Freeman, Randy
Freeman, Randy
Freeman, Randy
Calculations
Abstract
The IEC 61511 standard requires a verification calculation that a proposed design for a safety
instrumented function (SIF) achieves the desired safety integrity level (SIL). The evaluation of
the safety integrity level of a new or existing safety instrumented system requires detailed
calculations based on the failure rates of the device and the planned maintenance/testing cycle
for the system. The failure rates of the devices are often taken from standard failure rate
tabulations of equipment. The maintenance and testing plans are developed based on plant
experience. All of the data used in the SIL calculations are uncertain. This paper develops a
general method for uncertainty analysis of the SIL calculations. The general method is based on
the application of probability theory - variance contribution analysis (VCA) – to the equations
presented in ISA TR 84.00.02-2115. An example is worked to demonstrate the methodology.
Background
The calculation of the probability of failure on demand (PFD) is a common engineering task
when designing an interlock or safety system that is to be in compliance with IEC 61511
[Ref. 1]. The calculation of the PFD is often done using approximate equations defined in the
ISA TR84.00.02 technical report [Ref. 2]. The simplified equation method in the ISA report is
commonly used and is based on the use of reliability block diagrams where the field sensors,
Safety Instrumented System (SIS) logic solver and final control elements are considered
independent of each other in the sense of not sharing common devices or systems. The PFD is
then calculated using the failure rates of the devices, planned test intervals, vendor supplied
estimates on diagnostic coverage of the devices and an allowance for the potential for common
cause failures. Almost all of these parameters are uncertain. The failure rate data is often taken
from generic data sources which show wide ranges in the observed values.
Because of the uncertainty in the parameters, the design engineer makes allowances in the design
by the use of safety factors or rules of thumb to improve the chances that the final interlock
installation will work as intended. Since each engineer has a different set of safety factors and
rules of thumb, two designs may differ significantly in the way a hazard is controlled.
A more formal method for handling the underlying uncertainty in the calculation of the PFD of
an interlock is needed. Previously, Freeman and Summers [Ref. 3] published an uncertainity
analysis of the PFD of an interlock. Two different methods were used in this analysis:
Monte Carlo Simulation
Variance Contribution Analysis (VCA)
Monte Carlo Simulation requires that the engineer build a model of the interlock using
specialized computer software. The use of VCA requires that the sensitivity of the interlock
model be determined either by numerical methods or by direct analytical calculations. The
Freeman paper demonstrates that VCA can be used for the uncertainty analysis. However, the
paper does not present a complete analysis method that can be applied to any system defined in
the ISA technical report TR84.00.02. The goal of this paper is to develop a general set of
analytical equations that will allow VCA to be used in uncertainty analysis of any interlock
developed per the IEC 61511 standard.
What is needed is a means to rapidly evaluate the impact of parameter uncertainty on the
interlock PFD. The remainder of this paper applies the methods of variance contribution analysis
(VCA) to determine the mean (expected value) and the standard deviation of the interlock PFD
for a given design.
Table 1. Simplified PFD avg formulas for Non-Repairable System
without considering CCF, Diagnostics or MTTR.
Appendix
PFD based on "Average before"
Configuration Function A Equation
failure rate
Number
D TI
1oo1 F1 = 2 A-1
D 2 TI 2
1oo2 F2 = ( ) A- 2
4
D 3 TI 3
1oo3 F3 = ( ) A-3
8
D
2oo2 F4 = TI A-4
3 D 2
2oo3 F5 = ( ) TI2 A-5
4
TI
3oo3 F6 = 3 D A-6
2
Appendix
A
Configuration Function PFD based on "Average before" failure rate
Equation
Number
(1 DC) D TI DC D DI
1oo1 F7 =
D MTTR A-24
2 2
2
(1 DC) (1 ) D TI
2
DC (1 ) D DI
(1 ) MTTR
D
2
1oo2 F8 = (1 DC) TI
D
A- 25
2
DC D DI
MTTR
D
2
3
(1 DC) (1 ) D TI
2
DC (1 ) D DI
(1 ) D MTTR
2
1oo3 F9 = (1 DC) TI
D
A-26
2
DC D DI
MTTR
D
2
(1 DC) D TI DC D DI
2oo2 F 10 = 2 D MTTR A-27
2 2
Table 2. Simplified PFD avg Formulas for Repairable System
considering CCF, Diagnostics and MTTR
Appendix
A
Configuration Function PFD based on "Average before" failure rate
Equation
Number
2
(1 DC) (1 ) D TI
3 2
DC (1 ) D DI
(1 ) MTTR
D
2oo3 F 11 =
2 A-28
(1 DC) TI
D
2
DC D DI
MTTR
D
2
(1 DC) D TI DC D DI
3oo3 F 12 = 3 D MTTR A-29
2 2
Review of Variance Contribution Analysis (VCA) Methodology
The mean and variance of a function of random variables can be approximated using the method
described by Haugen [Ref. 5] and applied by Freeman [Ref. 3, 6, 7]. Define an arbitrary function
of a set of random variables, xi, as:
Let
Y = F(xi) (Eq 1)
Where:
E(Y) = expected value of random variable Y = mean of Y
E(xi) = expected value of random variable xi = mean of xi
2
n Y
V(Y) = i1 V ( xi ) (Eq 3)
xi
Where:
V(Y) = variance of random variable Y as defined above in Equation 1
V(xi) = variance of random variable xi as defined above in Equation 1
Note that the variance is simply the square of the standard deviation. Using the variance will
simplify the mathematics that is described below. The contribution of each independent random
variable to the overall variance in the function is:
2
Y
V(Y from xi) = V ( xi ) (Eq 4)
x
i
The relative contribution of each term to the overall variance V(Y) is a measure of the
importance in the uncertainty in the particular random variable, xi. In effect, this is a sensitivity
analysis combined with a uncertainty evaluation. The variance contribution combines the
sensitivity in the answer to changes in the uncertain random variable, xi, with a measure of the
uncertainty in the random variable, xi. The overall variance in Y is found by summing the
sensitivity weighted variances from each random variable.
1. Complete the interlock design using the methods outlined in IEC 61511 [Ref. 1].
2. Review with the process system management and determine if the proposed interlock
should be considered repairable or non-repairable. A simple flow chart for this decision
making is presented in Figure 2. The basic question is: “can the interlock be repaired
safely while the process operates.” This is a management question and management
should be the one that decides the answer to this important question.
3. Create interlock performance equation as the mathematical model for the combination of
sensor, logic solver and final control elements using the methods outlined in ISA
technical report (TR84.00.02) [Ref. 2]. For non-repairable systems, Table 3 can be used.
For more complex systems such as non-repairable redundant systems with the potential
for common cause failures, use the repairable equations of Table 4 and set DI, DC, and
MTTR all equal to zero. For systems where common cause failures (DCF), Diagnostics
and repair are to be considered, use the recommendations of Table 4.
Table 3. Roadmap for Mean and Variance of Non-Repairable System
Without Considering CCF, Diagnostics and MTTR
1oo2 F2 = A- 10 A- 19
1oo2 F8 = A- 31 A- 86
Note that in all of the calculations indicated by the equations referenced in Table 4, the expected
value of any the random variables is used to complete the calculations.
4. Define the uncertainty in the parameters and variables of the interlock model specified in
step 2. The uncertainty can be given as the upper and lower range of the possible values
(uniform probability distribution), as the upper, lower and recommended values
(triangular distribution), or as a mean and standard deviation (normal distribution). See
the example above for guidance in the evaluation of safety instrumented system
interlocks.
5. Compute the expected value of each variable in the interlock performance equation. The
equations for the mean and variance for the uniform, triangular and normal probability
distributions are presented for various probability distributions in Vose [Ref. 8]. The
example interlock calculations used a triangular distribution to represent the uncertainty
in the parameters.
6. Compute the expected value or mean of the interlock PFD using the mean value of each
of the variables in Step 5. See Tables 4 and 5 for recommended equations.
7. Compute the sensitivity of the result from the interlock performance equation by use of
the partial derivative of the basic interlock performance equation with respect to each of
the variables as presented in Appendix A.
8. Compute the variance of the interlock performance equation PFD by use of the variance
contribution using equations from Tables 3 or 4. This entails multiplying the variance of
each of the uncertain variables in the basic interlock performance equation by the square
of its sensitivity (obtained in step 7), as evaluated at the variable mean. Sum the resulting
terms to obtain the overall variance of the PFD in the interlock performance equation.
See Tables 4 and 5 for recommended equations.
9. Determine the level of risk that the owner/operator wishes to take that the final interlock
will not work. Note that this is a management decision not an instrument engineer
decision! In this paper, the 95% level of risk reduction has been used:
5% chance of failure or a 95% chance of the interlock achieving the desired risk
reduction
10. Assuming that the interlock owner operator wishes to take a low risk (5%) of the
interlock failing to achieve its design target PFD, compute the 95% upper confidence
limit on the computed PFD by use of the standard normal factor, Z, [Ref. 9] as:
𝑥𝑖−𝐸(𝑥)
Z= [ ] (Eq 5)
𝜎
Where:
σ = standard deviation of the PFD of the interlock of interest from the interlock
performance equation obtained from step 7. Note that the variance of a random
variable is the square of the standard deviation of the random variable.
E(x) = the expected value of the PFD of the interlock of interest from the interlock
performance equation obtained from step 5
For the 95% upper limit, Z = 1.645. Rearranging Eq. 5 allows for the direct
calculation of the corresponding value of the 95% upper confidence limit on the
PFD as:
Where:
X95% = the upper 95% limit on the computed PFD of the interlock of interest
from the interlock performance equation.
Compare the 95% upper confidence limit on the PFD of the interlock of concern with that
established as the desired PFD for risk reduction. If the 95% confidence of the RRF is greater
than the desired RRF, the design is complete. If not, revise the design or change inspection test
intervals to achieve the desired RRF. If it is not possible to achieve the desired target RRF
economically, revisit the LOPA study accordingly to incorporate better information obtained in
the uncertainty analysis. Improve the integrity of the LOPA IPLs or identify additional IPLs to
drive the risk to a tolerable level. Continue this process until the computed RRFs are greater
than the desired RRFs for risk reduction and risk management.
Models
The first step in the calculation of the “goodness” of an interlock is to establish the model to be
used in the calculations. Note that the sensors are 2oo3 voting and the final control elements are
each 1oo1. Appendix A presents the equations for various models that can be used for
describing this system.
The overall probability of failure on demand (PFD) of the interlock is given as:
Where:
PFD = Probability of failure on demand of the interlock as a whole
PFDs = Probability of failure on demand of the sensors (voting as 2oo3)
PFDsis = Probability of failure on demand of the SIS logic solver
PFDfce = Probability of failure on demand of the final control elements.
Since there are two final control elements arranged in series, the PFDfce = sum of the PFDs of
the final control elements (Relay PFD and MCC PFD).
Where:
PFDr = Probability of failure on demand of the two relays voting as 1oo2 to shutdown gas
compressor.
PFDmcc = Probability of failure on demand of the MCC to shutdown the gas compressor
For this example, the following selections are made to model the performance of the interlock.
2
(1 DCs) (1 s) Ds TIs DCs (1 s) Ds DIs
PFDsavg = 3 (1 s) Ds MTTRs +
2 2
Where:
PFDsavg is the average probability of failure on demand of the sensors
DCs is the diagnostic coverage for sensor failure
DIs is the diagnostic interval for the sensors
MTTRs is the mean time to restore the sensors to functionality given a sensor failure
TIs is the test interval for the sensors
βs is the common cause failure parameter
λDs is the failure rate to a dangerous condition for the sensors
MTTR is the mean time to restore the system from the time that failure occurs
2
(1 r ) Dr TIr r Dr TIr
PFDravg = (Eq 10)
2 2
Where:
PFDravg is the average probability of failure on demand of the relays voting 1oo2 to shutoff the
gas compressor.
TIr is the test interval for the relays
βr is the common cause failure parameter
λDr is the failure rate to a dangerous condition for the relays
Model for MCC (1oo1)
From Appendix A and using equation A-1 for the non-repairable MCC, the model becomes:
𝝀𝑫𝒎𝒄𝒄 ∗𝐓𝐈𝐦𝐜𝐜
𝑷𝑭𝑫𝒎𝒄𝒄𝒂𝒗𝒈 = (Eq 11)
𝟐
Where:
PFDmccavg is the average probability of failure on demand of the MCC to shutoff the gas
compressor.
TImcc is the test interval for the MCC
λDmccis the failure rate to a dangerous condition for the MCC
Data
The calculation of the PFD of the interlock requires a set of data to be used to represent the
system. Tables 5, 6, and 7 are taken from the Freeman-Summers paper [Ref. 3] and presents the
data used to represent the interlock system. Note that these data were originally taken from
generic data sources and do not represent any particular device or system.
The mean PFD of 0.00773 implies a mean risk reduction factor of:
RRF = 1/PFD = 1/0.00773 = 129 (Eq 11)
This is essentially the same result previously reported by Freeman and Summers [Ref. 3] using
either Monte Carlo Simulation or numerical approximation methods for the VCA sensitivities.
The calculated PFD at the 95% level of 0.01881 indicates that there is only a 5% chance that the
interlock will provide an RRF worse that 53. Since this level is only SIL-1 capable and not
SIL-2 capable as desired by management, a revised design will be needed to achieve the desired
risk reduction or a different protective measure will be needed to control risk.
References
1. International Society of Automation, Functional Safety: Safety Instrumented Systems for
the Process Sector—Parts 1, 2, and 3, ANSI/ISA 84.00.01, 2004 [USA implementation of
IEC 61511].
4. Center for Chemical Process Safety, Layer of Protection Analysis – Simplified Process
Risk Assessment, AmericanInstitute of Chemical Engineers, New York, 2001
5. Edward B. Haugen, Probabilistic Approaches to Design, John Wiley, New York, 1968
6. R.A. Freeman, “Quantifying LOPA Uncertainty,” Process Safety Progress, Vol 31, No. 3,
pp 240-247, 2012
8. David Vose, Risk Analysis – A Quantitative Guide, 3rd Edition, John Wiley, 2008
9. Paul L. Meyer, Introductory Probability and Statistical Applications, John Wiley, New
York, 1972
Final Control
Sensors Logic Solver
Element
Failure NO
Non-Repairable
Announced?
YES
NO
Repair
Non-Repairable
Safely?
YES
Repairable
Compressed Gas
To Process
Power to Motor
Gas Compressor
Relay
R1
MCC
Relay
Relays R1 and R2 Vote
R2
1oo2 to activate MCC
Compressor
Knock Out
Drum SIS
Logic
Solver
Level Transmitters LT-1,
Inlet LT-2 and LT-3 Vote 2oo3
Gas on High Level to Activate
Compressor Shutdown
Interlock
LT-1
LT-2
LT-3
Liquids to Recycle
APPENDIX A -- DEVELOPMENT OF UNCERTAINTY EQUATIONS
NON-REPAIRABLE SYSTEMS
For systems that are considered non-repairable, the simplified equations of Table A.1
(taken from the ISA Technical Report [Ref. 2]) are used for the analysis.
D TI
1oo1 F1 = 2 A-1
D 2 TI 2
1oo2 F2 = ( ) A- 2
4
D 3 TI 3
1oo3 F3 = ( ) A-3
8
D
2oo2 F4 = TI A-4
3 D 2
2oo3 F5 = ( ) TI2 A-5
4
TI
3oo3 F6 = 3 D A-6
2
Table A.2 Expected Value of PFD avg formulas for Non-Repairable System
without considering CCF, Diagnostics or MTTR.
E(TI)
E ( ) 2
D
1oo1 E(F 1 ) = A-9
E(TI)2
1oo2 E(F 2 ) = ( E ( D 2
)) A- 10
4
E(TI)3
1oo3 E(F 3 ) = ( E ( D 3
)) A-11
8
E ( ) E (TI)
D
2oo2 E(F 4 ) = A-12
3
2oo3 E(F 5 ) = ( E (D )) 2 E (TI)2 A-13
4
E(TI)
3 E ( D )
2
3oo3 E(F 6 ) = A-14
𝜕𝑦 2
𝑉(𝑦) = ∑𝑛𝑖=1 [ ] 𝑉(𝑥𝑖 ) (Eq A-16)
𝜕𝑥𝑖
Where:
V(y) = variance of random variable y as defined above
V(xi) = variance of random variable xi as defined above
The sensitivity of y with respect to a random variable 𝑥𝑖 is:
𝜕𝑦
Sensitivity of y with respect to 𝑥𝑖 = [ ] (Eq A-17)
𝜕𝑥𝑖
For the configurations defined in Table A.1, the corresponding variance of the PFD are
presented in Table A.3.
Table A.3 Variance of PFDavg formulas for Non-Repairable System
without considering CCF, Diagnostics or MTTR.
E ( ) V ( )
D
2
1oo2 V(F 2 ) = A- 19
2
D 2 E (TI )
E ( ) 2
V (TI )
2
D 2 E(TI)
3
3 E ( ) V ( )
D
2
1oo3 V(F 3 ) = A-20
2
3 2
8 E ( ) E (TI ) V (TI )
D 3
2
3 2
2 E ( ) E (TI) V ( )
D D
2oo3 V(F 5 ) = 2 A-22
3
2 E ( ) E (TI) V (TI )
D 2
2
3
2 E (TI) V ( )
D
3oo3 V(F 6 ) = 2 A-23
3
2 E ( ) V (TI )
D
Note that for the calculation of the variance functions, V(Fi), the random variables are evaluated
at the expected value (mean).
REPAIRABLE SYSTEMS
For systems that are considered repairable, the simplified equations of Table A. 4 are used
for the analysis. The expected value of the probability of failure on demand (PFD) is found
by substituting the expected value of each of the random variables into the corresponding
equation. The expected value of the PFD for each of the system configurations is prese nted
in Table A.5
Table A.4 Simplified PFD avg Formulas for Repairable System
considering CCF, Diagnostics and MTTR
Configuratio Equation
Function PFD based on "Average before" failure rate
n Number
(1 DC) D TI DC D DI
1oo1 F7 =
D MTTR A-24
2 2
2
(1 DC) (1 ) D TI
2
DC (1 ) D DI
(1 ) MTTR
D
2
1oo2 F8 = (1 DC) TI
D
A- 25
2
DC D DI
MTTR
D
2
3
(1 DC) (1 ) D TI
2
DC (1 ) D DI
(1 ) MTTR
D
2
1oo3 F9 = (1 DC) TI
D
A-26
2
DC D DI
D MTTR
2
(1 DC) D TI DC D DI
2oo2 F 10 = 2 D MTTR A-27
2 2
2
(1 DC) (1 ) D TI
3 2
DC (1 ) D DI
(1 ) MTTR
D
2oo3 F 11 =
2 A-28
(1 DC) TI
D
2
DC D DI
MTTR
D
2
Table A.4 Simplified PFD avg Formulas for Repairable System
considering CCF, Diagnostics and MTTR
Configuratio Equation
Function PFD based on "Average before" failure rate
n Number
(1 DC) D TI DC D DI
3oo3 F 12 = 3 D MTTR A-29
2 2
Where:
DC is the diagnostic coverage;
DI is the diagnostic interval;
TI is the proof test interval,
λD is the dangerous failure rate;
MTTR is the mean time to restore the system to operation
is the common cause failure parameter that is always is between 0 and 1
Table A.5 Expected PFD Formulas for Repairable System
considering CCF, Diagnostics and MTTR
Configuratio Equation
Function PFD based on "Average before" failure rate
n Number
1oo2 E(F 8 ) = (1 E ( DC )) E ( ) E ( ) E (TI )
D A- 31
2
E ( DC ) E ( ) E (D ) E ( DI
)
2
E ( ) E ( ) E ( MTTR)
D
3
(1 E ( DC )) (1 E ( )) E (D ) E (TI )
2
E ( DC ) (1 E ( )) E (D ) E ( DI )
2
(1 E ( )) E ( ) E ( MTTR)
D
1oo3 E(F 9 ) = (1 E ( DC )) E ( ) E (D ) E (TI ) A-32
2
E ( DC ) E ( ) E (D ) E ( DI )
2
E ( ) E ( ) E ( MTTR)
D
Table A.5 Expected PFD Formulas for Repairable System
considering CCF, Diagnostics and MTTR
Configuratio Equation
Function PFD based on "Average before" failure rate
n Number
(1 E ( DC )) E (D ) E (TI ))
2
E ( DC ) E (D ) E ( DI )
2oo2 E(F 10 ) = 2 A-33
2
E ( ) E ( MTTR)
D
2
(1 E ( DC )) (1 E ( )) E (D ) E (TI )
2
E ( DC ) (1 E ( )) E (D ) E ( DI )
3
2
(1 E ( )) E ( ) E ( MTTR)
D
2oo3
E(F 11 ) = A-34
(1 E ( DC )) E ( ) E ( ) E (TI )
D
2
E ( DC ) E ( ) E (D ) E ( DI )
2
E ( ) E ( ) E ( MTTR)
D
(1 E ( DC )) E (D ) E (TI ))
2
E ( DC ) E (D ) E ( DI )
3oo3 E(F 12 ) = 3 A-35
2
E ( ) E ( MTTR)
D
The variance of the PFD of the repairable systems is found in the same manner as that in the
non-repairable cases. Once again let:
y = F(xi) (Eq A-36)
𝜕𝑦 2
𝑉(𝑦) = ∑𝑛𝑖=1 [ ] 𝑉(𝑥𝑖 ) (Eq A-37)
𝜕𝑥𝑖
Where:
V(y) = variance of random variable y as defined above
V(xi) = variance of random variable xi as defined above
The sensitivity of y with respect to a random variable 𝑥𝑖 is:
In the case of the repairable systems, there are several more potentially uncertain or random
variables:
DC is the diagnostic coverage;
DI is the diagnostic interval;
TI is the proof test interval,
λD is the dangerous failure rate;
MTTR is the mean time to restore the system to operation
is the common cause failure parameter that is always is between 0 and 1
We must evaluate the partial derivative of the PFD function with respect to each and then
combine them using equation A-37. The partial derivatives of function F7 with respect to each
random variable are found as follows
F7 D TI D DI
= (Eq A-38)
DC 2 2
F7 (1 DC) TI DC DI
= MTTR (Eq A-39)
D
2 2
F7 (1 DC) D
= (Eq A-40)
TI 2
F7 DC D
= (Eq A-41)
DI 2
F7
= D (Eq A-42)
MTTR
2
D TI D DI (1 DC) TI DC DI
2
𝑉 ( F7 ) = V(DC) + MTTR V( D )+
2 2 2 2
2 2
(1 DC) D DC D
V(TI) + (DI) +
D 2
V(MTTR) (Eq A-44)
2 2
Equation 44 represents the variance of the probability of failure on demand of the 1001
configuration when the system is repairable. We note the following relationships between the
1001, 2oo2 and 3oo3 configurations:
F10 = 2 F7 (Eq A-45)
F12 = 3 F7 (Eq A-46)
We can directly determine the variance of functions F10 and F12 from the properties of the
variance operator, V(X).
V(F10 )= V( 2 F7) (Eq A-47)
V(F10 )= 4 V(F7) (Eq A-48)
V(F12) = V(3 F7) (Eq A-49)
V(F12) = 9 V(F7) (Eq A-50)
The determination of the variance of functions F8, F10, and F11 is done in a similar manner. To
simplify the presentation of the derivation of variance of functions F8, F10, and F11, we introduce
two functions H and Q as:
(1 DC ) (1 ) D TI
H= 2 (Eq A-51)
DC (1 ) D DI
(1 ) MTTR
D
2
(1 DC) D TI DC D DI
Q= D MTTR (Eq A-52)
2 2
We note the following relationships:
F8 = H 2 + Q (Eq A-53)
F9 = H 3 + Q (Eq A-54)
F11 = 3 H2 + Q (Eq A-55)
The variance of F8, F9 and F11 are found as:
V(F8 ) = V(H2 + Q) (Eq A-56)
V(F9 ) = V(H3 + Q) (Eq A-57)
V(F11)= V(3 H2 + Q) (Eq A-58)
We will need the sensitivity of F8, F9 and F11 to each of the potential random variables.
F8 (H 2 + Q) (H 2 ) ( Q)
= = + (Eq A-59)
x x x x
Likewise
F9 (H 3 + Q) ( H 3 ) ( Q)
= = + (Eq A-60)
x x x x
F11 3(H 2 + Q) (H 2 ) ( Q)
= =3 +3 (Eq A-61)
x x x x
F9 (H) ( Q)
= 3H2 + (Eq A-63)
x x x
F11 (H) ( Q)
= 6H + (Eq A-64)
x x x
We now evaluate the derivatives of function H with respect to each potential random variables:
DC is the diagnostic coverage;
DI is the diagnostic interval;
TI is the proof test interval,
λD is the dangerous failure rate;
MTTR is the mean time to restore the system to operation
is the common cause failure parameter that is always is between 0 and 1
(H) (1 ) D TI (1 ) D DI
= (Eq A-65)
DC 2 2
(H) (1 DC) (1 ) D
= (Eq A-66)
TI 2
(1 DC) (1 ) TI
(H) 2
= (Eq A-67)
D DC (1 ) DI (1 ) MTTR
2
(H)
= (1 ) D (Eq A-68)
MTTR
(1 DC) (1) D TI
(H) 2
= (Eq A-69)
DC (1) D DI
(1) MTTR
D
2
(H) DC (1 ) D
= (Eq A-70)
DI 2
In a similar manner we evaluate the partial derivatives of function Q with respect to each
potential random variables.
(1 DC) D TI DC D DI
Q= D MTTR (Eq A-71)
2 2
DC is the diagnostic coverage;
DI is the diagnostic interval;
TI is the proof test interval,
λD is the dangerous failure rate;
MTTR is the mean time to restore the system to operation
is the common cause failure parameter that is always is between 0 and 1
(Q) (1) D TI D DI
= (Eq A-72)
DC 2 2
(Q) (1 DC) D
= (Eq A-73)
TI 2
(Q) (1 DC) TI DC DI
= MTTR (Eq A-74)
D
2 2
(Q)
= D MTTR (Eq A-75)
MTTR
(Q) (1 DC) D TI DC D DI
= D MTTR (Eq A-76)
2 2
(Q) DC D
= (Eq A-77)
DI 2
We can now determine the sensitivity of the functions F8, F9 , F11 to the random variables of
interest. Restating equation A-62 for sensitivity of F8 with respect to the random variables.
F8 (H) ( Q)
= 2H + (Eq A-78)
x x x
For F8 we find
F8 (H) ( Q)
= 2H + (Eq A-80)
x x x
(1 DC ) (1 ) D TI
F8 2
=2 [
DC DC (1 ) D DI
(1 ) D MTTR
2
(1 ) D TI (1 ) D DI
]+
2 2
(1) D TI D DI
(Eq A-79)
2 2
(1 DC ) (1 ) D TI
F8 2 (1 DC) (1 ) D
=2 [ ]+
TI DC (1 ) D DI 2
(1 ) MTTR
D
2
(1 DC) D
(Eq A-81)
2
(1 DC ) (1 ) D TI
F8 2
=2
MTTR DC (1 ) D DI
(1 ) MTTR
D
2
[ (1 ) ] + D MTTR
D
(Eq A-82)
(1 DC ) (1 ) D TI
F8 2
=2
DC (1 ) D DI
(1 ) MTTR
D
2 [
(1 DC) (1) TI
D
2 +
DC (1) D DI
(1) D MTTR
2 ]
(1 DC) D TI DC D DI
D MTTR (Eq A-83)
2 2
(1 DC ) (1 ) D TI
F8 2 DC (1 ) D
=2 [ ]+
DI DC (1 ) D DI 2
(1 ) MTTR
D
2
DC D
(Eq A-84)
2
(1 DC) (1 ) D TI (1 DC) (1 ) TI
F8 2 2
D = 2
DC (1 ) D DI DC (1 ) DI (1 ) MTTR
(1 ) MTTR
D
2 2
(1 DC) TI DC DI
+ MTTR (Eq A-85)
2 2
Using the sensitivities for F8 calculated above, the variance in F8 due to uncertain or random
variables is found as:
F F F
2 2 2
F9 (H) ( Q)
= 3H2 + (Eq A-87)
x x x
2
(1 DC) (1 ) D TI
F9 2
=3 [
DC DC (1 ) D DI
(1 ) D MTTR
2
(1 ) D TI (1 ) D DI
]+
2 2
(1) D TI D DI
(Eq A-88)
2 2
2
(1 DC) (1 ) D TI
F9 2 (1 DC) (1 ) D
=3 [ ]+
TI DC (1 ) D DI 2
(1 ) D MTTR
2
(1 DC) D
(Eq A-89)
2
2
(1 DC) (1 ) D TI
F9 2
=3 [ (1 ) D ] +
MTTR DC (1 ) DI
D
(1 ) D MTTR
2
2
(1 DC) (1 ) D TI
F9 2
=3
DC (1 ) D DI
(1 ) MTTR
D
2 [
(1 DC) (1) TI
D
2 +
DC (1) D DI
(1) D MTTR
2 ]
(1 DC) D TI DC D DI
D MTTR (Eq A-91)
2 2
2
(1 DC) (1 ) D TI
F9 2 DC (1 ) D
=3 [ ]+
DI DC (1 ) D DI 2
(1 ) D MTTR
2
DC D
(Eq A-92)
2
2
(1 DC) (1 ) D TI
F9 2
D =3
DC (1 ) D DI
(1 ) D MTTR
2
(1 DC) (1 ) TI
2
+
DC (1 ) DI (1 ) MTTR
2
(1 DC) TI DC DI
MTTR (Eq A-93)
2 2
Using the sensitivities for F9 calculated above, the variance in F9 due to uncertain or random
variables is found as:
F F
2 2
F9
2
D V( ) +
D
V(F9) = 9 V(DC) + 9 V(TI) +
DC TI
2
F9 F9 F9
2 2
(1 DC ) (1 ) D TI
F11 2
=6 [
DC DC (1 ) D DI
(1 ) D MTTR
2
(1 ) D TI (1 ) D DI
]+
2 2
(1) D TI D DI
(Eq A-96)
2 2
(1 DC ) (1 ) D TI
F11 2 (1 DC) (1 ) D
=6 [ ]+
TI DC (1 ) D DI 2
(1 ) MTTR
D
2
(1 DC) D
(Eq A-97)
2
(1 DC ) (1 ) D TI
F11 2
=6 [ (1 ) D ] +
MTTR DC (1 ) DI
D
(1 ) D MTTR
2
D MTTR (Eq A-98)
(1 DC ) (1 ) D TI
F11 2
=6
DC (1 ) D DI
(1 ) MTTR
D
2 [
(1 DC) (1) TI
D
2 +
DC (1) D DI
(1) D MTTR
2 ]
(1 DC) D TI DC D DI
D MTTR (Eq A-99)
2 2
(1 DC ) (1 ) D TI
F11 2 DC (1 ) D
=6 [ ]+
DI DC (1 ) D DI 2
(1 ) MTTR
D
2
DC D
(Eq A-100)
2
(1 DC ) (1 ) D TI
F11 2
D = 6
DC (1 ) D DI
(1 ) MTTR
D
2
(1 DC) (1 ) TI
2
+
DC (1 ) DI (1 ) MTTR
2
(1 DC) TI DC DI
MTTR (Eq A-101)
2 2
Using the sensitivities for F11 calculated above, the variance in F11 due to uncertain or random
variables is found as:
F F F
2 2 2
V( ) +
D
V( F11 ) = 11 V(DC) + 11 V(TI) + 11D
DC TI
2
F11 F11 F11
2 2
The end result of the above calculations is the determination of the mean and variance of the
configuration used in the sensor, logic solver or final control element systems. Table A.6
presents a cross reference roadmap for the determination of the mean and variance of various of
the probability of failure on demand (PFD) of various hardware configurations. The mean and
variance for the particular configuration is then returned to the overall calculations of the PFD of
the interlock.