Martin Törngren

dblp:95/1411 · DBLP profile ↗
← Back
38ranked-venue papers
2as first author
10since 2021 · last 2025
0000-0002-4300-885XORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 12 · 2 first-author · 3 since 2021Software engineering, systems software and programming languages · 11 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 7 · 2 since 2021Security and privacy · 5Artificial intelligence and machine learning · 4 · 2 since 2021Human-computer interaction and ubiquitous computing · 2 · 2 since 2021
YearPublicationVenuePosition
2025 The Road to Safe Automated Driving Systems: A Review of Methods Providing Safety Evidence
abstract
In recent years, enormous investments in Automated Driving Systems (ADSs) have distinctly advanced ADS technologies. Despite promises made by several high profile auto-makers, it has however become clear that the challenges involved for deploying ADS have been drastically underestimated. Contrary to previous generations of automotive systems, common design, development, verification and validation methods for safety critical systems do not suffice to cope with the increased complexity and operational uncertainties of an ADS. Therefore, the aim of this paper is to provide an understanding of existing methods for providing safety evidence and, most importantly, identifying the associated challenges and gaps pertaining to the use of each method. To this end, we have performed a literature review, articulated around four categories of methods: design techniques, verification and validation methods, run-time risk assessment, and run-time (self-)adaptation. We have identified and present eight challenges, collectively distinguishing ADSs from safety critical systems in general, and discuss the reviewed methods in the light of these eight challenges. For all reviewed methods, the uncertainties of the operational environment and the allocation of responsibility for the driving task on the ADS stand-out as the most difficult challenges to address. Finally, a set of research gaps is identified, and grouped into five major themes: 1) completeness of provided safety evidence, 2) improvements and analysis needs, 3) safe collection of closed loop data and accounting for tactical responsibility on the part of the ADS, 4) integration of AI/ML-based components, and 5) scalability of the approaches with respect to the complexity of the ADS.
Magnus Gyllenhammar, Gabriel Rodrigues de Campos, Martin Törngren
IEEE Trans. Intell. Transp. Syst.3
2023 Special Session: Digital Technologies for Sustainability - Research Challenges and Opportunities
Paul Pop, Christian Graulund, Sonia Yeh, Martin Törngren
CODES+ISSS4
2023 Finding Critical Scenarios for Automated Driving Systems: A Systematic Mapping Study
abstract
Scenario-based approaches have been receiving a huge amount of attention in research and engineering of automated driving systems. Due to the complexity and uncertainty of the driving environment, and the complexity of the driving task itself, the number of possible driving scenarios that an Automated Driving System or Advanced Driving-Assistance System may encounter is virtually infinite. Therefore it is essential to be able to reason about the identification of scenarios and in particular critical ones that may impose unacceptable risk if not considered. Critical scenarios are particularly important to support design, verification and validation efforts, and as a basis for a safety case. In this paper, we present the results of a systematic mapping study in the context of autonomous driving. The main contributions are: (i) introducing a comprehensive taxonomy for critical scenario identification methods; (ii) giving an overview of the state-of-the-art research based on the taxonomy encompassing 86 papers between 2017 and 2020; and (iii) identifying open issues and directions for further research. The provided taxonomy comprises three main perspectives encompassing the problem definition (the why), the solution (the methods to derive scenarios), and the assessment of the established scenarios. In addition, we discuss open research issues considering the perspectives of coverage, practicability, and scenario space explosion.
Xinhai Zhang, Jianbo Tao, Kaige Tan, Martin Törngren, José Manuel Gaspar Sánchez, Muhammad Rusyadi Ramli, Xin Tao 0003, Magnus Gyllenhammar, Franz Wotawa, Naveen Mohan, Mihai Nica, Hermann Felbinger
IEEE Trans. Software Eng.4
2022 Which skills? A critical perspective on the skills facilitating the transfer of third-cycle students to knowledge-intensive SMEs
abstract
This Research Full Paper relates to public-private innovation ecosystems. This loosely knit form of cooperation allows for beneficial activities such as knowledge transfer, dissemination of novel technology, and recruitment. In these contexts students graduating from third-cycle education should be able to find opportunities for transferring to knowledge-intensive positions in small and medium-sized enterprises (SMEs).(/p)()pHowever, a 3-year study of the reasons why firms approach public organisations within a Europe-wide, public-private innovation ecosystem suggests that students might struggle to find such opportunities. Through a questionnaire provided to all firms approaching the ecosystem we identify recruitment as one of their lowest ranked interests. By interviewing members of the public organisations found in the ecosystem we identify how cooperation is initiated and maintained, and how this influences the opportunities for students to transfer into industry. The results provide nuance to the current emphasis in skill development within third-cycle (engineering) education. It is rarely recognized that fostering technical skill and academic entrepreneurship might not be enough to allow all types and sizes of firms to receive engineering students.Particularly, this study identifies the academic and industrial boundary spanning roles at knowledge-intensive SMEs as important. These roles require a third-cycle education that early on hones skills that typically do not become critical until much later for students that pursue an academic path – e.g., the inter-organisational project management skills necessary to effectively seek research funding or to negotiate goal alignment between organisations. We argue that to allow third-cycle students to practice the finer points of such skills, universities need to evolve more distributed support structures for innovation that integrate in-depth engineering knowledge with innovation skills and have an increased focus on human and social capital.
Fredrik Asplund, Mats Magnusson, Martin Törngren, Tobias Vahlne, Martin Karlsson
FIE3
2022 Uncertainty Aware Data Driven Precautionary Safety for Automated Driving Systems Considering Perception Failures and Event Exposure
abstract
Ensuring safety is arguably one of the largest remaining challenges before wide-spread market adoption of Automated Driving Systems (ADSs). One central aspect is how to provide evidence for the fulfilment of the safety claims and, in particular, how to produce a predictive and reliable safety case considering both the absence and the presence of faults in the system. In order to provide such evidence, there is a need for describing and modelling the different elements of the ADS and its operational context: models of event exposure, sensing and perception models, as well as actuation and closed-loop behaviour representations. This paper explores how estimates from such statistical models can impact the performance and operation of an ADS and, in particular, how such models can be continuously improved by incorporating more field data retrieved during the operation of (previous versions 00 the ADS. Focusing on the safe driving velocity, this results in the ability to update the driving policy so to maximise the allowed safe velocity, for which the safety claim still holds. For illustration purposes, an example considering statistical models of the exposure to an adverse event, as well as failures related to the system’s perception system, is analysed. Estimations from these models, using statistical confidence limits, are used to derive a safe driving policy of the ADS. The results highlight the importance of leveraging field data in order to improve the system’s abilities and performance, while remaining safe. The proposed methodology, leveraging a data-driven approach, also shows how the system’s safety can be monitored and maintained, while allowing for incremental expansion and improvements of the ADS.
Magnus Gyllenhammar, Gabriel Rodrigues de Campos, Fredrik Sandblom, Martin Törngren, Håkan Sivencrona
IV4
2022 Foresee the Unseen: Sequential Reasoning about Hidden Obstacles for Safe Driving
abstract
Safe driving requires autonomous vehicles to anticipate potential hidden traffic participants and other unseen objects, such as a cyclist hidden behind a large vehicle, or an object on the road hidden behind a building. Existing methods are usually unable to consider all possible shapes and orientations of such obstacles. They also typically do not reason about observations of hidden obstacles over time, leading to conservative anticipations. We overcome these limitations by (1) modeling possible hidden obstacles as a set of states of a point mass model and (2) sequential reasoning based on reachability analysis and previous observations. Based on (1), our method is safer, since we anticipate obstacles of arbitrary unknown shapes and orientations. In addition, (2) increases the available drivable space when planning trajectories for autonomous vehicles. In our experiments, we demonstrate that our method, at no expense of safety, gives rise to significant reductions in time to traverse various intersection scenarios from the CommonRoad Benchmark Suite.
José Manuel Gaspar Sánchez, Truls Nyberg, Christian Pek, Jana Tumova, Martin Törngren
IV5
2022 Edge Computing for Cyber-physical Systems: A Systematic Mapping Study Emphasizing Trustworthiness
abstract
Edge computing is projected to have profound implications in the coming decades, proposed to provide solutions for applications such as augmented reality, predictive functionalities, and collaborative Cyber-Physical Systems (CPS). For such applications, edge computing addresses the new computational needs, as well as privacy, availability, and real-time constraints, by providing local high-performance computing capabilities to deal with the limitations and constraints of cloud and embedded systems. Edge computing is today driven by strong market forces stemming from IT/cloud, telecom, and networking—with corresponding multiple interpretations of “edge computing” (e.g., device edge, network edge, distributed cloud). Considering the strong drivers for edge computing and the relative novelty of the field, it becomes important to understand the specific requirements and characteristics of edge-based CPS, and to ensure that research is guided adequately, e.g., avoiding specific gaps. Our interests lie in the applications of edge computing as part of CPS, where several properties (or attributes) of trustworthiness, including safety, security, and predictability/availability, are of particular concern, each facing challenges for the introduction of edge-based CPS. We present the results of a systematic mapping study, a kind of systematic literature survey, investigating the use of edge computing for CPS with a special emphasis on trustworthiness. The main contributions of this study are a detailed description of the current research efforts in edge-based CPS and the identification and discussion of trends and research gaps. The results show that the main body of research in edge-based CPS only to a very limited extent consider key attributes of system trustworthiness, despite many efforts referring to critical CPS and applications like intelligent transportation. More research and industrial efforts will be needed on aspects of trustworthiness of future edge-based CPS including their experimental evaluation. Such research needs to consider the multiple interrelated attributes of trustworthiness including safety, security, and predictability, and new methodologies and architectures to address them. It is further important to provide bridges and collaboration between edge computing and CPS disciplines.
José Manuel Gaspar Sánchez, Nils Jörgensen, Martin Törngren, Rafia Inam, Andrii Berezovskyi, Lei Feng 0002, Elena Fersman, Muhammad Rusyadi Ramli, Kaige Tan
ACM Trans. Cyber Phys. Syst.3
2022 Model-Based Systems Engineering Tool-Chain for Automated Parameter Value Selection
abstract
Cyber-physical systems (CPSs) integrate heterogeneous systems and process sensor data using digital services. As the complexity of CPS increases, it becomes more challenging to efficiently formalize the integrated multidomain views with flexible automated verification across the entire lifecycle. This article illustrates a model-based systems engineering tool-chain to support CPS development with an emphasis on automated parameter value selection for co-simulation. First, a domain-specific modeling approach is introduced to support the formalizations of CPS artifacts, development processes, and simulation configurations. The domain-specific models are used as the basis to generate a Web-based process management system for automated parameter value selections, which coordinates Open Services for Lifecycle Collaboration services of development information and technical resources (models, data, and tools) in order to support automated co-simulation. The services are deployed by a service orchestrator based on a decision-making algorithm for parameter value selection. Finally, developers make use of the WPMS to implement simulations and to select system parameter values for co-simulation automatically. The approach is illustrated by a case study on auto-braking system development and we evaluate the efficiency of this tool-chain by both qualitative and quantitative methods. The results show that parameter values are selected more efficiently and effectively when implementing co-simulations using our tool-chain.
Jinzhi Lu 0001, Dejiu Chen, Guoxin Wang 0001, Dimitris Kiritsis, Martin Törngren
IEEE Trans. Syst. Man Cybern. Syst.5
2021 Programmable Systems for Intelligence in Automobiles (PRYSTINE): Final results after Year 3
abstract
Autonomous driving is disrupting the automotive industry as we know it today. For this, fail-operational behavior is essential in the sense, plan, and act stages of the automation chain in order to handle safety-critical situations on its own, which currently is not reached with state-of-the-art approaches.The European ECSEL research project PRYSTINE realizes Fail-operational Urban Surround perceptION (FUSION) based on robust Radar and LiDAR sensor fusion and control functions in order to enable safe automated driving in urban and rural environments. This paper showcases some of the key exploitable results (e.g., novel Radar sensors, innovative embedded control and E/E architectures, pioneering sensor fusion approaches, AI-controlled vehicle demonstrators) achieved until its final year 3.
Norbert Druml, Anna Ryabokon, Rupert Schorn, Jochen Koszescha, Kaspars Ozols, Aleksandrs Levinskis, Rihards Novickis, Ethiopia Nigussie, Jouni Isoaho, Selim Solmaz, Georg Stettinger, Sergio E. Diaz, Mauricio Marcano, Jorge Villagra, Juan Medina, Martina Schwarz, Antonio Artuñedo, Mauro Comi, Rutger Beekelaar, Onur Özçelik, Elif Aksu Tasdelen, Yesim Gürbüz, Jan Saijets, Jukka Kyynäräinen, Dmitry Morits, Björn Debaillie, Maxim Rykunov, Joan Escamilla, Jarno Vanne, Tomi Korhonen, Kalle Holma, Eva-Maria Matzhold, Carlo Novara, Fabio Tango, Paolo Burgio, Giuseppe Carlo Calafiore, Milad Karimshoushtari, Emilie Boulay, Miguel Dhaens, Kylian Praet, Han Zwijnenberg, Henri Palm, David Aledo Ortega, Ercan Kalali, Tuomas Pensala, Arto Kyytinen, Morten Larsen, Omar Veledar, Georg Macher, Michael Lafer, Lorenzo Giraudi, Jakob Reckenzaun, Daniel Hammer, Naveen Mohan, Josef Schmid, Alfred Höß, Shai Ophir, Anand Dubey, Jonas Fuchs, Maximilian Lübke, Andrei Anghel, Nicolae-Catalin Ristea, Martin Törngren, Alua Musralina, Marlene Harter, Joseena Memadathil Jose, George Dimitrakopoulos 0001
DSD63
2021 Industrial Edge-based Cyber-Physical Systems - Application Needs and Concerns for Realization
Martin Törngren, Haydn Thompson, Erik Herzog, Rafia Inam, James Gross, György Dán
SEC1
2019 Efficient State Update Exchange in a CPS Environment for Linked Data-based Digital Twins
abstract
This paper addresses the problem of reducing the number of messages needed to exchange state updates between the Cyber-Physical System (CPS) components that integrate with the rest of the CPS through Digital Twins in order to maintain uniform communication interface and carry out their tasks correctly and safely. The main contribution is a proposed architecture and the discussion of its suitability to support correct execution of complex tasks across the CPS. A new State Event Filtering component is presented to provide event-based communication among Digital Twins that are based on the Linked Data principles while keeping the fan-out limited to ensure the scalability of the architecture.
Andrii Berezovskyi, Rafia Inam, Jad El-khoury, Martin Törngren, Elena Fersman
INDIN4
2019 Adaptive Trajectory Planning and optimization at Limits of Handling
abstract
In this paper, we tackle the problem of trajectory planning and control of a vehicle under locally varying traction limitations, in the presence of suddenly appearing obstacles. We employ concepts from adaptive model predictive control for run-time adaptation of tire force constraints that are imposed by local traction conditions. To solve the resulting optimization problem for real-time control synthesis with such time varying constraints, we propose a novel numerical scheme based on Real Time Iteration Sequential Quadratic Programming (RTI-SQP), which we call Sampling Augmented Adaptive RTI (SAA-RTI). Sampling augmentation of conventional RTI-SQP provides additional feasible candidate trajectories for warm-starting the optimization procedure. Thus, the proposed SAA-RTI algorithm enables real time constraint adaptation and reduces sensitivity to local minima. Through extensive numerical simulations we demonstrate that our method increases the vehicle's capacity to avoid accidents in scenarios with unanticipated obstacles and locally varying traction, compared to equivalent non-adaptive control schemes and traditional planning and tracking approaches.
Lars J. Svensson, Monimoy Bujarbaruah, Nitin R. Kapania, Martin Törngren
IROS4
2018 Safe Stop Trajectory Planning for Highly Automated Vehicles: An Optimal Control Problem Formulation
abstract
Highly automated road vehicles need the capability of stopping safely in a situation that disrupts continued normal operation, e.g. due to internal system faults. Motion planning for safe stop differs from nominal motion planning, since there is not a specific goal location. Rather, the desired behavior is that the vehicle should reach a stopped state, preferably outside of active lanes. Also, the functionality to stop safely needs to be of high integrity. The first contribution of this paper is to formulate the safe stop problem as a benchmark optimal control problem, which can be solved by dynamic programming. However, this solution method cannot be used in real-time. The second contribution is to develop a real-time safe stop trajectory planning algorithm, based on selection from a precomputed set of trajectories. By exploiting the particular properties of the safe stop problem, the cardinality of the set is decreased, making the algorithm computationally efficient. Furthermore, a monitoring based architecture concept is proposed, that ensures dependability of the safe stop function. Finally, a proof of concept simulation using the proposed architecture and the safe stop trajectory planner is presented.
Lars J. Svensson, Lola Masson, Naveen Mohan, Erik Ward, Anna Pernestål Brenden, Lei Feng 0002, Martin Törngren
Intelligent Vehicles Symposium7
2018 Empirical-Evolution of Frameworks Supporting Co-simulation Tool-Chain Development
Jinzhi Lu 0001, Didem Gürdür Broo, Dejiu Chen, Jian Wang 0024, Martin Törngren
WorldCIST (1)5
2017 A Case Study on Achieving Fair Data Age Distribution in Vehicular Communications
abstract
In vehicular communication protocol stacks, received messages may not always be decoded successfully due to the complexity of the decoding functions, the uncertainty of the communication load and the limited computation resources. Even worse, an improper implementation of the protocol stack may cause an unfair data age distribution among all the communicating vehicles (the receiving bias problem). In such cases, some vehicles are almost locked out of the vehicular communication, causing potential safety risk in scenarios such as intersection passing. To our knowledge, this problem has not been systematically studied in the fields of vehicular communication and intelligent transport systems (ITS). This paper analyzes the root of the receiving bias problem and proposes architectural solutions to balance data age distribution. Simulation studies based on commercial devices demonstrate the effectiveness of these solutions. In addition, our system has been successfully applied during the Grand Cooperative Driving Challenge, where complicated scenarios involving platooning maneuvering and intersection coordination were conducted.
Xinhai Zhang, Xinwu Song, Lei Feng 0002, Martin Törngren
RTAS5
2016 Security-aware development of cyber-physical systems illustrated with automotive case study
Viacheslav Izosimov, Alexandros Asvestopoulos, Oscar Blomkvist, Martin Törngren
DATE4
2016 Formulating customized specifications for resource allocation problem of distributed embedded systems
abstract
There are plentiful attempts for increasing the efficiency, generality and optimality of the Design Space Exploration (DSE) algorithms for resource allocation problems of distributed embedded systems. Most contemporary approaches formulate DSE as an optimization or SAT problem, based on a set of predefined constraints. In this way, the end users lose the flexibility to guide and customize the exploration based on specifics of their actual problem. Besides, during the design of the DSE algorithms, manual formulation is time consuming and error-prone. To solve these problems, 1) a formal representation is defined for capturing customized architectural constraints based on a combination of propositional logic and Pseudo-Boolean (PB) formulas; 2) A process is designed to automatically translate these architectural constrains into corresponding Integer Linear Programming (ILP) constraints, commonly used for DSE. The translation process is also optimized to create ILP formulation with less introduced variables so as to reduce computation time. The results show that the generated constraints correctly reflect the corresponding specification with decent efficiency.
Xinhai Zhang, Lei Feng 0002, Martin Törngren, Dejiu Chen
ICCAD3
2016 A functional reference architecture for autonomous driving
Sagar Behere, Martin Törngren
Inf. Softw. Technol.2
2015 The discourse on tool integration beyond technology, a literature survey
Fredrik Asplund, Martin Törngren
J. Syst. Softw.2
2014 On the modeling and generation of service-oriented tool chains
Matthias Biehl, Jad El-khoury, Frédéric Loiret, Martin Törngren
Softw. Syst. Model.4
2013 A characterization of integrated multi-view modeling in the context of embedded and cyber-physical systems
abstract
Embedded systems, with their tight technology integration, and multiple requirements and stakeholders, are characterized by tightly interrelated processes, information and tools. Embedded systems will as a consequence be described by multiple, heterogeneous and interrelated descriptions such as for example requirements documents, design and analysis models, software and hardware descriptions. We refer to a system designed this way as a multi-view (MV) system. The main contribution of this paper is a characterization of model-based approaches to MV systems. The characterization takes three main perspectives for the relations between viewpoints: semantic relations (content), relations over time (process), and manipulation of views (operations). We complement these perspectives by investigating MV system challenges and by a survey of related approaches. The characterization aims to provide a basis for a better understanding, design and implementation of MV systems, and thereby to overcome the current fragmented points of view on integrated multi-view modeling (MVM).
Magnus Persson 0001, Martin Törngren, Ahsan Qamar, Jonas Westman, Matthias Biehl, Stavros Tripakis, Hans Vangheluwe, Joachim Denil
EMSOFT2
2013 Structuring Safety Requirements in ISO 26262 Using Contract Theory
Jonas Westman, Mattias Nyberg, Martin Törngren
SAFECOMP3
2013 A reference architecture for cooperative driving
Sagar Behere, Martin Törngren, Dejiu Chen
J. Syst. Archit.2
2012 A Timed Automata-Based Method to Analyze EAST-ADL Timing Constraint Specifications
Tahir Naseer Qureshi, Dejiu Chen, Martin Törngren
ECMFA3
2012 Qualifying Software Tools, a Systems Approach
Fredrik Asplund, Jad El-khoury, Martin Törngren
SAFECOMP3
2011 A Concept for Secure Production Programming of Embedded Industrial Field Devices
abstract
The importance of securing the investment made in software is increasing for small embedded devices, as the size of the development efforts are rapidly growing. The meaning of securing in this context is related to protecting against cloning, prohibit reverse engineering of software, preventing alterations performed in order to tweak performance etc. Sales of illegal copies of devices are a major threat to industrial companies. We introduce a concept which mitigates the issues of counterfeiting and unauthorized production, allowing for production of embedded devices in locations which are not trusted. We define this concept as Secure Production Programming. It targets software-intense microcontroller-based embedded devices where it is crucial to protect the embedded software. Moreover, the concept allows for programming of the complete software in any (un-trusted) location without the risk of exposing the intellectual properties contained in the software, eliminating the risk that someone successfully can download the software on non-authentic hardware. A proof of concept implementation of the Secure Production Programming is presented, and performance figures are given.
Jimmy Kjellsson, Martin Törngren
COMPSAC2
2011 From EAST-ADL to AUTOSAR Software Architecture: A Mapping Scheme
Tahir Naseer Qureshi, Dejiu Chen, Henrik Lönn, Martin Törngren
ECSA4
2010 Integrating safety analysis into the model-based development toolchain of automotive embedded systems
abstract
The automotive industry has a growing demand for the seamless integration of safety analysis tools into the model-based development toolchain for embedded systems. This requires translating concepts of the automotive domain to the safety domain. We automate such a translation between the automotive architecture description language EAST-ADL2 and the safety analysis tool HiP-HOPS by using model transformations and by leveraging the advantages of different model transformation techniques. Through this integration, the analysis can be conducted early in the development process, when the system can be redesigned to fulfill safety goals with relatively low effort and cost.
Matthias Biehl, Dejiu Chen, Martin Törngren
LCTES3
2010 Model-Based Safety Engineering of Interdependent Functions in Automotive Vehicles Using EAST-ADL2
Anders Sandberg, Dejiu Chen, Henrik Lönn, Rolf Johansson 0002, Lei Feng 0002, Martin Törngren, Sandra Torchiaro, Ramin Tavakoli Kolagari, Andreas Abele
SAFECOMP6
2010 MODIFI: A MODel-Implemented Fault Injection Tool
Rickard Svenningsson, Jonny Vinter, Henrik Eriksson, Martin Törngren
SAFECOMP4
2008 Modelling Support for Design of Safety-Critical Automotive Embedded Systems
Dejiu Chen, Rolf Johansson 0002, Henrik Lönn, Yiannis Papadopoulos, Anders Sandberg, Fredrik Törner, Martin Törngren
SAFECOMP7
2007 Managing Complexity of Automotive Electronics Using the EAST-ADL
abstract
The complexity of embedded automotive systems calls for a more rigorous approach to system development compared to current state of practice. A critical issue is the management of the engineering information that defines the embedded system. Development time, cost efficiency, quality and dependability all benefit from appropriate information management. System modeling based on an architecture description language is a way to keep the engineering information within one information structure. The EAST-ADL was developed in the EAST-EEA project (www.easteea.net) and is an architecture description language for automotive embedded systems. It is currently refined in the ATESSTproject (www.atesst.org). This paper gives an overview of the EAST-ADL and accounts for some recent refinements as developed in the ATESST project. Areas covered include the relation to other standardization initiatives such as UML2.0, AADL, AUTOSAR, SysML, Marte profile, requirements management and variability.
Philippe Cuenot, Dejiu Chen, Sébastien Gérard, Henrik Lönn, Mark-Oliver Reiser, David Servat, Carl-Johan Sjöstedt, Ramin Tavakoli Kolagari, Martin Törngren, Matthias Weber 0001
ICECCS9
2005 Guidelines for a graduate curriculum on embedded software and systems
abstract
The design of embedded real-time systems requires skills from multiple specific disciplines, including, but not limited to, control, computer science, and electronics. This often involves experts from differing backgrounds, who do not recognize that they address similar, if not identical, issues from complementary angles. Design methodologies are lacking in rigor and discipline so that demonstrating correctness of an embedded design, if at all possible, is a very expensive proposition that may delay significantly the introduction of a critical product. While the economic importance of embedded systems is widely acknowledged, academia has not paid enough attention to the education of a community of high-quality embedded system designers, an obvious difficulty being the need of interdisciplinarity in a period where specialization has been the target of most education systems. This paper presents the reflections that took place in the European Network of Excellence Artist leading us to propose principles and structured contents for building curricula on embedded software and systems.
Paul Caspi, Alberto L. Sangiovanni-Vincentelli, Luís Almeida 0001, Albert Benveniste, Bruno Bouyssounouse, Giorgio C. Buttazzo, Ivica Crnkovic, Werner Damm, Jakob Engblom, Gerhard Fohler, Marisol García-Valls, Hermann Kopetz, Yassine Lakhnech, François Laroussinie, Luciano Lavagno, Giuseppe Lipari, Florence Maraninchi, Philipp Peti, Juan Antonio de la Puente, Norman Scaife, Joseph Sifakis, Robert de Simone, Martin Törngren, Paulo Veríssimo, Andy J. Wellings, Reinhard Wilhelm, Tim A. C. Willemse, Wang Yi 0001
ACM Trans. Embed. Comput. Syst.23
2005 What is embedded systems and how should it be taught?---results from a didactic analysis
abstract
This paper provides an analysis of embedded systems education using a didactic approach. Didactics is a field of educational studies mostly referring to research aimed at investigating what's unique with a particular subject and how this subject ought to be taught. From the analysis we conclude that embedded systems has a thematic identity and a functional legitimacy. This implies that the subject would benefit from being taught with an exemplifying selection and using an interactive communication, meaning that the education should move from teaching “something of everything” toward “everything of something.” The interactive communication aims at adapting the education toward the individual student, which is feasible if using educational methods inspired by project-organized and problem-based learning. This educational setting is also advantageous as it prepares the students for a future career as embedded system engineers. The conclusions drawn from the analysis correlate with our own experiences from education in mechatronics as well as with a recently published study of 21 companies in Sweden dealing with industrial software engineering.
Martin Edin Grimheden, Martin Törngren
ACM Trans. Embed. Comput. Syst.2
2004 A metrics system for quantifying operational coupling in embedded computer control systems
abstract
One central issue in system structuring and quality prediction is the interdependencies of system modules. This paper proposes a novel technique for determining the operational coupling in embedded computer control systems. It allows us to quantify dependencies between modules, formed by different kinds of relationships in a solution, and therefore promotes a more systematic approach to the reasoning about modularity. Compared to other existing coupling metrics, which are often implementation-technology specific such as confining to the inheritance and method invocation relationships in OO software, this metrics system considers both communication and synchronization and can be applied throughout system design. The metrics system has two parts. The first part supports a measurement of coupling by considering individual relationship types separately. The quantification is performed by considering the topology of connections, as well as the multiplicity, replication, frequency, and accuracy of component properties that appear in a relationship. The second part provides a methodology for combining coupling by individual relationship types into an overall coupling, where domain specific heuristics and technology constraints are used to determine the weighting.
Dejiu Chen, Martin Törngren
EMSOFT2
2001 Towards A Framework for Architecting Mechatronics Software Systems
abstract
As mechatronics software systems become larger and more complex, the need to ensure system consistency and completeness with respect to the requirements and to manage system complexity becomes more important. From a system point of view, complexity depends on the number and the multiplicity of system constituent units and their relationships. In this paper, the initial results from our efforts to adopt the concept of software architecture in the development of mechatronics software systems for the purpose of managing complexity and ensuring system qualities are presented. A design framework for architecting mechatronics software systems is being developed. The design framework includes two models. (I) an architecture model, and (2) a decision model. The architecture model aims to provide an effective basis for managing complexity and performing architecture based system development. The decision model aims to provide a basis for reasoning about how to meet flexibility-related qualities in the development.
Dejiu Chen, Martin Törngren
ICECCS2
2001 Towards a Toolset for Architectural Design of Distributed Real-Time Control Systems
abstract
We describe a novel tool developed to support architectural design of distributed real-time control systems. The approach enables the co-simulation of functionality (from discrete-time control to logic) together with the controlled continuous-time processes and the behaviour of the computer system. In particular modelling and simulation of distributed computer control systems is supported allowing analysis of timing and control system robustness. An emphasised feature of the tool is its multidisciplinary and integrated approach that combines the views of control and computer engineering into one view at an appropriate level of abstraction. The use of the models and the tool is illustrated through examples and the usefulness of the approach for architectural design is discussed together with avenues for further work. The current models and the tool are designed with the modelling and analysis of fault-tolerant systems in mind. Improved support in this direction is the subject of ongoing work.
Jad El-khoury, Martin Törngren
RTSS2
1998 Fundamentals of Implementing Real-Time Control Applications in Distributed Computer Systems
Martin Törngren
Real Time Syst.1