, Verifying and validating the required behaviour of an IIP

, Defining a list of safety properties

, Demonstrating how we can help to meet FDA requirements for certifying IIPs using formal methods

, Showing how to use Event-B's refinement process to retain intellectual control of the modelling process, formalization, and analysis

P. Carayon and K. E. Wood, Patient safety. Inf. Knowl. Syst. Manag, vol.8, issue.1-4, pp.23-46, 2009.

Y. Chen, M. Lawford, H. Wang, and A. Wassyng, Insulin pump software certification, FHIES 2013, vol.8315, pp.87-106, 2014.

N. K. Singh, H. Wang, M. Lawford, T. Maibaum, and A. Wassyng, Formalizing the glucose homeostasis mechanism, DHM 2014, vol.8529, pp.460-471, 2014.

K. L. Keatley, A review of the FDA draft guidance document for software validation: guidance for industry, Qual. Assur, vol.7, issue.1, pp.49-55, 1999.

, A reseach and development needs report by NITRD: high-confidence medical devices: cyber-physical systems for 21st century health care

I. Lee, G. J. Pappas, R. Cleaveland, J. Hatcliff, B. H. Krogh et al., High-confidence medical device software and systems, Computer, vol.39, issue.4, pp.33-38, 2006.

J. Bowen and V. Stavridou, Safety-critical systems, formal methods and standards, Softw. Eng. J, vol.8, issue.4, pp.189-209, 1993.

N. K. Singh, Using Event-B for Critical Device Software Systems, 2013.

D. Méry and N. K. Singh, Real-time animation for formal specification, Complex Systems Design and Management, pp.49-60, 2010.

A. Wassyng, Though this be madness, yet there is method in it, Proceedings of For-maliSE, pp.1-7, 2013.

J. Abrial, Modeling in Event-B -System and Software Engineering, 2010.

, Project RODIN: rigorous open development environment for complex systems, 2004.

P. Masci, A. Ayoub, P. Curzon, I. Lee, O. Sokolsky et al., Model-based development of the generic PCA infusion pump user interface prototype in PVS, SAFECOMP. LNCS, vol.8153, pp.228-240, 2013.

B. G. Kim, A. Ayoub, O. Sokolsky, I. Lee, P. Jones et al., Safety-assured development of the GPCA infusion pump software, 2011 Proceedings of the International Conference on Embedded Software (EMSOFT), pp.155-164, 2011.

J. Wang, S. Liu, Y. Qi, and D. Hou, Developing an insulin pump system using the SOFL method, 4th Asia-Pacific Software Engineering Conference (APSEC), pp.334-341, 2007.

H. Xu and T. Maibaum, An Event-B approach to timing issues applied to the generic insulin infusion pump, FHIES 2011, vol.7151, pp.160-176, 2012.

I. Sommerville, Software Engineering, 7th edn, 2004.

N. K. Singh, H. Wang, M. Lawford, T. S. Maibaum, and A. Wassyng, Report 18: formalizing insulin pump using Event-B, McSCert, 2014.