Formal Modeling and Analysis of AFDX Frame Management Design
نویسندگان
چکیده
The Avionics Full Duplex Switched Ethernet (AFDX) has been developed to provide reliable data exchange with strong data transmission time guarantees in internal communication of the aircraft. The AFDX design is based on the principle of a switched network with physically redundant links to support availability and be tolerant to transmission and link failures in the network. In this work, we develop a formal model of the AFDX frame management to ascertain the reliability properties of the design. To capture the precise temporal semantics, we model the system as a network of timed automata and use UPPAAL to model-check for the desired properties expressed in CTL. Our analysis indicates that the design of the AFDX frame management is vulnerable to faults such as network babbling which can trigger unwarranted system resets. We show that these problems can be alleviated by modifying the original design to include a priority queue at the receiver for storing the frames. We also suggest communicating redundant copies of the reset message to achieve tolerance to network babbling. Comments Copyright 2006 IEEE. Reprinted from the 9th IEEE International Symposium on Object-oriented Real-time Distributed Computing (ISORC 2006), pages: 393-399 This material is posted here with permission of the IEEE. Such permission of the IEEE does not in any way imply IEEE endorsement of any of the University of Pennsylvania's products or services. Internal or personal use of this material is permitted. However, permission to reprint/republish this material for advertising or promotional purposes or for creating new collective works for resale or redistribution must be obtained from the IEEE by writing to [email protected]. By choosing to view this document, you agree to all provisions of the copyright laws protecting it. This conference paper is available at ScholarlyCommons: http://repository.upenn.edu/cis_papers/246 Formal Modeling and Analysis of the AFDX Frame Management Design ∗ Madhukar Anand University of Pennsylvania, Philadelphia, PA 19104 [email protected] Steve Vestal Honeywell Technology Center, Minneapolis, MN 55418 [email protected] Samar Dajani-Brown Honeywell Technology Center, Minneapolis, MN 55418 [email protected] Insup Lee University of Pennsylvania, Philadelphia, PA 19104
منابع مشابه
A Finite State Modeling of AFDX Frame Management Using Spin
Data exchange with strong data transmission time guarantees is necessary in the internal communication of an aircraft. The Avionics Full Duplex Switched Ethernet (AFDX) has been developed for this purpose. Its design is based on the principle of a switched network with physically redundant links to support availability. It should also be tolerant to transmission and link failures in the network...
متن کاملFormal Specification and Analysis of AFDX Redundancy Management Algorithms
Reliable communication among avionic applications is a crucial prerequisite for today’s all-electronic fly-by-wire aircraft technology. The AFDX switched Ethernet has been developed as a scalable, cost-effective network, based upon IEEE 802.3 Ethernet. It uses redundant links to increase the availability. Typical consensus strategies for the redundancy management task are not feasible, as they ...
متن کاملForward End-To-End delay Analysis for AFDX networks
Packet switched networks and message multiplexing have been a major upgrade for industrial systems communications. In the avionics domain, this evolution was brought by the introduction of Avionics Full Duplex Switched Ethernet (AFDX). Guaranteed upper bounds of end-to-end delays for messages transmitted over an AFDX network are mandatory for certification reasons. In this article, we present t...
متن کاملQoS-aware AFDX: benefits of an efficient priority assignment for avionics flows
AFDX (Avionics Full Duplex Switched Ethernet) standardised as ARINC 664 is a major upgrade for avionics systems. The certification imposes to guarantee that the end-toend delay of any frame transmitted on the network is upperbounded and that no frame is lost due to buffer overflow. This guarantee is obtained thanks to a worst-case analysis assuming a FIFO scheduling policy of flows on each outp...
متن کاملSeismic Evaluation of Flexible-Base Low-Rise Steel Frames Using Beam-On-Nonlinear-Winkler-Foundation Modeling of Shallow Footings
Recent investigations have shown that the influences of Soil-Structure Interaction (SSI) may be detrimental to the seismic response of structure, and hence neglecting this phenomenon in analysis and design may lead to an un-conservative design. The objective of this paper is to quantify the effects of nonlinear soil-structure interaction on the seismic response of a low-rise special moment fram...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
دوره شماره
صفحات -
تاریخ انتشار 2015