Formal specification and verification