beautypg.com

Safety-related characteristics, Safety-related characteristics 7.1 assumptions, 2 specific safety-related characteristics – KROHNE H250 M9 Safet V2 EN User Manual

Page 10

background image

7

SAFETY-RELATED CHARACTERISTICS

10

H250 M9

www.krohne.com

06/2013 - 4000656702 MA H250-M9 SIL R03

Safety-related characteristics

7.1 Assumptions

The following assumptions have been made during the Failure Modes, Effects and Diagnostic
Analysis of the variable-area flowmeter H250/M9 with switching contact output.

• Failure rates are constant, wear out mechanisms are not included.
• Propagation of failures is not relevant.
• The time to restoration after a safe failure is 8 hours.
• All modules are operated in low demand mode of operation.
• External power supply failure rates are not included.
• The stress levels are average for an industrial outdoor environment and can be compared to

the Ground Fixed classification of MIL-HNBK-217F.

Alternatively, the assumed environment is similar to:
IEC 60654-1, Class C (sheltered location) with temperature limits within the manufacturer´s
rating and an average temperature over a long period of time of 40°C.

• Humidity levels are assumed within manufacturer´s rating.
• Only the switching contact output is used for safety applications.

7.2 Specific safety-related characteristics

Under the assumptions described in 7.1 and the definitions given in section 4 the following tables
show the failure rates according to IEC 61508:

Based on the construction of the H250/M9 this device is specified as a type A device according to
IEC 61508 with a HFT (Hardware Failure Tolerance) = 0 and a classification as SIL (Safety
Integrity Level): 1.

1 The switching contact output is connected to a fail-safe NAMUR amplifier (e.g. Pepperl +
Fuchs KF**-SH-Ex1). Failure rates of the amplifiers are not included.

PFD

AVG

was calculated for three different proof test times using the Markov modeling.

The PFD

AVG

value in brackets mean, that the calculated PFD

AVG

values are within the allowed

range for SIL 2 according to table 2 of IEC 61508-1 but do not fulfil the requirement to not claim
more than 35% of this range, i.e. to be better than or equal to 3.50E-03.
The PFD

AVG

value (not in brackets) mean, that the calculated PFD

AVG

values are within the

allowed range for SIL 2 according to table 2 of IEC 61508-1 and do fulfil the requirement to not
claim more than 35% of this range, i.e. to be better than or equal to 3.50E-03.

System

SFF

T

PROOF

PFD

AVG

λ

SD

λ

SU

λ

DD

λ

DU

H250/M9

connected to a

standard switching

amplifier

54%

1 year

5.04E-04

0 FIT

81 FIT

55 FIT

115 FIT

5 years

2.52E-03

10 years

(5.03E-03)

H250/M9

connected to a fail-

safe switching

amplifier 1

57%

1 year

3.35E-04

0 FIT

50 FIT

55 FIT

77 FIT

5 years

1.67E-03

10 years

3.34E-03

MA_H250_M9_SIL2_R03_en_656702_PRT.book Page 10 Wednesday, June 26, 2013 9:08 AM