semi合集-English.pdf - 第6783页
SEMI S2-0703a E © SEMI 1991, 2004 12 11.4 Upon activation, the safety interlock shou ld alert the operator immediately. EXCEPTION: Alerting the operat or is not expected if a safety interlock triggers the EMO circuit (se…

SEMI S2-0703a
E
© SEMI 1991, 2004 11
descriptions of the emergency off (EMO) and
interlock functions;
a list of hazardous materials (e.g., lubricants,
cleaners, coolants) required for maintenance,
ancillary equipment or peripheral operations,
including anticipated change-out frequency,
quantity, and potential for contamination from the
process;
a list of items that become solid waste as a result of
the operation, maintenance, and servicing of the
equipment, and that are constructed of or contain
substances whose disposal might be regulated (e.g.,
berylium-containing parts, vapor lamps, mercury
switches, batteries, contaminated parts,
maintenance wastes); and
maintenance and troubleshooting procedures
needed to maintain the effectiveness of safety
design features or devices (i.e., engineering
controls).
9.6.4 Information should be provided regarding
potential routes of unintended releases (see Section
21.2.4).
9.6.5 Recommended decontamination and
decommissioning procedures should be provided in
accordance with SEMI S12, and should include the
following information:
identity of components and materials of
construction, in sufficient detail to support
recycling, refurbishment, and reuse decisions (see
Section 8.5.3); and
residual hazardous materials, or parts likely to
become contaminated with hazardous materials,
that may be in the equipment prior to
decommissioning.
NOTE 20: It is recommended that the manual state that
changes to the typical process chemistry or to the equipment
could alter the anticipated environmental impact.
9.6.6 Maintenance Procedures with Potential
Environmental Impacts — The supplier’s
recommended maintenance procedures should:
identify procedural steps during which releases
might occur, and the nature of the releases; and
identify waste characteristics and methods to
minimize the volume of effluents, wastes, or
emissions generated during maintenance
procedures.
9.7 Fire Protection Documentation — The equipment
supplier should provide:
a summary fire protection report as described in
Section 14.3;
descriptions of optional fire risk mitigation features
(see Section 14.3.2);
NOTE 21: It is recommended that this be provided prior to
purchase.
fire detection system operations, maintenance, and
test manuals;
fire suppression system operations, maintenance,
and test manuals;
acceptance documents provided by licensed
designers and installers (see Sections 14.4.4.12 and
14.4.5.16); and
a list of any special apparatus needed to test the fire
detection or suppression features of the equipment.
The list should note whether the apparatus is
included with the equipment, or is sold separately.
10 Hazard Warning Labels
10.1 Where it is impractical to eliminate hazards
through design selection or to adequately reduce the
associated risk with safety or warning devices, hazard
warning labels should be provided to identify and warn
against hazards.
10.2 Labels should be durable and suitable for the
environment of the intended use.
10.3 Labels should conform to SEMI S1.
EXCEPTION: Some hazard label formats and content
are dictated by law (e.g., laser labeling and chemical
hazard communication labeling in certain countries of
use) and may not conform to SEMI S1.
11 Safety Interlock Systems
11.1 This section covers safety interlocks and safety
interlock systems.
NOTE 22: If a fire detection or suppression system is
provided with the equipment, see Section 14 for additional
information.
11.2 Where appropriate, equipment should use safety
interlock systems that protect personnel, facilities, and
the community from hazards inherent in the operation
of the equipment.
NOTE 23: Safety critical parts whose primary function is to
protect the equipment (e.g., circuit breakers, fuses) are
typically not considered to be safety interlocks.
11.3 Safety interlock systems should be designed such
that, upon activation of the interlock, the equipment, or
relevant parts of the equipment, is automatically
brought to a safe condition.

SEMI S2-0703a
E
© SEMI 1991, 2004 12
11.4 Upon activation, the safety interlock should alert
the operator immediately.
EXCEPTION: Alerting the operator is not expected if a
safety interlock triggers the EMO circuit (see Section
12) or otherwise removes power to the user interface.
NOTE 24: An explanation of the cause is preferred upon
activation of a safety interlock.
11.5 Safety interlock systems should be fault-tolerant
and designed so that the functions or set points of the
system components cannot be altered without
disassembling, physically modifying, or damaging the
device or component.
EXCEPTION: When safety interlock systems having
adjustable set points or trip functions are used, access
should be limited to maintenance or service personnel
by requiring a deliberate action, such as using a tool or
special keypad sequences, to access the adjustable
devices or to adjust the devices.
NOTE 25: This section does not address the defeatability of
safety interlocks. See Section 11.7 for additional information.
NOTICE: Section 11.6 below will be withdrawn
upon July 1, 2006 publication and replaced by the
new Section 11.6 including: figures and tables as
shown in Delayed Revisions Section 2. The EH&S
Committee has voted that implementation of the
information is OPTIONAL before the effective date.
11.6 Electromechanical devices and components are
preferred. Solid-state devices and solid state
components may be used, provided that the safety
interlock system, or relevant parts of the system, are
evaluated for suitability for use in accordance with
appropriate standard(s). The evaluation for suitability
should take into consideration abnormal conditions
such as overvoltage, undervoltage, power supply
interruption, transient overvoltage, ramp voltage,
electromagnetic susceptibility, electrostatic discharge,
thermal cycling, humidity, dust, vibration, and jarring.
EXCEPTION: Where the severity of a reasonably
foreseeable mishap is deemed to be Minor per SEMI
S10, a software-based interlock may be considered
suitable.
NOTE 26: Where a safety interlock is provided to safeguard
personnel from a Severe or Catastrophic mishap as
categorized by SEMI S10, consideration of positive-opening
type switches is recommended.
NOTE 27: Evaluation for suitability for use may also include
reliability, self-monitoring, and redundancy as addressed
under standards such as NEMA ICS 1.1 and UL 991.
NOTE 28: Solid-state devices include operational amplifiers,
transistors, and integrated circuits.
11.6.1 FECS may be used in conjunction with
electromechanical or solid state devices and
components provided the programmable safety control
system conforms to an appropriate standard for
electronic safety systems. Components of the FECS
should be tested and certified according to the
requirements of the standard used. Examples of
recognized electronic safety systems standards include
IEC 61508 ISO 13849-1 (EN 954-1), ANSI/ISA
SP84.01 DIN/V/VDE-0801.
NOTE 29: Paragraph 13.4.3 states additional assessment
criteria for safety-related components and assemblies.
NOTE 30: A FECS is a subsystem of a (PES) Programmable
Electronic System. IEC 61508 is the preferred standard for
complex PES.
NOTE 31: Related Information 14 provides additional
information on applications of FECS design.
11.7 The safety interlock system should be designed to
minimize the need to override safety interlocks during
maintenance activities.
11.7.1 Safety interlocks that safeguard personnel
during operator tasks should not be defeatable without
the use of a tool.
11.7.2 When maintenance access is necessary to areas
protected by interlocks, defeatable safety interlocks
may be used, provided that they require an intentional
operation to bypass.
11.7.2.1 Upon exiting or completing the maintenance
mode, all safety interlocks should be automatically
restored.
11.7.2.2 If a safety interlock is defeated, the
maintenance manual should identify administrative
controls to safeguard personnel or to minimize the
hazard.
11.8 The restoration of a safety interlock should not
initiate equipment operation or parts movement where
this can give rise to a hazardous condition.
11.9 Switches and other control device contacts should
be connected to the ungrounded side of the circuit so
that a short circuit to ground does not result in the
interlocks being satisfied.
11.10 Where a hazard to personnel is controlled
through the use of an enclosure, the enclosure should
either: require a tool to gain access and be labeled
regarding the hazard against which it protects
personnel; or be interlocked. In addition to enclosures,
physical barriers at the point of hazard should be
included where inadvertent contact is likely.
NOTE 32: Where the removal of a cover exposes a hazard,
consider additional labels. See Section 10 for guidance.

SEMI S2-0703a
E
© SEMI 1991, 2004 13
12 Emergency Shutdown
12.1 The equipment should have an “emergency off”
(EMO) circuit. The EMO actuator (e.g., button), when
activated, should place the equipment into a safe
shutdown condition, without generating any additional
hazard to personnel or the facility.
EXCEPTION 1: An EMO circuit is not needed for
equipment rated 2.4 kVA or less, where the hazards are
only electrical in nature, provided that the main
disconnect meets the accessibility provisions of Section
12.5.2 and that the effect of disconnecting the main
power supply is equivalent to activating an EMO
circuit.
EXCEPTION 2: Assemblies that are not intended to be
used as stand-alone equipment, but rather within an
overall integrated system, and that receive their power
from the user’s system, are not required to have an
emergency off circuit. The assembly’s installation
manual should provide clear instructions to the
equipment installer to connect the assembly to the
integrated system’s emergency off circuit.
NOTE 33: It is recommended that the emergency off
function not reduce the effectiveness of safety devices or of
devices with safety-related functions (e.g., magnetic chucks or
braking devices) necessary to bring the equipment to a safe
shutdown condition effectively.
NOTE 34: If a fire detection or suppression system is
provided with the equipment, see Section 14 for additional
information.
12.1.1 If the supplier provides an external EMO
interface on the equipment, the supplier should include
instructions for connecting to the interface.
12.2 Activation of the emergency off circuit should
deenergize all hazardous voltage and all power greater
than 240 volt-amps in the equipment beyond the main
power enclosure.
EXCEPTION 1: A non-hazardous voltage EMO circuit
(typically 24 volts) and its supply may remain
energized.
EXCEPTION 2: Safety related devices (e.g., smoke
detectors, gas/water leak detectors, pressure
measurement devices, etc.) may remain energized from
a non-hazardous power source.
EXCEPTION 3: A computer system performing
data/alarm logging and error recovery functions may
remain energized, provided that the energized
breaker(s), receptacle(s), and each energized conductor
termination are clearly labeled as remaining energized
after EMO activation. Hazardous energized parts that
remain energized after EMO activation should be
insulated or guarded to prevent inadvertent contact by
maintenance personnel.
EXCEPTION 4: Multiple units mounted separately
with no shared hazards and without interconnecting
circuits with hazardous voltages, energy levels or other
potentially hazardous conditions may have:
separate sources of power and separate supply
circuit disconnect means if clearly identified, or
separate EMO circuits, if they are clearly
identified.
12.2.1 The EMO circuit should not include features
that are intended to allow it to be defeated or bypassed.
12.2.2 The EMO circuit should consist of
electromechanical components.
EXCEPTION 1: Solid-state devices and components
may be used, provided the system or relevant parts of
the system are evaluated and found suitable for use.
The components should be evaluated and found suitable
considering abnormal conditions such as over voltage,
under voltage, power supply interruption, transient over
voltage, ramp voltage, electromagnetic susceptibility,
electrostatic discharge, thermal cycling, humidity, dust,
vibration and jarring. The final removal of power
should be accomplished by means of electromechanical
components.
EXCEPTION 2: FECS may be used provided the FECS
conforms to an appropriate standard for electronic
safety systems. Components of the FECS should be
tested and certified according to the requirements of the
standard used. IEC 61508 and ISO 13849-1 (EN 954-
1) are examples of internationally recognized electronic
safety systems standards. The final removal of power
should be accomplished by means of electromechanical
components.
NOTE 35: Paragraph 13.4.3 states additional assessment
criteria for safety-related components and assemblies.
NOTE 36: A FECS is a subsystem of a (PES) Programmable
Electronic System. IEC 61508 is the preferred standard for
complex PES.
12.2.3 All EMO circuits should be fault-tolerant.
12.2.4 Resetting the EMO switch should not re-
energize circuits, equipment, or subassemblies.
12.2.5 The EMO circuit should shut down the
equipment by deenergizing rather than energizing
control components.
12.2.6 The EMO circuit should require manual
resetting so that power cannot be restored
automatically.