A
A-22
User manual IC220SDL953 - September 2011
GFK-2731
A 6
Implementation of data flow between the standard
controller and the safety modules
For the parallel communication required between safe components, data flow must be
ensured by the relevant standard controller. Consistency must, therefore, be ensured over
the entire data width of the safe devices.
Data flow within standard infrastructure components is not safety-related. The measures
for safeguarding failsafe communication are implemented in the safe termination devices.
A 6.1
Implementation of data flow with a function block
A copy function block (COPY FB) to safeguard data flow between the VersaSafe modules
is available from GE Intelligent Platforms for certain systems.
A 6.2
Implementation of data flow without a function block
If a function block (COPY FB) is not available for your controller, you must implement data
flow within the VersaSafe system yourself.
The VersaSafe components are represented in the process image of the higher-level con-
troller with a special I/O structure. The structure is mapped in the corresponding device de-
scription.
The components illustrated in Figure A-4 must be copied according to the arrows for the
data flow required between the VersaSafe components. The data/registers in bold are also
useful for the standard application program of the standard controller.
A 7
Enable principle
The enable principle is implemented in the VersaSafe system. For this, all modules with
local outputs have an enable function integrated in the device firmware (ANDed bit-by-bit)
for each local safe output channel. The enable function can be parameterized
(enabled/disabled) for each specific channel.
When the enable function is enabled, the relevant safe local output is ANDed bit-by-bit with
the corresponding standard output of the standard controller (Data-LPSDO register). This
output is then only set if the result of the safety function calculation permits this and the
standard controller has set the corresponding output in the Data-LPSDO register (see also
"I/O image and data flow in a system comprising 1 IC220SDL953 and 3 satellites" on
page A-15).
The enable function is performed according to the single-channel or two-channel
parameterization of the safe outputs.
If data consistency is not ensured, the module shuts down and requests an operator
acknowledgment.