Download MTT Raportti 6
Transcript
from the original 3 to lowest 1. So the class is reduces from 13 to 11 and the result of evaluation will still give the risk level of “high”. The result of the evaluation was quite a surprise for the work group as without the evaluation method the risk was estimated to be much smaller. Also engineering judgement is needed when the effectiveness of risk reduction is considered. The two safety concepts given are examples of possible systems to reduce the risk. How these systems would be implemented is not considered, but they demonstrate the requirements that are required from the system and problems that need to be solved to implement the system. The examples take different approaches to demonstrate possible solutions to the problem and to show what kind of problems there are in different approaches. The solution for implementation might just as well be a hybrid between the given examples. The solution based on a locking device can be implemented independently from the tractor so that no resource is needed from the tractor or so that the safety function performed if a fault occurs in required resource. On the down side system based on a locking device needs the physical locking device which adds to the component and assembly costs of the implement. The software lock approach, on the other hand, does not necessarily need any new components, but it needs to use the ISOBUS network and tractor resources and therefore we would need some kinds of guarantees that we can perform the required function. Now there exists a possibility that for example a message requesting that function is for some reason is not received or for some reason some other node in the network overrides the requested function. Also, there is no redundancy in the ISOBUS system as it is requested by the architectural constraints. The probability for failure to happen in ISOBUS system is very low, but in safety and especially in cases, where the failure of safety would lead to serious injuries or loss of life the requirements are set to be very strict and therefore all possible failures are to be considered. The ISOBUS network can be used if the function can be guaranteed and the loss of that function can be detected. As we first tried to acquire some kind of definition of the level of safety for our existing machine, we realized that it is very difficult or even impossible to apply IEC 61508, EN 62061 or ISO/DIS 25119 to existing design, especially if there is no rigorous documentation of the development process available. This is because these standards do not regerd safety as something that the machine has, but as something that is designed and built into the machine. MTT RAPORTTI 6 69