This manual contains information for application of the device in functional safety
related loops.
The corresponding data sheets, the operating instructions, the system
description, the Declaration of Conformity, the EC-Type-Examination Certificate,
the Functional Safety Assessment and applicable Certificates (see data sheet)
are integral parts of this document.
The documents mentioned are available from www.pepperl-fuchs.com or by
contacting your local Pepperl+Fuchs representative.
Mounting, commissioning, operation, maintenance and dismounting of any
devices may only be carried out by trained, qualified personnel. The instruction
manual must be read and understood.
When it is not possible to correct faults, the devices must be taken out of service
and action taken to protect against accidental use. Devices should only be
repaired directly by the manufacturer. De-activating or bypassing safety functions
or failure to follow the advice given in this manual (causing disturbances or
impairment of safety functions) may cause damage to property, environment or
persons for which Pepperl+Fuchs GmbH will not be liable.
The devices are developed, manufactured and tested according to the relevant
safety standards. They must only be used for the applications described in the
instructions and with specified environmental conditions, and only in connection
with approved external devices.
1.2Intended Use
This signal conditioner is a loop powered safety relay module with a logic input
and two different relay outputs:
It can be used as an interface in output loops for fire and gas systems classified as
SIL3. The safe state in this application is energized to safe (ETS). Output I with
two relays in parallel must be used, no fuse available.
It can also be used as an interface in output loops for ESD (Emergency Shut
Down) systems classified as SIL3. The safe state in this application is
de-energized to safe (DTS). Output II with two relays in series must be used. An
additional fuse in series to the relay contacts is available (see chapter 3).
With both outputs in combination a non safety application for dual pole switching
(DPS) is possible.
Additionally a test input for proof tests is available. The proof test checks if each
single relay is working correctly.
The device is usually mounted on a DIN rail in cabinets with access for qualified
personnel only.
Standard of functional safety: safety instrumented systems for the process
industry sector (user)
225538 2011-04
5
SAFETY MANUAL SIL KFD0-RSH-1.4S.PS2
Planning
2Planning
2.1System Structure
2.1.1Low Demand Mode
If there are two loops, one for the standard operation and another one for the
functional safety, then usually the demand rate for the safety loop is assumed to
be less than once per year.
The relevant safety parameters to be verified are:
■ the PFD
(proof test interval that has a direct impact on the PFD
■ the SFF value (Safe Failure Fraction)
■ the HFT architecture (Hardware Fault Tolerance architecture)
2.1.2High Demand Mode
If there is only one loop, which combines the standard operation and safety
related operation, then usually the demand rate for this loop is assumed to be
higher than once per year.
The relevant safety parameters to be verified are:
■ PFH (Probability of dangerous Failure per Hour)
■ Fault reaction time of the safety system
■ the SFF value (Safe Failure Fraction)
■ the HFT architecture (Hardware Fault Tolerance architecture)
value (average Probability of Failure on Demand) and T
avg
avg
)
proof
225538 2011-04
6
Loading...
+ 12 hidden pages
You need points to download manuals.
1 point = 1 manual.
You can buy points or you can get point for every manual you upload.