<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Methodology of Defining the Accident Rate Function for Fault Tolerant System with High Responsibility Purpose</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Leonid Ozirkovskyy</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Bohdan Volochiy</string-name>
          <email>bvolochiy@ukr.net</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Mykhailo Zmysnyi</string-name>
          <email>zmysnyim@gmail.com</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Andriy Maschak</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>Lviv Polytechnic National University</institution>
          ,
          <addr-line>12 S. Bandera street, Lviv, Ukraine, 79000</addr-line>
        </aff>
      </contrib-group>
      <abstract>
        <p>In this paper we propose a new term - accident rate function. Such term gave a possibility to provide the quantative assessment for operational safety in the fault tolerant systems with high responsiblity purposes. Moreover, we propose a binary structural automata model. Using the proposed binary structural automata model in the ASNA software, we provide a possibility to build models of the fault tolerant systems in the form of a graph of states and transitions, in an automatic way. Obtained graph of states and transitions is used to define the accident rate function. The authenticity of the emergency rate function is confirmed by the coincidence of two calculated values. One value is obtained based on accident rate function at determined time interval and the other value is the probability of minimal cut sets obtained based on fault tree at a similar time interval. Using the ASNA software to get the accident rate function and the usage of new methodology of forming the accident rate function from the subarray of nonfunctioning states makes the process of obtaining the results in an automatic way. As a result, the proposed approach gives a possibility to perform multivariant analysis of functional safety for the systems with high responsibility purpose.</p>
      </abstract>
      <kwd-group>
        <kwd>Safety Analysis</kwd>
        <kwd>Reliability Model</kwd>
        <kwd>Fault-Tolerant System</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>-</title>
      <p>
        If the high quality of critical system functioning is required, then the required level of
its reliability must be ensured. There are such critical systems as a control system for
transport vehicles (aviation, railway, marine transport), a control system with power
objects (nuclear, thermal, hydroenergetics), military-oriented systems, medical
systems. For such systems, the most determined property is the pre-defined level of
functional safety. Functional safety is the property of the system and it determines
whether the system or the system submodule fails, and if it does, then the system
switches to the state in which there are not any harmful consequences for humans or
environment or dependant systems/submodules [
        <xref ref-type="bibr" rid="ref1 ref2 ref3">1 - 3</xref>
        ].
      </p>
      <p>
        An assesment of functional safety of exploitation of the critical systems is carried
out using the following analyses - Failure Mode, Effects and Criticality Analysis
(FMECA), Fault Tree Analysis (FTA) and Even Tree Analysis (ETA). As a result, we
obtain the values of the exploitation risk. The proper values are set according to
international standards [
        <xref ref-type="bibr" rid="ref1 ref2 ref20">1, 2, 20</xref>
        ]. In case of exceeding maximum legitimate value, it
is necessary to provide some corrective actions to decrease it.
      </p>
      <p>For the functional safety, the main value of risk exploitation is a probability of the
minimum cut sets (MCS). The minimum cut set is the smallest combination of events
called “element failed”, which results in failure of the whole system. If one of the
“element failed” events is removed from MCS, the system failure is impossible [4
6]. The analysis of MCS gives a possibility to present the most vulnerable elements of
the system. As a result, the functional safety of the whole system can increase if the
safety of only the most critical (vulnerable) elements of the system expands.</p>
      <p>
        Based on the literature review of functional safety assesment, we may assume that
a basic methodology (as an instrument) is a Fault Tree Analysis. The improvements
of MCS determination methodology based on FTA are shown in the papers [
        <xref ref-type="bibr" rid="ref10 ref11 ref12 ref14 ref9">9, 10, 11,
12, 14</xref>
        ]. Methods of time decreasing for MCS determination using FTA, and the
methods of calculation probabilities are shown in the publications [
        <xref ref-type="bibr" rid="ref13 ref15 ref7 ref8">7, 8, 13, 15</xref>
        ]. It can
be seen that in FTA the tree building is the largest and the most time-consuming
operation. Therefore, this operation requires a considerable skill from a designer.
      </p>
      <p>The main use of FTA is acceptable only when you need to analyse the functional
safety of complex systems only once. But FTA usage is not applicable on the design
stage, when it is necessary to execute the functional safety assesment for each
proposed variant of the system. The question is about the synthesis of the system with
required level of functional safety.</p>
      <p>
        The functional safety assesment, based on the Markov model for the complex
system, is shown in the papers [
        <xref ref-type="bibr" rid="ref16 ref17">16, 17</xref>
        ]. In a monography [
        <xref ref-type="bibr" rid="ref16">16</xref>
        ], the approach is
developed to obtain the MCS from the graph of the states and transitions. This
approach is intended to be used for the analysis of the systems where its model has a
large dimension (count with the number of states more than a million). The method of
simplification of the graph of the states and transitions was used as a basis for the
proposed approach. The simplification has a rule to unite the “similar” states. In the
article [
        <xref ref-type="bibr" rid="ref17">17</xref>
        ], the approach of safety assessment using the Markov model is presented.
As the safety index, the Mean Time Until Failure is used.
      </p>
      <p>Development of the fault tolerant system of the responsibility purpose with the
predefined level of functional safety on the design stage foresees tackling the task of
synthesis of functionality and reliability. Such tasks can be solved with the analysis of
many expedient variants of the system. To solve such task, the designer must have a
methodology based on which he can determine the functional safety for lots of system
variants in a limited interval of time.
2</p>
      <p>
        Accident rate function for fault tolerant system
For the safety assessment of fault-tolerant systems, the MCS are used. The MCS are
presented as logical functions [
        <xref ref-type="bibr" rid="ref18 ref19">18, 19</xref>
        ]. Note that obtained MCS using the fault tree
are point-based and these MCS represent the specific value for the time of operation.
For the designer of the fault tolerant system, it is useful to have the dependence of the
MCS occurrence probability value and the change of the time of operation. To obtain
such a characteristic, many fault trees must be developed, since the fault tree is
constructed for given operating time.
      </p>
      <p>Using the model of the fault tolerant system in the form of the graph of the states
and transitions opens up the possibility to determine the MCS occurence probability
for any value of the time of operation [22].</p>
      <p>
        The time spent on developing complex system model in the form of the fault tree is
comperative to the development of the graph of states and transitions [22]. However,
if the building of the state graph is automated [
        <xref ref-type="bibr" rid="ref3">3</xref>
        ], then it is possible to determine the
MCS occurrence probability, depending (as a function) on the time of operation of the
system which is under investigation. We propose to name this function as an
"accident rate" function.
      </p>
      <p>Accident rate function (ARF) is dependence on the time of operation (observation),
and the probability of the system in the failure state, which leads to an accident. For
example, the value of the accident rate is defined as the sum of the probabilities of
staying in safe non-functioning states, critical and/or catastrophic states. The
transitions between these states show the trajectory of the transition (evolution) of the
system from the insignificant failure to failure. Moreover, the less transitions from a
failure safe state to a catastrophic one occur, the lower level of the functional safety
system has. And therefore, there are fewer opportunities to avoid an accident.</p>
      <p>According to the results of the provided research for the accident rate function, the
following properties are established:</p>
      <p>1) For a particular system, the number of accident rate functions QA (t) equals to
the minimum cut sets (MCS) for an accident.</p>
      <p>2) The value of the accident rate function at a specific moment of time is equal to
the probability of the appearance of the minimum cut set, which is obtained using the
fault tree for the same time period.</p>
      <p>3) The probability of occurrence of an accident rate situation QAC (t) at a given
interval of time is determined by the following formula:</p>
      <p>k
QAC (t)  1  [1  QAi (t)] (1)</p>
      <p>i1
where QAі(t) ‒ i-accident rate function,
k ‒ a number of accident rate functions.</p>
      <p>The methodology of determining the accident rate function is shown in the section
below.
3</p>
      <p>Creation of the mask to select the non-functioning states
which form the accident rate function</p>
      <p>To get the formula of the accident rate function, we need to define the space of
non-functioning states. These non-functioning states cause the accident situation.
Because some non-functioning states could be in the different ARF, it is required to
have the means to define their identification. As such means, we propose to use the
mask of the accident rate situation.</p>
      <p>The accident rate mask is a logical function, formed from the components of the
vector states, the transition into a non-functioning state which is necessary and there
is a sufficient condition to make the accident situation occur. The accident rate mask
is obtained from "Condition of fault of the fault tolerant sytem fail" by minimizing it
under the rules of algebra of logic.</p>
      <p>The accident rate mask has the following properties:</p>
      <p>If the logical expression, which describes the accident situation, consists of
components of the vector states (VS), united only by the operator "AND", then for the
research object there is one accidental function:</p>
      <p>(Vg=0)(Vh=0)…  (Vk=0)</p>
      <p>If the logical expression, which describes the accident situation, consists of groups
of components united by the operator "OR", and in each of the groups, the VS
components are combined only by the operator "AND", then the z-functions of the
accident rate are inherent in the object of the investigation:</p>
      <p>((Vm=0)(Vn=0) …(Vq=0)) ….. ((Vs=0)(Vt=0)… (Vy=0))
For instance, if as a result of minimization for the "Condition of fault the fault
tolerant sytem fail" the following function was obtained and it consists of three
groups of the MCS components which are combined by the OR logical operator:
((V1=0)∧(V2=0)∧(V4=0))∨((V2=0)∧(V5=0))∨((V1=0)∧(V5=0)),
then in this case, there are three accident rate functions. The first function of the
accident rate is formed by non-functioning states of the system in which the 1st, the
2nd and the 4th modules fail. The second ARF forms non-functioning states of the
system, in which the 2nd and the 5th modules fail, and the third one - the
nonfunctioning states of the system in which the 1st and the 5th modules are
nonfunctioning</p>
      <p>Based on the obtained masks, using the special algorithm, which is given below,
the ARF is formed.
4</p>
      <p>Algorithm to form the accident rate functions from the sub
Space of Non-Functioning States
The algorithm of the ARF formation consists of two stages. At the first stage, the
groups of all the states are determined based on the mask of an accident rate which
correspond to a specific ARF. At the second stage - the expressions are formed to
calculate the quantitative value of ARF, from the selected states.
4.1</p>
      <p>Stage I: Defining the groups of the states which correspond to each
accident rate function
All the states are selected, in which the VS components correspond to the mask of the
accident rate equal to zero. If the mask of the accident rate has several components
integrated by the logical OR operator, then there will be ARFs, and there will be the
selected group of states for each of them.</p>
      <p>The input data for the algorithm is a set of non-functioning states, that are obtained
using a binary structural automata model (SAM).</p>
      <p>When developing the algorithm for automated determination of ARF , the
following assumptions were adopted:
• at least one ARF is inherent to the system;
• a catastrophic state (CS) is the state of the fault system with high responsibility
purpose (FSHRP), which creates an accident rate on the object of its (use);
• the accident rate function of the system is determined by a set of states, in which
the system enters the path to the fault (accident). If at least one VS component, which
is zero, in all these states has given the value of one (to be put into functioning
condition), then the creation of an accidental situation will not be due to the FSHRP.</p>
      <p>For a compact (algorithmic) description of the developed method, the following
abbreviations are used:
n – a pointer to the ordinal number of the ARF.
i, j - indicators of the ordinal number of the VS components.</p>
      <p>CSC - a counter for the number of components in an accident rate mask (the
number of expressions separated by operators OR).</p>
      <p>ECC – an external cycle counter.</p>
      <p>ICC - an internal cycle counter.</p>
      <p>CNCVS - a constant number of components of the vector state.</p>
      <p>CNC - a counter of the number of VS components in the accident rate mask.</p>
      <p>ZCn - a zero counter; this counter for ARF, with ordinal number n the number of
VS components which value equals to zero.</p>
      <p>ARFC - ARF counter.</p>
      <p>ARMC - the mask of an accident rate component.</p>
      <p>AARF - an array of ARFs.</p>
      <p>SE - a sign of equality.</p>
      <p>SARF - a sign of ARF.</p>
      <p>Vсn [i] - the value of the i-th state vector of the mask component of the accident
situation with the ordinal number n.</p>
      <p>To find ARF, it is necessary to sort the obtained array of non-functioning system
states on the basis of the smallest number of events which led to the accident rate of
the system with the minimum number of VS components equal to zero. They are
nonfunctioning states, in which the transition was made directly from functioning state.
As a rule, they are non-functioning safe states. On the basis of the sorted array of
nonfunctioning system states in accordance with the mask component of an accident rate,
there are the system states which serve to form the specific ARF. As a result, the array
of ARF is obtained.</p>
      <p>The first step of this phase is to create a matrix which will consist of three columns
– in the first column the ordinal number of the mask of accident rate component is
written – N, in the second one – VS component is written using comma which
corresponds to the first component of accident rate mask and its value, in the third one
– the value of zero counter – especially the number of zeros of VS component in their
respective VS (ZC).</p>
      <p>ARF sorting procedure</p>
      <p>The sorting procedure is performed in two embedded cycles – external and internal
ones – by comparing two adjacent components of the accident rate mask, and
involves the execution of the following steps.</p>
      <p>The input data:
ECC - an external cycle counter which is assigned with the value of a number of
components of the accident rate mask.</p>
      <p>ICC = (ECC - 1)
n – a pointer to the ordinal number of mask component of an accident rate.
(n+1) – a pointer to the next ordinal number of mask component of an accident rate
(of an accident rate)</p>
      <p>Step 1. n=1 is assigned to the pointer to the ordinal number of mask component of
an accident rate system; a pointer to the next ordinal number receives the value
(n+1)=2, the unit is subtracted from the counter of an external cycle ECC, -ECC =
ECC-1; Then you should check the condition whether ECC equals to zero:</p>
      <p>If ECC = 0, it means that the sorting procedure of the mask components of an
accident rate is considered to be completed. As a result of such procedure, the matrix
of mask components of an accident rate is obtained where they are sorted according to
the number of VS components which value equals to zero. So, at the beginning the
states with the smallest number of VS components which value equals to zero will be
introduced.</p>
      <p>If ECC &gt; 0, it means that the sorting procedure of the mask components of an
accident rate continues and it is necessary to proceed to step 2.</p>
      <p>Step 2. At this stage the counter of ZCn zeros with the number n is compared to the
counter of ZC(n+1) zeros with the number (n+1).</p>
      <p>If the value of the counter of ZCn zeros with the ordinal number n is bigger than
the value of the counter of ZC(n+1) MCS with the ordinal number (n+1), then these VS
must be swapped; then it is necessary to reduce the counter of an internal cycle ICC =
ICC - 1 and proceed to step 3.</p>
      <p>Note. In the matrix the mask component of an accident rate of ordinal numbers
should not be changed, only mask components should be swapped which means to
swap VS.</p>
      <p>If the value of the zero counter in the mask component of an accident rate ZCn
with the ordinal number n is smaller or equals to the value of the zero counter of
ZC(n+1) component with the ordinal number (n+1), which means that these
components are not swapped; Then it is necessary to reduce the counter of internal
cycle ICC = ICC-1 and proceed to step 3.</p>
      <p>Step 3. At this stage it is necessary to increase the pointer to the ordinal number of
the mask component of an accident rate adding one n = n + 1 and the next pointer to
the ordinal mask component (n+1) = (n+1) + 1. It is also necessary to check whether
the value of counter of internal cycles does not equal to zero:</p>
      <p>If ICC &gt; 0, it means that not all adjacent mask components of an accident rate
were compared, so it is necessary to proceed to step 2;</p>
      <p>If ICC = 0, it means that all adjacent mask components of an accident rate were
compared, so it is necessary to proceed to step 1;</p>
      <p>As a result of moving mask components of an accident rate in the matrix, the
sorted matrix of these components is obtained. The sorting was based on the value of
the number of zeros in MCS. In the first line of the obtained matrix, there will be VS
with the smallest number of zeros which corresponds to the mask component of an
accident rate. Then there will be the mask component with the same or bigger number
of VS components which equals to zero and until all the states are selected, which
value of VS components corresponds to the accident rate mask.</p>
      <p>Method of determining the accident rate functions</p>
      <p>Method of determining ARF uses the following procedures: to find ARF and to
compare the mask component of an accident rate. The process of finding ARF takes
place in several embedded cycles – the general cycle of finding ARF and the internal
cycles of the comparing procedure of mask components of an accident rate.</p>
      <p>The input data:
CNC – the value of a number of mask components of an accident rate is assigned;
ARFC – zero is assigned to ARF counter ARFC = 0;
j- pointers to the serial VS component;
n- a pointer to the ordinal number of CCn;
SE - a sign of equality.</p>
      <p>SARF - a counter of ARF sign.</p>
      <p>Step 1 . The pointer to the ordinal number of mask component of an accident rate
obtains the value of the number of components in a mask minus a unit – n = CNCVS
and it is necessary to proceed to step 2.</p>
      <p>Step 2. The pointer to the ordinal VS component obtains the first value and the
counter of ARF sign obtains the value of the pointer to the ordinal number CC – j=1;
SAFR=n. It is necessary to proceed to step 3.</p>
      <p>Step 3. At this stage it is necessary to use the comparison procedure of mask
comparison of an accident rate (MCAR). The input data will be the following ones:
nthe pointer to the ordinal number ON and j – the pointer to the ordinal VS component.
After MCAR execution it is necessary to check the sign of equality SE:</p>
      <p>If after the MCAR execution the sign of equality will equal to zero SE=0, it means
that the counter of ARF sign should be reduced by one SAFR = SAFR - 1, and
proceed to step 4.</p>
      <p>If after the MCAR execution the sign of equality will not equal to zero SE=0, it is
necessary to proceed to step 4.</p>
      <p>Having increased the pointer to the ordinal VS component, the next component is
selected VS – j = j + 1; However, it is necessary to check whether such VS
component exists so that such condition is to check:</p>
      <p>If j &gt; n, it is necessary to proceed to step 5.</p>
      <p>If j ≤ n, it is necessary to proceed to step 3.</p>
      <p>Step 5. This step checks whether the mask component of an accident rate with the
ordinal number n is ARF. It is done by checking the counter of МСS sign which
equals to zero or not.</p>
      <p>If SAFR = 0, it means that MCS with the ordinal number n is the AFR system. The
mask component with the ordinal number n should be written in an array of accident
rate functions AARF, and increase the counter MCS by a unit ARFC = ARFC + 1;
then proceed to step 6.</p>
      <p>If SAFR &gt; 0, it is necessary to proceed to step 6.</p>
      <p>Step 6. n = n - 1;
If n &gt; 0, it is necessary to go to step 2.</p>
      <p>If n=0, it means that all MCS are checked and all procedures to find ARF were
completed and all states of a graph which form the specific ARF were found. The
procedure to find ARF is completed.</p>
      <p>The procedure of comparing the system states
The input data:
CNCVS – is assigned to the value of the number of VS components;</p>
      <p>ZCn - is assigned to the number of zeros of VS components in a state with the
ordinal number n.</p>
      <p>VSn [i] – the value of i of VS component that corresponds to the mask component of
an accident rate with the ordinal number n.</p>
      <p>VSj [i] – the value of i component of the vector state that corresponds to the mask
component of an accident rate with the ordinal number j.</p>
      <p>i = l;</p>
      <p>The input data is also the obtained data from the procedure of finding ARF
especially n and j.</p>
      <p>Step 1. At this stage the relevant VS components are compared to the mask
components of an accident rate.</p>
      <p>If ВСn[i] component equals to zero (ВСn[i] = 0) and ВСj[i] component also equals
to zero (ВСj[i] = 0), it means that ZCn = ZCn -1; і = і + 1; then it is necessary to
proceed to step 2.</p>
      <p>If any of the above mentioned conditions is not fulfilled, it means that і = і + 1; the
it is necessary to proceed to step 2.</p>
      <p>Step 2. At this stage the current number of VS component is checked whether it
exceeds the total number of VS components of an accident rate in the mask.</p>
      <p>If і ≤ VSC, then go back to step 1.</p>
      <p>If і &gt; VSC, then proceed to step 3.
Step 3. At this stage the certain value is attributed to the SE comparison sign.
If ZCn =0, so 1 is assigned to SE.</p>
      <p>IF ZCn &gt; 0 , so 0 is assigned to SE.</p>
      <p>At this stage the comparison procedure of the mask components of an accident rate
is completed.</p>
      <p>As a result of such procedure, there is the return value of the equality sign SE to
the procedure which triggered it.
4.2</p>
      <p>Stage II: Algorithm for forming expressions for the accident rate
functions
At the stage II, it is necessary to create the matrix which consists of four columns –
in the first column the ordinal ARF number is written – N, in the second one – VS
component and its value is written, in the third one – the numbers of states are written
that form the specific ARF.</p>
      <p>The input data:
ARF array obtained at the Stage 1.</p>
      <p>An array of all system states (functioning and non-functioning).</p>
      <p>ZC – the counter of ARF amount that is recorded in the AARF array.
CNCVS – constant total number of the number of system states.</p>
      <p>Step 1. j is assigned a unit to the pointer of the ordinal ARF number. It means that
the first ARF is selected from the array of accident rate functions – j=1.</p>
      <p>Step 2. n is assigned a unit to the pointer of the ordinal number of a matrix
component of an accident rate MCAR. It means that the first MCS is selected from
the array of all system states – n=1.</p>
      <p>Step 3. Then it is necessary to use the comparison procedure of matrix components
of an accident rate MCAR where n and j are the initial data.</p>
      <p>If after the MCAR procedure, the equality sign will equal to one SE = 1, then in
the third column in AARF the state number –n should be written and proceed to step
4.</p>
      <p>If after the MCAR procedure, the equality sign will equal to zero SE = 0, then
proceed to step 4.</p>
      <p>Step 4. The pointer to the ordinal number VSC – n is increased by one – n = n + 1;
It is also necessary to check whether the given pointer has exceeded an array of
system states. The check is carried out according to the following condition:</p>
      <p>If Якщо n &lt; CNCVS, then the given pointer has not exceeded the array of system
states, that is why it is necessary to proceed to step 3.</p>
      <p>If n ≥ CNCVS, then it is necessary to proceed to step 5.</p>
      <p>Step 5. The pointer to the ordinal number of matrix component of an accident rate
– j is increased by one j = j + 1; It is also necessary to check whether the given
counter has exceeded the ARF array. The check is carried out according to the
following condition:</p>
      <p>If j ≤ ZC, then the given pointer has not exceeded the array of system states, that is
why it is necessary to proceed to step 2.</p>
      <p>If j &gt; ZC, then the procedure of finding states which posesss the relevant ARF is
completed.</p>
      <p>As a result of such procedure, the third AARF column is filled in.</p>
      <p>The procedure to obtain the ARF expression is to sum the probability values of
staying in relevant states, whose numbers were found in the previous procedure,
meaning in states which are written in the third column of the relevant ARF in the
matrix of ARF array. As a result, the fourth column is filled with the probability
values of relevant ARF. Therefore, the expression of an accident rate function equals to
the sum of probabilities in those states that correspond to the accident rate mask.
q
QAi (t)   Pj (t)  ... (2)
jm
where Pj (t) – probabilities of MCS stay in a group of non-functioning states m … q,
whose value of VS components equals to zero in accordance with i accident rate
mask. The group of non-functioning states in the simplest case can include all the
non-functioning states. There can be several groups of such states for MCS.</p>
      <p>For example, if the accident rate mask:</p>
      <p>(Vg=0)(Vh=0)(Vk=0)
corresponds to such states 20, 21 … 27 and 32 … 35, then the ARF expression will
have such a look (3):</p>
      <p>27 35
QA (t)   Pi (t)   Pi (t)
i20 i32
(3)
5</p>
      <p>
        The methodology validation of determining accident rate
functions
The methodology validation of determining accident rate functions is carried out by
comparing the results obtained from the universal MCS model in a form of a graph of
states and transitions using binary structural automata model (SAM) and the results
obtained from the fault tree constructed using the software Reliasoft BlockSim [
        <xref ref-type="bibr" rid="ref21">21</xref>
        ]
for test MCS.
      </p>
      <p>Test MCS without restoration consists of two different modules connected
consecutively. Both modules have hot reserve. The first module, which is less reliable, has
two reserve modules, while the second one has 1 module. In case of the main module
failure, the backup one connects instead of the main one. Means of control and
commutation are considered to be absolutely reliable and fast. Therefore, in the most
reliable model the probability of successful control and the probability of successful
reserve module connection equal to one, and duration of these procedures equals to
zero. Reserve modules can malfunction regardless of their main ones.
At the first validation stage, the binary structural automata model (SAM) is
constructed. A separate component of vector states corresponds to each module. The initial
value of each component of vector states equals to 1, since all modules are
functioning at the initial moment of time.</p>
      <p>The constructed binary structural automata model (SAM) is appointed for ASNA
software tool which constructs a graph of states and transitions on its basis. As a
result, the graph of states and transitions is obtained which contains 32 states and 111
transitions. The list of states with the value description of each component of vector
states is illustarted in Fig. 1.</p>
      <p>According to the methodology, the determination of the array of non-functioning
states was carried out. The states 1 – 7, 9 – 15, 17 – 23 are functioning. The states 8,
16, 24-32 are non-functioning. Accident rate functions will be formed out of these
states.</p>
      <p>In order to form accident rate functions in accordance with the developed
methodology, it is necessary to form accident rate masks by minimizing the condition of the
catastrophic MCS failure:</p>
      <p>((V1=0) AND (V2=0) AND (V3=0)) OR ((V4=0) AND (V5=0))</p>
      <p>Since the relatively simple fault-tolerant system is chosen in this example, it means
that the condition of catastrophic MCS failure does not require minimization and was
immediately written as the disjunction of the conjunctions. As a result, there are two
operandas with the disjunction sign and therefore, there are two accident rate
functions.</p>
      <p>The first accident rate function has the mask - ((V1=0) AND (V2=0) AND
(V3=0)), and the second one - ((V4=0) AND (V5=0)).</p>
      <p>So, the first accident rate function will be the sum of probabilities in states where
V1, V2 and V3 components equal to zero (4). These states are 8, 16, 24 and 32 (look
at Fig.1):</p>
      <p>Q1 (t)  P8 (t)  P16 (t)  P24 (t)  P32 (t)
(4)</p>
      <p>The second accident rate function will be the sum of probabilities in states where
V4 and V5 components equal to zero (5). These states are 24-32 (look at Fig.1):</p>
      <p>Q2 (t)  P25 (t)  P26 (t)  P27 (t)  P28 (t)  P29 (t)  P30 (t)  P31 (t)  P32 (t) (5)
The Kolmogorov–Chapman system of differential equation was compiled using
ASNA software and based on the obtained graph of states and transitions, it was
solved and the probabilities division in each state was obtained. The obtained division
was exported to Excel spreadsheets and accident rate functions Q1 (t) , Q2 (t) were
constructed which are illustrated on Fig.2.</p>
      <p>There is also constructed the dependence of probability of accident rate occurrence
on time as the sum of probabilities in all non-functioning states (6):
The next validation stage included the transformation of the structural reliability
schema by means of ReliaSoft BlockSim to the fault-tolerant tree which is illustrated
on Fig. 4. MCS were found for the fault-tolerant tree by means of ReliaSoft
BlockSim, the probabilities of their occurrence were calculated at the same moments
of time as well as accident rate functions and the comparison of results was made. As
it can be seen from the Fig. 5 the value of the accident rate function
value of probabilities of MCS1fta occurrence completely coincided. Similarly, the
Q1(t) and the
value of the accident rate function Q2 (t) and the value of probabilities of MCS2 FTA
occurrence coincided.</p>
      <p>As a result, it can be concluded that the developed methods and methodology offer
reliable results and it is possible to obtain the safety pointer using the graph of states
and transitions.
6</p>
      <p>Conclusions
1. The task of further research will be the development of behavior algorithms of
universal reconnaissance complex for medium and unfavorable conditions and the
study of their efficiency with considering the incorrect recognition of objects. The
term ‘an accident rate function’ was introduced. It allowed to quantify the impact of
reliability on safety and vice versa. It is seen that from a reliable model of the system
in the form of a graph of states and transitions, it is possible to determine the accident
rate function.</p>
      <p>2. The confirmation of the accident rate function was provided by comparing two
values – the value obtained from the accident rate function, at a determined interval of
time with the values obtained from the occurrence probability of the minimum cut set.
The minimum cut set was obtained from the fault tree for a similar time interval.</p>
      <p>3. The proposed binary structural automata model with ASNA software allows to
automate the design of fault-tolerant systems in the form of graphs of states and
transitions, which is intended to determine the accident rate function.</p>
      <p>4. The usage of ASNA software for the accident rate function and a new method
to form accident rate functions from the subspace of the non-functioning states
automates this process. Also, it allows a multivariate analysis without excessive time
expenditures for the functional safety of the systems with responsible purpose.</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          1.
          <string-name>
            <surname>US</surname>
          </string-name>
          <article-title>Department of Defense Standard Practice for System Safety: MIL-STD-882E</article-title>
          ,
          <year>101p</year>
          . (
          <year>2012</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          2.
          <string-name>
            <surname>US</surname>
          </string-name>
          <article-title>Department of Defense System Safety Program Requirements: MIL-STD-882C</article-title>
          .
          <article-title>-1993.</article-title>
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          3.
          <string-name>
            <given-names>Bobalo</given-names>
            <surname>Yu</surname>
          </string-name>
          .,
          <string-name>
            <surname>Volochii</surname>
            <given-names>B</given-names>
          </string-name>
          .
          <article-title>Mathematical models and methods of reliability analysis of radioelectronic, electrical and software systems</article-title>
          . O.
          <string-name>
            <surname>Lozinsky</surname>
            ,
            <given-names>B.</given-names>
          </string-name>
          <string-name>
            <surname>Mandzii</surname>
            ,
            <given-names>L.</given-names>
          </string-name>
          <string-name>
            <surname>Ozirkovskii</surname>
            ,
            <given-names>D.</given-names>
          </string-name>
          <string-name>
            <surname>Fedasyuk</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          <string-name>
            <surname>Scherbovskikh</surname>
            ,
            <given-names>V.</given-names>
          </string-name>
          <string-name>
            <surname>Yakovin</surname>
          </string-name>
          . Lviv : Lviv Polytechnic Publishing House,
          <volume>300</volume>
          p. (
          <year>2013</year>
          ).
          <article-title>(in Ukrainian)</article-title>
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          4.
          <string-name>
            <surname>Kececioglu D. Reliability Engineering</surname>
            <given-names>Handbook</given-names>
          </string-name>
          , Volume
          <volume>2</volume>
          . Prentice Hall Inc.: New Jersey,
          <volume>541</volume>
          <fpage>р</fpage>
          . (
          <year>1991</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          5.
          <string-name>
            <surname>Baldwin</surname>
            <given-names>E.</given-names>
          </string-name>
          <string-name>
            <surname>Carr</surname>
          </string-name>
          <article-title>Unmanned Aerial Vehicles: Examining the Safety, Security, Privacy and Regulatory Issues of Integration into U.S. Airspace. National Center for Policy Analysis</article-title>
          ,
          <volume>44</volume>
          p. (
          <year>2013</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          6.
          <string-name>
            <surname>Myers</surname>
            <given-names>A.</given-names>
          </string-name>
          :
          <article-title>Complex System Reliability</article-title>
          .
          <source>Multichannel Systems with Imperfect Fault Coverage 2nd Edition</source>
          . Springer-Verlag: London, 238 p. (
          <year>2010</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          7.
          <string-name>
            <given-names>Jan</given-names>
            <surname>Krcál</surname>
          </string-name>
          ,
          <source>Pavel Krcál Scalable Analysis of Fault Trees with Dynamic Features. 45th Annual IEEE/IFIP International Conference on Dependable Systems and Networks</source>
          . (
          <year>2015</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          8.
          <string-name>
            <given-names>Yanbo</given-names>
            <surname>Che</surname>
          </string-name>
          ,
          <string-name>
            <given-names>Yuancheng</given-names>
            <surname>Zhao</surname>
          </string-name>
          , Jianmei
          <string-name>
            <surname>Xu</surname>
          </string-name>
          , and
          <article-title>Jinhuan Zhou / A Hierarchical Approach for Fast Calculating Minimal Cut Sets of a Microgrid</article-title>
          . Mathematical Problems in Engineering, pp.
          <fpage>1</fpage>
          -
          <lpage>8</lpage>
          . (
          <year>2017</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          9.
          <string-name>
            <given-names>Yuancheng</given-names>
            <surname>Zhao</surname>
          </string-name>
          ,
          <string-name>
            <given-names>Yanbo</given-names>
            <surname>Che</surname>
          </string-name>
          , Tingjun Lin, Chuanyan
          <string-name>
            <surname>Wang</surname>
          </string-name>
          , Jiaxuan Liu, Jianmei Xu,
          <article-title>Jinhuan Zhou Minimal Cut Sets-Based Reliability Evaluation of the More Electric Aircraft Power System /</article-title>
          / Mathematical Problems in Engineering, pp.
          <fpage>1</fpage>
          -
          <lpage>11</lpage>
          . (
          <year>2018</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          10.
          <string-name>
            <surname>Pang</surname>
            <given-names>J.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Liu</surname>
            <given-names>Y.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Mauw</surname>
            <given-names>S.</given-names>
          </string-name>
          : Automatic Generation of Minimal Cut Sets //: 4th International Workshop on Engineering Safety and
          <source>Security Systems 2015 (ESSS'15) EPTCS 184</source>
          , pp.
          <fpage>33</fpage>
          -
          <lpage>47</lpage>
          . (
          <year>2015</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          11.
          <string-name>
            <surname>Guofeng</surname>
            <given-names>Tang</given-names>
          </string-name>
          ,
          <source>Wei Gao Research of the Minimal Cut Sets Post Processing of the PSA Quantification Engine. Nuclear Safety, Security, Non-Proliferation and Cyber Security; Risk Management Shanghai, China, July 2-6</source>
          , (
          <year>2017</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          12.
          <string-name>
            <surname>Zuoyu</surname>
            <given-names>Miao</given-names>
          </string-name>
          , Ru Niu :
          <article-title>A new generation algorithm of fault tree minimal cut sets and its application in CBTC system</article-title>
          .
          <source>Tao Tang</source>
          , Jieyu Liu.
          <source>2013 IEEE International Conference on Intelligent Rail Transportation Proceedings</source>
          , pp.
          <fpage>11</fpage>
          -
          <lpage>23</lpage>
          . (
          <year>2013</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          13.
          <string-name>
            <surname>Woo</surname>
          </string-name>
          <article-title>Sik Jung A method to improve cutset probability calculation in probabilistic safety assessment of nuclear power plants // Reliability Engineering and System Safety</article-title>
          , Volume
          <volume>134</volume>
          ,
          <string-name>
            <surname>February</surname>
          </string-name>
          , pp.
          <fpage>134</fpage>
          -
          <lpage>142</lpage>
          . (
          <year>2015</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          14. Francesco Di Maio, Samuele Baronchelli,
          <article-title>Enrico Zio Minimal Cut Sets Identification of Nuclear Systems by Evolutionary Algorithms</article-title>
          .
          <source>International Topical Meeting on Probabilistic Safety Assessment and Analysis</source>
          ,
          <source>Sep</source>
          <year>2013</year>
          , Columbia, United States pp.
          <fpage>1</fpage>
          -
          <lpage>18</lpage>
          (
          <year>2013</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref15">
        <mixed-citation>
          15.
          <article-title>Kara‐Zaitri An improved minimal cut set algorithm //</article-title>
          <source>International Journal of Quality &amp; Reliability Management</source>
          , Vol.
          <volume>13</volume>
          Issue: 2, pp.
          <fpage>114</fpage>
          -
          <lpage>132</lpage>
          (
          <year>2013</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref16">
        <mixed-citation>
          16.
          <string-name>
            <surname>Dabrowski</surname>
            ,
            <given-names>C.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Hunt</surname>
            ,
            <given-names>F.</given-names>
          </string-name>
          and
          <string-name>
            <surname>Morrison</surname>
            ,
            <given-names>K.</given-names>
          </string-name>
          ,
          <source>Improving the Efficiency of Markov Chain Analysis of Complex Distributed Systems. National Institute of Standards and Technology, Interagency Report 7744</source>
          , 81 p. (
          <year>2010</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref17">
        <mixed-citation>
          17.
          <string-name>
            <surname>Gandi</surname>
            <given-names>Satyanarayana</given-names>
          </string-name>
          , Seetharamaiah P.:
          <article-title>Component safety assessment using three-state Markov model</article-title>
          .
          <source>International Research Journal of Engineering and Technology (IRJET)</source>
          , Volume:
          <volume>02</volume>
          Issue: 09 | Dec-2015, pp.
          <fpage>299</fpage>
          -
          <lpage>306</lpage>
          . (
          <year>2015</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref18">
        <mixed-citation>
          18.
          <string-name>
            <surname>Vesely</surname>
            ,
            <given-names>W.E.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Dugan</surname>
            ,
            <given-names>J.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Fragola</surname>
            ,
            <given-names>J.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Minarick</surname>
            <given-names>III</given-names>
          </string-name>
          , J.,
          <string-name>
            <surname>Railsback</surname>
          </string-name>
          , J.:
          <article-title>Fault Tree Handbook with Aerospace Applications. National Aeronatics and Space Adminis-tration</article-title>
          ,
          <year>August 2002</year>
          .
          <volume>218</volume>
          p. (
          <year>2002</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref19">
        <mixed-citation>
          19.
          <string-name>
            <surname>Eckard</surname>
            <given-names>Bode</given-names>
          </string-name>
          , Thomas Peikenkamp :
          <article-title>Model Based Importance Analysis for Minimal Cut Sets</article-title>
          . Jan Rakow, Samuel Wischmeyer.
          <source>International Symposium on Automated Technology for Verification and Analysis (ATVA</source>
          <year>2008</year>
          ):
          <source>Automated Technology for Verification and Analysis</source>
          ,
          <year>2008</year>
          , P.
          <fpage>303</fpage>
          -
          <lpage>317</lpage>
          . (
          <year>2008</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref20">
        <mixed-citation>
          20.
          <article-title>US Department of Defense Standard Practice for System Safety: MIL-STD-882D</article-title>
          .
          <article-title>-2000</article-title>
        </mixed-citation>
      </ref>
      <ref id="ref21">
        <mixed-citation>
          21.
          <string-name>
            <surname>Block</surname>
          </string-name>
          <article-title>Sim. RBDs, fault trees and Markov diagrams</article-title>
          . Режим доступу: https://www.reliasoft.com/products/reliability-analysis/blocksim 22.
          <string-name>
            <surname>Volochiy</surname>
            <given-names>B.</given-names>
          </string-name>
          <string-name>
            <surname>Yu</surname>
          </string-name>
          .:
          <article-title>Method of Computation of Minimal Cut Sets of Fault-Tolerant Systems Based on Structural-Automatic Model</article-title>
          .
          <string-name>
            <given-names>B.</given-names>
            <surname>Yu. Volochiy</surname>
          </string-name>
          ,
          <string-name>
            <given-names>L. D.</given-names>
            <surname>Ozirkovsky</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A. V.</given-names>
            <surname>Mashchak</surname>
          </string-name>
          ,
          <string-name>
            <given-names>O. P.</given-names>
            <surname>Shkiliuk</surname>
          </string-name>
          ,
          <string-name>
            <given-names>I. V.</given-names>
            <surname>Kulyk</surname>
          </string-name>
          . Bulletin of National Technical University of Ukraine. Series Radiotechnique. Radioapparatus Building, №
          <volume>52</volume>
          , pp.
          <fpage>38</fpage>
          -
          <lpage>45</lpage>
          . (in Ukarinian).
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>