I. Introduction
The traditional safety assessment process based on MIL-STD-882E [1], ARP 4754A/4761 [2], [3] has been widely used in aviation, aerospace, automotive and medical industries. In last two decades, the development of computer science and IC manufacture process promoted the deep integration of mechanical and electrical systems, and sharp increased system complexity. Moreover, the embedded software control style gradually replaced the traditional mechanical control, which makes the system indigestion. Traditinal safety assessment methods which rely heavily on experience have some problems such as the weakness of describe ability, inaccurate result and poor iteration.