{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,30]],"date-time":"2026-06-30T12:52:56Z","timestamp":1782823976789,"version":"3.54.5"},"reference-count":40,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[2021,11,6]],"date-time":"2021-11-06T00:00:00Z","timestamp":1636156800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2021,11,6]],"date-time":"2021-11-06T00:00:00Z","timestamp":1636156800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Discrete Event Dyn Syst"],"published-print":{"date-parts":[[2022,3]]},"abstract":"<jats:title>Abstract<\/jats:title><jats:p>The development of supervisory controllers for cyber-physical systems is a laborious and error-prone process. Supervisor synthesis enables control designers to automatically synthesize a correct-by-construction supervisor from a model of the plant combined with a model of the control requirements. From the supervisor model, controller code can be generated which is suitable for the implementation on a programmable logic controller (PLC). Supervisors for industrial systems that operate in close proximity to humans have to adhere to strict safety standards. To achieve these standards, safety PLCs (SPLCs) are used. For SPLC implementation, the supervisor has to be split into a regular part and a safety part. In previous work, a method is proposed to automatically split a supervisor model for this purpose. The method assumes that the provided plant model is a collection of finite automata. In this paper, the extension to extended finite automata is described. Additionally, guidelines are provided for modeling the plant and the requirements to achieve a favorable splitting. A case study on a rotating bridge is elaborated which has been used to validate the method. The case study spans all development steps, including the implementation of the resulting supervisor to control the real bridge.<\/jats:p>","DOI":"10.1007\/s10626-021-00350-4","type":"journal-article","created":{"date-parts":[[2021,11,6]],"date-time":"2021-11-06T07:02:27Z","timestamp":1636182147000},"page":"115-141","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":13,"title":["Supervisory controller synthesis and implementation for safety PLCs"],"prefix":"10.1007","volume":"32","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-3965-8948","authenticated-orcid":false,"given":"Ferdie F. H.","family":"Reijnen","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Toby R.","family":"Erens","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Joanna M.","family":"van de Mortel-Fronczak","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Jacobus E.","family":"Rooda","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2021,11,6]]},"reference":[{"key":"350_CR1","doi-asserted-by":"crossref","unstructured":"Baeten JCM, Van de Mortel-Fronczak JM, Rooda JE (2016) Integration of supervisory control synthesis in model-based systems engineering","DOI":"10.1007\/978-3-319-28860-4_2"},{"issue":"7","key":"350_CR2","doi-asserted-by":"publisher","first-page":"1040","DOI":"10.1109\/9.231459","volume":"38","author":"S Balemi","year":"1993","unstructured":"Balemi S, Hoffmann GJ, Gyugyi P, Wong-Toi H, Franklin GF (1993) Supervisory control of a rapid thermal multiprocessor. IEEE Trans Autom Control 38(7):1040\u20131059","journal-title":"IEEE Trans Autom Control"},{"issue":"3","key":"350_CR3","doi-asserted-by":"publisher","first-page":"605","DOI":"10.1109\/TAC.2009.2039237","volume":"55","author":"K Cai","year":"2010","unstructured":"Cai K, Wonham WM (2010) Supervisor localization: a top-down approach to distributed control of discrete-event systems. IEEE Trans Autom Control 55(3):605\u2013618","journal-title":"IEEE Trans Autom Control"},{"key":"350_CR4","doi-asserted-by":"crossref","unstructured":"Cassandras CG, Lafortune S (2009) Introduction to Discrete Event Systems. Springer Science + Business Media","DOI":"10.1007\/978-0-387-68612-7"},{"key":"350_CR5","unstructured":"Chen YL, Lin F (2000) Modeling of discrete event systems using finite state machines with parameters. In: Proceedings of the 2000 Conference on Control Applications, IEEE, pp941\u2013946"},{"issue":"1","key":"350_CR6","doi-asserted-by":"publisher","first-page":"57","DOI":"10.1145\/225871.225880","volume":"1","author":"KT Cheng","year":"1996","unstructured":"Cheng KT, Krishnakumar AS (1996) Automatic generation of functional vectors using the extended finite state machine model. ACM Trans Des Autom Electron Syst 1(1):57\u201379","journal-title":"ACM Trans Des Autom Electron Syst"},{"key":"350_CR7","doi-asserted-by":"crossref","unstructured":"Darvas D, Majzik I, Vi\u00f1uela EB (2016) Formal verification of safety PLC based control software. In: Proceedings of the 12th Conference on Integrated Formal Methods, Springer, pp 508\u2013522","DOI":"10.1007\/978-3-319-33693-0_32"},{"key":"350_CR8","doi-asserted-by":"crossref","unstructured":"de Queiroz MH, Cury JER (2000) Modular control of composed systems. In: Proceedings of the 2000 American Control Conference, IEEE, 6, pp 4051\u20134055","DOI":"10.1109\/ACC.2000.876983"},{"key":"350_CR9","first-page":"24","volume":"157","author":"European Commission","year":"2006","unstructured":"European Commission (2006) Machinery directive. Official Journal of the European Union L 157:24\u201386","journal-title":"Official Journal of the European Union L"},{"key":"350_CR10","doi-asserted-by":"crossref","unstructured":"Fabian M, Hellgren A (1998) PLC-based implementation of supervisory control for discrete event systems. In: Proceedings of the 37th Conference on Decision and Control, IEEE, vol 3, pp 3305\u20133310","DOI":"10.1109\/CDC.1998.758209"},{"key":"350_CR11","doi-asserted-by":"crossref","unstructured":"Forschelen STJ, Van de Mortel-Fronczak JM, Su R, Rooda JE (2012) Application of supervisory control theory to theme park vehicles. Discrete Event Dynamic Systems 22(4):511\u2013540","DOI":"10.1007\/s10626-012-0130-6"},{"key":"350_CR12","doi-asserted-by":"crossref","unstructured":"Goorden MA, van de Mortel-Fronczak JM, Reniers MA, Fokkink WJ, Rooda JE (2019) Modeling guidelines for component-based supervisory control synthesis. In: Proceedings of the Conference on Formal Aspects of Component Software, Springer, pp 3\u201324","DOI":"10.1007\/978-3-030-40914-2_1"},{"issue":"12","key":"350_CR13","doi-asserted-by":"publisher","first-page":"1027","DOI":"10.1177\/0037549715614652","volume":"91","author":"Y Huang","year":"2015","unstructured":"Huang Y, Seck MD, Verbraeck A (2015) Component-based light-rail modeling in discrete event systems specification. Simulation 91(12):1027\u20131051","journal-title":"Simulation"},{"key":"350_CR14","unstructured":"IEC 61131-3 (2013) IEC 61131-3: Programmable Controllers \u2013 Part 3: Programming Languages (3rd). Standard, International Electrotechnical Commission"},{"key":"350_CR15","unstructured":"IEC 62061 (2005) IEC 61508: Safety of machinery \u2013 Functional safety of safety-related electrical, electronic and programmable electronic control system. Standard, International Electrotechnical Commission"},{"key":"350_CR16","doi-asserted-by":"crossref","unstructured":"Khan A, Th\u00f6nnessen D, Fabian M (2019) On-the-fly conformance testing of safety PLC code using QuickCheck. In: Proceedings of the 17th International Conference on Industrial Informatics, IEEE, vol 1, pp 419\u2013424","DOI":"10.1109\/INDIN41052.2019.8972277"},{"key":"350_CR17","doi-asserted-by":"crossref","unstructured":"Kov\u00e1cs G, Pi\u00e9trac L, B\u00e1lint K (2012) A component-based approach for supervisory control. In: Proceedings of 20th Mediterranean Conference on Control & Automation, IEEE, pp 800\u2013805","DOI":"10.1109\/MED.2012.6265736"},{"issue":"6","key":"350_CR18","doi-asserted-by":"publisher","first-page":"1567","DOI":"10.1109\/TCST.2011.2169262","volume":"20","author":"O Ljungkrantz","year":"2012","unstructured":"Ljungkrantz O, Akesson K, Yuan C, Fabian M (2012) Towards industrial formal specification of programmable safety systems. IEEE Trans Control Syst Technol 20(6):1567\u20131574","journal-title":"IEEE Trans Control Syst Technol"},{"issue":"5","key":"350_CR19","doi-asserted-by":"publisher","first-page":"782","DOI":"10.1109\/TAC.2006.875030","volume":"51","author":"C Ma","year":"2006","unstructured":"Ma C, Wonham WM (2006) Nonblocking supervisory control of state tree structures. IEEE Trans Autom Control 51(5):782\u2013793","journal-title":"IEEE Trans Autom Control"},{"key":"350_CR20","unstructured":"Malik P (2003) From supervisory control to nonblocking controllers for discrete event systems. PhD thesis, Universit\u00e4t Kaiserslautern"},{"issue":"1","key":"350_CR21","doi-asserted-by":"publisher","first-page":"5794","DOI":"10.1016\/j.ifacol.2017.08.427","volume":"50","author":"R Malik","year":"2017","unstructured":"Malik R, \u00c5Kesson K, Flordal H, Fabian M (2017) Supremica\u2013an efficient tool for large-scale discrete event systems. IFAC-PapersOnLine 50(1):5794\u20135799","journal-title":"IFAC-PapersOnLine"},{"key":"350_CR22","doi-asserted-by":"crossref","unstructured":"Markovski J, van Beek DA, Theunissen RJM, Jacobs KGM, Rooda JE (2010) A state-based framework for supervisory control synthesis and verification. In: Proceedings of the 49th Conference on Decision and Control, IEEE, pp 3481\u20133486","DOI":"10.1109\/CDC.2010.5717095"},{"key":"350_CR23","doi-asserted-by":"crossref","unstructured":"Miremadi S, \u00c5kesson K, Lennartson B (2008) Extraction and representation of a supervisor using guards in extended finite automata. In: Proceedings of Workshop on Discrete Event Systems, IEEE, pp 193\u2013199","DOI":"10.1109\/WODES.2008.4605944"},{"issue":"3","key":"350_CR24","doi-asserted-by":"publisher","first-page":"560","DOI":"10.1109\/TASE.2011.2124457","volume":"8","author":"L Ouedraogo","year":"2011","unstructured":"Ouedraogo L, Kumar R, Malik R, \u00c5Kesson K (2011) Nonblocking and safe control of discrete-event systems modeled as extended finite automata. IEEE Transactions on Automation Science and Engineering 8(3):560\u2013569","journal-title":"IEEE Transactions on Automation Science and Engineering"},{"key":"350_CR25","unstructured":"PLCopen (2018) Safety software technical specifications \u2013 Part 1: concepts and function blocks (2nd). Standard, PLCOpen"},{"issue":"7","key":"350_CR26","doi-asserted-by":"publisher","first-page":"304","DOI":"10.1016\/j.ifacol.2018.06.317","volume":"51","author":"L Prenzel","year":"2018","unstructured":"Prenzel L, Provost J (2018) PLC implementation of symbolic, modular supervisory controllers. IFAC-PapersOnLine 51(7):304\u2013309","journal-title":"IFAC-PapersOnLine"},{"issue":"1","key":"350_CR27","doi-asserted-by":"publisher","first-page":"206","DOI":"10.1137\/0325013","volume":"25","author":"PJ Ramadge","year":"1987","unstructured":"Ramadge PJ, Wonham WM (1987) Supervisory control of a class of discrete event processes. SIAM J Control Optim 25(1):206\u2013230","journal-title":"SIAM J Control Optim"},{"key":"350_CR28","doi-asserted-by":"crossref","unstructured":"Reijnen FFH, Goorden MA, van de Mortel-Fronczak JM, Reniers MA, Rooda JE (2018) Application of dependency structure matrices and multilevel synthesis to a production line. In: Proceedings of the 2nd Conference on Control Technology and Applications, IEEE, pp 458\u2013464","DOI":"10.1109\/CCTA.2018.8511449"},{"key":"350_CR29","doi-asserted-by":"crossref","unstructured":"Reijnen FFH, Hofkamp AT, Reniers MA, van de Mortel-Fronczak JM, Rooda JE (2019) Finite response and confluence of state-based supervisory controllers. In: Proceedings of the 15th Conference on Automation Science and Engineering, IEEE, pp 509\u2013516","DOI":"10.1109\/COASE.2019.8843335"},{"key":"350_CR30","doi-asserted-by":"crossref","unstructured":"Reijnen FFH, Erens TR, van de Mortel-Fronczak JM, Rooda JE (2020a) Supervisory control synthesis for safety PLCs. In: Proceedings of the 15th Workshop on Discrete Event Systems, IFAC, pp 151\u2013158","DOI":"10.1016\/j.ifacol.2021.04.015"},{"key":"350_CR31","doi-asserted-by":"crossref","unstructured":"Reijnen FFH, Goorden MA, Van de Mortel-Fronczak JM, Rooda JE (2020b) Modeling for supervisor synthesis \u2013 a lock-bridge combination case study. Discrete Event Dynamic Systems 30(3):499\u2013532","DOI":"10.1007\/s10626-020-00314-0"},{"issue":"1","key":"350_CR32","first-page":"56","volume":"38","author":"JM Roussel","year":"2005","unstructured":"Roussel JM, Giua A (2005) Designing dependable logic controllers using the supervisory control theory. IFAC Proceedings 38(1):56\u201361","journal-title":"IFAC Proceedings"},{"key":"350_CR33","doi-asserted-by":"crossref","unstructured":"Sk\u00f6ldstam M, \u00c5kesson K, Fabian M (2007) Modeling of discrete event systems using finite automata with variables. In: Proceedings of the 46th Conference on Decision and Control, IEEE, pp 3387\u20133392","DOI":"10.1109\/CDC.2007.4434894"},{"key":"350_CR34","unstructured":"Smith DJ, Simpson KG (2020) The Safety Critical Systems Handbook. Butterworth-Heinemann"},{"key":"350_CR35","doi-asserted-by":"crossref","unstructured":"Soliman D, Frey G (2011) Verification and validation of safety applications based on plcopen safety function blocks. Control Engineering Practice 19:929\u2013946","DOI":"10.1016\/j.conengprac.2011.01.001"},{"issue":"2","key":"350_CR36","first-page":"188","volume":"47","author":"L Swartjes","year":"2014","unstructured":"Swartjes L, van Beek DA, Reniers MA (2014) Towards the removal of synchronous behavior of events in automata. IFAC Proceedings 47(2):188\u2013194","journal-title":"IFAC Proceedings"},{"key":"350_CR37","doi-asserted-by":"crossref","unstructured":"Th\u00f6nnessen D, Smallbone N, Fabian M, Claessen K, Kowalewski S (2019) Testing safety PLCs using QuickCheck. In: Proeedings of the 15th International Conference on Automation Science and Engineering, IEEE, pp 1\u20136","DOI":"10.1109\/COASE.2019.8843227"},{"key":"350_CR38","doi-asserted-by":"crossref","unstructured":"van Beek DA, Fokkink WJ, Hendriks D, Hofkamp AT, Markovski J, van de Mortel-Fronczak JM, Reniers MA (2014) CIF 3: Model-based engineering of supervisory controllers. In: Proceedings of the 20th Conference on Tools and Algorithms for the Construction and Analysis of Systems, Springer, pp 575\u2013580","DOI":"10.1007\/978-3-642-54862-8_48"},{"key":"350_CR39","doi-asserted-by":"crossref","unstructured":"Wonham WM, Cai K (2019) Supervisory Control of Discrete-Event Systems. Springer","DOI":"10.1007\/978-3-319-77452-7"},{"key":"350_CR40","doi-asserted-by":"publisher","first-page":"152","DOI":"10.1016\/j.arcontrol.2017.03.004","volume":"43","author":"J Zaytoon","year":"2017","unstructured":"Zaytoon J, Riera B (2017) Synthesis and implementation of logic controllers\u2013a review. Annu Rev Control 43:152\u2013168","journal-title":"Annu Rev Control"}],"container-title":["Discrete Event Dynamic Systems"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10626-021-00350-4.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s10626-021-00350-4\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10626-021-00350-4.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,3,14]],"date-time":"2022-03-14T09:12:34Z","timestamp":1647249154000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s10626-021-00350-4"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,11,6]]},"references-count":40,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2022,3]]}},"alternative-id":["350"],"URL":"https:\/\/doi.org\/10.1007\/s10626-021-00350-4","relation":{},"ISSN":["0924-6703","1573-7594"],"issn-type":[{"value":"0924-6703","type":"print"},{"value":"1573-7594","type":"electronic"}],"subject":[],"published":{"date-parts":[[2021,11,6]]},"assertion":[{"value":"8 January 2021","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"25 August 2021","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"6 November 2021","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The authors declare that they have no conflict of interest.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"<!--Emphasis Type='Bold' removed-->Conflict of Interests"}}]}}