RAMSynapse
Log inSign up

Reliability Block Diagram · Chapter 4

Worked Example

The method applied end-to-end on a concrete system, with numbers.

Consider the instrument-air supply of a water treatment works: the compressors, dryers, receiver and header that keep every pneumatically actuated valve on the site able to move. It is deliberately neither the gas compressor train the industry examples carry nor the interlocking controller the allocation module budgets, and its numbers belong to neither. Every value below is an illustrative teaching figure; the arithmetic is the method's.

The success criterion, agreed before anything was drawn: dry air above 6 bar at the actuator header, continuously, for the 720 hours between planned maintenance windows. The site cannot run on half pressure and cannot run on wet air, and 720 hours is the interval at which everything is inspected anyway.

The blocks

The instrument-air supply as reliability logic: a series inlet, a bridged pair of compressor and dryer trains, a single receiver and header, and a 2oo3 pressure vote. Rates in failures per 10⁶ hours, mission 720 hours.
The instrument-air supply as reliability logic: a series inlet, a bridged pair of compressor and dryer trains, a single receiver and header, and a 2oo3 pressure vote. Rates in failures per 10⁶ hours, mission 720 hours.
Blockλ per 10⁶ hR(720)Position in the logic
F · Intake filter and inlet3.00.997842Series, alone
C1, C2 · Screw compressors120 each0.917227Left side of the bridge
X · Cross-tie between the trains250.982161The bridge element
D1, D2 · Desiccant dryers60 each0.957720Right side of the bridge
V · Air receiver8.00.994257Series, alone
H · Header and isolation5.00.996406Series, alone
P1, P2, P3 · Pressure transmitters40 each0.9716112-out-of-3 vote

The plant is built as two independent compressor-and-dryer trains with a cross-tie between them, which is exactly a bridge: C1 can feed D2 and C2 can feed D1, but only through X. The transmitters are voted 2-out-of-3, so the control loop survives one of them failing.

The bridge, three ways

Conditioning on the cross-tie splits the structure into two that collapse. With X healthy the compressors are a parallel pair in series with a parallel pair of dryers:

R(X works) = [1 − (1 − 0.917227)²] × [1 − (1 − 0.957720)²] = 0.993149 × 0.998212 = 0.991373

With X failed the two trains are independent paths:

R(X failed) = 1 − (1 − 0.917227 × 0.957720)² = 1 − 0.121554² = 0.985225

Rbridge = 0.982161 × 0.991373 + 0.017839 × 0.985225 = 0.991264

Enumerating all 32 states of the five elements returns the same 0.991264, and the minimal-cut bound returns 0.991250, fourteen parts per million low. The minimal-path bound returns 0.999722, which is not an answer to anything.

What the cross-tie is worth is visible in those two conditional lines. Without it the bridge would be 0.985225; with a perfect one it would be 0.991373. The real tie, at 25 per 10⁶ hours, delivers 0.991264: it buys 0.604 percentage points of reliability and its own unreliability gives back 0.011 of them. A cheap element in the right place is worth more than an expensive one in the wrong place, and this is the arithmetic that says so.

The vote and the system

The 2-out-of-3 transmitter group, from the binomial with R = 0.971611:

Rvote = 3R² − 2R³ = 2.832087 − 1.834458 = 0.997628

The five groups are in series, so they multiply:

Rsys(720) = 0.997842 × 0.991264 × 0.994257 × 0.996406 × 0.997628 = 0.977585

Two point two four per cent of maintenance intervals lose instrument air. For comparison, the same eleven blocks summed as a series chain, which is what a parts-count prediction returns, come to 521 per 10⁶ hours: an MTBF of 1,919 hours and R(720) = 0.687. The structure is worth a factor of fourteen on the shortfall, and the difference is entirely the success criterion.

Where the 2.24 per cent goes

The shortfall by contributor. The four redundant machines and their cross-tie account for 38.7 per cent of it; the three items with nothing standing behind them for just over half, and the receiver alone for more than the whole instrument vote.
The shortfall by contributor. The four redundant machines and their cross-tie account for 38.7 per cent of it; the three items with nothing standing behind them for just over half, and the receiver alone for more than the whole instrument vote.
GroupIts unreliabilityShare of the summed contributions
The bridge: 4 machines and a cross-tie8.74 × 10⁻³38.7%
V · air receiver5.74 × 10⁻³25.4%
H · header and isolation3.59 × 10⁻³15.9%
P · the 2oo3 vote2.37 × 10⁻³10.5%
F · intake filter2.16 × 10⁻³9.5%

Read by cut-set order the same result is starker. The three order-1 cuts, the filter, the receiver and the header on their own, carry 51.3 per cent of the shortfall between them. The order-2 cuts (both compressors, both dryers, or two of the three transmitters) carry 49.0 per cent, and everything requiring three simultaneous failures carries 0.7. Summed as though the cuts were disjoint they give 0.022631 against the exact 0.022415, the 1 per cent difference being the overlap the rare-event approximation ignores.

The design conversation follows directly, and it is not the one the plant expected:

ChangeR(720)Shortfall removed
As built0.9775850%
A second air receiver0.98320025%
A third compressor on the duty side0.98381728%
A second receiver and a duplicated header0.98673341%
Halving the rate of every block in the plant0.99140862%

A pressure vessel with no moving parts buys almost exactly what a third screw compressor buys, for a small fraction of the money, because the vessel is an order-1 cut and the compressor is already the third element of an order-2 one. This is the whole argument for drawing the diagram before choosing what to buy.

Would a standby have been better than a running pair?

The compressor function taken on its own, at 120 per 10⁶ hours a unit and the same 720-hour mission:

ArrangementR(720)MTTF
One compressor0.9172278,333 h
Two running in parallel0.99314912,500 h
One duty, one cold spare, perfect start0.99647616,667 h
One duty, one cold spare, 95 per cent start0.99251316,250 h

The last two rows are the lesson. A cold spare that starts 95 times in a hundred has the longer mean life of the two real options, 16,250 hours against 12,500, and the worse mission reliability, 0.9925 against 0.9931. Setting the two expressions equal puts the break-even start probability at 0.958: below that the running pair wins the mission, above it the spare does, and the mean life says the opposite throughout. Which number the plant should optimise is settled by the criterion in the first paragraph, not by the tables.

What the model is still assuming

Both compressors are the same model from the same supplier, commissioned in the same week, maintained by the same crew on the same day. The base result treats their failures as independent, which is the most optimistic claim in the whole calculation.

β on the compressor pairSystem R(720)Probability the mission fails
0, the independence assumption0.9775852.24%
0.020.9761552.38%
0.050.9740052.60%
0.100.9704092.96%
0.200.9631703.68%

At β = 0.10 the shared-cause term contributes 0.86 percentage points on its own, which is more than the pair contributed in total when the failures were independent, and it is in series with the group: a third compressor does not touch it. Staggering the two overhauls so the pair is never opened in the same week is a procedural change that costs nothing and moves this table further than any hardware on it.

Two other assumptions are worth stating because they are invisible in the arithmetic. Nothing is repaired inside the 720 hours, so the answer is a floor rather than an estimate for a plant that can fix a compressor in a day. And the mission starts with everything working, which is untrue of any site that defers a defect to the next window.


Want to see this on a live system model? Request a walkthrough.