Accident scenario generation system for safety analysis

The accident scenario generation system addresses inefficiencies in safety analysis by automatically generating and analyzing scenarios using STPA and FTA, improving analysis speed and accuracy, and enhancing the reliability of electronic control units and software.

WO2026063551A1PCT designated stage Publication Date: 2026-03-26VWAY CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-09-30
Publication Date
2026-03-26

AI Technical Summary

Technical Problem

Existing systems lack an efficient method to automatically generate accident scenarios for safety analysis of complex electronic control units and software, leading to inefficiencies in safety analysis time and accuracy, and resulting in potential operational failures.

Method used

An accident scenario generation system that includes a data processing unit, scenario generation unit, scenario concretization unit, and scenario analysis unit to automatically generate and analyze accident scenarios using safety analysis technology, applying techniques like STPA and FTA, and enabling user verification and modification of development information.

Benefits of technology

The system reduces safety analysis time, improves analysis accuracy, and enhances the reliability of systems and software by identifying potential accidents, thereby reducing operational failures.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure KR2024014822_26032026_PF_FP_ABST
    Figure KR2024014822_26032026_PF_FP_ABST
Patent Text Reader

Abstract

An accident scenario generation system connected to a user equipment through a network, according to an embodiment of the present invention, may comprise: a data processing unit that receives development information from the user equipment and generates same as basic information; a scenario generation unit that stores performance information, and processes the basic information on the basis of the performance information to generate an accident scenario candidate; a scenario specifying unit that derives an accident scenario by specifying the accident scenario candidate; and a scenario analysis unit that generates analysis information by analyzing the accident scenario.
Need to check novelty before this filing date? Find Prior Art

Description

Accident scenario generation system for safety analysis

[0001] The present invention relates to an accident scenario generation system, and more specifically, to an accident scenario generation system for safety analysis capable of deriving accident scenarios that may occur in an operating environment for a system and software.

[0002] Today, industrial sectors such as the electronics, telecommunications, automotive, aviation, and medical industries are seeing an increased proportion of development in electronic control units and software due to the impact of the Fourth Industrial Revolution, and the complexity of these electronic control units and software is also growing. In particular, systems and software installed in automobiles, nuclear power, and aviation require high stability and reliability.

[0003] Meanwhile, to develop systems and software with high safety and reliability, safety analysis and verification of the systems and software are required during the development phase. In particular, various incidents can occur during the operation of systems and software, such as data integrity failures, system downtime or performance degradation, exploitation of security vulnerabilities, interface errors, real-time processing failures, algorithm errors, hardware-software interaction issues, insufficient exception handling, version control and update problems, and resource management failures. These incidents need to be identified for the safety analysis of the systems and software. Consequently, there is a need to generate incident scenarios that can be utilized for the safety analysis of systems and software.

[0004] The technical problem that the accident scenario generation system according to the technical concept of the present invention aims to solve is to provide an accident scenario generation system capable of automatically generating accident scenarios according to development conditions.

[0005] Furthermore, the technical objective of the accident scenario generation system according to the technical concept of the present invention is to provide an accident scenario generation system that generates accident scenarios and scenario information by applying safety analysis technology and enables their application to development.

[0006] Furthermore, the technical objective that the accident scenario generation system according to the technical concept of the present invention aims to achieve is to provide an accident scenario generation system capable of reducing safety analysis time and improving safety analysis accuracy.

[0007] Furthermore, the technical objective of the accident scenario generation system according to the technical concept of the present invention is to provide an accident scenario generation system that enables the development of systems and software with high safety and reliability by significantly reducing accidents resulting from the operation of the system and software.

[0008] The technical problems that the accident scenario generation system according to the technical concept of the present invention aims to solve are not limited to those mentioned above, and other unmentioned problems will be clearly understood by a person skilled in the art from the description below.

[0009] An accident scenario generation system according to one embodiment of the technical concept of the present invention may be characterized by comprising: a data processing unit that receives development information from a user terminal and generates it as basic information; a scenario generation unit that stores execution information and processes the basic information based on the execution information to generate accident scenario candidates; a scenario concretization unit that concretizes the accident scenario candidates to derive an accident scenario; and a scenario analysis unit that analyzes the accident scenario to generate analysis information.

[0010] In addition, development information may include development requirements and design models.

[0011] In addition, the scenario generation unit can define the analysis scope from basic information, model the control structure, identify unsafe control actions, and generate accident scenario candidates based on the identified unsafe control actions.

[0012] In addition, the control structure may include a controller, a controlled process, a control action, and feedback.

[0013] In addition, the scenario generation unit can identify unsafe control actions by using feedback among the control actions.

[0014] In addition, the scenario concretization unit can classify accident scenario candidates by accident scenario case and derive accident scenarios by concretizing the accident scenario candidates through combination with the classified accident scenario cases.

[0015] Additionally, the accident scenario case may include at least one of a case where the feedback is normal and the controller is unstable, a case where both the feedback and the controller are unstable, a case where the controller is normal and the controlled process is unstable, and a case where the controller and the controlled process are normal and the controlled system is unstable.

[0016] In addition, the scenario analysis unit generates analysis information by analyzing accident scenarios using analysis elements based on Fault Tree Analysis (FTA), and the analysis information may include a truncated set, failure rate, and accident-causing factors.

[0017] In addition, the accident scenario generation system further includes a modification induction unit that transmits mutually corresponding accident scenarios and analysis information to a user terminal, wherein the modification information, which modifies development information considering the accident scenarios and analysis information, is input into the user terminal, transmitted from the user terminal to an information processing unit, and can be generated as basic information by the information processing unit.

[0018] In addition, the accident scenario generation system further includes a login unit that receives user login information from a user terminal and determines whether to allow the user's login by comparing the user login information with pre-registered user login confirmation information, wherein the login unit arranges and displays eight contact areas sequentially on the screen of the user terminal and randomly assigns eight different notes constituting a musical scale to each contact area, and when the user touches a contact area through the user terminal, the note assigned to the contacted contact area is output only through earphones connected to the user terminal, and simultaneously performs a sound-color display step in which, after the user touches all eight contact areas and confirms the note assigned to each contact area, multiple different colors begin to be displayed in a random order at predetermined display time intervals on the contact area that the user touches again, and the login unit performs a sound transmission step in which, when the user touches a contact area once and then presses the contact area again for a predetermined time after a predetermined pause time has passed, sound data corresponding to the note assigned to the contact area is transmitted from the user terminal, and when the pressing for the predetermined time occurs, [the] corresponding to the color displayed on the contact area The login unit performs a color transmission step of receiving color data from a user terminal, and repeats the sound-color display step, the sound transmission step, and the color transmission step, wherein the login unit performs an input data formation step of sequentially connecting sound data transmitted from the user terminal through the sound transmission step to form sound input data and sequentially connecting color data transmitted from the user terminal through the color transmission step to form color input data, and the login unit performs a sound data verification step of verifying whether the sound input data matches the sound registration data included in the user login verification information pre-registered by the user.A color data verification step is performed to verify whether the color registration data and color input data included in the user login verification information pre-registered by the user match, and the login unit may allow the user's login if the sound registration data and sound input data match in the sound data verification step, and at the same time, the color registration data and color input data match in the color data verification step.

[0019] The accident scenario generation system according to embodiments based on the technical concept of the present invention has the following effects.

[0020] (1) An accident scenario for accidents that may occur depending on the development situation is automatically generated.

[0021] (2) Safety analysis technology is applied to generate accident scenarios and scenario information, and the generated accident scenarios and scenario information can be applied to development.

[0022] (3) Reduce the time required for safety analysis and improve the accuracy of the safety analysis.

[0023] (4) The number of accidents resulting from the operation of the system and software is significantly reduced, so that the system and software can be developed with high safety and reliability.

[0024] However, the effects achievable by the accident scenario generation system according to one embodiment of the present invention are not limited to those mentioned above, and other unmentioned effects will be clearly understood by a person skilled in the art from the description below.

[0025] A brief description of each drawing is provided to help to better understand the drawings cited in this specification.

[0026] FIG. 1 is a drawing illustrating an accident scenario generation system according to one embodiment of the present invention.

[0027] FIG. 2 is an implementation flowchart of an accident scenario generation system according to one embodiment of the present invention.

[0028] The present invention is capable of various modifications and may have various embodiments, and specific embodiments are illustrated in the drawings and described in detail in the detailed description. However, this is not intended to limit the present invention to specific forms of practice, and it should be understood that the present invention includes all modifications, equivalents, and substitutions that fall within the spirit and scope of the invention.

[0029] In describing the present invention, if it is determined that a detailed description of related prior art may unnecessarily obscure the essence of the present invention, such detailed description is omitted. Additionally, numbers used in the description of this specification (e.g., 1st, 2nd, etc.) are merely identification symbols to distinguish one component from another.

[0030] In addition, when a component is described in this specification as being "connected" or "connected" to another component, it should be understood that the component may be directly connected to or directly connected to the other component, but unless otherwise specifically stated, it may also be connected or connected through another component in between.

[0031] In addition, components expressed as '~part' in this specification may consist of two or more components combined into a single component, or a single component may be divided into two or more components according to more detailed functions. Furthermore, each component described below may additionally perform some or all of the functions performed by other components in addition to the primary function it is responsible for, and it goes without saying that some of the primary functions performed by each component may be exclusively performed by other components.

[0032] Hereinafter, embodiments based on the technical concept of the present invention will be described in detail in turn.

[0033] FIG. 1 is a drawing illustrating an accident scenario generation system according to one embodiment of the present invention, and FIG. 2 is an implementation flowchart of an accident scenario generation system according to one embodiment of the present invention.

[0034] As illustrated in FIGS. 1 and 2, an accident scenario generation system (100) according to one embodiment of the present invention may be connected to a user terminal (10) via a network (1) and may include an information processing unit (101), a scenario generation unit (102), a scenario concretization unit (103), a scenario analysis unit (104), and a modification induction unit (105). Here, the user may refer to a person responsible for safety analysis of the system and software, and although it is illustrated as being composed of one person in this embodiment, it may be composed of two or more people.

[0035] Additionally, the information processing unit (101), the scenario generation unit (102), the scenario concretization unit (103), the scenario analysis unit (104), and the modification induction unit (105) may include at least one of a processor, a memory, and a data transceiver.

[0036] The user can use a user terminal (10) to access the accident scenario generation system (100) and exchange signals with the accident scenario generation system (100). The accident scenario generation system (100) may display a web page through a web browser running on the user terminal (10) and allow access to the accident scenario generation system (100) after logging in on the web page, or an application capable of accessing the accident scenario generation system (100) may be installed and run on the user terminal (10).

[0037] The user terminal (10) can be implemented as a computer capable of connecting to a remote server or terminal via a network (1). Here, the computer may include, for example, a notebook, desktop, laptop, etc. equipped with a web browser. Additionally, the user terminal (10) can be implemented as a terminal device capable of connecting to a remote server or terminal via a network (1). The terminal device may include, for example, all types of handheld-based wireless communication devices such as PCS (Personal Communication System), GSM (Global System for Mobile communications), PDC (Personal Digital Cellular), PHS (Personal Handyphone System), PDA (Personal Digital Assistant), IMT (International Mobile Telecommunication)-2000, CDMA (Code Division Multiple Access)-2000, W-CDMA (W-Code Division Multiple Access), Wibro (Wireless Broadband Internet) terminals, smartphones, smartpads, tablet PCs, etc.

[0038] Here, the network (1) refers to a connection structure capable of exchanging information between each node, such as multiple terminals and servers. Examples of such networks include, but are not limited to, a 3GPP (3rd Generation Partnership Project) network, an LTE (Long Term Evolution) network, a 5G network, a WIMAX (World Interoperability for Microwave Access) network, the Internet, a LAN (Local Area Network), a Wireless LAN (Wireless Local Area Network), a WAN (Wide Area Network), a PAN (Personal Area Network), a Bluetooth network, a satellite broadcasting network, an analog broadcasting network, and a DMB (Digital Multimedia Broadcasting) network.

[0039] The information processing unit (101) can receive development information from the user terminal (10) (S101). Here, the development information may refer to information generated for the development of the system and software, and may include development requirements, design models, etc. Additionally, the development requirements may include content to be applied in the system and software, content to be considered or paid attention to when developing the system and software, etc., and the design model may model the structure and function of the system and software, etc., and may include content corresponding to the modeling.

[0040] The user can input development information into the user terminal (10), and the user terminal (10) can transmit the development information input by the user to the information processing unit (101).

[0041] Additionally, the information processing unit (101) can generate the received development information as basic information (S102). Here, the basic information may specifically refer to information processed from the development information in a form usable by the scenario generation unit (102) described later, and may include, for example, data from which parts necessary for safety analysis have been selected from the development information.

[0042] The scenario generation unit (102) can generate accident scenario candidates by processing basic information based on execution information (S103). Here, the execution information may include analysis elements according to an analysis technique that analyzes basic information, for example, analysis elements according to FMEA (Failure Mode and Effects Analysis), analysis elements according to FTA (Fault Tree Analysis), analysis elements according to STPA (System Theoretic Process Analysis), etc. The scenario generation unit (102) can store multiple execution information.

[0043] In particular, the scenario generation unit (102) can generate accident scenario candidates by processing basic information using analysis elements according to STPA.

[0044] First, the scenario generation unit (102) can define the scope of analysis from basic information. Here, the scenario generation unit (102) can clearly define the parts analyzed in the system and software and their boundaries corresponding to the basic information, and identify the purpose and high-level risk of the system and software.

[0045] Next, the scenario generation unit (102) can model a control structure. Here, the control structure may consist of a diagram including a controller, a controlled process, a control action, and feedback. Additionally, the controller is a component that makes control decisions and performs control actions, the controlled process refers to a system or subsystem affected by the controller, the control action refers to a command or input that the controller applies to the controlled process, and the feedback refers to information that conveys the state or result of the controlled process to the controller.

[0046] Next, the scenario generation unit (102) can identify unsafe control actions (UCA). In particular, unsafe control actions can be identified among control actions using feedback. As a result, potentially dangerous situations regarding control actions can be identified.

[0047] Additionally, the scenario generation unit (102) can generate accident scenario candidates based on the identified unsafe control actions. Here, the accident scenario candidates may refer to a set of potentially dangerous situations or conditions, for example, a situation where an obstacle is not detected due to a sensor error in an autonomous vehicle system, or a situation where the network connection of a drug administration system is disconnected in a medical system.

[0048] The scenario concretization unit (103) can classify accident scenario candidates by accident scenario case and combine them with the classified accident scenario cases to concretize the accident scenario candidates and derive an accident scenario (S104). Here, the accident scenario case may include at least one of a case where the feedback is normal and the controller is unsafe, a case where both the feedback and the controller are unsafe, a case where the controller is normal and the controlled process is unsafe, and a case where the controller and the controlled process are normal and the controlled system is unsafe.

[0049] In addition, accident scenarios may include starting conditions, event sequences, results, etc., in accident scenario candidates. For example, this could be a situation in an autonomous vehicle system where sudden braking occurs because a pedestrian crossing is detected late due to limited visibility caused by water droplets on the front camera during rain, or a situation in a medical system where medical staff are late in recognizing a cardiac abnormality because a patient's heart rate data is not updated for 5 minutes due to a temporary network failure in the intensive care unit monitoring system.

[0050] The scenario analysis unit (104) can generate analysis information by analyzing the accident scenario (S105). Here, the scenario analysis unit (104) can analyze the accident scenario using analysis elements based on Fault Tree Analysis (FTA), and the analysis information may include a cut set, failure rate, and accident-inducing factors. The cut set refers to a set of basic events that can cause system failure derived from the accident scenario through Fault Tree Analysis (FTA), the failure rate refers to the probability of failure occurring in the system and software per unit time and can be calculated by dividing the number of failures by the product of the number of components and the operating time, and the accident-inducing factor may refer to development information corresponding to the cut set.

[0051] The modification guidance unit (105) can transmit mutually corresponding accident scenarios and analysis information to the user terminal (10) (S106). Here, the user can check the accident scenarios and analysis information through the user terminal (10) and input modification information into the user terminal (10) by modifying the development information in consideration of the accident scenarios and analysis information. The modification information is transmitted from the user terminal (10) to the information processing unit (101) and can be generated as basic information by the information processing unit (101). As a result, the generation of accident scenarios based on the modification information can be achieved, and the user can obtain the best accident scenarios and analysis information by repeatedly modifying the development information in consideration of the accident scenarios and analysis information.

[0052] The accident scenario generation system (100) according to the present embodiment can generate basic information through an information processing unit (101) that receives development information from a user. Here, basic information refers to information processed so that development information can be used by the scenario generation unit (102). In particular, the basic information is processed by the scenario generation unit (102) to generate accident scenario candidates, and the accident scenario candidates are concretized by the scenario concretization unit (103) to derive accident scenarios. Accordingly, the accident scenario generation system (100) according to the present embodiment can automatically generate accident scenarios for accidents that may occur depending on the development situation, and can improve the accuracy of safety analysis while reducing the time required for safety analysis of systems and software.

[0053] In addition, the accident scenario generation system (100) according to the present embodiment may use analysis elements based on STPA (System Theoretic Process Analysis) when generating an accident scenario from basic information, and may use analysis elements based on FTA (Fault Tree Analysis) when generating analysis information from the accident scenario. The accident scenario and analysis information can be transmitted to a user terminal (10) and verified by the user. Accordingly, the accident scenario generation system (100) according to the present embodiment generates accident scenarios and analysis information by applying safety analysis technology so that they can be applied to development.

[0054] In addition, the accident scenario generation system (100) according to the present embodiment transmits accident scenarios and analysis information to a user terminal (10), allowing the user to verify and modify development information. Accordingly, the accident scenario generation system (100) according to the present embodiment can significantly reduce accidents resulting from the operation of the system and software, thereby enabling the development of a system and software with high safety and reliability.

[0055] Meanwhile, the accident scenario generation system (100) according to the present embodiment may further include a login unit.

[0056] The login unit receives user login information from the user terminal (10) and compares the user login information with pre-registered user login confirmation information to determine whether to allow the user to log in.

[0057] Login information may include a user ID, sound input data, color input data, etc. User login verification information is information registered by the user in advance and serves as reference information for determining whether it is identical to the login information, and may include a user ID, sound registration data, color registration data, etc.

[0058] The login section can perform tone-color display steps as follows.

[0059] The login unit displays eight contact areas arranged in sequence on the screen of the user terminal (10) (e.g., arranged in a line, arranged in a circle), and eight different notes constituting a musical scale can be randomly assigned to each of the contact areas. The eight notes can consist of Do, Re, Mi, Fa, Sol, Si, and Do, and the contact areas can have the shape of a triangle, a square, or a circle, and it is preferable that the eight contact areas have the same size.

[0060] After the user enters an ID through the user terminal (10), the login unit displays eight contact areas arranged in order on the screen of the user terminal (10), and when the user touches any one of the contact areas through the user terminal (10), the sound assigned to the contacted contact area is output through the earphones connected to the user terminal (10). At the same time, after the user touches all eight contact areas and checks the sound assigned to each contact area, the login unit may start displaying multiple different colors in a random order at predetermined display time intervals on the contact area that the user touches again.

[0061] Here, it is preferable that the tone-color display step operates only when earphones are connected to the user terminal (10).

[0062] The login unit can perform a sound transmission step in which, when a user touches a contact area once and then presses the contact area again for a predetermined time after a predetermined pause time has passed, sound data corresponding to a sound assigned to the contact area is transmitted from the user terminal (10), and a color transmission step in which color data corresponding to a color displayed in the contact area is transmitted from the user terminal (10) when the pressing for the predetermined time occurs.

[0063] The login unit can repeat the sound-color display step, sound transmission step, and color transmission step.

[0064] The login unit can perform an input data formation step in which it sequentially connects sound data transmitted from the user terminal (10) through the sound transmission step to form sound input data, and sequentially connects color data transmitted from the user terminal (10) through the color transmission step to form color input data.

[0065] The login unit can perform a sound data verification step to check whether sound registration data included in user login verification information pre-registered by the user matches sound input data, and a color data verification step to check whether color registration data included in user login verification information pre-registered by the user matches color input data.

[0066] The login unit may allow the user's login if the sound registration data and sound input data match during the sound data verification step, and at the same time, the color registration data and color input data match during the color data verification step. Here, the user terminal (10) can be connected to the accident scenario generation system (100).

[0067] For example, the login process through the login section is explained as follows.

[0068] The user may apply to the login unit in advance as sound registration data "Re-Sol-Mi-Fa-Si" through the user terminal (10), and the login unit sequentially stores sound data corresponding to the first note "Re," sound data corresponding to the second note "Sol," sound data corresponding to the third note "Mi," sound data corresponding to the fourth note "Fa," and sound data corresponding to the fifth note "Si" as sound registration data. Here, the sound data is data that matches the corresponding sound, which can be arbitrarily set, and may be data having a binary value, text, image, etc.

[0069] Additionally, the user can pre-register colors for each note of "Re, Sol, Mi, Fa, Si." The user can register white for "Re," white for "Sol," white for "Mi," green for "Fa," and yellow for "Si." The login unit sequentially stores the color data corresponding to white, the color data corresponding to white, the color data corresponding to green, and the color data corresponding to yellow as color registration data. Here, the color data is data that matches the corresponding color; it can be arbitrarily set and may be binary data, text, images, etc.

[0070] After the user enters an ID through the user terminal (10) and connects the earphones to the user terminal (10), the login unit displays eight contact areas arranged in order on the screen of the user terminal (10).

[0071] The user can check the notes assigned to each contact area by touching all eight contact areas. The user can confirm that "Re" is assigned to the third contact area, "Sol" is assigned to the fifth contact area, "Mi" is assigned to the first contact area, "Fa" is assigned to the second contact area, and "Si" is assigned to the fourth contact area.

[0072] Next, the user touches the third contact area through the user terminal (10), and after a pause of 3 seconds, while looking at the colors displayed at 4-second intervals in the third contact area, when the white color registered to the first note "Re" is displayed, the user presses the third contact area for 3 seconds, and accordingly, the login unit receives sound data corresponding to the note assigned to the third contact area and color data corresponding to the color pressed in the third contact area from the user terminal (10).

[0073] The login unit can repeat the sound-color display step, sound transmission step, and color transmission step. That is, eight different sounds are randomly assigned to each of the eight contact areas on the screen of the user terminal (10), and the user touches all eight contact areas to check the sound assigned to each contact area and repeats the above process to complete the contact for "Re-Sol-Mi-Fa-Si".

[0074] Whenever sound data and color data are transmitted, the login unit sequentially connects the transmitted sound data and color data to form sound input data and color input data, compares the sound registration data with the sound input data, and compares the color registration data with the color input data to determine whether they match.

[0075] Login through the login unit is a login method determined by the user's hearing and sight, and even if someone is watching from the side, the user proceeds by listening to the sound through earphones, so the login password cannot be known. In addition, even if only the sound is heard from the user's surroundings, the login password cannot be known unless the color associated with the sound is known. Accordingly, the user can safely and conveniently log in to the accident scenario generation system (100) with a single login information. That is, the accident scenario generation system (100) according to the present embodiment can form login information through sound and color using the login unit, and can further enhance user login security procedures and convenience.

[0076] The functional operations and modes of practice relating to the subject matter described above in this specification may be implemented in digital electronic circuits, computer software, firmware, or hardware, or in a combination of one or more of these, including the structures disclosed in this specification and their structural equivalents.

[0077] The embodiment of the subject matter described herein may be implemented as one or more computer program products, that is, as one or more modules relating to computer program instructions encoded on a tangible program medium for execution by a data processing device or for controlling the operation thereof. The tangible program medium may be a radio signal or a computer-readable medium. A radio signal is an artificially generated signal, such as an electrical, optical, or electromagnetic signal generated by a machine, for example, to encode information to be transmitted to a suitable receiver device for execution by a computer. A computer-readable medium may be a machine-readable storage device, a machine-readable storage substrate, a memory device, a combination of materials affecting a machine-readable radio signal, or a combination of one or more of these.

[0078] A computer program (also known as a program, software, software application, script, or code) may be written in any form of a programming language, including compiled or interpreted languages, or a priori or procedural languages, and may be developed in any form, including a standalone program, modules, components, subroutines, or other units suitable for use in a computer environment.

[0079] A computer program does not necessarily correspond to a file in a file system. A program may be stored within a single file provided to the requested program, within multiple interacting files (e.g., a file storing one or more modules, subprograms, or parts of code), or within a part of a file containing other programs or data (e.g., one or more scripts stored within a markup language document).

[0080] Computer programs can be deployed to be executed on multiple computers or a single computer that are located at one site or distributed across multiple sites and interconnected by a communication network.

[0081] Additionally, the logical flow and structural block diagrams described herein describe corresponding actions and / or specific methods supported by corresponding functions and steps supported by the disclosed structural means, and can also be used to construct corresponding software structures and algorithms and their equivalents.

[0082] The processes and logic flows described in this specification can be performed by one or more programmable processors that execute one or more computer programs to perform functions by operating on input data and generating outputs.

[0083] Processors suitable for the execution of computer programs include, for example, both general-purpose and special-purpose microprocessors and any one or more processors of any type of digital computer. Generally, the processor will receive instructions and data from read-only memory or random access memory or both.

[0084] The core elements of a computer are one or more memory devices for storing instructions and data, and a processor for executing instructions. Additionally, a computer will generally be combined with or include one or more mass storage devices for storing data, such as magnetic, magneto-optical, or optical discs, to be operable to receive data from, transmit data to, or perform both of these operations. However, a computer does not need to have such devices.

[0085] The description provided herein presents the best mode of the invention and offers examples to explain the invention and to enable those skilled in the art to manufacture and use the invention. The specification thus written is not intended to limit the invention to the specific terms presented.

[0086] Accordingly, although the present invention has been described in detail with reference to the examples above, those skilled in the art may make modifications, changes, and variations to these examples without departing from the scope of the present invention. In short, it is stated that in order to achieve the intended effect of the present invention, it is not necessary to separately include all functional blocks shown in the drawings or to follow all sequences shown in the drawings exactly as shown; such matters may fall within the technical scope of the present invention as described in the claims even if they are not.

[0087] [Explanation of the symbol]

[0088] 100: Accident Scenario Generation System

[0089] 101: Information Processing Unit

[0090] 102: Scenario Generation Section

[0091] 103: Scenario Refinement Section

[0092] 104: Scenario Analysis Department

[0093] 105: Modification induction section

Claims

1. In an accident scenario generation system connected to a user terminal via a network, A data processing unit that receives development information from a user terminal and generates it as basic information; A scenario generation unit that stores execution information and generates accident scenario candidates by processing basic information based on the execution information; A scenario concretization unit that derives an accident scenario by concretizing accident scenario candidates; and An accident scenario generation system characterized by including a scenario analysis unit that analyzes accident scenarios and generates analysis information.

2. In Paragraph 1, An accident scenario generation system characterized by development information including development requirements and design models.

3. In Paragraph 1, An accident scenario generation system characterized by a scenario generation unit defining an analysis range from basic information, modeling a control structure, identifying unsafe control actions, and generating accident scenario candidates based on the identified unsafe control actions.

4. In Paragraph 3, An accident scenario generation system characterized by a control structure including a controller, a controlled process, a control action, and feedback.

5. In Paragraph 4, An accident scenario generation system characterized by a scenario generation unit identifying unsafe control actions using feedback among control actions.

6. In Paragraph 5, An accident scenario generation system characterized by a scenario concretization unit classifying accident scenario candidates by accident scenario case and deriving accident scenarios by concretizing the accident scenario candidates through combination with the classified accident scenario cases.

7. In Paragraph 6, An accident scenario generation system characterized by including at least one of the following accident scenario cases: a case where feedback is normal and the controller is unstable; a case where both feedback and the controller are unstable; a case where the controller is normal and the controlled process is unstable; and a case where the controller and the controlled process are normal and the controlled system is unstable.

8. In Paragraph 1, The Scenario Analysis Department analyzes accident scenarios using analysis elements based on Fault Tree Analysis (FTA) to generate analysis information, and An accident scenario generation system characterized by analysis information including a cutoff set, failure rate, and accident-inducing factors.

9. In paragraph 1, the accident scenario generation system, It further includes a modification induction unit that transmits mutually corresponding accident scenarios and analysis information to a user terminal, An accident scenario generation system characterized by modified information, which modifies development information considering accident scenarios and analysis information, being input into a user terminal, transmitted from the user terminal to an information processing unit, and generated as basic information by the information processing unit.

10. In paragraph 1, the accident scenario generation system, The system further includes a login unit that receives user login information from a user terminal and determines whether to allow the user's login by comparing the user login information with pre-registered user login confirmation information, The login unit displays eight contact areas arranged sequentially on the screen of the user terminal, randomly assigns eight different notes constituting a musical scale to each contact area, and when the user touches a contact area through the user terminal, the note assigned to the contacted contact area is output only through the earphones connected to the user terminal, and simultaneously performs a tone-color display step in which, after the user touches all eight contact areas and confirms the note assigned to each contact area, multiple different colors begin to be displayed in a random order at predetermined display time intervals on the contact area that the user touches again. The login unit performs a sound transmission step of receiving sound data corresponding to a sound assigned to the one contact area from a user terminal when the user presses the one contact area again for a predetermined time after a predetermined pause time has elapsed following contacting the one contact area once, and a color transmission step of receiving color data corresponding to a color displayed in the one contact area from a user terminal when the pressing for the predetermined time occurs. The login unit repeats the above-mentioned tone-color display step, the above-mentioned tone transmission step, and the above-mentioned color transmission step, but, The login unit performs an input data formation step in which it sequentially connects sound data transmitted from a user terminal through the sound transmission step to form sound input data, and sequentially connects color data transmitted from a user terminal through the color transmission step to form color input data. The login unit performs a sound data verification step to check whether sound registration data included in user login verification information pre-registered by the user matches sound input data, and performs a color data verification step to check whether color registration data included in user login verification information pre-registered by the user matches color input data. An accident scenario generation system characterized by a login unit that allows user login when the negative registration data and negative input data match in the negative data verification step, and when the color registration data and color input data match in the color data verification step.

Citation Information

Patent Citations

  • Simulator device

    JP2004021461A

  • Security event monitoring device, method, and program

    JP2013061794A

  • Digital twin control system and method

    JP2022161342A

  • Testing apparatus and method for mobile software

    KR1020100108000A

  • Software development and test automation framework

    KR102352162B1