首页 > 最新文献

Formal Methods in Software Practice最新文献

英文 中文
Specifying the mode logic of a flight guidance system in CoRE and SCR 在CoRE和SCR中指定飞行制导系统的模式逻辑
Pub Date : 1998-03-04 DOI: 10.1145/298595.298856
Steven P. Miller
This paper describes the experiences of Rockwell Avionics & Communications in using the CORE and SCR methods to specify the requirements for the mode logic of a Flight Guidance System for a General Aviation class aircraft. The example was first specified by hand using the CORE method,inspected, then entered into a prototype tool supporting the SCR method provided by the Naval Research Lab. Despite careful review of the CORE model, use of the SCR tool revealed 27 errors, many of them sign& cant. Difficulties encountered, a brief analysis of the errors discovered, and issues for industrial use are discussed.
本文介绍了罗克韦尔航空电子与通信公司在通用航空级飞机飞行制导系统中使用CORE和SCR方法确定模式逻辑要求的经验。首先使用CORE方法手工指定示例,进行检查,然后进入支持海军研究实验室提供的SCR方法的原型工具。尽管对CORE模型进行了仔细的审查,但SCR工具的使用发现了27个错误,其中许多是显著的。遇到的困难,对发现的错误进行了简要分析,并讨论了工业应用中的问题。
{"title":"Specifying the mode logic of a flight guidance system in CoRE and SCR","authors":"Steven P. Miller","doi":"10.1145/298595.298856","DOIUrl":"https://doi.org/10.1145/298595.298856","url":null,"abstract":"This paper describes the experiences of Rockwell Avionics & Communications in using the CORE and SCR methods to specify the requirements for the mode logic of a Flight Guidance System for a General Aviation class aircraft. The example was first specified by hand using the CORE method,inspected, then entered into a prototype tool supporting the SCR method provided by the Naval Research Lab. Despite careful review of the CORE model, use of the SCR tool revealed 27 errors, many of them sign& cant. Difficulties encountered, a brief analysis of the errors discovered, and issues for industrial use are discussed.","PeriodicalId":125560,"journal":{"name":"Formal Methods in Software Practice","volume":"35 1","pages":"0"},"PeriodicalIF":0.0,"publicationDate":"1998-03-04","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"123827538","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 118
Verification of an audio control protocol within real time process algebra 实时过程代数中音频控制协议的验证
Pub Date : 1998-03-04 DOI: 10.1145/298595.298860
Liang Chen
1. ABSTRACT In this paper, we formally analyze an audio control protocol developed by Philips. We use real time process algebra to model the protocol and weak bisimulation to verify its implementation against its specification. 1.1 Keywords Communication protoco1, real time system formal methods, process algebra, weak bisimulation. 2. INTRODUCTION In [4], Bosscher, Polak and Vaandrager have formally analyzed, based on weak timed forward simulation by using the timed I/O automata, a simple version of an audio control protocol developed by Philips for the physical layer of an interface bus that connects the various devices of some stereo equipment. The protocol, which uses Manchester encoding, has to deal with a significant uncertainty in the timing events due to both hardware and software constraints. It is a very nice example and therefore it has been suggested as a benchmark for other researchers to test their methods on, just as the Cizt and Mouse example of [lo] and the Gas Burner example of [ 143. Process algebra such as CCS [ll], CSP [9] and ACP [3] have been used to describe and analyze concurrently executing systems including communication protocols. The notion of weak bisimulation provides simple and elegant proof techniques for showing an implementation (usually a parallel process) meets its specification (usually a Permission IO make di&l/hard copy of all or pan of this work for personal or classroom use is gaated without fee provided that copies ate not made of dishibuted for profit or commerci al advantage, the copyright notice, tbe tide of the publication aad its date appear, aad notice is given that copying is by permission of ACM, Inc. To copy otherwise, to republish. to post oa servets or to redistribute to lists, requires prior SpeGifiC permission sad/or a fee. sequential process). There are many applications of process algebra for the formal verification of concurrent systems based on weak bisimulation [7,12,13] Recently there are many proposals and resultson real time process algebra. Most of the published .results regard completeness, de&lability and expressiveness issues. Unlike the untimed case, the timed version of weak bisimulation bears criticism of being too fine to be useful in formal verification of real time systems. So far there are very few published results in verification of real time systems (even toy examples) based on timed weak bisimulation. In this paper, we will present a formal analysis of the Philips's audio control protocol based on timed …
1. 本文正式分析了飞利浦公司开发的音频控制协议。我们使用实时过程代数对协议进行建模,并使用弱双仿真来验证其实现是否符合其规范。1.1关键词通信协议,实时系统形式化方法,过程代数,弱双仿真2. 在b[4]中,Bosscher, Polak和Vaandrager通过使用定时I/O自动机进行弱定时前向仿真,正式分析了飞利浦为连接某些立体声设备的各种设备的接口总线的物理层开发的音频控制协议的简单版本。该协议使用曼彻斯特编码,由于硬件和软件的限制,必须处理定时事件的重大不确定性。这是一个非常好的例子,因此它被建议作为其他研究人员测试他们的方法的基准,就像Cizt和Mouse的例子[lo]和Gas Burner的例子[143]一样。进程代数如CCS[11]、CSP[9]和ACP[3]已被用于描述和分析包括通信协议在内的并发执行系统。弱bisimulation提供简单和优雅的概念证明显示技术实现(通常是一个平行的过程)符合其规范(通常是一个IO di&l /许可复印件全部或盘的工作为个人或教室使用复制提供gaated不费吃不是利润或由dishibuted commerci基地优势,版权通知,此种潮流出版aad的日期出现,广告注意的是考虑到复制是ACM的许可,公司。复制,再版发布oa服务器或重新分发到列表,需要事先获得特定许可和/或收费。连续的过程)。过程代数在基于弱双仿真的并发系统形式化验证中有许多应用[7,12,13],最近有许多关于实时过程代数的建议和成果。大多数已发表的结果涉及完整性、可解性和表达性问题。与非定时情况不同,弱双模拟的定时版本因过于精细而无法用于实时系统的正式验证而受到批评。到目前为止,在基于时间弱双仿真的实时系统验证(甚至是玩具示例)方面发表的结果很少。在本文中,我们将对Philips的基于定时的音频控制协议进行形式化分析。
{"title":"Verification of an audio control protocol within real time process algebra","authors":"Liang Chen","doi":"10.1145/298595.298860","DOIUrl":"https://doi.org/10.1145/298595.298860","url":null,"abstract":"1. ABSTRACT In this paper, we formally analyze an audio control protocol developed by Philips. We use real time process algebra to model the protocol and weak bisimulation to verify its implementation against its specification. 1.1 Keywords Communication protoco1, real time system formal methods, process algebra, weak bisimulation. 2. INTRODUCTION In [4], Bosscher, Polak and Vaandrager have formally analyzed, based on weak timed forward simulation by using the timed I/O automata, a simple version of an audio control protocol developed by Philips for the physical layer of an interface bus that connects the various devices of some stereo equipment. The protocol, which uses Manchester encoding, has to deal with a significant uncertainty in the timing events due to both hardware and software constraints. It is a very nice example and therefore it has been suggested as a benchmark for other researchers to test their methods on, just as the Cizt and Mouse example of [lo] and the Gas Burner example of [ 143. Process algebra such as CCS [ll], CSP [9] and ACP [3] have been used to describe and analyze concurrently executing systems including communication protocols. The notion of weak bisimulation provides simple and elegant proof techniques for showing an implementation (usually a parallel process) meets its specification (usually a Permission IO make di&l/hard copy of all or pan of this work for personal or classroom use is gaated without fee provided that copies ate not made of dishibuted for profit or commerci al advantage, the copyright notice, tbe tide of the publication aad its date appear, aad notice is given that copying is by permission of ACM, Inc. To copy otherwise, to republish. to post oa servets or to redistribute to lists, requires prior SpeGifiC permission sad/or a fee. sequential process). There are many applications of process algebra for the formal verification of concurrent systems based on weak bisimulation [7,12,13] Recently there are many proposals and resultson real time process algebra. Most of the published .results regard completeness, de&lability and expressiveness issues. Unlike the untimed case, the timed version of weak bisimulation bears criticism of being too fine to be useful in formal verification of real time systems. So far there are very few published results in verification of real time systems (even toy examples) based on timed weak bisimulation. In this paper, we will present a formal analysis of the Philips's audio control protocol based on timed …","PeriodicalId":125560,"journal":{"name":"Formal Methods in Software Practice","volume":"16 1","pages":"0"},"PeriodicalIF":0.0,"publicationDate":"1998-03-04","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"116505938","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 1
Checking properties of safety critical specifications using efficient decision procedures 使用有效的决策程序检查安全关键规格的属性
Pub Date : 1998-03-04 DOI: 10.1145/298595.298603
David Y. W. Park, J. U. Skakkebæk, M. Heimdahl, Barbara J. Czerny, D. Dill
Abstract : The increasing use of software in safety critical systems entails increasing complexity, challenging the safety of these systems. Although formal specifications of real-life systems are orders of magnitude simpler than the system implementations, they are still quite complex. It is easy to overlook problems in a specification, ultimately compromising the safety of the implementation. Since it is error-prone and time consuming to check large specifications manually, mechanical support is needed. The challenge is to find the right combination of deductive power (i.e., how rich a logic and what theories are decided) and efficiency to complete the verification in reasonable time. In addition, it must be possible to explain why a proof fails. As an initial approach to solving this problem, we have adapted the Stanford Validity Checker (SVC), a highly efficient, general-purpose decision procedure for quantifier-free first-order logic with linear arithmetic, to check the consistency of specifications written in Requirements State Machine Language (RSML). We have concentrated on a small but complex part of version 6.04a of the specification of the (air) Traffic alert and Collision Avoidance System (TCAS II). SVC was extended to produce a counter-example in terms of the original specification. The efforts discovered an undesired inconsistency in the specification, which the maintainers of the specification independently discovered and subsequently fixed in the most recent version. The case study demonstrates the practicality of uncovering problems in real-life specifications with a modest effort, by selective application of state-of-that-art formal methods and tools. The logic of SVC was sufficiently expressive for the properties that we checked, but more work is needed to extend the class of formulae that SVC decides to cover the properties found in other parts of the TCAS II specification.
摘要:软件在安全关键系统中的应用越来越多,其复杂性也越来越高,对系统的安全性提出了挑战。尽管实际系统的正式规范比系统实现简单很多,但它们仍然相当复杂。很容易忽略规范中的问题,最终危及实现的安全性。由于手工检查大规格容易出错,耗时长,需要机械支持。挑战在于找到演绎能力(即逻辑有多丰富,决定什么理论)和效率的正确组合,以便在合理的时间内完成验证。此外,必须有可能解释为什么证明失败。作为解决这个问题的初始方法,我们采用了Stanford Validity Checker (SVC),这是一种高效的通用决策程序,用于使用线性算法进行无量词的一阶逻辑,用于检查用需求状态机语言(RSML)编写的规范的一致性。我们专注于(空中)交通警报和避碰系统(TCAS II)规范的6.04a版中一个小而复杂的部分。SVC被扩展为根据原始规范产生一个反例。这些努力发现了规范中不希望出现的不一致,规范的维护者独立地发现并随后在最新版本中进行了修复。案例研究通过选择性地应用最先进的形式化方法和工具,展示了通过适度的努力揭示现实生活规范中问题的实用性。对于我们检查的属性,SVC的逻辑已经足够表达,但是需要做更多的工作来扩展SVC决定的公式类,以涵盖TCAS II规范的其他部分中的属性。
{"title":"Checking properties of safety critical specifications using efficient decision procedures","authors":"David Y. W. Park, J. U. Skakkebæk, M. Heimdahl, Barbara J. Czerny, D. Dill","doi":"10.1145/298595.298603","DOIUrl":"https://doi.org/10.1145/298595.298603","url":null,"abstract":"Abstract : The increasing use of software in safety critical systems entails increasing complexity, challenging the safety of these systems. Although formal specifications of real-life systems are orders of magnitude simpler than the system implementations, they are still quite complex. It is easy to overlook problems in a specification, ultimately compromising the safety of the implementation. Since it is error-prone and time consuming to check large specifications manually, mechanical support is needed. The challenge is to find the right combination of deductive power (i.e., how rich a logic and what theories are decided) and efficiency to complete the verification in reasonable time. In addition, it must be possible to explain why a proof fails. As an initial approach to solving this problem, we have adapted the Stanford Validity Checker (SVC), a highly efficient, general-purpose decision procedure for quantifier-free first-order logic with linear arithmetic, to check the consistency of specifications written in Requirements State Machine Language (RSML). We have concentrated on a small but complex part of version 6.04a of the specification of the (air) Traffic alert and Collision Avoidance System (TCAS II). SVC was extended to produce a counter-example in terms of the original specification. The efforts discovered an undesired inconsistency in the specification, which the maintainers of the specification independently discovered and subsequently fixed in the most recent version. The case study demonstrates the practicality of uncovering problems in real-life specifications with a modest effort, by selective application of state-of-that-art formal methods and tools. The logic of SVC was sufficiently expressive for the properties that we checked, but more work is needed to extend the class of formulae that SVC decides to cover the properties found in other parts of the TCAS II specification.","PeriodicalId":125560,"journal":{"name":"Formal Methods in Software Practice","volume":"21 1","pages":"0"},"PeriodicalIF":0.0,"publicationDate":"1998-03-04","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"121205865","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 18
期刊
Formal Methods in Software Practice
全部 Acc. Chem. Res. ACS Applied Bio Materials ACS Appl. Electron. Mater. ACS Appl. Energy Mater. ACS Appl. Mater. Interfaces ACS Appl. Nano Mater. ACS Appl. Polym. Mater. ACS BIOMATER-SCI ENG ACS Catal. ACS Cent. Sci. ACS Chem. Biol. ACS Chemical Health & Safety ACS Chem. Neurosci. ACS Comb. Sci. ACS Earth Space Chem. ACS Energy Lett. ACS Infect. Dis. ACS Macro Lett. ACS Mater. Lett. ACS Med. Chem. Lett. ACS Nano ACS Omega ACS Photonics ACS Sens. ACS Sustainable Chem. Eng. ACS Synth. Biol. Anal. Chem. BIOCHEMISTRY-US Bioconjugate Chem. BIOMACROMOLECULES Chem. Res. Toxicol. Chem. Rev. Chem. Mater. CRYST GROWTH DES ENERG FUEL Environ. Sci. Technol. Environ. Sci. Technol. Lett. Eur. J. Inorg. Chem. IND ENG CHEM RES Inorg. Chem. J. Agric. Food. Chem. J. Chem. Eng. Data J. Chem. Educ. J. Chem. Inf. Model. J. Chem. Theory Comput. J. Med. Chem. J. Nat. Prod. J PROTEOME RES J. Am. Chem. Soc. LANGMUIR MACROMOLECULES Mol. Pharmaceutics Nano Lett. Org. Lett. ORG PROCESS RES DEV ORGANOMETALLICS J. Org. Chem. J. Phys. Chem. J. Phys. Chem. A J. Phys. Chem. B J. Phys. Chem. C J. Phys. Chem. Lett. Analyst Anal. Methods Biomater. Sci. Catal. Sci. Technol. Chem. Commun. Chem. Soc. Rev. CHEM EDUC RES PRACT CRYSTENGCOMM Dalton Trans. Energy Environ. Sci. ENVIRON SCI-NANO ENVIRON SCI-PROC IMP ENVIRON SCI-WAT RES Faraday Discuss. Food Funct. Green Chem. Inorg. Chem. Front. Integr. Biol. J. Anal. At. Spectrom. J. Mater. Chem. A J. Mater. Chem. B J. Mater. Chem. C Lab Chip Mater. Chem. Front. Mater. Horiz. MEDCHEMCOMM Metallomics Mol. Biosyst. Mol. Syst. Des. Eng. Nanoscale Nanoscale Horiz. Nat. Prod. Rep. New J. Chem. Org. Biomol. Chem. Org. Chem. Front. PHOTOCH PHOTOBIO SCI PCCP Polym. Chem.
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1