Design methodology for system correctness: lessons from the Tandem NonStop CLX | IEEE Conference Publication | IEEE Xplore