background image

 

10 

D5062 

- SIL 2 Vibration Transducer Interface 

G.M. International ISM0184-7 

Functional Safety Manual and Application 

3

rd 

Application for D5062S, with 2 wires AC (unpowered) transducer input

 

Failure category

 

Failure rates (FIT)

 

λ

dd

 = Total Dangerous Detected failures 

160.84 

λ

du

 = Total Dangerous Undetected failures 

71.96 

λ

sd

 = Total Safe Detected failures 

0.00 

λ

su

 = Total Safe Undetected failures 

0.00 

λ

tot safe

 = Total Failure Rate (Safety Function) = 

λ

dd

 + 

λ

du

 + 

λ

sd

 + 

λ

su

 232.80

 

MTBF (safety function, single channel) = (1 / 

λ

tot safe

) + MTTR (8 hours) 

490 years

 

λ

no effect

 = “No Effect” failures 

269.70 

λ

not part

 = “Not Part” failures 

22.70 

λ

tot device

 = Total Failure Rate (Device) = 

λ

tot safe

 + 

λ

no effect

 + 

λ

not part

  

525.20

 

MTBF (device, single channel) = (1 / 

λ

tot device

) + MTTR (8 hours) 

217 years

 

λ

sd

 

λ

su

 

λ

dd

 

λ

du

 

SFF

 

DC

D

 

0.0 FIT 

0.00 FIT 

160.84 FIT 

71.96 FIT 

69.09% 

69.09% 

T[Proof] = 1 year

 

T[Proof] = 3 years

 

PFDavg = 3.17E-04

 

Valid for 

SIL 2

  PFDavg = 9.51E-04

 

Valid for 

SIL 2

 

PFDavg vs T[Proof] table 

(assuming Proof Test coverage of 99%), with determination of SIL supposing module contributes >10% of total SIF dangerous failures: 

PFDavg vs T[Proof] table

 (assuming Proof Test coverage of 99%), with determination of SIL supposing module contributes 

10% of total SIF dangerous failures:       

Failure rates table according to IEC 61508:2010 Ed.2 : 

Failure rate table:

 

Safety Function and Failure behavior:

  

D5062S is considered to be operating in Low Demand mode, as a Type A module, having Hardware Fault Tolerance (HFT) = 0. 
The failure behaviour is described by the following definitions: 
 

 Fail-Safe State: is defined as the output going Low or High, considering that the safety logic solver can convert the Low or High fail (dangerous detected) to the fail-safe state. 

 

 Fail Safe: a failure mode that causes the module / (sub)system to go to the defined fail-safe state without a demand from the process. 

 

 Fail Dangerous: failure mode that does not respond to a demand from the process (i.e. being unable to go to  the defined fail-safe state) or deviates the output voltage by more  

     than 5 % of full span (> ± 1 Vdc). 
 

 Fail High: a failure mode that causes the output signal to go below the maximum negative voltage (< -20 Vdc). Assuming that the application program in the safety logic solver is  

     configured to detect High failure and does not automatically trip on this failure, this failure has been classified as a dangerous detected (DD) failure. 
 

 Fail Low: a failure mode that causes the output signal to go above the minimum negative voltage (> -0.5 Vdc). Assuming that the application program in the safety logic solver is  

     configured to detect Low failure and does not automatically trip on this failure, this failure has been classified as a dangerous detected (DD) failure. 
 

 Fail “No Effect”: failure mode of a component that plays a part in implementing the safety function but that is neither a safe failure nor a dangerous failure because the output  

     voltage is deviated by less than 5 % of full span (< ± 1 Vdc). When calculating the SFF, this failure mode is not taken into account. 
 

 Fail “Not part”: failure mode of a component that is not part of the safety function but part of the circuit  diagram and is listed for completeness. When calculating the SFF, this  

     failure mode is not taken into account. 

  Failure rate date: taken from Siemens Standard SN29500. 

Description:

  

For this application, set the internal dip-switches in the following mode (see page 11 for more information): 

D5062S 

Signal - 

 

2  

Out  

  The D5062S module is supplied (with 18 to 30Vdc supply voltage) at Pins 5 (+) – 6 (-). The green LED is lit in presence of supply power. 

The input transducer AC signal (0 to 20Vpp, DC to 20kHz) is applied between Pins 8-7/9 (-Signal, Common). No DC offset must be applied. 

  The input signal (0 to 20Vpp, DC to 20kHz) is identically repeated at output Pins 1-2 (-Signal, Common). 

T[Proof] = 20 years

 

PFDavg = 6.34E-03

 

Valid for 

SIL 2

 

 

Supply  

24 Vdc 

5 + 

6 - 

10 

 

In  

2 wires 

Vibration  

Transducer 

Dip-switch position (D5062S) 

1 2 3 4 

2 wires AC transducer  

OFF OFF OFF ON 

Systematic capability SIL 3.

 

Common 

7/9 

AC Signal 

Common 

Vibration 
Monitor - 

Safety 

PLC Input 

Summary of Contents for D5062S

Page 1: ...D5062 SIL 2 Vibration Transducer Interface G M International ISM0184 7 SIL 2 Vibration Transducer Interface DIN Rail and Termination Board Model D5062S D5062S INSTRUCTION SAFETY MANUAL...

Page 2: ...ent temperature Calibration accuracy 0 05 of full scale Linearity error 0 05 of full scale Supply voltage influence 0 005 of full scale for a min to max supply change Temperature influence 0 005 on ze...

Page 3: ...mpatibility to EN61000 6 2 EN61000 6 4 EN61326 1 EN61326 3 1 for safety system ATEX IECEx UL C UL UKR TR n 898 TIIS T V Certifications T V Functional Safety Certification Type Approval Certificate DNV...

Page 4: ...IIC E F G Co Ca 0 7 F 7 8 9 10 Ci Ci device C cable IIC A B Lo La 4 1 mH IIB C Lo La 16 4 mH IIA D Lo La 33 9 mH I Lo La 54 mH IIIC E F G Lo La 16 4 mH 7 8 9 10 Li Li device L cable IIC A B Lo Ro 56 8...

Page 5: ...P IIC SAFE AREA ZONE 2 GROUP IIC T4 NON HAZARDOUS LOCATIONS CLASS I DIVISION 2 GROUPS A B C D T Code T4 CLASS I ZONE 2 GROUP IIC T4 MODEL D5062S 8 9 5 6 Supply 24 Vdc 7 Out 1 2 In Power 3 wires Vibrat...

Page 6: ...T4 CLASS I ZONE 2 GROUP IIC T4 Input configuration selection via internal Dip Switch 1 2 3 4 ON OFF 2 wires transducers 4 mA 1 ON 2 OFF 3 OFF 4 OFF 1 2 3 4 ON OFF 2 wires transducers 6 mA 1 ON 2 ON 3...

Page 7: ...N HAZARDOUS LOCATIONS CLASS I DIVISION 2 GROUPS A B C D T Code T4 CLASS I ZONE 2 GROUP IIC T4 Input configuration selection via internal Dip Switch 1 2 3 4 ON OFF 2 wires AC transducers 1 OFF 2 OFF 3...

Page 8: ...ge 20 Vdc Assuming that the application program in the safety logic solver is configured to detect High failure and does not automatically trip on this failure this failure has been classified as a da...

Page 9: ...more than 5 of full span 1 Vdc Fail High a failure mode that causes the output signal to go below the maximum negative voltage 20 Vdc Assuming that the application program in the safety logic solver...

Page 10: ...able to go to the defined fail safe state or deviates the output voltage by more than 5 of full span 1 Vdc Fail High a failure mode that causes the output signal to go below the maximum negative volta...

Page 11: ...smaller than 1 In addition impose a zero input signal and verify that the output ripple is 20 mVrms This test detects any other possible failure in the loop transfer function 4 Connect a current sinki...

Page 12: ...totally isolated circuit located in Safe Area to drive vibration monitors or analyzers for rotating machinery control and supervision purposes The module provides 3 port isolation input output supply...

Reviews: