Welcome to the Industrial Automation website!

NameDescriptionContent
XING-Automation
E-mail  
Password  
  
Forgot password?
  Register
当前位置:

SCHNEIDER Quantum Safety PLC: Complete Analysis of SIL3 Safety Control System

F: | Au:FAN | DA:2026-01-20 | 403 Br: | 🔊 点击朗读正文 ❚❚ | Share:

4. Operation mode and diagnosis

4.1 Security Mode and Maintenance Mode

Safe mode: default mode, prohibited from modification and maintenance, only allowed to start and stop PLC. All safety functions are activated and the diagnostic results have been fully evaluated.

Maintenance mode: used for debugging, forcing values, and modifying programs. The diagnosis is still running but the results have not been fully evaluated. The mandatory value remains unchanged when switching to safe mode.

Mode switching needs to be controlled through a key switch, Unity Pro XLS, or CPU keyboard. Modifications made in maintenance mode must comply with the requirements of IEC 61508 and refer to T Ü V's "Maintenance Override" document.

4.2 Diagnosis and Error Handling

The system has multi-level diagnosis:

CPU diagnosis: dual processor comparison, memory check, watchdog monitoring

I/O diagnosis: channel health status, communication CRC check, power monitoring

Communication diagnosis: Black channel protocol detects transmission errors, omissions, disguises, etc

Once an error is detected, the system behavior varies depending on the pattern:

In safe mode: enter error state, all safe outputs enter safe state

In maintenance mode: entering the shutdown state, communication and debugging can still be carried out

The error information is stored in the system words% SW125-% SW127 for subsequent analysis. When the I/O module fails, only the faulty channel enters a safe state, while the other channels continue to operate.


5. Communication Security and Network Integration

5.1 Secure Ethernet Peer to Peer Communication

By configuring NTP service, S-WR-ETH/S-RD-ETH function block, and IO scanning service, SIL3 level secure communication between PLCs can be achieved. This communication is based on a black channel mechanism, which can detect and manage transmission errors, delays, address errors, etc. All Ethernet devices (switches, NTP servers) do not contribute PFD/PFH values.

5.2 Write Protection and Memory Isolation

The secure memory area provides write protection for external devices such as HMI and other PLCs. The unrestricted memory area can receive external data, but it must be transferred to secure memory through the secure move function block before it can be used for secure logic. Unity Pro XLS checks this rule during editing and building to ensure data flow isolation.

5.3 Communication Restrictions

Do not use Ethernet or Modbus Plus to connect I/O modules

Prohibit the use of distributed I/O or fieldbus I/O

Allow Ethernet/Modbus Plus to be used for communication between PLCs or PLC-HMI, but read can only be for unlimited memory areas


6. Safety time and performance calculation

6.1 Process Safety Time (PST) and System Response Time

PST refers to the time window from the occurrence of equipment failure to the occurrence of hazardous events. The system response time must be less than PST, and its calculation formula is:

System response time=PLC response time+sensor time+actuator time

PLC response time=CPU response time+input module time+output module time

CPU response time=(2+N_CRC) x CPU cycle time

Among them, N_CRC is the maximum allowed number of consecutive CRC errors (1-3).

6.2 Maximum CPU cycle time calculation

When considering secure peer-to-peer communication, the maximum CPU cycle time must meet:

(1+N_CRC) x Max (CPU-sender cycle time)+Max (CPU-receiver cycle time)<PST - ∑ each link time

The timeout of the output module must be greater than the CPU cycle time to ensure that the safe state can be triggered in a timely manner in case of failure.


7. Configuration List and Implementation Suggestions

The manual provides multiple checklists covering configuration, programming, I/O modules, secure peer-to-peer communication, and operation and maintenance. Key recommendations include:

Use authenticated security and non-interference modules

Each rack is equipped with dual power supplies

Redundant I/O modules should be distributed in different remote stations

Enable all warning options during programming and review them one by one

Regularly backup projects and test recovery processes

Follow T Ü V documentation for maintenance and mandatory operations


8. Industry specific requirements

8.1 Fire and Gas System

Must comply with EN 54 standard, requirements:

Detect open/short circuits in the circuit and sound an alarm

power redundancy

Analog input requires monitoring of ground faults (leakage current), usually achieved through shunt resistors and grounding devices

8.2 Emergency Shutdown and Burner Management

The safety status is in power-off state. The burner system must comply with EN 298, ensuring that the entire time from detection to safe shutdown does not exceed 1 second, and the on-site power supply must be a 20-25 VDC regulated power supply.

  • OMRON CJ1W-MD261 Mixed I/O Module
  • Omron NJ301-1100 PLC CPU eCat EIP Specs
  • Omron F500-C15-ETN Vision System PLC Module
  • Modicon M241-24IO TM/T2UK PLC with Ethernet
  • SIXNET YS-800-001 RTU PLC Module
  • BEMAC UST-202-D Interface Board 1307D V08B2
  • Yaskawa JANCD-MMOIC-02 Drive Circuit Board
  • ABB 3BSE005028R1 SDCS-COM-1 Comm Board
  • Omron 3G3MX2-A4110 A4150 Inverter Drives Specs
  • KEYENCE CA-E100 PLC Module
  • GE IC693ALG223-GB Analog Input Module Specs
  • ABB BAILEY IMMFP01 Multi Function Processor System
  • SIEMENS 6FC5372 0AA00 0AA1 NCU 7202 Controller
  • Modicon TM241CE4 40I O Transistor Programmable Controller
  • SIEMENS 6ES7 315 2EH13 0AB0 CPU 3152 PN DP
  • NORIS A1 91 PCB Card Rack Module System
  • SIEMENS 6ES7 313 5BE01 0AB0 Compact CPU
  • SCHNEIDER ELECTRIC S144B MICROLOGIC 60A Trip Unit
  • CNI PLC269 v3 Control Module Board Rev H
  • ABB BAILEY IIMCP02 Processor Module
  • OMRON NT20S ST121 EV3 Operator Interface Terminal
  • OMRON NS-CA001 Video Input Unit
  • GE Fanuc IC695CHS012 RX3i Backplane
  • Allen Bradley 2711E-K14C6 PanelView 1400e Terminal
  • Siemens Sinamics CCB 10000432.71 Power Cell
  • Siemens 6SL3210-1SE21-8UA0 Power Module PM340
  • Yaskawa CIMR-F7A20P4 AC Drive
  • Beckhoff EP1918-0002 EtherCAT Box I/O Module
  • OMRON CQM1-TC001 Temperature Control Module
  • GE Fanuc SGHA36AT0400 Industrial Contactor
  • OMRON NJ501-1500 PLC Machine Automation Controller
  • Mitsubishi MAZAK QX084 Power Supply MELDAS 500 CNC
  • B&R 0AC808.9 PLC Automation Module
  • OMRON CP1H-XA40DT1-D PLC Module
  • G&W Electric PLC15 5111 011 15kV Capnut Assembly
  • GE DS200SLCCG3AGH PCB Circuit Board
  • Siemens SINUMERIK 6FC3981-4FD PLC Extension
  • OMRON F300-DC I/O Image Processing Unit
  • FANUC A06B-0314-B002 AC Servo Motor
  • GC-S84 Programmable Controller Logic Module
  • PASABAN MONTELEC MTC3001-DC Drive Control PLC
  • Allen Bradley 100E460EJ11 Auxiliary Contactor
  • Bosch Rexroth 1070075337-101 Card Parameters
  • HMS Anybus AB7646-F Gateway Specifications
  • Bosch 062633-303401 CNC Servo PLC Card
  • TI 500-5023 Series PLC Power Supply
  • Siemens C98043-A7002-L1-12 Circuit Board
  • Omron E5CC-RX3A5M-000 Controller
  • CN-8032-L Profinet Network Adapter Module
  • Siemens 3TK2804-0BB4 Safety Relay Details
  • Toledo TTLM-2-1M I/O Load Module
  • NORIS A1-91 PLC Rack Board Specifications
  • Mitsubishi A3ACPUR21 MELSEC PLC CPU Module
  • Beckhoff EP7041‑3002 EtherCAT Box Digital Input Module
  • REER EOS2E 1053 EOS2R 1053 Safety Light Curtain
  • Mitsubishi Q80BD-J71BR11 MELSECNET/H Interface Board
  • Omron 3G3IV-B4220-EV2 VFD 400V 22kW
  • Allen-Bradley 96844671 1785-LT3 PLC-5/12 Processor Module
  • Pasaban MTC3001-DC Drive Control PLC Module
  • Omron CJ1M-CPU11 V4.0 PLC CPU Module
  • ABB CM579-PNIO B3 Communication Module
  • B&R X20 AI 4221 Analog Module
  • Siemens 6SY7000-0AC80 PLC Module
  • GE 531X300CCHAFM5 Control Card
  • AB 810-A15C Inverse Time Relay
  • WITTENSTEIN LP120X-MF2-20 Planetary Gear
  • Mitsubishi Kakoki E-01B-4130 PLC I/O Modules
  • ABB DSQC643 Safety Control Board
  • Siemens G26004-A2105-P100-2 PCB
  • OMRON F350-C10E Image Processing Unit
  • FUJI UG430H-TS1 HMI Touch Panel
  • Westronics CB100188-01 Rev F Board
  • Siemens 7MH4900-3AA01 Weighing Module
  • Gilbert & Nash Tracker 2000 Control Cabinet
  • OMRON CJ1M-CPU22 CPU Unit
  • OMRON F3SJ-E0625P25 Light Curtain
  • Siemens 3VA2340-5HL32-0AA0 Breaker
  • Mitsubishi Melsec A61P A2NCPU PLC System
  • Aeco 158-02 DSP-02 PCB Card
  • FUJI NP1PS-32R CPU Module
  • Siemens 6SL3040-1MA01-0AA0 Control Unit CU320-2 PN
  • Fuji RYE.75D PLC Driver AC Drive
  • Electro Cam PS-6144-24-P16M09-L-MB Programmable Limit Switch
  • Siemens C98043-A7001-L2-4 CUD1 Control Board
  • Pilz 312070 PSSu H PLC1 FS SN SD Safety Module
  • Siemens Plc42q4200atsn Circuit Breaker Fuse Box
  • GE Fanuc IC695ALG708-AB Analog Output Module Rx3i
  • Siemens 6SE7036-5GK84-1JC2 IGD8 Gate Driver Board
  • Charmilles 813078 852029 PLC PCB Robocut 2 CNC EDM
  • Siemens 6SL3130-1TE24-0AA0 Smart Line Module
  • Pasaban MTC3001-DC Drive Control PLC Module
  • Modicon AS-P890-000 Remote I/O Processor Power Supply
  • Siemens PXC100-PE96.A PXC Modular Controller
  • TOYO KEIKI P:CARD5 AVH-R YH-212 Industrial Control Card
  • Omron NS5-SQ00B-V2 HMI Touch Screen 5.7 Inch
  • Sciemetric SigPOD 1202-0H00 Data Acquisition Module
  • GE Fanuc IC693CPU331W CPU Module Series 90-30
  • Square D 8903SVO11V02 Lighting Contactor 200A
  • Beckhoff C9900-P224 Power Supply Unit 24V 10A
  • HSD PE323 PLC I/O Module
  • Pillar AB6406-11A Power Control Board
  • GE Fanuc IC693CPU331W CPU Module
  • FANUC A61L-0001-0072 LCD Monitor
  • AB 20D-D-011-A-0-EYNANANE Drive
  • AB 1785-L20B PLC-5/20 Processor
  • Siemens SIREC P/PA Recorder 7ND3021
  • Siemens D2E160-AH01-17 Fan Blower
  • Eaton 101073735-001 LEG Module
  • AB 1404-M605B-ENT Powermonitor 3000
  • OMRON CJ1W-MAD42 Analog I/O
  • Omron CJ1M-CPU13 V3.0 PLC CPU Module
  • Pe323 HSD PLC Module Industrial Controller
  • Pasaban MTC3001-DC Drive Control PLC Module
  • Mitsubishi R02CPU PLC Module MELSEC iQ-R
  • B&R X20DC2395 Digital Output Module 32 Ch
  • Hoffman A30N24ALP Enclosure with PLC Addons
  • Rieter PLC with RMC 24/5V 10 RMC188-1 RMC RIO-1
  • Allen-Bradley 1790D-TN4V0 CompactBlock LDX Base Block 4 AI
  • National Instruments NI 9242 Analog Input Module 4-Channel
  • ABB AO820 3BSE008546R1 Analog Output Module
  • Moeller XVC-101-C192K-K82 PLC
  • AB 440F-C4000P MatGuard Controller
  • AB 1692-ZRCLSS Protection Module
  • Schneider S48896 PLC Module
  • FANUC A02B-0303-C205 I/O Module
  • AB 1785-LT4 PLC-5/10 Processor
  • AB 1746-NO8V SLC 500 Analog Output
  • OMRON CQM1-TC001 Temperature Unit