Semantics of UML State Machines

Semantics of UML State Machines
复制标题

UML 状态机的语义

DOI:
--
复制
发表时间:
1999
期刊:
--
影响因子:
--
通讯作者:
Alexander Knapp
Alexander Knapp
中科院分区:
--
文献类型:
--
作者:
Alexander Knapp

文献摘要

被引文献

相似文献

定义了UML状态机的一个简化子类的抽象语法和语义。1 UML状态机我们通过一个简单的自动取款机(ATM)的UML模型来说明UML状态机的主要概念,如图1所示:图1(a)中的类图指定了一个(活动)类Bank。类定义属性,即,它的实例的局部变量,以及可以分别通过调用和发送动作在实例上调用的操作和信号。Bank类的状态机如图1(B)所示,由状态和状态之间的转换组成(我们稍后为状态编号以供参考)。状态可以是简单的(如Idle和DispenseMoney),也可以是复合的(如Dispensing);一个并发的复合状态包含几个由虚线分隔的正交区域。此外,fork和join(伪)状态,如条形图所示,同步了几个往返于正交区域的转换; junction(伪)状态,如实心圆所示,将多个转换链接在一起。状态之间的转换由事件触发。转换也可以由条件保护,并指定在触发转换时要执行的操作或要发出的事件。例如,从stateIdle到fork伪状态的转换需要存在信号verifyPIN;从VerifyingCard到CardValid的转换分支需要保护cardValid为true;到Idle的转换分支设置Bank属性和cardValid。事件也可以通过在激活或停用状态时执行的进入和退出动作来发出。没有显式触发器的转换(例如离开DispenseMoney的转换)称为完成转换,并由完成事件触发,当状态完成其所有内部活动时会发出完成事件。状态机的实际状态由其活动状态配置和事件队列的内容给出。活动状态配置是活动状态的树;特别地,对于每个并发复合状态,其正交区域中的每个都是活动的。事件队列保存计算机尚未处理的事件。事件调度器将第一个事件从队列中出队;然后在运行到完成(RTC)步骤中处理该事件。首先,选择一组最大一致的启用转换:如果所有的源状态都包含在活动状态配置中,如果触发器与当前事件匹配,并且如果保护为真,则转换是启用的;如果两个启用的转换不共享源状态,则它们是一致的。对于集合中的每个转换,确定其最小共同祖先(LCA),即包含所有转换的源和目标状态的最低复合状态。转换的主源状态(即包含源状态的LCA的直接子状态)被停用,转换的操作被执行,其目标状态被激活。示例状态机模拟银行计算机的卡和PIN验证。初始化后,银行计算机处于空闲状态。信号done的接收导致完成状态机,而在接收到信号verifyPIN时,验证过程在状态Vrifying中开始。如果卡无效,银行计算机立即返回到空闲状态。如果PIN无效,则检查是否超过最大试验次数。如果是这种情况,则卡被标记为无效;否则,试验次数增加1。在这两种情况下,银行计算机返回到空闲状态。如果PIN有效,则试验次数重置为零。如果PIN和卡都有效,则进入状态DispenseMoney,银行计算机从该状态返回到空闲状态。«signal» done «signal» verifyPIN inv:maxTries >= 0 Bank boolean cardValid boolean PINValid int tries = 0 int maxTries
The abstract syntax and semantics of a simplified subclass of UML state machines is defined. 1 UML State Machines We illustrate the main concepts of UML state machines by a simple UML model of an automatic teller machine (ATM), shown in Fig. 1: The class diagram in Fig. 1(a) specifies an (active) class Bank. Classes defineattributes, i.e., local variables of its instances, andoperationsand signals that may be invoked on instances by call and send actions, respectively. The state machine for class Bank is shown in Fig. 1(b), consisting of statesand transitionsbetween states (we number the states for short reference later on). States can besimple(such asIdle and DispenseMoney) or composite(such asVerifying); a concurrentcomposite state contains several orthogonal regions , separated by dashed lines. Moreover,fork andjoin (pseudo-)states, shown as bars, synchronize several transitions to and from orthogonal regions; junction (pseudo-)states, represented as filled circles, chain together multiple transitions. Transitions between states are triggered by events. Transitions may also be guarded by conditions and specify actions to be executed or events to be emitted when the transition is fired. For example, the transition leading from stateIdle to the fork pseudostate requires signal verifyPIN to be present; the transition branch fromVerifyingCard to CardValid requires the guard cardValid to be true; the transition branches to Idle set theBank attributestries andcardValid. Events may also be emitted by entry andexit actions that are executed when a state is activated or deactivated. Transitions without an explicit trigger (e.g. the transition leaving DispenseMoney), are calledcompletion transitionsand are triggered by completion eventswhich are emitted when a state completes all its internal activities. The actual state of a state machine is given by its active state configuration and by the contents of itsevent queue . The active state configuration is the tree of active states; in particular, for every concurrent composite state each of its orthogonal regions is active. The event queue holds the events that have not yet been handled by the machine. The event dispatcher dequeues the first event from the queue; the event is then processed in arun-to-completion(RTC) step. First, a maximally consistent set of enabled transitions is chosen: a transition is enabledif all of its source states are contained in the active state configuration, if its trigger is matched by the current event, and if its guard is true; two enabled transitions are consistentif they do not share a source state. For each transition in the set, its least common ancestor (LCA) is determined, i.e. the lowest composite state that contains all the transition’s source and target states. The transition’s main source state, that is the direct substate of the LCA containing the source states, is deactivated, the transition’s actions are executed, and its target states are activated. The example state machine simulates card and PIN validation of a bank computer. After initialization the bank computer is in state Idle. The reception of signal done leads to finalizing the state machine, whereas on reception of signal verifyPIN the verification process is started in state V rifying. If the card is invalid, the bank computer immediately returns to stateIdle. If the PIN is invalid, it is checked whether the maximum number of trials is exceeded. If this is the case, the card is marked invalid; otherwise the number of trials is incremented by one. In both cases, the bank computer returns to state Idle. If the PIN is valid, the number of trials is reset to zero. If both the PIN and the card are valid, stateDispenseMoney is entered from which the bank computer returns to state Idle. «signal» done «signal» verifyPIN inv: maxTries >= 0 Bank boolean cardValid boolean PINValid int tries = 0 int maxTries