Welcome to the Industrial Automation website!

NameDescriptionContent
XING-Automation
E-mail  
Password  
  
Forgot password?
  Register
当前位置:

Rockwell Trusted TMR Processor

F: | Au:FANS | DA:2026-05-22 | 397 Br: | 🔊 点击朗读正文 ❚❚ | Share:

Rockwell Trusted TMR Processor

Introduction: When the security system processor lights up with a red light

In process industries, oil and gas pipelines, nuclear power auxiliary facilities, and large rotating machinery protection systems, once the core processor of the Safety Instrumented System (SIS) fails or needs to be replaced, engineers face much greater pressure than ordinary control systems. Because any incorrect operation may result in device shutdown, production interruption, and even personal injury. And Rockwell Automation's Trusted ®  The TMR processor (common models T8111 and early T811B) is the most important computing and control center in this type of security system. A clear set of technical guidance and troubleshooting methods is crucial when it malfunctions or when a discontinued model needs to be upgraded.

Based on the Trusted TMR Processor product manual (ICSTT ‑ RM038) and engineering practice experience, this paper analyzes the the third mock examination redundancy (TMR) architecture, hardware characteristics, installation configuration, fault diagnosis and scanning time estimation methods of the processor in detail. Whether you are an engineer maintaining an outdated Trusted system or someone designing a new Safety Logic Controller (SIL 3), this article can provide you with actionable references.


Product Overview: Why Trusted processors can achieve SIL 3

2.1 Overview of Core Features

The Trusted TMR processor is a Trusted processor ®  The main processing component of the system, which adopts triple module redundancy (TMR) and hardware implemented fault tolerance (HIFT) architecture, can contain three independent processor fault containment regions (FCRs) in a single module. Each FCR includes an NXP PowerQUICC II series processor, local memory (EPROM, DRAM, Flash ROM, Flash RAM), and voting logic circuitry.

Key features include:

TMR fault tolerance: Supports 3-2-0 degradation mode (two out of three operation, can tolerate one failure; safe shutdown after a second failure).

Extremely fast fault identification and response: dedicated hardware and software testing mechanism, fault detection time is much shorter than the time required for safety actions.

Hot Replacement: No need to reload the program, automatically synchronizes with education after inserting a new module.

IEC 61131-3 programming language: Complies with international standards and facilitates the development of safety logic.

IRIG-B time synchronization: supports two formats, B002 (RS422 level) and B122 (amplitude modulation), for high-precision event sequence recording.

Front panel diagnostic port: RS232 serial port, used for system monitoring, configuration, and programming.

Redundant fault relays: Fault and Fail relays, respectively indicating non fatal and fatal faults in the system.

Two configurable RS422/485 serial ports and one RS485 serial port, supporting Modbus RTU slave.

SIL 3 certification: Suitable for applications with the highest safety integrity level according to IEC 61508.

2.2 Internal structure and voting mechanism of the module

Each processor FCR within the module runs independently, but synchronously executes the same application code in a lock step manner. Each processor performs 2oo3 voting on data from the I/O bus through an input voting device, and sends its own output to the I/O module through three independent bus channels. In the output module, compare the channels again. If one channel of data is inconsistent with the other two channels, the system recognizes it as a fault and automatically cuts off the faulty channel, continuing to operate in 2oo3 mode.

In addition, there is an independent fault containment zone FCR D inside the front panel, which does not participate in safety logic calculations but is responsible for driving the front panel LED, diagnostic serial port, IRIG-B interface, and fault/safety relays. This partition design ensures that non safety function failures do not affect the integrity of safety functions.


Hardware installation and precautions

3.1 Module insertion and removal

The Trusted TMR processor must be installed in the T8100 processor slot (usually located on the leftmost side of the controller rack, slot 0). Installation steps:

Ensure that the adapter unit (such as T8120, used to output IRIG-B and serial signals) is correctly installed on the back of the rack.

Use the unlock key to release the pop-up buckles at the top and bottom of the module, allowing it to fully open.

Grasp the buckle and smoothly push the module into the slot. After the current panel LED lights up, continue pushing it all the way until the module is fully seated.

Close the buckle and hear a "click" sound to confirm locking.

Notes:

The module contains static sensitive components inside, and it is strictly prohibited to touch the connector pins. The housing cannot be disassembled.

If you feel too much resistance, do not forcefully push in. Instead, pull out and check if the pin is bent.

Record the module model, version, and serial number before installation.

3.2 External I/O connector (PL1)

PL1 is a 48 pin DIN41612 E-type connector that provides the following key signals (partially):

Pin signal function

2 Fault Relay (NC): When the system is healthy, the relay is excited, and when there is a fault, it is released

4 Fault Relays (COM)

6 Fault Relay (NO)

8, 10 serial port 1 (RS485)

12,14 serial port 2 (RS422/485 TX/RX)

16,18,20,22 serial port 3 (RS422/485)

24,26 24V PSU low voltage warning, fault shutdown

To use IRIG-B and serial port, the processor interface adapter T8120 must be installed (for the T8111 model, a special adapter is not required in some cases, please refer to the manual for details). T811B requires a T812X adapter.

3.3 Fault/Safety Relay Wiring

Fault and Fail relays are both in normal excitation mode. When the system is healthy, the relay coil is energized, NO is closed, and NC is disconnected. Once a fault occurs, the relay loses power and the contact state flips.

Fault relay: When the system detects a recoverable fault (such as a single FCR fault or channel inconsistency), it will activate and the front panel system health LED will flash red.

Fail relay: When two out of three processors are declared faulty and the system is about to shut down, it will activate and the system cannot continue to operate safely.

It should be noted that in the Active/Standby configuration, the Standby processor drives the relay output, so even if the Active module fails, the relay status seen by the external monitoring circuit will not change due to switching.

Key points of system configuration

The Trusted TMR processor does not require hardware jumpers, and all configurations are completed through the System. INI file and Toolset (IEC 61131-3 programming environment). The following are the parameters that most affect system behavior and security functions.

4.1 Channel inconsistency time (discrepancy_val)

For TMR input/output modules, when the difference in readings between the three channels exceeds the set time, the system will report a channel inconsistency fault. The default value is 2000 ms. This value should be greater than the maximum normal establishment time of the on-site signal, but less than half of the process safety time. Format:

text

Discrepancy_val=2000 (unit: ms)

Similar parameters include:

Dualdiscrapancy_val - Used for Dual I/O modules

Ana_iscrepancy_val - Analog input, in units of 512 counts/volt, default 40 → approximately 78 mV

Do-discrepuval - Inconsistent threshold for digital output channels

4.2 IRIG-B time synchronization configuration

Check the "Inter Range Instrumentation Group" area in the Toolset system configuration, select the mode (B002 or B122), and enable LED monitoring (User2 LED flashing once per second indicates receiving a valid IRIG signal).

Common fault: IRIG source outputs TTL level instead of RS422 level, which can cause the module to fail to decode. After the correct settings, the time will automatically synchronize after the module is started. If the system health LED flashes red and "48 IRIG: Maximum update interval exceeded" appears in the MP log, you can enter the diagnostic port to perform IRIG S to check the status or IRIG I to view register details.

Definition of Status Register Bit:

Bit1: IRIG-B002 input exists

Bit2: IRIG-B122 input exists

Bit3: Time valid (only for seconds)

4.3 Scanning time estimation

The Composite Scan Time of the security system directly determines the security response speed. It consists of four parts:

Input module scanning time=1.3 ms x number of high-density input modules

Output module scanning time=1.6 ms x number of high-density output modules

Application execution time ≈ 0.08 ms x (number of input and output modules) or 0.013 ms x application size (KB)

Communication overhead ≈ 1.25 ms x number of I/O modules x number of communication modules

For example, a system with 4 T8403 digital inputs, 1 T8431 analog input, and 2 T8451 digital outputs (a total of 7 I/O modules and 2 communication modules):

Input scan: 1.3 × 5=6.5 ms

Output scan: 1.6 × 2=3.2 ms

Application execution: 7 × 0.08=0.56 ms

Communication: 7 × 1.25 × 2=17.5 ms

The total is about 27.8 ms. It can be further optimized through "scheduled polling" and "exception writing".


Operation and monitoring

5.1 Interpretation of Front Panel LED

LED green constantly on, green flashing, red off

Healthy A/B/C FCR Health - Fatal Fault -

Health flashing red: Non fatal malfunction (such as single channel abnormality)

Active is in active mode - inactive

Standby is in standby mode and has just switched from Active to Standby

Educate already received education in progress - uneducated/program stopped

Run - Normal Run - Program Stop

Prohibit - I/O lock or switch disable -

System Healthy system health startup/malfunction/self-test failure/module error - illegal status

User1/2 Application Control

When the Healthy LED flashes red, the system will automatically switch to the Standby processor (if present), and the faulty processor needs to be replaced.

5.2 Maintenance Enable Key Switch and Fault Reset Button

Key switch: Run position locks memory; The Maintain location allows downloading programs from the engineering workstation.

Fault reset button: Clear all recorded faults and reset the fault counter. Attention: Although the system LED may return to green after pressing, the accumulated intermittent fault records will be lost. It is recommended to record the fault code first and then reset.


Active/Standby Switching and Troubleshooting

6.1 When to use dual processor configuration

In critical situations, a second Trusted TMR processor can be installed as a hot spare in the Companion Slot (right processor slot). The Standby module runs diagnostics and continuously receives data updates from the Active module. When the Active module fails, the system automatically performs undisturbed switching.

Trigger conditions for switching:

An unrecoverable error has been detected internally in the Active module (such as the Healthy LED flashing red)

The operator opens the pop-up buckle of the Active module (in dual machine configuration)

Send switch command through diagnostic port

Important warning: Never forcefully unplug when the Active module indicates Active mode, otherwise it will cause all I/O modules to enter the default shutdown state.

6.2 Standard steps for replacing faulty processors

Assuming that Active module A is faulty, prepare to insert a new module B:

Insert the new module B into the empty slot (Standby position). After initialization, B becomes Standby and the Educated LED stays on.

At this time, the Inhibit LED may flash (indicating that switching is prohibited due to I/O forcing or other reasons). If Inhibit is on, check if any I/O is forced and cancel the force before continuing.

Pull out the new module B and then reinsert it.

After the second insertion, B will be initialized to Standby, but this time switching is allowed (Inhibit is disabled).

The system automatically raises B to Active, and the original faulty module A becomes Standby (its Healthy LED will flash red).

It is now safe to remove faulty module A for repair.

Note: If the original Active module has not completely failed but needs to be replaced (such as firmware upgrade), a new module can be inserted as Standby, and then the pop-up buckle of the original Active module can be opened to trigger manual switching.

Common troubleshooting guide

Possible causes and solutions for the phenomenon

The module cannot be inserted into the back adapter and is not aligned properly; Pin bending inspection adapter; Observe the pins with a magnifying glass and do not correct them on your own. Contact for repair

After power on, the Healthy LED is completely turned off and the backplane power supply is missing or the fuse is blown. Measure the 24 Vdc input of the backplane; Check the rack power module

A Healthy LED flashing red corresponds to a non fatal fault occurring in FCR (such as memory ECC error, brief communication loss). Record the fault code and reset according to the fault; If it repeatedly occurs, replace the module

System Healthy LED flashing red System failure: IRIG synchronization timeout, I/O module error, Active/Standby mismatch View MP logs; Check IRIG signal; Check the status of all I/O modules

Active and Standby cannot switch I/O forced; Cancel the mandatory configuration for the Standby module system due to inconsistent configuration; Ensure that both modules run the same version of firmware and System. INI

Serial communication abnormal wiring error; Check the definition of pin PL1 for baud rate/protocol mismatch; Confirm Modbus slave address and serial port mode (RS485 half duplex/full duplex)

IRIG time does not update signal type error (B002 provides TTL instead of RS422); The IRIG-B002 differential voltage should be about 1.5 V for low amplitude measurement; the B122 peak to peak value should be ≥ 0.25 V


System isolation and security design

The Trusted TMR processor meets the requirements of IEC 61508 SIL 3 for hardware fault tolerance and systematic safety. Its isolation characteristics include:

Power supply isolation: Each FCR's 24 Vdc power supply is independent and isolated through a backplane.

Diagnostic serial port isolation: The isolation voltage between the RS232 port on the front panel and FCR D is 50 V basic insulation (continuous), and can reach 250 V basic insulation in case of a fault.

Rear serial port and IRIG port: isolated from the module to avoid external interference affecting safety logic.

Grounding suggestion: The GND of the module and the FG of the rack should be connected internally, and the user equipment should connect the two together and uniformly connect them to the system grounding terminal.


Upgrade and replacement strategy

For users who use the earlier model T811B and need to replace it with T8111, please note:

T8111 has a larger internal memory, with a maximum application size of 960 KB (T811B is smaller). However, applications larger than 860 KB may not be able to switch to T810B, so compatibility of application sizes should be ensured when mixed use.

T8111 provides more flexible support for IRIG-B and may not require an additional T8120 adapter (depending on hardware version). Suggest checking the latest release note.

Replacement steps: First, insert the new T8111 into the Standby slot, and switch after successful education; If the application is compatible with the firmware, it can be seamlessly upgraded.

In the scenario of replacing discontinued modules, the Trusted TMR processor is one of the most secure choices. However, due to its complexity and security responsibilities, any replacement operation must be carried out by trained personnel and strictly follow the "Active/Standby Transfer" procedure in the manual.

  • Atlas Copco 48R050-01001 Relay Module
  • Atlas Copco 49-4100-01C5L Power Supply
  • Atlas Copco D303-DL-BASIC Controller
  • Atlas Copco 8433056445 I/O Expander Error Proofing Module
  • Atlas Copco PF4000-G-HW Screwdriver Controller
  • Atlas Copco 1202-66270-9325 Cooler Cover Valve
  • Atlas Copco EA2-TX-100 Dew Point Sensor
  • Atlas Copco PF4000-C-HW Controller 240VAC
  • Atlas Copco 1900 0701 05 Elektronikon Control Panel
  • Atlas Copco PF3107-C-HW Tensor 3-7 Controller
  • Atlas Copco TPS Control 8202900410 Controller
  • Atlas Copco 1900-1005-27 Circuit Board XAS 750
  • Atlas Copco Power Focus SL PF4002-C-HW Controller
  • Atlas Copco 1900520490 Air Compressor Control Panel
  • Atlas Copco QCM2-T-34050 Mass Flow Meter
  • Atlas Copco CSS91-B2 Compressor Controller Module
  • Atlas Copco PF3109-C-DN-HW Industrial Controller
  • Atlas Copco P1900520060 Air Compressor Controller Gateway
  • Atlas Copco Coupling 1635099600 Compressor Part
  • Atlas Copco ACTA 4000 Torque Calibrator
  • Atlas Copco 1626850005 Compressor Control Panel
  • Atlas Copco DMC50412 Digital Motion Controller
  • Kontron 2-DH34-0100-03 Atlas Copco SOKO-M@C-IIA-70 HMI 12-24V
  • Atlas Copco PF3107-G-HW PF3107GHW Controller
  • Atlas Copco PF3109-G-DN-HW PF3109GDNHW Controller
  • Atlas Copco 8433-2742-00 Power Supply Module
  • Atlas Copco 1900-0710-82 Controller Module
  • Atlas Copco 9040120204 Industrial Component
  • Atlas Copco 2906-0674-00 Zr55-90 8000H Maintenance Kit
  • Atlas Copco 1900 0701 23 High Range Regulator for Compressor Controller
  • Atlas Copco 4220263610 PF4 Tool Cable 10M ST Cable
  • Atlas Copco XC2002 1604951601 Compressor Panel
  • Atlas Copco S9 Tensor PF3009-G-DN-HW Controller
  • Atlas Copco 80471.000009 Pneumatic Roller Screw Unit
  • Atlas Copco 8433710005 PF4000-C-HW Compact Controller Profibus
  • Atlas Copco PF4002-G-HW Power Focus Controller
  • Atlas Copco 8431038150 Impulse Nutrunner
  • Atlas Copco PF6000 Power Focus Nutrunner Controller
  • Atlas Copco 1626850006 Compressor Controller Panel
  • Atlas Copco STR61-70-13 Tensor Angle Wrench
  • Atlas Copco ETV ST61-40-10 Right Angle Electric Screwdriver with Cable
  • Atlas Copco MK5S Touch Display Controller P1900520400
  • Atlas Copco 1900520020 Controller Panel for Compressor
  • Atlas Copco SRTT-B 1000Nm-50 Transducer 8059094675
  • Atlas Copco ETV ST61-50-10 Right Angle Electric Screwdriver with Cables
  • Atlas Copco 4240070100 Power Supply Module
  • Atlas Copco TC-52S-I TC52SI Controller
  • Atlas Copco ACTA 4000 QC Torque Calibrator
  • Atlas Copco 8433 1236 51 ETV S42-10-10 Right Angle Nutrunner
  • Atlas Copco ETV STB63-50-B10-BCR-IRCW Tensor STB Right Angle Nutrunner
  • Atlas Copco PF6000 SE-10523 Screwdriver Control System
  • Atlas Copco Power MACS TC52S 4240 0442 81 Controller
  • Atlas Copco 1900071162 Operator Interface Panel
  • Atlas Copco 4230-1705-80 I/O Expansion Module
  • Atlas Copco 8433 0005 10 Power Supply Module
  • Atlas Copco 8433-0020-20 Interface Module
  • Atlas Copco TC-4000-S 8435 6500 00 Controller
  • Atlas Copco PF4002-C-HW Power Focus SL Controller
  • Atlas Copco STanalyser STA-6000 8059095560 Torque Analyzer
  • Atlas Copco ComNode 2 Touch 8433271110 Communication Gateway
  • Atlas Copco PF3000-C-HW Tensor S4 S7 RBU Controller
  • Atlas Copco PPBE0613 24VAC Control Panel
  • Atlas Copco PF3000-C-HW Tensor S4 S7 Controller
  • Atlas Copco Neos ARC-D130-S+ Inverter Drive
  • Atlas Copco Power Focus SL PF4002-G-HW Controller
  • Atlas Copco 8436 6770 00 ILT Base Station
  • Atlas Copco 1900520400 Air Compressor Control Panel
  • Atlas Copco 1900-0711-51 Display Keypad Unit
  • Atlas Copco 1900-0710-52 Communication Control Board
  • Atlas Copco 1900-0701-04 Control Interface Module
  • Atlas Copco 8092 1143 40 SRTT Transducer 180Nm
  • Atlas Copco MT Focus 6000 Controller with Pump and Screwdriver
  • Atlas Copco Elektronikon GraphicPlus Controller PPBE0622 PPBE0633
  • Atlas Copco PF3109-G-DN-HW Tensor 8-9 Power Focus Nutrunner Control
  • Atlas Copco Elektronikon P1900520440 Touch Controller
  • Atlas Copco Power Focus 8 Controller 8436280002
  • Atlas Copco 8436 1500 03 FlexCarrier 3-Slot Torque System Component
  • Atlas Copco Power Focus 6000 PF6000 Industrial Controller
  • Atlas Copco TC-4000-P-PB-ES Power Macs Controller
  • Atlas Copco 8433-0015-20 8433001520 Cable Assembly
  • Atlas Copco 49X10301AB Pressure Transducer Sensor
  • Atlas Copco 8436180002 Replacement Filter Element
  • Atlas Copco C4700A01V216 Compressor Control Module
  • Alcatel-Lucent 3HE01019AAAA01 High-Speed Interface Module
  • Alcatel-Lucent 111381 Power Distribution Module
  • Alcatel TN 2523 1:1 CDN III Module – MRPQAE3
  • Alcatel-Lucent 3he06151aaac01 8-Port Interface Module – IPUIBKB3AA
  • Alcatel-Lucent LNW46 DMX Metro OC12 Interface Module – 108694878
  • Alcatel-Lucent 41A12C FT-2000 Optical Transponder Unit – 108188053
  • Alcatel-Lucent 8DG02607AA POW100 DC-DC Converter Module
  • Alcatel-Lucent LambdaXtreme WWBQ21 40G Optical Transponder
  • Alcatel-Lucent TN1891 5ESS Protocol Handler PHV5 Commcode 108747064
  • Alcatel-Lucent 300-0303-900 T1D3PDL1AE Digital Matrix Card
  • Alcatel-Lucent G-821M-A Module
  • Alcatel Lucent MPT-GC Eth 1G+ARM TX 81-86GHz 3DB80005AAAAO1
  • Nokia 3KC48990AB 1830PSS 16FAN2 Fan Unit
  • Alcatel 3EC17041AA PSPC-G4 PCB CP011200552
  • Alcatel 300-0437-906 Rev F DEXCS DMC T1D1L0S Module
  • Alcatel-Lucent 3DW03697ABBA01 TFD64A Module
  • Alcatel-Lucent AWR12 S1-1 UN Interface T3PQAC3AAA
  • ALCATEL LUCENT 9500-MPR ODU RADIO MPT-HC V2 9558HC 3DB20914BAAA03 6GHZ
  • Alcatel-Lucent 9500-MPR ODU 300 11GHz Microwave Radio MPT 3DB23035AEAA01
  • Alcatel 2C7-1005-000 Teflon Bell Jar Holder Ring – 146111
  • Alcatel-Lucent BNJ118 S1:4 Circuit Board – Interface Module
  • Alcatel-Lucent 9500-MPR ODU 300 6GHz Microwave Radio MPT 3DB23215AFAA01
  • Alcatel 3EM04001AA Signal Processing Unit with Accessory Cards
  • Alcatel VAUCAL5KAB AA1418FE2BG 3FE67437AAD02 Interface Card
  • Alcatel-Lucent 1642 Edge Multiplexer N1217P YF – Access Node
  • Alcatel-Lucent 3HE07158BA 7750 SR-12 12-Port 10GIGE MultiCore IMM IPUCA741AA
  • Alcatel 101200429000 Power Divider 746-776 MHz with Heatsinks
  • Alcatel-Lucent 9500-MPR ODU 300 MPT 6GHz 3DB23215ADAA01 High Power Radio
  • Alcatel-Lucent 9500-MPR MPT-HC 23GHz 2/2P ODU Radio 3DB20474BA
  • Alcatel-Lucent 9500-MPR ODU 300 MPT 6GHz 3DB23215AAAA01 Low Power Radio
  • Alcatel 3BA52126ABAA OmniPCX 4400 Compact Cabinet
  • Alcatel-Lucent 3HE12300AA 7750 SR-1 Subrack with Licenses
  • Alcatel 300-1368-903 Rev C DEXCS SPA-1 T1PQAC1 Line Card
  • Alcatel-Lucent 408977981 WOWUAB6HAA 10G XPR OTU2 XPonder Card
  • Alcatel-Lucent-Nokia 3HE08423AARC01 7750 SR Control Processor Module IPUCBGZ1AA
  • Alcatel-Lucent 9500-MPR ODU 300 MPT 6GHz 3DB23215ABAA01 Low Power Radio
  • Alcatel-Lucent CPU7-2 3BA23259ABJE 05 Control Processor Module
  • Alcatel WTM11AD 3DW03915DABA01 Optical Transponder Module
  • Alcatel-Lucent 1340FMPK Card Chip BA5IVY6BAA – Processor Module
  • Alcatel-Lucent 3HE06151ACAC01 Control Fabric Module
  • Alcatel-Lucent 9500-MPR 18GHz 1P-1 Protection ODU Radio 3DB20433BA AA04
  • Alcatel-Lucent 9500-MPR ODU MPT-HC 18GHz Radio 3DB20433BAAA04
  • Alcatel-Lucent SM269 LMPQ04KAXX Circuit Pack – Interface Module
  • Alcatel OME25HP Filter Cartridge – 107494
  • Alcatel-Lucent ALU-BZ74 99BC-4 –48V Battery Cabinet