7
Failure Rates in Accordance to IEC 61508
The following table summarizes the failure rates of the modules, which were calculated from
Failure Mode and Diagnostic Effects in accordance to standard IEC 61508. The information can
be used in calculating probability of dangerous failures using Reliability Block Modeling or Markov
Modeling. Such modeling should consider non-redundant 3132 AC output cards using the
3099/17-100 termination in a 1oo1 configuration, suitable for SIL-2 applications. Redundant 3132
AC output modules using the 3099/24-100 termination should be considered suitable for SIL-2
application as they are in a 2oo2 or 3oo3 configuration. For SIL-3 applications, the 3099/18
termination module should be used in which two redundant 3132 AC output cards operate in
1oo2 configuration.
Safe Failure Fraction:
99.65%
Diagnostic Coverage:
98.48%
Failure Rates In Common Circuitry:
Safe Detected 1.4359E-07
Safe Undetected 9.4504E-09
Dangerous Detected 3.3607E-07
Dangerous Undetected 1.7845E-09
Don't Care 2.5830E-07
Failure Rates In Per Channel Circuitry:
Safe Detected 3.6155E-08
Safe Undetected 3.6520E-10
Dangerous Detected 4.3233E-08
Dangerous Undetected 2.1725E-10
Don't Care 2.7430E-08
Average Frequency of a Dangerous Failure per Hour (1oo1):
2.0018E-09
Average Frequency of a Dangerous Failure per Hour (2oo2):
4.0035E-09
Average Frequency of a Dangerous Failure per Hour (3oo3):
6.0053E-09
Average Frequency of a Dangerous Failure per Hour (1oo2):
2.1034E-11
Mean Time to Restoration for 1oo1, 2oo2 and 3oo3 (SIL-2)
configurations:
≤ 9 days
Mean Time to Restoration for 1oo2 (SIL-3) configuration:
No
restriction
When the 3132 card is used for low-demand mode, readback (loopback) failure indications from
the card shall be monitored by operators / users. Such failure annunciation shall initiate
replacement of the module within the MTTR because the card’s ability to fail-safe might have
been lost.
Alternatively, the 3132 card can be used in high demand mode or continuous mode in which
failure annunciation shall be monitored within th
e user application logic utilizing the card’s error
status words. The user application logic in turn shall de-energize the power to the field
termination module 3099/17-100 or 3099/24-100 using an independent digital output (card &
channel) which is marked for safety. This solution provides an independent automatic means of
fail-safe action.