Aircraft and combined failure state analysis method for system safety of aircraft

By constructing a combined failure state matrix and utilizing matrix symmetry to simplify merging, the standardization problem of combined failure state analysis in aircraft and system safety assessment is solved, improving identification efficiency and the reliability of safety assessment, while reducing workload and the risk of omission.

CN121786944APending Publication Date: 2026-04-03AVIC GENERAL HUANAN AIRCRAFT IND CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-11-19
Publication Date
2026-04-03

AI Technical Summary

Technical Problem

The lack of standardized methods for analyzing combined failure states in existing technologies leads to an exponential increase in computational complexity for safety engineers when conducting safety assessments of aircraft and systems. This results in frequent discrepancies in the results and the potential to overlook important states, impacting aircraft safety and economic efficiency.

Method used

A combined failure state analysis method based on function definition is adopted. By constructing a combined failure state matrix, the matrix symmetry is used to calculate only the lower triangular region. The simplified and merged regions are then added to the failure state list to identify combined failure states.

Benefits of technology

It has achieved comprehensive and standardized safety analysis of aircraft and systems, reduced errors and omissions in manual enumeration, improved the efficiency of identifying combined failure states, reduced workload, and enhanced the reliability of safety assessment.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121786944A_ABST
    Figure CN121786944A_ABST
Patent Text Reader

Abstract

The invention discloses an aircraft and a combined failure state analysis method for system safety of the aircraft. Identifying a single failure state based on the functional definition; after the integrity of a single failure state is confirmed, the influence level is evaluated, the integrity of a task stage is verified, simplification and combination are carried out, and an external event is determined, a combined failure state is formed through combination; and constructing a combined failure state matrix, only calculating the combined failure state of the lower triangular region by using the matrix symmetry, and supplementing the combined failure state to a failure state list after simplification and combination. According to the method, errors and omission caused by manual enumeration can be reduced, and the traversal combination failure recognition analysis quantity is reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of aircraft and aircraft system safety analysis technology, specifically relating to a combined failure state analysis method for the safety of aircraft and its systems, applicable to the safety design and airworthiness compliance verification of aviation equipment such as transport category aircraft, normal category aircraft, and sport light category aircraft. Background Technology

[0002] To ensure aircraft safety, the aviation industry has established a rigorous and comprehensive safety assessment system, starting from the initial pre-design phase of an aircraft and continuing until its retirement. Safety requirements, design, and assessment are integrated throughout the entire aircraft lifecycle. Furthermore, safety assessments serve as guidelines for ensuring safe aircraft operation, are fundamental to continued airworthiness, and are a crucial method for improving aircraft system safety. Therefore, all civil aviation authorities include safety assessments as an essential component of their airworthiness standards, and completing safety assessments is the responsibility of aircraft manufacturers or type certificate holders.

[0003] To ensure the scientific conduct of aircraft safety assessments, global aviation industry experts have recommended normative guidelines. SAE ARP 4761A primarily outlines the guidelines and methods for safety assessments in civil aircraft certification, serving as a good example for transport and normal category aircraft. It also outlines the systemic methods for demonstrating compliance with FAR / CCAR 25.1309. Commonly used safety assessments by industry and airworthiness authorities include Functional Hazard Assessment (FHA), Preliminary Aircraft-Level Safety Assessment (PASA), Preliminary System-Level Safety Assessment (PSSA), Aircraft Safety Assessment (ASA), and System Safety Assessment (SSA). Functional Hazard Assessment, as the leading step in aircraft and system safety assessments, plays a crucial role; the rationality and comprehensiveness of its analysis significantly impact subsequent safety assessment stages.

[0004] Currently, in China, functional hazard assessments of aircraft and systems lack standardized methods for combined failure safety analysis due to the absence of a specified methodology in SAE ARP 4761A. This, coupled with the large number of aircraft and system failure states, leaves safety engineers without a clear, standardized approach. Domestic analysts primarily rely on engineering experience and manual enumeration for combined failure analysis, leading to an exponential increase in computational complexity when considering numerous failure state combinations. The lack of standardized methods results in frequent discrepancies and omissions when different safety engineers assess different aircraft models. The inability to unify analytical methods leads to a chaotic analytical process, reduces aircraft safety margins, increases operator maintenance costs, and impacts safety incidents, ultimately failing to meet the required safety and economic requirements. Summary of the Invention

[0005] The purpose of this invention is to provide a method for analyzing combined failure states of aircraft and their systems. This invention can reduce errors and omissions caused by manual enumeration and reduce the amount of data required for combined failure identification and analysis.

[0006] Technical Solution. A combined failure state analysis method for the safety of aircraft and its systems, which identifies individual failure states based on functional definitions; after verifying the integrity of individual failure states, assessing their impact level, verifying the integrity of the mission phase, simplifying and merging them, and identifying external events, combines them to form combined failure states; constructs a combined failure state matrix, and utilizes the matrix symmetry to calculate only the combined failure states in the lower triangular region, which are then simplified, merged, and added to the failure state list.

[0007] In the aforementioned combined failure state analysis method for aircraft and its system safety, the identification of a single failure state is as follows: Based on the failure state list in the FHA, a single failure state is identified and summarized according to the functional definition to form a failure state integrity checklist.

[0008] In the aforementioned combined failure state analysis method for aircraft and its system safety, the principle for confirming the integrity of a single failure state is as follows: a single failure state includes two categories: loss of function and functional error. Among them, loss of function is divided into: complete loss of function, partial loss of function, intermittent operation of function, and performance degradation; functional error refers to the unexpected state or action of the function.

[0009] In the aforementioned combined failure state analysis method for aircraft and its systems safety, the process for assessing the impact level of a single failure state is as follows: Based on the severity of system or function failure, the impact level of the aircraft, crew and passengers is assessed using a failure state classification judgment table. Finally, the most severe impact level among the three is selected as the corresponding functional failure state level and written into the failure state integrity check table.

[0010] In the aforementioned combined failure state analysis method for aircraft and its system safety, the mission phase integrity verification of a single failure state is as follows: based on the mission phase used by each function in the functional definition, the failure impact level of each single failure state in all mission phases is defined.

[0011] In the aforementioned combined failure state analysis method for aircraft and its system safety, the failure state integrity check table is defined and then added to the failure state integrity check table, which gives the level and the highest failure level for each mission stage.

[0012] In the aforementioned combined failure state analysis method for aircraft and its systems safety, the simplified merging process for individual failure states is as follows: Single failure states that fall under the following conditions in the Failure State Integrity Checklist will be merged: a) The same failure state has different effects at different task stages: 1) All task phases are considered as a single failure state, with the impact defined by the most severe task phase; 2) When there are two or fewer different effects, list them as different failure states with the same name; when there are more than two different effects, only list the task stages with the first two severe effects as different failure states. Method 1) is preferred; if the quantitative calculation results of method 1) cannot meet the probability requirements, method 2) is used. b) If the same failure state has the same impact in different task phases, they are merged and regarded as the same failure state.

[0013] In the aforementioned combined failure state analysis method for aircraft and its system safety, external events are determined based on the aircraft configuration.

[0014] In the aforementioned combined failure state analysis method for aircraft and its systems safety, the combination principle of combined failure states is as follows: a combination is executed if any one of these principles is met: a) Failure states that have already reached Category I in impact level will no longer be combined; b) Only combine functions that are used simultaneously in the same task phase, and do not combine functions that are not used simultaneously in the same task phase; c) The failure status of the main function should be combined with the failure of the corresponding alarm and indication functions to determine the failure status; d) Combined failures are considered for both flight-related and non-flight-related phases of the aircraft, resulting in two combined failure tables.

[0015] e) Functions operating under adverse conditions should be combined with external events, environmental events, and emergency configurations for failure, but events should not be combined with each other.

[0016] In the aforementioned combined failure state analysis method for aircraft and its systems safety, the calculation process of the combined failure state matrix is ​​as follows: A combined failure table is constructed based on the symmetry of the combined failure state matrix, and combined failures are identified based on this table. Combined failures are then addressed for each stage of flight. The horizontal and vertical headers list the single failure states and identified external events verified for mission phase integrity at each stage of flight. A diagonal lower triangular horizontal and vertical pairwise combination method is used for analysis. Combined failure states are categorized and their impact levels are assessed. Combined failure states with increased impact levels are simplified and merged as described above, and then added to the failure state list. When combining single failure states and external events, the failure state and event combination table is considered. The same method should be used to handle combination failures during non-flight phases. The combined failure table, failure state table, and event combination table are as follows: Combination Failure Table

[0017] Failure Status and Event Combination Table .

[0019] Advantages of this invention: This invention utilizes a combined failure state analysis method for aircraft and system safety, providing a comprehensive and standardized analysis of the aircraft and system safety analysis system. Through a standardized qualitative analysis process, it achieves efficient analysis and evaluation of combined safety failure states. In actual analysis, if a system-level failure state has approximately 20 items, using traditional methods such as manual enumeration would generate 400 combinations. However, using the combined failure state analysis method described in this invention, the lower triangular matrix contains 200 combined states, of which one is upgraded and generates a combined task item, accounting for 0.5% of the total combined failure state items. For aircraft-level failure states, there are 212 items, which, combined with external events, result in 30,500 combined failure states. Using the combined failure analysis method described in this invention, the lower triangular matrix contains 15,200 combined states, with 37 items ultimately upgraded and generating combined task items, accounting for 0.24% of the total combined failure state items. Therefore, the method described in this invention can not only comprehensively traverse all combined failure state items, avoiding the omission of items caused by the original method of using manual enumeration or engineering experience judgment, but also maintain a high and stable combined item identification rate when facing the exponentially increasing combined failure state item results as the number of failure states increases. Furthermore, the method of this invention can reduce the workload and steadily improve the efficiency of identifying combined tasks as the number of failure states increases.

[0020] In the aircraft development process, the lower triangular matrix-based combined failure state identification not only provides feedback and iteration for functional architecture and failure state impact levels, enabling safety engineers to fully consider the correlation between functions, but also helps system designers check the rationality of functional definitions. It not only standardizes the standard analysis methodology process and improves the efficiency of combined analysis, filling a gap in domestic analytical methods in this field, but also reduces discrepancies and omissions in results caused by the lack of standard analysis methods when safety engineers consider combined failure states. Furthermore, it increases the reliability of aircraft safety assessments, reduces potential safety incidents, and ensures that aircraft operators meet the economic and safety requirements of the main equipment manufacturer.

[0021] This invention can reduce errors and omissions caused by manual enumeration, reduce the amount of analysis required for identifying combined failures, standardize the safety assessment and analysis method, fill the gap in the standard analysis process for combined failures, meet the requirements of aircraft safety assessment and the management methods for safety assessment and analysis during aircraft airworthiness review, and output a standard safety analysis report that meets the requirements of the relevant airworthiness authorities. Attached Figure Description

[0022] Figure 1 This is a flowchart of the combined failure state analysis method for the safety of aircraft and their systems according to the present invention; Figure 2 This is a failure state integrity checklist for the combined failure state analysis method for the safety of aircraft and its systems according to the present invention. Detailed Implementation

[0023] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0024] Example 1. A combined failure state analysis method for aircraft and its systems safety, see [link to example]. Figures 1-2 This invention provides a comprehensive and standardized analysis of aircraft and system safety, employing a standardized qualitative analysis process to achieve efficient analysis and assessment of combined safety failure states. To achieve this, in a specific implementation plan, the invention utilizes a lower triangular matrix analysis method, combined with a failure state integrity checklist, to form a matrix of all combined failure states to be analyzed. During the combined failure analysis process, the failure impact level is determined, and the resulting combined failure states are simplified and merged, ultimately being incorporated into the failure state list as a supplement, forming a more complete safety assessment system.

[0025] To achieve the above objectives, the technical solution adopted is as follows: In a first aspect, the present invention provides an efficient analysis method for combined safety failure states of matrix-type aircraft, comprising the following steps: Step S1: Based on the failure status list in the Functional Hazard Assessment (FHA), identify and summarize individual failure statuses according to the functional definition. The purpose is to analyze the various situations of each function failure in the functional definition, mainly considering the impact of mission phase, environmental events, emergency configurations and external related aircraft functions, and form a preliminary failure status integrity checklist. Step S2: Confirm the integrity of a single failure state. Verify the integrity of the single failure states identified in step S1.

[0026] Failure states mainly fall into two categories: loss of function and functional error; The use of functions without notification should be determined on a case-by-case basis. Not all function "losses" need to be considered in terms of "notification" and "no notification". Therefore, the present invention does not treat function loss without notification as a separate category. If analysis is required, the failure status of the main function and the failure status of the alarm function will be considered in combination through the combined failure identification analysis method in step S8. Here, it is only a method for checking the integrity of a single failure status.

[0027] When there are no cases of partial loss of function, intermittent operation, or performance degradation, only the case of complete loss of function is considered.

[0028] Step S3: To maintain good traceability, failure states should be numbered. The failure state number should be combined with the function number, using the format "Considered Function Number + Failure Type + Serial Number". A represents a failure type of functional loss; B represents a failure type of functional error. For example, in "FC1.1.1-A1", "FC1.1.1" represents the first level 3 function of the first level 2 function within the first level 1 function of the aircraft-level system, "A" represents the failure type of functional loss, and the last "1" is a serial number.

[0029] Step S4: Determine the impact classification level of the failure state. The impact of the failure state is closely related to the mission phase. The same failure state may have different impacts in different flight phases. The impact of each failure state should be analyzed separately in different flight phases.

[0030] Determine the impact classification level of the failure state, which refers to the impact level of the aircraft, crew and passengers in a certain failure state. Finally, the failure state level with the most severe impact on the aircraft, crew and passengers is selected as the failure state level and written into the failure state integrity check table in step S1.

[0031] When examining and classifying the impact of failure states, one can analyze accident / incident data, consult guiding regulations, refer to past design experience, or consult the crew.

[0032] The classification of failure states does not depend on whether a system or function is required to be installed under the relevant regulations (e.g., Part 25 for transport category aircraft), but only on the severity of the failure. For example, position lights and broadcast systems are systems that are required to be installed under Part 25, but the severity of their failure states is generally minor; while for some systems that are not required to be installed under Part 25, the severity of their failure states may be greater or more serious.

[0033] As shown in Table 1, in a certain failure state, the impact on the second row of aircraft, the third row of crew, and the fourth row of passengers is assessed by the impact levels of the first and fifth rows, respectively. Finally, the failure state level is selected based on the most severe impact level on the aircraft, crew, and passengers, and is written into the failure state integrity check table in step S1.

[0034] Table 1 Failure Status Classification and Judgment Table

[0035] Step S5: Confirm the completeness of the task phases for the failure status. Based on the task phases used by each function in the function definition, define the failure impact level of each failure status in all task phases. Step S6: Simplify and merge failed states to improve work efficiency and reduce repetitive work.

[0036] There are two scenarios for merging failure states: first, the same single failure state has different impacts at different task stages; second, the same single failure state has the same impact at different task stages.

[0037] For the same failure state with different impacts at different task stages, there are two merging methods: First, all task stages are merged into the same failure state, and the impact is defined by the task stage with the most severe impact; Second, when there are two or fewer different impacts, they are listed as different failure states with the same name; when there are more than two different impacts, only the task stages with the two most severe impacts are listed as different failure states.

[0038] The first merging method is preferred. This method extends the risk time, which reduces the probability requirement value, strictly improves the safety requirements, and reduces the number of failure states, thus reducing the amount of work required later.

[0039] If the same failure state has the same impact in different task stages, and there is only one merging method, then merging will be regarded as the same failure state.

[0040] Step S7: Based on the determined aircraft configuration, identify external events and obtain a list of external events. The use and failure of certain functions are closely related to events and aircraft configuration. Considering environmental conditions will aggravate the impact of failure states. Ignoring environmental conditions will mitigate the impact of failure states, thereby reducing safety objectives.

[0041] Step S8: Combine according to the principle, supplement the combined failure states, screen the combined failure states that affect the improvement of the level, remove irrelevant combined failure states that have not been improved in level, and use the lower triangular matrix to identify the combined failure table, see Table 2.

[0042] The principles for combined failure states are as follows: execution can be performed if any one of them is met.

[0043] a) Failure states that have already reached Category I in impact level will no longer be combined; b) Only combine functions that are used simultaneously in the same task phase, and do not combine functions that are not used simultaneously in the same task phase; c) The failure status of the main function should be combined with the failure of the corresponding alarm and indication functions to determine the failure status; d) Combined failures are considered for both flight-related and non-flight-related phases of the aircraft, resulting in two combined failure tables.

[0044] e) Functions operating under adverse conditions should be combined with external events, environmental events, and emergency configurations for failure, but events should not be combined with each other.

[0045] Table 2 Combination Failure Table

[0046] Step S9: When determining the combination of failure states and specific events, the correlation between the two must be considered. Not all aircraft functions are related to specific events. Table 3 provides a recommended combination consideration method for failure states and event combinations.

[0047] Table 3 Failure State and Event Combination Table

[0048] Step S10: Check the rationality of the combined failure state. If the product of the probability requirements of the two individual failure states is greater than the probability requirement of the combined failure state, it is likely that these two functions have an impact on the safety margin of the aircraft that exceeds expectations. In this case, it is necessary to consider raising the level of the two individual failure states so that their safety requirements match their actual severity.

[0049] The lower triangular matrix-based combined failure state identification process helps system designers check the rationality of function definitions, such as whether functions are too detailed or overlapping. After combined failure checks, it can be shown that any pairwise combination of failure states provides a sufficient level of safety (otherwise, the two individual failure states should be upgraded), and it is not necessary to conduct "three-three" or more failure state combination analysis in FHA.

[0050] Step S11, corresponding to the combined failure states affecting the upgrade level in Table 2, should be simplified and merged using step S6. The simplified and merged combined failure states should be included in the functional hazard analysis list as a supplement. Based on step S3, the combined failure states are numbered with ZH, for example, "considered function number + ZH + failure type + serial number".

[0051] Secondly, this invention provides an efficient method for analyzing the combined safety failure states of a matrix-type aircraft system.

[0052] The analysis method is the same as the efficient analysis method for combined failure states of aircraft safety, except that in step S1, it takes into account the functional failure states assigned to the aircraft level within the system, and in steps 7 and S10, it only considers the events involved in the system.

[0053] Example 2. (As shown) Figure 1 As shown, this invention provides an efficient method for analyzing the combined safety failure states of matrix-type aircraft and systems, comprising the following steps: Step S1: Identify single failure states based on functional definitions. First, a single-function failure analysis and summary is performed based on the functional definitions. The purpose is to analyze various failure scenarios for each function in the functional definitions, mainly considering the impact of mission phases, environmental events, emergency configurations, and external related aircraft functions, in order to determine all failure states and form a complete set of failure states. Figure 2 Failure Status Integrity Checklist.

[0054] Step S2: Confirm the integrity of a single failure state. Verify the integrity of the single functional failure states identified in step S1. Failure states should include two main types: loss of function and functional error.

[0055] Functional loss can be categorized as follows: a) Complete loss of function, meaning that a certain function is completely unable to work; b) Partial loss of function, meaning that part of a function cannot work, while the rest works normally; c) Intermittent operation of a function refers to the alternating states of a function being in operation and not in operation. d) Performance degradation refers to a situation where the performance of a certain function fails to meet the expected requirements, but it can still work.

[0056] A functional error refers to a function exhibiting an unexpected state or action. Typical failure states include the following types: a) Functions without instructions or not in accordance with instructions refer to functions that work autonomously without receiving control instructions, or functions whose working state is inconsistent with the instructions. b) Out of control / over the limit (all or part) refers to a function operating beyond its usage limits; c) Jamming / blocking refers to a component that performs a certain function being subjected to resistance exceeding the driving force, causing its movement to be unsmooth or stuck in a non-neutral position; d) Free / floating, refers to the uncontrolled movement of a component that performs a certain function under the action of external forces; e) A faulty function refers to a function that sends incorrect instructions or signals to other functions; f) Misleading alarms / displays / information, referring to an instruction or alarm that indicates a discrepancy between the unit's actual operating status and its actual condition.

[0057] For unannounced function loss, the application should be determined on a case-by-case basis. Not all function loss needs to be considered in terms of "announced" and "unannounced" cases. Therefore, this method does not treat unannounced function loss as a separate category. If analysis is required, the failure status of the main function and the failure status of the alarm function will be considered in combination through the combined failure analysis method in step S8. This is only a method for checking the integrity of a single failure.

[0058] If there are situations where functionality may be partially lost, work intermittently, or performance may degrade, only the scenario of complete functional loss should be considered.

[0059] Not all functions will exhibit the various types of functional errors. Generally, "out of control / over-limit" applies to mechanical and electrical functions, "operating without command or not operating according to command," "stuck / blocked," and "detached / loose" apply to mechanical functions, while "misleading alarms / displays / information" applies to avionics functions.

[0060] Step S3: To maintain good traceability, failure states should be numbered. The failure state number should be combined with the function number, and it is recommended to use the format "Considered Function Number + Failure Type + Serial Number". A represents a failure type of functional loss; B represents a failure type of functional error. For example, in "FC1.1.1-A1", "FC1.1.1" represents the first level 3 function of the first level 2 function within the first level 1 function of the aircraft-level system, "A" represents the failure type of functional loss, and the last "1" is a serial number.

[0061] Step S4: Determine the impact classification level of the failure state. The impact of the failure state is closely related to the mission phase. The same failure state may have different impacts in different flight phases. The impact of each failure state should be analyzed separately in different flight phases.

[0062] Step S4.1, as shown in Table 1, in a certain failure state, the impact on the second column of aircraft, the third column of crew and the fourth column of passengers is assessed by the impact levels of the first and fifth columns respectively. Finally, the failure state level is selected as the failure state level with the most severe impact on the aircraft, crew and passengers, and is written into the failure state integrity check table in step S1.

[0063] Step S4.2, when checking and judging the impact classification of the failure status, you can analyze the accident / event data, consult the guiding regulations, refer to the previous design experience, or consult the crew members.

[0064] Step S4.3: Furthermore, the classification of failure states does not depend on whether the system or function is required to be installed under the relevant regulations (e.g., Part 25 for transport category aircraft), but only on the severity of the system or function failure. For example, position lights and broadcast systems are systems that are required to be installed under Part 25, but the severity of their failure states is generally minor; while for some systems that are not required to be installed under Part 25, the severity of their failure states may be greater or more serious.

[0065] Step S5: Confirm the completeness of the failure status task phases. Based on the task phases used by each function in the function definition, define the failure impact level of each failure status across all task phases, and supplement accordingly. Figure 2 The Failure Status Integrity Checklist provides the level and highest level for each stage.

[0066] Step S6: Simplify and merge failure states to improve work efficiency and reduce repetitive work. Figure 2 The following failure states in the Failure State Integrity Checklist will be merged: a) The same failure state has different effects at different task stages: 1) All task phases are considered as a single failure state, with the impact defined by the most severe task phase.

[0067] 2) When there are two or fewer different impacts, list them as different failure states with the same name; when there are more than two different impacts, only list the task stages with the most severe impacts as different failure states. Option 1 is preferred. This approach extends the risk time, thus reducing the probability requirement and strictly increasing safety standards. It also reduces the number of failure states and minimizes subsequent work.

[0068] If the quantitative calculation results cannot meet the probability requirements when using the first method, then the second method should be used for calculation.

[0069] b) If the same failure state has the same impact in different task phases, they will be merged and regarded as the same failure state.

[0070] Step S7: Determine external events based on the defined aircraft configuration. The use and failure of certain functions are closely related to events and aircraft configuration. Considering environmental conditions will exacerbate the impact of the failure state. Ignoring environmental conditions will mitigate the impact of the failure state, thereby reducing safety objectives.

[0071] Based on the combined failure analysis of aircraft safety, the following external events can be assumed: a) Strong crosswinds (>25kt) during takeoff and landing; b) Freezing conditions c) High-speed aborted takeoff d) Low oil content e) Emergency oil release f) Fire in APU / engine / cockpit, etc. Step S8: Based on the principles, combine and supplement the combined failure states. In order to screen the combined failure states that affect the improvement of the level, remove irrelevant combined failure states and those whose level has not been improved. The combination principles are as follows: a) Failure states that have already reached Category I in impact level will no longer be combined; b) Only combine functions that are used simultaneously in the same task phase, and do not combine functions that are not used simultaneously in the same task phase; c) The failure status of the main function should be combined with the failure of the corresponding alarm and indication functions to determine the failure status; d) Combined failures are considered for both flight-related and non-flight-related phases of the aircraft, resulting in two combined failure tables.

[0072] e) Functions operating under adverse conditions should be combined with external events, environmental events, and emergency configurations to prevent failure, but events should not be combined with each other.

[0073] The lower triangular matrix in Table 2 is used for combined failure identification. The horizontal and vertical headers list the single failure states (and their levels) selected in step S5 and the potentially related external events (external, environmental, scenario, etc.) selected in step S7 for each flight stage. The lower triangular matrix on the diagonal is used for pairwise combination analysis in both the horizontal and vertical directions. Failure states that have not been combined are marked with "-". Combined failure states are classified and their failure levels are determined according to step S4. Those whose levels have not been upgraded are kept in white by default, and those whose levels have been upgraded after combination are marked in red. The same applies to combined failures in non-flight stages.

[0074] Step S9: When determining the combination of failure states and specific events, the correlation between the two must be considered. Not all aircraft functions are related to specific events. Table 3 provides recommended combination considerations for failure states and events. The functions in the second column refer to higher-level aircraft functions; not all lower-level aircraft functions and system-level functions decomposed from these functions need to be combined with the events in the third column. In practice, the description and implementation path of the function should be specifically considered.

[0075] Step S10: Check the rationality of the combined failure state. If the product of the probability requirements of the two individual failure states is greater than the probability requirement of the combined failure state, it is likely that these two functions have an impact on the safety margin of the aircraft that exceeds expectations. In this case, it is necessary to consider raising the level of the two individual failure states so that their safety requirements match their actual severity.

[0076] Step S11, corresponding to the combined failure states affecting the upgrade level in Table 2, should be simplified and merged using step S6. The simplified and merged combined failure states should be included in the combined failure state list as a supplement. Based on step S3, the combined failure states are numbered with ZH, for example, "considered function number + ZH + failure type + serial number".

[0077] The efficient analysis method for combined safety failure states at the aircraft system level is the same as the steps described above, except that in step S1, it takes over the functional failure states assigned to the aircraft level within the system, and in steps 7 and S10, it only considers events related to the system.

[0078] In this embodiment, by analyzing the impact of different stages of aircraft and system failure states, and combining the events involved in the lower triangular matrix combined failure state analysis, the impact level of each combined failure is assessed. This further supplements the failure states of the aircraft's functions throughout the entire operational phase, improves the aircraft safety assessment process, and fills the gap in the standard analysis process for combined failures. This method solves the problems of low efficiency in traversing combined failures and easy omission of high-risk states in manual enumeration in traditional analysis. It meets the requirements of aircraft safety assessment and the management methods for inspection safety assessment analysis in aircraft airworthiness review, and can output a standard safety analysis report that meets the requirements of the corresponding airworthiness authorities.

[0079] While the embodiments disclosed in this invention are as described above, the content is merely for the purpose of facilitating understanding of the invention and is not intended to limit the invention. Any person skilled in the art to which this invention pertains may make any modifications and changes to the form and details of the implementation without departing from the spirit and scope disclosed herein; however, the scope of patent protection of this invention shall still be determined by the scope defined in the appended claims.

Claims

1. A method for analyzing combined failure states of aircraft and their systems, characterized in that, Identify single failure states based on functional definitions; After confirming the integrity of a single failure state, assessing its impact level, verifying the integrity of the task phase, simplifying and merging, and identifying external events, a combined failure state is formed. A combined failure state matrix is ​​constructed, and the combined failure states in the lower triangular region are calculated using the matrix symmetry. After simplification and merging, the combined failure states are added to the failure state list.

2. The combined failure state analysis method for aircraft and its systems safety according to claim 1, characterized in that, The identification of a single failure state is as follows: Based on the failure state list in the FHA, a single failure state is identified and summarized according to the functional definition to form a failure state integrity checklist.

3. The combined failure state analysis method for aircraft and its systems safety according to claim 2, characterized in that, The principles for confirming the integrity of a single failure state are as follows: Single failure states include two categories: loss of function and functional error. Among them, loss of function is divided into: complete loss of function, partial loss of function, intermittent operation of function, and performance degradation; functional error refers to the unexpected state or action of the function.

4. The combined failure state analysis method for aircraft and its systems safety according to claim 2, characterized in that, The process for assessing the impact level of a single failure condition is as follows: Based on the severity of system or function failure, the impact level of the aircraft, crew and passengers is assessed using a failure state classification judgment table. Finally, the most severe impact level among the three is selected as the corresponding functional failure state level and written into the failure state integrity check table.

5. The combined failure state analysis method for aircraft and its systems safety according to claim 2, characterized in that, The task phase integrity verification for a single failure state is as follows: Based on the task phase used by each function in the function definition, the failure impact level of each single failure state in all task phases is defined.

6. The combined failure state analysis method for aircraft and its systems safety according to claim 5, characterized in that, After definition, add it to the Failure State Integrity Check Table, which gives the level of each task stage and the highest failure level.

7. The combined failure state analysis method for aircraft and its systems safety according to claim 2, characterized in that, The simplified merging process for a single failure state is as follows: Single failure states that fall under the following conditions in the Failure State Integrity Checklist will be merged: a) The same failure state has different effects at different task stages: 1) All task phases are considered as a single failure state, with the impact defined by the most severe task phase; 2) When there are two or fewer different effects, list them as different failure states with the same name; when there are more than two different effects, only list the task stages with the first two severe effects as different failure states. Method 1) is preferred; if the quantitative calculation results of method 1) cannot meet the probability requirements, method 2) is used. b) If the same failure state has the same impact in different task phases, they are merged and regarded as the same failure state.

8. The combined failure state analysis method for aircraft and its systems safety according to claim 2, characterized in that, External events are determined based on aircraft configuration.

9. The method for analyzing combined failure states of aircraft and their systems according to claim 2, characterized in that, The combination principle for combined failure states is as follows: combination is executed if any one of the following conditions is met: a) Failure states that have already reached Category I in impact level will no longer be combined; b) Only combine functions that are used simultaneously in the same task phase, and do not combine functions that are not used simultaneously in the same task phase; c) The failure status of the main function should be combined with the failure of the corresponding alarm and indication functions to determine the failure status; d) Combined failures are considered for both flight-related and non-flight-related phases of the aircraft, resulting in two combined failure tables. e) Functions operating under adverse conditions should be combined with external events, environmental events, and emergency configurations for failure, but events should not be combined with each other.

10. The combined failure state analysis method for aircraft and its systems safety according to claim 2, characterized in that, The calculation process for the combined failure state matrix is ​​as follows: A combined failure table is constructed based on the symmetry of the combined failure state matrix, and combined failures are identified based on this table. Combined failures are then addressed for each stage of flight. The horizontal and vertical headers list the single failure states and identified external events verified for mission phase integrity at each stage of flight. A diagonal lower triangular horizontal and vertical pairwise combination method is used for analysis. Combined failure states are categorized and their impact levels are assessed. Combined failure states with increased impact levels are simplified and merged as described above, and then added to the failure state list. When combining single failure states and external events, the failure state and event combination table is considered. For combination failures during non-flight phases, the same method should be used; The combined failure table, failure state, and event combination table are as follows: Combination Failure Table Failure Status and Event Combination Table 。