Published proof test coverage(PTC)estimates for emergency shutdown valves(ESDVs)show only moderate agreement and are predominantly opinion-based.A Failure Modes,Effects,and Diagnostics Analysis(FMEDA)was undertaken us...Published proof test coverage(PTC)estimates for emergency shutdown valves(ESDVs)show only moderate agreement and are predominantly opinion-based.A Failure Modes,Effects,and Diagnostics Analysis(FMEDA)was undertaken using component failure rate data to predict PTC for a full stroke test and a partial stroke test.Given the subjective and uncertain aspects of the FMEDA approach,specifically the selection of component failure rates and the determination of the probability of detecting failure modes,a Fuzzy Inference System(FIS)was proposed to manage the data,addressing the inherent uncertainties.Fuzzy inference systems have been used previously for various FMEA type assessments,but this is the first time an FIS has been employed for use with FMEDA.ESDV PTC values were generated from both the standard FMEDA and the fuzzy-FMEDA approaches using data provided by FMEDA experts.This work demonstrates that fuzzy inference systems can address the subjectivity inherent in FMEDA data,enabling reliable estimates of ESDV proof test coverage for both full and partial stroke tests.This facilitates optimized maintenance planning while ensuring safety is not compromised.展开更多
Quantitative safety assessment of safety systems plays an important role in decision making at all stages of system lifecycle, i.e., design, deployment and phase out. Most safety assessment methods consider only syste...Quantitative safety assessment of safety systems plays an important role in decision making at all stages of system lifecycle, i.e., design, deployment and phase out. Most safety assessment methods consider only system parameters, such as configuration, hazard rate, coverage, repair rate, etc. along with periodic proof-tests (or inspection). Not considering demand rate will give a pessimistic safety estimate for an application with low demand rate such as nuclear power plants, chemical plants, etc. In this paper, a basic model of IEC 61508 is used. The basic model is extended to incorporate process demand and behavior of electronic- and/or computer-based system following diagnosis or proof-test. A new safety index, probability of failure on actual demand (PFAD) based on extended model and demand rate is proposed. Periodic proof-test makes the model semi-Markovian, so a piece-wise continuous time Markov chain (CTMC) based method is used to derive mean state probabilities of elementary or aggregated state. Method to determine probability of failure on demand (PFD) (IEC 61508) and PFAD based on these state probabilities are described. In example, safety indices of PFD and PFAD are compared.展开更多
This paper introduces the Integrated Security Embedded Resilience Architecture (ISERA) as an advanced resilience mechanism for Industrial Control Systems (ICS) and Operational Technology (OT) environments. The ISERA f...This paper introduces the Integrated Security Embedded Resilience Architecture (ISERA) as an advanced resilience mechanism for Industrial Control Systems (ICS) and Operational Technology (OT) environments. The ISERA framework integrates security by design principles, micro-segmentation, and Island Mode Operation (IMO) to enhance cyber resilience and ensure continuous, secure operations. The methodology deploys a Forward-Thinking Architecture Strategy (FTAS) algorithm, which utilises an industrial Intrusion Detection System (IDS) implemented with Python’s Network Intrusion Detection System (NIDS) library. The FTAS algorithm successfully identified and responded to cyber-attacks, ensuring minimal system disruption. ISERA has been validated through comprehensive testing scenarios simulating Denial of Service (DoS) attacks and malware intrusions, at both the IT and OT layers where it successfully mitigates the impact of malicious activity. Results demonstrate ISERA’s efficacy in real-time threat detection, containment, and incident response, thus ensuring the integrity and reliability of critical infrastructure systems. ISERA’s decentralised approach contributes to global net zero goals by optimising resource use and minimising environmental impact. By adopting a decentralised control architecture and leveraging virtualisation, ISERA significantly enhances the cyber resilience and sustainability of critical infrastructure systems. This approach not only strengthens defences against evolving cyber threats but also optimises resource allocation, reducing the system’s carbon footprint. As a result, ISERA ensures the uninterrupted operation of essential services while contributing to broader net zero goals.展开更多
Strasbourg’s application of proportionality test has some unique features.Due to the Court inherent subsidiary role,it hardly transplants the formulas and criteria adopted by the German Constitutional Court or Court ...Strasbourg’s application of proportionality test has some unique features.Due to the Court inherent subsidiary role,it hardly transplants the formulas and criteria adopted by the German Constitutional Court or Court of Justice European Union(CJEU) in the complete sense.Consequently,the Strasbourg application of the proportionality has been depicted as a "mysterious house" for the reason that it lacks of certainty.Therefore,some scholars often worry the application of the proportionality test will threaten the predictability and the Strasbourg rule of law.Generally,the proportionality test has two internal functions for the Strasbourg judges:(1) strike fair balance between/among the competing interests;(2) testing on the reasonableness and appropriateness between the measures employed and aim pursued.In the first category,the primary task of the Court is to protect the scope of "essence" of the Convention rights from the interference of collective goods relying on the interest-based rights theory.Beyond this scope,the Court would have to balance the interests explicitly incorporated into the Convention rights as well as the external collective goods claimed by the state authorities.In some sensitive judgments,the Strasbourg Court tends to impose the onerous responsibility of "burden of proof" to the State authorities,or strategically defers to the domestic decisions unless they will be found "manifestly unreasonable".Secondly,the Court must take a scrutiny towards the appropriateness between the means employed and ends pursued,and then it has to decide whether a less intrusive alternative existed or will possibly be found or not.Sometimes,the Court might impose state authorities an obligation looking for a new alternation.However,due to subsidiarity characteristic of the Strasbourg Court,the task of the assessments sometimes is complicated and time-consuming,so the Court are not capable of evaluations in all occasions.Finally,the Court could strike down the "chilling consequence" caused by some few of the legitimate measures which may highly potentially threaten the individual rights in the National legal order.展开更多
国产信创升级改造,通常更多关注产品的性能,认为产品性能符合要求就能满足国产化的需求,而忽视了产品和业务的匹配,极易出现应用程序崩溃、语法错误等问题。为解决此问题,本文提出了一种基于POC(Proof of Concept)测试的信创改造升级方...国产信创升级改造,通常更多关注产品的性能,认为产品性能符合要求就能满足国产化的需求,而忽视了产品和业务的匹配,极易出现应用程序崩溃、语法错误等问题。为解决此问题,本文提出了一种基于POC(Proof of Concept)测试的信创改造升级方法。首先,通过对现有信息系统现状的分析,明确了系统改造升级的规模和复杂度。在此基础上设计了比核心业务更为复杂的应用,并基于此应用分别进行了单产品测试、联合产品测试,最终形成测试的数据和结果。通过对比分析结果来辅助企业进行信创产品升级策略的制定。此方法可以有效的解决国产化产品和业务不匹配的问题。展开更多
文摘Published proof test coverage(PTC)estimates for emergency shutdown valves(ESDVs)show only moderate agreement and are predominantly opinion-based.A Failure Modes,Effects,and Diagnostics Analysis(FMEDA)was undertaken using component failure rate data to predict PTC for a full stroke test and a partial stroke test.Given the subjective and uncertain aspects of the FMEDA approach,specifically the selection of component failure rates and the determination of the probability of detecting failure modes,a Fuzzy Inference System(FIS)was proposed to manage the data,addressing the inherent uncertainties.Fuzzy inference systems have been used previously for various FMEA type assessments,but this is the first time an FIS has been employed for use with FMEDA.ESDV PTC values were generated from both the standard FMEDA and the fuzzy-FMEDA approaches using data provided by FMEDA experts.This work demonstrates that fuzzy inference systems can address the subjectivity inherent in FMEDA data,enabling reliable estimates of ESDV proof test coverage for both full and partial stroke tests.This facilitates optimized maintenance planning while ensuring safety is not compromised.
文摘Quantitative safety assessment of safety systems plays an important role in decision making at all stages of system lifecycle, i.e., design, deployment and phase out. Most safety assessment methods consider only system parameters, such as configuration, hazard rate, coverage, repair rate, etc. along with periodic proof-tests (or inspection). Not considering demand rate will give a pessimistic safety estimate for an application with low demand rate such as nuclear power plants, chemical plants, etc. In this paper, a basic model of IEC 61508 is used. The basic model is extended to incorporate process demand and behavior of electronic- and/or computer-based system following diagnosis or proof-test. A new safety index, probability of failure on actual demand (PFAD) based on extended model and demand rate is proposed. Periodic proof-test makes the model semi-Markovian, so a piece-wise continuous time Markov chain (CTMC) based method is used to derive mean state probabilities of elementary or aggregated state. Method to determine probability of failure on demand (PFD) (IEC 61508) and PFAD based on these state probabilities are described. In example, safety indices of PFD and PFAD are compared.
基金funded by the Office of Gas and Electricity Markets(Ofgem)and supported by De Montfort University(DMU)and Nottingham Trent University(NTU),UK.
文摘This paper introduces the Integrated Security Embedded Resilience Architecture (ISERA) as an advanced resilience mechanism for Industrial Control Systems (ICS) and Operational Technology (OT) environments. The ISERA framework integrates security by design principles, micro-segmentation, and Island Mode Operation (IMO) to enhance cyber resilience and ensure continuous, secure operations. The methodology deploys a Forward-Thinking Architecture Strategy (FTAS) algorithm, which utilises an industrial Intrusion Detection System (IDS) implemented with Python’s Network Intrusion Detection System (NIDS) library. The FTAS algorithm successfully identified and responded to cyber-attacks, ensuring minimal system disruption. ISERA has been validated through comprehensive testing scenarios simulating Denial of Service (DoS) attacks and malware intrusions, at both the IT and OT layers where it successfully mitigates the impact of malicious activity. Results demonstrate ISERA’s efficacy in real-time threat detection, containment, and incident response, thus ensuring the integrity and reliability of critical infrastructure systems. ISERA’s decentralised approach contributes to global net zero goals by optimising resource use and minimising environmental impact. By adopting a decentralised control architecture and leveraging virtualisation, ISERA significantly enhances the cyber resilience and sustainability of critical infrastructure systems. This approach not only strengthens defences against evolving cyber threats but also optimises resource allocation, reducing the system’s carbon footprint. As a result, ISERA ensures the uninterrupted operation of essential services while contributing to broader net zero goals.
文摘Strasbourg’s application of proportionality test has some unique features.Due to the Court inherent subsidiary role,it hardly transplants the formulas and criteria adopted by the German Constitutional Court or Court of Justice European Union(CJEU) in the complete sense.Consequently,the Strasbourg application of the proportionality has been depicted as a "mysterious house" for the reason that it lacks of certainty.Therefore,some scholars often worry the application of the proportionality test will threaten the predictability and the Strasbourg rule of law.Generally,the proportionality test has two internal functions for the Strasbourg judges:(1) strike fair balance between/among the competing interests;(2) testing on the reasonableness and appropriateness between the measures employed and aim pursued.In the first category,the primary task of the Court is to protect the scope of "essence" of the Convention rights from the interference of collective goods relying on the interest-based rights theory.Beyond this scope,the Court would have to balance the interests explicitly incorporated into the Convention rights as well as the external collective goods claimed by the state authorities.In some sensitive judgments,the Strasbourg Court tends to impose the onerous responsibility of "burden of proof" to the State authorities,or strategically defers to the domestic decisions unless they will be found "manifestly unreasonable".Secondly,the Court must take a scrutiny towards the appropriateness between the means employed and ends pursued,and then it has to decide whether a less intrusive alternative existed or will possibly be found or not.Sometimes,the Court might impose state authorities an obligation looking for a new alternation.However,due to subsidiarity characteristic of the Strasbourg Court,the task of the assessments sometimes is complicated and time-consuming,so the Court are not capable of evaluations in all occasions.Finally,the Court could strike down the "chilling consequence" caused by some few of the legitimate measures which may highly potentially threaten the individual rights in the National legal order.
文摘国产信创升级改造,通常更多关注产品的性能,认为产品性能符合要求就能满足国产化的需求,而忽视了产品和业务的匹配,极易出现应用程序崩溃、语法错误等问题。为解决此问题,本文提出了一种基于POC(Proof of Concept)测试的信创改造升级方法。首先,通过对现有信息系统现状的分析,明确了系统改造升级的规模和复杂度。在此基础上设计了比核心业务更为复杂的应用,并基于此应用分别进行了单产品测试、联合产品测试,最终形成测试的数据和结果。通过对比分析结果来辅助企业进行信创产品升级策略的制定。此方法可以有效的解决国产化产品和业务不匹配的问题。