Certification - Report - s7 - F-FH 326
Certification - Report - s7 - F-FH 326
to the
Choosecertainty.
Certificate Addvalüe.
Manufacturer:
Siemens AG
Industry Sector IA AS
Gleiwitzer Str. 555
0-90475 Nürnberg
Testing Body:
TÜV SÜD Automotive GmbH
Electronics Safety
Ridlerstraße 57
0-80339 München
Distribution, copying or any other use of information in this report in part is strictly prohibited.
Revision Log
4 RESULTS ............................................................................................................................................ 16
4.1 FUNCTIONAL SAFETY ...................................................................................................................... 16
4.2 BASIC SAFETY AND ELECTROMAGNETIC COMPATIBILlTY ................................................................... 18
4.3 PRODUCT SPECIFIC QUALITY ASSURANCE AND CONTROL ............................................................... 19
Functional Safety The ability of a safety-related system to carry out the actions ne-
cessary to achieve a (defined) safe state for the equipment un-
der control (EUC) or to maintain the safe state for the EUC.
CFC Continuous Function Chart
Multiple fault occurrence The multiple-fault occurrence period denotes a time frame, in
time which the probability for the appearance of combination-wise
safety-critical multiple faults is sufficiently low for the considered
requirement class. The period of time begins with the last point
in time, at which the considered system was in a fault-free as-
sumed condition according to the considered requirements
class.
The definition of this time is not system specific. A general rec-
ommendation is to assume this time to be magnitudes (2 to 3)
below the specified MTBF time.
Fault tolerance time The fault-tolerance time denotes a characteristic of the process
and describes the period of time, in which the process can be
controlled by a faulty control-output signal, without entering a
dangerous condition.
Interference free Property of a unit not to cause faulty state in connected units
even if it fails
Probability of Failure on Average probability of failure of a system to perform its design
Demand (PFD) functions on demand.
Probability of dangerous The probability of a dangerous failure per hour (in the case of
failure per hour (PFH) high demand or continuous mode)
2 System Overview
2.1 System Architecture
The SIMATIC S7 F/FH Systems are safety-related fail-safe programmable electronic systems
(PES) that are suitable for safety-related applications with a high level of potential danger, e.g.
controllers for offshore processes, chemical processes.
Operator Station
(System visualization)
r====='
D
~ S7-400F programmable controller
/ \
/
I ~H
D l~~, l~~,
~ Jl
/ \ Fail-safe 1/0 modules
(optionally redundant)
Redundant
PROFIBUS-DP\ _____
Standard 1/0 modules
(optionally redundant)
FM I~~~I
$----11-------' I
"
2.3.3 Communication
Safety-related communication between F-CPUs and F-I/O is based on the Profibus protocol but
implements an additional safety shell on top (PROFIsafe).
Safety-related communication between F-CPUs is based on a standard protocol like MPI, Profi-
bus-DP/PA or Ethernet but implements an additional safety shell on top.
Based on the specified purpose of use of the SIMATIC S7 F/FH Systems in safety critical
process protection applications the certification is based on the following set of standards. The
issuance of the certificate states compliance with these references unless specifically noted
otherwise.
Machinery Applications
EN 60204-1 :2006 Safety of machinery - Electrical equipment of machines
(to the extent applicable)
EN 954-1:1997 Safety of machinery; Safety-related parts of control systems
up to safety category 4 Part 1 "General principles for design"
ISO 13849-1 :2006 Safety of machinery - Safety-related parts of control systems -
EN ISO 13849-1:2008 Part 1: General prineiples for design
(to the extent applicable)
up to PL e
The fault tolerance period of the process controlled by the SIMATIC S7 F/FH Systems shall be
greater than the worst case response time. Additional information is given into the manual 'Safe-
ty Engineering in SIMATIC S7'.
5.1.1. The guidelines specified in the user's manuals shall be followed. Specifically the safety
notes in the user's manuals shall be followed.
5.1.2. Only hardware modules certified for safety-related operation, as listed in Annexes of this
report shall be used for safety-critical signals. Not certified standard modules (defined as
"interference-free") may be used for non-safety-critical signals only.
5.1.3. Only software modules listed in Annexes of this report shall be used to process safety
critical data.
5.1.4. The fault tolerance period of the process controlled by the system shall be greater than
the worst-case reaction time of the system.
5.1.5. A weil defined shutdown procedure shall be specified.
5.1.6. Non-safety-related blocks in the application program shall not control or affect data used
by any safety-critical block unless with safety-related function blocks for data conversion
and plausibility checks in the safety-related program.
5.1.7. Operator alarms as exclusive means of shutdown are only permitted under supervised
operation and if the fault tolerance time of the controlled process is sufficiently long to
ensure a safe manual reaction and shutdown and the operator has sufficient independent
means to supervise the process.
Installations that must react to shutdown conditions quicker than achievable with manual
intervention or installations running unsupervised shall incorporate an automatie fault
reaction procedure.
5.1.8. The operating conditions as specified in the user manuals shall be met.
5.2.1. Prior to commissioning, a complete functional test of all safety-relevant functions shall be
performed. The programming of the application shall ensure that modules are small and
self contained, sufficient to permit full functional testing.
5.3.1. Failed modules that are safety-related and in redundant configurations should be re-
placed as quickly as practical to minimize the probability of multiple fault accumulation
and potential (safe) nuisance shutdown. As a maximum, failed modules should be re-
placed within the multiple fault occurrence time.
5.3.2. Application program modification du ring run-time should only be permitted under
end-user responsibility.
5.3.3. The procedure described in the user manual has to be followed.
5.3.4. The application program modifications shall be limited and simple to verify and validate.
5.3.5. The modifications and their interaction with existing program sections shall be thoroughly
tested, e.g. using simulation.
5.3.6. The modification shall be granted by the approval authority for the plant assessment.
5.3.7. Maintenance override is to be limited (time-restriction and number) of logical points. The
TÜV guidelines for maintenance overrides are to be followed. TUV certification does not
cover output override.
5.3.8. The use of F-Function Blocks for SIMATIC S7 F/FH Systems F/FH is only permitted if for
the specific target system (F or FH system) an official F-Copy License with the order
number 6ES7 833 1CCOO 6YXO is available.
The F-Copy License consists of:
- the F-Copy License contract
- the copy of the TUV-Certificate
- two labels to mark up the CPU (or CPU's on a FH system) of the used F-Copy License
5.4.1. The Safety Protector allows use of failsafe-modules in combination with standard-
modules. Purpose of the Safety Protector is to isolate the failsafe-modules from overvol-
tages up to a maximum of 250 Volt AC/DC caused by not-safety related standard mod-
ules. No field voltage higher than 250V is allowed.
Munieh, 7-07-20
1)/ f!-~-
Vau
Technical Certifier
Manufacturer:
Siemens AG
Industry Sector IA AS
Gleiwitzer Str. 555
0-90475 Nürnberg
Testing Body:
TÜV SÜD Automotive GmbH
Electronics Safety
Ridlerstraße 57
0-80339 München
Distribution, copying or any other use of information in this report in part is strictly prohibited.
Revision Log
SM 326, 6ES7 01 1)7) to 06 1) 7), 07 8 channel NAMUR digital input module for
018 x 326-1RFOO- intrinsically-safe sensors
NAMUR OABO
SM 326, 6ES7 01 to 06 10 channel digital output module 24VOC/2A,
0010 x 326-2BF01- P-switch
OC24V/2A OABO 1)
Modules ET 200S:
4/B F-DI 6ES7 01 41B channel digital input module 24VDC
DC24V 13B-4FA04-
OABO 1)
Modules ET 200eco:
4/8 F-DI 6ES7 01 to 05 4/8 channel digital input module 24VDC
DC24V 148-3FAOO-
OXBO 2)8)
Modules ET 200pro:
8/16 F-DI 6ES7 01 to 05 8/16 channel digital input module 24VDC
DC24V 148-4FAOO-
OABO 2) 8)
Remark: For the 110 modules EN 298, 2003 and EN 230: 2005 is fulfilled with external
surge protection; see related manuals.
All other components of the S7-400 and S7-300 family are 'interference-free' and allowed to be
used, however, they are not certified for process safety critical signals and functions. Using
these components does not interfere with the proper functioning of the safety-related modules.
For details on architectural, configuration and implementation requirements please refer to the
Siemens manuals of the SIMATIC S7 F/FH Systems documentation package.
F967 4F58
F_CH_OO F-User block C5F2 2 ) BCEE 2)
F CH II F-User block 405E 3) 40AE 3)
F CH 10 F-User block 39E2 3
) 0409 3 )
F CMP R F-User block 689A 602E
1) RESTRICTION: "Safety Data Write" handling of Boolean parameters shall not be used with the OCX
Faceplate of S7 F Systems HMI V5.2, which is part of the optional package S7 F Systems
V5.2+SP2. F_CH_BO shall be used with the associated OCX of S7 F Systems HMI V5.2+SP3
or higher only.
2) signature of F-FB in S7 F Library V1.3 SP1 or higher
3) F-FB added in S7 F Library V1.3 SP1
1) displayed in S7 F Systems up to V5.2 SP3, if these F-FBs are the only F-FBs in a S7 program
2) signature of F-FB in S7 F Library V1.2 + SP1 or higher
3) F-FB added in S7 F Library V1.2 + SP1
4) F-FB added in S7 F Library V1.2 + SP2
5) F-FB added in S7 F Library V1.2 + SP4
6) RESTRICTlON: "Safety Data Write" handling of Boolean parameters shall not be used with the OCX
Faceplate of S7 F Systems HMI V5.2, which is part of the optional package S7 F Systems
V5.2+SP2. F_CH_BO shall be used with the associated OCX of S7 F Systems HMI V5.2+SP3
or higher only.
Attention!
Contrary to the Siemens S7 user's manual "Programmable Controllers S7 F/FH
Systems" (Edition 2/2003) the F_FR_FI function block of S7 F Library V1.2 is NOT
certified for safety applications and shall NOT be used to process safety critical
data.
Function Version
CFC 1) V5.2 or higher
1) Further restrietions specific to modules or versions of the optional package S7 F Systems can
be found in the corresponding user documentation.
Munieh, 2010-04-30
l~-2 ~'",
Frank Rauch
Technical Certifier