<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Independent Verification and Diversity: Two Echelons of Cyber Physical Systems Safety and Security Assurance</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Vyacheslav Kharchenko</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>KhAI - National Aerospace University “Kharkiv Aviation Institute”</institution>
          ,
          <addr-line>Chkalov st. 17, Kharkiv</addr-line>
          ,
          <country country="UA">Ukraine</country>
        </aff>
      </contrib-group>
      <abstract>
        <p>Conceptions of safety and security for cyber physical systems (CPS) in context of interaction with environment are analysed. Models and interconnection of safety and security and its attributes (functional safety, Internet safety, labor and occupational safety; cyber security, confidentiality, integrity, accessibility and physical security) for CPS functioning in conditions of information and physical environment are discussed considering common cause and time failures issue. Independent verification and validation (IV&amp;V) and D3 (Defence-inDepth and Diversity) approach are two echelons for protection of CPSs against cyber and physical attacks and failures caused by physical and design faults. The techniques of IV&amp;V (XMECA, XBD, XTA, XIT etc.) are analysed in point of view different safety and security attributes. Multi-FIT technique is described as an example for CPS safety assessment. Application of diversity for safety and security assurance is discussed.</p>
      </abstract>
      <kwd-group>
        <kwd>1 Cyber physical systems</kwd>
        <kwd>safety</kwd>
        <kwd>security</kwd>
        <kwd>independent verification and validation</kwd>
        <kwd>diversity</kwd>
        <kwd>common cause failure</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>1. Introduction</title>
      <p> to research the independent verification and validation techniques (XMECA, XBD, XTA,
XIT etc.) and D3 (Defence-in-Depth and Diversity) approach as two barriers against attacks and
failures caused by physical and design faults.</p>
      <p>Structure of the paper corresponds to objectives. Section 2 describes conceptions of CPS safety
and security in context of CCF. Sections 3 and 4 discuss two echelons of CPS protection such as
independent verification and validation and D3 principle. Section 5 concludes and formulates future
research directions.</p>
    </sec>
    <sec id="sec-2">
      <title>2. CPS safety and security in context of common cause failure</title>
    </sec>
    <sec id="sec-3">
      <title>2.1. Safety and security model</title>
      <p>
        Interconnection between functional safety and information (cyber) security as attributes of big
safety is described by Figure 1. According with [
        <xref ref-type="bibr" rid="ref4 ref5">4,5</xref>
        ] safety is an attribute defining how CPS directly
or via controlled object impacts on physical environment (PE) and information (IE) environment
(Figure 1,a) and decreases risks of accidents. Failures of safety critical I&amp;C systems increase such
risks. Information (cyber) and physical security defines the degree of influence of IE and PE on
system (blue and brown arrows, Figures 1,b-d). Insecure influence of IE on safety critical system can
cause failures and unsafe influence of system on environment (dotted blue arrow, Fig.1,c). More
detailed analysis of influence of IE and PE of safety critical system and its influence on environment
is illustrated by Figure 1,d, elements of notation are described by Figure 1,e.
      </p>
      <p>
        There are two types of attacks on CPS integrity (and accessibility or availability) and
confidentiality. First of them causes failures and can be reason of unsafe impact of CSP on IE and PE.
Second one causes receiving confidential data and can be reason more successful attacks on integrity
and accessibility. Influence of PE can cause fatal failures and corresponding influence of CPS on PE
and IE. If CPS safety depends on cyber security as a part of information security it’s justifiable using
of concept “cyber safety” as a part of safety [
        <xref ref-type="bibr" rid="ref6">6</xref>
        ].
      </p>
      <p>More detailed analysis of different attributes of safety including functional, Internet and labour
safety, and security including information security (confidentiality, integrity and accessibility), and
physical security is given in Table 1. It describes influence of physical and information environment
for all types of safety and security, and influence of attributes of safety and security on physical and
information environment. Besides, it is analysed level of potential effects (local, for controlled object
only, and global similar NPP accidents). Influence of attributes is marked by “+”.</p>
    </sec>
    <sec id="sec-4">
      <title>Common cause and common time failures</title>
      <p>One of the key problem of CPS safety (and security as well) assurance is minimization or
exclusion in general of common cause failure (CCF) risks. CCF is event when ef (two or more)
channels (versions) of redundant e-channel (e-version) system fail one by one or simultaneously and
there is common reason causing this event. In any case, CCF is a multiple failure (MF) of CPS unlike
single failure (SF) one of the redundant channels.</p>
      <p>
        It should be emphasized that MF occur as a result of not only one (common) cause. It may be
caused by a few different reasons concurring or spreading of failure time value does not exceed the
response time of on-line testing and reconfiguration. Such type of multiple failures is called as a
common time failure (CTF) which is common event failure (CEF) as CCF [
        <xref ref-type="bibr" rid="ref6">6</xref>
        ]. Classification of
common cause and time failures is shown on the Figure 2. In addition to considered concepts, three
attributes should be specified:
- reasons (physical, design faults and vulnerabilities of hardware (HW) and software (SW));
- number of failed channels (versions) (partial and full CCFs, i.e. PCCFs and FCCFs, and partial
and full CTFs, i.e. PCTFs and FCTFs);
      </p>
      <p>- matching of output channel data in case of failures, i.e. matching (MCCFs, MCTFs) and different
(DCCFs, DCTFs) failures.</p>
      <p>Two preliminary conclusions which are important for safety critical CPSs. Firstly, CTFs are
important objective of research because there are examples of serial failures caused by attacks on
vulnerabilities of redundant channels and combined reasons. Secondly, very important tasks is
analysis and assurance, if it’s possible, of distinguishability of failure effects (output data of failed
channels) to fix fact of partial or full common cause and time failures.
2.3.</p>
    </sec>
    <sec id="sec-5">
      <title>IV&amp;V-D3: two echelons of common failures protection</title>
      <p>
        Problem of CCF decreasing risks can be solved by use of two approaches (Figure 3):
 minimizing of latent faults, first of all, design faults and vulnerabilities. For that techniques of
verification and validation (V&amp;V) of developed or modernized CPSs (hardware, software, FPGA
components, platforms etc.) have to be applied. There is rigorous requirements to V&amp;V including
requirement to independence of verification and validation teams, process, techniques and tools for
safety critical CPSs such as NPP I&amp;C systems. V&amp;V which are performed by an organizational
and/or financially independent team is called independent V&amp;V (IV&amp;V). Implementing IV&amp;V
allows detecting faults which haven’t been detected by developers or QA specialists of company;
 application of diversity as a part of more general so-called principle D3
(Defense-inDepth&amp;Diversity) [
        <xref ref-type="bibr" rid="ref7">7</xref>
        ] to provide trusted fault-, vulnerability and intrusion-tolerance during CPS
operation. D3 is a horizontal/vertical defense echelon consisting of n subechelons ei and m version
redundancy types vrj (Figure 3) [
        <xref ref-type="bibr" rid="ref6 ref8">6, 8, 9</xref>
        ]. Diversity and multi-diversity when a few types version
process-product redundancy are applied allows decreasing risks of common cause failure and
common time failure as well during operation stage of CPSs.
      </p>
      <sec id="sec-5-1">
        <title>Threats (faults,…, anomalies) )</title>
        <p>Stages
of V&amp;V</p>
        <sec id="sec-5-1-1">
          <title>Project,</title>
          <p>n HW, SW and
tio FPGA
icacomponents,
irf I&amp;C
e
V</p>
        </sec>
      </sec>
      <sec id="sec-5-2">
        <title>Creation of CPS</title>
      </sec>
      <sec id="sec-5-3">
        <title>Operation of CPS</title>
        <p>These approaches are two echelons of CCF/CTF protection implementing DET principle “to detect
– to eliminate (detected faults during V&amp;V) – to tolerate (residual/undetected faults during
operation)”.</p>
      </sec>
    </sec>
    <sec id="sec-6">
      <title>3. Independent verification and validation techniques: the first echelon</title>
    </sec>
    <sec id="sec-7">
      <title>3.1. Methods of safety and security assessment and V&amp;V techniques</title>
      <p>
        There are a lot of methods of CPS safety and security assessment and V&amp;V techniques which are
used by developers/QA engineers of companies and independent verifiers as well such as [
        <xref ref-type="bibr" rid="ref4">4, 9, 11</xref>
        ]:
 XME(C/D)A, X (Failure, Software failure, Intrusion, …) Modes and Effects C/D
(Criticality/Diagnostics) Analysis;
 XBD, X (Reliability, Safety, Security, Trustworthiness, …) Block Diagrams;
 XTA, X (Failure, Attack, Non-availability, …) Tree Analysis;
 XIT, X (Fault, Software fault, Vulnerability, …) Injection Testing;
 HAZOP(X), Hazard Operation Analysis (X – for safety, security);
 MM(X), Markov’s Models (X – availability, dependability, safety, security).
 other techniques based on CCF analyses, model checking, formal methods and so on.
      </p>
      <p>The V&amp;V techniques include more software and documentation based procedures as review of
documents (static analysis, verification and validation plans and reports review, check-list based
analysis and so on). Table 2 summarizes the results of analysis of these techniques applicability for
assessment of different safety and security attributes. The following marks are used:
 applicable technique, + ;
 can be applicable, (+);
 can’t be applicable, x.</p>
      <p>
        Two preliminary conclusions are the following:
- in fact, all methods and techniques which were initially developed and are used to assess
functional safety have analogues to assess security and cyber security. For example, FME(C)A
technique (Failure ME(C)A) was modified for security assessment as IME(C)A (Intrusion Modes and
Effects (Criticality) Analysis). Feature of IMECA is considering failure as a pair
“vulnerabilityattack” or as a combination of threats, vulnerabilities and attacks/intrusions [
        <xref ref-type="bibr" rid="ref4">4, 11</xref>
        ];
- the methods of assessment and V&amp;V procedures can be used by combining ones. For that a
special graph-model describing a different ways to get searched measures or V&amp;V results or to assure
high level of trustworthiness by getting searched measures using different combinations of the
techniques.
      </p>
    </sec>
    <sec id="sec-8">
      <title>3.3. Multi-FIT based verification</title>
      <p>Fault (and vulnerability) injection testing is one of the techniques applied for IV&amp;V according
with standards requirements to safety critical CPS. The goals of FIT are to assess the test quality
considering test coverage/trustworthiness issues, efficiency of online testing, analyse fault- and
intrusion-tolerance (to design and physical faults). “Natural” failures for complex SW and HW, CPS
are multiple ones caused by physical and design faults, attacks with different scenarios.</p>
      <p>Main challenges of multiple fault injection (multi-FIT): complexity and time of verification (in
general number of faults equals 2kmn, n – number of faults, k – number of fault types, m – number of
CPS levels), mutation/masking of faults and blockage of verifiable performance. The standard
NUREG/CR-7151 recommends employing a multi-FIT, but it does not describe procedures of
injection. To tolerate these challenges two approaches can be applied [12]:
 development of injectable projects, i.e. assurance of ability to inject faults regarding to
actual/specified physical scheme or code (FITability) to optimize points and means of injection;
 implementing technique of multi-FIT based on application of modified t-wise procedure and
operations of de-masking and de-blockage of injected fault subsets (Figure 4).</p>
      <p>The future steps are important from research and practical point of view:
 development of techniques and tools that take into account the possibilities of injecting
different fault/vulnerability types for different CPS components and system levels. For
FPGAbased systems it may be physical faults injecting at the module and chip levels, design faults and
vulnerabilities injecting into VHDL code and top-level software code);
 development of methods assuring ability to multi-fault injections, i.e. multi-FIT-ability.</p>
    </sec>
    <sec id="sec-9">
      <title>4. Diversity and defence-in-depth: the second echelon</title>
    </sec>
    <sec id="sec-10">
      <title>4.1. Multi-version computing and classification of version redundancy</title>
      <p>Diversity is a basic principle of multi-version computing. Main concepts of multi-version
computing are the following:
 version is an option of different product or/and process realization of CPS function(s);
 version redundancy (VR) is a type of redundancy when different versions are used;
 diversity or multiversity (MV) is the principle providing use of several versions;
 multi-version system (MVS) is a system in which a few versions are used;
 multi-version technology (MVT) is set of the interconnected rules and design actions in which
a few versions-processes leading to development of two or more intermediate or end-products are
used;
 multi-version project (MVP) is a project in which the MVT is applied to create one- or
multiversion system;
 strategy of diversity (MV) is a collection of general criteria and rules defining principles of
formation and selection of version redundancy types and volume or MVTs;
 diversity metric is indicator to assess level of diversity of versions.</p>
      <p>
        To assess CPS safety measures especially a probability of common cause failure it is necessary to
evaluate the diversity metrics [
        <xref ref-type="bibr" rid="ref4">4, 9</xref>
        ]. Figure 5 presents set model of version faults (attacked
vulnerabilities) causing failures. For one-version and cannel system (Figure 5,a) number of single
faults equals N (N = Card SF). In this case, any faults of set SF is fatal and is, in fact, CCF. Hence 
factor as a metric of CCF determining relation of number of faults caused CCFs to total number of
such faults equals one (and  =  = 1).
      </p>
      <p>The metrics of two-version system (Figure 5,b,c) can be evaluated as following:  = NCCF / N, NCCF
= Card (SF1 ∩ SF2); N = (N1 + N2) / 2, Ni = Card SFi; i = 1 -  ; d = NMCCF / N; d = NDCCF / N;  =
d + d . Metrics of relative number of MCCFs and DCCFs (see Figure 2): *d = d / , *d = d /. For
three-version system (Figure 5,d)  = 1 -  - 2, where  is metric determining part of CCFs of any
two versions (PCCF),  = 2NPCCF / N). If  = 0 (Figure 5,e),  = 1 -  .</p>
      <p>These types of faults and vulnerabilities and metrics can be used to add a profile of injected faults
for FIT based verification of multi-version CPSs. Values of metrics  and  are determined using
statistics of testing and operation failures and expert methods [9].</p>
      <p>a)
b)
c)
d)
e)</p>
    </sec>
    <sec id="sec-11">
      <title>4.2. Application of defence-in-depth and diversity for safety and security assurance</title>
      <p>
        Classification of different diversity types and D3 in general is described in [
        <xref ref-type="bibr" rid="ref7">7</xref>
        ]. Table 3 contains
the results of diversity and defence-in-depth (DiD) applicability analysis for assurance of CPS safety
and security. The following marks are used:
 applicable type of diversity, + ;
 type of diversity can be applicable, (+);
 type of diversity can’t be applicable, x.
      </p>
      <p>
        Let’s analyse two examples of application of diversity to assess and improve safety and security.
In the first case CPS has hardware and software diversity. Dependencies of up-state probabilities on
time for the two-version structures are illustrated by Figure 6 [
        <xref ref-type="bibr" rid="ref6">6</xref>
        ]. Initial data for modeling are the
following: failure rate of version (channel) version = 310-5 1/h, metrics of diversity for physical and
design HW faults  Hp=0, Hd = 0.2, metric of diversity for SW design faults  Sd = 0.8; values of SF
metrics for one version hp= hd = sd = 1/3.
      </p>
      <p>Influence
of DiD
+
(+)
+
+
+
+
+
+
x
+
+
+
+
+
x
x
+
+
+
(+)
+
x
+
+
+
+
(+)
+
x
+
+
+
+
+</p>
      <p>
        The second case describes security assessment of FPGA-based MVS. Table 4 summarizes some
attacks and the results of assessment using IMECA-analysis. The table contains countermeasures
strategies which could be applied as a requirements from Regulatory Guide 5.71:2010 (Cyber
Security Programs For Nuclear Facilities, U.S. NRC) to eliminate the attack causes and, moreover,
FPGA-based MVS diversity type and its attributes as a countermeasures [
        <xref ref-type="bibr" rid="ref4">4</xref>
        ].
Altering the
input clock;
e
iv Creating
tcAomroumnednetra-rsyhoootvsetrothe supplied
voltage
      </p>
      <p>M</p>
      <p>H</p>
      <sec id="sec-11-1">
        <title>Diversity of EE:</title>
        <p>iiisecognnnexopLDDscfcemeaotorecaeerrepraautvvmtrerkttiieioeccaocomeettnaifontlieosnifnt itaccvodamiraeepCDMrmenrvepcleinaiorpulftcaekoyecdeiettmiitkcreis;nniotfaengigtinoofnngsfntee;dasfdcruettoithtroemeoatancshtfnutewdapglioellgtivrrhatlvdociitsltinehletcstarveaohtttseghhereolyeeessf, DtssdEEmecpiiCDDDEEcavhvehnssoeiiieecfff;nrurmimpfffsfsofeeerieibaelcrrrotoceeeiyaCdntgnnntuuoaAiitttocretfSiSentsoirSEoons(sSnfo;o;Sff)
tools and SSs</p>
      </sec>
    </sec>
    <sec id="sec-12">
      <title>5. Conclusions and recommendations</title>
      <p>The problem of the “last faults” is one of the most challengeable for critical cyber physical systems
and reputational for commercial applications. There are two key approaches to minimizing risk of
failures caused by design (SW/FPGA) faults and attacks on vulnerabilities using independent V&amp;V
and diversity.</p>
      <p>X (fault, vulnerability, anomaly) injection based techniques (X/FIT) are one of the efficient V&amp;V
techniques. Important tasks are fault profiling; FIT coverage and FIT-ability; multi-FIT and tools.
Systematization and aggregating of V&amp;V techniques allow achieving higher accuracy and
trustworthiness.</p>
      <p>Diversity assures minimizing common cause failure (CCF) risk. Key problems are assessment
CCF risk and implementation of new types of internal/external diversity, formal choice and
combining of different types of version redundancy, multi-fault/vulnerabilities injection for
multiversion systems and so on.</p>
    </sec>
    <sec id="sec-13">
      <title>6. References</title>
      <p>[9] V. Kharchenko, A. Siora, E. Bakhmach, Diversity-Scalable Decisions for FPGA-Based
SafetyCritical I&amp;Cs: from Theory to Implementation, in: Proceedings of the 6th ANS International
Topical Meeting on Nuclear Plant Instrumentation, Controls, and Human Machine Interface
Technology, NPIC&amp;HMIT2009, Knoxville, TN, USA: American Nuclear Society, 2009,
pp.1118.
[10] IEC 60812:2018. Failure modes and effects analysis (FMEA and FMECA), 2018. URL:
https://webstore.iec.ch/publication/26359
[11] E. Babeshko, V. Kharchenko and A. Gorbenko, Applying F(I)MEA-technique for
SCADABased Industrial Control Systems Dependability Assessment and Ensuring, in: 2008 Third
International Conference on Dependability of Computer Systems DepCoS-RELCOMEX,
Szklarska Poreba, Poland, 2008.
[12] O. Odarushchenko, V. Kharchenko, Sklyar, V. Multi-Fault Injection Testing: Cases for
FPGABased NPP I&amp;C Systems, in: Proceedings of ICONE-23 23rd International Conference on
Nuclear Engineering, May 17-21, Chiba, Japan, 2015, pp.31-38.</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          [1]
          <string-name>
            <given-names>A.</given-names>
            <surname>Avizienis</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.-C.</given-names>
            <surname>Laprie</surname>
          </string-name>
          ,
          <string-name>
            <given-names>B.</given-names>
            <surname>Randell</surname>
          </string-name>
          ,
          <string-name>
            <given-names>C.</given-names>
            <surname>Landwehr</surname>
          </string-name>
          ,
          <article-title>Basic Concepts and Taxonomy of Dependable and Secure Computing</article-title>
          ,
          <source>IEEE Transactions on Dependable and Secure Computing</source>
          <volume>1</volume>
          (
          <year>2004</year>
          )
          <fpage>11</fpage>
          -
          <lpage>33</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          [2]
          <string-name>
            <given-names>N.</given-names>
            <surname>Leveson</surname>
          </string-name>
          ,
          <source>Safeware: System Safety and Computers</source>
          ,
          <string-name>
            <surname>Addison-Wesley</surname>
          </string-name>
          ,
          <year>1995</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          [3]
          <string-name>
            <given-names>C.</given-names>
            <surname>Harvey</surname>
          </string-name>
          ,
          <string-name>
            <given-names>N.</given-names>
            <surname>Stanton</surname>
          </string-name>
          ,
          <article-title>Safety in System-of-Systems: Ten key challenges</article-title>
          ,
          <source>Safety Science</source>
          <volume>70</volume>
          (
          <year>2014</year>
          )
          <fpage>358</fpage>
          -
          <lpage>366</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          [4]
          <string-name>
            <given-names>M.</given-names>
            <surname>Yastrebenetsky</surname>
          </string-name>
          , V. Kharchenko (Eds.),
          <source>Security and Safety of Nuclear Power Plant Instrumentation and Control Systems</source>
          , Hershey, Pennsylvania, United States of America,
          <source>IGI Global</source>
          ,
          <year>2020</year>
          , 501 p.
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          [5]
          <string-name>
            <given-names>A.</given-names>
            <surname>Kornecki</surname>
          </string-name>
          ,
          <string-name>
            <given-names>N.</given-names>
            <surname>Subramanian</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Zalewski</surname>
          </string-name>
          ,
          <source>Studying Interrelationships of Safety and Security for Software Assurance in Cyber-Physical Systems Proceedings of the Federated Conference on Computer Science and Information Systems</source>
          ,
          <year>2013</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          [6]
          <string-name>
            <given-names>V.</given-names>
            <surname>Kharchenko</surname>
          </string-name>
          ,
          <article-title>Big Data and Internet of Things for Safety Critical Applications: Challenges, Methodology</article-title>
          and Industrial Cases,
          <source>International Journal on Information Technologies and Security</source>
          <volume>4</volume>
          (
          <year>2018</year>
          )
          <fpage>3</fpage>
          -
          <lpage>16</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          [7]
          <issue>NUREG7007</issue>
          :
          <year>2009</year>
          .
          <article-title>Diversity Strategy for Nuclear Power Plant Instrumentation and Control Systems</article-title>
          . URL: https://www.nrc.gov/docs/ML1005/ML100541256.pdf
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          [8]
          <string-name>
            <given-names>V.</given-names>
            <surname>Kharchenko</surname>
          </string-name>
          ,
          <article-title>Diversity for Safety and Security of Embedded and Cyber Physical Systems: Fundamentals Review and Industrial Cases</article-title>
          ,
          <source>in: Proceedings of 15th Biennial Baltic Electronics Conference</source>
          ,
          <year>2016</year>
          , pp.
          <fpage>21</fpage>
          -
          <lpage>30</lpage>
          .
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>