<?xml version="1.0" encoding="UTF-8"?>
<TEI xml:space="preserve" xmlns="http://www.tei-c.org/ns/1.0" 
xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" 
xsi:schemaLocation="http://www.tei-c.org/ns/1.0 https://raw.githubusercontent.com/kermitt2/grobid/master/grobid-home/schemas/xsd/Grobid.xsd"
 xmlns:xlink="http://www.w3.org/1999/xlink">
	<teiHeader xml:lang="en">
		<fileDesc>
			<titleStmt>
				<title level="a" type="main">Multilevel Environments in Insertion Modeling System</title>
			</titleStmt>
			<publicationStmt>
				<publisher/>
				<availability status="unknown"><licence/></availability>
			</publicationStmt>
			<sourceDesc>
				<biblStruct>
					<analytic>
						<author role="corresp">
							<persName><forename type="first">Dmitriy</forename><forename type="middle">M</forename><surname>Klionov</surname></persName>
							<email>soulslayermaster@gmail.com</email>
							<affiliation key="aff0">
								<orgName type="institution">Kherson State University</orgName>
								<address>
									<addrLine>40 rokiv Zhovtnya st. 27</addrLine>
									<settlement>Kherson</settlement>
									<country key="UA">Ukraine</country>
								</address>
							</affiliation>
						</author>
						<title level="a" type="main">Multilevel Environments in Insertion Modeling System</title>
					</analytic>
					<monogr>
						<imprint>
							<date/>
						</imprint>
					</monogr>
					<idno type="MD5">389F8BD35CED41FF69B22C8268A2F682</idno>
				</biblStruct>
			</sourceDesc>
		</fileDesc>
		<encodingDesc>
			<appInfo>
				<application version="0.7.2" ident="GROBID" when="2023-03-24T16:36+0000">
					<desc>GROBID - A machine learning software for extracting information from scholarly documents</desc>
					<ref target="https://github.com/kermitt2/grobid"/>
				</application>
			</appInfo>
		</encodingDesc>
		<profileDesc>
			<textClass>
				<keywords>
					<term>Insertion modeling</term>
					<term>multilevel environments</term>
					<term>compatibility relation</term>
					<term>client-server architecture Computation</term>
					<term>Model</term>
					<term>Insertion Modeling</term>
				</keywords>
			</textClass>
			<abstract>
<div xmlns="http://www.tei-c.org/ns/1.0"><p>The goal of this paper is to show that the Insertion Modeling System[1] developed by A.A. Letichevsky of the department 100/105 of the Glushkov Institute of Cybernetics, National Academy of Science of Ukraine, Kyiv, Ukraine, can be used as an instrument for the modeling and analysis of complex distributed systems, such as a client-server architectures. The Insertion Modeling [1] is based on the interactions of environments and agents inserted into that environments. Agents have different behaviors represented as Behavior Algebras, and can also be the environments themselves, having another agents with different behaviors inserted into them. The definition for multilevel environments was first given in a paper [1], and was slightly extended in following papers.</p></div>
			</abstract>
		</profileDesc>
	</teiHeader>
	<text xml:lang="en">
		<body>
<div xmlns="http://www.tei-c.org/ns/1.0"><head>Introduction</head><p>Insertion modeling is a technology for specification and verification of complex distributed systems based on the interactions of agents and environments. Agents and environments are models of some entities of real world or components of complex systems on different levels of abstraction that interact with one another by means of insertion functions. Also if the environment is considered as an agent it can also be inserted to other environments. In order to model complex systems those consist of a lot of components that have hierarchical structure, the notion of multilevel environments, with agents that are able to move from one environment to another is required. The notion of mobility of such mobile agents are based on the approach recently favored in declarative mobile language design is using mobile calculi that extend or modify the π-calculus <ref type="bibr" target="#b9">[10]</ref> with new features, including mechanisms for encryption and security. Calculi of this kind include, among others, the Spi Calculus <ref type="bibr" target="#b5">[6]</ref>, and the Ambient Calculus <ref type="bibr" target="#b6">[7]</ref>. In addition, there is a broader body of work favoring declarative approaches, including work in the field of coordination languages. There has also been a great expansion of the capabilities and security of agent-based languages such as OAA <ref type="bibr" target="#b9">[10]</ref> and D'Agents <ref type="bibr" target="#b12">[13]</ref>.</p><p>According to the Ambient Calculus <ref type="bibr" target="#b6">[7]</ref>, devised by Luca Cardelli the main difficulty of mobile computations in Web is not in mobility itself but in handling of administrative domains. In the early days of the Internet one could rely on a flat name space given by IP addresses; knowing the IP address of a computer would very likely allow one to talk to that computer in some way. This is no longer the case: firewalls partition the Internet into administrative domains that are isolated from each other except for rigidly controlled pathways. System administrators enforce policies about what can move through firewalls and how.</p><p>The client-server model is the prevalent approach in computer networking. The model assigns one of two roles to the computers in a network: a client or a server. A server is a computer system that selectively shares its resources; a client is a computer or computer program that initiates contact with a server in order to make use of a resource. Data, CPUs, printers, and data storage devices are some examples of resources. This model can be represented as a set of administrative domains, with defined access rules, or as some architectural design pattern, like three-tier pattern. Both of these are presented in this paper in terms of the insertion modeling.</p></div>
<div xmlns="http://www.tei-c.org/ns/1.0"><head n="2">Insertion Modeling System</head><p>Insertion modeling system is an environment for the development of insertion machines and performing experiments with them. Insertion model of a system represent this system as a composition of environment and agents inserted into it, using the insertion function. Contrariwise the whole system as an agent can be inserted into another environment. In this case we speak about the internal and external environment of a system. Agents inserted into the internal environment of a system themselves can be environments with respect to their internal agents. In this case we speak about multilevel structure of agent or environment and about high level and low level environments.</p><p>Agent and environments have a set of action and a set of behaviors (processes), defined in behavior algebra. Two set of actions: a set of environment actions and a set of agent actions define the type of environment. If an agent is about to be inserted into the environment at least one of its actions must be allowed by this environment. So the set of agent actions define the type of environments it can be inserted in, as well as the environment's set of allowed agent actions define the type of agents that can be inserted into this environment. Such a relation between types of agents and environments is called compatibility relation <ref type="bibr" target="#b1">[2]</ref>, which defines a directed graph. When an agent is inserted into some environment, it is able to move to another environment if it is compatible with this environment. For example the rule(1) shows an agent u that moves to an external environment E, from environment R, it is currently inserted into.</p><formula xml:id="formula_0">) , , , ( []] , [ ]] [ [ ) ( _ e move u R E P R u E u R E u u e r up move e move               (1)</formula><p>Here e and r -are the names of environments, R[] -describes environment R that currently have no agents inserted into it. Insertion only occurs if a predicate P is true, and in general case it may depend only on the types of agents and environments. This example rule shows "one step" movement of an agent u, and if the new state of agent u has the same type as u, and types of environments E and R had not changed as well, rule (1) can be considered as commutative. Also"long range" movements can be defined recursively, for any set of environments between E and R.</p></div>
<div xmlns="http://www.tei-c.org/ns/1.0"><head>3</head><p>Insertion Models of Client-Server Architecture</p></div>
<div xmlns="http://www.tei-c.org/ns/1.0"><head n="3.1">Domain Model</head><p>This model describes a client-server-architecture as a set of administrative domains that have certain access rules. Each of these domains is represented by an environment in IMS. Agents are messages that travel over these domains, trying to access certain protected area of some administrative domain of the server. As an example we take our website apsystem.or.ua. It is shown at picture below. The top-most environment E-represents some network (local-area network or internet), with environments of apsystem itself , and a set of clients C1, C2, … , Cn inserted into the network. Client environments create agents and send them over the network in order to gain access to some function of apsystem if they have certain permission, or to a domain of another client. One of the clients can represent a villain (Hacker), which goal is to find all possible security risks and ways of an attack to curtain security protocol.</p><p>In order to access administrative domain and to authorize on a server the client has to show that it knows some secret, which is only known to client and server (or two clients that want to exchange some data), and which is not transferred over the network. This key is used to encode messages (transferred by the agents), and when agents tries to move into the environment of administrative domain, this key is used to decode the message, if it is possible than agent inserts into the environment, and proceeds further. There are many ways for generating such secret. This model uses the standard Needham-Schroeder Public Key protocol <ref type="bibr" target="#b20">[21]</ref>. Each client and server has a secret key, which is used to decode messages encoded with appropriate public key. When an agent gets inside the administrative domain (apsystem for example), it have to get a permissions to act inside it. The message transferred by this agent, contains the information about the access rights of the client who sent it. This data is used to move further. When an agent reaches some function ("download_paper" for example) it has a permission to, it is to be sent back by the server to the client. Account environments that are inserted into the clients and the top-most environment of the server store all information required to authorize at appropriate client or server. Tables below show all types of environments and agents.</p><p>Types of environments of clients and the top-most environment of the server, are identical. In general the client differs from the server only by the means of environments inside it, which require an action authorized_move. Interactions with agents:</p><formula xml:id="formula_1">) , , , , , ( ]] [ []], [ [ []] ]], [ [ [ a send u A AC C E P u A C A C E A u AC C E u u a send a send               (2)</formula><p>In equation ( <ref type="formula">2</ref>) send(A) Means that client C sends the message u, with an appropriate account AC, to the server A[], over the network E, where a -is the name of server A[]. The definition A[] means that there were no agents inserted into this environment. </p><formula xml:id="formula_2">                 ;<label>(3)</label></formula><p>An agent u tries to gain access to the server A[], A tries to authorize it, using the secret y, if the authorization succeeds, then u enters appropriate account on the server that is CA, and ca is its name.</p><formula xml:id="formula_3">)) , ( ), ( _ , , , ( []] ], , [ [ []] ], [ [ , ) , ( ) ( _ ) , ( t r create x data get t u CA P D r u CA A D u CA A u u A C CA ca t r create x data get t r create                     (4)</formula><p>An account environment CA creates a new agent named r, which type is t . It carries all data received from u, by the action get_data(x), x -is that data. This rule creates an agent of type authorized_agent , but it can create an agent of any type that is compatible with this environment.</p><formula xml:id="formula_4">) , , , , ( ]]] [ ], [ [ []] ], , [ [ d authmove r D CA A P r D u A C A D r u CA A r r d authmove d authmove                  (5)</formula><p>The authorized agent u moves to the environment D[], that represent one of the server functions;</p><formula xml:id="formula_5">) , _ , , ( ] [ ] [ , _ invoke r permission check r D P r D r D r r D D invoke invoke u permission check                      (6)</formula><p>The agent u invokes the main function of D[], and depending on the result of check_permission u, the result of this invoke might be different.</p><formula xml:id="formula_6">)) ( ), ( _ , , ( ] [ ] [ ) ( ) ( _ y done x goal check r AC P AC r AC r C A AC y done x goal chech                (7)</formula><p>When an agent comes back to the client that sent it, the client checks the message it carried, and it matches the required result then it is successful termination. These rules only work if both the client and the server share a secret, known only to them. In order to safely generate such secret the Needham-Schroeder public key algorithm is used. Usually the Needham-Schroeder protocol requires a second server that hosts all the public keys, but for simplicity we assume that all clients and servers know all the public keys. If the secret has already been created, than it is taken instead of public key and secret key for encoding and decoding of messages.</p><p>It runs as follows:</p><p>1. First we check if the secret exists for an account A, if not we send message to the server A[] by the rule (2), and set the value of an agent's attribute mb to N 1 that is a simple random number.</p></div>
<div xmlns="http://www.tei-c.org/ns/1.0"><head n="2.">Then the server A[] uses the rule(3) to decode message using the secret key of server A[],</head><p>.if the secret is not created yet.</p><p>3. Then the server replies by the rule (2) to client C the value of mb is set to (N 1 ,N 2 ), N 1 -is the random number created by the client C, and N 2 -is the new random number. 4. If the first part of the mb is equal to the random number that was generated before, than C can take the pair (N 1 ,N 2 ), as a secret for the account A. 5. Then C sends a message to A[], that contains N2. When A will receive it, he will also take the pair (N 1 ,N 2 ), as a secret for account C.</p><p>In order to verify this protocol one of the clients has to take the role of a villain, its goal is to be authorized as another client from the network, using in this case a menin-middle attack. <ref type="bibr" target="#b21">[22]</ref> </p></div>
<div xmlns="http://www.tei-c.org/ns/1.0"><head n="3.2">Insertion Model of Three-Tier Architecture</head><p>Unlike of the previous model this one focuses on the actual behavior of data-packages represented by agents, inside the server environment, divided basically to three layers according to the three-tier architecture. The example model of the server hosting two sites apsystem and unarea, is presented. Their frontends are located inside the presentation tier.</p><formula xml:id="formula_7">[]]]]] _ [], _ [ [ [ []], _ [ []], _ [ [ [ [], [], [Pr[ d un d aps mysql Data l un Py l aps Php App un aps E (8)<label>(8)</label></formula><p>is the state of environment in such example. E -the top-most environment, Prthe presentation tier, aps -the apsystem frontend, un -the unarea frontend, App -the application tier, PHP\ PY -all sites developed in php and python accordingly, aps_l\un_l -the logic of apsystem\unarea, Data -the data tier, aps_d\un_d -the database of apsystem\unarea. The user only works with frontend. This means, that the incoming agent is compatible only with environments of the presentation layer. An agent inserted into one of the frontends carries one request. Interaction with environments: In the rule (9) u gets inside Pr using user_move pr, where pr is the name of the environment Pr, if P can allow this. (a simple one step insertion). The same way u gets inside the environment aps[], using in(aps). This shows how a user goes to some web-site (apsystem in our case), in order to download a page for example. In order to do so he has to load a web-page that has a required link to the paper he wants.</p><p>)) _ , (Pr,</p><formula xml:id="formula_8">[]]]]]] _ [ [ [], _ [ [], , [ r [P []]]]]] _ [ [ [], _ [ [], Pr[ , [ ) _ _ pr move user u P d APS mysql Data l APS App APS u E d APS mysql Data l APS App APS u E u u pr move user pr move user                     (9)</formula><p>The link to the paper is stored in the site's data base that is inside the Data tier, and the rules for extracting these data, and displaying them is inside the Application layer. So, the frontend part (environment of apsystem in our case) creates a new agent, that is compatible only with this environment, and with according environments of the Application layer:</p><formula xml:id="formula_9">)) ( , , ( ]] ]], [ [ r [P ]] ], [ [Pr[ ) ( ) ( x execute u APS P Q S AP E Q u APS E u x execute x execute                 <label>(10)</label></formula><p>Here we check if u is able to execute its request x if it succeeds than it is DELTA, if it is NOT able to, than we have to check if there any environments inside aps, that are compatible with u, go inside them, and again try the same rule. Q is put for simplicity; it describes all rest of environments that are not involved in the current rule. If there are no such environments or even after insertion to such environment u is still unable to solve(x), then we have to create a new agent r that will get necessary data from application tier.</p><p>)</p><formula xml:id="formula_10">) , ( , , ( ]] ]], , [ [ r [P ]] ], [ [Pr[ ) , ( ) , ( t create t APS Q r u s ap E Q u aps E S AP APS t r create t r create              <label>(11)</label></formula><p>Note: r has to be created inside that environment, which u is currently inserted in.</p><p>)</p><formula xml:id="formula_11">) ( _ , , _ ( ]]]]] [ _ [ [ ], [ [ r [P ]]]]] [ _ [ [ ], [ [Pr[ ) ( ) ( _ y script execute r l APS P r l APS P PH p Ap u APS E r l APS PHP App u APS E r r y solve y script execute                    (12)</formula><p>The agent r moves to that environment (APS_l). It should go first to the environment PHP, which is the top-environment of all sites based on PHP, and then moves to the environment APS_l. The rule for its movement is similar to the movement of a user request. The execution of script request is different: </p><formula xml:id="formula_12">                     (13)</formula><p>If the execution succeeds, than r moves back to the environment, which created it. If not, then the environment APS_l, creates a new agent, which is the query for the data tier. The rules are similar.</p></div>
<div xmlns="http://www.tei-c.org/ns/1.0"><head n="4">Conclusions</head><p>The client-server model can be considered as a prevalent approach in computer networking, and is one of the best examples of complex distributed systems. Two examples of insertion models of client-server architecture are presented in this paper: the domain model -as a set of administrative domains with pre-defined access rules; and a three-tier architecture -a client-server architecture in which the presentation, the application processing, and the data management functions are logically separated. Both these insertion models with multilevel environments and mobile agents can be extended later for more complicated applications, such as the verification of crypto-graphic protocols, the problem solving, the constraint propagation, the cognitive architectures.</p></div><figure xmlns="http://www.tei-c.org/ns/1.0" xml:id="fig_0"><head>Fig. 1 .</head><label>1</label><figDesc>Fig. 1. The domain model of client server</figDesc><graphic coords="3,179.04,528.78,237.12,130.08" type="bitmap" /></figure>
<figure xmlns="http://www.tei-c.org/ns/1.0" xml:id="fig_1"><head>Fig. 2 .</head><label>2</label><figDesc>Fig. 2. Compatibility graph for the client-server domain model Vertexes represent agents and environments, and edges represent a compatibility relation. Directions mean that for example the authorized agent can be inserted into the environments of the account, server functions environments, clients and servers environments.Interactions with agents:</figDesc><graphic coords="4,124.68,303.36,344.82,164.28" type="bitmap" /></figure>
<figure xmlns="http://www.tei-c.org/ns/1.0" xml:id="fig_2"><head>Fig. 3 .</head><label>3</label><figDesc>Fig. 3. Insertion model of three-tier client-server architecture</figDesc><graphic coords="7,196.68,373.38,201.90,147.00" type="bitmap" /></figure>
<figure xmlns="http://www.tei-c.org/ns/1.0" type="table" xml:id="tab_0"><head>Table 1 .</head><label>1</label><figDesc>Actions of agents and environments in domain model invokes the main function of the environments of the server functions, x -is the access level of authorized agent. It receives as an answer or the result of execution of function, or the "access denied" message.</figDesc><table><row><cell>Agent / Envi-ronments type</cell><cell cols="2">Attributes</cell><cell>Actions</cell></row><row><cell></cell><cell cols="2">mb -message body, actual</cell></row><row><cell></cell><cell cols="2">information carried by this</cell></row><row><cell></cell><cell>agent;</cell><cell></cell><cell>send a -makes agent to move to the server envi-</cell></row><row><cell>Simple message</cell><cell cols="2">sender -the name of the one who sent this message;</cell><cell>ronment named a,</cell></row><row><cell></cell><cell cols="2">enc_key -key that is used by encryption algorithm;</cell><cell>access d -agent tries to authorize in order to enter the environment named d, that is in the server environment.</cell></row><row><cell></cell><cell cols="2">mb -message body, actual</cell><cell>auth_move d -"authorized move" to some inter-</cell></row><row><cell></cell><cell cols="2">information carried by this</cell><cell>nal environments of the server named d</cell></row><row><cell></cell><cell>agent;</cell><cell></cell><cell>get_data(x) -agent shares the data it carries.</cell></row><row><cell cols="4">invoke(x) -Authorized mes-</cell></row><row><cell>sage</cell><cell cols="2">role -defines the access</cell></row><row><cell></cell><cell cols="2">level of this information</cell></row><row><cell></cell><cell></cell><cell></cell><cell>done(x) -required to check if the result it carries</cell></row><row><cell></cell><cell></cell><cell></cell><cell>is equivalent to the expected result</cell></row><row><cell>Clients and the top-most envi-ronment of the server Allowed actions: authmove send, access,</cell><cell cols="2">Secretkey -an integer value of the client's secret key, that is used by the Needham-Schroeder algorithm numbers. Nounce -a place for random</cell><cell>allow(y) -environment checks the incoming message from the server, y -is the secret key that is used to decode the information from that message.</cell></row><row><cell></cell><cell cols="2">server -the name of the server it belongs to</cell><cell>update(x) -account is able to update its data about the secret keys used in the Needham-Schroeder algorithm</cell></row><row><cell></cell><cell cols="2">role -an integer value that</cell><cell>check_goal(x) -checks if the result brought by</cell></row><row><cell>Accounts</cell><cell cols="2">represent a role of this ac-</cell><cell>the message, is equal to the expected result that is</cell></row><row><cell>Allowed actions:</cell><cell cols="2">count at server</cell><cell>x</cell></row><row><cell>access, authmove, send, get_ data(y), done(z)</cell><cell cols="2">publickey -the public key of the server, that is used by the Needham-Schroeder algo-rithm secret -that will be obtained</cell><cell>create(r,t) -environment creates agent named r, which has type t</cell></row><row><cell></cell><cell>by</cell><cell>Needham-Schroeder</cell></row><row><cell></cell><cell cols="2">algorithm</cell></row><row><cell>Environments that</cell><cell></cell><cell></cell></row><row><cell>represent server</cell><cell></cell><cell></cell><cell>check_permission u -checks if the access level</cell></row><row><cell>functions(</cell><cell cols="2">permission -an integer value</cell><cell>of agent u is appropriate for performing action, if</cell></row><row><cell>download_paper,</cell><cell cols="2">indicating what the required</cell><cell>it do then it is delta, if not then agent receives a</cell></row><row><cell>upload_paper)</cell><cell cols="2">permissions to access it are.</cell><cell>message that it has no rights to perform the</cell></row><row><cell>Allowed actions:</cell><cell></cell><cell></cell><cell>function of this environment</cell></row><row><cell>authmove, invoke</cell><cell></cell><cell></cell></row><row><cell>E</cell><cell></cell><cell></cell></row><row><cell>Allowed actions:</cell><cell></cell><cell></cell></row><row><cell>send a</cell><cell></cell><cell></cell></row></table></figure>
<figure xmlns="http://www.tei-c.org/ns/1.0" type="table" xml:id="tab_1"><head>Table 2 .</head><label>2</label><figDesc>Types of agents and environments</figDesc><table><row><cell>Agents/Environments types</cell><cell>Actions</cell></row><row><cell></cell><cell>execute(x) -executes the request brought by user,</cell></row><row><cell>User request</cell><cell>x-is the request data User_move d -User agent moves to environment,</cell></row><row><cell></cell><cell>named d</cell></row><row><cell>Script request Allowed actions: ex-cute(x),User_move d</cell><cell>execute_script(y) -executes the request brought by script, y-is the request data Script_move d -script agent moves to environment named d</cell></row><row><cell>Data base request Allowed actions: execute_script(y), Script_move d</cell><cell>Execute_query(z) -Executes the request brought by data base, z-is the request data Data_base_move d -Data base agent moves to environment named d</cell></row><row><cell>Environments of the Presentation tier</cell><cell></cell></row><row><cell>Allowed actions: exe-</cell><cell>Create (r,t) -Creates agent named r, of the type t</cell></row><row><cell>cute(x),User_move d, Script_move d</cell><cell></cell></row><row><cell>Environments of the Application tier</cell><cell></cell></row><row><cell>Allowed actions: execute_script(x),</cell><cell>Create (r,t) -Creates agent named r, of the type t</cell></row><row><cell>Script_move d,Data_base_move d</cell><cell></cell></row><row><cell>Environments of the Data tier</cell><cell></cell></row><row><cell>Allowed actions: execute_query(x),</cell><cell></cell></row><row><cell>Script_move d, Data_base_move d</cell><cell></cell></row></table></figure>
		</body>
		<back>
			<div type="references">

				<listBibl>

<biblStruct xml:id="b0">
	<analytic>
		<title level="a" type="main">Insertion Modeling</title>
		<author>
			<persName><forename type="first">A</forename><forename type="middle">A</forename><surname>Letichevsky</surname></persName>
		</author>
	</analytic>
	<monogr>
		<title level="j">Control Systems and Computers</title>
		<imprint>
			<biblScope unit="volume">6</biblScope>
			<biblScope unit="page" from="3" to="14" />
			<date type="published" when="2012">2012</date>
		</imprint>
	</monogr>
</biblStruct>

<biblStruct xml:id="b1">
	<analytic>
		<title level="a" type="main">Algebra of Behavior Transformations and its Applications</title>
		<author>
			<persName><forename type="first">A</forename><surname>Letichevsky</surname></persName>
		</author>
	</analytic>
	<monogr>
		<title level="m">Structural Theory of Automata, Semigroups, and Universal Algebra</title>
				<editor>
			<persName><forename type="first">V</forename><forename type="middle">B</forename><surname>Kudryavtsev</surname></persName>
		</editor>
		<editor>
			<persName><forename type="first">I</forename><forename type="middle">G</forename><surname>Rosenberg</surname></persName>
		</editor>
		<imprint>
			<publisher>Springer</publisher>
			<date type="published" when="2005">2005</date>
			<biblScope unit="volume">207</biblScope>
			<biblScope unit="page" from="241" to="272" />
		</imprint>
	</monogr>
</biblStruct>

<biblStruct xml:id="b2">
	<analytic>
		<title level="a" type="main">Leveraging UML to Deliver Correct Telecom Applications</title>
		<author>
			<persName><forename type="first">S</forename><surname>Baranov</surname></persName>
		</author>
		<author>
			<persName><forename type="first">C</forename><surname>Jervis</surname></persName>
		</author>
		<author>
			<persName><forename type="first">V</forename><surname>Kotlyarov</surname></persName>
		</author>
		<author>
			<persName><forename type="first">A</forename><surname>Letichevsky</surname></persName>
		</author>
		<author>
			<persName><forename type="first">T</forename><surname>Weigert</surname></persName>
		</author>
	</analytic>
	<monogr>
		<title level="m">UML for Real: Design of Embedded Real-Time Systems</title>
				<editor>
			<persName><forename type="first">L</forename><surname>Lavagno</surname></persName>
		</editor>
		<editor>
			<persName><forename type="first">G</forename><surname>Martin</surname></persName>
		</editor>
		<editor>
			<persName><forename type="first">B</forename><surname>Selic</surname></persName>
		</editor>
		<imprint>
			<publisher>Amsterdam</publisher>
			<date type="published" when="2003">2003</date>
		</imprint>
	</monogr>
</biblStruct>

<biblStruct xml:id="b3">
	<analytic>
		<title level="a" type="main">Basic Protocols, Message Sequence Charts, and the Verification of Requirements Specifications</title>
		<author>
			<persName><forename type="first">A</forename><forename type="middle">A</forename><surname>Letichevsky</surname></persName>
		</author>
		<author>
			<persName><forename type="first">J</forename><surname>Kapitonova</surname></persName>
		</author>
		<author>
			<persName><forename type="first">A</forename><surname>Letichevsky</surname><genName>Jr</genName></persName>
		</author>
		<author>
			<persName><forename type="first">V</forename><surname>Volkov</surname></persName>
		</author>
		<author>
			<persName><forename type="first">S</forename><surname>Baranov</surname></persName>
		</author>
		<author>
			<persName><forename type="first">V</forename><surname>Kotlyarov</surname></persName>
		</author>
		<author>
			<persName><forename type="first">T</forename><surname>Weigert</surname></persName>
		</author>
	</analytic>
	<monogr>
		<title level="j">Computer Networks</title>
		<imprint>
			<biblScope unit="volume">47</biblScope>
			<biblScope unit="page" from="662" to="675" />
			<date type="published" when="2005">2005</date>
		</imprint>
	</monogr>
</biblStruct>

<biblStruct xml:id="b4">
	<analytic>
		<title level="a" type="main">Validation of Embedded Systems</title>
		<author>
			<persName><forename type="first">J</forename><surname>Kapitonova</surname></persName>
		</author>
		<author>
			<persName><forename type="first">A</forename><surname>Letichevsky</surname></persName>
		</author>
		<author>
			<persName><forename type="first">V</forename><surname>Volkov</surname></persName>
		</author>
		<author>
			<persName><forename type="first">T</forename><surname>Weigert</surname></persName>
		</author>
	</analytic>
	<monogr>
		<title level="m">The Embedded Systems Handbook</title>
				<editor>
			<persName><forename type="first">R</forename><surname>Zurawski</surname></persName>
		</editor>
		<meeting><address><addrLine>Miami</addrLine></address></meeting>
		<imprint>
			<publisher>CRC Press</publisher>
			<date type="published" when="2005">2005</date>
		</imprint>
	</monogr>
</biblStruct>

<biblStruct xml:id="b5">
	<analytic>
		<title level="a" type="main">A Calculus for Cryptographic Protocols: the spi Calculus</title>
		<author>
			<persName><forename type="first">M</forename><surname>Abadi</surname></persName>
		</author>
		<author>
			<persName><forename type="first">A</forename><forename type="middle">D</forename><surname>Gordon</surname></persName>
		</author>
	</analytic>
	<monogr>
		<title level="m">Proc. 4th ACM Conference on Computer and Communications Security</title>
				<meeting>4th ACM Conference on Computer and Communications Security</meeting>
		<imprint>
			<date type="published" when="1997">1997</date>
			<biblScope unit="page" from="36" to="47" />
		</imprint>
	</monogr>
</biblStruct>

<biblStruct xml:id="b6">
	<analytic>
		<title level="a" type="main">Mobile Ambient</title>
		<author>
			<persName><forename type="first">L</forename><surname>Cardelli</surname></persName>
		</author>
		<author>
			<persName><forename type="first">A</forename><surname>Gordon</surname></persName>
		</author>
	</analytic>
	<monogr>
		<title level="m">Proc. FoSSaCs&apos;98: Foundations of Software Science and Computational Structures</title>
		<title level="s">LNCS</title>
		<editor>
			<persName><forename type="first">M</forename><surname>Nivat</surname></persName>
		</editor>
		<meeting>FoSSaCs&apos;98: Foundations of Software Science and Computational Structures</meeting>
		<imprint>
			<publisher>Springer-Verlag</publisher>
			<date type="published" when="1999">1999</date>
			<biblScope unit="volume">1378</biblScope>
			<biblScope unit="page" from="140" to="155" />
		</imprint>
	</monogr>
</biblStruct>

<biblStruct xml:id="b7">
	<monogr>
		<title level="m" type="main">Oshima: Programming and Deploying Java Mobile Agents with Aglets</title>
		<author>
			<persName><forename type="first">D</forename><forename type="middle">B</forename><surname>Lange</surname></persName>
		</author>
		<imprint>
			<date type="published" when="1998">1998</date>
			<publisher>Addison-Wesley</publisher>
		</imprint>
	</monogr>
</biblStruct>

<biblStruct xml:id="b8">
	<analytic>
		<title level="a" type="main">Mobile Agents and the Future of the Internet</title>
		<author>
			<persName><forename type="first">D</forename><surname>Kotz</surname></persName>
		</author>
		<author>
			<persName><forename type="first">R</forename><forename type="middle">S</forename><surname>Gray</surname></persName>
		</author>
	</analytic>
	<monogr>
		<title level="j">ACM Operating Systems Review</title>
		<imprint>
			<biblScope unit="volume">33</biblScope>
			<biblScope unit="issue">3</biblScope>
			<biblScope unit="page" from="7" to="13" />
			<date type="published" when="1999">1999</date>
		</imprint>
	</monogr>
</biblStruct>

<biblStruct xml:id="b9">
	<analytic>
		<title level="a" type="main">A Calculus of Mobile Processes (Parts I and II)</title>
		<author>
			<persName><forename type="first">R</forename><surname>Milner</surname></persName>
		</author>
		<author>
			<persName><forename type="first">J</forename><surname>Parrow</surname></persName>
		</author>
		<author>
			<persName><forename type="first">D</forename><surname>Walker</surname></persName>
		</author>
	</analytic>
	<monogr>
		<title level="j">Information and Computation</title>
		<imprint>
			<biblScope unit="volume">100</biblScope>
			<biblScope unit="page" from="1" to="77" />
			<date type="published" when="1992">1992</date>
		</imprint>
	</monogr>
</biblStruct>

<biblStruct xml:id="b10">
	<analytic>
		<title level="a" type="main">The Open Agent Architecture: A Framework for Building Distributed Software Systems</title>
		<author>
			<persName><forename type="first">D</forename><surname>Martin</surname></persName>
		</author>
		<author>
			<persName><forename type="first">A</forename><surname>Cheyer</surname></persName>
		</author>
		<author>
			<persName><forename type="first">D</forename><surname>Morgan</surname></persName>
		</author>
	</analytic>
	<monogr>
		<title level="j">Applied Artificial Intelligence</title>
		<imprint>
			<biblScope unit="volume">12</biblScope>
			<biblScope unit="page" from="91" to="128" />
			<date type="published" when="1999">1999</date>
		</imprint>
	</monogr>
</biblStruct>

<biblStruct xml:id="b11">
	<analytic>
		<title level="a" type="main">D&apos;Agents: Security in a Multiple-Language, Mobile-Agents System</title>
		<author>
			<persName><forename type="first">R</forename><forename type="middle">S</forename><surname>Gray</surname></persName>
		</author>
		<author>
			<persName><forename type="first">D</forename><surname>Kotz</surname></persName>
		</author>
		<author>
			<persName><forename type="first">G</forename><surname>Cybenko</surname></persName>
		</author>
		<author>
			<persName><forename type="first">D</forename><surname>Rus</surname></persName>
		</author>
	</analytic>
	<monogr>
		<title level="m">Mobile Agents and Security, LNCS 1419</title>
				<editor>
			<persName><forename type="first">G</forename><surname>Vigna</surname></persName>
		</editor>
		<imprint>
			<publisher>Springer-Verlag</publisher>
			<date type="published" when="1998">1998</date>
			<biblScope unit="page" from="154" to="187" />
		</imprint>
	</monogr>
</biblStruct>

<biblStruct xml:id="b12">
	<analytic>
		<title level="a" type="main">A Calculus of Communicating Systems</title>
		<author>
			<persName><forename type="first">R</forename><surname>Milner</surname></persName>
		</author>
	</analytic>
	<monogr>
		<title level="j">LNCS</title>
		<imprint>
			<biblScope unit="volume">92</biblScope>
			<date type="published" when="1980">1980</date>
			<publisher>Springer-Verlag</publisher>
		</imprint>
	</monogr>
</biblStruct>

<biblStruct xml:id="b13">
	<monogr>
		<title level="m" type="main">Communication and Concurrency</title>
		<author>
			<persName><forename type="first">R</forename><surname>Milner</surname></persName>
		</author>
		<imprint>
			<date type="published" when="1989">1989</date>
			<publisher>Prentice Hall</publisher>
		</imprint>
	</monogr>
</biblStruct>

<biblStruct xml:id="b14">
	<monogr>
		<title level="m" type="main">The Polyadic π-Calculus: a Tutorial</title>
		<author>
			<persName><forename type="first">R</forename><surname>Milner</surname></persName>
		</author>
		<imprint>
			<date type="published" when="1991">1991</date>
			<pubPlace>, UK</pubPlace>
		</imprint>
		<respStmt>
			<orgName>Laboratory for Foundations of Computer Science, Department of Computer Science, University of Edinburgh</orgName>
		</respStmt>
	</monogr>
	<note type="report_type">Tech. Rep. ECS-LFCS-91-180</note>
</biblStruct>

<biblStruct xml:id="b15">
	<analytic>
		<title level="a" type="main">Concurrency and Automata on Infinite Sequences</title>
		<author>
			<persName><forename type="first">D</forename><surname>Park</surname></persName>
		</author>
	</analytic>
	<monogr>
		<title level="j">LNCS</title>
		<imprint>
			<biblScope unit="volume">104</biblScope>
			<date type="published" when="1981">1981</date>
			<publisher>Springer-Verlag</publisher>
		</imprint>
	</monogr>
</biblStruct>

<biblStruct xml:id="b16">
	<analytic>
		<title level="a" type="main">Towards a Unified View of Bisimulation: a Comparative Ctudy</title>
		<author>
			<persName><forename type="first">M</forename><surname>Roggenbach</surname></persName>
		</author>
		<author>
			<persName><forename type="first">M</forename><surname>Majster-Cederbaum</surname></persName>
		</author>
	</analytic>
	<monogr>
		<title level="j">TCS</title>
		<imprint>
			<biblScope unit="volume">238</biblScope>
			<biblScope unit="page" from="81" to="130" />
			<date type="published" when="2000">2000</date>
		</imprint>
	</monogr>
</biblStruct>

<biblStruct xml:id="b17">
	<analytic>
	</analytic>
	<monogr>
		<title level="m">Languages for telecommunications applications -Message Sequence Charts (MSC)</title>
				<imprint>
			<date type="published" when="1999">11/99. 1999</date>
			<biblScope unit="volume">120</biblScope>
		</imprint>
	</monogr>
	<note>Recommendation Z.</note>
</biblStruct>

<biblStruct xml:id="b18">
	<monogr>
		<idno>ITU-T. Z.100</idno>
		<title level="m">Recommendation Z.100 -Specification and Description Language</title>
				<imprint>
			<publisher>SDL</publisher>
			<date type="published" when="1999">1999</date>
		</imprint>
	</monogr>
</biblStruct>

<biblStruct xml:id="b19">
	<analytic>
		<title level="a" type="main">Coalgebras and Systems</title>
		<author>
			<persName><forename type="first">J</forename><surname>Rutten</surname></persName>
		</author>
	</analytic>
	<monogr>
		<title level="j">TCS</title>
		<imprint>
			<biblScope unit="page">249</biblScope>
		</imprint>
	</monogr>
</biblStruct>

<biblStruct xml:id="b20">
	<analytic>
		<title level="a" type="main">Using Encryption for Authentication in Large Networks of computers</title>
		<author>
			<persName><forename type="first">R</forename><surname>Needham</surname></persName>
		</author>
		<author>
			<persName><forename type="first">M</forename><surname>Schroeder</surname></persName>
		</author>
	</analytic>
	<monogr>
		<title level="j">Comm. ACM</title>
		<imprint>
			<biblScope unit="volume">21</biblScope>
			<biblScope unit="issue">12</biblScope>
			<biblScope unit="page" from="993" to="999" />
			<date type="published" when="1978">1978</date>
		</imprint>
	</monogr>
</biblStruct>

<biblStruct xml:id="b21">
	<analytic>
		<title level="a" type="main">An Attack on the Needham-Schroeder Public Key Authentication Protocol</title>
		<author>
			<persName><forename type="first">G</forename><surname>Lowe</surname></persName>
		</author>
	</analytic>
	<monogr>
		<title level="j">Information Processing Letters</title>
		<imprint>
			<biblScope unit="volume">56</biblScope>
			<biblScope unit="issue">3</biblScope>
			<biblScope unit="page" from="131" to="136" />
			<date type="published" when="1995">1995</date>
		</imprint>
	</monogr>
</biblStruct>

<biblStruct xml:id="b22">
	<analytic>
		<title level="a" type="main">Three Tier Client/Server Architecture: Achieving Scalability, Performance, and Efficiency in Client Server Applications</title>
		<author>
			<persName><forename type="first">W</forename><surname>Eckerson</surname></persName>
		</author>
	</analytic>
	<monogr>
		<title level="j">Open Information Systems</title>
		<imprint>
			<biblScope unit="volume">3</biblScope>
			<biblScope unit="issue">20</biblScope>
			<biblScope unit="page">1</biblScope>
			<date type="published" when="1995">1995</date>
		</imprint>
	</monogr>
</biblStruct>

				</listBibl>
			</div>
		</back>
	</text>
</TEI>
