Alejandro Masrur

dblp:45/6623 · DBLP profile ↗
← Back
44ranked-venue papers
10as first author
11since 2021 · last 2026
0000-0003-2524-1751ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 26 · 6 first-author · 7 since 2021Software engineering, systems software and programming languages · 12 · 3 first-author · 4 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 2 since 2021Artificial intelligence and machine learning · 3 · 2 since 2021Computer networks · 2
YearPublicationVenuePosition
2026 Mitigating Cybersecurity Attacks on Automotive Radar Systems
Moritz Kahlert, Daniel Markert, Tai Fei, Markus Gardill, Alejandro Masrur
IV6
2025 Mitigating DoS Attacks on CAN: A Priority-Raise Approach and Its Timing Analysis
abstract
With an increasing level of interconnection, it has become easier for attackers to target in-vehicle buses in industrial and road vehicles alike. One of the most common attacks is Denial-of-Service (DoS), where the bus is flooded with messages disrupting critical functions and, thereby, jeopardizing the safety of operators and/or passengers. In this paper, we are concerned with DoS attacks on Controller Area Network (CAN) – one of the most popular buses – and propose a priority-raise approach (PRA) to mitigate their impact. Basically, we limit the priority of messages arriving through a gateway from outside the vehicle. If a DoS attack is started, this only affects the messages with lower priority than that used by the attacker. Affected messages can then switch to a higher priority reserved for them, i.e., they can raise their priority, to escape the attack. We investigate a centralized as well as a decentralized priority switching and analyze timing for a varying DoS severity.
Alejandro Masrur
DDECS2
2024 Environmental Microchanges in WiFi Sensing
abstract
Using WiFi's Channel State Information for human activity recognition—referred to as WiFi sensing—has attracted considerable attention. But despite this interest and many publications over a decade, WiFi sensing has not yet found its way into practice because of a lack of robustness of the inference results. In this paper, we quantitatively show that even “microchanges” in the environment can significantly impact WiFi signals, and potentially alter the ML inference results. We therefore argue that new training and inference techniques might be necessary for mainstream adoption of WiFi sensing.
Cristian Turetta, Philipp H. Kindt, Alejandro Masrur, Samarjit Chakraborty, Graziano Pravadelli, Florenc Demrozi
DATE3
2024 Characterizing Road Maps for Vehicle Endurance Testing with Machine Learning
abstract
To select optimal routes for vehicles endurance tests, it is necessary to have a road map characterized by events of interest. In this context, we define events as effects on the vehicle triggered by some proprieties of the routes. Such a characterization strongly relies on data from previous test drives. If new road maps are to be considered, e.g., in a different region, the route selection rather depends on the experience of engineers, which can lead to suboptimal decisions. To overcome this problem, we propose using the existing data from prior test drives to train a machine learning (ML) model, which then transfers this knowledge to unseen road maps. To this end, we formulate a sequential problem that can be solved with state-of-the-art ML architectures. Our experimental results based on real-world data show the potential of the proposed approach as we illustrate for the case of testing energy recuperation in electric vehicles.
Bijin Muthiyackal Abraham, Christian Drescher, Daniel Markert, Ana Pérez Grassi, Alejandro Masrur
IV5
2023 Towards Deep Learning-based Occupancy Detection Via WiFi Sensing in Unconstrained Environments
abstract
In the context of smart buildings and smart cities, the design of low-cost and privacy-aware solutions for recognizing the presence of humans and their activities is becoming of great interest. Existing solutions exploiting wearables and video-based systems have several drawbacks, such as high cost, low usability, poor portability, and privacy-related issues. Consequently, more ubiquitous and accessible solutions, such as WiFi sensing, became the focus of attention. However, at the current state-of-the-art, WiFi sensing is subject to low accuracy and poor generalization, primarily affected by environmental factors, such as humidity and temperature variations, and furniture position changes. Such is-sues are partially solved at the cost of complex data preprocessing pipelines. In this paper, we present a highly accurate, resource-efficient deep learning-based occupancy detection solution, which is resilient to variations in humidity and temperature. The approach is tested on an extensive benchmark, where people are free to move and the furniture layout does change. In addition, based on a consolidated algorithm of explainable AI, we quantify the importance of the WiFi signal w.r.t. humidity and temperature for the proposed approach. Notably, humidity and temperature can indeed be predicted based on WiFi signals; this promotes the expressivity of the WiFi signal and at the same time the need for a non-linear model to properly deal with it.
Cristian Turetta, Geri Skenderi, Luigi Capogrosso, Florenc Demrozi, Philipp H. Kindt, Alejandro Masrur, Franco Fummi, Marco Cristani, Graziano Pravadelli
DATE6
2023 A Two-Speed Synchronous Traffic Protocol for Intelligent Intersections: From Single-Vehicle to Platoon Crossing
abstract
With progress in cooperative and autonomous driving, there is an increasing interest in intelligent intersections to replace conventional traffic lights and, thereby, improve traffic efficiency. To avoid accidents in such safety-critical systems, a traffic protocol needs to be implemented. In this article, we are concerned with synchronous traffic protocols, i.e., those that synchronize the arrival time of vehicles at the intersection. In particular, such protocols are normally conceived for homogeneous vehicles of approximately the same size/length. However, these do not extend well to heterogeneous vehicles, i.e., they lead to unviable requirements on the road infrastructure. To overcome this limitation, based on the observation that large/overlength vehicles like buses and trams are less frequent than passenger vehicles, we propose an approach that treats them as exceptions (rather than the rule) leading to a much more efficient design. In contrast to approaches from the literature, we implement a two-speed policy—with a high speed for drive-through and a low speed for turn maneuvers—and analyze both single-vehicle as well as fairness-based platoon crossing. To conclude, we perform detailed comparisons illustrating the benefits by the proposed approach.
Daniel Markert, Alejandro Masrur
ACM Trans. Cyber Phys. Syst.2
2022 Practical identity recognition using WiFi's Channel State Information
abstract
Identity recognition is increasingly used to control access to sensitive data, restricted areas in industrial, healthcare, and defense settings, as well as in consumer electronics. To this end, existing approaches are typically based on collecting and analyzing biometric data and imply severe privacy con-cerns. Particularly when cameras are involved, users might even reject or dismiss an identity recognition system. Furthermore, iris or fingerprint scanners, cameras, microphones, etc., imply installation and maintenance costs and require the user's active participation in the recognition procedure. This paper proposes a non-intrusive identity recognition system based on analyzing WiFi's Channel State Information (CSI). We show that CSI data attenuated by a person's body and typical movements allows for a reliable identification - even in a sitting posture. We further propose a lightweight deep learning algorithm trained using CSI data, which we implemented and evaluated on an embedded platform (i.e., a Raspberry Pi 4B). Our results obtained using real-world experiments suggest a high accuracy in recognizing people's identity, with a specificity of 98% and a sensitivity of 99%, while requiring a low training effort and negligible cost.
Cristian Turetta, Florenc Demrozi, Philipp H. Kindt, Alejandro Masrur, Graziano Pravadelli
DATE4
2022 Analyzing CAN's Timing under Periodically Authenticated Encryption
abstract
With increasing connectivity, it has become easier to remotely access in-vehicle buses like CAN (Controller Area Network). This not only jeopardizes security, but it also exposes CAN's limitations. In particular, to reject replay and spoofing attacks, messages need to be authenticated, i.e., an authentication tag has to be included. As a result, messages become larger and need to be split in at least two frames due to CAN's restrictive payload. This increases the delay on the bus and, thus, some deadlines may start being missed compromising safety. In this paper, we propose a Periodically Authenticated Encryption (PAE) based on the observation that we do not need to send authentication tags with every single message on the bus, but only with a configurable frequency that allows meeting both safety and security requirements. Plausibility checks can then be used to detect whether non-authenticated messages sent in between two authenticated ones have been altered or are being replayed, e.g., the transmitted values exceed a given range or are not in accordance with previous ones. We extend CAN's known schedulability analysis to consider PAE and analyze its timing behavior based on an implementation on real hardware and on extensive simulations.
Philip Parsch, Henry Hoffmann, Alejandro Masrur
DATE4
2022 A Cyber-physical Approach for Emergency Braking in Close-Distance Driving Arrangements
abstract
In addition to fuel/energy savings, close-distance driving or platooning allows compacting vehicle flows and, hence, increasing throughput on congested roads. The shorter the inter-vehicle separation is in such settings, the more the benefits. However, it becomes considerably harder to guarantee safety, in particular, when braking in an emergency. In this article, we are concerned with this problem and propose a cyber-physical approach that considerably reduces the stopping distance of a platoon with inter-vehicle separations shorter than one vehicle length (i.e., 5 m) without sacrificing safety and independent of the road profile, i.e., whether on a flat road or in a downhill. The basic idea is to implement a cooperative behavior where a vehicle sends a distress message if it fails to achieve an assigned deceleration when braking in a platoon. This way, other vehicles in the arrangement can adapt their decelerations to avoid collisions. We illustrate and evaluate our approach based on detailed simulations involving high-fidelity vehicle models.
Dharshan Krishna Murthy, Alejandro Masrur
ACM Trans. Cyber Phys. Syst.2
2021 Controlled Intra-Platoon Collisions for Emergency Braking in Close-Distance Driving Arrangements
abstract
The increasing degree of automation and communication makes it possible that vehicles travel at short separations of a few meters, i.e., in a close-distance driving arrangement or platoon. This leads to higher energy/fuel savings and an increased vehicle throughput on roads, among other benefits. Whereas a considerable amount of effort has been dedicated to cruise control in such settings, techniques for emergency braking have been paid less attention. However, this is of paramount importance for a safe operation in such settings and requires special attention. The goal is to reduce the overall stopping distance when braking in an emergency, while keeping a compact platoon, i.e., inter-vehicle separations as short as possible to maximize benefits. This turns out to be challenging, in particular, if vehicles have different braking capabilities, e.g., due to their type and/or loading conditions. In some cases, intra-platoon collisions may even be the only way to avoid major accidents. In this paper, we are concerned with this problem and propose an approach based on engineering controlled intra-platoon collisions. The idea is to minimize potential damage incurred by platoon vehicles, while reducing the overall stopping distance. We illustrate and evaluate our proposed approach for the case of a two-vehicle arrangement based on detailed simulations.
Dharshan Krishna Murthy, Alejandro Masrur
DSD2
2021 A novel view on bounding execution demand under mixed-criticality EDF
abstract
Abstract In this paper, we are concerned with scheduling a mix of high-criticality (HI) and low-criticality (LO) tasks under Earliest Deadline First (EDF) on one processor. To this end, the system implements two operation modes, LO and HI mode. In LO mode, HI tasks execute for no longer than their optimistic execution budgets and are scheduled together with the LO tasks. The system switches to HI mode, where all LO tasks are prevented from running, when one or more HI tasks run for longer than expected. Since these mode changes may happen at arbitrary points in time, it is difficult to find an accurate bound on carry-over jobs, i.e., those HI jobs that were released before, but did not finish executing at the point of the transition. To overcome this problem, we propose a technique that works around the computation of carry-over execution demand. Basically, the proposed technique separates the schedulability analysis of the transition between LO and HI mode from that of stable HI mode. We prove that a transition from LO to HI mode is feasible, if an equivalent task set derived from the original is schedulable under plain EDF. On this basis, we can apply approximation techniques such as, e.g., the well-known Devi’s test to derive further tests that trade off accuracy versus complexity/runtime. Finally, we perform a detailed comparison with respect to weighted schedulability on synthetic data illustrating benefits by the proposed technique.
Mitra Mahdiani, Alejandro Masrur
Real Time Syst.2
2019 Analyzing the Impact of Probabilistic Estimates on Communication Reliability at Intelligent Crossroads
abstract
Intelligent crossroads aim to substitute conventional traffic lights by coordinating the order in which vehicles cross an intersection. Since vehicles come and go at arbitrary points in time, this results in an open-ended setting that is difficult to analyze with deterministic methods. In particular, deterministic methods fail to provide meaningful estimates of the maximum number of vehicles at the intersection, which is paramount to assess communication reliability and, in the end, guarantee safety. In contrast, statistical and probabilistic techniques are more suitable for this purpose and constitute the focus of this paper. We especially investigate how different driving directions and vehicle lengths influence the quality of probabilistic estimates in approximating the maximum number of vehicles at the intersection. These estimates are then incorporated into the design and analysis of the crossroad VANET to derive guarantees on communication reliability. Our results show that such estimates can greatly reduce pessimism and overdesign compared to deterministic approaches. These and other benefits are illustrated by means of a detailed case study and simulationsusing OMNeT++.
Daniel Markert, Philip Parsch, Alejandro Masrur
DSD3
2019 Analyzing the Impact of Secure CAN Networks on Braking Dynamics of Cooperative Driving
abstract
With the advent of cooperative driving, vehicles can travel at very short distances between them. These vehicle arrangements lead to fuel savings due to the reduced aerodynamic forces. However, the braking situations can be extremely dangerous due to the short vehicle distances. Therefore, a solution has to be devised for safe and collision-free braking. Additionally, such vehicle arrangements have to also be protected from cyber attacks so that no intruder can take over vehicle control. The in-vehicle sensors together with secure in-vehicle networks can be efficiently used for both braking and at the same time shielding the vehicle from intruders with malicious intent.
Dharshan Krishna Murthy, Alejandro Masrur
DSD3
2019 Space-Efficient Traffic Protocols for Intelligent Crossroads
abstract
With the advent of autonomous driving, intelligent crossroads aim to substitute conventional traffic lights by interleaving vehicles crossing in all possible directions. To this end, there must be sufficiently large gaps between vehicles on the different lanes, which needs to be enforced by a traffic protocol taking vehicles' dimensions into account. In particular, existing such protocols are designed for the longest possible vehicle resulting in space-hungry intersections, that require modifications in the infrastructure (in particular, broader roads/lanes), Moreover, these do not allow for vehicles that are exceptionally longer than the ones considered at design time (e.g., extra long trucks, or buses, etc.), In this paper, to overcome this limitation, we present a traffic protocol which handles overlength vehicles as exceptions to compensate for their low probability of occurrence, relaxing space requirements on the intersections. We perform a detailed analysis and comparison showing that the proposed approach leads to high vehicle throughput while keeping intersections small, in particular, as overlength vehicles become longer and less frequent.
Daniel Markert, Alejandro Masrur
IV2
2019 Improving Timing Behavior on Encrypted CAN Buses
abstract
CAN is probably the most successful bus in the automotive domain, especially, due to its low cost and robustness. However, with increasing connectivity, there is a need to encrypt data to avoid attacks such as Spoofing and Sniffing. This ends up exposing CAN's severe limitations. In particular, each encrypted message requires sending two frames due to its restrictive payload in CAN. Moreover, each frame of an encrypted message undergoes a separate arbitration process which negatively impacts timing and makes it difficult to meet deadlines. In this paper, to work around this problem, we propose a technique that consists in assigning different priorities to encrypted CAN frames so as to compensate for increased delay. The basic idea is that, once the first frame of an encrypted CAN message wins arbitration, its second frame will always win arbitration within a specified scope and can be sent with lesser delay. We have conducted experiments on real hardware and performed extensive simulations indicating that the proposed technique reduces transmission delay to one half or even one third compared with the standard approach allowing us to still meet typical automotive deadlines on an encrypted CAN bus.
Alejandro Masrur
RTCSA2
2019 Accounting for Reliability in Unacknowledged Time-Constrained WSNs
abstract
Wireless sensor networks typically consist of nodes that collect and transmit data periodically. In this context, we are concerned with unacknowledged communication, such as where data packets are not confirmed upon successful reception. This allows reducing traffic on the communication channel—neither acknowledgments nor retransmissions are sent—and results in less overhead and less energy consumption, which are meaningful goals in the era of the Internet of Things. However, packets can be lost, and hence we do not know how long it takes to convey data from one node to another, which hinders any form of real-time operation and/or quality of service. To overcome this problem, we propose a medium access control protocol, which consists of transmitting each packet at a random instant but within a specified time interval from the last transmission. In contrast to existing approaches from the literature, the proposed medium access control can be configured to meet reliability requirements—given by the probability that at least one data packet reaches its destination within a specified deadline—in the absence of acknowledgments. We illustrate this and other benefits of the proposed approach based on detailed OMNeT++ simulations.
Philip Parsch, Alejandro Masrur
ACM Trans. Cyber Phys. Syst.2
2018 On reliable communication in transmit-only networks for home automation
Philip Parsch, Alejandro Masrur
J. Netw. Comput. Appl.2
2017 A Subplatooning Strategy for Safe Braking Maneuvers
abstract
Reducing the inter-vehicle separation in a platoon results in the most benefits in terms of aerodynamic savings and vehicles throughput. However, this makes braking maneuvers dangerous and leads to long stopping distances, in particular, when considering heterogeneous vehicles with different braking capacities. Even though control theoretic approaches exist for the platoon cruise operation, the scenario of sudden braking has to be designed separately as the system reaches saturation, i.e., in order to minimize the stopping distance of the platoon, the application of the maximum possible braking forces is required. This cannot be handled by standard control systems alone, since they rely on varying (control) variables/signals, which is not possible under saturation. In this paper, we are concerned with vehicles of heterogeneous braking capacity and propose a subplatooning strategy that not only guarantees a collision-free braking, but also minimizes the stopping distance. Vehicles within each subplatoon have inter-vehicle separations of below one car length, whereas the inter-subplatoon separation is increased to compensate the differences in decelerations between subplatoons. We evaluate this scheme using a realistic simulation based on complex vehicle dynamics models and a HiL (hardware in the loop) setting.
Dharshan Krishna Murthy, Alejandro Masrur
DSD2
2017 An Ensemble-Based Approach for Scalable QoS in Highly Dynamic CPS
abstract
Modern cyber-physical systems (CPS) often involve distributed devices/components that closely interact with each other and their environment. In this context, operation conditions may constantly change and it is not always possible to guarantee quality of service (QoS), particularly, if resourcesdegrade or stop being available. In addition, sometimes, one would like QoS to scale up/down with operation conditions, e.g., maximize efficiency, minimize energy consumption, etc. without compromising safety. However, traditional design and development techniques fail to capture the dynamics of modern CPS, since they rather focus on individual components/devices, and are unable to provide such QoS guarantees. To overcome this problem, we propose a design methodology based on the concept of ensemble, i.e., a dynamic grouping of components, which allows for scalable QoS guaranties. We illustrate the utility of our approach based on a case study consisting of an intelligent production line and analyze the effect on performance as communication between components degrades. Finally, our methodology can be incorporated into existing ensemble-based tools such as DEECo, Helena or jRESP to generate executable code to be deployed onto distributed devices.
Vladimír Matena, Alejandro Masrur, Tomás Bures
SEAA2
2017 Exploiting space buffers for emergency braking in highly efficient platoons
abstract
With the advent of autonomous driving, road trains or platoons are regaining importance as a meaningful way of improving traffic efficiency and economizing on fuel/energy. It has been shown that reducing inter-vehicle separations to less than one car length results in the most benefits for the whole platoon; however, this poses a number of challenges. In particular, it becomes difficult to guarantee a collision-free braking in an emergency situation considering that individual vehicles may have different braking capacities in real-life settings - due to, for example, different load conditions, etc. Although control-theoretic approaches can be used to design a platoon's cruise operation, emergency braking leads to saturation, i.e., the maximum possible braking force is applied so as to stop the platoon in the shortest possible time and needs to be designed separately. In this paper, we address this issue and introduce a cyber-physical approach that guarantees a collision-free braking in emergency situations. The proposed approach exploits space buffers contained in between vehicles and can be configured to reduce stopping distance and platoon length, while maximizing aerodynamic benefits. We evaluate our approach based on realistic simulations with vehicle dynamics models typically used in the automotive industry for hardware-in-the-loop (HiL) testing. The effects of communication loss during platoon operation are also considered and fail-safe mechanisms are proposed and investigated.
Dharshan Krishna Murthy, Alejandro Masrur
RTCSA2
2017 A reliable MAC for delay-bounded and energy-efficient WSNs
abstract
With the advent of Internet of Things (loT), an increasing number of devices start exchanging information. This puts emphasis on wireless sensor networks (WSNs) to facilitate the interaction with the environment in varied application scenarios such as, for example, building and home automation among others. In this context, a reliable communication is usually required, i.e., it is necessary to guarantee that packets arrive within a specified maximum delay or deadline. In addition, since battery-driven nodes are used and/or for the sake of sustainability, WSNs often have to economize on energy. However, most existing MAC (Medium Access Control) protocols are either unable to provide guarantees on reliability (e.g., CSMA) or they incur too much energy consumption (e.g., TDMA). To overcome this problem, we propose a MAC technique that guarantees reliability requirements while allowing for delay-bounded and energy-efficient communication. We carry out a large number of experiments based on detailed simulations with OMNeT++ comparing the proposed MAC, in particular, with CSMA and TDMA and illustrating its benefits.
Philip Parsch, Alejandro Masrur
RTCSA2
2016 A probabilistic scheduling framework for mixed-criticality systems
abstract
We propose a probabilistic scheduling framework for the design and development of mixed-criticality systems, i.e., where tasks with different levels of criticality need to be scheduled on a shared resource. Whereas highly critical tasks normally require hard real-time guarantees, less or non-critical ones may be degraded or even temporarily discarded at runtime. We hence propose giving probabilistic (instead of deterministic) real-time guarantees on low-criticality tasks. This simplifies the analysis and reduces conservativeness on the one hand. On the other hand, probabilistic guarantees can be tuned by the designer to reach a desired level of assurance. We illustrate these and other benefits of our framework based on extensive simulations.
Alejandro Masrur
DAC1
2016 Introducing Utilization Caps into Mixed-Criticality Scheduling
abstract
We are concerned with mixed-criticality systems where a set of low-criticality (LO) and high-criticality (HI) tasks share one processor and are scheduled under EDF-VD algorithm. EDF-VD implements two operation modes: LO and HI. In LO mode, one or more HI tasks may exceed their execution budgets, which then causes a change to HI mode in the system. In HI mode, HI tasks are assigned larger execution budgets at the cost of the LO tasks, which often need to be discarded. In some cases, however, we would like to allow some LO tasks to continue running on the processor in spite of switching to HI mode. To this end, we incorporate utilization caps into the original EDF-VD algorithm. The idea is to partition tasks on the processor, for example, according to functional dependencies, and assign them a portion the total utilization. EDF-VD then applies to each of these partitions individually and up to their corresponding utilization caps. If one HI task exceeds its execution budget in LO mode, this only affects the LO tasks in the same partition, but not LO tasks in other partitions which can continue running. We present a technique to optimally choose utilization caps for each partition and perform a large set of experiments based on synthetic data illustrating benefits of the proposed technique.
Mitra Mahdiani, Alejandro Masrur
DSD2
2016 Braking in Close Following Platoons: The Law of the Weakest
abstract
This paper is concerned with the realization of semi-autonomous vehicle arrangements as the natural transition towards fully automated traffic. In particular, we are interested in road trains or platoons, which involve a group of vehicles at close following distances. This is known to reduce fuel -- or energy -- consumption due to reduced aerodynamic forces acting on them. Currently, available techniques and technologies allow for inter-vehicle distances close to 5 meters with suboptimal fuel/energy savings. To obtain the most savings from a platoon formation (with even less consumption for the lead vehicle), it has been shown that the inter-vehicle distance needs to be reduced to 2.5 meters or less making braking maneuvers even more dangerous. In this paper, we present the design and analysis of a brake-by-wire system for the above case, whose operation is characterized by the law of the weakest. That is, the system automatically adapts braking forces at different platoon members -- taking vehicles' load condition, etc. into account -- to equalize that of the weakest one, i.e., the one braking at the slowest rate in the platoon. We present simulation results based on an automotive hardware-in-the-loop (HiL) setup with realistic car models. Our experiments shows that the proposed system is safe, enabling for collision-free emergency braking at intervehicle distances of 2.5 meters and, hence, paving the way for highly efficient platoons.
Dharshan Krishna Murthy, Alejandro Masrur
DSD2
2016 A Reliable MAC for Energy-Efficient WSNs in the Era of IoT
abstract
Wireless sensor networks (WSNs) are gaining in importance with an increasing need for interconnectivity in the advent of Internet of Things. In some application scenarios, such as building and home automation, WSNs need to comply with deadlines and guarantee a reliable communication, for which a suitable MAC (Medium Access Control) is of paramount importance. However, existing approaches from the literature are either unable to provide such guarantees (e.g., CSMA) or they incur too much energy consumption (e.g., TDMA). To overcome this problem, we propose a MAC technique that guarantees reliability requirements while fulfilling a maximum delay constraint or deadline. We perform a large set of experiments based on detailed simulations with OMNeT++ showing that our technique is energy-efficient and significantly outperforms standard MAC approaches such as CSMA and TDMA.
Philip Parsch, Alejandro Masrur
DSD2
2016 A Slot Sharing TDMA Scheme for Reliable and Efficient Collision Resolution in WSNs
abstract
With the advent of Internet of Things (IoT), an increasing number of devices may spontaneously communicate to exchange information. This puts emphasis on wireless sensor networks (WSNs) and, in particular, on intelligent medium access control (MAC) protocols, as there is a need to guarantee a certain quality of service (QoS) on timely data/packet delivery. Most existing approaches, however, are either of random nature, making it impossible to guarantee any bounded delay, or do not scale well for a higher number of nodes. As a result, we propose slot sharing TDMAs², a deterministic contention resolution scheme in form of generating TDMA cycles with shared slots at the event of collisions. Every TDMA slot is assigned to a range of IDs, in which the corresponding nodes can transmit. By further dividing these slots in case of collisions, we implement an interval tree search enabling for fast collision resolution in logŝ-complexity, where ŝ is the number of slots in each cycle. Since our scheme is activated upon collisions, it incurs in zero overhead during normal operation and is able to quickly react to changing traffic load such as bursty traffic. We perform a large set of detailed simulations on OMNeT++ showing that our technique offers a fast collision resolution and is able to handle a large number of nodes in the network.
Philip Parsch, Alejandro Masrur
MSWiM2
2015 Composing real-time applications from communicating black-box components
abstract
To handle complexity, embedded software is usually divided into components that are developed independently from each other and then need to be integrated in a reliable and deterministic manner. This involves buffering and synchronizing exchanged signals, as well as finding a feasible execution schedule, which is a tedious and error-prone procedure. We propose a model of computation that enables a programming framework which automatically performs such an integration, without requiring access to the components' source code. The developer only needs to declare interface signals between the components, connect them and define their execution periods. A software library then synthesizes deterministic communication mechanisms and provides a flexible, yet safe interface for time-triggered execution. Our approach does not require any run-time environment or special compiler, which makes it light-weight and amenable to be used on embedded platforms with limited resources.
Martin Becker 0001, Alejandro Masrur, Samarjit Chakraborty
ASP-DAC2
2015 Application-Driven Evaluation of AUTOSAR Basic Software on Modern ECUs
abstract
When integrating AUTOSAR software on an automotive ECU, errors may occur due to the large number of modules involved and/or improper timing. These errors manifest at the application level complicating the test and verification process. Since AUTOSAR has a layered architecture, it is often cumbersome to identify sources of errors. In this paper, to help integrating software on an ECU, we propose a technique to verify functionality and timing of generated AUTOSAR modules in a semi-automated manner. Our technique consists in defining test cases based on the interface descriptions of AUTOSAR modules and application software. This allows reliably identifying AUTOSAR modules affected by functional and/or timing errors and simplifies the test and verification process. We illustrate the benefits by our technique by means of a case study performed on the real hardware.
Norbert Englisch, Felix Hänchen, Frank Ullmann, Alejandro Masrur, Wolfram Hardt
EUC4
2015 Bi-Level Deadline Scaling for Admission Control in Mixed-Criticality Systems
abstract
In some cases, tasks may be allowed to migrate from one processor to another, e.g., Due to hardware failures or for workload balancing. If a mixed-criticality setting is considered, it is necessary to decide whether new tasks with different levels of criticality may be accepted by a processor without compromising the already running tasks. Since this decision has to be taken on-line, there is a need for fast but yet accurate schedulability tests for mixed-criticality systems. In this paper, we consider that the EDF-VD algorithm is used to schedule tasks on the different processors. EDF-VD assigns virtual deadlines to high-criticality tasks, i.e., It uniformly downscales their real deadlines, to account for a potential increase in their execution demand. A deadline scaling factor is hence computed for the whole processor. However, in the case where the increase in computation demand strongly differs from one task to another, scaling deadlines uniformly makes EDF-VD incur pessimism. Of course, a scaling factor can be computed for every single task, however, this leads to a considerably more complex algorithm which cannot be used in an on-line setting. As a result, we propose an intermediate solution by introducing a bi-level deadline scaling. This way, high-criticality tasks that experience a small increase of workload are assigned one scaling factor, whereas tasks with a large increase of workload are assigned a separate scaling factor. Our experiments show that the proposed approach dominates the original EDF-VD algorithm while it does not increase complexity allowing for constant-time admission control in mixed-criticality systems.
Alejandro Masrur, Dirk Müller 0002, Matthias Werner 0001
RTCSA1
2014 The schedulability region of two-level mixed-criticality systems based on EDF-VD
abstract
The algorithm Earliest Deadline First with Virtual Deadlines (EDF-VD) was recently proposed to schedule mixed-criticality task sets consisting of high-criticality (HI) and low-criticality (LO) tasks. EDF-VD distinguishes between HI and LO mode. In HI mode, the HI tasks may require executing for longer than in LO mode. As a result, in LO mode, EDF-VD assigns virtual deadlines to HI tasks (i.e., it uniformly downscales deadlines of HI tasks) to account for an increase of workload in HI mode. Different schedulability conditions have been proposed in the literature; however, the schedulability region to fully characterize EDF-VD has not been investigated so far. In this paper, we review EDF-VD's schedulability criteria and determine its schedulability region to better understand and design mixed-criticality systems. Based on this result, we show that EDF-VD has a schedulability region being around 85% larger than that of the Worst-Case Reservations (WCR) approach.
Dirk Müller 0002, Alejandro Masrur
DATE2
2014 Towards Component-Based Design of Safety-Critical Cyber-Physical Applications
abstract
Cyber-physical systems typically involve a large number of mobile autonomous devices that closely interact with each other and their environment. Standard design and development techniques from the embedded domain fail to accurately model the dynamics of such systems and, hence, there is an increasing need for new programming models and abstractions. Component-based design approaches are a promising solution to manage the complexity of large-scale dynamic systems. However, existing such approaches either do not accurately model transitory interactions between components -- which are typical of cyber-physical systems -- or do not provide guarantees for real-time behavior which is essential in many safety-critical applications. To overcome this problem, in this paper, we present a component-based design technique based on DEECo (Dependable Emergent Ensembles of Components). The DEECo framework allows modeling large-scale dynamic systems by a set of interacting components. In contrast to other component-based design approaches from the literature, DEECo provides mechanisms to describe transitory interactions between components. We introduce necessary extensions to the DEECo design flow and integrate it with real-time analysis techniques that allow reasoning about timing behavior at the component-description level. Finally, we illustrate the simplicity and usefulness of our approach on a case study consisting of an intelligent crossroad system.
Alejandro Masrur, Michal Kit, Tomás Bures, Wolfram Hardt
DSD1
2013 Model-based development and verification of control software for electric vehicles
abstract
Most innovations in the automotive domain are realized by electronics and software. Modern cars have up to 100 Electronic Control Units (ECUs) that implement a variety of control applications in a distributed fashion. The tasks are mapped onto different ECUs, communicating via a heterogeneous network, comprising communication buses like CAN, FlexRay, and Ethernet. For electric vehicles, software functions play an essential role, replacing hydraulic and mechanic control systems. While model-based software development and verification are already used extensively in the automotive domain, their importance significantly increases in electric vehicles as safety-critical functions might no longer rely on mechanical (fall-back) solutions. The need for reducing costs, size, and weight in electric vehicles has also resulted in a considerable interest in topics such as the consolidation of ECUs as well as efficient implementation of control software. In this paper we discuss two broad issues related to model-based software development and verification in electric vehicles. The first is concerned with how to ensure that model-level semantics are preserved in an implementation, which has important implications on the verification and certification of control software. The second issue is related to techniques for reducing the computational and communication demands of distributed automotive control algorithms. For both these topics we provide a broad introduction to the problem followed by a discussion on state-of-the-art techniques.
Dip Goswami, Martin Lukasiewycz, Matthias Kauer, Sebastian Steinhorst, Alejandro Masrur, Samarjit Chakraborty, S. Ramesh 0002
DAC5
2013 Multirate controller design for resource- and schedule-constrained automotive ECUs
abstract
Automotive software mostly consists of a set of applications controlling the vehicle dynamics, engine and many other processes or plants. Since automotive systems design is highly cost driven, an important goal is to maximize the number of control applications to be packed onto a single processor or electronic control unit (ECU). Current design methods start with a controller design step, where the sampling period and controller gain values are decided based on given control performance objectives. However, operating systems (OS) on the ECU (e.g., ERCOSek) are usually pre-configured and offer only a limited set of sampling periods. Hence, a controller is implemented using an available sampling period, which is the shorter period closest to the one determined in the controller design step. However, this increases the load on the ECU (i.e., the processor runs the controller more often than what is actually required by design). This reduces the number of applications that can be mapped, and increases costs of the system. To overcome this predicament, we propose a multirate controller, which switches between multiple available sampling periods offered by the OS on the ECU. Apart from meeting all control objectives, this avoids the unnecessary ECU overload resulting from always sampling at a constant, higher rate.
Dip Goswami, Alejandro Masrur, Reinhard Schneider 0001, Chun Jason Xue, Samarjit Chakraborty
DATE2
2013 Compositional analysis of switched ethernet topologies
abstract
In this paper we study distributed automotive control applications whose tasks are mapped onto different ECUs communicating via a switched Ethernet network. As traditional automotive communication buses like CAN, FlexRay, LIN and MOST are gradually reaching their performance limits because of the increasing complexity of automotive architectures and applications, Ethernet-based in-vehicle communication systems have attracted a lot of attention in recent times. However, currently there is very little work on systematic timing analysis for Ethernet which is important for its deployment in safety-critical scenarios like in an automotive architecture. In this work, we propose a compositional timing analysis technique that takes various features of switched Ethernet into account like network topology, frame priorities, communication delay, memory requirement on switches, performance, etc. Such an analysis technique is particularly suitable during early design phases of automotive architectures and control software deployment. We demonstrate its use in analyzing mixed-criticality traffic patterns consisting of messages from performance-oriented control loops and timing-sensitive real-time tasks. We further evaluate the tightness of the obtained analytical bounds with an OMNeT++ based network simulation environment, which involves long simulation time and does not provide formal guarantees.
Reinhard Schneider 0001, Licong Zhang, Dip Goswami, Alejandro Masrur, Samarjit Chakraborty
DATE4
2013 Multi-layered scheduling of mixed-criticality cyber-physical systems
Reinhard Schneider 0001, Dip Goswami, Alejandro Masrur, Martin Becker 0001, Samarjit Chakraborty
J. Syst. Archit.3
2012 Timing analysis of cyber-physical applications for hybrid communication protocols
abstract
Many cyber-physical systems consist of a collection of control loops implemented on multiple electronic control units (ECUs) communicating via buses such as FlexRay. Such buses support hybrid communication protocols consisting of a mix of time- and event-triggered slots. The time-triggered slots may be perfectly synchronized to the ECUs and hence result in zero communication delay, while the event-triggered slots are arbitrated using a priority-based policy and hence messages mapped onto them can suffer non-negligible delays. In this paper, we study a switching scheme where control messages are dynamically scheduled between the time-triggered and the event-triggered slots. This allows more efficient use of time-triggered slots which are often scarce and therefore should be used sparingly. Our focus is to perform a schedulability analysis for this setup, i.e., in the event of an external disturbance, can a message be switched from an event-triggered to a time-triggered slot within a specified deadline? We show that this analysis can check whether desired control performance objectives may be satisfied, with a limited number of time-triggered slots being used.
Alejandro Masrur, Dip Goswami, Samarjit Chakraborty, Jian-Jia Chen, Anuradha M. Annaswamy, Ansuman Banerjee
DATE1
2012 QoC-oriented efficient schedule synthesis for mixed-criticality cyber-physical systems
Reinhard Schneider 0001, Dip Goswami, Alejandro Masrur, Samarjit Chakraborty
FDL3
2012 Schedulability Analysis for Processors with Aging-Aware Autonomic Frequency Scaling
abstract
With the rapid progress in semiconductor technology and the shrinking of device geometries, the resulting processors are increasingly becoming prone to effects like aging and soft errors. As a processor ages, its electrical characteristics degrade, i.e., the switching times of its transistors increase. Hence, the processor cannot continue error-free operation at the same clock frequency and/or voltage for which it was originally designed. In order to mitigate such effects, recent research proposes to equip processors with special circuitry that automatically adapts its clock frequency in response to changes in its circuit-level timing properties (arising from changes in its electrical characteristics). From the point of view of tasks running on these processors, such autonomic frequency scaling(AFS) processors become slower as they gradually age. This leads to additional execution delay for tasks, which needs to be analyzed carefully, particularly in the context of hard real time or safety-critical systems. Hence, for real-time systems based on AFS processors, the associated schedulability analysis should be aging-aware which is a relatively unexplored topic so far. In this paper we propose a schedulability analysis framework that accounts such aging-induced degradation and changes in timing properties of the processor, when designing hard real-time systems. In particular, we address the schedulability and task mapping problem by taking a lifetime constraint of the system into account. In other words, the system should be designed to be fully operational (i.e., meet all deadlines) till a given minimum period of time (i.e., its lifetime). The proposed framework is based on an aging model of the processor which we discuss in detail. In addition to studying the effects of aging on the schedulability of real-time tasks, we also discuss its impact on task mapping and resource dimensioning.
Alejandro Masrur, Philipp H. Kindt, Martin Becker 0001, Samarjit Chakraborty, Veit Kleeberger, Martin Barke, Ulf Schlichtmann
RTCSA1
2011 Near-Optimal Constant-Time Admission Control for DM Tasks via Non-uniform Approximations
abstract
Admission control decisions involve determining whether a new task can be accepted by a running system such that the new task and the already running tasks all meet their deadlines. Since such decisions need to be taken on-line, there is a strong interest in developing fast and yet accurate algorithms for different setups. In this paper, we propose a constant-time admission control test for tasks that are scheduled under the Deadline Monotonic (DM) policy. The proposed test approximates the execution demand of DM tasks using a configurable number of linear segments. The more segments are used, the higher the running time of the test. However, a small number of segments normally suffice for a near-optimal admission control. The main innovation introduced by our test is that approximation segments are distributed in a non-uniform manner. We can concentrate more segments for approximating critical parts of the execution demand and reduce the number of segments where this does not change significantly. In particular, the tasks with shorter deadlines dominate the worst-case response time under DM and, hence, these should be approximated more accurately for a better performance of the algorithm. In contrast to other constant-time tests based on well-known techniques from the literature, our algorithm is remarkably less pessimistic and allows accepting a much greater number of tasks. We evaluate this through detailed experiments based on a large number of synthetic tasks and a case study.
Alejandro Masrur, Samarjit Chakraborty
IEEE Real-Time and Embedded Technology and Applications Symposium1
2010 Constant-time admission control for Deadline Monotonic tasks
abstract
The admission control problem is concerned with determining whether a new task may be accepted by a system consisting of a set of running tasks, such that the already admitted and the new task are all schedulable. Clearly, admission control decisions are to be taken on-line, and hence, this constitutes a general problem that arises in many real-time and embedded systems. As a result, there has always been a strong interest in developing efficient admission control algorithms for various setups. In this paper, we propose a novel constant-time admission control test for the Deadline Monotonic (DM) policy, i.e., the time taken by the test does not depend on the number of admitted tasks currently in the system. While it is possible to adapt known utilization bounds from the literature to derive constant-time admission control tests (e.g., the Liu and Layland bound, or the more recent hyperbolic bound), the test we propose is less pessimistic. We illustrate this analytically where possible and through a set of detailed experiments. Apart from the practical relevance of the proposed test in the specific context of DM tasks, the underlying technique is general enough and can possibly be extended to other scheduling policies as well.
Alejandro Masrur, Samarjit Chakraborty, Georg Färber
DATE1
2010 Constant-Time Admission Control for Partitioned EDF
abstract
An admission control test is responsible for deciding whether a new task may be accepted by a set of running tasks, such that the already admitted and the new task are all schedulable. Admission control decisions have to betaken on-line and, hence, there is a strong interest in developing efficient algorithms for different setups. In this paper, we propose a novel constant-time admission control test for tasks scheduled on identical processors under partitioned Earliest Deadline First (EDF), i.e., once tasks have been assigned to a processor they remain on that processor. In particular, to model demanding real-time systems, we consider the case where relative deadlines may be less than the minimum separation between two consecutive task activations or jobs. The main advantage of the proposed test is that the time it takes is independent of the number of tasks currently admitted in the system. While it is possible to adapt polynomial-time schedulability tests from the literature to design a linear or even constant-time admission control for this setup, the test we propose provides a better accuracy/complexity ratio. We evaluate this test through a set of detailed experiments based on synthetic tasks and a realistic case study consisting of a real-time multimedia server.
Alejandro Masrur, Samarjit Chakraborty, Georg Färber
ECRTS1
2010 VM-Based Real-Time Services for Automotive Control Applications
abstract
Techniques for hardware virtualization have been successfully used to provide hardware-independent services and increase isolation between applications in the desktop domain. However, these characteristics make hardware virtualization also interesting for other domains like those involving control tasks. Since these techniques were initially not conceived for this kind of environments where, in particular, timing constraints must be guaranteed, it is necessary to analyze their behavior and investigate the viability of possible solutions based on them. In this paper, we are concerned with using VMs (Virtual Machines) to provide real-time services in the context of automotive control applications. For this purpose, we make use of the Xen hyper visor to design a real-time control loop on the top of a virtualization layer. We first analyze a typical Xen configuration and identify problems that arise when it is used for real-time applications. We show that the worst-case performance of Xen's standard SEDF scheduler (Simple Earliest Deadline First) can be improved by incorporating some minimal modifications. In addition, in order to reduce latency and jitter in a real-time control loop, we propose a new scheduler for the Xen hyper visor that uses the concept of a real-time VM. Real-time VMs are then scheduled before any other VM and under a fixed-priority policy. The proposed VM-based solution is shown to guarantee timing constraints typically encountered in automotive control applications. We further illustrate this through an extensive set of experiments.
Alejandro Masrur, Sebastian Drössler, Thomas Pfeuffer, Samarjit Chakraborty
RTCSA1
2010 High-level timing analysis of concurrent applications on MPSoC platforms using memory-aware trace-driven simulations
abstract
Due to the growing complexity of multiprocessor systems-on-chip (MPSoCs), there is an increasing demand on efficient design space exploration techniques. In addition to the analysis of diverse hardware architectures, these techniques should assist the designer in the flexible evaluation of various scheduling policies and application mappings while taking effects of the shared on-chip communication infrastructure into account. Most available simulation approaches are either unable to cover all these aspects jointly or have poor simulation performance. In this paper, we present a framework for timing analysis of MPSoC architectures using abstract and yet accurate traces. The traces capture both precise processing latencies and memory access patterns and represent application- and OS-related workload. Performance estimation is performed by an interleaved execution of the traces on a highly configurable multiprocessor platform modeled in our trace-driven SystemC TLM simulator. Using the flexible scheduler model presented in this paper, various mappings and scheduling policies can be rapidly evaluated while considering on-chip interconnect contention and usage of shared resources. Due to the abstraction of the trace-driven simulations, the proposed framework allows for both fast and accurate explorations of MPSoC design alternatives.
Roman Plyaskin, Alejandro Masrur, Martin Geier 0001, Samarjit Chakraborty, Andreas Herkersdorf
VLSI-SoC2
2008 Improvements in Polynomial-Time Feasibility Testing for EDF
abstract
This paper presents two fully polynomial-time sufficient feasibility tests for EDF when considering periodic tasks with arbitrary deadlines and preemptive scheduling on uniprocessors. Both proposed methods are proven, analytically and by means of an extensive experimental comparison, to be more accurate than known polynomial-time feasibility tests. Additionally, we show for a wide interval of practical processor utilization that one of these methods presents almost the same efficiency, in terms of accepted task sets, as the more complex pseudo-polynomial-time exact feasibility tests.
Alejandro Masrur, Sebastian Drössler, Georg Färber
DATE1