In verifying a safety-critical system, one usually begins by building a model of the basic system and of its safety mechanisms. If the basic system model does not reflect reality, the verification results are misleading. We show how a model of a system can be compared with the system’s fault trees to help validate the failure behaviour of the model. To do this, the meaning of fault trees are formalised in temporal logic and a consistency relation between models and fault trees is defined. An important practical feature of the technique is that it allows models and fault trees to be compared even if some events in the fault tree are not found in the system model.
Keywords
- System Fault
- Temporal Logic
- Fault Tree
- Atomic Proposition
- Component Failure
These keywords were added by machine and not by the authors. This process is experimental and the keywords may be updated as the learning algorithm improves.