<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Multi-Fragmental Markov Models of Information and Control Systems Safety Considering Elimination of Hardware-Software Faults</article-title>
      </title-group>
      <contrib-group>
        <aff id="aff0">
          <label>0</label>
          <institution>National Aerospace University KhAI</institution>
          ,
          <addr-line>Kharkiv</addr-line>
          ,
          <country country="UA">Ukraine</country>
        </aff>
        <aff id="aff1">
          <label>1</label>
          <institution>Poltava State Agrarian Academy PSAA</institution>
          ,
          <addr-line>Poltava</addr-line>
          ,
          <country country="UA">Ukraine</country>
        </aff>
        <aff id="aff2">
          <label>2</label>
          <institution>Research and Production Company Radiy</institution>
          ,
          <addr-line>Kirovograd</addr-line>
          ,
          <country country="UA">Ukraine</country>
        </aff>
      </contrib-group>
      <pub-date>
        <year>2013</year>
      </pub-date>
      <fpage>0000</fpage>
      <lpage>0001</lpage>
      <abstract>
        <p>The information and control systems of Nuclear Power Plant and other safety critical systems are considered as a set of three independent hardware channels including online testing system. Nuclear Power Plant information and control systems design on programmable platforms is rigidly tied to the V-model of the life cycle. Functional safety and availability during its life cycle are assessed using Markov and multi-fragmental models. Multifragmental models are used to assess the availability function and proof test period. The multi-fragmental model MICS31 contains an absorbing state in case of hidden faults and allows evaluating risks of “hidden” unavailability. The MICS41 model simulates the “migration” of states with undetected failures into states with detected faults. Results of multi-fragmental modeling (models MICS31 and MICS42) are compared to evaluate proof test period taking into account requirements for SIL3 level and limiting values of hidden fault probabilities.</p>
      </abstract>
      <kwd-group>
        <kwd>Multi-Fragmental Models</kwd>
        <kwd>Functional Safety Modeling</kwd>
        <kwd>Information and Control System</kwd>
        <kwd>Undetected Software Failure</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>-</title>
      <p>1 Introduction
For different classes of critical systems (medical equipment, banking systems, road,
air, railway transport and nuclear power plants) very strict requirements have been
developed. These requirements determine both the system characteristics from the
group of non-functional requirements (availability, reliability, safety, etc.) and the
content of the life cycle phases. During the development cycle, it is possible to change
the architecture of the information and control system (ICS) of the Nuclear Power
Plant (NPP) project and correct the parameters of its elements. Such actions require
justification, which uses special mathematical models to confirm the fulfillment of
design requirements.</p>
      <p>
        This paper discusses the class of the information and control systems on
programmable platforms, which are used in the reactor protection system of NPP in
normal operation. This class of information and control system is based on the 2oo3
architecture without versioning with the control system and is described in detail in
[
        <xref ref-type="bibr" rid="ref1 ref2">1,2</xref>
        ]. Expansion of the previously reviewed model consists of detailing the diagnostic
procedures. This paper discusses the separate diagnosis of hardware and software
with DCHW and DCSW parameters (DC is diagnostic coverage). As a separate process,
regular proof tests are highlighted, during which latent hardware (HW) and software
(SW) faults, that are not detected by the integrated control system, are detected.
      </p>
      <p>
        Studies carried out in [
        <xref ref-type="bibr" rid="ref3">3</xref>
        ] have shown that achievement of the requirements of
industrial systems on proof test TAreq ≥ 3 years’ period can be by influencing
parameters of the functional safety of SW (reducing an intensity of dangerous SW
λD S failure or increasing the completeness of control of dangerous SW DCS failure).
For information and control systems on programmable platforms, SW faults
(architectural project faults) are entered into the system of bug tracking after their
detection and eliminated within a certain time interval. The elimination of the
software fault (assuming no new faults are introduced) causes a decrease in SW
failure rate, as shown in [
        <xref ref-type="bibr" rid="ref4 ref5">4,5</xref>
        ]. To adequately display the elimination of SW faults and
reduce the failure rate in studies [
        <xref ref-type="bibr" rid="ref6">6</xref>
        ], it was suggested to use the mathematical
apparatus of multi-fragmental modeling.
      </p>
      <p>At first glance, the elimination of software faults may cause a desire to use the
information and control system project with the initial high intensity of dangerous SW
failures, because faults will be identified and eliminated over the time. But this
decision should be justified by the results of the study of the corresponding models of
the information and control system with the elimination of faults causing dangerous
SW failures.</p>
      <p>In this paper, multi-fragmental models of functioning of the information and
control system under the conditions of manifestation of dangerous HW and SW
failures and elimination of identified SW faults are studied. For each model,
graduated and oriented graphs are constructed; using the Matlab functions, systems of
Kolmogorov-Chapman differential equations are constructed and solved. As a result,
the values of the proof test TAreq period for the SIL3 level and input parameters are
obtained, at which the condition TAreq ≥ 3 years for industrial systems is satisfied.</p>
    </sec>
    <sec id="sec-2">
      <title>2 Approach and Modeling Technique</title>
      <p>
        2.1. Model Specification
In this paper we develop six models using Markov process theory as shown in
Table 1. Models MICS01 and MICS02 were studied at the papers [
        <xref ref-type="bibr" rid="ref1">1</xref>
        ] with the
assumption of manifestation of only dangerous HW failures and only DCH parameter.
We discuss in this work the separate diagnosis of hardware and software with DCHW
and DCSW parameters.
- several fragments, in each fragment there are
three groups of states
- there is the absorbing state in each fragment
(output only after the proof test)
- several fragments, in each fragment there are
three groups of states
- there are no absorbing states (after the
manifestation of the undetected failure, its
“migration” is possible before the proof test)
- several fragments, in the first fragments there are
three groups of states
- in the last fragment, there are two groups of
states, since all SW faults are eliminated
- there is the absorbing state in each fragment
(output only after the proof test)
- several fragments, in the first fragments there are
three groups of states
- in the last fragment, there are two groups of
states, since all SW faults are eliminated
- there are no absorbing states (after the
manifestation of the undetected failure, its
“migration” is possible before the proof test)
The assumptions during models building are as follows:
- the events of failures and restoration of hardware channels and software (until the
fault is eliminated) constitute of the simplest flows (stationary, ordinary and without
aftereffect), with the corresponding constant λHW, λSW (failure rate) and μHW, μSW
(recovery intensity) parameters;
- the system uses identical hardware channels with the same failure rates;
- the failure rate of the majority body and the control system is negligibly small and
these systems are assumed to be absolutely reliable in the considered model;
- the model considers only dangerous failures of hardware channels of the
information and control system and SW information and control system, the intensity of
the dangerous failures is estimated according to the method [
        <xref ref-type="bibr" rid="ref2">2</xref>
        ] and data obtained for
similar systems [
        <xref ref-type="bibr" rid="ref9">9</xref>
        ] as λD HW = 0.497 * λHW; λD SW = 0.476 * λSW ;
      </p>
      <p>
        - when diagnosing a part of dangerous failures, the intensity of detected dangerous
failures is λDD HW = λD HW * DCHW, and the intensity of undetected dangerous failures.
2.2. Multi-Fragmental Model for Evaluating the Functional Safety of the
Information and Control System with the Absorbing States
MICS31 multi-fragmental model is improved in comparison with MICS01 and
contains absorbing states in each fragment. The application of the multi-fragmental
principle [
        <xref ref-type="bibr" rid="ref6">6</xref>
        ] allows us to adequately make the model of the elimination of design
faults with the subsequent decrease in the intensity of dangerous SW failures. The
graduated graph of the model is presented in Fig.1. The two-fragmental model
describing the operation of the information and control system, in the course of which
one design fault is eliminated, is considered. Each fragment of the model contains 25
states: S0 ... S24 in the initial F0 fragment and S25 ... S49 in the final F1 fragment.
The initial operation of the system is described by the change of states, as in MICS01
model, but after detecting the dangerous SW failure, which manifests itself with λD S 0
intensity, the mechanism for its elimination is initiated, after which the system goes
into the new fragment of F1 states, which is modeled by the corresponding
S18 → S25, S19 → S26, S20 → S28, S21 → S29, S22 → S31, S23 → S32, S24 →
S33 transitions with µSR&gt;µS intensity.
      </p>
      <p>
        In the new fragment, the system functions in the same way as described for
MICS01 model [
        <xref ref-type="bibr" rid="ref1">1</xref>
        ] (taking into account the “shift” of state numbering by 25). At the
same time, in F1 fragment, the intensity of the manifestation of dangerous SW
failures is equal to λD S 1, and is defined as:
      </p>
      <p>DSi  DSi1  DS</p>
      <p>Since design faults remain in the system, after manifestation and detection of the
dangerous SW failure, the system restarts to eliminate its consequences of µS
intensity, which is modeled by S41 → S25, S42 → S26, S44 → S28,
S45 → S29,S47 → S31, S48 → S32, S49 → S33 transitions.</p>
      <p>In all fragments of МICS31 model, there are absorbing states: S17 in F0 fragment
and S42 in F1 fragment.</p>
      <p>The availability function taking into account dangerous failures is defined as (2):
A  t   P0  t   P1  t   P3  t  
P25  t   P26  t   P28 t .</p>
      <p>Baseline conditions: t = 0, P0 (0) = 1, P1(0)…P49(0) = 0.
(1)
(2)
3λhDCh
2λhDCh
µh
2λhDCh
λs0(1-DCs)
S1 2λh(1-DCh) S4 λh(1-DCh)
λhDCh</p>
      <p>µh λhDCh
2µh</p>
      <p>2µh
S0 3λh(1-DCh) S3 2λh(1-DCh) S6 λh(1-DCh) S8
µh
3λhDCh
S9
µh</p>
      <p>2λhDCh
λs0(1-DCs)</p>
      <p>λhDCh
λs0(1-DCs)</p>
      <p>µh
3λh(1-DCh) S12 2λh(1-DCh) S15 λh(1-DCh) S17
µh
S2
S27
µsr
µsr
µsr
µsr
2.3. Multi-Fragmental Model for Evaluating the Functional Safety of the
Information and Control System with the Migration of Failures
In MICS41 multi-fragmental model, the assumption of the “migration” of hidden
failures into decisive ones, described earlier for MICS02 model, was adopted. There
are no absorbing states on the graduated graph of the model (Fig. 2). Transitions from
the undetected dangerous failure state are simulated without additional measures
(proof test). This model also deals with the elimination of the decisive DC SW after
its manifestation. This is modeled as in MICS31 model by S18 → S25, S19 → S26,
S20 → S28, S21 → S29, S22 → S31, S23 → S32, S24 → S33 transitions with µSR
3λhDCh
2λhDCh
3λhDCh
2λhDCh
µh
S0
S1
S2
µh
S25
S26
S27
intensity. In the last F1 fragment, system
performed by restarting with µs intensity</p>
      <p>recovery after the dangerous SW
without its elimination.
Fig. 2.
МICS41
The number and nature of the states of the MICS41 model graph are identical to the
previous MICS31 model. In addition to the МICS31 model, transitions have been
added that simulate the migration of hidden HW failures: S3→S1, S4→S2, S6→S4,
S7→S5, S8→S7, S12→S10, S13→S11, S15→S13, S16→S14, S17→S6; transitions
that simulate the migration of hidden SW failures: S9→S18, S10→S19, S12→S20,
S13→S21, S15→S22, S16→S23, S17→S24 (for initial fragme nt F0). For F1
fragment migration of hidden HW failures is presented in transitions S28→S26,
S29→S27, S31→S29, S32→S30, S33→S32, S37→S35, S38→S36, S40→S38,</p>
    </sec>
    <sec id="sec-3">
      <title>4 Simulation and Comparative Analysis</title>
      <p>
        The calculation of the availability indicators is performed for the input data from
Table 2. To construct the matrix of the Kolmogorov-Chapman system of differential
equations, we use the matrix A function [
        <xref ref-type="bibr" rid="ref8">8</xref>
        ]. The Kolmogorov solution was performed
in the Matlab system using the ode15s method [
        <xref ref-type="bibr" rid="ref9">9</xref>
        ] for the time interval of [0 ... 50000]
hours. The results of the solution are presented in the graphical form in Fig. 3.
The presence of absorbing states in MICS31 model causes the availability function
behavior similar to MICS01 model - it's striving to zero. But it is obvious that the
elimination of design faults slows the decrease in availability to zero. The decrease in
the level of availability below 0.999 occurs after 13992 hours or 1.6 years. This value
is worse than in MICS01 model and does not meet the standard for industrial systems
in 3 years or 26298 hours.
      </p>
      <p>The availability function of MICS41 model is approaching to the stationary value
of 0.9901, at that it goes into the established mode on 106 hours later than the result of
the single-fragment MICS02 model. The decrease in the level of availability below
0.999 occurs after 14666 hours or 1.67 years. This value is worse than in MICS02
model and does not meet the standard for industrial systems in 3 years or
26298 hours.</p>
      <p>For MICS31 and MICS41 models, the additional studies were conducted to
determine the values of the input parameters at which TAreq ≥ 26298 hours. The
intervals for changing the input parameters are the same as for MICS01 model and are
shown in Table 3.
Cyclic scripts for Matlab were built to calculate the models. The results of the
research are shown as graphical dependences in Fig. 4 – Fig. 6.</p>
      <p>a)
b)
The results of the influence of values of the input λD H parameter on the behavior of
the availability function of MICS31 model are shown in Fig.4 (a). With the decrease
in the intensity of dangerous failures of HW, the reduction in availability to zero
slows down. But taking into account the scale on the horizontal axis (108 hours), this
result is not applicable in practice.</p>
      <p>The results of the influence of values of the input λ D H parameter on the established
value of the function of MICS02 model are shown in Fig. 4 (b). With the decrease in
the intensity of dangerous HW failures, Aconst increases insignificantly (6 decimal
places), which cannot be used for practical application. The result presented in
Fig. 4(b) is also practically not interesting since a change of λD H by two orders of
magnitude does not allow assuring TAreq ≥ 26298 hours’ condition.
The value of the input DC H parameter of MICS31 model affects the speed of the
transition of the availability function to the established value: with the increase in
DCH from 0.99 to 0.999, the descent of availability to zero slows down by 4 * 107
hours. The value of the input DCH parameter of MICS41 model practically does not
affect the speed of the transition of the availability function to the established value.
On the other hand, the change in DCH from 0 to 1 also causes a change in Aconst within
[0...0.9902]. The result presented in Fig.5 (b) is also important for practice, since after
modeling it becomes obvious that the increase in DCH to 1 does not allow to ensure
TAreq ≥ 26298 hours’ condition (as in MICS31 model).</p>
      <p>a)
b)
Fig. 6. Charts of availability function of MICS31 model (а), interval determination TAreq
MICS41 model (b) for different values of the input parameter DCs
The results of the influence of values of the input DCS parameter on the behavior of
the availability function of MICS31 model are shown in Fig.6 (a). With the increase
in the test coverage of dangerous SW failures by the order of magnitude (from DCS =
0.99 to DCS = 0.999, etc.), the availability function goes to zero level several times
slower (from 5 * 107 to 6 * 107 hours). The following result is important for practice:
starting from DCS = 0.9947 value, TAreq ≥ 26298 hours’ condition is provided.</p>
      <p>The results of the influence of values of the input DCS parameter on the behavior
of the availability function of the model are shown in Fig.6 (b). The dependence of
Aconst on DCS for MICS41 model is linear and is not shown in the graph. With
DCS = 1 → Aconst = 0.9999924. The value satisfying the requirements of SIL3
(Aconst = 0.99909) is achieved at DCS = 0.9991. Theoretically, this allows us to talk
about systems without a proof test, but from the practical point of view, it is very
difficult and costly to achieve such level of control completeness.</p>
      <p>The results are shown in Fig.6 (b) illustrate the maintenance of TAreq ≥ 3 years’
condition starting from DCS = 0.9942 value. And what is more interesting, in Fig.
6(b) it is shown that in DCS = [0.998 ... 0.9991] interval the multi-fragmental MICS41
model over the proof test period significantly benefits the single-fragmental MICS02
model.
5</p>
    </sec>
    <sec id="sec-4">
      <title>Conclusions</title>
      <p>In the article, the multi-fragmental model architecture for information and control
systems of NPP 2оо3 is presented with occurred HW and SW faults and eliminating
of hidden faults.</p>
      <p>Analysis of the obtained results of modeling the availability of the information and
control systems of NPP architecture with partially eliminating of design faults has
shown that:</p>
      <p>a) for the multi-fragmental MICS31 model with absorbing the decrease in the
availability function to zero is significant. For typical values of input parameters
(Table 2), the fulfillment of SIL3 requirements is guaranteed in [0 ... 1.6 years]
interval. The increase in the interest Tproof test interval of up to 3 years is possible with
the increase in the control completeness to detect dangerous SW failures to DCS =
0.9947 level and higher;</p>
      <p>b) the multi-fragmental MICS41 model is characterized by the decrease in the
availability function to the stationary Aconst value. For typical values of input
parameters (Table 2), the fulfillment of SIL3 requirements is guaranteed in [0 ... 1.67
years] interval. The increase in the interest Tproof test interval of up to 3 years is possible
with the increase in the control completeness to detect dangerous SW failures to
DCS = 0.9942 level. Starting from DCS = 0.9991, SIL3 requirements are guaranteed to
be fulfilled without additional proof tests.</p>
      <p>The developed mathematical models make it possible to assess the fulfillment of
the requirements for the functional safety of the designed information and control
system. Application of the developed models is advisable in specific time counts tied
to the phases of the V-model of the project life cycle (and possibly to the separate
layer of the V-model).</p>
      <p>The future step includes: it is necessary to put in order and regulate the operations
of choosing one of several models for the specific design phase, tight time reference
to the beginning/end of the life cycle phase, substantiation of assumptions, changes in
the structure and parameters of models in one method.</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          1.
          <string-name>
            <surname>Bulba</surname>
            ,
            <given-names>Y.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Ponochovny</surname>
            ,
            <given-names>Y.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Sklyar</surname>
            ,
            <given-names>V.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Ivasiuk</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          <article-title>Classification and research of the reactor protection instrumentation and control system functional safety Markov models in a normal operation mode</article-title>
          .
          <source>CEUR Workshop Proceedings</source>
          ,
          <volume>1614</volume>
          ,
          <fpage>308</fpage>
          -
          <lpage>321</lpage>
          (
          <year>2016</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          2. IEC 61508-6:
          <fpage>2010</fpage>
          .
          <article-title>Functional safety of electrical/electronic/programmable electronic safety-related systems</article-title>
          ,
          <source>Part 6: Guidelines on the application of IEC 61508-2</source>
          ,
          <issue>3</issue>
          (
          <year>2010</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          3.
          <string-name>
            <surname>Langeron</surname>
            ,
            <given-names>Y.</given-names>
          </string-name>
          <string-name>
            <surname>Barros</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          <string-name>
            <surname>Grall</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          <string-name>
            <surname>Berenguer</surname>
            ,
            <given-names>C.</given-names>
          </string-name>
          <article-title>Combination of safety integrity levels (SILs): A study of IEC61508 merging rules</article-title>
          .
          <source>Journal of Loss Prevention in the Process Industries</source>
          <volume>21</volume>
          (
          <issue>4</issue>
          ),
          <fpage>437</fpage>
          -
          <lpage>449</lpage>
          (
          <year>2008</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          4.
          <string-name>
            <surname>Zhu</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          <string-name>
            <surname>Pham</surname>
            ,
            <given-names>H.</given-names>
          </string-name>
          <article-title>A software reliability model with time-dependent fault detection and fault removal</article-title>
          .
          <source>Vietnam J Comput Sci</source>
          <volume>3</volume>
          (
          <issue>2</issue>
          ):
          <fpage>71</fpage>
          -
          <lpage>79</lpage>
          (
          <year>2016</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          5.
          <string-name>
            <surname>Pham</surname>
            ,
            <given-names>H.</given-names>
          </string-name>
          <article-title>Loglog fault-detection rate and testing coverage software reliability models subject to random environments</article-title>
          .
          <source>Vietnam J. Comput. Sci. 1</source>
          (
          <issue>1</issue>
          ),
          <fpage>39</fpage>
          -
          <lpage>45</lpage>
          (
          <year>2014</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          6.
          <string-name>
            <surname>Kharchenko</surname>
          </string-name>
          , V.;
          <string-name>
            <surname>Butenko</surname>
            ,
            <given-names>V.</given-names>
          </string-name>
          ;
          <string-name>
            <surname>Odarushchenko</surname>
            ,
            <given-names>O.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Sklyar</surname>
            ,
            <given-names>V.</given-names>
          </string-name>
          :
          <article-title>Multifragmentation Markov Modeling of a Reactor Trip System</article-title>
          .
          <source>ASME Journal of Nuclear Engineering and Radiation Science</source>
          , vol.
          <volume>1</volume>
          (
          <issue>3</issue>
          ),
          <fpage>031005</fpage>
          -
          <lpage>031005</lpage>
          -
          <fpage>10</fpage>
          (
          <year>2015</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          7.
          <fpage>D7</fpage>
          .
          <fpage>24</fpage>
          -
          <string-name>
            <surname>FSC(P3)-</surname>
          </string-name>
          FMEDA-V6R0.
          <source>Exida FMEDA Report of Project: Radiy FPGA-based Safety Controller (FSC)</source>
          (
          <year>2018</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          8.
          <string-name>
            <surname>Kharchenko</surname>
            ,
            <given-names>V.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Ponochovnyi</surname>
            ,
            <given-names>Y.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Boyarchuk</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Brezhnev</surname>
          </string-name>
          , E.:
          <article-title>Resilience Assurance for Software-Based Space Systems with Online Patching: Two Cases</article-title>
          . In: Zamojski W.,
          <string-name>
            <surname>Mazurkiewicz</surname>
            <given-names>J.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Sugier</surname>
            <given-names>J.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Walkowiak</surname>
            <given-names>T.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Kacprzyk</surname>
            <given-names>J</given-names>
          </string-name>
          . (eds)
          <article-title>Dependability Engineering and Complex Systems</article-title>
          .
          <source>DepCoS-RELCOMEX 2016. Advances in Intelligent Systems and Computing</source>
          , vol
          <volume>470</volume>
          ,
          <fpage>267</fpage>
          -
          <lpage>278</lpage>
          (
          <year>2016</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          9. Ode15s:
          <article-title>Solve stiff differential equations and DAEs - variable order method</article-title>
          . https://www.mathworks.com/help/matlab/ref/ode15s.html,
          <source>last accessed</source>
          <year>2019</year>
          /05/07
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>