ISE Functional Safety of Drone System: About Risk
ISE Functional Safety of Drone System: About Risk
∗
Ricardo Sanz
∗
Universidad Politcnica de Madrid — Autonomous Systems Laboratory
This exercise addresses the need of achieving the necessary safety Functional safety engineering is enabling the system to
for the INGENIA SE challenge. detect a potentially dangerous condition and activate activate
a protective or corrective subsystem or behaviour to prevent
Keywords: SE | Functional Safety | IEC 61508 hazardous events arising or providing mitigation to reduce the
consequence of the hazardous event.
Parts of this text have been obtained from the public web-
I NGENIA Systems Engineering (ISE) focuses on systems en-
gineering of software-intensive autonomous systems. This
requires from the student teams the capability of building
sites of the IEC and Wikipedia:
https://en.wikipedia.org/wiki/IEC_61508
complex systems. http://www.iec.ch/functionalsafety
This exercise (Ex01) focuses on functional safety of those
systems.
About risk
Contents
Introduction 1 Table 1 – Consequence categories
Category Definition
About risk 1 Catastrophic Multiple loss of life
Critical Loss of a single life
A dual concept of functional safety 1 Marginal Major injuries to one or more persons
Negligible Minor injuries at worst
IEC 61508 1
FS for INGENIA SE Drone Challenge ISE January 9, 2018 Ex01 v0.0 1–4
IEC 61508-1 — General requirements; ISO 26262. ISO 26262 is an adaptation of IEC 61508 for
IEC 61508-2 — Requirements for electrical / electronic / Automotive Electric/Electronic Systems. It is being widely
programmable electronic safety-related systems; adopted by the major car manufacturers.
IEC 61508-3 — Software requirements;
IEC 61508-4 — Definitions and abbreviations; IEC 62279. IEC 62279 provides a specific interpretation of
IEC 61508-5 — Examples of methods for the determination IEC 61508 for railway applications.
of safety integrity levels;
IEC 61508-6 — Guidelines on the application of IEC 61508- IEC 61513. IEC 61513 provides requirements and recommen-
2 and IEC 61508-3; dations for the instrumentation and control for systems im-
IEC 61508-7 — Overview of techniques and measures. portant to safety of nuclear power plants.
Other Specs
Relevant references
The IEC 61508 standard is considered a fundamental or ?root?
standard for functional safety. It is intentionally generic and The Eclipse Safety Framework (ESF) project provides a set of
vague to give room to domain-specific developments. IEC tools that enable both modelling and analysis of safety con-
61508 enables that various industry sectors develop their own cerns in the context of modelling standards such as SysML
specific standards based on established domain practices (e.g. and MARTE.
61513 for the nuclear domain, 62061 for the machine safety https://www.polarsys.org/proposals/
domain, and 61511 for the process control domain). eclipse-safety-framework
Glossary
IEC 61511. IEC 61511 is an IEC standard which sets out prac-
tices in the engineering of systems that ensure the safety of an domain-specific it is said of an entity that is tailored to an
industrial process through the use of specific safety instrumen- specific domain of application (in opposition to be general
tation. Such systems are referred to as Safety Instrumented or cross-domain). 1
Systems. The title of the standard is "IEC 61511 Func- functional safety is the part of the overall safety that de-
tional safety - Safety instrumented systems for the pends on a system operating correctly in response to its
process industry sector". inputs. 1
risk is a .... 1
References
IEC (2016a). IEC 61508-3-1:2016 functional safety of electri-
cal/electronic/programmable electronic safety-related sys-
tems - part 3-1: Software requirements - reuse of pre-
existing software elements to implement all or part of a
safety function. International Standard IEC TS 61508-3-
1:2016, International Electrotecnical Commission.
IEC (2016b). IEC 61508-3:2010 functional safety of electri-
cal/electronic/programmable electronic safety-related sys-
tems - part 3: Software requirements. International Stan-
dard IEC TS 61508-3:2010, International Electrotecnical
Commission.
IEC (2016c). IEC 61511-1:2016 functional safety - safety in-
strumented systems for the process industry sector - part 1:
Framework, definitions, system, hardware and application
Figure 1 – The 61508 family of standards have general parts and programming requirements. International Standard IEC
domain-specific parts. 61511-1:2016, International Electrotecnical Commission.