Related failure analysis coupling factor generation method and device, medium and product
By adopting a systematic method for generating coupling factors in related failure analysis, the problems of incomplete identification of coupling factors and lack of correlation of analysis results are solved, achieving more efficient and accurate DFA analysis and improving the consistency and coordination of functional safety processes.
Patent Information
- Application Number
- CN202511547413.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-10-28
- Publication Date
- 2026-01-23
AI Technical Summary
In existing technologies, Dependent Failure Analysis (DFA) lacks completeness in identifying coupling factors and lacks correlation between the results of different functional safety analyses, resulting in insufficient accuracy and consistency of the analysis.
This paper provides a method for generating coupling factors in related failure analysis. By acquiring coupling factors of the target product, collecting coupling factors from the fault tree, or generating coupling factors based on the security architecture, and combining FTA analysis and security architecture, coupling factors are systematically identified and automatically generated.
It significantly improves the comprehensiveness of coupling factor identification, increases analysis efficiency, shortens the analysis cycle, reduces development costs, and realizes the organic linkage and traceability of various work products throughout the security lifecycle.
Smart Images

Figure CN121389320A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the field of functional safety technology, in particular to a related failure analysis coupling factor generation method, device, medium and product. BACKGROUND
[0002] DFA (Dependent Failure Analysis) is a key analysis method in the ISO 26262 functional safety standard, which plays an important role in ensuring the safety and reliability of automotive electronic and electrical systems. In the DFA analysis process, the identification of coupling factors is the first and most important step. The core challenge faced by the industry in this step is how to systematically ensure the completeness of the identified coupling factors and avoid the omission of coupling factors that have potential related failure relationships. Traditional DFA analysis methods based on Excel usually rely on the personal experience and brainstorming of engineers, and lack a systematic and structured identification mechanism, making it difficult to cover all possible coupling factors comprehensively, which seriously affects the accuracy and reliability of the analysis.
[0003] In addition, the traditional Excel analysis method is often isolated from other work products of functional safety, and it is difficult to form effective association with FTA (Fault Tree Analysis), safety requirement decomposition, and architecture design outputs. This disconnection not only increases the analysis repetition and workload, but also makes it difficult to trace the achievements between different stages in the safety life cycle, thereby affecting the consistency and coordination of the overall functional safety process. SUMMARY
[0004] In view of the above problems of insufficient completeness of coupling factor identification and lack of association between different safety activities, the present application provides a related failure analysis coupling factor generation method, device, medium and product, which aims to ensure the comprehensiveness and accuracy of coupling factor identification through a systematic solution, and effectively break down the information barriers between different functional safety analysis results.
[0005] The present application provides a related failure analysis coupling factor generation method, comprising:
[0006] Obtaining coupling factors, the obtaining method of the coupling factors includes:
[0007] Obtaining the coupling factors of the target product, or collecting the coupling factors from the fault tree of the target product, or obtaining the coupling factors based on the safety architecture of the target product;
[0008] Performing failure cause analysis and failure impact analysis according to the coupling factors.
[0009] Optionally, the collecting the coupling factors from the fault tree of the target product comprises:
[0010] obtaining a second-order minimal cut set in the target product fault tree, and taking the second-order minimal cut set as the coupling factor.
[0011] Optionally, the obtaining of the coupling factor based on the safety architecture of the target product comprises:
[0012] identifying a decomposed safety requirement in an automotive safety integrity level architecture of the target product, determining a target element associated with the safety requirement, and taking the target element as the coupling factor.
[0013] Optionally, the obtaining of the coupling factor based on the safety architecture of the target product comprises:
[0014] identifying a plurality of target elements sharing one input interface in an automotive safety integrity level architecture of the target product, combining the target elements, and generating the coupling factor.
[0015] Optionally, the obtaining of the coupling factor based on the safety architecture of the target product comprises:
[0016] identifying two target elements having a data transmission relationship and sending data from a low-level target element to a high-level target element in an automotive safety integrity level architecture of the target product, and taking the two target elements as the coupling factor.
[0017] Optionally, the obtaining of the coupling factor based on the safety architecture of the target product comprises:
[0018] identifying a plurality of target elements sharing the same hardware resource and having different automotive safety integrity levels in an automotive safety integrity level architecture of the target product, and taking the target elements as the coupling factor.
[0019] Optionally, the obtaining of the coupling factor of the target product comprises:
[0020] providing a user with a predefined coupling factor category and / or a guide word;
[0021] receiving a coupling factor selected or input by a user based on the coupling factor category and / or the guide word.
[0022] The application also provides an electronic device, comprising: one or more processors; and a memory storing computer program instructions which, when executed, cause the processor to perform the steps of the related failure analysis coupling factor generation method as described above.
[0023] The application further provides a computer readable medium, which stores computer program instructions, and the computer program instructions can be executed by a processor to implement the related failure analysis coupling factor generation method.
[0024] The application further provides a computer program product, which comprises computer programs / instructions, and the computer programs / instructions are executed by a processor to implement the steps of the related failure analysis coupling factor generation method.
[0025] The above technical solution has the following beneficial effects:
[0026] In the technical solution, the related failure analysis coupling factor generation method can perform failure cause analysis and failure influence analysis based on the obtained coupling factors. The coupling factors are obtained in three ways: one is to directly obtain the coupling factors of the target product; two is to extract the coupling factors from the fault tree of the target product; and three is to generate the coupling factors according to the safety architecture of the target product. The method obtains coupling elements in a multi-source manner, significantly improves the comprehensiveness of coupling factor identification in DFA analysis, effectively improves the analysis efficiency, shortens the analysis cycle, and reduces the development cost. BRIEF DESCRIPTION OF DRAWINGS
[0027] One or more embodiments are illustrated by way of example in the accompanying drawings that are not intended to be limiting of the embodiments. Like reference numbers in the drawings indicate like elements unless otherwise specified. The drawings are not necessarily to scale, the emphasis instead being placed upon illustrating the principles of the embodiments.
[0028] Figure 1 A method flowchart of an embodiment of the related failure analysis coupling factor generation method described in the application;
[0029] Figure 2 An interface schematic diagram for guiding a user to add coupling factors through coupling factor guide words;
[0030] Figure 3 An interface schematic diagram of an FTA analysis report;
[0031] Figure 4 An interface schematic diagram for decomposing a technical safety requirement TSR into two software safety requirements;
[0032] Figure 5 An extraction schematic diagram of part of elements of a whole vehicle architecture;
[0033] Figure 6 A whole vehicle architecture schematic diagram;
[0034] Figure 7 Interface diagram for hardware resource allocation for software components;
[0035] Figure 8 Interface diagram for one embodiment of generating coupling factors through a vehicle architecture;
[0036] Figure 9 Interface diagram for another embodiment of generating coupling factors through a vehicle architecture;
[0037] Figure 10 Interface diagram for one embodiment of generating coupling factors through a software architecture;
[0038] Figure 11 Hardware structure diagram of a computer device for providing a related failure analysis coupling factor generation method for an application embodiment. DETAILED DESCRIPTION
[0039] The advantages of the present application are further set forth in the detailed description below.
[0040] The exemplary embodiments will be described in detail herein below with reference to the attached drawings.
[0041] The terminology used in the present disclosure is for the purpose of describing particular embodiments only and is not intended to be limiting of the present disclosure. As used in the description of the present disclosure and the appended claims, the singular forms "a", "an" and "the" are intended to include the plural forms as well, unless the context clearly indicates otherwise. It also will be understood that the term "and / or" as used herein refers to and encompasses any and all possible combinations of one or more of the associated listed items.
[0042] It will be understood that, although the terms first, second, third, etc. can be used herein to describe various information, these terms are not intended to denote a temporal or chronological order. Rather, these terms are used solely to distinguish different sets of information from one another. For example, a first information can be termed a second information, and similarly, a second information can be termed a first information without departing from the scope of the present disclosure. As used herein, the term "if' can be interpreted to mean "when" or "upon" or "in response to determining" depending on the context.
[0043] In the description of this application, it should be understood that the numerical labels before the steps do not indicate the order of the steps, but are only used to facilitate the description of this application and to distinguish each step, and therefore should not be construed as a limitation of this application.
[0044] The failure analysis coupling factor generation method of this application can be applied to fields such as automotive safety, aviation, and aerospace. This application can perform failure cause analysis and failure impact analysis based on the acquired coupling factors. The acquisition of coupling factors encompasses three approaches: first, directly acquiring coupling factors from the target product; second, extracting coupling factors from the target product's fault tree; and third, generating coupling factors based on the target product's security architecture. This method significantly improves the comprehensiveness of coupling factor identification in DFA analysis by acquiring coupling elements through a multi-source approach. By introducing FTA (Fault Tree Analysis) results to automatically generate coupling factors, it effectively improves analysis efficiency, shortens the analysis cycle, and reduces development costs.
[0045] The following terms are used in this document:
[0046] ESC: Electronic Stability Control, is an active safety system that prevents vehicle loss of control (such as skidding or sideslip) by controlling the braking force of individual wheels and engine torque, ensuring that the vehicle travels as the driver intends.
[0047] ADAS controller, or Advanced Driver-Assistance Systems Controller, is the core electronic control unit (ECU) used to implement various ADAS functions (such as adaptive cruise control (ACC), automatic emergency braking (AEB), lane keeping assist (LKA), etc.). It is responsible for processing sensor data, making decisions, and executing corresponding control actions.
[0048] EPS, Electric Power Steering, is a system that uses an electric motor to provide steering assistance. It replaces traditional hydraulic power steering and offers advantages such as energy efficiency and the ability to integrate advanced functions (such as lane keeping assist and automatic parking).
[0049] MCU, Microcontroller Unit, is also known as a single-chip microcomputer. It is the core computing brain of various ECUs (Electronic Control Units) in automobiles, integrating a processor core (CPU), memory (ROM / RAM), and various peripheral interfaces to perform control, calculation, and communication tasks.
[0050] A CAN transceiver, or Controller Area Network Transceiver, is an interface chip that connects the CAN controller and the physical CAN bus. It is responsible for converting the digital signals generated by the CAN controller into differential signals for transmission on the bus, and vice versa, providing anti-interference capabilities.
[0051] ASIL, Automotive Safety Integrity Level, is a risk classification system defined in the ISO 26262 standard. It is used to assess the stringency level required for a vehicle system or function. There are four levels: ASIL A (lowest stringency level), ASIL B, ASIL C, and ASIL D (highest stringency level). The level is determined by the severity (S), exposure rate (E), and controllability (C) of the hazard event.
[0052] This application proposes a method for generating coupling factors in relevant failure analysis to address the shortcomings of insufficient completeness in identifying coupling factors and the lack of correlation between various safety activities. (See reference...) Figure 1 This is a flowchart illustrating a method for generating related failure analysis coupling factors according to a preferred embodiment of this application. As can be seen from the figure, the method for generating related failure analysis coupling factors provided in this embodiment includes the following steps:
[0053] S1. Identify coupling factors;
[0054] Furthermore, the method for obtaining the coupling factors in step S1 may include:
[0055] The coupling factors of the target product are obtained, or the coupling factors are collected from the fault tree of the target product, or the coupling factors are obtained based on the security architecture of the target product.
[0056] In this embodiment, obtaining the coupling factors of the target product includes: providing the user with predefined coupling factor categories and / or guiding words; and receiving coupling factors selected or input by the user based on the coupling factor categories and / or the guiding words.
[0057] See Figure 2 A coupling factor interface is added. In this embodiment, the coupling factor categories include: shared resources, shared information input, insufficient environmental interference resistance, system coupling, and components and communications of the same type. Users can also add sub-items of coupling factors and failure types as needed.
[0058] In practical applications, the coupling factor categories and coupling factor guide terms are extracted from the DFA analysis content in the ISO 26262 standard. Users can not only use the coupling factor categories and coupling factor guide terms provided in this system, but also create project-level or enterprise-level coupling factor guide term libraries. This guide term library facilitates unified analysis guidance across the company and improves analysis efficiency.
[0059] In this embodiment, the step of collecting the coupling factors from the fault tree of the target product includes: obtaining the second-order minimal cut set in the fault tree of the target product, and using the second-order minimal cut set as the coupling factor for subsequent related failure analysis.
[0060] Specifically, the process of obtaining the second-order minimal cut sets is implemented through a software environment that integrates FTA analysis tools. After using this tool to complete fault tree analysis and generate all minimal cut sets, the system automatically extracts all second-order minimal cut sets and inputs the associated element objects as coupling factors into the DFA analysis module.
[0061] It should be noted that the coupling factors obtained from FTA analysis tools should be classified as common-cause failure types. A minimal cut set represents the smallest set of basic events that can lead to the top event, while a second-order minimal cut set refers to a failure combination consisting of two basic events, representing a two-point failure scenario. The purpose of introducing such second-order minimal cut sets into DFA analysis is to systematically identify whether there is a common underlying cause (i.e., a common cause) that could lead to the simultaneous failure of the two events. If no such common cause exists, it confirms that the independence judgment of the two-point failure in the FTA analysis is correct; if a common cause is identified, it indicates that the second-order cut set in the original FTA model actually has a common failure mechanism, requiring corresponding correction and optimization of the fault tree.
[0062] It should also be noted that this embodiment does not include minimum cut sets of order two or higher (i.e., order three and above) in the scope of DFA analysis. This is because in the field of functional safety, multi-point fault combinations involving more than two faults are usually regarded as safety faults and do not affect the safety integrity of the system. Therefore, there is no need to carry out further common cause analysis.
[0063] For example, see Figure 3 As shown, the minimum cut sets in the FTA analysis report include four sets of second-order minimum cut sets: (B011, B010), (B008, B009), (B006, B007), and (B015, B014). Each bottom event number corresponds to an element in the architecture. The names of the elements in the above sets will automatically be used as coupling factors and enter the DFA analysis stage for subsequent common cause failure verification.
[0064] In this embodiment, obtaining the coupling factor based on the security architecture of the target product includes: identifying the decomposed security requirements in the Automotive Safety Integrity Level (ASIL) architecture of the target product, determining the target element associated with the security requirement, and using the target element as the coupling factor.
[0065] Specifically, if the security requirements corresponding to two target elements are generated by ASIL decomposition of the same superior security requirement, then these two elements automatically constitute a coupling factor and are imported into the DFA analysis process for cascading failure and common cause failure analysis.
[0066] See Figure 4 This diagram illustrates the security requirements of a security requirements management tool integrated into the software. It's a structured three-tier functional safety requirements network. The central MCU APP element is the focus layer, and its tree structure shows the technical security requirements assigned to this focus element (TSR001, TSR006), along with the software security requirements (SSR002, SSR004, SSR003) that these technical security requirements are broken down into. The leftmost ADAS controller element is the upper level, and its tree structure shows the technical security requirements assigned to the focus layer elements (TSR001, TSR006). The rightmost control software module, maximum limit module, and LCC state machine module are the lower level, and their tree structure shows the software security requirements (SSR002, SSR004, SSR003) assigned to these modules by the focus layer. For example, in the ASIL security requirements list (see...), Figure 4 Safety requirements SSR002 and SSR004 are decomposed from ASIL D level technical safety requirement TSR001. SSR002 is assigned to ASIL D (D), and SSR004 is assigned to QM (ASIL D). In this case, DFA analysis is required to perform a coupled failure assessment on the two target elements implementing SSR002 and SSR004 respectively, to determine the rationality of this ASIL decomposition. If the analysis shows that both elements fail simultaneously due to common cause failure or cascading failure, it indicates that they are not independent, and this ASIL decomposition method is not reasonable.
[0067] It should be noted that the method described in this embodiment relies on an integrated tool environment: the ASIL decomposition tool is responsible for outputting the relationships between the decomposed architectural elements, while the DFA analysis tool automatically converts them into coupling factors to be analyzed and provides corresponding analysis support. The actual analysis work, including the specific determination of cascading failures and common-cause failures, is completed based on the analysis objects and context provided by the system.
[0068] In this embodiment, obtaining the coupling factors based on the security architecture of the target product includes: identifying multiple target elements in the vehicle safety integrity level architecture of the target product that share an input interface, and generating coupling factors from the multiple target elements.
[0069] Specifically, if multiple target elements share the same input interface, there are potential coupling failure paths among these elements, which need to be imported into the DFA analysis process as coupling items to assess whether there is a common cause failure.
[0070] Taking the actual vehicle speed signal interface as an example, please refer to... Figure 5 This signal is generated by the Electronic Stability Control (ESC) system and simultaneously sent to the ADAS controller and the forward millimeter-wave radar. This shared input relationship will be automatically identified, generating a pair of coupling factors between the ADAS controller and the forward millimeter-wave radar.
[0071] In this embodiment, obtaining the coupling factor based on the security architecture of the target product includes: identifying two target elements in the vehicle safety integrity level architecture of the target product that have a data transmission relationship and send data from a lower-level target element to a higher-level target element, and using the two target elements as the coupling factor.
[0072] It should be noted that, in this embodiment, the coupling factor is: the target element that sends data from a lower-level target element to a higher-level target element, the corresponding target element is extracted, and two of these target elements are used as the coupling factor. That is, the vehicle safety integrity level of the data sender target element is lower than the level of the data receiver target element; and these two target elements are used as the coupling factor.
[0073] Specifically, if a target element with a low ASIL level sends data to a target element with a high ASIL level, the two elements automatically constitute a coupling factor and are imported into the DFA analysis process to assess whether there is a risk of cascading failure caused by the low-level element.
[0074] See Figure 6As shown, taking the data transmission between the Electronic Stability Control (ESC) system and the ADAS controller as an example: the highest functional safety requirement level assigned to the ESC is ASIL D, so it is marked as an ASIL D level element in the architecture; the highest functional safety requirement level assigned to the ADAS controller is ASIL B(D), so it is marked as an ASIL B(D) level element. If the ADAS controller (lower ASIL level) sends a target deceleration value (ASIL B) to the ESC (higher ASIL level), then the interface relationship meets the above coupling conditions. The ESC and ADAS are considered as coupling factors, and the failure of the target deceleration value is automatically imported into the DFA analysis as a failure cause.
[0075] In this embodiment, obtaining the coupling factor based on the security architecture of the target product includes: identifying multiple target elements in the vehicle safety integrity level architecture of the target product that share the same hardware resources, and wherein the multiple target elements have different vehicle safety integrity levels, and using the target elements as the coupling factor. (Refer to...) Figure 7 As shown, the maximum limit module (with ASIL D(D)) is allocated 4 cores of hardware resources, and the control module (with ASIL QM(D)) is also allocated 4 cores of hardware resources.
[0076] Specifically, if multiple target elements with different ASIL levels share the same hardware resource, there is a potential resource-sharing coupling between these elements. This needs to be imported into the DFA analysis process as a coupling item to assess whether there is a risk of cascading failure caused by hardware resource failure.
[0077] Taking software components as an example, the control software module (QM level) and the maximum value limiting software module (ASIL D level) share the hardware resource of the Core 4 processor core. This sharing relationship will be automatically identified, and the coupling factor consisting of these two software modules will be generated.
[0078] S2. Analyze the causes of failure and the effects of failure based on the aforementioned coupling factors.
[0079] In this embodiment, the method for generating related failure analysis coupling factors can perform analysis layer by layer according to the product's architecture hierarchy. The analysis hierarchy includes: vehicle level, system level, software level, and hardware level. The vehicle level may include: ESC, ADAS controller, forward millimeter-wave radar, front camera module, and EPS, etc. The ADAS controller in the system level may include: MCU, power management chip, and CAN transceiver, etc. The MCU software level may include: torque limiting module and lateral control module. The MCU hardware level may include: CPU, RAM, ROM rack position sensor, camera, and motor position sensor, etc.
[0080] Specifically, this embodiment performs targeted failure analysis based on the different sources and characteristics of the coupling factors:
[0081] When the coupling factor originates from the second-order minimal cut set extracted by the FTA analysis tool, a common cause failure check is performed on the coupling factor to determine whether there is a common root cause that causes the two-point failure to occur simultaneously.
[0082] When the coupling factor is generated by ASIL decomposition, a common cause failure analysis is performed on the coupling factor based on the analysis context provided by the system to verify the rationality of ASIL decomposition and the independence between elements.
[0083] When the coupling factor corresponds to an element sharing the same input interface (e.g., emitted by the Electronic Stability Control (ESC) system and simultaneously sent to the ADAS controller and the forward millimeter-wave radar's actual vehicle speed signal interface), the analysis considers the failure of this shared signal as a potential common cause to determine whether it could lead to the simultaneous failure of multiple receiving elements. A common cause failure analysis is performed to verify the rationality of the interface sharing design, thus violating relevant safety objectives (SG). An analytical mind map is generated after the analysis. Figure 8 As shown, the CCF (common cause failure) icon displays the coupling factors generated by the architecture: ADAS controller & forward millimeter-wave radar. The FC (Failure cause) below it represents the failure cause, which is the failure of the actual vehicle speed signal generated by the architecture. The FE (Failure effect) failure impact needs to be analyzed by the user and judged whether the impact violates the safety objective SG.
[0084] When the coupling factors involve data transmission from a lower ASIL-level element to a higher ASIL-level element, the focus is on analyzing whether a failure in the lower-level element triggers a cascading failure in the higher-level element through this data interface, thereby assessing the security of cross-integrity data transmission. This cascading failure analysis verifies the security of data transmission between elements of different integrity levels and the rationality of the architectural design. An analytical mind map is generated after the analysis for reference. Figure 9 As shown, when a low-level ADAS (ASILB) element sends an ASILB data (target deceleration value) to a high-level ESC (ASIL D) element, a cascading failure (CF) is automatically generated by the architecture, displaying the coupling factors: ADAS controller & ESC. The subsequent FC (Fault Failure) is caused by an error in the target deceleration value generated by the architecture; the resulting FE (Fault Failure) requires the user to analyze and determine whether it violates safety objectives.
[0085] When the coupling factors are elements of different ASIL levels sharing the same hardware resource, based on the automatically generated hardware resource application table, the existence of cascading failures is analyzed to verify the security of resource sharing in a hybrid criticality system. This analysis verifies the security and rationality of shared hardware resources in a hybrid criticality system. An analytical mind map is generated after the analysis (see attached image). Figure 10 As shown.
[0086] Through the targeted analysis that distinguishes between sources and scenarios, this embodiment can systematically complete relevant failure analysis and provide a basis for optimizing the security architecture.
[0087] The failure analysis coupling factor generation method of this application can perform failure type analysis, failure cause analysis, and failure impact analysis based on the acquired coupling factors. The acquisition of coupling factors encompasses three approaches: first, guiding the user to generate coupling factors based on coupling factor prompts provided by the system; second, extracting coupling factors from the fault tree of the target product; and third, generating coupling factors based on the security architecture of the target product. This method significantly improves the comprehensiveness of coupling factor identification in DFA analysis by acquiring coupling elements through a multi-source approach; by introducing FTA (Fault Tree Analysis) and architecture analysis results to automatically generate coupling factors, it effectively improves analysis efficiency, shortens the analysis cycle, and reduces development costs; and it enables the organic linkage and traceability of various work products throughout the security lifecycle.
[0088] The steps of the various methods described above are only for clarity. In practice, they can be combined into one step or some steps can be split into multiple steps. As long as they include the same logical relationship, they are all within the scope of protection of this patent. Adding insignificant modifications or introducing insignificant designs to the algorithm or process, but without changing the core design of the algorithm and process, are also within the scope of protection of this patent.
[0089] Furthermore, some embodiments of this application also provide an electronic device. The electronic device can be various forms of digital computer, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, etc. The electronic device can also be various forms of mobile devices, such as personal digital processors, cellular phones, smartphones, wearable devices, and other similar computing devices.
[0090] The electronic device includes: one or more processors; and a memory storing computer program instructions that, when executed, cause the processor to perform the steps of the methods provided in any one or more of the above embodiments. Figure 11 An exemplary structural diagram of the electronic device is disclosed. For example... Figure 11 As shown, the electronic device includes one or more processors 1101, a memory 1102, and interfaces for connecting the components, including high-speed interfaces and low-speed interfaces. The components are interconnected via different buses and can be mounted on a common motherboard or otherwise as required. The processors can process instructions executed within the electronic device, including instructions stored in or on memory to display graphical information of a GUI on an external input / output device (such as a display device coupled to the interface). In some other embodiments, multiple processors and / or multiple buses can be used with multiple memories and multiple memory modules, if desired. Similarly, multiple electronic devices can be connected, each providing some of the necessary operations (e.g., as a server array, a group of blade servers, or a multiprocessor system). The components, their connections and relationships, and their functions shown herein are merely examples and are not intended to limit the implementation of the present application described and / or claimed herein.
[0091] The electronic device may further include an input device 1103 and an output device 1104. The processor 1101, memory 1102, input device 1103, and output device 1104 may be connected via a bus or other means. Figure 11 Taking the example of a connection between China and Israel via a bus.
[0092] Input device 1103 can receive input numerical or character information, and generate key signal inputs related to user settings and function control of the electronic device, such as a touch screen, keypad, mouse, trackpad, touchpad, joystick, one or more mouse buttons, trackball, joystick, etc. Output device 1104 may include a display device, auxiliary lighting device (e.g., LED), and haptic feedback device (e.g., vibration motor). The display device may include, but is not limited to, a liquid crystal display (LCD), a light-emitting diode (LED) display, and a plasma display. In some embodiments, the display device may be a touch screen.
[0093] To provide interaction with the user, the electronic device can be a computer. The computer has: a display device for displaying information to the user (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor); and a keyboard and pointing device (e.g., a mouse or trackball) through which the user provides input to the computer. Other types of devices can also be used to provide interaction with the user; for example, the feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including sound input, voice input, or tactile input).
[0094] In this embodiment, a computer-readable medium stores a computer program / instructions that, when executed by a processor, implement the steps of the methods provided in any one or more of the above embodiments. This computer-readable medium may be included in the electronic device described in the above embodiments; or it may exist independently and not assembled into that device. The aforementioned computer-readable medium carries one or more computer-readable instructions.
[0095] The memory 1102 can serve as a non-transitory computer-readable storage medium, used to store non-transitory software programs, non-transitory computer-executable programs, and modules. The processor 1101 executes various functional applications and data processing of the server by running the non-transitory software programs, instructions, and modules stored in the memory 1102, thereby implementing the program instructions / modules corresponding to the methods provided in any one or more of the embodiments described above in this application.
[0096] The memory 1102 may include a program storage area and a data storage area. The program storage area may store the operating system and applications required for at least one function; the data storage area may store data created based on the use of the electronic device. Furthermore, the memory 1102 may include high-speed random access memory and may also include non-transitory memory, such as at least one disk storage device, flash memory device, or other non-transitory solid-state storage device. In some embodiments, the memory 1102 may optionally include memory remotely located relative to the processor 1101, and these remote memories can be connected to the electronic device via a network. Examples of such networks include, but are not limited to, the Internet, intranets, local area networks, mobile communication networks, and combinations thereof.
[0097] It should be noted that the computer-readable medium described in this application can be a computer-readable signal medium or a computer-readable storage medium, or any combination thereof. A computer-readable medium can be, for example,—but not limited to—an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples of a computer-readable storage medium may include, but are not limited to: an electrical connection having one or more wires, a portable computer disk, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage device, magnetic storage device, or any suitable combination thereof. In this application, a computer-readable medium can be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, apparatus, or device.
[0098] Computer-readable media include permanent and non-permanent, removable and non-removable media, which can store information by any method or technology. Information can be computer-readable instructions, data structures, modules of programs, or other data. Examples of computer storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, read-only optical disc (CD-ROM), digital versatile optical disc (DVD) or other optical storage, magnetic tape, magnetic disk storage or other magnetic storage devices, or any other non-transfer medium that can be used to store information accessible by a computing device.
[0099] Computer program code for performing the operations of this application can be written in one or more programming languages or a combination thereof, including object-oriented programming languages such as Java, Smalltalk, and C++, and conventional procedural programming languages such as the "C" language or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving remote computers, the remote computer can be connected to the user's computer via any type of network—including a local area network (LAN) or a wide area network (WAN)—or can be connected to an external computer (e.g., via the Internet using an Internet service provider).
[0100] In the above embodiments, implementation can be achieved, in whole or in part, through software, hardware, firmware, or any combination thereof. For example, it can be implemented using an application-specific integrated circuit (ASIC), a general-purpose computer, or any other similar hardware device. In some embodiments, the software program of this application can be executed by a processor to implement the steps or functions described above. Similarly, the software program of this application (including related data structures) can be stored in a computer-readable recording medium, such as RAM memory, magnetic or optical drives, floppy disks, or similar devices. Furthermore, some steps or functions of this application can be implemented in hardware, for example, as circuitry that works with a processor to perform the various steps or functions.
[0101] The computer program product provided in this application includes one or more computer programs / instructions. When executed by a processor, these computer programs / instructions generate, in whole or in part, the processes or functions described in this application. The computer may be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions may be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions may be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via wired (e.g., coaxial cable, fiber optic, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium may be any available medium accessible to a computer or a data storage device such as a server or data center that integrates one or more available media. The available medium may be a magnetic medium (e.g., floppy disk, hard disk, magnetic tape), an optical medium (e.g., DVD), or a semiconductor medium (e.g., solid-state disk (SSD)).
[0102] The flowcharts or block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of devices, methods, and computer program products according to various embodiments of this application. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, may be implemented using a dedicated hardware-specific system that performs the specified function or operation, or using a combination of dedicated hardware and computer instructions.
[0103] The scope of this application is defined by the appended claims rather than the foregoing description, and is therefore intended to encompass all variations falling within the meaning and scope of equivalents of the claims. No reference numerals in the claims should be construed as limiting the scope of the claims. Furthermore, it is clear that the word "comprising" does not exclude other units or steps, and the singular does not exclude the plural. Multiple units or devices recited in a device claim may also be implemented by a single unit or device in software or hardware. Terms such as "first," "second," etc., are used only for distinguishing descriptions and do not indicate any particular order, nor should they be construed as indicating or implying relative importance.
[0104] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit them. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some or all of the technical features therein. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of this application.
Claims
1. A method for generating coupling factors in related failure analysis, characterized in that, include: The coupling factors are obtained, and the methods for obtaining the coupling factors include: The coupling factors of the target product are obtained, or the coupling factors are collected from the fault tree of the target product, or the coupling factors are obtained based on the security architecture of the target product. Failure cause analysis and failure impact analysis are performed based on the aforementioned coupling factors.
2. The method for generating coupling factors for relevant failure analysis according to claim 1, characterized in that, The process of collecting coupling factors from the fault tree of the target product includes: Obtain the second-order minimum cut set in the fault tree of the target product, and use the second-order minimum cut set as the coupling factor.
3. The method for generating coupling factors for relevant failure analysis according to claim 1, characterized in that, The process of obtaining the coupling factors based on the security architecture of the target product includes: Identify the decomposed safety requirements in the automotive safety integrity level architecture of the target product, determine the target elements associated with the safety requirements, and use the target elements as the coupling factors.
4. The method for generating coupling factors for relevant failure analysis according to claim 1, characterized in that, The process of obtaining the coupling factors based on the security architecture of the target product includes: In the automotive safety integrity level architecture of the target product, multiple target elements that share a single input interface are identified, and these target elements are combined to generate the coupling factor.
5. The method for generating coupling factors for relevant failure analysis according to claim 1, characterized in that, The process of obtaining the coupling factors based on the security architecture of the target product includes: In the automotive safety integrity level architecture of the target product, there are two target elements that have a data transmission relationship and send data from a lower-level target element to a higher-level target element. These two target elements are considered as the coupling factors.
6. The method for generating coupling factors for relevant failure analysis according to claim 1, characterized in that, The process of obtaining the coupling factors based on the security architecture of the target product includes: In the automotive safety integrity level architecture of the target product, multiple target elements that share the same hardware resources and have different automotive safety integrity levels are identified, and these target elements are used as the coupling factors.
7. The method for generating coupling factors for relevant failure analysis according to claim 1, characterized in that, The process of obtaining the coupling factors of the target product includes: Provide users with predefined categories of coupling factors and / or guide words; Receive coupling factors selected or input by the user based on the coupling factor category and / or the guide word.
8. An electronic device, characterized in that, The electronic device includes: One or more processors; and A memory storing computer program instructions, which, when executed, cause the processor to perform the steps of the method for generating related failure analysis coupling factors as described in any one of claims 1 to 7.
9. A computer-readable medium having a computer program / instructions stored thereon, characterized in that, When the computer program / instruction is executed by the processor, it implements the steps of the method for generating related failure analysis coupling factors as described in any one of claims 1 to 7.
10. A computer program product comprising a computer program / instructions, characterized in that, When the computer program / instruction is executed by the processor, it implements the steps of the method for generating related failure analysis coupling factors as described in any one of claims 1 to 7.