26.11.2014 Views

Safety Manager Safety Manual - Tuv-fs.com

Safety Manager Safety Manual - Tuv-fs.com

Safety Manager Safety Manual - Tuv-fs.com

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Special requirements for<br />

TUV-approved applications<br />

5<br />

General<br />

<strong>Safety</strong> <strong>Manager</strong> can be used for processes which require, amongst others, TUV<br />

approval. The requirements for the safety applications are the following:<br />

1. The maximum application cycle time is half the Process <strong>Safety</strong> Time. For<br />

example, the accepted Process <strong>Safety</strong> Time for a burner control system in<br />

accordance with TRD-411 for boilers > 30 kW (July 1985) Table 1, TRD-412<br />

(July 1985) Table 1 and DIN 4788 (June 1977) Part 2 Chapter 3.2.3.2 1 is 1<br />

second.<br />

This implies that the application cycle time must be 0.5 second or less. The<br />

application cycle time is monitored by the SM Controller and can be seen on<br />

the System Information screen of Controller Management.<br />

The application cycle time is limited to 2.3 seconds by the watchdog, resulting<br />

in a maximum typical cycle time of 2 seconds. The typical application cycle<br />

time can be calculated by the <strong>Safety</strong> <strong>Manager</strong> MTBF and Cycle time<br />

calculation tool. This tool is available via Honeywell SMS and includes:<br />

- cycle time estimation based upon amount of IO, DTI, application<br />

<strong>com</strong>plexity and <strong>com</strong>munication parameters,<br />

- MTBF calculation<br />

2. If <strong>Safety</strong> <strong>Manager</strong> detects a fault in output hardware that is configured with<br />

Fault Reaction Low or 0mA, it will de-energize the faulty output modules or<br />

instead de-energize all outputs. The de-energization of faulty output modules<br />

or all outputs is fully implemented in the software and cannot be influenced<br />

by the user (see also item 3).<br />

If an output module (configured with Fault Reaction Low or 0mA) is detected<br />

faulty, the outputs of that output module are switched off and the repair timer<br />

is started. The Control Processor then verifies the switch-off.<br />

- If the switch-off is verified the faulty output module can be replaced<br />

without affecting the status of the Control Processor and the<br />

<strong>Safety</strong> <strong>Manager</strong> <strong>Safety</strong> <strong>Manual</strong> 47

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!