Automated Safety Case Construction via Failure Port Mapping

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current safety critical systems lack automated methods for constructing safety cases at the system level, as manual connection of failure modes between interacting components is required, which is inefficient and not suitable for runtime safety assessment.

Innovation Solution

A method and apparatus for automated qualification of safety critical systems, where failure port mapping is performed using a generic fault type data model to connect output and input failure modes of component fault trees, enabling automatic fault tree analysis and comparison with safety targets.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Extent of automation

If manual connection of failure modes between components is used, then safety analysis can be performed, but automation and efficiency are reduced

Engineering Contradiction:
Improveautomation of safety case constructionVSAvoidtime for connecting failure modes
Core Design Contradiction:
Extent of automationVSLoss of time

Solution Approach 1:

The patent applies preliminary action by pre-defining failure mode connection rules and component interfaces during system design, before actual safety analysis is needed. Component fault trees are prepared with standardized failure mode definitions that can be automatically matched and connected later without manual intervention, thus automating the safety case construction process while reducing time loss.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary mechanism in the form of a failure mode connection database that stores predefined relationships between component failure modes. This intermediary allows automatic matching and connection of failure modes across system boundaries without requiring manual analysis, thereby increasing automation while reducing the time required for safety case construction.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If component-based models are used for safety evaluation, then reuse and modular composition are enabled, but automatic construction of system-level safety cases is not supported

Engineering Contradiction:
Improvereusability of safety analysis modelsVSAvoidautomatic construction of system-level safety cases
Core Design Contradiction:
Adaptability or versatilityVSExtent of automation

Solution Approach 1:

The patent applies universality by creating a standardized failure mode interface model that can be universally applied across different components and systems. The component fault tree structure with defined input/output failure modes serves as a universal building block that can be reused and automatically composed to construct system-level safety cases, thus enabling both reusability and automatic construction simultaneously.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent applies segmentation by dividing the safety analysis into modular component fault trees, each representing a discrete component with clearly defined failure modes. These segmented components can be independently analyzed and then automatically recombined to form complete system-level safety cases, enabling both modular reusability and automatic system-level construction.

Inventive Principle:
Principle #1Segmentation

3Reliability

If safety analysis is performed during development stage, then safety requirements can be checked, but runtime safety assessment is not supported

Engineering Contradiction:
Improvesafety requirement verificationVSAvoidtiming of safety assessment
Core Design Contradiction:
ReliabilityVSDuration of action of moving object

Solution Approach 1:

The patent applies preliminary action by performing safety analysis model preparation during the development stage, creating component fault trees with standardized failure mode definitions. These pre-prepared models can then be automatically instantiated and executed at runtime to support real-time safety assessment, thus maintaining reliability verification while extending capability to runtime operation.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10241852B2Automated qualification of a safety critical system
Publication Date: 2019.03.26 SIEMENS AG
  • US10241852B2 patent drawing
  • US10241852B2 patent drawing
  • US10241852B2 patent drawing

AI summary

A method for automated qualification of a safety critical system including a plurality of components is provided. A functional safety behavior of each component is represented by an associated component fault tree element. The method includes automatically performing a failure port mapping of output failure modes to input failure modes of component fault tree elements based on a predetermined generic fault type data model stored in a database.