Safety Goal Violation Analysis With Fault Tree-Bayesian Integration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for evaluating safety goals in automated driving systems are limited by boolean algebra in Fault Tree Analysis and do not account for the influence of environmental conditions, necessitating a more comprehensive approach to quantify safety goal violations.

Innovation Solution

Combining Fault Tree Analysis with Bayesian Networks to model both electrical/electronic faults and environmental influences, allowing for a quantitative evaluation of safety goal violations by integrating environmental conditions into the Fault Tree through an interface with Bayesian networks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If Fault Tree_analysis is used for safety evaluation, then electrical and electronic faults can be analyzed systematically, but the method is limited to boolean algebra and cannot account for environmental conditions

Engineering Contradiction:
Improvesafety evaluation completenessVSAvoidcapability to model environmental influences
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent combines Fault Tree Analysis (FTA) with Bayesian Networks (BN) into a hybrid evaluation system. The FTA handles electrical and electronic faults using boolean algebra, while the BN models environmental conditions and their probabilistic relationships. The two methods are merged through an interface that allows probabilistic values from the BN to be propagated to the FTA, enabling comprehensive safety evaluation that includes both fault types.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent introduces an interface as an intermediary component between the Fault Tree and Bayesian Network. This interface receives probabilistic outputs from the Bayesian Network regarding environmental conditions and transmits them to the Fault Tree analysis. The intermediary enables data exchange and integration between the two different analytical frameworks without requiring direct modification of either method's core structure.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If Bayesian Networks are used to model environmental conditions, then detailed statistical relationships can be captured, but the method cannot directly evaluate safety goal violations in the functional safety context

Engineering Contradiction:
Improvecapability to model environmental conditionsVSAvoidalignment with functional safety standards
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The interface acts as an intermediary that translates Bayesian Network outputs into a format compatible with Fault Tree Analysis and functional safety standards. It converts the probabilistic environmental condition data from the BN into propagated probabilities that can be integrated into the FTA safety evaluation framework, ensuring alignment with functional safety requirements.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The hybrid system achieves universality by making the safety evaluation framework capable of handling multiple types of inputs and conditions. The FTA component addresses electrical/electronic faults while the BN component addresses environmental conditions, and together they provide a unified safety evaluation that covers both functional safety (ISO 26262) and SOTIF (ISO 21448) requirements.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Measurement precision

If a comprehensive safety evaluation including environmental conditions is performed, then a more accurate safety assessment is achieved, but the system complexity increases

Engineering Contradiction:
Improvesafety probability quantification accuracyVSAvoidevaluation system structure
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the safety evaluation system into distinct functional modules: the Fault Tree Analysis module for electrical/electronic faults, the Bayesian Network module for environmental conditions, and the interface module for integration. This segmentation allows each module to specialize in its specific function while maintaining overall system manageability and reducing complexity through modular design.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS20250291981A1Method for determining a probability of a violation of safety goals
Publication Date: 2025.09.18 ROBERT BOSCH GMBH
  • US20250291981A1 patent drawing
  • US20250291981A1 patent drawing
  • US20250291981A1 patent drawing

AI summary

A method for determining a probability of a violation of safety goals of a technical system. The method includes: providing a violated safety goal; deriving a Fault Tree top-down from the violated safety goal to an event; in case of electrical and/or electronic fault(s) of a component outputting a propagated probability of respective components or events; in case of an environmental influence on a component's performance, defining an interface to a Bayesian network; defining and causally connecting nodes of environmental conditions in the Bayesian network; providing quantification input on conditional dependencies into the Bayesian network; providing, by the Bayesian network, a quantification on the environmental condition influence on the component's behavior to the interface or to the Fault Tree; outputting the probability of a violation of a safety goal.