Documente Academic
Documente Profesional
Documente Cultură
Simulink
Verification
and Validation verification tool:
DO-178B checks
Model coverage
This document is intended for use in the DO-178B tool qualification process
for verification tools.
See also the DO Qualification Kit Users Guide.
1 Introduction
1-2
2
Tool Operational
Requirements
The Tool Operational Requirements for the following capabilities in the
Simulink Verification and Validation product are documented in DO
Qualification Kit: Simulink Verification and Validation Tool Operational
Requirements:
DO-178B checks
Model coverage
2 Tool Operational Requirements
2-2
3
Certification Considerations
Requirement for Qualification on page 3-2
Certification Credit on page 3-5
This section provides certification considerations for the following capabilities
of the Simulink Verification and Validation verification tool:
DO-178B checks
Model coverage
3 Certification Considerations
Requirement for Qualification
In this section...
DO-178B Checks on page 3-2
Model Coverage on page 3-3
DO-178B Checks
To determine whether a tool must be qualified, you must answer the following
questions. If you answer yes to all three questions, you must qualify the tool.
Question DO-178B
Checks
Can the tool insert an error into the airborne software or
fail to detect an existing error in the software within the
scope of its intended usage?
Yes
1
Will the output of the tool not be verified as specified in
Section 6 of DO-178B?
Yes
Are processes of DO-178B eliminated, reduced, or automated
by the use of the tool? Will you use output from the tool
to meet an objective or replace an objective of DO-178B,
Annex A?
Yes
Given that the answer to all the preceding questions is yes, the DO-178B
checks in the Simulink Verification and Validation product must be qualified.
To determine the type of qualification (development tool or verification tool
qualification) needed, you must answer the following question about the tool.
Question DO-178B
Checks
Is the tool output part of the airborne software, such that
the output can insert an error into the software?
No
1. The DO-178B checks might fail to detect an error.
3-2
Requirement for Qualification
Because the answer to the preceding question is no, the DO-178B checks
in the Simulink Verification and Validation product must be qualified as a
verification tool.
Model Coverage
To determine whether a tool must be qualified, you must answer the following
questions. If you answer yes to all three questions, you must qualify the tool.
Question Model
Coverage
Can the tool insert an error into the airborne software or
fail to detect an existing error in the software within the
scope of its intended usage?
Yes
2
Will the output of the tool not be verified as specified in
Section 6 of DO-178B?
Yes
Are processes of DO-178B eliminated, reduced, or automated
by the use of the tool? Will you use output from the tool
to meet an objective or replace an objective of DO-178B,
Annex A?
Yes
Given that the answer to all the preceding questions is yes, the model
coverage capability in the Simulink Verification and Validation product must
be qualified.
To determine the type of qualification (development tool or verification tool
qualification) needed, you must answer the following question about the tool.
Question Model
Coverage
Is the tool output part of the airborne software, such that
the output can insert an error into the software?
No
2. Model coverage might fail to detect an error.
3-3
3 Certification Considerations
Because the answer to the preceding question is no, the model coverage
capability in the Simulink Verification and Validation product must be
qualified as a verification tool.
3-4
Certification Credit
Certification Credit
In this section...
DO-178B Checks on page 3-5
Model Coverage on page 3-9
DO-178B Checks
The following table shows the certification credit (see DO-178B Annex A
Objectives), being taken for the DO-178B checks in the Simulink Verification
and Validation product.
Note The DO-178B checks can contain two sections: an analysis section for
reviewing the model and an action section for automatically fixing warnings
and failures. The DO Qualification Kit covers the DO-178B check analysis,
not the check actions.
The DO Qualification Kit does not cover Model Advisor check exclusions.
Certification Credit for DO-178B Checks
Annex A
Table
Objective DO-178B
Reference
Software
Levels
Credit Taken
Table A-3 High-level
requirements
are accurate and
consistent
Section
6.3.1b
A, B, C, D Full or Partial
1
The DO178B
checks verify the accuracy and
consistency of the model statically. A
combination of Model Advisor checks,
simulation against the higher-level
requirements, and review of the
System Design Description can
be used to take full credit for this
objective.
Table A-3 High-level
requirements are
Section
6.3.1c
A, B Full or Partial
1, 3
The DO178B
checks verify that the code generator
3-5
3 Certification Considerations
Certification Credit for DO-178B Checks (Continued)
compatible with
target computer
settings related to the CPU are
correct. A combination of Model
Advisor checks and review of the
System Design Description can
be used to take full credit for this
objective.
Table A-3 High-level
requirements are
verifiable
Section
6.3.1d
A, B, C Full or Partial
1
The DO178B
checks verify parameter tunability,
test point visibility, and in some
cases can find unreachable decisions.
A combination of Model Advisor
checks and model coverage during
simulation can be used to take full
credit for this objective.
Table A-3 High-level
requirements
conform to
standards
Section
6.3.1e
A, B, C Full or Partial
1
The DO178B
checks verify conformance to
standards that have dedicated
checks. For any modeling standards
that do not have Model Advisor
checks, this verification may be
completed via manual reviews of the
System Design Description.
Table A-3 High-level
requirements
are traceable
to system
requirements
Section
6.3.1f
A, B, C, D Partial
1
The DO178B checks
verify that the requirements links
are consistent; the actual traceability
must be verified independently
by reviewing the Requirements
Traceability section of the System
Design Description.
3-6
Certification Credit
Certification Credit for DO-178B Checks (Continued)
Table A-3 Algorithms are
accurate
Section
6.3.1g
A, B, C Full or Partial
1
The DO178B
checks verify the accuracy of
data types used within the model
statically. A combination of Model
Advisor checks, simulation against
the higher-level requirements,
and review of the System Design
Description can be used to take full
credit for this objective.
Table A-4 Low-level
requirements
are accurate and
consistent
Section
6.3.2b
A, B, C Full or Partial
2
The DO178B
checks verify the accuracy and
consistency of the model statically. A
combination of Model Advisor checks,
simulation against the higher-level
requirements, and review of the
System Design Description can
be used to take full credit for this
objective.
Table A-4 Low-level
requirements are
compatible with
target computer
Section
6.3.2c
A, B Full or Partial
2, 3
The DO178B
checks verify that the code generator
settings related to the CPU are
correct. A combination of Model
Advisor checks and review of the
System Design Description can
be used to take full credit for this
objective.
Table A-4 Low-level
requirements are
verifiable
Section
6.3.2d
A, B Full or Partial
2
The DO178B
checks verify parameter tunability,
test point visibility, and in some
cases can find unreachable decisions.
A combination of Model Advisor
checks and model coverage during
simulation can be used to take full
credit for this objective.
3-7
3 Certification Considerations
Certification Credit for DO-178B Checks (Continued)
Table A-4 Low-level
requirements
conform to
standards
Section
6.3.2e
A, B, C Full or Partial
2
The DO178B
checks verify conformance to
standards that have dedicated
checks. For any modeling standards
that do not have Model Advisor
checks, this verification may be
completed via manual reviews of the
System Design Description.
Table A-4 Low-level
requirements
are traceable
to high-level
requirements
Section
6.3.2f
A, B, C Partial
2
- The DO-178B checks verify
that the requirements links are
consistent; the actual traceability
must be verified independently
by reviewing the Requirements
Traceability section of the System
Design Description.
Table A-4 Algorithms are
accurate
Section
6.3.2g
A, B, C Full or Partial
2
- The DO-178B checks
verify the accuracy of data types
used within the model statically. A
combination of Model Advisor checks,
simulation against the higher-level
requirements, and review of the
System Design Description can
be used to take full credit for this
objective.
Table A-4 Software
architecture is
consistent
Section
6.3.3b
A, B, C Full or Partial
2
The DO-178B
checks verify that the architecture of
the model is consistent statically. A
combination of Model Advisor checks,
simulation against the higher-level
requirements, and review of the
System Design Description can
be used to take full credit for this
objective.
3-8
Certification Credit
Certification Credit for DO-178B Checks (Continued)
Table A-4 Software
architecture
conforms to
standards
Section
6.3.3e
A, B, C Full or Partial
2
- The DO-178B checks
verify conformance to standards
that have dedicated checks. For
any modeling standards that do not
have Model Advisor checks, this
verification may be completed via
manual reviews of the System Design
Description.
Table A-5 Source code
is traceable
to low-level
requirements
Section
6.3.4e
A, B, C Partial
2, 3
The DO-178B checks
verify that the code generator settings
are appropriate for generating
traceable code; the actual traceability
must be verified independently.
Notes:
1
This credit is taken only if the Simulink and Stateflow
document:
Installation Guide
Model Coverage
Tool Operational Requirements for the model coverage capability of the
Simulink Verification and Validation product are in:
DO Qualification Kit: Simulink Verification and Validation Tool
Operational Requirements
The applicant will:
4-3
4 Tool Development Lifecycle
- Review the Tool Operational Requirements for applicability to the
project under consideration.
- Configure the Tool Operational Requirements in a configuration
management system.
User information for the model coverage capability of the Simulink
Verification and Validation product is in:
Simulink Verification and Validation Users Guide
Instructions for installing the Simulink Verification and Validation
product are in the following MathWorks document:
Installation Guide
4-4
Verification
Verification
In this section...
DO-178B Checks on page 4-5
Model Coverage on page 4-6
DO-178B Checks
Requirements-based test cases and procedures will be developed from the:
DO Qualification Kit: Simulink Verification and Validation Tool
Operational Requirements
The test cases and procedures will be developed in the form of the Simulink
models that exercise the DO-178B checks under consideration in the Model
Advisor.
The test cases and procedures are documented in:
DO Qualification Kit: Simulink Verification and Validation Test Cases,
Procedures, and Results
The applicant will:
Review the test cases and procedures for applicability to the project under
consideration.
Configure the test cases and procedures in a configuration management
system.
Execute the test cases and procedures in the installed environment.
Executing the Simulink Report Generator report listed in the following
table generates tool verification results in the specified test report.
Test File Test Report
qualkitdo_slvnv_tcpr1.rpt
1
qualkitdo_slvnv_qualificationreport1.html
The applicant will:
4-5
4 Tool Development Lifecycle
Review the test results for correctness.
Configure the test results in a configuration management system.
Model Coverage
Requirements-based test cases and procedures will be developed from the:
DO Qualification Kit: Simulink Verification and Validation Tool
Operational Requirements
The test cases and procedures will be developed in the form of the Simulink
models that exercise the model coverage capability.
The test cases and procedures are documented in:
DO Qualification Kit: Simulink Verification and Validation Test Cases,
Procedures, and Results
The applicant will:
Review the test cases and procedures for applicability to the project under
consideration.
Configure the test cases and procedures in a configuration management
system.
Execute the test cases and procedures in the installed environment.
Executing the Simulink Report Generator reports listed in the following table
generates tool verification results in the specified test reports.
Test File Test Report
qualkitdo_slvnv_tcpr2.rpt
1
qualkitdo_slvnv_qualificationreport2.html
qualkitdo_slvnv_tcpr3.rpt
2
qualkitdo_slvnv_qualificationreport3.html
qualkitdo_slvnv_tcpr4.rpt
1
qualkitdo_slvnv_qualificationreport4.html
qualkitdo_slvnv_tcpr5.rpt
2
qualkitdo_slvnv_qualificationreport5.html
4-6
Verification
Test File Test Report
qualkitdo_slvnv_tcpr6.rpt
3
qualkitdo_slvnv_qualificationreport6.html
Notes:
1
Requires a Simulink Fixed Point license.
2
Requires a Stateflow license.
3
Requires a Simulink Design Verifier license.
The applicant will:
Review the test results for correctness.
Configure the test results in a configuration management system.
4-7
4 Tool Development Lifecycle
4-8
5
Tool Lifecycle Data
DO-178B Checks on page 5-2
Model Coverage on page 5-4
5 Tool Lifecycle Data
DO-178B Checks
The following table shows the lifecycle data for the DO-178B checks in the
Simulink Verification and Validation product. The table maps the documents
and artifacts to DO-178B lifecycle data items.
Simulink Verification and Validation DO-178B Checks Lifecycle
Data
Data Available/
Submit
DO-178B
Reference
Documents/
Artifacts
Plan for
Software
Aspects of
Certification
(PSAC)
Submit Sections
12.2,
12.2.3a,
& 12.2.4
<Insert PSAC** reference
here.>
Tool
Qualification
Plan
Submit* Sections
12.2.3a(1),
12.2.3.1,
& 12.2.4
DO Qualification Kit:
Simulink Verification and
Validation Tool Qualification
Plan (this document)
Tool Operational
Requirements
Available Sections
12.2.3c(2)
& 12.2.3.2
DO Qualification Kit:
Simulink Verification and
Validation Tool Operational
Requirements
Test Cases and
Procedures
Available* Section
12.2.3c
DO Qualification Kit:
Simulink Verification and
Validation Test Cases,
Procedures, and Results
qualkitdo_slvnv_tcpr1.rpt
Test Results Available* Section
12.2.3c
DO Qualification Kit:
Simulink Verification and
Validation Test Cases,
Procedures, and Results
qualkitdo_slvnv_
qualificationreport1.html
5-2
DO-178B Checks
Simulink Verification and Validation DO-178B Checks Lifecycle
Data (Continued)
Data Available/
Submit
DO-178B
Reference
Documents/
Artifacts
Software
Accomplishment
Summary (SAS)
Submit Section
12.2.4
<Insert reference to SAS**
here.>
Tool
Qualification
Accomplishment
Summary
Submit Sections
12.2.3c(3)
& 12.2.4
<Insert reference to
Tool Qualification
Accomplishment Summary**
here.>
Notes:
* Optional for verification tool qualification
** To be created by applicant
The applicant must deliver data marked Submit to the certification
authorities. Data marked Available must be available at the applicants or
tool vendors site for inspection by the certification authorities.
5-3
5 Tool Lifecycle Data
Model Coverage
The following table shows the lifecycle data for the model coverage capability
of the Simulink Verification and Validation product. The table maps the
documents and artifacts to DO-178B lifecycle data items.
Simulink Verification and Validation Model Coverage Lifecycle
Data
Data Available/
Submit
DO-178B
Reference
Documents/
Artifacts
Plan for
Software
Aspects of
Certification
(PSAC)
Submit Sections
12.2,
12.2.3a,
& 12.2.4
<Insert PSAC** reference
here.>
Tool
Qualification
Plan
Submit* Sections
12.2.3a(1),
12.2.3.1,
& 12.2.4
DO Qualification Kit:
Simulink Verification and
Validation Tool Qualification
Plan (this document)
Tool Operational
Requirements
Available Sections
12.2.3c(2)
& 12.2.3.2
DO Qualification Kit:
Simulink Verification and
Validation Tool Operational
Requirements
Test Cases and
Procedures
Available* Section
12.2.3c
DO Qualification Kit:
Simulink Verification and
Validation Test Cases,
Procedures, and Results
qualkitdo_slvnv_tcpr2.rpt,
qualkitdo_slvnv_tcpr3.rpt,
qualkitdo_slvnv_tcpr4.rpt,
qualkitdo_slvnv_tcpr5.rpt,
qualkitdo_slvnv_tcpr6.rpt
5-4
Model Coverage
Simulink Verification and Validation Model Coverage Lifecycle
Data (Continued)
Data Available/
Submit
DO-178B
Reference
Documents/
Artifacts
Test Results Available* Section
12.2.3c
DO Qualification Kit:
Simulink Verification and
Validation Test Cases,
Procedures, and Results
qualkitdo_slvnv_
qualificationreport2.html,
qualkitdo_slvnv_
qualificationreport3.html,
qualkitdo_slvnv_
qualificationreport4.html,
qualkitdo_slvnv_
qualificationreport5.html,
qualkitdo_slvnv_
qualificationreport6.html
Software
Accomplishment
Summary (SAS)
Submit Section
12.2.4
<Insert reference to SAS**
here.>
Tool
Qualification
Accomplishment
Summary
Submit Sections
12.2.3c(3)
& 12.2.4
<Insert reference to
Tool Qualification
Accomplishment Summary**
here.>
Notes:
* Optional for verification tool qualification
** To be created by applicant
The applicant must deliver data marked Submit to the certification
authorities. Data marked Available must be available at the applicants or
tool vendors site for inspection by the certification authorities.
5-5
5 Tool Lifecycle Data
5-6
6
Schedule
<Insert tool schedule in this section.>