Additionally, the following parts may belong to the documentation, if applicable: • EU-type examination certificate • EU declaration of conformity • Attestation of conformity • Certificates • Control drawings • FMEDA report • Assessment report • Additional documents For more information about Pepperl+Fuchs products with functional safety, see www.pepperl-fuchs.com/sil.
Functional Safety HiC283* Introduction Safety Information Target Group, Personnel Responsibility for planning, assembly, commissioning, operation, maintenance, and dismounting lies with the plant operator. Only appropriately trained and qualified personnel may carry out mounting, installation, commissioning, operation, maintenance, and dismounting of the product. The personnel must have read and understood the instruction manual and the further documentation.
Functional Safety HiC283* Introduction Symbols Used This document contains symbols for the identification of warning messages and of informative messages. Warning Messages You will find warning messages, whenever dangers may arise from your actions. It is mandatory that you observe these warning messages for your personal safety and in order to avoid property damage.
Functional Safety HiC283* Product Description Product Description Function General This isolated barrier is used for intrinsic safety applications. The device transfers digital signals from NAMUR sensors or dry contacts from the hazardous area to the non-hazardous area. Via switches the mode of operation can be reversed and the line fault detection can be switched off.
2-channel devices: input I, input II, output I, output II • Non-safety relevant interfaces: power supply, fault output Note For corresponding connections see datasheet. Marking Pepperl+Fuchs Group Lilienthalstraße 200, 68307 Mannheim, Germany Internet: www.pepperl-fuchs.com HiC2831, HiC2832, HiC2831R1, HiC2832R1 Up to SIL 2 HiC2831R2, HiC2832R2, HiC2831R3, HiC2832R3...
Functional Safety HiC283* Planning Planning System Structure 3.1.1 Low Demand Mode of Operation If there are two control loops, one for the standard operation and another one for the functional safety, then usually the demand rate for the safety loop is assumed to be less than once per year.
Functional Safety HiC283* Planning Assumptions The following assumptions have been made during the FMEDA: • Failure rate based on the Siemens standard SN 29500. • Failure rates are constant, wear is not considered. • External power supply failure rates are not included. •...
Functional Safety HiC283* Planning Safety Function and Safe State Safe State The safe state of output I and output II is the high impedance state or the fault state. Safety Function HiC2831* Switch Position Function Output I and output II Normal mode of If a low current is present at input I, operation...
Page 13
Functional Safety HiC283* Planning Line Fault Diagnostics If the line fault detection is enabled (mandatory, see datasheet), the input circuit is monitored in all device versions. If a line fault is detected, the outputs change in the fault state (safe state). Note The fault indication output is not safety relevant.
Functional Safety HiC283* Planning Characteristic Safety Values Parameters Characteristic values Assessment type and Full assessment documentation Device type Mode of operation Low demand mode, high demand mode or continuous mode MTBF (HiC2831*) 154 years MTBF (HiC2832*) 120 years 99 % Safety function Inverse mode of operation Normal mode of operation...
Functional Safety HiC283* Planning Useful Lifetime Although a constant failure rate is assumed by the probabilistic estimation this only applies provided that the useful lifetime of components is not exceeded. Beyond this useful lifetime, the result of the probabilistic estimation is meaningless as the probability of failure significantly increases with time.
Functional Safety HiC283* Mounting and Installation Mounting and Installation Mounting and Installing the Device Observe the safety instructions in the instruction manual. Observe the information in the manual. Observe the requirements for the safety loop. Connect the device only to devices that are suitable for this safety application. Check the safety function to ensure the expected output behavior.
Functional Safety HiC283* Operation Operation Danger! Danger to life from missing safety function If the safety loop is put out of service, the safety function is no longer guaranteed. • Do not deactivate the device. • Do not bypass the safety function. •...
Page 18
Functional Safety HiC283* Operation Proof Test Procedure Prepare a test set-up, see figures below. Test the devices in the mode of operation they are used in. If necessary, change the configuration of the device. Verify the input and output values as given in table below.
Page 19
Functional Safety HiC283* Operation Termination Board Multimeter ( I ) Multimeter ( I ) Multimeter ( I ) Fault Supply + 24 V DC Zone 0, 1, 2 Zone 2 Power I supply Supply Div. 1, 2 Div. 2 supply Supply - Figure 5.1 Proof test set-up for HiC2831R1...
Page 20
Functional Safety HiC283* Operation Termination Board Multimeter ( I ) Multimeter ( I ) Multimeter ( I ) Fault Supply + 24 V DC Zone 0, 1, 2 Zone 2 Power I supply Supply Div. 1, 2 Div. 2 supply Supply - Figure 5.3 Proof test set-up for HiC2831, HiC2831R2, HiC2831R3, and HiC2831R5...
Page 21
Functional Safety HiC283* Operation Termination Board Multimeter ( U ) Multimeter ( I ) Multimeter ( I ) Multimeter ( U ) Multimeter ( I ) Fault Supply + 24 V DC Zone 0, 1, 2 Zone 2 power I supply Supply Div.
Report all failures in the safety function that are due to functional limitations or a loss of device function – especially in the case of possible dangerous failures. In these cases, contact your local sales partner or the Pepperl+Fuchs technical sales support (service line).
Functional Safety HiC283* List of Abbreviations List of Abbreviations Emergency Shutdown Failure In Time in 10 FMEDA Failure Mode, Effects, and Diagnostics Analysis Probability of safe failure Probability of dangerous detected failure Probability of dangerous undetected failure Probability of failures of components in the safety loop that have ...