Technical data 381
Relevant failure modes
The following failure modes related to the outputs of the FSO-12 have been
considered in the design:
• STO output
• PROFIsafe
• Digital outputs.
The relevant dangerous failure mode due to internal random hardware failure of FSO-
12 are that these outputs are not activated on command.
The probabilities of the dangerous undetected failures of the safety functions are
given in the basic safety table.
FSO-12 implements several diagnostics to detect internal random hardware failures.
The diagnostics cycle time for each of the channels is 10 hours or less. The
diagnostics of each channel is separate and independent of the other channel.
The relevant failure mode of the diagnostics is that, due to a random hardware fault in
the diagnostic system, the fault reaction is not performed while a detectable fault in
the safety function is present.
Conservative estimates for the probabilities of a dangerous random hardware failure
of the diagnostics when proof test interval is 20 years for the following configurations
is:
• FSO-12 module: 8.57*10-3
When a shorter proof test interval is used, the probability of a dangerous random
hardware failure is lower.
For FSO-12 module, there are no dangerous failures that are not detected by the
diagnostics.
Hardware diagnostics results, summary
λ
s
λ
d
MTTF
D
λ
du
MTTF
DU
[FIT]
[FIT]
[a]
[FIT]
[a]
FSO-xx diagnostics
713.21
713.21
160.1
7.1
16005.9
3AXD10001067885 rev B
Summary of Contents for FSO-12
Page 1: ... OPTIONS FOR ABB DRIVES FSO 12 safety functions module User s manual ...
Page 4: ......
Page 12: ...12 Table of contents ...
Page 36: ...36 Safety information and considerations ...
Page 136: ...136 Safety functions ...
Page 196: ...196 PROFIsafe 5 To read the diagnostic messages select the I O Device Diagnostics tab ...
Page 200: ...200 PROFIsafe ...
Page 326: ...326 Start up ...
Page 386: ...386 Dimension drawings ...