Abstract
Model checking is a proven, effective method for verifying instrumentation and control system application logics. If a model of the system being verified does not satisfy a specification, the failure scenario is presented to the user as a counterexample trace. Analysis of the counterexample can be time-consuming if the trace is long, the model is large, or the specification is complex. Spurious counterexamples ('false negatives') often exacerbate the problem. In this paper, we present a method that assists in identifying the root of the failure in both the model and the specification, by animating the model of the function block diagram as well as the LTL property. We also introduce a practical tool for visualizing LTL properties by animation and highlighting of important values based on causality. Using 43 actual design issues identified in practical nuclear industry projects, we then evaluate usefulness of the property visualization and explanation features.
Original language | English |
---|---|
Title of host publication | Proceedings of 16th International Conference on Industrial Informatics |
Subtitle of host publication | INDIN 2018 |
Publisher | IEEE Institute of Electrical and Electronic Engineers |
Pages | 747-753 |
Number of pages | 7 |
ISBN (Electronic) | 978-1-5386-4829-2, 978-1-5386-4828-5 |
DOIs | |
Publication status | Published - 27 Sept 2018 |
MoE publication type | Not Eligible |
Event | 16th IEEE International Conference on Industrial Informatics, INDIN 2018 - Porto, Portugal Duration: 18 Jul 2018 → 20 Jul 2018 Conference number: 16 |
Conference
Conference | 16th IEEE International Conference on Industrial Informatics, INDIN 2018 |
---|---|
Abbreviated title | INDIN 2018 |
Country/Territory | Portugal |
City | Porto |
Period | 18/07/18 → 20/07/18 |
Keywords
- Explanation of counterexamples
- Formal verification
- Model checking
- Visualization of counterexamples