The increasing adoption of multicore architectures in safety-critical and mixed-criticality systems has introduced significant challenges related to predictability, performance isolation, and security. This paper presents a comprehensive theoretical analysis of architectural strategies that address the inherent tension between shared resource utilization and strict real-time requirements in modern cyber-physical systems. Drawing exclusively on established literature, the study synthesizes advances in memory bandwidth management, cache partitioning, virtualization, and hardware-assisted security mechanisms such as ARM TrustZone. The research examines how shared memory hierarchies and multicore interference affect worst-case execution time predictability, and evaluates state-of-the-art techniques including MemGuard, BWLOCK, PRETI cache partitioning, and emerging memory policing frameworks. Furthermore, the paper explores the integration of virtualization technologies, including Xen and KVM, with real-time operating systems, highlighting both their potential benefits and inherent limitations in mixed-criticality environments. The role of modern hardware platforms such as Xilinx Zynq UltraScale+ MPSoC and Versal architectures is analyzed in terms of their capacity to support heterogeneous workloads with deterministic guarantees. The methodology adopts a qualitative synthesis approach, critically examining how these technologies interact across hardware and software layers. The findings reveal that while significant progress has been made in mitigating resource contention, achieving full predictability remains elusive due to complex interactions between memory systems, hypervisors, and shared caches. The discussion emphasizes the need for co-design approaches that integrate hardware isolation mechanisms with software-level resource management. Limitations include the lack of empirical validation and the evolving nature of hardware architectures. Future research directions include adaptive memory management, machine learning-assisted scheduling, and scalable trust architectures. This study contributes to the development of resilient and predictable multicore systems for next-generation safety-critical applications.
Architectural Strategies for Predictable and Secure Mixed-Criticality Multicore Systems: Integrating Memory Isolation, Virtualization, And Hardware-Assisted Trust Mechanisms
Keywords:
Abstract
References
Venkata S. K., Ahn I., Jeon D., et al. Sd-vbs: The San Diego Vision Benchmark Suite. IEEE International Symposium on Workload Characterization (2009), pp. 55–64.
Xilinx. ZCU102 MPSoC Technical Reference Manual (2022).
Xilinx. Xilinx Versal Architecture (2023).
Yun H., Yao G., Pellizzoni R., et al. MemGuard: Memory bandwidth reservation system for efficient performance isolation in multi-core platforms. IEEE Real-Time and Embedded Technology and Applications Symposium (2013).
Yun H., Pellizzoni R., Valsan P. K. Parallelism-aware memory interference delay analysis for COTS multicore systems. Euromicro Conference on Real-Time Systems (2015).
Yun H., Yao G., Pellizzoni R., et al. Memory bandwidth management for efficient performance isolation in multi-core platforms. IEEE Transactions on Computers, 65 (2) (2016), pp. 562–576.
Yun H., Ali W., Gondi S., et al. BWLOCK: A dynamic memory access control framework for soft real-time applications on multicore platforms. IEEE Transactions on Computers, 66 (7) (2017), pp. 1247–1252.
Zhou Y., Wentzlaff D. MITTS: Memory inter-arrival time traffic shaping. International Symposium on Computer Architecture (2016).
Zuepke A., Bastoni A., Chen W., et al. Mempol: Policing core memory bandwidth from outside of the cores. IEEE Real-Time and Embedded Technology and Applications Symposium (2023).
Chisholm M., Kim N., Ward B. C., Otterness N., Anderson J. H., Smith F. D. Reconciling the tension between hardware isolation and data sharing in mixed-criticality multicore systems. IEEE Real-Time Systems Symposium (2016), pp. 57–68.
Lesage B., Puaut I., Seznec A. PRETI: Partitioned real-time shared cache for mixed-criticality real-time systems. Real-Time and Network Systems (2012), pp. 171–180.
Kim N., Ward B. C., Chisholm M., Anderson J. H., Smith F. D. Attacking the one-out-of-m multicore problem by combining hardware management with mixed-criticality provisioning. Real-Time Systems, 53 (5) (2017), pp. 709–759.
ARM Developer Documentation. What is TrustZone?
Pan D., Burns A., Jiang Z., Liao X. TZDKS: A new TrustZone-based dual-criticality system with balanced performance. IEEE RTCSA (2018), pp. 59–64.
Jiang Z., Dong P., Wei R., Zhao Q., Wang Y., Zhu D., Zhuang Y., Audsley N. PSpSys: A time-predictable mixed-criticality system architecture based on ARM TrustZone. Journal of Systems Architecture, 123 (2022).
Griffin D., Bate I., Davis R. I. Generating utilization vectors for the systematic evaluation of schedulability tests. IEEE Real-Time Systems Symposium (2020), pp. 76–88.
Avanzini A., Valente P., Faggioli D., Gai P. Integrating Linux and the real-time ERIKA OS through the Xen hypervisor. IEEE International Symposium on Industrial Embedded Systems (2015).
Schulz B., Annighofer B. Evaluation of adaptive partitioning and real-time capability for virtualization with Xen hypervisor. IEEE Transactions on Aerospace and Electronic Systems, 58 (1) (2022), pp. 206–217.
Dall C., Nieh J. KVM/ARM: The design and implementation of the Linux ARM hypervisor. ACM SIGPLAN Notices, 49 (4) (2014), pp. 333–348.
Ma J.-S., Kim H.-Y., Choi W. KVM-QEMU virtualization with ARM 64-bit server system. Cloud Computing (2016), pp. 334–343.
Hildenbrand D., Schulz M. Virtio-mem: Paravirtualized memory hotplug. ACM SIGPLAN/SIGOPS International Conference on Virtual Execution Environments (2021).
Manik V. K., Arora D. Performance comparison of commercial VMM: ESXi, Xen, Hyper-V and KVM. IEEE INDIACom (2016), pp. 1771–1775.
Tran G. P. C., Chen Y.-A., Kang D.-I., Walters J. P., Crago S. P. Hypervisor performance analysis for real-time workloads. IEEE High Performance Extreme Computing Conference (2016).
Shi H., Li X., Zhao Y. Database performance comparison of Xen, KVM and OSv using Cassandra. IEEE IMCEC (2018), pp. 27–30.
Raho M., Spyridakis A., Paolino M., Raho D. KVM, Xen and Docker: A performance analysis for ARM-based NFV and cloud computing. IEEE AIEEE (2015).
26. Abdul Salam Abdul Karim. (2023). Fault-Tolerant Dual-Core Lockstep Architecture for Automotive Zonal Controllers Using NXP S32G Processors. International Journal of Intelligent Systems and Applications in Engineering, 11(11s), 877–885. Retrieved from https://ijisae.org/index.php/IJISAE/article/view/7749