19-Soft-A4 Real-Time Systems · May 2015
Nivaar worked solution (AI-drafted; not reviewed by a licensed engineer)
National Exams — May 2015 — 04-Soft-A4 Real-Time Systems. Three-hour, closed-book exam (Casio or Sharp approved calculators only). Format: six questions of equal value (20% each); any five constitute a complete paper and only the first five as they appear in the answer book are marked. All six are solved below for completeness. Where a doubt exists as to interpretation, the candidate is expected to state assumptions — engineering assumptions used below are flagged in check callouts.
Reference texts: Jane W. S. Liu, Real-Time Systems (Prentice Hall, 2000) — task models, timing requirements, FCFS and EDF scheduling; Giorgio C. Buttazzo, Hard Real-Time Computing Systems: Predictable Scheduling Algorithms and Applications (Springer, 3rd ed.) — preemptive dynamic-priority scheduling and the optimality of EDF; Hermann Kopetz, Real-Time Systems: Design Principles for Distributed Embedded Applications (Springer, 2nd ed.) — distributed real-time control, network-induced delay and time-triggered protocols; Katsuhiko Ogata, Modern Control Engineering (Pearson, 5th ed.) — frequency-domain stability, phase margin and delay margin; Ian Sommerville, Software Engineering (Pearson, 10th ed.) — general software-engineering process context.
Question text not reproduced: the examination questions are © Engineers and Geoscientists BC. Open the official past paper (linked at the top of this page) to read the question, then follow the worked solution below.
Given.
| Quantity | Symbol | Value |
|---|---|---|
| Travel speed | v | 50 km/h = 13.89 m/s |
| Warning threshold | dwarn | 15 m |
| Auto-brake threshold | dauto | 10 m |
| Braking distance | dbrake | 6 m |
| Safe (residual) distance | dsafe | 1 m |
Find. (1) A state diagram covering both the stationary- and moving-object cases; (2) the real-time latency budget available to the sensor + decision unit + actuator chain; (3) a general formula relating that budget to initial speed and braking distance.
Approach. Model the system as a distance-threshold state machine (the same abstraction covers a stationary object and a slower-moving one, because both reduce to "closing distance falls below a threshold" — only the closing-speed value differs between the two cases); then derive the maximum end-to-end system latency as the time budget left over once the physically-required stopping distance and safety margin are subtracted from the auto-brake trigger range.
d — not whether the object itself is moving — determines the transitions: Monitoring (d > 15 m), Warning (10 < d ≤ 15 m, advisory only — driver must brake manually), Auto-Brake (d ≤ 10 m, actuator engaged automatically), and Stopped (v = 0 with d ≥ 1 m remaining). For a stationary object, d decreases at the car's own ground speed v; for a moving (slower) object, d decreases at the closing speed Δv = v_{car} - v_{object} — the state machine itself is unchanged, only the rate at which the guard conditions are reached differs, and a return edge (Warning → Monitoring) covers the case where the lead vehicle accelerates away or the driver brakes enough to open the gap back past 15 m before auto-brake ever triggers.
d crosses the auto-brake threshold d_auto, the full chain — radar sample → distance/closing-speed estimate → brake-or-not decision → brake actuator command → physical braking — must complete, and the car must still come to rest, before the closing distance is consumed down to the safety margin. In the time the chain takes to react, the car (at speed v, to first order over the short reaction interval) continues closing at essentially constant speed, consuming distance v·t_sys before braking even begins; braking then consumes the given d_brake, and d_safe must remain unconsumed. The requirement is therefore
$$d_{\text{auto}} \ge v\,t_{\text{sys}} + d_{\text{brake}} + d_{\text{safe}}$$
$$t_{\text{sys}} \le \frac{d_{\text{auto}} - d_{\text{brake}} - d_{\text{safe}}}{v} = \frac{10 - 6 - 1}{13.89} = \boxed{0.216\ \text{s} \approx 216\ \text{ms}}$$
This 216 ms is the total real-time budget shared by the radar sampling interval, the decision-making unit's processing time, and the actuator's mechanical engagement lag — combined, they must not exceed it. As a secondary check, the interval between the Warning and Auto-Brake thresholds gives the driver's own manual-reaction window: (15-10)/13.89 = 0.36 s, confirming the automatic path has a substantially tighter deadline than the advisory path, as the design intends (the automatic system is the fallback for exactly the cases where 360 ms of human reaction time is not enough).v and any braking distance d_brake(v) (which itself typically scales with v² for a constant deceleration a, i.e. d_brake = v²/(2a)), the maximum tolerable end-to-end system latency is
$$\boxed{t_{\text{sys,max}}(v) = \frac{d_{\text{auto}} - d_{\text{brake}}(v) - d_{\text{safe}}}{v} = \frac{d_{\text{auto}}}{v} - \frac{v}{2a} - \frac{d_{\text{safe}}}{v}}$$
For the moving-object case, the same formula applies with the closing speed Δv = v_{car}-v_{object} in place of v wherever distance is being consumed by relative approach, while d_brake (the ego vehicle's own physical stopping distance) is still governed by the car's absolute speed v_{car}, since a vehicle's brakes only ever act against its own ground speed, not the closing rate — a distinction worth stating explicitly, since conflating the two would understate the available reaction time for a slower-moving lead object.| Quantity | Value |
|---|---|
| Travel speed, v | 13.89 m/s (50 km/h) |
| Manual-brake reaction window (Warning→Auto-Brake) | 0.36 s |
| Max. end-to-end system latency, t_sys | 0.216 s ≈ 216 ms |
| General formula | t_sys,max(v) = (d_auto − d_brake(v) − d_safe) / v |