{"title":"Applying Safety Concepts and Principles in Vital Controller Design","authors":"F. Shi","doi":"10.56094/jss.v56i1.31","DOIUrl":null,"url":null,"abstract":"A vital controller is safety critical and its failures, if not mitigated in time, can contribute to hazards in the application system. With electronics advancing and automation increasing, the expanding complexity of a vital controller creates challenges in designing it and assessing its safety integrity level. Typically, traditional safety engineering approaches are not effective for providing systematic guidance to design vital controllers and also not cost efficient for justifying their safety integrity. Through practice on developing multiple Communications-Based Train Control systems, we have identified an approach to using a set of safety concepts as guidance for both safety critical controller design and its safety integrity assessment. These safety concepts are categorized as intrinsic fail-safe, reactive fail-safe, and composite fail-safe. An effective combination of them is applying the composite fail-safe concept in checked redundancy techniques for designing the architecture of a controller, the reactive safety concept for identifying self-testing and monitoring mechanisms in each checked redundant channel, and the intrinsic fail-safe concept for ensuring safe interfaces to other controllers and controlled devices. This paper presents the approach for using these safety concepts and discusses their application principles and verification factors for achieving high safety integrity level of a controller.","PeriodicalId":250838,"journal":{"name":"Journal of System Safety","volume":"515 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2020-07-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Journal of System Safety","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.56094/jss.v56i1.31","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0
Abstract
A vital controller is safety critical and its failures, if not mitigated in time, can contribute to hazards in the application system. With electronics advancing and automation increasing, the expanding complexity of a vital controller creates challenges in designing it and assessing its safety integrity level. Typically, traditional safety engineering approaches are not effective for providing systematic guidance to design vital controllers and also not cost efficient for justifying their safety integrity. Through practice on developing multiple Communications-Based Train Control systems, we have identified an approach to using a set of safety concepts as guidance for both safety critical controller design and its safety integrity assessment. These safety concepts are categorized as intrinsic fail-safe, reactive fail-safe, and composite fail-safe. An effective combination of them is applying the composite fail-safe concept in checked redundancy techniques for designing the architecture of a controller, the reactive safety concept for identifying self-testing and monitoring mechanisms in each checked redundant channel, and the intrinsic fail-safe concept for ensuring safe interfaces to other controllers and controlled devices. This paper presents the approach for using these safety concepts and discusses their application principles and verification factors for achieving high safety integrity level of a controller.