Cyber-Physical System Safety Certification via Optimal Data Subset Selection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The certification of cyber-physical systems (CPS) is hindered by uncertainties in AI subcomponents, leading to unpredictable safety consequences due to non-determinism, and existing model-based design workflows fail to adequately address these complexities, particularly in safety-critical systems where post-market reviews and usage data are not timely incorporated, resulting in potential fatal failures.

Innovation Solution

A computer-implemented system that models the certification process as a cooperative game between manufacturer and certifier agents to determine an optimal subset of operating data for disclosure, using model reconstruction techniques to ensure accurate safety evaluation while minimizing risks and costs, iteratively refining the data selection to maximize the probability of affirmative safety certification.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If full operating data is disclosed during safety certification, then certification accuracy and reliability are improved, but disclosure costs, time, and risks increase

Engineering Contradiction:
Improvesafety certification reliabilityVSAvoidcertification time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system extracts only the most relevant and critical operating data from the complete dataset through automated analysis. The certification system identifies and selects specific data subsets that are sufficient for safety evaluation, excluding unnecessary information. This extraction approach maintains certification reliability while reducing disclosure time and costs.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The operating data is segmented into different categories and priority levels based on safety criticality. The system divides the comprehensive data set into essential safety-related portions and optional supplementary portions, allowing certifiers to focus on high-priority segments first. This segmentation enables phased review processes that reduce overall certification time while maintaining thoroughness.

Inventive Principle:
Principle #1Segmentation

2Measurement precision

If comprehensive operating data is disclosed, then safety evaluation accuracy is improved, but disclosure costs and human risks increase

Engineering Contradiction:
Improvesafety evaluation accuracyVSAvoiddisclosure risks
Core Design Contradiction:
Measurement precisionVSObject-generated harmful factors

Solution Approach 1:

The system automatically extracts only the essential safety-critical data elements needed for accurate evaluation, filtering out non-essential information that would increase disclosure risks without adding value to safety assessment. This targeted extraction maintains measurement precision while minimizing harmful disclosure effects.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The automated certification system acts as an intermediary that processes and analyzes data before presentation to human certifiers. This intermediary layer protects against direct exposure to sensitive raw data while ensuring accurate safety evaluation through systematic analysis, reducing both disclosure risks and human error.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of manufacture

If traditional model-based design workflows are used, then development cost is reduced, but they fail to address AI uncertainty and complex interactions

Engineering Contradiction:
Improvedevelopment costVSAvoidsafety certification reliability
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The system introduces an automated data analysis intermediary that bridges traditional model-based design and modern AI-enabled CPS certification. This intermediary automatically processes operating data to validate AI subcomponent behavior and component interactions, maintaining cost-effectiveness while significantly improving safety certification reliability through systematic analysis of uncertainty and complex scenarios.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If all operating data is analyzed, then complete safety assessment is achieved, but processing time and computational resources increase

Engineering Contradiction:
Improvesafety assessment completenessVSAvoidcertification efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The automated analysis system extracts and prioritizes only the most safety-critical data patterns and anomalies from the complete operating dataset. By identifying and focusing on high-impact data elements rather than uniformly processing all data, the system achieves comprehensive safety assessment while significantly improving certification efficiency and reducing processing time.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system implements periodic or phased analysis of operating data, starting with critical safety parameters and progressively analyzing additional data layers only if needed. This staged approach allows rapid initial assessment of safety status while maintaining the option for deeper analysis, thereby improving overall certification efficiency without compromising completeness.

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS20230024036A1Systems and methods for optimizing risk and time in safety certification of cyber-physical systems
Publication Date: 2023.01.26 THE ARIZONA BOARD OF REGENTS ON BEHALF OF THE UNIV OF ARIZONA
  • US20230024036A1 patent drawing
  • US20230024036A1 patent drawing
  • US20230024036A1 patent drawing

AI summary

Safety certification of cyber-physical system (CPS) such as autonomous cars or medical control systems are complicated especially due to the lack of transparency between the manufacturer and certifying authority. The manufacturer has significant restrictions in sharing knowledge with the certification authority. Further, given time constraints, it may not be feasible for the certification authority to examine internal details of the CPS. A system models the safety certification of CPS as an agile iterative game, where a manufacturer agent acting on behalf of the manufacturer and a certifier agent acting on behalf of a third-party certification entity aims to find an optimal subset of operating data to share for accurate safety certification. The certification agent, armed with CPS model mining methods and safety assessment analysis tools, aims to accurately assess safety of the CPS with the information shared.