Thread Content
I’ve been studying *functional safety assessment recently, which includes the lifecycle of SIS systems and the calculations for verifying SIL levels. There’s a concept called HFT hardware fault margin – could someone please provide a thorough explanation of how this differs from the redundancy methods we use in our factories on a daily basis? Thank you so much!
This post was last edited by Yang Mingyao on 2016-12-22 at 21:00. Hello, feel free to discuss any questions you have. HFT hardware fault tolerance refers to the ability of a functional unit to continue performing its required functions in the event of a failure. The so-called hardware fault margin N means that N+1 faults will result in the loss of the safety function. So it is primarily focused on hardware; it has nothing to do with software control, nor with diagnostic techniques. For logical controllers, redundant controllers mean a fault tolerance of 1. For instruments, the core unit is usually not redundant. However, when there are two identical instruments arranged in a 1oo2 configuration, a hardware failure margin of 1 can be assumed. This is why instruments are often designed to meet the SIF2 standard; the failure fraction SFF for such instruments is generally kept around 90%. Yet manufacturers claim that two redundant instruments can achieve an SIF3 level.
What does SIF2 mean? Should it be SIL2? You must have reached this conclusion by referring to the structural constraint table for LOGIC SOLVERS in IEC61511.
This post was last edited by zxb1990 on 2017-1-28 22:44. Redundancy is a relatively broad concept; in theory, two or more channels can be considered redundant. However, HFT refers to whether there is a specific level of safety tolerance – for example, in 1oo1 we say there is no redundancy, so HFT=0; 1oo2 represents redundancy, hence HFT=1. 2oo2 is also redundant, but HFT=0