Autonomic Policy Formalization for Provably Correct Code Generation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current software development processes face challenges in ensuring high dependability and reliability, particularly in validating systems that accurately reflect requirements, due to the complexity and cost of existing validation methods, which often leave execution paths unverified and are prone to human errors, especially in autonomic systems.

Innovation Solution

The development of systems and methods that automate the analysis, validation, and generation of complex procedures by inferring formal models from policies, allowing for automated translation and verification, reducing the need for manual intervention and large computational facilities, and enabling the generation of provably correct implementations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If domain simulators are used to validate generated code, then validation coverage can be improved, but computational cost and complexity increase significantly

Engineering Contradiction:
Improvevalidation coverageVSAvoidcomputational facilities
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates formal specifications as simplified models (copies) of the actual system behavior. These formal specifications capture essential execution paths and constraints without requiring full system simulation. By validating against these lightweight formal models rather than complex domain simulators, the system achieves adequate validation coverage with significantly reduced computational overhead.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent performs preliminary generation of formal specifications from policies before code generation. This upfront formalization captures requirements and constraints in a validated form, enabling subsequent automated verification without needing expensive runtime simulation. The preliminary action of creating executable formal specifications eliminates the need for complex validation facilities during testing.

Inventive Principle:
Principle #10Preliminary action

2Ease of manufacture

If manual validation methods are used, then implementation cost is reduced, but human errors increase and execution paths may remain unverified

Engineering Contradiction:
Improveimplementation costVSAvoiderror rate
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The system performs self-validation through automated generation of formal specifications from policies and executable interpretation of those specifications. The same system that generates code from policies also validates it by checking compliance with the formal specifications, eliminating the need for separate manual validation processes. This self-service approach maintains low implementation cost while significantly reducing human errors through automated verification.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent implements automated feedback loops where the system continuously verifies code compliance against formal specifications during generation. This real-time feedback mechanism detects and corrects errors automatically without human intervention, maintaining cost-effectiveness while improving reliability by ensuring execution paths are thoroughly verified through automated checking.

Inventive Principle:
Principle #23Feedback

3Productivity

If formal specifications are generated and analyzed automatically, then productivity is improved, but the need for sophisticated validation tools increases

Engineering Contradiction:
Improvedevelopment speedVSAvoidvalidation tools
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent introduces formal specifications as an intermediary representation between policies and executable code. This intermediate formal model serves as a bridge that enables automated validation without requiring sophisticated external tools. The formal specifications are designed to be executable and self-descriptive, allowing the system to validate itself through interpretation rather than requiring complex external analysis tools.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If existing validation approaches are used, then some validation can be achieved, but vast parts of execution paths remain unexplored and unverified

Engineering Contradiction:
Improvevalidation completenessVSAvoidvalidation time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies partial validation by focusing on generating and verifying formal specifications that capture critical execution paths and constraints, rather than attempting exhaustive simulation of all possible system behaviors. This selective approach validates the most important paths efficiently, achieving sufficient completeness for safety-critical properties without the prohibitive time cost of complete exhaustive validation.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS7886273B2Systems, methods and apparatus for generation and verification of policies in autonomic computing systems
Publication Date: 2011.02.08 UNITED STATES OF AMERICA AS REPRESENTED BY THE ADMINISTRATOR NAT AERONAUTICS & SPACE ADMINISTRATION
  • US7886273B2 patent drawing
  • US7886273B2 patent drawing
  • US7886273B2 patent drawing

AI summary

Described herein is a method that produces fully (mathematically) tractable development of policies for autonomic systems from requirements through to code generation. This method is illustrated through an example showing how user formulated policies can be translated into a formal mode which can then be converted to code. The requirements-based programming method described provides faster, higher quality development and maintenance of autonomic systems based on user formulation of policies.Further, the systems, methods and apparatus described herein provide a way of analyzing policies for autonomic systems and facilities the generation of provably correct implementations automatically, which in turn provides reduced development time, reduced testing requirements, guarantees of correctness of the implementation with respect to the policies specified at the outset, and provides a higher degree of confidence that the policies are both complete and reasonable. The ability to specify the policy for the management of a system and then automatically generate an equivalent implementation greatly improves the quality of software, the survivability of future missions, in particular when the system will operate untended in very remote environments, and greatly reduces development lead times and costs.