Fail-safe

Last updated

In engineering, a fail-safe is a design feature or practice that, in the event of a failure of the design feature, inherently responds in a way that will cause minimal or no harm to other equipment, to the environment or to people. Unlike inherent safety to a particular hazard, a system being "fail-safe" does not mean that failure is naturally inconsequential, but rather that the system's design prevents or mitigates unsafe consequences of the system's failure. If and when a "fail-safe" system fails, it remains at least as safe as it was before the failure. [1] [2] Since many types of failure are possible, failure mode and effects analysis is used to examine failure situations and recommend safety design and procedures. [3]

Contents

Some systems can never be made fail-safe, as continuous availability is needed. Redundancy, fault tolerance, or contingency plans are used for these situations (e.g. multiple independently controlled and fuel-fed engines). [4]

Examples

Mechanical or physical

Globe control valve with pneumatic diaphragm actuator. Such a valve can be designed to fail to safety using spring pressure if the actuating air is lost. Pl control valve.jpg
Globe control valve with pneumatic diaphragm actuator. Such a valve can be designed to fail to safety using spring pressure if the actuating air is lost.

Examples include:

Railway semaphore signals. "Stop" or "caution" is a horizontal arm, "Clear to Proceed" is 45 degrees upwards, so failure of the actuating cable releases the signal arm to safety under gravity. 130330 Thomas ELC and Wansbeck Railtour Northumberlandia 030.jpg
Railway semaphore signals. "Stop" or "caution" is a horizontal arm, "Clear to Proceed" is 45 degrees upwards, so failure of the actuating cable releases the signal arm to safety under gravity.

Electrical or electronic

Examples include:

Procedural safety

An aircraft lights its afterburners to maintain full power during an arrested landing aboard an aircraft carrier. If the arrested landing fails, the aircraft can safely take off again. FA-18-Afterburners.jpg
An aircraft lights its afterburners to maintain full power during an arrested landing aboard an aircraft carrier. If the arrested landing fails, the aircraft can safely take off again.

As well as physical devices and systems fail-safe procedures can be created so that if a procedure is not carried out or carried out incorrectly no dangerous action results. For example:

Other terminology

Fail-safe (foolproof) devices are also known as poka-yoke devices. Poka-yoke, a Japanese term, was coined by Shigeo Shingo, a quality expert. [11] [12] "Safe to fail" refers to civil engineering designs such as the Room for the River project in Netherlands and the Thames Estuary 2100 Plan [13] [14] which incorporate flexible adaptation strategies or climate change adaptation which provide for, and limit, damage, should severe events such as 500-year floods occur. [15]

Fail safe and fail secure

Fail-safe and fail-secure are distinct concepts. Fail-safe means that a device will not endanger lives or property when it fails. Fail-secure, also called fail-closed, means that access or data will not fall into the wrong hands in a security failure. Sometimes the approaches suggest opposite solutions. For example, if a building catches fire, fail-safe systems would unlock doors to ensure quick escape and allow firefighters inside, while fail-secure would lock doors to prevent unauthorized access to the building.

The opposite of fail-closed is called fail-open.

Fail active operational

Fail active operational can be installed on systems that have a high degree of redundancy so that a single failure of any part of the system can be tolerated (fail active operational) and a second failure can be detected – at which point the system will turn itself off (uncouple, fail passive). One way of accomplishing this is to have three identical systems installed, and a control logic which detects discrepancies. An example for this are many aircraft systems, among them inertial navigation systems and pitot tubes.

Failsafe point

During the Cold War, "failsafe point" was the term used for the point of no return for American Strategic Air Command nuclear bombers, just outside Soviet airspace. In the event of receiving an attack order, the bombers were required to linger at the failsafe point and wait for a second confirming order; until one was received, they would not arm their bombs or proceed further. [16] The design was to prevent any single failure of the American command system causing nuclear war. This sense of the term entered the American popular lexicon with the publishing of the 1962 novel Fail-Safe .

(Other nuclear war command control systems have used the opposite scheme, fail-deadly, which requires continuous or regular proof that an enemy first-strike attack has not occurred to prevent the launching of a nuclear strike.)

See also

Related Research Articles

<span class="mw-page-title-main">Fly-by-wire</span> Electronic flight control system

Fly-by-wire (FBW) is a system that replaces the conventional manual flight controls of an aircraft with an electronic interface. The movements of flight controls are converted to electronic signals transmitted by wires, and flight control computers determine how to move the actuators at each control surface to provide the ordered response. Implementations either use mechanical flight control backup systems or else are fully electronic.

<span class="mw-page-title-main">Relay</span> Electrically-operated switch

A relay is an electrically operated switch. It consists of a set of input terminals for a single or multiple control signals, and a set of operating contact terminals. The switch may have any number of contacts in multiple contact forms, such as make contacts, break contacts, or combinations thereof.

<span class="mw-page-title-main">Circuit breaker</span> Automatic circuit protection device

A circuit breaker is an electrical safety device designed to protect an electrical circuit from damage caused by current in excess of that which the equipment can safely carry (overcurrent). Its basic function is to interrupt current flow to protect equipment and to prevent fire. Unlike a fuse, which operates once and then must be replaced, a circuit breaker can be reset to resume normal operation.

<span class="mw-page-title-main">Thermostat</span> Component which maintains a setpoint temperature

A thermostat is a regulating device component which senses the temperature of a physical system and performs actions so that the system's temperature is maintained near a desired setpoint.

<span class="mw-page-title-main">Safety-critical system</span> System whose failure would be serious

A safety-critical system or life-critical system is a system whose failure or malfunction may result in one of the following outcomes:

<span class="mw-page-title-main">Dead man's switch</span> Equipment that activates or deactivates upon the incapacitation of operator

A dead man's switch is a switch that is designed to be activated or deactivated if the human operator becomes incapacitated, such as through death, loss of consciousness, or being bodily removed from control. Originally applied to switches on a vehicle or machine, it has since come to be used to describe other intangible uses, as in computer software.

<span class="mw-page-title-main">Emergency brake (train)</span>

On trains, the expression emergency brake has several meanings:

In electrical signalling an analog current loop is used where a device must be monitored or controlled remotely over a pair of conductors. Only one current level can be present at any time.

<span class="mw-page-title-main">Hydraulic machinery</span> Type of machine that uses liquid fluid power to perform work

Hydraulic machines use liquid fluid power to perform work. Heavy construction vehicles are a common example. In this type of machine, hydraulic fluid is pumped to various hydraulic motors and hydraulic cylinders throughout the machine and becomes pressurized according to the resistance present. The fluid is controlled directly or automatically by control valves and distributed through hoses, tubes, or pipes.

<span class="mw-page-title-main">Redundancy (engineering)</span> Duplication of critical components to increase reliability of a system

In engineering and systems theory, redundancy is the intentional duplication of critical components or functions of a system with the goal of increasing reliability of the system, usually in the form of a backup or fail-safe, or to improve actual system performance, such as in the case of GNSS receivers, or multi-threaded computer processing.

<span class="mw-page-title-main">Track circuit</span> Electrical device used to detect the presence of trains on rail tracks

A track circuit is an electrical device used to prove the absence of a train on rail tracks to signallers and control relevant signals. An alternative to track circuits are axle counters.

<span class="mw-page-title-main">Damper (flow)</span> Valve or plate for regulating airflow inside a duct, chimney, vent, etc.

A damper is a valve or plate that stops or regulates the flow of air inside a duct, chimney, VAV box, air handler, or other air-handling equipment. A damper may be used to cut off central air conditioning to an unused room, or to regulate it for room-by-room temperature and climate control - for example, in the case of Volume Control Dampers. Its operation can be manual or automatic. Manual dampers are turned by a handle on the outside of a duct. Automatic dampers are used to regulate airflow constantly and are operated by electric or pneumatic motors, in turn controlled by a thermostat or building automation system. Automatic or motorized dampers may also be controlled by a solenoid, and the degree of air-flow calibrated, perhaps according to signals from the thermostat going to the actuator of the damper in order to modulate the flow of air-conditioned air in order to effect climate control.

Fault tolerance is the ability of a system to maintain proper operation in the event of failures or faults in one or more of its components. Any decrease in operating quality is proportional to the severity of the failure, unlike a naively designed system in which even a small failure can lead to total breakdown. Fault tolerance is particularly sought after in high-availability, mission-critical, or even life-critical systems. The ability to maintain functionality when portions of a system break down is referred to as graceful degradation.

Building automation (BAS), also known as building management system (BMS) or building energy management system (BEMS), is the automatic centralized control of a building's HVAC, electrical, lighting, shading, access control, security systems, and other interrelated systems. Some objectives of building automation are improved occupant comfort, efficient operation of building systems, reduction in energy consumption, reduced operating and maintaining costs and increased security.

<span class="mw-page-title-main">Axle counter</span>

An axle counter is a system used in railway signalling to detect the clear or occupied status of a section of track between two points. The system generally consists of a wheel sensor and an evaluation unit for counting the axles of the train both into and out of the section. They are often used to replace a track circuit.

<span class="mw-page-title-main">Air brake (road vehicle)</span> Type of friction brake for vehicles

An air brake or, more formally, a compressed-air-brake system, is a type of friction brake for vehicles in which compressed air pressing on a piston is used to both release the parking/emergency brakes in order to move the vehicle, and also to apply pressure to the brake pads or brake shoes to slow and stop the vehicle. Air brakes are used in large heavy vehicles, particularly those having multiple trailers which must be linked into the brake system, such as trucks, buses, trailers, and semi-trailers, in addition to their use in railroad trains. George Westinghouse first developed air brakes for use in railway service. He patented a safer air brake on March 5, 1872. Westinghouse made numerous alterations to improve his air pressured brake invention, which led to various forms of the automatic brake. In the early 20th century, after its advantages were proven in railway use, it was adopted by manufacturers of trucks and heavy road vehicles.

A control valve is a valve used to control fluid flow by varying the size of the flow passage as directed by a signal from a controller. This enables the direct control of flow rate and the consequential control of process quantities such as pressure, temperature, and liquid level.

<span class="mw-page-title-main">Brake-by-wire</span> Automotive technology

Brake-by-wire technology in the automotive industry is the ability to control brakes through electronic means, without a mechanical connection that transfers force to the physical braking system from a driver input apparatus such as a pedal or lever.

<span class="mw-page-title-main">Valve actuator</span> Mechanism for opening and closing a valve

A valve actuator is the mechanism for opening and closing a valve. Manually operated valves require someone in attendance to adjust them using a direct or geared mechanism attached to the valve stem. Power-operated actuators, using gas pressure, hydraulic pressure or electricity, allow a valve to be adjusted remotely, or allow rapid operation of large valves. Power-operated valve actuators may be the final elements of an automatic control loop which automatically regulates some flow, level or other process. Actuators may be only to open and close the valve, or may allow intermediate positioning; some valve actuators include switches or other ways to remotely indicate the position of the valve.

A shutdown valve is an actuated valve designed to stop the flow of a hazardous fluid upon the detection of a dangerous event. This provides protection against possible harm to people, equipment or the environment. Shutdown valves form part of a safety instrumented system. The process of providing automated safety protection upon the detection of a hazardous event is called functional safety.

References

  1. "Fail-safe". AudioEnglich.net. Accessed 2009.12.31
  2. e.g., David B. Rutherford Jr., What Do You Mean It\'s Fail Safe? . 1990 Rapid Transit Conference
  3. Force V: The history of Britain's airborne deterrent, by Andrew Brookes. Jane's Publishing Co Ltd; First Edition 1 Jan. 1982, ISBN   0710602383, p.144.
  4. Bornschlegl, Susanne (2012). Ready for SIL 4: Modular Computers for Safety-Critical Mobile Applications. MEN Mikro Elektronik. Archived from the original (pdf) on 2019-06-09. Retrieved 2015-09-21.
  5. Wragg, David W. (1973). A Dictionary of Aviation (first ed.). Osprey. p. 127. ISBN   9780850451634.
  6. Bornschlegl, Susanne (2012). Ready for SIL 4: Modular Computers for Safety-Critical Mobile Applications. MEN Mikro Elektronik. Archived from the original (pdf) on 2019-06-09. Retrieved 2015-09-21.
  7. "P2138 DTC Throttle/Pedal Pos Sensor/Switch D / E Voltage Correlation". www.obd-codes.com.
  8. Manual on Uniform Traffic Control Devices, Federal Highway Administration, 2003
  9. "When Failure Is Not an Option: The Evolution of Fail-Safe Actuators". KMC Controls. 29 October 2015. Retrieved 12 April 2021.
  10. Harris, Tom (29 August 2002). "How Aircraft Carriers Work". HowStuffWorks, Inc. Retrieved 2007-10-20.
  11. Shingo, Shigeo; Andrew P. Dillon (1989). A study of the Toyota production system from an industrial engineering viewpoint. Portland, Oregon: Productivity Press. p. 22. ISBN   0-915299-17-8. OCLC   19740349
  12. John R. Grout, Brian T. Downs. "A Brief Tutorial on Mistake-proofing, Poka-Yoke, and ZQC", MistakeProofing.com Archived 2016-03-19 at the Wayback Machine
  13. "Thames Estuary 2100 Plan" (PDF). UK Environment Agency. November 2012. Archived from the original (PDF) on 2012-12-10. Retrieved March 20, 2013.
  14. "Thames Estuary 2100 (TE2100)". UK Environment Agency. Retrieved March 20, 2013.
  15. Jennifer Weeks (March 20, 2013). "Adaptation expert Paul Kirshen proposes a new paradigm for civil engineers: 'safe to fail,' not 'fail safe'". The Daily Climate. Archived from the original on May 13, 2013. Retrieved March 20, 2013.
  16. "fail-safe". Dictionary.com. Retrieved November 7, 2021.