Features

Life’s a beach for Rapita Systems

From an academic Impact Case Study that has since expanded into a successful commercial enterprise, Rapita continues to deliver confidence to customers with safety-critical systems.

In 2004, Mark Zuckerberg and his Harvard University college roommates launched Facebook.

At first glance, Facebook and Rapita System make odd bedfellows, but they do share some commonalities. Both were founded in 2004. Both share an academic background — Facebook was launched by Mark Zuckerberg and his college roommates at Harvard University; Rapita’s founders, members of the Real-Time Systems Research Group at the University of York. And both have had, and continue to have, a lasting impact on their respective fields: Facebook on social networking and Rapita on on-target software verification solutions, including multicore timing analysis.

As Guillem Bernat, Rapita Systems co-founder and CEO muses in conversation with Aerospace Innovations, “It’s difficult to think of specific achievements, it is more a realisation that the company I founded has made a meaningful contribution to safety-critical systems. For a specific example, once on a long work trip to Asia traveling with a colleague, we realised that Rapita technology was used on every plane we boarded.”

Although it’s led them on very different trajectories, just like Zuckerberg, Bernat has a curious mind and an interest in programming.

“I always wanted to be an inventor,” Bernat says. “Even as a small kid, I would dismantle things to find out how they worked. I remember that when my school friends were collecting football trump cards, I was collecting weekly issues of an encyclopaedia called “Como Funciona” (How it works) and building electronic kits,” he says.

That pursuit led him to studying computer science at the Universitat de les Illes Balears in Mallorca, where in his last year, he was given the opportunity to join the university as a lecturer, under the condition that he took a PhD.

Bookish beginnings
“There was a problem, though, my English was not great – it was good enough to read technical books and articles, but not good enough to write academic articles and do a PhD in English. Part of the deal was that I would do a year of my PhD in the UK to improve my English writing,” he says. He was subsequently awarded a grant to attend the University of Aberystwyth in Wales. “My PhD was on Scheduling in Safety Critical Real-Time systems.”

It is here that serendipity steps in. Noticing one day that Bernat was reading one of the primary textbooks, ‘Real-Time Systems and their programming languages’ by Alan Burns and Andy Wellings from the University of York, his supervisor, Professor Ian Pyle said “Do you want to meet them? I was one of the founders of the computer science department at York and I hired them.”

A meeting with Alan Burns in York led to a new direction for Bernat’s’ PhD and an invite to complete a post doctorate at York, which in turn led him to becoming a Research Associate on a UK funded project on portable Worst-Case execution time (WCET) analysis alongside Burns. “On the back of this project, I was invited to be the external PhD examiner of Antoine Colin, whom I ended up inviting to do a postdoc with me in York.”

Colin would become one of the founders of Rapita Systems, alongside another colleague Ian Broster, a postdoc at York.

“By that time,” explains Bernat, “I had won a lectureship position at York and was involved in one of the first funded EU projects on the embedded systems unit, where we had a work package of doing WCET analysis on a new computing paradigm based on the time triggered architecture of the company involved. Antoine and I invented a new method to do WCET analysis using a hybrid technique combining measurements and static analysis which became the first version of our WCET tool that is now RapiTime.”

Going to market
RapiTime is part of the Rapita Verification Suite (RVS), and it spurred on the creation of Rapita Systems (named after a fine-white sand beach on the south coast of Mallorca) to specifically commercialise it.

“I got really frustrated with how slow industry was in adopting the latest innovations from research centres and universities. There is a lot of good research that stays in papers gathering dust in shelves. And it struck us that the only way to get industry to adopt what we created was for us to push it ourselves. It helped that one of the industrial partners in the R&D project kept asking whether we were going to commercialise the tool. In the end we took the plunge and decided to create a company.”

During this process, the fourth founder of the company, Rob Davies, came into the picture, becoming CEO. Unfortunately, ill health later forced Davies to step away from the company, with Bernat assuming the CEO role, “We spent the first few years building the RapiTime tool and opening the market. More than 20 years later, we are still using the innovations that we invented,” explains Bernat.

One of the early adopters and pioneers was a leading multinational conglomerate, who adopted RapiTime for the flight control computer of a widebody aircraft.

“I remember that during one meeting, our internal champion, Wayne King, said “Could you also do structural code coverage? RapiTime already shows most of the data”. The answer, of course, was “Sure we can!” Taking advantage of our techniques for very low overhead of instrumentation that is required to do timing analysis, we could apply them to instrument for coverage analysis and in systems with very limited on-target resources available. This is how our second tool, RapiCover, was conceived. Along the way, we have had many other “features” that have shaped the future of our tools.”

Since launching with RapiTime and RapiCover, RVS has grown to include tools to support functional and requirements-based testing, task scheduling analysis and visualisation, and zero-instrumentation approaches to timing and coverage analysis. To this, the company has added DO-330 qualification kits for supported tools and key effort-saving features such as low on-target overheads and qualified instrumentation.

In addition to the expansive RVS portfolio, Rapita regularly publishes white papers and research articles, such as last year’s Defining Quantifiable Measures for Data Coupling and Control Coupling, coauthored with Collins Aerospace, which presents preliminary efforts towards making a step-change in the field of data coupling and control coupling analysis for safety-critical software. The company has also participated in a number of pan-European research projects, including the recently concluded ISOLDE Project, which aims to develop high performance RISC-V processing systems and platforms.

“We are still inventors and academics at heart, and we’re very proud of that,” says Bernat. “Solving technical problems and teaching what we know is in our genes. For us, doing R&D projects and writing papers is a continuation of our early days as academics converted into industrialists. We have developed a company ethos — “Safety through quality” — to make our skies safer to travel. Quality is in everything that we do – how we write our tools, how we teach best practice, and even how we answer the phone and treat each other.”

Happiness at heart
These values of trust and respect guide the company’s processes and strategies and have been deliberately cultivated. It’s an approach inspired by online clothing retailer Zappos, which seeks to deliver happiness to all its stakeholders, and become recognised for being “a service company that just happens to sell _.”

“I know it sounds like a cliché, but we are in the business of making people happy, and if you know how to ask, people tell you what makes their life difficult, and if you can find a solution to that, then you’ll have a happy customer for a very long time. This has been the philosophy of Rapita from the beginning,” Bernat explains.

He adds that people ultimately buy from people. “People are the basis for being happy. If you have a problem; you want people to help you. If you resolve it yourself, that’s fine. If we have a good relationship with our customer and can provide them something that can make their life easier because it helps them do something faster, better, cheaper, or all three, that’s our business model.”

Trust process
Part of this is Rapita’s unusual recruitment process, which sees potential employees spend a day in the office. As the company says, it’s not just about an individual’s talents, skills and experience. “It’s about you as a person, whether you fit within that environment, and how you work with people and how you treat people.”

Bernat says that as the company was developing, the focus was upon building something and making a successful business, first products and then verification tools.

As he points out, that was at a time when it was just the three founders (Rapita now has approximately 80 employees across three international sites, and since 2016, has been part of Danlaw, Inc., a global connected vehicle, automotive electronics and embedded engineering enterprise), who did everything. “Therefore, your work is directly the output of what you put in. But as soon as you need to get more people, then you end up doing less work, are less directly involved in the products. Instead, you are more involved in enabling other people to do their work. And the only way you can do it… is by extending the use of the term leadership: a leader is somebody who shows the way to people, who looks after those to the right, and to the left of them, so that they benefit,” Bernat states.

Being leaders rather than managers helps reinforce the ‘no blame’ culture of the company, which instead focuses on ‘how can we fix this?’ Bernat says that employees believe in this because the company has developed this knowledge, this relationship, this culture, and people with the right attitude. “That’s what’s important: the people we have. We empower them.”

This team ethos, rather than individualism, was very much on display last year as Rapita bought all employees under one roof, flying people in from the US and Spain for three days in York to workshop and socialise.

Trust and respect go together for the company, which goes beyond being just a trusted organisation. “We trust each other to actually deliver on what we’re doing and support each other. There’s a huge amount of trust within the organisation…that really feeds externally outwards. It’s something that we then want to instil in others and other companies that work with us, whether that’s partners or customers. We treat a lot of our customers as partners anyway, because we’re working to meet their needs and solve their pains in partnership with them. We don’t just sell to them and leave,” Bernat adds.

Above and beyond
“Because of this, helping shape guidance and industry best practice is a key part of our mission,” adds Bernat. “While some verification objectives such as structural coverage analysis are tried and tested and it’s obvious how they can be met practically, others such as multicore verification and data and control coupling analysis aren’t. In these areas, we’re actively engaging with both certification authorities and customers to cement the methods that will support the development of safe software, even as it becomes increasingly complex, for years to come. Around multicore verification specifically, we’ve been involved in developing the industry guidance and delivered training to many certification authorities around the world covering how guidance such as A(M)C 20-193 and AA-22-01 can be followed in a practical, repeatable manner.

“The dilemma here is to find the balance with doing the minimal thing that produces the maximum revenue and doing the right thing to make our skies safer to travel in the future. We chose to do the right thing and follow the intent of developing safety-critical systems, rather than just ticking the “certified” box.”

He provides an anecdote from years ago that explains this dilemma. “For DO-178C structural coverage analysis, the objective is to show by requirements-based testing that you have achieved 100% structural code coverage at the required granularities – basically, show that not a single line of code has not been tested. If your software is complex, there may be areas of the code that are very hard to test. Years ago, one customer kept asking us to help them make the argument that 80% code coverage was a good level of coverage. We refused to help that customer justify that 80% was enough coverage to their customer, because it isn’t. That 20% of hard to test code is probably where key functionality is, and the fact that it was not tested probably meant that it was designed in a way that was too complicated, hard to specify, develop and test, and likely still included defects. The objective isn’t really to achieve 100% code coverage, it’s to develop safe software that doesn’t kill people, and the metric is a way to show how good the code is. That customer no longer does business with us, but at least we slept much better.”

A key paradigm in the development of safety-critical software is to keep the architecture simple and the execution deterministic. This simplifies verification and maintainability of the software.

Multicore software by nature has more complex architecture and non-deterministic execution and this presents additional risk for software development and certification. According to Bernat, the key challenge is understanding how this risk can be mitigated during every aspect of the software development life cycle, from planning to software verification.

“Through R&D projects, working with certification authorities, partners and customers, and ultimately the development of the MACH178 solution, we’ve been helping the industry understand how to mitigate the risks of developing multicore software theoretically and practically for over a decade. This includes much more than just delivering tools and includes helping to shape the guidance and develop practical procedures that can be followed to mitigate the impact of interference and verify software behaviour in an efficient, repeatable manner.”

“We realised early on that our biggest competitor in supporting the certification of multicore processors was ignorance of the complexity of the problem. While the reality is that a single tool isn’t enough to provide a solution, that’s what many would naively look for. To address this, we embarked on an education initiative, organising multicore certification training events in both Europe and the US to explain the multicore guidance and how to interpret it, and how to achieve the certification objectives while minimising cost and risk through interference mitigation and efficient, repeatable testing. We’ve now been running such courses for over 5 years, for customers, partners, and even certification authorities.”

Passionate flame
After 21 years, Bernat is still driven by the pursuit of safety through quality. “It’s a passion. There’s a nice quote that says you live life with a purpose and with meaningful relationship. The meaningful relationship is the people that travel around. The purpose, the reason I get out of bed, is Rapita, and the machinery of the people here.”

Summing up, Bernat says, “We’re proud to be at the bleeding edge of developing the verification methods that will help the avionics industry deliver safe software for years to come. Today, we’re continuing our work on multicore software verification and helping define new best-in-class processes and tooling to support data coupling and control coupling analysis, which is also a concern for multicore verification. Looking further ahead, the sky is the limit, but we’re considering things such as how we can make the verification of code using model-based development workflows more efficient, how we can leverage AI in our tools and support the certified use of AI, and how our expertise can help cybersecurity verification.”