核电厂关键安全控制系统软件可靠性定量需求确定的自动化

B. Volochiy, O. Mulyak, L. Ozirkovskyi, V. Kharchenko
{"title":"核电厂关键安全控制系统软件可靠性定量需求确定的自动化","authors":"B. Volochiy, O. Mulyak, L. Ozirkovskyi, V. Kharchenko","doi":"10.1109/SMRLO.2016.62","DOIUrl":null,"url":null,"abstract":"Providing the high availability level for the Instrumentation and Control (I&C) Systems in Nuclear Power Plants (NPP) is highly important. The availability of the critical NPP I&C systems depends on the hardware and software reliability behavior. The high availability of the I&C systems is ensured by the following measures: structural redundancy with choice of the I&C system configurations (two comparable sub-systems in the I&C system, majority voting \"2oo3\", \"2oo4\", etc.), maintenance of the I&C system, which implies the repair (changing) of no operational modules, using the N-version programming, software updates, automatic software restart after temporary interrupts caused by the hardware fault. This paper proposes solution of the following case: the configuration of the fault-tolerant I&C system with known reliability indexes of hardware (failure rate and temporary failure rate) is chosen, the maintenance strategy of hardware (mean time to repair, numbers of repair) is specified. In these circumstances it is important to determine quantitative requirements to software reliability: number of software updates during operation I&C system, acceptable duration of the new software version development, acceptable duration of the automatic software restart, determination of acceptable failure rate for each software version. The value of the operational software parameters is determined for the specified availability level of the I&C system. The planned number of software updates determines the duration of testing in order to identify and correct the design faults. Duration of the software testing is limited to the moment when predicted model shows a specified number of hidden (undetected) design faults. To solve this issue, the availability model of the fault-tolerant I&C system was developed in the discrete-continuous stochastic system form. We have estimated the influence of the I&C system on the operational software parameters. Two configurations of I&C systems are presented in this paper: two comparable sub-systems in I&C system, and I&C system with majority voting \"2oo3\".","PeriodicalId":254910,"journal":{"name":"2016 Second International Symposium on Stochastic Models in Reliability Engineering, Life Science and Operations Management (SMRLO)","volume":"47 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2016-02-15","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"7","resultStr":"{\"title\":\"Automation of Quantitative Requirements Determination to Software Reliability of Safety Critical NPP I&C Systems\",\"authors\":\"B. Volochiy, O. Mulyak, L. Ozirkovskyi, V. Kharchenko\",\"doi\":\"10.1109/SMRLO.2016.62\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"Providing the high availability level for the Instrumentation and Control (I&C) Systems in Nuclear Power Plants (NPP) is highly important. The availability of the critical NPP I&C systems depends on the hardware and software reliability behavior. The high availability of the I&C systems is ensured by the following measures: structural redundancy with choice of the I&C system configurations (two comparable sub-systems in the I&C system, majority voting \\\"2oo3\\\", \\\"2oo4\\\", etc.), maintenance of the I&C system, which implies the repair (changing) of no operational modules, using the N-version programming, software updates, automatic software restart after temporary interrupts caused by the hardware fault. This paper proposes solution of the following case: the configuration of the fault-tolerant I&C system with known reliability indexes of hardware (failure rate and temporary failure rate) is chosen, the maintenance strategy of hardware (mean time to repair, numbers of repair) is specified. In these circumstances it is important to determine quantitative requirements to software reliability: number of software updates during operation I&C system, acceptable duration of the new software version development, acceptable duration of the automatic software restart, determination of acceptable failure rate for each software version. The value of the operational software parameters is determined for the specified availability level of the I&C system. The planned number of software updates determines the duration of testing in order to identify and correct the design faults. Duration of the software testing is limited to the moment when predicted model shows a specified number of hidden (undetected) design faults. To solve this issue, the availability model of the fault-tolerant I&C system was developed in the discrete-continuous stochastic system form. We have estimated the influence of the I&C system on the operational software parameters. Two configurations of I&C systems are presented in this paper: two comparable sub-systems in I&C system, and I&C system with majority voting \\\"2oo3\\\".\",\"PeriodicalId\":254910,\"journal\":{\"name\":\"2016 Second International Symposium on Stochastic Models in Reliability Engineering, Life Science and Operations Management (SMRLO)\",\"volume\":\"47 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2016-02-15\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"7\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2016 Second International Symposium on Stochastic Models in Reliability Engineering, Life Science and Operations Management (SMRLO)\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/SMRLO.2016.62\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2016 Second International Symposium on Stochastic Models in Reliability Engineering, Life Science and Operations Management (SMRLO)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/SMRLO.2016.62","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 7

摘要

为核电站的仪表与控制系统提供高可用性是非常重要的。核电站关键测控系统的可用性取决于硬件和软件的可靠性行为。控制系统的高可用性是通过以下措施来保证的:控制系统配置选择的结构冗余(控制系统中两个可比较的子系统,多数表决“2003”、“2004”等),控制系统的维护,这意味着没有操作模块的修复(更改),使用n版本编程,软件更新,在硬件故障造成的临时中断后自动重新启动软件。本文提出了以下解决方案:选择硬件可靠性指标(故障率和临时故障率)已知的容错I&C系统配置,确定硬件的维护策略(平均维修时间、维修次数)。在这种情况下,确定对软件可靠性的定量要求是很重要的:在I&C系统运行期间软件更新的次数,新软件版本开发的可接受时间,软件自动重启的可接受时间,确定每个软件版本的可接受故障率。操作软件参数的值是根据I&C系统的指定可用性级别确定的。计划的软件更新数量决定了测试的持续时间,以便识别和纠正设计错误。软件测试的持续时间被限制在预测模型显示指定数量的隐藏(未检测到的)设计错误的时刻。为解决这一问题,采用离散-连续随机系统的形式建立了容错I&C系统的可用性模型。我们估计了测控系统对运行软件参数的影响。本文提出了两种测控系统的结构:测控系统中的两个可比较子系统,以及多数表决“2003”的测控系统。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
Automation of Quantitative Requirements Determination to Software Reliability of Safety Critical NPP I&C Systems
Providing the high availability level for the Instrumentation and Control (I&C) Systems in Nuclear Power Plants (NPP) is highly important. The availability of the critical NPP I&C systems depends on the hardware and software reliability behavior. The high availability of the I&C systems is ensured by the following measures: structural redundancy with choice of the I&C system configurations (two comparable sub-systems in the I&C system, majority voting "2oo3", "2oo4", etc.), maintenance of the I&C system, which implies the repair (changing) of no operational modules, using the N-version programming, software updates, automatic software restart after temporary interrupts caused by the hardware fault. This paper proposes solution of the following case: the configuration of the fault-tolerant I&C system with known reliability indexes of hardware (failure rate and temporary failure rate) is chosen, the maintenance strategy of hardware (mean time to repair, numbers of repair) is specified. In these circumstances it is important to determine quantitative requirements to software reliability: number of software updates during operation I&C system, acceptable duration of the new software version development, acceptable duration of the automatic software restart, determination of acceptable failure rate for each software version. The value of the operational software parameters is determined for the specified availability level of the I&C system. The planned number of software updates determines the duration of testing in order to identify and correct the design faults. Duration of the software testing is limited to the moment when predicted model shows a specified number of hidden (undetected) design faults. To solve this issue, the availability model of the fault-tolerant I&C system was developed in the discrete-continuous stochastic system form. We have estimated the influence of the I&C system on the operational software parameters. Two configurations of I&C systems are presented in this paper: two comparable sub-systems in I&C system, and I&C system with majority voting "2oo3".
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信