A Safety Analysis Method for AADL Fault Modeling in Intelligent Vehicles

CN117610291BActive Publication Date: 2026-08-14EAST CHINA NORMAL UNIV
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-11-30
Publication Date
2026-08-14

AI Technical Summary

Technical Problem

存在着以下一些缺陷:安全分析通常是一个主观的过程,可能依赖于分析人员的专业经验和判断力

Benefits of technology

[0033]步骤D1:通过拓展属性集对相应故障模式补充FMEDA所需的额外属性;

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117610291B_ABST
    Figure CN117610291B_ABST
Patent Text Reader

Abstract

This invention discloses a safety analysis method for AADL fault modeling in intelligent vehicles. Its key feature is the use of AADL fault modeling and FMEA / FMEDA safety analysis frameworks to optimize the design of intelligent vehicle products and support safety analysis. Specifically, it includes: design or evaluation in the product concept phase; modeling the system layer, software layer, and hardware layer in AADL; FMEA and FMEDA analysis of the AADL phased system model; and iterative improvement of the system design based on the results of FMEA and FMEDA safety analysis. Compared with existing technologies, this invention optimizes quality control in product development and production to reduce failure costs, improves system safety and reliability, and further reduces design costs, demonstrating significant application market and development value.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of system safety analysis technology, and in particular to a safety analysis method for intelligent vehicles using AADL fault modeling and FMEA / FMEDA framework. Background Technology

[0002] Safety analysis is a systematic approach designed to identify and assess potential safety issues to help ensure system safety. It is an essential step in various industries, such as preliminary system safety assessment (SAE ARP 4761) in the aerospace industry and functional safety analysis (ISO 26262) in the automotive electronics industry. Safety analysis should be conducted at the earliest stage, alongside design activities, and is considered one of the most valuable parts of the development process. Appropriate and sufficient safety analysis can help functional safety development better achieve functional safety objectives. ISO 26262 requires the use of deductive and inductive methods for safety analysis and recommends FMEA (Failure Mode and Effects Analysis) and FTA (Fault Tree Analysis) for these two types of analysis, respectively. Furthermore, ISO 26262 recommends the use of FMEDA (Failure Mode Effects and Diagnostic Analysis) for failure analysis of random hardware components in electronic components.

[0003] Despite advancements in security analysis methodologies, current approaches still face challenges and limitations. These limitations include: security analysis is often a subjective process, potentially relying on the analyst's expertise and judgment. This can lead to inconsistent results and introduce bias; security analysis is often conducted manually, a time-consuming process that doesn't always allow for the analysis of every potential hazard or failure mode. Consequently, some hazards may be overlooked or missed, potentially leading to unsafe conditions; security analysis relies on historical data, such as failure rates or incident statistics, for predicting and identifying potential hazards. However, in some cases, this data may be limited or unavailable, making comprehensive analysis difficult; security analysis should be integrated with the system development process to ensure early identification and mitigation of potential hazards and failure modes. However, this can be difficult to achieve in practice, especially in large, complex projects with multiple stakeholders and competing priorities; when using multiple security analysis methods, it may sometimes be necessary to analyze the same component or system multiple times. The inability to perform multiple security analysis methods simultaneously can lead to duplication of work and unnecessary waste of resources.

[0004] AADL (Architecture Analysis and Design Language) is a modeling language for embedded real-time systems. It boasts advantages such as simple syntax, precise semantics, powerful functionality, and scalability. It can model and describe the functional and non-functional attributes of embedded software and enable system analysis and verification early in development. EMV2 (Error Model Annex Version 2) extends the core AADL language to support error behavior modeling. Its goal is to automate safety analysis methods by supporting analyzable architectural fault models. It allows users to extend hazard, fault propagation, fault modes, and fault impacts to components within the system and software architecture expressed in AADL, and to combine fault behavior specifications to facilitate incremental and scalable automated safety analysis.

[0005] Therefore, the AADL-based security analysis method has proven to be a good choice, as it is performed during the system design phase and is much less costly than applying it in the later stages of the system development process. Research shows that EMV2 excels in security analysis at the architectural level compared to some existing security analysis techniques.

[0006] Early safety analysis tools based on AADL and EMV2 could automatically perform FTA, FHA, and FMEA analyses to assess system safety by combining AADL system models and EMV2 fault models. While the automation of these safety analyses has made some progress, over time, the shortcomings and challenges of this approach have begun to emerge, including the following issues:

[0007] 1) Incomplete security analysis results. The impact of root-level faults can only be analyzed down to other components at the same level as the root component, and cannot be analyzed to analyze the impact of faults on higher-level system components.

[0008] 2) Outdated standards. In 2019, AIAG and VDA jointly standardized the FMEA methods previously used by different companies, proposing a seven-step FMEA standard. Their FMEA analysis tools are no longer capable of performing security analysis according to the latest FMEA standards.

[0009] 3) It cannot reveal all system component failures. Existing FMEA methods start from a failure mode of a root component and deduce the failure effects. Most system defects are found as a single system component failure, while multi-point component failures cannot be analyzed. This may cause inconsistencies between the results of FMEA and FTA analysis.

[0010] 4) It cannot fully display the causal network of the entire system's failures.

[0011] 5) There are no technical means to perform FMEDA analysis on random hardware failures in the AADL system model.

[0012] Therefore, in light of the shortcomings and challenges faced by intelligent vehicles based on the AADL safety analysis method, there is an urgent need for a method that can support the implementation of standard FMEA / FMEDA safety analysis of AADL intelligent vehicle fault models. Summary of the Invention

[0013] The purpose of this invention is to address the shortcomings of existing technologies by proposing a safety analysis method for intelligent vehicles using AADL fault modeling. This method employs AADL fault modeling and the FMEA / FMEDA safety analysis framework to optimize the design of intelligent vehicle products and support safety analysis. Based on the ISO 26262 international standard "Functional Safety of Road Vehicles," this invention first defines relevant items according to the standard, clarifying the system composition, functions, interfaces, and boundaries of the research object, and then performs system structure modeling in AADL. Next, hazard analysis and risk assessment are conducted. Fault tree analysis generated by AADL fault modeling identifies the hazards that may result from the functional failure of relevant items, and ASIL level assessments are performed on the hazards according to the operating scenarios to obtain the safety objectives for relevant items. For functional failures of system components, FMEA analysis is used to promptly identify, assess, and optimize all possible risks to the system. For underlying hardware that violates safety objectives, FMEDA analysis is used to calculate the system's hardware architecture metrics to assess and verify the violation of safety objectives caused by random hardware failures. Based on the analysis results of FMEA and FMEDA, a series of iterative improvements to the product design are made through design optimization and analytical calculations. This invention is applicable to the functional safety of electronic and electrical systems in road vehicles. It optimizes quality control in product development and production processes to reduce failure costs, improve system safety and reliability, and is simple to implement with good results. It further reduces design costs and has good application market and development value.

[0014] The objective of this invention is achieved as follows: a safety analysis method for AADL fault modeling in intelligent vehicles, including an autonomous driving system, characterized by employing AADL fault modeling and FMEA / FMEDA safety analysis frameworks to iteratively optimize the design of the autonomous driving system, thereby achieving design optimization of the intelligent vehicle product. The method specifically includes the following steps:

[0015] Step 1: Conduct product concept design or evaluation;

[0016] Step 2: Model the system layer, software layer, and hardware layer in AADL to gradually improve the system architecture;

[0017] Step 3: Perform FMEA analysis on the AADL phased system model;

[0018] Step 4: Perform FMEDA analysis on the AADL phased system model;

[0019] Step 5: Based on the results of the security analysis of FMEA and FMEDA, optimize and iterate the product design to support the security analysis.

[0020] The design or evaluation of the product concept phase in step one specifically includes the following steps:

[0021] Step A1: Complete the project definition;

[0022] Step A2: Obtain the safety objectives and their ASIL levels through hazard analysis and risk assessment;

[0023] Step A3: Complete the functional safety concept definition.

[0024] Step two involves modeling the system layer, software layer, and hardware layer in AADL to gradually improve the system architecture. Specifically, this includes the following steps:

[0025] Step B1: Refine and decompose security requirements and assign them to different system elements;

[0026] Step B2: Establish the hierarchical structure model of the AADL system;

[0027] Step B3: Add fault behavior modeling to system elements to support various security analysis methods.

[0028] Step three, performing FMEA analysis on the AADL phased system model, specifically includes the following steps:

[0029] Step C1: Supplement the corresponding failure mode with additional attributes required by FMEA by expanding the attribute set;

[0030] Step C2: Use the FMEA tool to analyze the system instantiation instance file;

[0031] Step C3: If the attributes for FMEA analysis were not supplemented through step C1, the FMEA tool can still be used to select the focus component of the system instance file for analysis.

[0032] Step four, performing FMEDA analysis on the AADL phased system model, specifically includes the following steps:

[0033] Step D1: Supplement the corresponding failure mode with additional attributes required by FMEDA by expanding the attribute set;

[0034] Step D2: Calculate the failure rate and failure mode percentage of the unknown component using the maximum likelihood estimation method;

[0035] Step D3: Use the FMEDA tool to analyze the system instantiation instance file.

[0036] Compared with the prior art, the present invention has the following beneficial technical effects and significant technical progress:

[0037] 1) This invention uses AADL for system architecture modeling during the system modeling and security analysis phases, and EMV2 for modeling the error behavior of system components. It integrates security analysis with the system development process, resulting in an analyzable architecture failure model to support security analysis. It supports early, coarse designs and allows for incremental improvements to the system structure and failure behavior during development until a detailed description of all aspects of the system is obtained. A consistent, up-to-date model is formed throughout the development process, and incremental and scalable security analysis is performed. This ensures the consistency and effectiveness of the security analysis results with respect to the system architecture model, improving system development efficiency.

[0038] 2) This invention develops an FMEA analysis tool conforming to the new AIAG-VDA standard, which has the following features: 1. Supports the entire process of the new AIAG-VDA FMEA seven-step method; 2. Incorporates the failure impact analysis of multi-point faults, and can generate a complete fault causal network, ensuring the consistency between FMEA analysis results and FTA analysis results; 3. Ensures the completeness of the derivation of the impact of root-level faults on higher-level system faults; 4. High versatility; this tool can be used for rapid FMEA analysis of any AADL system model that has completed fault modeling and can undergo FTA analysis.

[0039] 3) This invention develops an FMEDA analysis tool to analyze random hardware failures in the AADL system model. It combines the fault causal network generated by the FMEA tool, starts from the top event that violates the security objectives, obtains the set of underlying security-related hardware, automatically calculates hardware architecture indicators and evaluates whether they meet the requirements of the current security objectives.

[0040] 4) The FMEA and FMEDA analysis tools developed in this invention are also based on EMV2, just like the existing FTA analysis tools. On the basis of completing the FTA fault modeling, they expand the relevant attribute set to perform incremental modeling, supplement the attributes required for fault modes during FMEA and FMEDA analysis, avoid the repetitive work of fault modeling, and greatly improve the efficiency of safety analysis methods. Attached Figure Description

[0041] Figure 1 This is a schematic diagram of the process of the present invention;

[0042] Figure 2 This is a preliminary model diagram of an autonomous vehicle;

[0043] Figure 3 Example of allocating safety objectives and functional safety requirements;

[0044] Figure 4 A schematic diagram of a general structure for safety requirements;

[0045] Figure 5 This is a schematic diagram of the AIAG-VDA standard FMEA seven-step process.

[0046] Figure 6 A fault cause-effect network diagram for the optimized system;

[0047] Figure 7 An optimized model diagram for an autonomous driving system;

[0048] Figure 8 Screenshots of the user interfaces for the FMEA and FMEDA tools. Detailed Implementation

[0049] The present invention will be further described in detail below with reference to the specific embodiments and accompanying drawings. Except for the contents specifically mentioned below, the processes, conditions, and experimental methods for implementing the present invention are all common knowledge and general knowledge in the art, and the present invention does not have any particular limitations.

[0050] Example 1

[0051] See Figure 1 An AADL fault modeling and FMEA / FMEDA safety analysis framework for intelligent vehicles includes the following steps:

[0052] Step 1: Conduct product concept design or evaluation;

[0053] Step 2: Model the system layer, software layer, and hardware layer in AADL to gradually improve the system architecture;

[0054] Step 3: Perform FMEA analysis on the AADL phased system model;

[0055] Step 4: Perform FMEDA analysis on the AADL phased system model;

[0056] Step 5: Based on the results of the FMEA and FMEDA security analysis, optimize and iterate the system design to improve the product design.

[0057] The method for designing or evaluating the product concept stage in step one includes the following steps:

[0058] Step A1: Complete the project definition

[0059] Define and describe the project, and its relevance and interaction with the environment and other projects, to ensure that each activity defined in the safety lifecycle is implemented accurately; the project definition covers the project's functions, interfaces, environmental conditions, regulatory requirements, and hazards.

[0060] See Figure 2 The system considered in this example is a simplified autonomous vehicle that captures images while the car is in motion to detect obstacles on the road. It uses a speed sensor to detect the car's actual speed and activate acceleration or braking. If an obstacle is detected approaching, the car will brake (the braking force varies with the distance between the car and the obstacle). If there is no obstacle, acceleration can be activated. The car also includes entertainment features (such as music) and screens that provide feedback to passengers (such as actual speed and desired speed). Passengers can use the panel to set the desired speed and can also connect to and interact with external devices.

[0061] Step A2: Obtain safety objectives and their ASIL levels through hazard analysis and risk assessment.

[0062] The project is assessed based on potential risk events. Safety objectives are determined and their corresponding ASIL levels are assigned through a systematic evaluation of hazardous events to avoid unreasonable risks. The HAZOP method is used to analyze functional failures of relevant items based on defined keywords to identify vehicle-wide hazards. Vehicle-wide hazards are combined with specific scenarios to form hazard events, and each hazard event is rated on ASIL levels using three dimensions: Severity (S), Exposure (E), and Controllability (C). A safety objective is determined for each hazard event with an ASIL level; the ASIL level of the safety objective is derived from the hazard analysis.

[0063] After completing step A1, the safety objective of the driving system is obtained through hazard analysis and risk assessment: "The car can safely perform automatic driving", with an ASIL level of D.

[0064] Step A3: Complete the functional safety concept definition

[0065] See Figure 3 Functional safety requirements are derived from safety objectives and assigned to the initial architectural elements or external measures of the project. To meet safety objectives, functional safety concepts include safety measures (including safety mechanisms), which will be implemented in the architectural elements of the project.

[0066] Step two, which involves modeling the system layer, software layer, and hardware layer in AADL to gradually improve the system architecture, includes the following steps:

[0067] Step B1: Refine and decompose security requirements and assign them to different system elements.

[0068] See Figure 4 From the system layer to the software and hardware layers, the functional safety requirements allocated to the system are refined into technical safety requirements allocated to subsystems, and then further refined into hardware and software safety requirements. The system's hardware and software safety requirements after the initial design and step five iteration are detailed in Table 1 below:

[0069] Table 1: Correspondence between Software and Hardware Security Requirements

[0070]

[0071] Among them, obstacle_dection, obstacle_radar, and laser_sensor are system components added in step five iteration.

[0072] Step B2: Establish the hierarchical structure model of the AADL system

[0073] Based on security requirements and objectives, the AADL language is used to describe the various components of the system and the interactions between them, including hardware, software, and data flow, and to organize them into a hierarchical system.

[0074] Step B3: Add fault behavior modeling to system elements to support various security analysis methods

[0075] Based on existing experience or industry standards, add EMV2 fault behavior modeling to each element of the system. This includes error events, error states, and error propagation mechanisms (Propagation Conditions, Transitions). The fault behavior model for each component describes how a fault in that component is caused by a combination of faults in the component's input and / or within the component itself. Each component's error state, as its fault mode, should be designed to violate a specific safety requirement assigned to that component.

[0076] After refining and decomposing security requirements and assigning them to different system elements, each component of the system has assigned security requirements and failure modes that violate those requirements. Based on the above, architecture modeling and fault behavior modeling are performed in AADL. After adding FMEA and FMEDA attributes, analysis can be performed. For details on the user interfaces of the FMEA and FMEDA tools, please refer to the appendix. Figure 8 As shown.

[0077] The method for performing FMEA analysis on the AADL stage system model in step three includes the following steps:

[0078] Step C1: Supplement the corresponding failure mode with additional attributes required by FMEA by expanding the attribute set.

[0079] C1-1: Assign the corresponding security requirement attribute to the component's error state, which will be represented in the functional analysis.

[0080] C1-2: Evaluate the failure modes of related upper-level components and assign a severity S; evaluate the failure modes of related lower-level components and assign occurrence O and detectability D attributes.

[0081] C1-3, add preventative and detection measures as needed, and optimize and update attributes.

[0082] Step C2: Use the FMEA tool to analyze the system instantiation instance file.

[0083] See Figure 5 After selecting a focus component, FMEA analysis can be performed. The tool will read the model data and automatically perform the seven-step FMEA analysis: planning and preparation, structural analysis, functional analysis, failure analysis, risk analysis, and optimization. The final results are documented as an FMEA table. Some of the system's results after FMEA analysis and optimization are detailed in Table 2 below:

[0084] Table 2 FMEA Analysis and Optimization Results Report

[0085]

[0086] By analyzing some of the results of the optimized system using the FMEA analysis described above, the potential impact of failure modes can be assessed, helping to identify which failures require urgent attention and prioritize them. This facilitates focusing resources on the most pressing issues to minimize the impact on the system or process.

[0087] Step C3: If the attributes for FMEA analysis were not supplemented through step C1, the FMEA tool can still be used to analyze the focus components of the system instance file. The FMEA tool can perform structural analysis, functional analysis, and failure analysis in the seven-step method based on the existing model and present the analysis results in a table.

[0088] In the FMEA tool's user interface, you can check "show the whole failure net in graphical view" to display the entire failure causal network diagram of the system.

[0089] See Figure 6 The fault cause-effect network diagram of the optimized system drawn using the FMEA tool has the following advantages:

[0090] 1) It helps analyze the causes of system failures, thereby helping engineers to diagnose failures more quickly and accurately.

[0091] 2) It can provide decision support for managers, helping them to better understand the operation of the system and thus make more informed decisions.

[0092] 3) Reveal the bottlenecks and weaknesses in the system, helping designers optimize the system design and improve the system's performance and reliability.

[0093] 4) Help the team share their understanding and knowledge of the system, thereby improving the team's collaboration efficiency.

[0094] The method for performing FMEDA analysis on the AADL staged system model in step four includes the following steps:

[0095] Step D1: Add the additional attributes required by FMEDA for the corresponding failure mode.

[0096] By expanding the attribute set, additional attributes required by FMEDA are added to the corresponding failure modes, specifically including: the failure rate of each component, the failure percentage of each component for each failure mode, single-point safety mechanisms and their coverage, and multi-point safety mechanisms and their coverage.

[0097] Step D2: Calculate the failure rate and failure mode percentage of the unknown component using the maximum likelihood estimation method.

[0098] The failure rate of a component and the proportion of different failure modes can generally be obtained from relevant standards or manufacturers. If these methods are not available, estimation using historical sample data is necessary. The frequency of observed component failures in a sample is typically used as an estimate of the component's failure rate. For example, given a dataset of n samples where failures occurred k times, the failure frequency is f = k / n. This is an intuitive estimation method and is usually very effective in practice. However, frequency estimation is not always the most accurate method because it does not consider underlying model assumptions and data distribution. In contrast, Maximum Likelihood Estimation (MLE) is a model-based parameter estimation method that considers data distribution and estimates model parameters based on the probability distribution function of a given model. Under certain assumptions, MLE can yield optimal parameter estimates and is therefore usually more accurate than frequency estimation.

[0099] Step D3: Use the FMEDA tool to analyze the system instantiation instance file.

[0100] D3-1: Select a security objective of the current system for FMEDA analysis;

[0101] D3-2: Based on the fault cause-and-effect network provided by the FMEA tool, the tool will identify which components in the system are safety-related;

[0102] D3-3: Determine whether a failure mode is a single point of failure or a multi-point failure by finding the minimum cut set of the fault tree with the safety objective as the top-level event;

[0103] D3-4: Calculate the Single Point of Failure Metric (SPFM), Latent Failure Metric (LFM), and Hardware Random Failure Rate (PMHF) based on additional security mechanisms and failure rate attributes.

[0104] D3-5: Determine whether the system meets the ASIL level of the current security objectives based on Table 3 below.

[0105] Table 3. Evaluation Indicators for Different Security Levels

[0106]

[0107] D3-6: Finally, output the entire analysis results in tabular form. The preliminary FMEDA analysis results of the system design are detailed in Table 4 below:

[0108] Table 4. FMEDA Analysis Results Report for Preliminary System Design

[0109]

[0110] The FMEDA analysis results of the preliminary design show that the system's single-point failure rate is 68.87%, far below the ASIL D safety target. The FMEDA analysis reveals that only the accelerator and brake have the safety mechanism SM1 "fault detection and isolation." The lack of corresponding safety mechanisms for the wheel speed sensor and obstacle camera results in a very high single-point failure rate, making these two areas the main weaknesses in the system design. Enhanced safety monitoring mechanisms are needed in system improvements.

[0111] Step five involves iteratively optimizing the system design based on the results of FMEA and FMEDA security analyses. The method for improving product design includes the following steps:

[0112] Based on the FMEDA analysis results, components exhibiting high single-point failure rates or potential multi-point failure rates are considered system weaknesses. These weaknesses cause the system's hardware architecture to fail to meet ASIL safety target requirements. Adding single-point or multi-point safety mechanisms can resolve this issue. To ensure system reliability, this embodiment implements the following optimization measures after identifying system weaknesses based on FMEDA:

[0113] 1) Add a redundant laser sensor (laser_sensor) to the wheel sensor and design a speed voter process to remove erroneous data and avoid single point of failure.

[0114] 2) Add redundant laser ranging radar obstacle_radar to the obstacle detection camera and design the obstacle detection process obstacle_detection to avoid single point of failure.

[0115] See Figure 7 The optimized model of the autonomous driving system and the FMEDA results of the optimized system design are detailed in Table 5 below;

[0116] Table 5. FMEDA Analysis Results Report After System Design Optimization

[0117]

[0118] According to the FMEDA results of the optimized system design in Table 5 above, the single point of failure rate is 99.467%, the latent failure rate is 99.79%, and the random hardware failure rate is 1.56%, which meets the requirements of ASIL D safety objectives.

[0119] In FMEA analysis, a higher AP value indicates a greater risk to the system from the corresponding failure mode, requiring priority to be given to corrective actions to mitigate this risk. By adding prevention and detection mechanisms, the incidence and impact of the corresponding failure modes in the system can be comprehensively reduced, thereby lowering the system's risk level, improving its reliability and security, and enhancing its stability and availability.

[0120] This invention is based on the ISO 26262 international standard, "Functional Safety of Road Vehicles." First, it defines relevant items according to the standard, clarifying the system composition, functions, interfaces, and boundaries of the research object, and models the system structure using the Automatic Automation and Degradation Model (AADL). Second, it conducts hazard analysis and risk assessment, using fault tree analysis generated from AADL fault modeling to identify potential hazards caused by functional failures of relevant items. Based on the operating scenario, it assesses the ASIL level of the hazards to obtain the safety objectives for relevant items. For functional failures of system components, FMEA analysis is used to promptly identify, assess, and optimize all possible system risks. For underlying hardware that violates safety objectives, FMEDA analysis is used to calculate the system's hardware architecture metrics to assess and verify the safety objectives violated due to random hardware failures. Based on the analysis results of FMEA and FMEDA, a series of iterative improvements to the product design are made, including design optimization and analytical calculations. This invention is applicable to the functional safety of electronic and electrical systems in road vehicles. Using this method can optimize quality control in product development and production processes to reduce failure costs and improve system safety and reliability.

[0121] The scope of protection of this invention is not limited to the above embodiments. Any variations and advantages that can be conceived by those skilled in the art without departing from the spirit and scope of the inventive concept are included in this invention and are protected by the appended claims.

Claims

1. A safety analysis method for AADL fault modeling in intelligent vehicles, including an autonomous driving vehicle system, characterized in that, This paper employs the AADL fault modeling, FMEA, and FMEDA safety analysis frameworks to iteratively optimize the design of autonomous vehicle systems, thereby achieving design optimization of intelligent vehicle products. The specific steps of this method are as follows: Step 1: Design or evaluation in the product concept phase; Step 2: Model the system layer, software layer, and hardware layer in AADL; Step 3: Perform FMEA analysis on the AADL phased system model; Step 4: Perform FMEDA analysis on the AADL phased system model; Step 5: Based on the safety analysis results of FMEA and FMEDA, iterate on the autonomous vehicle system, improve the system design, optimize the design of intelligent vehicle products, and support safety analysis. Step three involves performing FMEA analysis on the AADL phased system model, specifically including the following steps: Step C1: Supplement the FMEA with additional attributes required for the corresponding failure mode by expanding the attribute set; Step C2: Use the FMEA tool to analyze the system instantiation instance file; Step C3: If the attributes analyzed in step C1 were not supplemented, use the FMEA tool to select the focus component of the system instance file for analysis; Step four, performing FMEDA analysis on the AADL phased system model, specifically includes the following steps: Step D1: Supplement the corresponding failure mode with additional attributes required by FMEDA by expanding the attribute set; Step D2: Calculate the failure rate and failure mode percentage of the unknown component using the maximum likelihood estimation method; Step D3: Use the FMEDA tool to analyze the system instantiation instance file.

2. The safety analysis method for AADL fault modeling for intelligent vehicles according to claim 1, characterized in that, The design or evaluation of the product concept phase in step one specifically includes the following steps: Step A1: Complete the project definition; Step A2: Obtain the safety objectives and their ASIL levels through hazard analysis and risk assessment; Step A3: Complete the functional safety concept definition.

3. The safety analysis method for AADL fault modeling for intelligent vehicles according to claim 1, characterized in that, Step two of the AADL involves modeling the system layer, software layer, and hardware layer, specifically including the following steps: Step B1: Refine and decompose security requirements and assign them to different system elements; Step B2: Establish the hierarchical structure model of the AADL system; Step B3: Add fault behavior modeling to system elements to support various security analysis methods.