Ch is ian Heinzemann
Ve i ica ion and Simula ion o Sel -
Adap i e Mecha onic Sys ems
Band 348 de Ve lagssch i en eihe des Heinz Nixdo Ins i u s
© Heinz Nixdo Ins i u , Uni e si ä Pade bo n – Pade bo n – 2015
ISSN (P in ): 2195-5239
ISSN (0nline): 2365-4422
ISBN: 978-3-942647-67-0
Das We k einschließlich seine Teile is u hebe ech lich geschü z . Jede Ve we ung auße -
halb de engen G enzen des U hebe ech sgese zes is ohne Zus immung de He ausgebe
und des Ve asse s unzulässig und s a ba . Das gil insbesonde e ü Ve iel äl igung, Übe -
se zungen, Mik o e ilmungen, sowie die Einspeiche ung und Ve a bei ung in elek onischen
Sys emen.
Als elek onische Ve sion ei e ügba übe die Digi alen Sammlungen de Uni e si ä sbibli-
o hek Pade bo n.
Sa z und Ges al ung: Ch is ian Heinzemann
He s elle : Ve lagshaus Monsens ein und Vanne da OHG
D uck Buch Ve lag
Müns e
P in ed in Ge many
Bibliog a ische In o ma ion De Deu schen Biblio hek
Die Deu sche Biblio hek e zeichne diese Publika ion in de Deu schen Na ional-
bibliog a ie; de aillie e bibliog a ische Da en sind im In e ne übe h p://dnb.ddb.de
ab u ba
Ve i ica ion and Simula ion
o Sel -Adap i e Mecha onic Sys ems
zu E langung des akademischen G ades eines
DOKTOR DER NATURWISSENSCHAFTEN (D . e . na .)
de Fakul ä Elek o echnik, In o ma ik und Ma hema ik
de Uni e si ä Pade bo n
genehmig e
DISSERTATION
on
D . Ch is ian Heinzemann
Kassel
Tag des Kolloquiums: 30. Juli 2015
Re e en : P o . D . Wilhelm Schä e
Ko e e en : P o . D . Be y H. C. Cheng
Ko e e en : P o . D .-Ing. S e en Becke
P e ace
So called sel -adap i e o sel -op imizing sys ems adjus hei so wa e a chi ec u e, i.e. he
con igu a ion o so wa e modules a a ce ain poin in ime, au oma ically a un ime. This
beha io esul s in an e icien use o a ailable (ha dwa e) esou ces and makes hese sys ems
mo e obus han non sel -adap i e sys ems in cases when he en i onmen condi ions change.
De eloping sel -adap i e sys ems is e y challenging, because he sys ems, which a e he
subjec o his hesis, belong o he class o cybe -physical sys ems and exhibi a complex
in e play be ween ha dwa e and so wa e componen s as well as ha d eal ime equi emen s
o in e - and in a-componen communica ion.
The hesis p esen s a holis ic de elopmen app oach o cybe -physical sys ems, which is
based on model d i en de elopmen . Howe e , i ex ends his “classical” so wa e enginee -
ing app oach by means o o mally speci y and analyze so wa e (a chi ec u e) econ igu a-
ions in combina ion wi h he ul illmen o ha d eal ime cons ain s o econ igu a ion and
communica ion. A pa icula new and in iguing ea u e is o include and adap exis ing simu-
la ion echniques and ools om con ol enginee ing o suppo he analysis o a sys em mod-
el.
The app oach ep esen s a signi ican s ep o wa d in making he de elopmen o complex
cybe -physical sys ems mo e e icien , i.e. less cos ly, mo e igo ous and con ollable con-
ce ning he quali y o he esul ing sys em. I will su ely make i s way also in o indus ial use.
Pade bo n
, No embe 6, 2015
P o . D . Wilhelm Schä e
Summa y
Sel -adap i e mecha onic sys ems au oma ically adap hei beha io o a changing en i on-
men by econ igu ing hei so wa e a chi ec u e a un ime. In pa icula , his includes o
dynamically o m sys ems o sys ems a un ime, whe e se e al sys ems collabo a e wi h each
o he using message-based communica ion p o ocols. O en, hese sys ems a e sa e y-c i ical
and need o sa is y ha d eal- ime cons ain s, i.e., any ( iming) e o in hei beha io may pu
li es a isk. As a consequence, he so wa e o a mecha onic sys em needs o mee high qual-
i y s anda ds. In pa icula , i needs o be gua an eed ha econ igu a ions o he so wa e a -
chi ec u e do no lead o an unsa e beha io o a iola ion o he eal- ime cons ain s. Tes ing
alone canno p o e he co ec ness and he eby he sa e y o he mecha onic sys em. Exis ing
app oaches o model-d i en de elopmen and analysis o mecha onic sys ems ei he p o ide
suppo o analyzing eal- ime cons ain s o o analyzing econ igu a ions o he so wa e
a chi ec u e, bu none o he exis ing app oaches suppo s bo h.
In his hesis, we p esen a combina ion o cons uc i e and analy ical echniques ha can be
used by so wa e enginee s as pa o a model-d i en so wa e enginee ing me hod o assu -
ing he co ec ness o he so wa e o a sel -adap i e mecha onic sys em. As a key no el y,
ou app oach combines o mal e i ica ion and simula ion-based es ing o achie ing a scala-
ble analysis o he sys em's so wa e. As a basis, ou componen -based so wa e a chi ec u e
explici ly sepa a es disc e e e en -based so wa e componen s om ime-con inuous eedback
con olle s. This enables o e i y he so wa e componen s using a composi ional model
checking app oach ha we ex ended by a e inemen check o message-based communica ion
p o ocols. The co ec in eg a ion o so wa e componen s and eedback con olle s is as-
sessed by a es ing-based app oach based on model-in- he-loop simula ion. Finally, we de ine
an app oach o speci ying and e i ying he econ igu a ion beha io o so wa e componen s
ha , in pa icula , sepa a es he econ igu a ion beha io om he unc ional beha io o
imp o ing scalabili y o he e i ica ion.
We e alua ed all o ou con ibu ions based on he RailCab sys em. In pa icula , we speci ied
a componen -based so wa e a chi ec u e including econ igu a ions o a RailCab and con-
duc ed wo case s udies. These case s udies demons a e he iabili y o ou echniques.
Zusammen assung
Selbs adap i e mecha onische Sys eme passen ih Ve hal en übe die Rekon igu a ion ih e
So wa ea chi ek u zu Lau zei au oma isch an eine sich e ände nde Umwel an. Dies e -
möglich insbesonde e die Bildung on sogenann en „Sys ems-o -Sys ems“ zu Lau zei , in
denen meh e e eigens ändige Sys eme un e Ve wendung nach ich enbasie e Kommunika i-
onsp o okolle mi einande kollabo ie en. Dabei müssen die einzelnen Sys eme in de Regel
ha en Ech zei an o de ungen genügen und sind häu ig siche hei sk i isch, d.h. jegliche Feh-
le im unk ionalen ode zei lichen Ve hal en können Menschenleben ge äh den. Nich zu-
le z deshalb muss die So wa e eines komplexen mecha onischen Sys ems hohen Quali ä s-
s anda ds genügen. Die besonde e K i ikali ä diese Sys eme beding , dass eine Rekon igu a-
ion de So wa ea chi ek u nich zu einem unde inie en bzw. ge äh denden Ve hal en ode
eine Ve le zung de Ech zei an o de ungen üh . Du ch die Anwendung es basie e Ve -
ah en alleine kann die Ko ek hei und dami auch die Siche hei des mecha onischen Sys-
ems nich ga an ie we den. Exis ie ende Ansä ze ü eine modellge iebene En wicklung
und Analyse mecha onische Sys eme e möglichen en wede die Analyse on Ech zei an o -
de ungen ode die Analyse on Rekon igu a ionen de So wa ea chi ek u zu Lau zei . Bis-
he exis ie jedoch kein Ansa z de beides un e s ü z .
Im Rahmen diese A bei wi d eine Kombina ion aus kons uk i en und analy ischen Ve ah-
en o ges ell . Sie kann on So wa een wickle n im Rahmen eine modellge iebenen So -
wa een wicklungsme hode eingese z we den, um die Ko ek hei de So wa e eines selbs -
adap i en mecha onischen Sys ems zu e i izie en. Die Neua igkei des o ges ell en Kon-
zep s lieg in de geziel en Kombina ion o male Ve i ika ions e ah en mi simula ions-
basie en Tes e ah en mi dem Ziel, einen skalie ba en Ansa z ü die Analyse de So wa e
eines mecha onischen Sys ems zu e hal en. Als G undlage ü diesen Ansa z wi d ein Kom-
ponen enmodell o ges ell , das explizi zwischen e eignisdisk e en So wa ekomponen en
und zei kon inuie lichen Regle n un e scheide . Es e laub die o male Ve i ika ion de So -
wa ekomponen en mi einem komposi ionalen Model Checking Ve ah en, das um eine Ve -
eine ungsübe p ü ung ü nach ich enbasie e Kommunika ionsp o okolle e wei e wu de.
Die ehle eie In eg a ion on So wa ekomponen en und Regle n wi d anschließend mi
einem Tes e ah en un e Ve wendung on Model-in- he-Loop Simula ionen übe p ü . E -
gänzend wi d ein Konzep ü die Spezi ika ion und Ve i ika ion on Rekon igu a ionen o -
ges ell . Diese Ansa z enn explizi die Spezi ika ion und Analyse des unk ionalen Ve hal-
ens om Rekon igu a ions e hal en, um die Skalie ba kei de Ve i ika ion zu e besse n.
Alle Bei äge diese A bei wu den au Basis des RailCab Sys ems e aluie . Dazu wu de eine
komponen enbasie e So wa ea chi ek u ü das RailCab inklusi e de no wendigen Rekon-
igu a ionen en wickel . Wei e hin wu den zwei Falls udien du chge üh , die die p ak ische
Anwendba kei de o ges ell en Ve ah en au zeigen.
Acknowledgmen s
W i ing his PhD hesis has been an in ense expe ience. Th oughou all he ime ha I spend
o esea ching and w i ing, I was su ounded by many people ha suppo ed me in a ious
ways. Wi hou hese people, his wo k would no ha e been possible.
Fi s o all, I wan o hank my supe iso P o . D . Wilhelm Schä e o gi ing me he oppo -
uni y o wo k in he inspi ing en i onmen o his esea ch g oup and o he scien i ic guid-
ance along he way. I hank P o . D . Be y H.C. Cheng and P o . D . S e en Becke o w i -
ing hei epo s and P o . D . Falko D essle , D . Ma hias Meye , P o . D . Ansga T äch le
o a ending my exam.
I hank P o . D . S e en Becke o he many inspi ing discussions and a lo o aluable ad-
ice. This hesis would no be he same wi hou you. Fu he mo e, I would like o hank all o
my ( o me ) colleagues a he so wa e enginee ing g oup and he F aunho e p ojec g oup
mecha onic sys ems design o he scien i ic discussions, bu also o he enjoyable social
ac i i ies ha made my ime a Pade bo n a e y pleasan and aluable expe ience. These col-
leagues a e Anas Anis, Ch is ian B enne , Ch is ophe B ink, Nicola Danielzik, Tobias Eck-
a d , Ma kus Fockel, Jens F ieben, Ch is ophe Ge king, Faezeh Ghassemi, D . Joel G eenye ,
D . S e an Henkle , Jö g Hol mann, Tho s en Koch, Sebas ian Leh ig, Rena e Lö le , Ahme
Mehic, S en Me schjohann, D . Jan Meye , Fa uk Pasic, Ma ie Ch is in Pla enius, Uwe
Pohlmann, D . Jan Rieke, Da id Schmel e , Ch is ian S i zke, Julian Suck, Oli e Sudmann,
D . Ma hias Tichy, Die ich T a kin, D . Ma kus on De en, Benedic Wohle s, Jinying Yu.
Special hanks go o h ee o my colleagues. Fi s , o Ma hias Becke o being a e y alua-
ble o ice ma e and o he many, no always scien i ic discussions. Second, o D . Claudia
P ies e jahn o he excellen coope a ion in many scien i ic opics and a lo o aluable ad-
ice along he way. Finally, o S e an Dziwok o he many discussions and he excellen co-
ope a ion in he de elopmen o MECHATRONICUML and he MECHATRONICUML Tool Sui e.
In addi ion I hank all o he people wi h whom I collabo a ed in he SFB 614, in he RailCab
p ojec , and in he E-Mobil p ojec o p o iding me wi h he oppo uni y o wo k in a e y
in e es ing, in e disciplina y en i onmen . I highly app ecia e ou discussions and he excel-
len in e disciplina y collabo a ion.
Special hanks go o Ju a Haup and Jü gen Manie a o he so wa e enginee ing g oup, Dan-
iela Peine, Meike S e en, and And eas Knoke o he F aunho e p ojec g oup as well as
As id Canisius and Eckha d S e en o he In e na ional G adua e School "Dynamic In elli-
gen Sys ems" o hei excellen adminis a i e and echnical suppo . You always knew wha
o do.
Mo eo e , his wo k would no ha e been possible wi hou he s uden s ha con ibu ed o he
ideas and hei implemen a ion as pa o hei Bachelo 's and Mas e 's heses as well as hei
jobs as s uden wo ke s. In pa icula , I would like o hank Da id Schube and And eas Volk
who ha e been my s uden wo ke s o se e al yea s. I was always un wo king wi h you.
I hank Ma hias Becke , S e an Dziwok, Ma ie Ch is in Pla enius, Claudia P ies e jahn, and
Aind ila Basak o hei p oo - eading.
Page 6
D.3 MATLAB/Simulink and S a eflow................................................. D-16
D.3.1 Simulink ....................................................................... D-18
D.3.2 S a eflow....................................................................... D-19
D.3.3 Message-Based Communica ion......................................... D-20
D.3.4 Reconfigu a ion .............................................................. D-23
Lis o Abb e ia ions Page 7
Lis o Abb e ia ions
ACI The A omici y, Consis ency, and Isola ion p ope ies o a da abase sys em. 23, 24,
93, 133, 134
ACI-T ACI p ope ies combined wi h a co ec Timing. 93–95, 124, 125, 133–136, 225
ADL A chi ec u e Desc ip ion Language 86, 88–90
AMS Au onomous Mecha onic Sys em 28–30, 44, 51–53, 56, 58, 76–78, 80, 81, 91,
137, 225, A-13
ATCTL ∀-quan ified Timed Compu a ion T ee Logic, a a ian o TCTL ha only uses
∀-pa h quan ifie s 148, 195
CIC Componen Ins ance Configu a ion 13, 66, 67, 69, 85, 86, 91, 100, 104, 124–127,
136, 137, 176–178, 182, 184, 202, 211, 213, 219, 231, A-46
CSD Componen S o y Diag am 7, 8, 11, 12, 68–76, 83, 85–87, 91, 94, 95, 100–103,
111, 125–127, 129, 130, 132, 136, 177, 200, 202, 206, 209, 215, 225, A-59
CTL Compu a ion T ee Logic 34, 35, 127, 148, 149
DBM Di e ence Bound Ma ix 161
EMF Eclipse Modeling F amewo k 85, 215
GTS G aph T ans o ma ion Sys em 36–38, 127
LHS Le Hand Side o a G aph T ans o ma ion Rule 38, 39, 41, 73, 75, 126
LTL Linea -Time Tempo al Logic 36, 88, 127, 148, 149, 166, 167
MFM Mecha onic Func ion Module 27, 28
MIL Model-in- he-loop simula ion 21, 22, 24, 125, 169–171, 175, 176, 217, 221–224
MSD Modal Sequence Diag am 77, 79
NAC Nega i e Applica ion Condi ion o a G aph T ans o ma ion Rule 38–40
NMS Ne wo ked Mecha onic Sys em 28, 51, 76, 135, 137, 167, 225, 229
NTA Ne wo k o Timed Au oma a 8, 31–36, 49, 128, 129, 151, 160, B-3
OCL Objec Cons ain Language 53, 69, 85, 89, 90
Page 8
OCM Ope a o -Con olle -Module 28, 29, 44, 52, 57–60, 76, 90, 97, 110, 139, 170,
227, 228
QoS Quali y-o -Se ice 49, 170, 178, 187, 189
RHS Righ Hand Side o a G aph T ans o ma ion Rule 38, 39, 41, 73, 75, 126
RTCP Real-Time Coo dina ion P o ocol 7, 8, 10, 11, 43–45, 48–50, 53, 55–58, 61–63,
65, 76–81, 85, 91, 137–142, 149, 160, 162, 163, 166, 167, 186, 219, 221, 225, 226,
229, A-11
RTSC Real-Time S a echa 7–13, 45–49, 51, 55, 56, 58, 77, 78, 80, 85, 94, 101, 105–
107, 112, 113, 115–121, 123, 124, 128, 129, 132, 136–144, 146, 150–152, 154,
155, 159–165, 167, 169, 173, 177, 179, 189, 190, 192–200, 202, 204–211, 213,
216, 219, 226, 229, 230, A-62, B-1
SDD S o y Decision Diag am 8, 12, 13, 81–86, 89, 91, 94, 109, 110, 127, 207, 208,
225, A-27
TCTL Timed Compu a ion T ee Logic 34–36, 127, 141, 148, 149
TGG T iple G aph G amma 190, 215
WCET Wo s -Case Execu ion Time 111, 129–131, 206
Lis o Figu es Page 9
Lis o Figu es
1.1 The RailCab Sys em................................................................... 19
1.2 Illus a ion o he So wa e Reconfigu a ion o RailCabs o Building a
Con oy.................................................................................... 21
1.3 Exce p o he Design P ocess o he De elopmen o Sel -Adap i e
Mecha onic Sys ems ................................................................. 25
2.1 S uc u ing o Sel -Adap i e Mecha onic Sys ems ........................... 30
2.2 O e iew o he Ope a o -Con olle -Module .................................. 31
2.3 Illus a ion o a Model@Run ime.................................................. 32
2.4 Ne wo k o Timed Au oma a Speci ying a Simple Con oy Beha io .... 34
2.5 Exce p o a Zone G aph o he NTA in Figu e 2.4............................ 35
2.6 Example o a Type G aph ............................................................ 39
2.7 Typed A ibu ed G aph .............................................................. 39
2.8 G aph T ans o ma ion Rule o S a ing a Con oy ............................ 40
2.9 S o y Pa e n............................................................................. 42
2.10 S o y Diag am wi h Con ol Flow ................................................. 43
2.11 S o y Diag am wi h o -each Ac i i y Node..................................... 45
2.12 Decla a ion o he RTCP Dis anceT ansmission .................................. 46
2.13 Ins ance o he RTCP Dis anceT ansmission ...................................... 47
2.14 RTSC o Role ecei e o Dis anceT ansmission.................................. 48
2.15 RTSC o Mul i Role p o ide o Dis anceT ansmission ......................... 49
3.1 Kinds o Po s........................................................................... 56
3.2 Kinds o A omic Componen s ...................................................... 59
3.3 S uc u e o a RTSC o a Disc e e A omic Componen ....................... 60
3.4 Illus a ion o Exchanging a Con olle wi hou Fading Func ion ......... 61
3.5 The s uc u ed componen ype Con oyCoo dina ion ........................... 63
3.6 The componen ype RailCabD i eCon ol ......................................... 64
3.7 The componen ype Veloci yCon olle ............................................. 65
3.8 S uc u ally Compa ible Po s Allowing o a Connec o .................... 67
3.9 Componen Ins ance o Componen RailCabD i eCon ol o a RailCab
D i ing Alone........................................................................... 69
3.10 Componen Ins ance o Componen Con oyCoo dina ion o a Con oy
wi h 1 Membe .......................................................................... 70
3.11 CSD o Componen RailCabD i eCon ol ha Reconfigu es he Compo-
nen Ins ance o Se e as a Membe ............................................... 73
3.12 CSD o Componen Veloci yCon olle ha Reconfigu es he Componen
Ins ance o Se e as a Membe ..................................................... 74
3.13 O de Cons ain s o Mul i Po Va iables ...................................... 75
3.14 CSD o Adding a Con oy Membe ............................................... 76
Page 10
3.15 CSD o Componen Ope a ionS a egy ha Reconfigu es he Po s o
Being Membe .......................................................................... 78
3.16 MSD Speci ying he B oadcas Message Exchange o Ins an ia ing he
RTCP P o ocolIns an ia ion ............................................................ 80
3.17 Decla a ion o he RTCP P o ocolIns an ia ion.................................... 81
3.18 MSD Speci ying he Message Exchange o Ins an ia ing an RTCP ..... 82
3.19 Componen SDD isCoo dina o o Componen RailCabD i eCon ol ....... 84
3.20 Componen SDD isS andalone o Componen RailCabD i eCon ol........ 86
3.21 Componen SDD con oyO de o Componen RailCabD i eCon ol ........ 87
3.22 Plugins Implemen ing he Concep s o he Componen Model............. 88
4.1 P ocess o Speci ying Reconfigu a ion Beha io ............................. 96
4.2 Reconfigu a ion Con olle o a S uc u ed Componen ...................... 97
4.3 Componen Ins ance RailCabD i eCon ol wi h Reconfigu a ion Con olle 98
4.4 Sho -hand No a ion o Reconfigu able Componen s........................ 99
4.5 Use Case 1: Reconfigu a ion a e Child Reques ............................. 101
4.6 Use Case 2: Reconfigu a ion as Pa o 2-Phase-Commi .................... 101
4.7 P oblems when Replacing Con inuous Componen Ins ances using Sin-
gle-Phase Execu ion ................................................................... 102
4.8 Illus a ion o Th ee-Phase Execu ion ............................................ 103
4.9 RailCabD i eCon ol a e Execu ing he Se up Phase o he Reconfigu-
a ion becomeMembe .................................................................. 104
4.10 App oach o Iden i ying Quiescen S a es in MECHATRONICUML .... 108
4.11 RM Po Specifica ion o he RailCabD i eCon ol Componen .............. 110
4.12 Manage Specifica ion o he RailCabD i eCon ol Componen .............. 112
4.13 Execu o Specifica ion o he RailCabD i eCon ol Componen .............. 113
4.14 RE Po Specifica ion o he RailCabD i eCon ol Componen ............... 114
4.15 Gene a ion Templa e o he Manage RTSC ................................... 116
4.16 Gene a ion Templa e o he Execu o RTSC (P . 1) .......................... 120
4.17 Gene a ion Templa e o he Execu o RTSC (P . 2) .......................... 121
4.18 In e nal S uc u e o he Execu e_Th eePhase S a e............................ 124
4.19 Example o a Fo bidden CIC........................................................ 128
4.20 Ske ch o he Gene a ed NTA....................................................... 131
4.21 Child S ub Rep esen ing Con oyCoo dina ion o he Ve ifica ion o Rail-
CabD i eCon ol.......................................................................... 131
5.1 O e iew o he Refinemen App oach........................................... 142
5.2 RTSCs o Role ailcab and Role sec ion o RTCP En e Sec ion .............. 144
5.3 Componen s o he Di e en Types o T ack Sec ions ...................... 146
5.4 Refined P o ocol Beha io o No mal Sec ions ............................... 147
5.5 Deadlock Resul ing om RailCab S opping on a Swi ch.................... 147
5.6 Refined P o ocol Beha io o Swi ches ......................................... 148
5.7 Inco ec ly Refined P o ocol Beha io o Rail oad C ossings due o a
Timing E o in S a e CheckReques ............................................... 149
Lis o Figu es Page 11
5.8 Example o Illus a ing he Di e ences Be ween he Conside ed Re-
finemen Defini ions................................................................... 151
5.9 Refinemen Check using Tes Au oma a ......................................... 154
5.10 Decision T ee o Selec ing a Refinemen Defini ion ......................... 155
5.11 Cons uc ion Schema o ou Tes Au oma a.................................... 157
5.12 Example Tes RTSC (Exce p ) o Checking he Timed Bisimula ion
o sec ion................................................................................. 158
5.13 Adjus ed Po RTSC o Rail oad C ossings .................................... 163
5.14 Plugins Implemen ing ou Refinemen Check .................................. 165
5.15 Coun e example o he Inco ec ly Refined Beha io o Rail oad C oss-
ings ........................................................................................ 168
5.16 Co ec ly Refined Beha io o Rail oad C ossings ........................... 169
6.1 Simple Simulink Model .............................................................. 176
6.2 Enabled Subsys em .................................................................... 177
6.3 Simple S a eflow Cha ............................................................... 178
6.4 P ocess o Pe o ming a MIL Simula ion o a MECHATRONICUML
Model in Simulink and S a eflow ................................................. 179
6.5 UML Ac i i y Diag am Defining he Algo i hm o T ansla ing a MECH-
ATRONICUML Model in o a MATLAB/Simulink and S a eflow Model 181
6.6 Gene a ion Templa e o C ea ing a Subsys em o an A omic Compo-
nen Ins ance ............................................................................ 182
6.7 Gene a ion Templa e o C ea ing he In e nal S uc u e o a Subsys em
o an A omic Componen Ins ance ............................................... 184
6.8 Gene a ion Templa e o In e nal S uc u e o a Subsys em o a Fading
Componen ............................................................................... 185
6.9 Example o a Simulink Model o a Fading Componen ..................... 186
6.10 Example o a S a eflow Cha o a Fading Componen ...................... 186
6.11 Helpe Blocks ha Enable Reconfigu a ion o Con inuous Connec o
Ins ances in Simulink ................................................................. 187
6.12 Gene a ion Templa e o T ansla ing Con inuous Connec o Ins ances .. 188
6.13 Example o Using a Mul iTa ge Con ol Block o T ansla ing a Recon-
figu able Delega ion Connec o .................................................... 188
6.14 Gene a ion Templa e o T ansla ing Assembly Connec o Ins ances .... 189
6.15 Gene a ion Templa e o T ansla ing Delega ion Connec o Ins ances... 189
6.16 S a eflow Cha o he Subsys em g1 ............................................ 195
6.17 Gene a ion Templa e o T ansla ing Sen and Recei ed Messages o
T ansi ions o S a eflow............................................................... 197
6.18 Gene a ion Templa e o T ansla ing T ansi ions wi h Deadline o S a e-
flow ........................................................................................ 199
6.19 Mul i Po Ins ance wi h Resul ing RTSC ....................................... 200
6.20 Gene a ion Templa e o T ansla ing T ansi ions wi h Plain Synch o-
niza ions o S a eflow ................................................................. 201
Page 12
6.21 Gene a ion Templa e o T ansla ing T ansi ions wi h Synch oniza ions
wi h Selec o s o S a eflow........................................................... 202
6.22 Example o Using T ansi ions wi h Synch oniza ions wi h Selec o s in
S a eflow.................................................................................. 203
6.23 Exce p o he Reachabili y G aph o he Componen Con oyCoo dina-
ion.......................................................................................... 206
6.24 In eg a ion o he Configu a ionS o e in he MATLAB-specific Recon-
figu a ion Con olle ................................................................... 207
6.25 Gene a ion Templa e o he Configu a ion S o e RTSC ..................... 209
6.26 Example o he execu o Region o he Configu a ion S o e RTSC ....... 210
6.27 Adap ed Gene a ion Templa e o he Manage RTSC ....................... 212
6.28 Adap ed Gene a ion Templa e o he Execu o RTSC ....................... 213
6.29 A ay Implemen a ion o he A ec edComponen s S uc u e................. 214
6.30 Configu a ionS o e in he MATLAB-specific econfigu a ion con olle ... 215
6.31 Gene a ion Templa e o In eg a ing he MATLAB-specific Reconfigu-
a ion Con olle in o a Block Diag am o a s uc u e componen ins ance 217
6.32 Reconfigu a ion in S a eflow ....................................................... 219
6.33 Plugins Implemen ing he T ansla ion o MECHATRONICUML Models
o MATLAB/Simulink Models ..................................................... 220
6.34 Coope a ing Del a Robo s............................................................ 223
6.35 Coo dina ed O e aking o Two Ca s ............................................. 223
6.36 RailCabs T ying o En e he Same Swi ch...................................... 224
A.1 Decla a ion o he RTCP Con oyEn y ............................................. A-2
A.2 RTSC o he Role pee o he RTCP Con oyEn y .............................. A-3
A.3 Decla a ion o he RTCP Con oyCoo dina ion.................................... A-4
A.4 RTSC o he Role coo dina o o he RTCP Con oyCoo dina ion ............. A-6
A.5 RTSC o he Role membe o he RTCP Con oyCoo dina ion................. A-7
A.6 Decla a ion o he RTCP P ofileDis ibu ion ....................................... A-8
A.7 RTSC o he Role p ofileP o ide o he RTCP P ofileDis ibu ion ............ A-8
A.8 RTSC o he Role p ofileRecei e o he RTCP P ofileDis ibu ion............ A-9
A.9 Decla a ion o he RTCP SpeedT ansmission..................................... A-9
A.10 RTSCs o he Roles sende and ecei e o he RTCP SpeedT ansmission. A-10
A.11 Decla a ion o he RTCP S a Execu ion........................................... A-10
A.12 RTSCs o he Roles ini ia o and execu o o he RTCP S a Execu ion ..... A-10
A.13 Decla a ion o he RTCP S a egyExchange ...................................... A-11
A.14 RTSC o he Role sende o he RTCP S a egyExchange..................... A-11
A.15 RTSC o he Role ecei e o he RTCP S a egyExchange ................... A-11
A.16 Decla a ion o he RTCP Nex Sec ionF ee ........................................ A-12
A.17 RTSCs o he Roles acksec ion and swi ch o he RTCP Nex Sec ionF ee A-12
A.18 En i onmen Model o he RailCab Sys em.................................... A-14
A.19 RTSC o he Sys emIden ifica ion P o ocol .................................... A-15
A.20 S o y Diag am Implemen ing he Ope a ion upda eEn i onmen ............ A-16
A.21 S o y Diag am Implemen ing he Ope a ion addSys em...................... A-16
Lis o Figu es Page 13
A.22 S o y Diag am Implemen ing he Ope a ion clean ............................. A-17
A.23 RTSC Implemen ing he B oadcas Communica ion o Ins an ia ing
he RTCP P o ocolIns an ia ion ....................................................... A-18
A.24 RTSC Implemen ing he Role eques o o he RTCP P o ocolIns an ia ion A-20
A.25 RTSC Implemen ing he Role eques ee o he RTCP P o ocolIns an ia ion A-21
A.26 S uc u ed Componen Rail oadC ossing .......................................... A-22
A.27 Componen Ins ance o Componen RailCabD i eCon ol o a Coo dina-
o RailCab............................................................................... A-23
A.28 Componen Ins ance o Componen Veloci yCon olle ha is used by a
Coo dina o RailCab .................................................................. A-24
A.29 Componen Ins ance o Componen Con oyCoo dina ion o a Con oy
wi h 1 Membe .......................................................................... A-24
A.30 Componen Ins ance o Componen Con oyCoo dina ion o a Con oy
wi h 2 Membe s ........................................................................ A-25
A.31 Componen Ins ance o Componen RailCabD i eCon ol o a Membe
RailCab ................................................................................... A-26
A.32 Componen Ins ance o Componen Veloci yCon olle ha is used by a
Membe RailCab ....................................................................... A-26
A.33 RTSC o he Componen Ope a ionS a egy (P . 1)............................. A-28
A.34 RTSC o he Componen Ope a ionS a egy (P . 2)............................. A-29
A.35 RTSC o he Componen D i eLogic................................................ A-31
A.36 RTSC o he Componen Membe Con ol.......................................... A-32
A.37 RTSC o he Componen Con oyManagemen ................................... A-34
A.38 RTSC o he Componen Re Gen ................................................... A-36
A.39 RTSC o he Componen No malT ackSec ion .................................... A-38
A.40 RTSC o he Componen Swi ch .................................................... A-40
A.41 RTSC o he Componen C ossing_In P oc ....................................... A-41
A.42 Manage Specifica ion o he Con oyCoo dina ion Componen .............. A-43
A.43 Execu o Specifica ion o he Con oyCoo dina ion Componen .............. A-43
A.44 RE Po Specifica ion o he Con oyCoo dina ion Componen ............... A-43
A.45 RM Po Specifica ion o he Veloci yCon olle Componen .................. A-44
A.46 Manage Specifica ion o he Veloci yCon olle Componen ................. A-44
A.47 Execu o Specifica ion o he Veloci yCon olle Componen ................. A-44
A.48 RE Po Specifica ion o he Veloci yCon olle Componen ................... A-45
A.49 RM Po Specifica ion o he Ope a ionS a egy Componen ................. A-45
A.50 RE Po Specifica ion o he Ope a ionS a egy Componen .................. A-46
A.51 RM Po Specifica ion o he Con oyManagemen Componen .............. A-46
A.52 RE Po Specifica ion o he Con oyManagemen Componen ............... A-46
A.53 CSD o Componen RailCabD i eCon ol ha Reconfigu es he Compo-
nen Ins ance o Se e as a Coo dina o .......................................... A-47
A.54 CSD o Componen Ope a ionS a egy ha Reconfigu es he Po s o
Being Coo dina o ..................................................................... A-48
A.55 Cons uc o CSD o C ea ing an Ins ance o Con oyCoo dina ion.......... A-49
Page 14
A.56 Cons uc o CSD o C ea ing an Ins ance o Re Gen......................... A-49
A.57 CSD o Componen RailCabD i eCon ol ha Adds an Addi ional Con-
oy Membe ............................................................................. A-50
A.58 CSD o Componen Con oyManagemen ha Adds Po Ins ances o
an Addi ional Con oy Membe a he Beginning o he Con oy........... A-51
A.59 CSD o Componen Con oyManagemen ha Adds Po Ins ances o
an Addi ional Con oy Membe in he Middle o he Con oy............... A-52
A.60 CSD o Componen RailCabD i eCon ol ha Disables he Con oy Mode
by Dele ing he Necessa y Po Ins ances o Con oy Build-up............ A-53
A.61 CSD o Componen Ope a ionS a egy ha Disables he Con oy Mode
by Dele ing he Po Ins ances ha a e Necessa y o Con oy Build-up . A-53
A.62 CSD o Componen RailCabD i eCon ol ha Enables he Con oy Mode
by C ea ing he Necessa y B oadcas Po Ins ance ........................... A-54
A.63 CSD o Componen Ope a ionS a egy ha Enables he Con oy Mode
by C ea ing he Necessa y B oadcas Po Ins ance ........................... A-54
A.64 CSD o Componen Ope a ionS a egy ha C ea es a eques o Po In-
s ance...................................................................................... A-55
A.65 CSD o Componen Ope a ionS a egy ha C ea es a eques ee Po In-
s ance...................................................................................... A-55
A.66 CSD o Componen Ope a ionS a egy ha C ea es a pee Po Ins ance A-56
A.67 Gene a ed RTSC o he Manage o RailCabD i eCon ol (P . 1)............ A-58
A.68 Gene a ed RTSC o he Manage o RailCabD i eCon ol (P . 2)............ A-59
A.69 Gene a ed RTSC o he Execu o o RailCabD i eCon ol (P . 1)............ A-60
A.70 Gene a ed RTSC o he Execu o o RailCabD i eCon ol (P . 2)............ A-61
A.71 Defini ion o he A ec edComponen s Da a Type ............................... A-63
A.72 S o y Diag am Implemen ing he Ope a ion compu eA ec edChild en-
Fo BecomeMembe ...................................................................... A-64
A.73 S o y Diag am Speci ying he Beha io o ge Nex Po Ins anceFo Reques A-65
A.74 S o y Diag am Speci ying he Beha io o ge Message ...................... A-65
A.75 S o y Diag am Speci ying he Beha io o se Reply........................... A-66
A.76 S o y Diag am Speci ying he Beha io o allRepliesRecei ed .............. A-66
A.77 S o y Diag am Speci ying he Beha io o canCommi ....................... A-67
A.78 S o y Diag am Speci ying he Beha io o ge Nex Po Ins anceFo Ac ion . A-67
A.79 S o y Diag am Speci ying he Beha io o allAc ionsPe o med ............. A-68
A.80 S o y Diag am Speci ying he Beha io o se Finished ....................... A-68
A.81 S o y Diag am Speci ying he Beha io o allEmbeddedFinished ........... A-69
A.82 S o y Diag am Speci ying he Beha io o ese Ac ionPe o med ........... A-69
A.83 Componen SDD isMembe o Componen RailCabD i eCon ol ha Spec-
ifies ha an Ins ance o he Componen Ope a es as a Con oy Membe . A-70
A.84 Componen SDD con oyDisabled o Componen RailCabD i eCon ol ha
Specifies ha an Ins ance o he Componen will no Engage in Con oys A-71
Lis o Figu es Page 15
A.85 In a ian Componen SDD alidCon oyS a e o Componen RailCab-
D i eCon ol ha Defines ha a RailCab may no be Coo dina o and
Membe a he Same Time........................................................... A-71
A.86 In a ian Componen SDD con oyO de o Componen Con oyCoo di-
na ion o Speci ying a Co ec O de o he Re Gen Ins ances ............. A-72
A.87 Componen SDD inS andaloneC l o Componen Veloci yCon olle o
Speci ying ha an Ins ance o he Componen Execu es he S andalone-
D i e Con olle ......................................................................... A-74
A.88 Componen SDD inCon oyC l o Componen Veloci yCon olle o Spec-
i ying ha an Ins ance o he Componen Execu es he Con oyD i e
Con olle ................................................................................ A-74
A.89 In a ian Componen SDD alidC l o Componen Veloci yCon olle o
Speci ying ha an Ins ance o he Componen does no Execu e bo h
Con olle s a he Same Time ....................................................... A-75
A.90 Componen SDD inCoo dina o Mode o Componen Ope a ionS a egy
o Speci ying ha an Ins ance o he Componen Ope a es in a Coo -
dina o RailCab......................................................................... A-76
A.91 Componen SDD inMembe Mode o Componen Ope a ionS a egy o
Speci ying ha an Ins ance o he Componen Ope a es in a Membe
RailCab ................................................................................... A-77
A.92 Componen SDD isFi s o Componen Re Gen o Speci ying ha an
Ins ance o he Componen is he Fi s One in he Sequence o Re Gen
Ins ances.................................................................................. A-77
A.93 Componen SDD isLas o Componen Re Gen o Speci ying ha an
Ins ance o he Componen is he Las One in he Sequence o Re Gen
Ins ances.................................................................................. A-78
A.94 Subsys em co esponding o Componen Ins ance g1 o Type Re Gen... A-79
A.95 Subsys em Co esponding o he In e nal S uc u e o A omic Compo-
nen Ins ance g1 o Type Re Gen .................................................. A-80
A.96 Subsys em co esponding o Componen Ins ance cc o Type Con oy-
Coo dina ion .............................................................................. A-81
A.97 Subsys em co esponding o he Embedded CIC o he S uc u ed Com-
ponen Ins ance cc o Type Con oyCoo dina ion ................................. A-82
A.98 Subsys em o Figu e A.97 Including he Gene a ed MATLAB-specific
Reconfigu a ion Con olle .......................................................... A-83
A.99 In e nal S uc u e o he Reconfigu a ionCon olle Subsys em Gene a ed
o Componen Ins ance cc o Type Con oyCoo dina ion ...................... A-85
C.1 F amewo k o Reachabili y Analyses............................................ C-1
C.2 Class Diag am o he Co e Me amodel o he Reachabili y Analysis
F amewo k............................................................................... C-2
C.3 Class Diag am o he Me amodel o Reachabili y Analysis on S o y
Diag ams ................................................................................. C-6
C.4 Enhancing S o y Diag ams o Compu ing Successo s....................... C-9
Page 22 Chap e 1
he componen s is essen ial o ealizing he unc ionali y o he sys em [SW07]. This in-
cludes bo h, he communica ion be ween componen s inside a single sys em bu also he
communica ion be ween sys ems as pa o a sys em o sys ems [WA13]. As a esul , he
co ec ness o he so wa e o a sel -adap i e mecha onic sys em does no only depend
on he co ec ness o a single componen bu also on he co ec ness o he applica ion-
le el communica ion p o ocols ha define he in e ac ion be ween componen s and be-
ween di e en sys em.
Due o he sa e y c i ical na u e o sel -adap i e mecha onic sys ems, i is desi able o
apply o mal e ifica ion me hods like model checking [CGP00, BK08] o ensu e co -
ec ness o hei componen -based so wa e. Model checking gi es a ma hema ical p oo
ha sa e y and li eness p ope ies, which ha e been specified o he sys em, hold. How-
e e , o mal e ifica ion echniques like model checking su e om he so-called s a e-
explosion p oblem [CGP00]. I deno es he ac ha he numbe o un ime s a es o a
so wa e g ows exponen ially in bo h, he numbe p ocesses and he numbe o s a es o
each p ocess, i he sys em has concu en execu ions [CKNZ12]. This makes he e -
ifica ion o componen -based sys ems wi h concu en componen s quickly in easible.
Composi ional e ifica ion app oaches [BCC98] ackle he s a e-explosion p oblem by
e i ying single componen s o a componen -based sys em in isola ion. Many o hese
app oaches a e based on he assume/gua an ee p inciple [CGP00, ch. 12], i.e., hey e -
i y he co ec ness o a componen based on assump ions ha mus be gua an eed by he
componen ’s en i onmen . One o he main di ficul ies o assume/gua an ee app oaches
is de i ing good assump ions au oma ically om he so wa e model [CAC08].
One example o a composi ional e ifica ion app oach based on he assume/gua an ee
p inciple is gi en by he composi ional e ifica ion app oach o MECHATRONICUML
[GTB+03, GS13]. This app oach p e en s he compu a ion o assump ions by p o iding
a syn ac ic decomposi ion o he sys em. In pa icula , MECHATRONICUML sepa a ely
defines componen s and communica ion p o ocols ha define he in e ac ion o compo-
nen s. Then, componen s may be e ified unde he assump ion ha he in e ac ion ia
he communica ion p o ocol is co ec . Gua an eeing his assump ion equi es wo s eps.
Fi s , we need o e i y he communica ion p o ocol using model checking [EHH+13].
A his poin , he assume/gua an ee p inciple equi es ha he p o ocol is independen o
he componen . Second, we need o gua an ee ha he componen co ec ly implemen s
he communica ion p o ocol wi hou in alida ing he e ifica ion esul s ob ained o he
communica ion p o ocol in he fi s s ep.
Howe e , implemen ing he communica ion p o ocol in he componen equi es o mod-
i y i . In pa icula , we need o in eg a e he p o ocol wi h he in e nal beha io o he
componen , o example, o accessing da a and igge ing compu a ions. As a esul , we
need o e i y ha he componen implemen a ion o he communica ion p o ocol is a
co ec efinemen o he e ified p o ocol beha io acco ding o a efinemen defini ion.
The efinemen defini ion gua an ees ha he componen implemen a ion o a communi-
ca ion p o ocol does no in alida e he e ifica ion esul ha has been ob ained o he
communica ion p o ocol. In pa icula , a efinemen defini ion o mally defines how he
In oduc ion Page 23
componen implemen a ion ( efined p o ocol) may de ia e om he communica ion p o-
ocol (abs ac p o ocol) wi hou in alida ing a pa icula se o e ified p ope ies. Thus,
a sui able defini ion o efinemen is essen ial o a composi ional e ifica ion app oach
as he one used by MECHATRONICUML.
In li e a u e, many di e en efinemen defini ions and acco ding e ifica ion p ocedu es
exis [BK08, WL97, JLS00]. "Examples include imed simula ion and imed bisimula-
ion [WL97]. Depending on he pa icula ype o p o ocol ha is efined, all efinemen
defini ions migh be use ul when building a sys em. A sui able efinemen defini ion
o a composi ional app oach needs o be as weak as possible o enabling euse o an
abs ac p o ocol in as many di e en componen s as possible bu as s ong as neces-
sa y o gua an eeing ha all e ified p ope ies hold o he efined p o ocol. I he
efinemen defini ion is oo weak, i is no gua an eed ha e ified p ope ies s ill hold
o he efined p o ocol. I he efinemen defini ion is oo s ong, he efinemen check
migh ejec he efined p o ocol al hough i ulfills all p ope ies. This may happen, o
example, i he efined p o ocol emo es beha io ha is i ele an o he p ope ies,
bu which is checked by he oo s ong efinemen defini ion. The exis ing efinemen
defini ions p o ide di e en comp omises be ween euse and p ese ed p ope ies. As a
consequence, he e does no exis one efinemen defini ion ha is sui able o all pos-
sible p o ocols. Ins ead, a composi ional e ifica ion app oach should suppo se e al
efinemen defini ions whe e each o which may be sui able o a pa icula abs ac and
efined p o ocol and a se o e ified p ope ies." [HBDS15]
As a esul , we need an in eg a ed app oach ha au oma ically selec s a sui able e-
finemen defini ion and, in pa icula , e ifies i o a gi en pai o abs ac and efined
p o ocols.
3. Simula ion o Sel -adap i e Mecha onic Sys ems The sa e and co ec op-
e a ion o a mecha onic sys em depends on he co ec in eg a ion o he ime-con inu-
ous eedback con olle s and he disc e e so wa e componen s. This includes, in pa -
icula , econfigu a ion o he so wa e a chi ec u e a un ime. As discussed be o e,
econfigu a ion o he so wa e a chi ec u e o a mecha onic sys em may equi e o ex-
change eedback con olle s. Exchanging eedback con olle s in ol es he specifica ion
and execu ion o po en ially complex ading unc ions [BGO06, OMT+08] ha gua an-
ee ha sa e meaning ul alues a e applied on he physical machine a any ime du ing
he exchange. The e o e, i is absolu ely manda o y o ensu e co ec ness o he econ-
figu a ions.
A majo objec i e o MECHATRONICUML is o p o e he co ec ness o such sys em
models by applying o mal e ifica ion. Howe e , he in eg a ion o ime-con inuous
eedback con olle s whose beha io is defined by di e en ial equa ions ha dens o -
mal e ifica ion significan ly. In li e a u e, i is o en e e ed o as he hyb id model
checking p oblem [Hen96]. Hyb id model checking app oaches ei he only use e y
simple models o ime-con inuous beha io o hey apply o e app oxima ion echniques
Page 24 Chap e 1
[HHMWT00]. "A p ima y eason o adop ing o e app oxima ion is ha a p ecise
model, o a p ac ical enginee ing model a hand, inco po a es elemen s ha no e ifi-
ca ion ool can handle in combina ion. This is o en he case o hyb id sys em models
due o hei ich ocabula y. Analysis o such models can only commence a e a chain
o app oxima ion s eps, some o which can be achie ed au oma ically, o he s – he ma-
jo i y in p ac ice – equi ing manual e o mula ion o he model unde inspec ion. Each
o hese app oxima ions may cause a loss o p ecision in he model, e.g., when cap u ing
nonlinea beha io by a linea model, making he analysis less likely o succeed wi h a
posi i e ce ifica e as ou come. A he same ime, as hese app oxima ions o en ha e
o be done manually, hey equi e ex emely skilled s a , a e edious and ha e o be e-
pea ed when he o iginal model changes." [ERNF12] In addi ion, e en he mos ecen
echniques can only handle models ha a e "s ill o academic na u e in he size o p ob-
lems sol able." [ERNF12]. As a esul , i is no ye possible o e i y co ec ness o
la ge and complex econfigu able mecha onic sys ems such as he RailCab.
A di e en app oach o assess he co ec ness o he ope a ions o a mecha onic sys em
is es ing by using a model-in- he-loop (MIL) simula ion [Plu06]. In a MIL simula ion,
he de elope es s a model o he mecha onic sys em agains a model o i s en i on-
men . The model o he mecha onic sys em always includes he eedback con olle s
and he disc e e so wa e componen s, bu i may also include models o he mechanic,
elec ic, o hyd aulic pa s o he sys em. This app oach is al eady used in he au omo i e
indus y [BB08, SHS12].
MIL simula ion o mecha onic sys ems is suppo ed by comme cial-o - he-shel sim-
ula o s such as MATLAB R
/Simulink R
[Ma g] o Dymola [Das] o he specifica ion
language Modelica [F i04, Mod09]. These ools, howe e , equi e models o be s a ic,
i.e., once specified, componen s and connec ions may no change while unning a simu-
la ion. In addi ion, hey do no p o ide na i e suppo o asynch onous, message-based
communica ion wi h message bu e s.
As a esul , we need an app oach ha suppo s MIL simula ion o sel -adap i e mecha-
onic sys ems ha communica e ia asynch onous, message-based communica ion p o-
ocols. This app oach needs o be in eg a ed in o ou componen -based de elopmen
app oach such ha model checking he e en -disc e e so wa e componen s using he
composi ional e ifica ion app oach men ioned abo e emains possible.
1.3 Con ibu ion
The con ibu ion o his hesis is a combina ion o cons uc i e and analy ical echniques
ha suppo he componen -based specifica ion and analysis o sel -adap i e mecha-
onic sys ems as pa o a model-d i en app oach. As a key no el y compa ed o ela ed
app oaches, we combine o mal e ifica ion and simula ion-based es ing o achie ing a
scalable analysis o ensu ing co ec ness o he so wa e o a sel -adap i e mecha onic
In oduc ion Page 25
sys em. In pa icula , we con ibu e a ansac ional execu ion o hie a chical econfig-
u a ions including an app oach o hei e ifica ion (C1), a e ifica ion p ocedu e o
showing co ec efinemen s o communica ion p o ocols (C2), and suppo o simu-
la ing sel -adap i e mecha onic sys ems in MATLAB/Simulink (C3). We in eg a e ou
con ibu ions in o he MECHATRONICUML me hod. As a esul , ou con ibu ions en-
hance he exis ing de elopmen p ocess o MECHATRONICUML [HSST13, BDG+14b]
as ou lined in Figu e 1.3. All o ou con ibu ions ha e been implemen ed as pa o he
MECHATRONICUML Tool Sui e [DGB+14].
Domain-Speci ic Design and De elopmen
De i e Componen
Model
Speci y Communica ion
P o ocols
componen model communica ion p o ocol in eg a ed
pla o m-independen
model
S1S2
domain-spanning
concep ual design Speci y Componen
Recon igu a ion
econ igu a ion
beha io
eal- ime componen
beha io
Speci y Real-Time
Beha io o
Componen s
S4
S3
T ansac ional Execu ion
o Hie a chical
Recon igu a ions
Ve i ica ion o Co ec
Re inemen s
Simula ion Suppo in
MATLAB/Simulink
C1
C2
C3
p ocess s ep pa allel execu ion a e ac con ibu ion
Simula e Pla o m-
Independen
Model S5
domain-spanning
concep ual design
so wa e
a i ac s
Speci y Pla o m-
Independen Model
Speci y Pla o m-
Speci ic Model
Domain-Spanning
Concep ual Design
pla o m-independen
model
pla o m-
independen
SW-model
Legend
Figu e 1.3: Exce p o he Design P ocess o he De elopmen o Sel -Adap i e Mecha-
onic Sys ems (c . [HSST13, GV14])
The s a ing poin o he p ocess, shown in Figu e 1.3, is he domain-spanning concep-
ual design [GFDK09, GSG+09] ha has been c ea ed collabo a i ely by expe s om
all disciplines in ol ed in building he mecha onic sys em, e.g., mechanical enginee -
ing, con ol enginee ing, and so wa e enginee ing. I includes all in o ma ion abou
use cases, unc ions, and sys em elemen s ha a ec mo e han one discipline. Based
on he domain-spanning concep ual design, each o he in ol ed disciplines s a s he
domain-specific design and de elopmen phase. In his phase, he so wa e enginee s
execu e he MECHATRONICUML p ocess [HSST13, BDG+14b], which consis s o wo
main phases in acco dance o he model-d i en a chi ec u e app oach [G o14]. Thus,
he p ocess s a s by c ea ing a pla o m-independen model o he so wa e. Then, he
so wa e enginee s de i e a pla o m-specific model o he so wa e and define a deploy-
men o he so wa e o he ha dwa e pla o m. The con ibu ions o his hesis add ess
he specifica ion o he pla o m-independen model.
The so wa e enginee s a s speci ying he pla o m-independen model in S ep S1by
de i ing an ini ial componen model om he domain-spanning concep ual design. In
Page 26 Chap e 1
his hesis, we uni y he exis ing componen models o MECHATRONICUML and p o-
ide an ex ension ha enables a concise, decla a i e specifica ion o hie a chical econ-
figu a ions. This specifica ion o ms he basis o a ansac ional execu ion o econ-
figu a ions (C1) ha espec s ACI-p ope ies o da abase sys ems [BHG87]. These a e
a omici y, i.e., ei he all componen ins ances econfigu e o none does, consis ency,
i.e., each econfigu a ion p oduces a consis en componen ins ance configu a ion, and
isola ion, i.e., econfigu a ions do no in e e e wi h each o he .
In S ep S2, he so wa e enginee specifies a communica ion p o ocol o each in e ac ion
be ween componen s. This includes a o mal e ifica ion o he p o ocol beha io using
model checking [GTB+03, EHH+13, Ge 13].
A e speci ying he communica ion p o ocols, he so wa e enginee needs o speci y
he eal- ime beha io o each componen o he componen model. This eal- ime be-
ha io needs o include he communica ion p o ocols ha ha e been specified and e -
ified in S ep S2such ha he e ified sa e y and li eness p ope ies a e no in alida ed.
We suppo he so wa e enginee in his s ep by an in eg a ed e ifica ion p ocedu e
ha e ifies whe he he eal- ime beha io o a componen co ec ly efines a commu-
nica ion p o ocol acco ding o a o mal efinemen defini ion (C2). As a byp oduc , ou
app oach au oma ically selec s a sui able efinemen defini ion ou o a se o possible
efinemen defini ions.
In S ep S4, he so wa e enginee specifies he econfigu a ion beha io o he compo-
nen s using ou a o emen ioned ex ensions o he componen model. In addi ion, we
ex end his s ep by an app oach o e i ying ha he econfigu a ion beha io ulfills
he equi ed ACI-p ope ies and mee s all ha d eal- ime deadlines (C1). The esul o
S eps S3and S4is a pla o m-independen model o he so wa e.
Finally, he so wa e enginee needs o analyze whe he e en -disc e e so wa e and
ime-con inuous eedback con olle s ha e been in eg a ed co ec ly by using a MIL
simula ion in S ep S5. We suppo he so wa e enginee in his s ep by au oma ically
de i ing a simula ion model ha includes bo h, he eal- ime beha io and he econ-
figu a ion beha io o he componen s. The simula ion model is hen ex ended by he
implemen a ions o he eedback con olle s and he en i onmen model. The MIL simu-
la ion may hen be ca ied ou using MATLAB/Simulink. I enables he enginee s o he
di e en disciplines o alida e he whole sel -adap i e mecha onic sys em by simula-
ion and enables o use he code gene a ion acili ies o MATLAB/Simulink o de i ing
sou ce code o he sys em.
1.4 O e iew
The emainde o his hesis is s uc u ed as ollows. Chap e 2 in oduces he ounda-
ions ha a e equi ed o unde s anding he con ibu ions o his hesis. In Chap e 3,
we define a new componen model o MECHATRONICUML. The MECHATRONICUML
componen model o ms he basis o he emaining con ibu ions o his hesis. Along
In oduc ion Page 27
wi h he componen model, we con inue ou RailCab example om Sec ion 1.1. We
use his example h oughou he emainde o his hesis. Chap e 4 in oduces ou con-
cep o ansac ional execu ion o econfigu a ions. In addi ion, we explain ou con-
cep o e i ying econfigu able componen s o ACI and iming p ope ies. The ea e ,
Chap e 5 p esen s ou app oach o e i ying ha communica ion p o ocols ha e been
co ec ly efined by he componen s in ou componen model. Nex , we p esen ou
app oach o MIL simula ion o sel -adap i e mecha onic sys ems in Chap e 6. In pa -
icula , we define how simula ion models in MATLAB/Simulink can be de i ed au o-
ma ically om a MECHATRONICUML model. Finally, we summa ize he con ibu ions
o his hesis and gi e a pe spec i e on u u e wo ks in Chap e 7. We discuss he im-
plemen a ion and e alua ion o ou concep s as well as ela ed wo ks along wi h ou
con ibu ions as pa o he main chap e s o his hesis.
The appendices p o ide addi ional, mo e echnical in o ma ion ha supplemen ou con-
ibu ions. Fi s , Appendix A p esen s addi ional pa s o he RailCab model ha we use
as a unning example. Appendix B con ains a o mal defini ion o he seman ics o Real-
Time S a echa s ha we use o defining s a e-based beha io . Finally, we desc ibe ou
amewo k o pe o ming eachabili y analyses (Appendix C) and he me amodels ha
ha e been c ea ed as pa o his hesis (Appendix D).
Founda ions Page 29
2 Founda ions
This chap e in oduces he ounda ions o unde s anding he concep s p esen ed in
he emainde o his hesis. We s a by e iewing concep s and e minology ela ed
o sel -adap i e mecha onic sys ems in Sec ion 2.1 ha we will use in he ollowing.
The ea e , Sec ion 2.2 in oduces imed model checking including imed au oma a and
he imed compu a ion ee logic. The la e wo p o ide he o mal basis o speci y-
ing and e i ying s a e-based beha io models o a sel -adap i e mecha onic sys em.
Sec ion 2.3 in oduces g aphs and co esponding g aph ans o ma ions ha o m he
basis o speci ying and e i ying econfigu a ion ope a ions o a sel -adap i e mecha-
onic sys em. Finally, Sec ion 2.4 in oduces MECHATRONICUML, which is a domain-
specific language based on imed au oma a and g aph ans o ma ions, ha enables o
speci y so wa e models o a sel -adap i e mecha onic sys em on a highe le el o
abs ac ion. We will in eg a e all o he con ibu ions o his hesis in o MECHATRON-
ICUML.
2.1 Sel -Adap i e Mecha onic Sys ems
Sel -adap i e mecha onic sys ems au oma ically adap hei so wa e a chi ec u e o a
changing en i onmen wi hou human in e en ion. Tha equi es o in eg a e and asso-
cia e he so wa e wi h he cons i uen pa s o he mecha onic sys em such ha he
sys em may eason abou i sel and i s beha io in i s cu en en i onmen . In his
sec ion, we in oduce basic concep s and co esponding e minology ela ed o sel -
adap i e mecha onic sys ems ha we use h oughou he emainde o his hesis. In
Sec ion 2.1.1, we desc ibe how sel -adap i e mecha onic sys ems may be s uc u ed
hie a chically. The ea e , we in oduce he ope a o -con olle -module as a e e ence
a chi ec u e ha enables o ealize sel -adap i e beha io in mecha onic sys ems (c .
Sec ion 2.1.2). Finally, Sec ion 2.1.3 desc ibes how he concep o models@ un ime
may be used o execu ing econfigu a ions.
2.1.1 S uc u ing
Sel -adap i e mecha onic sys ems can be s uc u ed hie a chically as shown in Fig-
u e 2.1. In pa icula , hey can be s uc u ed in o mecha onic unc ion modules, au-
onomous mecha onic sys ems, and ne wo ked mecha onic sys ems (c . [GRS14, pp. 8-
10]).
On he lowes le el, a mecha onic sys em consis s o se e al mecha onic unc ion mod-
ules (MFM). An MFM embodies pa o he mechanical sys em including senso s, ac u-
a o s, and so wa e o con olling he mechanical sys em. An example is gi en by he
d i e module [HZ14] o he ac i e suspension module [KT14] o a RailCab. MFMs may,
again, be composed o o he MFMs.
Page 30 Chap e 2
Ne wo ked Mecha onic Sys em (NMS)
Au onomous Mecha onic Sys em (AMS)
Mecha onic Func ion Module (MFM)
Figu e 2.1: S uc u ing o Sel -Adap i e Mecha onic Sys ems (c . [GRS14, p. 9])
The o e all mechanical s uc u e is ep esen ed by he au onomous mecha onic sys em
(AMS). I consis s o he MFMs o he mecha onic sys em and includes addi ional sen-
so s and so wa e componen s o ealizing sel -adap i e beha io . An example o an
AMS is a single RailCab.
Finally, AMS’ may collabo a e and o m ne wo ked mecha onic sys ems (NMS). Ne -
wo ked mecha onic sys ems usually ha e no physical ep esen a ion bu a e only i u-
ally c ea ed by he AMS by using message-based communica ion p o ocols. Then, each
AMS ulfills a pa icula ole in he NMS. An example is gi en by con oys o RailCabs.
2.1.2 Ope a o -Con olle -Module
The ope a o -con olle -module (OCM) is a e e ence a chi ec u e o sel -adap i e
mecha onic sys ems ha sepa a es he beha io specifica ion in o h ee concep ual le -
els [HOG04, GRS09, GRS14]. As pa o his hesis, we ela e ou con ibu ions o hese
h ee concep ual le els o he OCM. The di e en le els a e he cogni i e ope a o , he
eflec i e ope a o , and he con olle as shown in Figu e 2.2.
The con olle le el is he lowes . I con ains he eedback con olle s ha con ol he
physical sys em ha is also called he con olled sys em [Kil05]. A eedback con olle
con inuously ecei es he cu en alue o he con olled a iable om he physical sen-
so s. Based on a e e ence alue o he con olled a iable, i ies o educe he di e -
Founda ions Page 31
Ac ion Le el Planning Le el
moni o ing
sequence
C
B
A
Re lec i e Ope a o
Con olle
Ope a o -Con olle -Module (OCM)
...
con igu a ion-
con ol
eme gency
so eal ime
ha d eal ime
Model-based Sel -Op imiaza ion
Beha io -based Sel -Op imiza ion
cogni i e in o ma ion p ocessing
Cogni i e Ope a o
Cogni i e Loop
Re lec i e Loop
e lec i e in o ma ion p ocessing
mo o in o ma ion p ocessing
con igu a ions
A
C
B
con olled sys em
Mo o Loop
Figu e 2.2: O e iew o he Ope a o -Con olle -Module [GRS14, p. 11]
ence be ween he cu en alue and e e ence alue o ze o by compu ing signals o he
sys em’s ac ua o s.
The eflec i e ope a o o ms he middle laye o he OCM. I con ains e en -disc e e
so wa e ha is equi ed o he ope a ions o he mecha onic sys em as, o example,
he beha io o ope a ing as a coo dina o o membe o a con oy. As a key elemen o
his beha io , he eflec i e ope a o execu es communica ion p o ocols o in e ac ing
wi h o he AMS.
In addi ion, he eflec i e ope a o p o ides he abili y o econfigu e i s own so wa e
a chi ec u e including he eedback con olle s on he con olle le el. In acco dance o
Allen e al. [ADG98] and Zhang e al. [ZC06], we dis inguish be ween s eady-s a e be-
ha io and econfigu a ion beha io . The s eady-s a e beha io defines he beha io ha
is execu ed by he eedback con olle s on he con olle le el and by he eflec i e op-
e a o based on a pa icula so wa e a chi ec u e wi hou conside ing econfigu a ions.
The econfigu a ion beha io defines possible modifica ions o he so wa e a chi ec-
u e. Using he eflec i e loop, sel -adap i e sys ems con inuously moni o hei own
Page 38 Chap e 2
An al e na i e o speci ying sa e y and li eness p ope ies is gi en by linea - ime em-
po al logic (LTL, [Pnu77, HR04]). LTL uses a linea ime model based on pa hs ha do
no conside b anching. The e o e, he empo al connec i es o LTL only use a empo al
ope a o bu no pa h quan ifie . We discuss p ese a ion o LTL o mulas o ou efine-
men check, bu do no use LTL o speci ying sa e y and li eness p ope ies as pa o
his hesis because imed a ian s o LTL like he me ic empo al logic (MTL, [Koy90])
a e no decidable o he dense ime model used by NTAs p esen ed abo e [AH92] and,
hus, no model checke s exis .
2.2.3 Model Checking P ocedu e
A imed model checking p ocedu e decides whe he a gi en imed au oma a o NTA ul-
fills a gi en TCTL p ope y [HNSY94, BDM+98, BY04]. The e o e, he model check-
ing p ocedu e compu es a zone g aph o he imed au oma on o he NTA. Then, i
successi ely labels he esul ing s a es wi h he a omic p oposi ions and he sub o mulas
ha hold o a gi en s a e. The imed au oma on o he NTA ulfills he TCTL p ope y i
and only i he o mula is ue o he ini ial s a e o he zone g aph. I he TCTL p ope y
is no ulfilled, he model checke e u ns a coun e example. A coun e example is a
ace o he zone g aph ha caused ha he TCTL p ope y is no ulfilled. In he cou se
o his hesis, we use he model checke UPPAAL [LPY95, BDL+06b] o e i ying
TCTL p ope ies o NTAs.
2.3 G aph-Based Specifica ions
The heo y o g aph ans o ma ion sys ems (GTS, [Roz97]) is based on g aphs. In u-
i i ely, g aphs consis o nodes and edges connec ing he nodes. GTS define a language
consis ing o wo ds whe e each wo d is a g aph. P oduc ions o a GTS a e gi en by
g aph ans o ma ion ules ha o mally speci y how one g aph may be ans o med
in o ano he one. In his hesis, we use GTS as a basic o malism o o malizing e-
configu a ion ope a ions o MECHATRONICUML ha modi y he so wa e a chi ec u e
o a sel -adap i e mecha onic sys em. This, in u n, enables o o mally e i y econ-
figu a ion ope a ions o MECHATRONICUML, which we exploi in ou econfigu a ion
app oach in oduced in Chap e 4.
In a gene al GTS, he nodes and edges o a g aph do no ha e a p edefined co espon-
dence o a eal-wo ld o so wa e en i y. Fo defining econfigu a ions o a so wa e a -
chi ec u e by g aph ans o ma ions, we need o define a co espondence be ween nodes
and edges o a g aph and he componen s and connec o s o he so wa e a chi ec u e.
This a achie ed by using yped a ibu ed GTS ha we in oduce in Sec ion 2.3.1. S o y
diag ams as in oduced in Sec ion 2.3.2 ex end yped a ibu ed g aph ans o ma ion
ules by he abili y o speci y con ol flow. This enables o speci y mo e complex econ-
figu a ion ope a ions. The e o e, s o y diag ams a e he basis o speci ying econfigu-
a ion ope a ions in MECHATRONICUML as defined in Sec ion 3.3.
Founda ions Page 39
2.3.1 Typed A ibu ed G aph T ans o ma ions Sys ems
Typed a ibu ed GTS [EEPT06] ex end GTS by a ype g aph and node a ibu es. The
ype g aph defines which ypes o nodes exis and by which ypes o edges hey may be
connec ed. Node a ibu es enable o s o e alues like in ege s o s ings inside a node.
Bo h ea u es a e essen ial o modeling econfigu a ion (c . Sec ion 3.3).
Figu e 2.6 shows an example o a simple ype g aph ha defines wo nodes ypes and six
edge ypes. The wo nodes ypes, RailCab and T ackSec ion, ep esen RailCabs and ack
sec ions. The node ype RailCab defines an a ibu e o ype In ege ha s o es he size
o he con oy ha he RailCab is cu en ly d i ing in. The edge ypes define how nodes
o ype RailCab and T ackSec ion may be connec ed.
RailCab
con oySize : in
ailcabs
on
0..*
1
T ackSec ion nex 0..1
0..1
p e
0..1
coo dina o
0..* membe
Figu e 2.6: Example o a Type G aph
AT ackSec ion has a nex and a p e T ackSec ion. These edge ypes define he ou line
o he ack sys em. In addi ion, he edge ype ailcabs is used o e e o all RailCabs
cu en ly d i ing on a ack sec ion. The edge ype on enables o define on which T ack-
Sec ion aRailCab is cu en ly loca ed. Finally, coo dina o and membe enable a RailCab
o e e o i s coo dina o o i s membe s.
A yped a ibu ed g aph is always yped o e exac ly one ype g aph, while an a bi a y
numbe o yped a ibu ed g aphs may use he same ype g aph. All nodes and edges
o a yped a ibu ed g aph mus be yped o e exac ly one node ype o edge ype,
espec i ely, o he ype g aph. The ype o a node o edge is immu able. In he cou se
o his hesis, we will assume ha he ype g aph is gi en by a me amodel [Küh06].
Figu e 2.7 shows an example o a yped a ibu ed g aph ha is yped o e he ype g aph
in Figu e 2.6. I con ains fi e nodes and fi e edges. I specifies he si ua ion whe e wo
RailCabs d i e on wo consecu i e ack sec ions. The RailCabs a e no ye d i ing in a
con oy because hey a e no connec ed wi h each o he by a coo dina o o membe edge.
s3 : T ackSec ion
c1 : RailCab
con oySize = 0
p e s2 : T ackSec ion
nex
s1 : T ackSec ion
p e
nex
c2 : RailCab
con oySize = 0
onon
ailcabs ailcabs
Figu e 2.7: Typed A ibu ed G aph
Page 40 Chap e 2
Each node o a yped a ibu ed g aph has alues o all o i s a ibu es. In Figu e 2.7,
he nodes c1 and c2 bo h ha e alue 0 o hei con oySize a ibu e.
A yped a ibu ed GTS consis s o a ype g aph, an ini ial g aph ha is yped o e
he ype g aph, and a se o g aph ans o ma ion ules ha define how g aphs may be
modified. A g aph ans o ma ion ule specifies a le hand side (LHS), a igh hand
side (RHS), a so-called ule mo phism, and a se o nega i e applica ion condi ions
(NAC) [EEPT06]. LHS, RHS, and NACs a e yped a ibu ed g aphs based on he ype
g aph. The ule mo phism associa es nodes in he LHS o nodes in he RHS o deno e
which nodes a e he same. In addi ion, each NAC defines i s own mo phism ha asso-
cia es nodes in he LHS o nodes in he NAC.
Rule: s a Con oy
LHS
::=
RHS
NAC1
s2 : T ackSec ion
c1 : RailCab
s1 : T ackSec ion
nex
c2 : RailCab
onon
s2 : T ackSec ion
c1 : RailCab
con oySize = con oySize + 1
s1 : T ackSec ion
nex
c2 : RailCab
onon
coo dina o
membe
c3 : RailCab c2 : RailCab coo dina o
NAC2
c1 : RailCab c2 : RailCab membe
Figu e 2.8: G aph T ans o ma ion Rule o S a ing a Con oy
Figu e 2.8 shows an example o a g aph ans o ma ion ule s a Con oy ha s a s a
con oy be ween wo RailCabs ha a e posi ioned on wo consecu i e ack sec ions.
The LHS specifies his si ua ion. The RHS specifies he same si ua ion bu c2 is now a
membe o a con oy ha is coo dina ed by c1. In ou example, we implici ly define he
ule mo phism by using he same names, e.g., c1 and c2 o nodes in he LHS and RHS.
The g aph ans o ma ion ule s a Con oy defines wo NACs. NAC1defines a si ua ion
whe e c2 is al eady a membe o a con oy ha is coo dina ed by a di e en RailCab c3.
NAC2defines a si ua ion whe e c2 is al eady a membe o a con oy ha is coo dina ed
by c1.
The applica ion o a g aph ans o ma ion ule such as s a Con oy o a yped a ibu ed
g aph is pe o med in h ee s eps. In he fi s s ep, we sea ch a ma ch o he LHS o
he yped a ibu ed g aph, he so-called hos g aph. Basically, a ma ch is an occu ence
o he LHS in he hos g aph. The ma ch needs o conside bo h, he ype o he node
and he a ibu e alues o he node. Tha means, nodes o ype RailCab in he LHS
may only be ma ched o nodes o ype RailCab in he hos g aph. I a node in he LHS
specifies an a ibu e alue, he ma ched node in he hos g aph needs o ha e he same
a ibu e alue. A ibu es ha a e no used in he LHS a e igno ed while sea ching he
ma ch. A ma ch o a g aph ans o ma ion ule is only alid, i no NAC o he g aph
ans o ma ion ule can be ma ched o he hos g aph. In he second s ep, we emo e all
nodes and edges ha occu in he LHS bu no in he RHS o he g aph ans o ma ion
Founda ions Page 41
ule. To de e mine his se o nodes, we use he ule mo phism. In he hi d s ep, we
add all nodes and edges ha occu in he RHS bu no in he LHS. In his s ep, we also
modi y a ibu e alues i necessa y.
When applying he g aph ans o ma ion ule s a Con oy in Figu e 2.8 o he yped a -
ibu ed g aph in Figu e 2.7, we p oceed as ollows. Fo ob aining a ma ch, we sea ch
o an occu ence o he LHS in he g aph. The occu ence is gi en by he nodes c1, c2,
s2, and s3 in Figu e 2.7. Nex , we need o check whe he his ma ch may be ex ended
such ha any NAC is comple ely ma ched. This is no he case because c2 in Figu e 2.7
is no ye membe o a con oy. Thus, s a Con oy has been success ully ma ched and we
pe o m he g aph ew i ing. The e o e, we c ea e a coo dina o edge om c2 o c1 and a
membe edge om c1 o c2. In addi ion, we upda e he alue o he a ibu e con oySize
o c1 by inc emen ing i by 1.
Fo he applica ion o g aph ans o ma ion ules, we ollow he single pushou app oach
wi h injec i e ma ches (SPO, [Roz97]). In essence, ha means ha di e en nodes o
he LHS need o be ma ched o di e en nodes in he hos g aph. Fo example, c1 and
c2 in he LHS o s a Con oy need o be ma ched o di e en RailCab nodes in he hos
g aph. In addi ion, i he g aph ans o ma ion ule specifies o dele e a node wi hou
dele ing all o i s inciden edges, hen he inciden edges a e implici ly dele ed as well o
a oid dangling edges.
2.3.2 S o y D i en Modeling
S o y d i en modeling (SDM, [Zün01]) is an app oach o he objec -o ien ed and mod-
el-d i en so wa e de elopmen . One essen ial pa o SDM a e s o y diag ams
[FNTZ00, Zün01] ha a e used in he design phase o o mally speci ying ope a ions
o an objec -o ien ed p og am. They combine an impe a i e con ol flow specifica ion
based on UML Ac i i y Diag ams [G o11c] wi h a o mal, decla a i e specifica ion o
objec manipula ion based on yped a ibu ed g aph ans o ma ions, called s o y pa -
e ns. S o y diag ams may also be used as an endogenous in-place model ans o ma ion
language [CH06] and o m he basis o defining econfigu a ion ope a ions in ou ap-
p oach as desc ibed in Sec ion 3.3. In he ollowing, we gi e a b ie o e iew o s o y
pa e ns (c . Sec ion 2.3.2.1) and s o y diag ams (c . Sec ion 2.3.2.2) based on he la es
e sion by on De en e al. [ DHP+12a].
2.3.2.1 S o y Pa e ns
A s o y pa e n consis s o objec a iables and link a iables ha co espond o he
nodes and edges o a yped a ibu ed g aph ans o ma ion ule. Objec a iables and
link a iables a e yped o e a me amodel [Küh06]. S o y pa e ns use a concise no a ion
o he yped a ibu ed g aph ans o ma ion ule ha isualizes LHS, RHS, and NACs in
a single g aph. As an example, conside he s o y pa e n in Figu e 2.9 ha is equi alen
o he yped a ibu ed g aph ans o ma ion ule in Figu e 2.8.
Page 42 Chap e 2
c2
con oySize := con oySize + 1
c1
s2 : T ackSec ion s1 : T ackSec ion
nex ►
▼ on ▼ on
coo dina o ►
«c ea e»
◄ membe
«c ea e»
◄ membe
3 : RailCab ◄ coo dina o
Figu e 2.9: S o y Pa e n
Objec s a iables and link a iables ha shall be c ea ed by he s o y pa e n a e la-
belled wi h a «c ea e» anno a ion such as he link a iables coo dina o and membe
in Figu e 2.9. Objec a iables and link a iables ha shall be dele ed a e labeled wi h
«des oy». All objec a iables and link a iables no ca ying an anno a ion a e no
changed by he g aph ew i ing.
Fu he mo e, objec a iables ha e a binding s a e. In pa icula , we dis inguish be ween
bound and unbound objec a iables. An unbound objec a iable needs o be ma ched
by he g aph ma ching when he s o y pa e n is applied. A bound objec a iable has
al eady been ma ched o an objec o he hos g aph du ing he applica ion o ano he
s o y pa e n. This ma ching is no changed while ma ching he unbound objec a iables
o he s o y pa e n. In ou example, he objec a iables s1, s2, and 3 a e unbound,
while c1 and c2 a e bound. In he conc e e syn ax, unbound a iables isualize bo h,
hei name and hei ype, whe eas bound a iables only isualize hei name.
S o y pa e ns ha a e embedded in a s o y diag am always need o ha e a leas one
bound objec a iable. In addi ion, any unbound objec a iable mus be eachable om
a leas one bound objec a iable by a e sing link a iables. The objec i e o his
es ic ion is o educe he ma ching e o o s o y pa e ns compa ed o yped a ibu ed
g aph ans o ma ion ules. In gene al, de i ing a ma ching o a yped a ibu ed g aph
ans o ma ion ule is equi alen o he NP-comple e subg aph isomo phism p oblem
and, hus, equi es exponen ial un ime. The bound objec a iables, howe e , p o ide
s a ing poin s o he g aph ma che and, in combina ion wi h he ype g aph, educe
he numbe o possible ma chings and, hus, he un ime o de i ing a alid ma ching
significan ly [SWZ95, Zün95, pp. 195 .].
NACs a e ep esen ed by so-called nega i e a iables ha a e c ossed ou in he conc e e
syn ax. In ou example, he nega i e objec a iable c3 and he nega i e link a iable
coo dina o be ween c2 and c3 co espond o NAC1in Figu e 2.8. They deno e ha
c2 does no ha e a coo dina o e e ence o ano he RailCab. The nega i e link a iable
membe om c1 o c2 co esponds o NAC2and defines ha c2 mus no al eady be a
membe o c1.
Objec a iables may con ain condi ions on and assignmen s o objec a ibu es as in
yped a ibu ed g aph ans o ma ion ules. In ou example, he alue o he a ibu e
con oySize o c1 is se o one. As in yped a ibu ed g aph ans o ma ion ules, condi-
Founda ions Page 43
ions on objec a ibu es a e pa o he LHS, while assignmen s o a ibu ed alues a e
pa o he RHS.
2.3.2.2 S o y Diag ams
A s o y diag am consis s o ac i i y nodes and ac i i y edges o speci ying he con ol
flow such as sequen ial and condi ional execu ion as well as loops. As pa o his hesis,
we use di e en kinds o ac i i y nodes and ac i i y edges ha we illus a e below.
The kinds o ac i i y nodes ha we conside a e ini ial nodes, final nodes, s o y nodes,
decision nodes, ac i i y call nodes, and s a emen nodes. Each s o y diag am con ains
exac ly one ini ial node ha ma ks he s a ing poin o i s execu ion. In addi ion, each
s o y diag am has a leas one final node ha ma ks he end o i s execu ion. A s o y node
con ains a s o y pa e n and, hus, defines a modifica ion o an objec s uc u e. Decision
nodes enable o define complex b anch and me ge s uc u es o he con ol flow. An
ac i i y call node [B DHR11] enables o in oke ano he s o y diag am. Finally, s a e-
men nodes con ain sou ce code and may be used, o example, o define local coun e
a iables.
c1 as Coo dina o
[ ailu e]
s a Con oy(RailCab c1,RailCab c2) : Boolean esul
c2
con oySize := con oySize + 1
c1
s2 : T ackSec ion s1 : T ackSec ion
nex ►
▼ on ▼ on
coo dina o ►
«c ea e»
◄ membe esul := alse
[success]
esul := ue
«c ea e»
◄ membe
3 : RailCab ◄ coo dina o
Call
c1.enableCoo dina ion();
[else]
[ c1.con oySize == 1]
Figu e 2.10: S o y Diag am wi h Con ol Flow
As an example, conside he s o y diag am shown in Figu e 2.10. The s o y diag am
specifies he beha io o s a ing a con oy. I embeds he s o y pa e n shown in Fig-
u e 2.9 in he s o y node named c1 as Coo dina o .I c2 is he fi s membe o c1 as
specified by he decision node below he s o y node, we addi ionally in oke enableCoo -
dina ion on c1 ia he ac i i y call node a he bo om o he figu e.
Ac i i y edges connec he ac i i y nodes and define how he execu ion o he s o y
diag am p oceeds a e execu ing an ac i i y node. S o y diag ams suppo di e en
kinds o ac i i y edges ha a e dis inguished by hei labels in he conc e e syn ax. The
Page 44 Chap e 2
kind and numbe o ou going ac i i y edges depend on he kind o he sou ce ac i i y
node.
Ini ial nodes and ac i i y call nodes always ha e exac ly one ou going de aul ac i i y
edge bu no o he ou going ac i i y edges. A de aul ac i i y edge has no label. Final
nodes ha e no ou going edges. A s o y node may ei he ha e one ou going de aul
ac i i y edge o i may ha e one ou going success ac i i y edge, iden ified by he label
[success], and one ou going ailu e ac i i y edge, iden ified by he label [ ailu e]. The
success ac i i y edge is aken i he s o y pa e n in he s o y node has been ma ched
success ully. The ailu e ac i i y edge is aken i he s o y pa e n could no be ma ched.
Finally, a decision node may ha e ei he one ou going de aul ac i i y edge (me ge node)
o i has nou going ac i i y edges whe e n≥2(b anch node). In he la e case, n−1
o he ou going ac i i y edges mus ca y a Boolean condi ion, while he emaining one
is an else ac i i y edge ha has he label [else]. In his case, he ac i i y edge wi h a
sa isfied condi ion is execu ed o , i none o he Boolean condi ions is ulfilled, he else
ac i i y edge is execu ed.
In addi ion o defining he con ol flow, he ac i i y edges define how ma chings a e
p opaga ed h ough a s o y diag am. An ini ial ma ching o a s o y diag am is p o ided
by he inpu pa ame e s. The s o y diag am in Figu e 2.10 has wo inpu pa ame e s c1
and c2 o ype RailCab. This ma ching is p opaga ed o he s o y node ia he de aul
ac i i y edge. The s o y pa e n, which is embedded in he s o y node, uses c1 and
c2 as bound a iables. I he s o y pa e n can be applied success ully, he ma ching is
ex ended by all ma ched and c ea ed a iables. Des oyed objec a iables a e emo ed
om he ma ching. Then, he ma ching is p opaga ed ia he success ac i i y edge o
he subsequen node. I he s o y pa e n canno be ma ched, he ma ching is p opaga ed
unmodified ia he ailu e ac i i y edge. Decision nodes ne e change a ma ching. The
Boolean condi ions a he ou going ac i i y edges may e e o any objec a iables in he
cu en ma ching and o hei a ibu es. A a final node, objec a iables con ained in he
cu en ma ching can be assigned o he ou pu pa ame e s. In ou example, howe e , we
only assign he li e als ue and alse o he ou pu pa ame e esul depending on whe he
he c ea ion o he con oy was success ul.
S o y diag ams may be defined as an implemen a ion o an ope a ion o a class o he
me amodel. In his case, he s o y diag am may be in oked by calling he ope a ion o
an objec o he co esponding ype. In ou example in Figu e 2.10, he ac i i y call node
in okes he ope a ion enableCoo dina ion on he objec c1 o ype RailCab. In his case,
c1 se es as an implici pa ame e o he s o y diag am and may be used as a bound
a iable wi h he name his in he embedded s o y pa e ns.
Fo defining loops, s o y nodes may be ma ked as o -each s o y nodes. A o -each
s o y node is i e a i ely applied o any ma ching ha may be ob ained o he embedded
s o y pa e n in he hos g aph bu gua an ees ha no ma ching is used wice. A o -
each s o y node always has one ou going end ac i i y edge ha is aken i no u he
ma ching may be ob ained o he s o y pa e n in he o -each s o y node (labeled wi h
Founda ions Page 45
[end]). Op ionally, a o -each s o y node may ha e an addi ional each ime ac i i y edge
(labeled wi h [each ime]) ha is aken o each ma ching o he embedded s o y pa e n.
Bind each Membe ...
[end]
RailCab::b eakCon oy()
his
membe : RailCab
▼ membe
… and emo e i !
his
con oySize := con oySize –1
membe
▼ membe
[each ime]
«des oy»
Figu e 2.11: S o y Diag am wi h o -each Ac i i y Node
Figu e 2.11 shows he s o y diag am b eakCon oy. The s o y diag am may be in oked
on an objec o ype RailCab, ep esen ed by he his a iable, o dissol ing a con oy.
Fo he RailCab he o -each s o y node Bind each membe ..., which is isualized wi h a
cascaded bo de line, ma ches any membe o he RailCab. Fo each ma ch, we exi he
o -each s o y node ia he each ime ac i i y edge. The second s o y node des oys he
link o he membe and dec eases he con oySize by 1.
2.4 Mecha onicUML
MECHATRONICUML [GTB+03, EHH+13, BDG+14a] is a model-d i en so wa e en-
ginee ing me hod o de eloping e en -disc e e so wa e o sel -adap i e mecha onic
sys ems. I adap s he concep s o UML 2.4 [G o11c] o defining a componen -based
so wa e a chi ec u e, s a e-based beha io , and un ime econfigu a ion o a sel -adap-
i e mecha onic sys em. In he cou se o his hesis, we in eg a e all o ou con ibu ions
in o MECHATRONICUML and p o ide an example model o he RailCab sys em based
on MECHATRONICUML in Appendix A.
In he ollowing, we b iefly e iew he mos impo an pa s o speci ying pla o m-
independen models based on MECHATRONICUML ha we use as pa o his hesis.
In pa icula , we in oduce Real-Time Coo dina ion P o ocols (Sec ion 2.4.1), Real-
Time S a echa s (Sec ion 2.4.2), and he assump ions on quali y-o -se ice cha ac e -
is ics ha a e employed by MECHATRONICUML. Fo a de ailed desc ip ion o hese
pa s o MECHATRONICUML, we e e o he MECHATRONICUML language specifi-
ca ion [BDG+14b]. We discuss he componen model o MECHATRONICUML and he
specifica ion and execu ion econfigu a ions in de ail in Chap e s 3 and 4.
2.4.1 Real-Time Coo dina ion P o ocols
MECHATRONICUML uses Real-Time Coo dina ion P o ocols (RTCPs) o o mally
speci ying asynch onous message-based communica ion be ween wo communica ion
Page 46 Chap e 2
pa ne s [GTB+03, EHH+13]. RTCPs may be used in he eflec i e ope a o and in
he cogni i e ope a o o he OCM o defining message-based communica ion be ween
di e en AMS bu also be ween di e en componen s inside a single AMS.
An RTCP defines a name and wo named oles ha ep esen he communica ion pa -
ne s. Each ole has a beha io specifica ion in e ms o a Real-Time S a echa (c .
Sec ion 2.4.2) ha defines i s beha io . The oles a e connec ed by a ole connec o ha
specifies equi emen s o he physical connec ion such as he maximum ansmission
delay o a message and he possibili y o message loss (c . Sec ion 2.4.3).
p o ide ecei e
Dis anceT ansmission
[0..*] [1]
in-bu e size: 1 in-bu e size: 1
delay: 1 ms
single olemul i ole ole connec o
coo dina ion
p o ocol ole name label
Figu e 2.12: Decla a ion o he RTCP Dis anceT ansmission
Figu e 2.12 shows he decla a ion o a RTCP named Dis anceT ansmission ha is used
by a con oy coo dina o o pe iodically ansmi ing new e e ence da a o he mem-
be s [HH11a, EHH+13]. The RTCP has wo oles named p o ide and ecei e . The
RTCP is ep esen ed by he dashed ellipse, while he oles a e ep esen ed by he dashed
squa es including he connec ion o he pa e n ellipse. In ou example, he ole connec-
o specifies a ansmission delay o 1ms o each message.
Each ole defines a se o message ypes ha i may send o ecei e. Message ypes
a e used o ype he messages ha a e exchanged a un ime. They ha e a name and
an op ional lis o yped, named pa ame e s. Which messages may be sen o ecei ed
a a pa icula poin in ime is defined by he Real-Time S a echa s o he oles, which
we p esen in Sec ion 2.4.2. I a ole only ecei es messages, i is an in- ole. I i only
sends messages, i is an ou - ole. I i bo h sends and ecei es messages, i is an in/ou -
ole [BDG+14b]. In ou example in Figu e 2.12, bo h oles a e in/ou - oles which is
deno ed by he wo iangles inside he squa es.
Recei ed messages a e s o ed in a message bu e ha we call in-bu e . In his wo k,
we es ic ou sel es o FIFO-queues as in-bu e s whe e all he ecei ed messages a e
s o ed in he same queue. Each ole specifies a bu e size o i s in-bu e [BDG+14b].
In ou example, bo h oles speci y a bu e size o 1, i.e., hey can s o e a mos one
message in hei in-bu e .
In addi ion, each ole specifies a ca dinali y using a Min-Max-No a ion as defined by
Coad and You don [CY90, p. 127]. Thus, he ca dinali y o a ole defines wi h how many
ins ances o he o he ole i may communica e a leas and a mos . I he uppe bound
o he ca dinali y equals 1, hen we call i a single ole. I he uppe bound is g ea e
han 1, we call i a mul i ole [EHH+13, BDG+14b]. In ou example, he ole ecei e
Founda ions Page 47
defines a ca dinali y o [1] while p o ide defines a ca dinali y o [0..∗]. Consequen ly, an
ins ance o he mul i ole p o ide may communica e wi h 0 o many ecei e ’s while any
ins ance o he single ole ecei e may only communica e wi h exac ly one p o ide .
A un ime, an ins ance o a mul i ole con ains o a se o sub ole ins ances as shown
in Figu e 2.13. Each sub ole ins ance is connec ed ia a single-cas connec o o one
ins ance o he single ole and manages he communica ion wi h i . Due o he single-
cas connec o s, each sub ole ins ance may only exchange messages wi h one pa icula
single ole ins ance.
: ecei e
:p o ide : ecei e
: ecei e
:Dis anceT ansmission
p o ocol ins ance label
ole ins ance label ole ins ance label
ole connec o ins ance
single ole ins ance
mul i ole ins ance
sub ole ins ance
Figu e 2.13: Ins ance o he RTCP Dis anceT ansmission (c . [BDG+14b])
Mul i ole ins ances a e o de ed, i.e., he e exis s a o al o de o he sub ole ins ances.
One sub ole ins ance is he fi s one in he o de ing, ano he one is he las one in he
o de . Adjacen sub ole ins ances in he o de ha e a successo -p edecesso ela ionship.
In ou example in Figu e 2.13, we may assume ha he op mos sub ole ins ance is he
fi s one while he bo om mos sub ole ins ance is he las one. The sub ole ins ance in
he middle is he successo o he fi s one and he p edecesso o he las one.
2.4.2 Real-Time S a echa s
Real-Time S a echa s (RTSCs) as defined by Becke e al. [BDG+14b] a e a combina-
ion o UML s a emachines [G o11c] and imed au oma a (c . Sec ion 2.2.1). Thus, hey
enable o speci y hie a chical, s a e-based eal- ime beha io .
Basically, RTSCs consis o s a es and ansi ions. They use clocks wi h co esponding
in a ian s, ime gua ds, and ese s as defined o imed au oma a (c . Sec ion 2.2.1).
In addi ion, hey may use a iables o s o ing da a and ope a ions o encapsula ing
complex compu a ions. As in UML s a emachines, s a es may define ac ions ha a e
execu ed upon en e ing (en y e en ) o lea ing (exi e en ) a s a e.
As an example, we p o ide he RTSCs o he oles ecei e and p o ide o he RTCP Dis-
anceT ansmission in Figu es 2.14 and 2.15, espec i ely. They implemen he beha io
Page 54 Chap e 3
Bo h exis ing componen models do no ulfill all o he a o emen ioned equi emen s.
The componen model by Bu mes e , Giese, and Hi sch p o ides no suppo o ins an i-
a ing embedded componen s mo e han once. This and he ac ha all so wa e a chi ec-
u es need o be enume a ed lead o la ge models, in pa icula , i a componen may ha e
se e al a chi ec u es a un ime. This makes he models ha d o handle o a de elope .
The componen model by Tichy does no dis inguish be ween so wa e componen s and
eedback con olle s in he ype g aph ha is used o speci ying componen s o y di-
ag ams. As a esul , componen s o y diag ams canno speci y he econfigu a ion o
eedback con olle s. In addi ion, bo h componen models do no enable o connec so -
wa e componen s o eedback con olle s and o es ablish connec ions be ween di e en
AMS [HB14].
In his chap e , we de i e a consolida ed componen model o MECHATRONICUML
ha combines he ea u es o he wo exis ing componen models. In pa icula , we
ex end he concep o he ype g aph used by Tichy such ha he componen model
may include eedback con olle s and such ha hey may in e ac wi h so wa e com-
ponen s. As a esul , we can speci y so wa e a chi ec u es on he eflec i e ope -
a o and con olle le els o he OCM. In addi ion, we ex end componen s o y dia-
g ams such ha hey can econfigu e eedback con olle s as defined by Bu mes e and
Giese [GBSO04, Bu 06, BGO06]. Finally, we p o ide a concep o es ablishing con-
nec ions be ween AMS. As a esul , ou new componen model enables o concise and
o mal specifica ions o componen s, hei in eg a ion wi h eedback con olle s, and
hei econfigu a ion beha io .
In he ollowing, we illus a e ou componen model based on a so wa e a chi ec u e o
he d i ing module o a RailCab ha includes he beha io o building con oys. The e-
qui emen s o he con oy beha io ha e been p esen ed in ou echnical epo [Hei12].
In ou example, we use ideas p esen ed by Hi sch [Hi 08], Tichy [Tic09], and Flaßkamp
e al. [FHK+13]. These ideas ha e been significan ly ex ended as pa o his hesis.
The emainde o his chap e is s uc u ed as ollows. We s a by defining how compo-
nen s (Sec ion 3.1), componen ins ances (Sec ion 3.2), and econfigu a ion ope a ions
(Sec ion 3.3) a e specified. The ea e , we in oduce ou concep s o es ablishing con-
nec ions be ween AMS (Sec ion 3.4) and o speci ying a chi ec u al cons ain s (Sec-
ion 3.5). Nex , we desc ibe how he new componen model has been implemen ed as
pa o he MECHATRONICUML Tool Sui e (Sec ion 3.6). Finally, we discuss ela ed
app oaches (Sec ion 3.7) and summa ize he chap e (Sec ion 3.8).
3.1 Modeling Componen s
"A [..] componen is a so wa e elemen ha con o ms o a componen model and can be
independen ly deployed and composed wi hou modifica ion acco ding o a composi ion
Mecha onicUML Componen Model Page 55
s anda d." [HC01, p. 7] In acco dance o UML [G o11c], componen s a e ei he imple-
men ed di ec ly o hey a e assembled om o he componen s. We e e o he o me as
a omic componen s and o he la e as s uc u ed componen s.
In bo h cases, he in e nals o a componen a e hidden om he ou side wo ld. This
is deno ed as componen encapsula ion [SGM02]. Access o he capabili ies o da a o
a componen is only allowed ia i s po s. This enables o eplace one componen by
ano he one wi h a compa ible in e ace wi hou a ec ing any o he componen in a sys-
em. In addi ion, componen encapsula ion is one o he key enable s o composi ional
e ifica ion [BCC98, GTB+03] because i gua an ees ha he e may no exis mo e de-
pendencies o o he componen s han hose cap u ed by po s. We will exploi his in
Chap e 5.
Ou componen model explici ly dis inguishes be ween componen ypes and componen
ins ances. The componen ypes a e ins an ia ed o componen ins ances o ep esen ing
he so wa e a chi ec u e o a sys em. In he ollowing, we e e o componen ypes
simply as componen s. We in oduce componen ins ances in de ail in Sec ion 3.2.
We illus a e he specifica ion o componen s and componen ins ances based on exam-
ples gi en in conc e e syn ax. A o maliza ion o he componen model is gi en by a
me amodel [SV06, ch. 4] whose abs ac syn ax is defined in Appendix D.1. The s a ic
seman ics has been o malized based on cons ain s in he objec cons ain language
(OCL, [G o12]) ha a e con ained in he me amodel. The OCL cons ain s a e lis ed in
he MECHATRONICUML language specifica ion [BDG+14b].
In he ollowing, we fi s in oduce he di e en kinds o po s ha we suppo in ou
componen model (Sec ion 3.1.1). They di e in he kind o in o ma ion hey p ocess
and in hei pu pose. Based on he di e en kinds o po s, we define di e en kinds o
a omic componen s (Sec ion 3.1.2) and s uc u ed componen s (Sec ion 3.1.3). The e-
a e , we define how componen s may be connec ed ia hei po s using connec o s (Sec-
ion 3.1.4). As an ex ension o he p e ious componen models, ou componen model
suppo s ha a componen may expose a se o componen p ope ies (Sec ion 3.1.5) ha
we need o ou econfigu a ion concep p esen ed in Chap e 4. The concep s p esen ed
in his sec ion ha e successi ely been in eg a ed in o he MECHATRONICUML language
specifica ions [BDG+11, BBD+12, BBB+12, BDG+14b].
3.1.1 Po s
In ou componen model, we dis inguish be ween six kinds o po s based on hei pu -
pose and he kind o da a hey p ocess. We use disc e e and con inuous po s as defined
by Bu mes e and Giese [GBSO04, Bu 06, BGO06]. Addi ionally, we use hyb id po s
ha enable o connec disc e e so wa e componen s and eedback con olle s. Fu he -
mo e, we use b oadcas po s o ins an ia ing RTCPs be ween AMS. Finally, we use
wo kinds o econfigu a ion po s, namely econfigu a ion message po s (RM po s)
and econfigu a ion execu ion po s (RE po s), ha enable o execu e econfigu a ions
Page 56 Chap e 3
in ol ing se e al componen ins ances. Figu e 3.1 summa izes he conc e e syn ax o
he di e en kinds o po s.
in-po ou -po in/ou -po
disc e e
con inuous
hyb id
n/A
n/A
RM/RE
b oadcas
n/A n/A
n/A n/A B
RM RE
(a) Manda o y Single Po s
in-po ou -po in/ou -po
disc e e
con inuous
hyb id
n/A
n/A
RM / RE
b oadcas
n/A n/A
n/A n/A B
n/A
(b) Op ional Single Po s
in-po ou -po in/ou -po
disc e e
con inuous
hyb id
n/A
n/A
RM/RE
b oadcas
n/A n/A
n/A n/A
n/A n/A
n/A n/A
n/A
RM RE
(c) Manda o y Mul i Po s
in-po ou -po in/ou -po
disc e e
con inuous
hyb id
n/A
n/A
RM / RE
b oadcas
n/A n/A
n/A n/A
n/A n/A
n/A n/A
n/A
n/A
(d) Op ional Mul i Po s
Figu e 3.1: Kinds o Po s (c . [BDG+14b])
Each po defines a ca dinali y ha defines how many ins ances o i may be c ea ed in
one componen ins ance. The p e ious componen models only suppo ed h ee fixed
ca dinali ies ha defined ha he po can be ins an ia ed a mos once ([0..1]), exac ly
once ([1]), o a bi a y o en ([0..∗]). We ex end he concep o ca dinali ies by enabling
o speci y p ecise ca dinali ies using an in ege o lowe and uppe bound. Again, we
allow ∗as an uppe bound o indica e ha he po may be ins an ia ed a bi a y o en. I
he ca dinali y has a lowe bound o 0, we call i an op ional po and isualize i wi h
unfilled iangles (c . Figu es 3.1b and 3.1d) acco ding o Giese and Schä e [GS13]. I
he lowe bound o he ca dinali y is g ea e o equal o 1, we call i a manda o y po
and isualize i wi h filled iangles (c . Figu es 3.1a and 3.1c). Po s wi h an uppe
bound o 1a e called single po s while po s wi h an uppe bound g ea e han 1a e
called mul i po s in acco dance o Hi sch [Hi 08, HHG08]. We isualize mul i po s
wi h a cascaded bo de line as shown in Figu es 3.1c and 3.1d [Hi 08, HHG08, Tic09].
Mecha onicUML Componen Model Page 57
In he ollowing, we in oduce he di e en kinds o po s in mo e de ail.
3.1.1.1 Disc e e Po
Disc e e po s send and ecei e asynch onous messages. The e o e, each disc e e po
defines a se o message ypes ha i may send o ecei e. A message ype has a name and
an o de ed se o yped, named pa ame e s. In con as o he exis ing componen mod-
els, we do no p o ide explici in e aces in e ms o equi ed and p o ided in e aces.
Ins ead, we use a po -based specifica ion o he in e ace whe e we di ec ly assign mes-
sage ypes o he po s [CSVC11]. This app oach in oduces flexibili y ha we need o
in oducing hie a chical econfigu a ion in Chap e 4.
I a disc e e po only sends messages, i is an in-po which is deno ed by a small iangle
poin ing "in o" he componen simila o he no a ion o Koala [ O dLKM00]. I i only
sends messages, i is an ou -po as deno ed by he small iangle poin ing "ou side" he
componen . I i bo h sends and ecei es messages, i is an in/ou -po deno ed by wo
embedded iangles. Disc e e po s define a message bu e in he same ashion as a ole
o a RTCP (c . Sec ion 2.4.1).
Each disc e e po needs o efine a ole o an RTCP (c . Sec ion 2.4.1). Then, he
disc e e po needs o send and ecei e he same message ypes as he ole. In ou
conc e e syn ax, we enable o isualize he ole ha is efined by a po by a dashed line
ha is a ached o he po as shown in Figu e 3.5 on Page 63. Visualizing he efined
ole o a po is op ional.
A disc e e po has a beha io specifica ion in e ms o an RTSC. The beha io ha is
defined by he po ’s RTSC needs o be complian o he beha io ha is defined by he
ole. We desc ibe how he RTSC o a ole may be efined o an RTSC o a po in de ail
in Chap e 5. The RTSC o a mul i po has he same s uc u e as he RTSC o a mul i
ole (c . Sec ion 2.4.2).
3.1.1.2 Reconfigu a ion Message Po and Reconfigu a ion Execu ion
Po
Reconfigu a ion message po s (RM po s) and econfigu a ion execu ion po s (RE
po s) a e special kinds o disc e e po s. We use hese kinds o po s o ealizing he
communica ion ha is necessa y o ou concep o ansac ional execu ion o econ-
figu a ion in s uc u ed componen s as desc ibed in Chap e 4. In he conc e e syn ax,
we isualize RM po s and RE po s by squa es ha embed he le e "RM" and "RE",
espec i ely.
Compa ed o disc e e po s, RM po s and RE po s ha e ex ended in e ace specifi-
ca ions ha p o ide addi ional in o ma ion o he messages ypes ha may be sen o
ecei ed. We in oduce he in e ace specifica ion in de ail in Sec ion 4.3.
Page 58 Chap e 3
RM po s and RE po s ha e message bu e s and hei beha io is defined by a RTSC as
o disc e e po s. Howe e , RM po s and RE po s a e always manda o y in/ou po s.
Bo h may be used as mul i po s as we explain in Sec ion 4.1.
3.1.1.3 B oadcas Po
B oadcas po s a e a special kind o disc e e po . We use b oadcas po s only o
ins an ia ing RTCPs be ween di e en AMS as explained in Sec ion 3.4. In he conc e e
syn ax, we isualize b oadcas po s by squa es ha embed he le e "B".
Analogously o disc e e po s, b oadcas po s define a se o message ypes ha hey
may send and ecei e as well as a message bu e . Thei beha io is defined by a RTSC.
In con as o disc e e po s, b oadcas po s a e always in/ou -po s and may only be
used as single po s. In addi ion, hey do no efine a ole o a RTCP.
3.1.1.4 Con inuous Po
Con inuous po s send (ou -po ) o ecei e (in-po ) a signal alue. "A signal is a ime
a ying quan i y ha has alues a all poin s in ime" [Ma ]. The da a ype o he signal
mus be a p imi i e da a ype o an a ay o p imi i e ypes.
Con inuous po s a e ei he in-po s o ou -po s. In addi ion, con inuous po s may be
op ional, bu we cu en ly do no suppo con inuous mul i po s.
In he conc e e syn ax, con inuous po s a e isualized as isosceles iangles whe e he
op o he iangle ei he poin s in o he componen (in-po ) o ou side he componen
(ou -po ).
3.1.1.5 Hyb id Po
Hyb id po s send (ou -po ) o ecei e (in-po ) a signal alue simila o a con inuous
po . They enable ha a disc e e componen sends a signal o o ecei es a signal om a
eedback con olle . As o a con inuous po , he da a ype o he signal mus be a p im-
i i e da a ype o an a ay o p imi i e ypes. Thus, we define a new seman ics o hyb id
po s compa ed o Bu mes e [Bu 06]. Bu mes e in oduced hyb id po s as "mul iple
disc e e and con inuous po s as syn ac ic cons uc o educe isual complexi y" [Bu 06,
p. 56] bu did no define hem.
Hyb id po s a e ei he in-po s o ou -po s. Then, he RTSC o he componen may
ead (in-po ) o w i e (ou -po ) he alue o he hyb id po like a no mal a iable. In
addi ion, hyb id po s may be op ional, bu we cu en ly do no suppo hyb id mul i
po s.
Fo keeping he beha io specifica ion o a disc e e componen disc e e, hyb id po s
define a sampling in e al. Then, he alue o he signal only changes a he a e o he
sampling in e al and we do no make any assump ions on how he alue may change.
Mecha onicUML Componen Model Page 59
In he conc e e syn ax, hyb id po s a e isualized as squa es ha embed an isosceles
iangle. The op o he iangle ei he poin s in o he componen (in-po ) o ou side he
componen (ou -po ).
3.1.2 A omic Componen s
An a omic componen di ec ly con ains a beha io specifica ion and does no embed
o he componen s. Ou componen model dis inguishes h ee kinds o a omic compo-
nen s ha di e in hei pu pose and hei beha io specifica ion. In acco dance o Bu -
mes e and Giese [GBSO04, Bu 06, BGO06], we dis inguish be ween disc e e and con-
inuous a omic componen s. Disc e e a omic componen s define disc e e, e en -based
beha io while con inuous a omic componen s ep esen he eedback con olle s o he
sys em. In addi ion, we in oduce a new kind o a omic componen : he ading compo-
nen [Vol13].
Membe Con ol
e Dis
speedP o ide
membe
dis Recei e
(a) Disc e e A omic Componen
S andaloneD i e
e Speed
cu Speed o ce
(b) Con inuous A omic Componen
+-
Con oyFading
s andalone
con oy
o ce
(c) Fading Componen
Figu e 3.2: Kinds o A omic Componen s
Figu e 3.2 illus a es he conc e e syn ax o he di e en kinds o a omic componen s.
In acco dance o he UML [G o11c], componen s a e ep esen ed by ec angles wi h a
componen icon in he uppe igh co ne and a name label in he cen e . A he bo de
o he componen , we isualize he po s o he componen .
In con as o he p e ious componen models, we dis inguish he di e en kinds o
a omic componen s by using di e en componen icons o inc ease semio ic cla i y.
Semio ic cla i y equi es ha di e en seman ic cons uc s o a language need o be
ep esen ed by di e en g aphical symbols o educing he po en ial o misin e p e a-
ion [Moo09]. In he ollowing, we in oduce all h ee kinds o a omic componen s in
mo e de ail.
3.1.2.1 Disc e e A omic Componen
Disc e e a omic componen s define he disc e e, e en -based eal- ime beha io o he
sys em. As a esul , a disc e e componen ope a es on ime-disc e e alues and imple-
Page 60 Chap e 3
men s message-based communica ion. Thus, disc e e a omic componen s a e used o
defining he beha io o he eflec i e ope a o o he OCM.
A disc e e a omic componen may use disc e e po s o in e ac ing wi h o he compo-
nen s based on RTCPs. In addi ion, i may use hyb id po s o in e ac ing wi h con in-
uous a omic componen s (c . Sec ion 3.1.2.2) and b oadcas po s i i implemen s he
ins an ia ion o RTCPs be ween AMS. I he componen is econfigu able, i has one RM
po and one RE po .
Membe Con ol
Membe Con ol_Main
membe
dis Recei e
speedP o ide
Synch oniza ion1
Figu e 3.3: S uc u e o a RTSC o a Disc e e A omic Componen
The beha io o a disc e e a omic componen is defined by a RTSC ha has a fixed,
hie a chical s uc u e [Hi 08, p. 133]. Figu e 3.3 illus a es his s uc u e o he com-
ponen Membe Con ol shown in Figu e 3.2a. The RTSC always con ains one hie a chi-
cal s a e. This s a e con ains one egion o each disc e e po ha embeds he po ’s
RTSC. In he example, we ob ain egions o he disc e e po s membe ,dis Recei e ,
and speedP o ide . In addi ion, he RTSC may con ain an a bi a y numbe o so-called
synch oniza ion RTSCs ha may be used o synch onize he po RTSCs [GTB+03].
3.1.2.2 Con inuous A omic Componen
Con inuous a omic componen s ep esen he eedback con olle s o he sys em ha
a e loca ed o he con olle le el o he OCM. They ope a e on ime-con inuous alues
ha a e ep esen ed by signals. Thei beha io is ypically defined "by block-diag ams,
di e en ial equa ions, o ans e unc ions" [Bu 06, p. 56].
A con inuous a omic componen may only use con inuous po s o exchanging signals
wi h o he componen s. In acco dance o Bu mes e e al. [BGH+07], we only speci y
he in e ace o he con inuous componen based on i s po s bu no he componen ’s
beha io . The beha io o con inuous a omic componen s is specified in a con ol en-
ginee ing ool such as MATLAB/Simulink [Ma g].
As an example, conside he con inuous a omic componen S andaloneD i e shown in
Figu e 3.2b. I implemen s a eedback con olle ha le s a RailCab d i e a a cons an
Mecha onicUML Componen Model Page 61
speed. I ecei es a e e ence speed ia e Speed and he cu en speed o he RailCab
ia cu Speed. By modi ying o ce o he elec ic d i e emi ed ia o ce, i modifies
he speed o he RailCab such ha cu Speed e en ually equals e Speed. This con ol
s a egy, howe e , needs o be implemen ed in MATLAB/Simulink.
3.1.2.3 Fading Componen
A ading componen enables o swi ch be ween con inuous componen ins ances as pa
o a econfigu a ion i he con inuous componen ins ances p oduce he same ou pu
signal. Thus, ading componen s ope a e on ime-con inuous alues like con inuous
a omic componen s and a e loca ed on he con olle le el o he OCM.
As an example, conside ha he con inuous componen S andaloneD i e shown in Fig-
u e 3.2b is o be eplaced by a con inuous componen Con oyD i e as illus a ed in Fig-
u e 3.4. The Con oyD i e componen implemen s a eedback con olle ha addi ionally
conside s a e e ence dis ance ( e Dis ) and he cu en dis ance (cu Dis ) o he p eceding
RailCab. I needs o be used by all RailCabs ha a e con oy membe s. Thus, any Rail-
Cab ha wan s o join a con oy needs o pe o m his eplacemen a un ime as pa o
a econfigu a ion.
Physical Machine
:S andaloneD i e
: e Speed
:cu Speed
:cu Dis
:Con oyD i e
: e Speed
:cu Speed
: e Dis
: o ce
: o ce
«des oy»
«c ea e»
Figu e 3.4: Illus a ion o Exchanging a Con olle wi hou Fading Func ion
In gene al, con inuous componen ins ances mus no be eplaced ins an aneously i hey
p oduce he same ou pu signal such as o ce in Figu e 3.4. In he figu e, he g een g aphs
illus a e he compu ed alue o o ce o e ime while he e ical yellow ba deno es he
poin in ime whe e he con inuous componen ins ances a e eplaced ins an aneously.
In his case, a jump in he alue o he con olled a iable o ce occu s a he engine and
may damage i .
Fo p e en ing such jumps, p e ious wo ks in eg a ed ading unc ions based on c oss
ading [BGO06] and fla ness-based swi ching [OMT+08] in o MECHATRONICUML.
These a e wo s a egies o smoo hing he ou pu signal while eplacing con inuous
componen ins ances. The ac ual beha io o he ading unc ion o he fla ness-based
swi ching is specified in a con ol enginee ing ool such as MATLAB/Simulink [Ma g].
Page 62 Chap e 3
In ou componen model, we encapsula e ading unc ions and fla ness-based swi ching
in ading componen s such as Con oyFading shown in Figu e 3.2c. The ading componen
has one con inuous ou -po o he ou pu signal and one con inuous in-po o any
con inuous componen ha may p oduce his ou pu signal. Thus, Con oyFading has one
ou -po o ce and in-po s s andalone and con oy o he wo con inuous componen s
S andaloneD i e and Con oyD i e, espec i ely.
In addi ion o he po s, he ading componen defines a se o ading unc ions. Each
ading unc ion ades om he inpu signal o one in-po o he inpu signal o ano he in-
po . In he example in Figu e 3.4, he Con oyFading would need o ade om s andalone
o con oy. A his poin , we do no need o dis inguish whe he he ading unc ion
implemen s a c oss ading [BGO06] o fla ness-based swi ching [OMT+08]. We only
need o speci y how long i akes o execu e he ading unc ion. I he ading componen
does no execu e a ading unc ion, i o wa ds he inpu signal unmodified o i s ou -po .
3.1.3 S uc u ed Componen s
As uc u ed componen embeds o he componen ypes by means o componen pa s
as defined in he componen model by Tichy [Tic09]. Componen pa s a e defined
as an associa ion o ano he componen [G o11c], i.e., he same componen may be
embedded mul iple imes in a s uc u ed componen . Componen pa s define a name
and a ca dinali y.
S uc u ed componen s only define a econfigu a ion beha io bu no unc ional beha -
io . This enables sepa a ion o conce ns be ween econfigu a ion beha io and unc ional
beha io . Acco ding o McKinley e al. [MSKC04], his is one o he h ee key enable s
o success ully de eloping sel -adap i e sys ems. Wi h espec o he OCM gi en in
Sec ion 2.1.2, s uc u ed componen s belong o he eflec i e ope a o .
In con as o he exis ing componen models, ou componen model dis inguishes be-
ween wo kinds o s uc u ed componen s based on he kinds o componen s hey em-
bed. These a e disc e e s uc u ed componen s (c . Sec ion 3.1.3.1) and hyb id s uc u ed
componen s (Sec ion 3.1.3.2). The di e en ia ion be ween wo kinds o s uc u ed com-
ponen s is help ul o defining ou ansac ional econfigu a ion app oach in Chap e 4.
3.1.3.1 Disc e e S uc u ed Componen
A disc e e s uc u ed componen ( ecu si ely) embeds disc e e componen s only. Con-
sequen ly, a disc e e s uc u ed componen may use all kinds o po s excep con inuous
po s analogous o disc e e a omic componen s (c . Sec ion 3.2a).
Figu e 3.5 shows an example o a disc e e s uc u ed componen named Con oyCoo di-
na ion. I con ains he beha io o a con oy coo dina o , i.e., i p o ides beha io o
adding and emo ing RailCabs o/ om he con oy and o announcing all accele a ion
Mecha onicUML Componen Model Page 63
and b eaking maneu e s o he con oy membe s. Con oyCoo dina ion embeds wo com-
ponen s Con oyManagemen and Re Gen using wo componen pa s named man and e -
Gen, espec i ely. Bo h o which a e disc e e componen s.
Con oyCoo dina ion
man :
Con oyManagemen [1]
coo dina o
coo dina o
e Dis P o ide e Dis P o ide e Gen : Re Gen [1..*]
speedP o ide speedP o ide
p e nex
s a egy ecei e
cu Poscu Pos
p o ileP o ide
p o ileRecei e
Con oyCoo dina ion.coo dina o
Dis anceT ansmission.p o ide
S a egyT ansmission. ecei e
SpeedT ansmission.p o ide
Figu e 3.5: The s uc u ed componen ype Con oyCoo dina ion
Ou componen model allows o a p ecise specifica ion o ca dinali ies using in ege s
o lowe and uppe bound, bu s ill enables o use an as e isk o suppo an a bi a y
numbe o ins ances. Suppo ing p ecise ca dinali ies is especially use ul o simula ions
in a simula ion ool as MATLAB/Simulink as p esen ed in Chap e 6. In Figu e 3.5, he
componen pa man has a ca dinali y o [1]. Tha means any ins ance o Con oyCoo -
dina ion con ains exac ly one ins ance o Con oyManagemen . We call his a single pa .
e Gen has a ca dinali y o [1..∗]such ha an ins ance o Con oyCoo dina ion has a bi a y
many bu a leas one ins ance o Re Gen. In acco dance o Tichy, we call his a mul i
pa . In he conc e e syn ax, mul i pa s a e isualized by a cascaded bo de line [Tic09,
p. 38].
In Con oyCoo dina ion, he Con oyManagemen is esponsible o adding and emo ing
con oy membe s o he con oy and o nego ia ing he maximum speed o he con oy.
The in e ac ion wi h he con oy membe s is implemen ed in he po coo dina o ha
efines he ole coo dina o o he RTCP Con oyCoo dina ion [FHK+13, FHK+14]. We
p esen he RTCP Con oyCoo dina ion in Appendix A.1.2.
Fo each con oy membe , he Con oyCoo dina ion has one ins ance o he Re Gen mul i
pa ha gene a es e e ence da a o he con oy membe (c . [Tic09]). Re Gen ecei es
in o ma ion abou he co esponding con oy membe and he nego ia ed speeds om
Con oyManagemen ia p ofileRecei e . The in o ma ion abou he con oy membe s is
encapsula ed in so-called p ofiles [Hi 08, FHK+13, FHK+14]. The Re Gen ins ance o
he fi s con oy membe addi ionally ecei es he posi ion o he coo dina o RailCab ia
cu Pos. Then, Re Gen compu es a e e ence dis ance o he p eceding RailCab based on
he posi ion o his p eceding RailCab and he p ofile o he RailCab. This can be used
o adap he dis ances be ween RailCabs wi hin he con oy o changing en i onmen al
condi ions such as highe speeds, s ong wind, o slopes. Re Gen sends he new e e -
Page 70 Chap e 3
pa en componen ins ance. Po ins ances o s uc u ed componen ins ances ha e an
addi ional delega ion connec o ins ance o a po ins ance o an embedded componen
ins ance. Con inuous and hyb id po ins ances need o ulfill he same p ope ies, bu
wo excep ions apply. A con inuous o hyb id ou -po may ha e mo e han one ou -
going connec o ins ance, i.e., he signal alue may be send o se e al o he componen
ins ances. In addi ion, con inuous in-po s o a s uc u ed componen ins ance may be
delega ed o se e al embedded componen ins ances. A con inuous o hyb id po in-
s ance may also ha e no connec o ins ance i i is di ec ly a ached o ha dwa e as, e.g.,
ins ances o he po o ce o Veloci yCon olle . In any case, componen ins ances ha
a e embedded in a s uc u ed componen ins ance may only be connec ed by connec o
ins ances i he co esponding po ypes a e connec ed by a connec o in he s uc u ed
componen ype.
In addi ion, ou componen model uses h ee implici composi e agg ega ions o compo-
nen ins ances. Fi s , a componen ins ance ha is embedded in a s uc u ed componen
ins ance canno exis wi hou i s pa en . Second, a po ins ance canno exis wi hou i s
su ounding componen ins ance. Thi d, a connec o ins ance canno exis wi hou being
a ached o exac ly wo po ins ances [Tic09, p. 42].
Figu e 3.10 shows an ins ance o Con oyCoo dina ion ha is execu ed in a coo dina o
RailCab wi h one membe . I con ains an ins ance cm o ype Con oyManagemen and,
since he con oy has one membe , one ins ance g1 o ype Re Gen. Since g1 is as-
socia ed o he fi s con oy membe , i ecei es he cu en posi ion o he coo dina o
RailCab ia cu Pos. Fu he mo e, cc has ins ances o he coo dina o and e Dis P o ide
mul i po s o communica ing wi h he membe .
cc : Con oyCoo dina ion
cm / man :
Con oyManagemen
g1 / e Gen : Re Gen
:cu Pos:cu Pos
1: e Dis P o ide : e Dis P o ide
c1:coo dina o c1:coo dina o
:speedP o ide :speedP o ide
:s a egy : ecei e
p1:p o ileP o ide
:p o ileRecei e
Figu e 3.10: Componen Ins ance o Componen Con oyCoo dina ion o a Con oy wi h
1 Membe
Hi sch [Hi 08] and Tichy [Tic09] did no dis inguish be ween single po ins ances and
mul i po ins ances in he conc e e syn ax. Howe e , a mul i po ins ance has he same
s uc u e as a mul i ole ins ance (c . Sec ion 2.4.1), i.e., i con ains se e al subpo in-
s ances ha belong oge he . The e o e, we p opose o isualize he mul i po ins ance
by a dashed squa e ha g oups i s subpo ins ances as shown o he ins ances o co-
o dina o , e Dis P o ide , and p ofileP o ide in Figu e 3.10. The subpo ins ances a e
isualized as po ins ances as be o e.
Mecha onicUML Componen Model Page 71
We p esen addi ional componen ins ances o coo dina o RailCabs and membe Rail-
Cabs in Appendix A.4.
3.3 Modeling Reconfigu a ion
The exis ing componen models defined wo modeling languages o speci ying econ-
figu a ion beha io o econfigu able s uc u ed componen s. The componen model
by Tichy uses componen s o y diag ams (CSDs, [THHO08, Tic09]), which enable a
ule-based specifica ion o econfigu a ion beha io based on s o y diag ams (c . Sec-
ion 2.3.2). They enable o mal, modula , and concise models. In con as , hyb id e-
configu a ion cha s as p oposed by Bu mes e and Giese [GBSO04, BGO06, Bu 06]
p o ide a s a e-based model whe e each s a e con ains one configu a ion o a s uc u ed
componen ins ance. Hyb id econfigu a ion cha s quickly become e y la ge and un-
main ainable i a componen ins ance has se e al configu a ions. This is he case, o
example, o he componen Con oyCoo dina ion in Figu e 3.5 whe e we ha e a sequence
o Re Gen ins ances ha eflec s he o de o he con oy membe s on ack. As a esul ,
we chose o use CSDs o speci ying econfigu a ion o s uc u ed and a omic compo-
nen ins ances in ou componen model. We e e o Schube [Sch12] and ou echnical
epo [HB14] o a de ailed compa ison o hyb id econfigu a ion cha s and CSDs.
In he ollowing, we fi s in oduce CSDs as hey ha e been defined by Tichy (c . Sec-
ion 3.3.1). The ea e , we in oduce h ee ex ensions o CSDs ha we de eloped as
pa o his hesis. These a e con olle exchange nodes (c . Sec ion 3.3.2), cons ain s
o mul i po a iables (c . Sec ion 3.3.3), and CSDs o a omic componen s (c . Sec-
ion 3.3.4). These ex ensions add ea u es o CSDs ha a e necessa y o speci ying
econfigu a ion beha io in ou componen model. We illus a e hese ea u es based
on examples gi en in conc e e syn ax. A o maliza ion o CSDs is gi en by a me a-
model [SV06, ch. 4] whose abs ac syn ax is defined in Appendix D.2. The s a ic
seman ics has been o malized based on OCL cons ain s [G o12]. The ope a ional
seman ics o CSDs has al eady been defined by Tichy [Tic09, pp. 71 ] in o m o a
ansla ional seman ics [SK95] by defining a ans o ma ion o CSDs o s o y diag ams.
Ou ex ensions only ex end he ype sys em ha is used o he s o y diag ams and do
no equi e a new defini ion o he ope a ional seman ics.
3.3.1 Componen S o y Diag ams
In ou componen model, we use CSDs [THHO08, Tic09] o modeling econfigu a ion
o componen ins ances. Each componen con ains a se o CSDs ha define how in-
s ances o he componen may be econfigu ed a un ime. We define how and when
CSDs a e execu ed o a componen ins ance in Chap e 4.
CSDs a e based on s o y diag ams (c . Sec ion 2.3.2.2) and suppo he same con-
s uc s o speci ying con ol flow including a se o inpu and ou pu pa ame e s. The
Page 72 Chap e 3
s o y nodes o a CSD, howe e , con ain componen s o y pa e ns ins ead o s o y pa -
e ns [Tic09].
A componen s o y pa e n defines he modifica ion o a componen ins ance and, in
case o a s uc u ed componen ins ance, i s embedded CIC. We use he componen s
ha a e defined in ou componen model as a ype g aph o ype he a iables o he
componen s o y pa e n. Then, all a iables and links o he componen s o y pa e n
a e yped by he componen s, po s, and connec o s ha a e defined by he componen
model. The eby we can ensu e ha componen ins ances emain syn ac ically co ec
a e applying a componen s o y pa e n. In pa icula , we can ensu e ha a componen
s o y pa e n can only be execu ed i i s modifica ions do no iola e he ca dinali ies o
po s and componen pa s.
Each componen s o y pa e n con ains exac ly one his componen a iable. The his
a iable is yped by he componen ha con ains he co esponding CSD. A un ime,
he his a iable is au oma ically bound o he componen ins ance ha in oked he CSD
on i sel . Thus, i is a implici inpu pa ame e o any CSD [Tic09].
Figu e 3.11 shows a CSD becomeMembe o he componen RailCabD i eCon ol. The
CSD econfigu es an ins ance o RailCabD i eCon ol o a RailCab d i ing alone (c . Fig-
u e 3.9) o an ins ance o a RailCab d i ing as a membe o a con oy (c . Figu e A.31).
The CSD has wo s o y nodes. In he fi s s o y node, we ma ch he embedded com-
ponen ins ances o ypes Ope a ionS a egy,D i eLogic, and Veloci yCon olle . We des oy
he assembly connec o ins ance be ween os and dl. In addi ion, we in oke he econ-
figu a ion applyMembe S a egy on os ha des oys he speedP o ide po ins ance. We
explain his CSD in mo e de ail in Sec ion 3.3.4. In addi ion, we in oke he econfig-
u a ion swi chToCon oy on c ha econfigu es he eedback con olle s o d i ing as a
con oy membe . We in oduce his CSD in mo e de ail in Sec ion 3.3.2. In he second
s o y node, we c ea e an ins ance o Membe Con ol. In addi ion, we c ea e an ins ance
o Dis anceSenso and connec i o c by an assembly connec o ins ance. Finally, we
c ea e po ins ances o membe and e Dis Recei e on his and connec all po ins ances
o mc.
A CSD may speci y in oca ions o u he CSDs on embedded componen ins ances.
The in oca ion is di ec ly a ached o he co esponding componen a iable [Tic09,
p. 62] as shown in he fi s s o y node o he CSD becomeMembe in Figu e 3.11. We
define how such in oca ions a e execu ed wi h espec o he componen hie a chy in
Chap e 4.
In ou componen model, we es ic CSDs such ha hey espec componen encapsu-
la ion. In pa icula , we o bid ha a CSD di ec ly c ea es o des oys po ins ances
o embedded componen ins ances as i is allowed by Tichy [Tic09, p. 55]. Such po
ins ances may only be c ea ed by he embedded componen ins ance i sel . The co -
esponding CSD ha c ea es he po ins ance needs o be in oked on he embedded
componen ins ance as shown in Figu e 3.11.
Mecha onicUML Componen Model Page 73
his
Swi ch Ope a ion S a egy and des oy Assembly
C ea e Membe Con ol and Senso , Connec Po s
mc / membe :
Membe Con ol
his
c
:cu Dis : e Dis : e Dis
dl
:speedP o ide
:membe
:membe
:dis Recei e
: e Dis Recei e
:maxSpeed
ds / dis : Dis anceSenso
:dis ance
«c ea e»
«c ea e»
«c ea e»
«c ea e» «c ea e»
«c ea e»
«c ea e»
«c ea e»
os / s a egy :
Ope a ionS a egy
applyMembe S a egy()
dl / d i e :
D i eLogic
:maxSpeed
:speedP o ide
«des oy»
c / c l : Veloci yCon olle
swi chToCon oy()
RailCabD i eCon ol::becomeMembe ()
Figu e 3.11: CSD o Componen RailCabD i eCon ol ha Reconfigu es he Componen
Ins ance o Se e as a Membe
In acco dance o Tichy, a componen may define one o mo e cons uc o CSDs. A con-
s uc o CSD defines how ins ances o he componen a e ini ialized upon ins an ia ion.
Then, a componen a iable wi h s e eo ype «c ea e» may in oke a cons uc o [Tic09,
p. 62]. In addi ion, e e y componen defines an implici cons uc o ha ins an ia es all
po s and embedded componen s acco ding o hei minimum ca dinali y. The implici
cons uc o is always used i no explici cons uc o is in oked o a coponen a iable
wi h s e eo ype «c ea e». In Figu e 3.11, we used implici cons uc o s o bo h, ds
and mc. We p o ide an example o an explici cons uc o in Appendix A.6.2.
3.3.2 Con olle Exchange Nodes
The componen model by Tichy does no dis inguish be ween di e en kinds o com-
ponen s [Tic09]. Consequen ly, i does no enable o use ading unc ions, which a e
ypically equi ed when eplacing con inuous componen ins ances as explained in Sec-
ion 3.1.2.3.
Page 74 Chap e 3
As a solu ion, Schube [Sch12] in oduced con olle exchange nodes o enabling he
econfigu a ion o con inuous componen s. A con olle exchange node is a special kind
o s o y node ha enables sa e execu ion o ading unc ions. I has a fixed s uc u e
ha consis s o exac ly h ee componen a iables. Two o which e e ence con inuous
componen s whe e one is des oyed and one is c ea ed. The hi d componen a iable
e e s o he ading componen ha is connec ed o he wo con inuous componen s.
The componen a iable e e ing o he ading componen addi ionally specifies which
ading unc ion needs o be execu ed.
Pe o m ading o con oy con olle
Veloci yCon olle ::swi chToCon oy()
+-
[150 ms;180 ms]
+-
his
sd / s andalone_c l :
S andaloneD i e
: e Speed
:cu Speed
:cu Dis
cd / con oy_c l :
Con oyD i e
: e Speed
:cu Speed
: e Dis
: o ce
: o ce
:cu Dis
: e Speed
:cu Speed
: e Dis
/ ade :
Con oyFading
adeToCon oy()
:s andalone
:con oy
«des oy»
«c ea e»
«c ea e»
«c ea e»
«c ea e»
«c ea e»
«c ea e»
«des oy»
«des oy»
«des oy»
«c ea e»
«c ea e»
Figu e 3.12: CSD o Componen Veloci yCon olle ha Reconfigu es he Componen In-
s ance o Se e as a Membe
Figu e 3.12 shows he CSD swi chToCon oy ha uses a con olle exchange node. I is
in oked by becomeMembe and econfigu es an ins ance o Veloci yCon olle such ha i
uses an ins ance o Con oyD i e ins ead o S andaloneD i e. Consequen ly, i des oys he
la e and c ea es a new ins ance o he o me . Since bo h con inuous componen s p o-
ide a signal o ce, we need o use he ading componen Con oyFading o ade be ween
bo h signals. In he con olle exchange node o swi chToCon oy, we he e o e selec he
ading unc ion adeToCon oy o he econfigu a ion as specified wi hin he ading com-
ponen a iable. As indica ed in he uppe igh co ne o he con olle exchange node,
he ading akes be ween 150 ms and 180ms.
3.3.3 Cons ain s o Mul i Po Va iables
Mul i po s a e o de ed, i.e., he subpo ins ances a e a anged in a sequence as i has
been defined o mul i oles (c . Sec ion 2.4.1). Up o now, his o de canno be used in
Mecha onicUML Componen Model Page 75
componen s o y pa e n, o example, o c ea ing a subpo ins ance as a successo o
ano he subpo ins ance.
As an example, conside he componen Con oyCoo dina o shown in Figu e 3.5 on
Page 63. The subpo ins ances o an ins ance o he mul i po coo dina o shall ha e
he same o de as he co esponding con oy membe s on ack. Thus, i a new membe
joins he con oy a a pa icula posi ion, we need o inse a subpo ins ance a he same
posi ion in o he mul i po ins ance.
The e o e, we ex end componen s o y pa e ns by cons ain s o mul i po a iables
ha e e o he o de o he subpo ins ances [Hei14]. They a e inspi ed by so-called
link cons ain s o s o y diag ams [ DHP+12a]. In acco dance o hese link cons ain s,
we dis inguish be ween mul i po posi ion cons ain s and mul i po o de cons ain s.
Bo h o which a e illus a ed in Figu e 3.13.
O de Cons ain s
...
...
:po 1
his
«nex »
« i s »
«las »
Figu e 3.13: O de Cons ain s o Mul i Po Va iables
A mul i po posi ion cons ain enables o e e o he fi s (o las ) subpo ins ance o
a mul i po ins ance. In ou conc e e syn ax, we isualize i by a aching a s e eo ype
« i s » (o «las ») o he co esponding subpo a iable. In Figu e 3.13, he up-
pe subpo a iable ma ches he fi s subpo ins ance while he lowe subpo a iable
ma ches he las subpo ins ance.
A mul i po o de cons ain enables o e e o he ela i e o de o he subpo ins ances.
We enable o define ha a subpo ins ance is a di ec successo (o p edecesso ) o
ano he subpo ins ance. In ou conc e e syn ax, we isualize hese cons ain s by a
dashed a ow anno a ed wi h he s e eo ype «nex » (o «p e ») o deno e ha he
a ge subpo ins ance is a di ec successo (o di ec p edecesso ) o he sou ce subpo
ins ance. In Figu e 3.13, he lowe subpo ins ance has o be a di ec successo o he
uppe subpo ins ance o he mul i po ins ance o ype po 1 o success ully ma ching
he componen s o y pa e n.
Mul i po posi ion cons ain s and mul i po o de cons ain s may be pa o he LHS o
RHS o he componen s o y pa e n. A mul i po posi ion cons ain is pa o he LHS i
i is a ached o a subpo a iable wi h no s e eo ype o wi h s e eo ype «des oy».In
his case, he ma ched subpo a iable needs o ulfill he mul i po posi ion cons ain
o a success ul ma ching. A mul i po posi ion cons ain is pa o he RHS i i
Page 76 Chap e 3
in i := 1;
i (nex != null){
mpRe Gen := nex ;
nex := null;
mpC := c;
c := null}
[i < posi ion]
i++; [success]
[else]
[else]
[posi ion == 1]
[ ailu e]
cPo := newC,
Po := newR
Con oyCoo dina ion::addCon oyMembe A Pos(in posi ion) : (coo dina o cPo , e Dis P o ide Po )
Ge nex Re Gen
cm
mpC
his
mpRe Gen
c:coo dina o
«nex »
nex /
e Gen : Re Gen
:nex
:p e
mpP:p o ileP o ide
:p o ileRecei e
C ea e Embedded Po s
cm
(embC, embP) :=
c ea eMembe Po sA e ( mpC, mpP)
his
C ea e Embedded Po s
cm
(embC, embP) :=
c ea eFi s Membe Po s()
his
C ea e Re Gen
cm
his
mpRe Gen
c
newRe Gen /
e Gen : Re Gen
:nex
:p e
: e Dis P o ide
: e Dis P o ide
«c ea e»
«c ea e»
: e Dis P o ide
newR:
e Dis P o ide
«nex »
«c ea e»
«c ea e»
embP
:p o ileRecei e
«c ea e»
newC:coo dina o «c ea e»
«c ea e»
nex /
e Gen : Re Gen
:nex
:p e
mpC
: e Dis P o ide : e Dis P o ide
«nex »
«c ea e»
«des oy»
«nex »
«nex »
embC
C ea e Re Gen a Beginning
cm
his
newRe Gen /
e Gen : Re Gen
embC
«nex »
mpRe Gen
:nex
:p e
:cu Pos:cu Pos
newR:
e Dis P o ide
: e Dis P o ide
« i s »
«c ea e»
«c ea e»
«c ea e»
«c ea e»
: e Dis P o ide
: e Dis P o ide
«nex »
«c ea e»
:cu Pos
:cu Pos
«des oy» «des oy»
«des oy»
«c ea e»
embP
:p o ileRecei e
«c ea e»
newC:
coo dina o
« i s » «c ea e»
«c ea e»
« i s »
Ge i s Re Gen
cm / man :
Con oyManagemen
mpC:coo dina o
his
« i s »
mpRe Gen /
e Gen : Re Gen
:cu Pos:cu Pos
Figu e 3.14: CSD o Adding a Con oy Membe (c . [Tic09, Sch12])
Mecha onicUML Componen Model Page 77
is a ached o a subpo a iable wi h s e eo ype «c ea e». In his case, he c ea ed
subpo ins ance is inse ed a he specified posi ion in o he mul i po , i.e., ei he a fi s
o las posi ion. A mul i po o de cons ain is pa o he RHS i a leas one o he
a ached subpo a iables ca ies a «c ea e» s e eo ype. I is pa o he LHS in all
o he cases. I is no allowed o connec a subpo a iable s e eo yped wi h «c ea e»
and a subpo a iable s e eo yped wi h «des oy» by a mul i po o de cons ain .
Figu e 3.14 shows an example o a complex CSD o he componen Con oyCoo dina ion
ha implemen s he a o emen ioned use case o adding a new con oy membe a a spe-
cific posi ion o he con oy. The CSD akes a posi ion as i s inpu and e u ns he subpo
ins ances ha ha e been c ea ed o he mul i po s coo dina o and e Dis P o ide o Con-
oyCoo dina ion. In addi ion o he subpo ins ances, he CSD also c ea es an ins ance o
he Re Gen mul i pa .
The beha io o he CSD addCon oyMembe A Posi ion is as ollows. The fi s s o y node
ma ches he fi s Re Gen ins ance which is he only one ha ing an ins ance o he cu Pos
po . Ma ching his s o y node will always succeed because he co esponding com-
ponen pa s a e bo h manda o y. The ea e , he s a emen node ini ializes a coun e
a iable i ha is used o i e a ing o e he lis o Re Gen ins ances un il he ins ance
a he posi ion gi en as pa ame e has been ound. The i e a ion is pe o med ia he
s o y node and he wo s a emen nodes in he uppe igh co ne . The componen s o y
pa e n in he s o y node uses a mul i po o de cons ain o i e a ing o e he subpo
ins ances o coo dina o .
I he co ec posi ion has been ound, he s o y node in he lowe le co ne inse s
an ins ance o e Gen a he beginning o he lis , while he s o y node in he lowe
igh inse s an ins ance o e Gen a any o he posi ion. Along wi h he ins ance o
Re Gen, we c ea e subpo ins ances o he mul i po s coo dina o and e Dis P o ide o
his and inse hem a he co esponding posi ions. In he s o y node C ea e Re Gen a
Beginning, we use he « i s » s e eo ype wo imes wi hin he same mul i po a iable.
This is allowed because one is pa o he LHS o ma ching he p e iously fi s subpo
ins ance while he o he one is pa o he RHS. Finally, he final node assigns he c ea ed
subpo ins ances newC o ype coo dina o and newR o ype e Dis P o ide o he ou pu
pa ame e s cPo and Po , espec i ely.
3.3.4 Reconfigu a ion o A omic Componen s
In ou componen model, we use CSDs o econfigu ing a omic componen s as well.
Tichy nei he explici ly defined no es ic ed CSDs in ha way [Tic09]. The only di -
e ence o a CSD o a s uc u ed componen is ha we isualize he his componen
a iable as an a omic componen . Then, he his componen a iable may only con ain
po a iables bu no embedded componen a iables (c . [BDG+14b]).
Figu e 3.15 shows he CSD applyMembe S a egy ha is in oked in he fi s s o y node
o becomeMembe shown in Figu e 3.11. Ope a ionS a egy is an a omic componen and,
Page 78 Chap e 3
Dele e speedP o ide Po
Ope a ionS a egy::applyMembe S a egy()
his
«des oy»
:speedP o ide
Figu e 3.15: CSD o Componen Ope a ionS a egy ha Reconfigu es he Po s o Being
Membe
he e o e, he his a iable has no embedded componen a iables. The CSD dele es he
speedP o ide po ins ance because he e e ence speed o a membe is defined by he
coo dina o and no by i s own ope a ion s a egy.
3.4 Ins an ia ing Real-Time Coo dina ion P o ocols on
Sys em Le el
RTCPs on he sys em le el define he communica ion be ween di e en AMS while hey
collabo a e in an NMS. Since NMS a e i ual, he e does no exis a componen ha
con ains bo h AMS and ha may ins an ia e an RTCP be ween he AMS. Consequen ly,
he ins an ia ion canno be desc ibed by CSDs, bu he AMS need o ag ee on ins an i-
a ing a pa icula RTCP ia message-based communica ion. This, howe e , equi es a
leas one o he AMS o know abou he exis ence o he o he AMS. Then, one o he
AMS may ini ia e he communica ion o ag eeing on he ins an ia ion. This communi-
ca ion, howe e , canno be handled by he disc e e po s and connec o s in oduced in
Sec ion 3.1 because hei ins ances al eady equi e a connec o wi h a RTCP.
Fo sol ing his p oblem, we need o elax he s ic equi emen o MECHATRONIC-
UML ha all communica ion be ween AMS is exclusi ely handled by RTCPs wi h
single-cas connec o s [GTB+03, EHH+13]. In pa icula , we use b oadcas po s as
in oduced in Sec ion 3.1.1.3 ha enable o b oadcas communica ion. Whene e an
AMS sends a message ia a b oadcas po , he message is ecei ed by all o he b oad-
cas po s "in each" ha can p ocess his message. Which b oadcas po s a e in each
depends on he spa ial dis ibu ion o he AMS as well as he ansmission medium. In
gene al, i is no known a design ime which po s will ecei e a message and which
will no . In o de o e ain he sa e y gua an ees p o ided by he use o RTCPs, we only
allow he use o b oadcas po s o wo special pu poses. Fi s , o gaining knowledge
abou he exis ence o o he sys ems and, second, o ins an ia ing one pa icula RTCP
called P o ocolIns an ia ion. This RTCP hen enables o ins an ia e u he RTCPs. No
u he b oadcas po s a e allowed in a MECHATRONICUML model.
Mecha onicUML Componen Model Page 79
Following he e minology o Ba esi e . al. [BDNG06], gaining knowledge abou o he
sys ems is only equi ed in so-called open-wo ld scena ios. In an open-wo ld scena io,
sys ems do no know each o he in ad ance and he possible communica ion pa ne s
change equen ly o e ime. Fo example, RailCabs mo e along he ack sys em and
do no know when o whe e hey mee which o he RailCab. In his case, we may need o
use a b oadcas po ha execu es a so-called disco e y p o ocol [NNSS07] ha de ec s
and ga he s knowledge abou he sys ems in he en i onmen . This in o ma ion needs
o be s o ed in an en i onmen model ha may be used by he cogni i e ope a o o he
OCM o deciding which o he sys ems a e sui able o which coope a ion. We p esen
a simple disco e y p o ocol and en i onmen model in Appendix A.2.1, bu we do no
conside his use case in de ail as pa o his hesis.
In he ollowing, we illus a e how we use a b oadcas po o ins an ia ing he RTCP
P o ocolIns an ia ion o wo AMS (Sec ion 3.4.1). The ea e , we show how o use he
RTCP P o ocolIns an ia ion o ins an ia ing u he RTCPs (Sec ion 3.4.2).
3.4.1 Ins an ia ing he RTCP P o ocolIns an ia ion
An AMS may use i s p o ocolIns b oadcas po o con ac ing ano he AMS o ins an i-
a ing a connec o including he P o ocolIns an ia ion RTCP. P o ocolIns an ia ion is he only
RTCP ha may be ins an ia ed ia b oadcas communica ion. All o he RTCPs need o
be ins an ia ed ia P o ocolIns an ia ion o as pa o ano he , use -defined RTCP.
Assump ions Fo ins an ia ing he RTCP P o ocolIns an ia ion, he AMS ha ini ia es
he ins an ia ion needs o know he o he sys em in i s en i onmen model. Based on
his, we apply he ollowing assump ions o he ins an ia ion p ocess:
1. Each AMS has a unique ID ha is known o he RTSC o he b oadcas po .
2. The e may exis di e en e sions o his message exchange ha only di e in hei
iming cons ain s as, e.g., imeou s, whe e each e sion has a unique iden ifie .
The b oadcas po knows he ID o he e sion ha i implemen s.
3. The IDs a e ep esen ed using a da a ype ha can be sen as a pa ame e o a
message.
4. No message loss occu s du ing he in e ac ion.
5. No ea esd oppe ies o comp omise o p e en he connec ion se up.
Since he di e en e sions only di e in hei iming cons ain s, he message exchange
o ins an ia ing he RTCP P o ocolIns an ia ion may be used in di e en sys ems wi hou
modifica ion.
Page 86 Chap e 3
cc, ps
hen
0
RailCabD i eCon ol::isS andalone
his
cc / con oy :
Con oyCoo dina ion
:cu Pos
ps / pos : Posi ionSenso
:posi ion
mc
his
mc / membe :
Membe Con ol
hen else
01
else
Figu e 3.20: Componen SDD isS andalone o Componen RailCabD i eCon ol
e alua ion needs o e mina e a a (1)-node o any ma ching ha can be ob ained o he
uni e sal pa e n node.
The in a ian componen SDD con oyO de shown in Figu e 3.21 specifies ha any wo
successi e subpo ins ances o e Dis P o ide a e delega ed o successi e subpo in-
s ances o Con oyCoo dina ion. This ensu es ha e e ence speeds and dis ances can al-
ways be dis ibu ed wi hin he con oy in he igh o de . In he componen SDD, he
fi s pa e n node ma ches an ins ance o Con oyCoo dina ion ha is embedded in RailCab-
D i eCon ol. The second pa e n node is a uni e sal pa e n node ha ma ches all pai s
o successi e e Dis P o ide po ins ances. Fo any ma ch ha may be ob ained o his
pa e n node, he hi d pa e n node needs o be ma ched as well such ha he execu ion
e mina es a he (1)-node. I he e exis s no ma ching o he uni e sal pa e n node,
hen he componen SDD is ulfilled. Fo his eason, we only isualize one ou going
hen-edge o an uni e sal pa e n node as a sho hand no a ion [S a08, p. 63].
A componen SDD may equi e ha an embedded componen ins ance has a componen
p ope y wi h a pa icula alue. This componen p ope y may be specified, again,
using a componen SDD. This enables o connec a chi ec u al cons ain s h ough he
di e en hie a chy le els o he componen model. In Figu e 3.21, he pa a iable cc in
he uni e sal pa e n node equi es ha he componen p ope y con oyO de is ue o
he componen ins ance ma ched o cc.
Mecha onicUML Componen Model Page 87
1
cc
hen
«in a ian »
RailCabD i eCon ol::con oyO de
dp1, dp2
his
cc
[con oyO de ]
dp1: e Dis P o ide
«nex »
dp2: e Dis P o ide
his
cc / con oy :
Con oyCoo dina ion
hen else
dp3, dp4
his
cc
dp1
dp2
dp3: e Dis P o ide
«nex »
dp4: e Dis P o ide
hen else
01
Figu e 3.21: Componen SDD con oyO de o Componen RailCabD i eCon ol
Page 88 Chap e 3
3.6 Implemen a ion
The concep s p esen ed in his chap e ha e been implemen ed as pa o he MECHA-
TRONICUML Tool Sui e1[DGB+14]. We ha e buil a me amodel (c . Appendix D) and
se e al diag am edi o s o c ea ing models based on ou componen model. In con as
o he p e ious e sion o he ool, called Fujaba Real-Time Tool Sui e [PTH+10], he
me amodel has been de eloped using he Eclipse Modeling F amewo k (EMF,
[SBPM08]). The s a ic seman ics has been comple ely encoded in he me amodel us-
ing OCL [G o12]. Figu e 3.22 p o ides a concep ual o e iew o he Eclipse plugins
ha ha e been c ea ed.
«de.uni_pade bo n. ujaba»
muml
«o g.s o yd i en»
s o ydiag ams
«de.uni_pade bo n. ujaba.muml»
econ igu a ion
«de.uni_pade bo n. ujaba.muml»
componen s o ypa e n
«de.uni_pade bo n. ujaba.muml»
componen s o ydiag am
«de.uni_pade bo n. ujaba.muml. e i ica ion.sdd»
componen SDD
«de.uni_pade bo n. ujaba.muml»
componen .diag am
«de.uni_pade bo n. ujaba.muml»
componen ins ance
con igu a ion.diag am
«de.uni_pade bo n. ujaba.muml»
econ igu a ion.ui
«de.uni_pade bo n. ujaba.muml. e i ica ion.sdd»
componen SDD.diag am
«de.uni_pade bo n. ujaba.muml»
componen s o ydiag am.diag am
«ex ends»
«ex ends»«ex ends»
«ex ends»
«ex ends»
«ex ends»
«ex ends»
«ex ends»
«uses»
«uses»
«uses»
«uses»
«uses»
«package»
plugin name
«package»
plugin name
Legend: Me amodel Plugin Diag am Edi o Plugin
Figu e 3.22: Plugins Implemen ing he Concep s o he Componen Model
The plugin muml con ains he co e me amodel o MECHATRONICUML. I enables o
speci y componen s and CICs including RTCPs and RTSCs. In muml, we only suppo
non- econfigu able componen s in o de o ha e a co e language ha can be used o
simple, non-adap i e sys ems. Reconfigu able componen s a e modeled in he plugin
econfigu a ion. This plugin also con ains he me amodel o b oadcas po s. The me a-
model o CSDs has been spli in o wo plugins. The fi s one, called componen s o ypa -
e n, enables o speci y componen s o y pa e ns based on econfigu able componen s.
The componen s o ydiag am plugin adds he s o y nodes ha a e special o CSDs. The
me amodel o CSDs ex ends he s o y diag am me amodel [HR D+11] con ained in he
plugin s o ydiag ams and euses as much o he implemen a ion as possible. In addi ion,
we euse he componen s o ypa e n me amodel o speci ying componen SDDs. The
co esponding plugin componen SDD only defines he nodes and edges o componen
SDDs and uses he same componen s o y pa e n implemen a ion as CSDs. We p esen
class diag ams o ou me amodels in Appendix D.
1h ps:// ac.cs.upb.de/mecha onicuml
Mecha onicUML Componen Model Page 89
Based on he me amodels, we de eloped ou diag am edi o s using he g aphical mod-
eling amewo k (GMF, [G o09]). In pa icula , we c ea ed edi o s o speci ying com-
ponen s, CICs, CSDs, and componen SDDs. The econfigu a ion.ui plugin ex ends he
componen edi o such ha i may also be used o modeling econfigu able compo-
nen s.
A p esen , ou implemen a ion does no ye suppo he specifica ion componen p op-
e ies o a componen . Componen SDDs a e cu en ly only used as pa o ou ansac-
ional econfigu a ion app oach as discussed in Chap e 4. S a emen nodes o CSDs a e
no ye suppo ed as well.
3.7 Rela ed Wo k
This sec ion ela es ou new componen model o MECHATRONICUML o o he ap-
p oaches o defining so wa e a chi ec u es. Fi s , we compa e i o o he so wa e
componen models (Sec ion 3.7.1). Second, we ela e i o a chi ec u e desc ip ion lan-
guages (ADLs, [MT00]) o sel -adap i e sys ems (Sec ion 3.7.2). Finally, we discuss
ela ed wo ks ega ding he specifica ion o a chi ec u al cons ain s o a componen -
based sys em (Sec ion 3.7.3).
3.7.1 So wa e Componen Models
The su eys by Lau [LW07] and C nko i´
c e al. [CSVC11] e iew di e en kinds o
componen models. They dis inguish be ween gene al pu pose componen models as,
o example, CORBA [G o11a] and EJB [O a13], and specialized componen models
o pa icula domains. The la e usually add ess business in o ma ion sys ems o em-
bedded eal- ime sys ems. In his sec ion, we ocus p ima ily on componen models o
embedded eal- ime sys ems and on componen models ha suppo un ime econfigu-
a ion.
Hošek e al. [HPB+10] su eyed componen models o embedded eal- ime sys ems.
Only ew o which suppo un ime econfigu a ion including SOFA-HI, MyCCM-HI,
P oCom, BlueA X, and AUTOSAR. All o hese componen models a e es ic ed o
mode changes [HKMU06] whe e a componen ins ance mo es om one implemen a ion
o ano he one. SOFA-HI [PWT+08, PKH+11] is an ex ension o he SOFA 2.0 [HP06,
HB07] componen model o eal- ime sys ems. I enables o speci y hie a chical com-
ponen s ha a e conside ed o be implemen ed manually in C. In con as o SOFA 2.0,
econfigu a ions in SOFA-HI canno change connec o s a un ime [PWT+08, HPB+10].
MyCCM-HI [BFHP09] ex ends he OMG CORBA Componen Model (CCM, [G o11a])
o speci ying adap i e embedded sys ems wi h a ex ual syn ax. I enables a de ailed
specifica ion o asks and hei ac i a ion bu does no define how he beha io o asks
is implemen ed. A mode change o a s uc u ed componen may econfigu e connec-
o s. The BlueA X componen model by Bosch [KKH+08, KRKH09] also p o ides he
specifica ion o hie a chical componen s wi h mode changes. In BlueA X, he beha io
Page 90 Chap e 3
o a componen is defined by signal flows. In addi ion, each componen defines a se
o asks including a scheduling o hese asks. A mode swi ch may ei he change he
signal flow inside a componen o i may change he ask scheduling. Mode changes
canno be composed hie a chically. The P oCom componen model [VSC+09] has e-
cen ly been ex ended o suppo hie a chical econfigu a ion based on mode changes
as well [HQCH13]. We discuss his app oach in de ail in Sec ion 4.8 along wi h ou
ansac ional econfigu a ion app oach. Fo au omo i e sys ems, he AUTOSAR s an-
da d [FMB+09] defines a componen model o speci ying hie a chical componen s.
AUTOSAR does no speci y how applica ion so wa e componen s a e implemen ed
[AUT14c]. As o e sion 4.0, AUTOSAR suppo s modes [AUT14a] and a iming
specifica ion [AUT14b]. Modes only enable o ac i a e and deac i a e igge e en s
in a omic so wa e componen s he eby changing hei beha io . The iming specifi-
ca ion enables o define pe iods and o de s o e en s as well as end- o-end deadlines
o chains o e en s. All o hese componen models ha e in common ha hey do no
p o ide means o speci y and e i y asynch onous message-based communica ion wi h
eal- ime p ope ies and ha hey only p o ide limi ed econfigu a ion capabili ies. In
con as , CSDs o MECHATRONICUML p o ide a mo e powe ul and flexible specifica-
ion o econfigu a ions ha includes con ol flow and econfigu a ions ac oss di e en
le els o hie a chy (see also Chap e 4).
F ac al [BCL+06, LLC10] p o ides he defini ion o hie a chical componen s includ-
ing un ime econfigu a ion o s uc u ed componen s. Each componen consis s o a
memb ane and a con en a ea. The con en a ea embeds o he componen s while he
memb ane con ains so-called con olle s ha enable in ospec ion and econfigu a ion.
Al hough F ac al p o ides a C-implemen a ion called Think [AHJ+09], i does no p o-
ide he abili y o speci y clock-based eal- ime p ope ies o componen s o o e i y
he unc ional beha io o he econfigu a ion specifica ion.
The DEECo componen model [BGH+13] p o ides non-hie a chical componen s o
so eal- ime sys ems based on ensembles. While being in an ensemble, componen s
may communica e and exchange knowledge. The communica ion, howe e , is no ex-
plici ly modeled in hei app oach. Componen s decla a i ely speci y condi ions o
being pa o an ensemble and a sha ed un ime amewo k au oma ically cons uc s and
dissol es ensembles based on hese condi ions. De Nicola e al. [DNFLP13] p esen
a ex ual language named SCEL ha enables o exp ess hese condi ions as policies
including he necessa y modifica ions o he so wa e a chi ec u e o es ablishing he
ensemble. In con as o MECHATRONICUML, bo h app oaches nei he p o ide u he
econfigu a ions o componen s and no eal- ime cons ain s in hei beha io specifi-
ca ion. In [BBCP13], Ba na e al. in oduce DCCL ha is a o mal componen spec-
ifica ion implemen ing he concep s o DEECo. They p o ide an LTL model checking
o ensembles p o ing p ope ies conce ning he knowledge o componen s bu no hei
beha io o he s uc u e o he ensembles.
CompoSE [KKTS09, ASTPH10] defines a hie a chical componen model o modeling
embedded sys ems. A omic componen s may be implemen ed in a di e en language
Mecha onicUML Componen Model Page 91
compa able o ou con inuous componen s. Each a omic componen defines a se o
configu a ions each consis ing o a se o po s and a compu a ion ha defines he beha -
io . S uc u ed componen s speci y configu a ions based on combina ions o po s and
embedded componen ins ances. A un ime, a componen may swi ch be ween configu-
a ions. In con as o MECHATRONICUML, he app oach does no suppo using ading
unc ions and message-based communica ion.
EAST-ADL2 [CFJ+10] is an a chi ec u e desc ip ion language a ge ed o he de elop-
men o au omo i e sys ems. I p o ides a componen specifica ion whe e componen s
e e o an ex e nal implemen a ion, e.g., specified in MATLAB/Simulink [Ma g]. The
componen model can be mapped o he AUTOSAR componen model bu does no
ye suppo modes. Simila o MECHATRONICUML, i ocuses on he in eg a ion o
eedback con olle s bu p o ides no means o o mal e ifica ion o un ime econfig-
u a ion.
O he componen models o embedded eal- ime sys ems like Koala [ O dLKM00],
Robocop [Maa05], Sa eCCM [CHP06, ÅCF+07], Rubus [HMTN+08], COMDES-II
[KSA07], PECOS [GCW+02], and CHESS [PV14] p o ide he abili y o speci y eal-
ime beha io on a low le el o abs ac ion. They suppo o mal analysis as ou com-
ponen model bu nei he suppo message-based communica ion (excep COMDES-II)
no un ime econfigu a ion.
All o he men ioned app oaches excep DEECo do no p o ide a concep o ins an ia -
ing connec o s on sys em le el.
3.7.2 ADLs o Sel -Adap i e Sys ems
ADLs [MT00] speci y so wa e a chi ec u es based on componen s and connec o s, al-
hough he e m componen is less s ic ly defined as o componen models. Connec o s
define he in e ac ion o componen s, cons ain s define es ic ions ha he a chi ec u e
needs o ollow while i e ol es, and a chi ec u al s yles a e amilies o ela ed a chi ec-
u es [GMW00].
B adbu y e al. [BCDW04] su ey ADLs ha enable un ime econfigu a ion o he so -
wa e a chi ec u e. They classi y hese ADLs in o h ee ca ego ies: g aph-based, p ocess
algeb a-based, and o mal logic-based. G aph-based app oaches define an ini ial con-
figu a ion ha is modified by g aph ew i ing ules. Examples include CHAM [IW95]
and he app oaches by Le Mé aye [LM98] and Hi sch e al. [HIM98]. MECHATRON-
ICUML also belongs o his ca ego y. P ocess algeb a-based app oaches like Dynamic
W igh [ADG98], Da win [KM98], o he app oach by Ba els and Kleine [BK11] spec-
i y p ocesses o each configu a ion using a p ocess algeb a like he π-calculus [MPW92]
(Da win) o CSP [Hoa85] (Dynamic W igh , Ba els and Kleine). A un ime, compo-
nen s swi ch be ween p ocesses o execu e econfigu a ions. Fo mal-logic-based ap-
p oaches like he app oach by Agui e and Maibaum [AM02] o GeReL [EW92] decla -
a i ely speci y componen beha io and cons ain s based on fi s -o de logic. All o
Page 92 Chap e 3
he men ioned app oaches ely on a ex ual specifica ion and enable checking o a chi-
ec u al cons ain s. Howe e , hey do no suppo eal- ime cons ain s o unc ional o
econfigu a ion beha io . Mos app oaches discussed abo e (excep Da win and GeReL)
do no suppo s uc u ed componen s.
The app oach by Kacem e al. [KKJ12] specifies a sys em model using UML 2.0 com-
ponen s [G o05]. They speci y econfigu a ions by g aph ans o ma ions using he con-
c e e syn ax o componen s ha a e gua ded by OCL cons ain s [G o12]. In con as
o MECHATRONICUML, hey do no suppo con ol flow in hei ules. They suppo
e i ying cons ain s by ansla ing hei specifica ion o Z [Spi92]. In con as o MECH-
ATRONICUML, hey do no suppo hie a chical componen s and eal- ime p ope ies.
3.7.3 Cons ain Languages
We compa e ou app oach o modeling a chi ec u al cons ain s by componen SDDs
o wo kinds o cons ain s languages. Fi s , we compa e i o objec -based cons ain s
languages ha a e defined based on classes and objec s (c . Sec ion 3.7.3.1). Second,
we compa e componen SDDs o cons ain languages ha we e defined based on com-
ponen s, mos ly as pa o an a chi ec u e desc ip ion language (c . Sec ion 3.7.3.2).
3.7.3.1 Objec -Based Cons ain Languages
App oaches in his ca ego y enable o speci y cons ain s o app oaches ha a e based
on classes, e e ences, and objec s. P obably he mos well-known example is OCL
[G o12]. OCL suppo s he ex ual specifica ion o complex s uc u al p ope ies o
classes, e.g., using i e a o s, se s, and selec ions.
In [FHTW05], Fish e .al. compa e wo isualiza ions o OCL: isual OCL [BKPPT01,
KTW02] and cons ain diag ams [Ken97]. Visual OCL uses a g aph-based syn ax o
isualizing OCL cons ain s which is de i ed om he UML 1.4 no a ion [G o01]. Con-
s ain diag ams [Ken97] use a isual no a ion ha is inspi ed by UML and Venn di-
ag ams [Ven80]. In [FFH05], cons ain diag ams a e ex ended by a pa ial o de o
quan ifie s and hei seman ics is defined based on fi s -o de p edica e logic.
All o hese app oaches suppo he specifica ion o a chi ec u al cons ain s based on
he abs ac syn ax o he componen model. Tha equi es he de elope , who specifies
componen s based on conc e e syn ax, o ansla e he cons ain s o he abs ac syn ax
o he componen model. This in oduces addi ional complexi y o a de elope ha
keeps him om e ec i ely speci ying cons ain s.
3.7.3.2 Componen -Based Cons ain Languages
App oaches in his ca ego y enable o speci y cons ain s based on a componen specifi-
ca ion ei he p o ided by an a chi ec u e desc ip ion language o a componen model.
Mecha onicUML Componen Model Page 93
The ADL Dynamic W igh [ADG98] suppo s he specifica ion o cons ain s based on
fi s -o de logic using a ex ual no a ion. The cons ain s di ec ly e e o he compo-
nen s and connec o s defined by he a chi ec u al s yle. A mani [Mon01] is a cons ain
language o he Acme ADL [GMW00]. I allows o speci y a chi ec u al cons ain s
in a fi s -o de p edica e logic using a ex ual conc e e syn ax. In con as o ou ap-
p oach, nei he Dynamic W igh no A mani enable o e e o p ope ies o embedded
componen s.
FPa h [DLLC09] is a ex ual que y language based on he F ac al componen model. I
is inspi ed by XPa h [W3C10] and allows o selec a se o embedded componen s in a
hie a chical F ac al componen ac oss di e en le els o hie a chy. The e o e, i equi es
knowledge o he implemen a ion o all componen s he eby b eaking encapsula ion.
FPa h is no explici ly defined as a cons ain language, bu may be used like one.
The ACL amily o a chi ec u e cons ain languages [TFS10, TSDF11] enables he
specifica ion o cons ain s o componen s independen o a conc e e componen model.
I suppo s wo le els o abs ac ion: an objec le el using an OCL-like language called
CCL (co e cons ain language) and an a chi ec u e-le el cons ain language. In he la -
e , cons ain s a e modeled as special cons ain componen s ha a e connec ed o he
unc ional componen s by special non- unc ional o cons ain po s e en ac oss di e -
en le els o hie a chy. The cons ain s a e hen e ified a design- ime o ensu e ha
componen s a e co ec ly assembled and implemen ed. In con as o ou app oach, hey
do no enable o e alua e hei cons ain s du ing un ime.
3.8 Summa y
In his chap e , we in oduce a consolida ed componen model o MECHATRONICUML
ha enables o speci y so wa e a chi ec u es o sel -adap i e mecha onic sys ems.
The eby, ou componen model p ima ily add esses he eflec i e ope a o o he OCM
e e ence a chi ec u e bu also includes he in e ace o he eedback con olle s on he
con olle le el. The e o e, i combines and enhances wo exis ing componen mod-
els o MECHATRONICUML ha ha e been c ea ed by Bu mes e , Giese, and Hi sch
[GTB+03, GBSO04, BGO06, HHG08, GS13] as well as Tichy [THHO08, Tic09]. In a
li le mo e de ail, we use he necessa y dis inc ion o disc e e a omic componen s and
con inuous a omic componen s ep esen ing eedback con olle s om Bu mes e and
Giese [GBSO04, BGO06]. In addi ion, we use he specifica ion o s uc u ed com-
ponen s by means o componen pa s om Tichy [Tic09]. Compa ed o he p e i-
ous componen models, ou new componen model gua an ees componen encapsula-
ion, en o ces a sepa a ion o conce ns be ween unc ional and econfigu a ion beha -
io , and imp o es semio ic cla i y [Moo09] o he conc e e syn ax. In ou componen
model, we use CSDs [THHO08, Tic09] o speci ying econfigu a ions o componen s
because hey enable o a mo e concise specifica ion compa ed o hyb id econfigu a-
ion cha s [GBSO04, BGO06]. Fu he mo e, we in oduce a concep o ins an ia ing
RTCPs be ween AMS ha a e no ye connec ed wi h each o he . Finally, we defined
Page 94 Chap e 3
componen SDDs ha enable o speci y a chi ec u al cons ain s and componen p ope -
ies based on he so wa e a chi ec u e.
We unde pin he sui abili y o ou componen model o speci ying so wa e a chi ec-
u es o sel -adap i e mecha onic sys ems by p o iding a so wa e a chi ec u e o he
RailCab sys em (c . Sec ion 1.1) ocussing on he con oy mode. Ou example includes
he componen defini ions and he necessa y CSDs o ealizing RailCab con oys. Ad-
di ional CICs and CSDs o he example scena io a e gi en in Appendix A. We use his
example as a basis o illus a ing he u he con ibu ions o his hesis in he subse-
quen chap e s.
T ansac ional Execu ion o Hie a chical Reconfigu a ions Page 95
4 T ansac ional Execu ion o Hie a chical
Reconfigu a ions
Reconfigu a ions in a hie a chical componen model o en equi e he econfigu a ion o
se e al componen s ha a e loca ed on di e en le els o hie a chy. As an example, he
econfigu a ion o a s uc u ed componen ins ance may equi e he up on econfigu a-
ion o one o mo e o i s child en as i has been shown in he example o Figu e 3.11.
In his example, c ea ing he ins ance mc o Membe Con ol equi es o econfigu e he
ins ances o Ope a ionS a egy and Veloci yCon olle fi s . Then, he po ins ances c ea ed
by hese econfigu a ions a e connec ed by RailCabD i eCon ol. In gene al, we dis in-
guish wo use cases o such econfigu a ions.
In Use Case 1, an embedded componen ins ance, in he ollowing e e ed o as child,
de ec s a si ua ion ha equi es a econfigu a ion ha i canno handle by i sel . In ou ex-
ample in Figu e 3.6, he Ope a ionS a egy componen nego ia es ha he RailCab en e s
a con oy, bu i does no know how o do his i sel . Thus, i needs o send a eques o
he embedding s uc u ed componen ins ance o ype RailCabD i eCon ol o handle ha
si ua ion and o execu e he necessa y econfigu a ion. We will e e o he embedding
s uc u ed componen ins ance as pa en in he ollowing.
In Use Case 2, a s uc u ed componen ins ance execu es a econfigu a ion ha equi es
he econfigu a ion o one o mo e o i s child en. In ou example, becoming a membe
o a con oy equi es a econfigu a ion o he RailCabD i eCon ol (c . Figu e A.31). Exe-
cu ing his econfigu a ion, howe e , equi es ha he Ope a ionS a egy changes i s po
ins ances and ha he Veloci yCon olle swi ches o he Con oyD i e componen ins ance
(c . Figu e 3.12). The e o e, RailCabD i eCon ol needs o igge he co esponding e-
configu a ions on i s child en.
Fo bo h use cases, execu ing such econfigu a ions sa ely demands ha all componen
ins ances, which a e equi ed o econfigu e, pe o m hei econfigu a ion in a coo di-
na ed way. The necessa y condi ions o execu ing a hie a chical econfigu a ion sa ely
a e gi en by he ACI-p ope ies (a omici y, consis ency, and isola ion) o da abase sys-
ems [BHG87, LLC10] and a co ec iming. A omici y equi es ha ei he all o no
componen ins ances, which need o econfigu e, execu e hei econfigu a ion. I e-
configu a ions a e only execu ed pa ially, he sys em is usually unsa e. Consis ency
equi es ha any componen ins ance has a alid a chi ec u e be o e and a e each e-
configu a ion. Isola ion ensu es ha econfigu a ions do no in e e e wi h each o he .
In e e ence o econfigu a ions esul s in in alid a chi ec u es. A co ec iming de-
mands ha i a ha d deadline o execu ing a econfigu a ion exis s, he sys em needs o
make su e ha i mee s he deadline be o e s a ing o econfigu e. Fo he emainde , we
e e o hese p ope ies as ACI-T p ope ies. I a econfigu a ion is execu ed acco ding
o ACI-T p ope ies, we deno e his as ansac ional execu ion.
Page 102 Chap e 4
4.2.2 Th ee-Phase Execu ion
Single-phase execu ion o econfigu a ions as desc ibed in he p e ious sec ion canno be
applied i he econfigu a ion in ol es eplacing con inuous componen s. As an exam-
ple, conside he econfigu a ion o becoming a con oy membe shown in Figu e 3.11.
The econfigu a ion equi es ha he Veloci yCon olle swi ches om he S andaloneD i e
o he Con oyD i e eedback con olle (c . Figu e 3.7).
Figu e 4.7 shows an in e media e CIC ha would occu i we execu ed his econfigu-
a ion acco ding o single-phase execu ion. As pa o he execu ion phase, c1 al eady
que ied he execu ion on c1. As a esul , c1 s a ed execu ing he CSD shown in Fig-
u e 3.12. c1 al eady c ea ed he Con oyD i e ins ance and cu en ly execu es he adeTo-
Con oy ading unc ion in he ading componen . A his poin o ime, bo h con inuous
componen ins ances a e execu ed in pa allel. Howe e , he Con oyD i e ins ance will
no p ope ly wo k because he inpu po s e Dis and cu Dis ha e no defined alues. The
eason is ha hese po ins ances a e delega ed by c1 and needed o be connec ed in c1
be o e s a ing o execu e he ading. In pa icula , we needed o c ea e ins ances o he
SpeedSenso and he Membe Con ol in c1 p io o execu ing he ading unc ion.
c1 : RailCabD i eCon ol
c1 / c l : Veloci yCon olle
: e Speed
:cu Speed
: o ce
os / s a egy :
Ope a ionS a egy dl / d i e :
D i eLogic
:speedP o ide
: e Speed
B
:p o ocolIns
B
:p o ocolIns :sec ion1 :sec ion1
:sec ion2 :sec ion2
:maxSpeed
sp / sp : SpeedSenso
:speed
c1 : Veloci yCon olle
:cu Dis
: e Dis
+-
sd / s andalone_c l :
S andaloneD i e
: e Speed
:cu Speed
:cu Dis
cd / con oy_c l :
Con oyD i e
: e Speed
:cu Speed
: e Dis
: o ce
: o ce
:cu Dis
: e Speed
:cu Speed
: e Dis
/ ade:
Con oyFading
adeToCon oy()
:s andalone
:con oy
: o ce : o ce
RM
: econ Exec RE
: econ Msg
RM
: econ Exec RE
: econ Msg
Figu e 4.7: P oblems when Replacing Con inuous Componen Ins ances using Single-
Phase Execu ion
T ansac ional Execu ion o Hie a chical Reconfigu a ions Page 103
As a solu ion o his p oblem, we spli he execu ion phase o ou 2-phase-commi p o-
ocol in o h ee sub-phases as p oposed by Volk [Vol13] i he econfigu a ion eplaces
con inuous componen s. These sub-phases a e se up, ading, and ea down. Each o
hese sub-phases execu es pa o he econfigu a ion. Figu e 4.8 illus a es how hese
sub-phases a e execu ed in a s uc u ed componen ins ance. A filled ba deno es ha
he ins ance is cu en ly execu ing econfigu a ion beha io , while an unfilled ba de-
no es ha he ins ance is idle. We explain his figu e in mo e de ail along wi h he
di e en phases in he ollowing Sec ions 4.2.2.1 o 4.2.2.3. The o ing phase o he
2-phase-commi is execu ed as o single-phase execu ion (c . Sec ion 4.2.1) and will
no be desc ibed he e.
Ins ance Phase
Pa en
:RailCabD i eCon ol
:Veloci yCon olle
Se up Fading Tea down
Figu e 4.8: Illus a ion o Th ee-Phase Execu ion [Vol13]
4.2.2.1 Se up
The h ee-phase execu ion s a s wi h he se up phase. The se up phase (hie a chically)
econfigu es a componen ins ance such ha all p econdi ions o execu ing he ading
unc ions a e es ablished. The e o e, i changes he so wa e a chi ec u e o he mecha-
onic sys em, bu i does no change he exhibi ed beha io o he mecha onic sys em.
The se up phase is execu ed bo om-up as shown in Figu e 4.8, i.e., a componen fi s
igge s i s child en in pa allel and execu es i s own se up beha io a e all child en a e
finished.
In he se up phase, each componen ins ance ha is a ec ed by he econfigu a ion c e-
a es all disc e e, con inuous, and hyb id po ins ances as specified by he econfigu a-
ion ule. In addi ion, s uc u ed componen ins ances c ea e all embedded componen
ins ances and all connec o ins ances be ween con inuous and hyb id po ins ances. Dis-
c e e componen ins ances and po s a e kep in a suspended mode, i.e., hei RTSCs a e
no being execu ed and hei clocks do no ye p og ess. All hyb id po ins ances ha
ha e been c ea ed du ing se up al eady emi hei de aul alue hough. All a ec ed ad-
ing componen s s ill o wa d he unmodified alue o he con inuous componen ha is
o be eplaced.
Figu e 4.9 shows componen ins ances o RailCabD i eCon ol and Veloci yCon olle a e
pe o ming he se up phase o he econfigu a ion becomeMembe shown in Figu e 3.11.
The co esponding CSD is applied on he componen ins ance o RailCabD i eCon ol o
d i ing alone shown in Figu e 3.9.
Page 104 Chap e 4
c1 : RailCabD i eCon ol
c1 / c l : Veloci yCon olle
:cu Speed
: o ce
os / s a egy :
Ope a ionS a egy dl / d i e :
D i eLogic
:speedP o ide
B
:p o ocolIns
B
:p o ocolIns :sec ion1 :sec ion1
:sec ion2 :sec ion2
:maxSpeed
sp / sp : SpeedSenso
:speed
:cu Dis
ds / dis
: Dis anceSenso
:dis ance
: e Speed
: e Speed
: e Dis
mc / membe :
Membe Con ol
: e Dis
:speedP o ide
:membe :membe
:dis Recei e : e Dis Recei e
c1 : Veloci yCon olle
+-
sd / s andalone_c l :
S andaloneD i e
: e Speed
:cu Speed
:cu Dis
cd / con oy_c l :
Con oyD i e
: e Speed
:cu Speed
: e Dis
: o ce
: o ce
:cu Dis
: e Speed
:cu Speed
: e Dis
/ ade :
Con oyFading
adeToCon oy()
:s andalone
:con oy
: o ce : o ce
RM
: econ Exec RE
: econ Msg
RM
: econ Exec RE
: econ Msg
Figu e 4.9: RailCabD i eCon ol a e Execu ing he Se up Phase o he Reconfigu a ion
becomeMembe
Since he se up phase is execu ed bo om-up, he execu ion s a s a c1. c1 c ea es an
ins ance o Con oyD i e including he po ins ances e Dis and cu Dis . In addi ion, i
delega es all in-po s o he co esponding po ins ances o he new componen ins ance
cd. Finally, i c ea es he po con oy a he ading componen including he assembly
ins ance. As a esul , c1 con ains all necessa y componen ins ances, po ins ances,
and connec o ins ances o execu ing he ading unc ion.
A e c1 finished, c1 execu es i s se up phase. Acco ding o he CSD in Figu e 3.11, c1
c ea es ins ances o Dis anceSenso and Membe Con ol. Since Membe Con ol is a disc e e
componen , he ins ance mc emains suspended and only emi s he de aul e e ence dis-
ance ia i s hyb id e Dis po ins ance. In addi ion, c1 c ea es he po ins ances mem-
be and e Dis Recei e , bu i does no ye c ea e he co esponding delega ion ins ances.
Finally, c1 c ea es he assembly connec o ins ances be ween he con inuous and hyb id
po ins ances o connec ing Dis anceSenso and Membe Con ol o c1.
T ansac ional Execu ion o Hie a chical Reconfigu a ions Page 105
As i can be in e ed om Figu e 4.9, all in-po s o c1 a e p ope ly connec ed. Thus,
he ading unc ion can now be execu ed and p o ide a meaning ul esul . Up o now,
he beha io o c1 and c1 has no been changed because c1 s ill emi s he o ce alue
o sd and because he disc e e connec o ins ances in c1 ha e no ye been modified and
Membe Con ol is s ill suspended.
4.2.2.2 Fading
In he ading phase, he beha io o he mecha onic sys em changes, bu i s so wa e a -
chi ec u e does no change. In pa icula , we execu e he ading unc ions o all a ec ed
ading componen s. As shown in Figu e 4.8, we execu e all ading unc ions in pa allel,
i.e., he ading componen s now emi he alues o he ading unc ions ha combine
hei inpu alues. Disc e e componen s emain idle du ing his phase.
In ou example in Figu e 4.9, he ading componen execu es he swi chToCon oy ading
as specified by he CSD in Figu e 3.12.
4.2.2.3 Tea down
The execu ion o he econfigu a ion finishes wi h he ea down phase. In his phase,
bo h, he beha io and he so wa e a chi ec u e o he mecha onic sys em change. The
ea down phase is execu ed op-down as shown in Figu e 4.8, i.e., a componen fi s
execu es i s own ea down beha io be o e i igge s i s child en in pa allel.
In he ea down phase, we des oy all componen ins ances, po ins ances, and con-
nec o ins ances as specified by he econfigu a ion ule. Fu he mo e, we ac i a e all
disc e e componen ins ances and po ins ances ha we e c ea ed in he se up phase in-
cluding he connec o ins ances be ween disc e e po ins ances. The ading componen s
now o wa d he unmodified alue o he con inuous componen ins ance ha has been
c ea ed.
Con inuing ou example in Figu e 4.9, we now des oy he S andaloneD i e ins ance in-
cluding all o i s po ins ances and adjacen connec o ins ances. In c1, we des oy he
assembly be ween speedP o ide o os and maxSpeed o dl. Addi ionally, os des oys i s
speedP o ide po ins ance. Fu he mo e, we c ea e delega ion connec o ins ances ha
delega e he po ins ances membe and dis Recei e o mc o he co esponding po in-
s ances o c1. Finally, we c ea e he assembly connec o ins ance be ween speedP o ide
o mc and maxSpeed o dl. The esul is, as expec ed, equi alen o he componen in-
s ance Membe shown in Figu e A.31.
4.2.3 Quiescence
Componen ins ances and po ins ances may no be dele ed a any poin in ime. In
pa icula , hey may no be dele ed i hey cu en ly pe o m a compu a ion o i hey a e
Page 106 Chap e 4
engaged in execu ing a communica ion p o ocol ha is equi ed o he sa e ope a ion
o he sys em. Quiescence [KM98, ZC06] defines whe he i is sa e o dele e a compo-
nen ins ance o one o i s po ins ances a a ce ain poin o ime. Then, execu ing a
econfigu a ion sa ely demands ha all a ec ed componen ins ances a e quiescen .
As an example, conside a membe RailCab ha lea es a con oy. As a consequence,
he RailCab will des oy i s ins ance o Membe Con ol and i will swi ch back o he
S andaloneD i e eedback con olle (c . Sec ion 4.2.2). Howe e , he RailCab may no
pe o m his econfigu a ion i i is s ill d i ing closely behind ano he RailCab. I i
pe o ms he econfigu a ion, i will no be no ified abou b aking maneu e s o he
con oy and, hus, a c ash is likely o occu .
The e o e, we need a concep o defining quiescence o componen ins ances in MECH-
ATRONICUML. In pa icula , we need o define quiescence o disc e e a omic compo-
nen ins ances. Fo con inuous a omic componen ins ances, he ading unc ions define
how hey may be sa ely eplaced. A s uc u ed componen ins ance is quiescen wi h
espec o a pa icula econfigu a ion i all child en ha a e a ec ed by his econfigu-
a ion a e quiescen .
The concep o quiescence o disc e e a omic componen ins ances needs o answe he
ollowing h ee ques ions o being usable in ou 2-phase-commi p o ocol.
1. Is he componen ins ance quiescen ?
2. I he componen ins ance is quiescen , how long will i emain quiescen ?
3. I he componen ins ance is no quiescen , when will i be quiescen again?
These ques ions need o be answe ed by he disc e e a omic componen ins ance du ing
he o ing phase o he 2-phase-commi p o ocol. Ques ion 1 and 3 a e impo an o
de i ing he o ing esul . A disc e e a omic componen ins ance may only o e o
commi i i is p esen ly quiescen o i i will become quiescen ea ly enough. Ques ion 2
is impo an o de i ing he commi ime ha defines how long he componen ins ance
will s ick o i s commi . Howe e , he componen ins ance will only o e o commi i
he commi ime is abo e a h eshold ha is defined by he de elope as we discuss in
Sec ion 4.3.4.
An app oach ha may answe he h ee ques ions gi en abo e o a sel -adap i e mecha-
onic sys em has been de eloped as pa o a Mas e ’s hesis [Sch15]. We will ske ch
i s co e ideas in he ollowing. Ou ideas a e inspi ed by he app oach o Zhang and
Cheng [ZC06]. Thei app oach conside s a s a e-based unc ional beha io specifica ion
o componen s based on pe i ne s (c . [ZC06]) o UML S a echa s (c . [RC08]), bu
hey do no conside eal- ime cons ain s o p ope ies o he physical sys em in hei
specifica ion. Fo pe o ming a econfigu a ion, he sys em swi ches be ween sou ce and
a ge unc ional beha io s by execu ing an adap a ion beha io (c . Sec ion 2.1.2). In
ou app oach, he sou ce and a ge unc ional beha io s co espond o he CICs be o e
T ansac ional Execu ion o Hie a chical Reconfigu a ions Page 107
and a e execu ing a econfigu a ion, while he adap a ion beha io is ep esen ed by
ou 2-phase-commi p o ocol.
Fo gua an eeing quiescence, Zhang and Cheng define a se o global in a ian s using
empo al logic ha need o be ulfilled du ing he adap a ion p ocess. Then, a s a e so
he sou ce unc ional beha io is quiescen i he e exis s a s a e in he a ge unc ional
beha io such ha he adap a ion om s o does no iola e any global in a ian [ZC06].
This is ensu ed a design ime by model checking he unc ional beha io s and he adap-
a ion beha io [ZGC09]. Then, all s a es so he sou ce unc ional beha io a e ma ked
as quiescen wi h espec o a gi en adap a ion.
In a sel -adap i e mecha onic sys em, he s a e o a componen ins ance is no only
de e mined by he ac i e s a e o i s RTSC bu also by he cu en clock alues o he
RTSC and, po en ially, he physical s a e o he mecha onic sys em. The physical s a e
o a mecha onic sys em is gi en, o example, by i s cu en spa ial posi ion, i s speed, o
i s accele a ion. Conside a membe RailCab ha wan s o lea e a con oy as an example.
The e, we need o conside he RailCab’s dis ance o he p eceding RailCab and i s
cu en speed o deciding whe he he componen ins ance is quiescen . The e o e, i is
no possible o simply ma k s a es o an RTSC as quiescen as p oposed by Zhang and
Cheng.
As an addi ional p oblem, conside ing he clock alues and he physical s a e o he sys-
em induces a so-called hyb id model checking p oblem [Hen96]. Such model checking
p oblems canno be sol ed e ficien ly wi h cu en echniques [ERNF12] as we discuss
in mo e de ail in Chap e 6. As a possible solu ion, we can use ou app oach o mo ion
p ofiles [FHK+13, FHK+14] o a oiding hyb id e ifica ion. A mo ion p ofiles gi es
an asse ion on he limi s o a change o he physical pa ame e s o he mecha onic
sys em in he u u e. Each mo ion p ofile is defined wi h espec o a pa icula con ol
s a egy, wi h espec o he cu en d i ing maneu e , e.g., b aking o accele a ing, and
wi h espec o op imiza ion c i e ia, e.g., b aking s ongly s. b aking smoo hly. As
a esul , each sys em is equipped wi h a mul i ude o mo ion p ofiles. Howe e , e en
in his case he s a e-space ha needs o be explo ed is significan ly la ge compa ed o
Zhang e al. [ZGC09] because we need o conside clocks and all possible mo ion p o-
files o he RailCab based on each possible poin in ime o he maneu e ha is defined
by he mo ion p ofile.
The e o e, ou idea is o iden i y quiescen s a es a un ime as a pa o he o ing phase
o ou 2-phase-commi p o ocol. This is mo e e ficien han compu ing all possible sym-
bolic s a es a design ime [GCZ08] because we only need o check a ew symbolic
s a es. In pa icula , we only need o conside symbolic s a es ha a e eachable om
he cu en snapsho o he componen ins ance in a sho pe iod o ime. In addi ion,
we only need o conside he cu en ly applied mo ion p ofile ins ead o conside ing
all na ailable mo ion p ofiles which educes he s a e space by ac o n. Figu e 4.10
summa izes he idea o ou app oach.
Page 108 Chap e 4
A design ime, he de elope needs o speci y a se o condi ions o quiescence. These
condi ions e e o he di e en pa s o he a omic componen ins ance, e.g., an ac i e
s a e o he RTSC, messages ha a e loca ed in he message bu e o a po ins ance, o
alues ega ding he physical s a e o he sys em ha a e ecei ed ia a hyb id po in-
s ance. In ou example, we migh equi e ha he dis ance o he membe RailCab o he
RailCab di ec ly d i ing in on o i mus be la ge han 50m. Then, any symbolic s a e
o he RTSC ha ulfills all o he imposed condi ions a un ime is conside ed o be qui-
escen . Thus, he condi ions co espond o he in a ian s used by Zhang e al. [ZGC09].
Fo suppo ing he de elope , we p o ide him wi h a checklis o ypical influence ac-
o s ha need o be conside ed o quiescence. The checklis will be de i ed by analyzing
influence ac o s on quiescence in di e en sel -adap i e mecha onic sys ems such as
RailCabs o sel -coo dina ing ca s [PHMG14].
Design Time
Run ime
Disc e e A omic Componen
Checklis o
In luence Fac o s
De elope Se o Condi ions o
Quiescence
e e s o
E alua ion o Condi ions
ia Reachabili y Analysis
model@ un ime
Vo e
Commi Time
o
Figu e 4.10: App oach o Iden i ying Quiescen S a es in MECHATRONICUML
A un ime, we use ou model@ un ime o he a omic componen ins ance o e alua ing
he condi ions as a pa o he o ing phase o he 2-phase-commi p o ocol. I he a omic
componen ins ance is eques ed o execu e a econfigu a ion by i s pa en , we s a a
eachabili y analysis on he cu en snapsho o he model@ un ime. Then, we calcu-
la e he symbolic s a es ha he a omic componen ins ance may each in a sho ime
ame s a ing om he cu en snapsho . The ime ame ha needs o be conside ed
is defined by he ime o execu ion o ou 2-phase-commi p o ocol and he h eshold
o he commi ime. Fo each o he symbolic s a es, we e alua e he condi ions ha
he de elope has specified a design ime. The esul is a zone g aph (c . Sec ion 2.2.1)
whe e each symbolic s a e is ma ked as quiescen o non-quiescen . The eby, we only
need o conside he cu en ly ac i e mo ion p ofile and he cu en physical s a e o he
sys em. Based on he clock alues o he symbolic s a es, we may u ilize he pa hs o he
T ansac ional Execu ion o Hie a chical Reconfigu a ions Page 109
zone g aph o calcula ing whe he he componen ins ance is quiescen and how long i
will emain quiescen . F om his in o ma ion, we de i e he o ing esul and he commi
ime ha a e passed o he pa en .
The eachabili y analysis may be ca ied ou by a a ian o he eachabili y analysis o
RTSCs in oduced in Appendix C.3 ha is op imized o being execu ed on embedded
compu ing de ices. This echabili y analysis needs o be implemen ed such ha i s un-
ime is p edic able. This is necessa y o gua an eeing ha he componen ins ance will
ob ain a o ing esul wi hin a gi en ime ha he componen asse s o i s pa en as we
desc ibe in mo e de ail in Sec ion 4.3.4. P edic abili y may be achie ed, e.g., by limi ing
he numbe o symbolic s a es ha a e in es iga ed o each ace o he zone g aph as
p oposed by bounded model checking echniques [BCC+03].
4.3 Decla a i e, Table-based Specifica ion o he
Reconfigu a ion Con olle
In ou app oach, we p o ide a decla a i e specifica ion o he beha io o he econfigu-
a ion con olle based on ables. These ables ex end he componen model in oduced
in Chap e 3 by addi ional syn ac ical elemen s ha a e ailo ed he 2-phase-commi
p o ocol. Mo e echnically speaking, he ables elie e he de elope om manually
speci ying RTSCs o RM po s, RE po , manage , and execu o .
In a li le mo e de ail, he de elope needs o speci y one able o each RM po and o
each RE po o a econfigu able componen . This able enhances he in e ace o he
po , i.e., which messages he po may send o ecei e, wi h iming cons ain s o he
messages ha a e ele an o execu ing he 2-phase-commi p o ocol. In addi ion, he
de elope needs o speci y one able o he manage and o he execu o o each econ-
figu able s uc u ed componen . The en ies in hese ables define condi ions ha exp ess
when o execu e which econfigu a ion, bu hey do no speci y how he condi ions a e
checked and how econfigu a ions a e execu ed acco ding o he 2-phase-commi p o o-
col.
The iming cons ain s ha a e con ained in ou decla a i e, able-based specifica ion a e
equi emen s o an execu ion o he econfigu a ion beha io on a ha dwa e pla o m.
Fo a sel -adap i e mecha onic sys em, hese equi emen s o igina e om h ee sou ces.
Fi s , hey o igina e om condi ions ha a e imposed by he physical en i onmen . As
an example, conside a con oy build-up a a swi ch. In his case, he econfigu a ions
o becoming a coo dina o o membe , espec i ely, need o be finished be o e com-
ing oo close o he swi ch. Second, iming equi emen s a e defined by he unc ional
sa e y specifica ion. In case o a ha dwa e ailu e, a econfigu a ion ha implemen s a
sel -healing ope a ion needs o be finished wi hin a pa icula ime in o de o p e en
a haza d. This pa icula ime may be ob ained by pe o ming a imed haza d analy-
sis [PST13]. Thi d, iming equi emen s o igina e om he quiescence c i e ia. The
componen ins ances ha a e a ec ed by a econfigu a ion need o emain quiescen
Page 110 Chap e 4
h oughou he econfigu a ion (c . Sec ion 4.2.3). As a esul , he econfigu a ion needs
o be finished be o e he componen ins ance needs o execu e some non-quiescen be-
ha io ha is necessa y o sa ely ope a ing he sys em.
In he ollowing, we p o ide de ails ega ding ou decla a i e, able-based specifica ions
o manage and execu o as well as o he in e aces o RM po s and RE po s in Sec-
ions 4.3.1 o 4.3.3.
4.3.1 In e ace Specifica ion o RM Po s
An RM po is a special kind o disc e e po (c . Sec ion 3.1.1.2) ha is solely used
o communica ion be ween he manage s o econfigu able componen s. I s in e ace
is defined by a able wi h ou columns. The fi s column defines he message ypes
ha may be sen o he pa en . The second column gi es addi ional in o ma ion on he
seman ics o he message using a ype. We dis inguish wo ypes o messages: in o
messages and eques s. An in o message is only p o ided o in o ma ion and does no
necessa ily equi e a econfigu a ion. A eques is sen in si ua ions whe e a econfigu-
a ion is necessa y om he pe spec i e o he sending componen and whe e i canno
sol e he si ua ion i sel . In case o a eques , he de elope o a componen may spec-
i y an expec ed esponse ime in he hi d column. I defines he poin in ime whe e
he componen needs he in o ma ion whe he a econfigu a ion has been execu ed by
he pa en . The ou h column op ionally con ains a human eadable desc ip ion o he
epo ed si ua ion o a de elope . Each in e ace en y co esponds o one ow in he
able.
Message Type Desc ip ion
d i ingA HighSpeed RailCab a els a high speed.
Type
in o
Expec ed
Response Time
d i ingA No malSpeed RailCab a els a no mal speed.
in o
---
---
dis anceSenso Failu e Dis ance senso is b oken.
eques 200 ms
Figu e 4.11: RM Po Specifica ion o he RailCabD i eCon ol Componen (c . [HB13])
Figu e 4.11 shows an example o an RM po specifica ion o he RM po o he Rail-
CabD i eCon ol componen shown in Figu e 4.3. I con ains h ee en ies. Fi s , he
RailCabD i eCon ol in o ms i s pa en abou i s speed p ofile using he messages d i in-
gA HighSpeed and d i ingA No malSpeed o ype in o. This in o ma ion may be used o
adap he sensing o obs acles depending on he speed. I he speed is high, obs acles
need o be sensed in la ge dis ances o b ake ea ly enough. In addi ion, RailCabD i e-
Con ol sends a eques posi ionSenso Failu e, which deno es ha he dis ance senso is
b oken. This eques igge s a sel -healing ope a ion (c . [P i13, PST13]) and needs o
be finished in 200ms o gua an eeing he con oy sa e y.
T ansac ional Execu ion o Hie a chical Reconfigu a ions Page 111
4.3.2 Manage Specifica ion
The beha io o a manage is specified decla a i ely using a able wi h eigh columns.
We e e o each ow o he able as an en y o he manage specifica ion. The en ies o
he manage specifica ion define how he manage needs o eac i i ecei es a pa icula
message. In ou app oach, he manage only eac s o messages ha i ecei es om he
child en o om he execu o . We did no ye include dedica ed moni o ing capabili ies
o s uc u ed componen s in ou app oach. The manage specifica ion needs o con ain
exac ly one en y o each message ha he manage may ecei e om he child en o
om he execu o .
In he manage specifica ion, he fi s column con ains a message ype ha he manage
may ecei e ei he om a child o om he execu o . The second and hi d column
define whe he he manage ea s he message o whe he i p opaga es he message o
i s pa en . A message ha is ecei ed om he execu o always needs o be ea ed. We
allow, howe e , ha he manage ope a es as a sink wi h espec o messages sen by a
child by nei he ea ing no p opaga ing hem. We do no allow o ea and p opaga e a
message a he same ime because ha may lead o conflic ing econfigu a ion decisions
on di e en le els o hie a chy in he componen model. All messages ha a e specified
as p opaga ed in he manage specifica ion need o appea in he in e ace specifica ion
o he RM po pa en o he co esponding econfigu able componen .
I he specifica ion defines ha a message is ea ed, he de elope mus speci y a econ-
figu a ion ule o be execu ed by he execu o in he ou h column. Whe he a econ-
figu a ion may be execu ed a un ime depends on h ee condi ions ha a e specified in
columns fi e o se en: (1) whe he i is allowed o execu e he econfigu a ion (column
S uc u al Condi ion), (2) whe he i is sa e o execu e he econfigu a ion (column Sa e y
Rele an ), and (3) whe he i is use ul o execu e he econfigu a ion (column In oke Plan-
ne ). Only i all h ee condi ions e alua e o ue du ing un ime, he manage will igge
he execu o o execu e he econfigu a ion. We explain hese condi ions in mo e de ail
in he ollowing.
Fo each en y o he manage specifica ion, he de elope needs o define a s uc u al
condi ion. The s uc u al condi ion specifies a condi ion on he embedded componen
ins ances ha mus be ulfilled o execu ing he econfigu a ion. Cu en ly, we only
suppo speci ying s uc u al condi ions based on componen SDDs (c . Sec ion 3.5). I
is only allowed o execu e a econfigu a ion i he s uc u al condi ion is ulfilled. I he
execu ion o he econfigu a ion shall no be es ic ed, ue may be used as a s uc u al
condi ion as o En ies 4, 6, 7, and 8.
A econfigu a ion may a ec he unc ional sa e y [IEC10, ISO11a] o he sys em. An
example o such econfigu a ion is joining a con oy as a membe . The unc ional sa e y
specifica ion pu s a limi on he isk ha a dange ous si ua ion may occu du ing un-
ime. I a RailCab joins a con oy, he isk o a collision ises due o he small dis ances
be ween he RailCabs. I , in addi ion, one o he senso s necessa y o a con oy d i e
is b oken, he isk o a collision may become oo high o be accep able. In such cases,
Page 118 Chap e 4
econfigu a ion can no longe be execu ed. This is he case i he ime needed o exe-
cu ing he econfigu a ion exceeds he expec ed esponse ime. In his case, he subpo
sends an occupied message o he child indica ing ha he econfigu a ion is cu en ly
no possible.
The s a e Recei edMsgX may also be le ia he ansi ion o Deli e Msg. Tha ansi ion
ini ia es a synch oniza ion ia he synch oniza ion channel syncX. The synch oniza ion
channel syncX is gene a ed o each message x ha is ei he p opaga ed o ea ed by he
manage . The ansi ion synch onizes ei he wi h he in e nal beha io i he message is
ea ed o wi h he pa en i he message is p opaga ed.
I he message is p opaga ed, he subpo synch onizes wi h he pa en . Then, he pa en
swi ches om Idle o P opaga ed and sends he message x o he pa en . I he message is a
eques , he pa en swi ches o Awai Reply while he subpo swi ches o Awai Pa en Reply.
When he pa en answe s, ei he by success o ailu e o occupied. Then, he pa en uses
he synch oniza ion channel pa en Reply o epo he esul back o he subpo which, in
u n, sends he esul back o he child.
I he message ecei ed by he subpo is ea ed, he synch oniza ion ia syncX causes
he in e nal beha io o swi ch o CheckX. As i s ansi ion ac ion, he ansi ion checks he
s uc u al condi ion o he message xby calling he ope a ion checkS uc u alCondi ionX.
This ope a ion implemen s he s uc u al condi ion ha is specified in he manage spec-
ifica ion (c . Sec ion 4.3.2). I he econfigu a ion is sa e y ele an , hen he ope a ion
isBlocked checks whe he he econfigu a ion wi h he gi en id is cu en ly blocked by
he un ime isk manage . The e o e, i uses he a iable blockedReconfigu a ions ha is
se by he iskManage any ime he un ime isk manage p o ides new da a ia upda-
eRiskDa a. I he s uc u al condi ion is no ulfilled o he econfigu a ion is cu en ly
blocked, hen he in e nal beha io immedia ely swi ches o Fail. Then i epo s he esul
ia he synch oniza ion channel eply o he subpo i he message is a eques . I i is no
a eques , bo h RTSCs e u n o hei Idle s a es wi hou synch oniza ion. I he s uc u al
condi ion is ulfilled and he econfigu a ion is no blocked, he in e nal beha io swi ches
o Plan and op ionally in okes a planne . I he econfigu a ion should be execu ed, he
in e nal beha io synch onizes wi h he execu o egion using he synch oniza ion chan-
nel execu eRecon . Then, he in e nal beha io wai s in s a e Execu e o he esul o he
execu ion.
The synch oniza ion ia execu eRecon causes he execu o egion o swi ch om Idle
o Execu eRecon . The co esponding ansi ion sends a message execu eRecon o he
execu o . The econfigu a ion o be execu ed is e e ed by i s ID om he execu o
specifica ion and encoded by an in ege pa ame e o he message. Then, he execu o
pe o ms he 2-phase commi p o ocol and epo s he esul , ei he success o ailed, o
he manage . The execu o egion epo s he esul o he in e nal beha io using he
synch oniza ion channel execu ed. Then, he execu o egion akes he lowe ansi ion
om Finished back o Idle. I he message has been a eques , he in e nal beha io
epo s he esul o he ins ance o he subpo ha ini ia ed he econfigu a ion ia he
T ansac ional Execu ion o Hie a chical Reconfigu a ions Page 119
synch oniza ion channel eply. The ins ance o he subpo wai s o ha synch oniza ion
in he s a e Awai Reply and sends he esul , ei he success o ailed, back o he child. This
finishes Use Case 1.
In Use Case 2, he execu o sends a message x o he manage . This message is p o-
cessed by he execu o RTSC a he ansi ion om Idle o Reques . Such ansi ion is
gene a ed o each message o e ed by he RE po o he s uc u ed componen . This
ansi ion, howe e , may only fi e i a synch oniza ion ia he synch oniza ion channel
syncX wi h he in e nal beha io is possible. Tha , in u n, is only possible i cu en ly
no o he econfigu a ion is execu ed. Thus, we use he synch oniza ion channel syncX
o se ializing he messages inside he manage . I he synch oniza ion is possible, he
execu ion p oceeds as o Use Case 1. I he execu o egion eaches s a e Finished,how-
e e , i akes one o he uppe wo ansi ions back o Idle. These ansi ions synch onize
wi h he ansi ions om Success o Idle and Fail o Idle in he in e nal beha io . These
ansi ions enable o ea Use Cases 1 and 2 iden ical wi hin he in e nal beha io . This
finishes Use Case 2.
4.4.2 Execu o Specifica ion
Figu es 4.16 and 4.17 show he gene a ion empla e o he execu o RTSC. The empla e
includes he beha io o bo h, single-phase execu ion and h ee-phase execu ion. The
empla e implemen s he 2-phase-commi p o ocol including many a ia ion poin s ha
depend on he execu o and RE po specifica ion.
In he RTSC, all black s a es and ansi ions o m he gene al ame o he RTSC. As
o he manage gene a ion empla e, hey a e always p esen and will only be gene a ed
once o e e y execu o RTSC. The colo ed pa s a e a iable and depend on he execu o
and RE po specifica ion. We gene a e he blue pa s o each message ha is o e ed by
he RE po o he componen . The pu ple pa s a e gene a ed o each econfigu a ion
ule ha he execu o may execu e. Finally, he b own pa s a e gene a ed o e e y
econfigu a ion ule ha is o e ed by a child in i s RE po .
Fo ealizing Use Case 1, he in o ma ion flows as ollows h ough he execu o RTSC:
The execu o is ini ially igge ed by he manage and ecei es he eques in he e en s
egion. The e en s egion igge s he in e nal beha io ha ini ializes he 2-phase-
commi p o ocol. The implemen a ion o he 2-phase-commi p o ocol is mainly loca ed
in he adap a ion egion o embeddedCI. The adap a ion compu es he child en ha a e
a ec ed by he econfigu a ion. Then i pe o ms he o ing by igge ing he co e-
sponding subpo ins ances ha a e connec ed o he a ec ed child en. Then, he econ-
figu a ion is execu ed. In case o single-phase execu ion, he adap a ion egion igge s
he subpo ins ances again. A e he execu ion o he child econfigu a ions is finished,
he adap a ion epo s he esul o he in e nal beha io . Then, he in e nal beha io execu es
he econfigu a ion o he s uc u ed componen . In case o h ee-phase execu ion, he
adap a ion and he in e nal beha io execu e he h ee phases o he econfigu a ion. The
adap a ion igge s he subpo ins ances ha a e connec ed o he a ec ed child en while
Page 120 Chap e 4
Execu o
Execu o _Main
a iable: boolean singlePhase, in econ igu a ion, in mpCommi Time, boolean woPCResul ;
2
1
clock: c2;
channel: checkX, execu e[boolean], s a Execu ion, o ingComple e[boolean], doAbo , inished, pe o mRecon , inish[boolean], ini 2PC[in ], inished2PC, localSe up, localFading, localTea down, localFinish;
pa en
e en s
in e nal beha io
embeddedCI
3
4
a iable: in deadline, boolean omPa en , boolean abo edReqWai ing;
clock: c1;
ope a ion: Y();
a iable: Po subPo , in mpMsg, boolean mpCommi , in [Z.name]Msg := z.id;
γ = x. imeFo Decision –α
α = X. imeFo Planning + imeFo Gua dChecking+ 2* in e nalMessageDelay
Idle CheckX
c2 ≤ γ
x/
{ ese : c2;}
/ abo ()
CheckSel
checkX! /
execu e[ alse]? /
Awai Vo ing
execu e[ ue]? /
inished? /
inished()
SendAbo
U
Wai Fo Pa en
o ingComple e[ alse]?
o ingComple e[ ue]? /
con i m( mpCommi Time)
Execu ion
execu e
pe o mRecon ! /
abo
doAbo ! /
Abo ed
FinalizeAbo
doAbo ! /
abo ()
inished? /
[c2 ≥ γ]/
S a Execu ion
s a Execu ion! /
U
Execu eSe upWai FadingExecu eFadingWai Tea downExecu eTea down
inished? /
inished()
ea down
pe o mTea down! /
inishPhase? /
inished()
ading
pe o mFading! /
inishPhase? /
inished()
se up
pe o mSe up! /
Idle
en y/ omPa en := { alse;}
Check
c1 ≤ deadline
checkX? /
{deadline := α; ese : c1; omPa en := ue}
x()
con i mReques
execu e[ ue]! /
{ econ igu a ion := execu e. econ ;} Busy
declineReques
execu e[ alse]! / ailed()
execu eRecon s a Execu ion!/
{ econ igu a ion := execu eRecon . econ ;}
Finished
inish[ alse]? /
ailed()
inish[ ue]? /
success()
[ omPa en = alse && abo edReqWai ing = alse] /
[ omPa en = ue] inished! /
Awai Vo ing
DoAbo DoExecu e
o ingComple e[ alse]? /
[singlePhase]
o ingComple e[ ue]? /
doAbo ! /
pe o mRecon ! /
TimeOu [c1 = deadline]
execu e[ alse]! /
con i mReques /
ailed()
Abo Pa en Req
execu eRecon
execu e[ alse]!/
{ econ igu a ion := execu eRecon . econ ;}
s a Execu ion! /
{abo edReqWai ing := ue;}
Wai Fo Answe
[abo edReqWai ing = ue]
Answe Recei ed
U
UdeclineReques /
con i mReques /
/ {abo edReqWai ing := alse;} ailed()
U
execu eRecon
{ econ igu a ion := execu eRecon . econ ;}
declineReques / ailed()
execu eRecon
{ econ igu a ion := execu eRecon . econ ;}
DoSe up
BusySe up
DoFading
BusyFading
DoTea down
[no singlePhase] o ingComple e[ ue]? /
pe o mSe up! /
inishPhase? /
pe o mFading! /
inishPhase? /
pe o mTea down! /
Idle
[ econ igu a ion == Y1.id || ...]
s a Execu ion? / {singlePhase := ue;}
S a UWai
ini 2PC[ econ igu a ion]! /
Execu e
inished2PC? /
U
[ woPCResul == alse] inish[ alse]! /
Repo U
[singlePhase && woPCResul && econ igu a ion == Y1.id] /
{Y1()}
inish[ ue]! /
LocalExecu eY2
Se up localFinish! / Wai Fading
{Y2_se up();} localFading? /
{Y2_ ading();}
ope a ion: Y2_se up(), Y2_ ading(), Y2_ ea down();
[no singlePhase] /
Fading
Wai Tea down
localFinish! /
Tea down localTea down? /
{Y2_ ea down();}
Finish localFinish! / inished2PC? /
[ econ igu a ion == Y2.id]
localSe up? /
[ econ igu a ion == Y2.id || ...]
s a Execu ion? / {singlePhase := alse;}
Legend:
Gene a ed only once and a e used by all econ igu a ion ules
Gene a ed o each econ igu a ion message X ha is o e ed ia RE po
Gene a ed o each econ igu a ion message Z ha is o e ed by an embedded child
Gene a ed o each econ igu a ion ule Y ha is execu ed by he execu o
Gene a ed addi ionally o each econ igu a ion Y1/Z1 ha is execu ed using single-phase execu ion
Gene a ed addi ionally o each econ igu a ion Y2/Z2 ha is execu ed using h ee-phase execu ion
Figu e 4.16: Gene a ion Templa e o he Execu o RTSC (P . 1)
T ansac ional Execu ion o Hie a chical Reconfigu a ions Page 121
embeddedCI 4
a iable: Po subPo , in mpMsg, boolean mpCommi , in [Z.name]Msg := z.id;
embeddedCI_Main
adap a ion
subpo
2
1
channel: sendReques [Po ], eplyRecei ed, sendCommi [Po ], sendAbo [Po ], sendSe up[Po ], sendFading[Po ], sendTea down[Po ], econ Finished;
a iable: A ec edComponen s ac, in execu ionTime, in minCommi Time, Po cu Po ;
ope a ion: Po ge Nex Po Ins anceFo Ac ion(A ec edComponen s ac), Po allAc ionsPe o med(A ec edComponen s ac), oid se Finished(A ec edComponen s ac, Po po ), boolean allEmbeddedFinished(A ec edComponen s ac);
a iable: in commi Time, in imeFo Decision, in imeFo Execu ion, in imeFo Se up, in imeFo Fading, in imeFo Tea down;
clock: c2;
Idle
P epa eY
ini 2PC[Y.id]? /
Abo
Execu e_SinglePhase
Vo e
S a / {ac := compu eA ec ed
Child enFo Y();
execu ionTime := Y.execu ionTime;}
U
Finished
U
[ inished]
inished2PC! /
Repo
U
Wai Fo Pa en o ingComple e[TwoPCResul ]! /
{ mpCommi Time := minCommi Time;}
[singlePhase] pe o mRecon ?/
doAbo ?/
[ inished]
inished2PC! / Wai
en y / { inished :=
allEmbeddedFinished(ac)}
[ inished] /
{ inished := alse}
a iable: boolean inished := alse;
ope a ion: A ec edComponen s compu eA ec edChild enFo Y();
a iable: boolean inished := alse;
ope a ion: oid s o eMinCommi Time(in commi Time), Po ge Nex Po Ins anceFo Reques (A ec edComponen s ac),
in ge Message(A ec edComponen s ac, Po po ), boolean allRepliesRecei ed(A ec edComponen s ac),
oid se Reply(A ec edComponen s ac, Po po , boolean commi ), boolean canCommi ();
a iable: boolean inished := alse;
[no inished]
econ Finished? /
{se Finished(ac, subPo );}
SendAbo
en y / {cu Po :=
ge Nex Po Ins anceFo Ac ion(ac);
inished := allAc ionsPe o med(ac);}
[no inished]
sendAbo [cu Po ]! /
U
SendExecu e
en y / {cu Po :=
ge Nex Po Ins anceFo Ac ion(ac);
inished := allAc ionsPe o med(ac);}
U
[no inished]
sendCommi [cu Po ]! /
Ge Replies
en y / { inished :=
allRepliesRecei ed(ac)}
[no inished]
eplyRecei ed? /
{se Reply(ac, subPo , mpCommi );
s o eMinCommi Time( mpCommi Time)}
[cu Po == null]
/ {minCommi Time := 0} CheckResul
en y / {TwoPCResul :=
canCommi ();}
U
[ inished]
T igge SubPo
en y / {cu Po :=
ge Nex Po Ins anceFo Reques (ac);
mpMsg := ge Message(ac, cu Po );}
sendReques [cu Po ]! /
U
Execu e_Th eePhase [no singlePhase] pe o mSe up?/
Wai Fo Response
c2 ≤ imeFo Decision
Idle
en y/ {commi Time := 0;}
[ mpMsg == [Z.name]Msg] sendReques [sel ]? /
{ imeFo Decision := Z. imeFo Decision;
imeFo Execu ion := Z1. imeFo Execu ion; imeFo Se up := Z2. imeFo Se up;
imeFo Fading := Z2. imeFo Fading; imeFo Tea down := Z2. imeFo Tea down;
ese : c2;} z()
Vo edCommi
abo /[c2 ≥ imeFo Decision]
con i m /
{ ese : c2;
commi Time := con i m. ; }
Execu e
c2 ≤ imeFo Execu ion
sendAbo [sel ]? / abo ()
inished econ Finished! / {subPo := sel ;}
Vo edAbo
ReplyRecei ed
c2 ≤ commi Time
Awai Finish eplyRecei ed! /
{subPo := sel ; mpCommi := alse;
mpCommi Time := 0;}
sendAbo [sel ]? / eplyRecei ed! /
{subPo := sel ; mpCommi := ue;
mpCommi Time := commi Time;}
Execu eSe up
c2 ≤ imeFo Se up
sendCommi [sel ]? / { ese : c2} execu e() sendSe up[sel ]? /
{ ese : c2} se up()
Wai Fading
inished
econ Finished! /
{subPo := sel ;}
Execu eFading
c2 ≤ imeFo Fading
sendFading[sel ]? /
{ ese : c2} ading()
Wai Tea down
inished
econ Finished! /
{subPo := sel ;}
Execu eTea down
c2 ≤ imeFo Tea down
sendTea down[sel ]? /
{ ese : c2} ea down()
inished
econ Finished! /
{subPo := sel ;}
Figu e 4.17: Gene a ion Templa e o he Execu o RTSC (P . 2)
Page 122 Chap e 4
he in e nal beha io execu es he local econfigu a ion ope a ions. A e he econfigu a-
ion has been comple ely execu ed, he in e nal beha io no ifies he e en s egion ha he
econfigu a ion is comple ed. Then, he e en s egion no ifies he manage . This finishes
Use Case 1 o he execu o .
In Use Case 2, he pa en egion ecei es a message om he pa en . This message is
o wa ded o he e en s egion which, in u n, o wa ds he message o he manage .
Then, he manage answe s wi h he decision and, i he eques is confi med, wi h he
econfigu a ion o be execu ed. Then, he 2-phase-commi p o ocol is execu ed as in Use
Case 1 excep o one di e ence. A e finishing he o ing phase, he adap a ion igge s
he pa en egion o sending he o ing esul back o he pa en . Then, he pa en egion
wai s o he answe o he pa en and igge s he adap a ion egion a e he answe has
been ecei ed. In case o h ee-phase execu ion, his is epea ed o each o he h ee
phases. Finally, he pa en egion in o ms he pa en ha he econfigu a ion has been
comple ed. This finishes Use Case 2.
In he ollowing, we p o ide a de ailed, echnical desc ip ion o he gene a ion empla e
and explain how he Use Cases 1 and 2 a e encoded in he empla e. An example o a
gene a ed execu o RTSC is gi en in Appendix A.6.3.2 o he componen RailCabD i e-
Con ol.
In Use Case 1, he e en s egion ecei es a message execu eRecon om he manage .
This message is p ocessed by he ansi ion om Idle o Awai Vo ing. The message con-
ains he ID o he econfigu a ion ule o be execu ed as a pa ame e . In addi ion, he
ansi ion om Idle o Awai Vo ing synch onizes wi h he in e nal beha io ia s a Exe-
cu ion. The co esponding ansi ions om Idle o S a se he a iable singlePhase o
ue i he econfigu a ion needs o be execu ed wi h single-phase execu ion o alse i
he econfigu a ion needs o be execu ed wi h h ee-phase execu ion. Then, he in e nal
beha io s a s he 2-phase-commi p o ocol using he ansi ion om S a o Wai by
synch onizing wi h he adap a ion RTSC in embeddedCI ia ini 2PC. The econfigu a ion
o be execu ed is encoded in he selec o exp ession.
The RTSC o he mul i-po embeddedCI encodes he main logic o execu ing he 2-
phase-commi p o ocol and con olling i s di e en s ages. We use he adap a ion RTSC
o synch onizing he communica ion wi h he child en ha a e a ec ed by he econfig-
u a ion. The ac ual communica ion wi h he child en is con ained in he subpo RTSC.
I he adap a ion RTSC is igge ed ia ini 2PC, i en e s he P epa eY s a e. We gene -
a e such s a e o each econfigu a ion Y ha can be execu ed by he execu o . In his
s a e, we compu e which child en a e a ec ed by he econfigu a ion using he unc-
ion compu eA ec edChild enY(). The esul is sa ed in a empo a y da a s uc u e o ype
A ec edComponen s ha con ains he in o ma ion which econfigu a ion needs o be ex-
ecu ed on which child. By using his da a s uc u e, we achie e ha he emainde o
he adap a ion RTSC is independen o he ac ual econfigu a ion ha is execu ed. We
p esen he defini ion o A ec edComponen s in Appendix A.6.4.1 and an example o
T ansac ional Execu ion o Hie a chical Reconfigu a ions Page 123
compu eA ec edChild enY() in Appendix A.6.4.2. All unc ions ha a e ecu si ely con-
ained in embeddedCI a e o mally specified using s o y diag ams ha we p esen in
Appendix A.6.4.3.
A e P epa eY, he adap a ion swi ches o he Vo e s a e. In he Vo e s a e, he o es o
all a ec ed child en o execu ing hei econfigu a ion a e eques ed and collec ed. In
T igge SubPo , all subpo ins ances communica ing wi h an a ec ed child a e igge ed
by he sel - ansi ion using he synch oniza ion channel sendReques .
The subpo RTSC con ains one ansi ion om Idle o Wai Fo Response o each mes-
sage z ha is o e ed by a child. The message z o be sen o he pa icula child is s o ed
in he a iable mpMsg o embeddedCI. The adap a ion RTSC s o es his message in he
a iable mpMsg du ing i s en y ac ion in s a e T igge SubPo . Upon synch oniza ion
ia sendReques , he subpo RTSC uses his a iable in i s gua d o sending he co e-
sponding message z o he child. I he child does no answe in ime o answe s abo ,
he subpo swi ches o Vo edAbo . I he child answe s commi , he subpo swi ches o
Vo edCommi and s o es he commi ime in an in e nal a iable.
The adap a ion swi ches om T igge SubPo o Ge Replies a e all subpo s ha e been
igge ed. In Ge Replies, he adap a ion synch onizes wi h he subpo , again, o ecei e
hei o ing esul s. We use he synch oniza ion eplyRecei ed o ha pu pose and ans-
e he o ing esul s using he a iables mpCommi and mpCommi Time. A e collec ing
all o es, he adap a ion swi ches o CheckResul and calls he unc ion canCommi () upon
en y. The unc ion de e mines whe he all child en o ed o execu ing he econfigu a-
ion and whe he he minimum commi ime sen by he child en is g ea e han he ime
needed o execu ing he econfigu a ion. I so, i is possible o execu e he econfigu a-
ion.
A e he o ing phase has been finished, he adap a ion epo s he o ing esul ia o -
ingComple e o he e en s egion. The RTSC ei he swi ches o DoAbo o DoExecu e, e-
spec i ely, and igge s ei he he execu ion ia pe o mRecon o he abo ion ia doAbo .
Then, i wai s in s a e Busy un il he execu ion o he 2-phase-commi p o ocol has been
finished.
The u he beha io o he adap a ion depends on he o ing esul and whe he he e-
configu a ion is execu ed wi h single-phase o h ee-phase execu ion. I he econfigu a-
ion is abo ed, adap a ion en e s he Abo s a e and igge s all a ec ed subpo ins ances,
again, o sending he message o he co esponding child en. The subpo sends abo a
he ansi ion om ReplyRecei ed o Idle.
I he econfigu a ion is execu ed wi h single-phase execu ion, he adap a ion en e s he
Execu e_SinglePhase s a e. In his case, he adap a ion igge s all a ec ed subpo in-
s ances o sending execu e o he co esponding child en a he ansi ion om ReplyRe-
cei ed o Execu e. I he child execu ed, i answe s wi h finished a e success ully exe-
cu ing he econfigu a ion. Then, he subpo epo s o he adap a ion ha he child has
finished execu ing he econfigu a ion using he synch oniza ion finished. The adap a ion
Page 124 Chap e 4
wai s o hese synch oniza ions in subs a e Wai o Execu e. A e all child eplies ha e
been ecei ed, he adap a ion synch onizes wi h he in e nal beha io ia he synch oniza-
ion channel finished2PC o epo ha all child econfigu a ions ha e been comple ed.
Execu e_Th eePhase
Wai
en y / { inished :=
allEmbeddedFinished(ac)}
[ inished = ue] /
{ inished := alse}
a : boolean inished := alse;
op: oid ese Ac ionPe o med(A ec edComponen s ac);
[ inished = alse]
econ Finished? /
{se Finished(ac, subPo );}
SendSe up
en y / {cu Po :=
ge Nex Po Ins anceFo Ac ion(ac);
inished := allAc ionsPe o med(ac);}
U
[ inished = alse]
sendSe up[cu Po ]! /
Execu eLocalSe up
[ inished = ue]
localSe up! /
FinishedSe up
localFinish? /
UWai Fading
inishPhase! /
{ inished := alse;
ese Ac ionPe o med(ac);}
Wai
en y / { inished :=
allEmbeddedFinished(ac)}
[ inished = ue] /
{ inished := alse}
[ inished = alse]
econ Finished? /
{se Finished(ac, subPo );}
SendSe up
en y / {cu Po :=
ge Nex Po Ins anceFo Ac ion(ac);
inished := allAc ionsPe o med(ac);}
U
[ inished = alse]
sendFading[cu Po ]! /
FinishedFading
[ inished = ue]
localFinish? /
U
pe o mFading? / Execu eLocalFading
UlocalFading! /
Wai Tea down
inishPhase! /
{ inished := alse;
ese Ac ionPe o med(ac);}
Wai
en y / { inished :=
allEmbeddedFinished(ac)}
[ inished = ue] /
{ inished := alse}
[ inished = alse]
econ Finished? /
{se Finished(ac, subPo );}
SendTea down
en y / {cu Po :=
ge Nex Po Ins anceFo Ac ion(ac);
inished := allAc ionsPe o med(ac);}
U
[ inished = alse]
sendTea down[cu Po ]! /
[ inished = ue] .
inished2PC! /
Execu eLocalTea down localTea down! /
pe o mTea down? / Wai Local localFinish? /
U
Figu e 4.18: In e nal S uc u e o he Execu e_Th eePhase S a e
I he econfigu a ion is execu ed wi h h ee-phase execu ion, he adap a ion en e s he
Execu e_Th eePhase s a e. The in e nal s uc u e o his s a e is shown in Figu e 4.18.
The execu ion s a s in Execu e_Se up o execu ing he se up phase. Fi s , he adap a ion
igge s all a ec ed subpo ins ances o sending se up o he co esponding child en
a he ansi ion om ReplyRecei ed o Execu eSe up. I he child execu ed, i answe s
wi h finished a e success ully execu ing he se up phase. Again, he adapa a ion wai s
in subs a e Wai o Execu e_Se up o he eplies o he subpo ins ances. A e all chil-
d en ha e pe o med hei se up, he adap a ion synch onizes wi h he in e nal beha io
ia localSe up. This causes he in e nal beha io o en e he LocalExecu eY2 s a e and o
execu e he local se up. A e i is finished, i synch onizes ia localFinished and he adap-
a ion finishes he se up phase. I epo s ha he phase has been finished o he e en s
egion ia finishedPhase and wai s o he nex phase o s a . The emaining phases a e
execu ed in he same ashion. The e a e only wo no able di e ences. In he ading
phase, he adap a ion fi s igge s he local ading. Wi hou wai ing o he finish o he
local ading, i igge s he subpo ins ances such ha all ading unc ions a e execu ed
in pa allel. In he ea down phase, he adap a ion also igge s he local ea down fi s ,
bu wai s o he local ea down o finish. A e he local ea down is finished, i igge s
he subpo ins ances o he las ime. A e all child en ha e pe o med hei ea down,
T ansac ional Execu ion o Hie a chical Reconfigu a ions Page 125
he adap a ion synch onizes ia finished2PC wi h he in e nal beha io o epo ha he
econfigu a ion has been execu ed success ully.
In case o h ee-phase execu ion, he synch oniza ion ia finished2PC causes he in e nal
beha io o swi ch om Finished o Execu e. Since singlePhase is alse in his case, i
immedia ely p oceeds o Repo . In case o single-phase execu ion, he synch oniza ion
ia finished2PC causes he in e nal beha io o swi ch om Wai o Execu e.I woPCRe-
sul , which s o es he decision on whe he o execu e o no , is alse, he in e nal beha io
swi ches back o Idle.I woPCResul is ue, hen he in e nal beha io swi ches o Repo
and calls he own econfigu a ion ule in he ansi ion ac ion. The ansi ion back o Idle
synch onizes wi h he e en s egion o indica e ha he execu ion has been finished.
The synch oniza ion finish causes he e en s RTSC o swi ch om Busy o Finished. This
ansi ion also sends a message success o ailed o he manage in case ha he econ-
figu a ion has been execu ed o abo ed, espec i ely. Finally, he RTSC fi es he uppe
ansi ion om Finished o Idle which finishes Use Case 1.
In Use Case 2, messages each he execu o ia he pa en po and a e p ocessed by he
co esponding RTSC in egion pa en . Fo each message x ha he componen o e s ia
i s RE po , we gene a e one s a e CheckX including ansi ions om Idle o CheckX and
om CheckX o CheckSel and SendAbo . The ansi ion om Idle o CheckX ecei es he
message x.InCheckX, he pa en ies o synch onize ia checkX wi h he RTSC in he
e en s egion. The s a e CheckX con ains an in a ian c2 ≤γ.γis he ime o decision
specified in he RE po minus he ime ac ually needed o de i ing a decision in he
manage . I γis exceeded, i is no longe possible o check whe he he econfigu a ion
can be execu ed wi hin he ime o decision and he RTSC swi ches o SendAbo . This
case will usually happen i he execu o is al eady execu ing a econfigu a ion when he
message xa i es. In his case, a synch oniza ion wi h he e en s egion ia checkX is
no possible.
I he synch oniza ion ia checkX is possible, he pa en igge s he e en s egion and
swi ches o CheckSel . The RTSC in he e en s egion swi ches om Idle o Check and
o wa ds message x o he manage . We gene a e such ansi ion om Idle o Check o
each message xin he RE po specifica ion. In Check, he e en s egion wai s o he
decision o he manage . I he manage sends declineReques , he e en s egion epo s
he esul ia he synch oniza ion channel execu e and he pa en swi ches o SendAbo .
I he manage sends confi mReques , hen he econfigu a ion may be execu ed. The
e en s egion epo s ha esul ia execu e o he pa en which swi ches o Awai Vo ing
and igge s he in e nal beha io . Then, he o ing phase is pe o med as in Use Case 1.
In con as o Use Case 1, he o ing esul is e u ned o he pa en ha sends he o ing
esul o he pa en componen . I he componen needs o abo , he pa en swi ches
ia Abo ed o FinalizeAbo .InFinalizeAbo , i synch onizes ia finished wi h he e en s
egion and bo h RTSCs e u n o hei Idle s a es. I he componen has commi ed he
econfigu a ion, he pa en wai s in Wai Fo Pa en o he decision o he pa en compo-
nen . I he pa en componen abo s he econfigu a ion, he pa en FinalizeAbo . The
Page 126 Chap e 4
ansi ion om Wai Fo Pa en o FinalizeAbo synch onizes wi h he adap a ion RTSC o
embeddedCI ia doAbo o abo he child econfigu a ions. A e wa ds, i synch onizes
wi h he e en s egion ia finished as desc ibed abo e. I he pa en decided o execu e
he econfigu a ion, he pa en egion swi ches om Wai Fo Pa en o ei he Execu ion o
o Execu eSe up depending on whe he he econfigu a ion is execu ed wi h single-phase
o h ee-phase execu ion. The co esponding ansi ions synch onize ia pe o mRecon
wi h he adap a ion RTSC o embeddedCI. Then, he child econfigu a ions a e igge ed
as in Use Case 1. In h ee-phase execu ion, he adap a ion synch onizes wi h pa en ia
finishPhase a e comple ely execu ing one o he phases. The pa en hen epo s ha
he phase has been finished o he pa en . A e all child econfigu a ions and he own
econfigu a ion ha e been pe o med, he in e nal beha io synch onizes wi h he e en s
egion ha in o ms he manage abou he esul o he execu ion. Finally, e en s akes
he lowe ansi ion om Finished o Idle and synch onizes wi h pa en ia finished. Tha
synch oniza ion causes he ansi ion om Execu ion o Idle o fi e. This ansi ion sends
finished o he pa en componen which finishes Use Case 2.
In he execu o i may happen ha wo eques s a i e a he same ime: one om he
pa en componen , he o he one om he manage . These in e lea ings a e handled in
he e en s egion using he s a es Abo Pa en Req,Wai Fo Answe , and Answe Recei ed as
well as he a iable abo edReqWai ing. I he e en s egion is in s a e Check as pa o
Use Case 2, i may happen ha he manage sends execu eRecon ins ead o confi mRe-
ques . In his case, he manage al eady ea ed a child eques acco ding o Use Case 1
when he execu o o wa ded he pa en eques . Then, he e en s egion fi s ea s he
econfigu a ion ha was eques ed by he manage acco ding o Use Case 1. The e o e,
i swi ches om Check o Abo Pa en Req. This ansi ion abo s he pa en eques by
synch onizing ia execu e wi h he pa en . As a esul , he pa en swi ches o SendAbo
and finishes he eques . Howe e , he eques by he pa en s ill esides in he message
queue o he manage . The e o e, a e finishing he econfigu a ion, he e en s egion
does no e u n o Idle, bu i swi ches o Wai Fo Answe . In his s a e, i wai s o he
confi mReques o declineReques message om he manage . I one o hese messages
is ecei ed, he e en s RTSC swi ches o Answe Recei ed and immedia ely eplies ailed
o he manage . In Wai Fo Answe , i may also happen ha ano he execu eRecon mes-
sage a i es. Then, he manage has ea ed ano he child eques be o e he eques o
he execu o . Then, he e en s RTSC swi ches back o Abo Pa en Req and he p ocedu e
epea s as desc ibed be o e.
4.5 Ve i ying he Reconfigu a ion Specifica ion
We need o e i y ha he specified econfigu a ion beha io o a s uc u ed componen
ulfills all o he ACI-T p ope ies o he 2-phase-commi p o ocol. These p ope ies
gua an ee ha he econfigu a ion beha io o he s uc u e componen is co ec and,
hus, sa e. In ou app oach, o mal e ifica ion is enabled by he ope a ional beha io
specifica ions o manage and execu o in e ms o RTSCs.
T ansac ional Execu ion o Hie a chical Reconfigu a ions Page 127
Fo e i ying he ACI-T p ope ies o he 2-phase-commi p o ocol, we need o e i y
he ollowing ye in o mal p ope ies:
1. I he execu o decides o execu e (abo ), hen all a ec ed child en execu e (abo )
(A omici y).
2. The econfigu a ion ules canno p oduce an inconsis en CIC (Consis ency).
3. The execu o will execu e no o he econfigu a ion han he one eques ed by he
manage (Consis ency).
4. A any ime, a mos one econfigu a ion is execu ed (Isola ion).
5. The RTSCs o manage and execu o a e ee om deadlocks (Timing).
6. Each econfigu a ion is execu able (Timing).
P ope ies 1, 3, and 4 can al eady be gua an eed by he co ec ness o he gene a ion
empla es gi en in Sec ion 4.4. The e o e, hey do no need o be e ified again o
a pa icula s uc u ed componen . The co ec ness o he gene a ion empla es wi h
espec o hese h ee p ope ies has been e ified using UPPAAL [HB13, Vol13].
P ope y 2 specifies ha econfigu a ions may no p oduce an inconsis en CIC. A CIC
may ei he be syn ac ically inconsis en o seman ically inconsis en . A CIC is syn-
ac ically inconsis en i i iola es he condi ions o syn ac ical co ec ness ha we
in oduced in Sec ion 3.2. In ou app oach, he CSDs gua an ee ha CICs emain syn-
ac ically consis en a e a econfigu a ion due o syn ac ic es ic ions. Thus, no u he
check is necessa y. A CIC is seman ically inconsis en i he ins an ia ed componen
ins ances, po ins ances, and connec o ins ances do no cons i u e a desi ed unc ional
beha io . In he wo s case, he componen may e en be unsa e. As an example, con-
side a RailCab ha d i es as pa o a con oy as a membe bu which does no ha e an
ins ance o Membe Con ol (c . Figu e 4.7) al hough i swi ched he con olle . Such si u-
a ions canno be p e en ed by syn ac ic ules bu need o be e ified o each s uc u ed
componen as we desc ibe in Sec ion 4.5.1.
Finally, P ope ies 5 and 6 speci y he condi ions o a co ec iming specifica ion. In
a pla o m-independen model, we may e i y whe he he iming equi emen s p o-
ided in ou decla a i e, able-based specifica ion a e sa isfiable. I hey a e sa isfi-
able, he e may exis a ha dwa e pla o m ha enables o execu e he econfigu a ion
beha io wi hou iola ing he iming equi emen s. A e de i ing a pla o m-specific
model ha includes a pla o m model and a deploymen o componen s o ha dwa e
nodes [PMDB14], we may al eady check a design- ime whe he he execu ion o he e-
configu a ions on he ha dwa e pla o m ulfills he imposed equi emen s. We desc ibe
he e ifica ion o he iming specifica ion in de ail in Sec ion 4.5.2.
In combina ion, bo h e ifica ion s eps and he e ified gene a ion empla es enable o
e i y he econfigu a ion beha io o ou componen s comple ely wi h espec o he
ACI-T p ope ies. The only pa o he econfigu a ion beha io ha canno be o mally
e ified using model checking is gi en by he implemen a ions o he ading unc ions.
Page 134 Chap e 4
Minimum Commi Time Finally, he minimum commi ime dc deno es he mini-
mum ime ha he componen s icks o a commi . A s uc u ed componen ins ance may
only s ick o he commi a mos as long as he child en do. Thus, we need o conside he
minimum among he minimum commi imes dsub
c o all a ec ed child en. In addi ion,
we need o sub ac wo imes he message delay msub because he commi ime s a s
a e he child sen he commi and he que y o execu e needs o each he child be o e
he commi ime expi es. Thus, he minimum commi ime dc o a s uc u ed componen
mus be less o equal o
dc ≤min
i{dsub
c ,i −2·msub
i}
whe e dsub
c ,i e e s o he minimum commi ime o he i h child ha is a ec ed by his
econfigu a ion and msub
iis he message delay o a message sen o ha child.
4.6 Implemen a ion
We implemen ed he concep s in oduced in his chap e as pa o he MECHATRON-
ICUML Tool Sui e. In pa icula , we in eg a ed he implemen a ion in o he plugins
econfigu a ion and econfigu a ion.ui shown in Figu e 3.22 on page 88.
We ex ended he me amodel in plugin econfigu a ion such ha i includes ou econfigu-
a ion con olle including he decla a i e, able-based specifica ion. A class diag am o
his me amodel is p esen ed in Appendix D.2.1.
The plugin econfigu a ion.ui ex ends he componen edi o such ha i enables o speci y
econfigu able componen s including hei econfigu a ion con olle s. In addi ion, i
con ains he gene a o ha enables o gene a e RTSCs o manage and execu o based
on he gene a ion empla es gi en in Sec ion 4.4. The gene a o has been implemen ed
in QVT Ope a ional [G o11b]. In addi ion, we suppo o con e a non- econfigu able
componen in o a econfigu able componen .
4.7 Assump ions and Limi a ions
Ou app oach o he ansac ional execu ion o econfigu a ion unde lies he ollowing
assump ions and limi a ions:
•Any econfigu a ion ha has been s a ed can be finished success ully. In pa icula ,
we assume ha no ha dwa e ailu es occu while execu ing a econfigu a ion.
•All moni o ing is pe o med by a omic componen s ha accumula e he moni o ing
da a and p o ide accumula ed da a o he manage o he pa en componen .
•The econfigu a ion con olle and he gene a ion empla es o de i ing an ope a-
ional beha io specifica ion o manage and execu o ha e only been defined o
s uc u ed componen s because o he missing concep o quiescence o a omic
componen s in MECHATRONICUML (c . Sec ion 4.2.3).
T ansac ional Execu ion o Hie a chical Reconfigu a ions Page 135
•We may only igge a mos one econfigu a ion on each child o a s uc u ed
componen ins ance when execu ing a CSD o he s uc u ed componen ins ance.
In addi ion, ou implemen a ion unde lies he ollowing limi a ions:
•The gene a ion empla es do no suppo inpu and ou pu pa ame e s o CSDs as
hey a e used, e.g., by he CSD in Figu e 3.14 on Page 76.
•The concep o e i ying consis ency in oduced in Sec ion 4.5.1 has no ye been
implemen ed.
4.8 Rela ed Wo k
Sec ion 3.7 e iewed componen models and a chi ec u e desc ip ion languages ha sup-
po econfigu a ion o he so wa e a chi ec u e a un ime. Only ew o hem conside
econfigu a ion o hie a chical componen s suppo ing a ansac ional execu ion o e-
configu a ions. We e iew hei econfigu a ion capabili es in Sec ion 4.8.1. The ea e ,
we discuss ela ed app oaches o achie ing quiescence in a sys em in Sec ion 4.8.2.
4.8.1 App oaches Suppo ing Reconfigu a ion o Hie a chical
Componen s
Ou app oach is inspi ed by he econfigu a ion concep s o F ac al [BCL+06, LLC10]
which has been ex ended o dis ibu ed execu ion in [BHR09]. Thei concep ex ends
each econfigu able componen wi h a econfigu a ion in e ace and a econfigu a ion
execu o o execu ing econfigu a ion sc ip s. We ha e adop ed he concep o a e-
configu a ion execu o and ex ended he emo e econfigu a ion in oca ion. In con as
o ou app oach, F ac al s a s econfigu a ions op imis ically and pe o ms a oll-back
in case ha he econfigu a ion is no possible. As desc ibed in Sec ion 4.2, his is no
sa e in mecha onic sys ems. Thei app oach achie es ACI p ope ies as well, bu does
no conside iming o econfigu a ions. In addi ion, we suppo a highe le el modeling
language o modeling econfigu a ions a he han implemen ing hem as a sc ip . The
app oach by Boye e al. [BGP13] also ollows a oll-back app oach o achie ing eli-
able econfigu a ion, bu hei app oach nei he ea s hie a chy no achie es any o he
ACI-T p ope ies. The SOFA 2.0 componen uses componen con olle s simila o F ac-
al and o ou app oach, called mic o-componen s, bu does no p o ide a ansac ional
execu ion o econfigu a ions [HB07].
The a chi ec u e desc ip ion language GeReL [EW92] suppo s a sepa a ion o conce ns
be ween unc ional and econfigu a ion beha io . I uses a fi s -o de logic o de e mine
whe he a econfigu a ion can be execu ed o no . This ensu es consis ency o he modi-
fied sys em, while hei execu ion model gua an ees a omici y o econfigu a ions. Thei
app oach, howe e , does explici ly suppo hie a chical componen s. In addi ion, hey
do no conside eal- ime p ope ies.
Page 136 Chap e 4
Pop e al. [PPO+12] in oduce a mode change ope a ion o embedded eal- ime sys ems
based on he SOFA-HI [PWT+08] componen model. In hei app oach, each mode o
a componen ins ance co esponds o a configu a ion. They also sepa a e unc ional and
econfigu a ion beha io and enable mode changes ac oss di e en le els o hie a chy.
Consis en modes o a componen and i s child en a e specified by p ope y ne wo ks.
In con as o ou app oach, hey canno ensu e a omici y i a child is cu en ly no able
o econfigu e and hey do no p o ide a o mal e ifica ion suppo o checking o a
co ec iming o econfigu a ions.
The app oach by Hang e al. [HCH12, HQCH13] implemen s a composable mode change
ope a o based on he P oCom componen model [VSC+09]. As in [PPO+12], modes
co espond o componen configu a ions. Simila o ou app oach, hey use dedica ed
econfigu a ion componen s ha a e hie a chically connec ed. Reconfigu a ion eques s
may a e se he hie a chy bo om-up o op-down. In [HH13], hey adop ed ou ap-
p oach o execu ing econfigu a ions in wo phases and use ou e ifica ion app oach
in oduced in Sec ion 4.5.2. In con as o ou app oach, hey do no p o ide explici
eal- ime p ope ies ega ding he execu ion o econfigu a ions in hei specifica ion.
The amewo k by de Oli ei a e al. [DOLS13] uses se e al au onomic manage s o
adap ing cloud applica ions in a coo dina ed ashion. Thei au onomic manage s ha e a
simila pu pose as ou econfigu a ion con olle bu a e ho izon ally composed. They
sha e in o ma ion using e en -based coo dina ion p o ocols o imp o ing adap a ion
decisions bu do no conside ansac ional execu ion o eal- ime p ope ies.
The Rainbow amewo k [GCH+04, CGS09] p o ides an implemen a ion o he e e -
ence a chi ec u e MAPE-K [IBM06] ha a ge s business in o ma ion sys ems. Thei
concep defines an adap a ion manage and an adap a ion execu o ha closely co e-
spond o he manage and execu o in ou app oach. Howe e , hei app oach does no
espec componen encapsula ion o a hie a chical componen a chi ec u e. In addi ion,
hei app oach does nei he suppo eal- ime p ope ies no gua an ee ACI-T p ope ies.
Simila ly, Zhang e al. [ZCYM05] p o ide an app oach o sa e adap a ion o compo-
nen -based sys ems. Thei app oach uses one cen al adap a ion manage ha o ches-
a es he adap a ion p ocess, and se e al agen s ha a e a ached o he componen s
and pe o m hei modifica ion. I an adap a ion canno be finished success ully, hey
pe o m a oll-back o he p e ious configu a ion. Thus, hei app oach gua an ees ACI
p ope ies o he execu ion o econfigu a ions bu no eal- ime p ope ies. In addi ion,
hei app oach does no explici ly conside hie a chical componen s.
The app oach by Edwa ds e al. [EGT+09] uses me a-le el componen s o implemen -
ing a sel -adap a ion con ol loop simila o MAPE-K [IBM06] based on a hie a chical
componen model. The me a-le el componen s ulfill a simila pu pose as ou econ-
figu a ion con olle by moni o ing he componen s on he hie a chy le el below, by
e alua ing whe he and how o adap , and by execu ing he esul ing adap a ion plan.
Simila ly, V oman e al. [VWMA11] connec se e al MAPE con ol loops ha a e lo-
ca ed on he same hie a chy le el ollowing a mas e -sla e pa e n. Then, he con ol
T ansac ional Execu ion o Hie a chical Reconfigu a ions Page 137
loops communica e o de i ing a consis en adap a ion s a egy. Bo h app oaches do
no explici ly connec me a-le el componen o MAPE con ol loops, espec i ely, on
di e en hie a chy le els such ha hie a chical execu ion a e no suppo ed and ACI-T
p ope ies canno be gua an eed.
EUREMA [VG14] suppo s he specifica ion o sel -adap a ion eedback loops based on
MAPE-K [IBM06] using a g aphical no a ion called eedback loop diag ams. The ap-
p oach suppo s o use and o coo dina e mul iple eedback loops in a single sys em. In
addi ion, eedback loops on di e en a chi ec u al le els may be connec ed and coo di-
na ed by using laye diag ams. Weyns e al. [WSG+13] discuss di e en design pa e ns
o connec ing mul iple MAPE eedback loops in a sys em. Wi h espec o hei pa e n,
ou app oach is based on he hie a chical con ol pa e n. In con as o ou app oach,
he app oaches do no suppo eal- ime cons ain s and do no explici ly conside ACI-T
p ope ies. Howe e , EUREMA sa isfies isola ion o adap a ions.
Finally, he aul - ole an componen model by de Lemos e al. [dLdCGFR06] pa i-
ions componen beha io in o no mal and abno mal (excep ion) beha io . We ollow
he same idea by sepa a ing no mal beha io and econfigu a ion beha io . Thei ap-
p oach p o ides ho izon al p opaga ion o excep ions, bu no p opaga ion o pa en
componen s. Wi h a simila objec i e, S unk and Knigh [SK06] p o ide a depend-
able econfigu a ion app oach o ha d eal- ime sys ems whe e a sys em mo es om
one configu a ion o ano he one wi h deg aded unc ionali y in case o a ailu e. The
app oach, howe e , nei he conside s componen s no hie a chy, bu i ensu es by o mal
p oo s ha any econfigu a ion can be execu ed success ully.
4.8.2 Quiescence o Componen s
In he app oach by K ame and Magee [KM98], he condi ions o quiescence equi e
all a ec ed componen ins ances and all componen ins ances ha a e connec ed o hem
o be passi e. In essence, his means ha he componen ins ances a e shu down and
no longe execu ed. A e he econfigu a ion has been finished, hey a e s a ed, again.
Gi en an NMS such as a con oy o RailCabs, his is no a iable app oach. In he
wo s case, i equi es ha all he RailCabs in a con oy need o shu down i one RailCab
needs o pe o m a econfigu a ion. This, in u n, equi es he RailCab o s op o each
econfigu a ion, which is no desi able. The concep o anquili y [VEBD07] elaxes
he condi ions on quiescence by K ame and Magee [KM98]. The majo d awback o
hei app oach is ha anquili y is no p edic able, i.e., i canno be decided whe he a
componen ins ance will become anquil in a gi en amoun o ime.
The app oaches by Chen e al. [CHS01], Gha a i e al. [GJSH12], and Panzica La Manna
[PLM12] suppo he e olu ion o a so wa e a chi ec u e o a business in o ma ion sys-
em whe e componen ins ances a e upg aded o a new e sion implemen s he same be-
ha io . The new componen ins ance ei he fixes bugs o he old componen ins ance o
p o ides quali y o se ice ha sui es be e o he cu en equi emen s. The app oaches
by Chen e al. and Gha a i e al. wo k simila o ou ading unc ions. The componen
Page 138 Chap e 4
ins ance o be emo ed and he new componen ins ance a e execu ed in pa allel. Then,
new ansac ions a e handled by he new componen ins ance while he old componen
ins ance emains ac i e un il i has p ocessed all pending ansac ions. The app oach by
Panzica La Manna ies o ans e he comple e s a e o he old componen ins ance o
he new one such ha he new componen ins ance may con inue p ocessing all ans-
ac ions ha ha e been s a ed using he old componen ins ance. I his is no possible,
he app oach applies a e sion consis en upda e as defined by Ma e al. [MBG+11] ha
applies a simila s a egy as he app oaches by Chen e al. and Gha a i e al. In essence,
all o hese app oaches y o p ese e he unc ional beha io o he sys em du ing and
a e he upda e wi h he excep ion o co ec ed bugs and imp o ed quali y o se ice
cha ac e is ics. In con as , ou app oach explici ly aims a modi ying he unc ional
beha io , e.g, i a RailCab joins a con oy. The e o e, we equi e o add o o en i ely
emo e componen ins ances om he so wa e a chi ec u e, which is no suppo ed by
hese app oaches. In addi ion, hey do no conside he eal- ime cons ain s and he
physical mo emen o he sys em, e.g., i s cu en speed o i s dis ance o o he ehicles.
4.9 Summa y
This sec ion in oduces an app oach o execu ing econfigu a ions in a hie a chical com-
ponen model o sel -adap i e mecha onic sys ems. On he syn ac ic le el, we ex end
each s uc u ed componen by a dedica ed econfigu a ion con olle ha con ains he
econfigu a ion beha io . The econfigu a ion con olle con ains a manage , an execu-
o , and an op ional un ime isk manage . The manage defines whe he and how he
componen shall econfigu e. The execu o is esponsible o execu ing econfigu a ions
wi h espec o hie a chy. The un ime isk manage defines which econfigu a ions may
be execu ed such ha he unc ional sa e y o he sys em is e ained. On he seman ic
le el, ou econfigu a ion con olle implemen s a a ian o he 2-phase-commi p o o-
col [BHG87, ch. 7] ha has been adap ed o he domain o mecha onic sys ems. As a
esul , ou app oach sa isfies ACI-T p ope ies o he execu ion o econfigu a ions, i.e.,
a omici y, consis ency, isola ion, and a co ec iming, e en o econfigu a ions span-
ning e ical composi ions o componen s. Fu he mo e, ou app oach espec s encapsu-
la ion o componen s. Fo he execu ion o he econfigu a ion, ou app oach suppo s a
single-phase execu ion o econfigu ing disc e e componen ins ance and a h ee-phase
execu ion o sa ely eplacing con inuous componen s ha con ains eedback con olle s.
Ou app oach elie es he componen de elope om speci ying he complex implemen-
a ion o he 2-phase-commi p o ocol by hand o each componen . Ins ead, we p o ide
a concise decla a i e specifica ion o he beha io o manage and execu o based on a-
bles. These ables speci y he condi ions when o execu e which econfigu a ion. Then,
hese ables a e used as an inpu o a gene a o ha au oma ically de i es an implemen-
a ion o he 2-phase-commi p o ocol based on RTSCs. The gene a ed RTSCs ulfill
a omici y and isola ion by cons uc ion. In addi ion, he gene a ed RTSCs and he CSDs
T ansac ional Execu ion o Hie a chical Reconfigu a ions Page 139
ha define he modifica ion o he CIC se e as inpu s o ou e ifica ion p ocedu e ha
e ifies consis ency and a co ec iming o he econfigu a ion beha io .
Ve i ying Refinemen s based on Tes Au oma a Page 141
5 Ve i ying Refinemen s based on Tes Au oma a
Sel -adap i e mecha onic sys ems a e o en in ended o ope a e as pa o an NMS. As
an example, RailCabs a e in ended o ope a e in con oys. Then, he co ec unc ion-
ali y o he sel -adap i e mecha onic sys em and, in pa icula , i s sa e y do no only
depend on i s own co ec ness bu also on he co ec in e ac ion wi h o he AMS in-
side he NMS. The in e ac ion, in u n, is ypically defined by complex applica ion-le el
communica ion p o ocols. These communica ion p o ocols define which messages a e
needed o be exchanged and in which o de and ime in e als o ealizing he in ended
unc ionali y. Equally, defining he beha io o a single AMS equi es o connec he
di e en componen s o i s so wa e a chi ec u e using applica ion-le el communica ion
p o ocol as well. As an example, conside he componen ins ances o a RailCab gi en
in Sec ion 3.2 and Appendix A.4.
Due o he sa e y c i ical na u e o sel -adap i e mecha onic sys ems, we need o o -
mally e i y hei beha io based on model checking [CGP00, BK08] o gua an eeing
hei co ec ness. On he one hand, his equi es o e i y he econfigu a ion beha io
o he componen s as discussed in Sec ion 4.5. On he o he hand, his equi es o e i y
he unc ional beha io specifica ion o each disc e e a omic componen ha is used in
he so wa e a chi ec u e. Howe e , he co ec ness o a single componen does no only
depend on i s own beha io specifica ion bu also on he beha io specifica ions o he
componen s ha i needs o in e ac wi h. The esul ing so wa e a chi ec u e as gi en
by a CIC consis s o se e al in e connec ed componen ins ances. Such CIC, howe e ,
canno be e ified using s anda d model checking ools like UPPAAL [BDL+06b] due
o he s a e-explosion p oblem [CGP00].
Composi ional e ifica ion app oaches [BCC98] based on he assume/gua an ee p inci-
ple [CGP00, ch. 12] ackle he s a e explosion p oblem by decomposing he sys em in o
smalle uni s o e ifica ion. P e ious wo ks defined such composi ional e ifica ion
app oach o MECHATRONICUML as well [GTB+03, Gie03, GS13]. The basic idea
o MECHATRONICUML’s composi ional e ifica ion app oach is a syn ac ic decompo-
si ion o he unc ional beha io in o RTCPs and componen s. I equi es ha RTCPs
a e specified independen o componen s. Then, each disc e e po o a disc e e a omic
componen efines one ole o a RTCP, which esul s in one RTSC o each disc e e po .
These po RTSCs a e hen composed o a componen RTSC as illus a ed in Figu e 3.3.
This allows o e i y he unc ional beha io o la ge componen s o e en o comple e
an NMS in h ee s eps as illus a ed in Figu e 5.1.
In he ollowing, we illus a e he h ee s eps o MECHATRONICUML’s composi ional
e ifica ion app oach based on he RailCab sys em using he RTCP En e Sec ion.In
he RailCab sys em, RailCabs a el on a ack sys em ha is subdi ided in o di e en
ypes o sec ions including swi ches and ail oad c ossings. Be o e en e ing a sec ion, a
RailCab needs o que y he sec ion whe he i is allowed o en e i using En e Sec ion.
This is necessa y o ealizing collision a oidance because senso s in a RailCab may no
Page 142 Chap e 5
1. Ve i y Abs ac P o ocol ia Model Checking
|=
I
1,…,
I
n
3. Ve i y each Componen sepe a ely ia Model Checking
(a leas o deadlock eedom)
2. Ve i y Re inemen
|=
I
1,…,
I
n
AG (A¬ ailcab.en e Sec ion
Wsec ion.en e Allowed)
I
1
delay: 20ms
:sec ion2 :le
ailcab sec ion
En e Sec ion
« e ines»« e ines»
Abs ac P o ocolRe ined P o ocol
in-bu e size: 1 in-bu e size: 1
RailCab 1 :
RailCab s3:Swi ch
Figu e 5.1: O e iew o he Refinemen App oach [HBDS15]
de ec o he RailCabs i hey a e hidden behind a bend o some o he obs acle. The e o e,
RailCabs communica e wi h a sec ion o ge ing pe mission o en e i .
In he fi s s ep o he composi ional e ifica ion app oach, he de elope needs o e i y
all RTCPs ha he used in he sys em o sa e y and li eness p ope ies. The e ifica ion
may ei he be ca ied ou using model checking based on UPPAAL as desc ibed by
Ge king [Ge 13] o using a g aph-based e ifica ion echnique [EHH+13, SHS11]. In
ou RailCab example, his s ep includes e ifica ion o he RTCP En e Sec ion beside
o he s. Fo he emainde o his chap e , we e e o he beha io implemen ed by he
oles o he RTCP as he abs ac p o ocol.
In he second s ep, we e i y whe he he po s o a componen co ec ly efine he
oles o he RTCP. This is necessa y because he po s usually need o ex end he ole
beha io by addi ional compu a ions. In ou example, a po o a ack sec ion may no
decide on i s own whe he he ack sec ion is ee. I se e al po s o a ack sec ion
communica e wi h di e en RailCabs, he po s need o be synch onized such ha only
one po allows a RailCab o en e a a ime. Despi e he necessa y modifica ions, he
beha io o a po mus be complian o he specified ole beha io , i.e., i mus be a
legal efinemen acco ding o a efinemen defini ion. In he ollowing, we e e o he
beha io implemen ed by he disc e e po s as he efined p o ocol.
In he hi d s ep, we combine he po RTSCs o a componen RTSC using addi ional
synch oniza ion RTSCs (c . Sec ion 3.1.2.1). Then, we need o e i y o each com-
ponen RTSC ha i is ee o deadlocks [Gie03]. We may e i y addi ional sa e y and
li eness p ope ies e e ing o a co ec in e ac ion o he di e en po s o a componen
i necessa y. In ou RailCab example, we may e i y he a o emen ioned p ope y ha
he ack sec ion gi es pe mission o only one RailCab o en e a a ime. App oaches
o esol ing such dependencies au oma ically ha e beeen in oduced by Ecka d and
Henkle [EH10] and Goschin e al. [Gos14, DGB14].
Ve i ying Refinemen s based on Tes Au oma a Page 143
Ve i ying he co ec ness o he efinemen in he second s ep o he composi ional e ifi-
ca ion app oach equi es a o mal efinemen defini ion. I gua an ees ha all p ope ies
ha ha e been e ified o he RTCP also hold o he in e ac ion o componen s ia
hei disc e e po s. A sui able efinemen defini ion lea es he de elope wi h as much
flexibili y on efining he model as possible, bu is as es ic i e as necessa y o gua -
an eeing ha no e ified p ope y is iola ed. This enables o use he same RTCP o
di e en componen s. In he RailCab example, i is pa icula ly use ul o use he RTCP
En e Sec ion o all ypes o ack sec ions. Then, he ype o ack sec ion is opaque o
a RailCab. Each kind o ack sec ion, howe e , equi es he beha io o a sec ion o be
efined di e en ly.
In li e a u e, di e en efinemen defini ions ha e been p oposed [WL97, JLS00,
HH11a]. Each o which p o ides a di e en comp omise be ween p ese ed p ope ies
and allowed modifica ions. Depending on he pa icula ype o RTCP ha is efined,
all o hem migh be use ul when building a sys em. As a consequence, he e does
no exis one efinemen defini ion ha is sui able o all RTCPs. Ins ead, a composi-
ional e ifica ion app oach should suppo se e al efinemen defini ions. P esen ly, he
composi ional e ifica ion app oach suppo s only one pa icula kind o imed simula-
ion [Gie03], which is no su ficien o handle he example ske ched abo e.
In his chap e , we ex end he composi ional e ifica ion app oach o MECHATRONIC-
UML by suppo ing a o al o six di e en efinemen defini ions. As ou main con i-
bu ion, we p esen a efinemen check ha enables o e i y all six efinemen defini ions
o a gi en ole o a RTCP and a disc e e po o a componen . Ou efinemen check
ex ends he app oach by Jensen e al. [JLS00] ha is based on so-called es au oma a.
A es au oma on encodes bo h he beha io o he ole and he condi ions o a co ec
efinemen . I (and only i ) he po beha io iola es he condi ions o a co ec efine-
men , he es au oma on en e s a special e o loca ion indica ing a nega i e e ifica ion
esul . We pa ame e ized and ex ended he o iginal cons uc ion such ha we may e i y
all efinemen defini ions in a single algo i hm ha may easily be ex ended o include ad-
di ional efinemen defini ions i necessa y. As a byp oduc , ou efinemen check may
au oma ically de ec which efinemen defini ion is sui able o a gi en pai o ole and
po beha io including he e ified p ope ies. Al hough he composi ional e ifica ion
app oach o MECHATRONICUML is p ima ily in ended o e i ying he so wa e ha
is used in he eflec i e ope a o o he OCM [GS13], ou efinemen check may also be
used o checking efinemen s o RTCPs ha a e used in he cogni i e ope a o .
In he emainde o his chap e , we fi s desc ibe he beha io o he RTCP En e Sec ion
including efined po RTSCs o he di e en ypes o ack sec ions in Sec ion 5.1.
Sec ion 5.2 e iews he six efinemen defini ions ha we conside in ou app oach.
Then, we in oduce ou efinemen check based on es au oma a in Sec ion 5.3 and i s
implemen a ion in Sec ion 5.4. The ea e , we discuss he assump ions and limi a ions o
ou app oach in Sec ion 5.5. We e alua e ou efinemen check using a case s udy based
on he RTCP En e Sec ion (Sec ion 5.6). Finally, we discuss ela ed wo k (Sec ion 5.7)
and summa ize he esul s (Sec ion 5.8).
Supe ised Thesis Page 247
Supe ised Thesis
[AAB+11] AHMADIAN, A. S.; AYDOGAN, C.; BRAUN, D.; BUSTAMANTE, L. G.;
GERKING, C.; ISSIZ, S.; KOPECKI, L.; PRESCHER, P.: De elope doc-
umen a ion o he P ojec G oup Sa eBo s I. P ojec g oup, Uni e si y o
Pade bo n, Sep embe 2011.
[B e10] BRENNER, C.: Analyse on mecha onischen Sys emen mi els Tes au o-
ma en. Mas e ’s hesis, Uni e si y o Pade bo n, Augus 2010.
[B ö11] BRÖKER, K.: Modellie ung und Ve ifika ion on Kommunika ionsp o-
okollen ü den Be ieb des RailCab Sys ems. Mas e ’s hesis, Uni e si y
o Pade bo n, No embe 2011.
[D e11] DREISING, C.: Reconfigu a ion o Mecha onicUML componen a chi ec-
u es. Bachelo ’s hesis, Uni e si y o Pade bo n, No embe 2011.
[Pin12] PINES, A.: T ans o ma ion on ekonfigu ie ba en Mecha onicUML-Mo-
dellen nach MATLAB/Simulink. Bachelo ’s hesis, Uni e si y o Pade bo n,
June 2012.
[Sch12] SCHUBERT, D.: In eg a ion on Modellie ungssp achen ü Rekonfigu a-
ion in Mecha onicUML. Bachelo ’s hesis, Uni e si y o Pade bo n, June
2012.
[Sch15] SCHUBERT, D.: Iden ifica ion o sa e s a es o econfigu a ion in Mecha-
onicUML. Mas e ’s hesis, Uni e si y o Pade bo n, July 2015.
[Suc11] SUCK, J.: Model Checking zei beha e e G aph ans o ma ionssys eme.
Mas e ’s hesis, Uni e si y o Pade bo n, May 2011.
[Vol13] VOLK, A.: Hyb ide, ekonfigu ie ba e, hie a chische Komponen ens uk-
u en in MATLAB/Simulink. Mas e ’s hesis, Uni e si y o Pade bo n, De-
cembe 2013.
Li e a u e Page 249
Li e a u e
[ABBL03] ACETO, L.; BOUYER,P.;BURGUEÑO, A.; LARSEN,K.G.:
The powe o eachabili y es ing o imed au oma a. Theo e ical
Compu e Science, 300(1-3):411–475, May 2003. ISSN:0304-3975.
doi:10.1016/s0304-3975(02)00334-1.
[ABRW09] ANGERMANN, A.; BEUSCHEL, M.; RAU, M.; WOHLFARTH,U.:
MATLAB – Simulink – S a eflow, G undlagen, Toolboxen, Beispiele.
Oldenbou g Ve lag, München, 6 edi ion, 2009. ISBN:978-3-486-
59546-8.
[ACD93] ALUR, R.; COURCOUBETIS, C.; DILL, D. L.: Model-checking in
dense eal- ime. In o ma ion and Compu a ion, 104(1):2–34, May
1993. ISSN:0890-5401. doi:10.1006/inco.1993.1024.
[ÅCF+07] ÅKERHOLM, M.; CARLSON, J.; FREDRIKSSON, J.; HANSSON, H.;
HÅKANSSON, J.; MÖLLER, A.; PETTERSSON,P.;TIVOLI, M.: The
SAVE app oach o componen -based de elopmen o ehicula sys-
ems. Jou nal o Sys ems and So wa e, 80(5):655 – 667, May 2007.
ISSN:0164-1212. doi:10.1016/j.jss.2006.08.016.
[AD94] ALUR, R.; DILL, D. L.: A heo y o imed au oma a. Theo e i-
cal Compu e Science, 126(2):183–235, Ap il 1994. ISSN:0304-3975.
doi:10.1016/0304-3975(94)90010-8.
[ADG98] ALLEN, R.; DOUENCE, R.; GARLAN, D.: Speci ying and analyzing
dynamic so wa e a chi ec u es. Lec u e No es in Compu e Science,
1382:21–37, 1998.
[ADI06] ALUR, R.; DANG,T.;IVAN ˇ
CI´
C, F.: P edica e abs ac ion o each-
abili y analysis o hyb id sys ems. ACM T ansac ions on Embedded
Compu ing Sys ems (TECS), 5:152–199, Feb ua y 2006. ISSN:1539-
9087. doi:10.1145/1132357.1132363.
[ADM01] ASARIN, E.; DANG,T.;MALER, O.: d/d : A ool o eachabili y
analysis o con inuous and hyb id sys ems. In P oceedings o he 5 h
IFAC Symposium Nonlinea Con ol Sys ems, NOLCOS, pages 3–34,
July 2001. ISBN:978-0-08-043560-2.
[ADM02] ASARIN, E.; DANG,T.;MALER, O.: The d/d ool o e ifica ion o
hyb id sys ems. In BRINKSMA, E.; LARSEN, K. G. (Eds.), Compu e
Aided Ve ifica ion, olume 2404 o Lec u e No es in Compu e Science,
pages 365–370. Sp inge Be lin Heidelbe g, 2002. ISBN:978-3-540-
43997-4. doi:10.1007/3-540-45657-0_30.
Page 250
[ÅEM98] ÅSTRÖM, K. J.; ELMQVIST, H.; MATTSON, S. E.: E olu ion o
con inuous- ime modeling and simula ion. In P oceedings o he 12 h
Eu opean Simula ion Mul icon e ence on Simula ion - Pas , P esen and
Fu u e, pages 9–18. SCS Eu ope, 1998. ISBN:1-56555-148-6.
[AH92] ALUR, R.; HENZINGER, T. A.: Logics and models o eal ime:
A su ey. In DE BAKKER,J.W.;HUIZING, C.; DE ROEVER,
W.-P.; ROZENBERG, G. (Eds.), Real-Time: Theo y in P ac ice,
olume 600 o Lec u e No es in Compu e Science, pages 74–106.
Sp inge Be lin Heidelbe g, June 1992. ISBN:978-3-540-55564-3.
doi:10.1007/b b0031988.
[AHJ+09] ANNE, M.; HE, R.; JARBOUI,T.;LACOSTE, M.; LOBRY, O.; LO-
RANT, G.; LOUVEL, M.; NAVAS, J.; OLIVE,V.;POLAKOVIC, J.;
POULHIÈS, M.; PULOU, J.; SEYVOZ, S.; TOUS, J.; WATTEYNE,T.:
Think: View-based suppo o non- unc ional p ope ies in embedded
sys ems. In In e na ional Con e ence on Embedded So wa e and Sys-
ems, ICESS ’09, pages 147 –156. IEEE Compu e Socie y, May 2009.
ISBN:978-1-4244-4359-8. doi:10.1109/icess.2009.30.
[AHKV98] ALUR, R.; HENZINGER, T. A.; KUPFERMAN, O.; VARDI, M. Y.: Al-
e na ing efinemen ela ions. In SANGIORGI, D.; SIMONE, R. (Eds.),
CONCUR’98 Concu ency Theo y, olume 1466 o Lec u e No es in
Compu e Science, pages 163–178. Sp inge Be lin Heidelbe g, 1998.
ISBN:978-3-540-64896-3. doi:10.1007/b b0055622.
[Alu99] ALUR, R.: Timed au oma a. In HALBWACHS, N.; PELED,D.A.
(Eds.), Compu e Aided Ve ifica ion, olume 1633 o Lec u e No es in
Compu e Science, pages 8–22. Sp inge Be lin Heidelbe g, July 1999.
ISBN:978-3-540-66202-0. doi:10.1007/3-540-48683-6_3.
[Alu11] ALUR, R.: Fo mal e ifica ion o hyb id sys ems. In P oceedings o he
nin h ACM in e na ional con e ence on Embedded so wa e, EMSOFT
’11, pages 273–278, New Yo k, NY, USA, 2011. ACM. ISBN:978-1-
4503-0714-7. doi:10.1145/2038642.2038685.
[AM02] AGUIRRE, N.; MAIBAUM, T.: A empo al logic app oach o he
specifica ion o econfigu able componen -based sys ems. In P o-
ceedings o he 17 h IEEE In e na ional Con e ence on Au oma ed
So wa e Enginee ing, ASE 2002, pages 271–274, Los Alami os,
CA, USA, 2002. IEEE Compu e Socie y. ISBN:0-7695-1736-6.
doi:10.1109/ase.2002.1115028.
[A b04] ARBAB, F.: Reo: a channel-based coo dina ion model o
componen composi ion. Ma hema ical S uc u es in Com-
pu e Science, 14(3):329–366, May 2004. ISSN:1469-8072.
doi:10.1017/s0960129504004153.
Li e a u e Page 251
[ASTPH10] ADLER, R.; SCHAEFER, I.; TRAPP, M.; POETZSCH-HEFFTER,A.:
Componen -based modeling and e ifica ion o dynamic adap a ion in
sa e y-c i ical embedded sys ems. ACM T ansac ions on Embedded
Compu ing Sys ems, 10(2):20:1–20:39, Decembe 2010. ISSN:1539-
9087. doi:10.1145/1880050.1880056.
[AUT11] AUTOSARAUTOSAR 3.2 - Technical O e iew, Ap il 2011.
Documen Iden ifica ion No. 067, Ve sion 2.2.2. URL:
h p://www.au osa .o g/ ileadmin/ iles/ eleases/
3-2/main/auxilia y/AUTOSAR_TechnicalO e iew.pd
[ci ed Ma ch 14, 2015].
[AUT14a] AUTOSARAUTOSAR 4.1 - Guide o Modemanagemen , Ma ch
2014. Documen Iden ifica ion No. 440, Ve sion 2.2.0. URL: h p:
//www.au osa .o g/ ileadmin/ iles/ eleases/4-1/
so wa e-a chi ec u e/sys em-se ices/auxilia y/
AUTOSAR_EXP_Modemanagemen Guide.pd [ci ed Ma ch 14,
2015].
[AUT14b] AUTOSARAUTOSAR 4.1 - Specifica ion o Timing Ex ensions,
Ma ch 2014. Documen Iden ifica ion No. 411, Ve sion 2.1.1. URL:
h p://www.au osa .o g/ ileadmin/ iles/ eleases/
4-1/me hodology- empla es/ empla es/s anda d/
AUTOSAR_TPS_TimingEx ensions.pd [ci ed Ma ch 14, 2015].
[AUT14c] AUTOSARAUTOSAR 4.1 - Vi ual Func ional Bus, Ma ch
2014. Documen Iden ifica ion No. 056, Ve sion 3.2.0. URL:
h p://www.au osa .o g/ ileadmin/ iles/ eleases/
4-1/main/auxilia y/AUTOSAR_EXP_VFB.pd [ci ed Ma ch 14,
2015].
[BB08] BAUMANN, G.; BROST, M.: Tes e ah en ü Elek onik und Em-
bedded So wa e in de Au omobilen wicklung. In GIESE, H.;
HUHN, M.; NICKEL, U. A.; SCHÄTZ, B. (Eds.), Dags uhl-Wo kshop
MBEES: Modellbasie e En wicklung eingebe e e Sys eme IV, Schloss
Dags uhl, Ge many, 7.-9. Ap il 2008, Tagungsband Modellbasie e En-
wicklung eingebe e e Sys eme, numbe 2008-2 in In o ma ik-Be ich ,
pages 13–19. TU B aunschweig, Ins i u ü So wa e Sys ems Engin-
ee ing, Ap il 2008.
[BBCP13] BARNAT, J.; BENEŠ, N.; CERNÁ, I.; PETRUCHOVÁ, Z.: DCCL:
e ifica ion o componen sys ems wi h ensembles. In P o-
ceedings o he 16 h In e na ional ACM Sigso symposium on
Componen -based so wa e enginee ing, CBSE ’13, pages 43–52,
New Yo k, NY, USA, June 2013. ACM. ISBN:978-1-4503-2122-8.
doi:10.1145/2465449.2465453.
Page 252
[BBF09] BLAIR, G.; BENCOMO, N.; FRANCE, R. B.: Models@
un. ime. Compu e , 42(10):22 –27, Oc obe 2009. ISSN:0018-9162.
doi:10.1109/mc.2009.326.
[BBG+06] BECKER, B.; BEYER, D.; GIESE, H.; KLEIN,F.;SCHILLING,D.:
Symbolic in a ian e ifica ion o sys ems wi h dynamic s uc u al
adap a ion. In P oceedings o he 28 h In e na ional Con e ence on So -
wa e Enginee ing, ICSE ’06, pages 72–81, New Yo k, NY, USA, May
2006. ACM. ISBN:1-59593-375-1. doi:10.1145/1134285.1134297.
[BC12] BOUISSOU, O.; CHAPOUTOT, A.: An ope a ional seman ics o Si-
mulink’s simula ion engine. In P oceedings o he 13 h ACM SIG-
PLAN/SIGBED In e na ional Con e ence on Languages, Compile s,
Tools and Theo y o Embedded Sys ems, LCTES ’12, pages 129–
138, New Yo k, NY, USA, 2012. ACM. ISBN:978-1-4503-1212-7.
doi:10.1145/2248418.2248437.
[BCC98] BEREZIN, S.; CAMPOS, S.; CLARKE, E. M.: Composi ional ea-
soning in model checking. In ROEVER, W.-P.; LANGMAACK,
H.; PNUELI, A. (Eds.), Composi ionali y: The Significan Di e -
ence, olume 1536 o Lec u e No es in Compu e Science, pages 81–
102. Sp inge Be lin Heidelbe g, 1998. ISBN:978-3-540-65493-3.
doi:10.1007/3-540-49213-5_4.
[BCC+03] BIERE, A.; CIMATTI, A.; CLARKE, E. M.; STRICHMAN, O.; ZHU,
Y.: Bounded model checking. In ZELKOVWITZ, M. V. (Ed.), Ad ances
in Compu e s, Volume 58, pages 117–148. Else ie , 1s edi ion, 2003.
ISBN:0-12-012158-1.
[BCDW04] BRADBURY, J. S.; CORDY, J. R.; DINGEL, J.; WERMELINGER,M.:
A su ey o sel -managemen in dynamic so wa e a chi ec u e speci-
fica ions. In P oceedings o he 1s ACM SIGSOFT wo kshop on Sel -
managed sys ems, WOSS ’04, pages 28–33, New Yo k, NY, USA, 2004.
ACM. ISBN:1-58113-989-6. doi:10.1145/1075405.1075411.
[BCK98] BELLARE, M.; CANETTI, R.; KRAWCZYK, H.: A modula app oach
o he design and analysis o au hen ica ion and key exchange p o-
ocols (ex ended abs ac ). In P oceedings o he Thi ie h Annual
ACM Symposium on Theo y o Compu ing, STOC ’98, pages 419–
428, New Yo k, NY, USA, May 1998. ACM. ISBN:0-89791-962-9.
doi:10.1145/276698.276854.
[BCL+06] BRUNETON, E.; COUPAYE,T.;LECLERCQ, M.; QUÉMA,V.;STE-
FANI, J.-B.: The FRACTAL componen model and i s suppo in
Ja a. So wa e: P ac ice and Expe ience, 36(11-12):1257–1284, 2006.
ISSN:1097-024X. doi:10.1002/spe.767.
Li e a u e Page 253
[BDL04] BEHRMANN, G.; DAVID, A.; LARSEN, K. G.: A u o ial on Uppaal.
In BERNARDO, M.; CORRADINI, F. (Eds.), Fo mal Me hods o he
Design o Real-Time Sys ems, numbe 3185 in Lec u e No es in Com-
pu e Science, pages 200–236. Sp inge Be lin Heidelbe g, Sep embe
2004. ISBN:978-3-540-23068-7. doi:10.1007/978-3-540-30080-9_7.
[BDL06a] BEHRMANN, G.; DAVID, A.; LARSEN,K.G.:A Tu o ial on UPPAAL
4.0. Depa men o Compu e Science, Aalbo g Uni e si y, Denma k,
No embe 2006.
[BDL+06b] BEHRMANN, G.; DAVID, A.; LARSEN, K. G.; PETTERSSON,P.;YI,
W.; HENDRIKS,M.:UPPAAL 4.0. In P oceedings o he 3 d In e -
na ional Con e ence on he Quan i a i e E alua ion o Sys ems, QEST
2006, pages 125–126, Los Alami os, CA, USA, Sep embe 2006. IEEE
Compu e Socie y. ISBN:0-7695-2665-9. doi:10.1109/QEST.2006.59.
[BDM+98] BOZGA, M.; DAWS, C.; MALER, O.; OLIVERO, A.; TRIPAKIS, S.;
YOVINE, S.: K onos: A model-checking ool o eal- ime sys ems.
In RAVN, A.; RISCHEL, H. (Eds.), Fo mal Techniques in Real-Time
and Faul -Tole an Sys ems, olume 1486 o Lec u e No es in Compu e
Science, pages 298–302. Sp inge Be lin Heidelbe g, 1998. ISBN:978-
3-540-65003-4. doi:10.1007/b b0055357.
[BDNG06] BARESI, L.; DINITTO, E.; GHEZZI, C.: Towa d open-wo ld so -
wa e: Issue and challenges. Compu e , 39(10):36 –43, Oc obe 2006.
ISSN:0018-9162. doi:10.1109/mc.2006.362.
[Bey01] BEYER, D.: E ficien eachabili y analysis and efinemen checking o
imed au oma a using BDDs. In MARGARIA,T.;MELHAM,T.F.
(Eds.), Co ec Ha dwa e Design and Ve ifica ion Me hods, olume
2144 o Lec u e No es in Compu e Science, pages 86–91. Sp inge
Be lin Heidelbe g, 2001. ISBN:978-3-540-42541-0. doi:10.1007/3-
540-44798-9_6.
[BFHP09] BORDE, E.; FEILER, P. H.; HAÏK, G.; PAUTET, L.: Model
d i en code gene a ion o c i ical and adap a i e embedded sys-
ems. SIGBED Re iew, 6:10:1–10:5, Oc obe 2009. ISSN:1551-3688.
doi:10.1145/1851340.1851352.
[BGH+07] BURMESTER, S.; GIESE, H.; HENKLER, S.; HIRSCH, M.; TICHY,
M.; GAMBUZZA, A.; MÜNCH, E.; VÖCKING, H.: Tool suppo o
de eloping ad anced mecha onic sys ems: In eg a ing he Fujaba Real-
Time Tool Sui e wi h CAMeL-View. In P oceedings o he 29 h In-
e na ional Con e ence on So wa e Enginee ing, ICSE 2007, pages
801–804. IEEE Compu e Socie y, May 2007. ISBN:0-7695-2828-7.
doi:10.1109/ICSE.2007.88.
Page 254
[BGH+13] BUREŠ,T.;GEROSTATHOPOULOS, I.; HNˇ
ETYNKA,P.;KEZNIKL, J.;
KIT, M.; PLÁŠIL, F.: DEECo: an ensemble-based componen sys-
em. In P oceedings o he 16 h In e na ional ACM Sigso symposium
on Componen -based so wa e enginee ing, CBSE ’13, pages 81–90,
New Yo k, NY, USA, June 2013. ACM. ISBN:978-1-4503-2122-8.
doi:10.1145/2465449.2465462.
[BGK+96] BENGTSSON, J.; GRIFFIOEN,D.W.O.;KRISTOFFERSEN, K. J.;
LARSEN, K. G.; LARSSON,F.;PETTERSSON,P.;YI, W.: Ve ifica ion
o an audio p o ocol wi h bus collision using UPPAAL. In ALUR, R.;
HENZINGER, T. A. (Eds.), Compu e Aided Ve ifica ion, olume 1102
o Lec u e No es in Compu e Science, pages 244–256. Sp inge Be lin
Heidelbe g, July 1996. ISBN:978-3-540-61474-6. doi:10.1007/3-540-
61474-5_73.
[BGN+10] BECKER, B.; GIESE, H.; NEUMANN, S.; SCHENCK, M.; TREF-
FER, A.: Model-based ex ension o AUTOSAR o a chi ec u al on-
line econfigu a ion. In GHOSH, S. (Ed.), Models in So wa e En-
ginee ing, olume 6002 o Lec u e No es in Compu e Science, pages
83–97. Sp inge Be lin / Heidelbe g, 2010. ISBN:978-3-642-12260-6.
doi:10.1007/978-3-642-12261-3_9.
[BGO06] BURMESTER, S.; GIESE, H.; OBERSCHELP, O.: Hyb id UML compo-
nen s o he design o complex sel -op imizing mecha onic sys ems. In
BRAZ, J.; ARAÚJO, H.; VIEIRA, A.; ENCARNAÇÃO, B. (Eds.), In o -
ma ics in Con ol, Au oma ion and Robo ics I, pages 281–288. Sp inge
Ne he lands, Ma ch 2006. ISBN:978-1-4020-4136-5. doi:10.1007/1-
4020-4543-3_34.
[BGP13] BOYER,F.;GRUBER, O.; POUS, D.: Robus econfigu a ions o com-
ponen assemblies. In P oceedings o he 2013 In e na ional Con e -
ence on So wa e Enginee ing, ICSE ’13, pages 13–22, Pisca away, NJ,
USA, May 2013. IEEE Compu e Socie y. ISBN:978-1-4673-3076-3.
doi:10.1109/ICSE.2013.6606547.
[BGS05] BURMESTER, S.; GIESE, H.; SCHÄFER, W.: Model-d i en a chi ec-
u e o ha d eal- ime sys ems: F om pla o m independen models
o code. In HARTMAN, A.; KREISCHE, D. (Eds.), P oceedings o
he Eu opean Con e ence on Model D i en A chi ec u e – Founda ions
and Applica ions (ECMDA-FA ’05), olume 3748 o Lec u e No es in
Compu e Science, pages 25–40. Sp inge , Be lin/Heidelbe g, No em-
be 2005. ISBN:978-3-540-30026-7. doi:10.1007/11581741_4.
[BGSH11] BRINK, C.; GREENYER, J.; SCHÄFER,W.;HAHN, M.: Simula-
ion on hyb idem Ve hal en in CAMeL-View. In GAUSEMEIER,
Li e a u e Page 255
J.; RAMMIG, F.-J.; SCHÄFER,W.;TRÄCHTLER, A. (Eds.), Wis-
senscha s o um In elligen e Technische Sys eme 2011, olume 294 o
HNI-Ve lagssch i en eihe. Heinz Nixdo Ins i u , Uni e si ä Pade -
bo n, May 2011. ISBN:978-3942647137.
[BGST05] BURMESTER, S.; GIESE, H.; SEIBEL, A.; TICHY, M.: Wo s -case
execu ion ime op imiza ion o s o y pa e ns o ha d eal- ime sys ems.
In P oceedings o he 3 d In e na ional Fujaba Days 2005, pages 71–
78, Sep embe 2005.
[BHG87] BERNSTEIN, P. A.; HADZILACOS,V.;GOODMAN,N.:Concu ency
Con ol and Reco e y in Da abase Sys ems. Addison Wesley, 1987.
ISBN:0-201-10715-5.
[BHR09] BENNOUR, B.; HENRIO, L.; RIVERA, M.: A econfigu a ion ame-
wo k o dis ibu ed componen s. In P oceedings o he 2009 ESEC/FSE
wo kshop on So wa e in eg a ion and e olu ion @ un ime, SINTER
’09, pages 49–56, New Yo k, NY, USA, 2009. ACM. ISBN:978-1-
60558-681-6. doi:10.1145/1596495.1596509.
[BIPM06] Bu eau In e na ional des Poids e Mesu esThe In e na ional Sys em o
Uni s (SI), 8 h edi ion, 2006.
[BK08] BAIER, C.; KATOEN, J.-P.: P inciples o Model Checking. MIT P ess,
Camb idge, MA, USA, 2008. ISBN:978-0-262-02649-9.
[BK11] BARTELS, B.; KLEINE, M.: A CSP-based amewo k o he specifi-
ca ion, e ifica ion, and implemen a ion o adap i e sys ems. In P o-
ceedings o he 6 h In e na ional Symposium on So wa e Enginee -
ing o Adap i e and Sel -Managing Sys ems, SEAMS ’11, pages 158–
167, New Yo k, NY, USA, 2011. ACM. ISBN:978-1-4503-0575-4.
doi:10.1145/1988008.1988030.
[BK13] BOJIC, I.; KUSEK, M.: Sel -synch oniza ion o noniden ical ma-
chines in machine- o-machine sys ems. In IEEE 7 h In e na-
ional Con e ence on Sel -Adap i e and Sel -O ganizing Sys ems,
SASO’13, pages 265–266. IEEE Compu e Socie y, Sep embe 2013.
doi:10.1109/saso.2013.39.
[BKPPT01] BOTTONI,P.;KOCH, M.; PARISI-PRESICCE,F.;TAENTZER,G.:A
isualiza ion o OCL using collabo a ions. In GOGOLLA, M.; KO-
BRYN, C. (Eds.), UML 2001 — The Unified Modeling Language. Mod-
eling Languages, Concep s, and Tools, olume 2185 o Lec u e No es in
Compu e Science, pages 257–271. Sp inge Be lin / Heidelbe g, Oc o-
be 2001. ISBN:978-3-540-42667-7. doi:10.1007/3-540-45441-1_20.
Page 262
[Es ] Es e el TechnologiesSCADE Sui e - P oduc Homepage. URL:
h p://www.es e el- echnologies.com/p oduc s/
scade-sui e/ [ci ed Ma ch 14, 2015].
[ETA] ETAS GmbHASCET So wa e-P oduk e. URL: h p://www.e as.
com/de/p oduc s/asce _so wa e_p oduc s.php [ci ed
Ma ch 14, 2015].
[EW92] ENDLER, M.; WEI, J.: P og amming gene ic dynamic econfigu a ions
o dis ibu ed applica ions. In In e na ional Wo kshop on Configu able
Dis ibu ed Sys ems, pages 68–79. IEEE, Ma ch 1992. ISBN:0-85296-
544-3.
[FCT08] FENG, L.; CHEN, D.; TÖRNGREN, M.: Sel configu a ion o de-
penden asks o dynamically econfigu able au omo i e embedded
sys ems. In 47 h IEEE Con e ence on Decision and Con ol, CDC
2008, pages 3737–3742, Decembe 2008. ISBN:978-1-4244-3123-6.
doi:10.1109/cdc.2008.4739195.
[FFH05] FISH, A.; FLOWER, J.; HOWSE, J.: The seman ics o aug-
men ed cons ain diag ams. Jou nal o Visual Languages &
Compu ing, 16(6):541 – 573, Decembe 2005. ISSN:1045-926X.
doi:10.1016/j.j lc.2005.03.001.
[FHTW05] FISH, A.; HOWSE, J.; TAENTZER, G.; WINKELMANN, J.: Two isu-
aliza ions o OCL: a compa ison. Technical Repo VMG.05.1, Uni e -
si y o B igh on, 2005.
[FLGD+11] FREHSE, G.; LEGUERNIC, C.; DONZÉ, A.; COTTON, S.; RAY, R.;
LEBELTEL, O.; RIPADO, R.; GIRARD, A.; DANG,T.;MALER,O.:
SpaceEx: Scalable e ifica ion o hyb id sys ems. In GOPALAKRISH-
NAN, G.; QADEER, S. (Eds.), Compu e Aided Ve ifica ion, olume
6806 o Lec u e No es in Compu e Science, pages 379–395. Sp inge
Be lin / Heidelbe g, 2011. ISBN:978-3-642-22109-5. doi:10.1007/978-
3-642-22110-1_30.
[FMB+09] FÜRST, S.; MÖSSINGER, J.; BUNZEL, S.; WEBER,T.;KIRSCHKE-
BILLER,F.;HEITKÄMPER,P.;KINKELIN, G.; NISHIKAWA, K.;
LANGE,K.: AUTOSAR-awo ldwide s anda d is on he oad. In
P oceedings o he 14 h In e na ional VDI Cong ess Elec onic Sys ems
o Vehicles 2009, 2009.
[FNTZ00] FISCHER,T.;NIERE, J.; TORUNSKI, L.; ZÜNDORF, A.: S o y dia-
g ams: A new g aph ew i e language based on he Unified Modeling
Language and Ja a. In EHRIG, H.; ENGELS, G.; KREOWSKI, H.-
J.; ROZENBERG, G. (Eds.), Selec ed pape s om he 6 h In e na ional
Wo kshop on Theo y and Applica ion o G aph T ans o ma ions (TAGT
Li e a u e Page 263
’98), No embe 16-20, 1998, Pade bo n, Ge many, olume 1764 o
Lec u e No es in Compu e Science, pages 296 – 309. Sp inge Be lin
/ Heidelbe g, 2000. ISBN:3-540-67203-6. doi:10.1007/978-3-540-
46464-8_21.
[F e05] FREHSE, G.: PHAVe : Algo i hmic e ifica ion o hyb id sys ems pas
HyTech. In MORARI, M.; THIELE, L. (Eds.), P oceedings o he Hy-
b id Sys ems 8 h In e na ional Wo kshop on Compu a ion and Con ol
(HSCC 2005), olume 3414 o Lec u e No es in Compu e Science,
pages 258–273. Sp inge Be lin Heidelbe g, Ma ch 2005. ISBN:3-540-
25108-1. doi:10.1007/978-3-540-31954-2_17.
[F i04] FRITZSON,P.:P inciples o Objec -O ien ed Modeling and Simula-
ion wi h Modelica 2.1. John Wiley & Sons, 1s edi ion, Ap il 2004.
ISBN:978-0471471639.
[GAOR07] GÜDEMANN, M.; ANGERER, A.; ORTMEIER,F.;REIF, W.: Mod-
eling o sel -adap i e sys ems wi h SCADE. In IEEE In e na ional
Symposium on Ci cui s and Sys ems, ISCAS 2007, pages 2922 –
2925. IEEE Compu e Socie y, May 2007. ISBN:1-4244-0920-9.
doi:10.1109/iscas.2007.377861.
[GB03] GIESE, H.; BURMESTER, S.: Real- ime s a echa seman ics. Tech-
nical Repo - i-03-239, So wa e Enginee ing G oup, Uni e si y o
Pade bo n, Pade bo n, Ge many, June 2003.
[GBD07] GEIGER, L.; BUCHMANN,T.;DOTOR, A.: EMF code gene a ion wi h
Fujaba. In P oceedings o he Fi h In e na ional Fujaba Days, Oc obe
2007.
[GBSO04] GIESE, H.; BURMESTER, S.; SCHÄFER,W.;OBERSCHELP, O.: Mod-
ula design and e ifica ion o componen -based mecha onic sys ems
wi h online- econfigu a ion. In P oceedings o he 12 h ACM SIG-
SOFT Founda ions o So wa e Enginee ing, FSE 2004, pages 179–188,
New Yo k, NY, USA, No embe 2004. ACM. ISBN:1-58113-855-5.
doi:10.1145/1029894.1029920.
[GCH+04] GARLAN, D.; CHENG, S.-W.; HUANG, A.-C.; SCHMERL, B.;
STEENKISTE, P.: Rainbow: a chi ec u e-based sel -adap a ion wi h
eusable in as uc u e. Compu e , 37(10):46–54, Oc obe 2004.
ISSN:0018-9162. doi:10.1109/mc.2004.175.
[GCW+02] GENSSLER,T.;CHRISTOPH, A.; WINTER, M.; NIERSTRASZ, O.;
DUCASSE, S.; WUYTS, R.; ARÉVALO, G.; SCHÖNHAGE, B.;
MÜLLER,P.;STICH, C.: Componen s o embedded so wa e: The
PECOS app oach. In P oceedings o he 2002 In e na ional Con e -
ence on Compile s, A chi ec u e, and Syn hesis o Embedded Sys ems,
Page 264
CASES ’02, pages 19–26, New Yo k, NY, USA, 2002. ACM. ISBN:1-
58113-575-0. doi:10.1145/581630.581634.
[GCZ08] GOLDSBY, H. J.; CHENG,B.H.C.;ZHANG, J.: AMOEBA-RT: Run-
ime e ifica ion o adap i e so wa e. In GIESE, H. (Ed.), Models in
So wa e Enginee ing, olume 5002 o Lec u e No es in Compu e Sci-
ence, pages 212–224. Sp inge Be lin Heidelbe g, 2008. ISBN:978-3-
540-69069-6. doi:10.1007/978-3-540-69073-3_23.
[Gei13] GEISMANN, J.: Codegene ie ung ü LEGO Minds o ms - Robo e .
Bachelo ’s hesis, Uni e si y o Pade bo n, Janua y 2013.
[Ge 13] GERKING, C.: T anspa en Uppaal-based e i ca ion o Mecha onic-
UML models. Mas e ’s hesis, Uni e si y o Pade bo n, May 2013.
[GFDK09] GAUSEMEIER, J.; FRANK, U.; DONOTH, J.; KAHL, S.: Specifica ion
echnique o he desc ip ion o sel -op imizing mecha onic sys ems.
Resea ch in Enginee ing Design, 20:201–223, 2009. ISSN:0934-9839.
doi:10.1007/s00163-008-0058-x.
[GHS09] GIESE, H.; HILDEBRANDT, S.; SEIBEL, A.: Imp o ed flexibili y and
scalabili y by in e p e ing s o y diag ams. In MARGARIA,T.;PAD-
BERG, J.; TAENTZER, G. (Eds.), P oceedings o he Eigh h In e na-
ional Wo kshop on G aph T ans o ma ion and Visual Modeling Tech-
niques (GT-VMT 2009), olume 18. Elec onic Communica ions o he
EASST, 2009.
[Gie03] GIESE, H.: A o mal calculus o he composi ional pa e n-based
design o co ec eal- ime sys ems. Technical Repo - i-03-
240, Leh s uhl ü So wa e echnik, Uni e si ä Pade bo n, Pade bo n,
Deu schland, July 2003.
[GJSH12] GHAFARI, M.; JAMSHIDI,P.;SHAHBAZI, S.; HAGHIGHI, H.: An a -
chi ec u al app oach o ensu e globally consis en dynamic econfigu a-
ion o componen -based sys ems. In P oceedings o he 15 h ACM SIG-
SOFT symposium on Componen Based So wa e Enginee ing, CBSE
’12, pages 177–182, New Yo k, NY, USA, June 2012. ACM. ISBN:978-
1-4503-1345-2. doi:10.1145/2304736.2304765.
[GKP08] GAUSEMEIER, J.; KAHL, S.; POOK, S.: F om mecha onics o sel -
op imizing sys ems. In Sel -op imizing Mecha onic Sys ems: Design
he Fu u e, 7 h In e na ional Heinz Nixdo Symposium, olume 223.
HNI Ve lagssch i en eihe, Pade bo n, Feb ua y 2008.
[GMW00] GARLAN, D.; MONROE,R.T.;WILE, D.: Acme: a chi ec u al de-
sc ip ion o componen -based sys ems. In LEAVENS,G.T.;SITARA-
MAN, M. (Eds.), Founda ions o componen -based sys ems, pages 47–
Li e a u e Page 265
67. Camb idge Uni e si y P ess, New Yo k, NY, USA, Ma ch 2000.
ISBN:0-521-77164-1.
[GOS09] GUARINO, N.; OBERLE, D.; STAAB, S.: Wha is an on ology? In
STAAB, S.; STUDER, R. (Eds.), Handbook on On ologies, In e na-
ional Handbooks on In o ma ion Sys ems, pages 1–17. Sp inge Be lin
Heidelbe g, 2009. ISBN:978-3-540-70999-2. doi:10.1007/978-3-540-
92673-3_0.
[Gos14] GOSCHIN, S.: Syn hesis o ex ended hie a chical eal- ime beha io .
Mas e ’s hesis, Uni e si y o Pade bo n, Feb ua y 2014.
[GPVW96] GERTH, R.; PELED, D.; VARDI,M.Y.;WOLPER, P.: Simple on- he-
fly au oma ic e ifica ion o linea empo al logic. In P oceedings o
he Fi een h IFIP WG6.1 In e na ional Symposium on P o ocol Spec-
ifica ion, Tes ing and Ve ifica ion XV, pages 3–18, London, UK, 1996.
Chapman & Hall, L d. ISBN:0-412-71620-8.
[G a] G aph iz Open Sou ce TeamG aph iz - G aph Visualiza ion So wa e.
URL: h p://www.g aph iz.o g/ [ci ed Ma ch 14, 2015].
[G e11] GREENYER,J.:Scena io-based Design o Mecha onic Sys ems. PhD
hesis, Uni e si y o Pade bo n, Oc obe 2011.
[G o01] GROUP,O.M.:OMG Unified Modeling Language Specifica ion 1.4,
Sep embe 2001. Documen o mal/2001-09-67. URL: h p://www.
omg.o g/spec/UML/1.4/.
[G o05] GROUP,O.M.:Unified Modeling Language (UML) 2.0 Supe s uc u e
Specifica ion, July 2005. Documen o mal/2005-07-04. URL: h p:
//www.omg.o g/spec/UML/2.0/.
[G o09] GRONBACK,R.C.:Eclipse Modeling P ojec – A Domain-Specific
Language (DSL) Toolki . The Eclipse Se ies. Addison-Wesley, 1s edi-
ion, Ma ch 2009. ISBN:978-0321534071.
[G o10] GROUP,O.M.:OMG Sys ems Modeling Language (OMG SysML),
June 2010. Documen o mal/10-06-02. URL: h p://www.sysml.
o g/specs/.
[G o11a] GROUP,O.M.:Common Objec Reques B oke A chi ec u e (CORBA)
Specifica ion - Pa 3: CORBA Componen Model, No embe 2011.
Documen o mal/2011-11-03. URL: h p://www.omg.o g/spec/
CORBA/3.2/.
[G o11b] GROUP,O.M.:Que y/View/T ans o ma ion (QVT) 1.1, Janua y 2011.
Documen o mal/2011-01-01. URL: h p://www.omg.o g/spec/
QVT/1.1/.
Page 266
[G o11c] GROUP,O.M.:Unified Modeling Language (UML) 2.4.1 Supe s uc-
u e Specifica ion, Augus 2011. Documen o mal/2011-08-06.
[G o12] GROUP,O.M.:Objec Cons ain Language (OCL) 2.3.1, Janua y
2012. Documen o mal/2012-01-01. URL: h p://www.omg.o g/
spec/OCL/2.3.1/.
[G o14] GROUP,O.M.:Model D i en A chi ec u e (MDA) – MDA Guide e .
2.0, June 2014. Documen – o msc/14-06-01. URL: h p://www.
omg.o g/cgi-bin/doc?o msc/14-06-01.
[GRS09] GAUSEMEIER, J.; RAMMIG, F.-J.; SCHÄFER,W.
(Eds.)Selbs op imie ende Sys eme des Maschinenbaus – Defini io-
nen, Anwendungen, Konzep e, olume 234. HNI-Ve lagssch i en eihe,
Pade bo n, 1s edi ion, Janua y 2009. ISBN:978-3-939350-53-8.
[GRS14] GAUSEMEIER, J.; RAMMIG, F.-J.; SCHÄFER, W. (Eds.)Design
Me hodology o In elligen Technical Sys ems. Lec u e No es in Me-
chanical Enginee ing. Sp inge , 2014. ISBN:978-3-642-45434-9.
[GS04] GARLAN, D.; SCHMERL, B.: Using a chi ec u al models a un ime:
Resea ch challenges. In OQUENDO,F.;WARBOYS, B. C.; MORRI-
SON, R. (Eds.), So wa e A chi ec u e, olume 3047 o Lec u e No es in
Compu e Science, pages 200–205. Sp inge Be lin Heidelbe g, 2004.
ISBN:978-3-540-22000-8. doi:10.1007/978-3-540-24769-2_15.
[GS13] GIESE, H.; SCHÄFER, W.: Model-d i en de elopmen o sa e sel -
op imizing mecha onic sys ems wi h Mecha onicUML. In CÁMARA,
J.; DE LEMOS, R.; GHEZZI, C.; LOPES, A. (Eds.), Assu ances o
Sel -Adap i e Sys ems, olume 7740 o Lec u e No es in Compu e
Science, pages 152–186. Sp inge Be lin Heidelbe g, Janua y 2013.
ISBN:978-3-642-36248-4. doi:10.1007/978-3-642-36249-1_6.
[GSB+08] GOLDSBY, H. J.; SAWYER,P.;BENCOMO, N.; CHENG,B.H.C.;
HUGHES, D.: Goal-based modeling o dynamically adap i e sys em e-
qui emen s. In 15 h Annual IEEE In e na ional Con e ence and Wo k-
shop on he Enginee ing o Compu e Based Sys ems, ECBS 2008.,
pages 36–45. IEEE Compu e Socie y, Ma ch 2008. ISBN:0-7695-
3141-5. doi:10.1109/ecbs.2008.22.
[GSG+09] GAUSEMEIER, J.; SCHÄFER,W.;GREENYER, J.; KAHL, S.; POOK,
S.; RIEKE, J.: Managemen o c oss-domain model consis ency du ing
he de elopmen o ad anced mecha onic sys ems. In BERGENDAHL,
M. N.; GRIMHEDEN, M.; LEIFER, L.; SKOGSTAD,P.;LINDEMANN,
U. (Eds.), P oceedings o he 17 h In e na ional Con e ence on Engin-
ee ing Design, olume 6, Design Me hods and Tools o ICED’09, pages
1–12. Design Socie y, Augus 2009. ISBN:978-1-904670-10-0.
Li e a u e Page 267
[GSR05] GEIGER, L.; SCHNEIDER, C.; RECKORD, C.: Templa e- and model-
based code gene a ion o MDA- ools. In GIESE, H.; ZÜNDORF,A.
(Eds.), P oceedings o he Thi d In e na ional Fujaba Days 2005, ol-
ume - i-06-275 o Technical Repo , pages 1–6. Uni e si y o Pade -
bo n, Sep embe 2005.
[GTB+03] GIESE, H.; TICHY, M.; BURMESTER, S.; SCHÄFER,W.;FLAKE,
S.: Towa ds he composi ional e ifica ion o eal- ime UML designs.
In P oceedings o he 9 h Eu opean So wa e Enginee ing Con e ence
Held Join ly wi h 11 h ACM SIGSOFT In e na ional Symposium on
Founda ions o So wa e Enginee ing, ESEC/FSE’03, pages 38–47,
New Yo k, NY, USA, Sep embe 2003. ACM. ISBN:1-58113-743-5.
doi:10.1145/940071.940078.
[GTS14] GAUSEMEIER, J.; TRÄCHTLER, A.; SCHÄFER, W. (Eds.)Seman ische
Technologien im En wu mecha onische Sys eme: E ek i e Aus-
ausch on Lösungswissen in B anchenwe schöp ungske en. Ca l
Hanse Ve lag, München, June 2014. ISBN:978-3446436305.
[GV14] GAUSEMEIER, J.; VASSHOLZ, M.: Design me hodology o sel -
op imizing sys ems. In GAUSEMEIER, J.; RAMMIG, F.-J.; SCHÄFER,
W. (Eds.), Design Me hodology o In elligen Technical Sys ems, chap-
e 3.1, pages 66–69. Sp inge -Ve lag, Heidelbe g, Ge many, Janua y
2014. ISBN:978-3-642-45434-9.
[Ham05] HAMON, G.: A deno a ional seman ics o S a eflow. In P oceedings
o he 5 h ACM in e na ional con e ence on Embedded so wa e, EM-
SOFT ’05, pages 164–172, New Yo k, NY, USA, 2005. ACM. ISBN:1-
59593-091-4. doi:10.1145/1086228.1086260.
[HB07] HNˇ
ETYNKA,P.;BUREŠ, T.: Ad anced ea u es o hie a chical com-
ponen models. In ZENDULKA, J. (Ed.), P oceedings o he 10 h In e -
na ional Con e ence on In o ma ion Sys em Implemen a ion and Mod-
eling, ISIM’07, pages 1–8. CEUR-WS.o g Vol-252, Ap il 2007.
[HBRV10] HEGEDÜS, Á.; BERGMANN, G.; RATH, I.; VARRÓ, D.: Back-
anno a ion o simula ion aces wi h change-d i en model ans o -
ma ions. In 8 h IEEE In e na ional Con e ence on So wa e En-
ginee ing and Fo mal Me hods, SEFM’10, pages 145–155. IEEE
Compu e Socie y, Sep embe 2010. ISBN:978-1-4244-8289-4.
doi:10.1109/se m.2010.28.
[HC01] HEINEMAN,G.T.;COUNCILL, W. T. (Eds.)Componen -based So -
wa e Enginee ing: Pu ing he Pieces Toge he . Addison-Wesley Long-
man Publishing Co., Inc., Bos on, MA, USA, 2001. ISBN:0-201-
70485-4.
Page 268
[HCH12] HANG,Y.;CARLSON, J.; HANSSON, H.: Towa ds mode swi ch han-
dling in componen -based mul i-mode sys ems. In P oceedings o he
15 h ACM SIGSOFT Symposium on Componen Based So wa e Engin-
ee ing, CBSE’12, pages 183–188, New Yo k, NY, USA, June 2012.
ACM. ISBN:978-1-4503-1345-2. doi:10.1145/2304736.2304766.
[Hen96] HENZINGER, T. A.: The heo y o hyb id au oma a. In P oceedings o
he 11 h Annual IEEE Symposium on Logic in Compu e Science, LICS
’96, pages 278–292, Los Alami os, CA, USA, July 1996. IEEE Com-
pu e Socie y. ISBN:0-8186-7463-6. doi:10.1109/lics.1996.561342.
[Hen12] HENKLER,S.:Ein komponen enbasie e , modellge iebene So wa-
een wicklungsansa z ü e ne z e, mecha onische Sys eme. PhD he-
sis, Uni e si y o Pade bo n, Wa bu ge S . 100, Pade bo n, Ge many,
June 2012.
[HESV91] HSU, A.; ESKAFI,F.;SACHS, S.; VARAIYA, P.: Design o pla oon
maneu e p o ocols o IVHS. Technical Repo UCB-ITS-PRR-91-6,
UC Be keley: Cali o nia Pa ne s o Ad anced T ansi and Highways
(PATH), Ap il 1991. URL: h p://eschola ship.o g/uc/i em/
89c6p0cn.
[HH13] HANG,Y.;HANSSON, H.: Handling mul iple mode swi ch scena ios
in componen -based mul i-mode sys ems. In P oceedings o he 20 h
Asia-Pacific So wa e Enginee ing Con e ence, olume 1 o APSEC’13,
pages 404–413. IEEE Compu e Socie y, Decembe 2013. ISBN:978-
1-4799-2143-0. doi:10.1109/apsec.2013.61.
[HHG08] HIRSCH, M.; HENKLER, S.; GIESE, H.: Modeling collabo a ions
wi h dynamic s uc u al adap a ion in Mecha onic UML. In P o-
ceedings o he 2008 in e na ional wo kshop on So wa e enginee ing
o adap i e and sel -managing sys ems, SEAMS ’08, pages 33–40,
New Yo k, NY, USA, May 2008. ACM. ISBN:978-1-60558-037-1.
doi:10.1145/1370018.1370026.
[HHMWT00] HENZINGER,T.;HOROWITZ, B.; MAJUMDAR, R.; WONG-TOI,H.:
Beyond HyTech: Hyb id sys ems analysis using in e al nume ical
me hods. In LYNCH, N.; KROGH, B. (Eds.), Hyb id Sys ems: Compu-
a ion and Con ol, olume 1790 o Lec u e No es in Compu e Science,
pages 130–144. Sp inge Be lin / Heidelbe g, Ma ch 2000. ISBN:978-
3-540-67259-3. doi:10.1007/3-540-46430-1_14.
[HHR09] HARHURIN, A.; HARTMANN, J.; RATIU, D.: Mo i a ion and o mal
ounda ions o a comp ehensi e modeling heo y o embedded sys-
ems. Technical Repo TUM-I0924, Ins i u ü In o ma ik, Technische
Uni e si ä München, Sep embe 2009.
Li e a u e Page 269
[HHWT97] HENZINGER, T. A.; HO, P.-H.; WONG-TOI, H.: HYTECH: a model
checke o hyb id sys ems. In e na ional Jou nal on So wa e Tools o
Technology T ans e (STTT), 1(1-2):110–122, 1997. ISSN:1433-2779.
doi:10.1007/s100090050008.
[HIM98] HIRSCH, D.; INVERARDI,P.;MONTANARI, U.: G aph g amma s and
cons ain sol ing o so wa e a chi ec u e s yles. In P oceedings o
he hi d in e na ional wo kshop on So wa e a chi ec u e, ISAW ’98,
pages 69–72, New Yo k, NY, USA, 1998. ACM. ISBN:1-58113-081-3.
doi:10.1145/288408.288426.
[Hi 08] HIRSCH,M.:Modell-basie e Ve ifika ion on e ne z en mecha on-
ischen Sys emen. PhD hesis, Uni e si y o Pade bo n, Wa bu ge S .
100, Pade bo n, Ge many, Sep embe 2008.
[HKMU06] HIRSCH, D.; KRAMER, J.; MAGEE, J.; UCHITEL, S.: Modes o so -
wa e a chi ec u es. In GRUHN,V.;OQUENDO, F. (Eds.), So wa e A -
chi ec u e, olume 4344 o Lec u e No es in Compu e Science, pages
113–126. Sp inge Be lin Heidelbe g, 2006. ISBN:978-3-540-69271-3.
doi:10.1007/11966104_9.
[HKPV98] HENZINGER, T. A.; KOPKE,P.W.;PURI, A.; VARAIYA,P.:
Wha ’s decidable abou hyb id au oma a? Jou nal o Compu e
and Sys em Sciences, 57(1):94 – 124, 1998. ISSN:0022-0000.
doi:10.1006/jcss.1998.1581.
[HM03] HAREL, D.; MARELLY,R.:Come, Le ’s Play: Scena io-Based P o-
g amming Using LSC’s and he Play-Engine. Sp inge -Ve lag New
Yo k, Secaucus, NJ, USA, 2003. ISBN:3540007873.
[HM08a] HAREL, D.; MAOZ, S.: Asse and nega e e isi ed: Modal seman ics
o UML sequence diag ams. So wa e and Sys em Modeling, 7(2):237–
252, May 2008. ISSN:1619-1366. doi:10.1007/s10270-007-0054-z.
[HMTN+08] HÄNNINEN, K.; MÄKI-TURJA, J.; NOLIN, M.; LINDBERG, M.;
LUNDBÄCK, J.; LUNDBÄCK, K.-L.: The Rubus componen model
o esou ce cons ained eal- ime sys ems. In 3 d IEEE In e na ional
Symposium on Indus ial Embedded Sys ems, SIES 2008, pages 177–
183. IEEE Compu e Socie y, June 2008. ISBN:978-1-4244-1994-4.
doi:10.1109/SIES.2008.4577697.
[HNSY94] HENZINGER, T. A.; NICOLLIN, X.; SIFAKIS, J.; YOVINE,
S.: Symbolic model checking o eal- ime sys ems. In o ma ion
and Compu a ion, 111(2):193–244, June 1994. ISSN:0890-5401.
doi:10.1006/inco.1994.1045.
Page 270
[Hoa85] HOARE,C.A.R.: Communica ing Sequen ial P ocesses. Se ies
in Compu e Science. P en ice-Hall In e na ional, 1985. ISBN:978-
0131532717.
[HOG04] HESTERMEYER,T.;OBERSCHELP, O.; GIESE, H.: S uc u ed in-
o ma ion p ocessing o sel -op imizing mecha onic sys ems. In
ARAÚJO, H.; VIEIRA, A.; BRAZ, J.; ENCARNAÇÃO, B.; CARVALHO,
M. (Eds.), P oceedings o 1s In e na ional Con e ence on In o ma ics
in Con ol, Au oma ion and Robo ics, ICINCO 2004, pages 230–237.
INSTICC P ess, Augus 2004.
[HP06] HNˇ
ETYNKA,P.;PLÁŠIL, F.: Dynamic econfigu a ion and access o
se ices in hie a chical componen models. In GORTON, I.; HEINE-
MAN, G.; CRNKOVI ´
C, I.; SCHMIDT, H.; STAFFORD, J.; SZYPER-
SKI, C.; WALLNAU, K. (Eds.), Componen -Based So wa e Enginee -
ing, olume 4063 o Lec u e No es in Compu e Science, pages 352–
359. Sp inge Be lin / Heidelbe g, 2006. ISBN:978-3-540-35628-8.
doi:10.1007/11783565_27.
[HPB+10] HOŠEK,P.;POP,T.;BUREŠ,T.;HNˇ
ETYNKA,P.;MALOHLAVA,M.:
Compa ison o componen amewo ks o eal- ime embedded sys-
ems. In GRUNSKE, L.; REUSSNER, R.; PLÁŠIL, F. (Eds.), Componen
Based So wa e Enginee ing, olume 6092 o Lec u e No es in Compu e
Science, pages 21–36. Sp inge , Be lin/Heidelbe g, 2010. ISBN:978-3-
642-13237-7. doi:10.1007/978-3-642-13238-4_2.
[HQCH13] HANG,Y.;QIN, H.; CARLSON, J.; HANSSON, H.: Mode swi ch han-
dling o he P oCom componen model. In P oceedings o he 16 h
In e na ional ACM Sigso symposium on Componen -based so wa e
enginee ing, CBSE ’13, pages 13–22, New Yo k, NY, USA, June 2013.
ACM. ISBN:978-1-4503-2122-8. doi:10.1145/2465449.2465451.
[HR04] HUTH, M.; RYAN,M.:Logic in Compu e Science: Modelling and
Reasoning abou Sys ems. Camb idge Uni e si y P ess, Camb idge,
UK, 2nd edi ion, 2004. ISBN:978-0-521-54310-1.
[HR07] HAMON, G.; RUSHBY, J.: An ope a ional seman ics o S a eflow. In-
e na ional Jou nal on So wa e Tools o Technology T ans e (STTT),
9(5):447–456, July 2007. ISSN:1433-2779. doi:10.1007/s10009-007-
0049-7.
[HTS+08a] HENKE, C.; TICHY, M.; SCHNEIDER,T.;BÖCKER, J.; SCHÄFER,
W.: O ganiza ion and con ol o au onomous ailway con oys. In P o-
ceedings o he 9 h In e na ional Symposium on Ad anced Vehicle Con-
ol, AVEC’08, pages 318–323, Oc obe 2008.
Li e a u e Page 271
[HTS+08b] HENKE, C.; TICHY, M.; SCHNEIDER,T.;BÖCKER, J.; SCHÄFER,
W.: Sys em a chi ec u e and isk managemen o au onomous ail-
way con oys. In P oceedings o he 2nd Annual IEEE In e na ional
Sys ems Con e ence,, pages 1–8. IEEE Compu e Socie y, Ap il 2008.
ISBN:978-1-4244-2149-7. doi:10.1109/SYSTEMS.2008.4518986.
[HZ14] HÖLSCHER, C.; ZIMMER, D.: In elligen d i e module (iDM). In
GAUSEMEIER, J.; RAMMIG, F.-J.; SCHÄFER, W. (Eds.), Design
Me hodology o In elligen Technical Sys ems, chap e 2.1.2, pages 33–
36. Sp inge , Heidelbe g, Ge many, Janua y 2014.
[IBM06] IBM: An a chi ec u al bluep in o au onomic compu ing. Au onomic
compu ing whi e pape , IBM, June 2006.
[IEC96] IEC: G aphical symbols o diag ams. IEC 60617, 1996.
[IEC10] IEC: Func ional sa e y o elec ical/elec onic/p og ammable elec onic
sa e y- ela ed sys ems. IEC 61508 Edi ion 2.0, Ap il 2010.
[IEE08] IEEE: IEEE s anda d o a p ecision clock synch oniza ion p o ocol
o ne wo ked measu emen and con ol sys ems. IEEE S d 1588-
2008 (Re ision o IEEE S d 1588-2002), pages c1–269, July 2008.
doi:10.1109/ieees d.2008.4579760.
[IETF81] In e ne Enginee ing Task Fo ce (IETF)RFC793 - T ansmission Con ol
P o ocol, Sep embe 1981. URL: h p:// ools.ie .o g/h ml/
c793.
[ISO10] ISO: Sys ems and so wa e enginee ing – ocabula y.
ISO/IEC/IEEE 24765:2010(E), pages 1 –418, Decembe 2010.
doi:10.1109/ieees d.2010.5733835.
[ISO11a] ISO: Road ehicles – unc ional sa e y. ISO26262:2011, No embe
2011.
[IUH11] ISHII, D.; UEDA, K.; HOSOBE, H.: An in e al-based SAT modulo
ODE sol e o model checking nonlinea hyb id sys ems. In e na ional
Jou nal on So wa e Tools o Technology T ans e , 13(5):449–461, Oc-
obe 2011. ISSN:1433-2779. doi:10.1007/s10009-011-0193-y.
[IW95] INVERARDI,P.;WOLF, A. L.: Fo mal specifica ion and analysis
o so wa e a chi ec u es using he chemical abs ac machine model.
IEEE T ansac ions on So wa e Enginee ing, 21(4):373–386, Ap il
1995. ISSN:0098-5589. doi:10.1109/32.385973.
[IW14] IFTIKHAR, M. U.; WEYNS, D.: Assu ing sys em goals unde un-
ce ain y wi h ac i e o mal models o sel -adap a ion. In Com-
panion P oceedings o he 36 h In e na ional Con e ence on So -
wa e Enginee ing, ICSE Companion 2014, pages 604–605, New
Page 278
[NNSS07] NARTEN,T.;NORDMARK, E.; SIMPSON, W. A.; SOLIMAN,H.:
RFC4861 - Neighbo Disco e y o IP e sion 6 (IP 6). Ne wo k
Wo king G oup, Sep embe 2007. URL: h p:// ools.ie .o g/
h ml/ c4861.
[OHY11] OH, J.; HARMAN, M.; YOO, S.: T ansi ion co e age es ing o
Simulink/S a eflow models using messy gene ic algo i hms. In P oceed-
ings o he 13 h Annual Con e ence on Gene ic and E olu iona y Com-
pu a ion, GECCO ’11, pages 1851–1858, New Yo k, NY, USA, 2011.
ACM. ISBN:978-1-4503-0557-0. doi:10.1145/2001576.2001825.
[OMT98] OREIZY,P.;MEDVIDOVI ´
C, N.; TAYLOR, R. N.: A chi ec u e-
based un ime so wa e e olu ion. In P oceedings o he 20 h in e -
na ional con e ence on So wa e enginee ing, ICSE ’98, pages 177–
186. IEEE Compu e Socie y, Ap il 1998. ISBN:0-8186-8368-6.
doi:10.1109/ICSE.1998.671114.
[OMT+08] OSMIC, S.; MÜNCH, E.; TRÄCHTLER, A.; HENKLER, S.; SCHÄFER,
W.; GIESE, H.; HIRSCH, M.: Sa e online- econfigu a ion o sel -
op imizing mecha onic sys ems. In GAUSEMEIER, J.; RAMMIG, F. J.;
SCHÄFER, W. (Eds.), Selbs op imie ende mecha onische Sys eme: Die
Zukun ges al en. 7. In e na ionales Heinz Nixdo Symposium ü in-
dus ielle In o ma ions echnik, pages 411–426, Feb ua y 2008.
[O a13] ORACLE:JSR 345: En e p ise Ja aBeansTM, Ve sion 3.2,
EJB Co e Con ac s and Requi emen s, Ap il 2013. URL:
h p://download.o acle.com/o n-pub/jcp/ejb-3_
2- -e al-spec/ejb-3_2-co e- -spec.pd [ci ed Ma ch 14,
2015].
[PBKS07] PRETSCHNER, A.; BROY, M.; KRÜGER, I. H.; STAUNER, T.: So -
wa e enginee ing o au omo i e sys ems: A oadmap. In 2007 Fu-
u e o So wa e Enginee ing, FOSE ’07, pages 55–71, Washing-
on, DC, USA, 2007. IEEE Compu e Socie y. ISBN:0-7695-2829-5.
doi:10.1109/ ose.2007.22.
[PDM+14] POHLMANN, U.; DZIWOK, S.; MEYER, M.; TICHY, M.; THIELE,
S.: A Modelica coo dina ion pa e n lib a y o cybe -physical sys-
ems. In P oceedings o he 7 h In e na ional ICST Con e ence on
Simula ion Tools and Techniques, SIMUTools’14, pages 76–85, B us-
sels, Belgium, Ma ch 2014. ICST (Ins i u e o Compu e Sciences,
Social-In o ma ics and Telecommunica ions Enginee ing). ISBN:978-
1-63190-007-5. doi:10.4108/ics .simu ools.2014.254640.
[PDS+12] POHLMANN, U.; DZIWOK, S.; SUCK, J.; WOLF, B.; LOH, C. C.;
TICHY, M.: A Modelica lib a y o eal- ime coo dina ion mod-
eling. In P oceedings o he 9 h In e na ional MODELICA Con-
Li e a u e Page 279
e ence, pages 365–374. DLR - Robo ics and Mecha onics Cen-
e , Modelica Associa ion, Linköping Uni e si y Elec onic P ess,
Linköpings uni e si e , Sep embe 2012. ISBN:978-91-7519-826-2.
doi:10.3384/ecp12076365.
[Pea84] PEARL,J.:Heu is ics: in elligen sea ch s a egies o compu e p ob-
lem sol ing. Addison-Wesley Longman Publishing Co., Inc., Bos on,
MA, USA, 1984. ISBN:0-201-05594-5.
[PHMG14] POHLMANN, U.; HOLTMANN, J.; MEYER, M.; GERKING, C.: Gen-
e a ing Modelica models om so wa e specifica ions o he simula-
ion o cybe -physical sys ems. In P oceedings o he 40 h Eu omi-
c o Con e ence on So wa e Enginee ing and Ad anced Applica ions,
SEAA ’14, pages 191–198. IEEE Compu e Socie y, Augus 2014.
doi:10.1109/SEAA.2014.18.
[PKH+11] POP,T.;KEZNIKL, J.; HOŠEK,P.;MALOHLAVA, M.; BUREŠ,
T.; HNˇ
ETYNKA, P.: In oducing suppo o embedded and eal-
ime de ices in o exis ing hie a chical componen sys em: Lessons
lea ned. In 9 h In e na ional Con e ence on So wa e Enginee ing
Resea ch, Managemen and Applica ions, SERA’11, pages 3 –11.
IEEE Compu e Socie y, Augus 2011. ISBN:978-1-4577-1028-5.
doi:10.1109/se a.2011.14.
[PKP07] PAIZ, C.; KELTELHOIT, B.; PORRMANN, M.: A design amewo k o
FPGA-based dynamically econfigu able digi al con olle s. In IEEE
In e na ional Symposium on Ci cui s and Sys ems, ISCAS 2007, pages
3708–3711. IEEE Compu e Socie y, May 2007. ISBN:1-4244-0920-9.
doi:10.1109/iscas.2007.378648.
[PLM12] PANZICA LAMANNA, V.: Local dynamic upda e o componen -based
dis ibu ed sys ems. In P oceedings o he 15 h ACM SIGSOFT sym-
posium on Componen Based So wa e Enginee ing, CBSE ’12, pages
167–176, New Yo k, NY, USA, 2012. ACM. ISBN:978-1-4503-1345-2.
doi:10.1145/2304736.2304764.
[Plu82] PLUMMER,D.C.:RFC826 - An E he ne Add ess Resolu ion P o o-
col. Ne wo k Wo king G oup, No embe 1982. URL: h p:// ools.
ie .o g/h ml/ c826.
[Plu06] PLUMMER, A. R.: Model-in- he-loop es ing. P oceedings o he
Ins i u ion o Mechanical Enginee s, Pa I: Jou nal o Sys ems and
Con ol Enginee ing, 220(3):183–199, May 2006. ISSN:0959-6518.
doi:10.1243/09596518jsce207.
[PMDB14] POHLMANN, U.; MEYER, M.; DANN, A.; BRINK, C.: Viewpoin s
and iews in ha dwa e pla o m modeling o sa e deploymen . In
Page 280
P oceedings o he 2nd Wo kshop on View-Based, Aspec -O ien ed
and O hog aphic So wa e Modelling, VAO ’14, pages 23:23–23:30,
New Yo k, NY, USA, July 2014. ACM. ISBN:978-1-4503-2900-2.
doi:10.1145/2631675.2631682.
[Pnu77] PNUELI, A.: The empo al logic o p og ams. In P oceedings
o he 18 h Annual Symposium on Founda ions o Compu e Sci-
ence, pages 46–57. IEEE Compu e Socie y P ess, Oc obe 1977.
doi:10.1109/SFCS.1977.32.
[Poh13] POHLMANN, U.: Sa e deploymen o econfigu able cybe -physical
sys ems. In P oceedings o he 18 h In e na ional Doc o al Sym-
posium on Componen s and A chi ec u e, WCOP ’13, pages 31–36,
New Yo k, NY, USA, June 2013. ACM. ISBN:978-1-4503-2125-9.
doi:10.1145/2465498.2465503.
[Pos80] POSTEL,J.: Use Da ag am P o ocol. In e ne Enginee ing Task
Fo ce (IETF), Augus 1980. URL: h p:// ools.ie .o g/h ml/
c768.
[PPO+12] POP,T.;PLÁŠIL,F.;OUTLY, M.; MALOHLAVA, M.; BUREŠ,T.:
P ope y ne wo ks allowing o acle-based mode-change p opaga ion in
hie a chical componen s. In P oceedings o he 15 h ACM SIGSOFT
Symposium on Componen Based So wa e Enginee ing, CBSE’12,
pages 93–102, New Yo k, NY, USA, June 2012. ACM. ISBN:978-1-
4503-1345-2. doi:10.1145/2304736.2304753.
[P i13] PRIESTERJAHN,C.:Analyzing Sel -healing Ope a ions in Mecha onic
Sys ems. PhD hesis, Uni e si y o Pade bo n, Wa bu ge S . 100,
Pade bo n, Ge many, Augus 2013.
[PSR+12] POHLMANN, U.; SCHÄFER,W.;REDDEHASE, H.; RÖCKEMANN,
J.; WAGNER, R.: Gene a ing unc ional mockup uni s om so wa e
specifica ions. In P oceedings o he 9 h In e na ional MODELICA
Con e ence, pages 765–774. Linköping Uni e si y Elec onic P ess,
Linköpings uni e si e , Sep embe 2012. ISBN:978-91-7519-826-2.
doi:10.3384/ecp12076765.
[PST13] PRIESTERJAHN, C.; STEENKEN, D.; TICHY, M.: Timed haza d
analysis o sel -healing sys ems. In CÁMARA, J.; DE LEMOS, R.;
GHEZZI, C.; LOPES, A. (Eds.), Assu ances o Sel -Adap i e Sys ems,
olume 7740 o Lec u e No es in Compu e Science, pages 112–151.
Sp inge Be lin Heidelbe g, Janua y 2013. ISBN:978-3-642-36248-4.
doi:10.1007/978-3-642-36249-1_5.
[PTD+14] POHLMANN, U.; TRSEK, H.; DÜRKOP, L.; DZIWOK, S.; OESTER-
SÖTEBIER, F.: Applica ion o an in elligen ne wo k a chi ec u e on
Li e a u e Page 281
a coope a i e cybe -physical sys em: An expe ience epo . In P o-
ceedings o he 19 h IEEE In e na ional Con e ence on Eme ging Tech-
nology and Fac o y Au oma ion, ETFA’14, pages 1–6. IEEE Compu e
Socie y, Sep embe 2014. doi:10.1109/ETFA.2014.7005358.
[PTH+10] PRIESTERJAHN, C.; TICHY, M.; HENKLER, S.; HIRSCH, M.;
SCHÄFER, W.: Fujaba4Eclipse Real-Time Tool Sui e. In GIESE, H.;
KARSAI, G.; LEE, E. A.; RUMPE, B.; SCHÄTZ, B. (Eds.), Model-
Based Enginee ing o Embedded Real-Time Sys ems (MBEERTS), ol-
ume 6100 o Lec u e No es in Compu e Science, chap e 12, pages
309–315. Sp inge Be lin Heidelbe g, 2010. ISBN:978-3-642-16276-
3. doi:10.1007/978-3-642-16277-0_12.
[PV14] PANUNZIO, M.; VARDANEGA, T.: A componen -based p ocess wi h
sepa a ion o conce ns o he de elopmen o embedded eal- ime so -
wa e sys ems. Jou nal o Sys ems and So wa e, 96:105 – 121, Oc obe
2014. ISSN:0164-1212. doi:10.1016/j.jss.2014.05.076.
[PWT+08] PROCHAZKA, M.; WARD, R.; TUMA,P.;HNˇ
ETYNKA,P.;ADAMEK,
J.: A componen -o ien ed amewo k o spacec a on-boa d so wa e.
In P oceedings o DASIA 2008, DA a Sys ems In Ae ospace, Palma
de Mallo ca, Eu opean Space Agency Repo N . SP-665, May 2008.
ISBN:978-92-9221-229-2.
[Qua] Quanse Inc.Quanse Real-Time Con ol So wa e (QUARC). URL:
h p://www.qua cse ice.com/ReleaseNo es/ iles/
dynamic_ econ igu a ion.h ml [ci ed Ma ch 14, 2015].
[RC08] RAMIREZ, A. J.; CHENG, B. H. C.: Ve i ying and analyzing adap-
i e logic h ough UML s a e models. In 1s In e na ional Con e -
ence on So wa e Tes ing, Ve ifica ion, and Valida ion, pages 529–
532. IEEE Compu e Socie y, Ap il 2008. ISBN:978-0-7695-3127-4.
doi:10.1109/ics .2008.67.
[RCC10] ROBINSON,T.;CHAN, E.; COELINGH, E.: Ope a ing pla oons on
public mo o ways: An in oduc ion o he SARTRE pla ooning p o-
g amme. In 17 h Wo ld Cong ess on In elligen T anspo Sys ems, Oc-
obe 2010.
[Rei07] REINEKE, P.: Model checking on S o y-Diag ammen mi els
GROOVE. Bachelo ’s hesis, Uni e si y o Pade bo n, July 2007.
[Ren06] RENSINK, A.: Model checking quan ified compu a ion ee logic. In
BAIER, C.; HERMANNS, H. (Eds.), CONCUR 2006 – Concu ency
Theo y, olume 4137 o Lec u e No es in Compu e Science, pages
110–125. Sp inge Be lin Heidelbe g, Augus 2006. ISBN:978-3-540-
37376-6. doi:10.1007/11817949_8.
Page 282
[Ren07] RENSINK, A.: Isomo phism checking in GROOVE. In ZÜNDORF, A.;
VARRÓ, D. (Eds.), P oceedings o he Thi d In e na ional Wo kshop on
G aph Based Tools (G aBaTs 2006), olume 1 o Elec onic Commu-
nica ions o he EASST. Eu opean Associa ion o So wa e Science and
Technology, Sep embe 2007.
[Ren08] RENSINK, A.: Explici s a e model checking o g aph g amma s.
In DEGANO,P.;NICOLA, R.; MESEGUER, J. (Eds.), Concu ency,
G aphs and Models, olume 5065 o Lec u e No es in Compu e Sci-
ence, pages 114–132. Sp inge Be lin Heidelbe g, 2008. ISBN:978-3-
540-68676-7. doi:10.1007/978-3-540-68679-8_8.
[RJC12] RAMIREZ, A. J.; JENSEN, A. C.; CHENG, B. H. C.: A ax-
onomy o unce ain y o dynamically adap i e sys ems. In P o-
ceedings o he 2012 ICSE Wo kshop on So wa e Enginee ing o
Adap i e and Sel -Managing Sys ems, SEAMS’12, pages 99 –108.
IEEE Compu e Socie y, June 2012. ISBN:978-1-4673-1788-7.
doi:10.1109/seams.2012.6224396.
[Roz97] ROZENBERG,G.:Handbook o g aph g amma s and compu ing by
g aph ans o ma ion: olume I. ounda ions. Wo ld Scien ific Publish-
ing Co., Inc., Ri e Edge, NJ, USA, 1997. ISBN:9810228848.
[RS08a] REEVES, S.; STREADER, D.: Gene al efinemen , pa one: In e -
aces, de e minism and special efinemen . Elec onic No es in Theo-
e ical Compu e Science, 214:277–307, June 2008. ISSN:1571-0661.
doi:10.1016/j.en cs.2008.06.013.
[RS08b] REEVES, S.; STREADER, D.: Gene al efinemen , pa wo:
Flexible efinemen . Elec onic No es in Theo e ical Com-
pu e Science, 214:309–329, June 2008. ISSN:1571-0661.
doi:10.1016/j.en cs.2008.06.014.
[SBPM08] STEINBERG, D.; BUDINSKY,F.;PATERNOSTRO, M.; MERKS,E.:
EMF: Eclipse Modeling F amewo k. The Eclipse Se ies. Addison-
Wesley, 2nd edi ion, Decembe 2008. ISBN:978-0321331885.
[Sch95] SCHÜRR, A.: Specifica ion o g aph ansla o s wi h iple g aph g am-
ma s. In MAYR,E.W.;SCHMIDT, G.; TINHOFER, G. (Eds.), G aph-
Theo e ic Concep s in Compu e Science, olume 903 o Lec u e No es
in Compu e Science, pages 151–163. Sp inge Be lin / Heidelbe g,
June 1995. ISBN:978-3-540-59071-2. doi:10.1007/3-540-59071-4_45.
[Sch06] SCHMIDT, D. C.: Gues edi o ’s in oduc ion: Model-d i en en-
ginee ing. Compu e , 39(2):25–31, 2006. ISSN:0018-9162.
doi:10.1109/mc.2006.58.
Li e a u e Page 283
[SGM02] SZYPERSKI, C.; GRUNTZ, D.; MURER,S.:Componen So wa e -
Beyond Objec -O ien ed P og amming. Addison-Wesley, 2nd edi ion,
2002. ISBN:0-201-74572-0.
[SH99] SRISURESH,P.;HOLDREGE,M.:RFC2663 - IP Ne wo k Add ess
T ansla o (NAT) Te minology and Conside a ions. Ne wo k Wo k-
ing G oup, Augus 1999. URL: h p:// ools.ie .o g/h ml/
c2663.
[Sha02] SHAW, M.: "sel -healing": so ening p ecision o a oid b i leness: po-
si ion pape o WOSS ’02: wo kshop on sel -healing sys ems. In
P oceedings o he fi s wo kshop on Sel -healing sys ems, WOSS ’02,
pages 111–114, New Yo k, NY, USA, 2002. ACM. ISBN:1-58113-609-
9. doi:10.1145/582128.582152.
[SHS12] STOCKMANN, L.; HOLLER, D.; SPENNEBERG, D.: Ea ly simula ion
and es ing o i ual ECUs o elec ic ehicles. In In e na ional Ba -
e y, Hyb id and Fuel Cell Elec ic Vehicle Symposium (EVS26), May
2012.
[SK95] SLONNEGER, K.; KURTZ,B.L.:Fo mal Syn ax and Seman ics o
P og amming Languages - A Labo a o y Based App oach. Addison-
Wesley, 1995. ISBN:0-201-65697-3.
[SK00] SILVA, B. I.; KROGH, B. H.: Fo mal e ifica ion o hyb id sys ems
using CheckMa e: A case s udy. In P oceedings o he 2000 Ame ican
Con ol Con e ence, olume 3, pages 1679 –1683. IEEE Compu e So-
cie y, June 2000. ISBN:0-7803-5519-9. doi:10.1109/acc.2000.879487.
[SK06] STRUNK, E. A.; KNIGHT, J. C.: Dependabili y h ough assu ed e-
configu a ion in embedded sys em so wa e. IEEE T ansac ions on
Dependable and Secu e Compu ing, 3(3):172 –187, July-Sep . 2006.
ISSN:1545-5971. doi:10.1109/ dsc.2006.33.
[SLT09] SIMONOT-LION,F.;TRINQUET, Y.: Vehicle unc ional domains and
hei equi emen s. In NAVET, N.; SIMONOT-LION, F. (Eds.), Au omo-
i e Embedded Sys ems Handbook, Indus ial In o ma ion Technology
Se ies, chap e 1. CRC P ess, Boca Ra on, FL, USA, 2009. ISBN:978-
0-8493-8026-6.
[SP12] STÜRMER, I.; POHLHEIM, H.: Model quali y assessmen in p ac ice:
How o measu e and assess he quali y o so wa e models du ing he
embedded so wa e de elopmen p ocess. In P oceedings o he In-
e na ional Cong ess o Embedded Real Time So wa e and Sys ems,
ERTS’12, Feb ua y 2012.
Page 284
[Spi92] SPIVEY,J.M.:The Z No a ion: A Re e ence Manual. P en ice Hall
In e na ional (UK) L d., He o dshi e, UK, UK, 1992. ISBN:0-13-
978529-9.
[SRKC00] SILVA, B. I.; RICHESON, K.; KROGH, B. H.; CHUTINAN, A.: Mod-
eling and e i ying hyb id dynamic sys ems using CheckMa e. In P o-
ceedings o he 4 h In e na ional Con e ence on Au oma ion o Mixed
P ocesses: Hyb id Dynamic Sys ems, ADPM 2000, pages 323–328.
Shake Ve lag GmbH, Sep embe 2000. ISBN:978-3826578366.
[SS83] SKEEN, D.; STONEBRAKER, M.: A o mal model o c ash eco e y in
a dis ibu ed sys em. IEEE T ansac ions on So wa e Enginee ing, SE-
9(3):219–228, 1983. ISSN:0098-5589. doi:10.1109/ se.1983.236608.
[SSdR05] SYLLA, M.; STOMP,F.;DE ROEVER, W.-P.: Ve i ying pa ame e ized
efinemen . In P oceedings o he 10 h IEEE In e na ional Con e ence
on Enginee ing o Complex Compu e Sys ems, ICECCS 2005, pages
313 – 321. IEEE Compu e Socie y, June 2005. ISBN:0-7695-2284-X.
doi:10.1109/iceccs.2005.82.
[S a08] STALLMANN,F.:A Model-D i en App oach o Mul i-Agen Sys em De-
sign. PhD hesis, So wa e Enginee ing G oup, Uni e si y o Pade bo n,
Ap il 2008.
[S e97] STEPHENS, R.: A su ey o s eam p ocessing. Ac a In-
o ma ica, 34(7):491–541, July 1997. ISSN:0001-5903.
doi:10.1007/s002360050095.
[S e07] STEINKE, A.: In eg a ion Hyb ide Rekonfigu a ionscha s mi
Ma lab/Simulink-Modellen. Diploma bei , Uni e si y o Pade bo n,
Sep embe 2007.
[SV03] SCHMIDT, Á.; VARRÓ, D.: CheckVML: A ool o model checking i-
sual modeling languages. In STEVENS,P.;WHITTLE, J.; BOOCH,
G. (Eds.), UML 2003 - The Unified Modeling Language. Modeling
Languages and Applica ions, olume 2863 o Lec u e No es in Com-
pu e Science, pages 92–95. Sp inge Be lin Heidelbe g, Oc obe 2003.
ISBN:978-3-540-20243-1. doi:10.1007/978-3-540-45221-8_8.
[SV06] STAHL,T.;VÖLTER,M.:Model-D i en So wa e De elopmen – Tech-
nology, Enginee ing, Managemen . John Wiley & Sons, L d., 1 edi ion,
May 2006. ISBN:978-0470025703.
[SW07] SCHÄFER,W.;WEHRHEIM, H.: The challenges o building ad anced
mecha onic sys ems. In Fu u e o So wa e Enginee ing, FOSE ’07,
pages 72–84. IEEE Compu e Socie y, May 2007. ISBN:0-7695-2829-
5. doi:10.1109/FOSE.2007.28.
Li e a u e Page 285
[SWB12] SCHULZE, M.; WEILAND, J.; BEUCHE, D.: Au omo i e model-d i en
de elopmen and he challenge o a iabili y. In P oceedings o he 16 h
In e na ional So wa e P oduc Line Con e ence - Volume 1, SPLC ’12,
pages 207–214, New Yo k, NY, USA, 2012. ACM. ISBN:978-1-4503-
1094-9. doi:10.1145/2362536.2362565.
[SWZ95] SCHÜRR, A.; WINTER, A. J.; ZÜNDORF, A.: G aph g amma en-
ginee ing wi h PROGRES. In SCHÄFER,W.;BOTELLA, P. (Eds.),
P oceedings o he 5 h Eu opean So wa e Enginee ing Con e ence
(ESEC’95), olume 989 o Lec u e No es in Compu e Science, pages
219–234. Sp inge Be lin Heidelbe g, Sep embe 1995. ISBN:978-3-
540-60406-8. doi:10.1007/3-540-60406-5_17.
[T-V] T-VEC Technologies, Inc.T-VEC Tes e o Simulink and S a e-
flow. URL: h p://www. - ec.com/solu ions/simulink.php
[ci ed Ma ch 14, 2015].
[ BGS13] TER BEEK, M. H.; GADDUCCI,F.;SANTINI, F.: Valida ing econ-
figu a ions o Reo ci cui s in an e-banking scena io. In P oceedings o
he 4 h in e na ional ACM Sigso symposium on A chi ec ing c i ical
sys ems, ISARCS ’13, pages 39–48, New Yo k, NY, USA, June 2013.
ACM. ISBN:978-1-4503-2123-5. doi:10.1145/2465470.2465474.
[TDH11] THOMAS, J.; DZIOBEK, C.; HEDENETZ, B.: Va iabili y manage-
men in he AUTOSAR-based de elopmen o applica ions o in-
ehicle sys ems. In P oceedings o he 5 h Wo kshop on Va iabil-
i y Modeling o So wa e-In ensi e Sys ems, VaMoS ’11, pages 137–
140, New Yo k, NY, USA, 2011. ACM. ISBN:978-1-4503-0570-9.
doi:10.1145/1944892.1944909.
[TFS10] TIBERMACINE, C.; FLEURQUIN, R.; SADOU, S.: A amily o
languages o a chi ec u e cons ain specifica ion. Jou nal o Sys-
ems and So wa e, 83(5):815 – 831, May 2010. ISSN:0164-1212.
doi:10.1016/j.jss.2009.11.736.
[TGS06] TICHY, M.; GIESE, H.; SEIBEL, A.: S o y diag ams in eal- ime so -
wa e. In GIESE, H.; WESTFECHTEL, B. (Eds.), P oceedings o he 4 h
In e na ional Fujaba Days, olume - i-06-275 o Technical Repo ,
pages 15–22. Uni e si y o Pade bo n, Sep embe 2006.
[THB+10] TICHY, M.; HIRSCH, M.; BRINK, C.; SCHÄFER,W.;GERK-
ING, C.; HAHN, M.: In eg a ion hyb ide Modellie ungs echniken
in CAMeL-View. In 7. Pade bo ne Wo kshop En wu mecha on-
ische Sys eme, olume 272, pages 235–251, Pade bo n, 2010. HNI-
Ve lagssch i en eihe. ISBN:978-3-939350-91-0.
Page 286
[THHO08] TICHY, M.; HENKLER, S.; HOLTMANN, J.; OBERTHÜR, S.: Compo-
nen s o y diag ams: A ans o ma ion language o componen s uc-
u es in mecha onic sys ems. In Pos p oceedings o he 4 h Wo kshop
on Objec -o ien ed Modeling o Embedded Real-Time Sys ems (OMER
4), pages 27–39, 2008.
[THP+07] TRUMLER,W.;HELBIG, M.; PIETZOWSKI, A.; SATZGER, B.; UN-
GERER, T.: Sel -configu a ion and sel -healing in AUTOSAR. In P o-
ceedings o he 14 h Asia Pacific Au omo i e Enginee ing Con e ence,
APAC-14, pages 25–36, Hollywood, Cali o nia, USA, Augus 2007.
SAE In e na ional. doi:10.4271/2007-01-3507.
[Tic09] TICHY,M.:Ge ah enanalyse selbs op imie ende Sys eme. Disse a-
ion, Uni e si y o Pade bo n, Wa bu ge S . 100, Pade bo n, Ge many,
May 2009.
[TMD09] TAYLOR, R. N.; MEDVIDOVI ´
C, N.; DASHOFY,E.M.:So wa e A -
chi ec u e: Founda ions, Theo y, and P ac ice. John Wiley & Sons,
Feb ua y 2009. ISBN:978-0-470-16774-8.
[T i09] TRIPAKIS, S.: Checking imed Büchi au oma a emp iness
on simula ion g aphs. ACM T ansac ions on Compu a ional
Logic (TOCL), 10(3):15:1–15:19, Ap il 2009. ISSN:1529-3785.
doi:10.1145/1507244.1507245.
[TSCC05] TRIPAKIS, S.; SOFRONIS, C.; CASPI,P.;CURIC, A.: T ansla -
ing disc e e- ime Simulink o Lus e. ACM T ansac ions on Em-
bedded Compu ing Sys ems (TECS), 4(4):779–818, No embe 2005.
ISSN:1539-9087. doi:10.1145/1113830.1113834.
[TSDF11] TIBERMACINE, C.; SADOU, S.; DONY, C.; FABRESSE,L.:
Componen -based specifica ion o so wa e a chi ec u e cons ain s.
In P oceedings o he 14 h in e na ional ACM Sigso symposium
on Componen based so wa e enginee ing, CBSE ’11, pages 31–
40, New Yo k, NY, USA, 2011. ACM. ISBN:978-1-4503-0723-9.
doi:10.1145/2000229.2000235.
[TSL13] TRAPP, M.; SCHNEIDER, D.; LIGGESMEYER, P.: A sa e y oadmap o
cybe -physical sys ems. In MÜNCH, J.; SCHMID, K. (Eds.), Pe spec-
i es on he Fu u e o So wa e Enginee ing, pages 81–94. Sp inge ,
Be lin/Heidelbe g, 2013. ISBN:978-3-642-37394-7. doi:10.1007/978-
3-642-37395-4_6.
[VDI04] VDI: VDI 2206: En wicklungsme hodik ü mecha onische Sys eme.
Ve ein Deu sche Ingenieu e, 2004.
Li e a u e Page 287
[VEBD07] VANDEWOUDE,Y.;EBRAERT,P.;BERBERS, Y.; D’HONDT,T.:
T anquili y: A low dis up i e al e na i e o quiescence o ensu ing
sa e dynamic upda es. IEEE T ansac ions on So wa e Enginee ing,
33(12):856–868, 2007. ISSN:0098-5589. doi:10.1109/ se.2007.70733.
[Ven80] VENN, J.: On he diag amma ic and mechanical ep esen a ion o
p oposi ions and easonings. The London, Edinbu gh and Dublin
Philosophical Magazine and Jou nal o Science, 10(58):1–18, 1880.
doi:10.1080/14786448008626877.
[VG14] VOGEL,T.;GIESE, H.: Model-d i en enginee ing o sel -adap i e
so wa e wi h EUREMA. ACM T ansac ions on Au onomous and Adap-
i e Sys ems (TAAS), 8(4):18:1–18:33, Janua y 2014. ISSN:1556-4665.
doi:10.1145/2555612.
[ HWH12] VAN HOORN, A.; WALLER, J.; HASSELBRING, W.: Kieke : A
amewo k o applica ion pe o mance moni o ing and dynamic so -
wa e analysis. In P oceedings o he 3 d ACM/SPEC In e na-
ional Con e ence on Pe o mance Enginee ing, ICPE ’12, pages 247–
248, New Yo k, NY, USA, 2012. ACM. ISBN:978-1-4503-1202-8.
doi:10.1145/2188286.2188326.
[ L01] VAN LAMSWEERDE, A.: Goal-o ien ed equi emen s enginee -
ing: a guided ou . In P oceedings o he Fi h IEEE In e na-
ional Symposium on Requi emen s Enginee ing, RE’01, pages 249–
262. IEEE Compu e Socie y, Augus 2001. ISBN:0-7695-1125-2.
doi:10.1109/is e.2001.948567.
[ O dLKM00] VAN OMMERING, R.; VAN DER LINDEN,F.;KRAMER, J.; MAGEE,
J.: The Koala componen model o consume elec onics so -
wa e. Compu e , 33(3):78 –85, Ma ch 2000. ISSN:0018-9162.
doi:10.1109/2.825699.
[VSC+09] VULGARAKIS, A.; SURYADEVARA, J.; CARLSON, J.; SECELEANU,
C.; PETTERSSON, P.: Fo mal seman ics o he P oCom eal- ime com-
ponen model. In P oceedings o he 35 h Eu omic o Con e ence on
So wa e Enginee ing and Ad anced Applica ions, SEEA ’09, pages
478–485, Los Alami os, CA, USA, Augus 2009. IEEE Compu e So-
cie y. ISBN:978-0-7695-3784-9. doi:10.1109/seaa.2009.53.
[VWMA11] VROMANT,P.;WEYNS, D.; MALEK, S.; ANDERSSON,J.: On
in e ac ing con ol loops in sel -adap i e sys ems. In P oceed-
ings o he 6 h In e na ional Symposium on So wa e Enginee ing
o Adap i e and Sel -Managing Sys ems, SEAMS ’11, pages 202–
207, New Yo k, NY, USA, 2011. ACM. ISBN:978-1-4503-0575-4.
doi:10.1145/1988008.1988037.
Page A-4 Appendix A
I he o he pee ecei es canno Mas e om he one pee , hen i swi ches back o No-
Assignmen ega dless o he alue o sla eS a ed and se s sla ePossible o alse. Thus,
i canno be membe because he one pee canno be he coo dina o . I sla eS a ed is
ue and he o he sla e ecei es mas e Ready, i swi ches o Sla e and he assignmen
is finished o he o he pee . I sla eS a ed is alse and he o he pee ecei es mas e -
Ready, hen he o he pee swi ches back o NoAssignmen . The one pee eac s in he
same way as he o he pee based on he messages sla eReady and canno Sla e. I bo h,
mas e Possible and sla ePossible a e alse, hen RTSC swi ches o Failed.InFailed, he
one pee may s ill ecei e youSla e messages om he o he pee , which i answe s wi h
canno Sla e. In addi ion, he one pee will swi ch om NoAssigmen o Failed i i has
no ecei ed a message o 10.000ms. These wo ansi ions a e necessa y o p e en
deadlocks in case ha one o bo h pee s s a wi h one o he a iables mas e Possible o
sla ePossible being alse a he s a o execu ion.
We e ified he RTCP using UPPAAL. We ha e e ified he ollowing p ope ies:
•The RTCP is ee om deadlocks.
•None o he message bu e s may o e flow.
•I one pee eaches he Mas e s a e, hen he o he pee will always e en ually en e
he Sla e s a e.
•I one pee en e s he Fail s a e, hen he o he pee will always e en ually en e he
Fail s a e as well.
A.1.2 Con oyCoo dina ion
The RTCP Con oyCoo dina ion, whose decla a ion is shown in Figu e A.3, is esponsible
o managing he con oy. In pa icula , his RTCP finally decides whe he a RailCab
may join a con oy as a membe and i defines he posi ion whe e he RailCab may en e
he con oy. Bo h decisions a e made based on so-called mo ion p ofiles. A mo ion
p ofile, in he ollowing simply e e ed o as p ofile, is a ce ifica e how a RailCab
mo es in a pa icula d i ing maneu e such as b aking. Fo d i ing in a con oy, each
RailCab needs o be equipped wi h one o many o such p ofiles in o de o gua an ee
sa e con oys [FHK+13, FHK+14].
coo dina o membe
Con oyCoo dina ion
[0..*] [1]
in-bu e size: 1 in-bu e size: 1
delay: 1 ms
Figu e A.3: Decla a ion o he RTCP Con oyCoo dina ion
The RTCP consis s o wo oles, namely coo dina o and membe .coo dina o is a mul i
ole such ha a coo dina o RailCab may coo dina e a con oy wi h many membe s. I a
Comple e RailCab Example Page A-5
new membe wan s o en e he con oy, i sends all o i s p ofiles o he coo dina o . Then,
he coo dina o checks whe he an assignmen o p ofiles o con oy membe s exis s such
ha he con oy is sa e in all d i ing maneu e s. I so, he new membe may en e he
con oy, o he wise i may no en e . Figu e A.4 shows he RTSC ha defines he beha io
o he coo dina o ole while Figu e A.5 shows he RTSC o he membe ole.
The beha io o he coo dina o is sligh ly ex ended compa ed o ou p e ious publica-
ions [FHK+13, FHK+14]. In pa icula , i enables ha he p ofiles o RailCabs ha
al eady d i e as pa o he con oy may be changed i a new RailCab wan s o en e . We
desc ibe he beha io execu ed by coo dina o and membe in he ollowing.
The coo dina o s a s by ini ializing i s a iables. In pa icula , i mus c ea e a new P o-
fileS o e ha s o es all ecei ed p ofiles and ha is assigned o a iable allP ofiles. Then,
a an a bi a y poin in ime, a new membe may appea and a co esponding sub ole is
c ea ed by he ansi ion om Idle o HandleNewMembe . The membe fi es he ansi ion
om Idle o Reques and c ea es i s p ofiles. In addi ion, i sends eques Con oyEn y o
he coo dina o . The sub ole ecei es his message and synch onizes ia newMembe Pos-
sible wi h he adap a ion RTSC. Then, he adap a ion RTSC checks whe he i is possible
and use ul o add a new con oy membe a he gi en poin in ime. I no , i synch onizes
ia en yFail and he sub ole will decline he con oy en y. I he membe may en e , he
adap a ion RTSC synch onizes ia en ySuccess and he sub ole app o es he con oy
en y.
A e his, he membe ini ia es sending i s p ofiles using he message s a P ofileT ans-
mission while en e ing he Wai s a e. The sub ole acknowledges ha i is eadyFo P o-
fileT ansmission and he ansmission o he p ofiles s a s. As long as he membe has
unsen p ofiles, i swi ches om T ansmi o awai Ack and sends a p ofile o he sub ole.
The sub ole s o es he p ofile in allP ofiles and acknowledges ia p ofileRecei ed. A e all
p ofiles ha e been ansmi ed, he membe sends endO P ofileT ansmission, which causes
he sub ole o swi ch o P ofilesRecei ed. Using his ansi ion, he sub ole synch onizes
wi h he adap a ion RTSC ia eques Posi ion in o de o eques an en y posi ion o he
new membe .
The adap a ion RTSC hen in okes calcula eP ofiles. This unc ion compa es he p ofiles
o all RailCabs wi h each o he in o de o ob ain an assignmen o p ofiles o Rail-
Cabs such ha he con oy is sa e [FHK+13, FHK+14]. I no such assignmen could be
ound, newRailCabPosi ion is 0and he adap a ion RTSC synch onizes ia en yFail wi h
he sub ole. Then, he sub ole declines he con oy en y and swi ches o Fail. Simila ly,
he membe swi ches om Wai Fo Posi ion o Declined and he con oy en y has ailed.
Finally, he adap a ion RTSC dele es he sub ole including i s p ofiles and e u ns o Idle.
I calcula eP ofiles could ob ain a p ofile assignmen , he adap a ion RTSC swi ches o
Upda eRequi ed.I changed is alse, hen no p ofiles o he cu en con oy membe s ha e
been changed. In his case, he adap a ion swi ches o Finished and synch onizes ia
en ySuccess wi h he sub ole. Then, he sub ole sends he p ofile and he posi ion o he
membe . The membe acknowledges by sending s a Con oy and en e s he Con oy s a e.
Page A-6 Appendix A
coo dina o
Coo dina o _Main
adap a ion
sub ole
1
2
channel: newMembe Possible, en yFail, en ySuccess, eques Posi ion, sendNewP o ile[Role], inished[Role], con oy;
a iable: Role cu SubRole, Role mpSubRole, in membe s := 0, cons in maxNumMembe s := 3;
clock: c1, c2;
a iable: bool membe Possible, in newRailCabPosi ion, bool changed, P o ile newP o ile, P o ileS o e allP o iles;
ope a ion: bool isMembe Possible(), bool calcula eP o iles();
a iable: in newPos;
clock: c3, c4;
Idle NewQue y
[membe s < maxNumMembe s]/
{cu SubRole :=
c ea eSubRoleIns ance(sel );
membe s := membe s + 1; ese : c1;}
HandleNewMembe
c1 ≤ 10ms
NewMembe
c1 ≤ 1000ms
Calcula e
Upda eP o iles
c1 ≤ 10ms && c2 ≤ 1000ms
en y/ { ese : c1;}
Wai Fo Sub ole
c1 ≤ 100ms
newMembe Possible? /
{membe Possible :=
isMembe Possible ( ) }
[no membe Possible] en yFail! /
[membe Possible]
en ySuccess! /
{ ese : c1}
eques Posi ion? /
{calcula eP o iles()}
[newRailCabPosi ion > 0] /
[ mpSubRole <> cu SubRole]
sendNewP o ile[ mpSubRole]! /
{newP o ile := ge P o ile(allP o iles, mpSubRole);}
inished[ mpSubRole]? /
{ mpSubRole := mpSubRole.nex }
U
U
[500ms;500ms]
Upda eRequi ed
[changed] /
{ mpSubRole := i s ;
ese : c2;}
U
Finish
c1 ≤ 200ms
[ mpSubRole == null]/
{ ese : c1;}
[no changed] en ySuccess! /
{newP o ile := ge P o ile(allP o iles, cu SubRole);
ese : c1;}
Dele eSR
c1 ≤ 200ms
[newRailCabPosi ion == 0]
en yFail! /
[c2 ≥ 200ms] /
{dele eSubRoleIns ance(cu SubRole);
dele eSRP o iles(allP o iles, cu SubRole);
membe s := membe s –1;}
con oy? /
{cu SubRole := null;}
[ mpSubRole == cu SubRole] en ySuccess! /
{newP o ile := ge P o ile(allP o iles, mpSubRole);
mpSubRole := mpSubRole.nex ;}
Ini ialize
/ {allP o iles := ini ializeVa iables(); }
U
Idle
c3 ≤ 10ms Reques
eques Con oyEn y
newMembe Possible! / En yPossible
c3 ≤ 50ms
en ySuccess? /
{ ese : c3;}
app o eCon oyEn y()
Pe o m T ansmission
c3 ≤ 100ms && c4 ≤ 1000ms
en y/ { ese : c3}
s a P o ileT ansmission /
{c ea eP o ileLis (allP o iles, sel ); ese : c4;}
eadyFo P o ileT ansmission()
P o iles
Recei ed
endO P o ileT ansmission
eques Posi ion! /
Wai
c3 ≤ 200ms Con oy
en ySuccess? /
{newPos := newRailCabPosi ion;
ese : c3;}
en e Con oyA (newPos, newP o ile)
con oy!
accep Posi ion /
s a Con oy()
NewP o ile
c3 ≤ 100ms
sendNewP o ile[sel ]? /
{ ese : c3}
upda eP o ile(newP o ile)
con i mP o ileUpda e
inished[sel ]! /
p o ile /
{addP o ile(allP o iles, sel , p o ile.p);}
p o ileRecei ed()
Failed
en yFail? /
declineCon oyEn y()
en yFail? / declineCon oyEn y()
Figu e A.4: RTSC o he Role coo dina o o he RTCP Con oyCoo dina ion (c .
[FHK+14])
Comple e RailCab Example Page A-7
membe
Idle
c ≤ 10ms Declined
/ {p o iles :=
ob ainP o iles(numO P o iles)}
eques Con oyEn y()
a iable: cons in numO P o iles := 5, boolean hasNex , in en yPosi ion, P o ile cu P o ile;
P o ile mpP o ile, P o ileI e a o i e a o , P o ileLis p o iles;
clock: c;
Reques
c ≤ 75ms
Wai
c ≤ 50ms
T ansmi
c ≤ 10ms
en y/ { ese : c;
hasNex := hasFu he P o ile(i e a o );}
Wai Fo Posi ion
c ≤ 1000ms
declineCon oyEn y /
app o eCon oyEn y /
{ ese : c} s a P o ileT ansmission() declineCon oyEn y /
eadyFo P o ileT ansmission /
{i e a o := ge I e a o (p o iles);} [no hasNex ] /
{dele eI e a o (i e a o );}
endO P o ileT ansmission()
Recei edPosi ion
c ≤ 100ms
Awai Ack
c ≤ 50ms
[hasNex ] /
{ mpP o ile := ge Nex P o ile(i e a o );}
p o ile( mpP o ile)
p o ileRecei ed /
en e Con oyA /
{en yPosi ion := en e Con oyA .pos;
cu P o ile := en e Con oyA .p o ile;}
accep Posi ion()
Con oy s a Con oy /
upda eP o ile /
{cu P o ile := upda eP o ile.p o ile}
con i mP o ileUpda e()
Figu e A.5: RTSC o he Role membe o he RTCP Con oyCoo dina ion
A e ecei ing his message, he sub ole also swi ches o Con oy and synch onizes ia
con oy wi h he adap a ion RTSC, which finishes he con oy en y.
I calcula eP ofiles de i ed a p ofile assignmen ha equi es o change he p ofiles o he
exis ing con oy membe s, he adap a ion RTSC swi ches o Upda eP ofiles. Then, he
adap a ion RTSC i e a es all sub oles and synch onizes ia sendNewP ofile wi h hem. In
his case, he co esponding sub ole swi ches om Con oy o NewP ofile and sends he
new p ofile o he co esponding membe . The membe p ocesses he message a he sel -
ansi ion a Con oy and confi ms he upda e. The sub ole o he new membe is ea ed
as be o e and he con oy se up finishes a e all membe s ha e been in o med abou hei
new p ofiles.
A.1.3 P ofileDis ibu ion
The RTCP P ofileDis ibu ion, whose decla a ion is shown in Figu e A.6, is esponsible
o p opaga ing p ofiles and he da a, which is necessa y o using he p ofile, inside
he coo dina o RailCab. This p ofile is used wi hin he Con oyCoo dina ion componen
shown in Figu e 3.5. The mul i ole p ofileP o ide sends he p ofile in o ma ion o many
p ofileRecei e s and ecei es in o ma ion abou he cu en maximum speeds o he p o-
fileRecei e s. The la e in o ma ion may be used o adjus ing he con oy speed a e a
p ofile change.
Page A-8 Appendix A
p o ileP o ide p o ileRecei e
P o ileDis ibu ion
[0..*] [1]
in-bu e size: 1 in-bu e size: 1
delay: 1 ms
Figu e A.6: Decla a ion o he RTCP P ofileDis ibu ion
Figu e A.7 shows he RTSC o he mul i ole p ofileP o ide , while Figu e A.8 shows he
RTSC o he ole p ofileRecei e . The execu ion o he p ofileP o ide s a s in he Idle
s a e o he adap a ion RTSC. A an a bi a y poin o ime, i may add a new sub ole by
fi ing he sel - ansi ion a he Idle s a e. Thus, i will be defined by he implemen ing
componen a which poin in ime a new ins ance is equi ed.
p o ileP o ide
P o ileP o ide _Main
adap a ion
sub ole
1
2
channel: s a Upda e[Role], inished;
clock: c5;
a iable: in minDis ance, in newCon oySpeed, in con oySpeed, in ownMaxSpeed,
bool upda eP o iles := alse, P o ileS o e allP o iles;
a iable: P o ile mpP o ile, in mpMembe Speed;
ope a ion: in upda eCon oySpeed(in newSpeed);
clock: c6;
Idle
c5 ≤ 1s
en y/ { ese : c5;}
sendUpda e
c5 ≤ 950ms
[c5 ≥ 1s] s a Upda e[ i s ]! /
{newCon oySpeed := ownMaxSpeed; ese : c5;}
inished? / {con oySpeed := newCon oySpeed;}
[c5 ≤ 950ms]/
{c ea eSubRoleIns ance(sel );}
[10ms;10ms]
Idle s a Upda e[sel ]? /
Wai Answe
c6 ≤ 45 ms
en y/ { ese : c6;}
SendMsg
U
T igge Nex
c6 ≤ 1ms
en y/ {newCon oySpeed :=
upda eCon oySpeed( mpMembe Speed;
ese : c6;}
[upda eP o iles == ue] /
{ mpP o ile := ge P o ile(allP o iles, sel );
upda eP o iles := alse;}
newP o ile( mpP o ile, con oySpeed,
minDis ance, ownMaxSpeed)
[upda eP o iles == alse] /
newDa a(con oySpeed,
minDis ance, ownMaxSpeed)
upda eS a egy /
{ mpMembe Speed :=
upda eS a egy.speed;}
[sel == las ]
inished! /
[sel <> las ]
s a Upda e[nex ]! /
Figu e A.7: RTSC o he Role p ofileP o ide o he RTCP P ofileDis ibu ion
Once pe second, he adap a ion RTSC swi ches om Idle o sendUpda e and synch o-
nizes wi h he fi s sub ole ia s a Upda e. This ini ia es and upda e p ocess whe e new
da a and p ofile in o ma ion a e sen o he ecei e s. The synch oniza ion causes he
fi s sub ole o swi ch om Idle o SendMsg. I a new p ofile is a ailable, i sends a
newP ofile message o he p ofileRecei e . This message con ains he p ofile and in o -
ma ion ha is necessa y o using he p ofile such as he cu en e e ence speed o he
con oy, he minimum dis ance o be kep , and he own po en ial maximum speed o he
Comple e RailCab Example Page A-9
coo dina o . I no new p ofile is a ailable, hen he sub ole sends newDa a ha con ains
he same in o ma ion as newP ofile excep o he p ofile. The eby, we acknowledge he
ac ha applying a new p ofile equi es mo e complica ed ope a ions by he p ofileRe-
cei e and ha he p ofiles will change less equen ly han he emaining in o ma ion
because he emaining in o ma ion depends on he goals o he RailCabs and he cu en
en i onmen al condi ions such as s ong wind o slopes.
p o ileRecei e
Idle
newDa a/
{con oySpeed := newDa a.con Speed;
con oyMinDis := newDa a.minDis ;
coo dMaxSpeed := newDa a.coo dMaxSpeed;}
a iable: in con oyMinDis , P o ile cu P o ile, in con oySpeed,
in ownPo en ialMaxSpeed, in coo dMaxSpeed;
clock: c2;
NewDa a
c2 ≤ 1ms
en y/ { ese : c2;}
newP o ile/
{cu P o ile := newP o ile.p o ile;
con oySpeed := newP o ile.con Speed;
con oyMinDis := newP o ile.minDis ;
coo dMaxSpeed := newP o ile.coo dMaxSpeed;}
/ upda edS a egy(ownPo en ialMaxSpeed)
Figu e A.8: RTSC o he Role p ofileRecei e o he RTCP P ofileDis ibu ion
A e ecei ing ei he newP ofile o newDa a, he p ofileRecei e swi ches o NewDa a.
Then, i sends upda edS a egy con aining i s new po en ial maximum speed back o he
sub ole o p ofileP o ide . Then, he sub ole swi ches o T igge Nex and upda es he con-
oy speed. The co esponding ope a ion upda eCon oySpeed compu es he minimum o
all speeds p o ided by he p ofileRecei e s and s o es i in newCon oySpeed. Then, he
sub ole ei he igge s he nex sub ole o , i i is he las one, i synch onizes ia finished
wi h he adap a ion RTSC. Finally, he adap a ion RTSC e u ns o Idle and se s he con-
oySpeed o he newCon oySpeed. As a esul , he new con oy speed will be applied as
pa o he nex upda e.
A.1.4 SpeedT ansmission
The RTCP SpeedT ansmission, whose decla a ion is shown in Figu e A.9, is used o
pe iodically ansmi ing he cu en speed o he RailCab. I has been de i ed om he
Real-Time Coo dina ion Pa e n Pe iodicT ansmission [DBHT12].
sende ecei e
SpeedT ansmission
[1] [1]
in-bu e size: 1 in-bu e size: 1
delay: 0 ms
Figu e A.9: Decla a ion o he RTCP SpeedT ansmission
[Document text truncated for crawler view.]