Beruflich Dokumente
Kultur Dokumente
OW331_46
July 2010
(SIL3 Certified July 2009)
Copyright Notice
Since the equipment explained in this document has a variety of uses, the user and those
responsible for applying this equipment must satisfy themselves as to the acceptability of each
application and use of the equipment. Under no circumstances will Emerson Process
Management be responsible or liable for any damage, including indirect or consequential losses
resulting from the use, misuse, or application of this equipment.
The text, illustrations, charts, and examples included in this manual are intended solely to explain
the use and application of the Ovation Unit. Due to the many variables associated with specific
uses or applications, Emerson Process Management cannot assume responsibility or liability for
actual use based upon the data provided in this manual.
No patent liability is assumed by Emerson Process Management with respect to the use of
circuits, information, equipment, or software described in this manual.
No part of this publication may be reproduced, stored in a retrieval system, or transmitted in any
form or by any means, including electronic, mechanical, photocopying, recording or otherwise
without the prior express written permission of Emerson Process Management.
The document is the property of and contains Proprietary Information owned by Emerson Process
Management and/or its subcontractors and suppliers. It is transmitted in confidence and trust, and
the user agrees to treat this document in strict accordance with the terms and conditions of the
agreement under which it was provided.
This manual is printed in the USA and is subject to change without notice.
Ovation and WEStation are registered trademarks of Emerson Process Management. All other
trademarks or registered trademarks are the property of their respective holders.
Copyright Emerson Process Management Power & Water Solutions, Inc. All rights reserved.
Emerson Process Management
Power & Water Solutions
200 Beta Drive
Pittsburgh, PA 15238
USA
E-Mail: Technical.Communications@EmersonProcess.com
Website: https://www.ovationusers.com
Contents
1
1.1
1.2
1.3
1.4
1.5
1.6
Common Specifications
2.1
2.2
2.3
2.4
2.5
Required Practices
3.1
3.2
3.3
3.4
4.1
5.1
Index
OW331_46
13
17
21
E C T I O N
IN THIS SECTION
Ovation SIS Accessories Safety Manual overview ............................................................. 1
Certification ......................................................................................................................... 1
Management of Functional Safety ...................................................................................... 2
Restrictions.......................................................................................................................... 2
Engineering Practices ......................................................................................................... 2
Operations and Maintenance Practices .............................................................................. 3
1.1
1.2
Certification
The information in this document applies to the following hardware components of the SIS Relay
and Voltage Monitor.
RATINGS
COMPONENT
Safety Rated
Exida has certified the SIS Relay and Voltage Monitor hardware as suitable for use in applications
with a maximum Safety Integrity Level of 3 (SIL3) according to IEC 61508. The SIL3 certification
applies to simplex applications of the SIS Relay and Voltage Monitor.
The SIS Relay and Voltage Monitor hardware is certified for use in both the low and high demand
modes of operation as defined by IEC 61508.
Refer to Common Specifications (see page 5) for failure rate and other data to help you verify that
your safety requirements are being met and for additional considerations for using the SIS Relay
or Voltage Monitor hardware in high demand mode.
OW331_46
1.3
1.4
Restrictions
The practices required in the use of the Voltage Monitor and SIS Relay are summarized below.
Each topic is discussed in greater detail in Required Practices (see page 9).
1.5
You must complete a full functional test of the SIS Relay and Voltage Monitor hardware
before it is used to provide the protection function in a running process.
The SIS Relay and Voltage Monitor are designed for a de-energized to trip operation such
that the tripped state for the process is achieved when the output channels are de-energized.
Engineering Practices
The SIS Relay and Voltage Monitor products must be used within the published specifications.
Refer to Common Specifications (see page 5) for more information on safety relevant
specifications for the SIS Relay and Voltage Monitor products.
OW331_46
1.6
OW331_46
E C T I O N
Common Specifications
IN THIS SECTION
Failure Rate data for SIL verification................................................................................... 5
Failure Rate Data for Availability......................................................................................... 7
Response Time Data .......................................................................................................... 7
Limits - Product Life............................................................................................................. 7
Limits - Environmental Specifications ................................................................................. 8
2.1
Enter the number of SIS Relays that drive output channels in this SIF.
Multiply the number of SIS Relays by the DU failure rate (failures per hour) and enter the
result. Sum the results to get the total DU failure rate.
Enter the number of Voltage Monitors that are used as safety critical inputs in this SIF.
Multiply the number of SIS Relays and Voltage Monitors by the DU failure rate (failures per
hour) and enter the result. Sum the results to get the total DU failure rate contribution for this
SIF from SIS Relays and Voltage Monitors.
OW331_46
1.75E-11 (0.0175
FITS)
You can approximate the PFDavg contribution of the SIS Relay and Voltage Monitor subsystems
using the total failure rates in the table above, the proof test period for the SIS Relays and Voltage
Monitor channels in the SIF, and your maximum allowed repair time.
PFDavg (LS)= DU * T / 2 + DD * RT
where:
DU = Total DU failure rate from the table above.
T = Proof test period in hours.
DD = Total DD failure rate for each product. (0.0 in this case).
RT = Allowed repair time in hours.
Determine the PFDavg for the SIF by summing the PFDavg for the SIS Relay and Voltage
Monitor channels with the PFDavg for the logic solver subsystem plus the sensor and final
element subsystems.
High Demand Mode of Operation
In the high demand mode, the periodic proof test does not occur at least twice during the
expected demand interval, but the demand interval is sufficiently longer than the fault detection
and reaction time. SIL verification for the high demand mode uses the Probability of Dangerous
Failure per Hour (PFH).
There are several additional considerations when operating in the high demand mode. Generally
it is easy to avoid operating in high demand mode by reducing the proof test interval on the SIS
Relay and Voltage Monitor. But if there is a practical constraint in the proof testing frequency of
another subsystem of the SIF that causes the SIF to operate in the high demand mode, the
additional considerations of high demand mode apply.
As the SIS Relay and Voltage Monitor are simple products without any online diagnostics,
limitations on the use of high demand mode are most likely determined by the Logic Solver,
sensor, and final element subsystems.
The PFH for the SIS Relay or Voltage Monitor subsystems of the SIF is the total DU failure rate
from the table above.
PFH (SIS Relay and Voltage Monitor Channels) = DU
where:
DU = Total DU failure rate from the table above.
Determine the PFDavg for the SIF by summing the PFH for the SIS Relay and Voltage Monitor
channels with the PFH for the logic solver subsystem plus the sensor and final element
subsystems.
OW331_46
2.2
2.3
2.4
OW331_46
2.5
IP 20 rating
OW331_46
E C T I O N
Required Practices
IN THIS SECTION
Installation and Site Acceptance Testing ............................................................................ 9
Functional Testing After the Initial Installation .................................................................... 9
Functional Testing Changes to the Installation ................................................................... 9
Proof Testing the SIS Relay and Voltage Monitor ............................................................ 10
3.1
3.2
The functional test is required even if the identical logic has already been tested in an identical
configuration.
3.3
OW331_46
3.4
10
OW331_46
OW331_46
11
12
OW331_46
E C T I O N
IN THIS SECTION
SIS Relay module.............................................................................................................. 13
4.1
Two pin digital input connection for input from a Logic Solver or generic safety PLC 24VDC
Digital Output channel.
OW331_46
13
14
OW331_46
Two pin digital input connection for input from a Logic Solver or generic safety PLC 24VDC
Digital Output channel.
Four pin connection for the switched outputs to two DC field devices
OW331_46
15
The following table shows the specifications for the SIS Relay module.
SIS Relay Module Specifications
ITEM
SPECIFICATIONS
> 18VDC
< 6VDC
< 70 mA - 20%
2.5A @ 30 VDC
Maximum AC Source
280 VAC
Maximum DC Source
30 VDC
< 0.5
> 1 M
100 V
300 VAC
10 msec
12 msec
Mounting configuration
The dimensions for the SIS Relay module are the same as for the Voltage Monitor module (see
page 17).
16
OW331_46
E C T I O N
IN THIS SECTION
Voltage Monitor module .................................................................................................... 17
5.1
OW331_46
17
18
OW331_46
Two four-pin connection blocks, one for each voltage monitoring channel for connection to DC
or AC power source being monitored.
Two four-pin connection blocks, one for each voltage monitoring channel for connecting the
output to a Logic Solver or other safety PLC monitored DI channel and an Ovation Digital
Input channel (auxiliary).
OW331_46
19
The table below shows the specifications for the Voltage Monitor.
Voltage Monitor Specifications
20
ITEM
SPECIFICATIONS
250 VAC
< 6 mA 20%
<12mA
<15 mA
< 3.5 K
>8.5 K
30 VDC
250 VAC
30 VAC
250 VAC
30 msec
5 msec
Mounting configuration
Lifetime limitations
OW331_46
Index
C
Certification 1
Common Specifications 5
Competence of Persons - Engineering 2
Competence of Persons - General 2
Competence of Persons - Installation and
Hardware Maintenance 2
Copyright Notice 2
R
Required Practices 9
Response Time Data 7
Restrictions 2
S
SIS Relay module 13
Engineering Practices 2
F
Failure Rate Data for Availability 7
Failure Rate data for SIL verification 5
Functional Testing After the Initial
Installation 9
Functional Testing Changes to the
Installation 9
I
Installation and Site Acceptance Testing 9
L
Limits - Environmental Specifications 8
Limits - Product Life 7
M
Management of Functional Safety 2
O
Operations and Maintenance Practices 3
Ovation SIS Accessories Safety Manual 1
Ovation SIS Accessories Safety Manual
overview 1
P
Product Specific Instructions for the SIS
Relay Module 13
Product Specific Instructions for the Voltage
Monitor 17
Proof Testing the SIS Relay 10
Proof Testing the SIS Relay and Voltage
Monitor 10
Proof Testing the SIS Relay for AC Wiring
10
Proof Testing the SIS Relay for DC Wiring
11
OW331_46
21