Safety Goal Violation Analysis With Fault Tree-Bayesian Integration
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for evaluating safety goals in automated driving systems are limited by boolean algebra in Fault Tree Analysis and do not account for the influence of environmental conditions, necessitating a more comprehensive approach to quantify safety goal violations.
Innovation Solution
Combining Fault Tree Analysis with Bayesian Networks to model both electrical/electronic faults and environmental influences, allowing for a quantitative evaluation of safety goal violations by integrating environmental conditions into the Fault Tree through an interface with Bayesian networks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If Fault Tree_analysis is used for safety evaluation, then electrical and electronic faults can be analyzed systematically, but the method is limited to boolean algebra and cannot account for environmental conditions
Solution Approach 1:
The patent combines Fault Tree Analysis (FTA) with Bayesian Networks (BN) into a hybrid evaluation system. The FTA handles electrical and electronic faults using boolean algebra, while the BN models environmental conditions and their probabilistic relationships. The two methods are merged through an interface that allows probabilistic values from the BN to be propagated to the FTA, enabling comprehensive safety evaluation that includes both fault types.
Solution Approach 2:
The patent introduces an interface as an intermediary component between the Fault Tree and Bayesian Network. This interface receives probabilistic outputs from the Bayesian Network regarding environmental conditions and transmits them to the Fault Tree analysis. The intermediary enables data exchange and integration between the two different analytical frameworks without requiring direct modification of either method's core structure.
2Adaptability or versatility
If Bayesian Networks are used to model environmental conditions, then detailed statistical relationships can be captured, but the method cannot directly evaluate safety goal violations in the functional safety context
Solution Approach 1:
The interface acts as an intermediary that translates Bayesian Network outputs into a format compatible with Fault Tree Analysis and functional safety standards. It converts the probabilistic environmental condition data from the BN into propagated probabilities that can be integrated into the FTA safety evaluation framework, ensuring alignment with functional safety requirements.
Solution Approach 2:
The hybrid system achieves universality by making the safety evaluation framework capable of handling multiple types of inputs and conditions. The FTA component addresses electrical/electronic faults while the BN component addresses environmental conditions, and together they provide a unified safety evaluation that covers both functional safety (ISO 26262) and SOTIF (ISO 21448) requirements.
3Measurement precision
If a comprehensive safety evaluation including environmental conditions is performed, then a more accurate safety assessment is achieved, but the system complexity increases
Solution Approach 1:
The patent segments the safety evaluation system into distinct functional modules: the Fault Tree Analysis module for electrical/electronic faults, the Bayesian Network module for environmental conditions, and the interface module for integration. This segmentation allows each module to specialize in its specific function while maintaining overall system manageability and reducing complexity through modular design.
Data Source
AI summary
A method for determining a probability of a violation of safety goals of a technical system. The method includes: providing a violated safety goal; deriving a Fault Tree top-down from the violated safety goal to an event; in case of electrical and/or electronic fault(s) of a component outputting a propagated probability of respective components or events; in case of an environmental influence on a component's performance, defining an interface to a Bayesian network; defining and causally connecting nodes of environmental conditions in the Bayesian network; providing quantification input on conditional dependencies into the Bayesian network; providing, by the Bayesian network, a quantification on the environmental condition influence on the component's behavior to the interface or to the Fault Tree; outputting the probability of a violation of a safety goal.


