This paper appropriately describes the safety dynamics of switching control systems under the assumption of the most realistic and popular failure mode of a switching unit, “locking,” by introducing a new idea of situation-dependent basic events in dynamic fault trees to point out possible non-coherence in the safety dynamics for the first time. In order to properly address the possible non-coherence, this paper also presents a safety analysis framework based on Markov analysis.
展开▼