background image

 2

01

9-

12

14

Functional Safety KFD2-RSH-1.2E.L*(-Y1)

Planning

The characteristic safety values like PFD, PFH, SFF, HFT and T

1

 are taken 

from the FMEDA report. Observe that PFD and T

1

 are related to each other.

The function of the devices has to be checked within the proof test interval (T

1

).

3.5

Useful Lifetime

Although a constant failure rate is assumed by the probabilistic estimation this only applies 

provided that the useful lifetime of components is not exceeded. Beyond this useful lifetime, 

the result of the probabilistic estimation is meaningless as the probability of failure significantly 

increases with time. The useful lifetime is highly dependent on the component itself 

and its operating conditions 

 temperature in particular. For example, the electrolytic 

capacitors can be very sensitive to the operating temperature.
This assumption of a constant failure rate is based on the bathtub curve, which shows 

the typical behavior for electronic components.
Therefore it is obvious that failure calculation is only valid for components that have 

this constant domain and that the validity of the calculation is limited to the useful lifetime 

of each component.
It is assumed that early failures are detected to a huge percentage during the installation 

and therefore the assumption of a constant failure rate during the useful lifetime is valid.
The standard EN/ISO 13849-1:2015 proposes a useful lifetime T

M

 of 20 years for devices 

used within industrial environments. This device is designed for this lifetime. 

Observe that the useful lifetime can be reduced if the device is exposed to the following 

conditions:

highly stressful environmental conditions such as constantly high temperatures

temperature cycles with high temperature differences

permanent repeated mechanical stress (vibration)

As noted in DIN EN 61508-2:2011 note N3, appropriate measures taken by the manufacturer 

and plant operator can extend the useful lifetime.
Please note that the useful lifetime refers to the (constant) failure rate of the device. 

The effective lifetime can be higher.
The estimated useful lifetime is greater than the warranty period prescribed by law 

or the manufacturer's guarantee period. However, this does not result in an extension 

of the warranty or guarantee services. Failure to reach the estimated useful lifetime 

is not a material defect.

Derating

For the safety application, reduce the number of switching cycles or the maximum current. 

A derating to 2/3 of the maximum value is adequate.

Maximum Switching Power of Output Contacts

The useful lifetime is limited by the maximum switching cycles of the relays 

under load conditions.
For requirements regarding the connected output load, refer to the documentation 

of the connected peripheral devices.

Note

See corresponding datasheets for further information.

Summary of Contents for KFD2-RSH-1.2E.L2

Page 1: ...ISO9001 3 Functional Safety Relay Module KFD2 RSH 1 2E L2 Y1 KFD2 RSH 1 2E L3 Y1 Manual...

Page 2: ...ion as well as the supplementary clause Expanded reservation of proprietorship Worldwide Pepperl Fuchs Group Lilienthalstr 200 68307 Mannheim Germany Phone 49 621 776 0 E mail info de pepperl fuchs co...

Page 3: ...Standards and Directives for Functional Safe 9 3 Planning 10 3 1 System Structure 10 3 2 Assumptions 11 3 3 Safety Function and Safe State 12 3 4 Characteristic Safety Values 13 3 5 Useful Lifetime 1...

Page 4: ...Functional Safety KFD2 RSH 1 2E L Y1 Contents 4 2019 11...

Page 5: ...oting Dismounting Disposal The documentation consists of the following parts Present document Instruction manual Manual Datasheet Additionally the following parts may belong to the documentation if ap...

Page 6: ...and understood the instruction manual and the further documentation Intended Use The device is only approved for appropriate and intended use Ignoring these instructions will void any warranty and abs...

Page 7: ...are displayed in descending order as follows Informative Symbols Action This symbol indicates a paragraph with instructions You are prompted to perform an action or a sequence of actions Danger This s...

Page 8: ...he device is a relay module that is suitable for safely switching applications of a load circuit The device isolates load circuits up to 60 V DC and the 24 V DC control circuit KFD2 RSH 1 2E L3 Y1 The...

Page 9: ...and directives Pepperl Fuchs Group Lilienthalstra e 200 68307 Mannheim Germany Internet www pepperl fuchs com KFD2 RSH 1 2E L2 KFD2 RSH 1 2E L2 Y1 KFD2 RSH 1 2E L3 KFD2 RSH 1 2E L3 Y1 Up to SIL 3 Fun...

Page 10: ...the demand rate for this safety loop is assumed to be higher than once per year The relevant safety parameters to be verified are the PFH value Probability of dangerous Failure per Hour Fault reaction...

Page 11: ...value of the SIF Safety Instrumented Function should be smaller than 10 3 hence the maximum allowable PFDavg value would then be 10 4 For a SIL 3 application operating in high demand mode the total PF...

Page 12: ...3 Safety Function and Safe State Safety Function Whenever the input of the device is energized the ETS output is conducting Safe State In the safe state of the safety function the ETS output is close...

Page 13: ...rates of the safety function 2 While the diagnostic function is signaling the dangerous failure of one relay the other two redundant relays continue to provide the safety function Exceptions are commo...

Page 14: ...re rate during the useful lifetime is valid The standard EN ISO 13849 1 2015 proposes a useful lifetime TM of 20 years for devices used within industrial environments This device is designed for this...

Page 15: ...ue of 0 5 0 6 Nm 4 2 Configuration Configuring the Device The device is configured via DIP switches The DIP switches are on the side of the device 1 De energize the device before configuring the devic...

Page 16: ...that are suitable for this safety application 4 Correct any occurring safe failures within 8 hours Take measures to maintain the safety function while the device is being repaired Danger Danger to li...

Page 17: ...tions to achieve the diagnostic coverage see step 2 of the following section Internal Diagnosis Procedure 1 Enable the internal fault detection See chapter 4 2 1 2 You have 2 options to achieve the di...

Page 18: ...intervals depending on the applied PFDavg in accordance with the characteristic safety values See chapter 3 4 The internal fault detection may be used to implement a proof test The diagnostic coverage...

Page 19: ...at least 2 seconds LED OUT is on LED FLT is off 1 5 V 0 V DC between terminals 7 and 8 6 Wait at least 2 seconds LED OUT is off LED FLT is off 1 7 V 24 V DC between terminals 7 and 8 8 Wait at least...

Page 20: ...he standard application the process control system is connected to terminals 7 and 8 The line fault transparency LFT of the safety relay must be compatible with the line fault detection of the process...

Page 21: ...l loop of the dual pole switching If the fault indication output is open the output relay contacts cannot be enabled But as the fault is detected by the process control system a suitable reaction can...

Page 22: ...es not work Take appropriate measures to protect personnel and equipment while the safety function is not available Secure the application against accidental restart 3 Do not repair a defective device...

Page 23: ...fety function Probability of failure of components that are in the safety loop HFT Hardware Fault Tolerance MTBF Mean Time Between Failures MTTR Mean Time To Restoration PCS Process Control System PFD...

Page 24: ...Pepperl Fuchs Quality Download our latest policy here www pepperl fuchs com quality www pepperl fuchs com Pepperl Fuchs Subject to modifications Printed in Germany DOCT 5816C...

Reviews: