Technical Report Reliability Analyses

Similar documents
Failure Modes, Effects and Diagnostic Analysis

Failure Modes, Effects and Diagnostic Analysis

Failure Modes, Effects and Diagnostic Analysis. Rosemount Inc. Chanhassen, MN USA

FMEDA and Proven-in-use Assessment. Pepperl+Fuchs GmbH Mannheim Germany

FMEDA and Prior-use Assessment. Pepperl+Fuchs GmbH Mannheim Germany

Point Level Transmitters. Pointek CLS200 (Standard) Functional Safety Manual 02/2015. Milltronics

MANUAL Functional Safety

Type 9160 / Transmitter supply unit / Isolating repeater. Safety manual

Failure Modes, Effects and Diagnostic Analysis

Safety manual. This safety manual is valid for the following product versions: Version No. V1R0

Failure Modes, Effects and Diagnostic Analysis

Failure Modes, Effects and Diagnostic Analysis

Functional safety manual RB223

Proline Prowirl 72, 73

IQ Pro SIL option TÜV Certified for use in SIL 2 & 3 applications

Failure Modes, Effects and Diagnostic Analysis

Failure Modes, Effects and Diagnostic Analysis. PR electronics A/S

MANUAL Functional Safety

FMEDA Report Failure Modes, Effects and Diagnostic Analysis and Proven-in-use -assessment KF**-CRG2-**1.D. Transmitter supply isolator

Safety Manual. Vibration Control Type 663. Standard Zone-1-21 Zone Edition: English

Failure Modes, Effects and Diagnostic Analysis

Products Solutions Services. Functional Safety. How to determine a Safety integrity Level (SIL 1,2 or 3)

ACT20X-(2)HTI-(2)SAO Temperature/mA converter. Safety Manual

Soliphant M with electronic insert FEM54

MANUAL Functional Safety

Type Switching repeater. Safety manual

FMEDA and Proven-in-use Assessment. G.M. International s.r.l Villasanta Italy

SAFETY MANUAL SIL Switch Amplifier

Hardware safety integrity (HSI) in IEC 61508/ IEC 61511

MANUAL Functional Safety

Report. Certificate Z Rev. 00. SIMATIC Safety System

FUNCTIONAL SAFETY CERTIFICATE

HART Temperature Transmitter for up to SIL 2 applications

Rosemount Functional Safety Manual. Manual Supplement , Rev AG March 2015

ida Certification Services IEC Functional Safety Assessment Project: Masoneilan Smart Valve Interface, SVI II ESD Customer: GE Energy

HART Temperature Transmitter for up to SIL 2 applications

Failure Modes, Effects and Diagnostic Analysis

Mobrey Hydratect 2462

Failure Modes, Effects and Diagnostic Analysis

OPTISWITCH 5300C. Safety Manual. Vibrating Level Switch. Relay (2 x SPDT) With SIL qualification

FUNCTIONAL SAFETY CERTIFICATE

Low voltage switchgear and controlgear functional safety aspects

2oo4D: A New Design Concept for Next-Generation Safety Instrumented Systems 07/2000

Report. Certificate M6A SIMATIC Safety System

FUNCTIONAL SAFETY ASSESSMENT: AN ISSUE FOR TECHNICAL DIAGNOSTICS

Soliphant M with electronic insert FEM57 + Nivotester FTL325P

It s a safe world after all

Energize to Trip Requirement for SIL 3 according to IEC 61511

Safety Manual. VEGABAR series ma/hart - two-wire and slave sensors With SIL qualification. Document ID: 48369

The ApplicATion of SIL. Position Paper of

Hardware Safety Integrity. Hardware Safety Design Life-Cycle

Loop-powered Transmitter for Thermocouple Type K (NiCr-Ni)

Safe & available...vigilant!

Report. Certificate M6A SIMATIC S7 Distributed Safety

New developments about PL and SIL. Present harmonised versions, background and changes.

Vibrating Switches SITRANS LVL 200S, LVL 200E. Relay (DPDT) With SIL qualification. Safety Manual. Siemens Parts

PSR-PC50. SIL 3 coupling relay for safety-related switch on. Data sheet. 1 Description

Cerabar T PMP131, PMC131, PMP135

Safety Manual VEGASWING 61, 63. Relay (DPDT) With SIL qualification. Document ID: 52082

Original operating instructions Safety relay with relay outputs G1501S / / 2016

Apportionment of Safety Integrity

PFH and PFDavg Data for Trusted TMR System

Intelligent Valve Controller NDX. Safety Manual

Operating instructions AC010S Compact AS-i E-STOP safety module

Report. Certificate Z SIMATIC S7 F/FH Systems

Functional safety manual Liquiphant M/S with FEL58 and Nivotester FTL325N

Service & Support. Functional Safety One Position switch. Safe Machine Concepts without Detours. benefit from the Safety Evaluation Tool.

BT50(T) Safety relay / Expansion relay

Safety-related controls SIRIUS Safety Integrated

D5090S INSTRUCTION MANUAL. D A SIL 3 Relay Output Module for NE Load. DIN-Rail and Termination Board, Model D5090S

MACX MCR-EX-SD LP(-SP)

What functional safety module designers need from IC developers

Safe and Fault Tolerant Controllers

Commissioning and safety manual SIL2

Original operating instructions Safety relay with relay outputs with and without delay G1502S / / 2016

Failure Modes, Effects and Diagnostic Analysis

Functional Example AS-FE-I-013-V13-EN

Functional Safety Processes and SIL Requirements

Table of Content: 1 Objective of assessment Abbreviations and glossary System Overview... 6

ControlLogix SIL2 System Configuration

DK32 - DK34 - DK37 Supplementary instructions

ProductDiscontinued. Rosemount TankRadar Rex. Safety Manual For Use In Safety Instrumented Systems. Safety Manual EN, Edition 1 June 2007

Extension to Chapter 2. Architectural Constraints

INSTRUCTION & SAFETY MANUAL

SAFETY RELAY YRB-4EML-31S MAIN FEATURES

Options for ABB drives. User s manual Emergency stop, stop category 0 (option +Q951) for ACS880-07/17/37 drives

FACTORY AUTOMATION. MANUAL VAA-2E-G4-SE Original Instructions Version 1.1

Sense it! Connect it! Bus it! Solve it! SAFETY MANUAL SWITCHING AMPLIFIERS

SafeC S to MSR127 Conversion

The evolution of the cookbook

PowerFlex 700H AC Drive Safe Torque Off Option

FUNCTIONAL SAFETY CHARACTERISTICS

FACTORY AUTOMATION INSTRUCTION MANUAL. AS-Interface Safety at Work VAA-2E-G4-SN. Version 1.2

Removal of Hardware ESD, Independent of Safety Logic Solver

Applications & Tools. Technology CPU 317TF-2 DP: Example for determining the Safety Integrity Level (SIL) according to IEC

PHOENIX CONTACT - 02/2008

SIL 2/3 Relays for all applications, with or without Line & Load Diagnostics. Product presentation

D6030S - D6030D INSTRUCTION MANUAL. D SIL 3 Switch/Proximity Detector Repeater Relay Output. Models D6030S, D6030D

IQ SIL Option. IQ actuators for use in applications up to SIL 3. sira CERTIFICATION

Using Zynq-7000 SoC IEC Artifacts to Achieve ISO Compliance

Transcription:

Technical Report Client: Product(s): MSK200, MTP200 Number: 23.0.2 Version:.2 Date: 203-05-28 Author(s): Dr. M.J.M. Houtermans Risknowlogy B.V. Brunner bron 2 644 GX Brunssum The Netherlands HTwww.risknowlogy.com TH

Technical Report: 23.0.2 Client: XX Product(s): XMSK200, MTP200 X Number: X23.0.2X Version: X.2X Date: 203-05-28 Author(s): Dr. M.J.M. Houtermans 2002-203 Risknowlogy B.V. All Rights Reserved LIMITATION OF LIABILITY - This report was prepared using best efforts. Risknowlogy does not accept any responsibility for omissions or inaccuracies in this report caused by the fact that certain information or documentation was not made available to us. Any liability in relation to this report is limited to the indemnity as outlined in our Terms and Conditions. A copy is available at all times upon request. Printed in The Netherlands This document is the property of, and is proprietary to Risknowlogy. It is not to be disclosed in whole or in part and no portion of this document shall be duplicated in any manner for any purpose without Risknowlogy s expressed written authorization. Risknowlogy, the Risknowlogy logo, and Functional Safety Data Sheet are registered service marks. Page 2

Technical Report: 23.0.2 Revision History Revision Date By Reason.0 2005-06-0 MH First release. 2006-09-08 MH Updated STL, MTTF, DDC, Type.2 203-05-28 WVP Update of safety function definition Page 3

and summarize Technical Report: 23.0.2 Summary Mütec Instruments has requested Risknowlogy to carry out a reliability study on the products MSK200 and MTP200. Risknowlogy has carried out an FMEA and Markov study to determine the most important reliability properties of the product. These studies have been carried out following the rules of IEC 6508 and 65. To fully understand the calculation results it is necessary to read the complete report. XTable X summarizes the functional safety results. XTable 2X XTable 3X the results for sample calculations that have been carried out on the following reliability properties: PFD: The probability that the safety function has failed upon demand PFDavg: The average probability that the function has failed upon demand PFS: The probability that the safety function causes a spurious trip of the process FO: The probability that the product has failed but can still carry out its function AV: The probability that the function of the product is available UP: The probability that the product is running without any internal failures Table Functional safety summary results Properties MSK200 MTP200 Mixed type B B Hardware fault tolerance 0 0 Safe failure fraction 9.6% 90.% Safe detected failure rate [/h] 8.59E-07 8.75E-07 Safe undetected failure rate [/h].27e-06.5e-06 Dangerous detected failure rate [/h] 6.86E-07.E-06 Dangerous undetected failure rate [/h] 2.59E-07 3.47E-07 Dangerous diagnostic coverage 72.6% 76.2% MTTFd [y] 20.7 78.5 MTTFs [y] 53.6 56.3 Fit for use in Safety Integrity Level 2 2 Fit for use in Spurious Trip Level 4 4 Page 4

Technical Report: 23.0.2 Table 2 Sample probability calculations MSK200 Standalone connected to standard PLC Standalone connected to smart PLC Property Value Value Value Value Mission time year 0 years year 0 years Periodic testing None per 5 years 00% coverage None per 5 years, 00% coverage PFD 2.342e-003.36e-002 2.355e-003.37e-002 PFDavg.74e-003 5.75e-003.87e-003 5.763e-003 PFS 6.65e-005 6.259e-005 2.89e-005 2.652e-005 FO.279e-002 6.202e-002.279e-002 6.202e-002 AV 9.976e-00 9.886e-00 9.976e-00 9.886e-00 UP 9.848e-00 9.266e-00 9.848e-00 9.266e-00 Table 3 Sample probability calculations MTP200 Standalone connected to standard PLC Standalone connected to smart PLC Property Value Value Value Value Mission time year 0 years year 0 years Periodic testing None per 5 years 00% coverage None per 5 years, 00% coverage PFD 3.049e-003.473e-002 3.072e-003.475e-002 PFDavg.529e-003 7.468e-003.552e-003 7.49e-003 PFS 9.702e-005 9.060e-005 2.733e-005 2.552e-005 FO.394e-002 6.733e-002.394e-002 6.733e-002 AV 9.969e-00 9.852e-00 9.969e-00 9.852e-00 UP 9.829e-00 9.79e-00 9.830e-00 9.79e-00 Page 5

Technical Report: 23.0.2 Table of Contents Revision History... 3 Summary... 4 Table of Contents... 6 List of Figures... 7 List of Tables... 7 Terms and Definitions... 8 Introduction... 0. Objective... 0.2 About Mütec Instruments... 0.3 About Risknowlogy... 0.4 References... 0 2 Product Description... 2 2. Introduction... 2 2.2 Product: MSK200... 2 2.3 Product: MTP200... 2 2.4 Alarm Relay and output loop connection... 3 3 Reliability Analysis... 4 3. Introduction... 4 3.2 FMEA... 4 3.3 Results FMEA... 4 3.4 Markov... 5 3.5 Results Markov analysis... 5 4 Conclusions... 20 Page 6

Technical Report: 23.0.2 List of Figures Figure Product: MSK200 and MTP200... 2 Figure 2 Safety function signalling to control system... 3 Figure 2 PFD, PFS, FO Safety Function MSK200 Year, 0 Years... 6 Figure 3 AV, UP Safety Function MSK200 Year, 0 Years... 6 Figure 4 PFD, PFS, FO Safety Function MTP200 Year, 0 Years... 7 Figure 5 AV, UP Safety Function MTP200 Year, 0 Years... 7 Figure 6 PFD, PFS, FO Safety Function MSK200 Year, 0 Years... 8 Figure 7 AV, UP Safety Function MSK200 Year, 0 Years... 8 Figure 8 PFD, PFS, FO Safety Function MTP200 Year, 0 Years... 9 Figure 9 AV, UP Safety Function MTP200 Year, 0 Years... 9 List of Tables Table Functional safety summary results... 4 Table 2 Sample probability calculations MSK200... 5 Table 3 Sample probability calculations MTP200... 5 Table 4 Basis of the analysis... 0 Table 5 Client documentation... Table 6 Risknowlogy documentation... Table 7 Other... Table 8 Results FMEA study MSK200... 4 Table 9 Results FMEA study MTP200... 4 Table 0 Results safety function MSK200... 5 Table Results safety function MTP200... 6 Table 2 Results safety function MSK200... 7 Table 3 Results safety function MTP200... 8 Table 4 Functional safety summary results... 20 Page 7

Technical Report: 23.0.2 Terms and Definitions Term AV Availability Coverage Dangerous failure Safe failure Detected failure Undetected failure Diagnostic test FMEA FO FS Functional safety Hardware fault tolerance HFT Mission time Periodic test PF PFD PFS Proof test Safety function SIL Safety support function Definition See availability. The probability that function of the product (or process) is available The percentage of potential failures detected by a test An internal failure that prevents the product from carrying out its safety function upon demand. See also safe failure. An internal failure where a product carries out its safety function without a demand from the process. This failure can lead to a spurious trip. See also dangerous failure. An internal failure that is detected by built-in diagnostics. Because of the diagnostics the product can act upon the failure. See also undetected failure. An internal failure that is not detected by built-in diagnostics. See also detected failure. A built-in test, frequently and automatically carried out, to determine whether the product could carry out its (safety) function without problems. Failure mode and effects analysis. The probability that the product has failed but can still carry out its function. The probability that the function causes a spurious trip of the process. A product is functionally safe if random, systematic and common cause failures do not lead to malfunctioning of the system and do not result in injury or death of humans, spills to the environment, or loss of equipment or production Hardware fault tolerance indicates the number of failures the product or subsystem can withstand without losing the safety function. See hardware fault tolerance. Time period over which an analysis is carried out. A test that is initiated by hand on a periodic basis, e.g., once per year, to determine whether the product can carry out its (safety) function without problems. See also diagnostic test. The probability that the function has failed upon demand. The probability that the safety function has failed upon demand. The probability that the safety function causes a spurious trip of the process. See periodic test. Function implemented in the product required to achieve a safe state of the process. Safety Integrity Level Function implemented in the product which is not required to achieve a safe state of the process but which enhances the Page 8

Technical Report: 23.0.2 Term STL SFF TÜV Definition functionality of the product. Spurious Trip Level See safe failure fraction. Technischer Überwachungs Verein Type The complexity of a product is designated by Type A or Type B. See IEC 6508, part 2, clause 7.4.3..2 and 7.4.3..3. UP The probability that the product is functioning without any internal failures. Page 9

have Technical Report: 23.0.2 Introduction. Objective The objective of this report is to document the results of the reliability analyses that have been carried out on the MSK200 and MTP200 products developed and manufactured by Mütec Instruments..2 About Mütec Instruments Mütec Instruments was founded in 970 and offers solutions for even the most complicated problems. Mütec s team of highly experienced technical sales professionals and engineers works closely with each client to design a perfectly tailored solution and often forms a close and long-term working relationship with those customers. At Mütec Instruments, we do all the work ourselves-from the initial concept to the finished product. This means that all new developments comply with the strictest criteria and have been optimized for performance and functionality. Worldwide, our customers benefit from this standard..3 About Risknowlogy Risknowlogy is a leading provider of technical risk management solutions including knowledge, services, and products in the functional safety industry. Our key focus is on those clients in need of risk, reliability and safety solutions. Through the Risknowlogy Network of Experts (RNE), the Risknowlogy Reseller Associate Program (RRAP) and the Risknowlogy Affiliate Program (RAP) we are able to offer local services and products globally. Risknowlogy has a working agreement with TUV Rheinland, which assures that all our functional safety services are in line with the latest safety procedures of TUV..4 References The references in XTable 4X, XTable 5X, XTable 6X, and XTable 7X this project: been utilized and/or created during Table 4 Basis of the analysis. IEC 6508-2, Functional Safety of Electrical, Electronic, Programmable Electronic Safety Related Systems, 999 2. IEC 65, Functional safety - Safety instrumented systems for the process industry sector, 2003 3. DIN 9250, Control Technology; Fundamental Safety Aspects To Be Considered for Measurement and Control Equipment, 994 4. DIN 925, MC Protection Equipment, 995 5. DIN V VDE 080, Principles for computers in safety-related systems and Amendment A, 984 6. Siemens SN 29500 Part -4 996-999, Failure rates of components 7. ANSI/IEC/ASQC D6065-997: Application of Markov Techniques 8. Rouvroye, J.L., Enhanced Markov analysis as a method to assess safety in the process industry, Eindhoven University of Technology, 200 9. US MIL-STD-629, Failure Mode and Effects Analysis, National Technical Information Service, VA: Springfield, MIL629 0. Billinton R., Allan R.N., Reliability Evaluation of Engineering Systems, Concepts and Techniques. Pitman Books Limited, London, 983 Page 0

Technical Report: 23.0.2 Table 5 Client documentation. Mütec Instruments GmbH, Circuit Diagram MSK200iEx, Document number M. 3.03.202, revision 2.0 2003-03-30 2. Mütec Instruments GmbH, Circuit Diagram MTP200iEx, Document number M. 3.03.20, revision., 2003-03-0 3. Mütec Instruments GmbH, Betriebsanleitung des MSK200(iEx), 2003-- 4. Mütec Instruments GmbH, Betriebsanleitung des MTP200(iEx), 2004-5-5 5. Mütec Instruments GmbH, Stückliste des MSK200(iEX), Document number M 2.08.0, revision 2, 2002-08-0 6. Mütec Instruments GmbH, Stückliste des MTP200(iEX), Document number M 2.0.0, revision, 2002-0-0 7. TUV Nord e.v, Bericht zür AK4-Prüfung des 9 -Transmitter-Speisegerates MSK200/AK4, rev.0, 999-0-5 8. TUV Nord e.v, Bericht zür AK4-Prüfung des Meßumformers MTP200/AK4, rev.0, 998-08-24 9. Mütec Instruments GmbH, Hardware Implementierungs Dokumentation, MSK 200, 999-07-20 20. Mütec Instruments GmbH, Hardware Implementierungs Dokumentation, MTP 200, 998-07-0 Table 6 Risknowlogy documentation 2. Risknowlogy, Failure modes and effects analysis MSK200, Report number 23.0., version.0, 2005-04-7 22. Risknowlogy, Failure modes and effects analysis MTP200, Report number 23.0.3, version.0, 2005-04-30 23. Risknowlogy, Markov analysis MSK200 and MTP200, Report number 23.0.2, version.0, 2005-05-0 Table 7 Other 24. Risknowlogy Markov Modeling and Calculation Engine 25. Risknowlogy Failure Rate Collection Database Page

Technical Report: 23.0.2 2 Product Description 2. Introduction The products subject to hardware reliability analyses are the MSK200 and MTP200 smart transmitters. Examples of the products are given in XFigure X. The products are described in detail in [X3X,X4X]. Both products are certified by TUV Nord e.v. for AK 4 taking into account DIN 9250 [X3X], DIN 925 [X4X] and DIN V VDE 080 [X5X]. The certification is documented in [X7X,X8X]. The measures to control and avoid failures for AK 4, as required by DIN 9250 and DIN V VDE 080, are equivalent to measures to control and avoid failures in IEC 6508 for SIL 2. To demonstrate compliance with the IEC 6508 SIL 2 requirements it is therefore in addition necessary to perform reliability analysis and calculations. 2.2 Product: MSK200 Figure Product: MSK200 and MTP200 The MSK200 is a universal -channel measuring transmitter supply unit in DuoTec-Failsafe Technology with self-monitoring for supply of 2-wire transmitter. Main application for the product is safety related temperature measurement in explosive environment. The functional safety properties of the product according to IEC 6508 are: Output of the analogue 4-20mA current with an accuracy of 0.2 to 5% measurement and supervision of the loop resistance (0 to 2 KOhm) Supervision of the accuracy of the analogue output (%) Upon demand open the relays or open the alarm relay in case of an internal failure Internally the MSK200 can be divided into a Type A sub module and a Type B sub module. The overall product is a type B; Hardware fault tolerance is 0. 2.3 Product: MTP200 The MTP200 is a universal measuring transmitter in DuoTec-Failsafe Technology with self-control. The functional safety properties of the product according to IEC 6508 are: temperature measurement within specified accuracy of 0.2 to 5% for the resistor input temperature measurement within specified accuracy of 0.2 to 5mV for the thermocouple input measurement and supervision of the loop resistance (0 to 2 KOhm) Output of the analogue 4-20mA current with an accuracy of 0.2 to 5% Supervision of the accuracy of the analogue output (%) Page 2

Technical Report: 23.0.2 Upon demand open the relays or open the alarm relay in case of an internal failure Internally the MTP200 can be divided into a Type A sub module and a Type B sub module. The overall product is a type B; Hardware fault tolerance 0. 2.4 Alarm Relay and output loop connection In case parameters are exceeding the accuracy settings the analogue output current of the device switches to the alarm setting (0 ma or 22 ma). The alarm relay (REL3) indicates the internal status of the diagnostics. The safety function consists of the logical combination of output signal and REL3 status. It is mandatory that both signals are used by control logic or that the analogue signal is connected by REL3 to the control system (see figure below). Figure 2 Safety function signalling to control system Page 3

and present Technical Report: 23.0.2 3 Reliability Analysis 3. Introduction A qualitative and quantitative reliability study has been carried out in line with the requirements of the IEC 6508 [XX] standard and the TUV functional safety procedures. The reliability study consists of failure mode and effects analyses (FMEA) and Markov analyses. 3.2 FMEA The FMEA is a widely used and effective safety analysis technique. The standard reference for this method is US MIL-STD-629 [X9X]. Engineers have always performed an FMEA type of analysis on their design and manufacturing processes, but the first formal applications of the FMEA can be found in the mid-960 in the American aerospace industry. Today different variations of the FMEA technique exist, which differ in focus but not in their approach. An FMEA is carried out for two reasons. First of all to evaluate the failure behavior of the product(s) in terms of single failure modes and their effect on the product and the process the product is trying to protect. Second, to determine the existence and effectiveness of internal diagnostics and the safe failure fraction of the product(s) according to the applicable functional safety standard. 3.3 Results FMEA The results of the FMEA(s) are documented in [X2X,X22X] taking into account [XX,X2X,X3X,X4X,X5X,X6X,X7X,X8X,X9X,X20X,X6X,X25X]. During the FMEA each product was internally divided into type A and type B subsystems. The overall product is a Type B. XTable 8X XTable 9X a summary of the functional safety calculation results for each sub module of the products. Property Table 8 Results FMEA study MSK200 Type B Safe failure fraction 9.6% Safe detected failure rate [h] Safe undetected failure rate [h] Dangerous detected failure rate [h] Dangerous undetected failure rate [h] Don t care rate [h] 8.59E-07.27E-06 6.86E-07 2.59E-07 4.E-08 Table 9 Results FMEA study MTP200 Property Type B Safe failure fraction 90.% Safe detected failure rate [h] 8.75E-07 Safe undetected failure rate [h].5e-06 Dangerous detected failure rate [h].e-06 Dangerous undetected failure rate [h] 3.47E-07 Don t care rate [h] 7.75E-08 Page 4

Technical Report: 23.0.2 3.4 Markov The Markov approach or Markov modeling technique comes originally from the Russian mathematician A.A. Markov (856-922) [X0X]. Markov was engaged in research on mathematically describing random processes. With the years, that work has been extensively developed and the Markov technique has received more and more attention and use. The basic principle of Markov analysis is that a system can exist in different states. Each state is defined by (a combination of) one or more internal failures in the system. The Markov technique is a straightforward and systematic technique to determine the quantitative behavior of systems. The standard reference for Markov is [X7X] and in several research projects it has been identified as the ultimate technique to carry out safety analysis [X8X]. The Markov calculations are performed with [X24X]. The Markov technique is used to carry out quantitative reliability and availability calculations on the product(s). The following reliability properties are calculated: PFD: The probability that the safety function has failed upon demand PFDavg: The average probability that the safety function has failed upon demand PFS: The probability that the safety function causes a spurious trip of the process FO: The probability that the product has failed but can still carry out its function AV: The probability that the function of the product is available UP: The probability that the product is running without any internal failures The following paragraphs summarize the results from the detailed analyses performed in [X23X]. 3.5 Results Markov analysis The calculation results of the two functions of the products are presented in the following tables and figures. For each product the calculations are performed twice. The first calculation represents products purely as standalone devices. This means in practice that they would be connected to a PLC application that cannot differentiate 0-4mA from 4-20mA signals. The second set of calculations represents products that are connected to a smart PLC application that can differentiate the 0-4mA from the 4-20mA output signals. 3.5. Calculations for standalone products connected to standard PLC The following tables and figures show the calculation results for the standalone products connected to a standard PLC application. The results are for the products only, i.e., the values are excluding the PLC hardware. Table 0 Results safety function MSK200 Property Value Value Mission time year 0 years Periodic testing None per 5 years, 00% coverage PFD 2.342e-003.36e-002 PFDavg.74e-003 5.75e-003 PFS 6.65e-005 6.259e-005 FO.279e-002 6.202e-002 AV 9.976e-00 9.886e-00 UP 9.848e-00 9.266e-00 Page 5

Technical Report: 23.0.2 Mütec - MSK200 - SA - Years Mütec - MSK200 - SA - 0 Years PFD PFS FO PFD PFS FO 0. 0. 0.0 0.0 0.00 0.00 0.000 0.000 e-005 e-005 0 000 2000 3000 4000 5000 6000 7000 8000 9000 0 0000 20000 30000 40000 50000 60000 70000 80000 90000 Figure 2 PFD, PFS, FO Safety Function MSK200 Year, 0 Years Mütec - MSK200 - SA - Years Mütec - MSK200 - SA - 0 Years UP AV UP AV 0.998 0.99 0.996 0.98 0.994 0.97 0.992 0.96 0.99 0.95 0.988 0.94 0.986 0.93 0.984 0.92 0 000 2000 3000 4000 5000 6000 7000 8000 9000 0 0000 20000 30000 40000 50000 60000 70000 80000 90000 Figure 3 AV, UP Safety Function MSK200 Year, 0 Years Table Results safety function MTP200 Property Value Value Mission time year 0 years Periodic testing None per 5 years, 00% coverage PFD 3.049e-003.473e-002 PFDavg.529e-003 7.468e-003 PFS 9.702e-005 9.060e-005 FO.394e-002 6.733e-002 AV 9.969e-00 9.852e-00 UP 9.829e-00 9.79e-00 Page 6

Technical Report: 23.0.2 Mütec - MTP200 - SA - Years Mütec - MTP200 - SA - 0 Years PFD PFS FO PFD PFS FO 0. 0. 0.0 0.0 0.00 0.00 0.000 0.000 e-005 e-005 0 000 2000 3000 4000 5000 6000 7000 8000 9000 0 0000 20000 30000 40000 50000 60000 70000 80000 90000 Figure 4 PFD, PFS, FO Safety Function MTP200 Year, 0 Years Mütec - MTP200 - SA - Years Mütec - MTP200 - SA - 0 Years UP AV UP AV 0.998 0.99 0.996 0.98 0.994 0.97 0.992 0.99 0.96 0.95 0.988 0.94 0.986 0.93 0.984 0.92 0.982 0.9 0 000 2000 3000 4000 5000 6000 7000 8000 9000 0 0000 20000 30000 40000 50000 60000 70000 80000 90000 Figure 5 AV, UP Safety Function MTP200 Year, 0 Years 3.5.2 Calculations for standalone products connected to smart PLC The following tables and figures show the calculation results for the standalone products connected to a smart PLC application. The results are for the products only, i.e., the values are excluding the PLC hardware. Table 2 Results safety function MSK200 Property Value Value Mission time year 0 years Periodic testing None per 5 years, 00% coverage PFD 2.355e-003.37e-002 PFDavg.87e-003 5.763e-003 PFS 2.89e-005 2.652e-005 FO.279e-002 6.202e-002 AV 9.976e-00 9.886e-00 UP 9.848e-00 9.266e-00 Page 7

Technical Report: 23.0.2 Mütec - MSK200 - PLC - Years Mütec - MSK200 - PLC - 0 Years PFD PFS FO PFD PFS FO 0. 0. 0.0 0.0 0.00 0.00 0.000 0.000 e-005 e-005 0 000 2000 3000 4000 5000 6000 7000 8000 9000 0 0000 20000 30000 40000 50000 60000 70000 80000 90000 Figure 6 PFD, PFS, FO Safety Function MSK200 Year, 0 Years Mütec - MSK200 - PLC - Years Mütec - MSK200 - PLC - 0 Years UP AV UP AV 0.998 0.99 0.996 0.98 0.994 0.97 0.992 0.96 0.99 0.95 0.988 0.94 0.986 0.93 0.984 0.92 0 000 2000 3000 4000 5000 6000 7000 8000 9000 0 0000 20000 30000 40000 50000 60000 70000 80000 90000 Figure 7 AV, UP Safety Function MSK200 Year, 0 Years Table 3 Results safety function MTP200 Property Value Value Mission time year 0 years Periodic testing None per 5 years year, 00% coverage PFD 3.072e-003.475e-002 PFDavg.552e-003 7.49e-003 PFS 2.733e-005 2.552e-005 FO.394e-002 6.733e-002 AV 9.969e-00 9.852e-00 UP 9.830e-00 9.79e-00 Page 8

Technical Report: 23.0.2 Mütec - MTP200 - PLC - Years Mütec - MTP200 - PLC - 0 Years PFD PFS FO PFD PFS FO 0. 0. 0.0 0.0 0.00 0.00 0.000 0.000 e-005 e-005 0 000 2000 3000 4000 5000 6000 7000 8000 9000 0 0000 20000 30000 40000 50000 60000 70000 80000 90000 Figure 8 PFD, PFS, FO Safety Function MTP200 Year, 0 Years Mütec - MTP200 - PLC - Years Mütec - MTP200 - PLC - 0 Years UP AV UP AV 0.998 0.99 0.996 0.98 0.994 0.97 0.992 0.99 0.96 0.95 0.988 0.94 0.986 0.93 0.984 0.92 0.982 0.9 0 000 2000 3000 4000 5000 6000 7000 8000 9000 0 0000 20000 30000 40000 50000 60000 70000 80000 90000 Figure 9 AV, UP Safety Function MTP200 Year, 0 Years Page 9

and the Technical Report: 23.0.2 4 Conclusions Based on the description of the product in chapter 2, the reliability analyses and sample calculations in chapter X3X the applicable functional safety standards listed in XTable 4X functional safety results are summarized in XTable 4X. Additional XTable 4X gives the MTTF, the dangerous diagnostic coverage and the spurious trip level. The end-user can use the results presented in this report to calculate the PFD of the safety loop taking into account all components of the loop. Depending the application program of the connected PLC, the common cause factor and the periodic proof testing by the end user it is possible to use this product in a oo architecture up to the PFD requirements according to SIL 2 or in a oo2 architecture up to the PFD requirements according to SIL 3. The end-user can improve the performance of the products in terms of the probability of fail safe by writing an application program that differentiate the 0-4mA from the 4-20mA output signals. See calculation examples in paragraph X3.5.2X. Table 4 Functional safety summary results Properties MSK200 MTP200 Type B B Hardware fault tolerance 0 0 Safe failure fraction 9.6% 90.% Safe detected failure rate [/h] 8.59E-07 8.75E-07 Safe undetected failure rate [/h].27e-06.5e-06 Dangerous detected failure rate [/h] 6.86E-07.E-06 Dangerous undetected failure rate [/h] 2.59E-07 3.47E-07 Dangerous diagnostic coverage 72.6% 76.2% MTTFd [y] 20.7 78.5 MTTFs [y] 53.6 56.3 Fit for use in Safety Integrity Level 2 2 Fit for use in Spurious Trip Level 4 4 Page 20