Modeling Railway Control Systems in Promela
This paper presents an approach to systematically build Promela models with the aim of generating test cases within the system level testing process of railway control systems. The paper focuses on the encoding of the system model, of the aspects related to the representation of possible execution environments and their interaction with the system. The input for building a Promela model of the system under test is a state machine based specification. Indeed, state machines are one of the most common notations used in industrial settings to model critical systems and allow for easily obtaining the Promela model of the system by applying a well structured transformational approach; furthermore, state-based formalism are also highly recommended by CENELEC norms to model railway control systems.
In our approach Dynamic State Machines (DSTMs) are used, a newly developed extension of hierarchical state machines which allow for modeling dynamic instantiation of processes. The approach is applied to a functionality of the Radio Block Centre, the vital core of the ERTMS/ETCS Control System, in order to show the feasibility and effectiveness of the generation of the Promela model on a real system.
KeywordsModel checking Promela SPIN Dynamic state machine CRYSTAL Railway control systems Test case generation
This paper is partially supported by research project CRYSTAL (Critical System Engineering Acceleration), funded from the ARTEMIS Joint Undertaking under grant agreement no. 332830 and from ARTEMIS member states Austria, Belgium, Czech Republic, France, Germany, Italy, Netherlands, Spain, Sweden, United Kingdom.
- 2.Di Martino, B., et al.: An interoperable testing environment for ERTMS/ETCS control systems. In: Bondavalli, A., Ceccarelli, A., Ortmeier, F. (eds.) SAFECOMP 2014. LNCS, vol. 8696, pp. 147–156. Springer, Heidelberg (2014)Google Scholar
- 3.CENELEC EN50128: communication, signalling and processing systems - software for railway control and protection systems (2011)Google Scholar
- 6.Holzmann, G.J.: The SPIN Model Checker: Primer and Reference Manual, vol. 1003. Addison-Wesley, Reading (2004)Google Scholar
- 9.Nardone, R., et al.: Dynamic state machines for formalizing railway control system specifications. In: Artho, C., Ölveczky, P.C. (eds.) FTSCS 2014. CCIS, vol. 476, pp. 93–109. Springer, Heidelberg (2015)Google Scholar
- 10.Pflügl, H., El-Salloum, C., Kundner, I.: Crystal, critical system engineering acceleration, a truly european dimension. ARTEMIS Mag. 14, 12–15 (2013)Google Scholar
- 11.UIC. ERTMS/ETCS class1 system requirements specification, ref. SUBSET-026, issue 2.2.2 (2002)Google Scholar
- 12.Yin, L., Mallet, F., Liu, J.: Verification of marte/ccsl time requirements in promela/spin. In: 16th IEEE International Conference on Engineering of Complex Computer Systems (ICECCS), pp. 65–74 (2011)Google Scholar
- 13.Zheng, Y., Zhou, J., Krause, P.: A model checking based test case generation framework for web services. In: Fourth International Conference on Information Technology, ITNG 2007, pp. 715–722. IEEE (2007)Google Scholar