12.07.2015 Views

HIMax Safety Manual - Tuv-fs.com

HIMax Safety Manual - Tuv-fs.com

HIMax Safety Manual - Tuv-fs.com

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

<strong>HIMax</strong>9 Software• Compiling the program twice and <strong>com</strong>paring the two CRC checksums ensures that datacorruption in the application is detected that can result from random faults in the PC inuse.When starting up a safety-related controller for the first time, a <strong>com</strong>prehensive function testto verify the safety of the entire system must be performed.Function Test of the Controller1 Verify that the tasks to be performed by the controller were properly implemented usingthe data and signal flows.2. Perform a <strong>com</strong>prehensive function test of the logic by trial (see Testing the configurationand the appl.).The controller and the application are sufficiently tested.If a user program is modified, only the program <strong>com</strong>ponents affected by the change mustbe tested. To do this, the safe revision <strong>com</strong>parator in SILworX can be used to determineand display all changes relative to the previous version.9.3.2 Verifying the Configuration and the User ProgramTo verify that the user program created performs the required safety function, the user mustcreate suitable test cases for the required system specification.An independent test of each loop (consisting of input, the key interconnections in theapplication and output) is usually sufficient.Suitable test cases must also be created for the numerical evaluation of formulas.Equivalence class tests are reasonable . These are tests within defined ranges of values, atthe limits of or within invalid ranges of values. The test cases must be selected such thatthe calculations can be proven to be correct. The required number of test cases dependson the formula used and must include critical value pairs.HIMA rec<strong>com</strong>mends not to do without performing an active simulation with data sources,since this is the only way to prove that the sensors and actuators in the system (also thoseconnected to the system via <strong>com</strong>munication with remote I/Os) are properly wired. This isalso the only way to verify the system configuration.This procedure must be followed both when initially creating and when modifying the userprogram.HI 801 003 D Rev.2.0 Page 47 of 70

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!