Showing posts with label Safety Critical Systems. Show all posts
Showing posts with label Safety Critical Systems. Show all posts

Sunday, October 20, 2019

Design of computerized system contributed to the death of ten USN sailors

On 21 August 2017 the US Navy destroyer John S McCain collided with a civilian tanker near Singapore, resulting in the deaths of ten US sailors, and $100M in damage. The US National Transportation Safety Board report found the probable cause of the collision was "... a lack of effective operational oversight of the destroyer by the US Navy ...". However, also contributing to the accident was the computerized steering system: "Also contributing to the accident was the operation of the steering system in backup manual mode, which allowed for an unintentional, unilateral transfer of steering control.". This would be a useful report for students of safety critical systems to study.

John S McCain Bridge Control Station.
Drawing from IBNS technical manual;
color added by NTSB. Figure 4 of
NTSB/MAR-19/01 PB2019-100970.
The destroyer was equipped with bridge control stations with flat-panel touch screens, and a graphical user interface (GUI), in additional to a conventional steering wheel. The stations had an "emergency override to manual" function activated by what the crew referred to as the "big red button". This was intended to provide manual control in the event of a computer malfunction, and the designers no doubt thought it was foolproof: press the red button and steer the ship with the wheel.

However, as the NTSB detailed, the crew unintentionally
transferred control of steering from one station to another, but interpreted this as a failure of steering. This confusion may have been because the crew were uncomfortable with the automated mode of the system, and preferred to use the backup manual mode. However the backup mode was not intended for normal use, and allowed the control to be transferred without the operator noticing.

The  NTSB recommended crew being instructed to only operate the system in manual mode during an emergency. However, the underlying problem appears to be that the crew did not trust the automated system. This would require training the crew so they felt they could rely on the system, or to redesign the system to provide more intuitive feedback. Part of the intuitive feedback, I suggest, could be via manual controls.

The Bridge Control Stations have a ship's wheel, but this is an input only device, and there are no physical engine throttles, just a GUI display. One way aircraft cockpit interfaces display the operation of the autopilot is by physically moving the throttle levers. Similarly, in aircraft with a control yoke  the control moves in response to auto-pilot commands, and also provides tactile and visual feedback of the control responses put in by the co-pilot. The autopilot can be overridden simply by moving the yoke. If implemented on the ships bridge control, this would provide intuitive feedback as to who is in control, and an intuitive way to take control. The operator would be able to see, and feel, inputs through the wheel and throttles. If they wanted to override the automated system, or another operator, they just need to move the controls.

Some modern aircraft lack the visual and tactile feedback in controls, particularly those using side-stick controllers, rather than a yoke. However, in aircraft pilots receive intensive training in the use of these systems, and are sitting close to each other in the cockpit, so are usually able to see and hear what each other are doing. Even so, conflicting inputs have lead to aircraft accidents.  On a ship the operators are much further apart, which makes coordination much more difficult.

Reference


Collision between US Navy Destroyer John S McCain and Tanker Alnic MC Singapore Strait, 5 Miles Northeast of Horsburgh Lighthouse
August 21, 2017, Marine Accident Report, National Transportation
Safety Board, NTSB/MAR-19/01 PB2019-100970, Notation 58325
Adopted June 19, 2019 URL https://assets.documentcloud.org/documents/6243999/MAR1901.pdf

Tuesday, August 20, 2019

Memoir from Programmer of the Apollo 11 Lunar Module

The book "Sunburst and Luminary: An Apollo Memoir" by
Don Eyles relates his experience programming the computer on the Apollo Lunar Module. This is a relatively modest first person recounting of someone who fell into computer programming, and ended up on the Apollo program as their first assignment. It would be useful for students who have ambitions of a career in computing to read.
"In 1966 the author, newly graduated from college, went to work for the MIT laboratory where the Apollo guidance system was designed. His assignment was to program the complex lunar landing phase in the Lunar Module's onboard computer. As Apollo 11 approaches, the author flies lunar landings in simulators and meets the astronauts who will fly the LM for real. He explains the computer alarms that almost prevented Neil Armstrong from landing and describes a narrow escape from another dangerous problem. On Apollo 14 he devises a workaround when a faulty pushbutton threatens Alan Shepard's mission, earning a NASA award, a story in Rolling Stone, and a few lines in the history books.  This memoir is a new kind of book about Apollo. It tells a story never told before by an insider the development of the onboard software for the Apollo spacecraft. It makes a vertical connection between technical details and historic events, but by broadening the story using his own experiences as he grows into adulthood in the 1960s the author draws a parallel between that era of successful space exploration, and the exploration, inner and outer, that was taking place in the culture."

ps: I read the copy in Libraries ACT.

Monday, October 26, 2015

Design Flaw in Queensland OneSchool Student Protection Module

The Deloitte report "Queensland Department of Education and Training: OneSchool – Investigation into the 2015 failure of the OneSchool Student Protection Module" (16 October 2015) provides an excellent analysis of the response to a serious fault in a contemporary software system. However, there appears to be a fundamental flaw in the design of the OneSchool system which is not addressed by the report and remains in the system. Queensland school children remain at risk as a result.

The OneSchool SPM is designed to allow teachers to report possible child abuse to the relevant authorities. A fault in the software resulted in 644 reports not being forwarded to the police. Deloitte were commissioned by the Queensland Minister for Education to "to assist the Department of Education and Training (DET) with a review of the Student Protection Reporting Module in OneSchool". Deloitte have provided a good description of the problem, how it was found and fixed and also a reconciliation to verify that all reports are now accounted for. However, this will not be sufficient to prevent a similar problem occurring in the future.

The OneSchool "submission protection" function (shown in Figure 4.2 page 18 of the Deloitte report), shows a purely one way process. The system sends email, to Department of Communities, Child Safety and Disability Services (DCCSDS), or the Queensland Police Service (QPS). There is no provision for the system to verify the report was received. Therefore a similar problem could occur again, in the OneSchool system, in the email system, or in the systems of the DCCSDS or QPS and it would remain undetected.

The OneSchool system needs to be modified so that there is positive acknowledgment of the receipt of every report by the agencies it was sent to. As it involves child safety, OneSchool is a "Safety Critical System", but does not appear to have been designed to the required standard.

Sunday, December 22, 2013

Mango Trees Hazard on Queensland Railway

The Australian Transport Safety Bureau (ATSB) issued its final report on "Collision of passenger trainT842 with station platform, Cleveland,Queensland, 31 January 2013", 20 December 2013. The ATSB found the train wheels slipped due to contamination from nearby trees. "Slippery rail" is a well known in the railway industry. While the cause is usually due to leaves on the track, it can be remarkably hard to predict or combat. As part of the investigation ATSB found there were trees next to, or overhanging the railway line at the top 10 locations where trains had overrun station platforms. One aspect not covered in the report is if the type of vegetation effects rail slip.

The most instances on the Brisbane rail network of station overrun occurred at Lindum railway station. Figure 19 on page 31 of the report shows an overhead shot of the station, pointing to trees nearby. I attended school nearby and recognise the grove of Mango trees in the photo. These trees have a much more dense foliage than native eucalyptus and drop sticky sap filled leaves and twigs as well as fruit. I have suggested to the ATSB that perhaps this causes more wheel slip that other vegetation.

Friday, January 18, 2013

787 Battery Fire

burned auxiliary power unit battery from a Boeing 787
The US National Transportation Safety Board have issued photographs of the burned auxiliary power unit battery from a JAL Boeing 787 (14 January 2013). The lithium-ion cells are barely recognizable due to the fire. The battery weighs 63 US pounds, so there is a serious risk to an aircraft from fire.

Sunday, September 30, 2012

Australia's greatest inventions

The new book "Australia's greatest inventions and innovations" by Christopher Cheng and Linsay Knight (Powerhouse Museum, 2012) is written in language suitable for children but will be of interest to adults as well. In addition to the familiar stories of the Hills Rotary Hoist, there are some less familiar, such:
  1. CSIRO's invention of WiFi: Few Australian realise that the technology in their wireless gadgets was invented in Australia by the Australian Government's research lab.
  2. Integrated Communications Cap Lamp (ICCL): The ICCL is a belt worn battery pack to power the helmet light of miners. By using a compact and lightweight Lithium-Ion battery, the designers made room for extra communications and safety equipment on the same unit, such as an RFID tag, a radio, or a PED Text Pager. The PED Pager uses radio frequencies which penetrate rock and allow emergency messages to be sent to miners.
Unfortunately the book is not without problems. As an example, the entry on the PED pager refers to low frequency sound waves being used, when the device actually uses radio waves.

There is also a useful Wikipedia entry "List of Australian inventions".

Tuesday, May 15, 2012

Human Error in the Health System

Greetings from the Australian National University in Canberra, where former Royal Australian Air Force test pilot, Robyn Clay-Williams (UNSW Centre for Clinical Governance Research in Health) is peaking on "Human Error in Complex Systems". Robyn asserted that error is part of human behavior which has to be managed, not just an aberration. Using the "Invisible Gorilla Test", she demonstrated the effects of situational awareness (or its opposite "Inattentional blindness"). When an individual concentrates on part of a task they have a loss of awareness of other aspects. In the "Invisible Gorilla Test" subjects are asked to concentrate on one team in a video of a basketball game. About 25% of subjects then fail to notice a person dressed in a gorilla suit walk into the middle of the game, stop, wave to the audience and walk off. Analogously airline pilots who concentrate on an instrument malfunction can fly into the ground due to inattention, as happened with Eastern Air Lines Flight 401. Flight crews are now trained to allocate tasks so that one will keep the plane flying, while another tries to solve the instrument problem. Also the air crew are trained to say aloud what they are doing with standard terminology and for junior staff to question the actions of their superiors.

One lesson research is that auditory attention lessons when staff are concentrating on one problem. This is an issue in hospitals where a large variety of audio warnings; these can tend to be ignored. I wonder if medical personnel should have the equivalent of the stick shaker in an aircraft, which physically vibrates the controls in the pilot's hands. The vibrator in a smart phone could be used to alert medical staff to urgent matters.

One of the lessons from air accident investigation is that most accidents occur from honest hardworking people making a mistake. Simply finding someone to blame does not reduce the accidents in the future. Instead the accident needs to be looked at from the point of view of the team of people involved and what they perceive.

It occurs to me one example of what not to do are the recent royal commissions into Australian bush-fires.

Robyn pointed out that if there are pressures on staff they will tend to work outside the normal safe operating environment, this can result in very unsafe practices creeping into common use.

It occurs to me that it should be possible to monitor the delivery of health care in hospitals every easily. Hospitals keep detailed records which are now computerized. It should be possible to monitor the actions of the staff and the outcomes automatically across all hospitals in Australia. Something like this is already done with GPs, through automated examination of Medicare claims.

At discussion time we got on to the different philosophies of aircraft control between Boeing and Airbus: Boeing gives ultimate control of the aircraft to the pilot, whereas Airbus has computer controlled limits which the pilot cannot override. A local example is the room at ANU used for the talk, which has a bright yellow power switch installed at the instance of the computer scientists, whereas other rooms have the computer system in complete control of room functions.

One well know aircraft problem

F-22 Raptor fifth generation stealth fighter aircraft
While attempting its first overseas deployment to the Kadena Air Base in Okinawa, Japan, on February 11, 2007, a group of six Raptors flying from Hickam AFB experienced multiple computer crashes coincident with their crossing of the 180th meridian of longitude (the International Date Line). The computer failures included at least navigation (completely lost) and communication. The planes were able to return to Hawaii by following their tankers in good weather. The error was fixed within 48 hours and the F-22s continued their journey to Kadena. ...
From: F-22 Raptor, Wikipedia, 10 March 2007
Robyn recommended, The Human Contribution, Safety and Ethics in Healthcare: A Guide to Getting It Right, Patient Safety: A Human Factors Approach.

Tuesday, May 08, 2012

Human Error in Complex Systems

Former Royal Australian Air Force test pilot, Robyn Clay-Williams, from the UNSW Centre for Clinical Governance Research in Health, will speak on "Human Error in Complex Systems" at the Australian National University in Canberra, 3pm 15 May 2012. This is a free talk with no need to book:

Human Error in Complex Systems

Robyn Clay-Williams (Centre for Clinical Governance Research in Health, UNSW)

COMPUTER SCIENCE SEMINAR

DATE: 2012-05-15
TIME: 15:00:00 - 16:00:00
LOCATION: Seminar Room (N101), CSIT Building (Building 108, North Road)
CONTACT: Malcolm.Newey@anu.edu.au

ABSTRACT:
One of the by-products of conducting normal human operations in complex systems is error. Colloquially, error has been acknowledged as an inherent part of the human condition since Cicero (106-43BC) declared "to err is human". It was not until the Second World War, when accidents occurred on a large enough scale to impact on performance, however, that error became linked to safety. With the introduction of computer-based information technology in the 1960s, systems became larger, increasingly centralised and more complex. As human ability to manage these systems started to become a limitation, accidents became a more common occurrence. Interdependency of system elements and fast system response may cause a seemingly innocuous error to develop into a catastrophic accident before a solution can be found. Well known examples include nuclear accidents at Three Mille Island, USA (1979) and Chernobyl, USSR (1986), and the space shuttle Challenger (1986) and Columbia (2003) accidents.

Despite a large body of literature on error modelling and categorisation, little progress has been made on elimination of errors. Research has found that errors can be statistically predicted, but not with sufficient precision for prevention. The best we can do is to explore ways to minimise or mitigate the undesirable consequences of error. Current research efforts concentrate on engineering and design, psychology and human factors, or a combination of both.

Through discussion of accidents in aviation and health care, the presentation will explore how the ways that humans behave, both as individuals and in groups, can contribute to error. Some of the methods currently used by industry to prevent human error will also be introduced, with examples from aviation and health care.


BIO:
Robyn Clay-Williams has a 24 year background in the Royal Australian Air Force, where she worked as an engineer, test pilot, flight instructor and aviation team skills instructor. She was the operational advisory member on the Australian Defence Force board that introduced contemporary 5th Generation Crew Resource Management teamwork training into military aviation. Her PhD investigated the efficacy of aviation-style Crew Resource Management (CRM) training in improving public health safety, by evaluating attitude and behavioural changes in multi-disciplinary teams resulting from implementation of a CRM intervention in the Australian health care field.

Robyn's postdoctoral fellowship is in the field of human factors in health care. Specific areas of interest include teams and teamwork, decision making, and usability test and evaluation of medical devices and IT systems.

Monday, July 25, 2011

Air Crash Investigation Lab Tour

As part of Engineering Week, the Australian Transport Safety Bureau (ATSB) is providing a free tour of its “Air Crash Investigation Laboratory” in Canberra, on 1 Aug 2011:
The Australian Transport Safety Bureau (ATSB), in the spirit of Engineering Week 2011, extends an open invitation to interested members of the community, to visit its Canberra technical facilities.

This is an opportunity for a glimpse behind the scenes of Australia’s premiere transport safety investigation agency. In these limited-numbers sessions, experienced investigators will give you an insight into contemporary no-blame investigation methods and the application of advanced forensic engineering techniques. The ATSB maintains several advanced engineering laboratories dedicated to the recovery of evidence from accident wreckage, engineered systems and the ever-important ‘black box’ flight recorders. ...

Thursday, August 19, 2010

Australian Wireless Broadband Blueprint

NBN Co have released white papers on their proposed fibre, wireless and satellite products. The "Product Overview Wireless Access Services" (August 2010) I found to be of most interest. This describes a fourth generation wireless data service seamlessly integrated into NBN's network.

The 25 page PDF document is 905 kbytes. Most of the 905 kbytes is due to a photo on the cover: I guess if you a building a broadband network, you can afford to waste bandwidth. ;-)

The wireless overview is written from an unusual perspective, being a description of the features provided by a non-existent service. The idea seems to be that NBN is looking for suppliers (most likely of WiMax ) for the service they have envisaged.

What NBN has described looks feasible and a desirable product, if it can be provided at a reasonable price and at a level of reliability similar to that of the existing wired telephone service. Those companies who invested in spectrum for wireless broadband, such as Seven Network's Wireless Broadband Australia (WBA), might now see some return on their investment, by selling the spectrum to NBN. This would allow the Seven Network to concentrate on selling spare parts for tractors out of a shipping container.


However, if NBN can provide an affordable and reliable wireless service, it might make their fibre offering unattractive for the average consumer. It is likely that the average home owner will be using a wireless link for the last 10m from the NBN's termination point in their home to their IT equipment. So the home-owner is unlikely to see much difference in the service between a fibre option connection and a wireless one.

Saturday, March 07, 2009

Accident Report Finds Problems with Airbus Software

The Australian Transport Safety Bureau has released an interim report into the accident involving a Qantas Airbus A330-303 off Learmonth Western Australia on 7 October 2008 ("In-flight upset, VH-QPA, Airbus A330-303, 154 km west of Learmonth, Western Australia", AO-2008-070, ATSB, 7 October 2008 "). It appears spikes in sensor data caused the aircraft's flight control computers to make the plane pitch-down violently, seriously injuring 12 people on board. This is an interim report, but will make interesting reading for those working and teaching safety critical software. The crew was unable to read some of the error message displays in the cockpit, as so many messages were generated they scrolled off the screen. The software of the flight computers is being changed to filter out spikes better. The cause of the spikes is still unknown. But other similar incidents have occurred in the same area of Western Australia and possible interference from the Harold E. Holt Naval Communication Station is being investigated.

Wednesday, October 15, 2008

Qantas Airbus Accident Caused by Computer Fault

The Australian Transport Safety Bureau in "Qantas Airbus A330 accident Media Conference" has reported that the aircraft's computers causing the aircraft to pitch down violently, injuring passengers on 7 October 2008. While the accident appears due to a faulty a Air Data Inertial Reference Unit feeding incorrect data to the computers, perhaps the computers should have been programmed to detect and reject the erronious data.
... The ATSB has scheduled the media conference this evening to coincide with the release of an Operators Information Telex/Flight Operations Telex, which is being sent by Airbus to operators of all Airbus aircraft. The aim of that telex is to:
  • update operators on the factors identified to date that led to the accident involving QF72,
  • provide operational recommendations to mitigate risk in the event of a reoccurrence of the situation which occurred on QF72.

... The aircraft was flying at FL 370 or 37, 000 feet with Autopilot and Auto-thrust system engaged, when an Inertial Reference System fault occurred within the Number-1 Air Data Inertial Reference Unit (ADIRU 1), which resulted in the Autopilot automatically disconnecting. ...

The faulty Air Data Inertial Reference Unit continued to feed erroneous and spike values for various aircraft parameters to the aircrafts Flight Control Primary Computers which led to several consequences including:

  • false stall and overspeed warnings
  • loss of attitude information on the Captain's Primary Flight Display
  • several Electronic Centralised Aircraft Monitoring system warnings.

About 2 minutes after the initial fault, ADIRU 1 generated very high, random and incorrect values for the aircrafts angle of attack.

These very high, random and incorrect values of the angle attack led to:

  • the flight control computers commanding a nose-down aircraft movement, which resulted in the aircraft pitching down to a maximum of about 8.5 degrees,
  • the triggering of a Flight Control Primary Computer pitch fault.

The crew's timely response led to the recovery of the aircraft trajectory within seconds. During the recovery the maximum altitude loss was 650 ft.

The Digital Flight Data Recorder data show that ADIRU 1 continued to generate random spikes and a second nose-down aircraft movement was encountered later on, but with less significant values in terms of aircraft's trajectory.

At this stage of the investigation, the analysis of available data indicates that the ADIRU 1 abnormal behaviour is likely as the origin of the event. ...

Related Documents: | Audio file of media conference, 14 October 2008 (18 MB)


From: "Qantas Airbus A330 accident Media Conference", Media Release, Australian Transport Safety Bureau, 2008/43, 14 October 2008

Sunday, August 31, 2008

Investigation Reports Needed into Major Public Incidents

The Australian Transport Safety Bureau (ATSB) released a final report on the grounding of the ship Pasha Bulker at Newcastle on 8 June 2007. This is a clearly written technical report into what happened and what to do to stop it happening again. Fortunately there was no loss of life. Perhaps similar independent reports should be prepared where there is any major incident which risks public safety, or large financial loss.

Bodies, such as the coroner's court only have jurisdiction where there is an actual death. Also physical injury may only play a small part in many incidents which could have a large and detrimental impact on the public. At present it is necessary to rely on an uncoordinated array of overlapping investigative agencies and ad-hoc inquiries. Major incidents may require a special public inquiry, but a government may be reluctant to launch an inquiry which may find them at fault. Something like a more general version of the ATSB, can carry out an independent investigation, would be useful.

ps: Perhaps some time could be saved by calling the public inquiry into the Sydney Nort West Metro Project now. This project is quite clearly a disaster in the making. ;-)

Marine Safety Investigation Report - Final

Independent investigation into the grounding of the Panamanian registered bulk carrier Pasha Bulker on Nobbys Beach, Newcastle, New South Wales on 8 June 2007


Occurrence Details
Occurrence Number: 243 Location: Nobbys Beach, Newcastle
Occurrence Date: 08 June 2007 State: NSW
Occurrence Time: 0951 (UTC +10) Highest Injury Level: None
Occurrence Category: Incident Investigation Type: Occurrence Investigation
Occurrence Class:
Investigation Status: Completed
Occurrence Type: Grounding Release Date: 23 May 2008

Vessel Details
Vessel:Pasha BulkerFlag:Panam
IMO:9317729
Type of Operation:Bulk carrier
Damage to Vessel:Substantial
Departure Point:Newcastle anchorageDeparture Time:0748 local time
Destination:To sea

On 23 May 2007, the Panamanian registered bulk carrier Pasha Bulker anchored 2.4 miles off the coast near Newcastle, New South Wales. The ship had sufficient water ballast on board for the good weather at the time, and was not expected to load its coal cargo for about three weeks.

At midday on 7 June, Pasha Bulker's master veered more anchor cable after a gale warning was issued. The weather deteriorated and shortly after midnight, the wind had reached gale force.

At 0500 on 8 June, the wind had increased to strong gale force and the weather was severe. At 0625, Pasha Bulker started to drag its anchor. The master decided to put to sea and at 0748, the anchor was aweigh. The ship was now 1.2 miles from the shore and, with the southeast wind fine on the starboard bow, it made good a north-easterly course. At 0906, the master altered the ship’s course to starboard to put the wind on the port bow in an attempt to make good a southerly course on a south-southeasterly heading. However, its heading became south-westerly and, with the wind on the port beam, the ship started to rapidly approach the coast.

At 0931, with Nobbys Beach 0.8 of a mile away, the master attempted a starboard turn. The manoeuvre did not succeed and at 0946, with grounding imminent, he requested assistance from authorities ashore. At 0951, Pasha Bulker grounded on Nobbys Beach and the ship's momentum carried it further onto the beach. The crew were evacuated by helicopter during the afternoon.

On 2 July, Pasha Bulker was successfully refloated. The ship was temporarily repaired in Newcastle and on 26 July, taken in tow to Vietnam to undergo permanent repairs.

The report identifies a number of safety issues and issues recommendations or safety advisory notices to address them.


Download complete report [4.6 MB PDF]

Marine Safety Recommendations

[MR20080009] [MR20080010] [MR20080011] [MR20080012] [MR20080013] [MR20080014] [MR20080015] [MR20080016] [MR20080017] [MR20080018] [MR20080019]

Safety Advisory Notices

[MS20080015] [MS20080016] [MS20080017] [MS20080018]


Related Links: | Media release | Media conference audio file .avi 55 MB |

Thursday, August 28, 2008

Digital Apollo

Digital Apollo: Human and Machine in Spaceflight Digital Apollo: Human and Machine in Spaceflight by David A. Mindell (2008) is a new book covering the technical history of the development of the computer software for the first manned lunar landing. This book would be of value to students of software engineering.

Mindell concentrates on the development of the interface between the computer and the crew, pointing out that there were few precedents for the design. It was not clear if the astronauts should be simply passengers in an automated and remote controlled system, or if they should, or could, pilot the spacecraft like an aeroplane. Previous books have covered the politics of this issue, and Mindell perhaps dwells to much on how this conflicted with the "Right Stuff" macho image of test pilots.
B
ut Mindell provides new technical details of how contemporary systems then worked and how Apollo's approach was developed.

The Apollo systems were developed from ones designed for missiles and designed to be fully automated. This was modified to allow the crew the option to control part of the flight, but via the computer, making an early "fly by wire" system. The techniques and some of the hardware and software, was later adopted for military and then civilian aircraft. The DSKY interface of Apollo will look familiar to operators of civilian airliners and military computers, with a panel of indicator lights, small alphanumeric display and a keypad underneath. The Apollo side stick controllers, with multiple operating modes are the predecessors of military aircraft and Airbus airliner controls.

The early plans for Apollo did not take into account the difficulty of developing software and it was seen as just an adjunct to the hardware development. The software process became a bottleneck in the program, partly due to the success of the digital computer in replacing analogue hardware and so becoming central to the success of the project. This is a lesson military projects routinely fail to learn, with software development being seen as just something you do after the important part of building the hardware. The Australian Seasprite is one recent example of such a failure and the problem is increasing in government and corporate systems.

One of the useful lessons in the book for software engineers is how you end up doing some of the overall project planning for your clients. In the case of Apollo, there were no clear plans as to how the mission was to be structured. The software developers had to make up a structure for their work and this was adopted for the mission overall.

Mindell argues that many of the techniques for the systematic development and testing of software were either developed for, or refined with Apollo. One aspect not touched on was that how with the later Space Shuttle program the software engineering techniques had reached a point where they were superior to those for the hardware. In his comments on the Rogers Commission into the Challenger disaster, Richard Feynman praised the systematic development of the shuttle's software and criticised the processes for hardware.

It will be a startling less for modern students to see photos of little old ladies literally weaving the binary programs into magnetic core memories for Apollo. ;-)

Thursday, July 17, 2008

Improved Air Traffic Control with Cooperative Surveillance Techniques

Stephan Schulz from Comsoft GmbH, Germany, will talk about Air Traffic Control, 2008-08-06 at NICTA in Canberra:

NICTA LC SEMINAR

Improved Air Traffic Control with Cooperative Surveillance Techniques

Stephan Schulz (Comsoft GmbH)

DATE: 2008-08-06
TIME: 16:00:00 - 17:00:00
LOCATION: NICTA - 7 London Circuit

ABSTRACT:
Aircraft in controlled airspace are flying under the direction of air traffic controllers, which are responsible for safe, orderly, and expeditious traffic flow. In particular, maintaining proper aircraft separation is not left to individual pilots, but subject to air traffic control.

To support controllers in their task, surveillance systems are used to provide an air situation picture. The quality of the air situation picture determines both the workload of the controller and the safe separation limits of aircraft, and hence significantly influences the safe capacity of the air space. Most of todays surveillance systems are based on rotating antenna radars. However, radars are expensive to build and operate. They have a relatively low update rate and limited scalability.

New surveillance techniques rely on cooperative aircraft to overcome this disadvantage. Multilateration systems use a scalable array of small, low-cost sensors to determine aircraft position and parameters from the time difference of arrival of aircraft transponder signals. They achieve high accuracy, can provide updates several times per second, and provide secondary information about the aircraft based on the content of the received messages.

An even more radical departure from classical radar is Automated Dependent Surveillance - Broadcast. With ADS-B, the aircraft determines its own position using a global navigation satellite system. It broadcasts this position and auxiliary information, typically several times per second. The signal can be received by a low-cost ADS-B ground station with a simple omni-directional antenna. Thus, a small, passive sensor can provide a high-quality air situation picture.

BIO:
Stephan Schulz studied computer science and physics at the University of Kaiserslautern and graduated (Dipl. Inform.) in 1995. In the same year he joined the Automated Reasoning Group at the Technical University Munich. In 2000 he obtained a Ph.D. in computer science for his work on learning search control strategies for first-order deduction. He has contributed to the development of several high-performance deduction systems. Dr. Schulz is best known for developing E, one of the most friendly theorem provers for first-order equational logic. He taught at TU Munich, the University of Miami, and the University of the West Indies.

In 2005 he joined Comsoft GmbH, a German provider of solutions in he field of air traffic control, where he now is responsible for research and development of future surveillance technologies.

Monday, July 07, 2008

Vodafone software problems risk public safety

Vodafone changed to a new billing system in 2007 and there appear to be ongoing problems with the system. When I was unable to see any of the 2008 billing details for my Vodafone mobile phone, with their online system, I complained to the Telecommunications Ombudsman.

Vodafone then promptly contacted me and arranged to send paper copies of the missing bills and call details (which they did). Also they refunded some items on the bill which I queried.

However, the Vodafone online system is still not working properly. I can see my latest bill, but If I attempt to look at Account Summary or Call Details I get: "An error has occurred. Sorry for the inconvenience - There has been a communication problem and your request has not been processed. Please try again later.".

This appears to be a systemic problem, not within the Telecommunication Ombudsman's power to address. Vodafone could simply respond to each complaint by sending a paper copy and offering a partial refund, without fixing the system.

If there is a problem with Vodafone's billing system, there is a risk of financial fraud from misuse of the system. If the problems extend to the telecommunications system Vodafone provides, the safety of the public is at risk. As Vodafone's system is interconnected nationally and internationally, it places the entire telecommunications system at risk of fraud, crime and terrorism.

The ACMA needs to check if Vodafone is complying with its license conditions.

A well documented example of how a problem with a poorly maintained Vodafone system has implications for terrorism is detailed in "The Athens Affair" (by Vassilis Prevelakis and Diomidis Spinellis, IEEE Spectrum, July 2007). In this instance more than 100 senior people, who were customers of Vodafone Greece, had their mobile phones bugged due to poor system maintenance. Those bugged included the Prime Minister, the ministers of national defense, foreign affairs and justice, plus senior staff of the ministries of National Defense, Public Order, Merchant Marine, Foreign Affairs, Hellenic Navy general staff and an employee at the United States Embassy.

Hackers attached the Vodafone switches and exploited the system's facility designed for legal phone taps, modifying the system software. The attack was eventually discovered when it interfered with the delivery of text messages. Why the software change was not discovered in routine system maintenance has not been publicly revealed. Investigators were hampered by Vodafone deleting the system logs and by one of the engineers being found dead in an apparent suicide.

13th Australian Conference onSafety Related Programmable Systems

The 13th Australian Conference on Safety Related Programmable Systems is in Canberra, 21-22 August 2008.

13th Australian Conference on
Safety Related Programmable Systems

University House

Australian National University

CANBERRA, 21-22 August 2008

Regulating for Safety – is it enough?

The Australian Safety Critical Systems Association (aSCSa) announces its 13th National Conference on Safety Related Systems. The 2008 conference will be held in Canberra, ACT at University House, (Map), The Australian National University and its theme will be the role of regulation in the development and deployment of safety-related software intensive systems. Apart from specific hazardous industries where some level of regulation exists, the only direct governance for the development and deployment of safety-related software intensive systems is occupational health and safety legislation which is often applied after the fact. Tort (Common) Law could also be considered as an after-the-fact control.

Continuing the very successful format of recent annual conferences, international and local keynote speakers will address this topical issue. The keynote speakers include:

John McDermid Professor of Software Engineering Science at the University of York, UK

Frank McCormick President (Certification Services, Inc., USA) and FAA Consultant DER

Paul Cheeseman Deputy Technical Director, Asset Management, Lloyd’s Register Rail, UK

A “Call for Papers” has been issued. A programme for the conference is expected to be available July 2008 following the notification of acceptances. The two-day conference will commence at 9.00am Thursday 21 August 2008.

To complement the conference a course and a tutorial are offered. Prof John McDermid will present a short course on evidenced-based approaches for safety, commencing 2.00pm Wednesday, 20 August 2008. To register, please complete the registration form: [Editable Form] [Paper-based]

Want more information about the conference?

For questions about the Conference Program, please contact:

Dr Tony Cant (Program Chair)

Trusted Computer Systems Group

Information Network Division

Defence Science and Technology Organisation

PO Box 1500 Edinburgh SA 5111 Australia

Email: tony.cant(a)dsto.defence.gov.au

...

Sunday, July 06, 2008

Australian Government E-Security Framework

The Minister for Broadband, Communications and the Digital Economy announced a Whole-of-Government review of e-security on 3 July 2008. The Attorney-General’s Department, will conduct the review, of both the public and private sectors, by October 2008. The public and industry were invited to contribute. Available are:
  1. E-Security Review web site
  2. Media Release (copy appended)
  3. E-Security Review 2008 Terms of Reference (PDF 19KB)
  4. E-Security Review 2008 Public Discussion Paper (PDF 42KB)
Also giving an idea of the government's current thinking on e-security is the Trusted Information Sharing Network (TISN). This is a forum for those running critical infrastructure on security issues which affect critical infrastructure. This has a Computer Network Vulnerability Assessment Program. Also there is the Attorney-General's Critical Infrastructure Protection Branch.

Joint media release

The Hon Robert McClelland MP
Attorney-General

Senator the Hon Stephen Conroy
Minister for Broadband, Communications and the Digital Economy
Deputy Leader of the Government in the Senate


Whole-of-Government review of e-security

The Attorney-General Robert McClelland and the Minister for Broadband, Communications and the Digital Economy Senator Stephen Conroy today announced a whole-of-government review of e-security.

Australia’s ever-increasing reliance on information and communications technology and the threat of a hostile online environment has prompted the review, which will assist the development of a national framework for securing Australia’s electronic networks.

“New and networked systems increasingly underpin our business and social interactions, but they also provide fertile ground for exploitation by cyber criminals”, Mr McClelland said.

“The e-security review is an opportunity to look at what help the Government can provide to develop a more secure and trusted electronic operating environment for both the public and private sectors. The review will also consider whether Commonwealth programs can be better focused to deal with the ever increasing range of online threats.”

Senator Conroy said that the review of e-security was a vital step towards fostering confidence in using the internet for personal and business activities.

“A secure online environment trusted by the community coupled with the Government’s rollout of the National Broadband Network is critical to our nation’s continued social and economic prosperity,” Senator Conroy said.

A multi-agency team, led by the Attorney-General’s Department, will conduct the review, which will be completed by the end of this year.

The terms of reference for the review are attached. Details of how the public and industry can contribute to this review are available at: www.ag.gov.au/esecurityreview

Date: 3 July 2008

Media Contact:
Adam Sims, Mr McClelland’s office 0419 480 224
Tim Marshall, Senator Conroy’s office 0408 258 457

E-SECURITY REVIEW 2008
TERMS OF REFERENCE

The Attorney-General's Department is to lead a review of the Australian Government’s e‑security policy, programs and capabilities, assisted by other agencies represented on the E‑Security Policy and Coordination Committee. The review will take account of both the threat from electronic intrusions into Australian networks and the threat from complementary attacks on their physical, administrative or personnel security arrangements.

The purpose of the review is to develop a new Australian Government E-Security Framework in order to create a secure and trusted electronic operating environment for both the public and private sectors.

The review will:

  1. develop a new Australian Government policy framework for e-security, covering the span of e-security issues across government, business and the community
  2. examine current programs, arrangements and agency capabilities and capacities that contribute to e-security, including:
    • those being implemented by agencies under the E-Security National Agenda
    • incident response and crisis management arrangements for e-security, including the recommendations from Australia’s participation in Exercise Cyber Storm II, and
    • other relevant information and communications technologies (ICT) initiatives being undertaken by the Commonwealth and by state and territory governments to establish their suitability and effectiveness to achieve the policy objectives of the new Framework.
  3. address emerging e-security issues including:
    • those resulting from technological change, including roll-out of the National Broadband Network, and
    • an increasingly hostile online security environment, which does not respect traditional jurisdictional boundaries
  4. consider opportunities provided by international cooperation, including engagement with similar economies and like-minded governments
  5. bring forward recommendations, prioritised in accordance with an assessment of risk, for consideration by Government to:
    • tailor programs and agency capabilities and capacity to achieve the policy objectives of the new Framework
    • address current and emerging threats, and
    • determine how to measure the success of each approach
  6. principally focus on measures to be effective in the period to mid-2011, but also take into account longer term considerations, and
  7. consult with relevant stakeholders and experts in government, business, academia and the community.

The review is to be completed for Government consideration by October 2008.

An executive committee comprising senior representatives of the Attorney-General’s Department, the Defence Signals Directorate, ASIO, the Department of the Prime Minister and Cabinet, the Department of Broadband, Communications and the Digital Economy, the Australian Federal Police and the Australian Government Information Management Office will provide oversight of the Review.

From: Whole-of-Government review of e-security, Attorney-General and the Minister for Broadband, Communications and the Digital Economy, Australian Government, 3 July 2008

Sunday, April 13, 2008

Photochromic glasses dangerously reduce night vision

A worrying finding from investigation into a UK shipping accident is that photochromic glasses block so much light that they should not be used by ship's lookouts. The report on the loss of the yacht Ouzo and its crew of three, found that the lookout on the ship Pride of Bilbao, which collided with it, was wearing "reactolite" (photochromic or photoctomatic) prescription spectacles. These darken in reaction to ultra violet (UV) in daylight. At night these appear clear, but actually block 20% of the light (ordinary coated lenses only block 0.6% of the light). Perhaps there should be clearer warnings against the use of these lenses for other night activities, such as driving a car, or flying an aircraft.
The seaman lookout on board Pride of Bilbao at the time of the incident was 60 years of age. He had worked on board the vessel for 10 months and had sailed previously on board similar vessels for many years. He was, therefore, an experienced lookout.

He had a valid ENG 1 certificate of health, which includes a requirement for regular eyesight tests.

His eyes had been tested privately in 2005, after which he was prescribed glasses to adjust his slight short-sighted vision. As a consequence, he purchased a pair of reactolite, or photochromic lensed glasses, that he could wear both during the day and at night because they darkened only in reaction to daylight or ultra violet (UV) light.

Following the accident, the MAIB had the lookout’s eyes examined once again and his prescription was found to be still correct. His eyes were also tested for other defects or anomalies that might have affected his vision or night time adaptation, but none were found.

2.5.3 The seaman lookout’s glasses

... The lookout’s photochromic glasses were sent to University College London’s Institute of Ophthalmology to assess whether they might have had an adverse effect upon his night vision.

The glasses were examined and a report was prepared (Annex 1), which concluded that the optical transmission of the lenses was no more than 80% efficient and, taking into account all of the other known factors, was probably less at the time of the accident. This compares to 94.7% and 99.4% optical transmittance of ordinary uncoated and coated lenses, respectively. This was a startling result as the consequences of such a reduction in night vision had not been fully appreciated by opticians and ophthalmologists before the investigation of this accident.

The report also stated that it would be correct to assume that a uniform reduction in brightness due to the optical density of the lenses would decrease the likelihood that a subject would detect the lights of shipping vessels.

It appears, therefore, that the lookout’s glasses would have been a contributory factor when considering why Ouzo’s lights were not seen earlier. However, there are no rules or guidelines concerning the wearing of such glasses on the bridge of a vessel at night.

This incident has raised a serious concern that glasses fitted with photochromic lenses are inappropriate for use by lookouts on the bridge of merchant vessels. It also raises the question of applicability of use by operators in other modes of transport.

The MAIB also requested the Institute of Ophthalmology to test lenses from the major tinted photochromic lens manufacturers to determine whether the concerns raised in the initial report regarding the lookout’s glasses were widespread, and not just applicable to that particular pair or manufacturer (see Annex 2). The report concluded that all of the photochromic lenses tested showed significant reductions in the amount of transmitted light.

However the lenses of the glasses supplied for test by the MAIB were significantly inferior to the other currently commercially available lenses indicating that either manufacturers have improved the performance of their photochromic materials, or that the performance of photochromic glasses is reduced with time. As at least one manufacturer only guarantees the performance of lenses for 2 years, the latter reason may be the most likely.

This is obviously an additional concern regarding photochromic lens glasses, however it is outside the scope of this investigation. ...

From: Report on the investigation of the loss of the sailing yacht Ouzo and her three crew South of the Isle of Wight during the night of 20/21 August 2006, Report No 7/2007, Marine Accident Investigation Branch, United Kingdom, April 2007

Monday, August 27, 2007

Optionally piloted UAVs

In a talk at the Australian Defence Force Academy last year, I mentioned that one option being looked at for future military aircraft was optionally manned (or piloted) or flow with no one on board as a UAVs.

These are civilian or military aircraft modified to be flow without a pilot. This can be useful where sometimes a crew is needed, to fly the aircraft where UAVs are not permitted or where people are needed to do things a computer can't.

At present these are mostly proposals, not real systems. The German built Diamond DA42 civilian twin engine light aircraft, adapted for surveillance., is offered as an "Optional Piloted Surveillance and Reconnaissance System". Further in the future Lockheed Martin has proposed a pilotless F-35 fighter.

Recently Boeing has proposed an optionally manned Gulfstream G550 business jet for the US Navy’s Broad Area Maritime Surveillance (BAMS) project. On a smaller scale, the current crop of very light jets (VLJ), would seem suitable. These have advanced electronic avionics which are adaptable to remote control, carbon fiber construction which can be modified for sensors and are intended to be produced in large numbers at low cost (starting at $1M). Most have two engines, but units such as the Eclipse ECJ have a single engine.