scieee Science in your language
[en] (orig)

Risk analysis of safety-critical control systems

Abstract

This paper deals with problems associated with risks analysis of a safety-critical control system. In the paper there are introduced recommendations enabling practical enforceability of risk analysis by the assurance of sufficient objectivity level. In the initial phases of the system lifecycle risk analysis serves for a tolerable hazard rate definition for individual safety relevant functions. In the end of the control system development process the risk analysis (an analysis of failures consequences on system safety) serves for the verification of system safety attributes.

Read accessible full text

Risk analysis of safety-critical control systems

Author: Rástočný, Karol
Publisher: Žilinská univerzita v Žiline. Elektrotechnická fakulta
Year: 2008
Source: https://dspace.vsb.cz/bitstreams/060d5a3d-0be2-447e-a00b-74eff236ee8b/download
Risk analysis o sa e y-c i ical con ol sys ems 227
RISK ANALYSIS OF SATETY-CRITICAL CONTROL SYSTEMS
K. Rás oný
Depa men o Con ol and In o ma ion Sys ems, Facul y o Elec ical Enginee ing, Uni e si y o Žilina, Uni e zi ná
8215/1, SK-010 26 Žilina, Slo akia, Phone.: +421 41 513 3320, E-mail: ka ol. as ocny@ el.uniza.sk
Summa y: This pape deals wi h p oblems associa ed wi h isks analysis o a sa e y-c i ical con ol sys em. In he pape
he e a e in oduced ecommenda ions enabling p ac ical en o ceabili y o isk analysis by he assu ance o su icien
objec i i y le el. In he ini ial phases o he sys em li ecycle isk analysis se es o a ole able haza d a e de ini ion o
indi idual sa e y ele an unc ions. In he end o he con ol sys em de elopmen p ocess he isk analysis (an analysis o
ailu es consequences on sys em sa e y) se es o he e i ica ion o sys em sa e y a ibu es.
1. INTRODUCTION
The e is a class o con ol sys ems (so-called
sa e y-c i ical), whose aul y unc ion can esul in
pe sonal inju ies, conside able ma e ial damages,
en i onmen al damages, o o he undesi able a e -
e ec s. Sys em like his has o be ealized in such a
way, ha in he case o a ailu e- ee ope a ion i
mus pe o m exac ly he speci ied unc ions
( unc ional sa e y) and in he case o a ailu e
occu ence i mus ei he emain in a sa e s a e (i he
s a e in which he sys em is ound doesn’ endange
he con olled p ocess), o p oceed o a p ede ined
sa e s a e ( echnical sa e y).
I ’s ob ious, ega d o he knowledge le el,
echnological le el and limi ed inancial esou ces,
ha i is no possible o calcula e on he absolu e
sa e y (ze o isk), bu eally i is necessa y o assume
he occu ence o an e o , o a ailu e in he sys em,
which can lead o a ce ain isk o he con olled
p ocess. P o iding he e idence o sa e y
equi emen s ul ilmen and o a inal isk
accep abili y is possible only on he basis o he
sa e y analysis. I ’s no possible o p o e he s ic
sa e y equi emen s o he sa e y ele an sys em
only by es s o p axis esul s.
Gene ally, sa e y o a sys em can be unde s ood
as a se o sys em p ope ies. A ce ain dependency
exis s be ween hese p ope ies. The goal is o c ea e
a model, which enables o analyze he sensi i i y o
he sys em o pa icula ac o s in luencing i s sa e y
a ibu es and o ind a global op imum wi h he
espec o hese a ibu es, assuming an economical
accep abili y o he p oposed solu ion.
Accomplishmen o his goal is ela ed o he
p oblems sol ing in he ollowing a eas:

Risk analysis;

Modelling o sys em RAMS pa ame e s.
The undamen al in e na ional s anda d dealing
wi h sa e y-c i ical con ol sys ems is he s anda d
[12]. On he base o his s anda d some o he
applica ion s anda ds a e de i ed, among hem o
example s anda ds o ailway applica ions [9], [10],
[11] o indus ial applica ions [13]. Depending upon
equi emen s on sys em sa e y hese s anda ds de ine
4 sa e y in eg i y le els and o e e y sa e y in eg i y
le el (SIL) p ac ices a e ecommended, ha ha e o
be pe o med in indi idual li e-cycle phases o he
sys em in o de o achie e he abili y o he sys em o
ul il equi ed unc ions in ega d o he Reliabili y,
A ailabili y, Main ainabili y, Sa e y (RAMS
pa ame e s) and hei mu ual e ec s.
These s anda ds de ine common sa e y a ge s,
ecommend p ac ices o achie ing he equi ed
sa e y in eg i y le el and me hods o i s e alua ion,
howe e de ini ion o objec i es is ambiguous and
me hodical di ec i es o he sa e y e alua ion a e
a he gene al. Nega i e in luence also esul s om
he ac , ha a gene ally accep able heo e ical
appa a us o a isk analysis and sa e y le el
e alua ion is missing, which would objec i y he
whole p ocess o sa e y conside a ion. The e o e a
g ea a en ion is paid o his p oblem in in e na ional
discussion o ums (e.g. h p://www.sipi61508.com),
open specialised conso ia (e.g.
h p://www. ailwaydomain.o g,
h p://www. meu ope.o g), p ojec s (e.g.
h p://samne .in e s. ) and con e ences (e.g.
h p://www. o ms- o ma .ne ). I is pleasan , ha by
issuing o hese s anda ds he s anda diza ion p ocess
in sa e y c i ical con ol sys ems a ea is no inishing
bu o e shoo ing he p epa a ion o new s anda ds
and e ision o al eady accep ed s anda ds.
Nowadays used o de eloped p ac ises o sa e y
a ibu es e alua ion may be basically di ided in wo
g oups:

C ea ion o he model, ha p o ides he complex
desc ip ion o ailu e consequences on unc ional
and echnical sa e y; such a model could be usable
o he isk analysis, speci ica ion o he
unc ional equi emen s and e i ica ion o sa e y
a ibu es o he sys em; on he basis o Pe i ne s
such a model is de eloped wi hin he p ojec
Thomason [6], [8];

Using he combina ion o me hods; special
me hods and models a e used o he isk analysis
(haza d g aph, isk ma ix, BP- isk, ..), o he o
speci ica ion and modelling o unc ional
p ope ies o he sys em (UML, ini e au oma on,
Z-language, Pe i ne s, …), and ano he o
modelling o RAMS pa ame e s o he sys em
(FMEA, FTA, Ma ko chains, Pe i ne s, ..) [3],
[4], [7].
228 Ad ances in Elec ical and Elec onic Enginee ing
2. MODELLING OF RAMS PARAMETERS
OF THE CONTROL SYSTEM
Since pa icula RAMS pa ame e s in luence
each o he , i is necessa y o p opose such a solu ion,
which enables complex modelling o RAMS
pa ame e s. When modelling RAMS pa ame e s, he
ac o s a ec ing hem mus be espec ed, especially:

Deg ee o edundancy applied in he sys em;

Reliabili y o sys em componen s;

Diagnos ic co e age, aul de ec ion-and-nega ion
ime;

Reco e y o a ailabili y o he sys em a e
ailu e.
In he case o complex RAMS pa ame e s
analysis he s ochas ic p ocess is conce ned o
whose modelling o example Ma ko chains o Time
Pe i Ne s can be success ully used. Howe e ,
Ma ko chains ha e hei limi s. Thei main
disad an age is ha du ing modelling cons an
ansi ion in ensi ies a e supposed (homogenous
Ma ko chain). Tha means, ha occu ence o
e en s, which in luence ansi ions be ween s a es,
mus be app oxima ed by he exponen ial dis ibu ion,
ha mus n’ always co espond o eali y. Though
non-homogenous Ma ko chains can be heo e ically
conside ed, bu he solu ion is a he complica ed.
E en hough in he case o RAMS pa ame e s
analysis o he sys em, he Ma ko models ha e
speci ic cons ain s, hey a e gene ally accep ed.
Basically, c ea ion o such a Ma ko model may
p oceed in wo ways:

Logical conside a ion based on analys ’s expe
app oach; his way ends o analys ’s mis akes and
he e o e has limi a ions in espec o sys em’s
s a es quan i y; nowadays i is a u ilised me hod
o diag ams c ea ion;

Au oma ic gene a ion; au oma ic compu e model
gene a ion leads o models wi h la ge numbe o
s a es; his me hod equi es he u ilisa ion o
quali y compu e equipmen and speci ic so wa e
ools, which enable s a es numbe educ ion and
selec ion o an app op ia e nume ical me hod so
ha esul s can be ob ained in eal ime wi h he
su icien p ecision; his p ac ice is sui able o
he analysis o sys em eliabili y a ibu es, bu i
is no used o he analysis o RAMS pa ame e s.
Nowadays he p ojec [5] is submi ed; whose
one o he goals is achie ing an au oma ic gene a ion
o ansi ion in ensi ies ma ix ei he in a uni e sal
way, o a leas o some speci ic cases. Solu ion
based on an a omisa ion o he sys em and a
combina ion o di e en quan i a i e me hods comes
in o accoun . Sa e y a ibu es on sys em’s
componen s le el would be modelled using one
me hod and bonds be ween componen s would be
modelled using ano he me hod.
Analysis o s ochas ic models can be ealised in
se e al ways. They di e in he esul s p ecision,
applica ion op ions and compu ing demands. The
ollowing app oaches a e supposed:

Simula ion;

Nume ical solu ion;

Analy ical solu ion.
The use o an analy ical solu ion in combina ion
wi h he nume ical solu ions suppo ed by an
app op ia e so wa e ool seems o be he mos
sui able.
3. PROCESS OF THE RISK ANALYSIS OF
THE CONTROL SYSTEM
De elopmen o he sa e y-c i ical con ol sys em
mus be based on speci ica ion o he sa e y
equi emen s, which a e de ined on he base o isk
analysis associa ed wi h a con olled p ocess. SIL o
he sys em is p opo ional o a di e ence be ween
calcula ed o es ima ed isk and accep able isk.
Nowadays he e is no gene ally accep ed uni ied
me hod o isk analysis. The e a e numbe s o
me hods and p ocedu es o isk analysis (depending
on an applica ion a ea), which a e usually based on a
subjec i e e alua ion o “sensi i i y” o isk ac o s,
wha esul s in he ac , ha di e en collec i es o
analys s may ob ain signi ican ly di e en esul s,
e en when using he same me hod. This p oblem
comes in o spo ligh especially when mal unc ion o
he con ol sys em can lead o human casual ies
(p oblem o an accep able isk). P ocess o he isk
analysis can be objec i ied only on he base o
quan i a i e me hods, which lean on he heo e ical
conside a ions and acciden -e en s s a is ical da a.
Risk analysis (e en analysis o ailu e
consequences on con ol sys em sa e y) can be
ealised using quan i a i e o quali a i e me hods, bu
mo e equen ly by he combina ion o hese me hods
[7]. Quali a i e me hods help o unde s and
consequences o di e en ailu es o sys em
componen s on he en i e sys em and a logical
s uc u e o hei mu ual ela ions. Quan i a i e
me hods u ilise a ailable da a abou componen
ailu es, human mis akes, epai imes, and so on and
enable o de e mine he p obabili y o a ce ain
sys em’s c i ical s a e occu ence [1].
Gene ally isk can be o mula ed as a
combina ion o haza ds a e and hei consequences
o a ce ain ime uni . The e o e in he p ocess o
isk analysis i is necessa y o de ine sys em’s
incidence bounda ies, iden i y haza ds, de e mine
in ensi ies o hei occu ence, e alua e damages
caused by indi idual haza ds, and e alua e he
o e all isk associa ed wi h a con olled p ocess.
Based on knowledge o he o e all isk and
accep able isk ole able haza d a e (THR) can be
de i ed and consequen ly SIL can be assigned o
unc ions and componen s o he sys em.
Haza ds iden i ica ion is an impo an momen o
he isk analysis ( o c ea e a haza d lis ). Haza d lis
may be c ea ed on he base o heo e ical
conside a ion and analyses o on he base o p esen
expe iences in an analogical sys em ope a ion and
s a is ical en ies, bu mo e o en by p ope
Risk analysis o sa e y-c i ical con ol sys ems 229
combina ion o hese wo possibili ies. Wha is
necessa y o conside being haza d depends on
sys em analysis le el. Risk analysis esul is no
dependen on quan i y o he haza ds iden i ica ion bu
he eon how he en i e a ea o he haza dous s a es is
co e ed. Indi idual haza ds ha e o be independen
o each o he . I is desi able, i he haza d lis copies
lis o sa e y ele an sys em unc ions (Fig. 1). Fo
ins ance, i unc ion F
1
s a es claim on pe o mance o
ce ain ope a ion, hen he haza d H
1
s a es aul y
pe o mance o his ope a ion. This kind o he
app oach o haza ds iden i ica ion and o c ea ion o
bonds among haza ds conside ably simpli ies he
sa e y equi emen de ini ion p ocess o indi idual
modules o he con ol sys em. De ini ion o haza d
a e is qui e p oblema ic and gene ally has o be
accomplished on he base o he expe es ima ion
(solu ion like his conside ably impac s objec i i y o
quan i a i e analysis). The de e mina ion o haza d
a e is inaccu a e on he basis o s a is ical da a abou
acciden s, since no e e y haza d esul s in acciden .
F
21
F
22
F
23
F
2
F
3
F
1
F
H
21
H
22
H
23
H
2
H
3
H
1
H
Fig.1 Rela ion be ween unc ions ee and haza ds
ee Iden i ica ion o he indi idual haza d esul s may
be se on he basis o he p ac ical expe iences
(s a is ical da a) in he con ol p ocess o on he
expe es ima ions (mainly when he e a e p ocesses
wi hou p ac ical expe iences). P oblems a e up ising
i haza d may cause no only ma e ial damages bu
also human casual ies.
Quan i a i e isk analysis equi es ma e ial
damages and human casual ies ans e o a common
uni (how o quali y human heal h?). In his case he
ollowing possibili ies come in o accoun :

Ma e ial damages neglec , i haza d can esul in a
se ious human heal h ha m;

Risk calcula ion pa icula ly o ma e ial damages
and pa icula ly o human casual ies.
By quali a i e isk analysis simul aneously
ma e ial damages and human casual ies can be
conside ed.
Consume s a es ange o accep able isks in he
case o ma e ial damages. Conce ning human
casual ies he legal eques s mus be espec ed, which
issue ei he om collec i e isk ( o example
GAMAB c i e ia) o om indi idual isk ( o
example MEM o ALARP c i e ia) [9]. In he
p ac ical li e such an app oach can be me when
design o a new sys em esul s om s a is ical da a
ela ed o an old (exis ing) sys em. The p oblem is
ha he se o he new and he old sys em unc ions
ha e no o be iden ical on each o he ( o example i
a new sys em con ains a new unc ion, necessa y
s a is ical da a does no exis ).
4. IMPLEMENTATION OF SAFETY
REQUIREMENTS
Resul o isk analysis is de ini ion o THR o
he indi idual sa e y ele an unc ions (F
1
, F
2
, ... F
m
).
I is necessa y o ealise he decomposi ion o he
con ol sys em o indi idual modules (M
1
, M
2
, ... M
n
)
and hese consequen ly iden i y wi h he ealised
unc ions. Ne e heless, one module can ealise mo e
unc ions o one unc ion is ealised by mo e modules
(Fig. 2). Decomposi ion ha e o be ealised in such a
way, in o de o modules could be independen on
each o he .
F
1
F
2
F
3
M
1
M
2
M
3
M
4
RS
Se o
unc ions
RS
Se o
unc ions
THR
RS
THR
unc ions
Fig. 2 Func ion assignmen o sys em modules
Resul o isk analysis is de ini ion o THR o
he indi idual sa e y ele an unc ions (F
1
, F
2
, ... F
m
).
I is necessa y o ealise he decomposi ion o he
con ol sys em o indi idual modules (M
1
, M
2
, ... M
n
)
and hese consequen ly iden i y wi h he ealised
unc ions. Ne e heless, one module can ealise mo e
unc ions o one unc ion is ealised by mo e modules
(Fig. 2). Decomposi ion ha e o be ealised in such a
way, in o de o modules could be independen on
each o he .
I he i- h unc ion is ealised only by he j- h
module hen holds:
FM
THRTHR ≤
, (1)
whe e
F
THR
is a ole able haza d a e o gi en
unc ion and
M
THR
is a ole able haza d a e o
he gi en module.
I he unc ion is ealised by se e al modules (n
modules), hen holds:
MnMMF
THRTHR
∩∩∩
≥
....21
, (2)
whe e
Mn....M
THR
∩∩1
is an en i e ole able haza d
a e o modules 1 o n conside ing ealised unc ion.
I he module ealises se e al unc ions (n
unc ions) hen holds:
FmFFM
THRTHR
∩∩∩
≤
....21
, (3)
230 Ad ances in Elec ical and Elec onic Enginee ing
whe e
Fm...F
THR
∩∩1
is an en i e ole able haza d
a e o unc ions 1 o m conside ing he module, ha
ealises hem.
I he module ealises no sa e y ele an unc ion,
hen no sa e y equi emen s a e laid on i .
In connec ion wi h he dissemina ion o THR on
indi idual pa s o he sys em ques ion o sys em
s uc u e is also necessa y o be sol ed.
Selec ion o a sys em s uc u e is one o he mos
impo an decisions du ing he de elopmen p ocess.
By choice o he s uc u e i is necessa y o p og ess
e y ca e ully, because a comp omise be ween cos ,
SIL and a ailabili y o he sys em is conce ned. The
selec ion o he s uc u e has o be done based on he
esul s o RAMS pa ame e s modelling. C ea ed
model enables choosing he mos sui able solu ion so
ha cus ome ’s equi emen s on he indi idual RAMS
pa ame e s o he sys em will be espec ed. A model
c ea ed in ea ly phases o li ecycle can be
p og essi ely e ined and u ilised o he esul s
e i ica ion ob ained in pa icula phases o he
de elopmen p ocess.
5. CONCLUSION
Risk analysis has o be ealised se e al imes
(wi h di e en dep h) du ing he sys em de elopmen .
In he ini ial sys em de elopmen phase i se es o a
de ini ion o ole able haza d a es o he sys em o
i s indi idual pa s. In o he sys em de elopmen
phases i se es o he con ol whe he eal alues o
he haza d a e o he sys em o i s indi idual pa s
a e accep able.
In p ac ical li e we also o en mee wi h demand
o imp o ing quali y o se ices ha ha e al eady
been p o ided by an exis ing sa e y- ela ed sys em
( o example change o an exis ing unc ion o
implemen a ion o a new unc ion). To accep his
demand means o implemen a new module (ha dwa e
and/o so wa e) in o he sys em. Accep able isk
esul ing om p ocess con ol usually does no a y
(is no inc eased) e en hough a new unc ion has
been implemen ed. On he con a y, implemen a ion
o a new unc ion can cause inc ease o isk esul ing
om ope a ion o a modi ied sys em. Howe e ,
adding a new module (sys em) canno b ing inc ease
o isk o he con olled p ocess abo e he accep able
le el. The e o e i is necessa y o de ine no only
unc ional bu also sa e y equi emen s o his kind o
module.
This wo k has been suppo ed by he scien i ic g an
agency VEGA, g an No. VEGA-1/0040/08
“Ma hema ic-g aphical modelling o sa e y
a ibu es o sa e y-c i ical con ol sys ems”.
REFERENCES
[1] BRADLEY, J.: Elimina ion o Risk in Sys ems.
Tha sis Books, 2002
[2] RÁSTONÝ, K. – JANOTA, A. -
ZAHRADNÍK, J.: The Use o De elopmen o
a Railway In e locking Sys em. In Jou nal:
Lec u e No es in Compu e Science, Sp inge -
Ve lag Heidelbe g, 2004, pages 174-198,
ISSN 0302-9743
[3] RÁSTONÝ, K.: Model o sa e y analysis o
he in e locking sys em. In e na ional scien i ic
con e ence ELEKTRO ′99, 25 – 26 May 1999,
Žilina, pp.13 – 18, ISBN 80-7100-602-5
[4] RÁSTONÝ, K.: Risk Analysis o a Railway
In e locking Sys em. In: AEEE, No. 3 – 4 Vol.
2/2003, ŽU Žiline, pp. 24 -29, ISSN 1336-
1376 (in Slo ak)
[5] RÁSTONÝ, K.: Ma hema ic-g aphical
modelling o sa e y a ibu es o sa e y-c i ical
con ol sys ems. P ojec VEGA, No. 1/0040/08
[6] SLOVAK, R. e al.: Toolun e s ü z e
Modellie ung, Analyse und Syn hese
siche hei s ele an e S eue ungen ü den
Einsenbahn e keh mi Pe ine z echnologie.
P ojec Tomasen. TU B aunschweig
[7] ZAHRADNÍK, J. – RÁSTONÝ, K. –
KUNHART, M.: Sa e y o Railway
In e locking Sys ems. EDIS, 2004, ISBN 80-
8070-296-9 (in Slo ak)
[8] ZAHRADNÍK, J. e al.: Tool-suppo ed
modelling, analysis and syn hesis o ailway
sa e y sys ems by Pe i ne s echnologies.
P ojec No. 03 Cos 04 24/604, ŽU Žiline
[9] EN 50126: Railway applica ions: The
speci ica ion and demons a ion o
dependabili y, eliabili y, a ailabili y,
main ainabili y and sa e y (RAMS)
[10] EN 50128: Railway applica ions:
Communica ions, signalling and p ocessing
sys ems - So wa e o ailway con ol and
p o ec ion sys ems
[11] EN 50129: Railway applica ions: Sa e y
ela ed elec onic sys ems
[12] EN 61508: Func ional sa e y o elec ical
/elec onic/p og ammable elec onic sa e y-
ela ed sys ems
[13] EN 61511 Func ional Sa e y. Sa e y
Ins umen ed Sys ems o he P ocess Indus y
Sec o