Additionally, the following parts may belong to the documentation, if applicable: • EU-type examination certificate • EU declaration of conformity • Attestation of conformity • Certificates • Control drawings • FMEDA report • Assessment report • Additional documents For more information about Pepperl+Fuchs products with functional safety, see www.pepperl-fuchs.com/sil.
Functional Safety K*D0-RSH-1.1E.1, HiC5863(Y1) Introduction Safety Information Target Group, Personnel Responsibility for planning, assembly, commissioning, operation, maintenance, and dismounting lies with the plant operator. Only appropriately trained and qualified personnel may carry out mounting, installation, commissioning, operation, maintenance, and dismounting of the product. The personnel must have read and understood the instruction manual and the further documentation.
Functional Safety K*D0-RSH-1.1E.1, HiC5863(Y1) Introduction Symbols Used This document contains symbols for the identification of warning messages and of informative messages. Warning Messages You will find warning messages, whenever dangers may arise from your actions. It is mandatory that you observe these warning messages for your personal safety and in order to avoid property damage.
The test input may not be used during normal operation. The test input may be used for test only. Note For corresponding connections see datasheet. Marking Pepperl+Fuchs Group Lilienthalstraße 200, 68307 Mannheim, Germany Internet: www.pepperl-fuchs.com KFD0-RSH-1.1E.1, KCD0-RSH-1.1E.1, HiC5863, HiC5863Y1 Up to SIL 3...
Functional Safety K*D0-RSH-1.1E.1, HiC5863(Y1) Planning Planning System Structure 3.1.1 Low Demand Mode of Operation If there are two control loops, one for the standard operation and another one for the functional safety, then usually the demand rate for the safety loop is assumed to be less than once per year.
Functional Safety K*D0-RSH-1.1E.1, HiC5863(Y1) Planning Assumptions The following assumptions have been made during the FMEDA: • Failure rates are constant, wear is not considered. • Failure rate based on the Siemens standard SN 29500. • The safety-related device is considered to be of type A device with a hardware fault tolerance of 0.
Functional Safety K*D0-RSH-1.1E.1, HiC5863(Y1) Planning SILCL and PL application • The standards IEC/EN 62061 and EN/ISO 13849-1 require that the safety device is implemented according to the idle current principle. As the device is implemented following the working current principle, no safety classification according to IEC/EN 62061 and EN/ISO 13849-1 was carried out.
Exception for HiCTB16-TRX-RAC-PL-IO16 Termination Board: Add 1.5 FIT to the overall failure rate for dangerous undetected failures. Recalculate the necessary safety relevant values for your safety evaluation. Contact Pepperl+Fuchs for information on using other termination boards. The SFF value was not calculated according to IEC/EN 61508-2.
Functional Safety K*D0-RSH-1.1E.1, HiC5863(Y1) Planning Useful Lifetime Although a constant failure rate is assumed by the probabilistic estimation this only applies provided that the useful lifetime of components is not exceeded. Beyond this useful lifetime, the result of the probabilistic estimation is meaningless as the probability of failure significantly increases with time.
Functional Safety K*D0-RSH-1.1E.1, HiC5863(Y1) Mounting and Installation Mounting and Installation Mounting and Installing the Device Observe the safety instructions in the instruction manual. Observe the information in the manual. Observe the requirements for the safety loop. Connect the device only to devices that are suitable for this safety application. Check the safety function to ensure the expected output behavior.
Functional Safety K*D0-RSH-1.1E.1, HiC5863(Y1) Operation Operation Danger! Danger to life from missing safety function If the safety loop is put out of service, the safety function is no longer guaranteed. • Do not deactivate the device. • Do not bypass the safety function. •...
Page 17
Functional Safety K*D0-RSH-1.1E.1, HiC5863(Y1) Operation Proof Test Procedure Disconnect the field circuit. Check the device as shown in the following tables. After check reset the device to the necessary settings. Connect the field circuit again. Check the correct behavior of the safety loop. Is the configuration correct? Test No.
Page 18
Functional Safety K*D0-RSH-1.1E.1, HiC5863(Y1) Operation Test No. Input or Test Input Output (mA) • ETS output (terminals 1, 2): shows < 10 = 24 V DC Test 1 between terminals 7+ and 8- • LED TST is flashing • ETS output (terminals 1, 2): shows <...
Page 19
Functional Safety K*D0-RSH-1.1E.1, HiC5863(Y1) Operation Test No. Input or Test Input Output (mA) • ETS output (terminals 1a, 5a): shows < 10 = 24 V DC Test between terminals 3b+ and 3a- • LED TST is flashing • ETS output (terminals 1a, 5a): shows < 10 = 24 V DC Test between terminals 4a+, and 3a-...
Report all failures in the safety function that are due to functional limitations or a loss of device function – especially in the case of possible dangerous failures. In these cases, contact your local sales partner or the Pepperl+Fuchs technical sales support (service line).
Functional Safety K*D0-RSH-1.1E.1, HiC5863(Y1) List of Abbreviations List of Abbreviations Emergency Shutdown Failure In Time in 10 Failure Mode, Effects, and Diagnostics Analysis FMEDA Probability of safe failure Probability of dangerous detected failure Probability of dangerous undetected failure ...