background image

 2

02

1-

10

10

Functional Safety HiD282*, HiD284*

Planning

3

Planning

3.1

System Structure

3.1.1

Low Demand Mode of Operation

If there are two control loops, one for the standard operation and another one 

for the functional safety, then usually the demand rate for the safety loop is assumed to be less 

than once per year.
The relevant safety parameters to be verified are:

the PFD

avg

 value (average 

P

robability of dangerous 

F

ailure on 

D

emand) 

and the T

1

 value (proof test interval that has a direct impact on the PFD

avg

value)

the SFF value (

S

afe 

F

ailure 

F

raction)

the HFT architecture (

H

ardware 

F

ault 

T

olerance)

3.1.2

High Demand or Continuous Mode of Operation

If there is only one safety loop, which combines the standard operation and safety-related 

operation, then usually the demand rate for this safety loop is assumed to be higher 

than once per year.
The relevant safety parameters to be verified are:

the PFH value (

P

robability of dangerous 

F

ailure per 

H

our)

Fault reaction time of the safety system 

the SFF value (

S

afe 

F

ailure 

F

raction)

the HFT architecture (

H

ardware 

F

ault 

T

olerance)

3.1.3

Safe Failure Fraction

The safe failure fraction describes the ratio of all safe failures and dangerous detected failures 

to the total failure rate.
SFF = (

s

 + 

dd

) / (

s

 + 

dd

 + 

du

)

A safe failure fraction as defined in IEC/EN 61508 is only relevant for elements or (sub)systems 

in a complete safety loop. The device under consideration is always part of a safety loop 

but is not regarded as a complete element or subsystem.
For calculating the SIL of a safety loop it is necessary to evaluate the safe failure fraction 

of the elements and subsystems, but not of a single device.
Nevertheless the SFF of the device is given in this document for reference.

Summary of Contents for HiD2842

Page 1: ...ISO9001 2 Functional Safety Switch Amplifier HiD282 HiD284 Manual...

Page 2: ...ion as well as the supplementary clause Expanded reservation of proprietorship Worldwide Pepperl Fuchs Group Lilienthalstr 200 68307 Mannheim Germany Phone 49 621 776 0 E mail info de pepperl fuchs co...

Page 3: ...Function 8 2 3 Interfaces 8 2 4 Marking 9 2 5 Standards and Directives for Functional Safe 9 3 Planning 10 3 1 System Structure 10 3 2 Assumptions 11 3 3 Safety Function and Safe State 12 3 4 Characte...

Page 4: ...Functional Safety HiD282 HiD284 Contents 4 2021 10...

Page 5: ...ing Dismounting Disposal The documentation consists of the following parts Present document Instruction manual Manual Datasheet Additionally the following parts may belong to the documentation if appl...

Page 6: ...d understood the instruction manual and the further documentation Intended Use The device is only approved for appropriate and intended use Ignoring these instructions will void any warranty and absol...

Page 7: ...displayed in descending order as follows Informative Symbols Action This symbol indicates a paragraph with instructions You are prompted to perform an action or a sequence of actions Danger This symb...

Page 8: ...ault A separate fault indication output is available HiD284 The HiD2842 device is a 2 channel isolated barrier The HiD2844 device is a 4 channel isolated barrier This isolated barrier is used for intr...

Page 9: ...fuchs com HiD2822 HiD2824 HiD2842 HiD2844 Up to SIL 2 Note If you design the safety loops in homogeneous redundancy HFT 1 you can use the devices in applications up to SIL 3 Functional safety IEC EN 6...

Page 10: ...ually the demand rate for this safety loop is assumed to be higher than once per year The relevant safety parameters to be verified are the PFH value Probability of dangerous Failure per Hour Fault re...

Page 11: ...f 2 5 based on experience A similar factor must be used if frequent temperature fluctuations are expected Do not use more than one input channel of a multi channel device for a safety loop as the chan...

Page 12: ...sheet the input loops of all device versions are supervised The related safety function is defined as the outputs are de energized safe state if there is a line fault detected Reaction Time The fault...

Page 13: ...the safety function 156 FIT 162 FIT no part 34 FIT 34 FIT SFF 1 72 2 88 4 MTBF 2 2 acc to SN29500 This value includes failures which are not part of the safety function MTTR 24 h The value is calcula...

Page 14: ...influencing the safety function and are therefore not included in SFF and in the failure rates of the safety function 127 FIT 125 FIT no part 34 FIT 34 FIT SFF 1 75 3 86 6 MTBF 2 2 acc to SN29500 Thi...

Page 15: ...at the useful lifetime can be reduced if the device is exposed to the following conditions highly stressful environmental conditions such as constantly high temperatures temperature cycles with high t...

Page 16: ...Check the safety function to ensure the expected output behavior 4 1 Configuration Configuring the Device The device is configured via DIP switches The DIP switches for setting the safety functions a...

Page 17: ...es See chapter 3 4 It is under the responsibility of the plant operator to define the type of proof test and the interval time period Check the settings after the configuration by suitable tests 5 1 1...

Page 18: ...SC 220 or a resistor RLB 150 k to the input The device must detect an external fault This state is indicated by red LED and the relay of the corresponding output must be de activated The yellow LED is...

Page 19: ...hat repeats one NAMUR input Test all inputs outputs and safety loops that are used in the safety application HiD2822 Zone 0 1 2 Div 1 2 Zone 2 Div 2 Termination Board Multimeter mA Multimeter mA RLB R...

Page 20: ...input HiD2822 Zone 0 1 2 Div 1 2 Zone 2 Div 2 Termination Board Multimeter mA Multimeter mA RLB RSC 240 2 5 W 24 V DC Multimeter mA 240 2 5 W 24 V DC SL2 SL1 8a 7a 8b 7b 10a 9a 9b 10b 11 14 17 18 12 1...

Page 21: ...not work Take appropriate measures to protect personnel and equipment while the safety function is not available Secure the application against accidental restart 3 Do not repair a defective device A...

Page 22: ...afety function Probability of failure of components that are in the safety loop HFT Hardware Fault Tolerance MTBF Mean Time Between Failures MTTFD Mean Time To dangerous Failure MTTR Mean Time To Rest...

Page 23: ...Functional Safety HiD282 HiD284 Notes 2021 10 23...

Page 24: ...Pepperl Fuchs Quality Download our latest policy here www pepperl fuchs com quality www pepperl fuchs com Pepperl Fuchs Subject to modifications Printed in Germany DOCT 7253A...

Reviews: