2
02
1-
09
10
Functional Safety K-LB-*.*, F*-LB-I, P-LB-*.*.*
Planning
3
Planning
3.1
System Structure
3.1.1
Low Demand Mode of Operation
If there are two control loops, one for the standard operation and another one for the functional
safety, then usually the demand rate for the safety loop is assumed to be less than once
per year.
The relevant safety parameters to be verified are:
•
the PFD
avg
value (average
P
robability of dangerous
F
ailure on
D
emand)
and the T
1
value (proof test interval that has a direct impact on the PFD
avg
value)
•
the SFF value (
S
afe
F
ailure
F
raction)
•
the HFT architecture (
H
ardware
F
ault
T
olerance)
3.1.2
High Demand or Continuous Mode of Operation
If there is only one safety loop, which combines the standard operation and safety-related
operation, then usually the demand rate for this safety loop is assumed to be higher than
once per year.
The relevant safety parameters to be verified are:
•
the PFH value (
P
robability of dangerous
F
ailure per
H
our)
•
Fault reaction time of the safety system
•
the SFF value (
S
afe
F
ailure
F
raction)
•
the HFT architecture (
H
ardware
F
ault
T
olerance)