首页 > 最新文献

EDCC-CARS最新文献

英文 中文
Temporal isolation for the cohabitation of applications in automotive embedded software 汽车嵌入式软件中共存应用的时间隔离
Pub Date : 2010-04-27 DOI: 10.1145/1772643.1772651
D. Bertrand, S. Faucou, Y. Trinquet
With the advent of the integrated architecture paradigm promoted by AUTOSAR, the automotive domain needs a standard temporal isolation policy. In this paper, we review the different approaches proposed so far and we discuss their applicability to forthcoming systems.
随着AUTOSAR推动的集成架构范式的出现,汽车领域需要一个标准的时间隔离策略。在本文中,我们回顾了迄今为止提出的不同方法,并讨论了它们在即将到来的系统中的适用性。
{"title":"Temporal isolation for the cohabitation of applications in automotive embedded software","authors":"D. Bertrand, S. Faucou, Y. Trinquet","doi":"10.1145/1772643.1772651","DOIUrl":"https://doi.org/10.1145/1772643.1772651","url":null,"abstract":"With the advent of the integrated architecture paradigm promoted by AUTOSAR, the automotive domain needs a standard temporal isolation policy. In this paper, we review the different approaches proposed so far and we discuss their applicability to forthcoming systems.","PeriodicalId":221742,"journal":{"name":"EDCC-CARS","volume":"27 1","pages":"0"},"PeriodicalIF":0.0,"publicationDate":"2010-04-27","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"115167371","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 0
Tree scheduling versus sequential scheduling 树调度与顺序调度
Pub Date : 2010-04-27 DOI: 10.1145/1772643.1772664
C. Fotsing, Annie Choquet-Geniet, G. Vidal-Naquet
We present a new approach of validation for critical real-time applications: the tree based approach. This approach explicitly takes the conditional statements and the semantics contained in the tests into account. We substitute sequential schedules by scheduling trees. We thus add new scheduling possibilities to those provided by the sequential approach. We then give conditions which make the two approaches equivalent (i.e. give same results for schedulability).
我们提出了一种新的关键实时应用验证方法:基于树的方法。这种方法显式地考虑了测试中包含的条件语句和语义。我们用调度树代替顺序调度。因此,我们在顺序方法提供的调度可能性基础上增加了新的调度可能性。然后,我们给出了使这两种方法等价的条件(即对可调度性给出相同的结果)。
{"title":"Tree scheduling versus sequential scheduling","authors":"C. Fotsing, Annie Choquet-Geniet, G. Vidal-Naquet","doi":"10.1145/1772643.1772664","DOIUrl":"https://doi.org/10.1145/1772643.1772664","url":null,"abstract":"We present a new approach of validation for critical real-time applications: the tree based approach. This approach explicitly takes the conditional statements and the semantics contained in the tests into account. We substitute sequential schedules by scheduling trees. We thus add new scheduling possibilities to those provided by the sequential approach. We then give conditions which make the two approaches equivalent (i.e. give same results for schedulability).","PeriodicalId":221742,"journal":{"name":"EDCC-CARS","volume":"63 4","pages":"0"},"PeriodicalIF":0.0,"publicationDate":"2010-04-27","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"120842339","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 2
Automatic allocation of safety integrity levels 自动分配安全完整性等级
Pub Date : 2010-04-27 DOI: 10.1145/1772643.1772646
Y. Papadopoulos, M. Walker, Mark-Oliver Reiser, Matthias Weber, De-Jiu Chen, Martin Törngren, D. Servat, Andreas Abele, F. Stappert, Henrik Lönn, L. Berntsson, Rolf Johansson, Fulvio Tagliabo, Sandra Torchiaro, Anders Sandberg
In this paper, we describe a concept for the automatic allocation of general Safety Integrity Levels (SILs) to subsystems and components of complex hierarchical networked architectures that deliver sets of safety critical functions. The concept is generic and can be adapted to facilitate the safety engineering approach defined in several standards that employ the concept of integrity or assurance levels including ISO 26262, the emerging automotive safety standard. SIL allocation is facilitated by HiP-HOPS, an automated safety analysis tool, and can be performed in the context of development using EAST-ADL2, an automotive architecture description language. The process rationalizes complex risk allocation and leads to optimal/economic allocation of SILs.
在本文中,我们描述了一个概念,用于自动分配一般安全完整性等级(SILs)到提供安全关键功能集的复杂分层网络体系结构的子系统和组件。这个概念是通用的,可以适应于促进几个标准中定义的安全工程方法,这些标准采用完整性或保证级别的概念,包括新兴的汽车安全标准ISO 26262。自动化安全分析工具HiP-HOPS促进了SIL的分配,并且可以在使用汽车架构描述语言EAST-ADL2的开发环境中执行。这一过程使复杂的风险分配合理化,并导致SILs的最优/经济分配。
{"title":"Automatic allocation of safety integrity levels","authors":"Y. Papadopoulos, M. Walker, Mark-Oliver Reiser, Matthias Weber, De-Jiu Chen, Martin Törngren, D. Servat, Andreas Abele, F. Stappert, Henrik Lönn, L. Berntsson, Rolf Johansson, Fulvio Tagliabo, Sandra Torchiaro, Anders Sandberg","doi":"10.1145/1772643.1772646","DOIUrl":"https://doi.org/10.1145/1772643.1772646","url":null,"abstract":"In this paper, we describe a concept for the automatic allocation of general Safety Integrity Levels (SILs) to subsystems and components of complex hierarchical networked architectures that deliver sets of safety critical functions. The concept is generic and can be adapted to facilitate the safety engineering approach defined in several standards that employ the concept of integrity or assurance levels including ISO 26262, the emerging automotive safety standard. SIL allocation is facilitated by HiP-HOPS, an automated safety analysis tool, and can be performed in the context of development using EAST-ADL2, an automotive architecture description language. The process rationalizes complex risk allocation and leads to optimal/economic allocation of SILs.","PeriodicalId":221742,"journal":{"name":"EDCC-CARS","volume":"108 1","pages":"0"},"PeriodicalIF":0.0,"publicationDate":"2010-04-27","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"117324994","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 62
Enabling mode changes in a distributed automotive system 在分布式汽车系统中启用模式更改
Pub Date : 2010-04-27 DOI: 10.1145/1772643.1772665
M. Mitzlaff, R. Kapitza, Wolfgang Schröder-Preikschat
Due to the high pressure for innovation, recent cars offer a constantly increasing number of sophisticated functions for advanced driver assistance and an improved active safety. As a result, software complexity in cars rises. Up to now, configurations of current automotive embedded systems are fixed and remain static over the vehicle lifetime. However, this is problematic as all offered functions have to be taken into account for the schedule of currently upcoming time-triggered bus systems and also the OS schedules on the electronic control units (ECUs). In principle, this is not necessary, as subsets of these functions have disjoint phases of use. This paper presents dynamic reconfiguration in cars based on mode changes, allowing to switch between a set of statically defined bus and ECUs schedules during runtime. This decreases the resource usage and the complexity of a specific set of bus and ECU schedules, as only active functions have to be considered. We outline how such a mode change can safely be enabled using a membership service for a time-triggered bus system and outline our experience in the context of a practical use case scenario: dedicated modes for normal operation and for servicing a car.
由于创新的巨大压力,最近的汽车提供了越来越多的先进驾驶辅助和改进的主动安全性的复杂功能。因此,汽车软件的复杂性增加了。到目前为止,当前汽车嵌入式系统的配置是固定的,并且在车辆使用寿命期间保持不变。然而,这是有问题的,因为所有提供的功能都必须考虑到当前即将到来的时间触发总线系统的时间表,以及电子控制单元(ecu)上的操作系统时间表。原则上,这是不必要的,因为这些函数的子集具有不相交的使用阶段。本文提出了基于模式变化的汽车动态重新配置,允许在运行时在一组静态定义的总线和ecu调度之间切换。这减少了资源使用和特定总线和ECU调度集的复杂性,因为只需要考虑活动功能。我们概述了如何使用时间触发总线系统的会员服务安全地启用这种模式更改,并概述了我们在实际用例场景上下文中的经验:用于正常操作和维修汽车的专用模式。
{"title":"Enabling mode changes in a distributed automotive system","authors":"M. Mitzlaff, R. Kapitza, Wolfgang Schröder-Preikschat","doi":"10.1145/1772643.1772665","DOIUrl":"https://doi.org/10.1145/1772643.1772665","url":null,"abstract":"Due to the high pressure for innovation, recent cars offer a constantly increasing number of sophisticated functions for advanced driver assistance and an improved active safety. As a result, software complexity in cars rises. Up to now, configurations of current automotive embedded systems are fixed and remain static over the vehicle lifetime. However, this is problematic as all offered functions have to be taken into account for the schedule of currently upcoming time-triggered bus systems and also the OS schedules on the electronic control units (ECUs). In principle, this is not necessary, as subsets of these functions have disjoint phases of use.\u0000 This paper presents dynamic reconfiguration in cars based on mode changes, allowing to switch between a set of statically defined bus and ECUs schedules during runtime. This decreases the resource usage and the complexity of a specific set of bus and ECU schedules, as only active functions have to be considered. We outline how such a mode change can safely be enabled using a membership service for a time-triggered bus system and outline our experience in the context of a practical use case scenario: dedicated modes for normal operation and for servicing a car.","PeriodicalId":221742,"journal":{"name":"EDCC-CARS","volume":"1 1","pages":"0"},"PeriodicalIF":0.0,"publicationDate":"2010-04-27","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"128799917","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 5
Enforcing trust in control automotive platforms 加强对控制汽车平台的信任
Pub Date : 2010-04-27 DOI: 10.1145/1772643.1772656
C. Jouvray, Grégoire Chartier, Nicolas François, I. Ripoll, M. Masmano, A. Crespo
Trusted computing is a main concern for ensuring that the platform is secure and dependable. This paper will study AUTOSAR regarding to this area and will propose some suggestions to enforce trust in control automotive platforms.
可信计算是确保平台安全可靠的主要关注点。本文将研究AUTOSAR在这方面的研究,并提出一些建议,以加强信任控制汽车平台。
{"title":"Enforcing trust in control automotive platforms","authors":"C. Jouvray, Grégoire Chartier, Nicolas François, I. Ripoll, M. Masmano, A. Crespo","doi":"10.1145/1772643.1772656","DOIUrl":"https://doi.org/10.1145/1772643.1772656","url":null,"abstract":"Trusted computing is a main concern for ensuring that the platform is secure and dependable. This paper will study AUTOSAR regarding to this area and will propose some suggestions to enforce trust in control automotive platforms.","PeriodicalId":221742,"journal":{"name":"EDCC-CARS","volume":"29 1","pages":"0"},"PeriodicalIF":0.0,"publicationDate":"2010-04-27","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"121759954","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 2
Requirement traceability in safety critical systems 安全关键系统的需求可追溯性
Pub Date : 2010-04-27 DOI: 10.1145/1772643.1772647
Marie-Agnès Peraldi-Frati, A. Albinet
Safety engineering analysis is a mandatory stage in the design of critical embedded automotive systems. The derivation of safety requirements and their verification require establishing traceability links between requirements and the different artifacts involved in the design flow. This paper presents the different steps of a method for expressing non functional requirements (safety, timing, hardware, performance) and ensuring their validation and their traceability over a design flow for automotive system design based on the conjoint use of EAST-ADL2 and MARTE languages and supported in an Eclipse platform. A specific meta-model for requirements modeling and traceability is used. The methodology is illustrated on an industrial knock-control system characterized by strict safety and temporal constraints
安全工程分析是关键嵌入式汽车系统设计的必要阶段。安全需求的派生及其验证需要在需求和设计流中涉及的不同工件之间建立可追溯性链接。本文介绍了一种表达非功能需求(安全、时序、硬件、性能)的方法的不同步骤,并在基于EAST-ADL2和MARTE语言联合使用并在Eclipse平台中支持的汽车系统设计流程中确保它们的有效性和可追溯性。使用特定的元模型进行需求建模和跟踪。该方法以具有严格安全性和时间约束的工业碰撞控制系统为例进行了说明
{"title":"Requirement traceability in safety critical systems","authors":"Marie-Agnès Peraldi-Frati, A. Albinet","doi":"10.1145/1772643.1772647","DOIUrl":"https://doi.org/10.1145/1772643.1772647","url":null,"abstract":"Safety engineering analysis is a mandatory stage in the design of critical embedded automotive systems. The derivation of safety requirements and their verification require establishing traceability links between requirements and the different artifacts involved in the design flow. This paper presents the different steps of a method for expressing non functional requirements (safety, timing, hardware, performance) and ensuring their validation and their traceability over a design flow for automotive system design based on the conjoint use of EAST-ADL2 and MARTE languages and supported in an Eclipse platform. A specific meta-model for requirements modeling and traceability is used. The methodology is illustrated on an industrial knock-control system characterized by strict safety and temporal constraints","PeriodicalId":221742,"journal":{"name":"EDCC-CARS","volume":"38 1","pages":"0"},"PeriodicalIF":0.0,"publicationDate":"2010-04-27","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"122084399","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 28
Memory protection at option 存储器保护选项
Pub Date : 2010-04-27 DOI: 10.1145/1772643.1772649
Michael Stilkerich, D. Lohmann, Wolfgang Schröder-Preikschat
There is hardware- and software-based memory protection that can improve the dependability of software systems. The two variants vary in the degree of protection and the amount and sites of overhead. The decision for a particular mechanism therefore highly depends on the application and deployment scenario. We propose a system suited for deeply embedded systems that allows to choose among no protection, software-based protection, hardware-based protection or a combination of the two without the need to change the application. In this paper, we present the current state of this work and support our claim that the best-suited memory protection type depends on the application by a preliminary evaluation.
有基于硬件和软件的存储器保护,可以提高软件系统的可靠性。这两种变体在保护程度以及开销的数量和位置上有所不同。因此,特定机制的决策在很大程度上取决于应用程序和部署场景。我们提出了一种适合深度嵌入式系统的系统,允许在不保护,基于软件的保护,基于硬件的保护或两者的组合中进行选择,而无需更改应用程序。在本文中,我们介绍了这项工作的现状,并通过初步评估来支持我们的主张,即最适合的内存保护类型取决于应用程序。
{"title":"Memory protection at option","authors":"Michael Stilkerich, D. Lohmann, Wolfgang Schröder-Preikschat","doi":"10.1145/1772643.1772649","DOIUrl":"https://doi.org/10.1145/1772643.1772649","url":null,"abstract":"There is hardware- and software-based memory protection that can improve the dependability of software systems. The two variants vary in the degree of protection and the amount and sites of overhead. The decision for a particular mechanism therefore highly depends on the application and deployment scenario.\u0000 We propose a system suited for deeply embedded systems that allows to choose among no protection, software-based protection, hardware-based protection or a combination of the two without the need to change the application. In this paper, we present the current state of this work and support our claim that the best-suited memory protection type depends on the application by a preliminary evaluation.","PeriodicalId":221742,"journal":{"name":"EDCC-CARS","volume":"1 1","pages":"0"},"PeriodicalIF":0.0,"publicationDate":"2010-04-27","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"128969562","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 3
Opportunities from standardization in automotive safety assessment 汽车安全评估标准化带来的机遇
Pub Date : 2010-04-27 DOI: 10.1145/1772643.1772661
R. Barbosa, J. Karlsson
An important initiative in the automotive domain is the development of the ISO 26262 standard for functional safety of road vehicles. The standard introduces numerous techniques for analysis and verification throughout the lifecycle of automotive systems. There is therefore a need for the scientific community to contribute with new and existing knowledge on safety assessment. This position paper identifies challenges and opportunities for research in automotive safety assessment by connecting the research roadmap published in the AMBER project with the ISO 26262 standard.
汽车领域的一项重要举措是制定道路车辆功能安全的ISO 26262标准。该标准在汽车系统的整个生命周期中引入了许多分析和验证技术。因此,科学界需要提供有关安全评估的新的和现有的知识。本意见书通过将AMBER项目中发布的研究路线图与ISO 26262标准相结合,确定了汽车安全评估研究的挑战和机遇。
{"title":"Opportunities from standardization in automotive safety assessment","authors":"R. Barbosa, J. Karlsson","doi":"10.1145/1772643.1772661","DOIUrl":"https://doi.org/10.1145/1772643.1772661","url":null,"abstract":"An important initiative in the automotive domain is the development of the ISO 26262 standard for functional safety of road vehicles. The standard introduces numerous techniques for analysis and verification throughout the lifecycle of automotive systems. There is therefore a need for the scientific community to contribute with new and existing knowledge on safety assessment. This position paper identifies challenges and opportunities for research in automotive safety assessment by connecting the research roadmap published in the AMBER project with the ISO 26262 standard.","PeriodicalId":221742,"journal":{"name":"EDCC-CARS","volume":"33 1","pages":"0"},"PeriodicalIF":0.0,"publicationDate":"2010-04-27","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"116681872","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 1
Conditional safety certificates in open systems 开放系统中的条件安全证书
Pub Date : 2010-04-27 DOI: 10.1145/1772643.1772660
D. Schneider, M. Trapp
In the wake of current computing trends like Ubiquitous Computing, Ambient Intelligence and Cyber Physical Systems, new application domains like Car2Car emerged. One key characteristic of these new application domains is their openness with respect to dynamic integration of devices and components. It is obvious that traditional safety assurance techniques, both state of the practice and state of the art, are not sufficient in this context. A possible solution approach would be to shift portions of the safety assurance process into run time. This can be reached by the integration of appropriate run time safety models and corresponding dynamic evaluation mechanisms. In this paper we sketch out our recent work on conditional safety certificates, which facilitate such dynamic safety evaluation. We conclude with a brief discussion and state promising research directions for the future.
随着普适计算(Ubiquitous computing)、环境智能(Ambient Intelligence)和网络物理系统(Cyber Physical Systems)等当前计算趋势的兴起,Car2Car等新的应用领域应运而生。这些新应用领域的一个关键特征是它们在设备和组件的动态集成方面的开放性。显然,传统的安全保证技术,无论是实践状况还是技术状况,在这方面都是不够的。一种可能的解决方案是将部分安全保证过程转移到运行时。这可以通过集成适当的运行时安全模型和相应的动态评估机制来实现。在本文中,我们概述了我们最近在条件安全证书方面的工作,这有助于这种动态安全评价。最后,我们对其进行了简要的讨论,并展望了未来的研究方向。
{"title":"Conditional safety certificates in open systems","authors":"D. Schneider, M. Trapp","doi":"10.1145/1772643.1772660","DOIUrl":"https://doi.org/10.1145/1772643.1772660","url":null,"abstract":"In the wake of current computing trends like Ubiquitous Computing, Ambient Intelligence and Cyber Physical Systems, new application domains like Car2Car emerged. One key characteristic of these new application domains is their openness with respect to dynamic integration of devices and components. It is obvious that traditional safety assurance techniques, both state of the practice and state of the art, are not sufficient in this context. A possible solution approach would be to shift portions of the safety assurance process into run time. This can be reached by the integration of appropriate run time safety models and corresponding dynamic evaluation mechanisms. In this paper we sketch out our recent work on conditional safety certificates, which facilitate such dynamic safety evaluation. We conclude with a brief discussion and state promising research directions for the future.","PeriodicalId":221742,"journal":{"name":"EDCC-CARS","volume":"14 1","pages":"0"},"PeriodicalIF":0.0,"publicationDate":"2010-04-27","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"122204805","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 23
A calculation method for software safety integrity level 一种软件安全完整性等级的计算方法
Pub Date : 2010-04-27 DOI: 10.1145/1772643.1772653
T. Fujiwara, J. Estevez, Yoshinobu Satoh, S. Yamada
In the functional safety standards (IEC 61508 and ISO/DIS 26262), development methods and quantitative analytical methods are defined for establishment of safety-related systems. However, only development methods are recommended to establish the software of safety-related systems. That is, the safety integrity level for software is determined only by the number of the development methods applied to practical safety-related system development. This is not reasonable to evaluate the safety integrity level, because various risk factors should be taken up. In this paper, we propose how to calculate the safety integrity level for software. Especially, we propose the calculation method based on the software reliability growth model that has long been used in the large-scale system development.
在功能安全标准(IEC 61508和ISO/DIS 26262)中,定义了建立安全相关系统的开发方法和定量分析方法。然而,仅推荐开发方法来建立安全相关系统的软件。也就是说,软件的安全完整性水平仅取决于应用于实际安全相关系统开发的开发方法的数量。这样评价安全完整性水平是不合理的,因为要考虑各种风险因素。本文提出了软件安全完整性等级的计算方法。特别提出了在大型系统开发中应用已久的软件可靠性增长模型的计算方法。
{"title":"A calculation method for software safety integrity level","authors":"T. Fujiwara, J. Estevez, Yoshinobu Satoh, S. Yamada","doi":"10.1145/1772643.1772653","DOIUrl":"https://doi.org/10.1145/1772643.1772653","url":null,"abstract":"In the functional safety standards (IEC 61508 and ISO/DIS 26262), development methods and quantitative analytical methods are defined for establishment of safety-related systems. However, only development methods are recommended to establish the software of safety-related systems. That is, the safety integrity level for software is determined only by the number of the development methods applied to practical safety-related system development. This is not reasonable to evaluate the safety integrity level, because various risk factors should be taken up. In this paper, we propose how to calculate the safety integrity level for software. Especially, we propose the calculation method based on the software reliability growth model that has long been used in the large-scale system development.","PeriodicalId":221742,"journal":{"name":"EDCC-CARS","volume":"1 1","pages":"0"},"PeriodicalIF":0.0,"publicationDate":"2010-04-27","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"115053754","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 8
期刊
EDCC-CARS
全部 Acc. Chem. Res. ACS Applied Bio Materials ACS Appl. Electron. Mater. ACS Appl. Energy Mater. ACS Appl. Mater. Interfaces ACS Appl. Nano Mater. ACS Appl. Polym. Mater. ACS BIOMATER-SCI ENG ACS Catal. ACS Cent. Sci. ACS Chem. Biol. ACS Chemical Health & Safety ACS Chem. Neurosci. ACS Comb. Sci. ACS Earth Space Chem. ACS Energy Lett. ACS Infect. Dis. ACS Macro Lett. ACS Mater. Lett. ACS Med. Chem. Lett. ACS Nano ACS Omega ACS Photonics ACS Sens. ACS Sustainable Chem. Eng. ACS Synth. Biol. Anal. Chem. BIOCHEMISTRY-US Bioconjugate Chem. BIOMACROMOLECULES Chem. Res. Toxicol. Chem. Rev. Chem. Mater. CRYST GROWTH DES ENERG FUEL Environ. Sci. Technol. Environ. Sci. Technol. Lett. Eur. J. Inorg. Chem. IND ENG CHEM RES Inorg. Chem. J. Agric. Food. Chem. J. Chem. Eng. Data J. Chem. Educ. J. Chem. Inf. Model. J. Chem. Theory Comput. J. Med. Chem. J. Nat. Prod. J PROTEOME RES J. Am. Chem. Soc. LANGMUIR MACROMOLECULES Mol. Pharmaceutics Nano Lett. Org. Lett. ORG PROCESS RES DEV ORGANOMETALLICS J. Org. Chem. J. Phys. Chem. J. Phys. Chem. A J. Phys. Chem. B J. Phys. Chem. C J. Phys. Chem. Lett. Analyst Anal. Methods Biomater. Sci. Catal. Sci. Technol. Chem. Commun. Chem. Soc. Rev. CHEM EDUC RES PRACT CRYSTENGCOMM Dalton Trans. Energy Environ. Sci. ENVIRON SCI-NANO ENVIRON SCI-PROC IMP ENVIRON SCI-WAT RES Faraday Discuss. Food Funct. Green Chem. Inorg. Chem. Front. Integr. Biol. J. Anal. At. Spectrom. J. Mater. Chem. A J. Mater. Chem. B J. Mater. Chem. C Lab Chip Mater. Chem. Front. Mater. Horiz. MEDCHEMCOMM Metallomics Mol. Biosyst. Mol. Syst. Des. Eng. Nanoscale Nanoscale Horiz. Nat. Prod. Rep. New J. Chem. Org. Biomol. Chem. Org. Chem. Front. PHOTOCH PHOTOBIO SCI PCCP Polym. Chem.
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1