Challenging encapsulation in the design of high-risk control systemsAn apporpriate architectural approach is to acknowledge the underlying physics and to elevate the concepts of state and models to first-class design elements that are not encapsulated within subsystem objects.