Pyrrhus Software
Enduring Solutions
The SAE
Architecture Analysis & Design
Language
(AADL)
www.aadl.info
Bruce Lewis
Army AMCOM SED
Redstone Arsenal, AL
256-876-3224
Joyce L Tokar
Pyrrhus Software
Phoenix, AZ
480-951-1019
AADL Tutorial
AADL Tutorial
1
Tutorial Objectives
• Provide an overview of the SAE AADL Standard.
•
Introduce architecture-based development concepts.
• Provide a summary of AADL capabilities.
• Demonstrate the benefits of AADL in real-time systems
design.
• Provide an overview of the AADL development
environment.
AADL Tutorial
AADL Tutorial
2
Tutorial Outline
• Background & Introduction
• Introduction to AADL
• AADL in Use
• AADL Development Environment
• Benefits of AADL
AADL Tutorial
AADL Tutorial
3
The SAE AADL Standard
• Sponsored by
(cid:31)Society of Automotive Engineers (SAE)
• Avionics Systems Division (ASD)
o Embedded Systems (AS2)
» Avionics Architecture Description Language
Subcommittee (AS2C)
» Bruce Lewis -- Chairman
• Status
(cid:31)Requirements document SAE ARD 5296
• Balloted and approved in 2000.
(cid:31)Standard document SAE AS 5506
• Balloted and approved 2004.
• Contact
(cid:31) http://www.aadl.info
email: [email protected]
AADL Tutorial
AADL Tutorial
4
SAE AS-2C ADL Subcommittee
• Key Players:
(cid:31) Bruce Lewis (AMCOM): Chair, technology user
(cid:31) Steve Vestal (Honeywell): MetaH originator, co-author
(cid:31) Peter Feiler (SEI): Secretary, main author, editor,
technology user
(cid:31) Ed Colbert (USC): AADL & UML Mapping
(cid:31) Joyce Tokar (Pyrrhus Software): Programming Language
Annex, co-editor
• Members:
(cid:31) Boeing, Rockwell, Honeywell, Lockheed Martin, Raytheon,
Smith Industries, Airbus, Axlog, Dassault, EADS , Canadair,
High Integrity Systems
(cid:31) NAVAir, Open Systems JTF, British MOD, US Army
(cid:31) European Space Agency
• Coordination with:
(cid:31) NATO, ESA, COTRE, OMG-UML
AADL Tutorial
AADL Tutorial
5
Architecture & Analysis Design Language
AADL
• Specification of
(cid:31) Real-time
(cid:31) Embedded
(cid:31) Fault-tolerant
(cid:31) Securely partitioned
(cid:31) Modal & dynamically configurable
• Software task and communication architectures
• Bound to
(cid:31) Distributed multiple processor hardware architectures
• Fields of application
(cid:31) Avionics, Aerospace, Automotive, Autonomous systems,
…
AADL Tutorial
AADL Tutorial
6
Fields of Application
• Automotives
• Avionics
• Robotics
• Fixed sampling and processing rates
• Variable sampling and processing rates
• Stochastic event and processing rates
• Known operational modes and configurations
• Large-scale system integration
AADL Tutorial
AADL Tutorial
7
MetaH - A Precursor to AADL
1991 DARPA DSSA program begins
1992 Partitioned PFP target (Tartan MAR/i960MC)
1994 Multi-processor target (VME i960MC)
1995 Slack stealing scheduler
1998 Portable Ada 95 and POSIX middleware configurations
1999 Hybrid automata verification of core middleware modules
Numerous evaluation and demonstration projects, e.g.
Missile G&C reference architecture, demos, others (AMCOM SED)
Hybrid automata formal verification (AFOSR, Honeywell)
Missile defense (Boeing)
Fighter guidance SW fault tolerance (DARPA, CMU, Lockheed-Martin)
Incremental Upgrade of Legacy Systems (AFRL, Boeing, Honeywell)
Comanche study (AMCOM, Comanche PO, Boeing, Honeywell)
Tactical Mobile Robotics (DARPA, Honeywell, Georgia Tech)
Advanced Intercept Technology CWE (BMDO, MaxTech)
Adaptive Computer Systems (DARPA, Honeywell)
Avionics System Performance Management (AFRL, Honeywell)
Ada Software Integrated Development/Verification (AFRL, Honeywell)
FMS reference architecture (Honeywell)
JSF vehicle control (Honeywell)
IFMU reengineering (Honeywell)
AADL Tutorial
AADL Tutorial
8
MetaH Case Study at AMCOM
• Missile Application reengineered
(cid:31) Missile on-board software and 6DOF environment simulation
executing on dual i80960MC, Tartan Ada, VME Boards
(cid:31) Built to Generic Missile Reference Architecture
(cid:31) Specified in MetaH, 12 to 16 concurrent processes
(cid:31) MetaH reduced total re-engineering cost 40% on first project
it was used on. Missile prime estimated savings at 66%.
• Missile Application ported to a new execution
environment
(cid:31) Multiple ports to single and dual processor implementations
(cid:31) New processors (Pentium and PowerPC), compilers, O/S
(cid:31) First time executable, flew correctly on each target
environment
(cid:31) Ports took a few weeks rather than 10 months.
AADL Tutorial
AADL Tutorial
9
8000
7000
6000
5000
4000
3000
2000
1000
M
a
n
H
o
u
r
s
AMCOM Effort Saved Using
MetaH
Total project savings 50%, re-target savings 90%
Benefit During
Platform Retarget
Benefit During
Application Rewrite
0
Review 3-DOF
Trans-
late
6-DOF
Traditional
Approach
Using
MetaH
RT-
6DOF
Trans-
form
Test
6DOF
RT-
Missile
Build
Debug
Current
MetaH
Debug
Re-target
AADL Tutorial
AADL Tutorial
10
Architecture Description Languages
Research ADLs
• MetaH
(cid:31) Real-time, modal, system family
(cid:31) Analysis & generation
(cid:31) RMA based scheduling
Basis
• Rapide, Wright, ..
(cid:31) Behavioral validation
Extension
• ADL Interchange
(cid:31) ACME, xADL
(cid:31) ADML (MCC/Open Group, TOGAF)
Influence
Industrial Strength
• HOOD/STOOD
• SDL
• UML 2.0, UML-RT
Alignment
Enhancements
Extensible
Real-time
Dependable
AADL Tutorial
AADL Tutorial
11
Typical Software Development
Process
Requirements
Analysis
Design
Implementation
Integration
manual, paper intensive, error prone, resistant to change
AADL Tutorial
AADL Tutorial
12
Model-Based System Engineering
Model-Based & Architecture-Driven
Requirements
Analysis
Explicit Architecture
Engineering Models
Use of AADL
System
Integration
Predictable System
Rapid Integration
Upgradeability
Design, Analysis
and Implementation
AADL Tutorial
AADL Tutorial
13
Model-Based System Engineering
SoS Analysis
• Schedulability
• Performance
• Reliability
• Fault Tolerance
• Dynamic Configurability
Software
Systems
Engineer
System Construction
• Executive generation
• System Integration
Model the
Architecture,
Abstract & Precise
Performance-Critical Architecture Model
Application System & Execution Platform
Application
Software
Guidance
& Control
Automatic
Target
Recognition
Domain Specific
Components & Subsystems
Sensor
& Signal
Processing
Supply
Chain
Mechanized
Ambulatory
Information
Fusion
Execution
Platform
GPS
DB
HTTPS
Publicité
. . . . . . . . . .
RTOS
Devices Memory
Bus
Processor
AADL Tutorial
AADL Tutorial
14
Tutorial Outline
• Background & Introduction
• Introduction to AADL
• AADL in Use
• AADL Development Environment
• Benefits of AADL
AADL Tutorial
AADL Tutorial
15
What is Software Architecture?
• Architecture is the fundamental organization of a
system as embodied in
(cid:31)its components,
(cid:31)their relationships to each other and the environment,
(cid:31)the principles governing its design and evolution.
• The software architecture of a program or computing
system is
(cid:31)the structure or structural arrangements of its
composite software elements,
(cid:31)the externally visible properties of those elements,
(cid:31)the relationships among them.
Architecture is the foundation of
good software system engineering
AADL Tutorial
AADL Tutorial
16
What is an
Architecture Description Language
(ADL)?
• The architecture of a system defines its high-
level structure and exposes its gross organization
as a collection of interacting components.
• An Architecture Description Language (ADL)
focuses on the high-level structure of the overall
application rather than on the implementation
details of any specific component.
• ADLs and their accompanying toolsets support
architecture-based development, formal
modeling, and analysis of architectural
specifications.
AADL Tutorial
AADL Tutorial
17
Common Foundation of ADLs
• Components represent the primary (computational)
elements and data stores of a system.
• AADL Components:
(cid:31)Software Components:
• Data, subprogram, thread, thread groups process.
(cid:31)Execution Environment Components:
• Memory, bus, device, processor
(cid:31)Composite Components:
• System
• AADL Component Interfaces:
(cid:31)Shared Data
(cid:31)Ports
• Data ports, event ports, event data ports.
(cid:31)Subprogram Parameters
AADL Tutorial
AADL Tutorial
18
Common Foundation of ADLs
• Connectors represent interactions among
components.
• Connectors in AADL:
(cid:31)Subprogram Call Sequence
(cid:31)Connections
• Port connections, access connections
(cid:31)Flows
AADL Tutorial
AADL Tutorial
19
Common Foundation of ADLs
• Systems represent configurations of
components and connectors.
• Systems in AADL:
(cid:31)Packages
(cid:31)Systems
AADL Tutorial
AADL Tutorial
20
Common Foundation of ADLs
• Properties represent semantic information
about a system and its components that goes
beyond structure.
• AADL supplies:
(cid:31)Predefined Properties
(cid:31)User-defined Property Sets
AADL Tutorial
AADL Tutorial
21
Common Foundation of ADLs
• Constraints represent claims about an
architectural design that should remain true
even as it evolves over time.
• Constraints in AADL:
(cid:31)Hybrid automata assertions
(cid:31)Property value constraints
(cid:31)Annexes
AADL Tutorial
AADL Tutorial
22
Common Foundation of ADLs
• Styles represent families of related systems.
• Styles in AADL:
(cid:31)Multiple implementations
(cid:31)Refinement
(cid:31)Packages
(cid:31)Property sets
(cid:31)Annexes
AADL Tutorial
AADL Tutorial
23
Common Foundation of ADLs
• Components
• Connectors
• Systems
• Properties
• Constraints
• Styles
AADL Tutorial
AADL Tutorial
24
Focus Of SAE AADL
• Component View
(cid:31)Model of system composition & hierarchy.
(cid:31)Well-defined component interfaces.
• Concurrency & Interaction View
(cid:31)Time ordering of data, messages, and events.
(cid:31)Dynamic operational behavior.
(cid:31)Explicit interaction paths & protocols.
• Execution view
(cid:31)Execution platform as resources.
(cid:31)Binding of application software.
(cid:31)Specification & analysis of runtime properties
• timeliness, throughput, reliability, graceful
degradation, …
AADL Tutorial
AADL Tutorial
25
The AADL in a Nutshell
EXTENSIBLE/
SCALABLE
Multi-processor/multi-
process, easily add/change
and see effects. User defined
domain specific functions..
FLEXIBLE
System spec used to
change
implementation.
Interface with any
standard or
application
GENERIC
Modular,
scalable, system
“block diagram”
with semantics
System Architecture
Performance-Critical
Layering & Composition
Application
Thread, Process,
System
Execution Platform
Execution engine
Memory, Bus
Device
Components
Specifications
Variant implementations
Ports
Connections
Domain data objects
Behaviors
OBJECT-
ORIENTED
Clearly defined
object, messaging,
properties,
decomposition
OPEN
Gov usage rights.
Industry AADL
standard.
USABLE AND AVAILABLE
Approach/formalism is
SIMPLE/UNIFORM,
PRACTICAL, and EASY TO
USE, LEARN, AND
INTERFACE WITH OTHER
APPROACHES!
REUSABLE
Very portable.
Function/non-functional
requirements.
Ideal isolation from
hardware.
REAL-TIME
User specifies timing
requirements,
analyzers available,
concurrency handled
automatically!
RELIABILITY,
SAFETY,
SECURITY
SUPPORT
User specifies
requirements;
analyzers available
HARDWARE
MODELING AND BINDINGS FULLY
SUPPORTED BY AADL(auxiliary to
the SW API)
Implementation
HARDWARE
INDEPENDENT
No implementation
specified in SW API.
AADL Tutorial
AADL Tutorial
VERIFIABLE
Strong support for predictable
real-time architectures
exhibiting high-reliability
FORMAL, RICH
SEMANTICS
Models can span high-
level system to detailed
interfaces
26
The SAE AADL Standard
• Provides a standard & precise way to describe the
architecture of embedded computer systems.
• Provides a standard way to describe components,
assemblies of components, and interfaces to
components.
• Describes how components are composed together
to form complete system architectures.
• Describes the runtime semantics and thread
scheduling protocols.
• Describes the mechanisms to exchange control and
data between components.
• Describes dynamic run-time configurations.
AADL Tutorial
AADL Tutorial
27
AADL Concepts Overview
• Hierarchically composed & interconnected
components: system.
• Application system components: thread, thread group,
process, data, and subprogram.
• Execution platform components: processor, memory,
•
bus, and device.
Interaction in terms of directional flow via ports,
call/return, and data sharing.
• Flow of signals/state (data), control (event & time
triggered), and messages (event data) across multiple
components.
• Dynamic behavior in terms of statically known alternate
task & communication configurations (modes).
• Core AADL and Annex extensions.
AADL Tutorial
AADL Tutorial
28
Graphical & Textual Notation
system Data_Acquisition
features
speed_data: in data port metric_speed;
GPS_data: in data port position_carthesian;
user_input_data: in data port user_input;
s_control_data: out data port state_control;
end Data_Acquisition;
data type
of port
speed
_data
GPS
_data
user
input
data
Data_Acquisition
s_control_data
data port
AADL Tutorial
Publicité
AADL Tutorial
29
AADL Components
• Composite Components
(cid:31) System
• Software Components
• Execution Platform
(cid:31) Data
(cid:31) Subprogram
(cid:31) Thread
(cid:31) Thread Group
(cid:31) Process
Components
(cid:31) Memory
(cid:31) Device
(cid:31) Bus
(cid:31) Processor
AADL Tutorial
AADL Tutorial
30
AADL Components
• Component Type -- specifies the interface to
the component.
• Component Implementation -- zero or more
specifications of the component’s internal
representation.
AADL Tutorial
AADL Tutorial
31
System Components
• Specifies a well-formed interface.
• All external interaction points defined as features.
• Multiple implementations per component type.
• Properties as specified component characteristics.
• Components organized in nested hierarchy.
• Component interaction declarations must follow
system hierarchy.
AADL Tutorial
AADL Tutorial
32
System
System
• Hierarchical composition.
• Execution platform and application software
components.
• Data and bus sharable across system
hierarchy.
Features: port, subprogram
Provides: data access, bus access
Requires: bus access, data access
Subcomponents:
process, system,
memory, processor, bus,
device, and data
Connections: yes
Modes: yes
AADL Tutorial
AADL Tutorial
33
Device
device
• Physical component interfacing with environment.
Interacts with application components via port
•
connections.
• Connects physically to processors via bus.
• May have associated software executes on
connected processor.
• Examples
(cid:31) sensors and actuators
(cid:31) standalone systems such as a GPS
Features: port, subprogram
Requires: bus access
Connections: no
Modes: yes
AADL Tutorial
AADL Tutorial
34
AADL Interfaces & Connections
• Ports
(cid:31) Data ports
(cid:31) Event Data ports
(cid:31) Event ports
• Connections
(cid:31) Immediate
(cid:31) Delayed
AADL Tutorial
AADL Tutorial
35
AADL Interfaces & Connections
• Port Groups
• Connections
AADL Tutorial
AADL Tutorial
36
AADL Interfaces & Connections
• Subprograms
• Subprogram calls
(cid:31) Local
(cid:31) Server
(cid:31) Local
(cid:31) Remote
AADL Tutorial
AADL Tutorial
37
Shared Data & Bus Access
• Component requires
• Component provides
access
access
AADL Tutorial
AADL Tutorial
38
AADL Properties
• Predefined property
• User defined property
sets
sets
AADL Tutorial
AADL Tutorial
39
Application Component Hierarchy
System App
System S1
System S2
Process P2
Thread T5
Thread T6
Process P1
Thread T1
Thread T2
Process P3
Thread T3
Thread T4
Two ways of graphically
visualizing component hierarchy
AADL Tutorial
AADL Tutorial
40
3 Ways to Interact: AADL
Component Interaction
1553
Flight Mgr
Unidirectional
data & event flow
Synchronous call/return
(not shown)
data
Weapons
Mgr
Warnings
Annunciations
MFD Pilot
MFD Copilot
Managed shared data access:
only two threads have access
AADL Tutorial
AADL Tutorial
41
Application System & Execution
Platform
1553
Application system binding
to execution platform
Flight Mgr
Weapons
Mgr
data
Warnings
Annunciations
MFD Pilot
MFD Copilot
High speed network
Mission
Processor
Display
Processor
Display
Processor
1553 bus
Pilot Display
CoPilot Display
AADL Tutorial
AADL Tutorial
42
AADL and Scheduling
• AADL provides precise dispatch & communication
semantics via hybrid automata.
• AADL task & communication abstraction does not
prescribe scheduling protocols
(cid:31) Cyclic executive can be supported.
• Specific scheduling protocols may require additional
properties.
• Predefined properties support rate-monotonic fixed
priority preemptive scheduling.
This scheduling protocol is analyzable,
requires small runtime footprint,
provides flexible runtime architecture.
AADL Tutorial
AADL Tutorial
43
AADL Threads
• Threads
(cid:31)Periodic -- execute at given time intervals.
(cid:31)Aperiodic -- are triggered by an event or
remote procedure call.
(cid:31)Sporadic -- paced to limit execution rate.
(cid:31)Background -- run when there is available
processor time.
AADL Tutorial
AADL Tutorial
44
Active
Member of
current mode
Thread States
Uninitialized
Thread
Initialize
InitializeComplete:
Inactive
Not member of
current mode
InactiveInInitMode:
ActiveInInitMode:
Initialized
Thread
Activate
ActivateComplete:
ActiveIn
NewMode:
Inactive
DeactivateComplete:
Active
Dispatch:
Suspended
Complete:
Compute
Repaired:
Recovered:
Fault:
Recover
Deactivate
InactiveInNewMode:
Terminate:
Finalize
Thread State
Thread State with
Source Code
Execution
FinalizeComplete:
Terminated
Thread
Application Source Entrypoints
Application as Plug-in
AADL Tutorial
AADL Tutorial
45
Task & Interaction Architecture
Typed and
constrained
data streams
System System1
Immediate and delayed
communication
System Subsystem1
Thread Dispatch
Protocols
Periodic
Aperiodic
Sporadic
Background
Thread T3
Data1:
Pos
Process Prc1
Shared data
Data1:
Pos
Data1:
Pos
Process Prc2
E1
Thread T1
RSP1
SP1
SP2
Server Thread T2
Package
SP3
Thread T1
Data1
E1
Thread T2
E1
Directional
Data, event, message ports
Publicité
Queued and unqueued xfer
Call/Return
Local subprogram
Client/server subprogram
Shared Access
Persistent, shareable
data
Access coordination
AADL Tutorial
AADL Tutorial
46
Thread
Thread
•
Is a schedulable unit executing on a processor
under a scheduling protocol.
Is dispatched based on time or arrival of events.
•
• Executes within the protected address space of a
•
process.
Interacts with other threads through port
connections, remote subprogram calls, and shared
data access.
• Can be logically organized into thread groups.
Remote service calls
Features:
port, server subprogram
Requires: data access
Provides: data access
Subcomponents: Data
Connections: no
Modes: yes
AADL Tutorial
AADL Tutorial
47
Faults and Modes
• AADL provides a fault handling framework with
precisely defined actions.
• AADL supports runtime changes to task &
communication configurations.
• AADL defines timing semantics for task coordination
on mode switching.
• AADL supports specification of mode transition
actions.
• System initialization & termination are explicitly
modeled.
AADL Tutorial
AADL Tutorial
48
Hierarchical Modes
System System1
Mode as Alternative Configuration
E1 A
System Subsystem1
Initial Mode A: Prc1, Prc2;
Mode B: Prc1, Prc3;
Initial Mode A: T1, T2, T3;
Mode B: T1, T2;
Process Prc1
E1 A
Shared data
Thread T3
Data1:
Pos
Thread T1
RSP1
Server Thread T2
SP1
SP2
Package
E1 A
SP3
Process Prc3
Data1:
Pos
Data1:
Pos
Process Prc2
E1
Thread T1
Data1
E1
Thread T2
E1
Application Source Internal Mode
Conditional code
AADL Tutorial
AADL Tutorial
49
A Mode Example
system implementation Main.Example is
A: system Foo.Bar;
B: system Oof.Rab;
C_sub1, C_sub2: system;
D_sub1, D_sub2: system;
Mode1: initial mode (A, B, C_sub1, C_sub2);
Mode2: mode (A, B, D_sub1, D_sub2);
behaviors
mode Mode1 –[ A.Switch_To_D ]-> Mode2;
mode Mode2 –[ A.Switch_To_C ]-> Mode1;
end Main.Example;
AADL Tutorial
AADL Tutorial
50
Behavior Modeling
• Core Features
(cid:31)Operational modes
(cid:31) Runtime reconfiguration
(cid:31) End-to-end flows
• Language Extensions
(cid:31)Interaction behavior
State reachability
Flow traceability
Protocol verification
Model checking
• Port interaction pattern of component
• Interaction protocol of connection
(cid:31) Error models & reliability analysis
AADL Tutorial
AADL Tutorial
51
System Safety Engineering
Capture the results of
• Hazard analysis
• Component failure modes & effects analysis
Specify and analyze
• Fault trees
• Markov models
• Partition isolation/event independence
Supported by Error
Model Annex
Integration of system safety with architectural design
• Enables cross-checking between models
• Insures safety models and design architecture are
consistent
• Reduces specification and verification effort
AADL Tutorial
AADL Tutorial
52
System & Execution Platforms
Processors, buses, memory, and
devices as Virtual Machines
System System1
System LinuxNet
System Subsystem1
System LinuxBox
Process Prc1
Process Prc2
Processor PC1
Bus
Memory
Thread T3
Thread T3
Memory
Processor PC2
Threads as logical
unit of concurrency
AADL Tutorial
AADL Tutorial
53
Binding Systems to Execution Platforms
Satellite_SW.Control => Satellite_plant.linuxbox1
Satellite_SW.guidance.observe
=> Satellite_plant.linuxbox2
Satellite_sys: system
Satellite_SW: system
Satellite_plant: platform
guidance: process
control: process
Satellite: device
Satellite_bus: bus
Satellite_plant.linuxbox2
observe: thread
decide: thread
Satellite_plant.pentium
act: thread
Satellite_mem: memory
linuxbox1: platform pentium
linuxbox2: platform pentium
linuxbox3: platform PPC
AADL Tutorial
AADL Tutorial
54
Extensibility
• Core standard plus optional annexes
• Add values for predeclared standard
properties.
• Addition of properties.
• Component classifier libraries.
• Extension of component declarations.
• Refinement of subcomponent declarations.
• Modeling of source code data type
inheritance.
AADL Tutorial
AADL Tutorial
55
Extensible Components
Component type (interface)
Component implementations
Subcomponents (hierarchy)
Component instance
CT
CT1
CT2
CT11
CT12
Ports
Connections
Modes
Properties
Behavior
Component Classifier Refinement
Component type
I1
I2
I1
I2
I3
Component type extension
Component implementation
Component implementation extension
AADL Tutorial
AADL Tutorial
56
Extending an AADL Component
AADL Tutorial
AADL Tutorial
57
Extending AADL
• Component Types have multiple
implementations families.
• Component extension and refinement.
• Packages.
• Property Sets.
• Annex Subclauses.
• AADL Standard Annexes.
AADL Tutorial
AADL Tutorial
58
Component Evolution
• Partially complete component type and
implementation.
• Multiple implementations for a component
type.
• Extension & refinement
(cid:31)Component templates to be completed.
(cid:31)Variations and extensions in interface
(component type).
(cid:31)Variations and extensions in implementations.
AADL Tutorial
AADL Tutorial
59
Large-Scale Development
• Component type and implementation
declarations in packages
(cid:31)Name scope for component types.
(cid:31)Grouping into manageable units.
(cid:31)Nested package naming.
(cid:31)Qualified naming to manage name conflicts.
• Supports independent development of
subsystems.
• Supports large-scale system of system
development.
AADL Tutorial
AADL Tutorial
60
AADL Language Extensions
• Core standard plus optional annexes.
• Examples
(cid:31)Error Model
(cid:31)ARINC 653
(cid:31)Behavior
(cid:31)Constraint sublanguage
• Annex as document
(cid:31)New properties through property sets
(cid:31)Annex-specific subclauses expressed in an
annex-specific sublanguage
AADL Tutorial
AADL Tutorial
61
Summary of AADL Capabilities
• AADL abstractions separate application domain
concerns from runtime architecture concerns.
• AADL combines predictable task execution with
deterministic communication.
• AADL is effective for embedded, real-time, high-
dependability, software-intensive application systems.
• AADL supports predictable system analysis and
deployment through model-based system engineering.
• AADL component & communication semantics facilitate
the dialogue between application and software experts.
• AADL provides an extensible basis for a wide range of
embedded systems analyses.
• AADL builds on 13 years of DARPA investment +
experiments.
AADL Tutorial
Publicité
AADL Tutorial
62
Tutorial Outline
• Background & Introduction
• Introduction to AADL
• AADL in Use
• AADL Development Environment
• Benefits of AADL
AADL Tutorial
AADL Tutorial
63
What Is Involved In Using The
AADL?
• Specify software & hardware system architectures.
• Specify component interfaces and implementation
properties.
• Analyze system timing, reliability, partition isolation.
• Tool-supported software and system integration.
• Verify source code compliance & middleware
behavior.
Model and analyze early
and throughout product life cycle
AADL Tutorial
AADL Tutorial
64
AADL Analysis & Design Methodology
• Here we use the AADL as analysis & design
methodology on an existing system
• AADL employs
(cid:31) Components with precisely defined semantics.
(cid:31) Explicit interactions.
(cid:31) Decomposition.
(cid:31) Separation of concerns.
• Pattern-based architecture analysis approach
(cid:31) Uses design patterns in analysis.
(cid:31) Identifies systemic problems early.
(cid:31) Enables the right choices with confidence.
(cid:31) Provides analysis-based decisions.
AADL Tutorial
AADL Tutorial
65
Analysis & Design of an Avionics System
• Preemptive Scheduling and Data Flow
• Scheduling and Real-time Performance
• To Poll or Not to Poll
• Partitions & Communication Timing
• End-to-end Flows
• Many Uses of Modes
• System Safety Engineering
AADL Tutorial
AADL Tutorial
66
Avionics Systems
• Embedded avionics system designs are evolving to
(cid:31) Integrated systems from federated ones.
(cid:31) Predictable preemptive scheduling.
(cid:31) Extensible system architectures.
• There are distinct perspectives in the design
•
(cid:31) Control and domain engineers.
(cid:31) Application software engineers.
(cid:31) System software engineers.
In the remainder of this tutorial we consider
(cid:31) A representative avionics system.
(cid:31) Design within the context of the AADL.
(cid:31) The distinct perspectives involved.
(cid:31) Issues associated with the evolution of avionics systems.
AADL Tutorial
AADL Tutorial
67
Avionics System Example
• Reflects current design approaches including
(cid:31) Time and space partitioning
(cid:31) Shared memory & port communication
(cid:31) Cyclic executive & preemptive scheduling
(cid:31) Deterministic communication
(cid:31) Distributed system with legacy hardware
(cid:31) Fault tolerance and reconfiguration
(cid:31) Efficient execution and footprint
Focus on performance-critical system properties
AADL Tutorial
AADL Tutorial
68
Sample Avionics System
Hardware Configuration
Pilot
Multifunction
Display1
Pilot
Multifunction
Display2
CoPilot
Multifunction
Display1
CoPilot
Multifunction
Display2
Display
Processor
Display
Processor
Display
Processor
Display
Processor
Does not have
access to the
1553 buses
Mission
Processor
High speed network
High speed network
Mission
Processor
Redundant
Redundant
network and bus
network and bus
Mission
Processor
1553 bus
1553 bus
Auto-Pilot
GPS
Nav Radio
AADL Tutorial
AADL Tutorial
69
A Typical Context Diagram
AADL Tutorial
AADL Tutorial
70
Avionics Software Component
Layers
Display
Manager
Indirect information flow
Warning Annunciation
Manager
Page Content
Manager
Flight
Manager
Flight
Director
Situation
Awareness
Weapons
Manager
Comm.
Manager
• logical interface to 1553
• hides the fact that some
processors do not have
direct access to 1553 bus
1553 Access
AADL Tutorial
AADL Tutorial
71
Typical Software to Hardware Mapping
DM
WAM
PCM
DM
WAM
DM
WAM
High speed bus
High speed bus
DM
WAM
PCM
FM
SA
CM
WM
1553
CM
1553
FD
SA
FD
FM
CM
WM
1553 bus
1553 bus
AADL Tutorial
AADL Tutorial
72
Observations: Hidden Information
• Multiple instances as separate components.
• Both dual and quad redundancy.
• Grouping of redundant instances.
• Documented in text.
• Difficult to understand and analyze.
AADL Tutorial
AADL Tutorial
73
Avionics System Context Diagram
Pilot
Multifunction
Display1
Pilot
Multifunction
Display2
CoPilot
Multifunction
Display1
CoPilot
Multifunction
Display2
Auto-Pilot
Avionics
System
Nav Radio
Port group
Aggregate
connection
GPS
AADL Tutorial
AADL Tutorial
74
Flight Manager Context Diagram
Avionics System
Warning Annunciation
Manager
Flight
Director
Situation
Awareness
Flight
Manager
Auto-Pilot
Nav Radio
Page Content
Manager
Display
Manager
Weapons
Manager
Comm.
Manager
GPS
AADL Tutorial
AADL Tutorial
75
Perspectives on Devices
• Hardware Engineer
(cid:31) Device is part of physical system
Application
Physical Hardware
Device
Processor
Bus
• Application developer
(cid:31) Device functionality is part of the application software
• Control Engineer
Application System
Execution Platform
FM
FD
Device
(Driver)
Processor
Bus
(cid:31) Device represents the plant being controlled
Control System
FM
AP
AADL Tutorial
AADL Tutorial
Controlled Environment
Sensor
Actuator
Plant
76
Flight Manager: Principal Functionality
From other
Partitions
Periodic I/O
20Hz
20Hz
Navigation
Sensor
Processing
10Hz
Integrated
Navigation
Shared
Data
Area
20Hz
To other
Partitions