Beruflich Dokumente
Kultur Dokumente
(Part 3)
Version November 2009
Pre-requisites
Functional Safety
Safety Integrity Levels SIL
SIL Capability
Pre-requisites
Functional Safety
Pre-requisites
Safety and Availability
A safety device, which will shut down the
monitored production line or better the whole plant
In any case of the smallest probability of a
potential failure, this is safe and will comply to the
standards reaching a high SIL
Pre-requisites
Pre-requisites
Fault Tolerance
Fault tolerance means the safety device is still in
operation and in measuring mode after the fault
situation has been detected
Operation will proceed eventually with reduced
functionality
Pre-requisites
Emergency Mode
The SIL-standard in gas detection (EN 50402)
permits explicitly an emergency mode
Defined for a specified period of time for redundant
systems.
After detection of an internal fault the system is not
longer redundant but still fully operational.
Pre-requisites
Example: A typical gas detection device (system) with ATEXCertificate including the functional approval according IEC
61779, with regular maintenance is equivalent to SIL-1
8
Pre-requisites
Pre-requisites
10
Pre-requisites
Safe detected
Safe undetected
Dangerous detected
Dangerous undetected
Above classification important in design to determine the
Safe Failure Fraction, specific for each SIL level
Random faults
Systematic faults
11
Pre-requisites
Pre-requisites
Simple modules
Relays
Sensor element
any simple analogue electronics circuit
Complex modules
microprocessor based systems
13
Pre-requisites
14
Pre-requisites
Pre-requisites
HW SIL-2
SW SIL-2
HW SIL-2
SW SIL-2
HW SIL-3
SW SIL-2
SIL 2
16
Pre-requisites
HW SIL-2
SW SIL-3
HW SIL-2
SW SIL-3
In combination
HW SIL-3
SW SIL-3
SIL 3
17
Pre-requisites
18
Pre-requisites
Pre-requisites
21
22
23
24
25
26
Galvanic isolation
Galvanic isolation
Field Module
Galvanic isolation
Galvanic isolation
Field Module
Galvanic isolation
Galvanic isolation
Field Module
Galvanic isolation
Galvanic isolation
1. 2 closed loops, redundant one to the other, case in which the system will
feature whole capacity per each loop, monitoring both the same modules.
Control Unit
27
Details CPU
28
Galvanic isolation
FAULT
BATTERY
UNSET
TEST
POWER
SY STEM
OVER-RANGE
ALARM 3
ALARM 2
ALARM 1
UNDER-SCALE
FAULT
SIG NAL
Details CPU
Control Unit
ESC
ENT
29
Signalling interface
ALARM 2
ALARM 1
UNDER-SCALE
FAULT
FAULT
EMERGENCY
UNSET
TEST
POWER
SYSTEM LEDs
OVER-RANGE
ALARM 3
SIGNAL LEDs
30
Signalling interface
- Basic relays -
31
General Philosophy
Galvanic isolation
Control Unit
P No. 1
External Printer
External PC
P1
P2
33
No.
Galvanic isolation
1
ESC
ENT
Control Unit
34
Loop devices
All loop devices are addressable, each address
identifies uniquely one input or output, as follows:
35
Galvanic isolation
AIM Module
Galvanic isolation
Galvanic isolation
Control Unit
30
30
30
30
30
30
30
30
39
40
42
43
Galvanic isolation
Galvanic isolation
LOOP Module
Galvanic isolation
Galvanic isolation
Control Unit
30
30
30
30
30
30
44
45
Control Unit
8 RELAYS extension board
8 RELAYS
Galvanic isolation
AIM Module
Galvanic isolation
Galvanic isolation
48
SIL 2 configuration
Loop A redundant with loop B
P 1 redundant with P 2
NO redundancy on detectors level
30
Control Unit
Galvanic isolation
30
AIM Module
Galvanic isolation
AIM Module
Galvanic isolation
Galvanic isolation
30
30
49
SIL 3 configuration
LOOP 1-1 (RETURN)
LOOP 2-1 (RETURN)
LOOP 2-0
Galvanic isolation
P2
LOOP A
AIM Module
P1
Galvanic isolation
Galvanic isolation
30
P1
30
LOCATION 1
LOCATION 2
LOCATION 3
P2
Control Unit
Galvanic isolation
30
AIM Module
P1
P2
LOOP 1
LOOP 2
30
LOCATION 8
50
LOCATION 1
30
30
30
30
P1
30
LOCATION 3
30
30
LOCATION 4
30
P2
Galvanic isolation
LOOP 2-0
AIM Module
LOOP 1-0
Galvanic isolation
P2
Galvanic isolation
Galvanic isolation
P1
30
LOCATION 6
AIM Module
LOCATION 2
30
LOCATION 5
P1
30
Control Unit
30
LOCATION 7
30
30
LOCATION 8
30
P2
LOOP 1
LOOP 2
51
System setup
Whole system configuration is done by means of PC software
52