Safety assurance of a complex system cannot be completely ensured at design/development time since most uncertainties and unknowns are revealed when the system is deployed in a real environment. Safety assurance at runtime can be addressed by using models formalizing those safety assertions the system has to guarantee during operation, and specifying enforcement strategies aimed at preserving or eventually restoring safety. This paper presents an approach to runtime safety enforcement of software systems based on the MAPE-K control loop architecture for system monitoring and control, and on the State Machine as runtime model to specify safety assertions and enforcement strategies for steering the correct system behavior. The enforcer software is designed to act as a proxy system which wraps around the software system to realize safety enforcement, both as black-box enforcement on unsafe I/O events and as gray-box enforcement on unsafe internal system changes. The proposed approach is supported by a component framework called RSE (Runtime Safety Enforcement) that is here illustrated by means of two real case studies in the health-care domain.

(2023). A component framework for the runtime enforcement of safety properties [journal article - articolo]. In THE JOURNAL OF SYSTEMS AND SOFTWARE. Retrieved from https://hdl.handle.net/10446/235472

A component framework for the runtime enforcement of safety properties

Bonfanti, Silvia;Scandurra, Patrizia
2023-01-07

Abstract

Safety assurance of a complex system cannot be completely ensured at design/development time since most uncertainties and unknowns are revealed when the system is deployed in a real environment. Safety assurance at runtime can be addressed by using models formalizing those safety assertions the system has to guarantee during operation, and specifying enforcement strategies aimed at preserving or eventually restoring safety. This paper presents an approach to runtime safety enforcement of software systems based on the MAPE-K control loop architecture for system monitoring and control, and on the State Machine as runtime model to specify safety assertions and enforcement strategies for steering the correct system behavior. The enforcer software is designed to act as a proxy system which wraps around the software system to realize safety enforcement, both as black-box enforcement on unsafe I/O events and as gray-box enforcement on unsafe internal system changes. The proposed approach is supported by a component framework called RSE (Runtime Safety Enforcement) that is here illustrated by means of two real case studies in the health-care domain.
articolo
7-gen-2023
Bonfanti, Silvia; Riccobene, Elvinia; Scandurra, Patrizia
(2023). A component framework for the runtime enforcement of safety properties [journal article - articolo]. In THE JOURNAL OF SYSTEMS AND SOFTWARE. Retrieved from https://hdl.handle.net/10446/235472
File allegato/i alla scheda:
File Dimensione del file Formato  
A component framework for the runtime enforcement of safety properties.pdf

embargo fino al 31/01/2025

Descrizione: This in an Accepted Manuscript of an article published by Elsevier in Journal of Systems and Software, doi https://doi.org/10.1016/j.jss.2022.111605
Versione: postprint - versione referata/accettata senza referaggio
Licenza: Creative commons
Dimensione del file 1.27 MB
Formato Adobe PDF
1.27 MB Adobe PDF   Visualizza/Apri
Pubblicazioni consigliate

Aisberg ©2008 Servizi bibliotecari, Università degli studi di Bergamo | Terms of use/Condizioni di utilizzo

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/10446/235472
Citazioni
  • Scopus 2
  • ???jsp.display-item.citation.isi??? 2
social impact