FTA and FMEA fused double-track parallel tracing association analysis method
By combining the parallel approach of FMEA and FTA with a retrospective correlation analysis method, risk items of civil aviation equipment are identified, overcoming the limitations of FMEA and FTA in safety assessment and realizing comprehensive risk identification and improvement measures.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-09-19
- Publication Date
- 2026-04-14
AI Technical Summary
In existing technologies, the FMEA method focuses on the longitudinal analysis of a single failure mode and lacks the analysis of the combined effects of cross-sectional failure modes, while the FTA method may miss a single failure mode, resulting in an incomplete safety assessment of civil aviation equipment.
We employ a dual-track parallel analysis method that integrates FTA and FMEA, and traces back to the relevant aspects. FMEA identifies failure modes at each level from the bottom up, while FTA constructs a fault tree model from the top down. We also trace back the bottom and top events to achieve qualitative and quantitative comparisons, thereby identifying risk items and obtaining the minimum cut set.
It enables comprehensive risk identification for civil aviation equipment, fills the gap in FMEA in combined effects analysis, makes up for the shortcomings of FTA in single failure mode detection, and provides accurate analysis and improvement measures.
Smart Images

Figure CN121859429A_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the field of civil aircraft safety assessment, specifically involving a dual-track parallel and traceable analysis method that integrates FTA and FMEA. Background Technology
[0002] In the civil aviation sector, safety assessment and risk identification are crucial. Currently, Failure Mode and Effects Analysis (FMEA) and Fault Tree Analysis (FTA) are widely used in the civil aviation field as common safety and reliability analysis methods. However, each risk identification method has its limitations.
[0003] FMEA, as a bottom-up analysis method, is an inductive approach that traces failures from their causes to their consequences, belonging to the category of "prevention." FMEA defines failure modes and effects at different levels in sequence: component level, functional circuit level, board level, and equipment level. This can comprehensively cover equipment risk identification. However, FMEA focuses more on the vertical analysis of single failure modes and lacks the analysis of the combined effects of horizontal failure modes.
[0004] FTA's analysis logic starts from the "fault tree top event," which is an analysis method that goes from the consequences of a failure to the causes of the failure. By selecting logic gates, it can analyze the combined effects of different failure modes. It focuses on studying the combined effects of different failure modes at the same level from top to bottom, which can make up for the gap in FMEA's analysis of combined effects. However, there is a possibility that it may miss individual failure modes. Summary of the Invention
[0005] Purpose of the invention: To provide a dual-track parallel analysis method that integrates FTA and FMEA, and traces and correlates them, so as to accurately, in detail and comprehensively identify risk items and improve equipment safety and reliability.
[0006] Technical solution:
[0007] A dual-track, parallel, and correlation-based analytical method integrating FTA and FMEA includes:
[0008] Step S1: Using product architecture, circuit principles, and industry standards as input, perform FMEA analysis and output the analysis results at each level;
[0009] Step S2: Using the product feature list, design architecture, and security requirements as inputs, and SAE APR4761 as the analysis standard, perform FTA analysis from top to bottom to determine the quantitative security indicators of the bottom events and the minimum cut set of the top events.
[0010] Step S3: Based on the analysis results of FMEA and FTA, perform mutual tracing of failure modes and safety requirements between FMEA and FTA, including bottom event tracing and top event requirement tracing.
[0011] Further, step S1 specifically includes:
[0012] Based on the product's physical architecture, the hierarchical structure of FMEA analysis is determined as follows: product level, board level, functional circuit level, and component level. The failure modes and failure rates of each level are determined according to the hierarchical structure to obtain the FMEA summary table.
[0013] Based on the hierarchical structure, the FMEA master table is defined as the first table, the second table, the third table, and the FMES table.
[0014] Furthermore, in step S1, the FMEA master table includes: a first table {1-component level, 2-functional circuit level, 4-product level}, a second table {2-functional circuit level, 3-board level, 4-product level}, a third table {3-board level, 4-product level}, and an FMES table {4-product level}.
[0015] Further, step S2 specifically includes:
[0016] A fault tree model is constructed with safety requirements as the top event, first-level functions and second-level functions as intermediate events, and functional circuit levels as bottom events.
[0017] By down-distributing the failure rate of the top event, a quantitative indicator of the safety of the bottom event is obtained; and based on FTA analysis, the minimum cut set of the top event is calculated.
[0018] Furthermore, in step S2, the top event is "the failure rate of a remote power distribution device is less than 1E-7", the first-level function is "communication function", and the second-level function is "loss of internal communication function".
[0019] Further, step S3 specifically includes:
[0020] Step S31: In the tracing of the bottom event, the quantitative safety indicators of the FTA bottom event are traced back to each other with the functional circuit level of FMEA. The fault tree structure or the failure mode of FMEA are improved, supplemented or corrected through qualitative comparison. The circuit is judged to meet the safety requirements or whether there are potential risks through quantitative comparison.
[0021] Step S32: Based on the tracing results of the bottom event, trace the top event requirements.
[0022] Furthermore, the quantitative indicator of FTA bottom-event security is the FTA functional circuit-level security requirement.
[0023] Furthermore, in step S31:
[0024] Qualitative comparison involves tracing the failure modes at the bottom of the FTA and the functional circuit level of the FMEA to identify duplicates or missing items. Duplicates are removed and missing items are added to improve or correct the fault tree structure or the failure modes of the FMEA.
[0025] The quantitative comparison involves comparing the failure rate of traceable events at the FMEA functional circuit level with the quantitative security indicators at the FTA functional circuit level to determine whether the circuit meets security requirements or whether there are potential risks.
[0026] Further, step S32 specifically includes:
[0027] B1: Create a copy of the fault tree structure after supplementation or correction;
[0028] B2: Assuming the FMEA failure rate is the true value, perform bottom-up calculations on the fault tree replica to calculate the failure rate of the top event of the fault tree under the current hardware capabilities, and define the failure rate of the top event as a preset value.
[0029] B3: Compare preset values with security requirements to identify high-risk items that do not meet security requirements;
[0030] B4: Analyze high-risk items, obtain the minimum cut set of the current top event, and provide improvement measures for bottom events by improving hardware capabilities, increasing design redundancy, or adding detection methods.
[0031] Beneficial effects:
[0032] This invention combines FMEA and FTA analysis methods through a dual-track, parallel, and retrospective approach. This fills the gap in FMEA analysis for identifying combined failure modes and compensates for potential omissions in FTA analysis. By combining FTA and FMEA from the perspectives of functional classification and physical architecture, this invention provides a more comprehensive and complete analysis of failure modes at different levels, verifying whether they meet safety requirements. This identifies risk items, obtains their minimum cut sets, and pinpoints problems, enabling precise analysis and improvement measures. Attached Figure Description
[0033] Figure 1 This is a flowchart of the FMEA analysis procedure;
[0034] Figure 2 This is a flowchart of the FTA analysis procedure;
[0035] Figure 3This is a tracing diagram of FMEA and FTA. Detailed Implementation
[0036] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0037] The features and illustrative embodiments of various aspects of the present invention will now be described in detail. Numerous specific details are set forth in the following detailed description to provide a thorough understanding of the invention. However, it will be apparent to those skilled in the art that the invention may be practiced without requiring some of these specific details. The following description of embodiments is merely intended to provide a better understanding of the invention by illustrating examples of the invention. The invention is by no means limited to any specific setups and methods set forth below, but covers any improvements, substitutions, and modifications to structures, methods, and devices without departing from the spirit of the invention. Well-known structures and techniques are not shown in the drawings and the following description to avoid unnecessarily obscuring the invention.
[0038] In the description of this invention, it should be noted that the directions or positional relationships indicated by terms such as "center," "upper," "lower," "left," "right," "vertical," "horizontal," "inner," and "outer" are based on the directions or positional relationships shown in the accompanying drawings and are only for the convenience of describing and simplifying the invention, and should not be construed as limiting the invention. Furthermore, the use of ordinal numbers (e.g., "first and second," etc.) is for distinguishing objects and is not limited to this order, and should not be construed as indicating or implying relative importance.
[0039] In the description of this invention, it should be noted that, unless otherwise explicitly specified and limited, the terms "installation," "connection," and "linking" should be interpreted broadly, encompassing both direct connection and indirect connection via an intermediate medium. Those skilled in the art can understand the specific meaning of these terms in this invention based on the specific circumstances.
[0040] It should be noted that, unless otherwise specified, the embodiments of the present invention and the features thereof can be combined with each other, and the various embodiments can be referenced and cited in each other. The present invention will now be described in detail with reference to the accompanying drawings and embodiments.
[0041] The present invention will be further described in detail below with reference to the embodiments and accompanying drawings, but the embodiments of the present invention are not limited thereto.
[0042] To address the gaps in FMEA's analysis of combined effects and the shortcomings of FTA in identifying single failure modes, a dual-track, parallel, and traceable analysis method integrating FTA and FMEA is proposed. This method is used to identify high-risk items in remote power distribution equipment, enabling the provision of rational suggestions and improvement measures.
[0043] To achieve the purpose of this invention, this invention proposes a dual-track parallel analysis method that integrates FTA and FMEA, and traces and correlates data. The method specifically includes the following steps:
[0044] S1: First, use FMEA analysis to identify all potential failure modes and risks. Using the equipment's architecture design, product circuit principles, and GJB / Z 299D-2024 "Reliability Prediction Manual for Electronic Equipment" as input, determine the failure modes at the component level, functional circuit level, board level, and product level from the bottom up. Use spreadsheets to calculate the failure modes and failure rates at different levels to obtain a complete FMEA summary table.
[0045] Then, following the hierarchical structure of component level, functional circuit level, board level, and product level, the FMEA (Failure Mode and Effects Analysis) master table is defined as the first table, the second table, the third table, and the FMES table, and presented in the form of a spreadsheet.
[0046] S2: Based on the product-level safety requirements HLR={H1,H2,H3,......Hn}, with Hi as the top event of the fault tree; and using the product function list and design architecture as input, and SAE APR4761 as the analysis standard, fault tree analysis is performed. Specifically, it involves: top event, first-level function (intermediate event), second-level function (intermediate event), and functional circuit level (bottom event), thus constructing a fault tree model from top to bottom.
[0047] By down-allocating the failure rate of the top event, a quantitative indicator of the safety of the bottom event is obtained; and based on FTA analysis, the minimum cut set for the occurrence of the top event is calculated.
[0048] S3: Combine the FTA analysis results with the FMEA analysis results to corroborate and supplement each other. Tracing includes bottom-event tracing and top-event tracing.
[0049] Firstly, in the tracing of bottom-level events, the quantitative safety indicators of FTA bottom-level events, namely the FTA functional circuit-level safety requirements, are cross-traced with the second table of FMEA, namely the FMEA at the functional circuit level. This specifically includes the following qualitative and quantitative analyses: A1 Qualitative comparison and gap filling: By cross-tracing the failure modes of the FTA bottom-level events with those in the second table of FMEA, duplicates or missing items can be identified. Based on this (deleting duplicates and supplementing missing items), the failure mode of the fault tree structure or FMEA can be improved, supplemented, or corrected.
[0050] A2 Quantitative Comparison and Risk Identification: After qualitative analysis, the failure rate of traceable events in the second table of FMEA is compared with the quantitative indicators of FTA functional circuit-level safety to determine whether the circuit meets safety requirements or whether there are potential risks.
[0051] Following the completion of the tracing of the bottom event, the tracing of the top event requirements is then performed, such as... Figure 3 Specifically, it includes the following steps:
[0052] B1: Create a copy of the fault tree structure after supplementation or correction;
[0053] B2: Assuming the failure rate of FMEA is the true value, perform bottom-up calculations on the fault tree replica to calculate the failure rate of the top event of the fault tree under the current hardware capabilities, and define the failure rate of the top event as a preset value.
[0054] B3: Compare preset values with security requirements to identify high-risk items that do not meet the requirements.
[0055] B4: Analyze high-risk items, obtain the minimum cut set of the current top event, focus on the bottom events within it, and provide corresponding improvement measures for risk items by improving hardware capabilities, increasing design redundancy, or adding detection methods.
[0056] This application traces the top event of the fault tree back to the FMES, using this as the basis for defining the failure mode in the FMES. Furthermore, it can provide a reference for defining the severity of the failure mode based on the safety requirements of the traced top event.
[0057] Example:
[0058] The principles of this invention will be specifically explained below with reference to the accompanying drawings and examples. The analysis will now be carried out using the safety analysis of a remote power distribution device as an example.
[0059] The first step is to complete the FMEA analysis based on the physical architecture, circuit principles, and industry standards. The FMEA process is as follows: Figure 1 .
[0060] First, based on the physical architecture of the remote power distribution device (product), determine the hierarchical structure of the FMEA analysis: product level, board level, functional circuit level, and component level, as shown in Table 1. Analyze the failure modes and failure rates in sequence according to the following structure, and determine the failure modes and failure rates of each level from bottom to top (component level, functional circuit level, board level, product level).
[0061] Table 1 Hierarchical Structure of FMEA Analysis
[0062]
[0063] Then, following the hierarchical structure of component level, functional circuit level, board level, and product level, the FMEA master table is defined as follows: Table 1 {1-Component Level, 2-Functional Circuit Level, 4-Product Level}, Table 2 {2-Functional Circuit Level, 3-Board Level, 4-Product Level}, Table 3 {3-Board Level, 4-Product Level}, and FMES {4-Product Level}, presented in spreadsheet format. This approach facilitates a more intuitive and clear understanding of the failure modes and failure rates at each level.
[0064] The second step involves identifying product-level security requirements, using these as the top event in the fault tree. Based on the product's feature list, architecture design, and SAE APR4761, a fault tree structure is built according to functional divisions. The process is as follows: Figure 2 .
[0065] The hierarchical structure is defined as: top event, first-level function (intermediate event), second-level function (intermediate event), and functional circuit level (bottom event), thus constructing a fault tree model from top to bottom. Taking the top event—"loss rate of a remote power distribution device less than 1E-7", the first-level function—"communication function", and the second-level function—"loss of internal communication function"—as an example, a fault tree is constructed. By allocating the failure rate of the top event downwards, the quantitative safety index of the bottom event is obtained; and based on FTA analysis, the minimum cut set for the occurrence of the top event is calculated.
[0066] Step 3: Implement traceability, see step 4 for the procedure.
[0067] First, in the tracing of bottom-event events, the quantitative indicators of FTA bottom-event security, namely the FTA functional circuit-level security requirements, are cross-traced with the second table of FMEA, namely the FMEA at the functional circuit level. The tracing results are expressed in Table 2.
[0068] Table 2. Event Tracing Table
[0069]
[0070] Specifically, it includes the following qualitative and quantitative analyses:
[0071] A1 Qualitative comparison and gap filling: By tracing back the events at the bottom of the FTA with the failure modes in the second table of the FMEA, duplicate or missing items can be identified. Based on this, the fault tree structure or the failure modes of the FMEA can be improved, supplemented or corrected (by deleting duplicates and supplementing missing items).
[0072] A2 Quantitative Comparison and Risk Identification: After qualitative analysis, the failure rate of traceable events in the second table of FMEA is compared with the quantitative indicators of FTA functional circuit-level safety to determine whether the circuit meets safety requirements or whether there are potential risks.
[0073] Following the completion of tracing the bottom event, the tracing of the top event requirement is then carried out, specifically including the following steps:
[0074] B1: Create a copy of the fault tree after correction;
[0075] B2: Based on the traceability results in Table 2, the failure rate of the bottom event in FMEA is assumed to be the true value. The failure rate of the top event in the fault tree is calculated from bottom to top on the fault tree copy, and the failure rate of the top event is defined as the preset value.
[0076] B3: Compare preset values with security requirements to identify high-risk items that do not meet the requirements.
[0077] B4: Analyze high-risk items, obtain the minimum cut set of the current top event, focus on the bottom events within it, and provide corresponding improvement measures for risk items by improving hardware capabilities, increasing design redundancy, or adding detection methods.
[0078] This application traces the top event of the fault tree back to the FMES, using this as the basis for defining the failure mode in the FMES. Furthermore, it can provide a reference for defining the severity of the failure mode based on the safety requirements of the traced top event.
[0079] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the technical scope disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.
Claims
1. A dual-track parallel analysis method integrating FTA and FMEA, characterized by: include: Step S1: Using product architecture, circuit principles, and industry standards as input, perform FMEA analysis and output the analysis results at each level; Step S2: Using the product feature list, design architecture, and security requirements as inputs, and SAE APR4761 as the analysis standard, perform FTA analysis from top to bottom to determine the quantitative security indicators of the bottom events and the minimum cut set of the top events. Step S3: Based on the analysis results of FMEA and FTA, perform mutual tracing of failure modes and safety requirements between FMEA and FTA, including bottom event tracing and top event requirement tracing.
2. The method according to claim 1, characterized in that, Step S1 is as follows: Based on the product's physical architecture, the hierarchical structure of FMEA analysis is determined as follows: product level, board level, functional circuit level, and component level. The failure modes and failure rates of each level are determined according to the hierarchical structure to obtain the FMEA summary table. Based on the hierarchical structure, the FMEA master table is defined as the first table, the second table, the third table, and the FMES table.
3. The method according to claim 2, characterized in that, In step S1, the FMEA master table includes: the first table {1-component level, 2-functional circuit level, 4-product level}, the second table {2-functional circuit level, 3-board level, 4-product level}, the third table {3-board level, 4-product level}, and the FMES table {4-product level}.
4. The method according to claim 3, characterized in that, Step S2, specifically: A fault tree model is constructed with safety requirements as the top event, first-level functions and second-level functions as intermediate events, and functional circuit levels as bottom events. By down-distributing the failure rate of the top event, a quantitative indicator of the safety of the bottom event is obtained; and based on FTA analysis, the minimum cut set of the top event is calculated.
5. The method according to claim 4, characterized in that, In step S2, the top event is "the failure rate of a remote power distribution device is less than 1E-7", the first-level function is "communication function", and the second-level function is "loss of internal communication function".
6. The method according to claim 5, characterized in that, Step S3 is as follows: Step S31: In the tracing of the bottom event, the quantitative safety indicators of the FTA bottom event are traced back to each other with the functional circuit level of FMEA. The fault tree structure or the failure mode of FMEA are improved, supplemented or corrected through qualitative comparison. The circuit is judged to meet the safety requirements or whether there are potential risks through quantitative comparison. Step S32: Based on the tracing results of the bottom event, trace the top event requirements.
7. The method according to claim 6, characterized in that, The quantitative indicators of FTA bottom-event safety are the FTA functional circuit-level safety requirements.
8. The method according to claim 7, characterized in that, In step S31: Qualitative comparison involves tracing the failure modes at the bottom of the FTA and the functional circuit level of the FMEA to identify duplicates or missing items. Duplicates are removed and missing items are added to improve or correct the fault tree structure or the failure modes of the FMEA. The quantitative comparison is as follows: by comparing the failure rate of traceability events at the FMEA functional circuit level with the quantitative security indicators at the FTA functional circuit level, it is determined whether the circuit meets the security requirements or whether there are potential risks.
9. The method according to claim 8, characterized in that, Step S32 is as follows: B1: Create a copy of the fault tree structure after supplementation or correction; B2: Assuming the FMEA failure rate is the true value, perform bottom-up calculations on the fault tree replica to calculate the failure rate of the top event of the fault tree under the current hardware capabilities, and define the failure rate of the top event as a preset value. B3: Compare preset values with security requirements to identify high-risk items that do not meet security requirements; B4: Analyze high-risk items, obtain the minimum cut set of the current top event, and provide improvement measures for bottom events by improving hardware capabilities, increasing design redundancy, or adding detection methods.