background image

20

17-

06

10

Functional Safety HiC2883

Planning

3.2

Assumptions

The following assumptions have been made during the FMEDA:
• Failure rate based on the Siemens standard SN29500.
• Failure rates are constant, wear is not considered.
• External power supply failure rates are not included.
• The safety-related device is considered to be of type 

A

 device with a hardware 

fault tolerance of 

0

.

• The device will be used under average industrial ambient conditions, which 

are comparable with the classification "stationary mounted" in MIL-HDBK-

217F. Alternatively, the following ambient conditions are assumed:
• IEC/EN 60654-1 Class C (sheltered location) with temperature limits in the 

range of the manufacturer's specifications and an average temperature of 

40 

º

C over a long period. The humidity level is within manufacturer's rating. 

For a higher average temperature of 60 

º

C, the failure rates must be 

multiplied by a factor of 2.5 based on experience. A similar factor must be 

used if frequent temperature fluctuations are expected.

• The device shall claim less than 10 % of the total failure rate for a SIL 3 safety 

loop.

• For a SIL 3 application operating in low demand mode the total PFD

avg

 value 

of the SIF (

S

afety 

I

nstrumented 

F

unction) should be smaller than 10

-3

, hence 

the maximum allowable PFD

avg

 value would then be 10

-4

.

• For a SIL 3 application operating in high demand mode the total PFH value of 

the SIF should be smaller than 10

-7

 per hour, hence the maximum allowable 

PFH value would then be 10

-8

 per hour.

• Since the safety loop has a hardware fault tolerance of 

0

 and it is a type 

A

 

device, the SFF must be > 90 % according to table 2 of IEC/EN 61508-2 for a 

SIL 3 (sub) system.

Summary of Contents for HiC2883

Page 1: ...ISO9001 3 Functional Safety Solenoid Driver HiC2883 PROCESS AUTOMATION MANUAL...

Page 2: ...f Delivery for Products and Services of the Electrical Industry published by the Central Association of the Electrical Industry Zentralverband Elektrotechnik und Elektroindustrie ZVEI e V in its most...

Page 3: ...tandards and Directives for Functional Safety 8 3 Planning 9 3 1 System Structure 9 3 2 Assumptions 10 3 3 Safety Function and Safe State 11 3 4 Characteristic Safety Values 12 3 5 Useful Life Time 13...

Page 4: ...Disposal The documentation consists of the following parts Present document Instruction manual Manual Datasheet Additionally the following parts may belong to the documentation if applicable EU type e...

Page 5: ...nderstood the instruction manual and the further documentation Intended Use The device is only approved for appropriate and intended use Ignoring these instructions will void any warranty and absolve...

Page 6: ...splayed in descending order as follows Informative Symbols Action This symbol indicates a paragraph with instructions You are prompted to perform an action or a sequence of actions Danger This symbol...

Page 7: ...and de activated The line fault transparency function can display a line fault in the field by a change in impedance at the switching input of the solenoid driver The line fault transparency function...

Page 8: ...ectives System specific standards and directives Functional safety IEC EN 61508 part 1 7 edition 2010 Functional safety of electrical electronic programmable electronic safety related systems manufact...

Page 9: ...this safety loop is assumed to be higher than once per year The relevant safety parameters to be verified are the PFH value Probability of dangerous Failure per Hour Fault reaction time of the safety...

Page 10: ...ure of 40 C over a long period The humidity level is within manufacturer s rating For a higher average temperature of 60 C the failure rates must be multiplied by a factor of 2 5 based on experience A...

Page 11: ...afety Function When the input signal is active the output is activated The safe state is introduced when the input voltage is below 5 V DC Reaction Time The reaction time for all safety functions is 1...

Page 12: ...output is de energized if the input is in low condition s 130 FIT dd 0 FIT du 0 02 FIT total safety function 130 FIT SFF 1 1 No effect failures and Annunciation failures are not influencing the safet...

Page 13: ...onents that have this constant domain and that the validity of the calculation is limited to the useful lifetime of each component It is assumed that early failures are detected to a huge percentage d...

Page 14: ...ure the expected output behavior 4 1 Configuration Configuring the Device The device is configured via DIP switches The DIP switches for setting the safety functions are on the side of the device 1 De...

Page 15: ...haracteristic safety values See chapter 3 4 It is under the responsibility of the plant operator to define the type of proof test and the interval time period Check the settings after the configuratio...

Page 16: ...nput value Output value 1 24 V DC 19 V high On Imax current depends on device version 2 24 V DC 5 V low Off 0 5 mA 3 0 V DC 0 V Off 0 mA Table 5 1 Steps to be performed for the proof test HiC2883 14 1...

Page 17: ...y loop does not work without the device shut down the application Do not restart the application without taking proper precautions Secure the application against accidental restart 3 Do not repair a d...

Page 18: ...effect failure is not used for calculation of SFF not part Probability of failure of components that are not in the safety loop total safety function Safety function HFT Hardware Fault Tolerance MTBF...

Page 19: ...Functional Safety HiC2883 Notes 2017 06 19 Pulscon LTC50 HART...

Page 20: ...rl fuchs com PROCESS AUTOMATION PROTECTING YOUR PROCESS Worldwide Headquarters Pepperl Fuchs GmbH 68307 Mannheim Germany Tel 49 621 776 0 E mail info de pepperl fuchs com For the Pepperl Fuchs represe...

Reviews: