2015
DOI: 10.1007/s10009-015-0367-0
|View full text |Cite|
|
Sign up to set email alerts
|

How to model and prove hybrid systems with KeYmaera: a tutorial on safety

Abstract: This paper is a tutorial on how to model hybrid systems as hybrid programs in differential dynamic logic and how to prove complex properties about these complex hybrid systems in KeYmaera, an automatic and interactive formal verification tool for hybrid systems. Hybrid systems can model highly nontrivial controllers of physical plants, whose behaviors are often safety critical such as trains, cars, airplanes, or medical devices. Formal methods can help design systems that work correctly. This paper illustrates… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
1
1
1
1

Citation Types

0
32
0

Year Published

2015
2015
2020
2020

Publication Types

Select...
7
2
1

Relationship

2
8

Authors

Journals

citations
Cited by 50 publications
(32 citation statements)
references
References 55 publications
0
32
0
Order By: Relevance
“…The chosen case study deals with a stop sign controller proposed by Quesel et al in [17] (Sect. 5.3).…”
Section: Case-studymentioning
confidence: 99%
“…The chosen case study deals with a stop sign controller proposed by Quesel et al in [17] (Sect. 5.3).…”
Section: Case-studymentioning
confidence: 99%
“…As its decisions, ctrl lists that the car can either accelerate a := A or coast a := 0, while plant describes the motion of the car (position p changes according to velocity v, velocity v according to the chosen acceleration a). Details on dL are in the literature [10,11,12], including a tutorial on modeling and proving in KeYmaera [16].…”
Section: ?Fmentioning
confidence: 99%
“…Logic-based analysis of a given hybrid automaton has been thoroughly investigated by Platzer in [12] and became practically feasible by the tool KeYmaera [14]. This tool is an interactive theorem prover and allows the user to formally prove safety properties taken both discrete and continuous state variables into account.…”
Section: Motivationmentioning
confidence: 99%