Architectural constraints — SFF and hardware fault tolerance (IEC 61508-2 Tables 2 and 3)
The IEC 61508-2 route 1H architectural-constraint lookup — safe failure fraction band by hardware fault tolerance for type A and type B elements — applied to the three subsystems of a knock-out drum level trip, for a SIL verification report.
Make it your own.
title "Architectural constraints — SIF-107 (IEC 61508-2 Tables 2 and 3)"
input Fmeda "FMEDA data: lambda_SD, lambda_SU, lambda_DD, lambda_DU per element"
source Iec "IEC 61508-2:2010 cl. 7.4.4, route 1H"
decision Element "Element type, SFF and hardware fault tolerance"
decision MaxSil "Maximum SIL the architecture allows"
Fmeda -> Element
Iec -> Element
Iec -> MaxSil
Element -> MaxSil
// ── The three subsystems of SIF-107 (knock-out drum high-high level
// trip). SFF = (lambda_SD + lambda_SU + lambda_DD) / lambda_total,
// taken from each supplier's FMEDA report. HFT is the number of
// dangerous failures the voting group tolerates and still performs the
// safety function: 2oo3 tolerates one, 1oo2 tolerates one, 1oo1 none.
decision Element "Element type, SFF and hardware fault tolerance" {
hit U
input Subsystem enum { LT107, PLC107, XV107 }
output Type enum { A, B }
output SFFpct number [0..100]
output HFT enum { HFT0, HFT1, HFT2 }
rule LT107 -> B | 91.0 | HFT1 // guided-wave radar, microprocessor based, so type B; 2oo3 group
rule PLC107 -> B | 99.4 | HFT1 // certified safety PLC, 1oo2D internal architecture
rule XV107 -> A | 65.0 | HFT1 // ball valve and solenoid, well-defined failure modes, so type A; 1oo2 group
}
// ── The normative lookup. Rows are IEC 61508-2 Table 2 (type A
// elements) and Table 3 (type B elements). The SFF bands are the
// standard's own: below 60 %, 60 % to below 90 %, 90 % to below 99 %,
// and 99 % and above, written half-open so they tile [0..100] exactly.
decision MaxSil "Maximum SIL the architecture allows" {
hit U
input Type enum { A, B }
input SFFpct number [0..100]
input HFT enum { HFT0, HFT1, HFT2 }
output MaxSIL enum { NotAllowed, SIL1, SIL2, SIL3, SIL4 }
rule A | [0..60) | HFT0 -> SIL1
rule A | [0..60) | HFT1 -> SIL2
rule A | [0..60) | HFT2 -> SIL3
rule A | [60..90) | HFT0 -> SIL2
rule A | [60..90) | HFT1 -> SIL3
rule A | [60..90) | HFT2 -> SIL4
rule A | [90..99) | HFT0 -> SIL3
rule A | [90..99) | HFT1 -> SIL4
rule A | [90..99) | HFT2 -> SIL4
rule A | [99..100] | HFT0 -> SIL3
rule A | [99..100] | HFT1 -> SIL4
rule A | [99..100] | HFT2 -> SIL4
rule B | [0..60) | HFT0 -> NotAllowed
rule B | [0..60) | HFT1 -> SIL1
rule B | [0..60) | HFT2 -> SIL2
rule B | [60..90) | HFT0 -> SIL1
rule B | [60..90) | HFT1 -> SIL2
rule B | [60..90) | HFT2 -> SIL3
rule B | [90..99) | HFT0 -> SIL2
rule B | [90..99) | HFT1 -> SIL3
rule B | [90..99) | HFT2 -> SIL4
rule B | [99..100] | HFT0 -> SIL3
rule B | [99..100] | HFT1 -> SIL4
rule B | [99..100] | HFT2 -> SIL4
}