Fail-safe explained

In engineering, a fail-safe is a design feature or practice that, in the event of a failure of the design feature, inherently responds in a way that will cause minimal or no harm to other equipment, to the environment or to people. Unlike inherent safety to a particular hazard, a system being "fail-safe" does not mean that failure is naturally inconsequential, but rather that the system's design prevents or mitigates unsafe consequences of the system's failure. If and when a "fail-safe" system fails, it remains at least as safe as it was before the failure.[1] [2] Since many types of failure are possible, failure mode and effects analysis is used to examine failure situations and recommend safety design and procedures.[3]

Some systems can never be made fail-safe, as continuous availability is needed. Redundancy, fault tolerance, or contingency plans are used for these situations (e.g. multiple independently controlled and fuel-fed engines).[4]

Examples

Mechanical or physical

Examples include:

Electrical or electronic

Examples include:

Procedural safety

As well as physical devices and systems fail-safe procedures can be created so that if a procedure is not carried out or carried out incorrectly no dangerous action results. For example:

Other terminology

Fail-safe (foolproof) devices are also known as poka-yoke devices. Poka-yoke, a Japanese term, was coined by Shigeo Shingo, a quality expert.[11] [12] "Safe to fail" refers to civil engineering designs such as the Room for the River project in Netherlands and the Thames Estuary 2100 Plan[13] [14] which incorporate flexible adaptation strategies or climate change adaptation which provide for, and limit, damage, should severe events such as 500-year floods occur.[15]

Fail safe and fail secure

Fail-safe and fail-secure are distinct concepts. Fail-safe means that a device will not endanger lives or property when it fails. Fail-secure, also called fail-closed, means that access or data will not fall into the wrong hands in a security failure. Sometimes the approaches suggest opposite solutions. For example, if a building catches fire, fail-safe systems would unlock doors to ensure quick escape and allow firefighters inside, while fail-secure would lock doors to prevent unauthorized access to the building.

The opposite of fail-closed is called fail-open.

Fail active operational

Fail active operational can be installed on systems that have a high degree of redundancy so that a single failure of any part of the system can be tolerated (fail active operational) and a second failure can be detected – at which point the system will turn itself off (uncouple, fail passive). One way of accomplishing this is to have three identical systems installed, and a control logic which detects discrepancies. An example for this are many aircraft systems, among them inertial navigation systems and pitot tubes.

Failsafe point

During the Cold War, "failsafe point" was the term used for the point of no return for American Strategic Air Command nuclear bombers, just outside Soviet airspace. In the event of receiving an attack order, the bombers were required to linger at the failsafe point and wait for a second confirming order; until one was received, they would not arm their bombs or proceed further.[16] The design was to prevent any single failure of the American command system causing nuclear war. This sense of the term entered the American popular lexicon with the publishing of the 1962 novel Fail-Safe. (Other nuclear war command control systems have used the opposite scheme, fail-deadly, which requires continuous or regular proof that an enemy first-strike attack has not occurred to prevent the launching of a nuclear strike.)

See also

Notes and References

  1. "Fail-safe". AudioEnglich.net. Accessed 2009.12.31
  2. e.g., David B. Rutherford Jr., What Do You Mean It\'s Fail Safe? . 1990 Rapid Transit Conference
  3. Force V: The history of Britain's airborne deterrent, by Andrew Brookes. Jane's Publishing Co Ltd; First Edition 1 Jan. 1982,, p.144.
  4. Book: Bornschlegl , Susanne . Ready for SIL 4: Modular Computers for Safety-Critical Mobile Applications . MEN Mikro Elektronik . 2012 . pdf . 2015-09-21 . 2019-06-09 . https://web.archive.org/web/20190609205912/https://www.menmicro.com/downloads/search/dl/sk/%22White%20Paper%3A%20Ready%20for%20SIL4%3A%20Modular%20Computers%20for%20Safety-Critical%20Mobile%20Applications%22/dx/1/ . dead.
  5. Book: Wragg, David W. . A Dictionary of Aviation . 9780850451634 . first . Osprey . 1973 . 127.
  6. Book: Bornschlegl , Susanne . Ready for SIL 4: Modular Computers for Safety-Critical Mobile Applications . MEN Mikro Elektronik . 2012 . pdf . 2015-09-21 . 2019-06-09 . https://web.archive.org/web/20190609205912/https://www.menmicro.com/downloads/search/dl/sk/%22White%20Paper%3A%20Ready%20for%20SIL4%3A%20Modular%20Computers%20for%20Safety-Critical%20Mobile%20Applications%22/dx/1/ . dead.
  7. Web site: P2138 DTC Throttle/Pedal Pos Sensor/Switch D / E Voltage Correlation. www.obd-codes.com.
  8. Manual on Uniform Traffic Control Devices, Federal Highway Administration, 2003
  9. Web site: When Failure Is Not an Option: The Evolution of Fail-Safe Actuators . 29 October 2015 . KMC Controls . 12 April 2021 .
  10. Web site: Tom. Harris. How Aircraft Carriers Work. HowStuffWorks, Inc. 29 August 2002 . 2007-10-20.
  11. Shingo, Shigeo; Andrew P. Dillon (1989). A study of the Toyota production system from an industrial engineering viewpoint. Portland, Oregon: Productivity Press. p. 22. .
  12. John R. Grout, Brian T. Downs. "A Brief Tutorial on Mistake-proofing, Poka-Yoke, and ZQC", MistakeProofing.com
  13. Web site: Thames Estuary 2100 Plan . http://webarchive.nationalarchives.gov.uk/20121210131034/http://www.environment-agency.gov.uk/static/documents/Leisure/SE_TE2100_briefing.pdf . dead . 2012-12-10 . UK Environment Agency . March 20, 2013 . November 2012 .
  14. Web site: Thames Estuary 2100 (TE2100). UK Environment Agency. March 20, 2013.
  15. News: Adaptation expert Paul Kirshen proposes a new paradigm for civil engineers: 'safe to fail,' not 'fail safe'. March 20, 2013. The Daily Climate. March 20, 2013. Jennifer Weeks. dead. https://web.archive.org/web/20130513080832/http://wwwp.dailyclimate.org/tdc-newsroom/2013/03/flexible-infrastructure-climate-stress. May 13, 2013.
  16. Web site: fail-safe . Dictionary.com . November 7, 2021.