Integrating the Operator into Formal Models in the Air-Traffic Control Domain

Growing use of computers in safety-critical systems increases the need for Human Computer Interfaces (HCIs) to be both smarter to detect human errors and better designed to reduce likelihood of errors. We are developing methods for determining the likelihood of operator errors which combine current theory on the psychological causes of human errors with formal methods for modelling human-computer interaction. This paper outlines an approach to developing formal methods for evaluating safety of interactive systems, and illustrates the approach on a simplified problem from Air Traffic Control. We outline formal models for three components of an ATC simulator: the underlying computer system, the HCI and the operator.