Rogério de Lemos

dblp:09/577 · DBLP profile ↗
← Back
43ranked-venue papers
18as first author
4since 2021 · last 2025
0000-0002-0281-6308ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 18 · 9 first-author · 3 since 2021Security and privacy · 13 · 5 first-authorSystems, architecture and hardware · 9 · 4 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 1 first-authorDatabases, data management, data science and information retrieval · 1Human-computer interaction and ubiquitous computing · 1 · 1 first-authorTheory of computation · 1
YearPublicationVenuePosition
2025 An Extended Study of the Performance of Flexible Controllers Composed of Micro-controllers
abstract
Generic controllers for self-adaptive systems can be configured parametrically according to system needs, even though their reuse is restricted because of the wide range of services that may be provided by each stage of a feedback control loop, like MAPE-K. Rainbow is a typical example of such a generic, monolithic controller. This article revisits and extends prior work that advocates structurally flexible controllers, as ensembles of micro-controllers each providing specific services. We experimented with our approach with three different architectural configurations for the controller—monolithic, decentralised and decentralised with a meta-controller. Our results indicate that despite the decentralised configuration with a meta-controller demanding more computational resources, it performed comparatively well compared to the other configurations, including when measuring the target system’s response time. Moreover, we found that variations of the control loop timing at the different layers of the controller impact the stability of the target system. We have also evolved the controller by adding a new micro-controller, which caused no impact on the other micro-controllers, and mostly kept the target system’s performance. We conclude that a multi-layered controller design, based on micro-controllers, provides the basis for defining structurally flexible controllers at operational-time and may promote reuse at development-time.
Bento R. Siqueira, Fabiano Cutigi Ferrari, Rogério de Lemos
ACM Trans. Auton. Adapt. Syst.3
2023 Software Self-adaptation and Industry: Blame MAPE-K
abstract
If software self-adaptation has to be widely adopted by industry, we need to think big, embrace complexity, provide easily deployed and cost-effective solutions, and justify trust. On fairness, MAPE-K should not solely take the blame. MAPE-K is one of the many interpretations of feedback loops apply to systems for which mathematical models - mostly based on control theory, are difficult to be synthesised. MAPE-K has provided a basic and widely accepted framework for justifying the deployment of feedback loops in software systems. Undoubtedly, it has helped to promote and advance the whole area, but now more concrete and resilient solutions are necessary. This position paper argues that, first, industry has been adopting software self-adaptation, perhaps in a way that may not be recognised by the academic community, second, generic solutions are unfeasible since every software system brings its own challenges, and thirdly, the generic stages associated with a feedback loop, like MAPE-K, are insufficient to solve specific challenges.
Rogério de Lemos
SEAMS1
2023 Design and Evaluation of Controllers based on Microservices
abstract
In self-adaptive software systems, generic controllers can be configured parametrically according to system needs, even though their reuse is restricted because of the wide range of services that can be provided by each of the stages of a feedback control loop, like MAPE-K. Rainbow is a typical example of such a generic, monolithic controller. This paper advocates controllers that are structurally flexible, and which are composed from micro-controllers, each providing specific services (e.g., based on microservices). To provide evidence on the feasibility of our approach, we compare three different architectural configurations for the controller: monolithic, decentralised, and decentralised with a meta-controller. Results from our experiments indicate that even though the decentralised configuration with a meta-controller demanded more computational resources, it performed comparatively well when compared to the other configurations. We conclude that a multi-layered controller design, based on micro-controllers, provides the basis for defining structurally flexible controllers at operational-time, and may promote reuse at development-time.
Bento R. Siqueira, Fabiano Cutigi Ferrari, Rogério de Lemos
SEAMS3
2021 Testing of adaptive and context-aware systems: approaches and challenges
abstract
Summary Adaptive systems (ASs) and context‐aware systems (CASs) are able to evaluate their own behaviour and toadaptit when the system fails to accomplish its goals or when better functionality or performance is possible. Ensuring the reliability of ASs and CASs is demanding because failures might have undesirable consequences. Testing ASs and CASs effectively is not trivial because of the inherent characteristics of these systems. The literature lacks a comprehensive review that provides a broad picture of the area; current reviews are outdated and incomplete. The objectives of this study are characterizing the state of the art in AS and CAS testing and discussing approaches, challenges, observed trends, and research limitations and directions. We performed a systematic literature review (SLR) and a thematic analysis of studies, reporting up‐to‐date, refined and extended results when compared with existing reviews. Based on 102 selected studies, we (i) characterized testing approaches by grouping techniques for ASs and CASs; (ii) updated and refined a characterization of testing challenges for ASs and CASs; and (iii) analysed and discussed research trends and implications for AS and CAS testing. There are recurring research concerns regarding AS and CAS testing. Examples are the generation of test cases and built‐in tests. Moreover, we also identified recurring testing challenges such as context monitoring and runtime decisions. Moreover, there are some trends such as model‐based testing and hybrid techniques and some little investigated issues like uncertainty and prediction of changes. All in all, our results may provide guidance for developers and researchers with respect to the practice and the future research on AS and CAS testing.
Bento R. Siqueira, Fabiano Cutigi Ferrari, Kathiani Elisa de Souza, Valter Vieira de Camargo, Rogério de Lemos
Softw. Test. Verification Reliab.5
2020 Malicious changeload for the resilience evaluation of self-adaptive authorisation infrastructures
Rogério de Lemos
Future Gener. Comput. Syst.2
2020 A cloud-edge based data security architecture for sharing and analysing cyber threat information
abstract
Cyber-attacks affect every aspect of our lives. These attacks have serious consequences, not only for cyber-security, but also for safety, as the cyber and physical worlds are increasingly linked. Providing effective cyber-security requires cooperation and collaboration among all the entities involved. Increasing the amount of cyber threat information (CTI) available for analysis allows better prediction, prevention and mitigation of cyber-attacks. However, organizations are deterred from sharing their CTI over concerns that sensitive and confidential information may be revealed to others. We address this concern by providing a flexible framework that allows the confidential sharing of CTI for analysis between collaborators. We propose a five-level trust model for a cloud-edge based data sharing infrastructure. The data owner can choose an appropriate trust level and CTI data sanitization approach, ranging from plain text, through anonymization/pseudonymization to homomorphic encryption, in order to manipulate the CTI data prior to sharing it for analysis. Furthermore, this sanitization can be performed by either an edge device or by the cloud service provider, depending upon the level of trust the organization has in the latter. We describe our trust model, our cloud-edge infrastructure, and its deployment model, which are designed to satisfy the broadest range of requirements for confidential CTI data sharing. Finally we briefly describe our implementation and the testing that has been carried out so far by four pilot projects that are validating our infrastructure.
David W. Chadwick, Wenjun Fan, Gianpiero Costantino, Rogério de Lemos, Francesco Di Cerbo, Ian Herwono, Mirko Manea, Paolo Mori, Ali Sajjad, Xiao-Si Wang
Future Gener. Comput. Syst.4
2018 Risks of Sharing Cyber Incident Information
abstract
Incident information sharing is being encouraged and mandated as a way of improving overall cyber intelligence and defense, but its take up is slow. Organisations may well be justified in perceiving risks in sharing and disclosing cyber incident information, but they tend to express such worries in broad and vague terms. This paper presents a specific and granular analysis of the risks in cyber incident information sharing, looking in detail at what information may be contained in incident reports and which specific risks are associated with its disclosure. We use the STIX incident model as indicative of the types of information that might be reported. For each data field included, we identify and evaluate the threats associated with its disclosure, including the extent to which it identifies organisations and individuals. The main outcome of this analysis is a detailed understanding of which information in cyber incident reports requires protection, against specific threats with assessed severity. A secondary outcome of the analysis is a set of guidelines for disciplined use of the STIX incident model in order to reduce information security risk.
Adham Albakri, Eerke A. Boiten, Rogério de Lemos
ARES3
2018 Evaluating Self-Adaptive Authorisation Infrastructures Through Gamification
abstract
Self-adaptive systems are able to modify their behaviour and/or structure in response to changes that occur to the system itself, its environment, or even its goals. In terms of authorisation infrastructures, self-adaptation has been shown to provide runtime capabilities for specifying and enforcing access control policies and subject access privileges, with a goal to mitigate insider threat. The evaluation of self-adaptive authorisation infrastructures, particularly, in the context of insider threats, is challenging because simulation of malicious behaviour can only demonstrate a fraction of the types of abuse that is representative of the real-world. In this paper, we present an innovative approach based on an ethical game of hacking, protected by an authorisation infrastructure. A key feature of the approach is the ability to observe user activity pre- and post-adaptation when evaluating runtime consequences of self-adaptation. Our live experiments captured a wide range of unpredictable changes, including malicious behaviour related to the exploitation of known vulnerabilities. As an outcome, we demonstrated the ability of our self-adaptive authorisation infrastructure to handle malicious behaviour given the existence of real and intelligent users, in addition to capturing how users responded to adaptation.
Christopher Bailey 0003, Rogério de Lemos
DSN2
2017 Robustness-Driven Resilience Evaluation of Self-Adaptive Software Systems
abstract
An increasingly important requirement for certain classes of software-intensive systems is the ability to self-adapt their structure and behavior at run-time when reacting to changes that may occur to the system, its environment, or its goals. A major challenge related to self-adaptive software systems is the ability to provide assurances of their resilience when facing changes. Since in these systems, the components that act as controllers of a target system incorporate highly complex software, there is the need to analyze the impact that controller failures might have on the services delivered by the system. In this paper, we present a novel approach for evaluating the resilience of self-adaptive software systems by applying robustness testing techniques to the controller to uncover failures that can affect system resilience. The approach for evaluating resilience, which is based on probabilistic model checking, quantifies the probability of satisfaction of system properties when the target system is subject to controller failures. The feasibility of the proposed approach is evaluated in the context of an industrial middleware system used to monitor and manage highly populated networks of devices, which was implemented using the Rainbow framework for architecture-based self-adaptation.
Javier Cámara 0001, Rogério de Lemos, Nuno Laranjeiro, Rafael Ventura, Marco Vieira
IEEE Trans. Dependable Secur. Comput.2
2016 Incorporating architecture-based self-adaptation into an adaptive industrial software system
Javier Cámara 0001, Pedro Correia, Rogério de Lemos, David Garlan, Bradley R. Schmerl, Rafael Ventura
J. Syst. Softw.3
2014 Self-adaptive federated authorization infrastructures
Christopher Bailey 0003, David W. Chadwick, Rogério de Lemos
J. Comput. Syst. Sci.3
2011 Self-Adaptive Authorization Framework for Policy Based RBAC/ABAC Models
abstract
Authorization systems are an integral part of any network where resources need to be protected. They act as the gateway for providing (or denying) subjects (users) access to resources. As networks expand and organisations start to federate access to their resources, authorization infrastructures become increasingly difficult to manage. In this paper, we explore the potential of self-adaptive authorization as a means to automate the management of the access control configuration. We propose a Self-Adaptive Authorization Framework (SAAF) that is capable of managing any policy based distributed RBAC/ABAC authorization infrastructure. SAAF relies on a feedback control loop to monitor decisions (by policy decision points) of a target authorization infrastructure. These decisions are analysed to form a view of the subject's behaviour to decide whether to adapt the target authorization infrastructure. Adaptations are made in order to either endorse or restrict the identified behaviour, e.g. by loosening or tightening the current authorization policy. We demonstrate in terms of representative scenarios SAAF's ability for detecting abnormal behaviour, such as, misuse of access to system resources, proposing solutions that either prevent/endorse such behaviour, applying a cost function to each of these solutions, and executing the adaptive changes against a target authorization infrastructure.
Christopher Bailey 0003, David W. Chadwick, Rogério de Lemos
DASC3
2011 Workshop on assurances for self-adaptive systems (ASAS 2011)
abstract
Assurances for Self-Adaptive Systems (ASAS) is a workshop that will bring together researchers to discuss software engineering aspects of self-adaptive systems, including methods, architectures, languages, algorithms, techniques, and tools that can be used to support assurances in self-adaptive system development. ASAS is intended as a complement to the efforts started a while ago at the successful FSE workshop series on Self-Healing Systems (WOSS), or the Software Engineering for Adaptive and Self-Managing Systems (SEAMS) symposium. However, in contrast with those events, ASAS is focused on the collection, storage, and analysis of evidence for the provision of assurances that a self-adaptive software system is able to behave functionally and non-functionally according to its specification.
Javier Cámara 0001, Rogério de Lemos, Carlo Ghezzi, Antónia Lopes
SIGSOFT FSE2
2010 Fifth Workshop on Software Engineering for Adaptive and Self-Managing Systems (SEAMS 2010)
abstract
The Software Engineering for Adaptive and Self-managing Systems (SEAMS) workshop has consolidated the interest in the software engineering community on self-adaptive and self-managing systems. SEAMS provides a forum for researchers and practitioners to share new results, discuss challenging issues, raise awareness, and promote collaboration within the community. The SEAMS 2010 workshop aims to continue the success of previous ICSE SEAMS workshops: in Shanghai in 2006, in Minneapolis in 2007, in Leipzig in 2008, and in Vancouver in 2009.
Betty H. C. Cheng, Rogério de Lemos, David Garlan, Holger Giese, Marin Litoiu, Jeff Magee, Hausi A. Müller, Mauro Pezzè, Richard N. Taylor
ICSE (2)2
2009 Workshop on Architecting Dependable Systems (WADS 2009)
abstract
This workshop summary gives a brief overview of the workshop on “Architecting Dependable Systems” held in conjunction with DSN 2009. The main aim of this workshop is to promote cross-fertilization between the software architecture and dependability communities. We believe that both of them will benefit from clarifying approaches that have been previously tested and have succeeded as well as those that have been tried but have not yet been shown to be successful.
António Casimiro, Rogério de Lemos, Cristina Gacek
DSN2
2009 Architecting Fault Tolerance with Exception Handling: Verification and Validation
Patrick Henrique da S. Brito, Rogério de Lemos, Cecília M. F. Rubira, Eliane Martins
J. Comput. Sci. Technol.2
2008 Workshop on Architecting Dependable Systems (WADS 2008)
abstract
This workshop summary gives a brief overview of the workshop on ldquoArchitecting Dependable Systemsrdquo held in conjunction with DSN 2008. The main aim of this workshop is to promote cross-fertilization between the software architecture and dependability communities. We believe that both of them will benefit from clarifying approaches that have been previously tested and have succeeded as well as those that have been tried but have not yet been shown to be successful.
Rogério de Lemos, Jean-Charles Fabre, Cristina Gacek
DSN1
2008 Development of Fault-Tolerant Software Systems Based on Architectural Abstractions
Patrick Henrique da S. Brito, Rogério de Lemos, Cecília M. F. Rubira
ECSA2
2008 Artificial iImmune systems for data fusion: A novel biologically inspired approach
Adam Knowles, Jonathan Timmis, Rogério de Lemos, Simon Forrest, Heather McCracken
FUSION3
2007 Workshop on Architecting Dependable Systems (WADS 2007)
abstract
This workshop summary gives a brief overview of the workshop on "Architecting Dependable Systems" held in conjunction with DSN 2007. The main aim of this workshop is to promote cross-fertilization between the software architecture and dependability communities. We believe that both of them will benefit from clarifying approaches that have been previously tested and have succeeded as well as those that have been tried but have not yet been shown to be successful.
Rogério de Lemos, Felicita Di Giandomenico, Cristina Gacek
DSN1
2007 Immune-Inspired Adaptable Error Detection for Automated Teller Machines
abstract
This paper presents an immune-inspired adaptable error detection (AED) framework for automated teller machines (ATMs). This framework has two levels: one is local to a single ATM, while the other is network-wide. The framework employs vaccination and adaptability analogies of the immune system. For discriminating between normal and erroneous states, an immune-inspired one-class supervised algorithm was employed, which supports continual learning and adaptation. The effectiveness of the proposed approach was confirmed in terms of classification performance and impact on availability. The overall results are encouraging as the downtime of ATMs can de reduced by anticipating the occurrence of failures before they actually occur.
Rogério de Lemos, Jonathan Timmis, Modupe Ayara, Simon Forrest
IEEE Trans. Syst. Man Cybern. Part C1
2006 Workshop on Architecting Dependable Systems (WADS)
abstract
This workshop will continue the initiative, which started four years ago, of bringing together the international communities of dependability and software architectures. The first workshop on Architecting Dependable Systems was organised during the International Conference on Software Engineering 2002 (ICSE), and since then five workshops were organised and three books were published (http://www.cs.kent.ac.uk/wads). This activity has culminated in 2004 with the organisation of the Twin Workshops that were held at ICSE 2004 and DSN 2004. This series of workshops have shown to be a fertile ground for both communities for clarifying approaches that have been previously tried and succeeded, as well as those that have been tried but have not yet shown to be successful. This not only helps avoid the reinvention of the wheel, but also clarifies and promotes areas where the most promising research may lie.
Rogério de Lemos, Cristina Gacek, Alexander B. Romanovsky
DSN1
2006 Software engineering for adaptive and self-managing systems
abstract
The objective of this workshop is to consolidate the interest in the software engineering community on autonomic, self-managing, self-healing, self-optimizing, self-configuring, and self-adaptive systems. The workshop will provide a forum for researchers to share new results, raise awareness of new adaptive concerns, and promote collaboration among the community. This workshop will be the first of several to assess progress and identify challenges in this important area.
Betty H. C. Cheng, David Garlan, Rogério de Lemos, Jeff Magee, Richard N. Taylor, Stephen Fickas, Hausi A. Müller
ICSE3
2006 Software architectures for dependable systems: a software engineering perspective
abstract
Although there is a large body of research in dependability, architectural level reasoning about dependability is only just emerging as an important theme in software development. This is due to the fact that dependability concerns are often left until too late in the process of development. In addition, the complexity of emerging applications and the trend of building trustworthy systems from existing untrustworthy components are urging dependability concerns to be considered at the architectural level. This tutorial will present the current challenges and promising solutions for structuring dependable systems at the architectural level. In addition of providing basic concepts related to dependability and software architectures, the rest of the tutorial is presented in the context of the dependability technologies. Throughout the tutorial, case studies will be used to exemplify the key concepts.
Rogério de Lemos
ICSE1
2006 Architecting dependable systems
Rogério de Lemos, Cristina Gacek, Alexander B. Romanovsky
J. Syst. Softw.1
2005 Workshop on architecting dependable systems (WADS 2005)
abstract
This workshop summary gives a brief overview of the workshop on "Architecting Dependable Systems" held in conjunction with the ICSE 2005. The main aim of this workshop is to promote cross-fertilization between the software architecture and dependability communities. We believe that both of them will benefit from clarifying approaches that have been previously tested and have succeeded as well as those that have been tried but have not yet been shown to be successful.
Rogério de Lemos, Alexander B. Romanovsky
ICSE1
2005 Exception handling in the development of dependable component-based systems
abstract
Exception handling is a structuring technique that facilitates the design of software systems by encapsulating the process of error recovery. In this paper, we present a systematic approach for incorporating exceptional behaviour in the development of component-based software. The premise of our approach is that components alone do not provide the appropriate means to deal with exceptional behaviour in an effective manner, hence the need to consider the notion of collaborations for capturing the interactive behaviour between components when error recovery involves more than one component. The feasibility of the approach is demonstrated in terms of the mining control system case study. Copyright © 2004 John Wiley & Sons, Ltd.
Cecília M. F. Rubira, Rogério de Lemos, Gisele Rodrigues Mesquita Ferreira, Fernando Castor Filho
Softw. Pract. Exp.2
2004 Twin Workshops on Architecting Dependable Systems (WADS 2004)
Rogério de Lemos, Cristina Gacek, Alexander B. Romanovsky
DSN1
2004 Twin Workshops on Architecting Dependable Systems (WADS 2004)
Rogério de Lemos, Cristina Gacek, Alexander B. Romanovsky
ICSE1
2004 Analysing failure behaviours in component interaction
Rogério de Lemos
J. Syst. Softw.1
2003 ICSE 2003 Workshop on Software Architectures for Dependable Systems
abstract
This workshop summary gives a brief overview of a one-day workshop on "Software Architectures for Dependable Systems" held in conjunctions with ICSE 2003.
Rogério de Lemos, Cristina Gacek, Alexander B. Romanovsky
ICSE1
2003 Integrating COTS Software Components into Dependable Software Architectures
abstract
This paper considers the problem of integrating commercial off-the-shelf (COTS) software components into systems with high dependability requirements. These components, by their very nature, are built to be reused as black boxes that cannot be modified. Instead, the system architect has to rely on techniques external with respect to the component for resolving mismatches of the services required and provided that might arise in the interaction of the component and its environment. This paper proposes an architectural solution to turning COTS components into idealised fault-tolerant COTS components by adding protective wrappers to them.
Paulo Asterio de Castro Guerra, Alexander B. Romanovsky, Rogério de Lemos
ISORC3
2003 A fault-tolerant software architecture for COTS-based software systems
abstract
This paper considers the problem of integrating Commercial offthe-shelf (COTS) components into systems with high dependability requirements. Such components are built to be reused as black boxes that cannot be modified. The system architect has to rely on techniques that are external to the component for resolving mismatches between the services required and provided that might arise in the interaction of the component and its environment. The paper puts forward an approach that employs the layer-based C2 architectural style for structuring error detection and recovery mechanisms to be added to the component during system integration.
Paulo Asterio de Castro Guerra, Cecília M. F. Rubira, Alexander B. Romanovsky, Rogério de Lemos
ESEC / SIGSOFT FSE4
2002 ICSE 2002 workshop on architecting dependable systems
abstract
This workshop summary gives a brief overview of a one day workshop on "Architecting Dependable Systems" held in conjunctions with ICSE 2002.
Rogério de Lemos, Cristina Gacek, Alexander B. Romanovsky
ICSE1
2001 Describing Evolving Dependable Systems Using Co-Operative Software Architectures
abstract
The paper describes an architectural approach that facilitates the modelling and analysis of dependable systems that are built from untrustworthy components whose designs, we assume, cannot be changed. The approach is based on the definition of an architectural style in which connectors are considered as first class entities, which embody the description of collaborative behaviour between components. This style is shown to be particularly suitable for describing system components that have to evolve in order for the system to provide dependable services. The feasibility of the proposed architectural style in dealing with evolving dependable systems is demonstrated in terms of a gas station case study.
Rogério de Lemos
ICSM1
1999 Exception Handling in a Cooperative Object-Oriented Approach
abstract
A cooperative action (CO action) is a modelling abstraction for representing collaborative behaviour between objects at different phases of the software development. In this paper, the original definition of a cooperative object-oriented approach for software development is extended in order to include the description of exceptional behaviour. Unlike the traditional methods that usually deal with exceptions at the late design and implementation phases, the proposed approach emphasises the separation of treatments of application-related, design-related and implementation-related exceptions during the software life-cycle. The feasibility of the approach is demonstrated in terms of a benchmark case study.
Rogério de Lemos, Alexander B. Romanovsky
ISORC1
1999 Safety Analysis Techniques for Validating Formal Models During Verification
Rogério de Lemos, Amer Saeed
SAFECOMP1
1998 Coordinated Atomic Actions in Modelling Objects Cooperation
abstract
The approach described in this paper makes use of Coordinated Atomic Actions (CA actions)-a structural design mechanism, for representing the cooperation between objects, at different stages of the software development. The original concept of a CA action has been expanded for accommodating the modelling needs of the initial stages of software development. One of the motivations for using CA actions in an OO approach, is the ability of CA actions to extract from the specification of an object those issues which are related with its the collaborative activities, thus avoiding that a specification of a cooperation be scattered among the specifications of the objects. The feasibility of the approach is demonstrated in terms of a benchmark case study.
Rogério de Lemos, Alexander B. Romanovsky
ISORC1
1997 An Object-Based Approach to Modelling and Analysis of Failure Properties
Marko Cepin, Rogério de Lemos, Borut Mavko, Steve Riddle, Amer Saeed
SAFECOMP2
1995 Safety Analysis for Requirements Specifications: Methods and Techniques
Amer Saeed, Rogério de Lemos, Tom Anderson 0001
SAFECOMP2
1993 Robust Requirements Specifications for Safety - Critical Systems
Amer Saeed, Rogério de Lemos, Tom Anderson 0001
SAFECOMP2
1992 A Train Set as a Case Study for the Requirements Analysis of Safety-Critical Systems
abstract
Requirements analysis plays a vital role in the development of safety-critical systems since any faults in the requirements specification will corrupt the subsequent stages of system development. Experience in safety-critical systems has shown that faults in the requirements can and do cause disasters. The analysis of the safety requirements of a train set system is discussed in terms of a general framework for the requirements analysis of safety-critical systems. This framework is based on the clear separation of the mission and safety issues, and also on the separation of the analysis, into two phases, to be performed in terms of the properties of the real world, i.e. physical laws and rules of operation, and the properties of the system, i.e. the mapping of the real world properties in terms of the system sensors and actuators. Due to the different expressive needs of the two phases we propose the utilisation of different formal models, respectively, a logical formalism (Timed History Logic) and a net formalism (Predicate-Transition nets).
Rogério de Lemos, Amer Saeed, Tom Anderson 0001
Comput. J.1
1990 A Robust Group Membership Algorithm for Distributed Real-Time Systems
abstract
An algorithm is presented by which nonfaulty processors of a group of fixed size will be able to maintain a consistent and timely knowledge of the group membership. The authors assume an architecture in which the broadcast network is accessed by some time domain multiplexing techniques where the exclusive right to transmit messages is granted to each processor once in every 'cycle'. In an execution of the proposed algorithm, every nonfaulty processor knows of any processor failure within at most two cycles following the cycle in which the failure occurred, and a restarted processor can join the group in two cycles. At most less than half the number of processors are assumed to fail in any three consecutive cycles.>
Paul D. Ezhilchelvan, Rogério de Lemos
RTSS2