Using STAMP/STPA to Chinese High Speed Railway Train Control System
|
|
|
- Justin Welch
- 9 years ago
- Views:
Transcription
1 Using STAMP/STPA to Chinese High Speed Railway Train Control System Liu Jintao,Ph.D. candidate State Key Laboratory of Rail Traffic Control and Safety Beijing Jiaotong University
2 Outline Background and Motivation Train control system in requirements phase Hazard analysis on train control system Some ideas in using STPA in requirements phase Internal Function Modules in Control Loops Causal Factors Formal model-based Causal Factors Analysis Case study : Chinese Train Control System Chinese High Speed Railway Train Control System Perform STPA on study case Conclusion
3 Background and Motivation What is train control system? To separate and protect train against collision and derailment. Train Control V 80km/h Real speed Line limit speed Permitted speed Infrastructure Train S S AT VCC S S Safety braking distance S S AT RCC S S Sep German High-Speed Maglev Accident. 23 people dead, 10 injured. Apr China JiaoJi Railway Accident.. 72 people dead, 416 injured. Jul China YongWen Railway Accident. 40 people dead, 200 injured. Train Control System is Safety-Critical
4 Background and Motivation Main features of Train Control System in the Requirements Phase In requirements phase of train control system lifecycle, the system is specified in system requirements specification (SRS). - Described in natural language - Refinement of functional requirements on technical level (A set of function modules and their inputs/outputs)
5 Background and Motivation Hazard Analysis on Train Control System in the Requirements Phase As the basis of system design and development, train control system depicted in SRS shall be analyzed to identify the hazardous factors that lead to the system hazard. According to these hazardous factors, we could further improve the SRS, and establish the safety requirements.
6 Background and Motivation Why and How to use STAMP/STPA Event Chain can not effectively help to analyze the hazardous factors. Specifically Not Repeat the Benefits of STPA Step1: Identify unsafe control actions Step2: Identify causal factors Causal factors focused by STPA are related to the control algorithm, the process model and so on. The system in requirements phase is described in natural language, for which the formal description is more accurate way. Considering such two aspects, we propose some ideas to customize the specific implementation of STPA.
7 Outline Background and Motivation Train control system in requirements phase Hazard analysis on train control system Some ideas in using STPA in requirements phase Internal Function Modules in Control Loops Causal Factors Formal model-based Causal Factors Analysis Case study : Chinese Train Control System Chinese High Speed Railway Train Control System Perform STPA on study case Conclusion
8 Some ideas in using STPA in requirements phase Internal Function Modules in Control Loops Step 1: activity F1 a, activity F2 b; Step 2: activity F3 c; Step 3: activity F4 d, activity F5 e;... Inputs Internal function module F1 Step 2 Internal function module F3 Step 1 Internal function module F2 Controller Internal function module F4 Step 3 Internal function module F5 Outputs
9 Some ideas in using STPA in requirements phase Internal Function Modules in Control Loops We describe the internal function modules and their inputs/outputs in the controller using the form of lists. Inputs Internal function module F1 Internal function module F3 Internal Function Internal function module F2 F1 Controller Modules in Controller F2 F3 Input: Internal function Output: module Input: F4 Output: Input: Output: Inputs/Outputs Internal function module F5 Outputs
10 Some ideas in using STPA in requirements phase Causal Factors Map the control algorithm-related and process model-related issues into the layer of function modules and their inputs. Inputs of internal function modules in controller is incorrect, missing, or not updated in time Flaw(s) in engineering process Flaw(s) in updating process Incorrect data entered by human Internal function modules in controller fail Flaw(s) in creation process Incorrect modification a) We identify the inputs-related causal factors with manual analysis. b) We identify the function modulerelated issues with formal method.
11 Some ideas in using STPA in requirements phase Formal model-based Causal Factors Analysis Behavior Model Functional Failure Model Step1: Find all possible internal functional failures according to the list of controller. Definition 1 The Functional Failure Description Notation (FFDN) consists of the representing characters of <C, M, F, D, S, f, A >, where, Step2: Model the normal behavior with Hybrid Automata 1) Unsafe C refers to a finite set of system components; Integrated 2) Control M refers to a finite set of failure description modules of system components, for i C, M Model i is Actions the failure description module of component i, and is also called FFDN module; 3) F= {F 1, F 2 F n } refers to a finite set of possible functional failures of a system component; failures with FFDN 4) D= {D 1_dev, D 2_dev D n_dev } refers to a finite set of the data deviations resulted by the functional failures, for m, k C and m k, D Function modulesrelated causal factors m D k = ; 5) S= {S 1, S 2 S n } refers to the set of states affected by functional failures, and S S, where the S is the set of states of the normal behavior model; above leading to UCAs 6) f : F D S refers to the mapping relationships between F and D, and F and S, where f={f D, f S }; 7) A= {f D (F), f S (F)} refers to the influence of functional failures, where f D (F) refers to the influence monitor. of functional failures on the data and f S (F) refers to the influence of functional failures on the states. Step3: Model the internal functional Definition 2 (Monitor). The fault events monitor is a structure M=(S, A, f,init),where, S={s 1, s Step4: 2 s Integrate n } is the sets of states these two models of the monitor, A= {a 1, a 2 a n } is the sets of fault events in the PHAVer model, f : A S is the mapping function from A to S, Init=S Step5: Analyze the internal function 0 is the sets of initial states of the fault events modules-related causal factors with the tool PHAVer
12 Outline Background and Motivation Train control system in requirements phase Hazard analysis on train control system Some ideas in using STPA in requirements phase Internal Function Modules in Control Loops Causal Factors Formal model-based Causal Factors Analysis Case study : Chinese Train Control System Chinese High Speed Railway Train Control System Perform STPA on study case Conclusion
13 Case Study Chinese High Speed Railway Train Control System One typical hazard of the system is considered: The train control system does not protect the train against exceedance of the safe speed limits. Train1 The hazard can be traced to one system-level safety constraint that mitigates the hazard: The train control system shall make impossible the violation of the safe speed limits. Reference structure of the system
14 Case Study Control Structure We take vital computer as example to illustrate the list containing internal function modules and inputs/outputs. Internal Function Modules in Vital Computer 1 Supervision and protection 2 Train properties handling 3 Data provision 4 Emergency handling Inputs/Outputs Input: Track description, Train data, System data, Location data, MA data, Emergency stop location, Session status Output: Train order, MA request Input: Driver input, Location data Output: Train data, Train integrity status, Position report Input: Track description, MA data, System data The down arrows represent the Output: Track description, MA data, System data control actions, and the up Input: Emergency message, Revocation arrows of represent emergency the message feedbacks. Output: Emergency stop location, The Acknowledgement horizontal arrows of represent emergency stop the information interaction.
15 Case Study Step1: Unsafe Control Actions (UCAs) Type UCAs Scenarios Refined safety constraints A required control action is not provided or is inadequately executed An incorrect or unsafe control action is provided. A potentially correct or adequate control action is provided at the wrong time UCA1.1 The train in over-speed doesn t receive the brake command from the VC. UCA1.2 The VC doesn t receive the emergency message from the RBC. UCA1.3 The VC doesn t receive the route information or the speed restriction. UCA2.1 The RBC provides an incorrect MA for the VC. UCA2.2 Both RBC and balise provide incorrect route information and speed restriction. UCA2.3 The driver inputs incorrect train data into the VC. UCA2.4 The driver accelerates the train. UCA3.1 The VC sends the brake command to the train too late. UCA3.2 The RBC shortens a given MA too late when necessary. UCA3.3 The driver releases the emergency brake too early. The speed of train have been exceeded the speed limitation. The emergency situations happened. The route has the fixed speed limit. When VC requests the MA or the MA is sent periodically. The route has the fixed speed limit. When driver started the train. When the speed is close to the speed restriction The speed of train have been exceeded the speed limitation. When the route has been changed in some situations. The train has not been stopped completely. The train shall receive the brake command when the speed of train have been exceeded the speed limitation. The VC shall receive the emergency message in emergency situations. The VC shall receive the route information and the speed restriction The RBC shall provide the correct MA for the VC. Type UCAs Scenarios Refined safety constraints A required control action is not provided or is inadequately executed UCA1.1 The train in over-speed doesn t receive the brake command from the VC. The speed of train have been exceeded the speed limitation. The train shall receive the brake command when the speed of train have been exceeded the speed limitation. Both RBC and balise shall provide correct route information and speed restriction. The driver shall input correct train data into the VC The driver shall not accelerate the train without considering the speed restriction. The VC shall send the brake command to the train in time. The RBC shall shorten a given MA in time. The driver shall release the emergency brake when the train has stopped. Hazard: The train exceeds the safe speed limits.
16 Case Study Step2A: Inputs-related Causal Factors Unsafe control actions (UCA) UCA1.1 The train in over-speed doesn t receive the brake command from the VC. UCA1.2 The VC doesn t receive the emergency message from the RBC. Inputs-related causal factors(icf)leading to unsafe control actions ICF1.1.1: The actual speed used to compare with the speed restriction in the VC is incorrect. ICF1.1.2: The train data (e.g. train category, braking model, etc.) used for speed profile is incorrect. ICF1.1.3: The system data used to select brake commands in the VC is incorrect. ICF1.1.4: The emergency stop location in the VC is missing. ICF1.2.1: The emergency situation which shall be known by the RBC is incorrect or missing. ICF1.2.2: The end of authority (EOA) used to evaluate emergency in the RBC is incorrect. ICF1.2.3: The location data received by the RBC is incorrect. UCA1.3 The VC doesn t receive the route information or the speed restriction. Unsafe control actions (UCA) UCA2.1 The RBC provides an incorrect MA for the VC. UCA2.2 Both RBC and balise provide incorrect route information and speed restriction. UCA1.1 The train in over-speed doesn t receive the brake command from the VC. UCA2.3 The driver inputs incorrect train data into the VC. UCA2.4 The driver accelerates the train. UCA3.1 The VC sends the brake command to the train too late. UCA3.2 The RBC shortens a given MA too late when necessary. ICF1.3.1: The route information and the speed restriction stored in both balise and RBC are missing. Inputs-related causal factors leading to unsafe control actions ICF2.1.1: The location data used to generate the MA is incorrect. ICF2.1.2: The route information used to generate the MA is incorrect. ICF2.1.3: The train data received by the RBC is incorrect. ICF1.1.1: The actual speed used to compare with the speed ICF2.2.1: The route information and the speed restriction both balise and RBC are incorrect. restriction in the VC is incorrect. ICF1.1.2: ICF2.3.1: The The train train data known (e.g. by the train driver is category, incorrect. braking model, etc.) used for speed profile is incorrect. ICF2.4.1: The permit speed and the target speed displayed to the driver are incorrect. ICF1.1.3: ICF2.4.2: The The system actual speed data or the used location data to select displayed to brake the driver commands is incorrect. in the VC is incorrect. ICF1.1.4: The emergency stop location in the VC is missing. ICF3.1.1: The actual speed or the location data used to determine the braking time is incorrect. ICF3.1.2: The EOA or the speed restriction used for the calculation of speed profile is incorrect. ICF3.1.3: The train data used to determine the braking time is incorrect. ICF3.2.1: The route information in the RBC is not updated in time. ICF3.2.2: The location data in the RBC is not updated in time. UCA3.3 The driver releases the emergency brake too early. ICF3.3.1: The current speed provided by the DMI is incorrect.
17 Case Study Step2B: Formal Model-based Causal Factors Analysis
18 Case Study Step2B: Formal Model-based Causal Factors Analysis Unsafe control actions (UCA) UCA1.1V>Vmrsp+dv_sbi&Order_reqSB=0 or Lc>EOA&Order_reqSB=0 Unsafe control actions (UCA) UCA1.2 Emsituation=1&MesgGot=0 UCA1.3 MesgGot=0&BTM_BMsg=0&RouteInfor=1 &BaliseInfor=1 UCA1.1 The train in over-speed doesn t receive the brake command from the VC. UCA2.1 MesgSent=1&MesgGot=1&MesgCorrect=0 UCA1.2 The VC doesn t receive the emergency message from the RBC. Unsafe control actions UCA2.2 RouteInfor=1&BaliseInfor=1&MesgGot=1& BTM_BMsg=1&MesgCorrect=0&BMesgCorrect=0 UCA1.3 The VC doesn t receive the route information or the speed restriction. UCA2.3 Input=1&DMI_TD=1&DataCorrect=0 UCA2.1 The RBC provides an incorrect MA for UCA1.1V>Vmrsp+dv_sbi&Order_reqS the VC. B=0 or Lc>EOA&Order_reqSB=0 UCA2.4 V>Vmrsp+dv_sbi&Acc=1 or Lc>EOA&Acc=1 UCA3.1 Order_reqSB=0&t_Delay2=tnormal2 UCA2.2 Both RBC and balise provide incorrect route information and speed restriction. UCA3.2 t1_rbc=tnormal4&mesgsent=0 UCA2.3 The driver inputs incorrect train data into the VC. UCA3.3 V>0& Order_reqEB=1&RelEB=1 UCA2.4 The driver accelerates the train. Function module-related causal factors leading to unsafe control actions {F_SDU_3, F_VC_11},{F_VC_3},{F_VC_8}, {F_VC_9},{F_VC_12},{F_VC_14},{F_VC_15}, {F_VC_17},{F_TIU_1},{F_SDU_1} Inputs-related causal factors(icf)leading to unsafe control actions {F_RBC_5},{F_RBC_6},{F_RBC_11},{F_RTM_2} {F_RBC_11, F_Balise_2},{F_RTM_2, F_BTM_3}, {F_RTM_2, F_BTM_1} ICF1.1.1: The actual speed used to compare with the speed restriction in the VC is incorrect. ICF1.1.2: The train data (e.g. train category, braking model, etc.) used for speed profile is incorrect. ICF1.1.3: The system data used to select brake commands in the VC is incorrect. ICF1.1.4: The emergency stop location in the VC is missing. {F_RTM_5, F_VC_2, F_RBC_1} Function module-related causal factors leading to unsafe control actions ICF1.2.1: The emergency situation which shall be known by the RBC is incorrect or missing. ICF1.2.2: The end of authority (EOA) used to evaluate emergency in the RBC is incorrect. ICF1.2.3: The location data received by the RBC is incorrect. {F_RBC_2, F_Balise_1},{F_RTM_5, F_VC_2}, {F_BTM_2, F_VC_2} ICF1.3.1: The route information and the speed restriction stored in both balise and RBC are missing. {F_Driver_1},{F_DMI_1} {F_SDU_3, F_VC_11},{F_VC_3},{F_VC_8}, {F_VC_9},{F_VC_12},{F_VC_14},{F_VC_1 5}, {F_VC_17},{F_TIU_1},{F_SDU_1} ICF2.1.1: The location data used to generate the MA is incorrect. ICF2.1.2: The route information used to generate the MA is incorrect. ICF2.1.3: The train data received by the RBC is incorrect. {F_Driver_2},{F_DMI_2},{F_DMI_3},{F_Driver_4} {F_VC_16},{F_VC_18},{F_TIU_5} ICF2.2.1: The route information and the speed restriction in both balise and RBC are incorrect. {F_RBC_12},{F_RTM_6},{F_RBC_6} ICF2.3.1: The train data known by the driver is incorrect. {F_Driver_3},{F_DMI_2} ICF2.4.1: The permit speed and the target speed displayed to the driver are incorrect. ICF2.4.2: The actual speed or the location data displayed to the driver is incorrect.
19 Case Study Comparison with traditional analysis Analysis using FTA Inputs-related issues leading to the hazard are hard to analyze in detail. For example, incorrect data to trackside constituents Some failures identified are mistaken for the single points of failures. For example, SDU fail to determine the distance {F_SDU_3} Once the hazard changes, the analysis needs to be performed all over again from the beginning to the end Analysis using STPA Inputs-related control flaws identified with the STPA method are more detailed, (missing, incorrect or not updating in time) Results are more complete. For example, {F_SDU_3, F_VC_11} Hierarchical control structure and the behavior models can be reused for analyzing another hazard as long as the system remains unchanged
20 Outline Background and Motivation Train control system in requirements phase Hazard analysis on train control system Some ideas in using STPA in requirements phase Internal Function Modules in Control Loops Causal Factors Formal model-based Causal Factors Analysis Case study : Chinese Train Control System Chinese High Speed Railway Train Control System Perform STPA on study case Conclusion
21 Conclusion We found that STAMP/STPA is extremely useful for the train control system. We showed the specific implementation of STPA in the hazard analysis of train control system in requirements phase. Future work is suggested that more study should be carried out on identification of inputs-related causal factors with the formal methods.
22 Q&A Thank you! State Key Laboratory of Rail Traffic Control and Safety Beijing Jiaotong University, Beijing, China
Using STAMP to analysis Chinese High Speed Railway Accident --7.23 Yong-wen Railway Accident
Using STAMP to analysis Chinese High Speed Railway Accident --7.23 Yong-wen Railway Accident Lecturer: Li Chenling, Ph.D. candidate State Key Lab. of Rail Traffic Control and Safety Beijing Jiaotong University,
APPLICATION OF CAST AND STPA TO RAILROAD SAFETY IN CHINA. Airong Dong
APPLICATION OF CAST AND STPA TO RAILROAD SAFETY IN CHINA by Airong Dong Bachelor in Engineering, Communications and Information System, Dalian Maritime University (1997) Master in Engineering, Communications
A Comprehensive Safety Engineering Approach for Software Intensive Systems based on STPA
www.uni-stuttgart.de A Comprehensive Safety Engineering Approach for Software Intensive Systems based on STPA STPA-based Approach STPA Safety Analysis Asim Abdulkhaleq, Ph.D Candidate Institute of Software
ERTMS/ETCS Configuration Management
ERTMS/ETCS Configuration Management Bernhard Stamm Siemens Transportation Systems Nick Cory Bombardier Transportation 1 Configuration Management What is it? What to? Why? How? When? Who does it? 2 Configuration
Safety Driven Design with UML and STPA M. Rejzek, S. Krauss, Ch. Hilbes. Fourth STAMP Workshop, March 23-26, 2015, MIT Boston
Safety Driven Design with UML and STPA M. Rejzek, S. Krauss, Ch. Hilbes System and Safety Engineering A typical situation: Safety Engineer System Engineer / Developer Safety Case Product 2 System and Safety
Comparison of Risk Analysis Methodologies in an Electrical Grid. Svana Helen Björnsdóttir STAMP Workshop in Amsterdam October 4-6, 2015
Comparison of Risk Analysis Methodologies in an Electrical Grid Svana Helen Björnsdóttir STAMP Workshop in Amsterdam October 4-6, 2015 INTRODUCTION S.H.Bjornsdottir Stiki/Reykjavik University 2 Aim of
Using STAMP to analyze serious accidents in China railway system
Using STAMP to analyze serious accidents in China railway system Liu Hong Huahzong University of Science and Technology, China Nextrans Center, Purdue University 2013.03.27 China railway system Total railway
CTCS Chinese Train Control System
CTCS Chinese Train Control System B. Ning, T. Tang, K. Qiu, C. Gao & Q. Wang Department of Control Engineering, School of Electronics and Information Engineering, Northern Jiaotong University, P. R. China
ERTMS/ETCS. Functional Requirements Specification FRS
ERTMS/ETCS Functional Requirements Specification FRS Version 5.00 Dated 21 June 2007 Filing number ERA/ERTMS/003204 Version No. Amendments Date Not known The amendments of this document have 08/11/94 been
Railway Business Strategy and R&D in Europe
Railway Business Strategy and R&D in Europe Hitachi Review Vol. 61 (2012), No. 5 190 Keith Jordan Yoichi Sugita, Dr. Eng. Takayoshi Nishino Toshiaki Kono Kiyoshi Morita OVERVIEW: Hitachi s European railway
BENEFIT OF DYNAMIC USE CASES TO EARLY DESIGN A DRIVING ASSISTANCE SYSTEM FOR PEDESTRIAN/TRUCK COLLISION AVOIDANCE
BENEFIT OF DYNAMIC USE CASES TO EARLY DESIGN A DRIVING ASSISTANCE SYSTEM FOR PEDESTRIAN/TRUCK COLLISION AVOIDANCE Hélène Tattegrain, Arnaud Bonnard, Benoit Mathern, LESCOT, INRETS France Paper Number 09-0489
The Shanghai Maglev Route
The Shanghai Maglev Route 1 Contents 1. About the Shanghai Maglev... 3 2. Background information about EMS Technology... 4 3. Your train... 5 3.1 Getting to know the cab... 5 3.2 Central DMI screen additional
Multiagent Control of Traffic Signals Vision Document 2.0. Vision Document. For Multiagent Control of Traffic Signals. Version 2.0
Vision Document For Multiagent Control of Traffic Signals Version 2.0 Submitted in partial fulfillment of the requirements of the degree of MSE Bryan Nehl CIS 895 MSE Project Kansas State University Page
Risk Analysis of a CBTC Signaling System
Risk Analysis of a CBTC Signaling System João Batista Camargo Jr. 1, Jorge Rady de Almeida Jr. 1, Paulo Sérgio Cugnasca 1 1 Escola Politécnica da Universidade de São Paulo, São Paulo-SP, Brazil Abstract
Managing Design Changes using Safety-Guided Design for a Safety Critical Automotive System
Managing Design Changes using Safety-Guided Design for a Safety Critical Automotive System by John Sgueglia B.S. Electrical Engineering Rochester Institute of Technology, 2000 SUBMITTED TO THE SYSTEM DESIGN
Thameslink Desiro City & Signalling Press Trip April 20 to 21, 2015 Evolution in Motion. Siemens Mobility Division
Thameslink Desiro City & Signalling Press Trip April 20 to 21, 2015 Evolution in Motion Siemens Rolling Stock Portfolio in Great Britain We have some of the most reliable trains in UK.. Over 350 trains
Appendix A. About RailSys 3.0. A.1 Introduction
Appendix A About RailSys 3.0 This appendix describes the software system for analysis RailSys used to carry out the different computational experiments and scenario designing required for the research
University of Paderborn Software Engineering Group II-25. Dr. Holger Giese. University of Paderborn Software Engineering Group. External facilities
II.2 Life Cycle and Safety Safety Life Cycle: The necessary activities involving safety-related systems, occurring during a period of time that starts at the concept phase of a project and finishes when
Lineside Signal Spacing and Speed Signage
Document to be withdrawn as of 03/12/11 To be superseded by GKRT0075 Iss 2 published on 03/09/11 Date March 11 Lineside Signal Spacing and Speed Synopsis This document specifies the minimum distances that
SFTA, SFMECA AND STPA APPLIED TO BRAZILIAN SPACE SOFTWARE
SFTA, SFMECA AND STPA APPLIED TO BRAZILIAN SPACE SOFTWARE Carlos H N Lahoz Instituto de Aeronautica e Espaco (IAE) Instituto Tecnologico da Aeronautica(ITA) BRAZIL STAMP/STAP Workshop 2014 25-27 March2014-MIT
3 RBC INTERFACE TO INTERLOCKINGS IN FINLAND
RBC INTERFACE TO CURRENT INTERLOCKINGS IN FINLAND Laura Järvinen, M.Sc (Tech), VR Track Oy Lassi Matikainen, M.Sc. (Tech), VR Track Oy SUMMARY The signalling systems in Finland originate from many decades
Railway Crossing Information System
Railway Crossing Information System ITS Canada Presentation June 2, 2014 Ian Steele, P.Eng Agenda Click to edit Master title style RBRC Program Project Background Concept of Operations Design Process Design
AUTOMATIC TRAIN OPERATION: THE MANDATORY IMPROVEMENT FOR ETCS APPLICATIONS
AUTOMATIC TRAIN OPERATION: THE MANDATORY IMPROVEMENT FOR ETCS APPLICATIONS Benoit Bienfait and Patrick Zoetardt, Alstom Transport, Belgium Bob Barnard, Signalling Solutions Ltd, UK SUMMARY European Main
Railway Research and Technology in China Today
Railway Research and Technology in China Today Lan Wang China Academy of Railway Sciences 1 INTRODUCTION The railway as the backbone of integrative traffic transportation system in China is main artery
2005-01-0785. Effective Application of Software Safety Techniques for Automotive Embedded Control Systems SAE TECHNICAL PAPER SERIES
2005-01-0785 SAE TECHNICAL PAPER SERIES Effective Application of Software Safety Techniques for Automotive Embedded Control Systems Barbara J. Czerny, Joseph G. D Ambrosio, Brian T. Murray and Padma Sundaram
Frame of IoT in China
Frame of IoT in China EuropElectro Summary Orgalime - The European Engineering Industries Association, Brussels Orgalime - 欧 洲 工 程 行 业 协 会, 布 鲁 塞 尔 ZVEI - German Electrical and Electronic Manufacturers
CAST Analysis. 2013 John Thomas and Nancy Leveson. All rights reserved.
CAST Analysis 1 CAST Process Identify the Accident (Loss) Identify the Hazards Identify the Safety Constraints Identify the Proximal Events Draw the Safety Control Structure Analyze each component 2 CAST
Lineside Signal Spacing and Speed Signage
Document comes into force on 05/12/15 Supersedes GKRT0075 Iss 3 on 05/12/15 Date September 15 Lineside Signal Spacing and Speed Synopsis This document specifies the minimum distances that must be provided
Meeting DO-178B Software Verification Guidelines with Coverity Integrity Center
Meeting DO-178B Software Verification Guidelines with Coverity Integrity Center May, 2009 Thomas Schultz Director of Product Strategy, Coverity, Inc. Executive Summary Development organizations that create
INSTRUCTOR S GUIDE. Stay on the Right Track Highway-Railway Crossing Awareness Training for Newly Licensed Drivers
INSTRUCTOR S GUIDE Stay on the Right Track Highway-Railway Crossing Awareness Training for Newly Licensed Drivers WHAT WE DO Operation Lifesaver is a nationwide, non-profit public information and education
Requirements Analysis Concepts & Principles. Instructor: Dr. Jerry Gao
Requirements Analysis Concepts & Principles Instructor: Dr. Jerry Gao Requirements Analysis Concepts and Principles - Requirements Analysis - Communication Techniques - Initiating the Process - Facilitated
Human Factors in the Development of Safety- Critical Railway Systems
Human Factors in the Development of Safety- Critical Railway Systems Simon Zhang, Weihang Wu Technical Director, Senior Consultant Lloyd s Register Rail (Asia) Ltd SUMMARY Existing CENELEC railway safety
Cisco Positive Train Control: Enhancing End-to-End Rail Safety
Solution Overview Cisco Positive Train Control: Enhancing End-to-End Rail Safety What You Will Learn Positive Train Control (PTC), one of many new safety measures mandated by the U.S. Federal Government,
Safety-Driven Model-Based System Engineering Methodology Part I: Methodology Description *
Safety-Driven Model-Based System Engineering Methodology Part I: Methodology Description * December 16, 2007 Prepared by: Margaret Stringfellow Herring, MIT Brandon D. Owens, MIT Dr. Nancy Leveson, MIT
WITH HIGH SPEED TO A SAFE EMERGENCY HANDLING - VIENNA - ST. PÖLTEN TUNNEL HIGH-SPEED LINE
- 20 - WITH HIGH SPEED TO A SAFE EMERGENCY HANDLING - VIENNA - ST. PÖLTEN TUNNEL HIGH-SPEED LINE F. Diernhofer 1, C. Sommerlechner 2, B. Fößleitner 2 1 ILF Consulting Engineers, Austria 2 ÖBB-Infrastruktur
CATIA V5R21 - FACT SHEET
CATIA V5R21 - FACT SHEET Introduction What s New at a Glance Overview Detailed Description INTRODUCTION CATIA V5 is the leading solution for product success. It addresses all manufacturing organizations;
Traffic Engineering Management Concepts
3 CHAPTER This chapter includes an overview of Cisco Prime Fulfillment and of some of the concepts used in this guide. This chapter includes the following sections: Prime Fulfillment TEM Overview, page
Dominic Taylor CEng MIET MIMechE MIRSE MCMI, Invensys Rail
MAXIMIZING THE RETURN ON INVESTMENT FROM ETCS OVERLAY Dominic Taylor CEng MIET MIMechE MIRSE MCMI, Invensys Rail SUMMARY ETCS Level 2 offers many benefits to rail from reduced infrastructure costs, through
A comprehensive information system for railway networks
A comprehensive information system for railway networks Bin Ning', Xuewei Li2 'Department of Control Engineering, School of Electronics and Information Engineering, Northern Jiaotong University 2School
Comparison Control Strategies for ISG hybrid electric vehicle. Hailu Tang 1, a
3rd International Conference on Mechatronics, Robotics and Automation (ICMRA 2015) Comparison Control Strategies for ISG hybrid electric vehicle Hailu Tang 1, a School of Automotive Engineering,Wuhan University
Automatic Train Control based on the Multi-Agent Control of Cooperative Systems
The Journal of Mathematics and Computer Science Available online at http://www.tjmcs.com The Journal of Mathematics and Computer Science Vol.1 No.4 (2010) 247-257 Automatic Train Control based on the Multi-Agent
4. Critical success factors/objectives of the activity/proposal/project being risk assessed
ARTC Risk Management Work Instruction 2: 1. Conduct Risk Assessment Workshop This Work Instruction provides general guidelines for conducting a generic Risk Assessment workshop. The instructions supplement
Test Specification. Introduction
Test Specification Introduction Goals and Objectives GameForge is a graphical tool used to aid in the design and creation of video games. A user with little or no experience with Microsoft DirectX and/or
System Theoretic Approach To Cybersecurity
System Theoretic Approach To Cybersecurity Dr. Qi Van Eikema Hommes Lecturer and Research Affiliate Hamid Salim Stuart Madnick Professor IC3.mit.edu 1 Research Motivations Cyber to Physical Risks with
System Safety Process Applied to Automotive High Voltage Propulsion Systems
System Safety Process Applied to Automotive High Voltage Propulsion Systems ISSC Tutorial Mark Vernacchia, Galen Ressler, Padma Sundaram August 2015 Tutorial Overview Objectives Safety Process Overview
The momentum of a moving object has a magnitude, in kg m/s, and a... (1)
Q. (a) Complete the following sentence. The momentum of a moving object has a magnitude, in kg m/s, and a.... () (b) A car being driven at 9.0 m/s collides with the back of a stationary lorry. The car
Adaptive Cruise Control System Overview
5th Meeting of the U.S. Software System Safety Working Group April 12th-14th 2005 @ Anaheim, California USA 1 Introduction Adaptive Cruise System Overview Adaptive Cruise () is an automotive feature that
RATP safety approach for railway signalling systems
RATP safety approach for railway signalling systems ReSIST summer School 007 Pierre CHARTIER Summary. Introduction. Hardware fault detection. 6 Introduction Global railway system Rolling stock Environment
Using big data in automotive engineering?
Using big data in automotive engineering? ETAS GmbH Borsigstraße 14 70469 Stuttgart, Germany Phone +49 711 3423-2240 Commentary by Friedhelm Pickhard, Chairman of the ETAS Board of Management, translated
Introduction to system safety and risk management in complex systems. Dr. John Thomas Massachusetts Institute of Technology
Introduction to system safety and risk management in complex systems Dr. John Thomas Massachusetts Institute of Technology Agenda Introduction to system safety Challenges for complex systems Goals System-theoretic
ASSESSMENT OF THE ISO 26262 STANDARD, ROAD VEHICLES FUNCTIONAL SAFETY
ASSESSMENT OF THE ISO 26262 STANDARD, ROAD VEHICLES FUNCTIONAL SAFETY Dr. Qi Van Eikema Hommes SAE 2012 Government/Industry Meeting January 25, 2012 1 Outline ISO 26262 Overview Scope of the Assessment
HAVEit. Reiner HOEGER Director Systems and Technology CONTINENTAL AUTOMOTIVE
HAVEit Reiner HOEGER Director Systems and Technology CONTINENTAL AUTOMOTIVE HAVEit General Information Project full title: Project coordinator: Highly Automated Vehicles for Intelligent Transport Dr. Reiner
Inventory Routing. An advanced solution for demand forecasting, stock replenishment, and route planning and execution
Inventory Routing An advanced solution for demand forecasting, stock replenishment, and route planning and execution Our solution delivers a competitive advantage that goes beyond the capabilities of ERP,
Functional Safety with ISO 26262 Principles and Practice Dr. Christof Ebert, Dr. Arnulf Braatz Vector Consulting Services
Functional Safety with ISO 26262 Principles and Practice Dr. Christof Ebert, Dr. Arnulf Braatz Vector Consulting Services Welcome to the Webinar Functional Safety with ISO 26262 Webinar Part 1, Principles
ChE-1800 H-2: Flowchart Diagrams (last updated January 13, 2013)
ChE-1800 H-2: Flowchart Diagrams (last updated January 13, 2013) This handout contains important information for the development of flowchart diagrams Common Symbols for Algorithms The first step before
Making model-based development a reality: The development of NEC Electronics' automotive system development environment in conjunction with MATLAB
The V850 Integrated Development Environment in Conjunction with MAT...iles and More / Web Magazine -Innovation Channel- / NEC Electronics Volume 53 (Feb 22, 2006) The V850 Integrated Development Environment
Complementary Tests: the key of the successful ERTMS deployment in Spain.
Complementary Tests: the key of the successful ERTMS deployment in Spain. M. Cambronero 1, A.. Arranz 1,, C. de la Roza 1, B. Domingo 1, J. Gómez 1 ; J. Iglesias 1, J. Santiago 2, C. Arias 3 1 ADIF. Spanish
ProSoftMod Commission Report Documentation
ProSoftMod Commission Report Documentation The purpose of these modifications is to produce commission reports by salesman. The reports can be done by total sales or gross profit. The can also by produced
Technical Bulletin. Understanding Servo Safety Functionality and SIL ratings
Technical Bulletin Understanding Servo Safety Functionality and SIL ratings What is meant by SIL rating and Stop Categories? Why do I need to understand how safety works if none of my current customers
Ein einheitliches Risikoakzeptanzkriterium für Technische Systeme
ETCS Prüfcenter Wildenrath Interoperabilität auf dem Korridor A Ein einheitliches Risikoakzeptanzkriterium für Technische Systeme Siemens Braunschweig, Oktober 2007 Prof. Dr. Jens Braband Page 1 2007 TS
S3 Benchmark A Fault Tree Based Model for ETCS Application Level 2
S3 Benchmark A Fault Tree Based Model for ETCS Application Level 2 AVACS S3 1 Albert-Ludwigs-Universität Freiburg, Fahnenbergplatz, 79085 Freiburg, Germany 2 Carl von Ossietzky Universität Oldenburg, 26111
siemens.com/mobility Trainguard LEU S21 Central trackside equipment component
siemens.com/mobility Central trackside equipment component cross-border safety with ETCS Level 1 Ensuring mobility is one of the big challenges in our society. To ensure our mobility in future, we need
Design of Network Educating Information System Based on Use Cases Driven Shenwei Wang 1 & Min Guo 2
International Symposium on Social Science (ISSS 2015) Design of Network Educating Information System Based on Use Cases Driven Shenwei Wang 1 & Min Guo 2 1 College of Electronic and Control Engineering,
OSW TN002 - TMT GUIDELINES FOR SOFTWARE SAFETY TMT.SFT.TEC.11.022.REL07
OSW TN002 - TMT GUIDELINES FOR SOFTWARE SAFETY TMT.SFT.TEC.11.022.REL07 August 22, 2012 TMT.SFT.TEC.11.022.REL07 PAGE 2 OF 15 TABLE OF CONTENTS 1 INTRODUCTION 3 1.1 Audience... 3 1.2 Scope... 3 1.3 OSW
Cyber Safety: A Systems Thinking and Systems Theory Approach to Managing Cyber Security Risks
Cyber Safety: A Systems Thinking and Systems Theory Approach to Managing Cyber Security Risks Hamid Salim Stuart Madnick Working Paper CISL# 2014-12 September 2014 Composite Information Systems Laboratory
Automated Firewall Change Management. Ensure continuous compliance and reduce risk with secure change management workflows
Automated Firewall Change Management Ensure continuous compliance and reduce risk with secure change management workflows JANUARY 2015 Executive Summary Firewall management has become a hot topic among
Trainguard Sirius CBTC
siemens.com/mobility Trainguard Sirius CBTC For efficient mass transit operation Trainguard Sirius CBTC Trainguard Sirius communication based train control (CBTC) is Siemens Rail Automation s solution
Application of Adaptive Probing for Fault Diagnosis in Computer Networks 1
Application of Adaptive Probing for Fault Diagnosis in Computer Networks 1 Maitreya Natu Dept. of Computer and Information Sciences University of Delaware, Newark, DE, USA, 19716 Email: [email protected]
Nemo 96HD/HD+ MODBUS
18/12/12 Pagina 1 di 28 MULTIFUNCTION FIRMWARE 2.30 Nemo 96HD/HD+ MODBUS COMMUNICATION PROTOCOL CONTENTS 1.0 ABSTRACT 2.0 DATA MESSAGE DESCRIPTION 2.1 Parameters description 2.2 Data format 2.3 Description
Algorithms and optimization for search engine marketing
Algorithms and optimization for search engine marketing Using portfolio optimization to achieve optimal performance of a search campaign and better forecast ROI Contents 1: The portfolio approach 3: Why
Functional Safety Lifecycle of the LCLS PLC PPS Systems E. Michael Saleski * May 31, 2006
Functional Safety Lifecycle of the LCLS PLC PPS Systems E. Michael Saleski * May 31, 2006 1.0 Introduction Safety functions are increasingly being carried out by electrical, electronic, or programmable
Hybrid System for Driver Assistance
International Journal of Information & Computation Technology. ISSN 0974-2239 Volume 4, Number 15 (2014), pp. 1583-1587 International Research Publications House http://www. irphouse.com Hybrid System
ITIL Intermediate Qualification: Service Offerings and Agreement. Webinar presentation 8 May 2009
ITIL Intermediate Qualification: Service Offerings and Agreement Webinar presentation 8 May 2009 Team Lead SOA Vernon Lloyd FISM IT Industry before it was IT (1970) Done most things in most places ITSM
Software Engineering Introduction & Background. Complaints. General Problems. Department of Computer Science Kent State University
Software Engineering Introduction & Background Department of Computer Science Kent State University Complaints Software production is often done by amateurs Software development is done by tinkering or
Safety and Security Driven Design. Unmanned Aircraft-National Airspace System Integration Case Study
2 nd uropean STAMP Workshop, 2014 Safety and Security Driven Design. Unmanned Aircraft-National Airspace System Integration Case Study Kip Johnson Prof. Nancy eveson See accompanying abstract: Johnson,
Rail Automation. What is ACSES? usa.siemens.com/rail-automation
Rail Automation What is ACSES? usa.siemens.com/rail-automation What is ACSES? Siemens, a specialist in the area of US Cab Signal design, offers a carborne product that provides both Civil Speed Enforcement
Cars of the future. What is your most favourite car in the world? Give a description of your first car
Cars of the future What is your most favourite car in the world? Give a description of your first car What are the next big features for cars in the next ten years? Hybrid Cars Will people jump on the
Car Racing Game. Figure 1 The Car Racing Game
CSEE 4840 Embedded System Design Jing Shi (js4559), Mingxin Huo (mh3452), Yifan Li (yl3250), Siwei Su (ss4483) Car Racing Game -- Project Design 1 Introduction For this Car Racing Game, we would like to
Introduction to Simulink
Introduction to Simulink MEEN 364 Simulink is a software package for modeling, simulating, and analyzing dynamical systems. It supports linear and nonlinear systems, modeled in continuous time, sampled
Design and Implementation of Production Management Information System for Jiujiang Railway Track Depot
Management Information System for Jiujiang Railway Track Depot 1 Information Technology Center Jiujiang University Jiujiang, Jiangxi, 332005, China E-mail: [email protected] Upon analyzing the actual situation
Energy Recovery System for Excavators Meng (Rachel) Wang, Chad Larish Eaton Corporation
Energy Recovery System for Excavators Meng (Rachel) Wang, Chad Larish Eaton Corporation Abstract Increasing fuel costs have become a significant portion of the operating expenses for owners and fleet managers
Health and safety policy
1. General statement of intent The Company recognises and accepts its responsibilities as an employer to ensure, so far as is reasonably practicable, the health, safety and welfare of its employees and
By: M.Habibullah Pagarkar Kaushal Parekh Jogen Shah Jignasa Desai Prarthna Advani Siddhesh Sarvankar Nikhil Ghate
AUTOMATED VEHICLE CONTROL SYSTEM By: M.Habibullah Pagarkar Kaushal Parekh Jogen Shah Jignasa Desai Prarthna Advani Siddhesh Sarvankar Nikhil Ghate Third Year Information Technology Engineering V.E.S.I.T.
Introduction to Project Management
L E S S O N 1 Introduction to Project Management Suggested lesson time 50-60 minutes Lesson objectives To be able to identify the steps involved in project planning, you will: a b c Plan a project. You
PEDESTRIAN AND BICYCLE ACCIDENT DATA. Irene Isaksson-Hellman If Insurance Company P&C Ltd.
PEDESTRIAN AND BICYCLE ACCIDENT DATA Irene Isaksson-Hellman If Insurance Company P&C Ltd. Vulnerable road users 2 Number Number Official accident statistics 45 35 4 3 35 25 3 25 2 2 15 15 1 1 5 5 5 4 5
Karunya University Dept. of Information Technology
PART A Questions 1. Mention any two software process models. 2. Define risk management. 3. What is a module? 4. What do you mean by requirement process? 5. Define integration testing. 6. State the main
Big Data: A new era of insurance? Dr. Iordanis Chatziprodromou, Mexico 2015
Big Data: A new era of insurance? Dr. Iordanis Chatziprodromou, Mexico 2015 What is Big Data? 2 What is Big Data? There are several definitions for Big Data based on different properties regarding the
