ion level. In Slomka et. al., the authors define an abstract reference model, which captures all of the information about the system, and specific models, which are built from the reference model. Feiler et. al. proposes an approach that defines an architecture model as the single source for architecture analysis. Independently maintained analytical models and views are generated from the architecture model. The architecture model has annotations that describe characteristics of objects in the model. The characteristics, such as fault rates, security properties, and timing, may be used in domain specific analyses. Any changes to the architecture are reflected in all dimension of the views and the domain specific analyses. As with other approaches in this category, the consistency between views can be managed using model transformation and translation techniques by construction of the architecture model. This approach reduces the effort to manage consistency between views. Our work is most closely related to the second approach for multi-view modeling. We construct a system model by establishing a common semantic domain from which different views may be constructed or generated. A common semantic domain is a common language for which reasoning different aspects of a system can be achieved in a semantically consistent way. Our approach establishes a common semantic domain by developing a common system model from which views are projected. To avoid conflicts when multiple views contain overlapping content, we establish authoring privileges that dictate which view can be modified. This influences the propagation of changes to the other views through the system model. Moreover, our work is aimed for declarative modeling as opposed to executable simulation models. This allows us to express analytical models and use declarative proposition logics to describe the intent of the system without having to specify all of the details of the implementation of specification in the target analytical tool. This allows for abstracting the intent of the system architecture from its implementation. In addition, we have observed that little work has applied MBSE to explicitly capture the architectural decision process that is inherent in system architecting. Using models and automated optimization techniques in rigorous design flows have yet to be applied broadly in space system design as it has been applied in other domains such as system-on-chip design and Very-Large Scale Integrated (VLSI) circuit design where the use of models in system development has resulted in huge increases in design productivity and improved design quality . Similarly, we are working towards the development of a framework that embodies a rigorous design flow for space system design. As with any design flow, models and choosing the appropriate levels of abstraction are essential. In our approach, we avoid arbitrarily choosing abstractions for the common system model based on hierarchy alone. Instead, we choose appropriate abstractions that drive more detailed architecture decisions, and we partition the common system model using the chosen set of abstractions. As a result, we not only support multi-view modeling, but our approach for capturing the system architecture is more aligned with key architectural decisions. Thus, it is amenable to automatic and synthesis-based design exploration. In this paper we will describe our work towards a design environment that embodies a rigorous design flow for space system design. III. Overview of Approach Raising the level of abstraction is widely recognized in software and electronic system design communities as a technique to address complexity. Abstraction is a technique that helps to manage complexity by hiding information that is irrelevant to a problem. Abstractions can be categorized into vertical and horizontal abstractions. Vertical abstraction hides information at different levels of detail, whereas horizontal abstraction abstracts information at the same level of abstraction. Complexity can be managed more effectively by decomposing a system into abstractions. Abstraction in system architecting allows system engineers to focus on bounding problems whose solution remains agnostic to the greater problem as a whole. However, the essence of abstraction in system design is choosing the appropriate level of abstraction to address a problem. This is true for architecting space systems, as well. A central tenet of a systems approach to system architecting and engineering is choosing appropriate abstractions for specific concerns while simultaneously considering the problem as a whole. System architecting of space systems is a decision process that requires information with various degrees of granularity. Our approach applies the principles of component-based design and platform-based in the development of space system architecture to capture and effectively traverse the problem space at multiple levels of abstraction. The approaches are complementary, and they are used together to achieve a balance between contradicting goals of generality and achieving efficient component implementation. The following sections provide a summary of these principles.
Modern space flight systems are required to perform more complex functions than previous generations to support space missions. This demand is driving the trend to deploy more electronics to realize system functionality. The traditional approach for the specification, design, and deployment of electrical system architectures in space flight systems includes the use of informal definitions and descriptions that are often embedded within loosely coupled but highly interdependent design documents. Traditional methods become inefficient to cope with increasing system complexity, evolving requirements, and the ability to meet project budget and time constraints. Thus, there is a need for more rigorous methods to capture the relevant information about the electrical system architecture as the design evolves. In this work, we propose a model-centric approach to support the specification and design of electrical flight system architectures using the System Modeling Language (SysML). In our approach, we develop a domain specific language for specifying electrical system architectures, and we propose a design flow for the specification and design of electrical interfaces. Our approach is applied to a practical flight system.
In the verification of multitask software in real-time embedded systems, general purpose model checkers do not inherently consider characteristics of the real-time operating system, such as priority-based scheduling, priority inversion, and protocols for protecting shared memory resources. Since explicit state model checkers generally explore all possible execution paths and task interleaving, this could potentially lead to exploring execution paths that are redundant, unnecessarily increasing verification complexity and hampering tractability. Based on this premise, in this work we investigate how one can improve the performance of explicit state model checkers, such as SPIN, for the verification of multitask applications that target real-time operating systems.
We introduce a model-based approach to heterogeneou s system design that enables the automatic generati on of fault trees for analyzing system reliability properties. This approach extends our previous work that addre ssed the generation of fault trees from a dataflow model. I n this new context, heterogeneous systems are compo sed f interacting discrete-time components, such as an el ectronic feedback controller, and continuous-time c omponents, such as a plant. More recent work in computer-aide d fault-tree generation methods is based on functio al models of the system to produce a system fault tree automatic ally. Yet, most of these approaches were not appli ed to heterogeneous systems. Furthermore, these approache s continued to rely on intuition to create fault tr ees. Since in this approach fault tree generation is disjoint fro m the system modeling, consistency problems may ari se when the structure and behavior of the system model is not a ccurately reflected. Our approach is different sin ce we use a model of the system specified as a set of mathemati cal equations to derive the system fault modes and ultimately produce fault trees for heterogeneous systems.
Designing embedded software for complex, safety critical, realtime feedback control applications is a complex task. Typical applications, like a steer-by-wire application, contain a model of the components computing control laws and interacting with a plant using sensors and actuators. Well-defined mathematical models are often useful in the design of such systems because they allow formal validation, techniques like code generation, and reduces the ambiguity in specifications amongst a team of designers. An experimental model of computation called Fault Tolerant Data Flow is explored for safety critical, real-time feedback control systems. This report describes the operational semantics and structure of this model of computation, and its implementation in the Ptolemy II design environment.
Claudio Pinello合作论文数Cadence Research Labs1