HCBBS Forum (English)
Submit Chemical Projects / Find Solutions
Amplify Your Requirements on a Broader Chemical Platform *Engineering · Technology · Equipment · Solutions*
Submit Request

Essentials | The implementation and verification process of the Safety Instrumented Function SIF

2018-01-15View Original

Thread Content

SIF: yunrun.com.cn/news/1713.html Author: Jiang Ronghuai, Siemens (China) Co., Ltd. This article, in accordance with international safety standards IEC61508, IEC61511, and ANAI/ISA-84.00.01 (IEC61511 Mod), introduces the design methods for implementing Safety Instrumented Functions (SIF) through Safety Instrumented Systems (SIS) within the safety life cycle of the process industry; it also covers the evaluation and selection of functionally safe equipment, the achievement of SIL levels, and the verification of safety functions. The analysis phase is an important stage in the IEC61511 safety lifecycle. According to the Safety Instrumented Function (SIF) requirements specified in the safety requirements standards, properly designing the Safety Instrumented System (SIS), selecting appropriate functional safety devices, and verifying and validating the safety instrumented functions using diagnosis and testing techniques are all crucial aspects of this phase. This paper will, in conjunction with safety standards and specification requirements, mainly introduce the implementation and verification process of safety instrumented functions. 1. Implementation process of Safety Instrument Function (SIF): The design of the Safety Instrument Function (SIF) in a Safety Instrumented System (SIS) must be carried out in accordance with the Safety Instrument Requirements Specification (SRS). As a critical document for the safety lifecycle in IEC61511, the SRS contains a comprehensive list of all requirements for the design of safety instrumented functions (SIFs), including the following: ① Hazards and their consequences ; ②Probability of hazardous events ; ③Corresponding PID ; ④Process measurement parameters and trip points ; ⑤Response requirements for primary and auxiliary equipment ; ⑥The relationship between process measurement and output, including logic, algorithmic functions, and feasibility – defined for all operating modes, such as normal operation, normal conditions, abnormal conditions, emergency shutdown, etc ; ⑦Required safety integrity level ; ⑧Target testing cycle ; ⑨Maximum allowable no-parking rate ; ⑩Maximum response time requirement for SIF ; Requirements for manually starting SIF ; ⑪SIF reset requirement (locked or automatic reset) ; ⑫SIF response for fault diagnosis (automatic shutdown, only alarm, or other) ; ⑬Thermal machine interface requirements - Variable display and input ; ⑭Bypass maintenance capability requirements ; ⑮Average recovery after tripping; estimated restart time ; ⑯Environmental conditions for normal operation and emergency situations. In addition to the aforementioned inner cylinder, corresponding elements should also be added based on different applications and the various requirements of different industries. After confirming the SIF design objectives in the SRS, equipment selection, determination of redundancy requirements, SIF testing techniques, and verification calculations for the SIF should be carried out. The brief design process of SIF is shown in Figure 1. http://yunrun.com.cn/upload/201801/10/201801102357046978.png Figure 1: Brief design process of SIF. During the design phase, statistical calculations are used to verify whether the design meets the required SIL level. Verify that the calculations comply with the requirements of IEC61508 or ANSI/ISA 84.00.01; common calculation methods include fault trees, Markov models, etc. 2. Selection of safety instrumented function equipment: The equipment used for safety instrumented functions must meet all the requirements related to safety functions. In addition to choosing materials suitable for the specific process and ensuring they can withstand the environmental conditions, it is also necessary to evaluate the functional safety of such instruments. All design adjustments and changes must be documented as part of the project records. ANSI/ISA-84.00.01 requires that devices used in SIS be certified to achieve the required SIL level in accordance with IEC61508, or be used appropriately based on the principle of prior use (ANSI/ISA-84.00.01 Part 1, Section 11.5.3). Prior use is not defined in detail in the standards; it is generally assumed that if a certain version of a instrument has a history of successful use (without any dangerous failures) as documented in the user company’s records over many years, then that instrument can also be used for safety instrument functions without the need for safety certification. Prior Use requires that all field failures and failure modes during on-site use by the user be thoroughly documented. The documentation must include the hardware and software versions of the instrument. Changes in the designed version will render the Prior use data invalid. Many users request instrument manufacturers to provide assistance regarding prior use, and the manufacturers often entrust third-party companies or institutions to carry out assessments of different levels of prior use. These assessments are conducted by experts from such third-party companies or institutions (such as TüV, FM, or E*da), and typically the manufacturers require two or more assessment companies to work together to complete the evaluations. 3. Methods for functional safety assessment of products ① FMEDA assessment: The FMEDA assessment of instruments involves using FMEDA (Failure Modes, Effects, and Diagnostics) to conduct a hardware analysis of the instrument in order to identify its inefficiencies and failure modes. FMEDA is an extended application of traditional FMEA; safety engineers can use the data obtained through FMEDA analysis to conduct statistical calculations and verification calculations for Safety Instrumented Functions (SIF). The FMEDA analysis includes the lifecycle of the instrument as well as effective proof testing methods; the coverage rate of these proof tests is used in the actual calculation of PFH/PFD/PFDavg. It should be noted that FMEDA analysis cannot serve as a sufficient condition for selecting a product. ②Prior Use Evaluation: The initial purpose of Prior Use evaluation is to verify whether there are any defects in the product’s design by obtaining fault data from actual field applications. Although some manufacturers typically assist users by providing data and information on the prior use of a particular device, and some manufacturers also offer assessments of on-site failure records for a device conducted by third-party evaluation companies or institutions, the evaluation of prior use should be the responsibility of the end user. Fault data should include hardware and software faults, and the evaluation should cover the process of obtaining fault data as well as the process of modifying product versions. Manufacturers must provide sufficiently detailed information on the data acquisition process to ensure data quality. The methods of data acquisition, the completeness of the reports, and the validity of the analysis should be strictly examined. It should be noted that the failure rate calculated from the on-site failure record data should be compared with the data obtained from FMEDA analysis; if it is low enough compared to the FMEDA data, it proves that there are no major defects in the product’s design. Additionally, considering data integrity, the failure rate in field failure records cannot be used for the SIL verification calculations. ③A complete evaluation in accordance with IEC61508: A comprehensive IEC61508 evaluation includes FMEDA, prior use (Prior Usc), as well as measures for fault avoidance and fault control in the development of the product’s hardware and software. It also involves a detailed analysis of the product’s testing, modifications, user documentation, and manufacturing process. The fault data records in Prior Use often fail to reflect all fault data, especially system errors, such as software failures. Certain software faults can be resolved by software “resetting” or switching the power supply, without the need for a “replacement”; as a result, such software faults cannot be fully reflected in the repair and replacement reports provided by users to the manufacturer. A complete IEC61508 assessment ensures the reliability of system error data. IEC61508 defines various hardware and software techniques for fault avoidance and fault control aimed at reducing system errors. Especially in the IEC61508 certification of a product, the safety level applicable to that product is specified explicitly, such as SIL2 or SIL3. Table 1 briefly summarizes the evaluation principles adopted by different evaluation techniques. http://yunrun.com.cn/upload/201801/11/201801110015260026.png *It depends on the assessment agency; not all third-party agencies offer this service. 4. Redundant structure design: In addition to selecting appropriate equipment, the required level of safety can also be achieved through redundant design of subsystems. Table 2 shows the relationship between the minimum hardware fault tolerance (HFT) for field devices and the SIF level as specified in ANSI/ISA-84.00.01. http://yunrun.com.cn/upload/201801/11/201801110020418111.png Table 2 clearly shows that a higher SIL level can be achieved by increasing the hardware fault tolerance; for example, for input subsystems that require a SIL2 level as specified in the SIF, the design calls for the use of two transmitters ; For SIL3 input subsystems, 3 transmitters are required. If the selection of products is based on the Prior Use criterion and complies with the following restrictions. Then, under the same HFT conditions, one SIL level can be increased accordingly: ① The device is allowed to make only adjustments to process-related parameters (such as the measurement range, or the upper or lower limit failure thresholds) ; ②Process-related parameter adjustments have protective measures (such as passwords, etc.) ; ③The SIL level requirement for SIF is less than 4. As explained above, under certain constraints, one transmitter with Prior Use can also meet the SIL 2 requirements; alternatively, a transmitter that has been certified for SIL 2 can be used as well. For the Logic Processor subsystem, products certified under IEC51508 should generally be used, and the certified SIL level should be equal to or higher than the SIL level required in the SIF. Table 3 shows the relationship requirements specified in IEC61508 between the SIL level of Category B related logic processors and hardware fault tolerance (HFT). http://yunrun.com.cn/upload/201801/11/201801110026400460.png As can be seen from Table 3, if the SFF value is high enough, a higher safety level can be achieved without increasing HFT; for example, when SFF > 99%, a configuration with HFT=0 (single-channel structure) can still achieve SIL 3. 5. Testing techniques and methods for SIF: IEC61508 defines 3 operation modes for devices that perform SIF functions (Table 4): Continuous Demand mode, High Demand mode, and Low Demand mode. The relationship between these devices and the testing techniques varies depending on the operation mode in question. ①Continuous Demand mode: Since DI≤ATI and DI≤PTI, neither the manual verification tests nor the automatic diagnostic testing techniques have any impact on the single-channel system (loo1); these testing techniques are relevant only to redundant systems. ②High Demand operation mode: Since DI > ATI and DI ≤ PTI, the automatic diagnostic testing technique has an impact even on single-channel systems (1ool), whereas manual verification testing does not have such an impact. ③Low Demand mode: Since DI > ATI and DI > PTI, both manual verification testing and automatic diagnostic testing techniques will have an impact on the system, even in a single-channel system (1ool). In the process industry, the SIF is typically in Low Demand mode in most cases. This is especially the case when an independent protective layer is properly designed. 6. Verification of Safety Instrumented Function (SIF) Table 5 shows the relationship between the SIL level and the required average failure probability PFDavg under the Low Demand operation mode specified by IEC61508. http://yunrun.com.cn/upload/201801/11/201801110040425427.png The SIF verification for the Low Demand operation mode should include: defining verification test procedures ; The effectiveness of the verification test procedure is determined by estimating and verifying the diagnostic coverage. Specifically, the SIL level verification calculations for the SIF design should be carried out in accordance with the requirements of IEC61508 or ANSI/ISA 84.00.01, in order to confirm whether the final design of the SIF meets the design requirements specified in the SRS. The calculation methods include Fault Tree analysis, Markov Models, etc., and a verification report is provided in file format. Below, typical design and verification calculation results for SIL2 and SIL3 loop systems are briefly presented via examples. Example 1: The structure of a typical SIL2 circuit is shown in Figure 2. http://yunrun.com.cn/upload/201801/11/201801110110451177.png The SIL2 loop configuration and the results of the verification calculations are shown in Table 6. http://yunrun.com.cn/upload/201801/11/201801110130406676.png Note: In the example above, one TüV-certified SIL2 safety transmitter is used as the sensor sub-unit; alternatively, a Prior Use transmitter can be used, or 2 transmitters (1oo2) or 3 transmitters (2oo3) ; For the final component sub-unit, a DVC isolation valve with PST function was selected; alternatively, 2 isolation valves equipped with solenoid valves (1oo2) can also be used ; However, the final verification showed that the calculation results met the SIL2 level. Example 2: The typical SIL3 circuit configuration is shown in Figure 3. http://yunrun.com.cn/upload/201801/11/201801110105193150.png The SIL3 circuit configuration and verification calculation results are shown in Table 7. http://yunrun.com.cn/upload/201801/11/201801110126380590.png Note: In the example above, 2 TüV-certified SIL2 safe transmitters were used for the sensor sub-unit, while 2 DVC isolation valves with PST function were chosen for the final component sub-unit. It is also possible to use 2 Prior Use transmitters in the sensor sub-unit, or 3 transmitters (2oo3). However, the final verification showed that the calculation results met the SIL3 level. The selection and design of safety instrument systems and safety instrument functions are important components of the safety lifecycle in the process industry. To effectively reduce risks and ensure personal safety, property safety, and environmental safety, every stage of the safety lifecycle is crucial, whether it is the analysis phase or the implementation and operation phases. Only by referring to the relevant international standards and design requirements when using safety instrument systems can end-users, engineering companies, and design institutes effectively reduce risks and ensure personal safety, property safety, and environmental safety.
Reply #22019-10-04
Do you have a question bank for the certification exams for functional safety engineers? Thank you

Submit a Project

**Looking for Chemical Technology, Equipment & Solutions?** No Registration Required Broader Platform Exposure | Global Chemical Service Provider Connections

Submit Request — Free Consultation

Disclaimer

This is an automated machine translation of the original thread. Some technical terms may have inaccuracies; the original text shall prevail. Click "View Original" at the top right to access the source page, which supports IP-based automatic real-time language translation. Please watch out for contact details and sales inducements to prevent fraud. All content and translations are for reference only, representing solely the poster's personal views. For enquiries, email service@hcbbs.com.