Model-based aircraft functional hazard analysis method and apparatus
By combining functional hazard analysis with event sequence modeling, an aircraft functional hazard analysis model is automatically acquired and constructed, solving the explicitness problem of traditional analysis methods, realizing the automatic generation of safety and mission reliability requirements, and improving the accuracy and efficiency of the analysis.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- CHINA AERO POLYTECH ESTAB
- Filing Date
- 2023-11-30
- Publication Date
- 2026-05-26
AI Technical Summary
Traditional aircraft functional hazard analysis relies mainly on human experience. The analysis process is not explicit enough, and the development path from functional failure state to accident consequences cannot be intuitively judged, making it difficult to adapt to model-based aircraft development models.
By combining functional hazard analysis with event sequence modeling, the system automatically acquires functional models, identifies functional failure states, determines initiating events and their attributes, constructs event sequence models, and automatically generates safety and task reliability requirements.
It enables the automatic generation of functional hazard analysis results, improving the accuracy and efficiency of the analysis, and can intuitively display the accident evolution path, reducing manual complexity.
Smart Images

Figure CN117786838B_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the field of system safety technology, and specifically relates to a model-based method and apparatus for analyzing functional hazards of aircraft. Background Technology
[0002] Aircraft development is a complex systems engineering project. It not only needs to meet the aircraft's intended use objectives but also comply with relevant mandatory airworthiness requirements. Airworthiness, particularly regarding safety requirements, necessitates that the design of aircraft systems and related components ensures they can perform their intended functions under all foreseeable operating conditions, and that the probability of any failure state that would prevent the aircraft from continuing safe flight and landing is extremely low. Furthermore, because it concerns the lives of the aircraft and its occupants, safety is the most critical characteristic in aircraft development. Especially with the continuous development of aviation technology, new technologies, materials, and processes are constantly emerging, and the degree of system integration is increasing. Therefore, it is essential to employ effective safety analysis methods and processes to identify hazards, assess risks, and determine risk mitigation measures, thereby reducing accident risks to an acceptable safety level from an aircraft development perspective.
[0003] The aircraft system safety assessment process mainly includes aircraft functional hazard analysis, preliminary aircraft safety assessment, system functional hazard analysis, preliminary system safety assessment, system safety assessment, and aircraft safety assessment. Among these, functional hazard analysis is the most critical and primary activity in the entire system safety assessment. This analysis takes the results of aircraft or system functional analysis as input, analyzes the possible consequences of different functional failure states, classifies the impact of different failure states according to severity levels, determines the corresponding probability control levels, and the results of functional hazard analysis will determine the objectives of the entire system safety assessment.
[0004] Traditional functional hazard analysis in system safety analysis is mainly based on experience. Before the analysis, the aircraft's operational profile, relevant assumptions, and safety level classification are determined. Functional failure states in the functional decomposition structure of the aircraft or system are identified in a form. Each functional failure state is analyzed in turn, along with other functional failure states that may be coupled with or backed up by the failure state, as well as external events. This allows for a description of the possible consequences of the failure state, which is generally analyzed from several dimensions, such as the impact on the aircraft, the pilot, and the personnel on board. Finally, the safety level of the failure state is given, and relevant supporting materials or data are used as the basis for determining the safety level.
[0005] In recent years, with the gradual application of digitalization and Model-Based Systems Engineering (MBSE) in aircraft development, model-based approaches have been used to varying degrees in the aircraft development process and are gradually becoming the main development model in the future. Therefore, how to utilize existing models to conduct functional hazard analysis and simplify functional hazard analysis has become a key issue that needs to be considered in subsequent aircraft development. At the same time, since traditional functional hazard analysis is mainly based on human experience, there are problems such as insufficient explicitness of the analysis process and the inability to intuitively judge the development path from functional failure state to accident consequences. However, by using a model-based approach, we can not only connect with functional models, but also effectively express the accident simulation process of functional failure state, thereby promoting the adaptation of functional hazard analysis to the model-based aircraft development model, standardizing the functional hazard analysis process, and improving the accuracy and rationality of functional hazard analysis.
[0006] In summary, this invention proposes a model-based method and apparatus for aircraft functional hazard analysis to support the application of system safety analysis in the aircraft development process under a model-based development model. Summary of the Invention
[0007] To address the shortcomings of existing technologies, this invention combines functional hazard analysis processes with event sequence modeling to provide a model-based method for aircraft functional hazard analysis, specifically including the following steps:
[0008] Step 1: Determine the basic data for functional hazard analysis;
[0009] Basic data is pre-stored in the database, including flight phase data, safety impact data, mission reliability impact data, and external event data;
[0010] After browsing or modifying the basic data pre-existing in the database, confirm the changes.
[0011] Step 2: Automatically acquire the functional model;
[0012] When obtaining the functional model, firstly, based on the functional decomposition structure model in the functional model, the lowest level functional modules are identified to obtain the functions; then, based on the functional flow model in the functional model, the functions related to the function are identified to obtain the relationship between different functions.
[0013] Step 3: Define the function failure status according to the function definition;
[0014] For the functions identified in step two, a corresponding function failure state is defined for each function by selecting a predetermined function failure description, and the function and the corresponding function failure state are saved to the function failure state list in the database.
[0015] Step 4: Identify the initial event and obtain its attributes;
[0016] The functional failure states identified in step three are used as initial cause events. Each initial cause event includes the following attributes:
[0017] 1) Function, which is obtained from the functions corresponding to the function failure status in the function failure status list;
[0018] 2) Function failure state, which is a function failure state in the list of function failure states. Each function failure state plus function in the list of function failure states is defined as an initiating event.
[0019] 3) Flight phase, which is the phase in which functional failure occurs under this initial cause event;
[0020] 4) Scenario activities, which are the operational backgrounds considered when the initial event occurs;
[0021] 5) Execution Scenario: The name of the execution scenario to which the scene activity under this initial event belongs;
[0022] Step 5: Determine the result event data;
[0023] Based on the hazard severity level in step 12 and the task reliability level determined in step 13, the result event data is obtained by using a combination of hazard severity level first and task reliability level second.
[0024] Step Six: Construct an event sequence model;
[0025] The specific steps for establishing an event sequence model are as follows: First, select the initial event of the event sequence model to obtain all scenarios and flight stages related to this initial event. Select a certain operating scenario and flight stage, and then take the initial event as the initial node. Based on one of the other functional failure states or external events that subsequently occur under the initial event, take it as the key event in the event sequence. Use occurrence lines to connect the initial event to the key event to represent the different results of the initial event under other functional failure states or external events. Next, after the key event, select occurrence lines and non-occurrence lines respectively, and determine the danger severity level and mission reliability level of the initial event when other functional failure states or external events occur and do not occur respectively. Finally, select appropriate result events based on the danger severity level and mission reliability level as the end of the event sequence of the two lines respectively. At this time, an event sequence model is established.
[0026] An event sequence model is established for all initial events and related key event combinations;
[0027] Once all event sequence models have been built, the event sequence models need to be automatically checked for construction rules and quantitative probability. Only after all event sequence models have passed the construction rule check and quantitative probability verification can the subsequent steps be executed. Otherwise, the hazard probability level and task reliability requirements of the initiating events or key events in the event sequence models need to be adjusted.
[0028] Step 7: Automatic generation of FHA (Functional Hazard Analysis) based on event sequences;
[0029] Each complete event sequence chain in each event sequence model is treated as a record in the FHA data. Each record includes the function, failure state, operating scenario, and flight phase of the initiating event in each event sequence, the event name of the critical event, and the severity level, probability level, safety impact description, mission reliability level, mission reliability requirements, and mission impact description of the resulting event.
[0030] Step 8: Automatically generate security and task reliability requirements;
[0031] Based on the functional hazard analysis data in step six, the safety and reliability requirements for each functional failure are automatically generated according to the specific expression template of the safety and task reliability requirements.
[0032] Preferably, step one specifically comprises:
[0033] Step 11: Determine the basic data for the flight phase;
[0034] Flight phases are used to consider when functional failure states occur. Flight phase data includes flight phase names and definitions.
[0035] Confirm the flight phase data. When modifying a pre-stored flight phase, the definition of the modified flight phase also needs to be modified accordingly.
[0036] Step 12: Basic data on the impact on security;
[0037] No modifications are permitted to the safety impact data; the data provided by the system must be used. The safety impact data includes the severity level, hazard characteristics, and hazard probability level.
[0038] Step 13: Determine the basic data affecting mission reliability;
[0039] Mission reliability impact refers to the effect of functional failure during aircraft operation on the completion of the current mission; mission reliability impact data includes mission reliability level, mission impact criteria, and mission reliability requirements; the mission reliability impact data is modified and confirmed.
[0040] Step 14: Determine the basic data for external events;
[0041] External event data includes the name of the external event and its occurrence summary; external event data can be modified and confirmed.
[0042] Preferably, the predetermined functional failure description in step three includes:
[0043] 1) Loss of all XX functions without prior notice;
[0044] 2) Complete loss of XX function;
[0045] 3) Unannounced partial loss of XX function, including: unannounced symmetrical loss of XX function and unannounced asymmetrical loss of XX function;
[0046] 4) Partial loss of XX function, including: symmetrical loss of XX function and asymmetrical loss of XX function;
[0047] 5) An unannounced error occurred while executing the XX function;
[0048] 6) Error executing XX function
[0049] 7) XX alarm function false alarm;
[0050] 8) Non-command XX functions.
[0051] Preferably, in step four:
[0052] The five attributes of the initial cause event include: function, which is obtained from the function corresponding to the function failure status in the function failure status list; function failure status is directly derived from the function failure status in step three; and the three attributes of flight phase, scenario activity, and operation scenario are obtained from the traceability relationship between activity-function, activity-scenario, and activity-flight phase in the scenario-based functional model or are filled in manually.
[0053] Each function and its failure state determines an initial cause event. For each initial cause event, related initial cause event attributes are determined, and finally, the data of all initial cause events is obtained.
[0054] Preferably, in step six:
[0055] The event sequence model can be divided into two types according to the type of key events following the initial cause event. One type is combined functional failure, that is, the key events following the initial cause event are other functional failure states, which come from the initial cause event defined in step four. The other type is coupled with external events, that is, the initial cause event is triggered, followed by external events, which come from the external event data in step one.
[0056] Preferably, step six involves checking the construction rules and verifying the quantitative probability of the event sequence model, specifically as follows:
[0057] (1) Construct rules to check whether the event sequence model meets the basic logical requirements, including whether there are breakpoints, whether it includes the initial event, key event and result event, whether the connection order of the three is correct, whether the key event includes the two cases of occurrence line and non-occurrence line, etc., and provide error prompts for event sequence models that do not meet the requirements.
[0058] (2) Perform quantitative probability verification of the event sequence model to ensure that the probability requirements for the initial event or critical event meet the safety or mission reliability objectives. Specifically, this is implemented as follows:
[0059] Based on the result events after the first critical event in each event sequence model does not occur, the hazard probability level and task reliability requirement of each initial cause event are obtained. The hazard probability level and task reliability requirement of each initial cause event are statistically analyzed, and the one with the highest hazard probability level and task reliability requirement is taken as the hazard probability level and task reliability requirement of that initial cause event.
[0060] Based on the event sequence model, the hazard probability level and task reliability requirement of the initiating event and critical event are multiplied respectively. It is then determined whether the resulting hazard probability level and task reliability requirement meet the requirements of the outcome event. An error message is given for event sequence models that do not meet the requirements. At this time, it is necessary to adjust the hazard probability level and task reliability requirement of the initiating event or critical event in the event sequence model that does not meet the requirements.
[0061] Preferably, the template for the specific expression of security and task reliability requirements in step eight includes:
[0062] 1) Single function failure: In the XX operation scenario, during the XX flight phase, the probability of "XX function failure state" occurring per flight hour should be less than the quantitative requirements for XX safety or mission reliability;
[0063] 2) Functional combination failure: In scenario XX, at phase XX, the probability of "XX function.Functional failure state 1" and "XX function.Functional failure state 2" occurring per flight hour should be less than the quantitative requirements for XX safety or mission reliability;
[0064] 3) The combination of XX function and XX function should be developed in accordance with the XX level of development assurance.
[0065] 4) Function XX should be developed in accordance with the XX level of development assurance.
[0066] 5) Function XX and function XX should remain independent of each other;
[0067] XX should be filled in according to the actual situation in the FHA data.
[0068] Preferably, it includes the following components: database, basic data setting module, functional model import module, functional failure status determination module, initial cause event determination module, result event determination module, event sequence model construction module, FHA automatic generation module, and security task reliability requirement generation module;
[0069] The database includes flight phase data, safety impact data, mission reliability impact data, external event data, functional model data, functional failure status data, initial event data, outcome event data, event sequence data, FHA data, and safety mission reliability requirements data.
[0070] The basic data setting module is used to set flight phase data, mission reliability impact data, and external event data;
[0071] The functional model import module is used to import the functional decomposition structure model, functional flow model and scenario-based functional model from the functional model, identify the lowest level function in the functional decomposition structure model, identify the functions related to the function according to the functional flow model, obtain the relationship between different functions, and identify the scenario activities, operation scenarios and flight phases of the function according to the scenario-based functional model.
[0072] The functional failure status determination module is used to determine functional failure status data, including displaying and importing existing functional failure status data, and adding and deleting functional failure status data.
[0073] The initial cause event determination module is used to generate initial cause event data. The initial cause event determination module obtains all functions and function failure states from the function failure state data in the database, and takes each combination of function and function failure state as an initial cause event to obtain an initial cause event list. It obtains a scenario-based function model from the function model import module and automatically populates the initial cause event attributes in the initial cause event list. If a scenario-based function model is not obtained from the function model import module, only the function and function failure state attributes in the initial cause event attributes are filled in, and the attributes of flight phase, scenario activity and running scenario need to be manually filled in by clicking the corresponding initial cause event.
[0074] The result event determination module is used to obtain result event data. The result event determination module 6 arranges and combines the danger severity level of the security impact data and the task reliability level of the task reliability impact data in the database to obtain result event data with the danger severity level first and the task reliability level second.
[0075] The event sequence model construction module is used to construct an event sequence model. It constructs an event sequence module from the initial cause event display submodule, key event display submodule, and result event display submodule in the construction display submodule. The event sequence module is saved and displayed in the event sequence display submodule. The verification submodule is used to verify all event sequence modules.
[0076] The FHA automatic generation module is used to generate and query FHA data. Based on the event sequence data in the database, each complete event sequence chain in each event sequence model is taken as a record in the FHA data. Each record includes the function, failure status, operating scenario, and flight phase of the initiating event in each event sequence, the event name of the key event, and the hazard severity level, hazard probability level, safety impact description, mission reliability level, mission reliability requirements, and mission impact description of the resulting event.
[0077] The security task reliability requirement generation module is used to generate and query security task reliability requirements. Based on the selected hazard severity level and task reliability level, it selects the corresponding records from the FHA data list and generates a security task reliability requirement document based on the records in the FHA and the specific expression template of the task reliability requirement.
[0078] Preferably, the event sequence model construction module includes an initial cause event display submodule, a key event display submodule, an outcome event display submodule, a construction display submodule, an event sequence display submodule, and a verification submodule;
[0079] The initial cause event display submodule is connected to the database and the initial cause event determination module respectively. The initial cause event display submodule retrieves the initial cause event data from the database and displays it in a list. The selected initial cause event can be placed into the display submodule by dragging and dropping. If an initial cause event is directly clicked in the initial cause event display submodule, the initial cause event determination module will be called to adjust the attributes of the initial cause event.
[0080] The critical event display submodule is connected to the database, the function failure status determination module, and the basic data setting module. The critical event display submodule retrieves function failure status data and external event data from the database and displays them in a list. Selected critical events can be placed into the display submodule by dragging and dropping. If a critical event is clicked directly in the critical event display submodule, if the critical event is function failure status data, the function failure status determination module will be called to modify the function failure status data. If the critical event is an external event, the database setting module will be called to modify the external event data.
[0081] The results event display submodule connects to the database and displays the results event data. Selected results events can be placed into the display submodule by dragging and dropping.
[0082] The Build Display submodule displays an event sequence model being edited. It allows editing of the initial event, key event, result event, and occurrence / non-occurrence lines used in the event sequence model. The Build Display submodule generates initial events, key events, and result events by dragging and dropping them from the Initial Event Display submodule, Key Event Display submodule, and Result Event Display submodule, respectively. These events are then connected together using occurrence / non-occurrence lines to form an event sequence model. The Build Display submodule saves the completed event sequence model in the event sequence data, which is stored in a database. The event sequence data includes initial events, key events, result events, and occurrence / non-occurrence lines between key events and result events.
[0083] The event sequence display submodule is used to display saved event sequence data. Clicking on an event sequence name in the event sequence data will display the corresponding event sequence model in the display submodule.
[0084] The validation submodule is used to validate the event sequence data stored in the database. The validation rules are checked and quantitatively verified according to the construction rules in step six. If the validation fails, the event sequence that fails the validation needs to be marked and displayed in the event sequence display submodule.
[0085] Compared with the prior art, the present invention has the following beneficial effects:
[0086] (1) This invention is adapted to the model-based systems engineering development mode of aircraft and provides a model-based functional hazard analysis method for aircraft. It is applicable to functional hazard analysis at the aircraft level and system level and can realize the automatic generation of functional hazard analysis results and the automatic capture of safety and mission reliability requirements, effectively improving the efficiency of functional hazard analysis.
[0087] (2) This invention applies the event sequence model to the process of functional hazard analysis of aircraft, and expresses the process of functional hazard analysis, which was previously carried out directly through tables, through event sequence. It provides an intuitive display of the accident evolution path after functional failure, so that safety and reliability personnel can effectively confirm the impact level with various design disciplines, thereby improving the accuracy of functional hazard analysis.
[0088] (3) The present invention also provides a model-based aircraft functional hazard analysis device. Using this device, functional hazard analysis and safety mission reliability requirement documents can be automatically generated, reducing the complexity of manual filling and analysis. Attached Figure Description
[0089] Figure 1 This is a flowchart of the model-based aircraft functional hazard analysis method of the present invention;
[0090] Figure 2 This is an example of the safety impact level definition of the present invention;
[0091] Figure 3 Examples of task reliability levels and reliability requirements defined for this invention;
[0092] Figure 4 This is a typical detailed functional decomposition structure model example of the present invention;
[0093] Figure 5 This is an example of the functional flow model of the present invention;
[0094] Figure 6 This is an example of defining the functional failure state of the present invention;
[0095] Figure 7 This is an example of a list of initial events for the present invention;
[0096] Figure 8 This is the interface for the platform event sequence model construction module of the present invention;
[0097] Figure 9 This is an example of an event sequence model for the "loss of all means of communication" initial cause event in the air phase of the present invention;
[0098] Figure 10 This is an example of an event sequence model for the "unannounced loss of all ground deceleration" initiating event during the takeoff phase of the present invention;
[0099] Figure 11 This invention provides a description of its security and mission impacts.
[0100] Figure 12 Example of an automatic generation screening interface for functional hazard analysis according to the present invention;
[0101] Figure 13 Automatically generate a filter interface example to meet the requirements of this invention;
[0102] Figure 14 This is a schematic diagram of the model-based aircraft functional hazard analysis device of the present invention. Detailed Implementation
[0103] Exemplary embodiments, features, and aspects of the present invention will now be described in detail with reference to the accompanying drawings. The same reference numerals in the drawings denote elements that have the same or similar functions. Although various aspects of the embodiments are shown in the drawings, they are not necessarily drawn to scale unless specifically indicated otherwise.
[0104] This invention provides a model-based method for functional hazard analysis of aircraft, such as... Figure 1 As shown, the specific implementation steps are as follows:
[0105] Step 1: Determine the basic data for functional hazard analysis.
[0106] Before conducting a Functional Hazard Analysis (FHA), the baseline data must first be determined. This baseline data is pre-stored in a database and includes flight phase data, safety impact data, mission reliability impact data, and external event data. Determining the baseline data involves browsing, modifying, deleting, or adding data to the pre-stored database and then confirming the findings.
[0107] Step 11: Determine the basic data for the flight phase.
[0108] Flight phases are used to consider the timing of functional failure states. Based on the aircraft's intended use and the natural, geographical, airport, and route infrastructure environments it faces, the aircraft's mission tasks are determined. By analyzing the different characteristic states and mission progress within the mission tasks, the aircraft's mission scenarios / flight phases or special states are divided, including related activities on the ground and in flight, to ensure that the divided flight phases can meet the different characteristic states and mission progress.
[0109] The division of flight phases must meet the following requirements:
[0110] 1) All flight phases cover a complete mission profile.
[0111] 2) There is no overlap between flight phases, and the boundaries of each phase are clearly defined.
[0112] 3) The flight phase is organized according to the time sequence of the mission.
[0113] 4) It should at least cover the taxiing, takeoff, climb, cruise, descent, approach and landing phases, and may also include special flight phases such as go-around.
[0114] In practice, the division of flight phases can be defined in two ways:
[0115] 1) If model-based scenario analysis has been conducted for this type of aircraft, the flight phases in the scenario model can be used as the basic data for the flight phase division of this invention.
[0116] 2) If model-based scenario analysis has not yet been conducted for this aircraft model, it is necessary to import pre-stored flight phases from the database and then modify and define them accordingly. At this point, pre-stored flight phases can be used directly, or they can be modified according to specific needs. It is important to note that the flight phases defined here must be consistent with those used in scenario analysis and functional analysis.
[0117] The pre-stored flight phase data in this embodiment is shown in Table 1, including the flight phase name and definition.
[0118] Table 1 Flight Phase
[0119]
[0120] When modifying a pre-stored flight phase, the definition of the modified flight phase must also be modified accordingly. Although the definition of the flight phase is not used, it provides a clear definition and division of each flight phase, which can facilitate subsequent querying and adjustment.
[0121] Step 12: Basic data on security impact.
[0122] Safety impact data must not be modified in any way and must use the data provided by the system. The safety impact data of this invention should include the severity level, hazard characteristics, and likelihood level of the hazard.
[0123] The severity levels of hazards are represented by numbers from highest to lowest, including: I (Catastrophic), II (Hazardous), III (Major), IV (Minor), and V (No Safety Effect). Each severity level has a corresponding hazard characteristic, and the severity level can be obtained based on the hazard characteristic.
[0124] Hazard characteristics are used to determine the severity level of a hazard. Hazard characteristics include both the impact on the aircraft and the impact on personnel, such as causing loss of aircraft control, causing the death or incapacitation of the flight crew, causing the death of multiple passengers, and other situations.
[0125] A hazard probability level is a quantitative requirement for the probability of a hazardous feature occurring. Each hazard severity level corresponds to a fixed hazard probability level. The higher the hazard severity level, the lower the probability of the hazardous feature occurring must be, and the smaller the probability corresponding to the hazard probability level must be.
[0126] The security impact data of this invention pre-stored in the database is shown in Table 2 (the names corresponding to the severity of the danger are not displayed), and the display interface is as follows. Figure 2 As shown.
[0127] Table 2 Safety Impact
[0128]
[0129] Where FH represents flight hours, for example, 10 -9 / FH indicates that the probability of occurrence per flight hour is no more than 10. -9 .
[0130] Step 13: Determine the basic data affecting mission reliability
[0131] Mission reliability impact refers to the effect on the completion of the aircraft's current mission when a functional failure occurs during aircraft operation.
[0132] The data on the impact of mission reliability includes mission reliability level, mission impact criteria, and mission reliability requirements.
[0133] Mission reliability level is a classification of the severity of the impact on a flight mission. Mission reliability levels are represented by numbers from high to low, including: I (Mission in the air), II (Mission on the ground), III (Mission delay), IV (Mission degraded), V (Unable to perform the next mission), VI (No mission impact), etc.
[0134] The task impact criterion is used to determine the reliability level of a task.
[0135] Task reliability requirements are quantitative requirements for task reliability, and there are corresponding quantitative targets for task reliability for different task reliability levels.
[0136] The task reliability impact data provided by this invention is shown in Table 3, and it also provides a customization function for the task reliability impact, allowing for adaptive modifications based on the original data. The display interface for the task reliability impact is shown in Table 3. Figure 3 As shown.
[0137] Table 3 Impact of Task Reliability
[0138]
[0139] Step 14: Determine the basic data for external events.
[0140] External events can theoretically be categorized into four types: operating conditions, operating events, environmental conditions, and environmental events. However, this invention does not classify external events; the external event data only includes the external event name and its corresponding probability of occurrence. Table 4 shows some of the external event data provided by this invention. The external events provided by this invention also offer a customization function, allowing for adaptive modifications based on existing data.
[0141] Table 4 External Events
[0142]
[0143]
[0144] Step 2: Automatically acquire the functional model.
[0145] The functional model is constructed during aircraft development. The functional model mainly includes the functional decomposition structure model and the function flow model. The functional decomposition structure model is as follows: Figure 4 As shown, the functional flow model is as follows Figure 5 As shown, the existing functional model is defined as follows: based on the existing operational scenario model, focusing on the behaviors performed by the aircraft as the executor, identifying the aircraft's functions, and forming an aircraft functional decomposition structure model. Furthermore, for the underlying functions in the decomposition structure, functional flow construction is carried out, establishing the input and output relationships between aircraft functions and stakeholders, and between functions themselves.
[0146] When obtaining the functional model, the lowest-level functional modules are first identified based on the functional decomposition structure model within the functional model to obtain the functions. Then, based on the functional flow model within the functional model, related functions are identified to obtain the relationships between different functions. Please note that this invention is based on the functional model; therefore, if the functional model cannot be successfully imported, this invention will display an import error and will be unable to execute subsequent steps.
[0147] Step 3: Define the function failure status according to the function definition.
[0148] Functional failure status describes the abnormal state of a function. For each function identified in step two, a corresponding functional failure status is defined, and the function and its corresponding functional failure status are saved to a functional failure status list in the database. Functional failure statuses in critical events are displayed as follows: Figure 6 As shown.
[0149] Defining a function failure state is achieved by selecting a predefined function failure description. The predefined function failure descriptions include:
[0150] 1) Loss of all XX functions without prior notice.
[0151] 2) Complete loss of XX function.
[0152] 3) Unannounced partial loss of XX function, including: unannounced symmetrical loss of XX function and unannounced asymmetrical loss of XX function.
[0153] 4) Partial loss of XX function, including: partial loss of symmetrical XX function and partial loss of asymmetrical XX function.
[0154] 5) An unannounced error occurred while executing the XX function.
[0155] 6) Error executing XX function.
[0156] 7) XX alarm function false alarm.
[0157] 8) Non-command XX functions.
[0158] When defining functional failure states, the following requirements should be met:
[0159] 1) The identification of functional failure states should at least consider the dangers posed by the loss of a function or malfunction of a certain aircraft function.
[0160] 2) When defining the failure state of functional loss, complete loss of function and partial loss of function should be considered. Partial loss of function includes symmetrical loss of function or asymmetrical loss of function.
[0161] 3) When defining the failure state of a function error, the situation of inaccurate function execution and non-instruction execution should be considered. At the same time, for alarm and related functions, false alarms should be considered.
[0162] 4) For failure states that may be significantly affected by crew operations, the presence or absence of a flight crew notice should be considered.
[0163] The following table shows the defined failure states of the "Provide Ground Deceleration" function as an example.
[0164] Table 5 provides examples of ground deceleration function failure states.
[0165]
[0166] Step 4: Identify the initial event and obtain the event attributes.
[0167] The functional failure states identified in step three are used as initial cause events. Each initial cause event includes the following attributes:
[0168] 1) Function, which is obtained from the function corresponding to the function failure status in the function failure status list.
[0169] 2) Function failure state, which is a function failure state in the list of function failure states. Each function failure state in the list of function failure states plus the function is defined as an initiating event.
[0170] 3) Flight phase, which is the phase in which functional failure occurs under the initial cause event.
[0171] 4) Scenario activities, which are the background activities to be considered when the initial event occurs.
[0172] 5) Running scenario: The name of the running scenario to which the scene activity under this initial event belongs.
[0173] The initial cause event has five attributes. The "function" attribute is derived from the function corresponding to the function failure state in the function failure state list. The function failure state directly originates from the function failure state in step three. The "flight phase," "scenario activity," and "operational scenario" attributes have two different data sources. If the existing functional model already includes a scenario-based functional model, the corresponding correspondence between activities, scenarios, and flight phases can be obtained based on the traceability relationships between activities and functions, activities and scenarios, and activities and flight phases in the scenario-based functional model. Because one function can correspond to multiple activities in a scenario-based functional model, an initial cause event can contain multiple flight phases, scenario activities, and operation scenarios. If a scenario-based functional model has not yet been established, the flight phase of the corresponding function failure state can be selected using the flight phase data from step one. By analyzing the flight phases during which the function executes normally and the flight phases where functional errors may occur, combined with the operation scenario and operation activity, the flight phase, scenario activity, and operation scenario attributes of the initial cause event can be manually filled in to form the initial cause event for functional hazard analysis.
[0174] Taking the "unannounced loss of all ground deceleration" failure state of the "provide ground deceleration" function as an example, considering the takeoff and landing phases and related scenario activities and operational scenarios, the data format for the initial cause event "provide ground deceleration, unannounced loss of all ground deceleration" is shown in Table 6. The initial cause event is displayed as follows: Figure 7 As shown.
[0175] Table 6. Initial Causes of "Unannounced Loss of All Ground Deceleration"
[0176]
[0177] Each function and its failure state determines an initial cause event. For each initial cause event, related initial cause event attributes are determined, and finally, the data of all initial cause events is obtained.
[0178] Step 5: Determine the result event data.
[0179] Based on the hazard severity level in step 12 and the task reliability level determined in step 13, the result event data is obtained by using a combination of hazard severity level first and task reliability level second.
[0180] Step 6: Construct an event sequence model.
[0181] First, determine the list of event sequences to be analyzed. For ease of processing, in this embodiment, the list of event sequences is consistent with the initial cause events, that is, an event sequence model must be established for all initial cause events. The specific steps for establishing an event sequence model for a primary cause event are as follows: First, select the primary cause event in the event sequence model to obtain all scenarios and flight phases related to this primary cause event. Select a specific operational scenario and flight phase, and then, using the primary cause event as the initial node, determine one of the other possible functional failure states or external events that may occur after the primary cause event as the critical event in the event sequence. Use occurrence lines to connect the primary cause event to the critical event, representing the different outcomes of the primary cause event under other functional failure states or external events. Next, select occurrence lines and non-occurrence lines after the critical event, and determine the severity level and mission reliability level of the consequences caused by the primary cause event when other functional failure states or external events occur and do not occur, respectively. Finally, select appropriate outcome events as the end points of the event sequences for the two lines based on the severity level and mission reliability level. The selection of outcome events can refer to the functional failure states related to the primary cause event and the critical event. Whether the two are related is determined based on the correlation between different functions obtained in step two. At this point, an event sequence model is established. Event sequence models are built for each initial event and related key event combination. Once all are completed, the event sequence model data is finished. The interface for building the event sequence model is shown below. Figure 8 As shown, each new event sequence model is saved to the event sequence model data.
[0182] Event sequence models can be divided into two types based on the type of critical events following the initial cause event. One type is combined functional failure, where the critical events following the initial cause event are other functional failure states, which originate from the initial cause event defined in step four. Taking the initial cause event "providing communication but losing all communication means" as an example, the subsequent critical event is "providing navigation but losing all navigation means." Then, the resulting events are obtained based on whether "providing navigation but losing all navigation means" occurs or not. The constructed event sequence model is as follows: Figure 9 As shown; another approach is coupling with external events, where an initial cause event triggers the subsequent external events, which originate from the external event data in step one. Taking the initial cause event of "unannounced loss of ground deceleration" as an example, the subsequent key event is "abortion of takeoff." Based on whether the "abortion of takeoff" external event occurs, the resulting events are obtained, and the constructed event sequence model is as follows: Figure 10 As shown.
[0183] The outcome events in each event sequence model are selected from the outcome event data. To determine the specific options for the outcome events, a knowledge base, neural network, or manual judgment can be used. Typically, based on the requirements of the user department or airworthiness certification, pilot experience, user department's fault statistics, engineering calculations, analysis, and experience with previous models, the corresponding hazard characteristics and mission impacts are determined. Then, the hazard severity level and mission reliability level are determined according to the hazard characteristics and mission impact criteria. If more than one possible impact occurs simultaneously, the most severe level is used. This step also requires completing the corresponding safety impact description and mission impact description based on the hazard characteristics and mission impact criteria, such as... Figure 11 As shown, this description is intended to provide a clearer understanding of the criteria for judging the severity level of a hazard and the reliability level of a task in subsequent use, facilitating discussions and modifications regarding the determination of the severity level of a hazard and the reliability level of a task, as well as the generation of functional hazard analysis data.
[0184] Once all event sequence models have been built, they need to be automatically checked for construction rules and quantitative probability. Subsequent operations can only proceed after all event sequence models have passed these checks. The specific steps for checking construction rules and quantitative probability of event sequence models are as follows:
[0185] (1) The rule check mainly checks whether the event sequence model meets the basic logical requirements, such as: whether there are breakpoints, whether it includes the initial event, key event and result event, whether the connection order of the three is correct, whether the key event includes the two cases of occurrence and non-occurrence, etc., and provides error prompts for event sequence models that do not meet the requirements.
[0186] (2) Perform quantitative probability verification of the event sequence model to ensure that the probability requirements for the initial event or critical event meet the safety or mission reliability objectives. Specifically, this is implemented as follows:
[0187] Based on the result events following the failure of the first critical event in each event sequence model, the hazard probability level and task reliability requirement of each initial cause event are obtained. Since the critical event does not occur at this time, the hazard probability level and task reliability requirement of the result event are equivalent to the hazard probability level and task reliability requirement of the initial cause event. The hazard probability level and task reliability requirement of each initial cause event are statistically analyzed, and the one with the highest hazard probability level and task reliability requirement is taken as the hazard probability level and task reliability requirement of that initial cause event.
[0188] If a critical event is a failure state of other functions, the hazard probability level and task reliability requirements of the critical event are the same as those of the initial cause event of the failure state. If a critical event is an external event, the hazard probability level and task reliability requirements of the external event are the probability of occurrence of the external event data.
[0189] Based on the event sequence model, the hazard probability level and task reliability requirement of the initiating event and critical event are multiplied respectively. It is then determined whether the resulting hazard probability level and task reliability requirement meet the requirements of the outcome event. An error message is displayed for event sequence models that do not meet the requirements. In this case, the hazard probability level and task reliability requirement of the initiating event or critical event in the event sequence model that does not meet the requirements need to be adjusted.
[0190] Step 7: Automatic generation of FHA (Functional Hazard Analysis) based on event sequence.
[0191] Automatic FHA data generation is achieved based on event sequence model data. Each complete event sequence chain in each event sequence model is treated as a record in the FHA data. A complete event sequence chain includes an initiating event, a critical event, and a result event. Each record includes the function, failure state, operational scenario, and flight phase of the initiating event in each event sequence; the event name of the critical event; and the severity level, probability level, safety impact description, mission reliability level, mission reliability requirements, and mission impact description of the result event. When the critical event is a failure state of another function, the critical event name is the function plus the failure state. When the critical event is an external event, the event name is the external event name. When a critical event and an external event are connected by a non-occurring line in a complete event sequence chain, the event name is empty.
[0192] After saving the FHA data, you can either directly provide an FHA data list or display the desired FHA data list by filtering. The filtering interface is as follows: Figure 12 As shown in Table 7, the automatically generated FHA data list is presented.
[0193] Table 7 Example of FHA Data List
[0194]
[0195]
[0196] Step 8: Automatically generate security and task reliability requirements.
[0197] Based on the functional hazard analysis data in step six, the safety and task reliability requirements for each functional failure can be automatically generated, enabling automatic capture of safety and task reliability requirements.
[0198] Safety requirements mainly include three categories: quantitative probability requirements, independence requirements, and development assurance level requirements. Mission reliability requirements mainly include quantitative probability requirements and independence requirements. Since the independence requirement in mission reliability requirements is the same as the independence requirement in safety requirements, it does not need to be listed separately. Templates for the specific expression of safety and mission reliability requirements include:
[0199] 1) Single function failure: In XX (operational scenario), in XX (flight phase), the probability of "XX function failure state" occurring per flight hour should be less than XX (quantitative requirements for safety / mission reliability);
[0200] The quantitative requirements for safety or mission reliability here refer to the safety and mission reliability requirements when the event name in the "XX function.Function failure state failure state" entry in the FHA data is empty. Whenever "quantitative requirements for safety / mission reliability" appear, according to the FHA data, it indicates that the quantitative requirements for safety and mission reliability should be expressed separately.
[0201] 2) Functional combination failure: In XX (scenario), in XX (phase), the probability of "XX function.Functional failure state 1" and "XX function.Functional failure state 2" occurring per flight hour should be less than XX (quantitative requirements for safety / mission reliability).
[0202] The quantitative requirements for security / mission reliability here refer to the security and mission reliability requirements when the failure state in the FHA data is "XX function failure state 1" and the event name is "XX function failure state 2".
[0203] 3) Functional combinations (covering XX function, XX function) should be developed according to the XX level of development assurance; the development level is determined based on safety requirements, and the two usually have a clear correspondence, such as for a safety requirement of <10 -9 The relevant functions of / FH should be developed according to the Class A development assurance level; for safety requirements of <10 -5 The relevant functions of / FH should be developed in accordance with the C-level development assurance level.
[0204] 4) The XX function should be developed in accordance with the XX level of development assurance.
[0205] 5) Functions XX and XX should remain independent of each other; this means that when a combination of functions fails, the two functions must remain independent of each other.
[0206] This invention also provides a filtering function for different levels of security and task reliability requirements. The default filtering options are functional failures with a severity level of minor (Level IV) or higher, and functional failures with a task reliability severity level of inability to execute the next task or higher. Security and task reliability requirements are then formalized through standardized expressions. The filtering interface for security and task reliability requirements is shown below. Figure 13 As shown, an example of the list is shown in Table 8.
[0207] Table 8. Example of Security and Mission Reliability Requirements List
[0208]
[0209] By implementing the above steps, the model-based systems engineering development process can be fully integrated. Using the aircraft's functional model as input and combining event sequences, FHA data and safety / mission reliability requirements can be automatically generated, providing an effective model-based aircraft functional hazard analysis method for use by aircraft safety analysis teams.
[0210] This invention also provides a model-based functional hazard analysis device, such as... Figure 14 As shown, the device includes a database 1, a basic data setting module 2, a functional model import module 3, a functional failure state determination module 4, a cause event determination module 5, a result event determination module 6, an event sequence model construction module 7, an FHA automatic generation module 8, and a security task reliability requirement generation module 9.
[0211] Initially, Database 1 only includes flight phase data, safety impact data, mission reliability impact data, and external event data. Later, it will add functional model data, functional failure status data, initial event data, result event data, event sequence data, FHA data, and safety mission reliability requirements documents.
[0212] Flight phase data includes 10 flight phases as shown in Table 1 and their corresponding definitions.
[0213] Safety impact data includes hazard severity level, hazard characteristics, and hazard probability level as shown in Table 2. The hazard severity level is determined based on the hazard characteristics, and the hazard probability level and hazard severity level correspond one-to-one.
[0214] The data on the impact of mission reliability includes mission reliability level, mission impact criteria, and mission reliability requirements, as shown in Table 3. The mission reliability level is determined based on the mission impact criteria, and there is a one-to-one correspondence between the mission reliability level and the mission reliability requirements.
[0215] External event data includes the names and probabilities of occurrence of external events, as shown in Table 4.
[0216] Basic Data Settings Module 2 is used to configure flight phase data, mission reliability impact data, and external event data. Note that safety impact data cannot be modified by users using the database settings module.
[0217] The Functional Model Import Module 3 is used to import the Functional Decomposition Structure Model, Functional Flow Model, and Scenario-based Functional Model from the functional model. It identifies the lowest-level functions in the Functional Decomposition Structure Model and identifies related functions based on the Functional Flow Model, thus obtaining the relationships between different functions. Based on the Scenario-based Functional Model, it identifies the scene activities, operational scenarios, and flight phases of each function. The data obtained from the functional model is saved to the Functional Model Data, which includes functions, functional relationships, and the correspondences between functions, scene activities, operational scenarios, and flight phases.
[0218] The Function Failure Status Determination Module 4 is used to determine function failure status data, including displaying and importing existing function failure status data, and adding and deleting function failure status data. This module can display function failure status data; if existing data exists, it can be directly imported and modified. If no existing data exists, only all functions obtained from the function model data will be displayed. When adding a new function failure status, the module first selects the identified function, then selects the function failure description that matches the predefined failure description to obtain the corresponding failure status. After selecting a function failure status, simply selecting "Delete" will remove that failure status. The module saves the function failure status data to the database; the data includes both the function and its failure status.
[0219] The Initial Cause Event Determination Module 5 is used to generate initial cause event data. This module obtains all functions and function failure states from the function failure state data in the database, and combines each function and function failure state into an initial cause event, generating an initial cause event list. It then imports a scenario-based function model from the function model import module and automatically populates the initial cause event attributes in the initial cause event list. If a scenario-based function model is not obtained from the function model import module, only the function and function failure state attributes in the initial cause event attributes are populated, and the attributes for flight phase, scenario activity, and operating scenario need to be manually filled in by clicking on the corresponding initial cause event. The initial cause event determination module saves the initial cause event data to the database, which includes functions, function failure states, flight phases, scenario activities, and operating scenarios.
[0220] The result event determination module 6 is used to obtain result event data. The result event determination module 6 arranges and combines the hazard severity level of the security impact data and the task reliability level of the task reliability impact data in the database to obtain result event data with the hazard severity level first and the task reliability level second. The result event data is stored in the database and includes the hazard severity level and the task reliability level.
[0221] The event sequence model construction module 7 is used to construct the event sequence model. The entire event sequence model construction module is divided into six sub-modules, namely the initial cause event display sub-module 71, the key event display sub-module 72, the result event display sub-module 73, the construction display sub-module 74, the event sequence display sub-module 75, and the verification sub-module 76.
[0222] The initial cause event display submodule 71 is connected to the database and the initial cause event determination module 5 respectively. The initial cause event display submodule retrieves the initial cause event data from the database 1 and displays it in a list. The selected initial cause event can be placed into the display submodule by dragging and dropping. If an initial cause event is directly clicked in the initial cause event display submodule, the initial cause event determination module will be called to adjust the attributes of the initial cause event.
[0223] The critical event display submodule 72 is connected to the database 1, the function failure status determination module 4, and the basic data setting module 2. The critical event display submodule 72 retrieves function failure status data and external event data from the database and displays them in a list. Selected critical events can be placed into the display submodule by dragging and dropping. If a critical event in the critical event display submodule 72 is clicked directly, if the critical event is function failure status data, the function failure status determination module 4 is called to modify the function failure status data. If the critical event is an external event, the database setting module 2 is called to modify the external event data.
[0224] The result event display submodule 73 is connected to database 1 and displays result event data. Selected result events can be dragged and dropped into the construction display submodule 74.
[0225] The display module 74 is used to display an event sequence model being edited. It allows editing of the initial event, key event, result event, and occurrence / non-occurrence lines used in the event sequence model. The display module 74 obtains initial events, key events, and result events by dragging and dropping from the initial event display module 71, key event display module 72, and result event display module 73 respectively, and connects them together using occurrence / non-occurrence lines to form an event sequence model. The display module 74 saves the completed event sequence model in the event sequence data, and stores the event sequence data in database 1. The event sequence data includes initial events, key events, result events, and occurrence / non-occurrence lines between key events and result events.
[0226] The event sequence display submodule 75 is used to display the saved event sequence data. Clicking on an event sequence name in the event sequence data will display the corresponding event sequence model in the display submodule 74.
[0227] The verification submodule 76 is used to verify the event sequence data stored in database 1. The verification rules are checked and quantitatively verified according to the construction rules in step six. If the verification fails, the event sequence that fails the verification needs to be marked in the event sequence display submodule 75, such as by highlighting, marking, or changing the font color. The FHA automatic generation module 8 cannot be called for subsequent operations until all event sequence data passes the verification.
[0228] The FHA auto-generation module 8 is used to generate and query FHA data. Based on the event sequence data in database 1, it treats each complete event sequence chain in each event sequence model as a record in the FHA data. Each record includes the function, failure state, operational scenario, and flight phase of the initiating event in each event sequence; the event name of the critical event; and the severity level, probability level, safety impact description, mission reliability level, mission reliability requirements, and mission impact description of the resulting event. When the critical event is a failure state of another function, the critical event name is the function plus the failure state; when the critical event is an external event, the event name is the external event name. When a critical event and an external event in a complete event sequence chain are connected by a non-occurring line, the event name is empty. The FHA data is stored in the database. The FHA auto-generation module filters and displays the required FHA data list and can automatically generate an FHA data list.
[0229] The security task reliability requirement generation module 9 is used to generate and query security task reliability requirements. Based on the selected hazard severity level and task reliability level, it selects the corresponding records from the FHA data list, and generates a security task reliability requirement document based on the records in the FHA and the specific expression template of the task reliability requirement in step seven.
[0230] The embodiments described are merely preferred embodiments of the present invention and are not intended to limit the scope of the present invention. Various modifications and improvements made by those skilled in the art to the technical solutions of the present invention without departing from the spirit of the present invention should fall within the protection scope defined by the claims of the present invention.
Claims
1. A model-based method for functional hazard analysis of aircraft, characterized in that: It includes the following steps: Step 1: Determine the basic data for functional hazard analysis; Basic data is pre-stored in the database, including flight phase data, safety impact data, mission reliability impact data, and external event data; After browsing or modifying the basic data pre-existing in the database, confirm the changes. Step one specifically involves: Step 11: Determine the basic data for the flight phase; Flight phases are used to consider when functional failure states occur. Flight phase data includes flight phase names and definitions. Confirm the flight phase data. When modifying a pre-stored flight phase, the definition of the modified flight phase also needs to be modified accordingly. Step 12: Basic data on the impact on security; No modifications are allowed to the safety impact data; the data provided by the system must be used. The safety impact data includes the severity level, hazard characteristics, and hazard probability level. The severity level is determined based on the hazard characteristics, and the hazard probability level and the severity level are in one-to-one correspondence. Step 13: Determine the basic data affecting mission reliability; Mission reliability impact refers to the effect of functional failure during aircraft operation on the completion of the current mission; mission reliability impact data includes mission reliability level, mission impact criteria, and mission reliability requirements, wherein the mission reliability level is determined based on the mission impact criteria, and there is a one-to-one correspondence between the mission reliability level and the mission reliability requirements; the mission reliability impact data is modified and confirmed. Step 14: Determine the basic data for external events; External event data includes the name of the external event and its corresponding probability of occurrence; the external event data can be modified and confirmed. Step 2: Automatically acquire the functional model; When obtaining the functional model, firstly, based on the functional decomposition structure model in the functional model, the lowest level functional modules are identified to obtain the functions; then, based on the functional flow model in the functional model, the functions related to the function are identified to obtain the relationship between different functions. Step 3: Define the function failure status according to the function definition; For the functions identified in step two, a corresponding function failure state is defined for each function by selecting a predetermined function failure description, and the function and the corresponding function failure state are saved to the function failure state list in the database. Step 4: Identify the initial event and obtain its attributes; The functional failure states identified in step three are used as initial cause events. Each initial cause event includes the following attributes: 1) Function, which is obtained from the functions corresponding to the function failure status in the function failure status list; 2) Function failure state, which is a function failure state in the list of function failure states. Each function failure state plus function in the list of function failure states is defined as an initiating event. 3) Flight phase, which is the phase in which functional failure occurs under this initial cause event; 4) Scenario activities, which are the operational backgrounds considered when the initial event occurs; 5) Execution Scenario: The name of the execution scenario to which the scene activity under this initial event belongs; Step 5: Determine the result event data; Based on the hazard severity level in step 12 and the task reliability level determined in step 13, the result event data is obtained by using a combination of hazard severity level first and task reliability level second. Step Six: Construct an event sequence model; The specific steps for establishing an event sequence model are as follows: First, select the initial event of the event sequence model to obtain all scenarios and flight stages related to this initial event. Select a certain operating scenario and flight stage, and then take the initial event as the initial node. Based on one of the other functional failure states or external events that subsequently occur under the initial event, take it as the key event in the event sequence. Use occurrence lines to connect the initial event to the key event to represent the different results of the initial event under other functional failure states or external events. After the key event, select occurrence lines and non-occurrence lines respectively, and determine the danger severity level and mission reliability level of the initial event when other functional failure states or external events occur and do not occur respectively. Finally, select appropriate result events based on the danger severity level and mission reliability level as the end of the event sequence of the two lines respectively. At this time, an event sequence model is established. An event sequence model is established for all initial events and related key event combinations; Once all event sequence models have been built, the event sequence models need to be automatically checked for construction rules and quantitative probability. Only after all event sequence models have passed the construction rule check and quantitative probability verification can the subsequent steps be executed. Otherwise, the hazard probability level and task reliability requirements of the initiating events or key events in the event sequence models need to be adjusted. Step 7: Automatic generation of FHA based on event sequences; Each complete event sequence chain in each event sequence model is treated as a record in the FHA data. Each record includes the function, failure state, operating scenario, and flight phase of the initiating event in each event sequence, the event name of the critical event, and the severity level, probability level, safety impact description, mission reliability level, mission reliability requirements, and mission impact description of the resulting event. Step 8: Automatically generate security and task reliability requirements; Based on the FHA data in step seven, the security and task reliability requirements for each function failure are automatically generated according to the specific expression template of the security and task reliability requirements.
2. The model-based aircraft functional hazard analysis method according to claim 1, characterized in that: The predefined function failure description in step three includes: 1) Loss of all XX functions without prior notice; 2) Complete loss of XX function; 3) Unannounced partial loss of XX function, including: unannounced symmetrical loss of XX function and unannounced asymmetrical loss of XX function; 4) Partial loss of XX function, including: symmetrical loss of XX function and asymmetrical loss of XX function; 5) An unannounced error occurred while executing the XX function; 6) Error executing function XX; 7) XX alarm function false alarm; 8) Non-command XX functions.
3. The model-based aircraft functional hazard analysis method according to claim 1, characterized in that: In step four: The five attributes of the initial cause event include: function, which is obtained from the function corresponding to the function failure status in the function failure status list; function failure status is directly derived from the function failure status in step three; and the three attributes of flight phase, scenario activity, and operation scenario are obtained from the traceability relationship between activity-function, activity-scenario, and activity-flight phase in the scenario-based functional model or are filled in manually. Each function and its failure state determines an initial cause event. For each initial cause event, related initial cause event attributes are determined, and finally, the data of all initial cause events is obtained.
4. The model-based aircraft functional hazard analysis method according to claim 1, characterized in that: In step six: The event sequence model can be divided into two types according to the type of key events following the initial cause event. One type is combined function failure, that is, the key events following the initial cause event are other function failure states, which come from the initial cause event defined in step four. Another approach is coupling with external events, where the initial event triggers the subsequent external events, which originate from the external event data in step one.
5. The model-based aircraft functional hazard analysis method according to claim 1, characterized in that: Step six involves checking the construction rules and verifying the quantitative probability of the event sequence model, specifically as follows: (1) Construct rules to check whether the event sequence model meets the basic logical requirements, including whether there are breakpoints, whether it includes the initial event, key event and result event, whether the connection order of the three is correct, whether the key event includes the two cases of occurrence line and non-occurrence line, and provide error prompts for event sequence models that do not meet the requirements. (2) Perform quantitative probability verification of the event sequence model to ensure that the probability requirements for the initial event or key event meet the safety or mission reliability objectives. Specifically, this is implemented as follows: Based on the result events after the first critical event in each event sequence model does not occur, the hazard probability level and task reliability requirement of each initial cause event are obtained. The hazard probability level and task reliability requirement of each initial cause event are statistically analyzed, and the one with the highest hazard probability level and task reliability requirement is taken as the hazard probability level and task reliability requirement of that initial cause event. Based on the event sequence model, the hazard probability levels of the initial cause event and the critical event are multiplied together, and the task reliability requirements of the initial cause event and the critical event are multiplied together. It is then determined whether the obtained hazard probability levels and task reliability requirements meet the requirements of the result event. An error message is given for event sequence models that do not meet the requirements. At this point, it is necessary to adjust the hazard probability level and task reliability requirements of the initial cause event in the event sequence model that does not meet the requirements, or the hazard probability level and task reliability requirements of the critical event.
6. The model-based aircraft functional hazard analysis method according to claim 1, characterized in that: The specific expression templates for the security and task reliability requirements in step eight include: 1) Single function failure: In the XX operation scenario, during the XX flight phase, the probability of "XX function failure state" occurring per flight hour should be less than the quantitative requirements for XX safety or mission reliability; 2) Functional combination failure: In XX scenario, at XX stage, the probability of "XX function.Functional failure state 1" and "XX function.Functional failure state 2" occurring per flight hour should be less than the quantitative requirements for XX safety or mission reliability; 3) The combination of functions XX and XX should be developed in accordance with the XX level of development assurance. 4) Function XX should be developed in accordance with the XX level of development assurance. 5) Function XX and Function XX should remain independent of each other; XX should be filled in according to the actual situation in the FHA data.
7. A model-based device for functional hazard analysis of aircraft, characterized in that: It includes the following parts: The module includes a database, a basic data setting module, a functional model import module, a functional failure status determination module, a cause event determination module, a result event determination module, an event sequence model construction module, an FHA automatic generation module, and a security task reliability requirement generation module. The database includes flight phase data, safety impact data, mission reliability impact data, external event data, functional model data, functional failure status data, initial event data, outcome event data, event sequence data, FHA data, and safety mission reliability requirements data. The basic data setting module is used to set flight phase data, mission reliability impact data, and external event data; The functional model import module is used to import the functional decomposition structure model, functional flow model and scenario-based functional model from the functional model, identify the lowest level function in the functional decomposition structure model, identify the functions related to the function according to the functional flow model, obtain the relationship between different functions, and identify the scenario activities, operation scenarios and flight phases of the function according to the scenario-based functional model. The functional failure status determination module is used to determine functional failure status data, including displaying and importing existing functional failure status data, and adding and deleting functional failure status data. The initial cause event determination module is used to generate initial cause event data. The initial cause event determination module obtains all functions and function failure states from the function failure state data in the database, and takes each combination of function and function failure state as an initial cause event to obtain an initial cause event list. It obtains a scenario-based function model from the function model import module and automatically populates the initial cause event attributes in the initial cause event list. If a scenario-based function model is not obtained from the function model import module, only the function and function failure state attributes in the initial cause event attributes are filled in, and the attributes of flight phase, scenario activity and running scenario need to be manually filled in by clicking the corresponding initial cause event. The result event determination module is used to obtain result event data. The result event determination module arranges and combines the danger severity level of the security impact data and the task reliability level of the task reliability impact data in the database to obtain result event data with the danger severity level first and the task reliability level second. The event sequence model construction module is used to construct an event sequence model. It constructs an event sequence module from the initial cause event display submodule, key event display submodule, and result event display submodule in the construction display submodule. The event sequence module is saved and displayed in the event sequence display submodule. The verification submodule is used to verify all event sequence modules. The FHA automatic generation module is used to generate and query FHA data. Based on the event sequence data in the database, each complete event sequence chain in each event sequence model is taken as a record in the FHA data. Each record includes the function, failure status, operating scenario, and flight phase of the initiating event in each event sequence, the event name of the key event, and the hazard severity level, hazard probability level, safety impact description, mission reliability level, mission reliability requirements, and mission impact description of the resulting event. The security task reliability requirement generation module is used to generate and query security task reliability requirements. Based on the selected hazard severity level and task reliability level, it selects the corresponding records from the FHA data list and generates a security task reliability requirement document based on the records in the FHA and the specific expression template of the task reliability requirement.
8. The apparatus for model-based aircraft functional hazard analysis according to claim 7, characterized in that: The event sequence model construction module includes an initial event display submodule, a key event display submodule, an outcome event display submodule, a construction display submodule, an event sequence display submodule, and a verification submodule. The initial cause event display submodule is connected to the database and the initial cause event determination module respectively. The initial cause event display submodule retrieves the initial cause event data from the database and displays it in a list. Selected initial cause events can be placed into the display submodule by dragging and dropping. If an initial cause event is clicked directly in the initial cause event display submodule, the initial cause event determination module will be called to adjust the attributes of the initial cause event. The critical event display submodule is connected to the database, the function failure status determination module, and the basic data setting module. The critical event display submodule retrieves function failure status data and external event data from the database and displays them in a list. Selected critical events can be placed into the display submodule by dragging and dropping. If a critical event is clicked directly in the critical event display submodule, if the critical event is function failure status data, the function failure status determination module will be called to modify the function failure status data. If the critical event is an external event, the basic data setting module will be called to modify the external event data. The results event display submodule connects to the database and displays the results event data. Selected results events can be placed into the display submodule by dragging and dropping. The Build Display submodule displays an event sequence model being edited. It allows editing of the initial event, key event, result event, and occurrence / non-occurrence lines used in the event sequence model. The Build Display submodule generates initial events, key events, and result events by dragging and dropping them from the Initial Event Display submodule, Key Event Display submodule, and Result Event Display submodule, respectively. These events are then connected together using occurrence / non-occurrence lines to form an event sequence model. The Build Display submodule saves the completed event sequence model in the event sequence data, which is stored in a database. The event sequence data includes initial events, key events, result events, and occurrence / non-occurrence lines between key events and result events. The event sequence display submodule is used to display saved event sequence data. Clicking on an event sequence name in the event sequence data will display the corresponding event sequence model in the display submodule. The validation submodule is used to validate the event sequence data stored in the database. The validation rules are checked and quantitatively verified according to the construction rules in step six. If the validation fails, the event sequence that fails the validation needs to be marked and displayed in the event sequence display submodule.