Mission time and risk aggregation: rates, probabilities and changing exposure

Integrate a piecewise mission hazard, distinguish repeated-mission counts from probabilities, and preserve state, repair and uncertainty assumptions when aggregating exposure.

On this page

A ship’s machinery does not necessarily face one constant condition throughout a mission. Loads, required functions, available support and environmental challenges can change between operating phases. Aggregating those phases requires more than multiplying a convenient annual rate by a duration. The analysis must preserve what the rate describes, which state the system occupies and whether it survives or is restored between phases. Time is part of the model, not just a unit conversion at the end.

Define the clock and failure endpoint

The relevant clock may be operating time, time in a particular mode or calendar age. A mission can include running, standby and transitions, each with different failure opportunities. Define the functional endpoint and whether the calculation stops at its first occurrence or counts repeated occurrences after restoration. These choices determine the mathematical model.

A propulsion-related mission might be divided into phases for a bounded reliability study, but the phase names alone do not define hazard values. The data must correspond to the equipment state, duty and failure definition in each phase. A failure rate measured over mixed fleet service cannot automatically be assigned to one demanding phase merely because it is the only available number.

Integrate hazard rather than add probabilities blindly

The NIST hazard-rate discussion relates a nonrepairable lifetime’s survival to cumulative hazard H(t), the integral of the conditional hazard over time. Under that model, first-failure probability is F(t) = 1 − exp[−H(t)]. For piecewise constant hazard, H is the sum of each phase’s hazard multiplied by its duration.

The quantities added are cumulative-hazard contributions, not independent phase-failure probabilities. Each hazard is conditional on survival into the phase and appropriate to the state being modelled. The resulting probability remains between zero and one. Simply adding phase probabilities counts some hypothetical combinations inconsistently unless the necessary approximation and its error are established.

Calculate a two-phase mission

Consider an initially functioning, nonrepairable item with an invented hazard 0.000100 h⁻¹ during an 8 h first phase and 0.000500 h⁻¹ during a 2 h second phase. Assume these hazards depend only on the assigned phase and remain valid conditional on survival. Cumulative hazard is 0.000100 × 8 + 0.000500 × 2 = 0.001800.

Mission first-failure probability is 1 − exp(−0.001800), approximately 0.001798381. The time-weighted average hazard is 0.001800/10 = 0.000180 h⁻¹ and gives the same result over the same 10 h under this model. Taking the unweighted average of the two hazard values gives 0.000300 h⁻¹ and cumulative hazard 0.003, answering a different exposure question.

A two-phase hazard plot shows 8 hours at.0001 per hour and 2 at.0005. Areas contribute.0008 and.0010 to cumulative hazard. TotalH=.0018 gives first-failure probability.00179838; the last 20% of mission time contributes 55.6% of H.
Original piecewise-constant hazard-area diagram. Horizontal scale 27 units/hour; vertical 40 units per 10⁻⁴ h⁻¹. Hazards are conditional on survival into the phase and stipulated to have no transition penalty or history effect. Add cumulative hazards, then convert; do not add phase probabilities or take the unweighted mean of rates. Values are invented and do not establish an acceptable mission duration or real vessel reliability.

Understand what reordering phases assumes

In the deliberately simple example, exchanging the order of the two fixed phase exposures leaves the integrated hazard unchanged. That follows because the assigned hazards have no memory, ageing interaction or transition penalty beyond the stated phase. It is a mathematical property of this model, not a general statement that the order of ship operations is irrelevant.

If a hot phase changes the condition entering the next phase, a transition can induce failure, or an earlier impairment removes redundancy later, the hazards or states cannot be kept unchanged after reordering. A state-transition or degradation model may then be necessary. The mission model should represent the effect that makes order important instead of hiding it inside a generic average rate.

Distinguish repeated missions from continuous survival

The NIST binomial model supports a separate repeated-trial calculation. Suppose 20 missions each start in the same relevant condition and their failure outcomes are independent with the previous mission probability p = 1 − exp(−0.001800). Expected failed missions are 20p, approximately 0.035968. The probability of at least one failed mission is 1 − (1 − p)²⁰, approximately 0.035360.

The latter also equals 1 − exp(−0.036) under these particular inputs. That equality does not prove that the physical assumptions for repeating missions are met. A hidden fault persisting between missions, incomplete restoration or a shared environmental state can create dependence. State explicitly what establishes the repeated starting condition; merely beginning a new voyage record does not reset the equipment.

Use occurrence-rate models for repeated events when appropriate

NIST’s non-homogeneous Poisson-process discussion describes a time-varying occurrence-rate model for repairable-system events. Such a counting process is distinct from a nonrepairable first-failure lifetime even though both can involve an integral over time. The interpretation of the integrated quantity must stay with the model.

For a counting process with a specified intensity, the integral gives expected occurrences over the interval. Under a Poisson model, one minus the exponential of its negative gives the probability of one or more occurrences. If repair changes future behaviour, events cluster or the intensity depends on an unobserved state, a simple deterministic-intensity model may be inadequate. The same formula shape does not establish the same physical process.

Preserve uncertainty when converting to probability

In an original uncertainty example, suppose cumulative hazard H is either 0 or 0.020 with equal probability. Its mean is 0.010. Averaging the conditional failure probabilities gives [0 + 1 − exp(−0.020)]/2, approximately 0.009900663. Converting only the mean gives 1 − exp(−0.010), approximately 0.009950166. The values differ because the conversion is nonlinear.

Here the two states represent an explicitly assigned uncertainty distribution, not observed equal-frequency operating phases. For uncertain rates or durations, preserve their relationship before converting. A long exposure may occur precisely when hazard is elevated. Independently averaging the two inputs can remove that association and change the expected consequence. A sensitivity range and a probabilistic uncertainty model should also be labelled differently.

Connect mission exposure to calendar reporting carefully

A per-mission probability, expected failed missions per year and probability of at least one annual failure are different outputs. Converting requires the number and type of missions, their starting states and their dependence. Calendar downtime, inactive periods and maintenance can matter even when the operating-time model assigns no running exposure to them.

If mission duration is itself random, applying the model at the mean duration is generally not equivalent to averaging the mission probabilities. If failures shorten the observed mission, using only completed-mission durations can bias the exposure record. Keep the observation rules, censored durations and population definition visible when moving from service records to a mission model.

Report the aggregation with its assumptions

A useful result identifies the endpoint, time basis, phase durations, hazards or occurrence intensities, transitions, repair treatment and dependence assumptions. Show phase contributions and the exact conversion used, with a check on any small-probability approximation. This lets a reviewer see whether one short but demanding phase dominates the result.

Mission aggregation should preserve the engineering story as it reduces the data to a number. It can support comparisons of defined operating profiles and identify where better evidence matters. It cannot turn an unmatched failure rate into a vessel-specific prediction or establish an acceptable operating duration without the relevant physical, operational and regulatory basis.

Sources