Functional safety. Functional safety of Programmable systems, devices & components: Requirements from global & national standards

Similar documents
PL estimation acc. to EN ISO

Hydraulic (Subsea) Shuttle Valves

Bespoke Hydraulic Manifold Assembly

Pneumatic QEV. SIL Safety Manual SIL SM Compiled By : G. Elliott, Date: 8/19/2015. Innovative and Reliable Valve & Pump Solutions

FP15 Interface Valve. SIL Safety Manual. SIL SM.018 Rev 1. Compiled By : G. Elliott, Date: 30/10/2017. Innovative and Reliable Valve & Pump Solutions

Solenoid Valves For Gas Service FP02G & FP05G

Eutectic Plug Valve. SIL Safety Manual. SIL SM.015 Rev 0. Compiled By : G. Elliott, Date: 19/10/2016. Innovative and Reliable Valve & Pump Solutions

PROCESS AUTOMATION SIL. Manual Safety Integrity Level. Edition 2005 IEC 61508/61511

Safety Manual. Process pressure transmitter IPT-1* 4 20 ma/hart. Process pressure transmitter IPT-1*

Safety Manual VEGAVIB series 60

Safety Manual VEGAVIB series 60

L&T Valves Limited SAFETY INTEGRITY LEVEL (SIL) VERIFICATION FOR HIGH INTEGRITY PRESSURE PROTECTION SYSTEM (HIPPS) Report No.

Safety Manual OPTISWITCH series relay (DPDT)

Session: 14 SIL or PL? What is the difference?

SPR - Pneumatic Spool Valve

Failure Modes, Effects and Diagnostic Analysis. Rosemount Inc. Chanhassen, MN USA

Failure Modes, Effects and Diagnostic Analysis

Failure Modes, Effects and Diagnostic Analysis

High Integrity Pressure Protection Systems HIPPS

Achieving Compliance in Hardware Fault Tolerance

YT-3300 / 3301 / 3302 / 3303 / 3350 / 3400 /

Neles ValvGuard VG9000H Rev 2.0. Safety Manual

Understanding safety life cycles

DSL, DSH: Specially designed pressure limiter

New Thinking in Control Reliability

Failure Modes, Effects and Diagnostic Analysis

Functional Safety SIL Safety Instrumented Systems in the Process Industry

SIL explained. Understanding the use of valve actuators in SIL rated safety instrumented systems ACTUATION

Safety Manual VEGASWING 61, 63. NAMUR With SIL qualification. Document ID: 52084

Failure Modes, Effects and Diagnostic Analysis

Accelerometer mod. TA18-S. SIL Safety Report

Solenoid Valves used in Safety Instrumented Systems

Safety-critical systems: Basic definitions

Failure Modes, Effects and Diagnostic Analysis

CHANGE HISTORY DISTRIBUTION LIST

Transmitter mod. TR-A/V. SIL Safety Report

Vibrating Switches SITRANS LVL 200S, LVL 200E. Safety Manual. NAMUR With SIL qualification

Failure Modes, Effects and Diagnostic Analysis

Special Documentation Proline Promass 80, 83

Failure Modes, Effects and Diagnostic Analysis

Commissioning and safety manual

What safety level can be reached when combining a contactor with a circuitbreaker for fail-safe switching?

Implementing IEC Standards for Safety Instrumented Systems

Safety manual for Fisher GX Control Valve and Actuator

DeZURIK Double Block & Bleed (DBB) Knife Gate Valve Safety Manual

DeZURIK. KSV Knife Gate Valve. Safety Manual

YT-300 / 305 / 310 / 315 / 320 / 325 Series

Transducer mod. T-NC/8-API. SIL Safety Report

Valve Communication Solutions. Safety instrumented systems

RESILIENT SEATED BUTTERFLY VALVES FUNCTIONAL SAFETY MANUAL

Service & Support. Questions and Answers about the Proof Test Interval. Proof Test According to IEC FAQ August Answers for industry.

Jamesbury Pneumatic Rack and Pinion Actuator

DeZURIK. KGC Cast Knife Gate Valve. Safety Manual

Failure Modes, Effects and Diagnostic Analysis

Rosemount 2130 Level Switch

H250 M9 Supplementary instructions

SIL Safety Manual. ULTRAMAT 6 Gas Analyzer for the Determination of IR-Absorbing Gases. Supplement to instruction manual ULTRAMAT 6 and OXYMAT 6

Neles trunnion mounted ball valve Series D Rev. 2. Safety Manual

Failure Modes, Effects and Diagnostic Analysis

Ultima. X Series Gas Monitor

Failure Modes, Effects and Diagnostic Analysis. Rosemount Inc. Chanhassen, Minnesota USA

TRI LOK SAFETY MANUAL TRI LOK TRIPLE OFFSET BUTTERFLY VALVE. The High Performance Company

DSB, DSF: Pressure monitors and pressure switches

This manual provides necessary requirements for meeting the IEC or IEC functional safety standards.

THE IMPROVEMENT OF SIL CALCULATION METHODOLOGY. Jinhyung Park 1 II. THE SIL CALCULATION METHODOLOGY ON IEC61508 AND SOME ARGUMENT

Safety Integrity Verification and Validation of a High Integrity Pressure Protection System (HIPPS) to IEC 61511

Section 1: Multiple Choice Explained EXAMPLE

COMPLIANCE with IEC EN and IEC EN 61511

Partial Stroke Testing. A.F.M. Prins

DSB, DSF: Pressure monitors and pressure switches

Failure Modes, Effects, and Diagnostic Analysis of a Safety Device

Understanding the How, Why, and What of a Safety Integrity Level (SIL)

C. Mokkapati 1 A PRACTICAL RISK AND SAFETY ASSESSMENT METHODOLOGY FOR SAFETY- CRITICAL SYSTEMS

EL-O-Matic E and P Series Pneumatic Actuator SIL Safety Manual

High performance disc valves Series Type BA, BK, BW, BM, BN, BO, BE, BH Rev Safety Manual

Proof Testing A key performance indicator for designers and end users of Safety Instrumented Systems

DETERMINATION OF SAFETY REQUIREMENTS FOR SAFETY- RELATED PROTECTION AND CONTROL SYSTEMS - IEC 61508

Section 1: Multiple Choice

Failure Modes, Effects and Diagnostic Analysis

Failure Modes, Effects and Diagnostic Analysis

Reliability of Safety-Critical Systems Chapter 3. Failures and Failure Analysis

The Key Variables Needed for PFDavg Calculation

CT433 - Machine Safety

model for functional safety of

Rosemount 2120 Level Switch

Safety-critical systems: Basic definitions

Introduction to Machine Safety Standards

Failure Modes, Effects and Diagnostic Analysis

Failure Modes, Effects and Diagnostic Analysis

Why do I need dual channel safety? Pete Archer - Product Specialist June 2018

Every things under control High-Integrity Pressure Protection System (HIPPS)

Applications & Tools. Evaluation of the selection of a safetyrelated mode using non-safety-related components

SIL Safety Manual for Fisherr ED, ES, ET, EZ, HP, or HPA Valves with 657 / 667 Actuator

18-642: Safety Plan 11/1/ Philip Koopman

The Safety Case. Structure of Safety Cases Safety Argument Notation

Special Documentation Liquiphant M/S with electronic insert FEL56 + Nivotester FTL325N

A study on the relation between safety analysis process and system engineering process of train control system

Safety Critical Systems

EMERGENCY SHUT-DOWN RELIABILITY ADVANTAGE

UNDERSTANDING SAFETY INTEGRITY LEVEL

Transcription:

Functional safety Functional safety of Programmable systems, devices & components: Requirements from global & national standards Matthias R. Heinze Vice President Engineering TUV Rheinland of N.A. Email : mheinze@us.tuv.com ASI / 968-1

Overview History of standards Standards overview Comparison of different risk classes and systems Estimation of the requirements from the standards application dependent / independent Example EN 954 Main topics of IEC 61508 Basic documents for the approval Type approval and certification ASI / 968-2

Standards, history In the past: All safety related standards were application dependent result: Different safety philosophies and requirements and mainly oriented to low complex components FMEA of single component failures ASI / 968-3

Standards, history Today: Risk oriented Risk reduction general standards, application independent Technology dependent Life-cycle oriented and application or sector specific dependent ASI / 968-4

Standards to be taken in to account Risk assessment IEC 61508 ANSI B11.TR3 Functional safety of programmable electronic safety-related systems Risk and Risk reduction (Machine tools) Requirements for E/E/PES systems ( application independent / technology specific ) IEC 61508 DIN 19251 DIN V VDE 0801 A1 Application dependent requirements EN 50156 EN 60204 EN 954 EN 692 Functional safety of programmable electronic safety-related systems Control equipment, requirements and measures for safe guarded functions Principles for computers in safety related systems, including Amendment A1 Electrical equipment for furnaces Safety of machinery-electrical equipment of machines Safety of machinery-safety related parts control systems Mechanical presses-safety ANSI B11.1 Mechanical power presses-safety requirements for construction... ASI / 968-5

Current Status of IEC 61508 IEC 61508-1 General requirements final - 2 Requirements for E/E/PES final - 3 Software requirements final - 4 Definitions final - 5 Examples of methods final for the determination of SIL - 6 Guidelines on the application final of part 2 and 3-7 Overview of techniques final and measures ASI / 968-6

Risk Class - Requirement Class Safety Integrity Level - Category of Control NE 31 Risk Class DIN V 19250 Requirement class IEC 61508 Safety Integrity Level EN 954-1 Category of Control 1 - B* I 2 3 1 1 2 4 2 3 II 5 6 3 4 7 8 4 The direction of the arrows must be observed when comparing classification *)B (EN 954-1) corresponds to requirement class 1 (DIN V 19250) and vice versa ASI / 968-7

Comparison IEC 61508 / DIN 19250and VDE 0801 Sensor E / E / PES Actuator 35% 15% 50% IEC DIN / VDE Safety function Components ASI / 968-8

EN 954 Safety category 4 Category Summary of Requirements System Behaviour Principles for the Realisation of Safety The requirements of category B - When the Mainly by the and the use of well tried faults occur structure safety principles apply. the safety function is always performed. 4 Safety related parts have to The faults will be designed, that: detected in time - a single fault in any of its to prevent the parts does not lead to a loss of safety loss of safety function, and function. - the single fault is detected at or before the next demand on the safety function, or, if this detection is not possible then an accumulation of faults shall not lead to a loss of safety function. ASI / 968-9

The IEC 61508 covers for processors, devices, components range and extent of measures and techniques for the avoidance and control of faults ( HW and SW ) applied during the design and development hardware fault tolerance of systems / subsystems ( structure ) in combination with safe failure fraction and diagnostic coverage probability of failure to danger of the subsystem using reliability modelling techniques measures and techniques for avoidance and control of faults during the design and development of the application software ASI / 968-10

Integrity level according IEC 61508 Safety integrity levels: target failure measures for a safety function, allocated to an E/E/PE safety-related system operating in low demand mode of operation Safety integrity level Low demand mode of operation (Average probability of failure to perform its design function on demand) 4 10-5 to < 10-4 3 10-4 to < 10-3 2 10-3 to < 10-2 1 10-2 to < 10-1 Safety integrity levels: target failure measures for a safety function, allocated to an E/E/PE safety-related system operating in high demand or continuous mode of operation Safety integrity level High demand or continuous mode of operation (Probability of a dangerous failure per hour) 4 10-9 to < 10-8 3 10-8 to < 10-7 2 10-7 to < 10-6 1 10-6 to < 10-5 ASI / 968-11

IEC 61508 architectural constraints on low complex subsystems Safe failure fraction Hardware fault tolerance 0 1 2 < 60 % SIL 1 SIL 2 SIL 3 60 % - 90 % SIL 2 SIL 3 SIL 4 90 % - 99 % SIL 3 SIL 4 SIL 4 99 % SIL 3 SIL 4 SIL 4 ASI / 968-12

IEC 61508 architectural constraints on complex subsystems Safe failure fraction Hardware fault tolerance 0 1 2 < 60 % Not allowed SIL 1 SIL 2 60 % - 90 % SIL 1 SIL 2 SIL 3 90 % - 99 % SIL 2 SIL 3 SIL 4 99 % SIL 3 SIL 4 SIL 4 ASI / 968-13

Safe failure fraction The safe failure fraction of a subsystem is defined as (Σλ S + Σλ DD ) / (Σλ S + Σλ D ), λ S λ D λ DD is safe failure is dangerous failure is dangerous failure detected by the internal diagnostic ASI / 968-14

Example PFD calculation SAFETY LOOP Typically pre-certified Sensor Input Module CPU board Output Module Actuator ~30% OF PFH ~50% OF PFH PED 10-20% OF PFH OF SAFETY LOOP ASI / 968-15

Example PFD calculation SAFETY INTEGRITY LEVELS TARGET FAILURE MEASURES FOR A SAFETY FUNCTION TABLE 3 IEC 61508-1 SIL HIGH DEMAND OR CONTINUOUS MODE OF OPERATION (PROBILITY OF A DANGEROUS FAILURE PER HOUR) 4 > 1.00E-09 TO < 1.00E-08 3 > 1.00E-08 TO < 1.00E-07 2 > 1.00E-07 TO < 1.00E-06 1 > 1.00E-06 TO < 1.00E-05 PED IS EQUAL TO 10% OF THE TOTAL SAFETY LOOP 1.00E-07 > λ(sl) > 1.00E-08 1.00E-08 > λ(ped) > 1.00E-09 ASI / 968-16

Example PFD calculation λ(ped) = 2((1-β)λ(DD) + (1-β)λ(DU))^2 x t(de) + βλ(dd) +βλ(du) λ(ped) = 1.77E-09 TERM UNITS DEFINITION λ(t) FAILURES PER HOUR SUM OF AVERAGE PROBABILITY OF FAILURES OF THE SYSTEM COMPONENTS λ(s) FAILURES PER HOUR PROBABILITY OF DETECTED SAFE FAILURE λ(d) FAILURES PER HOUR PROBABILITY OF DANGEROUS FAILURES λ(dd) FAILURES PER HOUR PROBABILITY OF DANGEROUS DETECTED FAILURES λ(du) FAILURES PER HOUR PROBABILITY OF DANGEROUS UNDETECTED FAILURES λ(ped) FAILURES PER HOUR PROBABILITY OF PED FAILURES t(de) HOURS DEVICE EQ. MEAN DOWN TIME MTBF HOURS MEAN TIME BETWEEN FAILURES β PERCENTAGE FRACTION OF FAILURES HAVING A COMMON CAUSE ASI / 968-17

Requirements For all subsystems the following requirements have to be fulfilled: measures to avoid and control failures ( HW/SW ) especially systematic faults architectural requirements ( SFF and HFT ) probability of failure to danger application dependent requirements ASI / 968-18

Development Accompanying Inspection and Certification Phase Phase 1 1 Concept Review Concept Review Validated Validated and and Authorised Authorised Requirement Requirement Specification Specification Phase Phase 2 2 Main Inspection Main Inspection Extensive Extensive Safety Safety Technical Technical Inspection Inspection and and Report Report Phase Phase 3 3 Certification Certification Certification Certification of of the the Inspected Inspected Devices Devices ASI / 968-19

Assessment Overview Functional safety including HW/SW/mechanical Electrical safety Environmental conditions, EMC Quality management during the life-cycle of the equipment FMEA (system level, sub-system, component) Failure detection and reaction (internal self-tests) Estimation / demonstration of proven in use Verification / Calculation of PFD, SFF figures Software approval ASI / 968-20