Pepperl+Fuchs HiC2883 Manual Download Page 9

Functional Safety HiC2883

Planning

20

17-

06

9

3

Planning

3.1

System Structure

3.1.1

Low Demand Mode of Operation

If there are two control loops, one for the standard operation and another one for 

the functional safety, then usually the demand rate for the safety loop is assumed 

to be less than once per year.
The relevant safety parameters to be verified are:
• the  PFD

avg

 value (average 

P

robability of dangerous 

F

ailure on 

D

emand) and 

the T

1

 value (proof test interval that has a direct impact on the PFD

avg

 value)

• the SFF value (

S

afe 

F

ailure 

F

raction)

• the  HFT  architecture  (

H

ardware 

F

ault 

T

olerance)

3.1.2

High Demand or Continuous Mode of Operation

If there is only one safety loop, which combines the standard operation and 

safety-related operation, then usually the demand rate for this safety loop is 

assumed to be higher than once per year.
The relevant safety parameters to be verified are:
• the PFH value (

P

robability of dangerous 

F

ailure per 

H

our)

• Fault reaction time of the safety system 
• the SFF value (

S

afe 

F

ailure 

F

raction)

• the  HFT  architecture  (

H

ardware 

F

ault 

T

olerance)

3.1.3

Safe Failure Fraction

The safe failure fraction describes the ratio of all safe failures and dangerous 

detected failures to the total failure rate.
SFF = (

s

 + 

dd

) / (

s

 + 

dd

 + 

du

)

A safe failure fraction as defined in IEC/EN 61508 is only relevant for elements or 

(sub)systems in a complete safety loop. The device under consideration is 

always part of a safety loop but is not regarded as a complete element or 

subsystem.
For calculating the SIL of a safety loop it is necessary to evaluate the safe failure 

fraction of elements, subsystems and the complete system, but not of a single 

device.
Nevertheless the SFF of the device is given in this document for reference.

Functional Safety HiC2883

Summary of Contents for HiC2883

Page 1: ...ISO9001 3 Functional Safety Solenoid Driver HiC2883 PROCESS AUTOMATION MANUAL...

Page 2: ...f Delivery for Products and Services of the Electrical Industry published by the Central Association of the Electrical Industry Zentralverband Elektrotechnik und Elektroindustrie ZVEI e V in its most...

Page 3: ...tandards and Directives for Functional Safety 8 3 Planning 9 3 1 System Structure 9 3 2 Assumptions 10 3 3 Safety Function and Safe State 11 3 4 Characteristic Safety Values 12 3 5 Useful Life Time 13...

Page 4: ...Disposal The documentation consists of the following parts Present document Instruction manual Manual Datasheet Additionally the following parts may belong to the documentation if applicable EU type e...

Page 5: ...nderstood the instruction manual and the further documentation Intended Use The device is only approved for appropriate and intended use Ignoring these instructions will void any warranty and absolve...

Page 6: ...splayed in descending order as follows Informative Symbols Action This symbol indicates a paragraph with instructions You are prompted to perform an action or a sequence of actions Danger This symbol...

Page 7: ...and de activated The line fault transparency function can display a line fault in the field by a change in impedance at the switching input of the solenoid driver The line fault transparency function...

Page 8: ...ectives System specific standards and directives Functional safety IEC EN 61508 part 1 7 edition 2010 Functional safety of electrical electronic programmable electronic safety related systems manufact...

Page 9: ...this safety loop is assumed to be higher than once per year The relevant safety parameters to be verified are the PFH value Probability of dangerous Failure per Hour Fault reaction time of the safety...

Page 10: ...ure of 40 C over a long period The humidity level is within manufacturer s rating For a higher average temperature of 60 C the failure rates must be multiplied by a factor of 2 5 based on experience A...

Page 11: ...afety Function When the input signal is active the output is activated The safe state is introduced when the input voltage is below 5 V DC Reaction Time The reaction time for all safety functions is 1...

Page 12: ...output is de energized if the input is in low condition s 130 FIT dd 0 FIT du 0 02 FIT total safety function 130 FIT SFF 1 1 No effect failures and Annunciation failures are not influencing the safet...

Page 13: ...onents that have this constant domain and that the validity of the calculation is limited to the useful lifetime of each component It is assumed that early failures are detected to a huge percentage d...

Page 14: ...ure the expected output behavior 4 1 Configuration Configuring the Device The device is configured via DIP switches The DIP switches for setting the safety functions are on the side of the device 1 De...

Page 15: ...haracteristic safety values See chapter 3 4 It is under the responsibility of the plant operator to define the type of proof test and the interval time period Check the settings after the configuratio...

Page 16: ...nput value Output value 1 24 V DC 19 V high On Imax current depends on device version 2 24 V DC 5 V low Off 0 5 mA 3 0 V DC 0 V Off 0 mA Table 5 1 Steps to be performed for the proof test HiC2883 14 1...

Page 17: ...y loop does not work without the device shut down the application Do not restart the application without taking proper precautions Secure the application against accidental restart 3 Do not repair a d...

Page 18: ...effect failure is not used for calculation of SFF not part Probability of failure of components that are not in the safety loop total safety function Safety function HFT Hardware Fault Tolerance MTBF...

Page 19: ...Functional Safety HiC2883 Notes 2017 06 19 Pulscon LTC50 HART...

Page 20: ...rl fuchs com PROCESS AUTOMATION PROTECTING YOUR PROCESS Worldwide Headquarters Pepperl Fuchs GmbH 68307 Mannheim Germany Tel 49 621 776 0 E mail info de pepperl fuchs com For the Pepperl Fuchs represe...

Reviews: