Component Fault Tree Integration for Early Safety Inconsistency Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current safety analysis methods for complex safety-critical systems face challenges in early identification of safety drawbacks and integration of information from existing systems when reusing components, leading to increased development costs and risks due to the lack of precise safety information and manual handling of component interactions.

Innovation Solution

A method and apparatus that automate the adaptation and integration of safety analysis models by using component fault trees to identify and address inconsistencies in failure modes, enabling the reuse of safety analysis models and transferring knowledge between different system contexts through a repository, facilitating forward and backward maturation of safety analysis models.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If safety analysis models are manually constructed and adapted for each system component, then precision of safety information is improved, but time consumption and development costs increase significantly

Engineering Contradiction:
Improveprecision of safety informationVSAvoidtime consumption for safety analysis
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent creates templates for safety analysis models that can be copied and reused across different system components. These templates capture standardized safety analysis patterns, allowing teams to replicate proven safety approaches without manually constructing models from scratch, thereby maintaining precision while reducing time consumption.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent performs safety analysis model construction and validation in advance during the development phase. By preparing safety analysis templates and models beforehand, the system enables rapid deployment and reuse in subsequent projects, eliminating the need for time-consuming manual construction during critical later stages.

Inventive Principle:
Principle #10Preliminary action

2Productivity

If safety analysis is performed late in the development process, then system functionality is more complete, but the impact on time and costs increases

Engineering Contradiction:
Improvesystem functionality completenessVSAvoiddevelopment time and cost impact
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The patent implements safety analysis model templates and methodologies during the early development phases, enabling safety considerations to be integrated before full system functionality is implemented. This preliminary safety planning allows for early identification of safety requirements without compromising the eventual completeness of system functionality.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent divides safety analysis into modular, independent components that can be developed and validated separately from the overall system functionality. This segmentation allows safety analysis to proceed in parallel with functionality development, reducing the time impact while maintaining both safety precision and functionality completeness.

Inventive Principle:
Principle #1Segmentation

3Adaptability or versatility

If component-based models are used for safety assessment, then reusability and modular composition are improved, but automatic construction of safety cases on system level is not supported

Engineering Contradiction:
Improvereusability of safety analysis modelsVSAvoidautomatic construction of safety cases
Core Design Contradiction:
Adaptability or versatilityVSExtent of automation

Solution Approach 1:

The patent implements feedback mechanisms that automatically aggregate safety analysis results from individual component models to generate system-level safety cases. The system collects safety data from reused component models, validates consistency, and automatically synthesizes comprehensive safety assessments, enabling both reusability and automation at the system level.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent merges individual component safety analysis models into a unified system-level safety case through automated composition. By combining modular component models with standardized integration rules, the system achieves automatic construction of comprehensive safety cases while preserving the reusability and modularity of individual component analyses.

Inventive Principle:
Principle #5Merging (Combining)

4Difficulty of detecting and measuring

If brainstorm techniques such as preliminary hazard analysis are used, then identification of hazards at the beginning is improved, but evaluation of different realization options is not enabled

Engineering Contradiction:
Improveidentification of hazardsVSAvoidevaluation of different realization options
Core Design Contradiction:
Difficulty of detecting and measuringVSAdaptability or versatility

Solution Approach 1:

The patent employs dynamic safety analysis models that can adapt and evaluate different system configurations and realization options. Unlike static brainstorming techniques, these models can simulate various design alternatives, assess their safety implications, and provide comparative evaluations, enabling both hazard identification and option assessment in an integrated manner.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentEP3249484B1Method and apparatus for providing a safe operation of a technical system
Publication Date: 2021.09.01 SIEMENS AG
  • EP3249484B1 patent drawingFigure 1~2
  • EP3249484B1 patent drawingFigure 3~4
  • EP3249484B1 patent drawingFigure 5

AI summary

The present invention relates generally to a method and an apparatus for providing a safe operation of a technical system comprising a plurality of system components. Said method comprising the steps of: a) providing a safety analysis model (CFTc, CFTd, CFTu) matured by knowledge about former implementations of the respective system components in different context, b) whereby system components' dependencies are modelled by connecting inports (i1) with outports (o1) of the respective system components and/or vice versa, c) whereby at least one or a plurality of such in and/or outports are associated with input failure modes and/or output failure modes, d) characterized in automatically uncovering inconsistencies caused by at least one system component to be integrated in connection with at least another system component whereby the input and/or output failure mode of said system component carries the knowledge from another implementation into said context.