#### DMCA

## Modular analysis of discrete controllers for distributed hybrid systems (2002)

Venue: | IN: IFAC WORLD CONGRESS |

Citations: | 5 - 2 self |

### Citations

1007 | Design and synthesis of synchronization skeletons using branching time temporal logic
- Clarke, Emerson
- 1981
(Show Context)
Citation Context ...ep of this approach is to verify local properties for each module individually using justified assumptions about its environment – here the Assumption/Commitment method is employed, as introduced in (=-=Clarke and Emerson, 1982-=-; Queille and Sifakis, 1982). A required property of a single module Mj is first verified by model checking for a likely (or desired) behavior of the module’s environment. Hence, the automaton Sj comm... |

772 | The algorithmic analysis of hybrid systems
- Alur, Courcoubetis, et al.
- 1995
(Show Context)
Citation Context ...ed process, an important step is to model the modules such that (i) the communication between the individual modules can be represented, and (ii) that the model can be analyzed by model checking. In (=-=Alur et al., 1995-=-), Linear Hybrid Automata (LHA) are defined as a model for linear hybrid systems for which implementations of model checking algorithms are available. A LHA combines a state transition structure with ... |

597 | Conjoining specifications
- Abadi, Lamport
- 1995
(Show Context)
Citation Context ...mitment can be found in literature. Depending on the underlying formalism they are called Rely/Guarantee, Assumption/Commitment or Assume/Guarantee (Misra and Chandy, 1981; Jones, 1981; Pnueli, 1984; =-=Abadi and Lamport, 1995-=-). However, most of them were applied to discrete systems and still few applications to real time and hybrid systems have been reported (Hooman, 1997; Chang et al., 1994; Alur and Henzinger, 1997; Hen... |

468 | HyTech: A model checker for hybrid systems
- Henzinger, Ho, et al.
- 1997
(Show Context)
Citation Context ...mits. After each action, the controller interacts with a high level controller for at most tC seconds. This is modelled by including busy states. Model checking was carried out using the tool HyTech (=-=Henzinger et al., 1997-=-). The CLHA were converted to LHA by adding appropriate loops to represent the behavior of sending and receiving labels. The first step starts with the controller S1. The expected behavior is modelled... |

309 | Model checking and modular verification
- Grumberg, Long
- 1994
(Show Context)
Citation Context ...he assumption/commitment pairs is the creative work of the modeler and can only partially be automated. 3.1 Application Using Automata The proof of relation (1) can be automated using model checking (=-=Grumberg and Long, 1991-=-). The assumptions ai are modeled by automata Ai and the commitments ci are expressed by temporal specifications, e.g., CTL formulae. Alternatively, a test automaton CT i can be constructed which incl... |

194 |
Chandy, Proofs of networks of processes
- Misra, M
- 1981
(Show Context)
Citation Context ...l analysis based on the principle of Assumption/Commitment can be found in literature. Depending on the underlying formalism they are called Rely/Guarantee, Assumption/Commitment or Assume/Guarantee (=-=Misra and Chandy, 1981-=-; Jones, 1981; Pnueli, 1984; Abadi and Lamport, 1995). However, most of them were applied to discrete systems and still few applications to real time and hybrid systems have been reported (Hooman, 199... |

145 |
Specification and verification of concurrent systems
- Queille, Sifakis
- 1982
(Show Context)
Citation Context ...verify local properties for each module individually using justified assumptions about its environment – here the Assumption/Commitment method is employed, as introduced in (Clarke and Emerson, 1982; =-=Queille and Sifakis, 1982-=-). A required property of a single module Mj is first verified by model checking for a likely (or desired) behavior of the module’s environment. Hence, the automaton Sj commits itself to the required ... |

119 | You assume, we guarantee: Methodology and case studies
- Henzinger, Qadeer, et al.
- 1998
(Show Context)
Citation Context ...995). However, most of them were applied to discrete systems and still few applications to real time and hybrid systems have been reported (Hooman, 1997; Chang et al., 1994; Alur and Henzinger, 1997; =-=Henzinger et al., 1998-=-; Henzinger et al., 2000). In difference to those approaches, this contribution aims at developing an analysis strategy that can be used within the design procedure for discrete controllers of distrib... |

115 |
Development Methods for Computer Programs including a Notion of Interference
- Jones
- 1981
(Show Context)
Citation Context ...principle of Assumption/Commitment can be found in literature. Depending on the underlying formalism they are called Rely/Guarantee, Assumption/Commitment or Assume/Guarantee (Misra and Chandy, 1981; =-=Jones, 1981-=-; Pnueli, 1984; Abadi and Lamport, 1995). However, most of them were applied to discrete systems and still few applications to real time and hybrid systems have been reported (Hooman, 1997; Chang et a... |

81 | Modularity for Timed and Hybrid Systems”.
- Alur, Henzinger
- 1997
(Show Context)
Citation Context ...1984; Abadi and Lamport, 1995). However, most of them were applied to discrete systems and still few applications to real time and hybrid systems have been reported (Hooman, 1997; Chang et al., 1994; =-=Alur and Henzinger, 1997-=-; Henzinger et al., 1998; Henzinger et al., 2000). In difference to those approaches, this contribution aims at developing an analysis strategy that can be used within the design procedure for discret... |

40 | Compositional verification of real-time systems
- Chang, Manna, et al.
- 1994
(Show Context)
Citation Context ...ones, 1981; Pnueli, 1984; Abadi and Lamport, 1995). However, most of them were applied to discrete systems and still few applications to real time and hybrid systems have been reported (Hooman, 1997; =-=Chang et al., 1994-=-; Alur and Henzinger, 1997; Henzinger et al., 1998; Henzinger et al., 2000). In difference to those approaches, this contribution aims at developing an analysis strategy that can be used within the de... |

32 | Decomposing refinement proofs using assume-guarantee
- Henzinger, Qadeer, et al.
- 2000
(Show Context)
Citation Context ...hem were applied to discrete systems and still few applications to real time and hybrid systems have been reported (Hooman, 1997; Chang et al., 1994; Alur and Henzinger, 1997; Henzinger et al., 1998; =-=Henzinger et al., 2000-=-). In difference to those approaches, this contribution aims at developing an analysis strategy that can be used within the design procedure for discrete controllers of distributed hybrid systems. Par... |

16 |
transition for global to modular temporal reasoning about programs," in Logics and Models of Concurrent Systems
- Pnueli, \In
- 1984
(Show Context)
Citation Context ...Assumption/Commitment can be found in literature. Depending on the underlying formalism they are called Rely/Guarantee, Assumption/Commitment or Assume/Guarantee (Misra and Chandy, 1981; Jones, 1981; =-=Pnueli, 1984-=-; Abadi and Lamport, 1995). However, most of them were applied to discrete systems and still few applications to real time and hybrid systems have been reported (Hooman, 1997; Chang et al., 1994; Alur... |

11 | Compositional verification of real-time applications
- Hooman
- 1998
(Show Context)
Citation Context ...handy, 1981; Jones, 1981; Pnueli, 1984; Abadi and Lamport, 1995). However, most of them were applied to discrete systems and still few applications to real time and hybrid systems have been reported (=-=Hooman, 1997-=-; Chang et al., 1994; Alur and Henzinger, 1997; Henzinger et al., 1998; Henzinger et al., 2000). In difference to those approaches, this contribution aims at developing an analysis strategy that can b... |

1 | Verification of hybrid controlled processing systems based on decomposition and deduction - Frehse, Stursberg, et al. - 2001 |

1 | 1427 of LNCS - Vol |