Better bounds by worse assumptions — Improving network calculus accuracy by adding pessimism to the network model
Steffen Bondorf · 2017
Safety-critical systems require certification in order to attain permission to operate. Nowadays, these systems routinely embed a communication sub-systems whose performance must be formally verified for certification. Deterministic Network Calculus (DNC) can be employed for this task. It provides a mathematical framework to derive worst-case bounds on the delay of data flows, i.e., deterministic delivery guarantees. Their accuracy is decisive as even small improvements can change the outcome of certification. In general, delay bound accuracy depends on the accuracy of the network model. While previous work assumed that a more accurate model will invariantly yield more accurate delay bounds, we show that the opposite can actually be true. In this paper, we examine a specific weakness of DNC network analysis that leads to this counter-intuitive result. We make use of this insight in a mitigation strategy called flow prolongation. By prolonging the paths of flows, we let them interfere with more other flows but may still get better results. An evaluation in differently sized networks gives information about its impact on delay bound accuracy as well as analysis effort.