KROHNE OPTISWITCH 3x00C 2wire SIL EN User Manual

Page 6

Advertising
background image

If the ratio of the internal diagnostics test rate of the measuring
system to the demand rate exceeds the value 100, the
measuring system can be treated as if it is executing a safety
function in the mode with low demand rate (IEC 61508-2,
7.4.3.2.5).

An associated characteristic is the value PFD

avg

(average

Probability of dangerous Failure on Demand). It is dependent
on the test interval T

Proof

between the function tests of the

protective function.

Number values see chapter "Safety-related characteristics".

If the "low demand rate" does not apply, the measuring system
as safety-relevant subsystem in "high demand mode" should
be used (IEC 61508-4, 3.5.12).

The fault tolerance time of the complete system must be higher
than the sum of the reaction times or the diagnostics test
periods of all components in the safety-related measurement
chain.

An associated characteristic is the value PFH (failure rate).

Number values see chapter "Safety-related characteristics".

The following assumptions form the basis for the implemen-
tation of FMEDA:

l

Failure rates are constant, wear of the mechanical parts is
not taken into account

l

Failure rates of external power supplies are not taken into
account

l

Multiple errors are not taken into account

l

The average ambient temperature during the operating
time is 40 °C (104 °F)

l

The environmental conditions correspond to an average
industrial environment

l

The lifetime of the components is around 8 to 12 years
(IEC 61508-2, 7.4.7.4, remark 3)

l

The repair time (exchange of the measuring system) after
an nondangerous malfunction is eight hours (MTTR = 8 h)

l

The processing unit can interprete "fail low" and "fail high"
failures as errors and trigger a suitable error message

l

The scanning interval of a connected control and pro-
cessing unit is max. 1 hour, in order to react to dangerous,
detectable errors

l

Existing communication interfaces (e. g. HART, I²C-Bus)
are not used for transmission of safety-relevant information

High demand mode

Assumptions

6

OPTISWITCH series 3000 • - two-wire

Functional safety

32745

-EN

-080414

Advertising