Method for modelling the occurrence of feared events within a critical system for detecting the occurrence of such a feared event
The method addresses the limitations of existing models by generating dynamic models for critical systems using a combination of Altarica language and fault tree data, effectively enhancing the detection of feared events and improving system reliability.
Patent Information
- Application Number
- PCT/FR2024/051710
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-12-18
- Filing Date
- 2024-12-18
- Publication Date
- 2025-06-26
AI Technical Summary
Existing methods for modeling critical systems, such as fault trees, fail to account for the dynamic behavior of systems composed of multiple subsystems, leading to incomplete risk assessment and failure detection.
A method that generates a dynamic model for each subsystem using a combination of Altarica language models and fault tree data, allowing for the detection of feared events by updating internal states and propagating information across the system.
Enables comprehensive modeling of critical systems, capturing dynamic behaviors and improving the detection of feared events, thereby enhancing the reliability and safety of complex systems.
Smart Images

Figure FR2024051710_26062025_PF_FP_ABST
Abstract
Description
Description Title of the invention: Method for modeling the occurrence of feared events within a critical system allowing the detection of the occurrence of such a feared event. Domain
[0001] The present invention belongs to the general field of the detection of feared events impacting critical systems.
[0002] More particularly, the present invention relates to a solution for detecting the occurrence of a feared event within a critical system based on the modeling of the different subsystems constituting the critical system taking into account the heterogeneity of the information formats provided for each subsystem.
[0003] Modeling and formal analysis of high-integrity systems are crucial practices in the field of critical systems engineering, where errors can have serious consequences, such as accidents, significant financial losses, or human injuries. These systems are often encountered in fields such as aerospace, automotive, medical systems, nuclear energy, etc. where operational safety is paramount.
[0004] Both are essential practices for ensuring the reliability and safety of high-integrity systems, thereby minimizing the risks associated with serious consequences in the event of failure.
[0005] Formal modeling involves describing the expected behavior of the system in a precise and unambiguous manner using formal languages. These specifications serve as the basis for the development and verification of the critical system.
[0006] Formal analysis, on the other hand, involves the use of automated tools to mathematically verify that the critical system meets these specifications. This may include, among other things, error checking and detection.
[0007] The Altarica language is a formal specification language used in the field of design and verification of critical systems.
[0008] Such a language is based on the notion of logical states, or internal states in the remainder of this document. Logical states are used to represent the state of a system or subsystem at different times.
[0009] Thus, a model conforming to the Altarica language includes a set of logical states that characterize the possible conditions of the system or subsystem under consideration. These logical states are used to express properties of the system under consideration, transitions between internal states, events, etc.
[0010] For example, in the context of an embedded system, it is possible to define internal states representing conditions such as "running", "stopped", "in standby mode", etc. These Internal states can then be used to specify the expected behavior of the system and to perform formal analyses.
[0011] One of the specific features of the Altarica language is that it is used to describe dynamic behaviors. Such dynamic behaviors are represented by transitions between internal states of the system under consideration, where logical conditions determine the transition from one internal state to another. When a transition between two internal states occurs, the values of the variables associated with these internal states are updated, and these new values are then propagated through the rest of the model.
[0012] The behavior of the system under consideration can also be influenced by other external elements, such as events, actions, operations, etc.
[0013] There are other methods for representing the behavior of a critical system, including the so-called fault tree method, or FTA. This FTA method is a safety analysis technique that is also used to evaluate and model the potential causes of failures in a critical system.
[0014] The main objective of the FTA method is to identify events that could lead to system failure and to assess the probability of these failures. To achieve this, the FTA method is based on the concept of a fault tree. A fault tree is a logical diagram that graphically represents the logical combinations of events that lead to system failure.
[0015] The fault tree is a powerful tool for assessing and improving the reliability and safety of complex systems, identifying potential failure scenarios and facilitating decision-making for risk reduction. However, such a tool does not take into account the dynamic aspect of the operation of the system under study.
[0016] This is a hindrance when it comes to modeling a critical system composed of several subsystems modeled both according to models conforming to the Altarica language and at the same time by means of fault trees because the dynamic aspect of the behavior of the critical system is lost. Statement of the invention
[0017] The present invention aims to remedy the aforementioned drawbacks by proposing a solution making it possible to ignore the method used to model a critical system and identify the events impacting the subsystems constituting it.
[0018] To this end, and according to a first aspect, the invention relates to a method for modeling the occurrence of feared events within a critical system comprising at least two subsystems, at least a first subsystem being represented by means of a first model comprising a plurality of internal states characterizing a possible condition of the subsystem, a transition from one internal state to another triggering an update of values of variables associated with one or more internal states, the method comprising the following steps implemented by at least one processor configured to: obtain a first list of elementary failures that may occur within a second subsystem, obtaining a second list of combinations of elementary failures that may occur within the second subsystem, a combination of elementary failures corresponding to the occurrence of a feared event, generating a second model representing the second subsystem, the second model comprising a plurality of internal states each corresponding to an elementary failure, a transition from one internal state to another triggering an update of a current combination of elementary failures occurring within the second subsystem, transmitting, to the first model, information relating to the occurrence of a feared event within the second subsystem in the case where the current combination of elementary failures corresponds to one of the combinations of elementary failures included in the second list.
[0019] Generally, the critical system is represented by a plurality of subsystems. At least one of these subsystems is modeled by means of a fault tree, the others being represented by models conforming to the Altarica language.
[0020] This solution allows, starting from data from a fault tree representing a subsystem, to create a model representing the dynamic behavior of this same subsystem.
[0021] The generation of this model does not require any information about the subsystem other than that contained in the fault tree. In other words, there is no need to know the various components of the subsystem or the physical values involved in the operation of the subsystem.
[0022] In particular modes of implementation, the first list includes, for at least one elementary failure, an associated type of probability law.
[0023] In particular modes of implementation, the first list includes, for at least one elementary failure, an occurrence rate.
[0024] In particular embodiments, the method further comprises a step of obtaining a third list associating at least one elementary failure from the first list with a component of the second subsystem.
[0025] In particular implementation modes, a model representing each component of the second subsystem is generated.
[0026] The invention also relates to a method for determining the occurrence of a feared event within a critical system composed of at least two subsystems, said critical system being represented by: a first model representing a first subsystem and comprising a plurality of internal states characterizing a possible condition of the subsystem, a transition from one internal state to another triggering an update of values of variables associated with one or more internal states, and at least one second model representing a second subsystem, the second model comprising a plurality of internal states each corresponding to an elementary failure which can occur within the second subsystem, a transition from one internal state to another triggering an update of a current combination of elementary failures occurring within the second subsystem, said method comprising the following steps implemented by at least one processor configured to: detect an event triggering, within the second model, a transition from one internal state to another internal state, when the occurrence of a feared event within the second subsystem is detected, transmit information indicating the occurrence of the feared event within the second subsystem to the first model, the reception of this information modifying a current value of at least one internal state of the first model, determine the occurrence of said feared event within the critical system as a function of information indicating the occurrence of at least one feared event within the first subsystem.
[0027] The invention also relates to a device capable of modeling the occurrence of dreaded events within a critical system comprising at least two subsystems, at least a first subsystem being represented by means of a first model comprising a plurality of internal states characterizing a possible condition of the subsystem, a transition from one internal state to another triggering an update of values of variables associated with one or more internal states, the device comprising at least one processor configured to: obtain a first list of elementary failures that may occur within a second subsystem, obtain a second list of combinations of elementary failures that may occur within the second subsystem, a combination of elementary failures corresponding to the occurrence of a dreaded event, generate a second model representing the second subsystem,the second model comprising a plurality of internal states each corresponding to an elementary failure, a transition from one internal state to another triggering an update of a current combination of elementary failures occurring within the second subsystem, transmitting, to the first model, information relating to the occurrence of a feared event within the second subsystem in the case where the current combination of elementary failures corresponds to one of the combinations of elementary failures included in the second list.,
[0028] The invention finally relates to a device capable of determining the occurrence of a feared event within a critical system composed of at least two subsystems, said critical system being represented by: a first model representing a first subsystem and comprising a plurality of internal states characterizing a possible condition of the subsystem, a transition from one internal state to another triggering an update of values of variables associated with one or more internal states, and at least a second model representing a second subsystem, the second model comprising a plurality of internal states each corresponding to an elementary failure that may occur within the second subsystem, a transition from one internal state to another triggering an update of a current combination of elementary failures occurring within the second subsystem, said device comprising at least one processor configured to: detect an event triggering, within the second model, a transition from one internal state to another internal state, when the occurrence of a feared event within the second subsystem is detected, transmit information indicating the occurrence of the feared event within the second subsystem to the first model, the reception of this information modifying a current value of at least one internal state of the first model,determining the occurrence of said feared event within the critical system based on information indicating the occurrence of at least one feared event within the first subsystem., Brief description of the drawings
[0029] Other characteristics and advantages of the present invention will emerge from the description given below, with reference to the appended drawings which illustrate an exemplary embodiment thereof without any limiting character. In the figures:
[0030] [Fig.l] Figure 1 represents an example of a critical system for which there is a need to determine all the conditions leading to the occurrence of one or more feared events,
[0031] [Fig. ] Figure 2 schematically shows the constitution and operation of a brick constituting a dynamic model,
[0032] [Fig.3] Figure 3 represents a flowchart of the steps constituting a method for modeling the occurrence of feared events within a subsystem constituting a critical system according to an embodiment of the present invention,
[0033] [Fig.4] Figure 4 represents a flowchart of the steps constituting a method for determining the occurrence of feared events within the critical system according to an embodiment of the present invention,
[0034] [Fig.5] Figure 5 represents a device capable of implementing at least one of the different methods which are the subject of the present invention. Description of the embodiments
[0035] Figure 1 is an example of a critical system 1 for which there is a need to determine all the conditions leading to the occurrence of one or more feared events. Such a critical system is, for example, an airplane engine system, or a cooling system for a radioactive fuel bunker, etc.
[0036] Such a critical system 1 comprises, in the non-limiting example shown in Figure 1, three subsystems 10, 11 and 12.
[0037] In order to enable a safety engineer to carry out a failure analysis of the critical system 1, he integrates within a global model representing the critical system 1 a plurality of models representing the different subsystems 10, 11 and 12 and which will enable him to determine and analyze the behavior of the critical system 1 and thus identify the combinations of events and the associated conditions which lead to the occurrence of one or more feared events such as for example an engine failure or a failure of a cooling system.
[0038] In the remainder of this document, the Ml model representing the behavior of the critical system 1 is consistent with the Altarica language. More generally, the Ml model is a model capable of describing dynamic behaviors which allows a more detailed analysis of the behavior of the systems studied.
[0039] Such a model Ml is, just like the system 1 which it represents, made up of a plurality of models M10, Mil, M12 respectively representing the behaviors of the subsystems 10, 11 and 12.
[0040] In the embodiment described in the remainder of this document, the Mil and M12 models are, just like the M1 model, capable of describing dynamic behaviors of the Mil and M12 subsystems.
[0041] Figure 2 schematically represents the constitution and operation of a brick constituting a dynamic model such as the Mil and M12 models. The Mil, M12 models are based on a representation of the physical and / or functional architecture of the subsystem represented enriched with dysfunctional data of the subsystem in order to allow the performance of a failure analysis of the subsystem. More specifically, each brick represents the operation of one of the constituent components of the modeled subsystem.
[0042] More particularly, a building block B constituting a Mil model, M12 comprises a plurality of internal states El, which characterize the possible operating conditions of a component of the subsystem considered. These internal states El, express properties of the component considered. Most often these internal states El, are associated with a current value of a physical quantity such as a voltage, a temperature or with a current value of a logical state such as "on", "stopped", "in standby mode", "failed", "critical value", etc.
[0043] The occurrence of an EVT event within the subsystem considered, or coming from another subsystem, triggers a transition Ti_>j between one or more internal states of the brick B. These transitions Ti_>j between internal states El, trigger an update of the values of the variables associated with these internal states El,. This update Prop of the values of the variables associated with these internal states El,, then propagate through the rest of the model relating to the subsystem, also impacting the current operation of the latter.
[0044] This modification of the current operation of the component results in a modification of the output flow Fext of brick B. In other words, a transition Ti_>j of the component results in the transmission of information representative of this new behavior to other bricks constituting the Mil, M12 model, this information is transmitted in the output flow Fext of brick B.
[0045] Unlike subsystems 11 and 12 represented natively by the dynamic Mil and M12 models, subsystem 10 is represented by a list of combinations of elementary LCPE failures, each combination of elementary failures leading to the occurrence of a feared event within subsystem 10.
[0046] In other words, no representation of the physical and / or functional architecture of the subsystem 10 is available, only the dysfunctional data of the subsystem 10 are accessible.
[0047] The present solution proposes, on the basis of this dysfunctional data alone, to generate a dynamic model representing the subsystem 10. Such a solution is implemented, for example within a computer-type device comprising at least one processor configured to implement the different steps of this solution. The internal structure of such a computer will be described in more detail in the remainder of this document.
[0048] Figure 3 represents a flowchart of the steps constituting a method for modeling the occurrence of feared events within a subsystem constituting a critical system according to an embodiment of the present invention.
[0049] Thus, in a step E1, the device implementing the method obtains a first list of elementary failures LPE that may occur within the subsystem 10. In the example chosen, the LPE list comprises five elementary failures PI to P5. Such an LPE list can be obtained, for example, from a fault tree associated with the subsystem 10.
[0050] In a step E2, which may be concomitant with step E1, the device obtains a second list LCPE of combinations of elementary failures which may occur within the subsystem 10, a combination of elementary failures corresponding to the occurrence of a feared event ER within the subsystem 10.
[0051] Once in possession of these two lists LPE and LCPE, the device can generate the model M10 representing the subsystem 10. In a first implementation, the model 10 only includes a single brick B'.
[0052] To do this, firstly, the device creates a brick B' corresponding to subsystem 10. An internal state El, of brick B' is associated with an elementary failure from the list of elementary failures LPE. Thus, in the example that interests us, brick B' includes five internal states E to EI5 corresponding respectively to elementary failures PI to P5. In this brick B', each internal state El, can take two values: "on" or "failed".
[0053] In a second step, the device determines all possible updates of the values of the variables associated with these internal states El, of the brick B' according to the LCPE list of elementary failure combinations.
[0054] Thus, when the occurrence of an EVT event within subsystem 10, or coming from another subsystem, triggers a transition between one or more internal states of the brick B', these transitions Ti_>j between internal states El, trigger an update of the values of the variables associated with these internal states which then propagate through the rest of the model relating to the subsystem 10 also impacting the current operation of the latter.
[0055] The device then compares, in a step E3, the current combination of elementary failures with the combinations of elementary failures included in the LCPE list of combinations of elementary failures leading to the occurrence of a feared event ER.
[0056] The modification of the current operation of the brick B' results in a modification of the output flow Fext of the brick B'. In other words, a transition Ti_>j between two internal states occurring within the brick B' results in the transmission of information representative of this new behavior to the other models Mil, M12, this information is transmitted, in a step E4, in the output flow Fext of the brick B' and reports, where appropriate, the occurrence of a feared event ER within the subsystem 10.
[0057] In a particular embodiment, the LPE list of elementary failures associates with each elementary failure P1-P5 included in this LPE list an associated probability law type. Thus, for example, the elementary failure PI is associated with an exponential type law, the elementary failures P2 and P3 are associated with a dormant type law and finally the elementary failures are associated with a constant type law.
[0058] In another embodiment complementary to the previous one, the LPE list of elementary failures associates with each elementary failure P1-P5 included in this LPE list, in addition to a probability law, a rate of occurrence of the elementary failure concerned. As a non-limiting example, the elementary failure PI has an occurrence rate per hour of 10 -6 just like the elementary breakdown P2, the elementary breakdowns P2 and P3 have an occurrence rate per hour of 10 -9as well as a dormancy time of approximately 100 hours, and finally, the elementary failure P5 has an occurrence rate per hour of 0.9.
[0059] This information relating to the probability law and the rate of occurrence per hour of the various elementary breakdowns makes it possible to refine the rules for updating the values of the variables associated with these internal states El, of the brick B' in order to propose a modeling of the subsystem 10 closest to the real behavior of the subsystem 10.
[0060] In a second implementation, the device obtains a third list associating at least one elementary failure P1-P5 from the LPE list with a component of the subsystem. In such an implementation, the model 10 is then made up of N+1 bricks B', N being the number of components constituting the subsystem 10. Each brick B' is generated in accordance with step E2 and on the basis of the various information obtained by the device such as the list of elementary failures LPE, the list LCPE of combinations of elementary failures leading to the occurrence of a feared event ER within the subsystem 10.
[0061] Figure 4 represents a flowchart of the steps constituting a method for determining the occurrence of feared events within the critical system 1 according to an embodiment of the present invention. Such a method is implemented, for example within a computer-type device comprising at least one processor configured to implement the different steps of this method. The internal structure of such a computer will be described in more detail in the remainder of this document.
[0062] In a step Gl, the device detects the occurrence of an event EVT triggering, within the model M10, a transition Ti_>j between one or more internal states of a brick B'. These transitions between internal states El, in turn trigger, in a step G2, an update of the values of the variables associated with these internal states El,.
[0063] When the occurrence of a feared event is detected in one of the bricks B' of the model 10, as described with reference to the step E3 previously described, the model 10 transmits, in a step G3, information indicating the occurrence of this feared event to at least one of the models Mil, M12, the reception of this information modifying a current value of at least one internal state of one of these models Mil, M12. The identity of the model receiving the information indicating the occurrence of a feared event within the model M10 depends on the interactions existing between the different subsystems 10, 11 and 12.
[0064] Finally, depending on the different information relating to the occurrence of feared events within the different models M10, Mil and M12, the device determines in a step G4 the occurrence of a feared event within the critical system 1.
[0065] Figure 5 represents a device capable of implementing at least one of the different methods which are the subject of the present invention.
[0066] Such a device may comprise at least one hardware processor 501, a storage unit 502, and at least one communication interface 503, which are connected to each other through a bus 504. Of course, the constituent elements of the device may be connected by means of a connection other than a bus.
[0067] The processor 501 controls the operations of the device. The storage unit 502 stores at least one program for implementing the various methods that are the subject of the invention to be executed by the processor 501, and various data, such as parameters used for calculations performed by the processor 501, intermediate data of calculations performed by the processor 501, etc. The processor 501 may be formed by any known and suitable hardware or software, or by a combination of hardware and software. For example, the processor 501 may be formed by dedicated hardware such as a processing circuit, or by a programmable processing unit such as a central processing unit (Central Processing Unit) which executes a program stored in a memory thereof.
[0068] The storage unit 502 may be formed by any suitable means capable of storing the program(s) and data in a computer-readable manner. Examples of the storage unit 502 include non-transitory computer-readable storage media such as semiconductor memory devices, and magnetic, optical, or magneto-optical recording media loaded into a read-write unit.
[0069] The interface 503 provides an interface between the device and any other device with which it is required to receive or transmit data during the execution of at least one of the methods that are the subject of the present invention.
Claims
Claims
1. Method for modeling the occurrence of feared events within a critical system (1) comprising at least two subsystems (10, 11, 12), at least a first subsystem (10, 11, 12) being represented by means of a first model (Mil, M12) comprising a plurality of internal states (Eli) characterizing a possible condition of the subsystem, a transition (Ti_>j) from one internal state to another triggering an update (Prop) of values of variables associated with one or more internal states, the method comprising the following steps implemented by at least one processor configured to: obtain (El) a first list of elementary failures (LPE) that may occur within a second subsystem (10), obtain (E2) a second list of combinations of elementary failures (LCPE) that may occur within the second subsystem (10), a combination of elementary failures corresponding to the occurrence of a feared event,generating a second model (M10) representing the second subsystem (10), the second model comprising a plurality of internal states (El,) each corresponding to an elementary failure (P1-P5), a transition (Ti_>j) from one internal state to another triggering an update of a current combination of elementary failures occurring within the second subsystem, transmitting (E4), to the first model (11, 12), information relating to the occurrence of a feared event within the second subsystem in the case where the current combination of elementary failures corresponds to one of the combinations of elementary failures included in the second list.,
2. Method for modeling the occurrence of feared events within a critical system according to claim 1 in which the first list comprises, for at least one elementary failure, an associated type of probability law.
3. Method for modeling the occurrence of feared events within a critical system according to claim 1 or claim 2, in which the first list comprises, for at least one elementary failure, an occurrence rate.
4. Method for modeling the occurrence of feared events within a critical system according to any one of claims 1 to 3, further comprising a step of obtaining a third list associating at least one elementary failure from the first list with a component of the second subsystem.
5. A method of modeling the occurrence of feared events within a critical system according to claim 4, wherein a model representing each component of the second subsystem (10) is generated.
6. Method for determining the occurrence of a feared event within a critical system (1) composed of at least two subsystems (10, 11, 12), said critical system being represented by: a first model (Mil, M12) representing a first subsystem (11, 12) and comprising a plurality of internal states (Eli) characterizing a possible condition of the subsystem, a transition (^) from one internal state to another triggering an update of values of variables associated with one or more internal states, and at least one second model (M10) representing a second subsystem (10), the second model comprising a plurality of internal states (Eli) each corresponding to an elementary failure (P1-P5) that may occur within the second subsystem, a transition (Ti_>j) from one internal state to another triggering an update (Prop) of a current combination of elementary failures occurring within the second subsystem, said method comprising the following steps implemented by at least one processor configured to: detect (Gl) an event (EVT) triggering, within the second model (M10),a transition from one internal state to another internal state, when the occurrence of a feared event within the second subsystem is detected, transmitting (G3) information indicating the occurrence of the feared event within the second subsystem (M10) to the first model (M1), the reception of this information modifying a current value of at least one internal state of the first model, determining (G4) the occurrence of said feared event within the critical system (1) as a function of information indicating the occurrence of at least one feared event within the first subsystem (11, 12).,
7. Device capable of modeling the occurrence of dreaded events within a critical system (1) comprising at least two subsystems (10, 11, 12), at least a first subsystem (11, 12) being represented by means of a first model (Mil, M12) comprising a plurality of internal states (Eli) characterizing a possible condition of the subsystem, a transition (T,. >j) from one internal state to another triggering an update (Prop) of values of variables associated with one or more internal states, the device comprising at least one processor configured to: obtain a first list (LPE) of elementary failures that may occur within a second subsystem, obtain a second list (LCPE) of combinations of elementary failures that may occur within the second subsystem (10), a combination of elementary failures corresponding to the occurrence of a dreaded event, generate a second model (M10) representing the second subsystem (10),the second model comprising a plurality of internal states (Eli) each corresponding to an elementary failure (Pl-P5), a transition (Ti_>j) from one internal state to another triggering an update of a current combination of elementary failures occurring within the second subsystem, transmitting, to the first model (Ml), information relating to the occurrence of a feared event within the second subsystem (10) in the case where the current combination of elementary failures corresponds to one of the combinations of elementary failures included in the second list.,
8. Device capable of determining the occurrence of a feared event within a critical system (1) composed of at least two subsystems (10, 11, 12), said critical system being represented by: a first model (Mil, M12) representing a first subsystem (11, 12) and comprising a plurality of internal states (Eli) characterizing a possible condition of the subsystem, a transition (Ti_>j) from one internal state to another triggering an update of values of variables associated with one or more internal states, and at least one second model (M10) representing a second subsystem (10), the second model comprising a plurality of internal states (Eli) each corresponding to an elementary failure (P1-P5) that may occur within the second subsystem, a transition from one internal state to another triggering an update of a current combination of elementary failures occurring within the second subsystem,said device comprising at least one processor configured to: detect an event (EVT) triggering, within the second model (M10), a transition from one internal state to another internal state, when the occurrence of a feared event within the second subsystem is detected, transmit information indicating the occurrence of the feared event within the second subsystem (10) to the first model (M11, M12), the reception of this information modifying a current value of at least one internal state of the first model, determine the occurrence of said feared event within the critical system (1) as a function of information indicating the occurrence of at least one feared event within the first subsystem (11, 12).,
9. Computer program comprising instructions for implementing a method for modeling the occurrence of feared events within a critical system according to any one of claims 1 to 5, when said program is executed by a computer.
10. Computer program comprising instructions for implementing a method for determining the occurrence of a feared event within a critical system according to claim 6, when said program is executed by a computer.
Citation Information
Patent Citations
Method, devices and computer program for assisting in the diagnostic of an aircraft system, using failure condition graphs
FR2966616A1
Method for determining the state of a device in an aircraft
FR3018933A1
Methods systems and apparatus for analyzing complex systems via prognostic reasoning
US20110118905A1