Safety Analysis of Hardware / Software Interactions in Complex Systems
John A. McDermid, David Pumfrey · 2002
This paper describes a new analysis technique developed specifically to study the safety implications of the relationship between software and the hardware on which it runs. The technique was developed in response to a request for assistance in completing the safety argument for a critical avionics application. Evidence was required that the segregation mechanism, used to partition functions of different integrity levels running on the same processor, would adequately protect critical program and data memory from corruption by the lower integrity software. The technique is based on an analysis of time and physical resources, using interpretations of a number of generic failure classes to prompt consideration of various hypothetical deviations from designed behaviour. We consider this research to be of particular significance, as the ability to provide such evidence is fundamental to the development of safety cases for future systems which will need to use a generic high integrity kernel to manage a number of processes with different integrity levels running on the same hardware. The paper describes the principles of the technique, and also presents our experience in applying it to the avionics system project which prompted its development.