Jérôme Hugues

dblp:88/1216 · DBLP profile ↗
← Back
32ranked-venue papers
10as first author
3since 2021 · last 2023
0000-0003-0148-7175ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 17 · 3 first-author · 2 since 2021Systems, architecture and hardware · 4 · 3 first-author · 1 since 2021Theory of computation · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2023 Special issue on Reliable Software Technologies (AEiC2022)
Jérôme Hugues
J. Syst. Archit.1
2022 Formalization of the AADL Run-Time Services
John Hatcliff, Jérôme Hugues, Danielle Stewart, Lutz Wrage
ISoLA (2)2
2022 Mechanization of a Large DSML: An Experiment with AADL and Coq
abstract
Domain-Specific Modeling Languages (DSMLs) rely on model-based techniques to deliver tailored languages to meet specific needs, such as system modeling, formal verification, and code generation. A DSML has specific static and dynamic behavior rules that must be properly assessed before processing the model. The definition of these rules remains a challenge. Meta-modeling techniques usually lack the foundational elements required to fully express behavioral semantics. In this context, using an interactive theorem prover provides a mathematical foundation with which the semantics of a DSML can be defined. This includes an abstract syntax tree, typing rules, and derivation of an executable simulator. In this paper, we report on an ongoing effort to capture the SAE AADL language using Coq along with specific analysis capabilities. Our contribution provides an unambiguous semantics for a large set of the language and can be used as a foundation to build rich analysis capabilities.
Jérôme Hugues, Lutz Wrage, John Hatcliff, Danielle Stewart
MEMOCODE1
2020 A correct-by-construction AADL runtime for the Ravenscar profile using SPARK2014
abstract
Middleware is an integral part of critical software, providing core services for data exchange and manipulation, job execution, and scheduling. Their correctness is central to the correct execution of the software. They must be carefully configured to meet all functional and non-functional requirements. From a set of valid configuration parameters, one then has to demonstrate the implementation is correct and can fulfill its mission. Model-based techniques provide the foundations for correct-by-construction engineering. Most notably, they can be used to model a system, assess its configuration is correct, and then generate the corresponding middleware instance. The SAE AADL language supports the modeling of safety-critical systems and covers its design, configuration, and analysis. In this paper, we present several contributions: the definition of a model of computation aligned with the Ada Ravenscar profile supported by an architectural model expressed using AADL; derivation rules from AADL constructs to middleware services using Ada 2012 and SPARK 2014, and the proof of correctness of the implementation. Our contribution illustrates how one can prove the absence of runtime errors in middleware configured from high-level descriptions. This effort illustrates the positive effect models, programming languages and associated toolsets have on developing high-assurance middleware.
Jérôme Hugues
J. Syst. Archit.1
2020 A formal approach to AADL model-based software engineering
Hana Mkaouar, Bechir Zalila, Jérôme Hugues, Mohamed Jmaiel
Int. J. Softw. Tools Technol. Transf.3
2019 Trade-off analysis for SysML models using decision points and CSPs
Patrick Leserf, Pierre de Saqui-Sannes, Jérôme Hugues
Softw. Syst. Model.3
2018 Towards the systematic analysis of non-functional properties in Model-Based Engineering for real-time embedded systems
Guillaume Brau, Jérôme Hugues, Nicolas Navet
Sci. Comput. Program.2
2016 Architectural performance analysis of FPGA synthesized LEON processors
abstract
Current processors have gone through multiple internal optimization to speed-up the average execution time e.g. pipelines, branch prediction. Besides, internal communication mechanisms and shared resources like caches or buses have a significant impact on Worst-Case Execution Times (WCETs). Having an accurate estimate of a WCET is now a challenge. Probabilistic approaches provide a viable alternative to single WCET estimation. They consider WCET as a probabilistic distribution associated to uncertainty or risk.
Corentin Damman, Gregory Edison, Fabrice Guet, Eric Noulard, Luca Santinelli, Jérôme Hugues
RSP6
2015 Multi domain optimization with SysML modeling
abstract
Finding the set of optimal architectures is an important challenge for the designer who uses the Model-Based System Engineering with SysML. The paper discusses the application of techniques to solve a Constraint Satisfaction Multi-criteria Optimization Problem (CSMOP) obtained from a SysML model. In this paper, we present our methodology and propose several stereotypes for model variability, including continuous and discrete variables. Then we define a new parametric diagram usage for context modeling optimization. From this optimization context and model variability, it is possible to generate a problem description file for the PyOpt optimization framework. Finally a case study combining optical and electronic parameters illustrates the methodology with numerical results.
Patrick Leserf, Pierre de Saqui-Sannes, Jérôme Hugues
ETFA3
2015 A Contract-Based Approach to Support Goal-Driven Analysis
abstract
In the design of real-time systems, models are usual artifacts to capture and represent the various features of the system. They are later analyzed to check for their correctness. A key issue is to handle models and analyses in a systematic, consistent and efficient way. This paper presents an approach for the systematic and correct execution of analyses on real-time system models along with a proof-of-concept. The contribution aims at 1) directing the analyses targeting goals and 2) using contracts to reason about models, analyses and goals. An example of goal is to enrich a model with missing information or to obtain precise data to conclude about the system quality. In our approach, contracts are used to formally depict both the properties required and provided by the analyses, but also models and goals. Through the concept of contracts, we identify all the feasible paths to execute the analyses in order to reach a goal.
Guillaume Brau, Jérôme Hugues, Nicolas Navet
ISORC2
2015 SysML Modeling for Embedded Systems Design Optimization - A Case Study
abstract
International audience
Patrick Leserf, Pierre de Saqui-Sannes, Jérôme Hugues, Khaled Chaaban
MODELSWARD3
2015 Model-based design and automated validation of ARINC653 architectures
abstract
Safety-Critical Systems as used in avionics systems are now extremely software-reliant. As these systems are life-or mission- critical, software must be carefully designed and certified according to stringent standards. One typical pitfalls of such project is the late detection of safety issues or bugs at integration time that impose to redo development steps. Model-Based Engineering aims at capturing system concerns with a specific notations and use models to drive the development process through all its phases - design, validation, implementation and ultimately, certification. Through a single consistent notation, such an approach would avoid undefined assumption and traditional hurdles due to informal, text-based, specifications. In this paper, we present recent contributions we pushed forward in the AADL architecture description language for the design and validation of Integrated Modular Avionics systems. First, we review modeling patterns to support abstractions for IMA systems. We then introduce capabilities to check all ARINC653 patterns are enforced at model-level. In addition, we review errror modeling and safety analysis capabilities towards the production of safety reports conforming to ARP4761 recommandations.
Jérôme Hugues, Julien Delange
RSP1
2015 Performance verification for ESL design methodology from AADL models
abstract
One of the key issues to ensure high-quality designs is the verification methodology. The typical verification methodology used for RTL design is based on the V diagram. In this article we work at higher levels of abstraction (named ESL) by focusing on the performance verification process. A subsystem and its interconnected components are modeled with AADL. AADL also contains constructs for modeling both software and hardware components. Through the ESL virtual platform SpaceStudioTM, we can rapidly estimate the performance on different architectures. This performance verification flow has been experimented on a Motion-JPEG video decoder application for video thumbnails that targets a Xilinx Zynq-7000 platform.
Gaudron Mathieu, Bois Guy, Jérôme Hugues, Fellipe Monteiro
RSP3
2015 Preface to the special issue: Architecture-Driven Semantic Analysis of Embedded Systems
Jérôme Hugues, Oleg Sokolsky
Sci. Comput. Program.1
2014 Analysis as a First-Class Citizen: An Application to Architecture Description Languages
abstract
Architecture Description Languages (ADLs) support modeling and analysis of systems through models transformation and exploration. Various contributions made proposals to bring verification capabilities to designers through model-based frame-works and illustrated benefits to the overall system quality. Model-level analyses are usually performed as an exogenous, unidirectional and semantically weak transformation towards a third-party model. We claim such process can be incomplete and/or inefficient because gathered results lead to evolution of the primary model. This is particularly problematic for the design of Distributed Real-Time Embedded (DRE) systems that has to tackle many concerns like time, security or safety. In this paper, we argue why analysis should no longer be considered as a side step in the design process but, rather, should be embedded as a first-class citizen in the model itself. We review several standardized architecture description languages, which consider analysis as a goal. As an element of solution, we introduce current work on the definition of a language dedicated to the analysis of models within the scope of one particular ADL, namely the Architecture Analysis and Design Language (AADL).
Jérôme Hugues, Guillaume Brau
ISORC1
2013 Mapping AADL models to a repository of multiple schedulability analysis techniques
abstract
To fill the gap between the modeling of real-time systems and the scheduling analysis, we propose a framework that supports seamlessly the two aspects: (1) modeling a system using a methodology, in our case study, the Architecture Analysis and Design Language (AADL), and (2) helping to easily check temporal requirements (schedulability analysis, worst-case response time, sensitivity analysis, etc.). We introduce the usefulness of an intermediate framework called MoSaRT, which supports a rich semantic concerning temporal analysis. We show with a case study how the input model is transformed into a MoSaRT model, and how our framework is able to generate the proper models as inputs to several classic temporal analysis tools.
Yassine Ouhammou, Emmanuel Grolleau, Jérôme Hugues
ISORC3
2013 Enforcing software engineering tools interoperability: An example with AADL subsets
abstract
Model-Based Engineering is now a valuable asset to design complex real-time systems. Toolchains are assembled to cover the various stages of the process: high-level modeling, analysis and code generation. Yet tools put heterogeneous requirements on models: specific modeling patterns must be respected so that a given analysis is performed. This creates an interoperability paradox: models must be tuned not given system requirements, but to abide to tools capabilities. In this paper, we propose a systematic process to define the definition, comparison and enforcement of tools-specific subsets. Thus, we guide the user in selecting the tools that could support its engineering process. Our contribution is illustrated in the context of the AADL Architecture Design Language.
Vincent Gaudel, Frank Singhoff, Alain Plantec, Jérôme Hugues, Pierre Dissaux, Jérôme Legrand
RSP4
2012 Editorial to the Special Issue of Rapid System Prototyping'10
Kenneth B. Kent, Jérôme Hugues
Softw. Pract. Exp.2
2011 An Implementation of the Behavior Annex in the AADL-Toolset Osate2
abstract
AADL is a modeling language to design and analyze High-Integrity Distributed and Real-time systems. Embedded sub-languages published as AADL annexes extend an AADL model to enhance analysis. The behavior annex specifies the behavior of an AADL application model. Thus, an implantation of this annex allows to perform behavior analysis. In addition, as there are several AADL annexes, the implementation of generic mechanisms to support each one of them is challenging. The behavior annex is a valid candidate to illustrate these challenges by combining several sub-languages. In this paper we expose our experiment to support the behavior annex in the reference AADL tool set OSATE2. This one, supports the AADL version 2 by providing a front-end and a set of analysis plug-ins to analyze an AADL model.
Gilles Lasnier, Laurent Pautet, Jérôme Hugues, Lutz Wrage
ICECCS3
2011 Modeling and Verification of Memory Architectures with AADL and REAL
abstract
Real-Time Embedded systems must respect a wide range of non-functional properties, including safety, respect of deadlines, power or memory consumption. We note that correct hardware resource dimensioning requires taking into account the impact of the whole software, both the user code and the underlying run time environment. AADL allows one to precisely capture all of them. In this article, we evaluate the AADL modeling to define memory architectures, and then verification rules to assess that the memory is correctly dimensioned. We use the REAL domain-specific language to express memory requirements (such as layout or size) and then validate them on a case-study using the VxWorks real-time kernel.
Stéphane Rubini, Frank Singhoff, Jérôme Hugues
ICECCS3
2011 A Model-Based Transformation Process to Validate and Implement High-Integrity Systems
abstract
Despite numerous advances, building High-Integrity Embedded systems remains a complex task. They come with strong requirements to ensure safety, schedulability or security properties, one needs to combine multiple analysis to validate each of them. Model-Based Engineering is an accepted solution to address such complexity: analytical models are derived from an abstraction of the system to be built. Yet, ensuring that all abstractions are semantically consistent, remains an issue, e.g. when performing model checking for assessing safety, and then for schedulability using timed automata, and then when generating code. Complexity stems from the high-level view of the model compared to the low-level mechanisms used. In this paper, we present our approach based on AADL and its behavioral annex to refine iteratively an architecture description. Both application and runtime components are transformed into basic AADL constructs which have a strict counterpart in classical programming languages or patterns for verification. We detail the benefits of this process to enhance analysis and code generation. This work has been integrated to the AADL-tool support OSATE2.
Gilles Lasnier, Laurent Pautet, Jérôme Hugues
ISORC3
2010 An MDE-Based Process for the Design, Implementation and Validation of Safety-Critical Systems
abstract
Distributed Real-Time Embedded (DRE) systems have critical requirements that need to be verified. They are either related to functional (e. g. stability of a furnace controller) or non-functional (e. g. meeting deadlines) aspects. Model-Driven Engineering (MDE) tools have emerged to ease DRE systems design. These tools are also capable of generating code. However, these tools either focus on the functional aspects or on the runtime architecture. Hence, the development cycle is partitioned into pieces with heterogeneous modeling notations and poor coordination. In this paper, we propose a MDE-based process to create DRE systems without manual coding. We show how to integrate functional and architecture concerns in a unified process. We use industry-proven modeling languages to design functional elements of the system, and automatically integrate them using our AADL toolchain.
Julien Delange, Laurent Pautet, Jérôme Hugues, Dionisio de Niz
ICECCS3
2010 Expressing and Enforcing User-Defined Constraints of AADL Models
abstract
The Architecture Analysis and Design Language AADL allows one to model complete systems, but also to define specific extensions through property sets and library of models. Yet, it does not define an explicit mechanism to enforce some semantics or consistency checks to ensure property sets are correctly used. In this paper, we present REAL (Requirements and Enforcements Analysis Language) as an integrated solution to this issue. REAL is defined as an AADL annex language. It adds the possibility to express constraints as theorems based on set theory to enforce implicit semantics of property sets or AADL models. We illustrate the use of the language on case studies we developed with industrial partners.
Olivier Gilles, Jérôme Hugues
ICECCS2
2010 A MDE-Based Optimisation Process for Real-Time Systems
abstract
The design and implementation of Real-Time Embedded Systems is now heavily relying on Model-Driven Engineering (MDE) as a central place to define and then analyze or implement a system. MDE toolchains are taking a key role as to gather most of functional and not functional properties in a central framework, and then exploit this information. Such toolchain is based on both 1) a modeling notation, and 2) companion tools to transform or analyse models. In this paper, we present a MDE-based process for system optimisation based on an architectural description. We first define a generic evaluation pipeline, define a library of elementary transformations and then shows how to use it through Domain-Specific Language to evaluate and then transform models. We illustrate this process on an AADL case study modeling a Generic Avionics Platform.
Olivier Gilles, Jérôme Hugues
ISORC2
2009 From AADL Architectural Models to Petri Nets: Checking Model Viability
abstract
Modeling of distributed real-time embedded (DRE) systems allows one to evaluate models behavior or schedulability. However, assessing that a DRE system's behavior is correct in the causal domain is a challenge: one need to elaborate a mathematical abstraction suitable for checking properties like absence of deadlock or safety conditions (i.e. an invariant remains all over the execution). In this paper, we propose a global approach to building Petri Nets models from an architecture described using AADL. We consider the semantics of interacting entities defined by AADL, and show how to build corresponding Petri Nets models. Based on a case study, we show how the verification process could be automated and parameterized.
Xavier Renault, Fabrice Kordon, Jérôme Hugues
ISORC3
2009 Towards Model-Based Optimisations of Real-Time Systems, an Application with the AADL
abstract
Model driven engineering provides facilities to tackle complexity in real-time systems, from early requirements capture to validation & verification down to code generation. We note that models are built from a system perspective, and resources are allocated to meet communication, energy or scheduling constraints. Yet, it is seldom optimal. In this paper, we explore transformations applied at model-level that preserve schedulability of the system, yet reduce the overall resource consumption. We use AADL as input formalism. By automating this process, we show how to transition from a system view to an implementation view, closer to actual hardware constraints.
Olivier Gilles, Jérôme Hugues
RTCSA2
2008 Towards Automatic Middleware Generation
abstract
Building middleware for distributed applications is a complex task, mixing antagonistic concerns: heterogeneity, performance, reliability, quality of services. Optimization and fine-tuning of middleware for a particular application is even a harder task, usually done manually or through complex design patterns. The advent of "schizophrenic'' middleware which separates concerns between distribution model, communication protocols, and their implementation by refining the definition and role of "personalities'' brought some elements to solve this problem by enabling full tailoring of the middleware by the developer. In this paper we extend this approach to full automation by generating middleware from an architectural model of the system expressed in a modeling language. This enables precise tuning and configuration of the middleware by generating exactly the required code, prior to runtime. We finally show how this approach fits the requirements of high-integrity or real-time distributed systems.
Bechir Zalila, Laurent Pautet, Jérôme Hugues
ISORC3
2008 From the prototype to the final embedded system using the Ocarina AADL tool suite
abstract
Building distributed deal-time embedded systems requires a stringent methodology, from early requirement capture to full implementation. However, there is a strong link between the requirements and the final implementation (e.g., scheduling and resource dimensioning). Therefore, a rapid prototyping process based on automation of tedious and error-prone tasks (analysis and code generation) is required to speed up the development cycle. In this article, we show how the AADL ( Architecture Analysis and Design Language ), which appeared in late 2004, helps solve these issues thanks to a dedicated tool suite. We then detail the prototyping process and its current implementation: Ocarina.
Jérôme Hugues, Bechir Zalila, Laurent Pautet, Fabrice Kordon
ACM Trans. Embed. Comput. Syst.1
2007 Combining Model Processing and Middleware Configuration for Building Distributed High-Integrity Systems
abstract
Requirements of high integrity systems now encompass distribution mechanisms along with strong functional and non-functional features (run-time support for hardware, dependability, safety, analyzability). In this paper, we show how model processing help addressing such needs. We present a generic distribution model suitable for high integrity systems, and demonstrate how a high-level modeling deployment view allows one to greatly reduce the model complexity. Finally, we conclude by assessing a case study
Jérôme Hugues, Bechir Zalila, Laurent Pautet
ISORC1
2007 A Generative Approach to Building a Framework for Hard Real-Time Applications
abstract
The communication and tasking infrastructure of a real- time application makes up a significant portion of any em- bedded control system. Traditionally, the tasking and com- munication constructs are provided by an RTOS. We present an approach to automatically generate a robust framework for a single-node application from its architectural descrip- tion. This framework sits atop a Ravenscar-compliant run- time as opposed to a standard RTOS. Finally, we present an extension of our approach to support code generation for distributed applications.
Irfan Hamid, Jérôme Hugues
SEW3
2006 A Framework for DRE middleware, an Application to DDS
abstract
Heterogeneous non-functional requirements of DRE system put a limit on middleware engineering; building an application-tailored middleware becomes a challenge. In this paper, we show how we use the PolyORB middleware and its architecture as a framework to implement DDS, the data distribution services (DDS) recently published by the OMG. We demonstrate how the architecture proposed by PolyORB enables a rapid implementation of this specification, and allows for extreme tailorability to support application requirements
Jérôme Hugues, Laurent Pautet, Fabrice Kordon
ISORC1
2005 Revisiting COTS middleware for DRE systems
abstract
Distributed real-time embedded systems (DRE) increasingly rely on COTS middleware to meet their distribution needs. Yet, there is a technology gap between the design of COTS middleware and the high-integrity constraints of real-time engineering. This puts a limit on the adoption of middleware by system families such as space or avionics. In this paper, we present our current work on the "schizophrenic middleware architecture", a highly tailorable middleware architecture, and its implementation PolyORB. We illustrate how it allows for support of real-time engineering guidelines, enforces determinism, allows for modeling and verification.
Jérôme Hugues, Laurent Pautet, Fabrice Kordon
ISORC1