Welcome to the Industrial Automation website!

NameDescriptionContent
HONG  KANG
E-mail  
Password  
  
Forgot password?
  Register
当前位置:

SCHNEIDER Quantum Safety PLC: Complete Analysis of SIL3 Safety Control System

来源: | 作者:FAN | 发布时间 :2026-01-20 | 192 次浏览: | Share:

Schneider Electric Quantum Safety PLC: A High Reliability Safety Control System for SIL3 Applications

1. Product Overview and Certification Background

Quantum Safety PLC is a safety related system developed by Schneider Electric based on the Quantum series programmable logic controller (PLC), specifically designed to meet the functional safety requirements of IEC 61508 standard. This system is certified by T Ü V Rheinland and supports applications up to SIL3, suitable for safety scenarios in low demand mode (PFD ≥ 10 ⁻⁴ to<10 ⁻³) and high demand mode (PFH ≥ 10 ⁻⁸ to<10 ⁻⁷). Its safety state is defined as the de energized state, which is typically applied to critical industrial processes such as emergency shutdown, burner management, fire protection, and gas systems.

In addition to IEC 61508, this PLC also complies with multiple international and industry standards such as IEC 61131-2, IEC 62061, EN ISO 13849, NFPA 85/86, EN 54, and EN 298, and has a wide range of applicability. The system must use certified security firmware and Unity Pro XLS programming software to ensure full chain security compliance from hardware to software.


2. Hardware architecture and security mechanisms

2.1 Secure CPU and Dual Execution Architecture

Quantum Safety PLC provides two types of safety CPUs:

140 CPU 651 60S: for standalone systems

140 CPU 671 60S: Used for Hot Standby high availability systems

The CPU adopts a dual processor architecture (Intel Pentium and application processor) internally, which executes the same security logic in independent memory areas and compares the results at the end of each cycle. This dual code generation and execution mechanism can effectively detect:

Systematic errors in code generation (through compiler diversity)

Systematic errors during code execution

Random errors in CPU and RAM

The CPU has built-in hardware and firmware watchdog to monitor PLC activity and user logic execution time. Static memory (Flash, PCMCIA card, RAM) is verified through cyclic redundancy check (CRC) and dual code execution; Dynamic memory is protected through dual code execution and periodic memory testing.

2.2 Safety I/O module

The system supports three types of certified secure I/O modules:

140 SAI 940 00S: Safety analog input (8 channels, 4-20 mA)

140 SDI 953 00S: Secure Digital Input

140 SDO 953 00S: Secure Digital Output

All safety I/O modules adopt a dual microcontroller system, running the same program and regularly cross checking. The module supports local backplane or remote I/O station installation, and communicates with the CPU through the "black channel" protocol to ensure that errors can be detected during data transmission. The module has comprehensive diagnostic functions, including wire breakage detection, overload, out of range, power monitoring, etc., and supports redundant configuration to improve availability (but redundancy does not enhance safety level).

2.3 Non interfering modules and power supply

The system allows the use of non-interference modules to expand non safety functions, such as:

Backboard (140 XBP 006/010/016 00)

Remote I/O adapter (140 CRP 932 00/140 CRA 932 00)

Ethernet module (140 NOE 771 11)

Standard digital/analog I/O module

These modules do not affect the execution of safety functions, and faults will not affect the safety modules. The power module (140 CPS 124 20/140 CPS 224 00) is certified but does not contribute PFD/PFH values. The system recommends equipping each rack with dual power supplies to achieve redundancy.


3. Programming and software requirements

3.1 Programming Environment and Language Limitations

Only Unity Pro XLS (XL Safety version) can be used for SIL3 project programming. This software provides project protection, self checking functions, and a library of security function blocks. Programming languages are limited to:

Function Block Diagram (FBD)

Ladder diagram (LD)

It is prohibited to use languages such as ST, IL, SFC, as well as subroutines, interrupt tasks, conditional segment execution, and jump labels. All security logic must be written in the MAST task segment.

3.2 Data and Memory Management

Memory is divided into safe memory area and unrestricted memory area (UMA):

Secure memory area: write protected, used for processing security related data

Unrestricted memory area: can be written, but data needs to be transferred to secure memory through the secure move function block (s_SMOVE-BIT/s_SMOVE_SWORD) before it can be used

Only basic data types (BOOL, INT, WORD, etc.) and simple arrays are allowed, and derived data types are prohibited. All variables must be located and their addresses must be within a valid memory range.

3.3 Safety Function Block Library

Unity Pro XLS provides a certified library of security feature blocks, covering functions such as mathematical operations, comparison, logic, statistics, timers, type conversion, high availability, and hot standby. The key functional blocks include:

S-AISIL2/S-DISIL2: Used for selecting and monitoring redundant analog/digital inputs

S-HSBY_SWAP: Used for switching between primary and backup CPUs in hot standby systems

S-WR-ETH/S-RD-ETH: Used for secure Ethernet peer-to-peer communication

  • BENTLY 1-536067-4 Proximitor Connector Lead
  • BENTLY 3500/34 125696-01 TMR Relay Module
  • BENTLY 125704-01 3500/32M I/O Module
  • BENTLY 126632-01 Keyphasor I/O Module
  • BENTLY 3500/25 125792-01 Keyphasor Module
  • Bently Nevada 2300/25-00 Vibration Monitor
  • Bently Nevada 3500/05-01-03-00-00-00 Rack
  • Bently Nevada 3500/42M 140734-02 Monitor
  • Bently Nevada 123M4610 Accelerometer
  • Bently Nevada 3500/05-02-04-00-00-00 Rack
  • Bently Nevada 3500/53 133388-01 Overspeed Detection Module
  • Bently Nevada 3500/32 125712-01 Relay Module for Machinery Protection
  • Bently Nevada 3500/20 125744-02 Rack Interface Module
  • Bently Nevada 3500/40M 140734-01 Proximitor Monitor Module
  • Bently Nevada 3500/60 163179-01 Temperature Monitor Module
  • BENTLY 3500/22M 288055-01 Enhanced TDI Module
  • BENTLY 3500/22M 146031-01 TDI Module
  • BENTLY 133396-01 3500/22M I/O Module
  • BENTLY 3500/34 TMR RMS Interface Module
  • BENTLY 128275-01-E Proximitor I/O Module
  • Bently Nevada 128276-011 Proximity Probe
  • Bently Nevada 135489-03 Accelerometer
  • Bently Nevada 135473-01 Seismic Transducer
  • Bently Nevada 1900/55 General Purpose Monitor
  • Bently Nevada ASSY78462-01U Proximitor Assembly
  • Bently Nevada 330100-90-01 Proximity Probe for Vibration Monitoring
  • Bently Nevada 330100-90-00 Proximity Probe for Machinery Monitoring
  • Bently Nevada 132419-01 Proximitor Sensor for Vibration Monitoring
  • Bently Nevada 10244-27-50-01 Proximity Probe Extension Cable
  • Bently Nevada 22810-01-05-50-02 Proximity Probe System
  • BENTLY 330980-51-00 3300 NSv Proximitor Sensor
  • BENTLY 330130-045-00-00 3300 XL Extension Cable
  • BENTLY 1X35668 Replacement Internal Module
  • BENTLY 3300/16 Dual XY Vibration Monitor
  • BENTLY 3500/15 133292-01 High Availability Power Supply
  • Bently Nevada 3500/62 163179-03 Process Monitor
  • Allen-Bradley 80190-100-01-R*3 Output Module
  • Allen-Bradley 80190-099-01 Analog Module
  • Allen-Bradley 80190-479-01 I/O Module
  • Allen-Bradley 80190-480-01-R Control Module
  • Bently 3500/15 125840-01 Power Supply Module
  • Bently 24765-02-01 Signal Conditioner Module
  • Bently 330130-085-00-00 Extension Cable
  • Bently 3500/22M 138607-01 Vibration Monitor Module
  • Bently 146031-02 Proximity Probe Sensor
  • BENTLY 330104-00-05-10-02-CN Proximity Probe
  • BENTLY 125768-01 3500 I/O Module Interface
  • BENTLY 3500/92 136180-01 Communication Gateway
  • BENTLY 84152-01 Proximitor Sensor Cable
  • BENTLY 3300/20 Dual Driver Proximitor Housing
  • BENTLY 3300/16-11-01-03-00-00-01 16-Channel Monitor
  • DEIF PPU-3 Power Protection Unit for Genset Control
  • DEIF RMV-112D Reactive Power Divider and Voltage Matching Relay
  • DEIF OPM-1 Output Protection Module for Gensets
  • DEIF IPM-1 Integrated Protection Module for Generators
  • DEIF CM-2 Control Module for Industrial Power Systems
  • DEIF PSM-1 Power System Manager Module
  • DEIF DELOMATIC-3 DGU2 Automatic Generator Control Unit
  • DEIF DLQ144-PC-NB Power Monitoring Meter
  • DEIF DU-2/MKIII Voltage Relay Controller
  • DEIF IOM4.2 Input/Output Module for Power Management
  • DEIF SCM-1 Synchronizing Control Module
  • DEIF GPU/2/GS Genset Parallel Unit Controller
  • EMERSON PR6426/010-110 CON021 Proximity System
  • EMERSON PR6423/011-110+C0N021 Proximity Sensor System
  • DEIF LSU-112DG Load Sharing Unit
  • DEIF PCM4.4 Advanced Power Control Module
  • DEIF TAC-311DG Transducer for AC Voltage
  • DEIF SCM4.1 Engine Start Control Module
  • DEIF PCM4.3 Power Control Module
  • Emerson 2500M/AI4UNIV Universal Analog Input Module
  • Emerson PR6424/011-140 Eddy Current Sensor
  • Emerson KJ3242X1-BK1 12P4711X042 Analog Input Module
  • Emerson FX-316 960132-01 Control Processor Module
  • Emerson KJ4006X1-BD1 Power Supply Module
  • EMERSON 1C31181G01 Ovation Analog Output Module
  • EMERSON CE4003S2B6 DeltaV Analog Module
  • EMERSON KJ4001X1-CK1 DeltaV I/O Carrier Card
  • EMERSON VE4012S2B1 DeltaV I/O Module Specifications
  • EMERSON SS6501T01 DeltaV System Assembly Technical Overview
  • Emerson A6370D/DP Display
  • Emerson P188.R2 Power Supply
  • Emerson A6824R 24-Ch Relay
  • Emerson KJ2201X1-JA1 Serial
  • Emerson VE3008 Main Controller
  • Emerson VE3008 CE3008 KJ2005X1-MQ1 Controller Module
  • Emerson TPMC917 Embedded Processor Module
  • Emerson P152.R4 Industrial Control Module
  • Emerson DA7281520 P152 Power Module
  • Emerson PR6423/008-110 Eddy Current Sensor
  • EMERSON 5X00273G01 Ovation DCS Digital Output Module
  • EMERSON KJ4001X1-NB1 12P3368X012 REV:E Redundant Controller Backplane
  • EMERSON KJ4001X1-NA1 12P3373X012 REV:C Intrinsically Safe Interface
  • EMERSON KJ4001X1-BE1 12P0818X072 REV:L DeltaV I/O Carrier
  • EMERSON KJ2221X1-BA1 DeltaV SIS SISNet Repeater Module
  • EMERSON PR6423/000-131 Eddy Current Sensor
  • EMERSON 5X00790G01 Ovation Digital Output Module
  • EMERSON 5X00846G01 Ovation Analog Input Module
  • EMERSON KJ4110X1-BA1 DeltaV Power Supply Base
  • EMERSON CSI3125 A3125/022-020 Dual Channel Monitor
  • EMERSON A6740 Displacement Case Expansion Monitor
  • EMERSON A6312/06 Speed Monitoring Module
  • EMERSON KJ4001X1-BE1 DeltaV Carrier Module
  • EMERSON SE3008 KJ2005X1-MQ2 DeltaV Controller
  • EMERSON KJ4001X1-CA1 DeltaV Terminal Block
  • Emerson PR6423/00R-010 CON031 Eddy Current Probe System
  • Emerson A6824 9199-00090 Operator Workstation
  • Emerson A6410 9199-00005 Operator Workstation
  • Emerson A6110 9199-00001 Operator Workstation
  • Emerson 9199-00002 A6120 Operator Workstation
  • Emerson KJ3002X1-BF1 12P1732X042 FIELDVUE DVC6200
  • Emerson 5X00500G01 Ovation Analog Output Module
  • Emerson VE4001S2T2B4 DeltaV Controller Module
  • Emerson 5X00502G01 Ovation Analog Input Module
  • Emerson A6824R 9199-00098-13 Operator Workstation
  • EMERSON A6140 9199-00058 Dual Channel Monitor
  • EMERSON VE3007 KJ2005X1-BA1 DeltaV Controller
  • EMERSON DB1-1 Connection Termination Block
  • EMERSON PMC-IO-ADAPTER Mezzanine Interface Card
  • EMERSON L0115012 L0115032 Solenoid Valve Components
  • Emerson A6410 Large Operator Workstation
  • Emerson A6210 Operator Workstation
  • Emerson 1C31232G02 Ovation Controller Module
  • Emerson 5X00106G02 Ovation Power Supply Module
  • Emerson 5X00106G01 Ovation Power Supply Module
  • EMERSON PMC-IO-PROZESSOR High-Speed I/O Module
  • EMERSON PMC PROFINET Communication Module
  • EMERSON MVME7100-0171 VMEbus Single Board Computer