Applying Safety Concepts and Principles in Vital Controller Design

Authors

  • Fenggang Shi

DOI:

https://doi.org/10.56094/jss.v56i1.31

Keywords:

controller, train, fail-safe, safety integrity level

Abstract

A vital controller is safety critical and its failures, if not mitigated in time, can contribute to hazards in the application system. With electronics advancing and automation increasing, the expanding complexity of a vital controller creates challenges in designing it and assessing its safety integrity level. Typically, traditional safety engineering approaches are not effective for providing systematic guidance to design vital controllers and also not cost efficient for justifying their safety integrity. Through practice on developing multiple Communications-Based Train Control systems, we have identified an approach to using a set of safety concepts as guidance for both safety critical controller design and its safety integrity assessment. These safety concepts are categorized as intrinsic fail-safe, reactive fail-safe, and composite fail-safe. An effective combination of them is applying the composite fail-safe concept in checked redundancy techniques for designing the architecture of a controller, the reactive safety concept for identifying self-testing and monitoring mechanisms in each checked redundant channel, and the intrinsic fail-safe concept for ensuring safe interfaces to other controllers and controlled devices. This paper presents the approach for using these safety concepts and discusses their application principles and verification factors for achieving high safety integrity level of a controller.

Author Biography

Fenggang Shi

Fenggang Shi, Ph.D., is senior expert and chief safety architect at Thales Canada Transportation Solutions in Toronto, Canada. He has 25 years of experience in the fi eld of CBTC system safety engineering. Shi has been the technical leader and supervisor of safety teams on more than 40 CBTC systems and products for future signaling.

References

CENELEC BS EN 50129. "Railway Applications - Communication, signalling, and processing systems - Safety Related Electronic Systems for Signalling," European Committee for Electrotechnical Standardization (CENELEC), 2018.

IEEE Std 1483-2000. "IEEE Standard for Verification of Vital Functions in Processor-Based Systems Used in Rail Transit Control," IEEE Standards Association, 2000.

Shi, F. "Defining Layered Safety Concepts based on Open System Architectures as Foundation for Multi-Suppli-ers to Develop Interoperable Safety Critical Systems," Proceedings of International System Safety Conference, 2014.

Shi, F. "Using Layered Safety Objectives and Concepts to Guide Large Scale System Designs for Achieving Built-in Safety Properties in Hierarchy," Proceedings of International System Safety Conference, 2015.

Article

Downloads

Published

2020-07-01

How to Cite

Shi, F. (2020). Applying Safety Concepts and Principles in Vital Controller Design. Journal of System Safety, 56(1), 13–20. https://doi.org/10.56094/jss.v56i1.31