PHA — Validation & Methodology
Drift-proof: recomputed live from the pinned engine. Indicative / screening — competent-person review required.
WORK PROJECT NAME:
Customer's Logo
Customer's NAME
PHA QUANTITATIVE-ANALYSIS
VALIDATION & METHODOLOGY
DOCUMENT NO. :
REVISION :
BY
DEKENGINEER.COM
GB R&D
APPROVAL NOTE
ReviewedApproved for screening use
RESUBMIT FOR APPROVAL BY
Indicative / screening analyses only — not certification-grade. Competent-person review per IEC 61882 / IEC 61511 is required prior to issue; SIL/LOPA outputs must not be relied upon as a system of record for credited-IPL or SIS decisions without validated device FMEDA data and independent assessment.
DATE
OWNER NAME
| 0 | IFR | ||||
| REVISION | ISSUE DATE | PREPARED BY | CHECKED BY | APPROVED BY | REVISION STATUS |
DekEn Page 2 / 6 | PHA QUANTITATIVE-ANALYSIS — VALIDATION & METHODOLOGY IEC 61508-6 · IEC 61508-2 (Route 1H) · IEC 61508-1 · IEC 61025 · IEC 62502 · IEC 61511 · CCPS | Rev.0 | |
| SIL VERIFICATION — PFDavg (IEC 61508-6 Annex B) | |||
Method IEC 61508-6 Annex B B.3.2.2 — SIL verification — PFDavg by voted architecture (1oo1/1oo2/1oo2D/2oo3).
PFDavg (low-demand) via the IEC 61508-6 Annex B simplified equations; λ_DU = λ_D·(1−DC), λ_DD = λ_D·DC; SIL bands per IEC 61508-1 Table 2 (SIL4 [1e-5,1e-4) · SIL3 [1e-4,1e-3) · SIL2 [1e-3,1e-2) · SIL1 [1e-2,1e-1)). Any PFDavg below 1e-4 claims SIL 4 (the classifier caps at SIL 4 — no enforced 1e-5 floor). Reference SIFs: λ_D = 1e-6/h, TI = 8760 h, MTTR = 8 h, β_D = β/2. | |||
| 1oo1 · DC 0% · β 0% | PFDavg = 4.39e-3 → SIL 2 | ||
| 1oo1 · DC 60% · β 0% | PFDavg = 1.76e-3 → SIL 2 | ||
| 1oo2 · DC 0% · β 2% | PFDavg = 1.12e-4 → SIL 3 | ||
| 1oo2 · DC 60% · β 5% | PFDavg = 9.17e-5 → SIL 4 | ||
| 2oo3 · DC 0% · β 2% | PFDavg = 1.62e-4 → SIL 3 | ||
| 2oo3 · DC 60% · β 5% | PFDavg = 9.94e-5 → SIL 4 | ||
Note At realistic β (2–5%) the common-cause term β·λ_DU·(TI/2+MTTR) dominates PFDavg (~80–95%) for every redundant architecture — β and proof-test interval matter more than the voting choice. 1oo2D uses the Hokstad-corrected closed form, cross-checked against an independent FT/Markov reference (audited). | |||
| ARCHITECTURAL CONSTRAINT — SFF × HFT (IEC 61508-2 Route 1H) | |||
Method IEC 61508-2:2010 Route 1H (Tables 2 & 3). The achieved SIL is capped by the hardware architecture: achieved = min(PFDavg-band SIL, architectural-constraint SIL). Element Type A = simple/well-defined failure modes; Type B = complex/programmable (more constrained). Tables rendered live from `architecturalConstraintSil`; HFT from `hardwareFaultTolerance`. | |||
| HFT — 1oo1 | 0 | ||
| HFT — 1oo2 | 1 | ||
| HFT — 2oo2 | 0 | ||
| HFT — 1oo2D | 0 | Note | conservative (HFT excludes diagnostics) |
| HFT — 2oo3 | 1 | ||
Type A — max SIL HFT 0 · HFT 1 · HFT 2 | |||
| SFF < 60% | SIL 1 · SIL 2 · SIL 3 | ||
| SFF 60–<90% | SIL 2 · SIL 3 · SIL 4 | ||
| SFF 90–<99% | SIL 3 · SIL 4 · SIL 4 | ||
| SFF ≥ 99% | SIL 3 · SIL 4 · SIL 4 | ||
Type B — max SIL HFT 0 · HFT 1 · HFT 2 | |||
| SFF < 60% | not allowed · SIL 1 · SIL 2 | ||
| SFF 60–<90% | SIL 1 · SIL 2 · SIL 3 | ||
| SFF 90–<99% | SIL 2 · SIL 3 · SIL 4 | ||
| SFF ≥ 99% | SIL 3 · SIL 4 · SIL 4 | ||
| Worked cap example — 1oo2 · DC 0 · Type B | PFDavg 2.43e-4 reaches SIL 3, but SFF 0% / HFT 1 caps the claim at SIL 1 (architecture governs). | ||
DekEn Page 3 / 6 | PHA QUANTITATIVE-ANALYSIS — VALIDATION & METHODOLOGY IEC 61508-6 · IEC 61508-2 (Route 1H) · IEC 61508-1 · IEC 61025 · IEC 62502 · IEC 61511 · CCPS | Rev.0 | |
| FAULT TREE ANALYSIS (IEC 61025) | |||
Method IEC 61025 — Fault Tree Analysis — top-event probability + minimal cut sets. AND=∏pᵢ, OR=1−∏(1−pᵢ); minimal cut sets by Boolean expansion. | |||
| AND(a=0.1, b=0.2) | top-event probability 0.0200 · 1 cut set(s): {a·b} | ||
| OR(a=0.1, b=0.2) | top-event probability 0.2800 · 2 cut set(s): {a} {b} | ||
| EVENT TREE ANALYSIS (IEC 62502) | |||
Method IEC 62502 — Event Tree Analysis — outcome frequencies from pivotal events. f_IE × ∏ branch probabilities over 2ᵏ paths. | |||
| IE 2/yr · A p=0.1 · B p=0.2 | 4 outcomes, Σ = 2.00 /yr (= f_IE ✓) | ||
| Seq S-S | 1.44 /yr | ||
| Seq S-F | 0.36 /yr | ||
| Seq F-S | 0.16 /yr | ||
| Seq F-F | 0.04 /yr | ||
DekEn Page 4 / 6 | PHA QUANTITATIVE-ANALYSIS — VALIDATION & METHODOLOGY IEC 61508-6 · IEC 61508-2 (Route 1H) · IEC 61508-1 · IEC 61025 · IEC 62502 · IEC 61511 · CCPS | Rev.0 | |
| SCOPE, LIMITATIONS & LABELLING | |||
Status Indicative / screening analyses only — not certification-grade. Competent-person review per IEC 61882 / IEC 61511 is required prior to issue; SIL/LOPA outputs must not be relied upon as a system of record for credited-IPL or SIS decisions without validated device FMEDA data and independent assessment. | |||
Scope SIL: single + multi-element series-SIF subsystems, user-entered failure rates, PFDavg + the Route 1H architectural cap; the Hokstad 1oo2D form is audited against an independent FT/Markov reference. FTA: small trees, independent roll-up (repeated events approximate). ETA: independent branches, ≤ 12 pivotals. Deferred: spurious-trip rate, proof-test optimisation, Route 2H. | |||
DekEn Page 5 / 6 | PHA QUANTITATIVE-ANALYSIS — VALIDATION & METHODOLOGY IEC 61508-6 · IEC 61508-2 (Route 1H) · IEC 61508-1 · IEC 61025 · IEC 62502 · IEC 61511 · CCPS | Rev.0 | |
| RECORDS & ELECTRONIC SIGNATURES (21 CFR PART 11-ALIGNED) | |||
Status Documents the 21 CFR Part 11-ALIGNED records & electronic-signature controls implemented in the platform — indicative, not a certified compliance claim. Procedural controls, system validation per §11.10(a) and operator SOPs remain the deploying organisation’s responsibility. | |||
Audit trail Full-content audit trail: every create / update / delete on study content is recorded with the acting user, UTC time and before→after values (ORM-flush interceptor). Capture scope: unit-of-work operations — Core-level bulk operations and DB-cascade child deletes are evidenced by the parent’s delete event. | |||
Tamper evidence Per-study HMAC-SHA256 hash chains over canonical JSON with a genesis check; the verify endpoint re-walks the chain and recomputes every link. The evidence table is append-only (Postgres triggers) under row-level security, and evidence survives study deletion (no foreign key to studies or users). | |||
Electronic signatures Per-study multi-signer sign-off. The §11.50 signing manifest (printed name, date/time, meaning of signature) is captured immutably at signing; the §11.70 signature↔record link is an HMAC over the signed tuple including the content hash. Password re-authentication at signing; study content freezes from the first signature of a round; void rounds are audited with a mandatory reason and supersede — never delete — prior signatures. | |||
Deferred IdP re-authentication for SSO signers (today: opt-in local password — a session-holder can set one; see the Phase 5C spec); org-level retention configuration; platform-wide login-attempt lockout. | |||
DekEn Page 6 / 6 | PHA QUANTITATIVE-ANALYSIS — VALIDATION & METHODOLOGY IEC 61508-6 · IEC 61508-2 (Route 1H) · IEC 61508-1 · IEC 61025 · IEC 62502 · IEC 61511 · CCPS | Rev.0 | |
| PUBLIC BENCHMARK — INDEPENDENT CROSS-METHOD (arXiv:1501.06487) | |||
Cross-method benchmark Source (open access): F. Brissaud & L.F. Oliveira (2015), "Average probability of a dangerous failure on demand: Different modelling methods, similar results", DNV — arXiv:1501.06487. The paper computes PFDavg for a low-demand SIF by FOUR methods (multi-phase Markov, stochastic Petri nets, fault tree, DNV approximate equations) over six parameter sets; Markov ≈ Petri is the reference, the fault tree reads ≤3.5% higher, the DNV equations up to ~28.5% higher (case vi).
DekEn computes the IEC 61508-6 Annex B SIMPLIFIED equations — a FIFTH, independent method. Every DekEn PFDavg below is recomputed LIVE from the shipped engine (computeSifVerification), so this page cannot drift from the implementation. DekEn’s imperfect-proof-test residual is ARCHITECTURE-AWARE: the revealed fraction PTC·λ_DU behaves at the proof-test interval, and the never-revealed (1−PTC)·λ_DU fraction is routed THROUGH the voting structure over the equipment life T0 (CCF-floored at β·λ_DUU·T0/2 for a redundant group), exactly as the paper treats it.
AGREEMENT — all six cases land within ±15% of the published spread. The 1oo1 cases (i, ii) land at/inside the published cluster. The redundant cases (iii–vi, 1oo2 / 2oo3) read 0.9–12% BELOW the paper’s Markov/Petri reference — the recognised, slightly non-conservative gap of the IEC 61508-6 simplified equations vs an exact state model (the dominant β-floor term is fully retained). No case is buried under a loose tolerance; the band is set from the measured worst gap (case v, −12.1%).
DEFERRED: the IEC 61508-6 Annex B and ISA-TR84.00.02 worked-example benchmarks are pending purchase of those standards and are not included here. | |||
| Case i — 1oo1, λ_D 2.70e-6/h, DC 50%, PTC 90%, T1 6 mo | DekEn PFDavg = 7.46e-3 · published 7.41e-3–7.46e-3 · Δ +0.0% vs published — within ±15% ✓ | ||
| Case ii — 1oo1, λ_D 1.35e-5/h, DC 25%, PTC 70%, T1 12 mo | DekEn PFDavg = 1.38e-1 · published 1.24e-1–1.38e-1 · Δ +0.0% vs published — within ±15% ✓ | ||
| Case iii — 1oo2, λ_D 2.70e-6/h, DC 50%, PTC 90%, T1 6 mo | DekEn PFDavg = 4.08e-4 · published 4.29e-4–4.31e-4 · Δ -4.8% vs published — within ±15% (simplified eq. vs Markov reference) ✓ | ||
| Case iv — 1oo2, λ_D 1.35e-5/h, DC 25%, PTC 70%, T1 12 mo | DekEn PFDavg = 2.71e-2 · published 2.83e-2–3.25e-2 · Δ -4.2% vs published — within ±15% (simplified eq. vs Markov reference) ✓ | ||
| Case v — 2oo3, λ_D 2.70e-6/h, DC 50%, PTC 90%, T1 6 mo | DekEn PFDavg = 4.81e-4 · published 5.47e-4–5.49e-4 · Δ -12.1% vs published — within ±15% (simplified eq. vs Markov reference) ✓ | ||
| Case vi — 2oo3, λ_D 1.35e-5/h, DC 25%, PTC 70%, T1 12 mo | DekEn PFDavg = 5.38e-2 · published 5.43e-2–6.98e-2 · Δ -0.9% vs published — within ±15% (simplified eq. vs Markov reference) ✓ | ||