Since it was established in 1979, SAFECOMP has contributed to the progress of the state-of-the-art in dependable applications of computer systems. SAFECOMP is an annual event covering the stateof-the-art, experience and new trends in the areas of computer safety, reliability and security regarding dependable applications of computer systems. SAFECOMP provides ample opportunity to exchange insights and experience on emerging methods and practical applications across the borders of different disciplines. SCOPE OF THE CONFERENCE SAFECOMP focuses on safety-critical computer applications and is a platform for knowledge and technology transfer between academia, industry and research institutions. Programme The 22nd International Conference Computer Safety, Reliability and Security 23-26 September 2003 Edinburgh, Scotland, United Kingdom The cross-fertilization between different scientific communities and industry supports the achievement of long-term results contributing to the integration of multidisciplinary experiences in order to improve the design and deployment of dependable computer-based systems. Over the years the industry participation in SAFECOMP has grown steadily. This emphasizes the importance of technology transfer between academia and industry. SAFECOMP 2003 further sustains the healthy interchange of research results and practical experiences. The SAFECOMP 2003 programme consists of 30 papers selected from 96 submissions from all over the world. SAFECOMP 2003 acknowledges the invited Keynote Talks enhancing the technical and scientific merit of the conference. We would like to thank the International Programme Committee, the External Reviewers, the Keynote Speakers and the Authors for their work in support of SAFECOMP 2003. We would also like to thank the Conference Staff at the National e-Science Centre for their valuable collaboration in organizing and hosting SAFECOMP 2003. We really enjoyed the entire work and we hope you appreciate the care that we have put in order to deliver an enjoyable and fruitful event. Finally, we would like to invitate you to attend SAFECOMP 2003. www.safecomp.org -1- PROGRAMME AT A GLANCE Tuesday 23 September 08:30 09:00 09:30 10:00 10:30 11:00 11:30 12:00 12:30 13:00 13:30 14:00 14:30 15:00 15:30 16:00 16:30 17:00 17:30 18:00 18:30 19:00 19:30... Tutorial1 Tutorial 2 Coffee Break Tutorial 1 Tutorial 2 Wednesday Thursday Friday 24 September 25 September 26 September Registration SAFECOMP Opening Keynote Talk Keynote Talk Keynote Talk Session 4 Session 8 Coffee Break Coffee Break Session 1 Session 5 WEDNESDAY, 24 SEPTEMBER 09:00-09:30 SAFECOMP 2003 Welcome & Opening Bev Littlewood (City University, GB) EWICS TC7 Welcome Udo Voges (Forschungszentrum Karlsruhe, DE) Session 9 Lunch SAFECOMP 2003 Presentation of the Technical Programme Stuart Anderson, Massimo Felici (University of Edinburgh, GB) Session 10 Tutorial 1 Tutorial 3 Session 2 Session 6 SAFECOMP Closing Coffee Break Coffee Break Tutorial 1 Tutorial 3 Session 3 09:30-10:30 KEYNOTE TALK Issues in Safety Assurance Martyn Thomas (University of Oxford, GB) 10:30-11:00 COFFEE BREAK 11:00-13:00 SESSION 1: FORMAL METHODS Chair: Maritta Heisel (University of Magdeburg, DE) Session 7 Panel SAFECOMP 2003 Welcome Reception SAFECOMP 2003 Social Dinner Elicitation and Validation of Graphical Dependability Models David Wright (City University, GB) TUESDAY, 23 SEPTEMBER 09:00-18:00 Visual Modeling and Verification of Distributed Reactive Systems A. Iqbal, A. K. Bhattacharjee, S. D. Dhodapkar (Bhabha Atomic Research Centre, IN), and S. Ramesh (Indian Institute of Technology, IN) SAFECOMP 2003 TUTORIALS TUTORIAL 1 Critical Systems Development with UML and Model-based Testing Jan Jürjens (Munich University of Technology, DE) Automatic Timeliness Verification of a Public Mobile Network Ester Ciancamerla, Michele Minichino (ENEA CR Casaccia, IT), Stefano Serro (TECSIT Telecontrollo e Sistemi, IT), and Enrico Tronci (Università di Roma “La Sapienza”, IT) TUTORIAL 2 The CORAS Methodology for Model-based Risk Assessment Bjørn Axel Gran (Institutt for energiteknikk, OECD Halden Reactor Project, NO) TUTORIAL 3 Self-Stabilization - Fault Tolerance in Distributed Systems Pradip K. Srimani (Clemson University, South Carolina, US) You will find further information about the tutorials in the SAFECOMP 2003 website. 18:30... SAFECOMP 2003 OPENING SAFECOMP 2003 WELCOME RECEPTION AT THE NATIONAL E-SCIENCE CENTRE -2- Improving System Reliability via Model Checking: the FSAP/NuSMV-SA Safety Analysis Platform Marco Bozzano and Adolfo Vollafiorita (ITC-IRST, IT) 13:00-14:00 LUNCH 14:00-16:00 SESSION 2: DESIGN FOR DEPENDABILITY Chair: Udo Voges (Forschungszentrum Karlsruhe, DE) Integrity Static Analysis of COTS/SOUP Peter Bishop, Robin Bloomfield (City University and Adelard, GB), Tim Clement, Sofia Guerra, and Claire Jones (Adelard, GB) -3- Safety Lifecycle for Developing Safety Critical Artificial Networks Zeshan Kurd and Tim Kelly (University of York, GB) 10:00-11:00 SESSION 4: DEPENDABILITY AND PERFORMANCE ANALYSIS Chair: Erwin Schoitsch (ARC Seibersdorf research, AT) Web Service Availability - Impact of Error Recovery Magnos Martinello, Mohamed Kaâniche, and Karama Kanoun (LAAS, FR) Quantitative Reliability Estimation of a Computer-based Motor Protection Relay Using Bayesian Networks Atte Helminen and Urho Pulkkinen (VTT Industrial System, FI) A Unified Tool for Performance Modelling and Prediction Stephen Gilmore and Leïla Kloul (University of Edinburgh, GB) A Dependability Model for Domestic Systems Guy Dewsbury, Ian Sommerville, Karen Clarke, and Mark Rouncefield (Lancaster University, GB) 11:00-11:30 COFFEE BREAK 16:00-16:30 COFFEE BREAK 11:30-13:00 SESSION 5: DEPENDABILITY OF MEDICAL SYSTEMS Chair:Floor Koorneef (Technische Universiteit Delft, NL) 16:30-18:00 SESSION 3: SECURITY AND FORMAL METHODS Chair: Stefan Wittmann (BSI, DE) An Approach to Trust Case Development J. Górski (Technical University of Gdañsk, PL), A. Jarzêbowicz, R. Leszczyna, J. Miler, and M. Olszewski (Project IST-DRIVE) Modelling and Verification of Layered Security Protocols: A Bank Application Johannes Grünbauer (Munich University of Technology, DE), Helia Hollmann (Secaron AG, DE), Jan Jürjens, and Guido Wimmel (Munich University of Technology, DE) Reliable Data Replication in a Wireless Medical Emergency Network Joe Gorman, Ståle Walderhaug, and Håvard Kvålen (SINTEF Telecom and Informatic, NO) Critical Feature Analysis of a Radiotherapy Machine Andrew Rae (University of Queensland, AU), Daniel Jackson, Prasad Ramanan (Massachusetts Institute of Technology, US), Jay Flanz (Massachusetts General Hospital,US), and Didier Leyman (Ion Beam Applications, BE) A Constraint Framework for the Qualitative Analysis of Dependability Goals: Integrity Stefano Bistarelli (Università “G. D'Annunzio" di Chieti-Pescara and CNR, IT) and Simon N. Foley (University College, IR) Software Tamper Resistance Using Program Certificates Hongxia Jin (IBM Almaden Research Center, US), Gregory F. Sullivan, and Gerald M. Masson (Johns Hopkins University, US) 18:00-19:00 PANEL: DEPENDABLE EMBEDDED SYSTEMS Chair: Erwin Schoitsch (ARC Seibersdorf research, AT) Dependable Embedded Systems: Roadmap and Challenges From Requirements to Maintenance THURSDAY, 25 SEPTEMBER 09:00-10:00 KEYNOTE TALK Developing High Assurance Systems: On the Role of Software Tools Constance Heitmeyer (Naval Research Laboratory, US) -4- 13:00-14:00 LUNCH 14:00-16:00 SESSION 6: FAULT TOLERANCE Chair: Robin Bloomfield (City University and Adelard, GB) Byzantine Fault Tolerance, from Theory to Reality Kevin Driscoll, Brendan Hall (Honeywell International, US), Håkan Sivencrona (Chalmers University of Technology, SE), and Phil Zumsteg (Honeywell International, US) Redundancy Management for Drive-by-Wire Computer Systems Oliver Rooks (University of Karlsruhe, DE), Michael Armbruster (University of Stuttgart, DE), Serge Büchli, Armin Sulzmann, Gernot Spiegelberg (DaimlerChrysler AG, DE), and Uwe Kiencke (University of Karlsruhe, DE) Fault-tolerant Communication System to Improve Safety in Railway Environments César Mataix, Pedro Martín, Francisco Javier Rodríguez, -5- María José Manzano, and Javier Pozo (Universidad de Alcalá, ES) 10:00-11:00 Dependable Communication Synthesis for Distributed Embedded Systems Nagarajan Kandasamy (Vanderbilt University, US), John P. Hayes (University of Michigan, US), and Brian T. Murray (The Delphi Corporation, US) 16:00-16:30 16:30-18:00 Security Policy Configuration Issues in Grid Computing Environments George Angelis, Stefanos Gritzalis, and Costas Lambrinoudakis (University of the Aegean, GR) COFFEE BREAK SESSION 7: TOOLS FOR DEPENDABLE DESIGN Chair: Michael Harrison (University of York, GB) Enhancing Software Safety by Fault Trees: Experiences from an Application to Flight Critical SW Wolfgang Weber, Heidemarie Tondok (EADS Military Aircraft, DE), and Michael Bachmayer (Bachmayer GmbH, DE) Dependability and Survivability of Large Complex Critical Infrastructures Sandro Bologna, Claudio Balducelli, Giovanni Dipoppa, and Giordano Vicoli (ENEA C.R.Casaccia, IT) 11:00-11:30 COFFEE BREAK 11:30:13:00 SESSION 9: HAZARD AND SAFETY ANALYSIS Chair: Felix Redmill (University of Newcastle upon Tyne, GB) On the Role of Traceability for Standards Compliance: Tracking Requirements to Code P. A. J. Mason (University of Newcastle upon Tyne, GB), A. Saeed (Advantage Business Group, GB), and S. Riddle (University of Newcastle upon Tyne, GB) Safety Assessment of Experimental Air Traffic Management Procedures Alberto Pasquini and Simone Pozzi (Deep Blue s.r.l., IT) The Application of Causal Analysis Techniques for Computer-related Mishaps Chris Johnson (University of Glasgow, GB) Tools Supporting the Communication of Critical Domain Knowledge in High-consequence Systems Development Kimberly S.Wasson, John C. Knight, Elisabeth A. Strunk, and Sean R.Travis (University of Virginia, US) 19:30... SESSION 8: DEPENDABILITY OF CRITICAL INFRASTRUCTURES Chair: Chris Johnson (University of Glasgow, GB) Reuse in Hazard Analysis: Identification and Support Shamus P. Smith and Michael D. Harrison (University of York, GB) SAFECOMP 2003 SOCIAL DINNER AT OUR DYNAMIC EARTH 13:00-14:00 LUNCH 14:00-15:00 SESSION 10: DESIGN FOR DEPENDABILITY Chair: Janusz Górski (Technical University of Gdañsk, PL) The Characteristics of Data in Data-intensive Safety-related Systems Neil Storey (University of Warwick, GB) and Alastair Faulkner (CSE International Ltd., GB) Using IEC 61508 to Guide the Investigation of Computer-related Incidents and Accidents Chris Johnson (University of Glasgow, GB) Our Dynamic Earth, Holyrood Road, Edinburgh EH8 8AS FRIDAY, 26 SEPTEMBER 09:00-10:00 KEYNOTE TALK TBA Ross Anderson (Computer Laboratory, University of Cambridge, GB) -6- 15:00-15:30 SAFECOMP 2003 CLOSING 15:30-16:00 COFFEE BREAK -7- REGISTRATION Co-located and Coordinated Event EWICS TC7 EUROPEAN WORKSHOP ON INDUSTRIAL COMPUTER SYSTEMS RELIABILITY, SAFETY AND SECURITY 23 SEPTEMBER 2003 EDINBURGH, SCOTLAND, UK The mission of EWICS is: "To promote the economical and efficient realisation of programmable industrial systems through education, information exchange, and the elaboration of standards and guidelines" EWICS is active in the field of Programmable Electronic Systems reliability, safety and security. It has members from most European countries, covering various fields of interests and affiliations, as well as from the USA. To achieve the above goals we - assess the state of the art in methods and tools for critical software development and maintenance in industrial environments - develop standards and guidelines for the development and assessment of safe and secure systems - disseminate information and knowledge in this field - exchange technical knowledge between members Please register on the SAFECOMP 2003 web site. Notice that you may also request (by the online registration form) an Accommodation. The Conference Staff at the National e-Science Centre (NeSC) will book an accommodation according to your requirements (i.e., arrival and departure dates, type of accommodation, and accommodation budget). Once the Conference Staff booked an accommodation, you will then need to arrange for the accommodation payment directly with the hotel. All the hotels have been selected by the NeSc and they are conveniently located nearby the NeSC and the Edinburgh City Centre. The following table shows the different Registration Rates - Conference Fees in British Pounds £. Registration Type Speaker (2) EWICS Member Non-member Student (3) Exhibitor (includes 1 delegate registration) Tutorial 1 (4) Tutorial 2 (4) Tutorial 3 (4) Companion Dinner Ticket Early (by 31 August) 250 (by 7 July2) 250 300 170 400 150 150 150 30 Late / On site(1) (After 31 August) 350 300 350 200 450 150 150 150 30 http://www.ewics.org/ 1. Due to limited space we cannot guarantee to accept on site registrations. You are strongly advised to register in advance. 2. The Speaker early registration is conditional for the publication of the accepted paper in the proceedings. 3. A proof of student status must be attached. 4. Tutorial registrations include: access to the specific tutorial; a copy of the tutorial notes/slides; lunch and coffee breaks. or contact the EWICS TC7 Chair: EXHIBITION AND TOOL FAIR To receive further infomation about the EWICS TC7 meetings please visit the EWICS TC7 web site A dedicated space will be organised for Exhibition and Tool Fair. Organisations requiring to show their own stands and products should register as Exhibitor according to the instructions provided in the conference web site. Udo Voges Forschungszentrum Karlsruhe Institut für Angewandte Informatik Postfach 3640, 76021 Karlsruhe, Germany SPONSORS PROGRAMME To become a sponsor of SAFECOMP 2003, please refer to the information about the Sponsors Programme in the conference web site. E-mail: voges@iai.fzk.de CONFERENCE VENUE National e-Science Centre e-Science Institute 15 South College Street Edinburgh EH8 9AA United Kingdom -8- -9- Scientific Sponsor THE HOST CITY IFAC - International Federation of Automatic Control IFIP - WG10.4 on Dependable Computing and Fault Tolerance IFIP - WG13.5 on Human Error, Safety and System Development ISA-EUNET OCG - Austrian Computer Society in collaboration with the Scientific Co-sponsors AICA - Working Group on Dependability in Computer Systems SCSC - Safety-Critical Systems Club SRMC - Software Reliability & Metrics Club SAFECOMP 2003 Organization BCS - British Computer Society DIRC - Interdisciplinary Research Collaboration in Dependability of Computer-Based Systems EACE - European Association of Cognitive Ergonomics One of the greenest and most beautiful cities in Europe, Edinburgh annually attracts over 2 million visitors, not just for its architecture, but as a city rich in social, cultural, learning and sporting facilities. Each year it hosts internationally-renowned events such as the Edinburgh International Arts, Fringe, Film, TV and Science festivals. Yet it is more than just a tourist attraction. Edinburgh is a thriving commercial and financial centre, the site of the new Scottish Parliament and a gateway to the coastline, hills and open country of the Scottish Highlands. Edinburgh is a beautiful, dynamic, prosperous European city that benefits from a unique architectural heritage and a magnificent natural setting. Edinburgh is also home to a thriving software industry supporting the major financial institutions in the city and creating new products. Over the past years Edinburgh has seen a huge increase in start-ups in the software sector. Close to Edinburgh, the Silicon Glen houses major microelectronics, communications and software design companies. Scottish Enterprise, the development agency for Scotland, places a strong emphasis on developing industries providing key infrastructure for the knowledge economy. This is based on the firm foundation of a strong supply of appropriately-qualified graduates from the ten universities in central Scotland. FURTHER INFORMATION AND ENQUIRIES www.safecomp.org info@safecomp.org - 10 - SAFECOMP 2003 has also currently received Sponsorship from: ENCRESS - European Network of Clubs for Reliability and Safety of Software GI - Gesellschaft für Informatik IEE www.wileyeurope.com General Chair Bev Littlewood, GB Program Co-chairs Stuart Anderson, GB Massimo Felici, GB www.elsevier.com EWICS Chair Udo Voges, DE Organizing Committee Stuart Anderson, GB Massimo Felici, GB International Programme Committee S. Anderson, GB A. Bertolino, IT H. Bezecny, DE R. Bloomfield, GB S. Bologna, IT A. Bondavalli, IT H. Breitwieser, DE M. Colnaric, SI P. Daniel, GB B. de Mol, NL H. R. Fankhauser, SE M. Felici, GB R. Garnier, FR R. Genser, AT C. Goring ,GB J. Gorski, PL E. Großpietsch, DE W. Halang, DE M. Harrison, GB M. Heisel, DE E. Hollnagel, SE C. Johnson, GB M. Kaâniche, FR K. Kanoun, FR F. Koornneef, NL J. Li, US V. Maggioli, US P. Marti, IT O. Nordland, NO A. Pasquini, IT G. Rabe, DE F. Redmill, GB A. Rizzo, IT H. Roth, DE F. Saglietti, DE A.E.K. Sahraoui, FR R. Sanz, ES E. Schoitsch, AT J. Trienekens, NL M. van der Meulen, NL U. Voges, DE M. Wilikens, IT R. Winther, NO S. Wittmann, DE E. Wong ,US J. Zalewski, US Z. Zurakowski, PL