<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>On the use of the Goal-Oriented Paradigm for System Design and Law Compliance Reasoning</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Mirko Morandini</string-name>
          <email>morandini@fbk.eu</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Luca Sabatucci</string-name>
          <email>sabatucci@fbk.eu</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Alberto Siena</string-name>
          <email>siena@fbk.eu</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>John Mylopoulos</string-name>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Loris Penserini</string-name>
          <email>penserini@fbk.eu</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Anna Perini</string-name>
          <email>perini@fbk.eu</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Angelo Susi</string-name>
          <email>susi@fbk.eu</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>Fondazione Bruno Kessler - IRST</institution>
          ,
          <addr-line>Trento</addr-line>
          ,
          <country country="IT">Italy</country>
        </aff>
        <aff id="aff1">
          <label>1</label>
          <institution>University of Trento</institution>
          ,
          <country country="IT">Italy</country>
        </aff>
      </contrib-group>
      <fpage>71</fpage>
      <lpage>75</lpage>
      <abstract>
        <p>The concept of goal may be used to model intentions of human actors, such as requirements analysts or designers, as well as the reasons for pro-active behaviour of software agents. This short paper describes three ongoing research e orts on the application of the Goal-Oriented paradigm to system requirements analysis, system design and development of self-adaptive software agents.</p>
      </abstract>
      <kwd-group>
        <kwd>Goal-Oriented paradigm</kwd>
        <kwd>Requirements Engineering</kwd>
        <kwd>Design Patterns</kwd>
        <kwd>Software Agents</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>Introduction</title>
      <p>
        The concept of goal, as a state of a airs that an actor (human, organization
or system) wants to achieve, together with social aspects and other intentional
concepts de ne the Goal-Oriented (GO) paradigm that has been largely studied
and applied in Requirements Engineering (RE) since more than ten years [
        <xref ref-type="bibr" rid="ref1 ref2">1, 2</xref>
        ].
      </p>
      <p>Evidences of the usefulness of the GO paradigm can be found in a variety of
real world experiences that exploited available GO methodologies that support
software system development activities ranging from requirements acquisition,
analysis and understanding, to design and test cases derivation.</p>
      <p>A key feature of the GO paradigm is that of allowing to model and
reason about alternatives. These alternatives are usually represented in terms of
OR-decompositions of goals or tasks, which lead to the de nition of goal trees,
whose alternative paths may be evaluated against possible situations of bene t,
drawback or con ict.</p>
      <p>This paper summarizes three ongoing research e orts at FBK-IRST in which
the GO paradigm plays a central role at support of decision making for domain
and system analysts, system designers and also for proactive arti cial agents, in
di erent contexts: (i) when analysts have to decide about the compliance of a
set of the system's requirements with respect to law; (ii) when designers have
to choose a suitable design pattern; (iii) when software agents of a self-adaptive
system have to decide at run-time which one among their alternative sub-goals
to achieve, while attempting to satisfy the main goals assigned to them by the
designers.
2</p>
    </sec>
    <sec id="sec-2">
      <title>An i * Framework for Law Compliance: Nomos</title>
      <p>Laws and regulations address processes and associated information systems within
organizations. Available methods and techniques for system design give little
support to the requirements engineer when analysing the impact of those
regulations during the de nition of requirements for a new system, or when an
existing organization has to restructure and re-engineer its operation in order to
achieve compliance.</p>
      <p>Goal-oriented requirements engineering rests on the idea of deriving the
requirements for a software system from the analysis of the goals that the
systemto-be will support once developed and deployed. However, when the stakeholders
are addressed by laws, the system-to-be has to be aligned with the legal
prescriptions, too, and goals per se do not provide information about such an alignment.
This is the problem of law compliance of goals models. Finding a solution to this
problem means nding the assignment of actors' responsibilities (goals) such
that if every actor ful ls its goals, then law is respected. To address this
problem we adopt a modelling approach which consists in starting from a model of
legal prescriptions, and building the model of goals in an incremental way that
maintains the alignment with the prescriptions.</p>
      <p>
        The i * modelling language focuses on intentional elements as the key to
describe and understand a given organizational setting. Laws play a di erent
role as they have (i) physical existence as natural language sentences in legal
texts; and (ii) prescription objectives with regard to the organization. The
contribution of the Nomos framework consists in a conceptual binding between the
two conceptions of intentions and regulations. The binding relies on the analysis
of legal sentences, which ultimately allows to identify the juridical concept of
normative proposition (NP), as the most atomic proposition able to carry a
normative semantics, containing information concerning: (i) the subject(s)
addressed by the NP itself; (ii) the legal modality; and (iii) the description of the
object of such modality. The legal modality is one of the eight elementary rights,
classi ed by Hohfeld [
        <xref ref-type="bibr" rid="ref3">3</xref>
        ] as: Privilege, which is the entitlement for a person to
discretionally perform an action, regardless of the will of others and Claim, which is
the entitlement for a person to have something done from another person, with
their correlative rights No-claim and Duty ; Power, which is the (legal) capability
to produce changes in the legal system towards another subject, and Immunity,
which is the right of being kept untouched from other performing an action, and
their correlatives rights, Liability and Disability.
      </p>
      <p>
        In order to support modelling of laws and compliance solutions, the i *
metamodel (in the variant proposed by the Tropos methodology [
        <xref ref-type="bibr" rid="ref4">4</xref>
        ]) has been
extended with the Nomos concepts, integrating the two set of concepts.
Moreover, a systematic process has been de ned to support the building of compliant
requirements models, as described in detail in [
        <xref ref-type="bibr" rid="ref5 ref6">5, 6</xref>
        ], considering the following
issues: the binding of domain stakeholders with subjects addressed by law, the
identi cation of legal alternatives, the identi cation of potential realisations of
normative propositions, the identi cation of legal risks, the identi cation of proof
artefacts, the constraining of delegation of goals to other actors.
      </p>
      <p>As future work, we are investigating the use of argumentation framework in
order to support the acceptability of compliance solutions.
3</p>
    </sec>
    <sec id="sec-3">
      <title>Design Pattern Representation with Motivations</title>
      <p>
        Software patterns are reusable solutions to recurring design problems and |
since their de nition | are considered a mainstream of software reuse practice.
They are typically documented with a textual description of the context where
they can apply, the purpose for their reuse and forces to balance. For encouraging
the understanding of design patterns and to ease their application during the
design phase, many approaches have been proposed to provide the solution by
using formal, semi-formal graphical notations or logic languages [
        <xref ref-type="bibr" rid="ref7">7</xref>
        ].
      </p>
      <p>
        We propose to use i * to represent not only the pattern solution, but also
the whole reasoning process that led to its formation, including motivation,
trade-o s and alternatives [
        <xref ref-type="bibr" rid="ref8">8</xref>
        ]. The main motivations of this approach are (i) to
improve the communication encapsulated in a design pattern without changing
the informative content and (ii) to provide some criteria for motivating pattern
selection and reuse during the design process.
      </p>
      <p>The proposed abstraction considers the design activity as the application
area in which we apply the i * framework, and the Designer as the main Actor
of the design activity, whose job is to balance design forces coming from the
system to be modelled. The designer's activities arise from needs, such as: (i) the
achievement of Design Goals to solve speci c design problem emerging during
the modelling of the system, and (ii) the compliance with Design Properties
(or soft goals) that specify qualities of the system. In this context a pattern
is a collection of collaborating roles, intended as autonomous holder of design
intentions that are delegated of some responsibilities from the designer, namely:
(i) design goals/soft- goals to be achieved, (ii) design tasks for introducing a
well-known solution, and (iii) system elements to introduce or to organize in the
solution.</p>
      <p>In this approach, the designer is supported with techniques for balancing
pattern contextual forces and for customizing the pattern implementation to
the speci c application context. We exploit the Strategic Dependency model for
representing the high-level responsibility organization of a design pattern, and
the Strategic Rationale model for entering in detail in the solution structure.</p>
      <p>The Strategic Dependency main role is always the designer who delegates
design intentionality to pattern roles. This view allows for highlighting main
intents and motivations of a pattern, and it is an instrument for quick selection of
the pattern to reuse from a catalogue. On the other side the Strategic Rationale
model allows for reasoning on design issues, considering consequences and
balancing design alternatives, thus customizing the solution to meet forces coming
from the context.</p>
      <p>This approach opens new research directions we are working on: (i) to
represent | and reason on | pattern composition and con icts, and (ii) the use
of an ontology for standardizing design intentional elements, that may help in
automatic discovery of patterns to reuse.
4</p>
    </sec>
    <sec id="sec-4">
      <title>Goal-Oriented Development of Self-Adaptive Systems</title>
      <p>
        Self-adaptive Software (SAS) aims at dealing autonomously with unpredictable
changes which occur in the dynamic environment it executes (at run-time), on
the basis of its knowledge and of the objectives it has been designed for. We
aim at de ning a process and a tool-supported design framework to develop
SAS with the necessary knowledge that enables adaptation of their behaviour
at run-time. Belief-Desire-Intention (BDI) agents [
        <xref ref-type="bibr" rid="ref9">9</xref>
        ] were chosen as reference
architecture and implementation platform.
      </p>
      <p>
        The proposed framework and development process, called Tropos4AS
(Tropos for Adaptive Systems) [
        <xref ref-type="bibr" rid="ref10">10</xref>
        ], exploits the basic Tropos early and late
requirements phases, with an extensive use of variability modelling [
        <xref ref-type="bibr" rid="ref11">11</xref>
        ], and extends the
design phase with environment modelling, extended goal modelling and failure
modelling.
      </p>
      <p>
        The environment model captures the non-intentional entities involved in,
used and perceived by the SAS, which are necessary for interfacing the system
with the surrounding world. For instance, the environment for a cleaner robot
includes the oor, the dustbins and a battery charging station. These entities
are represented through artifacts [
        <xref ref-type="bibr" rid="ref12">12</xref>
        ], non-intentional entities that provide
functionalities usable by agents to sense and act in the environment.
      </p>
      <p>
        In extended goal modelling, the goal model is linked with the environment.
The process of goal achievement is related to the environment by de ning the
context where the goal is applicable, the conditions which lead to its adoption,
its achievement and failure states. Di erent goal types further characterise the
process of goal achievement, distinguishing among goals that the SAS has to
achieve in a given situation (e.g. clean a wet oor), goals that the SAS has to
achieve and maintain all along its life cycle (e.g. maintain a battery loaded), and
goals that can be rather described as executing a given procedure (e.g. searching
for dirt). Goal types were already present in the Formal Tropos [
        <xref ref-type="bibr" rid="ref13">13</xref>
        ] language,
which was however developed with the aim of consistency veri cation via
modelchecking techniques. On the contrary, Tropos4AS focuses on the semantics of an
agent's goal model that can be directly coded in a BDI agent programming
language (e.g. Jadex, 2APL or Jack), following prede ned mapping rules to link
the goals in the design artefacts to the agent goals in the code, respecting the
semantics of the goal model [
        <xref ref-type="bibr" rid="ref14">14</xref>
        ].
      </p>
      <p>In failure modelling, Tropos4AS aids the designer in anticipating possible
failures, giving a process to elicit errors possibly causing them and analysing
the possibilities to x them. Entities added to the Tropos4AS meta-model for
supporting failure modelling are: failures, representing undesirable states known
to the designer for the impossibility to achieve a goal, perceivable errors that
may be the cause of these failures, and recovery activities, i.e. actions that the
SAS may undertake to recover from errors, preventing failure.</p>
      <p>The implementation is based on a tool-supported mapping of goal models to
Jadex BDI agent code, maintaining the goal model with its semantics also at
runtime. This goal model drive the agent's behaviour at a knowledge level, de ning
the relationship between requirements (goals) and the agents' capabilities, and
to ensure traceability of run-time choices back to the design.</p>
      <p>The main issue in our research agenda concerns the consolidation of the
tools supporting the development and testing of self-adaptive software. Moreover,
a validation of the framework on more realistic scenarios will be performed,
focusing on the adaptive qualities of the system under development.</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          1.
          <string-name>
            <surname>Mylopoulos</surname>
            ,
            <given-names>J.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Chung</surname>
            ,
            <given-names>L.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Yu</surname>
            ,
            <given-names>E.</given-names>
          </string-name>
          :
          <article-title>From object-oriented to goal-oriented requirements analysis</article-title>
          .
          <source>Commun. ACM</source>
          <volume>42</volume>
          (
          <issue>1</issue>
          ) (
          <year>1999</year>
          )
          <volume>31</volume>
          {
          <fpage>37</fpage>
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          2. van Lamsweerde,
          <string-name>
            <surname>A.</surname>
          </string-name>
          :
          <article-title>Goal-oriented requirements engineering: A guided tour</article-title>
          . In: RE, IEEE Computer Society (
          <year>2001</year>
          )
          <fpage>249</fpage>
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          3.
          <string-name>
            <surname>Hohfeld</surname>
            ,
            <given-names>W.N.</given-names>
          </string-name>
          :
          <article-title>Fundamental Legal Conceptions as Applied in Judicial Reasoning</article-title>
          .
          <source>Yale Law Journal</source>
          <volume>23</volume>
          (
          <issue>1</issue>
          ) (
          <year>1913</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          4.
          <string-name>
            <surname>Susi</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Perini</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Mylopoulos</surname>
            ,
            <given-names>J.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Giorgini</surname>
            ,
            <given-names>P.:</given-names>
          </string-name>
          <article-title>The tropos metamodel and its use</article-title>
          .
          <source>Informatica (Slovenia)</source>
          <volume>29</volume>
          (
          <issue>4</issue>
          ) (
          <year>2005</year>
          )
          <volume>401</volume>
          {
          <fpage>408</fpage>
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          5.
          <string-name>
            <surname>Siena</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Mylopoulos</surname>
            ,
            <given-names>J.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Perini</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Susi</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          :
          <article-title>Designing law-compliant software requirements</article-title>
          .
          <source>In: 31st International Conference on Conceptual Modeling (ER'09)</source>
          , Gramado,
          <source>Brasil (November 09</source>
          <year>2009</year>
          )
          <volume>472</volume>
          {
          <fpage>486</fpage>
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          6.
          <string-name>
            <surname>Siena</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Mylopoulos</surname>
            ,
            <given-names>J.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Perini</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Susi</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          :
          <article-title>Towards a framework for lawcompliant software requirements</article-title>
          .
          <source>In: ICSE Companion</source>
          .
          <article-title>(</article-title>
          <year>2009</year>
          )
          <volume>251</volume>
          {
          <fpage>254</fpage>
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          7.
          <string-name>
            <surname>Mikkonen</surname>
            ,
            <given-names>T.</given-names>
          </string-name>
          :
          <article-title>Formalizing design patterns</article-title>
          .
          <source>In: Proceedings of ICSE '98</source>
          , Washington, DC, USA, IEEE Computer Society (
          <year>1998</year>
          )
          <volume>115</volume>
          {
          <fpage>124</fpage>
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          8.
          <string-name>
            <surname>Sabatucci</surname>
            ,
            <given-names>L.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Cossentino</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Susi</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          :
          <article-title>Introducing motivations in design pattern representation</article-title>
          .
          <source>In: Proc. of ICSR 11. LNCS</source>
          , Springer (
          <year>2009</year>
          )
          <volume>201</volume>
          {
          <fpage>210</fpage>
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          9.
          <string-name>
            <surname>Rao</surname>
            ,
            <given-names>A.S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>George</surname>
            ,
            <given-names>M.P.</given-names>
          </string-name>
          :
          <article-title>Bdi agents: From theory to practice</article-title>
          . In: ICMAS. (
          <year>1995</year>
          )
          <volume>312</volume>
          {
          <fpage>319</fpage>
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          10.
          <string-name>
            <surname>Morandini</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Penserini</surname>
            ,
            <given-names>L.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Perini</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          :
          <article-title>Towards goal-oriented development of selfadaptive systems</article-title>
          . In: SEAMS '08: Workshop on Software engineering
          <article-title>for adaptive and self-managing systems</article-title>
          , New York, NY, USA, ACM (
          <year>2008</year>
          )
          <volume>9</volume>
          {
          <fpage>16</fpage>
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          11.
          <string-name>
            <surname>Penserini</surname>
            ,
            <given-names>L.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Perini</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Susi</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Mylopoulos</surname>
            ,
            <given-names>J.</given-names>
          </string-name>
          :
          <article-title>High variability design for software agents: Extending tropos</article-title>
          .
          <source>ACM Transactions on Autonomous and Adaptive Systems (TAAS) 2</source>
          (
          <issue>4</issue>
          ) (
          <year>2007</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          12.
          <string-name>
            <surname>Omicini</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Ricci</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Viroli</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          : Agens Faber:
          <article-title>Toward a theory of artefacts for MAS</article-title>
          .
          <source>Electr. Notes Theor. Comput. Sci</source>
          .
          <volume>150</volume>
          (
          <issue>3</issue>
          ) (
          <year>2006</year>
          )
          <volume>21</volume>
          {
          <fpage>36</fpage>
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          13.
          <string-name>
            <surname>Fuxman</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Pistore</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Mylopoulos</surname>
            ,
            <given-names>J.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Traverso</surname>
            ,
            <given-names>P.</given-names>
          </string-name>
          :
          <article-title>Model checking early requirements speci cations in Tropos</article-title>
          .
          <source>In: IEEE Int. Symposium on Requirements Engineering</source>
          , Toronto (CA),
          <source>IEEE Computer Society (August</source>
          <year>2001</year>
          )
          <volume>174</volume>
          {
          <fpage>181</fpage>
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          14.
          <string-name>
            <surname>Morandini</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Penserini</surname>
            ,
            <given-names>L.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Perini</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          :
          <article-title>Operational Semantics of Goal Models in Adaptive Agents</article-title>
          .
          <source>In: 8th Int. Conf. on Autonomous Agents and Multi-Agent Systems (AAMAS'09)</source>
          , IFAAMAS (May
          <year>2009</year>
          )
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>