Hierarchical Safety Cases

  • Ewen Denney
  • Ganesh Pai
  • Iain Whiteside
Part of the Lecture Notes in Computer Science book series (LNCS, volume 7871)


The development of a safety case has become common practice for the certification of systems in many safety-critical domains, but large safety cases still remain difficult to develop, evaluate and maintain. We propose hierarchical safety cases (hicases) as a technique to overcome some of the difficulties that arise in manipulating industrial-size safety arguments. This paper introduces and motivates hicases, lays their formal foundations and relates them to other safety case concepts. Our approach extends the existing Goal Structuring Notation (GSN) with abstraction mechanisms that allow viewing the safety case at different levels of detail.


Abstraction Automation Formal methods Hierarchy Safety assurance Safety cases 


Unable to display preview. Download preview PDF.

Unable to display preview. Download preview PDF.


  1. 1.
    Bloomfield, R., Bishop, P.: Safety and Assurance Cases: Past, Present and Possible Future – An Adelard Perspective. In: Proc. 18th Safety-Critical Sys. Symp. (February 2010)Google Scholar
  2. 2.
    Denney, E., Habli, I., Pai, G.: Perspectives on Software Safety Case Development for Unmanned Aircraft. In: Proc. 42nd Intl. Conf. Dependable Sys. and Networks (June 2012)Google Scholar
  3. 3.
    Denney, E., Pai, G.: A lightweight methodology for safety case assembly. In: Ortmeier, F., Daniel, P. (eds.) SAFECOMP 2012. LNCS, vol. 7612, pp. 1–12. Springer, Heidelberg (2012)Google Scholar
  4. 4.
    Denney, E., Pai, G., Pohl, J.: Automating the generation of heterogeneous aviation safety cases. Tech. Rep. NASA/CR-2011-215983, NASA Ames Research Center (August 2011)Google Scholar
  5. 5.
    Denney, E., Pai, G., Pohl, J.: AdvoCATE: An Assurance Case Automation Toolset. In: Ortmeier, F., Daniel, P. (eds.) SAFECOMP 2012 Workshops. LNCS, vol. 7613, pp. 8–21. Springer, Heidelberg (2012)CrossRefGoogle Scholar
  6. 6.
    Denney, E., Pai, G., Pohl, J.: Heterogeneous aviation safety cases: Integrating the formal and the non-formal. In: 17th IEEE Intl. Conf. Eng. of Complex Comp. Sys. (July 2012)Google Scholar
  7. 7.
    Denney, E., Power, J., Tourlas, K.: Hiproofs: A hierarchical notion of proof tree. Electr. Notes on Theoretical Comp. Sci. 155, 341–359 (2006)CrossRefGoogle Scholar
  8. 8.
    Denney, E., Whiteside, I.: Hierarchical safety cases. Tech. Rep. NASA/TM-2012-216481, NASA Ames Research Center (December 2012)Google Scholar
  9. 9.
    European Organisation for the Safety of Air Navigation: Preliminary safety case for ADS-B airport surface surveillance application. PSC ADS-B-APT (November 2011)Google Scholar
  10. 10.
    Goal Structuring Notation Working Group: GSN Community Standard v.1 (November 2011),
  11. 11.
    Stone, G.: On arguing the safety of large systems. In: 10th Australian Workshop on Safety-Related Programmable Sys. ACM Intl. Conf. Proc. Series, vol. 162, pp. 69–75 (2006)Google Scholar

Copyright information

© Springer-Verlag Berlin Heidelberg 2013

Authors and Affiliations

  • Ewen Denney
    • 1
  • Ganesh Pai
    • 1
  • Iain Whiteside
    • 2
  1. 1.SGT / NASA Ames Research CenterMoffett FieldUSA
  2. 2.School of InformaticsUniversity of EdinburghEdinburghScotland

Personalised recommendations