Manuel Barranco

dblp:35/1250 · also Manuel Alejandro Barranco González · DBLP profile ↗
← Back
39ranked-venue papers
10as first author
5since 2021 · last 2024
0000-0002-3937-0821ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 35 · 9 first-author · 5 since 2021Applied, interdisciplinary, general and emerging computing · 6 · 1 first-author
YearPublicationVenuePosition
2024 Towards a Node Active Replication Schema for Highly Reliable Distributed Control Systems Based on TSN
abstract
Given their nature, many control applications that arise from the integration of Operation Technologies (OT) and Information Technologies (IT) are built on top of highly reliable real-time (RT) Distributed Control Systems (DCSs). Since a DCS is made up of several computing nodes that exchange information through a communication subsystem, to achieve high reliability it is necessary that both this subsystem and the service from the nodes are very reliable. To provide RT highly reliable communications while benefiting from Ethernet's advantages, Industry and Academia are pushing the Time-Sensitive Networking Ethernet standards (TSN). On the other hand, one of the most used strategies to ensure a highly reliable service from the nodes is to use fault tolerance in the form of active replication. Our general goal is to develop a complete fault-tolerant architecture (addressing faults both in the communication subsystem and in the nodes) for highly reliable real-time DCSs based on TSN. In this paper we show our ongoing work towards an active replication schema for the nodes of this architecture.
Joan Evangelisti, Manuel Barranco, Julián Proenza, Alberto Ballesteros, Mateu Jover
ETFA2
2024 Mapping IEC 61850 GOOSE Messages into Time-Sensitive Networking
abstract
Modern electrical Substation Automation Systems (SAS) are designed following the guidelines defined in the IEC 61850 standard. This standard specifies the necessary information models and communication services for SAS in such a way that they are independent of the implementation. This allows system designers to choose the specific communication technology that best fits their needs. Time-Sensitive Networking (TSN) is arising as one of the most appealing technologies for this purpose. However, it is necessary to map the communication services to TSN, ensuring that the real-time and fault-tolerance requirements of the messages are met. In particular, efficiently mapping the messages of the Generic Object Oriented Substation Events (GOOSE) service is challenging. This is because it exhibits a transmission pattern that does not align with the types of traffic defined in TSN. In this paper we analyze this transmission pattern, identify and characterize its subpatterns, propose the most suitable mapping for each of them and discuss the efficiency gain with respect the typical approaches used to do this mapping.
Mateu Jover, Alberto Ballesteros, Manuel Barranco, Julián Proenza
ETFA3
2024 Characterizing the Tradeoff between Fault Tolerance and Cost of Redundant TSN Networks
abstract
New emerging Distributed Control Systems (DCSs), like Substation Automation Systems (SASs) of Smart Power Grids, raise new requirements on their underlying control networks. To meet these new requirements, both Industry and Academia are promoting the Time-Sensitive Networking (TSN) Ethernet standards. In particular, TSN includes mechanisms to exchange information simultaneously through several paths of practically any spatially redundant network topology. This topological flexibility can offer a better balance between fault tol-erance (FT) and redundancy cost (extra number of components) than classical Industrial Ethernets. However, the mentioned TSN mechanisms may also increase the cost in terms of extra latency and jitter, which could jeopardize real-time communications. In this paper we show our ongoing work to experimentally assess this extra latency and jitter and, thus, characterize the benefits of TSN in terms of balance between FT and cost.
Mateu Jover, Manuel Barranco, Josep Naranjo, Julián Proenza, Alberto Ballesteros
ETFA2
2023 Opportunities and Specific Plans for Migrating from PRP to TSN in Substation Automation Systems
abstract
Electrical substations are vital for the power grid, and Substation Automation Systems (SASs) have been employed to enhance substation functionality and safety. As the energy landscape evolves, substations face new challenges such as accommodating an increasing number of prosumers. Thus, SASs require a reliable substation communication network (SCN) capable of supporting real-time control and diverse applications. While Ethernet-based SCN technologies have emerged, they often fall short in meeting all requirements, including TCP/IP support, cost-effective fault tolerance, and managing traffic with different real-time demands. Time-Sensitive Networking (TSN) standards have shown promise in addressing these limitations by providing novel mechanisms. In this paper we compare TSN with the Parallel Redundancy Protocol (PRP) demonstrating that TSN offers better functionality and efficiency. In the direction of designing a comprehensive TSN-based architecture for SASs’ Distributed Control Systems (DCSs) we start here by proposing a roadmap for the fault tolerance aspects.
Mateu Jover, Manuel Barranco, Julián Proenza
ETFA2
2022 Migrating Legacy Ethernet-Based Traffic with Spatial Redundancy to TSN networks
abstract
Distributed Control Systems (DCSs) for emerging industrial control applications impose new communication requirements that cannot be satisfied by current Industrial Ethernet protocols. As a result, industry is pushing the Time-Sensitive Networking (TSN) standards as the de-facto Ethernet-based linklayer to fulfill these requirements. Adequate roadmaps are needed to support a smooth transition from Industrial-Ethernet-based legacy systems to TSN-based ones. In this context some works propose mechanisms to migrate, i.e. map, route and schedule, legacy traffic to TSN. However none of them considers traffic including streams with spatial redundancy requirements and, thus, they cannot be used to migrate legacy highly-reliable DCSs. The present work extends a previous toolchain to migrate, for the first time, legacy critical traffic that includes spatially redundant streams. Particularly, since redundancy is costly, this work proposes and compares two routing methods that consider one redundant stream per traffic.
Mateu Jover, Manuel Barranco, Ines Alvarez, Julián Proenza
ETFA2
2019 Simulation of the Proactive Transmission of Replicated Frames Mechanism over TSN
abstract
The Time-Sensitive Networking (TSN) Task Group (TG) is providing Ethernet with timing guarantees, reconfiguration services and fault tolerance mechanisms. Some of TSN's targeted applications are real-time critical applications, which must provide a correct service continuously. To support these applications the TSN TG standardised a spatial redundancy mechanism. Even though spatial redundancy can tolerate permanent and temporary faults, it is not cost-effective. Instead, temporary faults can be tolerated using time redundancy. We proposed the Proactive Transmission of Replicated Frames (PTRF) mechanism to tolerate temporary faults in the links. In this work we present a new PTRF approach, a PTRF simulation model and a comparison of the approaches using exhaustive fault injection.
Ines Alvarez, Drago Cavka, Julián Proenza, Manuel Barranco
ETFA4
2019 Temporal Replication of Messages for Adaptive Systems using a Holistic Approach
abstract
Critical Adaptive Distributed Embedded Systems (ADES) must meet high real-time and dependability requirements, while autonomously rearranging themselves to operate in dynamic operational contexts. The DFT4FTT project proposes a self-reconfigurable complete infrastructure, whose different architectural levels provide a set of real-time (RT), fault-tolerance (FT) and flexibility mechanisms that collaborate to adequately support critical ADESs. To efficiently tolerate transient faults in the network of an ADES, this paper describes our ongoing work on providing a dynamic temporal replication of messages that takes into account all the DFT4FTT fault-tolerance mechanisms from a holistic point of view.
Alberto Ballesteros, Manuel Barranco, Sergi Arguimbau, Marc Costa, Julián Proenza
ETFA2
2019 Formal Verification of the FTTRS Mechanisms for the Consistent Update of the Traffic Schedule
abstract
Critical Adaptive Distributed Embedded Systems (ADESs) are nowadays the focus of many researchers. ADESs are envisioned to dynamically modify their behavior to support changes of their real-time and dependability requirements at runtime as the conditions of the environment in which they operate vary. To provide ADESs with an adequate communication infrastructure, our research group proposed the Flexible-Time-Triggered Replicated Star (FTTRS). FTTRS provides highly reliable communication services on top of Ethernet, while keeping the adaptivity benefits that the Flexible-Time-Triggered (FTT) communication paradigm offers from a real-time perspective. This paper formally verifies, by means of model checking, the correctness of the mechanisms FTTRS includes to enforce consistent changes of the communication scheduling at runtime.
Daniel Bujosa, Sergi Arguimbau, Patricia Arguimbau, Julián Proenza, Manuel Barranco
ETFA5
2019 Fault Tolerance in Highly Reliable Ethernet-Based Industrial Systems
abstract
Many industrial systems have specific requirements derived from the applications they execute. Specifically, the interaction of a distributed embedded control system (DECS) with the real-world imposes strict real-time (RT) and reliability requirements. For a system to be RT, it has to produce a proper result in a bounded time. On top of that, for a system to be reliable, it has to operate continuously during its mission time, and in cases in which very high reliability is needed, fault tolerance (FT) techniques are used. Moreover, these systems are often deployed in dynamic environments where the operational conditions may change in an unpredictable manner. Therefore, there is an increasing interest in creating DECSs that are capable of modifying their behavior autonomously and dynamically in response to unexpectedly changing requirements or conditions. In recent years, there is a growing trend toward using Ethernet as the network technology for DECSs. Unfortunately, the original specification of this technology lacks appropriate services to fulfill the most demanding requirements of industrial systems. In this regard, many Ethernet-based protocols and standards have been proposed along the past years to deal with these limitations. In this paper, we survey solutions that have been proposed to achieve FT in Ethernet-based DECSs, considering faults both in their nodes and communication subsystem. In addition, we discuss adaptive FT techniques that can be used to increase the flexibility of adaptive DECS. Finally, we identify future trends and open challenges to build highly reliable DECS in the future.
Ines Alvarez, Alberto Ballesteros, Manuel Barranco, David Gessner, Sinisa Derasevic, Julián Proenza
Proc. IEEE3
2019 A Fault-Tolerant Ethernet for Hard Real-Time Adaptive Systems
abstract
Distributed embedded systems (DESs) that perform critical tasks in unpredictable environments must be reliable, hard real-time, and adaptive. Since a DES comprises nodes that rely on a network, the network must provide adequate support: it must be reliable, convey messages on time, and meet new real-time requirements as the nodes adapt. Ethernet is ill-suited for such hard real-time adaptive systems, but it can be made suitable. The flexible time-triggered (FTT) paradigm already supports hard real-time message exchanges and the necessary flexibility to meet evolving hard real-time requirements, but its Ethernet implementations had reliability limitations. To address these, we designed FTT replicated star for Ethernet (FTTRS), a communication subsystem that tolerates permanent and transient faults, even if they occur simultaneously, while keeping the paradigm's key features: support for both the timely exchange of periodic and sporadic real-time messages, and support for updating the real-time parameters of these messages at runtime. In this paper, we present FTTRS, the first Ethernet-based communication subsystem specifically designed for highly reliable hard real-time adaptive DESs.
David Gessner, Julián Proenza, Manuel Barranco, Alberto Ballesteros
IEEE Trans. Ind. Informatics3
2018 Towards a Fault-Tolerant Architecture Based on Time Sensitive Networking
abstract
The Time Sensitive Networking (TSN) Task Group has been working on describing a set of standards that will provide enhanced capabilities to standard Ethernet. Specifically, they work to provide Ethernet with real-time, reliability and reconfiguration capacities. Nevertheless, this set of standards (commonly referred to as TSN) does not cover some reliability aspects that are relevant for the correct operation of critical distributed control systems. Thus, in this work we present a first proposal of a highly reliable architecture and a set of mechanisms based on TSN to support the real-time and reliability requirements of these critical systems.
Ines Alvarez, Manuel Barranco, Julián Proenza
ETFA2
2017 Towards a time redundancy mechanism for critical frames in time-sensitive networking
abstract
Time-Sensitive Networking (TSN) is a set of technical standards that is being developed to provide Ethernet with hard real-time, reliability and flexibility services. In the last years, there has been a growing interest in increasing the connectivity of all kind of devices. This trend has reached industrial environments, where the demanding timing and reliability constraints imposed the use of specialised networks with specific features to support these requirements. Moreover, the industry has shown interest in using Ethernet as the network technology in industrial environments, due to its low cost, high bandwidth and extensive use. The ability of TSN to support both, data-oriented and traditional control traffic over the same network makes it an appealing technology to implement the next generation of industrial networks with high connectivity. Nevertheless, TSN does not cover some reliability aspects important for its deployment in critical systems. In this work we propose the implementation of time redundancy of frames in order to tolerate temporary faults in the channel and, therefore, increase the reliability of the network.
Ines Alvarez, Julián Proenza, Manuel Barranco, Mladen Knezic
ETFA3
2016 First implementation and test of reintegration mechanisms for node replicas in the FT4FTT Architecture
abstract
Distributed Embedded Control Systems (DECSs) used for critical applications must usually abide by strict real-time and dependability requirements. Correspondingly, the FT4FTT project proposes a complete fault-tolerant (FT) architecture for RT DECSs. The Flexible Time-Triggered Ethernet (FTT-Ethernet) communication protocol fulfills the RT requirements, while the FT mechanisms added on top of it, which are based on channel duplication and active replication of nodes, provide the FT behaviour. Temporary faults affecting the channel or the nodes, which are the most probable type of faults in DESs, can manifest in such a way that a node replica loses its coordination with the others and, thereby, it also loses its communication and/or computation capability from then on, leading to attrition of the redundancy initially provided by the active replication of nodes. This paper describes the implementation and test of specific mechanisms that are devised to determine which replicas are temporarily faulty and to promptly reintegrate them.
Alberto Ballesteros, Sinisa Derasevic, Manuel Barranco, Julián Proenza
ETFA3
2016 Improving maintenance of FT4FTT: Extending it to monitor and log its available redundancy via internet
abstract
The FT4FTT project aims at proposing a complete Fault-Tolerant (FT) architecture for Real-Time (RT) critical adaptative Distributed Embedded Control Systems (DECSs) based on Ethernet. FT4FTT tolerates permanent faults in the channel and nodes by using a duplicated Flexible Time-Triggered (FTT) Switched Ethernet star and active replication of the nodes. It also includes mechanisms for node replicas to diagnose and reintegrate after temporary faults affecting the channel or their internal circuitry. However, FT4FTT has no mechanism to deal with channel and node redundancy attrition provoked by permanent faults. This paper presents our ongoing work to extend FT4FTT to both monitor/log its available redundancy, and to remotely access this information via Internet. This will allow to carry out proper maintenance actions, for instance, to timely restore the adequate redundancy level, forecast repairs, and assess the flexibility of the FT mechanisms of adaptative systems.
Manuel Barranco, Adel Zendouh, Alberto Ballesteros, Julián Proenza
ETFA1
2016 First implementation and test of a node replication scheme on top of the flexible time-triggered replicated star for ethernet
abstract
Distributed embedded systems typically have real-time and dependability requirements. Moreover, they must also be flexible to changing conditions when they are deployed in dynamic environments. The FT4FTT project aims at providing a switched Ethernet architecture that can support distributed control applications that are predictable, highly-reliable and adaptive. FT4FTT relies on the Flexible Time-Triggered Replicated Star for Ethernet (FTTRS) to tolerate channel faults. Moreover, nodes' hardware faults are tolerated by means of active node replication with majority voting. In order to coordinately trigger the execution of the tasks in the replicas, we designed the CD4NR mechanism, in which the network assists in deciding what to execute and when. This paper presents the first implementation of the CD4NR mechanism on a real prototype of FTTRS and the first testing of the complete system. For this we developed an experimental setup, based on the hardware-in-the-loop technique, running a real-time control application.
Alberto Ballesteros, Sinisa Derasevic, David Gessner, Francisca Font, Ines Alvarez, Manuel Barranco, Julián Proenza
WFCS6
2016 Designing fault-diagnosis and reintegration to prevent node redundancy attrition in highly reliable control systems based on FTT-Ethernet
abstract
Distributed Embedded Control Systems (DECSs) used for Real-Time (RT) critical applications must satisfy stringent time requirements and attain high reliability. FTT-Ethernet provides nodes of DECSs with real-time communication capabilities, but does not include Fault Tolerance (FT) mechanisms. The FT4FTT project aims at proposing a complete FT architecture for RT critical DECSs. It uses a duplicated switched FTT-Ethernet star and active node replication with consistent distributed majority voting to respectively tolerate channel and node faults. However, FT4FTT, in its current state, still lacks mechanisms to prevent node redundancy attrition due to temporary faults affecting the nodes and channel, which are the most likely types of faults in DESs. This paper presents our ongoing work to complete the FT4FTT architecture with appropriate fault-diagnosis and reintegration mechanisms that overcome this limitation.
Sinisa Derasevic, Manuel Barranco, Julián Proenza
WFCS2
2015 An OMNET++ model to asses node fault-tolerance mechanisms for FTT-Ethernet DESs
abstract
Distributed embedded systems (DESs) that operate in dynamic environments require emerging flexibility and adaptivity communication requirements. When those DESs are deployed for critical applications, they must also employ appropriate fault-tolerance (FT) mechanisms to attain a high level of reliability. The FTT-Ethernet communication protocol supports the flexibility needed in dynamic environments, but does not provide adequate fault tolerance. In order to overcome this limitation the ongoing FT4FTT project proposes a communication architecture that includes fault-tolerance capabilities at different levels of DESs relying on FTT-Ethernet. In particular, it provides communication and execution mechanisms to tolerate node failures by means of active node replication with majority voting. This paper builds upon a previous OMNET++ model of an FTT-Ethernet-based DES in order to add, simulate and assess those mechanisms. Specifically, it models the communication mechanisms envisaged to enforce replica determinism in the voting procedure, as well as to trigger and coordinate the tasks executed in the replicas.
Sinisa Derasevic, Manuel Barranco, Julián Proenza
ETFA2
2015 First experimental evaluation of the consistent replicated voting in the hard real-time ethernet switching architecture
abstract
Distributed Embedded Systems (DESs) typically have dependability and real-time requirements. Moreover, when they are deployed in dynamic environments, they must be flexible enough to adapt to changes in the operation requirements. The Fault Tolerance for Flexible Time-Triggered Ethernet (FT4FTT) project aims at providing a Switched-Ethernet architecture, based on the Flexible Time-Triggered communication paradigm (FTT), that is flexible and highly reliable. In particular, FT4FTT provides node fault-tolerance by means of active replication with majority voting. In this sense, FT4FTT includes the Consistent Replicated Voting (CRV) protocol to enforce replica determinism, even in presence of faults, while maximizing the reliability that can be achieved thanks to the node redundancy and the communication subsystem itself. This papers presents a first implementation of this protocol in a real prototype, and shows the on-going experimental evaluation been carried out to asses its correctness.
Sinisa Derasevic, Maties Melia, Alberto Ballesteros, Manuel Barranco, Julián Proenza
ETFA4
2014 A model for quantifying the reliability of highly-reliable distributed systems based on fieldbus replicated buses
abstract
Despite the efforts devoted to increase the dependability of highly-reliable distributed fieldbus systems by means of simplex stars and replicated stars/buses, literature lacks of appropriate analyses that quantify the system reliability these topologies yield. In previous work, we proposed models to adequately quantify the system reliability benefits of simplex buses and simplex/replicated stars. However, a model for replicated buses is an open issue that needs to be addressed, as they normally include less components than stars and, thus, can be more reliable and cost-effective. To fill this gap, this paper presents a model that makes it possible to appropriately quantify the reliability that a highly-reliable distributed system can achieve when using a replicated bus.
Manuel Barranco, Francisco Pozo, Julián Proenza
ETFA1
2014 Appropriate consistent replicated voting for increased reliability in a node replication scheme over FTT
abstract
In the context of critical applications there is an increasing interest in having Distributed Embedded Systems (DESs) that are able to operate in dynamic environments, while at the same time reaching a high reliability. The Flexible Time-Triggered communication paradigm (FTT) is designed to support the QoS and real-time requirements of the traffic of these systems. However, FTT does not provide fault tolerance. This paper explains our on-going work towards designing a consistent and highly-reliable voting protocol which supports node replication on DESs that use FTT switched Ethernet. In particular, we propose a protocol for the node replicas to vote consistently on messages exchanged through an FTT Ethernet network that uses time redundancy, while trying to maximize the reliability that can be achieved thanks to the redundancy of the nodes and the communication subsystem itself.
Sinisa Derasevic, Manuel Barranco, Julián Proenza
ETFA2
2014 Using FTT-ethernet for the coordinated dispatching of tasks and messages for node replication
abstract
The Flexible Time Triggered (FTT) paradigm provides online flexible scheduling for distributed embedded systems but it does not present adequate fault tolerance mechanisms so as to reach a very high reliability. Adding the adequate fault tolerance mechanisms to FTT-based architectures would open room for adaptive yet highly dependable systems. In this work we present a fault-tolerant system architecture for control applications that adds a node replication scheme with voting on top of an FTT-based system. Using a previously proposed network-centric approach we show how to coordinate the execution of the different phases for a typical control application in our system architecture, i.e. we show how to trigger the execution of tasks in node replicas and the transmission of messages in the communication channel, using the underlying FTT protocol. At the end, we demonstrate how to apply this idea of coordinated dispatching to one concrete control application, ball-on-plate.
Sinisa Derasevic, Julián Proenza, Manuel Barranco
ETFA3
2014 Towards an experimental assessment of the slave elementary cycle synchronization in the Flexible Time-Triggered Replicated Star for Ethernet
abstract
The communication subsystem of distributed embedded systems (DES) that must operate continuously and satisfy unpredictable requirement changes must be reliable and flexible. Recently the Flexible Time-Triggered Replicated Star for Ethernet (FTTRS) has been proposed as a communication subsystem that satisfies these two attributes. It is based on the master/multi-slave Flexible-Time Triggered (FTT) communication paradigm and relies on two custom switches, each with its own embedded FTT master. Both masters are active simultaneously and provide the same service. Specifically, they simultaneously and periodically broadcast so-called trigger messages (TMs) in a redundant manner to make them robust to transient channel faults. One of the functions of these TMs is to divide the communication time into rounds called elementary cycles (ECs). For the correct operation of FTTRS, it is important that all slaves agree when each EC starts and ends. A mechanism to achieve this has been recently proposed. This paper presents a first implementation of this mechanism and a series of experimental tests that constitute a first step towards building a prototype of an FTTRS network.
David Gessner, Ines Alvarez, Alberto Ballesteros, Manuel Barranco, Julián Proenza
ETFA4
2014 Towards a reliability analysis of the design space for the communication subsystem of FT4FTT
abstract
Fault Tolerance for Flexible Time-Triggered Ethernet-based systems (FT4FTT) is a project to devise an architecture for distributed embedded systems that provides both flexibility to changing real-time requirements and high reliability through fault tolerance. One of the key parts of such an architecture is the communication subsystem. When designing such a subsystem many decisions have to be made. To understand how such decisions impact the reliability of the final design, in this paper we present a framework to evaluate the reliability of a large number of potential designs. The approach is based on storing a finite subset of the design space for the communication subsystem of FT4FTT in an undirected graph and then generating a continuous-time Markov chain from the graph to evaluate the reliability of each design belonging to the subset.
David Gessner, Julián Proenza, Manuel Barranco, Paulo Portugal
ETFA3
2013 Towards preventing error propagation in a real-time Ethernet switch
abstract
Flexible Time-Triggered communication (FTT) allows a distributed embedded system (DES) to adapt to changing real-time requirements at runtime. This facilitates the continuous operation of the DES under dynamic environments that change over time. However, for continuous operation, high reliability in the nodes of the DES is also crucial. This can be achieved using node replication, as long as failure independence between replicas is ensured, which calls for preventing the propagation of errors. Our goal is to prevent the propagation of Byzantine node behaviours and to ensure that local errors in the channel cannot disturb the global communication. For this, we construct the HaRTES/PG switch, a new switch based on the HaRTES implementation of FTT for Ethernet. This paper presents as a first step a study of the possible errors that may lead to Byzantine node behaviours and a global communication disturbance in HaRTES, as well as some ideas on how to prevent the propagation of these errors in HaRTES/PG.
Alberto Ballesteros, David Gessner, Julián Proenza, Manuel Barranco, Paulo Pedreiras
ETFA4
2013 Towards a Flexible Time-Triggered replicated star for ethernet
abstract
Distributed embedded systems have traditionally been designed using static approaches, i.e., assuming a static environment. Such approaches, however, cannot guarantee continuous operation under dynamic environments that impose new requirements upon a system as time passes. As a solution, flexible approaches have been proposed. One such approach that allows a system to adapt to changing real-time requirements is the Flexible Time-Triggered (FTT) communication paradigm. Nevertheless, if continuous operation under dynamic environments is desired, then flexibility is not enough. Indeed, it is also crucial for the system to be sufficiently reliable. In this paper we therefore explore some design ideas to make FTT highly reliable through fault tolerance by using replication. As a starting point we will use the switch of the Hard Real-Time Ethernet Switching (HaRTES) implementation of FTT.
David Gessner, Julián Proenza, Manuel Barranco, Luís Almeida 0001
ETFA3
2013 Design and Verification of a Media Redundancy Management Driver for a CAN Star Topology
abstract
Some of the severe dependability limitations of Controller Area Network (CAN) can be overcome by replacing its bus topology with a star topology. Thus, a replicated star topology with advanced error-containment and fault-tolerance mechanisms for CAN, called ReCANcentrate, has been proposed. Its two hubs are coupled with each other and create a single logical broadcast domain. This allows each node to easily manage the replicated star by means of a software driver, called reCANdrv, that abstracts away the details of this replication. The goal of reCANdrv is to manage the star's media redundancy transparently for a CAN application, allowing it to exchange information through the star while tolerating faults. This paper describes the design of reCANdrv, the specification as properties of reCANdrv's correct redundancy management, and the verification of these properties by means of model checking.
David Gessner, Manuel Barranco, Julián Proenza
IEEE Trans. Ind. Informatics2
2012 Developing TOBE-CAN: Total order broadcast enforcement in CAN
abstract
One of the drawbacks of the Controller Area Network (CAN) that must be overcome to make it suitable for critical applications is its incapacity for providing a Total Order Broadcast (TOB) communication service. A number of mechanisms were proposed to solve this problem, but each one of them only addresses a specific TOB limitation. Thus, this paper introduces TOBE-CAN, the first solution that comprehensively overcomes all the TOB flaws these previous mechanisms deal with. TOBE-CAN takes advantage of some of these mechanisms and further provides TOB while tolerating faults that are beyond their capabilities.
Manuel Barranco, Julián Proenza
ETFA1
2012 A first qualitative evaluation of star replication schemes for FTT-CAN
abstract
Highly dependable distributed embedded systems (DES) have traditionally been developed using static approaches, i.e., assuming a mostly constant environment. However, the little flexibility of such approaches does not allow continuous operation under dynamic environments. The Flexible Time-Triggered (FTT) communication paradigm is a promising approach to introduce the required flexibility. However, for continuous operation reliability is also crucial. Replicated star topologies are particularly well-suited to provide an increased reliability. Nevertheless, for FTT-CAN, the implementation of FTT for CAN, no replicated star topology that takes advantage of FTT-CAN's features to increase reliability and error containment exists. This paper discusses important design questions that need to be solved to create such a novel solution.
David Gessner, Manuel Barranco, Julián Proenza, Michael Short 0001
ETFA2
2012 Using FTT and stars to simplify node replication in CAN-based systems
abstract
Nodes, among the components of distributed embedded systems, exhibit the greatest permanent failure rate. Thus, providing tolerance to nodes faults is mandatory whenever high-reliability is required, being node replication the most common technique for that purpose. This paper proposes a novel technique suitable for CAN-based systems that simplifies existing approaches taking advantage of a star topology and the FTT protocol.
Julián Proenza, Manuel Barranco, Joan Llodra, Luís Almeida 0001
ETFA2
2012 The design of the CANbids architecture
abstract
Despite the significant advantages of the Controller Area Network (CAN) there is an extended belief that CAN is not suitable for critical applications, mainly because of several dependability limitations. During the CANbids project each one of these limitations has been addressed and a complete architecture for CAN-based fault-tolerant systems has been devised. This architecture allows building highly-reliable systems. This paper describes the design of such an architecture and the prototyping of its fundamental parts.
Julián Proenza, Manuel Barranco, Guillermo Rodríguez-Navas, David Gessner, Fernando Guardiola, Luís Almeida 0001
ETFA2
2011 Towards understanding the sensitivity of the reliability achievable by simplex and replicated star topologies in CAN
abstract
Star-based field buses are gaining importance in the context of highly-dependable systems. However, although the error-containment and fault-tolerance capabilities of different stars have been evaluated, no one had appropriately quantified the system dependability benefits stars actually yield. Thus, in previous work, we quantitatively demonstrated, for the case of CAN, that a simplex and a replicated star called CANcentrate and ReCANcentrate can improve the system reliability when compared with a bus. However, we characterized all the dependability-related aspects of the system and the network to favor whenever possible the bus; except in one case, in which we studied the benefits of the simplex star over the bus depending on the error-containment capabilities of the nodes. Thus, to completely understand the full potential of stars, it is still necessary to assess how variations in each one of those aspects affect the reliability achievable with them when compared with the bus. This paper presents two of the set of analyses we are carrying out in this direction.
Manuel Barranco, Julián Proenza
ETFA1
2011 Towards the integration of flexible-time-triggered communication and replicated star topologies in CAN
abstract
There is a growing interest in making the CAN field-bus more suitable for dependable applications. In the past years, several dependability limitations of CAN have already been addressed and a significant number of solutions are available. Nevertheless, the integration of these solutions into a single communication infrastructure is still an open issue. In this paper we discuss the integration of two specific solutions: FTT-CAN and ReCANcentrate. FTT-CAN is a higher-layer protocol that guarantees flexible real-time scheduling of CAN messages; whereas ReCANcentrate is a duplicated star topology for CAN that includes several enhanced mechanisms for media fault tolerance. We show how they are integrated into a single architecture that preserves the properties of each solution.
Manuel Barranco, Guillermo Rodríguez-Navas, David Gessner, Julián Proenza
ETFA1
2011 Designing sfiCAN: A star-based physical fault injector for CAN
abstract
This paper presents the design and a preliminary implementation of sfiCAN: a physical fault injector for the CAN field-bus that allows the creation of a great variety of complex fault scenarios. The fault injector replaces the CAN bus topology with a star topology, whose central element is a hub with fault injection mechanisms. The fault injector is easily configured, with great flexibility, from a PC connected to a dedicated port of the hub. For this it uses a fault-injection specification, which is translated to a configuration protocol on top of CAN. This protocol is only used in-between fault injection tests and therefore does not interfere with the execution of any test. The purpose of the fault injector is to test the behavior of the nodes of a CAN network in the presence of channel errors, in particular, of the nodes' CAN controllers and the software executing on them, for which the star topology is transparent.
David Gessner, Manuel Barranco, Alberto Ballesteros, Julián Proenza
ETFA2
2010 First prototype and experimental assessment of media management in ReCANcentrate
abstract
Although the use of star topologies to improve dependability in field-buses is gaining in importance, as in TTP/C and FlexRay, a mature technology such as the Controller Area Network (CAN) remained essentially a bus-only network. Thus, we proposed a CAN-compliant replicated star topology called ReCANcentrate, which has advanced error-containment and fault-tolerance mechanisms. Its two hubs are coupled with each other and create a single logical broadcast domain that allowed us to propose, in a previous work, a strategy for each node to easily manage the replicated star by means of a software driver that abstracts away the details of the replication. This paper describes the main functionalities of this driver, as well as the first tests we have conducted, on a real ReCANcentrate prototype, to verify the correctness and the performance of the driver in the absence and in the presence of faults.
Manuel Barranco, David Gessner, Julián Proenza, Luís Almeida 0001
ETFA1
2009 Demonstrating the Feasibility of Media Management in ReCANcentrate
abstract
Star topologies are rising the interest of newer field-bus communication technologies like TTP/C and FlexRay, given the dependability advantages stars can offer. However, it is also possible to take advantage of a mature technology such as Controller Area Network (CAN), while benefiting from stars. For that, we developed a CAN-compliant replicated star called ReCANcentrate. It includes two hubs that are coupled with each other, thereby forcing a single broadcast domain that allowed us to define, in a previous work, a strategy for each node to easily manage the replicated star. To demonstrate the feasibility of this management, this paper presents its on-going implementation as a driver to be executed at each node.
Manuel Barranco, David Gessner, Julián Proenza, Luís Almeida 0001
ETFA1
2009 First Quantitative Results of the Dependability Improvement Achieved by ReCANcentrate
abstract
There is a growing interest in using star topologies instead of buses as the communication infrastructure for highly-reliable distributed control systems, given the better dependability stars are supposed to provide. For the controller area network (CAN), we developed a simplex and a replicated star called CANcentrate and ReCANcentrate respectively. In a previous work we modelled the dependability of the CAN bus and CANcentrate using stochastic activity networks (SANs). There we presented the first quantitative analysis of the error-containment benefits of a simplex star when considering permanent hardware faults. This paper quantitatively analyzes, for the first time, how a replicated star such as ReCANcentrate can improve both error-containment and reliability, also considering permanent hardware faults. We explain our modelling strategy using SANs and show some first and novel results.
Manuel Barranco, Julián Proenza, Luís Almeida 0001
ETFA1
2008 Designing and verifying media management in ReCANcentrate
abstract
To overcome some dependability limitations of CAN that arise from its non-redundant bus topology, we have proposed a CAN-compliant replicated star topology, ReCANcentrate, whose hubs incorporate the necessary fault-treatment and fault-tolerance mechanisms. This paper presents ongoing work regarding the design and formal verification of the strategy each node of ReCANcentrate uses to manage the transmissions and the receptions on the replicated star, as well as to tolerate faults.
Manuel Barranco, Julián Proenza, Luís Almeida 0001
ETFA1
2006 An active star topology for improving fault confinement in CAN networks
abstract
The controller area network (CAN) is a field bus that is nowadays widespread in distributed embedded systems due to its electrical robustness, low price, and deterministic access delay. However, its use in safety-critical applications has been controversial due to dependability limitations, such as those arising from its bus topology. In particular, in a CAN bus, there are multiple components such that if any of them is faulty, a general failure of the communication system may happen. In this paper, we propose a design for an active star topology called CANcentrate. Our design solves the limitations indicated above by means of an active hub, which prevents error propagation from any of its ports to the others. Due to the specific characteristics of this hub, CANcentrate is fully compatible with existing CAN controllers. This paper compares bus and star topologies, analyzes related work, describes the CANcentrate basics, paying special attention to the mechanisms used for detecting faulty ports, and finally describes the implementation and test of a CANcentrate prototype.
Manuel Barranco, Julián Proenza, Guillermo Rodríguez-Navas, Luís Almeida 0001
IEEE Trans. Ind. Informatics1
2003 COTS-based hardware support to timeliness in CAN networks
abstract
Advances in programmable hardware have simplified integration of communication facilities in low-cost hardware components. This has proved to be beneficial in the design of distributed embedded systems as it allows the communication subsystem to provide important properties at a low level. The present work follows this approach in order to achieve timeliness in CAN networks. This paper describes the implementation of the LST-CAN protocol in programmable hardware. This protocol is an extension to CAN which ensures timely communication regardless of environmental interferences.
Guillermo Rodríguez-Navas, Manuel Barranco, Julián Proenza, Ian Broster
ETFA (1)2