A Domain-Specific Language for Generic Interlocking Models and Their Properties
State-of-the-art railway interlocking systems typically adhere to the product line paradigm, where each individual system is obtained by instantiating a generic system with configuration data. In this paper, we present a domain-specific language, IDL, for specifying generic behavioural models and generic properties of interlocking systems. An IDL specification of a generic model consists of generic variable declarations and generic transition rules, and generic properties are generic state invariants. Generic models and generic properties can be instantiated with configuration data. This results in concrete models and concrete properties that can be used as input for a model checker to formally verify that the system model satisfies desired state invariants. The language and a configuration data instantiator based on the semantics have been implemented as components of the RobustRailS tool set for formal specification and verification of interlocking systems. They have successfully been applied to (1) define a generic model and generic safety properties for the new Danish interlocking systems and to (2) instantiate these generic artefacts for real-world stations and lines in Denmark. A novelty of this work is to provide a domain-specific language for generic models and an instantiator tool taking not only configuration data but also a generic model as input instead of using a hard-coded generator for instantiating only one fixed generic model and its properties with configuration data.
KeywordsRailway interlocking systems Domain-specific languages Formal methods Formal models Formal verification
The authors would like to thank Ross Edwin Gammon and Nikhil Mohan Pande from Banedanmark (Railnet Denmark) and Jan Bertelsen from Thales for helping us with their expertise about Danish interlocking systems; and Dr.-Ing. Uwe Schulze and Florian Lapschies from University of Bremen for their help with the implementation in the RT-Tester tool-chain.
- 1.Cao, Y., Xu, T., Tang, T., Wang, H., Zhao, L.: Automatic generation and verification of interlocking tables based on domain specific language for computer based interlocking systems (dsl-cbi). In: Proceedings of the IEEE International Conference on Computer Science and Automation Engineering (CSAE 2011), pp. 511–515. IEEE (2011)Google Scholar
- 2.CENELEC European Committee for Electrotechnical Standardization: EN 50128: 2011 - Railway applications - Communications, signalling and processing systems - Software for railway control and protection systems (2011)Google Scholar
- 3.European Railway Agency: Annex A for ETCS Baseline 3 and GSM-R Baseline 0, April 2012. http://www.era.europa.eu/Document-Register/Pages/New-Annex-A-for-ETCS-Baseline-3-and-GSM-R-Baseline-0.aspx
- 5.Hansen, J.B.: A formal specification language for generic railway control systems. Master’s thesis, Technical University of Denmark, DTU Compute (2015)Google Scholar
- 9.Luteberget, B., Johansen, C., Feyling, C., Steffen, M.: Rule-based incremental verification tools applied to railway designs and regulations. In: Fitzgerald, J., Heitmeyer, C., Gnesi, S., Philippou, A. (eds.) FM 2016. LNCS, vol. 9995, pp. 772–778. Springer, Cham (2016). doi: 10.1007/978-3-319-48989-6_49 CrossRefGoogle Scholar
- 10.Mewes, K.: Domain-specific Modelling of Railway Control Systems with Integrated Verification and Validation. Verlag Dr. Hut, München (2010)Google Scholar
- 11.Peleska, J.: Industrial-strength model-based testing - state of the art and current challenges. In: Petrenko, A.K., Schlingloff, H. (eds.) Proceedings 8th Workshop on Model-Based Testing, Rome, Italy. Electronic Proceedings in Theoretical Computer Science, vol. 111, pp. 3–28. Open Publishing Association (2013)Google Scholar
- 12.Peleska, J., Baer, A., Haxthausen, A.E.: Towards domain-specific formal specification languages for railway control systems. In: Schnieder, E., Becker, U. (eds.) Proceedings of the 9th IFAC Symposium on Control in Transportation Systems 2000, 13–15 June 2000, Braunschweig, Germany, pp. 147–152 (2000)Google Scholar
- 13.Verified Systems International GmbH: RT-Tester Model-Based Test Case and Test Data Generator - RTT-MBT - User Manual (2013). http://www.verified.de
- 14.Vu, L.H., Haxthausen, A.E., Peleska, J.: A domain-specific language for railway interlocking systems. In: Schnieder, E., Tarnai, G. (eds.) FORMS/FORMAT 2014 – 10th Symposium on Formal Methods for Automation and Safety in Railway and Automotive Systems, pp. 200–209. Technische Universität Braunschweig, Institute for Traffic Safety and Automation Engineering (2014)Google Scholar
- 16.Vu, L.H.: Formal development and verification of railway control systems - in the context of ERTMS/ETCS Level 2. Ph.D. thesis, Technical University of Denmark, DTU Compute (2015)Google Scholar
- 18.Winter, K., Robinson, N.J.: Modelling large railway interlockings and model checking small ones. In: Proceedings of the 26th Australasian Computer Science Conference, ACSC 2003, vol. 16, pp. 309–316. Australian Computer Society, Inc., Darlinghurst (2003)Google Scholar