background image

Functional Safety KFD2-RSH-1.2E.L*(-Y1)

Planning

 2

01

9-

12

11

3.2

Assumptions

The following assumptions have been made during the FMEDA:

Failure rates are constant, wear is not considered.

Failure rate based on the Siemens standard SN 29500.

The safety-related device is considered to be of type 

A

 device with a hardware 

fault tolerance of 

0

.

The device will be used under average industrial ambient conditions comparable 

to the classification "stationary mounted" according to MIL-HDBK-217F.

Alternatively, operating stress conditions typical of an industrial field environment similar 

to IEC/EN 60654-1 Class C with an average temperature over a long period of time 

of 40

º

C may be assumed. For a higher average temperature of 60

º

C, the failure rates 

must be multiplied by a factor of 2.5 based on experience. A similar factor must be used 

if frequent temperature fluctuations are expected.

The nominal voltage at the digital input is 24 V. Ensure that the nominal voltage 

does not exceed 26.4 V under all operating conditions.

To achieve the safe state even in the case of an internal device fault, the DO card 

must be able to supply a signal current of at least 100 mA.

Observe the useful lifetime limitations of the output relays.

SIL 3 application

To build a SIL safety loop for the defined SIL, it is assumed as an example that this device 

uses 10 % of the available budget for PFD

avg

/PFH.

For a SIL 3 application operating in low demand mode the total PFD

avg

value 

of the SIF (

S

afety 

I

nstrumented 

F

unction) should be smaller than 10

-3

hence the maximum allowable PFD

avg

value would then be 10

-4

.

For a SIL 3 application operating in high demand mode the total PFH value 

of the SIF should be smaller than 10

-7

 per hour, hence the maximum allowable PFH value 

would then be 10

-8

 per hour.

For a SIL 3 application operating in high demand mode the internal fault detection 

and the line fault detection must be enabled. The fault indication output, 

the collective error message output, or the input impedance change must be monitored. 

In case of detected faults the necessary reaction must be introduced.

If the device is used in applications for high demand mode, perform a risk analysis 

regarding systematic faults and implement suitable measures to control these systematic 

faults. For example, this can be the following measures:

usage of redundant power supplies,

monitoring of input signal, wiring and connections for short circuits and open circuits,

monitoring the output for open circuits.

Since the safety loop has a hardware fault tolerance of 

0

 and it is a type

A

 device, 

the SFF must be > 90 % according to table 2 of IEC/EN 61508-2 for a SIL 3 (sub) system.

SILCL and PL application

The standards IEC/EN 62061 and EN/ISO 13849-1 require that the safety device 

is implemented according to the idle current principle. As the device is implemented 

following the working current principle, no safety classification according 

to IEC/EN 62061 and EN/ISO 13849-1 was carried out. If you use the device 

in machinery safety applications, assess the specific application and show that 

an equivalent safety level will be achieved.

Содержание KFD2-RSH-1.2E.L2

Страница 1: ...ISO9001 3 Functional Safety Relay Module KFD2 RSH 1 2E L2 Y1 KFD2 RSH 1 2E L3 Y1 Manual...

Страница 2: ...ion as well as the supplementary clause Expanded reservation of proprietorship Worldwide Pepperl Fuchs Group Lilienthalstr 200 68307 Mannheim Germany Phone 49 621 776 0 E mail info de pepperl fuchs co...

Страница 3: ...Standards and Directives for Functional Safe 9 3 Planning 10 3 1 System Structure 10 3 2 Assumptions 11 3 3 Safety Function and Safe State 12 3 4 Characteristic Safety Values 13 3 5 Useful Lifetime 1...

Страница 4: ...Functional Safety KFD2 RSH 1 2E L Y1 Contents 4 2019 11...

Страница 5: ...oting Dismounting Disposal The documentation consists of the following parts Present document Instruction manual Manual Datasheet Additionally the following parts may belong to the documentation if ap...

Страница 6: ...and understood the instruction manual and the further documentation Intended Use The device is only approved for appropriate and intended use Ignoring these instructions will void any warranty and abs...

Страница 7: ...are displayed in descending order as follows Informative Symbols Action This symbol indicates a paragraph with instructions You are prompted to perform an action or a sequence of actions Danger This s...

Страница 8: ...he device is a relay module that is suitable for safely switching applications of a load circuit The device isolates load circuits up to 60 V DC and the 24 V DC control circuit KFD2 RSH 1 2E L3 Y1 The...

Страница 9: ...and directives Pepperl Fuchs Group Lilienthalstra e 200 68307 Mannheim Germany Internet www pepperl fuchs com KFD2 RSH 1 2E L2 KFD2 RSH 1 2E L2 Y1 KFD2 RSH 1 2E L3 KFD2 RSH 1 2E L3 Y1 Up to SIL 3 Fun...

Страница 10: ...the demand rate for this safety loop is assumed to be higher than once per year The relevant safety parameters to be verified are the PFH value Probability of dangerous Failure per Hour Fault reaction...

Страница 11: ...value of the SIF Safety Instrumented Function should be smaller than 10 3 hence the maximum allowable PFDavg value would then be 10 4 For a SIL 3 application operating in high demand mode the total PF...

Страница 12: ...3 Safety Function and Safe State Safety Function Whenever the input of the device is energized the ETS output is conducting Safe State In the safe state of the safety function the ETS output is close...

Страница 13: ...rates of the safety function 2 While the diagnostic function is signaling the dangerous failure of one relay the other two redundant relays continue to provide the safety function Exceptions are commo...

Страница 14: ...re rate during the useful lifetime is valid The standard EN ISO 13849 1 2015 proposes a useful lifetime TM of 20 years for devices used within industrial environments This device is designed for this...

Страница 15: ...ue of 0 5 0 6 Nm 4 2 Configuration Configuring the Device The device is configured via DIP switches The DIP switches are on the side of the device 1 De energize the device before configuring the devic...

Страница 16: ...that are suitable for this safety application 4 Correct any occurring safe failures within 8 hours Take measures to maintain the safety function while the device is being repaired Danger Danger to li...

Страница 17: ...tions to achieve the diagnostic coverage see step 2 of the following section Internal Diagnosis Procedure 1 Enable the internal fault detection See chapter 4 2 1 2 You have 2 options to achieve the di...

Страница 18: ...intervals depending on the applied PFDavg in accordance with the characteristic safety values See chapter 3 4 The internal fault detection may be used to implement a proof test The diagnostic coverage...

Страница 19: ...at least 2 seconds LED OUT is on LED FLT is off 1 5 V 0 V DC between terminals 7 and 8 6 Wait at least 2 seconds LED OUT is off LED FLT is off 1 7 V 24 V DC between terminals 7 and 8 8 Wait at least...

Страница 20: ...he standard application the process control system is connected to terminals 7 and 8 The line fault transparency LFT of the safety relay must be compatible with the line fault detection of the process...

Страница 21: ...l loop of the dual pole switching If the fault indication output is open the output relay contacts cannot be enabled But as the fault is detected by the process control system a suitable reaction can...

Страница 22: ...es not work Take appropriate measures to protect personnel and equipment while the safety function is not available Secure the application against accidental restart 3 Do not repair a defective device...

Страница 23: ...fety function Probability of failure of components that are in the safety loop HFT Hardware Fault Tolerance MTBF Mean Time Between Failures MTTR Mean Time To Restoration PCS Process Control System PFD...

Страница 24: ...Pepperl Fuchs Quality Download our latest policy here www pepperl fuchs com quality www pepperl fuchs com Pepperl Fuchs Subject to modifications Printed in Germany DOCT 5816C...

Отзывы: