12.07.2015 Views

AADvance Safety Manual - Tuv-fs.com

AADvance Safety Manual - Tuv-fs.com

AADvance Safety Manual - Tuv-fs.com

SHOW MORE
SHOW LESS
  • No tags were found...

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

<strong>AADvance</strong> System ArchitecturesChapter 4An <strong>AADvance</strong> controller can be configured to manage non-safety, SIL 2 or SIL 3 safetyrelated system requirements and low demand or high demand fault tolerantapplications.This chapter describes the different system architectures that can be configured for an<strong>AADvance</strong> controller to meet this variety of requirements.Note: Architectures are independent of I/O module capacity therefore 8 or 16channel I/O modules can be used.In This ChapterSIL2 Architectures .............................................................................................. 4-4SIL3 Architectures .............................................................................................. 4-4Planned Certified Configurations.................................................................... 4-4Internal Diagnostics............................................................................................ 4-4SIL2 ArchitecturesDefinitions:SIL2 Fail-safe ArchitectureSIL2 architectures are re<strong>com</strong>mended for fail-safe low demand applications. All SIL2architectures can be used for de-energize to trip applications; however, for energize toaction applications a SIL2 architecture configured with dual output modules is required.In any configuration when a faulty module is replaced within the MTTR then theprevious fault tolerance level is restored. For example in a fault tolerant inputarrangement and one module is faulty then the system will degrade to 1oo1D, byreplacing the faulty module the configuration is restored to 1oo2D.Low Demand Mode - is where the frequency of demands on the safety-related systemis no greater than twice the proof test frequency. Where the proof test frequencyrefers to how often the the safety system is <strong>com</strong>pletely tested and insured to be fullyoperational. For the <strong>AADvance</strong> System the default Proof Test Interval is 12 months.High Demand Mode - sometimes called continuous mode, is where the frequency ofdemands for operation made on a safety-related system is greater than twice the prooftest frequency.The following is a fail-safe SIL2 architecture where I/O modules operate in 1oo1Dunder no fault conditions and will fail-safe on the first detected fault. The processormodule operates in 1oo1D and will degrade to fail safe on the first detected fault.Document number 553630 Issue 7: February 2010 4-1

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!