1、 IEC 61508-2Edition 2.0 2010-04INTERNATIONAL STANDARD NORME INTERNATIONALEFunctional safety of electrical/electronic/programmable electronic safety-related systems Part 2: Requirements for electrical/electronic/programmable electronic safety-related systems Scurit fonctionnelle des systmes lectrique
2、s/lectroniques/lectroniques programmables relatifs la scurit Partie 2: Exigences pour les systmes lectriques/lectroniques/lectroniques programmables relatifs la scurit IEC61508-2:2010 BASIC SAFETY PUBLICATION PUBLICATION FONDAMENTALE DE SCURIT THIS PUBLICATION IS COPYRIGHT PROTECTED Copyright 2010 I
3、EC, Geneva, Switzerland All rights reserved. Unless otherwise specified, no part of this publication may be reproduced or utilized in any form or by any means, electronic or mechanical, including photocopying and microfilm, without permission in writing from either IEC or IECs member National Commit
4、tee in the country of the requester. If you have any questions about IEC copyright or have an enquiry about obtaining additional rights to this publication, please contact the address below or your local IEC member National Committee for further information. Droits de reproduction rservs. Sauf indic
5、ation contraire, aucune partie de cette publication ne peut tre reproduite ni utilise sous quelque forme que ce soit et par aucun procd, lectronique ou mcanique, y compris la photocopie et les microfilms, sans laccord crit de la CEI ou du Comit national de la CEI du pays du demandeur. Si vous avez d
6、es questions sur le copyright de la CEI ou si vous dsirez obtenir des droits supplmentaires sur cette publication, utilisez les coordonnes ci-aprs ou contactez le Comit national de la CEI de votre pays de rsidence. IEC Central Office 3, rue de Varemb CH-1211 Geneva 20 Switzerland Email: inmailiec.ch
7、 Web: www.iec.ch About the IEC The International Electrotechnical Commission (IEC) is the leading global organization that prepares and publishes International Standards for all electrical, electronic and related technologies. About IEC publications The technical content of IEC publications is kept
8、under constant review by the IEC. Please make sure that you have the latest edition, a corrigenda or an amendment might have been published. Catalogue of IEC publications: www.iec.ch/searchpub The IEC on-line Catalogue enables you to search by a variety of criteria (reference number, text, technical
9、 committee,). It also gives information on projects, withdrawn and replaced publications. IEC Just Published: www.iec.ch/online_news/justpub Stay up to date on all new IEC publications. Just Published details twice a month all new publications released. Available on-line and also by email. Electrope
10、dia: www.electropedia.org The worlds leading online dictionary of electronic and electrical terms containing more than 20 000 terms and definitions in English and French, with equivalent terms in additional languages. Also known as the International Electrotechnical Vocabulary online. Customer Servi
11、ce Centre: www.iec.ch/webstore/custserv If you wish to give us your feedback on this publication or need further assistance, please visit the Customer Service Centre FAQ or contact us: Email: csciec.ch Tel.: +41 22 919 02 11 Fax: +41 22 919 03 00 A propos de la CEI La Commission Electrotechnique Int
12、ernationale (CEI) est la premire organisation mondiale qui labore et publie des normes internationales pour tout ce qui a trait llectricit, llectronique et aux technologies apparentes. A propos des publications CEI Le contenu technique des publications de la CEI est constamment revu. Veuillez vous a
13、ssurer que vous possdez ldition la plus rcente, un corrigendum ou amendement peut avoir t publi. Catalogue des publications de la CEI: www.iec.ch/searchpub/cur_fut-f.htm Le Catalogue en-ligne de la CEI vous permet deffectuer des recherches en utilisant diffrents critres (numro de rfrence, texte, com
14、it dtudes,). Il donne aussi des informations sur les projets et les publications retires ou remplaces. Just Published CEI: www.iec.ch/online_news/justpub Restez inform sur les nouvelles publications de la CEI. Just Published dtaille deux fois par mois les nouvelles publications parues. Disponible en
15、-ligne et aussi par email. Electropedia: www.electropedia.org Le premier dictionnaire en ligne au monde de termes lectroniques et lectriques. Il contient plus de 20 000 termes et dfinitions en anglais et en franais, ainsi que les termes quivalents dans les langues additionnelles. Egalement appel Voc
16、abulaire Electrotechnique International en ligne. Service Clients: www.iec.ch/webstore/custserv/custserv_entry-f.htm Si vous dsirez nous donner des commentaires sur cette publication ou si vous avez des questions, visitez le FAQ du Service clients ou contactez-nous: Email: csciec.ch Tl.: +41 22 919
17、02 11 Fax: +41 22 919 03 00 IEC 61508-2Edition 2.0 2010-04INTERNATIONAL STANDARD NORME INTERNATIONALEFunctional safety of electrical/electronic/programmable electronic safety-related systems Part 2: Requirements for electrical/electronic/programmable electronic safety-related systems Scurit fonction
18、nelle des systmes lectriques/lectroniques/lectroniques programmables relatifs la scurit Partie 2: Exigences pour les systmes lectriques/lectroniques/lectroniques programmables relatifs la scurit INTERNATIONAL ELECTROTECHNICAL COMMISSION COMMISSION ELECTROTECHNIQUE INTERNATIONALE XDICS 25.040.40 PRIC
19、E CODECODE PRIXISBN 978-2-88910-525-0BASIC SAFETY PUBLICATION PUBLICATION FONDAMENTALE DE SCURIT Registered trademark of the International Electrotechnical Commission Marque dpose de la Commission Electrotechnique Internationale 2 61508-2 IEC:2010 CONTENTS FOREWORD.5 INTRODUCTION.7 1 Scope.9 2 Norma
20、tive references .12 3 Definitions and abbreviations12 4 Conformance to this standard.12 5 Documentation .13 6 Management of functional safety 13 7 E/E/PE system safety lifecycle requirements 13 7.1 General .13 7.1.1 Objectives and requirements general13 7.1.2 Objectives .13 7.1.3 Requirements 13 7.2
21、 E/E/PE system design requirements specification .17 7.2.1 Objective .17 7.2.2 General .17 7.2.3 E/E/PE system design requirements specification18 7.3 E/E/PE system safety validation planning 19 7.3.1 Objective .19 7.3.2 Requirements 19 7.4 E/E/PE system design and development19 7.4.1 Objective .20
22、7.4.2 General requirements 20 7.4.3 Synthesis of elements to achieve the required systematic capability22 7.4.4 Hardware safety integrity architectural constraints.23 7.4.5 Requirements for quantifying the effect of random hardware failures .32 7.4.6 Requirements for the avoidance of systematic faul
23、ts .34 7.4.7 Requirements for the control of systematic faults.35 7.4.8 Requirements for system behaviour on detection of a fault 35 7.4.9 Requirements for E/E/PE system implementation 36 7.4.10 Requirements for proven in use elements 38 7.4.11 Additional requirements for data communications 39 7.5
24、E/E/PE system integration.40 7.5.1 Objective .40 7.5.2 Requirements 40 7.6 E/E/PE system operation and maintenance procedures .41 7.6.1 Objective .41 7.6.2 Requirements 41 7.7 E/E/PE system safety validation 42 7.7.1 Objective .42 7.7.2 Requirements 42 7.8 E/E/PE system modification.43 7.8.1 Objecti
25、ve .43 7.8.2 Requirements 43 7.9 E/E/PE system verification 44 7.9.1 Objective .44 61508-2 IEC:2010 3 7.9.2 Requirements 44 8 Functional safety assessment.46 Annex A (normative) Techniques and measures for E/E/PE safety-related systems control of failures during operation47 Annex B (normative) Techn
26、iques and measures for E/E/PE safety-related systems avoidance of systematic failures during the different phases of the lifecycle .62 Annex C (normative) Diagnostic coverage and safe failure fraction71 Annex D (normative) Safety manual for compliant items 74 Annex E (normative) Special architecture
27、 requirements for integrated circuits (ICs) with on-chip redundancy .76 Annex F (informative) Techniques and measures for ASICs avoidance of systematic failures .81 Bibliography89 Figure 1 Overall framework of the IEC 61508 series 11 Figure 2 E/E/PE system safety lifecycle (in realisation phase)14 F
28、igure 3 ASIC development lifecycle (the V-Model)15 Figure 4 Relationship between and scope of IEC 61508-2 and IEC 61508-3 15 Figure 5 Determination of the maximum SIL for specified architecture (E/E/PE safety-related subsystem comprising a number of series elements, see 7.4.4.2.3) 28 Figure 6 Determ
29、ination of the maximum SIL for specified architecture (E/E/PE safety-related subsystem comprised of two subsystems X any IEC National Committee interested in the subject dealt with may participate in this preparatory work. International, governmental and non-governmental organizations liaising with
30、the IEC also participate in this preparation. IEC collaborates closely with the International Organization for Standardization (ISO) in accordance with conditions determined by agreement between the two organizations. 2) The formal decisions or agreements of IEC on technical matters express, as near
31、ly as possible, an international consensus of opinion on the relevant subjects since each technical committee has representation from all interested IEC National Committees. 3) IEC Publications have the form of recommendations for international use and are accepted by IEC National Committees in that
32、 sense. While all reasonable efforts are made to ensure that the technical content of IEC Publications is accurate, IEC cannot be held responsible for the way in which they are used or for any misinterpretation by any end user. 4) In order to promote international uniformity, IEC National Committees
33、 undertake to apply IEC Publications transparently to the maximum extent possible in their national and regional publications. Any divergence between any IEC Publication and the corresponding national or regional publication shall be clearly indicated in the latter. 5) IEC itself does not provide an
34、y attestation of conformity. Independent certification bodies provide conformity assessment services and, in some areas, access to IEC marks of conformity. IEC is not responsible for any services carried out by independent certification bodies. 6) All users should ensure that they have the latest ed
35、ition of this publication. 7) No liability shall attach to IEC or its directors, employees, servants or agents including individual experts and members of its technical committees and IEC National Committees for any personal injury, property damage or other damage of any nature whatsoever, whether d
36、irect or indirect, or for costs (including legal fees) and expenses arising out of the publication, use of, or reliance upon, this IEC Publication or any other IEC Publications. 8) Attention is drawn to the Normative references cited in this publication. Use of the referenced publications is indispe
37、nsable for the correct application of this publication. 9) Attention is drawn to the possibility that some of the elements of this IEC Publication may be the subject of patent rights. IEC shall not be held responsible for identifying any or all such patent rights. International Standard IEC 61508-2
38、has been prepared by subcommittee 65A: System aspects, of IEC technical committee 65: Industrial-process measurement, control and automation. This second edition cancels and replaces the first edition published in 2000. This edition constitutes a technical revision. This edition has been subject to
39、a thorough review and incorporates many comments received at the various revision stages. It has the status of a basic safety publication according to IEC Guide 104. 6 61508-2 IEC:2010 The text of this standard is based on the following documents: FDIS Report on voting 65A/549/FDIS 65A/573/RVDFull i
40、nformation on the voting for the approval of this standard can be found in the report on voting indicated in the above table. This publication has been drafted in accordance with the ISO/IEC Directives, Part 2 A list of all parts of the IEC 61508 series, published under the general title Functional
41、safety of electrical / electronic / programmable electronic safety-related systems, can be found on the IEC website. The committee has decided that the contents of this publication will remain unchanged until the maintenance result date indicated on the IEC web site under “http:/webstore.iec.ch“ in
42、the data related to the specific publication. At this date, the publication will be reconfirmed, withdrawn, replaced by a revised edition, or amended. 61508-2 IEC:2010 7 INTRODUCTION Systems comprised of electrical and/or electronic elements have been used for many years to perform safety functions
43、in most application sectors. Computer-based systems (generically referred to as programmable electronic systems) are being used in all application sectors to perform non-safety functions and, increasingly, to perform safety functions. If computer system technology is to be effectively and safely exp
44、loited, it is essential that those responsible for making decisions have sufficient guidance on the safety aspects on which to make these decisions. This International Standard sets out a generic approach for all safety lifecycle activities for systems comprised of electrical and/or electronic and/o
45、r programmable electronic (E/E/PE) elements that are used to perform safety functions. This unified approach has been adopted in order that a rational and consistent technical policy be developed for all electrically-based safety-related systems. A major objective is to facilitate the development of
46、 product and application sector international standards based on the IEC 61508 series. NOTE 1 Examples of product and application sector international standards based on the IEC 61508 series are given in the Bibliography (see references 1, 2 and 3). In most situations, safety is achieved by a number
47、 of systems which rely on many technologies (for example mechanical, hydraulic, pneumatic, electrical, electronic, programmable electronic). Any safety strategy must therefore consider not only all the elements within an individual system (for example sensors, controlling devices and actuators) but
48、also all the safety-related systems making up the total combination of safety-related systems. Therefore, while this International Standard is concerned with E/E/PE safety-related systems, it may also provide a framework within which safety-related systems based on other technologies may be consider
49、ed. It is recognized that there is a great variety of applications using E/E/PE safety-related systems in a variety of application sectors and covering a wide range of complexity, hazard and risk potentials. In any particular application, the required safety measures will be dependent on many factors specific to the application. This International Standard, by being generic, will enable such m