中国安全科学学报 ›› 2021, Vol. 31 ›› Issue (9): 8-14.doi: 10.16265/j.cnki.issn1003-3033.2021.09.002

• 安全科学理论与安全系统科学 • 上一篇    下一篇

面向IMA通用系统管理的STPA安全性分析*

肖国松1,2 实验师, 刘嘉琛2,3, 董磊1,2 副研究员, 孙紫荆2,3, 赵长啸1,2 副研究员   

  1. 1 中国民航大学 民航航空器适航审定技术重点实验室;天津 300300;
    2 中国民航大学 安全科学与工程学院,天津 300300;
    3 天津市民用航空器适航与维修重点实验室,天津 300300
  • 收稿日期:2021-06-21 修回日期:2021-08-08 出版日期:2021-09-28 发布日期:2022-03-28
  • 作者简介:肖国松 (1982—),男,湖南衡阳人,硕士,实验师,主要从事民机加改装、系统安全性评估工作。E-mail: xiaoguosong@sina.cn。
  • 基金资助:
    国家自然科学基金资助(U1933106);航空科学基金资助(20185167017);中央高校基本科研业务费(3122019167);天津市教科委科研计划项目(2019KJ134)。

STPA safety analysis on IMA generic system management

XIAO Guosong1,2, LIU Jiachen2,3, DONG Lei1,2, SUN Zijing2,3, ZHAO Changxiao1,2   

  1. 1 Key Laboratory of Civil Aircraft Airworthiness Technology, Civil Aviation University of China, Tianjin 300300, China;
    2 College of Safety Science and Engineering, Civil Aviation University of China, Tianjin 300300, China;
    3 Tianjin Key Laboratory for Airworthiness and Maintenance of Civil Aircraft, Tianjin 300300, China
  • Received:2021-06-21 Revised:2021-08-08 Online:2021-09-28 Published:2022-03-28

摘要: 通用系统管理(GSM)是综合模块化航电(IMA)系统服务中不可或缺的一部分,为解决传统安全性分析方法难以捕获复杂系统中组件交互所带来的危险。首先,研究GSM的工作环境及相关组件的功能划分,确定层次化系统管理的工作流程;其次,面向GSM建立基于系统理论事故过程的扩展模型,并通过系统理论过程分析(STPA)对动态重构实例的不安全控制行为(UCA)进行识别,生成相关致因场景及其对应的安全性需求;最后,通过时间自动机对实例进行仿真验证。结果表明:模型的逻辑和时序的完整性及UCA的可达性,可为GSM的安全性分析提供形式化依据。

关键词: 综合模块化航电(IMA), 通用系统管理(GSM), 系统理论过程分析(STPA), 动态重配置, 安全性分析

Abstract: GSM is an indispensable part of IMA system services. In order to address the difficulties traditional safety analysis methods have in capturing risks caused by component interaction in complex systems, firstly, GSM work environment and function division of its components were studied, and workflow of hierarchical system management was determined. Secondly, an extended model based on accident process of systematic theory was established for GSM, unsafe control actions(UCA) of dynamic reconfiguration case were identified through STPA, and relevant causative scenarios and their corresponding safety requirements were generated. Finally, the case is simulated and verified by timed automata. The results show that the model's logic and timing integrity and reachability of UCA behavior provide a formal basis for GSM safety analysis.

Key words: integrated modular avionics (IMA), generic system management (GSM), systematic theory process analysis (STPA), dynamic reconfiguration, safety analysis

中图分类号: