Roman Obermaisser

dblp:64/1102 · DBLP profile ↗
← Back
104ranked-venue papers
13as first author
29since 2021 · last 2026
0009-0002-4483-1503ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 65 · 5 first-author · 19 since 2021Applied, interdisciplinary, general and emerging computing · 13 · 3 first-author · 6 since 2021Software engineering, systems software and programming languages · 9 · 1 first-author · 6 since 2021Artificial intelligence and machine learning · 3 · 2 since 2021Computer networks · 3 · 2 since 2021Human-computer interaction and ubiquitous computing · 3 · 3 since 2021Security and privacy · 2 · 1 first-authorGraphics, computer vision, multimedia, augmented reality and games · 2 · 1 since 2021
YearPublicationVenuePosition
2026 Governance-Aligned Architectures for Knowledge-Graph-Grounded Automated Question Generation
Constance Jumbo, Roman Obermaisser
CSEDU (3)2
2026 Automated Bitstream-Level Cost-Reliability Design-Space Exploration for SRAM-Based FPGAs
abstract
Triple Modular Redundancy (TMR) is a common approach to mitigate the effects of Single-Event Upsets (SEUs) in SRAM-based Field-Programmable Gate Arrays (FPGAs), where these faults may cause changes in the configuration of logic or interconnect resources. Partial TMR aims at balancing SEU mitigation with redundancy costs. This work introduces a Design-Space Exploration (DSE) approach that automatically generates and evaluates cost-reliability-optimized, Pareto-optimal partial TMR configurations of modules in a hierarchical design. The approach is evaluated using a proof-of-concept implementation for AMD’s 7 Series FPGAs and five case-study designs, including the NEORV32 RISC-V CPU. Multiple fitness assignment variants – based on static bitstream analysis, (statistical) fault injection results, and a combined approach –-are compared regarding effectiveness and runtime. Comparing the hypervolumes of the generated Pareto fronts of the final generation and a randomly generated starting generation, the approach improves cost-effectiveness of the generated TMR solutions by 17%–52%, delivering an attractive benefit-cost-ratio. The presented approach effectively generates a diverse set of TMR solutions across a wide cost-reliability range, allowing the designer to choose a variant that best fulfills the application’s, mission’s, or mission phase’s cost-reliability requirements.
Christian Fibich, Martin Horauer, Roman Obermaisser
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst.3
2025 Generalised Skin Cancer Detection using Transfer Learning for Real-world Scenarios
abstract
Skin cancer has been recognised as a significant global health concern, with millions of cases diagnosed annually. Early detection, particularly for melanoma, has improved survival rates. In recent years, artificial intelligence (AI) techniques have gained attention in skin cancer classification and have shown potential for automated skin cancer diagnosis. However, the research mainly uses dermoscopic or macroscopic images for AI model training. This research addresses these limitations by developing a generalised deep learning model that integrates dermoscopic and macroscopic image datasets, utilising transfer learning with VGG16 to enhance accuracy and accessibility. The model is designed to generalise features from the macroscopic and dermoscopic perspective, making skin cancer diagnosis more scalable. The model was trained and tested on two diverse datasets, including HAM10000 [15] and PAD-UFES-20 [14], ensuring adaptability to clinical settings and patient populations. We achieved an average Receiver Operating Characteristic Area Under the Curve (ROC AUC) score of 0.97, which indicates a good performance of the classifier. Furthermore, we also test the model in the real-time data application by testing the model’s ability to classify the lesion from a web-camera stream for real-world scenarios.
Mohamed Dwedar, Fatima Mammadova, Daniel Onwuchekwa, Roman Obermaisser
CoDIT4
2025 Memory Optimization for Adaptive Time-Triggered Systems
abstract
Adaptation is crucial in time-triggered systems for maintaining system performance and reliability under varying conditions, such as dynamic workloads or resource failures. Time-triggered systems rely on metascheduling techniques for adaptation; however, utilizing existing metascheduling schemes for time-triggered systems faces storage challenges for adaptation using the resulting schedules. This work presents a Genetic Algorithm (GA)-based metascheduler to tackle the state explosion problem in time-triggered systems. Our proposed method is designed to optimize meeting the application deadline and memory utilization by employing a Multi-Objective Genetic Algorithm (MOGA). Meeting the deadlines is crucial for safety-critical applications. Additionally, minimizing the schedule changes after a context event reduces the memory overhead. We leverage the similarity between successive schedules to store schedules incrementally, retaining only the differences between parent and child schedules. This approach significantly reduces redundant data storage and helps mitigate the state explosion problem. Comparative experiments demonstrate that our MOGA-based metascheduler achieves up to 90% memory savings, outperforming a makespan-optimized metascheduler and a metascheduler optimizing the lateness in a scenario with twenty-two context events. These results highlight the potential of our approach in enhancing the scalability and efficiency of metascheduling techniques in memory-coznstrained environments.
Omar Hekal, Daniel Onwuchekwa, Roman Obermaisser
CoDIT3
2025 LLM-Assisted Knowledge Graph Completion for Curriculum and Domain Modelling in Personalized Higher Education Recommendations
abstract
While learning personalization offers great potential for learners, modern practices in higher education require a deeper consideration of domain models and learning contexts, to develop effective personalization algorithms. This paper introduces an innovative approach to higher education curriculum modelling that utilizes large language models (LLMs) for knowledge graph (KG) completion, with the goal of creating personalized learning-path recommendations. Our research focuses on modelling university subjects and linking their topics to corresponding domain models, enabling the integration of learning modules from different faculties and institutions in the student's learning path. Central to our approach is a collaborative process, where LLMs assist human experts in extracting high-quality, fine-grained topics from lecture materials. We develop a domain, curriculum, and user models for university modules and stakeholders. We implement this model to create the KG from two study modules: Embedded Systems and Development of Embedded Systems Using FPGA. The resulting KG structures the curriculum and links it to the domain models. We evaluate our approach through qualitative expert feedback and quantitative graph quality metrics. Domain experts validated the relevance and accuracy of the model, while the graph quality metrics measured the structural properties of our KG. Our results show that the LLM-assisted graph completion approach enhances the ability to connect related courses across disciplines to personalize the learning experience. Expert feedback also showed high acceptance of the proposed collaborative approach for concept extraction and classification.
Hasan Abu-Rasheed, Constance Jumbo, Rashed Al Amin, Christian Weber 0003, Veit Wiese, Roman Obermaisser, Madjid Fathi
EDUCON6
2025 Requirement Analysis and Didactic Evaluation of a Collaborative Remote Laboratory for FPGAs
abstract
Field-Programmable Gate Arrays (FPGAs) have received significant attention in academic and industrial research due to their reconfigurability, power efficiency, and ability for real-time high-performance computation. The growing demand for FPGA-based systems across various applications has necessitated the development of robust design and verification platforms to support academic and research objectives. In pursuit of this long-term goal, numerous FPGA-based remote laboratory platforms have been proposed, emphasizing didactic needs. However, more attention must be paid to requirement analysis and evaluation criteria specific to FPGA-based remote laboratory platforms. This paper addresses this gap by investigating state-of-the-art remote laboratory platforms alongside a comprehensive requirement analysis. A didactic evaluation has been conducted to assess qualitative and quantitative data to effectively align requirements with outcomes, providing insights into students' perceptions of the platform and its efficacy in meeting learning objectives. Furthermore, the evaluation highlights students' engagement with laboratory tasks across different time intervals throughout the day. However, this requirement analysis and evaluation serve as a foundation for effectively designing an efficient FPGA design and verification platform, fostering enhanced learning experiences in remote laboratory settings.
Rashed Al Amin, Veit Wiese, Sven Jacobs, Timo Hardebusch, Steffen Jaschke, Roman Obermaisser
EDUCON6
2025 Enhanced Drift-Aware Computer Vision Architecture for Autonomous Driving
abstract
The use of computer vision in automotive is a trending research in which safety and security are a primary concern. In particular, for autonomous driving, preventing road accidents requires highly accurate object detection under diverse conditions. To address this issue, recently the International Organization for Standardization (ISO) released the 8800 norm, providing structured frameworks for managing associated AI relevant risks. However, challenging scenarios such as adverse weather or low lighting often introduce data drift, leading to degraded model performance and potential safety violations. In this work, we present a novel hybrid computer vision architecture trained with thousands of synthetic image data from the road environment to improve robustness in unseen drifted environments. Our dual mode framework utilized YOLO version 8 for swift detection and incorporated a five-layer CNN for verification. The system functioned in sequence and improved the detection accuracy by more than 90% when tested with drift-augmented road images. The focus was to demonstrate how such a hybrid model can provide better road safety when working together in a hybrid structure.
Md Shahi Amran Hossain, Abu Shad Ahammed, Sayeri Mukherjee, Roman Obermaisser
IECON4
2025 Enhancing Hydrogen Energy Management with a TSN-Driven Scalable Smart Grid Architecture
abstract
The integration of renewable energy and hydrogen-based systems into smart grids requires a robust and determonistic communication infrastructure. This study presents a Time-Sensitive Network (TSN)-based smart grid architecture to facilitate secure and real-time data exchange between decentralized energy producers, storage units, and consumers. The proposed framework incorporates key TSN mechanisms, including IEEE 802.1AS (time synchronization), IEEE 802.1Qbv (traffic shaping), and IEEE 802.1CB (fault tolerance), to ensure reliable operation in dynamic energy environments. This work evaluates the feasibility of the proposed architecture through theoretical analysis and system modeling as an initial step. Key challenges such as network resilience, compliance with IEC 61508, and interoperability with existing industrial energy infrastructures are examined. Future research will focus on practical validation through fault injection experiments and Hardware-in-the-Loop (HIL) testing. The results contribute to developing a scalable and standardized TSN-based smart grid architecture that supports the transition to hydrogen-powered industrial energy systems.
Veit Wiese, Rashed Al Amin, Roman Obermaisser
IECON3
2025 A Computer Vision Approach for Autonomous Cars to Drive Safe at Construction Zone
abstract
To build a smarter and safer city, a secure, efficient, and sustainable transportation system is a key requirement. The autonomous driving system (ADS) plays an important role in the development of smart transportation and is considered one of the major challenges facing the automotive sector in recent decades. A car equipped with an autonomous driving system (ADS) comes with various cutting-edge functionalities such as adaptive cruise control, collision alerts, automated parking, and more. A primary area of research within ADAS involves identifying road obstacles in construction zones regardless of the driving environment. This paper presents an innovative and highly accurate road obstacle detection model utilizing computer vision technology that can be activated in construction zones and functions under diverse drift conditions, ultimately contributing to build a safer road transportation system. The model developed with the YOLO framework achieved a mean average precision exceeding 94% and demonstrated an inference time of 1.6 milliseconds on the validation dataset, underscoring the robustness of the methodology applied to mitigate hazards and risks for autonomous vehicles.
Abu Shad Ahammed, Md Shahi Amran Hossain, Roman Obermaisser
IPAS3
2025 Superscalar Time-Triggered Versatile-Tensor Accelerator
abstract
Integrating AI hardware accelerators into safety-critical real-time systems to speed up the inference execution of safety-critical AI applications demands rigorous assurance to prevent potentially catastrophic outcomes, especially in environments where timely and accurate results are crucial. Even in cases where AI models are potentially designed and constructed correctly using AI frameworks, the systems safety will also rely on the real-time behavior of the AI hardware accelerator. While AI hardware accelerators can achieve the necessary throughput, conventional accelerators such as the Versatile Tensor Accelerator (VTA) encounter significant challenges in predictability and reliability. These challenges stem from the variability in event-driven inference execution and insufficient timing control, posing considerable risks in safety-critical scenarios where delays in providing inference results can have severe consequences. To address this challenge, previous work introduced the Time-Triggered Versatile Tensor Accelerator (TT-VTA) to ensure timely execution of tensor operations. Nonetheless, the TTVTA exhibited a slightly longer average inference time of 53ms compared to the conventional VTAs 51ms, underscoring the ongoing need for optimization in this crucial domain to speed up the inference execution, while sustaining the deterministic and predictable behavior of the TT-VTA. This paper proposes a novel Superscalar Time-Triggered VTA (STT-VTA) architecture specifically designed to address the deficiencies of conventional VTAs and TT-VTAs. The STT-VTA architecture employs pattern-based timing schedules generated by an extended software simulator and an architecture configuration manager to analyze tensor operations within a given AI model and determine the required number of additional VTA modules for faster inference than a single (TT-)VTA setup. It integrates DRAMSim2 for memory instructions and a cycle-accurate simulator for non-memory instructions. Evaluation using various models demonstrates that the STT-VTA achieves identical classification accuracy as the conventional VTA and TT-VTA, while improving performance and reducing inference time by 20-41%. Moreover, it ensures deterministic temporal use of shared resources such as memories and memory-buses and precise timing control to avoid interference. These results contribute towards safety and reliability of AI systems deployed in a safety-critical environment
Yosab Bebawy, Aniebiet Micheal Ezekiel, Roman Obermaisser
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst.3
2024 Enhancing Neural Network Predictability through Simulation-Based Analysis of Memory Accesses for Time-Triggered Tensor Acceleration
abstract
This paper introduces an innovative simulation-based analysis and optimizing technique for managing memory access in neural network deployment, specifically focusing on the Versatile Tensor Accelerator (VTA). Our work addresses critical issues and challenges in memory access involving inefficient resource utilization, resource contention, memory collisions, unpredictable memory access, and erratic behavior, which are detrimental to safety-critical applications. These challenges underscore the need to not only eliminate memory contention but also improve memory throughput and efficiently utilize memory access idle phases while ensuring deterministic execution. Our proposed techniques aim to enhance the safety and predictability of neural networks by offering a schedule guaranteeing timing while significantly improving memory access efficiency. Our approach strategically leverages idle zones for prefetching data, achieving 5% overall time savings in memory execution. Evaluated on the simulation testbench, this advancement paves the way for further hardware integration with a time-triggered controller, optimizing memory access across diverse neural network architectures. This advancement represents progress towards a safer, more predictable, and more efficient neural network memory access architecture for applications in safety-critical domains.
Aniebiet Micheal Ezekiel, Yosab Bebawy, Roman Obermaisser
CoDIT3
2024 Time-Triggered Inference on FPGAs
abstract
Safety-critical AI systems demand the utmost reliability to prevent catastrophic outcomes. However, conventional AI hardware accelerators, such as the Versatile Tensor Accelerator (VTA), suffer from limitations in predictability and reliability due to inherent variability in event-driven task execution and the lack of precise timing control. These limitations make them unsuitable for safety-critical applications where erroneous or untimely operations could lead to catastrophic consequences. This paper proposes a novel time-triggered VTA (TT-VTA) architecture specifically designed to address the shortcomings of conventional VTAs and enhance safety and reliability in safety-critical AI systems. The TT-VTA architecture utilizes pattern-based timing schedules which are generated by a software simulator that integrates DRAMSim2 to simulate memory-related instructions as well as by a cycle-accurate simulator to provide accurate cycle counts for non-memory-related instructions. A comparative evaluation using a ResNet18 classification model demonstrates that the TT-VTA achieves identical classification accuracy while maintaining deterministic resource utilization and enabling precise timing control. Our proposed TT-VTA architecture demonstrates significant promise for enhancing the safety and reliability of AI systems in safety-critical applications.
Yosab Bebawy, Michael Schmidt 0014, Hamidreza Ahmadian, Aniebiet Micheal Ezekiel, Roman Obermaisser
ETFA5
2024 Discrete-Event Co-Simulation Interface for Time-Triggered Organic Computing
abstract
In response to the increasing complexity of distributed embedded systems, self-organizing systems have emerged. One such system is organic computing, which draws inspiration from biological organisms. It improves the adaptability and robustness of distributed embedded systems by allocating tasks to computing nodes on demand. However, this approach has drawbacks in terms of determinism and dependability. To address these limitations, time-triggered communication concepts have been incorporated to form a time-triggered organic computing architecture (TTOC). Herein, task executions and message communications are predefined by a table schedule based on a list scheduler. The schedule table, i.e., the order in which application tasks get executed, has been validated by a previously introduced TTOC simulator. The next step towards a real-world usage of TTOC is a discrete-event simulator that includes the simulation of actual time-triggered communication protocols such as TSN. OMNeT++ provides such discrete-event simulations. Both the TTOC simulator and OMNeT++ are discrete-event simulators. Consequently, this paper presents a discrete-event-based co-simulation interface that can control the execution of the TTOC simulator and OMNeT++.
Mario Qosja, Simon Meckel, Roman Obermaisser
IS3
2023 Bitstream- Level Interconnect Fault Characterization for SRAM-based FPGAs
abstract
A significant portion of the configuration memory of modern SRAM-based FPGAs is dedicated to configuring the interconnect. Understanding the effects of interconnect-related Single-Event Upsets (SEUs) on the circuit's behavior is critical for developing accurate reliability prediction and efficient fault mitigation approaches. This work describes an approach to classify the effects of single-bit interconnect faults into well-known fault models, and to characterize the electrical effects of these modeled faults. An experimental fault characterization for two families of Xilinx and Lattice FPGAs shows that different types of single-bit interconnect faults exhibit significantly different criticality. This may serve as a partial explanation for the large discrepancies reported in literature between faults predicted to be critical by state-of-the-art methods (“essential bits”) compared to the numbers of actually critical bits determined experimentally and may be used to improve prediction accuracy or reliability-aware routing approaches.
Christian Fibich, Martin Horauer, Roman Obermaisser
DATE3
2023 Characterization of Interconnect Fault Effects in SRAM-based FPGAs
abstract
The configurable interconnect of SRAM-based FPGAs makes up a significant portion of their configuration, and thus exposes a large attack surface to single-event upsets. A better understanding of the behavior of FPGA interconnects under the presence of these faults may allow fault injection campaigns and reliability estimation techniques to treat some interconnect faults as more serious than others. This work proposes an approach to (1) analyze the interconnect configuration of a given FPGA technology to deduce the logical effects caused by single-bit flips and (2) to characterize the effects of such faults on routes implemented on a given FPGA technology. These approaches are illustrated in case studies on two FPGA technologies: Xilinx 7 Series and Lattice iCE40. Characterization of interconnect faults on these devices revealed that certain subcategories of interconnect fault types are far more critical than others, allowing more focused fault injection campaigns. Applying this knowledge to three benchmark designs implemented on a Xilinx 7 Series device shows that fault injection effort can be significantly reduced by skipping bits that are unlikely to critically impact the design.
Christian Fibich, Martin Horauer, Roman Obermaisser
DDECS3
2023 Verifying Bio-Electronic Systems
abstract
The functional safety of implanted medical devices is of high importance. This works presents a novel concept to verify bio-electronic systems modeling the medical device in connection with the interacting biological system. The concept is applied to a setup consisting of an implanted pacemaker and an interacting organ, the human heart. The resulting model is verified with respect to relevant properties such as the reachability of hazard-related states appearing through the interaction of the bio-electronic system. In contrast to previous contributions this work demonstrates the ability to deterministicly verify bio-electronic systems containing relevant and detailed models of the interacting biological system.
Joseline Heuer, Rene Krenz-Baath, Roman Obermaisser
DDECS3
2023 Optimization of the Versatile Tensor Accelerator (VTA) Load Module in a Time-Triggered Memory Access
abstract
Embedded systems powered by artificial intelligence (AI) are widely employed in diverse domains. However, the lack of inherent predictability in existing AI accelerators poses significant challenges, especially in safety-critical applications where deterministic safety specifications are essential. Moreover, temporal unpredictability caused by memory access contention further hinders the suitability of current platforms for safety-critical tasks. To address these issues, we propose a time-triggered memory access approach for the versatile tensor accelerator (VTA) that provides temporal predictability guarantees for load data. Our research focuses on investigating the temporal predictability of Neural Network load input, weight, and operations. We introduce a time-triggered memory access mechanism that pre-fetches data from DDR memory ahead of the VTA load module request. Through extensive experimentation and analytical evaluations in the VTA runtime environment, we demonstrate the effectiveness of our time-triggered memory access concept. The results reveal an 8% performance improvement and reduced execution time while upholding strict safety specifications and predictability. These findings establish the feasibility of employing a time-triggered approach for runtime neural network prediction.
Aniebiet Micheal Ezekiel, Daniel Onwuchekwa, Roman Obermaisser
DSD3
2023 Fault-Tolerant Lightweight High Level Architecture
abstract
This research presents a fault-tolerant distributed Run-Time Infrastructure (RTI) using the High-Level Architecture (HLA) standard, emphasizing its importance for safety-critical use cases such as automotive systems. In this context, HLA serves as an enabler for hardware-in-the-loop testing, particularly vehicle-in-the-loop testing. Ensuring system reliability, managing real-time responses, facilitating seamless integration and interoperability of various components, effectively handling potential component failures, and maintaining the scalability of complex systems is paramount. Furthermore, the ability to comply with stringent safety regulations also underlines the necessity for safety mechanisms. These safety measures are crucial in protecting users and ensuring dependable system performance, particularly in safety-critical automotive applications where user safety is paramount. The study develops a fault-tolerant distributed RTI, validates it with an automotive use case, and provides a comparative assessment of centralized and distributed HLA implementations. The findings offer insight into large-scale distributed simulations' efficiency, dependability, and safety in various safety-critical applications.
Daniel Onwuchekwa, Krishi Savla, Devika Joshi, Roman Obermaisser, Tobias Pieper
DSD4
2023 Metascheduling Using Discrete Particle Swarm Optimization for Fault Tolerance in Time-Triggered IoT-WSN
abstract
In time-triggered systems, adaptation is performed by using metascheduling approaches to ensure temporal predictability. Wireless sensor networks (WSNs) are growing to be used as a reliable, an energy-efficient, and a scalable network infrastructure for numerous Internet of Things (IoT) applications. Because of run-time changes because of failure events, a metascheduling system is required to address the changes by precomputing schedules for several context events at design time. Therefore, this paper proposes a metascheduler that solves a new scheduling problem for each adaptation scenario in IoT-WSN using our offline algorithm named discrete particle swarm optimization for reliable task allocation (DPSO-TA), resulting in a multi-schedule graph that combines the repeated schedules. In this work, a time-triggered IoT-WSN metascheduler is proposed that takes into considerations the node or link failures that are common in WSN. Single and two failure events are considered, where a graph for all feasible schedules is formed at the network design time. Such a large number of schedules causes a state space explosion problem, which is managed using a re-convergence method. Different application model sizes and network topologies are used to assess the proposed metascheduler under various failure event scenarios. The results show a reduction in the size of the multi-schedule graph by applying inputs with different deadline values and different number of tasks. Furthermore, the validity suggested by the proposed metascheduler, which is the ratio of valid to invalid schedules, is improved when compared to algorithms that schedule tasks to hosts with the shortest completion time or algorithms that select hosts for a set of sorted tasks based on energy consumed and task arrival time.
Haytham Baniabdelghany, Roman Obermaisser, Alá F. Khalifeh, Pascal Muoka
IEEE Internet Things J.2
2022 Graph Neural Networks Based Meta-scheduling in Adaptive Time-Triggered Systems
abstract
Meta-scheduling algorithms are used for adaptation in time-triggered systems as they adapt to different scenarios such as failures or different environmental conditions. Most meta-scheduling algorithms demand a considerable amount of storage space from the host cyber-physical system due to the state-space explosion problem in covering a reasonable number of scenarios. This work deploys the Graph Neural Network (GNN) to learn the multi-schedules from the meta-scheduling algorithm required for adaptation. The GNN is used to learn the scheduling mechanism of a Genetic Algorithm (GA) so that at runtime, adaptation is achieved using the GNN model. We further investigate the impact of modifiable tasks during a meta-scheduling operation on the overall makespan. Finally, a comparison of the makespans is made between a List Scheduler (LS), GA and the proposed GNN-based technique to evaluate the impact of our approach. Our proposed GNN-based approach outperforms the LS scheduler as the number of modifiable tasks increases. The results show that the proposed GNN-based meta-scheduling can be suitable for real-time scenario adaptation in cyber-physical systems.
Samer Alshaer, Carlos Lua, Pascal Muoka, Daniel Onwuchekwa, Roman Obermaisser
ETFA5
2022 Detection of Respiratory Emergency Situation of Rescue Patients with Machine Learning Algorithms
abstract
Respiratory complications are quite common to the rescue personnel and often require urgent medical intervention to save an emergency patient. During a rescue mission, based on health vitals, patient’s medical history and first responder’s primary impression, a disease is diagnosed to provide first aid. In this paper, we present a detection model developed with machine learning that can help to make a quick diagnosis of respiratory complications and reduce human error in rescue operation. Current methods are mostly focused on detecting selected respiratory diseases from clinically recorded data or long term historical patients’ data. Here we introduce a novel approach of detecting respiratory complications in general instead of focusing on one complication with 9 years of historical data of a rescue station using machine learning based classifiers e.g Support vector machine(SVM), K-Nearest Neighbor(KNN), Gradient Boosting(GB), Extreme Gradient Boosting(XGB) and Random Forest. Additionally, a performance comparison of these algorithms is shown to identify the best detector. Of all the classifiers implementation, the highest detection accuracy was found with support vector machine and boosting algorithms with 91% using 15 attributes; including patient’s real health symptoms, demographic information and primary diagnosis. The outcome of this research presented in the paper can be used by rescue employees worldwide to detect a respiratory situation and save the life of a patient without any delay.
Abu Shad Ahammed, Sampada Reddy Donthireddy, Roman Obermaisser
IECON3
2022 Design and Evaluation of Guided Wave Signal Generation for System-On-Chip Platform on FPGA
abstract
The subsequent structural health monitoring plays an essential role in system health management applications for buildings, power plants, aircraft, and railways. This paper designs and evaluates a high-precision signal generator based on field programmable gate arrays (FPGA) for guided waves to be used in ultrasonic systems for the structural health monitoring (SHM) domain. A system model of the signal generator is designed by StarUML and implemented in Xilinx Vivado. The design and implementation are based on the Zynq 7010 system-on-Chip (SoC) integrated on the evaluation board RedPitaya. However, the designed architecture is represented in detail, showing the functionality of the implemented VHDL hardware modules. For better evaluation, generated signal by RedPitaya with the calculated signal in MATLAB and generated signal on the Handyscope HS6 are compared. Through theoretical analysis and experimental verification, the test results demonstrate that the FPGA-based signal generator can generate the required excitation signal for ultrasonic guided wave and this signal can accomplish the system’s purposes.
Veit Wiese, Rashed Al Amin, Roman Obermaisser
IECON3
2022 In-Circuit Debugger for Wireless Real-Time Monitoring and Diagnosis of FPGA Applications
abstract
As the level of System-on-Chip (SoC) based embedded systems complexity continues to enlarge, the post-silicon validation stage contributes a major part of the entire development cost. Due to precipitous design complexity, it is nearly unattainable to detect and fix all design errors during the design phase. This paper presents a solution to resolve this problem with the help of a novel In-Circuit Debugger (ICD), which aims to enhance the post-production validation process by enabling observation and control of internal signals, such as input and output signals of safety critical systems. The ICD is an efficient technique for monitoring and verification of on-chip IP-cores. This paper proposes a novel system debugging technique and explains how it differs from existing techniques. Moreover, various use cases of ICD are also discussed in detail.
Veit Wiese, Michael Schmidt 0014, Darshak Sheladiya, Roman Obermaisser
IECON4
2022 Reliable Task Allocation for Time-Triggered IoT-WSN Using Discrete Particle Swarm Optimization
abstract
A wireless sensor network (WSN) constitutes of nodes that are used to sense a certain physical environment phenomena and sends these collected data to a remote node for further processing and decision making. With the proliferation of Internet of Things (IoT), WSN is evolving to be used as reliable, energy efficient, cost effective, and scalable network infrastructure for many IoT applications. To have a robust WSN with IoT (IoT-WSN), it is a challenge to allocate the tasks among different sensor nodes because the distribution of dependent tasks among wireless nodes must satisfy precedence and time constraints, minimize energy consumption, and prevent signal interference. The problem becomes more complex if a system requires high reliability in the event of link or node failures. This article presents an offline discrete particle swarm optimization algorithm for reliable task allocation (DPSO-TA) in IoT-WSN. DPSO-TA defines a utility function to optimize the task allocation problem by iteratively trying to improve the solution. The defined function is designed to satisfy goals, including saving energy, reducing task completion time, and minimizing the failure rates. A load balance mechanism is applied to make balancing of the tasks on several hosts. During the task allocation process, the frame replication and elimination for reliability (FRER) approach is used to support flow fault tolerance by replicating transmitted flows over redundant routes. DPSO-TA considers the periodicity of the time-trigged (TT) flows and applies a physical interference model to prevent signal interference on the transmitted flows through assigning them to conflict-free time slots. The analysis and simulation results show the optimization of DPSO-TA on timeliness, deadline missing ratio, failure rates, and energy efficiency comparing it with algorithms that allocate tasks to hosts that produce the minimum completion time or that use a traditional procedure to find the most suitable nodes during the task allocation process.
Haytham Baniabdelghany, Roman Obermaisser, Alá F. Khalifeh
IEEE Internet Things J.2
2021 Estimation of Linux Kernel Execution Path Uncertainty for Safety Software Test Coverage
abstract
With the advent of next-generation safety-related systems, different industries face multiple challenges in ensuring the safe operation of these systems according to traditional safety and assurance techniques. The increasing complexity that characterizes these systems hampers the maximum achievable test coverage during system verification and, consequently, it often results in untested behaviors that hinder safety assurance and represent potential risk sources during system operation. In the context of paving the way towards quantifying the risks caused by software malfunction and, hence, towards the safety-compliance of next-generation safety-related systems, this paper studies and provides a method to estimate the probability of Linux kernel execution paths that remain unobserved during the test campaign.
Imanol Allende, Nicholas Mc Guire, Jon Pérez 0001, Lisandro Gabriel Monsalve, Javier Fernández 0004, Roman Obermaisser
DATE6
2021 Device- and Temperature Dependency of Systematic Fault Injection Results in Artix-7 and iCE40 FPGAs
abstract
Systematic fault injection into the configuration memory of SRAM-based FPGAs promises to gain insight into the criticality of individual configuration bits. Current approaches implicitly assume that results obtained on one FPGA device can be generalized to all devices of that type and hence allow to parallelize fault injection. This work, to the best of our knowledge, is the first to challenge this assumption. To that end, a synthetic test design was subjected to systematic fault injection on 16 Xilinx Artix-7 as well as 10 Lattice iCE40 FPGAs for which bitstream documentation is publicly available. The results of these experiments indicate that the derived sets of critical configuration bits vary from device to device of the same type, especially if the interconnect is targeted. Furthermore, temperature is observed to influence the fault injection results on Artix-7. Suggestions for dealing with the implications in future fault injection experiments are provided.
Christian Fibich, Martin Horauer, Roman Obermaisser
DATE3
2021 Evolutionary Algorithm for Incremental Scheduling in Systems of Systems with Real-Time Requirements
abstract
Time-triggered Systems-of-Systems (SoS) promise to satisfy the real-time and dependability requirements of safety-relevant applications such as medical systems, smart manufacturing and defense systems. However, the time-triggered scheduling algorithms in the state-of-the-art were developed for monolithic systems and they do not support the requirements and constraints of SoS. Scheduling tasks and optimizing the resource allocation in SoS is more complex than in monolithic systems due to the autonomy of its constituting systems, the lack of central control, and no global information about the resources in different constituent systems.In this article, we propose a two-level interactive heuristic approach using a Genetic Algorithm (GA) to schedule real-time applications incrementally by adding them to the time-triggered SoS. We compute and deploy the schedule for each new SoS application at runtime after its arrival. Therefore, the limited communication and computational resources must be shared between different SoS applications released over time. By reducing the blocking time of shared resources, we can cope with the possible shortage of resources for future applications. Therefore, we develop a new resource allocation algorithm which creates more balance in the blocking times of shared resources and helps to satisfy future resource requests. We generate example scenarios to examine the schedulability of our new incremental scheduling algorithm. The experimental results show that the proposed optimization scheme compared to an incremental scheduler without blocking time considerations can find a better schedule for a sequence of applications.
Setareh Majidi, Roman Obermaisser
IECON2
2021 A Reliable Job Allocation Scheduler for Time-Triggered Wireless Networks
abstract
The job allocation problem is a challenging in wireless systems, because the spatial and temporal distribution of dependent jobs to hosts must satisfy the precedence constraints, prevent communication interference and minimize energy consumption. In this paper, a new scheduler called Reliable Job Allocation scheduler (RJA) is proposed to improve the reliability of realtime wireless systems. The proposed scheduler uses an approach called Frame Replication and Elimination for Reliability (FRER) to replicate the communication flows through redundant routes. RJA considers the periodicity of Time-Triggered (TT) flows and the impact of the induced interference, by applying a physical interference model which is used to ensure that all flows are transmitted successfully in the assigned time-slots. The scheduling efficiency and the system reliability are improved through allocating jobs to hosts with high performance in terms of flow arrival time, energy consumption and failure rates. A reliability model is also introduced to determine the reliability of the system. The reliability model computes the reliability of each job depending on the reliability of all its incoming flows. The reliability of the leaf job, which has no forwarding flows, presents the global reliability of the overall system. RJA is compared with state-of-the-art TT schedulers that use either the shortest or load-aware routes to send flows without addressing reliability. The experimental results show that the reliability of the system computed by RJA is improved compared to the other schedulers while also ensuring scalability in the network design (i.e. increase of the number of jobs and hosts) and timeliness. We also study the impact of the injected link failures on the flow delivery ratio.
Haytham Baniabdelghany, Roman Obermaisser, Alá F. Khalifeh
ISORC2
2021 Towards Linux based safety systems - A statistical approach for software execution path coverage
Imanol Allende, Nicholas Mc Guire, Jon Pérez 0001, Lisandro Gabriel Monsalve, Roman Obermaisser
J. Syst. Archit.5
2020 A Simple Domain Shifting Network for Generating Low Quality Images
abstract
Deep Learning systems have proven to be extremely successful for image recognition tasks for which significant amounts of training data is available, e.g., on the famous ImageNet dataset. We demonstrate that for robotics applications with cheap camera equipment, the low image quality, however, influences the classification accuracy, and freely available data bases cannot be exploited in a straight forward way to train classifiers to be used on a robot. As a solution we propose to train a network on degrading the quality images in order to mimic specific low quality imaging systems. Numerical experiments demonstrate that classification networks trained by using images produced by our quality degrading network along with the high quality images outperform classification networks trained only on high quality data when used on a real robot system, while being significantly easier to use than competing zero-shot domain adaptation techniques.
Guruprasad M. Hegde, Avinash Nittur Ramesh, Kanchana Vaishnavi Gandikota, Roman Obermaisser, Michael Möller 0001
ICPR4
2020 Time Triggered Scheduling Algorithm for Real-Time Wireless Systems
abstract
Time Sensitive Networking (TSN) is a group of standards to improve reliability, minimize jitter and ensure bounded latency by using scheduled traffic for safety critical realtime applications. Recently, the incorporation of Time-Triggered (TT) wireless technology into this kind of networked systems has been proposed because of its flexibility and easy design. Despite these benefits, the mutual interference between signals must be considered depending on the transmission intervals and the spatial proximity. Interference may prevent reception, cause the corruption of signals or affect on the signal quality. Most of the scheduling algorithms consider either the perspective of scheduling and routing restrictions, or the impact of interference on the wireless scheduling solutions. To address the interference restrictions besides the scheduling and routing restrictions, a Wireless Heuristic List Scheduler (WHLS) is proposed in this paper to determine the schedule. In this algorithm, TT messages of the computational jobs use the optimal routes with minimum latency from all available routes. In addition, the message is fragmented according to the timeslot size and assigned to several time-slots. In each time-slot all messages can be transmitted simultaneously by using a physical interference model. WHLS supports multi-cast communication while respecting the precedence constraints between computation jobs and periodicity restrictions. To evaluate the proposed scheduler, a basic List Scheduler (LS) that uses a static route (the least hop count) is implemented. The experimental results show that WHLS outperforms LS in all simulation tests, where schedulability, make span and execution time are used as parameters.
Haytham Baniabdelghany, Roman Obermaisser, Alá F. Khalifeh
INDIN2
2020 Fault-Tolerant Scheduler with Genetic Algorithm for Safety-Critical Time-Triggered Systems of Systems
abstract
A common problem in Systems of Systems (SoS) is how to effectively coordinate the Constituent Systems (CSs) to realize the emerging services of the overall system when these CSs have independent internal purposes, while also serving the overall goal of the SoS. The conflict between the individual purposes and SoS goals, make it difficult to find a good scheduling solution for the system. This situation is even complicated in safety-critical real-time SoS, where malfunctions may result in danger to the environment or humans. In this paper, we introduce a scheduler based on a two-level interactive Genetic Algorithm (GA) along with fault-tolerance techniques to satisfy the requirements of these types of systems in the presence of faults. The performance of the model is evaluated by comparing the results from different generated scenarios. The results show that the scheduler significantly improves the reliability and timeliness of safety-critical SoS.
Setareh Majidi, Roman Obermaisser, Sudam Wasala, Mario Qosja
INDIN2
2020 Failure Detection in TSN Startup Using Deep Learning
abstract
Time triggered devices are increasingly deployed in safety-critical distributed applications. Failures that manifest during the startup process of the synchronisation service pose a challenge to diagnose. The difficulty stems from the fact that most implemented diagnostic services for time-triggered systems employ the prior knowledge of the schedule to provide diagnosis. However, at the beginning of the startup process, when the global time base is not yet established, these diagnostic services are not viable. This work proposes the use of a fault injection framework to generate data that resembles the behaviour of failed components during startup. The data generated can then be used for developing fault diagnostic mechanisms. Due to the large data set that can be provided by fault injection frameworks, deep learning is proposed as a strategy for failure identification. The data generated from a fault injection framework is used to train the neural network to distinguish between correct behaviour, corruption and omission failures during startup.
Daniel Onwuchekwa, Juan Garcia Enamorado, Carlos Lua, Roman Obermaisser
ISORC4
2019 Composability Modeling for the Use Case of Demand-controlled Ventilation and Heating System
abstract
In recent engineering practice, the complexity of the systems is increasing. This complexity will keep on increasing if new components are added into the system or system configuration is changed. Numerous configurations of these components are repeated or their relationship is recognizable. On the other hand, simulation tools are commonly used to track the behavior of the modeled systems over time because of their advantages against experimental setups which are the abstraction of reality. However, the ability to integrate different components at different levels of the designed model along with the different techniques used for their inter-relationships based on users requirement is a challenge. The main contribution of this paper is to give an example of how to apply composability to handle this issue. One tangible example is to study the behavior of heating, ventilation, and air-conditioning systems in large buildings. Therefore, finding a solution to model this kind of complex system in a highly composable and scalable view is promising. Composability is a system design challenge that describes how different components can be selected and combined in different configurations and different levels to satisfy users requirement with a highly reduced development cost and time in the simulation, as its advantages. Finally, the practical steps for design and implementation of a composable demand-controlled ventilation and heating system as a useful and energy-efficient smart building's technology in MATLAB/Simulink (besides its constraints) is provided.
Ali Behravan, Nadra Tabassam, Osama Al-Najjar, Roman Obermaisser
CoDIT4
2019 Combined Compression of Multiple Correlated Data Streams for Online-Diagnosis Systems
abstract
Online fault-diagnosis is applied to various systems to enable an automatic monitoring and, if applicable, the recovery from faults to prevent the system from failing. For a sound decision on occurred faults, typically a large amount of sensor measurements and state variables has to be gathered, analyzed and evaluated in real-time. Due to the complexity and the nature of distributed systems all this data needs to be communicated among the network, which is an expensive affair in terms of communication resources and time. In this paper we present compression strategies that utilize the fact that many of these data streams are highly correlated and can be compressed simultaneously. Experimental results show that this can lead to better compression ratios compared to an individual compression of the data streams. Moreover, the algorithms support real-time constraints for time-triggered architectures and enable the data to be transmitted by means of shorter messages, leading to a reduced communication time and improved scheduling results.
Seungbum Jo, Markus Lohrey, Simon Meckel, Roman Obermaisser, Simon Plasger
DSD4
2019 Optimized Automotive Fault-Diagnosis based on Knowledge Extraction from Web Resources
abstract
The maintenance and repair of modern vehicles is a challenge for garages, as different causes of faults lead to similar symptoms in the highly complex vehicles these days. Existing processes for fault-diagnosis based on manufacturer service manuals and human experiences are often inadequate and result in high effort and wrong decisions. In addition to these service manuals which provide basic models for e.g., diagnostic terms, primary physical quantities, causal relationships, and plausibilities, nowadays, internet forums offer a comprehensive source of experiences for solutions to these challenges. This paper, therefore, presents methods for the extraction of knowledge from unstructured and informal contributions in internet forums with the goal to synthesize diagnostic graphs from the established knowledge base, which are part of a maintenance software to supports garages in the maintenance of vehicles by suggesting more efficient and target-oriented diagnostic and maintenance actions in real-time.
Simon Meckel, Johannes Zenkert, Christian Weber 0003, Roman Obermaisser, Madjid Fathi, Rubaiyat Islam Sadat
ETFA4
2019 State-Estimation for Increased Accuracy in Software- and Hardware-In-The-Loop testing via the Internet
abstract
Model-based design is an effective approach to develop complex embedded systems. Involving geographically distributed manufacturers can complicate this process due to hardware shipping and the protection of intellectual property. The usage of our framework which validates the communication between the components on a network-centric abstraction level solves these issues. It combines distributed co-simulation with Software- and Hardware-In-The-Loop (SIL/HIL) testing via wide area networks such as the Internet.The Internet as a best effort network cannot provide the required temporal guarantees for the real-time tests performed in HIL. As inputs may be delayed, it is only possible to validate systems with communication periods that are larger than the network delays. However, these large periods result in decreased accuracy of the system. To overcome this disadvantage, we introduce the usage of state-estimation in this paper. We use adjustable communication periods based on the network delays to exchange data between the components. In between, the framework forwards inputs to the devices which are estimated using the devices' previous outputs and a model of the remaining system under test.To evaluate the mechanism, we implement a distributed fan control application. This application exchanges data periodically between a fan model and a triplicated PID controller. We define different communication periods and compare the resulting fan speed with and without state-estimation. If state-estimation is enabled, the framework can provide the required inputs in time for all periods. Furthermore, it is possible to provide a sufficient accuracy. Without state-estimation, a stable control is impossible if the network delays are larger than the communication periods.
Tobias Pieper, Roman Obermaisser
ETFA2
2019 System-on-Chip Platform for Safety-Relevant Structural Health Monitoring Applications
abstract
In domains such as aerospace, wind turbines and railway, structures are exposed to tough environmental conditions. Structural Health Monitoring (SHM) systems offer the possibility to realize condition-based maintenance (CBM) and monitoring methods in order to prevent fatal accidents. For this reason, real-time processing of the acquired data is necessary. The real-time processing of this data in combination with safety requirements and high availability needs a safe platform that can provide high computational power. In this paper a System-on-Chip (SoC) platform is shown, which addresses these challenges through the combination of an ARM processor with Programmable Logic (PL). Based on the SoC, the integration of safety-critical and non safety-critical functionality is possible in a single device. Targeting the standards EN 61508, EN 50126 and EN 50657 the introduction of SoCs as a platform for certifiable systems is discussed. With diversity and redundancy on a single chip, SoCs are ideally suited for requirements such as reliability, availability, maintainability and safety. Moreover, the implementation of functions in hardware on the PL in connection with the Programmable System (PS) facilitates real time data processing.
Veit Wiese, Michael Schmidt 0014, Tobias Reitz, Roman Obermaisser, Ferid Mahdi, Sumathaja Danush
IECON4
2019 Virtual Gateway in TCMS Execution Environment based on an Integrated Architecture
abstract
In the railway domain, the development trend is evolving from federated to integrated architectures, which promise massive cost reduction through higher functional integration of Train Control and Monitoring Systems (TCMS). An integrated architecture means that components are integrated on a computing node, which formerly were allocated to separate computing nodes. Therefore, the execution environment needs to support communication between these components on a computing node. Based on an integrated architecture, a virtual switch supporting time-space isolation and dynamic configuration has been proposed in previous work to address the mixed criticality of TCMS applications and dynamic coupling of vehicles. However, controlled information import and export between different data flows is not addressed in the state of the art. In this paper, we propose a virtual gateway residing in the TCMS execution environment to resolve property mismatches between different data flows and prevent fault propagation between applications of different safety critical levels. We capture the properties of data flows in the gateway specification and realise the gateway services by leveraging a database in the gateway. The experimental results show the isolation and the controlled information transportation between data flows.
Hongjie Fang, Roman Obermaisser
INDIN2
2019 State-Estimation for Delay-Management in Distributed Real-Time Co-Simulation via the Internet
abstract
Typical distributed embedded real-time systems are composed of several subsystems developed by different, geographically distributed manufacturers. During the development process, these subsystems have to be integrated via real-time communication networks and tested. The verification can be simplified combining co-simulation and Software- and Hardware-In-The-Loop (SIL/HIL) testing in a distributed co-simulation framework. In such a framework, software (SIL) and hardware (HIL) components can be tested against the model of a simulated plant. This way it is possible to detect design faults and integration problems while the subsystems are still located at their manufacturers' sites.Real-time systems impose strict temporal and reliability requirements on the communication network connecting the subsystems. However, these requirements cannot be achieved using the Internet for communication in the distributed co-simulation framework. In this paper we introduce state-estimation as a delay-management technique to provide required subsystem inputs in time. Based on previous outputs and a simulation model of the remaining system, the mechanism estimates a subsystem's future inputs. Using scheduling information about the real-time communication in the system, the framework can determine if an input packet is received in time. If not, the estimated packet is forwarded. As soon as the real input packet is received later, its content is compared with the estimated input and the operator is notified if the error between estimated and real input exceeds a configurable threshold.
Tobias Pieper, Roman Obermaisser
INDIN2
2019 Simulation Framework for Clock Synchronization in Time Sensitive Networking
abstract
Hard real-time systems like industrial control applications have strict temporal requirements. Many hard real-time systems depend on a global time base for coordinating access to shared resources and for time-stamping events. Hence, the Time Sensitive Networking (TSN) task group introduces a fault-tolerant and robust clock synchronization mechanism (i.e. IEEE 802.1AsRev) that results in a synchronized network. This paper presents a simulation framework for IEEE 802.1AsRev to evaluate the reliability of the global time base in TSN-based systems. The simulation models are developed on top of our existing TSN models that support the time-based features of TSN (e.g. IEEE 802.1Qbv and IEEE 802.1Qci standards). Moreover, the evaluation of different TSN synchronization modules such as Best Master Clock Algorithm (BMCA), synchronization and peer delay measurement are carried out in our simulation framework. We also study the behavior of IEEE 802.1AsRev in the presence of either a node failure or a link failure using an example scenario of a train communication network. The experimental results validate the correctness and applicability of TSN clock synchronization for modern cyber physical systems with demanding timing requirements.
Maryam Pahlevan, Balakrishna Balakrishna, Roman Obermaisser
ISORC3
2018 Virtual Switch Supporting Time-Space Partitioning and Dynamic Configuration for Integrated Train Control and Management Systems
abstract
In the railway domain, an execution environment supporting data flows of mixed-criticality applications is an open research problem towards higher integration of future Train Control and Monitoring Systems (TCMS). Compared to the avionic and automotive domains, train inauguration deals with changes of train composition and configuration and is a specific requirement of the railway domain. The statically configured communication channels of other domains need to be extended, in order to cover the requirement of dynamic configuration for train inauguration. In this paper, we propose a virtual switch that ensures temporal and spatial partitioning between data flows of the TCMS applications hosted on the same computing node. The switch leverages the Software-Defined Networking (SDN) paradigm to be reconfigurable in order to cover the train inauguration requirement.
Hongjie Fang, Roman Obermaisser
DSD2
2018 Generation of a Diagnosis Model for Hybrid-Electric Vehicles Using Machine Learning
abstract
Online fault-diagnosis on system level for complex mechatronic systems takes multiple sensor measurements of the various components into account and contributes to a significantly increased system reliability by tracking down faults in the system at run time, enabling fault-specific recovery actions, such as reconfigurations. Ongoing efforts in the technological development of automobiles, especially in the field of driver assistance systems, yield more and more safety-critical systems, e.g., breaking control systems, and thus generate a high demand for reliable online diagnosis systems. In order to perform fault diagnosis on system level, the interrelations between all measurements must be determined, which is a challenging and often demanding task done by human system experts. In this paper we present a systematic approach based on machine learning to establish an online diagnosis system for a hybrid-electric vehicle model.
Simon Meckel, Roman Obermaisser, Jie-Uei Yang
DSD2
2018 Simulation and Validation Framework for Safety-Critical Applications in System-of-Systems
abstract
The following topics are dealt with: production engineering computing; factory automation; manufacturing systems; control engineering computing; Internet of Things; real-time systems; mobile robots; industrial control; learning (artificial intelligence); scheduling.
Ayman Murshed, Mohammed Abuteir, Roman Obermaisser
ETFA3
2018 Genetic Algorithm for Scheduling Time-Triggered Traffic in Time-Sensitive Networks
abstract
Time-Sensitive Networking (TSN) is introduced as a series of Ethernet extensions to address strict temporal constraints of modern mission-critical applications. TSN offers determinism using global Time-Triggered (TT) transmission schedules. Most of existing scheduling solutions ignore interdependence of routing and scheduling problems and derive the design space of system implementations only from scheduling constraints. This strategy limits the capability of former approaches to compute a global schedule of TT communication for several real-time systems. In this paper, we present a heuristic scheduling approach based on a genetic algorithm. Our approach combines the routing and scheduling constraints and generates static global schedules using joint constraints in a single-step. The number of scheduling possibilities within the design space that is derived from joint routing and scheduling constraints increases in comparison to the approaches that only use the fixed routing. Thereby, the schedulability is improved by our solution. Our genetic-based approach also considers the distribution of real-time applications, multicast patterns and interdependencies of TT flows in the scheduling process. Due to optimized task binding and resource allocation, the experimental results show a significant enhancement of schedulability, TT transmission efficiency and resource utilization compared to the state-of-art solutions.
Maryam Pahlevan, Roman Obermaisser
ETFA2
2018 Minimizing the Make Span of Diagnostic Multi-Query Graphs Using Graph Pruning and Query Merging
abstract
Active diagnosis can significantly increase the reliability of a real-time system in case of fault occurrences. Root causes are identified for observed failures and the root causes are associated with suitable recovery actions such as the migration of services to spare resources or application-specific reconfiguration. Real-time databases and diagnostic multi-query graphs (DMG) are a promising technique for root-cause analysis. However, in order to ensure safety the completion of the diagnostic queries must be performed within strict timing bounds dictated by the environment. This paper presents optimization techniques for diagnostic multi-query graphs in order to minimize the make span of a root cause analysis. The optimization is split into two steps. The first step comprises the pruning of the graph nodes without affecting the semantics of diagnostic queries. Each graph node that satisfies a certain set of constraints is deleted and its query is merged with its neighborhood nodes. The constraints for pruning and merging are based on the matching of SQL operations (select or join) and the data tables between the queries. The new graph generated after pruning is a subset of the original graph based on the merged queries from the deleted nodes. The second step is based on the optimization of the diagnostic queries in each node of the DMG, by selecting the best query execution plan. After the DMG is pruned and queries are optimized the new DMG is given as an input to a scheduler to determine the ensuing make span.
Nadra Tabassam, Roman Obermaisser
ETFA2
2018 Fault Injection Framework for Assessing Fault Containment of TTEthernet Against Babbling Idiot Failures
abstract
In safety critical communication systems, faulty nodes can monopolize a channel by transmitting untimely messages at random intervals and thus resulting in the failure of the system. This failure is known as a babbling idiot failure. This could be costly and catastrophic for safety critical systems, therefore these failures are avoided in time triggered communication systems by implementing fault tolerant functions such as local or central guardians. Research works evaluating the guardian functionality for real time networks such as Flexray and TTP have been carried out. This work evaluates the guardian functionality of the TTEthernet protocol. TTEthernet enforces a TDMA scheme for time triggered traffic and traffic policing for rate constrained traffic thereby protecting the network against babbling idiot failures. However these guardian functionality was not extensively evaluated. Dependability evaluation by fault injection on the entire TTEthernet communication system as a whole has not been extensively studied. In this paper we exploit a novel fault injection framework to generate babbling idiot failures for the purpose of verifying TTEthernet implementations with respect to fault containment. The framework adopts a novel cut-through approach abstracting the fault injector from both the end systems and switches, thereby facilitating portability and ease of use. This work introduces a fault injection framework to effectively verify babbling idiot fault tolerance of TTEthernet hardware implementations. In addition, it provides a means to evaluate the effect of various network faults on applications running on top the protocol. Test results carried out indicate the effect of babbling idiot messages on the latency and jitter of traffic over the TTEthernet network.
Daniel Onwuchekwa, Roman Obermaisser
IWQoS2
2018 Evaluation of Time-Triggered Traffic in Time-Sensitive Networks Using the OPNET Simulation Framework
abstract
Highly reliable, scalable and deployable net-works with strict temporal constraints are inevitable for future cyber physical systems. Due to widespread usage and success of Ethernet technologies, the Time Sensitive Networking task group introduces a series of protocol extensions to the IEEE 802.1 Ethernet standard. These standards provide real time capabilities and performance improvements. Simulation environments are intensively used to investigate correctness and applicability of new protocol suites. This paper presents an OPNET simulation framework for simulating TSN time-based features. Our framework implements ingress time-based policing and enhancements for scheduled traffic as an extensions of the Ethernet standard. We describe the implementation details of our simulation models which provide temporal properties. We also evaluate and compare our results with the expected behaviors of the aforementioned protocols.
Maryam Pahlevan, Roman Obermaisser
PDP2
2018 Guest Editorial Special Section on Industrial Communication Technologies and Systems
abstract
The eleven papers in this special section focus on industrial communication systems and technologies (ICS). Major requirements of the ICS are real-time support and dependability under all considered load and fault assumptions. The ICS may need to meet stringent deadlines as a basis for the stability in control loops and alarm monitoring. At the same time, high reliability and availability is demanded to avoid down times. In particular, reliability with respect to critical failure modes is of utmost importance for safety-critical applications where failures may result in significant financial losses or risk to humans and the environment. From the point of view of the information and communication technology (ICT), current ICS solutions are based on wired systems to support distributed industrial controls.
Claudio Zunino, Roman Obermaisser, Stig Petersen
IEEE Trans. Ind. Informatics2
2017 An Architecture for Online-Diagnosis Systems Supporting Compressed Communication
abstract
With its ability to detect, identify and, if applicable, recover from occurred faults, online-diagnosis can help achieving fault-tolerant systems. A sound decision on an occurred fault is the foundation for fault-specific recovery actions. For this, typically a large amount of data has to be analyzed and evaluated. A diagnostic process implemented on a distributed system needs to communicate all those data among the network which is an expensive affair in terms of communication resources and time. In this paper we present an architecture for a distributed online diagnosis system with real time constraints that supports data compression to reduce the communication time. We further present a lossy compression method with a guaranteed compression ratio that is suitable for real time purposes.
Seungbum Jo, Markus Lohrey, Damian Ludwig, Simon Meckel, Roman Obermaisser, Simon Plasger
DSD5
2017 Modular Development and Certification of Dependable Mixed-Criticality Systems
abstract
The transition from conventional federated architectures to integrated architectures enables the integration of functionalities with different criticality with respect to safety, security and real-time on a single embedded computing platform. Mixed-criticality networks provide safe and predictable communication for functionalities with different criticality, offering benefits regarding spatial and temporal segregation. However, they imply certification challenges due to the increasing demand for features with different criticality, which lead to a significant and potentially unacceptable increase of engineering and certification costs. On the other hand, the traditional certification process relies on the assessment of the entire system where if a requirement changes, the whole system shall be re-attested. This paper analyses modularity from a system-of-system and a product line development perspective and contributes a reusable generic modular safety concept where the safety arguments that a mixed-criticality network must provide to be compliant with the IEC 61508 safety standard are defined. This safety case is used for defining the linking analyses where the way in which two industrial networks fulfil the safety-related arguments stated in the safety concept are analysed.
Asier Larrucea, Imanol Martinez, Carlos F. Nicolás, Jon Pérez 0001, Roman Obermaisser
DSD5
2017 Time-triggered scheduling of query executions for active diagnosis in distributed real-time systems
abstract
In recent years, many control applications have replaced safety critical mechanical systems with distributed realtime embedded systems comprising of many processors, sensors and actuators interlaced together with a dedicated communication network and without any mechanical backup e.g., steer-bywire used in steering systems of automotive vehicles. Such systems demand a high level of reliability and performance. These systems also have severe cost constraints so including redundant components in the end product is not a viable solution for improving reliability and performance. Another solution is to continuously monitor the system and introduce fault diagnosis to ensure that the dependability of the system is greater than the dependability of its constituent hardware and software components. Active diagnosis is one such technique that improves the reliability of the system by diagnosing facts at run-time for fault isolation and error recovery. The presented work addresses an active diagnosis scenario that uses diagnostic queries and a real-time database to find faults within a distributed system that has limited resources and strict deadlines. Since scheduling the diagnostic tasks is an important aspect of a timely analysis of the system, a list schedule has been proposed that calculates the points in time when the diagnostic queries are executed and data is replicated to the database. This a priori knowledge about the behavior of the query executions will bound the time required for inferring faults that will lead to a realizable diagnostic framework. The proposed algorithm utilizes a priority scheme to schedule the diagnostic tasks onto free processors within minimum time while respecting their precedence and periodicity constraints. The paper presents the approach in detail with the help of examples and results with different design constraints.
Sarah Amin, Roman Obermaisser
ETFA2
2017 Scheduler for reliable distributed systems with time-triggered networks
abstract
Real-time communication and reliability are two important requirements in the development of safety-critical embedded systems, which benefit from the inherent fault isolation and temporal predictability of time-triggered networks. These systems depend on redundant communication schedules that contain global time-based information of message transmissions with conflict-free paths through the switches. In these systems the use of redundancy to handle communication errors requires the pre-allocation of communication resources. On the basis of a time-triggered scheduler using Mixed Integer Linear Programming (MILP), this paper introduces a novel scheduler for redundant time-triggered networks that assigns messages to redundant paths. The scheduler considers the link reliability along with physical and logical models and produces a schedule where each message is assigned to two different paths along the switches. We also discuss and validate the approach with results from a prototype implementation.
Ayman Murshed, Roman Obermaisser
INDIN2
2017 Class-based query-optimization for minimizing worst-case execution times of diagnostic queries in embedded real-time systems
abstract
Active diagnosis in real time embedded computer systems increases the overall reliability of the system by performing error detection and fault recovery. Real time databases and diagnostic queries are a common solution to realize active diagnosis. This paper presents a technique to optimize the diagnostic queries in a fault tolerant real time embedded system. A directed graph called the DMG (Diagnostic Multi-query Graph) based on the diagnostic symptoms and features is the input to the query optimization module for the processing of each query within a short worst case execution time. The diagnostic inference process is temporally and spatially decomposed by introducing intermediate inference steps called symptoms. These symptoms and diagnostic features extracted from the DMG are stored in an embedded database created in a Pervasive SQL server. The query execution is based on periods and each query node of the DMG has to finish within its time bound which is worst case execution time of the query. At first the estimated worst case execution time for each diagnostic query is calculated. After that the algorithm optimizes the diagnostic query using a class based query categorization technique. The access method for each query is selected on the basis of its type. For join queries the most optimized join order is calculated by estimating the selectivity factor based on the number of tuples present in each join order. Results presented in this context show that the diagnostic queries are optimized effectively and their estimated worst case execution time is minimized.
Nadra Tabassam, Roman Obermaisser
INDIN2
2017 Global Adaptation for Energy Efficiency in Multicore Architectures
abstract
Today mixed-criticality systems are used in most industrial domains, because of their integration advantages. They are smaller, weigh less and reduce the idle time of previously dedicated hardware. However, these systems can still be improved. Since their hardware is now used more efficiently it automatically suffers more under the aging effects of heat created by all the simultaneous computations. Heat accelerates the aging process of hardware and increases failure rates. To prevent this the systems need to be cooled down by additional cooling devices like fans. In turn, these devices introduce new failure sources due to their movable parts. In this paper we propose a chip-wide approach to dynamically manage the system's computation and communication to optimize the energy-efficiency. By reducing the energy usage of the system we can reduce the additional hardware and therefore the weight of the whole system. Furthermore, we can prolong the system's lifetime as the available power resource lasts longer. We expand the current usage of tile-based energy management to a system wide scheme by implementing a meta-scheduler, which monitors the system state and changes the schedule if an optimization can be performed. This approach is shown to save up to 48% depending on the slack occurrence in an experimental setup.
Alina Lenz, Tobias Pieper, Roman Obermaisser
PDP3
2017 Efficient Multi-core AUTOSAR-Platform Based on an Input/Output Gateway Core
abstract
The AUTOSAR standard provides support for multicore systems since version 4. However, this AUTOSAR multicore version focuses on inter-core communication with a shared memory approach. In contrast, the paradigm of message-based network-on-chips provides multiples advantages for real-time embedded systems such as automotive electronics including better temporal predictability, fault containment and energy efficiency. In this paper we propose an efficient multicore architecture for AUTOSAR based on time-triggered network-on-chips and dedicated input/output cores. Additionally, a health monitoring service is integrated into the AUTOSAR ECU architecture in order to provide recovery actions in case of failures of the automotive application or the hardware of a specific core in the multiprocessor. The results demonstrate how the operating system overhead decreases considerably when using the defined input/output cores that serve as hardware accelerators for the AUTOSAR software. Also, the reliability of the system is improved significantly due to the implemented health monitoring service.
Moisés Urbina, Roman Obermaisser
PDP2
2016 On-chip networks for mixed-criticality systems
abstract
We propose the integration of a network-on-chip-based MPSoC in mixed-criticality systems, i.e. systems running applications with different criticality levels in terms of completing their execution within predefined time limits. An MPSoC contains tiles that can be either CPUs or memories, and we connect them with an instance of a customizable point-to-point interconnect from STMicroelectronics called STNoC. We explore whether the on-chip network capacity is sufficient for meeting the deadlines of external high critical workloads, and at the same time for serving less critical workloads that are generated internally. To evaluate the on-chip network we vary its configuration parameters, such as the link-width, and the Quality-of-Service (QoS), in specific the number (1 or 2) and type (high or low priority) of virtual channels (VCs), and the relative priority of packets from different flows sharing the same VC.
Polydoros Petrakis, Mohammed Abuteir, Miltos D. Grammatikakis, Kyprianos Papademetriou, Roman Obermaisser, Zaher Owda, Antonis Papagrigoriou, Michael Soulie, Marcello Coppola
ASAP5
2016 A Realistic Approach to a Network-on-Chip Cross-Domain Pattern
abstract
The transition from conventional federated architectures to integrated architectures enables the integration of functionalities with different criticality (such as safety, security and real-time) on a single embedded computing platform. Many embedded systems require distributed subsystems with networks (e.g., EtherCAT or Ethernet) to satisfy computational resource demands and installation requirements and ensure fault-tolerance. The broad trend of the integration of functionalities with different criticality on a single embedded computing platform involves the implementation of safe and predictable communication systems with temporal segregation between different criticality. However, they represent challenges of certification such as the guarantee of non-interference between safety-critical and non-safety-critical communications, which leads to the increase of engineering and certification cost. This paper contributes a network-on-chip cross-domain pattern which provides a generic solution to recurring problems in mixed-criticality networks. In addition, this paper presents a modular safety case for an IEC 61508 compliant mixed-criticality network that is used for defining the linking analysis of the proposed network pattern. On the other hand, this paper also defines the integration of the cross-domain pattern on a simplified wind turbine case study.
Asier Larrucea, Hamidreza Ahmadian, Roman Obermaisser, Jon Pérez 0001, Carlos F. Nicolás
DSD3
2016 SAFEPOWER Project: Architecture for Safe and Power-Efficient Mixed-Criticality Systems
abstract
With the ever increasing industrial demand for bigger, faster and more efficient systems, a growing number of cores is integrated on a single chip. Additionally, their performance is further maximized by simultaneously executing as many processes as possible not regarding their criticality. Even safety critical domains like railway and avionics apply these paradigms under strict certification regulations. As the number of cores is continuously expanding, the importance of cost-effectiveness grows. One way to increase the cost-efficiency of such System on Chip (SoC) is to enhance the way the SoC handles its power resources. By increasing the power efficiency, the reliability of the SoC is raised, because the lifetime of the battery lengthens. Secondly, by having less energy consumed, the emitted heat is reduced in the SoC which translates into fewer cooling devices. Though energy efficiency has been thoroughly researched, there is no application of those power saving methods in safety critical domains yet. The EU project SAFEPOWER1 targets this research gap and aims to introduce certifiable methods to improve the power efficiency of mixed-criticality real-time systems (MCRTES). This paper will introduce the requirements that a power efficient SoC has to meet and the challenges such a SoC has to overcome.
Alina Lenz, Mikel Azkarate-askatsua, Javier Coronel, Alfons Crespo, Simon Davidmann, Juan Carlos Diaz Garcia, Nera González Romero, Kim Grüttner, Roman Obermaisser, Johnny Öberg, Jon Pérez 0001, Ingo Sander, Ingemar Söderquist
DSD9
2016 Fault injection for IEC 61499 applications
abstract
Distributed control systems relying on IEC 61499 are a common engineering approach for various application domains ranging from industrial control to the management and control of modern buildings. In this paper we propose a generic fault-injection concept to support the verification of applications. A potential use-case therefore is, for example, to stress measures that aim to improve their reliability.
Bernd Glatz, Harald Schuster, Martin Horauer, Thomas Rauscher, Roman Obermaisser
ETFA5
2016 Mixed-criticality transactional memory controller for embedded systems
abstract
The pervasiveness of multi-core platforms and the trend towards mixed-criticality applications are major technology drivers in the area of embedded systems. Although transactional memories offer the potential to radically simplify the development of these systems, fault isolation and temporal predictability are open research challenges. This paper introduces a priority-based hardware transactional memory controller for mixed-criticality systems, which offers algorithms for predictable and selective conflict resolution. The memory controller is part of a multi-core architecture with a mapping to a deterministic time-triggered interconnect. As a consequence, fault propagation to higher criticality is prevented and the timing analysis of safety-relevant transactions can abstract from lower criticality levels. The presentation of the architecture and the explanation of the algorithms is complemented by the formal analysis of the WCET. In addition, an automotive use case with a simulation environment serves for the evaluation of the temporal behavior of the architecture and the memory controller.
Zaher Owda, Roman Obermaisser
INDIN2
2016 Co-simulation framework for AUTOSAR multi-core processors with message-based Network-on-Chips
abstract
Simulation environments play a very important role in the development of embedded systems helping system architects in exploring design decisions. However, the simulation of AUTOSAR multi-core processors with Network-on-Chips (NoCs) for inter-core communication is still a significant research problem. Message-based NoCs provide significant advantages for real-time embedded systems as in the case of the automobile industry. Such a simulation would provide early insights into the real-time behavior of the AUTOSAR application on the message-based multi-core chip. This paper presents as a novel contribution a co-simulation framework supporting the integration of the AUTOSAR architecture with NoC-based platforms. We describe a simulation model for application cores playing the role of virtual AUTOSAR ECUs on the MPSoC platform. The framework introduces an interface for the co-simulation of simulation models for the AUTOSAR-based software (virtual ECUs), the natural environment and the NoC behavior. This co-simulation interface combines a Functional Mock-up Unit (FMU) and a local coordinator for the synchronization and the data exchange between the simulators hosting the simulation models. The implementation is performed using the VEOS simulator for the AUTOSAR-based software and physical environment models, and the GEM5 simulator for the on-chip communication level. An anti-lock braking use case serves for the evaluation of the co-simulation framework.1
Moisés Urbina, Hamidreza Ahmadian, Roman Obermaisser
INDIN3
2016 Self-configuring real-time communication network based on OpenFlow
abstract
One of the major tasks when deploying real-time Ethernet networks is their configuration to achieve real-time behavior. In this paper we present an approach for a self-configuring plug-n-play network that automatically sets up devices and offers hard real-time guarantees to such devices. A new architecture and a protocol based on OpenFlow are proposed to achieve a system that can react to failures of switches and links by trying to repair such failures on a network level and restoring a full redundancy level while maintaining hard real-time guarantees. Implementation details are explained and the architecture is evaluated against randomly generated topologies. It is shown, that the solution can achieve a seamless failure recovery in link failures without any complexity at the end-device side.
Peter Heise, Marc Lasch, Fabien Geyer, Roman Obermaisser
LANMAN4
2015 Deterministic OpenFlow: Performance evaluation of SDN hardware for avionic networks
abstract
Due to special requirements avionic networking devices are typically quite expensive. One way to reduce costs is to make use of commercial off the shelf devices and configure them in a way that gives similar performance. In this paper we evaluate the use of OpenFlow in the avionics environment in terms of performance and configuration. The main feature of OpenFlow is fine-grained access to the switch's forwarding plane. While it was primarily designed to offer high configurability and reduction of cost through harmonization of interfaces, in newer versions OpenFlow added support for traffic policing. In OpenFlow this is realized with meters that allow for quality of service enforcement on a hardware level as well as an arbitrary mapping of meters to flows. This paper shows how to make use of OpenFlow's meter commands to achieve deterministic behavior and discusses its advantages and shortcomings. We then implement the proposed solution on a commercial off the shelf OpenFlow switch and compare the switching performance to a state of the art avionics switch used in current aircraft.
Peter Heise, Fabien Geyer, Roman Obermaisser
CNSM3
2015 Time-Triggered Extension Layer for On-Chip Network Interfaces in Mixed-Criticality Systems
abstract
The increasing trend towards mixed-criticality in different domains demands a platform in which the physical integration of subsystems with different criticalities is accommodated. A fundamental prerequisite for such a platform is to establish temporal and spatial segregation between different subsystems in order to eliminate the interference on safety-critical functions, caused by non-safety-critical ones. Furthermore, as mixed-criticality systems often comprise heterogeneous subsystems, the platform shall support different timing models (e.g., periodic and sporadic activities). This paper introduces an extension layer for the Network Interface (NI) of a network-on-a-chip in order to establish the temporal and spatial partitioning over the entire chip. We describe how chip-wide temporally aligned activities of different NIs in combination with resource allocations assure the absence of interference for time-triggered messages and bounded latencies for rate-constrained messages. The chip-wide configuration of the NIs establishes guarding windows for time-triggered messages and traffic shaping of rate-constrained messages.
Hamidreza Ahmadian, Roman Obermaisser
DSD2
2015 A Modular Safety Case for an IEC-61508 Compliant Generic Hypervisor
abstract
The development of mixed-criticality systems that integrate several functionalities of different criticality levels (e.g., SIL1-4 according to IEC-1508) on the same embedded computing platform provide benefit in terms of cost, size, weight, reliability and scalability. The soaring demand for high performance mixedcriticality system has contributed to their capabilities expansion. This upward trend is subject to certification processes with different levels of rigorousness, which lead to prohibitive cost. This paper presents the modular safety concept of an IEC-61508 generic hypervisor where the minimum reasonable safety arguments and evidences are defined. Additionally, the use of the modularity approach limits the impact of changes to a reduced area of the safety case, enabling in turn the reusability of the safety cases parts. The work described in this paper has been reviewed and approved by a certification body, within the context of a European research project.
Asier Larrucea, Jon Pérez 0001, Irune Agirre, Vicent Brocal, Roman Obermaisser
DSD5
2015 Co-simulation framework for networked multi-core chips with interleaving discrete event simulation tools
abstract
The simulation of networked multi-core chips is a significant research problem in large embedded applications. Although multi-core processors in embedded systems offer increased computational resources and performance, many applications still require distributed systems with multiple of these processors to satisfy resource requirements and provide fault-tolerance at system level. This paper introduces a framework for the co-simulation of a distributed system (i.e., off-chip networks, end-systems) with multi-core chips based on networks-on-a-chip. Simulation components are presented for the synchronization and data exchange between these simulators. A realization is performed using the simulator GEM5 for the chip level, the simulator OPNET for the cluster level and components for communication and synchronization via TCP/IP. An evaluation for a use case demonstrates the utility of the framework to analyse applications and their timing on networked multi-core chips.
Zaher Owda, Mohammed Abuteir, Roman Obermaisser
ETFA3
2015 Multi-core architecture for AUTOSAR based on virtual Electronic Control Units
abstract
Message-based Networks-on-a-Chip (NoC) provide significant advantages with respect to temporal predictability, fault isolation and energy efficiency. However, the AUTOSAR standard for multi-core operating systems focuses only on multi-core platforms with shared memories. In order to obtain the benefits of message-based interactions, this paper maps an AUTOSAR system to a multi-core platform with a time-triggered NoC. Cores serve as virtual Electronic Control Units (ECUs), each containing a lightweight AUTOSAR operating system and a Run-Time Environment (RTE). Virtual ECUs provide meaningful units of abstraction and ensure freedom of inference from other cores. Computationally expensive functionality of the basic software is delegated to system cores, which serve as hardware accelerators for the application cores.
Moisés Urbina, Roman Obermaisser
ETFA2
2015 A Predictable Transactional Memory Architecture with Selective Conflict Resolution for Mixed-Criticality Support in MPSoCs
abstract
Transactional memories can radically simplify the programming of mixed-criticality systems by offering atomicity, consistency and isolation guarantees between subsystems of different criticality. A major objective in mixed-criticality systems is a modular safety case where each subsystem is certified to the respective safety assurance level. The prerequisite for this modular certification is the prevention of any effect of low criticality subsystems on the temporal behavior of subsystems of higher criticality. This paper introduces a transactional memory architecture based on a time-triggered network-on-a-chip with fault isolation based on a TDMA scheme. The memory architecture contains a memory gateway for selective conflict resolution when committing transactions. The memory gateway triggers a rollback of a transaction in case higher criticality subsystems would be affected. The proposed transactional memory architecture ensures that the validation and certification of high criticality subsystems does not depend on subsystems with lower criticality.
Zaher Owda, Roman Obermaisser
EUC2
2015 Scheduling of rate-constrained and time-triggered traffic in multi-cluster TTEthernet systems
abstract
Multi-cluster systems with real-time networks are gaining increasing importance to address the communication needs of large-scale embedded systems in different domains such as automotive, factory automation and health-care systems. At the same time, heterogeneous application subsystems with varying criticality levels require different timing models including time-triggered communication, event-triggered communication with rate-constraints and best-effort communication. An example is the coexistence of periodic control functions, event-triggered comfort functions and streaming multimedia services of in-vehicle electronic systems. This paper presents a scheduling algorithm as well as a simulation and verification framework for such multi-cluster systems. We support the allocation and scheduling of time-triggered and rate-constrained services to processing elements and communication links of multiple Time-Triggered Ethernet (TTE) clusters. The simulation and verification framework supports the automatic generation of test cases based on generic scenario parameters including the connectivity degree as well as the number of clusters, processing elements, switches and services. Thereby, we enable a comprehensive evaluation of the scheduling algorithm for use cases of varying complexity. In addition, the simulation and verification framework is a foundation for the systematic comparison of different scheduling algorithms including the evaluation of schedulability and runtime for different types of scenarios.
Mohammed Abuteir, Roman Obermaisser
INDIN2
2015 Scheduling and allocation of time-triggered and event-triggered services for multi-core processors with networks-on-a-chip
abstract
Multi-core processors are gaining increasing importance in safety-relevant embedded real-time systems, where temporal guarantees must be ensured despite the sharing of on-chip resources such as processor cores and networks-on-a-chip. At the same time, many applications comprise workloads with different timing models including time-triggered and even-triggered communication. This paper introduces a scheduling model based on Mixed Integer Linear Programming (MILP) supporting the allocation of computational jobs to processing cores as well as the scheduling of messages and the selection of paths on networks-on-a-chip. The model supports dependencies between computational jobs and it combines both time-triggered and event-triggered messages. Phase-alignment of time-triggered messages is performed, while avoiding collisions between time-triggered messages and satisfying bandwidth constraints for event-triggered messages. Example scenarios are solved optimally using the IBM CPLEX optimizer yielding minimal computational and communication latencies.
Ayman Murshed, Roman Obermaisser, Hamidreza Ahmadian, Alá F. Khalifeh
INDIN2
2015 Model-based development of systems-of-systems with reliability requirements
abstract
The development of Systems-of-Systems (SoS) architectures is challenged by the inherent characteristics of SoS such as operational independence, heterogeneity of constituent systems, emergent behavior and large-scale distribution. At present, the resulting complexity restricts the design space exploration of SoS architectures to be focused on cost and functionality. In this paper we extend our previous work on timing analysis and optimization in early SoS design phases by supporting reliability requirements in the generated SoS architecture. Our approach defines a SoS architecture development methodology that applies an architecture optimization method based on concise modeling with architecture patterns, timing and reliability requirements, and extensions to the Unified Profile for DoDAF and MODAF (UPDM). Optimization using Mixed Integer Linear Programming (MILP) is used to satisfy the real-time and reliability requirements and optimization results are back annotated to UPDM models.
Imad Sanduka, Roman Obermaisser
INDIN2
2015 Minimizing revalidation and recertification in evolutionary embedded systems
abstract
Embedded systems have gained immense importance in various domains and they evolve rapidly driven by the necessity to cope with new emerging technologies and new required functionalities. The requirements of evolving embedded systems are subject to changes, thereby leading to repeated redesigns. In model-driven engineering the application's functional and nonfunctional requirements are specified separately from the underlying execution platform. Scheduling is the process of allocating the services of the application model onto the available resources of the platform model. Due to the continuous changes and updates in evolving embedded systems the rescheduling process becomes a critical challenge, because the output of scheduling can be significantly different even upon small changes. This avalanche effect leads to high effort and cost for recertification and revalidation. The contribution of this paper is a method for incremental scheduling, which minimizes the number of changed resource allocations while also satisfying the application's temporal constraints. The incremental scheduling is realized using Mixed Integer Linear Programming (MILP) and the IBM CPLEX optimizer. The presented results allow to reduce cost for recertification and revalidation compared to state-of-the-art scheduling methods.
Waled Al-Makhawi, Roman Obermaisser
WFCS2
2014 End-to-End Real-Time Communication in Mixed-Criticality Systems Based on Networked Multicore Chips
abstract
Mixed-criticality systems combine applications at different levels of criticality on the same platform. Today, mixed-criticality integration is addressed individually at different integration levels such as the operating system, the chip-level and the cluster-level. Since many mixed-criticality systems span all of these integration levels, a system perspective of mixed-criticality applications is required. The access to remote resources located on another chip needs to be relayed via gateways involving gateways between on-chip and off-chip networks (i.e., vertical integration) and gateways between different types of off-chip networks (i.e., horizontal integration). This paper introduces a system model with gateways for end-to-end channels over hierarchical, heterogeneous and mixed-criticality networks. We focus on the timing of end-to-end channels, as well as the interoperability across gateways.
Roman Obermaisser, Zaher Owda, Mohammed Abuteir, Hamidreza Ahmadian, Donatus Weber
DSD1
2014 Architectures for mixed-criticality systems based on networked multi-core chips
abstract
Mixed-criticality architectures with support for modular certification make the integration of application subsystems with different safety assurance levels both technically and economically feasible. Strict segregation of these subsystems is a key requirement to avoid fault propagation and unintended side-effects due to integration. Also, mixed-criticality architectures must deal with the heterogeneity of subsystems that differ not only in their criticality, but also in the underlying computational models and the timing requirements. Non safety-critical subsystems often demand adaptability and support for dynamic system structures, while certification standards impose static configurations for safety-critical subsystems. Several aspects such as time and space partitioning, heterogeneous computational models and adaptability were individually addressed at different integration levels including distributed systems, the chip-level and software execution environments. However, a holistic architecture for the seamless mixed-criticality integration encompassing distributed systems, multi-core chips, operating systems and hypervisors is an open research problem. This paper describes the state-of-the-art of mixed-criticality systems and discusses the ongoing research within the European project DREAMS on a hierarchical mixed-criticality platform with support for strict segregation of subsystems, heterogeneity and adaptability.
Roman Obermaisser, Donatus Weber
ETFA1
2014 Runtime evaluation of ontology-based reconfiguration of distributed embedded real-time systems
abstract
In modern safety-relevant applications a high degree of dependability and fault tolerance is demanded, which is obtained by the application of fault-tolerance techniques. Most of those techniques build on the active replication of sensors, actuators and computational components. During system design, explicit redundancy involves a fundamental trade-off between the number and types of tolerated faults and the resulting cost of increased reliability. Usually in such systems also implicit redundancy exists which is given by the vast number of measuring and actuation devices used to monitor, predict and control the physical process. Most common fault-tolerance techniques are designed to tolerate faults considered in the fault hypothesis of a system. However, they are not capable to benefit from implicit redundancy or to mitigate unforeseen failures. An effective technique to counteract these problems is ontology-based dynamic reconfiguration, which exploits implicit redundancy in the system to recover from failures. In order for dynamic reconfiguration to be applicable for embedded real-time systems, a temporal bound for system recovery has to be guaranteed. In this paper an approach for ontology-based reconfiguration is presented which can be performed within bounded time. The theoretical runtime considerations regarding the proposed technique are underlined by the results of reconfiguration experiments.
Oliver Höftberger, Roman Obermaisser
INDIN2
2014 Model-based development of Systems-of-Systems with real-time requirements
abstract
Many Systems-of-Systems (SoS) are real-time systems and temporal correctness needs to be considered in the development process. Introducing a temporal specification and timing analysis in early design phases of the SoS architecting process avoids change efforts in later design phases where the SoS architecture fails to meet its timing requirements. This paper introduces a model-based development approach for SoS with real-time requirements. We introduce an architecture optimization method based on concise modeling with architecture patterns, timing requirements and extensions to the Unified Profile for DoDAF and MODAF (UPDM). Optimization using Mixed Integer Linear Programming (MILP) is used to satisfy the real-time requirements and optimization results are back annotated to UPDM models.
Imad Sanduka, Roman Obermaisser
INDIN2
2014 Secure automotive gateway - Secure communication for future cars
abstract
The main focus of the paper is to secure the onboard communication of automobiles. The current trend in the automotive domain is to incorporate technologies known from the consumer segment (e.g., WLAN, Ethernet) into the car. This makes it easier for an attacker to attack the on-board networks of the car, even without having physical access. To detect attacks against the automotive networks such as CAN and FlexRay, we introduce the concept of the so called “security gateway” which is part of the automotive architecture and is located on transition points, where different networks connect with each other. A language was created to specify the correct application behavior and to configure the security gateway. Using this representation of the application behavior the security gateway not only detects failures caused by an attacker but also detects failures caused by malfunctions.
Stefan Seifert, Roman Obermaisser
INDIN2
2014 Active Diagnosis in Distributed Embedded Systems Based on the Time-Triggered Execution of Semantic Web Queries
abstract
Active diagnosis aims at significantly improving system reliability by computing diagnostic information at run-time for fault isolation and online error recovery. The presented work extends semantic techniques, usually used in large-scale IT systems, for active diagnosis in open embedded real time systems. Open embedded systems (e.g., ambient assisted living for elderly care, critical infrastructures, health management and medical systems) exhibit real-time and reliability requirements, while the constituent components are unknown at design time. Time-triggered diagnostic inference supports the incremental generation of symptoms, which result from the temporal and spatial decomposition of the diagnostic analysis process. The methods and algorithms are prototypically implemented, as well as experimentally evaluated. The paper demonstrates that dynamic semantic web services in combination with time-triggered scheduling techniques are suitable to enable active diagnosis in open embedded systems with reliability and real-time requirements.
Roman Obermaisser, Rubaiyat Islam Sadat, Fabian Weber
ISORC1
2013 Simulation environment for Time-Triggered Ethernet
abstract
Time-Triggered Ethernet (TTEthernet) is an SAE standard of a real-time Ethernet extension, which supports real-time requirements, fault isolation and mixed criticality applications. TTEthernet supports different communication mechanisms ranging from best-effort messaging with a high channel utilization to predictable real-time messaging based on a time-triggered communication schedule. This paper presents a simulation framework for TTEthernet-based systems, which supports the analysis and validation of TTEthernet-based applications at early development stages. We introduce generic model building blocks (e.g., TTEthernet switches, TTEthernet end systems, fault injectors), which can be instantiated, configured and extended to model distributed embedded applications. In particular, these building blocks can be configured to support application-specific time-triggered schedules and communication topologies. The fault injector allows to evaluate the reliability in the presence of messages failures with given failure modes and failure rates. We demonstrate the simulation environment in an example scenario with two TTEthernet switches, multiple end systems and injected faults.
Mohammed Abuteir, Roman Obermaisser
INDIN2
2013 Composability and compositionality in CAN-based automotive systems based on bus and star topologies
abstract
Controller Area Network (CAN) is the most widely used field bus protocol in the automotive domain. The development process of today's cars follows the well established automotive V-Model. Traditional bus-based CAN makes the development an ever increasing challenge. For example, the introduction of a single additional CAN message influences the timing of already existing messages and thereby increases testing and integration efforts. The lack of composability and compositionality of traditional CAN leads to an overhead in the whole development cycle. In this paper we propose a development process that is based on a time-triggered CAN router. We examine the influence of our proposed development approach on major phases of the automotive V-Model. Our evaluation is based on CAN traffic of a mass-produced car by a major car manufacturer and a Fiel Programmable Gate Array (FPGA) based prototype implementation of the CAN router. From the results we gathered during our evaluation we conclude that a CAN router based development approach has the potential to simplify the development efforts that have to be undertaken by car manufactures.
Roland Kammerer, Bernhard Frömel, Roman Obermaisser, Paul Milbredt
INDIN3
2013 Ontology-based runtime reconfiguration of distributed embedded real-time systems
abstract
Embedded real-time systems with dynamic resource management capabilities are able to adapt to changing resource requirements, resource availability, the occurrence of faults and environmental changes. This enables better resource utilization, more flexibility and increased dependability. Depending on the application domain, reconfiguration decisions must be found and applied within temporal bounds. Although semantic techniques are used to react to unexpected events in standard IT systems, they exhibit a computational complexity and temporal unpredictability that is not suitable for real-time systems. This paper describes a temporally predictable framework for reconfigurable embedded real-time systems. It uses a service-oriented approach to dynamically reconfigure component interactions. Knowledge about the system structure and semantics is provided in a system ontology with relevant information for embedded realtime systems (e.g., transfer delay times, accuracy of relations). The ontology allows to automatically generate service substitutes by exploiting implicit redundancy in the system. Furthermore, an algorithm is presented that searches the ontology for semantically equivalent implementations of failed services. The process of substitution search and substitute service generation is demonstrated with an example from the automotive domain.
Oliver Höftberger, Roman Obermaisser
ISORC2
2013 Dependable and predictable time-triggered Ethernet networks with COTS components
Martin Elshuber, Roman Obermaisser
J. Syst. Archit.2
2012 Dynamic configuration of a time-triggered router for controller area network
abstract
The time-triggered router for CAN has as its goal to improves the dependability, performance and timeliness of CAN communication. The configuration of the CAN router includes knowledge about the permitted behavior of nodes in the time and value domains. Based on this configuration the CAN router performs fault isolation, diagnosis, message multicasting and message transformations. This paper presents architectural elements and algorithms for the modification of the router configuration at run-time. The router is realized as a Multi-Processor-System-on-a-Chip (MPSoC) and contains a dedicated hardware core for controlling the reconfiguration process. The configuration information is transferred to the cores responsible for the individual CAN segments through a time-triggered network-on-a-chip. We provide a solution for assured reconfiguration with predictable timing and continuity of service during the reconfiguration. An experimental evaluation demonstrates the bounded time for reconfiguration, as well as the seamless and consistent switching to new configurations.
Roland Kammerer, Roman Obermaisser
ETFA2
2011 Time-predictable and composable architectures for dependable embedded systems
abstract
Embedded systems must interact with their real-time environment in a timely and dependable fashion. Most embedded-systems architectures and design processes consider "non-functional" properties such as time, energy, and reliability as an afterthought, when functional correctness has (hopefully) been achieved. As a result, embedded systems are often fragile in their real-time behaviour, and take longer to design and test than planned. Several techniques have been proposed to make real-time embedded systems more robust, and to ease the process of designing embedded systems:
Saddek Bensalem, Kees Goossens, Christoph M. Kirsch, Roman Obermaisser, Edward A. Lee, Joseph Sifakis
EMSOFT4
2011 Component and service-oriented distributed embedded real-time systems (Extended papers from ISORC 2010)
Roman Obermaisser
Softw. Pract. Exp.1
2010 Modeling Time-Triggered Architecture Based Safety-Critical Embedded Systems Using SystemC
Jon Pérez 0001, Carlos F. Nicolás, Roman Obermaisser, Christian El Salloum
FDL3
2010 Executable Time-Triggered Model (E-TTM) for Real-Time Control Systems
abstract
The development of distributed real-time control-systems that must satisfy a certain set of timing constraints with an ever-increasing functionality leads to a considerable complexity growth. Tackling the complexity challenge and providing a consistent notion of time are key challenges, on which this research work is focused. The proposed Executable Time-Triggered Model (E-TTM) provides a deterministic (time and value domain) executable modeling approach for the composable development of distributed real-time control-systems. E-TTM provides a consistent notion of time and supports different strategies to tackle the complexity challenge such as abstraction, partition and segmentation. E-TTM metamodel has been implemented as a C++ library that extends SystemC with the time-triggered Model of Computation (MoC). This approach is illustrated with a case study.
Jon Pérez 0001, Antonio Perez, Roman Obermaisser
ISORC3
2010 A Cross-Domain Multi-Processor System-on-a-Chip for Embedded Real-Time Systems
abstract
GENESYS Multiprocessor System-on-a-Chip (MPSoC) is the building block of a generic platform for the component-based development of embedded real-time systems in different domains, such as in automotive, aerospace, industrial control, and consumer-electronic applications. The GENESYS MPSoC offers a stable set of domain-independent core services (e.g., common time, message-based communication, and configuration). On top of the core services, higher level services can be implemented by domain-independent and domain-specific system components that customize the platform to the needs of the specific application domain. Through its cross-domain applicability, the GENESYS MPSoC supports the wide reuse of components and realizes the benefits of the economies of scale of the semiconductor technology. Furthermore, the GENESYS MPSoC contributes towards the solution of prevalent technological challenges such as complexity management, robustness, and technology obsolescence. This paper presents the GENESYS MPSoC and provides insights from a prototype implementation, which demonstrates that such a cross-domain MPSoC can be built with today's technology.
Roman Obermaisser, Hermann Kopetz, Christian Paukovits
IEEE Trans. Ind. Informatics1
2009 Fundamental Design Principles for Embedded Systems: The Architectural Style of the Cross-Domain Architecture GENESYS
abstract
The GENESYS (Generic Embedded System) project is a European research project that aims to develop a cross-domain architecture for embedded systems. The requirements and constraints for such an architecture are documented in the ARTEMIS strategic research agenda in the form of seven key challenges. This paper presents the architectural style of GENESYS by listing the key architectural principles, such as: strict component orientation, separation of computation from communication, availability of a common time, hierarchical system structure, adherence to message passing, state awareness, fault isolation and integrated resource manage-ment. This paper explains how these architectural principles contribute to solve the seven key challenges in the ARTEMIS strategic research agenda.
Roman Obermaisser, Christian El Salloum, Bernhard Huber, Hermann Kopetz
ISORC1
2009 From a Federated to an Integrated Automotive Architecture
abstract
This paper describes an integrated system architecture for automotive electronic systems based on multicore systems-on-chips (SoCs). We integrate functions from different suppliers into a few powerful electronic control units using a dedicated core for each function. This work is fueled by technological opportunities resulting from recent advances in the semiconductor industry and the challenges of providing dependable automotive electronic systems at competitive costs. The presented architecture introduces infrastructure IP cores to overcome key challenges in moving to automotive multicore SoCs: a time-triggered network-on-a-chip with fault isolation for the interconnection of functional IP cores, a diagnostic IP core for error detection and state recovery, a gateway IP core for interfacing legacy systems, and an IP core for reconfiguration. This paper also outlines the migration from today's federated architectures to the proposed integrated architecture using an exemplary automotive E/E system.
Roman Obermaisser, Christian El Salloum, Bernhard Huber, Hermann Kopetz
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst.1
2008 Temporal and Spatial Partitioning of a Time-Triggered Operating System Based on Real-Time Linux
abstract
Real-time Linux variants are becoming prominent solutions for the development of embedded systems. Compared to traditional real-time operating systems, embedded system engineers can leverage solutions and knowhow from the Linux development community (e.g., development tools, applications, drivers). Due to the availability of implementations of Internet protocols and network drivers, Linux also facilitates the implementation of embedded systems connected to the Internet. The goal of this paper is to evaluate experimentally the capabilities of the Real-time Linux variant RTAI/LXRT with respect to partitioning between different application software modules. Partitioning ensures that a failure caused by a design fault in one application software module cannot propagate to cause a failure in other application software modules, e.g., by blocking access to the CPU or by overwriting memory. Partitioning is important when building mixed-criticality systems comprising both non safety-critical software modules and safety-related ones. Even at the same level of criticality, partitioning improves the robustness of an embedded system. The experimental results described in this paper point out several limitations of RTAI/LXRT Linux concerning fault isolation. Based on these results, we propose modifications to improve the partitioning with respect to temporal and spatial interference.
Roman Obermaisser, Bernhard Leiner
ISORC1
2008 Temporal Partitioning of Communication Resources in an Integrated Architecture
abstract
Integrated architectures in the automotive and avionic domain promise improved resource utilization and enable a better coordination of application subsystems compared to federated systems. An integrated architecture shares the system's communication resources by using a single physical network for exchanging messages of multiple application subsystems. Similarly, the computational resources (for example, memory and CPU time) of each node computer are available to multiple software components. In order to support a seamless system integration without unintended side effects in such an integrated architecture, it is important to ensure that the software components do not interfere through the use of these shared resources. For this reason, the DECOS integrated architecture encapsulates application subsystems and their constituting software components. At the level of the communication system, virtual networks on top of an underlying time-triggered physical network exhibit predefined temporal properties (that is, bandwidth, latency, and latency jitter). Due to encapsulation, the temporal properties of messages sent by a software component are independent from the behavior of other software components, in particular from those within other application subsystems. This paper presents the mechanisms for the temporal partitioning of communication resources in the dependable embedded components and systems (DECOS) integrated architecture. Furthermore, experimental evidence is provided in order to demonstrate that the messages sent by one software component do not affect the temporal properties of messages exchanged by other software components. Rigid temporal partitioning is achievable while at the same time meeting the performance requirements imposed by present-day automotive applications and those envisioned for the future (for example, X-by-wire). For this purpose, we use an experimental framework with an implementation of virtual networks on top of a time division multiple access (TDMA)-controlled Ethernet network.
Roman Obermaisser
IEEE Trans. Dependable Secur. Comput.1
2007 Periodic Finite-State Machines
abstract
Finite state machine (FSM) models are widely used to model the operations of computer systems. Since the basic FSM model is timeless, it is not possible to model within the basic FSM framework system properties that are dependent on the progression of real time, such as the duration of computations or the limited temporal validity of real-time data. To overcome these limitations, efforts have been made to modify the FSM model to include some notion of time. It is the objective of this paper to expand existing work on basic FSMs and timed automata to include the concept of a sparse global time base as a central element of the model. We call such an extended FSM model a periodic finite state machine (PFSM) model. The PFSM model also incorporates the notions of state variables, global time, periodic clock constraints, and time-triggered activities. Thereby, PFSMs enable a concise and intuitive representation of distributed control systems and reduce the gap between a modeled system and its implementation
Hermann Kopetz, Christian El Salloum, Bernhard Huber, Roman Obermaisser
ISORC4
2007 A Model-Driven Framework for the Generation of Gateways in Distributed Real-Time Systems
abstract
As part of the DECOS architecture, this paper presents a generic framework for gateways, which enable message exchanges across application subsystem boundaries in order to exploit redundancy and to coordinate the behavior of application subsystems. In the DECOS architecture, networks of different application subsystem can exhibit property mis matches, such as different protocols (e.g., CAN protocol vs. time-triggered communication), divergent syntax, and incoherent naming. Gateways provide a systematic solution for resolving these property mismatches. Within a gateway, a real-time database separates the application subsystems and stores temporally accurate real-time images. Controlled by a formal gateway specification based on an extension of timed automata, a gateway acquires messages from one gateway side to update these real-time images and recombines the real-time images into messages for the other gateway sides. In a prototype implementation, development tools use such a formal gateway specification expressed as a UML model as an input and automatically generate a configuration module for the parameterization of a generic architectural gateway service to a specific application.
Roman Obermaisser
RTSS1
2007 A Comparison of Partitioning Operating Systems for Integrated Systems
Bernhard Leiner, Martin Schlager, Roman Obermaisser, Bernhard Huber
SAFECOMP3
2007 An integrated architecture for future car generations
Roman Obermaisser, Philipp Peti, Fulvio Tagliabo
Real Time Syst.1
2006 Investigating Connector Faults in the Time-Triggered Architecture
abstract
In the context of distributed real-time systems as deployed in the avionic and the automotive domain a substantial number of system malfunctions result from connector faults. For instance, a middle class car has more than 40 electronic control units (ECUs) interconnected by a heterogenous network infrastructure consisting of hundreds of wires and connections. Connector faults such as loose contacts impose a challenging task for the technician at the service station. This paper investigates to what extent the use of time-triggered communication protocols, in particular the TTP C2 communication controller, helps in identifying connector faults. We perform fault injection campaigns to judge whether the status information provided by the TTP C2 controller is sufficient for the detection of connector faults. The derived results constitute an important input for online analysis mechanisms
Philipp Peti, Roman Obermaisser, Harald Paulitsch
ETFA2
2006 Realization of virtual networks in the DECOS integrated architecture
abstract
Due to the better utilization of computational and communication resources and the improved coordination of application subsystems, designers of large distributed embedded systems (e.g., in the automotive domain) are eager to replace existing federated architectures with integrated ones. This paper focuses on the communication infrastructure of the DECOS integrated system architecture, which realizes for each application subsystem a so-called virtual network as an overlay network on top of a time-triggered communication protocol. Since all virtual networks share a single physical network, virtual networks promise massive cost savings through the reduction of physical networks and reliability improvements with respect to wiring and connectors. Furthermore, virtual networks support application subsystems that range from ultra-dependable control applications (e.g., an X-by-wire system) to non safety-critical applications such as comfort systems. For this reason, two classes (event-triggered and time-triggered) of virtual networks are realized. Encapsulation mechanisms ensure that the temporal properties of each virtual network are known a priori and independent from the communication activities in other virtual networks. In order to ensure that the virtual network abstractions hold also in the case of software faults, each application subsystem possesses a dedicated virtual network with statically assigned resources at the underlying time-triggered communication service
Roman Obermaisser, Philipp Peti
IPDPS1
2006 MDA-Based Development in the DECOS Integrated Architecture - Modeling the Hardware Platfor
abstract
Reduced time-to-market in spite of increasing the system's functionality, reuse of software on different hardware platforms, and the demand for performing validation activities earlier in the development phase raise the need for revising the state-of-the-art development methodologies for distributed embedded systems. The model driven architecture is a design methodology addressing these emerging requirements. Developing embedded systems according to this model-based paradigm requires a platform-independent representation of the functionality of the application as well as a precise model of the targeted hardware platform. In this paper we introduce a meta-model for capturing the resources of hardware platforms realizing the DECOS architecture, which is an integrated time-triggered architecture aimed at the development of distributed embedded systems. Furthermore, we present a tool chain based on this meta-model that speeds up the modeling process and reduces the likelihood of human errors by facilitating the reuse of hardware building blocks from libraries
Bernhard Huber, Roman Obermaisser, Philipp Peti
ISORC2
2006 Diagnostic Framework for Integrated Time-Triggered Architectures
abstract
Integrated architectures promise substantial technical and economic benefits in the development of distributed embedded real-time systems. In the context of diagnosis new diagnostic strategies can be applied by taking the physical and functional structure of an integrated system into account. In this paper we present a diagnostic framework that is designed to tackle prevalent diagnostic problems industry is currently facing, such as the trouble-not-identified phenomenon in electronic systems. So-called out-of-norm assertions (ONAs) are employed that combine diagnostic information to correlate experienced failures in order to decide on the type fault (e.g., transient vs. permanent, internal vs. external) affecting the system. Based on a prototype implementation of the integrated time-triggered DECOS architecture we show the feasibility of this diagnostic strategy
Philipp Peti, Roman Obermaisser
ISORC2
2006 Reuse of CAN-Based Legacy Applications in Time-Triggered Architectures
abstract
Upcoming car series will be deployed with time-triggered communication protocols due to benefits with respect to bandwidth, predictability, dependability, and system integration. In present day automotive networks, controller area network (CAN) is the most widely used communication protocol. Today, up to five CAN buses and several private CAN networks result from the bandwidth limits of CAN in conjunction with constraints concerning bus utilization aimed at controlling transmission latencies. In this context, the upcoming introduction of time-triggered networks into series production offers the potential to reduce the number of CAN networks by exploiting the high bandwidth of the time-triggered network instead of CAN buses. Due to the elimination of CAN buses, the resulting reduction of wiring and connectors promises a significant reduction in hardware cost and reliability improvements. In order to support the reuse of existing CAN-based application software, this paper presents a solution for the emulation of a CAN communication service on top of an underlying time-triggered network. By providing to CAN-based applications the same interface as in a conventional CAN system, redevelopment efforts for CAN-based legacy software are minimized. For this purpose, a CAN emulation middleware operates between a operating system and the CAN-based applications. In a first step, the middleware establishes event channels on top of the communication network in order to support on-demand transmission requests at a priori unknown points in time. The middleware then emulates the carrier sense multiple access collision avoidance (CSMA/CA) media access protocol of a physical CAN network for passing messages received via event channels to the application in the correct temporal order. Finally, the application programming interface (API) of the widely used HIS/VectorCAN driver provides a handle-based programming interface with support for message filtering and callbacks. A validation setup with a time-triggered protocol (TTP) cluster demonstrates that the CAN emulation can handle CAN-based legacy software and a real-world communication matrix provided by the automotive industry
Roman Obermaisser
IEEE Trans. Ind. Informatics1
2005 An Integrated Architecture for Future Car Generations
abstract
Depending on the physical structuring of large distributed safety-critical real-time systems, one can distinguish federated and integrated system architectures. The DECOS architecture combines the complexity management advantages of federated systems with the functional integration and hardware benefits of an integrated approach. This paper investigates the benefits of the DECOS integrated system architecture as an electronic infrastructure for future car generations. The shift to an integrated architecture results in quantifiable cost reductions in the areas of system hardware cost and system development. In the paper we present a current federated Fiat car E/E architecture and discuss a possible mapping to an integrated solution based on the DECOS architecture. The proposed architecture provides a foundation for mixed-criticality integration with both safety-critical and non safety-critical subsystems. In particular, this architecture supports applications up to the highest criticality classes (10/sup -9/ failures per hour), thereby taking into account the emerging dependability requirements of by-wire functionality in the automotive industry.
Philipp Peti, Roman Obermaisser, Fulvio Tagliabo, Antonio Marino, Stefano Cerchio
ISORC2
2005 Out-of-Norm Assertions
abstract
The increasing use of electronics in transport systems, such as the automotive and avionic domain, has lead to dramatic improvements with respect to functionality, safety, and cost. However, with this growth of electronics the likelihood of failures due to faults originating from electronic equipment also increases. Although permanent failure rates are constantly diminishing due to improvements in manufacturing, the downsizing of semiconductor features has lead to a significant increase in transient system disturbances. Furthermore, transients are frequently the precursors of upcoming permanent failures. In order to cope with this development, a diagnostic subsystem must especially be designed to detect and analyze such transients to reduce the failure-not-found ratio in today's systems. Therefore, diagnostic detection mechanisms must be devised that refrain from traditional error detection techniques operating only on component-local data in favor of a system-wide view to detect and analyze correlated failures and infer the corresponding fault. In this work, we present out-of-norm assertions (ONAs) as a diagnostic mechanism operating on the distributed state to detect correlated component malfunction. ONAs take the characteristics of faults in the time, value and space domain into account in order to discriminate between different types of faults that are affecting the operation of the distributed system. Since ONAs are specified on the interface state mutual error detection of interface state variables is performed. In contrast to bivalent assertions that need to indisputably decide on correct or incorrect system states at the time of occurrence, the proposed ONAs are also useful in the detection of system irregularities that cannot be forced into the predominant bivalent assessment scheme.
Philipp Peti, Roman Obermaisser, Hermann Kopetz
IEEE Real-Time and Embedded Technology and Applications Symposium2