SIL3 Functional Safety Architecture: Dual Brake Redundancy

SIL3 Functional Safety Architecture: Dual-Brake Redundancy and Full-Chain Protection with Safety PLCs. In modern overhead crane systems, functional safety has evolved from an optional feature to a mandatory requirement.

In modern industrial overhead crane systems, functional safety has shifted from an optional configuration to a mandatory requirement. Kelude Heavy Industry has built a SIL3-rated functional safety system in accordance with IEC 61508 (Functional Safety of Electrical/Electronic/Programmable Electronic Safety-Related Systems), IEC 62061 (Safety of Machinery — Functional Safety of Safety-Related Electrical, Electronic and Programmable Electronic Control Systems), and the ISO 4301 Crane Design Standard. This system covers the entire workflow — from Hazard Analysis and Risk Assessment (HARA), three-tier safety architecture design, dual-brake redundancy protection, safety PLC programming with PROFIsafe communication, to TÜV Certification acceptance — delivering a full-lifecycle functional safety solution from safety goal definition to system acceptance. This article details Kelude Heavy Industry's technical practices in SIL3 functional safety, providing a systematic technical reference for overhead crane safety design.

SIL3 functional safety architecture: dual-brake redundancy and safety PLC full-chain protection — technical specifications and process diagram

HARA Hazard Analysis for Overhead Crane Systems

Hazard analysis and risk assessment (HARA) is the starting point of any functional safety design. Following the requirements of ISO 12100 (Safety of Machinery — General Principles for Design — Risk Assessment and Risk Reduction) and IEC 62061, Kelude Heavy Industry conducts hazard identification across all operating conditions and the full lifecycle of the overhead crane system. Key hazard events for overhead cranes include: uncontrolled lowering of the hoisting mechanism causing the load to drop, collisions from the cross travel and long travel mechanisms causing personnel injury, brake failure leading to load drift, limit switch failure resulting in travel overrun, and wire rope breakage (strand or wire fractures) causing the suspended load to fall. For each hazard event, the HARA team performs a quantitative risk assessment based on three parameters — severity (Se), frequency of exposure (Fr), and probability of avoidance (Av) — to determine the required Safety Integrity Level (SIL). The table below presents the HARA results for a typical Kelude overhead crane system.

← Scroll left / right to view full table →
Hazardous Event SeveritySe ExposureFrequencyFr Avoidance PossibilityAv RiskGrade RequiredSafety Integrity Level (SIL) Safety Function
Hoisting mechanismOverspeedLowering4(Catastrophic)3(Frequent)1(Almost Impossible)IIIaSIL3Overspeed Protection+Dual Brakeredundancy
LargeCross Travel / Trolley TravelCollision3(Serious)4(Continuous)2(Almost Impossible)IIIbSIL2Safety Limit+Anti-Collision Device
BrakeFailureCrane Drift4(Catastrophic)3(Frequent)1(Almost Impossible)IIIaSIL3BrakeCondition Monitoring+redundancyBraking
Limit switchFailureOvertravel3(Serious)2(Occasional)2(Almost Impossible)IISIL1DualLimit switch+Software Limit
Wire RopeFracture4(Catastrophic)2(Occasional)1(Almost Impossible)IIIbSIL2wire rope broken wire detection+Overload Protection

Kelude Heavy Industry's HARA analysis team is led by experts with TÜV Functional Safety Engineer certification, ensuring the authority and compliance of every analysis. The HARA report is a core component of the machine's safety documentation and is delivered with the equipment for the customer's records.

SIL Levels and Safety Targets for Overhead Cranes

Safety Integrity Level (SIL) is a discrete classification of the safety performance required of a safety-related system. As defined by IEC 61508, SIL levels are determined by the average probability of failure on demand (PFDavg) or the probability of dangerous failure per hour (PFH): SIL1 requires a PFDavg between 10⁻² and 10⁻¹, or a PFH between 10⁻⁶ and 10⁻⁵; SIL2 requires a PFDavg between 10⁻³ and 10⁻², or a PFH between 10⁻⁷ and 10⁻⁶; SIL3 requires a PFDavg between 10⁻⁴ and 10⁻³, or a PFH between 10⁻⁸ and 10⁻⁷; SIL4 requires a PFDavg between 10⁻⁵ and 10⁻⁴, or a PFH between 10⁻⁹ and 10⁻⁸. Kelude Heavy Industry's SIL3 safety target for overhead crane systems is: PFH < 10⁻⁷, with a safety availability greater than 99.99%. This means the system's dangerous failure time is limited to no more than 52.6 minutes per year. To achieve this target, Kelude implements redundant hardware architectures (1oo2D, 2oo3, etc.), certified safety PLCs and safety communication protocols at the software level, and third-party audits by TÜV SÜD or TÜV Rheinland at the management level, ensuring the functional safety management system complies with IEC 61508.

Three-Layer Safety Architecture for Crane Control Systems

Kelude Heavy Industry's crane functional safety system is built on a classic three-layer safety architecture. The first layer is the Basic Control System, responsible for normal crane operation, including hoisting, trolley and gantry travel start/stop and speed control, as well as conventional overload protection and travel limit functions. This layer uses general-purpose PLCs and does not carry safety functions. The second layer is the Safety Control System, which operates independently of the basic control system and is responsible for implementing SIL-related safety functions. This layer uses TÜV-certified safety PLCs (such as the Siemens S7-1200F or S7-1500F series) and exchanges data with distributed safety I/O modules and safety drives via the PROFIsafe safety communication protocol. The safety control system continuously monitors safety-related signals such as hoisting overspeed, brake status, door limit switches, and emergency stop buttons. Upon detecting a hazardous condition, it immediately triggers a safe stop sequence. The third layer is the Safety Monitoring & Diagnosis System, which provides online monitoring and fault diagnosis of the safety control system's operational status, along with safety status display and alarm logging on the Human-Machine Interface (HMI). The core principle of the three-layer architecture is independence — the safety control system's hardware and software must be physically and logically isolated from the basic control system to avoid common cause failures. Kelude's three-layer safety architecture has received SIL3 system certification from TÜV SÜD and has been applied to more than 500 overhead crane systems to date.

Dual Brake Redundancy and Overspeed Protection for Hoisting

The hoisting mechanism is the subsystem with the highest safety risk in an overhead crane, making its protective measures the core of SIL3 functional safety design. Kelude Heavy Industry employs a dual brake redundancy design in the hoisting mechanism: one Safety Brake is installed on the high-speed shaft of the gearbox and another on the drum shaft, with both brakes being electrically and mechanically fully independent. Under normal operating conditions, both brakes engage simultaneously; if one brake fails, the other can independently handle the full braking torque, ensuring the suspended load remains safely held. Brake status is continuously monitored by the safety PLC through limit switches and brake wear sensors. If abnormal response time, reduced braking torque, or excessive brake pad wear is detected, the system automatically triggers an alarm and requires maintenance before the next work cycle. Overspeed protection works in coordination with the dual brake redundancy: an Overspeed Switch is mounted on the hoist's high-speed shaft. When the lowering speed exceeds 1.25 times the rated value, the safety PLC triggers an emergency braking sequence within 50 ms, engaging both Safety Brakes simultaneously. Kelude has also developed a "soft braking" control strategy — during normal stops, the two brakes engage with a time offset of approximately 200 ms, avoiding impact loads caused by simultaneous braking and extending brake service life. The dual brake redundancy system's safety functions are certified to meet SIL3 requirements, with a PFH value below 5×10⁻⁸ and safety availability exceeding 99.995%.

Safety PLC and PROFIsafe Communication for SIL3 Systems

The safety PLC is the core control element of an SIL3 functional safety system. Kelude Heavy Industry uses the Siemens S7-1500F series safety PLC as the standard configuration for its crane safety control systems. This PLC series is TÜV SÜD certified to SIL3 and supports password-protected engineering configuration, secure user program download, and integrated fail-safe communication. Data exchange between the safety PLC and distributed safety I/O modules (such as the ET 200SP F series) is carried out via the PROFIsafe communication protocol. PROFIsafe is a safety communication layer on the PROFINET bus system that adds a safety CRC checksum (CRC2) and a sequence number (Watchdog) to standard PROFINET telegrams, ensuring the integrity, timeliness, and authenticity of safety data during transmission. PROFIsafe fail-safe communication meets the requirements of IEC 61784-3-3, with a safety response time below 30 ms, satisfying SIL3 communication requirements. Kelude has also developed a standardized library of safety PLC function blocks covering safe stop (SS1, STO), safely limited speed (SLS), safety gate monitoring, emergency stop handling, and brake control. This significantly shortens the programming and commissioning cycle of safety control systems. Safety PLC programs undergo rigorous code review and functional testing, with test coverage requirements of 100% statement coverage and over 95% branch coverage. All test records are archived as technical evidence for TÜV certification audits.

Safety System Acceptance Testing and SIL Verification

Acceptance testing and verification of safety systems are critical milestones in the functional safety lifecycle. Kelude Heavy Industry develops a complete safety system acceptance test plan in accordance with IEC 61508 Part 7 and IEC 62061 Chapter 8. The acceptance testing process is divided into three phases. The first phase is the Factory Acceptance Test (FAT), conducted at Kelude's manufacturing workshop, covering safety function correctness testing, safety response time testing, fault injection testing (simulating sensor failures, communication interruptions, power supply faults, and other abnormal conditions), and redundancy system switchover testing. The second phase is the Site Acceptance Test (SAT), performed at the crane installation site, verifying the coordination between safety functions and the operating system under real working conditions. The third phase is SIL verification calculation, which uses hardware architecture constraints (HFT — hardware fault tolerance), diagnostic coverage (DC), and common cause failure β factors, along with the formulas and Markov models in IEC 61508-6 annexes, to calculate PFDavg or PFH values and verify that the system's actual achieved SIL level meets design requirements. Upon completion of safety system acceptance, Kelude issues a comprehensive safety system acceptance report, SIL verification calculation document, and functional safety archive manual, supporting final audits by customers or third-party certification bodies such as TÜV SÜD and TÜV Rheinland. To date, Kelude Heavy Industry has completed TÜV certification acceptance for more than 50 SIL3 crane systems, with a 100% success rate.

Frequently Asked Questions

Q: Is SIL3 functional safety mandatory for all overhead crane applications? How do I determine the required SIL rating?
A: Not every overhead crane application requires SIL3. The required Safety Integrity Level (SIL) is determined by the Hazard Analysis and Risk Assessment (HARA), which evaluates the severity of the hazardous event, the frequency of exposure, and the probability of avoidance. Per IEC 62061, hoisting mechanisms on standard industrial overhead cranes (non-explosion-proof, non-nuclear-safety-grade) typically require SIL2 to SIL3, while the trolley travel and bridge travel mechanisms typically require SIL1 to SIL2. Kelude offers modular functional safety solutions spanning SIL1 through SIL3, configured flexibly based on your HARA findings to avoid the cost burden of over-engineering.
Q: How is synchronization and reliability ensured between the two brakes in a dual-brake redundant system?
A: Kelude's dual-brake redundant system ensures synchronization and reliability through the following measures: The two brakes are each controlled by independent safety relay contacts, with fully isolated electrical circuits. A safety PLC independently monitors the operational status of each brake, including shoe open/closed position signals, brake coil current detection, and braking response time monitoring (normal range: 150–300 ms). If an abnormal response is detected in one brake, the system automatically triggers an alarm and blocks the next work cycle. During normal stops, the two brakes engage sequentially with a time offset of approximately 200 ms; during emergency braking, they engage simultaneously. The brakes are safety-rated units from Germany's Sibre or Italy's Gru, delivering a static braking torque of at least 1.5 times the rated load, in compliance with ISO 4301, Section 6.3.
Q: What are the key differences between programming a safety PLC and a standard PLC? Do programmers need special qualifications?
A: Programming a safety PLC is fundamentally different from programming a standard PLC. Safety PLC programs must be configured and programmed using TÜV-certified engineering tools, such as Siemens TIA Portal V17 and Above with the F-options package. Safety programs rely exclusively on certified safety function blocks (F-FBs); user-defined safety functions are not permitted. Program downloads require password authorization and CRC verification. Programmers must hold a Functional Safety Engineer certificate issued by TÜV (TÜV FS Engineer or TÜV FSEng) and pass Kelude Heavy Industry's internal safety PLC programming assessment before they can independently undertake safety PLC programming work. Kelude Heavy Industry offers Siemens safety PLC programming training, covering PROFIsafe communication configuration, application of safety function blocks, and fault-safe program debugging.
Q: What are the costs and timelines for SIL3 certification, and what key issues should be considered during the process?
A: The cost and duration of SIL3 certification depend on the complexity of the overhead crane system and the chosen certification body. For a standard double-girder bridge crane with a 50t lifting capacity and a 30m span, TÜV SÜD certification costs approximately USD 44,000–74,000, with a typical certification period of 6–12 months. Key considerations during certification include: first, the functional safety management system must be established and operational before project kickoff, covering the entire lifecycle—safety planning, HARA analysis, safety requirement specifications, design verification, production and installation controls, and operation and maintenance guidance. Second, hardware selection for the safety system must use TÜV-certified components (safety PLCs, safety relays, safety encoders, etc.), supported by complete certificates and technical parameter documentation. Third, the FMEA analysis of the safety system must address all potential failure modes, with diagnostic measures defined for each. Kelude offers end-to-end functional safety engineering services—from HARA analysis through TÜV certification—significantly shortening the certification timeline and reducing compliance risk.

Related News

contact

contact us

phone:
+86 13903802779

mail:3915269@qq.com

Working hours: Monday to Friday

Wechat
Wechat
SHARE
TOP