26.11.2014 Views

Safety Manager Safety Manual - Tuv-fs.com

Safety Manager Safety Manual - Tuv-fs.com

Safety Manager Safety Manual - Tuv-fs.com

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

3 – <strong>Safety</strong> <strong>Manager</strong> fault detection and response<br />

Repair timer<br />

Note:<br />

The repair timer setting must be based on a hardware reliability analysis which includes<br />

MTTR figures.<br />

All configurations of <strong>Safety</strong> <strong>Manager</strong> are single fault tolerant towards faults that<br />

affect safety: By using a secondary means <strong>Safety</strong> <strong>Manager</strong> is always able to bring<br />

a process to safe state, regardless of the fault.<br />

However, given some time, a second fault may occur. This second fault may then<br />

disable the secondary means that keeps the process in a safe state.<br />

To prevent such a scenario to develop, the system starts a repair timer if a<br />

secondary means be<strong>com</strong>es vulnerable to faults. Once started, this configurable<br />

timer counts down until the fault is repaired. If the timer is allowed to reach zero,<br />

the Control Processor halts.<br />

20 Release 131, Issue 4.2

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!