EDBT 2026 Demo / reviewers in the wild / expert
Bjarne Johansson
dblp:251/4974
· DBLP profile ↗
13ranked-venue papers
6as first author
11since 2021 · last 2026
0000-0002-5333-3699ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 12 · 6 first-author · 10 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Timing-Aware Configuration Framework for TSN and OPC UA in Industrial Automation Systems
Kasra Ekrad, Bjarne Johansson, Ines Alvarez, Saad Mubeen, Mohammad Ashjaei |
ISORC | 2 |
| 2025 | A Methodology to Map Industrial Automation Traffic to TSN Traffic ClassesabstractThis paper identifies that existing industrial automation standards, such as IEC/IEEE 60802 and IEEE 802.1Q, often have inconsistent definitions of traffic types. In the context of utilizing time-sensitive networking (TSN) standards for future automation systems, clear and consistent traffic characteristics and use cases should be defined to benefit from TSN features. Besides that, to facilitate the integration of TSN into the automation systems, the current standards provide a recommendation for mapping the automation traffic to the TSN traffic classes. In this paper, we propose an alternative mapping methodology for automation traffic to TSN traffic classes after presenting the existing automation traffic and their characteristics. Finally, through a case study, we show the potential of the new mapping methodology compared to the standard mapping strategy. Kasra Ekrad, Ines Alvarez, Bjarne Johansson, Saad Mubeen, Mohammad Ashjaei |
ETFA | 3 |
| 2024 | Real-Time Fault Diagnosis of Node and Link Failures for Industrial Controller RedundancyabstractIn an Industrial Control System (ICS), link failures causing partitioning between the redundant controller pair can prevent synchronization. This disruption could potentially trigger incorrect redundancy role-switching procedures. Distinguishing link and node failures from each controller's perspective can effectively mitigate these dependability threats. We introduce an algorithm capable of detecting and differentiating link failures from node failures within a bounded time. The proposed algorithm leverages periodic messages generated by industrial protocols operational in network devices. Our preliminary evaluation indicates the feasibility of the proposed algorithm in terms of meeting the real-time requirements of the ICSs. Kasra Ekrad, Sebastian Leclerc, Bjarne Johansson, Ines Alvarez, Saad Mubeen, Mohammad Ashjaei |
ETFA | 3 |
| 2024 | OPC UA PubSub and Industrial Controller RedundancyabstractIndustrial controllers constitute the core of numerous automation solutions. Continuous control system operation is crucial in certain sectors, where hardware duplication serves as a strategy to mitigate the risk of unexpected operational halts due to hardware failures. Standby controller redundancy is a commonly adopted strategy for process automation. This approach involves an active primary controller managing the process while a passive backup is on standby, ready to resume control should the primary fail. Typically, redundant controllers are paired with redundant networks and devices to eliminate any single points of failure. The process automation domain is on the brink of a paradigm shift towards greater interconnectivity and interoperability. OPC UA is emerging as the standard that will facilitate this shift, with OPC UA PubSub as the communication standard for cyclic real-time data exchange. Our work investigates standby redundancy using OPC UA PubSub, analyzing a system with redundant controllers and devices in publisher-subscriber roles. The analysis reveals that failovers are not subscriber-transparent without synchronized publisher states. We discuss solutions and experimentally validate an internal stack state synchronization alternative. Bjarne Johansson, Olof Holmgren, Martin Dahl, Håkan Forsberg, Thomas Nolte, Alessandro Vittorio Papadopoulos |
ETFA | 1 |
| 2024 | Towards High-Integrity Redundancy Role LeasingabstractControl systems are often an integral part of automation solutions where high reliability is crucial due to the high cost of downtime. The risk of unplanned downtime is typically reduced with redundant solutions. Additionally, safety-critical automation functions require high-integrity controllers. Today, the prevalent redundancy solution is a standby scheme, where one active primary controller drives the process while a standby backup controller is ready to take over in case of primary failure. This redundant controller pair can consist of high - integrity controllers. The automation industry is trending towards Ethernet as the sole communication medium. Our work presents an initial study of a high-integrity realization of a redundancy failure detection mechanism that guarantees only one primary controller, even in the case of network partitioning between the redundant controller pair. The failure detection is a lease-based function that leases the primary role from a central lease broker. This work discusses a high-integrity realization of the primary redundancy role leasing. We deduce and present the high-integrity-related requirements and a high-level design as an initial step towards a high-integrity realization of the redundancy role leasing. Bjarne Johansson, Olof Holmgren, Håkan Forsberg, Thomas Nolte, Alessandro Vittorio Papadopoulos |
ETFA | 1 |
| 2024 | Redundancy Link Security Analysis: An Automation Industry PerspectiveabstractIndustrial automation and control systems are responsible for running our most important infrastructures, providing electricity and clean water, producing medicine and food, along with many other services and products we take for granted. The safe and secure operation of these systems is therefore of great importance. Reliability is a fundamental requirement, with spatial controller redundancy being one important fault-tolerance mechanism. In current control system solutions, controller redundancy is implemented using state and heartbeat transfer communicated over dedicated physical links, based on an assumption of implicit trust. However, with the emerging network-centric control strategies there is a desire to transition into dynamic redundancy scenarios, where such dedicated links are unfeasible. In this paper, an approach for a threat-model based security analysis is presented from the perspective of the automation industry. The approach is applied to the communication links used for supporting control system redundancy within a network-centric architecture. Björn Leander, Bjarne Johansson, Saad Mubeen, Mohammad Ashjaei, Tomas Lindström |
ETFA | 2 |
| 2024 | Towards Developing a Supervisory Agent for Adapting the QoS Network ConfigurationsabstractAs the industry trend is moving toward Ethernet-based Industrial Control Systems (ICSs) in line with the industry 4.0 paradigm, the network traffic must be monitored and managed to keep the systems reliably available. A flat converged network architecture where all the controllers, Input/Output (I/O), and supervisory systems are connected introduces mixed traffic classes competing for network resources and access to the shared medium. These traffic classes are typically managed with different Quality of Service (QoS) techniques. The challenge lies in managing end-to-end QoS in a heterogeneous environment and configuring switches according to the vendor, model, and operating software. Meanwhile, emerging greenfield technology are not deployable with switches used in today's ICS. We propose a distributed QoS supervisory agent, capable of detecting and correcting faulty QoS configurations in a contemporary heterogeneous Layer 2 switch environment. The initial results are achieved through two experimental testbeds in a use case where our agent successfully corrected the QoS configurations. Sebastian Leclerc, Kasra Ekrad, Bjarne Johansson, Ines Alvarez, Mohammad Ashjaei, Saad Mubeen |
ETFA | 3 |
| 2023 | Centralised Architecture for the Automatic Self-Configuration of Industrial NetworksabstractNovel production paradigms aim at increasing the efficiency and flexibility of production systems. Nonetheless, traditional industrial infrastructures lack the mechanisms needed to support these new paradigms. One of the main limiting factors is the architecture, which follows the automation pyramid in which subsystems are divided in layers depending on their functionalities. This allowed to meet the timing and dependability requirements of the production subsystems, however at the cost of limiting the exchange of information required to provide increased flexibility to the system. For this reason, in this paper we propose a new industrial architecture with a single network infrastructure to connect all the devices that conform to the industrial systems. On top of that, we design an Automatic Network Configurator to support the automatic configuration of the system. To assess the feasibility of our design and evaluate its performance, we implement the first instance of the architecture capable of supporting changes in the traffic requirements during run-time, i.e., without stopping or disrupting the system's operation. Furthermore, we use the implemented instance to measure the time required for reconfigurations. Ines Alvarez, Daniel Bujosa, Bjarne Johansson, Mohammad Ashjaei, Saad Mubeen |
ETFA | 3 |
| 2023 | Consistency Before Availability: Network Reference Point based Failure Detection for Controller RedundancyabstractDistributed control systems constitute the automation solution backbone in domains where downtime is costly. Redundancy reduces the risk of faults leading to unplanned downtime. The Industry 4.0 appetite to utilize the device-to-cloud continuum increases the interest in network-based hardware-agnostic controller software. Functionality, such as controller redundancy, must adhere to the new ground rules of pure network dependency. In a standby controller redundancy, only one controller is the active primary. When the primary fails, the backup takes over. A typical network-based failure detection uses a cyclic message with a known interval, a.k.a. a heartbeat. Such a failure detection interprets heartbeat absences as a failure of the supervisee; consequently, a network partitioning could be indistinguishable from a node failure. Hence, in a network partitioning situation, a conventional heartbeat-based failure detection causes more than one active controller in the redundancy set, resulting in inconsistent outputs. We present a failure detection algorithm that uses network reference points to prevent network partitioning from leading to dual primary controllers. In other words, a failure detection that prioritizes consistency before availability. Bjarne Johansson, Mats Rågberger, Alessandro Vittorio Papadopoulos, Thomas Nolte |
ETFA | 1 |
| 2023 | Dependability and Security Aspects of Network-Centric ControlabstractIndustrial automation and control systems are responsible for running our most important infrastructures, providing electricity and clean water, producing medicine and food, along with many other services and products we take for granted. The safe and secure operation of these systems is therefore of great importance.One of the emerging trends in industrial automation systems is the transition from static hierarchical controller-centric systems to flexible network-centric systems. This transition has a great impact on the characteristics of industrial automation systems. In this article we describe the network-centric design strategy for industrial automation systems and describe the impact on dependability and security aspects that this strategy brings, looking at both challenges and possibilities. Björn Leander, Bjarne Johansson, Tomas Lindström, Olof Holmgren, Thomas Nolte, Alessandro Vittorio Papadopoulos |
ETFA | 2 |
| 2022 | Priority Based Ethernet Handling in Real-Time End System with Ethernet Controller FilteringabstractThis work addresses the impact of best-effort traffic on network-dependent real-time functions in distributed control systems. Motivated by the increased Ethernet use in real-time dependent domains, such as the automation industry, a growth driven by Industry 4.0, interconnectivity desires, and data thirst. Ethernet allows different network-based functions to converge on one physical network infrastructure. In the automation domain, converged networks imply that functions with different criticality and real-time requirements coexist and share the same physical resources. The IEEE 60802 Time-Sensitive Networking profile for Industrial Automation targets the automation industry and addresses Ethernet network determinism on converged networks. However, the profile is still in the draft stage at the time of writing this paper. Meanwhile, Ethernet already provides attributes utilized by network equipment to prioritize time-critical communication. This paper shows that Ethernet Controller filtering with prioritized processing is a prominent solution for preserving real-time guarantees while supporting best-effort traffic. A solution capable of eliminating all best-effort traffic interference in the real-time application is exemplified and evaluated on a VxWorks system. Bjarne Johansson, Mats Rågberger, Thomas Nolte, Alessandro Vittorio Papadopoulos |
IECON | 1 |
| 2020 | Heartbeat Bully: Failure Detection and Redundancy Role Selection for Network-Centric ControllerabstractHigh availability and reliability are fundamental for distributed control systems in the automation industry. Redundancy solutions, with duplicated hardware, is the common way to increase availability. With the advent of Industry 4.0, the automation industry is undergoing a paradigm shift; a peer-to-peer mesh oriented architecture is replacing the traditional hierarchical automation pyramid. With generic computational power provided anywhere in the cloud - device continuum, the conventional control centric solutions are becoming obsolete. The paradigm shift imposes new challenges and possibilities on the redundancy solutions used. We present and evaluate a hardware-agnostic algorithm suitable for failure detection and redundancy role selection in the new automation paradigm. The algorithm is modeled, evaluated and validated with the model checking tool UPPAAL. Bjarne Johansson, Mats Rågberger, Alessandro Vittorio Papadopoulos, Thomas Nolte |
IECON | 1 |
| 2019 | Classification of PROFINET I/O Configurations utilizing Neural NetworksabstractIn process automation installations, the I/O system connect the field devices to the process controller over a fieldbus, a reliable, real-time capable communication link with signal values cyclical being exchanged with a 10-100 millisecond rate. If a deviation from intended behaviour occurs, analyzing the potentially vast data recordings from the field can be a time consuming and cumbersome task for an engineer. For the engineer to be able to get a full understanding of the problem, knowledge of the used I/O configuration is required. In the problem report, the configuration description is sometimes missing. In such cases it is difficult to use the recorded data for analysis of the problem.In this paper we present our ongoing work towards using neural network models as assistance in the interpretation of an industrial fieldbus communication recording. To show the potential of such an approach we present an example using an industrial setup where fieldbus data is collected and classified. In this context we present an evaluation of the suitability of different neural net configurations and sizes for the problem at hand. Bjarne Johansson, Björn Leander, Aida Causevic, Alessandro Vittorio Papadopoulos, Thomas Nolte |
ETFA | 1 |