[论文解读] Model Based System Assurance Using the Structured Assurance Case Metamodel
本文提出一种基于模型的系统保障方法,采用对象管理组织(OMG)发布的结构化保障案例元模型(SACM)标准。该方法通过为现有方法(如目标结构化符号法(GSN)和主张-论据-证据法(CAE))提供符合SACM的元模型,以及双向转换机制,实现了形式化、互操作的保障案例开发,显著提升了安全关键系统在可追溯性、可重用性和工具支持方面的表现。
Assurance cases are used to demonstrate confidence in system properties of interest (e.g. safety and/or security). A number of system assurance approaches are adopted by industries in the safety-critical domain. However, the task of constructing assurance cases remains a manual, trivial and informal process. The Structured Assurance Case Metamodel (SACM) is a standard specified by the Object Management Group (OMG). SACM provides a richer set of features than existing system assurance languages/approaches. SACM provides a foundation for model-based system assurance, which has great potentials in growing technology domains such as Open Adaptive Systems. However, the intended usage of SACM has not been sufficiently explained. In addition, there has been no support to interoperate between existing assurance case (models) and SACM models. In this article, we explain the intended usage of SACM based on our involvement in the OMG specification process of SACM. In addition, to promote a model-based approach, we provide SACM compliant metamodels for existing system assurance approaches (the Goal Structuring Notation and Claims-Arguments-Evidence), and the transformations from these models to SACM. We also briefly discuss the tool support for model-based system assurance which helps practitioners to make the transition from existing system assurance approaches to model-based system assurance using SACM.
研究动机与目标
- 阐明SACM标准在基于模型的系统保障中预期用途。
- 通过符合SACM的元模型,弥合传统保障案例方法(如GSN、CAE)与SACM标准之间的差距。
- 通过正式转换机制,实现现有保障案例模型与SACM兼容模型之间的互操作性。
- 通过工具支持,实现从传统方法到基于模型的保障案例开发的无缝迁移。
- 通过实用、标准化的建模支持,推动SACM在开放自适应系统等新兴领域中的应用。
提出的方法
- 为目标结构化符号法(GSN)和主张-论据-证据法(CAE)设计符合SACM的元模型。
- 定义从GSN和CAE模型到SACM模型的双向转换规则,以确保一致性与可追溯性。
- 利用OMG的SACM标准作为建模保障案例的形式化基础,赋予其机器可处理的语义。
- 将转换机制集成到工具支持中,实现自动化模型转换与验证。
- 通过在典型的安全关键系统保障场景中应用该方法,验证其有效性。
- 提供参考实现与工具栈,支持从业者向基于模型的保障案例开发过渡。
实验结果
研究问题
- RQ1SACM标准在实践中如何有效应用于基于模型的系统保障?
- RQ2将现有保障案例方法(如GSN和CAE)与SACM集成时面临哪些关键挑战?
- RQ3如何实现传统保障案例模型与SACM兼容模型之间的互操作性?
- RQ4在将GSN和CAE转换为SACM时,需要哪些转换机制以保持语义完整性?
- RQ5工具支持如何促进工业环境中基于模型的保障案例开发的采纳?
主要发现
- 作者成功为GSN和CAE开发了符合SACM的元模型,使保障案例能够在SACM框架内实现形式化表达。
- 在GSN/CAE模型与SACM模型之间建立了双向转换,确保了语义一致性和可追溯性。
- 该方法支持自动化工具链,实现模型转换、验证与分析,显著降低了保障案例构建的维护工作量。
- SACM与现有方法的集成,提升了保障案例的可重用性、可维护性与可审计性。
- 该方法支持可扩展、形式化的保障案例开发,尤其在开放自适应系统等复杂领域具有显著优势。
- 本工作为工业界从业者提供了从非正式或非标准化的保障案例实践向标准化、基于模型的方法过渡的实用路径。
更好的研究,从现在开始
从阅读论文到最终审阅,大幅缩短您的研究时间。
无需绑定信用卡
本解读由 AI 生成,并经人工编辑审核。