10-Steps To Performance Level
10-Steps To Performance Level
Your Guideline
for More Safety
Clear Rules 4
Focus on Safety-Related Parts of a Control System (SRP/CS) 6
Functional Safety (ISO 13849) 7
Everything from a Single Source 8
At a Glance: The Systematics for Safety 10
Risk Assessment based on ISO 14121 12
Identification of the Safety Functions 13
Specification of the required Performance Level (PLr) 14
Choice of the System Architecture (Category) 15
Analysis of the Circuit to Create the Block Diagram 16
Modeling the Circuit as a Block Diagram 17
Selection of Appropriated Components (MTTFd, B10 , PL, PFHd) 18
Evaluation of the System Monitoring (DC) 19
Evaluation of the System Robustness (CCF) 20
Check the Safety Principles and Software Requirements 21
Verification and Validation of the reached
Performance Level (PL ≥ PLr) 22
The same Language – Glossary 23
4
Clear Rules
The European Machinery Directive
2006/42/EC and the Machinery
Safety Standards ISO 13849 and
IEC 62061 provide the framework:
in an extensive evaluation with
statistical parameters, machine
manufacturers must proof protection
of personnel under consideration of
all components and systems installed
into the machine or production
system.
Machinery Safety
C standards
EN ...
EN
474
EN 693
Electronic
1010
ISO IEC control
23125 61508*
IEC Electric
Risk ISO
60204 equipment
assessment 14121
Rexroth supports machine and
production system manufacturers IEC Electric
with know-how and individual 61800-5-2 drives
consulting. The guideline
Machinery Directive
“10 Steps to Performance Level”
supports you by the evaluation of
IEC A
risks systematically and according Ba sta
62061 sis nda
to standards, by designing and sta rds:
nda ISO Design
implementing the corresponding rds
12100 basic laws
safety measures. ISO
13849
We gladly support you personally – Bs
Machinery Ge tanda
n r EN 982
please contact us. Control sta eric s ds: EN 983
nda af (ISO 4413)
Systems rds ety (ISO 4414)
Hydraulics
Pneumatics
* IEC 61508 is not a
harmonized standard
Cs
t
according to the Pro andards
Machinery Directive, duct :
sta
but it serves as basis nda safety
rds
for other European
harmonized standards.
6
Hydraulic/pneumatic drive
Danger!
The ISO 13849 shows the way to The focus is on the parts of the called “Functional Safety” with
fulfill the safety requirements of control system which are relevant special requirements on the avail-
the European Machinery Directive to the safety of the machine. ability of the Safety Function.
for control systems. This standard As soon as the safety of a machine
considers the design and integra- depends on a correct function of
tion of safety-related parts of a the control system, it is therefore
control system (SRP/CS), regard-
less of the applied technology, such
as electrical, hydraulic, mechanical
or pneumatic. Furthermore, IEC
62061 regulates the specifications
specifically for electronic control
systems.
During all working steps of this The new design criteria and Rexroth provides these data with
guideline, specialists from probabilistic calculations cover all necessary additional infor
Rexroth are available as know- safety engineering classifications mation.
how partners for all drive and of components and systems for
control technologies: From the nearly all stationary and mo- Because of our product know-how
design up to the implementation bile machines. For this purpose, and worldwide application experi-
of the safety functions. suppliers must provide informa- ence, we know the interactions
tion about the reliability of all and interdependency between the
involved electrical, hydraulic, different technologies applied for
mechanical and pneumatic mechatronic systems. Take advan-
components. tage from our knowledge.
9
10
Identification of the
2 Check the Safety
Safety Functions
9 Principles and Software
Requirements
Specification of
the required Evaluation of the
3 8 System Robustness
Performance Level
(PL r) (CCF)
Risk estimation
Risk evaluation
No
Avoidance by safeguards
Everything done?
MTTFd
l ≥ 3 to < 10 years Category B Category 1 Category 2 Category 3 Category 4
low
MTTFd
≥ 10 to < 30 years
medium m I L O I L O I L O I1 L1 O1 I1 L1 O1
MTTFd
H ≥ 30 to < 100 years
high
TE OTE I2 L2 O2 I2 L2 O2
Performance Level a
PFHd: ≥ 10 -5 to < 10 -4 [h-1]
Performance Level b
≥ 3 * 10 -6 to < 10 -5 [h-1]
Performance Level c
≥ 10 -6 to < 3 * 10 -6 [h-1]
Performance Level d
≥ 10 -7 to < 10 -6 [h-1]
Performance Level e
≥ 10 -8 to < 10 -7 [h-1]
PFHd: Probability of a DC: none none low medium low medium high
dangerous failure per
(operating) hour Information about DC values under step 7
16
1V5b
What tests this function,
how and how often? 1V3
1V1
Position monitoring!
1S1 1S2 1Z1
Connecting the blocks with each other Channel 1 safe holding with
(reverse analysis): valve combination 1V3 and 1V4
Channel 2 safe holding with 1V5
What does this element depend on?
Serial connection (dependency) both channels are controlled by PLC K1 which
receives the request of the safety function
If this element fails, from sensor F1.
what takes over its function?
Parallel connection (redundancy) with tests: monitoring by 1S3
1S3 Tests
SRP/CS c
18
none: DC < 60 %
⅄d,u ⅄d,d
Denotation
60 % ≤ DC < 90 %
DC range
low:
medium: 90 % ≤ DC < 99 %
high: 99 % ≤ DC
Measure Technology DC
Ful-
Measure against CCF Fluid technology Electronics Points
filled?
Clearances and creep age
Separation between
Separation in piping distances on printed-circuit 15
signal paths
boards.
Diversity e.g. different valves e.g. different processors 20
9.c Safety principles: Check list for machine builders (ISO 13849-2, example)
PL
No PL ≥ PLr
Yes
Safety on board with IndraDrive:
Next safety function Worldwide first safe braking
and holding system
The functional safety standards define clearly a set of terms and parameters. The most important ones:
PL (Performance Level): Discrete level used to specify the B10: Statistic expected value of the number of cycles until
ability of safety-related parts of control systems to 10% of the components have exceeded specified limits
perform a safety function under foreseeable conditions (response time, leakage, switching pressure, …) under
PLr: Required Performance Level defined conditions
SIL (Safety Integrity Level): Safety Integrity Level B10d: Expected number of cycles until 10% of the compo
(appropriated only for electronic control systems, nents fail dangerously
see PL and IEC 62061) T10d: Expected value of the mean time until 10% of the
MTTF (Mean Time To Failure): Statistic expected value components fail dangerously (maximal service time
of the mean time to failure of a component).
MTTFd (Mean Time To dangerous Failure): Statistic TM (Mission Time): Service life
expected value of the mean time to dangerous failure DC: Diagnostic Coverage
FIT (Failure In Time): Unit used to measure the failure rate CCF: Common Cause Failure
of electronic components (1 FIT=1x10 -9/h) SRP/CS: Safety-Related Parts of a Control System
PFHd (Probability of Dangerous Failure per Hour): Dangerous failure: Failure which has the potential to
Probability of dangerous failure per hour (reference put the SRP/CS in a hazardous or fail-to-function
value for PL and SIL) state
Bosch Rexroth AG
97816 Lohr am Main
Germany
[email protected]
www.boschrexroth.com/
safety
Printed in Germany
RE 08511/08.09
substitutes RE 08511/04.09