2013
DOI: 10.1007/s00165-011-0203-6
|View full text |Cite
|
Sign up to set email alerts
|

The mechanical generation of fault trees for reactive systems via retrenchment II: clocked and feedback circuits

Abstract: Abstract. The manual construction of fault trees for complex systems is an error-prone and time-consuming activity, encouraging automated techniques. In this paper we show how the retrenchment approach to formal system model evolution can be developed into a versatile structured approach for the mechanical construction of fault trees. The system structure and the structure of retrenchment concessions interact to generate fault trees with appropriately deep nesting. We show how this approach can be extended to … Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
2
1
1
1

Citation Types

0
7
0

Year Published

2013
2013
2023
2023

Publication Types

Select...
4
3

Relationship

5
2

Authors

Journals

citations
Cited by 9 publications
(7 citation statements)
references
References 26 publications
0
7
0
Order By: Relevance
“…Our work is similar in spirit to [5], which presents a methodology based on retrenchment (an extension of classical refinement), to generate hierarchical FTs from systems represented as circuits, exploiting the system dataflow. A major difference is that retrenchment does not focus on top-down development, but rather on the relation between nominal and faulty behaviors.…”
Section: Related Workmentioning
confidence: 96%
“…Our work is similar in spirit to [5], which presents a methodology based on retrenchment (an extension of classical refinement), to generate hierarchical FTs from systems represented as circuits, exploiting the system dataflow. A major difference is that retrenchment does not focus on top-down development, but rather on the relation between nominal and faulty behaviors.…”
Section: Related Workmentioning
confidence: 96%
“…If there had been, the second occurrence of GearStartMoving_S would have been disabled in the pilot machine, causing problems. 8 We have discussed this point with some care because the same issue arises every time the computers issue commands to any of the remaining equipment, e.g. to the analogical switch, or to the hydraulic apparatus.…”
Section: The Nominal Regimementioning
confidence: 99%
“…For this to work, the pilot's handle events are further synchronised with analogical switch events that reset clk_AnSw to the appro- 7 Dealing with this properly in the Conf development caused the majority of the excessive verbosity. 8 It may be argued that the phenomenon being discussed is absent at level 00, so the guard could have been included there, and removed at level 01, but in Event-B refinement, guards are strengthened, so this would have prevented the 00 to 01 development step from being an Event-B refinement. priate value, depending on its value at the occurrence of the handle event (N. B.…”
Section: The Nominal Regimementioning
confidence: 99%
See 1 more Smart Citation
“…Even at this stage in the design process, systems may exhibit a high degree of complexity (Roy et al 2013), and formal modelling of the system typically captures the ideal, fault-free, conception of the system. Subsequently, the resultant FTA is based on an informal description of the underlying system (Ericson 2005), or requires modelling the system in an separate FTA specific modelling language (Liggesmeyer & Rothfelder 1998, Banach & Bozzano 2011. This makes it difficult to check the consistency of the analysis, because it is possible that causes are noted in the tree which do not lead to the failure (incorrectness) or that some causes of failure are overlooked (incompleteness).…”
Section: Introductionmentioning
confidence: 99%