8536IB1904EN-03 SCHNEIDER | Alldatasheet
Document overview
- PDF pages: 72
Technical content
T eSys™ island – Digital Motor Management Solution Functional Safety Guide T eSys of fers innovative and connected solutions for motor starters. 8536IB1904EN-03 www .schneider-electric.com
The Schneider Electric brand and any trademarks of Schneider Electric SE and its subsidiaries referred to in this guide are the property of Schneider Electric SE or its subsidiaries. All other brands may be trademarks of their respective owners. This guide and its content are protected under applicable copyright laws and furnished for informational use only . No part of this guide may be reproduced or transmitted in any form or by any means (electronic, mechanical, photocopying, recording, or otherwise), for any purpose, without the prior written permission of Schneider Electric. Schneider Electric does not grant any right or license for commercial use of the guide or its content, except for a non-exclusive and personal license to consult it on an "as is" basis. Schneider Electric products and equipment should be installed, operated, serviced, and maintained only by qualified personnel. As standards, specifications, and designs change from time to time, information contained in this guide may be subject to change without notice. T o the extent permitted by applicable law , no responsibility or liability is assumed by Schneider Electric and its subsidiaries for any errors or omissions in the informational content of this material or consequences arising out of or resulting from the use of the information contained herein. Schneider Electric, Preventa, and T eSys are trademarks and the property of Schneider Electric SE, its subsidiaries, and aff iliated companies. All other trademarks are the property of their respective owners.
T eSys™ island – Digital Motor Management Solution T able of Contents Wiring Categories 8536IB1904EN-03 3
T eSys™ island – Digital Motor Management Solution 4 8536IB1904EN-03
Safety Information T eSys™ island – Digital Motor Management Solution Safety Information Important Information Read these instructions carefully , and look at the equipment to become familiar with the device before trying to install, operate, service, or maintain it. The following special messages may appear throughout this documentation or on the equipment to warn of potential hazards or to call attention to information that clarifies or simplifies a procedure. Please Note Electrical equipment should be installed, operated, serviced, and maintained only by qualified personnel. No responsibility is assumed by Schneider Electric for any consequences arising out of the use of this material. A qualified person is one who has skills and knowledge related to the construction and operation of electrical equipment and its installation, and has received safety training to recognize and avoid the hazards involved. The addition of this symbol to a “Danger” or “W arning” safety label indicates that an electrical hazard exists which will result in personal injury if the instructions are not followed. This is the safety alert symbol. It is used to alert you to potential personal injury hazards. Obey all safety messages that follow this symbol to avoid possible injury or death. DANGER indicates a hazardous situation which, if not avoided, will result in death or serious injury DANGER W ARNING indicates a hazardous situation which, if not avoided, could result in death or serious injury W ARNING CAUTION indicates a hazardous situation which, if not avoided, could result in minor or moderate injury CAUTION NOTICE is used to address practices not related to physical injury NOTICE 8536IB1904EN-03 5
T eSys™ island – Digital Motor Management Solution About the Book About the Book Document Scope Use this document to learn more about the following T eSys™ island functional safety features:
- general understanding
- key aspects to consider
- performances
- hardware description
- typical configurations
- sample architectures
- standards references V alidity Note This guide is valid for all T eSys island configurations. The availability of some functions described in this guide depends on the communication protocol used and the physical modules installed on the island. For product compliance with environmental directives such as RoHS, REACH, PEP , and EOLI, go to www .se.com/green-premium. For technical characteristics of the physical modules described in this guide, go to www .se.com. The technical characteristics presented in this guide should be the same as those that appear online. We may revise content over time to improve clarity and accuracy . If you see a diff erence between the information contained in this guide and online information, use the online information. 6 8536IB1904EN-03
About the Book T eSys™ island – Digital Motor Management Solution Related Documentation Document title Description Document number T eSys island – System Guide Introduces and describes the main functions of T eSys island 8536IB1901 T eSys island – Installation Guide Describes the mechanical installation, wiring, and commissioning of T eSys island 8536IB1902 T eSys island – Operating Guide Describes how to operate and maintain T eSys island 8536IB1903 T eSys island – Functional Safety Guide Describes the Functional Safety features of T eSys island 8536IB1904 T eSys island – Third Party Function Block Guide Contains the information needed to create function blocks for third party hardware 8536IB1905 T eSys island – EtherNet/IP™ Function Block Library Guide Describes the T eSys island library used in the Rockwell Software Studio 5000 EtherNet/IP environment 8536IB1914 T eSys island – EtherNet/IP™ Quick Start Guide Describes how to quickly integrate T eSys island into the Rockwell Software Studio 5000 EtherNet/IP environment 8536IB1906 T eSys island – DTM Online Help Guide Describes how to install and use various functions of T eSys island configuration software and how to configure the parameters of T eSys island 8536IB1907 T eSys island – PROFINET and PROFIBUS Function Block Library Guide Describes the T eSys island library used in the Siemens™ TIA Portal environment 8536IB1917 T eSys island – Quick Start Guide for PROFINET and PROFIBUS Applications Describes how to quickly integrate T eSys island into the Siemens™ TIA Portal environment 8536IB1916 T eSys island – Product Environmental Profile Describes constituent materials, recyclability potential, and environmental impact information for the T eSys island ENVPEP1904009 T eSys island – Product End of Life Instructions Contains end of life instructions for the T eSys island ENVEOLI1904009 T eSys island – Instruction Sheet, Bus Coupler , TPRBCEIP Describes how to install the T eSys island Ethernet/IP bus coupler MFR44097 T eSys island – Instruction Sheet, Bus Coupler , TPRBCPFN Describes how to install the T eSys island PROFINET bus coupler MFR44098 T eSys island – Instruction Sheet, Bus Coupler , TPRBCPFB Describes how to install the T eSys island PROFIBUS DP bus coupler GDE55148 T eSys island – Instruction Sheet, Starters and Power Interface Modules, Size 1 and 2 Describes how to install size 1 and 2 T eSys island starters and power interface modules MFR77070 T eSys island – Instruction Sheet, Starters and Power Interface Modules, Size 3 Describes how to install size 3 T eSys island starters and power interface modules MFR77085 T eSys island – Instruction Sheet: Input/Output Modules Describes how to install the T eSys island analog and digital I/O modules MFR44099 T eSys island – Instruction Sheet: SIL Interface and V oltage Interface Modules Describes how to install the T eSys island voltage interface modules and SIL interface modules MFR44100 8536IB1904EN-03 7 1. Safety Integrity Level according to standard IEC 61508.
T eSys™ island – Digital Motor Management Solution About the Book T erminology Derived from Standards The technical terms, terminology , and the corresponding descriptions in this guide normally use the terms or definitions in the relevant standards. Among others, these standards include:
- EN ISO 13849-1: Safety of machinery – Safety-related parts of control systems – Part 1: General principles for design
- EN ISO 13849-2: Safety of machinery – Safety-related parts of control systems – Part 2: V alidation
- IEC 61508: Functional safety of Electrical / Electronic / Programmable Electronic safety-related systems
- EN 62061: Safety of machinery – Functional safety of safety-related electrical, electronic and programmable electronic control systems
- IEC 6151 1: Functional safety – Safety instrumented systems for the process industry sector
- EN/IEC 60204-1: Safety of machinery – Electrical equipment of machines – Part 1: General requirements
- IEC 61000-6-7: Electromagnetic compatibility (EMC) – Part 6-7: Generic standards – Immunity requirements for equipment intended to perform functions in a safety-related system (functional safety) in industrial locations
- IEC 60664-5: Insulation coordination for equipment within low-voltage systems – Part 5: Comprehensive method for determining clearances and creepage distances equal to or less than 2 mm
- IEC 60947-4-1: Low-voltage switchgear and control gear – Part 4-1: Contactors and motor-starters – Electromechanical contactors and motor- starters
- IEC 60947-5-1: Low-voltage switchgear and control gear – Part 5-1: Control circuit devices and switching elements – Electromechanical control circuit devices
- IEC 60947-7-1: Low-voltage switchgear and control gear – Part 7-1: Ancillary equipment – T erminal blocks for copper conductors
- IEC 60947-7-2: Low-voltage switchgear and control gear – Part 7-2: Ancillary equipment – Protective conductor terminal blocks for copper conductors
- EN 50205: Relays with forcibly guided (mechanically linked) contacts
- IEC TR 62380: Reliability data handbook – Universal model for reliability prediction of electronics components, PCBs and equipment 8 8536IB1904EN-03
About the Book T eSys™ island – Digital Motor Management Solution Functional Safety T erminology ATTENTION The functional safety terminology used in this guide is defined below . T erm Standard Definition Fault T olerance IEC 6151 1-1 Ability of a functional item to continue to perform a required function in the presence of faults or errors Functional Safety IEC 61508-4 Part of the overall safety relating to the Equipment Under Control (EUC) and the EUC control system that depends on the correct functioning of the Electrical/Electronic/ Programmable Electronic (E/E/PE) safety-related systems and other risk reduction measures Safe Failure IEC 61508–4 Failure of an element and/or subsystem and/or system that plays a part in implementing the safety function that: 1. results in the spurious operation of the safety function to put the EUC (or part thereof) into a safe state or maintain a safe state; or 2. increases the probability of the spurious operation of the safety function to put the EUC (or part thereof) into a safe state or maintain a safe state. Safe Failure Fraction IEC 61508–4 The ratio of the rate of safe failures to the total failure rate of the system. Safe State IEC 6151 1-1 State of the process when safety is achieved IEC 61800-5-2 State of the PDS(SR) when safety is achieved Safe Stop IEC 61800-5-2 The Safe Stop functions are defined as:
- Safe T orque Off (STO) ◦ This function prevents force-producing power from being provided to the motor . ◦ This safety sub-function corresponds to an uncontrolled stop in accordance with stop category 0 of IEC 60204-1.
- Safe Stop 1 (SS1) ◦ Safe Stop 1 deceleration controlled: SS1-d initiates and controls the motor deceleration rate within selected limits to stop the motor and performs the STO function (see 4.2.3.2) when the motor speed is below a specified limit; or ◦ Safe Stop 1 ramp monitored: SS1-r initiates and monitors the motor deceleration rate within selected limits to stop the motor and performs the STO function when the motor speed is below a specified limit; or ◦ Safe Stop 1 time controlled SS1-t initiates the motor deceleration and performs the STO function after an application specific time delay . Safety Function IEC 61800-5-2 Function to be implemented by a safety-related system or other risk reduction measures, that is intended to achieve or maintain a safe state for the equipment or machinery driven by the PDS(SR) , in respect of a specific hazardous event Safety Integrity Level (SIL) IEC 61508 The standard IEC 61508 defines four Safety Integrity Levels (SILs) for safety functions: SIL 1 is the lowest integrity level and SIL 4 is the highest. A hazard analysis and risk assessment serves as a basis for determining the required safety integrity level. 8536IB1904EN-03 9 2. EUC: Equipment under control 3. Safety related power drive systems
T eSys™ island – Digital Motor Management Solution About the Book T erm Standard Definition Safety Related System IEC 61800-5-2 Designated system that both
- implements the required safety functions necessary to achieve or maintain a safe state for the equipment or machinery driven by the PDS (SR) ; and
- is intended to achieve, on its own or with other risk reduction measures, the necessary safety integrity for the required safety functions Subsystem IEC 61800-5-2 Part of the top-level architectural design of a safety- related system, failure of which results in failure of a safety-related function EC Declaration of Conformity The EC Declarations of Conformity for T eSys™ island can be obtained on www . schneider-electric.com. 10 8536IB1904EN-03 4. Safety related power drive systems
Precautions T eSys™ island – Digital Motor Management Solution Precautions Read and understand the following precautions before performing any procedures in this guide. DANGER HAZARD OF ELECTRIC SHOCK, EXPLOSION, OR ARC FLASH
- This equipment must only be installed and serviced by qualified electrical personnel.
- T urn of f all power supplying this equipment before working on or inside this equipment.
- Use only the specified voltage when operating this equipment and any associated products.
- Always use a properly rated voltage sensing device to confirm power is of f.
- Use appropriate interlocks where personnel and/or equipment hazards exist.
- Power line circuits must be wired and protected in compliance with local and national regulatory requirements.
- Apply appropriate personal protective equipment (PPE) and follow safe electrical work practices per NFP A 70E, NOM-029-STPS, or CSA Z462 or local equivalent. Failure to follow these instructions will result in death or serious injury . W ARNING UNINTENDED EQUIPMENT OPERA TION
- For complete instructions about functional safety , refer to the T eSys™ island Functional Safety Guide, 8536IB1904.
- Do not disassemble, repair , or modify this equipment. There are no user serviceable parts.
- Install and operate this equipment in an enclosure appropriately rated for its intended application environment.
- Each implementation of this equipment must be individually and thoroughly tested for proper operation before being placed into service. Failure to follow these instructions can result in death, serious injury , or equipment damage. W ARNING: This product can expose you to chemicals including Antimony oxide (Antimony trioxide), which is known to the State of California to cause cancer . For more information go to www .P65W arnings.ca.gov. 8536IB1904EN-03 1 1
T eSys™ island – Digital Motor Management Solution Precautions Qualified Personnel Only appropriately trained persons who are familiar with and understand the content of this guide and all other related product documentation are authorized to work on and with this product. The qualified person must be able to detect possible hazards that may arise from modifying parameter values and generally from mechanical, electrical, or electronic equipment. The qualified person must be familiar with the standards, provisions, and regulations for the prevention of industrial accidents, which they must observe when designing and implementing the system. The use and application of the information contained in this guide requires expertise in the design and programming of automated control systems. Only you, the user , the machine builder , or the integrator , can be aware of all the conditions and factors present during installation, setup, operation, and maintenance of the machine or process, and can therefore determine the automation and associated equipment and the related safeties and interlocks which can be eff ectively and properly used. When selecting automation and control equipment (and any other related equipment or software) for a particular application, you must also consider applicable local, regional, or national standards and/or regulations. Pay particular attention to adhere to any safety information, electrical requirements, and normative standards that apply to your machine or process in the use of this equipment. Intended Use The products described in this guide, together with software, accessories, and options, are starters for low-voltage electrical loads, intended for industrial use according to the instructions, directions, examples, and safety information contained in this document and other supporting documentation. The product may only be used in compliance with all applicable safety regulations and directives, the specified requirements, and the technical data. Before using the product, you must perform a hazard analysis and risk assessment of the planned application. Based on the results, appropriate safety- related measures must be implemented. Since the product is used as a component of a machine or process, you must ensure the safety of persons by means of the overall system design. Operate the product only with the specified cables and accessories. Use only genuine accessories and spare parts. Any use other than the use explicitly permitted is prohibited and can result in unanticipated hazards. 12 8536IB1904EN-03
T eSys™ island Functional Safety Overview T eSys™ island – Digital Motor Management Solution T eSys™ island Functional Safety Overview Master Range: T eSys T eSys™ is an innovative motor control and management solution from the global market leader . T eSys of fers connected, efficie nt products and solutions for switching and protection of motors and electrical loads in compliance with all major global electrical standards. T eSys island Concept T eSys island is a modular , multifunctional system providing integrated functions inside an automation architecture, primarily for the direct control and management of low-voltage loads. T eSys island can switch, help protect, and manage motors and other electrical loads up to 80 A (AC1) installed in an electrical control panel. This system is designed around the concept of T eSys avatars. These avatars:
- Represent both the logical and physical aspects of the automation functions
- Determine the configuration of the island The logical aspects of the island are managed with software tools, covering all phases of product and application lifecycle: design, engineering, commissioning, operation, and maintenance. The physical island consists of a set of devices installed on a single DIN rail and connected together with flat cables providing the internal communication between modules. The external communication with the automation environment is made through a single bus coupler module, and the island is seen as a single node on the network. The other modules include starters, power interface modules, analog and digital I/O modules, voltage interface modules, and SIL (Safety Integrity Level according to standard IEC 61508) interface modules, covering a wide range of operational functions. 8536IB1904EN-03 13
T eSys™ island – Digital Motor Management Solution T eSys™ island Functional Safety Overview Figure 1 - T eSys island Overview H D E F E F G B A C A Bus Coupler E Power Interface Module B Analog I/O Module F Standard Starter C Digital I/O Module G SIL Starter D V oltage Interface Module H SIL Interface Module Functional Safety in T eSys island T eSys™ island provides specific avatars and physical devices to build configurations for Stop Category 0 and Stop Category 1 functions according to EN/IEC 60204-1. T eSys avatars are digital representations of the physical modules on the island, however , the T eSys island safety function relies only on electro-mechanical hardware components. The specific devices are the SIL starter and SIL interface module. Another important concept is the SIL group: a set of avatars that are associated to one SIL interface module and follow the same safety function. Multiple SIL groups are possible within an island. T eSys island must be integrated with other safety-related elements in a broader safety-related system to help ensure the functional safety of a machine or a system/process. 14 8536IB1904EN-03 5. Safety Integrity Level according to standard IEC 61508.
T eSys™ island Functional Safety Overview T eSys™ island – Digital Motor Management Solution T eSys island Functional Safety Characteristics T eSys™ island provides Functional Safety features in compliance with these specific conditions:
- Standards and Certified Characteristics, page 15
- Operating Conditions, page 16
- Single-Channel Architecture (ISO 13849), page 16
- Dual-Channel Architecture (ISO 13849), page 16
- Stop Categories (EN/IEC 60204-1), page 16
- Wiring Categories (ISO 13849), page 17
- Acceptance T est, page 18 Standards and Certified Characteristics T eSys island follows these directives and standards:
- Machinery Directive 2006/42/CE: ◦ EN ISO 13849-1: 2015 ◦ EN 62061: 2016 or IEC 62061: 2015 (edition 1.2)
- Functional safety of electrical/electronic/programmable electronic safety- related systems: IEC 61508 edition 2: 2010
- Functional safety – Safety instrumented systems for the process industry sector: IEC 6151 1 edition 2: 2016
- T eSys island Stop Category 0 and Stop Category 1 functions follow EN/IEC 60204-1. In single channel, the highest performances for those functions are:
- Performance Level “d” Category 2 in compliance with EN ISO 13849-1
- SIL 2 capability in compliance with IEC 61508 Ed 2 and IEC 6151 1 Ed 2
- SIL CL 2 capability in compliance with EN 62061 Ed 1 In dual channel, the highest performances for those functions are:
- Performance Level “e” Category 4 in compliance with EN ISO 13849-1
- SIL 3 capability in compliance with IEC 61508 Ed 2 and IEC 6151 1 Ed 2
- SIL CL 3 capability in compliance with EN 62061: 2016 or IEC 62061: 2015 (edition 1.2) T eSys island is designed to support different functional safety performance levels and safety integrity levels depending on its wiring architecture, and is compliant with the functional safety characteristics described in the following table. T able 1 - Functional Safety Characteristics Function Safety-related stop function Fallback position Open contactor Response time (worst case) 145 ms Stop Category EN/IEC 60204-1 Cat. 0 / Cat. 1 Machinery Directive Y es T eSys island system architecture Single channel Dual channel Performance Level EN ISO 13849-1 PL c, d PL c, d, e Wiring Category ISO 13849-1 Cat 1, 2 Cat 3, 4 8536IB1904EN-03 15 6. Safety Integrity Level according to standard IEC 61508.
T eSys™ island – Digital Motor Management Solution T eSys™ island Functional Safety Overview T able 1 - Functional Safety Characteristics (Continued) SIL CL EN 62061 SIL CL 2 SIL CL 3 SIL IEC 61508 / IEC 6151 1 SIL 2 SIL 3 The certificate for functional safety is accessible on www .se.com/tesys/. NOTE: For certification relating to functional aspects, only a T eSys island suitable for use in safety-related applications will be considered, not the complete system into which it is integrated to help to ensure the functional safety of a machine or a system/process. Operating Conditions T eSys island is designed to durably sustain the following conditions. Other conditions may apply to specific modules as described in their data sheet document, available on www .se.com/tesys-island.
- 40 °C (104 °F) ambient temperature
- 400/480 V motor
- 50% humidity
- 80% load
- Horizontal mounting orientation
- All inputs activated
- All outputs activated
- 24 hours/day , 365 days/year run time Single-Channel Architecture (ISO 13849) T eSys island is applicable to single-channel architectures in which a detected fault can lead to the loss of the safety function. Dual-Channel Architecture (ISO 13849) T eSys island is applicable to dual-channel architectures in which a single detected fault (including common-mode faults) does not lead to the loss of the safety function. Stop Categories (EN/IEC 60204-1) The stop category relates to the way the driven load is de-energized and depends on the external safety-related sub-system that triggers the Stop function. An external safety-related sub-system can be implemented with devices such as the Preventa™ XPS modules. Stop Category 0 Stop Category 0 is defined as stopping the machine motion by immediate removal of electrical power from the machine actuators. Stop Category 0 is an uncontrolled stop. Stop Category 1 Stop Category 1 is defined as stopping the machine motion with electrical power maintained to the machine actuators during the stop process. Power is removed when the stop is complete. Stop Category 1 is a controlled stop. 16 8536IB1904EN-03
T eSys™ island Functional Safety Overview T eSys™ island – Digital Motor Management Solution Wiring Categories Wiring categories relate to the way the external Preventa™ XPS module (or equivalent) is wired, and to the associated additional level of control over the safety function. Wiring Category 1 A single detected fault may lead to the loss of the safety function and no diagnostic coverage is required. The safety-related sensor element can be directly wired to the SIL-IN/SIL Common inputs. The Mirror In/Mirror Out inputs are not used. For more information on wiring the SIL-IN/SIL Common inputs, see Safety-Related Sensor Element, page 23. Wiring Category 2 The safety-related sensor element is wired to a Preventa XPS module (or equivalent). The Preventa XPS module (or equivalent) outputs are wired to the SIL-IN/SIL Common inputs of the SIL interface module. T o meet the requirement for Category 2, the mirror contact feedback (Mirror In/ Mirror Out) must be monitored by a Preventa XPS module (or equivalent) that performs external diagnostic monitoring of the mirror contact. If the mirror contact does not close on stop, the next restart is prevented to all SIL starters in the SIL group. Implementing Indirect Monitoring for Category 2 T o reach category 2 requirements for diagnostic coverage (DC>60%), external monitoring of the group status should be implemented to trigger a secondary mechanism to stop the machine (breaker shunt trip, etc.) or to prevent access to dangerous areas (guard lock). Each SIL group has five states associated with it to indicate the operational state. State 0 indicates there is not a SIL group present in this slot. T eSys island supports up to 10 SIL groups in the island. SIL group status for SIL Stop function:
- 0 = SIL group not present in system configuration
- 1 = SIL group impacted by avatar Device Event
- 2 = Stop Command received, SIL starters not open yet
- 3 = Stop Command successfully issued, all SIL starters are open
- 4 = Stop Command issued to only one SIL interface module (SIM) input channel (jumper or SIM input wiring is causing an issue), but SIL starters did successfully open
- 5 = Normal operation, SIL starters can be open or closed State 5 is the normal run state, and State 3 is the normal SIL Stop state. State 1 indicates a firmware or communication issue with a SIL starter . States 2 and 4 indicate SIL Stop related problems with the SIM, SIL Starters or SIL Stop wiring. Indirect monitoring should look for states 2 or 4 to persist for longer than the actuation time of a SIL Stop and use the status information to trigger a secondary mechanism to stop the machine (breaker shunt trip, etc.). T o read the SIL group status, the external monitoring must use the SystemDiagnostics function block. Each SIL group in the system has an output on this function block for its SIL group status, labeled on the function block as “SILStarterStopMsgGrp n,” where n is the SIL group number in the island. The SIL group status follows the enumeration shown above. 8536IB1904EN-03 17 7. Wiring Categories according to ISO 13849. 8. Safety Integrity Level according to standard IEC 61508.
T eSys™ island – Digital Motor Management Solution T eSys™ island Functional Safety Overview Diagnostic Monitoring As the diagnostic monitoring occurs immediately upon demand of the safety function, the overall time to detect the fault and to bring the machine to a non- hazardous condition should be shorter than the time to reach the hazardous area. According to ISO 13849-2, 9.2.3, for Category 2: The MTTF d of the monitoring equipment should be greater than half of the MTTF d of the logic. The contribution of the T eSys island to the MTTF d of the diagnostic monitoring is MTTF d > 100 years. Wiring Category 3 A single fault will not lead to the loss of the safety function and whenever practicable, the single fault shall be detected at or before the next demand on the safety function. T o meet the requirement for Category 3, the mirror contact feedback (Mirror In/ Mirror Out) must be monitored by a Preventa XPS module (or equivalent) that performs external diagnostic monitoring of the SIL starter ’ s mirror contact. If the mirror contact does not open on stop, the next restart is prevented for all SIL starters in the SIL group. The safety-related sensor element is wired to a Preventa XPS module (or equivalent). The Preventa XPS module (or equivalent) outputs are wired to the SIL-IN/SIL Common inputs of the SIL interface module. In case of indirect monitoring, the external monitoring of the group status should look for states 2 or 4 to persist for longer than the actuation time of a SIL Stop. Use the status information to prevent the next restart of the group SIL starters. Wiring Category 4 A single fault will not lead to the loss of the safety function. The single fault is detected at or before the next demand on the safety function. If this detection is not possible, then an accumulation of undetected faults shall not lead to the loss of the safety function. T o meet the requirement for Category 4, the mirror contact feedback (Mirror In/ Mirror Out) must be monitored by a Preventa XPS module (or equivalent) that performs external diagnostic monitoring of the SIL starter ’ s mirror contact. If the mirror contact does not open on stop, the next restart is prevented for all SIL starters in the SIL group. The safety-related sensor element is wired to a Preventa XPS module (or equivalent). The Preventa XPS module (or equivalent) outputs are wired to the SIL-IN/SIL Common inputs of the SIL interface module. Acceptance T est The system integrator/machine manufacturer must perform an acceptance test of the safety function to verify and document the correct functionality of the safety function. The system integrator/machine manufacturer thereby certifies to have tested the eff ectiveness of the safety functions used. The acceptance test must be performed based on the hazard analysis and risk assessment. In case of low demand mode with category 4, the safety function should be tested at least once per month. All applicable standards and regulations must be followed. 18 8536IB1904EN-03 9. Mean time to dangerous failure as defined in ISO 13849-1. 10. Safety Integrity Level according to standard IEC 61508.
Concepts and Components T eSys™ island – Digital Motor Management Solution Concepts and Components T ypical T eSys™ island Structure The illustration below shows an example of a T eSys™ island that consists of two SIL 1 1 groups. The composition of the island is defined by the T eSys island digital tools according to the functional needs expressed by the user . Figure 2 - T eSys island with T wo SIL Groups A B C D E F G A SIL Group 1 E Avatar A4 B SIL Group 2 F Wiring Category 1, Stop Category 0 C Avatar A1 G Wiring Category 2, Stop Category 1 D Avatar A3 SIL Group 1: includes one avatar that includes two SIL starters: for instance, a “Motor T wo Directions – SIL Stop, W . Cat 1/2” avatar (Avatar A1). The actual motor is wired to these SIL starters and follows the avatar logic and the operational commands coming from the PLC through the fieldbus. The SIL Stop Command comes from the emergency stop push button wired to the SIL interface module (Wiring Category 1) and causes the SIL starters to de-energize the load and enter the safe state (contactor is opened, and the motor is de-energized). SIL Group 2: includes two avatars, for instance a “Switch – SIL Stop, W . Cat 1/2" (Avat ar A3) and a “Motor One Direction – SIL Stop, W . Cat 1/2" (Ava tar A4), each of them consisting of a single SIL starter . Both avatars follow the avatar logic and operational commands coming from the PLC through the fieldbus. The SIL Stop Command comes from the external Preventa™ XPS module (or equivalent) wired 8536IB1904EN-03 19 1 1. Safety Integrity Level according to standard IEC 61508. 12. Wiring Category 1 according to ISO 13849. Stop Category 0 according to EN/IEC 60204-1. 13. Wiring Category 2 according to ISO 13849. Stop Category 1 according to EN/IEC 60204-1.
T eSys™ island – Digital Motor Management Solution Concepts and Components to the SIL interface module, and causes the SIL starters to de-energize the load and enter the safe state (Wiring Category 2). SIL Group A SIL group is made up of one or more SIL avatars, all assigned to a single SIL interface module. All SIL avatars in the SIL group react to a single SIL Stop Command. The SIL interface module is always installed to the right of the last SIL starter included in the SIL group (far side of the bus coupler). An island may include several SIL groups. SIL A vatars SIL avatars available for SIL Stop functions are:
- Switch - SIL Stop, W . Cat 1/2
- Switch - SIL Stop, W . Cat 3/4
- Motor One Direction - SIL Stop, W . Cat 1/2
- Motor One Direction - SIL Stop, W . Cat 3/4
- Motor T wo Directions - SIL Stop, W . Cat 1/2
- Motor T wo Directions - SIL Stop, W . Cat 3/4
- Motor T wo Speeds - SIL Stop, W . Cat 1/2
- Motor T wo Speeds - SIL Stop, W . Cat 3/4
- Motor T wo Speeds T wo Directions - SIL Stop, W . Cat 1/2
- Motor T wo Speeds T wo Directions - SIL Stop, W . Cat 3/4
- Conveyor One Direction - SIL Stop, W . Cat 1/2
- Conveyor T wo Directions - SIL Stop, W . Cat 3/4 SIL avatars consist of specific hardware devices, including SIL starters, standard starters, and the required SIL interface module that manages the SIL group that the SIL avatars are assigned to. NOTE: SIL avatars are designed for applications with a low frequency of operational commands—below a yearly average of 15 start/stop cycles per hour . SIL Starter Standard Starter SIL Interface Module 20 8536IB1904EN-03 14. Safety Integrity Level according to standard IEC 61508.
Concepts and Components T eSys™ island – Digital Motor Management Solution SIL Interface Module The T eSys™ island SIL interface module (SIM) is an accessory module required to enable the Functional Safety feature of the island. The SIL Stop function is achieved by pure electromechanical means without any digital communication or bus coupler involvement. The SIM:
- interfaces with an external Preventa™ XPS module (or equivalent)
- commands the stop function of its SIL group
- exchanges operational data with the bus coupler
- reports operational information through front face LEDs SIL Starters Contact Status The status of the SIL starters belonging to a SIL group is reported via the SIM Mirror In/Out connections. This allows the implementation of Wiring Category 2 architectures where the mirror contacts are connected to the Preventa XPS module (or equivalent). These configurations provide direct monitoring capabilities of electromechanical devices by a mechanically linked contact element, which gives diagnostic coverage up to 99%. Refer to EN ISO 13849-1, T able E.1 – Estimates for diagnostic coverage (DC). T able 2 - SIL Starter Contact Status SIL Group Status Mirror In/Out Status All SIL Starters are open Mirror In/Out contact is closed At least one SIL Starter is closed Mirror In/Out contact is open T eSys island unpowered, or fault detected by the safety function Mirror In/Out contact is open 8536IB1904EN-03 21 15. Safety Integrity Level according to standard IEC 61508. 16. Wiring Category 2 according to ISO 13849.
T eSys™ island – Digital Motor Management Solution Concepts and Components Figure 3 - SIM to Preventa Module XPS-AF Wiring A A1 A2 S11 S12 Y1 Y 2 13 23 33 Z1S22S21 14 24 34 AC/DC DC+ DC+ CH+CH+ DC DC+ CH+ F1* SIM B C F E D SIM KC
230 Vac
24 Vdc
G H H I J A External start conditions (ESC) F Start button (S2) B Emergency stop push button (S1) G Power supply C Preventa XPS-UAF Module H Input D SIM mirror out I Start E SIM mirror in J Extension 22 8536IB1904EN-03
Concepts and Components T eSys™ island – Digital Motor Management Solution Safety-Related Sensor Element The SIM module is connected upstream:
- to the 24 Vdc source
- to the safety-related sensor element or a Preventa XPS module (or equivalent). The SIM module is designed with two input channels to accommodate dual channel safety-related sensor elements. For a higher level of fault tolerance, the two-input channel architecture is recommended. For the wiring diagrams below , refer to Legend for SIM Channel Wiring Diagrams, page 23. Figure 4 - SIM — One Channel Wiring
13 K1 KC K2 1
+24 Vdc
0 Vdc
B B A Figure 5 - SIM — T wo Channel Wiring +24 Vdc B B A T able 3 - Legend for SIM Channel Wiring Diagrams A Emergency stop push button (S1) B Flat cable connector 8536IB1904EN-03 23
T eSys™ island – Digital Motor Management Solution Concepts and Components SIL Starters W ARNING UNINTENDED EQUIPMENT OPERA TION For complete instructions about functional safety , refer to the T eSys™ island Functional Safety Guide, 8536IB1904.. Failure to follow these instructions can result in death, serious injury , or equipment damage. SIL starters provide similar functions to standard starters but are associated with a SIL interface module. The main functions of the SIL starters are as follows:
- Provide Stop Category 0 and Stop Category 1 functionality
- Provide operational control for loads
- Measure electrical data related to the load
- Provide energy monitoring data when a voltage interface module is installed in the island Multiple SIL starters might be needed for a single T eSys avatar function. For example, the avatar Motor T wo Directions - SIL Stop, W . Cat 1/2 includes two SIL starters. In addition, avatars using SIL starters always include a SIL interface module. The SIL starters are connected:
- Upstream to a circuit breaker
- Downstream to the load The SIL starters communicate with the bus coupler , sending operational data and receiving commands. T able 4 - SIL Starter Ratings Power Ratings Amperage Reference kW hp 4 5 0.18–9 TPRSS009 1 1 15 0.5–25 TPRSS025 18.5 20 0.76–38 TPRSS038 30 40 3.25–65 TPRSS065 37 40 4–80 TPRSS080 24 8536IB1904EN-03 17. Safety Integrity Level according to standard IEC 61508. 18. Stop Category 0 and Stop Category 1 according to EN/IEC 60204-1. 19. Wiring Category 1 and Category 2 according to ISO 13849.
Concepts and Components T eSys™ island – Digital Motor Management Solution Figure 6 - SIL Starter Features A C D G E F B A Flat cable (for connection with the module to the left) E Name tag B LED status indicators F Mobile bridge C Upstream power connections G Downstream power connections D QR code External Safety-Related Element T eSys™ island must be integrated with other safety-related elements in a broader safety-related system to help ensure the functional safety of a machine or a system/process. The following configurations illustrate typical devices. 8536IB1904EN-03 25
T eSys™ island – Digital Motor Management Solution Concepts and Components SIL Stop, Stop Category 0, Wiring Category 1 Configuration NOTE: Safety Integrity Level according to standard IEC 61508. Wiring Category 1 according to ISO 13849. Stop Category 0 according to EN/IEC 60204-1. The SIL Stop of the motor is directly controlled by the opening of the contact of the emergency stop push button. Figure 7 - SIL Stop B A D C E A Avatar A1 D Wiring Category 1, Stop Category 0 B SIL Group 1 E PLC C Motor SIL Stop, Stop Category 0, Wiring Category 2 Configuration NOTE: Safety Integrity Level according to standard IEC 61508. Wiring Category 2 according to ISO 13849. Stop Category 0 according to EN/IEC 60204-1. 26 8536IB1904EN-03
Concepts and Components T eSys™ island – Digital Motor Management Solution Figure 8 - Example: Motor T wo Directions - SIL Stop, W . Cat 1/2 — Stop Category 0, Wiring Category 2 Configuration (Indirect Monitoring) A1 A2 S11 S12 Y1 Y 2 13 23 33 Z1S22S21 14 24 34 AC/DC DC+ DC+ CH+CH+ DC DC+ CH+ F1* D G B H PLC BC L L L T T T L L L T T T L1 L2 L3 U1 V1 W1 M K J I A C KC E E E E E F E E 1 2 3 4 5 13 K1 L N N O P L 8536IB1904EN-03 27
T eSys™ island – Digital Motor Management Solution Concepts and Components T able 5 - Legend for Example: Motor T wo Directions - SIL Stop, W . Cat 1/2 — Stop Category 0, Wiring Category 2 Configuration (Indirect Monitoring), page 27 A Mechanical interlock I Bus coupler B Parallel link J PLC C Reversing link K Upstream circuit breaker D Emergency stop push button (S1) L Power supply E Flat cable connector N Input F SIL interface module (SIM) O Start G Preventa XPS-UAF Module P Extension H Start button (S2) 28 8536IB1904EN-03
Concepts and Components T eSys™ island – Digital Motor Management Solution Figure 9 - Example: Motor T wo Directions - SIL Stop, W . Cat 1/2 — Stop Category 0, Wiring Category 2 Configuration (Direct Monitoring) SS-1 SS-2 L L L T T T L L L T T T L1 L2 L3 U1 V1 W1 M B K J A C K1 KC K2 14 In1 In2 In3 Out1 Out2 D E E E E E F E 1 2 3 4 5 M N A Mechanical interlock F SIL interface module (SIM) B Parallel link J Safety Function PLC C Reversing link K Upstream circuit breaker D Emergency stop push button (S1) M Digital input E Flat cable connector N Digital output 8536IB1904EN-03 29
T eSys™ island – Digital Motor Management Solution Concepts and Components SIL Stop, Stop Category 1, Wiring Category 2 Configuration NOTE: Safety Integrity Level according to standard IEC 61508. Wiring Category 2 according to ISO 13849. Stop Category 1 according to EN/IEC 60204-1. Stop Category 1 is defined as “a controlled stop with power available to the machine actuators to achieve the stop and then removal of power when the stop is achieved.” When the emergency stop is triggered, the stop command is first sent to an external device (for example, a PLC or a drive). In this way , the process is stopped in a controlled manner rather than by immediate power removal. After a pre- defined time, the SIL Stop Command is then sent to the SIM to de-energize loads on the SIL avatars in the associated SIL group. The recommended setup is to use a PLC to help ensure that the process is correctly stopped before the SIL Stop occurs. The stop command can be routed directly to a digital input of the PLC, or to a T eSys™ island Digital I/O Module avatar , using one of its digital inputs read by the PLC. Upon receiving a stop command input, the PLC initiates a controlled stop by issuing an operational stop command to the targeted T eSys island avatar . Figure 10 - Stop Command B G D A F E C H A Avatar A1 E Wiring Category 2, Stop Category 1 B SIL Group 1 F Controlled Stop Category 1 command C Motor G PLC D Uncontrolled stop H Operational stop command 30 8536IB1904EN-03
Concepts and Components T eSys™ island – Digital Motor Management Solution Figure 1 1 - Example: Motor T wo Directions - SIL Stop, W . Cat 1/2 — Stop Category 1, Wiring Category 2 Configuration A1 A2 S11 S12 Y1 Y
2 Z1 13 23 33
F1* 57 67 75 48 68 76 M N PLC BC L L L T T T L L L T T T L1 L2 L3 U1 V1 W1 M O B P Q A C KC13 K1 E E E E E F E E 1 2 3 4 5 H I G L L R R S T 8536IB1904EN-03 31
T eSys™ island – Digital Motor Management Solution Concepts and Components T able 6 - Legend for Example: Motor T wo Directions - SIL Stop, W . Cat 1/2 — Stop Category 1, Wiring Category 2 Configuration, page 31 A Mechanical interlock M Controlled stop B Parallel link N Stop Category 1 C Reversing link O Upstream circuit breaker E Flat cable connector P PLC F SIL interface module (SIM) Q Bus coupler G Preventa XPS-UAF Module R Input H Emergency stop push button S Start I S2 Start Button T Extension L Power supply 32 8536IB1904EN-03
Concepts and Components T eSys™ island – Digital Motor Management Solution SIL Stop, Stop Category 0, Wiring Category 3/4 Configuration NOTE: Safety Integrity Level according to standard IEC 61508. Wiring Category 3/4 according to ISO 13849. Stop Category 0 according to EN/IEC 60204–1. The SIL Stop of the motor is directly controlled by the opening of the contact of the emergency stop push button. Figure 12 - SIL Stop, Wiring Category 3/4 P r e v e n t a XPSUAB POWER ERROR STATE START S12 S13 FUNCTION START A B L R E M V A C N L V A H C A B E D G F D A Av atar A1 E Bus coupler B SIL Group 1 F 24 VDC C Motor G Preventa XPS-UAF Module D Wiring Category 3/4, Stop Category 0 H PLC 8536IB1904EN-03 33
T eSys™ island – Digital Motor Management Solution Concepts and Components Figure 13 - Example: Motor One Direction - SIL Stop, W . Cat 3/4 — Stop Category 0, Wiring Category 3/4 Configuration U1 V1 W1 M A1 A2 S11 S12 Y1 Y 2 13 23 33 Z1S22S21 14 24 34 AC/DC DC+ DC+ CH+CH+ DC DC+ CH+ F1* D C G H L L L T T T L L L T T T L1 L2 L3 KC E E F 1 2 3 4 5 13 K1 C I I J K 34 8536IB1904EN-03
Concepts and Components T eSys™ island – Digital Motor Management Solution T able 7 - Legend for Example: Motor One Direction - SIL Stop, W . Cat 3/4 — Stop Category 0, Wiring Category 3/4 Configuration, page 34 C Power supply H Start button (S2) D Emergency stop push button (S1) I Input E Flat cable connector J Start F SIL interface module (SIM) K Extension G Preventa XPS-UAF Module SIL Stop, Stop Category 1, Wiring Category 3/4 Configuration NOTE: Safety Integrity Level according to standard IEC 61508. Wiring Category 3/4 according to ISO 13849. Stop Category 1 according to EN/IEC 60204. Stop Category 1 is defined as “a controlled stop with power available to the machine actuators to achieve the stop and then removal of power when the stop is achieved.” When the emergency stop is triggered, the stop command is first sent to an external device (for example, a PLC or a drive). This way , the process is stopped in a controlled manner rather than by immediate power removal. After a pre- defined time, the SIL Stop Command is then sent to the SIM to de-energize loads on the SIL avatars in the associated SIL group. For setup, the recommendation is to use a PLC to help ensure that the process is correctly stopped before the SIL Stop occurs. The Stop command can be routed directly to a digital input of the PLC, or to a T eSys™ island Digital I/O Module avatar , using one of its digital inputs read by the PLC. Upon receiving a stop command input, the PLC initiates a controlled stop by issuing an operational stop command to the targeted T eSys island avatar . 8536IB1904EN-03 35
T eSys™ island – Digital Motor Management Solution Concepts and Components Figure 14 - Stop Command, Wiring Category 3/4 P r e v e n t a XPSUAB POWER ERROR STATE START S12 S13 FUNCTION START C A F B H G D E A Av atar A1 E Wiring Category 3/4, Stop Category 1 B SIL Group 1 F Controlled Stop Category 1 command C Motor G PLC D Uncontrolled stop H Operational stop command 36 8536IB1904EN-03
Concepts and Components T eSys™ island – Digital Motor Management Solution Figure 15 - Example: Motor T wo Directions - SIL Stop, W . Cat 3/4 — Stop Category 1, Wiring Category 3/4 Configuration A1 A2 S11 S12 Y1 Y F1* 57 67 75 48 68 76 M G N H I D
13 K1 KC
L L L T T T SS-1 L1 L2 L3 L L L T T T SS-2 L L L T T T SS-3 B E E F U1 V1 W1 M C D J D J K L 8536IB1904EN-03 37
T eSys™ island – Digital Motor Management Solution Concepts and Components T able 8 - Legend for Example: Motor T wo Directions - SIL Stop, W . Cat 3/4 — Stop Category 1, Wiring Category 3/4 Configuration, page 37 B Parallel link I S2 Start Button C Reversing link J Input D Power supply K Start E Flat cable connector L Extension F SIL interface Module (SIM) M Controlled stop G Preventa XPS-UAF Module N Stop Category 1 H Emergency stop push button (S1) Protected Cable Insulation DANGER UNINTENDED EQUIPMENT OPERA TION Make sure to install the cables of the safety-related system according to ISO 13849-2. Failure to follow these instructions will result in death or serious injury . If short circuits and cross circuits can occur with the cables of the safety-related system and if they are not detected by upstream devices, protected cable installation according to ISO 13849-2 is required. In the case of an unprotected cable installation, the two signals (both channels) of a safety function in short circuit state may be connected to external voltage if a cable is damaged. In this case, the safety function is no longer operative. 38 8536IB1904EN-03
Concepts and Components T eSys™ island – Digital Motor Management Solution Low/High Frequency Switching Architecture The information in this section can be used to determine whether you are operating in a low or high frequency architecture. The electromechanical part of the SIL starter is characterized with a B10d. T o calculate the MTTF d (according ISO 13849-1) or λd (according to IEC 62061), the following formula applies: MTTF d =B10d/(0,1*Nop) with λd=1/MTTF d Nop: Mean number of annual operations According to ISO 13849, the operation time of an electromechanical component is limited to T10d (the mean time until 10% of the components fail dangerously Therefore, the operation time of a SIL starter is limited to: T10d=B10d/Nop The B10d of the SIL starter is B10d = 1,369,863 and assuming a T10d of 10 years, the number of cycles for a T eSys island SIL starter is limited to Nop = B10d/ T10 = 131,400/year (or a yearly average of 15 cycles/h). If the application requires a Nop lower than that value, it falls under the low switching frequency category (where SIL avatars can be used as is). Otherwise, it falls under the high switching frequency category (where the safety function must be implemented with a devoted SIL avatar as described below). 8536IB1904EN-03 39 20. Safety Integrity Level according to standard IEC 61508. 21. Fail dangerously according to ISO 13849
T eSys™ island – Digital Motor Management Solution Concepts and Components Low Switching Frequency (< 15 cycles per hour) In low switching frequency , the SIL Stop and the operational on/off control functions can be achieved together with a SIL avatar . Figure 16 - Example A vatar with SIL Starter T able 9 - Low Switching Frequency — Operational and Safety Functions SIL A vatar Module 1 Module 2 Module 3 Module 4 Module 5 Switch - SIL Stop, W . Cat 1/2 SIL Starter SIM — — — Switch - SIL Stop, W . Cat 3/4 SIL Starter SIL Starter SIM — — Motor One Direction - SIL Stop, W . Cat 1/2 SIL Starter SIM — — Motor One Directions - SIL Stop, W . Cat 3/4 SIL Starter SIL Starter SIM — — Motor T wo Directions - SIL Stop, W . Cat 1/2 SIL Starter SIL Starter SIM — — Motor T wo Directions - SIL Stop, W . Cat 3/4 SIL Starter SIL Starter SIL Starter SIM — Motor T wo Speeds - SIL Stop, W . Cat 1/2 SIL Starter SIL Starter SIM — — Motor T wo Speeds - SIL Stop, W . Cat 3/4 SIL Starter SIL Starter SIL Starter SIM — Motor T wo Speeds T wo Directions - SIL Stop, W . Cat 1/2 Standard Starter Standard Starter SIL Starter SIL Starter SIM Motor T wo Speeds T wo Directions - SIL Stop, W . Cat 3/4 SIL Starter SIL Starter SIL Starter SIL Starter SIM Conveyor One Direction - SIL Stop, W . Cat 1/2 SIL Starter SIM — — — Conveyor T wo Directions - SIL Stop, W . Cat 1/2 SIL Starter SIL Starter SIM — — 40 8536IB1904EN-03 22. Safety Integrity Level according to standard IEC 61508. 23. Wiring Category 1 and Category 2 according to ISO 13849. 24. Wiring Category 3 and Category 4 according to ISO 13849.
Concepts and Components T eSys™ island – Digital Motor Management Solution High Switching Frequency (≥ 15 cycles per hour) For high frequency use, the safety function must be isolated from the operational function by using a SIL avatar for the safety function and a standard avatar for the operational function. The standard starters are then wired in series downstream the SIL starter(s). High Switching Frequency – Operational and Safety Functions, page 41 shows examples of standard avatars used downstream the SIL starter(s) for SIL Stop, W . Cat 1/2 and SIL Stop, W . Cat 3/4 architectures. Figure 17 - Standard A vatar for Operational Function + SIL A vatar Used for Safety Function —SIL Stop, W . Cat 1/2 A B A Standard avatar B SIL avatar T able 10 - High Switching Frequency - SIL Stop, W . Cat 1/2 — Operational and Safety Functions Standard A vatar SIL A vatar Module 1 Module 2 Module 3 Module 4 Module 5 Module Switch Switch - SIL Stop, W . Cat 1/2 Standard Starter SIL Starter SIM — — — Motor One Direction Switch - SIL Stop, W . Cat 1/2 Standard Starter SIL Starter SIM — — — Motor T wo Directions Switch - SIL Stop, W . Cat 1/2 Standard Starter Standard Starter SIL Starter SIM — — Motor T wo Speeds Switch - SIL Stop, W . Cat 1/2 Standard Starter Standard Starter SIL Starter SIM — — Motor T wo Speeds T wo Directions Switch - SIL Stop, W . Cat 1/2 Standard Starter Standard Starter Standard Starter Standard Starter SIL Starter SIM Conveyor One Direction Switch - SIL Stop, W . Cat 1/2 Standard Starter SIL Starter SIM — — — Conveyor T wo Directions Switch - SIL Stop, W . Cat 1/2 Standard Starter Standard Starter SIL Starter SIM — — Motor Y/D One Direction Switch - SIL Stop, W . Cat 1/2 Standard Starter Standard Starter Standard Starter SIL Starter SIM — Motor Y/D T wo Directions Switch - SIL Stop, W . Cat 1/2 Standard Starter Standard Starter Standard Starter Standard Starter SIL Starter SIM 8536IB1904EN-03 41 25. Safety Integrity Level according to standard IEC 61508. 26. Wiring Category 1 and Category 2 according to ISO 13849. 27. Wiring Category 3 and Category 4 according to ISO 13849.
T eSys™ island – Digital Motor Management Solution Concepts and Components Figure 18 - Standard A vatar for Operational Function + SIL A vatar Used for Safety Function — SIL Stop, W . Cat 3/4 A B A Standard avatar B SIL avatar T able 1 1 - High Switching Frequency - SIL Stop, W . Cat 3/4 — Operational and Safety Functions Standard A vatar SIL A vatar Module 1 Module 2 Module 3 Module 4 Module 5 Module 6 Module 7 Switch Switch - SIL Stop, W . Cat 3/4 Standard Starter SIL Starter SIL Starter SIL Starter — — — Motor One Direction Switch - SIL Stop, W . Cat 3/4 Standard Starter SIL Starter SIL Starter SIL Starter — — — Motor T wo Directions Switch - SIL Stop, W . Cat 3/4 Standard Starter Standard Starter SIL Starter SIL Starter SIM — — Motor T wo Speeds Switch - SIL Stop, W . Cat 3/4 Standard Starter Standard Starter SIL Starter SIL Starter SIM — — Motor T wo Speeds T wo Directions Switch - SIL Stop, W . Cat 3/4 Standard Starter Standard Starter Standard Starter Standard Starter SIL Starter SIL Starter SIM Motor Y/D One Direction Switch - SIL Stop, W . Cat 3/4 Standard Starter Standard Starter Standard Starter Standard Starter SIL Starter SIL Starter SIL Starter Motor Y/D T wo Directions Switch - SIL Stop, W . Cat 3/4 Standard Starter Standard Starter Standard Starter Standard Starter SIL Starter SIL Starter SIL Starter 42 8536IB1904EN-03
Sample Architectures T eSys™ island – Digital Motor Management Solution Sample Architectures The following architectures are available for T eSys™ island functional safety:
- SIL Stop, Stop Category 0, Wiring Category 1
- SIL Stop, Stop Category 0, Wiring Category 2
- SIL Stop, Stop Category 1, Wiring Category 2
- SIL Stop, Stop Category 0, Wiring Category 3/4
- SIL Stop, Stop Category 1, Wiring Category 3/4 SIL Stop, Stop Category 0, Wiring Category 1 Figure 19 - Example: SIL Stop, Stop Category 0, Wiring Category 1 1 2 3 4 5 SS-1 SS-2 L L L T T T L L L T T T L1 L2 L3 U1 V1 W1 M B A C D +24 VDC
E E E E E F E A Mechanical interlock D Emergency stop push button (S1) B Parallel link E Flat cable connector C Reversing link F SIL interface module (SIM) 8536IB1904EN-03 43 28. Safety Integrity Level according to standard IEC 61508. Wiring Category 1, Category 2, and Category 3/4 according to ISO 13849. Stop Category 0 and Category 1 according to EN/IEC 60204-1. 29. Safety Integrity Level according to standard IEC 61508. Wiring Category 1 according to ISO 13849. Stop Category 0 according to EN/ IEC 60204-1.
T eSys™ island – Digital Motor Management Solution Sample Architectures SIL Stop, Stop Category 0, Wiring Category 2 Figure 20 - Example: SIL Stop, Stop Category 0, Wiring Category 2 E A1 A2 S11 S12 Y1 Y 2 13 23 33 Z1S22S21 14 24 34 AC/DC DC+ DC+ CH+CH+ DC DC+ CH+ F1* G D H I L L L T T T L L L T T T L1 L2 L3 U1 V1 W1 M A B C KC E E E E E F 1 2 3 4 5 13 K1 D J J K L 44 8536IB1904EN-03 30. Safety Integrity Level according to standard IEC 61508. Wiring Category 2 according to ISO 13849. Stop Category 0 according to EN/ IEC 60204-1.
Sample Architectures T eSys™ island – Digital Motor Management Solution T able 12 - Legend for Example: SIL Stop, Stop Category 0, Wiring Category 2, page 44 A Mechanical interlock G Emergency stop push button (S1) B Parallel link H Preventa XPS-UAF Module C Reversing link I Start button (S2) D Power supply J Input E Flat cable connector K Start F SIL interface module (SIM) L Extension 8536IB1904EN-03 45
T eSys™ island – Digital Motor Management Solution Sample Architectures SIL Stop, Stop Category 1, Wiring Category 2 Figure 21 - Example: SIL Stop, Stop Category 1, Wiring Category 2 A1 A2 S11 S12 Y1 Y F1* 57 67 75 48 68 76 M D H G I N PLC BC L L L T T T L L L T T T L1 L2 L3 U1 V1 W1 M O B P Q A C KC13 K1 E E E E E F E E 1 2 3 4 5 G J J K L 46 8536IB1904EN-03 31. Safety Integrity Level according to standard IEC 61508. Wiring Category 2 according to ISO 13849. Stop Category 1 according to EN/ IEC 60204-1.
Sample Architectures T eSys™ island – Digital Motor Management Solution T able 13 - Legend for Example: SIL Stop, Stop Category 1, Wiring Category 2, page 46 A Mechanical interlock J Input B Parallel link K Start C Reversing link L Extension E Flat cable connector M Controlled stop F SIL interface module (SIM) N Stop Category 1 G Power supply O Upstream circuit breaker H Emergency stop push button (S1) P PLC I S2 Start Button Q Bus coupler 8536IB1904EN-03 47
T eSys™ island – Digital Motor Management Solution Sample Architectures SIL Stop, Stop Category 0, Wiring Category 3/4 Figure 22 - Example: SIL Stop, Stop Category 0, Wiring Category 3/4 U1 V1 W1 M A1 A2 S11 S12 Y1 Y 2 13 23 33 Z1S22S21 14 24 34 AC/DC DC+ DC+ CH+CH+ DC DC+ CH+ F1* D C G H L L L T T T L L L T T T L1 L2 L3 KC E E F 1 2 3 4 5 13 K1 C I I J K 48 8536IB1904EN-03 32. Safety Integrity Level according to standard IEC 61508. Wiring Category 3/4 according to ISO 13849. Stop Category 0 according to EN/ IEC 60204-1.
Sample Architectures T eSys™ island – Digital Motor Management Solution T able 14 - Legend for Example: SIL Stop, Stop Category 0, Wiring Category 3/4, page 48 C Power supply H Start button (S2) D Emergency stop push button (S1) I Input E Flat cable connector J Start F SIL interface module (SIM) K Extension G Preventa XPS-UAF Module 8536IB1904EN-03 49
T eSys™ island – Digital Motor Management Solution Sample Architectures SIL Stop, Stop Category 1, Wiring Category 3/4 Figure 23 - Example: SIL Stop, Stop Category 1, Wiring Category 3/4 A1 A2 S11 S12 Y1 Y F1* 57 67 75 48 68 76 M G N H I D L L L T T T SS-1 L1 L2 L3 L L L T T T SS-2 L L L T T T SS-3 B E E F U1 V1 W1 M C D J D J K L 50 8536IB1904EN-03 33. Safety Integrity Level according to standard IEC 61508. Wiring Category 3/4 according to ISO 13849. Stop Category 1 according to EN/ IEC 60204-1.
Sample Architectures T eSys™ island – Digital Motor Management Solution T able 15 - Legend for Example: SIL Stop, Stop Category 1, Wiring Category 3/4, page 50 B Parallel link I S2 Start Button C Reversing link J Input D Power supply K Start E Flat cable connector L Extension F SIL interface Module (SIM) M Controlled stop G Preventa XPS-UAF Module N Stop Category 1 H Emergency stop push button (S1) 8536IB1904EN-03 51
T eSys™ island – Digital Motor Management Solution T echnical Data T echnical Data SIL Interface Module T able 16 - Calculated V alues of the SIL Interface Module (SIM) Architecture SIM PFH PFD SFF HFT MTTF d (years) DC Wiring Category 1 2.10 – 10 2.10 – 5 >90% 1 17,459 Not relevant Wiring Category 2 >99% 90% Wiring Category 3 >99% 90% Wiring Category 4 99% 99% NOTE: PFD and PFH values are calculated with the following:
- T est Interval = 20 years
- MTTR =MRT = 24 hours Architectural requirements defined in IEC 61508-2 T able 3 and EN 62061 T able 5 are met for levels up to SIL 3. SIL Starter The following data help define the level of performance for SIL starters. B10: 1,000,000 % of dangerous failures : 73% B10 d : 1,369,863 Assuming number of operations = 131,400 cycles/year (average of 15 cycles/hour) The calculated values of the SIL starter are provided in the following tables: T able 17 - SIL Starter in Single Channel Wiring Category SFF HFT MTTF d (years) DC Category 1 27% 0 100 years Not relevant Category 2 – Direct monitoring 90% 0 100 years ≥ 90% 52 8536IB1904EN-03 34. Safety Integrity Level according to standard IEC 61508. 35. Average frequency of dangerous failure [h-1], as defined in IEC 61508-4 36. Probability of dangerous failure on demand, as defined in IEC 61509-4. 37. Safe failure fraction, as defined in IEC 61509-4. 38. Hardware fault tolerance, as defined in IEC 61509-4. 39. Diagnostic coverage, as defined in IEC 61509-4. 40. Wiring Categories 1, 2, 3, and 4 according to ISO 13849. 41. Mean time to repair , as defined in IEC 61509-4 42. Mean repair time, as defined in IEC 61509-4 43. Dangerous failure as defined in IEC 61508-4
T echnical Data T eSys™ island – Digital Motor Management Solution T able 18 - SIL Starter in Dual Channel Wiring Category SFF HFT MTTF d (years) DC Category 3 27% 0 100 years ≥ 90% Category 4 90% 0 100 years ≥ 99% The relation between PFH d and PFD of the SIL starters, depending on the architecture and the test interval, is given in the following table: T able 19 - SIL Starters — PFH d and PFD Wiring Category PFH (IEC 61508) PFD (IEC 61508) Ti=10 years PFD (IEC 61508) Ti=5 years Category 1 1.10E-06 4.80E-02 4.82E-03 Category 2 – Direct monitoring 1.10E-06 4.82E-03 5.06E-04 Category 3 4.5E-09 — 1.30E-04 Category 4 2.5E-10 — 2.5E-06 Architectural requirements defined in IEC 61508-2 T able 3 and EN 62061 T able 5 are met for levels up to SIL 2. A Category 2 architecture is needed to meet SIL 2 architectural constraints (accomplished using direct monitoring Mirror In/Mirror Out). NOTE: The fault detection and specified fault reaction must be performed before the hazardous situation addressed by the safety-related control function can occur . 8536IB1904EN-03 53 44. T esting interval
T eSys™ island – Digital Motor Management Solution T echnical Data Reliability Data Safety Function Standard Reference The SIL Stop function has priority over a stop triggered for operational reasons The performance level depends on the wiring category , the MTTF d , and the DC avg The following diagram shows the positioning of T eSys™ island according to the category requirement. Figure 24 - T eSys island Positioning by Category Requirement Key PL perfor mance lev el
1 MTTF
d of each channel = low
2 MTTF
d of each c hannel = medium
3 MTTF
d of each channel = high T able 20 - Simplified Procedure for Evaluating PL Achieved by Safety-Related Parts of Control Systems (SRP/CS) Category B 1 2 2 3 3 4 DC avg none none low medium low medium high MTTF d of each channel Low a Not covered a b b c Not covered Medium b Not covered b c c d Not covered High Not covered c v d d d e According to T eSys island architecture and wiring category , the key indicators (DC avg , MTTF d , PL) for T eSys island comply with the values shown in the table below . T able 21 - V alues of Key Indicators for Single and Dual Channel Architectures T eSys island system architecture Category Single fault tolerance DC avg MTTF d of each channel T argeted PL Single channel 1 No None High (≥ 30 years) c 54 8536IB1904EN-03 45. Safety Integrity Level according to standard IEC 61508. 46. Wiring Categories according to ISO 13849. 47. Single fault tolerance means that a single fault (including common-mode events) must not lead to the loss of the safety function.
T echnical Data T eSys™ island – Digital Motor Management Solution T able 21 - V alues of Key Indicators for Single and Dual Channel Architectures (Continued) T eSys island system architecture Category Single fault tolerance DC avg MTTF d of each channel T argeted PL 2 No Low (≥ 60%) to medium (≥ 90%) Low (≥ 3 years) to high (≥ 30 years) c, d Dual channel
3 Y es c, d, e
4 Y es High (≥ 99%) High (≥ 30 years) e
The wiring diagrams in this section are for the SIL avatars. The following table is a legend for the diagrams in this section. T able 22 - Legend for Wiring Diagrams A Mechanical interlock B Parallel link C Reversing link E Electrical circuit Figure 25 - Switch - SIL Stop, W . Cat 1/2 L L L T T T L1 L2 L3 E 8536IB1904EN-03 55 48. Single fault tolerance means that a single fault (including common-mode events) must not lead to the loss of the safety function. 48. Safety Integrity Level according to standard IEC 61508. 49. Wiring Category 1 and Category 2 according to ISO 13849.
T eSys™ island – Digital Motor Management Solution T echnical Data Figure 34 - Motor T wo Speeds T wo Directions - SIL Stop, W . Cat 3/4 M B A B A C L L L T T T L L L T T T L L L T T T SS-1 SS-3 L1 L2 L3 U1 V1 W1 U2 V2 W2 L L L T T T SS-2 SS-4 Figure 35 - Conveyor One Direction - SIL Stop, W . Cat 1/2 AIOM 24 V I0+ 3 4 5 6 7 8 9 10 Q+ Q-I0- NC0 I1+ I1- NC1 DIOM 24 V 11 12 13 14 1 5 16 17 18 1 2 3 4 5 6 7 8 1 2 3 4 5 6 7 8 QC Q1I1 IC I
2 I3 Q0
L L L T T T L1 L2 L3 U1 V1 W1 M 60 8536IB1904EN-03
T echnical Data T eSys™ island – Digital Motor Management Solution Figure 36 - Conveyor T wo Directions - SIL Stop, W . Cat 1/2 AIOM 24 V I0+ 3 4 5 6 7 8 9 10 Q+ Q-I0- NC0 I1+ I1- NC1 DIOM 24 V 11 12 13 14 1 5 16 17 18 1 2 3 4 5 6 7 8 1 2 3 5 6 7 8 QC Q1I1 IC I B A C SS-1 L1 L2 L3 SS-2 M U1 V1 W1 L L L T T T L L L T T T 8536IB1904EN-03 61
T eSys™ island – Digital Motor Management Solution Commissioning the Safety Function Commissioning the Safety Function Use this procedure to commission the safety function. The procedure comprises two steps:
- Installation tests
- Safety function proof tests Installation T ests Perform the steps in the following table to test the installation of the safety function. T able 23 - Installation T est
1 Using the DIAGNOSTICS panel in the T eSys™ island DTM, verify that the physical topology
matches the logical topology .
2 Using the MY A V A T AR panel in the T eSys island DTM, verify in A V A T AR P ARAMETERS
avatars are associated with the proper SIL group. Safety Function Proof T est The safety function proof test is performed for each SIL group on the island. A SIL group may comprise multiple SIL avatars managed by one SIL Interface Module (SIM). The safety function proof test is successful if upon activation of the emergency stop device associated with a SIL group, all SIL starters belonging to that SIL group enter the safe state (the load is de-energized). NOTE: For Stop Category 0 (uncontrolled stop), the stop should be immediate. For Stop Category 1 (controlled stop) the stop is effe ctive after a delay . Perform the steps in the following table for each SIL group on the island to perform the safety function proof test. T able 24 - Safety Function Proof T est
1 Activate the emergency stop device associated with the SIL group, and check that all SIL
starters belonging to the group enter the safe state (the load is de-energized). NOTE: The Device Status (DS) LED will flash red on the SIL starters, indicating a Device Minor Event state. If the test does not pass:
- The emergency stop device may be connected to the wrong SIM. Check these connections.
- The emergency stop device may not be correctly wired to the SIM. Check these connections.
- Some SIL avatars may not be attached to the expected SIL Group. Check the configuration.
2 In the T eSys™ island DTM or OMT A V A T ARS panel, in the DIAGNOSTICS section, check
the ST A TUS and EVENT LOGS to verify that SIL Group Status is equal to "Stop Command." In the Event Log it will read “SIL Group Stop cmd, Safe State achieved.” If the test does not pass:
- Some SIL avatars may not be attached to the expected SIL Group. Check the configuration. 62 8536IB1904EN-03 51. Proof test as defined in IEC 62061 52. Safety Integrity Level according to standard IEC 61508. 53. Stop Category 0 and Category 1 according to EN/IEC 60204-1.
Commissioning the Safety Function T eSys™ island – Digital Motor Management Solution T able 24 - Safety Function Proof T est (Continued)
3 In the DEVICES section of the DIAGNOSTICS panel, verify that the SIL Interface Module
(SIM) Status is equal to "Stop Command.” In the Event Log it will read “SIL Group Stop cmd, Safe State achieved.” If the test does not pass:
- The emergency stop device may be connected to the wrong SIM. Check these connections.
- The emergency stop device may not be correctly wired to the SIM. Check these connections.
4 Apply a start command to a SIL avatar belonging to the SIL group and verify that the start is
unsuccessful: the starters should remain open and the start command should be disregarded until the emergency stop device is reset. If the test does not pass:
- Some SIL avatars may not be attached to the expected SIL Group. Check the configuration. If any of these tests continue not to pass despite corrective actions, do not continue to operate the island. Replace the devices that did not pass the tests.
5 After the safety function proof test is complete, reset the emergency stop device and verify
that all SIL starters and SIL interface modules are in Ready state (the DS LED is steady green). 8536IB1904EN-03 63
T eSys™ island – Digital Motor Management Solution Safety Function Maintenance Requirements Safety Function Maintenance Requirements This section describes the routine maintenance required for maintaining functional safety on your T eSys™ island. Maintenance Schedule Maintenance intervals depend on the frequency mode.
- For Low Frequency mode (the yearly average number of contactor cycles is less than 15 cycles/hour), perform maintenance every 12 months.
- For High Frequency mode (the yearly average number of contactor cycles is greater than 15 cycles/hour or 136,986 cycles/year), perform maintenance at intervals that are 1/10th of the device estimated lifetime. The device estimated lifetime (years) = B10d (=1,369,863) / yearly average number of contactor cycles Maintenance Checks Device Usage Checks Perform the checks described in the following table to verify that the SIL starter contactor cycles are within the acceptable lifetime values.
1 Using the Devices DIAGNOTSICS feature of the T eSys™ island DTM or OMT , access the
device asset information for each SIL starter .
2 If the Number of Contactor Cycle is greater than B10d (=1,369,863), then replace the
SIL starter . 3 If not, use the Number of Contactor Cycle value to schedule the next maintenance. See Maintenance Schedule, page 64. Safety Function Proof T est Perform the Safety Function Proof T est on each SIL Group. See Safety Function Proof T est, page 62. 64 8536IB1904EN-03 54. Safety Integrity Level according to standard IEC 61508.
Appendix: Single-Channel Architecture T eSys™ island – Digital Motor Management Solution Appendix: Single-Channel Architecture This single-channel architecture encompasses Wiring Categories 1 and 2. Architectural Requirements for Wiring Category 1 Designated architecture for Category 1 is defined in EN ISO 13849-1, 6.2.4. Figure 37 - Designated architecture for Category 1 (EN ISO 13849-1) I: input device L: logic O: output device i m: interconnecting means SRP/CS, the safety-related part of the control system, of Wiring Category 1 must be designed and constructed using well-tried components. A “well-tried component” for a safety-related application is a component which has been either:
- widely used in the past with successful results in similar applications, or
- made and verified using principles which demonstrate its suitability and reliability for safety-related applications. There is no diagnostic coverage (DC avg = none) within Category 1 systems. 8536IB1904EN-03 65
T eSys™ island – Digital Motor Management Solution Appendix: Single-Channel Architecture Architectural Requirements for Wiring Category 2 Designated architecture for Category 2 is defined in EN ISO 13849-1, 6.2.5. Figure 38 - Designated Architecture for Category 2 (EN ISO 13849-1) I: input device m: monitoring L: logic TE: test equipment O: output device OTE: output of TE i m: interconnecting means SRP/CS, the safety-related part of the control system, of Wiring Category 2 must be designed so that their function(s) are checked at suitable intervals by the machine control system. In single-channel architecture, a SIM is associated with a SIL starter . Specifically , for Wiring Category 2, the mirror contact is connected to the Preventa™ XPS module (or equivalent). If the state of the mirror contact feedback line does not equal the Preventa XPS module (or equivalent) output state, the Preventa XPS module (or equivalent) blocks a second start. NOTE: The mirror contact feedback conveys diagnosis information only . 66 8536IB1904EN-03 55. Safety Integrity Level according to standard IEC 61508.
T eSys™ island – Digital Motor Management Solution Glossary A A verage Frequency of Dangerous Failure [h ] (PFH). (Dangerous failure as defined in IEC 61508-4) T o maintain the safety function, the IEC 61508 standard requires various levels of measures for avoiding and controlling detected errors, depending on the required SIL All components of a safety function must be subjected to a probability assessment to evaluate the effe ctiveness of the measures implemented for controlling detected faults. This assessment determined the PFH (Average Frequency of Dangerous Failure ]) for a safety-related system. This is the probability per hour that a safety- related system fails in a hazardous manner and the safety function cannot be correctly executed. Depending on the SIL, the PFH must not exceed certain values for the entire safety-related system. The individual PFH values of a function chain are added. The result must not exceed the maximum value specified in the standard. Safety Integrity Level A verage Frequency of Dangerous Failure ] (PFH) at High Demand or Continuous Demand 4 10 ≤ — < 10 3 10 ≤ — < 10 2 10 ≤ — < 10 1 10 ≤ — < 10 E EN ISO 13849 Standard This European Standard specifies the validation process, including hazard analysis, risk assessment, and testing, for the safety functions and categories for the safety-related parts of control systems. Descriptions of the safety functions and the requirements for the categories are given in ISO 13849-1, which covers the general principles for design. Some requirements for validation are general and some are specific to the technology used. EN ISO 13849-2 also specifies the conditions under which the validation by testing of the safety-related parts of control systems should be carried out. EN/IEC 60204-1 Standard Stop Category 0 is defined as a function “stopping by immediate removal of power to the machine actuators (i.e. an uncontrolled stop).” Stop Category 1 is defined as “a controlled stop with power available to the machine actuators to achieve the stop and then removal of power when the stop is achieved.” F 56. Safety Integrity Level according to standard IEC 61508. 57. Dangerous failure as defined in IEC 61508-4
T eSys™ island – Digital Motor Management Solution Fault A voidance Measures Systematic errors in the specifications, in the hardware and the software, usage faults and maintenance faults in the safety-related system must be avoided to the maximum degree possible. T o meet these requirements, IEC 61508 specifies a number of measures for fault avoidance that must be implemented depending on the required SIL . These measures for fault avoidance must cover the entire life cycle of the safety-related system, i.e. from design to decommissioning of the system. Functional Safety Automation and functional safety engineering are two areas that were completely separate in the past but have recently become more integrated. The engineering and installation of complex automation solutions are simplified by integrated safety functions. Usually , the functional safety engineering requirements depend on the application. The level of requirements results from the risk and the hazard potential arising from the specific application. H Hardware Fault T olerance (HFT) and Safe Failure Fraction (SFF) Depending on the SIL for the safety-related system, the IEC 61508 standard requires a specific hardware fault tolerance (HFT) in connection with a specific proportion of safe failures, shown as Safe Failure Fraction (SFF). The HFT is the ability of a system to execute the required safety function in spite of the presence of one or more hardware faults. The SFF of a system is defined as the ratio of the rate of safe failures to the total failure rate of the system. According to IEC 61508, the maximum achievable SIL of a system is partly determined by the HFT and the SFF of the system. These types are specified on the basis of criteria which the standard defines for the safety-related elements. SFF HFT T ype A Subsystem HFT T ype B Subsystem 0 1 2 0 1 2 < 60% SIL 1 SIL 2 SIL 3 — SIL 1 SIL 2 60% – < 90% SIL 2 SIL 3 SIL 4 SIL 1 SIL 2 SIL 3 90% – < 99 % SIL 3 SIL 4 SIL 4 SIL 2 SIL 3 SIL 4 ≥ 99% SIL 3 SIL 4 SIL 4 SIL 3 SIL 4 SIL 4 I IEC 61508 Standard The standard IEC 61508 covers the functional safety of electrical/electronic/ programmable electronic safety-related systems. Instead of a single component, an entire function chain (for example, from a sensor through the logical processing units to the actuator) is considered as a unit. This function chain must meet the requirements of the specific safety integrity level as a whole. 58. Safety Integrity Level according to standard IEC 61508.
T eSys™ island – Digital Motor Management Solution L Low/High Demand Mode IEC 61508 defines the safety function demand mode of operation:
- high demand or continuous mode (PFH)
- low demand mode (PFDavg, PTI) M Mean T ime to Dangerous Failure (MTTF d Standard ISO 13849-1 defines the MTTF d as the expectation of the mean time to dangerous failure. P Performance Level (PL) The standard IEC 13849-1 defines five performance levels (PL) for safety functions. Level a is the lowest level and e is the highest. Five levels (a, b, c, d, and e) correspond to dif ferent values of average probability of dangerous failure per hour . Performance Level Probability of a Dangerous Failure per Hour e ≥ 10 to < 10 d ≥ 10 to < 10 c ≥ 10 to < 3 x 10 b ≥ 3 x 10 to < 10 a ≥ 10 to < 10 S Safety Integrity Level (SIL) The standard IEC 61508 defines four safety integrity levels (SIL) for safety functions. SIL 1 is the lowest integrity level and SIL 4 is the highest. A hazard analysis and risk assessment serves as a basis for determining the required safety integrity level. This is used to decide whether the relevant function chain is to be considered as a safety function, and which hazard potential it must cover . 59. Dangerous failure as defined in IEC 61508-4
800 Federal Street
01810 Andover , MA
https://www .schneider-electric.com/en/work/support/ www .schneider-electric.com As standards, specifications, and design change from time to time, please ask for confirmation of the information given in this publication. © 2021 – Schneider Electric. All rights reserved. 8536IB1904EN-03