Professional Documents
Culture Documents
Knegtering - 1999 - Reliability Engineering & System Safety PDF
Knegtering - 1999 - Reliability Engineering & System Safety PDF
www.elsevier.com/locate/ress
Abstract
This paper presents a method that will drastically reduce the calculation effort required to obtain quantitative safety and reliability
assessments to determine safety integrity levels for applications in the process industry. The method described combines all benefits of
Markov modeling with the practical benefits of reliability block diagrams. q 1999 Elsevier Science Ltd. All rights reserved.
Keywords: Reliability block diagrams; Fault tree analysis; Micro Markov analysis
The probabilities of the states, that the safeguarding Undetected, Dangerous Detected and Dangerous Unde-
system may be in, can be calculated (see Fig. 3) using the tected. This is why Markov models for large system will
following basic probability axioms: often only consider combinations of up to two failures. This
may be justified by assuming that the probability of states
Psystem is active 1 2 Psystem has tripped ;
where three failures have occurred is negligible compared to
the probability of being in a state where only one or two
Psystem is okay Psystem is active 2 Psystem has failed to function : failures have occurred.
The above principle serves as the basis for splitting up a
full Markov model into “Micro” Markov models, using rear- 4. Combining reliability block diagrams and Markov
ranged Reliability Block Diagrams. modeling
quantitative safety standards: different techniques, different be solved analytically, which once again simplifies the
results?”.) probability calculation.
Another thing is the small differences between all three 4. The results of the micro Markov modeling calculation
Markov-based modeling techniques. However, restricted appear to be more conservative (i.e. “safer”) compared
Markov models show a more optimistic safety performance to restricted Markov modeling, which considers a maxi-
compared to full Markov models, which also considers mum of two failures.
states in which more than two modules have failed. If
micro Markov modeling is applied, the values turns out to
be a bit more conservative, i.e. a more safely calculated References
performance. The micro Markov modeling technique is
[1] Xing L, Fleming KN, Loh WT. Comparison of Markov model and fault
therefore preferable to the restricted Markov modeling tech-
tree approach in determining initiating event frequency for systems
nique, which considers a maximum of two failures. with two train configurations. Reliability Engineering and System
Safety 1996;53:17–29.
[2] Rouvroye JL, Brombacher AC, et al. Uncertainty in safety. New tech-
8. Conclusions niques for the assessment and optimisation of safety in process indus-
try. SERA-Vol. 4, Safety Engineering and Risk Analysis, ASME, San
1. Building large Markov models is very time-consuming Francisco, 1995.
and very susceptible to modeling errors. [3] ISA S84. 67 Alexander Drive, P.O. Box 12277, Research Triangle
2. To practically handle reliability calculations using Park, NC 27709.
[4] ISA TR84.0.02. Version 3, 67 Alexander Drive, P.O. Box 12277,
Markov modeling, the Reliability Block Diagram should Research Triangle Park, NC 27709, December 1997.
first be redefined. This must be done in such a way that [5] IEC 61508. Functional safety of electrical/electronic/programmable
the number of failure-redundant parts is minimized. electronic safety-related systems.
Solving many small Markov models takes a lot less [6] IEC 61078. Analysis techniques for dependability—Reliability block
calculation effort than solving one huge Markov model diagram method, 1991.
[7] Rouvroye JL, Brombacher AC. New quantitative safety standards:
that contains everything [7]. different techniques, different results? Proceedings of the ESREL
3. When systems are considered which are a maximum of conference on European Safety and Reliability, Trondheim, 16–19
one-fault tolerant, the micro Markov models can easily June, 1998.