<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Recommendations for developing safety-related systems with graphical languages</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Nick Berezowski</string-name>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Markus Haid</string-name>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Marie-Elisabeth Hartmann</string-name>
        </contrib>
        <contrib contrib-type="author">
          <string-name>CCASS Hochschule Darmstadt</string-name>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Darmstadt</string-name>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Germany</string-name>
        </contrib>
        <contrib contrib-type="author">
          <string-name>nick.berezowski</string-name>
        </contrib>
        <contrib contrib-type="author">
          <string-name>markus.haid}@h-da.de http://www.ccass.h-da.de</string-name>
        </contrib>
      </contrib-group>
      <fpage>89</fpage>
      <lpage>101</lpage>
      <abstract>
        <p>The present paper deals with the development of recommendations for the application of graphical programming languages in safetyrelated system developments. The basis for this development is the analysis of existing safety-related systems and the way in which these systems implemented in text-based programming environments meet the applicable norms and standards. Based on that a present research project analyzes how graphical programming environments can meet these requirements. The core of the project is the development and validation of recommendations for graphical programming languages to meet these applicable norms and standards, including certification bodies, professional associations, manufacturers and users. The elaboration is limited to concepts and suggestions regarding software aspects. Finally, these recommendations should be implemented and verified in the specific development environment LabVIEW.</p>
      </abstract>
      <kwd-group>
        <kwd>functional Safety</kwd>
        <kwd>safety-related Systems</kwd>
        <kwd>LabVIEWsafety</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>-</title>
      <p>1.1</p>
    </sec>
    <sec id="sec-2">
      <title>Background</title>
      <sec id="sec-2-1">
        <title>Graphical programming languages</title>
        <p>
          Graphical programming languages show a way in which algorithms and
system behavior of programs can be implemented by graphical elements and their
arrangement [
          <xref ref-type="bibr" rid="ref36">36</xref>
          ]. This paper presents these relationships mainly using the
programming language G of the development environment LabVIEW. It is a
programming environment of the manufacturer National Instruments, which started
more than 30 years ago. The language G describes a flow-controlled model [
          <xref ref-type="bibr" rid="ref7">7</xref>
          ],
similar to the usual graphic modeling using block diagrams in UML. LabVIEW
programs are called Virtual Instruments, or VIs for short. These essentially
consist of two components, the front panel containing the user interface and the
2
block diagram with the graphical program code [
          <xref ref-type="bibr" rid="ref8">8</xref>
          ]. This doesn’t translate into
other programming languages, but the graphical code is compiled directly into
machine language [
          <xref ref-type="bibr" rid="ref9">9</xref>
          ].
        </p>
        <p>
          G combines the strengths of the theoretical data flow model with the
practiceoriented principles of structured and modular programming, revealing key
features of traditional higher-level programming languages [
          <xref ref-type="bibr" rid="ref37">37</xref>
          ]. These are simple
and compound data types, static typing with strict type checking, hierarchical
and polymorphic operations, branches, case distinctions, sequences and loops
[
          <xref ref-type="bibr" rid="ref37">37</xref>
          ].
1.2
        </p>
      </sec>
      <sec id="sec-2-2">
        <title>Safety-related systems</title>
        <p>
          Safety-related systems consist of two different parts. On the one hand, a
functional hardware control to be monitored and, on the other, safety functions that
monitor the correct functioning of the overall system and initiate risk-reducing
measures [
          <xref ref-type="bibr" rid="ref11">11</xref>
          ]. Safety-instrumented functions as a link between software and
hardware represent software code that can enhance the functional safety of
hardware components by performing a risk assessment, for example, using the risk
graph method according to DIN EN ISO 12100 or ISO 61508-5 [
          <xref ref-type="bibr" rid="ref19">19</xref>
          ]. High
demands are placed on all hardware and software components [
          <xref ref-type="bibr" rid="ref26">26</xref>
          ]. A so far very
successful concept for the realization of such safety-related monitoring systems
represent programmable logic controllers which are used in the largest industrial
sectors of process, automotive, aviation and medical industry. They work
internal processes with a cyclic process-driven behavior and can be implemented in a
user interface consisting of text-based and graphical-based elements. In addition,
there are also purely text-based programming languages and corresponding
development environments, such as C, C ++ or Pascal, with which safety-related
systems can be developed [
          <xref ref-type="bibr" rid="ref35">35</xref>
          ].
1.3
        </p>
      </sec>
      <sec id="sec-2-3">
        <title>Present procedure</title>
        <p>
          The procedure for implementing applications in computer science is primarily not
standardized. Developers can choose from a variety of schematic approaches,
implementation methods, and programming languages. Assuming text-based
programming, this ultimately consists of a large amount of lines of code that are
difficult to use even in smaller projects with multiple programming library
accesses [
          <xref ref-type="bibr" rid="ref2">2</xref>
          ]. Large projects, with mainly several developers, increasingly restrict
the structural quality in terms of maintainability, modularity and extensibility,
if no other application description or handling exist [
          <xref ref-type="bibr" rid="ref2">2</xref>
          ].
        </p>
        <p>
          Textual descriptions such as text-based program code are thus a relatively poor
working basis for an efficient handling of software applications. There is a lack of
abstracting intermediate models that allow people with technical understanding
to understand the various abstraction levels and perspectives of the software,
thus allowing a gradual approximation to the application [
          <xref ref-type="bibr" rid="ref2">2</xref>
          ].
        </p>
        <p>
          Graphical programming languages for safety-related system development
3
Other industrial sectors, such as mechanical engineering, have already adapted
to the complexity of present and future machines [
          <xref ref-type="bibr" rid="ref2">2</xref>
          ]. Using CAD, the
computeraided design, two- and three-dimensional constructions could be constructed
digitally for the first time in the 50s and 60s of the last century, allowing them
to move, adapt and expand freely. Initial programs still worked with digital
drawing tables and pen output, later the accuracy of output improved due to
higher-resolution screens and printers [
          <xref ref-type="bibr" rid="ref5">5</xref>
          ]. As a result of this digital graphical
modeling, great development time savings have been made, along with higher
value solutions and lower development costs. Reasons for this can be found in the
significantly better controllability of complexity in a digital graphical framework
[
          <xref ref-type="bibr" rid="ref2">2</xref>
          ].
        </p>
        <p>
          A similar approach can be applied to software development. For example, UML,
the Unified Modeling Language, can be considered as the first step in graphical
software modeling [
          <xref ref-type="bibr" rid="ref2">2</xref>
          ]. UML uses block diagrams to describe the architecture,
the design and the implementation of a software. Through this visual modeling,
it is possible to produce universally valid structural and behavioral models of
the software. The result is a promotion of the intelligibility of the implemented
structures solely through the graphical representation [
          <xref ref-type="bibr" rid="ref4">4</xref>
          ].
        </p>
        <p>
          In view of the development in current machines, digitization, communication
and flexibility of individual components are in the foreground. Static processes
without adaptive manufacturing processes, resources and subscribers should be
a thing of the past very soon [
          <xref ref-type="bibr" rid="ref6">6</xref>
          ]. Technologically, the industry speaks from the
fourth industrial revolution. In order to network the entire corporate structure
of companies, automation systems should be no longer controlled in individual
processes but independently exchange information between different operating
areas and coordinate entire work processes [
          <xref ref-type="bibr" rid="ref21">21</xref>
          ]. Possibilities for this can be
found in the constant development of communication via the Internet, using
microcomputers. This development is also called IoT, which is the acronym for
the term Internet of Things. However, the implementation of systems mentioned
for industrial environment applications requires the use of abstracting but still
structuring programming languages [
          <xref ref-type="bibr" rid="ref26">26</xref>
          ].
        </p>
        <p>
          However, many Internet of Things applications and many Industrie 4.0
applications and implementations must also meet safety-critical requirements, so that
application standards for precisely these programming languages have become
indispensable in the safety-critical environment such as medical technology,
automation systems, the automotive industry and aerospace engineering. The
research of future electrical, electronic and programmable electronic automation
systems generally depends on the IEC 61508, which is described as the basic
standard, which is presented as the basis of all others. [
          <xref ref-type="bibr" rid="ref1">1</xref>
          ]. It covers requirements
for the entire safety lifecycle, from the concept phase through system
development and production start-up to the decommissioning of safety-related products
4
[
          <xref ref-type="bibr" rid="ref11">11</xref>
          ].
        </p>
        <p>
          The standard distinguishes between hardware and software conception, as well
as the management of a project, with all its components. An integral part of the
concept and development phases is the software architecture for safety-critical
systems. A development environment should be used to adequately support this
process by having pre-certified structures or providing guidelines [
          <xref ref-type="bibr" rid="ref11">11</xref>
          ].
Management regulations are mostly used for quality assurance, project overview
and traceability regarding tests and security features of systems and project
constellations [
          <xref ref-type="bibr" rid="ref11">11</xref>
          ]. Software rules, including programming language rules, define
how to properly handle and comply with policy values in order to create only
secure source code, and which will cause harmless consequences only [
          <xref ref-type="bibr" rid="ref11">11</xref>
          ]. In
addition to various methods for determining the safety integrity and risk analysis
of component groups, hardware regulations also specify maximum permissible
limits for developed systems [
          <xref ref-type="bibr" rid="ref11">11</xref>
          ]. Depending on the field of application, such
a system requires different limits and problem approaches, but all of them
follow the same basic designs [
          <xref ref-type="bibr" rid="ref11">11</xref>
          ]. This is the reason for the norm and guideline
development of different industries according to their own requirements in
accordance with the legal regulations of European committees. These are european
standards, so-called EN, which set the legal requirements. These technical
standards may be inaccurate, incomplete, interpretable or even obsolete, but at the
legal level represent the state of the art [
          <xref ref-type="bibr" rid="ref39">39</xref>
          ].
        </p>
        <p>
          Programming languages established in the safety-critical environment are the
text-based languages C in the area of embedded systems and IL list for
programmable logic controllers [
          <xref ref-type="bibr" rid="ref35">35</xref>
          ]. It’s about these text-based languages in a
strongly and weakly typed environment that is aligned to the norms [
          <xref ref-type="bibr" rid="ref11">11</xref>
          ]. Strongly
and weakly typed programming languages compile a large number of tests that
define the use of data types, variables, and other syntax, such as data access or
procedure calls, to ensure maximum system safety [
          <xref ref-type="bibr" rid="ref11">11</xref>
          ].
        </p>
        <p>
          Programming guidelines, such as the MISRA-C, additionally support developers
in complying with the specifications expected of certification bodies [
          <xref ref-type="bibr" rid="ref14">14</xref>
          ]. Other
environments are not allowed or used, including graphical implementation.
For the development of functionally safe software code in graphical programming
languages like G, various individual criteria can be set up, which are divided into
four consecutive categories.
        </p>
        <p>The first step is to check the syntax in a programming language. Each
programming language has its own language set and possibilities to connect different
elements or commands. If these language limitations are not met, it would not
be possible to compile into the machine language, making verification the basic
element of any programming language. Most development environments for C
or C ++ can query for syntax compliance before a program is transferred. In
graphical languages, such as G, this query can be done at every syntactic change.</p>
        <p>
          Graphical programming languages for safety-related system development
5
It therefore has equivalence to text-based languages, such as C [
          <xref ref-type="bibr" rid="ref40">40</xref>
          ].
The second step involves compliance with guidelines that represent the proven
structures for safety-related systems in various industries. Similar to the first
step it is a static code analysis. Advanced rules, such as those defined in policies
such as MISRA-C, can be used to review structural constraints. Such
programming languages are limited to a smaller language scope [
          <xref ref-type="bibr" rid="ref40">40</xref>
          ]. This is limited to
a verifiable level of complexity that precludes, for example, the use of pointers
to produce only clear traceable code. Such a set of rules in the form of
recommendations for a policy is part of the work. For this purpose, the already
proven MISRA-C Guideline was roughly compared with the LabVIEW
Development Guideline provided by the software manufacturer National Instruments
[
          <xref ref-type="bibr" rid="ref30">30</xref>
          ]. However, a direct comparison of the two is difficult, because the structure
is based on a guide to designing and implementing a project in LabVIEW, not
listed rules. VI Analyzer, a LabVIEW’s tool, can validate the design suggestions
that are made there, making it possible to analyze MISRA-C against LabVIEW
compliance. In addition, the VI Analyzer offers the possibility to develop own
tests for the static verification of the code [
          <xref ref-type="bibr" rid="ref16">16</xref>
          ]. It was noticeable that some rules
are already included in the LabVIEW Development Guideline and VI Analyser
tests [
          <xref ref-type="bibr" rid="ref15">15</xref>
          ]. Others do not need a definition, because LabVIEW has no other way
than being compliant due to the building block principle. All yellow marked
rules should be included in a new policy and should be checked for compliance
[
          <xref ref-type="bibr" rid="ref30">30</xref>
          ]. Overall, the MISRA-C defines 141 rules, of which only 121 are required.
By means of the color code, the rules to be implemented can thus be reduced
to just under one third. The remaining 40 required rules still to be implemented
are basically the pure definition of the correct LabVIEW application [
          <xref ref-type="bibr" rid="ref30">30</xref>
          ] [
          <xref ref-type="bibr" rid="ref17">17</xref>
          ].
The third step is basically to prove that the software code is running properly.
This must be ensured by assigning software code to functional requirements,
but also requires a test environment to check runtime errors and timing [
          <xref ref-type="bibr" rid="ref40">40</xref>
          ].
What software verification can look like from conceptual design to the testing
of safety-related systems in graphical programming languages is currently being
developed. Using the example of G, the tools NI RequirementsGateway and NI
UnitTestFramework could be used.
        </p>
        <p>
          The third step closes the link between static code verification, dynamic run-time
testing and quality management to the fourth step regulatory compliance. This
is only possible if design regulations, such as modularity or diversified design,
depending on the applicable standards, can be checked. The tools mentioned in
the previous paragraph are expected to provide a more general approach due to
the iteratively building complexity [
          <xref ref-type="bibr" rid="ref40">40</xref>
          ]. A comparison of individual criteria of
the standards for possible realization in graphical languages is currently being
developed.
6
2
        </p>
      </sec>
    </sec>
    <sec id="sec-3">
      <title>Future relevance</title>
      <p>
        If you consider UML instead of a modeling language as a own programming
language, it fulfills almost all requirements of graphical development. The
vocabulary of the language would consist of graphical elements which, by their wording,
describe the functionality [
        <xref ref-type="bibr" rid="ref2">2</xref>
        ]. Relations and relationships between functions and
classes could easily be analyzed and surveyed by their slightly abstracting level
of development [
        <xref ref-type="bibr" rid="ref2">2</xref>
        ]. However, this is just as the problem in the implementation.
Due to the general abstracting approach of UML it is not suitable for the
concrete implementation of complex systems even in the extended versions UML
2.0. There is a lack of a specific vocabulary or syntax [
        <xref ref-type="bibr" rid="ref2">2</xref>
        ]. Often, UML is also
run as an additional layer in parallel with the text-based project, which means
that at least two languages are spoken in a project. The problem of such system
breaks often lies in the greater complexity in project organization. If any defects
occur, this can partially or completely nullify the benefits of graphical modeling
[
        <xref ref-type="bibr" rid="ref2">2</xref>
        ]. In 2004, Martina Maier already stated that a complete expressive graphical
description language would free us from the breaking with languages and thus
advance a big step towards to controllability of complexity in software
development [
        <xref ref-type="bibr" rid="ref3">3</xref>
        ].
      </p>
      <p>
        In 2015, a research initiative launched by the CAS in Darmstadt with the
company National Instruments and other Alliance partners. This is where the term
‘LabVIEWsafety‘ emerged, which should serve as a defining element in the use
of graphical languages for programming in high-assurance system development
[
        <xref ref-type="bibr" rid="ref10">10</xref>
        ].
      </p>
      <p>Through cooperation with various alliance partners and certification authorities,
the possibility of a safety-related system development in this and other graphic
development environments is likely to emerge in the future.</p>
      <p>
        Even at the beginning of the research initiative it was noticeable that a
visualization of the program execution could considerably improve the understanding of
complex processes in some points. By means of graphical notation, software can
also be understood by non-software specialists, as it maps the function similar
to a block diagram. Such a universal and solution-neutral approach is
particularly helpful as a communication tool in the team or during prototyping with
the customer. The data flow model used here can thus be used flexibly, starting
with the design, the modeling and the simulation, over the implementation, up
to the test and the validation of the system. Difficult concepts of traditional
programming such as dynamic data structures or variables are largely eliminated.
Program execution can be done in parallel, without much effort by using special
instructions for developers. A structured programming approach is facilitated by
clear interface definition [
        <xref ref-type="bibr" rid="ref23">23</xref>
        ].
      </p>
      <p>Graphical programming languages for safety-related system development
7
3</p>
    </sec>
    <sec id="sec-4">
      <title>Problem description</title>
      <p>
        In the research and development of technical automation systems, there is a
trend to design and develop more and more complex systems with a decrease
of development times and more complex legal basic conditions. This
progressive approach of companies is mainly due to increasing demand and competitive
pressure from the continuous automation and autonomization of industrial fields
and private environmental influences. An ever increasing subarea of such
automation systems are the safety-related systems, which are set to a much higher legal
framework than conventional systems [
        <xref ref-type="bibr" rid="ref11">11</xref>
        ]. Text-based programming languages
are considered established in the context of implementing functional safety.
Evidence that graphical languages can not live up to these conditions does not exist.
Thus, a responsibility issue arises in relation to a possible further development
of safety-related software development [
        <xref ref-type="bibr" rid="ref26">26</xref>
        ].
      </p>
      <p>
        The task of the research thus also represents an comparison, based on the
standardization, between these different languages in order to create clear structures,
in terms of aptitudes in the safety-related environment, and to ensure a strict
typing of the programming language [
        <xref ref-type="bibr" rid="ref11">11</xref>
        ].
      </p>
      <p>
        Since a high degree of clarity in management and thus often long training
periods are necessary to develop complex systems in a safety-conscious way, in
text-based languages this often only allows a small group of developers. This
limits the know-how required for task and solution finding as well as potentials
for early error detection [
        <xref ref-type="bibr" rid="ref25">25</xref>
        ]. A graphical development environment can bring
significant benefits here [
        <xref ref-type="bibr" rid="ref25">25</xref>
        ].
      </p>
      <p>
        In their basic structure, conventional programming languages , whether
textbased or graphical, have few prerequisites to control such complex structures in
the Internet of Things in a clear way. Software code must always be checked for
errors and should have a well-proven compiler. [
        <xref ref-type="bibr" rid="ref23">23</xref>
        ]. There is an enormous
development effort to create a necessary modular environment for a safety-related
system [
        <xref ref-type="bibr" rid="ref24">24</xref>
        ]. A similar development effort is evident in graphic programming
languages, but according to previous analyzes better clarity and less potential for
errors should arise [
        <xref ref-type="bibr" rid="ref23">23</xref>
        ].
      </p>
      <p>
        In addition to the industrial development, programming languages continue to
evolve. In 4th generation languages, a high level of abstraction can be achieved
through modular design and easy-to-use tools, which can be quickly understood
by inexperienced developers and checked for accuracy or extensibility [
        <xref ref-type="bibr" rid="ref22">22</xref>
        ]. The
principle of a strong abstraction in complex working modules basically enables all
people with technical understanding to have access to the programmatic
development of programmable electronic systems, especially in the graphical framework
[
        <xref ref-type="bibr" rid="ref23">23</xref>
        ]. Part of the research work will be the exploration and development of such
a higher abstraction level for the safety-related environment in graphical
programming languages using the example of LabVIEW.
8
      </p>
      <p>
        For very specific safety-critical systems, such as those required for medical
devices or individual process plants, reliable, fast and inexpensive design methods
are still lacking. There are already products that have been largely realized with
programmable logic controllers. However, these are very expensive in small
quantities, since there is little combination with components of other manufacturer
product ranges. There is a lack of a viable alternative for custom machine
design in the industry that could be created through a modular iterative approach
[
        <xref ref-type="bibr" rid="ref27">27</xref>
        ]. Findings from previous drafts in the text-based and graphical environment
should serve to build higher levels of abstraction for graphical system modeling
and implementation.
      </p>
      <p>
        Safety functions provide a link between software and hardware. According to
DIN EN ISO 12100, the central standard for risk assessment in the safety-related
area, a safety functions is a function of a machine whose failure can directly
increase the risk. They represent software code that can increase the functional
safety of hardware components by means of a risk assessment. The extent to
which the use of a safety function actually minimizes the risk can be determined
by means of the risk graph method according to DIN EN ISO 12100 or
according to ISO 61508-5 [
        <xref ref-type="bibr" rid="ref19">19</xref>
        ] [
        <xref ref-type="bibr" rid="ref11">11</xref>
        ]. Such certification for risk assessment for graphical
program code does not exist yet, without evidence of inability.
      </p>
      <p>
        A means of program verification of software code is a formal method. It helps
to ensure compliance with legal standards by verifying the accuracy of the
algorithms and not just subordinating them to testing. Examples of formal methods
can be found in symbolic program execution, as well as the method of pre- and
post-conditions according to Hoare [
        <xref ref-type="bibr" rid="ref38">38</xref>
        ]. The extent to which these methods can
be used in graphic development has not been examined yet. It must be developed
a program verification for graphical program code.
4
      </p>
    </sec>
    <sec id="sec-5">
      <title>Objective</title>
      <p>
        The project is dedicated to the topic of using graphical programming languages
for safety-related system development for various reasons. On the one hand,
the increasingly complex safety-critical system structures of systems to be
automated create the need for further development of development environments and
programming languages for the application of current, but also new structures
for module-based clear systems in the IoT and Industry 4.0 [
        <xref ref-type="bibr" rid="ref11">11</xref>
        ]. The work does
not pretend to solve current problems immediately, but plans new approaches
for graphical system architectures to create comparisons to current approaches.
This may be useful for demonstrating operational reliability, as sub-architectures
from earlier safety-related constructs could be used.
      </p>
      <p>On the other hand, some approaches of the current industry and its standards
are already outdated and thus increasingly difficult to reconcile with the latest
developments in the direction of IoT. Some do not provide a graphical
devel</p>
      <p>
        Graphical programming languages for safety-related system development
9
opment approach or can be difficult to apply to graphical languages such as
LabVIEW. Although such guidelines and standards are updated in committees
every few years, they still rely on the same approaches in current releases [
        <xref ref-type="bibr" rid="ref11">11</xref>
        ]
[
        <xref ref-type="bibr" rid="ref18">18</xref>
        ] [
        <xref ref-type="bibr" rid="ref14">14</xref>
        ]. Graphical, well-structured programming tools, could take away an
essential level of complexity and thus allow the creation of more complex projects,
sometimes with the help of inexperienced developers. In addition, a graphical
approach also helps to avoid program code errors, such as misspelling or
forgetting to include libraries, as these are simply not possible [
        <xref ref-type="bibr" rid="ref24">24</xref>
        ].
      </p>
      <p>
        By demonstrating and restricting various approaches in a new graphical
programming language policy, using LabVIEW as an example, and certifying it,
graphic software and hardware manufacturers can legally secure themselves in
relation to the various provisions in the standards and provide an additional
incentive for researchers and developers of safety-critical systems for the
selection of graphical development environments for implementation [
        <xref ref-type="bibr" rid="ref27">27</xref>
        ]. A complete
new guideline development also creates the opportunity for a better orientation
towards future-oriented technology and architectural designs. The aim of this
research is to develop recommendations for such a directive, as actual
implementation is only possible through close cooperation between manufacturers,
certification bodies and the various industrial sectors.
5
      </p>
    </sec>
    <sec id="sec-6">
      <title>Summary</title>
      <p>
        Guidelines, such as the MISRA-C and C ++, consist of a list of rules for safe and
consistent programming in the programming languages. The purpose is the
simple verifiability of certification bodies. Projects created under this policy thus
comply with all legal regulations of the software, by strictly typing the
programming algorithms [
        <xref ref-type="bibr" rid="ref14">14</xref>
        ]. In order to guarantee a scientific gain of knowledge,
the guidelines of Design Science Research (DSR) will be used as a
methodological framework for the processing of the presented research questions [
        <xref ref-type="bibr" rid="ref32">32</xref>
        ].
In general, already established, fundamental theories and practices are applied,
adapted, abstracted or combined in order to generate concepts for solving
existing application-related knowledge gaps [
        <xref ref-type="bibr" rid="ref31">31</xref>
        ] [
        <xref ref-type="bibr" rid="ref33">33</xref>
        ]. The research is not intended to
develop a completely new technology and approach for safety-related systems,
but also to examine the existing approaches with regard to their applicability in
future machine structures, in order to make optimal use of the potentials of
previous architectures for future visionary automation applications. The usability
of the developed solution concept and the scientifically grounded approach to
the preservation of this concept is thereby secured by the iterative research
process provided by the DSR [
        <xref ref-type="bibr" rid="ref33">33</xref>
        ]. In addition, the already existing approaches are
adapted to the efficient development of the overall architecture. The procedure
for splitting the problem into subproblems in order to be able to break down the
complexity is called Method Engineering [
        <xref ref-type="bibr" rid="ref34">34</xref>
        ].
      </p>
      <p>A next step is a further examination of the existing standards from the given
10
areas and a comparative analysis between graphical and text-based code, as
well as various graphical programming languages. In addition to the software
architecture, special emphasis must be placed on the hardware, which must be
fundamentally divided into different artifacts. Further steps include
recommendations for developing current and exploration of new standards and guidelines
for graphical programming languages, which could include the creation of
proprietary software architectures, security libraries, qualification tools and code
analysis tools.</p>
      <p>Basically, the total cost of creating safety-related software is divided into two
subcategories that are interdependent. These are the joint creation of guidelines
by graphical software and hardware manufacturers and our research institute,
which will later help guarantee easy certification with graphical languages
created safety-related software. The basic prerequisite for this is, first of all, the
certification of the development environment in order to prove that all the
necessary requirements are met. Beginnings of the analysis can be found in chapter
Present procedure.</p>
      <p>
        In order to presuppose on the legal level that all specifications are adhered to in
the current development environment, a pre-certification of existing
functionalities is an option. Special emphasis should be placed on the basic level of such
languages, which usually contain all components of more complex functionalities
[
        <xref ref-type="bibr" rid="ref15">15</xref>
        ]. Thus, referring to the research aspect, it is derived from a presentation of
these towards certification bodies, for concrete analysis.
      </p>
      <p>The observation and reworking of concrete methods and methods for assessing
the adaptation of graphical programming structures is an essential part of the
data collection to be created in the first steps. For example, expert interviews
with persons involved in the certification selection process represent a further
survey method in order to gain an overview of the requirements of individual
devices with regard to the certification bodies. Document and content analyzes
of the industry-specific standards to be investigated in the course of research
projects are to be used to find solutions for a wide range of safety-related,
electronically programmable devices.</p>
      <p>
        High standards of clarity and traceability are also set for the programming
technology. Some of these are already very detailed in the LabVIEW Development
Guideline on the example of LabVIEW [
        <xref ref-type="bibr" rid="ref15">15</xref>
        ]. However, there are some limitations
to interrupts and recursions, exclusion criteria for using dynamic variables, and
static verification methods needed in the safety-related part of programming [
        <xref ref-type="bibr" rid="ref14">14</xref>
        ].
There is a lack of framework conditions for the use of graphical programming
languages for the development of safety-related electronically programmable
systems. This creates a need to evolve safety-critical code into the graphical
environment [
        <xref ref-type="bibr" rid="ref28">28</xref>
        ]. So far, there are neither legal nor systemic requirements to fulfill
this goal.
      </p>
      <p>Graphical programming languages for safety-related system development
11
12</p>
      <p>N. Berezowski et al.</p>
      <p>Graphical programming languages for safety-related system development
13</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          1.
          <string-name>
            <surname>Braband</surname>
            ,
            <given-names>J.: Funktionale</given-names>
          </string-name>
          <string-name>
            <surname>Sicherheit</surname>
          </string-name>
          . https://link.springer.com/content/pdf/10.1007%
          <fpage>2F978</fpage>
          -
          <fpage>3</fpage>
          -
          <fpage>540</fpage>
          -31707-4 14.pdf.
          <source>Last accessed 13.10</source>
          .2018
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          2.
          <string-name>
            <surname>Maier</surname>
            ,
            <given-names>M.:</given-names>
          </string-name>
          <article-title>UML: Sta¨rken und Schw¨achen der grafischen Modellierung</article-title>
          . https://www.tecchannel.de/a/uml
          <article-title>-staerken-und-schwaechen-der-grafischenmodellierung</article-title>
          .
          <source>Last accessed 10.10</source>
          .2018
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          3.
          <string-name>
            <surname>Maier</surname>
            ,
            <given-names>M.:</given-names>
          </string-name>
          <article-title>UML: Sta¨rken und Schw¨achen der grafischen Modellierung</article-title>
          . https://www.tecchannel.de/a/uml
          <article-title>-staerken-und-schwaechen-der-grafischenmodellierung</article-title>
          .pp.
          <volume>3</volume>
          ,
          <string-name>
            <surname>Chapter</surname>
            <given-names>3</given-names>
          </string-name>
          , last paragraph.
          <source>Last accessed 10.10</source>
          .2018
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          4.
          <string-name>
            <surname>Petre</surname>
            ,
            <given-names>M.:</given-names>
          </string-name>
          <article-title>UML in practice</article-title>
          . https://ieeexplore.ieee.org/document/6606618. Last accessed
          <volume>15</volume>
          .10.2018
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          5. MiSUMi. Die Geschichte des CAD. https://de.misumi-ec.com/de/customer-service/
          <article-title>blog-beitragsleser/computer-aideddesign-teil-1-die-anfaenge-der-konstruktionszeichnungen</article-title>
          .
          <source>Last accessed 11.10</source>
          .2018
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          6.
          <string-name>
            <surname>Weyrich</surname>
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Ebert</surname>
            ,
            <given-names>C.</given-names>
          </string-name>
          :
          <article-title>Reference Architectures for the Internet of Things</article-title>
          . https://www.researchgate.net/publication/288855901
          <article-title>Reference Architectures for the Internet of Things</article-title>
          .
          <source>Last accessed 15.11</source>
          .2018
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          7. National Instruments: International Directory of Company Histories. Vol.
          <volume>22</volume>
          .
          <string-name>
            <surname>St</surname>
          </string-name>
          . James Press (
          <year>1998</year>
          ). http://www.fundinguniverse.com/company-histories/national-instrumentscorporation-history/.
          <source>Last accessed 13.10</source>
          .2018
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          8.
          <string-name>
            <given-names>National</given-names>
            <surname>Instruments</surname>
          </string-name>
          : Grundlagen zur LabVIEW-Umgebung http://www.ni.com/getting-started/labview-basics/d/environment.
          <source>Last accessed 13.10</source>
          .2018
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          9.
          <string-name>
            <given-names>National</given-names>
            <surname>Instruments</surname>
          </string-name>
          :
          <article-title>Wie funktioniert der Compiler von NI LabVIEW?</article-title>
          . http://www.ni.com/tutorial/11472/de/.
          <source>Last accessed 13.10</source>
          .2018
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          10. H.Z.:
          <article-title>Auf dem Weg zu Labview Safety</article-title>
          . www.etz.de, VDE Verlag,
          <volume>10</volume>
          /
          <year>2015</year>
          . ftp://ftp.ni.com/pub/branches/germany/2015/artikel/11- november/09 Auf dem
          <article-title>Weg zu-LabVIEW Safety Ronald Heinze etz 10</article-title>
          <year>2015</year>
          .pdf.
          <source>Last accessed 20.10</source>
          .2018
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          11.
          <string-name>
            <surname>Funktionale</surname>
          </string-name>
          <article-title>Sicherheit sicherheitsbezogener elektrischer/elektronischer/programmierbarer elektronischer Systeme - Teil 1 bis Teil 10 (IEC 61508:</article-title>
          <year>2010</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          12.
          <string-name>
            <surname>Hilderman</surname>
          </string-name>
          , V.:
          <string-name>
            <surname>Understanding</surname>
            <given-names>DO</given-names>
          </string-name>
          -178C
          <source>Software Certification: Benefits Versus Costs</source>
          . https://ieeexplore.ieee.
          <source>org/document/6983815. 11.10</source>
          .2018
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          13.
          <source>Richtlinie</source>
          <year>2006</year>
          /42/EG des Europa¨
          <article-title>ischen Parlaments und des Rates vom 17</article-title>
          .
          <article-title>Mai 2006 u¨ber Maschinen und zur A¨nderung der</article-title>
          <source>Richtlinie</source>
          <volume>95</volume>
          /16/EG (Neufassung). http://eur-lex.europa.eu/legal-content/DE/TXT/PDF/?uri=
          <source>CELEX:32006L0042&amp; from=EN. Last accessed 10.07</source>
          .2015
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          14.
          <string-name>
            <surname>MISRA C+</surname>
          </string-name>
          <article-title>+:2008 Guidelines for the use of the C++ language in critical systems</article-title>
          . http://frey.notk.org/books/MISRA-Cpp-
          <year>2008</year>
          .pdf.
          <source>Last accessed 07.07</source>
          .2015
        </mixed-citation>
      </ref>
      <ref id="ref15">
        <mixed-citation>
          15. National Instruments: LabVIEW Development Guideline http://www.ni.com/pdf/manuals/321393d.pdf.
          <source>Last accessed 08.07</source>
          .2015
        </mixed-citation>
      </ref>
      <ref id="ref16">
        <mixed-citation>
          16.
          <string-name>
            <surname>National</surname>
          </string-name>
          <article-title>Instruments: USER GUIDE LabVIEW VI Analyzer Toolkit http</article-title>
          ://www.ni.com/pdf/manuals/373631d.pdf.
          <source>Last accessed 30.12</source>
          .2018
        </mixed-citation>
      </ref>
      <ref id="ref17">
        <mixed-citation>
          17.
          <string-name>
            <given-names>MISRA</given-names>
            <surname>Safety</surname>
          </string-name>
          <article-title>Analysis</article-title>
          . http://www.misra.org.uk/Activities/MISRASafetyAnalysis/tabid/92/Default.aspx.
          <source>Last accessed 08.07</source>
          .2015
        </mixed-citation>
      </ref>
      <ref id="ref18">
        <mixed-citation>
          18.
          <string-name>
            <surname>Klein</surname>
          </string-name>
          , G.:
          <article-title>Funktionale Sicherheit nach DIN EN 61511</article-title>
          . http://www.tuev-sued-stiftung.de/uploads/images/1339742016358384280324/ funktionalesicherheit-61511.pdf.
          <source>Last accessed 04.09</source>
          .2015
        </mixed-citation>
      </ref>
      <ref id="ref19">
        <mixed-citation>
          19.
          <string-name>
            <surname>Sicherheit</surname>
          </string-name>
          von Maschinen - Allgemeine Gestaltungsleitsa¨tze. https://www.beuth.de/de/norm/din-en-iso-
          <volume>12100</volume>
          /128264334. Last accessed
          <volume>12</volume>
          .10.2018
        </mixed-citation>
      </ref>
      <ref id="ref20">
        <mixed-citation>
          20. W¨ohner, M.:
          <article-title>Sicher programmieren auf Basis der IEC 61131-3</article-title>
          . https://www.computer-automation.de/steuerungsebene/safetysecurity/artikel/88378/. Last accessed
          <volume>31</volume>
          .09.2015
        </mixed-citation>
      </ref>
      <ref id="ref21">
        <mixed-citation>
          21.
          <source>Was ist Industrie 4</source>
          .0?. https://www.plattform-i40.de/I40/Navigation/DE/Industrie40/WasIndustrie40/wasist-industrie-
          <volume>40</volume>
          .html,
          <source>Last accessed 14.10</source>
          .2018
        </mixed-citation>
      </ref>
      <ref id="ref22">
        <mixed-citation>
          22.
          <string-name>
            <surname>Yamamoto</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Kawasaki</surname>
            ,
            <given-names>R.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Nagaoka</surname>
            <given-names>M.:</given-names>
          </string-name>
          <article-title>VGUIDE: 4GL application platform for large distributed information systems</article-title>
          . https://ieeexplore.ieee.org/document/545880; Last Accessed15.
          <fpage>10</fpage>
          .2018
        </mixed-citation>
      </ref>
      <ref id="ref23">
        <mixed-citation>
          23.
          <string-name>
            <surname>Schmid</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          : Kreativita¨t entfesseln. Embedded - Softwareentwicklung fu¨r Cyber - Physical
          <string-name>
            <surname>Systems</surname>
          </string-name>
          . iX Developer - Embedded
          <string-name>
            <surname>Software</surname>
          </string-name>
          (
          <volume>2</volume>
          /
          <year>2014</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref24">
        <mixed-citation>
          24.
          <string-name>
            <surname>Schmid</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          :
          <article-title>Cyber - Physical Systems ganz konkret. Eine neue Generation smarter, dezentraler und vernetzter Embedded Systems erfordert neue Denkweisen und Entwicklungsmethoden</article-title>
          .
          <source>ELEKTRONIKPRAXIS Embedded Software Engineering Report (Nr. 7</source>
          ,
          <year>2014</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref25">
        <mixed-citation>
          25.
          <string-name>
            <surname>Schmid</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          : Entwicklungsbeschleuniger:
          <article-title>Zeit als neue Wa¨hrung (Teil 1). Ausfu¨hrbare Rechenmodelle in einem heterogenen Aktor - Framework unterstu¨tzen unsere Denkweise und beschleunigen die Entwicklung von Timing in Embedded - Software</article-title>
          .
          <source>ELEKTRONIKPRAXIS Embedded Software Engineering Report (Februar</source>
          <year>2015</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref26">
        <mixed-citation>
          26.
          <string-name>
            <surname>Rahman</surname>
          </string-name>
          , J.:
          <article-title>Sensors need to evolve to make Industry 4.0 workable</article-title>
          . Control Engineering Europe (
          <volume>04</volume>
          .
          <fpage>11</fpage>
          .
          <year>2014</year>
          ). http://www.controlengeurope.com/article/87387/Sensors-need
          <article-title>-to-evolve-to-makeIndustry-4-0workable</article-title>
          .aspx.
          <source>Last accessed 16.04</source>
          .2018
        </mixed-citation>
      </ref>
      <ref id="ref27">
        <mixed-citation>
          27.
          <string-name>
            <surname>Rahman</surname>
          </string-name>
          , J.:
          <article-title>Fu¨nf Kerntechnologien treiben das Internet of Things voran</article-title>
          .
          <source>Markt &amp; Technik (18.12</source>
          .
          <year>2014</year>
          ). http://www.elektroniknet.de/markt-technik/industrie-40
          <article-title>-iot/fuenfkerntechnologien-treiben-das-internet-of-things-voran-115696.html</article-title>
          .
          <source>Lastt accessed 16.04</source>
          .2018
        </mixed-citation>
      </ref>
      <ref id="ref28">
        <mixed-citation>
          28.
          <string-name>
            <surname>Rahman</surname>
          </string-name>
          , J.:
          <article-title>Beyond IoT: 2015 is the year of Industry 4.0</article-title>
          .
          <string-name>
            <given-names>Electronics</given-names>
            <surname>Weekly</surname>
          </string-name>
          (
          <volume>06</volume>
          .
          <fpage>01</fpage>
          .
          <year>2015</year>
          ). https://www.electronicsweekly.com/blogs/viewpoints/beyond-iot-2015
          <source>-yearindustry-4-0-2015-01/. Last accessed 16.04</source>
          .2018
        </mixed-citation>
      </ref>
      <ref id="ref29">
        <mixed-citation>
          29.
          <string-name>
            <surname>Berezowski</surname>
          </string-name>
          , N.:
          <article-title>High-Assurance System Development with LabVIEW. Masterthesis zur Erlangung des akademischen Grades Master of Science an der Hochschule Darmstadt (</article-title>
          <year>2015</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref30">
        <mixed-citation>
          30.
          <string-name>
            <surname>Berezowski</surname>
          </string-name>
          , N.:
          <article-title>High-Assurance System Development with LabVIEW. 18</article-title>
          . GMA/ITG-Fachtagung
          <source>Sensoren und Messsysteme</source>
          <year>2016</year>
          . https://www.ama-science.
          <source>org/proceedings/details/2426. Last accessed 12.10</source>
          .2018
        </mixed-citation>
      </ref>
      <ref id="ref31">
        <mixed-citation>
          31.
          <string-name>
            <surname>Hevner</surname>
            ,
            <given-names>A. R.</given-names>
          </string-name>
          ; March, S. T.,
          <string-name>
            <surname>Park</surname>
          </string-name>
          , J.:
          <source>Design Science in Information Systems Research. MIS Quarterly</source>
          Vol.
          <volume>28</volume>
          No.
          <issue>1</issue>
          , pp.
          <fpage>75</fpage>
          -
          <lpage>105</lpage>
          (
          <year>March 2004</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref32">
        <mixed-citation>
          32.
          <string-name>
            <surname>Venable</surname>
            ,
            <given-names>J. R.:</given-names>
          </string-name>
          <article-title>A framework for design science research activities</article-title>
          .
          <source>Proceedings of the 2006 Information Resource Management Association Conference (CD)</source>
          , Washington, DC, USA,
          <fpage>21</fpage>
          -
          <lpage>24</lpage>
          May
          <year>2006</year>
          , Idea Group Publishing, Hershey, Pennsylvania, USA
        </mixed-citation>
      </ref>
      <ref id="ref33">
        <mixed-citation>
          33.
          <string-name>
            <surname>Vaishnavi</surname>
            ,
            <given-names>V.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Kuechler</surname>
            ,
            <given-names>W.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Petter</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          : Design Science Research in Information Systems. http://www.desrist.org/design-research
          <article-title>-in-information-systems/</article-title>
          .
          <source>Last accessed 10.10</source>
          .2018
        </mixed-citation>
      </ref>
      <ref id="ref34">
        <mixed-citation>
          34.
          <string-name>
            <surname>Agh</surname>
            ,
            <given-names>H.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Ramsin</surname>
            ,
            <given-names>R.:</given-names>
          </string-name>
          <article-title>A pattern - based model - driven approach for situational method engineering</article-title>
          .
          <source>Information and Software Technology</source>
          ,
          <volume>78</volume>
          , pp.
          <fpage>95</fpage>
          -
          <lpage>120</lpage>
        </mixed-citation>
      </ref>
      <ref id="ref35">
        <mixed-citation>
          35.
          <string-name>
            <surname>Huelke</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          :
          <article-title>Sicherheitsbezogene Anwendungssoftware von Maschinen</article-title>
          .
          <source>IFA Report 2/2016</source>
          , pp.
          <fpage>13</fpage>
          -
          <lpage>15</lpage>
        </mixed-citation>
      </ref>
      <ref id="ref36">
        <mixed-citation>
          36.
          <string-name>
            <surname>Lehrerfortbildung</surname>
          </string-name>
          Baden-Wortemberg. Visuelle Programmierung. https://lehrerfortbildung-bw.de/u matnatech/informatik/gym/bp2016/fb1/2 algorithmen/1 hintergrund/2 hintergrund/1 visuell/.
          <source>Last accessed 18.10</source>
          .2018
        </mixed-citation>
      </ref>
      <ref id="ref37">
        <mixed-citation>
          37.
          <string-name>
            <surname>Andrade</surname>
            ,
            <given-names>H. A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Kovner</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          :
          <article-title>Software Synthesis from Dataflow Models for G and LabVIEW</article-title>
          . http://users.ece.utexas.edu/˜bevans/professional/ asilomar98/hugoscott.pdf.
          <source>Last access 18.10</source>
          .2018
        </mixed-citation>
      </ref>
      <ref id="ref38">
        <mixed-citation>
          38.
          <string-name>
            <surname>Halang</surname>
            ,
            <given-names>W. A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Konakovsky</surname>
            ,
            <given-names>R. M.:</given-names>
          </string-name>
          <article-title>Einige formale Methoden zur Programmverifikation</article-title>
          . Sicherheitsgerichtete Echtzeitsysteme pp
          <fpage>269</fpage>
          -
          <lpage>306</lpage>
        </mixed-citation>
      </ref>
      <ref id="ref39">
        <mixed-citation>
          39.
          <string-name>
            <surname>Wilrich</surname>
            ,
            <given-names>T.</given-names>
          </string-name>
          :
          <article-title>Die rechtliche Bedeutung technischer Normen als Sicherheitsmaßstab</article-title>
          . pp.
          <fpage>3</fpage>
          -
          <lpage>29</lpage>
          , Beuth Recht
        </mixed-citation>
      </ref>
      <ref id="ref40">
        <mixed-citation>
          40.
          <string-name>
            <surname>Lalo</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          :
          <article-title>Embedded Software Verification for IEC 61508</article-title>
          and ISO 26262. https://de.mathworks.com/videos/embedded
          <article-title>-software-verification-for-</article-title>
          <string-name>
            <surname>iec-</surname>
          </string-name>
          61508
          <string-name>
            <surname>-</surname>
          </string-name>
          and-iso-
          <volume>26262</volume>
          -81727.html?elqsid=1548418121128&amp;
          <string-name>
            <surname>potential</surname>
            <given-names>use</given-names>
          </string-name>
          =
          <source>Education. Last accessed 3</source>
          .
          <fpage>10</fpage>
          .2018
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>