The goal of System Level Formal Verification is to\ud
show system correctness notwithstanding uncontrollable events\ud
(disturbances), as for example faults, variation in system parameters,\ud
external inputs, etc. This may be achieved with an exhaustive\ud
Hardware In the Loop Simulation based approach, by considering\ud
all relevant scenarios in the System Under Verification (SUV)\ud
operational environment.\ud
In this paper, we present SyLVaaS, a Web-based tool enabling\ud
Verification as a Service (VaaS). SyLVaaS implements an assumeguarantee\ud
approach to the verification problem outlined above.\ud
SyLVaaS takes as input a high-level model defining the SUV\ud
operational environment and computes, using parallel algorithms\ud
deployed in a cluster infrastructure, a set of highly optimised\ud
simulation campaigns, which can be executed in an embarrassingly\ud
parallel fashion on a set of Simulink instances, using a platform\ud
independent Simulink driver downloadable from the SyLVaaS\ud
Web site.\ud
As the actual simulation is carried out at the user premises\ud
(e.g., in a private cluster), SyLVaaS allows full Intellectual\ud
Property protection on the SUV model and the user verification\ud
flow.\ud
The simulation campaigns computed by SyLVaaS randomise\ud
the verification order of operational scenarios and this enables,\ud
at anytime during the parallel simulation activity, the estimation\ud
of the completion time and the computation of an upper bound\ud
to the Omission Probability, i.e., the probability that there is\ud
a yet-to-be-simulated operational scenario which violates the\ud
property under verification. This information supports graceful\ud
degradation in the verification activity.\ud
We show effectiveness of the SyLVaaS algorithms and infrastructure\ud
by evaluating the system on industry-scale input related\ud
to the verification of the Fuel Control System (FCS) model in the\ud
Simulink distribution