23.12.2012 Views

Safety Considerations Guide for Trident v2 Systems - TUV ...

Safety Considerations Guide for Trident v2 Systems - TUV ...

Safety Considerations Guide for Trident v2 Systems - TUV ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

56 Chapter 4 Application Development<br />

Table 12 Input Parameters <strong>for</strong> SYS_SHUTDOWN Function Block in EX02_SHUTDOWN<br />

Parameter Description<br />

CI Control In<br />

If false, then CO is false—no change in the output value<br />

If true and ERROR_NUM is 0, then CO is true<br />

IO_CO Critical I/O control out<br />

IO_TMR All critical I/O points are operating in triple modular<br />

redundant mode<br />

IO_GE_DUAL All critical I/O points are operating are operating in dual or<br />

TMR mode<br />

IO_GE_SINGLE All critical I/O points are operating are operating in single,<br />

dual, or TMR mode<br />

IO_NO_VOTER_FLTS If true, then no voter faults exist on a critical I/O module<br />

If false, then a voter fault exists on a critical I/O module<br />

IO_ERROR Error number: Zero indicates no error. Non-zero indicates a<br />

programming or configuration error<br />

MAX_TIME_DUAL Maximum time with only two channels operating<br />

MAX_TIME_SINGLE Maximum time with only one channel operating<br />

MAX_SCAN_TIME 50% of the maximum response time<br />

Table 13 Output Parameters <strong>for</strong> SYS_SHUTDOWN Function Block in EX02_SHUTDOWN<br />

Parameter Description<br />

CO Control Out<br />

OPERATING When true, all safety-critical modules are<br />

operating properly<br />

When false, the time in degraded operation<br />

exceeds the specified limits; there<strong>for</strong>e, the<br />

control program should shut down the process<br />

TMR System is operating in triple modular redundant<br />

mode<br />

DUAL At least one safety-critical point is controlled by<br />

two channels<br />

SINGL At least one safety-critical point is controlled by<br />

one channel<br />

ZERO At least one safety-critical point is not controlled<br />

by any channel<br />

TIMER_RUNNING Time left to shutdown is decreasing<br />

TIME_LEFT Time remaining be<strong>for</strong>e shutdown<br />

ALARM_PROGRAMMING_PERMITTED True if application changes are permitted<br />

<strong>Safety</strong> <strong>Considerations</strong> <strong>Guide</strong> <strong>for</strong> <strong>Trident</strong> <strong>v2</strong> <strong>Systems</strong>

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!