China Safety Science Journal ›› 2026, Vol. 36 ›› Issue (4): 103-113.doi: 10.16265/j.cnki.issn1003-3033.2026.04.0636

• Safety Technology and Engineering • Previous Articles     Next Articles

Safety analysis of aero-engine thrust reverser system based on STPA-MBSA

Xiao Guosong1,2(), Tang Hao3, Dong Lei1,2, Bai Jie1,2,**()   

  1. 1 Key Laboratory of Civil Aircraft Airworthiness Technology, Civil Aviation University of China, Tianjin 300300, China
    2 Science and Technology Innovation Research Institute, Civil Aviation University of China, Tianjin 300300, China
    3 College of Safety Science and Engineering, Civil Aviation University of China, Tianjin 300300, China
  • Received:2025-11-07 Revised:2026-02-04 Online:2026-04-28 Published:2026-10-28
  • Contact: Bai Jie

Abstract:

TRS is a safety-critical aero-engine system. In response to the inadequacies of conventional safety analysis techniques in addressing the complexities associated with multilevel coupling and cross-linking of multiple systems concerning system interaction and closed-loop design specifications, this study proposes a method that integrates STPA and MBSA. By establishing a whole-process analysis framework from system requirement capture to verification, an overall system model was constructed through the use of SysML to reveal the architectural principles. The STPA method was employed to define 4 types of system-level losses (accidents) and 8 types of system-level hazards, construct a TRS feedback control structure model, identify 11 unsafe control actions (UCAs), derive causal scenarios, and assign respective safety levels. Using the model checking tool new symbolic model verifier (NuSMV), fault and nominal models were constructed to verify critical system safety properties. The results demonstrate that the proposed model possesses logical integrity and correctness, and indicate that the probability of "Thrust Reverser Non-Command Open in Air," as determined from minimal cut set, is 1.95×10-10 per flight hour, thereby meeting the safety requirement of a failure probability of less than 10-9 per flight hour.

Key words: aero-engine, systems-theoretic process analysis(STPA), model based safety analysis(MBSA), thrust reverser system(TRS), safety analysis, systems modeling language(SysML)

CLC Number: