The growing complexity of airborne embedded systems has made safety assessment an increasingly demanding activity throughout development and certification. In industrial practice, traditional techniques such as Fault Tree Analysis (FTA) remain widely adopted, but they often prove difficult to maintain, reuse, and update as system architectures evolve, particularly during the early design phases. In this context, Model-Based Safety Analysis (MBSA) has emerged as a promising approach for supporting safety engineering through formal, executable, and reusable models, and is explicitly recognized in ARP4761A as an acceptable method for failure-propagation analysis and probability evaluation. This thesis investigates the role of MBSA in the early development of complex airborne systems, with particular reference to flight control applications. The work proposes a structured MBSA workflow aimed at generating quantitative safety evidence while supporting major safety-assessment outcomes, including the identification of single points of failure, the rationale for Design Assurance Level (DAL) allocation, the treatment of common-cause considerations, and the derivation of safety requirements. To this end, the AltaRica language is adopted to model safety-relevant behaviour and failure propagation, while the Cecilia Workshop environment is used to execute the models and produce analysis results. To improve clarity, maintainability, and consistency with system development, the proposed safety model is organized according to a layered structure comprising an architectural view, a failure-propagation view, and a safety view. This modelling strategy supports traceability between requirements, assumptions, model artefacts, and analysis outcomes, thereby facilitating coherence across the safety process. The methodology is applied to a representative industrial case study concerning the Heading Control Function of a rotorcraft Flight Control System, instantiated on the Proteus RWUAS architecture. The thesis also discusses the comparison between MBSA and classical FTA with respect to representativeness, modelling effort, reusability, and update cost in early design iterations. The results indicate that, when supported by a structured workflow, a layered modelling pattern, and suitable post-processing activities, MBSA can provide not only a formal alternative to traditional assessment techniques, but also an effective engineering framework for organizing safety knowledge, generating quantitative evidence, and supporting early-phase safety assessment in a rigorous and reusable manner. The work therefore contributes to the advancement of executable safety models for complex airborne systems, while identifying future research directions in dynamic and timed analyses, richer modelling libraries, closer integration with Model-Based Systems Engineering, and increased automation of certification-oriented safety activities.
La crescente complessità dei sistemi embedded aeronautici ha reso la safety assessment un’attività sempre più impegnativa lungo l’intero processo di sviluppo e certificazione. Nella pratica industriale, tecniche tradizionali come la Fault Tree Analysis (FTA) restano ampiamente adottate, ma spesso risultano difficili da mantenere, riutilizzare e aggiornare al variare dell’architettura di sistema, soprattutto nelle prime fasi di progetto. In questo contesto, la Model-Based Safety Analysis (MBSA) si è affermata come un approccio promettente per supportare la safety engineering mediante modelli formali, eseguibili e riutilizzabili, ed è esplicitamente riconosciuta nella ARP4761A come metodo accettabile per l’analisi della propagazione dei guasti e per la valutazione probabilistica. Questa tesi indaga il ruolo della MBSA nello sviluppo preliminare di sistemi aeronautici complessi, con particolare riferimento alle applicazioni di controllo di volo. Il lavoro propone un workflow strutturato di MBSA finalizzato alla generazione di evidenze quantitative di safety e al supporto dei principali risultati richiesti dal processo di safety assessment, tra cui l’identificazione dei single point of failure, la giustificazione dell’allocazione del Design Assurance Level (DAL), il trattamento delle common-cause considerations e la derivazione dei requisiti di safety. A tale scopo, il linguaggio AltaRica è adottato per modellare il comportamento safety-relevant e la propagazione dei guasti, mentre l’ambiente Cecilia Workshop è utilizzato per l’esecuzione dei modelli e la produzione dei risultati di analisi. Per migliorare chiarezza, manutenibilità e coerenza con il processo di sviluppo del sistema, il modello di safety proposto è organizzato secondo una struttura a livelli comprendente una vista architetturale, una vista di failure propagation e una vista di safety. Tale strategia di modellazione supporta la tracciabilità tra requisiti, assunzioni, artefatti di modello e risultati di analisi, favorendo così la coerenza complessiva del processo di safety. La metodologia è applicata a un caso di studio industriale rappresentativo relativo alla Heading Control Function di un Flight Control System rotorcraft, istanziato sull’architettura Proteus RWUAS. La tesi discute inoltre il confronto tra MBSA e FTA classica in termini di rappresentatività, sforzo di modellazione, riusabilità e costo di aggiornamento nelle iterazioni progettuali iniziali. I risultati mostrano che, se supportata da un workflow strutturato, da un pattern di modellazione a livelli e da adeguate attività di post-processing, la MBSA può costituire non solo un’alternativa formale alle tecniche di assessment tradizionali, ma anche un efficace framework ingegneristico per organizzare la conoscenza di safety, generare evidenze quantitative e supportare la safety assessment nelle prime fasi di sviluppo in modo rigoroso e riutilizzabile. Il lavoro contribuisce pertanto all’avanzamento dell’uso di modelli di safety eseguibili per sistemi aeronautici complessi, individuando al contempo future direzioni di ricerca nelle analisi dinamiche e temporizzate, nell’ampliamento delle librerie di modellazione, nella più stretta integrazione con il Model-Based Systems Engineering e nella maggiore automazione delle attività di safety orientate alla certificazione
Model-based safety analysis and assessment for flight control system development
Lanzani, Isabella
2026
Abstract
The growing complexity of airborne embedded systems has made safety assessment an increasingly demanding activity throughout development and certification. In industrial practice, traditional techniques such as Fault Tree Analysis (FTA) remain widely adopted, but they often prove difficult to maintain, reuse, and update as system architectures evolve, particularly during the early design phases. In this context, Model-Based Safety Analysis (MBSA) has emerged as a promising approach for supporting safety engineering through formal, executable, and reusable models, and is explicitly recognized in ARP4761A as an acceptable method for failure-propagation analysis and probability evaluation. This thesis investigates the role of MBSA in the early development of complex airborne systems, with particular reference to flight control applications. The work proposes a structured MBSA workflow aimed at generating quantitative safety evidence while supporting major safety-assessment outcomes, including the identification of single points of failure, the rationale for Design Assurance Level (DAL) allocation, the treatment of common-cause considerations, and the derivation of safety requirements. To this end, the AltaRica language is adopted to model safety-relevant behaviour and failure propagation, while the Cecilia Workshop environment is used to execute the models and produce analysis results. To improve clarity, maintainability, and consistency with system development, the proposed safety model is organized according to a layered structure comprising an architectural view, a failure-propagation view, and a safety view. This modelling strategy supports traceability between requirements, assumptions, model artefacts, and analysis outcomes, thereby facilitating coherence across the safety process. The methodology is applied to a representative industrial case study concerning the Heading Control Function of a rotorcraft Flight Control System, instantiated on the Proteus RWUAS architecture. The thesis also discusses the comparison between MBSA and classical FTA with respect to representativeness, modelling effort, reusability, and update cost in early design iterations. The results indicate that, when supported by a structured workflow, a layered modelling pattern, and suitable post-processing activities, MBSA can provide not only a formal alternative to traditional assessment techniques, but also an effective engineering framework for organizing safety knowledge, generating quantitative evidence, and supporting early-phase safety assessment in a rigorous and reusable manner. The work therefore contributes to the advancement of executable safety models for complex airborne systems, while identifying future research directions in dynamic and timed analyses, richer modelling libraries, closer integration with Model-Based Systems Engineering, and increased automation of certification-oriented safety activities.| File | Dimensione | Formato | |
|---|---|---|---|
|
ModelBased_Thesis_Ufficiale.pdf
non disponibili
Licenza:
Tutti i diritti riservati
Dimensione
9.52 MB
Formato
Adobe PDF
|
9.52 MB | Adobe PDF |
I documenti in UNITESI sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.
https://hdl.handle.net/20.500.14242/376792
URN:NBN:IT:POLIMI-376792