In Figure 1, the relation REQ specifies the relation between estimates of the monitored
quantities M and estimates of the controlled quantities C. In most cases, REQ extends REQ because
REQ not only describes the ideal behavior captured by REQ but also describes the externally
visible behavior that is not part of the ideal behavior. Because REQ is based on perfect knowledge of
the monitored quantities and perfect computations of the controlled quantities, REQ does not
describe how the system reports hardware malfimctions. In practical systems, hardware devices,
such as sensors, will fail, and the system will need to provide external notification of such failures.
REQ extends the required behavior described by REQ by describing how notification of hardware
malfunctions is presented to system users.