• No se han encontrado resultados

Cálculo de pérdidas en el sistema

2.11. Parámetros en el diseño de conductos

2.11.7. Cálculo de pérdidas en el sistema

General guidance properties focus on the investigation of two particular features of the ambient systems’ functioning, the advices that can be provided by the system throughout its operation and the possibility of returning to a previous state of the system. The first property examines whether the system can provide the user with all the possible advices at some point. In other words, it checks the redundancy of the system’s advices. On the other hand, the second property examines whether the user can revisit a state of the system.

These properties apply mostly to the verification of the Ambient Guidance Systems, as their functioning depends both on the advices given to the users with respect to their actions and on the users’ ability to redo some actions during the operation of these systems. For example, if at least one of the possible advices of the ambient garage cannot be given to the user, then this could misdirect him resulting in the non completion of his goal. Furthermore, the ability of redoing actions is of high importance for the functioning of the ambient garage as the user should be able to go back to a previously visited place of the garage when the system redirects him after a wrong action. On the other hand, these properties are not so important for the Ambient Information Systems and especially for the ambient conference room, since the users always follow the procedure and the system always provides the proper advices to them. Furthermore, the users of the system are not allowed to redo actions. The ambient conference room permits the return to a previous state, only when an unauthorised user (intruder) enters and then leaves the room representing in that way

7.1 Model Checking

that the system can go back to a ‘normal’ condition where the conference process can be continued in order to conclude to a final decision about the reviewed papers.

Although, it is known from the modelling of the ambient conference room that it always provides the users with the correct advices and that the user cannot redo certain actions, the general guidance properties can be used to confirm that indeed the system can potentially give all the possible advices to the user and that an unauthorised user eventually leaves the room and the process continues from the point that was ‘paused’. 7.1.2.1.1 Examining Redundancy of Advices

This property checks if there exists any advice in the set of all possible advices of the system that is never provided to the user. To examine the redundancy of the system’s advices, the property is expressed as follows:

“None of the advices from the set of possible advices is redundant.”

The CTL proposition of the above property is presented for both T-APN nets in Figure 7.21.

(a) CTL proposition of advices redundancy property for ambient garage

(b) CTL proposition of advices redundancy property for ambient conference room

Figure 7.21: CTL propositions of redundancy of advices property for both T-APN nets.

To check this property, the above CTL propositions are used as input to Charlie model checker. The results for both T-APN models are presented in Figure 7.22.

(a) Redundancy of advices property result for ambient garage

(b) Redundancy of advices property result for ambient conference room

7.1 Model Checking

The property being true for the ambient garage, means that each of the advices might be the right advice for some user at some point of the execution. For example, during the operation of the ambient garage, the advice go left or right might be the proper one for a user with respect to his current position.

On the other hand, the property being true for the ambient conference room con- firms that at some point of the system’s execution all the tasks or phases of the confer- ence are completed or about to be completed. The completion of the tasks or phases is confirmed by providing the right advices to the users. For example, there exists a state where an advice is given to the user notifying him about a conflict with a paper or another state where an advice is given to notify the user about the papers that have not been reviewed.

Hence, the results of this property show that none of the advices used for the operation of each of the two systems is redundant.

7.1.2.1.2 Returning to Previous States

This property checks whether a state that has already been visited once by a user during the operation of an ambient system, can be revisited at some point in the future. For the examination of the user’s return to previous states, the property is expressed as follows:

‘The user can return to one of the previously visited states.”

The CTL proposition of the above property for the examined T-APN nets is pre- sented in Figure 7.23.

(a) CTL proposition of returning to previous states property for ambient garage

(b) CTL proposition of returning to previous states property for ambient conference room

Figure 7.23: CTL propositions of returning to previous states property for both T-APN nets.

To check this property, the above CTL propositions are examined by Charlie model checker. The results of the property for both T-APN nets are shown in Figure 7.24.

The property being true for the ambient garage means that the users can redo some of their actions throughout the operation of the system. For example, a user can go from place p1 to the parking bay A1 and go back to p1 either because he parked his car to A1 and now he wants to leave the garage or because he went to the wrong parking bay (A1) and now he wants to correct his mistake by moving back to p1 in order to head towards the correct parking bay (A2).

7.1 Model Checking

(a) Returning to previous states property result for ambient garage

(b) Returning to previous states property result for ambient conference room

Figure 7.24: Results of returning to previous states property for both T-APN nets.

On the other hand, the property being true for the ambient conference room implies that the system can return to the state where it was before an unauthorised user enters to a restricted area. For instance, an unauthorised user (intruder) enters the restricted are of the personal display of a reviewer while he is at the home page forcing the system to switch off that display and stop the reviewing process. Then, after the intruder has left the restricted area or the room, the display returns to its previous state, which is the home page allowing the reviewer to continue the process.

The results of this property indicate that some states of the systems can be ‘re- visited’ during the operation of the ambient garage and the ambient conference room respectively.

Documento similar