Professional Documents
Culture Documents
Mbsa s1 - Intro Et Fmea
Mbsa s1 - Intro Et Fmea
Mbsa s1 - Intro Et Fmea
Faïda MHENNI
Phd. Eng. Associate Professor
Institut Supérieur de Mécanique de Paris – ISAE-SUPMECA
Introduction
Terminology
Safety Standards
REQUIRMENTS IMPLEMENTATION
Why are we still using systems despite the inherent mishap risk?
Faïda Mhenni - faida.mhenni@supmeca.fr 5
Introduction: Risk Acceptance
• Risks Acceptability :
• benefit from the use of technical systems
• balance between frequency of occurrence and severity of
consequences
o Quantitative safety analysis: evaluate the reliability using statistical techniques and methods
and/or
o Confidentiality Dependability
o Integrity
o Vol 2:
tige vis
Tige seule
Plan arrière
(insuffisant pour Tige cassée
flottant
supporter l’effort)
29
Safety Analysis Approaches
o …
o Examples: Failure mode and effects analysis (FMEA), HAZard and OPerability
analysis (HAZOP)
o Examples: Fault tree analysis (FTA), Event tree analysis (ETA), Common cause
failure analysis (CCFA)
o Markov Chains
o Petri Nets
o …
o AltaRica
• L The use of system models (that are abstractions of the system defined with an
intended goal in mind) may impose undue constraints on the safety assessment
leading to incomplete analysis results with respect to the real-world behavior of the
system
• J Models are created for the goal of safety assessment à avoid unnecessary
complexity.
• L Losing the provable validity of the safety analysis results with respect to design, and
replacing consistency by construction with some form of traceability between models
in design and safety domains.
[Ericson 2005]
o Detection: rates the likelihood that the problem will be detected before it results
in a mishap.
RPN = 𝑆 # 𝑂 # 𝐷
t t t t t
Function Loss No Function (fails to start) Operates inadvertently Performs incorrectly Fails to stop
o intermittent failure
Hazardous with Affects safe vehicle operation and/or involves non-compliance with 9
warning government regulations with warning
Very High Vehicle/item inoperable with loss of primary function 8
High Vehicle/item operable but at reduced level of performance. Customer 7
dissatisfied
Moderate Vehicle/item operable but comfort/ convenience item inoperable. Customer 6
experiences discomfort
Low Vehicle/item operable but comfort/ convenience item operable but at 5
reduced level of performance. Customer experiences some dissatisfaction
Very low Fit & Finish/Squeak & Rattle item does not conform. Defect noticed by 4
most customers
Minor Fit & Finish/Squeak & Rattle item does not conform. Defect noticed by 3
average customer.
Very Minor Fit & Finish/Squeak & Rattle item does not conform. Defect noticed by 2
discriminating customers
None No Effect 1
Faïda Mhenni - faida.mhenni@supmeca.fr 47
Example of occurrence probability ranking
Probability of Possible Failure Rates Ranking
Failure
Very High: >= 1 in 2 10
failure is almost
inevitable 1 in 3 9
High: repeated 1 in 8 8
failures
1 in 20 7
Moderate: 1 in 80 6
occasional
failures 1 in 400 5
1 in 2.000 4
Low: relatively 1 in 15.000 3
few failures
1 in 150.000 2
Remote: failure <= 1 in 1.500.000 1
is unlikely
Absolute Design control will not and/or cannot detect a potential cause/mechanism 10
Uncertainty and subsequent failure mode, or there is no Design Control
Very Remote Very remote chance the Design Control will detect a potential 9
cause/mechanism and subsequent failure mode
Remote Remote chance the Design Control will detect a potential cause/mechanism 8
and subsequent failure mode
Very Low Very low chance the Design Control will detect a potential 7
cause/mechanism and subsequent failure mode
Low Low chance the Design Control will detect a potential cause/mechanism 6
and subsequent failure mode
Moderate Moderate chance the Design Control will detect a potential 5
cause/mechanism and subsequent failure mode
Moderately high Moderately high chance the Design Control will detect a potential 4
cause/mechanism and subsequent failure mode
High High chance the Design Control will detect a potential cause/mechanism 3
and subsequent failure mode
Very High Very High chance the Design Control will detect a potential 2
cause/mechanism and subsequent failure mode
Almost Certain Design Control will almost certainly detect a potential cause/mechanism 1
and subsequent failure mode
o Failure Mode 2:
• Severity: Minor (3);
o When battery power is desired, the squib is fired to break the membrane, and
the released electrolyte energizes the battery.
(Boîtier)
(Amorceur)
(Plaques et
cosses)
Squib