHL�PSUHM J�J�^WG_hYUHOSPSZ�ZKUHG:X M \�FH\�PSUHR FHO1\�IKZ#b R PSxWM IKJ_N'UHL�V IKZKPSV PSR e�IKuWPSJ�\�IKR ZKI�UHN`a>PSR R PSR eJ�\�L�FH\�IKeHPSIKJ�v:y>b I�eHFHG:I�J�\�L�M ZK\�M L�I_PSJ-eHPSrHIKRnPSG:X OSPSZKPS\�OS^KpzFHR V+\�b I_a>PSR R PSR e�ZKUHR V PS\�PSUHRnPSJ-UHN\�b I-N'UHL�G|{@} ��� ���/�~W� N'UHL�J�\�FH\�I.X L�IKV PSZKFH\�IKJz}�FHR V ~ v�y>b I7[ L�J�\4\�IKZ#b R PSxWM I.IKG:X OSU2^WJ�J�^WG:chYUHOSPSZ�[ uWXYUHPSRW\�ZKUHG:X M \�FH\�PSUHR�M J�PSR e8UHL�V IKL�IKVfh PSR FHL�^gV IKZKPSJ�PSUHR�V PSFHeHL�FHG:J8� ���Svty>b I.J�IKZKUHR V\�IKZ#b R PSxWM I.Z#b IKZ#�WJ7N'UHL>\�b I.IKuWPSJ�\�IKR ZKI�UHN�J�\�L�FH\�IKeHPSIKJ7\�b FH\>IKR J�M L�I-a>PSR R PSR e�a>PS\�b PSRn�:J�\�IKX J�pN'UHL`F8M J�IKL`J�XYIKZKPS[ IKV�hYUHM R V���p6hW^�L�IKV M ZK\�PSUHR�\�U�\�b I-J�FH\�PSJ�[ FHh PSOSPS\�^�UHN�xWM FHRW\�PS[ IKV�hYUWUHOSIKFHRN'UHL�G_M OSFHJ�v`��PSR FHOSOS^Kp6\�b I7hYUHM R V IKV:ZKFHJ�I7ZKFHR�FHOSJ�U�hYI>J�UHOSrHIKV�hW^8L�IKV M ZK\�PSUHRg\�U_J�FH\�PSJ�[ FHh PSOSPS\�^UHN%UHL�V PSR FHL�^�hYUWUHOSIKFHR8N'UHL�G_M OSFHJ�p FHR V8a4I�V PSJ�ZKM J�J�\�a4U�\�IKZ#b R PSxWM IKJ�p UHR I�h FHJ�IKV8UHR8IKR ZKUWV PSR e\�b I�J�\�L�FH\�IKeH^�\�L�IKIKp�FHR V�UHR I_h FHJ�IKV�UHR�IKR ZKUWV PSR egFga>PS\�R IKJ�J7J�M h eHL�FHX b p�N'UHL7L�IKV M ZK\�PSUHR�\�U� �H� v`�nI7ZKUHG:X FHL�I7\�b Itr�FHL�PSUHM J4FHX X L�UHFHZ#b IKJ`UHR�\�a4U�IKuWFHG:X OSIKJ4M J�PSR e�IKuWPSJ�\�PSR e_\�UWUHOSJ`J�M Z#bFHJ>��� ���l�n� �H�Sp����l��� � � ���Sp � ���1���W�l�n� �H���Sp��.� �W�+� �H� �Sp6¡`���(�l�1¢S£¤� �H¥��Sv

¦ §(¨�©%ª6«�¬8­8®Q©%¯#«t¨

°1±Y²�³_´�µ�¶o·Y¸Bµ�¶o´�¹nº´�»:¼´�½o· ¶o¹Y¾f¾�¸�³_² ¼z¶o¹nº´�»�³f¸B½�¸B¹1¸B½o¿�¼¶�¼4´�»�¶o¾�¶o¹1¸Bµ�²�À+Á.¶oµ�±ÃÂ1± ÄY»�ÅK±1Æo¼¼¿ ¹ µ�±Y² ¼¶�¼�ÇY»�´�ÈY½o² ³|¶o¹dµ�±Y²�Å�´�¹ µ�²�É µg´�º:¸BÄYµ�´�³f¸Bµ�¶oÅ ¸B½o½o¿Ê¼¿ ¹ µ�±Y² ¼¶oË�¶o¹Y¾¤Å�¶o»�Å�ÄY¶oµ�¼-º»�´�³¼Ç�²�Å�¶oÌYÅ ¸Bµ�¶o´�¹1¼�ÍoÎ�ÏBÐ�ÑdÒ�¸�³_² ¼.±1¸�·W²Ó¼¶o¹YÅ�²nµ�±Y²�¹ÃÈ�²�Å�´�³_²�Ç�´�ÇYÄY½�¸B»g¶o¹Ãº´�»�³f¸B½�³_²�µ�±YÔ´%À1¼1Á.¶oµ�±!·Y¸B»�¶o´�Ä1¼�¸BÇYÇY½o¶oÅ ¸Bµ�¶o´�¹1¼1¶o¹YÅ�½oÄYÀY¶o¹Y¾�Å�´�¹ µ�»�´�½�´�ºzÀY¶�¼Å�»�²�µ�²�²�·W²�¹ µ�¼¿�¼µ�² ³f¼�ÍoÕ�ÕBÐ�Ö»�² ¸B½o¶oË ¸BÈY¶o½o¶oµ�¿×¸B¹YÀq¼¿ ¹ µ�±Y² ¼¶�¼�Ö_¸B¹YÀq³_´%ÀY²�½oÔ@ÅK±Y²�ÅKØ ¶o¹Y¾iÙ�Ô@Å ¸B½oÅ�ÄY½oÄ1¼�º´�»�³.ÄY½�¸B²dÍoÕBÚ�Ð�ÑÃÛo¹º´�»�³f¸B½ ·W²�»�¶oÌYÅ ¸Bµ�¶o´�¹1ÖWµ�±Y²�¿�±1¸�·W²g¼²�·W²�»�¸B½1¸BÇYÇY½o¶oÅ ¸Bµ�¶o´�¹1¼�¶o¹�·W²�»�¶oº¿ ¶o¹Y¾:»�² ¸BÅ�µ�¶o·W²g¼¿�¼µ�² ³f¼Á.±Y²�»�²�µ�±Y²]¸B¾�²�¹ µ�¼tÅ�´�³_ÇY»�¶�¼¶o¹Y¾Tµ�±Y²]¼¿�¼µ�² ³Ü¸B»�²�· ¶o²�Át²�Àݸ�¼tÇY½�¸�¿W²�»�¼7´�º�¸g¾�¸�³_² Þ.¶o¹³_´%ÀYÄY½�¸B»�·W²�»�¶oÌYÅ ¸Bµ�¶o´�¹ßÍoÎ�àBÐ�Öl¶o¹á¼¿ ¹ µ�±Y² ¼¶�¼>´�º4º´�»�³f¸B½z¶o¹ µ�²�»�º�¸BÅ�² ¼�µ�´¤³_´%ÀYÄY½o² ¼_ÍoâKÐ-¸B¹YÀ¶o¹Ã¸BÇYÇY»�´�¸BÅK±Y² ¼`µ�´fÅ�´�³_Ç�´�¼¶oµ�¶o´�¹1¸B½z·W²�»�¶oÌYÅ ¸Bµ�¶o´�¹áÍoÎWÖoÕBÐ�Ñ

ã�ä�å-æ2ç è ézê�ë�ì�í�î�ï�ð�ï�í�ì�ñQò>ó�ñ�ì�ëQò.ì�ô�ï�õ(ö�÷�ø�ù�ðQú'ï�û�ü�ñ�ñQúoü�í�ïýQþ�ÿ �zÿ ��������� ÿ �-ÿ � ������������@ÿ ��� ��ýQþ ��� � ���������@ÿ �����Qÿ �������� � ÿ �@þ ���ÿ �

�� � !"������ÿ $#���!"��zÿ ��ýQþ ������!�ÿ ��&%����'��� !"���( #ÿ �� �)�*'+-,/.�.�.�0 »�¼�Ã<»212½<»<º 0 ¿�¼�3�¼�Ä54<À76�»�3+»(¿8694�Ã

Page 42: BMC’03 - JKUfmv.jku.at/papers/bmc03-preliminary-proceedings.pdfBMC’03 Boulder, Colorado, USA. ... Alessandro Cimatti (IRST, Italy) Raanan Fraer (Intel, Israel) Danny Geist (IBM

:<;�=->�?�@A?�=/;�BDC&EF;�GH;�B�=JIFK8?�L

M�N�OPN�Q7RAS2TUQ7V�W<RAN8XYQ7ZAN8W[Q7\�\�X^]^S�Q7ZA]^_&V�ODT�QA`�N�X^N8W<ZA_a`�Q7RA]^N8ZYbc_&dfe�Q&ghNidP_&R gkj�XYQ7ZA]^_&V�OOPj�S2TlQ&Om]^V�n�V�]^ZANoe�Q&ghN�Om_&Vpn�V�]^ZANqe&R Q7\�T�OArsS8_&V�S8j�RARAN8V�ZUgkj�X^ZA]^t�\�XYQAb�N8Rue�Q&ghN�O<Q7V�We�Q&ghN�Oa_&Vv\�j�OPT�W�_ wkVxOPbDOPZAN�gyOqz^{7|&}Y~���_ w�N8`�N8R r�ZAT�NpOP]Ygh\�X^N�OPZqe�Q&ghN[ZAT�Q7ZHgh_�OPZOP_&X^j�ZA]^_&V�O�S8_�gh\�j�Z Q7ZA]^_&V�Q7X^X^b�RAN8X^b�_&V�]YO�ZAT�NoZYw�_&t�\�XYQAb�N8R�RAN�Q7S2T�Q7��]^X^]^ZYb�e�Q&ghNo_&V�Qn�V�]^ZANae&R Q7\�T�~h� j�S2T�Qme�Q&ghNa]YO�\�XYQAb�N8W���N8ZYw�N8N8V�ZYw�_u\�XYQAb�N8R OAr�ZAT�N��2�9�2�"����Q7V�WoZAT�N�������P���/���������"r�Q7V�W�ZAT�Nqe�Q&ghNq\�RA_&��X^N�g�]YO�ZA_HS2T�N8S2��wkT�N8ZAT�N8RJZAT�N�OPbDOPZAN�g�T�Q&O<Qwk]^V�V�]^V�e�OPZAR Q7ZAN8e&bHZAT�Q7Zcwk]^X^X�dP_&RAS8NuZAT�N�e�Q&ghN�dPRA_�g�ZAT�Nu]^V�]^ZA]YQ7X�\�_�OP]^ZA]^_&V ZA_pOP_�ghNe&_�Q7XD\�_�OP]^ZA]^_&V�r�V�_[gyQ7ZAZAN8RiT�_ w¡ZAT�N¢N8V�`�]^RA_&V�ghN8V�Zh\�XYQAbDOA~

£�T�_&j�e&T[ZAT�NcZAT�N8_&RAN8ZA]^S�Q7X$S8_�gh\�X^N8¤�]^ZYb�_&dhOP_&X^`�]^V�e�`�Q7RA]^_&j�Ose�Q&ghN�Os]^V[ZAT�NcX^]^ZAN8R Q7tZAj�RAN�]YO¥w�N8X^X-j�V�W�N8R OPZA_-_-W�r ZAT�N8RANFT�Q&O���N8N8V�RAN8XYQ7ZA]^`�N8X^baX^N�OAO¥N8¦�_&RAZkOP\�N8V�Z�]^Vc]^W�N8V�ZA]^dPb�]^V�eT�_ w§ZAT�Na\�_ w�N8RAdPj�XiOPbDgk��_&X^]^ScZAN8S2T�V�]^¨�j�N�O�j�OPN8W�]^V�gh_-W�N8X^t�S2T�N8S2��]^V�e©dAQ7RANa]^V�OP_&X^`�]^V�ee�Q&ghN�O�wk]^ZATªXYQ7RAe&NoOPZ Q7ZAN8t7OP\�Q7S8N�OA~�«^VªZAT�]YO�\�Q7\�N8R rfw�Ny]^V�]^ZA]YQ7ZANoOPj�S2TvQ7VUN8¦�_&RAZ���b�QS8_�gh\�Q7R Q7ZA]^`�NmQ7V�W¢N8¤�\�N8RA]YghN8V�Z Q7XDOPZAj�W�b�_&d�OP_&X^`�]^V�e�OP]Ygh\�X^NsRAN�Q7S2T�Q7��]^X^]^ZYb�e�Q&ghN�O'¬AQ7j�e&tghN8V�ZAN8WHwk]^ZATvQ©OAQ7dPN8ZYb[S8_&V�W�]^ZA]^_&V�­�j�OP]^V�eoZAN8S2T�V�]^¨�j�N�OkZAT�Q7Z¢j�OPNq® =-= OAr�¯ ;�° t7OP_&X^`�N8R OQ7V�W�±k²�³´t7OP_&X^`�N8R OA~yµªN�gh_-W�N8X�e�Q&ghN�OaOPbDgk��_&X^]^S�Q7X^X^bUj�OP]^V�eo��_-_&X^N�Q7VU`�Q7RA]YQ7��X^N�OaQ7V�WOPj�S8S8]^V�S8Zc��_-_&X^N�Q7V¶N8¤�\�RAN�OAOP]^_&V�O�W�N�OPS8RA]^��]^V�e[ZAT�NuZAR Q7V�OP]^ZA]^_&V�Ok·¸ZAT�NJN8¤�\�X^]^S8]^Zce�Q&ghNZAT�]YO$W�N8n�V�N�O�w�_&j�X^Wo��N�ZYb�\�]^S�Q7X^X^b©N8¤�\�_&V�N8V�ZA]YQ7X']^V©ZAT�NuOP]^¹8Na_&d�ZAT�N¢W�N8n�V�]^ZA]^_&V�~

£�T�N¢OPZ Q7V�W�Q7RAWqQ7ZAZAR Q7S8ZA_&RAt7OPN8ZkQ7\�\�RA_�Q7S2TcZA_yOP_&X^`�N�RAN�Q7S2T�Q7��]^X^]^ZYbae�Q&ghN�O¥]YO$QhOP]Ygh\�X^Nn�¤�t�\�_&]^V�ZmQ7X^e&_&RA]^ZAT�gvZAT�Q7ZsS�Q7V<N�Q&OP]^X^b���N�]Ygh\�X^N�ghN8V�ZAN8Wuj�OP]^V�eJ® =-= OA~�£�T�N8RAN�Q7RAN�ZYw�_��]^V�W�O�_&dF® =-= t���Q&OPN8W�OP_&X^`�N8R Osw�Naj�OPN�º :<»½¼&>�; wkT�]^S2T�]YO�QJgh_-W�N8X^t�S2T�N8S2��N8RmZAT�Q7Z�S�Q7VW�]^RAN8S8ZAX^byT�Q7V�W�X^N�OP\�N8S8]^n�S�Q7ZA]^_&V�O']^VUQ�e�Q&ghN�X^_&e&]^S�S�Q7X^X^N8WªQ7X^ZAN8RAV�Q7ZA]^V�eaZAN�gh\�_&R Q7X¥X^_&e&]^S¬ I'°&K ­�Q7V�W :<?�¼&¾½¿ wkT�]^S2T�]YO�QuÀft�S�Q7X^S8j�X^j�O�gh_-W�N8X�S2T�N8S2��N8RJN�OP\�N8S8]YQ7X^X^b ZAj�V�N8WÁQ7V�WN8¤�ZAN8V�W�N8WoZA_yT�Q7V�W�X^N�Àft�S�Q7X^S8j�X^j�O$dP_&R gkj�XYQ&OA~

Â�_&Ry\�RA_&\�_�OP]^ZA]^_&V�Q7XcOP_&X^`�N8R OArFw�N�S8_&V�OP]^W�N8RJ��_&j�V�W�N8W�RAN�Q7S2T�Q7��]^X^]^ZYb�e�Q&ghN�OA~pµªNn�R OPZ�S8_&V�OP]^W�N8R�e�Q&ghN�O�wkT�N8RANhw�NyQ&OP�ywkT�N8ZAT�N8R�ZAT�N�OPbDOPZAN�gÁT�Q&OFQ�OPZAR Q7ZAN8e&byZAT�Q7Z�wk]^X^XN8V�OPj�RAN<ZAT�Nye�Q&ghNyRAN�Q7S2T�N�OkZAT�Nye&_�Q7X�wk]^ZAT�]^VÄÃUOPZAN8\�OAr�wkT�N8RANUÃJ]YO¢Qcj�OPN8RAt7OP\�N8S8]^n�N8W\�Q7R Q&ghN8ZAN8R ~�£�T�N©V�Q7ZAj�R Q7XFw�QAb¶ZA_[N8V�S8_-W�N�ZAT�]YO�Q&O�Q<\�RA_&\�_�OP]^ZA]^_&V�Q7X¢OAQ7ZA]YOPn�Q7��]^X^]^ZYb\�RA_&��X^N�gÄ]YODj�OP]^V�e©Q�¨�j�Q7V�ZA]^n�N8Wu��_-_&X^N�Q7V<dP_&R gkj�XYQ&r&wkT�N8RANhZAT�N8RAN�]YO�Q�\�RAN8n�¤y_&dsQ7X^ZAN8RAtV�Q7ZA]^V�ea¨�j�Q7V�ZA]^n�N8R O'_&dfX^N8V�e&ZATª{/ÃhZAT�Q7Z�S�Q7\�ZAj�RANyQaOPZAR Q7ZAN8e&bydP_&RsZAT�N�OPbDOPZAN�gÁdP_&X^X^_ w�N8W��b¶Q¢��_-_&X^N�Q7VodP_&R gkj�XYQ¢ZAT�Q7Z�S2T�N8S2�DOFwkT�N8ZAT�N8RmZAT�N©OPZAR Q7ZAN8e&bq]YO�]^V�W�N8N8W[wk]^V�V�]^V�e�dP_&RZAT�N�OPbDOPZAN�gy~$µªNiZAT�N8V<j�OPN¢±k²�³�OP_&X^`�N8R O�¯ ¿ G�Å L�»½Å z^Æ&Ç7}Yr-± ?�; ³5³ K8¿ z^{&È7}�Q7V�Wq± ? ² ¿ z^Æ&É2}ZA_�OP_&X^`�NaZAT�N�OPNadP_&R gkj�XYQ&OA~

«^V RAN8S8N8V�Zyb�N�Q7R OAr�ZAT�N8RAN�T�Q&Oi��N8N8VÁQ[OP]^e&V�]^n�S�Q7V�Zy]^V�ZAN8RAN�OPZy]^V N8V�e&]^V�N8N8RA]^V�e�¯ ;�° tOP_&X^`�N8R OsZAT�Q7ZhT�Q&O�RAN�OPj�X^ZAN8W[]^V�`�N8RAbqN8ÊyS8]^N8V�ZJOP_&X^`�N8R OAr¥wkT�]^X^NcZAT�N�N8¦�_&RAZh]^V�OP\�N8N8W�]^V�ej�\ ±k²�³uOP_&X^`�N8R O�T�Q&O���N8N8VURAN8XYQ7ZA]^`�N8X^boX^N�OAOA~mµªN�T�N8V�S8NoQ7XYOP_�S8_&V�OP]^W�N8R¢N8V�S8_-W�]^V�e�O�_&de�Q&ghN�O$]^V�ZA_©¯ ;�° \�RA_&��X^N�gyOAr½]^VqZYw�_<W�]^¦�N8RAN8V�Z�w�QAbDOA~�«^VqZAT�N¢n�R OPZcQ7\�\�RA_�Q7S2T�r-w�N¢j�OPN¯ ;�° ZA_�e&j�N�OAOiQ�wk]^V�V�]^V�e[OPZAR Q7ZAN8e&bJZARAN8N�_&d'W�N8\�ZAT Ã�¬PZAT�N�ZARAN8N�]YO�N8¤�\�_&V�N8V�ZA]YQ7XD]^V Ã½­A~£�T�]YO�S�Q7V���N�OPN8N8V[N�OAOPN8V�ZA]YQ7X^X^b�Q&O�Ë�j�V�wk]^V�W�]^V�e&ÌuZAT�N©Q7X^ZAN8RAV�Q7ZA]^V�eJ¨�j�Q7V�ZA]^n�S�Q7ZA]^_&V[]^VZAT�Nc±k²�³kdP_&R gkj�XYQcQ7��_ `�N�]^V�ZA_qQ�ZARAN8Nm_&d�N8¤�]YOPZAN8V�ZA]YQ7XD¨�j�Q7V�ZA]^n�S�Q7ZA]^_&V�OAr-��bJS8_&V�`�N8RAZA]^V�eN�Q7S2T�j�V�]^`�N8R OAQ7X½S2T�_&]^S8N�ZA_�Q7X^X�\�_�OAOP]^��X^N�S2T�_&]^S8N�OA~'µªN�T�N8V�S8N�e&N8ZkQ7V�N8¤�\�_&V�N8V�ZA]YQ7X^t7OP]^¹8N8W¯ ;�° dP_&R gkj�XYQ�wkT�]^S2T�]YOhOAQ7ZA]YOPn�Q7��X^N�]^d�Q7V�Wo_&V�X^b�]^d�ZAT�N8RAN�]YO�QJOPZAR Q7ZAN8e&b�ZAT�Q7Z�wk]^V�O�]^VÃ�OPZAN8\�OAr'Q7V�Wqw�Naj�OPN¢ZAT�Ny¯ ;�° t7OP_&X^`�N8R O�Í�Î >�; ³5³�z^Æ&Ï7}FQ7V�WU® ¿ L/¾½G�Ð�B z^Æ&{7}Y~

«^VcZAT�N¢OPZAR Q7ZAN8e&b¢ZARAN8NFe&j�N�OAOPN8WoQ7��_ `�N�r�OPN8`�N8R Q7X�V�_-W�N�O�_&d�ZAT�NFZARAN8NFS8_&j�X^WcRAN8\�RAN�OPN8V�ZZAT�NuOAQ&ghN¢\�_�OP]^ZA]^_&Vq]^VqZAT�Nae�Q&ghNuQ7V�WqZAT�N¢ZARAN8N¢N8V�S8_-W�N�O�ZAT�N�OPZAR Q7ZAN8e&]^N�O$dPRA_�g�ZAT�N�OPN

{

Page 43: BMC’03 - JKUfmv.jku.at/papers/bmc03-preliminary-proceedings.pdfBMC’03 Boulder, Colorado, USA. ... Alessandro Cimatti (IRST, Italy) Raanan Fraer (Intel, Israel) Danny Geist (IBM

Ñ<Ò�Ó-Ô�Õ�ÖAÕ�Ó/Ò�×DØ&ÙFÒ�ÚHÒ�×�ÓJÛFÜ8Õ�Ý

Þ�ß-à�á�âaâPá8ã�ä7å ä7æAá8ç^è�é[ê ë^Þ�ì8áJåAá�ä7ì2í�ä7î�ë^ç^ë^æYèªï�ä&ðhá�â�í�äAñ�áJò8á8åAß&ó7ðhá�ðhß&åAè�âPæAå ä7æAá8ï&ë^á�âAô�õ�áÞ�á8á8àoÞ�ß&æ�ï&ö�á�âAâ�âPá8ã�ä7å ä7æAá©âPæAå ä7æAá8ï&ë^á�â�÷PåAß�ðlæAí�á�âPáaÞ�ß-à�á�âAémø^ÞoæAí�á�âPá8ì8ß&Þ�à�åAá8à�ö�ì8æAë^ß&ÞæAߪù Ò�ú ô�õ�áJì8ß&Þ�âPë^à�á8å©äcñ�ä7åAëYä7æAë^ß&ÞHõkí�á8åAáJõ�áJá�âAâPá8Þ�æAëYä7ç^ç^èªï&ö�á�âAâ�äoû/üPý�þ2ÿ��"þ2û��/ÿ��9ÿ���üPÿ��ý�����ß&÷kã�ß�âPë^æAë^ß&Þ�âiß&÷kæAí�á�ï�ä&ðháJõkí�ë^ì2í�á8Þ�ì8ß-à�áHä�âPæAå ä7æAá8ï&èª÷Pß&å�æAí�áHâPèDâPæAá�ð ä7Þ�àõkí�ë^ì2íuõkë^æAÞ�á�âAâPá�â'æAí�á�÷Aä7ì8æsæAí�ä7æsæAí�á�âPèDâPæAá�ðÁõkë^Þ�âDæAí�á�ï�ä&ðhá�é ��ë^ñ�á8Þªä�ã�ä7å ä&ðhá8æAá8å��ß&Þ<æAí�áyâPë^ò8áhß&÷sâPö�ì2íHä�õkë^æAÞ�á�âAâ�âPá8æ ô/ß&ö�å�åAá8à�ö�ì8æAë^ß&Þuì2í�á8ì��Dâ'õkí�á8æAí�á8å�æAí�á�âPèDâPæAá�ðÁí�ä&âä�âPæAå ä7æAá8ï&è�âPö�ì2í�æAí�ä7æ�æAí�á8åAáhëYâFä�âPá8æFß&÷Dã�ß�âPë^æAë^ß&Þ�â�î�ß&ö�Þ�à�á8à�î�è��©õkë^æAí�ë^Þ�õkí�ë^ì2í�æAí�áâPèDâPæAá�ðxì�ä7Þ[÷Pß&åAì8á�æAí�ácï�ä&ðhácæAß�î�á�õkë^æAí�ë^Þ�ä7Þ�à[åAá�ä7ì2íUæAí�á�ï&ß�ä7çYé���í�ëYâFëYâsã�á8åAí�ä7ã�âæAí�áuðhß&åAá�Þ�ä7æAö�å ä7ç�ï&á8Þ�á8å ä7ç^ë^ò�ä7æAë^ß&Þqß&÷�î�ß&ö�Þ�à�á8à�ðhß-à�á8ç^ó�ì2í�á8ì���ë^Þ�ïJæAß<ï�ä&ðhá�âAé� á�ì8ß�ðhã�ä7åAá©ä7ç^ç�æAí�á©ä7î�ß ñ�á©ðhá8æAí�ß-à�âmä7Þ�à�æAí�á�à�ë���á8åAá8Þ�æmá8Þ�ì8ß-à�ë^Þ�ï�â�à�á�âPì8åAë^î�á8à

ä7î�ß ñ�á�ö�âPë^Þ�ïyæYõ�ßyá��Dä&ðhã�ç^á�â�æAí�ä7æ�ì�ä7Þ©î�á<âPì�ä7ç^á8à�é���í�á���å âPæká��Dä&ðhã�ç^á¢ëYâkä�ã�ö�å âPö�á8åAóá8ñ�ä7à�á8åaï�ä&ðháyõkí�á8åAáJæAí�áyß&î��Pá8ì8æAë^ñ�áuëYâ�æAßqï&ö�ë^à�á[äcåAß&î�ß&æ�÷PåAß�ð ß&Þ�áyá8Þ�àHß&÷¢äcï&åAë^àæAß ä7Þ�ß&æAí�á8åaõkí�ë^ç^áJá8ñ�ä7à�ë^Þ�ï�ä7Þ�ß&æAí�á8å�âPç^ß õ�á8å�åAß&î�ß&æ¢æAí�ä7æuðhß ñ�á�âcä7åAî�ë^æAå ä7åAë^ç^è[ë^ÞHæAí�áï&åAë^à�ékê ë^Þ�ì8á¢ß&ö�åkåAá�âPö�ç^æ â�âPí�ß õ¡æAí�ä7æ�� Ó-Ó ðhá8æAí�ß-à�â$ß&ö�æAã�á8åA÷Pß&å ð§î�ß&æAíUù Ò�ú ä7Þ�à! #"%$ðhá8æAí�ß-à�â�î�èuä�çYä7åAï&á�ðyä7åAï&ë^Þ�÷Pß&å'æAí�ëYâ�á��Dä&ðhã�ç^á�ô õ�áFì8ß&Þ�âPë^à�á8å�ë^Þ�æAí�á�âPá8ì8ß&Þ�à�á��Dä&ðhã�ç^áä�ï�ä&ðhá�õkí�ë^ì2ícëYâ&��Þ�ß õkÞcæAß�î�á�í�ä7åAàa÷Pß&å'� Ó-Ó â)(Pö�âPë^Þ�ïhæAí�á�*�+,��cá��Dä&ðhã�ç^áF÷PåAß�ð.-�/103254Aé6 ß õ�á8ñ�á8å ô9ë^æ'æAö�åAÞ�â�ß&ö�æ�æAí�ä7æ'� Ó-Ó â�âPæAë^ç^ç-ß&ö�æAã�á8åA÷Pß&å ð�æAí�á�ù Ò�ú ä7Þ�à7 #"%$iðhá8æAí�ß-à�âAé � áã�ß�âPæAã�ß&Þ�áJä<ðhß&åAá¢à�á8æ ä7ë^ç^á8àqà�ëYâPì8ö�âAâPë^ß&Þ�ß&÷�æAí�á¢åAá�âPö�ç^æ â�æAßyæAí�á¢ì8ß&Þ�ì8ç^ö�à�ë^Þ�ïUâPá8ì8æAë^ß&Þ�é

8 ö�å<ä7ëYð ë^ÞUæAí�ëYâ�ã�ä7ã�á8åmëYâ�æAß�í�äAñ�áoäaì8ß�ðyðhß&ÞUã�çYä7æA÷Pß&å ð æAßHâPã�á8ì8ë^÷Pè�âPèDðkî�ß&ç^ë^ìï�ä&ðhá�âiâPß[ä&â$æAßyì8ß�ðhã�ä7åAáañ�ä7åAë^ß&ö�âiâPèDðkî�ß&ç^ë^ìaæAá8ì2í�Þ�ë�9�ö�á�âmä7Þ�àqá8ñ�ä7ç^ö�ä7æAá¢æAí�á�ðyé���í�áï�ä&ðhá�â�õ�á¢ì8ß&Þ�âPë^à�á8åië^Þ�ñ�ß&ç^ñ�áaì8ß&Þ�æAë^Þ�ö�ß&ö�â�ë^Þ�æAá8å ä7ì8æAë^ß&Þ©î�á8æYõ�á8á8ÞoæAí�á¢æYõ�ßyã�çYäAè�á8å âAô'ä&âëYâkì8ß�ðyðhß&Þ ë^Þ¡ðhß�âPæcï�ä&ðhá�â�âPæAö�à�ë^á8à�ë^Þ ÷Pß&å ðyä7ç�ðhá8æAí�ß-à�âAé:��í�áuö�âPá�ß&÷aâPèDðkî�ß&ç^ë^ìðhá8æAí�ß-à�âkæAß�âPß&ç^ñ�áuã�åAß&î�ç^á�ðyâiåAá8çYä7æAá8à¶æAßoï�ä&ðhá�âkëYâkÞ�ß&æaÞ�á8õ�éªê èDðkî�ß&ç^ë^ìªðhá8æAí�ß-à�âí�äAñ�ámî�á8á8Þuã�åAß&ã�ß�âPá8àªä7Þ�àªâPæAö�à�ë^á8à�ë^ÞuæAí�áyä7åAá�äkß&÷Dã�çYä7Þ�Þ�ë^Þ�ïcë^Þ<;yøYô&÷Pß&å�á��Dä&ðhã�ç^á�ô�ë^Þì8ß&Þ�à�ë^æAë^ß&Þ�ä7çfã�çYä7Þ�Þ�ë^Þ�ï�ö�âPë^Þ�ï= #"%$�ðhá8æAí�ß-à�â -�>1/32sä7Þ�àu÷Pß&åFö�Þ�ë^ñ�á8å âAä7ç�ã�çYä7Þ�Þ�ë^Þ�ï�ö�âPë^Þ�ï� Ó-Ó â?-�/3@%2A(AâPá8áoä7çYâPßB-�C3254Aé 6 ß õ�á8ñ�á8å ôfõ�á�à�ß�Þ�ß&æ?��Þ�ß õlß&÷hä7Þ�èoì8ß�ðhã�ä7å ä7æAë^ñ�áoâPæAö�à�èß&÷kâPß&ç^ñ�ë^Þ�ï<ï�ä&ðhá�â$ö�âPë^Þ�ïJà�ë���á8åAá8Þ�æcâPèDðkî�ß&ç^ë^ì©ä7ã�ã�åAß�ä7ì2í�á�âAé

��í�ámã�ä7ã�á8åFëYâ'ß&åAï�ä7Þ�ë^ò8á8àªä&â�÷Pß&ç^ç^ß õ�âAéiê á8ì8æAë^ß&Þ!>içYäAèDâ'ß&ö�æFæAí�áhã�åAá8ì8ëYâPá�à�á���Þ�ë^æAë^ß&Þß&÷�âPèDðkî�ß&ç^ë^ì�æYõ�ß&ó�ã�çYäAè�á8å�åAá�ä7ì2í�ä7î�ë^ç^ë^æYè¶ï�ä&ðhá�âAé ø^Þ¡ê á8ì8æAë^ß&Þ.Dyõ�á�ß&ö�æAç^ë^Þ�áuæYõ�ß�ä7ã�óã�åAß�ä7ì2í�á�â¥ö�âPë^Þ�ï�� Ó-Ó â¥æAßyâPß&ç^ñ�ákï�ä&ðhá�âAô9ß&Þ�áFö�âPë^Þ�ï Û'ú&Ü âPã�á8ì8ë���ì�ä7æAë^ß&Þ�âfë^Þ Ñ�EGF&Ô�Ò ä7Þ�àæAí�á¢ß&æAí�á8åiö�âPë^Þ�ï7Hfó�ì�ä7ç^ì8ö�ç^ö�âiâPã�á8ì8ë���ì�ä7æAë^ß&Þ�â�ë^Þ Ñ<ÕIF1JGK éiê á8ì8æAë^ß&ÞL@yà�á�ä7çYâ�õkë^æAí âPß&ç^ñ�óë^Þ�ï¢î�ß&ö�Þ�à�á8à<ñ�á8å âPë^ß&Þ�âDß&÷�æAí�áiï�ä&ðhákã�åAß&î�ç^á�ðyô&ö�âPë^Þ�ïaåAá8à�ö�ì8æAë^ß&Þ�âfæAßuâAä7æAëYâM��ä7î�ë^ç^ë^æYèyß&÷ #"%$mä7Þ�à�ù Ò�ú ÷Pß&å ðkö�çYä&âAé N�ß&å$æAí�á�ù Ò�ú åAá8à�ö�ì8æAë^ß&Þyõ�ákß&ö�æAç^ë^Þ�ákî�ß&æAíyæAí�áaâPæAå ä7æAá8ï&è�ó�æAåAá8áä7ã�ã�åAß�ä7ì2í[ä&âfõ�á8ç^ç�ä&âfæAí�áiõkë^æAÞ�á�âAâPó�ï&å ä7ã�íUä7ã�ã�åAß�ä7ì2í�é � áiã�åAá�âPá8Þ�æFß&ö�å�á���ã�á8åAëYðhá8Þ�æ ä7çåAá�âPö�ç^æ â�÷Pß&åkæYõ�ß<ï�ä&ðhá¢á��Dä&ðhã�ç^á�â�ë^Þ ê á8ì8æAë^ß&ÞOC<ä7Þ�à©ì8ß&Þ�ì8ç^ö�à�áaë^Þ ê á8ì8æAë^ß&ÞQP&é

R SUT,VXWZY

ø^ÞªæAí�ëYâaâPá8ì8æAë^ß&Þ�ôDõ�á<à�á���Þ�á<æAí�á<åAá�9�ö�ë^åAá8àHæAá8å ðhë^Þ�ß&ç^ß&ï&è�é\[½á8æ^] î�á[ä^��Þ�ë^æAá[âPá8æaß&÷ñ�ä7åAëYä7î�ç^á�âAé � áyõkåAë^æAá�]�_'`bacd_fegcih:]kj�÷Pß&å¢æAí�á�âPá8æ¢ß&÷�ã�åAëYðhá8àHñ�ä7åAëYä7î�ç^á�âFß&÷�]�é� á<à�á8Þ�ß&æAáJî�èml1�n�5(poL4�æAí�á[âPá8æ�ß&÷aä7ç^ç�æAß&æ ä7çs÷Pö�Þ�ì8æAë^ß&Þ�âkæAí�ä7æ�ðyä7ãHá8ñ�á8åAèªñ�ä7åAëYä7î�ç^áë^ÞL] æAß[ähñ�ä7ç^ö�áaë^Þqë^æ â$à�ß�ðyä7ë^Þ�é���í�áuâPá8æ�ß&÷kä7ç^ç�ã�åAá8à�ë^ì�ä7æAá�â�ß ñ�á8åq] ëYâ$à�á8Þ�ß&æAá8àoî�èr (f]Q4Aé?��ë^ñ�á8Þts\hXl1�n�5(poL4�ä7Þ�à�ä�ã�åAá8à�ë^ì�ä7æAáLu�ß ñ�á8å?]v`wacyx�z|{�{�{�z�cd}&j&ô½õ�á�õkåAë^æAáuy- s%2<`vuy- cyx�~3sd(fcyxp4�z|{�{�{�z�cd}&~3sd(fcd}G4M2�÷Pß&åJæAí�á�æAåAö�æAí�ñ�ä7ç^ö�á�ß&î�æ ä7ë^Þ�á8à�î�è�åAá8ã�çYä7ì8ë^Þ�ï

D

Page 44: BMC’03 - JKUfmv.jku.at/papers/bmc03-preliminary-proceedings.pdfBMC’03 Boulder, Colorado, USA. ... Alessandro Cimatti (IRST, Italy) Raanan Fraer (Intel, Israel) Danny Geist (IBM

���I���I�I�p�I�n�I���1���I�B�I�I�7�����I�

�I�3���\�&�3�p�5�3�&�����d�y�������O�L #��¡p�\¡p�&�¢�&�3��£&��¤d¥f�d�§¦p¨© �^ªq«�¬&���y��­�®n¯�°²±�³3´%µ&�g��¡5 ¶�����t�¢·�¸¹·�º»°�¯¼�3�&¬½��¡¿¾'°�ÀÂÁ�ÃMÄ�ÅnÀ¯�°�Àº�£)¾M���&Æ<�¢­�®n¯�°

·�º»Ä3Ç�È�º»Ç�Ä�°\É!Ê.¥f��ËgÌ���ͶÌ|Î\ËgÌ|Î\ͶÌ�Ï�Ë�Ì�Ï�Í,¦y #��¡p�\¡p�&�¢ÐM«1����«¿ #���&Æ���«gªqÑg«1�&���I¡¿¾pÒÓ ��Ë��5¾²��Ô&�&��¡p�!¾M��¡�«1Ð^Á�®nÄ3ÃM®nÕ�Ö×°�·�¡p�&�B¾MØ�¾M¡p�IªÙ��«1�I¡p�p«1�5¾pÚ#�3�&¬Q��ÍÛ�5¾²��Ô&�&��¡p�!¾M��¡«1ТÁ�®nÄ3ÃM®nÕ�Ö×°�·^¡p�&�����I�I���p«1�)ªq���I¡²��«1�I¡p�p«1�5¾# #��¡p�:��Ë<Ü=��ÍÝÊmÞ1¨ © �� #�p��¡p�7�ßÊ��Ë�à���ÍLÐM«1��¡p�&�7¾M��¡ «1Ð ¾MØ�¾M¡p�Iªb�3�&¬=���I�I���p«1�)ªq���I¡��&�3�p�5�3�&���I¾pÚ��3�&¬:á.Êãâ1®nÖ5¥päL¦ÐM«1�#¡p�&�<¾M��¡A«1ÐA¾M¡¿�3¡p�I¾y«1ÐAÉ,¨

Ó Î\˲�5¾��#Ô&�&��¡p�½¾M��¡ «1ж¯�ÅnÁ�°q�&�3�p�5�3�&���I¾¹å= #�&�����=¬&��¡p���¿ªq���&�?¡p�&�q�&��æI¡�¯�ÅnÁ�°q«1Ð�¡p�&�¾MØ�¾M¡p�Iªã�3�&¬ÛÎ\Í:�5¾���Ô&�&��¡p�L¾M��¡?«1Ð?¯�ÅnÁ�°��&�3�p�5�3�&���I¾' #�&�����!¬&��¡p���¿ªq���&�½¡p�&�²�&��æI¡¯�ÅnÁ�°=«1Ð�¡p�&�=���I�I���p«1�)ªq���I¡¿¨ © �:�1¾p¾M£)ªq�OÎ\Ë\Ü:Î\ÍçÊèÞ1Ú�Î\Ë�Ü\�éÊ�Þ��3�&¬Î\Íêܽ�ëÊìÞ1¨

Ó Ï�ËO�kíA¥f�tÌ|Î\Ë�Ì���îË ¦¶�5¾��\º»Ä�®nÀ·�ÃMº»ÃMÅnÀ�ï�Ä�°�ðnÃMÈ�®nº»°�ÐM«1��¡p�&��¾MØ�¾M¡p�Iªb�&�3�p�5�3�&���I¾p¨\ñ%«1��I�3����ò=�Xâ1®nÖ5¥päL¦pÚÂó�ËL�Xâ1®nÖ5¥pôLõ�¦��3�&¬êò%îË �Xâ1®nÖ5¥pä�îõ ¦pÚ&��Ð,Ï�Ëg± òÂÌ�ó�Ë�Ì�ò%îË µ'ÊUº»Ä3Ç�°¡p�&���êò%îË �5¾ö¡p�&���&��æI¡��&�3��£)�3¡p��«1�\«1Ðy�&�3�p�5�3�&���I¾ö���ê��Ë� #�&���L¡p�&�=¾MØ�¾M¡p�Iª÷Ñ&����ø�¾,¡p�&�ªq«¿�%�¢ó�ËL�3¡�¡p�&��¾M¡¿�3¡p��ò&¨#ù¿�5ªq���5�3�p��ØIÚ�Ï�Í:�LíA¥f�tÌ|Î\ͶÌ�� îÍ ¦Z�5¾ �²º»Ä�®nÀ·�ÃMº»ÃMÅnÀ�ï�Ä�°�ðnúÃMÈ�®nº»°�ÐM«1�?¡p�&�²���I�I���p«1�)ªq���I¡¢�&�3�p�5�3�&���I¾p¨½ñ%«1�q�I�3���!òL�mâ1®nÖ5¥päL¦pÚgó�Íi�mâ1®nÖ5¥pôLû�¦�3�&¬êò%îÍ �üâ1®nÖ5¥pä�îû ¦pÚG��Ð,Ï�Í'± òÂÌ�ó�ͶÌ�ò%îÍ µ,Êwº»Ä3Ç�°²¡p�&����ò%îÍ �5¾,¡p�&�^�&��æI¡q�&�3��£)�3¡p��«1�L«1Ð�&�3�p�5�3�&���I¾y���L��Í� #�&���L¡p�&�¢���I�I���p«1�)ªq���I¡qÑ&����ø�¾ö¡p�&�<ªq«¿�%�^ó�ÍÛ�3¡#¡p�&�<¾M¡¿�3¡p��ò&¨ý «¿ ^Ún ¶�q¬&��Ô&�&���^­�®n¯�°�þÝÊìÿ�É Ì � Ì���Ì����� #��¡p�!�#Æg�1ªq�½¾M¡p�p£&��¡p£&�p�7É,Úd�3�!ÃMÀÂÃMº»ÃM®nÖ

·�º»®nº»°� � �÷â1®nÖ5¥f�Q¦pÚ���­�Å�®nÖIï�Ä�°�ðnÃMÈ�®nº»°���LíA¥f�Q¦#�3�&¬O��·�®��p°Aï�Ä�°�ðnÃMÈ�®nº»° �\�êíA¥f�Q¦ #�&���p�AÐM«1�ö�I�3����ò7�÷â1®nÖ5¥päL¦pÚ¹��Ð��g± ò¿µyÊݺ»Ä3Ç�°�¡p�&���½¡p�&�^¾M¡¿�3¡p��ò��5¾g���½¡p�&�²­�Å�®nÖG�p��Æ1��«1�)Ú�3�&¬���Ð���± ò¿µ#Ê纻Ä3Ç�°�¡p�&���t¡p�&�L¾M¡¿�3¡p��ò7�5¾¶����¡p�&�L·�®��p°½�p��Æ1��«1�)¨��)�&��Æg�1ªq�L¾M¡¿�3�p¡¿¾¶���¡p�&�����&��¡p�5�3�^¾M¡¿�3¡p�O�3�&¬k��� ���%���pØݾM¡p��Ñ)Ú'¡p�&�O¾MØ�¾M¡p�Iªv�3�&¬k¡p�&�\���I�I���p«1�)ªq���I¡7Ñ&����øÝ�ªq«¿�%�O¾M�5ª#£&��¡¿�3�&��«1£)¾M��Øì�3�&¬k¡p�&�:¾M¡¿�3¡p�\���%«1���%�I¾<�3����«1�p¬&���&Æ!¡p«!¡p�&�5¾q���&«1�����I¨���Ðq¡p�&�Æ1«g�3���p��Æ1��«1�\�5¾y�p�I�3���&��¬L¡p�&���\¡p�&�7¾MØ�¾M¡p�Iª  #���)¾p¨���Ðy¡p�&�¢��£&�p�p���I¡²¾M¡¿�3¡p�¢�5¾y�&«1¡#���\¡p�&�¾p�3ÐM�¢�p��Æ1��«1�)ÚI¡p�&�¢���I�I���p«1�)ªq���I¡q #���)¾p¨���¡p�&���p #�5¾M�IÚG¡p�&�¢Æg�1ªq�¢��«1�I¡p���I£&�I¾,ÐM«1�p���%���¿¨ñ%«1�ö¡5 ¶«=¾M¡¿�3¡p�I¾�¤7�3�&¬�ò&Ú% ¶�²¾p�pز¡p�)�3¡'òq�5¾�¡p�&�^·�Ç�È�È�°�·�·�ÅnÄ#«1Ð�¤���Ðg¡p�&���p�²�3�p�Aó�Ë��

â1®nÖ5¥pôLõI¦q�3�&¬�ó�Íi�bâ1®nÖ5¥pôLû ¦q¾M£&���t¡p�)�3¡?Ï�Ëg± ¤gÌ�ó�Ë�Ì�ò%îË µ�Ê º»Ä3Ç�°GÚdÏ�Í'± ¤gÌ�ó�Í'Ì�ò%îÍ µ¶Êº»Ä3Ç�°ê�3�&¬tò\Ê ò|Ë7à7ò|Í'¨ © �L�1¾p¾M£)ªq��¡p�)�3¡?¡p�&���p����æI�5¾M¡¿¾¢�3¡q���I�1¾M¡�«1�&�\¾M£&�����I¾p¾M«1�=�3¡���%���pØ!¾M¡¿�3¡p�I¨��ìïG®nº���«1Ð#Éê�5¾A��Ô&�&��¡p�¢«1�#���&Ô&�&��¡p�<¾M���I£&���&�����7Êkò��¹Ì�ò! �Ì#"$"$"1«1Ð ¾M¡¿�3¡p�I¾¾M£&���ê¡p�)�3¡�ÐM«1�²�3���ZÑg«g¾M��¡p��«1�)¾&%�')(1Ú&ò|� *� ö�5¾q�7¾M£&�����I¾p¾M«1�?«1Ðöò|�5¨?ñ%«1�²��Ñ)�3¡p�+�ê�3�&¬Q�Ñg«g¾M��¡p��«1� %�'�(1Ú¿ ¶� £)¾M�,�d± %»µZ�3�&¬�d±-(nÌ.%»µ�¡p«�¬&���&«1¡p� ¡p�&�/%�0 ¡p�\¾M¡¿�3¡p� «1Ð1�½�3�&¬�¡p�&��Ô&�&��¡p�Ñ&�p��Ô&æêò��%Ì�ò! �Ì#"$"$"�Ì�ò|�)«1Ð2�dÚd�p�I¾MÑg����¡p���%����ØI¨3� ·�º»Ä�®nº»°�­�¸<ÐM«1�?¡p�&�L¾MØ�¾M¡p�Iªü�5¾���ÐM£&�&��¡p��«1�4 Òdá *65 â1®nÖ5¥pôLõI¦y #�&�����Qª½�3Ñ)¾ö���%���pØ=�&«1�&�IªqÑ&¡5Ø�Ô&�&��¡p�<¾M¡¿�3¡p�<¾M���I£&���&����=�:á *¡p«B��ªq«¿�%� 4 ¥7�d¦?� â1®nÖ5¥pôLõ�¦p¨98 ���%���i��¾M¡p�¿�3¡p��Æ1Ø 4 Úg ¶��¬&��Ô&�&�½¡p�&�½ï�Ö×®n¸¹·�«1Ð 4 ¡p«�g��¡p�&�ê¾M��¡�ï�Ö×®n¸¹·%¥ 4 ¦¶«1жÑ)�3¡p�)¾¶ #�&����� �3�p��Ñg«g¾p¾M���&���� #�&���!¡p�&�ê¾MØ�¾M¡p�IªXÐM«1����«¿ ^¾�¡p�&�¾M¡p�¿�3¡p��Æ1Ø 4;: ¡p�)�3¡,�5¾pÚd��Ñ)�3¡p�<�7Êkò��%Ì�ò! �Ì#"$"$"��5¾����½ï�Ö×®n¸¹·%¥ 4 ¦g��Ð�ÐM«1�q�3���&Ñg«g¾M��¡p��«1�)¾=%�'�(1Ú¡p�&���p�ê�3�p��ó�ËO� â1®nÖ5¥pôLõ�¦¢�3�&¬Bó�ÍÝ�ãâ1®nÖ5¥pôLû�¦¢¾M£&���B¡p�)�3¡�ó�Ë:Ê 4 ¥7�d±-(nÌ.%»µ5¦��3�&¬ò|� *� �5¾Z¡p�&�7ÿfó�Ë�Ì�ó�Í>��¾M£&�����I¾p¾M«1�A«1ÐZò|�§¨/8 ���%���B�AÆg�1ªq�7þÝÊìÿ�É Ì � Ì���Ì����pÚg�²¾M¡p�¿�3¡p��Æ1Ø?A@�BDC�E�B.F�GIHJE�CKML G$NPO#QRAE�B�S�QTAU�V L L!WYXZB.[\E�V BDE�NPV B�]ZL G1^_Ea`bV EacML G�cMd�[�V B>]�G$B�GI`bE�L OeV fgE/NhFJNh[�G$Ci E�N�Cjd�L [\V KML GDWYXZCKkXZB�G$B.[\NJ[ i G$B>[ i GI`PG�WIE�B>ckGDE�CX\^�G�^_Ea`bV EacML G�f X�`�G$E�W i WYXZCKkXZB�G$B.[\lm2noG3WIE�B i E�B�S�L G3Cjd�L [\V KML GpNh[\Ea`P[�Nh[\Ea[�G$Nqc#FrV B.[�`PXJS�d�WIV B�]sEDB�GIUtNh[\Ea[�G3E�N1E�BpV B�V [\V E�LuNh[\Ea[�G�U�V [ iCX\^�G$N![�XpE�L L�[ i GDNh[\Ea`P[jNh[\Ea[�G$NPl

´

Page 45: BMC’03 - JKUfmv.jku.at/papers/bmc03-preliminary-proceedings.pdfBMC’03 Boulder, Colorado, USA. ... Alessandro Cimatti (IRST, Italy) Raanan Fraer (Intel, Israel) Danny Geist (IBM

v�w!xJy!z!{�z!xZw!|=}e~�w!��w!|!xr����z!����������&���u�u���u�,�\���.�Z���\�$�s�-����M�3���e�D�����-�����e o�b¡-¡�¢¤£+¥�¦k§.¥!¨7§#©$©$©uª�«;¬h�Z�_�k­7�;®���¯M°\����±�b�p¥�¦9£³²;´=���M�� �����µ!�������o�,¶������-���-�e�¸·,¹»º���¯M°\�¸���±�b��¼�½ ¥#¾-¿D£À���bÁJ�Â�b�MÃÂ���e 9�b¡-¡¶������-���-�e�±�AºrÄÆÅ�Ç�·\´=È=½ ¥#É�¿�£Ê���bÁJ�gË Ìq�-�±�b¡-¡-Í!´q�e�-Îk���Ï�p���e�D��Ê£ÑÐ7Ò�§.²=§�¼;§�È=Ó�´q���M��$�ZÔ �2«;�.ÕZÖ$¬h�$Ô×��������°\�M��°\ØÂÙ/�M�����M�� p���M�Ú��Í=�����!�À�±�e�3�,Ù/�-�M�M�-�M�Û���� ��b�����eÍÜ�-�Â���M����e�D�9�3Ë

Ý>Þ �ZÔ�«;¬h��ß�àá±�e�±���-ÃM�� p���M�s���e�D�sâ�����Ùj�����ã�b�t�$ä$�ZåZ�$� Ý �b�MÃt�,«;ÁJ�b�\ÁJ�$�sæ)�e�Ï�b��çtè�çÛ�e ��-Ã�e�D���M��Ù/�<�-�éÌq�-�e¯M ���êkË ë±�M�,��ÎM�bÃM�� A�� ��-�!�j���9 ��!�b°\�Ü���M�,¶M ���ÃM��ìM�M��Ãt�$Õ$�Z¬±¶������-���-�e��+Ù/�-���M�e¯M��â����-�M�,°!�b¯M�e�!��â!Ís���M�A¶M¯M ���¯M�� �Ë�ë±�M�A��ÎM�bÃM�� �°\�M�J�����!�±�e�M�s�e�D�e�M������ìMÎk��D��Îk�!��í�Á#«;î�åZÕZ�&�uî�¬h�Iï���îD�b���$ðZ� �b�MÃã�\���Z���-�¸��Îk�� �Ít������¶±ËÂë±�M�r¶M¯M ���¯M�� �´±�M��Ùj��Îk�� �´°\�M�J�����!�&�e�M����¯M°\�é�D��Îk�o�e�M¡-Í��-�Ú��Îk�� �Í��JÃMÃ6������¶+�b�MÃ�-�s�/¯±���s������͸�����b���-�e�±�b �Í��-���Îk�� �Ír��Îk����������¶±Ë�á±�e�±���-ÃM�� ��-�M�s���M�D��ÎM�bÃM�� p�e����M�s��Í=�����!�ñ¶M¡���Ík�� o�b�MÃ9���M�A¶M¯M ���¯M�� �e�����M�2���!Î!�- ��e�±�D���!��¶M¡���Ík�� �´!Ùj�2°!�b�¤ÃM��ìM�M�2���M�A���e�D�r�)£òÐ7Ò�§.²=§�¼;§�È=Ó��e����e¡-¡-��Ùo��Ë

Ìq�- �����´JÙj�9�D�JÃM��¡����M�3���e�D�9���� �¯M°���¯M ��pâ!Í�Ò�£Æ­ôó�õ;§.ó�ö>§#÷�õ;§#÷�öj§.ø;õ�§.ø;ö>®�Ëù ó�õò£ûú�üqý$§.þeý�ÿ�Ù/�M�� ��<üqýÚ�b�MÃãþeý  ��b�M�e�-�M�Û��Îk�� ¸úeºZ§#©$©$©�§.ç��òêZÿ¸�b ��Ü���M�Üü � þ°��J�e �ÃM�-�±�b���!���e�����M�/��ÎM�bÃM�� �´u�b�MÃ�ó�ö�£ñú�ü � §.þ � §��$¬hÕ����qÿjÙ/�M�� ���ü � �b�MÃ�þ �  ��b�M�e�-�M���Îk�� AúeºZ§#©$©$©�§.ç��¤êZÿ2�b ��/ü � þ3°��J�e �ÃM�-�±�b���!���e�u���M�/¶M¯M ���¯M�� D�b�MÃ�$¬hÕ����D ��b�M�e�-�M�2��Îk�� úeºZ§�êZÿD�����D���e�e�e¡-�r��¶���°��-��Í!�-�M�rÙ/�M������M�3¶M¯M ���¯M�� �°!�b��°\�±�b�M�e�3�-����¶������-���-�e�±Ëù ÷�õ £ ú��ý#ÿ �b�Mà ÷�ö £ ú� � ÿ Ù/�M�� ����ý �b�Mà �  ��b�M�e� ��Îk�� úeÁ#«&§�åZÕZ�&��§�¬h�Iï���§��b���$ðZ��§��\���Z��ÿeË

ù � õ��

��� � ý�������� � � ý���� "!�#$�%� � �'&ý � � ý)(+*��,� � -.&ý � - ý/�0�1 �0� � ý�23�(4*���� � � ý5�7698;:�<=#$��� � �'&ý � � ý�>?*���� � -.&ý � - ý$�0�1 �0� - ý�23@(4*���� � � ý��7A.BC��� � �'&ý � � ý/�%� � -.&ý � - ý�>?*��0�1 �0� - ý�������� � � ý5��D=E9F�G%��� � �'&ý � � ý/�%� � -.&ý � - ý)(4*��0�1 �0� � ý��7HI#9J9K'�%� � �'&ý � � ý$��� � -.&ý � - ý$�0�

� ö��

�0L � E LNM �7*���� ��� � � ������� � � � ��� "!�#9��� � �'&� � � � (4*���� � -.&� � - � �0�1 �0� � � 23�(4*���� � � � �7698;:�<=#/�%� � �'&� � � � >?*���� � -.&� � - � �0�1 �0� - � 23@(4*���� � � � �7A.BC��� � �'&� � � � ��� � -.&� � - � >?*��0�1 �0� - � ������� � � � ��D=E9F�G��%� � �'&� � � � ��� � -.&� � - � (4*��0�

1 �0� � � �7HI#9J9K'��� � �'&� � � � �%� � -.&� � - � �0�O ­9�$¬hÕ���� &5P£Q�$¬hÕ����u®$R

²TS ú�üqý�£»ºZ§.þeý £ ºZ§.ü � £»êZ§.þ � £VUZÿ �-�����M�r�-�M�-�����b¡>¶������-���-�e���e�����M�r��ÎM�bÃM�� ���2­ôü+£ ºZ§.þ£ ºe®2�b�MÃ<���M� �-�M�-�����b¡1¶������-���-�e�<�e�>���M� ¶M¯M ���¯M�� p���2­ôü+£ êZ§.þ£WUe®�Ë�¼�������bÁJ�o�-�����M�pü � þr°��J�e �ÃM�-�±�b���!���e�����M�3��ÎM�bÃM��  �b ��r���e�D�pÙ/�-������M�3¶M ���ÃM��ìM�M��ÃÚ�e���b¡¶������-���-�e�±Ë�È����A���bÁJ�,�-�&���M�,ü � þ¤°��J�e �ÃM�-�±�b���!�>�e�1���M�,��ÎM�bÃM�� s�b ��oÃM�YX��� ����!�A�� ����ò���M�¶M¯M ���¯M�� =Z-��íjÈS�­ôüqý P£6ü � ®,[­ôþeý P£+þ � ®�Ë

\

Page 46: BMC’03 - JKUfmv.jku.at/papers/bmc03-preliminary-proceedings.pdfBMC’03 Boulder, Colorado, USA. ... Alessandro Cimatti (IRST, Italy) Raanan Fraer (Intel, Israel) Danny Geist (IBM

]@^`_Ca`b`c9b`_d^`e%f.gh^`ij^`e`_�khl�b`m

P

E

G

n%oqp�rts�rvuxw`y�z�w`oq{0|~}/����z�oq����������}

�����t�t�=�����x���Y�=�%�����.�Y�Y��� �C¡£¢����/¤£¢��/¥`�Y¦£§©¨~�.ª�§�«.� ¢�¬£ª9�.�£�Y¢`��­~®

¯�°x±x² ��³@« §�«.� ¢�´�µ�¶$·�¸�¹%¸=º»¸9¼�½9¾¿ ² � ±x² ��³ÁÀ9¤£¢©«Â¦x­~Ãv¢�ªÄÀ9��À9¤£¢©� �C¡£¢����/¤£¢��/¥`�Y¦£§©¬£ª9�.�£�Y¢`�Ũ~�.ª�À9¤£¢�§�«.� ¢`¾

Æ�Ç µ�È�ÉdÊqË/Ì`ÍÎ Ç µÅº�ÍÏ �x����Ð ÎTÑÒ Æ4Ó �

Æ�Ç µ ÆÕÔ Î ÍÎ Ç µ�Ö5×�Ì'Ø)Ù Æ�Ú,Û ¼%Í� Ó Í��Ü Æ Ù�¹ Ú ���xÐ ° ª9¢�À9Ý£ª9¦ßÞà×ÂáCÌ'ÍÐ`��â�Ðãª9¢�À9Ý£ª9¦4ä9ÉdÊqË/ÌCÍ

n%oqp�r�å�r5æ`çè� é£��êqoqë����èì`}/êíëIî`}/ëIïèoq�`pã��êqp���y�oq{0î`�Åð;��y5p�����}�ñ`y���é`êq}/��zò ó�ôvõIö�÷Iø�ùúùvû�üþý,ÿ���ÿ'÷Iø�ù������Qÿ� ¦�À9¤£�0­ ­~¢���À9�Y�.¦�,Ãv¢ ­~�.��è¢�§�«.� ¢`­�Ýx­~�Y¦£§�£�Y¦x«Âª9� ¡£¢����0­~�Y�.¦ ¡£�0«Â§.ª=«.��­ Ù � _C_ ­ Ú ¾��x¤£¢­~À=«Â¦£¡x«Âª9¡ «ÂÀ9À9ª=«Â��À9�.ª��­~¢�À+� ¢�À9¤£�C¡ßÀ9�7­~�.��è¢�§�«.� ¢`­��0­ «������ ¬��.�Y¦`À4«Â�Y§.�.ª9�YÀ9¤x��­�À9¤x«ÂÀ�`«Â¦?��¢��0� ¬£�Y¢`� ¢�¦`À9¢�¡ Ýx­~�Y¦£§�� _C_ ­9¾��t�Y§.Ý£ª9¢��+­~¤£�=Ãã­ «+­~�%�����.�Y�Y� � �C¡£¢����/¤£¢��/¥`�Y¦£§«Â�Y§.�.ª9�YÀ9¤x�ú¨~�.ªã�.Ý£ªã§�«.� ¢©¬£ª9�.�£�Y¢`���xÃ�¤£�Y�/¤���«Â¦£�Y¬£Ý£�0«ÂÀ9¢`­Õ­~À=«ÂÀ9¢�­~¢�À=­Ä�.¨ ·�¾�����è¢�¦«�§.��«Â��ª9¢�§.�Y�.¦ «Â¦£¡ «?­9«Â¨~¢4ª9¢�§.�Y�.¦�)Ãv¢4����� ¬£Ý£À9¢ß«Â�Y�ã­~À=«ÂÀ9¢`­Á¨~ª9��� Ã�¤£�Y�/¤�À9¤£¢�ª9¢4�0­« Ã��Y¦£¦£�Y¦£§7­~À9ª=«ÂÀ9¢�§.� ¨~�.ª�À9¤£¢ ­~�%­~À9¢`��¾����.À9¢�À9¤x«ÂÀ�À9¤£¢@¨~Ý£¦£��À9�Y�.¦ Ö5×�Ì'Øß�0­�¡£�� �¢�ª9¢�¦`À¨~ª9��� À9¤£¢Ä¬£ª9¢!� �0��«Â§.¢ ¨~Ý£¦£��À9�Y�.¦��.¨#"%$ l � �C¡£¢��t�/¤£¢��/¥è¢�ª=­9¾&�x¤£¢ ¨~Ý£¦£��À9�Y�.¦�Ö5×�Ì'Ø#�.Ã�¤£¢�¦§.��è¢�¦T«Á¬£ª9¢�¡£�Y�`«ÂÀ9¢ Æ Ù('*)»¸+'*, Ú �'ª9¢�À9Ý£ª9¦x­ «�¬£ª9¢�¡£�Y�`«ÂÀ9¢+Ö5×�Ì Ø Ù Æ�Ú.-0/ Ù(' Ú ¨~�.ª�À9¤£¢�­~¢�À�.¨5­~À=«ÂÀ9¢`­1�­~Ý£�/¤©À9¤x«ÂÀh¨~ª9����12�.À9¤£¢Õ­~�%­~À9¢`��¢�¦£¨~�.ª9��¢`­,À9¤£¢ ¦£¢!�`À�­~À=«ÂÀ9¢ À9��­9«ÂÀ9�0­~¨~� Æ ¦£���«ÂÀ9À9¢�ª�¤£�=Ã�À9¤£¢�¢�¦�`�Yª9�.¦x� ¢�¦`ÀÄ��¢�¤x«�è¢`­9¾&�è�.ª=��«Â�Y�Y���

Ö5×�Ì Ø Ù Æ�Ú Ò4365 )»¸+'07)98 : 5 ,v¸+'07,;8=< )�Ù('?¸ 5 )»¸+'07) Ú$Û Ù < ,5Ù('?¸ 5 ,v¸+'07, Ú?> Æ Ù('07) ¸+'07, Ú9Ú 8

� ¦4À9¤£¢©«Â�Y§.�.ª9�YÀ9¤x����­~¢�À=­)�.¨�­~À=«ÂÀ9¢`­Ä«Â¦£¡4À9¤£¢�À9ª=«Â¦x­~�YÀ9�Y�.¦4ª9¢��0«ÂÀ9�Y�.¦ß«Âª9¢�ª9¢�¬£ª9¢`­~¢�¦`À9¢�¡ �`�� _C_ ­ ��@®0¾�A,�.À9¤ À9¤£¢ k $ l � �C¡£¢��x�/¤£¢��/¥è¢�ª�«Â¦£¡0B9� �`«Â�Y��Ý£�YÝx­�� �C¡£¢�� �/¤£¢��/¥è¢�ª�Ýx­~¢ÕÀ9¤£�0­«Â�Y§.�.ª9�YÀ9¤x��¾

C

Page 47: BMC’03 - JKUfmv.jku.at/papers/bmc03-preliminary-proceedings.pdfBMC’03 Boulder, Colorado, USA. ... Alessandro Cimatti (IRST, Italy) Raanan Fraer (Intel, Israel) Danny Geist (IBM

D*E�FHG�I�J�I�FKE�LNMPOQE�RSE�L�FUTQV!I�W

X&YZ\[^]`_Ka`bQcdKafe`g`hji6kD*lnmPG�E�o�pfqnr sut;vxw!y�r�z�{�t=|�r�}P~�w!~�v�r�y�}P~�&w!~�|%�j}Py��&}H����� t=yuvxw!y�r�z�{�t=|�r�}P~��j}Py�t=��|�w!y�~t=|�r�~��P�|�r �&w�|�w��&��}Py�t=�N��}P�Pr�{��H�.��r�{f��r s�t���tP�&w���}P�Pr�{�w!��|�w!~sjr�}P~�}P�?�%�PV��

� r�vxw!~�t���tP�&w����������+�N���9�� �¡��6�?w�sj��w!{!r��j¢£t���tP�&w^sj|�y���{!|���y�w¤�¥tPs?y�w�t={!|�r�vxw�&}H������w�s�o�p=q#�.��w!y�w�|���w�sj¢Nsj|�w��¦t=~���r�|�sQw!~�v�r�y�}P~�&w!~�|�t=y�w���w�sj{!y�r�§�w!�Sr�~�sjw!�t=y�t=|�w�&}H������w�s��t=~���sj��w!{!r��j¢¨��t=~��� StPs&t=~ST©�PV��j}Py��.��� t��sjr�~��ª|���w¬«2­9® ¯=°�}P��w!y�t=|�}Py�±��² ��w&��}P�Pr�{�T©�PV�t=��&r�|�sQt.�j}Py��.��� t³� �(´�¡ ¡�µ¶±¶·��P�.��w!y�w*µ¸t=~��ª·¹t=y�w�sj|�t=|�w&��y�w!��r�{�t=|�w�st=~��0´ºr s�t�sj��§sjw!|�}P�%��� t�¢xw!y�s�� ² ��w��j}Py��.��� t¸� �(´�¡ ¡�µ¶±¶·»tPs�sjw!y�|�s?|��t=|&|���w³��� t�¢xw!y�sr�~¼´½{�t=~¥{!}H}P��w!y�t=|�w0|�}�¾xw!w!�¿s�t=|�r sj�j¢�r�~��Àµ\��~�|�r��Us�t=|�r sj�j¢�r�~��¨·Á~�}¹��t=|�|�w!y¸��}��|���w�y�w���t=r�~�r�~��*��� t�¢xw!y�s%§�w!�t�vxw��ÃÂ}P~sjr���w!y�r�~���´ÁtPs|���w�sj¢Nsj|�w�����|���wªsjw���t=~�|�r�{�s%}P�� �(´�¡ ¡�µ¶±¶·�r s2w!�Nt={!|���¢^s�tP�&w�tPs2|���w.��tP�&w¶��y�}P§���w����¶Äx}Py�Å9�NtP�&����w¬ÆP���?w¬sj��w!{!r��j¢³|���ww!v�t=��w!yªt=~���|���w�����y�sj��w!y�tPs�sjw!�t=y�t=|�w0�&}H������w�s��;t=~��Çsj��w!{!r��j¢0|���w���tP�&w���y�}P��w!y�| ¢tPs#|���wUT©�PV�sj��w!{!r�z�{�t=|�r�}P~�#� ��È.É�Ê�ËNÌÎÍ6¡ ¡�Ï�ÐfÑÓÒ a ± k`] Ñ bÕÔ � ² ��w!~�6�?w¬�sjw^sj¢N�.§�}P��r�{ªT©�PV�&}H��w!��{f��w!{f¾�r�~��³}P�D*lnmPG�E��x�.��r�{f�Ur �&����w��&w!~�|�s�|���w³t=���P}Py�r�|���ºsj��}��.~Ur�~0Ä2r��P��y�w¬ÖP�

×;Ø e Ñ bÙe`ÚHbÙÚ Ð [^]`_Ka`b?cdKafe`g`hji6k² ��w × �Û{�t=��{!�����s#o ÜPqHr s2��y�}P��}�sjr�|�r�}P~t=�©�&}H�t=�H��}P�Pr�{Qw!��|�w!~���w!�*�.r�|���|���wQ��w�tPsj|#z�����}Pr�~�|}P��w!y�t=|�}Pyªt=~���r s.r�~�|�w!y���y�w!|�w!�\}�vxw!y^ÝQy�r���¾xw�sj|�y���{!|���y�w�s���ÞÇ��r���w × �Û{�t={!�����s¬�&}H��w!���{f��w!{f¾�r�~���{�t=~�§�w^sjw!w!~�|�}¸§�w�w!ß���r�v�t=��w!~�|�|�}�w!v�t=���t=|�r�~�� hjiáàui6hjâãa�ä ÑKå hjâãæ¸k ÑKç a Ð�}P~z�~�r�|�w¤�Py�t=���s��Q|���w × �Û{�t=��{!�����sªt=� sj}\|�y�r�v�r t=����¢¨w!~�{!}H��w�s�sj}P����|�r�}P~s�|�}�y�w�t={f�t=§�r���r�| ¢��tP�&w�s���è�~^}P��y.{!}P~�|�w!��|��n|���w × �Û{�t=��{!�����su�j}Py��.��� tPé

×Nê�ë Ï k`] Ñ b9ì Ï�ÐfÑÓÒ a�íîQï+ð�ñfò+óÙô õ�öÎ÷ îQø+ð�ñfò+óÙô õ�ù`÷

�(ú¸ûü�+ú¸ýü¡ ê Ô�Ô

{!}��&����|�w�s%|���w¬�.r�~�~�r�~���t=y�w�t��j}PyÃ��� t�¢xw!y*�%�©tPs#r�|�sj|�t=~��s%�j}PyÃ|���w���w�tPsj|�sjw!| ê {!}P~��|�t=r�~�r�~���|���w��P}�t=�9{!}P~�z��P��y�t=|�r�}P~s.tPs©�?w!���QtPs|���}�sjw�{!}P~�z��P��y�t=|�r�}P~s�jy�}��¹�.��r�{f�^|���wsj¢Nsj|�w��þ{�t=~^�j}Py�{!wªt��&}�vxw�r�~�|�} ê �

ÿ r�~�{!w*��w�tPsj|�z�����}Pr�~�|�{!}��&����|�t=|�r�}P~sQ{�t=~�§�w���w!y��j}Py��&w!�Çsj¢N�.§�}P��r�{�t=����¢��N�?w*{�t=~�sjw�sj¢N�.§�}P��r�{ × �Û{�t=��{!�����su�&}H��w!��{f��w!{f¾xw!y�s�|�}�sj}P��vxwQ��tP�&w�s6�sjr�~����#FHF6s�� ² ��w��&}H��w!���{f��w!{f¾xw!y³�?wU{!}P~sjr���w!y¬r s��©r�w!y�w���s¬�&}H��w!�;{f��w!{f¾xw!y�D*I�m����Ï × m��� Ô o�=q ���.��r�{f��r s¶��w!�vxw!��}P��w!���.r�|��Çt=~¨t=r ��|�}¸§�w�t × �Û{�t=��{!�����s��&}H��w!�#{f��w!{f¾xw!y¬|��t=|���w!y��j}Py���s�tPs?�?w!���tPs�sj¢N�.§�}P��r�{��&}H��w!���Û{f��w!{f¾xw!y�sÃ��r�¾xw ��R��ª}P~�|���w^�%�PV��jy�t=���&w!~�|���D*I�m����r s�t��#FHFá��&}H��w!�u{f��w!{f¾xw!y�}P��|�r �&r��!w!���j}Py&|���w × �Û{�t=��{!�����s?�sjr�~���|�w!{f��~�r�ß���w�s�sjr �&r�� t=y�|�}�|���}�sjww��&����}�¢xw!�£r�~¹�&}H��w!���Û{f��w!{f¾xw!y�s��j}Pyª�%�PV^Ïj��r�¾xw�t=����}H{�t=|�r�~��0z���w!��v�t=y�r t=§���w�}Py���w!y�r�~���s�j}Py.v�t=y�r t=§���w�su{!}��&����|�r�~��*z�����}Pr�~�|�s��n�jy�}P~�|�r�w!y³sjw!|³sjr �&����r�z�{�t=|�r�}P~��w!|�{�� Ô �

ÞÇ��w!~�{!}H��r�~�����tP�&w�s.r�~�|�} × �Û{�t=��{!�����s��©�?wU{�t=~¼t=� sj}�r �&����w��&w!~�| a ÑKå bÙæ�âãa å=ç h Øi Ñ âãhj]Ki ��r � w��¸|�w!y��&r�~t=|�r�~��¤|���w�t=§�}�vxwªz����Û��}Pr�~�|¬{!}��&����|�t=|�r�}P~\�.��w!~\�?wªy�w�t={f��t=~r�~�r�|�r t=�?sj|�t=|�w�� ² ��r s#{�t=~^§�w�w!~�{!}H��w!�\tPs�é

×Nê�ë Ï k`] Ñ b9ì Ï�������¸ê éx���� Ô©ì Ï�ÐfÑÓÒ a�íîQï ð�ñfò+óÙô õ�ö�÷ îQø+ð�ñfò+ó ô õ�ù`÷

�(ú¸û!�+ú¸ýü¡ ê Ô�Ô

è�~^|���wªt=§�}�vxw��nr���t=~^r�~�r�|�r t=�Qsj|�t=|�w�r suy�w�t={f��w!���|���wªsjw!| ê r ���&w!��r t=|�w!��¢¸�Pw!|�s�sjw!||�}�|���w�w!~�|�r�y�wªsjw!|Ã}P�.sj|�t=|�w�s�t=~��^|���w�z�����}Pr�~�|�|�w!y��&r�~t=|�w�s��

Page 48: BMC’03 - JKUfmv.jku.at/papers/bmc03-preliminary-proceedings.pdfBMC’03 Boulder, Colorado, USA. ... Alessandro Cimatti (IRST, Italy) Raanan Fraer (Intel, Israel) Danny Geist (IBM

�������� �!" ��#��$&%�'(��)*��$��,+(-. �/

0 1325476987:3;=<>25?3:3@3AB@DCFEHGIABJ

KML&NPORQ�S�T�UVNWQ�XZY.S�U\[ZY.U\]�T�^Z_�`�a�b\c�[�d�eORY.Y.^�dfU\]�^ZQMgPS�Y.XZ_�Y.Xhd�e�df^iY.jkU.T�Y.^�l�mnY.o"T�pZU�dfl"T�Q�^l"Y.U\[Z^ZT�q�rZY�s3tudf^�L*evL&NPORQ�S�T�UwNWQ�XZY.S�U\[ZY.U\]nY.oMe5r�evY�x ��� ey`�z\c{d�e|o"Y.}Zo"Y�evY.^�lMdfl"T�Q�^�e�~vQ�oevY.lMe�Q�~9evlMdfl"Y�eydf^ZXhl"oMdf^�evT�l"T�Q�^ho"Y.S�dfl"T�Q�^�sy�HQMg5Y.mnY.oM��l"[ZY�evT��.Y�Q�~(x ��� e9Nkd"L�T�^ZU.o"Y�d�evYY.��}RQ�^ZY.^�l"T�dfS�S�L*d�e|l"[ZYi^�r�NPORY.oyQ�~�mZdfo"T�dfOZS�Y�e"s� Y.U.Y.^�l"S�L��Rd{^ZY.g�l�L�}RY9Q�~�NWQ�XZY.S�U\[ZY.U\]�T�^Z_�l"Y.U\[Z^ZT�q�rZY����\�#�����#�\�������#�������#�\�����v���

gPT�l"[�e"dfl"T�evp�dfOZT�S�T�l�L�evQ�S�m�T�^Z_�`�����a�afc��([�d�e�S�Y.X�l"Q�}Zo"QRNWT�evT�^Z_>o"Y�evrZS�lMe"sI��^�ORQ�rZ^ZXZY.XNWQ�XZY.SBU\[ZY.U\]�T�^Z_R� _�T�mnY.^¡d3l"oMdf^�evT�l"T�Q�^>evL&evl"Y�N£¢H�Bd3l"Y�NW}RQ�oMdfSBS�Q�_�T�U�~vQ�oMNPrZS�d�¤¥df^ZXd,r�evY.o"¦fevrZ}Z}ZS�T�Y.X�ORQ�rZ^ZX¨§�©�ªV��g5YhU.Q�^�evl"o"rZU.lud,}Zo"Q�}RQRevT�l"T�Q�^�dfSP~vQ�oMNPrZS�d¥` `«¢�¬­¤#c c¯®gP[ZT�U\[�T�e�e"dfl"T�evp�dfOZS�Y�T�~°df^ZX±Q�^ZS�L¥T�~Pl"[ZY�~vQ�oMNPrZS�d²¤²T�e9mZdfS�T�X³dfS�Q�^Z_¡evQRNWY�}�dfl"[�Q�~S�Y.^Z_�l"[>§sP´�[ZY.^��g5Y�evQ�S�mnY�l"[ZYi~vQ�oMNPrZS�dk` `«¢�¬­¤#c c¯®Vr�evT�^Z_�d°µ ��¶ evQ�S�mnY.oMs

·#¸"¹»º5¼{½¿¾ ��ÀÁ�#���#Âà Q�ohevQ�S�m�T�^Z_¥ORQ�rZ^ZXZY.X¡_Rd�NWY�e"��g5Yw^ZY.Y.X¨NWQ�o"Y�XZY.pZ^ZT�l"T�Q�^�e"sÅÄ{T�mnY.^¨d�_Rd�NWY�ÆDÇÈ ¢�¬ÊÉ&¬MË�¬"Ì�Í"�Rd�evl"oMdfl"Y._�L¥¤ df^ZX*d9ORQ�rZ^ZX±§�#Î��ÐÏ#ÑÒ ®�Ó ¤�Ô�T�e�l"[ZY�evY.l{Q�~�}ZS�d"L&e�Q�~BS�Y.^Z_�l"[§�gP[ZT�U\[Õdfo"Y,}RQRe"evT�OZS�Y�gP[ZY.^�l"[ZY�evL&evl"Y�NÖ~vQ�S�S�QMg°e9l"[ZY�evl"oMdfl"Y._�LŤ�s�×Øevl"oMdfl"Y._�LŤT�eidh��Ù�ÚH�v�����v����Â\ÀÁÛÊÏ#ÀÁ�\��ÑwT�^�d�_Rd�NWY²Æ�T�~(~vQ�o,dfS�SVÜ*ÇFÝ.Þn¬­ß�ß�ß.¬ÊÝ­®w©�Î��ÐÏ#ÑÒ ®nÓ ¤�Ôidfo"YgPT�^Z^ZT�^Z_R�ZT�s Y�s���l"[ZY.o"Y°Y.��T�evlMeVd3}RQRevT�l"T�Q�^>à�á�âyá�§ evrZU\[ul"[�dfl,ËR` Ý­ã�c�ÇFÀÁÛf���hdf^ZXu~vQ�odfS�S|}RQRevT�l"T�Q�^�eià�á�ä²å³â\�BÌ&` Ý­æ�cPÇçÀÁÛf���s,´�[ZYu�\�#�����#�\� ��Ï#���3Î�ÛÊ�#���Ð���èT�e"�R_�T�mnY.^�d_Rd�NWY�ÆÕdf^ZX²d{ORQ�rZ^ZX�§�nl"Q�U\[ZY.U\]kgP[ZY.l"[ZY.o5l"[ZY�evL&evl"Y�NÕ[�d�e5d�§�¦égPT�^Z^ZT�^Z_wevl"oMdfl"Y._�LT�^�l"[ZY�_Rd�NWYuÆis,ê�Q�^�evY.q�rZY.^�l"S�L���g5Ykg3df^�l3l"QwU.Q�^�evl"o"rZU.l�d�ORQ�Q�S�Y�df^�~vQ�oMNPrZS�dwë9ìí|î ®gP[ZT�U\[�T�e3e"dfl"T�evp�dfOZS�Y�T�~Vdf^ZX²Q�^ZS�L T�~�l"[ZYhevL&evl"Y�Nç[�d�eVdw§�¦égPT�^Z^ZT�^Z_±evl"oMdfl"Y._�LhT�^�l"[ZY_Rd�NWY�ÆisÄ{T�mnY.^ïd³_Rd�NWY=Æ Ç È ¢�¬ÊÉ&¬MË�¬"Ì&Í�gPT�l"[ð¢ñÇ Óóò�ô ¬ ò�õ ¬­ö ô ¬­ö õ ¬Ê÷ ô ¬Ê÷ õ Ô

df^ZXïdÕORQ�rZ^ZXø§�ug5Y�XZY.^ZQ�l"Y��u~vQ�o�Y.mnY.o"Lïàùáúâûá §�ul"[ZY�âÁ¦él"[èU.Q�}�LÖQ�~ò ¬ ò�ô ¬ ò�õ O�L ò ã ¬ ò ãô ¬ ò ãõ �(o"Y�ev}RY.U.l"T�mnY.S�L�sÕg5YuXZT�m�T�XZY�ɱT�^�l"Q>É ô df^ZX�É õ gP[ZT�U\[dfo"Y�l"[ZY�T�^ZT�l"T�dfS|mZdfS�rZY�e5~vQ�o ò�ô df^ZX ò�õ � o"Y�ev}RY.U.l"T�mnY.S�L�s��HQMg5Y.mnY.oM�&rZ^ZS�T�]nY�ORQ�rZ^ZXZY.XNWQ�XZY.SyU\[ZY.U\]�T�^Z_R�Pg5Yu^ZY.Y.X�dfS�l"Y.o"^�dfl"T�Q�^�eiQ�~VY.��T�evl"Y.^�l"T�dfS3q�r�df^�l"T�pZU�dfl"T�Q�^�df^ZX�rZ^ZT�¦mnY.oMe"dfS5q�r�df^�l"T�pZU�dfl"T�Q�^±T�^±Q�o"XZY.o�l"Q>evQ�S�mnY�d�ORQ�rZ^ZXZY.X±_Rd�NWY�}Zo"Q�OZS�Y�Nks�´�[ZY.o"Y.~vQ�o"Y��l"[ZY*~vQ�oMNPrZS�d�ë ìí|î ® T�e d�q�r�df^�l"T�pZY.XFORQ�Q�S�Y�df^�~vQ�oMNPrZS�d�ORY._�T�^Z^ZT�^Z_�gPT�l"[=d�}Zo"Y.pZ�ü ò Þô ¬­ö Þô�ý þ ò Þõ ¬­ö Þõ�ý ß�ß�ß ý ü ò ®Òÿ ìô ¬­ö ®Òÿ ìô ý þ ò ®Òÿ ìõ ¬­ö ®Òÿ ìõ ý ü ò ®ô�ý þ ò ®õ s�ë ìí|î ® XZY�evU.o"T�ORY�el"[�dfl�l"[ZY.o"YhY.��T�evlMe�d¥evY.o"T�Y�eVQ�~kevL&evl"Y�N���e,NWQMmnY�e3l"Q�_�r�dfoMdf^�l"Y.Yhl"[�dfl�~vQ�oudfS�S°evY.o"T�Y�eQ�~�Y.^�m�T�o"Q�^�NWY.^�l���eVNWQMmnY�e"�Zl"[ZYi_�QRdfS&o"Y._�T�Q�^hT�e|o"Y�dfU\[ZY.Xul"[Zo"Q�rZ_�[hl"[ZY�e"df~vYio"Y._�T�Q�^�d�eS�Q�^Z_hd�e�l"[ZYVY.^�m�T�o"Q�^�NWY.^�lP}Zo"Q�U.Y.Y.X�ePdfU.U.Q�o"XZT�^Z_�l"Q�l"[ZYWl"oMdf^�evT�l"T�Q�^�o"Y.S�dfl"T�Q�^�sPë í|î ®9T�ed�e�~vQ�S�S�QMg°e"s

ë ìí|î ®�� ü ò Þô ¬­ö Þô ý þ ò Þõ ¬­ö Þõ ý ß�ß�ß ý ü ò ®Òÿ ìô ¬­ö ®Òÿ ìô ý þ ò ®Òÿ ìõ ¬­ö ®Òÿ ìõ ý ü ò ®ô ý þ ò ®õ ýÉ ô Óóò Þô Ô���� ì � Ó É õ�Óóò Þõ Ô��� ì Ô� �

gP[ZY.o"Y��� � ì � ®Òÿ ìã ��Þ ÷ ôRÓóò ã�¬­ö ãô ¬ ò ã � ìô Ô"�� ì � ®Òÿ ìã ��Þ ÷ õ�Óóò ã�¬­ö ãõ ¬ ò ã � ìõ ÔPdf^ZX

z

Page 49: BMC’03 - JKUfmv.jku.at/papers/bmc03-preliminary-proceedings.pdfBMC’03 Boulder, Colorado, USA. ... Alessandro Cimatti (IRST, Italy) Raanan Fraer (Intel, Israel) Danny Geist (IBM

��������������������� �!��"#�����%$!&'��()+*-, ./ 02143657398 /;:�< =6> /@?�398 = :�:�ABDC#E�FHGJI6K7L�MNG%OPL Q�RTSHUVI�WYXZ4[ . \ E�FHGJ]PSHKHOPL Q�RTSHUVI ] \T^ X I6CH_a` X \ OPL Q�b'G�E�FcI6E�E�FHG%CHG'd�E]PE�I6E�G�]eI6UDL CHf�E�FHGhgcI6E�Fi]PFHL SHUD_jL K7G'klE�FHGYE�Q�I6Cc]PmDE�mDL C%Q�G'UVI6E�mDL CJI6CH_ * G'CHb'L�_HG�]nQ�G�I6boFHpI6KHmDUDmDEVkjE�L�E�FHGqf L7I6U�Q�G'f mDL C+E�FHQ�L SHf F-E�FHGj]�I6OPGqQ�G'f mDL C+rTmDE�FHmDCts-]PE�G'gc] AucFHG!E�L E�I6U�C�ScRTK7G'Q4L OHMHI6Q�mVI6KHUDG�]2mDC-WYXZ4[ . mV]4v 3 s�wyx : rTFHG'Q�Gzx|{~} 8��Y�+�c�Y�+� } \I6CH_qE�FHG�UDG'CHf E�F�L OnWYXZ4[ . 3 I6OPE�G'Q!]PL7R�G�]PmVR�gHUDmD�Hb�I6E�mDL C : mV]�v 3 s2w 3 } � � }��z} � � }��z} 5 }��z} ? } : �} � � }���} � � } : rTFHG'Q�Gi} 5 }���} ? }���} � � }���} � � }���} � � }�I6CH_�} � � }4I6Q�GlE�FHGlUDG'CHf E�Fc]eL OeOPL Q�RTSHUVI ] ABDC�E�FHmV]TG'd�gHQ�G�]�]PmDL C \ s�w 3 } � � }H��} � � } : mV]TE�FHG%_HL7R�mDCcI6C�E�O�I6b'E�L Q�K7G'b�I6Sc]PG#} � � }�I6CH_} � � }�I6Q�Gq��ScI6_HQ�I6E�mDbqmDCtx \ KHSHEl} 5 }�I6CH_t} ? }�I6CH_+mV]4UDmDCHG�I6QYmDCtx A

��GY_HG'�HCHGlI�CHG'r�OPL Q�RTSHUVI�W4�Z4[ . rTFHmDboFjFcI ]�E�FHQ�G'GYG'd�E�Q�ITb'L gHmDG�]�L O7E�FHGYMHI6Q�mVI6KHUDG�]8��J�+�j���+� \ KHSHEqrTFHmDboF#mV]�]PFHL Q�E�G'QqE�FcI6C�E�FHGlgHQ�G'M�mDL Sc]�OPL Q�RTSHUVI+WYXZ4[ . ]PmDCHb'G�mDEFcI ]�L CHUDkaL CHG+L�b'b'SHQ�Q�G'CHb'G�L O�� � I6CH_�� � A ucFHG�E�Q�mDbo�amV]�E�L�FcI�MNGtI6C~I6_H_HmDE�mDL CcI6USHCHmDMNG'Q�]�I6U���ScI6C�E�mD�Hb�I6E�mDL C�I6OPE�G'Q�E�FHG�s�I6UDE�G'Q�CcI6E�mDCHfj��ScI6C�E�mD�HG'Q�]qI6CH_iE�LjE�Q�G�I6E�E�FHG�]PGI ]�E�G�R�g7L Q�I6Q�ktMHI6Q�mVI6KHUDG�]�I6CH_�boFHG'bo��E�FcI6E�mDO�E�FHG'k�R�I6E�boF�E�FHG��; ¢¡tI6CH_ 3 �T�¤£ :9¥'¦b'L g�ktL O�E�FHG�L Q�mDf mDCcI6UhMHI6Q�mVI6KHUDG�] \ E�FHG'C§E�FHG'k�]�I6E�mV]POPk�E�FHG�gHQ�G'_HmDb�I6E�G�]�� � I6CH_�� � A¨ SHKc]PG'��SHG'C�E�UDk \ E�FHG�E�L E�I6U2C�ScRTK7G'Q�L O�MHI6Q�mVI6KHUDG�]nmDCJW �Z4[ . mV]�v 3 s�w'x : I6CH_%E�FHG�UDG'CHf E�FL O�W �Z4[ . 3 I6OPE�G'Q�]PL7R�Gl]PmVR�gHUDmD�Hb�I6E�mDL C : mV]ev 3 sew 3 } 5 }©��} ? } : ��} � � }©��} � � }©��} � � }©��} � � } :ªAW � Z4[ . mV]4f mDMNG'C�K�k�«W � Z4[ . ,~¬­8 1� � � 1��® ¯ 8 1� � � 1��® w@w@w ® ¬­8 .��® ¯ 8 .�e® ¯2° � °�± � °�² ��³���³ ± ��³ ²P®

� �´398 1� :�< ^ � < 3 � ��398 1� :�< ` � :�µ *rTFHG'Q�G \) ^ � , .­¶ X/ 021 3�398 / { ° :�< 3©� /� { °�± :c< 398 / · X� { ° ² :�:eµ � �73 ° � °�± � ° ² : \) ` � , .­¶ X/ 021�3�398 / {�³ :�< 3©� /� {~³ ± :�< 398 / · X� {~³ ² :�:�µ � ��3 ³���³ ± ��³ ² : I6CH_)+*-, ./ 02143657398 / :�< =6> /@?�398 = :�:�A

��Gl_HG'CHL E�G�K�k�¸a¹ºE�FHG�R�G'E�FHL�_�rTFHmDboF#Sc]PG�]!E�FHG��HQ�]PE�OPL Q�RTSHUVI-W XZ4[ . E�L�]PL UDMNGE�FHG�f7I R�G \ I6CH_lK�k-¸+»�E�FHGzR�G'E�FHL�_lrTFHmDboF�Sc]PG�]�W �Z4[ . A ��GTSc]PG�¼T½N¾�]PL UDMNG'Q�]�]PSHboFiI ]¿�À "cÁ�(NÂÃÁ�Ä £ ÅoÆ \ ¼ ��� ¾�¾ & À ÄDÇ È Æ�I6CH_j¼ � ½ À Ä £ É6Æ�mDClL Q�_HG'Q4E�L%]PL UDMNG�E�FHG�I6K7L�MNGT��ScI6C�E�mD�HG'_K7L�L UDG�I6C-OPL Q�RTSHUVI ] AÊ�Ë »ÍÌ2Î�Ït¸+Ð@ÑÓÒ�Ô@ÕºÖ�×oØPÙ2ÚlÌ2ÑÓÛÝÜ�ÑÓÐoÚ@ÞiÏ2ÛÝÐoÐucFHGqK7L SHCH_HG'_�f7I R�GqgHQ�L KHUDG�RßmV]�CcI6E�SHQ�I6UDUDkjE�Q�I6Cc]PUVI6E�G'_�E�L�I�¼T½N¾�]PL UDM�mDCHf�gHQ�L KHUDG�RI ]�reG�]�I�r¤mDC ¨ G'b'E�mDL Cià A £jI6CH_ireG+RTSc]PE�Sc]PGj¼T½N¾%]PL UDMNG'Q�] A�á L�reG'MNG'Q \ ]PG'MNG'Q�I6U ¿ �@â]PL UDMNG'Q�]YFcI�MNGjQ�G'b'G'C�E�UDk�]PFHL�rTCagHQ�L7R�mV]PmDCHf�Q�G�]PSHUDE�] A BDC�E�FHG%CHG'd�EzEVreLã]PSHKc]PG'b'E�mDL Cc] \reG�]PFHL�rßFHL�rßE�LjE�Q�I6Cc]PUVI6E�GlE�FHG�f7I R�GlgHQ�L KHUDG�RäE�L�I�K7L�L UDG�I6CiOPL Q�RTSHUVI�L CHUDk�rTmDE�FG'd�mV]PE�G'C�E�mVI6U���ScI6C�E�mD�Hb�I6E�mDL C�mDC+L Q�_HG'QYE�L�Sc]PG ¿ �@â ]PL UDMNG'Q�] AåNL QnE�Q�I6Cc]PUVI6E�mDCHfYE�FHGe��ScI6C�E�mD�HG'_zOPL Q�RTSHUVI�OPL Q!W Z4[ . mDC�E�FHG�gHQ�G'M�mDL Sc]c]PG'b'E�mDL CzmDC�E�L�IK7L�L UDG�I6C%OPL Q�RTSHUVI \ reG�CHG'G'_jE�LzG'UDmVR�mDCcI6E�G�SHCHmDMNG'Q�]�I6U���ScI6C�E�mD�Hb�I6E�mDL CºK�k�mDC�E�Q�L�_HSHb'mDCHfG'd�E�Q�I4b'L gHmDG�]HL O�MHI6Q�mVI6KHUDG�]ÃmDC�L Q�_HG'QnE�L�]Pg7G'b'mDOPk�G'd�gHUDmDb'mDE�UDk%I6UDU b�I ]PG�]HrTmDE�FHL SHEnSHCHmDMNG'Q�]�I6U��ScI6C�E�mD�Hb�I6E�mDL Ccæ!OPL Q�G'd�I R�gHUDG \ ¯2ç4® ¬­è ® 3 ç < è : ,鬭è X � è � ® 3�3 ÑÓÛ6Ö�Ð < è X :�:!< 3Pê Ü�ë¢×oÐ <è � :�:ªA å´mDf SHQ�GzÉq]PFHL�rz]�Q�G'UVI6E�mDL Cc]�K7G'EVreG'G'CJ]PSHb'b'G�]�]PL Q�]!I6CH_�gHQ�G'_HG'b'G�]�]PL Q�]nmDC-¼T½N¾�I6CH_

ì

Page 50: BMC’03 - JKUfmv.jku.at/papers/bmc03-preliminary-proceedings.pdfBMC’03 Boulder, Colorado, USA. ... Alessandro Cimatti (IRST, Italy) Raanan Fraer (Intel, Israel) Danny Geist (IBM

í�î�ï�ð�ñ�ò�ñ�ï�î�ó�ô õ!î�ö#î�ó�ï%÷!ø'ñ�ù

k steps

Tree−based SAT Method

k steps

QBF Methods

ú'ûãüý7þ ÿ ûãü�ú'û��ý7þ ÿ û���

� ü� �

���

û�� ü��ý û�� ü�� ü��� û�� ü��ý û�� ü�� ���

û�� ü�� ü��ý û�� ü�� ü�� ü��� û�� ü�� ��ý û�� ü�� �� � ��

� � ü��� � ü�� ü�� � � ü�� ��

� � ü�� ü�� ü�� � � ü�� �� � �

��������������������� �"!�#���$�% î�&(' ��)�*"+,$

% î�&.-0/21436587:94;=<?>@14A4/2/2BDC:EF9 /27 % î�&.-0/21436587:GIHJ/LK?>"14A45876M6N2/L/2O"P6Q?K?N2K?14Q?RS5F>6/LN25FP"R.5FTU EVA4K�EVC6Q?/"9�T 5FAW/ U /2A4R=>65876/XK?>�1436/X14A4/2/";ZY:3"M:94G[1436/X>"M:-\C�/2AJ5FT�N25FP6K?/"9�K�9�/2O"P�5F>6/2>"14K�EVQK?>]1436/^C�5FM6>67`_a;

b U /2A4R.P:EV143S5FTW1436/(14A4/2/2BDC:EF9 /27 % î�&c-0/21436587dN25FA4A4/"9 P�5F>67:9�145eE^P6Q�E4Rc5FTWQ?/2>6fF143_gEV>67hHJ/ji M:9 1Z>6/2/27k145(H\A4K?14/�EXT 5FAl-\M6Q�EX145(N�36/2N�mg143:EV1n1436/jP:EV143:9Z9 1lE4R�K?>h1436/�o�prq4sA4/2fFK?5F>]M6>"14K?Qt1436/2RhA4/"EVN�3c1436/hu�v�p[wxA4/2fFK?5F>:G"H\36K?N�3SHJ/^H\A4K?14/hEF9y1436/^T 5FAl-\M6Q�E�z { � | ;

Y:36/^>"M:-\C�/2AX5FT U EVA4K�EVC6Q?/"9:K?>}z { � | K�9�~�������� |��6�4� H\36/2A4/���K�9:1436/h-=EVO"K�-\M:->"M:-\C�/2A=5FT�/2> U K?A45F>:-0/2>"1l�?9g-05 U /"9�EV>67`1436/]Q?/2>6fF143`5FTLz { � | K�9=~���� |��6� �I��� � ý ���� � � �2��_\��� �x�2��_\��� ��� � ��� � ý �2��� � � � � ;t�e/01436/2>hM:9 /(����ù[�Ãö:�¢óg�?�F�V��EV>67S�r �ð�î"¡�¡¢�?�F£��K?>]5FA476/2AX145S9 5FQ U /�1436/^C�585FQ?/"EV>]T 5FAl-\M6Q�E�z { � | ;

¤[¥ ¦¨§�©0ª`« s�¬®­[v�¯k°8o�± ²�u`³=± ¬®²�s�o�o § s�¬<?>´1436/µ9 14AlEV14/2fFR"BD14A4/2/}C:EF9 /27 % î�&¶-0/21436587:GjHJ/·N25F>:9 14A4M6N214/27¸Ee14A4/2/}H\36K?N�3�K�9SEH\K?14>6/"949¹T 5FAdEkC�5FM6>676/27ºf�EF-0/cP6A45FC6Q?/"-»H\K?143¼EhC�5FM6>67�_a;½Y:36/.14A4/2/"GJ365lHJ/ U /2AlGN25FM6Q?7`3:E U /·-=EV>"R}K?76/2>"14K?N"EVQ(9 1lEV14/"9=EV>67`HJ/]N�36/2N�m`1436/�9 14AlEV14/2fFR}T A45�-¾1436/]K?76/2>6B14K?N"EVQ=9 1lEV14/"9k-=EV>"Rº14K�-0/"94;<?>¿1436K�9k9 /2N214K?5F>:GZHJ/@K?>"14A45876M6N2/ºE}-0/21436587¿143:EV1hN"EV>fF/2>6/2AlEV14/ÀESH\K?14>6/"949S9 /21.H\K?143¶Q?/"949LN25FP6K?/"9L5FT U EVA4K�EVC6Q?/"94;ÁY:36/¿-=EVK?>¶K?76/"EdK�9L145N25F>:9 14A4M6N21@E�9 /21g143:EV1gH\K?14>6/"949 /"9�1436/.T4EVN21�143:EV1�1436/`9 R�9 14/"-ÁH\K?>:94;¼Y:3"M:94GnfFK U /2>E�f�EF-0/�»ÃÁÄ�ÅxÆ���Æl��Æ4��Ç(EV>67¶E�M:9 /2A.9 M6P6P6Q?K?/27ºÈÊÉ�ËjG:HJ/]fF/2>6/2AlEV14/�E�C�585FQ?/"EV>T 5FAl-\M6Q�E`zyÌ{ � Í H\36K?N�3¶K�9]94EV14K�9 Î:EVC6Q?/@K?TkEV>67µ5F>6Q?RºK?T¢HJ/@N"EV>¿fF/2>6/2AlEV14/ÏE.H\K?14>6/"9499 /21¹H\K?143�ȵ9 1lEV14/"94;kÐIK?Al9 1lG�HJ/=76/2Î6>6/���Ñ���Ò@Æ�Ó ý Æ�ÒdÔ � EF9^E�P6A4/276K?N"EV14/=T 5FA¹1436/L>6/2O"19 1lEV14/=H\36/2>e1436/�/2> U K?A45F>:-0/2>"1l�?9¢-05 U /�K�9nÎ6O"/27:;cÐ,5FA¹/"EVN�3�/2Q?/"-0/2>"1¢�]Ñ�5FTJ1436/S9 /21Õ � � Æ�� � Æ������rÆ���Ö�×ÙØ6ÚL5FTZ1436/g/2> U K?A45F>:-0/2>"1l�?9L-05 U /"94G���ÑÛ��Ò@Æ�Ó ý Æ�ÒdÔ � K�9\1436/gP6A4/276K?BN"EV14/(5FC61lEVK?>6/27dT A45�-Ê� ý ��Ò@Æ�Ó ý Æ�Ò Ôý �yÜ � � ��Ò@Æ�Ó � Æ�Ò Ô� � � H\36/2A4/=Ò Ô ÃµÒ Ôý�Ý Ò Ô� �C"R�A4/2P6Q�EVN2K?>6f@/"EVN�3Þ5FTX1436/ U EVA4K�EVC6Q?/"9jß¿ÉàÓ � H\K?143Þ1436/ U EVQ?M6/]�]ÑÛ��ß � ;ºáW5lH¢GyHJ/76/2Î6>6/@ELH\K?14>6/"949L9 /21¢T 5FAkELC�5FM6>676/27}f�EF-0/gP6A45FC6Q?/"-âEF9\T 5FQ?Q?5lH¢94;eãZK U /2>µELf�EF-0/¶ôÄ�ÅxÆ���Æl��Æ4��Ç�H\K?143dÅ�ö��Ò ý Æ�Ò � Æ�Ó ý Æ�Ó � Æ�� ý Æ�� � � EV>67=M:9 /2Aj9 M6P6P6Q?K?/27g>"M:-\C�/2AÈWGxäåà Õræ � Æ æ � Æ������2Æ æ Í Ú0K�9XE0H\K?14>6/"94909 /21XT 5FA\1436/^f�EF-0/kÂÀK?TXEV>67]5F>6Q?RkK?Tç T 5FA\1436/^K?>6K?14K�EVQxP6A4/276K?N"EV14/kè¢5FT¢éJGa��� æ � �yý¬®êV°8saG�EV>67

�Fë

Page 51: BMC’03 - JKUfmv.jku.at/papers/bmc03-preliminary-proceedings.pdfBMC’03 Boulder, Colorado, USA. ... Alessandro Cimatti (IRST, Italy) Raanan Fraer (Intel, Israel) Danny Geist (IBM

ì�í"î8ï"ð"ñ4ð"î[í"ò�óFôní"õ�í"ò"îgön÷2ð"ø

ù]ú ûFü¢ý"þVÿ���������� ��� ����������������tûFü��� � ����������������þ�!#"%$&�6ý2ü4ýhý('*),+-$�+Lþ.+-/ +-$4ý*000û�1,ý32 �4 +-56ÿ��6$&�:þ�$�ú ûFüWý"þVÿ��616þ�7�)�"�ý(7?ý*00ý(!*$82:9;)�!<$&�6ý=+ ý($�>?2A@�BC2EDFB�GHGHG(BC2:I;JLK*MûFútý(!*1*)?ü4ûN!;00ý(!*$O00û�1,ý*+Xþ�$P���Q*$&�6ý2ü4ý^ý('*),+-$�+�R8SUT VXWX+-56ÿ��Y$&�:þ�$PZ[9?� ���CBC2 �4 BC��\]�;���������^

_ �6ý^ú ûFü�0`5#7�þ<acbdce f�ú ûFü`g`)�$&!6ý*+&+-hji:þN+ ý("%k íHl 00ý($&�6û�"Y),+XþN+yú ûN7�7?û�gm+&^

a b dce f<nXo[prq @&sut f� vc@ ��prq �Qsuw � prq �Qsut I;JLK

9�vc@ pyxz9?prq�Qs|{ f

\-}F� Z[9(prq� B�~ �4 BCq \rs&s

g`�6ý2ü4ý�xz9A���Pprq s �ú ûFügý(1,ý2ü&/���V��UV�2E�*�;8),+hþ%�H�z���-�z�-���E�[�C���z�-���z���Sú ûFü6$&�6ýý(!*1*)?ü4ûN!;00ý(!*$��.xz9?� �������������E)?ú¢þ�!#"}ûN!#7�/�)?úP2:9�),+P16þ�7�)�"}ý(!*1*)?ü4ûN!;00ý(!*$���+O00û�1,ý�þ�$$&�6ý�+-$lþ�$4ýE�#^ _ �6ý�"6ý(�#!#)�$&)?ûN!·ûFú¢þ=g`)�$&!6ý*+&+=+ ý($(ú ûFü4ÿ2ý*+P$&�:þ�$¢ý(1,ý2ü&/�ÿ2ûN�*/A���|g`�#)?ÿ��),+�!6ûN$�þ��Fû�þ�7,�0`5;+-$Y�:þ&1,ýÏþ�$4ülþ�!;+-)�$&)?ûN!�$4ûU+ û�00ý���\ g`�6ý2ü4ý�T8),+:+-$4ü&)?ÿ($&7�/�7�þVü&�Fý2ü$&�:þ�!�R�^¡ WûN$4ý�$&�:þ�$ � f 0`5;+-$3�6ý(!6ÿ2ý�i�ýkþ��Fû�þ�7¢��û�+-)�$&)?ûN!·þ�!#"�)�!.ú4þVÿ($P$&�6ý�"6ý(�#!#)�$&)?ûN!ú ûFü4ÿ2ý*+0þ�7�7u�#7�þ&/ +�ý(!6ÿ2û�"6ý(".)�!.$&�6ý�g`)�$&!6ý*+&+�+ ý($3$4ûgý(!#".)�!�$&�6ým�Fû�þ�7,^�£�!�$&�6ý¢ú ûFü�0`5#7�þa b dce f�*$&�6ý�$4ûN$lþ�7 !*5;0`i�ý2ü�ûFú;16þVü&)�þ�i#7?ý*+�),+ ¤�prWYGz¥ s þ�!#"Y$&�6ý�7?ý(!#�N$&�.ûFú;$&�6ý^ú ûFü�0`5#7�þ),+<¤�pr2EW D G§¦ Z[9�¦©¨�WªG§py¦-�[¦©¨�¦ �¢¦ s ¨�¦ o ¦ s g`�6ý2ü4ý�2«),+¡$&�6ý%0=þ�'*),0`5;0�!*5;0`i�ý2ü�ûFúý(!*1*)?ü4ûN!;00ý(!*$���+`00û�1,ý*+&^�¬eý=þ���þ�)�!�5;+ ý®­�¯ øz°aõ;±�ò þ�!#".²?³ ï"í*´�´ )�!kûFü&"6ý2üµ$4û:+ ûN7�1,ý�$&�6ýi�û8ûN7?ý"þ�!]ú ûFü�0`5#7�þOacbdce f�^

¶ ·�¸P¹®ºu»©¼L½¾ºu¿PÀ�ÁÃÂ�Ä�ºuÅ�Æ�ÂLÀ�Ŭeýhþ�7,+ û=ÿ2ûN!;+-)�"6ý2üLþO+ ý2ÿ2ûN!#".ý('�þN03�#7?ý*�g`�#)?ÿ��.),+cÇ*!6û�g`!�$4ûOi�ý��:þVü&"]ú ûFü�­ î8î +P���NÈ��,^ÉËÊ �zÌ �[���mÍzÎ_ �6ý:+ ý2ÿ2ûN!#"Sý('�þN03�#7?ým),+3Ï�ÐÃ�?�.)�!*$4ü4û�"#56ÿ2ý(".)�!����NÈ��,^|¬eý�ÿ��:þ�!#�Fým$&�6ý�ý('�þN03�#7?ý®)�!*$4ûþ���þN00ýY�6ü4ûNi#7?ý*0O^ _ �6ý2ü4ý�),+�þ�!�þVü4ülþ&/�Ñ=�c�Pg`)�$&��W¿ý(7?ý*00ý(!*$�+�g`�#)?ÿ��¼þVü4ý�2�hji#)�$i#)�!:þVü&/�!*5;0`i�ý2ü�+&^:¬eý@þN+&+-5;00ý�$&�:þ�$®W�V�Ò I + û.$&�:þ�$kþ�7�7Jý(7?ý*00ý(!*$�+ )�!%$&�6ý@þVü4ülþ&/ÿ"þ�!Ói�ý®"#),+-$&)�!6ÿ($�^<£�!#)�$&)�þ�7�7�/YgJý=�:þ&1,ý*�ú ûFü�þ�7�7PÔ6VÕR�S�WÃ�Ñ=� R��8���ÖR�^ ×`$jý"þVÿ���+-$4ý(�;$&�6ý�+-/ +-$4ý*0�ÿ��6û8û�+ ý*+=þ<"#)?ü4ý2ÿ($&)?ûN!�i�ý($,gJý2ý(!����LØ&��þ�!#"U���-ÙHÚz��þ�!#"ª$&�6ýký(!*1*)?ü4ûN!;00ý(!*$ÿ��6û8û�+ ý*+nþ�!6)�!#"6ý('<R�N)�!6$&�6ý�ülþ�!#�Fý=ÔzB�GHGHG?BCWOÛ��NÜN$&�6ý(!�$&�6ý 16þ�7�56ý�ûFú¢Ñ=� R��§),+µ+-g¹þ��#��ý("g`)�$&�%$&�:þ�$¢ûFú`Ñ=��prRµÛU� s¢Ý[ÞNß W��JûFümÑ=��prRµ¨Ö� s Ý[ÞNß W��,ZþVÿ2ÿ2ûFü&"#)�!#�Ó$4û�$&�6ý6"#)?ü4ý2ÿ($&)?ûN!$&�6ý<+-/ +-$4ý*0�#)?ÿ�Ç,ý(";^ _ �6ý��6ü4ûN��ý2ü&$,/6gJý�g¹þ�!*$`$4ûLÿ��6ý2ÿ�Ç�),+;g`�6ý($&�6ý2üP$&�6ý6+-/ +-$4ý*0�ÿ"þ�!ý(1,ý(!*$&5:þ�7�7�/Ö0=þ�Ç,ýYÑ=��Ô��^þ�!#"XÑ=������+4þN00ýE!6û�0=þ�$&$4ý2ü=g`�:þ�$=$&�6ýký(!*1*)?ü4ûN!;00ý(!*$<"6û8ý*+p-$&�6ý�+-/ +-$4ý*0¼ÿ(7?ý"þVü&7�/E7?û�+ ý*+ s ^¬eý.ÿ2û�03�:þVü4ý.$&�6ýX00ý($&�6û�";+�gJýÞþ�"#"6ü4ý*+&+ ý("�5;+-)�!#�ª$&�6ýXà['�þN03�#7?ý*+:�}þ�!#"ÒN^âá,ûFüã`ä ´ 00ý($&�6û�";+&�ûN56ü®�6ü4ûN�FülþN0å�6ü�+-$=�Fý(!6ý2ülþ�$4ý*+=þÓætû8ûN7?ý"þ�!·ÿ()?ü4ÿ(5#)�$.��ÒNç��µ�#7?ý*�g`�#)?ÿ��),+=þ�00ûFü4ý%+-56ÿ2ÿ()�!6ÿ($�ú ûFü�0=þ�$=$&�:þ�!Õ³ ò*´ ^ _ �6ý(!XgJýY5;+ ý äéèNê�è ò*´ ��ÒNç��`$4û�$4ülþ�!;+-7�þ�$4ý$&�6ý<ætû8ûN7?ý"þ�!]ÿ()?ü4ÿ(5#)�$`)�!*$4û:³ ò*´ ^P£�!E$&�6ý��6ü4û8ÿ2ý*+&+&¢0=þ�!*/�)�!*$4ý2ü�00ý("#)�þ�$4ý�16þVü&)�þ�i#7?ý*+\þVü4ý)�!*$4ü4û�"#56ÿ2ý(";^Pá§)�!:þ�7�7�/*"ûN56ü8�6ü4ûN�FülþN0 þ�$&$lþVÿ��6ý*+cë*5:þ�!*$&)��6ÿ"þ�$&)?ûN!:$4û=$&�6ý=³ ò*´ �#7?ýgþ�5#$4ûNh0=þ�$&)?ÿ"þ�7�7�/.þ�!#"6gJý35;+ ý ã`ä ´ + ûN7�1,ý2ü�+8+-56ÿ��eþN+�k*¯ õ;ìløéí�ì ã ð"í*´�´�÷ ¯¢þ�!#" ã ð ä ¯`$4û:+ ûN7�1,ý$&�6ýO³ ò*´ ú ûFü�0`5#7�þ3g`)�$&��ë*5:þ�!*$&)��6ÿ"þ�$&)?ûN!;^

�N�

Page 52: BMC’03 - JKUfmv.jku.at/papers/bmc03-preliminary-proceedings.pdfBMC’03 Boulder, Colorado, USA. ... Alessandro Cimatti (IRST, Italy) Raanan Fraer (Intel, Israel) Danny Geist (IBM

î<ï*ð�ñ*ò*ó&ò*ðzï*ô õNöµï*÷Aï*ô*ð6øµù(ò*úû3ü,ý-þ�ÿ��-þ���� ï���� ��� þ��;ý�� ��� �� ��� �� ���uþ�þNü � ��� � � � ��� �"! ü � � � � ��� � ý-ü#� ��$� �

� þ&% ô(')� ý � ����*,+�-�+Nô('/.102"� ý "���� � ï�� ý-þNü 3 ��ý5476 ú98�÷;:�ô � � �2<=% ñ*ï('>' þ �&���� % ô('�-þ�� �?� ü#� . û3ü�ü @(AB � �#�� �(� ýC� � "AB ���-þ�� �� �Yþ � �$DFE � ý � ��� �$G�HJICKLD �(��� �;�NM�M�MA �&þ � ý&ý-þ���ÿOG . P HJ� ��(� þ���QR� � � ����TSU� �(��@ þ AB ��� ��� ��� ýVQ ý ��(�$.W �� � ý � ü � ýX�-þ��$Y @ � ��A ü GT�Z� ý � þ�� �� � W �Z[#ü G"� �� � �����\���#�� ý � þ�� ��� ý����� @( � ����� þ �&���#��]� � ý � þ � �;ý&ÿO^ _B` �� � � ý ��� � ��� � � � � � þ ��� þ ��A ü ��a� � G�b � þ � ��ý&ÿ� � �Rc �� � � ý ���� ý � K þ�� ����]� ��A����?! ü �a�Ný � þ�þ®ü#�Z� ��]� þ @( � ����Td þ�3 �eG�HJ�5f .�M �4 ð�ð��� ��� þ��;ý&ÿ ����"�(�;� [ � � ��A �Z� �(���� ý � ý � ý ����J�(�;� [ � þ�� � �� ��� ��� þ � ý � �Zg �h� þ� � �i������"!�@(jkA þ � �(� � ��� ü J� ������ � � ���� ý&ý �� ��� þ��;ÿ ����"�(�;� [ � � ��A �Z� �(���� ý � ý � ý���� ý � K þ�� ���� � � ���� ý&ýµý ��.5l þ�� �Z�&ü Q �� � ��� � � ��� þ � � ý � ü � ý&ÿ ����)� þB��ü A þ�ý � ��� þ � �a�Ný�i� þ�ý � �Ný dnmFo,p9q p=mFoir f;�-þ�� ����JmtsTm�� � � �;ý .�M ������� ý @ � ��A ü ÿ î<ò(+�8 6 AB ���-þ�� �� �[ ���� � ��� � �Yî�uU+Nñ*ï�.5l þ��)v *,'"�� ��� þ��RwxGNÿ�v ò(* 6 dVyC � . �5z9G . b�f��|þ���g �{[ ý � � � ��-þ��"v *,'��� ��� þ��|wx}NÿO�(6 ÷;~�ú,uU~TdVyC � . } r b�}�b�}�fPý � þ�� � ���� [ ý � � ý � ü ��."l þ��J� ï���� ��� þ��;ý&ÿU476 ú98�÷;:�ô �|þ���g �T[ ý ��. W �� � ý � ü � ý � ������)� �Z[#ü �Z� )���� � ý � ü � ýO�-þ�� ����� þ�þNü,ý ��� � �5AB ���-þ�� �� �&[ ý ��.)l þ�� ����� ý @ � ��A ü ÿ�4 ð�ð/j [;�Ný � �� ��� þ��;ýPý (� [ ���� ���� � � v *,' ÿ�� � ��� ï��>j [;�Ný � �� ��� þ��;ý ý (� [ ���� � ��� � � v *,'�jZ�� ��� þ��;ý .W �Z[#ü }�ý � þ��mý ���� � ý � ü � ý)�-þ��TY @ � ��A ü }�� �� � T���� 4 ð�ð��� ��� þ��%þ ����AB � j�-þ�� �� �v *,' � � �� ï��L�� ��� þ��;ý .)�C� ü � g Y @ � ��A ü GNÿ ���� v *,'e�� ��� þ��&�a�Ný;[ ���� ���� � ������e� � j [;�Ný �R� ï��&�� ��� þ�� . W ��� ý � ý AB � � � A ý7[ � � � ý ÿ � � Y @ � ��A ü }Nÿ ���� � 3 � �&þ �;�� �(�]� �Ný m�� þ�3 ý]� �� 3 ��Qªý � � �� ÿ�� ��� �i�|� �Zg ý ���� ý � ��� �� � Q � � 3 ��Qü#�Z� �� ÿ(� ��� ü J� � Y @ � ��A ü GNÿ � �)� �Ný)� �e� þ�ý �)! 3 {� þ�3 ý�� � � � QAý � � ��(.� �t�X�a�O���a�U���X�a�02�� ��3 ?A � ý �(�� �$3��Z� � þ � ýcýVQ � [�þNü � �e�� ��� þ��;ý � ý � ��� 4 ð�ð ý&ÿ(� ï��>j ý-þNü 3 ��ýC� � �Tv *,'�jý-þNü 3 ��ý � þ�ý-þNü 3 ýVQ � [�þNü � � ��ü�ü Q A � ý �(�� �âý ��� � � ��� �T� � �� ýT� � � 3���ü � � �� � ����(�þ ��� �|þ @ � ��A ü ý . W ��� ý"� ý �Z� �i��� ý A � ü �#��� � �Z��Q�� � ��þ ��h� � ��� þ � ������� � �Z���� þ ��� ü � ý � þ � ý�Q ��.�l �&þ ������T� � ��� �(� � ý � ü � ý&ÿ � þ�� 3 ��ÿ � � �#þ ý®ý (����� � � 4 ð�ð ýdV ý AB � � ��ü�ü Q î<ò(+�8 6�f8þ ����AB ���-þ�� ���� ��� þ��;ý ��� � �J� ý LA �&þ A þ�ý � ��� þ � ��ü¡ý-þNü 3 ��ý . W ��� � � �A �&þ�[#ü (� � � ��� � � ��� ��� þ �� þ� ï�� ý (� ý � þT[ \����\ @(A þ �� �(��� ��ü7[#ü�þ�� jk��A�� ����� � � ��� ��� þ �$� þ � � �� � � ���� ý&ý ý . û3ü,ý-þ�ÿ/� � ý � � � ��� � ���"���� ý � K þ�� ���� �-þ�� �?� ü#�X[(Q� �Zg � ����� �L� þ�� $� þ ��A ü @ ÿ|ý (� ý � þ � �Zg � ï�� � � ��v *,' ý-þNü 3 ��ý AB ���-þ�� � �|þ���ý ��� � � � � ��� �Óý �#��A ü [ ��� ü#�Z� �� � ��� þ�� � ���B.tM �Pþ ��{� þ � ü � � þ ��{��A � � ��� ��3 ��Qý � ��ü�ü � þ ��� þ � þ��F�?� � ���� ý&ýµý � �-þ��F� � ����� ���e� � �� ý&ÿ �����A �&þ A þ�ý � ��� þ � ��ü�ý-þNü 3 ��ý � ��Q��� � � þ ���)� þ$[ T� þ�� "A þ�� ��� � ü .W �� � �Z� ý 3 ����ü � ý&ý �� ý ��� � � �Z� \� �(�� � ý ��� ��� �-þ���� ����� � ý ��� ��Q .$l�� ��ý � ÿ � þ�ý �� A�A ü � � � ��� þ � ý�� �(��� � �� þEý-þNü 3 ��U�9�Z���V�9 ��V¡/¢�£9�Z¤��9���V£9¡{¥��9¤�¦�§ � � � � �X� ý � þ �X� ü �Z� � þ��� þ @(�� � � ������ ��� þ��;ý � þ � � � �#ü ������ ý . û3ü,ý-þ�ÿ¢þ ��� � g � þ�� ��� � �"���� ýVQ ý ��(�� � � ��� � � ý ������ � �� ÿ�� �#þ � þ � g � þ�� � þ�� � �Z��� � �J� ý � þ @(� ��� � � ��� � ����� ���ý � ��� �� � Q�þ��;� �Ný-þ � �Z[#ü ý � K �V�&þ ������ �Z[�þ�3 JA �&þ � � � � ý .HJ� �� ý � ��3 [ � � � �(� ü Q � ý � � �¨����T @(� ��� � ��� þ � þ��)�-þ�� � ��ü � �(�� ����� � ý � þý-þ�� � �a�Z� $� þ�� � ü ý&ÿ � � þ���� � � þ �i�� � g � þ � ý � ý �� ��� QL[ � � � ý-þ�� � �a�Z� �� þ ��A þ �� �(� ý© ªi« .aM � �|þ � ü �¬[ J� �(�� � ý ��� ���{� þ � ��QEþ �������� �Z[�þ�3 ýVQ � [�þNü � �e� � �� ý-þNü 3 � ���T�� �i��j��� �(�� ý � � ý ���i� ���#þ � � � �;.

G�}

Page 53: BMC’03 - JKUfmv.jku.at/papers/bmc03-preliminary-proceedings.pdfBMC’03 Boulder, Colorado, USA. ... Alessandro Cimatti (IRST, Italy) Raanan Fraer (Intel, Israel) Danny Geist (IBM

­�®(¯�°(±(²�±(¯9®(³�´�µ�®(¶R®(³(¯L·�¸ ±(¹º7¯�¯�»"¼i½#¾(¿,À(Á Â7¿�Ã(Ä(À(¼iÀ�»"¼i½#¾(¿,À(Á

Å)ÆÈÇ À$Á ÇÊÉ ¼ ­�±(Ë�ÌUÍ Î?Ï,Ða»"¼i½#¾(¿,À(Á Ñ(®�Ò�»"¼i½#¾(¿,À(Á­�ÓUË�°(® Ô ¿ Æ »"Õ�Ö ×;Õ Æ ÖÊØ Ù ½#¼iÚ�ÛnÜ�Ý Þàß Þàá â Æ ¼i¼ ã Ç ½#Ä(¼iÁÈÁä ß å�å�æ æç ß�è�é ê æ

äBë�ä æ é é ì á�é�å ä ê æ í�ß�íÛ ß�é Ý Û ì Ý Û é Ý ß�å ê ê ß�ì Û á�å Ýß ç ê ê î

ä ß�á�å ê æí ë í ç é é å é ä ì�í�é ê æ êÛ á�ß Ý Û ß ç Ý Û ß ç Ý ß�å ê ê ß�ß�ìß ç ê ê î

ß�á ê ê á�è êß ç ë ß ç ß�è�æ é é ß�å ê ê ß�é�åÛ é ç Ý Û é�á Ý Û é�á Ý ß ç ê ê î

ß�á ê ê å�í êé�á ë é�á ç ä è�é å å ß�å ê ê å�é�ßÛ ç í Ý Û ç ä Ý Û ç ä Ý ß ç ê ê î

á�å ç ë á�å ç ê é�ì�é ß�æ�æ í ê ê ê êÛ å�ß�á Ý Û á ç é Ý ß�á ê ê ê

å�ß�á ë å�ß�á ê ê ä æ�á ä í ê ê ê êÛ å�ß�ì Ý ß�á ê ê ê

â Õ�ï(Öʼ ßâ ¾(¼ Æ ¼iÁÈÃ(Öʽ#ÁFðñ¿ Æ ×;ò,Õ�»"Ú(Öʼ ß�óô�õ ö;÷Zø ø ù(ú�û$ü(û$õ ø ø#÷Zö�ý;÷�þ)÷�ÿ�� üiý�ö�õ������eÿ�������ö���� ��ö�������������� ø�üiý�� ü��(õ ö����;þVõ ö��

Ñ(®�Ò þ���ø�������þ�ú �?ý������ Ñ(®�Ò�� þ���ø�������þX÷������� �!�ø���õ ÿ����Lÿ����$÷Zö�õ�!���ø#÷Zÿ��\þ�� ÿ�þ"� #CþVÿ�÷Zÿ��(þFþVÿ�� �����÷�þ$������ø��(÷Zö%#�� �&����ø#÷�þ('�) *�+-,/.0�1!�ø#÷Zö\ÿ��2�� �!�ø�� ���1�?ý�� ÿ�ý����3�B÷ ���(þ�ü(÷Zö�÷Zø#þ��2���Jþ���ø�������;þVõ ö��÷$þVõ-��õ ø#÷��\÷�!�!����B÷Züiý4,57698�69:$69;=</69>

? ßA@CBXóED ÖÊà ÆGFH ó À(¼ D ÖÊðñÕ Æ ¿ F âFóI ¼iÄ ÉiÇ Ä�J�¼ ÆGF Õ�Ä(ÀLK óEM Õ�Ä�J óED Ã(½#¿�»"Õ�½ Ç Ä�Jx»"¿,À(Ã(ÖÊÕ ÆN ¼ ÆÈÇPO�Q Õ�½ Ç ¿�Ä óSR ÄUT4V�W�XZYZYZ[�\^]�_a`bW�ced�f�Yhg"Yi]�d�fkj-]�d�YiV�]ml�d�\GW�]ml&npo3W�]�c�YiV�Yi]mXZYqW�]o3W�]mXir V�V�Yi]mXistg�f�YZW�V�s F N ¿�ÖÊÃ(»"¼ ß ç�ç ä Ç Ä H Ôvu Ù F Ù Ú ÆÈÇ Ä�J�¼ ÆGF Ú(Ú ó�í�á�êUè�ì F ß�è�è�è�ó

? áA@CBXó9D ÖÊà ÆGF âFóPD�ó9I ¼iÄ ÉiÇ Ä�J�¼ ÆGF Õ�Ä(Àtw ó9x Ã(Ú(ðñ¼ Æ »"Õ�Ä ómD Öʽ#¼ Æ Ä(Õ�½ Ç Ä�JAyV½ Ç »"¼e½#¼i»"Ú�¿ Æ Õ�Ö�ÖÊ¿AJ ÇPQ óz W�r V�]ml&n�W�c1d�f�Y|{2o�} F ä è Û å Ý-~ ß�ê ä á F á�æ�æ�á�ó

? éA@CBXó�D ÖÊà ÆGF âFóPD�ó�I ¼iÄ ÉiÇ Ä�J�¼ ÆGF K óP��óPuFó�M Õ�Ä�J F Ù ó=� Õ�À(¼i¼ ÆGF Ù óPx)ó=B Õa�ÈÕ�»"Õ�Ä ÇPF Õ�Ä(À Ù óâ Õ�Á ÇÊÆ Õ�Ä ó ­�ÓUË�°(®�~ M ¿,À(Ã(ÖÊÕ ÆÈÇ ½�Ø Ç Ä$»"¿,À(¼iÖ Q ¾(¼ QZ�,Ç Ä�J ó�R ÄT4V�W�Xa�9W�c1d�f�Y=�&��d�fj-]�d&� n�o3W�]�c��W�]7o3W��2�&r d�YiV���{�\G[&YZ[���YiV�\ �|XZl�d�\GW�] F N ¿�Ö óCß ä á�ì ¿�ð H Ôvu Ù F Ú(ÕAJ�¼iÁ å�á�ß�êUå�á�å�ó Ù Ú ÆÈÇ Ä�J�¼ Æ y� ¼ Æ ÖÊÕAJ F ß�è�è�í�ó

? ä @CD Æ Ä(¿�ÖÊÀ D�ó Õ�Ä(À Ô ÇP�FÇ Ä(Á �,Ç9� ó4B Ã(À Ç »"¼iÄ,½#Á�¿�ð9�my Q Õ�Ö Q Ã(ÖÊÃ(Á ó Ù ½#Ã(À Ç ¼iÁ Ç Ä H ¿AJ ÇPQ Õ�Ä(À�½#¾(¼K(¿�Ã(Ä(À(Õ�½ Ç ¿�Ä(ÁX¿�ð M Õ�½#¾(¼i»"Õ�½ ÇPQ Á ß ä ç óBá�æ�æ�ß�ó

) �

Page 54: BMC’03 - JKUfmv.jku.at/papers/bmc03-preliminary-proceedings.pdfBMC’03 Boulder, Colorado, USA. ... Alessandro Cimatti (IRST, Italy) Raanan Fraer (Intel, Israel) Danny Geist (IBM

�E�������������C���m� �v��� �����¢¡v£���¤

¥¦���E§�¨�©-ª�«�¬ ­¦«A®�¯�¬�¨�¬§�¨�©-ª�«�¬�°±v²G²G³a´ °GµP¶�¨ ·�¸�¹=§�¨�©-ª�«�¬ º��A»§�¨�©-ª�«�¬

�E¼�½ ��� ¾�©-¨�¿mÀÂÁ&à ÄÆÅ Ç ² ¨�¨È É É

È Ê Ë ÉAÌ ÅAÍAÍÀ È Ã Î ÌAÈ Î Ï

È Ð ÌAÉË Å Ë ÐAÉ Å Ë Î ÅAÍ

À Ë Ã Î Í Î Ì ÏÈ ÌAÌ ÍAÅ

Î Ð Ë ÍAÑAÅ ÏÀ�ÎAÃ Î É Í Î Ì Ï

È ÑAÅ ÅAÍ ÐAÈÍ ÎAÎ Ë Å ÐAÊ Å ÏÀ Í Ã Î Å Ê Î Ñ Ë Ï

Ð È ÅAÍ È Ï ÅAÅ Î Ë ÑÀ Ð Ã Ë Ï Ï

Ç ³AÒ�Ó ¨ ÌÇ ª�¨ ² ¨�°G® Ó ©-°�Ô^« ²�Õ4Ö�³ §�¿ Ó ¨ ÌA×

Ø ÈAÙCÚ�× ­¦¨ ² ©-« Ó µPÛ ± ×4Ü µP§ ³ ©-©-µPÛ(Ý ×4Ú µP°G©-« ² ¨�Û4Ý ×4Þ «aßA¨ ² µPÛ ³ ¯�¬ Ú�× Ç ²G³ ßA¨ ² °G«EàEá¦â�ã�ä�àæå�ç&èaéáêä�ëAèZç�â�é ä�ì�ìmèií × î ¯2â4í�å�ïað$å�ñ4ò�ó�ô�õvò-ö�÷�ø&ø&ù3úvå�í�ûaëZü�å�ý¢å�ìþâ�é ä�ì�ì�ÿ^ì���� ìmç&èií���ìmïZèií���ä�ÿ^ì���ä�ìmçêò-ìmïZå�2ý�é è���èvò-ì�ñ�å�í�Eä���ÿGå�ì�Û ÌAÊAÊ Å ×

Ø ËAÙ ± × ­¦µP¨ ² ¨�Û ± ×�Ü µP§ ³ ©-©-µPÛ Õ × Ý ×�Ü ÓP³A² � ¨�Û ³ ¯�¬�� ×�� ª�® × ¾ ´ § Ò « Ó µ��(§�«�¬�¨ Ó �Zª�¨�� � µP¯�����µP©-ª�«A®�©­����1° ×¦î ¯��"å�å&é ë ä�ìmç õ2é �Cå�í�ÿ���ü�2ë1ñ�å�í���ü�è�õ�ìmä&é ��ëZÿ^ë ä�ìmçtô3å�ì�ë���í���ï���ÿGå�ì å�ñ ����ë���è�2ë! �Cõ2ô�õ"�$# %�%�&ZÛ�ßA« Ó ®�§�¨ Å È Î Ð µP¯('*) Ü ¾�Û�¿ ³ �A¨�° Å ÐAÉ Ï ÌAÊ Î × ¾�¿ ² µP¯��A¨ ² +, ¨ ²GÓP³ �AÛ Å ÐAÐAÐA×

Ø Î Ù ± × ­¦µP¨ ² ¨ ×.- � � ¨ +vÕ0/ ��µP¨�¯�© - + � ³AÓ ��® Ó ®�°2§�«�¬�¨ Ó �Zª�¨�� � µP¯�� ×¦î ¯ â4í�å�ïZèZèZç�ÿ^ì��aëtå�ñ1��ü�è2%���üò-ì���èií�ìmä���ÿGå�ìmä&é ô3å�ì�ñ�èií�èiìmïZè|å�ì¢ô3å�2ý��3��èií�ö�õ�ÿGç&èZç54�èií�ÿ 6|ïZä���ÿGå�ì�Û&ßA« Ó ®�§�¨ Å ÌAÈ Ñ «AÔ3'*) Ü ¾�Û¿ ³ �A¨�° Ñ Ë Í Ï Ñ Î Å × ¾�¿ ² µP¯��A¨ ² +, ¨ ²GÓP³ �AÛ Å ÐAÐ Î ×

Ø Í ÙCÞ|× Õ × ­ ²G´A³ ¯�© ×*7 ²G³ ¿�ª +�Ò�³ °G¨�¬ ³AÓ �A« ² µP©-ª�§�°vÔ^« ²|Ò «�« Ó ¨ ³ ¯EÔ^®�¯���©-µP«A¯E§ ³ ¯�µP¿�® ÓP³ ©-µP«A¯ × ò980808�Cí�ä�ì�ëAä&ï���ÿGå�ì�ëå�ì0ô3å�2ý��3��èií�ëZÛ ÉAÈ À Í Ã9: Ë ÎAÎZÏ ËAÐ Å Û Å Ð Í ËA×

Ø ÐAÙ ± ×�Ü ª ³;��²G³AÒ�³A² ©-µPÛ<' × ¬�¨ ±vÓ Ô ³A² «AÛ Ç × ± ×>= ¨�¯�¶�µP¯��A¨ ² Û�Ý ×@? ® ² ¬�¶�µP¯�° � µPÛ ³ ¯�¬5A × � ×PÜ�× Ý ³ ¯�� ×î ¯�©-¨ ² Ô ³ ��¨���«A§�¿ ³ ©-µ Ò µ Ó µP© ´ �Zª�¨�� � µP¯��%Ô^« ² °G«AÔ^©B� ³A² ¨ê§�«�¬�® Ó ¨�° ×�î ¯Eâ4í�å�ïað4å�ñC��ü�è�ù�D���üò-ì���# éô3å�ì�ñ�ð�å�ì�ô3å�2ý��3��èií�ö�õ�ÿGç&èZç�4�èií�ÿ 6|ïZä���ÿGå�ì�Û�'*) Ü ¾ Ì Ñ Ê Ñ Û ¿�¿ × Ñ Ì Í Ï ÑAÑAÅ × ¾�¿ ² µP¯��A¨ ² +, ¨ ²GÓP³ �AÛÌAÊAÊAÌA×

Ø Å ÊAÙ ± × Ü ª�® ² �Zª × '�«;�Aµ���Û ³A² µP©-ª�§�¨�©-µ���°GÛ ³ ¯�¬ ³ ®�©-«A§ ³ © ³ × î ¯ â4í�å�ïZèZèZç�ÿ^ì��aë å�ñE��ü�èò-ì���èií�ìmä���ÿGå�ìmä&é4ô3å�ì��aí�èiëZëEå�ñêàæä���ü�è�Eä���ÿGïiÿGä�ì�ë�F�ù�%�G�÷&Û9¿ ³ �A¨�° ÌAÉ Ï ÉAÈ Û î ¯�°G©-µP©-®�©1Ý¢µP©-© ³ � +'�¨�H�¨ ² Û Å ÐAËAÉA×

Ø ÅAÅ Ù ± ×�7 ®�¿�© ³ Û Ý ×I7 ³ ¯ ³ µPÛ Ü�×�J ³ ¯��AÛ ��× � ³ ¯��AÛ ³ ¯�¬ Ú�× ) × ± °Gª ³A² × '�¨ ³A² ¯�µP¯���Ô ² «A§ ­����1°"µP¯¾ ± Ç +�Ò�³ °G¨�¬ Ò «A®�¯�¬�¨�¬%§�«�¬�¨ Ó �Zª�¨�� � µP¯�� × Ç « ³ ¿�¿�¨ ³A² Û$â4í�å�ïZèZèZç�ÿ^ì��aëå�ñ���ü�è$D�ø���ü�KþèiëZÿ��aìõL�3��å�Eä���ÿGå�ì ô3å�ì�ñ�èií�èiìmïZè ! K|õ2ô�# ø�M�&ZÛ ÌAÊAÊAÉA×

Ø Å ÌAÙ Õ ×N7 « Ó ¬ Ò ¨ ² � ³ ¯�¬O� × )v«aß�µ � «aß × ­¦¨ ² � Ý¢µP¯�: ± Ô ³ °G© ³ ¯�¬ ² « Ò ®�°G©¢¾ ± Ç °G« Ó ßA¨ ² ×=î ¯â4í�å�ïZèZèZç�ÿ^ì��aë å�ñ�KþèiëZÿ��aì õL�3��å�Eä���ÿGå�ì ä�ìmçP�"èië��|ÿ^ìQ80� í�å�ý è ! K|õ��*8�# ø�÷�&ZÛ/¿ ³ �A¨�° ÅAÑ Ì ÏÅAÑ Ð Û ÌAÊAÊAÌA×

RTS

Page 55: BMC’03 - JKUfmv.jku.at/papers/bmc03-preliminary-proceedings.pdfBMC’03 Boulder, Colorado, USA. ... Alessandro Cimatti (IRST, Italy) Raanan Fraer (Intel, Israel) Danny Geist (IBM

U(V�W<X�Y�Z�Y�W[V�\^]3_"V�`aV�\�Wcb"deY�f

g h;i;j�k0l*mon�p�q�r�s�n�t;u�n�v;w^xcl*y"v;z n�{�{�v;q�|5v;q�}(~"l*��v;r�r�s���u�u�v;l.�o�"��k0�*~�� ��� �9������|;z"}���r�n�}�n�q�t� p�v;q��9n�����}��@|�|;u���v;q���|;z ��p�u�v;�P� v;�9n�� ��v;��n�u�n��B��lN��q��0�T�T����������������� P¡¢@�c£9��¡������^¤�¡� ���^¤�¥¦ ������¡o§¨���e ©���T���^���1���PªL«3¡���¬(¤�¡����®­���¤��;���������P¯°£ ¦ §*ª"­(± ²�³�´�w*µ�v;t;���$i;¶;·�¸>i;¶;¹;w�º;»;»;h;l

g h;·;j�¼$lL½I��q�� ��q¾v;q�}¿xcl$À.��u�|;� |;l"Áo��Â�Â�Ã��v;� ��}a�"q�n�Ä;��z � v;u$µ�u�v;q�q�n�q�tÅ��|;z1� ��q�r�s�z |;q�n�{���}v;t;��q��9�"n�q2q�|;q�Ã}����9��z �1n�q�n�� �9n�ro}�|;�1v;n�q�� lƽI|;p�z q�v;uÆ|;�^~"z �9n���r�n�v;uÇ��q��9��u�u�n�t;��q�r���¼$��� ��v;z r�s�wh;i;w*µ�v;t;���$h;È;¹;ú;º;¶;w�º;»;»;»;l

g h;É;j�Áol¨Êop�µ�����z �1v;q�w�v;q�}¿xcl¨Ë"lLÀ.v;z }�n�lLxc|�}�p�u���r�s���r�Ì�n�q�t;l"��qÍ�0�T�T�������������Î� �¡¢@�PÏ�¡¢£9��¡������^¤�¡� ���^¤�¥3§¨���e ©���T���^���$���c§¨��¬NÐ�«3¡�����Ñ�ªL� �����5Ò>����� Ó$��¤�¡� ����w�Ä;|;u�p��1�0h;h;»;º$|;�3Ô*y"ÕLÖ�wµ�v;t;���$×;É�¸>È;¶;l�Ö�µ�z n�q�t;��z ÃÀ.��z u�v;t;w*h;¹;¹;¶;l

g h;¶;j�¼$��n�q�s�|;u�}�Ô*���9� l@Ô*���1�1v�v;q�}��1|�}���u<r�v;r�s�n�q�t n�q�}���r�n�� n�|;q5µ�z |�r���}�p�z ���Ø��|;z � p�v;q��9n�����}�@|�|;u���v;q(��|;z ��p�u�v;� lÇ��q2�0�T�T��ÙÚ� �ªL«3¡���¬(¤�¡����®­���¤��;���������ÜÛ.��¡¢�ªL�^¤�¥ Ý©¡� �NÞ�¤�ß�¥ ��¤�«3àP¤��^�­���¥ ¤�¡�����áÍ��¡¢@�T����w*Ä;|;u�p��1�oº;i;È;hÜ|;�^Ô*y"ÕLÖ�w@µ�v;t;���$h;¶;»�¸>h;×;É;l^Ö�µ�z n�q�t;��z ÃÀ.��z u�v;t;w*º;»;»;º;l

g h;×;j�Êol�Ô*lÆxcr�xcn�u�u�v;q�l�â�Ý©¬(ß���¥ � �$áÍ�T����¥*§*¢@����ã�������lÆÊou�p�äØ��z$~"r�v;}����1n�roå0p���u�n�� s���z � wÆh;¹;¹;i;lg h;È;j�Êol�Ô*l�xcr�xcn�u�u�v;q�l�~"µ�µ�u���n�q�tæÖ�~.�ç�1���9s�|�}��èn�qép�q��@|;p�q�}���}ê� �����@|;u�n�rë�1|�}���ur�s���r�Ì�n�q�t;l���qo�0�T�T���������������C� .¡¢@�L³�ì�¡¢o£9��¡������^¤�¡� ���^¤�¥3§¨���e ©���T���^���L���c§¨��¬NÐ�«3¡�����Ñ�ªL� �����Ò>����� Ó$��¤�¡� ����w*Ä;|;u�p��1�oº;·;»;·Ü|;�^Ô*y"ÕLÖ�wƵ�v;t;���$º;É;»�¸>º;¶;·;l�Ö�µ�z n�q�t;��z ÃÀ.��z u�v;t;w*º;»;»;º;l

g h;¹;j�xcl�xc|;� Ì;��äLn�r�{�w�ÕLl�xcv;}�n�t;v;q�w�Ë"l�íÇs�v;|;w�Ô*l�íÇs�v;q�t;w;v;q�}oÖ�l;xcv;u�n�Ì�l�ÕLs�v;î>�;k0q�t;n�q�����z n�q�tv;qN��ï1r�n���q��^Ö�~.�Q� |;u�Ä;��z l���q��0�T�T���������������®� 0¡¢@�"ð�Ï�¡¢®ñÜ���������1ªL«3¡���¬(¤�¡� ���ò§¨���e ©���T���^���¯°ñ$ªN§�± ²�³�´�wǵ�v;t;���$É;i;»�¸>É;i;É;w�º;»;»;h;l

g º;»;j�½Il�¼$n�q��9v;q���q�l<���1µ�z |�Ä;���1��q��9�Ø�9|®�9s��L��Äev;u�p�v;�9n�|;q5|;� � p�v;q��9n�����}��@|�|;u���v;qÜ��|;z ��p�u�v;��l<��q�0�T�T���������������Ü� L¡¢@�®³�ó�¡¢Ü£9��¡������^¤�¡� ���^¤�¥ ¦ ������¡"§¨���e ©���T���^�������2ªL��¡� Ó$��� ¤�¥©£9��¡���¥�¥ ���[���^����wµ�v;t;���$h;h;¹;º�¸>h;h;¹;×;w.xc|;z t;v;q(Êov;p����1v;q�q�å0p���u�n�� s���z � w@h;¹;¹;¹;l

g º;h;j�½Ilؼ$n�q��9v;q���q�l¨ÕL|;q�� �9z p�r��9n�q�tcr�|;q�}�n��9n�|;q�v;u¨µ�u�v;q��N���ôvP�9s���|;z ���æµ�z |�Ä;��z l�½I|;p�z q�v;uØ|;�~"z �9n���r�n�v;u*��q��9��u�u�n�t;��q�r���¼$��� ��v;z r�s�wÇh;»;��i;º;i�¸>i;É;º;w�h;¹;¹;¹�l

g º;º;j�å@l�½Il�molؼ$v;�1v;}�t;��w�v;q�}Qõal�xcl�õò|;q�s�v;�1lØ�Ls��Ür�|;q��9z |;u�|;�L}�n�� r�z ���9����Ä;��q��N� ��� �9���1� lå0z |�r�lÇ��k0k0k0wÆ×;×;��È;h;ù;È;w^h;¹;È;¹;l

g º;i;j���|;�1�1nǽIp�q��9�9n�u�v;lÇ��|�|;u���v;qcr�n�z r�p�n��Lµ�v;r�Ìev;t;�®Ä;��z � n�|;q(»;l�º;»;lö�÷�÷�ø�ùBú�ú�û�û�û�üB÷Çý�þ�üBö�ÿ�÷�ü�����ú���÷���ÿ���÷�÷���úÇý����Çý�ÿ ��÷�þ�ú ����������üBöI÷���

g º;·;j�õal¨�Ls�|;�1v;� l���q���q�n��9�5t;v;�1���Üv;q�} Ä;��z n���r�v;�9n�|;q�l$��qÍ�0�T�T��Ù�� �¡¢@�c³�ì�¡¢Q£9��¡�± ¥¨§¨���e ©Ù���a§¨��¬NÐ�«3¡�����Ñ�ªL� ����� Ò>����� Ó$��¤�¡� ����w*Ä;|;u�l�º;·;»;·�|;�^Ô*y"ÕLÖ�wǵ�µ�l�É;È�¸>¶;·;l�Ö�µ�z n�q�t;��z ÃÀ.��z u�v;t;wº;»;»;º;l

g º;É;j�Ô*l2íÇs�v;q�t�v;q�} Ö�l�xcv;u�n�Ì�lcÕL|;q���n�r��¿}�z n�Ä;��q u���v;z q�n�q�t n�q v � p�v;q��9n�����} �@|�|;u���v;q� v;�9n�� ��v;��n�u�n��B��� |;u�Ä;��z lN��q��0�T�T��ÙÜ� ò£9��¡�± ¥®§¨���e ©���T���^���¿����§¨��¬NÐ�«3¡����QªL� �����ôñÜ���������¯°£e§¨§*ª"ñò± ²���´�w*º;»;»;º;l

���

Page 56: BMC’03 - JKUfmv.jku.at/papers/bmc03-preliminary-proceedings.pdfBMC’03 Boulder, Colorado, USA. ... Alessandro Cimatti (IRST, Italy) Raanan Fraer (Intel, Israel) Danny Geist (IBM
Page 57: BMC’03 - JKUfmv.jku.at/papers/bmc03-preliminary-proceedings.pdfBMC’03 Boulder, Colorado, USA. ... Alessandro Cimatti (IRST, Italy) Raanan Fraer (Intel, Israel) Danny Geist (IBM

������� "!$#&%&'&(*),+�),-/.0%01324'0%45&)6�-

SAT-BasedMethodsfor SequentialHardwareEquivalenceVerificationWithout

Synchronization

ZurabKhasidashviliandZiyadHanna

Logic andValidationTechnologyDesignTechnology Division

Intel DevelopmentCenter, Haifa, Israel7zurab.khasidashvili, ziyad.hanna 8 @intel.com

Abstract

The BDD- andSAT-basedmodelcheckingandverificationmethodsnormally requireaninitial state.Herewe areconcernedwith sequentialhardwareverification,whereaninitialstatemustbe oneof the resetstates.In practice,a resetstateis not alwaysgiven by thedesigner, andcomputingaresetstateof acircuit is ahardproblem.In thispaperweproposeamethodallowing usageof SAT-basedverificationmethodswithoutaneedfor auser-givenor a computedinitial state.Theideais to employ a binaryencodingof 9 -valuedmodelingof circuits,andusetheundefinedstate: asa resetstate.

1 Intr oduction

In thetheoryof FiniteStateMachines(FSM) [Koh78], oneassumesan initial state(or asetof initial states),from whichthemachinestartsoperating.Herewewill beconcernedwith sequentialverificationof synchronizedhardware(circuit) models.In the practiceof hardwareverification,an initial state ;&< of a circuit = is a statewhereall stateelements(latchesandflip-flops) have a binaryvalue( > or ? ), andthereis an initializing sequence@ < that brings = from the A stateto that binarystate;&< [CA89]. A resetor asynchronizationsequencefor = , on theotherhand,isasequence@ B thatbrings = from any binarystateto auniquestate;&B , calleda resetor a synchronizationstate( @ B and ;&B areindependentfrom thestatefrom which =startsoperating)[Koh78]. Any initializing sequenceis clearlyaresetsequence,buttheconversedoesnothold [CA89].

ClassicBDD-basedmodelcheckingandverificationalgorithmsrequirea resetstate[CBM89,CM90,TSLBS90,CCQ96,CC97,McM93]. Thesameis truefor wellknown SAT-basedmodelcheckingalgorithmssuchasBoundedModel Checking[BCC99,BCCFZ99] or the inductionmethod[SSS00]. Computationof resetse-quencesis a hardproblem[CJSP93,PB94,PJH94,LP96,KBS96,CPRSS97,RH02].

CED/FHGIFHGKJML�NPORQ F S$F T�J�NVUXW�ORNRG�FZYT\[ICED�O�]/T�J�Q�W�ORNRG�FZYTX^ F Q Q`_4OaLcb�_�Q FHG�D�O�deF Tf�QZO�g�hiNPYT/FigIjMY*hkO,GIF TlCED�OmYNPOhiFig,J�Q�n�YSoLcb/hkORNKp�gqFZORTrgPOsEt�u`v*w"w"w�x '&(&5�'�y�)'0% x -�("z"(06&{0.0|*'&z"'�-*|/{&5

Page 58: BMC’03 - JKUfmv.jku.at/papers/bmc03-preliminary-proceedings.pdfBMC’03 Boulder, Colorado, USA. ... Alessandro Cimatti (IRST, Italy) Raanan Fraer (Intel, Israel) Danny Geist (IBM

}c~����\���\�������\���r�

Thereforein this work wearelooking for verificationmethodsthatcanwork with-outa resetstate.

UnlikeSAT andBDD-basedmethods,theATPGmethodsdonotrequirearesetstate. There,oneassumesthe outputsto differ, andlooks for a justifying assign-ment. Thecircuit modelingis ternary– besidesthetwo binaryvalues� and � , oneconsidersan unknownvalue, � (elsewherealsodenotedby � or � ). A justifiedassignmentgivesan input vectorsequencethat, if appliedto the circuits startingat theunknown state� (or at anybinarystate),bringsthemto a statewheretheiroutputsdiffer.

In order to take advantageof the rapidly developing SAT-basedverificationtechnology, herewe proposea SAT-basedmethodfor verifying � -valuedequiva-lenceof sequentialcircuitswithout initialization. Ourmethodis basedonthedual-rail modelingof circuits,whereeveryternaryvalueis representedwith apairof bi-naryvalues(see[Bry87,BS94,SB95,KR03]). Via dual-railencoding,wecanarriveto ordinary( � -valued)propositionallogic formulationof theverificationproblem.

The novelty of our approachis to show that thedual-rail � statecanbe usedasa resetstatein the (forward aswell asbackward) SAT-basedalgorithmsmen-tionedabove (the BMC andinductionalgorithms). We first presentan algorithmfor checking� -valuedequivalencewhichusesthe � stateasaresetstate,andproveits correctnessandcompleteness.We thendiscusstheapplicabilityof our methodto verification with respectto other conceptsof sequentialequivalence,suchasalignability or post-synchronizationequivalence[Pix92], andsteady-stateequiva-lence[KMH02].

Thepaperis structuredasfollows. In thenext section,we quickly recallsomebasicdefinitionsusedin thiswork. In Section3, werecallabackwardATPGbasedalgorithmfor verifying � -valuedequivalenceandexplain its drawbacks. In Sec-tion 4, wegivea light introductionto abinaryencoding,calleddual-rail encoding,of � -valuedlogic into Booleanlogic, originally developedfor the purposeof ef-ficient symbolicsimulationandmoredirectmodelingof circuit operation[BS94].Wealsoreferto morerecentresultsonusageof thedual-railencodingin SAT-basedsequentialverification[KR03]. In section5, we proposea SAT-basedmethodfor� -valuedequivalenceverification, and discusshow it relatesto the ATPG algo-rithm mentionedabove. In Section6 we discusshow our methodcanbeextendedto steady-stateandalignability sequentialequivalenceverification. Experimentalresultsarediscussedin Section7. Conclusionsappearin Section8.

2 Preliminaries

Without restrictinggenerality, we will assumethat any circuit � hasexactly oneoutput, � . We denoteby ��� and �$� our specificationandimplementationcircuits(with outputs ��� and �/� , respectively), andassumethat they have the samesetofinputs(dummyinputscanbeadded,if necessary).Wedenoteby ���0�q� thecombinedcircuit with sharedinputsandXORedoutput �l�����\�������/� . And we denoteby�����*�q� the combinedcircuit (the productmachine [HS98]) with sharedinputsand

2

Page 59: BMC’03 - JKUfmv.jku.at/papers/bmc03-preliminary-proceedings.pdfBMC’03 Boulder, Colorado, USA. ... Alessandro Cimatti (IRST, Italy) Raanan Fraer (Intel, Israel) Danny Geist (IBM

�c �¡�¢\£�¢\¤�¥�¦�¢\¤�¤r¢

XNORedoutput §©¨ª§�«\¬�­¯®�°�§/± .We considerternarymodelingof circuit nodevalues.Thevaluescouldbeone

of thebinary values– ² or ³ , or anundefinedvalue– ´ (elsewherealsodenotedby ¬ or µ ). Givenaternary(or binary)inputvectorsequence¶ , ·¹¸qº�»�¶K¼ will denotethevalueof node· of acircuit ½ after ¾ -valuedsimulationof ½ with ¶ , startingatstate º . Similarly, ½�¸qº�»�¶K¼ denotesthe(ternary)stateinto which ¶ brings ½ , fromstateº .

A circuit ½ is specifiedasa collectionof next-statefunctions(NSFs)of thelatchesaswell asof the output. An NSF is a function of currentandnext-statevaluesof inputsandlatches.« Thiscollectionof NSFsdefinesasequentialinstancecorrespondingto ½ , denoted¿R·Iº&À&¸�½�¼ . We denoteby Á©Âq·Iº�¸�½�¼ the setof inputs,latches,andthe outputof ½ . Every pin variable à canbe viewed asa sequence¸ÄÃKÅ ÆÈÇk¼,ÉoÊ\Ë of Booleanvariables,eachÃKÅ ÆÈÇ representingvalueof pin à at phaseÆ(thusthenext stateof ÃKÅ ÆÈÇ is ÃKÅ ÆÍÌÏÎ&Ç ).

Assumptionsandproof obligationscanbe addedto an instance.Assumptionsareassumedto betruein all (relevant)timephases,andproofobligationsrepresentpropertieswhosevalidity in all (relevant) phaseswe intend to check. The proofobligationswe will be interestedin aresafetypropertiesrelatedto thevalidity of§4Ð�Ñ*ÒqÓoÔÕ² .

Unrolling to depth Ö of the instance¿R·Iº&À&¸�½�¼ yieldsa combinationalinstance,denoted½�Å ×E»0Ö�Ç , consistingof variables Ø�ÃKÅ Â�ÇcÙm×ÛÚÜÂÝÚÕÖ`»qÃßÞàÁ©Âq·Iº�¸�½�¼�á , andthe relationson themare inducedby the NSFs. The function of the output § in½�Å ×E»0Ö�Ç at timephaseÖ will bedenotedby §EÅ ×E»0Ö�Ç . Weassumeit is apartialfunctionon all Booleanvariablesin the instance;partialbecausesomevaluecombinationsareillegal asthey contradicttheNSFrelationsimposedon the instance.Alterna-tively, §EÅ ×E»0Ö�Ç canbeseenastheconjunctionof all NSFrelationsandassumptionsin ½�Å ×E»0Ö�Ç .

Intuitively, falsificationof aproofobligationexpressing§�«&Å Ö�Ç�Ôâ§/±/Å Ö�Ç in ½�Å ×E»0Ö�Çcorrespondsto Ö iterationsof an ATPG procedureof finding a counter-example(CEX) to theproof obligation §�«ãÔä§/± . We will seein the latersectionsthat thiscorrespondenceis notastight asit mayseemfrom thefirst sight.

Thefollowing exampleclarifiestheabovedefinitions.

Example2.1 Consideracircuit ½ thatconsistsof anegatedlatch å , with dataæ andclock which is alwaysfalse: çX¨Í³ (seeFigure1). Let §è¨êé¹å denotetheoutput.Then ¿R·Iº&À&¸�½�¼ consistsof two NSFs: åìë ¨Ûç�ëÄí©æ�ëZÌ©é¹ç�ëÄí©å�¨Ûå and §4ë ¨îé¹åìë , whereï ëdenotesnext statevalueof ï . Unrolling ¿R·Iº&À&¸�½�¼ to depth Î yieldscombinationalinstance½�Å ×E»*Î&Ç consistingof variables §EÅ ×�Çq»�§EÅÄÎ&Çq»�åmÅ ×�Çq»�åmÅÄÎ&Çq»�æ`Å ×�Çq»�æ`ÅÄÎ&Ç and relations§EÅ Â�Çð¨ñé¹åmÅ Â�Ç for Â�¨ñ×E»*Î , and åmÅÄÎ&Çð¨ªåmÅ ×�Ç .

òThus,thecircuitsthatweconsiderareMealymachines.

3

Page 60: BMC’03 - JKUfmv.jku.at/papers/bmc03-preliminary-proceedings.pdfBMC’03 Boulder, Colorado, USA. ... Alessandro Cimatti (IRST, Italy) Raanan Fraer (Intel, Israel) Danny Geist (IBM

ócô�õ�ö\÷�ö\ø�ù�ú�ö\ø�ørö

d l o

c=F

Fig. 1. NegatedLatch

3 A backward ATPG basedmethodfor verification without ini-tialization

Huangetal [HCC01] developedanATPGbasedmethodfor verifying û -valuedsafereplacementaswell as3-valuedequivalencefor sequentialcircuitswith or withoutaninitial state.To define û -valuedequivalence,they introducedacoveringrelationon signalswith ternaryvalues:signal ürý coverssignal ü�þ if f whenever ürý©ÿ�� orürýoÿ�� , then ürý�ÿÏü�þ .Definition 3.1 � Circuit �$þ with output �/þ is called û -valuedsafereplacementof

circuit ��ý with output ��ý if f for any input sequence� , ��ý�� ����� covers �/þ��� ����� .(Thatis, when ��ý hasabinaryvalue,then �/þ musthave thesamebinaryvalue.)

� Circuits ��ý and �$þ are3-valuedequivalent, written ��ý�� ÿ�� �$þ , if f for any inputsequence� , ��ý��� �����oÿ��/þ��� ����� .The values ��������������������� ������ ��!��" for the output pair ����ý#���/þ�� are called û -

valuedequal-pairs of ��ý and �$þ ; in this case, �%$�&'�( is in û -valuedequal-state.Theremainingpairs ��������� ������������������ ���������� ��� ��")��������!����������!��" arecalled û -valueddiffer-pairs, and �%$�&'�( is in û -valueddiffer-statein this case.

An input vectorsequence� suchthat ����ý��� ���������/þ���**þ�������,+-��������� ��������������"is calledapartial testfor ��ý and �$þ in [HCC01] (thisdefinitionis not symmetric).Note that sucha � brings �%$�&'�( from state into a û -valueddiffer-state. When**þ$ÿ. , � is alsocalleda testsequence(for stack-at-falsefor �/$�'�( ).

To checkfor û -valuedsafereplacement,the authorsproposeto usean ATPGsolver in thefollowing way:

The backward justificationfor the �/$�'�( ÿ0� (on �%$�'�( ) stopswhenever oneofthefollowing two conditionsis satisfied:

� (Unjustifiablecondition): All staterequirementsgeneratedduring thesearchofapartialtestsequenceareprovenunjustifiable.Then �$þ is û -valuedsafereplace-mentof ��ý .

� (Justifiedcondition): A staterequirementthatdoesnothaverequirementson ��ýis reached.Thenapartialtestsequencehasbeenfound,and �$þ is nota û -valuedsafereplacementof ��ý .Similarly, û -valuedequivalencecanbedisprovedby generatingastaterequire-

menthasnorequirementson ��ý or on �$þ . And û -valuedequivalencecanbeprovedby showing thatall thosestaterequirementsthataregeneratedwhile searchingforapartialtestfor ��ý and �$þ andfor a partialtestfor �$þ and ��ý , areunjustifiable.

Theabove algorithmneedsa terminationcriterion,basedon somesort of ‘di-ameter’or afix-point, to becomplete.For example,let both ��ý and �$þ benegated

4

Page 61: BMC’03 - JKUfmv.jku.at/papers/bmc03-preliminary-proceedings.pdfBMC’03 Boulder, Colorado, USA. ... Alessandro Cimatti (IRST, Italy) Raanan Fraer (Intel, Israel) Danny Geist (IBM

132)46587 589):<;=589)9>5

C

C

O2

O1F

Fig. 2. ? -valuedinequivalentcircuits.

latches,@BA and @DC , with control E (likethecircuit F in Example2.1). Then F%G�H�I/J K�L�M)Nwill dependon variables@BA�J K�N and @DC�J K�N for any M , andneitherof the two stoppingconditionswill ever be satisfied. Thus the algorithm will report ’INDETERMI-NATE’ whena time limit will bereached.

Thereis alsoanotherreasonwhy the above algorithmis not complete: If aninputvectorsequencethatcanbring F%G�H�I from O stateto adiffer state(with outputP

) exists,a partial testfor F%G�H�I that thebackward justificationalgorithmabove islooking for maynot exist:

Example3.2 Considertwo circuits FQA and FRC (seeFigure2), eachconsistingofa singlelatch with clock signal S , with patternsay S<T P L�E�L P L�E�LUUU . The inputof the first latch is constantE , while the input of the other latch is V�CWOYX ZYV�C .Startingfrom the O state,V6A behavesas V6A%T�O[L�E�L�E�LUUU , and V]\ behavesas V�C�TO[L�O[L�O[LUUU . Thusthesecircuitsarenot ^ -valuedequivalent(and FRC is not ^ -valuedsafereplacementof FQA ). However, V/G�H�I cannever become

Pif it startsoperation

from anon-P

state(theonly two concretizationsof thesequenceV�CRT_O[L�O[L�O[LUUUare V�C,T`E�L�E�L�E�LUUU and V�C�T P L�E�L�E�LUUU ), thusa partial testdoesn’t exist for FQAand FRC .Remark 3.3 Theaboveexamplewaspointedoutto usasa counter-exampleto (thesufficiencypart of) Lemma2 of [HCC01], which statesthat FRC is a ^ -valuedsafereplacementof FQA iff there is no partial testfor FQA and FRC . While webelieve theaboveexampleis notacounter-exampleto Lemma2of [HCC01] C , thecorrectnessof the lemmadoesnot affect thecorrectnessof theabovealgorithmor our resultsbelow, andwewill not elaborateon this issuefurther (it goesbeyondthescopeofthispaper).

Notethat,intuitively, work with O valuesin acircuit correspondsto work withQBFs (QuantifiedBooleanFormulas): latch valuesare universallyquantifiedina predicateexpressinga stop condition in the ATPG procedureabove. Abdullaet al [ABE00] investigatedways to simplify QBF translationinto quantifierfree

aThe authorsstatethat they usean enhancedb -valuedlogic simulationin Lemma c ; suchsim-

ulation is basedon approximatingb -valuedsimulationby c -valuedsimulation,thusassumesonlybinaryvalueson inputsaswell asinitial valuesof latches(seealsoExample4.1). In thealgorithmhowever they usetheusual b -valuedsimulation.

5

Page 62: BMC’03 - JKUfmv.jku.at/papers/bmc03-preliminary-proceedings.pdfBMC’03 Boulder, Colorado, USA. ... Alessandro Cimatti (IRST, Italy) Raanan Fraer (Intel, Israel) Danny Geist (IBM

d3e)f6g8h g8i)j<k=g8i)i>g

propositionalformulaeto facilitateSAT solverson QBF, for the purposeof SAT-basedmodelchecking.Herewe pursuea differentpath: To developa SAT-basedverificationalgorithmfor l -valuedequivalencechecking,we considera dual-railencodingof theternaryvalues.In thenext section,we give a brief introductiontothesubject.Wewill laterexplainwhy thisapproachcanworkwell with certainSATsolvers,and how it canbe extendedto verifying sequentialequivalencewithoutinitializationwith respectto otherusefulconceptsof sequentialequivalence.

4 Verification using dual-rail modeling of circuits

Dual-rail modelingof circuits was introducedby Bryant [Bry87]. It was usedin [BS94] to enablea moreprecisemodelingof circuit operation,and to enablerepresentationof all ternaryvalueswith BDDsvia abinaryencoding.It resultedinamoreefficient symbolicsimulator, asmorecomplex behaviors couldbemodeledwith asinglesimulationrun. Wereferto [SB95,Jon02] for moreinformation.

Eachternaryvalue m is encodedasa pair of binary values nBm�o>pqm�rDs , calledthehigh andthe low values.Theundefinedvalue t is encodedasa pair t�uvn�w�p�w�s .The truth constantsareencodedby wvuxn�w�p�y s and yzuxn�y�p�w�s . The pair {zun�y�p�y s encodesacontaminatedor over-specifiedvalue.To avoid any confusion,weusey,|~} , wQ|~} , and t�|~} to denotethedual-railencodingof w�p�y and t , respectively.And m |~} u`nBm�o>pqm�rDs will denotethedual-railencodingof a ternaryvariablem .

Sequentiallogic canbeexpressedby usingBooleanlogic connectivessuchas� p�� , and � , anda phase-delayor next stateoperation,� . Thusin orderto modelsequentiallogic in dual-rail, it is enoughto have dual-rail rules for theseopera-tions. We overloadtheselogic connectivesto denotethe correspondingdual-railcounterpartsaswell. Thesedual-rail rulesareasfollows: Let � |~} uzn���o>p���rDs and� |~}%u`n � o>p � r�s bedual-railencodingof ternaryvariables� and � . Then� n���o>p���r�s � n � o>p � r�s�u`n���o � � o>p���rD� � r�s ;� n���o>p���r�s�� n � o>p � r�s�u`n���o�� � o>p���r � � r�s ;� ��n���o)p���rDs�u`n���rBp���o�s ;� n���o>p���r�s~��u�n��W�o p��W�r s .

Thusa dual-railNSFis a pair of NSFsof thehigh andlow values.We denoteby � |~}�� � p��)� the unrolled,to depth � , dual-rail sequentialinstance,anddenoteby� |~}�� � p��)� thevalueof � in thatinstance(cf. definitionof � � � p��)� in � � � p��)� .

Example4.1 Let uscompute� |~}��Y� � � |~} for � |~} u�t |~} , asin Example3.2:

6

Page 63: BMC’03 - JKUfmv.jku.at/papers/bmc03-preliminary-proceedings.pdfBMC’03 Boulder, Colorado, USA. ... Alessandro Cimatti (IRST, Italy) Raanan Fraer (Intel, Israel) Danny Geist (IBM

�3�)�6�8� �8�)�<�=�8�)�>����~�W Y¡ ¢£���~�¥¤ ¦�¦�§�¨�§�©«ª,¬�¦�§�¨�§�©�©�­®¦�¬�¦�§�¨�§�©«ª¯¦�§�¨�§�©�©

¤ ¦�¦�§�¨�§�©«ª®¦�§�¨�§�©�©�­ ¦�¦�§�¨�§�©«ª¯¦�§�¨�§�©�©¤ ¦�§°ª°§�¨�§°ª�§�©�­ ¦�§°ª�§�¨�§°ª°§�©¤ ¦�§�¨�§�©�­ ¦�§�¨�§�©¤ ¦�§�­Q§�¨�§�­°§�©¤ ���~�

.

Wecanseethatdual-railcomputationcorrespondsto usual ± -valuedlogic. ²To ensurethat in a sequentialinstancethe inputsarealwaysbinary, oneneeds

to add, for any input variable ³ , an assumption³�´ ¤µ¬ ³�¶ . This in particularwillguaranteethatwedo not introduce

¦�·�¨�· ©valuesin theinstance.Further, if

¦�·�¨�· ©valuesare not introducedin assumptionsor in proof obligations,the NSFscan-not introducethemeither (becausethe above four operationscannotresult in an¦�·�¨�· ©

valueif theargumentsarenot over-constrained).Thus,for example,over-constrainedvaluesshouldnot appearin a satisfyingassignmentfound by a SAT-solver. An appearanceof

¦�·�¨�· ©in a satisfyingassignmentindicatesa bug (in the

designor in the tool), that is why we don’t addto the instanceanassumptionfor-biddingover-constrainedvalueson all variables.

Wedemonstratedual-railcomputationon anotherexample:

Example4.2 Let ¸ bea circuit asin Example2.1. Then ¹»º½¼�¾ ¦ ¸ © consistsof fourNSFs: ¿�À´ ¤Á¦� À´ ª,à À´ ©�­ ¦� À¶ ª ¿D´ ©Ä¤ ¿D´ , ¿�À¶ ¤Á¦� À¶ ­�à À¶ ©«ª¯¦� À´ ­ ¿D¶ ©Ä¤ ¿D¶ , Å/À´ ¤ ¿�À¶ , andÅ/À¶ ¤ ¿�À´ . Besides,we assumethat

Ã, as an input, is always binary, by addingà ´ ¤.¬Æà ¶ asanassumptionto ¹»º½¼�¾ ¦ ¸ © .

Dual-rail modelingis currentlyusedin an alignability verificationengine,In-sight,in theformal verificationgroupat Intel. Despitethedoublenumberof vari-ables,experimentalresultsshow that the dual-rail implementationis Ç6ÈÊÉ�Ë fasterthanasingle-railimplementationbasedontheinitializationflow reportedin [RH02].Among other factors,this is due to the fact that the dual variables‘behave sim-ilarly’, andour SAT solver canexploit this similarity without a significantover-head[KR03]. For example,SAT solversbasedon the saturation method[SS00]areknown to performwell whentherearemany equivalent(up to negation)vari-ablesin theinstance.

5 A SAT-basedmethod for checking Ì -valuedequivalence

In this section,we show how theBMC algorithm[BCC99,BCCFZ99] andthe in-ductionmethod[SSS00] canbeadaptedto enableverificationwithouta resetstate,by usingthe dual-rail state

�asan initial state. Unlike the original ATPG based

ÍWith enhancedÎ -valuedsimulationasin theproofof Lemma2 of [HCC01], weget Ï,Ð ÑÓÒÔÏÖÕ×, sinceØ�Ð ÑÓÒ!ØÙÕ × Ð ÑÓÒ × Õ × .

7

Page 64: BMC’03 - JKUfmv.jku.at/papers/bmc03-preliminary-proceedings.pdfBMC’03 Boulder, Colorado, USA. ... Alessandro Cimatti (IRST, Italy) Raanan Fraer (Intel, Israel) Danny Geist (IBM

Ú3Û)Ü6Ý8Þ Ý8ß)à<á=Ý8ß)ß>Ý

algorithmof Huanget al [HCC01], our algorithm is (soundand)complete. Wewill alsoseethat a moredirect encodingof the ATPG algorithminto SAT baseddual-railformalismresultsin anincompletealgorithm.

Algorithm 1 describesour â -valuedequivalenceverificationprocedurewithouta resetstate.

Algorithm 1 SAT-basedalgorithmfor â -valuedequivalenceverificationw/o resetstate

1: Check â -valuedequivalenceof ã6ä and ã�å½æ2: Createadual-railsequentialinstancecorrespondingto ç%è�éê�ë ;3: Bind to ì highandlow latchvaluesin phaseí ;4: Add proof obligationexpressingã/è�éê�ëqî ë=ï ìQî ë ;5: Apply acompleteSAT-basedmethodto theinstance;6: if acounter-exampleis generatedthen7: Report’DIFFER’ andEXIT ;8: end if9: if theproof obligationis provedthen

10: Report’EQUAL’ andEXIT ;11: end if12: elsereport‘INDETERMINATE’ andEXIT ;13: ð

Theorem 5.1 Algorithm 1 is a soundand completeprocedure for checking â -valuedequivalence.

Proof. The situationswhenthe proof obligation can be falsified are exactly thesituationswhere thepair ñ�ã6ä#ò�ã�å�ó is a â -valueddiffer-pair:

ñ�ã6äôî ë ò�ã�åqî ë óRõöæ�ñ�ìQî ë ò�÷,î ë ó�ò�ñ�÷,î ë ò�ìQî ë ó�ò�ñ�ø�î ë ò�ìQî ë ó�ò�ñ�ø�î ë ò�÷,î ë ó�ò�ñ�ìQî ë ò�ø�î ë ó�ò�ñ�÷,î ë ò�ø�î ë ó�ð)ùThusthe algorithm returns’DIFFER’ exactly when çQäûú üý�þ�çRå , and the counter-examplebrings ç%è�éê�ë fromstateø to a â -valueddiffer state. Bythesameargument,the algorithm returns ’EQUAL’ iff çQäqüý�þ�çRå . (Only) in casethe run terminateswithoutresolvingtheinstance, thealgorithmreturns’INDETERMINATE’. ÿ

In Algorithm 1, wemainly useinductionbasedalgorithms[SSS00], sincetheyperformbetterwhena full proof is sought. (We usethe BMC basedmethodsinalgorithmsthat requireinitialization – the counter-examplesbecome(part of) theinitializing or synchronizingsequences[RH02,KR03].) We recall briefly that intheinductionmethod,unrollingwith increasingdepthsis performed,till acounter-example(to the proof-obligation)is found, or inductionstepcanbe proved (seealso[BC00] for a nicedescriptionon why a simpleinduction,with depth � , is notenough). In [SSS00], terminationconditionsfor inductionsteparepresentedthatreflectbothforwardandbackwardstatespacetraversalmethods,thusouralgorithmalsocanbemadeforwardor backward(or combined),dependingonwhichkind ofinductionis used.

8

Page 65: BMC’03 - JKUfmv.jku.at/papers/bmc03-preliminary-proceedings.pdfBMC’03 Boulder, Colorado, USA. ... Alessandro Cimatti (IRST, Italy) Raanan Fraer (Intel, Israel) Danny Geist (IBM

������������� �������

A direct encodingof the ATPG algorithmof [HCC01] into SAT-basedmodelcheckingproblemwouldcorrespondto� Consideringthesetof (combined)stateswhereall latchesof ��� or all latchesof

��� arein state����� asthesetof initial states;� Consideringthestateswhere ��� � � ����!#"���� asthebadstates;� And applyingthebackwardinductionschemeof [SSS00].

Counter-examplesfoundbysuchanalgorithmwouldbethecorrectones,but theal-gorithmwould misscounter-examplesin situationslike in Example3.2. We there-foreabandonthis algorithmin favor of Algorithm 1 above.

6 Verification with respectto other conceptsof equivalence

In this section,we commenton the applicability of our methodsfor equivalencecheckingwith respectto someotherconceptsof equivalence,namelysteady-stateequivalenceandalignabilityequivalence.

6.1 Verifyingsteady-stateequivalence

We recall definition of steady-stateequivalencefrom [KMH02]. In steady-stateequivalence,we comparetheoutputsonly in time phaseswherebothoutputshavebinaryvalues.Valuesin othertime phasesaredon’t cares.Thuscircuits that are$-valuedequivalentarealsosteady-stateequivalent,but not viceversa.

Definition 6.1 ([KMH02])� An input vectorsequence% is calleda steady-statesequencefor a circuit � if�'&(�*)+%-, is binary.� Circuits ��� and ��� with outputs ��� and �.� are called steady-stateequivalent,written ���0/!21(1 ��� , if f for any input sequence% thatis a steady-statesequenceforboth ��� and ��� , ���3&(�*)+%-,4!5�.�.&(�*)+%-, .In orderto developa verificationprocedurefor verifying steady-stateequiva-

lencewithout a resetstate,we cansimply changethe proof obligation in Algo-rithm 1 to the following one: &7698(:<;�=?><&7���+,A@B698(:<;�=?><&7�.� ,+,DCE&7���GFH�.� , , where698(:<;�=?><&7��IJ, denotesthe propertythat ��I hasa binary value (that is, ��ILKM!ON4��ILPQ, ,8R!TS�) U .6.2 Verifyingalignability equivalence

Werecalldefinitionof alignabilityorpost-synchronizationequivalencefrom[Pix92].

Definition 6.2 � State &(V?� ) V3� , of thecombinedcircuit �W�9X3� � is anequivalentstateif for any input sequence% , ���Y&(V?� )+%-,Z![�.�?&(V3�3)+%-, . \

]The conceptsof equal-anddiffer-statesshouldnot be mixed with equivalentand inequivalent

states.In this definition,all statesarebinary.

9

Page 66: BMC’03 - JKUfmv.jku.at/papers/bmc03-preliminary-proceedings.pdfBMC’03 Boulder, Colorado, USA. ... Alessandro Cimatti (IRST, Italy) Raanan Fraer (Intel, Israel) Danny Geist (IBM

^�_�`�abac�d�e�ac�c�af A binaryinput sequenceg is analigning sequencefor a combinedstate h(i?j k i3l m

of nWo9p3q(r if it brings nWo9p3q(r from state h(i?j k i3l m into anequivalentstate.f Circuits n�j and n�l arealignable, written n�j+st�uwv p�n�l , if every stateof nWo9p3q(r hasan aligning sequence(or equivalently, there is a sequence,called a universalaligningsequence, thatalignsany stateof nWo9p3q(r ).

Lemma 6.3 (i) If circuits n�j and n�l are synchronizableand n�j0st2x(x n�l , thenn�j styuwv p�n�l .

(ii) If n�j st�uwv p�n�l , then n�j st x(x n�l .Proof.

(i) Let n�j and n�l besteady-stateequivalent.Considersequenceg that synchro-nizesboth n�j and n�l , sayinto a statepair h(i?jzk i3l m . Thenfor any sequenceg<{ , theconcatenationof g and g<{ is a steady-statesequence, thus g<{ endsina state h(i { j k i { l m where |�j and |.l haveequalbinary values.Thus h(i?jzk i3l m is anequivalentstatepair, implyingthat n�j st�uwv p�n�l .

(ii) Now let n�j and n�l be alignable. Supposeon the contrary that n�j and n�lare not steady-stateequivalent.Thenthere is a steady-statesequenceg thatbringsanystateinto a differ state(with outputsdifferentbinaryvalues).Sucha sequencecandistinguishanypair of states,thus n�j and n�l do not haveanequivalentstatepair, andthey cannotbealignable– a contradiction. }

Alignability equivalenceis a widely usedconceptof equivalence.Therefore,to show the importanceof our methods,it is importantto clarify the relevanceofourmethodsfor alignabilityequivalenceverification.Indeed,thereareanumberofwaysallowing to infer alignabilityor non-alignabilityof circuitsby usingthemeth-odsof checkingsteady-stateor ~ -valuedequivalencepresentedin theearlysections.Wementiona few of them,basedon theabove lemmaanda resultin [HCC01].f If our steady-stateverificationalgorithmprovescircuits n�j and n�l inequivalent,

then it returnsa counter-example g�� that brings nWo9p3q(r from state � to binarydiffer-state.Sucha sequenceg�� is actuallya universalcounter-exampledemon-stratingthat n�j��st�uwv p�n�l (asit candistinguishany pair of statesof n�j and n�l ).f If on the other hand n�j st x(x n�l , then from the SAT procedureproving this, itis possibleto extract informationwhetherthe part �9�(�<���?�<h7|�j+mw�2�9�(�<���?�<h7|.l m be-comestrue in somephase.Sucha proceduredependson theparticularstrategyusedto resolve thesequentialinstance,andgoesbeyondthescopeof this paper.(Of courseinitializability of n�j and n�l canbe checked separately.) If yes,wehave actuallyproven n�j st�uwv p�n�l aswell. If not, we cannotclaim n�j�� st�uwv p�n�l ,assynchronizingbut not initializing sequencemay exist that brings nWo9p3q(r intoanequivalentstate.For suchnot ~ -valuedinitializable circuits [HCC01] weusea formal initialization method,briefly discussedin [RH02], to find an aligningsequencewhenit exists.f It is shown in [HCC01] that if both n�j and n�l are initializable, then n�j st��9n�limplies n�j+st�uwv p�n�l . Actually, it is enoughto show that one of the circuits is

10

Page 67: BMC’03 - JKUfmv.jku.at/papers/bmc03-preliminary-proceedings.pdfBMC’03 Boulder, Colorado, USA. ... Alessandro Cimatti (IRST, Italy) Raanan Fraer (Intel, Israel) Danny Geist (IBM

���������������������

Steady-stateequivalence Alignability equivalence

Ckt #L #G Pass Probl. Time(sec.) Pass Probl. Time(sec.)

�Z�712 7838 9 0 1067 9 0 1106�R�1208 38259 0 1 1331 0 1 1728�R�100 1202 28 0 1128 28 0 2701

�-�826 6260 7 1 2697 6 2 3921

�R�154 1730 35 0 2008 35 0 3251

Total 79 2 12707 78 3 8231

Table1Comparisonof performance(#L latches,#Ggates).

initializableandtheotheroneis its � -valuedsafereplacement[HCC01].� Since � -valuedequivalencerequires� � and � � to matchin all time phases,theabovesufficientconditionmaynotbepracticalto infer alignabilityfrom � -valuedequivalence.Instead,a ( ��� ) delayed� -valuedequivalencecanbeused,whichrequires � � and � � to matchfrom phase� onward. Still, usageof delayed � -valuedequivalencein proving alignability is limited.

7 Experimental results

We have implementedAlgorithm 1 andits modifiedversionfor checking� -valuedandsteady-stateequivalences.Most of our circuits areresetable,thusin practicethisalgorithmsperformsalignability checkaswell.

Experimentsreportedbelow wereperformedon550MHzdualCPULinux ma-chinewith 2GB memory. A timeoutof �� �  secondswasusedin the SAT solver.Experimentalresultsshow that saythe steady-stateequivalencealgorithmis ¡�¢¤£.¥fasterthan a dual-rail alignability equivalencealgorithm that first performssyn-chronizationof the specificationand implementationcircuits (seeTable1; there,numbersof latchesand gatesrepresentan averageper output). And as alreadymentioned,the latter in turn is ¡�¢¤£.¥ fasterthana correspondingsingle-rail imple-mentationof alignability checkingengine(despitethe fact that dual-rail model-ing requirestwice as much NSFs)[KR03]. Furthermore,the counter-examplesreturnedby the steady-stateenginearein average¦.¥ shorterthanthosefoundbythe alignability engine,which is muchmore important(for debugging) than theabove reportedspeed-up(seeTable2, wherecircuits § �

– §A¨ containloops,whilecircuits §�© – § �J�

areloop-free;all datais givenpersingleoutputs).

11

Page 68: BMC’03 - JKUfmv.jku.at/papers/bmc03-preliminary-proceedings.pdfBMC’03 Boulder, Colorado, USA. ... Alessandro Cimatti (IRST, Italy) Raanan Fraer (Intel, Israel) Danny Geist (IBM

ª�«�¬�­®­¯�°�±�­¯�¯�­

Steady-stateequivalence Alignability equivalence

Ckt #L #G len Ckt #L #G len Ckt len Ckt len

²�³526 2509 9 ´Rµ 151 1747 4 ´ ³

21 ´Rµ 8

´R¶ 18 160 6²�·

173 2037 6 ´R¶ 8 ´ ·8

´R¸ 18 92 6 ´ ³7¹107 1263 6 ´R¸ 11 ´ ³7¹

12

´-º 18 415 4 ´ ³�³112 1317 6 ´-º 5 ´ ³�³

9

´R» 24 207 4 ´ ³ ¶ 67 744 4 ´R» 6 ´ ³ ¶ 9

´R¼ 25 1121 8 ´ ³ ¸ 57 619 4 ´R¼ 10 ´ ³ ¸ 10

´¾½ 704 7660 11 ´ ³ º 98 726 3 ´¾½ 65 ´ ³ º 6

Total 81 188

Table2Comparisonof counter-examplelength(#L latches,#G gates,len = CEX length).

8 Conclusions

Thusfar, SAT-basedverificationmethodshave beenmainly concentratedon prop-ertychecking,andfor thegoodreason:It is well understoodthatcircuit equivalenceverification can be performedby the model-checkingof propertiesthat expressequivalenceof thecircuit outputs.Indeed,in thiswork, wehavedemonstratedhowSAT-basedmethods(suchasthe BMC or the inductionmethod)canbe usedforproving sequentialequivalencein accordancewith a numberof importantsequen-tial equivalenceconcepts.

In particular, we have developedSAT-basedverificationmethodsfor verifica-tionof sequentialcircuitswith respectto ¿ -valued,steady-stateand(partly)alignabil-ity equivalence.Thenovelty of ourapproachis thatit doesnot requirea resetstate.Instead,we canusethe undefinedstateasa resetstate,after encodingthe latterinto a binary representation.Unlike the ATPG-basedmethodof [HCC01], fromwhich our approachemerged, our algorithmsfor checking ¿ -valuedand steady-stateequivalencearecomplete.We hopethatour work shedsfurther light on therelationshipbetweentheATPG-andSAT-basedsequentialverification.

An advantageof our approachis that the verificationprocedurebecomesrel-atively simple conceptually, thus it is easyto implementand maintain it. Ourmethodcomplimentsearliermethodsfor whichsynchronizationis anessentialpartof verification,asour algorithmsoutperform(in a numberof dimensions)similaralgorithmsthat needto computeresetstates.Clearly, this doesnot decreasetheimportanceof initialization basedmethods.In particular, synchronizationmethodswheninitializing sequencesdonot exist areindispensable.

Actually, becauseof the importanceof shortcounter-examplesfor debuggingat earlystagesof design,steady-stateverificationis enteringa default flow in our

12

Page 69: BMC’03 - JKUfmv.jku.at/papers/bmc03-preliminary-proceedings.pdfBMC’03 Boulder, Colorado, USA. ... Alessandro Cimatti (IRST, Italy) Raanan Fraer (Intel, Israel) Danny Geist (IBM

À�Á�Â�ÃÄÃÅ�Æ�Ç�ÃÅ�Å�Ã

verificationmethodology, whichwaspreviouslybasedoninitialization. Weremarkalsothattheability to find counter-examplesquickly is importantin theframeworkof modelabstractionrefinement(seee.g.[CGJLV00]). There,becauseoneworkswith prunedmodels,thereis a higherprobability of (false)negatives,till a rightpruningis found.And synchronizationcanbecheckedoncorrectlyprunedmodelsonly, whentheprunedmodelsaresteady-stateequivalent.

Despitetherapiddevelopmentandsuccessof SAT-basedmodelchecking,thereis still a long way to go. As an example,we mentionthat, on loop-freecircuits,SAT-basedequivalencemethods(bothwith or without initialization) performverypoorlycomparedto themethoddevelopedin [KMH02] for loop-freecircuits.Bothsteady-stateandalignability checkstime out after thousandsof secondson teststhatcanbeverifiedin lessthanaminutewith themethodin [KMH02]. SAT-basedmodelcheckingwill profit from thedevelopmentof alternativewaysof translatingmodel-checkingproblemsinto SAT problems.

Acknowledgments WethankR. Fraer, A. Jas,D. Kaiss,J.Moondanos,A. Rosen-mannandG. Wolfovitz for careful reading,andShi-Yu Huangfor clarifying thesubtletiesof hisATPGmethodfor checkingÈ -valuedequivalence.

References

[ABE00] P. A. Abdulla, P. Bjesse,N. Een. Symbolic reachability analysis basedonSAT solvers, Tools and Algorithms for the Constructionand Analysis of Systems,TACAS’00,SpringerLNCS,2000.

[BC00] P. Bjesse,K. Claessen.SAT basedverification without state spacetraversal,FMCAD’00, SpringerLNCS,2000.

[BCC99] A. Biere,A. Cimatti, E. Clarke. Symbolicmodelchecking withoutBDDs, ToolsandAlgorithmsfor theConstructionandAnalysisof Systems,1999.

[BCCFZ99]A. Biere,A. Cimatti, E. Clarke, M. Fujita. Y. Zhu. SymbolicmodelcheckingusingSAT proceduresinsteadof BDDs, DAC 1999.

[Bry87] R. E.Bryant.BooleanAnalysisof MOSCircuits, IEEETransactionsonComputer-AidedDesignof IntegratedCircuitsandSystems,Vol. CAD-6, No. 4, 1987

[BS94] R.E.Bryant,C.-J.H.Seger. Digital circuit verificationusingpartially-orderedstatemodels, Twenty-FourthInternationalSymposiumon Multiple-ValuedLogic, 1994.

[BCLMD94] J.R. Burch, E.M. Clarke, D.E. Long, K.L. McMillan, D.L. Dill. Symbolicmodelchecking for sequentialcircuit verification, IEEE Transactionson Computer-AidedDesignof IntegratedCircuitsandSystems,vol 13,n. 4, 1994.

[CCQ96]G. Cabodi,P. Camurati,S. Quer. Improvedreachability analysisof large finitestatemachines, ICCAD 1996.

13

Page 70: BMC’03 - JKUfmv.jku.at/papers/bmc03-preliminary-proceedings.pdfBMC’03 Boulder, Colorado, USA. ... Alessandro Cimatti (IRST, Italy) Raanan Fraer (Intel, Israel) Danny Geist (IBM

É�Ê�Ë�ÌÍÌÎ�Ï�Ð�ÌÎ�Î�Ì

[CC97] G. Cabodi,P. Camurati.SymbolicFSMtraversalsbasedon thetransitionrelation,IEEE Transactionson Computer-Aided Designof IntegratedCircuits andSystems,vol. 16,n. 5, 1997.

[CA89] K.-T. Cheng,D. Agrawal. Stateassignmentfor initializablesynthesis, ICCAD’89.

[CJSP93]H. Cho, S.-W. Jeong,F. Somenzi,C. Pixley. Synchronizing sequencesandsymbolic traversal techniques in test generation, J. Electron. Test.: Theory ÑApplications,vol. 4, n. 2, 1993.

[CGJLV00] E.M. Clarke, O. Grumberg, S. Jha,Y. Lu, H. Veith. Counterexample-guidedAbstractionRefinement, CAV’00, SpringerLNCS,2000.

[CGP99]E. Clarke,O. Grumberg, D. Peled.ModelChecking, MIT Press,1999.

[CPRSS97]F. Corno, P. Prinetto,M. Rebaudengo,M. SonzaReordaand G. Squillero.A new approach for initialization sequencescomputationfor synchronoussequentialcircuits, IEEEVLSI in ComputersandProcessors,1997.

[CBM89] O. Coudert, C. Berthet, J.C. Madre. Verification of synchronous sequentialmachinesbasedonsymbolicexecution, Workshopof AutomaticVerificationMethodsfor Finite StateSystems,1989.

[CM90] O. Coudert, J.C. Madre. A Unified framework for the formal verification ofsequentialcircuits., ICCAD 1990.

[HS98] G.D. Hachtel,F. Somenzi.Logic Synthesisand Verification Algorithms, KluwerAcademicPublishers,1998.

[HCC01] S.-Y. Huang,K.-T. Cheng,K.-C. Chen.Verifying sequentialequivalenceusingATPGtechniques, ACM Transactionson DesignAutomationof ElectronicSystems,2001.

[Jon02]R.B. Jones.SymbolicSimulation Methods for Industrial Formal Verification,Kluwer AcademicPublishers,2002.

[KR03] D. Kaiss,A. Rosenmann.Dual rail modelingfor SATbasedsequentialverification.(In preparation.)

[KBS96] M. Keim, B. Becker and B. Stenner. On the (non)-resetabilityof synchronoussequentialcircuits, IEEE VLSI TestSymposium,1996.

[KMH02] Z. Khasidashvili, J. Moondanos,Z. Hanna. TRANS: Efficient SequentialVerificationof Loop-FreeCircuits. HLDVT’02, IEEEComputerSocietyPress,2002.

[Koh78]Z. Kohavi. SwitchingandFinite AutomataTheory, McGrawHill, New York, 1978(secondedition).

[LP96] Y. Lu andI. Pomeranz.Synchronizationof largesequentialcircuitsbypartial reset,IEEE VLSI TestSymposium,1996.

[McM93] K.L. McMillan. SymbolicModelChecking: An Approach to theStateExplosionProblem, Kluwer AcademicPublishers,1993.

14

Page 71: BMC’03 - JKUfmv.jku.at/papers/bmc03-preliminary-proceedings.pdfBMC’03 Boulder, Colorado, USA. ... Alessandro Cimatti (IRST, Italy) Raanan Fraer (Intel, Israel) Danny Geist (IBM

Ò�Ó�Ô�ÕÖÕ×�Ø�Ù�Õ×�×�Õ

[Pix92] C. Pixley. A theoryandimplementationof sequentialhardware equivalence, IEEEtransactionson Computer-Aided Design,vol. 11,no.12,1992.

[PB94] C. Pixley, G. Beihl. Calculatingresetabilityandresetsequences, ICCAD, 1991.

[PJH94]C . Pixley, S.-W. Jeong, G.D. Hachtel. Exact calculation of synchronizingsequencesbasedonbinarydecisiondiagrams, IEEEtransactionsonComputer-AidedDesign,vol. 13,1994

[PR96]I. Pomeranz,S.M.Reddy. Onremoving redundanciesfromsynchronoussequentialcircuitswith synchronizingsequences, IEEE transactionsof computers,vol. 45,no.1,1996.

[RH02] A. Rosenmann,Z. Hanna.Alignability equivalenceof synchronous sequentialcircuits, IEEE International High Level Design Validation and Test Workshop,HLDVT’02, IEEE ComputerSocietyPress,2002.

[SB95] C.-J. H. Seger, and R. E. Bryant. Formal verification by symbolicevaluation ofpartially-orderedtrajectories, FormalMethodsin SystemDesign,vol. 6, no.2, 1995.

[SS00]M. Sheeran,G. Stalmarck.A tutorial onStalmarck’s methodof propositionalproof.FormalMethodsIn SystemDesign,16 (1), 2000.

[SSS00]M. Sheeran,S. Singh,G. Stalmarck.Checking safetypropertiesusinginductionanda SAT-solver, FMCAD, 2000.

[TSLBS90]H. Touati,H. Savoj, B. Lin, R.K. Brayton,A. Sangiovanni-Vincentelli.Implicitenumeration of finite statemachinesusingBDDs, CAD’90, 1990.

15

Page 72: BMC’03 - JKUfmv.jku.at/papers/bmc03-preliminary-proceedings.pdfBMC’03 Boulder, Colorado, USA. ... Alessandro Cimatti (IRST, Italy) Raanan Fraer (Intel, Israel) Danny Geist (IBM
Page 73: BMC’03 - JKUfmv.jku.at/papers/bmc03-preliminary-proceedings.pdfBMC’03 Boulder, Colorado, USA. ... Alessandro Cimatti (IRST, Italy) Raanan Fraer (Intel, Israel) Danny Geist (IBM

ÚÜÛÞÝàß ázâ2ãzä3åYæ3çéè�çwê�ë äzìDí�å9ä.îYç9ï0ê

A Satisfiability-BasedApproachto AbstractionRefinement in ModelChecking

ð

Bing Li ñ ChaoWangò FabioSomenzióUniversity of Coloradoat Boulder

Abstract

Wepresentanabstractionrefinementalgorithmfor modelcheckingof safetypropertiesthatreliesexclusively on a SAT solver for checkingtheabstractmodel,testingabstractcoun-terexampleson theconcretemodel,andrefinement.Model checkingof theabstractionsisbasedon boundedmodelcheckingextendedwith checksfor theexistenceof simplepathsthathelpin decidingpassingproperties.All minimum-lengthspuriouscounterexamplesareeliminatedin onerefinementstepby a procedurethatcombinestheanalysisof theconflictdependency graphproducedby theSAT solverwhile lookingfor concretecounterexampleswith aneffectiveabstractionminimizationprocedure.

1 Intr oduction

Model checking[CGP99] is analgorithmic approachto theverificationof proper-tiesof reactive systems,which hasbeensuccessfully appliedto bothhardwareandsoftware. Sincemodelcheckingentailstheexploration of a potentially very largestatespace,the alleviation of the so-calledstateexplosionproblemhasbeentheobjectof muchresearch.On the onehand,techniqueshave beendevelopedthatallow modelswith hundredsof statevariablesto beanalyzeddirectly. On theotherhand,abstractionhasbeenusedto allow themodelchecker to draw conclusionsontheoriginal,concretemodelby examiningasimpler, abstractone.

For systemswith many statevariablesandmany transitions, thesymbolic ap-proachhasprovedcrucial. In symbolicmodelchecking,setsof statesandtransitionaredescribedby theircharacteristicfunctions.Variousformsof representationhavebeenusedfor thesefunctions,the mostpopularbeingBinary DecisionDiagrams(BDDs) [Bry86], andConjunctiveNormalForm (CNF).

ôThis work wassupportedin partby SRCcontract 2001-TJ-920andNSFgrantCCR-99-71195.õEmail: [email protected]öEmail: [email protected]÷Email: [email protected]øÜù?ú ûÜú ûàüàý�þ7ÿ�� ú �Aú �.ü þ����zÿwþ7û(ú ���ÜøÜù.ÿ ���.ü����zÿwþ7û(ú �����Üú � ����ÿ�ý������ ú û7ù?ÿ��yú ���� ÿ����(þ���.ú � �����(ÿwûÜú �yøÜù.ÿ�� þ(ÿ��7ú �wü��� ���àý����(ÿwþ !��wú ÿ����wÿ"�#%$'&)((*(�+ åYæ3î9å�,.ç9å ä + ê.æ-zæYï/.9ë�03å-Yå0ê*0�.zî

Page 74: BMC’03 - JKUfmv.jku.at/papers/bmc03-preliminary-proceedings.pdfBMC’03 Boulder, Colorado, USA. ... Alessandro Cimatti (IRST, Italy) Raanan Fraer (Intel, Israel) Danny Geist (IBM

132547698):�;�478�:�<9=�>@?�A�:�B2

ClassicalBDD-basedmodelchecking[McM94] is basedon the computationof fixpoints. For instance,the reachablestatesof a model are computedas theleastfixpoint of the function C3DFE�GIHKJ�L�M*M'NODQP , which addsthe successorsof thestatesin D to theinitial states.Both thesetof statesandthesuccessor relationarestoredasBDDs. Thefixpoint computationconvergesin anumberof iterationsthatequalsthemaximumdistanceof a reachablestatefrom theinitial states.Checkingfor convergenceis madeeasyby the strongcanonicityof BDDs (identical setssharethe samerepresentation). BDD-basedmodelcheckingcanthereforeprovepropertiesalmostaseasilyasit candisprove them.

BoundedModel Checking(BMC) [BCCZ99], on the otherhand,formulatesthereachabilitytestasa seriesof satisfiability(SAT) checksfor pathsof boundedlength. (To seeif a pathof length R to a setof statesexists, the transitionrelationis unrolled R times.) For finite systemstheprocessmusteventuallyterminate:thelengthof theshortestpathbetweentwo statescannotexceedthenumberof states.Hence,if nopathis foundwith lengthupto thenumberof states,thetargetstatesareknown to beunreachable.This observation,however, doesnot helpfor thekind ofmodelsthatoneencountersin practice.Thediameterof thestategraphwouldgiveamuchbetterboundon R , but, unfortunately, it is hardto compute [BCCZ99]. Forthis reason,BMC hascometo beregardedasanexcellentdebugging (asopposedto verification) technique.That is, classicalBMC is particularlyadeptat findingcounterexamples,but ill-suited to prove their absence.

The ability demonstrated by BMC to deal with modelsbeyond the reachofBDD-basedmethodshassparked interestin theuseof CNF andSAT for proof aswell asrefutation. Two mainapproacheshave beenpursued:The replacementofBDDswith CNFformulaein thefixpoint computation [ABE00,WBCG00,McM02],andthedevelopmentof moreeffective termination criteriafor BMC.

Theopportunity of replacingBDDs with CNF formulaecanbearguedon thegroundsthatcanonicityof representationmakesBDDssomewhatinflexible. Hence,somefunctions thatadmitcompactrepresentationsin CNF have exceedinglylargeBDDs. However, the inflexibili ty argumentcan also be usedagainst CNF, andmemoization techniquesaremoreeffective for BDDs. In fact,to date,CNF-basedfixpoint computation hasnot demonstrateda consistentadvantageover theclassi-cal BDD-basedone. Onemayarguethat themainreasonfor thesuccessof BMCin finding counterexampleslies in its avoidanceof the needlesscomputationandstorageof reachablestatesthatarenoton theerrortrace.

Severalproposalshave beenmadeto improve BMC’s ability to prove thenon-existenceof a path. It is straightforward to checkfor inductive invariants,sinceitonly entailscheckingfor theexistenceof a transitionfrom a statethatsatisfiestheinvariant to onethat doesnot. An extensionof the inductive approachhasbeenpresentedin [SSS00], in which terminationoccursassoonasthelengthof thepathreachesthe lengthof the longestsimplepath from an initial state,or to a targetstate.A recentpaper[McM03] proposestheanalysisof theunsatisfiableformulaeto allow terminationwhenthereversesequentialdepthof themodelis reached.

Early termination in BMC requiresadditionalchecksbeyond the onefor the

2

Page 75: BMC’03 - JKUfmv.jku.at/papers/bmc03-preliminary-proceedings.pdfBMC’03 Boulder, Colorado, USA. ... Alessandro Cimatti (IRST, Italy) Raanan Fraer (Intel, Israel) Danny Geist (IBM

S3T5U7V9W)X�Y�U7W�X�Z9[�\@]�^�X�_T

`

a3b

adc�e5ff

a c f

ahg�i�j

k%b

klcme5ff

k c f

k g�ij

n

Fig. 1. Modelwith longsimplepath

op b

p j

q b

q jr

Fig. 2. Abstractionof themodelof Fig. 1

existenceof pathsof certainlengths.Thesecheckstranslateinto moreclausesinthe CNF formulaewhosesatisfiabilityhasto be established.For the approachof[SSS00], thenumberof extraclausesis quadraticin thelengthof thepath.As are-sult,it is notsurprisingthatfindingcounterexamplesis slowerthanwith pureBMC.Theextracost,however, appearsto beworthpaying,sinceit increasessubstantiallythefractionof passingpropertiesthatcanbedecided.Unfortunately, thereremaininstancesfor whichtheadditional terminationtestsaretooexpensive. Considerthemodelillustratedin Fig. 1. It hasstvuFs states,oneof which is initial (w ). The tyxzsstates{�|}�~��/�/�*�/�/{ |)��� arethe(unreachable)targetstates.Thelongestsimplepathfrom theinitial statehaslengtht�u�� , while thelongestsimplepathto atargetstatethatdoesnotvisit any othertargetstatehaslengthtyxzs ; thereversesequentialdepthof themodelis alsot�x�s . Hence,themethodsof [SSS00,McM03] will have to con-siderpathsof length tyxzs beforethey candeclarethetargetstatesunreachable.Bycontrast,theforwardsequentialdepthis 2.

Fig. 2 shows an abstractionof the modelof Fig. 1. Statesw , ��� , � , and {��areabstractedby � , �d� ~ � }�|*� , � , and �'� ~ � }�|*� , respectively. The target stateremainsunreachablein this model,andtheforwardsequentialdepthis still 2; however, thelongestsimplepathandthesequentialdeptharereduced.Thoughin generalthereis noguaranteethatabstractionwill shortenor evennot lengthenthelongestsimplepaths,or theshortestpaths,thisexampleillustrateshow abstractionmayhelpBMC,

3

Page 76: BMC’03 - JKUfmv.jku.at/papers/bmc03-preliminary-proceedings.pdfBMC’03 Boulder, Colorado, USA. ... Alessandro Cimatti (IRST, Italy) Raanan Fraer (Intel, Israel) Danny Geist (IBM

�3�5�7�9�)�����7�����9���@��������

especiallyfor passingproperties.AbstractionandBMC havebeencombinedin morethanonerecentwork, espe-

cially in thecontext of abstractionrefinement.In abstractionrefinement[Kur94],onestartswith a coarseabstractionof the given,concretemodelandkeepsrefin-ing it until the propertyis decided. For universalpropertieslike the reachabilityproperties thatarethe focusof this paper, this oftenmeansthat theabstractmod-els simulatethe concreteone [Mil71], and that either the property is shown tohold on an abstractmodel,or a counterexampleis found in the concreteone. In[WHL � 01,CGKS02,CCK� 02,WLJ� 03] BMC is usedto checkwhethercounterex-amplesfound in the abstractmodelscanbe concretized, that is, whethera coun-terexamplecanbe found in the concretemodelthat is mappedby the abstractiononto the abstractcounterexample. The first threeof thesemethodsalsoanalyzethe failed concretizationtest to guide the refinement. Therefore,they representinstancesof counterexample-guidedabstractionrefinement. On the other hand,[WLJ� 03] analyzestheabstractmodelto decidehow to refineit. Yet anotherap-proachis theoneof [MA03], in which theabstractmodelis derivedfrom a failingBMC run on theconcretemodel.This reversalof thecustomaryorderis attractivefor thosefrequentcasesin which pathsof moderatelengthcanbeeasilycheckedon theconcretemodel.

Onecommontrait of theapproachesto abstractionrefinementmentionedsofaris theapplicationof aBDD-basedmodelcheckerto theabstractmodels,andof SATsolversto theconcreteones.By contrast,theobjective of this paperis to explorewhatcanbeachievedwith a SAT solver astheonly decisionprocedurein theab-stractionrefinementframework. Therationalefor combiningBDDsandSAT is thateachis well-suitedto the taskassignedto it: TheSAT solver is goodat checkingtheexistenceof a pathof a givenlengthin a largemodel,whereastheBDD-basedmodelchecker is betterat proving theabsenceof certainpaths,regardlessof theirlengths,in a modelof moderatesize. This observation is certainlywell motivatedwhenoneregardsthe modelsfor which abstractionrefinementresultshave beenreportedin theliterature;their sizesrarelyexceed1,000binarystatevariables.Asthemodelsgrow larger, however, we expectanapproachpurelybasedon SAT tobecomemorecompetitive. Therefore,ourgoalis to eventuallybeingableto switchbetweenBDD-basedmodelcheckingandSAT-basedtechniquesfor theanalysisoftheconcretemodel.In thispaperwereportonasignificantstepin thatdirectionbypresentinganalgorithm for abstractionrefinementthatis purelybasedonSAT.

Our approachis similar to the onesdiscussedso far in the fact that abstrac-tionsareobtainedby removing partof thestatevariablesof themodel;refinementthenconsistsof reinstatingsomeof theremovedvariables.Thealgorithmhasthreemajor components:the decisionprocedurefor the abstractmodel is the one of[SSS00], which hasalreadybeenmentioned.Thesecondcomponent—thechoiceof therefinement—combineselementsof [WLJ� 03] and[CCK� 02]. Like thefor-mer, it addressesall theabstractcounterexamplesatonce;likethelatter, it analyzestheconflictdependency graphof thefailedconcretizationtestto deriveasetof can-didatestatevariablesfrom which theonesthatwill beaddedto theabstractmodel

4

Page 77: BMC’03 - JKUfmv.jku.at/papers/bmc03-preliminary-proceedings.pdfBMC’03 Boulder, Colorado, USA. ... Alessandro Cimatti (IRST, Italy) Raanan Fraer (Intel, Israel) Danny Geist (IBM

�3�5 7¡9¢)£�¤� 7¢�£�¥9¦�§@¨�©�£�ª�

arechosen.Finally, the third componentis a heuristicprocedurefor abstractionminimization. This minimizationis quite important in our approach,becausethesimultaneouselimination of all spuriouscounterexamplesof a certainlengthtendsto generatelarge setsof candidatevariables. Our experimental evaluationof theSAT-basedabstractionrefinementalgorithmcomparedit to both BMC (with andwithoutearlyterminationchecksfor passingproperties)andto thebestabstractionrefinementalgorithmavailableto us[WLJ« 03]. Theresults,discussedin Section4,show thatthenew approach,thoughnotuniformly superior, is morerobustthantheothers,andis especiallypromisingfor themorechallengingproblems.

2 Preliminaries

Let ¬®­®¯°h±³²/´*´/´/²�°zµh¶ bea set.We designateby ¬¸· theset ¯°'· ± ²/´/´*´/²�°'·µ ¶ consistingof the primedversionof the elementsof ¬ , andby ¬¸¹ the set ¯°�¹ ± ²/´*´/´/²�°�¹µ ¶ . Wedefineanopensystemasa4-tuple

º ¬�²/»¼²�½¾²�¿�À¼²where ¬ is thesetof (current)statevariables,» is thesetof combinationalvari-ables,½�ÁO¬Ã is the initial statepredicate,and ¿ÃÁO¬�²/»¼²/¬¸·Ä is thetransitionrelation.Thevariablesin ¬¸· arethenext statevariables.All setsarefinite, andall variablesrangeoverfinite domains.

Weassumethatthetransitionrelationis givenasthecompositionof elementaryrelations.If »Å­Æ¯ÇñO²/´*´/´/²�ÇÉÈ�¶ with ÊÌËÎÍ , ourassumptionamountsto writing:

¿ÏÁO¬Ð²*»�²*¬ · Ây­ ±�Ñ ¹ Ñ�µÁm° ·¹ÐÒ Ç ¹ Â%Ó ±�Ñ ¹ Ñ�È

¿ ¹ ÁO»¼²/¬Ï¼´ (1)

We considerthecaseof a sequentialcircuit, in which thevariablesin » areasso-ciatedwith theprimary inputsandtheoutputsof thecombinational logic gatesofthecircuit; thevariablesin ¬ areassociatedwith thememoryelements.Each¿ ¹ iscalleda gaterelationbecauseit usuallydescribesthebehavior of a logic gate.Forinstance,if Ç ¹ is theoutputvariableof a two-input AND gatewith inputs ÇÉÔ and°zÕ , then¿ ¹ ­ÖÇ ¹ Ò ÁmǸÔ3Ó¸°zÕ7 . If, ontheotherhand,Ç ¹ is aprimary input to thecir-cuit, then ¿ ¹ ­Ø× . Eachtermof theform °'·¹ Ò Ç ¹ equatesa next statevariableto acombinationalvariable.(Theoutputof thegatefeedingthe Ù -th memoryelement.)

In a sequentialcircuit, a statevariable°zÔ is saidto be in thedirect supportofvariable° ¹ (Ç ¹ ) if thememoryelementassociatedto °zÔ is connectedto thememoryelement(logic gate)associatedto ° ¹ (Ç ¹ ) by a paththat goesthrough logic gatesonly. Variable° ¹ is in the coneof influence(COI) of ° ¹ (Ç ¹ ) if thereis a path(ofany kind) connecting°zÔ to ° ¹ (Ç ¹ ).

An opensystemÚ definesa labeledtransitionstructurein theusualway, withstatesÛlÜ correspondingto thevaluationsof thevariablesin ¬ , andtransitionlabelscorresponding to thevaluationsof thevariablesin » . Conversely, a setof statesÝßÞ ÛlÜ correspondsto a predicate

Ý Áà¬Ã orÝ ÁO¬ ·  . Predicate

Ý ÁO¬Ã (Ý ÁO¬ ·  ) is the

5

Page 78: BMC’03 - JKUfmv.jku.at/papers/bmc03-preliminary-proceedings.pdfBMC’03 Boulder, Colorado, USA. ... Alessandro Cimatti (IRST, Italy) Raanan Fraer (Intel, Israel) Danny Geist (IBM

á3â5ã7ä9å)æ�ç�ã7å�æ�è9é�ê@ë�ì�æ�íâ

characteristicfunction of î expressedin termsof thecurrent(next) statevariables.Stateï�ðòñÉó is an initial stateif it satisfiesôöõO÷Ïø . Stateset îòùúñÉó is reachablefrom stateset îöû in ü stepsif thereis a pathof length ü in the labeledtransitionstructuredefinedby ý thatconnectssomestatein î¾û tosomestatein î ; equivalentlyif

î û õO÷¸þ�ø%ÿ � ������� � õà÷��� � � � � ÷ � ø%ÿ¼î õO÷ � ø (2)

is satisfiable.Stateset î is reachablefrom î û if thereexists ü¼ð�� suchthat î isreachablein ü stepsfrom î¾û . A statesetis reachable(in ü steps)if it is reachable(in ü steps)from ô . Whenno confusionariseswe shall identify a stateï ð ñlówith the set ï�� . A finite (infinite) sequenceof states� ð®ñ��ó ( ð ñ��ó ) is a finite(infinite) run of ý if thefirst stateis initial, andevery otherstateis reachablefromits predecessorin onestep.Thesetof all possiblerunsof ý is the languageof ý ,denotedby �yõàýÉø .

A linear-time safetyproperty � of ý is a subsetof ñ �ó suchthat any infinitesequenceover ñló not in � hasafinite prefix thatcannotbeextendedto asequencein � [AS85]. Opensystemý satisfiessafetyproperty � if � õàý¸ø�ù�� . Checkingthe satisfaction of an � -regular safetyproperty � by an opensystem ý can bereducedto the reachabilityproblemby composingý with an automaton��� thatacceptstheinextensibleprefixesof thesequencesnot in � . Thepropertyis satisfiedby the opensystemif no stateof the composition ý������ that projectson anacceptingstateof ��� is reachable.In thesequelwe restrictourselvesto � -regularsafetyproperties,andassumethat thegivenopensystemalreadyincorporatestheproperty automaton.This assumptionallows usto identify thepropertywith a setof (accepting)statesof thesystem,whichwealsodenoteby � . Hence,property �is satisfiedby ý if thereis no ü ð � suchthat

ô�õO÷¸þ�ø%ÿ � ������� � õO÷��� � �! � � ÷ � ø%ÿ#"$� õO÷ � ø (3)

is satisfiable.An invariant is a safetypropertythat statesthat a certainpredicateholdsof all reachablestatesof ý . In this case� is thesetof statesthatsatisfythatpredicate.

Thesearchfor a ü suchthat(3) is satisfiablecanobviously berestrictedto therange &% �''!'�( ñ ó (*),+ � . Hence,in theory, theprocessis guaranteedto terminate.In practice,thenumberof statesis too largeto beof any practicaluse,andtighterupperboundsfor ü aresought. In modelcheckingapproachesthat arebasedonfixpoint computations[McM94,ABE00,WBCG00,McM02], the maximumvalueof ü is providedby thenumberof iterationsneededto reachconvergence.On theotherhand,for algorithmsthatdirectlycheckthesatisfiabilityof (3), thediameterofthegraph[BCCZ99] or boundsobtainedfrom thestructureof thehardwaremodelhave beenproposed[BKA02]. Herewe summarizea methodproposedin [SSS00]thatis of particularinterestto us.

A simplepath is onethat visits a stateat mostonce. If somestatein "-� isreachable,theremustexist a simplepathfrom aninitial stateto it thatdoesnot go

6

Page 79: BMC’03 - JKUfmv.jku.at/papers/bmc03-preliminary-proceedings.pdfBMC’03 Boulder, Colorado, USA. ... Alessandro Cimatti (IRST, Italy) Raanan Fraer (Intel, Israel) Danny Geist (IBM

.0/21&35476*891&4*6*:5;*<>=9?@6*AB/through any otherstatesin C or D$E . Hence,if no simplepathof length F existssuchthatits first stateis initial andnootherstateis initial, or suchthatits final stateis in D$E andnootherstateis in D-E , then,thereis nopathof lengthgreaterthanorequalto F connectinga statein C to a statein D$E . If in addition,thereis no pathof lengthlessthan F connectingC to D-E , then G�H IJE . Two setsof statesKML and Kareconnectedby asimplepathof length F in G if

NPO&Q K LSR KPT-IUK L QWV�X TWY Z\[�]�[ O_^ QWV]�`_Z R!a ] R V ] TWY$K QWV O TbY X [@ced�]�[ O Zf[@gS[�h

Qji ]glkI icg T (4)

is satisfiable.Checkingthe two conditions above thenamountsto checkingthateitherof thefollowing formulaeis unsatisfiable.

NmO&Q C R!n T9Y X d�]�[ O DMCQoV ] T (5)

NmO&Q npR D-ElT9Y X [�]�d O EQWV ] Trq (6)

Notethatthepredicatecorrespondingto theset n is sutwv7x .Abstractinterpretation [CC77] providesa very flexible framework for the de-

scriptionof abstraction.In thispaper, however, weconsiderthefollowing restricteddefinition.OpensystemGyIUz V R a{R C R ^}| is anabstractionof G if~ V{�{V ;~ a � a suchthat

i ]�� Vimplies � ]9� a ;~ C Q V TPIJ� QWV�� V T0quC QWV T ;~ ^ Q V R a{R V L T-IU� QWV,� V T�q� Q a � a T�q� QWV L � V L T0q ^ QWV RarR V L T .

(Note that � ] is the combinational variableassociatedtoi L] .) Property E is the

abstractionof property E with respectto G if E Q V T-IU� QWV�� V T�qE QWV T . If E is an� -regularsetand G satisfies(or models)E , then G satisfiesE . Thatis,

G�H I EU��G�H IUE�q (7)

This preservation result is the basisfor the following abstractionrefinementap-proachto the verification of E . One startswith a coarseabstractionG X of theconcreteopensystem G andcheckswhether G X H I E X . If that is the case,thenG�H IUE ; otherwise,thereexistsa least F L � � suchthat

C Q V�X T�Y Z\[�]�[ OW� ^ Q V]�`_Z R a ] R V ] T�Y#D E Q V O � T (8)

is satisfiable. The satisfyingassignmentsto (8) are the shortest-length abstractcounterexamples(ACEs). If G X kH I E X oneor more ACEs arechecked for con-cretization. Thatis,onecheckswhether(3) hassolutionsthatagreewith theACE(s)

7

Page 80: BMC’03 - JKUfmv.jku.at/papers/bmc03-preliminary-proceedings.pdfBMC’03 Boulder, Colorado, USA. ... Alessandro Cimatti (IRST, Italy) Raanan Fraer (Intel, Israel) Danny Geist (IBM

�0�2�&�5�7�*�9�&�*�*�5�*�>�9�@�*�B�beingchecked.Becauseof theadditionalconstraintsprovidedby theACEs,acon-cretizationtestis oftenlessexpensive thatthesatisfiabilitycheckof (3). However,its failure only indicatesthat the abstracterror tracesarespurious. Therefore,ifthe concretizationtest fails, onechoosesa refinedabstraction��� andrepeatstheprocess,until oneof thesecasesoccurs.

(i) �P��� � �0� for some  , in whichcase��� �J� is inferred.

(ii) The concretizationtestpassesfor some  , in which caseit is concludedthat�¢¡� �£� andthesatisfyingassignmentfoundis returnedascounterexampleto� .

(iii ) Therefinementeventuallyproduces�m�m�J� . In this final case,thesatisfiabil-ity checkof (8) answersthemodelcheckingquestionconclusively. This is anundesirableoutcomebecausethepurposeof abstractionis defeated.

Whentherefinement�P� ¤�� of �m� is chosenwith thehelpof theinformationprovidedby the failed concretizationtest,one talks of counterexample-guided abstractionrefinement.

Theconeof influence(directsupport)of apropertyis theunionof theconesofinfluence(directsupports)of all thevariablesmentionedin theproperty. Cone-of-influencereductionrefersto theabstractionin which ¥ is theCOI of theproperty.It is commonly appliedbeforeany modelcheckingis attempted,becauseit satisfies

��� � �U¦���� �U��§ (9)

3 Algorithm

Our algorithm is shown in Fig. 3. Initially, an abstractmodel � is computedbycollectingonly thestatevariables(called latcheshenceforth)in thedirectsupportof the property � . The algorithm thenprogressively increases from its initialvalue0 until eithera counterexampleof length ¨ is found in theconcretesystem� , or it is concludedthat no counterexample exists in the currentabstractmodel.If at somepoint, theabstractmodelbecomestheconcretemodel,theendgameisexecutedasdescribedin Lines14–19.

Lines 3–13 verify the abstractmodels. First, (5) and (6) are checked to seewhetherthesimplepathconditionsaremet. If eitheroneis unsatisfiable,theprop-erty holds,andthealgorithm terminates.Otherwise,thealgorithmcheckswhetherthereis acounterexampleof length ¨ in theabstractmodel,by checking(3) on � ; ifthereis no length- abstractcounterexample,thereis nocounterexampleof lengthup to ¨ in theconcretemodeleither. (This is becauseevery abstractmodelsimu-latestheconcretemodel;hence,if thereis a realcounterexample of length ¨M©Mª£¨in the concretemodel,theremustbe a corresponding abstractcounterexample oflength ¨M© ©pª«¨M© . Sincethe counterexample length is increasedin incrementsofone,we would have found this counterexample before.) Sincethereis no coun-terexampleof lengthup to ¨ (in eithertheabstractmodelor theconcretemodel),¨ is increasedby one.Ontheotherhand,if thereis anabstractcounterexamplesof

8

Page 81: BMC’03 - JKUfmv.jku.at/papers/bmc03-preliminary-proceedings.pdfBMC’03 Boulder, Colorado, USA. ... Alessandro Cimatti (IRST, Italy) Raanan Fraer (Intel, Israel) Danny Geist (IBM

¬0­2®&¯5°7±*²9®&°*±*³5´*µ>¶9·@±*¸B­booleanPURESAT( ¹ , º ) »1 ¼ = 0;2 ¹ = CREATEINITIALABSTRACTION( ¹ , º );3 while ( ¹U½¾ ¹ ) »4 if ( ¿ CHECKSIMPLEPATH( ¹ , º , ¼ ))5 return TRUE;6 if (EXISTCEX( ¹ , º , ¼ )) »7 if (EXISTCEX( ¹ , º , ¼ ))8 return FALSE;9 refinement= GETREFINEMENTFROMCA( ¹ , ¹ , º , ¼ );10 ¹ = ADDREFINEMENTTOABSMODEL( ¹ , refinement);11 À12 ¼ ¾ ¼ÂÁyà ;13 À14 while (CHECKSIMPLEPATH( ¹ , º , ¼ )) »15 if (EXISTCEX( ¹ , º , ¼ ))16 return FALSE;17 ¼ ¾ ¼ÂÁyà ;18 À19 return TRUE;À

Fig. 3. ThePureSAT algorithm

setGETREFINEMENTFROMCA( ¹ , ¹ , º , ¼ ) »nsVarSet= GETNEXTSTATEVARSFROMCDG( ¹ , º , ¼ );sufficient= Ä ;while (sufficientdoesnot kill all length-¼ counterexamplesÅ

nsVarSetis notempty) »someNsVars= PICKVARSTHRESHOLD(nsVarSet,threshold);sufficient= sufficient Æ someNsVarsnsVarSet= nsVarSetÇ someNsVarsÀ

RCArray= COMPUTERELATIVECORRELATIONARRAY(sufficient,¹ , ¹ );return REFINEMENTM INIMIZATION( ¹ ,RCArray);À

Fig. 4. Therefinementalgorithm

length ¼ , (3) is checkedon theconcretemodelto seeif any concretecounterexam-pleof thesamelengthexists. If it does,thepropertyfails;otherwise,therefinementstep(Lines9–10)is executed.

Thegoalof therefinementprocedureis to find a minimal setof latchesnot in¹ which, afterbeingaddedto theabstractmodel,cankill all thecounterexamples

9

Page 82: BMC’03 - JKUfmv.jku.at/papers/bmc03-preliminary-proceedings.pdfBMC’03 Boulder, Colorado, USA. ... Alessandro Cimatti (IRST, Italy) Raanan Fraer (Intel, Israel) Danny Geist (IBM

È0É2Ê&Ë5Ì7Í*Î9Ê&Ì*Í*Ï5Ð*Ñ>Ò9Ó@Í*ÔBÉof thelength Õ . Our refinementalgorithmis basedoncomputingandanalyzingtheunsatisfiablecore [GN03,ZM03] associatedwith theproof thatthereis noconcretecounterexampleof length Õ ; hence,it is similar to theconflictanalysismethodpro-posedin [CCKÖ 02]. However, ourapproachdifferssignificantlyfrom [CCKÖ 02]in thefollowingaspects:

(i) Theauthorsof [CCKÖ 02] first identify a singlespuriousabstractcounterex-ample(by usingBDD-basedmodelchecking),togetherwith its failureindex.(I.e., thetime stepfrom which theACE is no longerconcretizablein thecon-cretemodel.)A conflictdependency graphis built from theunsatisfiableBMCobtainedby constrainingtheconcretemodelwith thesinglespuriousACEupto the failure index time step. The refinementset is thencomputedby ana-lyzing the conflict dependency graph. In our algorithm, however, we do notusea singleabstractcounterexample to constraintheBMC instance(andwedo not computethe failure index). Rather, an unconstrainedBMC instance(on theconcretemodel,for pathlengthup to Õ ) is usedfor theconcretizationtest;sucha BMC instancecoversall the possiblelength-Õ spuriousabstractcounterexamples.

(ii) In [CCKÖ 02], the invisible latches(thosenot currentlyin × ) areaddedto therefinementsetif their correspondingliteralsat thefailureindex time stepap-pearin theconflictdependency graph.In ouralgorithm, all theliterals(whichcorrespondto eitherlatchesor internallogic gatesat differenttime steps)ap-pearingin the unsatisfiablecore are recordedin the SAT solver. However,only thoseinvisible latcheswhosenext-statevariable literals(i.e., theliteralscorrespondingto the input variableof a latchat a differenttime step)appearin theunsatisfiablecoreareaddedto therefinementset. This refinementset,whenaddedto × , is sufficient to kill all length-Õ spuriousabstractcounterex-amples. Our algorithmfor picking refinementvariablesis shown in Fig. 4.The original “sufficient set” (i.e., nsVarSetin the pseudocode)may or maynotbeminimal; hence,refinementminimizationis usedto getrid of theredun-dantlatchesin therefinementsetbeforethe functionreturns.In somecases,thenumberof redundantinvisible latchesin nsVarSetmaybetoo large,caus-ing REFINEMENTM INIMIZATION to spendtoo muchtime. The while loop,togetherwith a threshold,is usedto heuristically getasmaller“sufficientset”for therefinementminimization: Eachtime,only acertainnumberof invisiblelatchesarepickedfrom nsVarSet,afterwhich (3) is checkedto seeif they arealreadysufficient.

(iii ) Ourrefinementminimizationalgorithmisalsosomewhatdifferentfrom[CCKÖ 02].Both methodsremove redundantlatchesgreedily. Eachlatchin turn is tenta-tively removed. If (3) remainsunsatisfiable,the remaininglatchesare stillsufficient, andthedroppedlatch is indeedredundant;otherwise,that latch isrestoredto the refinementset. In our method,the order in which invisiblelatchesare removed in the minimizationprocedureis basedon the relativecorrelationof eachcandidatelatchto thecurrentabstractmodel.Therelative

10

Page 83: BMC’03 - JKUfmv.jku.at/papers/bmc03-preliminary-proceedings.pdfBMC’03 Boulder, Colorado, USA. ... Alessandro Cimatti (IRST, Italy) Raanan Fraer (Intel, Israel) Danny Geist (IBM

Ø0Ù2Ú&Û5Ü7Ý*Þ9Ú&Ü*Ý*ß5à*á>â9ã@Ý*äBÙcorrelationof aninvisible latchequalstheratio of thenumberof gatesin theCOI of this latchwhich arealreadyin theabstractmodeldividedby thetotalnumberof gatesin the COI of this latch. Intuitively, the larger the relativecorrelationof a latch,thelargereffect it will havewhenaddedto or subtractedfrom thecurrentabstractmodel.Theinvisible latchesof thecurrentsufficientsetaresortedby FunctionCOMPUTERELATIVECORRELATIONARRAY: Theonewith thesmallerrelativecorrelationis consideredof lessimportance,andthus will be testedfor deletionearlier. In this way, we canconcentrateonthe important invisible latchesandat thesametime keeptherefinedabstractmodelsmall.

Our approachis also relatedto the one of [MA03]. Both approachescheckall counterexamplesof a certainlenghtat onceby a model checkingrun on theconcretemodel.Themaindifferencesare:

(i) We useSAT, insteadof a BDD-basedmodelchecker, for theabstractmodel.This will give our methodan advantagein proofs that requirean abstractmodelof sizecomparableto thatof theconcreteone.

(ii) Our abstractiongrows at eachrefinement,andwe userefinementminimiza-tion to control its size,whereastheabstractionof [MA03] is computedfromscratcheachtime. Refinementminimization requiresrepeatedBMC runs;these,however, arerunson theabstractmodel.In theexperimentsreportedinSection4, refinementminimizationwasnever thebottleneck,andit couldbefurther spedupby usinganincrementalSAT solver.

4 Experimental Results

Toevaluatethetechniqueof Section3, wecomparedfouralgorithms:animplemen-tationof theBMC [BCCZ99] algorithm, BMC extendedwith thechecksfor simplepaths[SSS00] (referredto asSSS),our PURESAT algorithm,andtheGRAB algo-rithm of [WLJå 03], which usesboth BDDs andSAT. All the four algorithms areimplementedin VIS-2.0 [Bå 96,VIS], andChaff [MMZ å 01] wasuseastheback-endSAT solver. Theexperimentswererun underLinux on an IBM IntelliStationwith a1.7GHz Intel Pentium4 CPUand2 GB of RAM.

The comparisonwas conductedon 26 models,either from industry or fromVIS verificationbenchmarks[Bå 96,VIS] exceptfor lsp. This modelwascreatedto illustratethe help BMC could get from abstraction.A simplified versionof itappearsin Fig. 1. Sincein theconcretemodel,thelongestsimplepathis long,SSSfailedto complete,eventhoughPURESAT finishedwithin onesecond.

Theresultsareshown in Table1. Thefirst columnis thenameof themodel,thesecondcolumnindicateswhethereachpropertypassesor fails; if a propertyfails,thenumberin this columnis the lengthof thecounterexample. The third columngives the numberof latchesin the coneof influenceof the property. The fourthcolumnlists thetime of BMC. A time in parenthesesis thetime elapsedwhentheprocessranout of memory. In our experiments,the time limit wassetto 8 hours.

11

Page 84: BMC’03 - JKUfmv.jku.at/papers/bmc03-preliminary-proceedings.pdfBMC’03 Boulder, Colorado, USA. ... Alessandro Cimatti (IRST, Italy) Raanan Fraer (Intel, Israel) Danny Geist (IBM

æ0ç2è&é5ê7ë*ì9è&ê*ë*í5î*ï>ð9ñ@ë*òBç

Table1Experimentalresults.Boldfaceis usedto highlightbestCPUtimes

model pass/ latches BMC SSS PureSAT Grab

cex length in COI time time time final sz. time final sz.

lsp-p1 pass 12 ó 8h ó 8h 1 3 1 3

D12-p1 16 48 5 25 37 23 14 23

D23-p1 5 85 1 1 3 25 20 21

D2-p1 14 94 6 25 20 48 180 48

D14-p1 14 96 65 83 1460 80 ó 8h (75)

D1-p1 9 101 1 5 11 20 9 21

D1-p2 13 101 2 12 26 23 51 23

D1-p3 15 101 3 18 32 23 56 25

I12-p1 370 119 ó 8h ó 8h ó 8h (12) 2503 16

B-p1 pass 124 ó 8h ó 8h 2074 18 173 18

B-p2 17 124 150 675 247 7 93 7

B-p3 pass 124 ó 8h ó 8h ó 8h (42) 223 43

B-p4 pass 124 ó 8h (23708) ó 8h (43) 393 42

D22-p1 10 140 2 10 17 132 720 132

D24-p1 9 147 7 10 2 4 1 4

D24-p2 pass 147 ó 8h 16 6 8 3 8

D24-p3 pass 147 ó 8h 1 4 6 20 8

D24-p4 pass 147 ó 8h 1 4 6 43 8

D24-p5 pass 147 ó 8h 1 4 8 3 5

M0-p1 pass 221 ó 8h (2537) 2156 13 136 16

D5-p1 31 319 58 592 155 13 31 18

D18-p1 23 506 96 795 4359 160 ó 8h (99)

D16-p1 8 531 10 29 31 14 92 14

D20-p1 14 562 26 101 6228 232 ó 8h (69)

rcu-p1 pass 2453 ó 8h (3115) 136 11 195 10

IU-p2 pass 4493 (11331) ó 8h 1756 14 ó 8h (6)

12

Page 85: BMC’03 - JKUfmv.jku.at/papers/bmc03-preliminary-proceedings.pdfBMC’03 Boulder, Colorado, USA. ... Alessandro Cimatti (IRST, Italy) Raanan Fraer (Intel, Israel) Danny Geist (IBM

ô0õ2ö&÷5ø7ù*ú9ö&ø*ù*û5ü*ý>þ9ÿ@ù��BõThefifth columnis thetimeof SSS;thesixthcolumnshowsthetimefor PURESAT;theseventhcolumnis thenumberof latchesin thefinal abstractmodel.If thetimeis greaterthan8 hours,thenumberin parenthesesin thenext columnis thenumberof latchesin theabstractmodelwhentime ranout. Thenext two columnsarethedatafor GRAB. All CPUtimesarein secondsexceptwhennoted.

Thealgorithm labeledBMC cancheckinductive invariants.However, no suchpropertiesareincludedin our setof experiments.Fromthe tablewe canseethat,in general,for passingproperties,PURESAT is betterthanbothBMC andSSS. Forfailing properties,with a few exceptions,BMC is best,while PURESAT is betterthan GRAB. For the largestmodel, like IU, whoseCOI contains4493 latches,PURESAT is the only onebeingableto verify the property. Interestingly, GRAB

andPURESAT fail to finishsimilarnumbersof experiments(4 for GRAB and3 forPURESAT). However, thetwo setsof failuresaredisjoint. This is anencouragingsignfor thedevelopmentof ahybrid algorithmthatmayswitchbetweenBDDsandSAT for theanalysisof theabstractmodels.

ThoughPURESAT appearsto bereasonablyrobust, thereareonly threecasesin Table1 in which it managesto befastest.This is in partdueto thefact that theimplementationis still preliminary.

5 Conclusions

We have presentedanabstractionrefinementalgorithm for modelcheckingsafetyproperties that usesa SAT solver assoledecisionprocedure.We have comparedthis algorithmto both BMC andto an abstractionrefinementalgorithmthat usesboth BDDs and CNF SAT. The new algorithm is competitive and was the onlyoneto completethe largesttestcase.Our implementation is still preliminary. Weplanto investigatetheuseof anincrementalSAT solver like SATIRE [WKS01] inthe abstractionminimization phase,which is currently the most time consumingpartof thealgorithm. We arealsointerestedin theextensionof the techniquesof[WLJ

�03] to theSAT environment. This is not anentirely trivial task,sincethey

arebasedontheknowledgeof thesetsof statesatvariousdistancesalongthepathsconnectinginitial statesto errorstates.

By its very nature,the PURESAT algorithmsuffers,albeit in attenuatedform,from thesameproblemsthatafflict thebasicprocedureusedin analyzingtheab-stractmodels. Improvementslike thoseproposedin [McM03] may boostPURE-SAT’s performance.More generally, the integrationwith a BDD-basedapproachto the analysisof the abstractmodel shouldlead to a more robust andpowerfulapproachto abstractionrefinement.

References

[ABE00] P. A. Abdulla, P. Bjesse,andN. Een. Symbolic reachabilityanalysisbasedon SAT-solvers. In Tools and Algorithms for the Constructionof Systems(TACAS), pages411–425,2000.LNCS1785.

13

Page 86: BMC’03 - JKUfmv.jku.at/papers/bmc03-preliminary-proceedings.pdfBMC’03 Boulder, Colorado, USA. ... Alessandro Cimatti (IRST, Italy) Raanan Fraer (Intel, Israel) Danny Geist (IBM

������� �����������������������

[AS85] B. Alpern and F. B. Schneider. Defining liveness. Information ProcessingLetters, 21:181–185,October1985.

[B � 96] R. K. Brayton et al. VIS: A systemfor verification and synthesis. InT. Henzingerand R. Alur, editors,Eighth Conferenceon ComputerAidedVerification (CAV’96), pages428–432.Springer-Verlag, RutgersUniversity,1996.LNCS1102.

[BCCZ99] A. Biere, A. Cimatti, E. Clarke, and Y. Zhu. Symbolic model checkingwithout BDDs. In Fifth International Conferenceon Tools and Algorithmsfor Construction and Analysis of Systems(TACAS’99), pages 193–207,Amsterdam,TheNetherlands,March1999.LNCS1579.

[BKA02] J. Baumgartner, A. Kuehlmann,and J. Abraham. Property checking viastructuralanalysis. In E. Brinksma and K. G. Larsen,editors,FourteenthConference on Computer Aided Verification (CAV’02), pages 151–165.Springer-Verlag,Berlin, July2002.LNCS2404.

[Bry86] R. E. Bryant. Graph-basedalgorithmsfor Booleanfunction manipulation.IEEETransactionsonComputers, C-35(8):677–691,August1986.

[CC77] P. CousotandR. Cousot. Abstractinterpretation:A unified latticemodelforstatic analysisof programsby constructionsor approximationof fixpoints.In Proceedingsof the ACM Symposiumon the Principles of ProgrammingLanguages, pages238–250,1977.

[CCK� 02] P. Chauhan,E. Clarke,J.Kukula,S.Sapra,H. Veith,andD. Wang.Automatedabstractionrefinementfor modelcheckinglargestatespacesusingSAT basedconflict analysis. In M. D. Aagaard and J. W. O’Leary, editors, FormalMethodsin ComputerAidedDesign, pages33–51.Springer-Verlag,November2002.LNCS2517.

[CGKS02]E. Clarke, A. Gupta,J. Kukula, and O. Strichman. SAT basedabstraction-refinementusingILP andmachinelearning.In E. BrinksmaandK. G. Larsen,editors,FourteenthConferenceon ComputerAidedVerification (CAV 2002),pages265–279.Springer-Verlag,July2002.LNCS 2404.

[CGP99]E. M. Clarke, O. Grumberg, andD. A. Peled. Model Checking. MIT Press,Cambridge,MA, 1999.

[GN03] E. Goldberg andY. Novikov. Verificationof proofsof unsatisfiabilityfor CNFformulas. In Design,AutomationandTestin Europe(DATE’03), pages886–891,Munich,Germany, March2003.

[Kur94] R. P. Kurshan. Computer-Aided Verification of Coordinating Processes.PrincetonUniversityPress,Princeton,NJ,1994.

[MA03] K. L. McMillan andN. Amla. Automaticabstractionwithout counterexamples. In InternationalConferenceonToolsandAlgorithmsfor ConstructionandAnalysisof Systems(TACAS’03), pages2–17,Warsaw, Poland,April 2003.LNCS2619.

14

Page 87: BMC’03 - JKUfmv.jku.at/papers/bmc03-preliminary-proceedings.pdfBMC’03 Boulder, Colorado, USA. ... Alessandro Cimatti (IRST, Italy) Raanan Fraer (Intel, Israel) Danny Geist (IBM

�������� �� ������!�"�#�$�%���&��

[McM94] K. L. McMillan. SymbolicModel Checking. Kluwer AcademicPublishers,Boston,MA, 1994.

[McM02] K. L. McMillan. Applying SAT methodsin unboundedsymbolic modelchecking. In E. BrinksmaandK. G. Larsen,editors,FourteenthConferenceon ComputerAided Verification (CAV’02), pages250–264.Springer-Verlag,Berlin, July2002.LNCS2404.

[McM03] K. L. McMillan. Interpolation and SAT-based model checking. InFifteenth Conference on ComputerAided Verification (CAV’03). Springer-Verlag,Berlin, July2003.LNCS 2725.To appear.

[Mil71] R. Milner. An algebraicdefinitionof simulationbetweenprograms.Proc.2ndInt. Joint Conf. onArtificial Intelligence, pages481–489,1971.

[MMZ ' 01] M. Moskewicz, C. F. Madigan, Y. Zhao, L. Zhang,and S. Malik. Chaff:EngineeringanefficientSAT solver. In Proceedingsof theDesignAutomationConference, pages530–535,LasVegas,NV, June2001.

[SSS00]M. Sheeran,S. Singh,and G. Stalmarck. Checkingsafetypropertiesusinginductionanda SAT-solver. In W. A. Hunt, Jr. andS. D. Johnson,editors,Formal Methodsin ComputerAidedDesign, pages108–125.Springer-Verlag,November2000.LNCS1954.

[VIS] URL: http://vlsi.colorado.edu/( vis.

[WBCG00] P. Williams, A. Biere, E. M. Clarke, and A. Gupta. Combining decisiondiagramsandSAT proceduresfor efficient symbolicmodelchecking.In E. A.Emersonand A. P. Sistla, editors,Twelfth Conferenceon ComputerAidedVerification (CAV’00), pages124–138.Springer-Verlag, Berlin, July 2000.LNCS1855.

[WHL ' 01] D. Wang,P.-H. Ho,J.Long,J.Kukula,Y. Zhu,T. Ma,andR.Damiano.Formalpropertyverification by abstractionrefinementwith formal, simulationandhybrid engines.In Proceedingsof theDesignAutomationConference, pages35–40,LasVegas,NV, June2001.

[WKS01] J. Whittemore, J. Kim, and K. Sakallah. SATIRE: A new incrementalsatisfiability engine. In Proceedingsof the DesignAutomationConference,pages542–545,LasVegas,NV, June2001.

[WLJ' 03] C. Wang,B. Li, H. Jin, G. D. Hachtel,andF. Somenzi.Improving Ariadne’sbundleby following multiple threadsin abstractionrefinement.Submittedforpublication,April 2003.

[ZM03] L. Zhang and S. Malik. Validating SAT solvers using an independentresolution-basedchecker:Practicalimplementationsandotherapplications.InDesign,AutomationandTestin Europe(DATE’03), pages880–885,Munich,Germany, March2003.

15

Page 88: BMC’03 - JKUfmv.jku.at/papers/bmc03-preliminary-proceedings.pdfBMC’03 Boulder, Colorado, USA. ... Alessandro Cimatti (IRST, Italy) Raanan Fraer (Intel, Israel) Danny Geist (IBM
Page 89: BMC’03 - JKUfmv.jku.at/papers/bmc03-preliminary-proceedings.pdfBMC’03 Boulder, Colorado, USA. ... Alessandro Cimatti (IRST, Italy) Raanan Fraer (Intel, Israel) Danny Geist (IBM

)+*-,/. 0�132�465�768:9;8=<?>@4�ACB65@4�D�8@EF<

G HJILKNMPORQTS/UWVCXZYT[/\ZQT]_^`QTSJ[/aCbdcCefaCbhgCVCXZ\Z]Cij S/QTkCXZbhU \Z]mln\ZiTaCXZopKqQT]Cr�[/S/YT\Z]CbhgmlnYTS/gCstYTS/b

cCo�r�[/bhUur

vxwzy|{~}~wz��������y|�����~w �~�����|wz���C������� �������:y|{~���R�~����h��� �����=�����:�=�����¡ ¢��£����|�

¤¡��¥�¦+���/§f¨����©«ª��¬�:�=ª��f­®�Z¯6��£�©«ª��¬�:�=ª  ¨£�����°+­Z  §�±f²

³C´z�6µ·¶R�|{~�~��y���wz�6¸ ¹º�~��wzy|{~��¹ºy;¸»y|�|{~� ¼-�|½�wz{~�|��w�¾¿y���y|{~y|���À ª������|�=�Á¤Â��Ã=��Ä���Å�Æ6Ã=����©ÇÃ=°�­®�|��¦

ÈÉ��£�Ê ��� ��Æ6° À §

ËÍÌfÎzÏÑÐZÒ�Ó�ÏÔfÕ�ÖØ×ÁÙ�Ú?Ù�Û@ÜÁÝ�Û@×:Þ@Ü:ÖØß�Û@×�ÚÂà�á�â?Û@ã|Ú?Ù�Ù�ãØÖØÞ@Ú?ä®ÖØá?àæå�á?Ü�ç�è+Ô¢é�ß�Ú?×:Û@Ýæêëá?ì�à�Ý�Û@Ý«í�á;Ý�Û@ã¢îfÕ�Û@Þ=ï;ÖØà�ðñ êëí�îfòfófÖØä®Õ�ÖØàôÕ�Ú?Ü:Ý�ó»Ú?Ü:Ûh×:Þ=Õ�Û@Ý�ì�ãØÖØà�ð3Ù�Ü:á?ß�ãØÛ@õö×:÷ø ÖØÜ:×:äöá?å�Ú?ãØãØù¡ÖØä3ÖØà;ä®Ü:á;Ý�ì�Þ@Û@×öÚ-à�Û@óúõöá;Ý�Û@ã~å�á?ÜöÞ@á?à;ä®Ü:á?ãØû¬Ý�Û@Ù�Û@à�Ý�Û@à;äö×:ü;×:ä®Û@õö×:÷þýzàÿä®Õ�ÖØ×

õöá;Ý�Û@ãØù Ú?ãØä®Û@Ü:à�Ú?ä®ÖØâ?Û~Û��;Û@Þ@ì�ä®ÖØá?à�× ñ Ù�Ü:á;Ý�ì�Þ@ÖØà�ð��=ä®Ü:Û@Û@û¬ãØÖØï?Û��Í×:Þ=Õ�Û@Ý�ì�ãØÖØà�ð¡ä®Ü:Ú?Þ@Û@×:ò+Ú?Ü:ÛëõöÚ?à�Ú?ð?Û@ÝÚ?×ÇÞ@á?à�Þ@ì�Ü:Ü:Û@à;äº×:ü;×:ä®Û@õö×:ùëófÕ�Û@Ü:Û Ú?ãØä®Û@Ü:à�Ú?ä®ÖØâ?Û�ß�Û@Õ�Ú�â;ÖØá?Ü:×ÇÚ?Ü:Û å�á?ãØãØá�ó»Û@ÝÿÖØà Ù�Ú?Ü:Ú?ãØãØÛ@ãØ÷ ÔfÕ�ÖØ×Û@à�Ú?ß�ãØÛ@× ×:ä®Ú?à�Ý�Ú?Ü:Ýxêëí�î ä®Û@Þ=Õ�à�Ö��;ì�Û@×:ùÍÙ�Ü:á;Ý�ì�Þ@ÖØà�ð-×:á?ãØì�ä®ÖØá?à�× õöÚ?Ý�Û«ì�Ùxá?åÍ×:ÖØà�ð?ãØÛ�Ù�Ú?ä®Õ�×Þ@á?à�à�Û@Þ@ä®ÖØà�ðöÖØà�ÖØä®ÖØÚ?ã�Ú?à�Ýôä®Û@Ü:õöÖØà�Ú?ã ×:ä®Ú?ä®Û@×:÷ç�Û@Þ@á?à�Ý�ãØü@ùfÖØäºÝ�ÖØ×:Þ@ì�×:×:Û@׺ä®Õ�ÛÂõöÚ?ÖØà Ù�Ü:á?ß�ãØÛ@õJÚ?Ü:ÖØ×:ÖØà�ð�å�Ü:á?õJä®Õ�Û Ú?ß�á�â?ÛTÞ=Õ�á?ÖØÞ@Û@ùfÖØ÷ØÛ@÷ØùfÜ:Û@û

ófÜ:ÖØä®ÖØà�ð3Ü:Û@×:á?ì�Ü:Þ@ÛÍß�á?ì�à�Ý�×:ù�×:áöä®Õ�Ú?äfä®Õ�Û@üTä®Ú?ï?ÛÉÖØà;ä®áöÚ?Þ@Þ@á?ì�à;äÁä®Õ�ÛÍÚ?Ü:ä®Ö���Þ@ÖØÚ?ã�Þ@á?à�Þ@ì�Ü:Ü:Û@à�Þ@ÖØÛ@×ÖØà;ä®Ü:á;Ý�ì�Þ@Û@Ý�å�á?ÜÁÞ@á?à;ä®Ü:á?ãØãØÛ@Ý«ß�Û@Õ�Ú�â;ÖØá?Ü:×:÷ÔfÕ�ÖØÜ:Ý�ãØü@ù/ó»Û3Û��;Ù�ãØá?ÖØäÉç�è+Ôfû¬ß�Ú?×:Û@Ý�êëá?ì�à�Ý�Û@Ý-í�á;Ý�Û@ã+îfÕ�Û@Þ=ï;ÖØà�ðôÚ?×ÍÚ�â?Û@Ü:Ö���Þ@Ú?ä®ÖØá?àCä®Û@Þ=Õ�û

à�Ö��;ì�ÛÍõöá?×:ä®ãØü�á?Ü:ÖØÛ@à;ä®Û@Ý�ä®á ß�ì�ðöÕ;ì�à;ä®ÖØà�ðöÚ?à�Ý«Þ@á?ì�à;ä®Û@Ü:û¬Û��;Ú?õöÙ�ãØÛºÛ��;ä®Ü:Ú?Þ@ä®ÖØá?à�÷Éýzàôá?Ü:Ý�Û@ÜÁä®áÞ@á?à�×:ÖØÝ�Û@Ü�Ü:Û@×:á?ì�Ü:Þ@ÛÉÞ@á?à�×:ä®Ü:Ú?ÖØà;ä®×:ù+ä®Õ�ÛÉ×:á?ãØì�ä®ÖØá?à�סá?å+õöá;Ý�ÖØå�ü;ÖØà�ðÂä®Õ�Ûºç�è+Ô ×:á?ãØâ?Û@Ü¡á?Ü¡Ú?Ý�Ý�ÖØà�ðÛ��;ä®Ü:ÚöÞ@ãØÚ?ì�×:Û@×ÁÚ?Ü:Ûhß�á?ä®Õôä®Ú?ï?Û@à�ÖØà;ä®áöÞ@á?à�×:ÖØÝ�Û@Ü:Ú?ä®ÖØá?à�÷� Ü:Û@ãØÖØõöÖØà�Ú?Ü:üæÛ��;Ù�Û@Ü:ÖØõöÛ@à;ä®Ú?ã/Ü:Û@×:ì�ãØä®×:ù�Þ@á?õöÙ�Ú?Ü:ÖØà�ðôá?ì�ÜÍç�è+Ô ß�Ú?×:Û@Ý-Ú?Ù�Ù�Ü:á?Ú?Þ=ÕPä®á«×:ä®Ú?ä®Û@û

á?å�û¬ä®Õ�ÛÍÚ?Ü:ä~ê�¡û¬ß�Ú?×:Û@Ý�ä®Û@Þ=Õ�à�Ö��;ì�Û@×ÁÚ?Ü:ÛÍÛ@â?Û@à;ä®ì�Ú?ãØãØü�Ù�Ü:Û@×:Û@à;ä®Û@Ý�÷

� ����������������������

� �"!"#%$'&"(*)+(-,/.�&10321)4&1!"#657!'89$')4:/$<;=&1>%.*,/> ?357!'21&@21,/!"#%>%,/A=B'!')4# (�57!'898-57# 5�;-57#%$-(�.*>%,=?$')4:/$'CDA4&1EF&1AHG=&1$-5%E")4,/> 57AI(*;=&121)4J'2"57#%)4,/!-(K$-5/(KA4,/!':6G=&1&1!<21,/!-(*)48'&1>%&18L5MEF&1>%�N;'>%,=?O)+(*)4!':#%&12�$'!')4P"B'&Q.*,/>�# 572�R"A4)4!':S#%$'&3&1EF&1>T:/>%, UM)4!':V21,=?O;'A4&1W")4#+�X,/.Y8')4:/)4# 57A8'&"(*)4:/!-Z\[M#�#%$'&(%5/?O&S#%)+?O&"]�)4#N)+(Q59EF&1>%�^&1A4B-(*)4EF&_:/,=57A+]`G=&12"57B-(*&^57.*#%&1>_?O,/>%&S#%$-57!a#+U�&1!"#+�a�F&"57> (,/.)4!"#%&1!-(*)4EF&\>%&"(*&"57>%2�$-]57!'8b&1EF&1!_#%$'&c57;';=&"57> 57!'21&6,/!b#%$'&c?357>%RF&1#@,/.d(*,=?O&e)4!'8'B-(*C

f�g h iKh i�j-k'lDm�n h o�h p jql�r6sqm�lDiDh tqp uvf�g mw p jqn"sqm�lDiDh tqpdx�h n n"yFm=k'z y n h iDg m�{@h p|=n m�}�~�lDtqp h }��-tq~�m�iKh p@f�g m�tqlDm�~�h }�jqn/��tqoKk'z ~�m�l�� }�h m�p }�m�'�K�����q�q�=� 5�76D@5���8@5@4 � <?7q��7�E��@>7�65q�Z5F<1����D

Page 90: BMC’03 - JKUfmv.jku.at/papers/bmc03-preliminary-proceedings.pdfBMC’03 Boulder, Colorado, USA. ... Alessandro Cimatti (IRST, Italy) Raanan Fraer (Intel, Israel) Danny Geist (IBM

�I�"�F�����=� �\�"�"�

�%�%�+�7�� -¡3¢£�%¤�¤/�+¥%¦'§'�4¨/§'©D�4ª1«Fª1��¥*¬"­"�%§'ª"¥*�+¥��+¥O¥*�%�4�4��®%�7�d®*�%¤=¯±°=ª1�4­'¨<²M�4³'ª1�4¬V´-¥*ª1³a�/¥I�4� ¥µ �%ª1³'ª1¶1ª"¥%¥*¤/� ¥%¦'�%ª1¨/�+¥*�%ª1�%©D�%� �7­-¥*®*ª1���4ª1«Fª1�M�7­'³c�4¤/¨/�4¶<¥*¬"­"�%§'ª"¥*�+¥%·

¸ �4�%§'�4­S�%§'�+¥I®*� �/¯Oª1²�¤/�%¹v¦-º�¢�¢�©D°-�/¥*ª1³»¯3�7­'� µ ´'�+�7�%�4¤/­-¥I§-�%«Fª6�%ª1¶1ª1­"�%�4¬»�7�%� �7�4­'ª1³�4­"�%ª1�%ª"¥*�%�4­'¨9�%ª"¥*´'�4� ¥%¦�/¥@�7­^�7�4�%ª1�%­-�7�%�4«Fª\�%¤X¼+½K¾£�7­'³b§'ª1´'�%�+¥*�%�4¶e�%ª1¶�§'­'�4¿"´'ª"¥%·3¼4­_�%§'�+¥� µ'µ �%¤=�7¶�§À�_­'¤/­'©D³'ª1�%ª1� ¯O�4­'�+¥*�%�4¶LÁ'­'�4�%ªÂ�7´'�%¤=¯3�7� �_³'ª"¥*¶1�%�4°=ª"¥3³'ª"¥*�4¨/­Ã�7�4�%ª1�%­-�7�%�4«Fª"¥®*¤/��§'�4¨/§'�4¬"©D¶1¤/­-¥*�%� �7�4­'ª1³_¶1¤/­"�%�%¤/�4©D³'¤=¯O�4­-�7�%ª1³^¯O¤�³'ª1�+¥%·Y¡O®*�%ª1�d�%§-�7� ¦��%§'ª9�7´'�%¤=¯3�7� �/Ä4¥¥*� �7�%ªQ¥ µ �7¶1ª��+¥M¥*¬v¯M°=¤/�4�4¶"�7�4�4¬9«"�+¥*�4�%ª1³-¦K�7³'¤ µ �%�4­'¨b¯O¤�³'ª1�v¶�§'ª1¶�¹"�4­'¨=Ä4¥O¥*� �7�%ª1©D¤/®*©D�%§'ª1©7�7�%��%ª1¶�§'­'�4¿"´'ª"¥%·ÆÅ-§'ª"¥*ªb�%ª1¶�§'­'�4¿"´'ª"¥9�7�%ª^¯O�4Ç^¤/®@®*¤/�%²��7�%³±�7­'³a°-�7¶�¹"²��7�%³Â�%� �%«Fª1� ¥%�7�+¥%¦�7�+¯Oª1³È�7��Á'­'³'�4­'¨S�6¥*¶�§'ª1³'´'�4�4­'¨b¥*¤/�4´'�%�4¤/­É�/¥Y�M�%� �7¶1ªO¶1¤/­'­'ª1¶1�%�4­'¨\�4­'�4�%�+�7�I�7­'³<�%ª1� ¯O�4©­-�7��¥*� �7�%ª"¥%·

¼4­È�%§'ª_¥*�+¯ µ �4ª"¥*�6¶"�/¥*ªQ¤/®�¥*¬v¥*�%ª"¯3¥�²M�4�%§'¤/´'�T¶1¤/­"�%�%¤/�I¶�§'¤/�4¶1ª"¥eÊ%Ë Ì%Í+Î�Ï�ÐÒÑ�Í+ÐÒÓ�Ô�ÐO¶1¤/­'©¥*�%�%´'¶1� Õ%¦Ö��¥*¶�§'ª1³'´'�4ªO�+¥�� µ �7�%§-¦Ö�7­'³_¥*¬v¯M°=¤/�4�4¶\¥*¶�§'ª1³'´'�4�4­'¨e²�¤/�%¹v¥v×*´-¥*�`�4�4¹Fªd�4­"«'�7�%�+�7­"�¶�§'ª1¶�¹"�4­'¨L²M�4�%§a¶1¤/´'­"�%ª1�%©Dª1Çv�/¯ µ �4ªSª1Ç"�%� �7¶1�%�4¤/­-·ÙØI¤ ²�ª1«Fª1� ¦�¶1¤/­"�%�%¤/�4©D³'ª µ ª1­'³'ª1­"�Q°=ª1©§-�%«"�4¤/� µ �%¤�³'´'¶1ª"¥�¥*¶�§'ª1³'´'�4�4­'¨Q�4­-¥*� �7­'¶1ª"¥��/¥�¢¡6ÚT¥MÊ*¤/���%�%ª1ª"¥%Õ%¦�²M§'ª1�%ª�Ì%Û�Ü7Ý��7­'³cÞ%Û�Ë*Ñ­'¤�³'ª"¥9�7�%ª_�4­"�%�%¤�³'´'¶1ª1³£�%¤»�%ª µ �%ª"¥*ª1­"�»¥*¶�§'ª1³'´'�4�4­'¨a¶�§'¤/�4¶1ª"¥%¦�³'ª µ ª1­'³'�4­'¨ß¤/­Â«'�7�4´'ª"¥¤/®M¶1¤/­"�%�%¤/�Y¤ µ ª1� �7­'³-¥%·^Å-§'�+¥d§-�/¥��%ª1¿"´'�4�%ª1³à�b¥ µ ª1¶1�4Á'¶c°-�7¶�¹"²��7�%³^�%� �%«Fª1� ¥%�7� µ �%¤�¶1ª1©³'´'�%ª\Ê*¶"�7�4�4ª1³XáÒâ�Ó�Ë*ã�â�Î�Ë*Û�Ñ��4­Xä4å7æ+Õ%¦F²M§'�4¶�§-¦H�7�4°=ª1�4��­'¤/��®%�7�`®*�%¤=¯ç¥*� �7­'³-�7�%³Xº�¢�¢�©D°-�/¥*ª1³�%� �%«Fª1� ¥%�7�+¥%¦�+¥d­'¤/�\³'�4�%ª1¶1�%�4¬£¯3� µ'µ ª1³^�%¤a¥*� �7­'³-�7�%³àè3¤�³'ª1�6 -§'ª1¶�¹"�4­'¨ÂÊ*ª"· ¨=·4¦� MÅM½KÕµ �%¤�¶1ª1³'´'�%ª"¥%·

¼4­��%§'�+¥�²�¤/�%¹@²�ª µ �%¤ µ ¤=¥*ªI�%¤�¶�§-�7­'¨/ª`�%§'ª`¤/�%�4¨/�4­-�7�=�7´'�%¤=¯3�7�%¤/­Q¯O¤�³'ª1���4­"�%�%¤�³'´'¶1ª1³�4­aä4é/¦4å/¦ ê=¦4ë/ë7æ�®*¤/�@¶1¤/­"�%�%¤/�4©D³'ª µ ª1­'³'ª1­"�<¥*¬v¥*�%ª"¯3¥%¦�¥*¤c�%§-�7�N¥*� �7­'³-�7�%³ì¯O¤�³'ª1�¶�§'ª1¶�¹"�4­'¨µ �%¤�¶1ª1³'´'�%ª"¥9�7�%ªß¥*´ µ'µ ¤/�%�%ª1³-·Àè3¤/�%ªa¥ µ ª1¶1�4Á'¶"�7�4�4¬ì²�ª_�%� �7­-¥*®*¤/� ¯í�7�4�%ª1�%­-�7�%�4«Fªa¥*´'°'©�%� �7¶1ª"¥��%¤3¶1¤/­'¶1´'�%�%ª1­"�O°=ª1§-�%«"�4¤/� ¥²M§'�4¶�§^�7�%ª�®*¤/�4�4¤ ²�ª1³V�4­ µ �7� �7�4�4ª1�+·�¼4­V�%§'�+¥²��%¬9�%§'ª�%ª"¥*´'�4�%�4­'¨ì¥*¶�§'ª1³'´'�4�4­'¨É�+¥\�7�4²��%¬v¥3� µ �7�%§àÊ*�4­-¥*�%ª"�7³ß¤/®e�_¢¡6ÚTÕ�¶1¤/­'­'ª1¶1�%�4­'¨È�4­'�4�%�+�7��7­'³bÁ'­-�7�M¥*� �7�%ª"¥%·M¡3¥O��°"¬ µ �%¤�³'´'¶1� ¦�²�ªe¶"�7­bª1Ç µ �4¤/�4�Nî ¡OÅ-©D°-�/¥*ª1³aºK¤/´'­'³'ª1³aè3¤�³'ª1� -§'ª1¶�¹"�4­'¨=·a¼4­'³'ª1ª1³-¦��/¥d�%§'ª<³'ª"¥*�4¨/­'ª1� Ä4¥3�7�+¯ï�+¥d�%¤bð�Ñ�ãX�_¥*¶�§'ª1³'´'�4ª"¦­'¤/�e�%¤ µ �%¤ «Fª�4� ¥d�7°-¥*ª1­'¶1ª"¦�²�ª6°=ª1�4�4ª1«FªVº�èb ß¶"�7­S²�¤/�%¹L�7���4� ¥I°=ª"¥*� ¦-�/¥d�@«Fª1�%�4Á'¶"�7�%�4¤/­_�%ª1¶�§'­'�4¿"´'ª¯O¤=¥*�%�4¬V¤/�%�4ª1­"�%ª1³X�%¤<°'´'¨9§"´'­"�%�4­'¨É�7­'³_¶1¤/´'­"�%ª1�%©Dª1Çv�/¯ µ �4ª\ª1Ç"�%� �7¶1�%�4¤/­-¦=� �7�%§'ª1�O�%§-�7­µ �%¤�¤/®�¤/®�¶1¤/�%�%ª1¶1�%­'ª"¥%¥%·ÂñIª1«Fª1�%�%§'ª1�4ª"¥%¥%¦��4­^¤/�%³'ª1�\�%¤_ª1­-�7°'�4ªc�%§'�+¥3¯Oª1�%§'¤�³-¦�²�ªL�7�+¥*¤¯M´-¥*�I�%ª1©D²M�%�4�%ªM�%§'ªM�%ª"¥*¤/´'�%¶1ª�°=¤/´'­'³-¥%¦�¥*¤��%§-�7��%§'ª1¬e� �7¹FªM�4­"�%¤<�7¶1¶1¤/´'­"�I�%§'ª6�7�%�%�4Á'¶1�+�7�¶1¤/­'¶1´'�%�%ª1­'¶1�4ª"¥I�4­"�%�%¤�³'´'¶1ª1³V®*¤/�M¶1¤/­"�%�%¤/�4�4ª1³S°=ª1§-�%«"�4¤/� ¥%·

¡3¥���Á'­-�7��%ª"¯3�7�%¹v¦Ö­'¤/�%�4¶1ª\�%§-�7�N¯3�7­"¬^ØI�4¨/§a½�ª1«Fª1�Oî ¬"­"�%§'ª"¥*�+¥Y�%¤�¤/�+¥`´-¥*ªS -¤/­'©�%�%¤/�@¢��7� �SòÖ�4¤ ²óÚ�� � µ §-¥6Ê% M¢�òKÚT¥%Õ6�/¥M�%§'ª1�4�6�4­"�%ª1�%­-�7��¯O¤�³'ª1���7­'³L³'¤b­'¤/�c¯O¤�³'ª1�²�ª1�4��¶1¤/­-¥*�%� �7�4­"� ¥v¶1¤=¯O�4­'¨T®*�%¤=¯Â�4­ µ ´'� ô7¤/´'� µ ´'�`¤ µ ª1� �7�%�4¤/­-¥=²M�4�%§N�%§'ª�ª1Ç"�%ª1�%­-�7�Ö²�¤/�%�4³Ê*ª"· ¨=·4¦¥*¬"­'¶�§'�%¤/­'�4õ"�7�%�4¤/­-¦�¯O�4­-ô/¯3�7ÇS� �7�%ª"¦=×*�4�%�%ª1� ¦=ª1�%¶"·4ÕÉ�7­'³X¤/®*�%ª1­ì¯O¤=¥*�%�4¬S³-�7� �T³'ª1©µ ª1­'³'ª1­'¶1�4ª"¥`�7�%ªM§-�7­'³'�4ª1³-¦�²M§'�4�4ª�¶1¤/­"�%�%¤/���+¥=ª1�4�%§'ª1�I�4¨/­'¤/�%ª1³3¤/��§-�7­'³'�4ª1³N°"¬6¶1¤=¯ µ �4ª1�%ª¶"�/¥*ªX¥ µ �4�4�%�%�4­'¨@öÖ·9¡O�4�%§'¤/´'¨/§L²�ª<´-¥*ªÈ M¢�òKÚT¥6�/¥M�%§'ªQ�4­ µ ´'�V¥ µ ª1¶1�4Á'¶"�7�%�4¤/­»®*¤/�T¤/´'��%¤�¤/�+¦�²�ª<�7³'¤ µ �M�%§'ªQ¯O¤�³'ª1���4­"�%�%¤�³'´'¶1ª1³V°"¬Èä4å7æ+¦"²M§'�4¶�§S�+¥M�7�M�%§'ªQ¥%�/¯Oª��%�+¯Oª�Ì%Û�Ü7÷\â�ÓÊ*°-�/¥*ª1³3¤/­\¶1¤/­'¶1´'�%�%ª1­"�@�7´'�%¤=¯3�7� �/Õ%¦'Ð�øLùÒË*ÐÒÑ�Î�Ê*�4��+¥ µ ¤=¥%¥*�4°'�4ª��%¤�´-¥*ª6¥*¬v¯M°=¤/�4�4¶��%ª µ �%ª1©¥*ª1­"� �7�%�4¤/­N�%ª1¶�§'­'�4¿"´'ª"¥v²M�4�%§Nª1­'§-�7­'¶1ª"¯Oª1­"� ¥�³'ª1�%�4«Fª1³Q®*�%¤=¯ì¶1¤/­'¶1´'�%�%ª1­"��¥ µ ª1¶1�4Á'¶"�7�%�4¤/­¯O¤�³'ª1�+¥%Õ%¦vù�Û�Ñ�Î�ÜúÛ�Ó�Í+Û�Ü7Ë*ÐÒÑ�Î�Ð�ãXÊ*¶1¤/­'³'�4�%�4¤/­cª1«'�7�4´-�7�%�4¤/­L�7­'³L¥ µ ª1¶1´'�+�7�%�4«FªTª1Ç"ª1¶1´'�%�4¤/­»�7�%ª

û\ü'ý ý þDÿ������������ �����ý����� ������� � ����� �%þ������� ÿ����þDÿ�� ��� ����� ��� ���! #"%$'&(�*)���+ ���,����- .�/102� �����43������ ���þDÿ'� + �5��Iÿ�� � ��þ���5����� �6

é

Page 91: BMC’03 - JKUfmv.jku.at/papers/bmc03-preliminary-proceedings.pdfBMC’03 Boulder, Colorado, USA. ... Alessandro Cimatti (IRST, Italy) Raanan Fraer (Intel, Israel) Danny Geist (IBM

7(8:9�;=<'>@? AB8:C:D

EGF@HJIJKML�IONGH:PRQ�S�T�H:E2UVNXWMYRZ�[�\�PR]�^`_(abcGdefahg�i�jVklIJUV]mEGQ�T PRKM]:Q E*I:PR]on@HpT�HJF�T�H:EGHJ]:Q�HJ^qn:rT�H:EGQ�T�KMIJQ�KMUV]mEsUV]tQ�u�HvPRS�Q�U@w!PRQ POEGQ PRQ�HxEGFmPRIJH:[�y{z!E{WMYRZ%|sHBT�HJF�T�H:EGHJ]:Q}K�w~F��MKMIJKMQ��Mr�Q�u�HNGS��M�sEGUV�MS�Q�KMUV]oEGFmPRIJH}n:rhw~H:PR]mE%UVNmQ�u�H,EGQ PRQ�H,EGFmPRIJH}UVN�P~F�T�U'^�S�IJQ2UVN�PRS�Q�U@w!PRQ PVy

� ���(���2�s���s�{�{�� H�PVE�EGSmw~H�Q�u�H�T�H:PR^�HJT%K�E�N�PVw~KM�MK�PRT%|�KMQ�uv���{�{E�\=� z~�oPR]�^v��UVS�]�^�HJ^v�!U'^�HJ���mu�HJI��:�KM]��@y�z!EXPBIJUV]mEGHJ�:S�HJ]�IJHO|sHpn�T�KMHJ��r�T�HJ :KMHJ|¡UV]��MrtQ�u�H�nmPVEGKMIpIJUV]�IJHJF�Q E2|�KMQ�u�KM]`UVS�TPRF�F��MKMI:PRQ�KMUV]vNGT PVw~HJ|sUVT��¢y£�¤�¥§¦ cG¨©�ª�«�a¬ae¢­�®°¯�±�©�a²�cG²4³va±�©�´µ�´�ef´¨cGa²¶ K�EGQ�UVT�KMI:PR�M�Mr�Q�|sU�nmPVEGKMI�PRF�F�T�U@PRI�u�H:E2umP� �HOn@HJHJ]`SmEGHJ^�NGUVTOEGI�u�HJ^�S��MKM]��@· ¶ HJS�T�K�EGQ�KMI:EPR�M�VUVT�KMQ�umw!E(PR]�^�iM]:Q�HJ�VHJT{¸=KM]�H:PRT~¹ºT�UV�VT PVw!w~KM]��@y�k�]!Q�u�H2UV]�H�umPR]�^m\�F�T�KMUVT�KMQ�r:��nmPVEGHJ^u�HJS�T�K�EGQ�KMI�w~HJQ�u�U'^mEXgGH:y �@yM\(WM»V¼RZ�[�I:PR]½PRIJIJU@w!w~U'^mPRQ�H�P� �PRT�KMHJQ�r�UVN�^mPRQ PR��^�U@w~KM]mPRQ�HJ^PR]�^¾IJUV]:Q�T�UV�M��^�U@w~KM]mPRQ�HJ^¿n@HJumP� :KMUVT E�\}�:S�KMI��:�Mr¾L�]�^�KM]��½�VU'U'^ÀEGUV�MS�Q�KMUV]mEpNGUVT���PRT��VHF�T�UVn��MH:w!E�yok�]oQ�u�H,UVQ�u�HJT�umPR]�^m\�Q�u�HJr½w!P�r�N�PRKM��Q�U�L�]�^ÁPR]`UVF�Q�K�w!PR��EGUV�MS�Q�KMUV]oKM]Q�KM�Vu:Q��Mr!IJUV]mEGQ�T PRKM]�HJ^OF�T�UVn��MH:w!E�\�|�u�HJT�H4H:PRT��Mr�F�T�S�]�KM]���^�HJIJK�EGKMUV]mE�w!P�r�HJÂ:IJ�MS�^�H4I:PR]��^�KM^mPRQ�H:EmHJ �HJ]:Q�SmPR�M�MrO�MH:PR^�KM]��BQ�UxEGS�F@HJT�KMUVTXEGUV�MS�Q�KMUV]mE�y2iM]:Q�HJ�VHJTX¸=KM]�H:PRTX¹ºT�UV�VT PVw!w~KM]��w~HJQ�u�U'^mE{gGH:y �@yM\(WMÃRZ�[ÄI:PR]ÅEGUV�M �H�EGI�u�HJ^�S��MKM]��xHJ¢PRIJQ��Mr:y ¶ U |sHJ �HJT \¢Q�u�H�i�¸�¹oIJU@w~F��MHJÂ:�KMQ�r�EGKM�V]�KML�I:PR]:Q��Mr�KM]�IJT�H:PVEGH:E�n:rxIJUV]mEGKM^�HJT�KM]��vIJUV]:Q�T�UV�%IJUV]mEGQ�T PRKM]:Q E�gGKMNG��Q�u�HJ]���HJ��EGHxPR]�^�MU'UVFmE�[�\ÄPR]�^�Q�u:SmE}w!P�r��MH:PR^�Q�UÆS�]mPRIJIJHJF�Q PRn��MHpHJÂ:HJIJS�Q�KMUV]`Q�K�w~H:E�yv�!UVT�HJU  �HJT \#Q�u�HJrIJUV]mEGKM^�HJT{UV]��MrvUV]�HvEGUV�MS�Q�KMUV]ÇPRQ�P�Q�K�w~H:\(PR]�^�u�HJ]�IJHxPRT�H�]�UVQ~FmPRT�Q�KMIJS���PRT��Mr�EGS�KMQ PRn��MHNGUVT�KM]:Q�HJT PRIJQ�KM �HOEGr:]:Q�u�H:EGK�E�y

£�¤G£ ­�®°ÈBd�´�efcGÉ�­�É©�a�µ�Ê'efcG¯�¨�!UVT�HÄT�HJIJHJ]:Q��Mr,WMË�\MYV\ Ì@\M»V»RZºEGr¢w�n@UV�MKMI{w~HJQ�u�U'^mE�umP� �Hsn@HJHJ]}F�T�U  �HJ^�HJÍ@HJIJQ�KM �H�KM]}L�]�^�KM]��HJ¢PRIJQ�EGUV�MS�Q�KMUV]mEÎKM]Æu�KM�Vu��MrOIJUV]mEGQ�T PRKM]�HJ^xF�T�UVn��MH:w¾NGUVT w�S���PRQ�KMUV]mE�y

iM]�WM»V»RZ�\°Q�u�HXPRS�Q�u�UVT E@F�T�UVF@U@EGHXP�EGr¢w�n@UV�MKMI*NGUVT w�S���PRQ�KMUV]!Q�umPRQ*PR�M�MU |XEÄEGF@HJIJS���PRQ�KM �HUVF@HJT PRQ�KMUV]�HJÂ:HJIJS�Q�KMUV]ÏPR]�^�HJ¢PRIJQ}T�H:EGUVS�T�IJHJ��IJUV]mEGQ�T PRKM]�HJ^ÁEGI�u�HJ^�S��MKM]��@y�iM]½WMËV\MYRZ�\¢Q�u�HPRS�Q�u�UVT EmK�w~F�T�U  �HJ^xQ�u�H�F�T�HJ :KMUVSmE2w~HJQ�u�U'^vn:r,F�T�UVF@U@EGKM]���P~]�HJ|ÐHJÑ!IJKMHJ]:Q*HJ]�IJU'^�KM]��Q�UBT�HJ^�S�IJH�HJÂ:HJIJS�Q�KMUV]vQ�K�w~H:y2�mu�K�EmHJ]�IJU'^�KM]��!UV]��MrpKM]�^�KMI:PRQ�H:E�Ò�|�u�HJQ�u�HJT2UVT�]�UVQ�ÓxPR]�^]�UVQ�Ò�|�u�HJ]�Ó½PR]�UVF@HJT PRQ�KMUV]qumPVE~n@HJHJ]¾EGI�u�HJ^�S��MHJ^myÁÔ�KM]mPR�M�Mr:\�W ÌVZ�umPR]�^��MH:E4�MU'UVFmE~KM]�{PRQ PBÔ��MU |¡Õ�T PRF�umE2g��{Ô�Õ}E�[�y

�mu�HJKMT�EGI�u�HJ^�S��MKM]��4Q�HJI�u�]�KM�:S�H�g�PVE=|sHJ�M�#PVE=UVS�T E�[�PVE�EGSmw~H:E%PR]}KM]�F�S�Q�KM]XQ�u�HÄNGUVT w�UVNPp���{Ô�Õ}y=zÖ���{Ô�ÕÁK�E~P{^�KMT�HJIJQ�HJ^ÇPRIJr:IJ�MKMI��VT PRF�ux^�H:EGIJT�KMn�KM]��Æn@UVQ�ux^mPRQ PR����U |×PR]�^IJUV]:Q�T�UV�*^�HJF@HJ]�^�HJ]�IJKMH:EXn@HJQ�|sHJHJ]ÏQ�u�HxUVF@HJT PRQ�KMUV]mE�yØk�F@HJT PRQ�KMUV]Ù]�U'^�H:E,PRT�H�PRQ�U@w~KMIPRIJQ�KMUV]mE*F@UVQ�HJ]:Q�K�PR�M�Mr`T�HJ�:S�KMT�KM]��tQ�u�HÆSmEGHOUVN*umPRT�^�|{PRT�HOT�H:EGUVS�T�IJH:E4NGUVT�UV]�HOUVTxw~UVT�HIJ�MU'I��tIJr:IJ�MH:E�yo�sKMT�HJIJQ�HJ^ÏPRT�I:E2H:EGQ PRn��MK�EGuÁP!�MKM]���n@HJQ�|sHJHJ]oH:PRI�uoUVF@HJT PRQ�KMUV]ÏPR]�^`Q�u�HF�T�HJ^�HJIJH:E�EGUVT E%Q�umPRQ�F�T�U'^�S�IJH{^mPRQ P2T�HJ�:S�KMT�HJ^Æn:rpKMQ ymz×EGUVS�T�IJHpPR]�^hPBEGKM]��tPRT�H�PR^�^�HJ^n@HJNGUVT�H�HJ �HJT�rXUVF@HJT PRQ�KMUV]B|�KMQ�u�UVS�QÎF�T�HJ^�HJIJH:E�EGUVT EsPR]�^xPRNGQ�HJT%HJ �HJT�r�UVF@HJT PRQ�KMUV]B|�KMQ�u�UVS�QEGS�IJIJH:E�EGUVT E�y*�mUV]�^�KMQ�KMUV]mPR�ºn@HJumP� :KMUVT�K�E�EGF@HJIJKML�HJ^Æn:r�w~H:PR]mEmUVN¢NGUVT���PR]�^,ÚGUVKM],]�U'^�H:E�\PR]�^�^�KMT�HJIJQ�HJ^ÏPRT�I:E}PR��EGUxH:EGQ PRn��MK�EGuÏPB�MKM]���n@HJQ�|sHJHJ]oQ�u�H�UVF@HJT PRQ�KMUV]�HJ �PR�MSmPRQ�KM]��xQ�u�HIJUV]�^�KMQ�KMUV],PR]�^�Q�u�H(T�HJ��PRQ�HJ^}NGUVT��¢jRÚGUVKM]{FmPRKMT ysk�F@HJT PRQ�KMUV]mE'Q�umPRQ�PRT�H(]�HJKMQ�u�HJT�IJUV]�]�HJIJQ�HJ^

Y

Page 92: BMC’03 - JKUfmv.jku.at/papers/bmc03-preliminary-proceedings.pdfBMC’03 Boulder, Colorado, USA. ... Alessandro Cimatti (IRST, Italy) Raanan Fraer (Intel, Israel) Danny Geist (IBM

Û(Ü:Ý�Þ=ß'à@á âBÜ:ã:ä

å:æ`ç�è�éMê�ëJìJí�ëJè�îmçRí�ïmð�ñ�òVê!ó�ô�í�ômçRõMõMævëJö:ìJõMôm÷GéMø�ë!è�ô�ë�í�òtç�î�ê�ëJìJëJè�éMñ�ùOúGòVê�ûÆñ�ò'è�ë:ðmçRê�ëìJòVñ�ìJô�ê�ê�ëJñ:í�üÎýþ4ÿ���������� ���� éMùVô�ê�ë��{÷Gï�ò��X÷ÄçRñ!ëJö¢çVó~î�õMë2òVú���� ��� ý��Mñ!îmçRê�í�éMìJô�õ�çRê � éMùVô�ê�ë�����ç��÷Gï�ò��X÷mí�ï�ë4îm÷GëJô�è�ò� �ìJò'è�ë{úGòVê}ç2ìJòVñ�è�éMí�éMòVñmçRõÄ÷Gí çRí�ë:ó~ëJñ:í�çRñ�è � éMùVô�ê�ë!���Gå���í�ï�ë4ìJòVê�ê�ë" ÷Gî@òVñ�è�éMñ�ù#��� ��� ý

else

if (x>0) y = x + 1

y = x − 1

T F

y

x

>

CDFG source

op2 op3

CDFG sink

op1

Fork

Join

Data Dependency

Control Dependency

−+

(a)

(b)

$�%'&)( *)(,+.-!/1032)46587'/:9);�<,=>$ ?:(

@BADCFEHG)IBJ1KBLNM'ODPHQ�R�LNSUTBVXWBSUWY ÷Gì�ï�ëJè�ô�õMéMñ�ùBî�ê�òVå�õMë:ó!ðVòVê�éMùVéMñmçRõMõMæBè�ë:÷GìJê�éMå@ëJèhçV÷sçZ��� ��� ð°ì:çRñpå@ë*í�ê çRñm÷Gõ�çRí�ëJèpéMñ:í�òçRñhçRô�í�ò@ó!çRí�òVñmð�è�ë"[�ñ�ëJèÆå:æ,í�ï�ë4úGòVô�ê\ �í�ô�î�õMë]�_^�`1acb�`ed�fg`ed�hN��ðB��ï�ëJê�ëi^½é�÷mí�ï�ëj[�ñ�éMí�ë:ðñ�òVñ� �ë:ó~î�í�æq÷GëJí�òVú{÷Gí çRí�ë:÷�ð�acb�k�^mln^po¢é�÷sí�ï�ë!í�ê çRñm÷GéMí�éMòVñ�ê�ëJõ�çRí�éMòVñmðÄçRñ�èqd�f2çRñ�èd�hpçRê�ë�ê�ë:÷Gî@ëJìJí�éMø�ëJõMæví�ï�ë,÷GëJí ÷%òVú%éMñ�éMí�é�çRõsçRñ�èr[�ñmçRõ�÷Gí çRí�ë:÷�ý

s ï�ë�ùVëJñ�ëJê�éMìutU �í�ï�òVî@ëJê çRí�éMòVñ�éMñhí�ï�ë���� ��� �GëJö:ìJõMô�è�éMñ�ù�úGòVê�ûqçRñ�èwvGòVéMñ�òVî@ëJê çx í�éMòVñm÷\�¢é�÷�ó~ò'è�ëJõMëJè,å:æ�ç�íy�sò� R÷Gí çRí�ë!çRô�í�ò@ó!çRí�òVñmý>�Mí ÷#í�ê çRñm÷GéMí�éMòVñpê�ëJõ�çRí�éMòVñpé�÷#ëJñ�ìJò'è�ëJè��éMí�ïBëJö¢çRìJí�õMæ�íy�sòiz�ò'òVõMë:çRñBø�çRê�é�çRå�õMë:÷{�|Bf'úGòVê%í�ï�ë�î�ê�ë:÷GëJñ:í4÷Gí çRí�ë}çRñ�è]}�f'úGòVêÎí�ï�ë�ñ�ëJö:í÷Gí çRí�ë8��ðN��éMí�ïví�ï�ë�úGòVõMõMò���éMñ�ù�ó~ë:çRñ�éMñ�ù~k� |Bf����B`�}�f,����k�òVî@ëJê çRí�éMòVñ#t�ïmçV÷(ñ�òVí~å@ëJëJñÙ÷Gì�ï�ëJè�ô�õMëJè�î�ê�ëJø:éMòVôm÷GõMæ�çRñ�è���éMõMõ%ñ�òVíå@ë,÷Gì�ï�ëJè�ô�õMëJè�éMñví�ï�ë�ñ�ëJö:í2ìJæ:ìJõMë:ý

� |Bf:���B`�}�f�����k*òVî@ëJê çRí�éMòVñwt�ïmçV÷�ñ�òVí�å@ëJëJñÅ÷Gì�ï�ëJè�ô�õMëJè`î�ê�ëJø:éMòVôm÷GõMæÙçRñ�èw��éMõMõ(å@ë÷Gì�ï�ëJè�ô�õMëJè�éMñví�ï�ë�ñ�ëJö:í*ìJæ:ìJõMë:ý

� |BfZ���B`�}�fZ����kBòVî@ëJê çRí�éMòVñ�t4ïmçV÷*å@ëJëJñ ÷Gì�ï�ëJè�ô�õMëJèÇî�ê�ëJø:éMòVôm÷GõMæ`å�ô�íBí�ï�ëOê�ë:÷Gô�õMí��éMõMõ#ñ�òBõMòVñ�ùVëJê�å@ëpç�ø�çRéMõ�çRå�õMë{éMñÆí�ï�ë{ñ�ëJö:í2ìJæ:ìJõMë8�=í�ï�é�÷mé�÷%úGòVê�å�éMè�è�ëJñÆéMñ����x��ð¢çV÷��sëJõMõçV÷2éMñoòVô�êÆ÷GòVõMô�í�éMòVñmð%éMñ`òVê�è�ëJê�í�ò�ê�ëJè�ô�ìJëOí�ï�ë�çVó~òVô�ñ:í�òVú�ë"�:ô�éMø�çRõMëJñ:íx÷Gì�ï�ëJè�ô�õMë:÷ùVëJñ�ëJê çRí�ëJèmý

� |Bf6���B`�}�f6����kXòVî@ëJê çRí�éMòVñ�t~ïmçV÷*å@ëJëJñÁ÷Gì�ï�ëJè�ô�õMëJèÇî�ê�ëJø:éMòVôm÷GõMæÏçRñ�èoí�ï�ë,ê�ë:÷Gô�õMíê�ë:ó!çRéMñm÷*ç�ø�çRéMõ�çRå�õMë:ý

s ï�ëXìJò@ó~î�õMëJí�ëv÷Gì�ï�ëJè�ô�õMéMñ�ùOé�÷(í�ï�ë���çRê�í�ë:÷Gé�çRñ�î�ê�ò'è�ô�ìJí*òVúÎí�ï�ëÆçRå@ò ø�ëvçRô�í�ò@ó!çRí ç4ê�ë" ÷Gí�ê�éMìJí�ëJèvå:æ�÷GëJø�ëJê çRõ�ìJòVñm÷Gí�ê çRéMñ:í ÷�ð'ë:çRì�ïvòVñ�ë�ê�ëJî�ê�ë:÷GëJñ:í�éMñ�ùtç~îmçRê�í�éMìJô�õ�çRêXçRõMõMò��sëJèvå@ë" �]���\�������������N�\�)� �B�  "¡1�\�:��� ¢\£Z� ��¤¥�B¢�¢\�)¤¥¡U�)�§¦���¤�£>¡U�.¡1�\�:�'�B¨\©x¤¥�)�ª¤«��¢p��� �'�,¦3�§¬N� �«­®�)�p���~�.����  �¯ �«¡U©x��°��«¡1±�²\¢{¡1��� ��³��g³3�«©�­®�´¨��'��¡1�\�´��¨\¡U�B�>�g¡1�gµ¶¦����'�)�p¢\��¡1�g¡1� �B¢´  ��©.¤¥�B¢���� �'¡U�)¢�¤¥·:­.� ¡1�j¸ ¹�¹�º±

»

Page 93: BMC’03 - JKUfmv.jku.at/papers/bmc03-preliminary-proceedings.pdfBMC’03 Boulder, Colorado, USA. ... Alessandro Cimatti (IRST, Italy) Raanan Fraer (Intel, Israel) Danny Geist (IBM

¼{½8¾3¿�ÀNÁ~Â�ÃX½8Ä8Å

Æ�Ç\È8É�Ê�Ë�ÌÍcήÏÐ~Ñ�Ò{Ó{Ô

ÕÏ Ð Õ Ö Ò Õ Ó�×)ÍcÎNØ�Ù�Ú)ÏÐ~Ñ�Ò{Ó�×�ÍcÎ8ÛgÙ�Ü"ÏÐ~Ñ�Ò{Ó

Ý Æ�Þ!ß´ÊNà�Þ"á�É�â�ã�Çxä�å\Ê~ß!Çxå\Ê�âuà�Þ8æDç"Ë\É�è~Þ"àiè8é�ÍcÎêÞ"â�ç8Çxë�æDä�áyÇxå\Þ8æ>Çxá�á á�Þ"ã~Çxá Þ"ì8Þ"ç"ä�å\É�Ê�âæDÞ"í8ä�Þ"â�ç"Þ8æ.Ê�îjÇiæDé�æDå\Þ8ß!Ì!ï3ä�â�à�Ç�ß´Þ"â8å�Çxá�á�é8ð~É�åjË\Þ"ë�Ë\Þ8æDÞ"â8å�æ6ß�ä�á�å\É�ë�á�ÞXá�Þ"ã~Çxá�Þ"ì8Þ"ç"ä�å\É�Ê�âæDÞ"í8ä�Þ"â�ç"Þ8æ{È8ÉyÇ´â�Ê�â�à�Þ"å\Þ"Ë�ß´É�â�ÉyæDå\É�çZç1Æ�Ê�É�ç"Þ8æ\ð�é3Þ"å�Ç´Ë\Þ8Çxá�Éyß´ë�á�Þ8ß´Þ"â8å�Çxå\É�Ê�âñß�ä�æDåêß!Çxò3Þà�Þ"å\Þ"Ë�ß´É�â�ÉyæDå\É�çpç1Æ�Ê�É�ç"Þ8æ\Ì:ó�î~â�Ê�â�à�Þ"å\Þ"Ë�ß´É�â�ÉyæDå\É�ç´ç1Æ�Ê�É�ç"Þ8æ.ÇxË\Þ�ë�Ë\ä�â�Þ"àuå\Ê6á�Þ8Ç\È3ÞpÊ�â�á�éêÊ�â�Þà�Þ"å\Þ"Ë�ß´É�â�ÉyæDå\É�çuç1Æ�Ê�É�ç"Þ8ð�Ê�Ë6É�îZß�ä�á�å\É�ë�á�Þuç1Æ�Ê�É�ç"Þ8æ�ÇxË\Þ#ß!Çxà�Þ]à�Þ"å\Þ"Ë�ß´É�â�ÉyæDå\É�çiè8é#ç"Ê�â�à�É�ôå\É�Ê�â�æ\ð8å\Æ�Þ"â�Ç´õ�â�É�å\ÞuæDå�Çxå\Þuß!Çxç1Æ�É�â�Þ6ç"Ê�â8å\Ë\Ê�á�á�Þ"Ë�ß!Ç\éiè~Þcà�É�Ë\Þ"ç"å\á�éwæDé8â8å\Æ�Þ8æDÉ�ö"Þ"à�Ì Ý Æ�Þç"Ë\É�å\Þ"Ë\É�Ê�ârä�æDÞ"à÷å\Ê]Þ"á�Éyß´É�â�Çxå\ÞZâ�Ê�â�à�Þ"å\Þ"Ë�ß´É�â�Éyæ\ßøÉyæ§ä�æDä�Çxá�á�é�ß´É�â�Éyß�ä�ß�Þ"ì8Þ"ç"ä�å\É�Ê�â�áyÇxôå\Þ"â�ç"é8Ìúù´ÇxË\ÉyÇxå\É�Ê�â�æjÊ�î´å\Æ�ÉyæcÞ"ì8ÉyæDåuîDÊ�Ë]ç"Ê�â8å\Ë\Ê�á�ô�à�Þ"ë~Þ"â�à�Þ"â8åuè~Þ"Æ�Ç\È8É�Ê�Ë�ð�û�Æ�Þ"Ë\Þ�æDÊ~ß´Þç"Ê�â8å\Ë\Ê�á�ç8Ç�æDÞ8æpß´É�ã�Æ8åpè~Þuß´Ê�Ë\Þ6î\Ç\È3Ê�Ë\Þ"à÷å\Æ�Çxâ�Ê�å\Æ�Þ"Ë�æ\Ì

ü Þ"åpä�æ�è�Ë\É�Þ"ý�é�æDä�ß!ß!ÇxË\É�ö"Þ�Æ�Þ"Ë\Þ�à�Þ"ë~Þ"â�à�Þ"â�ç"éñÇxâ�àrË\Þ8æDÊ�ä�Ë\ç"Þ�ç"Ê�â�æDå\Ë�ÇxÉ�â8å�æ\ð§æDÉ�â�ç"Þå\Æ�Þ"éiû�É�á�á�è~Þ6ä�æDÞ"à÷É�ârå\Æ�ÞiæDÞ"í8ä�Þ"áyþÿ ÍcÎ8Ø�Ù�Ú§Ë\Þ"ë�Ë\Þ8æDÞ"â8å�æ~à�Çxå�Ç{à�Þ"ë~Þ"â�à�Þ"â�ç"É�Þ8æ\ð3ÉyÌ Þ8Ì�ð�É�å�ÉyæHÉ�á�á�Þ"ã~ÇxáNå\Ê!æDç1Æ�Þ"à�ä�á�Þ�Çxâ�Ê�ë~Þ"Ë�Çxå\É�Ê�âû�É�å\ÆñÇjë�Ë\Þ"à�Þ"ç"Þ8æ\æDÊ�Ë´å\Æ�Çxå�Æ�Ç�æ§â�Ê�å�é3Þ"åpè~Þ"Þ"âñæDç1Æ�Þ"à�ä�á�Þ"à�þ

Ð Õ Ò��#Éyæ§É�á�á�Þ"ã~Çxá�îDÊ�Ë�Çxá�á������qà�Çxå�Ç´à�Þ"ë~Þ"â�à�Þ"â�ç"É�Þ8æ´ÏDà�à�Ó

ÍcÎ8Ø�Ù�Ú�ÏÐ~Ñ�Ò{Ó,ÔÕ� �� ���

ÏÐ Õ~Ö Ò���Ó

ÿ ÍcÎ8ÛgÙ�ÜêË\Þ"ë�Ë\Þ8æDÞ"â8å�æ6Ë\Þ8æDÊ�ä�Ë\ç"Þ�ç"Ê�â�æDå\Ë�ÇxÉ�â8å�æ\Ì ü Þ"å]ä�æcÆ�Ç\È3Þ�Ç Ë\Þ8æDÊ�ä�Ë\ç"Þ�æDÞ"åuû�É�å\Æ��Ë\Þ8æDÊ�ä�Ë\ç"Þ8æ,Ê�îpÇcã�É�È3Þ"â#ò8É�â�à ÏDÞ8Ì ã~Ì�ð�ß�ä�á�å\É�ë�á�É�Þ"Ë�æ\ÓjÇ\È�ÇxÉ�áyÇxè�á�Þ8ð§Çxâ�à�ÇuæDÞ"å��iÊ�î�Ê�ë~Þ"Ë�Çxôå\É�Ê�â�æ{ç"Ê~ß´ë~Þ"å\É�â�ãiîDÊ�ËêæDä�ç1ÆúÇcË\Þ8æDÊ�ä�Ë\ç"Þ�æDÞ"å�ÌZó�åpÉyæ{É�á�á�Þ"ã~Çxá�å\Ê æDç1Æ�Þ"à�ä�á�Þ÷ß´Ê�Ë\ÞZå\Æ�Çxâ�´ç"Ê�â�ç"ä�Ë\Ë\Þ"â8åpÊ�ë~Þ"Ë�Çxå\É�Ê�â�æ§îDË\Ê~ß��~Ì

Ï Ð Õ Ò Õ ×�������× Ð��xÒ���Ó§û�É�å\Æ�� ����������� �]Éyæ§É�á�á�Þ"ã~Çxá�É�î"!#� ����������!%$&�

ü Þ"å('*)ªÏÐ Ó{è~Þ�å\Æ�ÞêÉ�â�É�å\ÉyÇxá:æDå�Çxå\Þ�Ê�î{å\Æ�ÞræDç1Æ�Þ"à�ä�á�É�â�ãrë�Ë\ÊNà�ä�ç"å!Çxä�å\Ê~ß!Çxå\Ê�â�ðHÉ�â#û�Æ�É�ç1Æâ�Ê�Ê�ë~Þ"Ë�Çxå\É�Ê�âiÆ�Ç�æ�è~Þ"Þ"â�æDç1Æ�Þ"à�ä�á�Þ"à�Ì Ý Æ�Þ]æDÞ"å>Ê�î�æDå�Çxå\Þ8æ�Ë\Þ8Çxç1Æ�Çxè�á�Þ]Çxå.å\Æ�Þ��Uô�å\Æiç"á�ÊNç1òç"é8ç"á�Þ ß!Ç\éiè~Þ6ç"Ê~ß´ë�ä�å\Þ"à÷è8éwÇ!æDå�Çxâ�à�ÇxË\àrÉ�å\Þ"Ë�Çxå\É�È3ÞZÉyß!Çxã�Þ6ç"Ê~ß´ë�ä�å�Çxå\É�Ê�â�þ

' Õ ÏÒ{Ó:Ô,+.-0/®ÏyÍcήÑ�' Õ21�3 Ó:Ô543Ú76 ÍcÎ~ÏÐ~Ñ�Ò{Ó�×�' Õ21�3 ÏÐ Ó98Ï;:�Ó

ù´Çxá�É�àñæDç1Æ�Þ"à�ä�á�Þ8æjÇxË\ÞZË\Þ"ë�Ë\Þ8æDÞ"â8å\Þ"à#è8é�æDå�Çxå\ÞZë�Çxå\Æ�æ§å\Æ�ÇxåpË\Þ8Çxç1Æ�Çjõ�â�Çxá.æDÞ"åpÊ�î:æDå�Çxå\Þ8æÉ�â�û�Æ�É�ç1Æ÷å\Þ"Ë�ß´É�â�Çxá�Ê�ë~Þ"Ë�Çxå\É�Ê�â�æ�Æ�Ç\È3ÞZè~Þ"Þ"â�æDç1Æ�Þ"à�ä�á�Þ"à�Ì

Ý Æ�Þ�Þ"ì8ë�á�Ê�Ë�Çxå\É�Ê�â å\Þ"ç1Æ�â�É�í8ä�Þ8æ]ë�Ë\Þ8æDÞ"â8å\Þ"à Æ�Þ"Ë\Þ ÇxË\Þwà�É�Ë\Þ"ç"å\Þ"à è8éøÇúß´É�â�Éyß�ä�ßáyÇxå\Þ"â�ç"éXÊ�è�<DÞ"ç"å\É�È3Þ8Ì Ý Æ�Þ"é!à�Þ"å\Þ"Ë�ß´É�â�Þpû�Æ�Þ"å\Æ�Þ"Ë�ð�ã�É�È3Þ"â Çxá�áHç"Ê�â�æDå\Ë�ÇxÉ�â8å�æ�Éyß´ë~Ê~æDÞ"à Çxâ�àÇrå�ÇxË\ã�Þ"å áyÇxå\Þ"â�ç"é>=DðZÇ÷È�Çxá�É�àqÞ"ì8Þ"ç"ä�å\É�Ê�â æDÞ"í8ä�Þ"â�ç"Þ�Ê�î6á�Þ"â�ã�å\Æ5?@=>Þ"ì8ÉyæDå�æ\ÌBA É�å\Æç"Ê�â8å\Ë\Ê�á�ô�à�Þ"ë~Þ"â�à�Þ"â8å!ß´ÊNà�Þ"áyæ\ð§æDÊ~ß´Þ�Çxà�à�É�å\É�Ê�â�Çxá�È�Çxá�É�à�É�åyé�ç"Ë\É�å\Þ"Ë\ÉyÇuÇxË\Þ�Éyß´ë~Ê~æDÞ"à�ð�Çxâ�àæDë~Þ"ç"ä�áyÇxå\É�È3ÞpÞ"ì8Þ"ç"ä�å\É�Ê�â#ß!Ç\érÇxá�á�Ê�û æDÊ~ß´Þ:Ê�ë~Þ"Ë�Çxå\É�Ê�â�æ{ÇxîDå\Þ"Ë´Ç�îDÊ�Ë\ò�Çxâ�à!è~Þ"îDÊ�Ë\Þ�ÇC<DÊ�É�âå\Ê!è~ÞiæDç1Æ�Þ"à�ä�á�Þ"à�è~Þ"îDÊ�Ë\Þcå\Æ�Þ6ç"Ê�â�à�É�å\É�Ê�â÷Þ"È�Çxá�ä�Çxå\É�Ê�â�Æ�Ç�æ§è~Þ"Þ"â�æDç1Æ�Þ"à�ä�á�Þ"à�Ì

D

Page 94: BMC’03 - JKUfmv.jku.at/papers/bmc03-preliminary-proceedings.pdfBMC’03 Boulder, Colorado, USA. ... Alessandro Cimatti (IRST, Italy) Raanan Fraer (Intel, Israel) Danny Geist (IBM

EGF.HJILK*MON7PQF.R.S

T UWVGXZYZ[]\]XZ^`_baCX"c*deaC[�YZfhgifhXZYZfhXZ_bfWc*jZdeaCkZ^Cjl_baCXZ_bkZdedefhXZ_bm

nGo�p�q�rJs0t;u�swv9qyx{z�p�s}|Q~.��v9s���������t7�����7�&��|7��z�u�v;������q�t;o�s.v;vQv9~�u�s}����p�s �9��|�~}��o.t;|;��p����s}zOs}o���s}o.t�x{�*��s}pyv�qyv�o���ti�(v9q�o���p�s�z���t;u�q�o���z���t;u�v9s}t%����t%|7��t;u�s}|i�(v9s}t%����z���t;u�v�9|;�Ox�v9t7��|;tZt;����o���p%v9t7��t;s.v;�(�7��~�u��0v9s}tZ���Gz���t;u�vCqyv�~.��p�p�s}����o����e�����Q �¡¢�(��£�¤���¥�¦*¡¢�q�o�§�¨�©"��o���x���v9tZq�o�~}p�����sª��z���t;u«�9��|�s.��~�u«��qyv9t;q�o�~}t¬~}��o.t;|;��p��­��s}zOs}o���s}o.t¬s}®.s}~}��t;q���ov9s}¯.��s}o�~}s.�`°J��|�q�o�v9t7��o�~}s.����±%²y��³>z�|;�*~}s.v;v9��|´x���v9t �Osµ����p�s¶t;��s}®.s}~}��t;s���p�p{q�o��v9t;|;��~}t;q���o�v���o��«t;u�s}|;s}�9��|;s���o¶s}o�v9s.x���p�s¶v9~�u�s}����p�s��9��|���±%²y��³�z�|;�*~}s.v;v9��|�~}��o.t7��q�o�vv9s}¯.��s}o�~}s.v{�9��|�s}·Js}|;¸¹q�o�v9t;|;��~}t;q���o���º�vi�¶x{��|;swv9zOs}~}q���~0s}®���x{z�p�s.��~}��o�v9q���s}|�v9�Ox{s~}��o.t;|;��p��­��s}zOs}o���s}o.t��Os}u��;·.q���|{t;u���t%��|7��o�~�u�s.v�q�o.t;��ty�C�wv9s}t7vG�����Os}u��;·.q���|7v���s}zOs}o����q�o�����o¹�{t;|;��s.»��;��pyv9s¬~}��o.t;|;��pb|;s.v9��p���t;q���o���º{o�s}o�v9s.x���p�s v9~�u�s}����p�s��9��|�t;u�qyv�s}®���x{z�p�sx���v9t"~}��o.t7��q�o��{z���t;u��9|;�OxWt;u�s�v9t7��|;t�v9t7��t;s¬t;��t;u�s¬��o���pb��o�sZt;u���t"|;s}z�|;s.v9s}o.t7vGs}®.s}�~}��t;q���o�����t;|;��s¬~}��o.t;|;��pb|;s.v9��p���t;q���oª�Os}u��;·.q���|7�h��o�����o���t;u�s}|"z���t;u�t;u���t"~}�7·Js}|7vG�;��pyv9s~}��o.t;|;��p�|;s.v9��p���t;q���oª�Os}u��;·.q���|7�²�ow¼�½Z½C�­����v9s}���9��|7x���py��t;q���o���t;u�qyvh|;s}¯.��q�|;s.v�t;u�s{q�o.t;|;�*����~}t;q���o0���b~}��o.t;|;��pO������|;�

·���|;qy����p�s.v;�¾|;s}z�|;s.v9s}o.t;q�o���o���o��­��s}t;s}|7x{q�o�qyv9t;q�~"~�u���q�~}s.v¿���es.��~�u�~}��o.t;|;��p�p�q�o��Z��zOs}|7��t;q���o��º�������|;�Àqyv0�ª��q�o���|;¸�����v9t;|7��~}t;q���oÀ����t;u�s«����t7��·���p���sÁ~}��o.t;|;��p�p�q�o��Â����|7��o�~�u�q�o��~}��o���q�t;q���o��¹ºÄí~}�Ox{z�p�s}t;s}o�s.v;v9Å�~�u�s}~�rÂÆ9qy� s.������p�p�������|;�µ·���p���s.v�u��;·Js�|;s.��~�u�s}��t;u�st;s}|7x{q�o���pÇv9t7��t;s.È�qyv"������s}��t;��t;s}|7x{q�o���t;q���o�~}��o���q�t;q���o�v;�°J��|;t;u�s}|7x{��|;s.����·���p�q�����t;q���oÀz�|;�*~}s}����|;sÁ��zOs}|7��t;s.v ������~�r.�Z��|;�Éz�|;��o�q�o����7·Js}|

t;u�s¹v9t7��t;s�v9s}t7v�~}�Ox{z���t;s}���.¸��9��|;�Z��|;�W¼�°�����Ê{��p�q�����t;q���oµqyv�t;u�s�x{�Ov9t�s}®.zOs}o�v9q�·Jsv9¸�x��O��p�q�~ª��zOs}|7��t;q���oW��o��µt;u�s�x���q�o�~.����v9s��9��|¶¼�½Z½Ë��p��7���­��z��²�t�~}��o�v9qyv9t7v¬���Q�z�|;s}qyx�����sª|;����t;q�o�s¶��q�t;u���o�q�·Js}|7v;��p�¯.����o.t;q���~.��t;q���o����Z~}��o.t;|;��p{������|;��v���t�~}��o.t;|;��p|;s.v9��p���t;q���o�zO��q�o.t7v;�%Ì�u�qyv�qyv�o�s}~}s.v;v;��|;¸ t;��s}o��9��|;~}s�~.����v;��p�q�ty¸´Æ9q���s}o.t;q�~.��phq�o�q�t;qy��pÇv9�����z���t;u�È��9��|�����t;����q�o���z���t;u�v"��t"�9��|;r�zO��q�o.t7v;�º{z���|;tQ�9|;�OxÍ~}�Ox{z�p�s}®.q�ty¸�qyv;v9��s.v;����|7��o�~�u�q�o���v9~�u�s}����p�s.v���o��µt;u�s0|;s}py��t;s}�µ·���p�q��

����t;q���o�v9t;s}z�v���|;s¶��x��7Î9��|¬z�|;����p�s.x&�9��|����7º{Ì��­����v9s}�¹�9��|7x���py��t;q���o���²�o´��|;��s}|�t;��;·J��q��(t;u�s.x��J�Cs"q�o.t;s}|;z�|;s}tC~�u���q�~}s%·Js}|;t;q�~}s.vC��v¿~}��o�~}��|;|;s}o.t��9��|;r�v;�Ï��o��(�Cs"t;|7��o�v9�9��|7x��p�t;s}|;o���t;q�·Js¬��|7��o�~�u�s.vGq�o.t;��~}��o�~}��|;|;s}o.t%z���t;u�v;��7�0�Cs�|;s.x{�7·Js��9��|;r���o��«Î9��q�o«o��*��s.vÇ�9|;�OxËt;u�sª³�½Z°hÐ�����o��«�Cs�|;s}z�py��~}sQt;u�s.x

��q�t;u(��o�~}��o���q�t;q���o�s}������t7�Ç��s}zOs}o���s}o�~}q�s.v;��º�vC��|;s.v9��p�t7�O�¬³�½Z°hе�Os}~}�Ox{s.vC��½Z°hÐ����o����7º{Ì�~.��ows}®.z�p���|;s«v9qyx���p�t7��o�s}����v9p�¸���p�pG~}��o���q�t;q���o���pG��|7��o�~�u�s.v����Ct;u�s(��|;q���q�o���p³�½Z°hÐ��°Ïq�����|;s«Ñ�v9u��7��v"t;u�s«���O�7·Js�t;|7��o�v9�9��|7x���t;q���oÀ��z�z�p�q�s}�´t;�ªt;u�s(s}®���x{z�p�s����¬°Ïq����

��|;s�ÒJ�°J��|;r ��o��(Î9��q�o�u��;·Js%�Os}s}o(|;s.x{�7·Js}����~}��o.t;|;��p���s}zOs}o���s}o�~}¸¶x���q�o.t7��q�o�s}�ÁÆ;��v¿����t7�

��s}zOs}o���s}o�~}¸�È��9��|¬t;u�s���zOs}|7��t;q���o�v�Ó;Ô�¡9¡¢Ô�ÕGÖ9�e×�Ø2¤���Ù;Ô�Ö9�¹ÚÛ��£�Ô��Q �Ö9�eÜ�Ø2Ö9Ô��e� Ì�u�s}|;s}�9��|;s.�q�o(����|�v9��p���t;q���o(Î9��q�o�v��C��|;rª��v�v9¸.o�~�u�|;��o�q�Ý.��t;q���o�zO��q�o.t7v;�O��v¿o�����zOs}|7��t;q���o(�9��p�p��7��q�o���{Î9��q�o qyv"��p�p��7�Cs}��t;���Os¬s}®.s}~}��t;s}�ªq����O��t;u t;u�s¬��|7��o�~�u�s.v�����t;u�s¬~}��o.t;|;��p�|;s.v9��p���t;q���ou��;·Js«o���t��Os}s}oÀ~}�Ox{z�p�s}t;s}�À¸Js}t7�ÞÌ�u�qyv�x{s.��o�v�t;u���t�����|Áx{�*��s}p{���*s.v¬o���tw��p�p��7�~}��o.t;|;��p�z�|;q���|;q�t;q�Ý.��t;q���oWÆ;��v��Cs���p��Z�;¸�v�u��;·Jsªt;u�s �C��|7v9t(��s}py�;¸�È;������t(�Cs�u��;·Js�o��p��Ov;v�q���t;u�s{����Î9s}~}t;q�·Js�qyvCx{q�o�qyx{q�Ý}q�o��it;u�s{�C��|7v9tÇ~.��v9s{s}®.s}~}��t;q���o�py��t;s}o�~}¸.�"ß���|;s}�7·Js}|7�v9q�o�~}s��Cs¬|;s.x{�7·Js�t;u�s¬��s}zOs}o���s}o�~}¸���t��9��|;r�v;�bv9zOs}~}��py��t;q���oªqyv"v9t;q�p�pÇ��p�p��7�Cs}���

à

Page 95: BMC’03 - JKUfmv.jku.at/papers/bmc03-preliminary-proceedings.pdfBMC’03 Boulder, Colorado, USA. ... Alessandro Cimatti (IRST, Italy) Raanan Fraer (Intel, Israel) Danny Geist (IBM

áGâ.ãJäLå*æOç7èQâ.é.ê

else

if (x>0) y = x + 1

y = x − 1

y

x

>

CDFG source

op2 op3

CDFG sink

op1

Data Dependency

−+

Control Dependency(a)

(b)

ë�ì¢í�îOï�î�ð�ñ�ò�ëÏóÉô�õ#öy÷�øCõ#ù�øÛúJû]üÛù�ì¢ý�øÛ÷�þ¬ù ÿ}ô��¢î

� �������� � ����������� ���������� ������� �������������� ���������

"!$#&%�')()*,+$-.*/%�01324')5�-.246$-.7$')')#.6$-.*,#98;:�#<!"%)=>#?*,69()')2�@$7$-.#.@A!"%)=>#?6$2B83*,@$#.CD#.EF#.-.(G*,6()!$#H-9%483#I241J83-K!$#.@$7$0,*,6$LM:N*,()!�7$69OF247$6$@$#.@�')#983247$')-.#98)PRQ,6S1)%�-.(UTVL4*,=>#.6W%�69XY83#.(Z241-.246$-.7$')')#.69([24\F#.'U%�()*,246"8)T]*,1%_^D0/%�')L4#;#.6$247$L4!$`a83#.(b241�')#983247$')-.#98N-9%�6<OF#c%�0,0,2�-9%�()#.@"T%�0,0d24\F#.'U%�()*,246"8�eZ%)X?%�0,:%)Xd8fOF#b#.g9#.-.7$()#.@"P "!$#N-9%483#N241hOF247$6$@$#.@Z')#983247$')-.#98]*/8h0,#98)8]()')*,=9*/%�0/PiQ,6Z()!$*/8F-9%483#N6$24(j%�0,0�-.246$-.7$')')#.69(

#.g9#.-.7$()*,246"8�%�')#k^D')#9%�0,`l-.246$-.7$')')#.6$-.*,#98)TF83*,6$-.#[832Fem#N241$()!$#9en%�')#po37"83(�%�')()*,+$-.*/%�0/P�qZ8V%-.246"83#.r97$#.6$-.#9T 6$24(J%�0,0�-.246$-.7$')')#.69(j24\F#.'U%�()*,246"8j%�')#b-.2Fem\F#.()*,6$Ls1324'�')#983247$')-.#98)PtqZ8�%@$*,')#.-.(j247$()-.2Fem#9T$:�#u6$#.#.@c()2<em2�@$*,13XH')#983247$')-.#u-.246"83()'U%�*,69(U8)T ()2v(U%�5>#[*,69()2<%�-.-.247$69(()!"%�(w832Fem#x24\F#.'U%�()*,246"8l-.247$0,@&OF#a%�0,0,2�-9%�()#.@�()2M()!$#a8)%4em#x')#983247$')-.#�%�(s()!$#a8)%4em##.g9#.-.7$()*,246x()*/em#9P

yZ24')#z83\F#.-.*,+$-9%�0,0,X9Tm0,#.(G7"8J:�24')5z246{%�|N}~���:N*,()!{%�83#.(G241G��24\F#.'U%�()*,246"8�N�_�������F�����,�,�,�������l� T�#9%�-K!_246$#weZ%�\$\F#.@_()2S�3*/P #9P,T�#.g9#.-.7$(U%�O$0,#kO9X&%;')#983247$')-.#k241��%;')#983247$')-.#H-.0/%48)8�:N*,()!$*,6a()!$#<83#.(x� �����������,�,�,�����I� PM "!$#kL4#.6$#.')*,-k')#983247$')-.#k-.0/%48)8��� */8f-K!"%�'U%�-.()#.')*,�.#.@wO9X_%lOF247$6$@c������T�')#.\$')#983#.69()*,6$LH()!$#I%4em247$69(j241V24\F#.'U%�()*,246x7$6$*,(%)=$%�*,0/%�O$0,#Z1324'()!"%�(-.0/%48)8)T�:N!$#.')#9%48N�d����*/8i()!$#s()24(U%�0f697"eNOF#.'[241�24\F#.'U%�()*,246"8i*,6 �N�eZ%�\$\F#.@S()2<()!$# ��� ')#983247$')-.#I-.0/%48)8)P& "!$#I')#983247$')-.#IOF247$6$@S\$')24O$0,#9e�*/8j24O9=9*,247"830,X()')*,=9*/%�0�1324'j-.0/%48)8 ��� *,1��d���f z������T�83*,6$-.#J()!$#.')#u-9%�6c6$#.=>#.'lOF#H%')#.r97$#983(241V')#983247$')-.#98L4')#9%�()#.'N()!"%�6G()!$#k%)=$%�*,0/%�O$0,#b246$#98��)%48V1324'N()!$#b-9%483#b241"*,6$+$6$*,()#[')#983247$')-.#98)�)Pq¡eN7$-K!Sem24')#[-K!"%�0,0,#.6$L4*,6$Lv\$')24O$0,#9e�*/8f()!$#b-9%483#[241V')#983247$')-.#[OF247$6$@"8j%�-.()7"%�0,0,X

')#.@$7$-.*,6$L;()!$#v%4em247$69(p241�\F2F8)83*,O$0,#-.246$-.7$')')#.6$-.*,#98)Pm¢�#.( ����� %�6$@ ����£ OF#l(/:�2;24\F#.'U%�C()*,246"8leZ%�\$\F#.@w()2k()!$#G8)%4em#J')#983247$')-.#;-.0/%48)8)Tf83-K!$#.@$7$0,#.@M1324'm-.246$-.7$')')#.69(#.g9#.-.7$()*,246�3()!$#.')#s*/8[%G83(U%�()#s()'U%�6"83*,()*,246?:N!$#.')# ��� � � ��£ � £ !$240,@"8)�)Pc "!$#.6"T�')#983247$')-.#<%�0,0,2�-9%�()*,246eZ%)Xk1)%�0,0d*,6G246$#b241"()!$#b13240,0,2U:N*,6$Ls()!$')#.#b-9%483#98)¤¥_¦ 6$-.246$@$*,()*,246$#[email protected]$-.7$')')#.6$-.X9Pb "!$#[(/:�2v24\F#.'U%�()*,246"8f@$2v6$24(�OF#.0,246$Lv()2s@$*,EF#.')#.69(-.246$@$*,()*,246"%�0]O$'U%�6$-K!$#98"*,6k()!$#l24')*,L4*,6"%�0�|N}~��[Th832;()!$#.*,'p-.246$-.7$')')#.6$-.Xv*/8p%G^D')#9%�0,`246$#9T�')#.r97$*,')*,6$Lv()!$#k%�0,0,2�-9%�()*,246I241"(/:�2s')#983247$')-.#98)P

¥ yZ7$()7"%�0d#.g9-.0,7"83*,246"Pj "!$#(/:�2Z24\F#.'U%�()*,246"8p%�')#l-.2469()')240,0,#.@IO9X?eN7$()7"%�0,0,Xv#.g9-.0,7"83*,=>#-.246$@$*,()*,246"8)T]*/P #9P,TF()!$#.XS%�')#J246<@$*,EF#.')#.69(O$'U%�6$-K!$#98i241l832Fem#Z1324')5G*,6<()!$#;24')*,L4*,6"%�0|N}~��[Pd "!$#.*,'j-.246$-.7$')')#.6$-.#[*/8�%�')()*,+$-.*/%�0/T�832so37"83(�246$#b')#983247$')-.#[*/8V')#.r97$*,')#.@"P

§

Page 96: BMC’03 - JKUfmv.jku.at/papers/bmc03-preliminary-proceedings.pdfBMC’03 Boulder, Colorado, USA. ... Alessandro Cimatti (IRST, Italy) Raanan Fraer (Intel, Israel) Danny Geist (IBM

¨�©9ª>«�¬�­F®U¯;©9°9±

²_³U´Fµ.¶.·$¸/¹�º)»,¼>µxµ.½9µ.¶.·$º)»,¾4¿"ÀY³U´Fµ.¶.·$¸/¹�º)»,¾4¿�¾�¶.¶.·$ÁUÂlÃNÄ$µ.¿$µ.¼>µ.Á<¹�¿S¾4´Fµ.ÁU¹�º)»,¾4¿S»/Âlµ.½9µ.Ŷ.·$º)µ.ÆaÇFµ.È3¾4Á)µv»,ºUÂN¶.¾4¿9º)Á)¾4¸,¸,»,¿$Éw¶.¾4¿$Æ$»,º)»,¾4¿_»/Â�Á)µ9Â3¾4¸,¼>µ.Æ"À_Ê,È�Ë�Ì�Íl¹�¿$ÆaË�Ì�Îs¹�Á)µvÇF¾4º)ĵ.½9µ.¶.·$º)µ.ÆkÇFµ.È3¾4Á)µNº)Ä$µ.»,ÁtÆ$»/Â3º)»,¿$É4·$»/Â3Ä$»,¿$ÉJ¶.¾4¿$Æ$»,º)»,¾4¿s»/Â]Ï9¿$¾UÃN¿"Ð4¶.¾4¿$¶.·$Á)Á)µ.¿$¶.µj»/Â]Á)µ9¹�¸/й�¿$ÆGº/Ã�¾sÁ)µ9Â3¾4·$Á)¶.µ9Âj¹�Á)µbÁ)µ.Ñ9·$»,Á)µ.Æ"ÀÊ,¿<¾4º)Ä$µ.ÁÃ�¾4Á)Æ"Â)Ð]Ã�µcÒZ¹)ÓcÄ"¹)¼>µZ¶.¾4·$´$¸,µZ¾4Èt¾4´Fµ.ÁU¹�º)»,¾4¿"Â�È3¾4ÁÃNÄ$»,¶KÄ?¶.¾4¿$¶.·$Á)Á)µ.¿$¶.Ó

Òm»,É4Ä9ºmÇFµu·$¿$¶.¾4¿$Æ$»,º)»,¾4¿$µ.Æ�Ô3Õ$ÁUÂ3ºm»,º)µ9ÒÖ»,¿cº)Ä$µG¹�ÇF¾U¼>µu¸,»/Â3ºU×)ÐV¹�¿$Æc¾4º)Ä$µ.Ám¾4¿$µ9Â�¶KÄ"¹�ÁU¹�¶.ź)µ.Á)»,Ø.µ.ÆGÇ9ÓH¶.¾4¿$Æ$»,º)»,¾4¿$µ.ÆG¶.¾4¿$¶.·$Á)Á)µ.¿$¶.Ó_Ô)Â3µ.¶.¾4¿$ÆS¹�¿$ÆGº)Ä$»,Á)ÆG»,º)µ9ÒZ×)À

Ù�Ú)ÛÝÜtÞ�ßKà�á�â�ãKÞJäKà�á�å æ�ßç�è3é�ê�è3åcé�ê�Þ;ë ìmíSßKà�îðï�Þ�âñ µ9Â3¾4·$Á)¶.µbÇF¾4·$¿$Æ"ÂV¶9¹�¿IÇFµv¹�¶.¶.¾4·$¿9º)µ.ÆxÈ3¾4ÁpÆ$»,Á)µ.¶.º)¸,ÓHÇ9Ó?¹Z³UòmóYÂ3¾4¸,¼>µ.ÁUÀjÊ,¿Iº)Ä$»/Â�Â3¾4¸,·$ź)»,¾4¿Jº)Ä$µ[³UòmóSÂ3¾4¸,¼>µ.ÁfÄ"¹4Âhº)¾lÇFµp´$Á)¾4´Fµ.Á)¸,ÓHÒm¾�Æ$»,Õ$µ.Æ;»,¿;¾4Á)Æ$µ.ÁVº)¾l¶.¾4·$¿9ºfº)Ä$µ[¹�¸,¸,¾�¶9¹�º)µ.ÆÁ)µ9Â3¾4·$Á)¶.µ9Â�ÃNÄ$»,¸,µtÁ)µ.¶.·$ÁUÂ3»,¼>µ.¸,ÓbÇ$·$»,¸,Æ$»,¿$ÉJ¹�Â3¶KÄ$µ.Æ$·$¸,»,¿$ÉZÂ3¾4¸,·$º)»,¾4¿"À�ó"Ä$»/Â�»/Â�¹�Â3´Fµ.¶.»/¹�¸4´$·$Á)Å´F¾FÂ3µxÂ3¾4¸,·$º)»,¾4¿<º)¾HÈ3¾4¸,¸,¾UÃn¾4¿$¸,Óx»,¿wº)Ä$µ;¶9¹4Â3µZº)Ä$µ;É4µ.¿$µ.ÁU¹�º)µ.Æ<¾U¼>µ.Á)Ä$µ9¹�Æ?»/Â�¿$µ.É4¸,»,É4»,Ç$¸,µ9ÀÊ,ºÇ"¹4Â3»,¶9¹�¸,¸,Ó<Á)µ.¸,»,µ9Âp¾4¿<»,Æ$µ.¿9º)»,È3Ó9»,¿$ÉS¹�¶.º)»,¼>µv¾4´Fµ.ÁU¹�º)»,¾4¿"Â�º)Ä$Á)¾4·$É4Ä?¼$¹�Á)»/¹�Ç$¸,µZÆ$µ.¶.»/Â3»,¾4¿"¹�¿$Æu»/Òm´$¸,»,¶9¹�º)»,¾4¿"Â)Ð ¹�¿$ÆuÏ>µ.µ.´$»,¿$ÉÁ)µ9Â3¾4·$Á)¶.µ[¹�¸,¸,¾�¶9¹�º)»,¾4¿u¶.¾4·$¿9º)µ.ÁUÂ)À�ò�Á)µ9Â3¾4·$Á)¶.µi¶.¾4¿$ô$»,¶.º¾�¶.¶.·$ÁUÂVÃNÄ$µ.¿$µ.¼>µ.ÁZ¹�¿a¹�¸,¸,¾�¶9¹�º)»,¾4¿I¶.¾4·$¿9º)µ.Á�»/ÂVÉ4Á)µ9¹�º)µ.Á�º)Ä"¹�¿Iº)Ä$µk¹�¸,¸,¾UÃ�µ.ÆxÇF¾4·$¿$Æ"À

Ù�Ú3õöÜtÞ�ßKà�á�â�ãKÞJäKà�á�å æ�ß÷�ßl÷Høpà�à�îðÞK÷�åxãKà�å ßKé�â�÷�è3å éòm¸,º)Ä$¾4·$É4Äzº)Ä$µ�¹�ÇF¾U¼>µ�Â3¾4¸,·$º)»,¾4¿z»/Â[È3µ9¹4Â3»,Ç$¸,µ9ÐpÃ�µw´$Á)µ.È3µ.Ákµ.½9´$¸,¾4Á)»,¿$ÉA¹�¿Ö¹�¸,º)µ.Á)¿"¹�º)»,¼>µ¾4¿$µ9Ð�º)Ä"¹�º[»/Â�¶.¾FÒm´"¹�º)»,Ç$¸,µkÃN»,º)ÄY¹ZÉ4µ.¿$µ.Á)»,¶?³UòmóùÂ3¾4¸,¼>µ.ÁUÐNÂ3»,¿$¶.µH¿$¾SÒm¾�Æ$»,Õ$¶9¹�º)»,¾4¿aº)¾º)Ä$µ_³Uòmóú¹�¸,É4¾4Á)»,º)Ä"Ò�»/Âm¿$µ.¶.µ9Â)Â)¹�Á)Ó9ÀSû?µ_Â3»/Òm´$¸,ÓaÈ3¾4¸,¸,¾UÃýüpþþ�ÅDÇ"¹4Â3µ.ÆW¹�´$´$Á)¾F¹�¶KÄ$µ9Â)ÐÇ9ÓIÉ4µ.¿$µ.ÁU¹�º)»,¿$É?¹Á)µ9Â3¾4·$Á)¶.µJ¶.¾4¿"Â3º)ÁU¹�»,¿9ºlÈ3¾4Ájº)Ä$µuº)ÁU¹�¿"Â3»,º)»,¾4¿cÁ)µ.¸/¹�º)»,¾4¿�Ô/ÿ��������.×)Ð$ÃNÄ$»,¶KÄÕ$¸,º)µ.ÁUÂV¾4·$º�»,¿9¼$¹�¸,»,ÆaÂ3µ.ºUÂf¾4È"¶.¾4¿$¶.·$Á)Á)µ.¿9ºjµ.½9µ.¶.·$º)»,¾4¿"Â)À

ó"Ä$µ.Á)µM¹�Á)µH¼$¹�Á)»,¾4·"ÂJÂ3º)ÁU¹�º)µ.É4»,µ9ÂmÈ3¾4ÁJÇ$·$»,¸,Æ$»,¿$É&Â3·$¶KÄW¹s¶.¾4¿"Â3º)ÁU¹�»,¿9ºx¹4ÂJ¹wü�¾�¾4¸,µ9¹�¿È3·$¿$¶.º)»,¾4¿GÁ)µ.º)·$Á)¿$»,¿$Ésº)Á)·$µb¾4¿_¹�¸,¸,¾UÃ�µ.ÆSÂ3µ.ºUÂf¾4È"¾4´Fµ.ÁU¹�º)»,¾4¿Iµ.½9µ.¶.·$º)»,¾4¿"Â)À

Ù�Ú3õ�Ú)Û�"îðè��á�Þ�ßà �jãKà�å ã�á�â�â�Þ�å ã�����â�÷ �]êò Â3º)ÁU¹�»,É4Ä9º)È3¾4Á)ù�Á)Æ{¹�´$´$Á)¾F¹�¶KÄAÃ�¾4Á)ÏdÂ;¾4¿Aº)Ä$µ?É4ÁU¹�´$ÄY¾4ÈJ´F¾FÂ)Â3»,Ç$¸,µM¶.¾4¿$¶.·$Á)Á)µ.¿$¶.»,µ9Â)ÐÃNÄ$µ.Á)µ�¾4´Fµ.ÁU¹�º)»,¾4¿"Â�¹�Á)µ�¿$¾�Æ$µ9Ât¹�¿$ÆZµ.Æ$É4µ9Â]¶.¾4¿$¿$µ.¶.º�´"¹�»,Á)ÃN»/Â3µ�¶.¾4¿$¶.·$Á)Á)µ.¿9º�¾4´Fµ.ÁU¹�º)»,¾4¿"Â)À³U·$¶KÄ<¹iÉ4ÁU¹�´$Äs¶9¹�¿sÇFµ�É4µ.¿$µ.ÁU¹�º)µ.Æ<¹4Â]º)Ä$µ�º)ÁU¹�¿"Â3»,º)»,¼>µj¶.¸,¾FÂ3·$Á)µj¾4Èt¹iÉ4ÁU¹�´$ÄsÃNÄ$µ.Á)µj´"¹�»,ÁU¾4Èl¾4´Fµ.ÁU¹�º)»,¾4¿"Âv¹�Á)µc¶.¾4¿$¶.·$Á)Á)µ.¿9ºk»,È¿$¾_Æ"¹�ºU¹IÆ$µ.´Fµ.¿$Æ$µ.¿$¶.Ó&¶.¾4¿$¿$µ.¶.ºUÂbº)Ä$µ9Ò ¹�¿$Æ&¿$¾Á)µ9Â3¾4¸,¼>µ.Æ�¶.¾4¿9º)Á)¾4¸[ÒZ¹�Ï>µ9Âmº)Ä$µ9Ò ÒN·$º)·"¹�¸,¸,Ó_µ.½9¶.¸,·"Â3»,¼>µ9ÀRó"Ä$µHÉ4ÁU¹�´$Äa¶9¹�¿SÇFµH¼9»,µ.Ã�µ.ƹ4Âl¹�¿w·$´$´Fµ.ÁÇF¾4·$¿$Æw¾4Èt¶.¾4¿$¶.·$Á)Á)µ.¿$¶.»,µ9ÂpÃN»,º)Ä$»,¿&¹HÂ3¶KÄ$µ.Æ$·$¸,µ9À��p»,¼>µ.¿<º)Ä$µJ´$Á)¾��3µ.¶.º)»,¾4¿¾4È�º)Ä$µs¶.¾4¿$¶.·$Á)Á)µ.¿$¶.Ó<É4ÁU¹�´$Ä?º)¾GÁ)µ9Â3¾4·$Á)¶.µv¶.¸/¹4Â)Â���Í Ðd¶.¸,»,Ñ9·$µ9ÂN¾4ÈbÂ3»,Ø.µs¸/¹�Á)É4µ.Ábº)Ä"¹�¿Mº)Ä$µ¹�¸,¸,¾UÃ�µ.ÆGÇF¾4·$¿$ÆaÔ�� ����×N¹�Á)µbÈ3¾4Á)Ç$»,Æ$Æ$µ.¿"Àó"Ä$»/Â"»/Âp¹�¿M¹�º)º)ÁU¹�¶.º)»,¼>µvÂ3¾4¸,·$º)»,¾4¿"Ð9µ9Â3´Fµ.¶.»/¹�¸,¸,ÓvÈ3¾4Ápµ.½9´$¸,»,¶.»,ºNµ.¿9·"Òmµ.ÁU¹�º)»,¾4¿"Ð�Ç$·$ºp»,ºp»/Â

´$ÁU¹�¶.º)»,¶9¹�¸,¸,Ól¸,»/Òm»,º)µ.Æuº)¾JÂ)ÒZ¹�¸,¸�¶9¹4Â3µ9Â)Ð�Æ$·$µtº)¾j»,ºUÂ�Ç$»,¿$¾FÒm»/¹�¸�¶.¾FÒm´$¸,µ.½9»,º/Ó9ÀpÊ,¿[´"¹�Á)º)»,¶.·$¸/¹�ÁUл,º�Ç$¸,¾UÃuÂd·$´s»,¿s´$Á)¾4Ç$¸,µ9ÒZÂdÃN»,º)ÄvÄ$»,É4ÄsÆ$µ.É4Á)µ.µ�¾4ÈF¶.¾4¿$¶.·$Á)Á)µ.¿$¶.Ó9Ð]Â3·$¶KÄ<¹4Â)Ð>È3¾4Átµ.½d¹4Òm´$¸,µ9ÐÒm¾�Æ$µ.¸/ÂV¾4È"´$»,´Fµ.¸,»,¿$µ.ÆxÇFµ.Ä"¹)¼9»,¾4ÁUÂ)À

Page 97: BMC’03 - JKUfmv.jku.at/papers/bmc03-preliminary-proceedings.pdfBMC’03 Boulder, Colorado, USA. ... Alessandro Cimatti (IRST, Italy) Raanan Fraer (Intel, Israel) Danny Geist (IBM

� ��!#"%$'&)(+*,��-�.

/10�210�235476981:,;�<�=?>1@A<�81=CBEDF@AG�HI<�=?J5KML'=?6�@A<�81=NPORQTSMUVUXWCYXZ[UX\�]_^�QTS+O�`�a7bI]MZ[QT\dce^�QTS�]Mf�UVY�bTg�UhQT^i`�\�YXQT\�j�Z[]MZ[QT\�UXjkYXQT\�YX`�SMSMUX\�YXl�cmZ7gn SMQ n Q)g�UXjoZ[\qp[rIs ^�QTS�tmu�uvSMU n SMU�g�UX\�]+bI]MZ[QT\dwyx[^ezeUCQ)ORZ[]{YXQT\dg�Z[j�UXSMZ[\�|VjdbI]+b}j�U n UX\�~j�UX\�YXZ[U�gMcmbI\�j�zeUog�Z7O n a[l�zeQTSM��QT\�Q n UXS+bI]MZ[QT\dgmQT^m]Mf�U�gMbTORU�SMU�g�QT`�SMYXU�YXa7bTgMgMc�]Mf�UX\]Mf�U}SMU�g�QT`�SMYXU��)QT`�\�jhYXQT\dg�]MS+bIZ[\�]iZ7gibI\hSM~�YXQ)O���Z[\dbI]MZ[QT\hUX� n SMU�gMg�Z[QT\dc g�UXa[UXYX]MZ[\�|_YXQ)OR~��Z[\dbI]MZ[QT\dgRQT^R` n ]MQ�� ���eQ n UXS+bI]MZ[QT\dgRQT`�]CQT^R�����Aw��oU�Y�bIa[a�]Mf�Z7gi��a[]MUXSMZ[\�|�^�`�\�YX]MZ[QT\�?�'� �7�X�M�����)� �I�����¡ ¡¢Mw£x[]+g�g�Z[¤XU�YXQ)O n a[UX��Z[]7l�c'z�f�UX\�UX� n SMU�gMg�UXj¥bTgmb,tmu�u¦Z[\dg�]MU�bIj�QT^£b]7zeQ�a[UX§#UXa¨^�QTS+OCc?Z7g �©� �����?ª«� ���A¢Mc?Z7w U�w[c?\�`dO��)UXS�QT^¨Q n UXS+bI]MZ[QT\dgiOCb n�n UXj�]MQ�]Mf�U�YXa7bTgMg]MZ7ORU�g)]Mf�Um�)QT`�\�jC^�QTSE]Mf�U�YXa7bTgMgMwm¬df�U�^�`�\�YX]MZ[QT\CZ7g)U�bTg�Z[a[l}]MS+bI\dg�a7bI]MUXjC]MQ�­�®R¯�^�QTS+OCbI]� z�Z[]MfyZ[\�]MUXS+ORUXj�Z7bI]MU_bIj�j�Z[]MZ[QT\dbIa°§�bISMZ7bI��a[U�gM¢Mc'z�Z[]Mf±g�Z7ORZ[a7bIS²YXQ)O n a[UX��Z[]7l�w

³ \�^�QTSM]M`�\dbI]MUXa[l�c5bTg n SMUX§�Z[QT`dg�a[l´g�f�Q+z�\dc¨zeU_fdbM§#U�YXQT\�j�Z[]MZ[QT\�UXj � Z7w U�w[c5bISM]MZ[��YXZ7bIa7¢YXQT\�YX`�SMSMUX\�YXZ[U�gMc�]MfdbI]dYXQ)O n a[Z[Y�bI]MUmQT`�S�ORQ'j�UXa'YXQ)O n bISMUXj�]MQCp[rIs7c%bI\�jyOCbI�#Um]Mf�U�bI�)Q+§#Ug�QTa[`�]MZ[QT\�UX� n QT\�UX\�]MZ7bIaµZ[\o]Mf�UC\�`dO��)UXS©QT^eYXQT\�]MSMQTa¨Y9f�QTZ[YXU�g � ^�QTSM��gM¢M¶²zeU�g�f�QT`�a[joUX��~n bI\�jhQT\�U}Z[\dg�]+bI\�YXU,QT^ YXQT\�YX`�SMSMUX\�YXlV|TS+b n fh^�QTS²U�bIY9f�Y�bTg�U�QT^ SMU�g�QTa[§#UXjd·I`�\�SMU�g�QTa[§#UXjYXQT\�]MSMQTa�Q n UXS+bI]MZ[QT\dw

/10�210�¸¹²º�;�HI<�»�@A¼ 8147DFG�½�G�D�> ¾1¾¡H¿8�>16�ÀÁ Z[\�YXUy\�QT\�U�QT^²]Mf�Uy]7zeQ n SMUX§�Z[QT`dg�b n�n SMQ)bIY9f�U�g�bIa[QT\�U�Z7g�bI��a[U�]MQoUXWCYXZ[UX\�]Ma[lvg�QTa[§#UQT`�S n SMQT��a[U�OCc�zeUij�UX§#UXa[Q n UXj�b5f�l���SMZ[j_]MUXY9f�\�Z[Â�`�U�c'z�f�Z[Y9f�^�QTa[a[Q+z}g�]Mf�URYXQT\�YX`�SMSMUX\�YXl|TS+b n f´g�]MS+bI]MUX|Tloa[Q'Y�bIa[a[l�cdz�Z[]Mf�Z[\±YXQT\�]MSMQTa£YXQ)O n QT\�UX\�]+g²QT^�]Mf�U�­�u�¯�écebI\�j±]Mf�U�SM~YXQ)O���Z[\dbI]MZ[QT\±b n�n SMQ)bIY9fyQT\±bR|Ta[QT�dbIa n UXS+g n UXYX]MZ[§#U�w

Ä QTSMU�Z[\¦j�UX]+bIZ[a7c zeUyUX� n SMU�gMg�]Mf�U�SMU�g�QT`�SMYXUyYXQT\dg�]MS+bIZ[\�]�^�`�\�YX]MZ[QT\ � ^�QTShb�|TZ[§#UX\SMU�g�QT`�SMYXU{YXa7bTgMg Å�Æ�¢5bTg5bRYXQ)O n Q)g�Z[]MZ[QT\yQT^d]7zeQ�g�`���~�^�`�\�YX]MZ[QT\dg

Ç�� �����È�É ���)� � ¢ Ê �?�'� �7�X�M�7˨� � Ì'Í+���)� � ¢ � � ����¢

¬df�U�QT`�]MUXS+ORQ)g�]_^�`�\�YX]MZ[QT\kZ7g � b±g�a[Z[|Tf�]�ORQ'j�Z[��Y�bI]MZ[QT\kQT^�¢{]Mf�U n SMUX§�Z[QT`dg�a[lqj�UX~g�YXSMZ[�)UXj�SM~�YXQ)O���Z[\dbI]MZ[QT\���a[]MUXS+c#z�f�UXSMU�bTg ˨� � Ì'Í Z7gµbe^�`�\�YX]MZ[QT\�]MfdbI] SMU�OCb n g�Q n UXS+bI]MZ[QT\]MS+bI\dg�Z[]MZ[QT\dgE]MQhb�g�UX]5QT^�bIa[a[Q'Y�bI]MZ[QT\�§�bISMZ7bI��a[U�gMc'z�Z[]MfV]Mf�U{^�QTa[a[Q+z�Z[\�|CSM`�a[U�gM¶Î�Ï bIY9fy`�\�YXQT\�]MSMQTa[a[UXjyQ n UXS+bI]MZ[QT\y� � Æ)Z7gESMU�OCb n�n UXjy]MQVbI\�bIa[a[Q'Y�bI]MZ[QT\_§�bISMZ7bI��a[U{Ð'ÆdÊ� Æ[��Æ7c�z�f�Z[Y9fVUX§�bIa[`dbI]MU�g¨]MSM`�U{z�f�UX\V]Mf�U{Q n UXS+bI]MZ[QT\�Z7gEUX��UXYX`�]MZ[\�|)w

Î ­dQT\�]MSMQTa[a[UXjog�`��dg�UX]+g�QT^¡]Mf�U,­�u�¯�à � g�`���|TS+b n fdg�Z[\�YXa[`�j�UXj_�)UX]7zeUXUX\_^�QTSM�ybI\�j�Ñ�QTZ[\\�Q'j�U�gM¢©bISMU�|Ta[QT�dbIa[a[l�SMU�OCb n�n UXj�]MQ±b n SMQ n UXS_g�UX]©QT^{bIa[a[Q'Y�bI]MZ[QT\o§�bISMZ7bI��a[U�gMc°Q+§#UXSz�f�Q)OÒ]Mf�U ˨� � Ì'Í ^�`�\�YX]MZ[QT\dg£SMUX]M`�SM\dg{b}\�`dO��)UXS{QT^eQT\�U�g£UX��bIYX]Ma[lhYXQTSMSMU�g n QT\�j�Z[\�|z�Z[]MfC]Mf�U�bTORQT`�\�] QT^�SMU�g�QT`�SMYXU�g¡SMUXÂ�`�Z[SMUXjdw Á Q�bIa[adbISM]MZ[��YXZ7bIa%YXQT\�YX`�SMSMUX\�YXZ[U�g£bI\�jd·IQTSg n UXYX`�a7bI]MZ[QT\dg²bISMU{]+bI�#UX\yZ[\�]MQ�bIYXYXQT`�\�]²��l�]Mf�Z7gE^�`�\�YX]MZ[QT\dw¬df�U�YXQ)O n Q)g�Z[]MZ[QT\_Z7g�\�UX§#UXS5YXQ)O n `�]MUXj�UX� n a[Z[YXZ[]Ma[l�c'��`�]mZ[\�]MUXS+ORUXj�Z7bI]MU�bIa[a[Q'Y�bI]MZ[QT\

§�bISMZ7bI��a[U�gCbISMU��#U n ]�bI\�j¦]MS+bI\dg�^�UXSMSMUXjÓ]MQ�]Mf�U�­�®R¯q^�QTS+O�`�a7bI]MZ[QT\¦QT^ Ç�� ��È�É c z�f�Z[Y9fbIa[a[Q+z}g�`dg°]MQ�^MbIYXUR]Mf�U�OCbIZ[\og�Z[¤XU��)QT]M]Ma[UX\�UXY9��gM¶ �MÔ ¢£¬df�UiYXQ)O n a[UX��Z[]7l�QT^°YXQT\�j�Z[]MZ[QT\dbIaYXQT\�YX`�SMSMUX\�YXl � ^�`�\�YX]MZ[QT\ ˨� � Ì'Í ¢�Z7gd�#U n ]�z�Z[]Mf�Z[\�gMOCbIa[a�SMUX|TZ[QT\dgdQT^°]Mf�U�­�u�¯�éw Ï g n UX~YXZ7bIa[a[ly^�QTS²]Mf�U�Z7O n QTSM]+bI\�]RY�bTg�U�QT^ a[Q'Q n Z[\�|obI\�jd·IQTS n Z n UXa[Z[\�UXj��)UXfdbM§�Z[QTS+gMc¨ORQ'j�UXa[UXj��l¥g�UXSMZ7bIa²bI\�j n bIS+bIa[a[UXa¨Z[\dg�]+bI\�YXU�g£QT^e]Mf�UVgMbTORU,SMUX^�UXSMUX\�YXUh­�u�¯�éc?]Mf�Z7g{OCbI�#U�g£]Mf�Ug�Z[¤XU,QT^ ˨� � Ì'Í a[Z[\�U�bIS�Z[\�]Mf�U,\�`dO��)UXS{QT^ig�UXSMZ7bIa7· n bIS+bIa[a[UXa¨Z[\dg�]+bI\�YXU�gMw � rT¢ �?�'� �7�X� c¡]Mf�U

Õ

Page 98: BMC’03 - JKUfmv.jku.at/papers/bmc03-preliminary-proceedings.pdfBMC’03 Boulder, Colorado, USA. ... Alessandro Cimatti (IRST, Italy) Raanan Fraer (Intel, Israel) Danny Geist (IBM

Ö ×�Ø#Ù%Ú'Û)Ü+Ý,×�Þ�ß

à�á�â�ãXäMå[æTâVä+çIè�å[â�é�ã�çIêMë©æTàEäMì�ë©æ+í#ëXê+çIî[î�ï�êMæTð�î[ë�ñCò�ìdçTó²ó�å[ôXë�õ©ö�÷�ø�ù?ú û ø�ùAüMò%å7ý ë�ý[ò%å[ä5å7ó¨î[å[â�þë�çIê}å[â�äMì�ë�â�ádñ�ð)ëXê,æTàmæTï)ëXê+çIäMå[æTâdóMò�à�æTê�ç,éTå[í#ëXâ±êMë�ó�æTá�êMãXë_ð)æTá�â�ÿdý��Có}çIâ�æ+í#ëXê+çIî[îêMë�ó�á�î[ä+ò�æTá�ê©êMë�ó�á�î[ä}ãXæTâdó�äMê+çIå[â�ä�à�á�â�ãXäMå[æTâ�å7ó}ó�ã�çIî7çIð�î[ë�òmçIâ�ÿ��eëXî[î{ó�á�å[äMëXÿ±à�æTê©î[æ'æTï�å[â�éçIâ�ÿ_ï�å[ï)ëXî[å[â�ëXÿyð)ëXìdçMí�å[æTê+óMò���ì�å[ã9ì±çIêMëiäMì�ë�ñRæ)ó�ämÿ�å��CãXá�î[ä5ï�êMæTð�î[ë�ñCódå[â���eþ�ðdçTó�ëXÿçIï�ï�êMæ)çIã9ì�ë�óMý

�� ��� ��������������������! ��!"�#��%$����! �"���&' å[éTá�êMë�(�çIâ�ÿ*)yó�ì�æ+� äMì�ëRïdó�ëXá�ÿ�æTþ�ãXæ'ÿ�ëiæTà�äMì�ë-,/. . 021{çIâ�ÿ43�52. 687:9�à�á�â�ãXäMå[æTâdó°êMë�ó�ï)ëXãXþäMå[í#ëXî�;�ý ' æTê²óMçIè#ë�æTàEó�å7ñRï�î[å[ãXå[ä8;,å[ä¨å7ó¨çTóMó�ádñRëXÿ�äMìdçIä5çIî[î%æTï)ëXê+çIäMå[æTâdó�å[â,äMì�ë-<= '?> çIêMëñCçIï�ï)ëXÿyæTâ�äMæCäMì�ë�óMçTñRë©êMë�ó�æTá�êMãXë©ãXî7çTóMóMò'à�æTê=��ì�å[ã9ì�@BADCE,/. . 021�á�â�å[ä+ó5çIêMë�çMí�çIå[î7çIð�î[ë�ý

F â�æTá�êmå7ñRï�î[ë�ñRëXâ�ä+çIäMå[æTâdò�ëXí#ëXê�;�æTï)ëXê+çIäMå[æTâ�å7ó�î7çIð)ëXî[ëXÿ���å[äMì_ä8�eæyçIäMäMêMå[ð�á�äMë�ó�G5ö�HTüäMì�ë�ó�ëXä¨æTà�çIî[î'ï)æ)óMó�å[ð�î�;©ãXæTâ�ãXá�êMêMëXâ�ä¨â�æ'ÿ�ë�óEçIâ�ÿ�ö�ITüdçJ���êMëXï�êMë�ó�ëXâ�äMå[â�é�äMì�ë£ãXæTâ�äMêMæTîã�çTó�ëµà�æTê?��ì�å[ã9ì}äMì�ëeæTï)ëXê+çIäMå[æTâ©å7ó%ëXâdçIð�î[ëXÿdý?�RãXäMádçIî[î�;�ò«å[â}æTêMÿ�ëXê�äMæ²ãXæ+í#ëXê�ó�ï)ëXãXá�î7çIäMå[æTâdòäMì�ë�ñRë�çIâ�å[â�é�æTà�ó�á�ã9ì¥çK��qå7óEäMìdçIä�äMì�ë{æTï)ëXê+çIäMå[æTâ�å7ó $�"�&L �M����L$ å[àdäMì�ë{ëXí�çIî[ádçIäMå[æTâæTàdäMì�ëN��Óà�æTê�äMì�ë�çIî[êMë�çIÿO;�êMë�ó�æTî[í#ëXÿhãXæTâ�äMêMæTî7óEêMëXäMá�êMâdó�PTý

�CómêMëXé)çIêMÿdómäMì�ëQ,/. . 021©à�á�â�ãXäMå[æTâdò£çIî[î ï)æ)óMó�å[ð�î[ë�ãXî[å�R�á�ë�ó�ö�æ+í#ëXê©äMì�ë�ó�ëXä}æTà£æTï)ëXê+çIþäMå[æTâdó£ð)ëXî[æTâ�éTå[â�éyäMæ�äMì�ë�êMëXãXëXå[í#ëXÿ´ó�á�ð�þ�éTê+çIï�ìdü{çIêMëCêMëXãXá�ê+ó�å[í#ëXî�;oð�á�å[î[ä{ð�;ÓñRë�çIâdómæTàäMì�ë�çIáOS�å[î[å7çIê�;UTV7:W�7:9XAY687:Z[. \ ]�^�7:_µà�á�â�ãXäMå[æTâdý/��ä²ë�çIã9ìyî[ëXí#ëXîdæTàdêMëXãXá�ê+ó�å[æTâdòdçRâ�ë:�vâ�æ'ÿ�ëå7óEçIÿ�ÿ�ëXÿ�äMæiäMì�ë£ï�êMëXí�å[æTádó�î�;}éTëXâ�ëXê+çIäMëXÿ�ãXî[å�R�á�ë�ò�ã9ì�ëXã9è�å[â�é{à�æTê�ó�ï)ëXãXá�î7çIäMå[í#ë�ë:S�ëXãXá�äMå[æTâdýF â_àMçIãXä+ò�äMì�ë��K`JÓð)ëXä8�eëXëXâyäMì�ë�â�æ'ÿ�ë�a[ódëXâdçIð�î[ë�çIâ�ÿ�äMì�ëiãXî[å�R�á�ë�a[ó¨ëXâdçIð�î[ë�êMëXäMá�êMâdó�çPµêMë�ó�á�î[ä æTâ�î�;©å[à?äMì�ëmãXá�êMêMëXâ�ä â�æ'ÿ�ë©çIâ�ÿVçIäEî[ë�çTó�ä æTâ�ëmâ�æ'ÿ�ë{çIî[êMë�çIÿO;}ð)ëXî[æTâ�éTå[â�éiäMæ�äMì�ëãXî[å�R�á�ëCçIêMë²å[â�ä8�eæ�ÿ�å�b)ëXêMëXâ�ä£ãXæTâ�äMêMæTî�ð�ê+çIâ�ã9ì�ë�óMýdcdì�ëXêMëXà�æTêMë�ò1äMì�ëRãXæTâ�ãXá�êMêMëXâ�ã:;�æTà�äMì�ëâ�æ'ÿ�ëe�}ý ê+ý ä+ý äMì�ë{ãXî[å�R�á�ë}å7óEêMë�çIî�æTâ�î�;�å[àEäMì�ë©ãXæTâ�äMêMæTî[î[å[â�é�æTï)ëXê+çIäMå[æTâdó¨ÿ�å7ó�ãXêMå7ñRå[âdçIäMå[â�éäMì�ëyð�ê+çIâ�ã9ì çIêMëyâ�æTä�êMë�ó�æTî[í#ëXÿf;#ëXäoö�å7ý ë�ý[òµäMì�ëVâ�æ'ÿ�ë�ó�å[âÓäMì�ëVâ�ë:� ãXî[å�R�á�ë¥çIêMëVë:S�ëXþãXá�äMëXÿkó�ï)ëXãXá�î7çIäMå[í#ëXî�;�üMýhg+á�ã9ì�ãXæTâ�äMêMæTî[î[å[â�éyæTï)ëXê+çIäMå[æTâdó{çIêMëCäMì�ëXêMëXà�æTêMëhçIÿ�ÿ�ëXÿoäMæyäMì�ëi ��jk��&L#���l��L$ ó�ëXä+ýJcdì�ë©äMê+çIâdó�å[äMå[æTâVãXæTêMêMë�ó�ï)æTâ�ÿ�å[â�é�äMæ�äMì�ë{â�ë:�vãXî[å�R�á�ë}å7ó¨äMì�ëXâ¥ó�äMæTêMëXÿçTó{çQ���ò çIâ�ÿoäMì�ë�ãXî[å�R�á�ë�ó5æTà£ð�å[éTéTëXê�ó�å[ôXë�ó}çIêMë�ð�á�å[î[ä_ö�äMì�ëhó�ëXä}æTà£ï)æ)óMó�å[ð�î�;�ãXæTâ�þãXá�êMêMëXâ�ä²â�æ'ÿ�ë�ó¨ð)ëXå[â�é�êMë�ó�äMêMå[ãXäMëXÿ¦çTóEäMì�ë©ãXî[å�R�á�ë}ìdçTóEäMæ�ð)ë{ãXæ)ñRï�î[ëXäMëXî�;�ãXæTâ�â�ëXãXäMëXÿdüMým í#ëXâ�äMádçIî[î�;�ò'äMì�ëiî7çTó�ä£î[æ'æTï�å[â_äMì�ën,/. . 021£à�á�â�ãXäMå[æTâ_ÿ�ë:o�â�ë�óEäMì�ëCçIî[î[æ'ã�çIäMå[æTâ�í�çIêMå7çIð�î[ë�ó�Gí�çIêMå7çIð�î[ëep2q�ä+çIè#ë�ó²çií�çIî[á�ë{æTà=HRå�b�äMì�ëXêMë{å7ó5çRäMê+çIâdó�å[äMå[æTâyå[âyäMì�ë{ãXá�êMêMëXâ�ä,ó�á�ð�þ�éTê+çIï�ìå[â�í#æTî[í�å[â�é�äMì�ë{ádóMçIéTë{æTà ��r���L �&L�ts êMë�ó�æTá�êMãXë�ó æTàdäMì�ë{ãXá�êMêMëXâ�ä5êMë�ó�æTá�êMãXë©ãXî7çTóMóMý

u£â�ãXëkçIî[î{äMì�ëoêMë�ó�æTá�êMãXë�ãXî[å�R�á�ë�óCìdçMí#ëoð)ëXëXâvéTëXâ�ëXê+çIäMëXÿdò²äMì�ëv3�52. 687:9©à�á�â�ãXäMå[æTâó�;�ñ�ð)æTî[å[ã�çIî[î�;�ð�á�å[î[ÿdó�çIî[îeí�çIî[å[ÿ±äMê+çIâdó�å[äMå[æTâdó5å[â�äMëXê+ñCó5æTà�äMì�ëoçIî[î[æ'ã�çIäMå[æTâ�í�çIêMå7çIð�î[ë�óMýc�æ©ÿ�æ©äMì�å7óMòTå[äµãXæ)ñ�ð�å[â�ë�ó�äMì�ë�çIî[î[æ'ã�çIäMå[æTâ�í�çIêMå7çIð�î[ë�ó�ãXæ)ñRå[â�é}à�êMæ)ñ äMì�ë²ÿ�å�b)ëXêMëXâ�äeã�çIî[î7óäMæ�äMì�ëw,/. . 021�à�á�â�ãXäMå[æTâÓäMæ�à�æTê+ñPçIâqë:S�ï�êMë�óMó�å[æTâkêMëXï�êMë�ó�ëXâ�äMå[â�é çIî[î²ï)æ)óMó�å[ð�î[ë "������Lx� ��çIî[î[æ'ã�çIäMå[æTâdó�ö�å7ý ë�ý[òmäMì�æ)ó�ëhêMë:R�á�å[êMå[â�évçIä�î[ë�çTó�äh@BADCE,/. . 021+yeH�êMë�ó�æTá�êMãXë�óMüMýzcdì�ëXâ äMì�ëãXæ)ñRï�î[ë�ñRëXâ�ä+çIäMå[æTâ�æTà ó�á�ã9ì�ë:S�ï�êMë�óMó�å[æTâdòV��ì�å[ã9ì�å[â�ÿ�ëXëXÿ�êMëXï�êMë�ó�ëXâ�ä+ó£çIî[îdçIî[î[æ'ã�çIäMå[æTâdó)æTàçIä£ñRæ)ó�är@BADCE,/. . 021�êMë�ó�æTá�êMãXë�óMò+å7ó�êMëXäMá�êMâ�ëXÿ�öMçIâ�ÿ©äMì�ëXâ}ÿ�å[êMëXãXäMî�;�ádó�ëXÿyçTó�ç¨ãXæ)ñRï)æTâ�ëXâ�äæTàr{�3¡üMý

�� ��� �|�}~&L�� ��������� ��������� ëXä©ádó�ãXæTâdó�å[ÿ�ëXêyçIé)çIå[â�äMì�ëU<= '?> ó�ì�æ+��â±å[â ' å[éTá�êMë�HVçIâ�ÿ�î[ëXä}ádó}çTóMó�ádñRë�äMìdçIäçIî[î¡äMì�ë{æTï)ëXê+çIäMå[æTâdó�çIêMë�ñCçIï�ï)ëXÿyæTâ�ç,ó�å[â�éTî[ëe� �?� ý�cdì�ëN<= '?> å7ódÿ�å[í�å[ÿ�ëXÿVð�;�äMì�ëçIî[éTæTêMå[äMìdñvå[â�äMæ�ä8�eæ�ó�á�ð�þ�éTê+çIï�ìdó�GEäMì�ë�o�ê+ó�ä5å7ódãXæ)ñRï)æ)ó�ëXÿyð�;�äMì�ë{ãXæ)ñRïdçIêMå7ó�æTâyæTâ�î�;�ò

HVP

Page 99: BMC’03 - JKUfmv.jku.at/papers/bmc03-preliminary-proceedings.pdfBMC’03 Boulder, Colorado, USA. ... Alessandro Cimatti (IRST, Italy) Raanan Fraer (Intel, Israel) Danny Geist (IBM

�������E�2�t�+�������

� �:�:�E�B���:�D�����+�� ������ ¢¡¤£¥¢¦w§©¨!ª+«�¬ ¬ ­�®°¯*£��±�²  ´³ ±kµ  �¶O¡¸·/¹¹ º°»[¼/½

� ������¾�¿LÀ:ÁdÂ=�:�D������à ¾�¿LÀ:ÁD³DÄ°Á ± �ÅkÆ  ´ÇLÈ�ÁDÄ°Á ± ¡ÊÉÈ�¾��DÁD³D¿ Æ�Ë ÁDÀJ¡ÊÉÁD¾���Ì Æ Á�¡v·/¹¹ ½=Í�»Î�ÏÑÐ:ÏÑÒ ¨LÓ ÏÑÔ ¬ Õ Ö:× ÏÑØ � ±�²  ´³ ±kÙ ¾�¿LÀ:Á Ù ÅkÆ  ´ÇLÈ�ÁDÄ°Á ±kÙ È�¾��DÁD³D¿ Æ�Ë ÁDÀ Ù ÁD¾���Ì Æ Á Ù ¾�¿LÀ:ÁYà Š¿L¾ Å È����

� ������ ¢¡¤£¥¢¦w§©¨!ª+«�¬ ¬ ­�®°¯*£���:�D������à �VÚE¡ Ð:Ï´Û Ü ¨ ÒÝtÞ ¡¸·/¹¹ � Í�¹d� ÝtÞ Ù ·/¹¹ ß�Í�½=¼����:�D������à �VÚ Ù�±�²  ´³ ±kµ  �¶à�!�

á �+â��+ã����V�+���:��äEå��+æ� ±�²  ´³ ±kÙ ¾�¿LÀ:Á Ù ÅkÆ  ´ÇLÈ�ÁDÄ°Á ±kÙ È�¾��DÁD³D¿ Æ�Ë ÁDÀ Ù ÁD¾���Ì Æ Á Ù Å ¿L¾ Å È��DÄ°Á ± �ç ��è ÅkÆ  ´ÇLÈ�ÁDÄ°Á ± è�éh§©¨!ª+«�¬ ¬ ­�®�XêÑëLì��îí

¾�ÁDï?ð©¾���Ì Æ ÁJ¡¸·/¹¹ � Í�¹ »[ß�ñóò�ôr��ÁD¾���Ì Æ Á Ù ¾�¿LÀ:ÁYà ÁD¾���Ì Æ Á Ù È�¾��DÁD³D¿ Æ�Ë ÁDÀV�¾�ÁDïõ�¾��DÁD³D¿ Æ�Ë ÁDÀö¡ÊÈ�¾��DÁD³D¿ Æ�Ë ÁDÀç ��·/¹¹ ñóò º°»[¼/½���¾�ÁDï?ð©¾���Ì Æ Á��¾�ÁDïõ�¾��DÁD³D¿ Æ�Ë ÁDÀö¡ÊÈ�¾��DÁD³D¿ Æ�Ë ÁDÀ-÷�®Ñ­ Ð:ø Õ ®ÑÓ�Õ Ð:Î�Ô ­ Ð Ó Ò ­�¬ Ø ��ÁD¾���Ì Æ Á Ù ¾�¿LÀ:ÁYà ÁD¾���Ì Æ Á��¾�ÁDï?ð©¾���Ì Æ Á�¡¸·/¹¹ � Í�¹d��·/¹¹ »[ß�ñóò�ôr��ÁD¾���Ì Æ Á Ù ¾�ÁDïõ�¾��DÁD³D¿ Æ�Ë ÁDÀV� Ù

·/¹¹ »[ß�ñóò�ôr��¾�¿LÀ:ÁYà ÁD¾���Ì Æ Á Ù ¾�ÁDïõ�¾��DÁD³D¿ Æ�Ë ÁDÀV�!�¾�ÁDï?ù Æ  ´ÇLÈ�Á¡ ÅkÆ  ´ÇLÈ�ÁDÄ°Á ± ÷�¾�¿LÀ:Á±�²  ´³ ±kµ è ¾�ÁDï?ù Æ  ´ÇLÈ�ÁYè ¶O¡¸·/¹¹ ½=¼�� ±�²  ´³ ±kµ è ¾�ÁDï?ù Æ  ´ÇLÈ�ÁYè ¶ Ù

Ó Ò ¨ Ð:Ø Õ Ó�Õ ­ Ð ��¾�ÁDï?ù Æ  ´ÇLÈ�Á Ù ¾�ÁDïõ�¾��DÁD³D¿ Æ�Ë ÁDÀV�!�¾�ÁDï?ù�¿L¾ Å È��d¡ Å ¿L¾ Å È��DÄ°Á ±°ú ¾�¿LÀ:ÁYà Š¿L¾ Å È��� ������¿L�öÂ=¾�ÁDï?ù�¿L¾ Å È����Î�ÏÑÐ:ÏÑÒ ¨LÓ ÏÑÔ ¬ Õ Ö:× ÏÑØ � ±�²  ´³ ±kÙ ¿L� Ù ¾�ÁDï?ù Æ  ´ÇLÈ�Á Ù ¾�ÁDïõ�¾��DÁD³D¿ Æ�Ë ÁDÀ Ù ¾�ÁDï?ð©¾���Ì Æ Á Ù ¾�ÁDï?ù�¿L¾ Å È����

û�ü�ý�þ°ÿ�þ���������� � � ���������8ü�����þ

¼������Ñ�V�+ãK�!�� Æ�Æ ¿ Å � ±  ´¿L¾�³ µ � ¶O¡¸·/¹¹ ½=Í�»� �������¡¤£=¥¢¦�§©¨!ª+«�¬ ¬ ­�®°¯*£��� Æ�Æ ¿ Å � ±  ´¿L¾�³ µ �k¶O¡¸·/¹¹ º°»[¼/½

� ������ ¢¡¤£¥¢¦������� "!$#&%ó�¾�ÁDï�' Æ�Æ ¿ Å � ±  ´¿L¾�³¡Ê� Æ�Æ ¿ Å � ±  ´¿L¾�³� �����)(=¡¤£¥¢¦�§©¨!ª+«�¬ ¬ ­�®t¯*£��� �������¡ � ¥¢¦�§©¨!ª+«�¬ ¬ ­�®°¯*£��ç �*( ¯+�é�§©¨!ª+«�¬ ¬ ­�®°¯*£, �Xê�-�.

� Æ�Æ ¿ Å ¡¸·/¹¹ � Í�¹d��� Æ�Æ ¿ Å � ±  ´¿L¾�³ µ �k¶ Ù �:�D������Úàà �*/��¾�ÁDï�' Æ�Æ ¿ Å � ±  ´¿L¾�³ µ ([¯+�k¶°¡¸·/¹¹ ½=¼���¾�ÁDï�' Æ�Æ ¿ Å � ±  ´¿L¾�³ µ ( ¯+�k¶ Ù � Æ�Æ ¿ Å �

� Æ�Æ ¿ Å � ±  ´¿L¾�³�¡Ê¾�ÁDï�' Æ�Æ ¿ Å � ±  ´¿L¾�³�XêÑëLì��îíd·/¹¹ Í�½=ôr��� Æ�Æ ¿ Å � ±  ´¿L¾�³ µ §©¨!ª+«�¬ ¬ ­�®�¯*£ó¶à�

û�ü�ý�þ10�þ�������2435� 6"7�89���������8ü�����þ

:<;>=@?$=�A5BDC$;>=EBF=@G@H5I>JLKMI>G@NMO>J>=�B>P1H5C$;QC$;>=�RTSQSUAVI>JXW>YEZ [<\]RL^<[_H5`1=@?aAVC$KMH5IbB$cd[b;>=@IC$;>=e?$=@NfAVC$KMH5IbBgJ>=@h>I>=@JiP�jXC$;>=eCf:dHkG�AVNMNfB]H5lbC$;>=Tm]n n oqp�lFO>I>G@C$KMH5IrAV?$=Q?$=�BF`1=@G@C$KMs�=@NMj4t

uqv w_x y v{z4v�| uqv} x�~�5�

Page 100: BMC’03 - JKUfmv.jku.at/papers/bmc03-preliminary-proceedings.pdfBMC’03 Boulder, Colorado, USA. ... Alessandro Cimatti (IRST, Italy) Raanan Fraer (Intel, Israel) Danny Geist (IBM

�������D�q�1�a�������

�V�>��q�D���� � ���4�+� � ���4�{� �q�D���� � ���4� � ���4� ���� �>�> @ @�¢¡$£> ¥¤>¦a§F¡¨§F©>ª>«"¬5¦a�V­>£¯®T�$°±­>¦$ �§F @��¡_²5�>³M°´��¡$¦a�V�b§FµM¡$µM²5�¢¦$ @¶�©>µM¦$µM�>¬�·�¸T¹�º

©>�>µM¡a»4¼<£> @¦$ ��5§<¡$£> ¥§F @½@²5�>�¢§F©>ª>«"¬5¦a�V­>£¢®EµM¬5£�¡¾¦$ @¶�©>µM¦$ À¿Á¸T¹�ºÂ©>�>µM¡a§$»9ª>©>¡¾²5�>³M°¥µM�¡$£> E½��5§F Q¡$£b�V¡Ã¡$£> Ä¸TÅQÅ��V�>�ÇÆ>ºEÈ É<Ê]¸LË<Ér²5­1 @¦a�V¡$µM²5�b§Ã�V¦$ Eª1²5¡$£+ @Ì� @½@©>¡$ @�_ª1 @ÍF²5¦$ ¡$£> �½@²5��¡$¦$²5³]¦$ �§F²5³M©>¡$µM²5�Ç£b�5§dª1 @ @�ΧF²5³MÏ� @�bÐ_Ñ{Ï� @��¡$©b�V³M³M°�»4¡$£> T¤>�b�V³]½@²5�b§F¡$¦a�VµM��¡eª>©>µM³M¡ª�°X¡$£> ÓÒÕÔqÖ ×fØ@Ù�ÍF©>�>½@¡$µM²5��µf§$Ú

ÛÝÜ ��Þ$ßfà ��á �{ß � � �� � � � � � �D�� � � �D��

â ãUäæåèçÄédêÕëíìQîðï�ñqòðédóô �>½@ õ¼d X£b�$Ï� X¬5 @�> @¦a�V¡$ @�r¡$£> õ¡$¦a�V�b§FµM¡$µM²5�ö¦$ @³f�V¡$µM²5�ö²5Í<¡$£> ÀË<ÅQ÷�ø¾»��5§<­>¦$ @Ï�µM²5©b§F³M°�> �§F½@¦$µMª1 @�b»D¼d e£b�$Ï� e¡$²T­>¦$²q�>©>½@ e¡$£> QÏ� @¦$µM¤>½��V¡$µM²5�i­>¦$²5ª>³M �®´¼<£>µM½�£�¼<µM³M³9¬5µMÏ� e©b§g¡$£> §F½�£> @�>©>³MµM�>¬�§F²5³M©>¡$µM²5�bÐ<Éb£>µf§9µf§4�>²5�> �ª�°T©>�>¦$²5³M³MµM�>¬L¡$£> �¡$¦a�V�b§FµM¡$µM²5�õ¦$ @³f�V¡$µM²5�À�<½@ @¦$¡a�VµM���©b®<ª1 @¦T²5Í�¡$µf®E �§T�V�>�ù¡$£> @�U¡$¦$°�µM�>¬À¡$²À­>¦$²aÏ� _¡$£> ö®<©>¡$©b�V³ ¦$ ��V½�£b�Vª>µM³MµM¡f°rª1 @¡f¼d @ @�µM�>µM¡$µf�V³d�V�>��¤>�b�V³Ã§F¡a�V¡$ �§$Ð

Éb£> ¾È ÅQÅÀ¦$ @­>¦$ �§F @��¡$µM�>¬e¡$£> Ã¡$¦a�V�b§FµM¡$µM²5�Á¦$ @³f�V¡$µM²5��úFµM��®E²5�>²5³MµM¡$£>µM½ ²5¦b½@²5�>ûF©>�>½@¡$µMÏ� ÍF²5¦a®Tübµf§�§F¡$²5¦$ @�r�5§��TË<ýE÷ÓÍF²5¦a®<©>³f�k�5§b�> �§F½@¦$µMª1 @�ÓµM�rþM·5ÿ��fÐ

Éb£>  Ï� @¦$µM¤>½��V¡$µM²5�i§F¡$¦a�V¡$ @¬5°e©b§F©b�V³M³M°+§F¡a�V¦$¡a§Õ¼<µM¡$£i��­b�V¡$£Á²5Í>³M @�>¬5¡$£� @¶�©b�V³q¡$²k·E�V�>�µM�>½@¦$ ��5§F �§�µM¡�¡$µM³M³b¡$£> ¾­>¦$²5ª>³M �®¯µf§�§F²5³MÏ� @�¥²5¦�½@²1®E­>©>¡a�V¡$µM²5�Ó¦$ �§F²5©>¦$½@ �§Ä�V¦$ ¾ @Ì�½@ @ @�> @�bÐ÷�²5¦k¡$£> ù�Vª1²aÏ� Ó¦$ ��5§F²5�b§e¡$£> Ó¡$ @½�£>�>µM¶�©> À¼d²5¦��4§¾¼d @³M³EµM�ÎÍ$�V³f§FµM¤>½��V¡$µM²5�í�V�>� ­b�V¦$¡$µf�V³Ï� @¦$µM¤>½��V¡$µM²5�b»>¼<£> @¦$ ��5§�ÍF©>³M³9Ï� @¦$µM¤>½��V¡$µM²5�Óµf§]©b§F©b�V³M³M°ö�V½�£>µM @Ï� @�Óª�°öÈ��ÓËU¼<µM¡$£i³M²5�>¬5 @¦�V�>�_³M²5�>¬5 @¦�ª1²5©>�>�b§$Ð

ô ©>¦Á­>¦$²5ª>³M �® µf§�§F²1®E @£>²a¼ §Fµf®E­>³M @¦i�5§$»g¼<µM¡$£��k­>¦$²5­1 @¦Á��©b®<ª1 @¦T²5Í�¦$ @¬5µf§F¡$ @¦a§$»¡$£> @¦$  µf§g�V³M¼Q�$°4§��ħF²5³M©>¡$µM²5��¡$²Ä¡$£> e§F½�£> @�>©>³MµM�>¬¾­>¦$²5ª>³M �®TÐ��T²5¦$ @²aÏ� @¦a»�²5©>¦g @Ì�­1 @¦$µM @�>½@ §F£>²a¼L§�¡$£b�V¡Á©>�b§$�V¡$µf§F¤b�Vª>³M +­>¦$²5ª>³M �®T§T�V¦$ À®<©>½�£ù£b�V¦$�> @¦Á¡$²±§F²5³MÏ� +¡$£b�V�§$�V¡$µf§F¤b�Vª>³M µM�b§F¡a�V�>½@ �§$ÐeÉ>²õ¡$£>µf§]¦$ �§F­1 @½@¡kÆa¸EÉ�§F²5³MÏ� @¦a§�²5ÍF¡$ @�i­>¦$ �§F @��¡T�V�i @Ì�­1²5�> @��¡$µf�V³bª1 @£b�$Ï�µM²5¦�5§<÷�µM¬5©>¦$ ��T§F£>²a¼L§$Ð

÷�²5¦e¡$£> �§F X¦$ ��5§F²5�b§<¡$£> ¥§F¡a�V�>�b�V¦$�ö­>¦$ @Ï�µM²5©b§F³M°Ç�> �§F½@¦$µMª1 @�r¡$ @½�£>�>µM¶�©> X­>¦$²aÏ� @�r¡$²ª1 E¶�©>µM¡$ QµM�> T½@µM @��¡aÐ ô �+¡$£> Ä½@²5��¡$¦a�V¦$°k¼d Q�>²Á£b�$Ï� õ�V�+ �§F¡$µf®T�V¡$ Ä²5Í9¡$£> õ®T�VÌ�µf®<©b®³f�V¡$ @�>½@°�» ¼<£>µM½�£Lµf§> @¶�©b�V³�¡$²�¡$£> ���©b®<ª1 @¦b²5Íq²5­1 @¦a�V¡$µM²5�b§DµM�¾¡$£> ÄË<ÅQ÷�ø¾Ð5Éb£>µf§b§F©>¬5¬5 �§F¡a§�ħF @½@²5�>�Ó§F¡$¦a�V¡$ @¬5°�»a�b�5®E @³M°_§F¡a�V¦$¡$µM�>¬ÄÍF¦$²1® ¡$£>  £>µM¬5£> �§F¡]ª1²5©>�>�i�V�>�Á�> @½@¦$ ��5§FµM�>¬eµM¡]µM�²5¦$�> @¦�¡$²k¤>�>�Ó¡$£> ¾¤>¦a§F¡�©>�b§$�V¡$µf§F¤b�Vª>³M LµM�b§F¡a�V�>½@ �ÐQÉb£> ¾�>¦a�$¼<ªb�V½��_²5Í]¡$£>µf§�®E @¡$£>²q�iµf§¡$£b�V¡Ã¡$£> Q �§F¡$µf®T�V¡$ Q²5Í9¡$£> k®T�VÌ�µf®<©b®´³f�V¡$ @�>½@°õ½��V�+ª1 Ä @Ì�¡$¦$ �®E @³M°XµM�b�V½@½@©>¦a�V¡$ �Ðg¸T§ ��>µM¦$ @½@¡�½@²5�b§F @¶�©> @�>½@ �»Õ¼d ¾­>¦$²5­1²1§F +�T§F²5³M©>¡$µM²5�U�V�>²5­>¡$µM�>¬Ó�Ī>µM�b�V¦$°¨§F ��V¦$½�£bÐ�Æa¡a�V¦$¡$µM�>¬¼<µM¡$£ �V�U �§F¡$µf®T�V¡$ �²5Í�¡$£> _²5­>¡$µf®T�V³<³f�V¡$ @�>½@°�»�¼d _½@¦$ ��V¡$ �¡$£> _½@²5¦$¦$ �§F­1²5�>�>µM�>¬ÎË<ýE÷­>¦$²5ª>³M �® �V�>�ǽ��V³M³�¡$£> ÓÆa¸EÉí§F²5³MÏ� @¦¾¬5µMÏ�µM�>¬�µM¡õ�_ú$§$®T�V³M³fü ¡$µf®E T³Mµf®EµM¡aÐL¸E½@½@²5¦$�>µM�>¬5³M°¡$²T¡$£> e¦$ �§F©>³M¡�­>¦$²q�>©>½@ @�iª�°+¡$£> X§F²5³MÏ� @¦a»D¡$£> ¾ �§F¡$µf®T�V¡$ ¾²5Íb¡$£> ¾³f�V¡$ @�>½@°+µf§g½@²5¦$¦$ @½@¡$ @�b»�V�>�Ç���> @¼¢ª1²5©>�>�+µf§�¡$¦$µM @�bÐ<ý�²5¡$µM½@ Ä¡$£b�V¡ÃµMÍ9¡$£> kÆa¸EÉ¢§F²5³MÏ� @¦<µf§�©>�b�Vª>³M Ä¡$²�§F²5³MÏ� Q¡$£> Ë<ýE÷_­>¦$²5ª>³M �®Â¼<µM¡$£>µM�+¡$£> E¡$µf®E E³Mµf®EµM¡a»�¼d Ä½@²5�b§FµM�> @¦ ¡$£> EµM�b§F¡a�V�>½@ k�5§9©>�b§$�V¡$µf§F¤b�Vª>³M �Ð� �X¬5 @�> @¦a�V³f»5¡$£>µf§ ®EµM¬5£�¡Ã³M ��V�X¡$²ÁµM�>½@²5¦$¦$ @½@¡eúFµfÐ  �ÐM»{§F©>ª>«"²5­>¡$µf®T�V³fü9¦$ �§F©>³M¡a§$»�µM�X¡$£> T§F @�b§F ¡$£b�V¡E�e§$�V¡$µf§F¤b�Vª>³M �µM�b§F¡a�V�>½@ �®T�$°Áª1 <½@²5�b§FµM�> @¦$ @�Ç�5§1©>�b§$�V¡$µf§F¤b�Vª>³M �»5ª>©>¡�¡$£> <­>¦$²5ª>³M �®½��V�Xª1 k§F²5³MÏ� @�ö§Fµf®E­>³M°kµM�>½@¦$ ��5§FµM�>¬T¡$£> ��"©>�b§$�V¡� Á¡$£>¦$ �§F£>²5³M�b»�¼<µM¡$£¨�V�Ç�V¡e®E²1§F¡ ³MµM�> ��V¦

·5¿

Page 101: BMC’03 - JKUfmv.jku.at/papers/bmc03-preliminary-proceedings.pdfBMC’03 Boulder, Colorado, USA. ... Alessandro Cimatti (IRST, Italy) Raanan Fraer (Intel, Israel) Danny Geist (IBM

���������������������

0

200

400

600

800

1000

1200

0 2 4 6 8 10 12 14 16 18

CPU Time

Bound

rotor benchmark

"!$#&%"'&%)(�*,+.-0/213+0!$46587,5�9;:;<�:�(�*,+.=?>&<�@�A�%B+0C�5DA�E&FGEHE&9;5B>&I�FGE&!$@�5�AKJ0!$FGC�EL9;<�@M>&NFGC�5D:;OPC�5�A�<�Q$5�9�>&@MFGC�5BRTS&UVSWR?IX5�@�OPC�46E&9;YHJ0!$FGCMFZJ[>H!$FG5�9;E&FG5�:\E&@�AMEL9;5�:;>&<�9;O�58EW]E&!$Q$E&I�!$Q$!$FZ^O�>&9;9;5�:;_X>&@�A�!$@�#BFG>6FGC�5a`�9;:;F?9;>WJb>&NcFGE&I�Q$5Dd&%egf�h�h[igjlk�mn�opfqn�rtsujXvm�h�w

x y{za|H}�~��P��}��a��������}����)�P���� m�hp�Xf���m��k�mn�iGr8mj���sue?n�m�hp�Xeg��h�fqj���mege[��jXf��\j���mjXv��2rtsun��"h)�g�u�GwL�2su�Xegml��hp�Xf��Lh���Xmtvf�r8kXegm��ig�G��fqo����Xmt��mjXv��2rtsun��.hpm� igj¡��mn�rth�fqo�j��2r\��mn fqo�fqk�mn�su��igfqj2h�¢�sujX£j��2r\��mnDfqo2vfqjX£Xig��igfqj2h[v��Xmv���m£2w

¤&¥ ¦ §©¨;¥ ª «­¬�®p¯©¦±°²ªV¥ ³´¶µ «­¤P³´¶·¸¥ ªV¥ ³´¶µ¦ ³Gª$³u¦ ¹Gº »µG¼G¦ ½Gº ¾¿ ·;§Tª ½G¹ À

+cE&I�Q$5aÁ-0!$9;O�<�!$F0-0>&46_�Q$5�Â�!$FZ^H!$@tFG5�9;46:0>&N"Ã�<�48IX5�9�>&N"Äa_X5�9;E&FG!$>&@�:0E&@�A�-0>&@�A�!$FG!$>&@�:0-0C�5�OPY&5�A�%+0C�5�A�E&FGEBE&9;5�9;5�N¶5�9;9;5�AHFG>BFGC�5�E&O�^�O�Q$!$O\]&5�9;:;!$>&@�>&N�FGC�5�46>�A�5�Q$ÅX!$%$5�%$Å�J0!$FGCaÆ;<�:;F[>&@�5�!$FG5�9;E&FG5�%

� man�sujtfq�Xn0m��k�mn�iGr8mj���h,fqj�s6�qÇqÈqÈ6É�Ê�ËHÌ�mj���ig�2rÎÍgÏ3�\ig�����6РÑ�����mafqo�rtsuigjr8m�r8fqn���waÒ�fqnLsuege"���Xm6m��k�mn�iGr8mj���h���m �2hpm£ÓÑ�mn��"ÉtigjÓ�g�q�u��sqhaÔ�Õ8�ÖmjX×qigjXm�w

�2su�XegmH� hp�2rtrtsun�igËm�h"fq�Xn0n�m�hp�Xeg��h�w � mavf�r8k2sun�ma���Xman�m�hp�Xeg��h"fq�X��suigjXm£M�\ig���­���Xmhp��n�su��m×q�tkXn�m�hpmj���m£ligj����XiGh�k2suk�mn��\ig���K���Xm­hpfqop�G�)sun�mBkXn�m�hpmj���m£�igj¡�g���0sujX£�egf�v�suegeg�n�mØVn��Xj2w Étfqn�mLigj�£Xm��suigeG¢�fq�Xn8£2su��sMsun�mLfq�X��suigjXm£bsu£XfqkX��igjX×����XmL�Xigj2sun��Öhpm�sun�v��ÚÙ�sqh£Xm�hpvn�ig��m£�igjL���Xm�kXn�mÛ�igfq�2h?hpmv��igfqj2Ü��\ig���ls����Xn�m�hp�Xfqeg£HfqoX�G��f­r8igj��X��m�h�w\Ý�fq��igvm����2su�suegeX���XmHh�su��iGhpÞ2su�XegmDigj2hp��sujXvm�h"��mn�mD��megeßn�mvfq×qjXigËm£M���H���XmHÔ�Õ8�ÚhpfqegÛ�mn�àáigjX£Xmm£M���Xmj��2r\��mn�h?fqo\hpv��Xm£X�Xegm£�v��vegm�h�n�mkXn�m�hpmj��8���Xm6��n��Xm)fqkX��iGrtsue,eGsu��mjXvigm�h�w

�2�Xm¡r8m�sujXigjX×�fqo\vfqeg�2r8j2h8iGha���XmKopfqegegf��\igjX×�â{ãåä æGçèVéêæGçëBigjX£Xigv�su��m�hD���XmKj��2r8Ø��mnDfqo[k2sun�suegegme�igj2hp��sujXvm�h0vfqj2hpig£Xmn�m£bÙp�\�Xmjb�q¢���mLn�mopmnD��fM���XmKsuv��vegigvLkXn�fq�Xegm�rt¢

�qì

Page 102: BMC’03 - JKUfmv.jku.at/papers/bmc03-preliminary-proceedings.pdfBMC’03 Boulder, Colorado, USA. ... Alessandro Cimatti (IRST, Italy) Raanan Fraer (Intel, Israel) Danny Geist (IBM

í�î�ï�ð�ñ�ò�ó�ô�î�õ�ö

÷&ø ù ú©û;ø ü ý­þ ü$ÿ©ù��²ü$ÿ�� ý���ÿ����û;ù úTÿ�� ý­÷�Vú� ÿ�� �� � �� ��� �����������;ø ��� �"!pÿ©ùý#�� � ��ø $�ÿ ý&%'�Zù � ý­÷( � û)�gÿ�� ��ø $�ÿ� *)�+;ÿ���� � ��� � ���

ù �Gü,�uù - -�.�/ -�0�/ -�1 -�2 354565756 7 8 3 95954 4 -5-�6 7 8 :- -�.�/ -�0�/ 251 ; 354565756 7 8 3 ;5952 4525:52 7 8 :- -�.�/ -�0�/ 251</ -)= -�7 ;545;5256 7 8 ; -5-�452 4 -�354 7 8 4- -�.�/ -�0�/ 251</ 2>= ; ;545;5256 7 8 3 95257 4 -�?52 7 8 :2 -�.�/ -�0�/ 251</ -)= -�7 ;53 -�35656 4 8 6 4535459 :56575453 -�7 8 72 -�.�/ -�0�/ 251</ 2>= 9 -�45453 -�?52 6 8 ; 45:5952 :525;535: -�7 8 ;2 -�.�/ -�0�/ 251</ :>= 9 -�;5654 -�25; ; 8 2 454525; :5:575256 ; 8 62 -�.�/ -�0�/ :51</ 2>= ; 4 -�?595?54 2 8 3 4525959 : -�?575: 6 8 3: -�.�/ -�0�/ 251</ -)= -�2 -�;565:5? -�45; -�?5254 8 7 95?535: 352545:56 -5-�; 8 9: -�.�/ -�0�/ 251</ 2>= -�2 @'A'B C 95;56 - 35:56 -�2 :575; 8 9: -�.�/ -�0�/ 251</ :>= -�2 @'A'B C 9595?53 35457575; 25;5; 8 :: -�.�/ -�0�/ :51</ 2>= 9 @'A'B C ;525259 ?595;575: :53 8 6

�5�Gù - -�.�/ -�0�/ 251</ -)= -�7 -�75756565357 ? 8 9 25?5:52 -�2545;54 -58 ;- -�.�/ -�0�/ :51</ 2>= 9 ?5:52545652 4 8 - 2535;5; -�4535354 2 8 2- -�.�/ D50�/ 251</ 2>= ; 4 -5-�;5656 : 8 7 4535459 -�25;5:52 -58 32 -�.�/ -�0�/ 251</ -)= -�: @'A'B C -�2 -�?5; -�75956525: :525; 8 62 -�.�/ -�0�/ :51</ 2>= -�7 @'A'B C -�75;5:59 ;535; -�3 656 8 ;2 -�.�/ D50�/ 251</ 2>= -�7 @'A'B C -�75?5:59 ;53 -�:53 652 8 9

E +;úTü - -�FG/ ->CH/ -)= -�9 :5756565757 -58 ? 253535? ;5:5652 -�:5: 8 3- -�FG/ ->CH/ 2>= -�: 257575: -�2 -58 2 2 -�:5; 6535352 -58 -2 -�FG/ ->CH/ -)= :52 C @'A'B -�9 -�2 - 2525:545:5: ?5252 8 72 -�FG/ ->CH/ 2>= 256 C @'A'B -�3 -�75: -�;5;53 -�9 45?54 8 6

IKJ(L�M,NPOQ�RS NUT�V�M,NXW�NUY>V�M,Z5Y>[\IKNU]>^`_,a�b(M,b(c(dfe)b(] R b(M,V�^`a�Y�gih�jUk5l(m�n�oUjUk"p�qsrtrtuPvPwxqsy{zsuPqsw

|\}P~�� qsW�q�I } W�u | w Q zs��u���w ~ zsy�I\u���wxy{b�b(��zs��IKJ(L�M,NUuPI\[ ~ zsy�I�_,Y\J`Z��Gb(��Z5_,^`NY>Z5NU��Y\��_,�HNUM,_,a�NUT�^�V�M,Z5_,��M,_,NU]���� S NUafa�b(Z\��]>NUY>NUa�Z5wx^�V�M,Z5_,��M,_ R J(Z5_,b(a�YsJ(]>NP�HNU]>e)b(]>^`NUT�L�d�Z S Nqsy{zs�5[xqsM,Mxb(Z S NU]�]>NUY>b(V�] R NUY\J(]>NPY>_,a�c(M,NPZ5_,^`NPY>Z5NU��[ }s�s� _,a�T�_ R J(Z5NUY�b��(NU]>��b��i��_,a#Z5NU]>^`Yb(e{^`NU^`b(]>d`b(] |\� z�Z5_,^`NU�5[���NXV�Y>NsJ&Z5_,^`NXM,_,^`_,Z�NU��V�J(M�Z5b&� S b(V�]GJ(a�TfJ&^`NU^`b(]>d`M,_,^`_,Z

NU��V�J(MxZ5b`�(�(� ~ ��d�Z5NUY>[

���¡ H¢ £¡¤X¥5¦�¢`¤�¢¨§�£¡¢` ©§�ªH«H¬�¥�ªH­®§�¬��¯��°H¥�ªH­�±{¢  ©§¡²�¥���£´³¡µ¯¶ ��¬�·©¸�ªº¹¼»�½ ¾¿�ÀÂÁÄà ½ ¾\¥�ªH«H¥�¶�§��¡¢�¦�¡ H¢¨ª�·©¸X±{¢ £®§�ªH«��5Å�°{¢���ÆP£¡¢�¦���·H£¡¶ ¢�¦�§�¬�¬��´¤�¢ «©µ&¹ÈÇ©É(Ã Ê ½ ¾&¥5¦Ë�¡ H¢�ÌHª©§�¬`¦���¬�·H�¡¥���ª�¥�ª�¡¢ £´¸Í��ÆΦ�¶U H¢ «H·H¬�¢ «�¶ Å�¶ ¬�¢�¦¡ÏÑÐ���£`¢�§�¶U Ò¢ Ó�°{¢ £¡¥5¸�¢ ª���¤�¢¨£¡¢ °{��£¡�`�¡ H¢�«©§��´§f��±H�´§�¥�ªH¢ «¤X¥��¡ ÕÔ�Ö�×5Ø�¥5Ï ¢�Ï�ØÂ�¡ H¢Ëª�·©¸X±{¢ £s��Æ\ÙtÚ�ÚºªH�¯«H¢�¦s§�ªH«#�¡ H¢�ÛXÜ\ÝÒ�¡¥5¸�¢�£¡¢ Þ�·H¥�£¡¢ «©ØK§�ªH«�¤X¥��¡ ��·H£Î¸�¢ �¡ H�¯«Òß�ª�·©¸X±{¢ £X��Æ<²H§�£¡¥5§�±H¬�¢�¦X§�ªH«à¶ ¬5§�·©¦�¢�¦G­�¢ ªH¢ £´§��¡¢ «àÆ���£t�¡ H¢�ÛXá�Ðâ°H£¡��±H¬�¢�¸¶ ��£¡£¡¢�¦�°{��ªH«H¥�ªH­#�¡���¡ H¢¨¦���¬�·H�¡¥���ª©Ø�§�ªH«â�¡ H¢`�¡���´§�¬�ÛXÜ\Ýã�¡¥5¸�¢�³¡Ï

ä ²�¢ £´§�¬�¬5Ø�¤�¢P¶�§�ª®¸�§�å�¢P�¡ H¢XÆ���¬�¬��´¤X¥�ªH­`��±©¦�¢ £¡²H§��¡¥���ª©¦¡ÏXÐ���£Ë§�¶ Å�¶ ¬�¥�¶P°H£¡��±H¬�¢�¸�¦¡Ø��¡ H¢�¡¥5¸�¢�¦<£¡¢ Þ�·H¥�£¡¢ «�±�Å#�¡ H¢&�5¤���¶ �{¸�°©§�£¡¢ «æ¸�¢ �¡ H�¯«©¦t§�£¡¢�Þ�·H¥��¡¢#¦�¥5¸�¥�¬5§�£Îß�¤X¥��¡ ¨��ªH¬�Å#��ªH¢¢ Ó�¶ ¢ °H�¡¥���ª©Øx�¡ H¢çÌH£´¦��&¢ Ó�°{¢ £¡¥5¸�¢ ª���Æ���£Îè�éÂà ꡳ¡Ïçëì�´¤�¢ ²�¢ £´Ø{¤X H¢ ªí¤�¢â¸��´²�¢��¡�¨¬��¯��°H¥�ªH­±{¢  ©§¡²�¥���£´¦¡Ø¯¤X H¥�¬�¢Î�¡ H¢¨¸�¢ �¡ H�¯«à·©¦�¢ «î¥�ªÒÔ�Ö�×�±{¢ ¶ �{¸�¢�¦G·HªHÆ�¢�§�¦�¥�±H¬�¢�Ø'��·H£�¦��¡£´§��¡¢ ­�ÅѦ��¡¥�¬�¬

ï�ð

Page 103: BMC’03 - JKUfmv.jku.at/papers/bmc03-preliminary-proceedings.pdfBMC’03 Boulder, Colorado, USA. ... Alessandro Cimatti (IRST, Italy) Raanan Fraer (Intel, Israel) Danny Geist (IBM

ñìò�ó�ô'õ¯ö{÷´øfò�ù�ú

ûHü¡ý¯þHÿ�����������çý�û����� ��Gü����ÿ�������� ��������� þ� ���ý�ÿ����&ý�������������������� ��!�û"� ü��������#�þ�����ý������¡ü# ������� ��Pý�ÿHü$��ý���ÿ���ý��%�� ��%&"��'(� ü)*��+"������'(���

, -�.0/21436527986.0/27;:�/2<>=�[email protected]

H �ÎûHü���������� 2����IJ �ûHûHü¡ý" ��K�L��ý�ü���)M�N&{ý�����%���K��� þHÿ������O*&� ���� þîý��P 2����I ûHü¡ý�&��������ý�ü#�Xÿ��� ���ý��Q ��Hþ%����`ÿ����`ý��SR#T��U��ý���'(� ü#�V ��HþXWZY\[X'(� ü�]��� ���ý��P������Hý¯þHý���ý�O�)��^ !�û"� ü��������# ��<ü����ÿ����#�Gý��`_2acbd�Z ��HþQ[N_2acbd�Z���Hý#IU��� ��Xý�ÿHüd��ý���ÿ���ý��e�� ��e&"�

'(� ü)*��+"������'(�* ��Hþ%� ý"��û"������'(�dIN���P��)M�N&{ý�����*WZ_2_0fg&� ���� þe����K�����h�ÿ�����a�ÿ��¡ÿHü�\I�ý�üi�IN������������ÿHþ��j���'(������O" ���ý�� ý���&"����� ük���¡ü# ����O�����d��ý�ül�����[Nm�a

ûHü¡ý�&������nO������ ü# ���ý��X ��HþX��ý���ÿ���ý��X���� �ü�K�����O"�

o Bcp�BcACBc/214Bc7

q rts�uMv*wyxtz{xt|~}{���e��v*���K�(�����(}{�6���e��ve����}{�(���t�l��v*�S}{���~���t�e��v*���~}{�K���*wyv*��xt����xt|~xt�� vl����|~�K�K�~��xt�*�"vl�"x���xt�t���t�e��vl�Mxt�~�~�K|~�t���K�*�Svl�����K���(}{�lxt��� � vl��xt���t}{����xt����}{�  }{���K�K�(���Kz{z{}{�M¡6��xt|~��¢£xt|~�K�����t¤¥�¦¢£xt|~�����t�����K�~}{�t���t¤@��§����K�����K����¨(�~���K§��@©d�����y��ªS�"«g���¬�¬ |~�txt�6���{­��Sz{�(¢£�K| � �Kxt���K§�}{�V������z{}{�~���K|~�~��rt®t®t¯tv

q °ts���v"��x�¨(��xtz{��¡ � �����t§�xt��xt��wyxt�~�K�e��¨(§����tz{}{�����6���K����z{}{���t�{­d����±²�����K�~}{�~��³���}{�t�K|~�~}{�¦¨��t¤��xtz{}{¤¥�t|~��}{x���xt�(��x�wyxt|~��xt|~xt�´±Z�K�Kv"°tµtµtµtv

q ¶ts���v���x�¨(��xtz4xt���luMv4wy|~�K¢£�K|~�0¡6��·��K}{�K�(�N�����K�(��}{���$¤¥�t|N��¸(xt�K�N��¨(§����tz{}{� � �����t§�xt��x6©wyxt�~�K�����6���K����z{}{���t�{­���|~�(�Kv�«g������«g��� � ±Z¹{®tºt� ¬ xt�t�K��»t¯t¯6©9»tºtrt����xt�V���t�~�K����xtz{}{¤¥�t|~��}{xt�¼ ���(v"rt®t®tºtv

q »ts���vy��x�¨(��xtz�xt���\uMv�wy|~�K¢£�K|~��¡ � �����t§�xt��xt��wyxt�~�K�Q���6���K����z{}{���l¤¥�t|2�"�(� ¬ }{���l±Zu´�S�~­t�«g�(���K|~��xtz´½0� ¬ �t|~������®t® rt»t�´ªS�K��v´rt®t®t®tv

q ¾ts��(��� ¬�¿{ÀtÀ ¤¥� ¬ v{}{�K�~v{���K}{v{�K��� Àt¬ ��� À ��z{�~¨(�(��� À�Á ���"��¨(�(����®t°t�{���"��¨(�(����®t¾�Â�v

q Ãts��(��� ¬�¿{ÀtÀ ¢�¢�¢�v{�~¨(��� ¬ �~¨(�~v{�K�t§ Àt¬ |~�(�����K��� À z{�t�t}{� À ���K�~}{�t� �K�t§ ¬ }{z{�K|~v{�(��§�z{v

q ¯ts���v���v���¢£xt���t�@��v���v@�"�K�K�@xt����Ä�v@��v����~���M¡ � u��t|~§�xtz ��¬�¬ |~�txt�6�d���V���������6���K����z{}{�����|~�t��z{�K§Å}{�Æ��}{�t�����"�K�t�Kz0��¨(�(�����K�~}{�~�{­*«g�����Ç��|~xt���~v��t�Æ���t§ ¬ �����K|~� � }{���K�j±Z�K�~}{�t���rtµ ¿ »tÃt»6©9»t¯t¾t� ��¬ |~vCrt®t®trtv

q ºts��Sv��S���t��|~}{���Sv0�"xt�(�(�~��§�}{��xt|~x�¨txt��xt�0xt��� ¼ v0����xt��¡6��}{�t����z{�K�t�KzZ�~¨(�(�����K�~}{�d�t¤Zz{��¢��¬ ��¢£�K|4�K�t�(��|~�tz{��È���¢k}{�(���K���~}{�t���K}{|~�K��}{���~�{­S«g�����*��|~xt���~v��t�2���t§ ¬ �����K|~� � }{���K�2±Z�K�~}{�t���rtº9É�rt°tÊ ¿ rt¯trt¾6©9rt¯t°t®#�c±Z�K�Kv"rt®t®t®tv

q ®ts � v���vË�Mxt|~�t�K|~����vË��vË��}{�K�Kxt|~|~�t�@xt���2��v���z{}{��xt|~�M¡6� � � ��¿@� ��|~�t�t|~xt§Ç¤¥�t|c±Zxt��x ¬ xt�����¨(�(�����K�~}{�~�{­���|~�(�Kv�«g����� Àt� ���n«g��� � ±Z¹{®trt� ¬ xt�t�K�M»tÃtr6©9»tÃtÃt���"xt�   �K�txt�~�Ë�������crt®tºtÃtv

q rtµts���v��SvM�Mxt��z{}{�lxt���l��v���vM�S��}{�t�(����¡6u��t|~�K�¦©9±Z}{|~�K�K���K�L���6���K����z{}{���$¤¥�t|Z������wy�K��x��(}{�t|~xtz��¨(�(�����K�~}{�c�t¤ � ��«g���~�{­N«g�����L��|~xt���~vË�t�d���t§ ¬ �����K|~� � }{���K��±Z�K�~}{�t����º ¿ ÃtÃtr6©9Ãt¯t®t�C�������rt®tºt®tv

Ì�Í

Page 104: BMC’03 - JKUfmv.jku.at/papers/bmc03-preliminary-proceedings.pdfBMC’03 Boulder, Colorado, USA. ... Alessandro Cimatti (IRST, Italy) Raanan Fraer (Intel, Israel) Danny Geist (IBM

Î�Ï�Ð(Ñ9Ò@Ó"Ô#Õ Ï�Ö�×

Ø ÙtÙtÚ�ÛgÜÞÝ0ßtà�á{âtã�ä~åKâ(á{æ;ßtç�àéèMÜÞêyë~åKì£åKë~íÆî6ïñð�åKìóò�ô(õ�ö�ãt÷{á{æ�ø�åKæ6ù�ç�á{ú(û�å�ü¥ãtë`ý�ãtç(þ�ë~ãt÷{ÿ� å���åKç�à�åKç(þ£ò�æ6ù�åKà�û�÷{á{ç��tí���Û����\ø�ë~ßtç�~Ü9ãtç$ý�ãtõ���û�þ�åKë~ÿ�ï�á{à�åKà � å�~á��tç�í9ý �9Ù�����Ù�������������tí���ßtç�Ü´Ù������tÜ

Ø Ù��tÚ���Ü��Sãt÷{à�ö�åKë��Sßtç�à ��Ü�ð�ã�â(á�!tã�â(í�î6êyåKë�!#"�á{ç��@ßVè�ß�~þ�ßtç�àdÝ0ãtö�û�~þcò�ï4ø�ÿ�ò�ãt÷{âtåKë~í��%$�ë~ã(æKÜÛ����&tï�ý'" � ï4ø'�(�)��tí ��ß��tå��Ù������9Ù����*$Mßtë~á�~í´è�åKö�Ü���)�)��tÜ

Ø Ù�+tÚ��SÜ"ý�ßtö�ã(à�áCßtç�àÞò�Ü´ð�ã(æKæKã$ßtç�àÞò�Ü�,Sû�åKë~íyî6Ûgõ���ë~ã�â(á{ç��dò�ï4ø�ÿ�ö�ß�~åKàÞêyãtû�ç�à�åKà-"�ã(à�åK÷ý�ù�åKæ�!(á{ç��Nö(ô."�åKßtç�cãtü9ê �/� ÿ�ö�ß�~åKàdï0����ë~ã21(á{õ�ßtþ�å�ø�ë~ß�âtåKë�~ßt÷�~í��%$�ë~ã(æKÜËÛ����&tï�ý'"� ï4ø'�3��)�)�+tí ��ß��tå�54���4�����)�+tí "�û�ç�á{æ6ù�í��SåKë~õ�ßtç(ôKí�"�ßtë~æ6ù-��)�)�+tÜ

687