ENG_1002694.XML
The PROFIsafe profile enables safety-related communication between the automation system (controller) and the process I/O via both PROFIBUS and PROFINET. The decision for choosing either PROFINET IO or the PROFIBUS DP/PA fieldbuses has a significant influence on the architecture of the safety-related system.
Safety-related design versions with PROFIBUS
In the case of a safety-related system with PROFIBUS communication integrated into SIMATIC PCS 7, a distinction is made across all architecture levels between two design versions:
- Single-channel, non-redundant design
- Redundant, fault-tolerant design
Both design versions are extremely variable, and offer a large scope for different customer requirements. Standard automation (basic process control) and safety-related functions can be combined flexibly, not only in the area of distributed I/O. Even at the controller level, they can be combined in one system or separated. In addition, there are numerous possibilities arising from the use of flexible modular redundancy.
G_PCS7_XX_00130
Safety-related design versions with PROFIBUS
At the individual architecture levels (controller, fieldbus, I/O), you have the configuration alternatives shown in the figure in line with the I/O used (ET 200SP HA, ET 200iSP, ET 200M remote I/O stations or PROFIBUS PA devices with PA profile 3.0 or higher).
Safety-related design versions with PROFINET
Safety-related AS single stations (F systems) and AS redundancy stations (FH systems) from the S7‑400 series can be networked simply and effectively with remote I/O stations via PROFINET IO. For this purpose, the PN/IE interface integrated in the CPU and the corresponding PROFINET interface module in the remote I/O stations (e.g. IM 155-6 PN HA for ET 200SP HA) are available on the automation system side.
The availability of the I/O devices on an AS Single Station (F-system) can be increased by a ring topology with media redundancy. If the transmission link in the ring is interrupted at one point, for example, due to a break in the ring cable or the failure of a station, the redundancy manager then immediately activates the alternative communication path.
G_PCS7_XX_00974
Safety-related PROFINET IO communication with media redundancy
The maximum availability with minimum fault reaction times is achieved by the AS redundancy station (FH system) in conjunction with the redundant PROFINET configuration R1. From the CPUs of the H system onwards, the R1 devices are connected via two separate line structures. In order to increase availability, we recommend reverse cabling (as shown in the blueprint). In contrast to the single-sided I/O device connection to only one CPU, failure of a CPU in this case does not automatically lead to failure of the connected I/O devices.
G_PCS7_XX_00975
Safety-related PROFINET IO communication with system redundancy