{"title":"安全关键型地铁系统的局部因果推理","authors":"E. Daylight, S. Shukla","doi":"10.1109/MEMCOD.2007.371245","DOIUrl":null,"url":null,"abstract":"Translating an informal design intent into a formal specification is an error prone process. A designer may be able to claim that his implementation meets his formal specification. But, in many cases, he cannot confidently claim that his formal specification correctly captures the original design intent. This problem, in our views, is due to global causal reasoning, as we show with LUSTRE for a Subway system. To resolve this lack of confidence, we briefly present our interactive design tool, which forces a designer to reason locally while formally specifying the design intent.","PeriodicalId":345459,"journal":{"name":"2007 5th IEEE/ACM International Conference on Formal Methods and Models for Codesign (MEMOCODE 2007)","volume":"155 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2007-05-30","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":"{\"title\":\"Local Causal Reasoning of a Safety-Critical Subway System\",\"authors\":\"E. Daylight, S. Shukla\",\"doi\":\"10.1109/MEMCOD.2007.371245\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"Translating an informal design intent into a formal specification is an error prone process. A designer may be able to claim that his implementation meets his formal specification. But, in many cases, he cannot confidently claim that his formal specification correctly captures the original design intent. This problem, in our views, is due to global causal reasoning, as we show with LUSTRE for a Subway system. To resolve this lack of confidence, we briefly present our interactive design tool, which forces a designer to reason locally while formally specifying the design intent.\",\"PeriodicalId\":345459,\"journal\":{\"name\":\"2007 5th IEEE/ACM International Conference on Formal Methods and Models for Codesign (MEMOCODE 2007)\",\"volume\":\"155 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2007-05-30\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"0\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2007 5th IEEE/ACM International Conference on Formal Methods and Models for Codesign (MEMOCODE 2007)\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/MEMCOD.2007.371245\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2007 5th IEEE/ACM International Conference on Formal Methods and Models for Codesign (MEMOCODE 2007)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/MEMCOD.2007.371245","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
Local Causal Reasoning of a Safety-Critical Subway System
Translating an informal design intent into a formal specification is an error prone process. A designer may be able to claim that his implementation meets his formal specification. But, in many cases, he cannot confidently claim that his formal specification correctly captures the original design intent. This problem, in our views, is due to global causal reasoning, as we show with LUSTRE for a Subway system. To resolve this lack of confidence, we briefly present our interactive design tool, which forces a designer to reason locally while formally specifying the design intent.