Pepperl+Fuchs SIL KFD0-RSH-1 Safety Manual Download Page 6

 2

014-07

6

Safety Manual SIL KFD0-RSH-1(-Y2), KFD2-SL-4

Planning

2

Planning

2.1

System Structure

2.1.1

Low Demand Mode of Operation
If there are two loops, one for the standard operation and another one for the 

functional safety, then usually the demand rate for the safety loop is assumed to 

be less than once per year.

The relevant safety parameters to be verified are:

the PFD

avg

 value (average 

P

robability of 

F

ailure on 

D

emand) and the T

proof

 

value (proof test interval that has a direct impact on the PFD

avg

)

the SFF value (

S

afe 

F

ailure 

F

raction)

the HFT architecture (

H

ardware 

F

ault 

T

olerance)

2.1.2

High Demand or Continuous Mode of Operation
If there is only one loop, which combines the standard operation and safety 

related operation, then usually the demand rate for this loop is assumed to be 

higher than once per year.

The relevant safety parameters to be verified are:

the PFH value (

P

robability of dangerous 

F

ailure per 

H

our)

Fault reaction time of the safety system 

the SFF value (

S

afe 

F

ailure 

F

raction)

the HFT architecture (

H

ardware 

F

ault 

T

olerance architecture)

2.1.3

Safe Failure Fraction
The safe failure fraction describes the ratio of all safe failures and dangerous 

detected failures to the total failure rate.

SFF = (

s

 + 

dd

) / (

s

 + 

dd

 + 

du

)

A safe failure fraction as defined in EN 61508 is only relevant for elements or 

(sub)systems in a complete safety loop. The device under consideration is 

always part of a safety loop but is not regarded as a complete element or 

subsystem.

For calculating the SIL of a safety loop it is necessary to evaluate the safe failure 

fraction of elements, subsystems and the complete system, but not of a single 

device.

Nevertheless the SFF of the device is given in this document for reference.

Safety Manual SIL KFD0-RSH-1(-Y2), KFD2-SL-4

Summary of Contents for SIL KFD0-RSH-1

Page 1: ...ISO9001 2 3 Relay Module KFD0 RSH 1 Y2 KFD2 SL 4 PROCESS AUTOMATION SAFETY MANUAL SIL...

Page 2: ...ry for Products and Services of the Electrical Industry published by the Central Association of the Electrical Industry Zentralverband Elektrotechnik und Elektroindustrie ZVEI e V in its most recent v...

Page 3: ...and Directives 5 2 Planning 6 2 1 System Structure 6 2 2 Assumptions 7 2 3 Safety Function and Safe State 8 2 4 Characteristic Safety Values 9 3 Safety Recommendation 12 3 1 Interfaces 12 3 2 Configu...

Page 4: ...safety functions can damage property and the environment or cause personal injury for which Pepperl Fuchs GmbH accepts no liability The devices have been developed manufactured and tested according to...

Page 5: ...uit proofed and overload proofed Line fault detection can be enabled via DIP switch Fault LED and collective error output via Power Rail behave as described within the data sheet of the device 1 3 Man...

Page 6: ...assumed to be higher than once per year The relevant safety parameters to be verified are the PFH value Probability of dangerous Failure per Hour Fault reaction time of the safety system the SFF value...

Page 7: ...value would then be 10 8 per hour Failure rate based on the Siemens SN29500 data base Failure rates are constant wear out mechanisms are not included External power supply failure rates are not includ...

Page 8: ...relay outputs need protection by a fuse initiating at 80 of the rated current to avoid contact welding 2 3 Safety Function and Safe State Safety Function KFD0 RSH 1 Y2 Whenever the input of the device...

Page 9: ...function Output relay in OFF state when input is de energized s 251 6 FIT dd 0 FIT du 0 4 FIT no effect 69 6 FIT total safety function 252 FIT SFF 99 8 MTBF 1 452 years PFH 4 00 x 10 10 1 h PFDavg fo...

Page 10: ...y in OFF state when input is de energized s 255 FIT dd 0 FIT du 4 4 FIT no effect 72 8 FIT total safety function 259 FIT not part 0 FIT SFF 98 3 MTBF 1 440 years PFH 4 38 x 10 9 1 h PFDavg for Tproof...

Page 11: ...FMEDA report Device type A Demand mode Low Demand Mode or High Demand Mode Safety function Outputs de energized when common disable input is de energized HFT 0 SIL 2 sd su 324 FIT dd 0 FIT du 1 0 FIT...

Page 12: ...highly dependent on the component itself and its operating conditions temperature in particular for example the electrolytic capacitors can be very sensitive to the working temperature This assumption...

Page 13: ...limited by the maximum switching cycles under load conditions You can see the relationship between the maximum switching power and the load conditions in the diagram below Figure 3 1 This is valid for...

Page 14: ...to define the type of proof test and the interval time period The ancillary equipment required KFD0 RSH 1 Y2 A digital multimeter without special accuracy will be used as ohmmeter mid range recommend...

Page 15: ...following tables and pictures Test each separate channel that is used in the safety function application and the respective safety path KFD0 RSH 1 Y2 Figure 4 1 Proof test set up for KFD0 RSH 1 The s...

Page 16: ...een terminals 11 12 load resistor on output Multimeter shows 24 V DC 2 Attach the input voltage subsequently to each input and check that no output is switching For this test the line fault detection...

Page 17: ...o effect on the safety function not part Probability of failure of components that are not in the safety path total safety function Safety function HFT Hardware Fault Tolerance MTBF Mean Time Between...

Page 18: ...2014 07 18 Safety Manual SIL KFD0 RSH 1 Y2 KFD2 SL 4 Notes Safety Manual SIL KFD0 RSH 1 Y2 KFD2 SL 4...

Page 19: ...Safety Manual SIL KFD0 RSH 1 Y2 KFD2 SL 4 Notes 2014 07 19...

Page 20: ...rl fuchs com PROCESS AUTOMATION PROTECTING YOUR PROCESS Worldwide Headquarters Pepperl Fuchs GmbH 68307 Mannheim Germany Tel 49 621 776 0 E mail info de pepperl fuchs com For the Pepperl Fuchs represe...

Reviews: