Software Assurance Graph-of-Graphs Quantification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current system assurance methods are limited by the complexity and size of systems, as they rely heavily on manual testing and simulation, which are prone to human bias, and formal verification is computationally impractical for large systems, failing to effectively quantify assurance and risk across all components throughout a system's life cycle, especially in real-situation conditions.
Innovation Solution
The ACE framework uses a graph-of-graphs (GoG) structure to combine logic-based and data-driven techniques for probabilistic assurance and risk evaluation, incorporating formal verification, testing, simulation, and operation data to quantify system assurance and risk across all components, extending contracts with 'emergent assumptions' discovered during simulation, testing, and operation, and providing an 'assurance heat map' for design improvement and error isolation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If formal verification is used to verify system components, then the assurance of individual components is improved, but the computational complexity and impracticality increase for large systems
Solution Approach 1:
The patent segments the system into hierarchical levels (system level, component level, module level) and applies different verification strategies to each segment. Formal verification is applied to critical components where it provides high assurance, while other components use alternative methods, thus managing computational complexity while maintaining overall system assurance.
Solution Approach 2:
The patent introduces intermediate assurance artifacts (test results, simulation data, operational evidence) that bridge the gap between formal verification of components and system-level assurance. These intermediaries allow assurance information to be composed and aggregated without requiring complete formal verification of the entire system.
2Reliability
If manual testing and simulation are used to evaluate system behaviors, then the coverage of system evaluation is improved, but the human bias and subjectivity increase
Solution Approach 1:
The patent implements feedback loops where test results, simulation outcomes, and operational data continuously inform and refine the assurance evaluation process. This systematic feedback mechanism reduces human bias by using objective, measurable data to drive assurance conclusions rather than subjective judgment alone.
Solution Approach 2:
The patent transforms subjective evaluation criteria into quantifiable parameters and metrics. By defining specific measurable attributes (e.g., test coverage percentages, simulation confidence levels, operational KPIs), the system converts qualitative assessments into objective, comparable data points that reduce human bias.
3Measurement precision
If runtime data from real operation is used for post-mortem diagnostics, then the diagnostic accuracy of specific problems is improved, but the ability to evaluate system assurance proactively is lost
Solution Approach 1:
The patent performs preliminary assurance evaluation during design and development phases using available artifacts (requirements, design documents, test plans) before the system reaches operation. This proactive approach identifies potential assurance gaps early, allowing corrective actions to be taken before deployment, rather than waiting for runtime data.
Solution Approach 2:
The patent establishes a continuous assurance evaluation process that operates throughout the entire system lifecycle - from design through development to operation and maintenance. Assurance artifacts are continuously collected, updated, and re-evaluated, maintaining ongoing assurance assessment rather than discrete post-mortem analysis.
4Productivity
If component-based assurance with contracts is used, then the verification efficiency of large systems is improved, but the inability to capture emergent behaviors reduces assurance completeness
Solution Approach 1:
The patent merges multiple assurance evidence sources (formal verification results, test outcomes, simulation data, operational metrics) into a unified assurance evaluation framework. This combination allows the system to capture both component-level contractual assurances and system-level emergent behaviors, achieving completeness that neither approach could provide alone.
Solution Approach 2:
The patent creates a universal assurance framework that can handle multiple types of assurance evidence and evaluation methods within a single system. The framework is multi-functional, accommodating formal verification, testing, simulation, and operational monitoring, allowing it to address both component contracts and emergent system behaviors through a unified approach.
Data Source
AI summary
A computer-implemented method for quantifying assurance of a software system includes collecting artifacts of the software system generated during phases of the software system's engineering lifecycle. A graph of graphs (GoG) is constructed encoding the artifacts. Each subgraph in the GoG is a semantic network corresponding to a distinct assurance requirement. The GoG is used to calculate a component assurance value for each software component for each distinct assurance requirement. A system assurance value is calculated based on the component assurance values. An architectural view of the software system is presented showing at least one of the component assurance values and the system assurance values.


