A. Arnold, G. Point, A. Griffault, and A. Rauzy, The altarica formalism for describing concurrent systems, Fundamenta Informaticae, vol.40, issue.23, pp.109-124, 1999.

J. Brunel, D. Chemouil, N. Mélédo, and V. Ibanez, Formal modelling and safety analysis of an avionic functional architecture with alloy, Embedded Real Time Software and Systems (ERTSS 2014), 2014.

J. Brunel, L. Rioux, S. Paul, A. Faucogney, and F. Vallée, Formal Safety and Security Assessment of an Avionic Architecture with Alloy, Proceedings Third International Workshop on Engineering Safety and Security Systems of Electronic Proceedings in Theoretical Computer Science (EPTCS), pp.8-19, 2014.
DOI : 10.4204/EPTCS.150.2

D. G. Firesmith, Engineering safety-and security-related requirements for softwareintensive systems: tutorial summary, International Conference on Software Engineering, pp.489-490, 2010.

D. Jackson, Software Abstractions: Logic, Language, and Analysis, 2006.

A. Lin, M. Bond, and J. Clulow, Modeling Partial Attacks with Alloy, Security Protocols, pp.20-33, 2010.
DOI : 10.1007/978-3-642-17773-6_4

M. Reynolds, Lightweight Modeling of Java Virtual Machine Security Constraints, Abstract State Machines, pp.146-159, 2010.
DOI : 10.1007/978-3-642-11811-1_12

M. Toahchoodee and I. Ray, Using Alloy to analyse a spatio-temporal access control model supporting delegation, IET Information Security, vol.3, issue.3, pp.75-113, 2009.
DOI : 10.1049/iet-ifs.2008.0074

J. Voirin, Method and tools to secure and support collaborative architecting of constrained systems, 27th Congress of the International Council of the Aeronautical Science, 2010.

J. Voirin and S. Bonnet, Arcadia: Model-based collaboration for system, software and hardware engineering, Complex Systems Design & Management, poster workshop, p.2013, 2013.