Virtual simple architecture (VISA): exceeding the complexity limit in safe real-time systems

Virtual simple architecture (VISA): exceeding the complexity limit in safe real-time systems
复制标题

虚拟简单架构(VISA):超越安全实时系统的复杂性限制

DOI:
--
复制
发表时间:
2003
期刊:
30th Annual International Symposium on Computer Architecture, 2003. Proceedings.
影响因子:
--
通讯作者:
F. Mueller
F. Mueller
中科院分区:
--
文献类型:
--
作者:
Aravindh Anantaraman;K. Seth;Kaustubh Patil;E. Rotenberg;F. Mueller

文献摘要

被引文献

相似文献

在安全实时系统中,满足截止日期是关键要求。安全计划需要最差的任务执行时间(WCET)。当代最差的计时分析工具可以在带有缓存和静态分支预测的单级单发管道上安全,紧密地绑定执行时间。但是,由于需要分析性,这种简单的管道似乎是一个复杂的限制。这不包括来自许多嵌入式系统的整个高性能处理器。我们通过通过虚拟简单体系结构(Visa)从处理器实施中将最差的计时分析从处理器实施中解除了复杂性/安全权衡。签证是假设简单管道的定时规范,是最坏情况计时分析的基础。但是,基础微观结构可能是任意复杂的。任务分为多个子任务,这些子任务提供了一种在复杂管道上衡量进度的手段。根据假设简单管道上的子任务的最新允许完成时间,为每个子任务分配了一个临时截止日期或检查点。如果没有错过检查点,则复杂管道与安全管道一样及时。如果错过了检查点,则管道将切换到直接实现签证的简单操作模式,以便安全地将未完成子任务的执行时间安全地界定。我们方法的意义在于,通过动态确认其行为是通过对更简单的代理管道的最坏情况分析来确认其行为的范围,我们对复杂管道进行了避免。使用高性能处理器的好处是,任务比明确安全的处理器要早得多。可以利用时间表中的新松弛,以获得更高的吞吐量或更低的功率。使用Visa方法,任意复杂的SMTProcessor可以与实时任务同时安全地运行非真实时间任务。另外,频率/电压可以安全降低以占用松弛。我们探索后一种应用程序,并显示符合签证的复杂管道的功率比显式安全管道少43-61%。
Meeting deadlines is a key requirement in safe real-time systems. Worst-case execution times (WCET) of tasks are needed for safe planning. Contemporary worst-case timing analysis tools can safely and tightly bound execution time on in-order single-issue pipelines with caches and static branch prediction. However, this simple pipeline appears to be a complexity limit, due to the need for analyzability. This excludes a whole class of high-performance processors from many embedded systems. We reconcile the complexity/safety trade-off by decoupling worst-case timing analysis from the processor implementation, through a virtual simple architecture (VISA). A VISA is the timing specification of a hypothetical simple pipeline and is the basis for worst-case timing analysis. However, the underlying microarchitecture can be arbitrarily complex. A task is divided into multiple subtasks which provide a means to gauge progress on the complex pipeline. Each subtask is assigned an interim deadline, or checkpoint, based on the latest allowable completion time of the subtask on the hypothetical simple pipeline. If no checkpoints are missed, then the complex pipeline is as timely as the safe pipeline. If a checkpoint is missed, the pipeline switches to a simple mode of operation that directly implements the VISA so that execution time of unfinished subtasks is safely bounded. The significance of our approach is that we circumvent worst-case timing analysis of the complex pipeline, by dynamically confirming its behavior is bounded by worst-case timing analysis of a simpler proxy pipeline. The benefit of using a high-performance processor is that tasks finish much sooner than they would have on an explicitly-safe processor. The new slack in the schedule can be exploited for higher throughput or lower power. With the VISA approach, an arbitrarily complex SMTprocessor can safely run nonreal-time tasks at the same time as a real-time task. Alternatively, frequency/voltage can be safely lowered to take up slack. We explore the latter application and show a VISA-compliant complex pipeline consumes 43-61% less power than an explicitly-safe pipeline.