VLDB 2026 Research / reviewers in the wild / expert
Barbara Gallina
dblp:34/3823
· DBLP profile ↗
50ranked-venue papers
17as first author
14since 2021 · last 2025
0000-0002-6952-1053ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 39 · 16 first-author · 11 since 2021Security and privacy · 7 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 7 · 2 first-author · 3 since 2021Systems, architecture and hardware · 4 · 1 since 2021Artificial intelligence and machine learning · 1Databases, data management, data science and information retrieval · 1Human-computer interaction and ubiquitous computing · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Integrating Attack-Fault Trees in the ODE Metamodel to Support Safety and Security Co-Analysis in the Automotive DomainabstractIntegrating safety and security in automotive cyber-physical systems (CPS) domains (e.g. autonomous vehicles), is challenging for two main reasons. First, it is still difficult to represent the potential consequences of system failures or malicious attacks. Secondly, these systems must ensure safety and security despite unknowns and uncertainties. A Digital Dependability Identity (DDI) can facilitate this by encapsulating all dependability characteristics (e.g., design, requirements, safety, and security analysis models) of CPS’s components. The Open Dependability Exchange (ODE) metamodel is an implementation of the DDI concept, but has limitations in the interplay between safety and security. ODE is aligned with with ISO 26262 but lacks certain security concepts to be aligned with ISO 21434. Also, ODE supports modeling fault trees, but modeling attack trees and attack-fault trees still not. This paper proposes an extension to the ODE metamodel, aiming to increase coverage of ISO 21434 concepts and allowing the modeling of attack-fault trees. We built these metamodel extensions based on an analysis of the ODE metamodel, industry standards, Microsoft STRIDE model, and HEAVENS security analysis methodologies. We evaluated the proposed extensions in an illustrative example of an autonomous vehicle. Victor Luiz Grechi, André Luíz de Oliveira, Barbara Gallina, Leonardo Montecchi, Rosana T. V. Braga |
COMPSAC | 3 |
| 2025 | Regulatory Compliance-Aware System Change Management via an Ontology-Based Approach
Barbara Gallina, Markus Schweizer, Henrik Dibowski |
EuroSPI (1) | 1 |
| 2025 | Towards an ontology for process compliance with the (machinery) legislationsabstractAbstract Legislations impose requirements on the manufacturing of machinery. Typically, these requirements are interpreted and refined by (domain‐specific) technical committees and published in terms of standards. At the company level, these refined requirements are further interpreted, refined, and documented in terms of internal processes. Due to the proliferation of (interdependent) legislations and standards and the consequent increase of the cognitive complexity, at the company level, manual knowledge management is becoming more and more challenging and requires automated decision support. Despite the availability of approaches aimed at automating the decision support, no one offers a satisfactory solution. In this paper, we focus on knowledge management for process compliance and we propose a novel structured ontology. Our ontology aims at mastering (by dividing and conquering via tracing) the cognitive complexity of the compliance problem, when heterogeneous and sometimes geographically distributed knowledge‐driven organizational structures (legal department, standardization department, etc.) are involved and need to communicate. We also illustrate the potential usefulness of our proposed ontology in the context of pumps manufacturing and safety process compliance with the Machinery Directive and related harmonized standards including EN 809:1998+A1. Specifically, first, we identify the competencies that characterize departments and interdepartment interactions, then we formulate an initial set of competency questions that translate those identified competencies, then we show how the ontology can be exploited to retrieve the answers to the questions and how the answers can be exploited to build a justification for compliance. Precisely, we propose an argumentation pattern given in two different argumentation notations, and we show how it can be partly instantiated by exploiting the returned answers. The illustration also partly covers the compliance with the Machinery Regulation, expected to replace the Machinery Directive by January 2027. Finally, we sketch our intended future work. Barbara Gallina, Gergo László Steierhoffer, Thomas Young Olesen, Eszter Parajdi, Mike Aarup |
J. Softw. Evol. Process. | 1 |
| 2024 | Safety of the Intended Functionality of External Human Interfaces: Gaps and Research AgendaabstractNext-generation human-computer interactions comprise the interactions that are expected to take place between e.g., pedestrians and the so-called External Human-Machine Interfaces (EHMIs). EHMIs are expected to replace the in vehicle Driver-oriented Driver-Machine Interface in the context of high automation levels, where the driving task is fully automated. In this context, it is paramount to ensure absence of unreasonable risk due to hazards resulting from functional insufficiencies of the intended functionality or its implementation, i.e., Safety Of The Intended Functionality (SOTIF), defined in ISO 21448:2022. ISO 21448:2022 has been applied to ensure the Safety Of The Intended Driver-Machine Interface-Functionality. SOTIF does not include any specific consideration to address the so-called External Human-Machine Interface. Hence, in this position paper, we posit that the functional insufficiencies shall also embrace the socio-technical issues that might emerge in the extended automated driving system's ecosystem. These issues include faulty interactions with pedestrians, traffic-lights, and more broadly, by taking a vehicle to everything perspective (VtoX), with everything. Manabu Okada, Barbara Gallina |
COMPSAC | 2 |
| 2024 | An Ontology-Based Representation for Shaping Product Evolution in Regulated Industries
Barbara Gallina, Henrik Dibowski, Markus Schweizer |
ICSR | 1 |
| 2023 | A Knowledge Management Strategy for Seamless Compliance with the Machinery Regulation
Barbara Gallina, Thomas Young Olesen, Eszter Parajdi, Mike Aarup |
EuroSPI (1) | 1 |
| 2022 | Automating Safety Argument Change Impact Analysis for Machine Learning ComponentsabstractThe need to make sense of complex input data within a vast variety of unpredictable scenarios has been a key driver for the use of machine learning (ML), for example in Automated Driving Systems (ADS). Such systems are usually safety-critical, and therefore they need to be safety assured. In order to consider the results of the safety assurance activities (scoping uncovering previously unknown hazardous scenarios), a continuous approach to arguing safety is required, whilst iteratively improving ML-specific safety-relevant properties, such as robustness and prediction certainty. Such a continuous safety life cycle will only be practical with an efficient and effective approach to analyzing the impact of system changes on the safety case. In this paper, we propose a semi-automated approach for accurately identifying the impact of changes on safety arguments. We focus on arguments that reason about the sufficiency of the data used for the development of ML components. The approach qualitatively and quantitatively analyses the impact of changes in the input space of the considered ML component on other artifacts created during the execution of the safety life cycle, such as datasets and performance requirements and makes recommendations to safety engineers for handling the identified impact. We implement the proposed approach in a model-based safety engineering environment called FASTEN, and we demonstrate its application for an ML-based pedestrian detection component of an ADS. Carmen Cârlan, Lydia Gauerhof, Barbara Gallina, Simon Burton 0001 |
PRDC | 3 |
| 2022 | Compliance checking of software processes: A systematic literature reviewabstractAbstract The processes used to develop software need to comply with normative requirements (e.g., standards and regulations) to align with the market and the law. Manual compliance checking is challenging because there are numerous requirements with changing nature and different purposes. Despite the importance of automated techniques, there is not any systematic study in this field. This lack may hinder organizations from moving toward automated compliance checking practices. In this paper, we characterize the methods for automatic compliance checking of software processes, including used techniques, potential impacts, and challenges. For this, we undertake a systematic literature review (SLR) of studies reporting methods in this field. As a result, we identify solutions that use different techniques (e.g., anthologies and metamodels) to represent processes and their artifacts (e.g., tasks and roles). Various languages, which have diverse capabilities for managing competing and changing norms, and agile strategies, are also used to represent normative requirements. Most solutions require tool‐support concretization and enhanced capabilities to handle processes and normative diversity. Our findings outline compelling areas for future research. In particular, there is a need to select suitable languages for consolidating a generic and normative‐agnostic solution, increase automation levels, tool support, and boost the application in practice by improving usability aspects. Julieth Patricia Castellanos Ardila, Barbara Gallina, Faiz Ul Muram |
J. Softw. Evol. Process. | 2 |
| 2021 | On-line Meetings for Educating the Minds of Future Safety Engineers during the COVID Pandemic: An Experience ReportabstractWorld-wide opportunities for “meetings of minds” was the goal of the research of visionaries who contributed to the creation of networked communication systems. During 2020, as a result of the COVID-19 pandemic, educational institutes massively exploited these systems enabling virtual spaces of synchronous and asynchronous meetings among students and among students and teachers. Technology alone, however, is not sufficient. Technological Pedagogical And Content Knowledge (TPACK) and competence are paramount. In this paper, I report about my experience in pedagogically designing and implementing an on-line version of an advanced master course on safety-critical systems engineering, conceived and delivered as a series of Zoom-based, and Community-Of-Inquiry (COI)-oriented meetings plus Canvas-based threads of discussions for educating the minds of future safety and software engineers. I also report about the limited but still talkative COI-specific questionnaire-based evaluation, conducted with the purpose of better understanding the limits of moving the course on line and elicit areas of improvement, given that likely education on-line is now here to stay. Finally, I elaborate on a roadmap for future development, based on the results from the first instance. Barbara Gallina |
CSEDU (2) | 1 |
| 2021 | Reusing (Safety-oriented) Compliance Artifacts while Recertifying
Julieth Patricia Castellanos Ardila, Barbara Gallina |
MODELSWARD | 2 |
| 2021 | Safety Case Maintenance: A Systematic Literature Review
Carmen Cârlan, Barbara Gallina, Liana Soima |
SAFECOMP | 2 |
| 2021 | A case study for risk assessment in AR-equipped socio-technical systemsabstractAugmented Reality (AR) technologies are used as human–machine interface within various types of safety-critical systems. Several studies have shown that AR improves human performance. However, the introduction of AR might introduce risks due to new types of dependability threats. In order to avoid unreasonable risk, it is required to detect new types of dependability threats (faults, errors, failures). In our previous work, we have designed extensions for the SafeConcert metamodel (a metamodel for modeling socio-technical systems) to capture AR-related dependability threats (focusing on faults and failures). Despite the availability of various modeling techniques, there has been no detailed investigation of providing an integrated framework for risk assessment in AR-equipped socio-technical systems. Hence, in this paper, we provide an integrated framework based on our previously proposed extensions. In addition, in cooperation with our industrial partners, active in the automotive domain, we design and execute a case study. We aim at verifying the modeling and analysis capabilities of our framework and finding out if the proposed extensions are helpful in capturing system risks caused by new AR-related dependability threats. Our conducted qualitative analysis is based on the Concerto-FLA analysis technique, which is included in the CHESS toolset and targets socio-technical systems. Soheila Sheikh Bahaei, Barbara Gallina, Marko Vidovic |
J. Syst. Archit. | 2 |
| 2021 | Product-line assurance cases from contract-based design
Damir Nesic, Mattias Nyberg, Barbara Gallina |
J. Syst. Softw. | 3 |
| 2021 | Specification and automated verification of atomic concurrent real-time transactionsabstractAbstract Many database management systems (DBMS) need to ensure atomicity and isolation of transactions for logical data consistency, as well as to guarantee temporal correctness of the executed transactions. Since the mechanisms for atomicity and isolation may lead to breaching temporal correctness, trade-offs between these properties are often required during the DBMS design. To be able to address this concern, we have previously proposed the pattern-based UPPCART framework, which models the transactions and the DBMS mechanisms as timed automata, and verifies the trade-offs with provable guarantee. However, the manual construction of UPPCART models can require considerable effort and is prone to errors. In this paper, we advance the formal analysis of atomic concurrent real-time transactions with tool-automated construction of UPPCART models. The latter are generated automatically from our previously proposed UTRAN specifications, which are high-level UML-based specifications familiar to designers. To achieve this, we first propose formal definitions for the modeling patterns in UPPCART, as well as for the pattern-based construction of DBMS models, respectively. Based on this, we establish a translational semantics from UTRAN specifications to UPPCART models, to provide the former with a formal semantics relying on timed automata, and develop a tool that implements the automated transformation. We also extend the expressiveness of UTRAN and UPPCART, to incorporate transaction sequences and their timing properties. We demonstrate the specification in UTRAN, automated transformation to UPPCART, and verification of the traded-off properties, via an industrial use case. Simin Cai, Barbara Gallina, Dag Nyström, Cristina Cerschi Seceleanu |
Softw. Syst. Model. | 2 |
| 2020 | Separation of Concerns in Process Compliance Checking: Divide-and-Conquer
Julieth Patricia Castellanos Ardila, Barbara Gallina |
EuroSPI | 2 |
| 2020 | A Barbell Strategy-oriented Regulatory Framework and Compliance Management
Barbara Gallina |
EuroSPI | 1 |
| 2020 | A Physiology-based Driver Readiness Estimation Model for Tuning ISO 26262 ControllabilityabstractWhen a hazardous situation approaches, the semi-autonomous vehicle opts for the driver as a fallback solution, unaware of the driver's readiness. During such a situation, autonomy misuse can occur when a driver becomes over-reliant on autonomous driving. For handling the hazardous event, controllability is paramount. We postulate that semi-autonomous vehicles decline their consideration in understanding the drivers' focus on the vehicle and the road. To examine the drivers' focus on the vehicle and the road we uphold that the vehicle must initiate exploring the drivers' situation awareness for the readiness, which could feasibly tune the ISO 26262 controllability. In this paper, we propose a physiology-based driver situation awareness for the readiness model through the driver's stress and drowsiness estimation. In addition, we boost the situation awareness for the readiness of the driver by enabling frequent interaction between the driver and the vehicle managing system. Moses Mariajoseph, Barbara Gallina, Marco Carli, Daniele Bibbo |
VTC Spring | 2 |
| 2020 | Special section on IST for ISSRE 2019
Barbara Gallina, Michel Cukier |
Inf. Softw. Technol. | 1 |
| 2020 | Guiding assurance of architectural design patterns for critical applications
Irfan Sljivo, Garazi Juez Uriagereka, Stefano Puri, Barbara Gallina |
J. Syst. Archit. | 4 |
| 2020 | Quantitative evaluation of tailoring within SPICE-compliant security-informed safety-oriented process linesabstractAbstract In the context of SPICE‐compliant and (security‐informed) safety processes, efficient process tailoring is necessary due to the increasing proliferation of requirements, which, if not systematised, may become an unmanageable cognitive overload leading to process degradation instead of improvement. Recently, security‐informed safety‐oriented process line engineering (SiSoPLE) has been proposed as a sound solution to systematise common and variable process elements in the context of security‐informed safety‐oriented processes described within security as well as safety‐related standards. SiSoPLE represents an extension of safety‐oriented process line engineering (SoPLE). The gain of the application of SoPLE in terms of efficient tailoring via reuse was measured in a previous work, where the GQM+ Strategies model, an extension of the goal/question/metric (GQM) paradigm, was adopted to develop a measurement model for achieving quantitative evidence. In this paper, we develop further our previously proposed measurement model to achieve quantitative evidence regarding the benefits of using process line engineering extended to SPICE‐compliant security‐informed safety processes. We then apply our extended GQM+ Strategies model on a SPICE for space‐compliant SiSoPL to illustrate and assess its usefulness. Finally, we discuss our findings and provide our perspectives on quantitative evaluation of tailoring in the context of critical‐systems engineering. Barbara Gallina |
J. Softw. Evol. Process. | 1 |
| 2019 | Statistical Model Checking for Real-Time Database Management Systems: A Case StudyabstractMany industrial control systems manage critical data using Database Management Systems (DBMS). The correctness of transactions, especially their atomicity, isolation and temporal correctness, is essential for the dependability of the entire system. Existing methods and techniques, however, either lack the ability to analyze the interplay of these properties, or do not scale well for systems with large amounts of transactions and data, and complex transaction management mechanisms. In this paper, we propose to analyze large scale real-time database systems using statistical model checking. We propose a pattern-based framework, by extending our previous work, to model the real-time DBMS as a network of stochastic timed automata, which can be analyzed by UPPAAL Statistical Model Checker. We present an industrial case study, in which we design a collision avoidance system for multiple autonomous construction vehicles, via concurrency control of a real-time DBMS. The desired properties of the designed system are analyzed using our proposed framework. Simin Cai, Barbara Gallina, Dag Nyström, Cristina Cerschi Seceleanu |
ETFA | 2 |
| 2019 | AMASS: A Large-Scale European Project to Improve the Assurance and Certification of Cyber-Physical Systems
Jose Luis de la Vara, Eugenio Parra, Alejandra Ruiz López, Barbara Gallina |
PROFES | 4 |
| 2019 | The new era of software reuseabstractThe new era of Rafael Capilla, Barbara Gallina, Carlos Cetina |
J. Softw. Evol. Process. | 2 |
| 2019 | Opportunities for software reuse in an uncertain world: From past to emerging trendsabstractAbstract Much has been investigated about software reuse since the software crisis. The development of software reuse methods, implementation techniques, and cost models has resulted in a significant amount of research over years. Nevertheless, the increasing adoption of reuse techniques, many of them subsumed under higher level software engineering processes, and advanced programming techniques that ease the way to reuse software assets, have hidden somehow in the recent years new research trends on the practice of reuse and caused the disappearance of several reuse conferences. Also, new forms of reuse like open data and feature models have brought new opportunities for reuse beyond the traditional software components. From past to present, we summarize in this research the recent history of software reuse, and we report new research areas and forms of reuse according to current needs in industry and application domains, as well as promising research trends for the upcoming years. Rafael Capilla, Barbara Gallina, Carlos Cetina, John M. Favaro |
J. Softw. Evol. Process. | 2 |
| 2018 | Enabling Compliance Checking Against Safety Standards from SPEM 2.0 Process ModelsabstractCompliance with process-based safety standards may imply the provision of a safety plan and its corresponding compliance justification. However, the provision of this justification is time-consuming since it requires that the process engineer checks the fulfillment of hundred of requirements by taking into account the evidence presented in the process entities. In this paper, we aim at supporting process engineers by introducing our compliance checking vision, which consists of the combination of process modeling capabilities via SPEM 2.0 (Systems & Software Process Engineering Metamodel) reference implementations and compliance checking capabilities via Regorous, a compliance checker, used for business processes compliance checking. Our focus is on the identification and exploitation of the appropriate (minimal set of) SPEM 2.0-like elements, available in the selected reference implementation, which can be used by Regorous for compliance checking. Then, we illustrate our vision by applying it onto a small excerpt from ISO 26262. Finally, we draw our conclusions. Julieth Patricia Castellanos Ardila, Barbara Gallina, Faiz Ul Muram |
SEAA | 2 |
| 2018 | Towards Quantitative Evaluation of Reuse Within Safety-Oriented Process Lines
Barbara Gallina, Shankar Iyer |
EuroSPI | 1 |
| 2018 | Effective Test Suite Design for Detecting Concurrency Control Faults in Distributed Transaction Systems
Simin Cai, Barbara Gallina, Dag Nyström, Cristina Cerschi Seceleanu |
ISoLA (3) | 2 |
| 2018 | Cost-aware Scheduling of Software Processes Execution in the CloudabstractUsing cloud computing to execute software processes brings several benefits to software development. In a previous work, we proposed a reference architecture, which treats software processes as wor ... Sami Alajrami, Alexander B. Romanovsky, Barbara Gallina |
MODELSWARD | 3 |
| 2018 | Specification and Formal Verification of Atomic Concurrent Real-Time TransactionsabstractAlthough atomicity, isolation and temporal correctness are crucial to the dependability of many real-time database-centric systems, the selected assurance mechanism for one property may breach another. Trading off these properties requires to specify and analyze their dependencies, together with the selected supporting mechanisms (abort recovery, concurrency control, and scheduling), which is still insufficiently supported. In this paper, we propose a UML profile, called UTRAN, for specifying atomic concurrent real-time transactions, with explicit support for all three properties and their supporting mechanisms. We also propose a pattern-based modeling framework, called UPPCART, to formalize the transactions and the mechanisms specified in UTRAN, as UPPAAL timed automata. Various mechanisms can be modeled flexibly using our reusable patterns, after which the desired properties can be verified by the UPPAAL model checker. Our techniques facilitate systematic analysis of atomicity, isolation and temporal correctness trade-offs with guarantee, thus contributing to a dependable real-time database system. Simin Cai, Barbara Gallina, Dag Nyström, Cristina Cerschi Seceleanu |
PRDC | 2 |
| 2018 | Safety-oriented process line engineering via seamless integration between EPF composer and BVR toolabstractThe integration between process engineering and variability management is required for tailoring of safety-oriented processes with variabilities to individual projects in a similar manner to the product lines. Previous studies have not adequately established the Safety-oriented Process Lines (SoPLs). This paper focuses on the seamless integration between Eclipse Process Framework (EPF) Composer and Base Variability Resolution (BVR) Tool. The former supports the major parts of the OMG's Software & Systems Process Engineering Metamodel (SPEM) Version 2.0, while the latter is a simplification and enhancement of the OMG's revised submission of Common Variability Language (CVL). The proposed integration is implemented as Eclipse plugin. It provides support for importing backend folders and files within the method library of EPF Composer, resolving problems with the files for variability management with the BVR Tool, and exporting back the resolved process models to the EPF Composer. The applicability of the implemented plugin is demonstrated by engineering an ECSS-E-ST-40C compliant SoPL for the space projects and applications. Muhammad Atif Javed, Barbara Gallina |
SPLC (2) | 2 |
| 2017 | Towards Increased Efficiency and Confidence in Process Compliance
Julieth Patricia Castellanos Ardila, Barbara Gallina |
EuroSPI | 2 |
| 2017 | Towards Systematic Compliance Evaluation Using Safety-Oriented Process Lines and Evidence Mapping
Timo Varkoi, Timo Mäkinen, Barbara Gallina, Frank Cameron, Risto Nevalainen |
EuroSPI | 3 |
| 2017 | Customized real-time data management for automotive systems: A case studyabstractReal-time DataBase Management Systems (RTDBMS) have been considered as a promising means to manage data for data-centric automotive systems. During the design of an RTDBMS, one must carefully trade off data consistency and timeliness, in order to achieve an acceptable level of both properties. Previously, we have proposed a design process called DAGGERS to facilitate a systematic customization of transaction models and decision on the run-time mechanisms. In this paper, we evaluate the applicability of DAGGERS via an industrially relevant case study that aims to design the transaction management for an onboard diagnostic system, which should guarantee both timeliness and data consistency under concurrent access. To achieve this, we apply the pattern-based approach of DAGGERS to formalize the transactions, and derive the appropriate isolation level and concurrency control algorithm guided by model checking. We show by simulation that the implementation of our designed system satisfies the desired timeliness and derived isolation, and demonstrate that DAGGERS helps to customize desired real-time transaction management prior to implementation. Simin Cai, Barbara Gallina, Dag Nyström, Cristina Cerschi Seceleanu |
IECON | 2 |
| 2017 | DAGGTAX: A Taxonomy of Data Aggregation Processes
Simin Cai, Barbara Gallina, Dag Nyström, Cristina Cerschi Seceleanu |
MEDI | 2 |
| 2017 | Arguing on Software-Level Verification Techniques Appropriateness
Carmen Cârlan, Barbara Gallina, Severin Kacianka, Ruth Breu |
SAFECOMP | 2 |
| 2017 | A method to generate reusable safety case argument-fragments from compositional safety analysis
Irfan Sljivo, Barbara Gallina, Jan Carlson, Hans A. Hansson, Stefano Puri |
J. Syst. Softw. | 2 |
| 2016 | EXE-SPEM: Towards Cloud-based Executable Software Process ModelsabstractExecuting software processes in the cloud can bring several benefits to software development. In this paper, we discuss the benefits and considerations of cloud-based software processes. EXE-SPEM is our extension of the Software and Systems Process Engineering (SPEM2.0) Meta-model to support creating cloud-based executable software process models. Since SPEM2.0 is a visual modelling language, we introduce an XML notation meta-model and mapping rules from EXE-SPEM to this notation which can be executed in a workflow engine. We demonstrate our approach by modelling an example software process using EXE-SPEM and mapping it to the XML notation. Sami Alajrami, Barbara Gallina, Alexander B. Romanovsky |
MODELSWARD | 2 |
| 2016 | Software Development in the Post-PC Era: Towards Software Development as a Service
Sami Alajrami, Alexander B. Romanovsky, Barbara Gallina |
PROFES | 3 |
| 2016 | Towards Cloud-Based Enactment of Safety-Related Processes
Sami Alajrami, Barbara Gallina, Irfan Sljivo, Alexander B. Romanovsky, Petter Isberg |
SAFECOMP | 2 |
| 2016 | Deriving Safety Case Fragments for Assessing MBASafe's Compliance with EN 50128
Barbara Gallina, Elena Gómez-Martínez, Clara Benac Earle |
SPICE | 1 |
| 2015 | A Method to Generate Reusable Safety Case Fragments from Compositional Safety Analysis
Irfan Sljivo, Barbara Gallina, Jan Carlson, Hans A. Hansson, Stefano Puri |
ICSR | 2 |
| 2015 | Using Safety Contracts to Guide the Integration of Reusable Safety Elements within ISO 26262abstractSafety-critical systems usually need to comply with a domain-specific safety standard. To reduce the cost and time needed to achieve the standard compliance, reuse of safety-relevant components is not sufficient without the reuse of the accompanying artefacts. Developing reusable safety components out-of-context of a particular system is challenging, as safety is a system property, hence support is needed to capture and validate the context assumptions before integration of the reusable component and its artefacts in-context of the particular system. We have previously developed a concept of strong and weak safety contracts to facilitate systematic reuse of safety-relevant components and their accompanying artefacts. In this work we define a safety contracts development process and provide guidelines to bridge the gap between reuse of safety elements developed out-of-context of a particular system and their integration in the ISO 26262 safety standard. We use a real-world case for demonstration of the process. Irfan Sljivo, Barbara Gallina, Jan Carlson, Hans A. Hansson |
PRDC | 2 |
| 2015 | Ontology-Based Identification of Commonalities and Variabilities Among Safety Processes
Barbara Gallina, Zoltán Szatmári |
PROFES | 1 |
| 2014 | Generation of Safety Case Argument-Fragments from Safety Contracts
Irfan Sljivo, Barbara Gallina, Jan Carlson, Hans A. Hansson |
SAFECOMP | 2 |
| 2012 | Towards a Safety-Oriented Process Line for Enabling Reuse in Safety Critical Systems Development and CertificationabstractSafety standards define development processes by indicating the set of partially ordered tasks that have to be executed to achieve acceptably safe systems. Process compliance constitutes a fundamental ingredient in safety argumentation for certification purposes. Certification is a very expensive, time-consuming and quality demanding activity. To increase quality and reduce time and cost, reuse-based approaches are being investigated. In this paper, we adopt process line approach in the framework of safety processes. This means that we treat a family of processes as a product line, and we identify commonalities and variabilities between them. The resulting information guides developers in reusing parts of the process, the system and safety case, e.g. which parts to make more generic, isolating changes in others to avoid ripple effects etc. Barbara Gallina, Irfan Sljivo, Omar Jaradat |
SEW | 1 |
| 2009 | Towards an Alloy Formal Model for Flexible Advanced Transactional Model DevelopmentabstractSPLACID is a semi-formal language conceived for the specification and synthesis of (advanced) transactional models from basic features, such as transaction types and (relaxed) ACID variants. SPLACID is an improvement of the ACTA framework offering a well-structured and formal syntax. Neither ACTA nor SPLACID, however, benefit from a formal tool-supported semantics. This paper presents the first step for having a full formal semantics of SPLACID by translation to Alloy. In particular, we present the translation of the SPLACID concepts into Alloy concepts focusing on those concepts pertaining to the structure of a Transactional Model and those characterizing the isolation variant. The Alloy specification obtained by this translation preserve the SPLACID main key-properties, namely, modularity, flexibility and reusability. To support this claim we show how flexible, modular and reusable structures and isolation variants can be obtained in Alloy. Finally, we analyze the flat and nested transactional model structures and the serializability-based isolation variant using the Alloy Analyzer. Barbara Gallina, Nicolas Guelfi, Pierre Kelsen |
SEW | 1 |
| 2008 | A Product Line Perspective for Quality Reuse of Development Frameworks for Distributed Transactional ApplicationsabstractFlexibility, autonomy, distribution and openness of the modern computing systems are properties which expand the spectrum of interactions possible among system components. Moreover these properties tend to impose more rigorous quality requirements on software development. To ensure the quality of distributed applications two notions have already been introduced: concurrency control and fault-tolerance. These notions are present and refined in so-called advanced transactional frameworks. All these frameworks have different interpretations of these two notions because they try to solve different issues. Engineering from scratch such a framework is a complex task which will achieve a low level result, if not supported by a quality oriented approach. This paper solves this issue by introducing a product line perspective founded on the semantic analysis of the variabilities and commonalities of the ACID (atomicity, isolation, durability and consistency) properties. Varying and composing ACID properties in a disciplined way is in our opinion a key issue to increase quality and quality reuse in the development of advanced transactional frameworks. For this our approach allows the elicitation of the requirements of the advanced transactional frameworks product line using the "DRET" template. Barbara Gallina, Nicolas Guelfi |
COMPSAC | 1 |
| 2008 | SPLACID: An SPL-Oriented, ACTA-Based, Language for Reusing (Varying) ACID PropertiesabstractACID (Atomicity, Consistency, Isolation and Durability) properties characterize the initial transactional model (TM). Being too restrictive and functionally limited to face the requirements of more recent application domains, the semantics of these properties has been relaxed (weakened) leading to an important set of TMs. Understanding, comparing and synthesizing TMs on the basis of core features and, more specifically, understanding and comparing relaxed ACID properties to be able to reuse them, during the synthesis of TMs, is still an unreached goal. The ACTA framework represented a relevant step towards the achievement of that goal. ACTA, however, as we contribute in highlighting, presents several points of weakness. To contribute in easing the identification and specification of reusable and composable commonalities and variabilities among TMs, we introduce a software product line oriented, ACTA-based, language, called SPLACID. SPLACID is dedicated to the formal specification of TMs in terms of the selection and specialisation of a set of TM standard features. SPLACID promotes reuse and enhance rigor and precision by providing a well structured concrete syntax. Barbara Gallina, Nicolas Guelfi |
SEW | 1 |
| 2007 | Coordinated Atomic Actions for Dependable Distributed Systems: the Current State in Concepts, Semantics and Verification MeansabstractCoordinated Atomic Actions (CAAs) have been introduced about ten years ago as a conceptual framework for developing fault-tolerant concurrent systems. All the work done since then extended the CAA framework with the capabilities to model, verify, and implement concurrent distributed systems following pre-defined development methodologies. As a result, CAAs, compared to other approaches available, offer a rich set of means for engineering dependable systems. Nevertheless, it is sometimes difficult to have a global and analytical view of all the features available as this concept provides a number of features which need to be applied in combination. The main contribution of this paper is in presenting a complete state-of-the-art overview of the work done around CAAs from the three perspectives: the definitions of the fundamental concepts, their various semantics and the means supporting formal verification. This paper is useful for the potential CAAs users in helping them to avoid misinterpretation when employing all the available features. Finally, our paper should contribute in better understanding of the likely directions in which the CAA framework may evolve in the near future. Barbara Gallina, Nicolas Guelfi, Alexander B. Romanovsky |
ISSRE | 1 |
| 2007 | A Template for Requirement Elicitation of Dependable Product Lines
Barbara Gallina, Nicolas Guelfi |
REFSQ | 1 |