Reasoning about the Reliability of Multi-Version, Diverse Real-Time Systems
A. Burns and B. Littlewood
This paper is concerned with the development of reliable real-time systems for use in high integrity applications. It advocates the use of diverse replicated channels, but does not require the dependencies between the channels to be evaluated. Rather it develops and extends the approach of Littlewood and Rushby (for general systems) by investigating a two channel system in which one channel, A, is produced to a high level of reliability (i.e. has a very low failure rate), while the other, B, employs various forms of static analysis to sustain an argument that it is perfect (i.e. it will never miss a deadline). The first channel is fully functional, the second contains a more restricted computational model and contains only the critical computations. Potential dependencies between the channels (and their verification) are evaluated in terms of aleatory and epistemic uncertainty. At the aleatory level the events ``A fails'' and ``B is imperfect'' are independent. Moreover, unlike the general case, independence at the epistemic level is also proposed for common forms of implementation and analysis for real-time systems and their temporal requirements (deadlines). As a result, a systematic approach is advocated that can be applied in a real engineering context to produce highly reliable real-time systems, and to support numerical claims about the level of reliability achieved.
BibTex Entry
@inproceedings{Burns2010g, author = {A. Burns and B. Littlewood}, booktitle = {Proceedings of 31st IEEE Real-Time Systems Symposium}, month = {December}, pages = {73--81}, publisher = {IEEE Computer Society}, title = {Reasoning about the Reliability of Multi-Version, Diverse Real-Time Systems}, year = {2010} }