Welcome to the Industrial Automation website!

NameDescriptionContent
XING-Automation
E-mail  
Password  
  
Forgot password?
  Register
当前位置:

Deep Analysis of HIMA HIMax Safety Control System: Architecture, Redundancy, and Engineering Application Guidelines

F: | Au:FAN | DA:2026-01-13 | 669 Br: | 🔊 点击朗读正文 ❚❚ | Share:

Deep Analysis of HIMA HIMax Safety Control System: Architecture, Redundancy, and Engineering Application Guidelines

1.Introduction: Overview of HIMax System

HIMax is a safety related control system designed by HIMA for continuous operation and maximum availability. As a highly modular system, HIMax distributes processing, input/output (I/O), and communication functions in pluggable modules installed on one or more baseboards. By connecting the motherboard through Ethernet cables, the system has strong scalability and can easily adapt to the expansion needs of future process flows.

This system not only complies with the IEC 61508 SIL 3 standard, but also supports multiple configuration modes from single machine non redundant to highly redundant, making it an ideal choice for critical safety tasks in the fields of process automation and factory automation.


2. Hardware architecture and system bus

2.1 Modular Base Plate Design

The core physical foundation of HIMax is the baseboard, which provides various types of baseboards according to the number of slots to meet different installation requirements:

10 slots (X-BASE PLATE 10 01): suitable for flat base installation.

15 slots (X-BASE PLATE 15 01/02): suitable for backplane installation or 19 inch cabinet installation.

18 slots (X-BASE PLATE 18 01): Suitable for backplane installation, providing maximum density.

Each slot can accommodate one module and one connection board. The slots 1 and 2 on the left side of the motherboard are reserved for the system bus module, while the remaining slots are used for processors, I/O, or communication modules.

2.2 Redundant System Bus

The HIMax system operates on two redundant system buses: System Bus A and System Bus B.

Communication mechanism: The module is inserted into the motherboard and connected to the system bus. If both buses are running, communication will occur simultaneously on both buses.

Scalability: The system bus is based on Ethernet technology, allowing the system to span vast production lines. When using fiber optic components, the maximum extension distance of the HIMax system can reach 19.6 kilometers.

Isolation: The system bus connection between the module and the motherboard is electrically isolated, ensuring at least 1500 V insulation voltage between the processor module and each I/O module.


3. Safety standards and operating principles

3.1 Safety Integrity Level (SIL)

HIMax safety related controllers are certified for the following high standard applications:

SIL 3 (compliant with IEC 61508)

Category 4 (compliant with EN 954-1)

PL e (compliant with ISO 13849-1)

3.2 Operating Principles

The system design follows the following core security principles:

Loss of excitation trip: The system design conforms to the principle of "loss of excitation trip", which means that no electricity is required to perform safety functions. Once a malfunction occurs, the input and output signals will enter a disabled safe state.

Power on trip: HIMax can also be used for "power on trip" applications (such as fire alarm systems), but it must meet the corresponding application standards (such as line diagnosis).

Fault tolerance time (FTT): When implementing safety related communication, it is necessary to ensure that the overall response time does not exceed the fault tolerance time.

4. High availability: comprehensive redundancy design

The conceptual design of HIMax is centered around high availability. Redundancy is only used to improve availability, not to increase SIL level.

4.1 Redundancy of processor modules

The system can be configured as a standalone system or a highly available system (supporting up to 4 redundant processor modules).

Downgrading and upgrading: Even if a processor module fails or is removed, the system can continue to operate safely. When adding a new processor module during operation, it will automatically synchronize with the existing module without interrupting security related operations.

4.2 I/O module and channel redundancy

Module redundancy: Two or three I/O modules of the same type can be defined as mutually redundant.

Channel redundancy: Channels with the same number can be defined as redundant. For input channels, users can specify how the controller combines signals from two redundant channels (such as 2oo3 voting).

Connection board: In order to save wiring workload, a special connection board allows two redundant modules to be inserted into adjacent slots, while on-site connections only need to be created once.


5. Engineering and Programming: Based on SILworX

The user program is created through a programming system (PADT) consisting of a PC with SILworX tool installed.

5.1 Multi task processing

HIMax supports processing up to 32 user programs simultaneously within the processor module.

Multi tasking mode:

Mode 1: Utilize unused execution time to reduce CPU cycle time (fastest response).

Mode 2: Allocate unused time from low priority programs to high priority programs (high availability mode).

Mode 3: Wait for unused time to expire in order to maintain a fixed CPU cycle time (constant cycle).

5.2 Variables and System Parameters

Variable types: Supports local variables (VAR) and global variables (VAR_GLOBAL). Global variables allow data exchange between program organizational units (POUs).

Initial value: All variables that receive values from physical inputs or communications must be assigned an initial value as a safe value.

5.3 Online modification

Reload: Load modified project configurations without interrupting security related operations. This includes changing user program logic, parameters, etc., provided that the overload conditions are not violated (such as adding new variable assignments that typically require a download).

Forcing: allows replacing the current value of a variable with a forced value, used for testing programs. Attention: Forcing values may result in output errors and prolong cycle time, and must be authorized by the testing agency and used within time limits.

image.png

6. Diagnosis and maintenance

6.1 Diagnosis of LED indicator lights

The LED on the front panel of the module provides a quick overview of the system status:

Module status: RUN (green), ERROR (red), STOP (yellow), Initiat (yellow).

Redundancy status: ESS (yellow, critical module), RED (yellow, running redundantly).

System bus: Display the connection status with buses A and B (green indicates normal, flashing indicates fault).

Maintenance instructions: Force, Test, Prog.

6.2 Diagnostic History Record

Each HIMax module maintains a historical record of faults or events, divided into:

Short term diagnosis: Circular buffer, new entries overwrite old entries.

Long term diagnosis: Store user actions and configuration changes. If the entry exceeds 3 days, the new entry will overwrite the old entry; If it does not exceed 3 days, the new entry will be rejected and marked.

6.3 Temperature Monitoring

The module monitors its own temperature. The state variables display the following range:

Normal:<40 ° C

Threshold 1 exceeds: 40... 60 ° C

Threshold 2 exceeds:>60 ° C


7. Lifecycle Management: Installation and Startup

7.1 Installation and Grounding

Mechanical installation: The base plate is installed in the control cabinet, ensuring sufficient heat dissipation (it is recommended to use a fan bracket).

Grounding (PE): Functional grounding must be implemented for electromagnetic compatibility (EMC). All surfaces of HIMax components (except for pluggable modules) are conductive and must be connected to the cabinet frame through a grounding wire (such as a 16mm ² or 25mm ² yellow green wire).

7.2 Startup Process

Hardware installation: Complete all module and cable connections.

Set IP and SRS: Log in to the system bus module and processor module through SILworX, and set the System. Rack. Plot address and IP address.

Load project: Execute Download or Reload.

Start running: Set the mode switch to RUN.

7.3 Maintenance and Repair

Preventive maintenance: It is recommended to regularly replace the controller fan.

ESD protection: Only personnel with knowledge of ESD (electrostatic discharge) protection can replace modules.

Power redundancy: Supports the connection of two redundant 24 VDC power units, powered through terminals L1+/L1- and L2+/L2-.


8. System specifications and delineation

To ensure the rationality of project design, engineers need to comply with the following system boundary restrictions:

Number of resources (controllers): 1... 65534 per project

Number of baseboards: 1... 16 per resource

Processor modules: 1... 4

User program: 1... 32

Event definition: 0... 20000

I/O modules: 0... 200

SafeEthernet connection: 0... 255

Non volatile event buffer size: 5000 events


Model Supplement

X-BASE PLATE 10 01 

X-BASE PLATE 15 01 

X-BASE PLATE 15 02

X-BASE PLATE 18 01 

X-CPU 01 (processor module)

X-SB 01 (System Bus Module)

X-COM 01 (Communication Module)

X-AI 32 01

X-AI 32 02

X-AI 32 02 SOE

X-DI 16 01

X-DI 32 01

X-DI 32 02 (for proximity switch)

X-DI 32 03

X-DI 32 04

X-DI 32 04 SOE

X-DI 32 05 (for proximity switch)

X-DI 32 05 SOE

X-DI 64 01

X-CI 24 01

X-AO 16 01

X-DO 12 01

X-DO 12 02

X-DO 24 01

X-DO 24 02

X-DO 32 01

X-FTA AI 32 01 01

X-FTA DI 32 01 01

X-FTA DI 32 02 01

X-FTA DO 12 01 01

X-FTA DO 24 01 01

X-FTA 001 01

X-FTA 001 02

X-FTA 002 01

X-FTA 002 02

X-FTA 003 02

X-FTA 005 02

X-FTA 006 01

X-FTA 006 02

X-FTA 007 02

X-FTA 008 02

X-FTA 009 02

X-CB 008 01 

X-CB 008 02

X-CB 008 03 

X-CB 008 04 


  • Triconex 3723X Analog Input Module with HART
  • Sumitomo SM-Cyclo RNFMS01-20L-80 Motor Gear
  • Sumitomo AF503-3A7 Transistor Inverter
  • CASE Sumitomo KHR30842 KHR30840 Cab Harness
  • Sumitomo FCS-A25G-29 PB051710 Gear Kit
  • Sumitomo KHR1787 SMCU-5 Controller
  • Sumitomo AF503-2A2 Inverter 3.9kVA
  • AMT 9502 Touch Screen Panel
  • Sumitomo CHHJS-6135Y-R2-6 Gearbox Adapter
  • Sumitomo PA136445 RNYMS02-1320YC-40 Gearmotor
  • Sumitomo ANFX-P130F-1GL3-33 Gearbox
  • Sumitomo SH55U-2 Rubber Track
  • Sumitomo US60125-GA AC Servo Driver SS6000
  • Sumitomo CNFXS6075LB21 Cyclo Drive Reducer Motor
  • Sumitomo QT62-125F-BP-Z Hydraulic Gear Pump
  • Sumitomo CNFX-6090G-11/G Gearbox
  • Sumitomo X81D1-0102 SEM-I-1614 Control Module
  • Sumitomo Eaton C300-S Counterbalance Valve
  • Sumitomo GR-RF20 Z4-12193-5 Ozone Generator
  • Sumitomo T.SBXH1.5PL-25PD LN Modulator
  • Sumitomo 8700109 AS-3340 rev D CPU Module
  • Sumitomo SHI Cyclo Drive F3CS-A25G-89 Reducer
  • Sumitomo KNR0827 Wiring Harness SH120-3 SH120A3
  • Sumitomo ULC100011-01 LNR Actuator Driver
  • LUBE GMN-10-200-CB2-7L Lubricator Grease Pump
  • Sumitomo SH65UJ Rubber Track
  • Sumitomo KHR69310 Excavator Monitor
  • Sumitomo FDT-2FS Fiber Identifier Power Meter
  • Sumitomo CNVMS-4085G-43 Ink Fountain Motor
  • Sumitomo GV9924023-38 Circuit Board
  • Sumitomo 407915-5510 4BG1TRA ECU Controller
  • Sumitomo Cyclo F71m/4 Induction Motor 0.37kW
  • Sumitomo ANFJ-K30-SV-9 Hydraulic Control Valve
  • Hitachi Sumitomo 4625051 Pilot Valve Joystick
  • Sumitomo Demag W4RAP 6 W7-04-30 Valve
  • Sumitomo RV F2CF-A35-119 Gearbox
  • Sumitomo SH120 Slew Ring JCB JS130
  • Sumitomo Truninger QT-42-20HS-A Gear Pump
  • Sumitomo D2X-00577/02 SLV Control Board
  • Sumitomo Type-36 ARC Fibre Fusion Splicer
  • Sumitomo WRX33000R125-300 Shell Milling Cutter
  • Sumitomo Fine Cyclo F4CS-C35-59 Gearbox
  • Sumitomo Demag 4WREE 10 W75-23 Flow Valve
  • Sumitomo RDK-408A3 MRI Cold Head 5445412
  • Sumitomo AF-500 AF502-1A5 Cold Head
  • Sumitomo TYPE-35SE Fiber Optic Fusion Splicer
  • Sumitomo SH60 Rubber Track
  • Sumitomo SXPL JA765811BE Controller Interface Display
  • Sumitomo RF4100R Shell Mill 6 Flute 1.25 inch Arbor 4 inch OD
  • Sumitomo SHI SA765621AX SA765587BC Control Module
  • Sumitomo P-022CD-1A Cold Head Drive Unit
  • Sumitomo NL6448AC33-18 JA762898AD Operator Panel
  • Sumitomo JA762870GC Populated Circuit Board
  • Sumitomo Type-37 SM MM Fusion Splicer
  • Steel Track Chain for Sumitomo SH75 Excavator
  • Sumitomo CNV-6095-6 Cyclo Drive
  • Sumitomo Fine Cyclo F4CS-C35-59 PB048860 GEB
  • Sumitomo TC-FXPA FB-2E Motor RNYM2-1520A-EP-B-60 Gearbox
  • Sumitomo Heavy Industries RDK-4XX MRI Cold Head
  • Sumitomo SA765523AX PMDRV PCB Card 7MBP50RA060
  • Sumitomo Drive 307H-25 119H2505 Speed Reducer
  • Sumitomo Eaton H-130AA2FXJ Orbit Motor
  • Sumitomo JA775810A3 Nozzle Heater 19-58 130W
  • Sumitomo ZNFM05 Gearbox
  • Sumitomo F1C-A25-119 Gearbox
  • Sumitomo Fusion Splicer Type 39BT
  • Sumitomo MC78 UMC78S000-01 Motion Controller
  • Sumitomo Cyclo 2 Speed Motor Brake Gearbox
  • Sumitomo Drive PA213763 RNYMS02-1320YC-40
  • Sumitomo JA450704A2 Cylinder Head
  • Sumitomo T39 Fusion Splicer
  • Sumitomo AF-500 Cold Head
  • Sumitomo 71C Fusion Splicer
  • Sumitomo RDK-408S Cryocooler Cold Head
  • Sumitomo L3 Coldhead
  • Sumitomo F2CS-A25-119 Gearhead
  • Sumitomo US60125-GA AC Servo Driver SS6000
  • Sumitomo Type 39 Fusion Splicer
  • Sumitomo ANFJ-K30-SV-9 Planetary Gearbox
  • Sumitomo Heavy Industries JA761557BC RSC86-I Control Board
  • Sumitomo SA765604AX SA765603BC SXEX Servo Control Board
  • Sumitomo SumiDrill WDX2250D3S150 Drill
  • Sumitomo Type-66M12 Mass Fusion Splicer
  • Sumitomo Heavy Industries JA761557AC RSC86-I Control Board
  • Sumitomo JA761015CC RSC86 Circuit Board
  • Sumitomo T-72M12 Mass Fusion Splicer
  • Sumitomo TYPE-72C-KIT Core Aligning Fusion Splicer
  • Sumitomo CI-10/600-ADSD1-2 Power Supply
  • Sumitomo HF5202-3A7 Electronic Module
  • Sumitomo JA761015EC RSC86 Servo Control Board
  • Sumitomo TYPE-39 DCM Micro Core Fusion Splicer
  • Sumitomo JA761070HC AP-M Circuit Board
  • Sumitomo TYPE-400S T-400S Fusion Splicer Kit
  • Sumitomo TYPE-201E-VS Quantum Fusion Splicer
  • Sumitomo MC78IO Drive Power Module
  • Sumitomo 3-Phase Motor Gearbox 4kW 241RPM
  • CASE KRC10510 Hydraulic Swing Motor Sumitomo
  • Sumitomo HF4302-011 HF-430 Inverter Drive 11kW
  • Sumitomo SA765654BC SXIO-B Control Board
  • Sumitomo SDPH-018CHB PWM Amplifier Module
  • Sumitomo JA761070JC AP-M Circuit Board
  • Sumitomo HV960LC Local Control Board
  • Sumitomo T-71C+ Fusion Splicer Camera Y Focus Error
  • Sumitomo CH-210 Cold Head Cryo Cooler
  • Sumitomo Type-71C+ DCM Fusion Splicer
  • Sumitomo Type-65M12 Ribbon Fiber Fusion Splicer
  • Sumitomo T-502S Elite Fusion Splicer
  • Sumitomo T-72C+ Fusion Splicer
  • Sumitomo JA767632AC Circuit Board
  • Sumitomo Type-72C+ Core Alignment Fusion Splicer
  • Sumitomo CP5003 101AGG01 Sequencer I/F Board
  • Sumitomo T-37SE Fibre Fusion Splicer
  • Sumitomo Type-71C-KIT-PLUS Fusion Splicer
  • Sumitomo Type-72C HD Fusion Splicer
  • Sumitomo Type-72C+ Fusion Splicer FC-6+
  • Sumitomo Type-65M12 Ribbon Fusion Splicer
  • Sumitomo Type-72C+ Fusion Splicer
  • Sumitomo Type-39 DCM Fusion Splicer
  • Sumitomo Z1C Core Alignment Fusion Splicer
  • Sumitomo Type-71C DCM Fusion Splicer
  • Sumitomo T-72M12 Ribbon Fusion Splicer
  • ABB SACO 64D4 Digital Annunciator Unit 64-Channel Alarm System
  • EMERSON FloBoss S600+ P154 PRV Board 7381540 Prover Module
  • EMERSON FloBoss S600+ P155 PSU Board 7161550 Power Supply
  • EMERSON FloBoss S600+ P153 Front Panel 7181530 Display Keypad
  • EMERSON FloBoss S600+ P148 Dual Pulse Mezzanine 7181483 Module
  • EMERSON FloBoss S600+ P144 I/O Board 7281440 Analog Digital Module
  • EMERSON FloBoss S600+ P152 CPU Board 7381520 Main Processor