Safety Manager Safety Manual - Tuv-fs.com
Safety Manager Safety Manual - Tuv-fs.com
Safety Manager Safety Manual - Tuv-fs.com
You also want an ePaper? Increase the reach of your titles
YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.
3 – <strong>Safety</strong> <strong>Manager</strong> fault detection and response<br />
Repair timer<br />
Note:<br />
The repair timer setting must be based on a hardware reliability analysis which includes<br />
MTTR figures.<br />
All configurations of <strong>Safety</strong> <strong>Manager</strong> are single fault tolerant towards faults that<br />
affect safety: By using a secondary means <strong>Safety</strong> <strong>Manager</strong> is always able to bring<br />
a process to safe state, regardless of the fault.<br />
However, given some time, a second fault may occur. This second fault may then<br />
disable the secondary means that keeps the process in a safe state.<br />
To prevent such a scenario to develop, the system starts a repair timer if a<br />
secondary means be<strong>com</strong>es vulnerable to faults. Once started, this configurable<br />
timer counts down until the fault is repaired. If the timer is allowed to reach zero,<br />
the Control Processor halts.<br />
20 Release 131, Issue 4.2