TUV ASI TÜV Cooperation Functional Safety
(Home)
TÜV Süddeutschland

System structures

The nomenclature for system structures describes the possible degradation behaviour after fault detection and fault localisation for the central processing units. Variations are possible due to different implementation possibilities. This table shall give a first guideline.

In the I/O area different degradation mechanisms are possible and implemented on the different systems.

 

Fault-free system Degradation 1 Degradation 2 Degradation 3 System structure
2oo4 1oo2 Shutdown   Safety related and fault tolerant
1oo3 Shutdown     Safety related
2oo3 1oo2 1oo1* Shutdown Safety related and fault tolerant

*with time restriction
2oo3 1oo2 Shutdown   Safety related and fault tolerant
1oo2D 1oo1D Shutdown   Safety related and fault tolerant
with time restriction
1oo2 Shutdown     Safety related
2oo2 1oo1 Shutdown   Safety related and fault tolerant
1oo1 Shutdown     Safety related

  Part 4 of the IEC 61508 gives the defintion of
MooN : M out of N channel architecture (for example 1oo2 is 1 out of 2 architecture, where either of the two channels can perform the safety function)
MooND :
M out of N channel architecture with diagnostic


  last change : 14. May 2003 


TÜV Rheinland Group
Industrial Services

Automation - Software - Information Technology (ASI)

Germany : Heinz Gall ph: +49-221-806-1790
USA : Matthias Haynl ph: +1-203-426-0888
Japan : Joachim Iden ph: +81-6-6355-5732

Homepage: http://tuvasi.com
TÜV SÜD Group
TÜV Automotive / TÜV Product Service
Automation, Software and Electronics
Ridlerstrasse 65
D-80339 Munich/Germany

Nat. / Internat. : Jürgen Blum ph: +49-89-5791-2275
Nat. / Internat. : Alfred Beer ph: +49-89-5791-2278
USA : Markus Weber ph: +1-858-566-2556
Japan : Tetsuro Kushiyama ph: +81-3-3372-4294

Homepage: http://www.tuev-sued.de/iqse