Fault Tree Generation for Complex System Safety Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional safety analysis methods fail to decompose safety critical systems into different layers and domains, limiting their ability to perform comprehensive safety assessments, especially in complex cyberphysical systems with numerous hardware and software components.

Innovation Solution

A method and apparatus for generating a fault tree that links components based on failure dependencies, allowing for the integration of output failure modes from one component into another via OR-gates, enabling the creation of a fault tree that spans multiple layers and domains, and applying Boolean logic to reduce the fault tree for specific failure modes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If conventional safety analysis methods are used, then the analysis process is simple, but the ability to decompose systems into different layers and domains is lost

Engineering Contradiction:
Improveanalysis model structureVSAvoidlayered decomposition capability
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The patent divides the safety analysis model into multiple layers (functional layer, physical layer) and domains (hardware, software, communication). Each layer can be independently analyzed and then integrated through the fault tree structure, enabling comprehensive multi-layered safety assessment while maintaining manageable complexity through systematic segmentation

Inventive Principle:
Principle #1Segmentation

2Productivity

If components are reused during development, then development time is saved, but existing safety analysis models become invalid and require adaption

Engineering Contradiction:
Improvedevelopment speedVSAvoidsafety model validity
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent performs preliminary safety analysis on individual components before system integration. Component-level fault trees are created in advance and can be reused across different system configurations. When components are reused, their pre-analyzed fault trees are automatically integrated into the new system context, maintaining safety model validity while enabling rapid development through component reuse

Inventive Principle:
Principle #10Preliminary action

3Reliability

If a unified safety analysis model is created for the entire system, then comprehensive coverage is achieved, but the complexity of analysis and certification increases

Engineering Contradiction:
Improvesafety analysis completenessVSAvoidmodel maintenance difficulty
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The fault tree is segmented into modular components where each subsystem has its own fault tree that can be independently developed, analyzed, and certified. These modular fault trees are then integrated through standardized interfaces to form the complete system fault tree, achieving comprehensive safety coverage while reducing overall model complexity through systematic modularity

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates a universal fault tree framework that can analyze multiple layers (functional, physical) and domains (hardware, software, communication) using a common structure and methodology. This multi-functional approach achieves comprehensive safety analysis across all system aspects while maintaining consistent analysis procedures that simplify certification processes

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10877471B2Method and apparatus for generating a fault tree for a failure mode of a complex system
Publication Date: 2020.12.29 SIEMENS AG
  • US10877471B2 patent drawing
  • US10877471B2 patent drawing
  • US10877471B2 patent drawing

AI summary

A method and apparatus for generating a fault tree for a failure mode of a complex system including a plurality of components, the method includes the steps of providing component fault tree, CFT, elements of the components; linking the components according to their failure dependencies within the complex system; and generating the fault tree by incorporating for each dependency link from a first component to a second component the output failure modes of the component fault tree element of the second component into the component fault tree element of the first component to trigger the output failure modes of the first component.