Rockwell Automation Publication ICSTT-RM446N-EN-P - April 2018
91
AADvance Functional Safety System Implementation
Chapter 4
Output Module Safety
Functions
Digital Output Module Safety Functions
The digital output module is rated at SIL 3 as a fail-safe module. In dual
redundant configurations it can be used for energize to action and de-energize
to trip SIL 3 applications. Each module provides the following safety
functions:
• output channel signals based on commands from the processor.
• redundant voltage and current measurements to the processor modules
for monitoring and diagnostics.
• over current and over voltage channel protection.
• executing diagnostic tests (on command from the processor module)
and reporting results back to the processor module.
• On power up or module insertion all output channels are set to the de-
energized (fail-safe) state until command states are received from the
processor. Each channel is driven individually according to the
command state values.
• When the module is unlocked, all of its output channels (including any
channels set to hold last state) always go to the de-energized state.
• the module enters a Shutdown Mode when the time between processor
commands exceeds the PST.
• The PFH & PFD
avg
data has been calculated on the basis that the
shutdown state is configured to the OFF state. Therefore the OFF state
shall be used for SIL 2 & SIL 3 applications.
• When a module fails then all the channels are set to the de-energized
state.
Reactions to faults in output modules
When an output module goes faulty the following status information is
reported:
• module presence
• module health and status
• channel health and status
• field faults
• an echo of the front panel indicators for each module
When any of the following internal conditions exist the output module will
fail-safe:
• power feed combiner over temperature detection
• power supply rails out of tolerance
Process safety time faults
For a digital output module, the process safety time represents the period of a
watchdog timer that specifies the length of time the controller will allow the
module to run without receiving updates from the application. If the module
Содержание AADvance T9110
Страница 4: ...4 Rockwell Automation Publication ICSTT RM446N EN P April 2018 ...
Страница 10: ...10 Rockwell Automation Publication ICSTT RM446N EN P April 2018 Preface ...
Страница 44: ...44 Rockwell Automation Publication ICSTT RM446N EN P April 2018 Chapter 2 Functional Safety Management ...
Страница 116: ...116 Rockwell Automation Publication ICSTT RM446N EN P April 2018 Chapter 5 Checklists ...