You are on page 1of 9

Maximizing

Safety and
Availability

Revised on June 17,
2008
Global Marketing Group
Industrial Safety Systems
Dept.
Copyright Yokogawa Electric Corporation
E-2008-0501 Safety and Availability
2008/05

Safety and Availability

What customers require for SIS

Safety

of course, it is SIS (Safety Instrumented System).


- SIS needs to make a safe action if demand comes
from the process.

High Availability (or less false trip)

at the same time, to keep running the process.


- Internal failure in SIS should not cause a false trip of
the process.
If above wishes are all possible in
a smart, simple architecture , it would be
PERFECT!!

Lets see how Yokogawa


satisfy these requirements!!
Copyright Yokogawa Electric Corporation
E-2008-0501 Safety and Availability
2008/05

Safety and Availability

can
Page 2

Safety and Availability in a Smart


Architecture

VMR* (Versatile Modular


Redundancy)

Safety: Single SIL3


SIL3 is achieved in single Input-CPU-Output module
configuration.

High Availability: Redundant Module


Option
Low false Trip is realized by VMR based on proven Pair &
Spare technology, even when an internal failure is diagnosed,
safety functionality is kept.
*VMR: certified in the US Patent and Trademark Office on March 20, 2007.
Copyright Yokogawa Electric Corporation
E-2008-0501 Safety and Availability
2008/05

Safety and Availability

Page 3

Super Reliable Safety in Single SIL3


is certified as applicable up to SIL3
application in a single modular configuration.
CPU & IOM have internal duplex channel architecture
with
Single CPU module
comparator and diagnostic functions.

Single Input module


Input

Single Output module


CPU

Output

Circuit, MPU

MPU, memory

Circuit, MPU

Circuit, MPU

MPU, memory

Circuit, MPU

Copyright Yokogawa Electric Corporation


E-2008-0501 Safety and Availability
2008/05

Safety and Availability

Page 4

VMR Redundant Option


provides high availability reached by
redundant module options of CPU module & I/O module.
Proven redundant technology from CS3000
Redundant CPU module

Redundant Input
module
Input

Redundant Output module


CPU

Output

Circuit, MPU

MPU, memory

Circuit, MPU

Circuit, MPU

MPU, memory

Circuit, MPU

Input

CPU

Output

Circuit, MPU

MPU, memory

Circuit, MPU

Circuit, MPU

MPU, memory

Circuit, MPU

Copyright Yokogawa Electric Corporation


E-2008-0501 Safety and Availability
2008/05

Safety and Availability

Page 5

Behaviors of VMR
Pair & Spare
I

With One Failure


-No Shut Down
-SIL 3

O
CPU

With Two
Failures
S
FE
Still;
O
I
-No Shut Down
-SIL 3
With Three
Failures
Still;
-No Shut
S: Sensor
Down
FE: Final Element
-SIL 3

Time to
Internal failure in SIS does not
affect the-Unlimited
process.
CPU

Repair

Moreover, on-line change of failure module is


possible without affecting the process.
Copyright Yokogawa Electric Corporation
E-2008-0501 Safety and Availability
2008/05

Safety and Availability

Page 6

Flexible Redundancy

I O

All Solutions
are SIL3!

Single inputs
Dual redundant outputs

CPU
CPU

I O

Dual redundant inputs


Single outputs

CPU
CPU

I O O

Dual redundant inputs


Dual redundant outputs

CPU
CPU

I O O

CPU
CPU

Single inputs
Single outputs

With single or dual redundant


CPUs
- Redundant options are selectable part by
part.
- Flexible selection also saves extra cost.

Copyright Yokogawa Electric Corporation


E-2008-0501 Safety and Availability
2008/05

Safety and Availability

Page 7

Summary

satisfies customers requirements for

SIS
Maximizing both Safety and High Availability
in a smart, simple architecture

Safety: Single SIL3


- SIL3 is achieved in a single Input-CPU-Output module
configuration.
- CPU & IOM have internal duplex channel architecture with
comparator and diagnostic functions.

High Availability: Redundant Module Option


- Low false Trip is realized by Yokogawas only VMR, based on fieldproven CENTUM CS3000 Pair & Spare technology.
- High availability is reached by redundant module options of CPU
module & I/O module.
- Even when an internal failure is diagnosed, safety functionality is
kept and it reduces a false trip of the process.
Copyright Yokogawa Electric Corporation
E-2008-0501 Safety and Availability
2008/05

Safety and Availability

Page 8

Thank you very much


for your attention
Copyright Yokogawa Electric Corporation
E-2008-0501 Safety and Availability
2008/05

Safety and Availability

Page 9

You might also like