Fail Safe
Fail Safe
Fail Safe
Topics: Protecting and functional safety of control systems. Safety certification Safety and acceptable risk
according to IEC 61508. Safety integrity level (SIL). F-system. Internal security system. PLC F-programming.
Classification of hazardous areas (IEC 61 241). ATEX. Explosion-proof units. Safety Rules for designing
systems with PLC. Safety Integrated control concept.
All systems will fail eventually. A fail-safe design will minimize the damage to people and equipment.
International safety standards such as the IEC 61508the International Electrotechnical Commission standard
governs functional safety in programmable electronic systems.
Safety PLC-based systems are less prone than hardwired safety systems to nuisance trips that can unnecessarily
shut down a factory operation. And they are much easier and faster to troubleshoot, resulting in less machine or
process downtime.
Fail-safe controls (F-PLC) in process technologies.
What's in a name?
The name is Safety programmable logic controller (PLC) means a special class of PLC designed for use in safety
critical applications. Safety PLCs and associated safety networks can help boost productivity. The unit meets all of
the requirements for use in applications up to SIL 3 (Safety integrity level - SIL) according to IEC 61508.
Fail-safe controllers are used widely in manufacturing processes to protect both personnel and machinery in the
event of a fault or power failure. Until recently, this type of device had to be hardwired into a system.
Example. PLC S7 300F ( F systems) mean fail safe CPU and signal modules. Software blocks of safety integrated
software are TV certified. What exactly guarantee that one PLC S7 300F system is actually a fail safe system. Is it
enough that they are TUV certified.
Fig. 8 Tagged out controls in the control room of an abandoned power plant. (Contributed and licensed under the
GFDL by the photographer, Gregory Maxwell. {{GFDL}})
A wide variety of safety and facility products include stock signs, pipe markers, tags, warning labels, Arc Flash
signage, voltage/electrical/fiber optic markers, quality/inspection labels, on-demand print (Fig. ) and underground
hazard tapes (Fig. )
Fig.9 Lockout-Tagout
61508
Functional
Safety
of
II
1
2G
2
E
4
Ex
5
ib
6
IIC
7
T4
8
Directive 94/9/EC
:
I ()
II
3.
4.
E European CENELEC standards EN 50..../60079...
5.
Ex
6.
Ib
7.
II - < 60 J
8.
T2 - (300C)
Error detection of communication telegrams to the safety PLC Category 3 and 4 requires redundant monitoring
signals, so two inputs per device can be easily software configured to function together
The central layer of protection is the safety rated Controller which creates redundant evaluation of input and safety
commands for outputs. In order to provide the extreme level of reliability required the controller is designed to
detect single errors in the program execution and the electronic hardware as it executes the program logic. To
achieve this in the safety-oriented program, the S7 Distributed Safety package performs automatic safety checks and
links in additional redundant safety blocks for error recognition and handling. These control blocks create a level of
time bounded diverse logic that continuously monitors for software errors and hardware faults. When faults occur
the corresponding reactions keep the safety system in a safe state or switch it to a safe state by either bringing the
controller to a safe stop or sending shutdown.
The next layer encountered is the safe communication network (PROFISafe) that provides the reliability to insure
that data passed between the layers arrives correctly to the proper partner and is properly interpreted.
communication bus it actually accounts for less that 1% of the risk formula in the safety analysis. Key features of
the safety rated bus are fault detection, fault reaction and recovery. A high speed cyclic reading bus like PROFIBUS
provided several inherent features that made it a great candidate for the first choice of and open safety rated
communication bus.
Referenses
1.
2.
3.
4.
5.
6.
7.