Score
Designs, builds, and analyzes software and hardware systems whose correctness depends on meeting explicit timing constraints, encompassing real-time operating systems, task scheduling, interrupt handling, predictable I/O, and resource management. Work includes worst-case execution time and schedulability analysis, timing verification and testing, and architectural or algorithmic choices to ensure deterministic latency and bounded jitter under load.
本文提出了一种基于CCSL的时序规范框架,支持逐步引入时序知识,解决现有形式化方法在迭代时序工程中的局限性。
研究通过结合概率设计时延分析与Kuksa实现监控,解决了软件定义车辆中因中间件通信导致的时间不确定性问题。
Transient-execution attacks (e.g., Spectre, Meltdown) expose a fundamental lack of global correctness in modern microprocessors—stemming from informal ISA specifications that cannot rigorously capture conformance to both functional and security properties under microarchitectural optimizations. Method: We propose the first formal theory of global correctness for transient execution. Our approach introduces two novel refinement relations: *action-skipping refinement* and *shared-resource commitment refinement*, enabling a modular, verifiable specification framework. It integrates bit-level and cycle-accurate executable models, property-driven testing, and noninterference-based modeling. Contribution/Results: The framework enables precise, cross-microarchitecture ISA conformance checking under transient execution, uncovering inherent vulnerabilities in mainstream processors. It supports lightweight, automated vulnerability verification and provides both theoretical foundations and practical tools for secure microarchitecture design and formal verification.
In hardware design, stateless signals change instantaneously with underlying register updates, introducing timing hazards—particularly metastability-induced glitches—yet existing HDLs lack static guarantees of signal value stability, forcing designers to rely on error-prone manual reasoning. This paper introduces Anvil, a novel general-purpose hardware description language featuring a type system that explicitly distinguishes registers from stable signals and enforces precise timing constraints between signal usage and register updates. Its key contributions are: (1) the first general-purpose HDL supporting static verification of timing safety while preserving cycle-accurate control; (2) parameterized dynamic timing contracts enabling modular composition and cross-module stability reasoning; and (3) end-to-end verification on the critical path of an open-source RISC-V CPU, demonstrating expressive power, formal timing safety, and practical engineering viability.
To address the lack of systematic response-time analysis and real-time scheduling guarantees in ROS 2’s multi-threaded executor, this paper introduces the first response-time analysis framework tailored to its kernel-level execution semantics. The framework supports modeling of arbitrary- and constrained-deadline task chains and precisely captures mutual exclusion among callback groups. We further propose a priority-driven scheduling enhancement mechanism that optimizes critical-path response times while preserving schedulability. Experimental evaluation on the Jetson AGX Xavier platform demonstrates that our framework yields tighter safe upper bounds on response time, reduces average response time of critical chains by a significant margin, and improves overall system schedulability by 23.6%.
This work addresses the challenge of obtaining trustworthy worst-case execution time (WCET) bounds, as existing analysis tools are often closed-source or lack support for commercial microcontrollers. We present an open-source static WCET analyzer designed for commercial off-the-shelf (COTS) microcontrollers. Adopting a simplicity-first design philosophy, the tool directly parses architecture-specific binaries to estimate WCET, natively supports mainstream chips such as the ESP32-C6, and explicitly reports unsound results arising from hardware or software limitations to ensure transparency. Experimental evaluations successfully derive reliable WCET bounds for both the ESP32-C6 and MSP430 platforms. These results validate the tool’s usability and its advantage of eliminating licensing barriers, demonstrating its suitability for real-time systems education and engineering practice.
This work addresses the challenge of verifying correctness across all valid instances of configurable Software-Defined Radio Access (SRA) systems composed of asynchronous processes coordinated by domain-specific sched日晚间. Traditional approaches struggle to verify such systems holistically due to their parameterized and infinite nature. To overcome this, the paper proposes a contract-based deductive verification framework that integrates compositional proof rules, automated method summarization for scheduler invocations, and simplification of configuration-space constraints. The approach handles quantified reasoning within an object-oriented first-order logic setting and leverages Dafny as its verification backend. This is the first method capable of delivering a unified correctness proof for an infinite family of SRA instances, thereby breaking the scalability barrier in verifying parameterized asynchronous systems. Experimental results on industrial case studies demonstrate the framework’s effectiveness in enabling efficient, automated reasoning about complex parameterized behaviors.
This work addresses the inefficiencies and semantic inconsistencies arising from separately implementing driver and monitor programs in traditional hardware module testing. To overcome this, the authors propose a domain-specific language (DSL) tailored to hardware communication protocols, which enables the unified specification of both driver and monitor logic through an imperative syntax, thereby ensuring their semantic consistency for the first time. Building upon this DSL, they develop a prototype tool that leverages waveform parsing and transaction-level trace inference techniques to accurately reconstruct protocol-compliant transaction sequences from raw signal waveforms. Experimental results demonstrate that the approach significantly improves development efficiency, with further validation planned on real-world interconnect protocols such as Wishbone and AXI-Stream.
This work addresses the critical need for rigorous assurance that implementations of Earliest Deadline First (EDF) schedulers in real-time operating systems adhere precisely to their intended scheduling semantics, rather than relying solely on abstract analyses. The paper presents the first general, property-driven formal verification framework specifically tailored for EDF implementations, explicitly defining three core correctness properties and conducting deductive verification using the Frama-C/ACSL platform. The framework has been successfully applied to EDF extensions in RTEMS 5, RTEMS 6, and FreeRTOS, demonstrating that three architecturally distinct scheduler implementations all satisfy the essential correctness properties. This approach effectively resolves the semantic fidelity challenges arising from reusing fixed-priority kernel infrastructure and substantially enhances the trustworthiness of EDF scheduler implementations in safety-critical systems.
This study addresses the lack of real hardware support in DAG scheduling theory and the difficulty existing platforms face in ensuring timing analyzability. To this end, we propose the first open-source RTOS that natively supports real-time DAG scheduling. By introducing a Function-as-Subtask (FasS) API to enforce DAG semantics and integrating a publish/subscribe model with a Global Earliest Deadline First (GEDF) algorithm, the system achieves OS-level native support for DAG task models alongside a modular scheduler with microsecond-level overhead and an automated testbed. Raspberry Pi-based experiments demonstrate that a GEDF scheduler implemented in merely 226 lines of code successfully ports autonomous driving components, enabling mechanical port migration without additional constraint reasoning. This work effectively bridges the gap between theoretical scheduling frameworks and practical engineering implementation.