23.03.2017 Views

wilamowski-b-m-irwin-j-d-industrial-communication-systems-2011

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

47<br />

SafetyLon<br />

Thomas Novak<br />

SWARCO Futurit<br />

Verkehrssignalssysteme<br />

GmbH<br />

Thomas Tamandl<br />

SWARCO Futurit<br />

Verkehrssignalssysteme<br />

GmbH<br />

Peter Preininger<br />

LOYTEC Electronics GmbH<br />

47.1 Introduction..................................................................................... 47-1<br />

47.2 The General SafetyLon Concept................................................... 47-1<br />

47.3 The Safety-Related Lifecycle.......................................................... 47-2<br />

47.4 The Hardware...................................................................................47-4<br />

47.5 The Safety-Related Firmware......................................................... 47-7<br />

47.6 The SafetyLon Tools...................................................................... 47-10<br />

Acronyms................................................................................................... 47-13<br />

References.................................................................................................. 47-13<br />

47.1 Introduction<br />

SafetyLon is a safety-related automation technology based on LonWorks used to realize a safety-related<br />

<strong>communication</strong> system. The idea is to integrate safety measures into the existing LonWorks to ensure a<br />

high level of integrity.<br />

The type and implementation of the safety measures is specified by the requirements of the international<br />

standard IEC 61508. It is necessary that a malfunction of the system does not lead to serious<br />

consequences, such as injury or even death of people, with a very high probability. Requirements and<br />

the corresponding measures have a great impact on the various entities of the <strong>communication</strong> system:<br />

the node hardware, the <strong>communication</strong> protocol, the node firmware, and the development, installation,<br />

commission, and maintenance process.<br />

In short, in a safety-related <strong>communication</strong> system integrity of data (management or process data) exchanged<br />

among nodes, or between a node and a management unit, must always be ensured with a high probability. For<br />

that reason, the nodes processing the data must meet distinct safety requirements. The hardware is therefore<br />

enhanced with additional integrated circuits, and online software self tests are executed. A protocol used to<br />

exchange data is integrated into the existing protocol. The tools applied to exchange management data that,<br />

in turn, are the base for process data exchange are also enhanced with a safety-related process.<br />

The result is a safety-related automation technology that meets the requirements of IEC 61508 safety<br />

integrity level 3 (SIL 3) [1]. It can be integrated into an existing LonWorks and allows safe and non-safe<br />

<strong>communication</strong> within a single <strong>communication</strong> network.<br />

47.2 the General SafetyLon Concept<br />

A common way to realize a safety-related automation technology is to use a standard technology—in<br />

case of SafetyLon LonWorks—and enhance it with safety features. Such a technology can be realized<br />

by two different approaches: integration of safety measures directly into the existing technology like<br />

CANopen Safety; or treating the non-safe technology as a black-box and base the safety-related measures<br />

logically totally isolated from the remainder on the standard technology.<br />

47-1<br />

© <strong>2011</strong> by Taylor and Francis Group, LLC

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!