Method for modeling the occurrence of feared events within a critical system allowing the detection of the occurrence of such a feared event.

The method generates a dynamic model from a fault tree to detect feared events in critical systems, addressing the challenge of dynamic behavior and information heterogeneity, and improving system reliability and safety.

FR3156928A1Active Publication Date: 2025-06-20SAFRAN AIRCRAFT ENGINES SAS
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
FR2023014350
Authority / Receiving Office
FR · FR
Patent Type
Applications
Current Assignee / Owner
Filing Date
2023-12-18
Publication Date
2025-06-20
Estimated Expiration
2043-12-18

AI Technical Summary

Technical Problem

Existing methods for modeling critical systems fail to account for the dynamic behavior and heterogeneity of information formats across subsystems, particularly when combining models conforming to the Altarica language with fault trees.

Method used

A method that generates a dynamic model representing a subsystem using a fault tree, allowing for the detection of feared events by updating internal states and transmitting information between models, without requiring detailed knowledge of the subsystem's components or physical values.

Benefits of technology

Enables effective detection and modeling of feared events within critical systems, maintaining dynamic behavior and accounting for heterogeneity in information formats, thereby enhancing the reliability and safety of critical systems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

Method for modeling the occurrence of dreaded events within a critical system allowing the detection of the occurrence of such a dreaded event. The invention relates to the modeling of the occurrence of dreaded events within a critical system comprising at least two subsystems, a first subsystem being represented by means of a first model comprising a plurality of internal states characterizing a possible condition of the subsystem, a transition from one internal state to another triggering an update of values ​​of variables associated with internal states. More precisely, the method is based on obtaining a first list of elementary failures that may occur within a second subsystem, a second list of combinations of these elementary failures, a combination of elementary failures corresponding to the occurrence of a dreaded event.The method generates a second model representing the second subsystem comprising a plurality of internal states each corresponding to an elementary failure, a transition from one internal state to another triggering an update of a current combination of elementary failures occurring within the second subsystem. Figure for abstract: Fig. 2.
Need to check novelty before this filing date? Find Prior Art

Description

Title of the invention: Method for modeling the occurrence of feared events within a critical system allowing the detection of the occurrence of such a feared event. Technical field

[0001] The present invention belongs to the general field of the detection of feared events impacting critical systems.

[0002] More particularly, the present invention relates to a solution for detecting the occurrence of a feared event within a critical system based on the modeling of the different subsystems constituting the critical system taking into account the heterogeneity of the information formats provided for each subsystem. Prior art

[0003] Modeling and formal analysis of high-integrity systems are crucial practices in the field of critical systems engineering, where errors can have serious consequences, such as accidents, significant financial losses, or human damage. These systems are often encountered in fields such as aerospace, automotive, medical systems, nuclear energy, etc. where operational safety is paramount.

[0004] They are both essential practices for ensuring the reliability and safety of high-integrity systems, thereby minimizing the risks associated with serious consequences in the event of failure.

[0005] Formal modeling consists of describing the expected behavior of the system in a precise and unambiguous manner using formal languages. These specifications serve as the basis for the development and verification of the critical system.

[0006] Formal analysis involves the use of automated tools to mathematically verify that the critical system meets these specifications. This may include, among other things, error detection and verification.

[0007] The Altarica language is a formal specification language used in the field of design and verification of critical systems.

[0008] Such a language is based on the notion of logical states, or internal states in the remainder of this document. Logical states are used to represent the state of a system or subsystem at different times.

[0009] Thus, a model conforming to the Altarica language comprises a set of logical states which characterize the possible conditions of the system or subsystem considered. These logical states are used to express properties of the system considered, transitions between internal states, events, etc.

[0010] For example, in the context of an embedded system, it is possible to define internal states representing conditions such as "on", "off", "in standby mode", etc. These internal states can then be used to specify the expected behavior of the system and to perform formal analyses.

[0011] One of the specificities of the Altarica language is that it is used to describe dynamic behaviors. Such dynamic behaviors are represented by transitions between internal states of the system considered, where logical conditions determine the passage from one internal state to another. When a transition between two internal states occurs, the values ​​of the variables associated with these internal states are updated, and these new values ​​are then propagated through the rest of the model.

[0012] The behavior of the system considered can also be influenced by other external elements, such as events, actions, operations, etc.

[0013] There are other methods for representing the behavior of a critical system, including the so-called fault tree method or FTA for "Fault Tree Analysis" in English. This FTA method is a technique for analyzing operational safety, also used to evaluate and model the potential causes of failures in a critical system.

[0014] The main objective of the FTA method is to identify events that could lead to a system failure and to assess the probability of these failures. For this, the FTA method is based on the concept of a fault tree. A fault tree is a logical diagram that graphically represents the logical combinations of events that lead to a system failure.

[0015] The fault tree is a powerful tool for assessing and improving the reliability and safety of complex systems, by identifying potential failure scenarios and facilitating decision-making for risk reduction. However, such a tool does not take into account the dynamic aspect of the operation of the system under study.

[0016] This constitutes a brake when it comes to modeling a critical system composed of several subsystems modeled both according to models conforming to the Altarica language and at the same time by means of fault trees because the dynamic aspect of the behavior of the critical system is lost. Statement of the invention

[0017] The present invention aims to remedy the aforementioned drawbacks by proposing a solution making it possible to ignore the method used to model a critical system and identify the events impacting the subsystems constituting it.

[0018] To this end, and according to a first aspect, the invention relates to a method of modeling-

[0019]

[0020]

[0021]

[0022]

[0023]

[0024] lization of the occurrence of dreaded events within a critical system comprising at least two subsystems, at least a first subsystem being represented by means of a first model comprising a plurality of internal states characterizing a possible condition of the subsystem, a transition from one internal state to another triggering an update of values ​​of variables associated with one or more internal states, the method comprising the following steps implemented by at least one processor configured to: - obtain an initial list of elementary failures that may occur within a second subsystem, - obtain a second list of combinations of elementary failures that may occur within the second subsystem, a combination of elementary failures corresponding to the occurrence of a feared event, - generating a second model representing the second subsystem, the second model comprising a plurality of internal states each corresponding to an elementary failure, a transition from one internal state to another triggering an update of a current combination of elementary failures occurring within the second subsystem, - transmit, to the first model, information relating to the occurrence of a feared event within the second subsystem in the case where the current combination of elementary failures corresponds to one of the combinations of elementary failures included in the second list. Generally, the critical system is represented by a plurality of subsystems. At least one of these subsystems is modeled by means of a fault tree, the others being represented by models conforming to the Altarica language. This solution allows, starting from data from a fault tree representing a subsystem, to create a model representing the dynamic behavior of this same subsystem. Generating this model does not require any information about the subsystem other than that contained in the fault tree. In other words, there is no need to know the various components of the subsystem or the physical values ​​involved in the operation of the subsystem. In particular modes of implementation, the first list includes, for at least one elementary failure, an associated type of probability law. In particular modes of implementation, the first list includes, for at least one elementary failure, an occurrence rate. In particular embodiments, the method further comprises a step of obtaining a third list associating at least one elementary failure of the first list to a component of the second subsystem.

[0025] In particular embodiments, a model representing each component of the second subsystem is generated.

[0026] The invention also relates to a method for determining the occurrence of a feared event within a critical system composed of at least two subsystems, said critical system being represented by: - a first model representing a first subsystem and comprising a plurality of internal states characterizing a possible condition of the subsystem, a transition from one internal state to another triggering an update of values ​​of variables associated with one or more internal states, and at least - a second model representing a second subsystem, the second model comprising a plurality of internal states each corresponding to an elementary failure that may occur within the second subsystem, a transition from one internal state to another triggering an update of a current combination of elementary failures occurring within the second subsystem, said method comprising the following steps implemented by at least one processor configured to: - detect an event triggering, within the second model, a transition from one internal state to another internal state, - when the occurrence of a feared event within the second subsystem is detected, transmitting information indicating the occurrence of the feared event within the second subsystem to the first model, the reception of this information modifying a current value of at least one internal state of the first model, - determine the occurrence of said feared event within the critical system based on information indicating the occurrence of at least one feared event within the first subsystem.

[0027] The invention also relates to a device capable of modeling the occurrence of feared events within a critical system comprising at least two subsystems, at least a first subsystem being represented by means of a first model comprising a plurality of internal states characterizing a possible condition of the subsystem, a transition from one internal state to another triggering an update of values ​​of variables associated with one or more internal states, the device comprising at least one processor configured to: - obtain an initial list of elementary failures that may occur within a second subsystem, - obtain a second list of combinations of elementary failures which can occur within the second subsystem, a combination of elementary failures corresponding to the occurrence of a feared event, - generating a second model representing the second subsystem, the second model comprising a plurality of internal states each corresponding to an elementary failure, a transition from one internal state to another triggering an update of a current combination of elementary failures occurring within the second subsystem, - transmit, to the first model, information relating to the occurrence of a feared event within the second subsystem in the case where the current combination of elementary failures corresponds to one of the combinations of elementary failures included in the second list.

[0028] The invention finally relates to a device capable of determining the occurrence of a feared event within a critical system composed of at least two subsystems, said critical system being represented by: - a first model representing a first subsystem and comprising a plurality of internal states characterizing a possible condition of the subsystem, a transition from one internal state to another triggering an update of values ​​of variables associated with one or more internal states, and at least - a second model representing a second subsystem, the second model comprising a plurality of internal states each corresponding to an elementary failure that may occur within the second subsystem, a transition from one internal state to another triggering an update of a current combination of elementary failures occurring within the second subsystem, said device comprising at least one processor configured to: - detect an event triggering, within the second model, a transition from one internal state to another internal state, - when the occurrence of a feared event within the second subsystem is detected, transmitting information indicating the occurrence of the feared event within the second subsystem to the first model, the reception of this information modifying a current value of at least one internal state of the first model, - determine the occurrence of said feared event within the critical system based on information indicating the occurrence of at least one feared event within the first subsystem. Brief description of the drawings

[0029] Other features and advantages of the present invention will emerge from the description made below, with reference to the attached drawings which illustrate an example of embodiment without any limiting character. In the figures:

[0030] [Fig-1] [Fig. 1] represents an example of a critical system for which there is a need to determine all the conditions leading to the occurrence of one or more feared events,

[0031] [Fig.2] [Fig.2] schematically shows the constitution and operation of a brick constituting a dynamic model,

[0032] [Fig.3] [Fig.3] represents a flowchart of the steps constituting a method for modeling the occurrence of feared events within a subsystem constituting a critical system according to an embodiment of the present invention,

[0033] [Fig.4] [Fig.4] represents a flowchart of the steps constituting a method determining the occurrence of feared events within the critical system according to an embodiment of the present invention,

[0034] [Fig.5] [Fig.5] represents a device capable of implementing at least one of the different methods which are the subject of the present invention. Description of the embodiments

[0035] [Fig.l] is an example of a critical system 1 for which there is a need to determine all of the conditions leading to the occurrence of one or more feared events. Such a critical system is, for example, an airplane engine system, or a cooling system for a radioactive fuel bunker, etc.

[0036] Such a critical system 1 comprises, in the non-limiting example shown in [Fig.l], three subsystems 10, 11 and 12.

[0037] In order to enable a safety engineer to carry out a failure analysis of the critical system 1, he integrates within a global model representing the critical system 1 a plurality of models representing the different subsystems 10, 11 and 12 and which will enable him to determine and analyze the behavior of the critical system 1 and thus identify the combinations of events and the associated conditions which lead to the occurrence of one or more feared events such as for example an engine failure or a failure of a cooling system.

[0038] In the remainder of this document, the model M1 representative of the behavior of the critical system 1 is in accordance with the Altarica language. More generally, the model M1 is a model capable of describing dynamic behaviors which allows a more detailed analysis of the behavior of the systems studied.

[0039] Such a model M1 is, just like the system 1 that it represents, made up of a plurality of models M10, Mil, M12 respectively representing the behaviors subsystems 10, 11 and 12.

[0040] In the exemplary embodiment described in the remainder of this document, the Mil and M12 models are, just like the M1 model, capable of describing dynamic behaviors of the Mil and M12 subsystems.

[0041] [Fig.2] schematically represents the constitution and operation of a brick constituting a dynamic model such as the Mil and Ml2 models. The Mil, M12 models are based on a representation of the physical and / or functional architecture of the subsystem represented enriched with dysfunctional data of the subsystem in order to allow the performance of a failure analysis of the subsystem. More specifically, each brick represents the operation of one of the constituent components of the modeled subsystem.

[0042] More particularly, a brick B constituting a model M1 1, M12 comprises a plurality of internal states EI; which characterize the possible operating conditions of a component of the subsystem considered. These internal states Eh express properties of the component considered. Most often, these internal states EI; are associated with a current value of a physical quantity such as a voltage, a temperature or with a current value of a logical state such as “on”, “stopped”, “in standby mode”, “failed”, “critical value”, etc.

[0043] The occurrence of an EVT event within the subsystem considered, or coming from another subsystem, triggers a transition between one or more internal states of the brick B. These transitions between internal states EI; trigger an update of the values ​​of the variables associated with these internal states EI;. This update Prop of the values ​​of the variables associated with these internal states El,, then propagate through the rest of the model relating to the subsystem, also impacting the current operation of the latter.

[0044] This modification of the current operation of the component results in a modification of the output flow Fext of the brick B. In other words, a transition of the component results in the transmission of information representative of this new behavior to other bricks constituting the model Mil, M12, this information is transmitted in the output flow Fext of the brick B.

[0045] Unlike subsystems 11 and 12 represented natively by the dynamic models M11 and M12, subsystem 10 is represented by a list of combinations of elementary failures LCPE, each combination of elementary failures leading to the occurrence of a feared event within subsystem 10.

[0046] In other words, no representation of the physical and / or functional architecture of the subsystem 10 is available, only the dysfunctional data of the subsystem 10 are accessible.

[0047] The present solution proposes, on the basis of these dysfunctional data alone, to generate a dynamic model representing the subsystem 10. Such a solution is implemented, for example within a computer-type device comprising at least one processor configured to implement the different steps of this solution. The internal structure of such a computer will be described in more detail in the remainder of this document.

[0048] [Fig. 3] represents a flowchart of the steps constituting a method for modeling the occurrence of feared events within a subsystem constituting a critical system according to an embodiment of the present invention.

[0049] Thus, in a step E1, the device implementing the method obtains a first list of elementary failures LPE that may occur within the subsystem 10. In the example chosen, the list LPE comprises five elementary failures P1 to P5. Such an LPE list can be obtained, for example, from a fault tree associated with the subsystem 10.

[0050] In a step E2, which may be concomitant with step E1, the device obtains a second list LCPE of combinations of elementary failures that may occur within the subsystem 10, a combination of elementary failures corresponding to the occurrence of a feared event ER within the subsystem 10.

[0051] Once in possession of these two lists LPE and LCPE, the device can generate the model M10 representing the subsystem 10. In a first implementation, the model 10 only comprises a single brick B'.

[0052] To do this, firstly, the device therefore creates a brick B' corresponding to the subsystem 10. An internal state EI; of the brick B' is associated with an elementary failure from the list of elementary failures LPE. Thus, in the example which interests us, the brick B' comprises five internal states Eli to EI5 corresponding respectively to the elementary failures PI to P5. In this brick B', each internal state EI; can take two values: "on" or "failed".

[0053] In a second step, the device determines all possible updates of the values ​​of the variables associated with these internal states EI; of the brick B' according to the LCPE list of elementary failure combinations.

[0054] Thus, when the occurrence of an EVT event within the subsystem 10, or coming from another subsystem, triggers a transition between one or more internal states of the brick B', these transitions between internal states EI; trigger an update of the values ​​of the variables associated with these internal states which then propagate through the rest of the model relating to the subsystem 10 also impacting the current operation of the latter.

[0055] The device then compares, in a step E3, the current combination of elementary failures with the combinations of elementary failures included in the list LCPE of combinations of elementary failures leading to the occurrence of a feared ER event.

[0056] The modification of the current operation of the brick B' results in a modification of the output flow Fext of the brick B'. ​​In other words, a transition between two internal states occurring within the brick B' results in the transmission of information representative of this new behavior to the other models Mil, M12, this information is transmitted, in a step E4, in the output flow Fext of the brick B' and reports, where appropriate, the occurrence of a feared event ER within the subsystem 10.

[0057] In a particular embodiment, the LPE list of elementary failures associates with each elementary failure P1-P5 included in this LPE list an associated probability law type. Thus, for example, the elementary failure PI is associated with an exponential type law, the elementary failures P2 and P3 are associated with a dormant type law and finally the elementary failures are associated with a constant type law.

[0058] In another embodiment complementary to the previous one, the LPE list of elementary failures associates with each elementary failure P1-P5 included in this LPE list, in addition to a probability law, a rate of occurrence of the elementary failure concerned. As a non-limiting example, the elementary failure PI has an occurrence rate per hour of 106 just like the elementary failure P2, the elementary failures P2 and P3 have an occurrence rate per hour of 109 as well as a dormancy time of approximately 100 hours, and finally, the elementary failure P5 has an occurrence rate per hour of 0.9.

[0059] This information relating to the probability law and the rate of occurrence per hour of the various elementary failures makes it possible to refine the rules for updating the values ​​of the variables associated with these internal states EI; of the brick B' in order to propose a modeling of the subsystem 10 closest to the real behavior of the subsystem 10.

[0060] In a second implementation, the device obtains a third list associating at least one elementary failure P1-P5 of the list LPE with a component of the subsystem. In such an implementation, the model 10 is then made up of N+1 bricks B', N being the number of components constituting the subsystem 10. Each brick B' is generated in accordance with step E2 and on the basis of the different information obtained by the device such as the list of elementary failures LPE, the list LCPE of combinations of elementary failures leading to the occurrence of a feared event ER within the subsystem 10.

[0061] [Fig.4] represents a flowchart of the steps constituting a method for determining the occurrence of feared events within the critical system 1 according to an embodiment of the present invention. Such a method is implemented, by example within a computer-type device comprising at least one processor configured to implement the different steps of this method. The internal structure of such a computer will be described in more detail later in this document.

[0062] In a step G1, the device detects the occurrence of an event EVT triggering, within the model M10, a transition between one or more internal states of a brick B'. ​​These transitions between internal states EI; in turn trigger, in a step G2, an update of the values ​​of the variables associated with these internal states EI;.

[0063] When the occurrence of a feared event is detected in one of the bricks B' of the model 10, as described with reference to the step E3 previously described, the model 10 transmits, in a step G3, information indicating the occurrence of this feared event to at least one of the models Mil, M12, the reception of this information modifying a current value of at least one internal state of one of these models Mil, M12. The identity of the model receiving the information indicating the occurrence of a feared event within the model M10 depends on the interactions existing between the different subsystems 10, 11 and 12.

[0064] Finally, depending on the different information relating to the occurrence of feared events within the different models M10, Mil and M12, the device determines in a step G4 the occurrence of a feared event within the critical system 1.

[0065] [Fig. 5] represents a device capable of implementing at least one of the different methods which are the subject of the present invention.

[0066] Such a device may comprise at least one hardware processor 501, a storage unit 502, and at least one communication interface 503, which are connected to each other via a bus 504. Of course, the constituent elements of the device may be connected by means of a connection other than a bus.

[0067] The processor 501 controls the operations of the device. The storage unit 502 stores at least one program for implementing the various methods that are the subject of the invention to be executed by the processor 501, and various data, such as parameters used for calculations performed by the processor 501, intermediate data of calculations performed by the processor 501, etc. The processor 501 may be formed by any known and suitable hardware or software, or by a combination of hardware and software. For example, the processor 501 may be formed by dedicated hardware such as a processing circuit, or by a programmable processing unit such as a central processing unit (Central Processing Unit) which executes a program stored in a memory thereof.

[0068] The storage unit 502 may be formed by any suitable means capable of storing the program(s) and data in a computer-readable manner. Examples of storage unit 502 include media computer-readable non-transitory storage such as semiconductor memory devices, and magnetic, optical, or magneto-optical recording media loaded into a read-write unit.

[0069] The interface 503 provides an interface between the device and any other device with which it is required to receive or transmit data during the execution of at least one of the methods that are the subject of the present invention.

Claims

Claims

1. Method for modeling the occurrence of feared events within a critical system (1) comprising at least two subsystems (10, 11, 12), at least a first subsystem (10, 11, 12) being represented by means of a first model (Ml 1, Ml2) comprising a plurality of internal states (Eh) characterizing a possible condition of the subsystem, a transition (T^) from one internal state to another triggering an update (Prop) of values ​​of variables associated with one or more internal states, the method comprising the following steps implemented by at least one processor configured to: - obtain (El) a first list of elementary failures (LPE) that may occur within a second subsystem (10), - obtain (E2) a second list of combinations of elementary failures (LCPE) that may occur within the second subsystem (10), a combination of elementary failures corresponding to the occurrence of a dreaded event,- generating a second model (M10) representing the second subsystem (10), the second model comprising a plurality of internal states (EI;) each corresponding to an elementary failure (P1-P5), a transition (T^) from one internal state to another triggering an update of a current combination of elementary failures occurring within the second subsystem, - transmitting (E4), to the first model (11, 12), information relating to the occurrence of a feared event within the second subsystem in the case where the current combination of elementary failures corresponds to one of the combinations of elementary failures included in the second list.,

2. Method for modeling the occurrence of feared events within a critical system according to claim 1 in which the first list comprises, for at least one elementary failure, an associated type of probability law.

3. A method of modeling the occurrence of feared events within a critical system according to claim 1 or claim 2, in which the first list includes, for at least one elementary failure, an occurrence rate.

4. Method for modeling the occurrence of feared events within a critical system according to any one of claims 1 to 3, further comprising a step of obtaining a third list associating at least one elementary failure from the first list with a component of the second subsystem.

5. A method of modeling the occurrence of feared events within a critical system according to claim 4, wherein a model representing each component of the second subsystem (10) is generated.

6. Method for determining the occurrence of a feared event within a critical system (1) composed of at least two subsystems (10, 11, 12), said critical system being represented by: - ​​a first model (Mil, M12) representing a first subsystem (11, 12) and comprising a plurality of internal states (Eh) characterizing a possible condition of the subsystem, a transition (T^j) from one internal state to another triggering an update of values ​​of variables associated with one or more internal states, and at least - a second model (M10) representing a second subsystem (10), the second model comprising a plurality of internal states (EI;) each corresponding to an elementary failure (P1-P5) that may occur within the second subsystem, a transition (1) ^) from one internal state to another triggering an update (Prop) of a current combination of elementary failures occurring within the second subsystem, said method comprising the following steps implemented by at least one processor configured to: - detect (Gl) an event (EVT) triggering, within the second model (M10), a transition from one internal state to another internal state, - when the occurrence of a feared event within the second subsystem is detected, transmit (G3) information indicating the occurrence of the feared event to the; within the second subsystem (M10) to the first model (M1), the reception of this information modifying a current value of at least one internal state of the first model, - determining (G4) the occurrence of said feared event within the critical system (1) as a function of information indicating the occurrence of at least one feared event within the first subsystem (11, 12).

7. Device capable of modeling the occurrence of feared events within a critical system (1) comprising at least two subsystems (10, 11, 12), at least a first subsystem (11, 12) being represented by means of a first model (Ml 1, Ml2) comprising a plurality of internal states (EI;) characterizing a possible condition of the subsystem, a transition (Tj.^) from one internal state to another triggering an update (Prop) of values ​​of variables associated with one or more internal states, the device comprising at least one processor configured to: - obtain a first list (LPE) of elementary failures which may occur within a second subsystem, - obtain a second list (LCPE) of combinations of elementary failures which may occur within the second subsystem (10), a combination of elementary failures corresponding to the occurrence of a feared event, - generating a second model (M10) representing the second subsystem (10), the second model comprising a plurality of internal states (Eh) each corresponding to an elementary failure (Pl-P5), a transition (T^j) from one internal state to another triggering an update of a current combination of elementary failures occurring within the second subsystem, - transmit, to the first model (Ml), information relating to the occurrence of a feared event within the second subsystem (10) in the case where the current combination of elementary failures corresponds to one of the combinations of elementary failures included in the second list.

8. Device capable of determining the occurrence of a feared event within a critical system (1) composed of at least two subsystems (10, 11, 12), said critical system being represented by: - a first model (Mil, M12) representing a first subsystem (11, 12) and comprising a plurality of internal states (El;) characterizing a possible condition of the subsystem, a transition (T^j) from one internal state to another triggering an update of values ​​of variables associated with one or more internal states, and at least - a second model (M10) representing a second subsystem (10), the second model comprising a plurality of internal states (EI;) each corresponding to an elementary failure (P1-P5) which may occur within the second subsystem, a transition from one internal state to another triggering an update of a current combination of elementary failures occurring within the second subsystem, said device comprising at least one processor configured to: - detect an event (EVT) triggering, within the second model (M10), a transition from one internal state to another internal state, - when the occurrence of a feared event within the second subsystem is detected, transmitting information indicating the occurrence of the feared event within the second subsystem (10) to the first model (Mil, Ml2), the reception of this information modifying a current value of at least one internal state of the first model, - determining the occurrence of said feared event within the critical system (1) based on information indicating the occurrence of at least one feared event within the first subsystem (11, 12).

9. Computer program comprising instructions for implementing implementation of a method for modeling the occurrence of feared events within a critical system according to any one of claims 1 to 5, when said program is executed by a computer.

10. A computer program comprising instructions for implementing a method for determining the occurrence of a feared event within a critical system according to claim 6, when said program is executed by a computer.

Citation Information

Patent Citations

  • Method, devices and computer program for assisting in the diagnostic of an aircraft system, using failure condition graphs

    FR2966616A1

  • Method for determining the state of a device in an aircraft

    FR3018933A1

  • Methods systems and apparatus for analyzing complex systems via prognostic reasoning

    US20110118905A1