Email: Password: Remember Me | Create Account (Free)

Back to Subject List

Old thread has been locked -- no new posts accepted in this thread
???
12/15/05 08:26
Read: times


 
Msg Score: +1
 +1 Informative
#105267 - Safety
Responding to: ???'s previous message

Mehdi, realistically no-one can make something 100% safe. I'm not sure about the requirements of medical equipment but most other devices that could cause death or injury need to be proven statistically that a failure might occur 1/10^9. There was an article in Circuit Cellar that went through the whole process. Nevertheless - in many cases the requirement is that a major failure cannot be caused by one item, two or more is acceptable BUT only if you can detect a single unit failure. At a guess, I would consider a failure of your unit to be either no heat or too much heat. You need to analyse what might cause either of these two conditions and add a safeguard so that a failure can be detected. This requires a bit of creative thinking. Say you add a mechanical thermostat as your safeguard - how could the system test that for failure? Also, remember that your microprocessor can't be trusted - extra hardware must be added to ensure the microprocessor behaves. If something goes wrong - you have to fail safe - turn off the heater and start beeping loudly. Even the relay to control the heater can't be trusted -what happens if that fails? How would you test that relay and cope with its failure?

Safe design starts early - use conservatively rated components. don't use a 5A relay to switch 3A, use a 10A and so on. In your software, have you used formal design methods to show the exact operation of your code. Have you used defensive programming techniques to catch errors and to handle them? Many of these things are trivial to include in the design stage but difficult to add to a finished product.

Do a search of 'therac 25' to see what happens when no safeguards are put in place.




List of 39 messages in thread
TopicAuthorDate
Amenic Temp Controller,            01/01/70 00:00      
   how do you read the ADC?            01/01/70 00:00      
      By Polling DRDY!            01/01/70 00:00      
         can't DRDY be connected to an int?            01/01/70 00:00      
   Sample rate.            01/01/70 00:00      
   16 bit ADC            01/01/70 00:00      
   Safety!!!!!            01/01/70 00:00      
   Classic Problem            01/01/70 00:00      
      Why not spend $0.82 and add a cheap micr            01/01/70 00:00      
         As I suggested            01/01/70 00:00      
            If it were me.            01/01/70 00:00      
               More!            01/01/70 00:00      
                  you MUST have a double security. I woul            01/01/70 00:00      
                     Life support            01/01/70 00:00      
                        Ameni            01/01/70 00:00      
                           Thanks Steve            01/01/70 00:00      
                  Overkill            01/01/70 00:00      
                     Kai,Steve,Erik,Farshid            01/01/70 00:00      
                        What kind of temp sensor?            01/01/70 00:00      
                           Sensor            01/01/70 00:00      
                              Some questions            01/01/70 00:00      
                                 Damned good idea.            01/01/70 00:00      
                                 Answers.            01/01/70 00:00      
                                    The heater heats up and heats up and ...            01/01/70 00:00      
                        Tehran 2001            01/01/70 00:00      
                           I Am Sorry Steve!            01/01/70 00:00      
                              Mehdi, you have evaded all posts re safe            01/01/70 00:00      
                                 I want...            01/01/70 00:00      
                                    In either of these cases I fear for your            01/01/70 00:00      
                                       Safety            01/01/70 00:00      
                                          Re: safety            01/01/70 00:00      
                  Again safety            01/01/70 00:00      
                     Incentive scheme            01/01/70 00:00      
                        No pursuing available            01/01/70 00:00      
                           Thanks Farshid            01/01/70 00:00      
      Thank You All            01/01/70 00:00      
         Mail            01/01/70 00:00      
            Hi Farshid            01/01/70 00:00      
         Please post solution            01/01/70 00:00      

Back to Subject List