Functional Safety Manual
for the Memosens transmitter Liquiline M CM42 SIL
Version:
Page:
2.0
24
of
72
A
ll
e
R
ec
h
te
v
o
rb
eh
al
te
n
.
D
as
K
o
p
ie
re
n
d
ie
se
s
D
o
k
u
m
en
ts
u
n
d
d
ie
V
er
w
en
d
u
n
g
v
o
n
T
ei
le
n
au
s
d
ie
se
m
D
o
k
u
m
en
t
is
t
o
h
n
e
sc
h
ri
ft
li
ch
e
G
en
eh
m
ig
u
n
g
d
er
E
n
d
re
ss
+
H
au
se
r
C
o
n
d
u
ct
a
G
m
b
H
+
C
o
.
K
G
n
ic
h
t
er
la
u
b
t.
A
ll
ri
gh
ts
re
se
rv
ed
.
P
as
si
n
g
o
n
an
d
co
p
yi
n
g
o
f
th
is
d
o
cu
m
en
t,
u
se
an
d
co
m
m
u
n
ic
at
io
n
o
f
it
s
co
n
te
n
ts
n
o
t
p
er
m
it
te
d
w
it
h
o
u
t
w
ri
tt
en
au
th
o
ri
za
ti
o
n
fr
o
m
E
n
d
re
ss
+
H
au
se
r
C
o
n
d
u
ct
a
G
m
b
H
+
C
o
.
K
G
.
Dangerous undetected failures in this scenario:
A dangerous undetected failure
DU
is defined as a wrong measurement signal on the
current outputs in the range of 4..20 mA, whereas a wrong measurement value is a
value departing for more than the given precision (see chapter 2.1.3) from the true
measurement value.
Some dangerous undetected failure can be found by the voter – but not all of them. In
these cases, the transmitter does not show an error message or an unusual behaviour.
Useful lifetime of electronic components:
The underlying failure rates apply within the useful lifetime according to IEC 61508-2
Clause 7.4.7.4 Note 3 [IEC61508:2000] or Clause 7.4.9.5 Note 3 [IEC61508:2010].
Other values can be used from experience of the previous use in a similar environment.
It is assumed that early failures are detected to a huge percentage during the production
testing and installation period and therefore the assumption of a constant failure rate
during the useful lifetime is valid.
According to IEC 61508-2 section 7.4.7.4 a useful lifetime based on experience should
be assumed.
Note!
Safe operation of the device requires a correct installation according to chapter 2.3.
2.4
Behavior of the device when in operation and in case of failure
2.4.1
Behavior of the device when switched on
When starting the device, loading the software takes about 40-60s.
Safety
related internal tests are carried out. During that time the current output is held at the
high error current (>21.5 mA)
.
The power to the Memosens cable and Memosens sensor is switched on after the boot
phase, not earlier.
2.4.2
Behavior of the device on demand
If an internal error is detected, the device enters the safe state within the error reaction
time (see chapter 2.2).
In case the device reaches the active safe state, the SIL measurement mode is left, but
the SIL mode is still active. So the SIL icon remains visible in the status bar.