semi合集-English.pdf - 第6860页

SEMI S2-0703a E © SEMI 1991, 2004 89 R14-8.3.3 Fault Tolera nt Equipment Control System With High Availability And Redundant Network — In Figures R14-2 through R14-6, the FECS enters a safe-state cond ition if a failure …

100%1 / 7923
SEMI S2-0703a
E
© SEMI 1991, 2004 88
Figure R14-6
Fail-To-Safe Equipment Control System with Combined Network for Standard and Fail-To-Safe
Communication and Separated Controller
SEMI S2-0703a
E
© SEMI 1991, 2004 89
R14-8.3.3 Fault Tolerant Equipment Control System With High Availability And Redundant Network — In Figures
R14-2 through R14-6, the FECS enters a safe-state condition if a failure should occur; however, the production
process would be interrupted. In order to increase the availability of the automation system and therefore avoid
process downtime resulting from control system faults as well as faults and errors of components such as the power
supply, the industrial controller, the network connection, and the I/O modules need to be made redundant. Possible
architectures (see Figure R14-7) for achieving high availability include 2 oo 2, 2 oo 3, 2 oo 4, etc. (see R14-Section
9). Using fail-to-safe and high availability systems, injury to people or environmental damage can be prevented and
the production process can be continued without interruption.
Figure R14-7
Fault-Tolerant Equipment Control System with High Availability FECS and Redundant Network
R14-9 Guide to Assessment and Test Methods
R14-9.1 Assessment and testing of an electronic system (especially programmable systems) for safety integrity
levels (SIL) according to IEC 61508/ANSI/ISA-84.01 or risk categories according to ISO 13849-1 (EN 954-1) is a
complex and time consuming task, requiring a considerable level of knowledge and expertise. The use of
components such as safety PLCs and safety networks, that are certified by third parties for use in systems, and
include specific SILs and risk categories, simplifies the process of assessing the whole system.
NOTE 9: Certified (or listed) components need to be certified for functional safety use in safety critical systems. The final
integrated system should be fully assessed; using tools such as IEC 61508/ANSI/ISA-84.01 or ISO 13849-1 (EN954-1).
Assessments can often simplified by using combinations of certified components or FECS.
R14-9.2 Commissioning and Site Approval — Commissioning and site approval as described in IEC 61508 may be
confusing and therefore the following criteria are necessary for understanding:
R14-9.2.1 Safety-related components should meet the safety requirements defined during the risk analysis.
NOTE 10: Use of Notified Bodies, ATLs or a Professional Engineer to perform system assessment, type approval/site
approval/commissioning of electronic components and for machinery with industrial controllers is defined by the jurisdiction of
use.
R14-9.2.2 During control system commissioning, all relevant documentation of the pre-inspection should be
available. A pre-inspection usually is the first phase of a control system commissioning.
SEMI S2-0703a
E
© SEMI 1991, 2004 90
R14-9.2.3 During pre-inspection, control system
commissioning protocols should be prepared.
R14-9.2.4 If a safety analysis or safety case has been
prepared for the specific installation, all documents
regarding this activity should be made available.
R14-9.2.5 Whether a safety analysis or safety case has
been prepared or not, a directory of available
documents should be generated.
R14-9.2.5.1 This list should include the titles, dates
and number of pages of all documents.
R14-9.2.5.1.1 If possible, all documents should also be
available in electronic form.
R14-9.2.5.2 The documentation should include:
a. Safety Specification (if possible as formal
specification),
b. Top-level diagram of the application (1 or 2
pages),
c. Technical implementation (e.g. block, flow
and timing diagrams),
d. Explanation of separation between safety
critical and not safety critical parts of the
application,
e. Safety handbooks of the system components
(safety handbooks of the safety controllers,
sensors and actuators),
f. Description of interfaces,
g. Specification of all safety relevant program
parts,
h. I/O documentation,
i. Software program documentation,
j. Wiring documents,
k. Diagram and listing of the interaction
between input- and output-data (e.g. safety
matrix, cause-effect diagrams or comparable
documents),
l. Cross reference listing,
m. Source programs on storage medium, and
n. Description of the procedure to verify, that
the documentation, respectively the files on
the storage medium, are identical to the
programs in the application (upload verify,
CRC checksums, or comparable).
R14-10 Safety Performance
R14-10.1 For details on how to achieve the necessary
safety system requirements, see ISO 13849.
NOTE 11: An update of document IEC 62061 is currently
under preparation, and it should be consulted for further
details.
R14-11 Application Examples
R14-11.1 Safety is important in semiconductor
equipment (especially in the area of wafer fabrication)
where toxic media (e.g. gases or chemicals), high-speed
motion, or lasers may be present. The following are
examples of some wafer fabrication equipment which
could be adapted to a FECS:
a. CVD
b. Cleaning Equipment
c. CMP
d. Diffusion/Oxidation
e. Dry Etch Systems
f. Epitaxy
g. Ion Implantation
h. Lithography
i. Physical Vapor Deposition
j. Vacuum Deposition
k. Wet Etch Systems
R14-12 Related Documents
R14-12.1 DIN V VDE Standards
24
DIN V VDE 19250 — Control Technology; Functional
Safety Aspects to be Considered for Measurement and
Control Equipment
24 VDE-Verlag GmbH, Bismarkstrasse 33, 10625 Berlin, Germany,
www.vde.de