۲۰۱٦/ ۸/ ۱۸ Home
2oo3 Architecture | Engineering360 News & Analysis
Products & Suppliers
Standards Library
Reference Library
Engineering Community
Stay Informed
Free Registration (http://w w w .globalspec.co…
(http://www.globalspec.com) (http://insights.globalspec.com) (http://www.globalspec.com/productfinder) (http://standards.globalspec.com) (http://reference.globalspec.com) (http://cr4.globalspec.com)
Reference Library
Search Reference Library
GO
Acquired Engineering360 Learn more (http://www.ieee.org/about/news/2016/29april_2016.html)
(http://www.globalspec.com) HOME (http://w w w .globalspec.com )
REFERENCE LIBRARY (http://reference.globalspec.com )
TECHNICAL ARTICLES
2oo3 Architecture By Harry Cheddie
From Safety Instrumented Systems Verification: Practical Probabilistic Calculations
Product Announcements
2oo3 Architecture An architecture designed to tolerate both "safe" and "dangerous" failures is the 2oo3 (two units out of three are required for the system to operate). This architecture provides both safety and high availability with three controller units. Two outputs from each controller unit are required for each output channel. The two outputs from the three controllers are wired in a "voting" circuit, which determines the actual output (Figure F20). The output will equal the "majority." When two sets of outputs conduct, the load is energized. When two sets of outputs are off, the load is deenergized.
(/FeaturedProducts/Detail/USTsu fromSpotlight=1)
Custom Shock Relay
(/FeaturedProducts/Detail/USTsu fromSpotlight=1)
U.S. Tsubaki Power Transmission, LLC
Figure F19: 2oo3 Architecture
(/FeaturedProducts/Detail/Elobau fromSpotlight=1)
Intelligent Input Expansion Units
(/FeaturedProducts/Detail/Elobau fromSpotlight=1)
elobau sensor technology, Inc.
Figure F20: Single Fault Degradation Models of 2003 Architecture A closer examination of the voting circuit shows that it will tolerate a failure of either failure mode dangerous (short circuit) or safe (open circuit). Figure F21 shows that when one unit fails open circuit, the system effectively degrades to a 1oo2 configuration. If one unit fails short circuit the system effectively degrades to a 2oo2 configuration. In both cases, the system remains in successful operation.
(/FeaturedProducts/Detail/PHOEN fromSpotlight=1)
PSRMXF multifunctional safety relay
(/FeaturedProducts/Detail/PHOEN fromSpotlight=1)
PHOENIX USA Figure F21: Dual Fault Failure Modes of 2oo3 Architecture
PFD Fault Tree for 2oo3
View More Product Announcements for Safety Relays
(/featuredproducts/manufacturin
The 2oo3 architecture will fail dangerously only if two units fail dangerously (Figure F22). There are three ways in which this can happen, the AB leg can fail short circuit, the AC leg can fail short circuit and the BC leg can fail short circuit. These are shown in the top level events of the PFD fault tree... (http://www.globalspec.com/Goto/GotoWebPage? gotoUrl=http%3A%2F%2Fwww%2Ebooks24x7%2Ecom%2Fpromo%2Fglobalspec&gotoType=bookpurchase&srrospectId=0) Interested in this book and
others like it? Try EngineeringPro™ from Books24x7® (http://www.globalspec.com/Goto/GotoWebPage? gotoUrl=http%3A%2F%2Fwww%2Ebooks24x7%2Ecom%2Fpromo%2Fglobalspec&gotoType=bookpurchase&srrospectId=0)
<< Previous Excerpt (/reference/76370/203279/1oo1darchitecture) | View Book Details (/reference/76343/203279/safetyinstrumentedsystemsverification practicalprobabilisticcalculations) | Next Excerpt >> (/reference/76372/203279/2oo2darchitecture)
Copyright ISA—Instrumentation, Systems, and Automation Society 2005 under license agreement with Books24x7
Products & Services
http://www.globalspec.com/reference/76371/203279/2oo3architecture
1/2
۲۰۱٦/ ۸/ ۱۸
2oo3 Architecture | Engineering360
Safety Relays (http://www.globalspec.com/SpecSearch/Suppliers/manufacturing_process_equipment/industrial_machine_safeguarding/safety_relays) Safety relays and control modules differ from conventional relays in that they have forceguided or positivedriven s. Search by Specification (http://w w w .globalspec.com /specsearch/SearchForm /m anufacturing_process_equipm ent/industrial_m achine_safeguarding/safety_relays) | Learn more about Safety Relays (http://w w w .globalspec.com /learnm ore/m anufacturing_process_equipm ent/industrial_m achine_safeguarding/safety_relays) | Safety Relays Insights (/insights/368/safetyrelaysdesigntrendsapplicationsbuyingadvicefrom technicalexperts) Maximum Current: Maximum AC Switching Voltage: Maximum DC Switching Voltage: At least 0.2 amps (javascript:void(0);) At least 110 volts (javascript:void(0);) At least 24 volts (javascript:void(0);) At least 3 amps (javascript:void(0);) At least 120 volts (javascript:void(0);) At least 50 volts (javascript:void(0);) At least 8 amps (javascript:void(0);) At least 240 volts (javascript:void(0);) At least 120 volts (javascript:void(0);) At least 16 amps (javascript:void(0);) At least 380 volts (javascript:void(0);) At least 250 volts (javascript:void(0);)
Receptacle Testers (http://www.globalspec.com/SpecSearch/Suppliers/test_measurement_equipment/multimeters_electrical_test_meters/receptacle_testers) Receptacle testers are used to test wiring in electrical receptacles. Search by Specification (http://w w w .globalspec.com /specsearch/SearchForm /test_m easurem ent_equipm ent/m ultim eters_electrical_test_m eters/receptacle_testers) | Learn more about Receptacle Testers (http://w w w .globalspec.com /learnm ore/test_m easurem ent_equipm ent/m ultim eters_electrical_test_m eters/receptacle_testers)
Protective Relays and Monitoring Relays (http://www.globalspec.com/SpecSearch/Suppliers/electrical_electronic_components/relays_timers/protective_monitoring_relays) Protective relays and monitoring relays detect or monitor for abnormal power system conditions. Search by Specification (http://w w w .globalspec.com /specsearch/SearchForm /electrical_electronic_com ponents/relays_tim ers/protective_m onitoring_relays) | Learn more about Protective Relays and Monitoring Relays (http://w w w .globalspec.com /learnm ore/electrical_electronic_com ponents/relays_tim ers/protective_m onitoring_relays) | Protective Relays and Monitoring Relays Insights (/insights/308/protectiverelaysandm onitoringrelaysdesigntrendsapplicationsbuyingadvicefrom technicalexperts)
Power Distribution Units (PDU) (http://www.globalspec.com/SpecSearch/Suppliers/electrical_electronic_components/power_supplies_conditioners/power_distribution_units) Power distribution units (PDUs) have an electrical input and several outputs, often as electrical outlets, for powering multiple devices. Search by Specification (http://w w w .globalspec.com /specsearch/SearchForm /electrical_electronic_com ponents/pow er_supplies_conditioners/pow er_distribution_units) | Learn more about Power Distribution Units (PDU) (http://w w w .globalspec.com /learnm ore/electrical_electronic_com ponents/pow er_supplies_conditioners/pow er_distribution_units)
Motor Controllers (http://www.globalspec.com/SpecSearch/Suppliers/motion_controls/motor_controls_drives/motor_controllers) Motor controllers receive supply voltages and provide signals to motor drives that are interfaced to motors. They include a power supply, amplifier, interface, and position control circuitry. Search by Specification (http://w w w .globalspec.com /specsearch/SearchForm /m otion_controls/m otor_controls_drives/m otor_controllers) | Learn more about Motor Controllers (http://w w w .globalspec.com /learnm ore/m otion_controls/m otor_controls_drives/m otor_controllers) | Motor Controllers Insights (/insights/188/m otor controllersdesigntrendsapplicationsbuyingadvicefrom technicalexperts)
Topics of Interest 2oo2D Architecture (http://www.globalspec.com/reference/76372/203279/2oo2darchitecture) 2oo2D Architecture The 2oo2D is a four channel architecture that consists of two 1oo1D controllers arranged in a 2oo2 style (Figure F26). Since the 1oo1D protects against dangerous failures when...
2oo2 Architecture (http://www.globalspec.com/reference/76369/203279/2oo2architecture) 2oo2 Architecture Another dual controller configuration was developed for the situation in which it is undesirable to fail with outputs deenergized. This system is used in energizetotrip...
1oo1 Architecture (http://www.globalspec.com/reference/76367/203279/1oo1architecture) 1oo1 Architecture A single PEC (Figure F2) represents a minimum system. No fault tolerance is provided by this system. No failure mode protection is provided. The electronic circuits can fail safely...
1oo2 Architecture (http://www.globalspec.com/reference/76368/203279/1oo2architecture) 1oo2 Architecture Two controllers can be wired to minimize the effect of dangerous failures. For deenergizetotrip systems, a series connection of two output circuits requires that both controllers...
1oo2D Architecture (http://www.globalspec.com/reference/76373/203279/1oo2darchitecture) 1oo2D Architecture The 1oo2D architecture is similar to the 2oo2D architecture except that additional control lines are added to allow one unit to deenergize the other unit. A 1oo2D architecture is... About Engineering360
Follow Engineering360
Top Categories
© Copyright 2016 IEEE GlobalSpec All rights reserved. Use of this
w ebsite signifies your agreement to the IEEE Term s and (http://www.globalspec.com/AboutUs) (http://www.twitter.com/engineering_360) (https://www.facebook.com/Engineering360) (http://www.globalspec.com/SiteMap/Directory/)
Conditions (http://w w w.ieee.org/site__conditions.html).
With Us
of Use
(http://www.globalspec.com/advertising/)
(http://www.globalspec.com/Help/OfUse)
Client Services (http://www.globalspec.com/ClientServices/)
Home (http://www.globalspec.com/) | Site Map (http://www.globalspec.com/SiteMap) | (http://www.globalspec.com/Us) | Accessibility
(http://www.ieee.org/accessibility_statement.html?WT.mc_id=hpf_acc) | Nondiscrimination Policy (http://www.ieee.org/p926.html?WT.mc_id=hpf_nondis) | Privacy &
Opting Out of Cookies (http://www.ieee.org/security_privacy.html?WT.mc_id=hpf_privacy)
http://www.globalspec.com/reference/76371/203279/2oo3architecture
2/2