Hardware Fault Tolerance: 5 Essential Rules for Better SIS

Share:
Safety Systems
Hardware Fault Tolerance: 5 Essential Rules for Better SIS

A safety function can have an excellent PFD on paper and still fail its SIL claim because the architecture is too thin. Learn how HFT and safe failure fraction set the minimum redundancy for every sensor, logic solver and valve.

HFT and MooN Safe Failure Fraction Route 1H and 2H IEC 61511 Table 6

Architectural constraints decide how much redundancy a safety instrumented function must have, regardless of how good its PFD calculation looks. This guide explains HFT, SFF, Type A and B elements and both IEC 61508 routes with worked examples.

Hello everyone, today we are going to learn what hardware fault tolerance means in a safety instrumented system, how safe failure fraction is calculated and how Route 1H, Route 2H and IEC 61511 set the minimum redundancy.
hardware fault tolerance

What Is Hardware Fault Tolerance?

Hardware fault tolerance is the number of dangerous hardware faults a subsystem can suffer while still performing its safety function, so HFT 0 means one dangerous fault can disable it. It is one of the three pillars of SIL verification, alongside random failure probability and systematic capability.

PR electronics puts it simply: 1oo1 equals HFT 0 and 1oo2 equals HFT 1. In other words, HFT counts redundant channels, and the voting arrangements covered in voting architectures in safety systems are how engineers build it in practice.

Table of minimum HFT requirements per SIL and demand mode according to IEC 61511
Image credit: PR electronics. Table courtesy of PR electronics, shown here for educational reference.

The requirement is called an architectural constraint because it limits the SIL you may claim for a given architecture. Even if your PFD average meets the target band in the SIL table, a single channel valve cannot be claimed for SIL 3 under IEC 61511 without the redundancy the table demands.

Advertisement
Do You Know?

Before the 2010 second edition of IEC 61508, there were no separate Route 1H and Route 2H options. exida notes that the revision also removed no effect failures from the SFF calculation, so manufacturers could no longer inflate SFF by adding extra components.

MooN Voting and HFT Relationship

For any M out of N voting group, HFT equals N minus M. The group trips when M channels demand a trip, so N minus M channels can fail dangerously and the function still works.

VotingChannelsHFTMain BenefitMain Weakness
1oo110Simple, low costOne dangerous fault defeats it
1oo221High safetySpurious trip if either channel fails safe
2oo220Few spurious tripsOne dangerous fault defeats it
2oo331Safety plus availabilityMore hardware and wiring
1oo332Highest safetyHighest spurious trip tendency

Notice that 2oo2 has two transmitters but still an HFT of 0, because a single dangerous failure blocks the trip. The popular 2oo3 voting logic gives HFT 1 and also tolerates one safe failure without tripping the plant.

Quick Tip

When you write the safety requirements, state the HFT for each subsystem separately: sensors, logic solver and final elements. A SIF is only as fault tolerant as its weakest subsystem.

Safe Failure Fraction and How It Is Calculated

Safe failure fraction, or SFF, is the share of all failures that are either safe or dangerous but detected by diagnostics. PR electronics describes it as the percentage of safe and dangerous detected failures versus total failures, and our article on safe failure fraction covers it in more depth.

SFF = (λS + λDD) ÷ (λS + λDD + λDU) × 100
DC = λDD ÷ (λDD + λDU) × 100

λ values in FIT, where 1 FIT = 1 failure per 10⁹ hours

Example, smart transmitter:
λS = 300 FIT, λDD = 450 FIT, λDU = 50 FIT
Total = 300 + 450 + 50 = 800 FIT
SFF = 750 ÷ 800 × 100 = 93.75 percent
DC = 450 ÷ 500 × 100 = 90 percent
Type B, SFF 90 to 99 percent, HFT 1 gives up to SIL 3

The λ values come from the FMEDA report or certificate of the device. A high SFF tells you that most dangerous faults will be caught by diagnostics and turned into an alarm or safe action, leaving few undetected dangerous failures.

Type A and Type B Elements

Type A Element

Simple device with well defined failure modes and behaviour under fault, with solid field data.

Best for: relays, solenoid valves, mechanical valves, simple switches
Simple
Type B Element

Complex device, usually with a microprocessor or software, where some failure modes are not fully known.

Best for: smart transmitters, safety PLCs, digital positioners
Complex

The type matters because Route 1H allows a Type A element a higher SIL than a Type B element at the same SFF and HFT. A SIS final element made of a valve, actuator and solenoid is usually Type A, while a smart positioner added to it is Type B.

Route 1H Hardware Fault Tolerance Tables

Route 1H, from IEC 61508 Part 2, uses the device type and its SFF to find the maximum SIL allowed for each HFT. The two tables below are the heart of hardware fault tolerance under Route 1H.

SFFType A HFT 0Type A HFT 1Type A HFT 2Type B HFT 0Type B HFT 1Type B HFT 2
Below 60 %SIL 1SIL 2SIL 3Not allowedSIL 1SIL 2
60 to 90 %SIL 2SIL 3SIL 4SIL 1SIL 2SIL 3
90 to 99 %SIL 3SIL 4SIL 4SIL 2SIL 3SIL 4
99 % and aboveSIL 3SIL 4SIL 4SIL 3SIL 4SIL 4

Read the table as a ceiling. If a Type B transmitter has an SFF of 85 percent, one transmitter can support at most SIL 1, and a 1oo2 pair can support at most SIL 2.

HFT 01oo1 or 2oo2
HFT 11oo2 or 2oo3
60 %SFF limit for single Type B
90 %Route 2H data confidence
Advertisement

Route 2H and Proven Field Data

Route 2H replaces the SFF tables with a fixed HFT per SIL, but only when failure rate data is collected from similar applications and environments. exida stresses that the data must reach a 90 percent statistical confidence level, which needs a disciplined field feedback system.

Under Route 2H, SIL 4 needs HFT 2, SIL 3 needs HFT 1, SIL 2 needs HFT 1 in high demand mode and HFT 0 in low demand mode, and SIL 1 needs HFT 0. Mirek Generowicz of TÜV Rheinland notes that this route lets SIL 3 be met with two valves instead of three.

His paper also points out that failure rates stated at 90 percent confidence are typically about 1.6 times higher than those at 70 percent confidence. The price of the simpler architecture is therefore a more conservative PFD calculation.

Do You Know?

PR electronics notes that IEC 61511 clause 11.4.9 accepts reliability data at a 70 percent upper confidence limit for its own prior use route. That is lower than the 90 percent confidence demanded by Route 2H in IEC 61508.

IEC 61511 2016 Hardware Fault Tolerance Table

The 2016 edition of IEC 61511 Part 1 simplified the process sector rules into a single table, similar to Route 2H. It applies to the whole subsystem, whether the elements are Type A or Type B.

SILDemand ModeMinimum HFTTypical Architecture
SIL 1Any mode01oo1 sensor and valve
SIL 2Low demand01oo1 with good data
SIL 2High or continuous11oo2 or 2oo3
SIL 3Any mode11oo2 or 2oo3
SIL 4Any mode21oo3, rarely used in process

The standard also allows the required HFT to be reduced by one for SIL 1 to SIL 3 where added redundancy would cause more process safety problems, for example extra spurious trips during a dangerous startup. Such a decision must be justified and recorded, and it is reviewed during the functional safety assessment.

5 Essential Rules for HFT Compliance

1
Define the Target
Take the SIL and demand mode from the SRS for each SIF.
2
Split Subsystems
Treat sensors, logic solver and final elements separately.
3
Pick the Route
Use IEC 61511 Table 6, Route 1H or Route 2H consistently.
4
Collect Device Data
Get type, SFF, λ values and certificates from FMEDA reports.
5
Check and Record
Compare achieved HFT with required HFT and document any reduction.

These five rules keep hardware fault tolerance checks repeatable from one SIF to the next. Use the same route for every subsystem of a SIF unless your company procedure clearly allows mixing, and keep the risk target from LOPA SIL assessment at the top of the worksheet.

Safe Failure Fraction Calculator

SFF and Route 1H Maximum SIL
Result
SFF 93.75 percent, DC 90.0 percent, Type B with HFT 1 allows up to SIL 3

Second Worked Example: Shutdown Valve for SIL 3

Consider a fail safe shutdown valve assembly treated as a Type A element with λS = 200 FIT, λDD = 0 FIT and λDU = 600 FIT, since a valve has no automatic diagnostics without partial stroke testing. Its SFF is 200 ÷ 800 × 100 = 25 percent.

Under Route 1H, a Type A element below 60 percent SFF needs HFT 2 for SIL 3, which means three valves in series. Under IEC 61511 Table 6 or Route 2H with good field data, two valves in 1oo2 give HFT 1 and meet the requirement, and partial stroke testing can still improve the PFD.

Advertisement
Quick Tip

Before you add a third valve to satisfy Route 1H, check whether your plant procedure allows IEC 61511 Table 6 with prior use data. Fewer valves often mean fewer leak paths, lower spurious trip rates and simpler maintenance.

Common Hardware Fault Tolerance Mistakes

Myth: Two transmitters always give HFT 1.
Fact: A 2oo2 arrangement has HFT 0, because one dangerous fault blocks the trip.
Myth: A low PFD means the architecture is acceptable.
Fact: HFT is a separate requirement, and a SIF can pass PFD yet fail its architectural constraint.
Myth: A SIL 3 certified device can be used alone in a SIL 3 SIF.
Fact: The certificate usually states the HFT needed, and many SIL 3 claims assume a redundant pair.
Myth: Redundancy alone guarantees safety.
Fact: Common cause failures, such as a shared impulse line or plugged tapping, can defeat both channels.

Common cause is the quiet enemy of redundancy. Two transmitters on one impulse line, or two valves supplied by one air header, behave closer to one channel, so use separate tapping points and review shared utilities as you would in emergency shutdown system design.

Field Checklist for HFT Verification

  • SIL and demand mode confirmed for every SIF in the SRS.
  • Voting of each subsystem written as MooN with its hardware fault tolerance.
  • Device type A or B taken from the certificate or FMEDA.
  • SFF and DC values recorded with the data source.
  • Route 1H, Route 2H or IEC 61511 Table 6 stated clearly.
  • Common cause sources checked: taps, power, air, cables.
  • Any HFT reduction justified and approved.
  • Proof test interval and coverage linked to the PFD calculation.
Advantages of Hardware Fault Tolerance
  • Survives one or more dangerous faults.
  • Protects against optimistic failure data.
  • 2oo3 also cuts spurious trips.
  • Allows online repair of one channel.
Limitations and Trade Offs
  • More hardware cost and wiring.
  • 1oo2 and 1oo3 raise spurious trip tendency.
  • Common cause can defeat redundancy.
  • More devices to proof test and maintain.

Where Hardware Fault Tolerance Matters Most

Furnace and Boiler Trips
Flame failure and low drum level SIFs with redundant sensors.
Compressor Protection
High discharge pressure and surge related trips.
Reactor Shutdown
High temperature and pressure SIFs at SIL 2 or SIL 3.
Tank Overfill Protection
Independent high high level switches and valves.
Pipeline ESD
Remote shutdown valves on hydrocarbon lines.

For Indian refineries, fertiliser plants and petrochemical units, HFT reviews usually take place during detailed engineering and again at the FAT. Clear separation of SIS and control hardware, explained in SIS and BPCS differences, makes the HFT argument much easier to defend.

Architectural Constraints Paper and Video

PDF
Achieving Compliance in Hardware Fault Tolerance
Mirek Generowicz, Safety Control Systems Conference, 61508 Association

Hardware Fault Tolerance FAQ

What is hardware fault tolerance?

It is the number of dangerous hardware faults a subsystem can tolerate while still performing its safety function. An HFT of 1 means the function survives any single dangerous fault.

It is calculated as N minus M for an M out of N voting group. A 1oo2 pair therefore has HFT 1, while a 2oo2 pair has HFT 0.

What is safe failure fraction?

Safe failure fraction is the share of all failures that are safe or dangerous but detected by diagnostics. It is calculated from the λS, λDD and λDU values in the FMEDA report.

A high SFF means few dangerous failures remain hidden. Under Route 1H, a higher SFF lets the same device support a higher SIL with the same redundancy.

What is the difference between Route 1H and Route 2H?

Route 1H finds the allowed SIL from the element type, its SFF and the fault tolerance of the design. It uses two tables in IEC 61508 Part 2, one for Type A and one for Type B elements.

Route 2H instead sets a fixed HFT for each SIL level and demand mode. It requires field failure data collected from similar applications with 90 percent statistical confidence.

How much HFT does IEC 61511 require for SIL 3?

The 2016 edition of IEC 61511 requires a minimum HFT of 1 for SIL 3 in any demand mode. In practice that means a 1oo2 or 2oo3 arrangement for sensors and final elements.

SIL 1 needs HFT 0, and SIL 2 needs HFT 0 in low demand mode. SIL 2 in high demand mode needs HFT 1, and SIL 4 needs HFT 2.

Is a Type A element better than a Type B element?

Not always, because the type only describes how well the failure behaviour is understood. Type A devices are simple, while Type B devices contain software or complex electronics.

Under Route 1H, Type A gets a higher SIL ceiling at the same safe failure fraction. A Type B smart transmitter with strong diagnostics can still reach a high SFF and a high SIL claim.

Can hardware fault tolerance requirements be reduced?

IEC 61511 allows a reduction of one in the required HFT for SIL 1 to SIL 3 in specific cases. The usual reason is that extra redundancy would create more process safety problems than it solves.

The justification must be documented and approved by competent people. It is checked again during the functional safety assessment before the system is put into service.

Does redundancy protect against common cause failure?

No, redundancy only helps if the channels fail independently of each other. A shared impulse line, power supply or instrument air header can disable every redundant channel at once.

Use separate process taps, diverse routing and independent utilities where possible. The PFD calculation should also include a realistic beta factor for the remaining common cause.

Advertisement

Related Articles

External References

What We Learn Today

  • Hardware fault tolerance is the number of dangerous faults a subsystem can survive, and for any MooN voting group it equals N minus M.
  • Safe failure fraction is (λS + λDD) ÷ (λS + λDD + λDU), and Route 1H uses it with the Type A or B tables.
  • IEC 61511 2016 requires HFT 1 for SIL 3 and HFT 0 for SIL 1, close to Route 2H, which needs field data at 90 percent confidence.
I hope you like above blog. There is no cost associated in sharing the article in your social media. Thanks for reading!! Happy Learning!!

Leave a Reply

Your email address will not be published. Required fields are marked *