Architecture Modeling - SPES 2020
Architecture Modeling - SPES 2020
Architecture Modeling - SPES 2020
Create successful ePaper yourself
Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.
Patternn<br />
Failuure<br />
has cr riticalityy<br />
critical lity<br />
S7:<br />
This paattern<br />
allows to associate e failures withh<br />
criticalities s that have been<br />
derived for instance e from the<br />
hazard classification<br />
during FHA A (functional hazard asse essment).<br />
Naturaal<br />
Language Requirement:<br />
Loss of the braking syst tem is considdered<br />
hazard dous<br />
Patternn<br />
based RSLL:<br />
LossOfBraakingSyste<br />
em has criiticality<br />
hazardous s<br />
Patteern<br />
hazarrd<br />
Hazard is definned<br />
by ( event e )<br />
S8:<br />
This ppattern<br />
can bbe<br />
used to describe<br />
the hhazard.<br />
The event repres sents the point<br />
in time wh here the<br />
hazarrd<br />
occurs.<br />
Natural<br />
Languagge<br />
Requirem ment:<br />
Unannnounced<br />
losss<br />
of deceleration<br />
capability<br />
during landing<br />
Patteern<br />
based RSL:<br />
<strong>Architecture</strong> <strong>Modeling</strong><br />
Hazaard<br />
UnannoouncedLoss<br />
sOfDecelerrationCapa<br />
ability is s defined by<br />
((CoontrolLampp==1)<br />
hold ds not durring<br />
[tr(p phase==Lan nding),PeddalPushed]<br />
] and<br />
thenn<br />
Brake noot<br />
during [PedalPusshed,500ms<br />
s])<br />
This eexample<br />
is taaken<br />
from the<br />
ARP4754 standard. Th he following graphic g explaains<br />
the form malization<br />
in moore<br />
detail:<br />
The CControlLampp<br />
indicates the<br />
failure of thhe<br />
braking system.<br />
Since e the hazard only occurs if the<br />
failuree<br />
is unannouunced<br />
there shall s be no innterruption<br />
in n the Control lLamp signall<br />
between the<br />
start of<br />
the laanding<br />
proceess<br />
and the PedalPushed<br />
P d event. This is expressed d in the first part of the ev vent<br />
descrription<br />
of the pattern:<br />
... (ControlLLamp==1)<br />
holds h not during [t tr(phase== =Landing), ,PedalPush hed] ..<br />
T1 exxpresses<br />
thee<br />
time in whic ch a brake reeaction<br />
to the e request by the pedal is expected. Is s there no<br />
Brakee<br />
event in thiis<br />
interval the e hazard occcurs:<br />
.... ... Brakee<br />
not duri ing [PedallPushed,50<br />
00ms] .... ....<br />
132/ 156