Properly crediting diagnostics in safety instrumented functions for high demand processes

J. Bukowski, W. Goble
{"title":"Properly crediting diagnostics in safety instrumented functions for high demand processes","authors":"J. Bukowski, W. Goble","doi":"10.1109/RAM.2017.7889648","DOIUrl":null,"url":null,"abstract":"According to certain safety standards [1, 2, 3], when assessing the safety performance of a safety instrumented function (SIF) operating in high demand mode, full credit can be given for the positive effects of SIF automatic self-diagnostics (ASD) provided the frequency of self-diagnostic execution is 100 times (100X) or more the demand rate on the SIF and the SIF is configured to convert dangerous failures into safe failures via an automatic shutdown. However, no credit may be given for the positive safety effects of SIF ASD if the frequency of ASD execution is less than 100X the demand rate. This paper shows that the 100X requirement is excessive and that significant positive safety effects accrue even when the ASD frequency is much smaller than the 100X stipulation. The theory, which provides reasonable justification for assigning some degree of partial diagnostic credit (PDC) for SIF ASD based on the ratio of ASD frequency to demand rate, is developed under two different assumptions: Scenario 1 which is extremely conservative and Scenario 2 which is realistic. It is shown that even under the conservative assumption, a frequency of ASD execution of as little as 2X the rate of demand on the SIF deserves at least 60% credit. Under the realistic assumption, the 2X frequency of ASD execution deserves at least 78% credit! Further, ASD execution frequencies of 10X deserve at least 90% credit under the conservative assumption and at least 95% credit under the realistic assumption. These findings suggest that a SIF operating in high demand mode which currently is not receiving credit for its ASD may be reassessed at a lower PDF(t)/hr (a safety metric for SIF in high demand mode) and perhaps a higher safety integrity level (SIL). Furthermore, manufacturers that may have been reluctant to include ASD in equipment used in SIF construction because of the likelihood that the ASD execution frequency would not qualify for PDC in a SIL assessment, may wish to reconsider given that reasonable justification for assigning at least some PDC for the positive effects of ASD is now possible.","PeriodicalId":138871,"journal":{"name":"2017 Annual Reliability and Maintainability Symposium (RAMS)","volume":"14 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"1900-01-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"3","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2017 Annual Reliability and Maintainability Symposium (RAMS)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/RAM.2017.7889648","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 3

Abstract

According to certain safety standards [1, 2, 3], when assessing the safety performance of a safety instrumented function (SIF) operating in high demand mode, full credit can be given for the positive effects of SIF automatic self-diagnostics (ASD) provided the frequency of self-diagnostic execution is 100 times (100X) or more the demand rate on the SIF and the SIF is configured to convert dangerous failures into safe failures via an automatic shutdown. However, no credit may be given for the positive safety effects of SIF ASD if the frequency of ASD execution is less than 100X the demand rate. This paper shows that the 100X requirement is excessive and that significant positive safety effects accrue even when the ASD frequency is much smaller than the 100X stipulation. The theory, which provides reasonable justification for assigning some degree of partial diagnostic credit (PDC) for SIF ASD based on the ratio of ASD frequency to demand rate, is developed under two different assumptions: Scenario 1 which is extremely conservative and Scenario 2 which is realistic. It is shown that even under the conservative assumption, a frequency of ASD execution of as little as 2X the rate of demand on the SIF deserves at least 60% credit. Under the realistic assumption, the 2X frequency of ASD execution deserves at least 78% credit! Further, ASD execution frequencies of 10X deserve at least 90% credit under the conservative assumption and at least 95% credit under the realistic assumption. These findings suggest that a SIF operating in high demand mode which currently is not receiving credit for its ASD may be reassessed at a lower PDF(t)/hr (a safety metric for SIF in high demand mode) and perhaps a higher safety integrity level (SIL). Furthermore, manufacturers that may have been reluctant to include ASD in equipment used in SIF construction because of the likelihood that the ASD execution frequency would not qualify for PDC in a SIL assessment, may wish to reconsider given that reasonable justification for assigning at least some PDC for the positive effects of ASD is now possible.
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
在高要求的过程中,正确地将诊断归功于安全仪表功能
根据一定的安全标准[1,2,3],在评估在高需求模式下运行的安全仪表功能(SIF)的安全性能时,如果自诊断执行频率是SIF需求率的100倍(100X)或更多,并且SIF配置为通过自动关闭将危险故障转换为安全故障,则SIF自动自诊断(ASD)的积极影响可以完全归功于SIF。然而,如果执行ASD的频率低于需求率的100倍,则SIF ASD的积极安全效果可能不会得到认可。本文表明,100X的要求过高,即使ASD频率远低于100X的规定,也会产生显著的积极安全效应。该理论为基于ASD频率与需求率的比率为SIF ASD分配一定程度的部分诊断信用(PDC)提供了合理的理由,该理论是在两个不同的假设下发展起来的:场景1是极端保守的,场景2是现实的。结果表明,即使在保守的假设下,ASD执行的频率只有SIF需求率的2倍,至少应该得到60%的信用。在现实的假设下,ASD执行的2倍频率至少值得78%的功劳!此外,10倍的ASD执行频率在保守假设下至少值得90%的学分,在现实假设下至少值得95%的学分。这些发现表明,在高需求模式下运行的SIF目前没有获得ASD的积分,可以在较低的PDF(t)/小时(高需求模式下SIF的安全度量)和更高的安全完整性水平(SIL)下重新评估。此外,由于ASD执行频率可能不符合SIL评估中PDC的标准,制造商可能不愿意将ASD纳入SIF构建设备中,考虑到现在有可能为ASD的积极影响分配至少一些PDC的合理理由,他们可能希望重新考虑。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 去求助
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
Reliability study on high-k bi-layer dielectrics Contracting for system availability under fleet expansion: Redundancy allocation or spares inventory? Risk modeling of variable probability external initiating events Human reliability assessments: Using the past (Shuttle) to predict the future (Orion) Uniform analysis of fault trees through model transformations
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1