<?xml version="1.0" encoding="utf-8"?>
<raweb xmlns:xlink="http://www.w3.org/1999/xlink" xml:lang="en" year="2018">
  <identification id="spades" isproject="true">
    <shortname>SPADES</shortname>
    <projectName>Sound Programming of Adaptive Dependable Embedded Systems</projectName>
    <theme-de-recherche>Embedded and Real-time Systems</theme-de-recherche>
    <domaine-de-recherche>Algorithmics, Programming, Software and Architecture</domaine-de-recherche>
    <urlTeam>http://team.inria.fr/spades</urlTeam>
    <structure_exterieure type="Labs">
      <libelle>Laboratoire d'Informatique de Grenoble (LIG)</libelle>
    </structure_exterieure>
    <structure_exterieure type="Organism">
      <libelle>Institut polytechnique de Grenoble</libelle>
    </structure_exterieure>
    <header_dates_team>Creation of the Team: 2013 January 01, updated into Project-Team: 2015 July 01</header_dates_team>
    <LeTypeProjet>Project-Team</LeTypeProjet>
    <keywordsSdN>
      <term>A1.1.1. - Multicore, Manycore</term>
      <term>A1.1.9. - Fault tolerant systems</term>
      <term>A1.3. - Distributed Systems</term>
      <term>A2.1.1. - Semantics of programming languages</term>
      <term>A2.1.6. - Concurrent programming</term>
      <term>A2.1.9. - Synchronous languages</term>
      <term>A2.3. - Embedded and cyber-physical systems</term>
      <term>A2.3.1. - Embedded systems</term>
      <term>A2.3.2. - Cyber-physical systems</term>
      <term>A2.3.3. - Real-time systems</term>
      <term>A2.4.1. - Analysis</term>
      <term>A2.4.3. - Proofs</term>
      <term>A2.5.2. - Component-based Design</term>
      <term>A7.3. - Calculability and computability</term>
    </keywordsSdN>
    <keywordsSecteurs>
      <term>B5.2.1. - Road vehicles</term>
      <term>B6.3.3. - Network Management</term>
      <term>B6.4. - Internet of things</term>
      <term>B6.6. - Embedded systems</term>
    </keywordsSecteurs>
    <UR name="Grenoble"/>
  </identification>
  <team id="uid1">
    <person key="spades-2018-idp144608">
      <firstname>Gregor</firstname>
      <lastname>Goessler</lastname>
      <categoryPro>Chercheur</categoryPro>
      <research-centre>Grenoble</research-centre>
      <moreinfo>Team leader, Inria, Researcher</moreinfo>
      <hdr>oui</hdr>
    </person>
    <person key="spades-2018-idp147520">
      <firstname>Pascal</firstname>
      <lastname>Fradet</lastname>
      <categoryPro>Chercheur</categoryPro>
      <research-centre>Grenoble</research-centre>
      <moreinfo>Inria, Researcher</moreinfo>
      <hdr>oui</hdr>
    </person>
    <person key="spades-2018-idp150368">
      <firstname>Alain</firstname>
      <lastname>Girault</lastname>
      <categoryPro>Chercheur</categoryPro>
      <research-centre>Grenoble</research-centre>
      <moreinfo>Inria, Senior Researcher</moreinfo>
      <hdr>oui</hdr>
    </person>
    <person key="spades-2018-idp153232">
      <firstname>Sophie</firstname>
      <lastname>Quinton</lastname>
      <categoryPro>Chercheur</categoryPro>
      <research-centre>Grenoble</research-centre>
      <moreinfo>Inria, Researcher</moreinfo>
    </person>
    <person key="spades-2018-idp155696">
      <firstname>Jean-Bernard</firstname>
      <lastname>Stefani</lastname>
      <categoryPro>Chercheur</categoryPro>
      <research-centre>Grenoble</research-centre>
      <moreinfo>Inria, Senior Researcher</moreinfo>
    </person>
    <person key="spades-2018-idp158176">
      <firstname>Xavier</firstname>
      <lastname>Nicollin</lastname>
      <categoryPro>Enseignant</categoryPro>
      <research-centre>Grenoble</research-centre>
      <moreinfo>Institut polytechnique de Grenoble, Associate Professor</moreinfo>
    </person>
    <person key="spades-2018-idp160672">
      <firstname>Jia Jie</firstname>
      <lastname>Wang</lastname>
      <categoryPro>PostDoc</categoryPro>
      <research-centre>Grenoble</research-centre>
      <moreinfo>Inria, from May 2018</moreinfo>
    </person>
    <person key="spades-2018-idp163136">
      <firstname>Nicolas</firstname>
      <lastname>Hili</lastname>
      <categoryPro>PostDoc</categoryPro>
      <research-centre>Grenoble</research-centre>
      <moreinfo>IRT Saint-Exupery</moreinfo>
    </person>
    <person key="spades-2018-idp165600">
      <firstname>Xiaojie</firstname>
      <lastname>Guo</lastname>
      <categoryPro>PhD</categoryPro>
      <research-centre>Grenoble</research-centre>
      <moreinfo>Univ. Grenoble Alpes</moreinfo>
    </person>
    <person key="spades-2018-idp168048">
      <firstname>Maxime</firstname>
      <lastname>Lesourd</lastname>
      <categoryPro>PhD</categoryPro>
      <research-centre>Grenoble</research-centre>
      <moreinfo>Univ. Grenoble Alpes</moreinfo>
    </person>
    <person key="polaris-2018-idp188912">
      <firstname>Stephan</firstname>
      <lastname>Plassart</lastname>
      <categoryPro>PhD</categoryPro>
      <research-centre>Grenoble</research-centre>
      <moreinfo>Univ. Grenoble Alpes</moreinfo>
    </person>
    <person key="spades-2018-idp172912">
      <firstname>Christophe</firstname>
      <lastname>Prévot</lastname>
      <categoryPro>PhD</categoryPro>
      <research-centre>Grenoble</research-centre>
      <moreinfo>Thales until Oct 2018, Inria from Nov 2018</moreinfo>
    </person>
    <person key="spades-2018-idp175376">
      <firstname>Arash</firstname>
      <lastname>Shafiei</lastname>
      <categoryPro>PhD</categoryPro>
      <research-centre>Grenoble</research-centre>
      <moreinfo>Orange Labs</moreinfo>
    </person>
    <person key="spades-2018-idp177808">
      <firstname>Martin</firstname>
      <lastname>Vassor</lastname>
      <categoryPro>PhD</categoryPro>
      <research-centre>Grenoble</research-centre>
      <moreinfo>Inria</moreinfo>
    </person>
    <person key="spades-2018-idp180240">
      <firstname>Souha</firstname>
      <lastname>Ben Rayana</lastname>
      <categoryPro>Technique</categoryPro>
      <research-centre>Grenoble</research-centre>
      <moreinfo>Inria, from May 2018</moreinfo>
    </person>
    <person key="spades-2018-idp182704">
      <firstname>Louise</firstname>
      <lastname>Penz</lastname>
      <categoryPro>Stagiaire</categoryPro>
      <research-centre>Grenoble</research-centre>
      <moreinfo>Univ. Grenoble Alpes, from Jun 2018 to Jul 2018</moreinfo>
    </person>
    <person key="tyrex-2018-idp198624">
      <firstname>Helen</firstname>
      <lastname>Pouchot-Rouge-Blanc</lastname>
      <categoryPro>Assistant</categoryPro>
      <research-centre>Grenoble</research-centre>
      <moreinfo>Inria</moreinfo>
    </person>
    <person key="spades-2018-idp187664">
      <firstname>Ismail</firstname>
      <lastname>Assayad</lastname>
      <categoryPro>Visiteur</categoryPro>
      <research-centre>Grenoble</research-centre>
      <moreinfo>Univ. Hassan II, Casablanca, Sep 2018</moreinfo>
    </person>
  </team>
  <presentation id="uid2">
    <bodyTitle>Overall Objectives</bodyTitle>
    <subsection id="uid3" level="1">
      <bodyTitle>Overall Objectives</bodyTitle>
      <p>The <span class="smallcap" align="left">Spades</span> project-team aims at contributing to meet the challenge of
designing and programming dependable embedded systems in an
increasingly distributed and dynamic context. Specifically, by
exploiting formal methods and techniques, <span class="smallcap" align="left">Spades</span> aims to answer three
key questions:</p>
      <orderedlist>
        <li id="uid4">
          <p noindent="true">How to program open networked embedded systems as dynamic
adaptive modular structures?</p>
        </li>
        <li id="uid5">
          <p noindent="true">How to program reactive systems with real-time and resource
constraints on multicore architectures?</p>
        </li>
        <li id="uid6">
          <p noindent="true">How to program reliable, fault-tolerant embedded systems with
different levels of criticality?</p>
        </li>
      </orderedlist>
      <p>These questions above are not new, but answering them in the context
of modern embedded systems, which are increasingly distributed, open
and dynamic in nature  <ref xlink:href="#spades-2018-bid0" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>, makes them more
pressing and more difficult to address: the targeted system properties
– dynamic modularity, time-predictability, energy efficiency, and
fault-tolerance – are largely antagonistic (<i>e.g.</i>, having a highly
dynamic software structure is at variance with ensuring that resource
and behavioral constraints are met). Tackling these questions
together is crucial to address this antagonism, and constitutes a key
point of the <span class="smallcap" align="left">Spades</span> research program.</p>
      <p>A few remarks are in order:</p>
      <simplelist>
        <li id="uid7">
          <p noindent="true">We consider these questions to be central in the construction of
future embedded systems, dealing as they are with, roughly, software
architecture and the provision of real-time and fault-tolerance
guarantees. Building a safety-critical embedded system cannot avoid
dealing with these three concerns.</p>
        </li>
        <li id="uid8">
          <p noindent="true">The three questions above are highly connected. For instance,
composability along time, resource consumption and reliability
dimensions are key to the success of a component-based approach to
embedded systems construction.</p>
        </li>
        <li id="uid9">
          <p noindent="true">For us, “Programming” means any constructive process to build
a running system. It can encompass traditional programming as well
as high-level design or “model-based engineering” activities,
provided that the latter are supported by effective compiling tools
to produce a running system.</p>
        </li>
        <li id="uid10">
          <p noindent="true">We aim to provide semantically sound programming tools for
embedded systems. This translates into an emphasis on formal
methods and tools for the development of provably dependable
systems.</p>
        </li>
      </simplelist>
    </subsection>
  </presentation>
  <fondements id="uid11">
    <bodyTitle>Research Program</bodyTitle>
    <subsection id="uid12" level="1">
      <bodyTitle>Introduction</bodyTitle>
      <p>The SPADES research program is organized around three main themes,
<i>Design and Programming Models</i>, <i>Certified real-time
programming</i>, and <i>Fault management and causal analysis</i>, that
seek to answer the three key questions identified in
Section <ref xlink:href="#uid3" location="intern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>. We plan to do so by developing and/or
building on programming languages and techniques based on formal
methods and formal semantics (hence the use of <i>“sound
programming”</i> in the project-team title). In particular, we seek to
support design where correctness is obtained by construction, relying
on proven tools and verified constructs, with programming languages
and programming abstractions designed with verification in mind.</p>
    </subsection>
    <subsection id="uid13" level="1">
      <bodyTitle>Design and Programming Models</bodyTitle>
      <p>Work on this theme aims to develop models , languages and tools to support
a “correct-by-construction” approach to the development of embedded systems.</p>
      <p>On the programming side, we focus on the definition of domain specific
programming models and languages supporting static analyses
for the computation of precise resource bounds for program executions.
We propose dataflow models supporting dynamicity while enjoying effective analyses. In particular, we study parametric extensions where
properties such as liveness and boundedness remain statically analyzable.</p>
      <p>On the design side, we focus on the definition of component-based models
for software architectures combining distribution, dynamicity, real-time and fault-tolerant
aspects.
Component-based construction has long been advocated as a key approach
to the “correct-by-construction” design of complex embedded
systems  <ref xlink:href="#spades-2018-bid1" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>. Witness component-based toolsets such
as <span class="smallcap" align="left">Ptolemy</span>   <ref xlink:href="#spades-2018-bid2" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>, BIP  <ref xlink:href="#spades-2018-bid3" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>, or
the modular architecture frameworks used, for instance, in the
automotive industry (AUTOSAR)  <ref xlink:href="#spades-2018-bid4" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>. For building large,
complex systems, a key feature of component-based construction is the
ability to associate with components a set of <i>contracts</i>, which
can be understood as rich behavioral types that can be composed and
verified to guarantee a component assemblage will meet desired
properties.</p>
      <p>Formal models for component-based design are an active area of
research. However, we are
still missing a comprehensive formal model and its associated
behavioral theory able to deal <i>at the same time</i> with different
forms of composition, dynamic component structures, and quantitative
constraints (such as timing, fault-tolerance, or energy consumption).</p>
      <p>We plan to develop our component theory by progressing on two fronts:
a semantical framework and domain-specific programming models.
The work on the semantical framework should, in the longer term,
provide abstract mathematical models for the more operational and
linguistic analysis afforded by component calculi. Our work on
component theory will find its application in the development of a
<span class="smallcap" align="left">Coq</span>-based toolchain for the certified design and construction of
dependable embedded systems, which constitutes our first main
objective for this axis.</p>
    </subsection>
    <subsection id="uid14" level="1">
      <bodyTitle>Certified Real-Time Programming</bodyTitle>
      <p>Programming real-time systems (<i>i.e.</i>, systems whose correct behavior
depends on meeting timing constraints) requires appropriate languages
(as exemplified by the family of synchronous
languages  <ref xlink:href="#spades-2018-bid5" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>), but also the support of
efficient scheduling policies, execution time and schedulability
analyses to guarantee real-time constraints (<i>e.g.</i>, deadlines) while
making the most effective use of available (processing, memory, or
networking) resources. Schedulability analysis involves analyzing the
worst-case behavior of real-time tasks under a given scheduling
algorithm and is crucial to guarantee that time constraints are met in
any possible execution of the system. Reactive programming and
real-time scheduling and schedulability for multiprocessor systems are
old subjects, but they are nowhere as mature as their uniprocessor
counterparts, and still feature a number of open research
questions  <ref xlink:href="#spades-2018-bid6" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>, <ref xlink:href="#spades-2018-bid7" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>, in particular in
relation with mixed criticality systems. The main goal in this theme
is to address several of these open questions.</p>
      <p>We intend to focus on two issues: multicriteria scheduling on
multiprocessors, and schedulability analysis for real-time
multiprocessor systems. Beyond real-time aspects, multiprocessor
environments, and multicore ones in particular, are subject to several
constraints <i>in conjunction</i>, typically involving real-time,
reliability and energy-efficiency constraints, making the scheduling
problem more complex for both the offline and the online
cases. Schedulability analysis for multiprocessor systems, in
particular for systems with mixed criticality tasks, is still very
much an open research area.</p>
      <p>Distributed reactive programming is rightly singled out as a major
open issue in the recent, but heavily biased (it essentially ignores
recent research in synchronous and dataflow programming), survey by
Bainomugisha et al.  <ref xlink:href="#spades-2018-bid6" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>. For our part, we
intend to focus on devising synchronous programming languages for
distributed systems and precision-timed architectures.</p>
    </subsection>
    <subsection id="uid15" level="1">
      <bodyTitle>Fault Management and Causal Analysis</bodyTitle>
      <p>Managing faults is a clear and present necessity in networked
embedded systems. At the hardware level, modern multicore
architectures are manufactured using inherently unreliable
technologies  <ref xlink:href="#spades-2018-bid8" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>, <ref xlink:href="#spades-2018-bid9" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>. The evolution
of embedded systems towards increasingly distributed architectures
highlighted in the introductory section means that dealing with
partial failures, as in Web-based distributed systems, becomes an
important issue.</p>
      <p>In this axis we intend to address the question of <i>how to cope
with faults and failures in embedded systems?</i>. We will tackle this
question by exploiting reversible programming models and by developing
techniques for fault ascription and explanation in component-based
systems.</p>
      <p>A common theme in this axis is the use and exploitation of causality
information. Causality, <i>i.e.</i>, the logical dependence of an effect on a
cause, has long been studied in disciplines such as
philosophy  <ref xlink:href="#spades-2018-bid10" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>, natural sciences,
law  <ref xlink:href="#spades-2018-bid11" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>, and statistics  <ref xlink:href="#spades-2018-bid12" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>, but it
has only recently emerged as an important focus of research in
computer science. The analysis of logical causality has applications
in many areas of computer science. For instance, tracking and
analyzing logical causality between events in the execution of a
concurrent system is required to ensure
reversibility  <ref xlink:href="#spades-2018-bid13" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>, to allow the diagnosis of faults
in a complex concurrent system  <ref xlink:href="#spades-2018-bid14" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>, or to enforce
accountability  <ref xlink:href="#spades-2018-bid15" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>, that is, designing systems in
such a way that it can be determined without ambiguity whether a
required safety or security property has been violated, and why. More
generally, the goal of fault-tolerance can be understood as being to
prevent certain causal chains from occurring by designing systems such
that each causal chain either has its premises outside of the fault
model (<i>e.g.</i>, by introducing redundancy  <ref xlink:href="#spades-2018-bid16" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>), or is
broken (<i>e.g.</i>, by limiting fault propagation  <ref xlink:href="#spades-2018-bid17" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>).</p>
    </subsection>
  </fondements>
  <domaine id="uid16">
    <bodyTitle>Application Domains</bodyTitle>
    <subsection id="uid17" level="1">
      <bodyTitle>Industrial Applications</bodyTitle>
      <p>Our applications are in the embedded system area, typically:
transportation, energy production, robotics, telecommunications,
the Internet of things (IoT),
systems on chip (SoC). In some areas, safety is critical, and
motivates the investment in formal methods and techniques for design.
But even in less critical contexts, like telecommunications and
multimedia, these techniques can be beneficial in improving the
efficiency and the quality of designs, as well as the cost of the
programming and the validation processes.</p>
      <p>Industrial acceptance of formal techniques, as well as their
deployment, goes necessarily through their usability by specialists of
the application domain, rather than of the formal techniques
themselves. Hence, we are looking to propose domain-specific (but
generic) realistic models, validated through experience (<i>e.g.</i>, control
tasks systems), based on formal techniques with a high degree of
automation (<i>e.g.</i>, synchronous models), and tailored for concrete
functionalities (<i>e.g.</i>, code generation).</p>
    </subsection>
    <subsection id="uid18" level="1">
      <bodyTitle>Industrial Design Tools</bodyTitle>
      <p>The commercially available design tools (such as <span class="smallcap" align="left">UML</span> with real-time
extensions, <span class="smallcap" align="left">Matlab</span>/ <span class="smallcap" align="left">Simulink</span>/
d<span class="smallcap" align="left">Space</span> <footnote id="uid19" id-text="1"><ref xlink:href="http://www.dspaceinc.com" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://<allowbreak/>www.<allowbreak/>dspaceinc.<allowbreak/>com</ref></footnote>) and execution
platforms (OS such as <span class="smallcap" align="left">VxWorks</span>, QNX, real-time versions of
<span class="smallcap" align="left">Linux</span> ...) start now to provide, besides their core functionalities,
design or verification methods. Some of them, founded on models of
reactive systems, come close to tools with a formal basis, such as for
example <span class="smallcap" align="left">StateMate</span> by i<span class="smallcap" align="left">Logix</span>.</p>
      <p>Regarding the synchronous approach, commercial tools are available:
<span class="smallcap" align="left">Scade</span> <footnote id="uid20" id-text="2"><ref xlink:href="http://www.esterel-technologies.com" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://<allowbreak/>www.<allowbreak/>esterel-technologies.<allowbreak/>com</ref></footnote> (based on
<span class="smallcap" align="left">Lustre</span>), <span class="smallcap" align="left">ControlBuild</span> and <span class="smallcap" align="left">RT-Builder</span> (based on
<span class="smallcap" align="left">Signal</span>) from <span class="smallcap" align="left">Geensys</span> <footnote id="uid21" id-text="3"><ref xlink:href="http://www.geensoft.com" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://<allowbreak/>www.<allowbreak/>geensoft.<allowbreak/>com</ref></footnote> (part
of <span class="smallcap" align="left">Dassault</span> <span class="smallcap" align="left">Systemes</span>), specialized environments like <span class="smallcap" align="left">CellControl</span> for
industrial automatism (by the Inria spin-off <span class="smallcap" align="left">Athys</span>– now part of
<span class="smallcap" align="left">Dassault</span> <span class="smallcap" align="left">Systemes</span>). One can observe that behind the variety of actors, there
is a real consistency of the synchronous technology, which makes sure
that the results of our work related to the synchronous approach are
not restricted to some language due to compatibility issues.</p>
    </subsection>
    <subsection id="uid22" level="1">
      <bodyTitle>Current Industrial Cooperations</bodyTitle>
      <p>Regarding applications and case studies with industrial end-users of
our techniques, we cooperate with Thales on schedulability analysis
for evolving or underspecified real-time embedded systems, with Orange
Labs on software architecture for cloud services and with Daimler on
reduction of nondeterminism and analysis of deadline miss models for
the design of automotive systems.</p>
    </subsection>
  </domaine>
  <logiciels id="uid23">
    <bodyTitle>New Software and Platforms</bodyTitle>
    <subsection id="uid24" level="1">
      <bodyTitle>pyCPA_TWCA</bodyTitle>
      <p>
        <i>Analysis tool for weakly-hard real-time systems</i>
      </p>
      <p noindent="true"><span class="smallcap" align="left">Keywords:</span> Real time - Scheduling analyses</p>
      <p noindent="true"><span class="smallcap" align="left">Functional Description:</span> pyCPA_TWCA is a pyCPA plugin for Typical Worst-Case Analysis. pyCPA is an open-source Python implementation of Compositional Performance Analysis developed at TU Braunschweig, which allows in particular response-time analysis. pyCPA_TWCA is an extension of that tool that is co-developed by Sophie Quinton and Zain Hammadeh at TU Braunschweig. It allows in particular the computation of weakly-hard guarantees for real-time tasks, i.e. number of deadline misses out of a sequence of executions. So far, pyCPA_TWCA is restricted to uniprocessor systems of independent tasks. pyCPA_TWCA can handle the following scheduling policies: Fixed Priority Preemptive, Fixed Priority Non-Preemptive, Weighted Round-Robin, Earliest Deadline First.</p>
      <simplelist>
        <li id="uid25">
          <p noindent="true">Contact: Sophie Quinton</p>
        </li>
      </simplelist>
    </subsection>
    <subsection id="uid26" level="1">
      <bodyTitle>CertiCAN</bodyTitle>
      <p>
        <i>Certifier of CAN bus analysis results</i>
      </p>
      <p noindent="true"><span class="smallcap" align="left">Keywords:</span> Certification - CAN bus - Real time - Static analysis</p>
      <p noindent="true"><span class="smallcap" align="left">Functional Description:</span> CertiCAN is a tool, produced using the Coq proof assistant, allowing the formal certification of the correctness of CAN bus analysis results. Result certification is a process that is light-weight and flexible compared to tool certification, which makes it a practical choice for industrial purposes. The analysis underlying CertiCAN, which is based on a combined use of two well-known CAN analysis techniques, is computationally efficient. Experiments demonstrate that CertiCAN is able to certify the results of RTaW-Pegase, an industrial CAN analysis tool, even for large systems. Furthermore, CertiCAN can certify the results of any other RTA tool for the same analysis and system model (periodic tasks with offsets in transactions).</p>
      <simplelist>
        <li id="uid27">
          <p noindent="true">Contact: Xiaojie Guo</p>
        </li>
      </simplelist>
    </subsection>
  </logiciels>
  <resultats id="uid28">
    <bodyTitle>New Results</bodyTitle>
    <subsection id="uid29" level="1">
      <bodyTitle>Design and Programming Models</bodyTitle>
      <participants>
        <person key="spades-2018-idp147520">
          <firstname>Pascal</firstname>
          <lastname>Fradet</lastname>
        </person>
        <person key="spades-2018-idp150368">
          <firstname>Alain</firstname>
          <lastname>Girault</lastname>
        </person>
        <person key="spades-2018-idp144608">
          <firstname>Gregor</firstname>
          <lastname>Goessler</lastname>
        </person>
        <person key="spades-2018-idp158176">
          <firstname>Xavier</firstname>
          <lastname>Nicollin</lastname>
        </person>
        <person key="spades-2018-idp172912">
          <firstname>Christophe</firstname>
          <lastname>Prévot</lastname>
        </person>
        <person key="spades-2018-idp153232">
          <firstname>Sophie</firstname>
          <lastname>Quinton</lastname>
        </person>
        <person key="spades-2018-idp175376">
          <firstname>Arash</firstname>
          <lastname>Shafiei</lastname>
        </person>
        <person key="spades-2018-idp155696">
          <firstname>Jean-Bernard</firstname>
          <lastname>Stefani</lastname>
        </person>
        <person key="spades-2018-idp177808">
          <firstname>Martin</firstname>
          <lastname>Vassor</lastname>
        </person>
        <person key="spades-2018-idp180240">
          <firstname>Souha</firstname>
          <lastname>Ben Rayana</lastname>
        </person>
      </participants>
      <subsection id="uid30" level="2">
        <bodyTitle>A multiview contract theory for cyber-physical system design and verification</bodyTitle>
        <p>The design and verification of critical cyber-physical systems is
based on a number of models (and corresponding analysis techniques and
tools) representing different viewpoints such as function, timing,
security and many more. Overall correctness is guaranteed by mostly
informal, and therefore basic, arguments about the relationship
between these viewpoint-specific models. More precisely, the
assumptions that a viewpoint-specific analysis makes on the other
viewpoints remain mostly implicit, and whenever explicit they are
handled mostly manually. In <ref xlink:href="#spades-2018-bid18" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>, we argue that
the current design process over-constrains the set of possible system
designs and that there is a need for methods and tools to formally
relate viewpoint-specific models and corresponding analysis results.
We believe that a more flexible contract-based approach could lead to
easier integration, to relaxed assumptions, and consequently to more
cost efficient systems while preserving the current modelling approach
and its tools.</p>
        <p>The framework we have in mind would provide viewpoint specific
contract patterns guaranteeing inter-viewpoint consistency in a
flexible manner. At this point, most of the work remains to be
done. On the application side, we need a more complete picture of
existing inter-viewpoint models. We also need the theory required for
the correctness proofs, but it should be based on the needs on the
application side.</p>
      </subsection>
      <subsection id="uid31" level="2">
        <bodyTitle>End-to-end worst-case latencies of task chains for flexibility analysis</bodyTitle>
        <p>In collaboration with Thales, we address the issue of change during
design and after deployment in safety-critical embedded system
applications. More precisely, we focus on timing aspects with the
objective to anticipate, at design time, future software evolutions
and identify potential schedulability bottlenecks. The work presented
in this section is the PhD topic of Christophe Prévot, in the context of a
collaboration with Thales TRT, and our algorithms are being
implemented in the Thales tool chain, in order to be used in industry.</p>
        <p>This year, we have completed our work on the analysis of end-to-end
worst-case latencies of task chains <ref xlink:href="#spades-2018-bid19" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/> that
was needed to extend our approach for quantifying the flexibility,
with respect to timing, of real-time systems made of chains of
tasks. In a nutshell, flexibility is the property of a given system to
accommodate changes in the future, for instance the modification of
some of the parameters of the system, or the addition of a new task in
the case of a real-time system.</p>
        <p>One major issue that hinders the use of performance analysis in
industrial design processes is the pessimism inherent to any analysis
technique that applies to realistic system models (<i>e.g.</i>, , systems with
task chains). Indeed, such analyses may conservatively declare
unschedulable systems that will in fact never miss any deadlines. The
two main avenues for improving this are (i) computing tighter upper
bounds on the worst-case latencies, and (ii) measuring the pessimism,
which requires to compute also guaranteed lower bounds. A lower bound
is guaranteed by providing an actual system execution exhibiting a
behavior as close to the worst case as possible. As a first step, we
focus in <ref xlink:href="#spades-2018-bid19" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/> on uniprocessor systems executing
a set of sporadic or periodic hard real-time task chains. Each task
has its own priority, and the chains are scheduled according to the
fixed-priority preemptive scheduling policy. Computing the worst-case
end-to-end latency of each chain is complex because of the intricate
relationship between the task priorities. Compared to state of the art
analyses, we propose here tighter upper bounds, as well as lower
bounds on these worst-case latencies. Our experiments show the
relevance of lower bounds on the worst-case behavior for the
industrial design of real-time embedded systems.</p>
        <p>Based on our end-to-end latency analysis for task chains, we have also
proposed an extension of the concept of slack to task chains and shown
how it can be used to perform flexibility analysis and sensitivity
analysis. This solution is particularly relevant for industry as it
provides means by which the system designer can anticipate the impact
on timing of software evolutions, at design time as well as after
deployment.</p>
      </subsection>
      <subsection id="uid32" level="2">
        <bodyTitle>Location graphs</bodyTitle>
        <p>We have introduced
the location graph model <ref xlink:href="#spades-2018-bid20" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/> as an expressive framework
for the definition of component-based models able to deal with
dynamic software configurations with sharing and encapsulation constraints.
We have completed a first study of the location graph behavioral theory
(under submission), initiated its formalization in Coq, and an implementation
of the location framework with an emphasis of the expression of different
isolation and encapsulation constraints.</p>
        <p>We are now studying conservative extensions to the location graph framework to
support the compositional design of heterogeneous hybrid dynamical systems
and their attendant notions of approximate
simulations <ref xlink:href="#spades-2018-bid21" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>.</p>
        <p>In collaboration with the Spirals team at Inria Lille – Nord Europe, we have applied
the location framework for the definition of a pivot model for
the description of software configurations in a cloud computing environment.
We have shown how to interpret in our pivot model several configuration management models and languages
including TOSCA, OCCI, Docker Compose, Aeolus, OpenStack HOT.</p>
      </subsection>
      <subsection id="uid33" level="2">
        <bodyTitle>Dynamicity in dataflow models</bodyTitle>
        <p>Recent dataflow programming environments support applications whose
behavior is characterized by dynamic variations in resource
requirements. The high expressive power of the underlying models (<i>e.g.</i>, Kahn Process Networks or the CAL actor language) makes it challenging
to ensure predictable behavior. In particular, checking
<i>liveness</i> (<i>i.e.</i>, no part of the system will deadlock) and
<i>boundedness</i> (<i>i.e.</i>, the system can be executed in finite memory)
is known to be hard or even undecidable for such models. This
situation is troublesome for the design of high-quality embedded
systems. In the past few years, we have proposed several parametric
dataflow models of computation (MoCs)  <ref xlink:href="#spades-2018-bid22" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>, <ref xlink:href="#spades-2018-bid23" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>, we have
written a survey providing a comprehensive description of the existing
parametric dataflow MoCs  <ref xlink:href="#spades-2018-bid24" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>, and we have studied
<i>symbolic</i> analyses of dataflow graphs  <ref xlink:href="#spades-2018-bid25" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>. More
recently, we have proposed an original method to deal with lossy
communication channels in dataflow graphs  <ref xlink:href="#spades-2018-bid26" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>.</p>
        <p>We are now studying models allowing dynamic reconfigurations of the
<i>topology</i> of the dataflow graphs. In particular, many modern
streaming applications have a strong need for reconfigurability, for
instance to accommodate changes in the input data, the control
objectives, or the environment.</p>
        <p>We have proposed a new MoC called Reconfigurable Dataflow
(RDF) <ref xlink:href="#spades-2018-bid27" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>. RDF extends SDF with transformation
rules that specify how the topology and actors of the graph may be
reconfigured. Starting from an initial RDF graph and a set of
transformation rules, an arbitrary number of new RDF graphs can be
generated at runtime. The major quality of RDF is that it can be
statically analyzed to guarantee that all possible graphs generated at
runtime will be connected, consistent, and live. This is the research
topic of Arash Shafiei's PhD, in collaboration with Orange Labs.</p>
      </subsection>
      <subsection id="uid34" level="2">
        <bodyTitle>Monotonic prefix consistency in distributed systems</bodyTitle>
        <p>We have studied the issue of data consistency in distributed
systems. Specifically, we have considered a distributed system that
replicates its data at multiple sites, which is prone to partitions,
and which is assumed to be available (in the sense that queries are
always eventually answered). In such a setting, strong consistency,
where all replicas of the system apply synchronously every operation,
is not possible to implement. However, many weaker consistency
criteria that allow a greater number of behaviors than strong
consistency, are implementable in available distributed systems. We
have focused on determining the strongest consistency criterion that
can be implemented in a convergent and available distributed system
that tolerates partitions, and we have shown that no criterion
stronger than Monotonic Prefix Consistency
(MPC  <ref xlink:href="#spades-2018-bid28" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>, <ref xlink:href="#spades-2018-bid29" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>) can be
implemented <ref xlink:href="#spades-2018-bid30" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>.</p>
      </subsection>
    </subsection>
    <subsection id="uid35" level="1">
      <bodyTitle>Certified Real-Time Programming</bodyTitle>
      <participants>
        <person key="spades-2018-idp147520">
          <firstname>Pascal</firstname>
          <lastname>Fradet</lastname>
        </person>
        <person key="spades-2018-idp150368">
          <firstname>Alain</firstname>
          <lastname>Girault</lastname>
        </person>
        <person key="spades-2018-idp144608">
          <firstname>Gregor</firstname>
          <lastname>Goessler</lastname>
        </person>
        <person key="spades-2018-idp158176">
          <firstname>Xavier</firstname>
          <lastname>Nicollin</lastname>
        </person>
        <person key="spades-2018-idp153232">
          <firstname>Sophie</firstname>
          <lastname>Quinton</lastname>
        </person>
        <person key="spades-2018-idp165600">
          <firstname>Xiaojie</firstname>
          <lastname>Guo</lastname>
        </person>
        <person key="spades-2018-idp168048">
          <firstname>Maxime</firstname>
          <lastname>Lesourd</lastname>
        </person>
      </participants>
      <subsection id="uid36" level="2">
        <bodyTitle>Time predictable programming languages and architectures</bodyTitle>
        <p>Time predictability (PRET) is a topic that emerged in 2007 as a
solution to the ever increasing unpredictability of today's embedded
processors, which results from features such as multi-level caches or
deep pipelines <ref xlink:href="#spades-2018-bid31" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>. For many real-time systems, it is
mandatory to compute a strict bound on the program's execution
time. Yet, in general, computing a tight bound is extremely
difficult <ref xlink:href="#spades-2018-bid32" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>. The rationale of PRET is to simplify
both the programming language and the execution platform to allow more
precise execution times to be easily computed <ref xlink:href="#spades-2018-bid33" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>.</p>
        <p>We have extended the <span class="smallcap" align="left">Pret-C</span> compiler <ref xlink:href="#spades-2018-bid34" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/> in order
to make it energy aware. To achieve this, we use dynamic voltage and
frequency scaling (DFVS) and we insert DVFS control points in the
control flow graph of the <span class="smallcap" align="left">Pret-C</span> program. Several difficulties arise:
(i) the control flow graph is concurrent, (ii) the resulting
optimization problem is a time and energy multi-criteria problem, and
(iii) since we consider <span class="smallcap" align="left">Pret-C</span> programs, we actually address the
Worst-Case Execution Time (WCET) and the Worst-Case Energy Consumption
(WCEC). Thanks to a novel ILP formulation and to a bicriteria
heuristic, we are able to address the two objectives jointly and to
compute, for each <span class="smallcap" align="left">Pret-C</span> program, the Pareto front of the
non-dominated solutions in the 2D space
(WCET,WCEC)  <ref xlink:href="#spades-2018-bid35" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>. We have recently improved
this result to reduce the complexity of the algorithm and to produce
the <i>optimal</i> Pareto front. This is the topic of Jia Jie Wang's postdoc.</p>
        <p>Moreover, within the <span class="smallcap" align="left">Caphca</span> project, we have proposed a new approach
for predictable inter-core communication between tasks allocated on
different cores. Our approach is based on the execution of synchronous
programs written in the <span class="smallcap" align="left">ForeC</span> programming language on deterministic
architectures called PREcision Timed. The originality resides in the
time-triggered model of computation and communication that allows for
a very precise control over the thread execution. Synchronisation is
done via configurable Time Division Multiple Access (TDMA)
arbitrations (either physical or conceptual) where the optimal size
and offset of the time slots are computed to reduce the inter-core
synchronization costs. Results show that our model guarantees
time-predictable inter-core communication, the absence of concurrent
accesses (without relying on hardware mechanisms), and allows for
optimized execution throughput. This is the topic of Nicolas Hili's postdoc.</p>
      </subsection>
      <subsection id="uid37" level="2">
        <bodyTitle>Schedulability of weakly-hard real-time systems</bodyTitle>
        <p>We focus on the problem of computing tight deadline miss models for
real-time systems, which bound the number of potential deadline misses
in a given sequence of activations of a task. In practical
applications, such guarantees are often sufficient because many
systems are in fact not hard
real-time <ref xlink:href="#spades-2018-bid36" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>. A weakly-hard real-time
guarantee specifies an upper bound on the maximum number m of deadline
misses of a task in a sequence of k consecutive executions. Based on
our previous work on Typical Worst-Case
Analysis <ref xlink:href="#spades-2018-bid36" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>, <ref xlink:href="#spades-2018-bid37" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>, we have
introduced in <ref xlink:href="#spades-2018-bid38" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/> the first verification
method which is able to provide weakly-hard real-time guarantees for
tasks and task chains in systems with multiple resources under
partitioned scheduling with fixed priorities. All existing weakly-hard
real-time verification techniques are restricted today to systems with
a single resource. Our verification method is applied in the context
of switched networks with traffic streams between nodes, and we
demonstrate its practical applicability on an automotive case study.</p>
      </subsection>
      <subsection id="uid38" level="2">
        <bodyTitle>Synthesis of switching controllers using approximately
bisimilar multiscale abstractions</bodyTitle>
        <p>The use of discrete abstractions for continuous dynamics has become
standard in hybrid systems design (see <i>e.g.</i>,  <ref xlink:href="#spades-2018-bid21" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/> and
the references therein). The main advantage of this approach is that
it offers the possibility to leverage controller synthesis techniques
developed in the areas of supervisory control of discrete-event
systems  <ref xlink:href="#spades-2018-bid39" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>. The first attempts to compute discrete
abstractions for hybrid systems were based on traditional systems
behavioral relationships such as simulation or bisimulation, initially
proposed for discrete systems most notably in the area of formal
methods. These notions require inclusion or equivalence of observed
behaviors which is often too restrictive when dealing with systems
observed over metric spaces. For such systems, a more natural
abstraction requirement is to ask for closeness of observed
behaviors. This leads to the notions of approximate simulation and
bisimulation introduced in  <ref xlink:href="#spades-2018-bid40" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>.
These approaches are based on sampling of time and space where the
sampling parameters must satisfy some relation in order to obtain
abstractions of a prescribed precision. In particular, the smaller the
time sampling parameter, the finer the lattice used for approximating
the state-space; this may result in abstractions with a very large
number of states when the sampling period is small. However, there
are a number of applications where sampling has to be fast; though
this is generally necessary only on a small part of the state-space.</p>
        <p>We are currently investigating an approach using mode sequences as
symbolic states for our abstractions. By using mode sequences of
variable length we are able to adapt the granularity of our
abstraction to the dynamics of the system, so as to automatically
trade off precision against controllability of the abstract states.</p>
      </subsection>
      <subsection id="uid39" level="2">
        <bodyTitle>A Markov Decision Process approach for energy minimization
policies</bodyTitle>
        <p>In the context of independent real-time sporadic jobs running on a
single-core processor equipped with Dynamic Voltage and Frequency
Scaling (DVFS), we have proposed a Markov Decision Process approach
(MDP) to compute the scheduling policy that dynamically chooses the
voltage and frequency level of the processor such that each job meets
its deadline and the total energy consumption is minimized. We
distinguish two cases: the finite case (there is a fixed time horizon)
and the infinite case. In the finite case, several <i>offline</i>
solutions exist, which all use the complete knowledge of all the jobs
that will arrive within the time horizon  <ref xlink:href="#spades-2018-bid41" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>, <i>i.e.</i>, their
size and deadlines. But clearly this is unrealistic in the embedded
context where the characteristics of the jobs are not known in
advance. Then, an optimal offline policy called Optimal Available (OA)
has been proposed in  <ref xlink:href="#spades-2018-bid41" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>. Our goal was to improve this
result by taking into account the <i>statistical characteristics</i>
of the upcoming jobs. When such information is available (for instance
by profiling the jobs based on execution traces), we have proposed
several speed policies that optimize the <i>expected</i> energy
consumption. We have shown that this general constrained optimization
problem can be modeled as an unconstrained MDP by choosing a proper
state space that also encodes the constraints of the problem. In
particular, this implies that the optimal speed at each time can be
computed using a <i>dynamic programming</i> algorithm (under a finite
horizon), and that the optimal speed at any time <formula type="inline"><math xmlns="http://www.w3.org/1998/Math/MathML" overflow="scroll"><mi>t</mi></math></formula> will be a
deterministic function of the current state at
time <formula type="inline"><math xmlns="http://www.w3.org/1998/Math/MathML" overflow="scroll"><mi>t</mi></math></formula>  <ref xlink:href="#spades-2018-bid42" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>. Under an infinite horizon, we
use a <i>Value Iteration</i> algorithm.</p>
        <p>This work led us to compare several existing speed policies with
respect to their feasibility. Indeed, the policies
(OA)  <ref xlink:href="#spades-2018-bid41" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>, (AVR)  <ref xlink:href="#spades-2018-bid41" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>, and
(BKP)  <ref xlink:href="#spades-2018-bid43" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/> all assume that the maximal speed <formula type="inline"><math xmlns="http://www.w3.org/1998/Math/MathML" overflow="scroll"><msub><mi>S</mi><mrow><mi>m</mi><mi>a</mi><mi>x</mi></mrow></msub></math></formula> available on the processor is infinite, which is an unrealistic
assumption. For these three policies and for our (MDP) policy, we have
established necessary and sufficient conditions on <formula type="inline"><math xmlns="http://www.w3.org/1998/Math/MathML" overflow="scroll"><msub><mi>S</mi><mrow><mi>m</mi><mi>a</mi><mi>x</mi></mrow></msub></math></formula> guaranteeing
that no job will ever miss its deadline.</p>
        <p>This is the topic of Stephan Plassart's PhD, funded by the <span class="smallcap" align="left">Caserm</span> Persyval
project.</p>
      </subsection>
      <subsection id="uid40" level="2">
        <bodyTitle>Formal proofs for schedulability analysis of real-time
systems</bodyTitle>
        <p>We have started to lay the foundations for computer-assisted formal
verification of real-time systems analyses. Specifically, we contribute to
Prosa <ref xlink:href="#spades-2018-bid44" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>, a Coq library of reusable concepts and proofs
for real-time systems analysis. A key scientific challenge is to
achieve a modular structure of proofs, <i>e.g.</i>, for response time
analysis. Our goal is to use this library for:</p>
        <orderedlist>
          <li id="uid41">
            <p noindent="true">a better understanding of the role played by some assumptions in
existing proofs;</p>
          </li>
          <li id="uid42">
            <p noindent="true">a formal verification and comparison of different analysis
techniques; and</p>
          </li>
          <li id="uid43">
            <p noindent="true">the certification of results of existing (<i>e.g.</i>, industrial) analysis tools.</p>
          </li>
        </orderedlist>
        <p>Our first major result <ref xlink:href="#spades-2018-bid45" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/> is a task model that
generalizes the digraph model <ref xlink:href="#spades-2018-bid46" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/> and its
corresponding analysis for fixed-priority scheduling with limited
preemption. The motivation for this work, which is not yet fully
proven in Coq, is to obtain a formally verified schedulability analysis for a very expressive task model. In the context of computer assisted verification, it permits to factorize the correctness proofs of a large number of analyses. The digraph task model seems a good candidate due to its
powerful expressivity. Alas, its ability to capture dependencies
between arrival and execution times of jobs of different tasks is very
limited. Our extended model can capture dependencies between
jobs of the same task as well as jobs of different tasks. We provide a
correctness proof of the analysis that is written in a way amenable to
its formalization in the Coq proof assistant. Despite being much more
general, the Response Time Analysis (RTA) for our model is not significantly
more complex than the original one. Also, it underlines similarities
between existing analyses, in particular the analysis for the digraph
model and Tindell's offset model <ref xlink:href="#spades-2018-bid47" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>.</p>
        <p>A second major result is CertiCAN, a tool produced using Coq for the
formal certification of CAN analysis results. Result certification is
a process that is light-weight and flexible compared to tool
certification, which makes it a practical choice for industrial
purposes. The analysis underlying CertiCAN is based on a
combined use of two well-known CAN analysis
techniques <ref xlink:href="#spades-2018-bid47" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/> that makes it computationally
efficient. Experiments demonstrate that CertiCAN
is able to certify the results of RTaW-Pegase, an industrial CAN analysis tool,
even for large systems. This result paves the way for a broader
acceptance of formal tools for the certification of real-time systems
analysis results. Beyond CertiCAN, we believe that this work is
significant in that it demonstrates the advantage of result
certification over tool certification for the RTA of CAN buses. In
addition, the underlying technique can be reused for any other system
model for which there exist RTAs with different levels of
precision. This work will be presented at RTAS 2019.</p>
        <p>In parallel, we have completed and published
in <ref xlink:href="#spades-2018-bid48" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/> a Coq formalization of Typical
Worst-Case Analysis (TWCA) <ref xlink:href="#spades-2018-bid36" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>, <ref xlink:href="#spades-2018-bid37" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>, an analysis technique for weakly-hard real-time
systems. Our generic analysis is based on an abstract model that
characterizes the exact properties needed to make TWCA applicable to
any system model. Our results are formalized and checked using the Coq
proof assistant along with the Prosa schedulability analysis
library. This work opens up new research directions for TWCA by
providing a formal framework for the trade-off that must be found
between time efficiency and precision of the analysis.
Hopefully, our generic proof will make it easier to extend TWCA
to more complex models in the future. In addition, our experience
with formalizing real-time systems analyses shows that it is not
only a way to increase confidence in the results of the analyses; it also
helps understanding their key intermediate steps,
the exact assumptions required,
and how they can be generalized.</p>
      </subsection>
      <subsection id="uid44" level="2">
        <bodyTitle>Logical execution time</bodyTitle>
        <p>In collaboration with TU Braunschweig and Daimler, we have worked on
the application of the Logical Execution Time (LET)
paradigm  <ref xlink:href="#spades-2018-bid49" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>, according to which data are read and
written at predefined time instants, to the automotive industry. The
LET paradigm was considered until recently by the automotive industry
as not efficient enough in terms of buffer space and timing
performance. The shift to embedded multicore processors has
represented a game changer: The design and verification of multicore
systems is a challenging area of research that is still very much in
progress. Predictability clearly is a crucial issue which cannot be
tackled without changes in the design process. Several OEMs and
suppliers have come to the conclusion that LET might be a key enabler
and a standardization effort is already under way in the automotive
community to integrate LET into AUTOSAR. We have organized a Dagstuhl
seminar <ref xlink:href="#spades-2018-bid50" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/> to discuss and sketch solutions to
the problems raised by the use of LET in multicore systems. A white
paper on the topic is under preparation.</p>
        <p>So far, LET has been applied only at the ECU (Electronic Control Unit)
level by the automotive industry. Recent developments in electric
powertrains and autonomous vehicle functions raise parallel
programming from the multicore level to the vehicle level where the
standard LET approach cannot apply directly. We have proposed System
Level LET <ref xlink:href="#spades-2018-bid51" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>, an extension of LET with relaxed
synchronization requirements which allows separating network design
from ECU design and makes LET applicable to automotive distributed
systems.</p>
      </subsection>
      <subsection id="uid45" level="2">
        <bodyTitle>Scheduling under multiple constraints and Pareto optimization</bodyTitle>
        <p>We have continued our work on multi-criteria scheduling, in two
directions. First, in the context of dynamic applications that are
launched and terminated on an embedded homogeneous multi-core chip,
under execution time and energy consumption constraints, we have
proposed a two layer adaptive scheduling
method  <ref xlink:href="#spades-2018-bid52" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>. In the first layer, each
application (represented as a DAG of tasks) is scheduled statically on
subsets of cores: 2 cores, 3 cores, 4 cores, and so on. For each size
of these sets (2, 3, 4, ...), there may be only one topology or
several topologies. For instance, for 2 or 3 cores there is only one
topology (a “line”), while for 4 cores there are three distinct
topologies (“line”, “square”, and “T shape”). Moreover, for each
topology, we generate statically several schedules, each one subject
to a different total energy consumption constraint, and consequently
with a different Worst-Case Reaction Time (WCRT). Coping with the
energy consumption constraints is achieved thanks to Dynamic Frequency
and Voltage Scaling (DVFS). In the second layer, we use these
pre-generated static schedules to reconfigure dynamically the
applications running on the multi-core each time a new application is
launched or an existing one is stopped. The goal of the second layer
is to perform a dynamic global optimization of the configuration, such
that each running application meets a pre-defined quality-of-service
constraint (translated into an upper bound on its WCRT) and such that
the total energy consumption be minimized. For this, we <i>(i)</i>
allocate a sufficient number of cores to each active application,
<i>(ii)</i> allocate the unassigned cores to the applications yielding
the largest gain in energy, and <i>(iii)</i> choose for each
application the best topology for its subset of cores (<i>i.e.</i>, better than
the by default “line” topology). This is a joint work with Ismail Assayad (U. Casablanca, Morocco) who visited the team in 2018.</p>
        <p>Second, we have proposed the first of its kind multi-criteria
scheduling heuristics for a DAG of tasks onto an homogeneous
multi-core chip. Given an application modeled as a Directed Acyclic
Graph (DAG) of tasks and a multicore architecture, we produce a set of
non-dominated (in the Pareto sense) static schedules of this DAG onto
this multicore. The criteria we address are the execution time,
reliability, power consumption, and peak temperature. These criteria
exhibit complex antagonistic relations, which make the problem
challenging. For instance, improving the reliability requires adding
some redundancy in the schedule, which penalizes the execution
time. To produce Pareto fronts in this 4-dimension space, we transform
three of the four criteria into constraints (the reliability, the
power consumption, and the peak temperature), and we minimize the
fourth one (the execution time of the schedule) under these three
constraints. By varying the thresholds used for the three constraints,
we are able to produce a Pareto front of non-dominated solutions. Each
Pareto optimum is a static schedule of the DAG onto the multicore. We
propose two algorithms to compute static schedules. The first is a
ready list scheduling heuristic called ERPOT (Execution time,
Reliability, POwer consumption and Temperature). ERPOT actively
replicates the tasks to increase the reliability, uses Dynamic Voltage
and Frequency Scaling to decrease the power consumption, and inserts
cooling times to control the peak temperature. The second algorithm
uses an Integer Linear Programming (ILP) program to compute an optimal
schedule. However, because our multi-criteria scheduling problem is
NP-complete, the ILP algorithm is limited to very small problem
instances. Comparisons showed that the schedules produced by ERPOT are on average only 10% worse than the optimal schedules computed by
the ILP program, and that ERPOT outperforms the PowerPerf-PET heuristic from
the literature on average by 33%. This is a joint work with Athena Abdi and
Hamid Zarandi from Amirkabir University in Tehran, Iran.</p>
      </subsection>
    </subsection>
    <subsection id="uid46" level="1">
      <bodyTitle>Fault Management and Causal Analysis</bodyTitle>
      <participants>
        <person key="spades-2018-idp147520">
          <firstname>Pascal</firstname>
          <lastname>Fradet</lastname>
        </person>
        <person key="spades-2018-idp150368">
          <firstname>Alain</firstname>
          <lastname>Girault</lastname>
        </person>
        <person key="spades-2018-idp144608">
          <firstname>Gregor</firstname>
          <lastname>Goessler</lastname>
        </person>
        <person key="spades-2018-idp155696">
          <firstname>Jean-Bernard</firstname>
          <lastname>Stefani</lastname>
        </person>
        <person key="spades-2018-idp177808">
          <firstname>Martin</firstname>
          <lastname>Vassor</lastname>
        </person>
      </participants>
      <subsection id="uid47" level="2">
        <bodyTitle>Fault Ascription in Concurrent Systems</bodyTitle>
        <p>The failure of one component may entail a cascade of failures in other
components; several components may also fail independently. In such
cases, elucidating the exact scenario that led to the failure is a
complex and tedious task that requires significant expertise.</p>
        <p>The notion of causality <i>(did an event <formula type="inline"><math xmlns="http://www.w3.org/1998/Math/MathML" overflow="scroll"><mi>e</mi></math></formula> cause an event <formula type="inline"><math xmlns="http://www.w3.org/1998/Math/MathML" overflow="scroll"><msup><mi>e</mi><mo>'</mo></msup></math></formula>?)</i>
has been studied in many disciplines, including philosophy, logic,
statistics, and law. The definitions of causality studied in these
disciplines usually amount to variants of the counterfactual test
“<formula type="inline"><math xmlns="http://www.w3.org/1998/Math/MathML" overflow="scroll"><mi>e</mi></math></formula> is a cause of <formula type="inline"><math xmlns="http://www.w3.org/1998/Math/MathML" overflow="scroll"><msup><mi>e</mi><mo>'</mo></msup></math></formula> if both <formula type="inline"><math xmlns="http://www.w3.org/1998/Math/MathML" overflow="scroll"><mi>e</mi></math></formula> and <formula type="inline"><math xmlns="http://www.w3.org/1998/Math/MathML" overflow="scroll"><msup><mi>e</mi><mo>'</mo></msup></math></formula> have occurred, and in a
world that is as close as possible to the actual world but where <formula type="inline"><math xmlns="http://www.w3.org/1998/Math/MathML" overflow="scroll"><mi>e</mi></math></formula>
does not occur, <formula type="inline"><math xmlns="http://www.w3.org/1998/Math/MathML" overflow="scroll"><msup><mi>e</mi><mo>'</mo></msup></math></formula> does not occur either”. In computer science,
almost all definitions of logical causality — including the landmark
definition of <ref xlink:href="#spades-2018-bid53" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/> and its derivatives — rely
on a causal model that. However, this model may not be known, for
instance in presence of black-box components. For such systems, we
have been developing a framework for blaming that helps us establish
the causal relationship between component failures and system
failures, given an observed system execution trace. The analysis is
based on a formalization of counterfactual
reasoning <ref xlink:href="#spades-2018-bid54" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>.</p>
        <p>We are currently working on a revised version of our general semantic
framework for fault ascription in  <ref xlink:href="#spades-2018-bid55" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/> that
satisfies a set of formally stated requirements — such as its
behavior under several notions of abstraction and refinement —, and
on its instantiation to acyclic models of computation, in order to
compare our approach with the standard definition of <i>actual
causality</i> proposed by Halpern and Pearl.</p>
      </subsection>
      <subsection id="uid48" level="2">
        <bodyTitle>Fault Management in Virtualized Networks</bodyTitle>
        <p>From a more applied point of view we are investigating, in the context
of Sihem Cherrared's PhD thesis, approaches for fault explanation and
localization in virtualized networks. In essence, Network Function
Virtualization (NFV), widely adopted by the industry and the
standardization bodies, is about running network functions as software
workloads on commodity hardware to optimize deployment costs and
simplify the life-cycle management of network functions. However, it
introduces new fault management challenges including dynamic topology
and multi-tenant fault isolation that we discuss
in <ref xlink:href="#spades-2018-bid56" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>. As a first step to tackle those
challenges, we have extended the classical fault management process to
the virtualized functions by introducing LUMEN: a Global Fault
Management Framework. Our approach aims at providing the availability
and reliability of the virtualized 5G end-to-end service chain. LUMEN
includes the canonical steps of the fault management process and
proposes a monitoring solution for all types of Network virtualization
Environments. Our framework is based on open source solutions and
could easily be integrated with other existing autonomic management
models.</p>
      </subsection>
    </subsection>
  </resultats>
  <contrats id="uid49">
    <bodyTitle>Bilateral Contracts and Grants with Industry</bodyTitle>
    <subsection id="uid50" level="1">
      <bodyTitle>Bilateral Contracts with Industry</bodyTitle>
      <simplelist>
        <li id="uid51">
          <p noindent="true">Inria and Orange Labs have established in 2015 a joint
virtual research laboratory, called <span class="smallcap" align="left">I/O Lab</span>. We have been
heavily involved in the creation of the laboratory and are actively
involved in its operation (Jean-Bernard Stefani is one of the two co-directors of
the lab). <span class="smallcap" align="left">I/O Lab</span> focuses on the network virtualization and
cloudification. As part of the work of <span class="smallcap" align="left">I/O Lab</span>, we have
cooperated with Orange Lab, as part of a cooperative research
contract funded by Orange, on defining architectural principles and
frameworks for network cloud infrastructures encompassing control
and management of computing, storage and network resources.</p>
        </li>
        <li id="uid52">
          <p noindent="true">With Daimler (subcontracting via iUTBS): We have proposed, in
collaboration with TU Braunschweig, an extension of the LET
paradigm  <ref xlink:href="#spades-2018-bid49" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>, called <i>System-level LET, to
accommodate the specific needs of the design process in the
automotive industry, in which the network structure must be made
explicit in the LET program.</i></p>
        </li>
      </simplelist>
    </subsection>
    <subsection id="uid53" level="1">
      <bodyTitle>Bilateral Grants with Industry</bodyTitle>
      <p>With Thales: Early performance assessment for evolving and variable
cyber-physical systems. This CIFRE grant funds the PhD of Christophe Prévot.</p>
      <p>With Orange: Programming IoT and sofware defined radio
with dynamic dataflow models of computation. This CIFRE grant funds
the PhD of Arash Shafiei.</p>
    </subsection>
  </contrats>
  <partenariat id="uid54">
    <bodyTitle>Partnerships and Cooperations</bodyTitle>
    <subsection id="uid55" level="1">
      <bodyTitle>Regional Initiatives</bodyTitle>
      <subsection id="uid56" level="2">
        <bodyTitle>CASERM (PERSYVAL-Lab project)</bodyTitle>
        <participants>
          <person key="spades-2018-idp147520">
            <firstname>Pascal</firstname>
            <lastname>Fradet</lastname>
          </person>
          <person key="spades-2018-idp150368">
            <firstname>Alain</firstname>
            <lastname>Girault</lastname>
          </person>
          <person key="spades-2018-idp144608">
            <firstname>Gregor</firstname>
            <lastname>Goessler</lastname>
          </person>
          <person key="spades-2018-idp165600">
            <firstname>Xiaojie</firstname>
            <lastname>Guo</lastname>
          </person>
          <person key="spades-2018-idp168048">
            <firstname>Maxime</firstname>
            <lastname>Lesourd</lastname>
          </person>
          <person key="spades-2018-idp158176">
            <firstname>Xavier</firstname>
            <lastname>Nicollin</lastname>
          </person>
          <person key="polaris-2018-idp188912">
            <firstname>Stephan</firstname>
            <lastname>Plassart</lastname>
          </person>
          <person key="spades-2018-idp153232">
            <firstname>Sophie</firstname>
            <lastname>Quinton</lastname>
          </person>
          <person key="spades-2018-idp155696">
            <firstname>Jean-Bernard</firstname>
            <lastname>Stefani</lastname>
          </person>
          <person key="spades-2018-idp177808">
            <firstname>Martin</firstname>
            <lastname>Vassor</lastname>
          </person>
        </participants>
        <p>Despite recent advances, there exists currently no integrated formal
methods and tools for the design and analysis of reconfigurable
multi-view embedded systems. This is the goal of the <span class="smallcap" align="left">Caserm</span> project.</p>
        <p>The <span class="smallcap" align="left">Caserm</span> project represents a significant effort towards a
<span class="smallcap" align="left">Coq</span>-based design method for reconfigurable multi-view embedded
systems, in order to formalize the structure and behavior of systems
and to prove their main properties. The use of a proof assistant to
support such a framework is motivated by the fact that the targeted
systems are both extremely complex and critical. The challenges
addressed are threefold:</p>
        <orderedlist>
          <li id="uid57">
            <p noindent="true">to model software architectures for embedded systems taking into
account their dynamicity and multiple constraints (functional as
well as non functional);</p>
          </li>
          <li id="uid58">
            <p noindent="true">to propose novel scheduling techniques for dynamically
reconfiguring embedded systems; and</p>
          </li>
          <li id="uid59">
            <p noindent="true">to advance the state of the art in automated proving for such
systems.</p>
          </li>
        </orderedlist>
        <p>The objectives of <span class="smallcap" align="left">Caserm</span> that address these challenges are organized
in three tasks. They consist respectively in designing an architecture
description framework based on a process calculus, in proposing online
optimization methods for dynamic reconfiguration systems (this is the
topic of Stephan Plassart's PhD), and in developing a formal framework for
real-time analysis in the <span class="smallcap" align="left">Coq</span> proof assistant (this is the topic of
Xiaojie Guo's and Maxime Lesourd's PhD). A fourth task focuses on common case studies for
the evaluation of the obtained results.</p>
        <p>The <span class="smallcap" align="left">Caserm</span> consortium gathers researchers from the <span class="smallcap" align="left">LIG</span> and
<span class="smallcap" align="left">Verimag</span> laboratories who are reknowned specialists in these fields.
The project started in November 2016 and will last three years.</p>
      </subsection>
    </subsection>
    <subsection id="uid60" level="1">
      <bodyTitle>National Initiatives</bodyTitle>
      <subsection id="uid61" level="2">
        <bodyTitle>ANR</bodyTitle>
        <subsection id="uid62" level="3">
          <bodyTitle>RT-Proofs</bodyTitle>
          <participants>
            <person key="spades-2018-idp147520">
              <firstname>Pascal</firstname>
              <lastname>Fradet</lastname>
            </person>
            <person key="spades-2018-idp165600">
              <firstname>Xiaojie</firstname>
              <lastname>Guo</lastname>
            </person>
            <person key="spades-2018-idp168048">
              <firstname>Maxime</firstname>
              <lastname>Lesourd</lastname>
            </person>
            <person key="spades-2018-idp153232">
              <firstname>Sophie</firstname>
              <lastname>Quinton</lastname>
            </person>
          </participants>
          <p>RT-Proofs is an ANR/DFG project between Inria, MPI-SWS, Onera, TU
Braunschweig and Verimag, running from 2018 until 2020.</p>
          <p>The overall objective of the RT-Proofs project is to lay the
foundations for computer-assisted formal verification of timing
analysis results. More precisely, the goal is to provide:</p>
          <orderedlist>
            <li id="uid63">
              <p noindent="true">a strong formal basis for schedulability, blocking, and
response-time analysis supported by the Coq proof assistant, that is
as generic, robust, and modular as possible;</p>
            </li>
            <li id="uid64">
              <p noindent="true">correctness proofs for new and well-established
generalized response-time analysis results, and a better, precise
understanding of the role played by key assumptions and formal
connections between competing analysis techniques;</p>
            </li>
            <li id="uid65">
              <p noindent="true">an approach for the generation of proof certificates so that
analysis results – in contrast to analysis tools – can be
certified.</p>
            </li>
          </orderedlist>
        </subsection>
        <subsection id="uid66" level="3">
          <bodyTitle>
            <span class="smallcap" align="left">DCore</span>
          </bodyTitle>
          <participants>
            <person key="spades-2018-idp144608">
              <firstname>Gregor</firstname>
              <lastname>Goessler</lastname>
            </person>
            <person key="spades-2018-idp155696">
              <firstname>Jean-Bernard</firstname>
              <lastname>Stefani</lastname>
            </person>
          </participants>
          <p><span class="smallcap" align="left">DCore</span> is an ANR project between Inria project teams <span class="smallcap" align="left">Antique</span>, <span class="smallcap" align="left">Focus</span> and <span class="smallcap" align="left">Spades</span>, and the <span class="smallcap" align="left">Irif</span> lab, running from 2019 to 2023.</p>
          <p>The overall objective of the project is to develop a semantically
well-founded, novel form of concurrent debugging, which we call <i>causal debugging</i>, that aims to alleviate the deficiencies of
current debugging techniques for large concurrent software systems.
The causal debugging technology developed by <span class="smallcap" align="left">DCore</span> will comprise and
integrate two main novel engines:</p>
          <orderedlist>
            <li id="uid67">
              <p noindent="true"><i>a reversible execution engine</i> that allows programmers to
backtrack and replay a concurrent or distributed program execution,
in a way that is both precise and efficient (only the exact threads
involved by a return to a target anterior or posterior program state
are impacted);</p>
            </li>
            <li id="uid68">
              <p noindent="true">a <i>causal analysis engine</i> that allows programmers to analyze concurrent
executions, by asking questions of the form “what
caused the violation of this program property?”, and that allows for
the precise and efficient investigation of past and potential program executions.</p>
            </li>
          </orderedlist>
        </subsection>
      </subsection>
      <subsection id="uid69" level="2">
        <bodyTitle>Institute of Technology (IRT)</bodyTitle>
        <subsection id="uid70" level="3">
          <bodyTitle>CAPHCA</bodyTitle>
          <participants>
            <person key="spades-2018-idp150368">
              <firstname>Alain</firstname>
              <lastname>Girault</lastname>
            </person>
            <person key="spades-2018-idp163136">
              <firstname>Nicolas</firstname>
              <lastname>Hili</lastname>
            </person>
          </participants>
          <p><span class="smallcap" align="left">Caphca</span> is a project within the Antoine de Saint Exupéry IRT. The
general objective of the project is to provide methods and tools to
achieve performance and determinism on modern, high-performance,
multi-core and FPGA-enabled SOCs. Our specific contribution lies
withing work pakacges dedicated to the design of novel PRET
architectures and programming languages (see Section <ref xlink:href="#uid36" location="intern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>).</p>
        </subsection>
      </subsection>
    </subsection>
    <subsection id="uid71" level="1">
      <bodyTitle>European Initiatives</bodyTitle>
      <subsection id="uid72" level="2">
        <bodyTitle>Collaborations in European Programs, Except FP7 &amp; H2020</bodyTitle>
        <sanspuceslist>
          <li id="uid73">
            <p noindent="true">Program: Celtic-Plus</p>
          </li>
          <li id="uid74">
            <p noindent="true">Project acronym: SENDATE</p>
          </li>
          <li id="uid75">
            <p noindent="true">Project title: Secure Networking for a Data center cloud in Europe</p>
          </li>
          <li id="uid76">
            <p noindent="true">Duration: April 2016 - March 2019</p>
          </li>
          <li id="uid77">
            <p noindent="true">Coordinator: Nokia France</p>
          </li>
          <li id="uid78">
            <p noindent="true">Other partners: Nokia, Orange, IMT, Inria</p>
          </li>
          <li id="uid79">
            <p noindent="true">Abstract: The SENDATE project aims to develop a clean-slate architecture for converged telecommunications networks and distributed data centers supporting 5G cellular networks and the needs from the Industrial Internet and the Internet of Things. It aims to provide scientific and technical solutions for intra and inter data centrers security, control, management and orchestration, placement and management of virtual network functions, as well as high-speed transport networks for data centers access and interconnection.</p>
          </li>
        </sanspuceslist>
      </subsection>
      <subsection id="uid80" level="2">
        <bodyTitle>Collaborations with Major European Organizations</bodyTitle>
        <p>We have a strong collaboration with the Technische Universität
Braunschweig in Germany. In particular, Sophie Quinton is involved in the CCC
project (<ref xlink:href="http://ccc-project.org/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://<allowbreak/>ccc-project.<allowbreak/>org/</ref>) to provide methods and
mechanisms for the verification of software updates after deployment
in safety-critical systems, and in the TypicalCPA project which aims at
computing deadline miss models for distributed systems.</p>
        <p>We also have a recent collaboration with the MPI-SWS in Kaiserslautern
(Germany) on formal proofs for real-time systems. This collaboration
will be concretized by an ANR-PRCI project called RT-PROOFS starting
in 2018, which involves MPI-SWS, TU Braunschweig, Inria, and Onera.</p>
      </subsection>
    </subsection>
    <subsection id="uid81" level="1">
      <bodyTitle>International Research Visitors</bodyTitle>
      <subsection id="uid82" level="2">
        <bodyTitle>Visits of International Scientists</bodyTitle>
        <simplelist>
          <li id="uid83">
            <p noindent="true">Ismail Assayad (from U. Casablanca, Morocco) visited the team for one
month in September 2018, to work on a two layer adaptive scheduling
method.</p>
          </li>
        </simplelist>
      </subsection>
    </subsection>
  </partenariat>
  <diffusion id="uid84">
    <bodyTitle>Dissemination</bodyTitle>
    <subsection id="uid85" level="1">
      <bodyTitle>Promoting Scientific Activities</bodyTitle>
      <subsection id="uid86" level="2">
        <bodyTitle>Scientific Events Organisation</bodyTitle>
        <subsection id="uid87" level="3">
          <bodyTitle>General Chair, Scientific Chair</bodyTitle>
          <simplelist>
            <li id="uid88">
              <p noindent="true">Alain Girault is member of the steering committee of the International
Federated Conference on Distributed Computing Techniques (DISCOTEC)
and of the ACM International Conference on Embedded Software
(EMSOFT).</p>
            </li>
            <li id="uid89">
              <p noindent="true">Gregor Gössler is member of the steering committee of the International
Workshop on Causal Reasoning for Embedded and Safety-critical
Systems Technologies (CREST).</p>
            </li>
            <li id="uid90">
              <p noindent="true">Jean-Bernard Stefani is the current chair of the steering committee of the IFIP
FORTE international conference series, a member of the steering
committee of the IFIP DISCOTEC conference series, and the current
chair of the IFIP Working Group 6.1.</p>
            </li>
          </simplelist>
        </subsection>
        <subsection id="uid91" level="3">
          <bodyTitle>Member of the Organizing Committees</bodyTitle>
          <simplelist>
            <li id="uid92">
              <p noindent="true">Sophie Quinton was the co-organizer of a Dagstuhl seminar entitled “The
Logical Execution Time Paradigm: New Perspectives for Multicore
Systems”. <ref xlink:href="https://www.dagstuhl.de/18092" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>www.<allowbreak/>dagstuhl.<allowbreak/>de/<allowbreak/>18092</ref></p>
            </li>
          </simplelist>
        </subsection>
      </subsection>
      <subsection id="uid93" level="2">
        <bodyTitle>Scientific Events Selection</bodyTitle>
        <subsection id="uid94" level="3">
          <bodyTitle>Member of the Conference Program Committees</bodyTitle>
          <simplelist>
            <li id="uid95">
              <p noindent="true">Alain Girault served in the program committees of the Symposium on
Industrial Embedded Systems (SIES'18), the Forum on specification
and Design Languages (FDL'18), and the Conference on Applications of
Concurrency to System Design (ACSD'18).</p>
            </li>
            <li id="uid96">
              <p noindent="true">Gregor Gössler served in the program committees of the 18th International
Workshop on Automated Verification of Critical Systems (AVOCS 2018)
and the 3rd international Workshop on Formal Reasoning about
Causation, Responsibility, and Explanations in Science and
Technology (CREST 2018).</p>
            </li>
            <li id="uid97">
              <p noindent="true">Sophie Quinton served in the program committees of the 30th Euromicro
Conference on Real-Time Systems (ECRTS'18), the 9th International
Workshop on Analysis Tools and Methodologies for Embedded and
Real-time Systems (WATERS'18), the 39th IEEE Real-Time Systems
Symposium (RTSS'18) and the 26th International Conference on
Real-Time Networks and Systems (RTNS'18).</p>
            </li>
          </simplelist>
        </subsection>
        <subsection id="uid98" level="3">
          <bodyTitle>Reviewer</bodyTitle>
          <simplelist>
            <li id="uid99">
              <p noindent="true">Alain Girault reviewed papers for the ECRTS'18 conference.</p>
            </li>
          </simplelist>
        </subsection>
      </subsection>
      <subsection id="uid100" level="2">
        <bodyTitle>Journal</bodyTitle>
        <subsection id="uid101" level="3">
          <bodyTitle>Member of the Editorial Boards</bodyTitle>
          <simplelist>
            <li id="uid102">
              <p noindent="true">Alain Girault is a member of the editorial board of the Journal on
Embedded Systems.</p>
            </li>
          </simplelist>
        </subsection>
        <subsection id="uid103" level="3">
          <bodyTitle>Reviewer - Reviewing Activities</bodyTitle>
          <simplelist>
            <li id="uid104">
              <p noindent="true">Alain Girault reviewed articles for J. of Transportation Technologies
(JTT) and IEEE Trans. Dependable and Secure Computing (TDSC).</p>
            </li>
            <li id="uid105">
              <p noindent="true">Gregor Gössler reviewed articles for IEEE Transactions on Automatic Control
(TAC) and ACM Transactions on Embedded Computing Systems (TECS).</p>
            </li>
            <li id="uid106">
              <p noindent="true">Sophie Quinton reviewed an article for ACM Trans. on Embedded Computing
Systems (TECS).</p>
            </li>
          </simplelist>
        </subsection>
      </subsection>
      <subsection id="uid107" level="2">
        <bodyTitle>Research Administration</bodyTitle>
        <simplelist>
          <li id="uid108">
            <p noindent="true">Pascal Fradet is head of the committee for doctoral studies (“Responsable
du comité des études doctorales”) of the Inria Grenoble – Rhône-Alpes research
center and local correspondent for the young researchers Inria mission (“Mission jeunes chercheurs”).</p>
          </li>
          <li id="uid109">
            <p noindent="true">Alain Girault is vice-chair of the Inria Evaluation Committee.</p>
          </li>
          <li id="uid110">
            <p noindent="true">Xavier Nicollin is member of the committee for computing resources users
(“Comité des Utilisateurs des Moyens Informatiques”) of the
Inria Grenoble – Rhône-Alpes research center.</p>
          </li>
          <li id="uid111">
            <p noindent="true">Jean-Bernard Stefani is head of science (délégué scientifique) of the Inria Grenoble – Rhône-Alpes research center and a member of the Inria Evaluation Committee.</p>
          </li>
        </simplelist>
      </subsection>
    </subsection>
    <subsection id="uid112" level="1">
      <bodyTitle>Teaching - Supervision - Juries</bodyTitle>
      <subsection id="uid113" level="2">
        <bodyTitle>Teaching</bodyTitle>
        <sanspuceslist>
          <li id="uid114">
            <p noindent="true">Licence : Pascal Fradet, Théorie des Langages 1 &amp; 2, 36 HeqTD, niveau L3, Grenoble INP
(Ensimag), France</p>
          </li>
          <li id="uid115">
            <p noindent="true">Licence : Pascal Fradet, Modèles de Calcul : <formula type="inline"><math xmlns="http://www.w3.org/1998/Math/MathML" overflow="scroll"><mi>λ</mi></math></formula>-calcul, 12 HeqTD, niveau L3, Univ. Grenoble Alpes, France</p>
          </li>
          <li id="uid116">
            <p noindent="true">Master : Pascal Fradet, Langages et Traducteurs, 16 HeqTD, niveau M1, Polytech Grenoble, Univ. Grenoble Alpes, France</p>
          </li>
          <li id="uid117">
            <p noindent="true">Master : Xavier Nicollin, Sémantique et Analyse des Programmes,
45 HeqTD, niveau M1, Grenoble INP (Ensimag), France</p>
          </li>
          <li id="uid118">
            <p noindent="true">Licence : Xavier Nicollin, Théorie des Langages 2, 36 HeqTD, niveau L3,
Grenoble INP (Ensimag), France</p>
          </li>
          <li id="uid119">
            <p noindent="true">Licence : Xavier Nicollin, Bases de la Programmation Impérative, 81 HeqTD
(2017-2018), niveau L3, Grenoble INP (Ensimag), France</p>
          </li>
          <li id="uid120">
            <p noindent="true">Licence : Sophie Quinton, Théorie des Langages 2, 18 HeqTD, niveau L3,
Grenoble INP (Ensimag), France</p>
          </li>
          <li id="uid121">
            <p noindent="true">Master : Sophie Quinton, Performance and Quantitative Properties, 6h,
MOSIG, Univ. Grenoble Alpes, France</p>
          </li>
          <li id="uid122">
            <p noindent="true">Master: Jean-Bernard Stefani, Formal Aspects of Component Software, 9h, MOSIG, Univ. Grenoble Alpes, France.</p>
          </li>
        </sanspuceslist>
      </subsection>
      <subsection id="uid123" level="2">
        <bodyTitle>Supervision</bodyTitle>
        <simplelist>
          <li id="uid124">
            <p noindent="true">PhD in progress: Sihem Cherrared, “Fault Management in
Multi-Tenant Programmable Networks”, Univ. Rennes 1, since October
2016, co-advised by Eric Fabre and Gregor Gössler.</p>
          </li>
          <li id="uid125">
            <p noindent="true">PhD in progress: Christophe Prévot, “Early Performance assessment for
evolving and variable Cyber-Physical Systems”, Univ. Grenoble
Alpes, since November 2015, co-advised by Alain Girault and Sophie Quinton.</p>
          </li>
          <li id="uid126">
            <p noindent="true">PhD in progress: Stephan Plassart, “On-line optimization in dynamic
real-time systems”, Univ. Grenoble Alpes, since September 2016, co-advised by Bruno
Gaujal and Alain Girault.</p>
          </li>
          <li id="uid127">
            <p noindent="true">PhD in progress: Xiaojie Guo, “Formal Proofs for the Analysis of
Real-Time Systems in <span class="smallcap" align="left">Coq</span>”, Univ. Grenoble Alpes, since December 2016, co-advised
by Pascal Fradet, Jean-François Monin, and Sophie Quinton.</p>
          </li>
          <li id="uid128">
            <p noindent="true">PhD in progress: Maxime Lesourd, “Generic Proofs for the Analysis of
Real-Time Systems in <span class="smallcap" align="left">Coq</span>”, Univ. Grenoble Alpes, since September 2017, co-advised
by Pascal Fradet, Jean-François Monin, and Sophie Quinton.</p>
          </li>
          <li id="uid129">
            <p noindent="true">PhD in progress: Arash Shafiei, “Programming IoT and sofware defined
radio with dynamic dataflow models of computation”, Univ. Grenoble Alpes, since
September 2017, co-advised by Pascal Fradet, Alain Girault, and Xavier Nicollin.</p>
          </li>
          <li id="uid130">
            <p noindent="true">PhD in progress: Martin Vassor, “Analysis and types for safe dynamic
software reconfigurations”, Univ. Grenoble Alpes, since November
2017, co-advised by Pascal Fradet and Jean-Bernard Stefani.</p>
          </li>
          <li id="uid131">
            <p noindent="true">M2 SIF in progress: T. Mari, “From diagnosis to causal
analysis”, U. Rennes, since November 2018, co-supervised by Gregor Gössler and
Louise Travé-Massuyès (<span class="smallcap" align="left">Laas</span>).</p>
          </li>
          <li id="uid132">
            <p noindent="true">PFE: Clément Arvis, “Génération automatique de musique”,
Grenoble INP/Ensimag, September 2018, supervized by Sophie Quinton.</p>
          </li>
        </simplelist>
      </subsection>
      <subsection id="uid133" level="2">
        <bodyTitle>Juries</bodyTitle>
        <simplelist>
          <li id="uid134">
            <p noindent="true">Alain Girault was referee for the PhD thesis of Colin Vidal, Université
Côte d'Azur, and for the PhD thesis of Julien Hascoet, INSA
Rennes. He was also vice-president of the Inria Senior Researcher
jury (DR2) and of the Inria Junior Researcher national jury (CRCN).</p>
          </li>
          <li id="uid135">
            <p noindent="true">Gregor Gössler was examiner for the PhD jury of Vincent Wang (U. Pennsylvania).</p>
          </li>
          <li id="uid136">
            <p noindent="true">Jean-Bernard Stefani was examiner for the Habilitation (HDR) jury of Thomas
Ledoux (U. Nantes).</p>
          </li>
          <li id="uid137">
            <p noindent="true">Sophie Quinton was member of the CRCN jury in Rennes.</p>
          </li>
        </simplelist>
      </subsection>
    </subsection>
    <subsection id="uid138" level="1">
      <bodyTitle>Popularization</bodyTitle>
      <subsection id="uid139" level="2">
        <bodyTitle>Interventions</bodyTitle>
        <p>Sophie Quinton gave a keynote at the MathC2+ event organized by Inria, entitled
“Faire des preuves par ordinateur : Pourquoi et comment ?”
(Computer-assisted proofs: Why and how?).</p>
      </subsection>
    </subsection>
  </diffusion>
  <biblio id="bibliography" html="bibliography" numero="10" titre="Bibliography">
    
    <biblStruct id="spades-2018-bid63" type="article" rend="refer" n="refercite:andalam14">
      <analytic>
        <title level="a">A Predictable Framework for Safety-Critical Embedded Systems</title>
        <author>
          <persName>
            <foreName>S.</foreName>
            <surname>Andalam</surname>
            <initial>S.</initial>
          </persName>
          <persName>
            <foreName>P.S.</foreName>
            <surname>Roop</surname>
            <initial>P.</initial>
          </persName>
          <persName key="spades-2018-idp150368">
            <foreName>A.</foreName>
            <surname>Girault</surname>
            <initial>A.</initial>
          </persName>
          <persName>
            <foreName>C.</foreName>
            <surname>Traulsen</surname>
            <initial>C.</initial>
          </persName>
        </author>
      </analytic>
      <monogr>
        <title level="j">IEEE Trans. on Computers</title>
        <imprint>
          <biblScope type="volume">63</biblScope>
          <biblScope type="number">7</biblScope>
          <dateStruct>
            <month>July</month>
            <year>2014</year>
          </dateStruct>
          <biblScope type="pages">1600–1612</biblScope>
        </imprint>
      </monogr>
    </biblStruct>
    
    <biblStruct id="spades-2018-bid64" type="article" rend="refer" n="refercite:DBLP:journals/todaes/BouakazFG17">
      <identifiant type="doi" value="10.1145/2999539"/>
      <analytic>
        <title level="a">A Survey of Parametric Dataflow Models of Computation</title>
        <author>
          <persName>
            <foreName>Adnan</foreName>
            <surname>Bouakaz</surname>
            <initial>A.</initial>
          </persName>
          <persName key="spades-2018-idp147520">
            <foreName>Pascal</foreName>
            <surname>Fradet</surname>
            <initial>P.</initial>
          </persName>
          <persName key="spades-2018-idp150368">
            <foreName>Alain</foreName>
            <surname>Girault</surname>
            <initial>A.</initial>
          </persName>
        </author>
      </analytic>
      <monogr>
        <title level="j">ACM Trans. Design Autom. Electr. Syst.</title>
        <imprint>
          <biblScope type="volume">22</biblScope>
          <biblScope type="number">2</biblScope>
          <dateStruct>
            <year>2017</year>
          </dateStruct>
          <biblScope type="pages">38:1–38:25</biblScope>
          <ref xlink:href="https://doi.org/10.1145/2999539" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>doi.<allowbreak/>org/<allowbreak/>10.<allowbreak/>1145/<allowbreak/>2999539</ref>
        </imprint>
      </monogr>
    </biblStruct>
    
    <biblStruct id="spades-2018-bid36" type="inproceedings" rend="refer" n="refercite:frehse:hal-01097622">
      <identifiant type="hal" value="hal-01097622"/>
      <analytic>
        <title level="a">Formal Analysis of Timing Effects on Closed-loop Properties of Control Software</title>
        <author>
          <persName>
            <foreName>Goran</foreName>
            <surname>Frehse</surname>
            <initial>G.</initial>
          </persName>
          <persName>
            <foreName>Arne</foreName>
            <surname>Hamann</surname>
            <initial>A.</initial>
          </persName>
          <persName key="spades-2018-idp153232">
            <foreName>Sophie</foreName>
            <surname>Quinton</surname>
            <initial>S.</initial>
          </persName>
          <persName>
            <foreName>Matthias</foreName>
            <surname>Wöhrle</surname>
            <initial>M.</initial>
          </persName>
        </author>
      </analytic>
      <monogr>
        <title level="m">35th IEEE Real-Time Systems Symposium 2014 (RTSS)</title>
        <loc>Rome, Italy</loc>
        <imprint>
          <dateStruct>
            <month>December</month>
            <year>2014</year>
          </dateStruct>
          <ref xlink:href="https://hal.inria.fr/hal-01097622" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01097622</ref>
        </imprint>
      </monogr>
    </biblStruct>
    
    <biblStruct id="spades-2018-bid61" type="article" rend="refer" n="refercite:girard:hal-01197426">
      <identifiant type="doi" value="10.1109/TAC.2015.2478131"/>
      <identifiant type="hal" value="hal-01197426"/>
      <analytic>
        <title level="a">Safety Controller Synthesis for Incrementally Stable Switched Systems Using Multiscale Symbolic Models</title>
        <author>
          <persName>
            <foreName>Antoine</foreName>
            <surname>Girard</surname>
            <initial>A.</initial>
          </persName>
          <persName>
            <foreName>Gregor</foreName>
            <surname>Gössler</surname>
            <initial>G.</initial>
          </persName>
          <persName>
            <foreName>Sebti</foreName>
            <surname>Mouelhi</surname>
            <initial>S.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-scientific-popularization="no" x-editorial-board="yes" x-international-audience="yes">
        <title level="j">IEEE Transactions on Automatic Control</title>
        <imprint>
          <biblScope type="volume">61</biblScope>
          <biblScope type="number">6</biblScope>
          <dateStruct>
            <year>2016</year>
          </dateStruct>
          <biblScope type="pages">1537-1549</biblScope>
          <ref xlink:href="https://hal.archives-ouvertes.fr/hal-01197426" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>archives-ouvertes.<allowbreak/>fr/<allowbreak/>hal-01197426</ref>
        </imprint>
      </monogr>
    </biblStruct>
    
    <biblStruct id="spades-2018-bid54" type="article" rend="refer" n="refercite:gossler:hal-01211484">
      <identifiant type="doi" value="10.1016/j.scico.2015.06.010"/>
      <identifiant type="hal" value="hal-01211484"/>
      <analytic>
        <title level="a">A general framework for blaming in component-based systems</title>
        <author>
          <persName>
            <foreName>Gregor</foreName>
            <surname>Gössler</surname>
            <initial>G.</initial>
          </persName>
          <persName key="privatics-2018-idp116160">
            <foreName>Daniel</foreName>
            <surname>Le Métayer</surname>
            <initial>D.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-scientific-popularization="no" x-editorial-board="yes" x-international-audience="yes">
        <title level="j">Science of Computer Programming</title>
        <imprint>
          <biblScope type="volume">113, Part 3</biblScope>
          <dateStruct>
            <year>2015</year>
          </dateStruct>
          <ref xlink:href="https://hal.inria.fr/hal-01211484" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01211484</ref>
        </imprint>
      </monogr>
    </biblStruct>
    
    <biblStruct id="spades-2018-bid60" type="article" rend="refer" n="refercite:lanese:hal-01303090">
      <identifiant type="doi" value="10.1016/j.tcs.2016.02.019"/>
      <identifiant type="hal" value="hal-01303090"/>
      <analytic>
        <title level="a">Reversibility in the higher-order <formula type="inline"><math xmlns="http://www.w3.org/1998/Math/MathML" overflow="scroll"><mi>π</mi></math></formula>-calculus</title>
        <author>
          <persName key="focus-2018-idp151632">
            <foreName>Ivan</foreName>
            <surname>Lanese</surname>
            <initial>I.</initial>
          </persName>
          <persName>
            <foreName>Claudio Antares</foreName>
            <surname>Mezzina</surname>
            <initial>C. A.</initial>
          </persName>
          <persName key="spades-2018-idp155696">
            <foreName>Jean-Bernard</foreName>
            <surname>Stefani</surname>
            <initial>J.-B.</initial>
          </persName>
        </author>
      </analytic>
      <monogr>
        <title level="j">Theoretical Computer Science</title>
        <imprint>
          <biblScope type="volume">625</biblScope>
          <dateStruct>
            <year>2016</year>
          </dateStruct>
          <biblScope type="pages">25-84</biblScope>
          <ref xlink:href="https://hal.inria.fr/hal-01303090" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01303090</ref>
        </imprint>
      </monogr>
    </biblStruct>
    
    <biblStruct id="spades-2018-bid37" type="inproceedings" rend="refer" n="refercite:QuintonHE12">
      <identifiant type="doi" value="10.1109/DATE.2012.6176523"/>
      <analytic>
        <title level="a">Formal analysis of sporadic overload in real-time systems</title>
        <author>
          <persName key="spades-2018-idp153232">
            <foreName>Sophie</foreName>
            <surname>Quinton</surname>
            <initial>S.</initial>
          </persName>
          <persName>
            <foreName>Matthias</foreName>
            <surname>Hanke</surname>
            <initial>M.</initial>
          </persName>
          <persName>
            <foreName>Rolf</foreName>
            <surname>Ernst</surname>
            <initial>R.</initial>
          </persName>
        </author>
      </analytic>
      <monogr>
        <title level="m">2012 Design, Automation &amp; Test in Europe Conference &amp; Exhibition, DATE 2012, Dresden, Germany, March, 2012</title>
        <imprint>
          <dateStruct>
            <year>2012</year>
          </dateStruct>
          <biblScope type="pages">515–520</biblScope>
          <ref xlink:href="http://dx.doi.org/10.1109/DATE.2012.6176523" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://<allowbreak/>dx.<allowbreak/>doi.<allowbreak/>org/<allowbreak/>10.<allowbreak/>1109/<allowbreak/>DATE.<allowbreak/>2012.<allowbreak/>6176523</ref>
        </imprint>
      </monogr>
    </biblStruct>
    
    <biblStruct id="spades-2018-bid62" type="article" rend="refer" n="refercite:SCP12">
      <analytic>
        <title level="a">Aspects preserving properties</title>
        <author>
          <persName>
            <foreName>Simplice</foreName>
            <surname>Djoko Djoko</surname>
            <initial>S.</initial>
          </persName>
          <persName key="gallinette-2018-idp159424">
            <foreName>Rémi</foreName>
            <surname>Douence</surname>
            <initial>R.</initial>
          </persName>
          <persName key="spades-2018-idp147520">
            <foreName>Pascal</foreName>
            <surname>Fradet</surname>
            <initial>P.</initial>
          </persName>
        </author>
      </analytic>
      <monogr>
        <title level="j">Science of Computer Programming</title>
        <imprint>
          <biblScope type="volume">77</biblScope>
          <biblScope type="number">3</biblScope>
          <dateStruct>
            <year>2012</year>
          </dateStruct>
          <biblScope type="pages">393-422</biblScope>
        </imprint>
      </monogr>
    </biblStruct>
    
    <biblStruct id="spades-2018-bid50" type="article" rend="year" n="cite:ernst:hal-01956964">
      <identifiant type="doi" value="10.4230/DagRep.8.2.122"/>
      <identifiant type="hal" value="hal-01956964"/>
      <analytic>
        <title level="a">The Logical Execution Time Paradigm: New Perspectives for Multicore Systems (Dagstuhl Seminar 18092)</title>
        <author>
          <persName>
            <foreName>Rolf</foreName>
            <surname>Ernst</surname>
            <initial>R.</initial>
          </persName>
          <persName>
            <foreName>Stefan</foreName>
            <surname>Kuntz</surname>
            <initial>S.</initial>
          </persName>
          <persName key="spades-2018-idp153232">
            <foreName>Sophie</foreName>
            <surname>Quinton</surname>
            <initial>S.</initial>
          </persName>
          <persName>
            <foreName>Martin</foreName>
            <surname>Simons</surname>
            <initial>M.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-scientific-popularization="no" x-editorial-board="yes" x-international-audience="yes" id="rid02206">
        <idno type="issn">2192-5283</idno>
        <title level="j">Dagstuhl Reports</title>
        <imprint>
          <biblScope type="volume">8</biblScope>
          <dateStruct>
            <year>2018</year>
          </dateStruct>
          <biblScope type="pages">122 - 149</biblScope>
          <ref xlink:href="https://hal.inria.fr/hal-01956964" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01956964</ref>
        </imprint>
      </monogr>
    </biblStruct>
    
    <biblStruct id="spades-2018-bid19" type="article" rend="year" n="cite:girault:hal-01956931">
      <identifiant type="doi" value="10.1109/TCAD.2018.2861016"/>
      <identifiant type="hal" value="hal-01956931"/>
      <analytic>
        <title level="a">Improving and Estimating the Precision of Bounds on the Worst-Case Latency of Task Chains</title>
        <author>
          <persName key="spades-2018-idp150368">
            <foreName>Alain</foreName>
            <surname>Girault</surname>
            <initial>A.</initial>
          </persName>
          <persName key="spades-2018-idp172912">
            <foreName>Christophe</foreName>
            <surname>Prévot</surname>
            <initial>C.</initial>
          </persName>
          <persName key="spades-2018-idp153232">
            <foreName>Sophie</foreName>
            <surname>Quinton</surname>
            <initial>S.</initial>
          </persName>
          <persName>
            <foreName>Rafik</foreName>
            <surname>Henia</surname>
            <initial>R.</initial>
          </persName>
          <persName>
            <foreName>Nicolas</foreName>
            <surname>Sordon</surname>
            <initial>N.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-scientific-popularization="no" x-editorial-board="yes" x-international-audience="yes" id="rid00719">
        <idno type="issn">0278-0070</idno>
        <title level="j">IEEE Transactions on Computer-Aided Design of Integrated Circuits and Systems</title>
        <imprint>
          <biblScope type="volume">37</biblScope>
          <biblScope type="number">11</biblScope>
          <dateStruct>
            <month>August</month>
            <year>2018</year>
          </dateStruct>
          <biblScope type="pages">2578-2589</biblScope>
          <ref xlink:href="https://hal.inria.fr/hal-01956931" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01956931</ref>
        </imprint>
      </monogr>
    </biblStruct>
    
    <biblStruct id="spades-2018-bid38" type="inproceedings" rend="year" n="cite:ahrendts:hal-01903759">
      <identifiant type="doi" value="10.4230/LIPIcs.ECRTS.2018.15"/>
      <identifiant type="hal" value="hal-01903759"/>
      <analytic>
        <title level="a">Verifying Weakly-Hard Real-Time Properties of Traffic Streams in Switched Networks</title>
        <author>
          <persName>
            <foreName>Leonie</foreName>
            <surname>Ahrendts</surname>
            <initial>L.</initial>
          </persName>
          <persName key="spades-2018-idp153232">
            <foreName>Sophie</foreName>
            <surname>Quinton</surname>
            <initial>S.</initial>
          </persName>
          <persName>
            <foreName>Thomas</foreName>
            <surname>Boroske</surname>
            <initial>T.</initial>
          </persName>
          <persName>
            <foreName>Rolf</foreName>
            <surname>Ernst</surname>
            <initial>R.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-scientific-popularization="no" x-international-audience="yes" x-proceedings="yes" x-invited-conference="no" x-editorial-board="yes">
        <title level="m">ECRTS 2018 - 30th Euromicro Conference on Real-Time Systems</title>
        <loc>Barcelona, Spain</loc>
        <imprint>
          <dateStruct>
            <month>July</month>
            <year>2018</year>
          </dateStruct>
          <biblScope type="pages">1-22</biblScope>
          <ref xlink:href="https://hal.inria.fr/hal-01903759" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01903759</ref>
        </imprint>
        <meeting id="cid64606">
          <title>Euromicro Conference on Real-Time Systems</title>
          <num>30</num>
          <abbr type="sigle">ECRTS</abbr>
        </meeting>
      </monogr>
    </biblStruct>
    
    <biblStruct id="spades-2018-bid56" type="inproceedings" rend="year" n="cite:cherrared:hal-01851610">
      <identifiant type="doi" value="10.1109/ICIN.2018.8401622"/>
      <identifiant type="hal" value="hal-01851610"/>
      <analytic>
        <title level="a">LUMEN: A Global Fault Management Framework For Network Virtualization Environments</title>
        <author>
          <persName key="sumo-2018-idp172768">
            <foreName>Sihem</foreName>
            <surname>Cherrared</surname>
            <initial>S.</initial>
          </persName>
          <persName>
            <foreName>Sofiane</foreName>
            <surname>Imadali</surname>
            <initial>S.</initial>
          </persName>
          <persName key="sumo-2018-idp150752">
            <foreName>Eric</foreName>
            <surname>Fabre</surname>
            <initial>E.</initial>
          </persName>
          <persName>
            <foreName>Gregor</foreName>
            <surname>Gössler</surname>
            <initial>G.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-scientific-popularization="no" x-international-audience="yes" x-proceedings="yes" x-invited-conference="no" x-editorial-board="yes">
        <title level="m">ICIN 2018 - 21st Conference on Innovation in Clouds, Internet and Networks and Workshops</title>
        <loc>Paris, France</loc>
        <imprint>
          <publisher>
            <orgName>IEEE</orgName>
          </publisher>
          <dateStruct>
            <month>February</month>
            <year>2018</year>
          </dateStruct>
          <biblScope type="pages">1-8</biblScope>
          <ref xlink:href="https://hal.inria.fr/hal-01851610" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01851610</ref>
        </imprint>
        <meeting id="cid625960">
          <title>Conference on Innovation in Clouds, Internet and Networks</title>
          <num>21</num>
          <abbr type="sigle">ICIN</abbr>
        </meeting>
      </monogr>
    </biblStruct>
    
    <biblStruct id="spades-2018-bid27" type="inproceedings" rend="year" n="cite:fradet:hal-01960788">
      <identifiant type="hal" value="hal-01960788"/>
      <analytic>
        <title level="a">RDF: Reconfigurable Dataflow</title>
        <author>
          <persName key="spades-2018-idp147520">
            <foreName>Pascal</foreName>
            <surname>Fradet</surname>
            <initial>P.</initial>
          </persName>
          <persName key="spades-2018-idp150368">
            <foreName>Alain</foreName>
            <surname>Girault</surname>
            <initial>A.</initial>
          </persName>
          <persName>
            <foreName>Ruby</foreName>
            <surname>Krishnaswamy</surname>
            <initial>R.</initial>
          </persName>
          <persName key="spades-2018-idp158176">
            <foreName>Xavier</foreName>
            <surname>Nicollin</surname>
            <initial>X.</initial>
          </persName>
          <persName key="spades-2018-idp175376">
            <foreName>Arash</foreName>
            <surname>Shafiei</surname>
            <initial>A.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-scientific-popularization="no" x-international-audience="yes" x-proceedings="yes" x-invited-conference="no" x-editorial-board="yes">
        <title level="m">2019 Design, Automation &amp; Test in Europe Conference &amp; Exhibition, DATE 2019</title>
        <loc>Florence, Italy</loc>
        <imprint>
          <dateStruct>
            <month>March</month>
            <year>2019</year>
          </dateStruct>
          <ref xlink:href="https://hal.inria.fr/hal-01960788" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01960788</ref>
        </imprint>
        <meeting id="cid58552">
          <title>Design, Automation, and Test in Europe</title>
          <num>22</num>
          <abbr type="sigle">DATE</abbr>
        </meeting>
      </monogr>
    </biblStruct>
    
    <biblStruct id="spades-2018-bid45" type="inproceedings" rend="year" n="cite:fradet:hal-01878100">
      <identifiant type="doi" value="10.1145/3273905.3273918"/>
      <identifiant type="hal" value="hal-01878100"/>
      <analytic>
        <title level="a">A Generalized Digraph Model for Expressing Dependencies</title>
        <author>
          <persName key="spades-2018-idp147520">
            <foreName>Pascal</foreName>
            <surname>Fradet</surname>
            <initial>P.</initial>
          </persName>
          <persName key="spades-2018-idp165600">
            <foreName>Xiaojie</foreName>
            <surname>Guo</surname>
            <initial>X.</initial>
          </persName>
          <persName>
            <foreName>Jean-François</foreName>
            <surname>Monin</surname>
            <initial>J.-F.</initial>
          </persName>
          <persName key="spades-2018-idp153232">
            <foreName>Sophie</foreName>
            <surname>Quinton</surname>
            <initial>S.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-scientific-popularization="no" x-international-audience="yes" x-proceedings="yes" x-invited-conference="no" x-editorial-board="yes">
        <title level="m">RTNS '18 - 26th International Conference on Real-Time Networks and Systems</title>
        <loc>Chasseneuil-du-Poitou, France</loc>
        <imprint>
          <dateStruct>
            <month>October</month>
            <year>2018</year>
          </dateStruct>
          <biblScope type="pages">1-11</biblScope>
          <ref xlink:href="https://hal.inria.fr/hal-01878100" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01878100</ref>
        </imprint>
        <meeting id="cid298234">
          <title>International Conference on Real-Time and Networks Systems</title>
          <num>26</num>
          <abbr type="sigle">RTNS</abbr>
        </meeting>
      </monogr>
    </biblStruct>
    
    <biblStruct id="spades-2018-bid48" type="inproceedings" rend="year" n="cite:fradet:hal-01903752">
      <identifiant type="hal" value="hal-01903752"/>
      <analytic>
        <title level="a">A Generic Coq Proof of Typical Worst-Case Analysis</title>
        <author>
          <persName key="spades-2018-idp147520">
            <foreName>Pascal</foreName>
            <surname>Fradet</surname>
            <initial>P.</initial>
          </persName>
          <persName key="spades-2018-idp168048">
            <foreName>Maxime</foreName>
            <surname>Lesourd</surname>
            <initial>M.</initial>
          </persName>
          <persName>
            <foreName>Jean-François</foreName>
            <surname>Monin</surname>
            <initial>J.-F.</initial>
          </persName>
          <persName key="spades-2018-idp153232">
            <foreName>Sophie</foreName>
            <surname>Quinton</surname>
            <initial>S.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-scientific-popularization="no" x-international-audience="yes" x-proceedings="yes" x-invited-conference="no" x-editorial-board="yes">
        <title level="m">RTSS 2018 - 39th IEEE Real-Time Systems Symposium</title>
        <loc>Nashville, United States</loc>
        <imprint>
          <dateStruct>
            <month>December</month>
            <year>2018</year>
          </dateStruct>
          <biblScope type="pages">1-12</biblScope>
          <ref xlink:href="https://hal.inria.fr/hal-01903752" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01903752</ref>
        </imprint>
        <meeting id="cid94684">
          <title>IEEE Symposium on Real-Time Systems</title>
          <num>39</num>
          <abbr type="sigle">RTSS</abbr>
        </meeting>
      </monogr>
    </biblStruct>
    
    <biblStruct id="spades-2018-bid30" type="inproceedings" rend="year" n="cite:girault:hal-01824817">
      <identifiant type="doi" value="10.1007/978-3-319-92612-4_3"/>
      <identifiant type="hal" value="hal-01824817"/>
      <analytic>
        <title level="a">Monotonic Prefix Consistency in Distributed Systems</title>
        <author>
          <persName key="spades-2018-idp150368">
            <foreName>Alain</foreName>
            <surname>Girault</surname>
            <initial>A.</initial>
          </persName>
          <persName>
            <foreName>Gregor</foreName>
            <surname>Gössler</surname>
            <initial>G.</initial>
          </persName>
          <persName>
            <foreName>Rachid</foreName>
            <surname>Guerraoui</surname>
            <initial>R.</initial>
          </persName>
          <persName>
            <foreName>Jad</foreName>
            <surname>Hamza</surname>
            <initial>J.</initial>
          </persName>
          <persName>
            <foreName>Dragos-Adrian</foreName>
            <surname>Seredinschi</surname>
            <initial>D.-A.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-scientific-popularization="no" x-international-audience="yes" x-proceedings="yes" x-invited-conference="no" x-editorial-board="yes">
        <editor role="editor">
          <persName>
            <foreName>Christel</foreName>
            <surname>Baier</surname>
            <initial>C.</initial>
          </persName>
          <persName>
            <foreName>Luís</foreName>
            <surname>Caires</surname>
            <initial>L.</initial>
          </persName>
        </editor>
        <title level="m">FORTE 2018 - 38th International Conference on Formal Techniques for Distributed Objects, Components, and Systems</title>
        <loc>Madrid, Spain</loc>
        <title level="s">Formal Techniques for Distributed Objects, Components, and Systems</title>
        <imprint>
          <biblScope type="volume">LNCS-10854</biblScope>
          <publisher>
            <orgName>Springer International Publishing</orgName>
          </publisher>
          <dateStruct>
            <month>June</month>
            <year>2018</year>
          </dateStruct>
          <biblScope type="pages">41-57</biblScope>
          <ref xlink:href="https://hal.inria.fr/hal-01824817" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01824817</ref>
        </imprint>
        <meeting id="cid282000">
          <title>International Conference on Formal Techniques for Networked and Distributed Systems</title>
          <num>38</num>
          <abbr type="sigle">FORTE</abbr>
        </meeting>
      </monogr>
    </biblStruct>
    
    <biblStruct id="spades-2018-bid18" type="inproceedings" rend="year" n="cite:graf:hal-01891146">
      <identifiant type="doi" value="10.1007/978-3-030-00244-2_2"/>
      <identifiant type="hal" value="hal-01891146"/>
      <analytic>
        <title level="a">Building Correct Cyber-Physical Systems: Why we need a Multiview Contract Theory</title>
        <author>
          <persName>
            <foreName>Susanne</foreName>
            <surname>Graf</surname>
            <initial>S.</initial>
          </persName>
          <persName key="spades-2018-idp153232">
            <foreName>Sophie</foreName>
            <surname>Quinton</surname>
            <initial>S.</initial>
          </persName>
          <persName key="spades-2018-idp150368">
            <foreName>Alain</foreName>
            <surname>Girault</surname>
            <initial>A.</initial>
          </persName>
          <persName>
            <foreName>Gregor</foreName>
            <surname>Gössler</surname>
            <initial>G.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-scientific-popularization="no" x-international-audience="yes" x-proceedings="yes" x-invited-conference="yes" x-editorial-board="yes">
        <title level="m">FMICS 2018 - 23rd International Conference on Formal Methods for Industrial Critical Systems</title>
        <loc>Dublin, Ireland</loc>
        <title level="s">LNCS</title>
        <imprint>
          <biblScope type="volume">11119</biblScope>
          <publisher>
            <orgName>Springer</orgName>
          </publisher>
          <dateStruct>
            <month>September</month>
            <year>2018</year>
          </dateStruct>
          <biblScope type="pages">19-31</biblScope>
          <ref xlink:href="https://hal.inria.fr/hal-01891146" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01891146</ref>
        </imprint>
        <meeting id="cid326189">
          <title>International Workshop on Formal Methods for Industrial Critical Systems</title>
          <num>23</num>
          <abbr type="sigle">FMICS</abbr>
        </meeting>
      </monogr>
    </biblStruct>
    
    <biblStruct id="spades-2018-bid57" type="inproceedings" rend="year" n="cite:quinton:hal-01903730">
      <identifiant type="doi" value="10.1007/978-3-030-00244-2_19"/>
      <identifiant type="hal" value="hal-01903730"/>
      <analytic>
        <title level="a">Evaluation and Comparison of Real-Time Systems Analysis Methods and Tools</title>
        <author>
          <persName key="spades-2018-idp153232">
            <foreName>Sophie</foreName>
            <surname>Quinton</surname>
            <initial>S.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-scientific-popularization="no" x-international-audience="yes" x-proceedings="yes" x-invited-conference="yes" x-editorial-board="yes">
        <title level="m">FMICS 2018 - 23rd International Conference on Formal Methods for Industrial Critical Systems</title>
        <loc>Maynooth, Ireland</loc>
        <title level="s">LNCS</title>
        <imprint>
          <biblScope type="volume">11119</biblScope>
          <publisher>
            <orgName>Springer</orgName>
          </publisher>
          <dateStruct>
            <month>September</month>
            <year>2018</year>
          </dateStruct>
          <biblScope type="pages">284-290</biblScope>
          <ref xlink:href="https://hal.inria.fr/hal-01903730" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01903730</ref>
        </imprint>
        <meeting id="cid326189">
          <title>International Workshop on Formal Methods for Industrial Critical Systems</title>
          <num>23</num>
          <abbr type="sigle">FMICS</abbr>
        </meeting>
      </monogr>
    </biblStruct>
    
    <biblStruct id="spades-2018-bid58" type="inproceedings" rend="year" n="cite:vassor:hal-01953756">
      <identifiant type="doi" value="10.1007/978-3-319-99498-7_20"/>
      <identifiant type="hal" value="hal-01953756"/>
      <analytic>
        <title level="a">Checkpoint/rollback vs causally-consistent reversibility</title>
        <author>
          <persName key="spades-2018-idp177808">
            <foreName>Martin</foreName>
            <surname>Vassor</surname>
            <initial>M.</initial>
          </persName>
          <persName key="spades-2018-idp155696">
            <foreName>Jean-Bernard</foreName>
            <surname>Stefani</surname>
            <initial>J.-B.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-scientific-popularization="no" x-international-audience="yes" x-proceedings="yes" x-invited-conference="no" x-editorial-board="yes">
        <title level="m">RC 2018 - 10th International Conference on Reversible Computation</title>
        <loc>Leicester, United Kingdom</loc>
        <title level="s">Lecture Notes in Computer Science</title>
        <imprint>
          <biblScope type="volume">11106</biblScope>
          <publisher>
            <orgName>Springer</orgName>
          </publisher>
          <dateStruct>
            <month>September</month>
            <year>2018</year>
          </dateStruct>
          <biblScope type="pages">286-303</biblScope>
          <ref xlink:href="https://hal.inria.fr/hal-01953756" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01953756</ref>
        </imprint>
        <meeting id="cid626057">
          <title>International Conference on Reversible Computation</title>
          <num>10</num>
          <abbr type="sigle">RC</abbr>
        </meeting>
      </monogr>
    </biblStruct>
    
    <biblStruct id="spades-2018-bid59" type="techreport" rend="year" n="cite:abdi:hal-01848087">
      <identifiant type="hal" value="hal-01848087"/>
      <monogr>
        <title level="m">ERPOT: A quad-criteria scheduling heuristic to optimize the execution time, failure rate, power consumption and temperature in multicores</title>
        <author>
          <persName>
            <foreName>Athena</foreName>
            <surname>Abdi</surname>
            <initial>A.</initial>
          </persName>
          <persName key="spades-2018-idp150368">
            <foreName>Alain</foreName>
            <surname>Girault</surname>
            <initial>A.</initial>
          </persName>
          <persName>
            <foreName>Hamid</foreName>
            <surname>Zarandi</surname>
            <initial>H.</initial>
          </persName>
        </author>
        <imprint>
          <biblScope type="number">RR-9196</biblScope>
          <publisher>
            <orgName type="institution">Inria ; 38</orgName>
          </publisher>
          <dateStruct>
            <month>July</month>
            <year>2018</year>
          </dateStruct>
          <biblScope type="pages">1-38</biblScope>
          <ref xlink:href="https://hal.inria.fr/hal-01848087" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01848087</ref>
        </imprint>
      </monogr>
      <note type="typdoc">Research Report</note>
    </biblStruct>
    
    <biblStruct id="spades-2018-bid51" type="techreport" rend="year" n="cite:ernst:hal-01962330">
      <identifiant type="hal" value="hal-01962330"/>
      <monogr>
        <title level="m">System Level LET with Application to Automotive Design</title>
        <author>
          <persName>
            <foreName>Rolf</foreName>
            <surname>Ernst</surname>
            <initial>R.</initial>
          </persName>
          <persName>
            <foreName>Leonie</foreName>
            <surname>Ahrendts</surname>
            <initial>L.</initial>
          </persName>
          <persName>
            <foreName>Kai-Björn</foreName>
            <surname>Gemlau</surname>
            <initial>K.-B.</initial>
          </persName>
          <persName key="spades-2018-idp153232">
            <foreName>Sophie</foreName>
            <surname>Quinton</surname>
            <initial>S.</initial>
          </persName>
          <persName>
            <foreName>Hermann</foreName>
            <surname>Von Hasseln</surname>
            <initial>H.</initial>
          </persName>
          <persName>
            <foreName>Julien</foreName>
            <surname>Hennig</surname>
            <initial>J.</initial>
          </persName>
        </author>
        <imprint>
          <publisher>
            <orgName type="institution">TU Braunschweig</orgName>
          </publisher>
          <dateStruct>
            <year>2018</year>
          </dateStruct>
          <biblScope type="pages">1-11</biblScope>
          <ref xlink:href="https://hal.inria.fr/hal-01962330" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01962330</ref>
        </imprint>
      </monogr>
      <note type="typdoc">Research Report</note>
    </biblStruct>
    
    <biblStruct id="spades-2018-bid34" type="inproceedings" rend="foot" n="footcite:AndalamRG10b">
      <analytic>
        <title level="a">Predictable Multithreading of Embedded Applications Using PRET-C</title>
        <author>
          <persName>
            <foreName>S.</foreName>
            <surname>Andalam</surname>
            <initial>S.</initial>
          </persName>
          <persName>
            <foreName>Partha</foreName>
            <surname>Roop</surname>
            <initial>P.</initial>
          </persName>
          <persName key="spades-2018-idp150368">
            <foreName>Alain</foreName>
            <surname>Girault</surname>
            <initial>A.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-international-audience="yes" x-editorial-board="yes">
        <title level="m">International Conference on Formal Methods and Models for Codesign, MEMOCODE'10</title>
        <loc>Grenoble, France</loc>
        <imprint>
          <publisher>
            <orgName>IEEE</orgName>
          </publisher>
          <dateStruct>
            <month>July</month>
            <year>2010</year>
          </dateStruct>
          <biblScope type="pages">159–168</biblScope>
        </imprint>
      </monogr>
    </biblStruct>
    
    <biblStruct id="spades-2018-bid52" type="inproceedings" rend="foot" n="footcite:assayad:hal-01672463">
      <identifiant type="hal" value="hal-01672463"/>
      <analytic>
        <title level="a">Adaptive Mapping for Multiple Applications on Parallel Architectures</title>
        <author>
          <persName key="spades-2018-idp187664">
            <foreName>Ismail</foreName>
            <surname>Assayad</surname>
            <initial>I.</initial>
          </persName>
          <persName key="spades-2018-idp150368">
            <foreName>Alain</foreName>
            <surname>Girault</surname>
            <initial>A.</initial>
          </persName>
        </author>
      </analytic>
      <monogr>
        <title level="m">Third International Symposium on Ubiquitous Networking, UNET'17</title>
        <loc>Casablanca, Morocco</loc>
        <imprint>
          <dateStruct>
            <month>May</month>
            <year>2017</year>
          </dateStruct>
          <ref xlink:href="https://hal.inria.fr/hal-01672463" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01672463</ref>
        </imprint>
      </monogr>
    </biblStruct>
    
    <biblStruct id="spades-2018-bid4" type="misc" rend="foot" n="footcite:Autosar">
      <monogr>
        <title level="m">Automotive Open System Architecture</title>
        <imprint>
          <dateStruct>
            <year>2003</year>
          </dateStruct>
          <ref xlink:href="http://www.autosar.org" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://<allowbreak/>www.<allowbreak/>autosar.<allowbreak/>org</ref>
        </imprint>
      </monogr>
    </biblStruct>
    
    <biblStruct id="spades-2018-bid33" type="article" rend="foot" n="footcite:Axer14">
      <analytic>
        <title level="a">Building Timing Predictable Embedded Systems</title>
        <author>
          <persName>
            <foreName>P.</foreName>
            <surname>Axer</surname>
            <initial>P.</initial>
          </persName>
          <persName>
            <foreName>R.</foreName>
            <surname>Ernst</surname>
            <initial>R.</initial>
          </persName>
          <persName>
            <foreName>H.</foreName>
            <surname>Falk</surname>
            <initial>H.</initial>
          </persName>
          <persName key="spades-2018-idp150368">
            <foreName>A.</foreName>
            <surname>Girault</surname>
            <initial>A.</initial>
          </persName>
          <persName>
            <foreName>D.</foreName>
            <surname>Grund</surname>
            <initial>D.</initial>
          </persName>
          <persName>
            <foreName>N.</foreName>
            <surname>Guan</surname>
            <initial>N.</initial>
          </persName>
          <persName>
            <foreName>B.</foreName>
            <surname>Jonsson</surname>
            <initial>B.</initial>
          </persName>
          <persName>
            <foreName>P.</foreName>
            <surname>Marwedel</surname>
            <initial>P.</initial>
          </persName>
          <persName>
            <foreName>J.</foreName>
            <surname>Reineke</surname>
            <initial>J.</initial>
          </persName>
          <persName>
            <foreName>C.</foreName>
            <surname>Rochange</surname>
            <initial>C.</initial>
          </persName>
          <persName>
            <foreName>M.</foreName>
            <surname>Sebatian</surname>
            <initial>M.</initial>
          </persName>
          <persName>
            <foreName>R.</foreName>
            <surname>von Hanxleden</surname>
            <initial>R.</initial>
          </persName>
          <persName>
            <foreName>R.</foreName>
            <surname>Wilhelm</surname>
            <initial>R.</initial>
          </persName>
          <persName>
            <foreName>W.</foreName>
            <surname>Yi</surname>
            <initial>W.</initial>
          </persName>
        </author>
      </analytic>
      <monogr>
        <title level="j">ACM Trans. Embedd. Comput. Syst.</title>
        <imprint>
          <dateStruct>
            <year>2014</year>
          </dateStruct>
        </imprint>
      </monogr>
      <note type="bnote">To appear</note>
    </biblStruct>
    
    <biblStruct id="spades-2018-bid6" type="article" rend="foot" n="footcite:BainomugishaCVCMDM13">
      <analytic>
        <title level="a">A Survey on Reactive Programming</title>
        <author>
          <persName>
            <foreName>E.</foreName>
            <surname>Bainomugisha</surname>
            <initial>E.</initial>
          </persName>
          <persName>
            <foreName>A.L.</foreName>
            <surname>Carreton</surname>
            <initial>A.</initial>
          </persName>
          <persName>
            <foreName>T.</foreName>
            <surname>Van Cutsem</surname>
            <initial>T.</initial>
          </persName>
          <persName>
            <foreName>S.</foreName>
            <surname>Mostinckx</surname>
            <initial>S.</initial>
          </persName>
          <persName>
            <foreName>W.</foreName>
            <surname>De Meuter</surname>
            <initial>W.</initial>
          </persName>
        </author>
      </analytic>
      <monogr>
        <title level="j">ACM Computing Surveys</title>
        <imprint>
          <biblScope type="volume">45</biblScope>
          <biblScope type="number">4</biblScope>
          <dateStruct>
            <year>2013</year>
          </dateStruct>
        </imprint>
      </monogr>
    </biblStruct>
    
    <biblStruct id="spades-2018-bid43" type="article" rend="foot" n="footcite:bansal07">
      <analytic>
        <title level="a">Speed Scaling to Manage Energy and Temperature</title>
        <author>
          <persName>
            <foreName>Nikhil</foreName>
            <surname>Bansal</surname>
            <initial>N.</initial>
          </persName>
          <persName>
            <foreName>Tracy</foreName>
            <surname>Kimbrel</surname>
            <initial>T.</initial>
          </persName>
          <persName>
            <foreName>Kirk</foreName>
            <surname>Pruhs</surname>
            <initial>K.</initial>
          </persName>
        </author>
      </analytic>
      <monogr>
        <title level="j">Journal of the ACM</title>
        <imprint>
          <biblScope type="volume">54</biblScope>
          <biblScope type="number">1</biblScope>
          <dateStruct>
            <year>2007</year>
          </dateStruct>
        </imprint>
      </monogr>
    </biblStruct>
    
    <biblStruct id="spades-2018-bid3" type="article" rend="foot" n="footcite:BasuBBCJNS11">
      <analytic>
        <title level="a">Rigorous Component-Based System Design Using the BIP Framework</title>
        <author>
          <persName>
            <foreName>A.</foreName>
            <surname>Basu</surname>
            <initial>A.</initial>
          </persName>
          <persName>
            <foreName>S.</foreName>
            <surname>Bensalem</surname>
            <initial>S.</initial>
          </persName>
          <persName>
            <foreName>M.</foreName>
            <surname>Bozga</surname>
            <initial>M.</initial>
          </persName>
          <persName>
            <foreName>J.</foreName>
            <surname>Combaz</surname>
            <initial>J.</initial>
          </persName>
          <persName>
            <foreName>M.</foreName>
            <surname>Jaber</surname>
            <initial>M.</initial>
          </persName>
          <persName>
            <foreName>T.-H.</foreName>
            <surname>Nguyen</surname>
            <initial>T.-H.</initial>
          </persName>
          <persName>
            <foreName>J.</foreName>
            <surname>Sifakis</surname>
            <initial>J.</initial>
          </persName>
        </author>
      </analytic>
      <monogr>
        <title level="j">IEEE Software</title>
        <imprint>
          <biblScope type="volume">28</biblScope>
          <biblScope type="number">3</biblScope>
          <dateStruct>
            <year>2011</year>
          </dateStruct>
        </imprint>
      </monogr>
    </biblStruct>
    
    <biblStruct id="spades-2018-bid23" type="inproceedings" rend="foot" n="footcite:BPDF">
      <analytic>
        <title level="a">BPDF: A Statically Analyzable Dataflow Model with Integer and Boolean Parameters</title>
        <author>
          <persName>
            <foreName>V.</foreName>
            <surname>Bebelis</surname>
            <initial>V.</initial>
          </persName>
          <persName key="spades-2018-idp147520">
            <foreName>P.</foreName>
            <surname>Fradet</surname>
            <initial>P.</initial>
          </persName>
          <persName key="spades-2018-idp150368">
            <foreName>A.</foreName>
            <surname>Girault</surname>
            <initial>A.</initial>
          </persName>
          <persName>
            <foreName>B.</foreName>
            <surname>Lavigueur</surname>
            <initial>B.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-international-audience="yes" x-editorial-board="yes">
        <title level="m">International Conference on Embedded Software, EMSOFT'13</title>
        <loc>Montreal, Canada</loc>
        <imprint>
          <publisher>
            <orgName>ACM</orgName>
          </publisher>
          <dateStruct>
            <month>September</month>
            <year>2013</year>
          </dateStruct>
        </imprint>
      </monogr>
    </biblStruct>
    
    <biblStruct id="spades-2018-bid5" type="article" rend="foot" n="footcite:BenvenisteCEHGS03">
      <analytic>
        <title level="a">The synchronous languages 12 years later</title>
        <author>
          <persName key="hycomes-2018-idp130624">
            <foreName>Albert</foreName>
            <surname>Benveniste</surname>
            <initial>A.</initial>
          </persName>
          <persName>
            <foreName>Paul</foreName>
            <surname>Caspi</surname>
            <initial>P.</initial>
          </persName>
          <persName>
            <foreName>Stephen A.</foreName>
            <surname>Edwards</surname>
            <initial>S. A.</initial>
          </persName>
          <persName>
            <foreName>Nicolas</foreName>
            <surname>Halbwachs</surname>
            <initial>N.</initial>
          </persName>
          <persName>
            <foreName>Paul</foreName>
            <surname>Le Guernic</surname>
            <initial>P.</initial>
          </persName>
          <persName key="kairos-2018-idp113904">
            <foreName>Robert</foreName>
            <surname>de Simone</surname>
            <initial>R.</initial>
          </persName>
        </author>
      </analytic>
      <monogr>
        <title level="j">Proceedings of the IEEE</title>
        <imprint>
          <biblScope type="volume">91</biblScope>
          <biblScope type="number">1</biblScope>
          <dateStruct>
            <year>2003</year>
          </dateStruct>
        </imprint>
      </monogr>
    </biblStruct>
    
    <biblStruct id="spades-2018-bid8" type="article" rend="foot" n="footcite:Borkar05">
      <analytic>
        <title level="a">Designing Reliable Systems from Unreliable Components: The Challenges of Transistor Variability and Degradation</title>
        <author>
          <persName>
            <foreName>S.</foreName>
            <surname>Borkar</surname>
            <initial>S.</initial>
          </persName>
        </author>
      </analytic>
      <monogr>
        <title level="j">IEEE Micro</title>
        <imprint>
          <biblScope type="volume">25</biblScope>
          <biblScope type="number">6</biblScope>
          <dateStruct>
            <year>2005</year>
          </dateStruct>
        </imprint>
      </monogr>
    </biblStruct>
    
    <biblStruct id="spades-2018-bid24" type="article" rend="foot" n="footcite:Survey2017">
      <identifiant type="hal" value="hal-01417126"/>
      <analytic>
        <title level="a">A Survey of Parametric Dataflow Models of Computation</title>
        <author>
          <persName>
            <foreName>Adnan</foreName>
            <surname>Bouakaz</surname>
            <initial>A.</initial>
          </persName>
          <persName key="spades-2018-idp147520">
            <foreName>Pascal</foreName>
            <surname>Fradet</surname>
            <initial>P.</initial>
          </persName>
          <persName key="spades-2018-idp150368">
            <foreName>Alain</foreName>
            <surname>Girault</surname>
            <initial>A.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-scientific-popularization="no" x-editorial-board="yes" x-international-audience="yes">
        <title level="j">ACM Transactions on Design Automation of Electronic Systems (TODAES)</title>
        <imprint>
          <dateStruct>
            <month>January</month>
            <year>2017</year>
          </dateStruct>
          <ref xlink:href="https://hal.inria.fr/hal-01417126" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01417126</ref>
        </imprint>
      </monogr>
    </biblStruct>
    
    <biblStruct id="spades-2018-bid25" type="article" rend="foot" n="footcite:SymbAna">
      <identifiant type="hal" value="hal-01417146"/>
      <analytic>
        <title level="a">Symbolic Analyses of Dataflow Graphs</title>
        <author>
          <persName>
            <foreName>Adnan</foreName>
            <surname>Bouakaz</surname>
            <initial>A.</initial>
          </persName>
          <persName key="spades-2018-idp147520">
            <foreName>Pascal</foreName>
            <surname>Fradet</surname>
            <initial>P.</initial>
          </persName>
          <persName key="spades-2018-idp150368">
            <foreName>Alain</foreName>
            <surname>Girault</surname>
            <initial>A.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-scientific-popularization="no" x-editorial-board="yes" x-international-audience="yes">
        <title level="j">ACM Transactions on Design Automation of Electronic Systems (TODAES)</title>
        <imprint>
          <dateStruct>
            <month>January</month>
            <year>2017</year>
          </dateStruct>
          <ref xlink:href="https://hal.inria.fr/hal-01417146" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01417146</ref>
        </imprint>
      </monogr>
    </biblStruct>
    
    <biblStruct id="spades-2018-bid7" type="article" rend="foot" n="footcite:DavisB11">
      <analytic>
        <title level="a">A Survey of Hard Real-Time Scheduling for Multiprocessor Systems</title>
        <author>
          <persName key="aoste2-2018-idp152784">
            <foreName>Rob</foreName>
            <surname>Davis</surname>
            <initial>R.</initial>
          </persName>
          <persName>
            <foreName>Alan</foreName>
            <surname>Burns</surname>
            <initial>A.</initial>
          </persName>
        </author>
      </analytic>
      <monogr>
        <title level="j">ACM Computing Surveys</title>
        <imprint>
          <biblScope type="volume">43</biblScope>
          <biblScope type="number">4</biblScope>
          <dateStruct>
            <year>2011</year>
          </dateStruct>
        </imprint>
      </monogr>
    </biblStruct>
    
    <biblStruct id="spades-2018-bid31" type="inproceedings" rend="foot" n="footcite:EdwardsL07">
      <analytic>
        <title level="a">The Case for the Precision Timed (PRET) Machine</title>
        <author>
          <persName>
            <foreName>S. A.</foreName>
            <surname>Edwards</surname>
            <initial>S. A.</initial>
          </persName>
          <persName>
            <foreName>E. A.</foreName>
            <surname>Lee</surname>
            <initial>E. A.</initial>
          </persName>
        </author>
      </analytic>
      <monogr>
        <title level="m">44th Design Automation Conference (DAC)</title>
        <imprint>
          <publisher>
            <orgName>IEEE</orgName>
          </publisher>
          <dateStruct>
            <year>2007</year>
          </dateStruct>
        </imprint>
      </monogr>
    </biblStruct>
    
    <biblStruct id="spades-2018-bid2" type="article" rend="foot" n="footcite:EkerJLLLLNSX03">
      <analytic>
        <title level="a">Taming heterogeneity - the Ptolemy approach</title>
        <author>
          <persName>
            <foreName>J.</foreName>
            <surname>Eker</surname>
            <initial>J.</initial>
          </persName>
          <persName>
            <foreName>J. W.</foreName>
            <surname>Janneck</surname>
            <initial>J. W.</initial>
          </persName>
          <persName>
            <foreName>E. A.</foreName>
            <surname>Lee</surname>
            <initial>E. A.</initial>
          </persName>
          <persName key="larsen-2018-idp208224">
            <foreName>J.</foreName>
            <surname>Liu</surname>
            <initial>J.</initial>
          </persName>
          <persName key="defi-2018-idp162592">
            <foreName>X.</foreName>
            <surname>Liu</surname>
            <initial>X.</initial>
          </persName>
          <persName>
            <foreName>J.</foreName>
            <surname>Ludvig</surname>
            <initial>J.</initial>
          </persName>
          <persName>
            <foreName>S.</foreName>
            <surname>Neuendorffer</surname>
            <initial>S.</initial>
          </persName>
          <persName>
            <foreName>S.</foreName>
            <surname>Sachs</surname>
            <initial>S.</initial>
          </persName>
          <persName>
            <foreName>Y.</foreName>
            <surname>Xiong</surname>
            <initial>Y.</initial>
          </persName>
        </author>
      </analytic>
      <monogr>
        <title level="j">Proceedings of the IEEE</title>
        <imprint>
          <biblScope type="volume">91</biblScope>
          <biblScope type="number">1</biblScope>
          <dateStruct>
            <year>2003</year>
          </dateStruct>
        </imprint>
      </monogr>
    </biblStruct>
    
    <biblStruct id="spades-2018-bid26" type="inproceedings" rend="foot" n="footcite:LossySDF">
      <identifiant type="hal" value="hal-01666568"/>
      <analytic>
        <title level="a">Lossy channels in a dataflow model of computation</title>
        <author>
          <persName key="spades-2018-idp147520">
            <foreName>Pascal</foreName>
            <surname>Fradet</surname>
            <initial>P.</initial>
          </persName>
          <persName key="spades-2018-idp150368">
            <foreName>Alain</foreName>
            <surname>Girault</surname>
            <initial>A.</initial>
          </persName>
          <persName>
            <foreName>Leila</foreName>
            <surname>Jamshidian</surname>
            <initial>L.</initial>
          </persName>
          <persName key="spades-2018-idp158176">
            <foreName>Xavier</foreName>
            <surname>Nicollin</surname>
            <initial>X.</initial>
          </persName>
          <persName key="spades-2018-idp175376">
            <foreName>Arash</foreName>
            <surname>Shafiei</surname>
            <initial>A.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-scientific-popularization="no" x-international-audience="yes" x-proceedings="yes" x-invited-conference="yes" x-editorial-board="yes">
        <title level="m">Principles of Modeling, Festschrift in Honor of Edward A. Lee</title>
        <loc>Berkeley, United States</loc>
        <imprint>
          <publisher>
            <orgName>Lecture Notes in Computer Science, Springer</orgName>
          </publisher>
          <dateStruct>
            <month>October</month>
            <year>2017</year>
          </dateStruct>
          <ref xlink:href="https://hal.inria.fr/hal-01666568" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01666568</ref>
        </imprint>
      </monogr>
    </biblStruct>
    
    <biblStruct id="spades-2018-bid22" type="inproceedings" rend="foot" n="footcite:SPDF">
      <analytic>
        <title level="a">SPDF: A schedulable parametric data-flow MoC</title>
        <author>
          <persName key="spades-2018-idp147520">
            <foreName>P.</foreName>
            <surname>Fradet</surname>
            <initial>P.</initial>
          </persName>
          <persName key="spades-2018-idp150368">
            <foreName>A.</foreName>
            <surname>Girault</surname>
            <initial>A.</initial>
          </persName>
          <persName>
            <foreName>P.</foreName>
            <surname>Polpavko</surname>
            <initial>P.</initial>
          </persName>
        </author>
      </analytic>
      <monogr>
        <title level="m">Design, Automation and Test in Europe, DATE'12</title>
        <imprint>
          <publisher>
            <orgName>IEEE</orgName>
          </publisher>
          <dateStruct>
            <year>2012</year>
          </dateStruct>
        </imprint>
      </monogr>
    </biblStruct>
    
    <biblStruct id="spades-2018-bid55" type="inproceedings" rend="foot" n="footcite:GoesslerStefani2015">
      <analytic>
        <title level="a">Fault Ascription in Concurrent Systems</title>
        <author>
          <persName>
            <foreName>G.</foreName>
            <surname>Gössler</surname>
            <initial>G.</initial>
          </persName>
          <persName>
            <foreName>J.-B.</foreName>
            <surname>Stefani</surname>
            <initial>J.-B.</initial>
          </persName>
        </author>
      </analytic>
      <monogr>
        <editor role="editor">
          <persName>
            <foreName>P.</foreName>
            <surname>Ganty</surname>
            <initial>P.</initial>
          </persName>
          <persName>
            <foreName>M.</foreName>
            <surname>Loreti</surname>
            <initial>M.</initial>
          </persName>
        </editor>
        <title level="m">Proc. Trustworthy Global Computing - 10th International Symposium, TGC 2015</title>
        <title level="s">LNCS</title>
        <imprint>
          <biblScope type="volume">9533</biblScope>
          <publisher>
            <orgName>Springer</orgName>
          </publisher>
          <dateStruct>
            <year>2016</year>
          </dateStruct>
        </imprint>
      </monogr>
    </biblStruct>
    
    <biblStruct id="spades-2018-bid42" type="techreport" rend="foot" n="footcite:gaujal:hal-01615835">
      <identifiant type="hal" value="hal-01615835"/>
      <monogr>
        <title level="m">Dynamic Speed Scaling Minimizing Expected Energy Consumption for Real-Time Tasks</title>
        <author>
          <persName key="polaris-2018-idp126368">
            <foreName>Bruno</foreName>
            <surname>Gaujal</surname>
            <initial>B.</initial>
          </persName>
          <persName key="spades-2018-idp150368">
            <foreName>Alain</foreName>
            <surname>Girault</surname>
            <initial>A.</initial>
          </persName>
          <persName key="polaris-2018-idp188912">
            <foreName>Stéphan</foreName>
            <surname>Plassart</surname>
            <initial>S.</initial>
          </persName>
        </author>
        <imprint>
          <biblScope type="number">RR-9101</biblScope>
          <publisher>
            <orgName type="institution">UGA - Université Grenoble Alpes ; Inria Grenoble Rhône-Alpes ; Université de Grenoble</orgName>
          </publisher>
          <dateStruct>
            <month>October</month>
            <year>2017</year>
          </dateStruct>
          <biblScope type="pages">1-35</biblScope>
          <ref xlink:href="https://hal.inria.fr/hal-01615835" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01615835</ref>
        </imprint>
      </monogr>
      <note type="typdoc">Research Report</note>
    </biblStruct>
    
    <biblStruct id="spades-2018-bid40" type="article" rend="foot" n="footcite:girard2007">
      <analytic>
        <title level="a">Approximation metrics for discrete and continuous systems</title>
        <author>
          <persName>
            <foreName>Antoine</foreName>
            <surname>Girard</surname>
            <initial>A.</initial>
          </persName>
          <persName>
            <foreName>G.J.</foreName>
            <surname>Pappas</surname>
            <initial>G.</initial>
          </persName>
        </author>
      </analytic>
      <monogr>
        <title level="j">IEEE Trans. on Automatic Control</title>
        <imprint>
          <biblScope type="volume">52</biblScope>
          <biblScope type="number">5</biblScope>
          <dateStruct>
            <year>2007</year>
          </dateStruct>
          <biblScope type="pages">782–798</biblScope>
        </imprint>
      </monogr>
    </biblStruct>
    
    <biblStruct id="spades-2018-bid9" type="inproceedings" rend="foot" n="footcite:GizopoulosPARHSMBV11">
      <analytic>
        <title level="a">Architectures for Online Error Detection and Recovery in Multicore Processors</title>
        <author>
          <persName>
            <foreName>D.</foreName>
            <surname>Gizopoulos</surname>
            <initial>D.</initial>
          </persName>
          <persName>
            <foreName>M.</foreName>
            <surname>Psarakis</surname>
            <initial>M.</initial>
          </persName>
          <persName>
            <foreName>S. V.</foreName>
            <surname>Adve</surname>
            <initial>S. V.</initial>
          </persName>
          <persName>
            <foreName>P.</foreName>
            <surname>Ramachandran</surname>
            <initial>P.</initial>
          </persName>
          <persName>
            <foreName>S. K. S.</foreName>
            <surname>Hari</surname>
            <initial>S. K. S.</initial>
          </persName>
          <persName>
            <foreName>D.</foreName>
            <surname>Sorin</surname>
            <initial>D.</initial>
          </persName>
          <persName>
            <foreName>A.</foreName>
            <surname>Meixner</surname>
            <initial>A.</initial>
          </persName>
          <persName>
            <foreName>A.</foreName>
            <surname>Biswas</surname>
            <initial>A.</initial>
          </persName>
          <persName>
            <foreName>X.</foreName>
            <surname>Vera</surname>
            <initial>X.</initial>
          </persName>
        </author>
      </analytic>
      <monogr>
        <title level="m">Design Automation and Test in Europe (DATE)</title>
        <imprint>
          <dateStruct>
            <year>2011</year>
          </dateStruct>
        </imprint>
      </monogr>
    </biblStruct>
    
    <biblStruct id="spades-2018-bid29" type="article" rend="foot" n="footcite:guerraoui2016">
      <analytic>
        <title level="a">Trade-offs in replicated systems</title>
        <author>
          <persName>
            <foreName>Rachid</foreName>
            <surname>Guerraoui</surname>
            <initial>R.</initial>
          </persName>
          <persName>
            <foreName>Matej</foreName>
            <surname>Pavlovic</surname>
            <initial>M.</initial>
          </persName>
          <persName>
            <foreName>Dragos-Adrian</foreName>
            <surname>Seredinschi</surname>
            <initial>D.-A.</initial>
          </persName>
        </author>
      </analytic>
      <monogr>
        <title level="j">IEEE Data Engineering Bulletin</title>
        <imprint>
          <biblScope type="volume">39</biblScope>
          <dateStruct>
            <year>2016</year>
          </dateStruct>
          <biblScope type="pages">14–26</biblScope>
        </imprint>
      </monogr>
    </biblStruct>
    
    <biblStruct id="spades-2018-bid16" type="article" rend="foot" n="footcite:Gartner99CS">
      <analytic>
        <title level="a">Fundamentals of Fault-Tolerant Distributed Computing in Asynchronous Environments</title>
        <author>
          <persName>
            <foreName>F. C.</foreName>
            <surname>Gärtner</surname>
            <initial>F. C.</initial>
          </persName>
        </author>
      </analytic>
      <monogr>
        <title level="j">ACM Computing Surveys</title>
        <imprint>
          <biblScope type="volume">31</biblScope>
          <biblScope type="number">1</biblScope>
          <dateStruct>
            <year>1999</year>
          </dateStruct>
        </imprint>
      </monogr>
    </biblStruct>
    
    <biblStruct id="spades-2018-bid14" type="incollection" rend="foot" n="footcite:HaarF13">
      <analytic>
        <title level="a">Diagnosis with Petri Net Unfoldings</title>
        <author>
          <persName key="mexico-2018-idp118672">
            <foreName>S.</foreName>
            <surname>Haar</surname>
            <initial>S.</initial>
          </persName>
          <persName key="sumo-2018-idp150752">
            <foreName>E.</foreName>
            <surname>Fabre</surname>
            <initial>E.</initial>
          </persName>
        </author>
      </analytic>
      <monogr>
        <title level="m">Control of Discrete-Event Systems</title>
        <title level="s">Lecture Notes in Control and Information Sciences</title>
        <imprint>
          <biblScope type="volume">433</biblScope>
          <biblScope type="chapter">15</biblScope>
          <publisher>
            <orgName>Springer</orgName>
          </publisher>
          <dateStruct>
            <year>2013</year>
          </dateStruct>
        </imprint>
      </monogr>
    </biblStruct>
    
    <biblStruct id="spades-2018-bid53" type="article" rend="foot" n="footcite:HalpernPearl2005">
      <analytic>
        <title level="a">Causes and Explanations: A Structural-Model Approach. Part I: Causes</title>
        <author>
          <persName>
            <foreName>J.Y.</foreName>
            <surname>Halpern</surname>
            <initial>J.</initial>
          </persName>
          <persName>
            <foreName>J.</foreName>
            <surname>Pearl</surname>
            <initial>J.</initial>
          </persName>
        </author>
      </analytic>
      <monogr>
        <title level="j">British Journal for the Philosophy of Science</title>
        <imprint>
          <biblScope type="volume">56</biblScope>
          <biblScope type="number">4</biblScope>
          <dateStruct>
            <year>2005</year>
          </dateStruct>
          <biblScope type="pages">843-887</biblScope>
        </imprint>
      </monogr>
    </biblStruct>
    
    <biblStruct id="spades-2018-bid1" type="inproceedings" rend="foot" n="footcite:HenzigerS06">
      <analytic>
        <title level="a">The Embedded Systems Design Challenge</title>
        <author>
          <persName>
            <foreName>T.A.</foreName>
            <surname>Henzinger</surname>
            <initial>T.</initial>
          </persName>
          <persName>
            <foreName>J.</foreName>
            <surname>Sifakis</surname>
            <initial>J.</initial>
          </persName>
        </author>
      </analytic>
      <monogr>
        <title level="m">Formal Methods 2006</title>
        <title level="s">Lecture Notes in Computer Science</title>
        <imprint>
          <biblScope type="volume">4085</biblScope>
          <publisher>
            <orgName>Springer</orgName>
          </publisher>
          <dateStruct>
            <year>2006</year>
          </dateStruct>
        </imprint>
      </monogr>
    </biblStruct>
    
    <biblStruct id="spades-2018-bid49" type="inproceedings" rend="foot" n="footcite:KirschS12">
      <analytic>
        <title level="a">The Logical Execution Time Paradigm</title>
        <author>
          <persName>
            <foreName>Christoph M.</foreName>
            <surname>Kirsch</surname>
            <initial>C. M.</initial>
          </persName>
          <persName>
            <foreName>Ana</foreName>
            <surname>Sokolova</surname>
            <initial>A.</initial>
          </persName>
        </author>
      </analytic>
      <monogr>
        <title level="m">Advances in Real-Time Systems (to Georg Färber on the occasion of his appointment as Professor Emeritus at TU München after leading the Lehrstuhl für Realzeit-Computersysteme for 34 illustrious years)</title>
        <imprint>
          <dateStruct>
            <year>2012</year>
          </dateStruct>
          <biblScope type="pages">103–120</biblScope>
        </imprint>
      </monogr>
    </biblStruct>
    
    <biblStruct id="spades-2018-bid15" type="inproceedings" rend="foot" n="footcite:KustersTV10">
      <analytic>
        <title level="a">Accountability: definition and relationship to verifiability</title>
        <author>
          <persName>
            <foreName>R.</foreName>
            <surname>Küsters</surname>
            <initial>R.</initial>
          </persName>
          <persName>
            <foreName>T.</foreName>
            <surname>Truderung</surname>
            <initial>T.</initial>
          </persName>
          <persName>
            <foreName>A.</foreName>
            <surname>Vogt</surname>
            <initial>A.</initial>
          </persName>
        </author>
      </analytic>
      <monogr>
        <title level="m">ACM Conference on Computer and Communications Security</title>
        <imprint>
          <dateStruct>
            <year>2010</year>
          </dateStruct>
          <biblScope type="pages">526-535</biblScope>
        </imprint>
      </monogr>
    </biblStruct>
    
    <biblStruct id="spades-2018-bid13" type="inproceedings" rend="foot" n="footcite:LaneseMS10">
      <analytic>
        <title level="a">Reversing Higher-Order Pi</title>
        <author>
          <persName key="focus-2018-idp151632">
            <foreName>I.</foreName>
            <surname>Lanese</surname>
            <initial>I.</initial>
          </persName>
          <persName>
            <foreName>C. A.</foreName>
            <surname>Mezzina</surname>
            <initial>C. A.</initial>
          </persName>
          <persName>
            <foreName>J.-B.</foreName>
            <surname>Stefani</surname>
            <initial>J.-B.</initial>
          </persName>
        </author>
      </analytic>
      <monogr>
        <title level="m">21th International Conference on Concurrency Theory (CONCUR)</title>
        <title level="s">Lecture Notes in Computer Science</title>
        <imprint>
          <biblScope type="volume">6269</biblScope>
          <publisher>
            <orgName>Springer</orgName>
          </publisher>
          <dateStruct>
            <year>2010</year>
          </dateStruct>
        </imprint>
      </monogr>
    </biblStruct>
    
    <biblStruct id="spades-2018-bid10" type="incollection" rend="foot" n="footcite:Menzies09">
      <analytic>
        <title level="a">Counterfactual Theories of Causation</title>
        <author>
          <persName>
            <foreName>P.</foreName>
            <surname>Menzies</surname>
            <initial>P.</initial>
          </persName>
        </author>
      </analytic>
      <monogr>
        <editor role="editor">
          <persName>
            <foreName>E.N.</foreName>
            <surname>Zalta</surname>
            <initial>E.</initial>
          </persName>
        </editor>
        <title level="m">Stanford Encyclopedia of Philosophy</title>
        <imprint>
          <publisher>
            <orgName>Stanford University</orgName>
          </publisher>
          <dateStruct>
            <year>2009</year>
          </dateStruct>
          <ref xlink:href="http://plato.stanford.edu/entries/causation-counterfactual" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://<allowbreak/>plato.<allowbreak/>stanford.<allowbreak/>edu/<allowbreak/>entries/<allowbreak/>causation-counterfactual</ref>
        </imprint>
      </monogr>
    </biblStruct>
    
    <biblStruct id="spades-2018-bid11" type="book" rend="foot" n="footcite:Moore1999">
      <monogr>
        <title level="m">Causation and Responsibility</title>
        <author>
          <persName>
            <foreName>M.S.</foreName>
            <surname>Moore</surname>
            <initial>M.</initial>
          </persName>
        </author>
        <imprint>
          <publisher>
            <orgName>Oxford</orgName>
          </publisher>
          <dateStruct>
            <year>1999</year>
          </dateStruct>
        </imprint>
      </monogr>
    </biblStruct>
    
    <biblStruct id="spades-2018-bid12" type="article" rend="foot" n="footcite:Pearl2009">
      <analytic>
        <title level="a">Causal inference in statistics: An overview</title>
        <author>
          <persName>
            <foreName>J.</foreName>
            <surname>Pearl</surname>
            <initial>J.</initial>
          </persName>
        </author>
      </analytic>
      <monogr>
        <title level="j">Statistics Surveys</title>
        <imprint>
          <biblScope type="volume">3</biblScope>
          <dateStruct>
            <year>2009</year>
          </dateStruct>
          <biblScope type="pages">96-146</biblScope>
        </imprint>
      </monogr>
    </biblStruct>
    
    <biblStruct id="spades-2018-bid44" type="misc" rend="foot" n="footcite:Prosa">
      <monogr>
        <title level="m">A Library for formally proven schedulability analysis</title>
        <imprint>
          <ref xlink:href="http://prosa.mpi-sws.org/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://<allowbreak/>prosa.<allowbreak/>mpi-sws.<allowbreak/>org/</ref>
        </imprint>
      </monogr>
    </biblStruct>
    
    <biblStruct id="spades-2018-bid39" type="article" rend="foot" n="footcite:ramadge87">
      <analytic>
        <title level="a">Supervisory Control of a Class of Discrete Event Processes</title>
        <author>
          <persName>
            <foreName>P.J.</foreName>
            <surname>Ramadge</surname>
            <initial>P.</initial>
          </persName>
          <persName>
            <foreName>W.M.</foreName>
            <surname>Wonham</surname>
            <initial>W.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-editorial-board="yes" x-international-audience="yes">
        <title level="j">SIAM Journal on control and optimization</title>
        <imprint>
          <biblScope type="volume">25</biblScope>
          <biblScope type="number">1</biblScope>
          <dateStruct>
            <month>January</month>
            <year>1987</year>
          </dateStruct>
          <biblScope type="pages">206–230</biblScope>
        </imprint>
      </monogr>
    </biblStruct>
    
    <biblStruct id="spades-2018-bid17" type="techreport" rend="foot" n="footcite:Rushby1999">
      <monogr>
        <title level="m">Partitioning for Safety and Security: Requirements, Mechanisms, and Assurance</title>
        <author>
          <persName>
            <foreName>J.</foreName>
            <surname>Rushby</surname>
            <initial>J.</initial>
          </persName>
        </author>
        <imprint>
          <biblScope type="number">CR-1999-209347</biblScope>
          <publisher>
            <orgName type="institution">NASA Langley Research Center</orgName>
          </publisher>
          <dateStruct>
            <year>1999</year>
          </dateStruct>
        </imprint>
      </monogr>
      <note type="typdoc">Technical report</note>
    </biblStruct>
    
    <biblStruct id="spades-2018-bid20" type="inproceedings" rend="foot" n="footcite:stefani:hal-01094208">
      <identifiant type="hal" value="hal-01094208"/>
      <analytic>
        <title level="a">Components as Location Graphs</title>
        <author>
          <persName key="spades-2018-idp155696">
            <foreName>Jean-Bernard</foreName>
            <surname>Stefani</surname>
            <initial>J.-B.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-scientific-popularization="no" x-international-audience="yes" x-proceedings="yes" x-invited-conference="yes" x-editorial-board="yes">
        <title level="m">11th International Symposium on Formal Aspects of Component Software</title>
        <loc>Bertinoro, Italy</loc>
        <title level="s">Lecture Notes in Computer Science</title>
        <imprint>
          <biblScope type="volume">8997</biblScope>
          <dateStruct>
            <month>September</month>
            <year>2014</year>
          </dateStruct>
          <ref xlink:href="https://hal.inria.fr/hal-01094208" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01094208</ref>
        </imprint>
      </monogr>
    </biblStruct>
    
    <biblStruct id="spades-2018-bid46" type="inproceedings" rend="foot" n="footcite:StiggeEGY11">
      <identifiant type="doi" value="10.1109/RTAS.2011.15"/>
      <analytic>
        <title level="a">The Digraph Real-Time Task Model</title>
        <author>
          <persName>
            <foreName>Martin</foreName>
            <surname>Stigge</surname>
            <initial>M.</initial>
          </persName>
          <persName>
            <foreName>Pontus</foreName>
            <surname>Ekberg</surname>
            <initial>P.</initial>
          </persName>
          <persName>
            <foreName>Nan</foreName>
            <surname>Guan</surname>
            <initial>N.</initial>
          </persName>
          <persName>
            <foreName>Wang</foreName>
            <surname>Yi</surname>
            <initial>W.</initial>
          </persName>
        </author>
      </analytic>
      <monogr>
        <title level="m">17th IEEE Real-Time and Embedded Technology and Applications Symposium, RTAS 2011, Chicago, Illinois, USA, 11-14 April 2011</title>
        <imprint>
          <dateStruct>
            <year>2011</year>
          </dateStruct>
          <biblScope type="pages">71–80</biblScope>
          <ref xlink:href="https://doi.org/10.1109/RTAS.2011.15" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>doi.<allowbreak/>org/<allowbreak/>10.<allowbreak/>1109/<allowbreak/>RTAS.<allowbreak/>2011.<allowbreak/>15</ref>
        </imprint>
      </monogr>
    </biblStruct>
    
    <biblStruct id="spades-2018-bid21" type="book" rend="foot" n="footcite:tabuada2009">
      <monogr>
        <title level="m">Verification and Control of Hybrid Systems - A Symbolic Approach</title>
        <author>
          <persName>
            <foreName>P.</foreName>
            <surname>Tabuada</surname>
            <initial>P.</initial>
          </persName>
        </author>
        <imprint>
          <publisher>
            <orgName>Springer</orgName>
          </publisher>
          <dateStruct>
            <year>2009</year>
          </dateStruct>
        </imprint>
      </monogr>
    </biblStruct>
    
    <biblStruct id="spades-2018-bid28" type="techreport" rend="foot" n="footcite:terry11">
      <monogr>
        <title level="m">Replicated Data Consistency Explained Through Baseball</title>
        <author>
          <persName>
            <foreName>Doug</foreName>
            <surname>Terry</surname>
            <initial>D.</initial>
          </persName>
        </author>
        <imprint>
          <biblScope type="number">MSR-TR-2011-137</biblScope>
          <publisher>
            <orgName type="institution">Microsoft Research</orgName>
          </publisher>
          <dateStruct>
            <month>October</month>
            <year>2011</year>
          </dateStruct>
        </imprint>
      </monogr>
      <note type="typdoc">Technical report</note>
    </biblStruct>
    
    <biblStruct id="spades-2018-bid47" type="book" rend="foot" n="footcite:tindell1992using">
      <monogr>
        <title level="m">Using offset information to analyse static priority pre-emptively scheduled task sets</title>
        <title level="s">Technical report YCS 182</title>
        <author>
          <persName>
            <foreName>Ken</foreName>
            <surname>Tindell</surname>
            <initial>K.</initial>
          </persName>
        </author>
        <imprint>
          <publisher>
            <orgName>University of York, Department of Computer Science</orgName>
          </publisher>
          <dateStruct>
            <year>1992</year>
          </dateStruct>
          <ref xlink:href="https://books.google.fr/books?id=qARQHAAACAAJ" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>books.<allowbreak/>google.<allowbreak/>fr/<allowbreak/>books?id=qARQHAAACAAJ</ref>
        </imprint>
      </monogr>
    </biblStruct>
    
    <biblStruct id="spades-2018-bid35" type="inproceedings" rend="foot" n="footcite:wang:hal-01412100">
      <identifiant type="doi" value="10.1145/2968478.2968500"/>
      <identifiant type="hal" value="hal-01412100"/>
      <analytic>
        <title level="a">Energy and timing aware synchronous programming</title>
        <author>
          <persName key="spades-2018-idp160672">
            <foreName>Jiajie</foreName>
            <surname>Wang</surname>
            <initial>J.</initial>
          </persName>
          <persName>
            <foreName>Partha S</foreName>
            <surname>Roop</surname>
            <initial>P. S.</initial>
          </persName>
          <persName key="spades-2018-idp150368">
            <foreName>Alain</foreName>
            <surname>Girault</surname>
            <initial>A.</initial>
          </persName>
        </author>
      </analytic>
      <monogr>
        <title level="m">International Conference on Embedded Software, EMSOFT'16</title>
        <loc>Pittsburgh, United States</loc>
        <imprint>
          <publisher>
            <orgName>ACM</orgName>
          </publisher>
          <dateStruct>
            <month>October</month>
            <year>2016</year>
          </dateStruct>
          <biblScope type="pages">10</biblScope>
          <ref xlink:href="https://hal.inria.fr/hal-01412100" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01412100</ref>
        </imprint>
      </monogr>
    </biblStruct>
    
    <biblStruct id="spades-2018-bid32" type="article" rend="foot" n="footcite:wilhelm07">
      <analytic>
        <title level="a">The Determination of Worst-Case Execution Times — Overview of the Methods and Survey of Tools</title>
        <author>
          <persName>
            <foreName>R.</foreName>
            <surname>Wilhelm</surname>
            <initial>R.</initial>
          </persName>
          <persName>
            <foreName>Jakob</foreName>
            <surname>Engblom</surname>
            <initial>J.</initial>
          </persName>
          <persName>
            <foreName>Andreas</foreName>
            <surname>Ermedahl</surname>
            <initial>A.</initial>
          </persName>
          <persName>
            <foreName>Niklas</foreName>
            <surname>Holsti</surname>
            <initial>N.</initial>
          </persName>
          <persName>
            <foreName>Stephan</foreName>
            <surname>Thesing</surname>
            <initial>S.</initial>
          </persName>
          <persName>
            <foreName>David B.</foreName>
            <surname>Whalley</surname>
            <initial>D. B.</initial>
          </persName>
          <persName>
            <foreName>Guillem</foreName>
            <surname>Bernat</surname>
            <initial>G.</initial>
          </persName>
          <persName>
            <foreName>Christian</foreName>
            <surname>Ferdinand</surname>
            <initial>C.</initial>
          </persName>
          <persName>
            <foreName>Reinhold</foreName>
            <surname>Heckmann</surname>
            <initial>R.</initial>
          </persName>
          <persName>
            <foreName>Tulika</foreName>
            <surname>Mitra</surname>
            <initial>T.</initial>
          </persName>
          <persName>
            <foreName>Frank</foreName>
            <surname>Mueller</surname>
            <initial>F.</initial>
          </persName>
          <persName key="pacap-2018-idp170912">
            <foreName>Isabelle</foreName>
            <surname>Puaut</surname>
            <initial>I.</initial>
          </persName>
          <persName>
            <foreName>Peter P.</foreName>
            <surname>Puschner</surname>
            <initial>P. P.</initial>
          </persName>
          <persName>
            <foreName>Jan</foreName>
            <surname>Staschulat</surname>
            <initial>J.</initial>
          </persName>
          <persName>
            <foreName>Per</foreName>
            <surname>Stenström</surname>
            <initial>P.</initial>
          </persName>
        </author>
      </analytic>
      <monogr>
        <title level="j">ACM Trans. Embedd. Comput. Syst.</title>
        <imprint>
          <biblScope type="volume">7</biblScope>
          <biblScope type="number">3</biblScope>
          <dateStruct>
            <month>April</month>
            <year>2008</year>
          </dateStruct>
        </imprint>
      </monogr>
    </biblStruct>
    
    <biblStruct id="spades-2018-bid41" type="inproceedings" rend="foot" n="footcite:yao95">
      <analytic>
        <title level="a">A scheduling model for reduced CPU energy</title>
        <author>
          <persName>
            <foreName>F.</foreName>
            <surname>Yao</surname>
            <initial>F.</initial>
          </persName>
          <persName>
            <foreName>A.</foreName>
            <surname>Demers</surname>
            <initial>A.</initial>
          </persName>
          <persName>
            <foreName>S.</foreName>
            <surname>Shenker</surname>
            <initial>S.</initial>
          </persName>
        </author>
      </analytic>
      <monogr>
        <title level="m">Proceedings of lEEE Annual Foundations of Computer Science</title>
        <imprint>
          <dateStruct>
            <year>1995</year>
          </dateStruct>
          <biblScope type="pages">374–382</biblScope>
        </imprint>
      </monogr>
    </biblStruct>
    
    <biblStruct id="spades-2018-bid0" type="misc" rend="foot" n="footcite:Artemis11SRA">
      <monogr>
        <title level="m">ARTEMIS Strategic Research Agenda</title>
        <author>
          <persName>
            <foreName/>
            <surname>ARTEMIS Joint Undertaking</surname>
            <initial/>
          </persName>
        </author>
        <imprint>
          <dateStruct>
            <year>2011</year>
          </dateStruct>
        </imprint>
      </monogr>
    </biblStruct>
  </biblio>
</raweb>
