CTL update of Kripke models through protections

We present a nondeterministic, recursive algorithm for updating a Kripke model so as to satisfy a given formula of computation-tree logic (CTL). Recursive algorithms for model update face two dual difficulties: (1) Removing transitions from a Kripke model to satisfy a universal subformula may dissat...

ver descrição completa

Detalhes bibliográficos
Autores: Carrillo, Miguel, Rosenblueth Laguette, David Arturo
Tipo de documento: artigo
Estado:Versão publicada
Data de publicação:2014
País:México
Recursos:Universidad Nacional Autónoma de México
Repositório:Repositorio Institucional del Instituto de Investigaciones en Matemáticas Aplicadas y en Sistemas, UNAM
Idioma:inglês
OAI Identifier:oai:www.ru.iimas.unam.mx:IIMAS_UNAM/ART25
Acesso em linha:http://www.ru.iimas.unam.mx/handle/IIMAS_UNAM/ART25
http://dx.doi.org/10.1016/j.artint.2014.02.005
Access Level:Acceso aberto
Palavra-chave:CTL model update
Model checking
Automatic synthesis
Ciencias Físico Matemáticas y Ciencias de la Tierra
Descrição
Resumo:We present a nondeterministic, recursive algorithm for updating a Kripke model so as to satisfy a given formula of computation-tree logic (CTL). Recursive algorithms for model update face two dual difficulties: (1) Removing transitions from a Kripke model to satisfy a universal subformula may dissatisfy some existential subformulas. Conversely, (2) adding transitions to satisfy an existential subformula may dissatisfy some universal subformulas. To overcome these difficulties, we employ protections of the form (E, A, L), recording information about the satisfaction of subformulas previously treated by the algorithm. Intuitively, (1) E is the set of transitions that we cannot remove without compromising the satisfaction of previously treated subformulas. Conversely, (2) A is the set of transitions that we can add. Hence, update proceeds without diminishing E and without augmenting A. Finally, (3) L is a set of literals protecting the model labels. We illustrate our algorithm through several examples: Emerson and Clarke's mutual-exclusion problem, Clarke et. al.'s microwave-oven example, synchronous counters, and randomly generated models and formulas. In addition, we compare our method with other update approaches for either CTL or fragments of CTL. Lastly, we provide proofs of soundness and completeness and a complexity analysis. (C) 2014 Elsevier B.V. All rights reserved.