Copyright c○2011-2012

نویسنده

  • Sanjit Arunkumar Seshia
چکیده

ion and Refinement This chapter focuses on relationships between models known as abstraction and refinement. These terms are symmetric in that the statement “model A is an abstraction of model B” means the same thing as “model B is a refinement of model A.” As a general rule, the refinement model B has more detail than the abstraction A, and the abstraction is simpler, smaller, or easier to understand. An abstraction is sound (with respect to some formal system of properties) if properties that are true of the abstraction are also true of the refinement. The formal system of properties could be, for example, a type system, linear temporal logic, or the languages of state machines. If the formal system is LTL, then if every LTL formula that holds for A also holds for B, then A is a sound abstraction of B. This is useful when it is easier to prove that a formula holds for A than to prove that it holds for B, for example because the state space of B may be much larger than the state space of A. An abstraction is complete (with respect to some formal system of properties) if properties that are true of the refinement are also true of the abstraction. For example, if the formal system of properties is LTL, then A is a complete abstraction of B if every LTL formula that holds for B also holds for A. Useful abstractions are usually sound but not complete, because it is hard to make a complete abstraction that is significantly simpler or smaller. Consider for example a program B in an imperative language such as C that has multiple threads. We might construct an abstraction A that ignores the values of variables and replaces all branches and control structures with nondeterministic choices. The abstraction clearly has less information than the program, but it may be sufficient for proving some properties about the program, for example a mutual exclusion property. Lee & Seshia, Introduction to Embedded Systems 349 13.2. TYPE EQUIVALENCE AND REFINEMENT a complete implementation. It also tells when it is safe to change an implementation, replacing it with another that might, for example, reduce the implementation cost. 13.2 Type Equivalence and Refinement We begin with a simple relationship between two models that compares only the data types of their communication with their environment. Specifically, the goal is to ensure that a model B can be used in any environment where a model A can be used without causing any conflicts about data types. We will require that B can accept any inputs that A can accept from the environment, and that any environment that can accept any output A can produce can also accept any output that B can produce. To make the problem concrete, assume an actor model for A and B, as shown in Figure 13.1. In that figure, A has three ports, two of which are input ports represented by the set PA = {x,w}, and one of which is an output port represented by the set QA = {y}. These ports represent communication between A and its environment. The inputs have type Vx and Vw, which means that at a reaction of the actor, the values of the inputs will be members of the sets Vx or Vw. If we want to replace A by B in some environment, the ports and their types impose four constraints: 1. The first constraint is that B does not require some input signal that the environment does not provide. If the input ports of B are given by the set PB, then this is guaranteed by PB ⊆ PA. (13.1) The ports of B are a subset of the ports of A. It is harmless for A to have more input ports than B, because if B replaces A in some environment, it can simply ignore any input signals that it does not need. 2. The second constraint is that B produces all the output signals that the environment may require. This is ensured by the constraint

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

بررسی پیامدهای الحاق ایران به نظام بین‌المللی حق مؤلف از دیدگاه ناشران شهر تهران

Purpose:  The present study aims to study Tehran city publishers' views about the consequences of Iran’s joining the international copyright treaty. Method: An analytical survey method was used as the research method. For the data collection, a researcher-made questionnaire was used. The statistical population of this research was Tehran city active publishers. The selected sample was 113 publ...

متن کامل

Linguistic Issues in Language Technology LiLT

This paper presents an ongoing project whose goal is to create a freely available dependency treebank for Persian. The data is taken from the Bijankhan corpus, which is already annotated for parts of speech, and a syntactic dependency annotation based on the Stanford Typed Dependencies is added through a bootstrapping procedure involving the opensource dependency parser MaltParser. We report pr...

متن کامل

Experimental Studies on Confinement Effect of Steel Hoops in Concrete Columns

ACI Structural Journal, V. 109, No. 1, January-February 2012. MS No. S-2008-321.R2 received November 23, 2010, and reviewed under Institute publication policies. Copyright © 2012, American Concrete Institute. All rights reserved, including the making of copies unless permission is obtained from the copyright proprietors. Pertinent discussion including author’s closure, if any, will be published...

متن کامل

Measurements of Top Quark Properties at the LHC

A summary on the most recent results of the ATLAS and CMS Collaborations on the top quark porperties is presented. The measurements used data from the 2010 and 2011 LHC run, using integrated luminosities ranging from 35 pb −1 to 5.0 f b −1 , the latter corresponding to the full 2011 data sample. c Copyright owned by the author(s) under the terms of the Creative Commons Attribution-NonCommercial...

متن کامل

Nurse:patient ratios influence the achievement of oxygen saturation targets in premature infants.

Copyright & reuse City University London has developed City Research Online so that its users may access the research outputs of City University London's staff. Copyright © and Moral Rights for this paper are retained by the individual author(s) and/ or other copyright holders. All material in City Research Online is checked for eligibility for copyright before being made available in the live ...

متن کامل

The Nature of Strategic Instability

Fall/Winter 2011 • volume xviii, issue 1 Copyright © 2011 by the Brown Journal of World Affairs Martin Libicki is a senior management scientist at the RAND Corporation, where he focuses on the impact of information technology on security. Prior to joining RAND in 1998, he worked at the National Defense University. He also teaches at Georgetown University and the U.S. Naval Academy. The Nature o...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2012