Service
Self Supervision
HighPROTEC
devices are continuously monitored and supervised through different methods during normal
operation as well as during start-up phase.
Results of this supervision may be:
•
messages appearing within event-recorder (from release 1.2 or later),
•
indications within the display or Smart view,
•
corrective measures,
•
disabling of protection functions,
•
restart of the device
•
or any combination out of these.
In case of failures that cannot be corrected immediately three restarts within 20 minutes are accepted before the
device will be deactivated. The device should be removed in for service in such case to ensure continuous
correct operation. Contact data and address can be found at the end of this manual.
In case of any failures the recorders of the device should be left untouched to ensure an easy diagnosis and
proper repair at the factory. Besides the records and visible indications to the customer there exists internal
information about failures. These allow service personnel to make a detailed analysis of files with failure reports,
at least at factory site.
Self supervision is applied by different functions at different cyclic or noncyclic timings to the following parts and
functions of the device:
•
faultless cyclic execution of software,
•
functional capability of memory boards,
•
consistency of data,
•
functional capability of hardware sub-assemblies and
•
faultless operation of the measuring unit.
Faultless cyclic operation of software is supervised by timing analysis and checking results of different functions.
Errors of the software function (watchdog function) lead to restarting the device and switching off the self-
supervision relay (life-contact). Also the System-OK LED will blink red, after three unsuccessful attempts to
restart the device within a time-period of 20 minutes.
The main processor cyclically monitors the operation of the signal processor and initiates corrective actions or
restart of the device in case of faulty operation.
Data and files are generally secured against unintended overwriting or faulty changes by checksums.
The measuring unit continuously checks the measured data by comparing received data with data from a
second channel sampled in parallel.
Monitoring of the auxiliary voltage is done by reset-IC's. If the voltage of one of the different supply circuits falls
below a certain threshold a restart of the device is initiated. There are three major supply groups (24 V, 3.3 V
and 1.6 V), each of them being monitored separately and forcing the processor to reset (stop of the device) until
the voltage again reaches nominal value. If the voltage staggers around the threshold the device also starts
again after 5 s.
Independent of these separate monitoring functions the intermediate voltage circuit is buffered for
100 ms until all important and relevant operational and fault-data have been saved and the device initiates a
restart.
Page 308
EN MRU4 10/09