Resilient Mixed-Trust Scheduling
Dionisio de Niz, Björn Andersson, Hyoseung Kim, Mark H. Klein, John P. Lehoczky
Abstract
In this paper we present a new scheduling model for resilient real-time mixed trust systems. This model extends the previous Real-Time Mixed-Trust Computing framework RT-MTC to support degradation modes. Management of these modes has been identified in industrial documents as a key requirement for deploying trusted autonomous vehicles for safe autonomy. RT-MTC uses verified components (known as enforcers) to guarantee that the output of a system is safe by replacing it with a verified safe one if this output is deemed unsafe or is not produced on time. In this paper we extend RT-MTC and develop a scheduling model that uses the digraph scheduling model as a baseline but extends it in four critical ways: (1) it creates extensions for the mixed-preemptive scheduling required by RT-MTC, (2) it enables priority bands in order to separate trusted and untrusted components, (3) it uses these bands in order to calculate intermediate deadlines used by the RT-MTC framework for the scheduling of the trusted components, and (4) it defines system mode semantics to obtain two desirable properties of the new schedulability analysis: low pessimism and low time-complexity. This paper evaluates the new schedulability algorithm and shows that it is efficient in that it only needs to analyze one transition at a time. The new model supports the construction of a resilient autonomous system with provable guarantees protected by verified enforcers within the RT-MTC framework and, more importantly, preserves these guarantees even across failure-triggered mode changes. Nominal Operation MRC m MRC n Final MRC I MRM m1 Degraded Operation Capabilities Not Fully available Capabilities Fully available MRM m2 MRM n1 MRM n2 MRM I1 MRM I2 Recovery (a) MRC Modes [12] VM HV LE Untrusted
‚ a high-speed enforcer that uses a lidar to detect an object with a detection range of 20m and braking power of
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 97e08bd0-bc19-449e-9a51-2046e72c7008Builds on2
- Building the Computing System for Autonomous Micromobility Vehicles: Design Constraints and Architectural OptimizationsBo Yu, Wei Hu, Leimeng Xu, Jie Tang et al.MICRO 2020 · 93 citations
- überSpark: Enforcing Verifiable Object Abstractions for Automated Compositional Security Analysis of a HypervisorAmit Vasudevan, Sagar Chaki, Petros Maniatis, Limin Jia et al.USENIX Security 2016 · 40 citations
Related papers
- HIART-MCS: High Resilience and Approximated Computing Architecture for Imprecise Mixed-Criticality SystemsZhe Jiang, Xiaotian Dai, Neil C. AudsleyRTSS 2021 · 8 citations
- RT-MOT: Confidence-Aware Real-Time Scheduling Framework for Multi-Object Tracking TasksDonghwa Kang, Seunghoon Lee, Hoon Sung Chwa, Seung-Hwan Bae et al.RTSS 2022 · 10 citations
- Mixed-Criticality Scheduling in Compositional Real-Time Systems with Multiple Budget EstimatesKecheng Yang, Zheng DongRTSS 2020 · 11 citations
- Virtual timeline: a formal abstraction for verifying preemptive schedulers with temporal isolationMengqi Liu, Lionel Rieg, Zhong Shao, Ronghui Gu et al.POPL 2020 · 17 citations
- Pythia-MCS: Enabling Quarter-Clairvoyance in I/O-Driven Mixed-Criticality SystemsZhe Jiang, Kecheng Yang, Nathan Fisher, Neil C. Audsley et al.RTSS 2020 · 10 citations
