There are different kinds of safety analyses classification, including failure analysis, which is crucial in identifying potential failure modes in a system before they manifest. One of them is to divide them between quantitative methods (predict the frequency of failures) and qualitative methods (identify failures but do not predict the frequency of failures). Examples are:

تشمل أساليب التحليل النوعي: 

— تحليل نوعي لأنماط الفشل وآثاره (FMEA) على مستوى النظام أو التصميم أو العملية؛ 

— تحليل شجرة الأعطال النوعي (FTA)؛  

— تحليل المخاطر وقابلية التشغيل (HAZOP)؛  

— تحليل شجرة الأحداث النوعي (ETA). 

تشمل أساليب التحليل الكمي: 

— تحليل كمي لأوضاع الفشل وتأثيراتها (FMEA)؛ 

— تحليل كمي لشجرة الأعطال (FTA)؛  

— تحليل كمي لشجرة الأحداث (ETA)؛ 

— نماذج ماركوف؛ 

— مخططات الكتلة الخاصة بالموثوقية. 

ما هو FMEA ولماذا هو مهم؟ 

FMEA هو أحد أشهر التحليلات الاستقرائية المستخدمة في قطاع السيارات.

FMEA is a step-by-step approach for identifying all possible failures in a design, a manufacturing or assembly process, or a product or service. Failure detection is a critical component in assessing the effectiveness of risk management strategies within FMEA. The most important outcomes are understanding how failure happens and taking proactive measures to prevent these failures:

– تحديد مخاطر جديدة لم تُحدد سابقاً خلال تحليل المخاطر وتقييمها (HARA)؛

– أدلة على ملاءمة مفاهيم السلامة؛

– تحديد تدابير السلامة لمنع الأعطال أو التحكم فيها؛

– تحديد متطلبات التصميم ومتطلبات الاختبار.

There are different types of FMEA. The main 2 groups are: Design and Process FMEA. The main goal of Design FMEA (DFMEA) is to perform failure mode analysis to uncover potential failures associated with the product design – product malfunctions, shortened life etc. On the other hand the main objective of Process FMEA (PFMEA) is to uncover failures related to process reliability, impact product quality, etc.

يقيّم تحليل أنماط الفشل الوظيفي (FMEA) وظائف النظام قبل وضع التصميم النهائي، مما يتيح اتباع نهج منظم لتحديد أنماط الفشل المحتملة بناءً على المتطلبات الوظيفية.

There are several trusted publications describing the approach to the Design and Process FMEA like: Failure Mode and Effect Analysis Handbook (issued by AIAG & VDA) or Design & Process FMEA (issued by SAE).

ما مدى أهمية تحليل سلامة البرمجيات؟ 

أفضل توضيح لدور التحليلات الموجهة لسلامة البرمجيات يمكن العثور عليه في الملحق E من الجزء 9 من ISO26262:2018 (الطبعة الثانية):

FMEA analysis what it is and why it’s important

The best time for safety analysis as per the diagram above is SW Architectural Design. It can be done using deductive or inductive analyses. One of the most efficient solutions for inductive analysis is SW FMEA. The best if it is supported by a deductive approach like SW FTA along with DFA.

يُعد تحليل عملية التصنيع أمراً بالغ الأهمية في تحديد الأعطال المحتملة خلال مرحلتي التصميم والتصنيع للمنتج.

When it comes to the SW FMEA availability of standards/guidelines is very low and it is not easy to verify the sources of publications. One of them is “Effective Application of SW Failure Modes Effect Analysis” by Ann Marie Neufelder.

This is a very complex approach containing a lot of different approaches, methods and steps. Especially for the companies which are at the beginning of ISO26262 journey, it might be very difficult to adapt it to their technology and processes without extensive support and time.

مهندسو Spyrosoft FUSA عبر مختلف ISO26262 projects were able to develop their own approach to SW FMEA. It is continuously evolving to adapt new technologies and lessons learnt. It is also worth to add that SpyroSoft safety analyses reports based on the SW FMEA already passed several FUSA Assessments.

عمّق معرفتك بمعيار ISO 26262. حمّل دليلنا.

احصل على الدليل

ما هي خطوات SW FMEA؟

 النهج العام لـ SW FMEA مشابه لنهج Design FMEA (AIAG & VDA). وقد يتم تنظيم أعمدة ورقة تحليل السلامة الخاصة بـ SW FMEA على النحو التالي:

تتضمن الخطوة الأولى من تحليل أنماط الفشل وتأثيراتها للبرمجيات (SW FMEA) أربع خطوات كما هو موضح في مخطط سير العمل أدناه:   

FMEA analysis what it is and why it’s important

HAZOP (Hazard and Operability Study) – systematically investigates each element in an Architecture or any other model/system/process. The goal is to find potential situations that would cause that element to pose a hazard or limit its operability. In this approach key words like “NO or NOT”, “PART OF” etc. help in defining potential failures in function/element.  

Each Potential Failure Cause shall contain Occurrence (O) rating. It describes the potential of the failure cause to occur in customer operation, according to the rating table, considering results of already completed detection controls. 

ما الفرق بين تحليلات السلامة النوعية والكمية؟ 

  • آثار الفشل المحتملة التي قد تنتهك هدف السلامة مباشرةً 
  • آثار الفشل المحتملة التي قد تؤثر على النظام/النظام الفرعي، أو الكيانات المحلية، أو تؤدي إلى عدم الامتثال للوائح، أو ضعف الأداء، أو فقدان الوظائف المقصودة، وغير ذلك. 

يجب تقييم كل تأثير باستخدام مقياس الخطورة (S). وهو مرتبط بأخطر تأثير فشل لوضع فشل معين على الوظيفة قيد التقييم. 

Each prevention/detection control shall be rated using Detection (D) measure. It is an estimated measure of the effectiveness of the detection control to reliably demonstrate the failure cause or failure mode before the item is released for production. 

  • الخطوة الثانية من تحليل SW FMEA هي تقييم المخاطر، والتحقق من FMEA SW وتحسينه
  • يجب أن تكون نقطة الاتصال الأولى مهندس البرمجيات المعماري المسؤول عن تنفيذ SMs ضمن البنية المعمارية للبرمجيات وملء عمود "تنفيذ SM" 
  • يُدار عمود "تغطية المتطلبات" بواسطة مهندس المتطلبات (Req Eng.). ويجب أن يحتوي على متطلبات السلامة البرمجية الموجودة بالفعل أو متطلبات جديدة تماماً مستمدة مباشرة من تحليل أنماط الفشل وتأثيراتها للبرمجيات (SW FMEA). 
  • يجب ملء عمود „Test Coverage” بمعرفات حالات الاختبار (على مستوى Unit أو Integration) المصممة للتحقق من السلوك الصحيح لآليات السلامة أثناء بدء التشغيل/التشغيل العادي. 

 لا تنسَ تقرير التحقق من تحليل السلامة المناسب المطلوب بموجب ISO26262.  

It shall summarise and communicate the results of the SW FMEA activity, confirmation of the effectiveness of the implemented actions, record of risk analysis and risk reduction to acceptable level. 

ما هي الإرشادات وأفضل الممارسات لتنفيذ تحليل SW FMEA بشكل جيد؟ 

  • Static View: the FUSA critical components shall be clearly marked. The critical signal path shall be shown from the HW peripherals through MCAL, ECUAL, BSW up to Application Layer (in AUTOSAR projects). Based on such diagram FUSA critical components (also QM ones if they are on the way of critical path) shall be taken into consideration for SW FMEA.  
  • العرض الديناميكي: حيث يمكن تحديد أعطال مثل: تأخر البيانات المرسلة، وحجب الوصول إلى قناة الاتصال، وتلف الذاكرة. 

إذا كنت تواجه صعوبة في تحليل أنماط الفشل وأثره على البرمجيات أو أي تحليلات أخرى لسلامة الأنظمة/البرمجيات – فيرجى زيارة موقعنا الإلكتروني لمزيد من المعلومات 

يمكنك حجز تدريب حضوري أو عبر الإنترنت لك ولفريقك للتعرف على الأساسيات والعمليات بناءً على دراسات حالة وأمثلة عملية جيدة التنظيم وتمارين تطبيقية.

Qualitative analyses identify potential failure modes without predicting how often they might occur, focusing instead on understanding system vulnerabilities. Quantitative analyses, on the other hand, use numerical data to estimate the likelihood or frequency of failures. Both approaches complement each other to create a complete picture of system reliability and safety.

FMEA (Failure Modes and Effects Analysis) helps engineers identify and evaluate potential failures in design, manufacturing, or processes before they cause real-world issues. It supports proactive risk management by defining safety measures, design requirements, and preventive actions. This method is essential for improving system reliability and ensuring compliance with safety standards like ISO 26262.

Design FMEA (DFMEA) focuses on potential failures in the product’s design that could lead to malfunctions or reduced lifespan. Process FMEA (PFMEA) examines failures that could arise during manufacturing or assembly, affecting product quality or reliability. Both approaches aim to identify risks early and implement effective countermeasures.

A good SW FMEA starts with a clear understanding of system architecture, marking safety-critical components and signal paths. It should combine both static and dynamic views to identify risks such as communication delays or memory corruption. Collaboration between software architects, requirements engineers, and testers is key to ensuring comprehensive analysis and effective safety validation.