<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Model Driven Performability Analysis of Service Con gurations with Reliable Messaging ?</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Laszlo Gonczy</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Zsolt Deri</string-name>
          <email>zsolt.deri@gmail.com</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Daniel Varro</string-name>
          <email>varrog@mit.bme.hu</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>Budapest University of Technology and Economics Department of Measurement and Information Systems H-1117 Budapest</institution>
          ,
          <addr-line>Magyar tudosok korutja 2</addr-line>
        </aff>
      </contrib-group>
      <abstract>
        <p>Due to the rapid increase in the number of available web services, more and more emphasis is put on their reliability, availability, security, etc. These non-functional requirements are frequently captured in service-level agreements between service requesters and providers. In order to meet such non-functional requirements, a service needs to be designed for reliability by making design decisions on a high, architectural level. In the paper, we present a model-driven approach for the precise analysis of service con gurations with reliable messaging. Starting from high-level UML models of service con gurations captured by a UML pro le dedicated to service design, performability models are derived by automated model transformations for the PEPA toolkit in order to assess the cost of fault tolerance techniques in terms of performance.</p>
      </abstract>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>-</title>
      <p>Service-Oriented Architectures (SOA) provide a exible and dynamic platform
for implementing business services. Due to the rapid increase in the number of
available services, more emphasis is put on their reliability, availability, security,
etc. In order to meet such non-functional requirements, a service needs to be
designed for reliability by making design decisions on an architectural level.</p>
      <p>Recently, various non-functional parameters of services have been identi ed
by various XML-based web service standards such as WS-Reliability, WS-RM,
WS-Security, etc. While these properties are attached to business-level web
services, they, in fact, specify the con guration and behavior of the service
infrastructure, i.e. services that are not part of a speci c application, but play a
dedicated role in the underlying service middleware. A focal issue in the service
infrastructure is to provide reliable messaging between services where the
delivery of a message can be transparently guaranteed by the underlying platform.</p>
      <p>
        Unfortunately, service con gurations are typically set up in a rather ad hoc
way. While non-functional requirements are precisely captured in service-level
? This work was partially supported by the SENSORIA European project
(IST-3016004). The third author was also supported by the Janos Bolyai Scholarship.
agreements, there is no guarantee that the service con gurations will actually
meet these requirements. One of the reasons for this is that \design for reliability"
is a complex task as performance and reliability requirements are contradicting:
an inappropriate setup of reliability attributes may cause signi cant decrease in
performance. As a consequence, performability analysis is necessitated to assess
the cost of using fault-tolerant techniques in terms of performance.
To tackle these problems, we propose a model-driven approach (illustrated
in Fig. 1) to e ciently design, analyze and deploy standards-compliant service
con gurations with reliable messaging. Our approach is strictly in line with the
model-driven service engineering framework being developed within the
SENSORIA EU FP6 research project [
        <xref ref-type="bibr" rid="ref17">17</xref>
        ].
      </p>
      <p>
        Modeling of service con gurations. In order to raise the level of abstraction
for service engineers when designing the con guration of the service
infrastructure, we rely on high-level UML models conforming to the UML4SOA pro le
(developed within SENSORIA), which uses the standard extensibility
mechanism of UML for modeling service-oriented applications. This pro le is closely
related to the core SOA metamodel presented in [
        <xref ref-type="bibr" rid="ref2">2</xref>
        ], but extended with various
(e.g. non-functional) aspects of service design. In this paper (Sec. 2), we
specialize this general-purpose pro le in order to capture service con gurations with
reliable messaging based upon a metamodel developed in [
        <xref ref-type="bibr" rid="ref9">9</xref>
        ].
      </p>
      <p>
        Model-based performability analysis. From such service con guration
models, automated model transformations generate formal process models for the
PEPA framework (Performance Evaluation Process Algebra, [
        <xref ref-type="bibr" rid="ref5">5</xref>
        ]) to provide an
early performability evaluation and prediction for service con gurations with
reliable messaging (Sec. 3). We identify the abstract behavior of core service
con guration elements, which incorporates reliable messaging semantics, but it
is independent of the business functionality of services. Then model
transformations assemble the formal performability model from these elementary building
blocks based upon the actual service con guration model. These transformations
were implemented in the VIATRA2 framework [
        <xref ref-type="bibr" rid="ref19 ref20">19, 20</xref>
        ] by following an MDA
approach with separated phases for PIM-to-PSM mappings and the generation of
the textual target descriptions. A brief insight to the actual transformations are
provided in Sec. 3.
      </p>
      <p>
        Analysis models serve also as the basis of deployment code generation to
reliable messaging middleware (see Fig. 1). The basic method for this has already
been described in [
        <xref ref-type="bibr" rid="ref7">7</xref>
        ]. Currently, we support the (semi-)automated deployment
to IBM RAMP and Apache Axis2 platforms (in the latter case we also generate
security con gurations).
2
      </p>
    </sec>
    <sec id="sec-2">
      <title>Modeling SOA with Reliable Messaging</title>
      <p>
        In the current section, we present how service con gurations can be modeled
using a high-level UML model dedicated to service design by a corresponding
UML pro le, which was designed as part of the SENSORIA project. This pro le
is conceptual follow up of [
        <xref ref-type="bibr" rid="ref2">2</xref>
        ] where a semi-formal platform-independent and a
SOA-speci c metamodel (ontology) was developed to capture service
architectures on various levels of abstraction in a model-driven development process for
business-level services. The UML4SOA pro le includes means to capture
nonfunctional aspects of services on a high-level of abstraction (i.e. independently of
speci c non-functional parameters such as availability or performance). In this
section, we brie y overview the core ideas behind this modeling language.
Moreover, we specialize this general-purpose non-functional pro le to capture service
con gurations with reliable messaging based upon a metamodel developed in [
        <xref ref-type="bibr" rid="ref9">9</xref>
        ].
2.1
      </p>
      <sec id="sec-2-1">
        <title>Running example</title>
        <p>
          In this paper we will use the "On Road Assistance" scenario developed in scope
of the Automotive Case Study [
          <xref ref-type="bibr" rid="ref12">12</xref>
          ] within the SENSORIA [
          <xref ref-type="bibr" rid="ref17">17</xref>
          ] project, which
describes a car-to-infrastructure application scenario. In this scenario:
1. The built-in diagnostic system of a car reports a severe failure of the engine.
2. This triggers the in-vehicle diagnostic system to perform an analysis of the
sensor values.
3. If the car is no longer drivable the system sends a message with the diagnostic
data and the GPS data of the vehicle to the car manufacturer or service
center.
4. Based on availability and the driver's preferences, the service discovery
system identi es and selects the appropriate services in the area: repair shop
(garage), tow truck and rental car.
5. The selection of services takes into account personalized policies and
preferences of the driver.
6. Upon con rmation, the owner of the car has to deposit a security payment
before being able to order services.
        </p>
        <p>
          This scenario raises several non-functional requirements against the system,
as collected in [
          <xref ref-type="bibr" rid="ref6">6</xref>
          ]. In this paper, we concentrate on the accountability, which
means on the service architecture level that the e ect of communication faults
have to be eliminated by the underlying middleware based upon appropriate
service con gurations to guarantee the message delivery between components.
2.2
        </p>
      </sec>
      <sec id="sec-2-2">
        <title>A core SOA metamodel and non-functional extensions</title>
        <p>(a) Main concepts of UML4SOA
(b) Metamodel of non-functional
properties of services</p>
        <p>
          The UML4SOA pro le [
          <xref ref-type="bibr" rid="ref13">13</xref>
          ] was developed in the SENSORIA project to
capture the abstract structural, behavioral and non-functional aspects of
serviceoriented applications. The core concepts in the UML pro le are describe in a
corresponding metamodel depicted in Fig. 2(a) (for core service concepts) and
Fig. 2(b) (for non-functional extensions). The pro le is built in a modular way,
and thus here, we mainly focus on non-functional aspects, which are most
relevant for the current paper. These non-functional aspects were inspired by
standard UML extensions (such as [
          <xref ref-type="bibr" rid="ref14">14</xref>
          ]).
        </p>
        <p>On a very abstract level, we de ne Services which are provided by
Components. Each service de nes two Interfaces, a provided interface and a required
interface. Each service de nes a Protocol while each component has an
Implementation.</p>
        <p>Non-functional aspects are included in the UML4SOA pro le by generalizing
Service Level Agreements. Attributes of a service are described by
NFDimensions which are collected to NFCharacteristics, which represent logical groups of
properties, such as security, performance or reliable communication. These
characteristics are contained within an NFSpeci cation.</p>
        <p>
          During the operation lifecycle of services, provided and requested properties
of services are negotiated (which process is out of the scope of the current paper).
After the negotiation, a contract with an agreement of the agreed speci cation
is created. Ful llment of the contract is monitored by a dedicated component.
Case study. An extract of the components of the \On Road Assistance"
scenario [
          <xref ref-type="bibr" rid="ref12">12</xref>
          ] is shown in Fig. 3(a). In the current paper, we focus on the the
Vehicle Communication Gateway component, which is responsible for the
car-toinfrastructure communication, i.e. it manages communication between external
service providers, like the Bank and the global positioning system (GPS). This
way, the Vehicle Communication Gateway acts as a communication mediator
between a central service Orchestrator component and the actual external services.
For our initial investigations, we disregard from this Orchestrator, and focus only
on the other three components.
2.3
        </p>
      </sec>
      <sec id="sec-2-3">
        <title>Reliable messaging standards for web services</title>
        <p>(a) Core components of the OnRoadAs- (b) Extension of non-functionalconcepts
sistance scenario for reliable messaging</p>
        <p>There are various industrial standards re ecting the emerging need for
reliable Web services middleware from which we focus on reliable messaging
standards (e.g., WS-Reliability and WS-ReliableMessaging) in this paper.</p>
        <p>The main importance of these reliable messaging standards lies in the fact
that they are expected to replace the current mainstream messaging middleware
(such as Message Queuing servers or JMS) which are now used together with
SOAP to provide a reliable asynchronous communication service.</p>
        <p>Reliable messaging in the elds traditional distributed systems is closely
related to the guaranteed semantics of message delivery. Usual delivery classes are
the following:
1. At least once delivery. In the case of normal operation, every message is
transferred at least once, with the possibility of sending multiple instances
of the same message. This can only be allowed in systems where this does
not have an undesired side-e ect.
2. At most once delivery guarantees that no message will be sent multiple times
to the receiver, but their successful transmission is not ensured.
3. Exactly once delivery is the strongest delivery semantics, guaranteeing both
the successful message delivery (usually acknowledgements are required for
each message) and the ltering of duplicate messages.</p>
        <p>The following attributes are required for the con guration of reliable
messaging (besides messagingSemantics, which selects the messaging mode as
described earlier):
{ inactivityTimeout: (integer, seconds), after this period of time if no
acknowledgment message has arrived, the connection is closed;
{ exponentialBacko : (boolean), if it is set to true, time amounts between
retransmissions are following an exponential distribution;
{ acknowledgementInterval: (integer, seconds), amount of time elapsed
before sending acknowledgement message;
{ retransmissionInterval: (integer, seconds), after this time a request is
resent by client if no acknowledgement arrived.</p>
        <p>
          As reliable messaging PIM, we use the metamodel of reliable messaging in
service con gurations was created in [
          <xref ref-type="bibr" rid="ref9">9</xref>
          ] to incorporate reliable messaging
attributes of these standards.
        </p>
        <p>We incorporate these attributes to the UML4SOA pro le by prescribing that
the NFCharacteristic of an NFSpeci cation should contain an NFDimension speci c
to reliable messaging ReliableMessaging (when reliable messaging is required by
a contract). The relationship between concepts is illustrated in Fig. 3(b).
Case study. We now demonstrate how the non-functional extensions of the
UML4SOA pro le can be used to capture reliable messaging speci cations in
Fig. 4(a) (for charging the bank account of the driver) and Fig. 4(b) (for the
Global Positioning System).</p>
        <p>For instance, communicating with the bank requires both reliable and secure
message communication, of which here we concentrate on the rst. Note that
here we are at the class level, a concrete instance of this system is shown later
in Fig. 8.</p>
        <p>NFSpeci cations are de ned to describe the relevant properties of
communication between GPSSystem and Vehicle Communication Gateway etc. These
specication can contain di erent characteristics like availability, performance or
reliable messaging. Certain parameters can be de ned for non-functional attributes
(averageResponseTime, messageSemantics etc.) in course of modeling which can
be used for example for generation of con guration les as can be seen later.</p>
        <p>In the current paper, we illustrate our approach by using the at-least-once
reliable messaging semantics as a communication model. However, using other
reliable messaging semantics would not cause signi cant complications for the
presented approach.</p>
        <p>(a) Non-functional speci cation of the (b) Non-functional speci cation of the
bank service GPS service</p>
      </sec>
    </sec>
    <sec id="sec-3">
      <title>Model-based Performability Analysis of Services</title>
      <p>
        As the main contribution, we present a model-driven technique for the
performability analysis of service con gurations with reliable messaging. Performability
refers to the behavior of the system in the presence of faults, in other words, the
cost of fault-handling (or fault-tolerant) techniques in terms of response time.
For our investigations, we use the PEPA (Performance Evaluation Process
Algebra) toolkit [
        <xref ref-type="bibr" rid="ref5">5</xref>
        ], which o ers a formal language for capturing and powerful
stochastic analysis techniques for the evaluation of performance models.
      </p>
      <p>Essentially, automatic model transformations derive PEPA processes from
the UML models of service con gurations extended with reliable messaging
attributes. This transformation takes various inputs:
{ Service con guration models, which only contain the architectural design, i.e.
the dependencies between services being relevant for performability analysis.
For performability analysis, we identify the main roles of service providers
and requesters potentially chained to incorporate third party services.
{ Prede ned library of component behavior, which captures the core,
performability related behavior of reliable messaging for each party (e.g. service
provider, requester). This library should include technology-related
behavior, which is typically observable but not controllable (in case of a reliable
messaging middleware, the overhead of access to stored message content
before generating new message instances).
{ Reliable messaging parameters, which a ect both the structure and the
dynamic behavior of performability models. This includes quantitative
characteristics of faults of message transmission (encoded implicitly into rates of
transitions) to estimate the e ect of unreliable communication layer.
3.1</p>
      <sec id="sec-3-1">
        <title>The performability model</title>
        <p>For capturing the performability model of the basic components (in our case,
the client and the server), we use a visualized version of the process algebra
notation of PEPA. Each process is visualized as an automaton. Rectangles represent
states, while transitions between states correspond to communication actions.
! stands for sending a message and ? means receiving a message. Sending and
receiving messages is carried out by synchronization between the two processes.
Internal actions without communication between processes are also distinguished
(e.g., timeout trigger events). The ring frequency of transition in PEPA are
considered to follow an exponential distribution.</p>
        <p>Fig. 5 shows the stochastic performability model created as a combination
of some core processes. The model represents the behavior of a service provider
(Bank) and a service requester Vehicle Communication Gateway when reliable
messaging is required between them.</p>
        <p>The service provider (shortly, server) component is either processing a
request or waiting for a new one, with the action of sending an acknowledgement
to the client once the message was successfully received.</p>
        <p>The service requester (or shortly, client) is assumed to behave according
to the at-east-once semantics (with an upper limit of three on the number of
messages). The automaton of the service requester represents that after sending a
message, it waits for an acknowledgement until a timeout occurs. Then it resends
the request until the maximum number of retransmission is reached. This is
represented by the non-trivial multiplication of a basic automaton as many times
as the maximum number of allowed retransmissions. If an acknowledgement
arrives, the message transmission is considered successful.</p>
        <p>
          It is worth pointing out that the handling of exactly-once delivery semantics
prescribing the ltering of duplicate messages is quite similar from a
performability perspective. Furthermore, note that this process model is an abstraction
of the graph transformation system presented in [
          <xref ref-type="bibr" rid="ref9">9</xref>
          ] as formal semantics of the
middleware behavior.
3.2
        </p>
      </sec>
      <sec id="sec-3-2">
        <title>Performability parameters for reliable messaging</title>
        <p>
          Reliable messaging parameters have di erent impact on the structure of this
model. The number of service providers and requesters can be altered by
changing the system equation (e.g. ClientIdle[
          <xref ref-type="bibr" rid="ref3">3</xref>
          ]). We used RAMP parameters of
services to derive send, resend, acknowledgement rates. These parameters has been
set between the two parties after negotiation process resulting in a NFContract.
        </p>
        <p>Values of parameters inactivityTimeout, exponentialBacko ,
acknowledgementInterval and retransmissionInterval serve as a basis for deriving
the actual ring rates of the transitions in Fig. 5. Note that ring times follow
an exponential distribution speci ed by these rates, i.e. a larger rate means that
the corresponding operation will be executed faster. Below we describe how the
rates in the PEPA model were derived from the reliable messaging parameters
in Sec. 2.3.</p>
        <p>{ acknowledgement rate (rateAck): it depends on the acknowledgement
interval:</p>
        <p>ack = 1=acknowledgementInterval;
On calculating this formula the prospective value of exponential distribution
with ack parameter will be equal to acknowledgementInterval.
{ timeout rate (rateTimeout): Similar to the previous formula:
timeout = 1=retransmissionInterval;
but if exponentialBacko is true the next timeout is:</p>
        <p>timeout = timeout=2;
thus between resend messages exponential amount of time elapses;
{ send rate (rateSend): it can be considered as an input parameter of
sensitivity analysis so a service con guration can be tested under di erent workload.
Alternatively, it can be derived from maximum throughput parameter in a
service level agreement, which expresses the number of requests received
from the user.
{ resend rate (rateResend): it should be a high value (compared to other
parameters) because when timeout occurs, resent message should be sent as
soon as possible.
{ reset rate (rateReset): like resend rate, it gets a high value in order to model
the transition to ClientIdle state after successful transmission.</p>
        <p>Note again that the number of allowed retransmissions (retransmission
number) changes the state space of the client automaton, i.e. additional
retransmission states are introduced (FailNx and SentNx). This number is determined
in the following way:
retransmissionN b =</p>
        <p>inactivityT imeout
retransmissionInterval
This expresses that the clients tries to resend the request until the inactivity
timeout is exceeded.
3.3</p>
      </sec>
      <sec id="sec-3-3">
        <title>Performability analysis objectives</title>
        <p>
          The typical questions for the PEPA solvers investigate passage time (i.e., the
expected response time of the system as a function of stochastic parameters),
utilization of states (what percentage of total operating time is spent in a
particular state). In addition, sensitivity analysis can also be performed to estimate
the e ect of changing transition rates on system-level performability attributes.
The number of possible retransmissions is also an interesting parameter to
investigate, however, this needs the modi cation of the structure of the performability
model (by re-executing the transformation), while tuning of other parameters
requires to modify only the rates in the generated PEPA model. Core examples
for using PEPA are available in [
          <xref ref-type="bibr" rid="ref21 ref5">5, 21</xref>
          ].
        </p>
        <p>We can investigate the utilization of states in order to answer questions like
"What percentage of time is spent waiting for the answer of the request?" The
result obtained from executing PEPA is listed in the pie chart of Fig. 6.</p>
        <p>With the parameter settings of our
running example (described in Fig. 5),
PEPA derives that in a steady state,
the system spends 23% of the time within
states MsgSentX and FailX, which are
exactly the states required for
providing reliable messaging. In other terms,
the system spends 23% of the time with
fault handling.
Sensitivity analysis. Fig. 7 shows the (relative) change of failure rate as a
function of RAMP related parameters acknowledgement time and retransmission
interval based upon PEPA calculation. For the failure rate, utilization of Failure
state has been used. X-axis shows di erent values of acknowledgment time while
the di erent curves plot di erent timeout thresholds.</p>
        <p>Our analysis results can be interpreted as early prediction of performability.
For instance, one can deduce from Fig. 7 that if the rateAck rate is increased
from 0.2 to 0.3 (namely acknowledgement interval decreases), then there is about
100% decrease in the frequency of errors. So it is worth improving performance
of the provider if its cost is linear. Decreasing rateTimeout rate (curves with
di erent colors) also leads to the improvement of failure rate.</p>
      </sec>
      <sec id="sec-3-4">
        <title>Transitive invocation of third-party services</title>
        <p>Now we extend our performability model to handle service con gurations where
a service provider itself needs to call some other (third-party) service in order to
serve its own request. This intermediate (mediator) component acts as a server
and a client at the same time, thus we derive its behavior by combining the basic
elements of our performability model (exempli ed in Fig. 5) by synchronizing
the core automata on send and ack messages.</p>
        <p>For our investigations, we have
bounded such a transitive behavior by
a depth limitation of 3, while we
assume that potential cyclic service
invocation is ltered out by formal model
checking.</p>
        <p>In the sample service con guration
of Fig. 8 Orchestrator invokes Vehicle
Communication Gateway (VCG) that acts
both as a service provider and service
requester. The worst performance is
observed when the VCG needs to call both</p>
        <p>GPS and Bank components to ful ll a</p>
        <p>Fig. 8. Multiple parties request.</p>
        <p>Sensitivity analysis. For this scenario, we carried out a sensitivity analysis
to measure the throughput of the acknowledgement action of the system. The
results are depicted in Fig. 9 where the rates rateSendVC and rateSendVG stand
for the sending rate between VCG - Bank and VCG - GPS components,
respectively. Increasing these rates results in a faster operation of the Bank and GPS
services. Observing the lower curve we can deduce that it is useless to increase
the performance of Bank component if the GPS operates slowly (0.2). However
the upper curve shows that it is worth increasing the speed of Bank service as
it results in signi cant increase in acknowledgement rate, thus it decreases the
acknowledgement time of the system.</p>
      </sec>
      <sec id="sec-3-5">
        <title>Transformation implementation</title>
        <p>The translation of the UML model to PEPA code was implemented in multiple
steps shown in Fig. 10 using Model2Model and Model2Code transformations.
The input of the transformation chain is a UML model using UML4SOa for
modeling services and non-functional parameters of messaging. This model is
imported to the internal representation of the VIATRA2 tool.</p>
        <p>
          First, uml2soa transformation takes out the relevant parts of the model. This
transformation is used to collect relevant information from the model
representation and generates a compact model (which is semantically similar to a Domain
Speci c Model). This model is also used in other work as a basis of con guration
generation for Web services [
          <xref ref-type="bibr" rid="ref7">7</xref>
          ].
        </p>
        <p>Then uml2pepa is executed to transform relevant parts of this model (from
the performance aspect) to the concepts of the PEPA tool by taking the contracts
attached to the model and generating PEPA automaton. This transformation
also uses a 'parameter library' (currently encoded as a set of constants) which
represent typical settings of the reliable middleware. These are also used to set
default values for parameters which were uninitialized in the high level model.
This transformation can be considered as a "PIM-to-PSM mapping" following
the MDA conventions.</p>
        <p>Finally, pepa2out is a syntactical transformation which generates textual code
from the PEPA model. Separating the syntax generation from the semantical
mapping enables to develop transformations which are easier to maintain;
moreover, the abstract performance model can also serve as the basis of creating input
to other stochastic analysis tools.</p>
        <p>Model transformations are also captured in a textual way by using a
combination of (i) graph patterns for querying models, (ii) graph transformation
rules for elementary model manipulations, and (iii) abstract state machines for
assembling complex transformations from simple rules.</p>
        <p>
          Creating transformation work ow The transformation work ow has also been
integrated to the SENSORIA Development Environment (SDE) (it will be
available for public download soon). SDE is an Eclipse-based tool which integrates
SOA development and analysis tools in a "SOA-style" [
          <xref ref-type="bibr" rid="ref16">16</xref>
          ].
        </p>
        <p>Using our transformations and the SENSORIA tools, the developer can
perform complex design tasks of SOA systems where analysis questions have to
be answered (for instance, whether it is worth using reliable messaging
considering expected failure rate and performance constraints). All models and tools
can be managed within the same Eclipse environment. Extended with
deployment transformations and references to component implementations, the service
con guration can directly generated to target execution environments.
4</p>
      </sec>
    </sec>
    <sec id="sec-4">
      <title>Related work</title>
      <p>
        A framework for automated WSDL generation from UML models is described
in [
        <xref ref-type="bibr" rid="ref18">18</xref>
        ], using the UML extensions of MIDAS [
        <xref ref-type="bibr" rid="ref3">3</xref>
        ]. In [
        <xref ref-type="bibr" rid="ref10">10</xref>
        ], Web service
descriptions are mapped to UML models, and (after using visual modeling techniques)
a composite service can be created for which the descriptor is automatically
generated. However, none of these works considers non-functional properties of
Web services.
      </p>
      <p>
        Non-functional aspects of e-business applications are discussed among others
in [
        <xref ref-type="bibr" rid="ref1">1</xref>
        ], having some description of deployment optimization for J2EE applications,
but without discussing details of model-based deployment.
      </p>
      <p>
        Integration of non-functional aspects in the development by model
transformations is also investigated in [
        <xref ref-type="bibr" rid="ref15 ref4">4, 15</xref>
        ] and [
        <xref ref-type="bibr" rid="ref11">11</xref>
        ], focusing on parts of the engineering
process. However, none of these approaches address performability analysis in
the context of SOA.
      </p>
      <p>
        In a service-oriented environment, PEPA has already been used to analyze
(application-speci c) high-level UML models or work ow-like descriptions of
services with Service Level Agreement attributes [
        <xref ref-type="bibr" rid="ref21">21</xref>
        ]. In this approach, the authors
investigate performance parameters (compared to performability in our case).
However, the main essential di erence is the (performance-related) behavior of
services needs to be modeled explicitly on the UML-level. In contrast, our
technique relies only on architectural level UML models, and the core building blocks
of (business-independent) performability-related behavior are instantiated in
accordance with the UML model of service con gurations, which allows better
reusability.
      </p>
      <p>
        Concerning previous work of the same authors, veri cation of the behavior of
the system (i.e., checking the conformance to requirements on reliable
messaging) was performed in [
        <xref ref-type="bibr" rid="ref9">9</xref>
        ], thus giving a formal semantics which can be checked
by using some basic veri cation techniques and tools. The process model used for
performability analysis in Sec. 3 is derived as an abstraction of this work,
concentrating on quantitative measures. A high-level initial overview of the current
framework were introduced in [
        <xref ref-type="bibr" rid="ref7">7</xref>
        ]; however, the current paper contains signi
cantly more details, and the performability analysis is completely novel. [
        <xref ref-type="bibr" rid="ref8">8</xref>
        ] shares
some conceptually similar ideas in order to carry out a model-based performance
evaluation to analyze BPEL processes with SLA requirements by using DEEM.
5
      </p>
    </sec>
    <sec id="sec-5">
      <title>Conclusions</title>
      <p>In the paper, we presented an integrated model-driven framework for the design
and analysis of standards-compliant service con gurations supporting reliable
messaging. Starting from high-level, platform independent service con guration
models (captured by service engineers using a UML Pro le or a domain-speci c
editor) performability analysis was carried out by generating stochastic process
models for the PEPA toolkit. We used an SLA-like description and (in contrary
to existing methods were the original source model had to be enriched by
performability parameters) we created a quantitative model which is the basis of
precise analysis, helping the designer to estimate the cost and bene t of using
reliable middleware.</p>
      <p>
        Transformations were implemented using the VIATRA model transformation
framework [
        <xref ref-type="bibr" rid="ref20">20</xref>
        ]. As modeling front-end, the IBM Rational Software Architect v7
UML tool was used with appropriate model importers for VIATRA.
      </p>
      <p>A thorough scalability analysis of our approach on a real-life example is
also part of our research activities. We will compare the provided performance
characteristics of the normal message communication and that of the reliable
messaging middleware. Here we anticipate that from the user point of view the
average response time will be increased because of the overhead of
acknowledgement and possible resending of messages, however, the number of failed messages
will obviously decrease.</p>
      <p>We also plan to work on the back-annotation of the results to the engineering
model. Finally, the same model representation is used as the basis of deployment
transformations to standard-compliant platform, such as IBM RAMP, Apache
Axis2 extended with Sandesha module and SCA environments with
implementations of the Policy framework.</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          1.
          <string-name>
            <given-names>A.</given-names>
            <surname>Balogh</surname>
          </string-name>
          ,
          <string-name>
            <given-names>D.</given-names>
            <surname>Varro</surname>
          </string-name>
          ,
          <article-title>and</article-title>
          <string-name>
            <given-names>A.</given-names>
            <surname>Pataricza</surname>
          </string-name>
          .
          <article-title>Model-based optimization of enterprise application and service deployment</article-title>
          .
          <source>In ISAS</source>
          , pp.
          <volume>84</volume>
          {
          <fpage>98</fpage>
          .
          <year>2005</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          2.
          <string-name>
            <given-names>L.</given-names>
            <surname>Baresi</surname>
          </string-name>
          ,
          <string-name>
            <given-names>R.</given-names>
            <surname>Heckel</surname>
          </string-name>
          , S. Thone, and
          <string-name>
            <given-names>D.</given-names>
            <surname>Varro</surname>
          </string-name>
          .
          <article-title>Style-based modeling and re nement of service-oriented architectures</article-title>
          .
          <source>Software and Systems Modeling</source>
          , vol.
          <volume>5</volume>
          (
          <issue>2</issue>
          ):pp.
          <volume>187</volume>
          {
          <issue>207</issue>
          ,
          <year>2006</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          3.
          <string-name>
            <given-names>P.</given-names>
            <surname>Caceres</surname>
          </string-name>
          , E. Marcos, and
          <string-name>
            <given-names>B.</given-names>
            <surname>Vera</surname>
          </string-name>
          .
          <article-title>A MDA-based approach for web information system development</article-title>
          .
          <source>In Workshop in Software Model Engineering (WiSME@UML2003)</source>
          .
          <year>2003</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          4.
          <string-name>
            <given-names>V.</given-names>
            <surname>Cortellessa</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A. D.</given-names>
            <surname>Marco</surname>
          </string-name>
          , and
          <string-name>
            <surname>P. Inverardi.</surname>
          </string-name>
          <article-title>Software performance model-driven architecture</article-title>
          .
          <source>In SAC '06: Proceedings of the 2006 ACM symposium on Applied computing</source>
          , pp.
          <volume>1218</volume>
          {
          <fpage>1223</fpage>
          . ACM Press, New York, NY, USA,
          <year>2006</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          5.
          <string-name>
            <given-names>S.</given-names>
            <surname>Gilmore</surname>
          </string-name>
          and
          <string-name>
            <given-names>M.</given-names>
            <surname>Tribastone</surname>
          </string-name>
          .
          <article-title>Evaluating the Scalability of a Web Service-Based Distributed e-Learning and Course Management System</article-title>
          .
          <source>In Workshop on Web Services and Formal Methods (WS-FM 2006)</source>
          , Springer-Verlag.
          <year>2006</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          6.
          <string-name>
            <given-names>S.</given-names>
            <surname>Gnesi</surname>
          </string-name>
          , M. ter
          <string-name>
            <surname>Beek</surname>
            ,
            <given-names>H.</given-names>
          </string-name>
          <string-name>
            <surname>Baumeister</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          <string-name>
            <surname>Hoelzl</surname>
            ,
            <given-names>C.</given-names>
          </string-name>
          <string-name>
            <surname>Moiso</surname>
            ,
            <given-names>N.</given-names>
          </string-name>
          <string-name>
            <surname>Koch</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          <string-name>
            <surname>Zobel</surname>
            , and
            <given-names>M.</given-names>
          </string-name>
          <string-name>
            <surname>Alessandrini</surname>
          </string-name>
          .
          <source>D8.0: Case studies scenario description</source>
          ,
          <year>2006</year>
          .
          <source>SENSORIA Deliverables Month</source>
          <volume>12</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          7. L. Gonczy, J. Aved, and
          <string-name>
            <given-names>D.</given-names>
            <surname>Varro</surname>
          </string-name>
          .
          <article-title>Model-based deployment of web services to standards-compliant middleware</article-title>
          . In I.
          <string-name>
            <surname>J. M. Pedro Isaias</surname>
          </string-name>
          , Miguel Baptista Nunes (ed.),
          <source>Proc. of the Iadis International Conference on WWW/Internet</source>
          <year>2006</year>
          (
          <article-title>ICWI2006)</article-title>
          . Iadis Press,
          <year>2006</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          8. L. Gonczy,
          <string-name>
            <given-names>S.</given-names>
            <surname>Chiaradonna</surname>
          </string-name>
          ,
          <string-name>
            <given-names>F. D.</given-names>
            <surname>Giandomenico</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Pataricza</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Bondavalli</surname>
          </string-name>
          , and
          <string-name>
            <given-names>T.</given-names>
            <surname>Bartha</surname>
          </string-name>
          .
          <article-title>Dependability evaluation of web service-based processes</article-title>
          . In M. Telek (ed.),
          <source>in Proceedings of European Performance Engineering Workshop (EPEW 2006), Lecture Notes on Computer Science</source>
          , pp.
          <volume>166</volume>
          {
          <fpage>180</fpage>
          . Springer, Budapest, HUNGARY,
          <year>2006</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          9. L. Gonczy, M. Kovacs, and
          <string-name>
            <given-names>D.</given-names>
            <surname>Varro</surname>
          </string-name>
          .
          <article-title>Modeling and veri cation of reliable messaging by graph transformation systems</article-title>
          .
          <source>In Proc. of the Workshop on Graph Transformation for Veri cation and Concurrency (ICGT2006)</source>
          . Elsevier,
          <year>2006</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          10.
          <string-name>
            <given-names>R.</given-names>
            <surname>Gronmo</surname>
          </string-name>
          ,
          <string-name>
            <given-names>D.</given-names>
            <surname>Skogan</surname>
          </string-name>
          ,
          <string-name>
            <surname>I. Solheim</surname>
          </string-name>
          , and
          <string-name>
            <given-names>J.</given-names>
            <surname>Oldevik</surname>
          </string-name>
          .
          <article-title>Model-driven web services development</article-title>
          .
          <source>In Proc. of the IEEE International Conference on e-Technology, eCommerce and e-Servie (EEE'04)</source>
          , pp.
          <volume>42</volume>
          {
          <fpage>45</fpage>
          . IEEE Computer Society, Los Alamitos, CA, USA,
          <year>2004</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          11. H.
          <string-name>
            <surname>Jonkers</surname>
          </string-name>
          , M.-E. Iacob,
          <string-name>
            <surname>M. M. Lankhorst</surname>
            , and
            <given-names>P.</given-names>
          </string-name>
          <string-name>
            <surname>Strating</surname>
          </string-name>
          .
          <article-title>Integration and analysis of functional and non-functional aspects in model-driven e-service development</article-title>
          .
          <source>In EDOC</source>
          , pp.
          <volume>229</volume>
          {
          <fpage>238</fpage>
          .
          <year>2005</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          12.
          <string-name>
            <given-names>N.</given-names>
            <surname>Koch</surname>
          </string-name>
          and
          <string-name>
            <given-names>D.</given-names>
            <surname>Brendl</surname>
          </string-name>
          .
          <source>D8.2.a: Requirements Modelling and Analysis of Selected Scenarios - Automotive Case Study</source>
          ,
          <year>2007</year>
          .
          <source>SENSORIA Deliverables Month</source>
          <volume>24</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          13.
          <string-name>
            <given-names>N.</given-names>
            <surname>Koch</surname>
          </string-name>
          ,
          <string-name>
            <given-names>P.</given-names>
            <surname>Mayer</surname>
          </string-name>
          ,
          <string-name>
            <given-names>R.</given-names>
            <surname>Heckel</surname>
          </string-name>
          , L. Gonczy, and
          <string-name>
            <given-names>C.</given-names>
            <surname>Montangero</surname>
          </string-name>
          .
          <source>D1</source>
          .
          <article-title>4.a: UML for Service-Oriented Systems</article-title>
          ,
          <year>2007</year>
          .
          <source>SENSORIA Deliverables Month</source>
          <volume>24</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          14. Object Management Group.
          <article-title>UML Pro le for QoS and</article-title>
          Fault Tolerance,
          <year>2006</year>
          . http://www.omg.org.
        </mixed-citation>
      </ref>
      <ref id="ref15">
        <mixed-citation>
          15. S. Rottger and
          <string-name>
            <given-names>S.</given-names>
            <surname>Zschaler</surname>
          </string-name>
          .
          <article-title>Model-driven development for non-functional properties: Re nement through model transformation</article-title>
          .
          <source>In Proc. The Uni ed Modeling Language (UML</source>
          <year>2004</year>
          ), vol.
          <volume>3273</volume>
          of LNCS, pp.
          <volume>275</volume>
          {
          <fpage>289</fpage>
          . Springer,
          <year>2004</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref16">
        <mixed-citation>
          16. SENSORIA Development Environment home page,
          <year>2007</year>
          . http://svn.pst.ifi. lmu.de/trac/sct.
        </mixed-citation>
      </ref>
      <ref id="ref17">
        <mixed-citation>
          17.
          <article-title>SENSORIA FP6 IST project</article-title>
          ,
          <year>2005</year>
          . http://sensoria-ist.eu.
        </mixed-citation>
      </ref>
      <ref id="ref18">
        <mixed-citation>
          18.
          <string-name>
            <surname>J. M. Vara</surname>
            , V. de Castro, and
            <given-names>E. Marcos. WSDL</given-names>
          </string-name>
          <article-title>Automatic Generation from UML Models in a MDA Framework</article-title>
          .
          <source>In NWESP '05: Proceedings of the International Conference on Next Generation Web Services Practices</source>
          , p.
          <fpage>319</fpage>
          . IEEE Computer Society,
          <year>2005</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref19">
        <mixed-citation>
          19.
          <string-name>
            <given-names>D.</given-names>
            <surname>Varro</surname>
          </string-name>
          and
          <string-name>
            <given-names>A.</given-names>
            <surname>Balogh</surname>
          </string-name>
          .
          <article-title>The model transformation language of the VIATRA2 framework</article-title>
          .
          <source>Science of Computer Programming</source>
          , vol.
          <volume>68</volume>
          (
          <issue>3</issue>
          ):pp.
          <volume>214</volume>
          {
          <issue>234</issue>
          ,
          <year>2007</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref20">
        <mixed-citation>
          20.
          <article-title>VIATRA2 Framework at Eclipse GMT</article-title>
          . http://www.eclipse.org/gmt/.
        </mixed-citation>
      </ref>
      <ref id="ref21">
        <mixed-citation>
          21.
          <string-name>
            <surname>M. Wirsing</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          <string-name>
            <surname>Clark</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          <string-name>
            <surname>Gilmore</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          <article-title>Holzl, A</article-title>
          . Knapp,
          <string-name>
            <given-names>N.</given-names>
            <surname>Koch</surname>
          </string-name>
          ,
          <article-title>and</article-title>
          <string-name>
            <given-names>A.</given-names>
            <surname>Schroeder</surname>
          </string-name>
          .
          <article-title>Semantic-Based Development of Service-Oriented Systems</article-title>
          . In E. N. et al. (ed.),
          <source>Proc. of FORTE'06, LNCS 4229</source>
          , pp.
          <volume>24</volume>
          {
          <fpage>45</fpage>
          . Springer-Verlag,
          <year>2006</year>
          .
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>