
Issue 5 - September 2006
Page 49 of 65
1
2
3
4
5
6
7
ESD
Network 009 - Example Shutdown Logic
Scan Rate 00030ms
Label 05010 Enabled
1005
3003
1006
3003
NOT
6009
9026
6009
1007
9027
1008
9028
3002
9028
3001
9027
1010
1011
5002
6009
1009
3004
3004
NOT
9029
MAIN
PUMP
START
HS001
MAIN
PUMP
STOP
HS002
SV0001
LATCH
WorkingDis3003
SV0001
LATCH
WorkingDis3003
COMBINED
PLC
SHUTDOWN
WorkingDis6009
STEAM
INLET
VALVE
SV0001
COMBINED
PLC
SHUTDOWN
MAIN
ESD
RESET
PALL0001
2oo3 VOTED
LOGIC INPUT
MAIN
SHUTDOWN
VALVE
TANK
LEVEL
HIGH
POSITIVE
LOGIC
LATCH
WorkingDis6009
HS003
WorkingDis3001
ESDV0001
LSH0001
WorkingDis3004
MAIN
SHUTDOWN
VALVE
FLOW
RATE
HIGH
ESD 2
BLOCK
VALVE
ESDV0001
FSH0001
ESDV0003
ESD1
RESET
HS004
PAHH0001
2oo3 VOTED
LOGIC INPUT
WorkingDis3002
ESD 1
BLOCK
VALVE
ESDV0002
PALL0001B
LOGIC
INPUT
WorkingDis5002
ESD 1
BLOCK
VALVE
COMBINED
PLC
SHUTDOWN
WorkingDis6009
ESD2
RESET
ESDV0002
HS005
POSITIVE
LOGIC
LATCH
WorkingDis3004
Example Shutdown Logic with resets are shown (both positive and negative logic example are shown).
Implementation of Logic is to customer Cause & Effects/Logic Diagrams or other design documentation.
It is Mandatory that the diagnostic shutdown is included into the customers logic requirements such that all
safety outputs are de-energised and the ESD logic is tripped (via discrete 6009) if only one processor is
running, or the scan is the first scan, or the system time constraint is exceeded, or an critical I/O module is
Off-Line for more than the time set in timer R1203, or an I/O module is removed from the chassis without first
being taken Off-line, or a I/O chassis is lost to be system by total power failure or loss of two MBB modules.
In addition, only the fail safe logic input should be used for safety critical logics.