欢迎访问瑞昌明盛自动化设备有限公司官网!
关于我们 | 联系我们

+86 15270269218

您的位置:首页>>产品中心 >> foxboro

12E2-MX模块备件

型号: 12E2-MX  分类: foxboro
  • 12E2-MX
  • 12E2-MX
  • 12E2-MX
  • 12E2-MX


12E2-MX

附加系统文档
除本手册外,还提供了以下配置HIMax系统的文档
可用:
名称内容文件编号。
D=德语
E=英语
希马克斯
系统手册
模块化系统的硬件描述
系统
你好,801000 D
你好801001 E
认证试验报告1)试验原理,
安全要求、结果
用户手册
组件
单个组件的说明
通信手册安全以太网和标准协议HI 801 100 D
你好801101 E
SILworX一步
手册
使用SILworX进行工程设计,启动
启动、测试和操作HIMA
系统。
你好801102 D
你好801103 E
1) 仅随HIMax系统提供
表8:系统文档概述
这些文件在HIMA网站www.HIMA.com上以PDF文件的形式提供。
3.使用PES HIMax的安全概念
14页,共64页HI 801 003 E版本4.00
3.使用PES的安全概念
本章包含有关HIMax系统功能安全的重要通用条款。
ƒ安全性和可用性
ƒ对安全重要的时间参数
ƒ验证测试
ƒ安全要求
ƒ认证
3.1安全性和可用性
HIMax系统不会造成迫在眉睫的危险。
危险
安全相关自动化系统连接不当造成的人身伤害
或编程。
启动前检查所有连接并测试整个系统!
HIMA强烈建议尽快更换出现故障的模块。
使用替代故障模块的替换模块在没有操作员的情况下启动操作
行动它采用故障模块的功能,前提是相同类型或是
经批准的替代型号。
3.1.1计算PFD和PFH值
根据以下公式计算了HIMax系统的PFD和PFH值:
符合IEC 61508。
HIMA将根据要求提供PFD、PFH和SFF值。
已为HIMax系统定义了10年的验证测试间隔(离线验证测试,
见IEC 61508-4,3.8.5段)。
安全功能由安全相关回路(输入、处理单元、输出和输出)组成
HIMA系统之间的安全通信)满足上述要求
所有组合。
3.1.2自检和故障诊断
模块的操作系统在启动和运行期间执行若干自检
活动测试以下部件:
ƒ处理器
ƒ存储区(RAM、非易失性存储器)
ƒ看门狗
ƒ模块之间的连接
ƒI/O模块的各个通道
如果在这些测试期间检测到故障,则故障模块或故障通道
I/O模块关闭。如果测试在启动时检测到模块故障
模块,模块将不会开始工作。
在非冗余系统中,这意味着子功能甚至整个PES将关闭
向下在冗余系统内检测到故障的情况下,冗余模块或
冗余通道接管要执行的功能。
HIMax 3使用PES的安全概念
HI 801 003 E版本4.00共64页15页
所有HIMax模块均配备LED,以指示已检测到故障。这
允许用户在出现故障时快速诊断模块或外部接线中的故障
报道。
此外,用户程序还可用于评估报告的各种系统变量
模块状态。
将记录系统性能和检测到的故障的大量诊断记录
并存储在处理器模块或其他模块的诊断存储器中。
系统故障后,可以使用PADT读取记录的数据。
有关评估诊断消息的更多信息,请参阅系统中的“诊断”
手册(HI 801001 E)。
对于极少数不影响安全的部件故障,HIMax系统
它不提供任何诊断信息。
3.1.3 PADT
用户使用PADT创建程序并配置控制器。安全
PADT的概念支持用户正确执行控制任务。
PADT采取多种措施检查输入的信息。
3.1.4冗余
为了提高可用性,可以设置包含活动组件的系统的所有部分
冗余,如有必要,在系统运行时更换。
冗余不会损害安全性。即使系统部件损坏,SIL 3仍有保证
冗余使用。
3.1.5根据“通电跳闸”构建安全系统
道德原则
根据“通电跳闸”原则运行的安全系统,例如火灾报警
以及消防系统具有以下安全状态:
1.系统关闭时的安全状态。
2.按需输入的状态,即执行安全功能时。在这种情况下
致动器被激活。
在按照以下要求构建安全系统时,请遵守以下几点:
通电跳闸原理:
ƒ确保在危险情况下的安全功能。
ƒ检测故障系统部件和反应:
-失败通知

12E2-MX

12E2-MX模块备件

12E2-MX

Additional System Documentation In addition to this manual, the following documents for configuring HIMax systems are also available: Name Content Document no. D = German E = English HIMax System Manual Hardware description of the modular system HI 801 000 D HI 801 001 E Certified test report 1) Test principles, safety requirements, results Manuals for the Components Description of the individual components Communication Manual safeethernet and standard protocols HI 801 100 D HI 801 101 E SILworX First Steps Manual Use of SILworX for engineering, starting up, testing and operating the HIMA systems. HI 801 102 D HI 801 103 E 1) Only supplied with the HIMax system Table 8 Overview System Documentation The documents are available as PDF files on HIMA website at www.hima.com. 3 Safety Concept for Using the PES HIMax Page 14 of 64 HI 801 003 E Rev. 4.00 3 Safety Concept for Using the PES This chapter contains important general items on the fuctional safety of HIMax systems. ƒ Safety and availability ƒ Time parameters important for safety ƒ Proof test ƒ Safety requirements ƒ Certification 3.1 Safety and Availability No imminent danger results from the HIMax systems. DANGER Physical injury caused by safety-related automation systems improperly connected or programmed. Check all connections and test the entire system before starting up! HIMA strongly recommends replacing failed modules as soon as possible. A replacement module that is used instead of a failed one, starts operation with no operator action. It adopts the function of the failed module provided that is of the same type or is an approved replacement model. 3.1.1 Calculating the PFD and the PFH Values The PFD and the PFH values have been calculated for the HIMax systems in accordance with IEC 61508. HIMA will gladly provide the PFD, PFH and SFF values upon request. A proof test interval of 10 years has been defined for the HIMax systems (offline proof test, see IEC 61508-4, paragraph 3.8.5). The safety functions, consisting of a safety-related loop (input, processing unit, output and safety communication among HIMA systems), meet the requirements described above in all combinations. 3.1.2 Self-Test and Fault Diagnosis The operating system of the modules executes several self-tests at start-up and during operation. The following components are tested: ƒ Processors ƒ Memory areas (RAM, non-volatile memory) ƒ Watchdog ƒ Connections between modules ƒ Individual channels of the I/O modules If faults are detected during these tests, the defective module or the defective channel of the I/O module is switched off. If the tests detect a module fault while starting up the module, the module will not begin to operate. In non-redundant systems, this means that sub-functions or even the entire PES will shut down. In case of a detected failure within a redundant system, the redundant module or redundant channel takes over the function to be performed. HIMax 3 Safety Concept for Using the PES HI 801 003 E Rev. 4.00 Page 15 of 64 All HIMax modules are equipped with LEDs to indicate that faults have been detected. This allows the user to quickly diagnose faults in a module or the external wiring, if a fault is reported. Further, the user program can also be used to evaluate various system variables that report the module status. An extensive diagnostic record of the system's performance and detected faults are logged and stored in the diagnostic memory of the processor module or that of other modules. After a system fault, the recorded data can be read using the PADT. For more information on evaluating diagnostic messages, see "Diagnostics“ in the System Manual (HI 801 001 E). For a very few number of component failures that do not affect safety, the HIMax system does not provide any diagnostic information. 3.1.3 PADT Using the PADT, the user creates the program and configures the controller. The safety concept of the PADT supports the user in the correct implementation of the control task. The PADT takes numerous measures to check the entered information. 3.1.4 Redundancy To improve availability, all parts of the system containing active components can be set up redundantly and, if necessary, replaced while the system is operating. Redundancy does not impair safety. SIL 3 is still guaranteed even if system components are used redundantly. 3.1.5 Structuring Safety Systems in Accordance with the Energize to Trip Principle Safety systems operating in accordance with the 'energize to trip' principle, e.g., fire alarm and fire-fighting systems , have the following safe states: 1. Safe state in the event of system shutdown. 2. State entered on demand, i.e., when performing the safety function. In such a case, the actuator is activated. Observe the following points when structuring safety systems in accordance with the energize to trip principle: ƒ Ensuring the safety function in hazardous situations. ƒ Detection of failed system components and reaction: - Failure notification. - Automatic switching to redundant components, if necessary and possible. Ensuring the Safety Function The planner must make sure that the safety system is able to perform its safety function in hazardous situations. The safety function is performed when the safety system energizes one or several actuators and, as a consequence, a safe state is adopted, e.g., a fire compartment door is closed. A redundant structure of the safety system components can be necessary to ensure the safety function, refer to the System Manual (HI 801 001 E) for further details: ƒ Power supply of the controller. ƒ Components of the controller: HIMax modules. ƒ When relay outputs are used, HIMA recommends to configure the relay outputs and the actuators' power supply redundantly. Reason: - A relay output has no line monitorin



更多
查看更多 >>

推荐产品