Abstract
State-of-the-art railway interlocking systems typically adhere to the product line paradigm, where each individual system is obtained by instantiating a generic system with configuration data. In this paper, we present a domain-specific language, IDL, for specifying generic behavioural models and generic properties of interlocking systems. An IDL specification of a generic model consists of generic variable declarations and generic transition rules, and generic properties are generic state invariants. Generic models and generic properties can be instantiated with configuration data. This results in concrete models and concrete properties that can be used as input for a model checker to formally verify that the system model satisfies desired state invariants. The language and a configuration data instantiator based on the semantics have been implemented as components of the RobustRailS tool set for formal specification and verification of interlocking systems. They have successfully been applied to (1) define a generic model and generic safety properties for the new Danish interlocking systems and to (2) instantiate these generic artefacts for real-world stations and lines in Denmark. A novelty of this work is to provide a domain-specific language for generic models and an instantiator tool taking not only configuration data but also a generic model as input instead of using a hard-coded generator for instantiating only one fixed generic model and its properties with configuration data.
L.H. Vu and A.E. Haxthausen research has been funded by the RobustRailS project granted by Innovation Fund Denmark.
Access this chapter
Tax calculation will be finalised at checkout
Purchases are for personal use only
Notes
- 1.
- 2.
Encodings are similar to classes in object-oriented languages, but only allow for the declaration of variables (fields). Moreover, the variables can only be specified for a pre-defined set elem-ty of interlocking-related elements (objects).
- 3.
Here it is assumed that the last element of route r is not a point, so that the next element is uniquely determined. This assumption is realistic for real interlocking systems.
- 4.
This priority operator was invented by Hansen in [5].
References
Cao, Y., Xu, T., Tang, T., Wang, H., Zhao, L.: Automatic generation and verification of interlocking tables based on domain specific language for computer based interlocking systems (dsl-cbi). In: Proceedings of the IEEE International Conference on Computer Science and Automation Engineering (CSAE 2011), pp. 511–515. IEEE (2011)
CENELEC European Committee for Electrotechnical Standardization: EN 50128: 2011 - Railway applications - Communications, signalling and processing systems - Software for railway control and protection systems (2011)
European Railway Agency: Annex A for ETCS Baseline 3 and GSM-R Baseline 0, April 2012. http://www.era.europa.eu/Document-Register/Pages/New-Annex-A-for-ETCS-Baseline-3-and-GSM-R-Baseline-0.aspx
Hansen, H.H., Ketema, J., Luttik, B., Mousavi, M.R., van de Pol, J.: Towards model checking executable UML specifications in mCRL2. Innovations Syst. Softw. Eng. 6(1), 83–90 (2010)
Hansen, J.B.: A formal specification language for generic railway control systems. Master’s thesis, Technical University of Denmark, DTU Compute (2015)
Haxthausen, A.E.: Automated generation of formal safety conditions from railway interlocking tables. Int. J. Softw. Tools Technol. Transfer (STTT) 16(6), 713–726 (2014). Special Issue on Formal Methods for Railway Control Systems
Haxthausen, A.E., Østergaard, P.H.: On the use of static checking in the verification of interlocking systems. In: Margaria, T., Steffen, B. (eds.) ISoLA 2016. LNCS, vol. 9953, pp. 266–278. Springer, Cham (2016). doi:10.1007/978-3-319-47169-3_19
James, P., Roggenbach, M.: Encapsulating formal methods within domain specific languages: a solution for verifying railway scheme plans. Math. Comput. Sci. 8(1), 11–38 (2014)
Luteberget, B., Johansen, C., Feyling, C., Steffen, M.: Rule-based incremental verification tools applied to railway designs and regulations. In: Fitzgerald, J., Heitmeyer, C., Gnesi, S., Philippou, A. (eds.) FM 2016. LNCS, vol. 9995, pp. 772–778. Springer, Cham (2016). doi:10.1007/978-3-319-48989-6_49
Mewes, K.: Domain-specific Modelling of Railway Control Systems with Integrated Verification and Validation. Verlag Dr. Hut, München (2010)
Peleska, J.: Industrial-strength model-based testing - state of the art and current challenges. In: Petrenko, A.K., Schlingloff, H. (eds.) Proceedings 8th Workshop on Model-Based Testing, Rome, Italy. Electronic Proceedings in Theoretical Computer Science, vol. 111, pp. 3–28. Open Publishing Association (2013)
Peleska, J., Baer, A., Haxthausen, A.E.: Towards domain-specific formal specification languages for railway control systems. In: Schnieder, E., Becker, U. (eds.) Proceedings of the 9th IFAC Symposium on Control in Transportation Systems 2000, 13–15 June 2000, Braunschweig, Germany, pp. 147–152 (2000)
Verified Systems International GmbH: RT-Tester Model-Based Test Case and Test Data Generator - RTT-MBT - User Manual (2013). http://www.verified.de
Vu, L.H., Haxthausen, A.E., Peleska, J.: A domain-specific language for railway interlocking systems. In: Schnieder, E., Tarnai, G. (eds.) FORMS/FORMAT 2014 – 10th Symposium on Formal Methods for Automation and Safety in Railway and Automotive Systems, pp. 200–209. Technische Universität Braunschweig, Institute for Traffic Safety and Automation Engineering (2014)
Vu, L.H., Haxthausen, A.E., Peleska, J.: Formal modeling and verification of interlocking systems featuring sequential release. In: Artho, C., Ölveczky, P.C. (eds.) FTSCS 2014. CCIS, vol. 476, pp. 223–238. Springer, Cham (2015). doi:10.1007/978-3-319-17581-2_15
Vu, L.H.: Formal development and verification of railway control systems - in the context of ERTMS/ETCS Level 2. Ph.D. thesis, Technical University of Denmark, DTU Compute (2015)
Vu, L.H., Haxthausen, A.E., Peleska, J.: Formal modelling and verification of interlocking systems featuring sequential release. Sci. Comput. Program. 133(Part 2), 91–115 (2017). http://dx.doi.org/10.1016/j.scico.2016.05.010
Winter, K., Robinson, N.J.: Modelling large railway interlockings and model checking small ones. In: Proceedings of the 26th Australasian Computer Science Conference, ACSC 2003, vol. 16, pp. 309–316. Australian Computer Society, Inc., Darlinghurst (2003)
Acknowledgements
The authors would like to thank Ross Edwin Gammon and Nikhil Mohan Pande from Banedanmark (Railnet Denmark) and Jan Bertelsen from Thales for helping us with their expertise about Danish interlocking systems; and Dr.-Ing. Uwe Schulze and Florian Lapschies from University of Bremen for their help with the implementation in the RT-Tester tool-chain.
Author information
Authors and Affiliations
Corresponding author
Editor information
Editors and Affiliations
Rights and permissions
Copyright information
© 2017 Springer International Publishing AG
About this paper
Cite this paper
Vu, L.H., Haxthausen, A.E., Peleska, J. (2017). A Domain-Specific Language for Generic Interlocking Models and Their Properties. In: Fantechi, A., Lecomte, T., Romanovsky, A. (eds) Reliability, Safety, and Security of Railway Systems. Modelling, Analysis, Verification, and Certification. RSSRail 2017. Lecture Notes in Computer Science(), vol 10598. Springer, Cham. https://doi.org/10.1007/978-3-319-68499-4_7
Download citation
DOI: https://doi.org/10.1007/978-3-319-68499-4_7
Published:
Publisher Name: Springer, Cham
Print ISBN: 978-3-319-68498-7
Online ISBN: 978-3-319-68499-4
eBook Packages: Computer ScienceComputer Science (R0)