Formal specification and analysis of AFDX redundancy management algorithms

  • Authors:
  • Jan Täubrich;Reinhard Von Hanxleden

  • Affiliations:
  • Philips Medical Systems DMC GmbH, Hamburg, Germany;Christian-Albrechts-Universität zu Kiel, Institut für Informatik, Kiel, Germany

  • Venue:
  • SAFECOMP'07 Proceedings of the 26th international conference on Computer Safety, Reliability, and Security
  • Year:
  • 2007

Quantified Score

Hi-index 0.00

Visualization

Abstract

Reliable communication among avionic applications is a crucial prerequisite for today's all-electronic fly-by-wire aircraft technology. The AFDX switched Ethernet has been developed as a scalable, cost-effective network, based upon IEEE 802.3 Ethernet. It uses redundant links to increase the availability. Typical consensus strategies for the redundancy management task are not feasible, as they introduce too heavy delays. In this paper, we formally investigate AFDX redundancy management algorithms, making use of Lamport's Temporal Logic of Actions (TLA). Furthermore, we present our experiences made with TLA+ and the TLA+ model checker TLC.