1、BRITISH STANDARD BS EN60671:2011Nuclear power plants Instrumentation and control systems important to safety Surveillance testingICS 27.120.20nullnull nullnullnullnullnullnullnull nullnullnullnullnullnullnull nullnullnull nullnullnullnullnullnullnullnullnullnull nullnullnullnullnullnull nullnull nul
2、lnullnullnullnullnullnullnullnull nullnull nullnullnullnullnullnullnullnullnull nullnullnullNational forewordThis British Standard is the UK implementation of EN 60671:2011. It supersedes BS IEC 60671:2007 which is withdrawn.The UK participation in its preparation was entrusted to Technical Committe
3、e NCE/8, Reactor instrumentation.A list of organizations represented on this committee can be obtained on request to its secretary.This publication does not purport to include all the necessary provisions of a contract. Users are responsible for its correct application.Compliance with a British Stan
4、dard cannot confer immunity from legal obligations.BS EN 60671:2011This British Standard waspublished under the authorityof the Standards Policy andStrategy Committeeon 29 June 2007 BSI 2011ISBN 978 0 580 70691 2Amendments/corrigenda issued since publicationDate Comments 31 October 2011 This corrige
5、ndum renumbers BS IEC 60671:2007 as BS EN 60671:2011EUROPEAN STANDARD EN 60671 NORME EUROPENNE EUROPISCHE NORM August 2011 CENELEC European Committee for Electrotechnical Standardization Comit Europen de Normalisation Electrotechnique Europisches Komitee fr Elektrotechnische Normung Management Centr
6、e: Avenue Marnix 17, B - 1000 Brussels 2011 CENELEC - All rights of exploitation in any form and by any means reserved worldwide for CENELEC members. Ref. No. EN 60671:2011 E ICS 27.120.20 English version Nuclear power plants - Instrumentation and control systems important to safety - Surveillance t
7、esting (IEC 60671:2007) Centrales nuclaires de puissance - Systmes dinstrumentation et de contrle-commande importants pour la sret - Essais de surveillance (CEI 60671:2007) Kernkraftwerke - Leittechnik fr Systeme mit sicherheitstechnischer Bedeutung - Prfungen zur Sicherstellung der Funktionsfhigkei
8、t (IEC 60671:2007) This European Standard was approved by CENELEC on 2011-08-08. CENELEC members are bound to comply with the CEN/CENELEC Internal Regulations which stipulate the conditions for giving this European Standard the status of a national standard without any alteration. Up-to-date lists a
9、nd bibliographical references concerning such national standards may be obtained on application to the Central Secretariat or to any CENELEC member. This European Standard exists in three official versions (English, French, German). A version in any other language made by translation under the respo
10、nsibility of a CENELEC member into its own language and notified to the Central Secretariat has the same status as the official versions. CENELEC members are the national electrotechnical committees of Austria, Belgium, Bulgaria, Croatia, Cyprus, the Czech Republic, Denmark, Estonia, Finland, France
11、, Germany, Greece, Hungary, Iceland, Ireland, Italy, Latvia, Lithuania, Luxembourg, Malta, the Netherlands, Norway, Poland, Portugal, Romania, Slovakia, Slovenia, Spain, Sweden, Switzerland and the United Kingdom. Foreword The text of the International Standard IEC 60671:2007, prepared by SC 45A, In
12、strumentation and control of nuclear facilities, of IEC TC 45, Nuclear instrumentation, was submitted to the formal vote and was approved by CENELEC as EN 60671 on 2011-08-08 without any modification. Attention is drawn to the possibility that some of the elements of this document may be the subject
13、 of patent rights. CEN and CENELEC shall not be held responsible for identifying any or all such patent rights. The following dates were fixed: latest date by which the EN has to be implemented at national level by publication of an identical national standard or by endorsement (dop) 2012-08-08 late
14、st date by which the national standards conflicting with the EN have to be withdrawn (dow) 2014-08-08 As stated in the nuclear safety directive 2009/71/EURATOM, Chapter 1, Article 2, item 2, Member States are not prevented from taking more stringent safety measures in the subject-matter covered by t
15、he Directive, in compliance with Community law. In a similar manner, this European standard does not prevent Member States from taking more stringent nuclear safety measures in the subject-matter covered by this standard. Annex ZA has been added by CENELEC. _ Endorsement notice The text of the Inter
16、national Standard IEC 60671:2007 was approved by CENELEC as a European Standard without any modification. _ BS EN 60671:2011 EN 60671:2011 (E) 2 Annex ZA (normative) Normative references to international publications with their corresponding European publications The following referenced documents a
17、re indispensable for the application of this document. For dated references, only the edition cited applies. For undated references, the latest edition of the referenced document (including any amendments) applies. NOTE When an international publication has been modified by common modifications, ind
18、icated by (mod), the relevant EN/HD applies. Publication Year Title EN/HD Year IEC 60880 - Nuclear power plants - Instrumentation and control systems important to safety - Software aspects for computer-based systems performing category A functions EN 60880 - IEC 60987 - Nuclear power plants - Instru
19、mentation and control important to safety - Hardware design requirements for computer-based systems EN 60987 - IEC 61226 - Nuclear power plants - Instrumentation and control important to safety - Classification of instrumentation and control functions EN 61226 - IEC 61513 - Nuclear power plants - In
20、strumentation and control for systems important to safety - General requirements for systems - - IEC 62138 - Nuclear power plants - Instrumentation and control important for safety - Software aspects for computer-based systems performing category B or C functions EN 62138 - IAEA Safety guide NS-G-1.
21、3 - Instrumentation and control systems important to safety in nuclear power plants - - BS EN 60671:2011 EN 60671:2011 (E) 3 CONTENTSINTRODUCTION.1 Scope.2Normative References3Terms and definitions.4Basic Principlesfor Surveillance Testing4.1General.4.2Gradation of Requirements Based on Category.14.
22、3Extent of Surveillance Testing.14.4Self-supervision in Lieu of Periodic Testing.14.5Continuous Operation in Lieu of PeriodicTesting 15General Requirements for Surveillance Testing15.1 Design Requirements15.2Procedures15.3Data to be recorded upon detectionof a fault15.4Other data to be recorded .15.
23、5Test intervals15.6Verification of actuation set-points.15.7Bypass15.8Response time 15.9Restoration16Requirements for Testing of Sensors and Signal Processing Devices.16.1General.16.2Non-tested parts16.3Testing devices .16.4Signals16.5Variation ofsignals16.5.1General .16.5.2Slowly changing signal16.
24、5.3Rapidly changing signal.16.5.4Large change in signal 16.6Operability.16.7Sensor response time16.8Testing equipment.16.9Calibration and transfer function16.10 Surveillance17Requirements for Testing of Electromechanical Equipment.17.1General.17.2Interface17.3Typical functional tests17.4Continuous m
25、onitoring.17.5Relays and valves.18Requirements for Testing of Logic Assemblies.8.1Scope8.2General.6899111122233344455556666667777778888888999202020BS EN 60671:2011 EN 60671:2011 (E) 4 8.3Switching ofsignals.8.4Testing signals8.5Interface8.6Data to bedisplayed8.7Data to be recorded.8.8Detailed displa
26、y.8.9Testing equipment.8.10 Testing equipment using pulses 29Self-supervision in computer-based Itest of a group of equipment or components to confirm properties that support the safetyfunction (continuity, power availability, etc.);testbased on information redundancy or comparison of control signat
27、ures (consistencychecking for redundant sensors, CRC-checking, Checksum, etc.);periodic testing which is related to the correctnessof functional behaviour of an I however, they may be combined withthe surveillance testing discussed herein. For anyon-line tests the potential interaction and fault dep
28、endencies between the part ofthesystem under test and the testing part, have to be carefully studied and their influenceshave to be fullyintegrated into the reliability assessment of the functionsimportant to safety (inaccordance with IEC 61513).BS EN 60671:2011 EN 60671:2011 (E) 8 This standard app
29、lies to the I this subset is t o be identified at the beginning of any project.SignalprocessingLogicassemblyActuatingdevice MSensor Extent ofI operationalbypass: abypass of certain protective actions when theyare not necessaryin a particularmode of plant operation IAEA Safety Glossary, Ed. 2.0 2006N
30、OTE 1 A maintenance bypass that is applied to a channel may still leave the safety function operable throughredundancy and majority voting (e.g. two out of four coincidence logic becomes two out of three).NOTE 2 A maintenance bypass is not the same as an operational bypass. Amaintenance bypass may r
31、educe the degree of redundancy of equipment, but it does not result in the loss of a safety function.3.4full functional testtestthat includes perturbation of the process variable, detection by the sensor, processing of the signal(s), actuation of the appropriate sub-assemblies, logic assemblies and
32、actuationdevices 3.5functional reliability ability to comply with requirements on complete and correct functionalityand performance in:a) all defined plant operational modes and conditions,b) in all defined plant I the state after switching is stable and correct; thetime delay or the time constant h
33、as the correct value.5.2 ProceduresPeriodic tests shall be made on the basis of carefully prepared test programmes in whichidentification ofthe testedparts, test condition sincluding initial plant state, test proceduresand test periods are stated. 5.3Datato be recorded upon detection of a fault Upon
34、 detection of a fault at least the following data shall be recorded: identification of the tested part; test device description;detectable fault combinations; date and time of the test during which faults have been detected;period between this test and the previous testthat would ha ve permitted the
35、 detection ofthe faults; type of failure which could becaused by the fault incase of demand;operating mode of I authorization signature(s); title of test programme; action taken when fault is detected.5.4Other data to be recorded 5.4.1 After each test where no fault was detected at least the followi
36、ng data shall be recorded: test frequency (for automatic tests only); test schedule used; date, time and duration of thetest(for manually initiated tests); identification of tested equipment.NOTE It is recommended that statistical data related to the test results be carefully recorded and analyzed t
37、o give realistic “failure rate” data. When such data become available with a reasonable confidence level, they should be compared with the frequency of testing to determine whether modification of the frequency in either direction isappropriate.BS EN 60671:2011 EN 60671:2011 (E) 14 5.4.2 Anynon-safe
38、tyrelevant valuesthat can be measured during the surveillance test sshould be analysed from the maintenance pointof viewand recorded. The onlylimitation of thesemeasurements is that they shall not jeopardise t he safetysurveillance te sting.5.5 Test intervals Thetest interval is the relevant design
39、parameter for the demonstration thatreliability and availability goalsare met for the system under consideration. The test intervals shall be basedon mathematical rel ations involving the reliability and availability goals, the type of systemarchitecture, the expected fault-rate or experienced fault
40、-rate, test durationand permissible system unavailability. 5.6Verification of actuation set-points5.6.1 Testing to verify actuati on set-points that are continuously calculated or likewisetesting toverifya calculated complex safety function witha fixed set-point level shall beperformed by manipulati
41、ng each variable that enters into the computation. While the signal forone or more variables is being varied toachieve actuation or change in computer output, the signalsfor the other variablesshould be adjusted to normal expected valuesfor the actuation condition.5.6.2 For computer-based I for exam
42、ple, testing the actuation device for a system pump separately fromthe actuation device for thesystemvalves. 7.2.3 The operation of certain actuatedequipment shallbe preventedduringa testof the related actuation devices; for example, moving the circuit breaker for a pump to a test position that prev
43、entspower from being supplied to the pump during a test closure ofits circuitbreaker. Operation of the actuated equipment itself shall be tested when plant conditionspermit in a way that overlaps this test. 7.2.4 Operation of the actuatedequipment shall require the coincident operation of more than
44、one actuator device; for example, individualtesting of the two solenoid-operatedvalvesthat act in coincidence to control compressed air to an is olation valve.7.2.5 Designin accordance with the requirements of7.2.3 or 7.2.4 shall be justified on thebasis that theprobability of failure of any act uat
45、ed equipment thatis not tested during stationoperation is acceptably low. 7.3Typical functional tests7.3.1 To ascertain that an I there areoutputs corresponding to a request for actuationwhen all the configurations ofinputs simulatinga request for safety function actuation have been injected; the ti
46、me constantof thesignal processing device iscorrect; the duration and timing of output signals arecorrect.The above applies to all the inputs to the signal processing device that may lead to a partialor total actuation.8.4.2 In the case thatoverlappingtesting is applied at least one component shall
47、be tested in the overlapping signal path (see 4.3.2 and 6.1.2).BS EN 60671:2011 EN 60671:2011 (E) 20 8.5 Interface Consideration shall be given in the design of the interface between th e test equipment and theIdetectable fault combinations; test interrupted; I test equipment failure(see 8.9); unsaf
48、e failure in the tested circuit; safe failure in the tested circ uit; partial actuation; totalactuation; position of operating mode switches, if any (normal operation, start-up, shutdown, etc.);incorrect signal processing device time constant ; period between thistest and previous test that would ha
49、ve detected the fault(s).8.7Data to be recordedFor the purpose of post-failure documentation, the following information should berecorded: all the information relating to a displayed failure;time of detection of a failure; time at which full availability of theIoperation of the circuit comparing the output from the I operation of the testing system; characteristics of testing system internal supplies; stall of automaticsequencing.BS EN 60671:2011 EN 60671:2011 (E) 21 8.10 Testin
copyright@ 2008-2019 麦多课文库(www.mydoc123.com)网站版权所有
备案/许可证编号:苏ICP备17064731号-1