HIERARCHICAL,
OB
JECT-ORIENTED MODELING
OF FAULT-TOLERANT COMPUTER
SYSTEMS
Juan
A.
Ca asco*
Depa amen d'Enginye ia Elec bnica, UPC
Diagonal
647,
pl a.
9
OS02S-Ba celona, Spain
Abs ac
A
hie a chical, objec -o ien ed modeling language o he speci-
ica ion o dependabili y models o complex aul - ole an com-
pu e sys ems is o e iewed. The language inco po a es he
hie a chical no ions o clus e , ope a ional mode and con ig-
u a ion and bo ows om objec -o ien ed p og animing he
concep s o class, pa ame e iza ion, and ins an ia ion. These
ea u es oge he esul in
a
highly exp essi e en i onmen al-
lowing he concise speci ica ion o sophis ica ed dependabili y
models o complex sys ems. In addi ion, he language sup-
po s he decla a ion o symme ies ha sys ems may exhibi
a le els highe han he componen le el. These symme ies
can be used o au oma ically gene a e lumped s a e-le el mod-
els o signi ican ly educed size in ela ion o he s a e-le el
models which would be gene a ed om
a
la , componen -le el
desc ip ion o he sys em.
1.
INTRODUCTION
ci ica ion o a bi a y CThlC dependabili y models bu equi e
complex and .hus e o -p one desc ip ions o la ge sys ems.
Ano he app oach
[6,
71
is he use o
a
special-pu pose lan-
guage wi h
an
implici modeling poin o iew and special con-
s uc s easing he speci ica ion o o en-encoun e ed complex
dependencies. In addi ion o being mo e use - iendly, he use
o
a
high-le el modeling language has he ad an age o con ey
ing seman ic knowledge which can be exploi ed du ing model
solu ion
[S,
9,
IO].
This pape o e iews
a
hie a chical, objec -o ien ed modeling
language o aul - ole an compu e sys ems which akes he
SAVE
modeling language
[6,7]
as
s a ing poin , bu in oduces
many ex ensions (clus e s, ope a ional modes, con igu a ions)
enhancing signi ican ly i s modeling powe and use - iendliness
and suppo ing au oma ic gene a ion o s a e-le el models o
educed size when,
as
i is o en he case, he sys em has sym-
me ies a le els highe han he componen le el. The la e
is impo an since i is he size o he CTLIC wha ul ima ely
limi s he applica ion o nume ical solu ion me hods. The es
_-
o he pape is o ganized
as
ollows. Sec ion
2
o e iews he
desc ip ion o he language syn ax and seman ics and addi-
ional examples can be ound in
[ll]).
Sec ion
3
discusses he
ep esen aLion o he s a es o he lumped CTSIC's
.
Sec ion
4
concludes he pape
A
aul - ole an compu e sys em can o en be concep ualized
ailu e, eco e y, and epai p ocesses. Dependencies among
componen s o en a ise in eal aul - ole an compu e sys ems
due
o
ailu e p opaga ion, limi ed eco e y e iciency, iecon-
igu a ions, and epai . S ochas ic p ocesses allow o conside
as
made
up
o
componen s ,-hanging hei s a e
as
a
esul
o
language using
O
mode a e
(a
all hese impo an de ails. Reco e y p ocesses a e ypically
se e al o de s o magni ude as e han bo h ailu e
and
epai
2.
LANGUAGE
OVERVIEW
p ocesses and can be modelled by using ins an aneous co e age
p obabili ies
[l],
which can be ob ,ained by s a is ical analysis
2.1.
Modeling
amewo k
[2]
o expe imen al da a collec ed om aul -injec ion expe i-
men s. Typically, ailu e and epai imes a e assumed o ha e In Ou language,
a
aul - ole an compu e sys em is concep u-
exponen ial dis ibu ions
so
ha he s ochas ic beha io o he alized
as
made
UP
o componen s and epai eams. Componen
sys em
can
be desc ibed by
a
con inuolls
ime
~~~l;~~,
s a es a e modi ied by ailu e and epai p ocesses. Failu e
p o-
(CTMC)
ha ing ailu e
epai
gene al, de. cesses only a ec un ailed componen s and a e associa ed wi h
pendencies among he beha io o he compoI1eIl s o he
sys.
Pa icula componen s o he sps em bu , in gene al. can he
em a e such ha he CTMC has
o
be gene a ed
and
sol ed p opaga ed o o he componen s. Repai p ocesses a e pe -
using gene al-pu pose, s a e-le el me hods,
Excep
o
sys ems
o med by epai eams. The sys em is ei he ope a ional o
wi h
an
small numbe
o
componen s, ile
CTP IC
has
a
size
down,
as
de e mined by he un ailed/ ailed condi ion o he
(numbe
o
s a es) sucll ha i s di ec
speci ica ,ion
is
,,np ac.
conlponen s o he sys em h ough
a
cohe en s uc u e
unc-
ical a.nd au olna ic gene a ion om
a
highe lc cl
speci ica ion
ion
[12].
Lack o co e age can be modeled in ou language
by
is equi ed. ailu e p opaga ion. This app oach is less es ic i e han
i
seems a i s glance. Fo ins ance, he ine iciency
o
sys em-
A ailable model speci ica ion me hodologies show
a
n lco le el eco e y p ocedu es can be modelled by in oducing
a
.' e-
be ween modeling powe and 11s . - iendliness.
W
lia ~ in one co e y" componen wi hou ailu e p ocesses which is equi ed
hand e y gene al speci ica ion me hodologies like S ,ochas ic o be un ailed o he sys em o be ope a ional. and
p opa-
Pe i ne s
[3,
41
and P oduc ion ules
[5],
which allow he spe- ga ing unco e ed ailu es o he " eco e y" componen . The
epai o he " eco e y" componen would model he es a
'This
wo k
was
suppo ed
by
he
ESPRIT
p ojec ,
o
he
Co iiiiiis~io~i
o
ac ion
usuaily
a e
ha
ype
o
sys em
ailu es.
he
Eu opean
Communi ies
no.
1909
"SllART.
Sys em
RI .;isii i,iiicn
aiid
A c
hi
ec
u e
Tecli i
qws"
CH3001-5/91/0000/0452/$01.00
0
1991
IEEE
452
Lack o co e age aking down only pa o he sys em can be
modeled simila ly.
A
componen , can be ope a ional, ailed,
o
do man .
As
in he
SAVE
modeling language
[6, 71,
he ailed s a e can be e ined
Iiy
ailed modes, which a e de e mined a he ime he ailu e o
lie componen occu s.
In
addi ion, in
ou
language, he ope -
a ,ional s ,a e can be e ined by ope a ional modes. Ope a ional
~iiodes p o ide he basis o modeling di e ences in he ail-
u e
p ocesses a ec ing a componen which may esul om he
con igu a ion in which he sys em is wo king, and a e an use ul
gc ic aliza ion expanding signi ican ly he modeling powe o
he
language. We also in oduce in
ou
language he concep
o clus e . Concep ually,
a
clus e is
a
collec ion o componen s
wliicli a
a
ce ain abs ac ion le el can be seen
as
a
whole.
Clus e s can ha e ope a ional modes and con igu a ions.
Con-
igu a ,ions a e also de ined a he sys em le el.
A
con igu a ion
le iiies a mapping o componen s and clus e s ins an ia ed a
a
gi m
le el in o ope a ional modes. This allows he concise
sp-i ica ion o complex con igu a ion s a egies by exploi ing
h
liic a chical s uc u e o he sys em.
Tlie hcha io o componen s and clus e s is desc ibed in
pa-
ame e izahle classes which can be ins an ia ed.
A
collec ion o
objec s can be ins an ia ed wi h he same name. The beha io
o ,he objec s wi h he same name is undis inguishable and his
in o ma ion is exploi ed o he gene a ion o lumped models
wliose
s a es a e de ined by ac o izing ins ances wi h he same
iiiiiiie and in he same s a e.
By
using clus e s, symme ies
ha , li sys em may ha e a le els highe han he componen
1e c.l (which would be dis ega ded i a la , componen -le el
desc ip ion we e used) can be made explici and exploi ed.
2.2.
An
example
Tlic
cons uc s o he language will be illus a ed h ough an
cxample o mode a e complexi y. The example is a dis ibu ed
anl - ,ole an da abase sys em wi h
4
si es. Each si e con ains
,wo p ocesso s and wo da abases, keeping wo. copies o he
la ,a.. .4 cess o da a is pe o med h ough wo on -ends. The
si s
and ,lie on -ends a e connec ed by wo local-a ea ne -
i oIlis
(LAN’s)
as
shown in Figu e
1.
The sys em is ope a ional
i
c~acli
si e
has a leas one un aikd p ocesso and one un ailed
la abase, and
a
leas one on -end and he
LAN
o which he
oli -end is connec ed a e un ailed. When he sys em is down
all he componen s a e do man .
In
addi ion, when
a
on -
cm l is ailcd
he
co esponding
LAX
is do man and ice e sa.
Do m ili
componen s do no ail.
Two
ailed modes a e conside ed o he p ocesso s: one e-
cliii ing epai (ha d ailu e) and ano he equi ing only es a
(so ailu c). The p ocesso so ailu e a e is highe when he
si
has only one ope a ional p ocesso , since in his con igu a-
io i
he p ocesso has
a
highe load. Da abases ha e also wo
iiilcd modes: one equi ing epai (ha d ailu e) and ano he
czc1ni ing only da a eco e y (so ailu e). In o de o keep he
colicx
o he da a consis en . w i e accesses a e pe o med in
Im allcl
o
all he ope a ional da abases o
a
si e.
A
p ocesso
;iilu c con amina es one (and only one) ope a ional da abase
wi h
a
p obabili y nhich depends
on
he ype o ailu e (ha d
o
so )
o
he p ocesso .
A
con amina ed da abase is in so
ailcd mode. Da a eco e y o da abases in so ailu e can be
done
in
wo
modes. The is mode ( es o ing) is possible i he
he o lie da abase and
a
leas one p ocesso
o
he si e a e
op-
4
...
I1
I
Figu e
1:
A
dis ibu ed aul - ole an da abase sys em.
e a ional and he si e is accessible om a leas one ope a ional
on -end. When es o ing is no possible he da abase has o
be eco e ed by
a
mo e ime-consuming eloading ope a ion.
P ocesso es a s also equi e he si e o be a ailable om a
leas one on -end.
Two ield enginee s epai da abases, on -ends,
LAN’s,
and
p ocesso s, wi h he highe p io i y gi en o da abases, nex
o on -ends and
LAN’s,
and nex o p ocesso s.
P ocesso
es a s and da abase eco e ies a e ca ied ou by an unlimi ed
numbe o ope a o s.
2.3.
Model
cons uc s
In
ou
language,
a
model is desc ibed by
a
se o pa ame e s
and sys em, clus e class, componen class, and epai eam des-
c ip ions. The
PARAMETERS
cons uc o he dis ibu ed aul -
ole an da abase sys em is gi en beIow. Each pa ame e can
be assigned
a
de aul alue o be used o CTMC gene a ion i
a
alue is no speci ied o i .
PARAMETERS
e :
l :
ph
:
pds
:
pss
:
dbh
:
dbs
:
hco :
e
:
l
:
p ep
:
p es
:
db ep
:
db es :
db el :
sco :
1/3600
1/800
1/20000
1/200
1/100
1/1200
1/3600
1/10
1/20
1/5
1/0.05
1/20
1/0.2
1
/*
on -end ailu e a e
*/
/*
LAN
ailu e a e
*/
/*
p ocesso ha d ailu e a e
*/
/*
p oc. so
.
a e in duplex
*/
/*
p oc. so . a e in simplex
*/
/*
da abase ha d ailu e a e
*/
/*
da abase so ailu e a e
*/
/*
COV. o p oc. ha d ailu es
*/
/*
co . o p oc. so ailu es
*/
/*
on -end epai a e
*/
/*
LAN
epai a e
*/
/*
p ocesso epai a e
*/
/*
p ocesso es a a e
*/
/*
da abase epai a e
*/
/*
da abase es o e a e
*/
/*
da abase eload a e
*/
In
ou
language,
a
sys em is desc ibed hie a chically as
a
se o
pa ame e ized ins an ia ions o clus e and componen classes.
This
is
done by
MADE
OF
cons uc s included in he
SYSTEM
and
CLUSTER CLASS
cons uc s. In addi ion, he
SYSTEM
cons uc
includes an op ional lis o esou ce a ibu es, ei he an
op-
e a ional
o
a
down exp ession, and con igu a ions. Resou ce
a ibu es a e logical a iables summa izing he a ailabili y
o
un ailed esou ces ins an ia ed a he sys em le el and a e de-
ined by logical exp essions wi h a oms o he o ms
compo-
nen [in ege ]
and
cll~s e . es-a [in ege ],
whe e
componen
(ch-
e )
is
a
componen (clus e ) class
o
name ins an ia ed a he
cu en (sys em) le el and
es-a
is a esou ce a ibu e o he
clus e class. These a oms a e ue when a leas
in ege
in-
453
s ances a e un ailed
o
ha e he esou ce a ibu e ue, espec-
i ely. P e iously de ined esou ce a ibu es can also be used.
Resou ce a ibu es can be used in he cons uc ion o he ope -
a ional/down exp ession and o he exp essions included in he
desc ip ion o con igu a ions.
The condi ions unde which he sys em is ope a ional a e des-
c ibed by ei he an ope a ional exp ession
o
a
down exp ession.
Bo h a e logical exp essions wi h he same syn ax as esou ce
a ibu e exp essions. The ope a ional exp ession e alua es o
ue when he sys em is ope a ional and i s a oms ha e he
same seman ics as in esou ce a ibu e exp essions.
A
down
exp ession e alua es o ue when he sys em is down and i s
a oms ha e e e sed seman ics (a leas
zn ege
ins ances a e
ailed
o
ha e he esou ce a ibu e alse, espec i ely). Re-
sou ce a ibu e, ope a ional, and down exp essions ha e o be
buil using only he logical
and,
OT
ope a o s. This es ic ion is
imposed o gua an ee ha he s uc u e unc ion
o
he sys em
is cohe en
[12].
A
con igu a ion is desc ibed by
a
lis o di ec i es mapping
un ailed componen ins ances and clus e ins ances in o ope -
a ional modes. Con igu a ions may ha e equi emen s and a e
ied in he o de hey appea
so
ha , in a gi en s a e, he
i s one whose equi emen s a e me is used. Thus, seman i-
cally,
a
lis o con igu a ions de ines a con igu a ion s a egy a
a
gi en le el. Uncon igu ed (unmapped) componen and clus-
e ins ances become do man .
A
do man clus e has all i s
clus e s and un ailed componen s do man . This implici be-
ha io is ollowed by many sys ems and, hus, u ns ou o be
use ul.
The SYSTEM cons uc
o
he dis ibu ed aul - ole an da abase
sys em is:
SYSTEM
MADE OF
2
Channel o ChannelC
4 Si e o Si eC
OPERATIONAL IF: Channel.UpC11
and
Si e.UpC41
CONFIGURATION
CLUSTERS: Channel.Up, Si e.Up
ope a ional: all
speci ying ha he sys em includes wo ins ances wi h name
Channel o he clus e class ChannelC and ou ins ances wi h
name Si e o he clus e class Si eC, and ha he sys em is
ope a ional
i
a leas one clus e Channel and all clus e s Si e
ha e hei esou ce a ibu e up ue.
A
con igu a ion mapping
all Up clus e s in o ope a ional is included. This is necessa y
because, by de aul , unmapped clus e s a e do man . The key-
wo d ope a ional is used because he clus e classes do no
ha e ope a ional modes.
A
clus e is
a
se o componen s seen
as
a
complex en i y which
can be con igu ed and can con igu e ,he componen s included
in i . The clus e concep is hie a chical, i.e.,
a
clus e can be
de ined in e ms o lowe le el clus e s.
As
componen s. clus e s
a e seen as ins ances o classes. The use o clus e s makes he
speci ica ion o he model mo e concise and allows
,o
exploi
symme ies which he sys em may exhibi a le els highe han
he componen le el. This is he case in he dis ibu ed aul -
ole an da abase sys em and wo clus e classes a e included
in he speci ica ion o he model. The clus e class ChannelC
includes one on -end and he
L.4N
connec ed o i and
is
Up
when bo h componen s a e un ailed. The clus e class Si eC
includes he p ocesso s and da abases o a si e. The desc ip ion
o Si eC is:
CLUSTER CLASS: Si eC
MADE
OF
2
P oc o P ocC
2
Db o DbC
RESOURCE ATTRIBUTES
Up: P oc[l] and DbCl]
CONFIGURATION
REQUIREMENTS
:
P oc
[21
COMPONENTS: P oc
Duplex:
2
COMPONENTS: Db
ope a ional:
all
CONFIGURATION
COMPONENTS: P oc
Simplex:
1
COMPONENTS: Db
ope a ional: all
The esou ce a ibu e up is ue when a leas one p ocesso
and one da abase a e un ailed. I is possible, in gene al.
o
de-
ine se e al esou ce a ibu es o
a
clus e class. The clus e
class Si eC has wo con igu a ions. The i s one is used when
d1 i s p ocesso s a e un ailed. The second one
is
used when
only one p ocesso is un ailed. The i s con igu a ion maps
he wo un ailed p ocesso s in o he ope a ional mode Duplex
and all un ailed da abases in o ope a ional. The second con ig-
u a ion maps he un ailed p ocesso in o he ope a ional mode
Simplex and all un ailed da abases in o ope a ional. Clus e
o
componen classes no ha ing ope a ional modes ha e o be
mapped in o ope a ional i hey a e no o become do man .
When he clus e class
has
ope a ional modes each con igu a-
ion has
o
be associa ed o
an
ope a ional mode
by
using he
cons uc
CONFIGURATION
FOR:
op-mode.
The beha io o componen s is also desc ibed in classes. The
desc ip ion o a componen class includes, in i s mo e gene al
o m, lis s o pa ame e s, ope a ional modes and ailed modes.
and desc ip ions o ailu e modes and epai modes. Pa ame e s
a e e y use ul in p ac ice.
Fo
ins ance, he beha io o on -
ends and
LAN’s,
which is quali a i ely iden ical, is desc ibed
in
he example by he ollowing componen class wi h pa ame e s
de ining he ailu e and epai a es:
COMPONENT CLASS: SimpleC
PARAMETERS: ail , ep
FAILURE
MODE
RATE: ail
RATE: ep
REPAIR TEAM: Fieldenginee s
PLEPAIR
MODE
The alues o he pa ame e s a e de ined when he componen s
a e ins an ia ed. Thus.
a
on -end would be ins an ia ed
as
SimpleC( e , e ).
The gene al o m o a componen class cons uc will be illus-
a ed by he desc ip ion o he componen class P occ o he
dis ibu ed aul - ole an da abase:
454
COMPONENT CLASS: P ocC
OPERATIONAL MODES: Duplex, Simplex
FAILED MODES: H , S
FAILURE MODE
FAILED MODE: H
RATE: ph
PROPAGATION MODE
PROBABILITY: I-hco
PROPAGATION EVENT
COMPONENTS: Db
NUMBER: 1
FAILED MODE: S
FAILURE MODE FROM: Duplex
FAILED MODE: S
RATE: pds
PROPAGATION MODE
PROBABILITY: 1-sco
PROPAGATION EVENT
COMPONENTS: Db
NUMBER:
1
FAILED MODE: S
FAILURE MODE FROM: Simplex
FAILED MODE: S
RATE: pss
PROPAGATION MODE
PROBABILITY: 1-sco
PROPAGATION EVENT
COMPONENTS: Db
NUMBER:
1
FAILED MODE: S
REPAIR MODE FROM: H
RATE: p ep
REPAIR TEAM: Fieldenginee s
REPAIR MODE FROM: S
DEPENDS UPON: /Channel
[l]
The componen class
P occ
has wo epai modes. The i s
one is used o ha d ailu es and is scheduled o he epai
eam
Fieldenginee s;
he second one is used o so ailu es,
is scheduled o he epai eam
Ope a o s,
and can only be
unde aken i a leas one channel is ope a ional (no e ha
his implies ha a leas one p ocesso and he o he da abase.
o he si e a e also ope a ional).
Repai s a egies a e speci ied in
REPAIR TEAM
cons uc s which
a e illus a ed by he epai eam
Fieldenginee s
o he dis-
ibu ed aul - ole an da abase sys em:
REPAIR TEAM: Fieldenginee s
NUMBER:
2
STRATEGY: p io i y
DbC:
1
SimpleC:
2
P ocC:
3
The eam has wo epai men and uses
a
p eemp i e p io i y
s a egy, in which ailed componen s scheduled o he eam a e
selec ed acco ding o gi en p io i ies, wi h he selec ion among
componen s wi h he same p io i y being a andom when he e
a e mo e ailed componen s han emaining epainnen. P io i-
ies can be assigned o componen wi h gi en names as well as
classes and can be made dependen o he mode in which he
componen s a e ailed. I is possible o speci y and
unlimi ed
numbe o epai men. In his case, he
STRATEGY
cons uc
is
omi ed. The simple s a egy
os
( andom o de se ice), in
which p io i ies a e no speci ied, can be used when all he com-
ponen s scheduled o he epai eam ha e he same p io i y.
RATE: p es
REPAIR TEAM: Ope a o s
2.4.
Me ic speci ica ion
The
Same
ype
o
me ics
which
a e
inco po a ed
in
can
be e alua ed
om
a
model
speci ied
using
he
lan-
guage
desc ibed he e.
These
me ics
include,
among
o he s,
ime
be ween
ailu es,
he
mean ime
o
ailu e,
he
eliabil-
i y,
and he main ainabili y,
as
well
as
cos
and
ela ed
me ics,
which esul
om
he assignmen
o
cos
o
pedo mance
indices
o
he
s a es
o
he
model.
The
me ic
o
be e alua ed
is
speci ied
using
he
METRIC
cons uc ,
This
con-
s uc includes he
OPTION
coIls uc o selec he me ic and,
i
equi ed by he chosen op ion, he
INITIAL
STATE
and
INDEX
cons uc s. The
INITIAL STATE
cons uc can be omi ed o he
s a e in which all componen s a e un ailed and has he s uc u e
illus a ed in he nex sec ion. The
INDEX
cons uc speci ies
a
The componen class
P occ
has h ee ailu e modes. The i s
iiodels ha d ailu es and i s ac i e in any ope a ional mode.
The s cond and hi d ailu e modes model so ailu es in, e-
e al, a lis
o
un ailed componen s a es, including ope a ional
modes and he keywo ds
ope a ional
and
do man ,
can be gi en
as
he a gumen o he
FAILURE MODE FROM
cons uc . The de-
sc ip ion o
a
ailu e mode includes he mode in which he com-
ponen
is
ailed. which can only be omi ed i he componen
class
do s
no ha e ailed modes, he a e o he e en ( o
~nch componen ins ance) and, op ionally,
a
lis o p opagahn
inod s.
spec 'i ely.
he
and
Simp1ex
Ope a ional In gen. he s eadys a e a ailabili y, he poin a ailabili y, he
mean
p opaga ion modcs
a e
exclusi e
e en s (a mos one
o
llenl Op ions equi ing
an
Ope a ional
s a e
wi h
he
O
he
caII
occu )
and
hei
desc ip ion
includes
he
p obabili y
o
mo l
and
a
lis
o
p opaga ion
P opaga ion
e en s
a e
Ilo
exclusi e (any combina ion o hem can in gene al occu ).
.4
p opaga ion e en p opaga es he ailu e o he componen o
ii
gi en numbe
o
ope a ional ins ances o
a
se o componen s
o
a
gi en class. The se is speci ied using
a
special cons uc
called componen selec o which allows na iga ion on he in-
s an ia ,ion ee o he sys em (s a ing om he le el a which
,lie conipone i
is
ins an ia ed) using
a
UNIX-like syn ax. The
:;c l c ion o ,he se
o
componen s o which he ailu e can be
1, c)paga ed can be e ined by speci ying
a
lis o ope a ional
111odes in which he componen s can be a ec ed. The desc ip-
ioil o
a
p opaga ion e en includes also he mode in which
llc
conipon n s a e a ec ed and he p obabili y o he e e i .
P oIxd)ili ies o p opaga ion modes and e en s can be omi ed
i ,li
a
dc aul alue o
1.
unc ion
o
be
used
o
he
O
s a e
indices'
3.
EXPLOITING SYMMETRIES
A
CTRlC
is au oma ically cons uc ed om
a
model speci ica-
ion a e selec ing
a
pa icula ype o me ic. Ad an age is
aken
o
he symme ies made explici by he model speci ica-
ion o educe he size o he gene a ed CTMC. This is done
us-
ing
a
hie a chical s a e desc ip ion in which clus e mac os a es
and componen s a es o ins ances wi h he same name a e ac-
o ized ou . This is possible because, by cons uc ion, compo-
nen s and clus e s wi h he same ins an ia ion name a e undis-
inguishable. We gi e nex o illus a ion pu poses he de-
sc ip ion o he s a e
o
he aul - ole an dis ibu ed da abase
455
in which one on -end is ailed and one piucesso o one si e is
in ha d ailed mode.
CLUSTERS: Channel
MACROSTATE
INSTANCES:
1
MODE:
do man
COMPONENTS:
Fe
ailed:
1
COMPONENTS: Lan
do man :
1
MACROSTATE
INSTANCES:
1
MODE:
ope a ional
COMPONENTS:
Fe
COMPONENTS: Lan
ope a ional
:
1
ope a ional
:
1
CLUSTERS: Si e
MACROSTATE
INSTANCES:
1
MODE:
ope a ional
COMPONENTS: P oc
ope a ional:
1
H :
1
COMPONENTS: Db
ope a ional:
2
MACROSTATE
INSTANCES:
3
MODE:
ope a ional
COMPONENTS: P oc
COMPONENTS:
Db
ope a ional:
2
ope a ional
:
2
The educ ion o size ob ained can be signi ican .
Fo
ins ance,
wi hou using he clus e cons uc o he language, on -ends,
LAN’s,
and he p ocesso s and da abases o di e en si es ha e
o
be conside ed di e en , and he gene a ed CTMC equi ed
o he compu a ion o he a ailabili y has
408,969
s a es, while
he lumped
CTMC
ob ained om he speci ica ion using
clus-
e s has only
14,850
s a es (abou
27
imes less). The educ ion
is also signi ican in combina ion wi h p uning echniques
[13]:
39
s a es o he educed CTMC agains
227
s a es when only
s a es wi h up o
wo
ailed componen s a e gene a ed.
4.
CONCLUSIONS
A
hie a chical, objec -o ien ed modeling language o aul - ol-
e an compu e sys ems has been o e iewed and i s exp essi e
powe illus a ed by an example o modc a e complexi y. We
ha e used he language o speci y concisely niodels o sub-
s an ially mo e complex sys ems
[ll].
By p o iding acili ies
o exp ess symme ies ha complex sys ems o en exhibi
a
le els highe han
he
componen le el, i is possible o gen-
e a e au oma ically lumped s a e-le el models o much smalle
size han would be gene a ed om
a
la , componen -le el
sys-
em desc ip ion. This is impo an since i is he size o he
s a e-le el model wha es ic s he applicabili y o numc ical
solu ion me hods. The kind o symme ies which ,he language
cap u es could be ex ended by using conccp s eccn ly de el-
oped in he con ex o Pe i ne modeling
[14],
[15].
REFERENCES
K.
T i edi, R. Geis .
M.
Smo he man, and
J.
B. Dugan .“Hy-
b id modeling o aul - ole an sys ems”
Compu .
Elec.
Eng.
In .
/.,
ol. 11, no. 2/3, pp. 87-108, 1984.
R.
Geis .
M.
Smo he man and
R.
Talley, “Modeling Reco e y
Time Dis ibu ions in Ul a eliable Faul -Tole an Sys ems,” in
P oc. 20 h
n .
Symp. on Faul -Tole an Compu ing (FTCS-
20),
Newcas le upon Tyne, June 1990, pp. 499-504.
M.
A.
Ma san, G. Con e, and
G.
Balbo,
“A
class
o
gene alized
s ochas ic Pe i ne s
o
he pe o mance e alua ion o
mul i-
p ocesso sys ems,”
ACM
T ans. on Compu e Sys ems.
ol.
2, pp. 93-122, May 1984.
0.
C.
ibe,
A.
Sa haye, R.
C.
Howe, and
K.
S.
T i edi, “S ochas-
ic Pe i Ne Modeling
o
VAXclus e Sys em A ailabili y,” in
P oc.
3 d. In . Wo kshop on Pe i ‘Ve s and Pe o mance
Models
(PNPMBS),
Kyo o, Japan, Decembe 1989.
pp.
112-
121.
J.
A.
Ca asco and
J.
Figue as,
“hIETFAC:
Design and Imple-
men a ion o a So wa e Tool
o
Modeling and E alua ion
o
Complex Faul -Tole an Compu ing Sys ems,” in
P oc. 16 h
In . Synip. on Faul -Tole an Compu ing (FTCS-16),
Yienna.
July 1986, pp. 421-429.
A.
Goyal,
W.
C.
Ca e ,
E.
de Souza e Sil a,
S.
S.
La enhe g.
and
K.
S.
T i edi, ”The Sys em A ailabili y Es ima o .“ in
P oc. 16 h In . Synap. on Faul -Tole an Compu ing (FTCS-
16),
Vienna, July 1986, pp. 84-89.
A.
Goyal and
S.
S.
La enbe g, “hIodeling and Analysis o
Compu e Sys em .4 ailabili y,”
IBA1
Resea ch Rep.
RC12158.
Yo k oi n Heigh s, No . 1986.
A. E. Conway and
A.
Goyal, “Mon e Ca lo Simula ion o Com-
pu e Sys em
A ailabili y/Reliabili y
Models,“ in
P oc. 17 h
In . Symp. on Faul -Tole an Compu ing (FTCS-17).
Pi s-
bu gh, 1987,
pp.
230-235.
Juan
A.
Ca asco. “Failu e dis ance-based simula ion
o
epai -
able aul - ole an sys ems.” in
P oc. 5 h In .
Con .
on
.llo l-
elling Techniques and
Tools
o Compu e Pe o mance
E nl-
ua ion,
To ino, Feb ua y 1991. pp. 337-351.
Juan
A.
Ca asco, ”E icien ansien simula ion o ailu e/ e-
pai ma ko ian models,” Technical Repo . UPC, June
1990.
submi ed o publica ion.
Juan
A.
Ca asco, “Dependabili y hiodeling in
ShlART“.
Re-
po , ESPRIT p ojec 1609:
SblART
(Sys em hleasu emen
and A chi ec u e Techniques), Janua y 1990.
R. E. Ba low and
F.
P oschan,
S a is ical Theo y o Reliabili y
and Li e Tes ing: P obabili y Models,
Sil e Sp ing. 1981.
R. R. hlun z, E. de Souza e Sil a. and
-1.
Goyal. “Bounding
A ailabili y o Repai able Compu e Sys ems.“
IEEE T ans.
on Compu e s,
ol. 38, no. 12; Decembe 1989.
pp.
1711-
1723.
C.
Du heille and
S.
Haddad. “Agg ega ion o S a es
in
Col-
o ed S ochas ic Pe i Ne s: Applica ion o a Slul ip ocesso
A4 chi ec u e,“ in
P oc.
3 d
In .
Il’o kshop on
Pe i
. -e s
and
Pe o mance Jlcdels
(P.VP.I SS),
Kyo o. Decembe
1989.
pp.
30-49.
Juan
A.
Ca asco, “.Au oma ed Cons uc ion
o
Compound
Ma ko Chains om Gene alized S ochas ic High-Le el Pe i
Ne s,” in
P oc.
3 d
In . Ii‘o kshop on Pe i , -e s and Pe o -
mance Models
(P.YP. 8S),
Kyo o, Decembe 1989.
pp.
03-103.
456