实验室1 上海沙格 实验室2 实验室3 实验室4 合肥沙格 合肥CMA 合肥CNAS 合肥IAS
微信咨询 微信二维码
联系方式
13248198029(甘先生)
17755604650(罗先生)

基本性能怎么定义才能通过 EMC 评价

基本性能怎么定义才能通过 EMC 评价

结论:基本性能定义的是「什么不能丢」,它决定抗扰度怎么判

抗扰度测试的逻辑是:施加规定的干扰,看设备是否仍然正常。「正常」的标准就是基本性能。

所以基本性能定义得好不好,直接决定了测试能不能做、判定有没有意义。

定义得过宽(把所有功能都算基本性能),很多产品无法通过,而实际上某些功能的短暂中断并不造成风险;定义得过窄(只留最核心的一项),可能遗漏了真正与安全相关的功能。

合理的定义应当基于风险 ——哪些功能的丧失或降级会导致不可接受的风险,那些就是基本性能。

定义的思路

第一步,列出设备的所有功能。 包括主功能、辅助功能、显示、报警、通信、数据记录。

第二步,对每项功能问: 如果这项功能在干扰下失效或降级,会发生什么?对使用者有什么后果?

第三步,判断后果的可接受性。 后果不可接受的,该功能属于基本性能。

第四步,确定降级的容许程度。 不是所有基本性能都要求完全不受影响,有些允许一定程度的降级或短暂中断,关键是说清楚界限。

第五步,写成可判定的准则。

第二步是核心。 这个分析与风险分析是同一件事,所以基本性能的定义应当与风险管理文件一致。

判定准则的写法

判定准则要能在测试现场直接判断,所以应当具体:

不好的写法: 「设备工作正常」「性能不降低」「无异常」。这些表述在现场无法判断。

较好的写法: 具体到可观察、可测量的现象。比如:输出参数的偏差不超过某个范围;报警功能仍然触发;显示的数值与实际值的偏差在某个范围内;控制指令仍然被正确执行;停止功能仍然有效。

要说清楚的几点:

允许的偏差范围是多少;允许中断多久;中断后是否要求自动恢复;恢复需要多长时间;干扰期间是否允许报警(报警本身可能是可接受的响应);以及需要人工干预才能恢复算不算通过。

「需要人工干预才能恢复」这一条要特别明确。 有些情况下这是可以接受的(比如设备安全停止并提示重启),有些情况下不可接受(比如使用者无法自行操作的设备)。

常见的定义问题

定义过宽。 把所有功能都列为基本性能,导致轻微的显示闪烁也判为失效。

定义过窄。 遗漏了与安全相关的功能,比如报警。

准则不可判定。 前面说的笼统表述。

未考虑降级模式。 只有「正常」和「失效」两种状态,没有中间的降级状态。

与风险文件不一致。 风险文件说某功能关键,基本性能定义里却没有。

未考虑组合影响。 多项功能同时轻微降级的综合影响。

「未考虑降级模式」在复杂设备上影响较大。 现代设备很少是非黑即白的,常见的是性能下降、响应变慢、精度降低。这些中间状态应当有明确的判定界限。

与风险管理的关系

基本性能的定义应当来自风险分析,两者的关系是:

风险分析识别危害。 哪些功能失效会导致危害。

基本性能对应风险控制。 保证这些功能在干扰下仍然有效,就是风险控制措施。

抗扰度测试验证控制措施。 测试结果是控制措施有效性的证据。

测试中发现的问题反馈到风险文件。 如果测试中发现某个未预期的失效模式,风险分析应当更新。

建议把基本性能的定义直接写进风险管理文件,或者至少在两者之间建立明确的引用关系。分开写容易不一致,而审查时会核对。

监测方法的准备

定义了基本性能,还要能在测试中监测它:

监测什么。 对应基本性能的具体参数或现象。

怎么监测。 目视、仪器测量、软件输出、视频记录。

监测设备的抗扰度。 监测设备本身在干扰环境中要能正常工作,否则分不清是被测设备异常还是监测设备异常。

记录方式。 干扰施加过程中的连续记录,便于事后分析。

「监测设备本身的抗扰度」是容易出问题的地方。 如果监测用的电脑或仪器也受干扰,测试就无法进行。通常的做法是把监测设备放在干扰场之外,用光纤或屏蔽线连接。

设计阶段的考虑

基本性能的概念在设计阶段就有用:

识别关键功能。 知道哪些功能必须在干扰下保持,设计时就可以有针对性地加强。

设计降级策略。 允许哪些功能降级、怎么降级、如何提示使用者。

设计恢复机制。 干扰消失后如何自动恢复。

设计告知机制。 功能降级时如何让使用者知道。

「告知机制」值得强调。 设备在干扰下降级但不告知使用者,使用者可能继续按正常状态使用,风险反而更大。降级但有明确提示,通常比静默降级安全。

不同类型产品的例子

把几类产品的基本性能大致列一下,作为参考:

产品类型 可能的基本性能
电动轮椅 按指令行驶、停止功能、不发生意外启动
监护类设备 参数测量精度、报警功能
治疗类设备 输出参数准确、超限保护、紧急停止
训练设备 阻力控制、急停、防止意外动作
护理床 按指令动作、不发生意外动作、停止功能

注意「不发生意外启动/动作」这类否定性的表述。 它不是要求某功能保持,而是要求某现象不出现。这类基本性能同样重要,而且容易被遗漏 ——定义时容易只想到「要保持什么」,忘了「不能出现什么」。

对于带运动功能的设备,意外动作往往是风险更大的失效模式,因为它可能直接造成伤害,而功能中断通常只是不便。

定义的复核

基本性能的定义不是定了就不变:

产品功能扩展时。 新增功能是否属于基本性能。

使用场景扩展时。 新场景下的风险可能不同。

风险分析更新时。 两者应当同步。

测试中发现新的失效模式时。 更新定义并评估。

建议把基本性能的复核纳入变更评审的固定项。

我们的做法

承接抗扰度测试前,我们会与委托方一起确认基本性能的定义和判定准则,并把准则写成现场可判断的形式。 如果委托方给的准则是「工作正常」这类表述,我们会请其具体化。

监测方面,我们会提前确认监测方法和所需的辅助工具。准备不足会导致测试过程中无法判断,只能中断重来。

如果你在准备抗扰度测试,不确定基本性能怎么定义、准则怎么写,可以把设备功能和风险分析发过来一起讨论,或者直接联系:132 4819 8029。能力范围见服务介绍,送检要求见送检要求,其他问题见常见问题。

English version

Conclusion. Immunity testing works by applying specified disturbances and observing whether the equipment still functions correctly. The standard for correctly is essential performance. How well essential performance is defined therefore determines directly whether the test can be conducted and whether the verdict means anything. Defined too broadly, treating every function as essential, many products cannot pass, when in fact brief interruption of some functions creates no risk. Defined too narrowly, retaining only the single core function, genuinely safety-related functions may be omitted. A sound definition rests on risk: the functions whose loss or degradation would produce unacceptable risk are the essential ones.

How to define it. List every function of the equipment, covering primary and auxiliary functions, display, alarms, communication and data logging. Ask of each function what would happen if it failed or degraded under disturbance, and what the consequence for the user would be. Judge the acceptability of that consequence; where unacceptable, the function is essential performance. Determine the permitted degree of degradation, since not every essential function must be wholly unaffected and some permit limited degradation or brief interruption, the point being to state the boundary. And write it as a testable criterion. The second step is the heart of it, and that analysis is the same exercise as risk analysis, so the definition of essential performance should agree with the risk management file.

Writing acceptance criteria. Criteria must be judgeable at the test site, so they must be specific. Poor wording says that the equipment operates normally, that performance does not degrade, or that nothing abnormal occurs; none of these can be judged in the moment. Better wording reaches observable, measurable phenomena: output parameter deviation within a stated range, the alarm function still triggering, displayed values within a stated deviation of actual values, control commands still executed correctly, the stop function still effective. Several matters must be stated: the permitted deviation, how long interruption is permitted, whether automatic recovery is required, how long recovery may take, whether an alarm during disturbance is acceptable, since alarming may itself be an acceptable response, and whether recovery requiring human intervention counts as a pass. That last point needs particular clarity: in some cases it is acceptable, as when equipment stops safely and prompts a restart, and in others it is not, as with equipment the user cannot operate unaided.

Common definition problems. Defining too broadly, so that a momentary display flicker is judged a failure. Defining too narrowly, omitting safety-related functions such as alarms. Criteria that cannot be judged, as in the vague wording above. Ignoring degraded modes, recognising only normal and failed states with nothing between. Inconsistency with the risk file, where a function described as critical there does not appear in the essential performance definition. And ignoring combined effects, where several functions each degrade slightly. Ignoring degraded modes matters particularly in complex equipment: modern devices are rarely binary, and reduced performance, slower response and lower accuracy are common, so those intermediate states need explicit boundaries.

Relationship to risk management. The definition should come from risk analysis. Risk analysis identifies hazards, meaning which functional failures cause harm. Essential performance corresponds to risk control, since keeping those functions effective under disturbance is the control measure. Immunity testing verifies the control, with results as evidence of effectiveness. And problems found in testing feed back into the risk file, updating the analysis where an unanticipated failure mode appears. Write the essential performance definition into the risk management file, or at minimum establish an explicit cross-reference. Kept separate they drift apart, and reviewers check them against one another.

Preparing monitoring. Having defined essential performance, it must be monitorable during testing. Decide what to monitor, meaning the specific parameters or phenomena corresponding to essential performance. Decide how, whether visually, by instrument, from software output or by video. Consider the monitoring equipment's own immunity, since it must work in the disturbance environment or abnormalities cannot be attributed. And decide how to record, with continuous logging during disturbance to support later analysis. Monitoring equipment immunity is where problems arise: if the monitoring computer or instrument is itself disturbed, testing cannot proceed. The usual approach places monitoring outside the disturbance field, connected by fibre or screened cable.

Considerations during design. The concept is useful at the design stage. Identifying critical functions shows which must be maintained under disturbance so that they can be strengthened specifically. Designing a degradation strategy determines which functions may degrade, how, and how the user is informed. Designing recovery determines how normal operation resumes once disturbance ceases. And designing notification determines how the user learns of degradation. Notification deserves emphasis: equipment that degrades under disturbance without telling the user leaves the user operating as though nothing had changed, which increases risk. Degradation with clear indication is generally safer than silent degradation.

How we handle it. Before immunity testing we agree the essential performance definition and acceptance criteria with the client and put the criteria into a form judgeable at the site. Where a client offers wording such as operates normally, we ask for specifics. On monitoring we confirm the method and the auxiliary tools needed in advance, since inadequate preparation leaves nothing judgeable during testing and the work must be interrupted and repeated.

Send us the equipment functions and risk analysis and we will work through the definition and criteria. Phone or WeChat: +86 132 4819 8029.