Justifying the Service Provided to Low Criticality Tasks in a Mixed Criticality System

Stephen Law, Iain Bate, Benjamin Lesage · 2020

Significant work has been presented over the last decade looking at the application of Mixed Criticality Scheduling. The premise being that if a failure occurs the scheduler performs a mode change from normal mode to high-criticality mode. In high-criticality mode, some low criticality tasks are given a reduced service (e.g. not executed or executed at a different period). Recently work has been performed to bound the number of low criticality jobs that might be skipped while the scheduler operates in high-criticality mode. However a significant gap in the analysis is to understand for how long the service to low criticality tasks may be reduced, i.e. how often the system switches to a high-criticality mode and how long the high-criticality mode is sustained. This is essential as part of supporting software certification. In this paper we consider a process, agnostic to the underlying scheduling strategy, designed to allow a system integrator to address this gap by assessing the level of service provided to low criticality tasks. The result is a safety argument with supporting evidence based on a real life case study, taken from a DAL-A certified aircraft engine control system.1

Read the paper · More papers on PaperTik