IP Library › Granted Patent US 12,735,198
Granted Patent B1
US 12,735,198 · App. 18/672,257 · Granted Sep 15, 2026

Extension of SysML for functional hazard analysis

Inventors: Alyssa Niquette (Rocky Hill, CT); Charles J. Nobilski (Vernon, CT)
Assignee: RTX CORPORATION
B64F5/60
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,735,198
App. No.
18/672,257
Granted
Sep 15, 2026
Kind
B1
Abstract

A method is disclosed of using Systems Modeling Language (SysML) for a hazard analysis description that describes a potential functional failure of a physical system. The method includes describing the potential functional failure of the physical system in SysML using a first type of custom SysML element; and describing at least one potential cause and at least one potential effect of the potential functional failure with respective instances of a second type of custom SysML element, wherein the first type of custom SysML element has a different SysML metaclass than the second type of custom SysML element. A method of using SysML for a hazard analysis description and a system for using SysML for a hazard analysis description are also disclosed.

Claims (57)

1 . A method of using Systems Modeling Language (SysML) for a hazard analysis description that describes a potential functional failure of a physical system, comprising:

describing the potential functional failure of the physical system in SysML using a first type of custom SysML element;

describing at least one potential cause and at least one potential effect of the potential functional failure with respective instances of a second type of custom SysML element; and

linking the at least one cause and the at least one effect to the potential functional failure using respective instances of a third type of custom SysML element that represents causation;

wherein the first type of custom SysML element has a different SysML metaclass than the second type of custom SysML element.

2 . The method of claim 1 , wherein the third type of custom SysML element has a different SysML metaclass than the first type of custom SysML element and the second type of custom SysML element.

3 . The method of claim 2 , wherein:

the metaclass of the first type of custom SysML element is class;

the metaclass of the second type of custom SysML element is activity; and

the metaclass of the third type of custom SysML element is dependency.

4 . The method of claim 2 , comprising:

describing in SysML each of one or mitigations that can be implemented to mitigate an effect or likelihood of the potential functional failure; and

linking each of the one or more mitigations to the potential functional failure using a respective fourth type of custom SysML element.

5 . The method of claim 4 , wherein:

the fourth type of custom SysML element and the third type of SysML element have a same SysML metaclass.

6 . The method of claim 4 , wherein each of the mitigations is described using one or more native, non-custom SysML element types.

7 . The method of claim 4 , comprising:

describing a potential system level effect of the potential functional failure using a fifth type of custom SysML element;

wherein the potential system level effect is linked to and is a higher level effect than a particular one of the at least one potential effects; and

wherein the potential system level effect is linked to the particular one of the at least one potential effects using an instance of the third type of custom SysML element.

8 . A method of using Systems Modeling Language (SysML) for a hazard analysis description that describes a potential functional failure of a physical system, comprising:

describing the potential functional failure of the physical system in SysML using a first type of SysML element; and

describing at least one potential cause and at least one potential effect of the potential functional failure with respective instances of a second type of SysML element; and

linking the at least one cause and the at least one effect to the potential functional failure using respective instances of a third type of SysML element that represents causation; wherein the first type of SysML element has a different SysML metaclass than the second type of SysML element; and

wherein the third type of SysML element has a different SysML metaclass than the first type of SysML element and the second type of SysML element.

9 . The method of claim 8 , wherein:

the metaclass of the first type of SysML element is class;

the metaclass of the second type of SysML element is activity; and

the metaclass of the third type of SysML element is dependency.

10 . The method of claim 8 , comprising:

describing in SysML each of one or mitigations that can be implemented to mitigate an effect or likelihood of the potential functional failure; and

linking each of the one or more mitigations to the potential functional failure using a respective fourth type of SysML element.

11 . The method of claim 10 , wherein:

the fourth type of SysML element and the third type of SysML element have a same SysML metaclass.

12 . The method of claim 10 , comprising:

describing a potential system level effect of the potential functional failure using a fifth type of SysML element;

wherein the potential system level effect is linked to and is a higher level effect than a particular one of the at least one potential effects; and

wherein the potential system level effect is linked to the particular one of the at least one potential effects using an instance of the third type of SysML element.

13 . A system for using Systems Modeling Language (SysML) for a hazard analysis description that describes a potential functional failure of a physical system, comprising:

processing circuitry operatively connected to memory and configured to:

describe the potential functional failure of the physical system in SysML using a first type of custom SysML element; and

describe at least one potential cause and at least one potential effect of the potential functional failure with respective instances of a second type of custom SysML element; and

link the at least one cause and the at least one effect to the potential functional failure using respective instances of a third type of custom SysML element that represents causation;

wherein the first type of custom SysML element has a different SysML metaclass than the second type of custom SysML element.

14 . The system of claim 13 , wherein the third type of custom SysML element has a different SysML metaclass than the first type of custom SysML element and the second type of custom SysML element.

15 . The system of claim 14 , wherein:

the metaclass of the first type of custom SysML element is class;

the metaclass of the second type of custom SysML element is activity; and

the metaclass of the third type of custom SysML element is dependency.

16 . The system of claim 14 , wherein the processing circuitry is configured to:

describe in SysML each of one or mitigations that can be implemented to mitigate an effect or likelihood of the potential functional failure; and

link each of the one or more mitigations to the potential functional failure using a respective fourth type of custom SysML element;

wherein the fourth type of custom SysML element and the third type of SysML element have a same SysML metaclass.

17 . The system of claim 16 , wherein:

the processing circuitry is configured to describe a potential system level effect of the potential functional failure using a fifth type of custom SysML element;

the potential system level effect is linked to and is a higher level effect than a particular one of the at least one potential effects; and

the potential system level effect is linked to the particular one of the at least one potential effects using an instance of the third type of custom SysML element.

Continuity (1)
Continuation 18495332 · Oct 26, 2023
References Cited (33)
US 10423884B2 · Hyde et al. · 2019 [cited by applicant]
US 11347919B2 · Heilmann et al. · 2022 [cited by applicant]
US 20090144599A1 · Leblond · 2009 [cited by examiner]
US 20090172632A1 · Kashai · 2009 [cited by examiner]
US 20110191089A1 · Votintseva · 2011 [cited by examiner]
US 20120254710A1 · Flanagan · 2012 [cited by examiner]
US 20130013993A1 · Oh · 2013 [cited by examiner]
US 20150019187A1 · Jones · 2015 [cited by examiner]
US 20160357895A1 · Hyde · 2016 [cited by examiner]
US 20190108084A1 · Hipp · 2019 [cited by examiner]
US 20210049060A1 · Heilmann · 2021 [cited by examiner]
US 20220058323A1 · Heilmann · 2022 [cited by examiner]
US 20220066403A1 · Kaukewitsch · 2022 [cited by examiner]
US 20220230485A1 · Bajpai · 2022 [cited by examiner]
US 20220247678A1 · Atwal · 2022 [cited by examiner]
US 20220358612A1 · Heilmann · 2022 [cited by examiner]
US 20230028912A1 · Steingrimsson · 2023 [cited by examiner]
US 20230229439A1 · Huang · 2023 [cited by examiner]
US 20230305550A1 · Zhong · 2023 [cited by examiner]
US 20250200208A1 · Roper, Jr. · 2025 [cited by examiner]
US 20250217114A1 · Roper, Jr. · 2025 [cited by examiner]
CN 110765568A · 2020 [cited by examiner]
CN 111427556B · 2022 [cited by examiner]
CN 114218781 · 2022 [cited by applicant]
CN 114816431 · 2022 [cited by applicant]
CN 115688650 · 2023 [cited by applicant]
CN 115718803 · 2023 [cited by applicant]
CN 116483705 · 2023 [cited by applicant]
SAE: ARP 4761, Guidelines and Methods for Conducting the Safety Assessment Process on Civil Airborne Systems and Equipment, USA, (Year: 1996). [cited by examiner]
Mechatronics 21 (2011) 1063-1075 System-level model integration of design and simulation for mechatronic systems based on SysML Yue Cao a, Yusheng Liu a,b, , Christiaan J.J. Paredis b (Year: 2011). [cited by examiner]
FAA: AC 23.1309-1E, System Safety Analysis and Assessment for Part 23 Airplanes, USA, 2011 (Year: 2011). [cited by examiner]
2016 Annual IEEE Systems Conference (SysCon)The Hazard Analysis Profile: Linking Safety Analysis and SysML Martina Müller, Michael Roth, Udo Lindemann—Institute of Product Development DOI: 10.1109/SYSCON.2016.7490532, E… [cited by examiner]
Software and Systems Modeling (2020) 19:889-910—Special Section Paper Model-based safety assessment with SysML and component fault trees: application and lessons learned Peter Munk1 ⋅ Arne Nordmann1 (Year: 2020). [cited by examiner]