Welcome to the Industrial Automation website!

NameDescriptionContent
XING-Automation
E-mail  
Password  
  
Forgot password?
  Register
当前位置:

Rockwell Automation ICS AADvance Controller

F: | Au:FAN | DA:2025-09-20 | 649 Br: | 🔊 点击朗读正文 ❚❚ | Share:

Rockwell Automation ICS AADvance Controller 

Basic Information and Usage Standards

1. Scope of application and core objectives

Applicable products: AADvance controller series (T9100/T9110 processor modules, T9401/2 digital input modules, etc.) and supporting software (AADvance Workbench 1.4/2.1, AADvance Robust SIS Workstation 2.00), supporting system version 2.011.

Core objective: Define SIF safety application standards (mandatory) and recommendations to ensure that the system meets and maintains the required Safety Integrity Level (SIL), with a maximum support for SIL 3.

2. Key usage requirements

Personnel qualifications: Installation, configuration, operation and maintenance operations must be carried out by professionally trained personnel who are familiar with relevant regulations (such as IEC 61508, NFPA series standards).

Responsibility statement: If the device is used in a manner that does not comply with the manufacturer's regulations, the protective function of the device may become ineffective; Rockwell is not responsible for indirect/consequential damages, and the examples in the manual are for illustration only and do not represent actual application guarantees.

System core features and authentication

1. Core functions and security design

Application scenarios: Suitable for safety critical scenarios such as emergency shutdown (ESD), fire and gas detection, rotating machinery control, burner management, etc., while supporting non safety but business critical control requirements.

Security Capability:

Both fail safe and fault tolerant architectures are supported, and fault tolerance can be realized through two module (1oo2D) or three module (2oo3D) configurations.

Built in comprehensive diagnostic function, capable of detecting hardware/software faults. The faulty module needs to be replaced within the mean time to repair (MTTR) to avoid a decrease in SIL level.

Supports two configurations: "Power Loss Trip (DTT)" and "Power On Action (ETA)", and the number of modules needs to be selected based on SIL level and demand rate (high/low) (see Table 1).

2. Module configuration and SIL compliance requirements

Minimum module configuration for different application scenarios (simplified version of Table 1):

Application type, number of input modules, number of processor modules, number of output modules

SIL 2/3, Low/high demand, DTT 1 2 1

SIL 2, High demand, ETA 2 2 2

SIL 3, High demand, ETA 2 2 2

Note: The single channel digital output module includes a series switch. The DTT scenario supports SIL 3, while the ETA scenario only supports SIL 2; There are no three module output configuration options.

3. International certification and compliance standards

Functional safety certification: Compliant with IEC 61508 SIL 3, certified by an independent certification body.

Hazardous environment certification:

North America: Class I, Division 2, Groups A-D (UL 61010-2-201, CSA C22.2 standard).

Europe/UK: ATEX (DEMKO 11 ATEX 1129711X, Ex ec IIC T4 Gc), UKCA (UL24UKEX2993).

International: IECEx (certificate number IECEx UL 12.0032X).

Other compliance: Complies with industry standards such as EN 50156 (furnace control), EN 54 (fire alarm), NFPA 85/86/87 (boilers/ovens/fluid heaters), etc.

Safety lifecycle and management system

1. Safety lifecycle stages

The full lifecycle defined by IEC 61508 must be followed, with core stages including:

Scope definition: Clearly define system boundaries, interfaces (with processes/third-party equipment), and environmental requirements (such as temperature and power).

Hazard and Risk Analysis: Identify hazardous events, trigger sequences, and risk levels as inputs for safety requirements.

System Design and Engineering: Divide system architecture, define security requirement levels for each component, and refine hardware/software design.

Integration and Verification: The application is integrated with the controller to test and verify whether SIF meets SIL requirements (such as response time and fault handling).

Operation and Maintenance: Develop an operation/maintenance plan to ensure the SIL level is maintained during operation; Changes must be strictly controlled, and suspensions must follow safety procedures.

2. Requirements for Safety Management System

Policy and Planning: Functional safety policies need to be developed to clarify measures, responsibilities, and record management (including change control) for each stage of the lifecycle.

Personnel capability: Personnel qualifications need to be evaluated, including engineering experience, functional safety knowledge, regulatory familiarity, etc. Higher qualification requirements are required for high-risk scenarios.

Functional Safety Assessment (FSA): Led by senior personnel independent of the project, it reviews whether the entire lifecycle work meets the requirements.


System Architecture Design (SIL 2/3)

1. SIL 2 architecture

Fault safety architecture: single input (1oo1D), dual processor (1oo1D degraded), single output (1oo1D), triggering a safe state in case of a fault.

Fault tolerant input architecture: dual/triple input (1oo2D/2oo3D), dual processors, single output. When a single input module fails, it will operate in a degraded state while still maintaining safety functions.

High demand architecture: dual input, dual processor, dual output, ensuring that faulty modules are replaced within MTTR to avoid SIF shutdown.

2. SIL 3 architecture

Fault safe I/O+fault-tolerant processor: single input/output, dual/triple processor (1oo2D/2oo3D), downgraded in case of processor failure, dual fault triggers safe state.

Fault tolerant I/O architecture: dual input/output, dual processors, both input/output modules support 1oo2D degradation, suitable for high safety requirements scenarios.

TMR architecture: three inputs, three processors (2oo3D), dual outputs, with the strongest fault tolerance. A single module failure does not affect system operation. When there are two failures, it will be downgraded, and when there are three failures, it will trigger a safe state.

3. Secure network communication

SNCP protocol: SIL 3 certified "Black Channel" protocol, supports Ethernet transmission of secure data, achieves data exchange between controllers through "variable binding", and can be configured as single network (fail safe) or dual network (fault-tolerant).

Peer to Peer communication: Supports SIL 3 data transmission between AADdistance and Trusted controllers, based on master-slave mode, and recommends using redundant networks to ensure availability.

Installation and environmental requirements

1. Non hazardous environment

Environmental conditions: temperature -25 ° C~+60 ° C, pollution level ≤ 2 (IEC 60664-1, only non-conductive pollution, occasional condensation); The burner management application requires an enclosure protection level of IP40 (indoor)/IP54 (outdoor).

Installation requirements: The module should be installed vertically (ensuring natural heat dissipation), DIN rail or wall mounted, without the need for forced air cooling.

2. Hazardous environment

Special requirements:

The enclosure protection level is ≥ IP54 (IEC 60079-0/7) and must be marked with "Do not open when powered on".

Grounding wire cross-sectional area ≥ 3.31mm ², wire temperature rating ≥ 85 ° C, only supports vertical installation.

The temperature range is the same as non hazardous environments, and the pollution level is ≤ 2.


Operations and Security Assurance

1. Key daily maintenance items

Fault handling: When the processor/input/output module fails, it needs to be replaced within MTTR; If not replaced in a timely manner, the relevant SIF needs to be shut down (unless there are compensatory measures in the SRS document).

Calibration and testing: Regularly calibrate sensors/actuators, test SIF response time (≤ 1/2 of process safety time PST), and archive test records.

Backup and Update: Regularly backup system configuration (AADvance Workbench/SIS Workstation project) and test backup effectiveness; Firmware updates require the use of the ControlFLASH tool.

2. System security measures

Network security: it is forbidden to connect to the unprotected Internet; Computers need to have firewalls, antivirus software, and password protection enabled; The software license USB key needs to be properly kept.

Port security: Some Ethernet ports (such as TCP 1132, UDP 2010) are open by default, and unused ports need to be closed through a firewall (refer to the configuration guide).

Program Security: The application requires password protection, and the controller needs to insert the "Program Enable Key" to modify the configuration; It is prohibited to force I/O points during operation, and it is recommended to use the program's "override" logic for maintenance.

Supporting documents and resources

1. Key related documents

Document Name Usage Description

AADvance Controller System Build Manual (ICSTT-RM448) System Assembly, Startup, and Operation Verification

AADvance PFH and PFDavg Data (ICSTT-RM449) Fault Probability (PFH/PFDavg) Data and Calculation Example

AADvance Troubleshooting and Maintenance Manual (ICSTT-RM406) System Maintenance, Troubleshooting, and Repair

2. Support channels

Technical support: Get help through rok.auto/support, register an account to subscribe to product security notifications.

Document download: Download the latest manuals and firmware from Rockwell Literature Library (rok.auto/iterative) or Product Compatibility and Download Center (rok.auto/pcdc).


Key Terminology (Glossary Simplified)

SIL (Safety Integrity Level): Safety Integrity Level, levels 1-4, with SIL 3 being the highest level supported by the manual.

PST (Process Safety Time): The maximum time for triggering a hazardous event when a hazardous state exists and there is no protection. The controller defaults to PST=2500ms and needs to be adjusted based on sensor/actuator delay.

MTTR (Mean Time To Repair): The average time to repair, during which faulty modules need to be replaced to maintain SIL.

1oo2D/2oo3D: Fault tolerant configuration, 1oo2D (2 out of 1 with diagnosis), 2oo3D (3 out of 2 with diagnosis).

image.png

  • GE IS2I5WEMAHIA+IS210BPPBHZCAA Mark VIe Safety Controller & I/O Module Set
  • GE IS2I5AEPAHICH+IS210BPPBHZCAA Mark VIe Analog I/O Control Module Set
  • GE IS2I5WECAH1B+IS2108PPBHZCAA Mark VIe Controller Redundant I/O Set
  • VMIC HSDA 332-000111 Scanning Analog-to-Digital Converter Module
  • GE VMIC VMIVME1150B VME Module
  • FANUC VMIVME3128 VME Digital I/O Board
  • GE Fanuc VMIVME-7697-350 VMEbus Single Board Computer
  • GE Fanuc VMIVME-4150 PLC Board
  • FANUC VMIVME-1160A VMEbus Module
  • GE Fanuc VMIVME-4116 VMEbus CPU Processor Controller
  • FANUC VMIVME-9300 VMEbus Module
  • VMIVME-7589A Pentium VMEbus CPU Board
  • GE Fanuc VMIPCI-7767-13100 PCI Board
  • GE Fanuc VMIVME-4140 VMEbus Module
  • IS415UCVGH1A VME Controller Card
  • VMIC VMIVME-1150 VME Circuit Board
  • VMIC VMIVME7589 Processor Board
  • FANUC VMIVME-2200 VME Circuit Board
  • IS215UCVEH2A VME Controller Card
  • VMIC VMIVME-7589A-446 VMEbus CPU SBC
  • VMIC VMIVME-7658-330 VME Single Board Computer
  • VMIC SEMIVISION OPAL VMEbus CPU Module with VMIVME-7588
  • GE Fanuc VMIVME-4140 VME Module
  • Abaco VMIVME 2532A 32-Bit High-Voltage Digital I/O Board – VMEbus
  • VMIC VMIVME 100-Pin VME Bus I/O Cables
  • VMIC ASSY 11994R13 VMEbus Module
  • GE Fanuc VMIVME 1182 VMEbus Input Board – 332-011182-030A
  • VMIC VMIVME-7589 VMEbus Module with VMIVME-7434
  • VMIC VMIVME-7588-787 Single Board Computer – 332-250236
  • VMIC 7487A VMEbus CPU Board – 332-107487-033 H
  • FANUC VMIVME-3125 VMEbus Analog Input Board
  • VMIC VMIVME 6015 VMEbus Board – 332-006015-000
  • VMIC ASSY 11993R2 VMEbus Module
  • Cisco 2851 Router with VMIC2-1MFT-T1/E1 Module
  • Applied Materials VMIC 7505 800MHz CPCI SBC
  • VMIVME-2534-046D 32-Bit High-Voltage Digital I/O Board
  • VMIC 5530M Optical Extender PCB Board
  • GE VMIC XVB602 Control Module
  • VMIVME-6005-020 Octal ARINC-429 Controller
  • VMIC VMI PCI 3322 Board
  • FANUC VMIVME-7487 VME Processor Board
  • VMIC 332-800576-000A VMIACC 0576 Module
  • VMIC VMIVME-7805-231000 VME Board
  • ABACO VMIC VMICBL-000-F3-102 Reflective Memory Cable
  • VMIC 332-000131-B VMIVME PCB Card
  • VMIC 320-250236 with VMIVME-7588 Processor Board
  • VMIC ASSY 12149 Module
  • FANUC VMIC VMIVME5010 I/O PCB Board
  • VMIC VMIVME-7698-345 VME Single Board Computer
  • IS215UCVEH2A VME Controller Card
  • VMIC VMIVME-7658-330 VME Single Board Computer
  • VMIC VMIPCI-5790-000 Dual-Channel Ultra160 SCSI Adapter
  • VMIC VMICPCI-7756-460 Single Board Computer
  • VMIVME-4920 Dual Channel Digital Converter Board – VMEbus
  • GE Fanuc VMIVME-4140 VMEbus Module
  • VMIC VMIPMC-7440 PMC Sound Card
  • VMIC PCI 4320 VMEbus Board-333-854320-000
  • VMIC VMIVME 5530S VMEbus Interface Module
  • FANUC 332-999995-000 VMEbus PCB Assembly
  • FANUC VMIVME-4116-030 VMEbus Module
  • VMIC VMIVME-7658-330 VMEbus Single Board Computer
  • VMIC VME-2532A VMIVME2532A-413 Digital I/O Board
  • VMIC VMIVME-7696-650 VMEbus Processor Board
  • VMIC VMIVME-7487A Mainframe Board
  • GE Fanuc VMIVME-2120-175 Digital Output Board
  • Abaco VMIVME-4125A-000 System Test Calibration Board
  • VMIC VMICPCI-5579 Reflective Memory PCI Board
  • FANUC A860-2000-X003 Encoder Interface Module
  • FANUC 332-999992-000 VME Module
  • VMIC VMIVME-7698 VME Module
  • FANUC A860-2000-X003 Encoder Interface Module
  • VMIC 333-657755-000 B LSC-3 4201 Board
  • VMIVME-9304 CPU Board with NEC FGA-002A Interface Chip
  • VMIC VMIVME-7805 VMEbus Board – VMIVME-7805-234001
  • VMIC 332-000131-000M01 VMIVME PCB Card
  • FANUC GE VMIC VMIVME 2510B Digital I/O Board
  • VMIC VMIPMC-5795-000 PMC Ultra160 SCSI Adapter
  • GE Fanuc VMIVME 5588 High-Speed Reflective Memory Board
  • VMIC VMIVME 4132 VMEbus Analog Output Board
  • VMIC VMIVME-3418 8-Channel Strain Gauge and RTD Board
  • VMIC VMIPMC-5797-000 Ultra320 SCSI Host Bus Adapter
  • VMIC VMIACC 0562 Accessory Module
  • Abaco VMIVME 4116 8-Channel 16-Bit Analog Output Board
  • VMIC VMIVME 4512 Analog I/O Board – 332-004512-300
  • VMIC VMIVME 4120 VMEbus Circuit Board – 332-004120
  • VMIC VMIVME-3801-100C Analog-to-Digital Converter Module
  • IS215UCVEH2AE VME Controller Card
  • FANUC 333-00DMA0-000 VME Module
  • GE Fanuc VMIVME-5588-200 High-Speed Reflective Memory Card
  • VMIC VMIVME-7696-650 VMEbus Single-Board Computer
  • GE Fanuc VMIVME-5532S VMEbus Fiber-Optic Repeater Link
  • VMIC GE EV-DIO-01 Control Board
  • Abaco VMIVME-7751 Pentium III VME Single Board Computer
  • PMC-5565PIORC-110000 128MB Reflective Memory Card
  • Abaco VMIVME-5565-010000 Reflective Memory Board
  • VMIC VMIPMC-5565 Reflective Memory PMC Module
  • VMIC VMIVME 5504 Slave VME Module
  • VMIC VMIVME-5740-12000 VMEbus Hard Drive Module
  • VMIC VMIVME-7751 VMEbus Processor Module
  • VMIC VMIVME-7588 CPU Module
  • VMIC 332-000132 VMIVME PCB Card
  • GE Fanuc VMIVME-4514A Analog I/O Board
  • Abaco VMIVME-2528-000 128-Bit TTL Digital I/O
  • VMIC VMIVME 4514 Scanning Analog I/O Board
  • VMIPCI 5588-101 High Speed Fiber Optic Reflective Memory Card
  • VMIC VMIVME-1228 VMEbus Board
  • VMIC VMIVME-7455 CD-ROM Drive Module
  • VMIC VMIACC 0577 Compact PCI Board
  • IS415UCVGH1A VME Controller Card
  • VMICPMC-5664 VME PMC Dual Fiber Card
  • VMIVME1128 128-Bit High-Voltage Digital Output Board
  • VMIC VMIVME-2170A VMEbus PCB Board
  • VMIC 332-015565-010L VME Module
  • VMIC VMICPCI-7612-470 Single Board Computer
  • VMIC EV-CNT/01 Control Board
  • VMIC VMIVME 1181 VMEbus Input Board – 333-001181-000 A
  • VMIC VMIVME-1150 VMEbus Module
  • VMIC VMIVME-5576 VMEbus Module
  • VMIC VMIVME-4150 VMEbus Module
  • VMIC VMIOMAX-8001B PLC Rack
  • VMIC VMIVME 2128 High-Voltage Digital Output Board
  • VMIC VMIVME-1111 64-Bit High-Voltage Digital Input Board
  • GE Fanuc VMIVME 1182 VMEbus Input Board – 332-011182-060C
  • VMIC VMIVME-7696 VMEbus PC Board
  • VMIC VMIVME-7686 VMEbus Module
  • GE VMIVME-7486 VME PCB Board
  • VMIC VMIVME-7740-840 Processor Module
  • VMIC VMIACC BT01 REV 0 Transition Board