Download MTT Raportti 6

Transcript
from the original 3 to lowest 1. So the class is reduces from 13 to 11 and the result of
evaluation will still give the risk level of “high”.
The result of the evaluation was quite a surprise for the work group as without the
evaluation method the risk was estimated to be much smaller. Also engineering
judgement is needed when the effectiveness of risk reduction is considered.
The two safety concepts given are examples of possible systems to reduce the risk. How
these systems would be implemented is not considered, but they demonstrate the
requirements that are required from the system and problems that need to be solved to
implement the system. The examples take different approaches to demonstrate possible
solutions to the problem and to show what kind of problems there are in different
approaches. The solution for implementation might just as well be a hybrid between the
given examples. The solution based on a locking device can be implemented
independently from the tractor so that no resource is needed from the tractor or so that the
safety function performed if a fault occurs in required resource. On the down side system
based on a locking device needs the physical locking device which adds to the component
and assembly costs of the implement. The software lock approach, on the other hand,
does not necessarily need any new components, but it needs to use the ISOBUS network
and tractor resources and therefore we would need some kinds of guarantees that we can
perform the required function. Now there exists a possibility that for example a message
requesting that function is for some reason is not received or for some reason some other
node in the network overrides the requested function. Also, there is no redundancy in the
ISOBUS system as it is requested by the architectural constraints. The probability for
failure to happen in ISOBUS system is very low, but in safety and especially in cases,
where the failure of safety would lead to serious injuries or loss of life the requirements
are set to be very strict and therefore all possible failures are to be considered. The
ISOBUS network can be used if the function can be guaranteed and the loss of that
function can be detected.
As we first tried to acquire some kind of definition of the level of safety for our existing
machine, we realized that it is very difficult or even impossible to apply IEC 61508, EN
62061 or ISO/DIS 25119 to existing design, especially if there is no rigorous
documentation of the development process available. This is because these standards do
not regerd safety as something that the machine has, but as something that is designed and
built into the machine.
MTT RAPORTTI 6
69