A Modular Proof of Correctness for a Network Synchronizer
Name
MIT-LCS-TM-341.pdf
Size
23.81 MB
Format
Adobe PDF
Checksum (MD5)
e9c3f96e7ad47a00c946b9e3cb8ea3a8
Author(s) • •
Fekete, A.
Lynch, N.
Shrira, L.
Date Issued
September 1987
Series/Report no.
MIT-LCS-TM-341
Abstract
In this paper we offer a formal, rigorous proof of the correctness of Awerbuch's algorithm for network synchronization. We specify both the algorithm and the correctness condition using the I/O automaton model, which has previously been used to describe and verify algorithms for concurrency control and resource allocation. We show that the model is also a powerful tool for reasoning about distributed graph algorithmss. Our prood of correctness follows closely the intuitive arguments made by the designer of the algorithm by exploiting the model's natural support for such important design techniques as stepwise refinement and modularity. In particular, since the algorithm uses simpler algorithms for synchronization within and between "clusters" of nodes, our prood can import as lemmas the correctness of these simpler algorithms.
Persistent DSpace Link