Thread Content
Please discuss the scope of application, real-world examples, or historical development of functional safety (the IEC61508 standard we often talk about). For instance, ESD is a system that relies on functional safety principles. I hope everyone will express their thoughts freely, participate actively, and valuable insights from those who take part in the discussion will be highly appreciated. Encourage originality
In May 2000, the International Electrotechnical Commission officially issued the IEC61508 standard, titled \"Functional Safety of Electrical/Electronic/Programmable Electronic Safety Systems\"; a corresponding standard in China is currently under development. The standard is divided into seven parts, covering more than 1,000 specifications. Systems composed of electrical and electronic components have been performing safety functions in many fields for years; computer-based systems are used for non-safety purposes in numerous areas, but they are also being employed more and more often for safety purposes. The current development of technologies such as computers and integrated circuits has penetrated all industrial sectors. The significant increase in computing power has completely transformed the control of factories and industrial processes, as well as security control strategies. For systems that include electronic and electrical equipment, as well as computer software and hardware, when they are to be used in areas related to personal and property safety, it is essential to provide standardized safety guidelines. IEC61508 establishes a fundamental evaluation method for the overall safety life cycle of electrical/electronic programmable electronic systems (E/E/PE) that serve safety functions and are composed of electrical/electronic/programmable electronic components. The goal is to propose a consistent and reasonable technical solution for electronic-based security systems, taking into account the integration of components within individual systems (such as sensors, communication systems, control devices, actuators, etc.) with the security system as a whole. The seven parts of IEC61508 are as follows: Part 1: General requirements, which describes the main concepts, organization, life cycle, documentation, evidence for guidance, and the definition of SIL. Part 2 outlines the requirements for electrical/electronic/programmable electronic safety systems, including those for equipment and systems; much of its content relates to the application of the identification methods in Part 7, which address random or systematic failures. Part 3 outlines the requirements for the software, describing methods to avoid failures, and is related to the appendix in Part 7. Part 4 is definitions and abbreviations. Part 5 provides some examples of methods for determining the safety integrity level. Part 6 includes the application guides for Parts 2 and 3. Part 7 provides the testing methods, brief annotations, and some references. (1) Basic definitions in IEC61508 1. Safety function A function implemented by the E/E/PE safety system, other technical safety systems, or external risk reduction measures, in order to achieve or maintain a safe state for the controlled equipment (EUC), in response to specified hazardous events. 2. Safety integrity The probability that a safety system will successfully perform the required safety functions under specified conditions and within a specified time frame. This definition focuses on the reliability of safety systems in performing their safety functions. In determining safety integrity, all factors that lead to unsafe conditions should be taken into account, such as random hardware failures, failures caused by software, and failures resulting from electrical interference. These types of failures, especially hardware failures, can be quantified using measurement methods, such as the failure rate in hazardous modes and system failures, or the probability of failures in safety protection systems operating under specified conditions. However, the safety integrity of the system also depends on many factors that cannot be quantified precisely and can only be considered qualitatively. 3.E/E/PE systems Systems used for control, protection, or monitoring based on electrical/electronic and programmable electronic devices, including all elements within such systems such as power supplies, sensors, all other input/output devices, and all communication means. 4. EUC (Equipment Under Control) Controlled equipment refers to devices, machines, apparatuses, or gear used in manufacturing, transportation, medical care, or other fields. 5. Acceptable risk Risk refers to the combination of the probability of harm occurring and the severity of that harm. Acceptable risk refers to the risk that is tolerable according to the standards of today’s society. 6. Safety There are no unacceptable risks. 7. Safety System (Safely-related-system): It serves two purposes: first, to carry out the required safety functions in order to achieve or maintain the safe state of the EUC; second, to ensure the necessary safety integrity for those required safety functions, either on its own or in conjunction with other E/E/PES safety systems, other technical safety systems, or external risk reduction measures. The safety system takes appropriate actions upon receiving commands to prevent the EUC from entering a dangerous state. The failure of safety systems is included among the factors that lead to specific hazardous events. Although there may be other systems with security functions, only those security systems are considered to meet the required permissible risk levels by relying on their own capabilities. Safety systems can be roughly divided into safety control systems and safety protection systems. A safety system can be an integral part of the EUC control system, or it can use sensors and/or actuators to interface with the EUC. It can meet the required safety integrity level by performing safety functions within the EUC control system, or it can use a separate/standalone system dedicated to safety purposes to carry out those functions. (II) Basic concepts of IEC61508 The IEC61508 standard requires that the consequences of random failures be quantitatively evaluated, with the validity being calculated using the Random Access Measurement System (RAMS) method. Quantifying system failures related to faults is useless; system failures should be avoided through organizational guidance or controlled through technical measures. 1. Concepts of risk and safety integrity 2. Contents of functional safety assurance Functional safety assurance mainly includes two aspects: failure identification and safety integrity level. (1) Failure detection. Failure means that a functional unit loses the ability to perform its function. Some functions are defined based on the behaviors that need to be achieved; when performing these functions, certain specific behaviors are not allowed, and the occurrence of such behaviors results in failure. Failure can be random, and such failure is usually caused by the wear and tear of hardware components. It could also be a system failure, which can occur in both hardware and software. Failure identification involves identifying the various causes of failure in different components and estimating the probability of system failure. (2) Safety Integrity Level (SIL) (safety integrity level). A discrete level used to specify the safety integrity requirements for the safety functions assigned to the E/E/PE safety system; the higher the safety integrity level of the safety system, the lower the likelihood of it failing to fulfill the required safety functions. IEC61508 specifies four safety integrity levels for systems, with SIL4 being the highest and SIL1 being the lowest. III. Functional Safety Assessment of Field Bus Systems (1) Functions Performed by Field Bus Systems The role of field bus systems is to enable communication; they consist of a set of hardware and software that allow for the exchange of information between two or more devices. During controlled processes, it should not propagate or generate errors that could lead to dangerous situations: it must be able to detect data errors, ensure the timely transmission of data, and maintain order in the transmission process to avoid chaos. At the same time, it should be possible to stay aware of potential fault conditions at all times, in order to avoid unnecessary security actions triggered by communication errors – such as stopping a process when it shouldn’t, or allowing it to continue operating despite a fault. (II) Methods for evaluating the safety functions of fieldbus systems To determine whether a system or subsystem can be used in safety applications and meets the IEC61508 standards, there are two approaches: one is to design a new system in accordance with the principles of IEC61508; the other is to use a system that has already been in use and proven to be safe, and verify it using the “proven in use” approach. The functional safety assessment of fieldbus systems generally adopts the second method. This is a concept of \"proven in use\". If a product or system is already in use, as long as the supplier has sufficient evidence to prove its safety, then the same product or system can be used in similarly safe applications in the future. The concept of “proven in use” proposed in IEC61508 provides significant incentives for both suppliers and users. Currently, all the major equipment suppliers in the world are beginning to obtain certifications for their products in this area. However, the “Proven in use” criterion actually has very strict requirements: (1) The Proven in use approach can only be applied to those functional and interface subsystems that meet the relevant requirements; (2) The operating conditions of the subsystem must be exactly the same as or very similar to those of the atomic system; (3) If the operating conditions of the subsystem differ, analytical and testing methods must be used to determine the level of functional safety integrity that the system can achieve, in order to ensure that it can be used in safety-related applications; (4) The declared failure rates must be supported by sufficient statistical data; (5) A sufficient amount of failure data must be collected; (6) Factors such as the complexity of the subsystem, its contribution to risk reduction, the potential consequences of subsystem failures on the entire system, and new designs must also be taken into consideration. IV. Factors to Consider When Users Choose a Fieldbus (I) Information to be Provided by the Supplier If a user intends to integrate a security system and is considering the use of a fieldbus, it is necessary to fully take into account the contribution of this fieldbus subsystem to the security integrity of the security system. To achieve this goal, system designers and integrators need to obtain some necessary information from fieldbus hardware and software suppliers. For example: (1) Documentation that provides a detailed explanation of functions, interfaces, application environments, etc ; (2) The possible failure rate of random hardware failures in each failure mode; (3) Diagnosis scope and diagnosis test interval; (4) Hardware failure tolerance; (5) Identification information required for hardware and software configurations; (6) Valid written documentation; (7) SIL level. (II) The relationship between the SIL of the fieldbus subsystem and the SIL of the entire system. It is important to note that the SIL level of the fieldbus subsystem does not represent the SIL of the entire control system. Once considering the SlL of the entire system, it is necessary to take into account all aspects of the system, including field devices and the application logic specific to a particular project. When they work together to perform security functions, all of these subsystems and devices are required to meet the SIL criteria for those functions; however, their combination does not necessarily enable achievement of the desired SIL, and in such cases SIL is not a concept that can be directly applied to a single subsystem or device. It’s actually quite simple to understand this: even if a subsystem or component with a high SIL level is installed incorrectly, the system will still fail. IEC61508 provides models and algorithms for the calculation and allocation of SlL values for safety systems. If the user’s organization has a functional safety assessment agency, it can calculate and evaluate the SLL of the system, its various subsystems, and components in accordance with the standard requirements; or it can ask a third party to carry out the evaluation and assign the SIL values. (III) Verification of the SIL level claimed by the supplier 1. Are the application conditions the same? Currently, the fieldbus systems of several companies have undergone IEC61508 certification; fieldbuses such as FF, WorldFIP, and Profibus have been certified by authoritative bodies and have achieved an SIL3 level. However, when choosing such a fieldbus, the user must consider whether the operating conditions under which this subsystem will be used are exactly the same as, or very similar to, those under which it was evaluated. If so, of course the SIL levels claimed by the suppliers are the same. If the operating conditions of the subsystems differ, analytical and testing methods are required to determine the possible SIL level of the system, in order to ensure that it can be used in safety-related applications. 2. Requirements for the independence of assessors or assessment organizations IEC61508 stipulates that those who conduct SIL level assessments of systems, subsystems, or devices must be relatively independent individuals or organizations. The independence level of the evaluators varies depending on the SIL level. For SIL1, only an independent individual within the same organization is required, while SIM requires an independent organization. As for the levels required for SIL2 and 3, they are influenced by additional factors such as system complexity, the novelty of the design, and the developer’s previous experience. There is also a special requirement, namely that the evaluator must possess qualified working capabilities.
The functional safety system I am currently working with is HIMA’s ESD system, rated at SIL3, for use in the petrochemical industry. It seems that the SIL certification process for current systems is rather chaotic. The evaluation of SIL levels is a systematic process that should normally be carried out after the system is completed, and it should cover all aspects of the functional safety system. But in China, it seems that as long as the control equipment has an SIL rating certification, it is assumed by default that the system also has the corresponding rating. There is a severe lack of experience in evaluating the SIL of systems. Furthermore, this situation is also related to the condition of the equipment; for example, a detailed quantitative assessment of SIL may require that the instruments or equipment in use have statistically determinable safety failure probabilities. However, it seems that few devices in China meet such requirements, and even fewer have obtained SIL certification. As a result, if certain uncertified devices or those lacking relevant statistical data are used in a system, it becomes very difficult to obtain certification for the system’s SIL level!
Functional safety was introduced in IEC61508 and 61511. For the instrumentation field, it primarily refers to Instrument Safety Functions (SIF). Whether a device requires SIF depends on a safety analysis of that device; if the analysis shows that other mechanical safeguards and warning functions are not sufficient to meet the requirements, then SIF should be implemented. SIF is implemented within the SIS system. An SIF should include three components: a sensing element, a logic controller, and a final actuator. The so-called SIL level is a discrete value representing safety requirements; the higher the required level of safety, the larger this discrete value is. For example, SIL3 represents a higher level, while SIL1 represents a lower level. So how can we determine whether the SIF meets the specified SIL level? This requires performing PFD (Probability of Failure on Demand) calculations for each aspect of the SIF, to determine whether the calculated PFD is lower than the PFD specified for that SIL level; if so, we say that this SIF meets the requirements of the corresponding SIL level. How do I calculate it? It is necessary to know the PFD for each stage; the data for these PFDs come from empirical data in internationally published sources, including those from DNV and an American publication. Data that cannot be found in these publications can be provided by the manufacturers. What to do if the calculation does not meet the requirements? The online testing time for a particular sample can be adjusted until the requirements are met. The results show that certain components need to be regularly tested based on the calculation outcomes, and there is available testing software for these tests, especially for valve manufacturers. There’s too much content; I’ll stop writing here for now. I’m quite clear about this issue, but it’s difficult to describe the chaos surrounding it in China.
Functional safety evaluation of fieldbus systems 1. Functions performed by fieldbus systems The role of fieldbus systems is to enable communication; they consist of a set of hardware and software that allow for the exchange of information between two or more devices. During controlled processes, it should not propagate or generate errors that could lead to dangerous situations: it must be able to detect data errors, ensure the timely transmission of data, and maintain order in the transmission process to avoid chaos. At the same time, it should be possible to stay aware of any potential fault conditions at all times, in order to prevent unreasonable safety actions from being triggered as a result of communication errors – for example, causing a process to stop when it shouldn’t, or allowing a process to continue operating despite a fault. 2. Methods for evaluating the safety functions of fieldbus systems. To determine whether a system or subsystem can be used in safety-related applications and Does it meet the requirements? the IEC61508 standard, there are two approaches: one is to design a new system in accordance with the principles of IEC61508; the other is to use a system that has already been in use and proven to be safe, and verify it using the “proven in use” approach. The functional safety assessment of fieldbus systems generally adopts the second method. This is a concept of \"proven in use\". If a product or system is already in use, as long as the supplier has sufficient evidence to prove its safety, then the same product or system can be used in similarly safe applications in the future. The concept of “proven in use” proposed in IEC61508 provides significant incentives for both suppliers and users. Currently, all the major equipment suppliers in the world are beginning to obtain certifications for their products in this area. However, “Proven in use” actually comes with very strict constraints: (1) The Proven in use approach can only be applied to those functional and interface subsystems that meet the relevant requirements; (2) The operating conditions of the subsystem must be exactly the same as or very similar to those of the atomic system; (3) If the operating conditions differ, analytical and testing methods must be used to determine the level of functional safety integrity that the system can achieve, in order to ensure it can be used in safety-related applications; (4) The declared failure rates must be supported by sufficient statistical data; (5) Adequate failure data must be collected; (6) Factors such as the complexity of the subsystem, its contribution to risk reduction, the potential consequences of subsystem failures on the entire system, and new designs must also be taken into consideration.
Three components: sensor, logic calculator, and actuator. Even if they have all been certified to a SIL level, it cannot be assumed that they meet the SIL requirements. This is a mistaken concept at this point. All three components may not require certification, but by providing parameters such as average time between failures, it is possible to calculate the PFD (probability of failure) for the entire SIF, thereby determining whether the requirements of the corresponding SIL level are met. There are some mature software tools for such calculations, and different software is used for various analysis methods, such as fault tree analysis, LOPA analysis, and so on. SIL analysis reports are generally provided by professional companies. This post was last edited by songzhiyuan on 2009-4-7 16:23]
Let me continue to express this from my personal perspective. When I discuss this with colleagues in the industry, I usually classify functional safety according to industry categories. The most important factor is the application environment in the industry, as there are significant differences among safety-oriented control systems. A. Process industries (or process-based industries) B. The manufacturing industry (also known as the discrete industry) and the process industry should be better explained using the concept of SIS. Safety-rated detection devices (meters, sensors, switches), safety-rated control systems (Safety-DCS, Safety-PLC, specialized ESD systems), and safety-rated actuators (valves, actuators). The SIS system is a concept introduced by IEC61511 specifically for the instrumentation and process industry. More focus is placed on “the overall safety of the circuit”. The biggest feature of safety systems in this industry is the emphasis on the overall safety of the entire circuit. What matters next are the differences in the control systems, such as whether it is a 3-redundancy voting system, a 4-redundancy system, or a dual-redundancy system. Unfortunately, the vast majority of people only focus their attention on the control system, ignoring other elements such as instruments and actuators. It also ignored the most crucial aspect of this standard: the overall safety of the circuit. Applications in the manufacturing industry are vastly different. Essentially, the core and concepts of safety remain the same; it is merely due to industry differences that the safety requirements in the manufacturing sector differ greatly from those in process industries. 1. For example. Process industries often (but not necessarily) cause greater harm than manufacturing industries. A chemical plant explosion damages equipment, causes deaths, and leads to environmental pollution. And if the safety of a paper cutting machine is not properly ensured, it’s possible for the cutting blade to injure the worker’s arm. 2. The process industry – in this industry, characteristics such as “process,” “loop,” and “continuity” are inherent throughout it. For example, with a SIS system, it may only be allowed to be shut down once every 3 years for maintenance and repair. In the manufacturing industry, if there is a problem with a certain press or a welding device, that device can be stopped. The loss for a factory isn’t related to explosions, deaths, or environmental pollution; rather, it’s the impact on productivity. For example, there are 3 presses, and one of them is shut down. These industry characteristics are also reflected in the choice of standards for PFD calculation units. In the process industry, SIS systems are typically evaluated for their failure probability over a period of years, while the manufacturing industry prefers to use hours. In the safety control systems of the manufacturing industry, we can find a large number of safety sensors, such as photoelectric switches, light curtains, and foot pedals. The typical appearance is yellow or red. There are also a large number of safety PLCs. There are also a large number of motor starters, frequency converters, control mechanisms with composite safety specifications, and even robots with composite safety features. These are hardly seen in process industries. 3. Back to the control system, this is an issue that everyone is very concerned about. In the process industry, have you seen ESD systems in chemical plants that use stand-alone systems? Not a single one! 3 redundancy, 4 redundancy, and even the extremely high level of 6 redundancy are all being heavily promoted. At the very least, there should be dual redundancy; while paying attention to system security, great emphasis is also placed on the system’s availability. And safety control systems for the manufacturing industry. For example, in automobile manufacturing, as far as I’ve seen, none use a dual-redundancy system; they are all single-unit systems! The mainstream option is AB’s SafetyPLC, GuardLogix, which is what we commonly refer to as the 1756S series. Compared to 1756, the extra S stands for Safety. Another mainstream option is Siemens’ F series; the 300F and 400F models are widely used. I saw power redundancy, but aside from that, there was almost no network redundancy, and absolutely no CPU redundancy. No IO redundancy was seen either. Does the automotive industry lack money? Can’t even afford redundancy? It’s not at all like that. . . Well-known brands such as HIMA, Triconex, and ICS are almost never used in the manufacturing industry! Basically it’s AB, Siemens. My personal understanding is two factors. First, in these typical manufacturing industries, there is a “relative” lack of need to pay too much attention to the availability of safety systems. For example, stopping for a few minutes or even a few hours, and then manually replacing the components, is tolerable. Second, and this is very important, current redundant control systems, whether they are safety-oriented or not, have issues with integration with motion control systems and servo control systems. For example, in the Siemens 400FH system, when the CPU performs redundant switching, motion control is problematic even during the shortest switching times; as a result, single-CPU operation is used instead. The same issue exists with AB as well. In many process industries, **well-known SIS systems such as Triconex, ICS, GE, and HIMA either lack motion and servo control units (GE does have them), or even if they do have such units, it is difficult to use them. (GE’s S90-70 single-unit setup can connect to motion control without issues, but a 3-redundancy system simply cannot connect to motion control.) In the manufacturing industry, it is almost impossible to operate assembly lines without motion control or servo control.