16
Rockwell Automation Publication ICSTT-RM446N-EN-P - April 2018
Chapter 1
Introduction
Terminology
Vocabulary and Conventions
The terms
certification
and
certified
are used widely within this Manual,
these terms refer principally to the functional safety certification of the
AADvance system to IEC 61508 SIL 3 and other relevant standards.
This Manual contains rules and recommendations:
•
Rules
are mandatory and shall be followed if the resulting application is
to be compliant with IEC 61508 up to and including SIL 3. These are
identified by the term 'shall'.
•
Recommendations
are not mandatory, but if they are not followed,
extra safety precautions shall be taken in order to certify the system.
Recommendations are identified by the term ‘
it is highly
recommended
'.
Process Safety Time
The generally accepted understanding of process safety time is the period a
dangerous condition can exist in the process before a hazardous event occurs
without a safeguard. This process safety time is used to determine the response
time for the SIF implemented in the SIS.
AADvance has a configuration parameter called 'Process Safety Time', which is
used to enforce the safe state when a dangerous failure is detected, to ensure
that the Process PST is not exceeded. This configuration parameter only
applies to the logic solver portion of the process safety time, so its value must be
configured taking into account both the sensor and final element response
times.
Fault Tolerance in Safety Applications
For safety applications you shall define how the control system will respond in
the presence of faults. Fail Safe configurations are designed to enforce a 'safe
state' when dangerous faults are detected.
Fault tolerant configurations are designed to allow continued operation of the
process without any loss of Safety Integrity when a dangerous fault is detected
(as long as the fault is repaired within the MTTR).
Internal diagnostics combined with redundancy provide the fault tolerance
capability. The AADvance system diagnostics will detect hidden faults so that
users can repair the system within the MTTR (used for the PFD calculations)
and maintain the SIF's integrity level.
The AADvance Controller
The AADvance Controller is specifically designed for functional safety and
critical control applications, it provides a flexible solution for smaller scale