Hydraulic/pneumatic drive Cylinder (machine actuator) Optoelectronics Light curtain (sensor) Electronics Control system Danger! Hydraulics/pneumatics Valves (actuators) Safety control SRP/CS subsystem a SRP/CS subsystem b subsystem c SRP/CS Focus of the standard on Functional Safety ISO 13849: Safety-Related Parts of a Control System (SRP/CS) 1 SRP/CS a SRP/CS b SRP/CS c 2 I L O I Input L Logic O Output 1 Start event (safety function request) 2 Machine drive element Pump (power unit) Hydraulic system: Focus of the standard ISO 4413 (pneumatic system: ISO 4414)
3 4 1 2 5 10 steps to performance level 6 10 7 9 8
Start Is there a type C standard for this machine? If yes, use it as a template. Determination of the limits of the machinery Hazard identification Risk estimation Risk evaluation Is the machinery safe? Yes Risk analysis End Risk assessment (ISO 12100) No Risk reduction measures Avoidance by: 1. inherently safe design 2. safeguarding 3. information for use
Risk reduction measures Avoidance by: 1. inherently safe design 2. safeguarding 3. information for use No Does the measure depend on a control system? Yes Safety function (SRP/CS) according to ISO 13849 ISO 13849 Risk reduction V t Residual risks (new hazards)? Assessment according to ISO 12100
Risk low F1 P1 PL r a Severity of injury (S) S1 S2 Slight (normally reversible injury) Serious (normally irreversible injury or death) S1 P2 b S2 F2 F1 P1 P2 P1 P2 b c c d Frequency and/or exposure to hazard (F) F1 F2 Seldom to less often and/or exposure time is short Frequent to continuous and/or exposure time is long F2 P1 d Possibility of avoiding hazard or limiting harm (P) P2 e P1 P2 Possible under specific conditions Scarcely possible Risk high
MTTF d low MTTF d medium MTTF d high 3 years 10 years 30 years 100 years Category B Category 1 Category 2 Category 3 Category 4 I L O I L O I L O I1 L1 O1 I1 L1 O1 TE O TE I2 L2 O2 I2 L2 O2 Performance Level a PFH d : 10 5 to < 10 4 [h 1 ] Performance Level b PFH d : 3 * 10 6 to < 10 5 [h 1 ] Performance Level c PFH d : 10 6 to < 3 * 10 6 [h 1 ] Performance Level d PFH d : 10 7 to < 10 6 [h 1 ] Performance Level e PFH d : 10 8 to < 10 7 [h 1 ] PFH d : Probability of a dangerous failure per (operating) hour I: Input L: Logic O: Output TE: Test equipment O TE : Test equipment output MTTF d : Mean time to dangerous failure Information on the DC values under Step 6
Which components are relevant for the safety function? Laser scanner F1 S1 Start 1A Dangerous movement Which hazards (dangerous movements) do exist? Cylinder! Which components prevent it? (Stop the movements)? Valves! What controls these components? Safety PLC! K1 1S3 Inputs Safety PLC Outputs 1V5 a K1 K1 1S3 1V4 K1 b 1V3 What triggers this function? Sensor! 1V5a 1V2 1Z2 K1 What tests this function, how, and how often? Position monitoring! What supports this function (safety principles)? Environmental conditions: Temperature, level, pressure, filter! 1M 1V3 M 3~ 1V5b 1V1 1P 1S1 1S2 1Z1
Sensors Logic Actuators 1V3 1V4 Channel 1 F1 K1 e.g., laser scanner (PL, PFH d ) Safety PLC (PL, PFH d ) 1V5 Channel 2 Diagnostic element 1S3 SRP/CS a SRP/CS b SRP/CS c
Failure rate of the detected dangerous failures Failure rate of the undetected dangerous failures Failure rate of the total dangerous failures 1/MTTFd
The right parameters for different technologies Hydraulic components Pneumatic components Hydraulic subsystems Electronic subsystems Supplier: MTTF d (B 10 ) Supplier: B 10 Supplier: PL r category (Valve: MTTF d ) Supplier: (certified product) PL (PFH d ) Category Machine manufacturer (OEM): Category DC CCF PL of the system Machine manufacturer (OEM): Category DC CCF PL of the system Machine manufacturer (OEM): DC CCF PL of the system Machine manufacturer (OEM): PL of the system (by addition of the PFH d values)
Specification of the safety functions Safety-related software specification Validation Validation Validated software System design Integration tests Module design Module tests Coding Verification Result
Requirement: PL r (steps 1 to 3) Design of the control system (steps 4 to 9) PL No PL PL r Yes Next safety function