{"title":"新一代列车控制系统中主备开关安全计算机的正式验证","authors":"Shi Yu, Lian-chuan Ma, Yuan Cao","doi":"10.1109/MAPE.2017.8250817","DOIUrl":null,"url":null,"abstract":"The next generation of train-control safety computer is designed as double-redundant systems as safety-critical system. Due to the complexity of the safety computer logic, the active-standby switching between the two subsystems involves multiple state transition under several different conditions. The correctness of the switching process needs to be confirmed by formal verification. In this paper, the UML is used to establish the model and the NuSMV is used to formalize the model. An analysis of multiple-faults situation and the dual-hoststate is carried out. According to the result of model checking, an improvement was proposed to optimize the switching process.","PeriodicalId":320947,"journal":{"name":"2017 7th IEEE International Symposium on Microwave, Antenna, Propagation, and EMC Technologies (MAPE)","volume":"379 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2017-10-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":"{\"title\":\"Formal verification of active-standby switchingon safety computer in next generation train control system\",\"authors\":\"Shi Yu, Lian-chuan Ma, Yuan Cao\",\"doi\":\"10.1109/MAPE.2017.8250817\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"The next generation of train-control safety computer is designed as double-redundant systems as safety-critical system. Due to the complexity of the safety computer logic, the active-standby switching between the two subsystems involves multiple state transition under several different conditions. The correctness of the switching process needs to be confirmed by formal verification. In this paper, the UML is used to establish the model and the NuSMV is used to formalize the model. An analysis of multiple-faults situation and the dual-hoststate is carried out. According to the result of model checking, an improvement was proposed to optimize the switching process.\",\"PeriodicalId\":320947,\"journal\":{\"name\":\"2017 7th IEEE International Symposium on Microwave, Antenna, Propagation, and EMC Technologies (MAPE)\",\"volume\":\"379 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2017-10-01\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"0\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2017 7th IEEE International Symposium on Microwave, Antenna, Propagation, and EMC Technologies (MAPE)\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/MAPE.2017.8250817\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2017 7th IEEE International Symposium on Microwave, Antenna, Propagation, and EMC Technologies (MAPE)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/MAPE.2017.8250817","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
Formal verification of active-standby switchingon safety computer in next generation train control system
The next generation of train-control safety computer is designed as double-redundant systems as safety-critical system. Due to the complexity of the safety computer logic, the active-standby switching between the two subsystems involves multiple state transition under several different conditions. The correctness of the switching process needs to be confirmed by formal verification. In this paper, the UML is used to establish the model and the NuSMV is used to formalize the model. An analysis of multiple-faults situation and the dual-hoststate is carried out. According to the result of model checking, an improvement was proposed to optimize the switching process.