AIB 2012-17: Trustworthy Spacecraft Design Using Formal Methods