background image

 2

018-

03

8

Functional Safety KFD2-VR4-Ex1.26

Planning

3

Planning

3.1

System Structure

3.1.1

Low Demand Mode of Operation

If there are two control loops, one for the standard operation and another one for the functional 

safety, then usually the demand rate for the safety loop is assumed to be less than once 

per year.

The relevant safety parameters to be verified are:

the  PFD

avg

 value (average 

P

robability of dangerous 

F

ailure on 

D

emand) and the 

T

1

value (proof test interval that has a direct impact on the PFD

avg

value)

the SFF value (

S

afe 

F

ailure 

F

raction)

the HFT architecture (

H

ardware 

F

ault 

T

olerance)

3.1.2

High Demand or Continuous Mode of Operation

If there is only one safety loop, which combines the standard operation and safety-related 

operation, then usually the demand rate for this safety loop is assumed to be higher than once 

per year.

The relevant safety parameters to be verified are:

the  PFH  value  (

P

robability of dangerous 

F

ailure per 

H

our)

Fault reaction time of the safety system 

the SFF value (

S

afe 

F

ailure 

F

raction)

the HFT architecture (

H

ardware 

F

ault 

T

olerance)

3.1.3

Safe Failure Fraction

The safe failure fraction describes the ratio of all safe failures and dangerous detected failures 

to the total failure rate.

SFF = (

s

 + 

dd

) / (

s

 + 

dd

 + 

du

)

A safe failure fraction as defined in IEC/EN 61508 is only relevant for elements or (sub)systems 

in a complete safety loop. The device under consideration is always part of a safety loop but 

is not regarded as a complete element or subsystem.

For calculating the SIL of a safety loop it is necessary to evaluate the safe failure fraction 

of elements, subsystems and the complete system, but not of a single device.

Nevertheless the SFF of the device is given in this document for reference.

Summary of Contents for KFD2-VR4-Ex1.26

Page 1: ...ISO9001 2 Functional Safety Voltage Repeater KFD2 VR4 Ex1 26 PROCESS AUTOMATION MANUAL...

Page 2: ...livery for Products and Services of the Electrical Industry published by the Central Association of the Electrical Industry Zentralverband Elektrotechnik und Elektroindustrie ZVEI e V in its most rece...

Page 3: ...n 7 2 2 Interfaces 7 2 3 Marking 7 2 4 Standards and Directives for Functional Safety 7 3 Planning 8 3 1 System Structure 8 3 2 Assumptions 9 3 3 Safety Function and Safe State 10 3 4 Characteristic S...

Page 4: ...ting Dismounting Disposal The documentation consists of the following parts Present document Instruction manual Manual Datasheet Additionally the following parts may belong to the documentation if app...

Page 5: ...nd understood the instruction manual and the further documentation Intended Use The device is only approved for appropriate and intended use Ignoring these instructions will void any warranty and abso...

Page 6: ...e displayed in descending order as follows Informative Symbols Action This symbol indicates a paragraph with instructions You are prompted to perform an action or a sequence of actions Danger This sym...

Page 7: ...3 wire sensors 2 2 Interfaces The device has the following interfaces Safety relevant interfaces input output Non safety relevant interfaces power supply 2 3 Marking 2 4 Standards and Directives for F...

Page 8: ...e demand rate for this safety loop is assumed to be higher than once per year The relevant safety parameters to be verified are the PFH value Probability of dangerous Failure per Hour Fault reaction t...

Page 9: ...total PFDavg value of the SIF Safety Instrumented Function should be smaller than 1 x 10 2 hence the maximum allowable PFDavg value would then be 1 5 x 10 3 For a SIL 2 application operating in high...

Page 10: ...lled as long as the output repeats the input voltage 0 V 20 V with a tolerance of 2 Safe State The safe state is defined as the output being de energized Reaction Time The time that is needed to trans...

Page 11: ...mode HFT 0 SIL hardware 2 sd su 1 1 Failures in components that are part of the safety function but do not influence the safety function are regarded as safe undetected 338 FIT dd 0 FIT du 103 FIT tot...

Page 12: ...components that have this constant domain and that the validity of the calculation is limited to the useful lifetime of each component It is assumed that early failures are detected to a huge percenta...

Page 13: ...nstructions in the instruction manual 2 Observe the information in the manual 3 Observe the requirements for the safety loop 4 Connect the device only to devices that are suitable for this safety appl...

Page 14: ...he proof test interval The proof test detects dangerous undetected failures that can affect the safety function of the plant It is under the responsibility of the plant operator to define the type of...

Page 15: ...r the test 10 Restore the safety loop Proof Test Procedure B 1 Prepare the test set up see next figure 2 Connect an input load of 2 1 k to terminals 4 and 5 3 Connect an output load of 10 k to termina...

Page 16: ...VR4 Ex1 26 Operation Figure 5 1 Set up for proof tests A and B Zone 0 1 2 Div 1 2 Zone 2 Div 2 Multimeter V 4 6 2 3 1 5 KFD2 VR4 Ex1 26 7 8 24V DC 11 12 Power Rail 24VDC Input load 2 1 k Output load...

Page 17: ...across the resistor and the current derived from it The current value must be between 4 9 mA and 5 7 mA 4 Disconnect the ancillary equipment 5 Set back the device to the original settings after the te...

Page 18: ...across the resistor and the current derived from it The current value must be between 2 9 mA and 4 3 mA 4 Disconnect the ancillary equipment 5 Set back the device to the original settings after the te...

Page 19: ...aced If the safety loop does not work without the device shut down the application Do not restart the application without taking proper precautions Secure the application against accidental restart 3...

Page 20: ...sed for calculation of SFF not part Probability of failure of components that are not in the safety loop total safety function Probability of failure of components that are in the safety loop HFT Hard...

Page 21: ...Functional Safety KFD2 VR4 Ex1 26 Notes 2018 03 21...

Page 22: ...rl fuchs com Worldwide Headquarters Pepperl Fuchs GmbH 68307 Mannheim Germany Tel 49 621 776 0 E mail info de pepperl fuchs com For the Pepperl Fuchs representative closest to you check www pepperl fu...

Reviews: