• <tr id="yyy80"></tr>
  • <sup id="yyy80"></sup>
  • <tfoot id="yyy80"><noscript id="yyy80"></noscript></tfoot>
  • 99热精品在线国产_美女午夜性视频免费_国产精品国产高清国产av_av欧美777_自拍偷自拍亚洲精品老妇_亚洲熟女精品中文字幕_www日本黄色视频网_国产精品野战在线观看 ?

    Hazard Prevention in Mission Plans for Aerial Vehicles Based on Soft Institutions

    2017-09-22 01:58:04FlavioCorreadaSilvaPaulChungMarceloZuffoPetrosPapapanagiotouDavidRobertsonWambertoVasconcelos
    民用飛機設(shè)計與研究 2017年3期

    Flavio S. Correa da Silva, Paul W. H. Chung, Marcelo K. Zuffo, Petros Papapanagiotou, David Robertson, Wamberto Vasconcelos

    (1. University of Sao Paulo, Sao Paulo Brazil; 2. Loughborough University, Loughborough UK;3. University of Edinburgh, Edinburgh UK; 4. University of Aberdeen, Aberdeen UK)

    Hazard Prevention in Mission Plans for Aerial Vehicles Based on Soft Institutions

    Flavio S. Correa da Silva1, Paul W. H. Chung2, Marcelo K. Zuffo1, Petros Papapanagiotou3, David Robertson3, Wamberto Vasconcelos4*

    (1. University of Sao Paulo, Sao Paulo Brazil; 2. Loughborough University, Loughborough UK;3. University of Edinburgh, Edinburgh UK; 4. University of Aberdeen, Aberdeen UK)

    Hazard prevention in mission plans requires careful analysis and appropriate tools to support the design of preventive and/or corrective measures. It is most challenging in systems with large sets of states and complex state relations. In the case of sociotechnical systems, hazard prevention becomes even more dicult given that the behaviour of human centric components can at best be partially predictable. In the present article we focus on a specic class of sociotechnical systems-namely air spaces containing pilot controlled as well as autonomous aircrafts and introduce the notion ofrelevanthazards. We also introducesoftinstitutionsas an appropriate basis for analysis, with the aim of addressing relevant hazards. The concept of soft institutions is drawn from specication languages for interaction between agents in multi-agent systems but, in our case, is adapted for use in systems that combine human and automated actors.

    safety engineering; hazard prevention; sociotechnical systems; soft institutions

    1 Introduction

    Hazard prevention requires the assessment of all possible behaviours of a system so that safety engineers can intervene in the system design to ensure that each behaviour leads to planned, foreseen and safe states[1], providing information support to design preventive and/or corrective measures for each potential hazard.

    Hazard prevention is most challenging in systems with large sets of states and complex state relations, which require careful planning and appropriate tools to generate and analyse potential hazard states, avoiding issues related to undecidability or combinatorial explosion during exhaustive scan of state spaces. In the case of sociotechnical systems, hazard prevention becomes even more difficult given that the behaviour of human centric components can at best be partially predictable.

    The concept of sociotechnical systems was coined in the early 50s to analyse the impact of the introduction of novel technologies in coal mining, after the empirical observation that gains in productivity were not uniform in all studied workgroups. Its roots can be traced back to the analysis of the introduction of mechanisation in jute milling in Scotland during the 30s[3, 11]. Sociotechnical systems can be characterised as open asynchronous concurrent systems in which some entities are humans and others are machines. Hence, interactions involving heterogeneous entities are a central concept to design, implement and analyse sociotechnical systems.

    In the present article we focus on safety and reliability and, more specifically, on the construction of tools to support systems design based on hazard prevention. Given that it can be impossible or too dificult to fully predict the behaviour of a sociotechnical system as a whole, we introduce the notion ofrelevanthazardsto be considered during the design of a system.

    In brief, we characterise a well determined subset of the set of all potential hazards for a system and perform backward induction to identify all initial states and chains of events that can lead to them. We then revise the system design in order to identify points in which design interventions can either prevent hazards or inject remedial procedures to be taken in case they occur.

    We focus on a specific class of sociotechnical systems for which hazard prevention is particularly relevant-namely, bounded air spaces containing pilot controlled aircrafts as well as unmanned aerial vehicles (UAVs). We introduce a diagrammatic language to support the characterisation of relevant hazards, of sequences of events that can lead to them and of events to which can be associated actions to be kept in store for each relevant hazard.

    We also introducesoftinstitutionsas an appropriate platform for hazard prevention based on relevant hazards, and illustrate how soft institutions can be used as a formal counterpart to diagrams employed to design a system for safe operations in bounded air spaces in which pilot controlled aircrafts share space with UAVs.

    This paper is organised as follows:

    — In section 2 we detail a characterisation of sociotechnical systems, highlighting as a relevant special case mission planning for coordinated UAVs with diversied levels of autonomy.

    — In section 3 we briefly introduce the main concepts related to hazard prevention and characterise in detail the notion of relevant hazards. We also introduce a diagrammatic language to represent sociotechnical systems aiming specically at the prevention and analysis of failures.

    — In section 4 we illustrate how the proposed diagrammatic language can be used to characterise complex agent interactions in such way that hazard prevention is supported. As a concrete example, we illustrate how it can be used to support the design of missions in bounded air spaces in which pilot controlled aircrafts share space with UAVs.

    — In section 5 we introduce the concept of soft institutions, a corresponding computational platform based on this concept and how it can be used as a platform to support hazard prevention for the design of sociotechnical systems.

    — Finally, in section 6 we present a brief discussion, conclusions and proposed future work.

    2 Sociotechnical systems

    A sociotechnical system can be characterised as an open network of heterogeneous interacting entities which can exchange messages and, therefore, coordinate their actions. Some of these entities are engineered and can be programmed to behave according to rules which are explicitly determined and fully understood, even in the cases when they are not fully deterministic; other entities are human centric and therefore their behaviour can, at best, be nudged towards desired patterns of behaviour.

    Following Davis et alli[3]we can characterise six facets of sociotechnical systems:

    1.Peoplecharacterised as interacting entities who can have different competences, attitudes, skills and interests, based on which they coordinate their actions with other entities as well as are considered by other entities in proposals for coordination and collaboration;

    2.Technologiesand tools that characterise engineered interacting entities which have dierent capabilities to sense, interpret and act upon the environment, based on which they can engage into interactions;

    3.Processes/proceduresembodied as programs and rules for engineered entities as well as norms, regulative policies, sanctioning and incentive mechanisms to steer people towards expected patterns of behaviour;

    4.Buildings/infrastructurewhich characterise environmental resources as well as constraints for interactions;

    5.Goalsand metrics to characterise whether the system as a whole as well as its individual entities are approaching or diverting from goals; and

    6.Culturewhich characterises defeasible assumptions and heuristics shared and adopted by groups of entities participating in a sociotechnical system.

    Depending on the combination and organisation of these facets, different design strategies for sociotechnical systems are most appropriate and require different strategies for design, implementation and management of sociotechnical systems:

    1.Opennessto admit or dismiss entities: a system can beclosed,partiallyopenorfullyopento the admission or dismissal of entities. Partially open systems can require certain conditions to be fullled in order to admit or dismiss entities from it;

    2.Coordinationlevels among entities: a system can beuncoordinated,locallycoordinatedorgloballycoordinated. In other words, entities participating in a sociotechnical system can act fully on their own, based on coordination rules involving groups of entities or based on coordination rules that engage the whole system to behave globally as a mechanism;

    3.Heterogeneityof entities in a system: a system can be comprisedprimarilyofhumans-thus characterising a social network in which human entities communicate and interact;primarilyoftechnologicalentities-thus characterising a distributed computational system, possibly containing entities whose behaviour is not fully deterministic; or havevaryingproportionsofhumansandtechnologicalentities;

    4.Statefulness: a sociotechnical system can bestateless, i.e. the global state of the system as well as the internal states of entities are static, and therefore do not need to be managed;globallystateful, i.e. the global state of the system can change but the internal states of entities are static, and therefore entities can be reactive and their modelling is simplied; orfullystateful, i.e. the global state of the system as well as the internal states of entities are dynamic and must be monitored and managed;

    5.Contextsensitiveness: updates in the environment can beirrelevantorunnoticeable, in which case context needs not be managed;dynamicalthoughirrespectiveofthestatesofthesystem, in which case the system as a whole as well as its components must be able to monitor changes in the environment and to adapt accordingly; anddynamicandsensitivetosystemstates, in which case system components must be able to monitor changes in the environment, correlate these changes with their actions and adjust actions to manage the environment while they pursue their goals.

    In the present work we are specically interested in bounded air spaces in which pilot controlled aircrafts share space with UAVs. In this scenario, a system is typically:

    1.Partiallyopen, as aircrafts are allowed in and out of the air space provided that well specied rules and norms are followed;

    2.Locallycoordinated, as entities communicate and coordinate their actions following strict protocols which induce a hierarchy of control;

    3.Heterogeneous, as we are considering autonomous vehicles interacting with pilot controlled vehicles and control systems comprised by sensors and actuators as well as human operators;

    4.Fullystateful, as the states of individual entities-especially engineered entities-must be stored and managed in order to manage the whole system, particularly with respect to hazard prevention and engineering;

    5.Sensitivetosystemstatesand changes resulting from external factors as well as from consequences of state updates of entities.

    Our focus in the present article is on hazard prevention during system design. We are interested in structuring the interactions among entities in this scenario in such way that all relevant hazards are taken into account and design decisions are made in order to avoid failures or to build readiness to fix them in case they occur.

    3 Hazard prevention based on relevant hazards

    We adopt the simplifying assumption that all participating entities have been admitted to the system by following the interaction protocols that characterise it. Entities which do not follow certified interaction protocols are considered as external entities which can influence but are not part of the system and, therefore, are not subject to design decisions related to it.

    We also assume that the behaviour of an entity can be completely described by the interactions in which it is prepared to participate. The internal functioning of any entity is not taken into account explicitly. This way, human centered entities can be considered uniformly together with complex engineered entities, and entities can be described using different levels of abstraction, according to the level of detail used to specify each interaction protocol under consideration.

    Two fundamental strategies can be considered for hazard prevention during systems design[6]:

    1.Avoidingthatthingsgowrong, i.e. anticipating hazards and their corresponding causes, to allow system re-design in order to prevent those causes to occur, and

    2.Ensuringthatthingsgoright, i.e. identifying hazards and their corresponding causes, and then looking ahead to events that can be a consequence of those hazards, so that corrective measures can be included in the system for each of the considered failures and/or their causes.

    We focus on a subset of the set ofallhazards, which are considered to be therelevantones, which are in fact the ones we are able to advance during synthesis and scrutiny of a system design. The design of complex systems that are resilient to failures must combine these two strategies in such way that all relevant hazards are considered.

    In summary, our proposed strategy for hazard prevention during the design of a sociotechnical system is based on the principles outlined in Figure 1.

    In order to support this strategy, we introduce a simple diagrammatic language to abstract entities in a sociotechnical system based on interaction protocols. The proposed language is presented in Figure 2.

    Each element in the proposed language can be represented using standardised notation as presented in Figures 3 and 4. Our purpose while designing this language was to make it as simple and compact as possible, as well as easy to translate as declarative executable specications using the existing infrastructure based onsoftinstitutions, as detailed in section 5.

    In Figure 3 we depict an entity which can participate in several contexts and assume several states within each of these contexts. For each state there are several interaction protocols which can be triggered by the entity. Some protocols have hand-offs in dierent contexts and/or states. Interaction protocols are portrayed as graphs inside white rectangles and hand-offs are represented as dashed arrows connecting graphs.

    In Figure 4 we depict all possible types of actions that can belong to an interaction protocol.

    As a brief example to illustrate the use of the diagrams, we feature in Figure 5 two entities-namely, a UAV and the Air Traffc Control (ATC)-during a simple interaction5. In this interaction, if necessary the UAV refuels and then it asks for permission to take-off. The ATC confirms the permission to take-off, and then the UAV changes state fromstandingtotaxiing.

    Figure1Principlesforhazardprevention

    5 A detailed example is presented in section 4.

    Figure2Diagrammaticlanguagetorepresententitiesinsociotechnicalsystems

    Hazard prevention can raise the possibility that the message from the ATC never gets to the UAV. Backward reasoning could suggest that the exchange of messages between the UAV and the ATC should contain additional steps, so that the UAV would acknowledge receipt of the message and the ATC would not stop sending copies of the permission to take-off until receiving an acknowledgment. Forward reasoning could suggest the inclusion of a time-out sensing operation as part of the interaction protocol for the UAV instandingstate, to prevent the UAV from staying idle in case the message from the ATC never arrives. Both strategies could be combined in order to design a system that is resilient to failures.

    Our purpose in building this diagrammatic language has been to support system designers activities with a clear and intuitive pictorial language capable of exposing hazards in a system which can then be considered accordingly.

    In the next section we present a detailed example in which a UAV is followed from standing off-lane through flying to landing.We use this example to illustrate how the proposed diagrammatic language can be used to represent complex systems in operation and how it can be used to identify hazards and help in the renement of system design to provide appropriate care to potential hazards.

    4 An illustrative example

    In order to show how the proposed diagrammatic language can be used for hazard prevention, we consider a slightly more sophisticated example in which a complete mission for a UAV is depicted and analysed. This mission corresponds to a complete flight-from standing off-lane through flying to landing-and requires interactions involving the UAV and an ATC. The number of states through which the UAV passes is seven:Standing,Taxiing,Take-off,Initialclimb,Enroute,ApproachandLanding.

    The diagrams corresponding to each state are depicted in Figures 6 to 12.

    In Figure 6 the entity UAV001 is initially switched off and off-lane. It is assumed that it is listening to the appropriate channel for messages to receivea message requiring it to start the engine, which takes entity UAV001 to the context of UAV and standing state. The message triggers the interaction protocol depicted in Figure 6. When it receives a message to start the engine, it updates the knowledge base and performs the action of starting the engine. It then queries the knowledge base to check whether the engine has started. If there is a failure, then it tries again to start the engine, otherwise it updates the knowledge base and checks fuel level and systems. If there is a problem, then it stops the engine and tries to start again, otherwise it updates the knowledge base and hands off control to an interaction protocol in Taxiing state.

    The proposed strategies for hazard prevention and prevention/recovery have resulted in the loops back to the engine start message, together with the action to stop the engine in case fuel and system messages indicate that the UAV is not ready for flying.

    In Figure 7 we have two entities, resp. UAV001 and ATC001. UAV001 stays in the context of UAV but now moves to taxiing state. ATC001 assumes context ATC and state to authorise taxiing towards take-off.

    The interaction protocol for UAV001 in context UAV and taxiing state is slightly more complex than the protocol for standing state. UAV001 sends a message to an entity that is available in the context of ATC. In our example, ATC001 receives this message and replies back with eithertake-offOK ortake-offdenied. If take-off is denied, then UAV001 loops back and re-sends the message, until take-off is OK. When take-off is OK, then UAV001 checks whether power back is required. In case it is, then it performs appropriate operations and checks again. When power back is not required, then it finally performs taxiing and hands off control to an interaction protocol in Take-off state.

    In Figure 8, UAV001 moves to take-off state and requests authorisation to take-off. If ATC001 authorises take-off, then UAV001 performs fuel and systems verification. If there is something wrong, then take-off is aborted and a new authorisation is requested; if verication succeeds then UAV001 proceeds to take-off. If ATC001 does not authorise take-off, then UAV001 checks its knowledge base to decide whether to hold take-off or to give up. If decision is to hold take-off, then a new authorisation is requested, otherwise mission is aborted.

    In Figure 9, UAV001 performs the transition from take-off to climb, which is itself a transition state towards en route state.

    In Figure 10, UAV001 moves to en route state and maintains communication with ATC001 anytime it requests change in cruise level, until it identies it is time to start descent. When this situation arises, then UAV001 requests permission to start descent. When ATC001 grants permission for descent then UAV001 performs descent and state moves to approach.

    In Figure 11, UAV001 moves to approach and maintains communication with ATC001 to request permission to start approach for landing. In case meteorological conditions are not adequate, permission is denied and, depending on what conditions are occurring, appropriate measures are taken before a second attempt to start approach for landing is started. In case meteorological conditions are fine, permission is granted and approach is started. In case some operation does not succeed during approach, UAV001 goes to circling and approach is restarted, otherwise approach is finalised and the entity moves to landing, which is the final state in this mission.

    Finally, in Figure 12, UAV moves to landing and attempts to perform landing. If it succeeds, then it goes to taxiing and switches off engines, otherwise it takes-off again.

    A design tool to support hazard prevention in these terms must allow the representation of complex systems based on this vocabulary, and the exhaustive simulation of interactions involving entities in a system once an event (or set of events) is highlighted. In the next section we introducesoftinstitutionsasan appropriate platform to build one such tool.

    5 Soft institutions

    We argue that soft institutions can be used as a tool to design and implement sociotechnical systems which is particularly useful for hazard prevention, given that a translation from the diagrammatic language presented in the previous sections to interactions protocols in a soft institution is immediate.

    Soft institutions generalise the concept of electronic institutions[4, 5, 10]to provide means to model complex systems comprised by human as well as engineered peers[7]. They have been proposed as an appropriate platform to design and implement sociotechnical systems[2].

    Electronic institutions are a powerful framework to build systems comprised by multiple entities based on the principle that the global behaviour of a complex system can be managed by the establishment of norms, rewards for entities that abide by these norms and sanctions for those who challenge them. In order for an entity to participate in an electronic institution, it must be prepared to respond to norms, rewards and sanctions, as well as interact with other participating entities.

    Norms, rewards and sanctions in an electronic institution form anormativesystemwhich should be flexible in order to adjust to the observed behaviour of participating entities in an institution. The normative system dictates the way entities should behave in order to be allowed into an electronic institution and an entity (or organisation comprised by entities) must comply with the normative system in order to be able to request participation in an electronic institution.

    Technological entities can be designed and built to comply with normative systems and, therefore, participate in electronic institutions. Human entities, however, may feel uncomfortable to need to learn and then to be submissive to third party rules as a prerequisite to join into a network of peers.

    Soft institutions, in contrast, allow entities to act freely and adjust their behaviour in a minimalist way to be able to join into local interaction protocols. Instead of having a centralised control around the normative system (as is the case with electronic institutions), soft institutions have a decentralised, possibly asynchronous control, centered on entities which choose to interact according to available protocols. This way, the barrier to enter a soft institution is significantly lower for humans, hence an interaction platform based on soft institutions can be more appealing to human entities than one based on electronic institutions, at the cost of only being able to have partial control over design, operation and management of a system based on soft institutions.

    From the perspective of hazard prevention, soft institutions are a good modeling language for complex sociotechnical systems, well aligned with the strategy for hazard prevention proposed in section 3. Soft institutions also consider as a basic principle that a full account of all states of the systems being modeled is not feasible, hence hazard prevention can only-and at best-be based on relevant hazards as characterised in section 3.

    Soft institutions are organised in four layers:

    1.Theentitycontrolledlayer: this layer caters for individual capabilities and actions corresponding to each entity. Entities can be human individuals (e.g. pilots and flight controllers), technological entities (e.g. aircrafts, sensing and communicating devices), or organisations constituted of other entities (e.g. teams of aircrafts flying in formation, teams of controllers);

    2.Thecommunicationslayer: this layer comprises the infrastructure and processing power to manage message exchanges between entities. In principle, messaging is peer-to-peer with unique addressing. Additional message control structures can be built using the entity controlled and the communications layer.

    3.Thecoordinationlayer: this layer consists of social norms that constrain and regulate interactions among selected peers (e.g. rules to enter a controlled air space, navigate in it, interact with other entities and leave the air space).

    4.Theenvironment: this layer comprises all other phenomena that can influence the behaviour and state of the soft institution.

    1.Terms: correspond to constant or atomic expressions of dierent types;

    2.Variables: are uniquely identied strings to which dierent values can be assigned;

    3.Functions: are collections of mappings from tuples of terms to terms.

    Messages are passed from entity to entity via the communications layer. To each entity is assigned a unique ID, and messages depend upon contexts and states to be properly treated. A messageMis assumed to have the formatM= , whereRsendis the context/state that the sending entity must necessarily hold when the message is sent;gTis a ground term which corresponds to the content of the message;Rrecis the context/state that the receiving entity must hold in order for the message to be received;IDotheris the ID of the “other” entity: it is the ID of the receiver when a message is being sent and the ID of the sender when a message is being received.

    The institutional knowledge base also contains two constructs that represent the state of the entity with respect to the soft institution:

    1.Commstores the status of communications. It contains the entity ID and two message queues containing incoming and outgoing messages respectively.

    2.Coordstores the status of coordination. It contains the list of contexts and states already held by the entity including the current context/state as head of the list, the protocol being followed, the stage of execution of the current protocol and the set of variable assignments / substitutions.

    Protocols are dened as a variation and extension of theLightweightCoordinationCalculus(LCC)[9]according to the specication presented in Figure 13. Carefully crafted sets of protocols embedded into appropriate states and contexts can implement sophisticated patterns of interaction, servicing large and complex sociotechnical systems. Interaction protocols work as support services for entities to engage into well regulated and carefully designed interactions, but they are not mandatory and they do not necessarily cover all aspects of all interactions that connect entities participating in the same sociotechnical system. System modeling based on soft institutions can be used to highlight facets of a system that are considered most relevant. For hazard prevention, relevant hazards can be characterised in detail and simulations can be performed, so that forward and backward reasoning can be performed and the design of a system can be rened and improved towards resilience with respect to failures.

    Figure13ProtocolsinLCC

    6 Conclusion and future work

    In this work we have considered hazard prevention during the design of systems for flight control of autonomous UAVs, based on a diagrammatic language that can be translated to protocols insoftinstitutions.

    Implementations of platforms for soft institutions have already been presented elsewhere[7], and frameworks for formal verification of interaction protocols with respect to desired properties have also been developed[8]. In future work, we plan to employ these systems as a platform to support the activities of safety engineers during the design of complex systems, by providing them with tools to identify potential relevant hazards.

    [1]F.Belmonte,W.Schon,L.Heurley,andR.Capel.Interdisciplinarysafetyanalysisofcomplexsocio-technologicalsystemsbasedonthefunctionalresonanceaccidentmodel:Anapplicationtorailwaytracsupervision.ReliabilityEngineeringandSystemSafety, 96:237-249, 2011.

    [2]F.S.CorreadaSilva,P.Papapanagiotou,D.Murray-Rust,andD.Robertson.Softinstitutions-aplatformtodesignandimplementsociotechnicalsystems(submitted)[C]//In20thInternationalConferenceonKnowledgeEngineeringandKnowledgeManagement,Italy, 2016.

    [3]M.C.Davis,R.Challenger,D.N.W.Jayewardene,andC.W.Clegg.Advancingsocio-technicalsystemsthinking:acallforbravery.AppliedErgonomics, 45:171-180, 2014.

    [4]M.Esteva,J.A.Rodriguez-Aguilar,C.Sierra,P.Garcia,andJ.L.Arcos.Ontheformalspecicationofelectronicinstitutions.InAgentmediatedelectroniccommerce,pages126-147.Springer, 2001.

    [5]M.EstevaandC.Sierra.ElectronicInstitutions:fromspecicationtodevelopment.ConsellSuperiord’InvestigacionsCientques,Institutd’InvestigacióenIntelligènciaArticial, 2003.

    [6]E.Hollnagel.Ataleoftwosafeties.NuclearSafetyandSimulation, 2013.

    [7]D.Murray-Rust,P.Papapanagiotou,andD.Robertson.Softeningelectronicinstitutionstosupportnaturalinteraction.HumanComputation, 2(2), 2015.

    [8]P.Papapanagiotou,D.Murray-Rust,andD.Robertson.Evolutionofthelightweightcoordinationcalculususingformalanalysis.Personalcommunication, 2016.

    [9]D.Robertson.Multi-agentcoordinationasdistributedlogicprogramming,pages416-430.Proceedings20thInternationalConferenceonLogicProgramming-SpringerLNCS3132. 2004.

    [10]C.Sierra,J.A.Rodriguez-Aguilar,P.Noriega,M.Esteva,andJ.L.Arcos.Engineeringmulti-agentsystemsaselectronicinstitutions.EuropeanJournalfortheInformaticsProfessional, 4(4):33-39, 2004.

    [11]E.Trist.Theevolutionofsocio-technicalsystems.Occasionalpaper, 2:1981, 1981.

    10.19416/j.cnki.1674-9804.2017.03.018

    * This work has been partially supported by FAPESP-Brazil and by the EPSRCUK. The present article is a revised and extended version of the articleHazardidenticationforUAVsbasedonsoftinstitutions, by the same authors, presented at the workshopCoordination,Organisations,InstitutionsandNorms-AAMAS2017. Many important comments and criticisms on early versions of this work have beengenerously provided by Dr. David Murray-Rust (Edinburgh, UK) and Dr. Amanda Whitbrook (Derby, UK).

    久久午夜亚洲精品久久| 日本爱情动作片www.在线观看 | 欧美国产日韩亚洲一区| 欧美色欧美亚洲另类二区| 精品久久久久久久末码| 日本 av在线| 大香蕉久久网| 精品不卡国产一区二区三区| 欧美+日韩+精品| 成人一区二区视频在线观看| 久久久久久大精品| 欧美+亚洲+日韩+国产| 午夜福利18| 黄色日韩在线| a级一级毛片免费在线观看| 最近视频中文字幕2019在线8| 亚洲熟妇中文字幕五十中出| 亚洲av免费在线观看| 免费高清视频大片| 日韩制服骚丝袜av| 国产亚洲精品av在线| 亚洲精品亚洲一区二区| 亚洲国产精品合色在线| 又爽又黄a免费视频| 毛片女人毛片| 99国产精品一区二区蜜桃av| 欧美精品国产亚洲| 精品一区二区免费观看| 九九久久精品国产亚洲av麻豆| 欧美高清成人免费视频www| 国产精华一区二区三区| 日本爱情动作片www.在线观看 | 99热这里只有精品一区| 精品无人区乱码1区二区| 69人妻影院| 久久久午夜欧美精品| 1000部很黄的大片| 国内少妇人妻偷人精品xxx网站| av黄色大香蕉| 乱人视频在线观看| 亚洲美女黄片视频| 丰满人妻一区二区三区视频av| 嫩草影院精品99| 观看美女的网站| 少妇裸体淫交视频免费看高清| 免费不卡的大黄色大毛片视频在线观看 | 欧美在线一区亚洲| 啦啦啦韩国在线观看视频| 久久精品夜色国产| 免费在线观看成人毛片| 国产精品久久久久久av不卡| 免费大片18禁| 色哟哟·www| 色综合亚洲欧美另类图片| 亚洲精品一区av在线观看| 在线观看66精品国产| 亚洲国产日韩欧美精品在线观看| 真人做人爱边吃奶动态| 搡老熟女国产l中国老女人| 伦理电影大哥的女人| 亚洲中文字幕一区二区三区有码在线看| 人人妻,人人澡人人爽秒播| 国产一区二区在线观看日韩| 久久久久久久久大av| 色哟哟·www| 日日干狠狠操夜夜爽| 亚洲最大成人手机在线| 99热这里只有是精品在线观看| 国产av一区在线观看免费| 在线国产一区二区在线| 人妻夜夜爽99麻豆av| 波多野结衣高清作品| 午夜精品在线福利| 成人精品一区二区免费| 色在线成人网| 久久久久久久久大av| 精品免费久久久久久久清纯| 亚洲久久久久久中文字幕| 国内精品一区二区在线观看| 1000部很黄的大片| 九九久久精品国产亚洲av麻豆| 综合色av麻豆| 日本欧美国产在线视频| 国产在线男女| 91av网一区二区| 国产黄色小视频在线观看| 成人二区视频| 九九在线视频观看精品| 亚洲av成人av| 男人和女人高潮做爰伦理| 精品一区二区三区av网在线观看| 天天躁夜夜躁狠狠久久av| 一级毛片电影观看 | 亚洲一区二区三区色噜噜| 亚洲综合色惰| 成人av在线播放网站| 国产精品野战在线观看| 精品人妻视频免费看| 日本爱情动作片www.在线观看 | 国产高清视频在线观看网站| 久久精品国产亚洲网站| 精品福利观看| 五月玫瑰六月丁香| 成年免费大片在线观看| 人人妻人人澡人人爽人人夜夜 | 三级毛片av免费| 亚洲精华国产精华液的使用体验 | 狂野欧美激情性xxxx在线观看| 久久久久性生活片| 欧美+日韩+精品| 午夜影院日韩av| 少妇裸体淫交视频免费看高清| 晚上一个人看的免费电影| 精品福利观看| 黑人高潮一二区| 亚洲国产色片| 熟妇人妻久久中文字幕3abv| 香蕉av资源在线| 午夜免费激情av| 国产成人a区在线观看| 人妻夜夜爽99麻豆av| 变态另类丝袜制服| 性欧美人与动物交配| 人妻制服诱惑在线中文字幕| 久久久久久伊人网av| 午夜福利视频1000在线观看| 成人欧美大片| 日韩中字成人| 久久久久九九精品影院| 午夜精品一区二区三区免费看| 悠悠久久av| 嫩草影院精品99| 91精品国产九色| h日本视频在线播放| 免费电影在线观看免费观看| 狂野欧美白嫩少妇大欣赏| 中国美白少妇内射xxxbb| 亚洲国产精品sss在线观看| 欧美zozozo另类| 日韩欧美国产在线观看| 日韩精品青青久久久久久| 免费看美女性在线毛片视频| 亚洲第一电影网av| 欧美+亚洲+日韩+国产| 一个人免费在线观看电影| 校园春色视频在线观看| 精品不卡国产一区二区三区| 亚洲内射少妇av| 韩国av在线不卡| 熟妇人妻久久中文字幕3abv| 日本精品一区二区三区蜜桃| 韩国av在线不卡| 黄色一级大片看看| 久久精品影院6| 热99re8久久精品国产| 国产成人freesex在线 | 国产精品人妻久久久久久| 亚洲真实伦在线观看| 亚洲18禁久久av| 性色avwww在线观看| 久久久久久久久久久丰满| 亚洲精华国产精华液的使用体验 | 波野结衣二区三区在线| 国产av在哪里看| 久久精品综合一区二区三区| 最近手机中文字幕大全| 亚洲第一电影网av| 国产白丝娇喘喷水9色精品| 3wmmmm亚洲av在线观看| 欧美一区二区亚洲| 69av精品久久久久久| 在线看三级毛片| 大又大粗又爽又黄少妇毛片口| 亚洲中文字幕日韩| 男人舔女人下体高潮全视频| 乱人视频在线观看| 国产人妻一区二区三区在| 欧美另类亚洲清纯唯美| 中文资源天堂在线| 亚洲激情五月婷婷啪啪| 波多野结衣高清作品| 免费观看的影片在线观看| 别揉我奶头 嗯啊视频| 内射极品少妇av片p| 人人妻人人澡欧美一区二区| 色综合站精品国产| 麻豆成人午夜福利视频| 99热这里只有是精品50| 成人亚洲欧美一区二区av| eeuss影院久久| 91在线精品国自产拍蜜月| 国产人妻一区二区三区在| 尾随美女入室| 国产国拍精品亚洲av在线观看| 国产精品一二三区在线看| 少妇高潮的动态图| 欧美精品国产亚洲| 日本三级黄在线观看| 1000部很黄的大片| 国产精品久久久久久av不卡| 久久久久免费精品人妻一区二区| 欧美精品国产亚洲| 熟女人妻精品中文字幕| 成人综合一区亚洲| 欧美日韩综合久久久久久| 久久久久国产精品人妻aⅴ院| 亚洲精品在线观看二区| 国产高清视频在线观看网站| 久久国内精品自在自线图片| 中文在线观看免费www的网站| 国语自产精品视频在线第100页| eeuss影院久久| av视频在线观看入口| 蜜桃亚洲精品一区二区三区| 欧美日本视频| 国产av在哪里看| 亚洲av一区综合| 国产视频内射| 久久久久免费精品人妻一区二区| 日本与韩国留学比较| 免费大片18禁| 久久精品国产99精品国产亚洲性色| 亚洲性久久影院| 亚洲美女视频黄频| 久久人人爽人人片av| 亚洲av二区三区四区| 亚洲av成人av| 色尼玛亚洲综合影院| 国产三级中文精品| 国产精华一区二区三区| 国内精品一区二区在线观看| 嫩草影院精品99| 久久久a久久爽久久v久久| 人人妻人人澡欧美一区二区| 麻豆成人午夜福利视频| 在线a可以看的网站| 噜噜噜噜噜久久久久久91| 精品久久久久久久久久久久久| av在线观看视频网站免费| 俺也久久电影网| 伦精品一区二区三区| 亚洲综合色惰| 久久久国产成人精品二区| 国产精品一区二区性色av| 99国产精品一区二区蜜桃av| 伦精品一区二区三区| 午夜a级毛片| 高清毛片免费观看视频网站| 村上凉子中文字幕在线| 亚洲性夜色夜夜综合| 国产日本99.免费观看| 欧美最黄视频在线播放免费| 人妻夜夜爽99麻豆av| 国产精品免费一区二区三区在线| 国产亚洲av嫩草精品影院| 亚洲三级黄色毛片| 嫩草影视91久久| 国产一区二区三区在线臀色熟女| 国产精品一二三区在线看| 久久精品国产亚洲av涩爱 | 搡老岳熟女国产| 少妇猛男粗大的猛烈进出视频 | 一边摸一边抽搐一进一小说| 又黄又爽又刺激的免费视频.| 99视频精品全部免费 在线| 一区福利在线观看| 亚洲婷婷狠狠爱综合网| 久久久久久久久久久丰满| 在线观看免费视频日本深夜| 亚洲18禁久久av| 国产成人aa在线观看| 日韩成人伦理影院| www日本黄色视频网| 毛片一级片免费看久久久久| av黄色大香蕉| 国产高潮美女av| 中文字幕熟女人妻在线| 成人二区视频| 三级男女做爰猛烈吃奶摸视频| 99久久中文字幕三级久久日本| 嫩草影院入口| 国产在视频线在精品| 不卡一级毛片| 舔av片在线| 老司机福利观看| 一级黄色大片毛片| 亚洲av成人av| 国产日本99.免费观看| 黄色配什么色好看| 久久久久久伊人网av| 精品一区二区三区视频在线| 欧美日本视频| 久久精品久久久久久噜噜老黄 | 日韩精品青青久久久久久| 午夜亚洲福利在线播放| 久久精品国产亚洲网站| 内射极品少妇av片p| eeuss影院久久| 久久久久国内视频| 日日摸夜夜添夜夜添小说| 自拍偷自拍亚洲精品老妇| 少妇猛男粗大的猛烈进出视频 | 毛片女人毛片| 欧美高清成人免费视频www| 久久精品久久久久久噜噜老黄 | 亚洲精品一区av在线观看| 欧美在线一区亚洲| 国产探花极品一区二区| 丰满乱子伦码专区| 国产精品野战在线观看| 国产一区二区激情短视频| 国产又黄又爽又无遮挡在线| 国产精品久久久久久精品电影| 亚洲av不卡在线观看| av天堂在线播放| 久久久国产成人免费| 成人亚洲欧美一区二区av| 日日摸夜夜添夜夜爱| 国产精品99久久久久久久久| 欧美日韩乱码在线| 国产伦一二天堂av在线观看| 日韩欧美免费精品| 国产伦一二天堂av在线观看| 免费观看人在逋| 真人做人爱边吃奶动态| 久久久精品94久久精品| 国产在线男女| 久久久久久大精品| 亚洲精华国产精华液的使用体验 | 国产精品嫩草影院av在线观看| 亚洲经典国产精华液单| 少妇猛男粗大的猛烈进出视频 | 成人三级黄色视频| 欧美中文日本在线观看视频| 深夜a级毛片| 中文字幕精品亚洲无线码一区| 国产高清视频在线播放一区| av女优亚洲男人天堂| 国产午夜福利久久久久久| videossex国产| 国产精品一区二区三区四区免费观看 | 三级毛片av免费| 日韩精品中文字幕看吧| 搡老妇女老女人老熟妇| 内射极品少妇av片p| 亚洲性夜色夜夜综合| 啦啦啦韩国在线观看视频| 国产一区二区三区av在线 | 日本三级黄在线观看| 人妻夜夜爽99麻豆av| 国产精品久久视频播放| 国产亚洲精品久久久久久毛片| 欧美xxxx黑人xx丫x性爽| 国产毛片a区久久久久| 日本a在线网址| 特级一级黄色大片| а√天堂www在线а√下载| 国产免费男女视频| 女人十人毛片免费观看3o分钟| 一个人看视频在线观看www免费| 久久综合国产亚洲精品| 日韩国内少妇激情av| 午夜亚洲福利在线播放| 国产精品乱码一区二三区的特点| 99国产精品一区二区蜜桃av| h日本视频在线播放| 日韩成人av中文字幕在线观看 | 日本精品一区二区三区蜜桃| 亚洲真实伦在线观看| 日日啪夜夜撸| 久久九九热精品免费| 久久久久久久久久成人| 国产亚洲91精品色在线| 久久久久精品国产欧美久久久| 亚洲精品亚洲一区二区| 国产精华一区二区三区| 国产毛片a区久久久久| 欧美性猛交黑人性爽| 亚洲人成网站高清观看| 久久婷婷人人爽人人干人人爱| 免费在线观看成人毛片| 一进一出抽搐gif免费好疼| 国产精华一区二区三区| 三级经典国产精品| 午夜a级毛片| 亚洲成a人片在线一区二区| 日本-黄色视频高清免费观看| 成人午夜高清在线视频| 嫩草影院入口| 丝袜喷水一区| 亚洲精品日韩av片在线观看| 日韩欧美精品免费久久| 伊人久久精品亚洲午夜| 搡老岳熟女国产| 国产人妻一区二区三区在| 日韩,欧美,国产一区二区三区 | 又爽又黄a免费视频| 日本与韩国留学比较| 午夜精品在线福利| 99久久九九国产精品国产免费| 国产精品日韩av在线免费观看| 亚洲国产精品成人综合色| 热99re8久久精品国产| h日本视频在线播放| 中国国产av一级| 蜜桃久久精品国产亚洲av| 国内少妇人妻偷人精品xxx网站| 色播亚洲综合网| av专区在线播放| 国产精品av视频在线免费观看| 精品无人区乱码1区二区| 成年女人看的毛片在线观看| 91在线精品国自产拍蜜月| 亚洲人成网站在线观看播放| 久久这里只有精品中国| 最新在线观看一区二区三区| 国内精品一区二区在线观看| 在线看三级毛片| 精品不卡国产一区二区三区| 亚洲五月天丁香| 国产成人freesex在线 | 国产国拍精品亚洲av在线观看| 在线播放国产精品三级| avwww免费| 精品无人区乱码1区二区| 一进一出抽搐gif免费好疼| 99riav亚洲国产免费| 成人永久免费在线观看视频| 亚洲成人中文字幕在线播放| 免费看av在线观看网站| 2021天堂中文幕一二区在线观| 人妻少妇偷人精品九色| 国产探花极品一区二区| 99热网站在线观看| 51国产日韩欧美| 欧美最新免费一区二区三区| 亚洲aⅴ乱码一区二区在线播放| 国产高清三级在线| 亚洲av美国av| 成人美女网站在线观看视频| 日产精品乱码卡一卡2卡三| 最近手机中文字幕大全| 黄色一级大片看看| 丰满乱子伦码专区| 精品久久久久久久久久免费视频| 美女大奶头视频| 老司机午夜福利在线观看视频| 在线观看av片永久免费下载| 精品一区二区三区视频在线| 亚洲成人av在线免费| 69人妻影院| 精品少妇黑人巨大在线播放 | 成人精品一区二区免费| 亚州av有码| 亚洲av不卡在线观看| 波多野结衣高清无吗| 国产中年淑女户外野战色| 国产白丝娇喘喷水9色精品| 观看美女的网站| 国产精品不卡视频一区二区| 免费电影在线观看免费观看| 特大巨黑吊av在线直播| 蜜臀久久99精品久久宅男| 成年免费大片在线观看| 亚洲激情五月婷婷啪啪| 日本三级黄在线观看| 波多野结衣巨乳人妻| 精品一区二区免费观看| 国产久久久一区二区三区| 色在线成人网| 精品久久久久久成人av| 免费高清视频大片| 熟妇人妻久久中文字幕3abv| 一级毛片我不卡| 我的老师免费观看完整版| 99热这里只有是精品在线观看| 男人舔女人下体高潮全视频| 男女那种视频在线观看| 我要看日韩黄色一级片| h日本视频在线播放| 日韩亚洲欧美综合| 国产精品无大码| 99久久成人亚洲精品观看| 国产黄a三级三级三级人| 欧美人与善性xxx| videossex国产| 一进一出抽搐gif免费好疼| 女人被狂操c到高潮| 国产成人91sexporn| 国产探花在线观看一区二区| 日韩成人av中文字幕在线观看 | 日韩欧美精品免费久久| 97碰自拍视频| 高清毛片免费看| 国产国拍精品亚洲av在线观看| 国产伦在线观看视频一区| 一区二区三区免费毛片| ponron亚洲| 成人二区视频| 亚洲av免费在线观看| 国产亚洲精品av在线| 嫩草影院入口| 久久精品人妻少妇| 欧美高清性xxxxhd video| 久久精品影院6| 久久精品国产亚洲av涩爱 | 男女那种视频在线观看| 黄色视频,在线免费观看| 欧美最新免费一区二区三区| 狂野欧美白嫩少妇大欣赏| 国产不卡一卡二| 亚洲三级黄色毛片| 国产高清有码在线观看视频| 欧美三级亚洲精品| 99热这里只有是精品在线观看| 菩萨蛮人人尽说江南好唐韦庄 | 日韩亚洲欧美综合| 人妻夜夜爽99麻豆av| 国产精品一区www在线观看| 日韩成人伦理影院| 欧美三级亚洲精品| 六月丁香七月| 老熟妇乱子伦视频在线观看| 91在线精品国自产拍蜜月| 免费无遮挡裸体视频| 日韩欧美免费精品| 国产精品国产高清国产av| 舔av片在线| 亚洲av中文av极速乱| 国产欧美日韩一区二区精品| 日本黄色视频三级网站网址| 日本爱情动作片www.在线观看 | 一进一出抽搐gif免费好疼| 久久久色成人| 国产午夜福利久久久久久| 亚洲最大成人手机在线| 国产老妇女一区| 免费人成视频x8x8入口观看| 日本熟妇午夜| 91在线精品国自产拍蜜月| 久久久久国产精品人妻aⅴ院| 夜夜爽天天搞| 亚洲精华国产精华液的使用体验 | 国产av不卡久久| 午夜免费男女啪啪视频观看 | 日韩欧美在线乱码| 天美传媒精品一区二区| 国产午夜精品论理片| 69人妻影院| 久久久久国产网址| 女人十人毛片免费观看3o分钟| 亚洲色图av天堂| 性插视频无遮挡在线免费观看| 亚洲经典国产精华液单| 国产精华一区二区三区| 日本黄色视频三级网站网址| 18禁裸乳无遮挡免费网站照片| 国产极品精品免费视频能看的| 国产成人aa在线观看| 国产一区二区三区av在线 | 国产在视频线在精品| 婷婷六月久久综合丁香| 精品久久久久久成人av| 日本五十路高清| 成人二区视频| 99国产极品粉嫩在线观看| 国产人妻一区二区三区在| 99久久久亚洲精品蜜臀av| 一级黄片播放器| av国产免费在线观看| 女的被弄到高潮叫床怎么办| 色综合亚洲欧美另类图片| 亚洲天堂国产精品一区在线| 十八禁网站免费在线| 波多野结衣巨乳人妻| 国产精品精品国产色婷婷| 伦精品一区二区三区| 偷拍熟女少妇极品色| 伊人久久精品亚洲午夜| 亚洲五月天丁香| 日本黄色视频三级网站网址| 老司机影院成人| 91久久精品电影网| 精品人妻熟女av久视频| 日韩精品青青久久久久久| 少妇熟女欧美另类| av中文乱码字幕在线| 男人狂女人下面高潮的视频| 3wmmmm亚洲av在线观看| 午夜久久久久精精品| 黑人高潮一二区| 亚洲欧美日韩高清在线视频| 女生性感内裤真人,穿戴方法视频| 免费av观看视频| 一个人免费在线观看电影| 日本熟妇午夜| 欧美xxxx黑人xx丫x性爽| 女同久久另类99精品国产91| 亚洲av免费高清在线观看| 国产乱人视频| 99久国产av精品| av免费在线看不卡| 美女被艹到高潮喷水动态| 久久久久久久午夜电影| 精品少妇黑人巨大在线播放 | 久久久久久九九精品二区国产| 最新在线观看一区二区三区| 99久久精品热视频| 欧美一级a爱片免费观看看| 听说在线观看完整版免费高清| 婷婷亚洲欧美| 男人和女人高潮做爰伦理| 最好的美女福利视频网| 亚洲图色成人| 国产精品三级大全|