STPA State-Machine Modeling for Accurate Loss Scenario Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing STPA method faces challenges in accurately and efficiently identifying loss scenarios in complex systems due to issues with modeling hierarchical system control structures, manual loss scenario identification, and incorrect UCA concepts, leading to inaccurate and inefficient safety analysis.

Innovation Solution

An STPA method and device that utilize system state machines and model checking techniques to identify unsafe control actions and loss scenarios, incorporating controller, controlled process, and actuator behaviors, and using SysML, AADL, or AltaRica for modeling, and NuSMV or UPPAAL for model checking.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If manual methods are used to identify loss scenarios in STPA, then the analysis can be performed with simple tools, but the identification accuracy and completeness deteriorate due to human error and inefficiency

Engineering Contradiction:
Improveloss scenario identification accuracyVSAvoidanalysis method complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent replaces manual mechanical analysis methods with automated model checking technology. The state machine model automatically verifies safety properties and identifies loss scenarios through formal verification, eliminating human error and subjectivity while maintaining analytical rigor. This substitution transforms the analysis from a manual process to an automated computational process.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system performs self-verification through model checking, where the state machine model automatically checks its own safety properties without external intervention. The automated analysis engine independently identifies loss scenarios by evaluating system states and transitions, making the analysis process self-sufficient and reducing reliance on manual expert review.

Inventive Principle:
Principle #25Self-service

2Adaptability or versatility

If traditional event chain analysis is used, then the analysis method is simple and familiar, but it fails to capture emergent hazards in complex systems

Engineering Contradiction:
Improvecapability to identify emergent hazardsVSAvoidcontrol structure modeling complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent uses dynamic state machine models that capture the evolving behavior of complex systems over time. Unlike static event chain analysis, the state machine approach models system dynamics, state transitions, and temporal relationships, enabling the identification of emergent hazards that arise from complex interactions and feedback loops in the system.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system decomposes complex system behavior into discrete states and transitions, allowing detailed analysis of individual system components and their interactions. This segmentation enables the model to capture local behaviors and emergent properties that arise from component interactions, which cannot be detected through traditional holistic event chain analysis.

Inventive Principle:
Principle #1Segmentation

3Productivity

If automated model checking is implemented, then loss scenario identification efficiency improves, but the learning curve and implementation difficulty increase

Engineering Contradiction:
Improveloss scenario identification efficiencyVSAvoidmethod implementation ease
Core Design Contradiction:
ProductivityVSEase of operation

Solution Approach 1:

The patent performs preliminary system modeling using state machines before conducting model checking analysis. By establishing the system model, states, and transitions in advance, the automated analysis can efficiently verify safety properties without requiring complex real-time computations. This preliminary structuring simplifies the subsequent automated analysis process.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The state machine model serves as an intermediary between the complex system being analyzed and the model checking tool. This intermediate representation simplifies the system description while preserving essential safety-critical behaviors, making the system amenable to automated verification without requiring direct complex system access or interpretation.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12449798B2STPA method and device for accurate identification of loss scenarios
Publication Date: 2025.10.21 BEIHANG UNIV
  • US12449798B2 patent drawing
  • US12449798B2 patent drawing
  • US12449798B2 patent drawing

AI summary

The present invention provides an STPA method and apparatus for accurate identification of a loss scenario. The method comprises: defining the purpose of the analysis, comprising identifying of a loss; modeling a system state machine using a finite state machine; identifying an unsafe control action using the identified loss and the modeled system state machine. The method according to the present invention achieves accurate and efficient identification of loss scenarios of a complex system using state machines and model checking techniques.