IEC 61508 Functional Safety Standard Explained

IEC 61508, "Functional Safety of Electrical/Electronic/Programmable Electronic Safety-Related Systems," is a key technical specification for the crane industry. As the overarching international standard in functional safety, it serves as the core reference for the safety design of crane electrical control systems. The standard introduces the concept of Safety Integrity Level (SIL) and systematically defines requirements for the design, development, verification, and validation of safety-related electrical control systems.

The standard provides a unified technical basis for design personnel, inspection bodies, and users. Kelude strictly implements the technical requirements of this standard throughout its product development and manufacturing processes, ensuring equipment compliance and reliability.


Scope and Application of the Standard

IEC 61508 specifies the technical requirements and safety indicators for electrical, electronic, and programmable electronic systems in cranes, and applies to all types of lifting appliances with a rated lifting capacity above 0.5 t. The standard covers not only the design and manufacturing of new equipment but also provides clear technical guidance for the inspection, maintenance, and modification of equipment already in service. As a key component of the crane standard system, IEC 61508 works in coordination with the EN 13001 Crane Safety Standard series and ISO 4309 Wire Rope Inspection Standard to form a complete technical specification framework. The clearly defined technical parameters and safety factor requirements give design personnel a solid design basis, while also providing third-party inspection bodies with quantifiable acceptance criteria for type tests and factory acceptance tests.


Functional safety diagram for electrical/electronic/programmable electronic safety-related systems


Core Technical Parameter Framework

Under IEC 61508, the design and manufacturing of electrical, electronic, and programmable electronic systems must satisfy a rigorous set of technical parameter requirements. These parameters are established on the basis of extensive test data and safety engineering theory, covering everything from material selection to structural design. The safety factor ranges specified in the standard take full account of fatigue life and limit load conditions under severe operating environments. In practical engineering applications, design personnel must select appropriate parameter combinations based on the equipment's work duty classification, load spectrum, and operating conditions. The parameter cards below summarize the core technical indicators defined by the standard:

Safety Integrity Level (SIL)
SIL2 (Crane)
Probability of Failure
PFH ≤ 10⁻⁶–10⁻⁷
Hardware Fault Tolerance
HFT ≥ 1 (Redundancy)
Diagnostic Coverage
DC ≥ 90% (SIL2)
Safety Circuit
Hard-Wired Safety Relay
Verification Interval
Periodic Functional Test

Comparative Analysis of Key Technical Parameters

The comparison table below systematically contrasts the core parameters specified in IEC 61508 with general engineering practice. All values shown are either mandatory or recommended requirements of the standard and should be strictly implemented during design and selection as well as factory acceptance testing.

Itemtechnical requirementsDescription
Safety Integrity Level (SIL)SIL2(crane Safety-Related)SIL1Low/SIL2Medium/SIL3High/SIL4Highest
PFHValueSIL2:1×10⁻⁷~1×10⁻⁶Danger per Hour Failure Probability
Hardware ArchitectureHFT=1(At Leastdual channel)single channel SIL2Required DC≥99%
diagnostic coverage ProbabilityDC≥90%(SIL2)Implemented via Self-Test and Comparator
safety circuitHard Wiring Safety RelayPure (Software-Only) Not Permitted PLCImplemented via Self-Test and Comparatorsafety function
Software RequirementsVModel-Based Development+Comprehensive Testingsafety function Software and Standard Functional Separation

Inspection Requirements and Intervals

IEC 61508 sets out clear requirements for factory acceptance testing, type testing, and periodic inspection of electrical, electronic, and programmable electronic systems. Factory acceptance tests must be performed on every unit at the manufacturer's facility by the quality inspection department, and each unit that passes must be accompanied by a detailed inspection report and a certificate of conformity. For equipment already in service, the periodic inspection interval is determined by the work duty classification and the operating environment, and generally must not exceed 12 months.

Itemtechnical requirementsDescription
safety function Testingoverload/Overspeed/limit switch/emergency stopMonthly+Allsafety function
diagnostic coverage TestingSimulated Fault Verification DiagnosisAnnual+coverage Probability≥90%
SILSimulated Fault VerificationPFHCalculation+Hardware Architecture ReviewAnnual+Re-Evaluation upon Change
Software Change ManagementVersion Control+Regression TestingExecuted on Every Software Change

Safe Operation and Management Requirements

Under IEC 61508, safe operation and routine management play a critical role in the overall safety lifecycle. The standard places strong emphasis on operator qualification and training, requiring that all operators complete specialized training and obtain the necessary certification before being allowed to work. User units must establish a robust equipment file management system that documents the full history of installation, use, maintenance and inspection. Any safety hazard identified must be addressed through the rectification procedure specified in the standard, ensuring the equipment remains safe and controllable at all times. The standard also imposes restrictive requirements on equipment use under extreme operating conditions.

Frequently Asked Questions

Q: What Safety Integrity Level (SIL) does IEC 61508 require for crane safety functions?

A: Safety-related control functions on cranes—such as overload protection, overspeed protection, and emergency stop circuits—must achieve SIL 2. SIL 2 requires a probability of dangerous failure per hour (PFH) between 1×10⁻⁷ and 1×10⁻⁶, meaning at most one dangerous failure every 114 to 1,140 years. To meet SIL 2, a dual-channel (1oo2) hardware architecture is recommended, with a diagnostic coverage of no less than 90%. Kelude's safety control systems use TUV-certified safety relay modules that satisfy SIL 2 requirements.

Q: How do hardware architecture and diagnostic coverage relate to each other?

A: Hardware fault tolerance (HFT) indicates the number of faults a system can withstand. For SIL 2, a single-channel architecture (HFT=0) requires a diagnostic coverage of DC≥99%, which calls for diverse diagnostic methods. With a dual-channel architecture (HFT=1), DC≥90% is sufficient. In both cases, the final safety integrity must be verified through PFH calculations.

Q: Why can't safety functions rely entirely on PLCs?

A: The standard requires that safety-related functions—emergency stop, overload cutoff, and limit switches—be implemented through hard-wired safety relays rather than pure PLC software logic. PLC software has complex failure modes that make it difficult to guarantee a defined SIL rating. Hard-wired safety relays offer well-defined failure modes and validated safety data. Safety functions should use an independent safety circuit, separated from the standard function circuit.

Q: What phases make up the software safety lifecycle?

A: Following the V-model: software safety requirements specification → safety validation plan → software architecture design → software module design → coding → module testing → integration testing → system safety validation. Each phase has defined inputs and outputs, with change management applied throughout. Any change to safety function software must go through the full change management process, including change request, impact analysis, regression testing, and approved release.


— Kelude Heavy Industry specializes in crane design and manufacturing, strictly adhering to the IEC 61508 standard system. We provide lifecycle service covering solution design, manufacturing and installation, and after-sales maintenance. To learn how this standard is applied in our products, contact our technical team for detailed technical documentation.

Related News

contact

contact us

phone:
+86 13903802779

mail:3915269@qq.com

Working hours: Monday to Friday

Wechat
Wechat
SHARE
TOP