Safety Considerations Guide for Trident v2 Systems - TUV ...

Safety Considerations Guide for Trident v2 Systems - TUV ... Safety Considerations Guide for Trident v2 Systems - TUV ...

23.12.2012 Views

20 Chapter 2 Application Guidelines Safety Measure Description Protects Against Redundancy with Cross-Checking Different Data Integrity Assurance Systems • PID and other control algorithms should not be used for safety-related functions. Each control function should be checked to verify that it does not provide a safety-related function. • Pointers should not be used for safety-related functions. For TriStation 1131 applications, this includes the use of VAR_IN_OUT variables. • An SIS PES should be wired and grounded according to the procedures defined by the manufacturer. Safety Considerations Guide for Trident v2 Systems In safety-related Fieldbus applications, the safety data may be sent twice, within one or two seperate messages, using identical or different integrity measures independent from the underlying Fieldbus. In addition, the transmitted safety data is cross-checked for validity over the Fieldbus, or over a seperate connection source or sink unit. If a difference is detected, an error has taken place: • during transmission • in the processing unit of the source • in the processing unit of the sink When redundant media are used, common mode protection using suitable measures (for example, diversity and time-skewed transmission) should be considered. If safety-relevant and non-safetyrelevant data are transmitted via the same bus, different data integrity assurance systems or encoding principles may be used (for example, different hash functions or different CRC generator polynomials and algorithms), to ensure that non-safetyrelevant messages cannot influence any safety function in a safety-relevant receiver. • Corruption (only for serial busses, and only comparable with a high-quality data assurance mechanism if a calculation can show that the residual error rate reaches the values required when two messages are sent through independent tranceivers) • Unintended Repetition • Incorrect Sequence •Loss • Insertion Masquerade

Emergency Shutdown Systems The safe state of the plant should be a de-energized or low (0) state. All power supplies should be monitored for proper operation. Burner Management Systems The safe state of the plant is a de-energized or low (0) state. General Guidelines 21 When a safety system is required to conform to the EN 50156 standard for electrical equipment for furnaces, PES throughput time should ensure that a safe shutdown can be performed within one second after a problem in the process is detected. Fire and Gas Systems Fire and gas applications should operate continuously to provide protection. The following industry guidelines apply: • If inputs and outputs are energized to mitigate a problem, a PES system should detect and alarm open and short circuits in the wiring between the PES and the field devices. • An entire PES system should have redundant power supplies. Also, the power supplies that are required to activate critical outputs and read safety-critical inputs should be redundant. All power supplies should be monitored for proper operation. • De-energized outputs may be used for normal operation. To initiate action to mitigate a problem, the outputs are energized. This type of system shall monitor the critical output circuits to ensure that they are properly connected to the end devices. Safety Considerations Guide for Trident v2 Systems

20 Chapter 2 Application <strong>Guide</strong>lines<br />

<strong>Safety</strong> Measure Description Protects Against<br />

Redundancy with<br />

Cross-Checking<br />

Different Data<br />

Integrity Assurance<br />

<strong>Systems</strong><br />

• PID and other control algorithms should not be used <strong>for</strong> safety-related functions. Each<br />

control function should be checked to verify that it does not provide a safety-related<br />

function.<br />

• Pointers should not be used <strong>for</strong> safety-related functions. For TriStation 1131<br />

applications, this includes the use of VAR_IN_OUT variables.<br />

• An SIS PES should be wired and grounded according to the procedures defined by the<br />

manufacturer.<br />

<strong>Safety</strong> <strong>Considerations</strong> <strong>Guide</strong> <strong>for</strong> <strong>Trident</strong> <strong>v2</strong> <strong>Systems</strong><br />

In safety-related Fieldbus applications,<br />

the safety data may be sent twice, within<br />

one or two seperate messages, using<br />

identical or different integrity measures<br />

independent from the underlying<br />

Fieldbus. In addition, the transmitted<br />

safety data is cross-checked <strong>for</strong> validity<br />

over the Fieldbus, or over a seperate<br />

connection source or sink unit. If a<br />

difference is detected, an error has taken<br />

place:<br />

• during transmission<br />

• in the processing unit of the source<br />

• in the processing unit of the sink<br />

When redundant media are used,<br />

common mode protection using suitable<br />

measures (<strong>for</strong> example, diversity and<br />

time-skewed transmission) should be<br />

considered.<br />

If safety-relevant and non-safetyrelevant<br />

data are transmitted via the<br />

same bus, different data integrity<br />

assurance systems or encoding<br />

principles may be used (<strong>for</strong> example,<br />

different hash functions or different<br />

CRC generator polynomials and<br />

algorithms), to ensure that non-safetyrelevant<br />

messages cannot influence any<br />

safety function in a safety-relevant<br />

receiver.<br />

• Corruption (only <strong>for</strong><br />

serial busses, and<br />

only comparable with<br />

a high-quality data<br />

assurance mechanism<br />

if a calculation can<br />

show that the residual<br />

error rate reaches the<br />

values required when<br />

two messages are sent<br />

through independent<br />

tranceivers)<br />

• Unintended<br />

Repetition<br />

• Incorrect Sequence<br />

•Loss<br />

• Insertion<br />

Masquerade

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!