<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Considerations on Combining Vestal's Mixed-criticality Task Model and the Predictable Execution Model (PREM) for Real-time Systems</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Ishfaq Hussain</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Muhammad Ali Awan</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Konstantinos Bletsas</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Pedro F. Souto</string-name>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Eduardo Tovar</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>CISTER Research Centre and ISEP/IPP</institution>
          ,
          <addr-line>Porto</addr-line>
          ,
          <country country="PT">Portugal</country>
        </aff>
        <aff id="aff1">
          <label>1</label>
          <institution>University of Porto, FEUP-Faculty of Engineering and CISTER Research Centre</institution>
          ,
          <addr-line>Porto</addr-line>
          ,
          <country country="PT">Portugal</country>
        </aff>
      </contrib-group>
      <abstract>
        <p>In the design of critical real-time embedded systems, predictability in timing behavior and in system resource usage is necessary. Vestal's mixed-criticality task model and the Predictable Execution Model (PREM) help achieve these objectives in diferent ways. Under Vestal's model, multiple worst-case execution time (WCET) estimates are considered for each task, with corresponding degree of confidence, and associated with a diferent criticality level. The schedulability analysis can derive the appropriate timing safety guarantees for each task without using more conservative estimates than needed, thereby avoiding overengineering. The adaptive variant of Vestal's model also allows for system modes, with some tasks idled at mode change and more conservative WCET estimates thereafter assumed for remaining tasks. Meanwhile, the 2-phase PREM model, via compiler support, first fetches from memory (into the cache) all the locations that a task will access, and only subsequently proceeds with computation. This removes a lot of the uncertainty in WCET estimation stemming from the cache state and memory access delays, leading to better predictability and tighter WCET estimates. Vestal's model and the PREM model, however, were independently conceived, and never combined. In this work, we explore diferent possibilities about how these two models could be combined. We focus on the semantics of multiple (static or probabilistic) per-task estimates of processor computation time and number of memory accesses, how these can be derived, the associated compiler and O/S support required, and the implications for timing analysis.</p>
      </abstract>
      <kwd-group>
        <kwd>eol&gt;Real time systems</kwd>
        <kwd>mixed criticality model</kwd>
        <kwd>Predictable execution model</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>1. Introduction</title>
      <p>The criticality of a computing task reflects the severity of the consequences of its failure;
and a deadline miss is a form of failure. Higher-criticality tasks are developed according
to stricter methodologies, require stronger safety guarantees and, traditionally, ran on
separate hardware from lower-criticality tasks. However, size, weight and cost concerns,
currently motivate (e.g., in automotive or avionics systems) mixed-criticality systems,
where tasks of diferent criticality can coexist on the same platform. Often,
commercialof-the-shelf (COTS) hardware is used, which ofers good performance for its cost but
is not very timing-predictable. Researchers try to deal with that in diferent ways, two
of which are Vestal’s mixed-criticality task model and the Predictable Execution Model
(PREM). The present work highlights alternatives ways for combining those two models.</p>
      <p>
        Vestal’s model [
        <xref ref-type="bibr" rid="ref1">1</xref>
        ] uses multiple WCET estimates for the same task, with diferent
degrees of confidence, associated with a corresponding criticality level. It avoids having
to assume very pessimistic WCET estimates for all tasks, in schedulability analysis. In
this paper, we consider its adaptive mode-based variant [
        <xref ref-type="bibr" rid="ref2">2</xref>
        ]. Under that model, every
task has a criticality level and a set of WCET estimates – one for every criticality level
up to its own (and progressively more conservative). The system is initially in the lowest
mode, with all tasks present (and their WCETs for the lowest-criticality level assumed).
If any task exceeds its WCET estimate for the system’s current mode, then all tasks
with criticality matching the mode’s level are dispensed with, and the system switches to
the next-highest mode and, for each remaining task, its next-highest WCET is assumed.
      </p>
      <p>The Predictable Execution Model (PREM) is a way of dealing with intercore
interference on accessing shared resources. PREM tasks are structured as sequences of scheduling
intervals, which are of two types: predictable or compatible. A predictable interval is
non-preemptible and it has a memory phase, followed by a computation phase. In the
memory phase, all the data required during the computation phase is prefetched into the
cache. This ensures that the computation phase is cache-miss-free and removes the need
to analyse the cache state during WCET analysis, and the resulting pessimism.</p>
      <p>In this work, we explore diferent ways in which PREM and the adaptive mode-based
mixed-criticality model could be combined. For each alternative, we summarise the
semantics, challenges and implications, in terms of analysis, compiler and O/S support.</p>
    </sec>
    <sec id="sec-2">
      <title>2. Related Work</title>
      <p>
        Vestal’s paper [
        <xref ref-type="bibr" rid="ref1">1</xref>
        ] was the first work which considered multiple WCET estimates per
task and co-scheduling of diferent-criticality tasks on the same platform. Building on
that, Baruah et al. [
        <xref ref-type="bibr" rid="ref2">2</xref>
        ] proposed adaptive mixed-criticality scheduling (AMC). It involves
system modes, with corresponding WCET estimates assumed for the tasks, and mode
changes triggered by WCET estimate overruns. AMC was later extended to arbitrary
deadlines [
        <xref ref-type="bibr" rid="ref3">3</xref>
        ] and multiframe tasks [
        <xref ref-type="bibr" rid="ref4 ref5">4, 5</xref>
        ]. For a survey of all related works, see [
        <xref ref-type="bibr" rid="ref6">6</xref>
        ].
      </p>
      <p>
        Deployment of real-time systems (single- or mixed-criticality) on COTS hardware gives
rise to predictability concerns, as diferent tasks access shared resources (i.e., caches, buses
and memory). There exist diferent approaches in the literature that try to alleviate and/or
upper-bound such interference, e.g., via regulation-based arbitration [
        <xref ref-type="bibr" rid="ref10 ref7 ref8 ref9">7, 8, 9, 10</xref>
        ], use of
locks [
        <xref ref-type="bibr" rid="ref11">11</xref>
        ], partitioning of shared resources or through code refactoring [
        <xref ref-type="bibr" rid="ref12 ref13 ref14">12, 13, 14</xref>
        ]. The
Predictable Execution Model (PREM) [
        <xref ref-type="bibr" rid="ref12">12</xref>
        ], in particular, requires task code structured
as distinct memory or computation phases. Besides the original 2-phase model
(memorycomputation), there also exists the 3-phase model (memory-computation-memory) [
        <xref ref-type="bibr" rid="ref15">15</xref>
        ].
In the 2-phase model, both reads and writes are combined and performed at the beginning
of a scheduling interval and the compiler ensures that that the computation phases will
execute without cache misses. In the 3-phase model, reads and writes are further split
into two phases. Our work considers the 2-phase mode, which was initially presented for
single cores [
        <xref ref-type="bibr" rid="ref12">12</xref>
        ] and later extended for multicores [
        <xref ref-type="bibr" rid="ref14">14</xref>
        ].
      </p>
    </sec>
    <sec id="sec-3">
      <title>3. System model</title>
      <sec id="sec-3-1">
        <title>3.1. Task Model</title>
        <p>
          Consider a set  of  independent sporadic tasks, i.e.,  = { 0,  1,  2, · · · ,   −1}. For
a task   ,   ,   and   ≤   denote its criticality, minimum inter-arrival time and
deadline, respectively. Each task is a sequence of non-preemptive predictable scheduling
intervals, as in PREM [
          <xref ref-type="bibr" rid="ref12">12</xref>
          ]. For simplicity, we assume just two criticality levels, high (H)
and low (L), i.e.,   ∈ {,  }. Let   denote the number of scheduling intervals of a
task   and   = { , 0,  , 1, · · · ,  ,  −1} the set of its scheduling intervals themselves.
Each scheduling interval can be modelled by two parameters: the (worst-case) number
of memory accesses performed in its memory phase and the (worst-case) length of its
execution phase. However, in this work, we consider multiple estimates of each of those two
parameters, with corresponding degrees of confidence associated with diferent criticality
levels. For example, measurement-based techniques can be used to infer probably (but
not provably) safe estimates whereas static analysis can be used for the highest degree of
confidence. Therefore, we have L- and H-estimates, for the same quantity.
        </p>
        <p>We assume that each memory access (cache miss) has a fixed latency. This allows us
to simplify the notation, by using that latency as the unit of time. Then, an interval  ,
can be modeled as { , ,  , ,  ,  | }; the first two scalars are estimates of memory
 | ,  ,
accesses in the memory phase and the latter two are WCET estimates for the execution
phase. (Diferent semantics for the pairs { , ,  , } are explored in Section 4.)</p>
      </sec>
      <sec id="sec-3-2">
        <title>3.2. Hardware Platform</title>
        <p>
          Consider a multicore platform composed of  identical cores { 0,  1, · · · ,   −1}. The
main memory is accessed through a single shared memory controller and interconnect,
whose combined scheduling policy is round-robin, as in [
          <xref ref-type="bibr" rid="ref7 ref9">7, 9</xref>
          ]. The outer-level cache is
partitioned or private to each core and same for the inner-level cache(s). Performance
measuring counters (PMCs) are used to count the number of memory accesses.
        </p>
      </sec>
    </sec>
    <sec id="sec-4">
      <title>4. Scheduling model</title>
      <p>Analogously to existing works based on Vestal’s adaptive mixed-criticality model, the idea
is for the system to undergo mode switch whenever some L-estimate by some scheduling
 | ) is exceeded. However, we have not yet defined how L- and
interval (e.g.,  , or  ,
H-estimates relate to each other, nor what happens at mode switch. Diferent conceivable
options for that exist. We next briefly examine four alternative models.</p>
      <p>For better illustration and comparison, we do so via an example task set, consisting of
four tasks (see Table 1). Two of these tasks are high-criticality ( 2,  3) while the other
two ( 0,  1) of low-criticality. We consider a dual-core platform, with 3 tasks ( 1 to  3)
assigned to core  1 and  0 assigned to  0. On core  1, task  3 has the lowest priority and
 1 the highest one. The trace of execution for diferent PREM-MCS scheduling models is
depicted in Figures 1 to 5. For easier illustration, we assume that memory accesses from
diferent cores are served by the memory controller in a round-robin manner. (This is
not part of the PREM-MCS model, which is agnostic w.r.t. the scheduling policy of the
memory controller. We just had to assume one such policy, when drawing the schedules.)
Definition 4.1 (Transition scheduling interval). If a mode switch is triggered by an
overrunning task   during the execution of scheduling interval  , of task   , then  , is a
transition scheduling interval.</p>
      <p>Definition 4.2 (Transition job).</p>
      <p>A job with a transition scheduling interval.</p>
      <p>Definition 4.3 (Compute-interfered scheduling interval). A transition interval that is in
(or at the start of) its processor computation phase at the time of a mode switch.
Definition 4.4 (Memory-interfered scheduling interval:). A transition interval that is in
(or at the start of) its memory phase at the time of a mode switch.</p>
      <sec id="sec-4-1">
        <title>4.1. PREM-MCS T-model</title>
        <p>This variant uses, for a scheduling interval of an H-task, a single memory access estimate
in both modes (i.e.,  , =  , ). This is conservatively derived, therefore it cannot be
exceeded, triggering a mode switch. A mode switch can only be triggered by a processor
execution overrun. The mode switch semantics are:
• Initially the system is in L-mode.
• A mode switch is triggered if any scheduling interval overruns its  , | .
 | estimates
• At the mode switch, all L-tasks are dropped and, for H-tasks, their  ,
are henceforth assumed, for the transition scheduling interval, subsequent scheduling
intervals of transition jobs and all future jobs.</p>
        <p>
          As shown in Figure 1, as soon as the mode switch is triggered by  0,1:  2,1 (2nd job of
task  2) executing on  1 and all subsequently-executed scheduling intervals of all tasks,
execute with more conservative H-mode estimates. This model is straightforward and
requires no changes to the existing PREM compiler and its timing analysis could be
based on that in [
          <xref ref-type="bibr" rid="ref2">2</xref>
          ] (for non-multiframe adaptive mixed-criticality tasks) with minimal
changes. However, it passes on the opportunity to use diferent memory access estimates
in each mode, instead always only using conservative estimates.
This variant uses less conservative estimates for both memory accesses and computation in
the L-mode ( , ≤  , and  ,, ≤  ,, ). In either mode, as in PREM, the computation
phase cannot incur cache misses; the memory phase is engineered to fetch all the locations
needed into the cache, be they many or few. The mode switch semantics are:
• Initially the system is in L-mode, with corresponding estimates assumed for the
tasks.
• A mode switch can be triggered by either memory access or computation overrun,
by some task’s scheduling interval.
• At mode switch, L-tasks are dropped and H-estimates are hitherto assumed for
H-task scheduling intervals. For a transit interval  , :
– If  , is memory-interfered, then H-estimates are assumed for it and for
subsequent intervals for this and all future jobs. This is depicted in Figure 2.
– Analogously if  , is compute-interfered, with one diference: Since the
memory phase of  , has already completed without violating its L-estimate,
for the transition interval we consider  , memory accesses. This scenario is
depicted in Figure 3.
        </p>
        <p>
          This model can ofer improved schedulability, compared to previous one (T).
Probabilistic worst-case analysis techniques could be used to obtain the L-estimates. Static
worst-case analysis techniques would only be used for H-estimates (safe but pessimistic).
The existing PREM compiler [
          <xref ref-type="bibr" rid="ref16">16</xref>
          ] can be used without any changes to derive
PREMcompliant scheduling intervals: Diferent jobs may issue diferent number of accesses
(e.g., depending on run-time conditions), but would cover all locations needed to ensure
no cache miss by the computation phase. The computation phase can still overrun
its L-WCET due to e.g., a rare control flow. The schedulability analysis would be
based on [
          <xref ref-type="bibr" rid="ref2">2</xref>
          ] with minor changes, as for the PREM-MCS T-model, just with the added
consideration of whether the transition interval was memory- or compute-interfered (to
avoid pessimism).
        </p>
      </sec>
      <sec id="sec-4-2">
        <title>4.3. PREM-MCS P-model</title>
        <p>The diference from the previous variant (K) is that the assumption/requirement of no
cache misses during the computation phase is relaxed. In the L-mode (i.e., as long as the
L-estimates are not overrun), this is still guaranteed by design. However, in the H-mode,
under this variant, cache misses are possible. Figure 4 shows the execution pattern of the
example task set as per the PREM-MCS P-model. The cache misses in the computation
phase after the mode switch are represented as boxes with grid fill pattern.</p>
        <p>
          This model violates the core assumption of PREM that computation phases are
cache-miss-free. Contention therefore arises from memory accesses generated during the
computation phase of H-tasks. If only few cache misses can occur, this can be managed
via hardware servers, as in [
          <xref ref-type="bibr" rid="ref17">17</xref>
          ], to manage their efect. Software-based memory regulation
can also be used [
          <xref ref-type="bibr" rid="ref7">7</xref>
          ] and/or even round-robin serving of accesses by diferent cores by the
memory controller. This facilitates analytically upper-bounding the memory stalls.
        </p>
      </sec>
      <sec id="sec-4-3">
        <title>4.4. PREM-MCS A-model</title>
        <p>The distinguishing feature of this variant is that, for compute-interfered transition
intervals, the computation phase is interrupted at the moment of mode changes, and
a supplementary memory phase (with  , −  , accesses) is executed; afterwards, the
computation phase resumes from where it was interrupted. This is a significant departure
from some of the assumptions in PREM.</p>
        <p>This arrangement seeks to optimise for the common case: instead of prefetching memory
locations that a task will rarely, if ever, need, only do this reactively, when indications
arise that there is a chance of needing them. A mode switch triggered by another task
can be such an indication. The case of the task itself triggering the mode switch, by
exceeding its computation phase L-WCET merits some discussion.</p>
        <p>In the general case, the computation phase of a scheduling interval  , overruning
its  , might be purely down to control flow, and will not necessarily indicate that an
access to a memory location other the  , locations prefetched by the corresponding
memory phase is imminent. Similarly, if the computation phase of  , needs to access a
memory location other than the  , locations prefetched by the corresponding memory
phase, this would not necessarily be preceded by an exceedance of its  , estimate. In
any case, the mode change semantics might be justified out of abundant caution.</p>
        <p>Another possible way to justify the arrangement is by selecting the  , memory
locations accessed during the memory phase and the computation phase L-mode WCET
 , in conjunction such that (verifiably, by ofline static analysis), under any control
lfow, no access to a memory location other than those  , occurs, unless (previously,
in the same control flow) there is an overrun of the  , computation phase WCET
estimate. Then, at mode switch, the supplementary memory phase fetches  , −  ,
additional locations, in case they are needed; and this ensures the compuation phase will
be cache-miss-free, in any case.</p>
        <p>These semantics require significant changes both to the existing PREM compiler and
scheduler. Under the PREM model, it is assumed that no system calls or interrupt service
routines are served during predictable intervals. (These are only served under compatible
intervals – the other type of scheduling intervals that we don’t consider here.) However,
for a transition interval, an interrupt-based method is required, to immediately initiate
the supplementary memory phase and to subsequently return control to the computation
phase, at the point of interruption.</p>
        <p>
          Some of the potential implications, in terms of complexity, on the static, ofline timing
WCET analysis have been mentioned above. From the schedulability analysis perspective,
the interference and stall from the additional memory phase need to be quantified and
incoroprated into the schedulability analysis. The specifics will difer, depending, e.g.,
on whether there is memory access regulation [
          <xref ref-type="bibr" rid="ref7">7</xref>
          ], TDMA-based memory access [
          <xref ref-type="bibr" rid="ref18">18</xref>
          ] or
DMA-enabled parallel memory accesses [
          <xref ref-type="bibr" rid="ref19">19</xref>
          ], but they can be complex. However, this
model is quite flexible and it has a potential for improved schedulability.
        </p>
        <p>In the example of Figure 5, an additional memory phase (with  2,2 −  2,2 = 2 - 1 = 1
access) takes place during the computation phase of  2,2.</p>
      </sec>
    </sec>
    <sec id="sec-5">
      <title>5. Conclusion</title>
      <p>Achieving both predictability and eficient resource utilisation for real-time systems
deployed on COTS multicore platforms is challenging because of shared resources. In
this work, we have proposed the combination of Predictable Execution model (PREM)
and the Adaptive Mixed-Criticality model (AMC), as a promising way of dealing with
such challenges. We outlined four possible ways of combining the semantics of those two
models, especially regarding mode changes. Each of those has diferent advantages and
implications, w.r.t. compiler support, run-time support and ofline timing analysis.</p>
      <p>This work is a first step in combining PREM and adaptive mixed-criticality scheduling.
As a next step, weighing all the options, we will settle on the appropriate model semantics,
and work on the corresponding schedulability analysis.</p>
    </sec>
    <sec id="sec-6">
      <title>Acknowledgements</title>
      <p>This work was partially supported by National Funds through FCT/MCTES (Portuguese Foundation
for Science and Technology), within the CISTER Research Unit (UIDP/UIDB/04234/2020); by the
Operational Competitiveness Programme and Internationalization (COMPETE 2020) under the PT2020
Partnership Agreement, through the European Regional Development Fund (ERDF), and by national
funds through the FCT, within project PREFECT (POCI-01-0145-FEDER-029119); by FCT through the
European Social Fund (ESF) and the Regional Operational Programme (ROP) Norte 2020, under grant
2020.08045.BD. This work is partially supported by Connecting Education and Research Communities
for an Innovative Resource Aware Society (CERCIRAS) COST Action CA19135 funded by European
Cooperation in Science and Technology (COST) Association.</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          [1]
          <string-name>
            <given-names>S.</given-names>
            <surname>Vestal</surname>
          </string-name>
          ,
          <article-title>Preemptive scheduling of multi-criticality systems with varying degrees of execution time assurance</article-title>
          ,
          <source>in: Proc. 28th RTSS</source>
          ,
          <year>2007</year>
          , pp.
          <fpage>239</fpage>
          -
          <lpage>243</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          [2]
          <string-name>
            <given-names>S. K.</given-names>
            <surname>Baruah</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Burns</surname>
          </string-name>
          ,
          <string-name>
            <surname>R. I. Davis</surname>
          </string-name>
          ,
          <article-title>Response-time analysis for mixed criticality systems</article-title>
          ,
          <source>in: Proc. 32th RTSS</source>
          ,
          <year>2011</year>
          , pp.
          <fpage>34</fpage>
          -
          <lpage>43</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          [3]
          <string-name>
            <given-names>A.</given-names>
            <surname>Burns</surname>
          </string-name>
          ,
          <string-name>
            <surname>R. I. Davis</surname>
          </string-name>
          ,
          <article-title>Response time analysis for mixed criticality systems with arbitrary deadlines</article-title>
          ,
          <source>in: Proc. 5th Int. Workshop on Mixed Criticality Systems (WMC)</source>
          ,
          <year>2017</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          [4]
          <string-name>
            <given-names>I.</given-names>
            <surname>Hussain</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M. A.</given-names>
            <surname>Awan</surname>
          </string-name>
          ,
          <string-name>
            <given-names>P. F.</given-names>
            <surname>Souto</surname>
          </string-name>
          ,
          <string-name>
            <given-names>K.</given-names>
            <surname>Bletsas</surname>
          </string-name>
          ,
          <string-name>
            <given-names>B.</given-names>
            <surname>Akesson</surname>
          </string-name>
          , E. Tovar,
          <article-title>Response time analysis of multiframe mixed-criticality systems</article-title>
          ,
          <source>in: Proc. 27th RTNS</source>
          ,
          <year>2019</year>
          , pp.
          <fpage>8</fpage>
          -
          <lpage>18</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          [5]
          <string-name>
            <given-names>I.</given-names>
            <surname>Hussain</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M. A.</given-names>
            <surname>Awan</surname>
          </string-name>
          ,
          <string-name>
            <given-names>P. F.</given-names>
            <surname>Souto</surname>
          </string-name>
          ,
          <string-name>
            <given-names>K.</given-names>
            <surname>Bletsas</surname>
          </string-name>
          ,
          <string-name>
            <given-names>B.</given-names>
            <surname>Akesson</surname>
          </string-name>
          , E. Tovar,
          <article-title>Response time analysis of multiframe mixed-criticality systems with arbitrary deadlines, Real-Time Systems 57 (</article-title>
          <year>2021</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          [6]
          <string-name>
            <given-names>A.</given-names>
            <surname>Burns</surname>
          </string-name>
          ,
          <string-name>
            <given-names>R.</given-names>
            <surname>Davis</surname>
          </string-name>
          ,
          <article-title>Mixed criticality systems - a review (12th ed</article-title>
          .),
          <source>Technical Report</source>
          , Department of Computer Science, University of York,
          <year>2019</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          [7]
          <string-name>
            <given-names>H.</given-names>
            <surname>Yun</surname>
          </string-name>
          , G. Yao,
          <string-name>
            <given-names>R.</given-names>
            <surname>Pellizzoni</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Caccamo</surname>
          </string-name>
          , L. Sha,
          <article-title>Memguard: Memory bandwidth reservation system for eficient performance isolation in multi-core platforms</article-title>
          ,
          <source>in: Proc. 19th RTAS</source>
          ,
          <year>2013</year>
          , pp.
          <fpage>55</fpage>
          -
          <lpage>64</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          [8]
          <string-name>
            <given-names>H.</given-names>
            <surname>Yun</surname>
          </string-name>
          , G. Yao,
          <string-name>
            <given-names>R.</given-names>
            <surname>Pellizzoni</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Caccamo</surname>
          </string-name>
          ,
          <string-name>
            <given-names>L.</given-names>
            <surname>Sha</surname>
          </string-name>
          ,
          <article-title>Memory access control in multiprocessor for real-time systems with mixed criticality</article-title>
          ,
          <source>in: Proc. 24th ECRTS</source>
          ,
          <year>2012</year>
          , pp.
          <fpage>299</fpage>
          -
          <lpage>308</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          [9]
          <string-name>
            <given-names>G.</given-names>
            <surname>Yao</surname>
          </string-name>
          ,
          <string-name>
            <given-names>H.</given-names>
            <surname>Yun</surname>
          </string-name>
          ,
          <string-name>
            <given-names>Z. P.</given-names>
            <surname>Wu</surname>
          </string-name>
          ,
          <string-name>
            <given-names>R.</given-names>
            <surname>Pellizzoni</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Caccamo</surname>
          </string-name>
          , L. Sha,
          <article-title>Schedulability analysis for memory bandwidth regulated multicore real-time systems</article-title>
          ,
          <source>IEEE Transactions on Computers</source>
          <volume>65</volume>
          (
          <year>2016</year>
          )
          <fpage>601</fpage>
          -
          <lpage>614</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          [10]
          <string-name>
            <given-names>M. A.</given-names>
            <surname>Awan</surname>
          </string-name>
          ,
          <string-name>
            <given-names>K.</given-names>
            <surname>Bletsas</surname>
          </string-name>
          ,
          <string-name>
            <given-names>P. F.</given-names>
            <surname>Souto</surname>
          </string-name>
          ,
          <string-name>
            <given-names>B.</given-names>
            <surname>Akesson</surname>
          </string-name>
          , E. Tovar,
          <article-title>Mixed-criticality scheduling with dynamic memory bandwidth regulation</article-title>
          ,
          <source>in: Proc. 24th RTCSA</source>
          ,
          <year>2018</year>
          , pp.
          <fpage>111</fpage>
          -
          <lpage>117</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          [11]
          <string-name>
            <given-names>H.</given-names>
            <surname>Yun</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Gondi</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Biswas</surname>
          </string-name>
          ,
          <article-title>Protecting memory-performance critical sections in soft real-time applications</article-title>
          ,
          <source>arXiv preprint arXiv:1502.02287</source>
          (
          <year>2015</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          [12]
          <string-name>
            <given-names>R.</given-names>
            <surname>Pellizzoni</surname>
          </string-name>
          ,
          <string-name>
            <given-names>E.</given-names>
            <surname>Betti</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Bak</surname>
          </string-name>
          , G. Yao,
          <string-name>
            <given-names>J.</given-names>
            <surname>Criswell</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Caccamo</surname>
          </string-name>
          ,
          <string-name>
            <given-names>R.</given-names>
            <surname>Kegley</surname>
          </string-name>
          ,
          <article-title>A predictable execution model for COTS-based embedded systems</article-title>
          ,
          <source>in: Proc. 17th RTAS</source>
          ,
          <year>2011</year>
          , pp.
          <fpage>269</fpage>
          -
          <lpage>279</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          [13]
          <string-name>
            <given-names>A.</given-names>
            <surname>Schranzhofer</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Chen</surname>
          </string-name>
          ,
          <string-name>
            <given-names>L.</given-names>
            <surname>Thiele</surname>
          </string-name>
          ,
          <article-title>Timing analysis for tdma arbitration in resource sharing systems</article-title>
          ,
          <source>in: Proc. 16th RTAS</source>
          ,
          <year>2010</year>
          , pp.
          <fpage>215</fpage>
          -
          <lpage>224</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          [14]
          <string-name>
            <given-names>A.</given-names>
            <surname>Alhammad</surname>
          </string-name>
          ,
          <string-name>
            <given-names>R.</given-names>
            <surname>Pellizzoni</surname>
          </string-name>
          ,
          <article-title>Schedulability analysis of global memory-predictable scheduling</article-title>
          ,
          <source>in: Proc. 14th EMSOFT</source>
          ,
          <year>2014</year>
          , pp.
          <volume>20</volume>
          :
          <fpage>1</fpage>
          -
          <lpage>20</lpage>
          :
          <fpage>10</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref15">
        <mixed-citation>
          [15]
          <string-name>
            <surname>J. M. Rivas</surname>
            ,
            <given-names>J.</given-names>
          </string-name>
          <string-name>
            <surname>Goossens</surname>
            ,
            <given-names>X.</given-names>
          </string-name>
          <string-name>
            <surname>Poczekajlo</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          <string-name>
            <surname>Paolillo</surname>
          </string-name>
          ,
          <article-title>Implementation of memory centric scheduling for COTS multi-core real-time systems</article-title>
          ,
          <source>in: Proc. 31st ECRTS</source>
          ,
          <year>2019</year>
          , pp.
          <volume>7</volume>
          :
          <fpage>21</fpage>
          -
          <lpage>7</lpage>
          :
          <fpage>23</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref16">
        <mixed-citation>
          [16]
          <string-name>
            <given-names>B.</given-names>
            <surname>Forsberg</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Solieri</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Bertogna</surname>
          </string-name>
          ,
          <string-name>
            <given-names>L.</given-names>
            <surname>Benini</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Marongiu</surname>
          </string-name>
          ,
          <article-title>The predictable execution model in practice: Compiling real applications for cots hardware</article-title>
          ,
          <source>ACM Trans. on Embedded Computing Systems (TECS) 20</source>
          (
          <year>2021</year>
          )
          <fpage>1</fpage>
          -
          <lpage>25</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref17">
        <mixed-citation>
          [17]
          <string-name>
            <given-names>R.</given-names>
            <surname>Pellizzoni</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Caccamo</surname>
          </string-name>
          ,
          <article-title>Impact of peripheral-processor interference on WCET analysis of real-time embedded systems</article-title>
          ,
          <source>IEEE Trans. on Computers</source>
          <volume>59</volume>
          (
          <year>2010</year>
          )
          <fpage>400</fpage>
          -
          <lpage>415</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref18">
        <mixed-citation>
          [18]
          <string-name>
            <given-names>G.</given-names>
            <surname>Yao</surname>
          </string-name>
          ,
          <string-name>
            <given-names>R.</given-names>
            <surname>Pellizzoni</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Bak</surname>
          </string-name>
          , E. Betti,
          <string-name>
            <given-names>M.</given-names>
            <surname>Caccamo</surname>
          </string-name>
          ,
          <article-title>Memory-centric scheduling for multicore hard real-time systems</article-title>
          ,
          <source>Real-Time Systems</source>
          <volume>48</volume>
          (
          <year>2012</year>
          )
          <fpage>681</fpage>
          -
          <lpage>715</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref19">
        <mixed-citation>
          [19]
          <string-name>
            <given-names>A.</given-names>
            <surname>Melani</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Bertogna</surname>
          </string-name>
          ,
          <string-name>
            <given-names>R. I.</given-names>
            <surname>Davis</surname>
          </string-name>
          ,
          <string-name>
            <given-names>V.</given-names>
            <surname>Bonifaci</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Marchetti-Spaccamela</surname>
          </string-name>
          , G. Buttazzo,
          <article-title>Exact response time analysis for fixed priority memory-processor co-scheduling</article-title>
          ,
          <source>IEEE Transactions on Computers</source>
          <volume>66</volume>
          (
          <year>2017</year>
          )
          <fpage>631</fpage>
          -
          <lpage>646</lpage>
          .
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>