EDBT 2026 Demo / reviewers in the wild / expert
Hans A. Hansson
dblp:65/1154 · also Hans Hansson
· DBLP profile ↗
65ranked-venue papers
8as first author
15since 2021 · last 2025
0000-0002-7235-6888ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 24 · 3 first-author · 9 since 2021Software engineering, systems software and programming languages · 22 · 2 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 9 · 2 first-authorSecurity and privacy · 6 · 2 since 2021Computer networks · 2 · 2 first-authorArtificial intelligence and machine learning · 1 · 1 since 2021Theory of computation · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Formalizing Operational Design Domains with the Pkl LanguageabstractThe deployment of automated functions that can operate without direct human supervision has changed safety evaluation in domains seeking higher levels of automation. Unlike conventional systems that rely on human operators, these functions require new assessment frameworks to demonstrate that they do not introduce unacceptable risks under real-world conditions. To make a convincing safety claim, the developer must present a thorough justification argument, supported by evidence, that a function is free from unreasonable risk when operated in its intended context. The key concept relevant to the presented work is the intended context, often captured by an Operational Design Domain specification (ODD) specification. ODD formalization is challenging due to the need to maintain flexibility in adopting diverse specification formats while preserving consistency and traceability and integrating seamlessly into the development, validation, and assessment. This paper presents a way to formalize an ODD in the Pkl language, addressing central challenges in specifying ODDs while improving usability through specialized configuration language features. The approach is illustrated with an automotive example but can be broadly applied to ensure rigorous assessments of operational contexts. Martin A. Skoglund, Fredrik Warg, Anders Thorsén, Hans A. Hansson, Sasikumar Punnekkat |
IV | 4 |
| 2025 | Machine Learning-Driven Intrusion Detection and Identification in Industrial Control SystemsabstractUsing machine learning to detect and identify cyberattacks in Industrial Control Systems (ICS) offers a promising solution for uncovering zero-day attacks that traditional rulebased models cannot detect. However, applying ML-based intrusion detection in ICS environments presents challenges, including limited availability of attack data and difficulty in accurately identifying attack types. This paper addresses these challenges by proposing two key strategies. First, we demonstrate that the predictable traffic patterns of ICS networks enable the use of semi-supervised learning models for attack detection. We validate this approach using a benchmark dataset, showing that semi-supervised models achieve comparable performance to fully supervised models while relying solely on training with normal network data. Second, we propose a sequence-based approach for attack identification, using temporal data to improve the accuracy of identifying specific attack types. Our experiments reveal that incorporating historical network parameters improves the attack identification. Our research underscores the potential of semisupervised learning for effective attack detection and highlights the importance of incorporating network temporal properties to improve attack identification. Alireza Dehlaghi-Ghadim, Mona Moslemzade, Nima Pattiyampully Dharmapal, Niclas Ericsson, Mahshid Helali Moghadam, Ali Balador, Hans A. Hansson |
PDP | 7 |
| 2024 | Using Decision Support to Fortify Industrial Control System Against CyberattacksabstractThis paper presents a cybersecurity solution designed to fortify Industrial Control Systems (ICS) against cyberattacks. The proposed solution integrates a Network-based Intrusion Detection System (NIDS) with a Decision Support System (DSS), leveraging machine learning to detect anomalies in network data and employing a filtering mechanism to reduce false alarms. The NIDS protects a simulated ICS testbed, detecting anomalies and forwarding them to the DSS for further analysis and selection of mitigation strategies. We outline the system architecture and showcase promising outcomes from a prototype implementation. Our proof of concept evaluation demonstrates high accuracy in detecting attack scenarios. Challenges such as detection delays between attacks and potential mitigations high-light areas for future improvement. This research contributes to bridging the gap between ML-based IDS and security solutions, paving the way for enhanced cybersecurity in ICS environments. Alireza Dehlaghi-Ghadim, Niclas Ericsson, Lars-Göran Magnusson, Mats Eriksson, Mahshid Helali Moghadam, Ali Balador, Hans A. Hansson |
ETFA | 7 |
| 2024 | Safety Argumentation for Machinery Assembly Control Software
Julieth Patricia Castellanos Ardila, Sasikumar Punnekkat, Hans A. Hansson, Peter Backeman |
SAFECOMP | 3 |
| 2024 | Evaluation of Storage Placement in Computing Continuum for a Robotic ApplicationabstractAbstract This paper analyzes the timing performance of a persistent storage designed for distributed container-based architectures in industrial control applications. The timing performance analysis is conducted using an in-house simulator, which mirrors our testbed specifications. The storage ensures data availability and consistency even in presence of faults. The analysis considers four aspects: 1. placement strategy, 2. design options, 3. data size, and 4. evaluation under faulty conditions. Experimental results considering the timing constraints in industrial applications indicate that the storage solution can meet critical deadlines, particularly under specific failure patterns. Comparison results also reveal that, while the method may underperform current centralized solutions in fault-free conditions, it outperforms the centralized solutions in failure scenario. Moreover, the used evaluation method is applicable for assessing other container-based critical applications with timing constraints that require persistent storage. Zeinab Bakhshi, Guillermo Rodríguez-Navas, Hans A. Hansson, Radu Prodan |
J. Grid Comput. | 3 |
| 2023 | Access Control Enforcement Architectures for Dynamic Manufacturing SystemsabstractIndustrial control systems are undergoing a trans-formation driven by business requirements as well as technical advances, aiming towards increased connectivity, flexibility and high level of modularity, that implies a need to revise existing cybersecurity measures. Access control, being one of the major security mechanisms in any system, is largely affected by these advances.In this article we investigate access control enforcement architectures, aiming at the principle of least privilege1in dynamically changing access control scenarios of dynamic manufacturing systems. Several approaches for permission delegation of dynamic access control policy decisions are described. We present an implementation using the most promising combination of architecture and delegation mechanism for which available industrial standards are applicable. Björn Leander, Aida Causevic, Tomas Lindström, Hans A. Hansson |
ICSA | 4 |
| 2023 | Analyzing the performance of persistent storage for fault-tolerant stateful fog applicationsabstractIn this paper, we analyze the scalability and performance of a persistent, fault-tolerant storage approach that provides data availability and consistency in a distributed container-based architecture with intended use in industrial control applications. We use simulation to evaluate the performance of this storage system in terms of scalability and failures. As the industrial applications considered have timing constraints, the simulation results show that for certain failure patterns, it is possible to determine whether the storage solution can meet critical deadlines. The presented approach is applicable for evaluating timing constraints also of other container-based critical applications that require persistent storage. Zeinab Bakhshi, Guillermo Rodríguez-Navas, Hans A. Hansson |
J. Syst. Archit. | 3 |
| 2022 | A Context-Specific Operational Design Domain for Underground Mining (ODD-UM)
Julieth Patricia Castellanos Ardila, Sasikumar Punnekkat, Anas Fattouh, Hans A. Hansson |
EuroSPI | 4 |
| 2022 | Simulation Environment for Modular Automation SystemsabstractWhen developing products or performing experimental research studies, the simulation of physical or logical systems is of great importance for evaluation and verification purposes. For research-, and development-related distributed control systems, there is a need to simulate common physical environments with separate interconnected modules independently controlled, and orchestrated using standardized network communication protocols.The simulation environment presented in this paper is a bespoke solution precisely for these conditions, based on the Modular Automation design strategy. It allows easy configuration and combination of simple modules into complex production processes, with support for individual low-level control of modules, as well as recipe-orchestration for high-level coordination. The use of the environment is exemplified in a configuration of a modular ice-cream factory, used for cybersecurity-related research. Björn Leander, Tijana Markovic, Aida Causevic, Tomas Lindström, Hans A. Hansson, Sasikumar Punnekkat |
IECON | 5 |
| 2021 | Self-Healing Protocol: Repairing Schedules Online after Link Failures in Time-Triggered NetworksabstractSwitched networks following the time-triggered paradigm rely on static schedules that determine the communication pattern over each link. In order to tolerate link failures, methods based on spatial redundancy and based on resynthesis and replacement of schedules have been proposed. These methods, however, do not scale to larger networks, which may be needed e.g. for future large-scale cyberphysical systems. We propose a distributed Self-Healing Protocol (SHP) that, instead of recomputing the whole schedule, repairs the existent schedule at runtime. For that, it relies on the coordination among the nodes of the network to redefine the repair problem as a number of local synthesis problems of significantly smaller size, which are solved in parallel by the nodes that need to reroute the frames affected by link failures. SHP exhibits a high success rate compared to full rescheduling, as well as remarkable scalability; it repairs the schedule in milliseconds, whereas rescheduling may require minutes for large networks. Francisco Pozo, Guillermo Rodríguez-Navas, Hans A. Hansson |
DSN | 3 |
| 2021 | Using UPPAAL to Verify Recovery in a Fault-tolerant Mechanism Providing Persistent State at the EdgeabstractIn our previous work we proposed a fault-tolerant persistent storage for container-based fog architecture. We leveraged the use of containerization to provide storage as a containerized application working along with other containers. As a fault-tolerance mechanism we introduced a replicated data structure and to solve consistency issue between the replicas distributed in the cluster of nodes, we used the RAFT consensus protocol. In this paper, we verify our proposed solution using the UPPAAL model checker. We explain how our solution is modeled in UPPAAL and present a formal verification of key properties related to persistent storage and data consistency between nodes. Zeinab Bakhshi, Guillermo Rodríguez-Navas, Hans A. Hansson |
ETFA | 3 |
| 2021 | A Questionnaire Study on the Use of Access Control in Industrial SystemsabstractIndustrial systems have traditionally been kept isolated from external networks. However, business benefits are pushing for a convergence between the industrial systems and new information technology environments such as cloud computing, as well as higher level of connectivity between different systems. This makes cybersecurity a growing concern for industrial systems. In strengthening security, access control is a fundamental mechanisms for providing security in these systems. However, access control is relatively immature in traditional industrial systems, as compared to modern IT systems, and organizations' adherence to an established cybersecurity standard or guideline can be a deciding factor for choices of access control techniques used. This paper presents the results of a questionnaire study on the usage of access control within industrial system that are being developed, serviced or operated by Swedish organizations, contrasted to their usage of cybersecurity standards and guidelines. To be precise, the article focuses on two fundamental requirements of cybersecurity: identification and authentication control, and presents related findings based on a survey of the Swedish industry. The goal of the study is breaching the gap between the current state and the requirements of emerging systems with regards to access control. Björn Leander, Aida Causevic, Tomas Lindström, Hans A. Hansson |
ETFA | 4 |
| 2021 | Black-Box Testing for Security-Informed Safety of Automated Driving SystemsabstractAn evaluation of safety and security properties performed by an independent organisation can be an important step towards establishing trust in Automated Driving Systems (ADS), bridging the gap between the marketing portrayal and the actual performance of such systems in real operating conditions. However, due to the complexity of an ADS's behaviour and dangers involved in performing real environment security attacks, we believe assessments that can be performed with a combination of simulation and validation at test facilities is the way forward.In this paper, we outline an approach to derive test suites applicable to generic ADS feature classes, where classes would have similar capabilities and comparable assessment results. The goal is to support black box testing of such feature classes as part of an independent evaluation. By the means of co-simulation of post-attack behaviour and critical scenarios, we derive a representative set of physical certification tests, to gain an understanding of the interplay between safety and security. During the initial tests an ADS is subjected to various attacks and its reactions recorded. These reactions such as reduced functionality, fall back etc., together with relevant scenarios for the class is further analysed to check for safety implications. Martin A. Skoglund, Fredrik Warg, Hans A. Hansson, Sasikumar Punnekkat |
VTC Spring | 3 |
| 2021 | Towards dynamic safety assurance for Industry 4.0abstractThe goal of Industry 4.0 is to be faster, more efficient and more customer-centric, by enhancing the automation and digitalisation of production systems. Frequently, the production in Industry 4.0 is categorised as safety-critical, for example, due to the interactions between autonomous machines and hazardous substances that can result in human injury or death, damage to machines, property or the environment. In order to demonstrate the acceptable safety of production operations, safety cases are constructed to provide comprehensive, logical and defensible justification of the safety of a production system for a given application in a predefined operating environment. However, the construction and maintenance of safety cases in alignment with Industry 4.0 are challenging tasks. For their construction, besides the modular, dynamic and reconfigurable nature of Industry 4.0, the architectural levels of the things, fog and cloud computing have to be considered. The safety cases constructed at system design and development phases might be invalidated during production operations, thus necessitating some means for dynamic safety assurance. Moreover, flexible manufacturing in Industry 4.0 also underlines the need for safety assurance in a dynamic manner during the operational phase. Currently published studies are not explicitly supporting the safety assurance of Industry 4.0, which is the focus of this paper with special emphasis on dynamic safety assurance. At first, the Hazard and Operability (HAZOP) and Fault Tree Analysis (FTA) techniques are used for the identification and mitigation/elimination of potential hazards. Next, based on the hazard analysis results, we derived the safety requirements and safety contracts. Subsequently, safety cases are constructed using the OpenCert platform and safety contracts are associated with them to enable necessary changes during runtime. Finally, we use a simulations based approach to identify and resolve the deviations between the system understanding reflected in the safety cases and the current system operation. The dynamic safety assurance is demonstrated using a use case scenario of materials transportation and data flow in the Industry 4.0 context. Muhammad Atif Javed, Faiz Ul Muram, Hans A. Hansson, Sasikumar Punnekkat, Henrik Thane |
J. Syst. Archit. | 3 |
| 2021 | Safe and secure platooning of Automated Guided Vehicles in Industry 4.0abstractAutomated Guided Vehicles (AGVs) are widely used for materials transportation. Operating them in a platooned manner has the potential to improve safety, security and efficiency, control overall traffic flow and reduce resource usage. However, the published studies on platooning focus mainly on the design of technical solutions in the context of automotive domain. In this paper we focus on a largely unexplored theme of platooning in production sites transformed to the Industry 4.0, with the aim of providing safety and security assurances. We present an overall approach for a fault- and threat tolerant platooning for materials transportation in production environments. Our functional use cases include the platoon control for collision avoidance, data acquisition and processing by considering range, and connectivity with fog and cloud levels. To perform the safety and security analyses, the Hazard and Operability (HAZOP) and Threat and Operability (THROP) techniques are used. Based on the results obtained from them, the safety and security requirements are derived for the identification and prevention/mitigation of potential platooning hazards, threats and vulnerabilities. The assurance cases are constructed to show the acceptable safety and security of materials transportation using AGV platooning. We leveraged a simulation-based digital twin for performing the verification and validation as well as finetuning of the platooning strategy. Simulation data is gathered from digital twin to monitor platoon operations, identify unexpected or incorrect behaviour, evaluate the potential implications, trigger control actions to resolve them, and continuously update assurance cases. The applicability of the AGV platooning is demonstrated in the context of a quarry site. Muhammad Atif Javed, Faiz Ul Muram, Sasikumar Punnekkat, Hans A. Hansson |
J. Syst. Archit. | 4 |
| 2020 | Dynamic Reconfiguration of Safety-Critical Production SystemsabstractThe current trends of digitalization and Industry 4.0 are bringing ample opportunities for manufacturing industry to fine tune their products and processes at will, to meet changing market needs within short notice. However, the characteristics of advanced production systems, such as dynamic interactions between machines and reconfigurations, if not carefully orchestrated, could potentially lead to production failures or mishaps, making them safety-critical. Previous studies on hazard analysis, safety-performance tradeoffs and assurance cases have not specifically considered the dynamic reconfiguration scenarios in production systems. In this paper, for the hazard identification and mitigation/elimination, the principal characteristics of highly reconfigurable production systems have been given special consideration. Even if the hazard analysis results are incorporated in the initial designs of production systems, operational changes, such as adding/removing machines in response to market demands, system failures, or unanticipated hazardous conditions may still adversely impact the production safety and operational performance. For the operational changes, we perform the quantitative assessment through configuration analytics to determine the corresponding impacts on safety, performance and production demands. After that, the assurance case models are obtained with production line to cope with the potential problems during the dynamic safety assurance. The applicability of the proposed methodology is demonstrated in the context of a quarry site production scenario. Faiz Ul Muram, Muhammad Atif Javed, Hans A. Hansson, Sasikumar Punnekkat |
PRDC | 3 |
| 2019 | Applicability of the IEC 62443 standard in Industry 4.0 / IIoTabstractToday's industrial automation systems are undergoing a digital transformation that implies a shift towards the Internet of Things (IoT), leading to the Industrial Internet of Things (IIoT) paradigm. Existing Industrial Automated Control Systems (IACS), enriched with a potentially large number of IoT devices are expected to make systems more efficient, flexible, provide intelligence, and ultimately enable autonomous control. In general, the majority of such systems come with high level of criticality that calls for well-established methods and approaches when achieving cybersecurity, preferably prescribed by a standard. Björn Leander, Aida Causevic, Hans A. Hansson |
ARES | 3 |
| 2019 | Cybersecurity Challenges in Large Industrial IoT SystemsabstractTo achieve efficient and flexible production at affordable prices, industrial automation is pushed towards a digital transformation. Such a transformation assumes an enhancement of current Industrial Automated Control Systems with a large amount of IoT-devices, forming an Industrial Internet of Things (IIoT). The aim is to enable a shift from automatic towards autonomous control in such systems. This paper discusses some of the main challenges IIoT systems are facing with respect to cybersecurity. We discuss our findings in an example of a flow-control loop, where we apply a simple threat model based on the STRIDE method to deduce cybersecurity requirements in an IIoT context. Moreover, the identified requirements are assessed in the light of current state of the art solutions, and a number of challenges are discussed with respect to a large-scale IIoT system, together with some suggestions for future work. Björn Leander, Aida Causevic, Hans A. Hansson |
ETFA | 3 |
| 2019 | Dependable Fog Computing: A Systematic Literature ReviewabstractFog computing has been recently introduced to bridge the gap between cloud resources and the network edge. Fog enables low latency and location awareness, which is considered instrumental for the realization of IoT, but also faces reliability and dependability issues due to node mobility and resource constraints. This paper focuses on the latter, and surveys the state of the art concerning dependability and fog computing, by means of a systematic literature review. Our findings show the growing interest in the topic but the relative immaturity of the technology, without any leading research group. Two problems have attracted special interest: guaranteeing reliable data storage/collection in systems with unreliable and untrusted nodes, and guaranteeing efficient task allocation in the presence of varying computing load. Redundancy-based techniques, both static and dynamic, dominate the architectures of such systems. Reliability, availability and QoS are the most important dependability requirements for fog, whereas aspects such as safety and security, and their important interplay, have not been investigated in depth. Zeinab Bakhshi, Guillermo Rodríguez-Navas, Hans A. Hansson |
SEAA | 3 |
| 2018 | A Runtime Verification Tool for Detecting Concurrency Bugs in FreeRTOS Embedded SoftwareabstractThis article presents a runtime verification tool for embedded software executing under the open source real-time operating system FreeRTOS. The tool detects and diagnoses concurrency bugs such as deadlock, starvation, and suspension based-locking. The tool finds concurrency bugs at runtime without debugging and tracing the source code. The tool uses the Tracealyzer tool for logging relevant events. Analysing the logs, our tool can detect the concurrency bugs by applying algorithms for diagnosing each concurrency bug type individually. In this paper, we present the implementation of the tool, as well as its functional architecture, together with illustration of its use. The tool can be used during program testing to gain interesting information about embedded software executions. We present initial results of running the tool on some classical bug examples running on an AVR 32-bit board SAM4S. Sara Abbaspour Asadollah, Daniel Sundmark, Sigrid Eldh, Hans A. Hansson |
ISPDC | 4 |
| 2018 | Work-in-Progress: A Hot-Patching Protocol for Repairing Time-Triggered Network SchedulesabstractTime-Triggered communication is based on generating an offline static schedule that guarantees frame transmissions with reduced latency and low jitter. However, static schedules are not adaptive: if some unpredicted event happens, like a link failure, the schedule is not valid anymore and a new one needs to be synthesized from scratch. This paper presents a novel hot-patching protocol which seeks, after a link failure disconnecting two nodes, to find a new path to reconnect both nodes and restore during run-time the affected part of the schedule. We also introduce the concept of reparability as a desired property of the schedule, which increases the probability of our protocol to succeed. The first evaluation shows that our hot-patching protocol can recover from a link failure consistently in less than 25ms. Francisco Pozo, Guillermo Rodríguez-Navas, Hans A. Hansson |
RTAS | 3 |
| 2018 | Schedule Reparability: Enhancing Time-Triggered Network Recovery Upon Link FailuresabstractThe time-triggered communication paradigm has been shown to satisfy temporal isolation while providing end to end delay guarantees through the synthesis of an offline schedule. However, this paradigm has severe flexibility limitations as any unpredicted change not anticipated by the schedule, such as a component failure, might result in a loss of frames. A typical solution is to use redundancy or replace and update the schedule offline anew. With the ever increase in size of networks and the need to reduce costs, supplementary solutions that enhance the reliability of such networks are also desired. In this paper, we introduce a repair algorithm capable of reacting to unpredicted link failures. The algorithm quickly modifies the schedule such that all frames are transmitted again within their timing guarantees. We found that the success of our algorithm increases significantly with the existence of empty slots spread over the schedule, an opposite approach compared to packing frames, commonly used in the literature. We propose a new ILP formulation that includes a maximization of frame and link intermissions to stretch empty slots over the schedule. Our results show that we can repair with 90% success rate within milliseconds to a valid schedule compared to a few minutes needed to re-schedule the whole network. Francisco Pozo, Guillermo Rodríguez-Navas, Hans A. Hansson |
RTCSA | 3 |
| 2017 | A method to generate reusable safety case argument-fragments from compositional safety analysis
Irfan Sljivo, Barbara Gallina, Jan Carlson, Hans A. Hansson, Stefano Puri |
J. Syst. Softw. | 4 |
| 2017 | 10 Years of research on debugging concurrent and multicore software: a systematic mapping study
Sara Abbaspour Asadollah, Daniel Sundmark, Sigrid Eldh, Hans A. Hansson, Wasif Afzal |
Softw. Qual. J. | 4 |
| 2016 | The SafeCOP ECSEL Project: Safe Cooperating Cyber-Physical Systems Using Wireless CommunicationabstractThis paper presents an overview of the ECSEL project entitled "Safe Cooperating Cyber-Physical Systems using Wireless Communication" (SafeCOP), which runs during the period 2016 - 2019. SafeCOP targets safety-related Cooperating Cyber-Physical Systems (CO-CPS) characterised by use of wireless communication, multiple stakeholders, dynamic system definitions (openness), and unpredictable operating environments. SafeCOP will provide an approach to the safety assurance of CO-CPS, enabling thus their certification and development. The project will define a runtime manager architecture for runtime detection of abnormal behaviour, triggering if needed a safe degraded mode. SafeCOP will also develop methods and tools, which will be used to produce safety assurance evidence needed to certify cooperative functions. SafeCOP will extend current wireless technologies to ensure safe and secure cooperation. SafeCOP will also contribute to new standards and regulations, by providing certification authorities and standardization committees with the scientifically validated solutions needed to craft effective standards extended to also address cooperation and system-of-systems issues. The project has 28 partners from 6 European countries, and a budget of about 11 million Euros corresponding to about 1,300 person-months. Paul Pop, Detlef Scholle, Hans A. Hansson, Gunnar Widforss, Malin Rosqvist |
DSD | 3 |
| 2016 | Period-Aware Segmented Synthesis of Schedules for Multi-hop Time-Triggered NetworksabstractTime-triggered offline scheduling is a cost-efficient way to guarantee low communication end-to-end latency and minimal jitter for communication networks in real-time systems. The schedule is generated pre-runtime and indicates the transmission times of time-triggered frames such that contention is prevented. The synthesis of such offline schedules is a bin-packing problem, known to be NP-complete, with complexity driven by the constraints on frame transmissions, and the number of frames in the schedule. Satisfiability Modulo Theories combined with segmented approaches have been successfully used for synthesizing schedules of large networks. However, such synthesis did not take into account frames periods that are much shorter than the time to execute the schedule cycle. This paper presents a period-aware segmented approach that takes into account the frame periods in order to allocate various instances of a frame within a single cycle. We describe three different synthesis strategies and evaluate them with different synthetic experiments. The results show better performance for one of the strategies, which can synthesize schedules of large networks with high communication loads in less than one hour. We also report how the synthesis time and the schedule quality can change with different parameter configurations. Francisco Pozo, Guillermo Rodríguez-Navas, Wilfried Steiner, Hans A. Hansson |
RTCSA | 4 |
| 2015 | A decomposition approach for SMT-based schedule synthesis for time-triggered networksabstractReal-time networks have tight communication latency and minimal jitter requirements. One way to ensure these requirements is the implementation of a static schedule, which defines the transmission points in time of time-triggered frames. Synthesizing such static schedules is known to be an NP-complete problem where the complexity is driven by the large number of constraints imposed by the network. Satisfiabily Modulo Theories (SMT) have been proven powerful tools to synthesize schedules of medium-to-large industrial networks. However, the schedules of new extremely large networks, such as integrated multi-machine factory networks, are defined by an extremely large number of constraints exceeding the capabilities of being synthesized by the tool alone. This paper presents a decomposition approach that will allow us to improve to synthesize schedules with up to two orders of magnitude in terms of the number of constraints that can be handled. We also present an implementation of a dependency tree on top of the decomposition approach to address application-imposed constraints between frames. Francisco Pozo, Wilfried Steiner, Guillermo Rodríguez-Navas, Hans A. Hansson |
ETFA | 4 |
| 2015 | A Method to Generate Reusable Safety Case Fragments from Compositional Safety Analysis
Irfan Sljivo, Barbara Gallina, Jan Carlson, Hans A. Hansson, Stefano Puri |
ICSR | 4 |
| 2015 | Flexible and Efficient Reuse of Multi-mode Components for Building Multi-mode Systems
Hans A. Hansson |
ICSR | 2 |
| 2015 | Using Safety Contracts to Guide the Integration of Reusable Safety Elements within ISO 26262abstractSafety-critical systems usually need to comply with a domain-specific safety standard. To reduce the cost and time needed to achieve the standard compliance, reuse of safety-relevant components is not sufficient without the reuse of the accompanying artefacts. Developing reusable safety components out-of-context of a particular system is challenging, as safety is a system property, hence support is needed to capture and validate the context assumptions before integration of the reusable component and its artefacts in-context of the particular system. We have previously developed a concept of strong and weak safety contracts to facilitate systematic reuse of safety-relevant components and their accompanying artefacts. In this work we define a safety contracts development process and provide guidelines to bridge the gap between reuse of safety elements developed out-of-context of a particular system and their integration in the ISO 26262 safety standard. We use a real-world case for demonstration of the process. Irfan Sljivo, Barbara Gallina, Jan Carlson, Hans A. Hansson |
PRDC | 4 |
| 2015 | A Survey on Testing for Cyber Physical System
Sara Abbaspour Asadollah, Rafia Inam, Hans A. Hansson |
ICTSS | 3 |
| 2014 | Handling Emergency Mode Switch for Component-Based SystemsabstractSoftware reuse is deemed as an effective technique for managing the growing software complexity of large systems. Software complexity can also be reduced by partitioning the system behavior into different modes. Such a multi-mode system is able to dynamically change its behavior by switching between different modes. When a multi-mode system is developed by reusable software components, a crucial issue is how to achieve a seamless composition of multi-mode components and handle mode switch properly. This is the motivation for the Mode Switch Logic (MSL), supporting the development of component-based multi-mode systems by providing mechanisms for mode switch handling. In this paper, MSL is extended and adapted to systems with emergency triggering of mode switches that must be handled with minimal delay. We propose an Immediate Handling with Buffering (IHB) approach to enable the responsive handling of such an emergency event in the presence of other concurrent non-emergency mode switch events. We present a model checking based verification of IHB and illustrate its benefits by an example. Yin Hang, Hans A. Hansson |
APSEC (1) | 2 |
| 2014 | Automated Specification and Verification of Functional Safety in Heavy-Vehicles: the VeriSpec ApproachabstractISO 26262 is the new standard for automotive functional safety. This standard identifies major process steps across a large number of system stages as well as safety-related artifacts required as input and output of these steps. The VeriSpec project intends to identify the main challenges for the adoption of ISO 26262 by the heavy-vehicle industry and to provide useful and industrially relevant "components" (methods, tools etc.) required by the standard. The project work targets two main research goals: (i) requirement formalization support, including a usable front-end for specifying requirements by using patterns, and (ii) formal analysis of realizations in form of architectural models at various levels of abstraction, by model-checking the formal representations of the latter. In this paper, we present the current challenges facing industry and justifying VeriSpec, together with a preliminary roadmap for the research. Guillermo Rodríguez-Navas, Cristina Cerschi Seceleanu, Hans A. Hansson, Mattias Nyberg, Oscar Ljungkrantz, Henrik Lönn |
DAC | 3 |
| 2014 | Generation of Safety Case Argument-Fragments from Safety Contracts
Irfan Sljivo, Barbara Gallina, Jan Carlson, Hans A. Hansson |
SAFECOMP | 4 |
| 2013 | Handling Multiple Mode Switch Scenarios in Component-Based Multi-mode SystemsabstractThe growing complexity of embedded systems software entails new development techniques. Component-Based Software Engineering is undoubtedly suitable for the development of complex systems thanks to its inherent component reuse. Another approach to reduce software complexity is by partitioning the system behavior into different operational modes. Each mode is associated with a unique behavior and the system can change behavior by switching between modes. When such a multi-mode system is developed by reusable software components, a crucial issue is how to achieve a seamless composition of multi-mode components and also how to handle mode switch properly. As an integrated solution to the challenges of multi-mode component-based software system development we have proposed the Mode Switch Logic (MSL). The current version of MSL assumes independent handling of a single mode switch scenario, i.e. that no other mode switch is triggered until an ongoing mode switch is completed. For a wide class of systems, this is an unrealistic assumption. In this paper we lift this assumption by proposing an extension of MSL to handle multiple mode switch scenarios concurrently triggered by different components. Yin Hang, Hans A. Hansson |
APSEC (1) | 2 |
| 2013 | Mode switch timing analysis for component-based multi-mode systems
Hans A. Hansson |
J. Syst. Archit. | 2 |
| 2012 | Timing Analysis for Mode Switch in Component-Based Multi-mode SystemsabstractComponent-Based Development (CBD) reduces development time and effort by allowing systems to be built from pre-developed reusable components. Partitioning the behavior into a set of major operational modes is a classical approach to reduce complexity of embedded systems design and execution. In supporting system modes in CBD, a key issue is seamless composition of pre-developed multi-mode components into systems. We have previously developed a Mode Switch Logic (MSL) for component-based multi-mode systems implementing such seamless composition. In this paper we extend our MSL to cope with atomic transactions, i.e., to handle sets of components that must not be aborted in the middle of the processing of data. This is in contrast with our original MSL, in which components are immediately aborted to perform a mode switch. Based on our extended MSL, we provide analysis of the mode switch timing. Yin Hang, Hans A. Hansson |
ECRTS | 2 |
| 2012 | Better, faster, cheaper, and safer too - Is this really possible?abstractIncreased levels of automation together with increased complexity of automation systems brings increased responsibility on the system developers in terms of quality demands from the legal perspectives as well as company reputation. Component based development of software systems provides a viable and cost-effective alternative in this context provided one can address the quality and safety certification demands in an efficient manner. In this paper we present our vision, challenges and a brief outline of various research themes in which our team is engaged currently within two major projects. Iain Bate, Hans A. Hansson, Sasikumar Punnekkat |
ETFA | 2 |
| 2011 | Analysis of Mistakes as a Method to Improve Test Case DesignabstractTest Design -- how test specifications and test cases are created -- inherently determines the success of testing. However, test design techniques are not always properly applied, leading to poor testing. We have developed an analysis method based on identifying mistakes made when designing the test cases. Using an extended test case template and an expert review, the method provides a systematic categorization of mistakes in the test design. The detailed categorization of mistakes provides a basis for improvement of the Test Case Design, resulting in better tests. In developing our method we have investigated over 500 test cases created by novice testers. In a comparison with industrial test cases we could confirm that many of these mistake categories remain relevant also in an industrial context. Our contribution is a new method to improve the effectiveness of test case construction through proper application of test design techniques, leading to an improved coverage without loss of efficiency. Sigrid Eldh, Hans A. Hansson, Sasikumar Punnekkat |
ICST | 2 |
| 2010 | Towards Fully Automated Test Management for Large Complex SystemsabstractDevelopment of large and complex software intensive systems with continuous builds typically generates large volumes of information with complex patterns and relations. Systematic and automated approaches are needed for efficient handling of such large quantities of data in a comprehensible way. In this paper we present an approach and tool enabling autonomous behavior in an automated test management tool to gain efficiency in concurrent software development and test. By capturing the required quality criteria in the test specifications and automating the test execution, test management can potentially be performed to a great extent without manual intervention. This work contributes towards a more autonomous behavior within a distributed remote test strategy based on metrics for decision making in automated testing. These metrics optimize management of fault corrections and retest, giving consideration to the impact of the identified weaknesses, such as fault-prone areas in software. Sigrid Eldh, Joachim Brandt, Mark Street, Hans A. Hansson, Sasikumar Punnekkat |
ICST | 4 |
| 2008 | Message from the CORCS 2008 Workshop OrganizersabstractPresents the introductory welcome message from the conference proceedings. Cristina Cerschi Seceleanu, Paul Pettersson, Hans A. Hansson |
COMPSAC | 3 |
| 2008 | CORCS 2008 Workshop OrganizationabstractProvides a listing of current committee members and society officers. Cristina Cerschi Seceleanu, Paul Pettersson, Hans A. Hansson |
COMPSAC | 3 |
| 2008 | Scheduling Timed Modules for Correct Resource SharingabstractReal-time embedded systems typically include concurrent tasks of different priorities with time-dependent operations accessing common resources. In this context, unsynchronized parallel executions may lead to hazard situations caused by e.g., race conditions. To be able to detect such faulty system behaviors before implementation, we introduce a unified model of resource constrained, scheduled real-time system descriptions, in Alur's and Henzinger's rigorous framework of timed reactive modules. We take a component-based design perspective and construct the realtime system model, by refinement, as a composition of realtime periodic preemptible tasks with encoded functionality, and a fixed-priority scheduler, all modeled as timed modules. For the model, we express the notions of race condition and redundant locking, formally, as invariance properties that can be verified by model-checking. Cristina Cerschi Seceleanu, Paul Pettersson, Hans A. Hansson |
ICST | 3 |
| 2007 | Modeling and Verification of Master/Slave Clock Synchronization Using Hybrid Automata and Model-Checking
Guillermo Rodríguez-Navas, Julián Proenza, Hans A. Hansson |
ICFEM | 3 |
| 2007 | The SAVE approach to component-based development of vehicular systems
Mikael Åkerholm, Jan Carlson, Johan Fredriksson, Hans A. Hansson, John Håkansson, Anders Möller, Paul Pettersson, Massimo Tivoli |
J. Syst. Softw. | 4 |
| 2006 | Integration of networked subsystems in a resource constrained environmentabstractWhen developing embedded systems, there is currently a trend to move from a traditional federated approach, where computer systems are developed for their own dedicated hardware architecture, to an integrated approach, where computer systems are encapsulated as subsystems and later integrated on a shared hardware architecture. The task of integrating subsystems is complex, and in resource constrained systems efficient techniques and methods are required. In this paper the issue of subsystem integration is thoroughly discussed, and it is shown how to use Server-CAN, a network scheduler for the controller area network, in the context of subsystem integration. As the network is a resource shared by all subsystems in a distributed architecture, its role in the integration process is particularly important. Here, the usage of an efficient and flexible network scheduler is essential. Thomas Nolte, Hans A. Hansson, Lucia Lo Bello |
ETFA | 2 |
| 2006 | Automatic Generation and Validation of Models of Legacy SoftwareabstractThe modeling approach is not used to its full potential in maintenance of legacy systems. Often, models do not even exist. The main reasons being that the economic implications and practical hurdles in manually maintaining models of in-use legacy systems are considered too high by the industry. In this paper, we present a method for automated validation of models automatically generated from recordings of executing real-time embedded systems. This forms an essential constituent of a unified process for the automatic modeling of legacy software. We also present a study in which we automatically model a state-of-practice industrial robot control system, the results of which are clearly positive indicators of the viability of our approach Joel Huselius, Johan Andersson, Hans A. Hansson, Sasikumar Punnekkat |
RTCSA | 3 |
| 2005 | Automotive communications-past, current and futureabstractThis paper presents a state-of-practice (SOP) overview of automotive communication technologies, including the latest technology developments. These networking technologies are classified in four major groups: (1) current wired, (2) multimedia, (3) upcoming wired and (4) wireless. Within these groups a few technologies stand out as strong candidates for future automotive networks. The goal of this paper is to give an overview of automotive applications relying on communications, identify the key networking technologies used in various automotive applications, present their properties and attributes, and indicate future challenges in the area of automotive communications Thomas Nolte, Hans A. Hansson, Lucia Lo Bello |
ETFA | 2 |
| 2005 | Towards analyzing the fault-tolerant operation of server-CANabstractThis work-in-progress (WIP) paper presents server-CAN and highlights its operation and possible vulnerabilities from a fault tolerance point of view. The paper extends earlier work on server-CAN by investigating the behaviour of server-CAN in faulty conditions. Different types of faults are described, and their impact on sever-CAN is discussed, which is the subject of on-going research Thomas Nolte, Guillermo Rodríguez-Navas, Julián Proenza, Sasikumar Punnekkat, Hans A. Hansson |
ETFA | 5 |
| 2005 | Real-time server-based communication with CANabstractThis paper investigates the concept of share-driven scheduling of networks using servers with real-time properties. Share-driven scheduling provides fairness and bandwidth isolation between predictable as well as unpredictable streams of messages on the network. The need for this kind of scheduled real-time communication network is high in applications that have requirements on flexibility, both during development for assigning communication bandwidth to different applications, and during run-time to facilitate dynamic addition and removal of system components. We illustrate the share-driven scheduling concept by applying it to the popular controller area network (CAN). We propose a scheduling mechanism that we call simple server-scheduled CAN (S/sup 3/-CAN), for which we also present an associated timing analysis. Additionally, we present a variant of S/sup 3/-CAN called periodic server-scheduled CAN (PS/sup 2/-CAN), which for some network configurations gives lower worst-case response-times than S/sup 3/-CAN. Also for this improvement, a timing analysis is presented. Moreover, we use simulation to evaluate the timing performance of both S/sup 3/-CAN and PS/sup 2/-CAN, comparing them with other scheduling mechanisms. Thomas Nolte, Mikael Nolin, Hans A. Hansson |
IEEE Trans. Ind. Informatics | 3 |
| 2003 | Server-based scheduling of the CAN busabstractIn this paper we present a new share-driven server-based method for scheduling messages sent over the controller area network (CAN). Share-driven methods are useful in many applications, since they provide both fairness and bandwidth isolation among the users of the resource. Our method is the first share-driven scheduling method proposed for CAN. Our server-based scheduling is based on earliest deadline first (EDF), which allows higher utilization of the network than using CAN's native fixed-priority scheduling approach. We use simulation to show the performance and properties of server-based scheduling for CAN. The simulation results show that the bandwidth isolation property is kept, and they show that our method provides a quality-of-service (QoS), where virtually all messages are delivered within a specified time. Thomas Nolte, Mikael Sjödin, Hans A. Hansson |
ETFA (1) | 3 |
| 2003 | Worst-case execution-time analysis for embedded real-time systems
Jakob Engblom, Andreas Ermedahl, Mikael Sjödin, Jan Gustafsson, Hans A. Hansson |
Int. J. Softw. Tools Technol. Transf. | 5 |
| 2001 | A simulation based approach for estimating the reliability of distributed real-time systemsabstractDesigners of safety-critical real-time systems are often mandated by requirements on reliability as well as timing guarantees. For guaranteeing timing properties, the standard practice is to use various analysis techniques provided by hard real-time scheduling theory. The paper presents analysis based on simulation, that considers the effects of faults and timing parameter variations on schedulability analysis, and its impact on the reliability estimation of the system. We look at a wider set of scenarios than just the worst case considered in hard real-time schedulability analysis. The ideas have general applicability, but the method has been developed with modelling the effects of external interferences on the controller area network (CAN) in mind. We illustrate the method by showing that a CAN interconnected distributed system, subjected to external interference, may be proven to satisfy its timing requirements with a sufficiently high probability, even in cases when the worst-case analysis has deemed it non-schedulable. Hans A. Hansson, Christer Norström, Sasikumar Punnekkat |
ETFA (1) | 1 |
| 2000 | Using deterministic replay for debugging of distributed real-time systemsabstractCyclic debugging is one of the most important and most commonly used activities in program development. During cyclic debugging, a program is repeatedly re-executed to track down errors when a failure has been observed. This process necessitates reproducible program executions. Applying classical debugging techniques, such as using breakpoints or single stepping, in real-time systems changes the temporal behaviour and makes reproduction of the observed failure during debugging less likely, if not impossible. Consequently, these techniques are not directly applicable to the cyclic debugging of real-time systems. In this paper, we present a novel software-based approach for the cyclic debugging of distributed real-time systems. By the online recording of significant system events, and then deterministically replaying them off-line, we can inspect a real-time system in great detail, while still preserving its real-time behaviour. Henrik Thane, Hans A. Hansson |
ECRTS | 2 |
| 1999 | Towards Systematic Testing of Distributed Real-Time SystemsabstractReproducible and deterministic testing of sequential programs can in most cases be achieved by controlling the sequence of inputs to the program. The behavior of a distributed real-time system, on the other hand not only depends on the inputs but also on the order and timing of the concurrent tasks that execute and communicate with each other and the environment. Hence, sequential test techniques are not directly applicable, since they disregard the significance of order and timing of the tasks. In this paper we present a method for identifying all possible orderings of task starts, preemptions and completions for tasks executing in a distributed real-time system. Together with an accompanying testing strategy, this method allows test methods for sequential programs to be applied, since each identified ordering can be regarded as a sequential program. In the presented analysis and testing strategy, we consider task sets with recurring release patterns, and take into account the effects of clock synchronization and variations in start and execution times of the involved tasks. Henrik Thane, Hans A. Hansson |
RTSS | 2 |
| 1998 | Improved Response-Time Analysis CalculationsabstractSchedulability analysis of fixed priority preemptive scheduled systems can be performed by calculating the worst-case response-time of the involved processes. The system is deemed schedulable if the calculated response-time for each process is less than its corresponding deadline. It is desirable that the Response-Time Analysis (RTA) can be efficiently performed. This is particularly important in dynamic real-time systems when a fast response is needed to decide whether a new job can be accommodated, or when the RTA is extensively applied, e.g., when used to guide the heuristics in a higher level optimiser. This paper presents a set of methods to improve the efficiency of RTA calculations. The methods are proved correct, in the sense that they give the same results as traditional (non-improved) RTA. We also present an evaluation of the improvements, by applying them to the particularly time-consuming traffic model used in RTA for ATM communication networks. Our evaluation shows that the proposed methods can give an order of magnitude reduction of the execution time of RTA. Mikael Sjödin, Hans A. Hansson |
RTSS | 2 |
| 1998 | The Slack Method: A New Method for Static Allocation of Hard Real-Time Tasks
Peter Altenbernd, Hans A. Hansson |
Real Time Syst. | 2 |
| 1997 | Response-time guarantees in ATM networksabstractWe present a method for providing response time guarantees in Asynchronous Transfer Mode (ATM) networks. The method is based on traditional real time CPU Response Time Analysis (RTA), and is intended to be used for admission control of hard real time traffic. The method determines if a new connection can be admitted without violating the strict timing requirements specified for the new as well as old connections. We illustrate the merits of our method by comparing it with Weighted Fair Queuing (WFQ) and the Calculus for Network Delays (CND). Two types of comparisons are made. In the first, we evaluate how well the associated analysis can accommodate different traffic scenarios and loads, and in the second comparison we use simulation to compare observed worst case behaviors with estimates obtained by the analysis. The comparisons clearly indicate that RTA outperforms both WFQ and CND for a set of realistic traffic scenarios. Andreas Ermedahl, Hans A. Hansson, Mikael Sjödin |
RTSS | 2 |
| 1997 | BASEMENT: An Architecture and Methodology for Distributed Automotive Real-Time SystemsabstractBASEMENT/sup TM/ is a distributed real-time architecture developed for vehicle internal use in the automotive industry. BASEMENT covers application development, as well as the hardware and software that provide execution and communication support. This paper gives an overview of the BASEMENT concept, as well as presenting two system realizations. The first realization is based on the commercial real-time kernel Rubus, while the second is an ultra-dependable architecture (DACAPO) with provisions for fault tolerance at various system levels. BASEMENT is designed for the automotive systems of the future. These systems will be required to simultaneously handle multiple safety critical functions and a large number of less critical functions. All of these features are to be provided at a production cost substantially lower than that of current systems, and, at the same time, with a reliability allowing vehicles to be built without mechanical backup systems, even for safety critical subsystems such as braking and steering. Hans A. Hansson, Harold W. Lawson, Olof Bridal, Christer Eriksson, Sven Larsson, Henrik Lönn, Mikael Strömberg |
IEEE Trans. Computers | 1 |
| 1996 | BASEMENT: A Distributed Real-Time Architecture for Vehicle Applications
Hans A. Hansson, Harold W. Lawson, Mikael Strömberg, Sven Larsson |
Real Time Syst. | 1 |
| 1994 | A Logic for Reasoning about Time and ReliabilityabstractAbstract We present a logic for stating properties such as, “after a request for service there is at least a 98% probability that the service will be carried out within 2 seconds”. The logic extends the temporal logic CTL by Emerson, Clarke and Sistla with time and probabilities. Formulas are interpreted over discrete time Markov chains. We give algorithms for checking that a given Markov chain satisfies a formula in the logic. The algorithms require a polynomial number of arithmetic operations, in size of both the formula and the Markov chain. A simple example is included to illustrate the algorithms. Hans A. Hansson, Bengt Jonsson 0001 |
Formal Aspects Comput. | 1 |
| 1991 | Modeling Timeouts and Unreliable Media with a Timed Probabilistic Calculus
Hans A. Hansson |
FORTE | 1 |
| 1990 | A Calculus for Communicating Systems with Time and ProbabitiliesabstractA process algebra that extends R. Milner's (1983) calculus of communicating systems (CCS) with probabilities and time is presented. With this calculus it is possible to describe real-time and reliability aspects of distributed systems. A (strong) bisimulation equivalence is defined, and a corresponding complete axiomatization is given. Several examples are included.> Hans A. Hansson, Bengt Jonsson 0001 |
RTSS | 1 |
| 1989 | Specification for Verification
Hans A. Hansson, Bengt Jonsson 0001, Fredrik Orava, Björn Pehrson |
FORTE | 1 |
| 1989 | A Framework for Reasoning about Time and ReliabilityabstractA logic is presented for stating properties such as 'after a request for service there is at least a 98% probability that the service will be carried out within 2 s'. The logic extends the temporal logic CTL by E.A. Emerson et al. (1983) with time and probabilities. Formulas are interpreted over discrete time Markov chains. Algorithms are provided for checking that a given Markov chain satisfies a formula in the logic. An example is included to illustrate the algorithms.> Hans A. Hansson, Bengt Jonsson 0001 |
RTSS | 1 |