Guided Safety Analysis for Cyber-Physical Systems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current tools for maintaining safety cases in software-intensive systems, particularly those interacting with Cyber-Physical Systems, face challenges in efficiently updating trace links and recertifying modified versions, leading to high costs and limited innovation due to the complexity of identifying changes and their safety impacts.

Innovation Solution

The Safety Artifact Forest Analysis (SAFA) method automatically identifies the impact of system-wide changes on previously certified safety assurance cases by generating delta views and providing actionable recommendations to update safety cases, using traceability paths and heuristics to visualize changes and highlight potential safety issues.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional traceability methods are used to maintain safety cases, then safety assurance is achieved, but the cost and effort of updating safety cases increases significantly

Engineering Contradiction:
Improvesafety assuranceVSAvoidcost and effort of updating safety cases
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system performs preliminary analysis by automatically generating artifact trees and comparing them across versions before full recertification is needed. This preliminary action identifies which safety case elements are actually impacted by changes, allowing organizations to focus resources only on those specific areas rather than performing complete recertification.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The safety case is segmented into discrete artifact trees that can be independently analyzed and compared. Each artifact tree represents a specific hazard and its mitigation artifacts, allowing selective updating of only those segments that are impacted by changes, rather than treating the entire safety case as a monolithic unit requiring full review.

Inventive Principle:
Principle #1Segmentation

2Reliability

If comprehensive traceability analysis is performed to identify all safety impacts, then safety is maintained, but the complexity of the process increases

Engineering Contradiction:
Improvesafety maintenanceVSAvoidcomplexity of traceability analysis
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system introduces an intermediary automated analysis layer that sits between the source code/artifact changes and the safety case updates. This intermediary automatically generates artifact trees, performs comparisons, and identifies impacted safety elements, transforming a complex manual analysis process into a standardized automated procedure.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The manual mechanical process of tracing through artifacts and identifying safety impacts is replaced with an automated computational system. The electronic processor automatically generates artifact trees, compares versions, and produces delta views, substituting human manual analysis with algorithmic processing.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If the entire safety case is recertified for every system modification, then safety is ensured, but innovation is limited due to high recertification costs

Engineering Contradiction:
Improvesafety certificationVSAvoidability to innovate and release new features
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

Instead of performing complete recertification (excessive action), the system performs partial analysis focused only on the specific artifact trees and safety elements that are actually impacted by changes. This partial action is sufficient to ensure safety for modified portions while avoiding the unnecessary overhead of full recertification.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The system provides feedback through delta views that clearly show which safety case elements are impacted by changes. This feedback mechanism enables safety analysts to make informed decisions about which areas require attention, creating a responsive system that adapts the recertification scope to the actual changes made.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11593097B2Guided safety analysis for cyber physical systems
Publication Date: 2023.02.28 UNIV OF NOTRE DAME DU LAC
  • US11593097B2 patent drawing
  • US11593097B2 patent drawing
  • US11593097B2 patent drawing

AI summary

Systems and methods for maintaining the safety of a software-based system. One method includes automatically generating a first artifact tree for a hazard for a first version of the system and automatically transforming the first artifact tree into a first augmented tree using a set of heuristics. The method also includes automatically generating a second artifact tree for the hazard for a second version of the system and automatically transforming the second artifact tree for the hazard into a second augmented tree using the set of heuristics. The method further includes automatically comparing the first augmented tree and the second augmented tree to generate a delta view, and automatically generating, based on the delta view, at least one selected from a group consisting of a safety warning for the second version of the software-based system and an actionable recommendation to maintain safety of the second version of the software-based system.