Estimation of average hazardous-event-frequency for allocation of safety-integrity levels

被引:55
作者
Misumi, Y [1 ]
Sato, Y [1 ]
机构
[1] Tokyo Univ Mercantile Marine, Dept Elect & Mech Engn, Koto Ku, Tokyo 1358533, Japan
关键词
IEC61508; safety-integrity level; safety-related system; target failure measure; hazardous event frequency; mode of operation;
D O I
10.1016/S0951-8320(99)00030-7
中图分类号
T [工业技术];
学科分类号
08 ;
摘要
One of the fundamental concepts of the draft international standard, IEC 61508, is target failure measures to be allocated to Electric/Electronic/Programmable Electronic Safety-Related Systems, i.e. Safety Integrity Levels. The Safety Integrity Levels consist of four discrete probabilistic levels for specifying the safety integrity requirements or the safety functions to be allocated to Electric/Electronic/Programmable Electronic Safety-Related Systems. In order to select the Safety Integrity Levels the draft standard classifies Electric/Electronic/Programmable Electronic Safety-Related Systems into two modes of operation using demand frequencies only. It is not clear which modes of operation should be applied to Electric/Electronic/Programmable Electronic Safety-Related Systems taking into account the demand-state probability and the spurious demand frequency. It is essential for the allocation of Safety Integrity Levels that generic algorithms be derived by involving possible parameters, which make it possible to model the actuality of real systems. The present paper addresses this issue. First of all, the overall system including Electric/Electronic/programmable Electronic Safety-Related Systems is described using a simplified fault-tree. Then, the relationships among demands, demand-states and proof-tests are studied. Overall systems are classified into two groups: a non-demand-state-at-proof-test system which includes both repairable and non-repairable demand states and a constant-demand-frequency system. The new ideas such as a demand-state, spurious demand-state, mean time between detections, rates of d-failure and h-failure, and an hid ratio are introduced in order to make the Safety Integrity Levels and modes of operation generic and comprehensive. Finally, the overall system is simplified and modeled by fault-trees using Priority-AND gates. At the same time the assumptions for modeling are described. Generic algorithms to estimate hazardous-event frequencies are derived based on the fault-trees. Thus, new definitions regarding modes of operation for the allocation of Safety Integrity Levels and shortcut methods for estimation of hazardous-event frequencies are proposed. (C) 1999 Elsevier Science Ltd. All rights reserved.
引用
收藏
页码:135 / 144
页数:10
相关论文
共 11 条
[1]  
*AN CTR TRAFF ACC, 1995, ANN STAT TRAFF ACC
[2]  
HENLEY E, 1992, PROBABILISTIC RISK A
[3]  
*JAP IND SAF HLTH, 1965, IND SAF YB
[4]  
KATO E, IEEET T
[5]  
KATO E, 1997, P 30 ISATA ROAD VEH, P383
[6]  
RADLEY CF, 1995, 198412 NASA
[7]  
*RAILW TECHN RES I, 1996, TECHN GUID SAF REL S
[8]  
REINERT D, 1997, COMMUNICATION JUN
[9]   AN ACTION-CHAIN MODEL FOR THE DESIGN OF HAZARD-CONTROL SYSTEMS FOR ROBOTS [J].
SATO, Y ;
HENLEY, EJ ;
INOUE, K .
IEEE TRANSACTIONS ON RELIABILITY, 1990, 39 (02) :151-157
[10]  
SATO Y, 1996, PROBABILISTIC SAFETY, V3, P1959