Académique Documents
Professionnel Documents
Culture Documents
By Robin J Carver
EN 1050
(ISO 14121)
EN ISO 12100
EN 62061
EN 61508
Other Industry sectors
EN 60204-1
Design of safety related parts of machinery control systems
ISO 13849
To provide designers with an overall framework and guidance to enable them to produce machines that are safe. replaced EN 292
EN 60204
Application of electrical & electronic systems to machines to be updated in 2006
EN IEC 62061
Requirements for the design, integration & validation of Safety Related Electrical, Electronic & Programmable Electronic Control Systems for Machines.
EN 1050
General principles for Risk Assessment to be replaced by prEN ISO 14121
EN 60204
Application of electrical & electronic systems to machines to be updated in 2006
EN 954-1
Safety Related Parts of Control Systems may be replaced by prEN ISO 13849
Acceptance of electronic equipment in safety systems. Use of PLCs, Industrial Computers, etc. More complex safety requirements.
MACHINE
A machine with high inertia normally controlled by a speed controller with dynamic braking. Braking control lost when guard is opened
C
MOTOR GUARD SWITCH
LOAD
A machine with high inertia normally controlled by a speed controller with dynamic braking. Guard may not be opened until the motor has stopped
LOAD
The Problem!
I am a control systems engineer with 40 years in the industry working with safety related systems I am a Chartered Safety Practitioner
I have spent many hours, days, even weeks trying to understand the requirements. I have tried to apply the Standards.
Two Standards:EN 62061 Safety of Machinery Functional safety of E/E/PE Control Systems Scope specifies requirements and makes recommendations for the design, integration & validation of SRECSs for machines. prEN ISO 13841 Safety of Machinery Safety related parts of Control Systems Scope provides safety requirements & guidance on the principals for the design & integration of SRP/CSs including the design of application software.
Two Standards:EN 62061 Safety of Machinery Functional safety of E/E/PE Control Systems Safety requirements based on:SIL Safety Integrity Levels SIL1 (lowest) to SIL3 (highest possible for machinery) prEN ISO 13841 Safety of Machinery Safety related parts of Control Systems Safety requirements based on:PL - Performance Levels PL = a (lowest) to PL = e (highest)
prEN ISO 13849 Safety of Machinery Safety related parts of Control Systems
Lots of new words:PL - Performance Level MTTFd - Mean Time to Dangerous Failure DC - Diagnostic Coverage CCF - Common Cause Failure Category - Defining system architecture (as used in EN 954-1) SFF - Safe failure fraction
a b c d e
Start
Some safety relay manufacturers are claming MTTFd of:650 years (on a 7000 uses/year) and 950 years (on a 4000 uses/year)
But how do you determine DC%? What is the DC% of a relay with forced driven contacts? What is the DC% of a relay with forced driven contacts with a monitoring contact? What is the DC% of an Emergency Stop Button with redundant contacts? What is the DC of its associated wiring? etc. etc.
B
MTTFd Low Med
1
MTTFd Low MTTFd High Med
2
MTTFd MTTFd Low Med High Med Low
a b c d e
HIGH RISK
MTTFd
Low
DCavg = CCF =
None
None
Low
Med
Low
Med
High
Not relevant
65% or better
The MTTFd for each channel must be calculated The MTTFd for each system must be calculated
MTTF
DC
avg
DC = MTTF
1
+
d1
DC MTTF
2
+ ........ +
d 12
MTTF
+
d1
DC MTTF
n
dn
MTTF
+ ........ +
d2
MTTF
dn
DC
avg
DC = MTTF
1
+
d1
DC MTTF
2
+ ........ +
d 12
MTTF
+
d1
DC MTTF
n
dn
MTTF
+ ........ +
d2
MTTF
dn
UNSAFE MACHINERY!
SAFE MACHINERY!
To achieve this the Standards must:9Be clear 9Non-conflicting