Fusa_017_System Safety Concept_Fail-safe vs Fail-operational

来源:公众号“功能安全沙龙”
2020-04-26
1991

As I have worked in the Automotive Engineering Service Field for 4 years(5 years OEM experience+ 4 years automotive engineering service), serveral functional safety engineers of my customers told me that they need their Hybrid Control Units have the fail-operational capability when they are doing the functional safety development.  It took me a lot of time to explain why it make no sense to do fail-operational concept for a fail-safe system. Today, let us have a look at them.

There are a lot of system safety concepts existing on the market for different safety purposes like human safety,finance safety, data safety,equipment safety… .  I tried to list some of them below, but only th safety concept used in the automotive industry will be addressed this blog today:

·       Fail-safe

·       Fail-passive

·       Fail-tolerant

·       Fail-operational

·       Fail-secure

·       Fail-deadly.

Fail-safe concept is used for the safety-related system which goes into safe mode when a critical failure occurs and being detected. The fail-safe concept is widely used in the industries like medical E/E systems, railway control systems, nuclear control systems and automotive E/E systems.
Famously, nuclear weapon systems that launch-on-command are fail-safe, because if the communication systems fail, launch cannot be commanded. Railway signaling is designed to be fail-safe.


 An example for the fail-safe concept applications in automotive field is the Engine Control Unit, it can fail, and as long as it stops the engine and alerts the driver, it will not lead to accident which could threaten the loss of people's life or injury perple as its safety interval is long enough to permit the driver or other participants response correctly.  This means that by going into a safe mode via loss of the functions or deactivating the systems in case of any safety-related faults are detected, the fail-safe system could ensure that the people in the control loop or involved in the hazard events could control or migitate hazard within the safety time interval.Following the same safety concept, the Hybrid Control Unit or Vehicle Control Unit, Transmission Control Unit are also designed to be fail-safe.

Fault-tolerant safety concept is used for the systems which avoid service failure when the system recognizes that it is receiving the wrong information.An example may include control systems for ordinary nuclear reactors. The normal method to tolerate faults is to have several computers continually test the parts of a system, and switch on hot spares for failing subsystems. As long as faulty subsystems are replaced or repaired at normal maintenance intervals, these systems are considered safe. Interestingly, the computers, power supplies and control terminals used by human beings must all be duplicated in these systems in some fashion.Fail-operational safety concept is used for the systems which continue to operate when one of their control systems fail.Examples of these include elevators,the gas thermostats in most home furnaces, and passively safe nuclear reactors. Nuclear weapons launch-on-loss-of-communications was rejected as a control system for the U.S. nuclear forces because it is fail-operational:  a loss of communications would cause launch, so this mode of operation was considered too risky.For the ADAS systems or AD systems in the automotive field, fail-operational safety concept could be required in case that some functions failed while the safety interval is not long enough to ensure driver take over the vehicle in time. Another typical application in automotive field of fail-operational safety concept is the EPS system. It will keep providing the steering assistance in case that one of the safety-related components or elements of the system is failed. That is because that the driver or other person involved in the hazard event couldn't handle the malfuction behavior of the EPS correctly within the safety time interval.

Fail-secure concept is used for the systems could maintain maximum security when they cannot operate.For example, the electronic door control systems which are used for information sensitive areas or finance areas will lock the door to keep the maximum security  in case of power failures. In contrast with the fail-secure systems, the fail-safe system will unlock the door in case of power failure. By apllcation of fail-safe concept, unlock the door could ensure that the people inside the door could safely escape the dangerous situations like fire or earthquake within the safety time interval.In automotive field, the fail-secure safety concept could be used for the connected vehicles for cybersecurity issues.

Another application of fail-secure safety concept is the control or service systems in the bank, In case that any faults could violate the secure requirements, the system will go into the maximum security mode to protect the property and the client's privacy.

5-  Reference

[1] Bing images

[2] Three things to know about functional safety, by NXP

[3] https://en.wikipedia.org/wiki/Safety-critical_system



收藏
点赞
2000