Safety data
The safety data for the Safe torque off function is given below.
Note:
The safety data is calculated for redundant use, and does not apply if both STO channels
are not used.
Life-
time
(a)
CCFHFTCat.
DC
(%)
MTTF
D
(a)
PFD
avg
(T
1
= 5
a)
PFD
avg
(T
1
= 2
a)
PFH
(T
1
=
20 a)
(1/h)
SFF
(%)
PLSC
SIL/SIL-
CL
Frame
size
208013≥9023970
1.1E-
06
4.5E-
07
5.0E-
11
>99e33R8i
208013≥9016330
1.3E-
06
5.5E-
07
6.2E-
11
>99e332×R8i
208013≥9012390
1.6E-
06
6.5E-
07
7.3E-
11
>99e333×R8i
208013≥909980
1.9E-
06
7.6E-
07
8.4E-
11
>99e334×R8i
208013≥908360
2.1E-
06
8.6E-
07
9.5E-
11
>99e335×R8i
208013≥907190
2.4E-
06
9.6E-
07
1.1E-
10
>99e336×R8i
208013≥906310
2.6E-
06
1.1E-
06
1.2E-
10
>99e337×R8i
208013≥905620
2.8E-
06
1.2E-
06
1.3E-
10
>99e338×R8i
3AXD10000078136 D
• The following temperature profile is used in safety value calculations:
•
670 on/off cycles per year with ΔT = 71.66 °C
•
1340 on/off cycles per year with ΔT = 61.66 °C
•
30 on/off cycles per year with ΔT = 10.0 °C
• 32 °C board temperature at 2.0% of time
• 60 °C board temperature at 1.5% of time
• 85 °C board temperature at 2.3% of time.
• The STO is a type B safety component as defined in IEC 61508-2.
• Relevant failure modes:
• The STO trips spuriously (safe failure)
• The STO does not activate when requested
• A fault exclusion on the failure mode “short circuit on printed circuit board” has been
made (EN 13849-2, table D.5). The analysis is based on an assumption that one
failure occurs at one time. No accumulated failures have been analyzed.
• STO reaction time (shortest detectable break): 1 ms
• STO response time: 2 ms (typical), 25 ms (maximum)
• Fault detection time: Channels in different states for longer than 200 ms
• Fault reaction time: Fault detection time + 10 ms
•
STO fault indication (parameter 31.22) delay: < 500 ms
200 The Safe torque off function