DekEn
Back to studies

Validation & Methodology

Every value below is recomputed live from the shipped calculation engine, so this document cannot drift from the implementation. Print to PDF for a compliance or RFQ attachment.

View the Tool Qualification Pack →
PHA — Validation & Methodology
Drift-proof: recomputed live from the pinned engine. Indicative / screening — competent-person review required.
RevisionIssue
กด “ดาวน์โหลด PDF” แล้วเลือก Save as PDF — พิมพ์เฉพาะใบสเปกนี้ ขนาด A4
WORK PROJECT NAME:
Customer's Logo
(click to upload)
Customer's NAME
PHA QUANTITATIVE-ANALYSIS VALIDATION & METHODOLOGY
DOCUMENT NO. :
REVISION :
BY
DEKENGINEER.COM
GB R&D
(click to upload)
APPROVAL NOTE
ReviewedApproved for screening use
RESUBMIT FOR APPROVAL BY
Indicative / screening analyses only — not certification-grade. Competent-person review per IEC 61882 / IEC 61511 is required prior to issue; SIL/LOPA outputs must not be relied upon as a system of record for credited-IPL or SIS decisions without validated device FMEDA data and independent assessment.
DATE
OWNER NAME
0
IFR
 
REVISIONISSUE DATEPREPARED BYCHECKED BYAPPROVED BYREVISION STATUS
DekEn
Page 2 / 6
PHA QUANTITATIVE-ANALYSIS — VALIDATION & METHODOLOGY
IEC 61508-6 · IEC 61508-2 (Route 1H) · IEC 61508-1 · IEC 61025 · IEC 62502 · IEC 61511 · CCPS
Rev.0
SIL VERIFICATION — PFDavg (IEC 61508-6 Annex B)
Method
IEC 61508-6 Annex B B.3.2.2 — SIL verification — PFDavg by voted architecture (1oo1/1oo2/1oo2D/2oo3). PFDavg (low-demand) via the IEC 61508-6 Annex B simplified equations; λ_DU = λ_D·(1−DC), λ_DD = λ_D·DC; SIL bands per IEC 61508-1 Table 2 (SIL4 [1e-5,1e-4) · SIL3 [1e-4,1e-3) · SIL2 [1e-3,1e-2) · SIL1 [1e-2,1e-1)). Any PFDavg below 1e-4 claims SIL 4 (the classifier caps at SIL 4 — no enforced 1e-5 floor). Reference SIFs: λ_D = 1e-6/h, TI = 8760 h, MTTR = 8 h, β_D = β/2.
1oo1 · DC 0% · β 0%PFDavg = 4.39e-3 → SIL 2
1oo1 · DC 60% · β 0%PFDavg = 1.76e-3 → SIL 2
1oo2 · DC 0% · β 2%PFDavg = 1.12e-4 → SIL 3
1oo2 · DC 60% · β 5%PFDavg = 9.17e-5 → SIL 4
2oo3 · DC 0% · β 2%PFDavg = 1.62e-4 → SIL 3
2oo3 · DC 60% · β 5%PFDavg = 9.94e-5 → SIL 4
Note
At realistic β (2–5%) the common-cause term β·λ_DU·(TI/2+MTTR) dominates PFDavg (~80–95%) for every redundant architecture — β and proof-test interval matter more than the voting choice. 1oo2D uses the Hokstad-corrected closed form, cross-checked against an independent FT/Markov reference (audited).
ARCHITECTURAL CONSTRAINT — SFF × HFT (IEC 61508-2 Route 1H)
Method
IEC 61508-2:2010 Route 1H (Tables 2 & 3). The achieved SIL is capped by the hardware architecture: achieved = min(PFDavg-band SIL, architectural-constraint SIL). Element Type A = simple/well-defined failure modes; Type B = complex/programmable (more constrained). Tables rendered live from `architecturalConstraintSil`; HFT from `hardwareFaultTolerance`.
HFT — 1oo10
HFT — 1oo21
HFT — 2oo20
HFT — 1oo2D0Noteconservative (HFT excludes diagnostics)
HFT — 2oo31
Type A — max SIL
HFT 0 · HFT 1 · HFT 2
SFF < 60%SIL 1 · SIL 2 · SIL 3
SFF 60–<90%SIL 2 · SIL 3 · SIL 4
SFF 90–<99%SIL 3 · SIL 4 · SIL 4
SFF ≥ 99%SIL 3 · SIL 4 · SIL 4
Type B — max SIL
HFT 0 · HFT 1 · HFT 2
SFF < 60%not allowed · SIL 1 · SIL 2
SFF 60–<90%SIL 1 · SIL 2 · SIL 3
SFF 90–<99%SIL 2 · SIL 3 · SIL 4
SFF ≥ 99%SIL 3 · SIL 4 · SIL 4
Worked cap example — 1oo2 · DC 0 · Type BPFDavg 2.43e-4 reaches SIL 3, but SFF 0% / HFT 1 caps the claim at SIL 1 (architecture governs).
DekEn
Page 3 / 6
PHA QUANTITATIVE-ANALYSIS — VALIDATION & METHODOLOGY
IEC 61508-6 · IEC 61508-2 (Route 1H) · IEC 61508-1 · IEC 61025 · IEC 62502 · IEC 61511 · CCPS
Rev.0
FAULT TREE ANALYSIS (IEC 61025)
Method
IEC 61025 — Fault Tree Analysis — top-event probability + minimal cut sets. AND=∏pᵢ, OR=1−∏(1−pᵢ); minimal cut sets by Boolean expansion.
AND(a=0.1, b=0.2)top-event probability 0.0200 · 1 cut set(s): {a·b}
OR(a=0.1, b=0.2)top-event probability 0.2800 · 2 cut set(s): {a} {b}
EVENT TREE ANALYSIS (IEC 62502)
Method
IEC 62502 — Event Tree Analysis — outcome frequencies from pivotal events. f_IE × ∏ branch probabilities over 2ᵏ paths.
IE 2/yr · A p=0.1 · B p=0.24 outcomes, Σ = 2.00 /yr (= f_IE ✓)
Seq S-S1.44 /yr
Seq S-F0.36 /yr
Seq F-S0.16 /yr
Seq F-F0.04 /yr
DekEn
Page 4 / 6
PHA QUANTITATIVE-ANALYSIS — VALIDATION & METHODOLOGY
IEC 61508-6 · IEC 61508-2 (Route 1H) · IEC 61508-1 · IEC 61025 · IEC 62502 · IEC 61511 · CCPS
Rev.0
SCOPE, LIMITATIONS & LABELLING
Status
Indicative / screening analyses only — not certification-grade. Competent-person review per IEC 61882 / IEC 61511 is required prior to issue; SIL/LOPA outputs must not be relied upon as a system of record for credited-IPL or SIS decisions without validated device FMEDA data and independent assessment.
Scope
SIL: single + multi-element series-SIF subsystems, user-entered failure rates, PFDavg + the Route 1H architectural cap; the Hokstad 1oo2D form is audited against an independent FT/Markov reference. FTA: small trees, independent roll-up (repeated events approximate). ETA: independent branches, ≤ 12 pivotals. Deferred: spurious-trip rate, proof-test optimisation, Route 2H.
DekEn
Page 5 / 6
PHA QUANTITATIVE-ANALYSIS — VALIDATION & METHODOLOGY
IEC 61508-6 · IEC 61508-2 (Route 1H) · IEC 61508-1 · IEC 61025 · IEC 62502 · IEC 61511 · CCPS
Rev.0
RECORDS & ELECTRONIC SIGNATURES (21 CFR PART 11-ALIGNED)
Status
Documents the 21 CFR Part 11-ALIGNED records & electronic-signature controls implemented in the platform — indicative, not a certified compliance claim. Procedural controls, system validation per §11.10(a) and operator SOPs remain the deploying organisation’s responsibility.
Audit trail
Full-content audit trail: every create / update / delete on study content is recorded with the acting user, UTC time and before→after values (ORM-flush interceptor). Capture scope: unit-of-work operations — Core-level bulk operations and DB-cascade child deletes are evidenced by the parent’s delete event.
Tamper evidence
Per-study HMAC-SHA256 hash chains over canonical JSON with a genesis check; the verify endpoint re-walks the chain and recomputes every link. The evidence table is append-only (Postgres triggers) under row-level security, and evidence survives study deletion (no foreign key to studies or users).
Electronic signatures
Per-study multi-signer sign-off. The §11.50 signing manifest (printed name, date/time, meaning of signature) is captured immutably at signing; the §11.70 signature↔record link is an HMAC over the signed tuple including the content hash. Password re-authentication at signing; study content freezes from the first signature of a round; void rounds are audited with a mandatory reason and supersede — never delete — prior signatures.
Deferred
IdP re-authentication for SSO signers (today: opt-in local password — a session-holder can set one; see the Phase 5C spec); org-level retention configuration; platform-wide login-attempt lockout.
DekEn
Page 6 / 6
PHA QUANTITATIVE-ANALYSIS — VALIDATION & METHODOLOGY
IEC 61508-6 · IEC 61508-2 (Route 1H) · IEC 61508-1 · IEC 61025 · IEC 62502 · IEC 61511 · CCPS
Rev.0
PUBLIC BENCHMARK — INDEPENDENT CROSS-METHOD (arXiv:1501.06487)
Cross-method benchmark
Source (open access): F. Brissaud & L.F. Oliveira (2015), "Average probability of a dangerous failure on demand: Different modelling methods, similar results", DNV — arXiv:1501.06487. The paper computes PFDavg for a low-demand SIF by FOUR methods (multi-phase Markov, stochastic Petri nets, fault tree, DNV approximate equations) over six parameter sets; Markov ≈ Petri is the reference, the fault tree reads ≤3.5% higher, the DNV equations up to ~28.5% higher (case vi). DekEn computes the IEC 61508-6 Annex B SIMPLIFIED equations — a FIFTH, independent method. Every DekEn PFDavg below is recomputed LIVE from the shipped engine (computeSifVerification), so this page cannot drift from the implementation. DekEn’s imperfect-proof-test residual is ARCHITECTURE-AWARE: the revealed fraction PTC·λ_DU behaves at the proof-test interval, and the never-revealed (1−PTC)·λ_DU fraction is routed THROUGH the voting structure over the equipment life T0 (CCF-floored at β·λ_DUU·T0/2 for a redundant group), exactly as the paper treats it. AGREEMENT — all six cases land within ±15% of the published spread. The 1oo1 cases (i, ii) land at/inside the published cluster. The redundant cases (iii–vi, 1oo2 / 2oo3) read 0.9–12% BELOW the paper’s Markov/Petri reference — the recognised, slightly non-conservative gap of the IEC 61508-6 simplified equations vs an exact state model (the dominant β-floor term is fully retained). No case is buried under a loose tolerance; the band is set from the measured worst gap (case v, −12.1%). DEFERRED: the IEC 61508-6 Annex B and ISA-TR84.00.02 worked-example benchmarks are pending purchase of those standards and are not included here.
Case i — 1oo1, λ_D 2.70e-6/h, DC 50%, PTC 90%, T1 6 moDekEn PFDavg = 7.46e-3 · published 7.41e-3–7.46e-3 · Δ +0.0% vs published — within ±15% ✓
Case ii — 1oo1, λ_D 1.35e-5/h, DC 25%, PTC 70%, T1 12 moDekEn PFDavg = 1.38e-1 · published 1.24e-1–1.38e-1 · Δ +0.0% vs published — within ±15% ✓
Case iii — 1oo2, λ_D 2.70e-6/h, DC 50%, PTC 90%, T1 6 moDekEn PFDavg = 4.08e-4 · published 4.29e-4–4.31e-4 · Δ -4.8% vs published — within ±15% (simplified eq. vs Markov reference) ✓
Case iv — 1oo2, λ_D 1.35e-5/h, DC 25%, PTC 70%, T1 12 moDekEn PFDavg = 2.71e-2 · published 2.83e-2–3.25e-2 · Δ -4.2% vs published — within ±15% (simplified eq. vs Markov reference) ✓
Case v — 2oo3, λ_D 2.70e-6/h, DC 50%, PTC 90%, T1 6 moDekEn PFDavg = 4.81e-4 · published 5.47e-4–5.49e-4 · Δ -12.1% vs published — within ±15% (simplified eq. vs Markov reference) ✓
Case vi — 2oo3, λ_D 1.35e-5/h, DC 25%, PTC 70%, T1 12 moDekEn PFDavg = 5.38e-2 · published 5.43e-2–6.98e-2 · Δ -0.9% vs published — within ±15% (simplified eq. vs Markov reference) ✓
ดูเวอร์ชันข้อความ (สำหรับวางในอีเมล)
=== PHA Validation & Methodology ===
IEC 61508-6 · IEC 61508-2 (Route 1H) · IEC 61508-1 · IEC 61025 · IEC 62502 · IEC 61511 · CCPS

-- COVER --
PROJECT          : PHA Quantitative-Analysis Validation
BY DEKENGINEER.COM
DATE / OWNER     : — / —


-- 1. SIL VERIFICATION — PFDavg (IEC 61508-6 Annex B) --
Method: IEC 61508-6 Annex B B.3.2.2 — SIL verification — PFDavg by voted architecture (1oo1/1oo2/1oo2D/2oo3).
PFDavg (low-demand) via the IEC 61508-6 Annex B simplified equations; λ_DU = λ_D·(1−DC), λ_DD = λ_D·DC; SIL bands per IEC 61508-1 Table 2 (SIL4 [1e-5,1e-4) · SIL3 [1e-4,1e-3) · SIL2 [1e-3,1e-2) · SIL1 [1e-2,1e-1)). Any PFDavg below 1e-4 claims SIL 4 (the classifier caps at SIL 4 — no enforced 1e-5 floor). Reference SIFs: λ_D = 1e-6/h, TI = 8760 h, MTTR = 8 h, β_D = β/2.
1oo1 · DC 0% · β 0%           : PFDavg = 4.39e-3 → SIL 2
1oo1 · DC 60% · β 0%          : PFDavg = 1.76e-3 → SIL 2
1oo2 · DC 0% · β 2%           : PFDavg = 1.12e-4 → SIL 3
1oo2 · DC 60% · β 5%          : PFDavg = 9.17e-5 → SIL 4
2oo3 · DC 0% · β 2%           : PFDavg = 1.62e-4 → SIL 3
2oo3 · DC 60% · β 5%          : PFDavg = 9.94e-5 → SIL 4
Note: At realistic β (2–5%) the common-cause term β·λ_DU·(TI/2+MTTR) dominates PFDavg (~80–95%) for every redundant architecture — β and proof-test interval matter more than the voting choice. 1oo2D uses the Hokstad-corrected closed form, cross-checked against an independent FT/Markov reference (audited).

-- 2. ARCHITECTURAL CONSTRAINT — SFF × HFT (IEC 61508-2 Route 1H) --
Method: IEC 61508-2:2010 Route 1H (Tables 2 & 3). The achieved SIL is capped by the hardware architecture: achieved = min(PFDavg-band SIL, architectural-constraint SIL). Element Type A = simple/well-defined failure modes; Type B = complex/programmable (more constrained). Tables rendered live from `architecturalConstraintSil`; HFT from `hardwareFaultTolerance`.
HFT — 1oo1                    : 0
HFT — 1oo2                    : 1
HFT — 2oo2                    : 0
HFT — 1oo2D                   : 0
Note                          : conservative (HFT excludes diagnostics)
HFT — 2oo3                    : 1
Type A — max SIL: HFT 0 · HFT 1 · HFT 2
SFF < 60%                     : SIL 1  ·  SIL 2  ·  SIL 3
SFF 60–<90%                   : SIL 2  ·  SIL 3  ·  SIL 4
SFF 90–<99%                   : SIL 3  ·  SIL 4  ·  SIL 4
SFF ≥ 99%                     : SIL 3  ·  SIL 4  ·  SIL 4
Type B — max SIL: HFT 0 · HFT 1 · HFT 2
SFF < 60%                     : not allowed  ·  SIL 1  ·  SIL 2
SFF 60–<90%                   : SIL 1  ·  SIL 2  ·  SIL 3
SFF 90–<99%                   : SIL 2  ·  SIL 3  ·  SIL 4
SFF ≥ 99%                     : SIL 3  ·  SIL 4  ·  SIL 4
Worked cap example — 1oo2 · DC 0 · Type B: PFDavg 2.43e-4 reaches SIL 3, but SFF 0% / HFT 1 caps the claim at SIL 1 (architecture governs).

-- 3. FAULT TREE ANALYSIS (IEC 61025) --
Method: IEC 61025 — Fault Tree Analysis — top-event probability + minimal cut sets. AND=∏pᵢ, OR=1−∏(1−pᵢ); minimal cut sets by Boolean expansion.
AND(a=0.1, b=0.2)             : top-event probability 0.0200 · 1 cut set(s): {a·b}
OR(a=0.1, b=0.2)              : top-event probability 0.2800 · 2 cut set(s): {a} {b}

-- 4. EVENT TREE ANALYSIS (IEC 62502) --
Method: IEC 62502 — Event Tree Analysis — outcome frequencies from pivotal events. f_IE × ∏ branch probabilities over 2ᵏ paths.
IE 2/yr · A p=0.1 · B p=0.2   : 4 outcomes, Σ = 2.00 /yr (= f_IE ✓)
Seq S-S                       : 1.44 /yr
Seq S-F                       : 0.36 /yr
Seq F-S                       : 0.16 /yr
Seq F-F                       : 0.04 /yr

-- 5. SCOPE, LIMITATIONS & LABELLING --
Status: Indicative / screening analyses only — not certification-grade. Competent-person review per IEC 61882 / IEC 61511 is required prior to issue; SIL/LOPA outputs must not be relied upon as a system of record for credited-IPL or SIS decisions without validated device FMEDA data and independent assessment.
Scope: SIL: single + multi-element series-SIF subsystems, user-entered failure rates, PFDavg + the Route 1H architectural cap; the Hokstad 1oo2D form is audited against an independent FT/Markov reference. FTA: small trees, independent roll-up (repeated events approximate). ETA: independent branches, ≤ 12 pivotals. Deferred: spurious-trip rate, proof-test optimisation, Route 2H.

-- 6. RECORDS & ELECTRONIC SIGNATURES (21 CFR PART 11-ALIGNED) --
Status: Documents the 21 CFR Part 11-ALIGNED records & electronic-signature controls implemented in the platform — indicative, not a certified compliance claim. Procedural controls, system validation per §11.10(a) and operator SOPs remain the deploying organisation’s responsibility.
Audit trail: Full-content audit trail: every create / update / delete on study content is recorded with the acting user, UTC time and before→after values (ORM-flush interceptor). Capture scope: unit-of-work operations — Core-level bulk operations and DB-cascade child deletes are evidenced by the parent’s delete event.
Tamper evidence: Per-study HMAC-SHA256 hash chains over canonical JSON with a genesis check; the verify endpoint re-walks the chain and recomputes every link. The evidence table is append-only (Postgres triggers) under row-level security, and evidence survives study deletion (no foreign key to studies or users).
Electronic signatures: Per-study multi-signer sign-off. The §11.50 signing manifest (printed name, date/time, meaning of signature) is captured immutably at signing; the §11.70 signature↔record link is an HMAC over the signed tuple including the content hash. Password re-authentication at signing; study content freezes from the first signature of a round; void rounds are audited with a mandatory reason and supersede — never delete — prior signatures.
Deferred: IdP re-authentication for SSO signers (today: opt-in local password — a session-holder can set one; see the Phase 5C spec); org-level retention configuration; platform-wide login-attempt lockout.

-- 7. PUBLIC BENCHMARK — INDEPENDENT CROSS-METHOD (arXiv:1501.06487) --
Cross-method benchmark: Source (open access): F. Brissaud & L.F. Oliveira (2015), "Average probability of a dangerous failure on demand: Different modelling methods, similar results", DNV — arXiv:1501.06487. The paper computes PFDavg for a low-demand SIF by FOUR methods (multi-phase Markov, stochastic Petri nets, fault tree, DNV approximate equations) over six parameter sets; Markov ≈ Petri is the reference, the fault tree reads ≤3.5% higher, the DNV equations up to ~28.5% higher (case vi).

DekEn computes the IEC 61508-6 Annex B SIMPLIFIED equations — a FIFTH, independent method. Every DekEn PFDavg below is recomputed LIVE from the shipped engine (computeSifVerification), so this page cannot drift from the implementation. DekEn’s imperfect-proof-test residual is ARCHITECTURE-AWARE: the revealed fraction PTC·λ_DU behaves at the proof-test interval, and the never-revealed (1−PTC)·λ_DU fraction is routed THROUGH the voting structure over the equipment life T0 (CCF-floored at β·λ_DUU·T0/2 for a redundant group), exactly as the paper treats it.

AGREEMENT — all six cases land within ±15% of the published spread. The 1oo1 cases (i, ii) land at/inside the published cluster. The redundant cases (iii–vi, 1oo2 / 2oo3) read 0.9–12% BELOW the paper’s Markov/Petri reference — the recognised, slightly non-conservative gap of the IEC 61508-6 simplified equations vs an exact state model (the dominant β-floor term is fully retained). No case is buried under a loose tolerance; the band is set from the measured worst gap (case v, −12.1%).

DEFERRED: the IEC 61508-6 Annex B and ISA-TR84.00.02 worked-example benchmarks are pending purchase of those standards and are not included here.
Case i — 1oo1, λ_D 2.70e-6/h, DC 50%, PTC 90%, T1 6 mo: DekEn PFDavg = 7.46e-3 · published 7.41e-3–7.46e-3 · Δ +0.0% vs published — within ±15% ✓
Case ii — 1oo1, λ_D 1.35e-5/h, DC 25%, PTC 70%, T1 12 mo: DekEn PFDavg = 1.38e-1 · published 1.24e-1–1.38e-1 · Δ +0.0% vs published — within ±15% ✓
Case iii — 1oo2, λ_D 2.70e-6/h, DC 50%, PTC 90%, T1 6 mo: DekEn PFDavg = 4.08e-4 · published 4.29e-4–4.31e-4 · Δ -4.8% vs published — within ±15% (simplified eq. vs Markov reference) ✓
Case iv — 1oo2, λ_D 1.35e-5/h, DC 25%, PTC 70%, T1 12 mo: DekEn PFDavg = 2.71e-2 · published 2.83e-2–3.25e-2 · Δ -4.2% vs published — within ±15% (simplified eq. vs Markov reference) ✓
Case v — 2oo3, λ_D 2.70e-6/h, DC 50%, PTC 90%, T1 6 mo: DekEn PFDavg = 4.81e-4 · published 5.47e-4–5.49e-4 · Δ -12.1% vs published — within ±15% (simplified eq. vs Markov reference) ✓
Case vi — 2oo3, λ_D 1.35e-5/h, DC 25%, PTC 70%, T1 12 mo: DekEn PFDavg = 5.38e-2 · published 5.43e-2–6.98e-2 · Δ -0.9% vs published — within ±15% (simplified eq. vs Markov reference) ✓

=== END ===