Automated Analysis of Reli liability Architecture
Fondazione Bruno Kessler Marco Bozzano, Alessandro Cimatti, and Cristian Mattarei Alpine Verification Meeting, 2013
Automated Analysis of Reli liability Architecture Fondazione Bruno - - PowerPoint PPT Presentation
Automated Analysis of Reli liability Architecture Fondazione Bruno Kessler Marco Bozzano, Alessandro Cimatti, and Cristian Mattarei Alpine Verification Meeting, 2013 Outline Architectural Design in Critical Systems Redundant systems
Fondazione Bruno Kessler Marco Bozzano, Alessandro Cimatti, and Cristian Mattarei Alpine Verification Meeting, 2013
2
4
5
6
7
8
𝑵𝟐 𝑵𝟑 𝑵𝟓 𝑵𝟒 𝑵𝟔 𝑵𝟕 Nominal architecture
[Abraham74]
9
𝑵𝟐 𝑵𝟑 𝑵𝟓 𝑵𝟒 𝑵𝟔 𝑵𝟕 Nominal architecture Redundant architecture
[Abraham74]
10
11
1 voter 2 voters 3 voters
12
[Hamamatsu10]
13
[Hamamatsu10]
14
[Hamamatsu10]
15
[Hamamatsu10]
16
Triple Redundant Module comparison (1 voter)
[Hamamatsu10]
17
Triple Redundant Module comparison (1 voter)
[Hamamatsu10]
19
20
21
using uninterpreted functions (e.g. x = y → 𝑔 𝑦 = 𝑔 𝑧 )
22
23
𝐺𝑈 𝐺, 𝑈𝑀𝐹 = {𝑔 ∈ 2𝐺|∃𝑗 ∈ 𝐽. 𝑈𝑀𝐹 𝑗, 𝑔 ∧ 𝑔 𝑗𝑡 𝑛𝑗𝑜𝑗𝑛𝑏𝑚} 𝑈𝑀𝐹 𝐽, 𝐺 = 𝑂𝑝𝑛𝑗𝑜𝑏𝑚 𝐽 ≠ 𝑆𝑓𝑒𝑣𝑜𝑒𝑏𝑜𝑢(𝐽, 𝐺)
24
𝐺𝑈 = 𝐺𝑁11 ∧ 𝐺𝑁12 ∨ 𝐺𝑁11 ∧ 𝐺𝑁13 ∨ ⋯ ∨ (𝐺𝑁23 ∧ 𝐺𝑊
2)
𝑮𝒏𝟐 𝑮𝒘 𝑮𝒏𝟒 𝑮𝒏𝟑 ⊤ ⊥ 𝑮𝒏𝟑
25
𝐺
𝑡𝑧𝑡 ∶ ℝ 0,1 × ⋯ × ℝ 0,1 ⟼ ℝ 0,1
BDD representation of the Fault Tree
𝑮𝒏𝟐 𝑮𝒘 𝑮𝒏𝟒 𝑮𝒏𝟑 ⊤ ⊥ 𝑮𝒏𝟑
26
𝑮𝒘 + 𝐺
𝑡𝑧𝑡 𝐺 𝑤, 𝐺𝑛1, 𝐺𝑛2, 𝐺𝑛3 =
𝐺
𝑡𝑧𝑡 ∶ ℝ 0,1 × ⋯ × ℝ 0,1 ⟼ ℝ 0,1
BDD representation of the Fault Tree
𝑮𝒏𝟐 𝑮𝒘 𝑮𝒏𝟒 𝑮𝒏𝟑 ⊤ ⊥ 𝑮𝒏𝟑
27
𝐺
𝑤 +
𝐺
𝑡𝑧𝑡 𝐺 𝑤, 𝐺𝑛1, 𝐺𝑛2, 𝐺𝑛3 =
+(𝟐 − 𝑮𝒘) ∗ 𝑮𝒏𝟐 ∗ 𝑮𝒏𝟑 +
𝐺
𝑡𝑧𝑡 ∶ ℝ 0,1 × ⋯ × ℝ 0,1 ⟼ ℝ 0,1
BDD representation of the Fault Tree
𝑮𝒏𝟐 𝑮𝒘 𝑮𝒏𝟒 𝑮𝒏𝟑 ⊤ ⊥ 𝑮𝒏𝟑
28
𝐺
𝑤 +
𝐺
𝑡𝑧𝑡 𝐺 𝑤, 𝐺𝑛1, 𝐺𝑛2, 𝐺𝑛3 =
+(1 − 𝐺
𝑤) ∗ 𝐺𝑛1 ∗ 𝐺𝑛2 +
+(𝟐 − 𝑮𝒘) ∗ 𝑮𝒏𝟐 ∗ (𝟐 − 𝑮𝒏𝟑) ∗ 𝑮𝒏𝟒 +
𝐺
𝑡𝑧𝑡 ∶ ℝ 0,1 × ⋯ × ℝ 0,1 ⟼ ℝ 0,1
BDD representation of the Fault Tree
𝑮𝒏𝟐 𝑮𝒘 𝑮𝒏𝟒 𝑮𝒏𝟑 ⊤ ⊥ 𝑮𝒏𝟑
29
𝐺
𝑤 +
𝐺
𝑡𝑧𝑡 𝐺 𝑤, 𝐺𝑛1, 𝐺𝑛2, 𝐺𝑛3 =
+(1 − 𝐺
𝑤) ∗ 𝐺𝑛1 ∗ 𝐺𝑛2 +
+(𝟐 − 𝑮𝒘) ∗ (𝟐 − 𝑮𝒏𝟐) ∗ 𝑮𝒏𝟑 ∗ 𝑮𝒏𝟒 +(1 − 𝐺
𝑤) ∗ 𝐺𝑛1 ∗ (1 − 𝐺𝑛2) ∗ 𝐺𝑛3 +
𝐺
𝑡𝑧𝑡 ∶ ℝ 0,1 × ⋯ × ℝ 0,1 ⟼ ℝ 0,1
BDD representation of the Fault Tree
𝑮𝒏𝟐 𝑮𝒘 𝑮𝒏𝟒 𝑮𝒏𝟑 ⊤ ⊥ 𝑮𝒏𝟑
30
𝐺
𝑤 +
𝐺
𝑡𝑧𝑡 𝐺 𝑤, 𝐺𝑛1, 𝐺𝑛2, 𝐺𝑛3 =
+(1 − 𝐺
𝑤) ∗ 𝐺𝑛1 ∗ 𝐺𝑛2 +
+(1 − 𝐺
𝑤) ∗ (1 − 𝐺𝑛1) ∗ 𝐺𝑛2 ∗ 𝐺𝑛3
+(1 − 𝐺
𝑤) ∗ 𝐺𝑛1 ∗ (1 − 𝐺𝑛2) ∗ 𝐺𝑛3 +
𝐺
𝑡𝑧𝑡 ∶ ℝ 0,1 × ⋯ × ℝ 0,1 ⟼ ℝ 0,1
BDD representation of the Fault Tree
31
32
33
34
35
𝐺
𝑡𝑧𝑡 = 𝐺 𝑤 + 3 ∗ 𝐺 𝑛 2 − 3 ∗ 𝐺 𝑤 ∗ 𝐺 𝑛 2 …
36
Triple Redundant Module comparison (1 voter)
e d c b a
1-Rv 1-Rm
𝐺
𝑡𝑧𝑡 = 𝐺 𝑤 + 3 ∗ 𝐺 𝑛 2 − 3 ∗ 𝐺 𝑤 ∗ 𝐺 𝑛 2 …
1 voter patterns comparison (2D) 1 voter patterns comparison (3D)
37
1 vs 2 voters comparison (2D) 1 vs 2 voters comparison (3D)
38
Varying 𝐺
𝑛 for 𝑁1 (1 voter)
Varying 𝐺
𝑤 for 𝑊 1 (2 voters)
39
41
Boolean Data
42
43
𝑄𝑝1 𝑝𝑜 = 𝑝1 𝑄𝑝2 𝑝𝑜 = 𝑝2 𝑄𝑝3 𝑝𝑜 = 𝑝3 … 𝑄𝑗2 𝑗𝑜1 = 𝑗21 𝑄𝑗3 𝑗𝑜1 = 𝑗31 … 𝑄𝑗1 𝑗𝑜1 = 𝑗11 𝑄𝑗4 𝑗𝑜2 = 𝑗12
44
… 𝐵1 𝑇1
𝐵
𝐷1 𝐺
1
= =
𝑄𝑝1 𝑝𝑜 = 𝑝1 𝑄𝑝2 𝑝𝑜 = 𝑝2 𝑄𝑝3 𝑝𝑜 = 𝑝3 … 𝑄𝑗2 𝑗𝑜1 = 𝑗21 𝑄𝑗3 𝑗𝑜1 = 𝑗31 … 𝑄𝑗1 𝑗𝑜1 = 𝑗11 𝑄𝑗4 𝑗𝑜2 = 𝑗12
45
… 𝐵1 𝑇1
𝐵
𝐷1 𝐺
1
= = … 𝐵2 𝑇2
𝐵
𝐷2 𝐺2
𝑄𝑝1 𝑝𝑜 = 𝑝1 𝑄𝑝2 𝑝𝑜 = 𝑝2 𝑄𝑝3 𝑝𝑜 = 𝑝3 … 𝑄𝑗2 𝑗𝑜1 = 𝑗21 𝑄𝑗3 𝑗𝑜1 = 𝑗31 … 𝑄𝑗1 𝑗𝑜1 = 𝑗11 𝑄𝑗4 𝑗𝑜2 = 𝑗12
46
… 𝐵1 𝑇1
𝐵
𝐷1 𝐺
1
= = … 𝐵2 𝑇2
𝐵
𝐷2 𝐺2 … 𝐵1 𝑇1
𝐵
… 𝑇2
𝐵
𝐷2 V
≠?
𝐺
1
𝐺2 = =
47
49
52
Automated Analysis of Reliability Architectures Marco Bozzano, Alessandro Cimatti and Cristian Mattarei In proc. of ICECCS 2013 Efficient Analysis of Reliability Architectures via Predicate Abstraction Marco Bozzano, Alessandro Cimatti and Cristian Mattarei Under review of FMCAD 2013
53
Cristian Mattarei Fondazione Bruno Kessler FBK ES-Group mattarei@fbk.eu