Interlocking Safety Cases for Unmanned Autonomous Systems in Shared Airspaces

被引:20
作者
Vierhauser, Michael [1 ]
Bayley, Sean [1 ]
Wyngaard, Jane [1 ]
Xiong, Wandi [3 ]
Cheng, Jinghui [2 ]
Huseman, Joshua [1 ]
Lutz, Robyn [3 ]
Cleland-Huang, Jane [1 ]
机构
[1] Univ Notre Dame, Dept Comp Sci & Engn, Notre Dame, IN 46556 USA
[2] Polythechn Montreal, Dept Comp Engn, Montreal, PQ H3T 1J4, Canada
[3] Iowa State Univ, Dept Comp Sci, Ames, IA 50011 USA
基金
奥地利科学基金会; 美国国家科学基金会;
关键词
Safety; Unmanned aerial vehicles; Monitoring; Runtime; Software; Atmospheric modeling; NASA; UAV; unmanned autonomous systems; safety assurance cases; monitoring; TRUST; REQUIREMENTS; CONSTRAINTS; CONFIDENCE; REPUTATION; UAVS;
D O I
10.1109/TSE.2019.2907595
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
The growing adoption of unmanned aerial vehicles (UAVs) for tasks such as eCommerce, aerial surveillance, and environmental monitoring introduces the need for new safety mechanisms in an increasingly cluttered airspace. In our work we thus emphasize safety issues that emerge at the intersection of infrastructures responsible for controlling the airspace, and the diverse UAVs operating in their space. We build on safety assurance cases (SAC) - a state-of-the-art solution for reasoning about safety - and propose a novel approach based on interlocking SACs. The infrastructure safety case (ISAC) specifies assumptions upon UAV behavior, while each UAV demonstrates compliance to the ISAC by presenting its own (pluggable) safety case (pSAC) which connects to the ISAC through a set of interlock points. To collect information on each UAV we enforce a "trust but monitor" policy, supported by runtime monitoring and an underlying reputation model. We evaluate our approach in three ways: first by developing ISACs for two UAV infrastructures, second by running simulations to evaluate end-to-end effectiveness, and finally via an outdoor field-study with physical UAVs. The results show that interlocking SACs can be effective for identifying, specifying, and monitoring safety-related constraints upon UAVs flying in a controlled airspace.
引用
收藏
页码:899 / 918
页数:20
相关论文
共 120 条
[1]   Automated Circular Assume-Guarantee Reasoning [J].
Abd Elkader, Karam ;
Grumberg, Orna ;
Pasareanu, Corina S. ;
Shoham, Sharon .
FM 2015: FORMAL METHODS, 2015, 9109 :23-39
[2]  
Adelard, 1998, ASCAD AD SAF CAS DEV
[3]  
American Red Cross, 2015, DRON DIS RESP REL OP
[4]  
Amorim Tiago, 2018, SOLUTIONS CYBER PHYS, P137, DOI DOI 10.4018/978-1-5225-2845-6
[5]  
[Anonymous], 2003, IC200350 EPFL
[6]  
[Anonymous], 2012, Experimentation in Software Engineering
[7]  
[Anonymous], 2015, NASATM2015218817
[8]  
[Anonymous], 2001, Technical Report
[9]  
[Anonymous], Object Constraint Language (OCL) Specification
[10]  
[Anonymous], 2017, ARDUPILOT