<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Formal Verification of Context Aware Systems</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>DEIB - Politecnico di Milano</string-name>
        </contrib>
        <contrib contrib-type="author">
          <string-name>fabio.schreiber@polimi.itg</string-name>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>DEI - University of Padova</institution>
        </aff>
      </contrib-group>
      <abstract>
        <p>This discussion paper introduces a modeling technique, based on Boolean Control Networks, for assessing useful properties of Context Aware systems. Indeed, Context Aware systems are becoming useful components in autonomic and monitoring applications and the assessment of their properties is an important step towards reliable implementation, especially in safety-critical applications.</p>
      </abstract>
      <kwd-group>
        <kwd>Boolean Control Networks (BCN) Context Aware Systems Fault detection Formal properties Pervasive Systems Reconstructibility Stability assessment</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>-</title>
      <p>mechanical systems.</p>
      <p>Stability is a traditional topic in control systems theory, and in [8] the authors explore
“... the extent to which control theory can provide an architectural and analytic
foundation for building self-managing systems ...”. However, control systems are typically
described by means of differential equations and by Matrix Algebra, while C-A
systems are digital and mostly based on Logics. Inspired by biological systems, Boolean
Networks (BN) and Boolean Control Networks (BCN) have been introduced, their
representative equations have been converted into an equivalent algebraic form, and
solutions to problems such as controllability, observability, stability and reconstructibility
have been proposed [3, 10, 12].</p>
      <p>In Section 2 the case study is outlined. In Section 3, we show how, by making use
of the algebraic approach to Boolean Control Networks, it is possible to formalize, by
means of a C-A system, a decision process to avoid hydrogeological disasters, as the
one that happened in Abruzzo, where a hotel was hit by an avalanche [16], as well as
false alarms. We can then assess the existence of globally attractive equilibrium points
of the overall system, corresponding to constant inputs, and investigate some
interesting structural properties such as observability and reconstructibility that formalize
system features of great practical relevance. Moreover, the possibility of identifying some
kinds of faults in the inputs, that could result in errors in the alarm system, is examined.
Sections 4 and 5 respectively describe the results of the analysis and possible future
developments.</p>
      <p>To conclude, we think that cooperation between C-A computing and Control
Systems theory can be fruitful to fill in the model gap.
2</p>
    </sec>
    <sec id="sec-2">
      <title>The architecture of the monitoring system</title>
      <p>Figure 1 shows the architecture of a C-A system [2, 7] conceived for monitoring
possible snow/ground slides. Signals, coming from physical sensors on the ground, are
evaluated in the context of the seismic and meteorological information provided by
Web Services RSSs - which can suggest immediate danger - in order to issue alarms.
The integration of data from the Context state with the actual physical data that are
input to the functional system allows the design of a flexible and effective prevention
information system which, as an example, can distinguish between the vibration caused
by the detachment of a snow mass and the one caused by a skier or a deer occasionally
passing near a sensor.</p>
      <p>In the monitoring system some states produce outputs that can affect the
environment, e.g. by possibly activating an alarm siren. In case of an alarm, the time to evacuate
a hotel can be in the order of hours, while the seismic and meteorological conditions can
change faster. The ultimate goal of this study is to be sure that, in dangerous situations,
an alarm signal is issued, but at the same time that frequent changes in the Context State
do not induce an oscillatory behavior of the alarm system and the resulting movement
of people out and back into the hotel; the designer of the C-A system must ensure that
no action is started before the preceding one is terminated. In this paper we use a
simple open-loop model; however, in more complex C-A self managing applications, the
system output can affect the context itself.</p>
      <p>Our aim is therefore:
– To describe a C-A system, as in Figure 1, by means of a logic State Space model:
web services provide input messages to the Context and sensors provide input
signals to the Monitoring System; the Context state is a further input to the latter.
– To use BCNs and System Theory tools to asses properties of a C-A system such as:
the existence of globally stable equilibrium points and the absence of oscillatory
behaviors (limit cycles) under constant inputs; the reconstructibility of the system
and the detection of some faults affecting the C-A system inputs.</p>
      <sec id="sec-2-1">
        <title>CONTEXT</title>
        <p>terrain temp.
snow height
accelerometer</p>
      </sec>
      <sec id="sec-2-2">
        <title>MONITORING</title>
        <p>SYSTEM</p>
        <p>alarm</p>
        <p>Although the following analysis refers to the case study, the proposed approach is
quite general and can be applied whenever properties should be proved in C-A dynamic
systems.
3</p>
      </sec>
    </sec>
    <sec id="sec-3">
      <title>The BCN Model of the Hydrogeological Example</title>
      <p>In [16] a short introduction to the algebraic representation of Boolean Control Networks
can be found; in the following we introduce the BCN model of our example case.
3.1</p>
      <sec id="sec-3-1">
        <title>The Context model</title>
        <p>Context Input Variables The values of the Context Input Variables are supplied by
RSS messages coming from National Web Services, such as Meteorological forecasts
and the National Geophysics Institute. Even if the message frequency can be variable,
for ease of modeling, we suppose that the system samples them with the same constant
frequency. Moreover, we suppose that a real danger situation can be expected only when
a defined number - in our example at least four - of consecutive earthquake
announcements are sent together with a snow forecast.</p>
        <p>We assume:</p>
        <p>INGVfearthquake; :earthquakeg := U1</p>
        <p>METEOfsnow; :snowg :=U2
Therefore, by expressing the context input variables in terms of canonical vectors, we
get:</p>
        <p>Context States As previously mentioned, we assume that simultaneous snow and
earthquake alerts can be regarded as reliable only if not isolated, namely if a
sufficiently high number of consecutive (simultaneous) alerts are sent (and received). For
this reason we introduce as Context State a counter: COUNTERf0; 1; 2; 3; &gt; 3g =: C
In the representation by means of canonical vectors, the counter is denoted by c and
d 1; d52; d53; d54; d55g, depending on how many consecutive
simultakes values in D5 := f 5
taneous alerts for snow and earthquake have been received. Specifically, for i = 1; 2; 3; 4,
we have that c(t) = d5i if the counter is i 1 at time t, while c(t) = d55 if the counter is
d 1; d52; d53; d54g and the context
at least 4 at time t. If the counter at time t has a value in f 5
input is u(t) = d41 (another simultaneous snow and earthquake alert comes in), then the
counter value at t + 1 is increased by 1. If c(t) = d55 and u(t) = d41, then c(t + 1) = d55,
while in every other case the counter is reset to c(t + 1) = d 1.
5
Therefore, the counter updates according to the following model (BCN):
c(t +1) = Cnu(t)nc(t), where n denotes the semi-tensor product, C = C1 C2 C3 C4 2
20, and
L5 20, the set of logic matrices of size 5
C1 = C n d41 = [d52 d53 d54 d55 d 5]</p>
        <p>5
C2 = C n d42 = [d51 d51 d51 d51 d51]
C3 = C n d43 = C2
C4 = C n d44 = C2
Obviously, the number of consecutive alert situations is a design variable which allows
to set stricter - if increased - or loser - if lowered - requirements on the alarm system.
Context Output Introduce the Context model output</p>
        <p>CONTEXT-ALERTfdanger; quietg := Uc
Since we assume that the CONTEXT-ALERT variable Uc is danger (the corresponding
canonical vector uc takes the value d21) if and only if there have been at least four
simultaneous snow and earthquake alerts, the variable uc is updated following the algebraic
rule:
uc(t) = Hc n c(t) where
Hc = d22 d22 d22 d22 d21 2 L2 5</p>
        <p>This is one possible solution, but it may be regarded as somewhat dangerous: if the counter
is erroneously reset, then the alert ends up being significantly delayed. An alternative solution
could be that of simply decreasing the counter by one if u(t) 6= d41 (or if u(t) = d4i ; i = 2; 3). This
solution would be more robust to possible disturbances occasionally affecting the context inputs.
C=δ51
C=δ55
δ41</p>
        <p>C=δ52</p>
        <p>δ41</p>
      </sec>
      <sec id="sec-3-2">
        <title>3.2 The Functional System model</title>
        <p>Functional System Input Variables We assume that, in addition to the
CONTEXTALERT variable, the Functional System model receives three more input signals from
local sensors, so that, at the end, the Input Vector v(t) 2 D16 is composed by the
following variables determining the system dynamics:
terrain temperature fhigh; lowg := V1
snow height fhigh; lowg := V2
accelerometer fhigh; lowg := V3
context-alert fdanger; quietg := V4 = Uc
Functional System State The CONTEXT-ALERT input is already the result of
repeated and consecutive notifications of alert situations, so we may regard it as a
variable that is hardly affected by false alarms. Also, we assume that a disturbance that can
instantaneously modify the terrain temperature or the snow height, unless connected
with an earthquake, is statistically not very realistic. On the other hand, the
accelerometer may be a source of false alarms since it can detect a “high” signal for reasons that
are not related to earthquakes: for instance, animals running close to the accelerometer.
As a result, we regard as reliable only repeated alerts coming from the
accelerometer. So, as in the case of simultaneous snow and earthquake warnings, we require that
the accelerometer has been “high” for two consecutive time instants (before t) in order
to regard the information given by the accelerometer as a real warning. Therefore, we
introduce the state variable:</p>
        <p>ACC-COUNTERf0; 1; &gt; 1g
The canonical vector representing the accelerometer counter is denoted by a and
d 1; d32; d33g. Specifically, a(t) = d31 if the counter is 0 at time
takes values in D3 = f 3
t; a(t) = d32 if the counter is 1 at time t; and a(t) = d33 if the counter is at least 2 at
time t. If the counter at time t has a value in fd31; d32g and the accelerometer vector is
v3(t) = d21, then the counter value at t + 1 is increased by 1. If a(t) = d33 and v3(t) = d 1,
2
then a(t + 1) = d 3, while when v3(t) = d22 the counter is moved back to a(t + 1) = d 1.</p>
        <p>3 3
Therefore, the accelerometer counter updates according to the following BCN:
a(t + 1) = A n v3(t) n a(t), where A = A1 A2 2 L3 6, and
A1 = A n d21 = [d32 d33 d 3]</p>
        <p>3
A2 = A n d22 = [d31 d31 d31]
Functional System Output We assume that the Functional System output can take
three values:
ALARM ftemp high; snow high; acc counter &gt; 1; acc high; ctx dangerg
ATTENTION ftemp low; snow high; acc counter ; acc ; ctx OR temp
high; snow low; acc counter ; acc ; ctx OR temp high; snow high; acc
counter low; acc ; ctx OR temp high; snow high; acc counter ; acc
low; ctx OR temp high; snow high; acc counter ; acc ; ctx quietg
NORMAL ftemp low; snow low; acc counter ; acc ; ctx g
Note that the alarm is sent out only when “acc counter &gt; 1” and “acc-high”. This
means that at the time t the alarm signal is issued if the accelerometer has detected
some movement for at least three consecutive time instants t ; t 1 and t 2. Of
course, as for the context-alert variable, the choice of how long we want to wait before
issuing the alarm signal is a design parameter that balances conflicting requirements:
security on the one hand and the need to avoid false alarms on the other.</p>
        <p>The functional system output is denoted by m and takes values in D3. Based on the
previous description of the three possible output values, it follows that the output vector
is generated based on the state a(t) and the input v(t) according to the following model:
m(t) = M n v(t) n a(t), where M = M1 M2 : : : M16 2 L6 16, and
M1 = M n d116 = [d32 d32 d 1]</p>
        <p>3
M2 = M n d126 = [d32 d32 d 2]
Mi = M n d1i6 = M2; for3 i = 3; : : : ; 12
M13 = M n d1163 = [d33 d33 d 3]
Mi = M n d1i6 = M13; for3 i = 14; 15; 16</p>
        <p>
          So, overall, the system model is a BCN obtained by connecting the BCN describing
the context and the BCN describing the functional model, and hence it is described by
the following equations:
c(t + 1) = C n u(t) n c(t)
a(t + 1) = A n v3(t) n a(t)
v4(t) = Hc n c(t)
m(t) = M n v(t) n a(t):
(
          <xref ref-type="bibr" rid="ref1">1</xref>
          )
(
          <xref ref-type="bibr" rid="ref2">2</xref>
          )
(
          <xref ref-type="bibr" rid="ref3">3</xref>
          )
(
          <xref ref-type="bibr" rid="ref4">4</xref>
          )
Note that the previous system could be represented as a standard BCN having u(t) :=
u(t) n v1(t) n v2(t) n v3(t) as input, x(t) := c(t) n a(t) as state vector, and y(t) = m(t)
as output. Such a representation, however, would be of larger dimension and would not
contribute to a better understanding of the system properties. On the contrary, it would
make the overall analysis more complicated. So, we investigate the model properties
by making use of the previous description (
          <xref ref-type="bibr" rid="ref1">1</xref>
          ) - (
          <xref ref-type="bibr" rid="ref4">4</xref>
          ). This provides further evidence of
the convenience of using C-A systems to model the system dynamics. Note that the
current cascade structure, having two counter variables as state variables of the two
connected BCNs, can be easily adapted to model a large class of C-A systems that
describe a decision process, in particular, an alert system. So, even if we focus on this
specific model, it is immediate to understand how the results and properties derived in
the following extend to all the alert systems that can be modelled as the cascade of a
Context and a Functional Systems, both of the them affected by external signals and
measurements, and whose target is to generate alert/alarm notifications based on the
occurrence of specific (possibly repeated) combinations of data.
4
        </p>
      </sec>
    </sec>
    <sec id="sec-4">
      <title>The main results</title>
      <p>In [16] we present a detailed description of the kind of reasoning that can be made using
the model developed in the previous sections. Here we only mention the main results,
referring to the original paper for a full treatment.</p>
      <p>
        – We use definitions and methods as in [4, 5, 11] to find equilibrium points of BCNs
corresponding to constant inputs. The analysis shows that no limit cycles can
appear in the system, and hence no contradicting alarm messages can be delivered by
it.
– Observability does not seem to be a fundamental system property for the
hydrogeological model, since identifying the initial state of the system during some
observation interval does not bring any practical advantage. On the other hand,
reconstructibility is a more relevant property to investigate: by identifying the current
system state, say x(T ), from the observation of the input and the output in some
time interval [0; T ], one may anticipate whether an alert signal will lead to an
alarm signal at the next time instant or not and hence be ready to run away or to
provide support. The analysis shows that the hydrogeological system described by
(
        <xref ref-type="bibr" rid="ref1">1</xref>
        )-(
        <xref ref-type="bibr" rid="ref2">2</xref>
        )-(
        <xref ref-type="bibr" rid="ref3">3</xref>
        )-(
        <xref ref-type="bibr" rid="ref4">4</xref>
        ) is reconstructible and the definition of reconstructibility holds for
T = 4:
– Detection of stuck-in faults. We proved that Given the hydrogeological system
described by (
        <xref ref-type="bibr" rid="ref1">1</xref>
        )-(
        <xref ref-type="bibr" rid="ref2">2</xref>
        )-(
        <xref ref-type="bibr" rid="ref3">3</xref>
        )-(
        <xref ref-type="bibr" rid="ref4">4</xref>
        ), a stuck-in fault for one of the state variables, c(t) or
a(t), cannot be identified corresponding to all the input sequences, but if one of the
counters gets stuck at a value that is not maximum, thus preventing the possible
generation of an alarm, then the previous state estimator always allows to detect
and identify the stuck-in fault at latest after T = 4 times instants from the fault
occurrence. Note, finally, that a false alarm cannot possibly be issued, because this
would require not only that one of the counters is stuck to the maximum value but
also that the other is at the maximum value in turn and the inputs are all high, but
this is the case when the alarm message should be issued!
5
      </p>
    </sec>
    <sec id="sec-5">
      <title>Conclusions and future work</title>
      <p>In this paper we model a simple Context-aware system as a Boolean Control Network
in order to use the powerful tools typical of system theory, which apply to linear analog
systems, also to digital systems, whose properties are usually expressed by logical rules.
The ultimate goal is to pave the way to formally assess reliability and safety properties
of self adapting safety critical systems. The existence of globally attractive equilibrium
points under constant input and the reconstructibility of the system have been proved,
as well as the possibility of identifying some faults which could adversely affect the
system output.</p>
      <p>The main advantages of the proposed approach are on the one hand to provide a solid
system theoretic framework where intuitive and practical features or goals for
Contextaware systems can be properly formalised, on the other hand to offer rigorous algebraic
tools to test these properties and solve those problems. The proposed solutions are easily
converted into computer algorithms. We are working to apply these techniques to more
complex feedback systems, where the output of the functional systems can affect in
turn the state of the Context, and to enhance fault tolerance by considering possible
correlations among the sensors and other system input/output devices.</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          1.
          <string-name>
            <surname>Bolchini</surname>
            ,
            <given-names>C.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Curino</surname>
            ,
            <given-names>C.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Orsi</surname>
            ,
            <given-names>G.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Quintarelli</surname>
            ,
            <given-names>E.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Rossato</surname>
            ,
            <given-names>R.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Schreiber</surname>
            ,
            <given-names>F.A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Tanca</surname>
            ,
            <given-names>L.</given-names>
          </string-name>
          :
          <article-title>And what can context do for data? Commun</article-title>
          . ACM
          <volume>52</volume>
          (
          <issue>11</issue>
          ),
          <fpage>136</fpage>
          -
          <lpage>140</lpage>
          (
          <year>2009</year>
          ). https://doi.org/10.1145/1592761.1592793, https://doi.org/10.1145/1592761.1592793
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          2.
          <string-name>
            <surname>Bolchini</surname>
            ,
            <given-names>C.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Curino</surname>
            ,
            <given-names>C.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Quintarelli</surname>
            ,
            <given-names>E.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Schreiber</surname>
            ,
            <given-names>F.A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Tanca</surname>
            ,
            <given-names>L.</given-names>
          </string-name>
          :
          <article-title>A data-oriented survey of context models</article-title>
          .
          <source>ACM SIGMOD Record 36, n.4</source>
          ,
          <fpage>19</fpage>
          -
          <lpage>26</lpage>
          (
          <year>2007</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          3. Cheng, D.,
          <string-name>
            <surname>Qi</surname>
          </string-name>
          , H.:
          <article-title>Controllability and observability of Boolean Control Networks</article-title>
          .
          <source>Automatica</source>
          <volume>45</volume>
          (
          <issue>7</issue>
          ),
          <fpage>1659</fpage>
          -
          <lpage>1667</lpage>
          (
          <year>2009</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          4. Cheng, D.,
          <string-name>
            <surname>Qi</surname>
            ,
            <given-names>H.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Li</surname>
            ,
            <given-names>Z.</given-names>
          </string-name>
          :
          <article-title>Analysis and control of Boolean networks</article-title>
          . Springer-Verlag, London (
          <year>2011</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          5. Cheng, D.,
          <string-name>
            <surname>Qi</surname>
            ,
            <given-names>H.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Li</surname>
            ,
            <given-names>Z.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Liu</surname>
            ,
            <given-names>J.B.</given-names>
          </string-name>
          :
          <article-title>Stability and stabilization of Boolean networks</article-title>
          .
          <source>Int. J. Robust Nonlin. Contr</source>
          .
          <volume>21</volume>
          ,
          <fpage>134</fpage>
          -
          <lpage>156</lpage>
          (
          <year>2011</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          6.
          <string-name>
            <surname>Cherfia</surname>
            ,
            <given-names>T.A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Belala</surname>
            ,
            <given-names>F.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Barkaoui</surname>
            ,
            <given-names>K.</given-names>
          </string-name>
          :
          <article-title>Towards formal modeling and verification of contextaware systems</article-title>
          . In: VECoS (
          <year>2014</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          7.
          <string-name>
            <surname>Dey</surname>
            ,
            <given-names>A.K.</given-names>
          </string-name>
          :
          <article-title>Understanding and using context</article-title>
          .
          <source>Personal Ubiquitous Computing</source>
          <volume>5</volume>
          (
          <issue>1</issue>
          ),
          <fpage>4</fpage>
          -
          <lpage>7</lpage>
          (
          <year>January 2001</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          8.
          <string-name>
            <surname>Diao</surname>
            ,
            <given-names>Y.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Hellerstein</surname>
            ,
            <given-names>J.L.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Parekh</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Griffith</surname>
            ,
            <given-names>R.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Kaiser</surname>
            ,
            <given-names>G.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Phung</surname>
            ,
            <given-names>D.</given-names>
          </string-name>
          :
          <article-title>Self-managing systems: A control theory foundation</article-title>
          .
          <source>In: 12th IEEE - ECBS'05</source>
          . pp.
          <fpage>441</fpage>
          -
          <lpage>448</lpage>
          (
          <year>April 2005</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          9.
          <string-name>
            <surname>Djoudi</surname>
            ,
            <given-names>B.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Bouanaka</surname>
            ,
            <given-names>C.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Zeghib</surname>
          </string-name>
          , N.:
          <article-title>A formal framework for context-aware systems specification and verification</article-title>
          .
          <source>J. Syst. Softw. 122(C)</source>
          ,
          <volume>445</volume>
          -
          <fpage>462</fpage>
          (
          <year>Dec 2016</year>
          ). https://doi.org/10.1016/j.jss.
          <year>2015</year>
          .
          <volume>11</volume>
          .035, https://doi.org/10.1016/j.jss.
          <year>2015</year>
          .
          <volume>11</volume>
          .035
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          10.
          <string-name>
            <surname>Fornasini</surname>
            ,
            <given-names>E.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Valcher</surname>
            ,
            <given-names>M.E.</given-names>
          </string-name>
          :
          <article-title>Observability, reconstructibility and state observers of Boolean control networks</article-title>
          .
          <source>IEEE Tran. Aut. Contr</source>
          .
          <volume>58</volume>
          (
          <issue>6</issue>
          ),
          <fpage>1390</fpage>
          -
          <lpage>1401</lpage>
          (
          <year>2013</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          11.
          <string-name>
            <surname>Fornasini</surname>
            ,
            <given-names>E.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Valcher</surname>
            ,
            <given-names>M.E.</given-names>
          </string-name>
          :
          <article-title>On the periodic trajectories of Boolean Control Networks</article-title>
          .
          <source>Automatica</source>
          <volume>49</volume>
          ,
          <fpage>1506</fpage>
          -
          <lpage>1509</lpage>
          (
          <year>2013</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          12.
          <string-name>
            <surname>Fornasini</surname>
            ,
            <given-names>E.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Valcher</surname>
            ,
            <given-names>M.E.</given-names>
          </string-name>
          :
          <article-title>Recent developments in Boolean Control Networks</article-title>
          .
          <source>Journal of Control and Decision</source>
          <volume>3</volume>
          (
          <issue>1</issue>
          ),
          <fpage>1</fpage>
          -
          <lpage>18</lpage>
          (
          <year>2016</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          13.
          <string-name>
            <surname>Padovitz</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Zaslavsky</surname>
            ,
            <given-names>A.B.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Loke</surname>
            ,
            <given-names>S.W.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Burg</surname>
            ,
            <given-names>B.</given-names>
          </string-name>
          :
          <article-title>Stability in context-aware pervasive systems: A state-space modeling approach</article-title>
          . In: INSTICC. pp.
          <fpage>129</fpage>
          -
          <lpage>138</lpage>
          (
          <year>2004</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          14.
          <string-name>
            <surname>Padovitz</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Zaslavsky</surname>
            ,
            <given-names>A.B.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Loke</surname>
            ,
            <given-names>S.W.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Burg</surname>
            ,
            <given-names>B.</given-names>
          </string-name>
          :
          <article-title>Maintaining continuous dependability in sensor-based context-aware pervasive computing systems</article-title>
          .
          <source>Proceedings of the 38th Hawaii International Conference on System Sciences</source>
          (
          <year>2005</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref15">
        <mixed-citation>
          15.
          <string-name>
            <surname>Schreiber</surname>
            ,
            <given-names>F.A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Panigati</surname>
          </string-name>
          , E.:
          <article-title>Context-aware self adapting systems: a ground for the cooperation of data, software, and services</article-title>
          .
          <source>IJNGC</source>
          <volume>8</volume>
          (
          <issue>1</issue>
          ) (
          <year>2017</year>
          ), http://perpetualinnovation.net/ojs/index.php/ijngc/article/view/364
        </mixed-citation>
      </ref>
      <ref id="ref16">
        <mixed-citation>
          16.
          <string-name>
            <surname>Schreiber</surname>
            ,
            <given-names>F.A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Valcher</surname>
            ,
            <given-names>M.E.</given-names>
          </string-name>
          :
          <article-title>Formal assessment of some properties of context-aware systems</article-title>
          .
          <source>IJNGC</source>
          <volume>10</volume>
          (
          <issue>3</issue>
          ),
          <fpage>163</fpage>
          -
          <lpage>177</lpage>
          (
          <year>2019</year>
          ), http://arxiv.org/abs/
          <year>2005</year>
          .00373
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>