Fig. 19 shows the fault tree of the events
leading to missing information from the process level (I4),
which can occur in case of failure of any of the IEDs or MUs.
It can be seen that AND gates are used to illustrate redundancy,
Fig. 19. Missing information from process level.
as both the primary and back-up components must fail in order
for the function to fail to operate as designed. P(I4) is given as
follows:
(4)
Similar fault trees can be developed for estimating P(I5) and
P(I6). The loss of communication (I5) can be divided into two
categories: failure in the communication between the substation
levels (internal) and in the communication with the rest of the
system (external). The former includes the failure of the Ethernet
switches and of the ring buses, while the latter includes the
failure of the gateways. The workstation failure (I6) consists of
the failures in the operator and engineering workstations, which
are fully redundant.