ISO 8102-6:2019
(Main)Electrical requirements for lifts, escalators and moving walks - Part 6: Programmable electronic systems in safety-related applications for escalators and moving walks (PESSRAE)
Electrical requirements for lifts, escalators and moving walks - Part 6: Programmable electronic systems in safety-related applications for escalators and moving walks (PESSRAE)
1.1 This document is applicable to the product family of escalators and moving walks used in residential buildings, offices, hospitals, hotels, industrial plants, etc. This document covers those aspects that need to be addressed when programmable electronic systems are used to carry out electric safety functions for escalators and moving walks (PESSRAE). This document is applicable for escalator and moving walk safety functions that are identified in escalator and moving walk codes, standards, or laws that reference this document for PESSRAE application. The safety integrity levels (SILs) specified in this document are understood to be valid for PESSRAE application in the context of the referenced escalator and moving walk codes, standards, and laws in the Bibliography. 1.2 This document is also applicable for the application of PESSRAE that are new or deviate from those described in this document. 1.3 The requirements of this document regarding electrical safety/protective devices are such that it is not necessary to take into consideration the possibility of a failure of an electric safety/protective device complying with all the requirements of this document and other relevant standards. This document: a) uses safety integrity levels (SIL) for specifying the target failure rate for the safety functions to be implemented by the PESSRAE; b) specifies the requirements for achieving safety integrity for a function but does not specify who is responsible for implementing and maintaining the requirements (for example, designers, suppliers, owner/operating company, contractor); this responsibility is assigned to different parties according to safety planning and national regulations; c) applies to PE systems used in escalator and moving walk applications that meet the minimum requirements of a recognized escalator and moving walk standards, such as EN 115, ASME A17.1/CSA B44 or The Japan Building Standard Law Enforcement Order For Elevator and Escalator; d) defines the relationship between this document and IEC 61508 and defines the relationship between this document and ISO 22200; e) outlines the relationship between escalator and moving walk safety functions and their safe-state conditions; f) applies to phases and activities that are specific to design of hardware and software but not the phases and activities which occur post design, for example sourcing and manufacturing; h) provides requirements relating to the hardware and software safety validation; i) establishes the safety integrity levels for specific escalator and moving walk safety functions; j) specifies techniques/measures required for achieving the specified safety integrity levels; k) defines a maximum level of performance (SIL 3) which can be achieved for a PESSRAE according to this document and defines a minimum level of performance (SIL 1). 1.4 This document does not cover: a) hazards arising from the PE systems equipment itself such as electric shock etc.; b) the concept of fail-safe that can be of value when the failure modes are well defined and the level of complexity is relatively low. The concept of fail-safe was considered inappropriate because of the full range of complexity of PESSRAE that are within the scope of this document; c) other relevant requirements necessary for the complete application of a PESSRAE in an escalator and moving walk safety function, such as system integration specifications, temperature and humidity, the mechanical construction, mounting and labelling of switches, actuators, or sensors that contain PESSRAE. d) foreseeable misuse involving security threats related to malevolent or unauthorized action. This document can be used in cases where a security threat analysis needs to be considered, provided that the specified SIL has been reassessed.
Exigences électriques pour ascenseurs, escaliers mécaniques et trottoirs roulants — Partie 6: Systèmes électroniques programmables dans les applications liées à la sécurité pour escaliers mécaniques et trottoirs roulants
General Information
- Status
- Published
- Publication Date
- 29-Jan-2019
- Technical Committee
- ISO/TC 178 - Lifts, escalators and moving walks
- Drafting Committee
- ISO/TC 178/WG 8 - Electrical requirements
- Current Stage
- 9093 - International Standard confirmed
- Start Date
- 10-Mar-2025
- Completion Date
- 13-Dec-2025
Relations
- Effective Date
- 28-Jan-2017
Overview
ISO 8102-6:2019 specifies electrical requirements for programmable electronic systems used in safety-related applications for escalators and moving walks (PESSRAE). It applies to the product family of escalators and moving walks used in buildings, hospitals, hotels, industrial plants, etc., and sets product‑specific requirements when programmable electronic (PE) systems implement electric safety functions. The standard uses Safety Integrity Levels (SILs) to define target failure rates and provides techniques/measures and validation requirements for achieving those SILs (SIL 1 minimum, SIL 3 maximum for PESSRAE under this document).
Key topics and technical requirements
- SIL-based safety specification: Defines target SILs for escalator and moving-walk safety functions and the relationship between safety functions and safe‑state conditions. (See Tables 1 and 2 in the standard.)
- Scope of application: Applies to design phases specific to hardware and software of PE systems (not post-design activities such as sourcing or manufacturing).
- Implementation & verification: Specifies techniques and measures to implement, verify and maintain compliance with specified SILs (Annex A is normative on techniques/measures; Annex B gives an example risk reduction decision table).
- Validation: Requirements for hardware and software safety validation to demonstrate SIL attainment.
- Integration constraints: Intended for PE systems that meet minimum requirements of recognized escalator/moving-walk standards (for example EN 115, ASME A17.1/CSA B44, or Japan Building Standard Law).
- Limitations & exclusions: Does not cover hazards from PE equipment itself (e.g., electric shock), the general fail‑safe concept for simple systems, some system‑integration aspects (temperature/humidity, mechanical mounting/labeling), or deliberate security threats - although the standard may be used when a security threat analysis leads to reassessment of SILs.
- Harmonization: Defines relationships with IEC 61508 and ISO 22200 and is intended for selective reference within national escalator and moving‑walk standards.
Practical applications
- Use ISO 8102-6:2019 to allocate and justify SILs for escalator/moving-walk safety functions during system design.
- Guide development of PE safety architectures (PLCs, microcontrollers, FPGAs, PLCs, sensors/actuators) and associated software to meet SIL requirements.
- Plan verification, validation and documentation evidence needed for conformity assessment and safety certification.
- Support national standards harmonization and to define product‑family specific safety requirements for new or modified safety functions.
Who uses this standard
- Safety engineers, system architects, and control‑system designers for escalators and moving walks
- Manufacturers and suppliers of PE systems and safety controllers
- Certification bodies, regulators and national standards committees
- Owners/operators and contractors involved in safety planning and compliance
Related standards
- IEC 61508 (all parts) - functional safety framework
- IEC 62061 - safety of machinery (related guidance)
- ISO 22200 - EMC product family standard for lifts, escalators and moving walks
- EN 115, ASME A17.1/CSA B44 - recognized escalator and moving‑walk standards referenced by ISO 8102-6
Keywords: ISO 8102-6:2019, PESSRAE, programmable electronic systems, escalator safety, moving walk safety, Safety Integrity Level, SIL, IEC 61508, ISO 22200, EN 115.
Frequently Asked Questions
ISO 8102-6:2019 is a standard published by the International Organization for Standardization (ISO). Its full title is "Electrical requirements for lifts, escalators and moving walks - Part 6: Programmable electronic systems in safety-related applications for escalators and moving walks (PESSRAE)". This standard covers: 1.1 This document is applicable to the product family of escalators and moving walks used in residential buildings, offices, hospitals, hotels, industrial plants, etc. This document covers those aspects that need to be addressed when programmable electronic systems are used to carry out electric safety functions for escalators and moving walks (PESSRAE). This document is applicable for escalator and moving walk safety functions that are identified in escalator and moving walk codes, standards, or laws that reference this document for PESSRAE application. The safety integrity levels (SILs) specified in this document are understood to be valid for PESSRAE application in the context of the referenced escalator and moving walk codes, standards, and laws in the Bibliography. 1.2 This document is also applicable for the application of PESSRAE that are new or deviate from those described in this document. 1.3 The requirements of this document regarding electrical safety/protective devices are such that it is not necessary to take into consideration the possibility of a failure of an electric safety/protective device complying with all the requirements of this document and other relevant standards. This document: a) uses safety integrity levels (SIL) for specifying the target failure rate for the safety functions to be implemented by the PESSRAE; b) specifies the requirements for achieving safety integrity for a function but does not specify who is responsible for implementing and maintaining the requirements (for example, designers, suppliers, owner/operating company, contractor); this responsibility is assigned to different parties according to safety planning and national regulations; c) applies to PE systems used in escalator and moving walk applications that meet the minimum requirements of a recognized escalator and moving walk standards, such as EN 115, ASME A17.1/CSA B44 or The Japan Building Standard Law Enforcement Order For Elevator and Escalator; d) defines the relationship between this document and IEC 61508 and defines the relationship between this document and ISO 22200; e) outlines the relationship between escalator and moving walk safety functions and their safe-state conditions; f) applies to phases and activities that are specific to design of hardware and software but not the phases and activities which occur post design, for example sourcing and manufacturing; h) provides requirements relating to the hardware and software safety validation; i) establishes the safety integrity levels for specific escalator and moving walk safety functions; j) specifies techniques/measures required for achieving the specified safety integrity levels; k) defines a maximum level of performance (SIL 3) which can be achieved for a PESSRAE according to this document and defines a minimum level of performance (SIL 1). 1.4 This document does not cover: a) hazards arising from the PE systems equipment itself such as electric shock etc.; b) the concept of fail-safe that can be of value when the failure modes are well defined and the level of complexity is relatively low. The concept of fail-safe was considered inappropriate because of the full range of complexity of PESSRAE that are within the scope of this document; c) other relevant requirements necessary for the complete application of a PESSRAE in an escalator and moving walk safety function, such as system integration specifications, temperature and humidity, the mechanical construction, mounting and labelling of switches, actuators, or sensors that contain PESSRAE. d) foreseeable misuse involving security threats related to malevolent or unauthorized action. This document can be used in cases where a security threat analysis needs to be considered, provided that the specified SIL has been reassessed.
1.1 This document is applicable to the product family of escalators and moving walks used in residential buildings, offices, hospitals, hotels, industrial plants, etc. This document covers those aspects that need to be addressed when programmable electronic systems are used to carry out electric safety functions for escalators and moving walks (PESSRAE). This document is applicable for escalator and moving walk safety functions that are identified in escalator and moving walk codes, standards, or laws that reference this document for PESSRAE application. The safety integrity levels (SILs) specified in this document are understood to be valid for PESSRAE application in the context of the referenced escalator and moving walk codes, standards, and laws in the Bibliography. 1.2 This document is also applicable for the application of PESSRAE that are new or deviate from those described in this document. 1.3 The requirements of this document regarding electrical safety/protective devices are such that it is not necessary to take into consideration the possibility of a failure of an electric safety/protective device complying with all the requirements of this document and other relevant standards. This document: a) uses safety integrity levels (SIL) for specifying the target failure rate for the safety functions to be implemented by the PESSRAE; b) specifies the requirements for achieving safety integrity for a function but does not specify who is responsible for implementing and maintaining the requirements (for example, designers, suppliers, owner/operating company, contractor); this responsibility is assigned to different parties according to safety planning and national regulations; c) applies to PE systems used in escalator and moving walk applications that meet the minimum requirements of a recognized escalator and moving walk standards, such as EN 115, ASME A17.1/CSA B44 or The Japan Building Standard Law Enforcement Order For Elevator and Escalator; d) defines the relationship between this document and IEC 61508 and defines the relationship between this document and ISO 22200; e) outlines the relationship between escalator and moving walk safety functions and their safe-state conditions; f) applies to phases and activities that are specific to design of hardware and software but not the phases and activities which occur post design, for example sourcing and manufacturing; h) provides requirements relating to the hardware and software safety validation; i) establishes the safety integrity levels for specific escalator and moving walk safety functions; j) specifies techniques/measures required for achieving the specified safety integrity levels; k) defines a maximum level of performance (SIL 3) which can be achieved for a PESSRAE according to this document and defines a minimum level of performance (SIL 1). 1.4 This document does not cover: a) hazards arising from the PE systems equipment itself such as electric shock etc.; b) the concept of fail-safe that can be of value when the failure modes are well defined and the level of complexity is relatively low. The concept of fail-safe was considered inappropriate because of the full range of complexity of PESSRAE that are within the scope of this document; c) other relevant requirements necessary for the complete application of a PESSRAE in an escalator and moving walk safety function, such as system integration specifications, temperature and humidity, the mechanical construction, mounting and labelling of switches, actuators, or sensors that contain PESSRAE. d) foreseeable misuse involving security threats related to malevolent or unauthorized action. This document can be used in cases where a security threat analysis needs to be considered, provided that the specified SIL has been reassessed.
ISO 8102-6:2019 is classified under the following ICS (International Classification for Standards) categories: 91.140.90 - Lifts. Escalators. The ICS classification helps identify the subject area and facilitates finding related standards.
ISO 8102-6:2019 has the following relationships with other standards: It is inter standard links to ISO 22201-2:2013. Understanding these relationships helps ensure you are using the most current and applicable version of the standard.
You can purchase ISO 8102-6:2019 directly from iTeh Standards. The document is available in PDF format and is delivered instantly after payment. Add the standard to your cart and complete the secure checkout process. iTeh Standards is an authorized distributor of ISO standards.
Standards Content (Sample)
INTERNATIONAL ISO
STANDARD 8102-6
First edition
2019-01
Electrical requirements for lifts,
escalators and moving walks —
Part 6:
Programmable electronic systems
in safety-related applications
for escalators and moving walks
(PESSRAE)
Exigences électriques pour ascenseurs, escaliers mécaniques et
trottoirs roulants —
Partie 6: Systèmes électroniques programmables dans les applications
liées à la sécurité pour escaliers mécaniques et trottoirs roulants
Reference number
©
ISO 2019
© ISO 2019
All rights reserved. Unless otherwise specified, or required in the context of its implementation, no part of this publication may
be reproduced or utilized otherwise in any form or by any means, electronic or mechanical, including photocopying, or posting
on the internet or an intranet, without prior written permission. Permission can be requested from either ISO at the address
below or ISO’s member body in the country of the requester.
ISO copyright office
CP 401 • Ch. de Blandonnet 8
CH-1214 Vernier, Geneva
Phone: +41 22 749 01 11
Fax: +41 22 749 09 47
Email: copyright@iso.org
Website: www.iso.org
Published in Switzerland
ii © ISO 2019 – All rights reserved
Contents Page
Foreword .iv
Introduction .v
1 Scope . 1
2 Normative references . 2
3 Terms and definitions . 2
4 Requirements . 6
4.1 General . 6
4.2 Extended application of this document . 7
4.2.1 General. 7
4.2.2 Risk assessment . . 7
4.2.3 Limits for specifying SIL for PESSRAE . 7
4.2.4 Safe-state requirements . 8
4.3 Safety function SIL requirements . 8
4.4 SIL relevant and non-SIL relevant safe state requirements . 9
4.5 Implementation and demonstration requirements for verification of SIL compliance .15
4.5.1 General.15
4.5.2 Required techniques and measures to implement and demonstrate PE
systems compliance with specified safety integrity levels in this document .15
4.5.3 Loss of power after a PESSRAE device has actuated .15
Annex A (normative) Techniques and measures to implement, verify, and maintain SIL
compliance .16
Annex B (informative) Example of risk reduction decision table .19
Bibliography .20
Foreword
ISO (the International Organization for Standardization) is a worldwide federation of national standards
bodies (ISO member bodies). The work of preparing International Standards is normally carried out
through ISO technical committees. Each member body interested in a subject for which a technical
committee has been established has the right to be represented on that committee. International
organizations, governmental and non-governmental, in liaison with ISO, also take part in the work.
ISO collaborates closely with the International Electrotechnical Commission (IEC) on all matters of
electrotechnical standardization.
The procedures used to develop this document and those intended for its further maintenance are
described in the ISO/IEC Directives, Part 1. In particular, the different approval criteria needed for the
different types of ISO documents should be noted. This document was drafted in accordance with the
editorial rules of the ISO/IEC Directives, Part 2 (see www .iso .org/directives).
Attention is drawn to the possibility that some of the elements of this document may be the subject of
patent rights. ISO shall not be held responsible for identifying any or all such patent rights. Details of
any patent rights identified during the development of the document will be in the Introduction and/or
on the ISO list of patent declarations received (see www .iso .org/patents).
Any trade name used in this document is information given for the convenience of users and does not
constitute an endorsement.
For an explanation of the voluntary nature of standards, the meaning of ISO specific terms and
expressions related to conformity assessment, as well as information about ISO's adherence to the
World Trade Organization (WTO) principles in the Technical Barriers to Trade (TBT) see www .iso
.org/iso/foreword .html.
This document was prepared by Technical Committee ISO/TC 178, Lifts, escalators and moving walks.
This document cancels and replaces ISO 22201-2:2013.
Any feedback or questions on this document should be directed to the user’s national standards body. A
complete listing of these bodies can be found at www .iso .org/members .html.
iv © ISO 2019 – All rights reserved
Introduction
0.1 General
Systems comprised of electrical and/or electronic elements have been used for many years to perform
safety functions in most application sectors. Computer-based systems, generically referred to as
programmable electronic systems, are being used in many application sectors to perform non-safety
functions and, increasingly, to perform safety functions. If computer system technology is to be
effectively and safely exploited, it is essential that those responsible for making decisions have sufficient
guidance on the safety aspects on which to make these decisions. In most situations, safety is achieved
by a number of protective systems that rely on many technologies (for example mechanical, hydraulic,
pneumatic, electrical, electronic, programmable electronic). Therefore, any safety strategy needs to
consider not only all the components within an individual system (for example sensors, controlling
devices and actuators) but also all the safety-related elements making up the total combination of
safety-related systems.
This document is based on the guidelines provided in generic standards IEC 62061 and EN 115-1:2008.
The requirements given in this document recognize the fact that the product family covers a total
range of escalators and moving walks used in residential buildings, offices, hospitals, hotels, industrial
plants, etc. This document is the product family standard for escalators and moving walks and takes
precedence over all aspects of the generic standard.
This document sets out the product-specific requirements for systems comprising programmable
electronic elements that are used to perform safety functions in escalators and moving walks. This
document has been developed so that consistent technical and performance requirements and rationale
can be specified for programmable electronic system in safety-related application for escalators
(PESSRAE) and moving walks.
Risk analysis, terminology, and technical solutions have been considered, taking into account the
methods of the IEC 61508 series. The risk analysis of each safety function specified in Table 1 resulted
in the classification of electric safety functions applied to PESSRAE. Tables 1 and 2 give the safety
integrity level and functional requirements, respectively, for each electric safety function.
The safety integrity levels (SIL) specified in this document can also be applied to other technologies
used to satisfy the safety functions specified in this document.
0.2 Harmonization with national escalator and moving walk standards
The application of this document is intended to be by reference within a national escalator and moving
walk standards such as escalator and moving walk codes, standards, or laws. There are three reasons
for this.
— to allow selective reference by national standards to specific escalator and moving walk safety
functions described in this document. Not all escalator and moving walk safety functions identified
in this document are called out in every national standard;
— to allow for future harmonization of national standards with escalator and moving walk safety
functions identified in this document. Because some differences exist in the requirements for
fulfilment of the safety objective of national escalator and moving walk standards and in national
practice of escalator and moving walk use and maintenance, there are instances where the
requirements for escalator and moving walk safety functions described in this document are based
on the consensus work and agreement by ISO/TC 178. National bodies can choose to selectively
harmonize with those escalator and moving walk safety functions that differ in the requirements
called for by the existing national standards in future revisions;
— to allow for the application of this document where escalator and moving walk safety functions
are new or deviate from those specified in this document. More and more, national escalator and
moving walk legislations are moving to performance based requirements. For this reason the
development of new or different escalator and moving walk safety functions can be foreseen in
product specific applications. For those who require escalator and moving walk safety functions
that are new or different from those specified in this document, this document provides a verifiable
method to establish the necessary level of safety integrity for those functions.
vi © ISO 2019 – All rights reserved
INTERNATIONAL STANDARD ISO 8102-6:2019(E)
Electrical requirements for lifts, escalators and moving
walks —
Part 6:
Programmable electronic systems in safety-related
applications for escalators and moving walks (PESSRAE)
1 Scope
1.1 This document is applicable to the product family of escalators and moving walks used in
residential buildings, offices, hospitals, hotels, industrial plants, etc. This document covers those aspects
that need to be addressed when programmable electronic systems are used to carry out electric safety
functions for escalators and moving walks (PESSRAE). This document is applicable for escalator and
moving walk safety functions that are identified in escalator and moving walk codes, standards, or laws
that reference this document for PESSRAE application. The safety integrity levels (SILs) specified in this
document are understood to be valid for PESSRAE application in the context of the referenced escalator
and moving walk codes, standards, and laws in the Bibliography.
1.2 This document is also applicable for the application of PESSRAE that are new or deviate from those
described in this document.
1.3 The requirements of this document regarding electrical safety/protective devices are such that it is
not necessary to take into consideration the possibility of a failure of an electric safety/protective device
complying with all the requirements of this document and other relevant standards.
This document:
a) uses safety integrity levels (SIL) for specifying the target failure rate for the safety functions to be
implemented by the PESSRAE;
b) specifies the requirements for achieving safety integrity for a function but does not specify who is
responsible for implementing and maintaining the requirements (for example, designers, suppliers,
owner/operating company, contractor); this responsibility is assigned to different parties according
to safety planning and national regulations;
c) applies to PE systems used in escalator and moving walk applications that meet the minimum
requirements of a recognized escalator and moving walk standards, such as EN 115, ASME A17.1/
CSA B44 or The Japan Building Standard Law Enforcement Order For Elevator and Escalator;
d) defines the relationship between this document and IEC 61508 and defines the relationship
between this document and ISO 22200;
e) outlines the relationship between escalator and moving walk safety functions and their safe-state
conditions;
f) applies to phases and activities that are specific to design of hardware and software but not the
phases and activities which occur post design, for example sourcing and manufacturing;
h) provides requirements relating to the hardware and software safety validation;
i) establishes the safety integrity levels for specific escalator and moving walk safety functions;
j) specifies techniques/measures required for achieving the specified safety integrity levels;
k) defines a maximum level of performance (SIL 3) which can be achieved for a PESSRAE according to
this document and defines a minimum level of performance (SIL 1).
1.4 This document does not cover:
a) hazards arising from the PE systems equipment itself such as electric shock etc.;
b) the concept of fail-safe that can be of value when the failure modes are well defined and the level of
complexity is relatively low. The concept of fail-safe was considered inappropriate because of the
full range of complexity of PESSRAE that are within the scope of this document;
c) other relevant requirements necessary for the complete application of a PESSRAE in an escalator
and moving walk safety function, such as system integration specifications, temperature and
humidity, the mechanical construction, mounting and labelling of switches, actuators, or sensors
that contain PESSRAE.
d) foreseeable misuse involving security threats related to malevolent or unauthorized action. This
document can be used in cases where a security threat analysis needs to be considered, provided
that the specified SIL has been reassessed.
2 Normative references
The following documents are referred to in the text in such a way that some or all of their content
constitutes requirements of this document. For dated references, only the edition cited applies. For
undated references, the latest edition of the referenced document (including any amendments) applies.
IEC 61508-1:2010, Functional safety of electrical/electronic/programmable electronic safety-related
systems — Part 1: General Requirements
IEC 61508-2, Functional safety of electrical/electronic/programmable electronic safety-related systems —
Part 2: Requirements for electrical/electronic/programmable electronic safety-related systems
IEC 61508-3, Functional safety of electrical/electronic/programmable electronic safety-related systems —
Part 3: Software requirements
IEC 61508-4, Functional safety of electrical/electronic/programmable electronic safety-related systems —
Part 4: Definitions and abbreviations
IEC 61508-5, Functional safety of electrical/electronic/programmable electronic safety-related systems —
Part 5: Example of methods for the determination of Safety Integrity Levels
ISO 22200, Electromagnetic compatibility — Product family standard for lifts, escalators and moving
walks — Immunity
IEC 62061, Safety of machinery — Functional safety of safety-related electrical, electronic and
programmable electronic control systems
3 Terms and definitions
For the purposes of this document, the terms and definitions given in IEC 61508-4 and the following apply.
ISO and IEC maintain terminological databases for use in standardization at the following addresses:
— ISO Online browsing platform: available at https: //www .iso .org/obp
— IEC Electropedia: available at http: //www .electropedia .org/
2 © ISO 2019 – All rights reserved
3.1
non-SIL relevant safe-state requirement
required response to the actuation of a SIL rated safety function where the function performing this
response is not required to be SIL-rated
Note 1 to entry: See Figure 4 and Table 2.
3.2
programmable electronic
PE
based on computer technology which can be composed of hardware, software, and of input and/or
output units
Note 1 to entry: This term covers microelectronic devices based on one or more central processing units (CPUs)
together with associated memories, etc.
EXAMPLE The following are all programmable electronic devices:
— microprocessors;
— micro-controllers;
— programmable controllers;
— field programmable gate array (FPGA);
— application specific integrated circuits (ASICs);
— programmable logic controllers (PLCs);
— other computer-based devices (for example smart sensors, transmitters, actuators).
3.3
programmable electronic system
PE system
system for control, protection or monitoring based on one or more programmable electronic devices,
including all elements of the system such as power supplies, sensors and other input devices, data
highways and other communication paths, and actuators and other output devices
Note 1 to entry: See Figure 1.
Note 2 to entry: A PE systems may perform functions that fulfil requirements for SIL-rated and non-SIL–rated
function(s). The SIL rating of a function is only required to consider that portion of PE systems that perform the
SIL relevant functional requirements.
Note 3 to entry: The programmable electronics are shown centrally located but can exist at several places in the
PE systems.
Figure 1 — Basic PE systems structure
3.4
programmable electronic systems in safety-related applications for escalators and moving walks
PESSRAE
application of a software-based PE systems in a safety-related system for escalators and moving walks
4.5
proof test
periodic test performed to detect dangerous hidden failures in a safety-related system so that, if
necessary, a repair can restore the system to an “as new” condition or as close as practical to this
condition
Note 1 to entry: In this document, the term “proof test” is used but it is recognized that a synonymous term is
“periodical test”.
Note 2 to entry: The effectiveness of the proof test is dependent both on failure coverage and repair effectiveness.
In practice, detecting 100 % of the hidden dangerous failures is not easily achieved for other than low-complexity
E/E/PE safety-related systems. This should be the target. As a minimum, all the safety functions which are
executed are checked according to the E/E/PE system safety requirements specification. If separate channels are
used, these tests are done for each channel separately. For complex elements, it can be necessary to perform an
analysis in order to demonstrate that the probability of hidden dangerous failure not detected by proof tests is
negligible over the whole life duration of the E/E/PE safety-related system.
Note 3 to entry: A proof test needs some time to be achieved. During this time, the E/E/PE safety-related system
may be inhibited partially or completely. The proof test duration can be neglected only if the part of the E/E/PE
safety-related system under test remains available in case of a demand for operation or if the EUC is shut down
during the test.
Note 4 to entry: During a proof test, the E/E/PE safety-related system may be partly or completely unavailable to
respond to a demand for operation. The MTTR can be neglected for SIL calculations only if the EUC is shut down
during repair or if other risk measures are put in place with equivalent effectiveness.
Note 5 to entry: A repair (including replacement) can be considered restoring the system to "as new”.
3.6
safety circuit
total combination of safety devices that fulfil all or a group of escalator and moving walk safety
functions
Note 1 to entry: See Figure 2
4 © ISO 2019 – All rights reserved
Figure 2 — Safety circuit
3.7
safety device
part of the safety-related system, including necessary control circuits, that has been designated to
achieve, in its own right, an escalator and moving walk safety function and can consist of PE system
elements and non-PE system elements
Note 1 to entry: See Figure 3 and Table 1.
Figure 3 — Safety device
3.8
safety function
function to be implemented by a safety-related system, which is intended to achieve or maintain a safe-
state of the escalator and moving walk, with respect to a specific hazardous event
Note 1 to entry: See Table 1.
Note 2 to entry: A safety function may include non-SIL relevant requirements, see Table 2.
3.9
safety-related system
system which consists of one or more safety devices performing one or more safety functions that can
be based on programmable electronic (PE), electrical, electronic and/or mechanical elements of the
escalator and moving walk
Note 1 to entry: The term includes all the hardware, software and supporting services (for example, power
supplies) necessary to carry out the specified safety function [sensors, other input devices, final elements
(actuators) and other output devices are therefore included in the safety-related system].
3.10
safety integrity level
SIL
discrete level for specifying the safety integrity requirements of the safety functions to be allocated to
the programmable electronic safety-related system
Note 1 to entry: There are four SIL: safety integrity level 4 has the highest level of safety integrity and safety
integrity level 1 has the lowest.
Note 2 to entry: In the context of this document, SIL 3 is the highest safety integrity level that is applied to
escalators and moving walks.
Note 3 to entry: The SIL is indicative of a failure rate that includes all causes of failures (both random hardware
failures and systematic failures), which lead to an unsafe state, for example hardware failures, software induced
failures and failures due to electrical interference
3.11
SIL relevant safe-state requirement
part of the safety-related system where it is required to meet the specified SIL of the function
Note 1 to entry: See Figure 4 and Table 2.
Figure 4 — Escalator and moving walk safety function
3.12
system reaction time
sum of the following two values:
a) the time period between the occurrence of a fault in the PESSRAE and the initiation of the
corresponding action on the escalator and moving walk;
b) the time period for the escalator and moving walk to respond to the action, maintaining a safe state.
4 Requirements
4.1 General
4.1.1 Table 1 defines the safety function names, the associated escalator and moving walk functional
description, applicable escalator and moving walk type and required SIL for the SIL relevant part of the
safety function.
NOTE Safety functions refer to the escalator and moving walk functions that are identified in codes
standards and laws that reference this document for PESSRAE application.
6 © ISO 2019 – All rights reserved
4.1.2 Table 2 defines the safe-state requirements when the safety functions in Table 1 are actuated. If a
safety function actuates, the safety function shall cause the escalator and moving walk system to revert to
the safe-state conditions specified by the requirements of Table 2.
4.1.3 PESSRAE shall consider the reaction time of the escalator and moving walk to respond to the
safety function and internal fault detection in the necessary time to achieve the safe-state condition
without hazard. Methods that fulfil internal fault detection shall consider the necessary system reaction
time required by the SIL.
NOTE For example, if an internal fault is detected by comparison of data in
...
記事のタイトル:ISO 8102-6:2019 - エレベータ、エスカレータおよび動く歩道に対する電気要件 - 第6部:エスカレータおよび動く歩道用安全関連アプリケーションのプログラマブル電子システム(PESSRAE) 記事の内容:この文書は、住宅、オフィス、病院、ホテル、工場などで使用されるエスカレータおよび動く歩道の製品群に適用されます。この文書は、エスカレータおよび動く歩道の電気安全機能を実現するためにプログラム可能な電子システムが使用される場合に必要な側面をカバーしています(PESSRAE)。この文書は、PESSRAEの適用が参照するエスカレータおよび動く歩道のコード、規格、あるいは法律で識別されるエスカレータおよび動く歩道の安全機能に適用されます。この文書で指定される安全性完全度(SIL)は、参考文献におけるエスカレータおよび動く歩道のコード、規格、および法律の文脈でPESSRAEの適用に有効であると理解されます。また、この文書は、この文書で説明されていない新しいPESSRAEの適用または変更にも適用されます。この文書の要件に関しては、電気安全/保護装置についての考慮は必要ありません。この文書は、PESSRAEによって実装される安全機能の目標故障率を指定するために安全性完全度(SIL)を使用します。また、要件を実装および維持する責任者を指定しません(例:設計者、サプライヤー、所有者/運営会社、請負業者)。この責任は、安全計画と国内規制に応じて異なる関係者に割り当てられます。また、EN 115、ASME A17.1/CSA B44、または日本建築基準法執行令(エレベータおよびエスカレータ用)など、承認されたエスカレータおよび動く歩道の規格の最小要件を満たすエスカレータおよび動く歩道の応用に適用されます。この文書はIEC 61508およびISO 22200との関係を定義し、エスカレータおよび動く歩道の安全機能とその安全な状態条件の関係を概説します。また、ハードウェアおよびソフトウェアの安全性検証に関する要件を提供し、特定のエスカレータおよび動く歩道の安全機能の安全性完全度を確立します。この文書は、PEシステム機器そのものから生じる危険、フェールセーフ概念、PESSRAEの完全な適用に必要なその他の関連要件、および不正行為に関連するセキュリティ脅威には言及していません。ただし、指定されたSILが再評価された場合には、セキュリティ脅威分析が考慮される必要がある場合にはこの文書を使用できます。
The article discusses ISO 8102-6:2019, which is a standard for programmable electronic systems in safety-related applications for escalators and moving walks (PESSRAE). The document applies to escalators and moving walks used in various settings such as residential buildings, offices, hospitals, hotels, and industrial plants. It covers the use of programmable electronic systems to carry out electric safety functions for escalators and moving walks. The standard specifies safety integrity levels (SILs) for PESSRAE application and outlines the relationship between escalator and moving walk safety functions and their safe-state conditions. It also provides requirements for hardware and software safety validation and establishes the maximum and minimum levels of performance (SIL 3 and SIL 1 respectively) that can be achieved for a PESSRAE. The standard does not cover hazards arising from the PE systems equipment itself, the concept of fail-safe, additional requirements for the complete application of a PESSRAE, or security threats related to malevolent or unauthorized action.
기사 제목: ISO 8102-6:2019 - 엘리베이터, 에스컬레이터 및 모빌리프트에 대한 전기 요구 사항 - 제 6 부: 에스컬레이터 및 모빌리프트용 안전 관련 응용 프로그래밍 전자 시스템 (PESSRAE) 기사 내용: 이 문서는 주거 건물, 사무실, 병원, 호텔, 공장 등에 사용되는 에스컬레이터 및 모빌리프트 제품군에 적용됩니다. 이 문서는 에스컬레이터 및 모빌리프트의 전기 안전 기능을 수행하기 위해 프로그래밍 가능한 전자 시스템이 사용될 때 고려해야 할 측면을 다룹니다(PESRRAE). 이 문서는 PESSRAE 응용에 참조되는 에스컬레이터 및 모빌리프트 코드, 표준 또는 법률에서 식별된 에스컬레이터 및 모빌리프트 안전 기능에 적용됩니다. 이 문서에서 지정된 안전 무결성 수준(SIL)은 참고 문헌의 에스컬레이터 및 모빌리프트 코드, 표준 및 법률의 맥락에서 PESSRAE 응용에 유효한 것으로 이해됩니다. 또한, 이 문서는 이 문서에서 설명되지 않은 새로운 PESSRAE 적용이나 변형에도 적용됩니다. 이 문서는 전기 안전/보호 장치에 대한 요구 사항은 이 문서와 관련 표준의 모든 요구 사항을 준수하는 전기 안전/보호 장치의 고장 가능성을 고려하지 않아도 된다는 점에서 요구사항을 제시합니다. 이 문서는 다음을 포함합니다: a) PESSRAE에서 구현할 안전 기능의 대상 고장률을 지정하기 위해 안전 무결성 수준(SIL)을 사용합니다. b) 안전 요구 사항을 달성하기 위한 책임자를 지정하지 않습니다(예: 설계자, 공급자, 소유자/운영 회사, 계약자). 안전 계획 및 국가 규정에 따라 이 책임은 다른 당사자에게 할당됩니다. c) EN 115, ASME A17.1/CSA B44, 또는 일본 건설 기준법 시행령과 같은 인정받은 에스컬레이터 및 모빌리프트 표준의 최소 요구 사항을 충족하는 에스컬레이터 및 모빌리프트 응용에 사용되는 PE 시스템에 적용됩니다. d) 이 문서와 IEC 61508, ISO 22200 간의 관계를 정의합니다. e) 안전 기능과 그들의 안전한 상태 조건 간의 관계를 개요합니다. f) 하드웨어 및 소프트웨어 설계를 위한 특정 단계 및 활동에 적용되지만, 예를 들어 소싱 및 제조와 같은 설계 이후 단계 및 활동은 적용되지 않습니다. h) 하드웨어 및 소프트웨어 안전 검증에 대한 요구 사항을 제공합니다. i) 특정 에스컬레이터 및 모빌리프트 안전 기능의 안전 무결성 수준을 설정합니다. j) 지정된 안전 무결성 수준을 달성하기 위해 필요한 기술/조치를 지정합니다. k) 이 문서에 따라 PESSRAE에 대해 달성할 수 있는 최대 수준(SIL 3)과 최소 수준(SIL 1)을 정의합니다. 이 문서는 다음을 다루지 않습니다: a) PE 시스템 장비 자체로 인해 발생하는 위험(전기 감전 등). b) 잘 정의된 실패 모드 및 상대적으로 낮은 복잡도 수준에서 가치가 있는 실패 안전 개념. 이 문서 범위 내의 다양한 PESSRAE의 복잡성에 대해 실패 안전 개념은 부적절하다고 여겨졌습니다. c) 에스컬레이터 및 모빌리프트 안전 기능에 PESSRAE를 완벽하게 적용하기 위해 필요한 기타 관련 요구 사항, 예를 들어 시스템 통합 사양, 온도 및 습도, 스위치, 액추에이터 또는 PESSRAE를 포함하는 센서의 기계적 구조, 부착 및 라벨링. d) 남남한 또는 무단의 행위와 관련된 안보 위협을 포함한 예견 가능한 오용. 지정된 SIL이 재평가된 경우, 이 문서는 보안 위협 분석이 고려되어야 할 경우 사용될 수 있습니다.










Questions, Comments and Discussion
Ask us and Technical Secretary will try to provide an answer. You can facilitate discussion about the standard in here.
Loading comments...