SlideShare une entreprise Scribd logo
1  sur  12
Télécharger pour lire hors ligne
Executive summary
Improper integration of Intelligent Electronic Devices
(IED) into medium / high voltage electrical networks
can impact both network performance and safety. Now,
standards such as IEC 61508 provide a framework
from which new safety risks can be managed. This
paper simplifies the complexity of integrating new
devices into existing grid networks by explaining how to
implement IEC safety and maintenance standards.
Examples are presented for how to minimize cost and
maximize safety benefits.
by Michel Bonnet, Maximilien Laforge, and Jean-Baptiste Samuel
998-2095-02-21-14AR0
Impact of IEC 61508 Standards on Intelligent Electrical Networks and Safety Improvement
Schneider Electric White Paper Revision 0 Page 2
Over the last several years utilities have replaced electro-mechanical technologies with new
programmable electronic systems. While utilities have benefitted from the new technologies,
it is difficult for operations personnel to determine every possible failure scenario and to
predict issue-related network behaviors. The stakes are high as the tolerance for medium /
high voltage electrical network downtime continues to erode. Costs are too high for both
customers and utilities when network failures occur. In addition, the need to maintain safe
network operation is a growing concern given the increase in complexity of the emerging
networks.
These programmable electronic systems (also referred to as Intelligent Electronic Devices or
IEDs), are characterized by failure modes that are different from the traditional electro-
mechanical relays. The IEDs contain hundreds of electronic components and have software
embedded into their microprocessors. This results in increased network complexity.
The risks are real. According to a study conducted by the UK Health and Safety Executive
1
65% of incidents involving process control systems occur during the specification, design,
installation and commissioning phases of the product implementation. The rest occur during
the maintenance and modification that take place after commissioning (see Table 1).
For effective management of IED devices, risk reduction can be best achieved through the
execution of robust design principles. Fortunately, industry standards such as IEC 61508
have been introduced that provide guidance on how to improve modern electrical network
safety performance. This paper interprets the IEC 61508 standard and provides guidance for
how to maintain high levels of safety when deploying IEDs on electric networks.
The goal is not to overload the network with IED redundant devices but to install just enough
to both minimize cost and establish the proper level of safety. Some industries, like the
nuclear industry have little leeway in exercising this balance and safety is their top priority. In
other industries such as aerospace, transportation, healthcare, and manufacturing, the risk is
slightly lower, and it may be viable to decrease the number of network IEDs and still attain a
proper safety level. In the utility industry the design of the network should be analyzed to
determine how many customers are affected should a failure occur. Areas of high exposure
should represent those areas of high investment.
1
Out of control: Why control systems go wrong and how to prevent failure - Health & Safety Executive –
UK 2003
IED failure categories
Percentage
of total
Design vs.
Operation
Specification 44%
65%
(Design)
Design and implementation 15%
Installation & commissioning 6%
Operation & maintenance 15% 35%
(Operation)Modification after commissioning 20%
100% 100%
Introduction
Table 1
Results of a study
commissioned by the UK
Health and Safety Executive
Step 1:
Balance cost
vs. safety
Impact of IEC 61508 Standards on Intelligent Electrical Networks and Safety Improvement
Schneider Electric White Paper Revision 0 Page 3
Scenarios for both the protection function and the control function should be evaluated in
order to determine where the risks are greatest. The distinction between these two intelligent
electrical network sub-processes needs to be well understood.
2
Protection functions
Protection functions allow for the quick isolation of the section of the electrical network that is
in default. This limits the consequences of an incident. These protection functions are
performed by a series of IEDs. For example, each IED may be programmed in a specialized
manner which allows it to focus on a particular aspect of the electrical distribution process
such as current arrival, current departure, line status, voltage transformation, or motor
operation.
In order to better understand the concept of protection functions, consider the example of an
arc flash incident. The main role of arc protection is to detect an arc flash and to cut off the
current path feeding the arc. The arc is detected by an arc sensor and confirmed by a phase
or an earth-fault overcurrent. Depending upon where the sensor is located, the confirmation
by overcurrent is done locally or remotely and the tripping occurs locally or remotely (see
Figure 1). The consequence of a non-eliminated default represents risk to people, loss of
production, and damage to expensive physical infrastructure. The consequence of the
tripping function executed without demand from the electrical process represents non-
distributed energy costs and even safety risks in the applications where the loss of power
supply is critical (for example to maintain lighting and / or air circulation in a tunnel in case a
problem occurs). This is why IED protection functions need to be properly configured and
designed.
Control functions
Control functions relieve the burden on operators by automatically executing some pre-
defined actions that must be executed in a very short time. These functions diminish the risk
of human error in circumstances where quick responses are required. Control functions are
frequently performed by IEDs.
2
Mémento De La Sûreté Du Système Electrique Edition 2004, RTE
Figure 1
Arc flash protection is
enabled by the IED’s
integrated in the network
Impact of IEC 61508 Standards on Intelligent Electrical Networks and Safety Improvement
Schneider Electric White Paper Revision 0 Page 4
One example of a common challenge is how to modify the electrical network scheme with
switching devices without breaking capacity. In order to accommodate such a scenario, IEDs
involved in the control function need to be configured and designed according to the following
rules:
 Avoid opening or closing a switch, where changing the position of a switch will
establish or cut off a current circuit
 Avoid opening or closing a circuit breaker where the new position of the circuit breaker
will connect a live circuit to the earth or will establish a current circuit through a switch
in movement
In this example, if key rules are not configured and designed within the IED for proper control
or automatic sequence, the consequences could result in injury and damage to the
equipment.
The level of safety integrity and availability of intelligent electrical networks can be adjusted
or enhanced based on requirements. Appendix A, located at the end of this paper, illustrates
several designs that alter the level of safety, integrity, and availability.
The IEC 61508 standard defines a methodology for engineering safety functions that allows
all the relevant factors, associated with a product or application, to be fully taken into account
and thereby meet the specific needs of users of the product and the application sector
3
. This
standard is widely used by electronic device manufacturers and suppliers when any part of
the safety function contains an electrical, electronic, or programmable electronic component
and where application sector international standards do not exist.
The IEC 61508 standard specifies the risk assessment and the measures to be taken in the
design of safety functions for the avoidance and control of faults. In fact, IEC 61508 provides
a complete safety life cycle that accounts for possible risk of physical injury and damage to
the environment. Acceptable levels of risk are determined and procedures for residual risk
management over time are established (see Figure 2).
3
IEC, Edition 2.0 2010-04, IEC 61508 parts 1 to 7: Functional safety of electrical / electronic /
programmable electronic safety-related systems
Step 2:
Application
of standards
Figure 2
Functional safety and risk
reduction
Impact of IEC 61508 Standards on Intelligent Electrical Networks and Safety Improvement
Schneider Electric White Paper Revision 0 Page 5
The standard also requires that hardware be designed to tolerate a certain level of random
hardware faults, and to demonstrate safe operation in harsh environments. It also calculates
the probability of failure of each safety function.
In order to achieve the necessary Safety Integrity Level (SIL), the standard requires a proof of
residual risk, which is based on the probability of dangerous failure (see Table 2). The
calculation is based on the equipment components that influence the entire safety loop
(sensor, IED, actuator). The failure probabilities of each component are considered together
so that the safety level of the holistic architecture can be determined.
The standard is quite comprehensive and addresses hardware failures, software failures,
systematic failures, and environmental and operational failures. The standard recommends a
set of techniques and measures for controlling these failures.
Some examples of the type of guidance provided in the hardware domain include:
 Verification of measured signals through analogue signal monitoring by comparative
reading between the current / voltage phases
 Verification of the processing unit by a second processing unit through the reciprocal
exchange of data and by detecting differences
 Verification of the output by coil monitoring of the relays
Recommendations to achieve the required safety integrity on the software side include:
 Implementation of self tests to monitor electronics at start up, during IED operation, and
to monitor program execution and data integrity
 Use of static and dynamic analysis tools
 Use of automated verification tools
 Use certified tools for code generation
The standard also provides requirements regarding development methods, competence of
the project team, project management, change management, tracking of requirements, and
documentation.
Safety integrity level, the company experience, and the complexity and uniqueness of the
design all impact the correct implementation of the standards. Since assessments that
evaluate system reliability are relatively new in the domain of power systems, the
recommended practice is to utilize an accredited independent organization to perform the
assessment.
Safety integrity
level (SIL)
Target average probability of
failure per year
Target risk reduction
4 ≥10
-5
to <10
-4
>10 000 to ≤100 000
3 ≥10
-4
to <10
-3
>1 000 to ≤10 000
2 ≥10
-3
to <10
-2
>100 to ≤1 000
1 ≥10
-2
to <10
-1
>10 to ≤100
Table 2
Safety integrity level (SIL)
estimates the probability of
failure
“A third party can ensure
that the quality level is
achieved without requiring
each utility stakeholder to
become an expert in
functional safety.”
Impact of IEC 61508 Standards on Intelligent Electrical Networks and Safety Improvement
Schneider Electric White Paper Revision 0 Page 6
When interpreting IEC 61508 standards, assessment by an external body ensures that
appropriate techniques and measures have been selected and applied. A third party can
ensure that the quality level is achieved without requiring each utility stakeholder to become
an expert in functional safety.
As illustrated in Table 1, 35% of process control system related downtime is due to
maintenance and modifications work. The IEC 61508 standard also addresses recommended
approaches to maintenance.
The purpose of maintenance is to detect and repair faulty systems and anticipate potential
failures (preventive maintenance). To ensure a level of system integrity that conforms to the
IEC 61508 standard, an efficient diagnostic and maintenance plan must be implemented.
In order to execute this step, proper hardware and software data must be gathered. The
following actions are recommended:
 Identify the failure probabilities per device as per the defined Safety Integrity (SIL)
levels (see Table 2). Products that are more reliable will require less maintenance.
 Implement IED software self-tests for all sensitive electronic components (e.g., CPU,
memory). In case of failure, the failure is detected instantly and the test resets the IED
to a safe state. The self testing function helps to significantly reduce the amount of
maintenance that needs to be performed (see Figure 3).
 Simplify spare parts logistics. Since manufacturers of products publish the failure rates
of their designs, it is possible to size the spare parts inventory with more precision and
this helps to reduce logistics costs.
Standard maintenance will still be required for components that are not checked by self-tests.
These elements have a probability of failure that increases over time. It is necessary to
Step 3:
Maintenance
plan
Figure 3
Advantages of devices which
are capable of the self-test
function
Impact of IEC 61508 Standards on Intelligent Electrical Networks and Safety Improvement
Schneider Electric White Paper Revision 0 Page 7
perform scheduled maintenance (such as examining torque connections) in order to maintain
uptime.
The IEC 61508 standard specifies the following aspects of completing a maintenance plan:
 Implementation of procedures
 Maintenance scheduling
 Documentation practices
 Execution of functional safety audits
 Documentation of modifications that have been made to the safety-related systems
Since many IEDs are modular in design, they are swappable which means that they can be
tested off of the network. This helps to reduce both maintenance and planned downtime.
Figure 4 summarizes the benefits of implementing a maintenance plan based on IEC 61508
standard guidelines.
Regarding modifications, the IEC 61508 standard requires that an analysis be carried out to
assess the impact of the proposed modification on safety (see Appendix B for detailed chart
of this process).
The role of software continues to grow in importance as intelligent electrical networks
continue to proliferate. This paper has primarily focused on the IEC 61508 standard, but other
standards such as UL 1998, IEC 60880, and IEC 61508-3 also focus on software within
electrical networks (see Appendix C for a more detailed explanation of these standards).
The standards all share a similar objective. The shared goal is to produce reliable, robust
firmware with pre-defined behaviors in the event of a hardware or firmware failure. The
Figure 4
How a solid maintenance
program increases both
availability and safety
Additional
standards
An increase in
reliability and
maintainability results
in an increase in safety
and availability
Impact of IEC 61508 Standards on Intelligent Electrical Networks and Safety Improvement
Schneider Electric White Paper Revision 0 Page 8
UL standards provide very general recommendations while the IEC standards publish
detailed requirements. IEC standards provide techniques to reach the objectives while UL
standards highlight objectives but do not specify techniques. The IEC 60880 standard, on the
other hand, focuses more on cyber security. Figure 5 provides an overlay map of the major
similarities and differences of the various standards.
The rapid growth of Intelligent Electronic Devices (IED’s) within electric networks is allowing
utilities to manage increased demand from users across the globe. However, the new
technologies demand that safety standards be updated and modernized. Industry standards
such as IED 61508 provide a roadmap for organizations that wish to deploy and support the
new technologies. However many utilities do not have the time to invest in becoming
functional safety experts. Implementation of the new technologies dictates that
knowledgeable individuals help to design and support these new networks. Involvement of
qualified third parties can ensure proper training, can assist in hazard and risk analysis, can
help in the determination of safety integrity levels (SILs), and can specify the safety functions.
©2014SchneiderElectric.Allrightsreserved.
Conclusion
Jean-Baptiste Samuel is responsible for protection relay automation within Schneider
Electric’s Energy Division. He has 10 years of project development experience with
specialization in protection relays and electrical networks. He holds a graduate degree in
software engineering from the University of Bordeaux, France.
Maximilien Laforge is responsible for software dependability within Schneider Electric’s
Projects & Engineering Center (Energy Division). Since 2007 he has worked to improve
software integrity and assists software development teams to attain safety certifications (e.g.,
IEC 61508, UL1998). He holds a Master degree from CNAM, France.
Michel Bonnet is responsible for functional safety management within Schneider Electric’s
energy automation department (Energy Division). Since 2008 he has driven quality assurance
and functional safety management development projects in the domain of protection relays. He
is an experienced application engineer and has worked on safety and substation Automation
Digital Control System projects. He holds an engineering degree from ESIGELEC, in Rouen,
France.
About the authors
Figure 5
Comparison and positioning
of reliability related software
standards
Impact of IEC 61508 Standards on Intelligent Electrical Networks and Safety Improvement
Schneider Electric White Paper Revision 0 Page 9
Appendix A
Safety Integrity and Availability Designs
It is possible to deploy multiple types of architectures to increase the safety integrity (lower probability of
failure) and / or the availability (higher hardware fault tolerance). Below are some examples of common
architectures:
Basic “1 out of 1 (1oo1)” architecture
Here a single channel performs the safety function. Detected faults lead to shutdown.
For example, in a protection function using an undervoltage trip coil, an electrical network defect or a severe
internal failure of the IED will activate a circuit breaker trip.
ActuatorMain FunctionSensor
Diagnostic
1 out of 2 (1oo2) architecture for higher safety integrity
Here, 2 channels can perform the safety function. Detected faults lead to shutdown.
Actuator
Main FunctionSensor
Diagnostic
Main FunctionSensor
Diagnostic
1oo1 with backup for higher availability
For higher availability, a single channel can perform the safety function. Detected faults in the main channel
lead to time limited single-channel operation of the backup function.
For example, in a protection function using a shunt trip coil, an electrical network defect will activate a circuit
breaker trip order while a severe internal failure of the IED will transfer the protection function to a backup
protection.
Block
Actuator
Backup FunctionSensor
Diagnostic
Main FunctionSensor
Diagnostic
Impact of IEC 61508 Standards on Intelligent Electrical Networks and Safety Improvement
Schneider Electric White Paper Revision 0 Page 10
Appendix A (continued)
2oo3 for higher safety integrity and higher availability.
Here, 2 channels can perform the safety function (2oo3). Detected faults in one channel lead to 1oo2
operation.
Actuator
Main FunctionSensor
Diagnostic
Main FunctionSensor
Diagnostic
Main FunctionSensor
Diagnostic
2oo3
Voter
As demonstrated it is possible to adjust safety integrity and availability levels of programmable electronic
systems and networks. However, a complete Safety Integrity Level (SIL) assessment report needs to first be
conducted to determine probability of failure risks.
Such a report should include:
 A functional safety manual that defines the architecture safety and availability goals and how to
operate the system
 Certified data for all safety parameters
 Evidence that failure avoidance and control measures have been executed during the project
 Assessment of the functional safety management system used by the manufacturer (including
processes used, and competence of the project team)
Impact of IEC 61508 Standards on Intelligent Electrical Networks and Safety Improvement
Schneider Electric White Paper Revision 0 Page 11
Appendix B
IEC 61508 Modification Procedure Model4
4
IEC, Edition 2.0 2010-04, IEC 61508 Functional safety of electrical/electronic/programmable electronic
safety-related systems - Part 1: general requirements - Figure 9: Example of modification procedure
model
Impact of IEC 61508 Standards on Intelligent Electrical Networks and Safety Improvement
Schneider Electric White Paper Revision 0 Page 12
Appendix C
Additional Standards
UL 1998 – Software in programmable components
5
UL 1998 is an umbrella standard that addresses application-specific embedded software residing in
programmable components. Application-specific means that the software is limited to a designated application.
This allows effective evaluation of the hazards and risks associated with the software. The requirements in UL
1998 are applicable to embedded microprocessor software whose failure is capable of resulting in a risk of fire,
electric shock, or injury of persons. The requirements in UL 1998 are intended to supplement applicable
product or component standards and requirements. These requirements are intended to address risks that
occur in the software or in the process used to develop and maintain the software.
IEC 61508-3 – Functional safety of electrical/electronic / programmable electronic safety-related
systems – Part 3: Software requirements
IEC 61508 is an umbrella standard concerning basic functional safety issues across many industries. Part 3
covers the software requirements of electrical / electronic / programmable electronic safety-related systems.
The requirements apply to any software forming part of a safety-related system or used to develop a safety-
related system. The requirements cover all software lifecycle activities from specification to design and
validation and up through maintenance.
IEC 60880 – Nuclear power plants: Instrumentation and control systems important to safety - Software
aspects for computer-based systems performing category A functions
6
IEC 60880 is an application specific standard. It addresses the software of computer-based instrumentation
and control (I&C) systems of nuclear power plants performing functions of safety category A as defined by IEC
61226. Category A denotes the functions that play a principal role in the achievement or maintenance of
nuclear power plant safety to prevent a design basis event from leading to unacceptable consequences.
Category A also denotes functions whose failure could directly lead to accident conditions which may cause
unacceptable consequences if not mitigated by other category A functions. This standard provides
requirements for achieving highly reliable software. It addresses each stage of software generation and
documentation, including requirements specification, design, implementation, verification, validation and
operation. The IEC 60880 standard is the interpretation of IEC 61508-3 for the nuclear industry.
Functional safety and cyber security standards
The following is a list of common safety and cyber security related standards:
 IEC 62351-10: Security architecture for TC 57 systems
 IEC 62351-7: Network and system management
 IEC 62351-8 RBAC: Power system management
 IEEE 1686 Standard for Substation Intelligent Electronic Devices Cyber Security Capabilities.
(2007, 12).
 NERC CIP 007: Systems Security Management - Ed. 4. (2011, 01 24)
5
UL 1998 - Software in programmable components 10/2008
6
IEC 60880 – Nuclear power plants – Instrumentation and control systems important to safety – Software aspects for
computer-based systems performing category A functions 05/2006

Contenu connexe

Tendances

Optical Source - Light Emitting Diodes
Optical Source - Light Emitting DiodesOptical Source - Light Emitting Diodes
Optical Source - Light Emitting DiodesFatiha Akma
 
Op amp comparator
Op amp comparatorOp amp comparator
Op amp comparatorAhmadoof
 
Unit 3- OPTICAL SOURCES AND DETECTORS
Unit 3- OPTICAL SOURCES AND DETECTORS Unit 3- OPTICAL SOURCES AND DETECTORS
Unit 3- OPTICAL SOURCES AND DETECTORS tamil arasan
 
Power Transformer Differential protection
Power Transformer Differential protectionPower Transformer Differential protection
Power Transformer Differential protectionRishi Tandon
 
Differential amplifier
Differential amplifierDifferential amplifier
Differential amplifierJayadeep Kumar
 
Basics of earthing
Basics of earthingBasics of earthing
Basics of earthingAsif Eqbal
 
Dispersion in optical fibers
Dispersion in optical fibersDispersion in optical fibers
Dispersion in optical fibersCKSunith1
 
Non linear effects in optical fibers
Non linear effects in optical fibersNon linear effects in optical fibers
Non linear effects in optical fibersCKSunith1
 
Opto electronics notes
Opto electronics notesOpto electronics notes
Opto electronics notesSAURAVMAITY
 
optical communication Unit 3
optical communication Unit 3optical communication Unit 3
optical communication Unit 3Asif Iqbal
 
Fiber optic communication
Fiber optic communicationFiber optic communication
Fiber optic communicationvishal gupta
 
Operational Amplifier
Operational AmplifierOperational Amplifier
Operational AmplifierVARUN KUMAR
 
Optical fiber communications
Optical fiber communicationsOptical fiber communications
Optical fiber communicationsRaju vaghela
 
optical transmitter
optical transmitteroptical transmitter
optical transmitter@zenafaris91
 
Fundamentals of Microprocessor Based Relays
Fundamentals of Microprocessor Based RelaysFundamentals of Microprocessor Based Relays
Fundamentals of Microprocessor Based Relaysmichaeljmack
 

Tendances (20)

Optical Source - Light Emitting Diodes
Optical Source - Light Emitting DiodesOptical Source - Light Emitting Diodes
Optical Source - Light Emitting Diodes
 
Op amp comparator
Op amp comparatorOp amp comparator
Op amp comparator
 
Unit 3- OPTICAL SOURCES AND DETECTORS
Unit 3- OPTICAL SOURCES AND DETECTORS Unit 3- OPTICAL SOURCES AND DETECTORS
Unit 3- OPTICAL SOURCES AND DETECTORS
 
Arc Flash Training
Arc Flash TrainingArc Flash Training
Arc Flash Training
 
Power Transformer Differential protection
Power Transformer Differential protectionPower Transformer Differential protection
Power Transformer Differential protection
 
Laser diodes
Laser diodesLaser diodes
Laser diodes
 
MIL-STD-461 EMI Filters
MIL-STD-461 EMI FiltersMIL-STD-461 EMI Filters
MIL-STD-461 EMI Filters
 
Op-amp.pptx
Op-amp.pptxOp-amp.pptx
Op-amp.pptx
 
Differential amplifier
Differential amplifierDifferential amplifier
Differential amplifier
 
Basics of earthing
Basics of earthingBasics of earthing
Basics of earthing
 
Dispersion in optical fibers
Dispersion in optical fibersDispersion in optical fibers
Dispersion in optical fibers
 
Non linear effects in optical fibers
Non linear effects in optical fibersNon linear effects in optical fibers
Non linear effects in optical fibers
 
Chap6 photodetectors
Chap6 photodetectorsChap6 photodetectors
Chap6 photodetectors
 
Opto electronics notes
Opto electronics notesOpto electronics notes
Opto electronics notes
 
optical communication Unit 3
optical communication Unit 3optical communication Unit 3
optical communication Unit 3
 
Fiber optic communication
Fiber optic communicationFiber optic communication
Fiber optic communication
 
Operational Amplifier
Operational AmplifierOperational Amplifier
Operational Amplifier
 
Optical fiber communications
Optical fiber communicationsOptical fiber communications
Optical fiber communications
 
optical transmitter
optical transmitteroptical transmitter
optical transmitter
 
Fundamentals of Microprocessor Based Relays
Fundamentals of Microprocessor Based RelaysFundamentals of Microprocessor Based Relays
Fundamentals of Microprocessor Based Relays
 

En vedette

20131216 cisec-standards-jp blanquart-jmastruc
20131216 cisec-standards-jp blanquart-jmastruc20131216 cisec-standards-jp blanquart-jmastruc
20131216 cisec-standards-jp blanquart-jmastrucCISEC
 
ISO 26262 introduction
ISO 26262 introductionISO 26262 introduction
ISO 26262 introductionKoenLeekens
 
Achieve iso 26262 certification
Achieve iso 26262 certificationAchieve iso 26262 certification
Achieve iso 26262 certificationPRQA
 
DMAP\'s Brochure
DMAP\'s BrochureDMAP\'s Brochure
DMAP\'s BrochureDMAP
 
Overview of DO-254: Design Assurance Guidance For Airborne Electronic Hardware
Overview of DO-254: Design Assurance Guidance For Airborne Electronic HardwareOverview of DO-254: Design Assurance Guidance For Airborne Electronic Hardware
Overview of DO-254: Design Assurance Guidance For Airborne Electronic HardwareOak Systems
 
Introduction to Functional Safety and SIL Certification
Introduction to Functional Safety and SIL CertificationIntroduction to Functional Safety and SIL Certification
Introduction to Functional Safety and SIL CertificationISA Boston Section
 
DO254 DMAP Training 2011 Trailer
DO254 DMAP Training 2011 TrailerDO254 DMAP Training 2011 Trailer
DO254 DMAP Training 2011 TrailerDMAP
 
IEC 61508-3 SW Engineering
IEC 61508-3 SW EngineeringIEC 61508-3 SW Engineering
IEC 61508-3 SW EngineeringHongseok Lee
 
IP PCIe
IP PCIeIP PCIe
IP PCIeSILKAN
 
Narated mike bartley reqs signoff
Narated mike bartley reqs signoffNarated mike bartley reqs signoff
Narated mike bartley reqs signoffMikeBartley
 
DMAP's presentation
DMAP's presentationDMAP's presentation
DMAP's presentationSILKAN
 
Jamil R. Mazzawi, Founder and CEO, Optima Design Automation
Jamil R. Mazzawi, Founder and CEO, Optima Design AutomationJamil R. Mazzawi, Founder and CEO, Optima Design Automation
Jamil R. Mazzawi, Founder and CEO, Optima Design Automationchiportal
 
Volvo Presents: Support for ISO 26262 in the EAST-ADL/AUTOSAR Context
Volvo Presents: Support for ISO 26262 in the EAST-ADL/AUTOSAR ContextVolvo Presents: Support for ISO 26262 in the EAST-ADL/AUTOSAR Context
Volvo Presents: Support for ISO 26262 in the EAST-ADL/AUTOSAR ContextTorben Haagh
 
ISApaperIEC61508_AMN_Final
ISApaperIEC61508_AMN_FinalISApaperIEC61508_AMN_Final
ISApaperIEC61508_AMN_FinalAndy Nack
 
Dorner works do-254_information
Dorner works do-254_informationDorner works do-254_information
Dorner works do-254_informationAnnmarie Davidson
 

En vedette (20)

20131216 cisec-standards-jp blanquart-jmastruc
20131216 cisec-standards-jp blanquart-jmastruc20131216 cisec-standards-jp blanquart-jmastruc
20131216 cisec-standards-jp blanquart-jmastruc
 
ISO 26262 introduction
ISO 26262 introductionISO 26262 introduction
ISO 26262 introduction
 
IEC 61508
IEC 61508IEC 61508
IEC 61508
 
Achieve iso 26262 certification
Achieve iso 26262 certificationAchieve iso 26262 certification
Achieve iso 26262 certification
 
DMAP\'s Brochure
DMAP\'s BrochureDMAP\'s Brochure
DMAP\'s Brochure
 
Overview of DO-254: Design Assurance Guidance For Airborne Electronic Hardware
Overview of DO-254: Design Assurance Guidance For Airborne Electronic HardwareOverview of DO-254: Design Assurance Guidance For Airborne Electronic Hardware
Overview of DO-254: Design Assurance Guidance For Airborne Electronic Hardware
 
Introduction to Functional Safety and SIL Certification
Introduction to Functional Safety and SIL CertificationIntroduction to Functional Safety and SIL Certification
Introduction to Functional Safety and SIL Certification
 
DO254 DMAP Training 2011 Trailer
DO254 DMAP Training 2011 TrailerDO254 DMAP Training 2011 Trailer
DO254 DMAP Training 2011 Trailer
 
Apex cnc catalogue
Apex cnc catalogueApex cnc catalogue
Apex cnc catalogue
 
IEC61508
IEC61508IEC61508
IEC61508
 
IEC 61508-3 SW Engineering
IEC 61508-3 SW EngineeringIEC 61508-3 SW Engineering
IEC 61508-3 SW Engineering
 
SPINDLE
SPINDLESPINDLE
SPINDLE
 
Sil presentation
Sil presentationSil presentation
Sil presentation
 
IP PCIe
IP PCIeIP PCIe
IP PCIe
 
Narated mike bartley reqs signoff
Narated mike bartley reqs signoffNarated mike bartley reqs signoff
Narated mike bartley reqs signoff
 
DMAP's presentation
DMAP's presentationDMAP's presentation
DMAP's presentation
 
Jamil R. Mazzawi, Founder and CEO, Optima Design Automation
Jamil R. Mazzawi, Founder and CEO, Optima Design AutomationJamil R. Mazzawi, Founder and CEO, Optima Design Automation
Jamil R. Mazzawi, Founder and CEO, Optima Design Automation
 
Volvo Presents: Support for ISO 26262 in the EAST-ADL/AUTOSAR Context
Volvo Presents: Support for ISO 26262 in the EAST-ADL/AUTOSAR ContextVolvo Presents: Support for ISO 26262 in the EAST-ADL/AUTOSAR Context
Volvo Presents: Support for ISO 26262 in the EAST-ADL/AUTOSAR Context
 
ISApaperIEC61508_AMN_Final
ISApaperIEC61508_AMN_FinalISApaperIEC61508_AMN_Final
ISApaperIEC61508_AMN_Final
 
Dorner works do-254_information
Dorner works do-254_informationDorner works do-254_information
Dorner works do-254_information
 

Similaire à Impact of IEC 61508 Standards on Intelligent Electrial Networks and Safety Improvement

FEEDER PROTECTION SYSTEM FROM EARTH FAULT, SHORT CIRCUIT AND OVERLOAD FAULTS
FEEDER PROTECTION SYSTEM FROM EARTH FAULT, SHORT CIRCUIT AND OVERLOAD FAULTSFEEDER PROTECTION SYSTEM FROM EARTH FAULT, SHORT CIRCUIT AND OVERLOAD FAULTS
FEEDER PROTECTION SYSTEM FROM EARTH FAULT, SHORT CIRCUIT AND OVERLOAD FAULTSIRJET Journal
 
Electricity Theft: Reason and Solution
Electricity Theft: Reason and SolutionElectricity Theft: Reason and Solution
Electricity Theft: Reason and SolutionIRJET Journal
 
IRJET- Embedded System based Multi-Source Leakage Current Protection for Low ...
IRJET- Embedded System based Multi-Source Leakage Current Protection for Low ...IRJET- Embedded System based Multi-Source Leakage Current Protection for Low ...
IRJET- Embedded System based Multi-Source Leakage Current Protection for Low ...IRJET Journal
 
SUBSTATION MONITORING AND CONTROLLING BASED ON MICROCONTROLLER BY USING IOT
SUBSTATION MONITORING AND CONTROLLING BASED ON MICROCONTROLLER BY USING IOTSUBSTATION MONITORING AND CONTROLLING BASED ON MICROCONTROLLER BY USING IOT
SUBSTATION MONITORING AND CONTROLLING BASED ON MICROCONTROLLER BY USING IOTIRJET Journal
 
Safety of machinery - Application of standard EN ISO 13849-1
Safety of machinery - Application of standard EN ISO 13849-1Safety of machinery - Application of standard EN ISO 13849-1
Safety of machinery - Application of standard EN ISO 13849-1dnunez1984
 
Safety of machinery
Safety of machinerySafety of machinery
Safety of machineryVo Quoc Hieu
 
STUDY AND ANALYSIS OF PROTECTION SCHEME OF DIGITAL SUBSTATION USING IEC61850-...
STUDY AND ANALYSIS OF PROTECTION SCHEME OF DIGITAL SUBSTATION USING IEC61850-...STUDY AND ANALYSIS OF PROTECTION SCHEME OF DIGITAL SUBSTATION USING IEC61850-...
STUDY AND ANALYSIS OF PROTECTION SCHEME OF DIGITAL SUBSTATION USING IEC61850-...IAEME Publication
 
protectionsettings-120425102109-phpapp01.ppt
protectionsettings-120425102109-phpapp01.pptprotectionsettings-120425102109-phpapp01.ppt
protectionsettings-120425102109-phpapp01.pptThien Phan Bản
 
protectionsettings-120425102109-phpapp01.ppt
protectionsettings-120425102109-phpapp01.pptprotectionsettings-120425102109-phpapp01.ppt
protectionsettings-120425102109-phpapp01.pptThien Phan Bản
 
Guideline for the certification of wind turbine service technicians 2015 july
Guideline for the certification of wind turbine service technicians  2015 julyGuideline for the certification of wind turbine service technicians  2015 july
Guideline for the certification of wind turbine service technicians 2015 julyMichael Mattocks
 
Guideline for the Chartered Certification WTSR of Wind Turbine Service Techni...
Guideline for the Chartered Certification WTSR of Wind Turbine Service Techni...Guideline for the Chartered Certification WTSR of Wind Turbine Service Techni...
Guideline for the Chartered Certification WTSR of Wind Turbine Service Techni...Michael Mattocks
 
Modelling and Implementation of Microprocessor Based Numerical Relay for Prot...
Modelling and Implementation of Microprocessor Based Numerical Relay for Prot...Modelling and Implementation of Microprocessor Based Numerical Relay for Prot...
Modelling and Implementation of Microprocessor Based Numerical Relay for Prot...Kashif Mehmood
 
IRJET- A Review Paper on Development of General Purpose Controller Board
IRJET- A Review Paper on Development of General Purpose Controller BoardIRJET- A Review Paper on Development of General Purpose Controller Board
IRJET- A Review Paper on Development of General Purpose Controller BoardIRJET Journal
 
Password Protected Circuit Breaker Using IoT
Password Protected Circuit Breaker Using IoTPassword Protected Circuit Breaker Using IoT
Password Protected Circuit Breaker Using IoTIRJET Journal
 
Induction Motor Protection Using PLC
Induction Motor Protection Using PLCInduction Motor Protection Using PLC
Induction Motor Protection Using PLCvivatechijri
 
Dr Dev Kambhampati | Electric Utilities Situational Awareness
Dr Dev Kambhampati | Electric Utilities Situational AwarenessDr Dev Kambhampati | Electric Utilities Situational Awareness
Dr Dev Kambhampati | Electric Utilities Situational AwarenessDr Dev Kambhampati
 
NIST Guide- Situational Awareness for Electric Utilities
NIST Guide- Situational Awareness for Electric UtilitiesNIST Guide- Situational Awareness for Electric Utilities
NIST Guide- Situational Awareness for Electric UtilitiesDr Dev Kambhampati
 
IRJET- Protection of Distribution Line Assets- with Modern Microprocessor bas...
IRJET- Protection of Distribution Line Assets- with Modern Microprocessor bas...IRJET- Protection of Distribution Line Assets- with Modern Microprocessor bas...
IRJET- Protection of Distribution Line Assets- with Modern Microprocessor bas...IRJET Journal
 
Understanding type 2 coordinated protection in motor branch circuit
Understanding type 2 coordinated protection in motor branch circuitUnderstanding type 2 coordinated protection in motor branch circuit
Understanding type 2 coordinated protection in motor branch circuitBassam Gomaa
 

Similaire à Impact of IEC 61508 Standards on Intelligent Electrial Networks and Safety Improvement (20)

FEEDER PROTECTION SYSTEM FROM EARTH FAULT, SHORT CIRCUIT AND OVERLOAD FAULTS
FEEDER PROTECTION SYSTEM FROM EARTH FAULT, SHORT CIRCUIT AND OVERLOAD FAULTSFEEDER PROTECTION SYSTEM FROM EARTH FAULT, SHORT CIRCUIT AND OVERLOAD FAULTS
FEEDER PROTECTION SYSTEM FROM EARTH FAULT, SHORT CIRCUIT AND OVERLOAD FAULTS
 
Electricity Theft: Reason and Solution
Electricity Theft: Reason and SolutionElectricity Theft: Reason and Solution
Electricity Theft: Reason and Solution
 
IRJET- Embedded System based Multi-Source Leakage Current Protection for Low ...
IRJET- Embedded System based Multi-Source Leakage Current Protection for Low ...IRJET- Embedded System based Multi-Source Leakage Current Protection for Low ...
IRJET- Embedded System based Multi-Source Leakage Current Protection for Low ...
 
SUBSTATION MONITORING AND CONTROLLING BASED ON MICROCONTROLLER BY USING IOT
SUBSTATION MONITORING AND CONTROLLING BASED ON MICROCONTROLLER BY USING IOTSUBSTATION MONITORING AND CONTROLLING BASED ON MICROCONTROLLER BY USING IOT
SUBSTATION MONITORING AND CONTROLLING BASED ON MICROCONTROLLER BY USING IOT
 
Safety of machinery - Application of standard EN ISO 13849-1
Safety of machinery - Application of standard EN ISO 13849-1Safety of machinery - Application of standard EN ISO 13849-1
Safety of machinery - Application of standard EN ISO 13849-1
 
Safety of machinery
Safety of machinerySafety of machinery
Safety of machinery
 
STUDY AND ANALYSIS OF PROTECTION SCHEME OF DIGITAL SUBSTATION USING IEC61850-...
STUDY AND ANALYSIS OF PROTECTION SCHEME OF DIGITAL SUBSTATION USING IEC61850-...STUDY AND ANALYSIS OF PROTECTION SCHEME OF DIGITAL SUBSTATION USING IEC61850-...
STUDY AND ANALYSIS OF PROTECTION SCHEME OF DIGITAL SUBSTATION USING IEC61850-...
 
Main report
Main reportMain report
Main report
 
protectionsettings-120425102109-phpapp01.ppt
protectionsettings-120425102109-phpapp01.pptprotectionsettings-120425102109-phpapp01.ppt
protectionsettings-120425102109-phpapp01.ppt
 
protectionsettings-120425102109-phpapp01.ppt
protectionsettings-120425102109-phpapp01.pptprotectionsettings-120425102109-phpapp01.ppt
protectionsettings-120425102109-phpapp01.ppt
 
Guideline for the certification of wind turbine service technicians 2015 july
Guideline for the certification of wind turbine service technicians  2015 julyGuideline for the certification of wind turbine service technicians  2015 july
Guideline for the certification of wind turbine service technicians 2015 july
 
Guideline for the Chartered Certification WTSR of Wind Turbine Service Techni...
Guideline for the Chartered Certification WTSR of Wind Turbine Service Techni...Guideline for the Chartered Certification WTSR of Wind Turbine Service Techni...
Guideline for the Chartered Certification WTSR of Wind Turbine Service Techni...
 
Modelling and Implementation of Microprocessor Based Numerical Relay for Prot...
Modelling and Implementation of Microprocessor Based Numerical Relay for Prot...Modelling and Implementation of Microprocessor Based Numerical Relay for Prot...
Modelling and Implementation of Microprocessor Based Numerical Relay for Prot...
 
IRJET- A Review Paper on Development of General Purpose Controller Board
IRJET- A Review Paper on Development of General Purpose Controller BoardIRJET- A Review Paper on Development of General Purpose Controller Board
IRJET- A Review Paper on Development of General Purpose Controller Board
 
Password Protected Circuit Breaker Using IoT
Password Protected Circuit Breaker Using IoTPassword Protected Circuit Breaker Using IoT
Password Protected Circuit Breaker Using IoT
 
Induction Motor Protection Using PLC
Induction Motor Protection Using PLCInduction Motor Protection Using PLC
Induction Motor Protection Using PLC
 
Dr Dev Kambhampati | Electric Utilities Situational Awareness
Dr Dev Kambhampati | Electric Utilities Situational AwarenessDr Dev Kambhampati | Electric Utilities Situational Awareness
Dr Dev Kambhampati | Electric Utilities Situational Awareness
 
NIST Guide- Situational Awareness for Electric Utilities
NIST Guide- Situational Awareness for Electric UtilitiesNIST Guide- Situational Awareness for Electric Utilities
NIST Guide- Situational Awareness for Electric Utilities
 
IRJET- Protection of Distribution Line Assets- with Modern Microprocessor bas...
IRJET- Protection of Distribution Line Assets- with Modern Microprocessor bas...IRJET- Protection of Distribution Line Assets- with Modern Microprocessor bas...
IRJET- Protection of Distribution Line Assets- with Modern Microprocessor bas...
 
Understanding type 2 coordinated protection in motor branch circuit
Understanding type 2 coordinated protection in motor branch circuitUnderstanding type 2 coordinated protection in motor branch circuit
Understanding type 2 coordinated protection in motor branch circuit
 

Plus de Schneider Electric

Secure Power Design Considerations
Secure Power Design ConsiderationsSecure Power Design Considerations
Secure Power Design ConsiderationsSchneider Electric
 
Digital International Colo Club: Attracting Investors
Digital International Colo Club: Attracting InvestorsDigital International Colo Club: Attracting Investors
Digital International Colo Club: Attracting InvestorsSchneider Electric
 
32 phaseo power supplies and transformers briefing
32 phaseo power supplies and transformers briefing 32 phaseo power supplies and transformers briefing
32 phaseo power supplies and transformers briefing Schneider Electric
 
Key Industry Trends, M&A Valuation Trends
Key Industry Trends, M&A Valuation TrendsKey Industry Trends, M&A Valuation Trends
Key Industry Trends, M&A Valuation TrendsSchneider Electric
 
EcoStruxure™ for Cloud & Service Providers
 EcoStruxure™ for Cloud & Service Providers EcoStruxure™ for Cloud & Service Providers
EcoStruxure™ for Cloud & Service ProvidersSchneider Electric
 
Zelio Time Electronic Relay Briefing
Zelio Time Electronic Relay BriefingZelio Time Electronic Relay Briefing
Zelio Time Electronic Relay BriefingSchneider Electric
 
Spacial, Thalassa, ClimaSys Universal enclosures Briefing
Spacial, Thalassa, ClimaSys Universal enclosures BriefingSpacial, Thalassa, ClimaSys Universal enclosures Briefing
Spacial, Thalassa, ClimaSys Universal enclosures BriefingSchneider Electric
 
Relay Control Zelio SSR Briefing
Relay Control Zelio SSR BriefingRelay Control Zelio SSR Briefing
Relay Control Zelio SSR BriefingSchneider Electric
 
Magelis HMI, iPC and software Briefing
Magelis HMI, iPC and software BriefingMagelis HMI, iPC and software Briefing
Magelis HMI, iPC and software BriefingSchneider Electric
 
Where will the next 80% improvement in data center performance come from?
Where will the next 80% improvement in data center performance come from?Where will the next 80% improvement in data center performance come from?
Where will the next 80% improvement in data center performance come from?Schneider Electric
 
EcoStruxure for Intuitive Industries
EcoStruxure for Intuitive IndustriesEcoStruxure for Intuitive Industries
EcoStruxure for Intuitive IndustriesSchneider Electric
 
Systems Integrator Alliance Program 2017
Systems Integrator Alliance Program 2017Systems Integrator Alliance Program 2017
Systems Integrator Alliance Program 2017Schneider Electric
 
EcoStruxure, IIoT-enabled architecture, delivering value in key segments.
EcoStruxure, IIoT-enabled architecture, delivering value in key segments.EcoStruxure, IIoT-enabled architecture, delivering value in key segments.
EcoStruxure, IIoT-enabled architecture, delivering value in key segments.Schneider Electric
 
It's time to modernize your industrial controls with Modicon M580
It's time to modernize your industrial controls with Modicon M580It's time to modernize your industrial controls with Modicon M580
It's time to modernize your industrial controls with Modicon M580Schneider Electric
 
A Practical Guide to Ensuring Business Continuity and High Performance in Hea...
A Practical Guide to Ensuring Business Continuity and High Performance in Hea...A Practical Guide to Ensuring Business Continuity and High Performance in Hea...
A Practical Guide to Ensuring Business Continuity and High Performance in Hea...Schneider Electric
 
Connected Services Study – Facility Managers Respond to IoT
Connected Services Study – Facility Managers Respond to IoTConnected Services Study – Facility Managers Respond to IoT
Connected Services Study – Facility Managers Respond to IoTSchneider Electric
 
Telemecanqiue Cabling and Accessories Briefing
Telemecanqiue Cabling and Accessories BriefingTelemecanqiue Cabling and Accessories Briefing
Telemecanqiue Cabling and Accessories BriefingSchneider Electric
 
Telemecanique Photoelectric Sensors Briefing
Telemecanique Photoelectric Sensors BriefingTelemecanique Photoelectric Sensors Briefing
Telemecanique Photoelectric Sensors BriefingSchneider Electric
 
Telemecanique Limit Switches Briefing
Telemecanique Limit Switches BriefingTelemecanique Limit Switches Briefing
Telemecanique Limit Switches BriefingSchneider Electric
 

Plus de Schneider Electric (20)

Secure Power Design Considerations
Secure Power Design ConsiderationsSecure Power Design Considerations
Secure Power Design Considerations
 
Digital International Colo Club: Attracting Investors
Digital International Colo Club: Attracting InvestorsDigital International Colo Club: Attracting Investors
Digital International Colo Club: Attracting Investors
 
32 phaseo power supplies and transformers briefing
32 phaseo power supplies and transformers briefing 32 phaseo power supplies and transformers briefing
32 phaseo power supplies and transformers briefing
 
Key Industry Trends, M&A Valuation Trends
Key Industry Trends, M&A Valuation TrendsKey Industry Trends, M&A Valuation Trends
Key Industry Trends, M&A Valuation Trends
 
EcoStruxure™ for Cloud & Service Providers
 EcoStruxure™ for Cloud & Service Providers EcoStruxure™ for Cloud & Service Providers
EcoStruxure™ for Cloud & Service Providers
 
Magelis Basic HMI Briefing
Magelis Basic HMI Briefing Magelis Basic HMI Briefing
Magelis Basic HMI Briefing
 
Zelio Time Electronic Relay Briefing
Zelio Time Electronic Relay BriefingZelio Time Electronic Relay Briefing
Zelio Time Electronic Relay Briefing
 
Spacial, Thalassa, ClimaSys Universal enclosures Briefing
Spacial, Thalassa, ClimaSys Universal enclosures BriefingSpacial, Thalassa, ClimaSys Universal enclosures Briefing
Spacial, Thalassa, ClimaSys Universal enclosures Briefing
 
Relay Control Zelio SSR Briefing
Relay Control Zelio SSR BriefingRelay Control Zelio SSR Briefing
Relay Control Zelio SSR Briefing
 
Magelis HMI, iPC and software Briefing
Magelis HMI, iPC and software BriefingMagelis HMI, iPC and software Briefing
Magelis HMI, iPC and software Briefing
 
Where will the next 80% improvement in data center performance come from?
Where will the next 80% improvement in data center performance come from?Where will the next 80% improvement in data center performance come from?
Where will the next 80% improvement in data center performance come from?
 
EcoStruxure for Intuitive Industries
EcoStruxure for Intuitive IndustriesEcoStruxure for Intuitive Industries
EcoStruxure for Intuitive Industries
 
Systems Integrator Alliance Program 2017
Systems Integrator Alliance Program 2017Systems Integrator Alliance Program 2017
Systems Integrator Alliance Program 2017
 
EcoStruxure, IIoT-enabled architecture, delivering value in key segments.
EcoStruxure, IIoT-enabled architecture, delivering value in key segments.EcoStruxure, IIoT-enabled architecture, delivering value in key segments.
EcoStruxure, IIoT-enabled architecture, delivering value in key segments.
 
It's time to modernize your industrial controls with Modicon M580
It's time to modernize your industrial controls with Modicon M580It's time to modernize your industrial controls with Modicon M580
It's time to modernize your industrial controls with Modicon M580
 
A Practical Guide to Ensuring Business Continuity and High Performance in Hea...
A Practical Guide to Ensuring Business Continuity and High Performance in Hea...A Practical Guide to Ensuring Business Continuity and High Performance in Hea...
A Practical Guide to Ensuring Business Continuity and High Performance in Hea...
 
Connected Services Study – Facility Managers Respond to IoT
Connected Services Study – Facility Managers Respond to IoTConnected Services Study – Facility Managers Respond to IoT
Connected Services Study – Facility Managers Respond to IoT
 
Telemecanqiue Cabling and Accessories Briefing
Telemecanqiue Cabling and Accessories BriefingTelemecanqiue Cabling and Accessories Briefing
Telemecanqiue Cabling and Accessories Briefing
 
Telemecanique Photoelectric Sensors Briefing
Telemecanique Photoelectric Sensors BriefingTelemecanique Photoelectric Sensors Briefing
Telemecanique Photoelectric Sensors Briefing
 
Telemecanique Limit Switches Briefing
Telemecanique Limit Switches BriefingTelemecanique Limit Switches Briefing
Telemecanique Limit Switches Briefing
 

Dernier

Generative AI for Technical Writer or Information Developers
Generative AI for Technical Writer or Information DevelopersGenerative AI for Technical Writer or Information Developers
Generative AI for Technical Writer or Information DevelopersRaghuram Pandurangan
 
Transcript: New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024Transcript: New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024BookNet Canada
 
Unleashing Real-time Insights with ClickHouse_ Navigating the Landscape in 20...
Unleashing Real-time Insights with ClickHouse_ Navigating the Landscape in 20...Unleashing Real-time Insights with ClickHouse_ Navigating the Landscape in 20...
Unleashing Real-time Insights with ClickHouse_ Navigating the Landscape in 20...Alkin Tezuysal
 
Assure Ecommerce and Retail Operations Uptime with ThousandEyes
Assure Ecommerce and Retail Operations Uptime with ThousandEyesAssure Ecommerce and Retail Operations Uptime with ThousandEyes
Assure Ecommerce and Retail Operations Uptime with ThousandEyesThousandEyes
 
Merck Moving Beyond Passwords: FIDO Paris Seminar.pptx
Merck Moving Beyond Passwords: FIDO Paris Seminar.pptxMerck Moving Beyond Passwords: FIDO Paris Seminar.pptx
Merck Moving Beyond Passwords: FIDO Paris Seminar.pptxLoriGlavin3
 
[Webinar] SpiraTest - Setting New Standards in Quality Assurance
[Webinar] SpiraTest - Setting New Standards in Quality Assurance[Webinar] SpiraTest - Setting New Standards in Quality Assurance
[Webinar] SpiraTest - Setting New Standards in Quality AssuranceInflectra
 
So einfach geht modernes Roaming fuer Notes und Nomad.pdf
So einfach geht modernes Roaming fuer Notes und Nomad.pdfSo einfach geht modernes Roaming fuer Notes und Nomad.pdf
So einfach geht modernes Roaming fuer Notes und Nomad.pdfpanagenda
 
The Future Roadmap for the Composable Data Stack - Wes McKinney - Data Counci...
The Future Roadmap for the Composable Data Stack - Wes McKinney - Data Counci...The Future Roadmap for the Composable Data Stack - Wes McKinney - Data Counci...
The Future Roadmap for the Composable Data Stack - Wes McKinney - Data Counci...Wes McKinney
 
New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024BookNet Canada
 
A Framework for Development in the AI Age
A Framework for Development in the AI AgeA Framework for Development in the AI Age
A Framework for Development in the AI AgeCprime
 
TeamStation AI System Report LATAM IT Salaries 2024
TeamStation AI System Report LATAM IT Salaries 2024TeamStation AI System Report LATAM IT Salaries 2024
TeamStation AI System Report LATAM IT Salaries 2024Lonnie McRorey
 
Connecting the Dots for Information Discovery.pdf
Connecting the Dots for Information Discovery.pdfConnecting the Dots for Information Discovery.pdf
Connecting the Dots for Information Discovery.pdfNeo4j
 
The State of Passkeys with FIDO Alliance.pptx
The State of Passkeys with FIDO Alliance.pptxThe State of Passkeys with FIDO Alliance.pptx
The State of Passkeys with FIDO Alliance.pptxLoriGlavin3
 
Genislab builds better products and faster go-to-market with Lean project man...
Genislab builds better products and faster go-to-market with Lean project man...Genislab builds better products and faster go-to-market with Lean project man...
Genislab builds better products and faster go-to-market with Lean project man...Farhan Tariq
 
The Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptx
The Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptxThe Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptx
The Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptxLoriGlavin3
 
Digital Identity is Under Attack: FIDO Paris Seminar.pptx
Digital Identity is Under Attack: FIDO Paris Seminar.pptxDigital Identity is Under Attack: FIDO Paris Seminar.pptx
Digital Identity is Under Attack: FIDO Paris Seminar.pptxLoriGlavin3
 
How AI, OpenAI, and ChatGPT impact business and software.
How AI, OpenAI, and ChatGPT impact business and software.How AI, OpenAI, and ChatGPT impact business and software.
How AI, OpenAI, and ChatGPT impact business and software.Curtis Poe
 
How to Effectively Monitor SD-WAN and SASE Environments with ThousandEyes
How to Effectively Monitor SD-WAN and SASE Environments with ThousandEyesHow to Effectively Monitor SD-WAN and SASE Environments with ThousandEyes
How to Effectively Monitor SD-WAN and SASE Environments with ThousandEyesThousandEyes
 
Use of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptx
Use of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptxUse of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptx
Use of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptxLoriGlavin3
 
The Ultimate Guide to Choosing WordPress Pros and Cons
The Ultimate Guide to Choosing WordPress Pros and ConsThe Ultimate Guide to Choosing WordPress Pros and Cons
The Ultimate Guide to Choosing WordPress Pros and ConsPixlogix Infotech
 

Dernier (20)

Generative AI for Technical Writer or Information Developers
Generative AI for Technical Writer or Information DevelopersGenerative AI for Technical Writer or Information Developers
Generative AI for Technical Writer or Information Developers
 
Transcript: New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024Transcript: New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
 
Unleashing Real-time Insights with ClickHouse_ Navigating the Landscape in 20...
Unleashing Real-time Insights with ClickHouse_ Navigating the Landscape in 20...Unleashing Real-time Insights with ClickHouse_ Navigating the Landscape in 20...
Unleashing Real-time Insights with ClickHouse_ Navigating the Landscape in 20...
 
Assure Ecommerce and Retail Operations Uptime with ThousandEyes
Assure Ecommerce and Retail Operations Uptime with ThousandEyesAssure Ecommerce and Retail Operations Uptime with ThousandEyes
Assure Ecommerce and Retail Operations Uptime with ThousandEyes
 
Merck Moving Beyond Passwords: FIDO Paris Seminar.pptx
Merck Moving Beyond Passwords: FIDO Paris Seminar.pptxMerck Moving Beyond Passwords: FIDO Paris Seminar.pptx
Merck Moving Beyond Passwords: FIDO Paris Seminar.pptx
 
[Webinar] SpiraTest - Setting New Standards in Quality Assurance
[Webinar] SpiraTest - Setting New Standards in Quality Assurance[Webinar] SpiraTest - Setting New Standards in Quality Assurance
[Webinar] SpiraTest - Setting New Standards in Quality Assurance
 
So einfach geht modernes Roaming fuer Notes und Nomad.pdf
So einfach geht modernes Roaming fuer Notes und Nomad.pdfSo einfach geht modernes Roaming fuer Notes und Nomad.pdf
So einfach geht modernes Roaming fuer Notes und Nomad.pdf
 
The Future Roadmap for the Composable Data Stack - Wes McKinney - Data Counci...
The Future Roadmap for the Composable Data Stack - Wes McKinney - Data Counci...The Future Roadmap for the Composable Data Stack - Wes McKinney - Data Counci...
The Future Roadmap for the Composable Data Stack - Wes McKinney - Data Counci...
 
New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
 
A Framework for Development in the AI Age
A Framework for Development in the AI AgeA Framework for Development in the AI Age
A Framework for Development in the AI Age
 
TeamStation AI System Report LATAM IT Salaries 2024
TeamStation AI System Report LATAM IT Salaries 2024TeamStation AI System Report LATAM IT Salaries 2024
TeamStation AI System Report LATAM IT Salaries 2024
 
Connecting the Dots for Information Discovery.pdf
Connecting the Dots for Information Discovery.pdfConnecting the Dots for Information Discovery.pdf
Connecting the Dots for Information Discovery.pdf
 
The State of Passkeys with FIDO Alliance.pptx
The State of Passkeys with FIDO Alliance.pptxThe State of Passkeys with FIDO Alliance.pptx
The State of Passkeys with FIDO Alliance.pptx
 
Genislab builds better products and faster go-to-market with Lean project man...
Genislab builds better products and faster go-to-market with Lean project man...Genislab builds better products and faster go-to-market with Lean project man...
Genislab builds better products and faster go-to-market with Lean project man...
 
The Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptx
The Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptxThe Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptx
The Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptx
 
Digital Identity is Under Attack: FIDO Paris Seminar.pptx
Digital Identity is Under Attack: FIDO Paris Seminar.pptxDigital Identity is Under Attack: FIDO Paris Seminar.pptx
Digital Identity is Under Attack: FIDO Paris Seminar.pptx
 
How AI, OpenAI, and ChatGPT impact business and software.
How AI, OpenAI, and ChatGPT impact business and software.How AI, OpenAI, and ChatGPT impact business and software.
How AI, OpenAI, and ChatGPT impact business and software.
 
How to Effectively Monitor SD-WAN and SASE Environments with ThousandEyes
How to Effectively Monitor SD-WAN and SASE Environments with ThousandEyesHow to Effectively Monitor SD-WAN and SASE Environments with ThousandEyes
How to Effectively Monitor SD-WAN and SASE Environments with ThousandEyes
 
Use of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptx
Use of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptxUse of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptx
Use of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptx
 
The Ultimate Guide to Choosing WordPress Pros and Cons
The Ultimate Guide to Choosing WordPress Pros and ConsThe Ultimate Guide to Choosing WordPress Pros and Cons
The Ultimate Guide to Choosing WordPress Pros and Cons
 

Impact of IEC 61508 Standards on Intelligent Electrial Networks and Safety Improvement

  • 1. Executive summary Improper integration of Intelligent Electronic Devices (IED) into medium / high voltage electrical networks can impact both network performance and safety. Now, standards such as IEC 61508 provide a framework from which new safety risks can be managed. This paper simplifies the complexity of integrating new devices into existing grid networks by explaining how to implement IEC safety and maintenance standards. Examples are presented for how to minimize cost and maximize safety benefits. by Michel Bonnet, Maximilien Laforge, and Jean-Baptiste Samuel 998-2095-02-21-14AR0
  • 2. Impact of IEC 61508 Standards on Intelligent Electrical Networks and Safety Improvement Schneider Electric White Paper Revision 0 Page 2 Over the last several years utilities have replaced electro-mechanical technologies with new programmable electronic systems. While utilities have benefitted from the new technologies, it is difficult for operations personnel to determine every possible failure scenario and to predict issue-related network behaviors. The stakes are high as the tolerance for medium / high voltage electrical network downtime continues to erode. Costs are too high for both customers and utilities when network failures occur. In addition, the need to maintain safe network operation is a growing concern given the increase in complexity of the emerging networks. These programmable electronic systems (also referred to as Intelligent Electronic Devices or IEDs), are characterized by failure modes that are different from the traditional electro- mechanical relays. The IEDs contain hundreds of electronic components and have software embedded into their microprocessors. This results in increased network complexity. The risks are real. According to a study conducted by the UK Health and Safety Executive 1 65% of incidents involving process control systems occur during the specification, design, installation and commissioning phases of the product implementation. The rest occur during the maintenance and modification that take place after commissioning (see Table 1). For effective management of IED devices, risk reduction can be best achieved through the execution of robust design principles. Fortunately, industry standards such as IEC 61508 have been introduced that provide guidance on how to improve modern electrical network safety performance. This paper interprets the IEC 61508 standard and provides guidance for how to maintain high levels of safety when deploying IEDs on electric networks. The goal is not to overload the network with IED redundant devices but to install just enough to both minimize cost and establish the proper level of safety. Some industries, like the nuclear industry have little leeway in exercising this balance and safety is their top priority. In other industries such as aerospace, transportation, healthcare, and manufacturing, the risk is slightly lower, and it may be viable to decrease the number of network IEDs and still attain a proper safety level. In the utility industry the design of the network should be analyzed to determine how many customers are affected should a failure occur. Areas of high exposure should represent those areas of high investment. 1 Out of control: Why control systems go wrong and how to prevent failure - Health & Safety Executive – UK 2003 IED failure categories Percentage of total Design vs. Operation Specification 44% 65% (Design) Design and implementation 15% Installation & commissioning 6% Operation & maintenance 15% 35% (Operation)Modification after commissioning 20% 100% 100% Introduction Table 1 Results of a study commissioned by the UK Health and Safety Executive Step 1: Balance cost vs. safety
  • 3. Impact of IEC 61508 Standards on Intelligent Electrical Networks and Safety Improvement Schneider Electric White Paper Revision 0 Page 3 Scenarios for both the protection function and the control function should be evaluated in order to determine where the risks are greatest. The distinction between these two intelligent electrical network sub-processes needs to be well understood. 2 Protection functions Protection functions allow for the quick isolation of the section of the electrical network that is in default. This limits the consequences of an incident. These protection functions are performed by a series of IEDs. For example, each IED may be programmed in a specialized manner which allows it to focus on a particular aspect of the electrical distribution process such as current arrival, current departure, line status, voltage transformation, or motor operation. In order to better understand the concept of protection functions, consider the example of an arc flash incident. The main role of arc protection is to detect an arc flash and to cut off the current path feeding the arc. The arc is detected by an arc sensor and confirmed by a phase or an earth-fault overcurrent. Depending upon where the sensor is located, the confirmation by overcurrent is done locally or remotely and the tripping occurs locally or remotely (see Figure 1). The consequence of a non-eliminated default represents risk to people, loss of production, and damage to expensive physical infrastructure. The consequence of the tripping function executed without demand from the electrical process represents non- distributed energy costs and even safety risks in the applications where the loss of power supply is critical (for example to maintain lighting and / or air circulation in a tunnel in case a problem occurs). This is why IED protection functions need to be properly configured and designed. Control functions Control functions relieve the burden on operators by automatically executing some pre- defined actions that must be executed in a very short time. These functions diminish the risk of human error in circumstances where quick responses are required. Control functions are frequently performed by IEDs. 2 Mémento De La Sûreté Du Système Electrique Edition 2004, RTE Figure 1 Arc flash protection is enabled by the IED’s integrated in the network
  • 4. Impact of IEC 61508 Standards on Intelligent Electrical Networks and Safety Improvement Schneider Electric White Paper Revision 0 Page 4 One example of a common challenge is how to modify the electrical network scheme with switching devices without breaking capacity. In order to accommodate such a scenario, IEDs involved in the control function need to be configured and designed according to the following rules:  Avoid opening or closing a switch, where changing the position of a switch will establish or cut off a current circuit  Avoid opening or closing a circuit breaker where the new position of the circuit breaker will connect a live circuit to the earth or will establish a current circuit through a switch in movement In this example, if key rules are not configured and designed within the IED for proper control or automatic sequence, the consequences could result in injury and damage to the equipment. The level of safety integrity and availability of intelligent electrical networks can be adjusted or enhanced based on requirements. Appendix A, located at the end of this paper, illustrates several designs that alter the level of safety, integrity, and availability. The IEC 61508 standard defines a methodology for engineering safety functions that allows all the relevant factors, associated with a product or application, to be fully taken into account and thereby meet the specific needs of users of the product and the application sector 3 . This standard is widely used by electronic device manufacturers and suppliers when any part of the safety function contains an electrical, electronic, or programmable electronic component and where application sector international standards do not exist. The IEC 61508 standard specifies the risk assessment and the measures to be taken in the design of safety functions for the avoidance and control of faults. In fact, IEC 61508 provides a complete safety life cycle that accounts for possible risk of physical injury and damage to the environment. Acceptable levels of risk are determined and procedures for residual risk management over time are established (see Figure 2). 3 IEC, Edition 2.0 2010-04, IEC 61508 parts 1 to 7: Functional safety of electrical / electronic / programmable electronic safety-related systems Step 2: Application of standards Figure 2 Functional safety and risk reduction
  • 5. Impact of IEC 61508 Standards on Intelligent Electrical Networks and Safety Improvement Schneider Electric White Paper Revision 0 Page 5 The standard also requires that hardware be designed to tolerate a certain level of random hardware faults, and to demonstrate safe operation in harsh environments. It also calculates the probability of failure of each safety function. In order to achieve the necessary Safety Integrity Level (SIL), the standard requires a proof of residual risk, which is based on the probability of dangerous failure (see Table 2). The calculation is based on the equipment components that influence the entire safety loop (sensor, IED, actuator). The failure probabilities of each component are considered together so that the safety level of the holistic architecture can be determined. The standard is quite comprehensive and addresses hardware failures, software failures, systematic failures, and environmental and operational failures. The standard recommends a set of techniques and measures for controlling these failures. Some examples of the type of guidance provided in the hardware domain include:  Verification of measured signals through analogue signal monitoring by comparative reading between the current / voltage phases  Verification of the processing unit by a second processing unit through the reciprocal exchange of data and by detecting differences  Verification of the output by coil monitoring of the relays Recommendations to achieve the required safety integrity on the software side include:  Implementation of self tests to monitor electronics at start up, during IED operation, and to monitor program execution and data integrity  Use of static and dynamic analysis tools  Use of automated verification tools  Use certified tools for code generation The standard also provides requirements regarding development methods, competence of the project team, project management, change management, tracking of requirements, and documentation. Safety integrity level, the company experience, and the complexity and uniqueness of the design all impact the correct implementation of the standards. Since assessments that evaluate system reliability are relatively new in the domain of power systems, the recommended practice is to utilize an accredited independent organization to perform the assessment. Safety integrity level (SIL) Target average probability of failure per year Target risk reduction 4 ≥10 -5 to <10 -4 >10 000 to ≤100 000 3 ≥10 -4 to <10 -3 >1 000 to ≤10 000 2 ≥10 -3 to <10 -2 >100 to ≤1 000 1 ≥10 -2 to <10 -1 >10 to ≤100 Table 2 Safety integrity level (SIL) estimates the probability of failure “A third party can ensure that the quality level is achieved without requiring each utility stakeholder to become an expert in functional safety.”
  • 6. Impact of IEC 61508 Standards on Intelligent Electrical Networks and Safety Improvement Schneider Electric White Paper Revision 0 Page 6 When interpreting IEC 61508 standards, assessment by an external body ensures that appropriate techniques and measures have been selected and applied. A third party can ensure that the quality level is achieved without requiring each utility stakeholder to become an expert in functional safety. As illustrated in Table 1, 35% of process control system related downtime is due to maintenance and modifications work. The IEC 61508 standard also addresses recommended approaches to maintenance. The purpose of maintenance is to detect and repair faulty systems and anticipate potential failures (preventive maintenance). To ensure a level of system integrity that conforms to the IEC 61508 standard, an efficient diagnostic and maintenance plan must be implemented. In order to execute this step, proper hardware and software data must be gathered. The following actions are recommended:  Identify the failure probabilities per device as per the defined Safety Integrity (SIL) levels (see Table 2). Products that are more reliable will require less maintenance.  Implement IED software self-tests for all sensitive electronic components (e.g., CPU, memory). In case of failure, the failure is detected instantly and the test resets the IED to a safe state. The self testing function helps to significantly reduce the amount of maintenance that needs to be performed (see Figure 3).  Simplify spare parts logistics. Since manufacturers of products publish the failure rates of their designs, it is possible to size the spare parts inventory with more precision and this helps to reduce logistics costs. Standard maintenance will still be required for components that are not checked by self-tests. These elements have a probability of failure that increases over time. It is necessary to Step 3: Maintenance plan Figure 3 Advantages of devices which are capable of the self-test function
  • 7. Impact of IEC 61508 Standards on Intelligent Electrical Networks and Safety Improvement Schneider Electric White Paper Revision 0 Page 7 perform scheduled maintenance (such as examining torque connections) in order to maintain uptime. The IEC 61508 standard specifies the following aspects of completing a maintenance plan:  Implementation of procedures  Maintenance scheduling  Documentation practices  Execution of functional safety audits  Documentation of modifications that have been made to the safety-related systems Since many IEDs are modular in design, they are swappable which means that they can be tested off of the network. This helps to reduce both maintenance and planned downtime. Figure 4 summarizes the benefits of implementing a maintenance plan based on IEC 61508 standard guidelines. Regarding modifications, the IEC 61508 standard requires that an analysis be carried out to assess the impact of the proposed modification on safety (see Appendix B for detailed chart of this process). The role of software continues to grow in importance as intelligent electrical networks continue to proliferate. This paper has primarily focused on the IEC 61508 standard, but other standards such as UL 1998, IEC 60880, and IEC 61508-3 also focus on software within electrical networks (see Appendix C for a more detailed explanation of these standards). The standards all share a similar objective. The shared goal is to produce reliable, robust firmware with pre-defined behaviors in the event of a hardware or firmware failure. The Figure 4 How a solid maintenance program increases both availability and safety Additional standards An increase in reliability and maintainability results in an increase in safety and availability
  • 8. Impact of IEC 61508 Standards on Intelligent Electrical Networks and Safety Improvement Schneider Electric White Paper Revision 0 Page 8 UL standards provide very general recommendations while the IEC standards publish detailed requirements. IEC standards provide techniques to reach the objectives while UL standards highlight objectives but do not specify techniques. The IEC 60880 standard, on the other hand, focuses more on cyber security. Figure 5 provides an overlay map of the major similarities and differences of the various standards. The rapid growth of Intelligent Electronic Devices (IED’s) within electric networks is allowing utilities to manage increased demand from users across the globe. However, the new technologies demand that safety standards be updated and modernized. Industry standards such as IED 61508 provide a roadmap for organizations that wish to deploy and support the new technologies. However many utilities do not have the time to invest in becoming functional safety experts. Implementation of the new technologies dictates that knowledgeable individuals help to design and support these new networks. Involvement of qualified third parties can ensure proper training, can assist in hazard and risk analysis, can help in the determination of safety integrity levels (SILs), and can specify the safety functions. ©2014SchneiderElectric.Allrightsreserved. Conclusion Jean-Baptiste Samuel is responsible for protection relay automation within Schneider Electric’s Energy Division. He has 10 years of project development experience with specialization in protection relays and electrical networks. He holds a graduate degree in software engineering from the University of Bordeaux, France. Maximilien Laforge is responsible for software dependability within Schneider Electric’s Projects & Engineering Center (Energy Division). Since 2007 he has worked to improve software integrity and assists software development teams to attain safety certifications (e.g., IEC 61508, UL1998). He holds a Master degree from CNAM, France. Michel Bonnet is responsible for functional safety management within Schneider Electric’s energy automation department (Energy Division). Since 2008 he has driven quality assurance and functional safety management development projects in the domain of protection relays. He is an experienced application engineer and has worked on safety and substation Automation Digital Control System projects. He holds an engineering degree from ESIGELEC, in Rouen, France. About the authors Figure 5 Comparison and positioning of reliability related software standards
  • 9. Impact of IEC 61508 Standards on Intelligent Electrical Networks and Safety Improvement Schneider Electric White Paper Revision 0 Page 9 Appendix A Safety Integrity and Availability Designs It is possible to deploy multiple types of architectures to increase the safety integrity (lower probability of failure) and / or the availability (higher hardware fault tolerance). Below are some examples of common architectures: Basic “1 out of 1 (1oo1)” architecture Here a single channel performs the safety function. Detected faults lead to shutdown. For example, in a protection function using an undervoltage trip coil, an electrical network defect or a severe internal failure of the IED will activate a circuit breaker trip. ActuatorMain FunctionSensor Diagnostic 1 out of 2 (1oo2) architecture for higher safety integrity Here, 2 channels can perform the safety function. Detected faults lead to shutdown. Actuator Main FunctionSensor Diagnostic Main FunctionSensor Diagnostic 1oo1 with backup for higher availability For higher availability, a single channel can perform the safety function. Detected faults in the main channel lead to time limited single-channel operation of the backup function. For example, in a protection function using a shunt trip coil, an electrical network defect will activate a circuit breaker trip order while a severe internal failure of the IED will transfer the protection function to a backup protection. Block Actuator Backup FunctionSensor Diagnostic Main FunctionSensor Diagnostic
  • 10. Impact of IEC 61508 Standards on Intelligent Electrical Networks and Safety Improvement Schneider Electric White Paper Revision 0 Page 10 Appendix A (continued) 2oo3 for higher safety integrity and higher availability. Here, 2 channels can perform the safety function (2oo3). Detected faults in one channel lead to 1oo2 operation. Actuator Main FunctionSensor Diagnostic Main FunctionSensor Diagnostic Main FunctionSensor Diagnostic 2oo3 Voter As demonstrated it is possible to adjust safety integrity and availability levels of programmable electronic systems and networks. However, a complete Safety Integrity Level (SIL) assessment report needs to first be conducted to determine probability of failure risks. Such a report should include:  A functional safety manual that defines the architecture safety and availability goals and how to operate the system  Certified data for all safety parameters  Evidence that failure avoidance and control measures have been executed during the project  Assessment of the functional safety management system used by the manufacturer (including processes used, and competence of the project team)
  • 11. Impact of IEC 61508 Standards on Intelligent Electrical Networks and Safety Improvement Schneider Electric White Paper Revision 0 Page 11 Appendix B IEC 61508 Modification Procedure Model4 4 IEC, Edition 2.0 2010-04, IEC 61508 Functional safety of electrical/electronic/programmable electronic safety-related systems - Part 1: general requirements - Figure 9: Example of modification procedure model
  • 12. Impact of IEC 61508 Standards on Intelligent Electrical Networks and Safety Improvement Schneider Electric White Paper Revision 0 Page 12 Appendix C Additional Standards UL 1998 – Software in programmable components 5 UL 1998 is an umbrella standard that addresses application-specific embedded software residing in programmable components. Application-specific means that the software is limited to a designated application. This allows effective evaluation of the hazards and risks associated with the software. The requirements in UL 1998 are applicable to embedded microprocessor software whose failure is capable of resulting in a risk of fire, electric shock, or injury of persons. The requirements in UL 1998 are intended to supplement applicable product or component standards and requirements. These requirements are intended to address risks that occur in the software or in the process used to develop and maintain the software. IEC 61508-3 – Functional safety of electrical/electronic / programmable electronic safety-related systems – Part 3: Software requirements IEC 61508 is an umbrella standard concerning basic functional safety issues across many industries. Part 3 covers the software requirements of electrical / electronic / programmable electronic safety-related systems. The requirements apply to any software forming part of a safety-related system or used to develop a safety- related system. The requirements cover all software lifecycle activities from specification to design and validation and up through maintenance. IEC 60880 – Nuclear power plants: Instrumentation and control systems important to safety - Software aspects for computer-based systems performing category A functions 6 IEC 60880 is an application specific standard. It addresses the software of computer-based instrumentation and control (I&C) systems of nuclear power plants performing functions of safety category A as defined by IEC 61226. Category A denotes the functions that play a principal role in the achievement or maintenance of nuclear power plant safety to prevent a design basis event from leading to unacceptable consequences. Category A also denotes functions whose failure could directly lead to accident conditions which may cause unacceptable consequences if not mitigated by other category A functions. This standard provides requirements for achieving highly reliable software. It addresses each stage of software generation and documentation, including requirements specification, design, implementation, verification, validation and operation. The IEC 60880 standard is the interpretation of IEC 61508-3 for the nuclear industry. Functional safety and cyber security standards The following is a list of common safety and cyber security related standards:  IEC 62351-10: Security architecture for TC 57 systems  IEC 62351-7: Network and system management  IEC 62351-8 RBAC: Power system management  IEEE 1686 Standard for Substation Intelligent Electronic Devices Cyber Security Capabilities. (2007, 12).  NERC CIP 007: Systems Security Management - Ed. 4. (2011, 01 24) 5 UL 1998 - Software in programmable components 10/2008 6 IEC 60880 – Nuclear power plants – Instrumentation and control systems important to safety – Software aspects for computer-based systems performing category A functions 05/2006