🤖 AI Summary
This study addresses the conflict between software updates and operational availability in safety-critical systems by proposing a disruption-free, secure deployment method that eliminates the need for cold-standby hardware. The interaction between the system and the update process is modeled as a two-player timed game. By employing bounded model checking-based quantified SMT encoding techniques under linear update automata, this work synthesizes fixed global-time schedules that decouple update scheduling from autonomous system behavior. Experimental evaluation on an autonomous driving trajectory planner demonstrates that the synthesized scheduling strategy ensures safe update deployment across all admissible execution paths. Consequently, this approach effectively mitigates update risks arising from behavioral uncertainty in safety-critical systems.
📝 Abstract
Ensuring safe software updates in safety-critical systems without interrupting operation and without provisioning and activating cold spare hardware poses a fundamental challenge due to the conflict between system availability and update execution. In this paper, we present a bounded SMT encoding for synthesizing fixed global-time update schedules for timed-games with linear update automata and a fixed number of update transitions. We model the interaction between the system and the update as a two-player timed game. Our key contribution is the synthesis of global time points that define a fixed update schedule which guarantees safe and complete deployment of the update independently of the autonomous system behavior. To this end, we reduce the scheduling problem to a reachability and safety objective and encode it as a quantified SMT problem. We demonstrate it on an example system of a trajectory planner for autonomous driving, showing that the synthesized schedule ensures safe deployment under all admissible executions.