RAMSynapse
Log inSign up

Reliability Allocation · Chapter 4

Worked Example

The method applied end-to-end on a concrete system, with numbers.

Consider a level-crossing wayside controller for a light-rail operator: the trackside electronics that reads the axle counters, decides the crossing state, drives the barriers and lamps, and reports to the control centre. The procurement contract sets its reliability target: MTBF ≥ 20,000 hours. Four subsystems, four different design owners, and no detailed design yet. Every number below is an illustrative teaching value; the arithmetic is the method's.

The target converts to the working currency first: λ* = 10⁶ / 20,000 = 50 failures per 10⁶ hours of rate budget to distribute.

The worked cascade: the 50 f/10⁶ h budget split over four subsystems by feasibility-of-objectives ratings, then the interlocking logic unit's 17.49 split over its three assemblies by ARINC against an early prediction. Both sums close exactly.
The worked cascade: the 50 f/10⁶ h budget split over four subsystems by feasibility-of-objectives ratings, then the interlocking logic unit's 17.49 split over its three assemblies by ARINC against an early prediction. Both sums close exactly.

Level 1: feasibility of objectives

At this stage nothing exists but the architecture and engineering judgement, so the level-1 split uses feasibility-of-objectives ratings, scored 1–10 against written ground rules and reconciled between two senior engineers:

SubsystemIntricacyState of artPerf. timeEnvironmentWeight wShareλ (f/10⁶ h)Allocated MTBF
A · Axle-counter interface538784019.1%9.56104,600 h
B · Interlocking logic unit86841,53635.0%17.4957,200 h
C · Trackside power module428957613.1%6.56152,400 h
D · Communications gateway65861,44032.8%16.3961,000 h
Σ4,392100%50.0

Reading the ratings: everything operates continuously (performance time 8 across the board), the interlocking unit is the most intricate and least proven (8 and 6), the power module is simple mature technology but the most exposed (environment 9), and the gateway sits in the middle on everything. The multiplication does the rest: the two hard subsystems claim two-thirds of the failure allowance between them, and the simple, exposed power module is asked to be the most reliable single element, 152,400 hours, precisely because nothing about it justifies a large share of the budget.

Level 2: ARINC inside the interlocking unit

A month later the interlocking logic unit has a preliminary parts list, and its owner runs an early parts-count prediction over its three assemblies: processor card 6.0, I/O card 9.0, power supply 7.5: 22.5 f/10⁶ h predicted against a budget of 17.49. The unit is 29% over budget before detailed design has begun; the allocation now decides how that pain is distributed. ARINC shares it in proportion to today's estimates:

AssemblyPredicted λShareAllocated λAllocated MTBFImplied improvement
B1 · Processor card6.026.7%4.66214,600 h×0.777
B2 · I/O card9.040.0%7.00142,900 h×0.777
B3 · Power supply7.533.3%5.83171,500 h×0.777
Σ22.5100%17.49

The last column is ARINC's signature: every assembly is asked for the same 22% rate reduction, because the method preserves relative standing by construction. Whether that is fair is an engineering conversation (perhaps the I/O card has easy derating wins and should absorb more), and that conversation is exactly what the table exists to trigger. Its output, whatever is negotiated, re-enters as a weighted-factor split.

An AGREE view of the gateway

The communications gateway's internals differ in a way ratings cannot see: duty cycles and criticality. Its radio module runs whenever the system runs; its fallback cellular path is energised rarely; and losing the fallback alone does not take the system down. That is AGREE territory. Over a 730-hour reporting month, with the gateway's own budget (61,000 h) as the goal: −ln R* = 730 / 61,000 = 0.01197.

UnitModules nᵢImportance wᵢOperating tᵢAllocated MTBF θᵢ
Radio module401.0730 h91,500 h
Fallback cellular path150.4200 h26,700 h
Antenna interface51.0730 h732,000 h

The pattern is the method's teaching: the complex, always-on, indispensable radio carries a demanding target; the fallback path, rarely energised, survivable when lost, is allowed to be an order of magnitude worse; and the five-module antenna interface must be extremely reliable because simplicity leaves it no claim on the budget. Note the two operating-time columns quietly doing real work: AGREE is the only method in the family that saw the fallback path's 200 hours at all.

The feasibility check bites

The budgets now meet reality. Fleet history for comparable trackside power supplies shows demonstrated MTBFs around 90,000 hours, and subsystem C's allocated 152,400 hours sits far beyond anything the technology has shown. The budget is infeasible not because C is weak but because the ratings gave it too small a share of the failure allowance. The rebalance shifts allowance from the gateway, which vendor data shows is comfortably placed:

SubsystemBeforeAfterNew MTBF budget
C · Trackside power module6.5611.0090,900 h, inside demonstrated capability
D · Communications gateway16.3911.9583,700 h, still above vendor-supported levels
Σ (with A, B unchanged)50.050.0budget conserved

Downstream numbers move with it: the gateway's AGREE sub-targets tighten when its budget drops to 83,700 hours and get re-run. That is not churn; it is the point: an allocation is a living negotiation between the target and the evidence, and every re-run leaves the tree more honest than it found it.


Want to see this on a live system model? Request a walkthrough.