- Book Chapter
3
- 10.1007/978-3-031-68738-9_13
Enabling Theory-Based Continuous Assurance: A Coherent Approach with Semantics and Automated Synthesis
- Jan 01, 2024
- Srivatsan Varadarajan + 8 more +8
Publications from 2021 to 2026
Showing 10 of 20 papers
Enabling Theory-Based Continuous Assurance: A Coherent Approach with Semantics and Automated Synthesis
Towards Identifying and closing Gaps in Assurance of autonomous Road vehicleS -- a collection of Technical Notes Part 1
This report provides an introduction and overview of the Technical Topic Notes (TTNs) produced in the Towards Identifying and closing Gaps in Assurance of autonomous Road vehicleS (Tigars) project. These notes aim to support the development and evaluation of autonomous vehicles. Part 1 addresses: Assurance-overview and issues, Resilience and Safety Requirements, Open Systems Perspective and Formal Verification and Static Analysis of ML Systems. Part 2: Simulation and Dynamic Testing, Defence in Depth and Diversity, Security-Informed Safety Analysis, Standards and Guidelines.
Read moreUsing an Assurance Case Framework to Develop Security Strategy and Policies
Assurance cases have been developed to reason and communicate about the trustworthiness of systems. Recently we have also been using them to support the development of policy and to assess the impact of security issues on safety regulation. In the example we present in this paper, we worked with a safety regulator (anonymised as A Regulatory Organisation (ARO) in this paper) to investigate the impact of cyber-security on safety regulation.
Read moreThe fate of proteins in outer space
It is well established that any properly conducted biophysical studies of proteins must take appropriate account of solvent. For water-soluble proteins it has been an article of faith that water is largely responsible for stabilizing the fold, a notion that has recently come under increasing scrutiny. Further, there are some instances when proteins are studied experimentally in the absence of solvent, as in matrix-assisted laser desorption/ionization or electrospray mass spectrometry, for example, or in organic solvents for protein engineering purposes. Apart from these considerations, there is considerable speculation as to whether there is life on planets other than Earth, where conditions including the presence of water (both in liquid or vapor form and indeed ice), temperature and pressure may be vastly different from those prevailing on Earth. Mars, for example, has only 0.6% of Earth's mean atmospheric pressure which presents profound problems to protein structures, as this paper and a large corpus of experimental work demonstrate. Similar objections will most likely apply in the case of most exoplanets and other bodies such as comets whose chemistry and climate are still largely unknown. This poses the question, how do proteins survive in these different environments? In order to cast some light on these issues we have conducted a series of molecular dynamics simulations on protein dehydration under a variety of conditions. We find that, while proteins undergoing dehydration can retain their integrity for a short duration they ultimately become disordered, and we further show that the disordering can be retarded if superficial water is kept in place on the surface. These findings are compared with other published results on protein solvation in an astrobiological and astrochemical setting. Inter alia, our results suggest that there are limits as to what to expect in terms of the existence of possible extraterrestrial forms as well to what can be achieved in experimental investigations on living systems despatched from Earth. This finding may appear to undermine currently held hopes that life will be found on nearby planets, but it is important to be aware that the presence of ice and water are by themselves not sufficient; there has to be an atmosphere which includes water vapor at a sufficiently high partial pressure for proteins to be active. A possible scenario in which there has been a history of adequate water vapor pressure which allowed organisms to prepare for a future dessicated state by forming suitable protective capsules cannot of course be ruled out.
Read moreA fully-abstract semantics of lambda-mu in the pi-calculus
We study the lambda-mu-calculus, extended with explicit substitution, and define a compositional output-based interpretation into a variant of the pi-calculus with pairing that preserves single-step explicit head reduction with respect to weak bisimilarity. We define four notions of weak equivalence for lambda-mu -- one based on weak reduction, two modelling weak head-reduction and weak explicit head reduction (all considering terms without weak head-normal form equivalent as well), and one based on weak approximation -- and show they all coincide. We will then show full abstraction results for our interpretation for the weak equivalences with respect to weak bisimilarity on processes.
Read moreSafety cases for medical devices and health information technology: Involving health-care organisations in the assurance of safety
In the United Kingdom, there are more than 9000 reports of adverse events involving medical devices annually. The regulatory processes in Europe and in the United States have been challenged as to their ability to protect patients effectively from unreasonable risk and harm. Two of the major shortcomings of current practice include the lack of transparency in the safety certification process and the lack of involvement of service providers. We reviewed recent international standardisation activities in this area, and we reviewed regulatory practices in other safety-critical industries. The review showed that the use of safety cases is an accepted practice in UK safety-critical industries, but at present, there is little awareness of this concept in health care. Safety cases have the potential to provide greater transparency and confidence in safety certification and to act as a communication tool between manufacturers, service providers, regulators and patients.
Read moreDoes Software Have to Be Ultra Reliable in Safety Critical Systems?
It is difficult to demonstrate that safety-critical software is completely free of dangerous faults. Prior testing can be used to demonstrate that the unsafe failure rate is below some bound, but in practice, the bound is not low enough to demonstrate the level of safety performance required for critical software-based systems like avionics. This paper argues higher levels of safety performance can be claimed by taking account of: 1) external mitigation to prevent an accident: 2) the fact that software is corrected once failures are detected in operation. A model based on these concepts is developed to derive an upper bound on the number of expected failures and accidents under different assumptions about fault fixing, diagnosis, repair and accident mitigation. A numerical example is used to illustrate the approach. The implications and potential applications of the theory are discussed.
Read moreCurrent Capabilities, Requirements and a Proposed Strategy for Interdependency Analysis in the UK
The UK government recently commissioned a research study to identify the state-of-the-art in Critical Infrastructure modelling and analysis, and the government/industry requirements for such tools and services. This study (Cetifs) concluded with a strategy aiming to bridge the gaps between the capabilities and requirements, which would establish interdependency analysis as a commercially viable service in the near future. This paper presents the findings of this study that was carried out by CSR, City University London, Adelard LLP, a safety/security consultancy and Cranfield University, defense academy of the UK.
Read moreAn Approach to Using Non Safety-Assured Programmable Components in Modest Integrity Systems
Programmable components (like personal computers or smart devices) can offer considerable benefits in terms of usability and functionality in a safety-related system. However there is a problem in justifying the use of programmable components if the components have not been safety justified to an appropriate integrity (e.g. to SIL 1 of IEC 61508). This paper outlines an approach (called LowSIL) developed in the UK CINIF nuclear industry research programme to justify the use of non safety-assured programmable components in modest integrity systems. This is a seven step approach that can be applied to new systems from an early design stage, or retrospectively to existing systems. The stages comprise: system characterisation, component suitability assessment, failure analysis, failure mitigation, identification of additional defences, identification of safety evidence requirements, and collation and evaluation of evidence. In the case of personal computers, there is supporting guidance on usage constraints, claim limits on reliability, and advice on locking down the component to maximise reliability. The approach is demonstrated for an example system. The approach has been applied successfully to a range of safetyrelated systems used in the nuclear industry.
Read moreSoissons
Identifiant de l'operation archeologique : 8887 Date de l'operation : 2006 (MH) Les parcelles concernees couvrent une surface de 7 451 m2 qui fera l'objet de constructions de maisons individuelles. Elles se situent en limite exterieure de l'enceinte de l'abbaye merovingienne de Saint-Medard. Sur le cote est, la surface est bordee par le Ru de Saint-Medard qui alimentait l'abbaye en eau. De l'autre cote de ce ru, une zone inondable est actuellement en pâtures. Elle se situe approximativement 2...
Read more