EDBT 2026 Demo / reviewers in the wild / expert
Tim Kelly
dblp:k/TimKelly · also Tim P. Kelly
· DBLP profile ↗
52ranked-venue papers
2as first author
8since 2021 · last 2025
0000-0002-7385-2031ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 23 · 1 since 2021Security and privacy · 17 · 2 first-authorApplied, interdisciplinary, general and emerging computing · 5Artificial intelligence and machine learning · 4Systems, architecture and hardware · 4 · 3 since 2021Theory of computation · 2 · 1 since 2021Databases, data management, data science and information retrieval · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Model-Based Security Assurance Cases for Open and Adaptive Cyber-Physical Systems
Luís Nascimento, André Luíz de Oliveira, Regina Braga 0001, Edelberto Franco Silva, Richard Hawkins 0001, Tim Kelly |
AINA (8) | 7 |
| 2024 | From Fault Tree Analysis to Runtime Model-Based Assurance Cases
Luís Nascimento, André Luíz de Oliveira, Regina Braga 0001, Richard Hawkins 0001, Tim Kelly |
AINA (2) | 6 |
| 2024 | ACCESS: Assurance Case Centric Engineering of Safety-critical SystemsabstractAssurance cases are used to communicate and assess confidence in critical system properties such as safety and security. Historically, assurance cases have been manually created documents, which are evaluated by system stakeholders through lengthy and complicated processes. In recent years, model-based system assurance approaches have gained popularity to improve the efficiency and quality of system assurance activities. This becomes increasingly important, as systems becomes more complex, it is a challenge to manage their development life-cycles, including coordination of development, verification and validation activities, and change impact analysis in inter-connected system assurance artifacts. Moreover, there is a need for assurance cases that support evolution during the operational life of the system, to enable continuous assurance in the face of an uncertain environment, as Robotics and Autonomous Systems (RAS) are adopted into society. In this paper, we contribute ACCESS - Assurance Case Centric Engineering of Safety-critical Systems, an engineering methodology, together with its tool support, for the development of safety critical systems around evolving model-based assurance cases. We show how model-based system assurance cases can trace to heterogeneous engineering artifacts (e.g. system architectural models, system safety analysis, system behaviour models, etc.), and how formal methods can be integrated during the development process. We demonstrate how assurance cases can be automatically evaluated both at development and runtime. We apply our approach to a case study based on an Autonomous Underwater Vehicle (AUV). Simon Foster 0001, Fang Yan 0004, Ruizhe Yang, Ibrahim Habli, Colin O'Halloran, Nick Tudor, Tim Kelly, Yakoub Nemouchi |
J. Syst. Softw. | 9 |
| 2024 | DECISIVE: Designing Critical Systems With Iterative Automated Safety AnalysisabstractSystems safety is becoming increasingly challenging due to the presence of ever-more complex applications. Safety analysis is an important aspect of Safety-Critical Systems Engineering (SCSE) to discover problems in system design that can potentially lead to hazards with risks that may lead to accidents. Performing safety analysis requires significant manual effort — its automation has become the research focus in the critical system domain due to the increasing complexity of systems and the emergence of open adaptive systems. In this paper, we propose a novel methodology in which automated safety analysis drives the design of safety-critical systems. We delve into the specifics of our approach and the supporting tools. Additionally, we discuss the method to integrate our approach into the current practice of SCSE. The experimental results reveal that the proposed approach with its supporting tool promotes the efficiency of safety analysis significantly, whilst maintaining high degrees of correctness, coverage and scalability. Zhe Jiang 0004, Xiaoran Guo, Ruizhe Yang, Athanasios Zolotas, Tim Kelly |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 7 |
| 2024 | Automated Model-Based Assurance Case Management Using Constrained Natural LanguageabstractAssurance cases are used to communicate and assess confidence in critical system properties, e.g., safety and security. Historically, assurance cases have been manually created documents, validated by engineers through lengthy and error-prone processes. Recently, system assurance practitioners have begun adopting model-based approaches to improve the efficiency and quality of system assurance activities. This becomes increasingly important, for example, to ensure the safety of robotics and autonomous systems (RASs), as they are adopted into society. Such systems can be highly complex, and so it is a challenge to manage the development life-cycle and improve efficiency, including coordination of validation activities, and change impact analysis in interconnected system assurance artifacts. However, adopting model-based approaches require skills in the model management languages, which system assurance practitioners may not be acquainted with. In this article, we contribute an automated validation framework for the model-based assurance cases, which promotes the usage of a constrained natural language (CNL), that can be automatically transformed and executed against engineering models involved in assurance case development. We apply our approach to a case study based on an autonomous underwater vehicle (AUV). Zhe Jiang 0004, Konstantinos Barmpis, Simon Foster 0001, Tim Kelly, Yan Zhuang 0013 |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 6 |
| 2023 | Runtime Model-Based Assurance of Open and Adaptive Cyber-Physical Systems
Luís Nascimento, André Luíz de Oliveira, Regina Braga 0001, Richard Hawkins 0001, Tim Kelly |
AINA (1) | 6 |
| 2022 | Designing critical systems with iterative automated safety analysisabstractSafety analysis is an important aspect in Safety-Critical Systems Engineering (SCSE) to discover design problems that can potentially lead to hazards and eventually, accidents. Performing safety analysis requires significant manual effort --- its automation has become the research focus in the critical system domain due to the increasing complexity of systems and emergence of open adaptive systems. In this paper, we present a methodology, in which automated safety analysis drives the design of safety-critical systems. We discuss our approach with its tool support and evaluate its applicability. We briefly discuss how our approach fits into current practice of SCSE. Zhe Jiang 0004, Xiaoran Guo, Athanasios Zolotas, Tim Kelly |
DAC | 6 |
| 2021 | Integration of Formal Proof into Unified Assurance Cases with Isabelle/SACMabstractAbstract Assurance cases are often required to certify critical systems. The use of formal methods in assurance can improve automation, increase confidence, and overcome errant reasoning. However, assurance cases can never be fully formalised, as the use of formal methods is contingent on models that are validated by informal processes. Consequently, assurance techniques should support both formal and informal artifacts, with explicated inferential links between them. In this paper, we contribute a formal machine-checked interactive language, called Isabelle/SACM, supporting the computer-assisted construction of assurance cases compliant with the OMG Structured Assurance Case Meta-Model. The use of Isabelle/SACM guarantees well-formedness, consistency, and traceability of assurance cases, and allows a tight integration of formal and informal evidence of various provenance. In particular, Isabelle brings a diverse range of automated verification techniques that can provide evidence. To validate our approach, we present a substantial case study based on the Tokeneer secure entry system benchmark. We embed its functional specification into Isabelle, verify its security requirements, and form a modular security case in Isabelle/SACM that combines the heterogeneous artifacts. We thus show that Isabelle is a suitable platform for critical systems assurance. Simon Foster 0001, Yakoub Nemouchi, Mario Gleirscher, Tim Kelly |
Formal Aspects Comput. | 5 |
| 2020 | Engineering of Runtime Safety Monitors for Cyber-Physical Systems with Digital Dependability Identities
Jan Reich, Daniel Schneider 0001, Ioannis Sorokos, Yiannis Papadopoulos, Tim Kelly, Eric Armengaud, Cem Kaypmaz |
SAFECOMP | 5 |
| 2019 | Isabelle/SACM: Computer-Assisted Assurance Cases with Integrated Formal Methods
Yakoub Nemouchi, Simon Foster 0001, Mario Gleirscher, Tim Kelly |
IFM | 4 |
| 2019 | Devil's in the Detail: Through-Life Safety and Security Co-assurance Using SSAF
Nikita Johnson, Tim Kelly |
SAFECOMP | 2 |
| 2019 | Model based system assurance using the structured assurance case metamodel
Tim Kelly, Xiaotian Dai 0001, Shuai Zhao 0004, Richard Hawkins 0001 |
J. Syst. Softw. | 2 |
| 2019 | Variability management in safety-critical systems design and dependability analysisabstractAbstract Safety‐critical systems are of paramount importance for many application domains, where safety properties are a key driver to engineer critical aspects and avoid system failures. For the benefits of large‐scale reuse, software product lines (SPL) have been adopted in critical systems industry. However, the integration of safety analysis in the SPL development process is nontrivial. Also, the different usage contexts of safety‐critical systems complicates component fault modeling tasks and the identification of potential hazards. In this light, better methods become necessary to estimate the impact of dependability properties during Hazard Analysis and Risk Assessment. Existing methods incorporating the analysis of safety properties in SPL are limited as they do not include hazard analysis and component fault modeling. In this paper, we present the novel DEPendable Software Product Line Engineering (DEPendable‐SPLE) approach, which extends traditional SPL processes to support the reuse of safety assets. We also present a detailed analysis of the impact of product and context features on the SPL design, safety analysis, and safety requirements. We applied DEPendable‐SPLE to a realistic case study from the aerospace domain to illustrate how to model and reuse safety properties. DEPendable‐SPLE reduced the effort of safety analysis for certifying system variants. André Luíz de Oliveira, Rosana T. V. Braga, Paulo César Masiero, David Parker 0002, Yiannis Papadopoulos, Ibrahim Habli, Tim Kelly |
J. Softw. Evol. Process. | 7 |
| 2018 | Control Diffusion of Information Collection for Situation Understanding Using Boosting MLNsabstractInformation fusion includes the integration of data for situational understanding. As a situation unfolds, maintaining awareness depends on diverse collections of data. In complex and dynamic scenarios, human operators face the difficult task of choosing which data to collect next. Hence, there is a need for multilayered fusion processes that exploit multiple models and levels of abstraction for understanding and sense-making Data collection has its roots in sensor management; however, there is an analogous need for data management - such as the incorporation of public domain data. Mature sensor management includes methods to utilize platform, sensor, and scene modeling so as to guide the user for future data collection. Additionally, these physics-based models could be a method to guide human-derived information models. Using the Data Fusion Information Group Model (DFIG), we develop an equivalent method for diffusion control. This paper focuses on recent techniques in statistical relational learning (SRL), Markov logic networks (MLN), and ontologies to support the control diffusion of data sensing to answer user queries. Erik Blasch, Robert Cruise, Sriraam Natarajan, Ali K. Raz, Tim Kelly |
FUSION | 5 |
| 2018 | ENTRUST: engineering trustworthy self-adaptive software with dynamic assurance casesabstractSoftware systems are increasingly expected to cope with variable workloads, component failures and other uncertainties through self-adaptation. As such, self-adaptive software has been the subject of intense research over the past decade [3, 4, 9, 10]. Radu Calinescu, Danny Weyns, Simos Gerasimou, M. Usman Iftikhar, Ibrahim Habli, Tim Kelly |
ICSE | 6 |
| 2018 | Variability Management in Safety-Critical Software Product Line Engineering
André Luíz de Oliveira, Rosana T. V. Braga, Paulo César Masiero, Yiannis Papadopoulos, Ibrahim Habli, Tim Kelly |
ICSR | 6 |
| 2018 | Engineering Trustworthy Self-Adaptive Software with Dynamic Assurance CasesabstractBuilding on concepts drawn from control theory, self-adaptive software handles environmental and internal uncertainties by dynamically adjusting its architecture and parameters in response to events such as workload changes and component failures. Self-adaptive software is increasingly expected to meet strict functional and non-functional requirements in applications from areas as diverse as manufacturing, healthcare and finance. To address this need, we introduce a methodology for the systematic ENgineering of TRUstworthy Self-adaptive sofTware (ENTRUST). ENTRUST uses a combination of (1) design-time and runtime modelling and verification, and (2) industry-adopted assurance processes to develop trustworthy self-adaptive software and assurance cases arguing the suitability of the software for its intended application. To evaluate the effectiveness of our methodology, we present a tool-supported instance of ENTRUST and its use to develop proof-of-concept self-adaptive software for embedded and service-based systems from the oceanic monitoring and e-finance domains, respectively. The experimental results show that ENTRUST can be used to engineer self-adaptive software systems in different application domains and to generate dynamic assurance cases for these systems. Radu Calinescu, Danny Weyns, Simos Gerasimou, M. Usman Iftikhar, Ibrahim Habli, Tim Kelly |
IEEE Trans. Software Eng. | 6 |
| 2017 | Integration of the 4+1 Software Safety Assurance Principles with Scrum
Osama Doss, Tim Kelly, Tor Stålhane, Børge Haugset, Mark Dixon |
EuroSPI | 2 |
| 2016 | Using Process Models in System Assurance
Richard Hawkins 0001, Thomas Richardson 0003, Tim Kelly |
SAFECOMP | 3 |
| 2016 | The 4+1 Principles of Software Safety Assurance and Their Implications for ScrumabstractAs part of our research concerning the integration of assurance case development with Scrum, we are planning to conduct semi-structured interviews with participants to gain feedback on a proposed approach. We will be interviewing individuals who have been involved with safety-critical systems development and Agile methods. Participants will be presented with an overview of the challenges associated with applying the 4+1 software safety assurance principles to Scrum. Initial recommendations concerning how the principles can be accommodated within a Scrum development will also be presented. Participants will be led through a series of questions to gain feedback on the feasibility of the approach, and for an assessment as to whether the 4+1 principles can be addressed without compromising agility. The motivation behind this research is to gain a deeper insight into the difficulties experienced when integrating assurance case in to Scrum process. Osama Doss, Tim Kelly |
XP | 2 |
| 2016 | Model-based specification of safety compliance needs for critical systems: A holistic generic metamodel
Jose Luis de la Vara, Alejandra Ruiz López, Katrina Attwood, Huáscar Espinoza, Rajwinder Kaur Panesar-Walawege, Ángel López, Idoya del Río, Tim Kelly |
Inf. Softw. Technol. | 8 |
| 2015 | Systematic application of ISO 26262 on a SEooC: Support by applying a systematic reuse approach
Alejandra Ruiz López, Alberto Melzi, Tim Kelly |
DATE | 3 |
| 2015 | An evidential reasoning approach for assessing confidence in safety evidenceabstractSafety cases present the arguments and evidence that can be used to justify the acceptable safety of a system. Many secondary factors such as the tools used, the techniques applied, and the experience of the people who created the evidence, can affect an assessor's confidence in the evidence cited by a safety case. One means of reasoning about this confidence and its inherent uncertainties is to present a `confidence argument' that explicitly justifies the provenance of the evidence used. In this paper, we propose a novel approach to automatically construct these confidence arguments by enabling assessors to provide individual judgements concerning the trustworthiness and the appropriateness of the evidence. The approach is based on Evidential Reasoning and enables the derivation of a quantified aggregate of the overall confidence. The proposed approach is supported by a prototype tool (EviCA) and has been evaluated using the Technology Acceptance Model. Sunil Nair, Neil Walkinshaw, Tim Kelly, Jose Luis de la Vara |
ISSRE | 3 |
| 2014 | Assurance Cases for Block-Configurable Software
Richard Hawkins 0001, Alvaro Miyazawa, Ana Cavalcanti 0001, Tim Kelly, John Rowlands |
SAFECOMP | 4 |
| 2014 | Evolving robust networks for systems-of-systems: is it viable for large networks?
Jonathan M. Aitken, Rob Alexander, Tim Kelly, Simon M. Poulding |
Empir. Softw. Eng. | 3 |
| 2013 | 1st international workshop on assurance cases for software-intensive systems (ASSURE 2013)abstractSoftware plays a key role in high-risk systems, i.e., safety and security-critical systems. Several certification standards and guidelines, e.g., in the defense, transportation (aviation, automotive, rail), and healthcare domains, now recommend and/or mandate the development of assurance cases for software-intensive systems. As such, there is a need to understand and evaluate (a) the application of assurance cases to software, and (b) the relationship between the development and assessment of assurance cases, and software engineering concepts, processes and techniques. The ICSE 2013 Workshop on Assurance Cases for Software-intensive Systems (ASSURE) aims to provide an international forum for high-quality contributions (research, practice, and position papers) on the application of assurance case principles and techniques for software assurance, and on the treatment of assurance cases as artifacts to which the full range of software engineering techniques can be applied. Ewen Denney, Ganesh J. Pai, Ibrahim Habli, Tim Kelly, John C. Knight |
ICSE | 4 |
| 2013 | Using argumentation to evaluate software assurance standards
Patrick J. Graydon, Tim Kelly |
Inf. Softw. Technol. | 2 |
| 2012 | Evolving Robust Networks for Systems-of-Systems
Jonathan M. Aitken, Rob Alexander, Tim Kelly, Simon M. Poulding |
SSBSE | 3 |
| 2011 | Using a Software Safety Argument Pattern Catalogue: Two Case Studies
Richard Hawkins 0001, Kester Clegg, Rob Alexander, Tim Kelly |
SAFECOMP | 4 |
| 2009 | Establishing a Framework for Dynamic Risk Management in 'Intelligent' Aero-Engine Control
Zeshan Kurd, Tim Kelly, John A. McDermid, Radu Calinescu, Marta Z. Kwiatkowska |
SAFECOMP | 2 |
| 2008 | A Model-Driven Approach to Assuring Process ReliabilityabstractThe process can fail to deliver its expected outputs and consequently contribute to the introduction of faults into the software system. The process may fail due to ambiguous and unsuitable notations, unreliable tool-support, flawed methods and techniques or incompetent personnel. However, not all process activities pose the same degree of risks and therefore require the same degree of rigour. In this paper, we define an extendable metamodel for describing lifecycle processes. The metamodel embodies attributes which facilitate the automated analysis of the process, revealing possible process failures and associated risks. The metamodel also provides the capability to automatically verify the compliance of the process with certification standards. The metamodel is evaluated against processes from the aerospace and automotive domains. Ibrahim Habli, Tim Kelly |
ISSRE | 2 |
| 2007 | Modeling and Learning Interaction-based Accidents for Safety-Critical Software SystemsabstractAnalyzing accidents is a vital exercise in the development of safety-critical software systems to prevent past accidents from reoccurring in the future. Current practices such as causal event analysis are insufficient in light of a growing trend of accidents involving complex interactions between components with and without the occurrence of failures. Furthermore, the reuse of accident knowledge in current practices relies heavily on human expert recall and interpretation. In this paper, we propose an ontological classification mechanism to acquire and reuse knowledge from past accidents that focuses on the interactions taking place in a system. A set of knowledge bases are constructed independently using a feature-based classification and a domain specific ontology to organize the term spaces of each feature. Similarity mechanisms are introduced to retrieve and integrate the acquired knowledge into the new system analyses. Our experiments show how our approach reuses accident knowledge to uncover potential safety concerns in future safety analysis that may otherwise have been incorrectly classified in traditional approaches. Edmund Kazmierczak, Tim Kelly, Dennis Plunkett |
APSEC | 3 |
| 2007 | Combining Bayesian Belief Networks and the Goal Structuring Notation to Support Architectural Reasoning About Safety
Weihang Wu, Tim Kelly |
SAFECOMP | 2 |
| 2007 | Challenges of Establishing a Software Product Line for an Aerospace Engine Monitoring SystemabstractThe introduction of a software product line may pose a great organizational challenge in the domain of highintegrity systems. Project and technical managers within an organization need to be assured that the reusable assets of a product line are reliable and trustworthy, particularly when project teams do not have full control over the development of these assets. In this paper we report on our experience with the establishment of a software product line for an aerospace Engine Monitoring Unit (EMU). Specifically, we report on challenges encountered with the configuration management and certification of EMU products derived from the product line. These two areas are still to be addressed adequately by the product line community as they are central for the management of product line assets across different projects within an organization. Ibrahim Habli, Tim Kelly |
SPLC | 2 |
| 2007 | Developing artificial neural networks for safety critical systems
Zeshan Kurd, Tim Kelly, Jim Austin |
Neural Comput. Appl. | 2 |
| 2006 | System of Systems Hazard Analysis Using Simulation and Machine Learning
Rob Alexander, Dimitar Kazakov, Tim Kelly |
SAFECOMP | 3 |
| 2006 | Using Agent-Based Modelling Approaches to Support the Development of Safety Policy for Systems of Systems
Martin Hall-May, Tim Kelly |
SAFECOMP | 2 |
| 2005 | Establishing a Standard Business Process Execution Architecture for Integrating Web ServicesabstractWith the realisation of the potential benefits of business process automation, many standards, best practices and technologies have evolved to model and execute business processes. The emerging Web services technology provides great flexibility for the development of cross platform, service oriented applications. This paper addresses the utilisation of the Web services technology for business process enactment and discusses a standardised architecture for Web service based business process execution. As a key objective it highlights the need for standardisation in Web service based business processes execution. In elaborating on the above need, this paper defines the development of a standard architecture to address key concerns such as service invocation, integration, transaction management, security and resource management in using the Web services technology for business process execution. Thilina Gunasinghe, Tim Kelly |
ICWS | 2 |
| 2005 | Defining and Decomposing Safety Policy for Systems of Systems
Martin Hall-May, Tim Kelly |
SAFECOMP | 2 |
| 2005 | Using Safety Critical Artificial Neural Networks in Gas Turbine Aero-Engine Control
Zeshan Kurd, Tim Kelly |
SAFECOMP | 2 |
| 2004 | Safety Tactics for Software Architecture DesignabstractThe influence of architecture in assurance of system safety is being increasingly recognised in mission-critical software applications. Nevertheless, most architectural strategies have not been developed to the extent necessary to ensure safety of these systems. Moreover, many software safety standards fail to discuss the rationale behind the adoption of alternative architectural mechanisms. Safety has not been explicitly considered by existing software architecture design methodologies. As a result, there is little practical guidance on how to address safety concerns in 'shaping' a 'safe' software architecture. This work presents a method for software architecture design within the context of safety. This method is centred upon extending the existing notion of architectural tactics to include safety as a consideration. The approach extends existing software architecture design methodologies and demonstrates the true value of deployment of specific protection mechanisms. The feasibility of this method is demonstrated by an example. Weihang Wu, Tim Kelly |
COMPSAC | 2 |
| 2004 | Component Failure Mitigation According to Failure TypeabstractOff-The-Shelf (OTS) software components are being used within complex safety-critical applications. However, to use these untrustworthy components with confidence, it is necessary to ensure that potential failures of the components cannot contribute to system level hazards. This requires the system level effects of component failures to be understood and mitigated using suitable fault tolerance techniques. However, the black-box nature of an OTS component implies the visibility and modifiability of the component is very limited. This restricts the choice of available fault tolerance techniques in mitigating failures of an OTS component. This work presents a systematic approach to facilitate the selection of appropriate mitigation strategies according to a classification of failure types of an untrustworthy component. This approach enables an untrustworthy component to be used in a safety-critical context with increased confidence. Fan Ye 0005, Tim Kelly |
COMPSAC | 2 |
| 2004 | Exploiting Safety Constraints in Fuzzy Self-organising Maps for Safety Critical Applications
Zeshan Kurd, Tim Kelly, Jim Austin |
IDEAL | 2 |
| 2004 | Using Fuzzy Self-Organising Maps for Safety Critical Systems
Zeshan Kurd, Tim Kelly |
SAFECOMP | 2 |
| 2003 | Establishing Safety Criteria for Artificial Neural Networks
Zeshan Kurd, Tim Kelly |
KES | 2 |
| 2003 | Safety Lifecycle for Developing Safety Critical Artificial Neural Networks
Zeshan Kurd, Tim Kelly |
SAFECOMP | 2 |
| 2002 | Architectural Considerations in the Certification of Modular Systems
Iain Bate, Tim Kelly |
SAFECOMP | 2 |
| 2001 | Deriving Safety Requirements Using ScenariosabstractElicitation of requirements for safety critical aero-engine control systems is dependent on the capture of core design intent and the systematic derivation of requirements addressing hazardous deviations from that intent. Derivation of these requirements is inextricably linked to the safety assessment process. Conventional civil aerospace practice (as advocated by guidelines such as ARP4754 and ARP4671) promotes the application of Functional Hazard Assessment (FHA) to sets of statements of functional intent. Systematic hazard analysis of scenario-based requirements representations is less well understood. This paper discusses the principles and problems of hazard analysis and proposes an approach to conducting hazard analysis on use case requirements representations. Using the approach, it is possible to justifiably derive hazard-mitigation use cases as first class requirements from systematic hazard analysis of core design intent scenarios. An industrial example is used to illustrate the technique. Karen Allenby, Tim Kelly |
RE | 2 |
| 2001 | Use of Modern Processors in Safety-Critical ApplicationsabstractThis paper investigates the implications of using modern superscalar processors in the safety-critical domain. Firstly, a description of current certification practice and devices is given as background. This is followed by an exposition of the certification argument for a processor when used in a safety-critical application. Throughout the presentation of the argument two types of modern processor are considered, commercial off-the-shelf (COTS) processors and purpose-designed bespoke devices. This allows the elaboration of positive and negative features of processors that can be used as part of the selection (for COTS) or design (for bespoke) process. Iain Bate, Philippa Conmy, Tim Kelly, John A. McDermid |
Comput. J. | 3 |
| 1999 | A Systematic Approach to Safety Case Maintenance
Tim Kelly, John A. McDermid |
SAFECOMP | 1 |
| 1997 | Safety Case Construction and Reuse Using Patterns
Tim Kelly, John A. McDermid |
SAFECOMP | 1 |
| 1995 | Safety Cases for Software Application Reuse
Peter Fenelon, Tim Kelly, John A. McDermid |
SAFECOMP | 2 |