STPA Hazard Analysis Using Concur Task Tree and Guide Word Mapping

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional hazard analysis methods for software control systems, such as STPA, are incomplete and dependent on guide words, leading to potential omissions in hazard detection and reduced accuracy in determining safety constraints, which is insufficient for complex systems with high potential hazards.

Innovation Solution

The method involves determining attribute and function demands of the system using a use case diagram, analyzing tasks with Concur Task Tree (CTT) to generate a hierarchical relation of control flow, and using a guide word mapping table to identify hazards and generate safety constraints, thereby enhancing the accuracy and completeness of hazard analysis.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If conventional STPA method is used for hazard analysis, then the analysis process is simple and guide words are provided, but the accuracy and completeness of hazard detection are reduced due to dependency on guide words and incomplete control order detection

Engineering Contradiction:
Improveease of hazard analysis operationVSAvoidaccuracy of hazard detection
Core Design Contradiction:
Ease of operationVSMeasurement precision

Solution Approach 1:

The patent introduces an intermediary computational model that acts as a bridge between the guide words and the control structure map. This model automatically detects incomplete control orders by analyzing the logical relationships in the control structure, rather than relying solely on manual guide word application. The intermediary processing step transforms the qualitative guide word approach into a more systematic and accurate automated analysis process.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If conventional STPA method is used for hazard analysis, then the analysis process is straightforward, but the completion of safety constraint determination is reduced due to incomplete hazard detection

Engineering Contradiction:
Improveproductivity of hazard analysisVSAvoidcompleteness of safety constraint determination
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent implements a feedback mechanism where the computational model continuously analyzes the control structure map and compares detected control orders against the specified control requirements. When incomplete or incorrect control orders are identified, the system feeds this information back to refine the hazard analysis and generate more comprehensive safety constraints. This iterative feedback process ensures that the analysis becomes more complete and reliable with each cycle.

Inventive Principle:
Principle #23Feedback

3Ease of manufacture

If manual guide word-based STPA is used, then the method is easy to implement, but the accuracy of determining safety constraints is reduced due to analyzer's knowledge and experience dependency

Engineering Contradiction:
Improveease of implementationVSAvoidaccuracy of safety constraint determination
Core Design Contradiction:
Ease of manufactureVSMeasurement precision

Solution Approach 1:

The patent enables the hazard analysis system to serve itself by automatically generating the computational model from the control structure map without requiring extensive manual intervention or expert knowledge. The system self-analyzes the control logic, automatically identifies incomplete control orders, and generates safety constraints based on the detected issues. This self-service capability reduces dependency on analyzer expertise while maintaining ease of implementation.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10496083B2Method and apparatus for analyzing hazard, and computer readable recording medium
Publication Date: 2019.12.03 SANGMYUNG UNIV SEOUL IND ACAD COOP FOUND
  • US10496083B2 patent drawing
  • US10496083B2 patent drawing
  • US10496083B2 patent drawing

AI summary

A method of analyzing a hazard of a software control system which is operated by a computer and based on STPA (System Theoretic Process Analysis) is provided. The method includes determining an attribute and function demands of the system, analyzing tasks of the system based on the determined attribute and the function demands, generating specification of a relation between the tasks using CTT (Concur Task Tree) method, the CTT method representing a hierarchical relation of a control flow between the tasks, determining at least one of the hazard of the system based on the specification and generating a safety constraint of the system based on the determined hazard. The determining at least one of the hazard of the system uses a guide word mapping table of CTT based STPA.