Deep dive ① · Analyze first
In Siemens MADe, the QX-250 started from failure physics, not geometry — a mission profile, a physics-of-failure model and a reliability block diagram that drove the redundant electrical architecture and two MIL-STD deliverables.
The analysis
A Mission Profile ("QX-250 Nominal Sortie," 7 phases over a 10.5-min sortie) accrues duty on every component. A physics-of-failure model captures each component's failure causes → mechanisms → modes — the causal basis of the FMECA. From it MADe generated a MIL-STD-1629A FMECA / Criticality (17 pp) and a MIL-STD-882E system-safety assessment (13 pp).
The decision that shaped the design
Swap in cheaper parts and mission reliability at 10.5 min falls from 0.9999676 to 0.9999463. Because the four rotors are irreducible single points, reliability was bought back on the electronics — dual battery and dual ESC as 1-of-2 Parallel Groups (battery MTTF 6000→9000 h, ESC 60000→90000 h) — restoring the system to 0.9999784 (MTTF 4673 h): cheaper parts, yet more reliable than the original. This is the decision that added the 2nd battery / 2nd flight controller / BMS to every downstream model — requirements, logical architecture, EBOM and MBOM.
Both are the actual MADe output, cover-branded for the QX-250 — click to read them in your browser (they open in a new tab; no download needed): View MIL-STD-1629A FMECA (PDF, 17 pp) ↗ · View MIL-STD-882E System Safety (PDF, 13 pp) ↗
Where this flows next. The redundancy decision becomes formal requirements (REL-003 derives REL-008/009), a redundant logical architecture, 2 batteries + 2 flight controllers in the EBOM, the dual-FC and OR-ing block wired in the Capital schematic, and finally positioned geometry in the NX physical mockup — the same decision, carried unbroken from failure physics to hardware.