background image

 2

018-

03

14

Functional Safety KFD2-VR4-Ex1.26

Operation

5

Operation

Operating the device

1. Observe the safety instructions in the instruction manual.
2. Observe the information in the manual.
3. Use the device only with devices that are suitable for this safety application.
4. Correct any occurring safe failures within 8 hours. Take measures to maintain the safety 

function while the device is being repaired.

5.1

Proof Test

According to IEC/EN 61508-2 a recurring proof test shall be undertaken to reveal potential 

dangerous failures that are not detected otherwise.

Check the function of the subsystem at periodic intervals depending on the applied 

PFD

avg

in accordance with the characteristic safety values. See chapter 3.4.

It is possible that the device is used under other circumstances than specified within 

the assumptions for the FMEDA assessment. The calculations for the safety loop can also 

reveal that the device can claim a different amount of the PFD value (standard is 15 %). 

Both effects can have an influence on the proof test interval.

The proof test detects dangerous undetected failures that can affect the safety function 

of the plant.

It is under the responsibility of the plant operator to define the type of proof test and the proof 

test interval. Do not exceed the proof test interval of a maximum of 3 years.

The following sections describe the steps of the proof test. The proof test reveals almost 

all possible dangerous faults (diagnostic coverage > 90 %).

The ancillary equipment required:

Digital multimeter with an accuracy better than 0.1 %

For the proof test of the intrinsic safety side of the devices, a special digital multimeter 

for intrinsically safe circuits must be used.

Intrinsically safe circuits that were operated with non-intrinsically safe circuits may not 

be used as intrinsically safe circuits afterwards.

Power supply set at nominal voltage of 24 V DC.

Apparatus suitable for generating the signals for test B.

Load  of  2.1 k

 and 1.8 k

 for the input, 10 k

 for the output.

Danger!

Danger to life from missing safety function

If the safety loop is put out of service, the safety function is no longer guaranteed.

Do not deactivate the device.

Do not bypass the safety function.

Do not repair, modify, or manipulate the device.

Summary of Contents for KFD2-VR4-Ex1.26

Page 1: ...ISO9001 2 Functional Safety Voltage Repeater KFD2 VR4 Ex1 26 PROCESS AUTOMATION MANUAL...

Page 2: ...livery for Products and Services of the Electrical Industry published by the Central Association of the Electrical Industry Zentralverband Elektrotechnik und Elektroindustrie ZVEI e V in its most rece...

Page 3: ...n 7 2 2 Interfaces 7 2 3 Marking 7 2 4 Standards and Directives for Functional Safety 7 3 Planning 8 3 1 System Structure 8 3 2 Assumptions 9 3 3 Safety Function and Safe State 10 3 4 Characteristic S...

Page 4: ...ting Dismounting Disposal The documentation consists of the following parts Present document Instruction manual Manual Datasheet Additionally the following parts may belong to the documentation if app...

Page 5: ...nd understood the instruction manual and the further documentation Intended Use The device is only approved for appropriate and intended use Ignoring these instructions will void any warranty and abso...

Page 6: ...e displayed in descending order as follows Informative Symbols Action This symbol indicates a paragraph with instructions You are prompted to perform an action or a sequence of actions Danger This sym...

Page 7: ...3 wire sensors 2 2 Interfaces The device has the following interfaces Safety relevant interfaces input output Non safety relevant interfaces power supply 2 3 Marking 2 4 Standards and Directives for F...

Page 8: ...e demand rate for this safety loop is assumed to be higher than once per year The relevant safety parameters to be verified are the PFH value Probability of dangerous Failure per Hour Fault reaction t...

Page 9: ...total PFDavg value of the SIF Safety Instrumented Function should be smaller than 1 x 10 2 hence the maximum allowable PFDavg value would then be 1 5 x 10 3 For a SIL 2 application operating in high...

Page 10: ...lled as long as the output repeats the input voltage 0 V 20 V with a tolerance of 2 Safe State The safe state is defined as the output being de energized Reaction Time The time that is needed to trans...

Page 11: ...mode HFT 0 SIL hardware 2 sd su 1 1 Failures in components that are part of the safety function but do not influence the safety function are regarded as safe undetected 338 FIT dd 0 FIT du 103 FIT tot...

Page 12: ...components that have this constant domain and that the validity of the calculation is limited to the useful lifetime of each component It is assumed that early failures are detected to a huge percenta...

Page 13: ...nstructions in the instruction manual 2 Observe the information in the manual 3 Observe the requirements for the safety loop 4 Connect the device only to devices that are suitable for this safety appl...

Page 14: ...he proof test interval The proof test detects dangerous undetected failures that can affect the safety function of the plant It is under the responsibility of the plant operator to define the type of...

Page 15: ...r the test 10 Restore the safety loop Proof Test Procedure B 1 Prepare the test set up see next figure 2 Connect an input load of 2 1 k to terminals 4 and 5 3 Connect an output load of 10 k to termina...

Page 16: ...VR4 Ex1 26 Operation Figure 5 1 Set up for proof tests A and B Zone 0 1 2 Div 1 2 Zone 2 Div 2 Multimeter V 4 6 2 3 1 5 KFD2 VR4 Ex1 26 7 8 24V DC 11 12 Power Rail 24VDC Input load 2 1 k Output load...

Page 17: ...across the resistor and the current derived from it The current value must be between 4 9 mA and 5 7 mA 4 Disconnect the ancillary equipment 5 Set back the device to the original settings after the te...

Page 18: ...across the resistor and the current derived from it The current value must be between 2 9 mA and 4 3 mA 4 Disconnect the ancillary equipment 5 Set back the device to the original settings after the te...

Page 19: ...aced If the safety loop does not work without the device shut down the application Do not restart the application without taking proper precautions Secure the application against accidental restart 3...

Page 20: ...sed for calculation of SFF not part Probability of failure of components that are not in the safety loop total safety function Probability of failure of components that are in the safety loop HFT Hard...

Page 21: ...Functional Safety KFD2 VR4 Ex1 26 Notes 2018 03 21...

Page 22: ...rl fuchs com Worldwide Headquarters Pepperl Fuchs GmbH 68307 Mannheim Germany Tel 49 621 776 0 E mail info de pepperl fuchs com For the Pepperl Fuchs representative closest to you check www pepperl fu...

Reviews: