Tullio Vardanega

dblp:81/2051 · DBLP profile ↗
← Back
59ranked-venue papers
11as first author
9since 2021 · last 2025
0000-0002-0089-0889ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 21 · 2 first-author · 5 since 2021Software engineering, systems software and programming languages · 12 · 4 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 6 · 1 first-authorHuman-computer interaction and ubiquitous computing · 3 · 1 first-author · 2 since 2021Computer networks · 2 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2025 Live migration of compiled Wasm modules across the Compute Continuum
abstract
The compute continuum is a model of deployment and computation that envelopes the Cloud and the Edge into a seamless runtime infrastructure. Vast heterogeneity at the Edge is one of the main challenges of the continuum. A lightweight uniform runtime, such as the one offered by WebAssembly (Wasm) may be an apt response to that. The other main challenge is the occasional need for computations to relocate. This happens when local resources are insufficient or inadequate to meet the application requirements or when location changes in the physical world require the computation to move with them. The notion of live migration applied to Wasm computations is not new. Yet, state-of-the-art solutions focus on either non-standard Wasm runtimes or interpreted modules. Supporting live migration for compiled modules across heterogeneous nodes is still an open challenge. This paper presents a mechanism to meet that need. By injecting checkpoint and restore procedures into a function bytecode within a Wasm module, we enable it to save its execution state and resume from it after a migration event. This paper presents two strategies for that, one of which with notably small run-time overhead. To assess the quality of the proposed strategies, we performed an empirical evaluation based on an open-source benchmark. The tools developed in this work are entirely open-source.
Edoardo Tinto, L. Marchiori, Tullio Vardanega
J. Syst. Archit.3
2024 A runtime infrastructure for the Continuum of Computing
abstract
Devices at the Edge of the network are experiencing a considerable increase in computational resources. At the same time, connectivity becomes more pervasive. These phenomena jointly facilitate the emergence of a new computational model, increasingly referred to as the Continuum of Computing. This model aims at including Edge resources in Cloud-like (and Cloud-inclusive) resource pooling to accommodate computations that need reduced latency, increased privacy, and general mobility. This model has the potential to enhance the power and the reach of high-performance computing (HPC) applications, making them extend up to the Edge of the network. However, managing a pool of resources that span across both Cloud and Edge nodes poses new challenges. Moving data across the network generates latency and security issues, while national policies may outright limit data mobility. This suggests moving computation towards data instead of the usual opposite. Enabling migrating computation is one of key traits of the envisioned Continuum of Computing. The vast heterogeneity in the technological stacks and the lack of uniform standards, however, hinder the deployment of applications in the Continuum. The availability of a common runtime environment across all host nodes of the Continuum is an obvious way to circumvent those problems, reviving the write-once-run-anywhere promise in that context. The ability to move computations opportunistically after user-specific performance objectives is another key trait of the Continuum model, which also is a foundation to spatial computing, a context-aware and space-aware computing paradigm. How to effectively orchestrate migrating computations so that they can deliver value added to their users is still an open question. There is a general understanding that Cloud-native orchestrators perform poorly when shifting towards the Edge, due to exceedingly restrictive (Cloud-centric) assumptions underneath their orchestration model. The matter of efficient orchestration in the Continuum is paramount in the envisioned model. To showcase the feasibility and viability of a Continuum-worthy runtime infrastructure, we singled out two emerging technologies: Rust and WebAssembly. The Rust programming language's highlight is its statically-checked memory safety. WebAssembly's highlights are solid guarantees of isolation and a portable bytecode format for applications compiled for its Instruction Set Architecture (ISA). To this project, WebAssembly components written in Rust constitute the candidate building blocks for the Continuum infrastructure, centred on memory-safe and sand-boxed execution capsules. In addition to that, this project aims to develop and deploy Continuum-worthy orchestration capabilities that leverage seamless migration.
Edoardo Tinto, Tullio Vardanega
HPDC2
2024 Experimental Analysis of First-Grade Students' Block-Based Programming Problem Solving Processes
abstract
This work presents an experimental analysis of first-grade students' block-based programming trajectories. These trajectories consist of edit-level program snapshots that capture learners' problem-solving processes in a navigational microworld. Our results highlight the potential of this fine-grained data capture. Snapshot frequencies in trajectories collected before and after a coding intervention showcase the collective progress of the learners. Graph visualizations, in which nodes represent snapshots and directed edges code edits, highlight strategies, pitfalls and debugging procedures. Individual programming trajectories shed light on details of learners' problem-solving processes that less granular analysis would conceal. Various works in the field of Learning Analytics research show the usefulness of collecting fine-grained process data that proceed from programming activities. However, how to analyze this data is still an open question and research on the subject is in an experimental phase. We contribute to this experimentation by analyzing and discussing results collected from 30 first-grade students in a pretest-posttest study.
Gabriele Pozzan, Costanza Padova, Chiara Montuori, Barbara Arfé, Tullio Vardanega
ITiCSE (1)5
2024 Providing spatial isolation for Mixed-Criticality Systems
abstract
Hard real-time systems, characterized by stringent timeliness requirements, occur in an increasing variety of industrial sectors. Some such domains carry important safety-critical concerns, notably avionics, space, and automotive. One common design trend across those domains seeks to reduce the number of computing devices embedded in them by integrating software applications of different criticality levels into one and the same onboard computer. A safety-savvy design approach however requires isolation among components of different criticality, to prevent unintended reciprocal interference across them. Isolation is traditionally achieved through partitioning. Partitioning, however, incurs low resource utilization as cautionary margins are used to inflate partition budgets over their anticipated needs. This situation has prompted research into alternative ways to integration that can safely afford higher levels of utilization. The Mixed-Criticality (MC) approach, which concentrates on the CPU scheduling problem, has yielded a large body of research results that show considerable gains in sustained utilization, but it has yet to meet all of the isolation requirements of safety-critical systems. This work presents a solution to augment a state-of-the-art MC solution with efficient and effective spatial isolation capabilities. Experimental results show that our solution provides adequate guarantees of temporal and spatial isolation with very small runtime overhead.
Edoardo Tinto, Tullio Vardanega
J. Syst. Archit.2
2023 Learning Iteration for Grades 2-3: Puzzles vs. UMC in Code.org
abstract
In a project partially supported by research grant PANN20_00690 to Italy's CINI National Lab "Informatica e Scuola", we compared the effectiveness of two alternative instructional methods applied to scaffold the learning of iterations for children at grades 2-3. Eight university groups across the Country collaboratively run the project in two successive rounds throughout the year 2022. Teachers' feedback collected across the two rounds helped fine-tune the deployment of the interventions. The experiment results show that the two alternative interventions have measurable outcome differences in the short term.
Enrico Nardelli, Francesco Lacchia, Renzo Davoli, Michael Lodi, Marco Sbaraglia, Veronica Rossano, Enrica Gentile, Violetta Lonati, Mattia Monga, Anna Morpurgo, Luca Forlizzi, Giovanna Melideo, Sara Capecchi, Ilenia Fronza, Tullio Vardanega
SIGCSE (2)15
2022 Automatic Distributed Deep Learning Using Resource-Constrained Edge Devices
abstract
Processing data generated at high volume and speed from the Internet of Things, smart cities, domotic, intelligent surveillance, and e-healthcare systems require efficient data processing and analytics services at the Edge to reduce the latency and response time of the applications. The fog computing edge infrastructure consists of devices with limited computing, memory, and bandwidth resources, which challenge the construction of predictive analytics solutions that require resource-intensive tasks for training machine learning models. In this work, we focus on the development of predictive analytics for urban traffic. Our solution is based on deep learning techniques localized in the Edge, where computing devices have very limited computational resources. We present an innovative method for efficiently training the gated recurrent-units (GRUs) across available resource-constrained CPU and GPU Edge devices. Our solution employs distributed GRU model learning and dynamically stops the training process to utilize the low-power and resource-constrained Edge devices while ensuring good estimation accuracy effectively. The proposed solution was extensively evaluated using low-powered ARM-based devices, including Raspberry Pi v3 and the low-powered GPU-enabled device NVIDIA Jetson Nano, and also compared them with Single-CPU Intel Xeon machines. For the evaluation experiments, we used real-world Floating Car Data. The experiments show that the proposed solution delivers excellent prediction accuracy and computational performance on the Edge when compared to the baseline methods.
Alberto Gutierrez-Torre, Kiyana Bahadori, Shuja-ur-Rehman Baig, Waheed Iqbal, Tullio Vardanega, Josep Lluís Berral, David Carrera 0001
IEEE Internet Things J.5
2022 Evaluating a multicore Mixed-Criticality System implementation against a temporal isolation kernel
Mattia Bottaro, Tullio Vardanega
J. Syst. Archit.2
2022 Rafting multiplayer video games
abstract
Abstract Consensus is a central concern for distributed systems, paramount for fault‐tolerant applications. Online multiplayer (video) games are an attractive instance of highly distributed application, where user experience requires resilience provisioning that includes distributed consensus. In this work, we report on experiments we performed on the use of the Raft consensus algorithm in two Proof‐of‐Concept instances of famous video games. Our experiments aim to show the feasibility of such a novel architectural approach, and to assess the ensuing scalability quantitatively against game‐specific performance metrics. To enable the transferability of this effort, we discuss our implementation choices and testing method, as well as the findings from said empirical evaluation.
Gabriele Pozzan, Tullio Vardanega
Softw. Pract. Exp.2
2021 Removing bias from the judgment day: A Ravenscar-based toolbox for quantitative comparison of EDF-to-RM uniprocessor scheduling
Dilan Perale, Tullio Vardanega
J. Syst. Archit.2
2020 A new start: Introducing the journal-track proceedings of the 24th Ada-Europe conference on reliable software technologies
Tullio Vardanega
J. Syst. Archit.1
2018 Designing and Implementing Elastically Scalable Services - A State-of-the-art Technology Review
abstract
The prospect of fast and affordable on-demand service delivery over the Internet proceeds from the very notion of Cloud Computing. For service providers, the ability to afford those benefits to the user is contingent on attaining rapid elasticity in service design and implementation, which is a very open research goal as yet. With a view to this challenge, this paper draws a trajectory that, starting from a better understanding of the principal service design features, relates them to the microservice architectural style and its implications on elastic scalability, most notably dynamic orchestration, and concludes reviewing how well state-of-the-art technology fares for their implementation.
Kiyana Bahadori, Tullio Vardanega
CLOSER2
2018 A two-staged capstone project to foster university-business dialogue
abstract
Capstone projects improve the endowments of knowledge, ability and skills earned by higher-education students, and help intensify the university-business dialogue. While not solely suited for BSc curricula, capstones raise the employability of BSc graduates, whose market value is intrinsically inferior to their MSc correspondents, yet highly attractive thanks to shorter turn-around time. Designing a BSc curriculum in Computer Science after those premises requires balancing two forces. One is traditional content-centered teaching, which has many adepts and exerts higher pressure on the shorter duration of the study path. The other is learner-centered teaching, which promotes active teaching strategies, and makes room for capstone inserts. This paper discusses how the University of Padua went around that challenge designing its BSc curriculum in Computer Science in 2002, and critically assesses its outcome to date. 27 credit hours of the total 180 in the novel curriculum were devolved to a capstone project comprising an internship in business, whose critical review feeds the final exam. The capstone was organized as a two-staged progression: (a) the first leg being a preparatory, learning-for-work collaborative laboratory aimed at the acquisition of soft skills, and exposure to technology innovation challenges; and (b) the second leg promoting a learning-through-work individual internship. Evaluation of field data from 14 cohorts of graduates, from 07/2004 to 12/2017, shows that the BSc curriculum has met with the appreciation of students and employers, and it has served well the purpose of boosting the university-business dialogue.
Tullio Vardanega, Monica Fedeli
ITiCSE1
2018 Fitting Software Execution-Time Exceedance into a Residual Random Fault in ISO-26262
abstract
Car manufacturers relentlessly replace or augment the functionality of mechanical subsystems with electronic components. Most such subsystems (e.g., steer-by-wire) are safety related, hence, subject to regulation. ISO-26262, the dominant standard for road vehicles, regards software faults as systematic, while differentiating hardware faults between systematic and random. The analysis of systematic faults entails rigorous processes and qualitative considerations. The increasing complexity of modern on-board computers, however, questions the very notion of treating the violation of execution-time envelopes for software programs as a systematic fault. Modern hardware in fact reduces the user's ability to delve deep enough into the fabric of hardware-software interaction to gage its extent of contribution to the worst-case execution time (WCET). Changing the nature of the WCET-analysis problem may help address that challenge effectively. To this end, we propose a solution that should allow ISO-26262 to quantify the likelihood of execution-time exceedance events, relating it to target failure metrics employed in support of certification arguments, similarly to random faults in hardware. To this end, we inject randomization in the timing behavior of the computer hardware to relieve the user from the need to control hard-to-reach low-level parts, and use measurement-based probabilistic timing analysis to quantify, constructively, the failure rates resulting from the likelihood of execution-time exceedance events.
Irune Agirre, Francisco J. Cazorla, Jaume Abella 0001, Carles Hernández 0001, Enrico Mezzetti, Mikel Azkarate-askatsua, Tullio Vardanega
IEEE Trans. Reliab.7
2017 EPC Enacted: Integration in an Industrial Toolbox and Use against a Railway Application
abstract
Measurement-based timing analysis approaches are increasingly making their way into several industrial domains on account of their good cost-benefit ratio. The trustworthiness of those methods, however, suffers from the limitation that their results are only valid for the particular paths and execution conditions that the user is able to explore with the available input vectors. It is generally not possible to guarantee that the collected measurements are fully representative of the worst-case timing behaviour. In the context of measurement-based probabilistic timing analysis, the Extended Path Coverage (EPC) approach has been recently proposed as a means to extend the representativeness of measurement observations, to obtain the same effect of full path coverage. At the time of its first publication, EPC had not reached an implementation maturity that could be trialled industrially. In this work we analyze the practical implications of using EPC with real-world applications, and discuss the challenges in integrating it in an industrial-quality toolchain. We show that we were able to meet EPC requirements and successfully evaluate the technique on a real Railway application, on top of a commercial toolchain and full execution stack.
Enrico Mezzetti, Mikel Fernández, Alen Bardizbanyan, Irune Agirre, Jaume Abella 0001, Tullio Vardanega, Francisco J. Cazorla
RTAS6
2017 Computing Safe Contention Bounds for Multicore Resources with Round-Robin and FIFO Arbitration
abstract
Numerous researchers have studied the contention that arises among tasks running in parallel on a multicore processor. Most of those studies seek to derive a tight and sound upper-bound for the worst-case delay with which a processor resource may serve an incoming request, when its access is arbitrated using time-predictable policies such as round-robin or FIFO. We call this value upper-bound delay (ubd). Deriving trustworthy ubd statically is possible when sufficient public information exists on the timing latency incurred on access to the resource of interest. Unfortunately however, that is rarely granted for commercial-of-the-shelf (COTS) processors. Therefore, the users resort to measurement observations on the target processor and thus compute a “measured” ubdm. However, using ubdm to compute worst-case execution time values for programs running on COTS multicore processors requires qualification on the soundness of the result. In this paper, we present a measurement-based methodology to derive a ubdm under round-robin (RoRo) and first-in-first-out (FIFO) arbitration, which accurately approximates ubd from above, without needing latency information from the hardware provider. Experimental results, obtained on multiple processor configurations, demonstrate the robustness of the proposed methodology.
Gabriel Fernandez 0002, Javier Jalle, Jaume Abella 0001, Eduardo Quiñones, Tullio Vardanega, Francisco J. Cazorla
IEEE Trans. Computers5
2016 PROXIMA: Improving Measurement-Based Timing Analysis through Randomisation and Probabilistic Analysis
abstract
The use of increasingly complex hardware and software platforms in response to the ever rising performance demands of modern real-time systems complicates the verification and validation of their timing behaviour, which form a time-and-effort-intensive step of system qualification or certification. In this paper we relate the current state of practice in measurement-based timing analysis, the predominant choice for industrial developers, to the proceedings of the PROXIMA (Probabilistic real-time control of mixed-criticality multicore systems) project in that very field. We recall the difficulties that the shift towards more complex computing platforms causes in that regard. Then we discuss the probabilistic approach proposed by PROXIMA to overcome some of those limitations. We present the main principles behind the PROXIMA approach as well as the changes it requires at hardware or software level underneath the application. We also present the current status of the project against its overall goals, and highlight some of the principal confidence-building results achieved so far.
Francisco J. Cazorla, Jaume Abella 0001, Jan Andersson, Tullio Vardanega, Francis Vatrinet, Iain Bate, Ian Broster, Mikel Azkarate-askatsua, Franck Wartel, Liliana Cucu-Grosjean, Fabrice Cros, Glenn Farrall, Adriana Gogonel, Andrea Gianarro, Benoit Triquet, Carles Hernández 0001, Code Lo, Cristian Maxim, David Morales, Eduardo Quiñones, Enrico Mezzetti, Leonidas Kosmidis, Irune Agirre, Mikel Fernández, Mladen Slijepcevic, Philippa Conmy, Walid Talaboulma
DSD4
2016 An automated framework for the timing analysis of applications for an automotive multicore processor
abstract
The inter-core interference that affects multicore processors highly complicates the timing analysis of embedded applications. The contribution of the execution-time penalty that software programs incur on access to hardware shared resources is hard to estimate, as it depends on both the resource arbitration policy and the quantity and activity of co-runners. An interesting vicious circle arises: the execution-time behavior of the application of interest must be known to determine its best allocation to a processor core; this decision however determines the actual set of co-runners, which in turns effects the inter-core interference suffered by the application of interest and consequently its execution-time behavior. This work presents a framework that aids the timing analysis of applications in presence of inter-core interference and addresses the cited circular dependency by providing a suite of synthetic co-runners designed to access hardware shared resources to produce fine-grained controlled interference. The framework specifically targets the Aurix Tricore family of processors designed by Infineon for the automotive domain, and includes a highly integrated toolchain to build, execute and trace applications. The toolchain includes a tailored version of Erika Enterprise, modified to exhibit time-composable behavior at run time, and the RT-Druid build environment. The paper includes an evaluation of the timing behavior of a real-world automotive application, adapted to fit the run-time target of choice and trialed under different levels of inter-core interference.
Davide Compagnin, Tullio Vardanega
ETFA2
2015 Increasing confidence on measurement-based contention bounds for real-time round-robin buses
abstract
Contention among tasks concurrently running in a multicore has been deeply studied in the literature specially for on-chip buses. Most of the works so far focus on deriving exact upper-bounds to the longest delay it takes a bus request to be serviced (ubd), when its access is arbitrated using a time-predictable policy such as round-robin. Deriving ubd for a bus can be done accurately when enough timing information is available, which is not often the case for commercial-of-the-shelf (COTS) processors. Hence, ubd is approximated (ubdm) by directly experimenting on the target processor, i.e by measurements. However, using ubdm makes the timing analysis technique to resort on the accuracy of ubdm to derive trustworthy worst-case execution time estimates. Therefore, accurately estimating ubd by means of ubdm is of paramount importance. In this paper, we propose a systematic measurement-based methodology to accurately approximate ubd without knowing the bus latency or any other latency information, being only required that the underlying bus policy is round-robin. Our experimental results prove the robustness of the proposed methodology by testing it on different bus and processor setups.
Gabriel Fernandez 0002, Javier Jalle, Jaume Abella 0001, Eduardo Quiñones, Tullio Vardanega, Francisco J. Cazorla
DAC5
2015 Resource usage templates and signatures for COTS multicore processors
abstract
Upper bounding the execution time of tasks running on multicore processors is a hard challenge. This is especially so with commercial-off-the-shelf (COTS) hardware that conceals its internal operation. The main difficulty stems from the contention effects on access to hardware shared resources (e.g., buses) which cause task's timing behavior to depend on the load that co-runner tasks place on them. This dependence reduces time composability and constrains incremental verification. In this paper we introduce the concepts of resource-usage signatures and templates, to abstract the potential contention caused and incurred by tasks running on a multicore. We propose an approach that employs resource-usage signatures and templates to enable the analysis of individual tasks largely in isolation, with low integration costs, producing execution time estimates per task that are easily composable throughout the whole system integration process. We evaluate the proposal on a 4-core NGMP-like multicore architecture.
Gabriel Fernandez 0002, Javier Jalle, Jaume Abella 0001, Eduardo Quiñones, Tullio Vardanega, Francisco J. Cazorla
DAC5
2015 Timing analysis of an avionics case study on complex hardware/software platforms
Franck Wartel, Leonidas Kosmidis, Adriana Gogonel, Andrea Baldovin, Zoë Stephenson, Benoit Triquet, Eduardo Quiñones, Code Lo, Enrico Mezzetti, Ian Broster, Jaume Abella 0001, Liliana Cucu-Grosjean, Tullio Vardanega, Francisco J. Cazorla
DATE13
2015 IEC-61508 SIL 3 Compliant Pseudo-Random Number Generators for Probabilistic Timing Analysis
abstract
Probabilistic Timing Analysis (PTA), especially its measurement based variant (MBPTA), has shown to be competitive with state-of-the-art timing analysis techniques. The use of MBPTA to analyse the timing behaviour of safety-critical systems rests on its ability to derive trustworthy WCET bounds. This ability depends on the soundness of the MBPTA method per se, as well as on the satisfaction of safety requirements placed on the pseudo-random number generator (prng) that plays a key role in the platform-level randomisation needed by MBPTA. This paper presents the design of a low-area, low-power prng that meets IEC-61508 SIL 3 safety requirements and allows for seamless integration in a real-world multicore architecture. This work enables the development and the IEC-61508 certification of mixed-criticality systems that use MBPTA for deriving timing bounds for mixed-criticality software programs running on multicore processors.
Irune Agirre, Mikel Azkarate-askatsua, Carles Hernández 0001, Jaume Abella 0001, Jon Pérez 0001, Tullio Vardanega, Francisco J. Cazorla
DSD6
2015 Experimental Evaluation of Optimal Schedulers Based on Partitioned Proportionate Fairness
abstract
The Quasi-Partitioning Scheduling algorithm optimally solves the problem of scheduling a feasible set of independent implicit-deadline sporadic tasks on a symmetric multiprocessor. It iteratively combines bin-packing solutions to determine a feasible task-to-processor allocation, splitting task loads as needed along the way so that the excess computation on one processor is assigned to a paired processor. Though different in formulation, QPS belongs in the same family of schedulers as RUN, which achieve optimality using a relaxed (partitioned) version of proportionate fairness. Unlike RUN, QPS departs from the dual schedule equivalence, thus yielding a simpler implementation with less use of global data structures. One might therefore expect that QPS should outperform RUN in the general case. Surprisingly instead, our implementation of QPS on LITMUS^RT invalidates this conjecture, showing that the QPS offline decisions may have an important influence on run-time performance. In this work, we present an extensive comparison between RUN and QPS, looking at both the offline and the online phases, to highlight their relative strengths and weaknesses.
Davide Compagnin, Enrico Mezzetti, Tullio Vardanega
ECRTS3
2015 Seeking Time-Composable Partitions of Tasks for COTS Multicore Processors
abstract
The timing verification of real-time single core systems involves a timing analysis step that yields an Execution Time Bound (ETB) for each task, followed by a schedulability analysis step, where the scheduling attributes of the individual tasks, including the ETB, are studied from the system level perspective. The transition between those two steps involves accounting for the interference effects that arise when tasks contend for access to shared resource. The advent of multicore processors challenges the viability of this two-step approach because several complex contention effects at the processor level arise that cause tasks to be unable to make progress while actually holding the CPU, which are very difficult to tightly capture by simply inflating the tasks' ETB. In this paper we show how contention on access to hardware shared resources creates a circular dependence between the determination of tasks' ETB and their scheduling at runtime. To help loosen this knot we present an approach that acknowledges different flavors of time compos ability, examining in detail the variant intended for partitioned scheduling, which we evaluate on two real processor boards used in the space domain.
Gabriel Fernandez 0002, Jaume Abella 0001, Eduardo Quiñones, Luca Fossati, Marco Zulianello, Tullio Vardanega, Francisco J. Cazorla
ISORC6
2015 EPC: Extended Path Coverage for Measurement-Based Probabilistic Timing Analysis
abstract
Measurement-based probabilistic timing analysis (MBPTA) computes trustworthy upper bounds to the execution time of software programs. MBPTA has the connotation, typical of measurement-based techniques, that the bounds computed with it only relate to what is observed in actual program traversals, which may not include the effective worst-case phenomena. To overcome this limitation, we propose Extended Path Coverage (EPC), a novel technique that allows extending the representativeness of the bounds computed by MBPTA. We make the observation data probabilistically path-independent by modifying the probability distribution of the observed timing behaviour so as to negatively compensate for any benefits that a basic block may draw from a path leading to it. This enables the derivation of trustworthy upper bounds to the probabilistic execution time of all paths in the program, even when the user-provided input vectors do not exercise the worst-case path. Our results confirm that using MBPTA with EPC produces fully trustworthy upper bounds with competitively small overestimation in comparison to state-of-the-art MBPTA techniques.
Marco Ziccardi, Enrico Mezzetti, Tullio Vardanega, Jaume Abella 0001, Francisco J. Cazorla
RTSS3
2014 Measurement-Based Probabilistic Timing Analysis and Its Impact on Processor Architecture
abstract
Critical Real-Time Embedded Systems (CRTES) industry needs increasingly complex hardware to attain the performance/cost ratio required to keep competitive edge in the market. Worst-case execution time (WCET) analysis is central to CRTES development. Whereas current timing analysis techniques are sound, their viability is hampered by the soaring cost of acquiring detailed knowledge of the internal operation and state of the system, at both software and hardware level. This is a major hurdle to using them for increasingly complex hardware platforms. Measurement-Based Probabilistic Timing Analysis (PTA) reduces the cost of acquiring the knowledge needed for computing trustworthy WCET bounds. This paper presents the changes required to hardware design to facilitate the use of the PTA techniques.
Leonidas Kosmidis, Eduardo Quiñones, Jaume Abella 0001, Tullio Vardanega, Ian Broster, Francisco J. Cazorla
DSD4
2014 Heart of Gold: Making the Improbable Happen to Increase Confidence in MBPTA
abstract
Measurement-Based Probabilistic Timing Analysis (MBPTA) has been recently proposed as a viable method to compute probabilistic worst-case execution time (pWCET) bounds for programs with hard real-time constraints. As a key trait, MBPTA needs a comparatively small number of observation runs, made on execution platforms to which MBPTA can be applied, to project the tail of the probability of occurrence of worst-case execution time durations of individual programs. In order for the use of MBPTA to fit the bill of industrial-quality development, it is imperative to understand what factors might threaten the trustworthiness of the pWCET computation. This paper addresses that important question by: (i) identifying the combined characteristics of applications and hardware resources that might lead to optimistic pWCET bounds, (ii) describing why this may occur, and (iii) providing the user with means to detect those cases so that trustworthiness is restored. In particular, we present a method for detecting risk scenarios for time-randomised caches, based on principles that apply to any other time-randomised resource which may challenge the application of MBPTA.
Jaume Abella 0001, Eduardo Quiñones, Franck Wartel, Tullio Vardanega, Francisco J. Cazorla
ECRTS4
2014 Putting RUN into Practice: Implementation and Evaluation
abstract
The Reduction to UNiprocessor (RUN) algorithm represents an original approach to multiprocessor scheduling that exhibits the prerogatives of both global and partitioned algorithms, without incurring the respective drawbacks. As an interesting trait, RUN promises to reduce the amount of migration interference. However, RUN has also raised some concerns on the complexity and specialization of its run-time support. To the best of our knowledge, no practical implementation and empirical evaluation of RUN have been presented yet, which is rather surprising, given its potential. In this paper we present the first solid implementation of RUN and extensively evaluate its performance against P-EDF and G-EDF, with respect to observed utilization cap, kernel overheads and inter-core interference. Our results show that RUN can be efficiently implemented on top of standard operating system primitives incurring modest overhead and interference, also supporting much higher schedulable utilization than its partitioned and global counterparts.
Davide Compagnin, Enrico Mezzetti, Tullio Vardanega
ECRTS3
2014 An architectural approach with separation of concerns to address extra-functional requirements in the development of embedded real-time software systems
abstract
A large proportion of the requirements on embedded real-time systems stems from the extra-functional dimensions of time and space determinism, dependability, safety and security, and it is addressed at the software level. The adoption of a sound software architecture provides crucial aid in conveniently apportioning the relevant development concerns. This paper takes a software-centered interpretation of the ISO 42010 notion of architecture, enhancing it with a component model that attributes separate concerns to distinct design views. The component boundary becomes the border between functional and extra-functional concerns. The latter are treated as decorations placed on the outside of components, satisfied by implementation artifacts separate from and composable with the implementation of the component internals. The approach was evaluated by industrial users from several domains, with remarkably positive results.
Marco Panunzio, Tullio Vardanega
J. Syst. Archit.2
2014 A component-based process with separation of concerns for the development of embedded real-time software systems
abstract
Numerous component models have been proposed in the literature, a testimony of a subject domain rich with technical and scientific challenges, and considerable potential. Unfortunately however, the reported level of adoption has been comparatively low. Where successes were had, they were largely facilitated by the manifest endorsement, where not the mandate, by relevant stakeholders, either internal to the industrial adopter or with authority over the application domain. The work presented in this paper stems from a comprehensive initiative taken by the European Space Agency (ESA) and its industrial suppliers. This initiative also enjoyed significant synergy with interests shown for similar goals by the telecommunications and railways domain, thanks to the interaction between two parallel project frameworks. The ESA effort aimed at favouring the adoption of a software reference architecture across its software supply chain. The center of that strategy revolves around a component model and the software development process that builds on it. This paper presents the rationale, the design and implementation choices made in their conception, as well as the feedback obtained from a number of industrial case studies that assessed them.
Marco Panunzio, Tullio Vardanega
J. Syst. Softw.2
2013 Limited preemptive scheduling of non-independent task sets
abstract
Preemption is a key factor against architectural coupling in concurrent systems. The whole verification process of real-time systems postulates composability in multiple dimensions, including time. As coupling wrecks composability, the design of real-time systems really needs preemption. However preemption effects complicate feasibility analysis or make it more pessimistic. Hence methods that limit preemptions without affecting feasibility are attractive. State-of-the-art approaches to limited preemption, however, do not treat resource sharing with the importance that it deserves. The placement of non-preemptive regions - and their interactions with shared resources - should not become a design problem, but rather stay as an implementation level feature that does not backtrack to the design space. In this paper we present a refinement to the state-of-the-art limited preemption model that addresses the interaction with resource sharing, and discuss a kernel implementation that uses run-time knowledge to warrant safe and efficient overlaps between critical sections and non-preemptive regions. Experimental results prove the effectiveness of the proposed solution.
Andrea Baldovin, Enrico Mezzetti, Tullio Vardanega
EMSOFT3
2013 Cross-Domain Reuse: Lessons Learned in a Multi-project Trajectory
Silvia Mazzini, John M. Favaro, Tullio Vardanega
ICSR3
2013 On Software Reference Architectures and Their Application to the Space Domain
Marco Panunzio, Tullio Vardanega
ICSR2
2013 Supporting industrial use of probabilistic timing analysis with explicit argumentation
abstract
Probabilistic Timing Analysis (PTA) in general and its measurement-based variant called MBPTA in particular have potential for mitigating the problems that impair current worstcase execution time (WCET) analysis techniques whether as in industrial practice or in state-of-the-art research. MBPTA can compute tight upper bounds on the execution time of software programs, which it expresses as probabilistic exceedance functions, without needing much information on the hardware and software internals of the system. To exploit this capability in practice, some reasoned argument must be constructed to explain why the method is suitable. This paper details our experience with the construction of such an argument, and in particular shows how the structure of the argument allows it to be easily configured for the needs of different industries.
Zoë Stephenson, Jaume Abella 0001, Tullio Vardanega
INDIN3
2013 Achieving timing composability with measurement-based probabilistic timing analysis
abstract
Probabilistic Timing Analysis (PTA) allows complex hardware acceleration features, which defeat classic timing analysis, to be used in hard real-time systems. PTA can do that because it drastically reduces intrinsic dependence on execution history. This distinctive feature is a great facilitator to time composability, which is a must for industry needing incremental development and qualification. In this paper we show how time composability is achieved in PTA-conformant systems and how the pessimism of worst-case execution time bounds obtained from PTA is contained within a 5% to 25% range for representative application scenarios.
Leonidas Kosmidis, Eduardo Quiñones, Jaume Abella 0001, Tullio Vardanega, Francisco J. Cazorla
ISORC4
2013 A rapid cache-aware procedure positioning optimization to favor incremental development
abstract
Truly incremental development is a holy grail of verification-intensive software industry. All factors that threaten it should be removed. Cache memories have an intrinsically jittery timing behavior. The WCET variability that this causes wrecks incrementality. This hazard occurs as the WCET bounds of a software system can only be safely determined when its final memory map is known, which only happens at the end of development. Interestingly, the memory layout optimization techniques, originally devised to optimize average- or worst-case cache response time, open some avenue to control the innate dependence of cache behavior on memory layout. The state-of-the-art approaches, though effective to their own goal, are onerous to use and intrinsically iterative, hence arch-enemy of incrementality. As such they do not lend themselves to effective application in real-world industrial development. In this paper, looking at instruction caches, we describe a novel procedure positioning technique that makes it possible to control the memory layout across incremental software releases. Experimental evidence confirms that our approach facilitates early reasoning on the timing behaviour of system increments and also improves cache performance.
Enrico Mezzetti, Tullio Vardanega
IEEE Real-Time and Embedded Technology and Applications Symposium2
2013 PROARTIS: Probabilistically Analyzable Real-Time Systems
abstract
Static timing analysis is the state-of-the-art practice of ascertaining the timing behavior of current-generation real-time embedded systems. The adoption of more complex hardware to respond to the increasing demand for computing power in next-generation systems exacerbates some of the limitations of static timing analysis. In particular, the effort of acquiring (1) detailed information on the hardware to develop an accurate model of its execution latency as well as (2) knowledge of the timing behavior of the program in the presence of varying hardware conditions, such as those dependent on the history of previously executed instructions. We call these problems the timing analysis walls. In this vision-statement article, we present probabilistic timing analysis , a novel approach to the analysis of the timing behavior of next-generation real-time embedded systems. We show how probabilistic timing analysis attacks the timing analysis walls; we then illustrate the mathematical foundations on which this method is based and the challenges we face in the effort of efficiently implementing it. We also present experimental evidence that shows how probabilistic timing analysis reduces the extent of knowledge about the execution platform required to produce probabilistically accurate WCET estimations.
Francisco J. Cazorla, Eduardo Quiñones, Tullio Vardanega, Liliana Cucu-Grosjean, Benoit Triquet, Guillem Bernat, Emery D. Berger, Jaume Abella 0001, Franck Wartel, Michael Houston, Luca Santinelli, Leonidas Kosmidis, Code Lo, Dorin Maxim
ACM Trans. Embed. Comput. Syst.3
2012 Towards a New Paas Architecture Generation
Claudio Guidi, Paolo Anedda, Tullio Vardanega
CLOSER3
2012 Measurement-Based Probabilistic Timing Analysis for Multi-path Programs
abstract
The rigorous application of static timing analysis requires a large and costly amount of detail knowledge on the hardware and software components of the system. Probabilistic Timing Analysis has potential for reducing the weight of that demand. In this paper, we present a sound measurement-based probabilistic timing analysis technique based on Extreme Value Theory. In all the experiments made as part of this work, the timing bounds determined by our technique were less than 15% pessimistic in comparison with the tightest possible bounds obtainable with any probabilistic timing analysis technique. As a point of interest to industrial users, our technique also requires a comparatively low number of measurement runs of the program under analysis, less than 650 runs were needed for the benchmarks presented in this paper.
Liliana Cucu-Grosjean, Luca Santinelli, Michael Houston, Code Lo, Tullio Vardanega, Leonidas Kosmidis, Jaume Abella 0001, Enrico Mezzetti, Eduardo Quiñones, Francisco J. Cazorla
ECRTS5
2012 CHESS: a model-driven engineering tool environment for aiding the development of complex industrial systems
abstract
Modern software systems require advanced design support especially capable of mastering rising complexity, as well as of automating as many development tasks as possible. Model-Driven Engineering (MDE) is earning consideration as a solid response to those challenges on account of its support for abstraction and domain specialisation. However, MDE adoption often shatters industrial practice because its novelty opposes the need to preserve vast legacy and to not disband the skills matured in pre-MDE or alternative development solutions. This work presents the CHESS tool environment, a novel approach for cross-domain modelling of industrial complex systems. It leverages on UML profiling and separation of concerns realised through the specification of well-defined design views, each of which addresses a particular aspect of the problem. In this way, extra-functional, functional, and deployment descriptions of the system can be given in a focused manner, avoiding issues pertaining to distinct concerns to interfere with one another.
Antonio Cicchetti, Federico Ciccozzi, Silvia Mazzini, Stefano Puri, Marco Panunzio, Alessandro Zovi, Tullio Vardanega
ASE7
2011 Measuring I/O Performance in Xen Paravirtualization Virtual Machines
Giovanni Giacobbi, Tullio Vardanega
CLOSER2
2010 Towards a Cache-Aware Development of High Integrity Real-Time Systems
abstract
The job description of caches is to speed up memory accesses in the average case. Their intrinsic unpredictability however can seriously hamper the practicality and trustworthiness of system analysis and validation. In effect, this conflict asks system designers to take side between best average-case performance and maximum assurance, since both can't be had. In this paper we study the I-cache predictability problem from a system-level perspective. We identify some sources of cache-related variability that can be addressed whilst considering the architectural specification of the system and thus at an early stage of development. We discuss an example of what we call a "cache-aware" software architecture and experimentally evaluate its effectiveness on a representative application.
Enrico Mezzetti, Tullio Vardanega
RTCSA2
2010 Ensuring Correctness in the Specification and Handling of Non-Functional Attributes in High-Integrity Real-Time Embedded Systems
abstract
In high-integrity systems, the focus of the development process is geared to assuring that the assertions made on the system are both correct (i.e., semantically sustainable) and feasible (i.e., true at run time). Some of those assertions take effect in the non-functional domain, that is, in how the system is realized and behaves in time, space and communication during execution; others in the functional domain, and thus concern what outputs the system produces for its inputs. In this paper, we address the problem of achieving correct specification and handling of non-functional attributes, with particular regard to the concurrent structure of the system, the safeness of the interaction protocols engaged in it, and the guarantee that its timing feasibility can be statically verified. Our approach is based on a Model-Driven Engineering methodology, in which correctness can be ensured by construction or verified at a high level of abstraction, while the runtime implementation structure and code are automatically generated. We employ the Ravenscar Computation Model (RCM) and focus, in particular, on aerospace applications, which impose stringent requirements on correctness properties. We discuss an algebraic formalization of our model based on graph theory which we use to prove safe termination in systems compliant with RCM, and show how to use the MAST+ static analyzer to verify the timing aspects. We finally illustrate the results of a prototype tool that was developed for evaluation by major industrial players in the European space industry.
Daniela Cancila, Roberto Passerone, Tullio Vardanega, Marco Panunzio
IEEE Trans. Ind. Informatics3
2009 An MDE methodology for the development of high-integrity real-time systems
abstract
This paper reports on experience gained and lessons learned from an intensive investigation of model-driven engineering methodology and technology for application to high-integrity systems. Favourable experimental context was provided for by ASSERT, a 40-month project partly funded by the EC as part of the 6th Framework Program. The goodness of fit of the MDE paradigm for the industrial domain of interest was critically assessed on a small number of candidate solutions. One of the main axes of investigation concerned HRT-UML/RCM, an advanced method and integrated tool for the model-driven development of embedded real-time software systems. HRT-UML/RCM vastly leveraged on version 2 of the OMG UML standard and combined it with the development of a domain-specific metamodel in the quest to attain correctness-by-construction from the ground up. The prototype tool developed in the project supported: (1) the separation of functional (sequential) design from the specification of real-time and concurrency requirements and properties to be preserved at run time; and (2) the exploitation of a fully generative approach to the development, equipped with support for model-based feasibility analysis and round-trip engineering.
Silvia Mazzini, Stefano Puri, Tullio Vardanega
DATE3
2009 Property Preservation and Composition with Guarantees: From ASSERT to CHESS
abstract
While the demand for high-integrity applications continues to rise, industrial developers seek cost effective development strategies that are capable of delivering the required guarantees. The very nature of high-integrity software systems make a-posteriori verification totally inapt to meet the time, cost and quality constraints that impend on developers. What is wanted instead is a development method that facilitates early verification and that devolves to proven automation as many of the error-prone development tasks as practically possible. Model-driven engineering (MDE) is an especially fit option to explore in that respect. In a recent European project very interesting results were obtained in the development and industrial evaluation of an MDE process centered on the joint principles of correctness by construction and property preservation. The proceedings of that project were so encouraging in fact that a continuation of it was instigated with a challenging broader scope.This paper provides an account of the approach taken in the original project with regard to property preservation and outlines the intent of its continuation.
Tullio Vardanega
ISORC1
2009 On Component-Based Development and High-Integrity Real-Time Systems
abstract
Component-based development approaches are becoming commonplace in business applications: they must therefore have some merit. In striking contrast to that, their penetration in the industrial practice of high-integrity real-time systems is virtually nil. This oddity needs explaining. In this paper we reflect on the presumed reasons of this situation and elaborate on possible systematic remedies. We contend that in order to make it in the high-integrity real-time systems domain, a component-based development approach must be constructed around four fundamental ingredients: a component model, a computational model, a programming model, and a congruent execution platform. Of those four ingredients, the computational model is key to bridging the lack of architectural concerns that afflicts the real-time workload models. We relate the component model to real-time systems theories. We illustrate how those elements could be neatly encased in a development method centred on model-driven engineering. We conclude by noting that the incorporation of component-based development methods, augmented with the cited ingredients, into model-driven engineering promises important savings in the development time and cost and also facilitates the industrial adoption of state-of-the-art techniques off real-time theory.
Marco Panunzio, Tullio Vardanega
RTCSA2
2008 Fitting Schedulability Analysis Theory into Model-Driven Engineering
abstract
The theory behind state-of-the-art schedulability analysis has reached such a level of sophistication that its complete mastering by the average industrial practitioner is practically infeasible. The centrality of automation promoted by model-driven engineering may facilitate the uptake of the front-end of the analysis theory by the industrial world. In this paper we qualitatively evaluate how current approaches to model-based schedulability analysis may employ and feed state-of-the-art analysis equations; we then illustrate a new strategy which, by way of model transformation, warrants a high degree of confidence in and permits an iterative refinement of the input to sophisticated analysis equations. We contend that model-driven engineering is well suited for fitting the most advanced analysis theories and to chart the course for future improvements in the area of model-based schedulability analysis.
Matteo Bordin, Marco Panunzio, Tullio Vardanega
ECRTS3
2007 An Approach to the Timing Analysis of Hierarchical Systems
abstract
Two architectural paradigms for the development of hierarchical systems arguably stand out for their flexibility and ease of reconfiguration: the server-based architecture and the priority-band architecture. Whilst the former has been deeply investigated, the latter, a fresh addition to a mainstream programming language standard, still lacks an accurate study of its timing behaviour. In this paper we relate those two architectural paradigms and devise timing analysis equations for the priority-band systems off the solid roots of the server-based theory.
Marco Panunzio, Tullio Vardanega
RTCSA2
2006 A UML2 Profile for Reusable and Verifiable Software Components for Real-Time Applications
Vaclav Cechticky, Martin Egli, Alessandro Pasetti, O. Rohlik, Tullio Vardanega
ICSR5
2006 Property-Preserving Reuse-Geared Approach to Model-Driven Development
abstract
In this short paper we illustrate a novel approach that aims to marry reuse-driven and model-driven development principles with engineering considerations of great concern to high-integrity real-time systems, for which the specification of properties to be preserved at run time is paramount
Tullio Vardanega
RTCSA1
2005 Automated Model-Based Generation of Ravenscar-Compliant Source Code
abstract
Graphical languages of various sorts are increasingly used for the specification and the design of high-integrity real-time systems. Their coverage however does not extend with as much success to automated source code generation. Several hurdles cause the model-to-code translation to often lapse in the preservation of the desired semantics. This paper illustrates the choices we have made to provide the HRT-UML design method with an automated Ravenscar-compliant source code generation engine. Compliance with the Ravenscar computational model warrants static analysability of the source code and predictability of execution. By elevating this compliance to the design stage, we earn semantic preservation across the whole development process.
Matteo Bordin, Tullio Vardanega
ECRTS2
2005 On the Dynamic Semantics and the Timing Behavior of Ravenscar Kernels
Tullio Vardanega, Juan Zamorano, Juan Antonio de la Puente
Real Time Syst.1
2003 Issues in Mapping HRT-HOOD to UML
abstract
HRT-HOOD has methodological strengths that deserve to be preserved in the face of the commercial decline of HOOD technology. The UML (Unified Modeling Language) meta-model, on the other hand, has a level of flexibility that makes it an especially attractive platform to express the specific real-time design minded features of the HRT-HOOD method. The object-oriented connotation of the method that results from mapping HRT-HOOD onto UML raises methodological issues that we deem of interest to the real-time community at large. This paper discusses three such issues in particular: the prevalence of objects over classes in real-time design, with the consequent inversion of the standard object-oriented development paradigm; the need to derive classes "by example", which arises from the demand to allow multiple, yet static, instances of real-time objects initially designed as singleton; the opportunity of reuse-oriented component-based real-time development, which descends from using interfaces instead of classes as the target of associations among objects.
Silvia Mazzini, Massimo D'Alessandro, Marco Di Natale, Giuseppe Lipari, Tullio Vardanega
ECRTS5
2002 Engineering software reuse for on-board embedded real-time systems
abstract
Abstract The dimensions of concern to ambitious reuse initiatives largely exceed the provision of desired functionalities. A domain‐specific blend of functional, technical and quality considerations determines the reuse potential of software reuse assets. In a recent project we realized considerable reuse dividends from coupling the definition of a reference software architecture and of an associated set of standard interfaces with the selection of a powerful computational model equipped with reuse‐geared enabling technology. In this paper we present our engineering approach to the project and show how it earned us a good balance between the preservation of predictability and scalability and the maximization of the reuse objective. Copyright © 2001 John Wiley & Sons, Ltd.
Tullio Vardanega, Gert Caspersen
Softw. Pract. Exp.1
1999 A Software Process for the Construction of Predictable On-Board Embedded Real-Time Systems
abstract
The rise of the ‘cheaper, faster, better’ mission paradigm increasingly challenges the industrial development of satellite systems. The novel paradigm will have a profound impact on the production of the real-time software embedded on board new-generation systems. This paper contends that a large proportion of the ensuing demands can be satisfied by an iterative and incremental development model revolving around two evolutionary enhancements to the present engineering approach, namely (1) static real-time analysis as a key ingredient of the software verification process, and (2) an architectural paradigm centred on fixed priority preemptive scheduling. Copyright © 1999 John Wiley & Sons, Ltd.
Tullio Vardanega, Jan van Katwijk
Softw. Pract. Exp.1
1998 Productive engineering of predictable embedded real-time systems: the road to maturity
Tullio Vardanega, Jan van Katwijk
Inf. Softw. Technol.1
1996 Tool support for the construction of statically analysable hard real-time Ada systems
abstract
The paper maintains that fixed priority process based preemptive scheduling is, arguably, more convenient, flexible and responsive than conventional cyclic scheduling for the construction of new generation software intensive satellite control systems. Predictable usage of preemptive priority based scheduling, however, demands the support of mature static analysis techniques. Worst case response time analysis models can be constructed which minimise the embodied pessimism and maximise useful processing. The paper presents the design and implementation of an Ada programming model and associated worst case response time analysis tools aimed to support the construction of highly predictable, highly efficient on-board control systems.
Tullio Vardanega
RTSS1
1994 Experience with the Development of Hard Real-Time Embedded Ada Software
Tullio Vardanega
ICSE1
1993 The use of preemptive priority-based scheduling for space applications
abstract
In January 1991, the European Space Agency commissioned a study into the practicality of using process-based scheduling techniques in an on-board application environment, with Ada as the implementation language. The short paper summarizes the results of that study.>
C. M. Bailey, E. Fyfe, Tullio Vardanega, Andy J. Wellings
RTSS3
1991 An operating system suited for integrated broadband communications networks
abstract
Broadband communications technologies are close to maturity. Substantial changes can be therefore anticipated in the software architecture of next-generation computer networks. The consequences will be numerous. Amongst them, the classic separation between local- and wide-area networks is bound to become impractical under future circumstances. This paper pursues this argument by introducing the design of an innovative operating system suitable for future broadband networks. Special focus lays on properties of distribution, openness and scalability.>
Tullio Vardanega
LCN1