12.07.2015 Views

HIMax Safety Manual - Tuv-fs.com

HIMax Safety Manual - Tuv-fs.com

HIMax Safety Manual - Tuv-fs.com

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

<strong>HIMax</strong>3 <strong>Safety</strong> Concept for Using the PES3.2.3 <strong>Safety</strong> Time (of PES)The safety time is the maximum permissible time within which the PES must react to asafety requirement event. <strong>Safety</strong> requirement events include:• Changes in input signals from process• Faults occurring in the controllerIn <strong>HIMax</strong> controllers, the safety time can be set anywhere between 20 ms and 100 000 ms.Within the safety time of the controller, the self-test facilities detect whether there are anypotentially dangerous faults. They trigger predefined fault reactions that set the faulty<strong>com</strong>ponents to a safe state.When determining the safety time, the effects of the following factors must be taken intoaccount:• With input modules, consider the following:Time-on/time-off delay settings for input channels:enter maximum delay time setting in μs + 4 ms• Noise blanking also needs time reserves.Choose a safety time that is long enough to account for the most significant factormentioned above, but still lower than the FTT of the process. It is important not to neglectthe sensor and actuator time parameters for the safety function.The safety time for the controller is:<strong>Safety</strong> time = 2 * watchdog time + reserve XIn the actual application, the user should measure reserve X by replacing a redundantprocessor module. Enter the average cycle time determined for the entire system as thereserve X into the above formula. This ensures maximum availability for the system.3.2.4 Response TimeAssuming that no delay results from the configuration or the user program logic, theresponse time of <strong>HIMax</strong> controllers running in cycles is twice the system cycle time.The cycle time of the controller consists of the following main <strong>com</strong>ponents:• Input processing- Processing input data on input module- Reading process data from <strong>com</strong>munication interfaces- Reading process data from input modules• Processing user program logic• Output processing- Writing process data to output modules- Writing process data to <strong>com</strong>munication interfaces- Processing output data on output modules• Additional processing of final actions for reloading, additional processor modules, etc.3.3 Proof TestA proof test is a periodic test performed to detect any hidden faults in a safety-relatedsystem so that, if necessary, the system can be restored to a state where it can perform itsintended functionality.HIMA safety systems must be subjected to a proof test in intervals of 10 years. It is oftenpossible to extend this interval using the SILence calculation tool from HIMA to analyze theimplemented safety loops.HI 801 003 D Rev.2.0 Page 19 of 70

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!