My experience of this field is limited mainly to the EU/CE marking 
issues rather than requirements for the US, but it's a subject I've 
been watching for years. I can tell you that this is a hot topic the 
debate over which has been building up over some years and shows no 
signs of cooling off any time soon.

You will get differing opinions from different people you talk to - 
and, in particular, manufacturers of 'safety PLC's' (i.e. 
programmable logic controls designed specifically for safety related 
applications) will tell you things about the acceptability of their 
devices which are not necessarily agreed with by other sectors of the 
industry.

Currently, I know of no machinery 'type C' standard which permits the 
use of programmable logic for safety functions (also known as 
'programmable safety systems' or 'PSS') and while this by no means 
prevents such systems being used, it does present some interesting 
challenges for the designer who needs to be able to justify that 
their machine will remain safe under foreseeable all conditions of 
use. One of the fundamental challenges of using PSS is that the 
Machinery Directive requires the manufacturer to compile a technical 
file which shows how the machine compiles with the essential 
requirements of the Directive. When a designer uses a PSS, it's very 
difficult to create a file which does not, at some level or other, 
rely on a certificate from a test house as evidence that a PSS will 
work as intended, as opposed to a reasoned argument which is what the 
directive actually requires.

As was mentioned by Doug Nix, if you happen to deal with machines 
which fall into Annex IV of the Directive, the use of PSS will raise 
some issues which might not otherwise arise. The involvement of a 
Notified Body in the CE marking of Annex IV machines can be limited 
to the lodgment of the Technical File in cases where the appropriate 
type C standard has been full complied with, but since, as I have 
already mentioned, no type C standard currently permit PSS to be 
used, this means that for annex IV machines with a PSS, a type 
approval will be required. This is a much more time consuming and 
expensive process and, in my experience actually adds very little 
value to the machine as far as the manufacturer is concerned.

Several other replies to this enquiry have mentioned IEC 61508, 
apparently in ignorance of the existence of EN 62061:2005, "Safety of 
machinery. Functional safety of safety-related electrical, electronic 
and programmable electronic control systems" which is, in effect, an 
adaptation of IEC 61508 to machine control applications. It is 
harmonised under the Machinery Directive and it is definitely the 
starting point for anyone thinking of using PSS in machine control 
applications.

I may have come across as being overly negative but let me say that I 
am in general in favour of using programmable safety systems - if 
properly applied they are certainly no less safe than the 
alternatives and can very likely be safer. They will almost certainly 
be cheaper and more convenient for machines of any size. However, 
they present a very different set of challenges to those which most 
small machinery designers who are otherwise only used to dealing with 
hardwired controls are used to, and meeting these challenges is not 
trivial. I would certainly not advise any manufacture of machinery to 
decide to follow this path without a good deal of initial thought and 
investigation, especially if they intend to build their own 
electronics.

Nick.


At 09:29 -0400 20/7/07, Kunde, Brian wrote:
>I have limited experience working with industrial machines with moving
>parts so I would appreciate any help you can provide.
>
>To protect an operator from moving parts, my understanding is that I
>have to use an approved interlock device (in this case a switch) and it
>has to directly control the device that makes the motion (pneumatic
>solenoid).
>
>But on a future project, we would like to have the interlock switch talk
>to an FPGA (silicon) and have firmware and software controls the motion
>device after many sensor checks are made. These "checks" are quite
>complex where many things have to be just right in the right sequence
>for the motion to occur. Engineering is saying that the sequence is too
>complex to limit with a simple interlock switch system.
>
>Is it possible to use silicon chips, firmware, and software in such a
>circuit? Can such an approach be used and if so what is involved in
>qualifying it?
>
>Thanks,
>The Other Brian
>
>LECO Corporation Notice:  This communication may contain 
>confidential information intended for the named recipient(s) only. 
>If you received this by mistake, please destroy it and notify us of 
>the error.  Thank  you.
>

-

This message is from the IEEE Product Safety Engineering Society
emc-pstc discussion list.    Website:  http://www.ieee-pses.org/

To post a message to the list, send your e-mail to [email protected]

Instructions:  http://listserv.ieee.org/request/user-guide.html

List rules: http://www.ieee-pses.org/listrules.html

For help, send mail to the list administrators:

     Scott Douglas           [email protected]
     Mike Cantwell           [email protected]

For policy questions, send mail to:

     Jim Bacher:             [email protected]
     David Heald:            [email protected]

All emc-pstc postings are archived and searchable on the web at:

    http://www.ieeecommunities.org/emc-pstc

______________________________________________________________________
This email has been scanned by the MessageLabs Email Security System.
For more information please visit http://www.messagelabs.com/email 
______________________________________________________________________

Reply via email to