- Research Article
25
- 10.1016/j.procs.2016.09.290
Topology-based Safety Analysis for Safety Critical CPS
- Jan 01, 2016
- Procedia Computer Science
- Jean-Yves Choley + 3 more +3
Topology-based Safety Analysis for Safety Critical CPS
SUMMARY & CONCLUSIONSMost, if not all, safety-critical systems developed are cyber-physical systems (CPS), defined by the presence of a physical component and connectedness to other systems, with a clear trend towards inclusion of over-the-air update capabilities. From a certification standpoint, every change to the system, even in software, should lead to an evaluation of its safety impact. Model-based system engineering offers the possibility of connecting domain-specific models used in the development of the CPS with relevant safety analysis models. The goal is to automate the evaluation of the impact of changes. Changes, however, can only be propagated if the dependencies of the specific model in which the change is introduced are accurately represented. These are difficult to model, as formal descriptions only exist for a subset of dependencies, and some have been completely neglected in model-based systems engineering. Our work provides an overview of the various shapes that dependencies take within model-based safety analysis. The importance of modeling these dependencies is shown in an illustrative example, in which an FMEA, SysML, and Lifecycle model are investigated.
Topology-based Safety Analysis for Safety Critical CPS
Topology-based Safety Analysis for Safety Critical CPS
Application and research on model-based safety analysis
With the increase of military and civil aircraft system complexity, the shortage of traditional safety analysis technology goes distinctly, while the Model-based Safety Analysis technology attaches more and more importance. Therefore, this paper presents the background, basic concept and research and application situation of Model-based Safety Analysis technology, identifies the benefit of it. This paper also presents a framework of taking Model-based Safety Analysis into airplane safety assessment process, and a case study of performing MBSA in powerplant system is given to shown the effect of MBSA. Finally, this paper analyses the shortage and challenge of Model-based Safety Analysis considering its application in aircraft safety assessment process.
Read moreTowards a Holistic and Functional Model-Based Design Method for Mechatronic Cyber-Physical Systems
Engineering cyber-physical systems (CPS) is complex and time-consuming due to the heterogeneity of the involved engineering domains and the high number of physical and logical interactions of their subsystems. Model-based systems engineering (MBSE) approaches tackle the complexity of developing CPS by formally and explicitly modeling subsystems and their interactions. Newer approaches also integrate domain-specific models and modeling languages to cover different aspects of CPS. However, MBSE approaches are currently not fully applicable for CPS development since they do not integrate formal models for physical and mechanical behavior to an extent that allows to seamlessly link mechanical models to the digital models and reuse them. In this paper, we discuss the challenges arising from the missing integration of physics into MBSE and introduce a model-based methodology capable of integrating physical functions and effects into an MBSE approach on a level where detailed physical effects are considered. Our approach offers a fully virtual, model-based development methodology covering the whole development process for the development of CPS. Evaluating this methodology on a real automotive use case demonstrates benefits regarding virtual development and functional testing of CPS. It shows potentials regarding automated development and continuous integration of the whole CPS including all domains. As an outlook of this paper, we discuss potential further research topics extending our development workflow.
Read moreThe hazard analysis profile: Linking safety analysis and SysML
To handle stricter safety regulations combined with increasing complexity and shorter development cycles, it is necessary to consider safety aspects starting from the early phases of design. This paper presents an approach to link methods of safety analysis and modeling (SysML). Even though SysML and MBSE are common in the early stages of system design, there is a lack of methods integrating model-based design activities and safety analyses. Existing approaches either focus on particular tasks or build models after conducting separate safety analyses. Our presented approach, tailored to early stages of system design, introduces a "Hazard Analysis" SysML profile accompanied by a procedure for its application within a model-based safety analysis. It provides a preliminary hazard analysis and facilitates the systematic identification of safety-critical functions and components.
Read moreApplication of MBSE to Risk-Informed Design Methods for Space Mission Applications
This paper describes research into the application of Model-Based Systems Engineering (MBSE) tools and processes to Risk-Informed Design (RID). RID enables system risk analyses early in the lifecycle of spaceflight projects allowing designers to use risk as a design commodity and part of the overall trade space. RID uses a “minimum functionality” approach, whereby a minimal, single-string system design is first envisioned that only meets basic performance requirements without any regard to overall reliability or safety. Risk analyses are then used to apply informed design enhancements based on their contribution to risk reduction. A recent application of RID was the Altair Lunar Lander Project that was intended for human lunar exploration under NASA’s Constellation Program. The Altair project’s approach and results are reviewed and analyzed in this paper as a specific application of RID. In traditional projects, several tools such as Relex, Windchill or SAPHIRE, are used in parallel to apply risk informed design techniques. These analyses also traditionally occur later in the design cycle when changes are more difficult to implement. Safety and reliability analyses typically have no direct connection with the system architecture model, which accurately depicts the physical and functional constructs of a system, including the “ilities.” The model is directly impacted by the results of the analyses. This creates a time-consuming iterative process of analyses and modification because of the need to integrate several tools and teams. To improve this process, the research described here investigated the use of a single, cloud-based MBSE CAD tool called Innoslate that integrates failure analysis into the system architecture model. The specific focus of the research was on the analysis of system failure events through the use of a system architecture-modeling tool and the establishment of an MBSE process that enables system engineers to make risk-informed system modifications during development. The conclusion of the research was that MBSE in general, and Innoslate specifically, is capable of providing an integrated, effective and quantitative means of developing a risk-informed system design using a minimum functionality baseline process. This can be applied to human and robotic spaceflight systems and other systems with similar complexity. The research demonstrated that random distributions could be added to failure probabilities in order to add “noise” to the results, a task that can be laborious, if not impossible, if performed using a calculator or spreadsheet. The research also demonstrated an end-to-end MBSE process that was applied to a basic system model and the Altair Project. Recommendations for future work conclude the paper.
Read moreSupporting the Automated Generation of Modular Product Line Safety Cases
The effective reuse of design assets in safety-critical Software Product Lines (SPL) would require the reuse of safety analyses of those assets in the variant contexts of certification of products derived from the SPL. This in turn requires the traceability of SPL variation across design, including variation in safety analysis and safety cases. In this paper, we propose a method and tool to support the automatic generation of modular SPL safety case architectures from the information provided by SPL feature modeling and model-based safety analysis. The Goal Structuring Notation (GSN) safety case modeling notation and its modular extensions supported by the D-Case Editor were used to implement the method in an automated tool support. The tool was used to generate a modular safety case for an automotive Hybrid Braking System SPL.
Read moreSystems Engineering Approaches and Tools for Redesigning the Higher Technical Education System
Nowadays, in software, electronics and automotive industries, it takes 1.5–2 years for a new product to appear, although it takes 3 or even more years to develop new space instruments. The update of higher education system standards is even more conservative. It takes 10 or more years. Because of this, graduates come into the industry with outdated knowledge. Thus, the problem is to synchronize the processes of updating technologies that ensure the creation of innovative products with educational programs. It can be solved by changing the paradigm of products creation based on the synthesis of deep and interdisciplinary educational, scientific, innovative and production activities with the model-based systems engineering software and methodological tools.The existing model-based systems engineering (MBSE) Software (SW) tools based on the Systems Modelling Language (SysML) are complex and expensive. This chapter raises the question, “Is it possible to make use of MBSE SW and methodological tools available to a wide audience of users?” To answer this question, the following MBSE approaches and tools were researched: Quality Function Deployment (QFD), House of Quality (HoQ), and SysML. Consequently, five methodological tools were developed for application during space instruments design and development life cycle stages. Tools are based on SysML, QFD, HoQ improvements and synthesis, and expressed in theoretical and practical algorithms.The theoretical algorithm determines “What” (input and output data) and “How” (by using which systems engineering (including MBSE) tools are methodically analysed at the certain space instruments life cycle stage. The practical algorithm automates the development of SysML diagrams by using data structured in HoQ models and widely available SW. It reduces the time to develop and update SysML requirements diagrams from several days to some minutes and enables implementation of SysML SW by many users. Altogether, the obtained results constitute the software and methodological toolkit (SMT) called “improved Quality Function Deployment for improved House of Quality”.To disseminate the obtained results, educational materials were created and validated during lectures on systems engineering. Lectures were supplemented with seminars and practicum. Practicum was focused on the design and development (D&D) of nanosatellites in the MBSE paradigm as the single project. The results showed that the developed SMT makes it possible to implement the life cycle of the cyber-physical system in the MBSE paradigm in a cost-effective way and a short time—in 6 months, students developed, conducted synthesis and flight tests of CubeSat-format satellite prototype and prepared the project documentation. In addition, students were motivated to study science, technology, engineering and math disciplines, MBSE tools, and become transdisciplinary specialists.In addition, developed SysML requirements models were applied to examine the “Preliminary Design” product life cycle (PLC) stage of different space projects. Such application allowed quick assessment of project results, identifying non-compliance with requirements, conducting beforehand all necessary corrections and generating correct new product documentation. Taking into account the mentioned advantages of the obtained MBSE SMT, it can be concluded that its usage improves the quality and accuracy of current projects and speeds up the planning process of future analogue projects by up to 60%. Consequently, projects (their life cycle stages) can be realized faster by 5–10%.These results allow to recommend for all interested in the innovative D&D of systems to initiate: formation of educational programs based on the project approach and MBSE paradigm; preparation of MBSE materials for online and offline teaching of students and teachers; development of domestic widely available software for the development of integrated SysML models with HoQ models that assures synchronization with CAE/CAD/CAM systems; support these recommendations for the implementation of the above-mentioned research results at educational organizations of different levels. The future research is focused on the application of the developed MBSE methodological toolkit during design and development with numerical modelling and operation of several CubeSat satellites.KeywordsSystems engineeringMBSEParadigmMethodological toolkitSysMLQFDHoQ
Read moreПРЕОДОЛЕНИЕ НЕДОСТАТКОВ ПРОГРАММНО-МЕТОДИЧЕСКОГО ИНСТРУМЕНТАРИЯ МОДЕЛЬНО-ОРИЕНТИРОВАННОГО СИСТЕМНОГО ИНЖИНИРИНГА, ИСПОЛЬЗУЕМОГО ПРИ ПРОЕКТИРОВАНИИ СИСТЕМ
Moscow Institute of Physics and Technology (National Research University) The paper advocates the need to move from separate stages of the product life cycle (LC; R&D, production, operation) to a single project implemented in a new paradigm of system design based on software and methodological tools of model-based systems engineering (MBSE). Currently available in Russia foreign software (SW) and methodological MBSE tools for the design and development (D&D) of systems (including space instruments) are expensive and complex. This paper formulates and considers the question: «Is it possible to reduce the cost and simplify the use of software and methodological MBSE tools by means that are available to a wide audience of users?». To answer this question, the authors analyzed SysML, QFD method, HoQ method, and the SW for their application. As the result of literature review, it is shown that in the leading countries, the relevance of implementing these tools in the design and development of hardware and software systems is increasing. For the use of SysML, QFD, HoQ by a wide audience of potential users from Russian Federation were defined software tools. 13 disadvantages that prevent the application of SysML, QFD and HoQ, as well as SW for their use were identified. In order to overcome the identified disadvantages, was developed SW and methodological MBSE tool based on modernization, specification and synthesis of SysML, QFD, HoQ and SW for their application. The developed MBSE SW and methodological tool allows for a wide audience of users to D&D systems in accordance with MBSE approach (QFD, HoQ, SysML), to identify critical requirements of different development elements, to develop automatically (in a few hours instead of several days) and update SysML models of requirements, to reduce labor costs for the implementation of the D&D LC stages of future analog products by 5-10%. As a result of validation of SysML models, it is proved that their repeated use reduces the planning time of the LC stages of analog products by up to 60%, increases the compliance of the reporting documentation of the LC stages with the requirements of regulatory and technical documents by 10%.
Read moreNew Methodology for Model-Based Safety Analysis
Model-Based Safety Analysis (MBSA) is an approach in which the system and safety engineers share a common system model created using a model based development process. There are two famous approaches for the addition of fault behaviors to system models. The first one is to enclose the model of failures into the system design directly. The second approach is to develop a fault model separately from the system model; thus combining both independent models for safety analysis. This paper introduces a new Methodology of MBSA. The approach will combine various concepts such as directed graph traversal, event lists. A prototype tool is developed upon object oriented paradigm. The tool shall be tested on the famous Wheel Brake System. The results will be analyzed; advantages/disadvantages will be represented.
Read moreSemi-automatic safety analysis and optimization
The complexity of safety-critical E/E-systems within the automotive domain are continuously increasing. At the same time, functional safety standards such as the ISO 26262 prescribe analysis methods like the Fault Tree Analysis (FTA) and Failure Mode and Effects Analysis (FMEA). Currently, these analysis methods are mainly performed manually and are often not consistent with an evolving system model. To tackle these challenges, we present our semi-automatic safety analysis and optimization (SASAO) process. The SASAO process extends model-based safety analysis (MBSA) approaches, which require a system model extended with component-internal error propagation information. By extracting necessary artifacts from such an extended system model, we show how safety experts can be supported when performing FTA and design FMEA that are consistent with the model. The resulting FTA and design FMEA represent mandatory arguments in the system's safety case. Furthermore, we propose a method to optimize the cost of the system with respect to the required safety level automatically.
Read moreComplexity assessment using SysML models
Complexity assessment using SysML models
SysML v2 based modelling guidelines for mechanical system elements
One approach to tackle the complexity in the development of cyber-physical systems is system decomposition and modelling in a central system model with model-based system engineering (MBSE). However, MBSE also requires increased development effort due to the high degree of formalisation of the development results using the Systems Modelling Language (SysML). One solution is reusing system elements from model libraries, which requires formalization that allows them to be networked into consistent models. Due to the abstract nature of SysML, the options for formalizing system elements are extremely diverse, meaning that even identical technical system elements are modelled with a different structure by engineers. As a consequence, no standardized structure is maintained and the reuse of system elements from model libraries is very unlikely. This leads to high, redundant modelling efforts as well as a considerable error potential and significantly hinders the economic application of MBSE in mechanical engineering. A standardized structure of the system elements can be ensured through MBSE methodology specific modelling guidelines. Current modelling guidelines for MBSE are based on the SysMLv1 language standard and cannot be used unchanged in SysML v2. Nevertheless, SysML v2 offers great potential for modelling reusable system elements, especially with its synonymous textual and graphical modelling capabilities, enabling the easy linkage of knowledge from various domain-specific tools. Consequently, modelling guidelines based on SysML v2, which guarantee a standardized structure, are required to fully exploit the potential of model libraries in MBSE. To solve this deficit, this paper presents modelling guidelines based on SysML v2 and their application for building reusable system elements.
Read morePlant modeling based on SysML domain specific language
Successful implementation of Model-based Systems Engineering(MBSE) obviously needs a model supporting efficient communication among engineers of various domains. The system modeling language standard, SysML is designed to create MBSE supporting models. However, SysML itself is not practical enough to be used for real-world engineering projects. As SysML is designed for generic systems and requires specialized knowledge, a model written in SysML has a limited capability to support communication between a systems engineer and a subsystem engineer. Our research's main goal is to develop a SysML based plant model integrating most outputs from plant design phases. As mentioned, a standard SysML based plant model is not specific enough to be understood by plant engineers. To make the SysML model more practical, a customized SysML for the plant engineering domain is required. Unfortunately, current researches on SysML Domain Specific Language(DSL) for the plant engineering industry are still on the early stage. So, as a pilot, we have developed our own SysML-based Piping & Instrumentation Diagram (P&ID) creation environment and P&ID itself for a specific plant system, via widely known SysML modeling tool called MagicDraw. P&ID is one of the most important output during the plant design phase, which contains all information for the plant construction phase. So a SysML based P&ID has a great potential to bridge gaps between plant engineers.
Read moreA Model-Based Safety Analysis Method for Hybrid Systems Based on Multiple Hazard Factor Categories
Safety issues in hybrid systems increasingly result from a combination of multiple categories of hazard factors. However, current hazard analysis methods mainly focus on just one kind of system hazard. This paper presents a model-based safety analysis method for hybrid system that is based on multiple hazard factor categories. Using a Model-Based Safety Analysis framework, the functional model of a hybrid system is first established. Its logic component is modeled using a state diagram and its continuous component is modeled using a transfer function or a state equation. The safety model of the system is then constructed considering a variety of hazard factors. Improper control and logic inconsistency are established for the logic component. Component deviation and logic inconsistency are established for the continuous component. Finally, the safety of the system is then analyzed and the hazard paths are obtained. As an example, the Wheel Brake System for an aircraft is taken to analyze the safety of the aircraft landing phase. By taking into account multiple hazard factor categories, we are able to identify hazard paths that could not be found using a single hazard factor category.
Read moreS171015 安全解析におけるプロセスモデリングの役割([S17101]機械のリスクアセスメントとリスク低減)
Model-based safety design and analysis uses high-fidelity models of processes and process equipment to provide accurate information for decision support in design and risk assessment of safety systems. This helps operating companies and EPCs to minimize capital expenditure while managing risk based on reliable and auditable quantification. It also provides the means to investigate many different failure scenarios within a relatively short timeframe. Until now much safety design and analysis has been done using steady-state or "pseudo-dynamic" trial-and-error modeling, looking at units in isolation, using off-the-shelf models that did not capture process complexity, or attempting to "bend" flowsheeting packages into doing something they were not designed for. It goes without saying that the models used for safety design and analysis need to be of the highest quality: It is essential that models have a high degree of predictive accuracy. This requires first-principles models with rigorous physical properties.
Read more