13.07.2015 Views

Safety Considerations Guide, Tricon v9.0 - Tuv-fs.com

Safety Considerations Guide, Tricon v9.0 - Tuv-fs.com

Safety Considerations Guide, Tricon v9.0 - Tuv-fs.com

SHOW MORE
SHOW LESS
  • No tags were found...

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Sample <strong>Safety</strong>-Shutdown Programs 55Sample <strong>Safety</strong>-Shutdown ProgramsThe following section describes sample programs and methods for implementingsafety-shutdown networks.All I/O Modules <strong>Safety</strong>-CriticalThe sample program, PROGRAM EX01_SHUTDOWN, shows one way to verifythat the safety system is operating properly when every module in the safety systemis safety-critical. The example uses an instance of the <strong>Tricon</strong>ex Library functionblock TR_SHUTDOWN named CRITICAL_MODULES. (The sample program isan element of project ExTUV.pt2 found on the TriStation CD. The default locationof the project is C:\Program Files\<strong>Tricon</strong>ex\TS1131\_<strong>Tricon</strong>\Examples.)When the output CRITICAL_MODULES_OPERATING is true, all safety-criticalmodules are operating properly. The input MAX_TIME_DUAL specifies themaximum time allowed with two channels operating (with no connection defaultsto 40000 days). The input MAX_TIME_SINGLE specifies the maximum timeallowed with one channel operating (3 days in the example).Note In typical applications, continued operation in dual mode is restricted to1500 hours (two months).Continued operation in single mode is restricted to 72 hours for SIL/AK5 and onehour for SIL/AK6 guidelines.When CRITICAL_MODULES_OPERATING is false, the time in degradedoperation exceeds the specified limits; therefore, the control program should shutdown the process under safety control.! CAUTIONThe sample program called EX01_SHUTDOWN does not handle detected fieldfaults, rare <strong>com</strong>binations of faults detected as field faults, or output voter faultshidden by field faults. The application program, not the TR_SHUTDOWNfunction block, must read the NO_FLD_FLTS module status or FLD_OK pointstatus to provide the required application-specific action.For information on improving availability using external, power-disconnect relaysand advanced programming techniques, see the sample program calledEX02_SHUTDOWN.Chapter 4Application Development

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!