background image

 

D5290S-079 

- 5 A SIL 3 Relay Output Module 

G.M. International ISM0153-2 

Functional Safety Manual and Applications 

 

 

D5290S-079 

- 5 A SIL 3 Relay Output Module (115 Vac coil voltage) 

G.M. International ISM0153-2 

Functional Safety Manual and Applications 

 

22 

21 

20 

23 

24-19 

18-13 

17 

14 

Application D5290S-079 - SIL 3 Load Normally Energized Condition (NE) and Normally Energized Relay: 

one common driving signal from PLC for both NE loads (A and B), with interruption of both load supply lines  

NE 

Load 

SIL 3 

PLC 

Output ON 

115 Vac 

Normal state operation 

De-energized to trip operation 

Service 
Load B 
(Not SIL) 

NE 
Load 
SIL 3 

16 

15 

Service 
Load A 
(Not SIL) 

22 

21 

20 

23 

24-19 

18-13 

17 

14 

NE 

Load 

SIL 3 

PLC 

Output OFF 

0 Vac 

Service 
Load B 
(Not SIL) 

NE 
Load 
SIL 3 

16 

15 

Service 

Load A 

(Not SIL) 

- / AC (for load A and its service load) 

+ / AC (for load A and its service load) 

+ / AC (for load B and its service load) 

- / AC (for load B and its service load) 

+ / AC (for load A and its service load) 

+ / AC (for load B and its service load) 

- / AC (for load A and its service load) 

- / AC (for load B and its service load) 

1) 

Description:

  

Input Signal from PLC/DCS is normally High (115 Vac) and is applied to pins 1-2 or 3-4 in order to Normally Energize (NE) the internal relays. 
Input Signal from PLC/DCS is Low (0 Vac) during “de-energize to trip” operation, in order de-energize the internal relays. 
Load A (and Load B if present) is Normally Energized (NE) therefore its safe state is to be de-energized. 
Disconnection of Loads A and B is done on both supply lines. 
Service Load A (and Service Load B if present) is normally de-energized, therefore it energizes during “de-energize to trip” operation. 
The following table describes the status (open or closed) of each output contact when input signal is High or Low. 

Safety Function and Failure behavior:

  

D5290S-079 is considered to be operating in Low Demand mode, as a Type A module, having Hardware Fault Tolerance (HFT) = 0. 
In the 1st Functional Safety application, the normal state operation of relay module is energized, with NE (Normally Energized) loads.  
In case of alarm or request from process, the relay module is de-energized (safe state), de-energizing loads.  
The failure behaviour of relay module is described by the following definitions: 
 

 fail-Safe State: it is defined as the output load being de-energized; 

 

 fail Safe: this failure causes the system to go to the defined fail-safe state without a process demand; 

 

 fail Dangerous: failure mode that does not respond to a demand from the process (i.e. being unable to go to the defined fail-safe state), so that the output load remains energized. 

In addition, there are other definitions of failure behaviours which are not safety-related: 
 

 fail “No effect”: failure mode of a component that plays a part in implementing the safety function but is neither a safe failure nor a dangerous failure; 

 

 fail “Not part”: failure mode of a component which is not part of the safety function but part of the circuit diagram and is listed for completeness. When calculating the SFF this 

      failure mode is not taken into account. It is also not considered for the total failure rate evaluation. 

T[Proof] = 20 years

 

PFDavg = 1.40 E-04 Valid for 

SIL 3

 

Failure rate table:

 

Failure category

 

Failure rates (FIT)

 

λ

dd

 = Total Dangerous Detected failures 

0.00 

λ

du

 = Total Dangerous Undetected failures 

1.60 

λ

sd

 = Total Safe Detected failures 

0.00 

λ

su

 = Total Safe Undetected failures 

158.88 

λ

tot safe

 = Total Failure Rate (Safety Function) = 

λ

dd

 + 

λ

du

 + 

λ

sd

 + 

λ

su

 160.48

 

λ

no effect

 = “No effect” failures 

11.92 

λ

not part

 = “Not Part” failures 

0.00 

λ

tot device

 = Total Failure Rate (Device) = 

λ

tot safe

 + 

λ

no effect

 + 

λ

not part

  

172.40

 

MTBF (device, single channel) = (1 / 

λ

tot device

) + MTTR (8 hours) 

662 years

 

MTTF

S

 (Total Safe) = 1 / (

λ

sd

 + 

λ

su

718 years 

MTTF

D

 (Dangerous) = 1 / 

λ

du

 

71347 years 

MTBF (safety function, single channel) = (1 / 

λ

tot safe

) + MTTR (8 hours) 

711 years 

Input Signal  

Pins 1-2 or 3-4 

Pins  

13-14 

Pins  

15-16 

NE Load A (SIL3) 

Pins 14-16 

NE Load B (SIL 3) 

Pins 23-21 

Service 

Load A 

High (115 Vac)  Closed  Closed 

Energized Energized De-Energized 

Low (0 Vac) 

Open 

Open 

De-Energized De-Energized 

Energized 

Service  

Load B 

De-Energized 

Energized 

Pins  

23-24 

Closed 

Open 

Pins  

21-22 

Closed 

Open 

Operation 

Normal  

Trip 

Pins  

17-18 

Open 

Closed 

Pins  

19-20 

Open 

Closed 

 

 

 

Failure rates table according to IEC 61508: 

λ

sd

 

λ

su

 

λ

dd

 

λ

du

 

SFF

 

0.00 FIT 

158.88 FIT 

0.00 FIT 

1.60 FIT 

99.00% 

PFDavg vs T[Proof] table

, with determination of SIL supposing module contributes 10% of entire safety function: 

T[Proof] = 1 year

 

T[Proof] = 10 years

 

PFDavg = 7.01 E-06 Valid for 

SIL 3

 

PFDavg = 7.01 E-05 Valid for 

SIL 3

 

T[Proof] = 20 years

 

PFDavg = 1.40 E-04 Valid for 

SIL 2

 

PFDavg vs T[Proof] table

, with determination of SIL supposing module contributes 20% of entire safety function: 

T[Proof] = 20 years

 

PFDavg = 1.40 E-04 Valid for 

SIL 3

 

Содержание D5290S-079

Страница 1: ... 3 Relay Output Module 115 Vac coil voltage G M International ISM0153 2 5 A SIL 3 Relay Output Module for NE or ND Loads with NE Relay condition DIN Rail Model D5290S 079 D5290S 079 INSTRUCTION MANUAL INSTRUCTION MANUAL ...

Страница 2: ... Mechanical Electrical life 10 106 5 104 operation typical Bounce time NO NC contact 4 10 ms typical Frequency response 10 Hz maximum Compatibility CE mark compliant conforms to 94 9 EC Atex Directive and to 2004 108 CE EMC Directive Environmental conditions Operating temperature limits 40 to 60 C relative humidity 95 up to 55 C Storage temperature limits 45 to 80 C Approvals TÜV Certificate No C ...

Страница 3: ...n 3 5 A SIL 3 SIL 2 contacts for NE or ND loads with NE Relay condition Input Output isolation EMC Compatibility to EN61000 6 2 EN61000 6 4 EN61326 1 EN61326 3 1 for safety system TÜV Certification Simplified installation using standard DIN Rail and plug in terminal blocks Model D5290S 079 DIN Rail accessories Cover and fix MCHP196 Normally Open NO contact Out S_1 Terminal block connections SAFE A...

Страница 4: ...ding to the relay breaking capacity diagram Relay contacts shown in de energized position Terminals 13 14 15 16 21 22 and 23 24 are open Terminals 17 18 and 19 20 are closed See the following pages for Functional Safety applications with related SIL value MODEL D5290S 079 1 2 3 4 22 21 19 20 23 24 Out S_1 NO contact 13 14 Out P_1 NC contact 17 18 16 15 Out S_2 NO contact Out S_4 NO contact Out P_2...

Страница 5: ...e output load being de energized fail Safe this failure causes the system to go to the defined fail safe state without a process demand fail Dangerous failure mode that does not respond to a demand from the process i e being unable to go to the defined fail safe state so that the output load remains energized In addition there are other definitions of failure behaviours which are not safety relate...

Страница 6: ...operating in Low Demand mode as a Type A module having Hardware Fault Tolerance HFT 0 In the 2nd Functional Safety application the normal state operation of relay module is energized with NE Normally Energized loads In case of alarm or request from process the relay module is de energized safe state de energizing loads The failure behaviour of relay module is described by the following definitions...

Страница 7: ...ailure behavior D5290S 079 is considered to be operating in Low Demand mode as a Type A module having Hardware Fault Tolerance HFT 0 In the 3rd Functional Safety application the normal state operation of relay module is energized with NE Normally Energized loads In case of alarm or request from process the relay module is de energized safe state de energizing loads The failure behaviour of relay m...

Страница 8: ...g Hardware Fault Tolerance HFT 0 In the 4th Functional Safety application the normal state operation of relay module is energized with ND Normally De energized loads In case of alarm or request from process the relay module is de energized safe state energizing loads The failure behaviour of all relay modules here considered is described by the following definitions fail Safe State it is defined a...

Страница 9: ...gize main power source turn off power supply voltage and disconnect plug in terminal blocks before opening the enclosure to avoid electrical shock when connected to live hazardous potential Start up Before powering the inputs of unit check that all wires are properly connected Check conductors for exposed wires that could touch each other causing dangerous unwanted shorts Enabling input the RELAY ...

Отзывы: