The safety of railway systems requires cooperation between many interdependent subsystems. As safety responsibilities are split between these subsystems, modeling cooperation, and conditional dependencies between subsystems become a central issue. This paper proposes the safety promise assessment method (SafePAM), an iterative approach to modeling these dependencies formally. SafePAM enriches the STPA - a structured hazard analysis technique based on systems theory - resulting in a formal description of dependencies provided by the promise theory. Together, this yields a flexible method of iterative refinement, which allows the embedding of novel system designs within their environment while upholding the overall system safety properties. In contrast to previous approaches, SafePAM permits integrating conditional dependencies within the model description without assuming pairwise independence between conditions. We evaluate the proposed method in a case study from the railway domain. We describe the system behavior based on promises that allow a seamless link between domain-specific properties and the system’s physical properties, enabling domain experts to validate the resulting model.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Towards a Novel Approach to Railway Safety Using STPA and Promise Theory

  • Felix Schaber,
  • Atif Mashkoor,
  • Michael Leuschel

摘要

The safety of railway systems requires cooperation between many interdependent subsystems. As safety responsibilities are split between these subsystems, modeling cooperation, and conditional dependencies between subsystems become a central issue. This paper proposes the safety promise assessment method (SafePAM), an iterative approach to modeling these dependencies formally. SafePAM enriches the STPA - a structured hazard analysis technique based on systems theory - resulting in a formal description of dependencies provided by the promise theory. Together, this yields a flexible method of iterative refinement, which allows the embedding of novel system designs within their environment while upholding the overall system safety properties. In contrast to previous approaches, SafePAM permits integrating conditional dependencies within the model description without assuming pairwise independence between conditions. We evaluate the proposed method in a case study from the railway domain. We describe the system behavior based on promises that allow a seamless link between domain-specific properties and the system’s physical properties, enabling domain experts to validate the resulting model.