
Functional Safety
- 84 -
Safety
function
Norm
reference
Required SIL
due to
EN81 (or
due to risk
analysis,
refer to
comments)
Achieved
SIL due
to PFHD
and SFF
PFHD
[FIT]
(acc. to
FMEDA)
Percentage
of required
SIL
Comments
ing system, the better values are valid
(eSGC would secure a failure of OC
in this case).
Door
bridging
EN81-20 §5.12.1.4
SIL2
SIL3
56 FIT
5.6 %
UCM
EN81-20 §5.6.7.7
SIL2
SIL3
76 FIT
7.6 %
Working
Platform
EN81-20
§5.2.6.4.3.1 b.)
SIL3
SIL3
27 FIT
27 %
Table 27: Safe failure fraction, HFT and Type of the subsystems
Subsystem
HFT Ty
pe Required SFF for SIL3 Achieved SFF Comments
Logic (µ-controller in the broad sense)
1
B 90 %
99.4 %
Required SFF for SIL3 achieved
Digital Inputs
1
A 60 %
99.9 %
Required SFF for SIL3 achieved
Diagnostics for digital inputs
0
A 90 %
99.6 %
Required SFF for SIL3 achieved
Position
1
A 60 %
99.9 %
Required SFF for SIL3 achieved
OC
1
A 60 %
75.8 %
Required SFF for SIL3 achieved
eSGC
1
A 60 %
98.5 %
Required SFF for SIL3 achieved
SR1 and SR2
1
A 60 %
75.8 %
Required SFF for SIL3 achieved
3.3 V and 2 V supply voltage
1
A 60 %
99.5 %
Required SFF for SIL3 achieved
12V Relay supply voltage
0
A 90 %
99.0 %
Required SFF for SIL3 achieved
EMC of main supply
0
A 90 %
97.3 %
Required SFF for SIL3 achieved
EMC of battery Supply
0
A 90 %
97.3 %
Required SFF for SIL3 achieved
Voltage supervision (diagnostics)
0
A 90 %
99,5 %
Required SFF for SIL3 achieved
External watchdog (diagnostics)
0
A 90 %
96.9 %
Required SFF for SIL3 achieved
CAN
0
B 90 %
99,1 %
Required SFF for SIL3 achieved
Floor Sensors
0
A 90 %
99.7 %
Required SFF for SIL3 achieved
Door Zone Output
0
A 90 %
99.0 %
Required SFF for SIL3 achieved
Others
1
A 60 %
97.7 %
Required SFF for SIL3 achieved
µ-controller-PINs
1
B 90 %
92.8 %
Required SFF for SIL3 achieved
Table 28: Diagnostics Test Interval (DTI) of the subsystems
Subsystem
Diagnostic Measurement
DTI
Comments
Position
Comparison of the two channels
10 ms
Analogue value range
10 ms
Plausibility of pattern of the analog
values
10 ms
Plausibility of succession of positions
10 ms
Dynamic check of analogue branch
90 ms
Logic (processing)
RAM Test
41 h : 56 min : 35 s
Also 1 x complete at
startup before relays close
ROM Test
17 min : 29 s
Also 1 x complete at
startup before relays close
Self-test of CPU
10 ms
Comparison with other channel
10 ms
Program flow
10 ms
Check of timing
10 ms
(hardware) watchdog
15 ms
Содержание LIMAX33 CP-00 SERIES
Страница 91: ...91 Notes...