Anne E. Haxthausen

dblp:70/2068 · also Anne Elisabeth Haxthausen · DBLP profile ↗
← Back
35ranked-venue papers
12as first author
13since 2021 · last 2026
0000-0001-7349-8872ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 22 · 8 first-author · 6 since 2021Theory of computation · 13 · 5 first-author · 7 since 2021Systems, architecture and hardware · 1Security and privacy · 1 · 1 first-author
YearPublicationVenuePosition
2026 A History of Formal Methods in Railways
abstract
The engineering of industrial systems, particularly in safety-critical domains such as railways, demands rigorous verification and validation processes to ensure system dependability. Formal methods have emerged as powerful tools to complement traditional software engineering practices. In the railway sector, which increasingly relies on complex, distributed, and cyber-physical control systems, formal methods have demonstrated particular value for many decades now. In this article, we provide a retrospective overview of the application of formal methods and tools in the railway domain, with emphasis on two prominent verification approaches and one frequently verified railway system: modeling and validation with the B method and tools and formal verification of interlocking systems by model checking. We explore their role in the design and development of key railway systems, highlighting both academic research and industrial success stories, as witnessed by international projects and initiatives. We conclude with an outlook on the potential of integrating AI and formal methods to enhance the efficiency of next-generation railway systems.
Maurice H. ter Beek, Alessandro Fantechi, Alessio Ferrari 0001, Stefania Gnesi, Anne E. Haxthausen, Thierry Lecomte
Formal Aspects Comput.5
2025 Mechanised Safety Verification for a Distributed Autonomous Railway Control System
abstract
We present a distributed railway interlocking (IXL) method based on trains communicating with switch boxes deployed along the railway network for switching points and monitoring the occupancy states of track elements. The method does not require any centralised IXL components. A distributed architecture is proposed that carefully separates the overall business logic and automated train operation from the safety-critical automated train protection and distributed IXL logic. This architecture is also suitable for autonomous trains traversing the railway network. The safety of the IXL logic is formally proven, using the Isabelle/HOL proof assistant. Experiments confirm that this proof-based approach is superior to model checking approaches, since the model checking effort grows exponentially with the size of the railway network. In contrast to this, the mathematical safety proof is performed once and for all railway networks fulfilling a realistic well-formedness condition. For a concrete network, only the well-formedness of the network and its initial train placements has to be verified, whereas the safety of the dynamic behaviour is a consequence of the network-independent safety proof.
Robert Sachtleben, Anne E. Haxthausen, Jan Peleska 0001
Formal Aspects Comput.2
2025 Formal methods for industrial critical systems
abstract
Abstract Formal methods for industrial critical systems are essential because they provide mathematically rigorous techniques to specify, design, and verify system behavior. This reduces the risk of failures in safety- and security-critical domains such as aerospace, automotive, and healthcare. This special issue of Software Tools for Technology Transfer contains four papers presenting recent advances in tools target the use of formal methods for critical systems in industry. The papers are revised and extended versions of selected conference papers from the 29th International Conference on Formal Methods for Industrial Critical Systems (FMICS 2024).
Anne E. Haxthausen, Wendelin Serwe
Int. J. Softw. Tools Technol. Transf.1
2024 Formal Methods for Distributed Computing in Future Railway Systems
Alessandro Fantechi, Stefania Gnesi, Anne E. Haxthausen
ISoLA (5)3
2024 Formal Verification of Railway Interlockings: a Compositional Approach Based on a Library of Pre-verified Components
Christophe Limbrée, Anne E. Haxthausen, Gloria Gori, Alessandro Fantechi
ISoLA (5)2
2023 Introduction to the Special Section on Reliability, Safety, and Security of Railway Systems
abstract
Securing a safety-critical system is a challenging task, because safety requirements have to be considered alongside security controls. We report on our experience to develop a security architecture for railway signalling systems starting from the bare ...
Simon Collart Dutilleul, Anne E. Haxthausen, Thierry Lecomte, Jim Woodcock 0001
Formal Aspects Comput.2
2023 Compositional Verification of Railway Interlocking Systems
abstract
Model checking techniques have often been applied to the verification of railway interlocking systems, responsible for guiding trains safely through a given railway network. However, these techniques fail to scale to the interlocking systems controlling large stations, composed of hundreds and even thousands of controlled entities, due to the state space explosion problem. Indeed, interlocking systems exhibit a certain degree of locality that allows some reasoning only on the mere set of entities that regard the train movements, but safe routing through a complex station layout requires a global reservation policy, which can require global state conditions to be taken into account. In this article, we present a compositional approach aimed at chopping the verification of a large interlocking system into that of smaller fragments, exploiting in each fragment a proper abstraction of the global information on routing state. A proof is given of the thesis that verifying the safety of the smaller fragments is sufficient to verify the safety of the whole network. Experiments using this compositional approach have shown important gains in performance of the verification, as well as in the size of affordable station layouts.
Anne E. Haxthausen, Alessandro Fantechi
Formal Aspects Comput.1
2022 Formal Methods for Distributed Control Systems of Future Railways
Alessandro Fantechi, Stefania Gnesi, Anne E. Haxthausen
ISoLA (4)3
2022 Standardisation Considerations for Autonomous Train Control
abstract
Abstract In this paper, we review software-based technologies already known to be, or expected to become essential for autonomous train control systems with grade of automation GoA 4 (unattended train operation) in existing open railway environments. It is discussed which types of technology can be developed and certified already today on the basis of existing railway standards. Other essential technologies, however, require modifications or extensions of existing standards, in order to provide a certification basis for introducing these technologies into non-experimental “real-world” rail operation. Regarding these, we check the novel pre-standard ANSI/UL 4600 with respect to suitability as a certification basis for safety-critical autonomous train control functions based on methods from artificial intelligence. As a thought experiment, we propose a novel autonomous train controller design and perform an evaluation according to ANSI/UL 4600. This results in the insight that autonomous freight trains and metro trains using this design could be evaluated and certified on the basis of ANSI/UL 4600 .
Jan Peleska 0001, Anne E. Haxthausen, Thierry Lecomte
ISoLA (4)2
2022 Safe and Secure Future AI-Driven Railway Technologies: Challenges for Formal Methods in Railway
Monika Seisenberger, Maurice H. ter Beek, Xiuyi Fan, Alessio Ferrari 0001, Anne E. Haxthausen, Phillip James, Andrew Lawrence, Bas Luttik, Jaco van de Pol, Simon Wimmer 0001
ISoLA (4)5
2021 Editorial
abstract
No abstract available.
Alessandro Fantechi, Anne E. Haxthausen, Jim Woodcock 0001
Formal Aspects Comput.2
2021 Stepwise development and model checking of a distributed interlocking system using RAISE
abstract
Abstract This paper considers the challenge of designing and verifying control protocols for geographically distributed railway interlocking systems. It describes how this challenge can be tackled by stepwise development and model checking of state transition system models in a new extension of the RAISE Specification Language. Railway interlocking systems are reconfigurable systems which can be configured by supplying data describing the network to be controlled and other details. Therefore, such systems are natural candidates for being modelled by generic state transition systems, which abstract away from the concrete configuration at the time of modelling, and can later be instantiated with concrete data. For a real-world case study, a generic state transition system is developed in steps, starting with an abstract model of the essential system behaviour and incrementally adding details and restrictions. The stepwise development method allows different variants of the control protocol to be explored. The generic models are instantiated with concrete configuration data, after which desired properties, in particular safety properties, of the system models are verified using model checking.
Signe Geisler, Anne E. Haxthausen
Formal Aspects Comput.2
2021 Efficient data validation for geographical interlocking systems
abstract
Abstract In this paper, an efficient approach to data validation of distributed geographical interlocking systems (IXLs) is presented. In the distributed IXL paradigm, track elements are controlled by local computers communicating with other control components over local and wide area networks. The overall control logic is distributed over these track-side computers and remote server computers that may even reside in one or more cloud server farms. Redundancy is introduced to ensure fail-safe behaviour, fault-tolerance, and to increase the availability of the overall system. To cope with the configuration-related complexity of such distributed IXLs, the software is designed according to the digital twin paradigm: physical track elements are associated with software objects implementing supervision and control for the element. The objects communicate with each other and with high-level IXL control components in the cloud over logical channels realised by distributed communication mechanisms. The objective of this article is to explain how configuration rules for this type of IXLs can be specified by temporal logic formulae interpreted on Kripke Structure representations of the IXL configuration. Violations of configuration rules can be specified using formulae from a well-defined subset of LTL. By decomposing the complete configuration model into sub-models corresponding to routes through the model, the LTL model checking problem can be transformed into a CTL checking problem for which highly efficient algorithms exist. Specialised rule violation queries that are hard to express in LTL can be simplified and checked faster by performing sub-model transformations adding auxiliary variables to the states of the underlying Kripke Structures. Further performance enhancements are achieved by checking each sub-model concurrently. The approach presented here has been implemented in a model checking tool which is applied by Siemens Mobility for data validation of geographical IXLs.
Jan Peleska 0001, Niklas Krafczyk, Anne E. Haxthausen, Ralf Pinger
Formal Aspects Comput.3
2020 Formal Methods for Distributed Computing in Future Railway Systems
Alessandro Fantechi, Stefania Gnesi, Anne E. Haxthausen
ISoLA (3)3
2020 Model Checking a Distributed Interlocking System Using k-induction with RT-Tester
Signe Geisler, Anne E. Haxthausen
ISoLA (3)2
2020 Formal Modelling and Verification of a Distributed Railway Interlocking System Using UPPAAL
Per Lange Laursen, Van Anh Thi Trinh, Anne E. Haxthausen
ISoLA (3)3
2018 Stepwise Development and Model Checking of a Distributed Interlocking System - Using RAISE
Signe Geisler, Anne E. Haxthausen
FM2
2018 Safety Interlocking as a Distributed Mutual Exclusion Problem
Alessandro Fantechi, Anne E. Haxthausen
FMICS2
2017 Model Checking Geographically Distributed Interlocking Systems Using UMC
abstract
The current trend of distributing computations over a network is here, as a novelty, applied to a safety critical system, namely a railway interlocking system. We show how the challenge of guaranteeing safety of the distributed application has been attacked by formally specifying and model checking the relevant distributed protocols. By doing that we obey the safety guidelines of the railway signalling domain, that require formal methods to support the certification of such products. We also show how formal modelling can help designing alternative distributed solutions, while maintaining adherence to safety constraints.
Alessandro Fantechi, Anne E. Haxthausen, Michel Boje Randahl Nielsen
PDP2
2017 Compositional Verification of Interlocking Systems for Large Stations
Alessandro Fantechi, Anne E. Haxthausen, Hugo Daniel Macedo
SEFM2
2017 Formal modelling and verification of interlocking systems featuring sequential release
Linh Vu Hong, Anne E. Haxthausen, Jan Peleska 0001
Sci. Comput. Program.2
2016 On the Use of Static Checking in the Verification of Interlocking Systems
Anne E. Haxthausen, Peter H. Østergaard
ISoLA (2)1
2016 On the Feasibility of a Unified Modelling and Programming Paradigm
Anne E. Haxthausen, Jan Peleska 0001
ISoLA (2)1
2016 Compositional Verification of Multi-station Interlocking Systems
Hugo Daniel Macedo, Alessandro Fantechi, Anne E. Haxthausen
ISoLA (2)3
2014 Complete Model-Based Equivalence Class Testing for the ETCS Ceiling Speed Monitor
Cécile Braunstein, Anne E. Haxthausen, Wen-ling Huang, Felix Hübner 0001, Jan Peleska 0001, Uwe Schulze, Linh Vu Hong
ICFEM2
2014 Automated generation of formal safety conditions from railway interlocking tables
Anne E. Haxthausen
Int. J. Softw. Tools Technol. Transf.1
2012 Automated Generation of Safety Requirements from Railway Interlocking Tables
Anne E. Haxthausen
ISoLA (2)1
2011 Formal Development of a Tool for Automated Modelling and Verification of Relay Interlocking Systems
Anne E. Haxthausen, Andreas A. Kjær, Marie Le Bliguet
FM1
2011 A formal approach for the construction and verification of railway control systems
abstract
Abstract This paper describes a complete model-based development and verification approach for railway control systems. For each control system to be generated, the user makes a description of the application-specific parameters in a domain-specific language. This description is automatically transformed into an executable control system model expressed in SystemC. This model is then compiled into object code. Verification is performed using three main methods applied to different levels. (0) The domain-specific description is validated wrt. internal consistency by static analysis. (1) The crucial safety properties are verified for the SystemC model by means of bounded model checking. (2) The object code is verified to be I/O behaviourally equivalent to the SystemC model from which it was compiled.
Anne E. Haxthausen, Jan Peleska 0001, Sebastian Kinder
Formal Aspects Comput.1
2009 A Domain-Specific Framework for Automated Construction and Verification of Railway Control Systems
Anne E. Haxthausen
SAFECOMP1
2008 Specification, proof, and model checking of the Mondex electronic purse using RAISE
abstract
Abstract This paper describes how the communication protocol of Mondex electronic purses can be specified and verified against desired security properties. The specification is developed by stepwise refinement using the RAISE formal specification language, RSL, and the proofs are made by translation to PVS and SAL. The work is part of a year-long project contributing to the international grand challenge in verified software engineering.
Chris George, Anne E. Haxthausen
Formal Aspects Comput.2
2000 Linking DC Together with TRSL
Anne E. Haxthausen, Xia Yong
IFM1
2000 Formal Development and Verification of a Distributed Railway Control System
abstract
The authors introduce the concept for a distributed railway control system and present the specification and verification of the main algorithm used for safe distributed control. Our design and verification approach is based on the RAISE method, starting with highly abstract algebraic specifications which are transformed into directly implementable distributed control processes by applying a series of refinement and verification steps. Concrete safety requirements are derived from an abstract version that can be easily validated with respect to soundness and completeness. Complexity is further reduced by separating the system model into a domain model and a controller model. The domain model describes the physical system in absence of control and the controller model introduces the safety-related control mechanisms as a separate entity monitoring observables of the physical system to decide whether it is safe for a train to move or for a point to be switched.
Anne E. Haxthausen, Jan Peleska 0001
IEEE Trans. Software Eng.1
1997 Order-Sorted Algebraic Specifications with Higher-Order Functions
Anne E. Haxthausen
Theor. Comput. Sci.1
1992 Formal, model-oriented software development methods: From VDM to ProCoS & from RAISE to LaCoS
Dines Bjørner, Anne E. Haxthausen, Klaus Havelund
Future Gener. Comput. Syst.2