13.07.2015 Views

Report on certificate - Tuv-fs.com

Report on certificate - Tuv-fs.com

Report on certificate - Tuv-fs.com

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Resp<strong>on</strong>se Times:The resp<strong>on</strong>se time to external requests applied directly to the FSC system is no more than twicethe cycle time of the automati<strong>on</strong> system.In the case of single-channel system c<strong>on</strong>figurati<strong>on</strong>, individual faults capable of bringing about adangerous operating c<strong>on</strong>diti<strong>on</strong> are detected within the projected test cycle time (c<strong>on</strong>figuredprocess safety time) by the self-test and external test facilities. In the case of redundant systemc<strong>on</strong>figurati<strong>on</strong>s, additi<strong>on</strong>al to the selftests, individual faults are detected within the period of twocycles of the automati<strong>on</strong> system by <strong>com</strong>paring the two channels.In the case of distributed safety-related system c<strong>on</strong>figurati<strong>on</strong>s, additi<strong>on</strong>al fault resp<strong>on</strong>se timesmust be taken into c<strong>on</strong>siderati<strong>on</strong> (see FSC Safety Manual, chapter 5.4, entitled "FSC Networks").Resp<strong>on</strong>se of System to Faults:The resp<strong>on</strong>se of the FSC system to detected faults can be broadly determined by means of theapplicati<strong>on</strong> program. The resp<strong>on</strong>sibility for programming the system’s resp<strong>on</strong>se to faults lies withthe applicati<strong>on</strong> program developer. The standard system resp<strong>on</strong>ses or system messages aredetailed in the FSC Safety Manual in the chapter 6, “FSC System Fault Detecti<strong>on</strong> and Resp<strong>on</strong>se".Individual faults which can be definitely attributed to a particular central part by the highly effectiveself-tests result in rec<strong>on</strong>figurati<strong>on</strong> in the case of the FSC systems "redundant CP - single I/O" and"redundant CP - redundant I/O" due to the dual-channel c<strong>on</strong>figurati<strong>on</strong> and an error message issent to the applicati<strong>on</strong> program.In the case of operati<strong>on</strong> with c<strong>on</strong>tinuous supervisi<strong>on</strong>, i.e. if the operator can observe the processand can react quickly enough to bring the process to a safe c<strong>on</strong>diti<strong>on</strong>, a fail-safe alarm can beprogrammed instead of the system shutdown (see FSC Safety Manual, chapter 6 entitled "FSCSystem Fault Detecti<strong>on</strong> and Resp<strong>on</strong>se").4.1.4 Modificati<strong>on</strong>s to the Applicati<strong>on</strong> Program during Operati<strong>on</strong>On-line modificati<strong>on</strong>s presuppose applicati<strong>on</strong>s programs that have been subjected to particularlythorough testing beforehand, e.g. at simulators. In the case of such thoroughly tested applicati<strong>on</strong>programs, it is sufficient for all modificati<strong>on</strong>s made to be subjected to a full functi<strong>on</strong> test in order todem<strong>on</strong>strate correct functi<strong>on</strong>ing of the program. If n<strong>on</strong>-safety-related modificati<strong>on</strong>s are made, theyshall be subjected to suitable functi<strong>on</strong> tests in order to dem<strong>on</strong>strate absence of interacti<strong>on</strong>.In general, resp<strong>on</strong>sibility for m<strong>on</strong>itoring the process during the period of <strong>on</strong>-line modificati<strong>on</strong> liesentirely with the pers<strong>on</strong> resp<strong>on</strong>sible for the <strong>on</strong>-line modificati<strong>on</strong>. Since <strong>on</strong>-line modificati<strong>on</strong>s aregenerally associated with an increased level of risk, the approval of <strong>on</strong>-line modificati<strong>on</strong>s is at thediscreti<strong>on</strong> of the testing and inspecti<strong>on</strong> center resp<strong>on</strong>sible for approval of the system.TÜV SÜD Rail GmbH 717506225Generic Safety Systems HH84623C_Rev1.0.docx / Rev. 1.0Barthstraße 16 • D-80339 Munich • GermanyAuthor: Martin BraunPh<strong>on</strong>e: +49 (89) 5190 -2899, Fax: -2933 05.02.2013E-Mail: martin.braun@tuev-sued.de Page 27 of 33

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!