2015
DOI: 10.1007/s10009-015-0409-7
|View full text |Cite
|
Sign up to set email alerts
|

The landing gear system in multi-machine Hybrid Event-B

Abstract: A system development case study problem based on a set of aircraft landing gear is examined in Hybrid Event-B (an extension of Event-B that includes provision for continuously varying behaviour as well as the usual discrete changes of state). Although tool support for Hybrid Event-B is currently lacking, the complexity of the case study provides a valuable challenge for the expressivity and modelling capabilities of the Hybrid Event-B formalism. The size of the case study, and in particular, the number of over… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
1
1
1
1

Citation Types

0
11
0

Year Published

2016
2016
2022
2022

Publication Types

Select...
3
3

Relationship

3
3

Authors

Journals

citations
Cited by 12 publications
(11 citation statements)
references
References 24 publications
(76 reference statements)
0
11
0
Order By: Relevance
“…They have been modelled faithfully by the patterns just described since the blood pump has been modelled in reasonable detail. 5 Of the rest, R-5 to R-11 and R-14 to R-17 also concern initiation/connection, involve the blood pump, and fit the patterns described. Of these, R-11 is modelled (though not the switching off of the blood pump, since it is unclear from the various parts of [16] when exactly the pump is to be switched on or off during initiation/connection).…”
Section: The Development In Detailmentioning
confidence: 62%
See 1 more Smart Citation
“…They have been modelled faithfully by the patterns just described since the blood pump has been modelled in reasonable detail. 5 Of the rest, R-5 to R-11 and R-14 to R-17 also concern initiation/connection, involve the blood pump, and fit the patterns described. Of these, R-11 is modelled (though not the switching off of the blood pump, since it is unclear from the various parts of [16] when exactly the pump is to be switched on or off during initiation/connection).…”
Section: The Development In Detailmentioning
confidence: 62%
“…without the faults derailing the strategy to an unconvincing degree. This aspects is to be contrasted with the landing gear case study treated in [3,5], where (and especially in [5]) great benefit was derived from focusing first on the nominal development, and then incorporating the faulty regime, using retrenchment [10,9,8]. There, the various levels of fault tolerance would have made a flat treatment unhelpfully complex.…”
Section: Discussionmentioning
confidence: 99%
“…This gave rise to the need for a number of tIIi's distributed around the various interfaces. The case study was revisited and extended in [8], and this time the earlier modelling decisions were overturned and a hypergraph architecture as we recommend here emerged naturally. It proved possible to eliminate all use of tIIi's thereby.…”
Section: The Hypergraph Project Architecture Patternmentioning
confidence: 99%
“…Larger case studies have already been mentioned: [7,8,10]. The case studies here are restricted to a small development done in discrete Event-B in Section 10.1, and, in Section 10.2, there is a reexamination of the European Train Control System, first examined using Hybrid Event-B as a single machine in PaperI.…”
Section: Small Project Case Studiesmentioning
confidence: 99%
See 1 more Smart Citation