WS2324 DSS 01 IntroductionSS
WS2324 DSS 01 IntroductionSS
DIT Deggendorf Institute of Technology – WS2324 – Design Safe Systems – 01 Introduction – Oct 11, 2023 – R. Platz, Slide 1
Paradigm of Safety by Design
People
DIT Deggendorf Institute of Technology – WS2324 – Design Safe Systems – 01 Introduction – Oct 11, 2023 – R. Platz, Slide 2
Poll – Attendance This Morning’s Class
DIT Deggendorf Institute of Technology – WS2324 – Design Safe Systems – 01 Introduction – Oct 11, 2023 – R. Platz, Slide 3
Ground Rules Zoom Lecture
• mute yourself
• turn off your camera unless you are in group assignments or discussions
• for questions, raise your hand and wait until I call you, than use your
microphone
DIT Deggendorf Institute of Technology – WS2324 – Design Safe Systems – 01 Introduction – Oct 11, 2023 – R. Platz, Slide 4
Timeline
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29
February 2024 dfdf We Th Fr Sa Su Mo Tu We Th Fr Sa Su Mo Tu We Th Fr Sa Su Mo Tu We Th Fr Sa Su Mo Tu We Th Fr Sa Su Mo Mo
number of lecture exam period *
exam: tba, together with "Design of Safe Systems"
auxiliary means: three two-sided sheets in DIN A4 format with own handwritten formulary, non-programmable hand calculator, ruler for whole exam
*semester break Feb. 15 to Mar. 14, 2024
DIT Deggendorf Institute of Technology – WS2324 – Design Safe Systems – 01 Introduction – Oct 11, 2023 – R. Platz, Slide 5
Organization
teaching method lecture via slides, live hand written derivations on white board, live group assignments,
homework if needed, 15 min break after 90 min
my expectation active participation during assignments – for your own good,
if you leave your computer permanently during class, log off from Zoom
recording no, due to organizational and legal reasons; slides after class on iLearn
exam for module “Functional Safety”, one final written exam in person in Cham, together with
“Principles of Functional Safety”, 90 min,
(date and venue tba), allowed aids: three two-sided sheets in DIN A4 format with own
handwritten formulary, hand calculator, ruler
consulting hours any time, appointments via e-mail, consulting via ZOOM
DIT Deggendorf Institute of Technology – WS2324 – Design Safe Systems – 01 Introduction – Oct 11, 2023 – R. Platz, Slide 6
Organization
literature (selection) Börcsök, Josef (2021): Funktionale Sicherheit. Grundzüge
sicherheitstechnischer Systeme. 5., überarbeitete Auflage. (English
version available, but not as good)
Bozzano, Marco; Villafiorita, Adolfo (2010): Design and safety
assessment of critical systems. Boca Raton: Auerbach Publications
Gebhardt, Vera; Rieger, Gerhard M.; Mottok, Jürgen; Gießelbach,
Christian (2013): Funktionale Sicherheit nach ISO 26262. Ein
Praxisleitfaden zur Umsetzung. 1. Aufl. Heidelberg: dpunkt-Verl.
(German only)
Smith, David J.; Simpson, Kenneth G.L. (2020): The Safety Critical
Systems Handbook. A straightforward Guide to Functional Safety:
IEC 61508 (2010 Edition), IEC 61511 (2016 Edition), ...
Standards IEC 61508 – Functional safety of elec./ … safety-related systems
2006/42/EC – Directive on machinery
ISO 13849-1 – Safety of machinery
ISO 26262-01 – Road vehicles, Functional safety
ISO 12100 – Safety of machinery
DIN EN 15233 – Methodik zur Bewertung der funktionalen
Sicherheit von Schutzsystemen für explosionsgefährdete Bereiche
CE Mark, Certification
DIT Deggendorf Institute of Technology – WS2324 – Design Safe Systems – 01 Introduction – Oct 11, 2023 – R. Platz, Slide 7
Design of Safe Systems
Contents
DIT Deggendorf Institute of Technology – WS2324 – Design Safe Systems – 01 Introduction – Oct 11, 2023 – R. Platz, Slide 8
Design of Safe Systems
Contents
DIT Deggendorf Institute of Technology – WS2324 – Design Safe Systems – 01 Introduction – Oct 11, 2023 – R. Platz, Slide 9
Promise of Today’s Lecture
Getting to know
… first view on product design process and formal methods for safety assessment
DIT Deggendorf Institute of Technology – WS2324 – Design Safe Systems – 01 Introduction – Oct 11, 2023 – R. Platz, Slide 10
Introduction
DIT Deggendorf Institute of Technology – WS2324 – Design Safe Systems – 01 Introduction – Oct 11, 2023 – R. Platz, Slide 11
Why Safe Systems?
example: Boeing 737-Max incidents due to its faulty
Maneuvering Characteristics Augmentation System (MCAS)
DIT Deggendorf Institute of Technology – WS2324 – Design Safe Systems – 01 Introduction – Oct 11, 2023 – R. Platz, Slide 12
Why Safe Systems?
example: Boeing 737-Max incidents due to its faulty
Maneuvering Characteristics Augmentation System (MCAS)
• MCAS erroneously activated on both flights, triggering a chain of events that ended
with 346 people dead
• „Boeing’s employees chose the path of profit over candor by concealing material
information from the FAA (Federal Aviation Administration) concerning the operation
of its 737 Max airplane and engaging in an effort to cover up their deception.”
[Acting Assistant Attorney General David P. Burns of the Justice Department’s
Criminal Division]
• $243.6 million in criminal penalties,
• plus $500 million to a crash-victim beneficiaries fund
• separate $1.77 billion compensation payment to Max customers
DIT Deggendorf Institute of Technology – WS2324 – Design Safe Systems – 01 Introduction – Oct 11, 2023 – R. Platz, Slide 13
[The Air Current, January 10, 2021]
DIT Deggendorf Institute of Technology – WS2324 – Design Safe Systems – 01 Introduction – Oct 11, 2023 – R. Platz, Slide 14
Why Safe Systems?
[www.therobotreport.com, Nuro]
… major catastrophic
accidents are yet to come?
[sproboticworks.com]
DIT Deggendorf Institute of Technology – WS2324 – Design Safe Systems – 01 Introduction – Oct 11, 2023 – R. Platz, Slide 15
DIT Deggendorf Institute of Technology – WS2324 – Design Safe Systems – 01 Introduction – Oct 11, 2023 – R. Platz, Slide 16
“Definition” of Complex Safety-Critical Systems
[SAE (1996) – Guidelines and Methods for Conducting the Safety Assessment Process on Civil Airborne Systems and
Equipment. Technical Report ARP4761, Society of Automotive Engineers]
DIT Deggendorf Institute of Technology – WS2324 – Design Safe Systems – 01 Introduction – Oct 11, 2023 – R. Platz, Slide 17
DIT Deggendorf Institute of Technology – WS2324 – Design Safe Systems – 01 Introduction – Oct 11, 2023 – R. Platz, Slide 18
Steady Trend Toward Complexity
reduction in costs is increasing diffusion
• Quantitative Software Management, Inc. (2009) estimates one function point as
148 lines of C code
• millions of embedded microprocessors are used for safety-critical applications and
many of them have faults
• between 1990 and 2000, firmware errors accounted for about 40% of the half-
million recalled pacemakers (Maisel et al., 2001; Ebert and Jones, 2009)
gain in performance is increasing complexity
• number of functions, e. g. for modern jet-fighters that are, in fact, designed to be
slightly aerodynamically unstable a small variation in the current flight conditions
causes the plane to abruptly change trajectory
• number of states, e. g. digital systems with a large number of states that can make
their comprehension difficult and exhaustive testing impossible
• discrete behavior, e. g. a little variation in one program input could cause a great
variation in one output
• invisibility, e. g. software can be visualized only by overlapping several different
views (e.g., data-flow, control-flow) that define its behavior.
DIT Deggendorf Institute of Technology – WS2324 – Design Safe Systems – 01 Introduction – Oct 11, 2023 – R. Platz, Slide 19
Steady Trend Toward Complexity
size of flight
software, e.g.
amount of code
lines
[Bozzano, 2010]
DIT Deggendorf Institute of Technology – WS2324 – Design Safe Systems – 01 Introduction – Oct 11, 2023 – R. Platz, Slide 20
Levels of Criticality [Bozzano, 2010]
business-critical systems
failure of the system might cause a high economic loss
* *
mission-critical systems
uncrewed baggage
failures might cause loss of a spacecraft handling
function necessary to achieve one
of the goals
safety-critical systems
system failures might cause risk to human life or damages to the environment
DIT Deggendorf Institute of Technology – WS2324 – Design Safe Systems – 01 Introduction – Oct 11, 2023 – R. Platz, Slide 22
Diverse Causes for Systems to Fail
incapable design
errors during development (especially early stages such as specification,
requirement, conception)
overloaded/overstressed
• operated in environmental conditions for which it was not designed
• failure of other system components
DIT Deggendorf Institute of Technology – WS2324 – Design Safe Systems – 01 Introduction – Oct 11, 2023 – R. Platz, Slide 23
Design of Safe Systems – History of Tools
1853 – Elevators
became popular only after 1853 when Elisha Otis demonstrated a freight elevator
equipped with a safety device to prevent falling in case the cable should tear
[Alamy.de]
[https://otiselevator.umwblogs.org/adoption/] https://www.youtube.com/watch?v=sSjJjKcoNRk
DIT Deggendorf Institute of Technology – WS2324 – Design Safe Systems – 01 Introduction – Oct 11, 2023 – R. Platz, Slide 24
Design of Safe Systems – History of Tools
1853 – Elevators
became popular only after 1853 when Elisha Otis demonstrated a freight elevator
equipped with a safety device to prevent falling in case the cable should tear
DIT Deggendorf Institute of Technology – WS2324 – Design Safe Systems – 01 Introduction – Oct 11, 2023 – R. Platz, Slide 25
Product Design Process PDP
DIT Deggendorf Institute of Technology – WS2324 – Design Safe Systems – 01 Introduction – Oct 11, 2023 – R. Platz, Slide 26
Product Design Process (PDP) with Reliability Assessment Tools
knowledge quality
from ABC-analysis, design management, collecting field
qualitative specification sheet experience review FMEA*, FTA*, … audits data
quantitative reliability targets non-deterministic and Weibull analysis, statistical analyzing field
probability measures DoE, Boole*, process data
Markov-Chains*, planning
FTA*
DIT Deggendorf Institute of Technology – WS2324 – Design Safe Systems – 01 Introduction – Oct 11, 2023 – R. Platz, Slide 27
Product Design Process PDP
[Asiedu, Gu 1998 – Product life cycle cost analysis: State of the art review]
DIT Deggendorf Institute of Technology – WS2324 – Design Safe Systems – 01 Introduction – Oct 11, 2023 – R. Platz, Slide 28
Research Examples
shunt-Damping
quantification of model
and data uncertainty / [SFB 805]
health monitoring
[Fraunhofer LBF]
adaptronics
passive/active vibration isolation
dynamic / electric / thermal
reliability of high-voltage batteries
DIT Deggendorf Institute of Technology – WS2324 – Design Safe Systems – 01 Introduction – Oct 11, 2023 – R. Platz, Slide 29
Weiterentwicklung Rundstab (bis zum MAFDS)
• load distribution
• stability
• vibration control
• health control
12 year research
collaboration: Controlling
Uncertainty in Load
Carrying Systems
(ended 2021)
[Patent: Enß, G., Gehb, C., Götz, B., Melz, T., Ondoua, S., Platz, R., Schäffner, M., (2015)]
DIT Deggendorf Institute of Technology – WS2324 – Design Safe Systems – 01 Introduction – Oct 11, 2023 – R. Platz, Slide 31
End of Lecture
DIT Deggendorf Institute of Technology – WS2324 – Design Safe Systems – 01 Introduction – Oct 11, 2023 – R. Platz, Slide 32