Fault-tolerant automation systems
2.2 Increasing the availability of plants
S7-400H
28
System Manual, 03/2012, A5E00267695-11
Graduated availability by duplicating components
The redundant structure of the S7-400H ensures requirements to reliability at all times. This
means: all essential components are duplicated.
This redundant structure includes the CPU, the power supply, and the hardware for linking
the two CPUs.
You yourself decide on any other components you want to duplicate to increase availability
depending on the specific process you are automating.
Redundancy nodes
Redundant nodes represent the fail safety of systems with redundant components. A
redundant node can be considered as independent when the failure of a component within
the node does not result in reliability constraints in other nodes or in the overall system.
The availability of the overall system can be illustrated simply in a block diagram. With a 1-
out-of-2 system, one component of the redundant node may fail without impairing the
operability of the overall system. The weakest link in the chain of redundant nodes
determines the availability of the overall system
No error/fault
36
36
&38
&38
60
,0
,0
36
36
&38
&38
60
,0
%XV
%XV
%XV
%XV
5HGXQGDQF\QRGHZLWKRRUHGXQGDQF\
Figure 2-3
Example of redundancy in a network without error