Banach, Richard, Jeske, Czeslaw, Poppleton, Michael and Stepney, Susan
Retrenching the Purse: Finite Exception Logs, and Validating the Small.
In, IEEE SEW-30: 30th Annual Software Engineering Workshop, Columbia, MD, USA,
25 - 27 Apr 2006.
IEEE Computer Society Press.
The Mondex Electronic Purse is an outstanding example of industrial scale formal refinement, and was the first verification to achieve ITSEC level E6 certification. A formal abstract model and a formal concrete model were developed, and a formal refinement was hand-proved between them. Nevertheless, certain requirements issues were set beyond the scope of the formal development, or handled in an unnatural manner. The retrenchment Tower Pattern is used to address one such issue in detail: the finiteness of the purse log (which records unsuccessful transactions). A retrenchment is constructed from the lowest level model of the purse system to a model in which logs are finite, and is then lifted to create two refinement developments of the purse, working at different levels of detail, and connected via retrenchments, forming the tower. The tower development is appropriately validated, vindicating the design used.
Conference or Workshop Item
|| R. Banach. Maximally abstract retrenchments. In Proc. IEEE ICFEM2000, pages 133–142, York, August 2000. IEEE Computer Society Press.  R. Banach, C. Jeske, and M. Poppleton. Composition mechanisms for retrenchment. 2004. submitted, http://www.cs.man.ac.uk/˜banach/some.pubs/ Retrench. Composition.pdf.  R. Banach and M. Poppleton. Retrenchment: An engineering variation on refinement. In D. Bert, editor, 2nd International B Conference, volume 1393 of LNCS, pages 129–147, Montpellier, France, April 1998. Springer. Event Dates: 25-27 April 2006
||retrenchment, refinement, mondex, pattern
||Faculty of Physical Sciences and Engineering > Electronics and Computer Science
|Accepted Date and Publication Date:
||06 Jul 2006
||27 Mar 2014 20:06
|Further Information:||Google Scholar|
Actions (login required)