...
首页> 外文期刊>IFAC PapersOnLine >Maintaining safety requirements of updated maritime surveillance systems ?
【24h】

Maintaining safety requirements of updated maritime surveillance systems ?

机译:保持更新的海上监控系统的安全要求

获取原文
           

摘要

The maritime domain is undergoing a transformation away from manual control and navigation towards automated and autonomous vessels controlled by a dedicated software system. These systems are composed out of interdependent and heterogeneous modules, that together form a System of Systems (SoS). Unlike before, these software-based modules allow their functionality to be monitored continuously and changes to be made remotely while in operation. However, adjustments made to devices that have already been approved can cause the existing certification to lose its validity and previously made safety properties may no longer apply. This poses a particular danger when the system is driving autonomously or a navigator is relying on it to function and is unaware of a failure and cannot take alternative action. Especially in case of new functionality being added through adaptive updates, unforeseen errors can occur that were not apparent beforehand. For this reason, a procedure based on assumption-guarantee contracts is presented to verify the impact on the safety properties of a system after an update and outline the required changes to the associated safety case. For this purpose, a safety case based on the Goal Structuring Notation (GSN) is made, whose tree structure has modular properties, so that the effects on the safety behavior can be tracked on a small scale and only partial branches have to be replaced or updated. Moreover, it is shown how a safety case augmented with contracts can meet its safety goals even when the system needs to revert to the state before the update while keeping the vessel operator informed. The concept is demonstrated by extending the functionality of a maritime collision avoidance system by a predictive resolution module and show how in situations missing a valid prediction, the system can still meet its overarching safety goal.
机译:海上域正在远离手动控制和导航到由专用软件系统控制的自动化和自治血管的转换。这些系统由相互依赖和异构模块组成,它们一起形成系统系统(SOS)。与之前,这些基于软件的模块允许连续监视其功能,并在操作中远程进行更改。但是,对已经批准的设备所做的调整可能导致现有的认证失去其有效性,并可能不再适用安全性。当系统自主行驶时或导航器依赖于它来运行并且不知道失败并且无法采取替代动作时,这会带来特殊的危险。特别是在通过自适应更新中添加新功能的情况下,可能会发生不可预见的错误,以前不明显。因此,提出了一种基于假设保证合同的程序,以验证更新后对系统的安全性质的影响,并概述相关的安全案件所需的更改。为此目的,制造基于目标结构符号(GSN)的安全壳,其树结构具有模块化属性,从而可以在小规模上跟踪对安全行为的影响,并且仅需要替换部分分支或更新。此外,它表明如何为合同增强的安全案例如何满足其安全目标,即使系统需要在更新之前恢复到状态,同时保持船舶运算符通知。通过预测分辨率模块扩展海上碰撞避免系统的功能来证明该概念,并显示在缺少有效预测的情况下,系统仍然符合其总体安全目标。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号