Professional Documents
Culture Documents
BR OR
2009 Machine Safety Market Leaders
P
OA TFO
DE LI
Vendor Market Share
ST O
Rockwell Automation #1
OMRON #2
Siemens #3
SICK #4
Pilz #5
SC
MOALA
S T BL E
Source Data: ARC Vendor Market Share
Invensys / Triconex Leader
Rockwell Automation #2
Honeywell #3
ABB #4
Hima #5
Rockwell Automation––The
RockwellAutomation Theworld
worldleader
leaderininthe
the$3B+
$3B+Safety
SafetyMarket*
Market*
Copyright © 2009 Rockwell Automation, Inc. All rights reserved. * Source ARC Machine Safety (2009) & Process Safety (2008) Market Studies 2
What is functional safety?
Performance Productivity
Sustainability
Time to market
Information Compliance
Development Costs Ops & Maintenance Costs
• How do we know
FT = Fault tolerant
FT = Fault tolerant
FT = Fault tolerant
• Do we need to know??
DC = Diagnostic Coverage
DC = Diagnostic Coverage
DC = Diagnostic Coverage
DC = Diagnostic Coverage
DC = Diagnostic Coverage
DC = Diagnostic Coverage
DC = Diagnostic Coverage
Some Standards not yet on OJ yet - but will be (EN 60204-1, EN 62061 etc)
For best info see: http://eur-lex.europa.eu/JOIndex.do
and
http://eur-lex.europa.eu/LexUriServ/LexUriServ.do?uri=OJ:C:2009:309:0029:0065:EN:PDF
Copyright © 2009 Rockwell Automation, Inc. All rights reserved. 36
New Machinery Directive
2006/42/EC
ISO EN 12100: Safety of machinery – Basic principles will be combined with EN ISO 14121: Risk
assessment -
No very significant changes
Published now:
IEC EN 62061: Safety of machinery - Functional safety of Electrical, electronic and programmable
electronic control systems – Published now
EN ISO 13849-1: Safety of machinery – Safety related parts of control systems – Transition
standard - Replaces EN 954-1 (the “Categories” standard) end of this year - Published now
IEC 61800-5-2 Power drive systems – Functional safety – Published now
Short term:
Common Annex to IEC EN 62061 and EN ISO 13849-1 – Clarification, questions answered, worked
calculation examples – IEC 62061-1/ISO TR 23849 Published now
IEC EN 60947-4-1 – Contactors – Functional safety data testing requirements being added –
Published now
IEC EN 60947-5-3: Proximity devices with defined behavior under fault conditions – Functional
safety requirements added – Published now
IEC EN 61508: Functional safety of Electrical, electronic and programmable electronic control
systems – Being revised – Safe failure fraction re-visited, safety manuals, new subsystem definition
– Published now
IEC 61131-6: Programmable logic controllers – Functional safety - Expected 2011
Longer term
Amalgamation of IEC EN 62061 and EN ISO 13849-1 – Approximately 5 years
Task Analysis
Risk Assessment
Safety Requirement Specification
Design & Implementation
Validation
Management, Competencies and
Organisation
Generic
IEC (EN) 61508
Functional safety of E/E/P
control systems SIL
l 5 -5
ica 4 7- -1
n 09 -5
a se 47
ec
h Noi 6 60
9
M EN/IEC 60204-1 I EC IE C
Machinery EN ISO 12100 Electrical EN ISO 13849
Safety of Safety of
Directive G u a rd I EC 6
machinery i ng machinery 2 0 61
2006/42/EC e rg IE
on Electrical C
Basic principles om 60
07
IE
equipment
Sl
ic 3
et c . . . .
et c . . . .
C
ips
60
t ri
EN/IEC 60204-1
43
ps
. . . ..
. . . ..
9
Previous versions used to state:
Clause 9.2.5.4.2
Where a category 0 stop is used for the emergency
stop function, it shall have only hardwired
electromechanical components. In addition, its
operation shall
not depend on electronic
logic (hardware or software) or on the
transmission of commands over a communications EN/IEC 60204-1
network or link. Current version now states:
And
Clause 11.3.4 Programmable electronic equipment Clause 9.4.1
shall not be used for Category 0 emergency stop The electrical control circuits shall have an appropriate level of
functions (see 9.2.5.4). safety performance that has been determined from the risk
For all other safety-related stop functions, the use
The requirements of
assessment at the machine.
of hardwired electromechanical components is
preferred (i.e. the function should not depend on the IEC 62061 and/or ISO 13849-1 ………………..shall
operation of programmable electronic equipment). apply.
PL
Performance
Level
S = Severity
F = Frequency
P = Probability
Contactor Motor
Requirements
• Basic Safety principles
Sensor
• Withstand expected influences Machine
Control
Contactor Motor
Requirements Guard
• interlock
Category B
switch
• Well tried components Machine
Control
• Well tried safety principles
Requirements
• Category B
• Well tried safety principles
• Functional check at start up and periodically
(on/off check) Now requires a test to demand ratio
Behaviour under fault conditions of >100:1
A fault occurring between the checks can cause a
loss of the safety function.
The structure and behaviour of the safety function under fault conditions
Designated Architecture Category 3 Typical implementation
Contactors with mechanically
linked contacts
Motor
Contactor monitoring
Guard Safety
Requirements interlock
switches
monitoring relay
• Category B
• Well tried safety principles
• Single fault does not cause a loss of safety
function
• Where practicable that fault should be detected Machine
Control
Motor
Guard
interlock
switches Contactor monitoring
Requirements Safety
monitoring
• Category B relays
• Well tried safety principles
• An accumulation of faults does not cause a loss
of safety function
Machine
Behaviour under fault conditions Control
Faults will be detected in time to prevent a loss of
safety function Fault Exclusion –
under the microscope!
Copyright © 2009 Rockwell Automation, Inc. All rights reserved. 50
EN ISO 13849-1 Safety of machinery — Safety related parts of control systems
MTTFd
Reliability (MTTFd –– Mean Time To Failure Dangerous of each channel )
Channel 1
Simplified into 4 ranges Both guard doors access the same hazard zone
• Can the system be designed simply using the • Are there complex safety functions e.g.
designated architectures ? depending on complex logic decisions?
• Will the system include technologies other • Will the system require validation to SIL e.g.
than electrical? machinery used in the process secor
If the answer to either question is YES If the answer to either question is YES
it is probably most appropriate to use it is probably most appropriate to use
You can choose the most suitable standard for your use
ISO EN 13849-1: 2008 is the usual choice
ISO TR 23849
IEC TR 62061-1
Recently Published
Fault exclusion
clarification
2. Fault Tolerance
5. Systematic Integrity
“Electronic” devices
Does not “wear” out.
Data is MTTFd (or PFH)
Failure related to a constant time
span independent of usage rate
The easiest way – But don’t! (unless you have PFH to spare!)
Combining subsystems with known PLs
PLe
Subsyste Nlow Achieved system
m PLlow PL
(Category 2
Architecture
Only)
Safety Output
Channel 1 linkage contacts Contactor 1
Switch channel 1
SmartGuard
600
Safety Output
Channel 2 linkage contacts Contactor 1
Switch channel 2
Data validation
Device
Documentation
Rockwell
Automation
SISTEMA
Data
Library
Technical
Report
launch SISTEMA
Safety Function 1
DC reduced
Safety Function 2
DC reduced
Safety Function 3
DC reduced
Safety Function 4
DC reduced
TLS SmartGuard
Safety Controller 100S
Guard locking
Safety Contactors
Interlocking Switch
Safety Function 1
Prevention of unexpected start-up
Safety Function 2
Guard locking