Assuring Software Fault Management with the Architecture Analysis and Design Language

Kenneth Evensen, Michela Muñoz Fernández · Infotech@Aerospace 2012 · 2012

Real-time software is becoming more prevalent in avionics systems such as unmanned aerial vehicles and spacecrafts. More often, these systems operate with limited human interaction or an increased latency in human response. Therefore, these systems require autonomous fault detection and a repair mechanism to respond to off nominal conditions that could arise. In order to prevent a hazard, these systems require assurance that they will operate in a safe manner while successfully completing a mission. Assurance, as a software engineering activity involves the reduction of risk, and inversely, an increase in confidence in a software system. In the context of fault management, this becomes a question of increasing confidence that a software system can detect and respond to the offnominal conditions occur. This activity is not always straight forward as off-nominal conditions in complex real-time systems do not always manifest as singular events, but rather as a combination of symptoms. Furthermore, for fault management assurance to be useful it needs to be rigorous. Therefore, the approach needs to be supported by a standard, repeatable framework. The foundation for this framework is in the ability to model the fault management system integrated in the hardware and software avionics real-time system. Models can assist in assuring both functional and quality attribute requirements such as reliability. The Architecture Analysis and Design Language (AADL) is a Society of Automotive Engineers (SAE) standard notation (AS5506/1) for the modeling and analysis of real-time systems. AADL has been extended to model fault management behavior through the AADL Error Annex, also an SAE standard. At its core, the AADL Error Annex provides rules for how software and hardware components are allowed to propagate an error across the avionics real-time system modeled in AADL. Because a standard notation is being used, there is intrinsic confidence to the approach. This paper will explore how the assurance of software fault management can be applied in practice. First, it is important to briefly review AADL and the AADL Error Annex as well as common terminology related to software fault management. Next, the application of software fault management assurance will be discussed. The first step in this application is to understand the very basic (atomic) hardware and software faults that occur at the component level. This information can be collected in the form of a failure modes and effects analysis (FMEA). An analysis is required in order to evaluate the ability of the software fault management system to, at the very least, detect the symptoms. This analysis answers two fundamental questions. First, to what degree are faults visible to the avionics software? Second, to what degree does the avionics software handle these faults? This paper presents an example to demonstrate the assurance of software fault management. The software fault management assurance framework proposed in this paper utilizes a standard notation, coupled with a formal mechanism for modeling faults. This provides a rigorous foundation for analysis on the avionics software real-time system in a repeatable manner. Therefore a model based assurance activity of a software fault management system can successfully be applied.

Read the paper · More papers on PaperTik