SAFETY INFORMATION (IN ENGLISH)
System requirements
The product holds a safety-related stop function that complies with the requirements for SIL3 according
to IEC61508:
The stop function deactivates all relays on the receiver when the stop button on the transmitter is
pressed. The stop function is available on all Tiger systems. The maximum delay of the stop function is
500 ms. The stop function complies with the requirements for SIL3 according to IEC61508 only when it
is a part of a complete end user system that complies with the requirements for SIL3 according to
IEC61508.
Connecting and controlling the safety function
The stop function controls the stop relays from the stop button. In order to comply with the
requirements for SIL3 according to IEC61508, the safety-related function shall use its corresponding
two relay output in an active redundant configuration in a safety-related application.
Measures for probability of hardware failures
Transmitter stop function
Probability of dangerous failure per hour
Fraction of total failure rate with dangerous and
detected consequence
Diagnostic coverage
Safe failure fraction
Common cause failure
Level of hardware fault tolerance
Proof test interval
Diagnostic test interval
Receiver stop function
Probability of dangerous failure per hour
Fraction of total failure rate with dangerous and
detected consequence
Diagnostic coverage
Safe failure fraction
Common cause failure
Level of hardware fault tolerance
Proof test interval
Diagnostic test interval
Radio communication between transmitter and
receiver
Probability of dangerous failure per hour
Stop function for a complete system*
Probability of dangerous failure per hour
* A complete system = transmitter + radio communication + receiver
PFHd= 8.5 FITs (=λdu)
λdd= 357 FITs
DC= 98.3%
SFF= 99.1 %
0 FIT
HFT = 1
10 years
Continuous
PFHd = 30.1 FITs (=λdu)
λdd = 685.0 FITs
DC = 96.9 %
SFF = 98.7 %
8.0 FIT
HFT = 1
10 years
Continuous
PFHd = 3.0 FITs
PFHd = 41.6 FITs(=λdu)
- 6 -