Pointers on MTTF, MTBF, MTTFd and Availability


Some common questions have started coming up as customers increasingly design their safety systems to SIL or PL. Both of these design methods require reliability data on the components that make up the safety system. There are many acronyms floating around and some common misconceptions about their definitions, here are some explanations that may help you out:

MTTF – Mean Time To Failure
As the name suggests, this metric is the average time until a component fails, based on reliability data or testing results.

MTBF – Mean Time Between Failures
This metric is sometimes assumed to be equal to the MTTF. However the average time between failures also includes the MTTR (Mean Time To Repair) thus:
MTBF = MTTF + MTTR
If the component has a very long expected life compared to the MTTR, then the MTTF and MTBF will be very similar.

The relationship between these values determines the availability of the component:
Availability = MTTF/MTBF
As availability approaches 1, the device is operational more. The smaller the MTTR, in relation to the life of the component, the closer the availability gets to an ideal value of 1.

What's the difference between MTTFd and MTTF?
So what about the value MTTFd? Is this the same as MTTF? The answer is no, MTTFd only considers dangerous failures of the component. 

For example: If an E-Stop contact needs to open to initiate a safe stop, MTTFd will only consider the failures that cause the contact to remain closed. However MTTF would consider failures that cause the contact to remain open or closed. 

In general, if you can source one of MTTFd or MTTF, but you require the other value, there is a relationship that can be used to calculate the metric you require:
MTTF= 2 x MTTF
Hopefully this clears up any confusion you have about theses reliability metrics.

Published: 19 August 2013

What Level of Diagnostics is required for Machine Safety Systems?


When designing machine safety control systems, what level of diagnostics is appropriate? This seems to be an issue that causes confusion and inconsistency throughout the industry.

For example, if the safety system is being designed to Safety Category 3 (according to AS 4024.1501), the requirement is as follows:

“Whenever reasonably practicable the single fault should be detected…… some but not all faults will be detected”

Not surprisingly these requirements have led to many interpretations of what diagnostics should be implemented for Category 3. The application that causes most confusion is when the safety system is monitoring multiple guard doors. Can these guard doors be connected in series? If so, how many? What criterion needs to be considered?

Up until now there hasn’t been any appropriate guidance on how wiring guard doors in series degrades the level of diagnostics and what level is acceptable for the Safety Category.

New machine safety standards have now been developed to assist the designer. ISO 13849.1 is a standard that provides a method for the designer to quantify the diagnostics of their safety system, using a measure called Diagnostic Coverage (DC). Each Safety Category will have specific requirements for the DC and the designer will know exactly what level of diagnostics is required for their system.

ISO 13849.1 is a current international standard that can be sourced for your reference and this international standard will be adopted into AS 4024 in the next revision. This will provide better guidance for safety system designers in the Australian Standard.

Published: 19 June 2013

Are Safety Categories Obsolete?


Have you heard that Safety Categories are a thing of the past? That changing international standards have rendered Safety Categories redundant since the start of 2012? And that all new safety control systems for machinery must be designed to Performance Levels (PL) or Safety Integrity Levels (SIL)?

If so, here is some more information on the matter:

Yes, international standards have now moved to probabilistic methods, with two current standards as the options:
  1. IEC 62061 – Highly mathematical method where safety control systems are designed to a Safety Integrity Level (SIL)
  2. ISO 13849.1 2008 – Method based on the architecture of Safety Categories where safety control systems are designed to a Performance Level (PL)
However, Australian Standard AS 4024.1501 is a current machine safety standard where safety control systems can be designed to a Safety Category. So if you are comfortable using Safety Categories, you can continue to use this standard.

It is true that AS 4024.1 will eventually be updated to reflect current international standards, but AS 4024.1501 will remain unchanged for at least the next 3-4 years.

In my opinion, for simple safety systems, (i.e. systems using devices such as safety relays), Safety Categories is a good option that will result in a high level of integrity. If software is being designed, I would recommend following the software lifecycles available in IEC/AS 62061 or ISO 13849.1.
However, be aware that at some stage in the future our Australian Standards will transition to these probabilistic methods, but not in the immediate future.

Published: 4 April 2013