Pressure transmitter SIL-2 DST P92S

Similar documents
Intrinsically safe pressure transmitter MBS 4201, MBS 4251, MBS 4701 and MBS 4751

Original operating instructions Fail-safe inductive sensor GG507S / / 2013

Pressure Transmitter Type AKS 32 and AKS 33 REFRIGERATION AND AIR CONDITIONING. Technical leaflet

Pressure transmitter AKS 32 and AKS 33

User manual. Load cell with one built in amplifier KOSD-FA KIMD-FA KEND-FA Load cell with two built in amplifiers KOSD-FAD KIMD-FAD KEND-FAD

Heavy Duty Pressure Transducers

Primary switch mode power supplies Product group picture

CP-E range Benefits and advantages

Test Specification for Type Approval

Original operating instructions Fail-safe inductive sensor GM504S / / 2010

Power supply CP-D 24/4.2 Primary switch mode power supply

Original operating instructions Fail-safe inductive sensor GG507S

Power supply CP-E 24/2.5

ACTUATOR LA12/LA12 PLC

VISION HISTORY Rev Level Rev Date Change Made Reason for Change Effective Approved By A 11/11/13 Specification Release S. Sadot A1 14/01/14 Update ope

Pressure measurement PBMR Fully welded pressure transmitter for railway applications

MACX MCR-UI-UI-UP(-SP)(-NC)

OIS25. Optical smart sensor for hydraulic cylinders. General Description. Features. Applications. Pin Functions. Ordering Information

Power supply CP-E 24/0.75

DSA150 Series. xxx Series. 150 Watts. AC-DC Power Supplies. Models & Ratings. Mechanical Details 3.92 (99.8) 2.18 (55.5) 4.92 (125.

Output Voltage* (nom.)(adjustable)

Power supply CP-E 24/20.0

Power supply CP-D 12/2.1

CP-T range Product group picture

ADC5000 SERIES. AC/DC Switch Mode Power Supplies and Rectifiers for Industrial and Telecom Applications. 60W, 125W and 250 W

Features. Picture. Specifications. Pressure Transmitter 4-20mA 2-wire MPG Type: MPGxxxxxxxx for level measurement Order No.: see Table 1 / Page 4

Type CP-S, CP-C & CP-A Switch mode

User and Safety Manual ProLine P224xx P1

Original operating instructions Fail-safe inductive sensor GM705S

DSR120 Series. xxx Series. 120 Watts. AC-DC Power Supplies. Models & Ratings. Mechanical Details

Technical explanations for electronic pressure switches

AUTOMOTIVE CURRENT TRANSDUCER FLUXGATE TECHNOLOGY CAB 300-C/SP3-XXX

Power supply CP-D 24/1.3

QUINT-PS/ 3AC/24DC/10

Inductive sensor slot-type SI2-K08-AP7

TPP 40 Series, 40 Watt. Order code Output voltage Output current max. Efficiency. max. screw terminal pin connector Vout 1 Vout 2 Vout 3

ACTUATOR LA36 PRODUCT DATA SHEET

AUTOMOTIVE CURRENT TRANSDUCER OPEN LOOP TECHNOLOGY DHAB S/157

CP-T range Benefits and advantages

SPECIFICATION SWITCHING POWER SUPPLY BPS-300SP/2U 6-OUTPUT WITH ACTIVE PFC FUNCTION SINGLE POWER 300W BEST POWER SOLUTIONS, INC.

The MPB150 product line is approved to the latest international regulatory standards, and displays the CE Mark.

Output Voltage Range ma ma 700 ma 176~305 Vac 160~357 Vdc 250W 93% 0.98 EBD-255S105DV

U5300 Industrial Pressure Transducer

Energy Management Energy Meter Type EM110

AUTOMOTIVE CURRENT TRANSDUCER OPEN LOOP TECHNOLOGY DHAB S/124

Your Global Automation Partner. IMX12-DI01 Isolating Switching Amplifier. Safety Manual

SPECIFICATION SWITCHING POWER SUPPLY SINGLE POWER 250W BEST POWER SOLUTIONS, INC. 9F, NO.196-7, SEC.3, TA-TUNG RD SHI CHIH, TAIPEI, TAIWAN, R.O.C.

Energy Management Energy Meter Type EM110

Three-phase monitoring relay CM-PFS

Doc. EA Model Number:

Electronic timer CT-TGD.22

Proximity Sensor Terminology

Temperature monitoring relays CM-TCS Monitoring relays for monitoring temperatures with a PT100 sensor (2- or 3-wire connection)

SPECIFICATION REDUNDANT POWER SUPPLY HOT-SWAPPABLE 370W+370W

Overcurrent Protection / 7SJ45

75W Constant Current (700mA) LED Driver

PD30CNB25xxPS. Photoelectrics, Background suppression reflective - PointSpot. Main features. Main functions. Description

Electronic timer CT-TGD.12 Pulse generator with 1 c/o (SPDT) contact

Liquid level monitoring relay CM-ENS.2x

FOUNDATION Fieldbus Junction Box

AUTOMOTIVE CURRENT TRANSDUCER OPEN LOOP TECHNOLOGY HAH3DR 800-S03/SP2

SIPROTEC easy 7SJ46 Numerical Overcurrent Protection Relay

Customer: Standard type Page 1 of 7 Description Fluxgate current sensor with toroidal core PCB mounting

MID. Energy Management Energy Analyzer Type EM11 DIN. Product Description. How to order EM11 DIN AV8 1 X O1 PF. Type Selection EM11 DIN

Online data sheet MAX48N-31V10K12500 MAX48 LINEAR ENCODERS

Precipition Sensor with analogue Intensity Output ,

50W Constant Current (700mA) Dimming LED Driver

Features. Regulated Converters. RAC01-C RAC02-C 1-2 Watt Single Output RAC0_- C. AC/DC Converter

Digital Grid Products. SICAM Fault Sensor Indicator (FSI) The Guardian for your Overhead Line Networks

Electronic timer CT-AHS.22 OFF-delayed with 2 c/o (SPDT) contacts

S5X Mobile Microcomputer. Technical Information 223,5 82,25 77,75 8,5 8,5 164,5 10,3. AMP Stecker AMP Connector 52,5 POWER SYSTEM MODE STATUS

Voltage monitoring relay CM-EFS.2 For single-phase AC/DC voltages

PD30ETB20xxIS. Photoelectrics, Background Suppression reflective with IR light. Main features. Description

NPRG860 & NPRG870 perform synchronization and paralleling of generators with electrical network. NPRG860 features a speed adjustment function.

RE17RCMU off-delay timing relay - 1 s..100 h V AC - 1 OC

Coupling unit CM-IVN For expansion of the insulation monitoring relay CM-IWN.x measuring range up to U n = 690 V AC and 1000 V DC

RE17RAMU on-delay timing relay - 1 s..100 h V AC - 1 OC

NPRG860 NPRG870 REGULATION. Automatic Synchronizer for Generator

Pressure transmitters for high temperature marine applications Type MBS 3300 and MBS 3350

RE22R2MMU Multifunction Timer Relay - 24VDC/ V AC - 2 C/O

LCL Series. SIngle Output Industrial Supplies. High Efficiency. Low Cost. 150 W Convection Cooled. 300 W & 500 W with Internal Fans

QUINT-PS/ 3AC/24DC/40

MINI MCR-SL-UI-f(-SP)

High-set undervoltage stage with definitetime. or inverse definite minimum time (IDMT) characteristic. Low-set undervoltage stage with definitetime

RE17RAMU on-delay timing relay - 1 s..100 h V AC - 1 OC

AUTOMOTIVE CURRENT TRANSDUCER OPEN LOOP TECHNOLOGY HAH1DRW 300-S

Precipitation Monitor ,

Actuator LA12 PRODUCT DATA SHEET

Strong monosilicon gauge pressure transmitter

PART NUMBERING SYSTEM

Technical data Model F1301 F13C1 ATEX/IECEX 2) F13C1 (Option) Nominal load F nom 10 / 20 / 30 / 50 / 100 / 200 kn 10 / 20 / 30 / 50 / 100 / 200 kn 10

Product Specification

Industrial PSU with universal input voltage range ( VAC line to line) and configurable output voltage. North America

PROXIMITY SENSOR TERMINOLOGY

MACX MCR-EX-SL-RPSSI-I-UP(-SP)

SIMEAS-T. Operating Instructions Transducer without auxiliary power. 7KG6111 and 7KG6101. Operating Instructions

Power supply CP-E 24/2.5

Features. Regulated Converter RAC05- SK/C14. RAC 5 Watt Single Output RAC05-3.3SK/C14. AC/DC Converter

The MDU150 Series provides the same benefits as the MPU150 Series, with nominal 48 volt DC input.

Electronic timer CT-WBS.22 Impulse generating and flashing with 2 c/o (SPDT) contacts

Transcription:

Safety guide Pressure transmitter SIL-2 DST P92S ia.danfoss.com

Table of contents Contents 1. Introduction... 2 2. General information... 3 2.1 Contact... 3 2.2 Used symbols and format... 3 2.3 Reference... 3 2.4 Abbreviations... 4 3. Qualification test... 5 3.1 Compliance information... 5 3.2 Electromagnetic and electrical tests... 5 3.3 Environmental qualification... 7 4. System information... 8 4.1 Functional safety classification... 9 4.2 Technical data... 9 4.3 Safty functions... 10 4.4 Diagnosis... 11 5. Safety requirements... 11 5.1 Known issues... 12 5.2 Instructions and constraints... 12 5.3 Safe state... 12 5.4 System... 13 5.5 Pressure... 14 5.6 Outputs... 15 5.7 Decommissioning and disposal... 16 5.8 Security... 16 6. Index... 17 1. Introduction This document includes system information and safety requirements for the pressure transmitter DST P92S, which have to be considered and fulfilled within the overall safety application. It shall be used as input for the: development of the overall safety application. overall installation and commissioning planning. overall safety validation planning. overall operation, maintenance and repair planning. 2 Danfoss DCS (im) 2017.01 IC.PS.P21.1A.02 520B7782

2. General information 2.1 Contact Danfoss A/S Industrial Automation DK-6430 Nordborg Denmark www.ia.danfoss.com E-mail: technical support_ia@danfoss.com 2.2 Used symbols and formats REQIREMENT: Requirement which shall be adhered to maintain safe system operations. RECOMMENDATION: Recommendation on how to handle certain aspects of requirements. WARNING: Warning of faults and errors during the application development. NOTE: A note provides additional and important information of the system behavior. 2.3 Reference No. Description /1/ International standard IEC 61508:2010 Functional safety of electrical, electronic and programmable electronic safety-related systems /2/ Safety standard EN ISO 13849-1:2015 Safety of machinery - Safety-related parts of control systems /3/ Siemens standard SN 29500: Failure rates of components /4/ EMC standard EN 61000-4-5:2005 Electromagnetic Compatibility; testing and measurement techniques - Surge immunity test Danfoss DCS (im) 2017.01 IC.PS.P21.1A.02 520B7782 3

2.4 Abbreviations Abbreviation Description ADC Analog Digital Converter AFB Analog Feedback CCF Common Cause Failure CFB Current Feedback CRC Cyclic Redundancy Check DC Diagnostic Coverage DFB Digital Feedback DTI Diagnostic Test Interval ECU Electronic Control Unit EEPROM Electrically Erasable Programmable ROM EMC Electromagnetic Compatibility FRT Fault Reaction Time FTT Fault Tolerance Time FS Full Scale GND Ground HW Hardware I/O Input / Output MDT Mean Downtime MTBF Mean Time Between Failure MTTFd Mean Time To dangerous Failure MTTR Mean Time To Restoration NVMEM Nonvolatile Memory (e.g. EEPROM, FRAM) PFH Probability of dangerous Failure per Hour PGA Programmable Gate Array PL Performance Level: Safety classification according to EN ISO 13849 PST Process Safety Time RAM Random Access Memory ROM Read Only Memory SFF Safe Failure Fraction SIL Safety Integrity Level: Safety classification according to IEC 61508 SMM Shadow Memory Module (if existing) SN Siemens Standard SW Software TBD To be determined / to be defined VCC Voltage at the common collector VFB Voltage Feedback VSRC Valid Safety Relevant Configuration 4 Danfoss DCS (im) 2017.01 IC.PS.P21.1A.02 520B7782

3. Qualification tests 3.1 Compliance information Standard Description Parameter ISO/IEC 17050-1 Conformity See EU Dclaration of conformity KBA (Kraftfahrt- Bundesamt) E 1 See also Functional Safety Classification on page 9 Certification This approved device can be used on any vehicle type with the following restrictions: All vhicle types with a 12 V respectively 24 V - electrical wiring and battery (-) at the body According UN ECE Regulation No. 10 3.2 Electromagnetic and electrical tests CE Conformity (EMC) Standard Test Description Test Parameter DIN EN 61000-6-3 DIN EN 61326-1 DIN EN 61326-1 DIN EN 61326-1 DIN EN 61326-1 Emission Electrostatic Discharge (ESD) Immunity Burst Immunity Conducted emission 0.15 Mhz...30 MHz Radiated emission <1 GHz 330 Ohm / 150 pf; Contact: ±2 kv, ±4 kv, ±6 kv Air: ±2 kv, ±4 kv, ±8 kv, ±15 kv 10 V/m (80 MHz to 1.0 HHz) 10 V/m (1.4 GHz to 2.7 GHz) Supply: ± 1.5 kv; 5 khz Signal: ± 1 kv; 5 khz Conducted disturbance 0.15 MHz 80 MHz, 3 V 80% AM sine wave 1 khz CE Conformity (Electrical safety Standard Test Description Test Parameter Factory standard Broken cable supply lines Interruption os supply lines U max = 36 V U min = 9 V t = 60 sec Factory standard Short circuits - signal lines Short circuits - load lines t = 60 sec Factory standard ISO 16750-2:2012-11 Polarity protection U test = 27 V for 5 minutes Factory standard Load test 48 hours at min. temperature: 12 hours without operating, 36 hours with operation U min and I Imin 48 hours at max. temperature with operation I max and U max Factory standard ISO 16750-2:2012-11 Factory standard ISO 16750-2:2012-11 Insulation resistance Dielectric strength Unpowered; 500 VDC; 60 sec; 50% rh; 35 C between connector pins and electric conductive housing without galvanic contact 500 VAC; 50 Hz; 60 sec; 50% rh; 35 C between connector pins and electric conductive housing without galvanic contact Danfoss DCS (im) 2017.01 IC.PS.P21.1A.02 520B7782 5

CE Conformity (Functional safety Standard Test Description Test Parameter DIN EN 61326-3-1 Immunity 20 V/m (80 MHz to 1,0 GHz)* 10 V/m (1,4 GHz to 2,7 GHz)* *according corrigendums 1:2008-09 of DIN EN 61326-3-1:2008-11, table 2t = 60 sec Attention: Only for variants with metal thread and a shielded cable! Otherwise, deviations in the range of 390 MHz - 470 MHz. DIN EN 61326-3-1 Power Frequency Magnetic Fields 50 Hz / 60 Hz 30 A/m 60 sec for each axis DIN EN 61326-3-1 Burst Supply: ± 3 kv; 5 khz Signal: ± 3 kv; 5 khz Attention: Test at ± 3 kv were fulfilled, if supply and data lines laid together DIN EN 61326-3-1 Surge ±1 kv; ±2 kv; DIN EN 61326-3-1 Immunity Conducted disturbance 0.15 MHz 80 MHz, 10V 80% AM sine wave 1 khz DIN EN 61326-3-1 Voltage Dips 12VDC / 24 VDC, 60% / 10 ms Short Interruptions 12VDC / 24 VDC, 20 ms E1 Conformity Standard Test Description Test Parameter CISPR 25/ECE R10 Emission Artificial network (AN): 150 khz to 108 MHz, 1 m, 120 khz bandwidth class 3 Antenna measurement (RE): 150 khz to 30 MHz, 1 m, 9 khz bandwidth class 4 30 MHz to 1 GHz, 1 m, 120 khz bandwidth class 3 1 GHz to 2,5 GHz, 1 m, 120 khz bandwidth class 5 ISO 7637-2: 2011-03 Emission Transient emmissions on supply cables (12 V) (CTE, Limits 75 V, -100 V) ISO 7637-2: 2011-03 Emission Transient emmissions on supply cables (24 V) (CTE, Limits 150 V, -450 V) Pulse 1 (24 V): -600 V, 5000 pulses Pulse 1 (12 V): -100 V, 5000 pulses ISO 7637-2: 2011-03 Road vehicles, electrical disturbance by conduction and coupling (data, signal), test level 4 Test level 4 for 12 V and 24 V systems Pulse 2a (24 V): +50 V, 5000 pulses Pulse 2a (12 V): +50 V, 5000 pulses Pulse 2b (24 V): +20 V, 10 pulses Pulse 2b (12 V): +20 V, 10 pulses Pulse 3a (24 V): -200 V, 1 hour Pulse 3a (12 V): -150 V, 1 hour Pulse 3b (24 V): +150 V, 1 hour Pulse 3b (12 V): +75 V, 1 hour Pulse 4 (24 V): -16 V, 2 pulses Pulse 4 (12 V): -7 V, 2 pulses 6 Danfoss DCS (im) 2017.01 IC.PS.P21.1A.02 520B7782

Standard Test Description Test Parameter ISO 7637-3: 2007-07 ISO 10605: 2008-07 Road vehicles, electrical disturbance by conduction and coupling (data, signal), test level 4 Electrostatic Discharge (ESD) automotive level 4 CCC Fast Pulse a (24 V): Level IV; -80V; 10 minutes CCC Fast Pulse a (12 V): Level IV; -60V; 10 minutes CCC Fast Pulse b (24 V): Level IV; +80V; 10 minutes CCC Fast Pulse b (12 V): Level IV; +40V; 10 minutes 330 Ohm / 330 pf, Contact: ±8 kv, Air: ±8 kv Packaging and handling: Contact: ±8 kv, Air: ±15 kv 3.3 Environmental qualification Standard Test Description Test Parameter IEC 60068-2-6: 2007 DIN EN 60068-2-6: 2008-10 Environmental testing: Vibration (sinusoidal) 5 Hz - 2000 Hz, 1 g, one sweep per each plane IEC 60068-2-6: 2007 DIN EN 60068-2-6: 2008-10 IEC 60068-2-14: 2009 DIN EN 60068-2-14: 2010-04 Environmental testing: Vibration (sinusoidal) with temperature profile 5 Hz - 2000 Hz, 20 g, 5 hours for each axis, -40 C to 85 C, 2 temperature cycles per axis IEC 60068-2-31: 2008 DIN EN 60068-2-31: 2008 Environmental testing: Free fall 1 m free fall on concrete ground, 6 axis IIEC 60068-2-14: 2009 DIN EN 60068-2-14: 2009 IEC 60068-2-64: 2008 DIN EN 60068-2-64: 2008 ISO 16750-3: 2012-12 Road vehicles: Environmental conditions and testing for electrical and electronic equipment: Mechanical loads - Random vibration Test VII 1 Hz - 2000 Hz, broadband random, 32 hours for each axe, -40 C --> +85 C, 4 temperature cycles per axis See ISO 16750-3:2012-12 clause 4.1.2.7 IEC 60068-2-27: 2008 DIN EN 60068-2-27: 2009 Environmental testing: Shock 50 g / 11 ms, half-sine wave, 3 positive, 3 negative shocks/axis IEC 60068-2-27: 2008 DIN EN 60068-2-27: 2009 IEC 60068-2-1: 2007 DIN EN 60068-2-1: 2007 IEC 60068-2-2: 2007 DIN EN 60068-2-2: 2007 Environmental testing: Bump Environmental testing: Cold storage Environmental testing: Dry heat (storage) Bump, 30 g / 6 ms, half-sine wave, 1000 shocks per axis 24 hours with -40 C 96 hours with 85 C IEC 60068-2-14: 2009 DIN EN 60068-2-14: 2010-04 Environmental testing: Change of temperature Na -40 C to 85 C, 100 cycles, duration time 1 hour, temp. change 10 seconds IEC 60068-2-14: 2009 DIN EN 60068-2-14: 2010-04 Environmental testing: Change of temperature Nb -40 C to 85 C, 10 cycles Danfoss DCS (im) 2017.01 IC.PS.P21.1A.02 520B7782 7

Standard Test Description Test Parameter Weibull test according ISO 16750-1:2003 IEC 60068-2-14: 2009 DIN EN 60068-2-14: 2010-04 Environmental testing: Life test, thermal shock Δ Tprac = 60 Kelvin Frequency of temperature differences = twice a day Number of days in the year = 365 days Lifetime = 10 years ISO 16750-4: 2010-04 IEC 60068-2-30: 2005 DIN EN 60068-2-30: 2005 IEC 60068-2-78: 2012 IEC 60068-2-60: 1996-09 ISO 16750-4: 2010-04 Environmental testing: Ice water shock Environmental testing: Damp heat cyclic Environmental testing: Damp heat constant Environmental testing: Shock 10 cycles +25 C to 55 C with 93 % r.h. 6 cycles (each cycle 24 hours) 21 days with 40 C and 93 % r.h. Flowing mixed gas corrosion test Sulfur dioxide SO2, Hydrogen sulfide H2S, Nitrous oxide NO2, Chlorine Cl2 DIN EN 60529: 2000-09 DIN 40050-9:1993-05 IP Protection classes IP 67, IP 69K, IP6KX Dust Tight according to ISO12103-1 Arizona test dust A2 fine ISO 16750-5: 2010-04 Chemical resistance Plastic connector: gas/petrol, diesel, cleaner solvent, antifreeze, battery fluid, brake fluid Metal connector: gas/petrol, diesel, cleaner solvent, antifreeze, urea, battery fluid, brake fluid, engine oil, hydraulic oil 4. System information The DST P92S is designed for the operation in working machinery and further suitable application areas and qualified especially for use under harsh conditions. The pressure transmitter is a passive intelligent sensor. Its basically function is to convert the physical quantity pressure to an electrical signal. The DST P92S is provided with two opposing curren outputs 4-20 ma / 20-4 ma. It can be varied by the pressure measurement range. 8 Danfoss DCS (im) 2017.01 IC.PS.P21.1A.02 520B7782

4.1 Functional safety classification The DST P92S has the following functional safety classification and parameters: Standard Description Parameters IEC 61508/1/ (see Reference on page 3) EN ISO 13849-1 /2/ (see Reference on page 3) Safety Integrity Level (SIL) 2 Architecture 1oo1 (single channel) Hardware Failure Tolerance (HFT) 0 Safety-related subsystem Type B Safe Failure Fraction (SFF) 95.3% * Average frequency of dangerous 8.41 10-9 failure per hour (PFH) Performance Level (PL) Category (Cat.) 2 Diagnostic Coverage (DC) 94.1% * Common Cause Failures (CCF) 70 points Mean Time To dangerous Failure (MTTFd) 100 years ** * with an external monitoring according to this safety manual ** the calculated value of 794 years has been limited to 100 years according to EN ISO 13849-1 d 4.2 Technical data Pressure Parameter Min. Max. Nominel pressure range 0-10 bar 0-1200 bar Overload (depending on pressure range) 20 bar 2200 bar Installation torque of the pressure connection Current output 35 Nm Parameter Min. Max. Current within nominal pressure range 4 ma 20 ma Current at off-state 0 ma 2 ma Current accuracy output 1 (depending on ambient temperature) 1% FS 2.5 % FS Current accuracy plausibility check output 1 + output 2 (depending on ambient temperature) 2.5 % FS 5 % FS Current load (depending on power supply) 0-775 Ohm 175-1325 Ohm NOTE The accuracy is only guaranteed under reference conditions (T medium = T ambient). The maximum current load depends on the power supply and is calculated by R MAX = (+UB - 5.5 V) / 0.02 A. The minimum current load is 0 Ohm up to +UB = 16.5 V and then calculated by R MIN = (+UB - 16.5 V) / 0.02 A. Danfoss DCS (im) 2017.01 IC.PS.P21.1A.02 520B7782 9

Operating area for current output General accuracy WARNING If the application operates at maximum load limit, pressures above 100% FS can not be displayed! Parameter Min. Max. Linearity, pressure hysteresis and repeatability Long-run stability 0.5% FS 0.2% FS Timing Parameter Min. Max. Startup time 40 ms Response time 1 ms System All data above are specified under the following conditions (unless otherwise specified) Parameter Min. Max. Voltage supply (VCC power supply pin) 9 V 32 V Operating chassis temperature -40 C +85 C 10 Danfoss DCS (im) 2017.01 IC.PS.P21.1A.02 520B7782

4.3 Safety functions The pressure transmitter DST P92S executes following safety function: Safety function Safety integrity Error reaction DTI safe conversion of the measured pressure into two proportional redundant-opposing current signals (0..100 %FS correspond to 4..20 ma, safety relevance: (a) accuracy of the sum of the single currents (b) maximum conversion delay) IEC 61508 / SIL-2 EN ISO 13849 / PLd Safe state (see Safe state on page 12 80 ms NOTE The outputs of the DST P92S are not safe by temselves but in combination with a redundant signal processing. 4.4 Diagnosis The DST P92S uses several mechanisms to detect faults in the electronic circuit. Those are realized in a start-up and a cyclic diagnosis. Start-Up Diagnosis The start-up diagnosis is made once after powering the DST P92S and includes internal tests concerning e.g. the oscillator, the watchdog or any memory. If the start-up diagnosis detects a fault, the safe state (see Safe State on page 12) is entered. The DST P92S remains in the safe state. Cyclic Diagnosis The cyclic diagnosis is made every 30-40ms and includes: testing of the temperature sensor element testing of the pressure sensor concerning drift, open circuit and short circuit testing of the sensor signal range If the cyclic diagnosis detects a fault, the safe state (see Safe State on page 12) is entered as long as the fault is pending. For this an error counter is in-/decremented accordingly. 5. Safety requirements The following diagram shows the pressure transmitter DST P92S is a typical application Sensor_Y_DST P92S NOTE Information: Safety requirements within this manual are characterized by an identifier like SR_DST P92S_<index>. This can be used to trace requirements that shall be followed through the development process of the application. Danfoss DCS (im) 2017.01 IC.PS.P21.1A.02 520B7782 11

5.1 Known issues NOTE There are no known issues for the DST P92S 5.2 Instructions and constraints Safety standards SR_DST P92S_001: The current national and international safety regulations, laws, and standards for the whole safety lifecycle have to be observed. Qualification of staff SR_DST P92S_002: The pressure transmitter DST P92S must be installed and operated by trained, qualified personnel only. The knowledge and the technical implementation of the safety information provided by this manual are imperative for a safe installation and operation. 5.3 Safe state THe safe state of the pressure transmitter DST P92S Signal Safe state Connector Output 1 I < 2 ma Pin 4 Output 2 I < 2 ma Pin 2 The safe state is entered when the DST P92S recognizes a fault condition. Both outputs go into the safe state simultaneous. Qualification of staff NOTE Specification: The maximum time between a fault occurrence and the safe state of the DST P92S is 80 ms. SR_DST P92S_006: The fault detection cycle of the superordinate logic system must be long enough to detect an error reliably. Method statement SR_DST P92S_003: Before setting the DST P92S into operation for an application it is necessary to read and follow the instructions of this safety manual. The limits of the technical data (see Technical Data on page 9) must be complied within the application. Proof test interval SR_DST P92S_004: A proof test interval of the pressure transmitter DST P92S must be initiated and controlled every 7½ years. As the DST P92S can not be recalibrated, it has to be replaced, if the deviations exceed the maximum tolerances. Troubleshooting procedures SR_DST P92S_005: A faulty transmitter must be replaced immediately. There is no maintenance or repair procedure provided for the DST P92S 12 Danfoss DCS (im) 2017.01 IC.PS.P21.1A.02 520B7782

Example: The following time diagram shows the DST P92S in a typical sensor-logic-actuator application e.g. with and electronic control unit. DST P92S Operation Interval DST P92S Safe state Reset condition NOTE Specification: If a fault condition isn t pending continously, the DST P92S will leave the safe state earliest after 60 ms. Restrictions WARNING The safe state may not be entered during an over- or under-voltage condition or during startup. Possibly occurring spikes on the outputs have to be ignored. SR_DST P92S_007: The diagnostic test interval of the superordinate logic system must be short enough to detect the safe state reliably. SR_DST P92S_022: The superordinate logic system has to consider non-functional operating modes, which do not lead to a safe state. 5.4 System System overview DST P92S SR_DST P92S_008: Exceeding the maximum supply voltage of the DST P92S may cause an unsafe operation. Therefore the superordinate logic system has to monitor the sensor power supply. SR_DST P92S_018: Take measures to avoid an overvoltage condition at the DST P92S. Danfoss DCS (im) 2017.01 IC.PS.P21.1A.02 520B7782 13

SR_DST P92S_009: Running the DST P92S outside its temperature limits may cause an unsafe operation. Therefore the superordinate logic system has to monitor the ambient temperature. SR_DST P92S_019: There have to be taken measures to avoid an over- or under-temperature condition at the DST P92S. SR_DST P92S_021: The chassis, in which the DST P92S is mounted, has to be connected to the power supply ground, to fulfill the EMC requirements. SR_DST P92S_023: The DST P92S must not be connected to a DC supply network, but to a separated power supply, to a battery, or to the sensor supply of the control unit. 5.5 Pressure The pressure is measured by a welded thin-film capsule, which converts the physical pressure into an electrical signal by resistor full-bridge. An additional temperature meander makes itpossible to compensate the signal. Functional diagram SR_DST 92S_010: Because the radius of the pressure channel of the DST P92S is very small, measures must be taken for the pressure system to prevent its clogging. SR_DST P92S_011: Running the DST P92S outside its temperature limits may cause an unsafe operation. Therefore, the superordinate logic system has to monitor the pressure medium temperature. SR_DST 92S_024: The thread shall be made of stainless steel and shall be free of lubricant. RECOMMENDATION Avoid to exceed the specified pressure ranges of the used DSR P92S. For a smooth operation the pressure system should be able to provide a stable nonfluctuating pressure. The accuracy of the pressure measurement is only guaranteed under reference conditions, that means if the medium temperature and the ambient temperature is nearly the same. Therefore measures should be taken to effect this. 14 Danfoss DCS (im) 2017.01 IC.PS.P21.1A.02 520B7782

WARNING A drift of the measurement cell due to an overpressure as well as an aging-related drift can only be detected at the pressure limits (0 %FS, 100 %FS) of the DST P92S. 5.6 Outputs The outputs of the DST P92S are designed as redundant opposing signals. The opposing signals can be used to establish a redundant signal processing for safety-related applications. Signal diagram SR_DST P92S_012: The superordinate logic system has to provide safety-related input pairs, which fulfill the reservations of the DST P92S outputs (see technical data (see Technical Data on page 9). (Especially the requirements for the minimum and maximum loading of the current outputs have to be observed.) SR_DST P92S_020: The superordinate logic system has to process both output signals simultaneously and to compare them in a meaningful way. SR_DST P92S_013: The measured pressure is always represented by output 1. Output 2 must only be used for the safety function, as it is not calibrated and temperature compensated. SR_DST P92S_014: The DST P92S outputs do not comply with a surge pulse as defined in EN 61000-4-5 /4/ (see Reference on page 3). Therefore the length of the cables, which are connected to them, must not exceed 30 meters. RECOMMENDATION For signal processing the two output values should be accumulated by the application and be compared to predefined limits (e.g. 24 ma ± 3 %FS). Danfoss DCS (im) 2017.01 IC.PS.P21.1A.02 520B7782 15

Output circuit The signal conditioning is supplied via a DC/DC converter and its outputs are used to generate the current signals. SR_DST P92S_016: A current value < 3.5 ma or > 20.5 ma may be the result of a damaged DST P92S. Therefore the superordinate logic system must be able to check the current range and react on an invalid value. RECOMMENDATION To check, if there is a short circuit between the DST P92S current outputs, one of them could be additional loaded, e.g. with a programmable pull-down resistor. The other one should not change its value. SR_DST P92S_017: The superordinate logic system has to check, if there is a short circuit between the DST P92S current outputs. Depending on the application this must be done cyclical or at start-up. RECOMMENDATION If the inputs of superordinate logic system do not provide suitable load resistors as required in the technical data (see Technical Data on page 9), an additional series resistance can be connected to the wiring. 5.7 Decommissioning and disposal 5.8 Security NOTE For the DST P92S there has nothing to be considered regarding decommissioning. The disposal of the DST P92S has to be done according to national laws. NOTE For the DST P92S there has nothing to be considered regarding security. 16 Danfoss DCS (im) 2017.01 IC.PS.P21.1A.02 520B7782

6. Index A Abbreviations 4 C Compliance Information 12 Contact 4 Copyright 5 D Decommissioning and Disposal 16 Diagnosis 11 E Electromagnetic and Electrical Tests 5 Environmental Qualification 7 F Functional Safety Classification 5, 8, 9 G General Information 3 I Instructions and Constraints 12 Introduction 2 K Known Issues 12 O Outputs 15 P Pressure 14 Q Qualification Tests 5 R Reference 3, 9, 15 S Safe State 11, 12 Safety Functions 11 Safety Requirements 11 Security 16 System 13 System Information 8 T Technical Data 9, 10, 12, 15, 16 U Used Symbols and Formats 3 Danfoss DCS (im) 2017.01 IC.PS.P21.1A.02 520B7782 17

Danfoss A/S Industrial Automation Nordborgvej 81 DK-6430 Nordborg Denmark www.ia.danfoss.com Danfoss DCS (im) 2017.01 IC.PS.P21.1A.02 520B7782 18