I/O configuration variants
6.2 Fail-safe operation
CPU 410 Process Automation/CPU 410 SMART
58
System Manual, 05/2017, A5E31622160-AC
6.2
Fail-safe operation
Ensuring functional safety
A safety-related system encompasses sensors for signal acquisition, an evaluation unit for
processing the signals, and actuators for signal output.
Figure 6-1
Processing chain: acquire, process, output
All of the components contribute to the functional safety of the system, in order, when a
dangerous event occurs, to put the system into a safe state or to keep it in a safe state.
Safety of fail-safe SIMATIC Safety Integrated systems
For SIMATIC Safety Integrated systems, the evaluation unit consists, for example, of fail-
safe single-channel CPUs and fail-safe dual-channel I/O modules. The fail-safe
communications take place via the safety-related PROFIsafe profile.
Functions of a fail-safe CPU
A fail-safe CPU has the following functions:
●
Comprehensive self-tests and self-diagnostics check the fail-safe state of the CPU.
●
Simultaneous execution of standard and safety programs on one CPU. When there are
changes to the standard user program, there are no unwanted effects on the safety
program.
S7 F/FH Systems
The S7 F Systems optional package adds security functions to the CPU 410. The current
TÜV certificates are available on the Internet: TÜV certificates
http://support.automation.siemens.com
) under "Product Support".
Fail-safe I/O modules (F-modules)
F-modules have all of the required hardware and software components for safe processing
in accordance with the required safety class. This includes wire tests for short-circuit and
cross-circuit. You only program the user safety functions.
Safety-related input and output signals form the interface to the process. This enables, for
example, direct connection of single-channel and two-channel I/O signals from devices such
as EMERGENCY STOP buttons or light barriers.