-
Notifications
You must be signed in to change notification settings - Fork 1
Expand file tree
/
Copy pathExampleSTPA.sysml
More file actions
179 lines (178 loc) · 7.67 KB
/
Copy pathExampleSTPA.sysml
File metadata and controls
179 lines (178 loc) · 7.67 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
package PaperExample {
private import LibrarySTPA::DefineAnalysisPurpose::*;
private import LibrarySTPA::ModelControlStructure::*;
private import LibrarySTPA::IdentifyUCAs::*;
private import LibrarySTPA::IdentifyLSs::*;
private import LibrarySTPA::MetaTypesSTPA::*;
private import LibrarySTPA::ViewsAndViewpoints::DefineAnalysisPurposeViews::*;
package DefineAnalysisPurpose {
package Stakeholders {
part def Passenger;
part def Manufacturer;
part def Operator;
concern Safety {
subject Ushift;
stakeholder : Passenger;
stakeholder : Manufacturer;
stakeholder : Operator;
}
concern Reputation {
subject Ushift;
stakeholder : Manufacturer;
stakeholder : Operator;
}
}
package Losses {
#loss occurrence LossOfCustomerSatisfaction {
:>> stakeholderConcern = Stakeholders::Reputation;
}
#loss occurrence LossOfLife {
:>> stakeholderConcern = Stakeholders::Safety;
}
}
package Hazards {
#hazard occurrence VehicleCanNotExecuteMission {
:>> lossesRef = (Losses::LossOfCustomerSatisfaction, Losses::LossOfLife);
}
#hazard occurrence VehicleTooCloseToPeople {
:>> lossesRef = Losses::LossOfLife;
}
}
}
package ModelControlStructure {
#controlStructure part UshiftCS {
:>> controllersRef = (Ushift.ControlElectronics, Teleoperator, Passenger, OtherTraffic, VRUs, Environment);
:>> actuatorsRef = Ushift.DriveSystem;
:>> sensorsRef = Ushift.PerceptionSystem;
:>> processesRef = VehicleMovement;
:>> controlActionsRef = (teleoperatorCMD, maneuverCMD, vehicleForces, travelCMD);
:>> feedbacksRef = (vehiclePerception, vehicleMovement, vehicleHealth, vehicleStatus, roadPerception, vruPerception, otherTrafficPerception);
#controller part Ushift {
#controller part ControlElectronics {
:>> processBeliefs = (VehicleLimitations, OperationalMode, UnderstandingOfPassengerBehavior, AssumptionAboutRoadInfrastructure, PassengerCapacity);
#processModel part VehicleLimitations;
#processModel part OperationalMode;
#processModel part UnderstandingOfPassengerBehavior;
#processModel part AssumptionAboutRoadInfrastructure;
#processModel part PassengerCapacity;
}
#sensor part PerceptionSystem;
#actuator part DriveSystem;
}
#controllerHuman part Teleoperator {
:>> mentalBeliefs = CurrentWorkload;
#mentalModel part CurrentWorkload;
}
#controllerHuman part Passenger {
:>> mentalBeliefs = UnderstandingOfVehicleBehavior;
#mentalModel part UnderstandingOfVehicleBehavior;
}
#controller part OtherTraffic;
#controller part VRUs;
#controller part Environment;
#process part VehicleMovement;
#controlAction flow teleoperatorCMD {
end ::> Teleoperator;
end ::> Ushift.ControlElectronics;
}
#feedback flow vehicleHealth {
end ::> Ushift.ControlElectronics;
end ::> Teleoperator;
}
#feedback flow vehicleStatus {
end ::> Ushift.ControlElectronics;
end ::> Passenger;
}
#controlAction flow maneuverCMD {
end ::> Ushift.ControlElectronics;
end ::> Ushift.DriveSystem;
}
#controlAction flow vehicleForces {
end ::> Ushift.DriveSystem;
end ::> VehicleMovement;
}
#feedback flow vehicleMovement {
end ::> VehicleMovement;
end ::> Ushift.PerceptionSystem;
}
#feedback flow roadPerception {
end ::> Environment;
end ::> Ushift.PerceptionSystem;
}
#feedback flow vruPerception {
end ::> VRUs;
end ::> Ushift.PerceptionSystem;
}
#feedback flow otherTrafficPerception {
end ::> OtherTraffic;
end ::> Ushift.PerceptionSystem;
}
#feedback flow vehiclePerception {
end ::> Ushift.PerceptionSystem;
end ::> Ushift.ControlElectronics;
}
#controlAction flow travelCMD {
end ::> Passenger;
end ::> Ushift.ControlElectronics;
}
doc /* This shows a simplified control structure of DLR's Ushift concept vehicle using the defined element types of the SysML v2 library for SysML v2*/
}
}
package IdentifyUCAs {
package Contexts {
#context occurrence EmergencyStateDueToClosedOneWayStreet {
:>> systemConditions = EmergencyState;
:>> environmentalConditions = ClosedOneWayStreet;
}
#sysCon occurrence EmergencyState;
#envCon occurrence ClosedOneWayStreet;
}
package UCAs {
#uca occurrence TeleoperatorDoesNotProvideOperationCommand {
doc /* Teleoperator does not provide operation command when the automated vehicle is in an emergency situation */
:>> sourceRef = ModelControlStructure::UshiftCS.Teleoperator;
:>> controlActionRef = ModelControlStructure::UshiftCS.teleoperatorCMD;
:>> typeRef = typesOfCAs.NotProvided;
:>> receiverRef = ModelControlStructure::UshiftCS.Ushift.ControlElectronics;
:>> contextRef = Contexts::EmergencyStateDueToClosedOneWayStreet;
:>> hazardsRef = DefineAnalysisPurpose::Hazards::VehicleCanNotExecuteMission;
}
}
}
package IdentifyLSs {
package CausalFactors {
#cf occurrence TeleoperatorNotInformed {
:>> factorRef = ModelControlStructure::UshiftCS.vehicleStatus;
attribute :>> status = "not forwarded";
}
}
package LossScenarios {
#ls occurrence TeleoperatorNotAwareOfVehiclesEmergencySituation {
doc /* The automated vehicle drives into a one way street which is closed and can not resolve the situation. However, the teleoperator is not aware that he is responsible for the vehicle. As a result, the teleoperator does not provide a resolving operation command */
:>> causalFactorsRef = CausalFactors::TeleoperatorNotInformed;
:>> ucasRef = IdentifyUCAs::UCAs::TeleoperatorDoesNotProvideOperationCommand;
}
}
}
//package ViewsCameo {
// private import CameoViewsSTPA::**;
// view ShowLosses : DefineLosses::LossTree {
// expose DefineAnalysisPurpose::Losses::*;
// }
// view HazardsAndLosses : HazardsTable {
// expose DefineAnalysisPurpose::**;
// filter @hazard;
// }
// view UCAs : UCAsTable {
// expose IdentifyUCAs::**;
// filter @uca;
// }
// view LSs : LSsTable {
// expose IdentifyLSs::**;
// filter @ls;
// }
// package ControlStructureDemo {
// view ControlStructureDemo : CameoViewsSTPA::CustomViewsSTPA::'STPA View';
// }
//}
}