🤖 AI Summary
This study addresses the insufficient trustworthiness of the compilation process and suboptimal performance of generated code in nuclear safety instrumentation and control (I&C) systems. By introducing the CompCert verified compiler into the TELEPERM XS platform, this work leverages formal methods to eliminate compiler defects and reduce the trusted computing base. Furthermore, the toolchain verification workflow is optimized, and the runtime performance of specific code patterns is improved. The core contribution lies in elevating the safety argumentation from mere maintenance to active enhancement, thereby establishing a more rigorous safety case for nuclear I&C software. Ultimately, this approach significantly improves both the safety assurance and development efficiency of safety-critical software production within the nuclear power domain.
📝 Abstract
The large safety instrumentation&control (I&C) systems in civil nuclear power plants (NPPs) are mainly safe-shutdown systems (reactor protection) or limitation and control systems. Framatome's established TELEPERM XS (TXS Core) product family is a digital I&C system platform to cover all these applications. We illustrate the role of verification in the different stages of the software production toolchain, focus on the formal compilation process, and discuss the contribution of the CompCert certified compiler to the safety case of the product. Scrutinizing the object code produced by this compiler has exhibited suboptimal run-time performance in a certain simple but recurring generated code pattern. We explain how formal methods allow us to address this issue in the compiler while simultaneously reducing its trusted computing base (TCB), thereby strengthening the safety case rather than merely preserving it.