Browse Publications Technical Papers 2012-01-2134
2012-10-22

Safety Assessment of Complex, Software-Intensive Systems 2012-01-2134

This paper presents a new methodology for the safety assessment of complex software intensive systems such as is envisioned for the coming major upgrade of the air traffic management system known as NextGen. This methodology is based on a new, more inclusive model of accident causation called Systems Theoretic Accident Model and Process (STAMP) [1]. STAMP includes not just the standard component failure mechanisms but also the new ways that software and humans contribute to accidents in complex systems. A new hazard analysis method, called Systems Theoretic Process Analysis (STPA), is built on this theoretical foundation. The STPA is based on systems theory rather than reliability theory; it treats safety as a control problem rather than a failure problem with interactive and possibly nested control loops that may include humans. In this methodology, safety is assured by closed loop control of safety parameters.
In the NextGen Concept of Operations, [2] many diverse ground and air systems will be tightly coupled leading to a greatly increased potential for the occurrence of safety critical events. The process described in this paper provides a rigorous, integrated and traceable safety analysis that improves upon the present somewhat ad-hoc multi-layered approach commonly used today. This process also improves upon the human-system interaction aspect of safety assessment, a topic that is not well covered in present certification practice.
We illustrate the effectiveness of this new methodology by an analysis of the NextGen “In-Trail Procedure in Oceanic Airspace” (ITP) that is specified in RTCA DO-312 [3]. We show how STPA derives some additional safety requirements beyond those in the Operational Safety Analysis (OSA) of DO-312.

SAE MOBILUS

Subscribers can view annotate, and download all of SAE's content. Learn More »

Access SAE MOBILUS »

Members save up to 16% off list price.
Login to see discount.
We also recommend:
TECHNICAL PAPER

Lightning Induced Voltages on Differently Protected and Routed Wires in a Carbon Fibre Wing Box

1999-01-2340

View Details

JOURNAL ARTICLE

Generic Architecture for a Self-Powered Smart Sensor Interface in Avionic Application

2012-01-2126

View Details

JOURNAL ARTICLE

A Resonant Capacitive Coupling WPT-Based Method to Power and Monitor Seat Belt Buckle Switch Status in Removable and Interchangeable Seats

2019-01-0465

View Details

X