<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Using the Doughnut Model to Support Sustainable Quality Requirements in iStar</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Jennifer Horko</string-name>
          <email>jennifer.horkoff@gu.se</email>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Tong Li</string-name>
          <email>litong@bjut.edu.cn</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>Technical University of Beijing</institution>
          ,
          <country country="CN">China</country>
        </aff>
      </contrib-group>
      <abstract>
        <p>Sustainability has become a critical topic, not only from an environmental perspective, but in the creation of software systems which are themselves sustainable. The sustainability literature has made use of the doughnut model from economics to understand the delicate balance needed for sustainable development. This model emphasizes the notion of having just the right amount of a resource (e.g., food, water) and not too much, else negative consequences (water depletion, starvation) may be felt by others in the ecosystem. Although iStar has covered well the notion of trade-o s between qualities (e.g. security vs. usability, performance vs. maintainability), the implicit aim of the work is always to maximize qualities. In this work we aim for \just enough" quality by applying the doughnut economic model to quality requirements in iStar. Overall, we propose a visually appealing model which emphasizes a sustainable balance between qualities.</p>
      </abstract>
      <kwd-group>
        <kwd>sustainability</kwd>
        <kwd>quality requirements</kwd>
        <kwd>quality analysis</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>Introduction</title>
      <p>
        Sustainability has become a critical topic, not only from the perspective of
environmental or natural sustainability, but in creating software systems which are
themselves sustainable [
        <xref ref-type="bibr" rid="ref1">1</xref>
        ]. Sustainability literature has made use of the
doughnut model from economics to understand the delicate balance between desired
aspects for inclusive and sustainable economic development [
        <xref ref-type="bibr" rid="ref2">2</xref>
        ]. This model
emphasizes the notion of having just the right amount of a resource (e.g., food,
water) and not too much, else negative consequences (water depletion,
starvation) may be felt by others in the ecosystem. Keeping in mind the importance of
sustainable software system development, we believe that this mindset can apply
well to the area of non-functional requirements (NFRs) and software qualities.
      </p>
      <p>
        Many methods exist to model and reason over the achievement of NFRs
and qualities (e.g., the NFR Framework [
        <xref ref-type="bibr" rid="ref3">3</xref>
        ], iStar [
        <xref ref-type="bibr" rid="ref4">4</xref>
        ], and similar frameworks).
Although this work has covered well the notion of trade-o s between qualities
(e.g. security vs. usability, performance vs. maintainability), the implicit aims
of the work is always to maximize the achievable qualities. Although previous
work deals with sati cing or satisfaction of qualities, as far as we are aware,
Copyright © 2020 for this paper by its authors. Use permitted under
Creative Commons License Attribution 4.0 International (CC BY 4.0).
existing work on requirements qualities does not consider the possibility of
oversaturation of satisfaction, having too much, or more than is needed of a
particular quality, which may have adverse e ects on other qualities (e.g., too much
usability is costly, too much performance hinders modi abilty). To create
systems which are sustainable, we should focus on \just enough" quality in various
dimensions, in line with agile thinking and the realities of business.
      </p>
      <p>
        In this work we apply the doughnut economic model to qualities in iStar.
We evaluate our idea through application to historical goal model examples,
focusing on qualities, considering changes to existing reasoning techniques. By
aiming to achieve just enough of various qualities, we argue that systems are
easier to construct and maintain, and are therefore more likely to be successful
and sustainable. Although other models for sustainable software development
have been proposed (e.g., [
        <xref ref-type="bibr" rid="ref1 ref5">1, 5</xref>
        ]) they do not speci cally focus
sustainabilityminded ways to visualize general quality requirements.
      </p>
      <p>In this paper, we brie y introduce the doughnut model in Sec. 2, then present
our ideas via an example in Sec. 3. We discuss issues such as semantics and
reasoning, including the notion of over-saturation in Sec. 4. We conclude and
describe future plans in Sec. 5.
2</p>
    </sec>
    <sec id="sec-2">
      <title>The Doughnut Economic Model</title>
      <p>
        The doughnut model combines together both planetary boundaries (climate
change, land use) with social boundaries (income, education) into one
holistic view of sustainable development [
        <xref ref-type="bibr" rid="ref2">2</xref>
        ] (see Fig. 1). In this model, the inner
boundary refers to social foundations, while the outer boundary forms the
enviollutin
o
aip
r
b
loiossdiversity
ozondeeplaleyteiorn
      </p>
      <p>acidifioccaetaionn
climate
change
ECOLOGICAL CEILING
afe and just space for hum
thes SOCIAL FOUNDATION anity</p>
      <p>water food
energy</p>
      <p>health
networks
housing</p>
      <p>SHOeRdTFuAcLaLtion
income
&amp; work
gender peace
equalitysocial politica&amp;l justice</p>
      <p>equality voice
R
E
G
EN</p>
      <p>ERAT</p>
      <p>IVE AND DISTRIBUTIVE</p>
      <p>Y</p>
      <p>M</p>
      <p>ECONO
convlearnsdion
freshwater
withdrawals</p>
      <p>SHORTFALL
lluop cehm
tno ilca
i
pniotropgheonru&amp;sloading
h s
ronmental dimensions. The idea is to nd a safe space for humanity that balances
all of these environmental and social factors. In our work, we are inspired by this
model, but adapt a simpler version to better suit quality requirements, keeping
the general principle of balance.
3</p>
    </sec>
    <sec id="sec-3">
      <title>The Doughnut Model applied to Qualities in iStar</title>
      <p>
        In order to further motivate the need for the new visualization and to
demonstrate how it would look and work in practice, we present two examples. We
start with a simple example from [
        <xref ref-type="bibr" rid="ref6">6</xref>
        ] focusing on security trade-o s, recreated
in Fig. 2a. We focus the top part of the original model, with the quality goals
(softgoals) and the functional elements (tasks and goals) which directly impact
qualities. To illustrate what a trade-o may look like we add a hurt link from
security to usability. We also add an extra security function to demonstrate
potential over saturation. We redraw this extended model using a visualization
inspired by the doughnut model, in Fig. 2b. Here we show the four qualities from
the original model as labels along the desirable inner part of the \doughnut".
We shade the doughnut segments representing the qualities di erent shades of
green, orange, and brown to re ect their level of satisfaction, for example,
security has three incoming help links, so is potentially over saturated (brown),
while usability is hurt (orange). We discuss reasoning further in Sec. 4. Speci c
colors and visual elements may have to be adjusted based on future usability
studies.
      </p>
      <p>In the second example, we recreate two of the three actors in Fig. 3a, again
focusing on qualities. Here we can see the doughnut model beginning to scale
to more qualities, in this case seven and ve. Due to the increasing number of
qualities in the doughnut, we can no longer use straight internal contribution
links as in the rst example, here we use curved green and red arrows for help
and hurt contributions within the doughnut and straight links from functional
elements to quality. Again, we indicate positive/negative via color, and severity
by link thickness (to be evaluated and improved in future studies). Here we
start to explore doughnuts in iStar actors with typical dependencies. We see the</p>
      <sec id="sec-3-1">
        <title>Employee Security</title>
      </sec>
      <sec id="sec-3-2">
        <title>Integrity Usability Confidentiality</title>
      </sec>
      <sec id="sec-3-3">
        <title>Restrict</title>
        <p>administrative
privledges</p>
        <p>Maintain
network address
integrity
Authenticate
to access
the host
Access to host
remotely
+</p>
        <p>Restrict
Administrative</p>
        <p>Privileges
Immediacy
[Services]</p>
      </sec>
      <sec id="sec-3-4">
        <title>Use Cyber</title>
        <p>Café/Portal/
Chat Room
Cyber Café/
Portal/Chat
Room Service
Immediacy
[Service]</p>
      </sec>
      <sec id="sec-3-5">
        <title>Text</title>
        <p>Messaging
Service</p>
      </sec>
      <sec id="sec-3-6">
        <title>Help As Many Kids as Possible</title>
      </sec>
      <sec id="sec-3-7">
        <title>Provide Online Counseling Services Increase</title>
      </sec>
      <sec id="sec-3-8">
        <title>Avoid Scandal</title>
      </sec>
      <sec id="sec-3-9">
        <title>Anonymity [Services]</title>
      </sec>
      <sec id="sec-3-10">
        <title>Use Text Messaging</title>
      </sec>
      <sec id="sec-3-11">
        <title>Provide counseling via text message</title>
      </sec>
      <sec id="sec-3-12">
        <title>Provide counseling via Cyber Café/Portal/ Chat Room</title>
      </sec>
      <sec id="sec-3-13">
        <title>Kids and Youth</title>
      </sec>
      <sec id="sec-3-14">
        <title>Comfortable ness with service</title>
        <p>KHP
Get Effective</p>
        <p>Help</p>
      </sec>
      <sec id="sec-3-15">
        <title>Anonymity [Service] Help be acquired</title>
      </sec>
      <sec id="sec-3-16">
        <title>Use Text Messaging Kids use Chat Room</title>
        <p>+
++
+
+
+</p>
      </sec>
      <sec id="sec-3-17">
        <title>Help As Many Kids as Possible</title>
      </sec>
      <sec id="sec-3-18">
        <title>High Quality Counselling</title>
      </sec>
      <sec id="sec-3-19">
        <title>Counsellors</title>
      </sec>
      <sec id="sec-3-20">
        <title>High Quality Counselling</title>
      </sec>
      <sec id="sec-3-21">
        <title>Listen for Cues</title>
      </sec>
      <sec id="sec-3-22">
        <title>Provide Online Counseling Services</title>
      </sec>
      <sec id="sec-3-23">
        <title>Happiness [Counsellors]</title>
      </sec>
      <sec id="sec-3-24">
        <title>Avoid Burnout</title>
      </sec>
      <sec id="sec-3-25">
        <title>Help As Many Kids as Possible</title>
      </sec>
      <sec id="sec-3-26">
        <title>Use Text</title>
        <p>Messaging</p>
      </sec>
      <sec id="sec-3-27">
        <title>Use Chat Room</title>
        <p>Counselors
Use
Chat
Room
+
+ + + +
-
-</p>
        <sec id="sec-3-27-1">
          <title>Use Text Messaging</title>
        </sec>
        <sec id="sec-3-27-2">
          <title>Provide Online Counseling</title>
          <p>common visual clutter, but there is also a clear distinction between quality and
function in the model.
4</p>
        </sec>
      </sec>
    </sec>
    <sec id="sec-4">
      <title>Semantics and Reasoning</title>
      <p>Existing descriptions of NFR or iStar/i* semantics, supporting goal reasoning,
can be adjusted to account for our proposal. Traditionally, satisfaction is thought
of on a scale from fully denied to fully satis ed, as is shown in Fig. 4a, with some
variation in the names, colors, and format of the labels. In this work, we
introduce the notion of Over-Saturation, to show that going beyond satisfaction (or
satis cing) is both possible and undesirable (see left side of Fig. 4b). We de ned
over-saturation in this case as: satisfying a quality to a degree that is more than
is necessary to achieve a desirable state. This de nition is vague by construction,
as satisfaction and over-saturation depend on the quality and context. For
example, for security, satisfaction may mean that the majority of users are happy
with the level of security provided by a system. Here even `majority' will depend
on the size of the user base, if there are only ve major customers, one
customer being dissatis ed with security is signi cant. However, if there are 1000
customers, it may be acceptable that 90% of customers are satis ed with the
system security. One can satisfy the additional 10% by adding more security
features, but this may negatively a ect cost, usability, or performance in such a
way that the overall trade-o is negative. In such a case, adding more security
interventions may lead to over-saturation.</p>
      <p>
        Existing goal model reasoning approaches such as reasoning described in the
NFR Framework [
        <xref ref-type="bibr" rid="ref3">3</xref>
        ] or iStar/i* [
        <xref ref-type="bibr" rid="ref7">7</xref>
        ] can be adjusted to account for the new
concept of over-saturation. This would mean the introduction of new labels or new
color codes. Previously, the goal model community has struggled with how to
determine whether something is fully or partially satis ed or denied (how much
is enough?), with di erent interpretations of goal models leading to di erent
procedures and semantics [
        <xref ref-type="bibr" rid="ref8">8</xref>
        ]. The question of when a quality moves from satis ed
to over-satis ed is similar, and can be dealt with in simiOlavOerrvseatrwissafatacistyfioasnct.ionFor
example, in thTehTNohFuoRguhFgrthasmtsoewnoonrSkSaatitsisffaaccttiiinootennractive approach- Lei-anLdesatd[o7snt]oo,tnsaowttissfhayitenisgnfyinga goal
and the
receives more than one source of positive evidence, one caonthoetrhqeuraqliutiaelsitiews hether the
judge
(a) Typical view of Quality Satisfaction (e.g., [
        <xref ref-type="bibr" rid="ref3 ref7">3, 7</xref>
        ])
New way with better colors? Denial vs. oversaturation?
      </p>
      <p>
        (b) New Proposal for Quality Satisfaction
Fig. 4: Satisfaction of Qualities: Old vs. New
goal is partially satis ed, satis ed, partially saturated, or over-saturated. For
other procedures, e.g., [
        <xref ref-type="bibr" rid="ref9">9</xref>
        ] where `promotion' of incoming contribution values is
not accounted for (e.g., any number of incoming partially satis ed values results
in partially satis ed), extending to support over-saturation is more challenging.
Generally, one needs either a way to `count' or quantify incoming positive
evidence, along with thresholds, to determine when a quality is too satis ed; or this
decision must be passed to users, relying on domain knowledge and expertise.
      </p>
    </sec>
    <sec id="sec-5">
      <title>Conclusions</title>
      <p>We have proposed an alternative way to visualize, think about, and reason over
quality requirements, including the notion of quality over-saturation. Through
examples, we have begun to show practical feasibility, and we have discussed
how the new concepts could in uence existing goal reasoning techniques.</p>
      <p>Future work will consider views over the model, e.g., incrementally showing
the Doughnut model elements, contribution links, contributing elements, etc.
Tooling should be adapted, ideally automatically transform existing i* or iStar
models into the new notation. We are working on an evaluate plan involving
surveys, prototypes and user studies with both iStar experts and novices. We
welcome others to participate in the use and development of these ideas.</p>
    </sec>
    <sec id="sec-6">
      <title>Acknowledgements</title>
      <p>Supported by Vetenskapsradet project \Non-Functional Requirements for
Machine Learning: Facilitating Continuous Quality Awareness (iNFoRM)".</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          1.
          <string-name>
            <given-names>S. S.</given-names>
            <surname>Mahmoud</surname>
          </string-name>
          and
          <string-name>
            <surname>I. Ahmad</surname>
          </string-name>
          , \
          <article-title>A green model for sustainable software engineering,"</article-title>
          <source>International Journal of Software Engineering and Its Applications</source>
          , vol.
          <volume>7</volume>
          , no.
          <issue>4</issue>
          , pp.
          <volume>55</volume>
          {
          <issue>74</issue>
          ,
          <year>2013</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          2.
          <string-name>
            <given-names>K.</given-names>
            <surname>Raworth</surname>
          </string-name>
          , \
          <article-title>A safe and just space for humanity: can we live within the doughnut,"</article-title>
          <source>Oxfam Policy and Practice: Climate Change and Resilience</source>
          , vol.
          <volume>8</volume>
          , no.
          <issue>1</issue>
          , pp.
          <volume>1</volume>
          {
          <issue>26</issue>
          ,
          <year>2012</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          3.
          <string-name>
            <given-names>L.</given-names>
            <surname>Chung</surname>
          </string-name>
          ,
          <string-name>
            <given-names>B. A.</given-names>
            <surname>Nixon</surname>
          </string-name>
          ,
          <string-name>
            <given-names>E.</given-names>
            <surname>Yu</surname>
          </string-name>
          , and
          <string-name>
            <given-names>J.</given-names>
            <surname>Mylopoulos</surname>
          </string-name>
          ,
          <article-title>Non-functional requirements in software engineering</article-title>
          . Springer Science &amp; Business
          <string-name>
            <surname>Media</surname>
          </string-name>
          ,
          <year>2012</year>
          , vol.
          <volume>5</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          4.
          <string-name>
            <given-names>F.</given-names>
            <surname>Dalpiaz</surname>
          </string-name>
          ,
          <string-name>
            <given-names>X.</given-names>
            <surname>Franch</surname>
          </string-name>
          , and
          <string-name>
            <given-names>J.</given-names>
            <surname>Horko</surname>
          </string-name>
          ,
          <article-title>\istar 2.0 language guide,"</article-title>
          <source>arXiv preprint arXiv:1605.07767</source>
          ,
          <year>2016</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          5.
          <string-name>
            <given-names>A.</given-names>
            <surname>Raturi</surname>
          </string-name>
          ,
          <string-name>
            <given-names>B.</given-names>
            <surname>Penzenstadler</surname>
          </string-name>
          ,
          <string-name>
            <given-names>B.</given-names>
            <surname>Tomlinson</surname>
          </string-name>
          , and
          <string-name>
            <given-names>D.</given-names>
            <surname>Richardson</surname>
          </string-name>
          , \
          <article-title>Developing a sustainability non-functional requirements framework,"</article-title>
          <source>in Proceedings of the 3rd International Workshop on Green and Sustainable Software</source>
          ,
          <year>2014</year>
          , pp.
          <volume>1</volume>
          {
          <fpage>8</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          6.
          <string-name>
            <given-names>G.</given-names>
            <surname>Elahi</surname>
          </string-name>
          and
          <string-name>
            <given-names>E.</given-names>
            <surname>Yu</surname>
          </string-name>
          , \
          <article-title>Modeling and analysis of security trade-o s{a goal oriented approach," Data &amp; Knowledge Engineering</article-title>
          , vol.
          <volume>68</volume>
          , no.
          <issue>7</issue>
          , pp.
          <volume>579</volume>
          {
          <issue>598</issue>
          ,
          <year>2009</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          7.
          <string-name>
            <given-names>J.</given-names>
            <surname>Horko</surname>
          </string-name>
          and
          <string-name>
            <given-names>E.</given-names>
            <surname>Yu</surname>
          </string-name>
          , \
          <article-title>Interactive goal model analysis for early requirements engineering,"</article-title>
          <source>Requirements Engineering</source>
          , vol.
          <volume>21</volume>
          , no.
          <issue>1</issue>
          , pp.
          <volume>29</volume>
          {
          <issue>61</issue>
          ,
          <year>2016</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          8. ||, \
          <article-title>Comparison and evaluation of goal-oriented satisfaction analysis techniques,"</article-title>
          <source>Requirements Engineering</source>
          , vol.
          <volume>18</volume>
          , no.
          <issue>3</issue>
          , pp.
          <volume>199</volume>
          {
          <issue>222</issue>
          ,
          <year>2013</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          9.
          <string-name>
            <given-names>P.</given-names>
            <surname>Giorgini</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Mylopoulos</surname>
          </string-name>
          , E. Nicchiarelli, and
          <string-name>
            <given-names>R.</given-names>
            <surname>Sebastiani</surname>
          </string-name>
          , \
          <article-title>Reasoning with goal models,"</article-title>
          <source>in International Conference on Conceptual Modeling</source>
          . Springer,
          <year>2002</year>
          , pp.
          <volume>167</volume>
          {
          <fpage>181</fpage>
          .
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>