A security analysis system and method integrating FTA and FMEA
By combining the safety analysis system of FTA and FMEA, the problem of the difficulty in verifying the results of independent FTA and FMEA analysis is solved, realizing comprehensive safety analysis of autonomous driving systems, discovering and supplementing missing functional safety requirements, outputting intuitive graphical results, and reducing the workload of analysts.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- ZHIJI AUTOMOTIVE TECH CO LTD
- Filing Date
- 2023-01-04
- Publication Date
- 2026-05-26
AI Technical Summary
In existing technologies, when FTA and FMEA are conducted independently for safety analysis, the results are difficult to corroborate each other, resulting in insufficient or incomplete safety analysis results for complex autonomous driving systems, which affects the functional safety development of autonomous driving systems.
The safety analysis system combining FTA and FMEA, through input modules, functional safety requirements management modules, FTA analysis modules, functional failure mode management modules, and FMEA analysis modules, enables mutual verification and reference of FTA and FMEA results. The output analysis results include FTA analysis tree diagrams and FMEA analysis hierarchy diagrams, using different colors or shapes to mark uncovered nodes, and performing multiple iterative analyses.
It enables mutual support and verification of FTA and FMEA analysis results, comprehensively analyzes safety, discovers and supplements missing functional safety requirements, outputs intuitive graphical analysis results, and reduces the workload of analysts.
Smart Images

Figure CN116167210B_ABST
Abstract
Description
Technical Field
[0001] This application belongs to the field of security and reliability technology, and in particular relates to a security analysis system and method that integrates FTA and FMEA. Background Technology
[0002] Definitions:
[0003] HARA: Hazard Analysis and Risk Assessment.
[0004] FTA (Fault Tree Analysis): Fault tree analysis is a top-down reliability analysis method. It starts with the event to be analyzed (top event) as the root of the fault tree and traces the cause of the event downwards until the basic event (bottom event).
[0005] FMEA (Failure and Effects Analysis) is a systematic activity that analyzes each system, part, or process that makes up a product to identify all potential failure modes and analyze their consequences, thereby taking necessary measures in advance to improve the quality and reliability of the product.
[0006] Fiscal Tree Analysis (FTA) is a crucial analytical method in safety systems engineering. It's a special type of inverted tree-like causal diagram that uses event symbols, logic gate symbols, and transition symbols to describe the causal relationships between various events in a system. It's a top-down analysis method, moving from the system to components and then to parts. Starting with the system, it analyzes the probability of failure events (also known as top-level events) by drawing a tree-like branching diagram using logic symbols. It can also be used to analyze the impact of component, component, or subsystem failures on the overall system failure, including human factors and environmental conditions.
[0007] FTA can be used for both qualitative and quantitative analysis; FMEA is a qualitative analysis tool; FMEDA is a quantitative analysis tool; FTA uses a top-down deductive analysis method, while FMEA and FMEDA use a bottom-up inductive analysis method.
[0008] ACC stands for Adaptive Cruise Control.
[0009] ACC stands for Adaptive Cruise Control, also known as Active Cruise Control. It is an automatic and intelligent system that can maintain the speed preset by the driver and reduce speed or brake at any time under specified safe driving conditions.
[0010] ACC also has some other functions as follows:
[0011] 1. This system can automatically decelerate and accelerate without the driver's active control, and can intelligently control the engine's accelerator pedal and braking system.
[0012] 2. When the cruise control system operates the vehicle's braking, it usually limits the braking deceleration to a level that does not affect comfort.
[0013] 3. ACC is used to achieve the following function, so you don't need to press the accelerator and brake yourself, which can reduce driving fatigue.
[0014] 4. The adaptive navigation system only works at speeds of approximately 25 kilometers per hour. When the speed drops below 25 kilometers per hour, manual control by the driver is required.
[0015] This intelligent car control system is also very useful in actual operation. It is safe at certain distances and time points, and can make the driver feel relaxed.
[0016] ACC is an intelligent automatic control system that can automatically control the distance and speed of the vehicle in front based on the situation of the vehicle in front, thereby reducing the driver's operation of the accelerator and brake and improving comfort.
[0017] ACC (Adaptive Cruise Control) avoids the need for frequent cancellation and resetting of cruise control, making the system suitable for more road conditions. Drivers can completely remove their feet from the pedals and focus solely on the steering wheel, significantly reducing fatigue during long drives and providing a more relaxed driving experience. Because the ACC system partially takes over vehicle control, its reliability requirements are high, necessitating thorough analysis of the safety impact on the entire system should any component fail.
[0018] Automobiles are complex products integrating mechanical, electrical, hydraulic, and pneumatic systems. Failure Mode and Effects Analysis (FMEA) and Failure Mode, Effects, and Criticality Analysis (FMECA) are commonly used for qualitative analysis in product reliability analysis, while Fault Tree Analysis (FTA), Boolean Theory, and Markov Theory are mostly used for quantitative analysis in reliability analysis. In engineering practice, they are often combined to leverage their respective advantages and complement each other, resulting in significant benefits with less effort. However, FTA and FMEA analyses are still conducted independently, involving a substantial workload.
[0019] For complex autonomous driving systems, conducting safety analysis using independent FTA or FMEA methods results in a large number of complex data points. The data from the two methods are difficult to corroborate and reference. Insufficient or incorrect analysis can lead to omissions or errors in safety requirements, affecting the functional safety development of the autonomous driving system and potentially causing unacceptable risks after a system failure. Summary of the Invention
[0020] To provide an efficient safety analysis system and method that integrates FTA and FMEA, enabling mutual verification and reference of FTA and FMEA analysis results, this invention proposes a comprehensive FTA and FMEA safety analysis system, including an input module, a functional safety requirements management module, an FTA analysis module, a functional failure mode management module, and an FMEA analysis module. The input module includes a system-to-system relationship input module, which obtains external input systems and system relationships; and a safety target input module, which obtains external input safety targets. The functional safety requirements management module manages the functional safety requirements list, including adding and deleting functional safety requirements. The functional failure mode management module manages the functional failure mode list, including functional failure mode list... The system includes: adding and deleting tables; the FTA analysis module performs FTA analysis based on the safety target list and the system relationship list to obtain the functional safety requirements list; the FMEA analysis module performs FMEA analysis based on the system and system relationship list and the functional safety requirements list to output the functional failure mode list; the functional failure mode management module manages the functional failure mode list, including adding and deleting functional failure modes; the functional safety requirements management module determines whether a functional safety requirement covers the functional failure mode list, and if not, adds a new functional safety requirement; the functional failure mode management module analyzes whether each functional safety requirement has a corresponding component and deletes duplicate functional safety requirements; and the functional failure mode management module analyzes whether each functional safety requirement corresponds to a specific functional failure mode, and if not, adds the corresponding functional failure mode.
[0021] It may also include an output module; the output module outputs the analysis results; the system-to-system relationship includes component name, component function, function failure mode and / or failure mode.
[0022] The analysis results can also include functional safety requirements, new functional safety requirements, and functional safety requirement analysis results.
[0023] The analysis results can also include an FTA analysis tree diagram, which includes a root node, at least one level of intermediate nodes, and leaf nodes. The root node represents the final failure impact, and the root node of the tree diagram includes both the final failure impact covered by the analysis and the final failure impact not covered by the analysis. The intermediate nodes represent intermediate component failures, and the intermediate nodes include both the intermediate component failures covered by the analysis and the intermediate component failures not covered by the analysis. The leaf nodes represent the initial failure component causes, and the leaf nodes include both the initial failure component causes covered by the analysis and the initial failure component causes not covered by the analysis.
[0024] The analysis results can also include an FMEA analysis hierarchy diagram, which includes a top-level node, at least one layer of intermediate nodes, and a bottom-level node. The top-level node represents the final failure impact, including both the final failure impact covered by the analysis and the final failure impact not covered by the analysis. The intermediate nodes represent intermediate component failures, including both the intermediate component failures covered by the analysis and the intermediate component failures not covered by the analysis. The bottom-level node represents the initial failure component cause, including both the initial failure component cause covered by the analysis and the initial failure component cause not covered by the analysis.
[0025] You can also use different colors or shapes to identify which nodes are covered or not.
[0026] It can also be an FMEA analysis module that includes a structural network analysis module, a functional network analysis module, and / or a failure network analysis module.
[0027] It can also be an FTA analysis module, including a fault tree analysis module.
[0028] A security analysis method integrating FTA and FMEA includes:
[0029] Step 10: Input system parameters;
[0030] Step 20: Perform FTA analysis based on the input parameters and output a list of functional safety requirements;
[0031] Step 30: Perform FMEA analysis based on the functional safety requirements list and output a functional failure mode list.
[0032] It can also include:
[0033] Step 40: Determine whether the functional safety requirement can cover the functional failure mode list. If not, add a new functional safety requirement.
[0034] Step 50: Determine if the current functional safety requirement is redundant. If not, end.
[0035] Step 60: Analyze whether each functional safety requirement corresponds to a specific functional failure mode; if not, add the corresponding functional failure mode.
[0036] Step 70: Determine whether all functional safety requirements have been analyzed. If not, proceed to step 40.
[0037] It can also be a safety analysis method used for automotive safety analysis.
[0038] A readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the security analysis method described in any one of the preceding claims.
[0039] One of the technical effects of the above-mentioned technical solution is that by combining FTA and FMEA safety analysis methods, it is possible to identify unconsidered functional safety requirements or add functional failure modes, and to comprehensively analyze safety by combining the advantages of FTA and FMEA.
[0040] The second technical effect of the above technical solution is that if any missing functional safety requirements are found during the analysis process, they can be added. The newly added functional safety requirements are renumbered and marked as unanalyzed. The newly added functional safety requirements are then subjected to FMEA analysis. After multiple iterations of analysis, the system analysis is completed.
[0041] The third technical effect of the above technical solution is that the output of FTA analysis tree diagram or FMEA analysis hierarchy diagram can be intuitively displayed in a graphical interface. The relationships between systems, intermediate components, the relationship between the initial component failure and the intermediate component failure, and the final failure impact of which component failure, etc., can be clearly seen by the user, allowing the user to clearly see the relationships and impacts.
[0042] The fourth technical effect of the above technical solution is that by adopting the same system and system relationship and security objectives, the analysis results of FTA and FMEA can support and verify each other.
[0043] The fifth technical effect of the above solution is: using different colors or shapes to identify nodes that are covered or not. If the eventual failure of an uncovered node has an impact, it is necessary to consider whether there are any unconsidered security targets, re-enter the security targets, and re-analyze. Attached Figure Description
[0044] Figure 1 This is one of the schematic diagrams of a security analysis system that integrates FTA and FMEA;
[0045] Figure 2 This is the second schematic diagram of a security analysis system that integrates FTA and FMEA.
[0046] Figure 3 This is one of the schematic diagrams of a security analysis method that integrates FTA and FMEA;
[0047] Figure 4 This is the second schematic diagram of a security analysis method that integrates FTA and FMEA;
[0048] Figure 5 This is a schematic block diagram of the functions of an automotive ACC system.
[0049] Figure 6 This is a schematic diagram illustrating the functional analysis results of an automotive ACC system.
[0050] Figure 7 This is a schematic diagram of FTA analysis results;
[0051] Figure 8 This is a schematic diagram of FMEA analysis results. Detailed Implementation
[0052] The contents of this application will be further described in detail below with reference to the accompanying drawings. It should be noted that the following description is of preferred embodiments of the present invention and does not constitute any limitation on the present invention. The description of the preferred embodiments of the present invention is merely an explanation of the general principles of the invention. The use of terms such as "first," "second," and "A," "B," etc., in the present invention is for ease of explanation only and does not represent a temporal or spatial order.
[0053] like Figure 1 A safety analysis system integrating FTA and FMEA includes an input module, a functional safety requirements management module, an FTA analysis module, a functional failure mode management module, and an FMEA analysis module; such as Figure 2The input modules include a system-to-system relationship input module, which obtains external input systems and their relationships; a safety target input module, which obtains external input safety targets; a functional safety requirements management module, which manages the functional safety requirements list, including adding and deleting functional safety requirements; a functional failure mode management module, which manages the functional failure mode list, including adding and deleting functional failure modes; and an FTA analysis module, which performs FTA analysis based on the safety target list and the system relationship list to obtain functional safety... The system comprises several modules: a requirements list, a FMEA analysis module (which performs FMEA analysis based on the system-to-system relationship list and the functional safety requirements list, and outputs a functional failure mode list), a functional failure mode management module (managing the functional failure mode list, including adding and deleting modules), a functional safety requirements management module (determining whether a functional safety requirement covers the functional failure mode list; if not, adding a new functional safety requirement), a functional failure mode management module (analyzing whether each functional safety requirement has a corresponding component and deleting duplicate functional safety requirements), and a functional failure mode management module (analyzing whether each functional safety requirement corresponds to a specific functional failure mode; if not, adding the corresponding functional failure mode).
[0054] like Figure 1 , Figure 2 The input module generates a list of safety targets and a list of system-to-system relationships based on external input. The functional safety requirements management module is responsible for adding and deleting items from the functional safety requirements list. These requirements can be entered when inputting system-to-system relationships, or supplemented or deleted during the analysis process. The failure component management module maintains the functional failure mode list, which includes the causes and effects of component failures. System-to-system relationships can be entered graphically, or a component's parent, sibling, or child components can be entered on the graphical interface.
[0055] The FTA analysis module includes a traditional fault tree analysis module, and may also include other FTA analysis modules. The FMEA analysis module includes a structural network analysis module, a functional network analysis module, and a failure network analysis module.
[0056] like Figure 7 The Fault Tree Analysis (FTA) method is a top-down reliability analysis approach. It starts with the event to be analyzed (the top event), which serves as the root of the fault tree, and traces the causes of the event downwards until the underlying event. However, this method is prone to overlooking the initial cause of the failure in a component, leading to insufficient analysis.
[0057] like Figure 8Failure Mode and Effects Analysis (FMEA) is a systematic activity that analyzes each system, part, or process that makes up a product to identify all potential failure modes and analyze their consequences. This allows for proactive measures to improve product quality and reliability. While this analytical method starts with details and analyzes them meticulously, the ultimate impact of failure is not intuitive and it is easy to get bogged down in the details and fail to see the overall situation.
[0058] By combining FTA and FMEA safety analysis methods, it is possible to identify unconsidered functional safety requirements or add functional failure modes, and to combine the advantages of FTA and FMEA to conduct a comprehensive safety analysis.
[0059] like Figure 1 It also includes output modules, output analysis results; the above system-system relationships include component names, component functions, function failure modes and / or failure modes.
[0060] like Figure 6 The above analysis results include functional safety requirements, newly added functional safety requirements, and functional safety requirement analysis results. For example... Figure 6 The analysis results can be output in a table. Components, functions, failure modes, and failure effects are input information. Safety objectives include SG1, SG2, SG3, and SG4. Functional safety requirements are input. If any missing functional safety requirements are found during the analysis, they can be added. The newly added functional safety requirements are renumbered and marked as unanalyzed. The newly added functional safety requirements are then subjected to FMEA analysis again. After multiple iterations of analysis, the system analysis is completed.
[0061] like Figure 7 The analysis results include an FTA analysis tree diagram, which includes a root node, at least one level of intermediate nodes, and leaf nodes. The root node represents the final failure impact, and the root node of the tree diagram includes the final failure impacts covered by the analysis and the final failure impacts not covered by the analysis. The intermediate nodes represent intermediate component failures, and the intermediate nodes include the intermediate component failures covered by the analysis and the intermediate component failures not covered by the analysis. The leaf nodes represent the initial failure component causes, and the leaf nodes include the initial failure component causes covered by the analysis and the initial failure component causes not covered by the analysis.
[0062] like Figure 8The above analysis results include an FMEA analysis hierarchy diagram, which includes a top-level node, at least one layer of intermediate nodes, and a bottom-level node. The top-level node represents the final failure impact, including both the final failure impact covered by the analysis and the final failure impact not covered by the analysis. The intermediate nodes represent intermediate component failures, including both the intermediate component failures covered by the analysis and the intermediate component failures not covered by the analysis. The bottom-level node represents the initial failure component cause, including both the initial failure component cause covered by the analysis and the initial failure component cause not covered by the analysis.
[0063] The analysis system can be a computer running analysis software. By selecting menu inputs, it can output either an FTA analysis tree diagram or a FMEA analysis hierarchy diagram. Using the same system-to-system relationships and security objectives, the analysis results of FTA and FMEA can support and verify each other. The graphical interface output clearly shows the relationships between systems, intermediate components, the relationship between the initial component failure and intermediate component failures, and the final failure impact on which component failures, etc., allowing users to clearly see the relationships and impacts.
[0064] like Figure 7 , 8 Different colors or shapes are used to identify which nodes are covered or uncovered in the analysis. If the eventual failure of an uncovered node has an impact, it is necessary to consider whether there are any unconsidered security objectives, re-enter the security objectives, and re-analyze.
[0065] like Figure 7 E1 and E2 are indicated by different colors to show components not covered in the analysis. As safety targets E1 and E2, if they are not analyzed, it means that the failure causes of the related intermediate components and the initial components have not been analyzed. This could be due to either incomplete system-to-system relationship inputs, lack of corresponding relationships, or the inability to form a top-down analysis, in which case the system-to-system relationships need to be supplemented; or the failure mode of the initial component C1 has not been clearly analyzed, requiring in-depth analysis of the component failure modes and supplementary inputs.
[0066] like Figure 8 Because the failure mode of C1 is unclear, it is impossible to analyze the final failure impact from low to high. Figure 7 In comparison, it's easy to miss the analysis of C1. By supplementing the C1 functional failure mode analysis and using FMEA analysis, the failure analysis of intermediate components is obtained. This is then correlated with the analysis of E1 to obtain a complete analysis diagram. Through this method, Figure 7 and Figure 8 Ultimately, this will result in a relatively consistent graph.
[0067] like Figure 2The aforementioned FMEA analysis module includes a structural network analysis module, a functional network analysis module, and / or a failure network analysis module. The aforementioned FTA analysis module includes a fault tree analysis module.
[0068] like Figure 3 A security analysis method integrating FTA and FMEA, comprising:
[0069] Step 10: Input system parameters;
[0070] Step 20: Perform FTA analysis based on the input parameters and output a list of functional safety requirements;
[0071] Step 30: Perform FMEA analysis based on the functional safety requirements list and output a functional failure mode list.
[0072] Step 10 may include a step of inputting system-to-system relationships and a step of inputting security objectives. System-to-system relationships are generally relatively fixed and can be input all at once, with supplementary input later. Security objectives are critical requirements.
[0073] In step 20, check if there are any new safety target inputs in the input requirements. If not, perform HARA analysis. Once there are new requirements inputs, perform FTA analysis to extract functional safety requirements and obtain a list of functional safety requirements.
[0074] like Figure 3 In step 10, input the system-to-system relationships and input the security objectives; the input system-to-system relationships and security objectives can be stored in list form, file form, or database.
[0075] When displaying, the relationships between input systems and input security objectives can be shown in the form of images or tables.
[0076] The graphical representation of system relationships clearly shows the connections between systems, making them easier to understand. Furthermore, graphical displays allow for the creation of input interfaces next to components, such as peer, parent, or child components, enabling quick input of information from these components.
[0077] In step 20, based on the input, it is determined whether there are any new safety target inputs. If there are no new safety target inputs, the FTA analysis is performed directly. If there are new safety target inputs, the new safety target needs to be decomposed into functional safety requirements during the FTA analysis. During the decomposition, the safety target is decomposed into components according to the relationship between systems. A component may have multiple functional safety requirements.
[0078] In step 20, based on the input system-to-system relationship and functional safety requirements, FMEA analysis is performed to identify the functional failure modes of the functional safety requirements and compile a list of functional failure modes.
[0079] In practice, the functional safety requirements list and the functional failure mode list can be a single table, with different entries used to differentiate between them.
[0080] like Figure 4 It also includes:
[0081] Step 40: Determine whether the current security requirements can cover component failure. If not, add new functional security requirements.
[0082] Step 50: Determine if the current functional safety requirement is redundant. If not, end.
[0083] Step 60: Analyze whether each functional safety requirement corresponds to a specific functional failure mode; if not, add the corresponding functional failure mode.
[0084] Step 70: Determine whether all functional safety requirements have been analyzed. If not, proceed to step 40.
[0085] In step 40, it is determined whether the current component security covers the failed component. If the failed component is not covered, a new security requirement needs to be added. By automatically traversing the component security to check if it corresponds to the failed component, the software can quickly find the uncovered components. The software requires adding functional security requirements to these components, which can reduce omissions.
[0086] After the software automatically identifies the new security requirements, it prompts the analysts, significantly reducing their workload.
[0087] In step 50, each functional safety requirement is analyzed to see if there is a corresponding failure mode. If there is a corresponding failure mode, the safety requirement is fine, and the analysis ends.
[0088] If a functional safety requirement cannot be matched with a corresponding functional failure mode, meaning that such a failure mode is not possible, then in step 60, analyze whether the functional safety requirement has considered all possible functional failure modes and whether it is necessary to conduct an FMEA analysis. If, after sufficient analysis, it is determined that the functional safety requirement is incorrect, redundant, or a duplicate requirement, merely differing in language description but essentially a duplicate functional safety requirement, then delete the functional safety requirement.
[0089] If the FMEA analysis shows that functional safety requirements affect safety objectives, then it is necessary to add the corresponding functional failure modes to the functional failure mode list and re-analyze the system.
[0090] like Figure 5 The aforementioned safety analysis method is applied to automotive safety analysis. First, based on the vehicle system block diagram, a system-to-system relationship diagram is completed. For example, a car includes a front radar, a forward-facing camera, an ACC system, a brake controller, a power controller, and a parking controller. The front radar senses information such as the type of obstacles; the forward-facing camera senses information and transmits it to the ACC system; the brake controller receives deceleration requests from the ACC system and executes deceleration operations accordingly, while simultaneously sending vehicle speed and system status information to the ACC system; the power controller sends system status information to the ACC system, and the ACC system sends an output torque request to the power controller; the parking controller sends system status information to the ACC system and simultaneously receives parking requests from the ACC system.
[0091] According to Figure 5 It can be seen that for the ACC system to function properly, the cooperation of various components is required. The failure of one or more components will lead to different or the same failure manifestations in the whole vehicle system. The analysis of system safety is relatively complex and has a large workload. Combining the two analysis methods, FTA and FMEA, one analyzes the safety requirements of the whole vehicle system from the top to the bottom, and the other analyzes the failure modes of components from the bottom components to the top. By jointly utilizing system-to-system relationship data, functional failure mode data, and component safety requirement data, a 1+1 is greater than 2 effect is formed.
[0092] like Figure 6 ,Will Figure 5 The relationships between systems are presented in a table and input into the analysis system. After analysis, a failure mode of the power controller is found that lacks a corresponding functional safety requirement. Therefore, the functional safety requirement is added, and the analysis is repeated. This process is repeated until all functional failure modes and functional safety requirements have been analyzed. At the end of the analysis, the system will give a prompt indicating that the analysis has ended. This can drive people to conduct a comprehensive analysis of the overall safety performance of the car.
[0093] Figure 6 In the table, security targets are relatively stable and are fixed as column items. In the diagram, SG1, SG2, SG3, and SG4 are the security target numbers. Each security target has detailed descriptive information and is managed in a separate table. Figure 6The table lists the safety objective numbers. We can see that the failure modes and effects of many components impact multiple safety objectives. Although different symbols, such as " / " and "o," are used to indicate whether there is an impact, the representation of components, functional failure modes, safety objectives, functional safety requirements, whether analysis has been performed, whether the analysis results are "OK," and whether new functional safety requirements need to be added is not intuitive enough. However, through... Figure 7 or Figure 8 This hierarchical representation allows for a quick and intuitive understanding of various relationships. By modifying a relationship in a table or diagram, the effects on related levels are automatically linked, significantly reducing the workload and difficulty for analysts.
[0094] A readable storage medium having a computer program stored thereon, which is executed by a processor using the security analysis method described above.
[0095] While the present invention has been described and illustrated with reference to preferred embodiments and several alternatives, the invention is not limited to the specific descriptions herein. Other alternatives or equivalent components may also be used to practice the invention.
Claims
1. A safety analysis system integrating FTA and FMEA for automotive safety analysis, characterized in that, It includes an input module, a functional safety requirements management module, an FTA analysis module, a functional failure mode management module, a FMEA analysis module, and an output module; The input module includes a system-to-system relationship input module, which obtains external input systems and relationships to form a list of system-to-system relationships; The input module includes a security target input module, which obtains externally input security targets and forms a security target list; The Functional Safety Requirements Management module manages the list of functional safety requirements, including adding and deleting functional safety requirements; The FTA analysis module performs FTA analysis based on the list of safety objectives and the list of system relationships to obtain a list of functional safety requirements. The FMEA analysis module performs FMEA analysis based on the system-to-system relationship list and the functional safety requirements list, and outputs a list of functional failure modes. The Functional Failure Mode Management module manages the list of functional failure modes, including adding and deleting functional failure modes. The functional safety requirements management module determines whether the functional safety requirements can cover the list of functional failure modes. If not, it adds new functional safety requirements. The Functional Failure Mode Management module analyzes whether each functional safety requirement has a corresponding component and deletes duplicate functional safety requirements. The Functional Failure Mode Management module analyzes whether each functional safety requirement corresponds to a specific functional failure mode; if not, it adds the corresponding functional failure mode. And, the output module, which outputs the analysis results; The system-to-system relationships include component names, component functions, function failure modes, and / or failure modes.
2. The security analysis system according to claim 1, characterized in that, The analysis results include functional safety requirements, newly added functional safety requirements, and functional safety requirement analysis results.
3. The security analysis system according to claim 1, characterized in that, The analysis results include an FTA analysis tree diagram, which includes a root node, at least one level of intermediate nodes, and leaf nodes; the root node represents the final failure impact, and the root node of the tree diagram includes the final failure impacts covered by the analysis and the final failure impacts not covered by the analysis. Intermediate nodes represent intermediate component failures, including both covered and uncovered intermediate component failures; leaf nodes represent the initial cause of the failure, including both covered and uncovered initial cause of the failure.
4. The security analysis system according to claim 1, characterized in that, The analysis results include an FMEA analysis hierarchy diagram, which includes a top-level node, at least one intermediate layer node, and a bottom-level node. The top-level node represents the final failure impact, which includes both the final failure impacts covered by the analysis and the final failure impacts not covered by the analysis. Intermediate layer nodes represent intermediate component failures, including both covered and uncovered intermediate component failures; bottom layer nodes represent the initial cause of the faulty component, including both covered and uncovered initial cause of the faulty component.
5. The security analysis system according to claim 3 or 4, characterized in that, Use different colors or shapes to identify nodes that are covered or not covered in the analysis.
6. The security analysis system according to claim 1 or 2, characterized in that, The FMEA analysis module includes a structural network analysis module, a functional network analysis module, and / or a failure network analysis module.
7. The security analysis system according to claim 1 or 2, characterized in that, The FTA analysis module includes a fault tree analysis module.
8. A security analysis method integrating FTA and FMEA, used to implement the security analysis system as described in any one of claims 1 to 7, characterized in that, include: Step 10: Input system parameters; Step 20: Perform FTA analysis based on the input parameters and output a list of functional safety requirements; Step 30: Perform FMEA analysis based on the functional safety requirements list and output a functional failure mode list.
9. The security analysis method according to claim 8, characterized in that, Also includes: Step 40: Determine whether the functional safety requirement can cover the functional failure mode list. If not, add a new functional safety requirement. Step 50: Determine if the current functional safety requirement is redundant. If not, end. Step 60: Analyze whether each functional safety requirement corresponds to a specific functional failure mode; if not, add the corresponding functional failure mode. Step 70: Determine whether all functional safety requirements have been analyzed. If not, proceed to step 40.
10. A readable storage medium having a computer program stored thereon, characterized in that, When executed by the processor, the program implements the security analysis method as described in any one of claims 8 or 9.