Abstract: | This paper evaluates reliability and fail-safety of a two unit cold standby fail-safe redundant system. Three modes of failure—(1) failure due to human error, (2) failure due to unit faults and (3) failure due to switchover faults—are considered. The complete failure states of the system are divided into two categories, fail-safe state and fail-dangerous state. Several fail-safety measures of interest to a fail-safe system designer are defined and evaluated, such as safety function, safety ratio and danger ratio. |