
Functional Safety HiD2872, HiC2873(Y1), HiD2876, HiC2877
Planning
2019-07
11
3.2 Assumptions
The following assumptions have been made during the FMEDA:
• Failure rate based on the Siemens standard SN 29500.
• The device will be used under average industrial ambient conditions comparable
to the classification "stationary mounted" according to MIL-HDBK-217F.
Alternatively, operating stress conditions typical of an industrial field environment similar
to IEC/EN 60654-1 Class C with an average temperature over a long period of time
of 40 ºC may be assumed. For a higher average temperature of 60 ºC, the failure rates
must be multiplied by a factor of 2.5 based on experience. A similar factor must be used
if frequent temperature fluctuations are expected.
• Failure rates are constant, wear is not considered.
• External power supply failure rates are not included.
• Since the outputs of the device use common components, these outputs must not be used
in the same safety function.
SIL 2 application (bus powered)
• A SIL 2 application can also be implemented in bus powered mode.
For corresponding connections see datasheet.
• The device shall claim less than 10 % of the total failure budget for a SIL 2 safety loop.
• For a SIL 2 application operating in low demand mode the total PFDavg value of the
SIF (Safety Instrumented Function) should be smaller than 10-2, hence the maximum
allowable PFDavg value would then be 10-3.
• For a SIL 2 application operating in high demand mode the total PFH value of
the SIF should be smaller than 10-6 per hour, hence the maximum allowable PFH value
would then be 10-7 per hour.
• Since the safety loop has a hardware fault tolerance of 0 and it is a type A device,
the SFF must be > 60 % according to table 2 of IEC/EN 61508-2 for a SIL 2 (sub) system.
SIL 3 application (loop powered)
• SIL 3 is not available for HiC2873Y1.
• A SIL 3 application can only be implemented using the loop powered mode.
For corresponding connections see datasheet.
• The device shall claim less than 10 % of the total failure rate for a SIL 3 safety loop.
• For a SIL 3 application operating in low demand mode the total PFDavg value of the
SIF (Safety Instrumented Function) should be smaller than 10-3, hence the maximum
allowable PFDavg value would then be 10-4.
• For a SIL 3 application operating in high demand mode the total PFH value of
the SIF should be smaller than 10-7 per hour, hence the maximum allowable PFH value
would then be 10-8 per hour.
• Since the safety loop has a hardware fault tolerance of 0 and it is a type A device,
the SFF must be > 90 % according to table 2 of IEC/EN 61508-2 for a SIL 3 (sub) system.