Stepwise Formal Modelling and Reasoning of Insulin Infusion Pump Requirements

  • Neeraj Kumar SinghEmail author
  • Hao Wang
  • Mark Lawford
  • Thomas S. E. Maibaum
  • Alan Wassyng
Conference paper
Part of the Lecture Notes in Computer Science book series (LNCS, volume 9185)


An insulin infusion pump (IIP) is a critical software-intensive medical device that infuses insulin satisfying patient needs under safety and timing constraints that are appropriate for the treatment of diabetes. This device is used by millions of people around the world. The USA Food and Drug Administration (FDA) has reported several recalls in which IIP failures were responsible for a large number of serious illnesses and deaths. The failures responsible for this harm to people who are dependent on external insulin were caused by the introduction of hardware or software design errors during the system development process. This paper presents an incremental proof-based development of an IIP. We use the Event-B modelling language to formalize the given system requirements. Further, the Rodin proof tools are used to verify the correctness of functional behaviour, internal consistency checking with respect to safety properties, invariants and events.


Insulin Infusion Pump (IIP) Event-B Refinement Formal methods Verification Validation 


  1. 1.
    Carayon, P., Wood, K.E.: Patient safety. Inf. Knowl. Syst. Manag. 8(1–4), 23–46 (2009)Google Scholar
  2. 2.
    Chen, Y., Lawford, M., Wang, H., Wassyng, A.: Insulin pump software certification. In: Gibbons, J., MacCaull, W. (eds.) FHIES 2013. LNCS, vol. 8315, pp. 87–106. Springer, Heidelberg (2014) CrossRefGoogle Scholar
  3. 3.
    Singh, N.K., Wang, H., Lawford, M., Maibaum, T., Wassyng, A.: Formalizing the glucose homeostasis mechanism. In: Duffy, V.G. (ed.) DHM 2014. LNCS, vol. 8529, pp. 460–471. Springer, Heidelberg (2014) Google Scholar
  4. 4.
    Keatley, K.L.: A review of the FDA draft guidance document for software validation: guidance for industry. Qual. Assur. 7(1), 49–55 (1999)Google Scholar
  5. 5.
    A reseach and development needs report by NITRD: high-confidence medical devices: cyber-physical systems for 21st century health care.
  6. 6.
    Lee, I., Pappas, G.J., Cleaveland, R., Hatcliff, J., Krogh, B.H., Lee, P., Rubin, H., Sha, L.: High-confidence medical device software and systems. Computer 39(4), 33–38 (2006)CrossRefGoogle Scholar
  7. 7.
    Bowen, J., Stavridou, V.: Safety-critical systems, formal methods and standards. Softw. Eng. J. 8(4), 189–209 (1993)CrossRefGoogle Scholar
  8. 8.
    Singh, N.K.: Using Event-B for Critical Device Software Systems. Springer GmbH, London (2013)CrossRefGoogle Scholar
  9. 9.
    Méry, D., Singh, N.K.: Real-time animation for formal specification. In: Aiguier, M., Bretaudeau, F., Krob, D. (eds.) Complex Systems Design and Management, pp. 49–60. Springer, Berlin Heidelberg (2010)CrossRefGoogle Scholar
  10. 10.
    Wassyng, A.: Though this be madness, yet there is method in it? In: Proceedings of FormaliSE, pp. 1–7. IEEE (2013)Google Scholar
  11. 11.
    Abrial, J.: Modeling in Event-B - System and Software Engineering. Cambridge University Press, Cambridge (2010)CrossRefGoogle Scholar
  12. 12.
    Project RODIN: rigorous open development environment for complex systems (2004).
  13. 13.
    Masci, P., Ayoub, A., Curzon, P., Lee, I., Sokolsky, O., Thimbleby, H.: Model-based development of the generic PCA infusion pump user interface prototype in PVS. In: Bitsch, F., Guiochet, J., Kaâniche, M. (eds.) SAFECOMP. LNCS, vol. 8153, pp. 228–240. Springer, Heidelberg (2013) CrossRefGoogle Scholar
  14. 14.
    Kim, B.G., Ayoub, A., Sokolsky, O., Lee, I., Jones, P., Zhang, Y., Jetley, R.: Safety-assured development of the GPCA infusion pump software. In: 2011 Proceedings of the International Conference on Embedded Software (EMSOFT), pp. 155–164, October 2011Google Scholar
  15. 15.
    Wang, J., Liu, S., Qi, Y., Hou, D.: Developing an insulin pump system using the SOFL method. In: 4th Asia-Pacific Software Engineering Conference (APSEC), pp. 334–341 (2007)Google Scholar
  16. 16.
    Xu, H., Maibaum, T.: An Event-B approach to timing issues applied to the generic insulin infusion pump. In: Liu, Z., Wassyng, A. (eds.) FHIES 2011. LNCS, vol. 7151, pp. 160–176. Springer, Heidelberg (2012) CrossRefGoogle Scholar
  17. 17.
    Sommerville, I.: Software Engineering, 7th edn. Pearson Addison Wesley, New Jersey (2004)Google Scholar
  18. 18.
    Singh, N.K., Wang, H., Lawford, M., Maibaum, T.S.E., Wassyng, A.: Report 18: formalizing insulin pump using Event-B. Technical report 18, McSCert, McMaster University, October 2014.

Copyright information

© Springer International Publishing Switzerland 2015

Authors and Affiliations

  • Neeraj Kumar Singh
    • 1
    Email author
  • Hao Wang
    • 2
  • Mark Lawford
    • 1
  • Thomas S. E. Maibaum
    • 1
  • Alan Wassyng
    • 1
  1. 1.McMaster Centre for Software CertificationMcMaster UniversityHamiltonCanada
  2. 2.Faculty of Engineering and Natural SciencesAalesund University CollegeAlesundNorway

Personalised recommendations