A Symbolic Model Checking Approach to Verifying Satellite Onboard Software (to appear)
AUTHORS:
Gan Xiang
,
Dubrovin Jori,
Heljanko Keijo
JOURNAL:
Science of Computer Programming
URL:
http://dx.doi.org/10.1016/j.scico.2013.03.005
@article{ GanDubHel:SCP-AVOCS, author = "Gan, Xiang and Dubrovin, Jori and Heljanko, Keijo", volume = "", issn = "0167-6423", language = "eng", title = "A Symbolic Model Checking Approach to Verifying Satellite Onboard Software", url = "http://dx.doi.org/10.1016/j.scico.2013.03.005", journal = "Science of Computer Programming", publisher = "Elsevier", doi = "10.1016/j.scico.2013.03.005", number = "", abstract = "This paper discusses the use of symbolic model checking technology to verify the design of an embedded satellite software control system called the attitude and orbit control system (AOCS). This system is mission-critical because it is responsible for maintaining the attitude of the satellite and for performing fault detection, isolation, and recovery decisions. An executable AOCS implementation by Space Systems Finland has been provided in Ada source code form, and we use the input language of the symbolic model checker NuSMV 2 to model the implementation at a detailed level. We describe the modeling techniques and abstractions used to alleviate the state space explosion due to the handling of timers and the large number of system components controlled by AOCS. The required behavior has been specified as extended state machine diagrams and translated to temporal logic properties. Besides well-known LTL and CTL model checking algorithms, we adapt a previously unexplored form of liveness-to-safety approach to the problem. The latter new technique turns out to successfully prove all desired properties of the system, outperforming both the LTL and CTL implementations of NuSMV 2.", responsibleauthor = "Xiang Gan, Jori Dubrovin, Keijo Heljanko", ee = "http://dx.doi.org/10.1016/j.scico.2013.03.005", corerank = "A", juforank = "2", il = "no", year = "to appear", keywords = "symbolic model checking, AOCS, NuSMV 2, liveness, safety", unitcode = "T306-99, T312-1", impactfactor = "A1", pages = "", flags = "DC HIIT copy" }