background image

 

D1130 

- SIL 2 Switch / Proximity Detector Repeater Relay Output 

G.M. International ISM0048-12 

Functional Safety Manual and Application 

Application for D1130S

 

Safety Function and Failure behavior:

  

D1130S is considered to be operating in Low Demand mode, as a Type B module, having Hardware Fault Tolerance (HFT) = 0. 
The failure behavior is described from the following definitions : 
 

 Fail-Safe State: it is defined as the output being de-energized (so that the output relay is de-energized). 

 

 Fail Safe: failure mode that causes the module / (sub)system to go to the defined fail-safe state without a demand from the process. 

 

 Fail Dangerous: failure mode that does not respond to a demand from the process (i.e. being unable to go to the defined fail-safe state), so that the output remains energized. 

 

 Fail “No Effect”: failure mode of a component that plays a part in implementing the safety function but is neither a safe failure nor a dangerous failure.  

     When calculating the SFF, this failure mode is not taken into account; 
 

 Fail “Not Part”: failure mode of a component which is not part of the safety function but which is part of the circuit diagram and is listed for completeness.  

     When calculating the SFF, this failure mode is not taken into account. 
As the module is supposed to be proven-in-use device, therefore according to the requirements of IEC 61511-1 section 11.4.4, a HFT = 0 is sufficient for SIL 2 (sub-) systems including 
Type B components and having a SFF equal or more than 60%. 
Only Out 1-A is functional safety related, while Out 1-B (Pins 6-5 or 7-5) as Out 1-A Duplicator output is only for service purpose, not functional safety related. 
Failure rate date: taken from Siemens Standard SN29500. 

Description:

  

For this application, enable input line fault (open or short) detection and direct input to output transfer function, by set the internal dip-switches in the following mode (see page 12 
for more information): 

ON operation 

  The module is powered by connecting 115-230 Vac power supply to Pins 3 (+ positive) - 4 (- negative). The green LED is lit in presence of supply power. 

Input signal from field is applied to Pins 13-14 (In 1 - Ch.1). 
Only Out 1-A is functional safety related, while Out 1-B (Pins 6-5 or 7-5) as Out 1-A Duplicator output is only for service purpose, not functional safety related. 
The following table describes for Channel 1 the state (open or closed) of its output when its input signal is in OFF or ON state, and it gives information about turn-on or turn-off 
of its channel status LED and channel fault LED: 

Dip-switch position 

1 2 3 4 

ON/OFF state 

ON ON OFF  - 

Failure category

 

Failure rates (FIT)

 

λ

dd

 = Total Dangerous Detected failures 

0.00 

λ

du

 = Total Dangerous Undetected failures 

82.13 

λ

sd

 = Total Safe Detected failures 

0.00 

λ

su

 = Total Safe Undetected failures 

203.81 

λ

tot safe

 = Total Failure Rate (Safety Function) = 

λ

dd

 + 

λ

du

 + 

λ

sd

 + 

λ

su

 285.94

 

MTBF (safety function, channel 1) = (1 / 

λ

tot safe

) + MTTR (8 hours) 

399 years

 

λ

no effect

 = “No Effect” failures 

107.03 

λ

not part

 = “Not Part” failures 

105.30 

λ

tot device

 = Total Failure Rate (Device) = 

λ

tot safe

 + 

λ

no effect

 + 

λ

not part

  

498.27

 

MTBF (device, channel 1) = (1 / 

λ

tot device

) + MTTR (8 hours) 

229 years

 

λ

sd

 

λ

su

 

λ

dd

 

λ

du

 

SFF

 

0.00 FIT 

203.81 FIT 

0.00 FIT 

82.13 FIT 

71.28% 

PFDavg vs T[Proof] table 

(assuming Proof Test coverage of 99%), with determination of SIL supposing module contributes >10% of total SIF dangerous failures: 

PFDavg vs T[Proof] table 

(assuming Proof Test coverage of 99%), with determination of SIL supposing module contributes 

10% of total SIF dangerous failures: 

Failure rates table according to IEC 61508:2010 Ed.2 : 

Failure rate table:

 

T[Proof] = 1 year

 

T[Proof] = 2 years

 

PFDavg = 3.60 E-04 Valid for 

SIL 2

  PFDavg = 7.21 E-04 Valid for 

SIL 2

 

D1130S 

 

Field Input: proximity is OFF 

or switch is open 

Out 1-B is Out 1-A Duplicator 
output 

Channel 1 

 

Out 1-A 

Safety 

PLC 

Input 

13 

14 

 

 

In 1 

 

Out 1-A relay is de-energized, 
2-1 is open, 8-1 is closed 

 

Out 1-B 

PLC 

Input 

OFF operation 

D1130S 

 

Field Input: proximity is ON 

or switch is closed 

Out 1-B is Out 1-A Duplicator 
output 

Channel 1 

 

Out 1-A 

Safety 

PLC 

Input 

13 

14 

 

 

In 1 

 

Out 1-A relay is energized, 
2-1 is closed, 8-1 is open 

 

Out 1-B 

PLC 

Input 

Input signal state 

Pins 13-14 (In 1 - Ch.1)  

Output relay contact state 

Pins 2-1 (Out 1-A - Ch.1)  

Proximity sensor is OFF or switch is open 

Open (De-energize relay) 

Proximity sensor is ON or switch is closed 

Closed (Energized relay) 

Independently from proximity sensor  

or switch state, the input line is break 

Open  

(De-energized relay as safe state condition) 

Independently from proximity sensor  

or switch state, the input line is in short circuit 

Open  

(De-energized relay as safe state condition) 

Channel status 
yellow LED state 

OFF 

ON 

OFF 

OFF 

Channel fault 

red LED state 

OFF 
OFF 

ON 

ON 

Output relay contact state 

Pins 8-1 (Out 1-A - Ch.1)  

Closed (De-energized relay) 

Open (Energize relay) 

Closed 

(De-energized relay as safe state condition) 

Closed  

(De-energized relay as safe state condition) 

This type “B” system has SFF = 71.28 % 

 60 % and HFT = 0, which is sufficient to get SIL 2 in accordance with the requirements of IEC 61511-1 section 11.4.4 during a proven-in-use 

assessment. 

T[Proof] = 10 years

 

PFDavg = 3.60 E-03 Valid for 

SIL 2

 

 

Supply  

 115-230 Vac 

3 (L) 

4 (N) 

 

Supply  

 115-230 Vac 

3 (L) 

4 (N) 

Содержание D1130D

Страница 1: ...D1130 SIL 2 Switch Proximity Detector Repeater Relay Output ISM0048 12 D1130S D1130D INSTRUCTION SAFETY MANUAL SIL 2 Switch Proximity Detector Repeater Relay Output DIN Rail Models D1130S D1130D ...

Страница 2: ...ut 2 5 KV Input switching current levels ON 2 1 mA OFF 1 2 mA switch current 1 65 mA 0 2 mA hysteresis Fault current levels open fault 0 2 mA short fault 6 8 mA when enabled both faults de energize channel relay with dual channel unit D1130D or actuate fault relay with single channel unit D1130S Input equivalent source 8 V 1 KΩ typical 8 V no load 8 mA short circuit Output voltage free SPDT relay ...

Страница 3: ...t Signals SPDT Relay Output for fault detection on single channel version Three port isolation Input Output Supply EMC Compatibility to EN61000 6 2 EN61000 6 4 In field programmability by DIP Switch ATEX IECEx UL C UL FM FM C INMETRO EAC EX UKR TR n 898 TÜV Certifications Type Approval Certificate DNV and KR for maritime applications High Reliability SMD components High Density two channels per un...

Страница 4: ...lay Normally Opened NO 2 L Power Supply 115 230 Vac 3 N Power Supply 115 230 Vac 4 Output Ch 2 Common 5 Output Ch 2 Relay Normally Opened NO 6 Output Ch 2 Relay Normally Closed NC 7 Output Ch 1 Relay Normally Closed NC 8 D1130S Input Ch 1 for Proximity or Input Ch 1 for Voltage free Contact HAZARDOUS AREA SAFE AREA Input Ch 1 for Proximity or Input Ch 1 for Voltage free Contact 13 14 Output Ch 1 A...

Страница 5: ...le Li Li device L cable Li Ri device and L cable R cable IIC Co Ca 2 23 µF Co Ca 15 6 µF Co Ca 69 µF IIB IIC Lo La 172 mH Lo La 689 mH Lo La 1300 mH IIB IIA IIC Lo Ro 930 µH Ω Lo Ro 3720 µH Ω Lo Ro 7440 µH Ω IIB IIA NOTE for USA and Canada IIC equal to Gas Groups A B C D E F and G IIB equal to Gas Groups C D E F and G IIA equal to Gas Groups D E F and G For installations in which both the Ci and L...

Страница 6: ...A ZONE 2 GROUP IIC T4 NON HAZARDOUS LOCATIONS CLASS I DIVISION 2 GROUPS A B C D T Code T4 CLASS I ZONE 2 GROUP IIC T4 MODEL D1130D 13 14 3 L 4 N 8 NC 2 NO 1 COM Supply 115 230 Vac Out 1 In 1 15 16 7 NC 6 NO 5 COM In 2 Out 2 voltage free Contact Proximity Proximity Common positive connection _ voltage free Contact MODEL D1130S 13 14 8 NC 2 NO 1 COM Out 1 A In 1 7 NC 6 NO 5 COM Out 1 B voltage free ...

Страница 7: ... SIL of a certain Safety Function as they are not completely independent one from another Failure rate date taken from Siemens Standard SN29500 Input signal state Pins 13 14 In 1 Ch 1 or 15 16 In 2 Ch 2 Output relay contact state Pins 2 1 Out 1 Ch 1 or 6 5 Out 2 Ch 2 Proximity sensor is OFF or switch is open Open De energize relay Proximity sensor is ON or switch is closed Closed Energized relay I...

Страница 8: ...and channel fault LED Dip switch position 1 2 3 4 ON OFF state ON ON OFF Failure category Failure rates FIT λdd Total Dangerous Detected failures 0 00 λdu Total Dangerous Undetected failures 82 13 λsd Total Safe Detected failures 0 00 λsu Total Safe Undetected failures 203 81 λtot safe Total Failure Rate Safety Function λdd λdu λsd λsu 285 94 MTBF safety function channel 1 1 λtot safe MTTR 8 hours...

Страница 9: ...ized modification must be avoided Warning D1130 Associated Apparatus FM Approved under Entity Concept and non incendive field wiring Unclassified Locations or Hazardous Classified Locations Class I Division 2 Groups A B C D T Code T4 Class I Zone 2 Group IIC IIB IIA T Code T4 FM Approved under Entity Concept or third party approval Hazardous Classified Locations Class I Division 1 Groups A B C D C...

Страница 10: ...50 V 500 VA 80 W resistive load The enclosure provides according to EN60529 an IP20 minimum degree of mechanical protection or similar to NEMA Standard 250 type 1 for indoor installation outdoor installation requires an additional enclosure with higher degree of protection i e IP54 to IP65 or NEMA type 12 13 consistent with the effective operating environment of the specific installation Units mus...

Страница 11: ... 3 Disabled contact proximity sensor Enabled proximity sensor or contact with terminating line resistor ON 13 2 OFF NO 14 1 2 8 NE OR NC 13 14 1 2 8 ND 13 NO 14 1 2 8 NE OR NC 13 14 1 2 8 ND Side A Panel View Input Output Input Output Output Input Output Input CH2 Setting Line fault detection ON IN OUT Operation NO NE or NC ND NO ND or NC NE ON OFF Disabled contact proximity sensor Enabled proximi...

Страница 12: ...ND NE No Fault D1130D Configuration Summary Table Channel IN OUT Operation NO NE or NC ND NO ND or NC NE For SIL applications SW2 OFF SW4 OFF ON 1 2 Channel Line fault detection Disabled contact proximity sensor Enabled For SIL applications proximity sensor or contact with terminating line resistor detects field open circuit and short circuit de energizing output SW1 SW3 1 2 ON OFF OFF ON ON IN OU...

Отзывы: