• DocumentCode
    1290078
  • Title

    Reasoning about the Reliability of Diverse Two-Channel Systems in Which One Channel Is "Possibly Perfect"

  • Author

    Littlewood, Bev ; Rushby, John

  • Author_Institution
    Centre for Software Reliability, City Univ., London, UK
  • Volume
    38
  • Issue
    5
  • fYear
    2012
  • Firstpage
    1178
  • Lastpage
    1194
  • Abstract
    This paper refines and extends an earlier one by the first author [1]. It considers the problem of reasoning about the reliability of fault-tolerant systems with two “channels” (i.e., components) of which one, A, because it is conventionally engineered and presumed to contain faults, supports only a claim of reliability, while the other, B, by virtue of extreme simplicity and extensive analysis, supports a plausible claim of “perfection.” We begin with the case where either channel can bring the system to a safe state. The reasoning about system probability of failure on demand (pfd) is divided into two steps. The first concerns aleatory uncertainty about 1) whether channel A will fail on a randomly selected demand and 2) whether channel B is imperfect. It is shown that, conditional upon knowing pA (the probability that A fails on a randomly selected demand) and pB (the probability that channel B is imperfect), a conservative bound on the probability that the system fails on a randomly selected demand is simply pA X pB. That is, there is conditional independence between the events “A fails” and “B is imperfect.” The second step of the reasoning involves epistemic uncertainty, represented by assessors´ beliefs about the distribution of (pA, pB), and it is here that dependence may arise. However, we show that under quite plausible assumptions, a conservative bound on system pfd can be constructed from point estimates for just three parameters. We discuss the feasibility of establishing credible estimates for these parameters. We extend our analysis from faults of omission to those of commission, and then combine these to yield an analysis for monitored architectures of a kind proposed for aircraft.
  • Keywords
    aircraft; probability; reasoning about programs; software fault tolerance; uncertainty handling; PFD; aircraft; aleatory uncertainty; assessors belief; conditional independence; diverse two-channel system; epistemic uncertainty; fault tolerant system; probability of failure on demand; randomly selected demand; reasoning about the reliability; Cognition; Phase frequency detector; Safety; Software; Software reliability; Uncertainty; Software reliability; assurance case; program correctness; software diversity; software fault tolerance;
  • fLanguage
    English
  • Journal_Title
    Software Engineering, IEEE Transactions on
  • Publisher
    ieee
  • ISSN
    0098-5589
  • Type

    jour

  • DOI
    10.1109/TSE.2011.80
  • Filename
    5975177