1995 Volume 31 Issue 7 Pages 916-922
This paper proposes three kinds of redundancy configurations for a safety monitoring system which consists of alarm subsystems with human interface of fault-alerting type or safety-presentation type. For each redundant configuration, we evaluate probabilities of spurious shutdowns (SS) and hazardous accidents (HA). We give conditions for which a redundant configuration can have less SS and HA probabilities than cases in which a single alarm subsystem is utilized. Moreover, we prove that a safety monitoring system consisting of safety-presentation alarm subsystems can be optimal in the sense that it can have the least SS and HA probabilities among possible redundant configurations.