semi合集-English.pdf - 第6855页
SEMI S2-0703a E © SEMI 1991, 2004 84 R14-8.3.1 Use of Fail-to-safe Equipment C ontrol Sys tems with Con ventional Safe ty Technology — Equi pment manufacture rs can achieve fu nctional safety by the use of hardwired circ…

SEMI S2-0703a
E
© SEMI 1991, 2004 83
immediately achieve a safe condition. An FECS
consists of sensors, logic systems and final elements as
shown in Section R14-11. Replacing an existing
electromechanical system with a safety controller does
not provide a safe system. Sensors and final elements
have to be considered as well.
R14-8.2.3 Safety Requirements – The FECS should be
suitable for SIL1 to SIL3 safety integrity level in
compliance with IEC 61508 or control categories 2 to 4
in compliance with ISO 13849-1 (EN 954-1). The
required safety performance requirements will be
determined in the system safety risk assessment. For
application assessment, local authorities and notified
bodies should request a safety handbook and
certification according to IEC 61508 or ISO 13849.
The safety-related system and its components should be
validated to ensure it fulfills the safety requirements
(SIL, CAT) determined from the risk analysis.
R14-8.2.4 Principle Of The Safety Functions — The
FECS executes safety functions to bring the equipment
into a safe state or to maintain it in a safe condition
when a hazardous event occurs. The safety function for
a production process can be realized using a user safety
function or a fault response function. The safe state can
be achieved by de-energizing the output modules.
R14-8.2.5 Communications — Non-safety-related and
safety-related communications between an industrial
controller and I/O modules should pass through a
standard network system or a safety network system in
sequence or through a combined network system (see
Figures R14-2-R14-7). Bridges, routers and repeaters
can be used in either standard networks or in safety
networks to adapt the network topology to the
individual layout of production process and equipment.
R14-8.3 Basic Topologies — Sections 7.3.1 through
7.3.3 describe examples of network-based architectures
that are capable of achieving a FECS. The suppliers
should take into account performance, timing, ease of
use, and other factors when selecting an architecture
type.
NOTE 8: These examples are not represented to be all-
inclusive.

SEMI S2-0703a
E
© SEMI 1991, 2004 84
R14-8.3.1 Use of Fail-to-safe Equipment Control Systems with Conventional Safety Technology — Equipment
manufacturers can achieve functional safety by the use of hardwired circuits. Such hardwired circuits are realized
with terminals, electromechanical or electronic safety relays, and contactors. The relays would be certified for use
in CAT 4 applications according to ISO 13849. In Figure R14-2, a standard industrial controller is used with
standard I/O over a standard network to provide for the non-safety aspects of the machine and to provide diagnostics
and visualization of the hardwired safety functions.
Figure R14-2
Fail-to-safe Equipment Control System with Conventional Safety Technology

SEMI S2-0703a
E
© SEMI 1991, 2004 85
R14-8.3.1.1 Use of Fail-to-safe Equipment Control Systems with Dual Networks for Standard and Fail-to-safe
Communications and Combined Controllers — Figures R14-3 and R14-4 are dual network systems with control of
the non-safety functions remaining the same as in Fail-to-safe Equipment Control Systems with Conventional Safety
Technology. Safety functions, however, are achieved using FECS with safety-related information and control
managed over a separate dedicated safety network.
Figure R14-3
Fail-To-Safe Equipment Control System with Dual Network for Standard and Fail-To-Safe Communication
and Separated Standard and Safety Controllers