Section II-6
Section II-6
Section II-6:
Safety Instrumented System Design
Hazard Analyses
Safety Requirements Specification
Conceptual Design
Technologies
Architectures
Design Verification
Detail Design
1
Safety Lifecycle e ida .com
excellence in dependable automation
Conceptual
Detailed
Process Design Process Information
Event History
Identify
Potential Risks
Safety
Potential Hazards
e ida.com
Layers of Protection excellence in dependable automation
PROBE Tool
Lifecycle
e ida.com
FETCH Tool
Analyze Potential excellence in dependable automation
Requirements
Required? Exit
Allocation
Instrumented Function, Target SIL,
Safety
Yes Mitigated Hazards, Process parameters,
Logic, Bypass/Maintenance
Develop Safety requirements, Response time, etc
Specification
Select Relays, Fail-Safe Solid State, PLC, Safety
Technology PLC, Sensors, Final Elements
SRS Requirements
• The SRS should contain
– System scope and application environment
– Functional Requirements
– Safety Integrity Requirements
– Safety Requirements Allocation
• The SRS should contain these requirements for each safety
functional
– Selection of energize-to-trip or de-energize-to-trip
– Definition of the safe state
– Timing requirements (response time, process safety time, discrepancy
time)
– Relationship between inputs and outputs
3
CFSE Exam Preparation: Section II-6
4
CFSE Exam Preparation: Section II-6
SRS Requirements
5
CFSE Exam Preparation: Section II-6
Requirements Tracking
Priority Ptr. to Test spec.
Allocation or Ptr. to Design spec. and Ptr. to User
No. Requirement Criticality and Test
Responsible Implementation documents
Stability protocol
Ptr. to Source
Cycle time shall be essential – for the System test User
R1 CPU S/W no reference
less than 300 ms application clause no. documentation
SIOP DEP safety critical Marketing material
unlikely to change
6
CFSE Exam Preparation: Section II-6
7
CFSE Exam Preparation: Section II-6
8
CFSE Exam Preparation: Section II-6
Safety Case
Goals
Provide justification that a system or appliance is safe
Provide one document for many certification authorities
Safety project status is immediately visible
(field “Required activities”)
Offload the development team from compliance work,
can be done by safety experts
9
CFSE Exam Preparation: Section II-6
10
CFSE Exam Preparation: Section II-6
11
CFSE Exam Preparation: Section II-6
12
CFSE Exam Preparation: Section II-6
Safety
Requirements
Specification
Select Technology
Select
Architecture Safety System
Design
SIS Conceptual
Design Determine Test
Philosophy
Reliability
Evaluation
Performance
Target Met?
Yes
Proceed to Manufacture
13
CFSE Exam Preparation: Section II-6
CCM
I/O
I/O
I/O
I/O
I/O
I/O
I/O
I/O
I/O
Determine Test Solid State Logic
Philosophy
Conventional PLC
Safety PLC
Reliability
Evaluation How many, What type of FINAL ELEMENTS
Performance No
Target Met?
Yes, proceed
14
CFSE Exam Preparation: Section II-6
Relay Systems
Hardwired Logic, Inherently Fail-Safe Logic
Positives:
• Generally Fail-Safe if correct components and design limits are used.
• Low initial cost compared to big programmable systems
Negatives:
• Potentially high trip rate depending on the design
• Little or no diagnostics
• Gets complex fast and errors in setting up logic have higher potential
• Hard to re-program as this requires almost complete teardown and rebuild
• High cost of ownership from ongoing expenses
15
CFSE Exam Preparation: Section II-6
Programmable Systems
Positives:
• Flexible because many functions are built-in
• Modular with different types of I/O and logic
• High space density especially for complex systems
• Calculation capability for discrete and analog variables, full math capability
• Computer communications are part of the design
• Documentation Tools are the best with management of change assistance and
even maintenance assistance
Negatives:
• Safety - failure modes. Unless safety critical rated per IEC61508, be careful
• Software reliability is a potential problem especially for equipment not certified
safety critical
• Communication security may be an issue depending on implementation
16
CFSE Exam Preparation: Section II-6
Safety-Rated Transmitters
• High-level of self-diagnostics
Safety-Rated Valves
• High-level of self-diagnostics, acoustics
Neles Automation
Moore Industries
Trip-A-Larm
More coming….
18
CFSE Exam Preparation: Section II-6
2oo3
Reliability
Evaluation
1oo1D
Performance No
Target Met?
1oo2D
Yes, proceed
19
CFSE Exam Preparation: Section II-6
Safety System Design Create Safety
Select Red. Architecture Specification
Select Technology
1oo1 Select
+ Architecture
Sensor Controller
Final Element Determine Test
Philosophy
-
PFS (Safe) PFD (Dangerous)
Reliability
Evaluation
1oo1 0.02 0.01
Performance No
Target Met?
Yes, proceed
20
CFSE Exam Preparation: Section II-6
Create Safety
1oo2 Architecture
Specification
1oo2 +
Select Technology
Sensor Controller
Select
Sensor Controller Architecture
Final Element
-
Determine Test
PFS (Safe) PFD (Dangerous) Philosophy
Performance No
Using Simple Approximation Formulas - Target Met?
No Common Cause or ß = 2%
Yes, proceed
21
CFSE Exam Preparation: Section II-6
Create Safety
Specification
2oo2 +
Select
Sensor Controller
Final Element
Architecture
-
PFS (Safe) PFD (Dangerous) Determine Test
Philosophy
1oo1 0.02 0.01
1oo2 0.04 0.0001 .. 0.0003 Reliability
Evaluation
2oo2 0.0004 .. 0.0008 0.02
Performance No
Target Met?
Using Simple Approximation Formulas -
No Common Cause or ß = 2% Yes, proceed
22
CFSE Exam Preparation: Section II-6
+
A
Output Circuit 1
Logic Solver
Sensor Input Circuit Common Circuitry
C
Output Circuit 1
Logic Solver
Sensor Input Circuit Common Circuitry
No
All these conditions can be precisely
Performance
Target Met? Markov modeled
Yes, proceed
24
CFSE Exam Preparation: Section II-6
Quantitative Analysis / SIL Verification
Performance No
Target Met?
Yes, proceed
25
CFSE Exam Preparation: Section II-6
SENSOR PART LOGIC SOLVER FINAL ELEMENT PART
PART
27
CFSE Exam Preparation: Section II-6
1/PFD(t)
IEC61508
SIL 4
SIL 3
1/PFDavg
SIL 2
SIL 1
test period
time
28
CFSE Exam Preparation: Section II-6
IEC61508
SIL 4
SIL 3
1/PFDavg
SIL 2
test
SIL 1 period
time
29
CFSE Exam Preparation: Section II-6
Create Safety
Specification
Select Technology
The Safety Lifecycle
Safety System Design
Select
Architecture
SIS Conceptual
Design
Determine Test
Philosophy
Reliability
Evaluation
Performance No
Target Met?
Yes
Proceed to Manufacture
30
CFSE Exam Preparation: Section II-6
Summary:
Safety Instrumented System Design
Safety Requirements Specification
Conceptual Design
Technologies
Architectures
Design Verification
31
CFSE Exam Preparation: Section II-6
Exercise 1
Safety Instrumented System Design
A PLC has a probability of failure for a one year time interval
[1/y] of 0.01. A switch has a probability of failure [1/y] of 0.05. A
solenoid valve has a probability of failure [1/y] of 0.1.
A system consists of two switches, a PLC and a solenoid valve.
Do the Fault Trees for the PFD and PFS for a proof test interval
of 1 year and the possible input evaluation schemes by the
controller.
32
CFSE Exam Preparation: Section II-6
Exercise 2 The Safety Life Cycle
Safety System Design
Safety Instrumented System Design
Verify that a high pressure protection loop consisting of a
pressure switch and solenoid meet the SIL requirements of the SIF.
D
33
CFSE Exam Preparation: Section II-6
Exercise 3
Safety Instrumented System Design
Verify that a high pressure protection loop consisting of a
Transmitter, DCS, and solenoid meet the SIL requirements of the SIF.
D
34
CFSE Exam Preparation: Section II-6
Exercise 4
Safety Instrumented System Design
Verify that a high pressure protection loop consisting of a
Safety Transmitter, Safety PLC, and 1oo2 solenoid meet the SIL
requirements of the SIF.
D
35
CFSE Exam Preparation: Section II-6
Exercise 1 (Key)
Safety Instrumented System Design
A PLC has a probability of failure for a one year time interval
[1/y] of 0.01. A switch has a probability of failure [1/y] of 0.05. A
solenoid valve has a probability of failure [1/y] of 0.1.
System Failure
1oo2
FS =0.1112
0.0025
SW X SW Y PLC Sol
36
CFSE Exam Preparation: Section II-6
Exercise 1 (Key)
Safety Instrumented System Design
A PLC has a probability of failure for a one year time interval
[1/y] of 0.01. A switch has a probability of failure [1/y] of 0.05. A
solenoid valve has a probability of failure [1/y] of 0.1.
System Failure
2oo2
FS =0.1959
SW X SW Y PLC Sol
37
CFSE Exam Preparation: Section II-6
Exercise 2 (Key)The Safety Life Cycle
Safety System Design
Safety Instrumented System Design
Verify that a high pressure protection loop consisting of a
pressure switch and solenoid meet the SIL requirements of the SIF.
D
•There is no failure rate data for
Solenoid 2.40 x 10-6 failures per hour safe failure, so assume SFF = 0
Pressure switch 4.55 x 10-6 failures per hour •There is no redundancy, so fault
tolerance is 0
No Diagnostics, Test Interval – 1 year, SIL2 •Solenoids and pressure switch
are simple devices—Type A.
Meeting architectural constraint depends on
SFF. Architectural constraint: SIL 1
DSys = DSol + DSw = (2.40 x 10-6 + 4.55 x 10-6) f/hr = 6.95 x 10-6 f/hr
PdF = 1 – e-Dt = 1 – e(-6.95 x 10-6 x 8760) = 0.0591
PFDAVE ~ PdF / 2 = 0.0591 / 2 = 0.0295 RRF = 33.9 SIL 1
Test
PdF Interval
~ t – 1 year, SIL2
PdF1Sol ~ 2.40 x 10-6 x 8760 = 0.0210
PdF2Sol = PdF1Sol x PdF1Sol = 0.02102 = 0.000441
PdFSTrans ~ 0.1 x 10-6 x 8760 = 0.000876
PdFSPLC ~ 0.6 x 10-6 x 8760 = 0.005256
PdFSys = 1 – ( 1 – 0.000441 ) x ( 1 – 0.000876 ) x ( 1 – 0.005256 )
= 0.00657 42
CFSE Exam Preparation: Section II-6
Exercise 4 (Key)
Safety Instrumented System Design
Verify that a high pressure protection loop consisting of a
Safety Transmitter, Safety PLC, and 1oo2 solenoid meet the SIL
requirements of the SIF.
D