background image

Functional Safety KFD0-CS-(Ex)*.54*, KFD0-CS-(Ex)*.56*

Planning

201

8-06

9

3

Planning

3.1

System Structure

3.1.1

Low Demand Mode of Operation

If there are two control loops, one for the standard operation and another one for the functional 

safety, then usually the demand rate for the safety loop is assumed to be less than once 

per year.

The relevant safety parameters to be verified are:

the  PFD

avg

 value (average 

P

robability of dangerous 

F

ailure on 

D

emand) and the 

T

1

value (proof test interval that has a direct impact on the PFD

avg

value)

the SFF value (

S

afe 

F

ailure 

F

raction)

the HFT architecture (

H

ardware 

F

ault 

T

olerance)

3.1.2

High Demand or Continuous Mode of Operation

If there is only one safety loop, which combines the standard operation and safety-related 

operation, then usually the demand rate for this safety loop is assumed to be higher than 

once per year.

The relevant safety parameters to be verified are:

the  PFH  value  (

P

robability of dangerous 

F

ailure per 

H

our)

Fault reaction time of the safety system 

the SFF value (

S

afe 

F

ailure 

F

raction)

the HFT architecture (

H

ardware 

F

ault 

T

olerance)

3.1.3

Safe Failure Fraction

The safe failure fraction describes the ratio of all safe failures and dangerous detected failures 

to the total failure rate.

SFF = (

s

 + 

dd

) / (

s

 + 

dd

 + 

du

)

A safe failure fraction as defined in IEC/EN 61508 is only relevant for elements or (sub)systems 

in a complete safety loop. The device under consideration is always part of a safety loop 

but is not regarded as a complete element or subsystem.

For calculating the SIL of a safety loop it is necessary to evaluate the safe failure fraction 

of elements, subsystems and the complete system, but not of a single device.

Nevertheless the SFF of the device is given in this document for reference.

Summary of Contents for 072221

Page 1: ...ISO9001 2 Functional Safety Repeater KFD0 CS Ex 54 KFD0 CS Ex 56 PROCESS AUTOMATION MANUAL...

Page 2: ...for Products and Services of the Electrical Industry published by the Central Association of the Electrical Industry Zentralverband Elektrotechnik und Elektroindustrie ZVEI e V in its most recent ver...

Page 3: ...2 1 Function 7 2 2 Interfaces 7 2 3 Marking 8 2 4 Relevant Standards and Directives 8 3 Planning 9 3 1 System Structure 9 3 2 Assumptions 10 3 3 Safety Function and Safe State 11 3 4 Characteristic S...

Page 4: ...leshooting Dismounting Disposal The documentation consists of the following parts Present document Instruction manual Manual Datasheet Additionally the following parts may belong to the documentation...

Page 5: ...read and understood the instruction manual and the further documentation Intended Use The device is only approved for appropriate and intended use Ignoring these instructions will void any warranty an...

Page 6: ...ges are displayed in descending order as follows Informative Symbols Action This symbol indicates a paragraph with instructions You are prompted to perform an action or a sequence of actions Danger Th...

Page 7: ...monitored by control systems Additionally the device transfers AC signals from the field device to the control system This transfer can be used as safety relevant information channel for an alarm syst...

Page 8: ...nnheim Germany Internet www pepperl fuchs com KFD0 CS Ex1 54 KFD0 CS Ex1 54 Y KFD0 CS Ex2 54 KFD0 CS Ex1 56 KFD0 CS Ex2 56 Up to SIL 2 KFD0 CS Ex1 54 Y72221 Part number 072221 KFD0 CS Ex1 54 Part numb...

Page 9: ...lly the demand rate for this safety loop is assumed to be higher than once per year The relevant safety parameters to be verified are the PFH value Probability of dangerous Failure per Hour Fault reac...

Page 10: ...solver is designed such that all currents below 1 mA or above 40 mA 20 mA for KFD0 CS Ex 54 are detected and lead to the safe state SIL 2 Application The device shall claim less than 10 of the total f...

Page 11: ...the alarm state Analog current signal transfer Enough voltage is available to supply the connected alarm devices while communication is not relied on Safe State Safety relevant communication The alarm...

Page 12: ...on Safety relevant communication Analog current signal transfer s 60 FIT 0 FIT dd 0 FIT 34 0 FIT du 5 7 FIT 34 2 FIT total safety function 132 FIT 68 FIT no effect 66 FIT 58 FIT not part 16 0 FIT 22 2...

Page 13: ...d for components that have this constant domain and that the validity of the calculation is limited to the useful lifetime of each component It is assumed that early failures are detected to a huge pe...

Page 14: ...fety instructions in the instruction manual 2 Observe the information in the manual 3 Observe the requirements for the safety loop 4 Connect the device only to devices that are suitable for this safet...

Page 15: ...oof test can be performed which will reveal all of the possible dangerous faults diagnostic coverage 100 Equipment required Digital multimeter with an accuracy better than 0 1 Use for the proof test o...

Page 16: ...voltage V 54 Y2 versions Output voltage V 54 Y3 versions Output voltage V 56 versions 1 24 00 0 00 22 75 0 75 22 75 0 75 22 75 0 75 n a 2 24 00 4 00 21 00 0 50 20 00 0 30 21 50 0 50 n a 3 24 00 20 00...

Page 17: ...r replaced If the safety loop does not work without the device shut down the application Do not restart the application without taking proper precautions Secure the application against accidental rest...

Page 18: ...not used for calculation of SFF not part Probability of failure of components that are not in the safety loop total safety function Probability of failure of components that are in the safety loop HF...

Page 19: ...Functional Safety KFD0 CS Ex 54 KFD0 CS Ex 56 Notes 2018 06 19...

Page 20: ...rl fuchs com Worldwide Headquarters Pepperl Fuchs GmbH 68307 Mannheim Germany Tel 49 621 776 0 E mail info de pepperl fuchs com For the Pepperl Fuchs representative closest to you check www pepperl fu...

Reviews: