Skip to content
DMN templates

Architectural constraints — SFF and hardware fault tolerance (IEC 61508-2 Tables 2 and 3)

The IEC 61508-2 route 1H architectural-constraint lookup — safe failure fraction band by hardware fault tolerance for type A and type B elements — applied to the three subsystems of a knock-out drum level trip, for a SIL verification report.

Template previewDMN
Architectural constraints — SIF-107 (IEC 61508-2 Tables 2 and 3)FMEDA data:lambda_SD,…IEC 61508-2:2010 cl.7.4.4, route 1HElement type, SFFand hardware fault…Maximum SIL thearchitecture allowsinformation requirementauthority requirementElement type, SFF and hardware fault tolerance — UniqueUSubsystem{ LT107, PLC107, XV107 }Type{ A, B }SFFpct[0..100]HFT{ HFT0, HFT1, HFT2 }AnnotationR1LT107B91.0HFT1guided-wave radar, microprocessor based, so typeB; 2oo3 groupR2PLC107B99.4HFT1certified safety PLC, 1oo2D internalarchitectureR3XV107A65.0HFT1ball valve and solenoid, well-defined failuremodes, so type A; 1oo2 groupMaximum SIL the architecture allows — UniqueUType{ A, B }SFFpct[0..100]HFT{ HFT0, HFT1, HFT2 }MaxSIL{ NotAllowed, SIL1, SIL2, SIL3, SIL4 }R1A[0..60)HFT0SIL1R2A[0..60)HFT1SIL2R3A[0..60)HFT2SIL3R4A[60..90)HFT0SIL2R5A[60..90)HFT1SIL3R6A[60..90)HFT2SIL4R7A[90..99)HFT0SIL3R8A[90..99)HFT1SIL4R9A[90..99)HFT2SIL4R10A[99..100]HFT0SIL3R11A[99..100]HFT1SIL4R12A[99..100]HFT2SIL4R13B[0..60)HFT0NotAllowedR14B[0..60)HFT1SIL1R15B[0..60)HFT2SIL2R16B[60..90)HFT0SIL1R17B[60..90)HFT1SIL2R18B[60..90)HFT2SIL3R19B[90..99)HFT0SIL2R20B[90..99)HFT1SIL3R21B[90..99)HFT2SIL4R22B[99..100]HFT0SIL3R23B[99..100]HFT1SIL4R24B[99..100]HFT2SIL4No overlaps and no gaps over the declared input space · 2 decisions · 1 input data · 1 knowledge source · 2 tables · 27 rulesEvery rule pair is disjoint and every declared input combination matches a rule.

Make it your own.

title "Architectural constraints — SIF-107 (IEC 61508-2 Tables 2 and 3)"

input    Fmeda   "FMEDA data: lambda_SD, lambda_SU, lambda_DD, lambda_DU per element"
source   Iec     "IEC 61508-2:2010 cl. 7.4.4, route 1H"
decision Element "Element type, SFF and hardware fault tolerance"
decision MaxSil  "Maximum SIL the architecture allows"

Fmeda   -> Element
Iec     -> Element
Iec     -> MaxSil
Element -> MaxSil

// ── The three subsystems of SIF-107 (knock-out drum high-high level
// trip). SFF = (lambda_SD + lambda_SU + lambda_DD) / lambda_total,
// taken from each supplier's FMEDA report. HFT is the number of
// dangerous failures the voting group tolerates and still performs the
// safety function: 2oo3 tolerates one, 1oo2 tolerates one, 1oo1 none.

decision Element "Element type, SFF and hardware fault tolerance" {
  hit U
  input  Subsystem enum { LT107, PLC107, XV107 }
  output Type   enum   { A, B }
  output SFFpct number [0..100]
  output HFT    enum   { HFT0, HFT1, HFT2 }

  rule LT107  -> B | 91.0 | HFT1   // guided-wave radar, microprocessor based, so type B; 2oo3 group
  rule PLC107 -> B | 99.4 | HFT1   // certified safety PLC, 1oo2D internal architecture
  rule XV107  -> A | 65.0 | HFT1   // ball valve and solenoid, well-defined failure modes, so type A; 1oo2 group
}

// ── The normative lookup. Rows are IEC 61508-2 Table 2 (type A
// elements) and Table 3 (type B elements). The SFF bands are the
// standard's own: below 60 %, 60 % to below 90 %, 90 % to below 99 %,
// and 99 % and above, written half-open so they tile [0..100] exactly.

decision MaxSil "Maximum SIL the architecture allows" {
  hit U
  input  Type   enum   { A, B }
  input  SFFpct number [0..100]
  input  HFT    enum   { HFT0, HFT1, HFT2 }
  output MaxSIL enum   { NotAllowed, SIL1, SIL2, SIL3, SIL4 }

  rule A | [0..60)    | HFT0 -> SIL1
  rule A | [0..60)    | HFT1 -> SIL2
  rule A | [0..60)    | HFT2 -> SIL3
  rule A | [60..90)   | HFT0 -> SIL2
  rule A | [60..90)   | HFT1 -> SIL3
  rule A | [60..90)   | HFT2 -> SIL4
  rule A | [90..99)   | HFT0 -> SIL3
  rule A | [90..99)   | HFT1 -> SIL4
  rule A | [90..99)   | HFT2 -> SIL4
  rule A | [99..100]  | HFT0 -> SIL3
  rule A | [99..100]  | HFT1 -> SIL4
  rule A | [99..100]  | HFT2 -> SIL4
  rule B | [0..60)    | HFT0 -> NotAllowed
  rule B | [0..60)    | HFT1 -> SIL1
  rule B | [0..60)    | HFT2 -> SIL2
  rule B | [60..90)   | HFT0 -> SIL1
  rule B | [60..90)   | HFT1 -> SIL2
  rule B | [60..90)   | HFT2 -> SIL3
  rule B | [90..99)   | HFT0 -> SIL2
  rule B | [90..99)   | HFT1 -> SIL3
  rule B | [90..99)   | HFT2 -> SIL4
  rule B | [99..100]  | HFT0 -> SIL3
  rule B | [99..100]  | HFT1 -> SIL4
  rule B | [99..100]  | HFT2 -> SIL4
}