1
November 2018Copyright 2014. FAST Functions Allocations Systems Traceability® is a registered trademark of Marcus Punch Pty. Ltd.
Presented by
Marcus Punch
RPEng, FSExpert (TÜV Rheinland),
ProfCert(Cybersecurity)
Marcus Punch Pty. Ltd.
Risk and Reliability
Mobile: +61 (0)432168849
Email: marcus@marcuspunch.com
Web: www.marcuspunch.com
28th Electrical Engineering Safety Seminar
7th and 8th November 2018
Safe and Cybersecure
Autonomous Mining
2
MarcusPunchPty.Ltd.www.marcuspunch.com
RiskandReliability0432168849
Copyright 2018.
This material may be copied or reproduced by the recipient, provided that the markings of Marcus Punch Pty. Ltd. as the source remain in place.
November 2018
Overview
Why automation is happening?
Segregated and non-segregated automation.
A ‘reasonable’ safety process.
Challenges.
Cybersecurity.
Punch’s ‘Golden Rules’ of Automation.
November 2018
3
MarcusPunchPty.Ltd.www.marcuspunch.com
RiskandReliability0432168849
Copyright 2014. FAST Functions Allocations Systems Traceability® is a registered trademark of Marcus Punch Pty. Ltd.
Mining Industry Productivity
“…the general slowdown in productivity growth cannot be attributed to weak investment, 
but is likely to be associated with either a slowdown in the pace of adoption of productivity‐
enhancing technological innovations or less rapid improvement in the efficiency with which 
capital and labour are employed”.
Patrick D’Arcy and Linus Gustafsson, Australia’s Productivity Performance
and Real Incomes, Reserve Bank Bulletin, June Quarter 2012.
November 2018
4
MarcusPunchPty.Ltd.www.marcuspunch.com
RiskandReliability0432168849
Copyright 2014. FAST Functions Allocations Systems Traceability® is a registered trademark of Marcus Punch Pty. Ltd.
12 Disruptive Technologies - McKinsey
1. Mobile internet.
2. Automation of knowledge work (non-routine, requiring judgement).
3. The internet of things (web-connected low-cost sensors).
4. Cloud technology.
5. Advanced robotics.
6. Autonomous and near-autonomous vehicles.
7. Next generation genomics.
8. Energy storage devices.
9. 3D printing.
10. Advanced materials.
11. Advanced oil / gas exploration & recovery.
12. Renewable energy.
McKinsey & Company - Disruptive technologies:
Advances that will transform life, business, and the
global economy, May 2013.
5
MarcusPunchPty.Ltd.www.marcuspunch.com
RiskandReliability0432168849
Copyright 2018.
This material may be copied or reproduced by the recipient, provided that the markings of Marcus Punch Pty. Ltd. as the source remain in place.
November 2018
Automation = Productivity Driver
http://www.theaustralian.com.au/business/powering-
australia/graph/work
6
MarcusPunchPty.Ltd.www.marcuspunch.com
RiskandReliability0432168849
Copyright 2018.
This material may be copied or reproduced by the recipient, provided that the markings of Marcus Punch Pty. Ltd. as the source remain in place.
November 2018
Automation ≠ Remote Control
Autonomous: machine that is
intended to accomplish its task/s
within a set of defined operations
without human intervention or direct
control.
Semi-autonomous: a machine which
requires direct control by a human
operator to complete some tasks,
while having a portion of its operating
cycle not under direct human control.
7
MarcusPunchPty.Ltd.www.marcuspunch.com
RiskandReliability0432168849
Copyright 2018.
This material may be copied or reproduced by the recipient, provided that the markings of Marcus Punch Pty. Ltd. as the source remain in place.
November 2018
Segregated Autonomy
People and autonomous machines are kept separate.
An Access Control System (ACS) is placed around
the autonomous production zone.
Access
Barrier
(physical
and/or
electronic)
8
MarcusPunchPty.Ltd.www.marcuspunch.com
RiskandReliability0432168849
Copyright 2018.
This material may be copied or reproduced by the recipient, provided that the markings of Marcus Punch Pty. Ltd. as the source remain in place.
November 2018
Segregated Autonomy
ACS keeps machines in and people
out.
Attempted exit by machine – machine
automatically de-energised before it exits
the autonomous zone.
Attempted entry by person - machines in
the autonomous zone are automatically
de-energised.
The ACS is controlling the risk.
Design ACS to a “sufficient” level of
reliability and independent of the
autonomous control system.
9
MarcusPunchPty.Ltd.www.marcuspunch.com
RiskandReliability0432168849
Copyright 2018.
This material may be copied or reproduced by the recipient, provided that the markings of Marcus Punch Pty. Ltd. as the source remain in place.
November 2018
Non-Segregated Autonomy
No Access
Barrier !
People, manual and autonomous machines mingle in the
autonomous production zone.
A Proximity Detection / Collision Avoidance System
(PD/CAS) protects all entities.
10
MarcusPunchPty.Ltd.www.marcuspunch.com
RiskandReliability0432168849
Copyright 2018.
This material may be copied or reproduced by the recipient, provided that the markings of Marcus Punch Pty. Ltd. as the source remain in place.
November 2018
Non-Segregated Autonomy
PD/CAS keeps machines and
people separated.
Out-of-control machine -
automatically de-energised before it
reaches another person or
machine.
Person too close to an autonomous
machine - machine automatically
de-energised.
The PD/CAS is controlling the
risk.
Design PD/CAS to an “sufficient”
level of reliability and
independent of the autonomous
control system.
11
MarcusPunchPty.Ltd.www.marcuspunch.com
RiskandReliability0432168849
Copyright 2018.
This material may be copied or reproduced by the recipient, provided that the markings of Marcus Punch Pty. Ltd. as the source remain in place.
November 2018
“Less Safe” Autonomy
PD/CAS or ACS not independent of the
autonomous control system.
PD/CAS or ACS not designed to a “sufficient”
level of reliability (eg. SIL).
PD/CAS or ACS not accurate.
12
MarcusPunchPty.Ltd.www.marcuspunch.com
RiskandReliability0432168849
Copyright 2018.
This material may be copied or reproduced by the recipient, provided that the markings of Marcus Punch Pty. Ltd. as the source remain in place.
November 2018
Examples of “Less Safe” Autonomy
GPS used for autonomous guidance and PD/CAS.
- if GPS provides incorrect or inaccurate positioning, this can
affect both the autonomous guidance and the PD/CAS at the
same time.
Autonomous guidance and safety systems use the
same processor / logic.
- if the processor / logic malfunctions, this can affect both the
autonomous guidance and the PD/CAS or ACS at the same
time.
The automation system will need continuous
optimisation – a non-independent safety system will
need to be re-validated whenever the automation
system is changed = lower availability of automation.
13
MarcusPunchPty.Ltd.www.marcuspunch.com
RiskandReliability0432168849
Copyright 2018.
This material may be copied or reproduced by the recipient, provided that the markings of Marcus Punch Pty. Ltd. as the source remain in place.
November 2018
Safety Process
Automation is not risk elimination.
Automation is risk substitution.
- Some old risks (manual operation) are removed.
- Some new risks (autonomous operation) are
introduced.
Care must be taken to control the new risks, so as
to ensure a net safety benefit.
The solution is to use a risk management approach
 identify “reasonably foreseeable” hazards / risks
 analyse risks (cause, likelihood, degree of harm)
 treat (control) risks
 apply the “hierarchy of controls”
satisfy the “reasonably practicable” test
 apply the “functional safety approach”
(ie. for ACS, PD/CAS of “sufficient” reliability).
 communicate & consult / monitor & review .
ISO17757 Earth-moving Machinery and Mining —
Autonomous and Semi-autonomous Machine
System Safety
14
MarcusPunchPty.Ltd.www.marcuspunch.com
RiskandReliability0432168849
Copyright 2018.
This material may be copied or reproduced by the recipient, provided that the markings of Marcus Punch Pty. Ltd. as the source remain in place.
November 2018
Challenges
1. Bring the people with you. Without the people you will not succeed.
2. Do not do this alone – buy the skills and keep them.
3. Is mixed manual / autonomy really necessary?
4. Automation is “buggy”. Be prepared for continuous optimisation.
Independent safety systems are essential.
5. Cybersecurity.
15
MarcusPunchPty.Ltd.www.marcuspunch.com
RiskandReliability0432168849
Copyright 2018.
This material may be copied or reproduced by the recipient, provided that the markings of Marcus Punch Pty. Ltd. as the source remain in place.
November 2018
Cybersecurity
16
MarcusPunchPty.Ltd.www.marcuspunch.com
RiskandReliability0432168849
Copyright 2018.
This material may be copied or reproduced by the recipient, provided that the markings of Marcus Punch Pty. Ltd. as the source remain in place.
November 2018
AS61508.1 Cybersecurity Trap
17
MarcusPunchPty.Ltd.www.marcuspunch.com
RiskandReliability0432168849
Copyright 2018.
This material may be copied or reproduced by the recipient, provided that the markings of Marcus Punch Pty. Ltd. as the source remain in place.
November 2018
Cybersecurity Management System (CSMS)
18
MarcusPunchPty.Ltd.www.marcuspunch.com
RiskandReliability0432168849
Copyright 2018.
This material may be copied or reproduced by the recipient, provided that the markings of Marcus Punch Pty. Ltd. as the source remain in place.
November 2018
Cybersecurity Risk Assessment
19
MarcusPunchPty.Ltd.www.marcuspunch.com
RiskandReliability0432168849
Copyright 2018.
This material may be copied or reproduced by the recipient, provided that the markings of Marcus Punch Pty. Ltd. as the source remain in place.
November 2018
Cybersecurity Security Levels (SL).
20
MarcusPunchPty.Ltd.www.marcuspunch.com
RiskandReliability0432168849
Copyright 2018.
This material may be copied or reproduced by the recipient, provided that the markings of Marcus Punch Pty. Ltd. as the source remain in place.
November 2018
But…..
21
MarcusPunchPty.Ltd.www.marcuspunch.com
RiskandReliability0432168849
Copyright 2018.
This material may be copied or reproduced by the recipient, provided that the markings of Marcus Punch Pty. Ltd. as the source remain in place.
November 2018
Cybersecurity Management = Know Your Enemies.
Hacking as a Service (HaaS), Malware as a Service (MaaS)
– jobs put out to bid.
Free / Cheap Hacking Software and Advice – eg. Backtrack.
SCADA and Control are now regular topics at ‘DEFCON’
and ‘Blackhat’ conferences.
Vendors publish information about vulnerabilities.
Project BASECAMP – www.digitalbond.com
22
MarcusPunchPty.Ltd.www.marcuspunch.com
RiskandReliability0432168849
Copyright 2018.
This material may be copied or reproduced by the recipient, provided that the markings of Marcus Punch Pty. Ltd. as the source remain in place.
November 2018
Cybersecurity and Functional Safety
23
MarcusPunchPty.Ltd.www.marcuspunch.com
RiskandReliability0432168849
Copyright 2018.
This material may be copied or reproduced by the recipient, provided that the markings of Marcus Punch Pty. Ltd. as the source remain in place.
November 2018
Thank-you
Punch’s Golden Rules for Automation
1. Bring the people with you. Without the people you will
not succeed.
2. Do not do this alone – buy the skills and keep them.
3. Identify reasonably foreseeable risks.
4. Use all reasonably practicable safeguards.
5. Make PD/CAS or ACS independent of automation.
6. Make PD/CAS or ACS of sufficient reliability.(eg. SIL)
7. Know your cyber-enemies and their methods.
8. Continuously optimise.
9. Enjoy the journey – this is supposed to be fun!

EESS 2018 Day 1 - Marcus Punch

  • 1.
    1 November 2018Copyright 2014.FAST Functions Allocations Systems Traceability® is a registered trademark of Marcus Punch Pty. Ltd. Presented by Marcus Punch RPEng, FSExpert (TÜV Rheinland), ProfCert(Cybersecurity) Marcus Punch Pty. Ltd. Risk and Reliability Mobile: +61 (0)432168849 Email: marcus@marcuspunch.com Web: www.marcuspunch.com 28th Electrical Engineering Safety Seminar 7th and 8th November 2018 Safe and Cybersecure Autonomous Mining
  • 2.
    2 MarcusPunchPty.Ltd.www.marcuspunch.com RiskandReliability0432168849 Copyright 2018. This materialmay be copied or reproduced by the recipient, provided that the markings of Marcus Punch Pty. Ltd. as the source remain in place. November 2018 Overview Why automation is happening? Segregated and non-segregated automation. A ‘reasonable’ safety process. Challenges. Cybersecurity. Punch’s ‘Golden Rules’ of Automation.
  • 3.
    November 2018 3 MarcusPunchPty.Ltd.www.marcuspunch.com RiskandReliability0432168849 Copyright 2014.FAST Functions Allocations Systems Traceability® is a registered trademark of Marcus Punch Pty. Ltd. Mining Industry Productivity “…the general slowdown in productivity growth cannot be attributed to weak investment,  but is likely to be associated with either a slowdown in the pace of adoption of productivity‐ enhancing technological innovations or less rapid improvement in the efficiency with which  capital and labour are employed”. Patrick D’Arcy and Linus Gustafsson, Australia’s Productivity Performance and Real Incomes, Reserve Bank Bulletin, June Quarter 2012.
  • 4.
    November 2018 4 MarcusPunchPty.Ltd.www.marcuspunch.com RiskandReliability0432168849 Copyright 2014.FAST Functions Allocations Systems Traceability® is a registered trademark of Marcus Punch Pty. Ltd. 12 Disruptive Technologies - McKinsey 1. Mobile internet. 2. Automation of knowledge work (non-routine, requiring judgement). 3. The internet of things (web-connected low-cost sensors). 4. Cloud technology. 5. Advanced robotics. 6. Autonomous and near-autonomous vehicles. 7. Next generation genomics. 8. Energy storage devices. 9. 3D printing. 10. Advanced materials. 11. Advanced oil / gas exploration & recovery. 12. Renewable energy. McKinsey & Company - Disruptive technologies: Advances that will transform life, business, and the global economy, May 2013.
  • 5.
    5 MarcusPunchPty.Ltd.www.marcuspunch.com RiskandReliability0432168849 Copyright 2018. This materialmay be copied or reproduced by the recipient, provided that the markings of Marcus Punch Pty. Ltd. as the source remain in place. November 2018 Automation = Productivity Driver http://www.theaustralian.com.au/business/powering- australia/graph/work
  • 6.
    6 MarcusPunchPty.Ltd.www.marcuspunch.com RiskandReliability0432168849 Copyright 2018. This materialmay be copied or reproduced by the recipient, provided that the markings of Marcus Punch Pty. Ltd. as the source remain in place. November 2018 Automation ≠ Remote Control Autonomous: machine that is intended to accomplish its task/s within a set of defined operations without human intervention or direct control. Semi-autonomous: a machine which requires direct control by a human operator to complete some tasks, while having a portion of its operating cycle not under direct human control.
  • 7.
    7 MarcusPunchPty.Ltd.www.marcuspunch.com RiskandReliability0432168849 Copyright 2018. This materialmay be copied or reproduced by the recipient, provided that the markings of Marcus Punch Pty. Ltd. as the source remain in place. November 2018 Segregated Autonomy People and autonomous machines are kept separate. An Access Control System (ACS) is placed around the autonomous production zone. Access Barrier (physical and/or electronic)
  • 8.
    8 MarcusPunchPty.Ltd.www.marcuspunch.com RiskandReliability0432168849 Copyright 2018. This materialmay be copied or reproduced by the recipient, provided that the markings of Marcus Punch Pty. Ltd. as the source remain in place. November 2018 Segregated Autonomy ACS keeps machines in and people out. Attempted exit by machine – machine automatically de-energised before it exits the autonomous zone. Attempted entry by person - machines in the autonomous zone are automatically de-energised. The ACS is controlling the risk. Design ACS to a “sufficient” level of reliability and independent of the autonomous control system.
  • 9.
    9 MarcusPunchPty.Ltd.www.marcuspunch.com RiskandReliability0432168849 Copyright 2018. This materialmay be copied or reproduced by the recipient, provided that the markings of Marcus Punch Pty. Ltd. as the source remain in place. November 2018 Non-Segregated Autonomy No Access Barrier ! People, manual and autonomous machines mingle in the autonomous production zone. A Proximity Detection / Collision Avoidance System (PD/CAS) protects all entities.
  • 10.
    10 MarcusPunchPty.Ltd.www.marcuspunch.com RiskandReliability0432168849 Copyright 2018. This materialmay be copied or reproduced by the recipient, provided that the markings of Marcus Punch Pty. Ltd. as the source remain in place. November 2018 Non-Segregated Autonomy PD/CAS keeps machines and people separated. Out-of-control machine - automatically de-energised before it reaches another person or machine. Person too close to an autonomous machine - machine automatically de-energised. The PD/CAS is controlling the risk. Design PD/CAS to an “sufficient” level of reliability and independent of the autonomous control system.
  • 11.
    11 MarcusPunchPty.Ltd.www.marcuspunch.com RiskandReliability0432168849 Copyright 2018. This materialmay be copied or reproduced by the recipient, provided that the markings of Marcus Punch Pty. Ltd. as the source remain in place. November 2018 “Less Safe” Autonomy PD/CAS or ACS not independent of the autonomous control system. PD/CAS or ACS not designed to a “sufficient” level of reliability (eg. SIL). PD/CAS or ACS not accurate.
  • 12.
    12 MarcusPunchPty.Ltd.www.marcuspunch.com RiskandReliability0432168849 Copyright 2018. This materialmay be copied or reproduced by the recipient, provided that the markings of Marcus Punch Pty. Ltd. as the source remain in place. November 2018 Examples of “Less Safe” Autonomy GPS used for autonomous guidance and PD/CAS. - if GPS provides incorrect or inaccurate positioning, this can affect both the autonomous guidance and the PD/CAS at the same time. Autonomous guidance and safety systems use the same processor / logic. - if the processor / logic malfunctions, this can affect both the autonomous guidance and the PD/CAS or ACS at the same time. The automation system will need continuous optimisation – a non-independent safety system will need to be re-validated whenever the automation system is changed = lower availability of automation.
  • 13.
    13 MarcusPunchPty.Ltd.www.marcuspunch.com RiskandReliability0432168849 Copyright 2018. This materialmay be copied or reproduced by the recipient, provided that the markings of Marcus Punch Pty. Ltd. as the source remain in place. November 2018 Safety Process Automation is not risk elimination. Automation is risk substitution. - Some old risks (manual operation) are removed. - Some new risks (autonomous operation) are introduced. Care must be taken to control the new risks, so as to ensure a net safety benefit. The solution is to use a risk management approach  identify “reasonably foreseeable” hazards / risks  analyse risks (cause, likelihood, degree of harm)  treat (control) risks  apply the “hierarchy of controls” satisfy the “reasonably practicable” test  apply the “functional safety approach” (ie. for ACS, PD/CAS of “sufficient” reliability).  communicate & consult / monitor & review . ISO17757 Earth-moving Machinery and Mining — Autonomous and Semi-autonomous Machine System Safety
  • 14.
    14 MarcusPunchPty.Ltd.www.marcuspunch.com RiskandReliability0432168849 Copyright 2018. This materialmay be copied or reproduced by the recipient, provided that the markings of Marcus Punch Pty. Ltd. as the source remain in place. November 2018 Challenges 1. Bring the people with you. Without the people you will not succeed. 2. Do not do this alone – buy the skills and keep them. 3. Is mixed manual / autonomy really necessary? 4. Automation is “buggy”. Be prepared for continuous optimisation. Independent safety systems are essential. 5. Cybersecurity.
  • 15.
    15 MarcusPunchPty.Ltd.www.marcuspunch.com RiskandReliability0432168849 Copyright 2018. This materialmay be copied or reproduced by the recipient, provided that the markings of Marcus Punch Pty. Ltd. as the source remain in place. November 2018 Cybersecurity
  • 16.
    16 MarcusPunchPty.Ltd.www.marcuspunch.com RiskandReliability0432168849 Copyright 2018. This materialmay be copied or reproduced by the recipient, provided that the markings of Marcus Punch Pty. Ltd. as the source remain in place. November 2018 AS61508.1 Cybersecurity Trap
  • 17.
    17 MarcusPunchPty.Ltd.www.marcuspunch.com RiskandReliability0432168849 Copyright 2018. This materialmay be copied or reproduced by the recipient, provided that the markings of Marcus Punch Pty. Ltd. as the source remain in place. November 2018 Cybersecurity Management System (CSMS)
  • 18.
    18 MarcusPunchPty.Ltd.www.marcuspunch.com RiskandReliability0432168849 Copyright 2018. This materialmay be copied or reproduced by the recipient, provided that the markings of Marcus Punch Pty. Ltd. as the source remain in place. November 2018 Cybersecurity Risk Assessment
  • 19.
    19 MarcusPunchPty.Ltd.www.marcuspunch.com RiskandReliability0432168849 Copyright 2018. This materialmay be copied or reproduced by the recipient, provided that the markings of Marcus Punch Pty. Ltd. as the source remain in place. November 2018 Cybersecurity Security Levels (SL).
  • 20.
    20 MarcusPunchPty.Ltd.www.marcuspunch.com RiskandReliability0432168849 Copyright 2018. This materialmay be copied or reproduced by the recipient, provided that the markings of Marcus Punch Pty. Ltd. as the source remain in place. November 2018 But…..
  • 21.
    21 MarcusPunchPty.Ltd.www.marcuspunch.com RiskandReliability0432168849 Copyright 2018. This materialmay be copied or reproduced by the recipient, provided that the markings of Marcus Punch Pty. Ltd. as the source remain in place. November 2018 Cybersecurity Management = Know Your Enemies. Hacking as a Service (HaaS), Malware as a Service (MaaS) – jobs put out to bid. Free / Cheap Hacking Software and Advice – eg. Backtrack. SCADA and Control are now regular topics at ‘DEFCON’ and ‘Blackhat’ conferences. Vendors publish information about vulnerabilities. Project BASECAMP – www.digitalbond.com
  • 22.
    22 MarcusPunchPty.Ltd.www.marcuspunch.com RiskandReliability0432168849 Copyright 2018. This materialmay be copied or reproduced by the recipient, provided that the markings of Marcus Punch Pty. Ltd. as the source remain in place. November 2018 Cybersecurity and Functional Safety
  • 23.
    23 MarcusPunchPty.Ltd.www.marcuspunch.com RiskandReliability0432168849 Copyright 2018. This materialmay be copied or reproduced by the recipient, provided that the markings of Marcus Punch Pty. Ltd. as the source remain in place. November 2018 Thank-you Punch’s Golden Rules for Automation 1. Bring the people with you. Without the people you will not succeed. 2. Do not do this alone – buy the skills and keep them. 3. Identify reasonably foreseeable risks. 4. Use all reasonably practicable safeguards. 5. Make PD/CAS or ACS independent of automation. 6. Make PD/CAS or ACS of sufficient reliability.(eg. SIL) 7. Know your cyber-enemies and their methods. 8. Continuously optimise. 9. Enjoy the journey – this is supposed to be fun!