Safety Measures - Siemens SIMATIC S5-115U User Manual

Simatic s5 series cpu 941-7ub11 cpu 942-7ub11 cpu 943-7ub11 and cpu 943-7ub21 cpu 944-7ub11 and cpu 944-7ub21
Table of Contents

Advertisement

Reliability, Availability and Safety of Electronic Control Equipment

14.3.2 Safety Measures

Single-Channel Configurations
In the case of single-channel programmable controllers, the means available for enhancing safety
are limited:
Programs or parts can be stored and executed more than once.
Outputs can be monitored per software by parallel feedback to inputs of the same device.
Diagnostic functions within the programmable control system, which bring the output of the
controller into a defined state (generally the FF state) when a failure occurs.
Failure characteristics of electromechanical and electronic control systems:
Relays and contactors pick up only if a voltage is applied to the coil. With such a control
element, therefore, active failures are less probable than passive failures.
In electronic control systems, however, the probability of both types of failure occurring
(active and passive) is approximately equal. The failing of an output transistor, for instance,
may cause this transistor to become either continuously non-conducting or continuously
conducting.
The safety of electronic control systems can therefore be enhanced as follows.
All functions not relevant to the safety of the plant are controlled electronically.
Functions that are relevant to the safety of the plant are implemented with conventional
control elements.
Multi-Channel Configurations
If the measures taken to improve safety in single-channel control systems are not sufficient to
satisfy safety requirements, electronic control systems should be designed as redundant,
i.e. multi-channel, systems.
Two-channel control systems
Both "channels" monitor each other mutually and the output commands are evaluated on a
"1-out-of-2" or "2-out-of-2" basis.
Typical PLC: S5-115F
This programmable controller consists of two submits that are identically programmed and
operate in clock synchronism; monitoring is implemented via two comparator modules.
Failures are displayed and the corresponding safety functions initiated.
Multi-channel control systems
Further voter systems (e.g. on the 2-out-of-3 principle) can be implemented by adding further
"channels".
14-6
S5-115U Manual
EWA 4NEB 811 6130-02b

Advertisement

Table of Contents
loading

Table of Contents