scieee Open visual document viewer

Fitting Software Execution-Time Exceedance into a Residual Random Fault in ISO-26262

Agirre, Irune,Cazorla, Francisco J.,Abella Ferrer, Jaume,Hernandez, Carles,Mezzetti, Enrico,Azkarate-askasua, Mikel,Vardanega, Tullio

Abstract

Car manufacturers relentlessly replace or augment the functionality of mechanical subsystems with electronic components. Most such subsystems (e.g., steer-by-wire) are safety related, hence, subject to regulation. ISO-26262, the dominant standard for road vehicles, regards software faults as systematic , while differentiating hardware faults between systematic and random . The analysis of systematic faults entails rigorous processes and qualitative considerations. The increasing complexity of modern on-board computers, however, questions the very notion of treating the violation of execution-time envelopes for software programs as a systematic fault. Modern hardware in fact reduces the user's ability to delve deep enough into the fabric of hardware–software interaction to gage its extent of contribution to the worst-case execution time (WCET). Changing the nature of the WCET-analysis problem may help address that challenge effectively. To this end, we propose a solution that should allow ISO-26262 to quantify the likelihood of execution-time exceedance events, relating it to target failure metrics employed in support of certification arguments, similarly to random faults in hardware. To this end, we inject randomization in the timing behavior of the computer hardware to relieve the user from the need to control hard-to-reach low-level parts, and use measurement-based probabilistic timing analysis to quantify, constructively, the failure rates resulting from the likelihood of execution-time exceedance events.

Full text

Fi ing So wa e Execu ion-Time Exceedance in o a Residual Random Faul in ISO-26262 I une Agi e, F ancisco J. Cazo la, Jaume Abella, Ca les He nandez, En ico Mezze i, Mikel Azka a e-askasua, and Tullio Va danega Abs ac —Ca manu ac u e s elen lessly eplace o augmen he unc ionali y o mechanical subsys ems wi h elec onic com- ponen s. Mos such subsys ems (e.g., s ee -by-wi e) a e sa e y ela ed, hence subjec o egula ion. ISO-26262, he dominan s anda d o oad ehicles, ega ds so wa e aul s as sys ema ic, while di e en ia ing ha dwa e aul s be ween sys ema ic and andom. The analysis o sys ema ic aul s en ails igo ous p o- cesses and quali a i e conside a ions. The inc easing complexi y o mode n on-boa d compu e s, howe e , ques ions he e y no ion o ea ing he iola ion o execu ion- ime en elopes o so wa e p og ams as a sys ema ic aul . Mode n ha dwa e in ac educes he use ’s abili y o del e deep enough in o he ab ic o ha dwa e-so wa e in e ac ion o gage i s ex en o con ibu ion o wo s -case execu ion ime (WCET). Changing he na u e o he WCET-analysis p oblem may help add ess ha challenge e ec i ely. To his end, we p opose a solu ion ha should allow ISO-26262 o quan i y he likelihood o execu ion- ime exceedance e en s, ela ing i o a ge ailu e me ics employed in suppo o ce i ica ion a gumen s, simila ly o andom aul s in ha dwa e. To his end, we injec andomiza ion in he iming beha io o he compu e ha dwa e o elie e he use om he need o con ol ha d- o- each low-le el pa s, and use Measu emen -Based P obabilis ic Timing Analysis (MBPTA) o quan i y, cons uc i ely, he ailu e a es esul ing om he likelihood o execu ion- ime exceedance e en s. Index Te ms—Execu ion- ime exceedance, sa e y ce i ica ion, measu emen -based p obabilis ic iming analysis (MBPTA), au- omo i e eal- ime sys ems I. INTRODUCTION AND MOTIVATION An inc easing a ie y o unc ions in mode n ca s a e con olled by elec ical and/o elec onic (E/E) subsys ems; o ins ance, ac i e/passi e sa e y and d i e assis ance. Fo quan i y, complexi y, and use, hose unc ions make he sa e y o E/E sys ems an inc easingly impo an and complex ma e . ISO-26262 [27] is he unc ional sa e y s anda d o e e - ence o he au omo i e domain. ISO-26262 is an adap a ion o he b oade IEC-61508 sa e y s anda d, which has been simi- la ly adap ed o nuclea plan s, indus ial machine y, ailway, and o he applica ion domains (see Figu e 1). ISO-26262 seeks o p ese e sys ems’ sa e y by sus aining sa e y goals (SG) ha p e en haza dous si ua ions due o E/E mal unc ion. To his end, ISO-26262 (much like he I. Agi e and M. Azka a e-askasua a e wi h he depa men o Depend- able Embedded Sys ems, IK4-IKERLAN, Mond ag´ on 20500, Spain (e-mail: [email p o ec ed]; [email p o ec ed]). F. Cazo la, J. Abella, C. He nandez and E. Mezze i a e wi h he CAOS g oup, Ba celona Supe compu ing Cen e , Ba celona 08034, Spain (e-mail: [email p o ec ed]; [email p o ec ed]; [email p o ec ed]; en- [email p o ec ed]). F. Cazo la is also wi h IIIA-CSIC, Ba celona, Spain T. Va danega is wi h he depa men o Ma hema ics, Uni e si a degli S udi di Pado a, Pado a 35122, I aly (e-mail: ullio. [email p o ec ed]). Fig. 1: Sa e y s anda ds in di e en applica ion domains and hose inhe i ing om IEC-61508 (including ISO-26262) pa en IEC-61508) de ines p ocedu es o he managemen o de e minis ic design aul s (i.e., sys ema ic aul s) and unp edic able ha dwa e aul s (i.e., andom aul s). The ISO- 26262 ene is ha sys ema ic aul s can be ei he a oided by adop ing p e en ion measu es h oughou he de elopmen p ocess, o con olled a un ime by sa e y mechanisms such as di e se edundancy. ISO-26262 uses cognizan assessmen , based on judgmen om p ac ical expe ience, o gua an ee ha he con ibu ion o sys ema ic aul s o SG iola ion is kep accep ably low by assu ing co e age o all equi emen s o he s anda d. Con e sely, andom aul s can only be con olled a un ime: ISO-26262 equi es hei likelihood o occu ence o be quan i ied and assessed agains e e ence alues, asse ing wi h su icien ly high con idence ha he esidual isk o SG iola ion alls below ole able a es. Mo i a ion. While o ha dwa e pa s1, he s anda d con- empla es bo h sys ema ic and andom ha dwa e aul s, so - wa e aul s a e all deemed sys ema ic. Ye , so wa e has unc ional and non- unc ional ai s, which may gi e ise o di e en aul ees, ill- i o he homogeneous ea men p esc ibed by ISO-26262. This p oblem becomes appa en o execu ion- ime exceedance e en s (i.e., he iola ion o wo s - case execu ion- ime, WCET, bounda ies), which is a non- unc ional ai , e iden ly in ol ing so wa e and ha dwa e conce ns. An inco ec (op imis ic) WCET es ima ion may be he oo cause o a possible deadline iola ion and hus o a iming ailu e. Fo ins ance, he sys em design may assign a ask an insu icien execu ion- ime allowance, and his unde - p o ision may go unno iced because he es ablished bounda y alue is only exceeded when a e ci cums ances o ha dwa e/- 1In his pape we ocus on he unc ional sa e y o he compu e subsys ems in ca s, using he e m ha dwa e o e e o embedded compu e s wi hin he au omo i e E/E; likewise we use so wa e o e e o applica ions. © 2018 IEEE. Pe sonal use o his ma e ial is pe mi ed. Pe mission om IEEE mus be ob ained o all o he uses, in any cu en o u u e media, including ep in ing/ epublishing his ma e ial o ad e ising o p omo ional pu poses, c ea ing new collec i e wo ks, o esale o edis ibu ion o se e s o lis s, o euse o any copy igh ed componen o his wo k in o he wo ks 2 so wa e in e ac ion happen, ei he undocumen ed o unknown, o exceedingly ha d o he use o ep oduce du ing WCET analysis. De e mining he WCET o a so wa e p og am is a e y di icul ask indeed, as he p og ams’ execu ion ime a ies much beyond use con ol (and, some imes, also com- p ehension). This s enuous ask is being made signi ican ly ha de by he massi e inc ease in complexi y o he ha d- wa e and so wa e o mode n au omo i e sys ems. Pos ula ing ha such execu ion- ime iola ions can all be p e en ed by s anda d p ocedu es de ined o sys ema ic aul s is becoming inc easingly p ohibi i e, yielding unsa is ac o y a ios o e o s. quali y o ou come. The ollowing obse a ions mani es he magni ude o he p oblem: ÀWhile he so wa e embedded in ca s al eady o als hun- d eds o millions lines o code [17], he compu a ional needs o no el unc ionali ies such as Ad anced D i e Assis ance a e p ojec ed o inc ease by 100x in he nex decade [10]. This end e lec s he cen ali y o so wa e o a ising p opo ion o he compe i i e alue o he ehicle. ÁThose pe o mance needs can only be me wi h high- pe o mance p ocesso s ha include mul i- and many-co e componen s, wi h deep cache hie a chies and high-end GPUs (like in he NVIDIA D i ePX [2], RENESAS R-Ca H3 [4], QUALCOMM Snapd agon 820 P ocesso [3], and he In el Go [1]), wi h massi ely inc easing ha dwa e complexi y. A s ing o inc easingly powe ul WCET analysis ech- niques o sa e y-c i ical sys ems has been pu o wa d by he esea ch communi y o e he las wo decades [45], [7], and comme cial ooling exis s ha implemen s (some o ) hem [42], [44]. Ye , he mos pa o hose echniques only eally applies o a small subse o ela i ely simple and highly c i ical (ASIL-D) sub-sys ems unning on simple and well-unde s ood p ocesso a chi ec u es, hus only co e ing a ac ion o he needs. Fo mos subsys ems, he e o e, he common indus ial p ac ice o uppe -bound he execu ion ime o eal- ime so wa e p og ams uses high-wa e ma k (HWM) measu emen s and adds a sa e y ma gin o hem o accoun o unobse ed beha io . Wi h his p ac ice, he con idence in he esul ing es ima es es s on he use abili y o: (i) unde s and he ha dwa e in e nals well enough o cap u e he majo sou ces o execu ion- ime a iabili y, and (ii) cons uc es cases ha se e o WCET de e mina ion e ec i ely. This knowledge, oge he wi h he addi ion o a conse a i e ma gin, sus ains he a gumen ha he isk o missing ou el- e an si ua ions in he analysis is su icien ly low. Whils his app oach may seem inadequa e in compa ison o s a e-o - he- a s a ic analysis solu ions o o he han low-c i icali y pa s, e idence o (cau ious) use o measu emen -based me hods exis s o DO-178C-ce i ied a ionics so wa e a he highes c i icali y [34]. Eme ging sys ems impe il he cu en iming analysis p ac- ices, by challenging he use abili y o unde s and deep enough he sou ces o ji e in he ha dwa e in e nals, and o con ol hem. The o me weakness hinde s he de e mina ion o how ha dwa e-so wa e in e ac ions a ec iming; he la e impai s he c ea ion o e ec i e analysis scena ios. In hose ci cums ances, he isk o execu ion- ime exceedance e en s can be made “su icien ly” low by using ei he ino dina ely la ge ma gins (hence enouncing esou ce e iciency) o lowe ma gins wi h less suppo e idence (hence inc easing isk). Ei he p ospec aces he use wi h a di e conund um. Measu emen -Based P obabilis ic Timing Analysis, nicked MBPTA [8], p oposes a se o echniques ha equi e applying small and sus ainable changes in he ha dwa e design (o al e na i ely in dedica ed un ime lib a ies) o cause he sys em o exhibi a p obabilis ic – hence p obabilis ically analyz- able – iming beha io . In his way, MBPTA p o ides by- cons uc ion e idence o quan i y he p obabili y o execu ion- ime exceedance e en s. Ea lie wo k desc ibes how o design MBPTA- iendly ha dwa e and so wa e pla o ms [30], [31] such ha execu ion- ime exceedance occu s wi h an (a bi a - ily low) p obabili y. Bo h ha dwa e [30] and so wa e [31] implemen a ions o MBPTA suppo ha e p o en iable e en wi h complex ha dwa e designs (i.e., mul ico e p ocesso s wi h mul i-le el cache hie a chies), in space [26] and au omo i e pla o ms [28], wi h success ul e alua ion in indus ial case s udies [19], [24], [28]. So a howe e , he e is lack o unde s anding o how he p obabilis ic ea men o execu ion- ime exceedance e en s can be unde s ood by sa e y ce i i- ca ion s anda ds in gene al, and ISO-26262 in pa icula . In his ega d, his pape seeks o answe he ollowing esea ch ques ion: How does he app oach o quan i ying he p ob- abili y o occu ence o execu ion- ime exceedance e en s i he scope and in en o ISO-26262? Con ibu ion. To add ess his esea ch ques ion, his wo k analyzes ISO-26262 and i s ea men o aul s, desc ibing how p obabilis ic execu ion- ime analysis solu ions can sa is y he ISO-26262 p esc ip ions and how quan i a i e e idence can be ob ained o suppo ce i ica ion a gumen s. Ou con en ion is ha o ackle his challenge sa is ac o ily we should change he na u e o he WCET-analysis p oblem: sa e y s anda ds should be enabled o allow sound quan i ica ion o he execu ion- ime exceedance a e (o i s likelihood o occu ence), in ela ion wi h a ge ailu e me ics associa ed wi h SG. This app oach would be akin o es ablished p ac ice o ha dwa e andom aul s in ISO-26262, and would no longe equi e leaning on quali a i e cognizan expe ience, sca cely a ailable wi h new ha dwa e, as in cu en p ac ice o he ea men o sys ema ic aul s. Acco dingly, in he emainde o his pape : we su ey he managemen o sys ema ic and andom aul s in ISO- 26262 (Sec ion II); we show how an asymme ic ea men o so wa e aul s ha add esses execu ion- ime exceedance p obabilis ically, i s in he sa e y li e cycle de ined in ISO- 26262 and how i can be ex ended o IEC-61508 (Sec ion III); we p esen he concep o MBPTA as a solu ion o quan i y execu ion- ime exceedance a es, and examine he easibili y o applying i o ISO-26262 complian au omo i e applica ions o con o mance o he s anda d in en and p esc ip ions and o cos o ha dwa e and so wa e modi ica ions (Sec ion IV); we p o ide e idence o he iabili y o he p oposed app oach wi h an au omo i e case s udy a ge ing he AURIX [43], a mul ico e p ocesso candida e o use in au omo i e sys ems 3 Fig. 2: Schema ic iew o ISO-26262 concep and de elop- men phases. (Sec ion V). Finally, in Sec ion VI, we d aw he main conclu- sions om his wo k. II. HARDWARE AND SOFTWARE FAULTS IN ISO-26262 ISO-26262 equi es he use o p o ide e idence o he absence o un easonable isk due o haza ds caused by he mal unc ion o E/E sys ems. Fo he managemen o unc ional sa e y, ISO-26262 includes a concep de ini ion phase, sys em, ha dwa e and so wa e de elopmen p ocesses, and p oduc ion and ope a ion measu es. Figu e 2 depic s he ISO-26262 wo k low o he concep and de elopmen phases, which a e he ocus o his wo k. Concep Phase. Fo each i em o be de eloped and ce i ied, he Haza d Analysis and Risk Assessmen (HARA) s ep de ines he se o haza dous e en s caused by i em’s mal unc ion unde speci ic ope a ional si ua ions. Sa e y expe s classi y he haza dous e en s a di e en in eg i y le els – called Au omo i e Sa e y In eg i y Le els (ASIL) – based on hei se e i y, p obabili y o exposu e and con ollabili y. The ASIL le els ange om A o D, wi h D being he mos es ic i e. O e all, his s ep o mula es he sa e y goals and associa ed ASILs o each haza dous e en . Fo each sa e y goal, he unc ional sa e y concep ( unc- ional SC) de ines he sa e y measu es o be implemen ed in he i em. Ra he han he echnical implemen a ion de ails, he unc ional SC desc ibes he unc ional sa e y equi emen s o achie e he sa e y goal. Sa e y measu es include ac i i ies o he a oidance o sys ema ic aul s and echnical sa e y mechanisms o de ec and con ol e o s caused by sys ema ic and andom ha dwa e aul s. Whene e a sa e y mechanism de ec s an e o , an ac ion shall be aken as de ined in he unc ional SC. In he applica ion domain o ISO-26262, his ac ion ypically seeks o achie e o main ain a sa e s a e, in which no un easonable le el o isk is known o exis . I he sys em has a sa e s a e, hen i is ca ego ized as ail sa e. De elopmen Phase. He e, he echnical SC elici s echnical equi emen s om he unc ional SC equi emen s, which de e mine how he ha dwa e and so wa e pa s should imple- men he unc ional SC o achie e he s a ed SG. The ASIL o each SG de e mines he se o sa e y equi emen s assigned o each pa . In his way, he s ingency o he design is de e mined by he p ope ies o he possible haza dous e en s ha he pa s may in luence. A ha poin , he ha dwa e and he so wa e pa s o he sys em a e de eloped in acco d wi h he echnical SC. A. Ha dwa e aul s in ISO-26262 ISO-26262 p o ides quan i a i e echniques o assessing he sa e y mechanisms, and he esidual isk o iola ing SG. The ha dwa e de elopmen p ocess (see Figu e 2) in ol es: Àde e mining and planning unc ional sa e y ac i i ies in he p oduc ini ia ion phase, Áde i ing he ha dwa e sa e y equi emen s om he echnical SC; Âdesigning ha dwa e componen s and à hei in e connec a a chi ec u al le el, and each componen in de ail, ac o ing sa e y equi emen s in hem (i.e., wi h p o isions o aul ole ance); Äe alua ing he ha dwa e mechanisms designa ed o handle aul s; Å in eg a ing and e i ying he ha dwa e a chi ec u e agains sys em speci ica ion. S eps Ãand Äinclude a quan i a i e analysis o sa e y mechanisms and esidual isk: he ha dwa e a chi ec u al me ics de ined in s ep Ãe alua e he e ec i eness o he ha dwa e a chi ec u e and he implemen ed sa e y mechanisms agains he aul handling equi emen s; s ep Ä equi es e al- ua ing whe he he esidual isk o sa e y goal iola ions is accep able (i.e., su icien ly low). ISO-26262 acknowledges ha sa e y echniques canno achie e ull co e age o all ypes o aul s and allows diag- nos ic co e ages e en below 90% o he highes -c i icali y applica ions. The sys em may he e o e be exposed o un- co e ed aul s, which esul s in esidual isk ha needs o be assessed. Faul s can be classi ied in o: sa ely-igno able aul s (i.e., mul iple-poin pe cei ed o de ec ed aul s) ha a e ega ded as i ele an since hei e ec s become “ isible” be o e hey can do ha m, o hey a e simply ha mless; and non sa ely-igno able aul s (i.e., single-poin aul s ha a e no co e ed by sa e y mechanisms, esidual aul s ha may escape sa e y mechanisms and mul iple-poin la en aul s) ha a e c i ical, as hey may lead o SG iola ion. ISO-26262 add esses non sa ely-igno able aul s by de ining he single-poin aul me ic (SPFM) ha de e mines he i em’s obus ness o single-poin and esidual aul s by ei he design o sa e y mechanisms, and he la en aul me ic (LFM) ha de e mines he i em’s obus ness o la en aul s by ei he design o sa e y mechanisms o d i e logic diagnosing he aul be o e SG iola ion. The pass/ ail e e ence igu es (Table I(a)) de ined o hese me ics ange be ween 90% and 99% o single-poin aul s and be ween 60% and 90% o la en ones, depending on he a ge ASIL le el. To assess whe he he esidual isk is accep able, s ic alues a e imposed on he allowed ailu e a es. In one o he me hods desc ibed in ISO-26262, ailu e a e classes (FRC) 1 o 5 a e de ined wi h di e en a ge a es. Table I(b) desc ibes he maximum FRC o ha dwa e pa s depending on he diagnos ic co e age achie ed o he ha dwa e aul s and he a ge ASIL. Fo ins ance, an ASIL-D SG equi es p o ing esidual ailu e a e ≤10−7(FRC 4) when he diagnos ic co e age is abo e 99.9%. Lowe ailu e a es a e equi ed 4 TABLE I: Ta ge alues o ha dwa e quan i ica ion me ics [27]. i he diagnos ic co e age is lowe , wi h highe ailu e a es allowed i he ASIL le el is lowe (e.g., C o B). O e all, he quan i a i e assessmen o andom ha dwa e aul s p o ides e idence o whe he he esul ing design mee s i s assigned sa e y equi emen s. B. So wa e aul s in ISO-26262 ISO-26262 holds a de e minis ic iew o so wa e aul s and classi ies hem all as sys ema ic. Mo eo e , ISO-26262 assumes ha all sys ema ic aul s ha e o be p e en ed, ole - a ed o emo ed a some s age o he de elopmen p ocess. I is o his eason ha hei con ibu ion o he esidual isk is no con empla ed. The so wa e de elopmen p ocess is simila o he ha dwa e one (Figu e 2), excep ha i does no include quan i a i e analysis. In p ac ice, howe e , p ocess-o ien ed solu ions canno p o- ide posi i e e idence o he lack o esidual aul s, especially in he ace o he inc easing complexi y o mode n so wa e unc ions, and he in ica e in e ac ions ha hey may ha e wi h ad anced ha dwa e. In e es ingly, some au ho s [41] a gue ha he so wa e complexi y combined wi h ha o he associa ed de elopmen p ocess cause aul s o be andomly sca e ed ac oss he p og am code. Quali a i e analysis is mean o p e en aul s in he de el- opmen phase, no o p edic hei occu ence du ing ope a ion. Fo quali a i e assessmen , so wa e a ian s exis [38], [35] o s a e-o - he-a echniques ha apply o ha dwa e componen s, such as Faul T ee Analysis and Failu e Mode and E ec s Analysis. The main ocus a his le el would be on p ocess- le el issues, o make su e ha all disc epancies be ween p og am beha io and unc ional speci ica ion a e in e cep ed. P oac i e echniques, such as so wa e aul injec ion o wo kload gene a o s can be le e aged o u he inc ease he es co e age and educe he isk o esidual aul s. All he abo e echniques, howe e , su e om he limi a ions ha he quali y o hei ou comes depends on he use ’s abili y o achie e su icien es co e age2. The objec i e o quan i a i e analysis, ins ead, is o p edic he occu ence o esidual aul s. ISO-26262 in oduces quan- i a i e assessmen o andom ha dwa e aul s, o quan i y he isk o esidual aul s and o de e mine whe he i is below he assigned h eshold. Ou con en ion he e is ha he same should be done o so wa e: means should be p o ided o eason on he p obabili y o esidual so wa e aul s (whose p esence is bound o s em om he inc easing complexi y o he sys em), and o ela e ha p obabili y o gi en h esholds. 2No e ha he analysis o non- unc ional ailu es has i s own me ics and analysis echniques (including iming and schedulabili y analysis). The me ic o use o quan i y he isk o esidual so wa e aul s depends on he speci ic p ope y, ei he unc ional o non- unc ional, o which he isk needs o be quan i ied. F om he unc ional/implemen a ion s andpoin , a lo o e o has been de o ed o s udy and p edic he occu ence o so wa e aul s as a g ound o easoning on so wa e eliabili y. Bo h de e minis ic o p obabilis ic models ha e been p oposed. De e minis ic models build on cha ac e is ics o he p og am’s code (e.g., Hals ead’s deli e ed bugs me ic [25] o McCabe’s cycloma ic complexi y [36]) complemen a y o hose sug- ges ed by bes p ac ice and guidelines o so wa e implemen- a ion. P obabilis ic models ins ead ela e he occu ence o aul s in a unc ion o i s equency o execu ion o , in e sely, o he numbe o es s execu ed on i [39]. P obabilis ic models gene ally ex apola e he in o ma ion collec ed du ing he es campaign o p edic he occu ence o aul s du ing ope a ion. These models de i e eliabili y p edic ions om ends obse ed in ailu e da a. Rele an echniques include Failu e Ra e, Faul Coun models, o he So wa e Reliabili y G ow h Models [22]. Fo non- unc ional p ope ies, such as, e.g., he p og am’s iming beha io , he me ics o in e es end o ela e o he es quali y and he ( es ) co e age achie ed du ing de elop- men . While a quan i a i e app oach may be needed o assess he esidual isk o a ious ypes o so wa e aul s, in he sequel we ocus on execu ion- ime exceedance e en s, whe e a so wa e uni exceeds i s assigned budge du ing ope a ion. III. THE CASE FOR EXECUTION-TIME EXCEEDANCE RATES ISO-26262 equi es es ablishing uppe -bounds on he exe- cu ion ime o eal- ime asks. The esul ing WCET es ima es allow deciding how o schedule asks a un ime, he eby assu ing he o e all easibili y o sys em’s execu ion. The p o ided WCET alues should be igh , o a oid was e o p o- cesso esou ces. The WCET alues should also be consis en wi h he SG equi emen s. I is commonly held ha any WCET es ima e o e un necessa ily causes a sys em-le el ailu e. Ye , his is a misconcep ion since exis ing sa e y mechanisms may ac o in he execu ion- ime exceedance’s impac on he SG, and p e en i s escala ion in o a iming ailu e. Whe eas an execu ion- ime exceedance may no comp o- mise sys em sa e y, he iming beha io o so wa e unc ions should s ill be cha ac e ized o assu e p ope unc ioning o he sys em. I is he e o e c ucial o assess he quali y o he p o- ided WCET es ima es o assu e ha hey igh ly uppe -bound he applica ion’s iming beha io unde any possible execu ion scena io. Un o una ely, as no ed, he inc easing complexi y o mode n compu ing pla o ms h ea ens he soundness o quali a i e assessmen o iming co ec ness, and may allow execu ion- ime exceedance si ua ions o escape p e en ion. Execu ion- ime exceedance may esul , o ins ance, om he combina ion o speci ic ask in e lea ing, ini ial cache s a es, in e up a i al pa e ns, DRAM e esh ope a ions, whose sou ces a e o en oo emo e om he use each and oo di icul o con ol and p e en . Acco dingly, we con end ha execu ion- ime exceedance e en s should be ea ed by ISO- 26262 simila ly o andom ha dwa e aul s, and he concep 5 o esidual isk should apply o he o me oo, in conjunc ion wi h quan i ica ion means as p oposed in his pape . A. Timing analysis challenges on complex sys ems Wi h inc easingly complex ha dwa e and so wa e, he WCET bounds ob ained wi h adi ional means a e subjec o unquan i iable isk a ising om he limi a ions o he analysis p ocess and he exceeding ha dness o he e - i ica ion p ocedu es. Two main WCET-analysis pa adigms ha e been used so a in indus y [45]: s a ic iming anal- ysis (STA) and measu emen -based iming analysis (MBTA). Those pa adigms and hei hyb id a ian s ha e been e iewed c i ically in [7], concluding ha , in spi e o occasional suc- cesses in indus ial applica ions, none o hem can be claimed o be e ec i e in he gene al case and e en less so agains he elen less inc ease in complexi y o new-gene a ion sys ems. While STA is gene ally held as scien i ically sound, con- idence in he esul s o i c i ically depends on he a ail- abili y o a de ailed and us wo hy iming model o he compu ing pla o m unde nea h he applica ion. Sadly, he la e is inc easingly a e, as IP es ic ions equen ly ban ha in o ma ion o public documen a ion. Hence, o u u e complex ha dwa e and so wa e sys ems, STA may become un enable, as ob aining he in o ma ion needed o i may become oo ha d o al oge he impossible. E idence o his end eme ges om ecen a ionics and au omo i e epo s, whe e he indus ial eams and hei STA ool p o ide s ha e been compelled o eso o measu emen -based analysis o de i e iming bounds o mul ico e p ocesso a chi ec u es like he NXP P4080 [37], Texas Ins umen TMS320C6678 [33], and ARM-based SABRE Li e [13]. Indus ial p agma ism, he e o e, con inues o ega d MBTA as he mos p ac icable iming analysis app oach e en o sa e y- ela ed eal- ime sys ems, which explains STA’s weake pene a ion [45]. MBTA equi es iden i ying he main sou ces o execu ion- ime ji e , o ac i a e hem du ing analysis. While being a om i ial, his iden i ica ion is a much easie job han building o acqui ing he de ailed iming model equi ed by STA, and can be pe o med by i s e iewing p ocesso spec- i ica ions o iden i y hose esou ces and hen using specialized p og ams called mic o-ke nels [37][40] ha place a p ede e - mined load on he desi ed p ocesso esou ce(s) o quan i y hei impac on iming. Fo MBTA, unce ain y s ems om he inhe en di icul y in mimicking, du ing analysis, all o he execu ion condi ions – especially hose o ji e y p ocesso esou ces – ha can a ise du ing ope a ion. De i ing eliable WCET es ima es on complex ha dwa e equi es ha low- le el a chi ec u al ea u es, which can con ibu e o signi ican execu ion- ime a ia ions (e.g., cache placemen ), a e ac o ed in he measu emen uns aken du ing analysis so ha he obse ed execu ion imes can be conside ed ep esen a i e o hose ha can a ise du ing ope a ion. As complex ha dwa e a chi ec u es may ha e a huge numbe o po en ial s a es wi h bea ing on execu ion- ime ji e , i is no ealis ically possible o ully explo e hem du ing analysis. Hence, by cons uc ion, MBTA canno exclude ha esidual execu ion- ime exceedance e en s may occu du ing ope a ion, e lec ing ci cums ances no co e ed du ing analysis. Common indus ial p ac ice o add ess unce ain ies in WCET analysis equi es adding conse a i e sa e y ma gins (o en s a ing a 20%) o he compu ed WCET alue. Any such numbe howe e e iden ly lacks scien i ic g ounding and simply es s on enginee ing judgmen . Consequen ly, his p ac ice may yield ei he ine ec i e use o he a ailable esou ces (due o WCET o e -es ima ion) o highe isk o execu ion- ime exceedance e en s (owing o WCET unde - es ima ion), as a esul o insu icien quali y in he compu ed bound. Mo eo e , his p ac ice does no scale o mo e complex ha dwa e and so wa e. Al eady on a ela i ely simple 4-co e p ocesso , in ac , small a ia ions in execu ion condi ions ha e been shown o cause ei he iny (e.g., below 10%) o huge slowdowns (e.g., up o 20x) [23]. App op ia e means a e he e o e needed o p oduce igh WCET es ima es ha can be ela ed o a quan i ied (and a bi a ily low) isk o execu ion- ime exceedance. B. P obabilis ic WCET dis ibu ion To add ess his challenge, we build on iming analysis solu ions ha yield p obabilis ic dis ibu ions o he execu ion- ime beha io o applica ion asks (nicked p obabilis ic WCET, pWCET), ins ead o a single- alued WCET. The pWCET dis ibu ion, illus a ed in he igh side o Figu e 3, ep esen s he p obabili y ha a ask may exceed he assigned budge en elope a un ime. Cu ing he ail o i a he desi ed p obabili y o exceedance (10−10 on he Y axis, pe un o hou o ope a ion) p ojec s on o an execu ion- ime alue (7 on he X axis) ha may se e as he WCET budge a ha le el o assu ance. Hence, he pWCET p o ides means o s a- is ically quan i y he likelihood o execu ion- ime exceedance accu a ely. C. Fi ing pWCET in o he Sa e y Li e Cycle In e es ingly, he no ion o pWCET dis ibu ion ollows ISO-26262’s philosophy o he handling o andom ha dwa e aul s and applies i o he iming domain. Re u ning o he ISO-26262 li e cycle depic ed in Figu e 2, wi h ocus on iming- ela ed equi emen s, we now desc ibe how an app oach deli e ing a pWCET cu e can i in he so wa e de elopmen p ocess de ined in he s anda d, which we illus- a e in Figu e 3. In he concep phase (no shown in Figu e 3), he unc ional SC should be ex ended o also conside he possibili y o execu ion- ime exceedance e en s ha can p opaga e in o im- ing ailu es and, acco dingly, de ine adequa e sa e y p o ec ion measu es agains hem (e.g., wa chdog ime ). In he so wa e de elopmen phase, ISO-26262 includes iming- ela ed equi emen s in h ee di e en phases o he so wa e V-model (ske ched in Figu e 3). Fi s , du ing so wa e sa e y speci ica ion phase À, i equi es sys em designe s o speci y he ime budge s o c i ical so wa e. Then, he so wa e a chi ec u al design Áshall conside he ime uppe - bounds o dimension he sys em. I an app oach deli e ing a pWCET dis ibu ion ins ead o a single- alued WCET is used, he designe needs o iden i y he app op ia e p obabili y o exceedance à o de e mine he co esponding WCET om 6 Fig. 3: Ske ch o how pWCET i s in ISO-26262 so wa e de elopmen p ocess he pWCET cu e Ä. To his end, he cu -o exceedance p obabili y (o allowed execu ion- ime exceedance a e) shall be e alua ed oge he wi h he diagnos ic co e age o iming e o s and he ASIL o he SG. In o he wo ds, he s anda d should p o ide a ge me ics o he combina ion o hese h ee ac o s as done o andom ha dwa e aul s in Table I. Fo in eg a ion es ing Â, ISO-26262 equi es p o iding e idence ha he so wa e is alloca ed enough ime o comple e i s unc ionali y. The pWCET dis ibu ion allows associa ing he assigned budge en elope o he co esponding p obabili y o exceedance. This app oach ad oca es abandoning he cu en p ac ice o adding a sa e y ma gin o he WCET es ima e and assuming – on expe judgmen only – ha i will ne e be exceeded, and he e o e exposing o an unquan i ied isk o execu ion- ime exceedance. In con as wi h ha , he pWCET imp o es he soundness o he e i ica ion p ocess by p o iding a quan i- a i e uppe -bound o he isk o execu ion- ime exceedance es ima ed wi h a sound app oach. To his end, howe e , i is o i al impo ance ha he iming analysis echnique mee s he p ope y o gua an eeing ha he deli e ed pWCET dis ibu ion is ep esen a i e o he wo s -case iming beha io ha may occu du ing ope a ion. D. So wa e ailu e a e classes and diagnosis co e age We now desc ibe ailu e a e classes (FRC) and diagnos ic co e age o execu ion- ime exceedance e en s, so ha hey can be used as o ha dwa e andom aul s. Failu e Ra e Classes. The pWCET dis ibu ion allows selec ing he accep able a e o execu ion- ime exceedance, no mally associa ed wi h a single un o he ask. By mul- iplying his alue by he ask’s execu ion equency pe hou , we de e mine he execu ion- ime exceedance a e pe hou o he ask. Fo ins ance, in o de o assu e an execu ion- ime exceedance a e pe hou o , e.g., 10−9, o a p og am execu ed 103 imes pe hou , he use should cu he pWCET ail a he 10−12 exceedance h eshold, which would yield a 7.7ms WCET alue in Figu e 3. In his way, i is p obabilis ically gua an eed ha he accumula ed execu ion- ime exceedance a e o all ins ances o he p og am execu ed pe hou is below 10−9. This easoning ma ches andom ha dwa e me ics as de ined in Table I. Simila ly o he ha dwa e case, he pa icula p obabili y o choose comes om he ASIL le el assigned o he so wa e elemen . Diagnos ic Co e age. The s anda d sugges s he usage o wa chdog ime s o de ec he consequences ha a aul in a ha dwa e componen may ha e in he p og am schedule (e.g., missed, delayed, o oo close ac i a ions o he p o- g am). In his scena io, he s anda ds o in e es ca ego ize he diagnos ic co e age achie able by wa chdogs o e o s in he con ol logic o p ocessing uni s as ei he low (60%) o medium (90%). Acco dingly, wa chdogs can also de ec (possibly wi h a high, >99%, diagnos ic co e age) execu ion- ime exceedance e en s in he ope a ional sys em. On he occu ence o such an e en , he sa e y mechanisms in place de ec he e o and ins iga e ac ion o emo e he esidual isk o SG iola ion. While ad ising he usage o an ex e nal moni o ing acili y (e.g., wa chdog) o e o de ec ion a he so wa e a chi ec u al le el (which co ela es o so wa e aul s ca ego ized as sys ema ic), ISO-26262 does no explici ly allude o he achie able diagnos ic co e age o mechanisms agains execu ion- ime exceedance. Fo ail-sa e sys ems, he sys em should be mo ed o a sa e s a e e e y ime a diagnos ic mechanism de ec s an execu ion- ime exceedance. In ha manne , he SG would be p ese ed a he expense o making some unc ionali y (o he en i e sys em) una ailable. As a esul , he deg ee o diagnos ic co e age ha he sa e y mechanisms p o ide o iming aul s should be aken in o accoun when quan i ying he esidual ailu e a e (as i is he case o ha dwa e, see Table I(b)). Whe eas sa e y is no a ec ed in ail-sa e sys ems in he e en o an execu ion- ime exceedance (assuming ha high diagnos ic co e age mechanisms a e in place), sys em a ail- abili y is ins umen al o he end use since an una ailable sys em does no deli e he expec ed unc ionali y. A guably, he e o e, solu ions ha yield eliable pWCET dis ibu ions can imp o e he design p ocess by allowing he use o assess he a ailabili y o ail-sa e sys ems om a iming pe spec i e. Fo ail-ope a ional sys ems, which need o s ay ope a ional o p ese e sa e y, he e en o an execu ion- ime exceedance should ac i a e he use o app op ia e o ms o edundancy o di e si y, so ha he occasional ailu e o one uni does no s op he (sa e) ope a ion o he en i e sys em. Whene e his solu ion is no possible, ha ing high diagnos ic co e age agains iming aul s is no su icien o p ese e sa e y and a su icien ly low cu -o p obabili y needs o be chosen o ensu e ha he con ibu ion o execu ion- ime exceedance o he esidual isk is kep co espondingly low. E. F om ISO-26262 o IEC-61508 The IEC-61508 me a- (o pa en -) s anda d di e s om ISO-26262 only sligh ly. The la e e ines some de ini ions o he li e-cycle phases and p o ides addi ional equi emen s o he sa e y equi emen speci ica ion o he ha dwa e. IEC- 61508 does no o ganize he li e cycle a ound concep and 7 de elopmen phases explici ly, bu a he agmen s i in o smalle uni s ha ma ch he ac i i ies de ined wi hin he ISO- 26262 wo k low. Those ac i i ies include, o ins ance, he Haza d and Risk Analysis (which ISO-26262 names Haza d Analysis and Risk Assessmen ) and he O e all sa e y e- qui emen s and Alloca ion (which ISO-26262 places in he Func ional Sa e y Concep ), whe e he SIL le el, anging 1 o 4, is compu ed. As a ule o humb, he highes ASIL le el in ISO-26262 (ASIL-D) ma ches on ce i ica ion ambi ion a SIL-3 in IEC-61508. The sa e y equi emen speci ica ion con- ce ning andom ha dwa e aul s is ligh e in IEC-61508 han in ISO-26262. The ha dwa e concep and de elopmen in ol e he same s eps in he me a-s anda d, bu he de i a ion o ha dwa e aul s nei he includes la en aul s no mul iple-poin aul s, which simpli ies he calcula ions. Rega ding so wa e aul s, he app oach is iden ical in bo h s anda ds: so wa e aul s a e conside ed sys ema ic and quali a i e measu es a e ecommended o aul a oidance, such us WCET analysis o assu e empo al independence among so wa e elemen s. Like ISO-26262, IEC-61508 de e mines he equi emen s o a oiding o con olling sys ema ic aul s based on expe judgmen om p ac ical expe ience. IEC-61508 s a es ha “ he p obabili y o occu ence o sys ema ic aul s canno in gene al be quan i ied”. To exempli y his di icul y, IEC- 61508 easoning obse es ha he e ec s o sys ema ic aul s mani es ing a un ime, depend on he momen o he li e cycle in which hey we e in oduced, and he e ec i eness o he p e en ion measu es (e.g., s uc u ed p og amming) in place, which a e bo h di icul o quan i y sensibly. Howe e , IEC-61508 allows conside ing ha he a ge ailu e educ ion o a sa e y unc ion is achie ed by demons a ing compliance o all equi emen s o he s anda d. In his ega d, he s anda d in oduces he concep o Sys ema ic Capabili y, which is equi alen o he SIL, bu only conside s sys ema ic aul s. In addi ion o sys ema ic aul educ ion o p e en ion in he design, he s anda d does also de ine mechanisms o con ol he un- ime e o s a ising om sys ema ic aul s (e.g., di e se so wa e edundancy). O e all, IEC-61508 e ains he no ion o andom ha dwa e aul s and p oposes a quali a i e app oach o so wa e aul s ha may no scale well agains inc easingly complex sys ems. A guably, he e o e, all he applica ion domains co e ed by he IEC-61508 umb ella migh equally bene i om inco po a ing an execu ion- ime exceedance quan i ica ion app oach, much like he au omo i e domain would do ia ISO-26262 ollowing he solu ion p esen ed in his pape . IV. MBPTA: CONCEPT AND APPLICATION As a pa icula p obabilis ic iming analysis solu ion, we build on he MBTA a ian p oposed in [8], [30], [29], called Measu emen -Based P obabilis ic Timing Analysis (MBPTA). MBPTA yields a eliable pWCET dis ibu ion while gua - an eeing, by cons uc ion, ha he deli e ed pWCET is an uppe -bound o he execu ion condi ions ha may occu a sys em ope a ion: i he e o e i s he ISO-26262 exceedance a e quan i ica ion app oach p esen ed in Sec ion III. MBPTA acknowledges ha he con ol ha he use can exe cise on he applica ion’s iming beha io du ing analysis necessa ily le e ages high-le el me ics such as so wa e code co e age, bu has inc easingly less means o add ess low-le el ha dwa e aspec s (e.g., bus occupancies, placemen o p o- g am’s code/da a in cache) comp ehensi ely. Hence, MBPTA elie es he use om he la e bu den by in oducing some pla o m modi ica ions. The applica ion o MBPTA es s on he p emise ha he compu ing pla o ms ha enable i s use [30], [31] modi y he iming beha io o selec ed ji e y esou ces so ha he execu ion- ime measu emen s collec ed du ing analysis ei he ma ch o uppe -bound p obabilis ically he iming beha io ha may occu du ing ope a ion. In ha manne , he ob ained pWCET dis ibu ion is wa an ed o cap u e any ex eme beha io ha may occu a ope a ion, and i is p oduced wi hou bu dening he use wi h he need o comp ehend all sys em s a es ele an o execu ion- ime analysis. I ha dwa e suppo is p o ided o enable he use o MBPTA, he p ocesso endo is he pa y in cha ge o singling ou ji e y esou ces and o designing MBPTA-compliance a ound hem app op ia ely. In e es ingly, using MBPTA, he p ocesso endo would no need o build a iming model o i s p ocesso , o g an ing access o all de ails o he ha dwa e design as STA equi es. All i would be equi ed o he endo is o design p ocesso esou ces ha can be explici ly and indi idually con igu ed o ea u e he desi ed o ms o MBPTA con o mance, and o documen hem in public use manuals. Con e sely, i ha dwa e suppo o MBPTA we e sca ce o inexis en , he use would ha e o iden i y he sou ces o execu ion- ime a ia ion building on he p ocesso spec- i ica ions, and apply so wa e solu ions o each MBPTA compliance. In gene al, he esou ces ha cause he la ges ji e (e.g., cache memo ies, in e connec ion ne wo ks, mem- o y con olle s) a e easy o iden i y. Missing ou some sou ces o ji e , while no desi able, is no pa icula ly ha m ul as long as he ji e ha hey may p oduce is no la ge han he cumula i e e ec o he execu ion- ime a ia ion p oduced by he o he known sou ces. To handle ji e y esou ces, MBPTA de ines wo main ech- niques, implemen ed in ei he ha dwa e [30] o so wa e [31], which we p esen below. A. Time uppe -bounding This echnique o ces selec ed ji e y ha dwa e esou ces o wo k a hei highes la ency du ing analysis. In ha manne , he ope a ion condi ions canno lead o highe execu ion imes om hem and hence, a single un su ices o cap u e hei wo s -case ope a ion- ime beha io . The ha dwa e esou ces ha bes i he use o his echnique a e hose whose ex ended a ia ion in iming beha io depends on elemen s ha he ha dwa e canno disc imina e e icien ly [18], [26]. The Floa ing Poin Uni (FPU) p o ides an illus a i e example o his kind o esou ces. The la ency o FP ope a ions depends on he ope ands, ou side o he ha dwa e’s own con ol. Fo ins ance, mul iplying any alue by 0.0may incu sho e la ency han mul iplying any pai o no -null pa am- e e s. Hence, o he analysis o e en he simples sequen ial p og am ha included FP ope a ions, cap u ing he ull ex en 8 o la encies ha i migh incu would equi e enume a ing all o he execu ed FP ope a ions and hei espec i e ope ands, which is unduly one ous and likely o in ol e labo ious debug- ging. On op o ha , he use would also need o de e mine whe he he dis ibu ion o he FP ope a ions and ope ands obse ed du ing analysis is ep esen a i e o wha may occu a ope a ion, which is e en ha de , i a all possible. Ins ead, MBPTA’s p esc ip ion o o ce he FP uni o wo k a i s highes la ency (pe ope a ion ype) du ing analysis elie es he use om he bu den o con olling he impac ha each FP ope a ion incu s on p og am execu ion ime. O iginal FP uni s allow se ing he esul and eleasing as soon as he cu en ope a ion inalizes. To implemen he said echnique, he ha dwa e de aul is modi ied by deac i a ing he immedia e- elease check, so ha all ope a ions ake maximum la ency ega dless o he inpu ope ands. The ha dwa e ea u e ha allows en o cing he highes la ency can be enabled o disabled by se ing he co esponding con igu a ion egis e acco dingly, so ha i can be kep enabled du ing analysis and disabled du ing ope a ion. In ha manne , ope a ion- ime beha io may expe ience sho e , bu ne e longe , la ency. Time uppe -bounding also applies o o he esou ces such as, e.g., he numbe o a bi a ed con ende s on he sha ed bus ha connec co es o a sha ed L2 cache [18], [26]. Fo a p og am unning on a co e, he con en ions su e ed du ing ope a ion depend on he so wa e being un on he o he co es. This in o ma ion is exceedingly di icul o de e mine du ing analysis e en o he s ic es o s a ic scheduling scena ios, since he a i al ime o bus eques s om con ende s may change ac oss di e en execu ion pa hs and cache hi /miss pa e ns. To add ess his challenge, a simple modi ica ion o he ha dwa e a bi e is applied [26] o cause a bi a ion o occu ac oss all po en ial con ende s ega dless o whe he hey ha e pending eques s o no , keeping he bus busy o he longes eques la ency a e selec ion. Selec i ely disabling his ea u e du ing ope a ion allows he p og am o expe ience ewe s alls han con empla ed o WCET analysis. B. Time andomiza ion This echnique causes he esponse ime o some ji e y e- sou ces o exhibi a p obabilis ic beha io ha also holds du - ing ope a ion. Acco dingly, a ep esen a i e dis ibu ion o he impac ha ji e y esou ces may cause on execu ion ime can eme ge a e a s a is ically-signi ican numbe o obse a ion uns. Fo ins ance, andomizing he placemen and eplace- men o objec s in cache memo ies, allows using execu ion- ime measu emen s o model cache beha io p obabilis ically. Such andomiza ion makes cache con lic s independen o he memo y loca ion o p og am objec s, which elie es he use om he need o con ol memo y placemen . In In eg a ed Modula A chi ec u e sys ems as used in a ionics [5] and au omo i e [12], indi idual so wa e applica ions a e o en subcon ac ed o di e en p o ide s. As a esul , he in eg a ion o he sys em p og esses inc emen ally, equi ing o assess a e e y s ep o in eg a ion ha he new build con o ms wi h he speci ica ion, o unc ional and non- unc ional equi emen s. Howe e , as applica ions ge in eg a ed in o he sys em bina y, hei memo y placemen and cache layou may a y [21], in alida ing he WCET es ima es compu ed p e iously. This phenomenon de e s iming e i ica ion o he la es s ages o in eg a ion, whe e he (bina y) image is nea inal, which in u n makes iming aul s much mo e cos ly o handle han du ing ea lie phases o de elopmen . Randomized caches mimic he beha io o mul iple so wa e in eg a ions, which allows he WCET es ima es compu ed in ea lie de elopmen s ages o hold ac oss he whole p ocess o in eg a ion as well as du ing ope a ion. To da e, ime andomiza ion has been implemen ed in p ocesso esou ces whose iming beha io depends on he s uc u al dependencies c ea ed by he ha dwa e design. Ran- domiza ion helps emo e hose dependencies, which ha e no bea ing on he p og am seman ics. Fo ins ance, whe he wo add esses compe e o he same cache space depends on how hey a e mapped o cache lines. And cache mapping can be andomized o make con lic s occu p obabilis ically. To ensu e ha he obse a ions made du ing analysis ep esen (p obabilis ically) he iming e en s ha may occu du ing op- e a ion, such andomiza ion mus be kep enabled a all imes, wi h no dis inc ion be ween analysis and ope a ion. Random placemen and andom eplacemen ha e been success ully implemen ed in ha dwa e [18], [26]. This echnique is e iden ly supe io o he ” ime uppe - bounding” al e na i e o modi ying he cache ha dwa e o espond wi h he highes (miss) la ency du ing analysis, owing o he massi e pe o mance decay incu ed by he la e . Wi h li le di icul y, ime andomiza ion has also been ap- plied o he bus a bi e , changing he way i chooses which co e is g an ed access o he sha ed L2 cache. Bus a bi e s he e o e ha e wo ypes o modi ica ions: ime uppe -bounding o de e mine he numbe o con ende s and he la ency wi h which he bus is eleased; and ime andomiza ion o choose which co e is g an ed access o he sha ed L2 cache. All ha dwa e pa s ha use ime andomiza ion equi e a ha dwa e sou ce o andomness. An exempla y Pseudo- Random Numbe Gene a o (PRNG) has been implemen ed o ha end [9], wi h a deg ee o andomness ha has passed he mos s ingen c yp og aphic es s. The ci ed publica ion shows ha he ha dwa e cos o i s implemen a ion is low, also because a single PRNG can be sha ed ac oss mul iple esou ces. The PRNG has also been p o en compa ible wi h high sa e y in eg i y le els. I ime andomiza ion is o be implemen ed in so wa e, a so wa e implemen a ion o he e y same PRNG algo i hm can also be used. C. P obabilis ic analysis The execu ion ime o he p og am ‘in la ed’ by ime uppe -bounding and andomiza ion esul s in an analysis- ime dis ibu ion (ATD) ha uppe -bounds he ope a ion- ime dis ibu ion (OTD) by cons uc ion. Figu e 4 illus a es his no ion. The do ed line depic s he empi ical complemen a y cumula i e dis ibu ion (ECCDF) o he OTD, and he dashed line he ECCDF o he ATD. A sound use o p obabilis ic analysis (such as, e.g., Ex eme Value Theo y, EVT) uses a sample o ATD alues – no less han a hund ed, and ypically 9 Fig. 4: Example esul s o MBPTA applica ion up o wo housands, which keeps he MBPTA o e head low – o de i e a high-quali y pWCET dis ibu ion ha uppe -bounds he ATD (and hence he OTD) [8]. Fo EVT o be applicable, he obse ed execu ion imes mus co espond o independen and iden ically dis ibu ed (i.i.d.) andom a iables, which means ha each measu emen obse a ion mus belong o he same execu ion- ime dis ibu ion. Sa is ying his equi emen has been p o en doable wi h simple-enough p ocedu es [14]. The MBPTA p ocess collec s execu ion- ime samples om he ATD, ea ning MBPTA con o mance hanks o he ha d- wa e modi ica ions discussed ea lie , and o a measu emen collec ion p ocess ha con ols he ini ial condi ions o he ex- pe imen [14]. The analysis p ocedu e may de e mine ha he sample ails o mee he eligibili y c i e ia o he applica ion o EVT o de ec ha i canno be uppe -bounded by exponen ial ail dis ibu ions, which is equi ed o ensu e igh ness. These si ua ions a e add essed by enla ging he sample size. I is known, in ac , ha inc easingly la ge samples om an i.i.d. andom a iable wi h a gua an ee ini e bound will e en ually be p o en s a is ically i.i.d., and also con e ge, mo e igh ly, o ei he exponen ial o ligh ails, he o me always uppe - bounding he la e . In ou analogy, he p og am’s execu ion- ime obse a ions a e he andom ou comes o ha a iable, and he p og am i sel has bounded du a ion in con o mance wi h well-es ablished eal- ime coding p ac ice. A ha poin , he la ge he sample size, he igh e he pWCET. Acco d- ingly, MBPTA use s should collec la ge – ye a o dable – samples, below 2,000 measu emen s on a e age [8]. MBPTA p omo es a pa adigm shi wi h espec o a- di ional, de e minis ic (i.e., single- alued) WCET analysis. The ela ion o MBPTA wi h i s de e minis ic coun e pa is s aigh o wa d: MBPTA’s main cons i uen s ( ime uppe - bounding and andomiza ion) speci ically add ess he ep e- sen a i i y conce ns ha a lic s anda d measu emen -based app oaches, and h ea en o become insu moun able wi h inc easingly complex sys ems. Rela ing MBPTA o STA is much ha de ins ead, as hose wo echniques build on la gely di e en (and mos ly incompa ible) assump ions [6]. The co ec ness and he p ecision o ei he o hem depend on whe he and o wha ex en hei assump ions a e gua an eed o hold. See [7] o a de ailed analysis o hose assump ions and how hey ela e o ha dwa e and so wa e complexi y. D. MBPTA: indus ial iabili y MBPTA’s iabili y o indus ial use in sa e y- ela ed sys- ems ela es o he cos o he equi ed ha dwa e o so wa e changes, and how he app oach can be i ed in he o e all ISO-26262 sa e y li e cycle as discussed in Sec ion III-C. The la e ques ion le e ages he need o s ep up he guide- lines o cu en sa e y s anda ds o inc easing complexi y o new-gene a ion p ocesso s. This has been done, o ins ance, in he a ionics domain, whe e CAST32 [15] and he accompa- nying CAST-32A [16] add ess he use o mul ico e p ocesso s. A guably, his game-changing scena io should ease he ask o inco po a ing MBPTA ela ed changes. The MBPTA equi emen s on he compu ing pla o m, i implemen ed a ha dwa e le el, ha e been shown a o dable, i s by implemen a ion in a chi ec u al simula o s, hen a RTL le el in FPGA, and inally in o - he-shel p oduc s [18]. Im- plemen ing andomiza ion has been su p isingly non-in usi e. We illus a e his o wo cases. Bus p o ocols like AMBA [11] (one o he mos , i no he mos , used), do no de ine any pa icula a bi a ion policy. This si ua ion allows adding andom a bi a ion policies wi h no impac on he p o ocol speci ica ion. The same happens o cache placemen and eplacemen . While he la e is al eady suppo ed in many p ocesso s, adding he o me equi es combining he add ess being accessed wi h a ha dwa e- (o so wa e-) gene a ed andom seed [9], changed ac oss uns, o map he add ess o a andom cache se . This change causes he iming beha io o cache con lic scena ios ha a e p obabilis ically ele an – hose whose iming beha io can only be exceeded wi h negligible p obabili y – o be close o a e age beha io which, in u n, is e y close o he ypical beha io on con en ional ha dwa e designs. A so wa e le el, andomiza ion has been implemen ed as a pass in he LLVM compile [29] o as a sou ce- o-sou ce ansla o de eloped in an app oach called TASA [31]. Bo h solu ions le e age he ac ha he way in which unc ions and da a (locals and globals) a e placed in he sou ce code and he bina y de e mines hei add ess in memo y. By andomly alloca ing hem and adding padding space among hem keeps he p og am unc ionali y unchanged and a ains simila an- domized iming o ha ob ained wi h ha dwa e-implemen ed andom placemen . As opposed o he ha dwa e and LLVM- based so wa e solu ions, which a ain andomiza ion a p o- g am un g anula i y, he TASA app oach applies andomiza- ion on a pe -bina y basis. As a esul , he p obabili y o exceedance de e mined by he use o TASA is equi alen o he execu ion- ime exceedance p obabili y o all sys ems wi h he same andomly-gene a ed bina y. Fo he ha dwa e and LLVM-based so wa e andomiza ion cases ins ead, he ob ained p obabili y is pe un o he p og am, and he e o e has o be mul iplied by i s a e. Time uppe -bounding a so - wa e le el is managed o -line, by moni o ing ele an e en s du ing he analysis- ime measu emen s ( h ough Pe o mance Moni o ing Coun e s, PMC) and by padding execu ion- ime obse a ions so ha hei impac on he p og am’s execu ion ime is de e minis ically uppe -bounded. Fo ins ance, eading a PMC ha e u ns he quan i y o FP ope a ions execu ed by