Siemens SIMATIC HMI KP Series Operating Instructions Manual page 39

Table of Contents

Advertisement

Note
Our electronics are equipped with such safety engineering features so that 98% of the
maximum permissible probability of hazardous faults is due to all other components of the
safety function. This corresponds to the recommended load division in safety engineering
between sensing devices, actuating devices, and electronic switching for input, processing,
and output.
The probability of hazardous faults and the rate of occurrence of hazardous faults of a safety
function must comply with an upper limit determined by an SIL or PL. For a description of the
HMI device, refer to chapter "Technical specifications (Page 84)".
If you operate the HMI device with an EMERGENCY-STOP button, you must use a 2-
channel equivalent sensor switching - see chapter "Connect KP8F - fail-safe inputs
(Page 46)".
Proof-test interval
Note the following:
● They have a considerable safety responsibility for the instrumentation with sensors.
● Sensors normally do not survive a proof-test interval of 10 years corresponding with
IEC 61508.
The sensors clearly lose their safety.
Note
In order to reach the safety categories SIL3, PL e and category 4, high-quality sensors
are required. The sensors used must fulfill the standards IEC EN 60947-5-1:2004 and
IEC EN 60947-5-5:1997 (VDE 0660, section 200).
The contacts of the sensors must be weld-resistant in accordance with the standard
IEC EN 60947-5. Ensure the short-circuit-free connection of the emergency-stop button.
Define an ideal proof-test interval for the used sensor.
Fault detection
Faults can be detected if the following connection errors are present:
● When non-equivalent sensor signals are connected.
● When a single-channel sensor has a redundant connection.
No redundant connection of two single-channel break contacts
If sensor signals are connected redundantly (break contacts), a fault will only be
recognized if one of the sensors is triggered.
Ascertain that under no circumstances are two single-channel break contacts
redundantly connected as sensor signals.
KP8, KP8F
Operating Instructions, 10/2010, A5E03284305-01
WARNING
Planning the use
3.7 Requirements for fail-safe operation
39

Advertisement

Table of Contents
loading

Table of Contents