Skip to Main Content
Protective systems have two kinds of failures: failed dangerous (FD) and failed-safe (FS). The former can lead to serious damage to the plant, while the latter can result in financial loss because of unnecessary protective actions. Frequently, protective system channels must be maintained and repaired during plant operation, ie, while they are in service. When this happens, one must choose whether the output of a channel being maintained should be set to the on or off position. On means the protective system protects against the FD failure, and is vulnerable to FS failures. We develop a systematic method to determine the output default values, and solve the more general problem of determining the optimal logic connections for the remaining channels. Analytic formulae are presented for transition failure rates are constant with time, and the channels are in voting configurations.