Using TLA+ in the Development of a Safety-Critical Fault-Tolerant Middleware | IEEE Conference Publication | IEEE Xplore