semi合集-English.pdf - 第7136页

SEMI S22-1103a © SEMI 2003, 2005 21 13.4 Operat ing Modes  When a system has more than one operating m ode, and operating m ode selection ca n result in a hazardous condition, mode selection should be restricted to trai…

100%1 / 7923
SEMI S22-1103a © SEMI 2003, 2005 20
EXCEPTION 2: Assemblies that are not intended to be used as stand-alone equipment, but rather within an overall
integrated system, and which receive their power from the end-user system, may not have a separate emergency off
circuit. The assembly’s installation manual should provide clear instructions to the equipment installer to connect
the assembly to the integrated system’s emergency off circuit.
NOTE 36: It is recommended that the emergency off function not reduce the effectiveness of safety devices or of devices with
safety-related functions (e.g., magnetic or braking devices) necessary to bring the equipment to a safe shutdown condition
effectively.
13.3.2 EMO Interfaces External EMO interfaces should be provided where the equipment is likely to be
integrated and is likely to have shared hazards with other assemblies in the end user’s facility. If an external EMO
interface is provided, the supplier should include instructions for connecting to the interface.
13.3.3 EMO Function Activation of the emergency off circuit should de-energize all hazardous voltage and all
power greater than 240 volt-amperes in the equipment beyond the main power enclosure.
EXCEPTION 1: A non-hazardous voltage EMO circuit (typically 24 Volts) may remain energized.
EXCEPTION 2: Safety related devices (e.g., smoke detectors, gas/water leak detectors, pressure measurement
devices, etc.) may remain energized from a non-hazardous power source.
EXCEPTION 3: A computer system or PLC performing data/alarm logging and error recovery functions may
remain energized, provided that the breaker and receptacle supplying the power to the computer system are clearly
labeled as remaining energized after EMO activation.
NOTICE: ¶13.3.4 below will be withdrawn upon July 1, 2006 publication and replaced by the new ¶13.3.4
including: figures and tables as shown in Delayed Revisions §2, however, the EH & S Committee has voted
that implementation of the information is OPTIONAL before the effective date.
13.3.4 EMO Design The design of the EMO circuit should include all the following:
a) the EMO circuit should not include controls that enable it to be defeated or bypassed;
b) the EMO circuit should consist of electro-mechanical components;
c) resetting the EMO switch should not re-energize circuits, equipment, or subassemblies that create a hazard to
personnel or the facility;
d) the EMO circuit should shut down the equipment by de-energizing rather than energizing control components;
and
e) the EMO actuator should be non-lockable and self-latching.
EXCEPTION 1: Solid-state devices and components may be used, provided the system or relevant parts of the
system are evaluated and found suitable for use. The components should be evaluated and found suitable
considering abnormal conditions such as over voltage, under voltage, power supply interruption, transient.
NOTE 37: For equipment intended for use in locations where fire or explosion hazards may exist, it is recommended that a
pneumatic or intrinsically safe EMO circuit be considered.
13.3.5 EMO Identification The EMO identification should include the following:
a) the emergency off actuator should be red and mushroom shaped;
b) a yellow background for the EMO should be provided;
c) all Emergency Off actuators should be clearly labeled as “EMO,” “Emergency Off,” or the equivalent, and
should be clearly legible from the viewing location. The label may appear on the actuator or on the yellow
background; and
d) Emergency Off buttons should be located or guarded to minimize accidental activation.
13.3.6 EMO Location and Size Emergency Off buttons should be readily accessible from operating and regularly
scheduled maintenance locations and appropriately sized to enable activation by the heel of the palm.
13.3.7 No operator or regularly scheduled maintenance location should require more than 3 meters (10 feet) travel
to the EMO button.
SEMI S22-1103a © SEMI 2003, 2005 21
13.4 Operating Modes When a system has more than one operating mode, and operating mode selection can
result in a hazardous condition, mode selection should be restricted to trained service or maintenance personnel.
13.5 Suspension of safeguards should satisfy ¶8.15.
13.6 Safety Controls
13.6.1 Hold-to-run Controls Hold-to-run controls should only be used if a hazard analysis determines that they
are an appropriate and adequate means to mitigate a hazard. When hold-to-run controls are used, they should
necessitate continuous actuation of the control devices to achieve operation.
13.6.2 Two Handed Controls When dual series-connected hand controls are used to isolate the operator from
hazards, the hand controls and/or control circuit should comply with the following:
a) the hand controls should be momentary contact switches with black or green heads. Each hand control should
be protected against unintended operation;
b) each hand control should be arranged by design, construction, and/or separation so that the use of both hands
is needed to start the machine cycle. Preferably, they are mounted at least 610 mm (24 in.) apart at the same
height;
c) two hand controls should be designed so that both hand controls need to be depressed within one second of
each other for the machine to cycle and both hand controls need to be held depressed until the hazard no
longer exists; and
d) the control system should incorporate an anti-repeat feature that limits the machine to one cycle for each
depression of the hand controls. The control system should incorporate an anti-tie-down feature that demands
the release of both hand controls between cycles.
13.6.3 Combined Start and Stop Controls Controls that alternately initiate and stop motion should only be used
when no hazardous condition can arise from their operation.
13.7 Safety Interlock Circuits
13.7.1 Protection against Fault Conditions When a single point failure can result in an unacceptable level of
risk, a safety interlocking circuit or other suitable means should be provided to protect against the consequences of
that single point failure.
13.7.2 Safety interlock Function Safety interlocks should be designed such that the equipment is automatically
brought to a safe condition before personnel can access the point of hazard. Each safety interlock, when activated,
should alert the operator immediately.
EXCEPTION: If a safety interlock triggers the emergency off (EMO) circuit, or otherwise removes power to the
user interface, notification to the operator is not needed.
NOTE 38: An explanation of the cause is preferred upon activation of a safety interlock.
NOTICE: ¶13.7.3 below will be withdrawn upon July 1, 2006 publication and replaced by the new ¶13.7.3
including: figures and tables as shown in Delayed Revisions §1, however, the EH & S Committee has voted
that implementation of the information is OPTIONAL before the effective date.
13.7.3 Safety Interlock Design Electromechanical devices and components are preferred. Solid state devices and
non-programmable solid state components may be used provided that the safety interlock system or relevant parts of
the system are evaluated for suitability for use in accordance with appropriate standard(s). The evaluation for
suitability should take into consideration abnormal conditions such as overvoltage, undervoltage, power supply
interruption, transient overvoltage, ramp voltage, electromagnetic susceptibility, electrostatic discharge, thermal
cycling, humidity, dust, vibration, jarring, or interfacing to a network.
NOTICE: ¶13.7.3.1 below will be withdrawn upon July 1, 2006 publication and replaced by the new ¶13.7.3.1
including: figures and tables as shown in Delayed Revisions §1, however, the EH & S Committee has voted
that implementation of the information is OPTIONAL before the effective date.
SEMI S22-1103a © SEMI 2003, 2005 22
13.7.3.1 FECS may be used in conjunction with electromechanical or solid state devices and components provided
the programmable safety control system conforms to an appropriate standard for electronic safety systems.
Components of the FECS should be tested and certified according to the requirements of the standard used.
Examples of recognized electronic safety systems standards include IEC 61508, ISO 13849-1, (EN 954-1),
ANSI/ISA SP84.01, DIN/V/VDE-0801.
EXCEPTION: Where the severity of a reasonably foreseeable mishap is deemed to be minor per SEMI S10, a
software-based safety interlock may be considered suitable.
NOTE 39: ¶8.4.1 states additional assessment criteria for safety-related components and assemblies.
NOTE 40: A FECS is a subsystem to a (PES) Programmable Electronic System. IEC 61508 is the preferred standard for
complex PES.
13.7.4 Safety Interlock Override The safety interlock system should be designed to minimize the need to
override safety interlocks during maintenance activities.
13.7.5 When maintenance access to areas protected by safety interlocks is necessary, safety interlocks that can be
defeated may be used, provided that they require an intentional operation to bypass. Safety interlocks that safeguard
operator tasks should not be able to be defeated without the use of a tool. Upon exiting or completing the
maintenance mode, all safety interlocks should be automatically restored.
13.7.6 If a safety interlock is defeated, the maintenance manual should identify administrative controls to safeguard
personnel and to minimize the hazard.
13.7.7 The restoration of a safety interlock should not automatically initiate machine motion or operation where this
can give rise to a hazardous condition.
13.7.8 Safety Interlock Circuit Connection To reduce the risk of interlocks not functioning correctly from short
circuiting of the device or wiring to ground, switches, contacts, and other safety interlock control devices should not
be connected to the earthed side of the circuit.
13.7.9 Shunt Trip Circuits Shunt trips should not be used as safety interlocks because they are not fail-safe.
13.8 Multiple Points of Control
13.8.1 Where multiple points of control are provided on a system, a hardware based device which meets the
considerations of ¶13.7 should be used to ensure a single point of control when multiple points of control can cause
an unacceptable risk.
13.8.2 The control point selection hardware-based device should either be lockable or be able to be under the
immediate control of the person(s) exposed to the hazard.
14 Interface Control
14.1 Hand Control Devices — Hand control devices should be located so that their intended use does not cause an
unacceptable risk.
14.1.1 Hand control devices should be designed and mounted to minimize inadvertent operation if an unacceptable
risk could result from inadvertent activation.
14.1.2 Control devices should withstand the stresses of normal use and foreseeable misuse. Considerations should
be given to normal operation as well as fault conditions. Factors such as chemical exposure to insulation, mechanical
and thermal stress, radiation, and other environmental factors that may result in unacceptable risks, should be taken
into account.
14.2 Push-actuators (buttons)
14.2.1 Colors — The color of the start/on actuator should be white, gray, black, or green. Green is preferred. Red
should not be used for the start/on actuator.
14.2.1.1 The color red should be used for EMO actuators. A yellow background for the EMO should be provided.
Refer to ¶13.3.
14.2.1.2 Non-EMO actuators should be differentiated from the EMO actuator.