scieee Open visual document viewer

Hierarchical object-oriented modeling of fault-tolerant computer systems

Carrasco, Juan A.

Abstract

A hierarchical, object-oriented modeling language for the specification of dependability models for complex fault-tolerant computer systems is overviewed. The language incorporates the hierarchical notions of cluster, operational mode and configuration and borrows from object-oriented programming the concepts of class, parameterization, and instantiation. These features together result in a highly expressive environment allowing the concise specification of sophisticated dependability models for complex systems. In addition, the language supports the declaration of symmetries that systems may exhibit at levels higher than the component level. These symmetries can be used to automatically generate lumped state-level models of significantly reduced size in relation to the state-level models which would be generated from a flat, component-level description of the system.

Full text

HIERARCHICAL, OB JECT-ORIENTED MODELING OF FAULT-TOLERANT COMPUTER SYSTEMS Juan A. Ca asco* Depa amen d'Enginye ia Elec bnica, UPC Diagonal 647, pl a. 9 OS02S-Ba celona, Spain Abs ac A hie a chical, objec -o ien ed modeling language o he speci- ica ion o dependabili y models o complex aul - ole an com- pu e sys ems is o e iewed. The language inco po a es he hie a chical no ions o clus e , ope a ional mode and con ig- u a ion and bo ows om objec -o ien ed p og animing he concep s o class, pa ame e iza ion, and ins an ia ion. These ea u es oge he esul in a highly exp essi e en i onmen al- lowing he concise speci ica ion o sophis ica ed dependabili y models o complex sys ems. In addi ion, he language sup- po s he decla a ion o symme ies ha sys ems may exhibi a le els highe han he componen le el. These symme ies can be used o au oma ically gene a e lumped s a e-le el mod- els o signi ican ly educed size in ela ion o he s a e-le el models which would be gene a ed om a la , componen -le el desc ip ion o he sys em. 1. INTRODUCTION ci ica ion o a bi a y CThlC dependabili y models bu equi e complex and .hus e o -p one desc ip ions o la ge sys ems. Ano he app oach [6, 71 is he use o a special-pu pose lan- guage wi h an implici modeling poin o iew and special con- s uc s easing he speci ica ion o o en-encoun e ed complex dependencies. In addi ion o being mo e use - iendly, he use o a high-le el modeling language has he ad an age o con ey ing seman ic knowledge which can be exploi ed du ing model solu ion [S, 9, IO]. This pape o e iews a hie a chical, objec -o ien ed modeling language o aul - ole an compu e sys ems which akes he SAVE modeling language [6,7] as s a ing poin , bu in oduces many ex ensions (clus e s, ope a ional modes, con igu a ions) enhancing signi ican ly i s modeling powe and use - iendliness and suppo ing au oma ic gene a ion o s a e-le el models o educed size when, as i is o en he case, he sys em has sym- me ies a le els highe han he componen le el. The la e is impo an since i is he size o he CTLIC wha ul ima ely limi s he applica ion o nume ical solu ion me hods. The es _- o he pape is o ganized as ollows. Sec ion 2 o e iews he desc ip ion o he language syn ax and seman ics and addi- ional examples can be ound in [ll]). Sec ion 3 discusses he ep esen aLion o he s a es o he lumped CTSIC's . Sec ion 4 concludes he pape A aul - ole an compu e sys em can o en be concep ualized ailu e, eco e y, and epai p ocesses. Dependencies among componen s o en a ise in eal aul - ole an compu e sys ems due o ailu e p opaga ion, limi ed eco e y e iciency, iecon- igu a ions, and epai . S ochas ic p ocesses allow o conside as made up o componen s ,-hanging hei s a e as a esul o language using O mode a e (a all hese impo an de ails. Reco e y p ocesses a e ypically se e al o de s o magni ude as e han bo h ailu e and epai 2. LANGUAGE OVERVIEW p ocesses and can be modelled by using ins an aneous co e age p obabili ies [l], which can be ob ,ained by s a is ical analysis 2.1. Modeling amewo k [2] o expe imen al da a collec ed om aul -injec ion expe i- men s. Typically, ailu e and epai imes a e assumed o ha e In Ou language, a aul - ole an compu e sys em is concep u- exponen ial dis ibu ions so ha he s ochas ic beha io o he alized as made UP o componen s and epai eams. Componen sys em can be desc ibed by a con inuolls ime ~~~l;~~, s a es a e modi ied by ailu e and epai p ocesses. Failu e p o- (CTMC) ha ing ailu e epai gene al, de. cesses only a ec un ailed componen s and a e associa ed wi h pendencies among he beha io o he compoI1eIl s o he sys. Pa icula componen s o he sps em bu , in gene al. can he em a e such ha he CTMC has o be gene a ed and sol ed p opaga ed o o he componen s. Repai p ocesses a e pe - using gene al-pu pose, s a e-le el me hods, Excep o sys ems o med by epai eams. The sys em is ei he ope a ional o wi h an small numbe o componen s, ile CTP IC has a size down, as de e mined by he un ailed/ ailed condi ion o he (numbe o s a es) sucll ha i s di ec speci ica ,ion is ,,np ac. conlponen s o he sys em h ough a cohe en s uc u e unc- ical a.nd au olna ic gene a ion om a highe lc cl speci ica ion ion [12]. Lack o co e age can be modeled in ou language by is equi ed. ailu e p opaga ion. This app oach is less es ic i e han i seems a i s glance. Fo ins ance, he ine iciency o sys em- A ailable model speci ica ion me hodologies show a n lco le el eco e y p ocedu es can be modelled by in oducing a .' e- be ween modeling powe and 11s . - iendliness. W lia ~ in one co e y" componen wi hou ailu e p ocesses which is equi ed hand e y gene al speci ica ion me hodologies like S ,ochas ic o be un ailed o he sys em o be ope a ional. and p opa- Pe i ne s [3, 41 and P oduc ion ules [5], which allow he spe- ga ing unco e ed ailu es o he " eco e y" componen . The epai o he " eco e y" componen would model he es a 'This wo k was suppo ed by he ESPRIT p ojec , o he Co iiiiiis~io~i o ac ion usuaily a e ha ype o sys em ailu es. he Eu opean Communi ies no. 1909 "SllART. Sys em RI .;isii i,iiicn aiid A c hi ec u e Tecli i qws" CH3001-5/91/0000/0452/$01.00 0 1991 IEEE 452 Lack o co e age aking down only pa o he sys em can be modeled simila ly. A componen , can be ope a ional, ailed, o do man . As in he SAVE modeling language [6, 71, he ailed s a e can be e ined Iiy ailed modes, which a e de e mined a he ime he ailu e o lie componen occu s. In addi ion, in ou language, he ope - a ,ional s ,a e can be e ined by ope a ional modes. Ope a ional ~iiodes p o ide he basis o modeling di e ences in he ail- u e p ocesses a ec ing a componen which may esul om he con igu a ion in which he sys em is wo king, and a e an use ul gc ic aliza ion expanding signi ican ly he modeling powe o he language. We also in oduce in ou language he concep o clus e . Concep ually, a clus e is a collec ion o componen s wliicli a a ce ain abs ac ion le el can be seen as a whole. Clus e s can ha e ope a ional modes and con igu a ions. Con- igu a ,ions a e also de ined a he sys em le el. A con igu a ion le iiies a mapping o componen s and clus e s ins an ia ed a a gi m le el in o ope a ional modes. This allows he concise sp-i ica ion o complex con igu a ion s a egies by exploi ing h liic a chical s uc u e o he sys em. Tlie hcha io o componen s and clus e s is desc ibed in pa- ame e izahle classes which can be ins an ia ed. A collec ion o objec s can be ins an ia ed wi h he same name. The beha io o ,he objec s wi h he same name is undis inguishable and his in o ma ion is exploi ed o he gene a ion o lumped models wliose s a es a e de ined by ac o izing ins ances wi h he same iiiiiiie and in he same s a e. By using clus e s, symme ies ha , li sys em may ha e a le els highe han he componen 1e c.l (which would be dis ega ded i a la , componen -le el desc ip ion we e used) can be made explici and exploi ed. 2.2. An example Tlic cons uc s o he language will be illus a ed h ough an cxample o mode a e complexi y. The example is a dis ibu ed anl - ,ole an da abase sys em wi h 4 si es. Each si e con ains ,wo p ocesso s and wo da abases, keeping wo. copies o he la ,a.. .4 cess o da a is pe o med h ough wo on -ends. The si s and ,lie on -ends a e connec ed by wo local-a ea ne - i oIlis (LAN’s) as shown in Figu e 1. The sys em is ope a ional i c~acli si e has a leas one un aikd p ocesso and one un ailed la abase, and a leas one on -end and he LAN o which he oli -end is connec ed a e un ailed. When he sys em is down all he componen s a e do man . In addi ion, when a on - cm l is ailcd he co esponding LAX is do man and ice e sa. Do m ili componen s do no ail. Two ailed modes a e conside ed o he p ocesso s: one e- cliii ing epai (ha d ailu e) and ano he equi ing only es a (so ailu c). The p ocesso so ailu e a e is highe when he si has only one ope a ional p ocesso , since in his con igu a- io i he p ocesso has a highe load. Da abases ha e also wo iiilcd modes: one equi ing epai (ha d ailu e) and ano he czc1ni ing only da a eco e y (so ailu e). In o de o keep he colicx o he da a consis en . w i e accesses a e pe o med in Im allcl o all he ope a ional da abases o a si e. A p ocesso ;iilu c con amina es one (and only one) ope a ional da abase wi h a p obabili y nhich depends on he ype o ailu e (ha d o so ) o he p ocesso . A con amina ed da abase is in so ailcd mode. Da a eco e y o da abases in so ailu e can be done in wo modes. The is mode ( es o ing) is possible i he he o lie da abase and a leas one p ocesso o he si e a e op- 4 ... I1 I Figu e 1: A dis ibu ed aul - ole an da abase sys em. e a ional and he si e is accessible om a leas one ope a ional on -end. When es o ing is no possible he da abase has o be eco e ed by a mo e ime-consuming eloading ope a ion. P ocesso es a s also equi e he si e o be a ailable om a leas one on -end. Two ield enginee s epai da abases, on -ends, LAN’s, and p ocesso s, wi h he highe p io i y gi en o da abases, nex o on -ends and LAN’s, and nex o p ocesso s. P ocesso es a s and da abase eco e ies a e ca ied ou by an unlimi ed numbe o ope a o s. 2.3. Model cons uc s In ou language, a model is desc ibed by a se o pa ame e s and sys em, clus e class, componen class, and epai eam des- c ip ions. The PARAMETERS cons uc o he dis ibu ed aul - ole an da abase sys em is gi en beIow. Each pa ame e can be assigned a de aul alue o be used o CTMC gene a ion i a alue is no speci ied o i . PARAMETERS e : l : ph : pds : pss : dbh : dbs : hco : e : l : p ep : p es : db ep : db es : db el : sco : 1/3600 1/800 1/20000 1/200 1/100 1/1200 1/3600 1/10 1/20 1/5 1/0.05 1/20 1/0.2 1 /* on -end ailu e a e */ /* LAN ailu e a e */ /* p ocesso ha d ailu e a e */ /* p oc. so . a e in duplex */ /* p oc. so . a e in simplex */ /* da abase ha d ailu e a e */ /* da abase so ailu e a e */ /* COV. o p oc. ha d ailu es */ /* co . o p oc. so ailu es */ /* on -end epai a e */ /* LAN epai a e */ /* p ocesso epai a e */ /* p ocesso es a a e */ /* da abase epai a e */ /* da abase es o e a e */ /* da abase eload a e */ In ou language, a sys em is desc ibed hie a chically as a se o pa ame e ized ins an ia ions o clus e and componen classes. This is done by MADE OF cons uc s included in he SYSTEM and CLUSTER CLASS cons uc s. In addi ion, he SYSTEM cons uc includes an op ional lis o esou ce a ibu es, ei he an op- e a ional o a down exp ession, and con igu a ions. Resou ce a ibu es a e logical a iables summa izing he a ailabili y o un ailed esou ces ins an ia ed a he sys em le el and a e de- ined by logical exp essions wi h a oms o he o ms compo- nen [in ege ] and cll~s e . es-a [in ege ], whe e componen (ch- e ) is a componen (clus e ) class o name ins an ia ed a he cu en (sys em) le el and es-a is a esou ce a ibu e o he clus e class. These a oms a e ue when a leas in ege in- 453 s ances a e un ailed o ha e he esou ce a ibu e ue, espec- i ely. P e iously de ined esou ce a ibu es can also be used. Resou ce a ibu es can be used in he cons uc ion o he ope - a ional/down exp ession and o he exp essions included in he desc ip ion o con igu a ions. The condi ions unde which he sys em is ope a ional a e des- c ibed by ei he an ope a ional exp ession o a down exp ession. Bo h a e logical exp essions wi h he same syn ax as esou ce a ibu e exp essions. The ope a ional exp ession e alua es o ue when he sys em is ope a ional and i s a oms ha e he same seman ics as in esou ce a ibu e exp essions. A down exp ession e alua es o ue when he sys em is down and i s a oms ha e e e sed seman ics (a leas zn ege ins ances a e ailed o ha e he esou ce a ibu e alse, espec i ely). Re- sou ce a ibu e, ope a ional, and down exp essions ha e o be buil using only he logical and, OT ope a o s. This es ic ion is imposed o gua an ee ha he s uc u e unc ion o he sys em is cohe en [12]. A con igu a ion is desc ibed by a lis o di ec i es mapping un ailed componen ins ances and clus e ins ances in o ope - a ional modes. Con igu a ions may ha e equi emen s and a e ied in he o de hey appea so ha , in a gi en s a e, he i s one whose equi emen s a e me is used. Thus, seman i- cally, a lis o con igu a ions de ines a con igu a ion s a egy a a gi en le el. Uncon igu ed (unmapped) componen and clus- e ins ances become do man . A do man clus e has all i s clus e s and un ailed componen s do man . This implici be- ha io is ollowed by many sys ems and, hus, u ns ou o be use ul. The SYSTEM cons uc o he dis ibu ed aul - ole an da abase sys em is: SYSTEM MADE OF 2 Channel o ChannelC 4 Si e o Si eC OPERATIONAL IF: Channel.UpC11 and Si e.UpC41 CONFIGURATION CLUSTERS: Channel.Up, Si e.Up ope a ional: all speci ying ha he sys em includes wo ins ances wi h name Channel o he clus e class ChannelC and ou ins ances wi h name Si e o he clus e class Si eC, and ha he sys em is ope a ional i a leas one clus e Channel and all clus e s Si e ha e hei esou ce a ibu e up ue. A con igu a ion mapping all Up clus e s in o ope a ional is included. This is necessa y because, by de aul , unmapped clus e s a e do man . The key- wo d ope a ional is used because he clus e classes do no ha e ope a ional modes. A clus e is a se o componen s seen as a complex en i y which can be con igu ed and can con igu e ,he componen s included in i . The clus e concep is hie a chical, i.e., a clus e can be de ined in e ms o lowe le el clus e s. As componen s. clus e s a e seen as ins ances o classes. The use o clus e s makes he speci ica ion o he model mo e concise and allows ,o exploi symme ies which he sys em may exhibi a le els highe han he componen le el. This is he case in he dis ibu ed aul - ole an da abase sys em and wo clus e classes a e included in he speci ica ion o he model. The clus e class ChannelC includes one on -end and he L.4N connec ed o i and is Up when bo h componen s a e un ailed. The clus e class Si eC includes he p ocesso s and da abases o a si e. The desc ip ion o Si eC is: CLUSTER CLASS: Si eC MADE OF 2 P oc o P ocC 2 Db o DbC RESOURCE ATTRIBUTES Up: P oc[l] and DbCl] CONFIGURATION REQUIREMENTS : P oc [21 COMPONENTS: P oc Duplex: 2 COMPONENTS: Db ope a ional: all CONFIGURATION COMPONENTS: P oc Simplex: 1 COMPONENTS: Db ope a ional: all The esou ce a ibu e up is ue when a leas one p ocesso and one da abase a e un ailed. I is possible, in gene al. o de- ine se e al esou ce a ibu es o a clus e class. The clus e class Si eC has wo con igu a ions. The i s one is used when d1 i s p ocesso s a e un ailed. The second one is used when only one p ocesso is un ailed. The i s con igu a ion maps he wo un ailed p ocesso s in o he ope a ional mode Duplex and all un ailed da abases in o ope a ional. The second con ig- u a ion maps he un ailed p ocesso in o he ope a ional mode Simplex and all un ailed da abases in o ope a ional. Clus e o componen classes no ha ing ope a ional modes ha e o be mapped in o ope a ional i hey a e no o become do man . When he clus e class has ope a ional modes each con igu a- ion has o be associa ed o an ope a ional mode by using he cons uc CONFIGURATION FOR: op-mode. The beha io o componen s is also desc ibed in classes. The desc ip ion o a componen class includes, in i s mo e gene al o m, lis s o pa ame e s, ope a ional modes and ailed modes. and desc ip ions o ailu e modes and epai modes. Pa ame e s a e e y use ul in p ac ice. Fo ins ance, he beha io o on - ends and LAN’s, which is quali a i ely iden ical, is desc ibed in he example by he ollowing componen class wi h pa ame e s de ining he ailu e and epai a es: COMPONENT CLASS: SimpleC PARAMETERS: ail , ep FAILURE MODE RATE: ail RATE: ep REPAIR TEAM: Fieldenginee s PLEPAIR MODE The alues o he pa ame e s a e de ined when he componen s a e ins an ia ed. Thus. a on -end would be ins an ia ed as SimpleC( e , e ). The gene al o m o a componen class cons uc will be illus- a ed by he desc ip ion o he componen class P occ o he dis ibu ed aul - ole an da abase: 454 COMPONENT CLASS: P ocC OPERATIONAL MODES: Duplex, Simplex FAILED MODES: H , S FAILURE MODE FAILED MODE: H RATE: ph PROPAGATION MODE PROBABILITY: I-hco PROPAGATION EVENT COMPONENTS: Db NUMBER: 1 FAILED MODE: S FAILURE MODE FROM: Duplex FAILED MODE: S RATE: pds PROPAGATION MODE PROBABILITY: 1-sco PROPAGATION EVENT COMPONENTS: Db NUMBER: 1 FAILED MODE: S FAILURE MODE FROM: Simplex FAILED MODE: S RATE: pss PROPAGATION MODE PROBABILITY: 1-sco PROPAGATION EVENT COMPONENTS: Db NUMBER: 1 FAILED MODE: S REPAIR MODE FROM: H RATE: p ep REPAIR TEAM: Fieldenginee s REPAIR MODE FROM: S DEPENDS UPON: /Channel [l] The componen class P occ has wo epai modes. The i s one is used o ha d ailu es and is scheduled o he epai eam Fieldenginee s; he second one is used o so ailu es, is scheduled o he epai eam Ope a o s, and can only be unde aken i a leas one channel is ope a ional (no e ha his implies ha a leas one p ocesso and he o he da abase. o he si e a e also ope a ional). Repai s a egies a e speci ied in REPAIR TEAM cons uc s which a e illus a ed by he epai eam Fieldenginee s o he dis- ibu ed aul - ole an da abase sys em: REPAIR TEAM: Fieldenginee s NUMBER: 2 STRATEGY: p io i y DbC: 1 SimpleC: 2 P ocC: 3 The eam has wo epai men and uses a p eemp i e p io i y s a egy, in which ailed componen s scheduled o he eam a e selec ed acco ding o gi en p io i ies, wi h he selec ion among componen s wi h he same p io i y being a andom when he e a e mo e ailed componen s han emaining epainnen. P io i- ies can be assigned o componen wi h gi en names as well as classes and can be made dependen o he mode in which he componen s a e ailed. I is possible o speci y and unlimi ed numbe o epai men. In his case, he STRATEGY cons uc is omi ed. The simple s a egy os ( andom o de se ice), in which p io i ies a e no speci ied, can be used when all he com- ponen s scheduled o he epai eam ha e he same p io i y. RATE: p es REPAIR TEAM: Ope a o s 2.4. Me ic speci ica ion The Same ype o me ics which a e inco po a ed in can be e alua ed om a model speci ied using he lan- guage desc ibed he e. These me ics include, among o he s, ime be ween ailu es, he mean ime o ailu e, he eliabil- i y, and he main ainabili y, as well as cos and ela ed me ics, which esul om he assignmen o cos o pedo mance indices o he s a es o he model. The me ic o be e alua ed is speci ied using he METRIC cons uc , This con- s uc includes he OPTION coIls uc o selec he me ic and, i equi ed by he chosen op ion, he INITIAL STATE and INDEX cons uc s. The INITIAL STATE cons uc can be omi ed o he s a e in which all componen s a e un ailed and has he s uc u e illus a ed in he nex sec ion. The INDEX cons uc speci ies a The componen class P occ has h ee ailu e modes. The i s iiodels ha d ailu es and i s ac i e in any ope a ional mode. The s cond and hi d ailu e modes model so ailu es in, e- e al, a lis o un ailed componen s a es, including ope a ional modes and he keywo ds ope a ional and do man , can be gi en as he a gumen o he FAILURE MODE FROM cons uc . The de- sc ip ion o a ailu e mode includes he mode in which he com- ponen is ailed. which can only be omi ed i he componen class do s no ha e ailed modes, he a e o he e en ( o ~nch componen ins ance) and, op ionally, a lis o p opagahn inod s. spec 'i ely. he and Simp1ex Ope a ional In gen. he s eadys a e a ailabili y, he poin a ailabili y, he mean p opaga ion modcs a e exclusi e e en s (a mos one o llenl Op ions equi ing an Ope a ional s a e wi h he O he caII occu ) and hei desc ip ion includes he p obabili y o mo l and a lis o p opaga ion P opaga ion e en s a e Ilo exclusi e (any combina ion o hem can in gene al occu ). .4 p opaga ion e en p opaga es he ailu e o he componen o ii gi en numbe o ope a ional ins ances o a se o componen s o a gi en class. The se is speci ied using a special cons uc called componen selec o which allows na iga ion on he in- s an ia ,ion ee o he sys em (s a ing om he le el a which ,lie conipone i is ins an ia ed) using a UNIX-like syn ax. The :;c l c ion o ,he se o componen s o which he ailu e can be 1, c)paga ed can be e ined by speci ying a lis o ope a ional 111odes in which he componen s can be a ec ed. The desc ip- ioil o a p opaga ion e en includes also he mode in which llc conipon n s a e a ec ed and he p obabili y o he e e i . P oIxd)ili ies o p opaga ion modes and e en s can be omi ed i ,li a dc aul alue o 1. unc ion o be used o he O s a e indices' 3. EXPLOITING SYMMETRIES A CTRlC is au oma ically cons uc ed om a model speci ica- ion a e selec ing a pa icula ype o me ic. Ad an age is aken o he symme ies made explici by he model speci ica- ion o educe he size o he gene a ed CTMC. This is done us- ing a hie a chical s a e desc ip ion in which clus e mac os a es and componen s a es o ins ances wi h he same name a e ac- o ized ou . This is possible because, by cons uc ion, compo- nen s and clus e s wi h he same ins an ia ion name a e undis- inguishable. We gi e nex o illus a ion pu poses he de- sc ip ion o he s a e o he aul - ole an dis ibu ed da abase 455 in which one on -end is ailed and one piucesso o one si e is in ha d ailed mode. CLUSTERS: Channel MACROSTATE INSTANCES: 1 MODE: do man COMPONENTS: Fe ailed: 1 COMPONENTS: Lan do man : 1 MACROSTATE INSTANCES: 1 MODE: ope a ional COMPONENTS: Fe COMPONENTS: Lan ope a ional : 1 ope a ional : 1 CLUSTERS: Si e MACROSTATE INSTANCES: 1 MODE: ope a ional COMPONENTS: P oc ope a ional: 1 H : 1 COMPONENTS: Db ope a ional: 2 MACROSTATE INSTANCES: 3 MODE: ope a ional COMPONENTS: P oc COMPONENTS: Db ope a ional: 2 ope a ional : 2 The educ ion o size ob ained can be signi ican . Fo ins ance, wi hou using he clus e cons uc o he language, on -ends, LAN’s, and he p ocesso s and da abases o di e en si es ha e o be conside ed di e en , and he gene a ed CTMC equi ed o he compu a ion o he a ailabili y has 408,969 s a es, while he lumped CTMC ob ained om he speci ica ion using clus- e s has only 14,850 s a es (abou 27 imes less). The educ ion is also signi ican in combina ion wi h p uning echniques [13]: 39 s a es o he educed CTMC agains 227 s a es when only s a es wi h up o wo ailed componen s a e gene a ed. 4. CONCLUSIONS A hie a chical, objec -o ien ed modeling language o aul - ol- e an compu e sys ems has been o e iewed and i s exp essi e powe illus a ed by an example o modc a e complexi y. We ha e used he language o speci y concisely niodels o sub- s an ially mo e complex sys ems [ll]. By p o iding acili ies o exp ess symme ies ha complex sys ems o en exhibi a le els highe han he componen le el, i is possible o gen- e a e au oma ically lumped s a e-le el models o much smalle size han would be gene a ed om a la , componen -le el sys- em desc ip ion. This is impo an since i is he size o he s a e-le el model wha es ic s he applicabili y o numc ical solu ion me hods. The kind o symme ies which ,he language cap u es could be ex ended by using conccp s eccn ly de el- oped in he con ex o Pe i ne modeling [14], [15]. REFERENCES K. T i edi, R. Geis . M. Smo he man, and J. B. Dugan .“Hy- b id modeling o aul - ole an sys ems” Compu . Elec. Eng. In . /., ol. 11, no. 2/3, pp. 87-108, 1984. R. Geis . M. Smo he man and R. Talley, “Modeling Reco e y Time Dis ibu ions in Ul a eliable Faul -Tole an Sys ems,” in P oc. 20 h n . Symp. on Faul -Tole an Compu ing (FTCS- 20), Newcas le upon Tyne, June 1990, pp. 499-504. M. A. Ma san, G. Con e, and G. Balbo, “A class o gene alized s ochas ic Pe i ne s o he pe o mance e alua ion o mul i- p ocesso sys ems,” ACM T ans. on Compu e Sys ems. ol. 2, pp. 93-122, May 1984. 0. C. ibe, A. Sa haye, R. C. Howe, and K. S. T i edi, “S ochas- ic Pe i Ne Modeling o VAXclus e Sys em A ailabili y,” in P oc. 3 d. In . Wo kshop on Pe i ‘Ve s and Pe o mance Models (PNPMBS), Kyo o, Japan, Decembe 1989. pp. 112- 121. J. A. Ca asco and J. Figue as, “hIETFAC: Design and Imple- men a ion o a So wa e Tool o Modeling and E alua ion o Complex Faul -Tole an Compu ing Sys ems,” in P oc. 16 h In . Synip. on Faul -Tole an Compu ing (FTCS-16), Yienna. July 1986, pp. 421-429. A. Goyal, W. C. Ca e , E. de Souza e Sil a, S. S. La enhe g. and K. S. T i edi, ”The Sys em A ailabili y Es ima o .“ in P oc. 16 h In . Synap. on Faul -Tole an Compu ing (FTCS- 16), Vienna, July 1986, pp. 84-89. A. Goyal and S. S. La enbe g, “hIodeling and Analysis o Compu e Sys em .4 ailabili y,” IBA1 Resea ch Rep. RC12158. Yo k oi n Heigh s, No . 1986. A. E. Conway and A. Goyal, “Mon e Ca lo Simula ion o Com- pu e Sys em A ailabili y/Reliabili y Models,“ in P oc. 17 h In . Symp. on Faul -Tole an Compu ing (FTCS-17). Pi s- bu gh, 1987, pp. 230-235. Juan A. Ca asco. “Failu e dis ance-based simula ion o epai - able aul - ole an sys ems.” in P oc. 5 h In . Con . on .llo l- elling Techniques and Tools o Compu e Pe o mance E nl- ua ion, To ino, Feb ua y 1991. pp. 337-351. Juan A. Ca asco, ”E icien ansien simula ion o ailu e/ e- pai ma ko ian models,” Technical Repo . UPC, June 1990. submi ed o publica ion. Juan A. Ca asco, “Dependabili y hiodeling in ShlART“. Re- po , ESPRIT p ojec 1609: SblART (Sys em hleasu emen and A chi ec u e Techniques), Janua y 1990. R. E. Ba low and F. P oschan, S a is ical Theo y o Reliabili y and Li e Tes ing: P obabili y Models, Sil e Sp ing. 1981. R. R. hlun z, E. de Souza e Sil a. and -1. Goyal. “Bounding A ailabili y o Repai able Compu e Sys ems.“ IEEE T ans. on Compu e s, ol. 38, no. 12; Decembe 1989. pp. 1711- 1723. C. Du heille and S. Haddad. “Agg ega ion o S a es in Col- o ed S ochas ic Pe i Ne s: Applica ion o a Slul ip ocesso A4 chi ec u e,“ in P oc. 3 d In . Il’o kshop on Pe i . -e s and Pe o mance Jlcdels (P.VP.I SS), Kyo o. Decembe 1989. pp. 30-49. Juan A. Ca asco, “.Au oma ed Cons uc ion o Compound Ma ko Chains om Gene alized S ochas ic High-Le el Pe i Ne s,” in P oc. 3 d In . Ii‘o kshop on Pe i , -e s and Pe o - mance Models (P.YP. 8S), Kyo o, Decembe 1989. pp. 03-103. 456