John Lygeros
and Nancy Lynch. On
the Formal Verification of the TCAS Conflict Resolution
Algorithms. Proceedings of the 36th IEEE Conference on
Decision and Control, San Diego, CA, December 1997.
(Postscript)
Abstract
TCAS is an on-board protocol for detecting conflicts between aircraft and providing resolution advisories to the pilots. Because of its safety-critical role the TCAS software should ideally be ``verified'' before it can be deployed. The verification task is challenging, due to the complexity of the TCAS code and the hybrid nature of the system. We show how the essence of this very complicated problem can be captured by a relatively simple hybrid model, amenable to formal analysis. We then outline a methodology for establishing conditions under which the advisories issued by TCAS are safe.