Safety Assessment of Complex, Software-Intensive Systems

被引:14
作者
Leveson, Nancy G. [1 ]
Fleming, Cody Harrison [1 ]
Spencer, Melissa [1 ]
Thomas, John [1 ]
Wilkinson, Chris [2 ]
机构
[1] MIT, Cambridge, MA 02139 USA
[2] Honeywell Adv Technol, Phoenix, AZ USA
来源
SAE INTERNATIONAL JOURNAL OF AEROSPACE | 2012年 / 5卷 / 01期
关键词
Aircraft accidents - Air traffic control;
D O I
10.4271/2012-01-2134
中图分类号
V [航空、航天];
学科分类号
08 ; 0825 ;
摘要
This paper presents a new methodology for the safety assessment of complex software intensive systems such as is envisioned for the coming major upgrade of the air traffic management system known as NextGen. This methodology is based on a new, more inclusive model of accident causation called Systems Theoretic Accident Model and Process (STAMP) [1]. STAMP includes not just the standard component failure mechanisms but also the new ways that software and humans contribute to accidents in complex systems. A new hazard analysis method, called Systems Theoretic Process Analysis (STPA), is built on this theoretical foundation. The STPA is based on systems theory rather than reliability theory; it treats safety as a control problem rather than a failure problem with interactive and possibly nested control loops that may include humans. In this methodology, safety is assured by closed loop control of safety parameters. In the NextGen Concept of Operations, [2] many diverse ground and air systems will be tightly coupled leading to a greatly increased potential for the occurrence of safety critical events. The process described in this paper provides a rigorous, integrated and traceable safety analysis that improves upon the present somewhat ad-hoc multi-layered approach commonly used today. This process also improves upon the human-system interaction aspect of safety assessment, a topic that is not well covered in present certification practice. We illustrate the effectiveness of this new methodology by an analysis of the NextGen "In-Trail Procedure in Oceanic Airspace" (ITP) that is specified in RTCA DO-312 [3]. We show how STPA derives some additional safety requirements beyond those in the Operational Safety Analysis (OSA) of DO-312.
引用
收藏
页码:233 / 244
页数:12
相关论文
共 10 条
[1]  
FAA, 2010, INT POL GUID AUT DEP
[2]  
Fleming Cody Harrison, 2012, NASACR2012217553
[3]  
Heimdahl M. P. E., 1998, DIG AV SYST C 17 DAS
[4]  
Joint Program Development Office, 2009, OP CONC NEXT GEN AIR
[5]   A new accident model for engineering safer systems [J].
Leveson, N .
SAFETY SCIENCE, 2004, 42 (04) :237-270
[6]   Intent specifications: An approach to building human-centered specifications [J].
Leveson, NG .
IEEE TRANSACTIONS ON SOFTWARE ENGINEERING, 2000, 26 (01) :15-35
[7]  
Leveson NG, 2011, ENG SYST, P1
[8]   Intent specifications: An approach to building human-centered specifications [J].
Leveson, NG .
THIRD INTERNATIONAL CONFERENCE ON REQUIREMENTS ENGINEERING - PROCEEDINGS, 1998, :204-213
[9]  
RTCA, 2008, DO312 RTCA
[10]  
SAE Aerospace Recommended Practice, 1996, ARP4761 SAE