System for safety analysis and fault injection verification for system and software
The safety analysis and fault injection verification system automates the generation and combination of safety analysis information, reduces manual effort, and enhances the reliability of systems and software by streamlining the safety analysis and verification processes.
Patent Information
- Application Number
- PCT/KR2023/020175
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-12-01
- Filing Date
- 2023-12-08
- Publication Date
- 2025-06-05
AI Technical Summary
Current safety analysis techniques for systems and software, such as FMEA, FTA, and STPA, are typically performed manually by experts, requiring significant time and effort, and lack automation for quick and efficient analysis and verification.
A safety analysis and fault injection verification system that automatically generates and inputs information for safety analysis, combines various safety analysis technologies for automated analysis, generates verification test cases based on analysis results, and reduces the time and effort required for safety analysis and verification.
The system significantly reduces the time and effort needed for safety analysis and verification, minimizes errors in systems and software, and enables the development of highly safe and reliable systems and software by automating the analysis and test case generation processes.
Smart Images

Figure KR2023020175_05062025_PF_FP_ABST
Abstract
Description
Safety analysis and fault injection verification system for systems and software
[0001] The present invention relates to a safety analysis and fault injection verification system, and more particularly, to a safety analysis and fault injection verification system for systems and software that enables the development of highly safe and reliable systems and software through safety analysis and verification of systems and software during the development stage.
[0002] Today, industries such as electronics, communications equipment, automotive, aviation, and medical are experiencing a surge in the development of electronic control devices and software, driven by the Fourth Industrial Revolution. This growth in complexity is also driving the development of electronic control devices and software. In particular, systems and software installed in automotive, nuclear power, and aviation systems require high stability and reliability.
[0003] Meanwhile, in order to develop systems and software with high safety and reliability, safety analysis and verification of systems and software are required during the development stage.
[0004] However, safety analysis techniques such as failure mode and effects analysis (FMEA), fault tree analysis (FTA), and system theoretic process analysis (STPA) are each applied individually. Furthermore, verification of safety analysis results is performed. Safety analysis and verification are currently conducted by experts. This requires significant time and effort. Therefore, there is a need to develop technologies that enable rapid and easy safety analysis and verification of systems and software.
[0005] The technical task to be achieved by the safety analysis and fault injection verification system according to the technical idea of the present invention is to provide a safety analysis and fault injection verification system in which information for safety analysis can be automatically generated and input.
[0006] In addition, a technical task to be achieved by the safety analysis and fault injection verification system according to the technical idea of the present invention is to provide a safety analysis and fault injection verification system that can automatically perform safety analysis by combining various safety analysis technologies.
[0007] In addition, a technical task to be achieved by the safety analysis and fault injection verification system according to the technical idea of the present invention is to provide a safety analysis and fault injection verification system capable of automatically generating a verification test case according to the results of safety analysis.
[0008] In addition, the technical task to be achieved by the safety analysis and fault injection verification system according to the technical idea of the present invention is to provide a safety analysis and fault injection verification system that can significantly reduce the time and effort required for safety analysis and verification.
[0009] In addition, the technical task to be achieved by the safety analysis and fault injection verification system according to the technical idea of the present invention is to provide a safety analysis and fault injection verification system that enables the development of systems and software with high safety and reliability by significantly reducing errors in systems and software.
[0010] The technical tasks to be achieved by the safety analysis and fault injection verification system according to the technical idea of the present invention are not limited to the tasks mentioned above, and other tasks not mentioned will be clearly understood by those skilled in the art from the description below.
[0011] A safety analysis and fault injection verification system according to one embodiment of the technical idea of the present invention is characterized by including a data processing unit that receives development data from a user terminal and generates analysis information; a safety analysis unit that analyzes the analysis information based on analysis performance information to generate analysis result information and generates safety measure information according to the analysis result information; and a verification information unit that combines the analysis information and the analysis result information to generate a verification test case.
[0012] Additionally, development data may include development requirements and design models.
[0013] In addition, the safety analysis department stores multiple analysis performance information, and the analysis performance information may include analysis elements according to FMEA (Failure Mode and Effects Analysis), analysis elements according to FTA (Fault Tree Analysis), and analysis elements according to STPA (System Theoretic Process Analysis).
[0014] Additionally, the safety analysis unit can analyze analysis information by combining multiple analysis execution information.
[0015] Additionally, the safety analysis unit may utilize machine learning frameworks using at least one of the following: Open Source Neural Network Libraries, End-To-End Open Source Machine Learning Platform, Keras, and Tensorflow.
[0016] Additionally, verification test cases can be implemented in the form of white box testing.
[0017] Additionally, the verification information unit can generate defect information by combining analysis result information and safety measure information, and can generate verification test cases by combining defect information with analysis information and analysis result information.
[0018] Additionally, verification test cases can be in the form of white box testing or black box testing.
[0019] In addition, the safety analysis and fault injection verification system may further include a verification communication unit that transmits a verification test case to a user terminal and receives verification data for the verification test case from the user terminal.
[0020] In addition, the safety analysis and defect injection verification system further includes a guidance device that is registered to correspond to a user terminal and is worn on a user's hand to generate guidance information and transmit it to a data processing unit, wherein the data processing unit stores the guidance information transmitted from the guidance device and receives new guidance information from the guidance device, and when the guidance information already stored in the data processing unit matches the new guidance information transmitted from the guidance device to the data processing unit, the user terminal corresponding to the guidance device that transmitted the guidance information transmits the inputted development data to the data processing unit, and the guidance device includes a first body including a band-shaped wearable that surrounds and is fixed to a user's wrist area, a plurality of auxiliary wearables each having a thimble shape into which a part of the user's finger can be inserted, a plurality of connecting wires each having a wire shape, a first end portion connected to the auxiliary wearable and a second end portion opposite to the first end portion inserted and positioned in the wearable, and a plurality of connecting winders each connected to the second end portion of the connecting wire and positioned rotatably inside the wearable, the first body providing a force to the connecting wire for winding the connecting wire;And a flat plate-shaped base, each having a square pillar shape and having an insertion space concavely formed on the upper surface, a plurality of housings positioned on the upper surface of the base, a first guide formed in the shape of a rack gear and positioned along the vertical direction on the inner surface of the insertion space, a contact plate formed in the shape of a plate corresponding to the cross-section of the insertion space and positioned inside the insertion space so as to be parallel to the upper surface of the insertion space at the top of the first guide, a second guide formed in the shape of a pinion gear and positioned inside the insertion space so as to engage with the first guide, and a second body including a handle that penetrates the housing and is connected to the center of the second guide to rotate the second guide, when the second guide is rotated in one direction by the handle, the first guide is moved to move the contact plate upward or downward, the user wears the first body of the guide device on the hand part and inserts the user's finger into the insertion space to make the auxiliary wearable contact the contact plate, and the bent state of the user's finger is constantly maintained for a predetermined time and the rotation of the connecting winder When the angle is maintained constant, the wearer can generate guidance information by combining the rotation angles of the connected winders and transmit it to the data processing unit.;
[0021] The safety analysis and fault injection verification system according to embodiments of the technical idea of the present invention has the following effects.
[0022] (1) Information for safety analysis can be automatically generated and entered.
[0023] (2) Safety analysis can be automatically performed by combining various safety analysis technologies.
[0024] (3) Test cases for verification can be automatically generated based on the results of safety analysis.
[0025] (4) The time and effort required for safety analysis and verification can be significantly reduced.
[0026] (5) It enables the development of systems and software with high safety and reliability by significantly reducing errors in systems and software.
[0027] However, the effects that can be achieved by the safety analysis and fault injection verification system according to one embodiment of the present invention are not limited to those mentioned above, and other effects not mentioned will be clearly understood by those skilled in the art from the description below.
[0028] To facilitate a more thorough understanding of the drawings cited herein, a brief description of each drawing is provided.
[0029] FIG. 1 is a diagram illustrating a safety analysis and fault injection verification system according to one embodiment of the present invention.
[0030] FIG. 2 is an implementation flowchart of a safety analysis and fault injection verification system according to one embodiment of the present invention.
[0031] FIG. 3 is a diagram illustrating the operation flow of a safety analysis and fault injection verification system according to one embodiment of the present invention.
[0032] FIG. 4 is a perspective view illustrating a guide device connected to a safety analysis and fault injection verification system according to one embodiment of the present invention.
[0033] The present invention is susceptible to various modifications and embodiments. Specific embodiments are illustrated in the drawings and described in detail. However, this is not intended to limit the invention to specific implementations, and it should be understood that the invention encompasses all modifications, equivalents, and alternatives falling within the spirit and technical scope of the invention.
[0034] In describing the present invention, detailed descriptions of related known technologies will be omitted if they are deemed to unnecessarily obscure the gist of the present invention. Furthermore, numbers (e.g., "first," "second," etc.) used throughout the description of this specification are merely identifiers used to distinguish one component from another.
[0035] Additionally, in this specification, when a component is referred to as being “connected” or “connected” to another component, it should be understood that the component may be directly connected or connected to the other component, but may also be connected or connected via another component in between, unless there is a specific description to the contrary.
[0036] In addition, the components expressed as "~part" in this specification may be two or more components combined into one component, or one component may be divided into two or more components with more detailed functions. In addition, each component described below may additionally perform some or all of the functions performed by other components in addition to its own main function, and of course, some of the main functions performed by each component may be exclusively performed by other components.
[0037] Hereinafter, embodiments according to the technical idea of the present invention will be described in detail one by one.
[0038] FIG. 1 is a diagram illustrating a safety analysis and fault injection verification system (100) according to one embodiment of the present invention, FIG. 2 is an implementation flowchart of a safety analysis and fault injection verification system (100) according to one embodiment of the present invention, and FIG. 3 is a diagram illustrating an operation flow of a safety analysis and fault injection verification system (100) according to one embodiment of the present invention.
[0039] As illustrated in FIGS. 1 to 3, a safety analysis and fault injection verification system (100) according to one embodiment of the present invention may be connected to a user terminal (10) via a network (1), and may include a data processing unit (101), a safety analysis unit (102), a verification information unit (103), and a verification communication unit (104). Here, the user may refer to a person in charge of safety analysis and verification for the system and software, and although this embodiment is illustrated as consisting of one person, it may be divided into a safety analysis manager and a verification manager, and may be composed of two people.
[0040] Additionally, the data processing unit (101), safety analysis unit (102), verification information unit (103), and verification communication unit (104) may include at least one of a processor, a memory, and a data transceiver.
[0041] A user can access the safety analysis and fault injection verification system (100) using a user terminal (10) and exchange signals with the safety analysis and fault injection verification system (100). The safety analysis and fault injection verification system (100) can display a web page through a web browser operated on the user terminal (10) and allow the user to log in to the web page and then access the safety analysis and fault injection verification system (100). Alternatively, an application capable of accessing the safety analysis and fault injection verification system (100) can be installed and operated on the user terminal (10).
[0042] The user terminal (10) may be implemented as a computer capable of connecting to a remote server or terminal via a network (1). Here, the computer may include, for example, a notebook, desktop, or laptop equipped with a web browser. In addition, the user terminal (10) may be implemented as a terminal device capable of connecting to a remote server or terminal via the network (1). The terminal device may include all types of handheld-based wireless communication devices such as, for example, a wireless communication device that guarantees portability and mobility, such as a PCS (Personal Communication System), GSM (Global System for Mobile communications), PDC (Personal Digital Cellular), PHS (Personal Handyphone System), PDA (Personal Digital Assistant), IMT (International Mobile Telecommunication)-2000, CDMA (Code Division Multiple Access)-2000, W-CDMA (W-Code Division Multiple Access), Wibro (Wireless Broadband Internet) terminal, smartphone, smartpad, tablet PC, etc.
[0043] Here, the network (1) refers to a connection structure that enables information exchange between each node, such as multiple terminals and servers, and examples of such networks include, but are not limited to, a 3GPP (3rd Generation Partnership Project) network, an LTE (Long Term Evolution) network, a 5G network, a WIMAX (World Interoperability for Microwave Access) network, the Internet, a LAN (Local Area Network), a Wireless LAN (Wireless Local Area Network), a WAN (Wide Area Network), a PAN (Personal Area Network), a Bluetooth network, a satellite broadcasting network, an analog broadcasting network, and a DMB (Digital Multimedia Broadcasting) network.
[0044] The data processing unit (101) may receive development data from the user terminal (10) (S101). Here, the development data may refer to information created for the development of a system and software, and may include development requirements, design models, etc. In addition, the development requirements may include contents to be applied to the system and software, matters to be considered or noted when developing the system and software, etc., and the design model may model the structure, functions, etc. of the system and software, and may include contents corresponding to the modeling.
[0045] A user can input development data into a user terminal (10), and the user terminal (10) can transmit the development data input by the user to a data processing unit (101).
[0046] Additionally, the data processing unit (101) can generate the received development data into analysis information (S102). Here, the analysis information may refer to the development data processed into a form usable by the safety analysis unit (102), which will be specifically described below, and may include, for example, data selecting portions necessary for safety analysis from the development data.
[0047] The safety analysis unit (102) can analyze the analysis information based on the analysis performance information and generate analysis result information (S103). Here, the analysis performance information can include analysis elements according to the safety analysis technique for analyzing the analysis information, and for example, can include analysis elements according to FMEA (Failure Mode and Effects Analysis), analysis elements according to FTA (Fault Tree Analysis), analysis elements according to STPA (System Theoretic Process Analysis), etc. The safety analysis unit (102) can store multiple analysis performance information.
[0048] FMEA refers to a technique for analyzing the system impact when a failure occurs and deriving the devices or components that have a large impact, and it can include analysis elements according to the basic FMEA workflow engine, domain-specific analysis worksheet, user-defined analysis fields, and domain-specific report forms to support safety analysis techniques in various industries such as automobiles, nuclear power, and railways. In addition, FTA refers to a quantitative safety assessment technique that deductively derives and predicts the causes of disasters and system failures, and can include analysis elements according to fault tree structure generation and structural analysis, failure countermeasure management, probability calculation based on binary decision diagram (BDD: Binary Decision Diagram) (failure probability calculation by reconstructing the FTA structure into a binary decision diagram), cut set grouping, bidirectional search, and multi-process-based failure probability parallel processing (failure probability parallel processing using multiple processes for each failure path). In addition, STPA refers to a technique for analyzing potential risks and causes of occurrence that exist throughout the entire system life cycle at a high level of the system, and includes the stages of defining accident and system-level hazards, creating a system control structure diagram, identifying UCA (Unsafe Control Action) from Control Action, and deriving Causal Factors, and may include analysis elements for each stage.
[0049] In particular, the safety analysis unit (102) can analyze analysis information by combining multiple analysis execution data. That is, the safety analysis unit (102) can analyze analysis information by integrating FMEA, FTA, and STPA. Therefore, analysis information can be analyzed from various perspectives and generated as analysis result information. Furthermore, analysis result information can refer to the analysis results of analysis information through confirmation of analysis information based on analysis elements according to analysis execution data.
[0050] Meanwhile, the safety analysis unit (102) of the present embodiment may utilize a machine learning framework utilizing at least one of open source neural network libraries, an end-to-end open source machine learning platform, Keras, and Tensorflow. That is, the safety analysis unit (102) may learn analysis information and analysis performance information, and analyze analysis information through a combination of the learned analysis information and analysis performance information.
[0051] Additionally, the safety analysis unit (102) can generate safety countermeasure information based on the analysis result information (S104). Here, the safety countermeasure information may refer to information about defects (e.g., safety accidents, failures, risk factors) and solutions for the defects among the analysis result information.
[0052] The verification information unit (103) can generate verification test cases by combining analysis information and analysis result information (S105). Here, the verification test cases refer to test scenarios for testing the safety of systems and software corresponding to the analysis information, and may include test sequences, etc. These verification test cases may be implemented in the form of white box testing, and white box testing may refer to a form of verification that allows for the internal structure and operation of systems and software to be verified, and even internal source code.
[0053] Meanwhile, the verification information unit (103) can generate defect information by combining analysis result information and safety measure information. Here, defect information may refer to information on system and software defect elements that can be derived from analysis result information, even if not included in the safety measure information, and may include information such as the type of occurrence, location, and time of occurrence.
[0054] When the verification information unit (103) generates defect information as described above, the verification information unit (103) can generate a verification test case by combining the defect information with analysis information and analysis result information. Here, the verification test case can be generated by considering not only the analysis information and analysis result information, but also the defect information.
[0055] Additionally, when verification test cases are generated with defect information in mind, they can be implemented in the form of white-box testing or black-box testing. Here, black-box testing refers to a form of verification that enables verification of the functional aspects of systems and software.
[0056] The verification communication unit (104) can transmit a verification test case to a user terminal (10) (S106). Here, the user terminal (10) may refer to a user terminal that transmitted the development data. That is, the user can receive a verification test case corresponding to the development data through the user terminal (10), and can use the verification test case to perform verification on the system and software corresponding to the development data.
[0057] Meanwhile, the user terminal (10) can confirm the received verification test case and input verification data according to the verification test case. This verification data can be transmitted from the user terminal (10) to the verification communication unit (104). This verification data can be stored in the verification communication unit (104), and the verification information unit (103) can use the verification data to create a verification test case to be created later.
[0058] The safety analysis and fault injection verification system (100) according to the present embodiment can generate analysis information through a data processing unit (101) that receives development data transmitted by a user. Here, the analysis information refers to information that has been converted into analyzable development data through a safety analysis unit (102). In other words, the safety analysis and fault injection verification system (100) can automatically generate analysis information in a form that enables safety analysis.
[0059] In addition, in the safety analysis and fault injection verification system (100) according to the present embodiment, the safety analysis unit (102) can store various analysis performance information and analyze the analysis information using the analysis performance information to generate analysis result information. That is, the safety analysis unit (102) can analyze the safety of the system and software based on the development data. Here, the analysis performance information includes analysis elements according to FMEA (Failure Mode and Effects Analysis), analysis elements according to FTA (Fault Tree Analysis), analysis elements according to STPA (System Theoretic Process Analysis), etc. That is, the safety analysis unit (102) can analyze the safety of the system and software by integrating various analysis elements for safety analysis techniques. Therefore, the safety analysis and fault injection verification system (100) according to the present embodiment can automatically perform safety analysis from various perspectives through the integration of various safety analysis techniques.
[0060] In addition, the safety analysis and fault injection verification system (100) according to the present embodiment can automatically generate verification test cases using the analysis information and analysis result information in the verification information unit (103). The user can perform verification of the system and software according to the development data using the verification test cases. As a result, the verification of the system and software can be easily performed. Therefore, the safety analysis and fault injection verification system (100) according to the present embodiment can automatically perform safety analysis and perform verification using the automatically generated verification test cases, thereby significantly reducing the time and effort required for safety analysis and verification, and significantly reducing errors in the system and software, thereby inducing the development of systems and software with high safety and reliability.
[0061] FIG. 4 is a perspective view illustrating a guide device (2000) connected to a safety analysis and fault injection verification system (100) according to one embodiment of the present invention.
[0062] As illustrated in FIG. 4, the guidance device (2000) can be worn on the user's hand to generate guidance information and transmit it to the data processing unit (101). Here, the guidance device (2000) can be registered to correspond to the user terminal (10), and the data processing unit (101) can store the guidance information transmitted from the guidance device (2000). In addition, the guidance information is composed of a combination of multiple symbols according to the position of the finger, and the symbols can be numbers, letters, symbols, etc.
[0063] The data processing unit (101) can receive new guidance information from the guidance device (2000) while storing the guidance information transmitted from the guidance device (2000). When the guidance information previously stored in the data processing unit (101) matches the new guidance information transmitted from the guidance device (2000) to the data processing unit (101), the user terminal (10) corresponding to the guidance device (2000) that transmitted the guidance information can transmit the input development data to the data processing unit (101) and utilize the safety analysis and defect injection verification system (100).
[0064] Additionally, the guide device (2000) may include a first body (2100) and a second body (2200).
[0065] The first body (2100) is worn on the user's hand corresponding to the user terminal (10), and can generate guidance information and transmit it to the data processing unit (101). In addition, the first body (2100) can include a wearable body (2110), an auxiliary wearable body (2120), a connection wire (2130), and a connection winder (2140).
[0066] The wearable (2110) is formed in a band shape and can be fixed to the user's wrist by surrounding the user's wrist area.
[0067] The auxiliary wearable (2120) may be composed of a plurality of pieces, each of which may be formed in the shape of a bone. A part of the user's finger, particularly the talus area, may be inserted and positioned in the auxiliary wearable (2120).
[0068] Additionally, the auxiliary wearable body (2120) of the present embodiment may preferably be composed of four pieces and may be positioned to correspond to four fingers excluding the thumb.
[0069] The connecting wire (2130) is formed in a plurality of pieces, each piece having a wire shape, and can connect each auxiliary wearable (2120) to the wearable (2110). Here, the first end portion of the connecting wire (2130) is connected to the auxiliary wearable (2120), and the second end portion of the connecting wire (2130), which is opposite to the first end portion of the connecting wire (2130), can be inserted into and positioned in the wearable (2110). In addition, when the wearing body (2110) is fixed while surrounding the user's wrist area and the distal phalanx of the user's finger is inserted into and positioned in the auxiliary wearable (2120), each of the connecting wires (2130) can be positioned on the user's finger and the back of the hand.
[0070] Additionally, the connecting wires (2130) of the present embodiment are preferably composed of four and can be positioned to correspond to four fingers excluding the thumb.
[0071] The connecting winder (2140) may be formed in a plurality of pieces, and may be connected to each second end portion of the connecting wire (2130) and positioned rotatably within the wearable body (2110). In addition, the connecting winder (2140) may provide force to the connecting wire (2130) to wind the connecting wire (2130). When the user's finger is increasingly spread, the connecting wire (2130) may be increasingly wound around the connecting winder (2140), whereas when the user's finger is increasingly bent, the connecting wire (2130) may be increasingly unwound from the connecting winder (2140). Here, depending on the bent state of the user's finger, the connecting winder (2140) may have different rotation angles. The rotation angle refers to the angle according to the rotation of the connecting winder (2140) when the finger is bent based on the state in which the finger is spread out, and the degree to which the connecting winder (2140) winds the connecting wire (2130) may vary depending on the rotation angle. In addition, the wearable (2110) can generate guidance information by combining the rotation angles of a plurality of connecting winders (2140).
[0072] In addition, the connection winder (2140) of the present embodiment preferably has four connection wires (2130) and can be positioned to correspond to four fingers excluding the thumb.
[0073] The second body (2200) can be used to set the bent state of the finger of a user wearing the first body (2100). In addition, the second body (2200) can include a base (2210), a housing (2220), a first guide (2230), a contact plate (2240), a second guide (2250), and a handle (2260).
[0074] The base (2210) may be formed in a flat plate shape.
[0075] The housing (2220) may be formed in a plurality of pieces, each of which may have a square pillar shape and may be positioned on the upper surface of the base (2210). An insertion space (2200') may be formed concavely on the upper surface of each of the housings (2220), and the insertion space (2200') may have a shape corresponding to the housing (2220). The finger of a user wearing the first body (2100) on the hand may be inserted into the insertion space (2200'). In addition, the housing (2220) of the present embodiment may preferably be formed in four pieces to correspond to the auxiliary wearable body (2120).
[0076] The first guide body (2230) is formed in the form of a rack gear and can be positioned along the vertical direction on the inner side of the insertion space (2200').
[0077] The contact plate (2240) is formed in a plate shape corresponding to the cross-section of the insertion space (2200') and can be positioned inside the insertion space (2200') so as to be parallel to the upper surface of the insertion space (2200') at the upper end of the first guide body (2230).
[0078] The second guide body (2250) is formed in the form of a pinion gear and can be positioned to mesh with the first guide body (2230) inside the insertion space (2200').
[0079] The handle (2260) can be connected to the center of the second guide (2250) by penetrating the housing (2220). Here, the first end portion of the handle (2260) is positioned to protrude from the housing (2220), and the second end portion of the first end portion of the handle (2260) can be connected to the center of the second guide (2250). Here, the handle (2260) can be rotated to rotate the second guide (2250) about the center of the second guide (2250).
[0080] In the above state, when the second guide (2250) is rotated in one direction by the handle (2260), the first guide (2230) can be moved to move the contact plate (2240) upward. On the other hand, when the second guide (2250) is rotated in the opposite direction by the handle (2260), the first guide (2230) can be moved to move the contact plate (2240) downward. That is, due to the rotation of the handle (2260), the position of the contact plate (2240) within the insertion space (2200') can be determined. In addition, the position of the contact plate (2240) within the insertion space (2200') can determine the depth of the insertion space (2200') into which a finger can be inserted.
[0081] In a state where the guidance information for the user terminal (10) and the guidance device (2000) corresponding to each other is not stored in the data processing unit (101), the user can adjust the position of the contact plate (2240) located inside the insertion space (2200') by using the handle (2260) in the second body (2200) of the guidance device (2000).
[0082] In the above state, the user can wear the first body (2100) of the guidance device (2000) on the hand and insert the user's finger into the insertion space (2200') so that the auxiliary wearable (2120) can be in contact with the contact plate (2240). Here, the wearable (2110) of the first body (2100) can be fixed to the user's wrist while surrounding the user's wrist, the distal phalanx of the user's finger can be inserted and positioned in the auxiliary wearable (2120), and the connection wire (2130) can be positioned on the user's finger and the back of the hand. In addition, the bent state of the user's finger can be maintained constantly for a predetermined period of time, and the rotation angle of the connection winder (2140) can also be maintained constantly. Accordingly, the wearable (2110) can generate guidance information by combining the rotation angles of the connection winders (2140) and transmit it to the data processing unit (101). The data processing unit (101) can store the received guidance information.
[0083] In a state where guidance information for a user terminal (10) and a guidance device (2000) corresponding to each other are stored in the data processing unit (101), the user may wear the first body (2100) of the guidance device (2000) on the hand and insert the user's finger into the insertion space (2200') so that the auxiliary wearable (2120) may be brought into contact with the contact plate (2240). Here, due to the second body (2200), the bent state of the user's finger and the rotation angle of the connection winder (2140) may be the same as when the guidance information is generated. In addition, the wearable (2110) may generate guidance information identical to the guidance information stored in the data processing unit (101) and transmit the same to the data processing unit (101). Meanwhile, if the position of the contact plate (2240) in the second body (2200) changes, the bent state of the user's finger and the rotation angle of the connecting winder (2140) may be different from when the guidance information is generated. Here, the wearable (2110) may generate guidance information that is different from the guidance information stored in the data processing unit (101).
[0084] In the above state, when the guidance information stored in the data processing unit (101) matches the guidance information transmitted from the guidance device (2000) to the data processing unit (101), the user terminal (10) corresponding to the guidance device (2000) that transmitted the guidance information can transmit the development data input by the user to the data processing unit (101) within a set period of time. That is, the user terminal (10) can be connected to the safety analysis and defect injection verification system (100) through the operation of the guidance device (2000) corresponding to the user terminal (10).
[0085] As described above, the guidance device (2000) combines the first body (2100) and the second body (2200), and guides the user's finger worn on the hand portion of the first body (2100) capable of generating guidance information and the rotation angle of the connection winder (2140) of the first body (2100) to be constant, thereby generating guidance information according to the bent state of the finger by the second body (2200). As a result, the user terminal (10) can be safely connected to the safety analysis and fault injection verification system (100) by the user who maintains the bent state of the finger set through the guidance device (2000), and the safety of the system and software can be verified based on the development data input through the safety analysis and fault injection verification system (100).
[0086] The functional operations and performance forms of the subject matter described in this specification may be implemented in digital electronic circuits, computer software, firmware, or hardware, or in a combination of one or more of these, including the structures disclosed in this specification and their structural equivalents.
[0087] The subject matter described herein may be implemented as one or more computer program products, i.e., one or more modules of computer program instructions encoded on a tangible program medium for execution by or controlling the operation of a data processing device. The tangible program medium may be a radio signal or a computer-readable medium. A radio signal is an artificially generated signal, such as a machine-generated electrical, optical, or electromagnetic signal, that is generated to encode information for transmission to a suitable receiver device for execution by a computer. The computer-readable medium may be a machine-readable storage device, a machine-readable storage substrate, a memory device, a combination of materials that affect a machine-readable radio signal, or a combination of one or more of these.
[0088] A computer program (also known as a program, software, software application, script or code) may be written in any programming language, including compiled or interpreted languages, a priori or procedural languages, and may be deployed in any form, including as a standalone program, a module, a component, a subroutine or other unit suitable for use in a computing environment.
[0089] Computer programs do not necessarily correspond to files in a file system. A program may be stored within a single file provided to the requested program, within multiple interacting files (e.g., a file storing one or more modules, subprograms, or portions of code), or within a file containing other programs or data (e.g., one or more scripts stored within a markup language document).
[0090] A computer program may be deployed to run on a single computer or on multiple computers located at a single site or distributed across multiple sites and interconnected by a communications network.
[0091] Additionally, the logical flow and structural block diagrams described herein describe corresponding functions and corresponding acts and / or specific methods supported by the disclosed structural means, and can also be used to construct corresponding software structures and algorithms and their equivalents.
[0092] The processes and logic flows described herein are executable by one or more programmable processors executing one or more computer programs to perform functions by operating on input data and generating output.
[0093] Processors suitable for executing computer programs include, for example, general-purpose and special-purpose microprocessors, as well as any one or more processors of any type of digital computer. Typically, the processor will receive instructions and data from read-only memory, random-access memory, or both.
[0094] The core elements of a computer are one or more memory devices for storing instructions and data, and a processor for executing instructions. Additionally, a computer will typically be coupled to or include one or more mass storage devices, such as magnetic, magneto-optical, or optical disks, to receive data from, transfer data to, or both of these operations. However, a computer need not include such devices.
[0095] This description presents the best mode of the invention and provides examples to illustrate the invention and to enable those skilled in the art to make and use the invention. The specification, as written, is not intended to limit the invention to the specific terms set forth herein.
[0096] Accordingly, while the present invention has been described in detail with reference to the above-described examples, those skilled in the art will appreciate that modifications, variations, and variations can be made to these examples without departing from the scope of the present invention. In short, it is to be understood that to achieve the intended effects of the present invention, not all functional blocks depicted in the drawings must be separately included, nor must all orders depicted in the drawings be followed in the exact order depicted. Even if this is not the case, the technical scope of the present invention as set forth in the claims may still be encompassed.
[0097] [Explanation of symbols]
[0098] 100: Safety Analysis and Fault Injection Verification System
[0099] 101: Data Processing Unit
[0100] 102: Safety Analysis Department
[0101] 103: Verification Information Department
[0102] 104: Verification Communications Department
Claims
1. In a safety analysis and fault injection verification system connected to a user terminal and a network, A data processing unit that receives development data from a user terminal and generates analysis information; A safety analysis unit that analyzes analysis information based on analysis performance information to generate analysis result information and generates safety measure information according to the analysis result information; and A safety analysis and fault injection verification system characterized by including a verification information unit that generates verification test cases by combining analysis information and analysis result information.
2. In paragraph 1, A safety analysis and fault injection verification system characterized by development data including development requirements and design models.
3. In paragraph 1, The safety analysis department stores multiple analysis performance information, A safety analysis and fault injection verification system characterized in that the analysis performance information includes analysis elements according to FMEA (Failure Mode and Effects Analysis), analysis elements according to FTA (Fault Tree Analysis), and analysis elements according to STPA (System Theoretic Process Analysis).
4. In paragraph 3, A safety analysis and fault injection verification system characterized by analyzing analysis information by combining multiple analysis performance information.
5. In paragraph 1, A safety analysis and fault injection verification system characterized by using a machine learning framework utilizing at least one of the Open Source Neural Network Libraries, the End-To-End Open Source Machine Learning Platform, Keras, and Tensorflow.
6. In paragraph 1, A safety analysis and fault injection verification system characterized in that the verification test cases are conducted in the form of white box testing.
7. In paragraph 1, A safety analysis and fault injection verification system characterized in that the verification information unit generates fault information by combining analysis result information and safety measure information, and generates verification test cases by combining the fault information with analysis information and analysis result information.
8. In paragraph 7, A safety analysis and fault injection verification system characterized in that the verification test cases are in the form of white box testing or black box testing.
9. In paragraph 1, the safety analysis and fault injection verification system, A safety analysis and fault injection verification system characterized by further including a verification communication unit that transmits a verification test case to a user terminal and receives verification data for the verification test case from the user terminal.
10. In paragraph 1, the safety analysis and fault injection verification system, It further includes a guidance device that is registered to correspond to the user terminal and is worn on the user's hand to generate guidance information and transmit it to the data processing unit. The data processing unit stores the guidance information transmitted from the guidance device and receives new guidance information from the guidance device, and when the guidance information already stored in the data processing unit and the new guidance information transmitted from the guidance device to the data processing unit match, the user terminal corresponding to the guidance device that transmitted the guidance information transmits the input development data to the data processing unit. The guide device is, A first body including a band-shaped wearable body that wraps around and is fixed to a user's wrist area, a plurality of auxiliary wearable bodies each having a bone shape and into which a portion of the user's finger can be inserted, a plurality of connection wires each having a wire shape and having a first end portion connected to the auxiliary wearable body and a second end portion opposite to the first end portion inserted and positioned in the wearable body, and a plurality of connection winders each connected to the second end portion of the connection wire and positioned rotatably inside the wearable body to provide force to the connection wire to wind the connection wire; and A flat plate-shaped base, a plurality of housings each formed in a square pillar shape and having an insertion space concavely formed on the upper surface and positioned on the upper surface of the base, a first guide formed in the shape of a rack gear and positioned along a vertical direction on the inner surface of the insertion space, a contact plate formed in a plate shape corresponding to the cross-section of the insertion space and positioned inside the insertion space so as to be parallel to the upper surface of the insertion space from the upper end of the first guide, a second guide formed in the shape of a pinion gear and positioned inside the insertion space so as to mesh with the first guide, and a second body including a handle that penetrates the housing and is connected to the center of the second guide to rotate the second guide. When the second guide body is rotated in one direction by the handle, the first guide body is moved to move the contact plate upward or downward, The user wears the first body of the guide device on the hand area and inserts the user's finger into the insertion space so that the auxiliary wearable body comes into contact with the contact plate. A safety analysis and fault injection verification system characterized in that when the bent state of the user's finger is maintained constant for a predetermined period of time and the rotation angle of the connected winder is maintained constant, the wearable generates guidance information by combining the rotation angles of the connected winders and transmits it to a data processing unit.
Citation Information
Patent Citations
Section modeling-based real-time performance test method and system for secure operating system
CN116841887A
Method for determining test alternation factor in robot software white box test and automated testing system
KR1020100136773A
Massage Machine and Control Method for the Same
KR1020210051289A
Bulletproof backpack with bullet-proof function
KR102168971B1
System and method for model based technology and process for safety-critical software development
US20170039039A1