FK Safety Manual E

Download as pdf or txt
Download as pdf or txt
You are on page 1of 20

MANUAL No. 6G16-012 Rev.

2
Published in Mar. 2016
Revised in Jun. 2016

FK Series

FK Series transducer
Safety Manual

 Be sure to read this manual thoroughly and understand the contents before
using this product.

 Keep this manual so that the operator can refer to it when needed.

SHINKAWA Sensor Technology, Inc.


Safety Manual Table of Contents

<Table of Contents>

Chapter 1 Introduction ............................................................................4


1.1 Terms and Abbreviations .......................................................................................................................4
1.2 Acronyms ..............................................................................................................................................5
1.3 Product Support.....................................................................................................................................5
1.4 Related Literature ..................................................................................................................................5
1.5 Reference Standards ..............................................................................................................................6

Chapter 2 Product Description ...............................................................7


2.1 Hardware and Software Versions ..........................................................................................................7

Chapter 3 Designing a SIF Using a Manufacturer Product ...................8


3.1 Safety Function .....................................................................................................................................8
3.2 Environmental Limits ............................................................................................................................8
3.3 Application Limits ................................................................................................................................8
3.4 Design Verification................................................................................................................................9
3.5 SIL Capability .......................................................................................................................................9
3.5.1 Systematic Integrity ......................................................................................................................9
3.5.2 Random Integrity ..........................................................................................................................9
3.5.3 Safety Parameters .........................................................................................................................9
3.6 General Requirements .........................................................................................................................10

Chapter 4 Installation and Commissioning.......................................... 11


4.1 Installation ........................................................................................................................................... 11
4.2 Connections ......................................................................................................................................... 11

Chapter 5 Operation and Maintenance.................................................12


5.1 Proof Test without Automatic Testing .................................................................................................12
5.2 Proof Test Alternative..........................................................................................................................12
5.3 Repair and Replacement......................................................................................................................13
5.4 Useful Life ..........................................................................................................................................13
5.5 Manufacturer Notification ...................................................................................................................13

Chapter 6 Revision History ...................................................................14

Appendix A - START-UP CHECKLIST ................................................................................................ 15


Appendix B - HARDWARE DOCUMENTS VERSIONS...................................................................... 16
Appendix C - HARDWARE AND SOFTWARE VERSIONS ................................................................ 17

3
Safety Manual Chapter 1 Introduction

Chapter 1 Introduction
This Safety Manual provides information necessary to design, install, verify and maintain a Safety Instrumented
Function (SIF) utilizing the FK Series Eddy-Current Transducers. This manual provides necessary user
information and requirements for meeting the IEC 61508 and/or IEC 61511 functional safety standards.

1.1 Terms and Abbreviations


Safety Freedom from unacceptable risk of harm
Basic Safety The equipment must be designed and manufactured such that it protects
against risk of damage to persons by electrical shock and other hazards and
against resulting fire and explosion. The protection must be effective under
all conditions of the nominal operation and under single fault condition
Functional Safety The ability of a system to carry out the actions necessary to achieve or to
maintain a defined safe state for the equipment / machinery / plant /
apparatus under control of the system
Safety Assessment The investigation to arrive at a judgment - based on evidence - of the safety
achieved by safety-related systems
Element Part of a subsystem comprising a single component or any group of
components that performs one or more element safety functions
Fail-Safe State State of the process when safety is achieved; <<describe the fail safe state;
usually de-energized state on fault detection>>
Fail Safe Failure that causes the <<product>> to go to the defined fail-safe state
without a demand from the process
Fail Dangerous Failure that does not permit the SIF to respond to a demand from the
process (i.e. being unable to go to the defined fail-safe state).
Fail Dangerous Undetected Failure that is dangerous and that is not being diagnosed by automatic
testing.
Fail Dangerous Detected Failure that is dangerous but is detected by automatic testing.
Fail Annunciation Undetected Failure that does not cause a false trip or prevent the safety function but
does cause loss of an automatic diagnostic and is not detected by another
diagnostic.
Fail Annunciation Detected Failure that does not cause a false trip or prevent the safety function but
does cause loss of an automatic diagnostic or false diagnostic indication.
Fail No Effect Failure of a component that is part of the safety function but that has no
effect on the safety function.
Low demand mode Mode where the safety function is only performed on demand, in order to
transfer the EUC into a specified safe state, and where the frequency of
demands is no greater than one per year and no greater than twice the proof
test frequency.
High demand mode Mode where the safety function is only performed on demand, in order to
transfer the EUC into a specified safe state, and where the frequency of
demands is greater than one per year or greater than twice the proof test
frequency.
Continuous Mode Mode where the safety function maintains the EUC in a safe state as part of
normal operation.

4
Safety Manual Chapter 1 Introduction

1.2 Acronyms
EUC Equipment Under Control
FMEDA Failure Modes, Effects and Diagnostic Analysis
HFT Hardware Fault Tolerance
MOC Management of Change. These are specific procedures to follow for any
work activities in compliance with government regulatory authorities or
requirements of a standard.
PFDavg Average Probability of Failure on Demand
PFH Probability of Failure per Hour
SFF Safe Failure Fraction, the fraction of the overall failure rate of an element
that results in either a safe fault or a diagnosed dangerous fault.
SIF Safety Instrumented Function, a set of equipment intended to reduce the
risk due to a specific hazard (a safety loop).
SIL Safety Integrity Level, discrete level (one out of a possible four) for
specifying the safety integrity requirements of the safety functions to be
allocated to the E/E/PE safety-related systems where Safety Integrity Level
4 is the highest level and Safety Integrity Level 1 is the lowest.
SIS Safety Instrumented System – Implementation of one or more Safety
Instrumented Functions. A SIS is composed of any combination of
sensor(s), logic solver(s), and final element(s).

1.3 Product Support


Product support can be obtained from:
SHINKAWA Sensor Technology, INC.
4-22, Yoshikawakogyodanchi, Higashihiroshima-shi, Hiroshima 739-0153, JAPAN
Phone:+81-82-429-1118 FAX:+81-82-429-0804

1.4 Related Literature


Hardware Documents:
● Model FK-202F Transducer Instruction Manual : MANUAL No.6G14-062
● Model FK-452F Transducer Instruction Manual : MANUAL No.6G14-064
● Model FK-302F Transducer Instruction Manual : MANUAL No.6G14-066
● Model FK-302F Transducer (15m System) Instruction Manual : MANUAL No.6G14-068
● Model FK-602F Transducer Instruction Manual : MANUAL No.6G14-070
● Model FK-143F Transducer Instruction Manual : MANUAL No.6G15-042
● Model FK-263F Transducer Instruction Manual : MANUAL No.6G14-074
* See Appendix B for the latest version.

5
Safety Manual Chapter 1 Introduction

Guidelines/References:
● Practical SIL Target Selection – Risk Analysis per the IEC 61511 Safety Lifecycle,
ISBN 978-1-934977-03-3, exida
● Control System Safety Evaluation and Reliability, 3rd Edition, ISBN 978-1-934394-80-9, ISA
● Safety Instrumented Systems Verification, Practical Probabilistic Calculations,
ISBN 1-55617-909-9, ISA
● Failure Modes, Effects and Diagnostic Analysis, SST 15/09-121 R001 Version 2 Revision 1

1.5 Reference Standards


Functional Safety

● IEC 61508: 2010 Functional safety of electrical/electronic/ programmable electronic safety-related


systems

● IEC 61511:2003 Functional Safety – Safety Instrumented Systems for the Process Industry Sector (or
ISA 84.00.01 if it is more appropriate)

6
Safety Manual Chapter 2 Product Description

Chapter 2 Product Description


The FK Series Eddy-Current Transducers are eddy current type non-contact displacement/vibration transducers,
user for measuring Shaft Vibration Axial Position, Rotating Speed and Phase Mark (Phase Reference) from
small rotating machinery to large critical machinery such as turbines and compressors in plants.
See Instruction Manual for additional setup and configuration details.

Figure 1 FK Transducer, Parts included in the FMEDA

Table 2 gives an overview of the different models of the FK Transducer.


FK-202F 0.25mm to 2.25mm measuring range
FK-302F 0.25mm to 3.25mm measuring range
FK-452F 0.5mm to 5.0mm measuring range
FK-602F 0.5mm to 6.5mm measuring range
FK-143F 3mm to 16.5mm measuring range
FK-263F 3mm to 29mm measuring range

2.1 Hardware and Software Versions


For hardware and software versions, refer to Appendix C.

7
Safety Manual Chapter 3 Designing a SIF Using a Manufacturer Product

Chapter 3 Designing a SIF Using a


Manufacturer Product
3.1 Safety Function
The product will sense vibration, temperature, etc. within the stated safety accuracy of 30%(SCF error/Only
FK-202F,FK-302F,FK-452F), 10%(Drift).
When internal dangerous faults are detected, the product output moves to its fail-safe state.
When de-energized, the FK Series Eddy-Current Transducers moves to its fail-safe position.
The FK Series Eddy-Current Transducers is intended to be part of a SIF subsystem as defined per IEC 61508
and the achieved SIL level of the designed function must be verified by the designer.
The worst case diagnostic interval time to complete all diagnostics is 0.5 sec.
The FK Series Eddy-Current Transducers can operate in low demand modes.

3.2 Environmental Limits


The designer of a SIF must check that the product is rated for use within the expected environmental limits.
Refer to the SHINKAWA Sensor Technology, Inc. FK Series Eddy-Current Transducers Brochure for
environmental limits.

3.3 Application Limits


The FK Series Eddy-Current Transducers performs non-contact measurement of the distance (gap) between the
FL sensor and the measured object (target), and outputs a voltage signal corresponding to the gap.
By combining The FK Series Eddy-Current Transducers with our monitor, it is possible to measure the vibration
of a rotating shaft, its eccentricity, thrust position, rotating speed etc. The unit is utilized for continuous
measurement or monitoring of shafts rotating at high speeds, in turbines, generators, compressors, etc.
The FK Series Eddy-Current Transducers is not designed for use in any other applications.
Decommissioning and disposal considerations for the product due are listed in installation manual. Please
contact us if there is anything you do not understand about disposal.

8
Safety Manual Chapter 3 Designing a SIF Using a Manufacturer Product

3.4 Design Verification


A detailed Failure Mode, Effects, and Diagnostics Analysis (FMEDA) report is available from SHINKAWA
Sensor Technology, Inc. This report details all failure rates and failure modes as well as the expected lifetime.
The achieved Safety Integrity Level (SIL) of an entire Safety Instrumented Function (SIF) design must be
verified by the designer via a calculation of PFDAVG or PFH, considering safety architecture, proof test interval,
proof test effectiveness, any automatic diagnostics and worst case fault detection interval, average repair time
and the specific failure rates of all products included in the SIF. Each subsystem must be checked to assure
compliance with minimum hardware fault tolerance (HFT) requirements. The exida exSILentia® tool is
recommended for this purpose as it contains accurate models for the FK Series Eddy-Current Transducers and
its failure rates.
The failure rate data listed the FMEDA report are only valid for the useful life time of FK Series Eddy-Current
Transducers. The failure rates will increase sometime after this time period. Reliability calculations based on the
data listed in the FMEDA report for mission times beyond the lifetime may yield results that are too optimistic,
i.e. the required Safety Integrity Level will not be achieved.

3.5 SIL Capability

3.5.1 Systematic Integrity

The product has met manufacturer design process requirements of Safety Integrity Level (SIL) 2. These are
intended to achieve sufficient integrity against systematic errors of design by the manufacturer. A Safety
Instrumented Function (SIF) designed with this product must not be used at a SIL level higher than the
statement without “prior use” justification by the end user or diverse technology redundancy in the design.

3.5.2 Random Integrity

The FK Series Eddy-Current Transducers is a Type A Element. Therefore, based on the SFF between 60% and
90%, a design can meet SIL 2 @ HFT=0 (or SIL 3 @ HFT=1) when the FK Series Eddy-Current Transducers is
used as the only component in a SIF subassembly.
When the SIF consists of many components (Condition Monitor, etc.) the SIL must be verified for the entire
assembly using failure rates from all components. This analysis must account for any hardware fault tolerance
and architecture constraints.
3.5.3 Safety Parameters

For detailed failure rate information refer to the Failure Modes, Effects and Diagnostic Analysis Report for the
FK Series Eddy-Current Transducers.

9
Safety Manual Chapter 3 Designing a SIF Using a Manufacturer Product

3.6 General Requirements


The system’s response time shall be less than the process safety time. The FK Series Eddy-Current Transducers
will move to its safe state in less than 0.5 sec under specified conditions.
All SIS components including the FK Series Eddy-Current Transducers must be operational before process
start-up.
User shall verify that the FK Series Eddy-Current Transducers is suitable for use in safety applications by
confirming the FK Series Eddy-Current Transducers nameplate is properly marked.
Personnel using and performing maintenance and testing on the FK Series Eddy-Current Transducers shall be
competent to do so.
Results from the proof tests shall be recorded and reviewed periodically.
For details about maintenance and service, refer to the instructions manual of each module.

10
Safety Manual Chapter 4 Installation and Commissioning

Chapter 4 Installation and Commissioning


4.1 Installation
The FK Series Eddy-Current Transducers must be installed per standard practices outlined in the Installation
Manual.
The environment must be checked to verify that environmental conditions do not exceed the ratings.
The FK Series Eddy-Current Transducers location and placement must be accessible for physical and/or visual
inspection and allow for manual proof testing.

4.2 Connections
For details about connection, observe the descriptions in the instruction manual.

11
Safety Manual Chapter 5 Operation and Maintenance

Chapter 5 Operation and Maintenance


5.1 Proof Test without Automatic Testing
The objective of proof testing is to detect failures within FK Series Eddy-Current Transducers that are not
detected by any automatic diagnostics of the system. Of main concern are undetected failures that prevent the
safety instrumented function from performing its intended function.
The frequency of proof testing, or proof test interval, is to be determined in reliability calculations for the safety
instrumented functions for which FK Series Eddy-Current Transducers is applied. The proof tests must be
performed at least as frequently as specified in the calculation in order to maintain the required safety integrity
of the safety instrumented function.
The following proof test is recommended. The results of the proof test should be recorded and any failures that
are detected and that compromise functional safety should be reported to SHINKAWA Sensor Technology, Inc.

Table1: Recommended Proof Test

Step Action
1 Bypass the safety function and take appropriate action to avoid a false trip.
2 Inspect the sensor and transmitter for any visible damage or contamination.
3 Perform a two-point calibration of the transmitter over the full working range.
4 Remove the bypass and otherwise restore normal operation.

Table2: Recommended Proof Test Equipment

No. Name Model Maker


Calibration Kit VZ-35A SHINKAWA Sensor Technology
1
(FK-202F, FK-302F)
Calibration Kit VZ-30A SHINKAWA Sensor Technology
2 (FK-452F, FK-602F,
FK-143F, FK-263F)
3 Digital Multi Meter 34401A KEYSIGHT

This test will detect 99% of possible DU failures in the FK Series Eddy-Current Transducers.
The person(s) performing the proof test of a FK Series Eddy-Current Transducers should be trained in SIS
operations, including bypass procedures and company Management of Change procedures.
It is recommended that a physical inspection (Step 3 from Table 1) be performed on a periodic basis with the
time interval determined by plant conditions. A maximum inspection interval of 1 year is recommended.

5.2 Proof Test Alternative


Repair procedures in the FK Series Eddy-Current Transducers Installation, Operation and Maintenance manual
must be followed.

12
Safety Manual Chapter 5 Operation and Maintenance

5.3 Repair and Replacement


Repair procedures in the FK Series Eddy-Current Transducers Installation, Operation and Maintenance manual
must be followed.

5.4 Useful Life


The useful life of the FK Series Eddy-Current Transducers is about 50 years.

5.5 Manufacturer Notification


Any failures that are detected and that compromise functional safety should be reported to SHINKAWA Sensor
Technology, Inc. Please contact the sales office where you purchased the product.

13
Safety Manual Chapter 6 Revision History

Chapter 6 Revision History


Rev.No. Date Description
0 '16.03.01 First release
Corrected the P8 3.1 Safety Function
1 '16.06.06 Add to P11 Table2
Move the Hardware and Software Versions from P11 to Appendix B.
2 '16.06.13 Add the FMEDA report to P6 1.4 Related Literature

14
Safety Manual Appendix A- START-UP CHECKLISTS

Appendix A- START-UP CHECKLISTS


The following checklist may be used as a guide to employ the SHINKAWA Sensor Technology, Inc. in a safety
critical SIF compliant to IEC61508.

Verified
# Activity Result
By Date
Design
Target Safety Integrity Level and PFDavg determined
Design decision documented
Product compatibility and suitability verified
SIS logic solver requirements defined and documented
Routing of electrical connections determined
SIS logic solver requirements for proof tests defined and documented
SIS Design formally reviewed and suitability formally assessed
Implementation
Physical location appropriate
Electrical connections appropriate and according to applicable codes
SIS logic solver valve actuation test implemented
Maintenance instructions for proof test released
Verification and test plan released
Implementation formally reviewed and suitability formally assessed
Verification and Testing
Electrical connections verified and tested
SIS logic solver valve actuation test verified
Safety loop function verified
Safety loop timing measured
Bypass function tested
Verification and test results formally reviewed and suitability formally assessed
Maintenance
Safety loop function tested

15
Safety Manual Appendix B- HARDWARE DOCUMENTS VERSIONS

Appendix B- HARDWARE DOCUMENTS VERSIONS

# Name Document No. Revision


Model FK-202F Transducer Instruction Manual 6G14-062 7
Model FK-452F Transducer Instruction Manual 6G14-064 5
Model FK-302F Transducer Instruction Manual 6G14-066 3
Model FK-302F Transducer (15m System) 6G14-068 3
Instruction Manual
Model FK-602F Transducer Instruction Manual 6G14-070 3
Model FK-143F Transducer Instruction Manual 6G15-042 1
Model FK-263F Transducer Instruction Manual 6G14-074 3

16
Safety Manual Appendix C- HARDWARE AND SOFTWARE VERSIONS

Appendix C- HARDWARE AND SOFTWARE VERSIONS

Version
# Model
H/W S/W
FK-202F1 Oscillator circuit board:1F04-001-B001 Rev.4 -
Output circuit board:1F04-001-B002 Rev.5
FK-202F2 Oscillator circuit board:1F04-001-B003 Rev.4 -
Output circuit board:1F04-001-B004 Rev.5
FK-452F1,2 Oscillator circuit board:1F06-001-B001 Rev.1 -
Output circuit board:1F06-001-B002 Rev.2
FK-302F1 1F07-002-B003 Rev.3 -

FK-302F2 1F07-002-B004 Rev.3 -

FK-302F3 1F10-001-B001 Rev.3 -

FK-602F1 1F07-003-B003 Rev.3 -

FK-602F2 1F07-003-B004 Rev.3 -

FK-143F1 1F15-001-B001 Rev.0 -

FK-143F2 1F15-001-B002 Rev.0 -

FK-263F5 1F11-001-B003 Rev.2 -

FK-263F6 1F11-001-B004 Rev.2 -

17
Hiroshima Factory
4-22, Yoshikawakogyodanchi, Higashihiroshima-shi, Hiroshima
739-0153, JAPAN
Tel. +81-82-429-1118 Fax. +81-82-429-0804
[Quality Assurance Group] E-Mail : [email protected]

© 2014 SHINKAWA Sensor Technology, Inc. All rights reserved.

You might also like