<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Availability Model of Critical NPP I&amp;C Systems with K-phase Erlang Distribution of Software Update</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>BogdanVolochiy</string-name>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Vitaliy Yakovyna</string-name>
          <email>vitaliy.s.yakovyna@lpnu.ua</email>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Oleksandr Mulyak</string-name>
          <email>mulyak.oleksandr@gmail.com</email>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Vyacheslav Kharchenko</string-name>
          <email>v.kharchenko@csn.khai.edu</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="editor">
          <string-name>Key Terms. Mathematical Modeling, Method, Software Systems.</string-name>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>National Aerospace University “KhAI”</institution>
          ,
          <addr-line>Kharkiv</addr-line>
          ,
          <country country="UA">Ukraine</country>
        </aff>
        <aff id="aff1">
          <label>1</label>
          <institution>National University Lviv Polytechnic</institution>
          ,
          <addr-line>Lviv</addr-line>
          ,
          <country country="UA">Ukraine</country>
        </aff>
      </contrib-group>
      <abstract>
        <p>This paper is the continuation of the research devoted to enhancing the adequacy of reliability model of Nuclear Power Plant (NPP) Instrumentation and Control (I&amp;C) Systems considering software reliability. The reliability model of NPP I&amp;C systems is a basement from which the availability, safety, risk, and other important characteristics of the system could be assessed. The availability function of a critical NPP I&amp;C system depends on the hardware and software reliability and maintenance. The high availability value of the critical I&amp;C systems could be ensured by following: structural redundancy; maintenance of the system; using the N-version programming; software updates. Thus the NPP I&amp;C system reliability model to ensure its high level of adequacy and applicability has to take into account both software and hardware failures, as well as realistic distribution of software fault correction and K-phase Erlang Distribution of software updates are specified.</p>
      </abstract>
      <kwd-group>
        <kwd>Instrumentation and Control (I&amp;C) System</kwd>
        <kwd>Discrete-Continuous Stochastic System</kwd>
        <kwd>Reliability Behavior</kwd>
        <kwd>Structural-Automated Model</kwd>
        <kwd>Markovian Chains</kwd>
        <kwd>Software Reliability</kwd>
        <kwd>Erlang distribution</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>-</title>
      <p>1.1</p>
    </sec>
    <sec id="sec-2">
      <title>Introduction</title>
      <sec id="sec-2-1">
        <title>Motivation</title>
        <p>Nowadays the development of fault-tolerant computer-based systems (FTCSs) is a
part of weaponry components, space, aviation, energy and other critical systems. One
of the main tasks is to provide requirements of reliability, availability and functional
safety. Thus the two types of possible risks relate to the assessment of risk, and to
ensuring their safety and security.</p>
        <p>
          Reliability (dependability) related design (RRD) [
          <xref ref-type="bibr" rid="ref1 ref2 ref3 ref4 ref5 ref6">1-6</xref>
          ] is a main part of
development of complex fault-tolerant systems based on computers, software (SW) and
hardware (HW) components. The goal of RRD is to develop the structure of FTCS
tolerating HW physical failure and SW designs faults and assure required values of
reliability, availability and other dependability attributes. To ensure fault-tolerance
software, two or more versions of software (developed by different developers, using
other languages and technologies, etc) are used [
          <xref ref-type="bibr" rid="ref7">7</xref>
          ].Therefore use of structural
redundancy for FTCS with multiple versions of software is mandatory. When
commissioning software some bugs (design faults) remain in its code [
          <xref ref-type="bibr" rid="ref8">8</xref>
          ], this leads to the
shutdown of the FTCS. After detection the bugs, a software update is carried out. These
factors have influence on the availability of the FTCS and should be taken into
account in the availability indexes. The efficiency of fault-tolerant hardware of FTCS is
provided by maintenance and repair.
        </p>
        <p>Significant impact on the availability model of FTCS as discrete-continuous
stochastic Markov systems has a real distribution of software debugging time. For that
approach, there is an important problem of improving models by considering realistic
distribution of procedure durations and time intervals between events in the process.
Presented improvement allows to automate the usage of K-phase Erlang Distribution
for the Markovian chain development of the statistical representation of the process of
FTCS exploitation.</p>
        <p>Insufficient level of adequacy of the availability models of FTCS leads either to
additional costs (while underestimating of the measures), or to the risk of total failure
(when inflating their values), namely accidents, material damage and even loss of life.
Reliability and safety are assured by using (selection and development) fault-tolerant
structures at RRD of the FTCS, and identifying and implementing strategies for
maintenance. Adoption of wrong decisions at this stage leads to similar risks.
1.2</p>
      </sec>
      <sec id="sec-2-2">
        <title>Related Works Analysis</title>
        <p>
          Research papers, which focus on RRD, consider models of the FTCS [
          <xref ref-type="bibr" rid="ref10 ref11 ref12 ref13 ref8 ref9">8-13</xref>
          ]. Most
models are primarily developed to identify the impact of one the above-listed factors
on reliability indexes. The rest of the factors are overlooked. Papers [
          <xref ref-type="bibr" rid="ref4 ref5">4, 5</xref>
          ] describe the
reliability model of FTCS which illustrates separate HW and SW failures. Paper [
          <xref ref-type="bibr" rid="ref6">6</xref>
          ]
offer reliability model of a fault-tolerant system, in which HW and SW failures are
differentiated and after corrections in the program code the software failure rate is
accounted for. Paper [
          <xref ref-type="bibr" rid="ref8">8</xref>
          ] describes the reliability model of the FTCS, which accounts
for the software updates. In paper [
          <xref ref-type="bibr" rid="ref10">10</xref>
          ] the author outlines the relevance of the
estimation of the reliability indexes of FTCS considering the failure of SW and recommends
a method for their determination. Such reliability models of the FTCS produce
analysis of its conditions under the failure of SW. This research suggests that
MTTFsystem=MTTFsoftware. Thus, it is possible to conclude that the author considers the HW
of the FTCS as absolutely reliable. Such condition reduces the credibility of the result,
especially when the reliability of the HW is commensurable to the reliability of the
SW. Paper [
          <xref ref-type="bibr" rid="ref11">11</xref>
          ] presents the assessment of reliability parameters of FTCS through
modeling behavior using Markovian chains, which account for multiple software
updates. Nevertheless there was no evidence of the quantitative assessments of the
reliability measures of presented FTCS.
        </p>
        <p>
          In paper [
          <xref ref-type="bibr" rid="ref12">12</xref>
          ], the authors propose a model of FTCS using Macro-Markovian
chains, where the software failure rate, duration of software verification, failure rate
and repair rate of HW are accounted for. The presented method of Macro-Markovian
chains modeling [
          <xref ref-type="bibr" rid="ref12 ref13">12, 13</xref>
          ] is based on logical analysis and cannot be used for profound
configurations of FTCS due to their complexity and high probability of the
occurrence of mistakes. Also there is a discussion around the definition of requirements for
operational verification of software of the space system, together with the research
model of the object for availability evaluation and scenarios preference. It is noted
that over the last ten years out of 27% of space devices failures, which were fatal or
such that restricted their use, 6% were associated with HW failure and 21% with SW
failure.
        </p>
        <p>
          Software updates are necessary due to the fact that at the point of SW
commissioning they may contain a number of undetected faults, which can lead to critical failures
of the FTCS. Presence of HW faults relates to the complexity of the system, and
failure to conduct overall testing, as such testing is time consuming and needs substation
financial support. To predict the number of SW faults at the time of its commissioning
various models can be used, one for example is Jelinski-Moranda [
          <xref ref-type="bibr" rid="ref14">14</xref>
          ].
        </p>
        <p>
          The K-phase Erlang method is used for development the analytical stochastic
models of functional and reliability behaviors of technical system. Usage of this method
for reliability predictions of technical system is presented in paper [
          <xref ref-type="bibr" rid="ref14">14</xref>
          ].Usage of this
method for functional behavior for queuing system is presented in researches [15; 16,
pp. 137-144;14, pp. 136-143].
        </p>
        <p>In monographs [15, pp. 10-11, pp. 36-37; 17,pp. 196] states that any real
distributions of the random variable is possible to present by “mix” of Erlang distributions
pi(tv):</p>
        <p>k
p(tv )   qi pi (tv ) for
i1
tv  0 ,
where qi  weighting coefficients, defining the share each of the Erlang distribution
pi(tv) which was used for presenting the real distribution.</p>
        <p>A goal of the paper is to suggest structural-automated model to develop a
Markovian chain for critical NPP I&amp;C system with different redundancy types (first of all,
structure and version) and real distribution of software update time, using the
proposed formal procedure and tool. The main idea is to decrease risks of errors during
development of Markovian chain (MC) for systems with very large (tens and
hundreds) number of states. We propose a special notation which allows supporting
development chain step by step and designing final MC using software tools. The paper
is structured in the following way. The aim of this research is calculating the
availability function of critical NPP I&amp;C system with version-structural redundancy and
double software updates.</p>
        <p>To achieve this goal we propose a newly designed reliability model of critical NPP
I&amp;C system. As an example a special critical NPP I&amp;C system is researched (Fig.2).
The following factors are accounted for in this model: overall reserve of critical NPP
I&amp;C system and joint cold redundancy of modules of main and diverse systems of
critical NPP I&amp;C system; the existence of three software versions; SW double update;
physicals fault.</p>
        <p>Structure of the paper is the following. Researched critical NPP I&amp;C system is
described in the second section. An approach to developing mathematical model based
on Markovian chain and detailed procedure for the critical NPP I&amp;C system are
suggested in the third and fourth sections correspondingly. Simulation results for
researched Markov’s model are analyzed in the section 5. Last section concludes the
paper and presents some directions of future researches and developments.
2</p>
      </sec>
    </sec>
    <sec id="sec-3">
      <title>The Dependency of Software Failure Rates on the Frequence</title>
      <p>of Data Input Changing. the Randomness of Software</p>
    </sec>
    <sec id="sec-4">
      <title>Failures</title>
      <p>
        Hardware ageing occurs naturally over time therefore, time is a generally accepted
variable in functions for estimating hardware reliability. On the other hand, software
failure will never occur if the software is not run. Therefore, in the context of software
reliability, it is more practical to represent software run time as the number of
computational operations completed by the software. It is important that the test metrics and
ways of running the software take into account the following: that statistics of
software failures should be investigated when a number of tasks are performing with
different input data. Performing a task repeated times with the same input data will
not result in a software failure if the software did not failure the first time the task was
completed. Therefore, according to [
        <xref ref-type="bibr" rid="ref18">18</xref>
        ], the number and nature of software failures is
the result of internal defects and depends on the conditions in which the software is
used.
      </p>
      <p>
        In contrast to hardware failures which can occur at any time regardless of input
data, software failure depends on the frequency with which data are input. In practice,
software can be considered such as some function f, which converts entry space into
output space. The entry space is a set of all input conditions and the output space is
the set of all output conditions [
        <xref ref-type="bibr" rid="ref19">19</xref>
        ]. Respective states are determined by a set of
variables or typical software commands/transactions. According to standard IEC 60880,
the input space which includes the branch of software performance is called the signal
path [
        <xref ref-type="bibr" rid="ref20">20</xref>
        ]. In the period between two sets of incoming data being input, a software
failure cannot occur if the software preliminary entry is performed and the software is
in standby mode. Based on this, if the probability of software failure is calculated
as104per 10,000 software launches and the frequency of input data from sensors is
one second, the resulting software failure rate is calculated as 104 seconds-1 or 0.36
hours-1 (without taking into account the time required to create the output state), what
can be unacceptable according to system reliability requirements, part of which is
such software.
      </p>
      <p>
        Failure is a concept in reliability theory and can be defined as an event, after the
occurrence of which the characteristics of a technical object are outside of defined
bounds [
        <xref ref-type="bibr" rid="ref21">21</xref>
        ]. According to [
        <xref ref-type="bibr" rid="ref22">22</xref>
        ], software failures are an event during which a
software failure is detected. The signs of software disability are outlined in technical
documentation. The unrealistic results of software performance can be the result of
temporary hardware failures or software defects. Software defects are the elements or
parts of code, usage of which leads to unrealistic results [
        <xref ref-type="bibr" rid="ref22">22</xref>
        ]. In contrast to hardware
failures, software failures can be caused by:
 incorrect algorithms or the incorrect implementation of algorithms (“write
element of program”);
 incorrect software documentation, which will lead to incorrect user actions;
 the input data which are being processed by the software;
 temporary failures of hardware which occur under external factors (ionizing
radiation, temperatures, humidity or other factor), which can sometimes can be
eliminated by a software restart.
3
      </p>
    </sec>
    <sec id="sec-5">
      <title>The Use of Erlang Distributions for Software Updates in</title>
    </sec>
    <sec id="sec-6">
      <title>Availability Model of Fault-Tolerant Computer Based</title>
    </sec>
    <sec id="sec-7">
      <title>Systems with Version-Structural Redundancy</title>
      <p>
        The duration of software updates is a random value and it is possible to present it by
“mean time of new (next) software version development”. The robustness of this
measure should be founded in the resolution of decision reliability syntheses tasks of
fault-tolerant computer based system which are an integral part of high availability
critical infrastructure. The duration of new software version development depends on
many factors such as: available staff with appropriated technology knowledge;
qualification of developers; the complexity of the software and other factors. In previous
papers [
        <xref ref-type="bibr" rid="ref23 ref24">23, 24</xref>
        ], it was assumed that the duration of software updates are a random
variable with exponential distributions. However, it is more correct to consider
software updates as a random variable with a normal (or Gaussian) distribution. If an
availability model is developed in the discrete-continuous stochastic system form, the
duration of all procedures in the fault-tolerant computer based system (included
software updates) being analysed will be presented by exponential distributions. In this
regard, the frequency with which software update durations occur in the vicinity of
the mean is low compared to short software updates with a duration near zero. This
leads to a decreasing adequacy of the availability model the object being studied.
      </p>
      <p>This paper provides detailed suggestions for using Erlang distributions for the
duration of software updates that will increase the adequacy of models and provide more
realistic availability predictions. Figure 1 shows the probability density function for
an exponential distribution and the probability density function of Erlang distributions
with a shape parameter k=5. The probability of the occurrence of software update
durations near the mean value in availability model with Erlang distributions is higher
than when using exponential distributions for software updates. In a defined (given)
interval, the area under the probability density function of the Erlang distribution (S1)
is larger than are under the probability density function of the exponential distribution
(S2). Difference between the probabilities of occurrences of software update durations
would be increased by increasing the shape parameter k of the Erlang distributions.</p>
      <p>
        Based on this analysis, we conclude that Erlang distributions of software update
durations is appropriate to use for availability models of fault-tolerant computer based
systems in Markovian chain development. The main idea and instructions for
implementing Erlang distributions with an arbitrary shape parameter (for any distributions)
for the automated building of the Markovian chain was presented in paper [
        <xref ref-type="bibr" rid="ref25">25</xref>
        ].
4
      </p>
    </sec>
    <sec id="sec-8">
      <title>Industry Case: FPGA Platform Based Reactor Trip System of NPP</title>
      <p>
        Here we provide the structure (Fig.2) of researched safety critical NPP Instrumentation
and Control system (I&amp;C) based on the digital FPGA platform RadICS [
        <xref ref-type="bibr" rid="ref26">26</xref>
        ]. This is
reactor trip system consisting of main and diverse systems [
        <xref ref-type="bibr" rid="ref27">27</xref>
        ]. Main and diverse
systems have been developed using the FPGA safety controller (FSC) with three parallel
channels on voting logic “2-out-of-3”.
      </p>
      <p>Main system</p>
      <p>Vcold
(FPGA)</p>
      <p>Track 1</p>
      <p>Track 2</p>
      <p>Track 3</p>
      <p>2oo3</p>
      <p>V1
(FPGA1.1)</p>
      <p>V2
(FPGA2.1)</p>
      <p>V1
(FPGA1.2)</p>
      <p>V2
(FPGA2.2)</p>
      <p>V1
(FPGA1.3)</p>
      <p>V2
(FPGA2.3)</p>
      <p>OR</p>
      <p>Track 1'
Diverse system</p>
      <p>Track 2'</p>
      <p>Track 3'</p>
      <p>2oo3</p>
      <p>The output signals from main and diverse systems are binary (signals “switch-off” of
reactor) and are joined according with logic OR (1 out of 2).
5</p>
    </sec>
    <sec id="sec-9">
      <title>Markov’s Model for Critical NPP I&amp;C Systems with K-phase</title>
    </sec>
    <sec id="sec-10">
      <title>Erlang Distribution of Software Update</title>
      <p>
        The method of formal and tool-based automated developing the Markovian chains for
the researched critical NPP I&amp;C systems are described in [
        <xref ref-type="bibr" rid="ref24 ref9">9, 24</xref>
        ]. It involves a
formalized representation of the object of study as a “structural-automated model”. The
detailed availability model of critical NPP I&amp;C systems was presented in our previous
papers [
        <xref ref-type="bibr" rid="ref23 ref24">23, 24</xref>
        ]. In current paper we present modified structural-automated model
considering the Erlang distributions of the software updates durations.
      </p>
      <p>Structural-Automated Model of the critical NPP I&amp;C systems for automated
development of the Markovian chains are presented on the table 1. Improvements for
Structural-Automated Model of consideration the K-phase Erlang Distribution of
software debugging duration are presented below (all improvements are marked by
bold font).</p>
      <p>The parameters of the critical NPP I&amp;C systems Markov’s model: n – number of
modules that are the part of the MS; k – number of modules that are the part of the
DS; mc –number of the modules in the cold standby;hw– the failure rate that is in MS
or DS and in the hot standby; sw11, sw12 – the failure rate of first and second software
versions; Ke – number of Erlang Distribution phase; Tup1, Tup2 – mean time of the first
and second software updates; Tswitch – mean time of the module connections from
standby; Tnot – mean time of developers notifications after software failures;
Trep– mean time of hardware repair.</p>
      <p>Terms and conditions of event</p>
      <sec id="sec-10-1">
        <title>Event 1. Hardware failure of the MS module</title>
        <p>(V1&gt;=(n-1)) AND (V6=0) AND (V10=0) AND
(V11=0) AND (V12=0)
Event 2. Software failure of the MS module
(V1&gt;=(n-1)) AND (V4=0) AND (V6=0) AND (V10=0)
AND (V11=0) AND (V12=0)
(V1&gt;=(n-1)) AND (V4=1) AND (V6=0) AND (V10=0)
AND (V11=0) AND (V12=0)
Event 3. “Completing the developers notifications after
software failures in main system
(V1&lt;=n) AND (V4=0) AND (V6=1) AND (V9=0)
AND (V11=0) AND (V12=0)
(V1&lt;=n) AND (V4=1) AND (V6=1) AND (V9=0)
AND (V11=0) AND (V12=0)
Event 4. Hardware failure of diverse system module
(V2&gt;=(k-1)) AND (V7=0) AND (V9=0) AND (V11=0)
AND (V12=0)
Event 5. Software failure of the diverse system module
(V2&gt;=(k-1)) AND (V5=0) AND (V7=0) AND (V9=0)
AND (V11=0) AND (V12=0)
(V2&gt;=(k-1)) AND (V5=1) AND (V7=0) AND (V9=0)
AND (V11=0) AND (V12=0)
Event 6. Completing the developers notifications after
software failures in diverse system
(V2&lt;=k) AND (V5=0) AND (V7=1) AND (V10=0)
AND (V11=0) AND (V12=0)
(V2&lt;=k) AND (V5=1) AND (V7=1) AND (V10=0)
AND (V11=0) AND (V12=0)
Event 7. Completing the procedure of software version
updates in main system
(V4=0) AND (V6=1) AND (V9=1) AND (V11&gt;0)
AND (V11&lt;Ke)
V1·λhw
λsw11
λsw12
1/Tnot
1/Tnot
λsw11
λsw12
1/Tnot
1/Tnot</p>
      </sec>
      <sec id="sec-10-2">
        <title>Event 8. Completing the procedure of software version updates in diverse system</title>
        <p>(V5=0) AND (V7=1) AND (V10=1) AND (V12&gt;0)
AND (V11&lt;Ke)
Ke(1/Tup1)</p>
        <p>V12:=V12+1
(V5=0) AND (V7=1) AND (V10=1) AND (V12=Ke)
Ke (1/Tup1)
(V5=1) AND (V7=1) AND (V10=1) AND (V12&gt;0)
AND (V11&lt;Ke)
Ke(1/Tup2)</p>
        <p>V12:=V12+1
(V5=1) AND (V7=1) AND (V10=1) AND (V12=Ke)
Ke(1/Tup2)</p>
        <p>V5:=1; V6:=0; V10:=0;
V12:=0
V5:=2; V6:=0; V10:=0;
V12:=0
Event 9. Completing the maintenances procedure of the
system
((V1&lt;=n) OR (V2&lt;=k)) AND (V8=4) AND (V11=0)
AND (V12=0)
1/Trep</p>
        <p>V2:=k; V1:=n; V8:=0</p>
        <p>The number of software updates can be also changed. It is necessary to change
vectors V4 and V5 the event 7, that are responsible for the number of updates. For
example, if there are three software updates for diverse system, the entry component of the
event will be as follows:
(V5=2) AND (V7=1) AND (V10=1) AND (V12&gt;0)
AND (V11&lt;Ke)
(V5=2) AND (V7=1) AND (V10=1) AND (V12=Ke)
Ke(1/Tup3)
Ke(1/Tup3)</p>
        <p>V12:=V12+1
V5:=3; V6:=0;
V10:=0; V12:=0</p>
        <p>
          The developed availability model of the critical NPP I&amp;C system gives the
possibilities according to technology [
          <xref ref-type="bibr" rid="ref9">9</xref>
          ] for automated construct of the Markovian chains.
This construction provides a software module ASNA [
          <xref ref-type="bibr" rid="ref28">28</xref>
          ]. The Markovian chains
which take into account the following settings critical NPP I&amp;C system: n=3; k=3;
mc=0; hw; sw11, sw12; Tup1, Tup2; Tswitch; Trep; Ke=0 are consists of 273 state and
893transitions. Information is available on the status of each software module ASNA
we have on file "vector.vs", which is written in the form:
        </p>
        <p>State 1: V1=3; V2=3; V3=0; V4=0; V5=0; V6=0; V7=0; V8=0; V9=0; V10=0; V11=0; V12=0
State 2: V1=2; V2=3; V3=0; V4=0; V5=0; V6=0; V7=0; V8=1; V9=0; V10=0; V11=0; V12=0
……….</p>
        <p>State 481: V1=2; V2=1; V3=0; V4=1; V5=2; V6=1; V7=0; V8=3; V9=1; V10=0; V11=3; V12=0
For three phase parameters (Ke) of Erlang distribution for software updates
durations were conducted tree Markovian chains with different dimension. The parameters
of this Markovian chain in table 2 are shown.
n</p>
        <p>The proposed structural-automated model of critical NPP I&amp;C system for
availability assessment can be easily transformed for other features of the object of study. It is
enough to: add / remove basic event; attach / remove components of the state vector;
and include / exclude parameters that describe the studied system. Based on
information about the work of critical NPP I&amp;C system an appropriate change in the
model could be made (Fig. 2).</p>
        <p>Based on the Markovian chains without Erlang distributions Ke=0 for critical NPP
I&amp;C system ("vector.vs") a system of differential equations was formed. Its solution
allows us to estimate the function availability value of researched critical NPP I&amp;C
system. In the same manner the systems of differential equation for Markovian chain
with Erlang distribution (Ke=3, Ke=5) of software updates was formed.
dP1 t </p>
        <p>dt
dP2 t </p>
        <p>dt
dP3 t 
dt
 6  hw  sw11   Р2 t  
1   Р2 t   Р3 t   Р6 t   Р7 t  </p>
        <p>Trepl
 Р8 t   Р9 t   Р11 t   Р16 t 
  1  Р2 t   2 sw11Р2 t   2 hw  Р2 t   3hw  Р2 t  </p>
        <p>Trepl
 2 hwР1 t 
  1  Р3 t   3 hw  sw11   Р3 t   2 hwР2 t </p>
        <p>Trepl
dP273 t 
dt
  1  Р273 t   2 hwР156 t   2 sw12 Р272 t </p>
        <p>Trepl
Initial conditions for the system (2) is Р1 t   1; Р2 t ...Р273 t   0.</p>
        <p>Based on the developed Markovian chains with different number of phase in Erlang
distributions formulas for availability of critical NPP I&amp;C system calculations could
be assembled. Availability functions of critical NPP I&amp;C system is calculated as the
sum of the probability functions staying in operable states of chains. Based on
Markovian chain of critical NPP I&amp;C system availability function with different shape
parameters are determined by following formulas:</p>
        <sec id="sec-10-2-1">
          <title>Research the Influence of K-phase Erlang Distribution of the Software</title>
        </sec>
        <sec id="sec-10-2-2">
          <title>Update Durations on Availability the Critical NPP I&amp;C System</title>
          <p>With the assistance of the proposed model, the following questions can be answered:
What are the duration values of the first and the second software update (ensuring the
values of the availability function of critical NPP I&amp;C system of the initial phase of
its operation do not reach below the specified level)? What are the allowed duration
values of the first and the second SW updates? How the correlation between the first
and the second SW does updates influence on the availability function? What is an
influence on the availability function of duration of SW updates by Erlang
distribution?</p>
          <p>The experiment is conducted for the condition where the duration of the first
software update is significantly shorter than the duration of the second update and the
distribution of software update duration presented by Erlang distribution with
different shape parameters Ke=0, Ke=3, Ke=5. The experiment is conducted with the
following parameters critical NPP I&amp;C system: hw=1·10-5 hour-1; sw11=2·10-4hour-1,
sw12=1·10-4hour-1; Trep=200 hour; Tup1=10 hour;Tup2=200 hours.
The following results have been obtained by the proposed experiments:
1) Minimal levels of the availability functions for Markovian chains without
Erlang distribution (Ke=0) for duration of software updates and Markovian chains with
Erlang distributions (Ke=3, Ke=5) are changed. Analyzing the dependents of
availability functions on the Fig. 3 could be concluded that real distribution of processes in
system have significant effect of reliability indexes of critical NPP I&amp;C system.</p>
          <p>2) With the assistance of the proposed model it is possible to choose the duration
of software updates that helps to ensure a minimum allowed level of the decrease of
the availability function of the critical NPP I&amp;C system.</p>
          <p>3) In this research we confirmed that the exponential distribution in
discretecontinuous stochastic models usage provides the limiting value of efficiency
indicators. This occurrence was described by J. Martin in his monograph [pp.58-59, 29].
However, based on proposed model we confirmed that exponential distributions
provide the most optimistic availability measures. The Erlang distribution for software
updates usage provides a more realistic availability measure that is important during
the operation of critical system and correction of software defects.</p>
        </sec>
      </sec>
    </sec>
    <sec id="sec-11">
      <title>Conclusion</title>
      <p>This research presents a model of critical NPP I&amp;C system with double software
updates and real distribution of software updates duration (by Erlang distributions
presented) to illustrate automated development of Markovian chains using a special
technology and tool ASNA.</p>
      <p>The presented model can be easily adapted to different configurations of critical
NPP I&amp;C system, which envisages the use different majority voting, standby of the
hardware part and as a consequence in the majority of software versions from
different developers. In fact, this model can be adopted for an arbitrary number of software
updates.</p>
      <p>Future research has the potential to supplement this model with further factors:
Erlang distribution for durations of hardware repair; unsuccessful restarting; unreliable
commutation of elements and so on.</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          1.
          <string-name>
            <surname>Mudry</surname>
            ,
            <given-names>P.A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Vannel</surname>
            ,
            <given-names>F.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Tempesti</surname>
            ,
            <given-names>G.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Mange</surname>
            ,
            <given-names>D.</given-names>
          </string-name>
          <article-title>A reconfigurable hardware platform for prototyping cellular architectures</article-title>
          .
          <source>In: International Parallel and Distributed Processing Symposium</source>
          . IEEE International, pp.
          <fpage>96</fpage>
          --
          <lpage>103</lpage>
          (
          <year>2007</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          2.
          <string-name>
            <surname>Viktorov</surname>
            ,
            <given-names>O.</given-names>
          </string-name>
          <article-title>Reconfigurable Multiprocessor System Reliability Estimation</article-title>
          .
          <source>Asian Jounal of Information Technology</source>
          <volume>6</volume>
          (
          <issue>9</issue>
          ), pp.
          <fpage>958</fpage>
          --
          <lpage>960</lpage>
          (
          <year>2007</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          3.
          <string-name>
            <surname>Rajesh</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Vinoth</surname>
            <given-names>Kumar C.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Srivatsan</surname>
            ,
            <given-names>R.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Harini</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Shanthi</surname>
            ,
            <given-names>A. Fault</given-names>
          </string-name>
          <article-title>Tolerance in Multicore Processors With Reconfigurable Hardware Unit</article-title>
          .
          <source>In: 15thInternational conference on high performance computing. Bangalore</source>
          , INDIA, pp.
          <fpage>166</fpage>
          --
          <lpage>171</lpage>
          (
          <year>2008</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          4.
          <string-name>
            <surname>Amerijckx</surname>
            ,
            <given-names>C.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Legat</surname>
          </string-name>
          , J.
          <string-name>
            <surname>-D. A Low-Power Multiprocessor ArchitectureFor Embedded Reconfigurable</surname>
          </string-name>
          <article-title>Systems</article-title>
          . In: Power and
          <string-name>
            <given-names>Timing</given-names>
            <surname>Modeling</surname>
          </string-name>
          , Optimization and Simulation, International Workshop, pp.
          <fpage>83</fpage>
          --
          <lpage>93</lpage>
          (
          <year>2008</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          5.
          <string-name>
            <given-names>Changyun</given-names>
            <surname>Zhu</surname>
          </string-name>
          ,
          <string-name>
            <surname>Gu</surname>
            ,
            <given-names>Z.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Dick</surname>
            ,
            <given-names>R.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Shang</surname>
            ,
            <given-names>L.</given-names>
          </string-name>
          <article-title>Reliable multiprocessor system-on-chip synthesis</article-title>
          .
          <source>In: International Conference Hardware/Software Co-design and System Synthesis</source>
          , pp.
          <fpage>239</fpage>
          --
          <lpage>244</lpage>
          (
          <year>2007</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          6.
          <string-name>
            <surname>Kim</surname>
            <given-names>P.</given-names>
          </string-name>
          <string-name>
            <surname>Gostelow</surname>
          </string-name>
          .
          <article-title>The design of a fault-tolerant, realtime, multi-core computer system</article-title>
          . In: In Aerospace Conference, IEEE, pp.
          <fpage>1</fpage>
          --
          <lpage>8</lpage>
          (
          <year>2011</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          7.
          <string-name>
            <surname>Lyu</surname>
            <given-names>M.R</given-names>
          </string-name>
          . (ed.),
          <source>Software Fault Tolerance</source>
          , New York: John Wiley &amp; Sons (
          <year>1995</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          8.
          <string-name>
            <surname>Korotun</surname>
          </string-name>
          , Т.М.
          <article-title>Models and methods for testing software systems</article-title>
          .
          <source>Programming problems</source>
          , vol.
          <volume>2</volume>
          , pp.
          <fpage>76</fpage>
          --
          <lpage>84</lpage>
          (
          <year>2007</year>
          )
          <article-title>(In Russian)</article-title>
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          9.
          <string-name>
            <surname>Volochii</surname>
            ,
            <given-names>B.</given-names>
          </string-name>
          :
          <article-title>Technology of modeling the information systems</article-title>
          .
          <source>Publishing NU "Lviv Polytechnic"</source>
          (
          <year>2004</year>
          )
          <article-title>(In Ukrainian)</article-title>
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          10.
          <string-name>
            <surname>Lei</surname>
            <given-names>Xiong</given-names>
          </string-name>
          , Qingping Tan,
          <string-name>
            <given-names>Jianjun</given-names>
            <surname>Xu</surname>
          </string-name>
          .
          <article-title>Effects of Soft Error to System Reliability</article-title>
          .
          <source>In: Workshops of International Conference on Advanced Information Networking and Applications</source>
          . pp.
          <fpage>204</fpage>
          --
          <lpage>209</lpage>
          (
          <year>2011</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          11.
          <string-name>
            <surname>Ponochonvyi</surname>
            ,
            <given-names>J.L.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Odarushchenko</surname>
            ,
            <given-names>E.B.</given-names>
          </string-name>
          <article-title>The reliability modeling non-redundant information and control systems with software updated</article-title>
          .
          <source>In: Radioelectronic and Computer Systems</source>
          , vol.
          <volume>4</volume>
          (
          <issue>8</issue>
          ), pp.
          <fpage>93</fpage>
          --
          <lpage>97</lpage>
          (
          <year>2004</year>
          )
          <article-title>(In Russian)</article-title>
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          12.
          <string-name>
            <surname>Kharchenko</surname>
            ,
            <given-names>V.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Odarushchenko</surname>
            ,
            <given-names>O.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Odarushchenko</surname>
            ,
            <given-names>V.</given-names>
          </string-name>
          <string-name>
            <surname>Popov</surname>
            ,
            <given-names>P.</given-names>
          </string-name>
          <string-name>
            <surname>Selecting</surname>
          </string-name>
          <article-title>Mathematical Software for Dependability Assessment of Computer Systems Described by Stiff Markov Chains</article-title>
          .
          <source>Proc. Int. Conf. ICTERI</source>
          , pp.
          <fpage>146</fpage>
          --
          <lpage>162</lpage>
          (
          <year>2013</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          13.
          <string-name>
            <surname>Kharchenko</surname>
            ,
            <given-names>V.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Ponochovny</surname>
            ,
            <given-names>Y.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Boyarchuk</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          <article-title>Availability Assessment of Information and Control Systems with Online Software Update and Verification</article-title>
          .
          <source>In: Information and Communication Technologies in Education, Research, and Industrial Applications Communications in Computer and Information Science</source>
          , Vol.
          <volume>469</volume>
          ,Springer International Publishing Switzerland, pp.
          <fpage>300</fpage>
          --
          <lpage>324</lpage>
          (
          <year>2014</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          14.
          <string-name>
            <surname>David</surname>
            <given-names>R.</given-names>
          </string-name>
          <string-name>
            <surname>Cox</surname>
          </string-name>
          :
          <article-title>Renewal theory</article-title>
          .
          <source>Methuen</source>
          ,
          <volume>142</volume>
          p. (
          <year>1962</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref15">
        <mixed-citation>
          15.
          <string-name>
            <surname>Konig</surname>
            ,
            <given-names>D.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Shtojan</surname>
            ,
            <given-names>D.</given-names>
          </string-name>
          :
          <article-title>Methoden der Bedienungstheoric [Methods of Queueing Theory]</article-title>
          . Vieweg, Braunschweig,
          <volume>128</volume>
          p. (
          <year>1976</year>
          )
          <article-title>(In German)</article-title>
        </mixed-citation>
      </ref>
      <ref id="ref16">
        <mixed-citation>
          16.
          <string-name>
            <surname>Klejnrok</surname>
            ,
            <given-names>L</given-names>
          </string-name>
          :.
          <article-title>Queueing systems</article-title>
          . Volume I:
          <article-title>Theory</article-title>
          . John Wiley, New York, 432 p. (
          <year>1976</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref17">
        <mixed-citation>
          17.
          <string-name>
            <surname>Rajnshke</surname>
            ,
            <given-names>K.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Ushakov</surname>
            ,
            <given-names>I.A.</given-names>
          </string-name>
          :
          <article-title>Assessment of The Reliability of The Systems Via Graphs</article-title>
          . Moskva, Radio i svjaz' Publ.,
          <volume>208</volume>
          p. (
          <year>1988</year>
          )
          <article-title>(In Russian)</article-title>
        </mixed-citation>
      </ref>
      <ref id="ref18">
        <mixed-citation>
          18.
          <string-name>
            <surname>Lipaev</surname>
            <given-names>V.</given-names>
          </string-name>
          :
          <article-title>Software reliability</article-title>
          . Moskov, Synteg,
          <volume>232</volume>
          p. (
          <year>1998</year>
          )
          <article-title>(In Russian)</article-title>
        </mixed-citation>
      </ref>
      <ref id="ref19">
        <mixed-citation>
          19.
          <string-name>
            <surname>Hoang</surname>
          </string-name>
          <article-title>Pham: System Software Reliability</article-title>
          . Springer Series in Reliability Engineering,
          <volume>387</volume>
          p. (
          <year>2006</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref20">
        <mixed-citation>
          20. IEC 60880.
          <article-title>Nuclear power plants - Instrumentation and control systems important to safety - Software aspects for computer-based systems performing category A functions</article-title>
          ,
          <volume>217</volume>
          p., (
          <year>2006</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref21">
        <mixed-citation>
          21.
          <string-name>
            <surname>Polovko</surname>
            <given-names>A.</given-names>
          </string-name>
          :
          <source>Fundamentals of reliability theory of Saint Petersburg</source>
          ,
          <volume>704</volume>
          p. (
          <year>2006</year>
          )
          <article-title>(In Russian)</article-title>
        </mixed-citation>
      </ref>
      <ref id="ref22">
        <mixed-citation>
          22.
          <string-name>
            <surname>DSTU</surname>
          </string-name>
          2844-
          <fpage>94</fpage>
          . Computer Software.
          <article-title>Quality ensuring. Terms and definitions</article-title>
          .
          <source>Federal standart</source>
          ,
          <volume>19</volume>
          p. (
          <year>1996</year>
          )
          <article-title>(In Ukrainian)</article-title>
        </mixed-citation>
      </ref>
      <ref id="ref23">
        <mixed-citation>
          23.
          <string-name>
            <surname>Volochiy</surname>
            ,
            <given-names>B.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Mulyak</surname>
            ,
            <given-names>O.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Kharchenko</surname>
          </string-name>
          , V.:
          <article-title>Automated Development of Markovian Chains for Fault Tolerant Computer-Based Systems with Version Structure Redundancy</article-title>
          .
          <source>Proceedings of the 11th International Conference on ICT in Education, Research and Industrial Applications: Integration, Harmonization and Knowledge Transfer</source>
          , Vol.
          <volume>1356</volume>
          . pp.
          <fpage>462</fpage>
          --
          <lpage>475</lpage>
          (
          <year>2015</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref24">
        <mixed-citation>
          24.
          <string-name>
            <surname>Bogdan</surname>
            <given-names>Volochiy</given-names>
          </string-name>
          , Oleksandr Mulyak, Leonid Ozirkovskyi, Vyacheslav Kharchenko:
          <article-title>Automation of Quantitative Requirements Determination to Software Reliability of Safety Critical NPP I&amp;C systems”</article-title>
          .
          <source>In Proceedings of the Second International Symposium on Stochastic Models in Reliability Engineering, Life Science and Operations Management (SMRLO'16)</source>
          , pp.
          <fpage>337</fpage>
          --
          <lpage>346</lpage>
          (
          <year>2016</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref25">
        <mixed-citation>
          25.
          <string-name>
            <surname>Fedasyuk</surname>
            ,
            <given-names>D.V.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Volochiy</surname>
            ,
            <given-names>S.B.</given-names>
          </string-name>
          :
          <article-title>Structural-automaton model of fault-tolerant systems for automated usage of erlang distribution Radioelektronic and Computer system</article-title>
          , Vol.
          <volume>3</volume>
          (
          <issue>77</issue>
          ), Kharkiv, pp.
          <fpage>78</fpage>
          -
          <lpage>92</lpage>
          , (
          <year>2016</year>
          )
          <article-title>(In Ukrainian)</article-title>
        </mixed-citation>
      </ref>
      <ref id="ref26">
        <mixed-citation>
          26.
          <string-name>
            <surname>Kharchenko</surname>
            ,
            <given-names>V.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Sklyar</surname>
            ,
            <given-names>V.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Volkoviy</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          :
          <article-title>Development and Verification of Dependable Multi-Version Systems on the Basic of IP-Cores</article-title>
          .
          <source>Proc. Int. Conf. Dependability of Computer Systems</source>
          (
          <year>2008</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref27">
        <mixed-citation>
          27.
          <article-title>Review Guidelines for Field-Programmable Gate Arrays in Nuclear Power Plant Safety Systems</article-title>
          . NUREG/CR-7006, U.S. Nuclear Regulatory Commission, Washington,
          <string-name>
            <given-names>D.C.</given-names>
            ,
            <surname>USA</surname>
          </string-name>
          (
          <year>2010</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref28">
        <mixed-citation>
          28.
          <string-name>
            <surname>Bobalo</surname>
            ,
            <given-names>J.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Volochiy</surname>
          </string-name>
          . B.,
          <string-name>
            <surname>Lozynskyi</surname>
            ,
            <given-names>O.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Mandzii</surname>
            ,
            <given-names>B.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Ozirkovskyi</surname>
            ,
            <given-names>L.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Fedasuk</surname>
            ,
            <given-names>D.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Shcherbovskyh</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Jakovyna</surname>
            ,
            <given-names>V.</given-names>
          </string-name>
          :
          <article-title>Mathematical models and methods for reliability analysis of electronic, electrical and software systems</article-title>
          , Lviv Polytechnic Press,
          <year>425p</year>
          , (
          <year>2013</year>
          )
          <article-title>(In Ukrainian)</article-title>
        </mixed-citation>
      </ref>
      <ref id="ref29">
        <mixed-citation>
          29.
          <string-name>
            <surname>Martin</surname>
            <given-names>J.:</given-names>
          </string-name>
          <article-title>System Analysis for Data Transmission</article-title>
          . IBM System Research Institute, Prentice Hall, Inc.,
          <string-name>
            <surname>Englewood</surname>
            <given-names>Cliffs</given-names>
          </string-name>
          ,
          <year>823p</year>
          (
          <year>1972</year>
          )
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>