中国安全科学学报 ›› 2026, Vol. 36 ›› Issue (4): 103-113.doi: 10.16265/j.cnki.issn1003-3033.2026.04.0636

• 安全技术与工程 • 上一篇    下一篇

基于STPA-MBSA的航空发动机反推系统安全性分析

肖国松1,2(), 唐昊3, 董磊1,2, 白杰1,2,**()   

  1. 1 中国民航大学 民航航空器适航审定技术重点实验室, 天津 300300
    2 中国民航大学 科技创新研究院, 天津 300300
    3 中国民航大学 安全科学与工程学院, 天津 300300
  • 收稿日期:2025-11-07 修回日期:2026-02-04 出版日期:2026-04-28
  • 通信作者:
    **白 杰(1963—),男,辽宁西丰人,硕士,教授,主要从事航空发动机使用可靠性及故障诊断、运输类飞机适航要求与符合性验证技术等研究。E-mail:
  • 作者简介:

    肖国松 (1982—),男,湖南衡阳人,硕士,实验师,主要从事航空器适航审定技术、航空发动机故障诊断及预测等方面的研究。E-mail:

    董磊, 副研究员

Safety analysis of aero-engine thrust reverser system based on STPA-MBSA

Xiao Guosong1,2(), Tang Hao3, Dong Lei1,2, Bai Jie1,2,**()   

  1. 1 Key Laboratory of Civil Aircraft Airworthiness Technology, Civil Aviation University of China, Tianjin 300300, China
    2 Science and Technology Innovation Research Institute, Civil Aviation University of China, Tianjin 300300, China
    3 College of Safety Science and Engineering, Civil Aviation University of China, Tianjin 300300, China
  • Received:2025-11-07 Revised:2026-02-04 Published:2026-04-28

摘要:

针对航空发动机反推系统(TRS)的传统安全性分析方法在应对多层级耦合和多系统交联时存在系统交互和需求-设计闭环的局限,提出系统理论过程分析(STPA)与基于模型的安全性分析(MBSA)融合方法。通过构建从系统需求捕获到验证的全流程分析框架,采用系统建模语言(SysML)构建多视图系统模型揭示架构原理,结合STPA方法定义4类系统级损失(事故)和8类系统级危险,构建TRS反馈控制结构模型,识别11种不安全控制行为(UCAs)并得出致因场景,给出相应安全性等级,基于模型检验工具(NuSMV)构建名义模型与故障模型,并验证系统关键安全属性。结果表明:模型具有逻辑的完整性和正确性,反推空中非指令打开发生概率为1.95×10-10/FH,满足小于10-9/FH的安全性要求。

关键词: 航空发动机, 系统理论过程分析(STPA), 基于模型的安全性分析(MBSA), 反推系统(TRS), 安全性分析, 系统建模语言(SysML)

Abstract:

TRS is a safety-critical aero-engine system. In response to the inadequacies of conventional safety analysis techniques in addressing the complexities associated with multilevel coupling and cross-linking of multiple systems concerning system interaction and closed-loop design specifications, this study proposes a method that integrates STPA and MBSA. By establishing a whole-process analysis framework from system requirement capture to verification, an overall system model was constructed through the use of SysML to reveal the architectural principles. The STPA method was employed to define 4 types of system-level losses (accidents) and 8 types of system-level hazards, construct a TRS feedback control structure model, identify 11 unsafe control actions (UCAs), derive causal scenarios, and assign respective safety levels. Using the model checking tool new symbolic model verifier (NuSMV), fault and nominal models were constructed to verify critical system safety properties. The results demonstrate that the proposed model possesses logical integrity and correctness, and indicate that the probability of "Thrust Reverser Non-Command Open in Air," as determined from minimal cut set, is 1.95×10-10 per flight hour, thereby meeting the safety requirement of a failure probability of less than 10-9 per flight hour.

Key words: aero-engine, systems-theoretic process analysis(STPA), model based safety analysis(MBSA), thrust reverser system(TRS), safety analysis, systems modeling language(SysML)

中图分类号: