12.07.2015 Views

AADvance Safety Manual - Tuv-fs.com

AADvance Safety Manual - Tuv-fs.com

AADvance Safety Manual - Tuv-fs.com

SHOW MORE
SHOW LESS
  • No tags were found...

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

<strong>AADvance</strong> <strong>Safety</strong> <strong>Manual</strong>TerminologyVocabulary and ConventionsProcess <strong>Safety</strong> TimeThe terms certification and certified are used widely within this <strong>Manual</strong>, these termsrefer principally to the functional safety certification of the <strong>AADvance</strong> system to IEC61508 SIL3 and other relevant standards.This <strong>Manual</strong> contains rules and re<strong>com</strong>mendations: Rules are mandatory and must be followed if the resulting system is to be a SIL3<strong>com</strong>pliant application. These are identified by the term 'shall'. Re<strong>com</strong>mendations are not mandatory, but if they are not followed, extra safetyprecautions must be taken in order to certify the system. Re<strong>com</strong>mendations areidentified by the term 'it is highly re<strong>com</strong>mended'.The process safety time for the equipment under control (denoted PST EUC ) is theperiod a dangerous condition can exist before a hazardous event occurs without asafety system as a protection. It can be a fraction of a second or several hours,depending on the process. A PST can be defined for a controller via the processormodule and independently for individual I/O modules, however, the processor definedPST will always have priority over the I/O PST if the I/O PST exceeds the processorvalue.Fault Tolerance in <strong>Safety</strong> ApplicationsFor safety applications, you must define how the control system will respond in thepresence of faults. As faults accumulate, this be<strong>com</strong>es the system's defined state ofdegraded operation or fault tolerance level. Simplex systems are not fault tolerant and do not have the ability to continue theiroperation in the presence of fault conditions, however they are designed to failsafe. Fault tolerant systems have redundant modules and processors that allow thesystem to continue operation or to ensure that the system fails safe in thepresence of faults. Redundant operation is when modules within the different stages (input, logicsolving and output) are configured as dual or triple modules.Internal diagnostics enhance the fault tolerance capability. For example, when a hiddenor covert fault occurs it could prevent the system from responding when required todo so — this is unacceptable for safety applications. To detect the presence of hiddenor covert faults you must perform diagnostic tests on the system. Detection of a faultis then used to force the system to its fail-safe condition.1-2 Document number 553630 Issue 7: February 2010

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!