
7/2021
14
10 Safety-Oriented Applications for SIL 2
Safety integrity requirements
(see Technical Report 123.493-10
–
rev. 1.0)
Error rates:
Type B-Gerät (according to EN 61508-2), Safety Integrity Level (SIL) 2
λ
sd
λ
su
λ
dd
λ
du
SFF
0
331
325
37
95%
λ
su
includes errors that do not lead to error triggering!
SFF = Safe Failure Fraction
FIT = Failure in Time (1 FIT = 1 Failure / 10
9
h)
PFD
AVG
values of the MSK 200-SIL-DX:
The beta factor is 2% and was derived from IEC / EN 61508-6, Appendix D.
T [Proof]
1 Year
5 Years
10 Years
20 Years
PFD
AVG
1,8E-4
8E-4
1,6E-3
3E-3
% SIL 2
1,8%
8%
16 %
30%
PFD
AVG
= Average probability of failure on demand
T [Proof] = Detection test interval
The calculated PFDAVG values are within the permissible range for SIL 2 in accordance with Table 2 of IEC /
EN 61508-1 and meet the requirement not to cover more than 16 % of the permissible range after 10 years.
PFS
AVG
for 1 year: 1,4E-3
PFS
AVG
= Average probability of safe failure
Failure limit:
The operating mode with a low request rate is used as a basis. The proportion of the MSK 200-SIL-DX
at the PFD
AVG
value of the entire safety chain should not exceed 30%.
Signal source
35 %
MSK 200-SIL-DX
30 %
Signal processing (PLS)
35 %
Conditions:
•
The failure rates of the components used are constant over the period of use.
•
The spread of errors by the device in the system is not considered.
•
The repair time (= exchange) should be less than 72 hours.
•
The average temperature at which the device is to be used is + 40 ° C.
Normal industrial conditions are assumed.
The specified error rates refer to an ambient temperature of + 40 ° C.
For an ambient temperature of + 60 ° C, the error rates must be a factor of
2.5 be multiplied. This factor is based on experience.
Verification test:
Take the right steps to avoid misuse. By simulating the values <3.6 mA and >22 mA, it can be verified
whether the subsequent devices in the signal chain can also process the signal outside the measuring range.
In the event of an error, the device must be replaced with an equivalent one. Then restore the full function of
the safety circuit. Finally, check normal operation.