I/O configuration variants
4.2 Fail-safe operation
CPU 410-5H Process Automation
54
System Manual, 09/2014, A5E31622160-AB
4.2
Fail-safe operation
Ensuring functional safety
A safety-related system encompasses sensors for signal acquisition, an evaluation unit for
processing the signals, and actuators for signal output.
Figure 4-2
Processing chain: acquire, process, output
All of the components contribute to the functional safety of the system, in order, when a
dangerous event occurs, to put the system into a safe state or to keep it in a safe state.
Safety of fail-safe SIMATIC Safety Integrated systems
For SIMATIC Safety Integrated systems, the evaluation unit consists, for example, of fail-
safe single-channel CPUs and fail-safe dual-channel I/O modules. The fail-safe
communications take place via the safety-related PROFIsafe profile.
Functions of a fail-safe CPU
A fail-safe CPU has the following functions:
●
Comprehensive self-tests and self-diagnostics check the fail-safe state of the CPU.
●
Simultaneous execution of standard and safety programs on one CPU. When there are
changes to the standard user program, there are no unwanted effects on the safety
program.
S7 F/FH Systems
The S7 F Systems optional package extends the CPU 410-5H by the safety functions. The
standards met with this optional package are listed in the following TÜV certificate: S7 F
Systems optional package (
http://support.automation.siemens.com/WW/view/en/35130252
Fail-safe I/O modules (F-modules)
F-modules have all of the required hardware and software components for safe processing
in accordance with the required safety class. This includes wire tests for short-circuit and
cross-circuit. You only program the user safety functions.
Safety-related input and output signals form the interface to the process. This enables, for
example, direct connection of single-channel and two-channel I/O signals from devices such
as EMERGENCY STOP buttons or light barriers.