AADL Tutorial: Architecture Analysis & Design Language Overview

Page 1 sur 218Lecteur de document UniversityLib

AADL Tutorial: Architecture Analysis & Design Language Overview

Software Architecture and Systems Engineering · notes

Voir tous les documents en génie logiciel

Pyrrhus Software

Enduring Solutions

The SAE

Architecture Analysis & Design

Language

(AADL)

www.aadl.info

Bruce Lewis

Army AMCOM SED

Redstone Arsenal, AL

[email protected]

256-876-3224

Joyce L Tokar

Pyrrhus Software

Phoenix, AZ

[email protected]

480-951-1019

AADL Tutorial

AADL Tutorial

1

Tutorial Objectives

• Provide an overview of the SAE AADL Standard.

Introduce architecture-based development concepts.

• Provide a summary of AADL capabilities.

• Demonstrate the benefits of AADL in real-time systems

design.

• Provide an overview of the AADL development

environment.

AADL Tutorial

AADL Tutorial

2

Tutorial Outline

• Background & Introduction

• Introduction to AADL

• AADL in Use

• AADL Development Environment

• Benefits of AADL

AADL Tutorial

AADL Tutorial

3

The SAE AADL Standard

• Sponsored by

(cid:31)Society of Automotive Engineers (SAE)

• Avionics Systems Division (ASD)

o Embedded Systems (AS2)

» Avionics Architecture Description Language

Subcommittee (AS2C)

» Bruce Lewis -- Chairman

» [email protected]

• Status

(cid:31)Requirements document SAE ARD 5296

• Balloted and approved in 2000.

(cid:31)Standard document SAE AS 5506

• Balloted and approved 2004.

• Contact

(cid:31) http://www.aadl.info

email: [email protected]

AADL Tutorial

AADL Tutorial

4

SAE AS-2C ADL Subcommittee

• Key Players:

(cid:31) Bruce Lewis (AMCOM): Chair, technology user

(cid:31) Steve Vestal (Honeywell): MetaH originator, co-author

(cid:31) Peter Feiler (SEI): Secretary, main author, editor,

technology user

(cid:31) Ed Colbert (USC): AADL & UML Mapping

(cid:31) Joyce Tokar (Pyrrhus Software): Programming Language

Annex, co-editor

• Members:

(cid:31) Boeing, Rockwell, Honeywell, Lockheed Martin, Raytheon,

Smith Industries, Airbus, Axlog, Dassault, EADS , Canadair,

High Integrity Systems

(cid:31) NAVAir, Open Systems JTF, British MOD, US Army

(cid:31) European Space Agency

• Coordination with:

(cid:31) NATO, ESA, COTRE, OMG-UML

AADL Tutorial

AADL Tutorial

5

Architecture & Analysis Design Language

AADL

• Specification of

(cid:31) Real-time

(cid:31) Embedded

(cid:31) Fault-tolerant

(cid:31) Securely partitioned

(cid:31) Modal & dynamically configurable

• Software task and communication architectures

• Bound to

(cid:31) Distributed multiple processor hardware architectures

• Fields of application

(cid:31) Avionics, Aerospace, Automotive, Autonomous systems,

AADL Tutorial

AADL Tutorial

6

Fields of Application

• Automotives

• Avionics

• Robotics

• Fixed sampling and processing rates

• Variable sampling and processing rates

• Stochastic event and processing rates

• Known operational modes and configurations

• Large-scale system integration

AADL Tutorial

AADL Tutorial

7

MetaH - A Precursor to AADL

1991 DARPA DSSA program begins

1992 Partitioned PFP target (Tartan MAR/i960MC)

1994 Multi-processor target (VME i960MC)

1995 Slack stealing scheduler

1998 Portable Ada 95 and POSIX middleware configurations

1999 Hybrid automata verification of core middleware modules

Numerous evaluation and demonstration projects, e.g.

Missile G&C reference architecture, demos, others (AMCOM SED)

Hybrid automata formal verification (AFOSR, Honeywell)

Missile defense (Boeing)

Fighter guidance SW fault tolerance (DARPA, CMU, Lockheed-Martin)

Incremental Upgrade of Legacy Systems (AFRL, Boeing, Honeywell)

Comanche study (AMCOM, Comanche PO, Boeing, Honeywell)

Tactical Mobile Robotics (DARPA, Honeywell, Georgia Tech)

Advanced Intercept Technology CWE (BMDO, MaxTech)

Adaptive Computer Systems (DARPA, Honeywell)

Avionics System Performance Management (AFRL, Honeywell)

Ada Software Integrated Development/Verification (AFRL, Honeywell)

FMS reference architecture (Honeywell)

JSF vehicle control (Honeywell)

IFMU reengineering (Honeywell)

AADL Tutorial

AADL Tutorial

8

MetaH Case Study at AMCOM

• Missile Application reengineered

(cid:31) Missile on-board software and 6DOF environment simulation

executing on dual i80960MC, Tartan Ada, VME Boards

(cid:31) Built to Generic Missile Reference Architecture

(cid:31) Specified in MetaH, 12 to 16 concurrent processes

(cid:31) MetaH reduced total re-engineering cost 40% on first project

it was used on. Missile prime estimated savings at 66%.

• Missile Application ported to a new execution

environment

(cid:31) Multiple ports to single and dual processor implementations

(cid:31) New processors (Pentium and PowerPC), compilers, O/S

(cid:31) First time executable, flew correctly on each target

environment

(cid:31) Ports took a few weeks rather than 10 months.

AADL Tutorial

AADL Tutorial

9

8000

7000

6000

5000

4000

3000

2000

1000

M

a

n

H

o

u

r

s

AMCOM Effort Saved Using

MetaH

Total project savings 50%, re-target savings 90%

Benefit During

Platform Retarget

Benefit During

Application Rewrite

0

Review 3-DOF

Trans-

late

6-DOF

Traditional

Approach

Using

MetaH

RT-

6DOF

Trans-

form

Test

6DOF

RT-

Missile

Build

Debug

Current

MetaH

Debug

Re-target

AADL Tutorial

AADL Tutorial

10

Architecture Description Languages

Research ADLs

• MetaH

(cid:31) Real-time, modal, system family

(cid:31) Analysis & generation

(cid:31) RMA based scheduling

Basis

• Rapide, Wright, ..

(cid:31) Behavioral validation

Extension

• ADL Interchange

(cid:31) ACME, xADL

(cid:31) ADML (MCC/Open Group, TOGAF)

Influence

Industrial Strength

• HOOD/STOOD

• SDL

• UML 2.0, UML-RT

Alignment

Enhancements

Extensible

Real-time

Dependable

AADL Tutorial

AADL Tutorial

11

Typical Software Development

Process

Requirements

Analysis

Design

Implementation

Integration

manual, paper intensive, error prone, resistant to change

AADL Tutorial

AADL Tutorial

12

Model-Based System Engineering

Model-Based & Architecture-Driven

Requirements

Analysis

Explicit Architecture

Engineering Models

Use of AADL

System

Integration

Predictable System

Rapid Integration

Upgradeability

Design, Analysis

and Implementation

AADL Tutorial

AADL Tutorial

13

Model-Based System Engineering

SoS Analysis

• Schedulability

• Performance

• Reliability

• Fault Tolerance

• Dynamic Configurability

Software

Systems

Engineer

System Construction

• Executive generation

• System Integration

Model the

Architecture,

Abstract & Precise

Performance-Critical Architecture Model

Application System & Execution Platform

Application

Software

Guidance

& Control

Automatic

Target

Recognition

Domain Specific

Components & Subsystems

Sensor

& Signal

Processing

Supply

Chain

Mechanized

Ambulatory

Information

Fusion

Execution

Platform

GPS

DB

HTTPS

Publicité

. . . . . . . . . .

RTOS

Devices Memory

Bus

Processor

AADL Tutorial

AADL Tutorial

14

Tutorial Outline

• Background & Introduction

• Introduction to AADL

• AADL in Use

• AADL Development Environment

• Benefits of AADL

AADL Tutorial

AADL Tutorial

15

What is Software Architecture?

• Architecture is the fundamental organization of a

system as embodied in

(cid:31)its components,

(cid:31)their relationships to each other and the environment,

(cid:31)the principles governing its design and evolution.

• The software architecture of a program or computing

system is

(cid:31)the structure or structural arrangements of its

composite software elements,

(cid:31)the externally visible properties of those elements,

(cid:31)the relationships among them.

Architecture is the foundation of

good software system engineering

AADL Tutorial

AADL Tutorial

16

What is an

Architecture Description Language

(ADL)?

• The architecture of a system defines its high-

level structure and exposes its gross organization

as a collection of interacting components.

• An Architecture Description Language (ADL)

focuses on the high-level structure of the overall

application rather than on the implementation

details of any specific component.

• ADLs and their accompanying toolsets support

architecture-based development, formal

modeling, and analysis of architectural

specifications.

AADL Tutorial

AADL Tutorial

17

Common Foundation of ADLs

• Components represent the primary (computational)

elements and data stores of a system.

• AADL Components:

(cid:31)Software Components:

• Data, subprogram, thread, thread groups process.

(cid:31)Execution Environment Components:

• Memory, bus, device, processor

(cid:31)Composite Components:

• System

• AADL Component Interfaces:

(cid:31)Shared Data

(cid:31)Ports

• Data ports, event ports, event data ports.

(cid:31)Subprogram Parameters

AADL Tutorial

AADL Tutorial

18

Common Foundation of ADLs

• Connectors represent interactions among

components.

• Connectors in AADL:

(cid:31)Subprogram Call Sequence

(cid:31)Connections

• Port connections, access connections

(cid:31)Flows

AADL Tutorial

AADL Tutorial

19

Common Foundation of ADLs

• Systems represent configurations of

components and connectors.

• Systems in AADL:

(cid:31)Packages

(cid:31)Systems

AADL Tutorial

AADL Tutorial

20

Common Foundation of ADLs

• Properties represent semantic information

about a system and its components that goes

beyond structure.

• AADL supplies:

(cid:31)Predefined Properties

(cid:31)User-defined Property Sets

AADL Tutorial

AADL Tutorial

21

Common Foundation of ADLs

• Constraints represent claims about an

architectural design that should remain true

even as it evolves over time.

• Constraints in AADL:

(cid:31)Hybrid automata assertions

(cid:31)Property value constraints

(cid:31)Annexes

AADL Tutorial

AADL Tutorial

22

Common Foundation of ADLs

• Styles represent families of related systems.

• Styles in AADL:

(cid:31)Multiple implementations

(cid:31)Refinement

(cid:31)Packages

(cid:31)Property sets

(cid:31)Annexes

AADL Tutorial

AADL Tutorial

23

Common Foundation of ADLs

• Components

• Connectors

• Systems

• Properties

• Constraints

• Styles

AADL Tutorial

AADL Tutorial

24

Focus Of SAE AADL

• Component View

(cid:31)Model of system composition & hierarchy.

(cid:31)Well-defined component interfaces.

• Concurrency & Interaction View

(cid:31)Time ordering of data, messages, and events.

(cid:31)Dynamic operational behavior.

(cid:31)Explicit interaction paths & protocols.

• Execution view

(cid:31)Execution platform as resources.

(cid:31)Binding of application software.

(cid:31)Specification & analysis of runtime properties

• timeliness, throughput, reliability, graceful

degradation, …

AADL Tutorial

AADL Tutorial

25

The AADL in a Nutshell

EXTENSIBLE/

SCALABLE

Multi-processor/multi-

process, easily add/change

and see effects. User defined

domain specific functions..

FLEXIBLE

System spec used to

change

implementation.

Interface with any

standard or

application

GENERIC

Modular,

scalable, system

“block diagram”

with semantics

System Architecture

Performance-Critical

Layering & Composition

Application

Thread, Process,

System

Execution Platform

Execution engine

Memory, Bus

Device

Components

Specifications

Variant implementations

Ports

Connections

Domain data objects

Behaviors

OBJECT-

ORIENTED

Clearly defined

object, messaging,

properties,

decomposition

OPEN

Gov usage rights.

Industry AADL

standard.

USABLE AND AVAILABLE

Approach/formalism is

SIMPLE/UNIFORM,

PRACTICAL, and EASY TO

USE, LEARN, AND

INTERFACE WITH OTHER

APPROACHES!

REUSABLE

Very portable.

Function/non-functional

requirements.

Ideal isolation from

hardware.

REAL-TIME

User specifies timing

requirements,

analyzers available,

concurrency handled

automatically!

RELIABILITY,

SAFETY,

SECURITY

SUPPORT

User specifies

requirements;

analyzers available

HARDWARE

MODELING AND BINDINGS FULLY

SUPPORTED BY AADL(auxiliary to

the SW API)

Implementation

HARDWARE

INDEPENDENT

No implementation

specified in SW API.

AADL Tutorial

AADL Tutorial

VERIFIABLE

Strong support for predictable

real-time architectures

exhibiting high-reliability

FORMAL, RICH

SEMANTICS

Models can span high-

level system to detailed

interfaces

26

The SAE AADL Standard

• Provides a standard & precise way to describe the

architecture of embedded computer systems.

• Provides a standard way to describe components,

assemblies of components, and interfaces to

components.

• Describes how components are composed together

to form complete system architectures.

• Describes the runtime semantics and thread

scheduling protocols.

• Describes the mechanisms to exchange control and

data between components.

• Describes dynamic run-time configurations.

AADL Tutorial

AADL Tutorial

27

AADL Concepts Overview

• Hierarchically composed & interconnected

components: system.

• Application system components: thread, thread group,

process, data, and subprogram.

• Execution platform components: processor, memory,

bus, and device.

Interaction in terms of directional flow via ports,

call/return, and data sharing.

• Flow of signals/state (data), control (event & time

triggered), and messages (event data) across multiple

components.

• Dynamic behavior in terms of statically known alternate

task & communication configurations (modes).

• Core AADL and Annex extensions.

AADL Tutorial

AADL Tutorial

28

Graphical & Textual Notation

system Data_Acquisition

features

speed_data: in data port metric_speed;

GPS_data: in data port position_carthesian;

user_input_data: in data port user_input;

s_control_data: out data port state_control;

end Data_Acquisition;

data type

of port

speed

_data

GPS

_data

user

input

data

Data_Acquisition

s_control_data

data port

AADL Tutorial

Publicité

AADL Tutorial

29

AADL Components

• Composite Components

(cid:31) System

• Software Components

• Execution Platform

(cid:31) Data

(cid:31) Subprogram

(cid:31) Thread

(cid:31) Thread Group

(cid:31) Process

Components

(cid:31) Memory

(cid:31) Device

(cid:31) Bus

(cid:31) Processor

AADL Tutorial

AADL Tutorial

30

AADL Components

• Component Type -- specifies the interface to

the component.

• Component Implementation -- zero or more

specifications of the component’s internal

representation.

AADL Tutorial

AADL Tutorial

31

System Components

• Specifies a well-formed interface.

• All external interaction points defined as features.

• Multiple implementations per component type.

• Properties as specified component characteristics.

• Components organized in nested hierarchy.

• Component interaction declarations must follow

system hierarchy.

AADL Tutorial

AADL Tutorial

32

System

System

• Hierarchical composition.

• Execution platform and application software

components.

• Data and bus sharable across system

hierarchy.

Features: port, subprogram

Provides: data access, bus access

Requires: bus access, data access

Subcomponents:

process, system,

memory, processor, bus,

device, and data

Connections: yes

Modes: yes

AADL Tutorial

AADL Tutorial

33

Device

device

• Physical component interfacing with environment.

Interacts with application components via port

connections.

• Connects physically to processors via bus.

• May have associated software executes on

connected processor.

• Examples

(cid:31) sensors and actuators

(cid:31) standalone systems such as a GPS

Features: port, subprogram

Requires: bus access

Connections: no

Modes: yes

AADL Tutorial

AADL Tutorial

34

AADL Interfaces & Connections

• Ports

(cid:31) Data ports

(cid:31) Event Data ports

(cid:31) Event ports

• Connections

(cid:31) Immediate

(cid:31) Delayed

AADL Tutorial

AADL Tutorial

35

AADL Interfaces & Connections

• Port Groups

• Connections

AADL Tutorial

AADL Tutorial

36

AADL Interfaces & Connections

• Subprograms

• Subprogram calls

(cid:31) Local

(cid:31) Server

(cid:31) Local

(cid:31) Remote

AADL Tutorial

AADL Tutorial

37

Shared Data & Bus Access

• Component requires

• Component provides

access

access

AADL Tutorial

AADL Tutorial

38

AADL Properties

• Predefined property

• User defined property

sets

sets

AADL Tutorial

AADL Tutorial

39

Application Component Hierarchy

System App

System S1

System S2

Process P2

Thread T5

Thread T6

Process P1

Thread T1

Thread T2

Process P3

Thread T3

Thread T4

Two ways of graphically

visualizing component hierarchy

AADL Tutorial

AADL Tutorial

40

3 Ways to Interact: AADL

Component Interaction

1553

Flight Mgr

Unidirectional

data & event flow

Synchronous call/return

(not shown)

data

Weapons

Mgr

Warnings

Annunciations

MFD Pilot

MFD Copilot

Managed shared data access:

only two threads have access

AADL Tutorial

AADL Tutorial

41

Application System & Execution

Platform

1553

Application system binding

to execution platform

Flight Mgr

Weapons

Mgr

data

Warnings

Annunciations

MFD Pilot

MFD Copilot

High speed network

Mission

Processor

Display

Processor

Display

Processor

1553 bus

Pilot Display

CoPilot Display

AADL Tutorial

AADL Tutorial

42

AADL and Scheduling

• AADL provides precise dispatch & communication

semantics via hybrid automata.

• AADL task & communication abstraction does not

prescribe scheduling protocols

(cid:31) Cyclic executive can be supported.

• Specific scheduling protocols may require additional

properties.

• Predefined properties support rate-monotonic fixed

priority preemptive scheduling.

This scheduling protocol is analyzable,

requires small runtime footprint,

provides flexible runtime architecture.

AADL Tutorial

AADL Tutorial

43

AADL Threads

• Threads

(cid:31)Periodic -- execute at given time intervals.

(cid:31)Aperiodic -- are triggered by an event or

remote procedure call.

(cid:31)Sporadic -- paced to limit execution rate.

(cid:31)Background -- run when there is available

processor time.

AADL Tutorial

AADL Tutorial

44

Active

Member of

current mode

Thread States

Uninitialized

Thread

Initialize

InitializeComplete:

Inactive

Not member of

current mode

InactiveInInitMode:

ActiveInInitMode:

Initialized

Thread

Activate

ActivateComplete:

ActiveIn

NewMode:

Inactive

DeactivateComplete:

Active

Dispatch:

Suspended

Complete:

Compute

Repaired:

Recovered:

Fault:

Recover

Deactivate

InactiveInNewMode:

Terminate:

Finalize

Thread State

Thread State with

Source Code

Execution

FinalizeComplete:

Terminated

Thread

Application Source Entrypoints

Application as Plug-in

AADL Tutorial

AADL Tutorial

45

Task & Interaction Architecture

Typed and

constrained

data streams

System System1

Immediate and delayed

communication

System Subsystem1

Thread Dispatch

Protocols

Periodic

Aperiodic

Sporadic

Background

Thread T3

Data1:

Pos

Process Prc1

Shared data

Data1:

Pos

Data1:

Pos

Process Prc2

E1

Thread T1

RSP1

SP1

SP2

Server Thread T2

Package

SP3

Thread T1

Data1

E1

Thread T2

E1

Directional

Data, event, message ports

Publicité

Queued and unqueued xfer

Call/Return

Local subprogram

Client/server subprogram

Shared Access

Persistent, shareable

data

Access coordination

AADL Tutorial

AADL Tutorial

46

Thread

Thread

Is a schedulable unit executing on a processor

under a scheduling protocol.

Is dispatched based on time or arrival of events.

• Executes within the protected address space of a

process.

Interacts with other threads through port

connections, remote subprogram calls, and shared

data access.

• Can be logically organized into thread groups.

Remote service calls

Features:

port, server subprogram

Requires: data access

Provides: data access

Subcomponents: Data

Connections: no

Modes: yes

AADL Tutorial

AADL Tutorial

47

Faults and Modes

• AADL provides a fault handling framework with

precisely defined actions.

• AADL supports runtime changes to task &

communication configurations.

• AADL defines timing semantics for task coordination

on mode switching.

• AADL supports specification of mode transition

actions.

• System initialization & termination are explicitly

modeled.

AADL Tutorial

AADL Tutorial

48

Hierarchical Modes

System System1

Mode as Alternative Configuration

E1 A

System Subsystem1

Initial Mode A: Prc1, Prc2;

Mode B: Prc1, Prc3;

Initial Mode A: T1, T2, T3;

Mode B: T1, T2;

Process Prc1

E1 A

Shared data

Thread T3

Data1:

Pos

Thread T1

RSP1

Server Thread T2

SP1

SP2

Package

E1 A

SP3

Process Prc3

Data1:

Pos

Data1:

Pos

Process Prc2

E1

Thread T1

Data1

E1

Thread T2

E1

Application Source Internal Mode

Conditional code

AADL Tutorial

AADL Tutorial

49

A Mode Example

system implementation Main.Example is

A: system Foo.Bar;

B: system Oof.Rab;

C_sub1, C_sub2: system;

D_sub1, D_sub2: system;

Mode1: initial mode (A, B, C_sub1, C_sub2);

Mode2: mode (A, B, D_sub1, D_sub2);

behaviors

mode Mode1 –[ A.Switch_To_D ]-> Mode2;

mode Mode2 –[ A.Switch_To_C ]-> Mode1;

end Main.Example;

AADL Tutorial

AADL Tutorial

50

Behavior Modeling

• Core Features

(cid:31)Operational modes

(cid:31) Runtime reconfiguration

(cid:31) End-to-end flows

• Language Extensions

(cid:31)Interaction behavior

State reachability

Flow traceability

Protocol verification

Model checking

• Port interaction pattern of component

• Interaction protocol of connection

(cid:31) Error models & reliability analysis

AADL Tutorial

AADL Tutorial

51

System Safety Engineering

Capture the results of

• Hazard analysis

• Component failure modes & effects analysis

Specify and analyze

• Fault trees

• Markov models

• Partition isolation/event independence

Supported by Error

Model Annex

Integration of system safety with architectural design

• Enables cross-checking between models

• Insures safety models and design architecture are

consistent

• Reduces specification and verification effort

AADL Tutorial

AADL Tutorial

52

System & Execution Platforms

Processors, buses, memory, and

devices as Virtual Machines

System System1

System LinuxNet

System Subsystem1

System LinuxBox

Process Prc1

Process Prc2

Processor PC1

Bus

Memory

Thread T3

Thread T3

Memory

Processor PC2

Threads as logical

unit of concurrency

AADL Tutorial

AADL Tutorial

53

Binding Systems to Execution Platforms

Satellite_SW.Control => Satellite_plant.linuxbox1

Satellite_SW.guidance.observe

=> Satellite_plant.linuxbox2

Satellite_sys: system

Satellite_SW: system

Satellite_plant: platform

guidance: process

control: process

Satellite: device

Satellite_bus: bus

Satellite_plant.linuxbox2

observe: thread

decide: thread

Satellite_plant.pentium

act: thread

Satellite_mem: memory

linuxbox1: platform pentium

linuxbox2: platform pentium

linuxbox3: platform PPC

AADL Tutorial

AADL Tutorial

54

Extensibility

• Core standard plus optional annexes

• Add values for predeclared standard

properties.

• Addition of properties.

• Component classifier libraries.

• Extension of component declarations.

• Refinement of subcomponent declarations.

• Modeling of source code data type

inheritance.

AADL Tutorial

AADL Tutorial

55

Extensible Components

Component type (interface)

Component implementations

Subcomponents (hierarchy)

Component instance

CT

CT1

CT2

CT11

CT12

Ports

Connections

Modes

Properties

Behavior

Component Classifier Refinement

Component type

I1

I2

I1

I2

I3

Component type extension

Component implementation

Component implementation extension

AADL Tutorial

AADL Tutorial

56

Extending an AADL Component

AADL Tutorial

AADL Tutorial

57

Extending AADL

• Component Types have multiple

implementations families.

• Component extension and refinement.

• Packages.

• Property Sets.

• Annex Subclauses.

• AADL Standard Annexes.

AADL Tutorial

AADL Tutorial

58

Component Evolution

• Partially complete component type and

implementation.

• Multiple implementations for a component

type.

• Extension & refinement

(cid:31)Component templates to be completed.

(cid:31)Variations and extensions in interface

(component type).

(cid:31)Variations and extensions in implementations.

AADL Tutorial

AADL Tutorial

59

Large-Scale Development

• Component type and implementation

declarations in packages

(cid:31)Name scope for component types.

(cid:31)Grouping into manageable units.

(cid:31)Nested package naming.

(cid:31)Qualified naming to manage name conflicts.

• Supports independent development of

subsystems.

• Supports large-scale system of system

development.

AADL Tutorial

AADL Tutorial

60

AADL Language Extensions

• Core standard plus optional annexes.

• Examples

(cid:31)Error Model

(cid:31)ARINC 653

(cid:31)Behavior

(cid:31)Constraint sublanguage

• Annex as document

(cid:31)New properties through property sets

(cid:31)Annex-specific subclauses expressed in an

annex-specific sublanguage

AADL Tutorial

AADL Tutorial

61

Summary of AADL Capabilities

• AADL abstractions separate application domain

concerns from runtime architecture concerns.

• AADL combines predictable task execution with

deterministic communication.

• AADL is effective for embedded, real-time, high-

dependability, software-intensive application systems.

• AADL supports predictable system analysis and

deployment through model-based system engineering.

• AADL component & communication semantics facilitate

the dialogue between application and software experts.

• AADL provides an extensible basis for a wide range of

embedded systems analyses.

• AADL builds on 13 years of DARPA investment +

experiments.

AADL Tutorial

Publicité

AADL Tutorial

62

Tutorial Outline

• Background & Introduction

• Introduction to AADL

• AADL in Use

• AADL Development Environment

• Benefits of AADL

AADL Tutorial

AADL Tutorial

63

What Is Involved In Using The

AADL?

• Specify software & hardware system architectures.

• Specify component interfaces and implementation

properties.

• Analyze system timing, reliability, partition isolation.

• Tool-supported software and system integration.

• Verify source code compliance & middleware

behavior.

Model and analyze early

and throughout product life cycle

AADL Tutorial

AADL Tutorial

64

AADL Analysis & Design Methodology

• Here we use the AADL as analysis & design

methodology on an existing system

• AADL employs

(cid:31) Components with precisely defined semantics.

(cid:31) Explicit interactions.

(cid:31) Decomposition.

(cid:31) Separation of concerns.

• Pattern-based architecture analysis approach

(cid:31) Uses design patterns in analysis.

(cid:31) Identifies systemic problems early.

(cid:31) Enables the right choices with confidence.

(cid:31) Provides analysis-based decisions.

AADL Tutorial

AADL Tutorial

65

Analysis & Design of an Avionics System

• Preemptive Scheduling and Data Flow

• Scheduling and Real-time Performance

• To Poll or Not to Poll

• Partitions & Communication Timing

• End-to-end Flows

• Many Uses of Modes

• System Safety Engineering

AADL Tutorial

AADL Tutorial

66

Avionics Systems

• Embedded avionics system designs are evolving to

(cid:31) Integrated systems from federated ones.

(cid:31) Predictable preemptive scheduling.

(cid:31) Extensible system architectures.

• There are distinct perspectives in the design

(cid:31) Control and domain engineers.

(cid:31) Application software engineers.

(cid:31) System software engineers.

In the remainder of this tutorial we consider

(cid:31) A representative avionics system.

(cid:31) Design within the context of the AADL.

(cid:31) The distinct perspectives involved.

(cid:31) Issues associated with the evolution of avionics systems.

AADL Tutorial

AADL Tutorial

67

Avionics System Example

• Reflects current design approaches including

(cid:31) Time and space partitioning

(cid:31) Shared memory & port communication

(cid:31) Cyclic executive & preemptive scheduling

(cid:31) Deterministic communication

(cid:31) Distributed system with legacy hardware

(cid:31) Fault tolerance and reconfiguration

(cid:31) Efficient execution and footprint

Focus on performance-critical system properties

AADL Tutorial

AADL Tutorial

68

Sample Avionics System

Hardware Configuration

Pilot

Multifunction

Display1

Pilot

Multifunction

Display2

CoPilot

Multifunction

Display1

CoPilot

Multifunction

Display2

Display

Processor

Display

Processor

Display

Processor

Display

Processor

Does not have

access to the

1553 buses

Mission

Processor

High speed network

High speed network

Mission

Processor

Redundant

Redundant

network and bus

network and bus

Mission

Processor

1553 bus

1553 bus

Auto-Pilot

GPS

Nav Radio

AADL Tutorial

AADL Tutorial

69

A Typical Context Diagram

AADL Tutorial

AADL Tutorial

70

Avionics Software Component

Layers

Display

Manager

Indirect information flow

Warning Annunciation

Manager

Page Content

Manager

Flight

Manager

Flight

Director

Situation

Awareness

Weapons

Manager

Comm.

Manager

• logical interface to 1553

• hides the fact that some

processors do not have

direct access to 1553 bus

1553 Access

AADL Tutorial

AADL Tutorial

71

Typical Software to Hardware Mapping

DM

WAM

PCM

DM

WAM

DM

WAM

High speed bus

High speed bus

DM

WAM

PCM

FM

SA

CM

WM

1553

CM

1553

FD

SA

FD

FM

CM

WM

1553 bus

1553 bus

AADL Tutorial

AADL Tutorial

72

Observations: Hidden Information

• Multiple instances as separate components.

• Both dual and quad redundancy.

• Grouping of redundant instances.

• Documented in text.

• Difficult to understand and analyze.

AADL Tutorial

AADL Tutorial

73

Avionics System Context Diagram

Pilot

Multifunction

Display1

Pilot

Multifunction

Display2

CoPilot

Multifunction

Display1

CoPilot

Multifunction

Display2

Auto-Pilot

Avionics

System

Nav Radio

Port group

Aggregate

connection

GPS

AADL Tutorial

AADL Tutorial

74

Flight Manager Context Diagram

Avionics System

Warning Annunciation

Manager

Flight

Director

Situation

Awareness

Flight

Manager

Auto-Pilot

Nav Radio

Page Content

Manager

Display

Manager

Weapons

Manager

Comm.

Manager

GPS

AADL Tutorial

AADL Tutorial

75

Perspectives on Devices

• Hardware Engineer

(cid:31) Device is part of physical system

Application

Physical Hardware

Device

Processor

Bus

• Application developer

(cid:31) Device functionality is part of the application software

• Control Engineer

Application System

Execution Platform

FM

FD

Device

(Driver)

Processor

Bus

(cid:31) Device represents the plant being controlled

Control System

FM

AP

AADL Tutorial

AADL Tutorial

Controlled Environment

Sensor

Actuator

Plant

76

Flight Manager: Principal Functionality

From other

Partitions

Periodic I/O

20Hz

20Hz

Navigation

Sensor

Processing

10Hz

Integrated

Navigation

Shared

Data

Area

20Hz

To other

Partitions