Beruflich Dokumente
Kultur Dokumente
TRADEMARKS
All rights to copyrights, registered trademarks, and trademarks reside with their respective owners.
Section 1 - Introduction
Introduction .....................................................................................................................13
Calculation Methods........................................................................................................13
Environment ....................................................................................................................15
Nomenclature ..................................................................................................................15
AC 800M HI Safety Integrity..........................................................................................19
General .............................................................................................................19
BPCS Risk Reduction with AC 800M HI............................................................20
Safety Reliability Block Diagrams.......................................................................21
Safety Reliability Calculations.............................................................................23
Calculations with Respect to Maintenance Effort................................................23
AC 800M HI Typical Configurations..............................................................................24
3BSE034876 5
Table of Contents
6 3BSE034876
About This Book
General
This book contains information necessary to support dependability studies and
availability and reliability calculations related to the use of AC 800M HI controller
in Safety Instrumented Systems (SIS).
A brief introduction to ABB reliability data methodology is given together with an
overview of definitions and nomenclature.
The main parts of the book addresses safety reliability and system availability
calculations.
Document Conventions
Microsoft Windows conventions are normally used for the standard presentation of
material when entering text, key sequences, prompts, messages, menu items, screen
elements, etc.
Electrical warning icon indicates the presence of a hazard which could result in
electrical shock.
3BSE034876 7
Terminology About This Book
Warning icon indicates the presence of a hazard which could result in personal
injury.
Tip icon indicates advice on, for example, how to design your project or how to
use a certain function
Although Warning hazards are related to personal injury, and Caution hazards are
associated with equipment or property damage, it should be understood that
operation of damaged equipment could, under certain operational conditions, result
in degraded process performance leading to personal injury or death. Therefore,
fully comply with all Warning and Caution notices.
Terminology
A complete and comprehensive list of terms is included in System 800xA System
Guide Functional Description (3BSE038018*). The listing included in Engineering
Concepts includes terms and definitions as they apply to the 800xA system where
the usage is different from commonly accepted industry standard definitions and
definitions given in standard dictionaries such as Webster’s Dictionary of Computer
Terms.
Term/Acronym Description
AC 800M HI AC 800M High Integrity
AI Analog Input
Application User defined logic. Used in Control Builder M Professional to
denote a “container” for executable programs and data that are
grouped together.
8 3BSE034876
About This Book Terminology
Term/Acronym Description
BPCS Basic Process Control System
Channel Element or group of elements that independently perform(s) a
function
CM Cluster Modem
Common cause failure Failure which is the result of one or more events, causing
coincident failures of two or more separate channels in a
multiple channel system, leading to system failure
CPU Central Processing Unit
DC Diagnostic Coverage
DI Digital Input
DO Digital Output
ESD Emergency Shutdown
F&G Fire and Gas (protection system)
FMEDA Failure Mode, Effect and Diagnostic Analysis
HFT Hardware Fault Tolerance
Interference free Hardware and software functions certified to be used in AC
800M HI for non safety related functions. This hardware and
software will not interfere undetected with the safety functions
or the safety integrity of the AC800M HI.
Logic Solver That portion of either a BPCS or SIS that performs one or
more logic function(s). Logic Solver consists of Input Board,
PU and Out Board.
Note. Sensors and final elements are not part of the logic
solver.
3BSE034876 9
Terminology About This Book
Term/Acronym Description
Mode of operation - Low demand: where the frequency of demands for operation
on a safety-related system is no greater than one per year and
no greater than twice the proof-test frequency
- High demand or continuous: where the frequency of
demands for operation on a safety-related system is greater
than one per year or greater than twice the proof-test
frequency.
MCB Miniature Circuit Breaker
NC Normally closed
ND Normally de-energized
NE Normally energized
NO Normally open
PCB Printed Circuit Board
PFD Probability of Dangerous Failure on Demand
PFDG Average Probability of Dangerous Failure on Demand
PFH Average Frequency of Dangerous Failure per Hour
Proof Test Test performed to reveal undetected faults in a safety
instrumented system so that, if necessary, the system can be
restored to its designed functionality
PST Process Safety Time
PU Processor Unit. In this document PU refers to assembly of
Processor and Supervisory Modules. This is a part of the logic
solver as defined in IEC61508.
RCU Redundant Control Unit
RRF Risk Reduction Factor
SFF Safe Failure Fraction
SIF Safety Instrumented Function
SIS Safety Instrumented System
10 3BSE034876
About This Book Related Documentation
Term/Acronym Description
SD Bulk power supply (main power supply)
SPOF Single Point Of Failure
SS Power voting unit
TB Cluster Modem
TP Base plate
TU Connection unit
1oo1D 1 out of 1 Channel Architecture with Diagnostics
1oo2D 1 out of 2 Channel Architecture with Diagnostics
Related Documentation
Whenever a reference to a specific instruction is made, the instruction number is
included in the reference.
3BSE034876 11
Related Documentation About This Book
12 3BSE034876
Section 1 Introduction
Introduction
This document includes methods and data to be used in the calculations of system
reliability both from an availability as well as from a safety reliability viewpoint.
Dependencies from a safety reliability viewpoint are illustrated in reliability block
diagrams.
Calculation Methods
The dependability calculation methods used within ABB for the calculation of
reliability complies with IEC/TR 62380 and Part 6 of IEC61508.
Quite conservative predictions can be expected from the very beginning of product
life cycle. Field observations of failure rates in typical industrial applications will
influence the module data given and make the data compatible to real life
experiences. Improvements of the quality of the data will then be achieved
gradually.
The failure rates for all circuit boards and units are calculated by a computer
program. Parts count method is used. When needed, considerations are taken to
actual loads. Certain components, measurement points etc. not essential for
continuos operation are not included in the calculations.
The reliability data for a circuit board or a system component is stated outgoing
from statistical calculation methods.
Failure rates are calculated and documented through failure mode effect and
diagnostics analysis (FMEDA) and approved by TÜV.
3BSE034876 13
Calculation Methods Section 1 Introduction
14 3BSE034876
Section 1 Introduction Environment
No Effect failure (#): Failure of an element that plays a part in implementing the
safety function but has no direct effect on the safety function.
No Part failure ( -): Failure of a component that plays no part in implementing
the safety function.
Environment
The failure rates are calculated for industrial environment. The requirement for
industrial data is stated in 3BSE036352 Appendix E. The ambient temperature
outside an electronic assembly/enclosure in these calculation is assumed to be 30°C.
Nomenclature
Failure rate; states the mean number of failures per hour.
1
Mean Time to Failure; MTTF = --- [hours]
MTTF 1
- 100 = --------------------------------------
Availability; A = -------------------------------------- [%] [2]
MTTF + MTTR 1 + xMTTR
MTTR, Mean Time To Restoration, is the average time required to move from
unsuccessful operation to successful operation. The definition includes the time
required to detect that a failure has occurred, and has been detected and identified,
as well as the time required to make the repair.
MTTR used in the calculation of redundant functions is 8 hours and alternatively 72
hours.
3BSE034876 15
Nomenclature Section 1 Introduction
Safe Failure Fraction (SFF) is the fraction of the overall random hardware failure
rate of a device that results in either a safe failure or a dangerous detected failure.
S + DD
SFF = -------------------------- [4]
D + S
Safe State. State of the equipment under control when safety is achieved.
Diagnostic Coverage (DC)[%] and Safe Failure Fraction (SFF)[%] is calculated
according to the methods given in Part 2 and the user guidelines given in Part 6 of
the IEC 61508.
DD
DC = ------------ [5]
D
Common cause failure (CCF) is a failure, which is the result of one or more events,
causing failures of two or more separate channels in a multiple channel system,
leading to system failure.
Quantification of hardware-related common cause failures, expressed as a -factor,
is described in Annex D in Part 6 of IEC 61508. A -factor of 1% is used in relevant
calculations in this document.
16 3BSE034876
Section 1 Introduction Nomenclature
The built-in diagnostics in the AC 800M HI controller ensures that the portion of
dangerous failures that is detected by the diagnostics will not prevent any safety
function within the logic solver from maintaining or achieving safe state. The
formula in IEC61508-6 Annex B, for 1oo1. As the system reacts on detected
failures within FDRT by bringing the EUC to the safe state the time after fault
detection and reaction can not contribute to the PFD value. Therefore the formula
in IEC61508-6 Annex B is modified accordingly [6]. This will result in a more
conservative value compared to the formula in the standard
PFD = DU T [6]
3BSE034876 17
Nomenclature Section 1 Introduction
PFH = DU [7]
18 3BSE034876
Section 1 Introduction AC 800M HI Safety Integrity
HW Fault
Sub-unit SIL
Tolerance
AC 800M HI PU SIL 2 0
- PM865/TP830
- SM810/SM811/TP855/TP868
AC 800M HI PU SIL 2 0
- PM867/TP830
- SM812/TP868
AC 800M HI PU SIL 3 1
- PM865/TP830
- SM811/TP868
AC 800M HI PU SIL 3 1
- PM867/TP830
- SM812/TP868
Analog Input module SIL 3 1
- AI880A
3BSE034876 19
BPCS Risk Reduction with AC 800M HI Section 1 Introduction
HW Fault
Sub-unit SIL
Tolerance
Digital Input module SIL 3 1
- DI880
Digital Output module SIL 3 1
- DO880 NE
Digital Output module SIL 3 1
- DO880 ND
20 3BSE034876
Section 1 Introduction Safety Reliability Block Diagrams
3BSE034876 21
Safety Reliability Block Diagrams Section 1 Introduction
PFDPFD DU
λ= DU I T– max λDU
I +β* min M ;
DU–PPM +
; λDUDU–SMSM –λDO
TDU DU T T
DO [11]
22 3BSE034876
Section 1 Introduction Safety Reliability Calculations
PFH DU
PFH=λDU I – maxλDU
I β+ * min P M;;
DU–PM λDU M +
DU–SSM λDUDU– DO
DO [12]
3BSE034876 23
AC 800M HI Typical Configurations Section 1 Introduction
24 3BSE034876
Section 1 Introduction AC 800M HI Typical Configurations
3BSE034876 25
AC 800M HI Typical Configurations Section 1 Introduction
26 3BSE034876
Section 2 Safety Reliability Calculations
General
The calculation methodology for probability of dangerous failure on demand (PFD)
and probability of dangerous failure per hour (PFH) is based on formulas in IEC
61508.
AC 800M HI SIL2 has a 1oo1D system architecture. AC 800M HI SIL2 1oo1D
design implies the ability to always accomplish safe state or safe mode of operation
upon detection of a dangerous failure (That is fail-to-safe shutdown of equipment
under control or continue in safe operation with redundant component or unit).
AC 800M HI SIL3 has a 1oo2D system architecture.S800 I/O HI (AI880A, DI880,
DO880) is certified for SIL3 applications.
AC 800M I/O HI communication system is certified for SIL3 applications. A safety
layer is made on top of platform specific protocols and communication devices, thus
excluding safety critical aspects of such components from the safety reliability
calculations.
The AC 800M HI Controller has been designed for easy adoption and scalability
with respect to availability.
Configuration
AC 800M HI is certified for up to SIL3 applications in single configuration
comprising of single PU, communication and single I/O modules.
Redundancy can be implemented individually for all types of sub-modules on a
modular basis without influencing the safety integrity:
• AC 800M HI PU:
3BSE034876 27
Configuration Section 2 Safety Reliability Calculations
*
These components do not contribute to dangerous undetected failures at system
level because only SELV power supplies are allowed according to Safety Manual
3BNP004865*.
28 3BSE034876
Section 2 Safety Reliability Calculations AC 800M HI Safety Reliability Data
3BSE034876 29
AC 800M HI Safety Reliability Data Section 2 Safety Reliability Calculations
I/O
Digital Input module DI880 DI880 common 3.52E-11 6.16E-6 3.52E-11
Module Termination Unit(MTU**) 1 channel
TU842/843
30 3BSE034876
Section 2 Safety Reliability Calculations AC 800M HI Safety Reliability Data
3BSE034876 31
AC 800M HI Safety Reliability Data Section 2 Safety Reliability Calculations
*The SD83x is included for completeness but do not have any dangerous failures.
** The calculations in Table 2 uses the data for MTU:s from Appendix A
*** The data is also valid when using AI880A as Loop supervised DI, Each channel AI880A includes
1*TY801 or 1*TY805 shunt stick.
32 3BSE034876
Section 2 Safety Reliability Calculations Calculating Probability of Dangerous Failure on Demand (PFD)
PFD figures for the most common AC 800M HI logic solver loop (I/O)
configurations are shown in Table 4, below.
3BSE034876 33
Calculating Probability of Dangerous Failure on Demand (PFD) Section 2 Safety Reliability Calculations
Table 4. AC 800M HI Logic Solver safety integrity in low demand mode of operation
IEC/TR 62380
SIF Architecture
SIL2 SIL3
PFD PFD
34 3BSE034876
Section 2 Safety Reliability Calculations Calculating Probability of Dangerous Failure per Hour (PFH)
3BSE034876 35
Calculating Probability of Dangerous Failure per Hour (PFH) Section 2 Safety Reliability Calculations
PFH figures for the most common AC 800M HI logic solver loop (I/O)
configurations are shown in Table 6 below.
Table 6. AC 800M HI Logic Solver safety integrity in high demand mode of operation
IEC/TR 62380
SIF Architecture
SIL2 SIL3
PFH PFH
36 3BSE034876
Section 3 Availability Calculations
The total system failure rate can be calculated as the sum of the individual
subsystem failure rates.
= 1 + 2 + 3 i 1 hour
3BSE034876 37
Single AC 800M HI PU Section 3 Availability Calculations
Single AC 800M HI PU
Single AC 800M HI PU
Table 7. Failure rates, Single AC 800M HI PU (PM865)
Functional
Total failure
failure rate Total
rate safety
Variant Including safety failure rate
function
function
Single Processor and 3.46E-6 3.46E-6 4.42E-6
Supervisory module (PU)
Options included:
- CEX interface
- COM 4 Tool port
Note: Functional options like control network interface, electrical and optical
ModuleBuses are considered from a functional failure rate viewpoint only.
38 3BSE034876
Section 3 Availability Calculations Single AC 800M HI PU
Functional
Total failure
failure rate Total
rate safety
Variant Including safety failure rate
function
function
Single Processor and 4.51E-6 4.51E-6 6.84E-6
Supervisory module (PU)
Options included:
- CEX interface
- COM 4 Tool port
COM 3 RS232 3.0 E-9 3.0 E-9
Add for use of internal
communication RS232
Note: Functional options like control network interface, electrical and optical
ModuleBuses are considered from a functional failure rate viewpoint only.
3BSE034876 39
Single AC 800M HI PU (with redundant Supervisory module) Section 3 Availability Calculations
Functional failure
Total failure rate safety function Total
rate safety failure
Variant Including function MTTR MTTR rate
8h 72h
Single Processor Module 4.46E-6 2.05E-6 2.05E-6 7.20E-6
with redundant
Supervisory module
Options included:
- COM 4 Tool port
- CEX interface
Note: Functional options like control network interface, electrical and optical Modulebuses
are considered from a functional failure type viewpoint only.
40 3BSE034876
Section 3 Availability Calculations Single AC 800M HI PU (with redundant Supervisory module)
Table 10. Failure rates, Single AC 800M HI PU (PM867) with redundant Supervisory module
Functional failure
Total failure rate safety function Total
rate safety failure
Variant Including function MTTR MTTR rate
8h 72h
Single Processor Module 6.78E-6 2.91E-6 2.92E-6 1.17E-5
with redundant
Supervisory module
Options included:
- COM 4 Tool port
- CEX interface
Note: Functional options like control network interface, electrical and optical Modulebuses
are considered from a functional failure type viewpoint only.
3BSE034876 41
Redundant AC 800M HI PU (with redundant Supervisory module) Section 3 Availability Calculations
Functional failure
Total failure rate safety function Total
rate safety failure
Variant Including function MTTR MTTR rate
8h 72h
Redundant Processor 6.51E-6 1.17E-9 1.85E-9 9.57E-6
Module with redundant
Supervisory module
Options included:
- COM 4 Tool port
- CEX interface
COM 3 RS232 3.0 E-9 3.0 E-9
Add for use of internal
communication RS232
Note: Functional options like control network interface, electrical and optical Modulebuses
are considered from a functional failure type viewpoint only.
42 3BSE034876
Section 3 Availability Calculations Redundant AC 800M HI PU (with redundant Supervisory module)
Table 12. Failure rates, Redundant AC 800M HI PU (PM867) with redundant Supervisory module
Functional failure
Total failure rate safety function Total
rate safety failure
Variant Including function MTTR MTTR rate
8h 72h
Redundant Processor 9.69E-6 1.27E-9 2.77E-9 1.51E-5
Module with redundant
Supervisory module
Options included:
- COM 4 Tool port
- CEX interface
COM 3 RS232 3.0 E-9 3.0 E-9
Add for use of internal
communication RS232
Note: Functional options like control network interface, electrical and optical Modulebuses
are considered from a functional failure type viewpoint only.
3BSE034876 43
AC 800M HI Redundant PU Section 3 Availability Calculations
AC 800M HI Redundant PU
Redundant AC 800M HI and Single I/O
Table 13. Failure rates, Redundant AC 800M HI PU (PM865) and Single I/O
44 3BSE034876
Section 3 Availability Calculations Redundant AC 800M HI and Single I/O
Table 13. Failure rates, Redundant AC 800M HI PU (PM865) and Single I/O
3BSE034876 45
Redundant AC 800M HI and Single I/O Section 3 Availability Calculations
Table 14. Failure rates, Redundant AC 800M HI PU (PM867) and Single I/O
46 3BSE034876
Section 3 Availability Calculations Redundant AC 800M HI and Single I/O
3BSE034876 47
Redundant AC 800M HI and Redundant I/O Section 3 Availability Calculations
48 3BSE034876
Section 3 Availability Calculations Redundant AC 800M HI and Redundant I/O
Table 15. Failure rates, Redundant AC 800M HI PU (PM865) and Redundant I/O
3BSE034876 49
Redundant AC 800M HI and Redundant I/O Section 3 Availability Calculations
Table 16. Failure rates, Redundant AC 800M HI PU (PM867) and Redundant I/O
50 3BSE034876
Section 3 Availability Calculations Redundant AC 800M HI and Redundant I/O
3BSE034876 51
AC 800M HI Power Supply 24V Section 3 Availability Calculations
52 3BSE034876
Section 3 Availability Calculations AC 800M HI Power Supply 24V
3BSE034876 53
AC 800M HI Power Supply 24V Section 3 Availability Calculations
54 3BSE034876
Section 3 Availability Calculations AC 800M HI, Single S800 I/O
Functional
Total Functional
failure rate Total
failure failure rate
(loosing one failure
Variant Including rate safety (locking
channel only rate
function modulebus)
including MTU)
S800 I/O HI Single
modules
3BSE034876 55
AC 800M HI, Redundant S800 I/O Section 3 Availability Calculations
Functional
failure rate
Total Functional
(loosing one Total
failure failure rate
channel only failure
Variant Including rate safety (locking both including rate
function modulebuses)
MTU)
S800 I/O HI
Redundant modules
56 3BSE034876
Section 3 Availability Calculations AC 800M HI Single Optical Modulebus
3BSE034876 57
AC 800M HI Single Optical Modulebus Section 3 Availability Calculations
58 3BSE034876
Section 3 Availability Calculations AC 800M HI Redundant Optical Modulebus
Functional Functional
Total failure
failure rate failure rate
rate safety Total failure
Variant Including affecting both affecting both
function rate
optical electrical
modulebuses modulebuses
Redundant optical
modulebus
Cluster Modem 2x TB840A 1.01E-6 1.63E-11 6.56E-9 1.78E-6
Termination Plate 1 x TU841
Single electrical
Modulebus
3BSE034876 59
Control Network Communication Section 3 Availability Calculations
Functional Functional
Total failure
failure rate failure rate
rate safety Total failure
Variant Including affecting both affecting both
function rate
optical electrical
modulebuses modulebuses
S800 I/O HI For single modules, see Table 18 above.
For redundant modules see Table 19 above.
Note: Typical values per set of I/O module and module termination unit.
Does not apply to S800 I/O HI. See Table 18 and Table 19 above for S800 I/O HI single
modules.
See separate document for individual reliability data for S800 I/O modules.
60 3BSE034876
Section 3 Availability Calculations Control Network Communication
3BSE034876 61
Control Network Communication Section 3 Availability Calculations
62 3BSE034876
Appendix A Component Reliability Data
The following Table 23 and Table 24 give detailed figures for safety certified and
safety relevant HW components. It is not always possible to use the numbers found
in this appendix to calculate the values in the System Availability calculation
section. The calculated numbers are based on additional documented assumptions in
each configuration.
3BSE034876 63
Appendix A Component Reliability Data
64 3BSE034876
Appendix A Component Reliability Data
3BSE034876 65
Appendix A Component Reliability Data
Note: Not all TU8xx modules are listed in this Table 24. For Digital I/O modules
other relevant MTU:s can be used. As an example TU810 have approximately the
same value asTU844/845. Values for AI880A includes 8*TY801 or 8*TY805 shunt
stick.
66 3BSE034876
Revision History
The following table lists the revision history of this User Manual.
Revision
Description Date
Index
- First version April 2016
3BSE034876 67
Revision History
68 3BSE034876
Contact us
3BSE034876