The combination of integrated software controlling devices, networking capabilities, and sensing/actuation technologies in Medical Cyber-Physical Systems (M-CPS) highlights some research challenges specific to this class of Cyber-Physical Systems (CPS). The major challenge is ensuring the confidentiality of the data or resources that they handle. In this paper, we tackle this problem by proposing a formal approach that combines CA-BRS (Control Agent and Bigraphical Reactive Systems) and BPMN (Business Process Model Notation) to specify and analyze CPS in general, while respecting several dimensions. The CPS structural dimension, which represents the space (physical and cyber entities) in which agents exist and interact, is defined by the Bigraphs. Control agents constituting the virtual dimension observe and control the physical and cyber entities of their environment. The complex and adaptive behavior of a CPS (behavioral dimension) is defined through several types of rules; each manages a possible evolution of a CPS component (physical, cyber or virtual). Two distinctive perspectives are associated with the semantic interpretation of these rules: states and activities. Both perspectives are defined with a particular semantics and notations.
This study focuses on the activities perspective that specifies the behavior of control agents using a BPMN activity diagram. This highlights how these two models (CA-BRS and BPMN) complement each other to assist designers in defining formal models for CPS. Additionally, it reveals how to provide the CA-BRS model with means of controlling unauthorized access to an Electronic Health Record system.