首页> 外文OA文献 >Multiplexing Adaptive with Classic AUTOSAR? Adaptive Software Control to Increase Resource Utilization in Mixed-Critical Systems
【2h】

Multiplexing Adaptive with Classic AUTOSAR? Adaptive Software Control to Increase Resource Utilization in Mixed-Critical Systems

机译:与经典AUTOSAR复用自适应?自适应软件控制以提高混合关键系统中的资源利用率

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

Automotive embedded systems need to cope with antagonist requirements: on the one hand, the users and market pressure push car manufacturers to integrate more and more services that go far beyond the control of the car itself. On the other hand, recent standardization efforts in the safety domain has led to the development of the ISO 26262 norm that defines means and requirements to ensure the safe operation of automotive embedded systems. In particular, it led to the definition of ASIL (Automotive Safety and Integrity Levels), i.e., it formally defines several criticality levels. Handling the increased complexity of new services makes new architectures, such as multi or many-cores, appealing choices for the car industry. Yet, these architectures provide a very low level of timing predictability due to shared resources, which goes in contradiction with timing guarantees required by ISO 26262. For highest criticality level tasks, Worst-Case Execution Time analysis (WCET) is required to guarantee that timing constraints are respected. The WCET analyzers consider the worst-case scenario: whenever a critical task accesses a shared resource in a multi/many-core platform, a WCET analyzer considers that all cores use the same resource concurrently. To improve the system performance, we proposed in a earlier work an approach where a critical task can be run in parallel with less critical tasks, as long as the real-time constraints are met. When no further interferences can be tolerated, the proposed run-time control suspends the low critical tasks until the termination of the critical task. In an automotive context, the approach can be translated as a highly critical partition, namely a classic AUTOSAR one, that runs on one dedicated core, with several cores running less critical Adaptive AUTOSAR application(s). We briefly describe the design of our proven-correct approach. Our strategy is based on a graph grammar to formally model the critical task as a set of control flow graphs on which a safe partial WCET analysis is applied and used at run-time to control the safe execution of the critical task.
机译:汽车嵌入式系统需要应对竞争者的需求:一方面,用户和市场压力迫使汽车制造商集成越来越多的服务,而这些服务远远超出了汽车本身的控制范围。另一方面,最近在安全领域的标准化工作导致了ISO 26262规范的发展,该规范定义了确保汽车嵌入式系统安全运行的方式和要求。特别是,它导致了ASIL(汽车安全性和完整性等级)的定义,即正式定义了几个关键等级。处理新服务日益复杂的问题,使新架构(例如多核或多核)成为汽车行业的诱人选择。但是,由于共享资源,这些体系结构提供了非常低的时序可预测性,这与ISO 26262所要求的时序保证相矛盾。对于关键度最高的任务,需要最坏情况执行时间分析(WCET)来保证时序遵守约束。 WCET分析器考虑最坏的情况:每当关键任务访问多/多核平台中的共享资源时,WCET分析器就会认为所有核同时使用同一资源。为了提高系统性能,我们在较早的工作中提出了一种方法,只要满足实时约束,就可以将关键任务与次要任务并行运行。当不能容忍其他干扰时,建议的运行时控制将低关键任务挂起,直到关键任务终止。在汽车环境中,该方法可以转换为高度关键的分区,即经典的AUTOSAR分区,该分区运行在一个专用内核上,而多个内核则运行不太关键的自适应AUTOSAR应用程序。我们简要描述了我们证明正确的方法的设计。我们的策略基于图文法,将关键任务正式建模为一组控制流程图,在该流程图上应用了安全的部分WCET分析,并在运行时用于控制关键任务的安全执行。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号