OFFICE OF THE DEPUTY ASSISTANT SECRETARY OF DEFENSE SYSTEMS ENGINEERING

OFFICE OF THE DEPUTY ASSISTANT SECRETARY OF DEFENSE SYSTEMS ENGINEERING
复制标题

DOI:
--
复制
发表时间:
2013
期刊:
--
影响因子:
--
通讯作者:
Ms Payuna Uday;K. Marais
Ms Payuna Uday;K. Marais
中科院分区:
其他
文献类型:
--
作者:
Ms Payuna Uday;K. Marais

文献摘要

被引文献

相似文献

系统的系统(SoS)是由独立运行的复杂系统的集成形成的,这些系统相互作用,以提供单个系统无法单独实现的整体能力。因此,从工程和管理的角度来看,设计和操作一个SoS都是具有挑战性的。弹性是一个系统或组织在早期阶段对干扰做出反应并从干扰中恢复的能力,对动态稳定性的影响最小。通常,在大型复杂系统中,冗余特征用于增加系统对扰动的弹性。例如,商业卫星配备了多个备份系统,以限制发生故障时的性能损失。传统的可靠性分析技术,如故障树和事件树,通常用于确定系统设计中要包括的冗余级别和类型。然而,这些方法并不能充分满足一个SoS的弹性需求。考虑到组成系统的异质性和通常广泛的地理分布,为一个SoS包括备份冗余系统是不切实际的和昂贵的。此外,系统之间的高度相互依赖意味着整个SoS中故障级联的风险增加。然而,我们认为,这些障碍提供了通过非常规手段提高总体系统弹性的独特机会。在这里,我们研究了一种方法来补偿一个组成系统的性能损失,通过重新分配剩余的系统。具体而言,当一个实体或SoS中的节点经历性能下降或故障模式时,其他实体可以改变其操作以补偿这种损失。我们称之为“替代冗余”。这就提出了几个有趣的问题,例如:(1)给定一个特定系统的故障,补偿损失的最佳配置是什么?(2)使用新配置可以恢复什么级别的性能?以及(3)替代冗余对开发成本和风险的上游影响是什么?在本文中,我们提出了两个概念来实现SoS中的替代冗余:(1)反应性弹性,和(2)主动弹性。这项研究有助于早期发展规划,架构,建模和仿真的主题。反应式弹性处理故障发生后的性能恢复。在这种情况下,对于一个特定的能力,我们研究了各种节点故障的整体SoS性能的降低,然后确定可以通过重新配置SoS的其余部分来恢复的性能水平。我们提供了一种方法来排名的基础上的性能水平恢复和易于实施的可行的配置。国防系统工程部副助理部长办公室更多信息:http://www.acq.osd.mil/se/outreach/sosecollab.html在研究了总节点故障对总体SoS性能的影响之后,我们扩展了跟踪节点逐渐退化对相同总体性能的影响的方法。随着节点性能随时间的推移而降低,SoS性能的相应降低可能会导致不同配置可能比当前配置更好的情况。这意味着在节点实际故障之前强制转换到不同的SoS配置。我们称之为主动弹性,因为在节点故障发生之前转换到新配置可以提高整个SoS的鲁棒性。Payuna Uday女士是普渡大学航空航天学院的博士生。她的研究重点是研究和设计系统中的弹性。Payuna获得了普渡大学的硕士学位,她的研究涉及评估航空运营变化的环境缓解潜力。她在迪拜完成了学业,拥有B.Tech学位。在印度Trichy的国家技术学院的电子和通信工程专业。卡伦·马雷是普渡大学航空航天学院的助理教授。她的研究兴趣包括安全性,可靠性,风险和复杂的社会技术系统的一般和航空航天和可再生服务系统的经济分析,特别是。此外,Marais博士还在FAA PARTNER卓越中心进行航空对环境影响的研究。
System-of-systems (SoS) are formed from the integration of independently operating complex systems that interact with one another to provide an overall capability which cannot be achieved by the individual systems alone. As a result, designing and operating an SoS is challenging both from an engineering as well as a managerial perspective. Resilience is the ability of a system or organization to react to and recover from disturbances at an early stage with minimal effect on the dynamic stability. Typically, in large complex systems, redundancy features are used to increase the resilience of the system to perturbations. For instance, commercial satellites are fitted with multiple backup systems to limit performance loss in the event of failures. Traditional reliability analysis techniques, such as fault trees and event trees, are typically used to determine the level and types of redundancy to be included in the system design. However, these approaches do not adequately satisfy the resilience needs of an SoS. Given the heterogeneity and, often wide geographic distribution, of the constituent systems, inclusion of backup redundant systems for an SoS is impractical and costly. Additionally, high levels of interdependency between the systems imply increased risks of failures cascading throughout the SoS. However, these hurdles, we argue, offer the unique opportunity to improve the resilience of the overarching system through unconventional means. Here, we study a way to compensate for a loss of performance in one constituent system by re-tasking the remaining systems. Specifically, as one entity, or node in an SoS, experiences degraded performance or a failure mode, other entities can alter their operations to compensate for this loss. We call this “stand-in redundancy”. This raises several interesting questions, such as: (1) given the failure of a specific system, what is the best configuration to compensate for the loss?; (2) what level of performance can be recovered with the new configuration?; and (3) what is the upstream effect of stand-in redundancy on development costs and risks? In this paper, we develop two concepts to implement stand-in redundancy in an SoS: (1) reactive resilience, and (2) proactive resilience. This research contributes to the topics of Early Development Planning, Architecture, and Modeling and Simulation. Reactive resilience deals with performance recovery after a failure has occurred. In this case, for a specific capability, we study the reduction in overall SoS performance given various nodal failures, and then determine the level of performance that can be recovered by reconfiguring the rest of the SoS. We provide a method to rank the feasible configurations based on performance level recovery and ease of implementation. OFFICE OF THE DEPUTY ASSISTANT SECRETARY OF DEFENSE SYSTEMS ENGINEERING For more information: http://www.acq.osd.mil/se/outreach/sosecollab.html Having studied the impact of total nodal failures on overall SoS performance, we expand the method to track the impact of gradual degradation of nodes on the same overall performance. As the nodes degrade over time, the corresponding reduction in SoS performance could result in a situation where a different configuration might fare better than the current one. This implies a forcible transition to a different SoS configuration before actual failure of the node. We call this proactive resilience, as this transition to a new configuration before nodal failure occurs improves the robustness of the overall SoS. Biographies Ms. Payuna Uday is a doctoral student in the School of Aeronautics and Astronautics at Purdue University. Her research is focused on studying and designing resilience in system-of-systems. Payuna received her master's degree from Purdue and her research involved evaluating the environmental mitigation potential of operational changes in aviation.. She completed her schooling in Dubai and holds a B.Tech. in electronics and communication engineering from the National Institute of Technology in Trichy, India. Karen Marais is an Assistant Professor in the School of Aeronautics and Astronautics at Purdue University. Her research interests include safety, reliability, risk and economic analysis of complex sociotechnical systems in general and aerospace and renewable service systems in particular. In addition, Dr. Marais conducts research on the environmental impact of aviation within the FAA PARTNER Center of Excellence.