Loreme CAL4/100ig Safety Manual Download Page 12

 

SOMMAIRE

 

LOREME

 12, rue des Potiers d'Etain - 57071 Metz  

 03.87.76.32.51 - Fax 03.87.76.32.52 - Email: [email protected] - [email protected]

 

E 12

 

Abbreviation  

 

 

Description 

 
HFT    

Hardware Fault Tolerance, capability of a functional unit to continue the execution of the demanded function when 

 

 

faults or anomalies exist. 

MTBF   

Mean interval between two failures 

MTTR   

Mean interval between the occurrence of the failure in a device or system and its repair 

PFD    

Probability of a dangerous failure of a system on demand 

PFDavg  

Average of probability of dangerous failure of a system on demand 

SIL  

 

Safety Integrity Level, the international standard IEC 61508 defines four discrete safety integrity levels (SIL1 to SIL4). 

 

 

Each level corresponds to a specific probability range with respect to the failure of a safety function. The higher the 

 

 

integrity level of the safety-related system, the lower the likelihood of the demanded safety functions not occurring. 

SFF    

Safe Failure Fraction, the proportion of failures without the potential to put the safety-related system into 

 

 

a dangerous or impermissible functional state. 

TProof  

In accordance with IEC 61508-4, chapter 3.5.8, TProof is defined as the periodic testing to expose errors in a  

 

 

safety-related system. 

XooY   

Classification and description of the safety-related system with respect to redundancy and the selection procedure 

 

 

used. "Y" indicates how often the safety function is carried out (redundancy). "X" determines how many channels must 

 

 

work properly. 

λsd and λsu  

λsd Safe de λsu Safe undetected Safe failure (IEC 61508-4, chapter 3.6.8): 

 

 

A safe failure is present when the measuring system switches to the defined safe state or the fault signaling mode with

 

 

out the process demanding it. 

λdd and λdu  

λdd Dangerous de λdu Dangerous undetected Unsafe failure (IEC 61508-4, chapter 3.6.7): 

 

 

Generally a dangerous failure occurs if the measuring system switches into a dangerous or functionally inoperable  

 

 

condition. 

λdu    

λdu Dangerous undetected.  A dangerous undetected failure occurs if the measuring system doesn't switch into a define 

 

 

safe state, or into an alarm signaling mode on process demand.  

Appendix  : term and definitions

.

 

SIL stands for "Security Integrity Level", which is the level of integrity of security. The concept of SIL has been introduced in the 
IEC61508 standard and is incorporated in standards derived from IEC61508, such as the IEC61511 standard for safety instrumented 
systems (SIS) for processes and IEC62061 for safety systems with programmable electronics for machines. 
When you want to make a security application, you have to start by assessing the risk (its dangerousness, its frequency of occur-
rence), which leads to defining the security requirements that we expect from the SIS. to say its SIL. 
Ultimately, the SIL defines the level of reliability of the SIS. There are two ways to define the SIL, depending on whether the security 
system operates in low demand mode or if on the contrary it operates continuously or with high demand. There are 4 levels of SIL 
(rated SIL1 to SIL4) higher the SIL level, higher the availability of the security system. 
For 

Safety system operating in low demand mode

The failure measure is based on average Probability of dangerous Failure on Demand ( PFD

avg 

) with a 10 years period. 

The relationship between SIL level and PFDavg are following: 
SIL 4 : PFDavg from 10

-5

 to 10

-4

 

SIL 3 : PFDavg from 10

-4

 to 10

-3

 

SIL 2 : PFDavg from 10

-3

 to 10

-2

 

SIL 1 : PFDavg from 10

-2

 to 10

-1

 

For 

Safety system operating in high demand mode,  

The failure measure is based on average Frequency of Dangerous failure per hour. relationship between level and PFH are following:  
SIL 4 : PFH from 10

-9

 to 10

-8

 

SIL 3 : PFH from 10

-8

 to 10

-7

 

SIL 2 : PFH from 10

-7

 to 10

-6

 

SIL 1 : PFH from 10

-6

 to 10

-5

 

4-20mA signal isolator, signal splitter with 2,3,4 outputs 
SIL2 / SIL3   

 

 

 

 CAL4/100ig     CAL4/100igM 

SIL levels scale : 

 

Mode of operations 

 

 

SIL* 

Low demand 

PFD** 

High demand 

PFH*** 

Risk reduction  

factor 

≥10

-5

 to <10

-4

 

≥10

-9

 to <10

-8

 

10 000 to 100 000 

≥10

-4

 to <10

-3

 

≥10

-8

 to <10

-7

 

1 000 to 10 000 

≥10

-3

 to <10

-2

 

≥10

-7

 to <10

-6

 

100 to 1 000 

≥10

-2

 to <10

-1

 

≥10

-6

 to <10

-5

 

10 to 100 

* Safety integrity level 
** Probability of Failure on low Demand 
*** Probability of a dangerous Failure per Hour 

Summary of Contents for CAL4/100ig

Page 1: ...fety manual LOREME 12 rue des Potiers d Etain Actipole BORNY B P 35014 57071 METZ Phone 03 87 76 32 51 Fax 03 87 76 32 52 Contact Commercial Loreme fr Technique Loreme fr Download manual on www loreme...

Page 2: ...tate E4 2 1 Safety function E4 2 2 Safety fallback position E4 3 Safety Recommendation E4 3 1 Interfaces E4 3 2 Configuration Calibration E4 3 3 Useful lifetime E4 4 Installation commissioning and rep...

Page 3: ...urity features and damage to property environment or people 1 2 Functions and intended uses The transducer CAL4 100ig provides isolation and duplication of analog current loop 4 20mA an auxiliary powe...

Page 4: ...ssumed by the probabilistic estimation that it applies only to the useful lifetime of components Beyond this lifetime the probability of failure is increasing significantly with time The useful lifeti...

Page 5: ...uts SIL2 SIL3 CAL4 100ig CAL4 100igM Green LED Power indicates that the device is cor rectly power on Blink if power is on protected mode under voltage supply overload or thermal protection mode Green...

Page 6: ...ode the output load resistance must be between 0 ohms and 600 ohms Input wiring In 4 20mA passive current input between terminal in and GND for active transmitter In 4 20mA loop with transmitter suppl...

Page 7: ...efined under paragraph proof interval 5 1 control steps Periodic proof allows detection of possible product internal failure and loop calibration environmental conditions and a minimum heating time of...

Page 8: ...ls 4 20mA image of input Generally a transducer is taking place between a sensor and a protective equipment designated as Logic Safety Equipment Sensor transmitter CAL4 100ig PLC Logic Safety Equipmen...

Page 9: ...reby in the FMEA analysis this state is considered as a not dangerous state Study hypotheses The failure rate of component are considered as constant for the all system life time The evaluation of the...

Page 10: ...ion up to SIL3 according to standard IEC61508 2 2000 respecting the safety instructions specified in the safety manual The assessment of the safety critical and dangerous random failure give the follo...

Page 11: ...of a device with a walkie talkie 5 W output power because it creates a electromagnetic field with an intensity greater than 10 V M for a distance of less than 50 cm 2 2 Power supply Observe the charac...

Page 12: ...failure occurs if the measuring system doesn t switch into a define safe state or into an alarm signaling mode on process demand Appendix term and definitions SIL stands for Security Integrity Level w...

Reviews: