Model-Based Microcode Development with Formal Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional approaches to developing and verifying high-assurance microcode for microprocessors are labor-intensive, error-prone, and lack formal specifications, making them inadequate for achieving certification requirements such as Common Criteria Evaluation Assurance Levels, especially for complex systems like avionics and secure computing applications.

Innovation Solution

A method that integrates model-based design principles with automatic code generation and formal verification tools, including graphical modeling, automatic test case generation, and translation into verification tool-specific formats, to ensure correctness and efficiency in microcode development.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of manufacture

If traditional hand-coding approaches are used for microcode development, then flexibility in implementation is maintained, but labor intensity and error rates increase significantly

Engineering Contradiction:
ImproveEase of microcode implementationVSAvoidDevelopment efficiency
Core Design Contradiction:
Ease of manufactureVSProductivity

Solution Approach 1:

The patent uses formal specifications as templates that automatically generate microcode through code generation tools. This copying approach ensures that the generated microcode faithfully reproduces the intended behavior defined in the formal specification, eliminating manual coding errors while maintaining implementation flexibility through the specifiable interface.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent replaces the manual mechanical process of hand-coding microcode with an automated system consisting of formal specification languages and code generation tools. This substitution transforms the labor-intensive manual process into an automated mechanical process that generates microcode systematically from formal specifications, dramatically improving productivity while reducing errors.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If formal verification tools are integrated into the development process, then certification compliance improves, but development complexity increases

Engineering Contradiction:
ImproveCertification assurance levelVSAvoidDevelopment process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent performs formal verification activities during the specification and code generation phases, before actual microcode implementation. By verifying formal specifications and generated code early in the development process, the system ensures certification compliance is built into the foundation rather than added later, reducing overall development complexity despite the formal methods involved.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces formal specifications as an intermediary layer between requirements and microcode implementation. This intermediary enables automated verification and code generation, bridging the gap between high-level requirements and low-level implementation while providing a structured path to certification compliance without directly complicating the final microcode.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Manufacturing precision

If model-based design with automatic code generation is used, then coding errors are reduced, but initial setup and learning curve increase

Engineering Contradiction:
ImproveMicrocode correctnessVSAvoidEase of development setup
Core Design Contradiction:
Manufacturing precisionVSEase of manufacture

Solution Approach 1:

The patent employs formal specification languages that serve multiple functions: they define microcode behavior, enable automated code generation, support formal verification, and facilitate certification compliance. This multi-functionality reduces coding errors through systematic generation while the same formal models streamline the development process rather than complicating it, offsetting the initial learning curve.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS8041554B1Method and system for the development of high-assurance microcode
Publication Date: 2011.10.18 ROCKWELL COLLINS INC
  • US8041554B1 patent drawing
  • US8041554B1 patent drawing

AI summary

The present invention is a methodology for developing high-assurance microcode. The method may comprise one or more of the following steps: (a) receiving a plurality of requirements detailing intended behavior of microcode (b) creating a model of microcode behavior; (c) generating microcode based on the model; (d) generating test cases based on the model; (e) simulating the behavior of the microcode; (f) translating the model into a verification tool-specific format; and (g) formally verifying the model using a verification tool.