Solid state equipment has operational characteristics differing from those of electromechanical equipment. Safety Guidelines for the Application,
Installation and Maintenance of Solid State Controls (publication SGI-1.1
http://literature.rockwellautomation.com
) describes some important differences between solid state equipment and hard-wired electromechanical
devices. Because of this difference, and also because of the wide variety of uses for solid state equipment, all persons responsible for applying this
equipment must satisfy themselves that each intended application of this equipment is acceptable.
In no event will Rockwell Automation, Inc. be responsible or liable for indirect or consequential damages resulting from the use or application of this
equipment.
The examples and diagrams in this manual are included solely for illustrative purposes. Because of the many variables and requirements associated
with any particular installation, Rockwell Automation, Inc. cannot assume responsibility or liability for actual use based on the examples and
diagrams.
No patent liability is assumed by Rockwell Automation, Inc. with respect to use of information, circuits, equipment, or software described in this
manual.
Reproduction of the contents of this manual, in whole or in part, without written permission of Rockwell Automation, Inc., is prohibited.
Throughout this manual, when necessary, we use notes to make you aware of safety considerations.
available from your local Rockwell Automation sales office or online at
Identifies information about practices or circumstances that can cause an explosion in a hazardous environment, which may
lead to personal injury or death, property damage, or economic loss.
Identifies information that is critical for successful application and understanding of the product.
Identifies information about practices or circumstances that can lead to: personal injury or death, property damage, or
economic loss. Attentions help you identify a hazard, avoid a hazard, and recognize the consequence.
Labels may be on or inside the equipment, such as a drive or motor, to alert people that dangerous voltage may be present.
Labels may be on or inside the equipment, such as a drive or motor, to alert people that surfaces may reach dangerous
temperatures.
Allen-Bradley, Rockwell Automation, FLEX I/O, RSLinx, RSLogix 5000 and TechConnect are trademarks of Rockwell Automation, Inc.
Trademarks not belonging to Rockwell Automation are property of their respective companies.
Preface
Introduction
Manual Set-Up
Table Preface.1
This application manual is intended to describe the FLEX I/O with ControlLogix
Control System components available from Rockwell Automation that are
suitable for use in SIL2 applications. Use this manual in conjunction with
publication 1756-RM001
Alternate architecture can be used in SIL2 applications if they are approved by
a certifying agency.
This manual is designed to make clear how the FLEX I/O with ControlLogix
Control System can be SIL2-certified. Table Preface.1 lists the information
available in each section.
Section:Title:Description:
Chapter 1SIL PolicyIntroduction to the SIL policy and how that
policy relates to FLEX I/O with a ControlLogix
system.
Chapter 2ControlLogix Communications Description of the ControlLogix communications
modules used in the SIL2-certified FLEX I/O
with ControlLogix system.
Chapter 3FLEX I/O ModulesDescription of the FLEX I/O modules used in the
SIL2-certified FLEX I/O with ControlLogix
system.
Chapter 4General Requirements for
Application Software
Application software requirements for using
ControlLogix and FLEX modules.
Chapter 5Technical SIL2 Requirements
for the Application Program
Appendix AFailure EstimatesFailure rates based on field returns.
Understanding Terminology
1Publication 1794-RM001G-EN-P - December 2011
The following table defines acronyms used in this manual.
Table Preface.2 List of Acronyms Used Throughout the Safety Application Manual
Acronym:Full Term:Definition:
CIPControl and
Information
Protocol
DCDiagnostic
Coverage
ENEuropean Norm.The official European Standard
GSVGet System Value A ladder logic output instruction that retrieves
Guidelines for application development in
RSLogix 5000 as they relate to SIL2.
A messaging protocol used by Logix5000™
systems. It is a native communications protocol
used on ControlNet™ communications networks,
among others.
The ratio of the detected failure rate to the total
failure rate.
specified controller status information and places
it in a destination tag.
Preface 2
Table Preface.2 List of Acronyms Used Throughout the Safety Application Manual
Acronym:Full Term:Definition:
MTBFMean Time
Average time between failure occurrences.
Between Failures
MTTRMean Time to
Restoration
Average time needed to restore normal operation
after a failure has occurred.
PADTProgramming and
Debugging Tool
RSLogix 5000 software used to program and
debug a SIL2-certified FLEX I/O with ControlLogix
application.
PCPersonal
Computer
Computer used to interface with, and control, a
ControlLogix system via RSLogix 5000
programming software.
PFDProbability of
Failure on
The average probability of a system to fail to
perform its design function on demand.
Demand
PFHProbability of
Failure per Hour
The probability of a system to have a dangerous
failure occur per hour.
1oo1One out of oneA 1oo1 (one out of one) architecture consists of a
single channel where any dangerous failure leads
to a failure of the safety function.
1oo2One out of twoA 1oo2 (one out of two) architecture consists of
two channels connected in parallel such that
either channel can process the safety function.
Publication 1794-RM001G-EN-P - December 2011
Chapter
SIL Policy
This chapter introduces you to the SIL policy and how the
ControlLogix/FLEX I/O system meets the requirements for SIL2
certification.
For information about:See page:
Introduction to SIL1-1
SIL2 Certification1-2
Proof Tests1-3
SIL2-Certified FLEX I/O System Components1-5
Hardware Designs and Firmware Functions1-8
Hardware Designs and Firmware Functions1-8
1
Introduction to SIL
Difference Between PFD and PFH1-8
SIL Compliance Distribution and Weight1-13
Response Times1-13
Certain catalog numbers (listed in Table 1.1 on page 1-5) of the FLEX I/O with
ControlLogix system are type-approved and certified for use in SIL2
applications, according to IEC 61508. SIL requirements are based on the
standards current at the time of certification.
These requirements consist of mean time between failures (MTBF),
probability of failure, failure rates, diagnostic coverage and safe failure
fractions that fulfill SIL2 criteria. The results make the ControlLogix/FLEX
I/O system suitable up to, and including, SIL2. When the
ControlLogix/FLEX I/O system is in the maintenance or programming
mode, the user is responsible for maintaining a safe state.
For support in creation of programs, the PADT (Programming and
Debugging Tool) is required. The PADT for ControlLogix/FLEX I/O is
RSLogix 5000, per IEC 61131-3, and this Safety Reference Manual.
The TUV Rheinland has approved the ControlLogix/FLEX I/O system for
use in up to and including SIL 2 safety related applications in which the
de-energized state is considered to be the safe state. All of the examples related
to I/O included in this manual are based on achieving de-energization as the
safe state for typical Emergency Shutdown (ESD) Systems.
1Publication 1794-RM001G-EN-P - December 2011
1-2 SIL Policy
Plant-wide Ethernet/Serial
ControlNet
SIL2-certified ControlLogix components’ portion of the overall safety loop
Programming Software
For SIL applications, a programming
terminal is not normally connected.
HMI
For Diagnostics and Visualization (read-only access to controllers in the
safety loop). For more information, see publication 1756-RM001.
E
N
B
C
N
B
To other safety related
ControlLogix or FLEX I/O
remote I/O chassis
Overall Safety Loop
Actuator
Actuator
1794 FLEX I/O
Input
Device
DI1
DO2
DO1
DI2
ControlNet
Input
Device
To other safety related
ControlLogix or FLEX I/O
remote I/O chassis
See Figures 3.1 and 3.5 for details.
1
Note 1: Multiple 1756-CNB or -CNBR modules can be installed into the chassis as needed.
Other configurations are possible as long as they are SIL2 approved.
+V
SIL2 Certification
Figure 1.1 shows a typical SIL loop, including:
• the overall safety loop
• the ControlLogix/FLEX I/O portion of the overall safety loop
• how other devices (for example, HMI) connect to the loop, while
operating outside the loop
Figure 1.1
Note 2: Two adapters are required for meeting SIL2 as shown in the figure.
The adapters can be either ControlNet or Ethernet and must be from the list of approved products.
Publication 1794-RM001G-EN-P - December 2011
SIL Policy 1-3
IMPORTANT
IMPORTANT
Important Note related to published PFDs.
• The user must choose the appropriate PFD depending
on combinations and the appropriate 1oo1 or 1oo2
configuration.
• Descrete and analog inputs must be used in a 1oo2
configuration for SIL 2.
• Adapters must be used in a 1oo2.
• Outputs may be 1oo2 in series or 1oo1 monitored by
an input with an external relay as a secondary device to
remove power.
• Some specialized inputs can only be wired to a single
sensor such as thermocuples and two 1oo1 PFDs must
be used for each.
• The total PFD for two 1oo1s is the sum of both.
The system user is responsible for:
Proof Tests
• the set-up, SIL rating and validation of any sensors or
actuators connected to the ControlLogix/FLEX I/O
control system.
• project management and functional testing.
programming the application software and the module
configuration according to the description in the
following chapters.
The SIL2 portion of the certified system excludes the
development tools and display/human machine interface
(HMI) devices; these tools and devices are not part of the
run time control loop.
IEC 61508 requires the user to perform various proof tests of the equipment
used in the system. Proof tests are performed at user-defined times (for
example, proof test intervals can be once a year, once every two years or
whatever timeframe is appropriate) and include some of the following tests:
• Testing of all fault routines to verify that process parameters are
monitored properly and the system reacts properly when a fault
condition arises.
• Testing of digital input or output channels to verify that they are not
stuck in the ON or OFF state.
Publication 1794-RM001G-EN-P - December 2011
1-4 SIL Policy
IMPORTANT
• Calibration of analog input and output modules to verify that accurate
data is obtained from and used on the modules.
Users’ specific applications will determine the timeframe
for the proof test interval.
However, keep in mind that the Probability of Failure on
Demand (PFD) calculations listed in Table 1.2 on page 1-8
use a proof test interval of once per year. If the proof test
interval is changed, the information must be recalculated.
For more information on system proof tests, see Publication 1756-RM001
more information on the necessary I/O module, see Table 1.1.
. For
Publication 1794-RM001G-EN-P - December 2011
SIL Policy 1-5
SIL2-Certified FLEX I/O
Table 1.1 lists the components available for use in a SIL2-certified FLEX I/O
system. For a list of ControlLogix SIL2 certified products, see publication
System Components
Table 1.1 FLEX I/O Components For Use in the SIL 2 System
1794-IP44 Ch. Pulse Counter ModuleB4, 4.x1794-IN0641794-UM016
1794-IE4XOE2XT4 Input/2 Output Analog
BNA1794-IN125NA
Combo Module
1794-IE8XT8 Input analog ModuleBNA
1794-OE4XT4 Output Analog ModuleBNA
1794-IF2XOF2IXT2 Input/2 Output Isolated
AI, I.x1794-IN129
Analog Combo Module
1794-IF4IXT4 Isolated Input Analog
AI, I.x
Module
1794-OF4IXT4 Isolated Output Analog
AI, I.x
Module
1794-IF4ICFXT4 Isolated Input Analog
AI, I.x1794-IN130
Module
1794-IJ2XT2 Ch. Frequency Counter
AE, E.x1794-IN049
Module
1794-IRT8XT8 TC/RTD Input Analog
BD, E, E.1, E.x 1794-IN050
Module
Publication 1794-RM001G-EN-P - December 2011
Table 1.1 FLEX I/O Components For Use in the SIL 2 System
SIL Policy 1-7
Related Documentation
with More Information on
Catalog Number:
Device Type:Catalog Number:
Terminal Base
Units
1794-TB33-Wire Terminal Base UnitANA1794-IN092NA
1794-TB3S3-Wire Terminal Base UnitANA
1794-TB3TTemperature Terminal Base
Firmware
Revision:
(1)
Description:
Series
(2)
(2) (3)
ANA
Installation
Instructions:
User Manual:
Unit
1794-TB3TSSpring-clamp Temperature
ANA
Base Unit
1794-TB3GCage-clamp Gen. Terminal
ANA
Base Unit
1794-TB3GSSpring-clamp Gen. Terminal
ANA
Base Unit
1794-TBNNEMA Terminal Base UnitANA
1794-TBNFFused NEMA Terminal Base
ANA
Unit
(1)
Certain catalog numbers have a K suffix. This indicates a conformally coated version of the product. These K versions have the same SIL2 certification as the non-K
versions.
(2)
The FW versions marked with extension .x (x can be 0 ... 99) are constitute to minor changes for enhancements. The test institute will be informed on any change.
(3)
Users must use these series and firmware revisions for their application to be SIL2 certified. Firmware revisions are available by visiting
These publications are available from Rockwell Automation by visiting http://literature.rockwellautomation.com.
(4)
Publication 1794-RM001G-EN-P - December 2011
1-8 SIL Policy
Hardware Designs and
Firmware Functions
Difference Between PFD
and PFH
Diagnostic hardware designs and firmware functions designed into the
ControlLogix/FLEX I/O platform allow it to achieve at least SIL2
certification in a single-controller configuration. These diagnostic features are
incorporated into specific FLEX I/O components, such as the:
• adapter
• power supply
• I/O modules
• terminal base units
and are covered in subsequent sections. The ControlLogix/FLEX I/O
platform’s designs, features and characteristics make it one of the most
intelligent platforms.
Table 1.2 and Table 1.3 present values of the PFDs and PFHs for the specific
FLEX I/O products evaluated by TUV.
FLEX I/O uses the same PFD and PFH assumptions as stated in publication
1756-RM001
.
Table 1.2 FLEX I/O Product Probability of Failure on Demand (PFD) Calculations (T1 = 1 yr)
Catalog NumberDescriptionMean Time
Between Failure
(1)
(MTBF)
1794-ACN15ControlNet Single Media Adapter8,223,6841.22E-072.15E-06
1794-ACNR15ControlNet Redundant Media Adapter8,223,6841.22E-072.15E-06
1794-AENT10/100Mb Ethernet Communication Adapter691,1341.45E-062.76E-05
1794-AENTR10/100Mb Ethernet Redundant Communication Adapter1,268,0707.89E-071.45E-05
1794-IB10XOB610 Input/6 Output Module4,943,4422.02E-073.60E-06
1794-IB1616 Sink Input Module4,105,0902.44E-074.34E-06
1794-IE8Analog Input Module37,952,6792.63E-084.64E-07
1794-IF2XOF2IIsolated Analog Input/Output Module25,296,9603.95E-086.97E-07
1794-IF4IIsolated Analog Input Module11,746,3438.51E-081.50E-06
1794-IJ2Frequency Counter Module2,418,3214.14E-077.45E-06
1794-IP4Pulse Counter Module2,375,3604.21E-077.58E-06
1794-IR8RTD Input Module6,191,6551.62E-072.87E-06
1794-IRT8TC/RTD/mV Input Module1,182,4388.46E-071.56E-05
1794-IT8Thermocouple Input Module1,564,3246.39E-071.17E-05
1794-OB1616 Source Output Module1,883,5945.31E-079.62E-06
1794-OB16PProtected Output Module2,135,2804.68E-078.46E-06
(3)
λ
Calculated PFD
1oo2 architecture
Publication 1794-RM001G-EN-P - December 2011
Table 1.2 FLEX I/O Product Probability of Failure on Demand (PFD) Calculations (T1 = 1 yr)
SIL Policy 1-9
Catalog NumberDescriptionMean Time
Between Failure
(1)
(MTBF)
1794-OB8EPProtected Output Module
2,389,669
(2)
(3)
λ
4.18E-077.54E-06
Calculated PFD
1oo2 architecture
1794-OE4Analog Output Module23,807,0864.20E-087.41E-07
1794-OF4IIsolated Analog Output Module7,191,1281.39E-072.47E-06
1794-OW8Relay Output Module14,766,8766.77E-081.20E-06
1794-TB3Terminal Base Units
21,128,346
(2)
4.73E-088.35E-07
1794-TB3GGeneric Terminal Base Units27,320,8003.66E-086.45E-07
1794-TB3GSGeneric Terminal Base Units46,425,6002.15E-083.79E-07
1794-TB3STerminal Base Unit
1794-TB3TTemperature Terminal Base Units
1794-TB3TSTemperature Terminal Base Units
71,433,747
73,096,226
75,763,399
(2)
(2)
(2)
1.40E-082.46E-07
1.37E-082.41E-07
1.32E-082.32E-07
1794-TBNTerminal Base Units75,716,6151.32E-082.32E-07
1794-TBNFFused Terminal Base Units
4,812,320
(2)
2.08E-073.70E-06
1794-ACNR15XTControlNet Redundant Media Adapter8,223,6841.22E-072.15E-06
1794-AENTRXT10/100Mb Ethernet Redundant Communication Adapter1,268,0707.89E-071.45E-05
1794-OB8EPXT8 Protected Output Module14,771,0496.77E-081.20E-06
1794-IB16XT16 Sink Input Module35,587,1892.81E-084.95E-07
1794-OB16PXT16 Protected Output Module26,709,4013.74E-086.60E-07
1794-IB10XOB6XT10 Input/6 Output Combo Module22,202,4874.50E-087.94E-07
1794-OW8XT8 Relay Output Module18,518,5195.40E-089.53E-07
1794-IE4XOE2XT4 Input/2 Output Analog Combo Module11,800,8028.47E-081.50E-06
1794-IE8XT8 Input analog Module14,041,0007.12E-081.26E-06
1794-OE4XT4 Output Analog Module11,381,7448.79E-081.55E-06
1794-IF2XOF2IXT2 Input/2 Output Isolated Analog Combo Module6,317,9181.58E-072.81E-06
1794-IF4IXT4 Isolated Input Analog Module7,297,1401.37E-072.43E-06
1794-IF4ICFXT4 Isolated Input Analog Module7,297,1401.37E-072.43E-06
1794-OF4IXT4 Isolated Output Analog Module5,493,9021.82E-073.24E-06
1794-IJ2XT2 Ch. Frequency Counter Module11,714,1288.54E-081.51E-06
1794-IRT8XT8 TC/RTD Input Analog Module8,204,7921.22E-072.16E-06
(1)
MTBF measured in hours.
(2)
Calculated using field-based values for components
(3)
λ = Failure Rate = 1/MTBF
Publication 1794-RM001G-EN-P - December 2011
1-10 SIL Policy
Table 1.3 FLEX I/O Product Probability of Undetected Dangerous Failure per Hour (PFH) Calculations (T1 = 1 yr)
Catalog NumberDescriptionMean Time
Between Failure
(1)
(MTBF)
(3)
λ
Calculated PFH
1oo2 architecture
1794-ACN15ControlNet Single Media Adapter8,223,6841.22E-078.64E-10
1794-ACNR15ControlNet Redundant Media Adapter8,223,6841.22E-078.64E-10
1794-AENT10/100Mb Ethernet Communication Adapter691,1341.45E-061.19E-08
1794-AENTR10/100Mb Ethernet Redundant Communication Adapter
1794-OE4Analog Output Module23,807,0864.20E-082.96E-10
1794-OF4IIsolated Analog Output Module7,191,1281.39E-079.90E-10
1794-OW8Relay Output Module14,766,8766.77E-084.78E-10
1794-TB3Terminal Base Units
21,128,346
(2)
4.73E-083.33E-10
1794-TB3GGeneric Terminal Base Units27,320,8003.66E-082.57E-10
1794-TB3GSGeneric Terminal Base Units46,425,6002.15E-081.51E-10
1794-TB3STerminal Base Unit
1794-TB3TTemperature Terminal Base Units
1794-TB3TSTemperature Terminal Base Units
71,433,747
73,096,226
75,763,399
(2)
(2)
(2)
1.40E-089.82E-11
1.37E-089.59E11
1.32E-089.25E-11
1794-TBNTerminal Base Units75,716,6151.32E-089.26E-11
1794-TBNFFused Terminal Base Units
4,812,320
(2)
2.08E-071.49E-09
1794-ACNR15XTControlNet Redundant Media Adapte8,223,6841.22E-078.64E-10
1794-AENTRXT10/100Mb Ethernet Redundant Communication Adapter
Table 1.3 FLEX I/O Product Probability of Undetected Dangerous Failure per Hour (PFH) Calculations (T1 = 1 yr)
SIL Policy 1-11
Catalog NumberDescriptionMean Time
Between Failure
(1)
(MTBF)
(3)
λ
Calculated PFH
1oo2 architecture
1794-IE4XOE2XT4 Input/2 Output Analog Combo Module11,800,8028.47E-085.99E-10
1794-IE8XT8 Input analog Module14,041,0007.12E-085.03E-10
1794-OE4XT4 Output Analog Module11,381,7448.79E-086.22E-10
1794-IF2XOF2IXT2 Input/2 Output Isolated Analog Combo Module6,317,9181.58E-071.13E-09
1794-IF4IXT4 Isolated Input Analog Module7,297,1401.37E-079.75E-10
1794-IF4ICFXT4 Isolated Input Analog Module7,297,1401.37E-079.75E-10
1794-OF4IXT4 Isolated Output Analog Module5,493,9021.82E-071.30E-09
1794-IJ2XT2 Ch. Frequency Counter Module11,714,1288.54E-086.04E-10
1794-IRT8XT8 TC/RTD Input Analog Module8,204,7921.22E-078.66E-10
(1)
MTBF measured in hours.
(2)
Calculated using field-based values for components
(3)
λ = Failure Rate = 1/MTBF
Table 1.4 shows an example of a PFD calculation for a safety loop involving
two DC input modules used in a 1oo2 configuration and a DC output module.
Table 1.4
Catalog Number:Description:MTBF:Calculated
1oo2 PFD:
1794-ACNR15ControlNet Dual Media
3,259,6051.56E-06
Adapter 1.5
1794-IB1624V DC Input Module6,409,8464.34E-06
1794-IB1624V DC Input Module6,409,8464.34E-06
1794-OB1624V DC Output Module4,284,8579.62E-06
1794-OW8Relay Output Module1,312,9731.20E-06
1756-L63B
1
ControlLogix Controller2,460,0652.33E-04
1756-CNBControlNet Bridge Module3,596,0871.15E-04
1756-CNBControlNet Bridge Module3,596,0871.15E-04
Total PFD calculation for a safety loop consisting of these products:3.70E-04
1 See Publication 1756-RM001
for more information.
Publication 1794-RM001G-EN-P - December 2011
1-12 SIL Policy
B
B
1794-OB16
1794-IB16
1794-TB3 (1)
1794-TB3 (2)
1794-ACNR15 (1)
1794-ACNR15 (2)
1794-IB16
1794-OW8
1756-CNB
1756-L63B
ControlNet
ControlNet
1756-CNB
Publication 1794-RM001G-EN-P - December 2011
SIL Policy 1-13
SIL Compliance
Distribution and Weight
Response Times
The programmable controller may conservatively be assumed to contribute
10% of the reliability burden. A SIL 2 system may need to incorporate multiple
inputs for critical sensors and input devices, as well as dual outputs connected
in series to dual actuators dependent on SIL assessments for the safety related
system.
The response time of the system is defined as the amount of time it takes for a
change in an input condition to be recognized and processed by the
controller’s ladder logic program, and then to initiate the appropriate output
signal to an actuator. The system response time is the sum of the following:
• input hardware delays
• input filtering
• I/O and communication module RPI settings
• controller program scan times
• output module propagation delays
See Table 1.1 for associated module information.
Each of the times listed above is variably dependent on factors such as the type
of I/O module and instructions used in the ladder program. For examples of
how to perform these calculations, see publication 1756-RM001
.
Publication 1794-RM001G-EN-P - December 2011
1-14 SIL Policy
Notes:
Publication 1794-RM001G-EN-P - December 2011
Loading...
+ 42 hidden pages
You need points to download manuals.
1 point = 1 manual.
You can buy points or you can get point for every manual you upload.