Runtime Assurance of Aeronautical Products: Preliminary Recommendations

Introduction

Runtime assurance (RTA) affords an operational layer of protection against safety hazards to systems that may include less trusted or untrusted functions. To that end, the RTA scheme must itself be trusted before it can be deployed into use:

  1. It must fit the intended purpose.
  2. It must not itself introduce safety hazards.

Definitions

Overview

literature-review1.pngFigure: Architecture of RTA

RTA functions an be decomposed into the following implicitly runtime functions:

  1. Input assurance - Ensures that not only do monitoring and backup functions receive trusted inputs, but also that they receive the right inputs.
  2. Monitoring - Detects safety-related deviations/violations by observing an SUO
    • emergent interactions at system boundary,
    • violations or incorrect function inputs or assumptions of environmental conditions,
    • computational deviations from required internal states, state changes, and guards in state transitions, or undesired state transitions.
  3. Switching decision logic - Risk mitigation intervention triggered by monitor to disconnect complex function and engage the backup function. Can be a simple or more sophisticated protocol.
  4. Backup function - RTA includes one or more that serve to replace or failover from the primary complex function. Is generally a copy of primary with reduced service and capability but robust safety.

Design

Trusted RTA is:

  1. Simple
  2. Benign
  3. Realisable
  4. Verifiable
  5. Dependable