The engineering of generic requirements for failure management
Colin Snook, Michael R. Poppleton, Ian G. Johnson · ePrints Soton (University of Southampton) · 2005
Abstract. We consider the failure detection and management function for en-gine control systems as an application domain where product line engineering is indicated. The need to develop a generic requirement set- for subsequent system instantiation- is complicated by the addition of the high levels of verication demanded by this safety-critical domain, subject to avionics industry standards. We present our case study experience in this area as a candidate methodology for the engineering, validation and verication of generic requirements using domain engineering and Formal Methods techniques and tools. For a dened class of sys-tems, the case study produces a generic requirement set in UML and an example instantiation in tabular form. Domain analysis and engineering produce a model which is integrated with the formal specication / verication method B by the use of our UML-B prole. The formal verication both of the generic require-ment set, and of a simple system instance, is demonstrated using our U2B and ProB tools. This work is a demonstrator for a tool-supported method which will be an out-put of EU project RODIN3. The method, based in the dominant UML standard, will exploit formal verication technology largely as a black box for this novel combination of product line, failure management and safety-critical engineering. 1