Formal Analysis and Design of Supervisor and User Interface Allowing for Non-Deterministic Choices Using Weak Bi-Simulation

In human machine systems, a user display should contain sufficient information to encapsulate expressive and normative human operator behavior. Failure in such system that is commanded by supervisor can be difficult to anticipate because of unexpected interactions between the different users and machines. Currently, most interfaces have non-deterministic choices at state of machine. Inspired by the theories of single user of an interface established on discrete event system, we present a formal model of multiple users, multiple machines, a supervisor and a supervisor machine. The syntax and semantics of these models are based on the system specification using timed automata that adheres to desirable specification properties conducive to solving the non-deterministic choices for usability properties of the supervisor and user interface. Further, the succinct interface developed by applying the weak bi-simulation relation, where large classes of potentially equivalent states are refined into a smaller one, enables the supervisor and user to perform specified task correctly. Finally, the proposed approach is applied to a model of a manufacturing system with several users interacting with their machines, a supervisor with several users and a supervisor with a supervisor machine to illustrate the design procedure of human–machine systems. The formal specification is validated by z-eves toolset.


Introduction
My specific target in this article is to preserve non-deterministic choices in the context of the fundamental feature of a user and supervisor machine interaction.At a more comprehensive level, the aim of this article is to give confidence to the analytic development of the concept of a formal model of supervisor and supervisor machine.The traditional use of theory has been to evaluate the supervisor interaction under different operating and environmental conditions [1].In formal model, the formal specification uses the variables that describe the system set of states to develop the proposition with a transition in between them [2].The process of formal model verification will satisfy the system model and system specification properties [3].The behavioral equivalences are used to verify a property of a system by assessing the equivalence of the observed system with a system which is known to possess that property and whether the two systems cannot be illustrated by an invader.These formal models manifest the mental and physical activities incorporating the user and supervisor with machine operation to achieve their objectives.Interaction between the user and machine may be brittle; the purpose of interface is only to provide the pre-enumerated condition for which it was planned [4].The brittle interaction of a complex and safety critical system due to unexpected deficiencies in communication and coordination between the human and the machine [5] encompasses manufacturing systems [6,7].Likewise, automated systems may be enabled to upscale their potential after being deployed [8].However, difficult situations can still emerge because of functional conditions or machine behaviors which were not expected by the designer; the automation design having been oversimplified because the embedded machine limitations, machine automation and user interface were not executed in agreement with the design.
Basic formalism is enough to model the functionality of systems, and hence to capture the qualitative behavior, but if one wants to also capture quantitative aspects, such as time or frequency-dependent properties, formalisms must be extended with real-time features [9].In systems that model quantitative processes, steps are associated with a given quantity, such as the resources (e.g., time or cost) needed to perform that step.Timed automaton has potential to allow for non-deterministic behavior to be solved while the weak bi-simulation perpetuate the co-reachability after its abstraction.The augmented interface was generated through the weak bi-simulation modelling technique that specifically addresses current modelling issues with several users and machines formally represented by timed automata.The concise, complete, unambiguous and comprehensible specification construction that unable the supervisor to make sense out of a rather complex implement.Our objective to develop a formal specification in such a way that it leads in the direction of an appropriate implementation and the process of progress called the refinement.We used Z notation for analyzing and validating the formal specification by z-eves toolset [10,11].
Initially, the formal representation of user and machine model is extended with a discrete event system and its further extension with event-based analysis as a means of representing the activities of the user and machine.These models show goal level of behavior in terms of the user and machine triggering transition.According to the principle of timed automaton, each transition will need time constraints that describe under what conditions a single transition among several possible transitions from the same state will be activated.This phenomenon will help us to understand the system characteristics in real time.Each user interacts with their machine and generate the interaction behavior by combining all users and machines inside the system that links with the supervisor to achieve the system goal under the time constraint value for each transition.However, non-deterministic choice in interface is not only in user but also in supervisor control which is a big safety concern regarding the manufacturing system and can contribute to unforeseen problems.For example, failure of part of the manufacturing system due to poor user interaction consisting of the interface of several machines being poorly defined can cause part supply delay and product recall [12,13] from the market.We first present the formal semantics and syntax of supervisor and supervisor machine model.We show how the interface can be generated through a weak bi-simulation that preserves the co-reachability.We then present a part of a manufacturing system that consists of several users and machines which are controlled by the supervisor.In conclusion, we present the limitations of this technique and the future direction for its model development.

Interface Generating Models of Human Automation Interaction
Scientists [14] modelled a user interface established on modes, error and pattern of interaction.Traditionally, most human factors research on interface design has emphasis on perceptual and cognitive compatibility between the human and the interface structure [15].Much fewer studies have been conducted on the correspondence between the interface [16] and the machine being controlled [17].Fewer researcher [18] modelled both the machine's behavior and user's operation as discrete event systems and put forward a formal approach for verifying their interface.Further, the scientists [19] modelled the detection of automation surprise in human machine system operated through multiple operation by user.Researchers [20] discussed an interface generating model based on user observable vs. unobservable and controllable vs. uncontrollable events provoked by the user decision through the interface model.Few scientists used logics and theory to represent the user and machine interaction [21].In their article, the user can be regarded as a human intervention which is an extension of supervisory control with some expedite actions and avoid mode confusion [22] accompany through the behavior of underlying machine by supervisor.To be clearer, these models explicitly used to develop training manuals to anticipate the underlying machine behavior and avoiding undeveloped accidents due to mode confusion and automation surprises.To execute this ultimate concern, it is important for manufacturing system for understanding of user, supervisor and machine model in realistic term.Moreover, I need to manifest the interface constitute of following different notions: 1.
User and Supervisor action-based interfaces, which distinguish between controllable vs. uncontrollable, observable vs. un-observable by the user and supervisor and internal transitions.

2.
The operating modes that characterize the user, supervisor and machine states that the user or supervisor needs to be able to distinguish.

Formal Verification with Interface Generating Models
Model checking is a computerized formal method practiced verifying system contents based on a formal model a set of anticipated characteristics in the form of formal specification [23].The formal model of a system defines with respect to the variable in the form of set and shifts among state of variable.Verification is the procedure of verifying that the system encounters the properties lying under specification.Model checking achieves this procedure automatically by comprehensively identifying a system's state space to control if these measures hold.If there is an against of rule, then counterexample will generate.The counterexample will show the clear description of rule violation for each state and specification including with next state of model that led up to the violation.
The scientist [24] integrates the user interface model into the discrete event system.This will allow the scientist to verify the state matching between the user and the machine [25] under the umbrella of user knowledge and their expectations.Also, it will verify that the interface will able to satisfy the user requirements and the need for updates to fulfil the system requirements.The first concept regarding formal verification of a user machine interaction model was introduced by [26].In this composition, the scientist combines the user and machine model states into a state duplet and estimates their matched march with respect to the identical specification classes.Few scientist [20] explores the verification of a user interface model by simulation relation.They [5] generate the user interface constructed on formal model and verifies it systematically maneuvering the formal specifications.In response of such needs, the non-deterministic choice at any state of interface is still insufficient for these interfaces.Further, the interface generating model can be used to include a single user and machine-based interaction.In case of several users that are controlled by the supervisor in a formal system models along with the necessary system elements such as the user machine interface and supervisor machine interface have still not been considered by the research community.

Limitations on Current Techniques
The prospective verification analysis is limited in extent by the potential user machine interaction model to establish the correct user behavior.Works such as these researcher [18] express the user machine interaction with an account of a formal description and they are not well reinforce the relation with user machine interaction.Correspondingly, they [20] established awareness of the link to unobservable and uncontrollable events for user but it had some weak points.Further, they [5] investigated and analyzed the human machine interaction through a formal model representation using predicate and proposition.All the provided practices do not have the non-deterministic behavior or choices lie at any state.
Moreover, currently we cannot generate the interface when the system has more than one user and machine all of which are interlinked with the supervisor as we described the limitation in Table 1.We are also interested to investigate the supervisor interface.(∑ com M ) choice=1 , (∑ obs ) and (∑ int ) have already evaluated in [19] the user domain while the supervisor's perspective still needs to be considered.Further, (∑ com ) choice>1 and (∑ com ) choice>1 events are still not being investigated by scientists.Only 1 L2 Only 1 No [20,26] >1 can be used

Formal Semantics of the Supervisor Model
We are assuming that we are considering only one supervisor in our system.This supervisor must merge the several users who are operating their machines.The functions and responsibility of supervisor is that she/he must inform the users of their tasks initially.After that the supervisor will also play their role by modifying the product through different user and machine interactions and obtain information through the supervisor interface [27].Therefore, the supervisor interface should be correct [28] and meaningful otherwise the outcome of product will not be as per the requirement of customer.We used the four-machine cell N S1 , N S2 , N S3 and N S4 operated by the four different users.At each cell we have states for operation for example in N S1 we have four states like wise L 1 , L 2 represent the low having the same class while M 1 , M 2 represent the medium having same class as shown in Figure 1.In between of these states we have transitions and these transitions are labelled as per our definitions.The dotted line represents the machine transitions while the dark line represents the user transition within the cell or if the transition is incoming or outgoing the cell then it termed as supervisor transition.
The supervisor has also the same character as the individual user, as shown in Table 2.The observable and controllable events α SUi ∈ (∑ com S ) choice>1 is formed due to the execution of a supervisor task.The α SUi ∈ (∑ com S ) choice>1 is the communication of the supervisor with the user and the supervisor has more than one choice in their state.All of them are observable and controllable.The machine transition which is also observable but uncontrollable β si ∈ ∑ obs S likewise moving the lathe to milling operation.If there is change inside the system without a user task, then the event must fall into the unobservable and uncontrollable category γ si ∈ ∑ int S for the supervisor.
The supervisor model can be represented as the timed automata; B(C) is the clock constraint where x ∼ n or x − y ∼ n for x, y ∈ C, ∼∈ [≤, <, =, >, ≥] and n ∈ .In our modelling, We used T Si for supervisor modelling state to state time constraint while, T xi is used for user station.The x is representing the station, we used as a, b, c and d station respectively while the i ∈ N.
According to the above definition we can write n S : g,a,r → n S if and only if n S , g S , a S , r S , n S ∈ E S .g S : is the guard of e s = n S , g S , a S , r S , n S ∈ E S , a S : is the action of e s , r s : is the set of clocks that is reset by e s , ∑ S : Set of events among the supervisor states.Definition 1.The appearance of observable and controllable event η S1 ∈ (∑ com s ) choice=1 will change the state of the supervisor interface through supervisor action.The formation of this event η i,j by any state will yield the only choice of user operations.When it appears in a state then it will become (N SM , N S ) ∈ B RSM or ((N SM0 ), (N S0 )) ∈ B RSM .The change of machine state n SM ∈ N SM or (N SM1 ) ∈ (N SM ) because of the observable and controllable event η S1 ∈ (∑ com S ) choice=1 .
Definition 2. The observable but uncontrollable event (β S1 , β S2 ) ∈ (∑ obs s ) will change the state of user interface through the occurrence of a machine transition.When it appears in a state then ((N SM , N S ) ∈ B RSM or (N SM2 ), (N S2 )) ∈ B RSM as in the supervisor model of Figure 1.The change of machine state n SM ∈ N SM or (N SM3 ) ∈ (Station2) M because of the observable and controllable event (β S1 , β S2 ) ∈ (∑ obs s ) that change the state (N SM2 ) ) having the interaction of (n SM , n S ) ∈ B RSM as per the supervisor model described in Figure 1 ( There is no binary relation that exists and the change of machine state n SM ∈ N SM or (N SM1 ) ∈ (Station1) M , (N SM2 ) ∈ (Station2) M and (N SM4 ) ∈ (Station4) M because of we have no supervisor action and the unobservable and uncontrollable event (γ ) that is internally triggered by machine having no interaction with supervisor.Definition 4. The observable and controllable supervisor event (α SU1 , α SU2 , α SU3 , α SU4 ) ∈ (∑ com S ) choice>1 has more than one choice at the starting state of supervisor for the user to perform the machine interaction.Similarly, (α S1 , α S2 ) ∈ (∑ com S ) choice>1 it has also more than one choice at N S1 state of supervisor to execute the task by the supervisor operations.The time transition will handle this choice easily to allow user to perform their operation safely and correctly.When it appears in a state then (N SM , N S ) ∈ B RSM or (N SM1 , N S1 ) ∈ B RSM as in the supervisor model of Figure 1.The change of machine state n SM ∈ N SM or (N SM1 ) ∈ (Station1a) SM , (N SM2 ) ∈ (Station1b) SM , (N SM3 ) ∈ (Station2) SM and (N SM4 ) ∈ (Station1c) SM because of the observable and controllable event that change the state (α SU1 , α SU2 , α SU3 , α SU4 ) ∈ (∑ com S ) choice>1 and in the Form of transition (N SM0 ) ) having the interaction of (n SM , n S ) ∈ B RSM or (N SM0 , N S0 ) ∈ B RSM has four choices and (N SM1 , N S1 ) ∈ B RSM has two choices for the interaction.
According to all the above definitions, the all supervisor operation is observable and controllable.The event that is unobservable and uncontrollable |E S (n S , e com |≤ 1 for any supervisor state n S ∈ N S is uncontrollable to the supervisor.We also incorporated the deterministic and non-deterministic choices into the supervisor model.Moreover, we used the Z notation for analyzing and validating the supervisor model using z-eves toolset.The information is well structured and presented at appropriate abstraction using z notation.The snapshot for specification validation of supervisor model is given in the appendix section in Figure A1.
Yes Yes *** Note: * Supervisor will deliver the instruction to user for preceding the user operations.Also, depend upon supervisor model; supervisor may have one or more than one choice to execute her/his task.** The machine transition could be one or more but activate as per time transition.*** Contribution.

Formal Semantics of the Supervisor Machine Model
The supervisor machine model consists of several interactions of users with respect to their machines to reach the desired goal.Each work cell consisting of a user and machine would be considered as a supervisor state.Moving the product from one work cell to another is considered as a machine transition.The state is observable vs controllable and uncontrollable vs unobservable if and only if the criteria as mentioned in the Table 2 are

Formal Semantics of the Supervisor Machine Model
The supervisor machine model consists of several interactions of users with respect to their machines to reach the desired goal.Each work cell consisting of a user and machine would be considered as a supervisor state.Moving the product from one work cell to another is considered as a machine transition.The state is observable vs controllable and uncontrollable vs unobservable if and only if the criteria as mentioned in the Table 2 are true.
The supervisor machine model as shown in Figure 2 can be represented in terms of timed automata; M SM = N SM , n OSM , E SM , l SM Where, N SM : Set of supervisor machine states, n OSM ∈ N SM : Initial (Starting) state of supervisor machine, → n SM when n SM , g SM , a SM , r SM , n SM ∈ E SM .We used similar technique for defining the time constraint as we described in supervisor model.g SM : is the guard of e = n SM , g SM , a SM , r SM , n SM ∈ E SM , a SM : is the action of e SM , r SM : is the set of clocks that is reset by e SM , ∑ SM : Set of events among the supervisor machine states.The set of supervisory action that consists of has three disjoint subsets.These subsets are only workable for  : an unobservable and uncontrollable event for user.These subsets are based on a discrete event system using finite state machines.In our case, we represent the semantics of the machine model by time automata because we can easily include more than one The set of supervisory action that consists of ∪ ∑ int M has three disjoint subsets.These subsets are only workable for (∑ com SM ) choice=1 : an observable and controllable event having only one choice for supervisor operation, (∑ com SM ) choice>1 : an observable and controllable event having more than one choice for supervisor operation, ∑ obs SM : an observable and uncontrollable event and ∑ int SM : an unobservable and uncontrollable event for user.These subsets are based on a discrete event system using finite state machines.In our case, we represent the semantics of the machine model by time automata because we can easily include more than one choices of user operation at any stage of machine state as shown in Figure 2. Now the updated equation will be as follows; According to the Figure 2 η S = {η S1 } are the observable and controllable events that exists in N SM0 state of machine such that ∀η S ∈ (∑ com SM ) choice=1 .They β S = {β S1 , β S2 } are the observable but uncontrollable events that exists in the N S2 and N S3 state of machine such that ∀β S ∈ ∑ obs SM .They γ S = {γ S1 , γ S2 , γ S3 , γ S4 } are the unobservable and uncontrollable events in N SM2 and N SM4 such that ∀γ S ∈ ∑ int SM .They α SU = {α SU5 , α SU6 } are the observable and controllable events that exists in the M1 machine state in which the user has only one choice to execute their operation such that ∀α SU ∈ (∑ com SM ) choice>1 .These α SU = {α SU1 , α SU2 , α SU3 , α SU4 } are the events in which the supervisor will give the task to the user to execute their operation in the N SM0 state such that ∀α SU ∈ (∑ com SM ) choice>1 .The time constraint at N SM0 is T S1 .While the outgoing transition has four different choices of state N SM1 , N SM2 , N SM3 and N SM4 with time constraints of N SM0 state is T S1 .N SM1 the state is T S2 , N SM2 state is T S5 and T S4 , N SM3 state is T S7 , T S3 , N SM4 state is T S12 .In addition, the formal specification of supervisor machine model is analyzed and validated using a-eves toolset.The snapshot for formal specification validation of supervisor machine model is given in appendix section in Figure A2.

Supervisor Interface Model
The details regarding the controllable and observable events, number of user and machine, non-deterministic choices, which lie or not in the user and supervisor model are mentioned in Table 2.The events α SU5 , α SU6 ∈ (∑ com SM ) choice>1 are supervisor observable and controllable having more than one choice at a single state and two choices at N S1 .The event η S1 ∈ (∑ com SM ) choice=1 is uncontrollable but observable for user and has only one choice for the supervisor perform their operation at N S0 described in the supervisor interface model and illustrated in Figure 3.The event γ S1 , γ S2 , γ S3 , γ S4 ∈ ∑ int SM are uncontrollable and unobservable for user.
Finally, the event (α SU1 , α SU2 , α SU3 , α SU4 ) ∈ (∑ com SM ) choice>1 are observable and controllable for supervisor that provides information to the user to perform their operation using the supervisor interface as shown in Figure 3. Accordingly, this event defines the supervisor and supervisor machine model as shown in the Table 2, the interaction between the n S ∈ N S supervisor and n SM ∈ N SM machine, n SM ∈ N SM supervisor and n S ∈ N S user described with binary relation.B R ⊆ N S × N U implies that the interaction (Supervisor, N U ) between the supervisor and user to proceed with the user operations B R ⊆ N S × N SM implies that the interaction between (Supervisor, N SM0 ), (Station1a, N SM1 ), (Station1b, N SM2 ), (Station1c, N SM4 ), (Station2, N SM3 ) the supervisor gives the command to the machine with the help of the supervisor interface.According to the supervisor machine model shown in Figure 2, it always shows the important transitions and state that describe the behavior of the machine operated by the supervisor according to the guideline of the supervisor interface model.

Interface Generation Using the Weak Bi-Simulation
To generate the interface, we need to consider the timed automaton, which can be either a machine model of user or a machine model of supervisor but as a machine model in the form of tuple can be describe as , , , , ,   is showing that all states are reachable but there is no illegal state [29] and   are the reachable states during the user and machine interaction.For co-reachability [30] the events are observable and controllable with respect to user

Interface Generation Using the Weak Bi-Simulation
To generate the interface, we need to consider the timed automaton, which can be either a machine model of user or a machine model of supervisor but as a machine model in the form of tuple can be describe as is a partial transition map, N m is the marker sate.Now, we are considering here the M is showing that all states are reachable but there is no illegal state [29] and ∑ rch M ⊆ ∑ M are the reachable states during the user and machine interaction.For co-reachability [30] the events are observable and controllable with respect to user ∪ ∑ obs events are not only ∑ com choice=1 .
∪ ∑ com choice>1 observable and controllable but also ∑ obs observable and uncontrollable with respect to user therefore P :   We used the abstract idea of [31] and explain this more clearly with the help of the machine model such that, where   We used the abstract idea of [31] and explain this more clearly with the help of the machine model such that, where ∑ M = {l oM1 , l oM2 , l oM3 , l oM4 } and ∑ rch M = {l oM2 , l oM4 }.The equivalence relation will be as a weak bi-simulation relation ∑ M = {(N M1 , N M1 ), (N M2 , N M3 )}.Hence, the l oM2 and l oM4 are different so they cannot be executed and will not fulfil the above definition criteria.The κ is the weak bi simulation relation to N M .According to the ∑ rch M thus the weak bi similarity will be as follows; Definition 6.The timed automaton M M = N M , l OM , E M , I M , υ M , N m assume that ∑ rch M ⊆ ∑ M .The degree of timed automaton according to ∼ ∑ M ∑ rch M is an automaton M M / ∼ ∑ M ∑ rch M := N MR , ∑ MR , υ MR , n oMR , N m where N MR : is the reduced state as shown in Figure 5, ∑ MR : a common user action represents a single action in the reduced model in Figure 5, υ MR : N MR × ∑ MR → 2 X and n oMR : the reduced initial state as specified by,  We normally describe M M / ∼ ∑ M ∑ rch M as the reduced form of M M by using the techniques of weak bi-simulation relation ∼ ∑ M ∑ rch M .As per the consideration of our example the final version of the automaton will be as in Figure 5.The partition on the set of state is M M .As per the easy understandable we have Hence the above automaton is in the form of the reduced automaton.
We can define the product of two systems ||sys × sys → sys : The symbol is || used to represents the product of two entities.We normally compare to obtain the product of the machine and user model with respect to transition architectures.According to the [12] user and machine model can be defined as M M and U M where timed automaton M M a set map to another set N MU : N M → U M if the following conditions hold.The first condition is There is a third condition; in the third condition, it is for every where this condition holds here In addition, the formal specification is presented here is analyzed and validated using z notation through z-eves toolset.We used the iteration-based approach to validate the interactive systems by using weak bi-simulation through checking of two systems simultaneously using z-eves, as a snapshot presented in appendix in Figure A3.The iteration 2 and 3 are solved based on source code using java.In iteration 1: we specify the system using the formal specification likewise in our case, the development of formal specification of supervisor, interface and machine model with transition definition.In iteration 2: we can identify the relevant interaction between the supervisor and machine through interface.In relevant interaction there is no blocking, error and illegal state [18].If there is irrelevant interaction then there must be blocking, error and illegal state then label it.Iteration 3: In this iteration, the identified irrelevant interaction should not be a part of the interaction.It means the supervisor and machine model interaction is free from blocking, error and illegal state.To make sure there is no irrelevant interaction, we apply the above described interface correction using weak bi-simulation method in Section 4. Iteration 4: In this iteration, we check the weak bi-simulation relation between the supervisor and machine model.If the supervisor and machine model are bi similar then the interaction has no illegal, error and blocking state.Hence, the correct interface is ready for the operational mode.
To apply the operation of a model checking verification, formal semantics of supervisor machine interaction model should be interpreted in the language of model checking.We apply the formal semantics to translate supervisor machine interaction model into the symbolic analysis laboratory (SAL) language [32,33].The formal semantics of supervisor machine interaction model to SAL translation is computerized by our practice constructed in java program which practices the document object model [34] to parse the supervisor and interaction model's extensible markup language (XML) code.
A diversity of examinations was course to authenticate that the translator was producing a SAL code that observed the formal semantics of supervisor machine interaction model.To estimate the complexity and scalability of the formal semantics of supervisor machine interaction models, we produced their models and examined the translated models' in terms of state spaces and runtimes by means of the SAL.The formal semantics supervisor model and formal semantics of supervisor machine interaction models comprise only supervisor who interact with different users and machine in a manufacturing system environment using the supervisor interface.Further, the different users also interact with their machine after getting the information from the supervisor by using their interface.The part manufacturing process were used to understand for both the users and supervisor operations.To guarantee that the verification method would examination a model's complete state space, we formed the specification that would not generate a counterexample.We also took help from the Z-eves tool to validate and verify our presented model using the analysis of counter example.

A Case Study of a Part Manufacturing System
To illustrate how this technique can be applied to find solutions to the problems in a parts manufacturing system, we present the following case study.In our case study the transmission does not shift into the higher gear when the driver wants to drive her/his vehicle at more than 160 km per hour.At the start we checked with the scan tool which point in the engine and ECT has the fault.After performing the code test, the malfunctioning in the shift solenoid control circuit was found to be high.There are three causes of these problems; the first one is open circuit, second one is a wiring problem and finally the solenoid valve malfunctioning.As per the manual instructions, first we checked the resistance of several solenoids.Fortunately, we traced the malfunctioning to solenoid valve having low resistance.We checked the underbody of the vehicle; the solenoid valve was completely dipped into oil and this was creating the malfunction.Further after analysis, we saw that the pipe set radiator was damaged and that it was draining the oil into this solenoid valve.After new parts were fitted, we faced same problem within a month.Moreover, we checked the engine noise and heating temperature inside the engine.
We identified that the engine noise and temperature as measured were not as per the standard.So, a high amount of gas was leaking from the exhaust manifold that caused the damage to the pipe resulting in the oil draining into the solenoid valve.We investigated the manufacturing process of exhaust manifold to identify the cause of the gas leakage.Now we will describe its current user and supervisor model and the user and supervisor machine model with the current user and supervisor interface.The data were obtained from the vendor of the car manufacturing company.We investigated the series of extensive production of exhaust manifold manufacturing using the automated manufacturing system.We selected the problematic fragment of the entire manufacturing process of the exhaust manifold and this analysis can be performed using our defined approach.As far as the verification is concerned, we start to describe the control panel by how the user interact with machine and several users are assisted and controlled by the supervisor.Also, the supervisor will interact with the machine and display inform to the user about their task and tells the supervisor the behavior of the machine.

Current Interface Description
The relevant elements of the computer-numerically controlled (CNC), Robot (low weight material transfer) control panel and the electronic attitude display mode in a CNC machine are shown in Figures 6 and 7.In the robot controller we will discuss about the function of the on/off switch and in the user controller we will discuss about the five switches controlling both control panel and display mode as shown in Figure 7 that are interest of us.These five switches are (1) tool change for machining operation; (2) coordinate setting for part manufacturing; (3) start cycle button; (4) move to bin; (5) take part from bin and are easily operated through the display mode.These five modes for user and one mode for supervisor can be engaged by pressing the respective buttons on the CNC and robot control panel as shown in Figures 6 and 7.
In the CNC machine the selection of the five operations is made on the top portion of the control panel operated by user having a small window as the display mode, indicating the tool change, start operation, movement of parts into the bin and dimension set by the user.The user can change the dimension by entering the values through the x, y and z button at the panel side.We can also adjust the speed of the spindle by the feed rate switch and edit the program as per the user or customer requirements as shown in Figure 7.The procedure for iteration 1 is given in the subsections.
in the user controller we will discuss about the five switches controlling both control panel and display mode as shown in Figure 7 that are interest of us.These five switches are (1) tool change for machining operation; (2) coordinate setting for part manufacturing; (3) start cycle button; (4) move to bin; (5) take part from bin and are easily operated through the display mode.These five modes for user and one mode for supervisor can be engaged by pressing the respective buttons on the CNC and robot control panel as shown in Figures 6 and 7   In the CNC machine the selection of the five operations is made on the top portion of the control panel operated by user having a small window as the display mode, indicating the tool change, start operation, movement of parts into the bin and dimension set by the user.The user can change the dimension by entering the values through the x, y and z button at the panel side.We can also adjust the speed of the spindle by the feed rate switch and edit the program as per the user or customer requirements as shown in Figure 7.The procedure for iteration 1 is given in the subsections.

Modeling the Rest of the System
The exhaust manifold manufacturing process is operated simultaneously in two ways; the first part is highly automated with no human involvement while the other part is operated by several users linked with the supervisor interacting with the machine.This two-way manufacturing process will be able to manufacture the exhaust manifold for the Corolla (EM1), Cuore (EM2) and innovative international multi-purpose vehicle (IMV) Hilux (EM3) car variants.We are considering here only the human involvement with machine.To complete the formal system model, for the system operational environment we created at the formal representation of a three-user model, three machine models, a supervisor model and supervisor machine model for exhaust manifold manufacturing system.The model representation is for more readable, expressive and includes the choices for the handling of non-determinism, so we can use easily the timed automaton transition systems.

Transition Definition
1 SU α : Supervisor transmit information to user 1 to perform the operations of turning {take first EM1 part then EM2 then EM3 from bin 1 to perform turning operations}, Facing {take first EM1 part then EM2 then EM3 part to perform the facing operation}and then perform the reaming and boring operation on EM1, EM2 and EM3 parts.After performing the turning operation on EM1, EM2 and EM3 user will move the few EM1 part into the bin2 similarly, user will move the few EM2 part into the bin 2 after finishing the facing operation.The few EM3 parts will receive from the bin 3 to perform the reaming operation and then part EM1, EM2 and EM3 will move to the bin 4 after finishing the boring operation.

α
: Supervisor transmit the information to user 2 to perform the operations of indexing, knurling, and taping on EM1, EM2 and EM3 then few EM1 and EM2 parts move to bin 6 after indexing operation and few EM3 parts move to bin 7 after knurling operation.After performing the taping operation on EM1, EM2 and EM3 parts will move to bin 8.

(
) m SU α : Supervisor transmit the information to user 2 to perform the operations of indexing1 and 2, knurling, and taping on EM1, EM2 and EM3 then few EM1 and EM2 parts move to bin 6 after

Modeling the Rest of the System
The exhaust manifold manufacturing process is operated simultaneously in two ways; the first part is highly automated with no human while the other part is operated by several users linked with the supervisor interacting with the machine.This two-way manufacturing process will be able to manufacture the exhaust manifold for the Corolla (EM1), Cuore (EM2) and innovative international multi-purpose vehicle (IMV) Hilux (EM3) car variants.We are considering here only the human involvement with machine.To complete the formal system model, for the system operational environment we created at the formal representation of a three-user model, three machine models, a supervisor model and supervisor machine model for exhaust manifold manufacturing system.The model representation is for more readable, expressive and includes the choices for the handling of non-determinism, so we can use easily the timed automaton transition systems.

Transition Definition
α SU1 : Supervisor transmit information to user 1 to perform the operations of turning {take first EM1 part then EM2 then EM3 from bin 1 to perform turning operations}, Facing {take first EM1 part then EM2 then EM3 part to perform the facing operation}and then perform the reaming and boring operation on EM1, EM2 and EM3 parts.After performing the turning operation on EM1, EM2 and EM3 user will move the few EM1 part into the bin2 similarly, user will move the few EM2 part into the bin 2 after finishing the facing operation.The few EM3 parts will receive from the bin 3 to perform the reaming operation and then part EM1, EM2 and EM3 will move to the bin 4 after finishing the boring operation.α SU2 : Supervisor transmit the information to user 2 to perform the operations of indexing, knurling, and taping on EM1, EM2 and EM3 then few EM1 and EM2 parts move to bin 6 after indexing operation and few EM3 parts move to bin 7 after knurling operation.After performing the taping operation on EM1, EM2 and EM3 parts will move to bin 8.
(α SU2 ) m : Supervisor transmit the information to user 2 to perform the operations of indexing1 and 2, knurling, and taping on EM1, EM2 and EM3 then few EM1 and EM2 parts move to bin 6 after indexing 2 operations.Few EM3 parts move to bin 7 after knurling operation.After performing the taping operation on EM1, EM2 and EM3 parts will move to bin 8. α SU3 : Supervisor transmits the information to user 3 to perform the operations of boring on EM1, EM2 and EM3 one by one or their availability.After performing the boring operation, the user will move the EM1, EM2 and EM3 parts for performing the reaming operation and move to bin 11.After this operation the user will perform the threading operation on EM1, EM2 and EM3.While few EM3 parts were received from bin 10 to perform the threading operation.Finally, the reaming operations were performed on EM1, EM2 and EM3 then move to bin 11.
(α SU3 ) m : Supervisor transmits the information to user 3 to perform the operations of boring on EM1, EM2 and EM3 one by one or their availability.After performing the boring 1 operation, the user will move the EM1, EM2 and EM3 parts for performing the reaming operation.After that the user will perform the boring 2 operations on EM1, EM2 and EM3.While few EM3 parts were received from bin 10 to perform the threading operation on all parts.Finally, the reaming operations were performed on EM1, EM2 and EM3 then move to bin 11. (α SU6 ) m : After finishing the boring 2 operations to perform the reaming operation {Reaming = 1 mm}.α SU7 : Parts are moved after indexing operation to perform reaming operation.(α SU7 ) m : Parts are moved after indexing 2 operations to perform reaming operation.η 1,1 : Take the part from bin1 one by one in ordering of first EM1, EM2 and EM3 or if and only if one of them is exists then perform the turning operation.The depth of cut is 3 mm.The few EM2 part will move to bin 2. α 1,2 : Take the part after performing the facing operation then go to the boring operation.η 2,1 : Take the part from bin 5 one by one in the ordering of first EM1, EM2 and EM3 or if and only if one of them is exists there then perform the indexing operation {Index = 6}.η 2,2 : Part will move to bin 6. η 2,3 : The Part will move to bin 6 at machine and bin 7 for supervisor model.η 2,4 : Part will move to bin 7 at machine and part will move for bin 8 for supervisor model.

Supervisor Model
In the supervisor model, we have only one supervisor and the supervisor will provide information to all users to perform the needed task as per the production schedule.The supervisor switches on the robot to transfer the part to its dedicated place.The parts will be moved by robot after the indexing operation to perform the reaming operation.Similarly, this operation is needed on those parts that have already under-gone the boring operation of user model 3.

Supervisor Machine Model
The supervisor will switch on the conveyor to transfer the part to its dedicated place and the parts will move from bin 6 to bin 2 and vice versa.Similarly, the parts move from bin 3 to bin 7 and bin 7 to bin 10.The user only places the part on to the conveyor and all the parts are moved through the conveyor which is controlled by the supervisor as per their company production plan.The dashed line is used for the machine transition and the dark lines represent the supervisor task as shown in Figures 8  and 9.The supervisor machine events are ∑ obs S = {β S1 , β S2 , β S3 , β S4 } and ∑ int S = {}.The procedure of iteration 2 is given in the Section 7 and their subsections.

Supervisor Model
In the supervisor model, we have only one supervisor and the supervisor will provide information to all users to perform the needed task as per the production schedule.The supervisor switches on the robot to transfer the part to its dedicated place.The parts will be moved by robot after the indexing operation to perform the reaming operation.Similarly, this operation is needed on those parts that have already under-gone the boring operation of user model 3.
While, after the facing operation the parts will move to indexing and boring operation.The supervisor events are 1 ( )

Supervisor Machine Model
The supervisor will switch on the conveyor to transfer the part to its dedicated place and the parts will move from bin 6 to bin 2 and vice versa.Similarly, the parts move from bin 3 to bin 7 and bin 7 to bin 10.The user only places the part on to the conveyor and all the parts are moved through the conveyor which is controlled by the supervisor as per their company production plan.The dashed line is used for the machine transition and the dark lines represent the supervisor task as shown in Figures 8 and 9

Discussion
Formal verification was performed using the model composition of user with machine and supervisor with a machine.For all user models, two of the timed automaton-based formalisms indicated that the acts of user model 2 and user model 3 reset-ability, act and skip-ability, every part of these user model as shown in Figure 8 and its associated time transitions between execution states was not reachable.Similarly, 6 S n and S 7 n in the supervisor model the supervisory task was unable to reach their target state as per customer requirements.Indicating that a conflicting mode arises which does not fulfil the user and the supervisor demand.Thus the complete-ability [35] will not be evaluated correctly, indicating that the manufacturing process of the exhaust manifold observed by user with machine and supervisor with the supervisor machine model composition.This could go for the exhaust gas leakage inside the engine compartment to create malfunction during driving of the car.In the user model the event sets 2 , 3 η and 3 , 2 η have an issue with the interaction of the machine due to their unmatched state compositions.Similarly, supervisor has also an unmatched state with their machine during the execution of task.This information was not mentioned inside the user manual.In that case the interface should be correct for the user and supervisor and there is a need to update the user and supervisor manual to execute the task by user and supervisor as per customer needs.

Formal Verification Results
Formal verification was done on a LG computer in succession with Linux Mint 18 with an intel core i7, and 64 giga bytes of RAM, Ansan, Korea with the aid of SAL's symbolic model checker open source.It acquired 19.86 s of entire completing time to validate all 68 obtained properties with 1496 numbered as the determined staying at states for verification.We also used the Z-eves tool for model verification using proof.Further, there is no counterexample formed.

Discussion
Formal verification was performed using the model composition of user with machine and supervisor with a machine.For all user models, two of the timed automaton-based formalisms indicated that the acts of user model 2 and user model 3 reset-ability, act and skip-ability, every of these user model as shown in Figure 8 and its associated time transitions between execution states was not reachable.Similarly, n S6 and n S7 in the supervisor model the supervisory task was unable to reach their target state as per customer requirements.Indicating that a conflicting mode arises which does not fulfil the user and the supervisor demand.Thus the complete-ability [35] will not be evaluated correctly, indicating that the manufacturing process of the exhaust manifold observed by user with machine and supervisor with the supervisor machine model composition.This could go for the exhaust gas leakage inside the engine compartment to create malfunction during driving of the car.In the user model the event sets η 2,3 and η 3,2 have an issue with the interaction of the machine due to their unmatched state compositions.Similarly, supervisor has also an unmatched state with their machine during the execution of α SU6 and α SU7 task.This information was not mentioned inside the user manual.In that case the interface should be correct for the user and supervisor and there is a need to update the user and supervisor manual to execute the task by user and supervisor as per customer needs.

Formal Verification Results
Formal verification was done on a LG computer in succession with Linux Mint 18 with an intel core i7, and 64 giga bytes of RAM, Ansan, Korea with the aid of SAL's symbolic model checker open source.It acquired 19.86 s of entire completing time to validate all 68 obtained properties with 1496 numbered as the determined staying at states for verification.We also used the Z-eves tool for model verification using proof.Further, there is no counterexample formed.

Scalability
We have no observation for substantial growth during the verification times and states pace magnitudes among the normal behavior of model holding at 2 min 38 s and 3,062,072 states producing scheme obtainable here does scale fit.Therefore, the scheme may be suitable for the examination of considerable bigger systems.Forthcoming work should explore how this technique should implement for different scenario.The procedure for iteration 3 and 4 are given in Section 8 and their subsection.

Interface of User Model and Supervisor Model
We rectified the supervisor interface as shown in Figure 10, interface of user model 2 as shown in Figure 11 and the user model 3 interfaces as shown in Figure 12 using the weak bi-simulation approach.This interface of user and the supervisor will be co-reachable because the weak bi-simulation preserves this property.We already implemented this interface after we received feedback from the customer in favor of the product.Further, this interface allows the user and supervisor to handle the non-deterministic choices with the help of time transition in user and the supervisor model as shown in Figures 10-12.
Operational incidents occur when the part is fitted into the vehicle and then after few weeks, leakage is identified by the customer.Normally this type of complain would not appear on the plant and dealer side.However, the customer feedback motivates us to improve the quality of product inside the plant to make the product as per the standard criteria.Similarly, the set pipe hose has no leakage after the improvement in the interface model of user and the supervisor and further the malfunctioning of the solenoid valve was not observed, and it performs well.

Interface of User Model and Supervisor Model
We rectified the supervisor interface as shown in Figure 10, interface of user model 2 as shown in Figure 11 and the user model 3 interfaces as shown in Figure 12 using the weak bi-simulation approach.This interface of user and the supervisor will be co-reachable because the weak bisimulation preserves this property.We already implemented this interface after we received feedback from the customer in favor of the product.Further, this interface allows the user and supervisor to handle the non-deterministic choices with the help of time transition in user and the supervisor model as shown in Figures 10-12.
Operational incidents occur when the part is fitted into the vehicle and then after few weeks, leakage is identified by the customer.Normally this type of complain would not appear on the plant and dealer side.However, the customer feedback motivates us to improve the quality of product inside the plant to make the product as per the standard criteria.Similarly, the set pipe hose has no leakage after the improvement in the interface model of user and the supervisor and further the malfunctioning of the solenoid valve was not observed, and it performs well.

Interface of User Model and Supervisor Model
We rectified the supervisor interface as shown in Figure 10, interface of user model 2 as shown in Figure 11 and the user model 3 interfaces as shown in Figure 12 using the weak bi-simulation approach.This interface of user and the supervisor will be co-reachable because the weak bisimulation preserves this property.We already implemented this interface after we received feedback from the customer in favor of the product.Further, this interface allows the user and supervisor to handle the non-deterministic choices with the help of time transition in user and the supervisor model as shown in Figures 10-12.
Operational incidents occur when the part is fitted into the vehicle and then after few weeks, leakage is identified by the customer.Normally this type of complain would not appear on the plant and dealer side.However, the customer feedback motivates us to improve the quality of product inside the plant to make the product as per the standard criteria.Similarly, the set pipe hose has no leakage after the improvement in the interface model of user and the supervisor and further the malfunctioning of the solenoid valve was not observed, and it performs well.

Conclusions
The design of an interface based on user understanding about the systems is not as stable as manufacturing systems and product quality demand, due to several user-machine interactions aligned with the supervisor when the process of manufacturing is ongoing.However, a general observation can still be drawn about their relative performance.To compare with those needs, we developed a formal framework for the analysis of human-computer interaction systems modelling based on time automaton.Compared with other models [36], our novel approach describes the formal models of user and supervisor activities with their machine behavior by adopting the modelling techniques of time automaton with full control and mode preserving.Also, we propose a technique to generate the supervisor interface based on multiple users with a machine and user interface through weak bi-simulation.Moreover, our technique has the potential to evaluate the interaction in real time and we also discuss how these techniques can be adapted to consider information about the machine and user states to solve for non-deterministic choices.We used z-eves for analyze and validate the formal specification of supervisor, machine and weak bi-simulation relation.We used the iteration-based approach to validate the interactive systems by using weak bi-simulation through checking of two systems simultaneously using z-eves to generate the correct interface.We implemented our technique on case study of a transmission gear not shifting at more than 189 km/h.Each treatment-created specification property designed the estimated consequence on behalf of that, for all its related transitions among finishing states was accessible.Further, there is no counterexample formed.For future perspectives, a possible extension is to add information about the environment and a cognitive model of the system and user.Such information constitutes a user and supervisor state-based interface.The supervisor and user models for such systems can be advanced in the sense that their transitions should be well defined.This will raise some issues related with observation of the user and supervisor state-interface meaning that both should know the previous interface observation.Defining the generation of such an interface is a possible extension of this work.Finally, with this method the interfaces are more expressive and understandable, and improvements in product quality and customer response have also been achieved.

Figure 1 .
Figure 1.An example of a supervisor model.

→
true.The supervisor machine model as shown in Figure 2 can be represented in terms of timed automata; of supervisor machine states, OSM SM n N ∈ : Initial (Starting) state of supervisor machine, Set of edges termed the transition among the system states, assigns invariants to locations, ( ) B C is the clock constraints where x~n or x~y~n for [ ,<,=,>, ] x,y C,∈ ∈ ≤ ≥ and n∈ ℕ.According to the above definition we can write

Figure 1 .
Figure 1.An example of a supervisor model.
of edges termed the transition among the system states, I SM : N SM → B(C) assigns invariants to locations, B(C) is the clock constraints where x ∼ n or x ∼ y ∼ n for x, y ∈ C, ∼∈ [≤, <, =, >, ≥] and n ∈ N. According to the above definition we can write n SM g,a,r of clocks that is reset by SM e , SM  : Set of events among the supervisor machine states.

Figure 2 .
Figure 2.An example of a supervisor machine model.

::
an observable and controllable event having only one choice for supervisor operation, an observable and controllable event having more than one choice for supervisor operation, obs SM  : an observable and uncontrollable event and int SM

Figure 2 .
Figure 2.An example of a supervisor machine model.

Figure 3 .
Figure 3.An example of supervisor interface model.
Figure 4.The transition map, m N is the marker sate.Now, we are considering here the

1
com choice>  observable and controllable but also obs  observable and uncontrollable with respect to user therefore : rch M M P →   is in the form of natural projection.The relation of weak bi-simulation to M N according to the rch M  is the equivalence relation

Figure 3 .
Figure 3.An example of supervisor interface model.

Definition 5 .
in the form of natural projection.The relation of weak bi-simulation to N M according to the∑ rch M is the equivalence relation κ ⊆ N M × N M | for each (n M , n M ) ∈ κ and every e cor M ∈ ∑ cor M .If υ M (n M , e cor M )! then ∃(e cor M ) ∈ ∑ cor M υ M (n M , (e cor M) )! having the following.The co-reachable event e cor M that is executed by user e cor M is the natural projection P : (e cor M ) → P(e cor M ) while if the events are the same before and after the state then it will fall under the equivalence relation for each machine state υ M (n M , (e cor M ) ) that is reachable by machine state n M ∈ υ M (N M , (e cor M ) ) with the equivalence relation (nU , n U ) ∈ κ ∧ [n U ∈ N M ⇔ n U ∈ N M ]the events of a system using machine are the same n M ∈ υ M (n M , (e cor M ) )∃n M ∈ υ M (N M , (e cor M ) ) before and after the machine state as formally represented if and only if

23 Definition 5 .→
Appl.Sci.2018, 8, x FOR PEER REVIEW 14 of The co-reachable event cor while if the events are the same before and after the state then it will fall under the equivalence relation for each machine state the machine state as formally represented if and only if

Figure 4 .
Figure 4.An example of machine model.
they cannot be executed and will not fulfil the above definition criteria.The κ is the weak bi simulation relation to M N .According to the rch rch the reduced state as shown in Figure5, MR  : a common user action represents a single action in the reduced model in Figure5, n : the reduced initial state as specified by, the reduced form of M M by using the techniques of weak bi-simulation relation ~rch M M  .As per the consideration of our example the final version of the automaton will be as in Figure5.The partition on the set of state is above automaton is in the form of the reduced automaton.

Figure 4 .
Figure 4.An example of machine model.

23 Figure 5 .
Figure 5.An example of reduced machine model.We can define the product of two systems , ) || : || :( M M

Figure 5 .
Figure 5.An example of reduced machine model. .

α
SU4 : Parts are moved after facing operation to perform Indexing operation.(α SU4 ) m : Parts are moved after facing operation to perform Indexing 1operation.α SU5 : Parts are moved after facing operation to perform boring operation.(α SU5 ) m : Parts are moved after facing operation to perform boring1 operation.α SU6 : Parts are moved after boring operation to perform reaming operation.

η 2 , 5 :
Part will move to Bin 8. β 2,1 : Part is moving into the knurling operation {Length = 18 mm}.β 2,2 : Part is moving into the taping operation {Length = 8 mm}.β 2,1b : Part is moving into the indexing 2 operation {Index = 6}.β S2 : Parts are moved through conveyor to bin 6 from bin 2. η 3,1 : Take the part from bin 9 one by one in the ordering of first EM1, EM2 and EM3 or if and only if one of them is exists there then perform the boring operation {Doc = 3 mm}.

3 S:
Parts are moved through conveyor to bin 7 from bin 3.

4 Sβ
: Parts are moved through conveyor to bin 10 from bin 7.


used as Ssint for machine we used Ssmint.Similarly, the symbol cor M  used as Sscor for machine we used Ssmcor, rch M  used as Ssrch for machine we used Ssmrch.Finally, the symbol int SM  used as Ssint for machine we used Ssmint and cor M e used as emcor respectively.

Figure A1 .
Figure A1.The snapshot of the formal specification analysis of supervisor model.

Figure A2 .
Figure A2.The snapshot of the formal specification analysis of machine model.

Figure A1 .
Figure A1.The snapshot of the formal specification analysis of supervisor model.

Figure A1 .
Figure A1.The snapshot of the formal specification analysis of supervisor model.

Figure A2 .
Figure A2.The snapshot of the formal specification analysis of machine model.Figure A2.The snapshot of the formal specification analysis of machine model.

Figure A2 .
Figure A2.The snapshot of the formal specification analysis of machine model.Figure A2.The snapshot of the formal specification analysis of machine model.

Figure A2 .
Figure A2.The snapshot of the formal specification analysis of machine model.

Figure A3 .
Figure A3.The snapshot of the formal specification analysis of weak bi-simulation model.

Table 1 .
Event execution based on criteria of observability and controllability through user and machine operation.
n OS , E S , I S Where, N S : Set of supervisor states, n OS ∈ N S : Initial (starting) state in the supervisor, E S ⊆ N S × B(C) × ∑ S ×2 C × N S : Set of edges termed as transition among the system states, I S : N S → B(C) Assigns invariants to locations.
(N SM2 ) #x2032; , (N S2 ) ) ∈ B RSM if and only if ∃β S1 and ((N SM3 ) , (N S3 ) ) ∈ B RSM if and only if ∃β S2 .The unobservable and uncontrollable event (γ S1 , γ S2 , γ S3 , γ S4 ) ∈ ∑ int S will not change the state of the supervisor.It is the internally change of machine state is and unobservable because there is no supervisor action either before or after the formation of the machine state.It may cause the uncontrollable event

Table 2 .
Event execution based on criteria of observability and controllability through supervisor and supervisor machine operation.