欢迎访问瑞昌明盛自动化设备有限公司官网!
关于我们 | 联系我们

+86 15270269218

您的位置:首页>>产品中心 >> foxboro

12HFA51A42H模块备件

型号: 12HFA51A42H  分类: foxboro
  • 12HFA51A42H
  • 12HFA51A42H
  • 12HFA51A42H
  • 12HFA51A42H
  • 12HFA51A42H


12HFA51A42H

 

该步骤对于达到所需的SIL是必要的。
如果部件因故障不再冗余运行,则修理故障部件
必须尽早确保组件。
如果发生以下情况,则无需冗余设计安全系统部件:
如果安全系统发生故障,则可以通过其他方式达到所需的安全级别,例如:
在实施组织措施时。
故障系统组件的检测
安全系统识别出部件不工作,并激活
冗余组件。这是通过以下方式完成的:
ƒHIMax模块的自检。
ƒ带输入和输出模块的线路监测(短路和开路)。这个
必须相应地配置模块。
ƒ如果项目需要,监测致动器的额外输入。
3.2对安全重要的时间参数
这些是:
ƒ容错时间
ƒ看门狗时间
ƒ安全时间
ƒ响应时间
3.2.1容错时间(FTT)
容错时间(FTT)是过程的一个属性,描述了时间跨度
在此期间,该过程允许在系统状态变为正常之前存在故障信号
危险的
3.2.2资源看门狗时间
看门狗时间在配置资源属性的对话框中设置。这次是
运行循环的大允许持续时间(循环时间)。如果循环时间超过
在预设的看门狗时间内,处理器模块采用错误停止状态。
在确定看门狗时间时,必须考虑以下因素:
ƒ应用程序所需的时间,例如用户程序中一个周期的持续时间。
ƒ过程数据通信所需的时间。
ƒ同步冗余处理器模块所需的时间。
ƒ执行重新加载所需的内部时间。
资源范围的看门狗时间的设置范围
从6ms到大7500ms。
默认设置为200毫秒。
设置看门狗时间时,必须应用以下内容:看门狗的时间≤ ½*安全
时间
HIMax 3使用PES的安全概念
HI 801 003 E版本4.00共64页17页
为了确保足够的可用性,HIMA强烈建议以下设置:
2*看门狗时间+大CPU周期时间+2*I/O周期时间≤ 安全时间
如果无法对大CPU周期时间进行可靠评估,则必须确定安全时间
设置为:
3*看门狗时间+2*输入/输出周期时间≤ 安全时间
I/O周期时间等于2ms。
项目的看门狗时间由完整系统上的测试确定。在过程中
测试时,将所有处理器模块插入底板。系统在运行中运行
满载模式。
所有通信链路都在运行(安全以太网和标准协议)。
为了确定看门狗时间
1.为测试设置看门狗时间上限。
2.在大负载下使用系统。在该过程中
连接必须通过安全以太网和标准协议运行。频繁地
读取控制面板中的循环时间,并记录循环时间的变化或负载峰值
循环时间。
3.依次卸下并重新插入底板中的每个处理器模块。之前
卸下一个处理器模块,等待刚刚安装的处理器模块
同步插入。
i当处理器模块插入底板时,它会自动同步
利用现有处理器模块的配置。进行测试所需的时间
同步过程将控制器周期延长至大周期时间。
同步时间随着具有以下功能的处理器模块的数量而增加:
已经同步。
有关如何插入和卸下处理器模块的更多信息,请参阅
X-CPU 01(HI 801009 E)。
4.在非同步模块的诊断历史记录中,读取同步时间
在每个同步过程中从n个处理器模块到n+1个处理器模块,并记录下来。
大同步时间值用于确定看门狗时间。
5.从长同步时间+12毫秒计算小看门狗时间
备用+备用,用于记录循环时间的变化。
6.使用以下等式计算看门狗时间TWD:
TWD=.TSync+TMarg+TCom+TConfig+TLatency+TPeak,其中
为处理器模块的同步确定的TSync时间
TMarg安全裕度12毫秒
TCom配置的系统参数:Max.Com。时间片异步[ms]
t配置配置的系统参数:配置连接的大持续时间
[ms]
t配置的系统参数的持续时间:大系统总线延迟[µs]*4
TPeak:用户程序的观察负载峰值
该方程允许计算看门狗时间的合适值。
i在特定情况下,如上所述计算的看门狗时间可能太短,无法满足以下要求:
执行重新加载。
3.使用PES HIMax的安全概念
18页,共64页HI 801 003 E版本4.00
提示:确定的看门狗时间可用作安全以太网中的大循环时间
构型

12HFA51A42H

12HFA51A42H模块备件

12HFA51A42H

This step can be necessary to achieve the required SIL. If the components are no longer operating redundantly due to a failure, repair of the failed component must be ensured at the earliest opportunity. It is not required to design the safety system components redundantly if, in the event of a safety system failure, the required safety level can otherwise be achieved, e.g., by implementing organizational measures, . Detection of Failed System Components The safety systems recognizes that components are not functioning and activates the redundant components. This is done with ƒ Self-tests of the HIMax modules. ƒ Line monitoring (short-circuits and open-circuits) with input and output modules. The modules must be configured accordingly. ƒ Additional inputs for monitoring the actuators, if required by the project. 3.2 Time Parameters Important for Safety These are: ƒ Fault tolerance time ƒ Watchdog time ƒ Safety time ƒ Response time 3.2.1 Fault Tolerance Time (FTT) The fault tolerance time (FTT) is a property of the process and describes the span of time during which the process allows faulty signals to exist before the system state becomes dangerous. 3.2.2 Resource Watchdog Time The watchdog time is set in the dialog for configuring the resource properties. This time is the maximum permissible duration of a RUN cycle (cycle time). If the cycle time exceeds the preset watchdog time, the processor module adopts the error stop state. When determining the watchdog time, the following factors must be taken into account: ƒ Time required by the application, e.g., the duration of a cycle in the user program. ƒ Time required for process data communication. ƒ Time required to synchronize the redundant processor modules. ƒ Time internally required to perform a reload. The setting range for the watchdog time of the resource ranges from 6 ms to maximum 7 500 ms. The default setting is 200 ms. When setting the watchdog time, the following must apply: watchdog time ≤ ½ * safety time HIMax 3 Safety Concept for Using the PES HI 801 003 E Rev. 4.00 Page 17 of 64 i To ensure sufficient availability, HIMA strongly recommends the following setting: 2 * watchdog time + max. CPU cycle time + 2 * I/O cycle time ≤ safety time If no reliable assessment of the max. CPU cycle time can be made, the safety time must be set such that: 3 * watchdog time + 2 * I/O cycle time ≤ safety time The I/O cycle time is equal to 2 ms. The watchdog time for a project is determined by a test on a complete system. During the test, all the processor modules are inserted in the base plate. The system operates in RUN mode with full load. All communication links are operating (safeethernet and standard protocols). To determine the watchdog time 1. Set the watchdog time high for testing. 2. Use the system under the maximum load. In the process, all communication connections must be operating both via safeethernet and standard protocols. Frequently read the cycle time in the Control Panel and note down the variations or load peaks of the cycle time. 3. In succession, remove and reinsert every processor module in the base plate. Prior to removing one processor module, wait that the processor module that has just been inserted is synchronized. i When a processor module is inserted in the base plate, it automatically synchronizes itself with the configuration of the existing processor modules. The time required for the synchronization process extends the controller cycle up to the maximum cycle time. The synchronization time increases with the number of processor modules that have already been synchronized. For more information on how to insert and remove a processor module, refer to the X-CPU 01 (HI 801 009 E). 4. In the diagnostic history for the non synchronized module, read the synchronization time from n to n+1 processor modules in every synchronization process and note it down. The greatest synchronization time value is used to determine the watchdog time. 5. Calculate the minimum watchdog time from the longest synchronization time + 12 ms spare + spare for the noted variations of the cycle time. 6. Calculate the watchdog time TWD using the following equation: TWD = .TSync + TMarg + TCom + TConfig + TLatency + TPeak where TSync Time determined for the processor module's synchronization TMarg Safety margin 12 ms TCom The configured system parameter: Max. Com.Time Slice ASYNC [ms] TConfig The configured system parameter: Max. Duration of Configuration Connections [ms] TLatency The configured system parameter: Maximum System Bus Latency [µs] * 4 TPeak Observed load peak of the user programs This equation allows one to calculate a suitable value for the watchdog time. i In particular cases, the watchdog time calculated as described above might be too short for performing a reload. 3 Safety Concept for Using the PES HIMax Page 18 of 64 HI 801 003 E Rev. 4.00 TIP The determined watchdog time can be used as maximum cycle time in the safeethernet configuration, see Communication Manual (HI 801 101 E). 3.2.3 Watchdog Time of the User Program Since each user program has its own watchdog and watchdog time. The watchdog time for the user program cannot be set directly. To calculate the watchdog time for a user program, HIMax uses the resource-specific parameter Max. Watchdog Time and the parameter Maximum Number of Cycles. Refer to Chapter 10.2.3 and Chapter 10.2.11 for more details. Make sure that the calculated watchdog time is not greater than the resulting reaction time, which is required for the process portion processed by the user program. 3.2.4 Safety Time (of PES) The safety time is the maximum permissible time within which the PES must react to a safety requirement event. Safety requirement events include: ƒ Changes in input signals from process. ƒ Faults occurring in the controller. In HIMax controllers, the safety time can be set anywhere between 20 ms and 22 500 ms. Within the safety time of the controller, the self-test facilities detect whether there are any potentially dangerous faults. They trigger predefined fault reactions that set the faulty components to a safe state. When determining the safety time, the effects of the following factors must be taken into account: ƒ If input modules are used, consider the following: Time-on/time-off delay settings for input channels: enter maximum delay time setting in μs + 2* cycle time of the I/O module ƒ Noise blanking also needs time reserves. Choose a safety time that is long enough to account for the most significant factor mentioned above, but still lower than the FTT of the process. It is important not to neglect the sensor and actuator time parameters for the safety function. The safety time for the controller is: Safety time > 2 * watchdog time + maximum cycle time + 2 * cycle time of the I/O modules In the actual application, the user should measure the maximum cycle time by replacing a redundant processor module. Enter the maximum cycle time determined for the entire system into the above formula. The cycle time of the I/O modules is equal to 2 ms. This ensures maximum availability for the system. 3.2.5 Safety Time of the User Program The safety time for the user program cannot be set directly. To calculate the safety time for a user program, HIMax uses the resource-specific parameter Max. Safety Time and the parameter Maxi



更多
查看更多 >>

推荐产品