【24h】

Model-Driven Development of Safety Architectures

机译:安全架构的模型驱动开发

获取原文

摘要

We describe the use of model-driven development for safety assurance of a pioneering NASA flight operation involving a fleet of small unmanned aircraft systems (sUAS) flying beyond visual line of sight. The central idea is to develop a safety architecture that provides the basis for risk assessment and visualization within a safety case, the formal justification of acceptable safety required by the aviation regulatory authority. A safety architecture is composed from a collection of bow tie diagrams (BTDs), a practical approach to manage safety risk by linking the identified hazards to the appropriate mitigation measures. The safety justification for a given unmanned aircraft system (UAS) operation can have many related BTDs. In practice, however, each BTD is independently developed, which poses challenges with respect to incremental development, maintaining consistency across different safety artifacts when changes occur, and in extracting and presenting stakeholder specific information relevant for decision making. We show how a safety architecture reconciles the various BTDs of a system, and, collectively, provide an overarching picture of system safety, by considering them as views of a unified model. We also show how it enables model-driven development of BTDs, replete with validations, transformations, and a range of views. Our approach, which we have implemented in our toolset, AdvoCATE, is illustrated with a running example drawn from a real UAS safety case. The models and some of the innovations described here were instrumental in successfully obtaining regulatory flight approval.
机译:我们描述了使用模型驱动的开发来确保NASA的开创性飞行操作的安全性,该飞行操作涉及由小型无人飞机系统(sUAS)组成的机队,其飞行范围超出了视线。中心思想是开发一种安全体系结构,为安全案例内的风险评估和可视化提供基础,这是航空监管机构要求的可接受的安全性的正式理由。安全体系结构由领结图(BTD)集合组成,这是一种通过将已识别的危害与适当的缓解措施联系在一起来管理安全风险的实用方法。给定无人机系统(UAS)操作的安全理由可能有许多相关的BTD。然而,实际上,每个BTD都是独立开发的,这对以下方面提出了挑战:进行增量开发,在发生更改时保持不同安全工件之间的一致性,以及提取和呈现与决策者相关的利益相关者特定信息。我们将展示安全架构如何协调系统的各种BTD,并通过将它们视为统一模型的视图来共同提供系统安全的总体情况。我们还将展示它如何支持BTD的模型驱动开发,以及大量的验证,转换和各种视图。我们的方法已在我们的工具集AdvoCATE中实现,并通过一个真实的UAS安全案例得出的运行示例进行了说明。这里描述的模型和一些创新对成功获得监管飞行批准至关重要。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号