Specificity of fault tree-based functional safety indicator definition in emergency shutdown systems
https://doi.org/10.21683/1729-2646-2022-22-4-45-52
Abstract
Aim. The paper aims to analyse the specifics of the use of commercial fault tree (FT)-based software suites as part of engineering practice for the purpose of dependability calculation of emergency shutdown systems (ESS). Standards of the IEC 61508 Functional safety series stress that, in such cases, there is a possibility of incorrect and non-conservative estimates of the mean probability of failure on demand of an ESS safety feature. Incorrect results are primarily caused by the use of approximate and simplified formulas for identifying the dependability indicators of ESS circuit components and calculating the ESS mean unavailability for safety function performance based on the mean unavailability values of its components. In order to correct the FT simulation results, correction factors can be used that take into account the ESS circuit structure along with exact formulas per IEC 61508-6 for calculating the mean probability of failure on demand of the ESS circuit components. Additionally, the type of common cause failure (ССF) model can be chosen.
Methods. A comparative analysis was performed as regards the effects of components of hazardous failures that may be detected or not detected by internal diagnostics on the assessment of the mean probability of failure on demand of an ESS circuit components. It was shown that in less dependable components this dependence significantly affects the unavailability value. The efficiency of correction coefficients that take into account the ESS circuit architecture also depends on the dependability of components, and their introduction is justified for those components whose safety integrity level is between 1 and 2. Engineering estimation of the functional safety indicators can be done using a beta-factor model of common cause failures that is employed as part of design analysis of ESS functional safety.
Results. An analysis of simplified and approximate formulas for calculating the mean unavailability of the non-redundant elements of an ESS circuit has shown that in the case of an over 90-percent diagnostic coverage the use of simplified formulas causes an underestimation of the unavailability indicator caused by the increased effect of detected hazardous failures on the probability of ESS misoperation. If the FT analysis is used for the purpose of deducing a conservative estimate of an ESS circuit unavailability indicator, correction factors should be used, whose values depend on the ESS channels redundancy parameters. Two models of accounting for CCF were examined that are used when calculating ESS functional safety. It was shown that under any ESS model the system’s dependability indicators decrease. This decrease is defined by the value of the beta factor and the dependability of the ESS system elements.
Conclusion. The information presented in the paper indicates the limited applicability of the simplified formula for calculating the mean unavailability of non-redundant ESS elements as the input data for FT construction. When identifying the safety integrity level of an ESS circuit that includes elements with a low dependability, it should be taken into consideration that, if a FT is used, commercial software suites may overestimate the dependability, which is undesirable in respect to functional safety analysis.
About the Authors
I. A. MozhaevaRussian Federation
Irina A. Mozhaeva, Candidate of Engineering, Lead Specialist of the Research Unit
15, korp. 2, lit. A 26-ya Liniya Vasiliyevskogo Ostrova, Birzha Business Centre, 199106, Saint Petersburg
A. V. Strukov
Russian Federation
Alexander V. Strukov, Candidate of Engineering, Associate Professor, Lead Specialist of the Research Unit
15, korp. 2, lit. A 26-ya Liniya Vasiliyevskogo Ostrova, Birzha Business Centre, 199106, Saint Petersburg
References
1. GOST R IEC 61508. Functional safety of electrical, electronic, programmable electronic safety-related systems. Part 6: Guidelines on the application of IEC 61508-2 and IEC 61508-3. Moscow: Standartinform; 2014. (in Russ.)
2. Rausand M. Reliability of Safety-Critical Systems: Theory and Applications. Willey; 2014.
3. Mozhaeva I.A., Nozik A.A., Strukov A.V. [Generic examples of functional safety calculation of emergency shutdown systems of hazardous industrial facilities]. In: [Proceedings of the Twentieth All-Russian Research and Practice Conference Topical Problems of Safety and Security, Vol. 2, Counter-Terrorist Measures]. Moscow: RARAN; Saint Petersburg: NPO SM; 2019. Pp. 486-494. (in Russ.)
4. Mozhaev A.S. Annotation for the ARBITR software (PK ASM SZMA). In: [Matters of Nuclear Science and Engineering. Nuclear Reactor Physics Series. Annotations for Rostekhnadzor-Certified Software. A Collection of Research and Engineering Papers]. Moscow: Kurchatov Institute 2008;2:105-116. (in Russ.)
5. https://www.isograph.com/software/reliability-workbench/ (accessed 03.08.2022).
6. Antonov A.V., Chepurko V.A., Cherniaev A.N. Research of the beta-factor model of accounting for common cause failures. Dependability 2019;2:9-17. DOI: 10.21683/1729-2646-2019-19-2-9-17.
7. Mozhaeva I.A., Strukov A.V. [Application of PK ARBITR for engineering assessment of functional safety indicators of emergency shutdown systems]. In: [Proceedings of the 4-th International Research and Practice Conference Simulation of Marine Facilities and Marine Transportation Systems (IKT MTMTS 2017)]. Saint Petersburg; 2017. Pp. 100-105. (in Russ.)
Review
For citations:
Mozhaeva I.A., Strukov A.V. Specificity of fault tree-based functional safety indicator definition in emergency shutdown systems. Dependability. 2022;22(4):45-52. (In Russ.) https://doi.org/10.21683/1729-2646-2022-22-4-45-52