Welcome to the Industrial Automation website!

NameDescriptionContent
XING-Automation
E-mail  
Password  
  
Forgot password?
  Register
当前位置:

Deep Analysis of HIMA HIMax Safety Control System: Architecture, Redundancy, and Engineering Application Guidelines

F: | Au:FAN | DA:2026-01-13 | 438 Br: | 🔊 点击朗读正文 ❚❚ | Share:

Deep Analysis of HIMA HIMax Safety Control System: Architecture, Redundancy, and Engineering Application Guidelines

1.Introduction: Overview of HIMax System

HIMax is a safety related control system designed by HIMA for continuous operation and maximum availability. As a highly modular system, HIMax distributes processing, input/output (I/O), and communication functions in pluggable modules installed on one or more baseboards. By connecting the motherboard through Ethernet cables, the system has strong scalability and can easily adapt to the expansion needs of future process flows.

This system not only complies with the IEC 61508 SIL 3 standard, but also supports multiple configuration modes from single machine non redundant to highly redundant, making it an ideal choice for critical safety tasks in the fields of process automation and factory automation.


2. Hardware architecture and system bus

2.1 Modular Base Plate Design

The core physical foundation of HIMax is the baseboard, which provides various types of baseboards according to the number of slots to meet different installation requirements:

10 slots (X-BASE PLATE 10 01): suitable for flat base installation.

15 slots (X-BASE PLATE 15 01/02): suitable for backplane installation or 19 inch cabinet installation.

18 slots (X-BASE PLATE 18 01): Suitable for backplane installation, providing maximum density.

Each slot can accommodate one module and one connection board. The slots 1 and 2 on the left side of the motherboard are reserved for the system bus module, while the remaining slots are used for processors, I/O, or communication modules.

2.2 Redundant System Bus

The HIMax system operates on two redundant system buses: System Bus A and System Bus B.

Communication mechanism: The module is inserted into the motherboard and connected to the system bus. If both buses are running, communication will occur simultaneously on both buses.

Scalability: The system bus is based on Ethernet technology, allowing the system to span vast production lines. When using fiber optic components, the maximum extension distance of the HIMax system can reach 19.6 kilometers.

Isolation: The system bus connection between the module and the motherboard is electrically isolated, ensuring at least 1500 V insulation voltage between the processor module and each I/O module.


3. Safety standards and operating principles

3.1 Safety Integrity Level (SIL)

HIMax safety related controllers are certified for the following high standard applications:

SIL 3 (compliant with IEC 61508)

Category 4 (compliant with EN 954-1)

PL e (compliant with ISO 13849-1)

3.2 Operating Principles

The system design follows the following core security principles:

Loss of excitation trip: The system design conforms to the principle of "loss of excitation trip", which means that no electricity is required to perform safety functions. Once a malfunction occurs, the input and output signals will enter a disabled safe state.

Power on trip: HIMax can also be used for "power on trip" applications (such as fire alarm systems), but it must meet the corresponding application standards (such as line diagnosis).

Fault tolerance time (FTT): When implementing safety related communication, it is necessary to ensure that the overall response time does not exceed the fault tolerance time.

4. High availability: comprehensive redundancy design

The conceptual design of HIMax is centered around high availability. Redundancy is only used to improve availability, not to increase SIL level.

4.1 Redundancy of processor modules

The system can be configured as a standalone system or a highly available system (supporting up to 4 redundant processor modules).

Downgrading and upgrading: Even if a processor module fails or is removed, the system can continue to operate safely. When adding a new processor module during operation, it will automatically synchronize with the existing module without interrupting security related operations.

4.2 I/O module and channel redundancy

Module redundancy: Two or three I/O modules of the same type can be defined as mutually redundant.

Channel redundancy: Channels with the same number can be defined as redundant. For input channels, users can specify how the controller combines signals from two redundant channels (such as 2oo3 voting).

Connection board: In order to save wiring workload, a special connection board allows two redundant modules to be inserted into adjacent slots, while on-site connections only need to be created once.


5. Engineering and Programming: Based on SILworX

The user program is created through a programming system (PADT) consisting of a PC with SILworX tool installed.

5.1 Multi task processing

HIMax supports processing up to 32 user programs simultaneously within the processor module.

Multi tasking mode:

Mode 1: Utilize unused execution time to reduce CPU cycle time (fastest response).

Mode 2: Allocate unused time from low priority programs to high priority programs (high availability mode).

Mode 3: Wait for unused time to expire in order to maintain a fixed CPU cycle time (constant cycle).

5.2 Variables and System Parameters

Variable types: Supports local variables (VAR) and global variables (VAR_GLOBAL). Global variables allow data exchange between program organizational units (POUs).

  • UniOP eTOP40C-0050 - Color Touch Screen HMI
  • UniOP ETOP03-0046 - Operator Interface Panel
  • UniOp eTOP30 - Graphic Display HMI
  • UniOP ETOP307-U301 - Industrial Touch Terminal
  • UniOP eTOP507 - Operator Panel HMI
  • UniOP eTOP05-0045 - HMI Touch Screen Panel
  • UniOP eTOP05-0045 - HMI Touch Screen Panel
  • GRUNDIG NEA02 AES 0 PLC Card
  • Siemens 6ES7215-1AG40-0XB0 CPU 1215C
  • Power-One LKP 5744-9ER Converter
  • Merlin Gerin STR 58U Masterpact Trip Unit
  • Siemens G26004-A2105-P100-2 PCB
  • Siemens 6ES7 405-0RA02-0AA0 Power Supply
  • PILZ 312070 PSSu H PLC1 FS SN SD
  • Siemens 3RV2031-4WA10 Motor Switch
  • GE Fanuc IC693CBK001 PLC Module
  • Siemens 6FX2007-1AD03 MINI-BHG
  • Mitsubishi MELSEC A2ASCPU PLC System
  • PC PMC25.2-002 PLC Module
  • B&R X20CP1382 Programmable Controller
  • Siemens C98043-A7002-L4 PC Board
  • Fanuc A16B-3300-0057 PCB Board
  • Schneider LV430403 Circuit Breaker TM160D
  • ABB CI810B 3BSE020520R1 PLC Interface
  • Omron R88D-HT10 Servo Drive
  • Omron CS1G-CPU43H CPU Unit
  • Mitsubishi QD70D4 Positioning Module
  • Siemens 6FC5110-0BB04-0AA1 Sinumerik 840C CPU
  • Siemens 3RT5045-1AC20 SIRIUS Contactor 75kW
  • Siemens 3VA2340-5HL32-0AA0 Circuit Breaker 400A
  • ABB HBS01-CJC I/O MTUS SD Series Module
  • Eberle MT42 Complete PLC Rack PLS514
  • Siemens C8451-A201-A9 PLC Card Slot Backplane
  • Cherokee ACX643 REV-B Power Supply Unit 100-240VAC
  • Schneider SSD1A320BDC1 Solid State Relay 20A
  • GE Fanuc IC694APU300 High Speed Counter Module
  • Schneider 140DA175300 Analog Output Module
  • Allen Bradley 1794-OA8I FLEX 8-Point Digital Output Module
  • Phoenix Contact PLC-BPT-24DC/1/SEN Solid State Relay Module
  • Schneider IG2000PG2 PLC Module Industrial Controller Card
  • Mitsubishi LE-40MTA-E Tension Controller Web Handling Control
  • Siemens 6FX1122-1AC02 PLC Card Industrial Interface Module
  • ABB AF210-30-11 Contactor Coil Voltage 110-240VAC
  • Mitsubishi GT2508-VTBD GT2508-VTBA HMI Touch Screen Panel
  • BPT 67200020 Touch Screen PLC Display Multifunction Terminal 50Hz
  • NORIS A1-91 PCB Rack Module A1-91-4 A1-91-5 A1-91-6 A1-91-7
  • Mitsubishi A1S61PN Power Supply Unit AnS Series 5VDC 5A
  • Pilz 312070AA PSSU H PLC1 FS SN SD Safety Module
  • Pasaban MTC-3044 PLC Rack with Power Supply Card
  • Schneider METSEPM8243 Power Meter PM800
  • Fanuc A16B-1212-0100-01 Power Supply Unit
  • Honeywell DPCB21010002 PCB IRTP-161 REV A
  • Siemens 6ES7315-2AH14-0AB0 CPU 315-2 DP
  • Omron GRT1-DA2V Analog Output Module 2 Channels
  • Mitsubishi FX3U-128MT/ESS PLC CPU Module
  • Schneider SSP05EMA12 Soft Starter Altistart 22
  • Mushroom 787602 Push Button Head 40mm
  • Hydraulik Elektronik EPM8900 91221 Proportional Module
  • ABB XZ C828 A101 Didt Dioder Snubber 3BHE039453R0101
  • ABB 3BHE032593R0001 Isolated Power Supply
  • ABB 3BHB02722R0001 single-phase charging transformer
  • ABB 3BHE006412R0101 UFC762AE101 main control board
  • ABB XVC770BE101 3BHE021083R0101 interface board
  • ABB 3BHE024747R0101 GD C801 Overvoltage Protection Motherboard
  • ABB 3BHE021887R0101 3BHB002751R0102 Variable Frequency Control Board
  • ABB SD812 power module 3BSC610023R0001
  • Automotive LC4A00010 Brushless Motor Controller
  • Doric NC500 Neuroscience Data Acquisition System
  • Honeywell X-DCS2000/EN Broadcast Manager
  • Kollmorgen S60600 servo drive 6A 480V
  • Honeywell 30751044-008 ROM Card
  • Honeywell 5SE1-12 Micro Switch Specifications
  • Schneider AS-BDAU-204 Analog Output Module
  • K93712 Expansion Kit Industrial Module
  • MGE DCHEN 3400116300 Circuit Board
  • Siemens 6SE7036-1EE85-1HA0 Rectifier Board
  • Renesas UPD70F3624GBA1 Microcontroller
  • Omron E5AC-CX4A5M-014 Temperature Controller Parameters
  • GE IS200TBCIH1BCE Contact Input Board
  • Fanuc A05B-2255-C101#EAW Teach Pendant Data
  • Rieter RMC186C RMC RIO-1 PLC Controller
  • Siemens PXC24.2-EF32.A Building Automation Controller
  • Fanuc A16B-1200-0220 PC Memory Board F3
  • Omron CJ2M-CPU33 PLC CPU Module
  • Beckhoff EL1918 Safety Input Terminal EtherCAT
  • Fanuc A16B-1212-0871 CNC PCB Board
  • GE Fanuc IC697BEM713J PLC Module
  • Mitsubishi A2ACPU-R21 PLC CPU Module
  • Programmable Relay 230V AC 16 Inputs 8 Outputs T2UK
  • Schneider F3SP71-4S Safety PLC Module
  • NEED-24DC- T2UK Programmable Relay 24V 16in 8out
  • Siemens 3RT1075-6SP36 SIRIUS Power Contactor 200kW
  • GE 1C31170G02 Printed Circuit Board Module 94V-0
  • BPT 67200020 Multifunction Touch Terminal 50Hz
  • Fanuc A16B-2200-0931 Option Board with Daughter Cards
  • Honeywell FC-SDOL-0424 I/O Module Board
  • Lenze EMF2179IB DeviceNet Communication Module
  • Yaskawa CIMR-JC4A0007BAA J1000 VFD 0.4kW
  • Yokogawa PSBCMNBN Bus Continuation Module ProSafe-PLC
  • Phoenix Contact PLC-BPT-24DC/1/SEN Solid-State Relay
  • Allen-Bradley 193-EC2AB E3 Plus Overload Relay
  • GE DS200TCTGG1AFF Turbine Control Board
  • Westinghouse 1C31170G02 Ovation Module
  • Mitsubishi A2ACPU21 Programmable Controller Review
  • 710-95045-AD PLC I/O Operation Console Cable
  • Allen-Bradley 1785-L11B PLC-5 Processor Specifications
  • BEMAC UST-202-D 1307D V08B2 Circuit Board
  • Pilz 312070 PSSu H PLC1 FS Safety Module
  • Keyence QS-MB1 Safety Network Module Overview
  • GE Fanuc IC693CPU372 CPU Module 90-30 Series
  • Mitsubishi RJ71EIP91 EtherNet/IP Module
  • Schneider LXM62DD27D21000 Lexium 62 Servo Drive
  • Mitsubishi Q13UDEHCPU Universal PLC CPU Module
  • B&R X20CP3585 Programmable Controller X20 CPU
  • Siemens 6FC5203-0AF02-0AA0 Sinumerik Operator Panel
  • IWKA PG02 VKR TEL-Z Self-Sufficient Measuring System
  • Schneider BMXCPS2010 PLC Power Supply Modicon M340
  • Mitsubishi A171SCPU Motion Servo CPU Specifications
  • PLC Board with Finder 44.52 Relay Module 6A 250V
  • Honeywell DOP 09436601 Measurex Module Data
  • Fanuc A20B-8101-0320 CNC Circuit Board
  • KUAX 680I V.24 PLC Module 68142304
  • Allen Bradley 1785-L30B PLC 5/30 Processor
  • Phoenix ILC 191 ETH 2TX 2700976 Ethernet Controller
  • Siemens 6SY7000-0AC80 PLC Power Supply Module
  • Reliance Electric MACS 804.46.20 CWW PLC Drive
  • Omron CP1E-N60DR-D PLC CPU 36 Input 24 Output
  • Mitsubishi Melsec PLC System A2ACPU A63P AY13E AX82