Software Assurance Graph-of-Graphs Quantification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current system assurance methods are limited by the complexity and size of systems, as they rely heavily on manual testing and simulation, which are prone to human bias, and formal verification is computationally impractical for large systems, failing to effectively quantify assurance and risk across all components throughout a system's life cycle, especially in real-situation conditions.

Innovation Solution

The ACE framework uses a graph-of-graphs (GoG) structure to combine logic-based and data-driven techniques for probabilistic assurance and risk evaluation, incorporating formal verification, testing, simulation, and operation data to quantify system assurance and risk across all components, extending contracts with 'emergent assumptions' discovered during simulation, testing, and operation, and providing an 'assurance heat map' for design improvement and error isolation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If formal verification is used to verify system components, then the assurance of individual components is improved, but the computational complexity and impracticality increase for large systems

Engineering Contradiction:
Improvecomponent assuranceVSAvoidcomputational complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the system into hierarchical levels (system level, component level, module level) and applies different verification strategies to each segment. Formal verification is applied to critical components where it provides high assurance, while other components use alternative methods, thus managing computational complexity while maintaining overall system assurance.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces intermediate assurance artifacts (test results, simulation data, operational evidence) that bridge the gap between formal verification of components and system-level assurance. These intermediaries allow assurance information to be composed and aggregated without requiring complete formal verification of the entire system.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If manual testing and simulation are used to evaluate system behaviors, then the coverage of system evaluation is improved, but the human bias and subjectivity increase

Engineering Contradiction:
Improvesystem evaluation coverageVSAvoidevaluation objectivity
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The patent implements feedback loops where test results, simulation outcomes, and operational data continuously inform and refine the assurance evaluation process. This systematic feedback mechanism reduces human bias by using objective, measurable data to drive assurance conclusions rather than subjective judgment alone.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent transforms subjective evaluation criteria into quantifiable parameters and metrics. By defining specific measurable attributes (e.g., test coverage percentages, simulation confidence levels, operational KPIs), the system converts qualitative assessments into objective, comparable data points that reduce human bias.

Inventive Principle:
Principle #35Parameter changes

3Measurement precision

If runtime data from real operation is used for post-mortem diagnostics, then the diagnostic accuracy of specific problems is improved, but the ability to evaluate system assurance proactively is lost

Engineering Contradiction:
Improvediagnostic accuracyVSAvoidreactive vs proactive evaluation
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent performs preliminary assurance evaluation during design and development phases using available artifacts (requirements, design documents, test plans) before the system reaches operation. This proactive approach identifies potential assurance gaps early, allowing corrective actions to be taken before deployment, rather than waiting for runtime data.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent establishes a continuous assurance evaluation process that operates throughout the entire system lifecycle - from design through development to operation and maintenance. Assurance artifacts are continuously collected, updated, and re-evaluated, maintaining ongoing assurance assessment rather than discrete post-mortem analysis.

Inventive Principle:
Principle #20Continuity of useful action

4Productivity

If component-based assurance with contracts is used, then the verification efficiency of large systems is improved, but the inability to capture emergent behaviors reduces assurance completeness

Engineering Contradiction:
Improveverification efficiencyVSAvoidassurance completeness
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent merges multiple assurance evidence sources (formal verification results, test outcomes, simulation data, operational metrics) into a unified assurance evaluation framework. This combination allows the system to capture both component-level contractual assurances and system-level emergent behaviors, achieving completeness that neither approach could provide alone.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent creates a universal assurance framework that can handle multiple types of assurance evidence and evaluation methods within a single system. The framework is multi-functional, accommodating formal verification, testing, simulation, and operational monitoring, allowing it to address both component contracts and emergent system behaviors through a unified approach.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11347864B2Ace: assurance, composed and explained
Publication Date: 2022.05.31 SIEMENS AG
  • US11347864B2 patent drawing
  • US11347864B2 patent drawing
  • US11347864B2 patent drawing

AI summary

A computer-implemented method for quantifying assurance of a software system includes collecting artifacts of the software system generated during phases of the software system's engineering lifecycle. A graph of graphs (GoG) is constructed encoding the artifacts. Each subgraph in the GoG is a semantic network corresponding to a distinct assurance requirement. The GoG is used to calculate a component assurance value for each software component for each distinct assurance requirement. A system assurance value is calculated based on the component assurance values. An architectural view of the software system is presented showing at least one of the component assurance values and the system assurance values.