HYDAC Centralita AEM 04 2016
HYDAC Centralita AEM 04 2016
HYDAC ELECTRONIC
Functional
Safety for
Electronic
Control
Agenda
Relevant standards
System design
Software design
Automatisation
Quelle/Source:: H. Hieronymus, CLAAS SE GmbH, VDI-Tagung 2012 Quelle/Source: H. Einig, Wirtgen GmbH, VDI-Tagung 2012
Functional Safety
Diagnosis
DO 178B / 254 ISO 26262 ISO 25119 EN ISO 13849 IEC 61508
SIL PL
Safety Integrity Level Performance Level
EN 62061 (IEC 61508) EN 13849-1
10-8
3 e
10-7
Safety
2 d
10-6
3x10-6
c
1
10-5 b
a
10-4
SIL or PL ?
(6) Verification
(7) Validation
Assessment
S: severity of injury:
H&R F: frequency and / or duration
of exposure to danger:
Machine
function
P: probability of avoiding the
Analysis exposure
Risk Graph:
Required risk minimisation and Performance Level:
Severity of injury:
S1 slight (usually reversible injury)
S2 serious (usually irreversible injury which may include death)
Channel
PL column chart
PL column chart
Example 1:
Performance Level
„PL d“ for a
machine function is
required
PL column chart
Example 1:
Performance Level
„PL d“ for a
machine function is
required
Category
Architecture / Design
Costs
MTTFd
Mean time to dangerous failure
Note:
indicator of the quality of a component
MTBF
Meaning: Average period between failures
Scope of the directive: Valid for units which are intended to be repaired.
MTTFd
Meaning: Average period until dangerous failure occurs.
Scope of the directive: Valid for units (components, systems), used in
safety-critical systems.
B10
Meaning: Statistically expected value of the number of cycles,
in which 10% of the components have exceeded the defined
limits (switch delay, leakage, switch pressure, etc.) under the
defined conditions.
B10d
Meaning: Expected number of cycles in which 10% of the components
have had dangerous failures.
Product Safety & Compliance Seminar
April 19 - 20, 2016 Rosemont, IL
Functional Safety for Electronic Control
Sensors with increased safety and/or diagnostic functions
Example: Pressure Transmitter – HYDAC
Category B/1
Category 3
Category 2
2 CPUs monitor
one and another Actuator for
safety-critical
Supply applications
PWM
Sensor
MainCPU
Diagnosis
Current feedback
Diagnosis Monitoring
Release
Watchdog
FET monitoring
CPU Monitoring of
the PWM outputs
Periodic tests of
Diagnosis of safety- RAM, Flash, CPU-
relevant inputs Registers, Stack
storage
Product Safety & Compliance Seminar
April 19 - 20, 2016 Rosemont, IL
Functional Safety for Electronic Control
Challenges for complex electronic systems
Multi-Controller-Systems
Machine functions distributed over a number of controllers
HY-TTC 30SH HY-TTC 77 HY-TTC 90, HY-TTC 94 HY-TTC 200 HY-TTC 500 Family HY-TTC 30H HY-TTC 50 Family
14 Inputs, 14 Outputs 39 Inputs, 26 Outputs 28 Inputs, 20 Outputs 33 Inputs, 36 Outputs HY-TTC 580 36 Inputs, 60 Outputs 14 Inputs, 16 Outputs HY-TTC 50 20 Inputs, 20 Outputs
EN ISO 13849 EN ISO 13849 IEC 61508 & EN ISO 13849 IEC 61508 HY-TTC 540 52 Inputs, 44 Outputs HY-TTC60 28 Inputs, 20 Outputs
IEC 61508 & EN ISO 13849
HY-TTC 30XSH HY-TTC 30XSI HY-TTC 48XS HY-TTC 30X Family HY-TTC 36X HY-TTC 48X
14 Inputs, 14 Outputs 26 Inputs, 4 Outputs 28 Inputs, 20 Outputs HY-TTC 30XH 14 Inputs, 16 Outputs 26 Inputs, 16 Outputs 28 Inputs, 20 Outputs
EN ISO 13849 EN ISO 13849 HY-TTC 30XO 16 Inputs, 14 Outputs 26 Inputs, 16 Outputs
EN ISO 13849
HY-TTC 30XI 26 Inputs, 4 Outputs
Joystick with
function keys
Hardware switches
and buttons
for safety-relevant
operating functions
10,4’’ Touch Display
Machine configuration
Monitoring of the functions
Failure display and diagnosis
Convenience functions
System design
- Example -
Example:
Required: PLr c
Sensor
PL c PL c PL c
Example 1:
PL low =c
PL = b
N low =3
Example 2:
PL low =c
PL = c
N low =2
Category 2 design
HY-TTC 30XS-H
HY-TTC 30XS-I
HY-TTC 30S-H
HY-TTC 48XS
HY-TTC 200
HY-TTC 540
HY-TTC 580
HY-TTC 90
HY-TTC 94
HDA 4700
HDA 8700
HAT 1000
Funktionale
HLT 1000
HIT 1000
HLS 100
HLS 200
Sicherheit
Functional
safety
PL d
PL d
PL c
PL c
Kategorie
3 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2
Category
SIL 2
SIL 2
Diagnosefähig
Diagnosable