semi合集-English.pdf - 第6853页
SEMI S2-0703a E © SEMI 1991, 2004 82 assessment and m aintenance of suitable control systems. R14-7.2.3 The usage co nditions and safety performance sho uld be determi ned by the finding of a risk assessment as described…

SEMI S2-0703a
E
© SEMI 1991, 2004 81
R14-6.2.18 safety PLC — a programmable logic
controller and associated I/O, certified as having the
necessary safety integrity to execute the safety-related
function.
R14-6.2.19 safety relay (SR) —- A positive or force-
guided relay, that is used in safety relay modules
(SRMs) to achieve a fail-to-safe circuit.
R14-6.2.20 safety relay module (SRM) — redundant
self monitoring electro-mechanical/ solid state device
certified for use in safety applications
R14-6.2.21 safety-related I/O modules —I/O modules
capable of diagnosing internal and external faults and
configured to be redundant. (e.g., a second shutdown
path is included for output-circuits).
R14-6.2.22 safety-related programmable system —
systems designed and implemented for safety functions
in accordance with ISO 13849 or IEC 61508. These
system types (e.g. safety PLC, safety-related I/O
modules) can diagnose internal and external faults and
can react upon detected faults in a controlled manner.
R14-6.2.23 safety requirements specification —
specification containing all the requirements of the
safety functions that have to be performed by the
safety-related systems.
R14-6.2.24 solid state electronics — designation used
to describe devices and circuits fabricated from solid
materials such as semiconductors, ferrites, or thin films
as distinct from devices and circuits making use of
electromechanical technology, e.g. solid state relay,
micro controller.
R14-6.2.25 systematic failure — failure related in a
deterministic way to a certain cause, which can only be
eliminated by a modification of the design or of the
manufacturing process, operational procedures,
documentation or other relevant factors.
R14-7 State-of-the-Art Safety Control System
— Comprised of Solid State Electronics
R14-7.1 Failure to perform normal function (for
example a failure of a computer or its software) may
cause economic loss, but is not necessarily a safety
issue. However, failure of a safety-related component
to perform its safety function could result in a
hazardous condition. A fail-to-safe system should be
designed in a manner to ensure that failures do not
result in a hazardous situation. It is therefore important
to perform a system risk assessment to determine
safety-related functions and the - safety performance
required. The process outlined in following figure
should be followed.
Figure R14-1
Roadmap to Risk Assessment and System Design
R14-7.2 Safety Interlocks — Semiconductor
manufacturing equipment requires the use of fast,
reliable and efficient means of safety interlocking.
Important issues concerning complex machine
architectures include availability and diagnostic
capabilities for quick troubleshooting.
R14-7.2.1 A FECS should, even in the case of failure,
maintain a safe state of the EUC. Therefore, a FECS is
able to detect faults and cause the system to go to a safe
state. A properly designed FECS – using methods such
as self-monitoring for fault detection and subsequent
well defined reaction – can offer high availability and
diagnostics.
R14-7.2.2 Section 11.6 of SEMI S2 (including
exceptions and notes) indicates a preference for
electromechanical devices and components, and gives
guidance on their use. However, non-
electromechanical devices and components are
permitted and they can provide necessary risk reduction
while maintaining safety performance. Section 11.6,
Note 26 of SEMI S2, suggests some tools for
investigation of suitability for use. Additionally, IEC
61508, ANSI/ISA-SP84.01, and ISO 13849-1 (EN 954-
1) provide guidance on the safety system design,

SEMI S2-0703a
E
© SEMI 1991, 2004 82
assessment and maintenance of suitable control
systems.
R14-7.2.3 The usage conditions and safety
performance should be determined by the finding of a
risk assessment as described in SEMI S10. Risk
assessment results can then be used to define
appropriate SIL levels and Categories.
NOTE 7:Emergency Off — Section 12.2.2 of SEMI S2 states
that the EMO system should consist of electromechanical
components. The exceptions give guidance to the design of
EMO circuits using alternative technologies. Regional,
national or industry standards may have additional
requirements (e.g., USA: ANSI/NFPA 79, Europe: EN
60204-1).
R14-7.2.4 Any deviation from the risk level of
electromechanical devices must be carefully evaluated
(see Section 8 of SEMI S2).
R14-7.2.5 Compliance with Section 12 of SEMI S2,
emergency shutdown will depend on the risk
assessment allowed in Section 8.3.11 of SEMI S2.
R14-7.3 Software and Programming
R14-7.3.1 The application software or function blocks
have to be verified before being used in an FECS. The
automation supplier usually provides a range of
approved software blocks.
R14-7.3.2 Access for programming of safety-related
functions should be restricted within the FECS to
trained people.
R14-7.3.3 To program or modify safety-related
programs or parts of it, specially trained or qualified
personnel are required. Any changes must be
documented and stored within the file history.
R14-8 Philosophy and General Concept
R14-8.1 Introduction — An automated machine
system mainly comprises components such as industrial
controller, drives, I/O etc. The level of safety
performance of equipment can differ depending on the
particular application of FECS. However, irrespective
of the particular application, the FECS always
comprises a series of sensors, logic elements and
actuators for safe shutdown or a motion into a safe and
stable machine state.
R14-8.1.1 The term FECS according to IEC 61508 Part
2, is equivalent to the terms SIS (safety instrumented
system) or SRS (safety related system) in other
application areas. The examples in this Related
Information show some possible architectures of the
logic system. Sensors, final elements and software are
discussed in this Related Information. Application
handbooks from automation suppliers provide users
with valuable information on how to use these
components in order to achieve a fail-to-safe,
equipment control system.
R14-8.1.2 For traditional semiconductor equipment,
non-safety-related and safety-related technology, are
separated. In many cases non-safety-related and safety-
related technology are linked, so that signals
representing diagnostics, enable, and feedback can be
exchanged.
R14-8.1.3 Main Characteristics of Architecture
Concepts
1. Fail-to-safe equipment control system with
conventional hardwired safety technology.
2. Fail-to-safe equipment control system with
separation between fail-to-safe and standard
network technology.
3. Fail-to-safe equipment control systems with
combined network technology for transmission
of fail-to-safe and standard data on a single
medium.
4. Redundancy can be used in all concepts to
increase availability. Different redundancy
concepts are in use (see R14-Section 9).
5. Visualization on the standard control part and
on the fail-to-safe part can be realized with
various interfaces on the standard part and on
the fail-to-safe part.
R14-8.2 Design of Architecture and Components
R14-8.2.1 Possible Application Areas
1. Semiconductor manufacturing industry
2. Guarding of people, machines, environment
and industrial processes
Emergency stop functions,
Emergency off functions,
Emergency shutdown functions,
Light gates,
Guard doors,
Scanners,
Motion control with safety functions,
Motor control with safety functions,
Process valves with safety functions, and
Process monitoring using safety-related interlocks.
R14-8.2.2 Safety-related Equipment Control System —
The design of FECS should be carried out in
accordance with IEC 61508 and applicable parts of the
other referenced standards. The safety controller is
used to control (open-loop) processes that can

SEMI S2-0703a
E
© SEMI 1991, 2004 83
immediately achieve a safe condition. An FECS
consists of sensors, logic systems and final elements as
shown in Section R14-11. Replacing an existing
electromechanical system with a safety controller does
not provide a safe system. Sensors and final elements
have to be considered as well.
R14-8.2.3 Safety Requirements – The FECS should be
suitable for SIL1 to SIL3 safety integrity level in
compliance with IEC 61508 or control categories 2 to 4
in compliance with ISO 13849-1 (EN 954-1). The
required safety performance requirements will be
determined in the system safety risk assessment. For
application assessment, local authorities and notified
bodies should request a safety handbook and
certification according to IEC 61508 or ISO 13849.
The safety-related system and its components should be
validated to ensure it fulfills the safety requirements
(SIL, CAT) determined from the risk analysis.
R14-8.2.4 Principle Of The Safety Functions — The
FECS executes safety functions to bring the equipment
into a safe state or to maintain it in a safe condition
when a hazardous event occurs. The safety function for
a production process can be realized using a user safety
function or a fault response function. The safe state can
be achieved by de-energizing the output modules.
R14-8.2.5 Communications — Non-safety-related and
safety-related communications between an industrial
controller and I/O modules should pass through a
standard network system or a safety network system in
sequence or through a combined network system (see
Figures R14-2-R14-7). Bridges, routers and repeaters
can be used in either standard networks or in safety
networks to adapt the network topology to the
individual layout of production process and equipment.
R14-8.3 Basic Topologies — Sections 7.3.1 through
7.3.3 describe examples of network-based architectures
that are capable of achieving a FECS. The suppliers
should take into account performance, timing, ease of
use, and other factors when selecting an architecture
type.
NOTE 8: These examples are not represented to be all-
inclusive.