S5-115U Manual
14.3
Safety
14.3.1 Types of Failures
The nature of a failure is decided by the effect it has. A distinction is made between active and
passive failures, as well as fatal and non-fatal failures.
Example:
Control of function "F
Schematic
circuit diagram:
Pushbutton
•
o
Input
0
1
0
1
Depending on the job a control system has to do, active or passive failures can also be fatal faults.
Examples:
•
In a drive control system, an active failure results in the unauthorized starting of the drive.
•
In an indicating system, a passive fault can be fatal since it blocks the indication of a
dangerous operating state.
In all cases where the occurence of failures can result in severe material damage or even injury to
persons, i.e. where the failure may be dangerous or fatal, measures must be taken to enhance the
safety of the control system. In this connection, the relevant regulations and specifications must
be observed.
EWA 4NEB 811 6130-02b
Reliability, Availability and Safety of Electronic Control Equipment
"
x
Enabling signals
a
b
F
o
x
Control System
No fault
Active failure
Passive failure
Figure 14-3. Control of Function "Fx"
•
o
c
o
Output
No output command
Output command
Output command
No output command
14-5