Formally verifying fault tolerant system designs