|
Functional
Safety, Introduction Reliability vs. Safety IEC 61508 ISO 13849 → IEC 61508 vs. ISO 13849 Summary |
When
engineers are asked about IEC 61508, they almost always think of key
safety indicators like "probability of failure per hour" and "SIL
level". While key indicators are beyond any doubt fundamental characteristics, they make only a small portion in the whole. |
HFT=0 |
HFT=1 | HFT=2 | |
SFF
= 0 ... <60% |
SIL
1 |
SIL
2 |
SIL
3 levels. |
SFF
= 60% ... <90% |
SIL
2 |
SIL
3 |
SIL
4 |
SFF = 90% ... <99% | SIL
3 |
SIL
4 |
SIL
4 |
SFF
> 99% |
SIL
3 |
SIL
4 |
SIL 4 |
HFT=0 |
HFT=1 | HFT=2 | |
SFF = 0 ... <60% | SIL 0 |
SIL
1 |
SIL
2 |
SFF = 60% ... <90% | SIL
1 |
SIL
2 |
SIL
3 |
SFF = 90% ... <99% | SIL
2 |
SIL
3 |
SIL
4 |
SFF > 99% | SIL
3 |
SIL
4 |
SIL
4 |
SIL
Level |
PFH |
Range
covered |
SIL 1 |
1E-5 > PFH > 1E-6 | Factor 10 |
SIL 2 |
1E-6 > PFH > 1E-7 | Factor 10 |
SIL 3 |
1E-7 > PFH > 1E-8 | Factor 10 |
SIL 4 |
1E-8 > PFH > 1E-9 | Factor 10 |
Cat
B |
Cat
1 |
Cat
2 |
Cat
3 |
Cat
4 |
|
PL
a |
x |
x |
x |
||
PL
b |
x |
x |
x |
x |
|
PL
c |
x |
x |
x |
||
PL
d |
x |
x |
|||
PL
e |
x |
x |
ISO
13849 Category |
Architectural
Constraints |
Required Diagnostic
Coverage |
Goal of the Category |
B |
Simple
safety related system. No requirements. |
none |
Focus rather
on reliability than on safety. Use common technical sense. |
1 |
Like B, plus: Proven principles (e.g. 4...20 mA). Evidence that system design is proven for safety applications. |
none |
Proven principles, proven components. Use technical expert knowledge. |
2 |
Like 1, plus: The safety related system must be tested periodically. |
min. 60% (min. 90% *) |
Increased
failure detection probability |
3 |
Like 1, plus: Fault tolerance whenever possible and feasible. Only few dangerous single failure modes allowed. In most cases this boils down to 100% single fault tolerance. |
min. 60% (min. 90% *) |
1. "Near
fault tolerance". 2. Undetectable dangerous single failure modes are allowed to some extent. |
4 |
Like 3, plus: Fault tolerance. Every single failure must be detectable before demand. In most cases this boils down to almost 100% double fault tolerance because any first failure shall not be masked by a subsequent second failure. |
min. 99% | 1. Fault
tolerance. 2. Undetectable dangerous single failure modes are not allowed. 3. No dangerous failure shall be masked by a subsequent failure. |
PFH | Performance
Level |
Range covered |
3E-5 > PFH > 1E-5 | a |
Factor 3 |
1E-5 > PFH > 3E-6 | b |
Factor 3 |
3E-6 > PFH > 1E-6 | c |
Factor 3 |
1E-6 > PFH > 1E-7 | d |
Factor 10 |
1E-7 > PFH > 2,5E-8 | e |
Factor 4 |