Distributed Safety: Sensor-Actuator Interfacing: SITRAIN Training For
Distributed Safety: Sensor-Actuator Interfacing: SITRAIN Training For
Sensor-actuator
interfacing
Siemens AG © 2010
Contents Page
Sensor-actuator interfacing: overview ................................................................................................. 2
Overview: Sensor/encoder wiring to F-DI modules (recommendation) ............................................... 3
Example: Sensor/encoder interfacing: Cat. 3/PLd/SIL2 ...................................................................... 4
Example: Sensor/encoder interfacing: Cat. 4/PLe/SIL3 ...................................................................... 5
Actuator interfacing to F-DO PM: Cat. 3/4/PLd/e/SIL2/3 (ET200S) .................................................... 6
Actuator interfacing to F-DO PP (S7-300/ET200M) ............................................................................ 7
Actuator interfacing to F power module PM-E F pm (ET200S) ........................................................... 8
Actuator interfacing to F power module PM-E F pp (ET200S) ............................................................ 9
Analog value processing with (SM 336; AI 6 x 13-bit) ......................................................................... 10
Current measurement, 4 to 20 mA (Cat. 3/PLd/SIL2) ......................................................................... 11
Current measurement, 4 to 20 mA (Cat. 4/PLe/SIL3) ......................................................................... 12
Examples of sensor/encoder interfacing: Emergency Stop command devices
and position switches ........................................................................................................................ 13
Series connection of sensors ............................................................................................................... 14
Examples of interfacing ESPE: light curtains/light arrays/laser scanners ............................................ 15
Protective door monitoring, Cat. 4/PL e/SIL3 with tumbler in Cat. 3/PLd/SIL2 .................................... 16
Distinguishing Emergency Off - Emergency Stop, EN 60204-1........................................................... 17
Safe shutdown in compliance with IEC 61800-5-2: STO, SS1, SS2 ................................................... 18
Example: actuator interfacing in Cat. 3/4/PLd/e/SIL2/3 ....................................................................... 19
Example: ET200S load circuit 24V DC/24-230V AC up to 8A 1F-RO fail-safe relay module .............. 20
Single and group deactivation of actuators in Cat. 4/PLe/SIL3 ............................................................ 21
STO in Cat. 4/PLe/SIL3 SS1 and SLS in Cat. 3/PLd/SIL2 ................................................................... 22
Help on use of safety technology ......................................................................................................... 23
Switch
SIMATIC ET 200S PN
SIMATIC
ET 200pro
EMERG
ENCY
STOP
EMERG
ENCY
STOP
Safety Unit
transducer
technology
EMER-
Laser scanners SIRIUS SIRIUS AS- Safe AS- GENCY Light curtain
position Interface Interface Light SIRIUS EMER-
STOP GENCY SIRIUS load
switches safety module curtain safety
STOP feeder
monitor relay
SITRAIN
ST-PPDS/Sensor-actuator interfacing Page 2 Siemens AG © 2010
Notes
....................................................................................................................................
....................................................................................................................................
....................................................................................................................................
....................................................................................................................................
....................................................................................................................................
....................................................................................................................................
....................................................................................................................................
....................................................................................................................................
....................................................................................................................................
....................................................................................................................................
....................................................................................................................................
....................................................................................................................................
....................................................................................................................................
....................................................................................................................................
F-DI
Terminal module
Vs1 Vs2 Vs1 Vs2 Vs1 Vs2
Sensors
1-channel
2-channel
equivalent
2-channel
antivalent
External L+ L+
SITRAIN
ST-PPDS/Sensor-actuator interfacing Page 3 Siemens AG © 2010
Sensor/ When fail-safe input modules are used, the substitute value '0' is forwarded to the
encoder use CPU after the detection of faults, which causes the safety program to execute a
safe reaction. Therefore, pay attention to the fact that the sensors/encoders must
also be implemented in such a way that they supply a 0 signal when the safety
program is to execute the safe reaction.
External L+
External L+ L+
SITRAIN
ST-PPDS/Sensor-actuator interfacing Page 4 Siemens AG © 2010
SITRAIN
ST-PPDS/Sensor-actuator interfacing Page 5 Siemens AG © 2010
DO 0 DO 1 DO 0 DO 1
L+ M P M P M L+ M P M P M
Note:
It is no longer possible to shut down an actuator if a cross
circuit has developed between the P and M switches of the
output.
To prevent cross circuits between the P and M switches of a
fail-safe digital output, you must route the cables used to
connect the relays on the P and M switches in a cross circuit-
proof manner (e.g. as separate, unsheathed cables or in
separate cable ducts).
SITRAIN
ST-PPDS/Sensor-actuator interfacing Page 6 Siemens AG © 2010
ET200S Standard The power module of the potential group in which the F-DO modules are inserted
power modules must be a standard power module. You can find out which of the power modules is
suitable to supply a potential group with fail-safe modules by looking in the
ET200S manuals.
F-DO parameters For some F-DO modules, it is possible to parameterize safety operation for
…S7-300/ET200M SIL2 or SIL3 (the type of test signal injection is specified internally).
…ET200 S/pro/eco For the F-DO modules, no parameterization possibilities exist since they are
generally designed for safety class SIL2/3.
Warning If the actuators are operated with voltages higher than 24V DC (at 230 V DC, for
example) or if the actuators switch higher voltages, safe electrical isolation must
be guaranteed between the outputs of the fail-safe output module and the
components carrying higher voltage (in compliance with the EN 50178 standard).
This requirement is generally met by relays and contactors and particular attention
must be paid to it when using semiconductor switches.
Notes on Variant 1:
The "wire break" fault is only detected if both contactors are disconnected from P
or M due to the wire breaking (not safety-related).
on Variant 2:
The contactors must be connected to L+ and M of the power module in whose
potential group they are located (same reference potential is required).
The "wire break" and "overload" faults are detected only at the P switch of the
F-DO module, and not at the M switch
Address switch
Overvoltage
protection
Output driver 1
Output driver 2
Readback
Logic
Diagnostics
Backplane bus
interface
SF SAFE State F
SITRAIN
ST-PPDS/Sensor-actuator interfacing Page 7 Siemens AG © 2010
PP-switching If loads are to be switched that have a connection between ground and earth
F-DO (e.g. to improve EMC properties) and their supplying power supply unit has a
ground-earth connection, then a PM-switching F-DO module would detect a "short-
circuit", since, from the point of view of the power module, the ground-earth
connection short-circuits the M switch of the module. This problem can be solved
with a PP-switching F-DO module:
Attainable The module switches the P voltage bus via two output drivers in a fail-safe
safety classes manner up to SIL3/Cat.4/PLe.
Wiring For safety reasons, the ground cable to the terminal module must be laid in
Notes duplicate because any interruption of a single ground conductor would prevent the
safety-related shutdown of voltage bus P2.
Note The potential groups 1L+, 2L+ and 3L+ can be supplied by separate power supply
units, but also by one common power supply unit as well.
Fail-safe
power module Standard DO
PM-switching
K5
Cat. 4 Cat. 3
PLe PLd
Cat.SIL3
4 K6
SIL2
SIL3
Note:
The "wire break" fault is detected only if the wire break has disconnected
both contactors from P or M (not safety-related)
SITRAIN
ST-PPDS/Sensor-actuator interfacing Page 8 Siemens AG © 2010
Fail-safe The fail-safe power module PM-E F pm 24VDC PROFIsafe has 2 fail-safe
power module digital outputs (P/M-switching, output current 2 A) and 2 relays for switching the
voltage buses P1 and P2 (output current 10 A).
The voltage buses P1 and P2 can be used to switch the power supply of the
following standard output modules (EM DO1, DO2, DO3 in the figure). The
individual standard DO outputs cannot be activated in a fail-safe manner, but only
deactivated simultaneously or all of them together in a fail-safe manner.
Wiring • The ET200S standard module power supply inputs must be connected to the
Notes fail-safe power module.
• The actuators connected to the standard DOs must always be supplied through
the terminal modules of the fail-safe power modules.
SIL1/Cat2/PL SIL1/Cat2/PL
PM-E F pp d PM-E F pp c
DO DO AO Relay
DO
Backpl.
Electronics
Electronics
Electronics
bus
IM 151
P2 P1
P M
Electronic supply
P
Analog 24V DC
actuator
SITRAIN
ST-PPDS/Sensor-actuator interfacing Page 9 Siemens AG © 2010
PP-switching If loads are to be switched that have a connection between ground and earth
power modules (e.g. to improve EMC properties) and their supplying power supply unit has a
ground-earth connection, then a PM-switching power module would detect a
"short-circuit", since, from the point of view of the power module, the ground-earth
connection short-circuits the power module's M switch.
This problem can be solved with the PP-switching power module:
The power module switches the voltage bar P2 in a fail-safe manner via two
series-connected relay contacts with SIL2/Cat. 3/PLd or SIL3/Cat. 4/PLe.
P2 is available as P on the terminal module, and P1 as M.
Wiring For safety reasons, the ground cable to the terminal module must be laid in
Notes duplicate because any interruption of a single ground conductor would prevent the
safety-related shutdown of voltage bus P2.
Input addressing in
the user program:
IW x
IW x+2
IW x+4
IW x+6
IW x+8
IW x+10
Bit number 15 14 13 12 11 10 9 8 7 6 5 4 3 2 1 0
Significance of the bits sign 214 213 212 211 210 29 28 27 26 25 24 23 22 21 20
Example 0 1 0 0 1 1 0 0 1 1 1 1 1 1 0 0
Warning
SITRAIN
ST-PPDS/Sensor-actuator interfacing Page 10 Siemens AG © 2010
Modules Two fail-safe, redundancy-enabled analog modules of the S7-300 module line are
available for connecting analog sensors/encoders:
• SM 336; AI 6 x 13-bit
• SM 336; F-AI 6 x 0/4 ... 20 mA HART.
Wire break and For the range of 4 to 20 mA required in the safety mode, a distinction is made
underflow test according whether wire break testing is parameterized:
• When wire break testing is parameterized, no underflow testing is
implemented and, in the event of a wire breaking (< 3.6 mA), the PII of the CPU
receives the substitute value 0 instead of the value 7FFFHex
• If no wire break testing is parameterized, in the event of an underflow (< 1.18 mA),
the PII of the CPU receives the substitute value 0 instead of the value 8000Hex
Input The inputs of the analog input module can be used as follows:
utilization • Standard mode:
All 6 channels for current measuring from 0 to 20 mA or 4 to 20 mA or up to
4 channels for voltage measuring (0 to 10 V) and the remaining two channels for
current measuring
• Safety mode: All 6 channels for current measurements from 4 to 20 mA only
Addressing Unlike standard analog modules, fail-safe analog modules are addressed in the
process image area. Therefore, the results of measurements are not accessed via
direct I/O access (which would not be possible in the safety program anyway), but by
access to the CPU's process image.
2-wire
measuring
transducer
- +
4-wire
Recommended
measuring
transducer
+ -
Recom-
mended
Warning
To achieve SIL2 (Category 3) with this wiring, you must install a suitably
qualified sensor, for example in accordance with IEC 60947.
SITRAIN
ST-PPDS/Sensor-actuator interfacing Page 11 Siemens AG © 2010
Encoder supply You are strongly advised to always use the short circuit-proof internal sensor
supply of the module. This internal sensor supply is monitored and its status is
indicated by the Vs LED.
The encoders can also be supplied through an external encoder supply. However,
the stability of the external encoder supply must correspond to the required safety
class SIL2!
Encoder signals Up to 6 process signals can be connected to one analog module. In the safety
mode, only the measuring range of 4 to 20mA is permitted.
Warning
To achieve SIL3 (Category 4) with this wiring, you must install a suitably
qualified sensor, for example in accordance with IEC 60947.
SITRAIN
ST-PPDS/Sensor-actuator interfacing Page 12 Siemens AG © 2010
Encoder supply You are strongly advised to always use the short circuit-proof internal sensor
supply of the module. This internal sensor supply is monitored and its status is
indicated by the Vs LED.
The encoders can also be supplied through an external encoder supply. However,
the stability of the external encoder supply must correspond to the required safety
class SIL3!
Process signals Up to 6 process signals can be connected to one analog module. In the safety
mode, only the measuring range of 4 to 20mA is permitted.
Two redundant sensors are connected to two opposite inputs of the analog module
for each process signal (1oo2 ((2oo2) evaluation).
Emergency Stop
Position switches (e.g. for door monitoring)
command devices
Cat. 2
PLc
SIL1 Position switch with
separate actuator Door monitoring
(or hinge switch) with solenoid switch
Cat. 3
PLd
SIL2
External encoder supply
Cat. 4
PLe
SIL3
Internal sensor/encoder supply by evaluation unit
SITRAIN
ST-PPDS/Sensor-actuator interfacing Page 13 Siemens AG © 2010
Emergency Stop Despite a mechanical 1-channel structure, Emergency Stop command devices
command devices manufactured in compliance with EN ISO 13850 can be used in applications up to
Cat. 4 in compliance with EN954-1 or PLe in compliance with EN ISO 13849-1 and
SIL3 in compliance with EN IEC 62061.
Position Use of an electrically 2-channel, but mechanically only 1-channel position switch
switches is only possible if it is equipped with a separate actuator whose breakage can be
ruled out (see DIN VDE 0113 for details or appropriate measures).
This exclusion of faults is not permitted for Cat. 4/PLe/SIL3!
Solenoid switches SIRIUS solenoid switches are certified for use up to Cat. 4/PL e/SIL 3.
* Note: An average diagnostics coverage of 90%, which can also be achieved with an
external sensor/encode supply, would also be possible to achieve SIL3 in
compliance with EN 62061. However, in compliance with ISO 13849-1, an
average diagnostics coverage is not sufficient for PLe!
EMERGENCY Protective
STOP n door
Closed
Open
Evaluation unit
Evaluation unit Evaluation unit
SITRAIN
ST-PPDS/Sensor-actuator interfacing Page 14 Siemens AG © 2010
OSSD 1
OSSD 1
OSSD 2
OSSD 2
Internal s e n s o r / e n c o d e r
External encoder supply s u p p l y by e v a l u a t i o n u n i t
SITRAIN
ST-PPDS/Sensor-actuator interfacing Page 15 Siemens AG © 2010
... with electron. Sensors with OSSD (Output Signal Switching Device) outputs possess
outputs integrated cross-/short-circuit detection. These must therefore be deactivated on
the evaluation unit (in HW Config in the case of F-DI modules).
... with relays Sensors with relay outputs cannot realize any cross-/short-circuit detection
outputs via their floating contacts.
In the case of Cat. 4/PLe/SIL3 applications, cross-/short-circuit detection must
therefore be activated on the evaluation unit (in HW Config in the case of F-DI
modules).
Release monitoring
Start
Actuator
F-DI
Machine is
at standstill
Hinge Safety
switch position
switch
SITRAIN
ST-PPDS/Sensor-actuator interfacing Page 16 Siemens AG © 2010
Function Locking units with a tumbler are mechanical or electrical units that permit
operation of a machine only when the protective door is closed and latched.
Locking and latching are maintained until the risk of injury from hazardous
machine movement is ruled out.
In this example, a speed or standstill monitor for monitoring hazardous continued
running of a machine is simulated by a pushbutton contact (NO) that is connected
in 1 channel to the fail-safe input module (F-DI). When real speed or standstill
monitors are used, these would have to be connected to the F-DI over 2 channels
(except when a correspondingly certified one-channel sensor/encoder is used)
(2oo2 evaluation).
In the example shown, an actuator fitted on the door moves into a safety position
switch with tumbler. During the potential hazard, the actuator is held (thus latching
the door) by virtue of the fact that a voltage is applied to a solenoid in the safety
position switch. This type of locking is referred to as magnetic force locking.
The solenoid of the safety position switch is triggered via a fail-safe digital output
channel (F-DO).
If the safety position switch fails, the safety function is maintained by the hinge
switch (which also detects when the protective door is open).
Notes For realization of a door tumbler in Cat. 4/PLe/SIL3, two safety position switches,
each with tumbler, should be used.
To achieve Category 4/PL e/SIL 3, for certain actuators (e.g. contactors) it is
imperative to evaluate the actuators' feedback signal by means of the program.
Reading back is not implemented in this example.
"Safe
standstill"
Danger through
SITRAIN
ST-PPDS/Sensor-actuator interfacing Page 17 Siemens AG © 2010
Notes
....................................................................................................................................
....................................................................................................................................
....................................................................................................................................
....................................................................................................................................
....................................................................................................................................
....................................................................................................................................
....................................................................................................................................
....................................................................................................................................
....................................................................................................................................
....................................................................................................................................
....................................................................................................................................
....................................................................................................................................
....................................................................................................................................
....................................................................................................................................
n Initiating
safe shutdown
Stop category 0
n
n Electrical
Stop category 1
isolation from
n Defined braking the
Safe Stop 1 (SS1)
ramp line
t
t Safe Torque Off (STO) is not
n
necessary!
Stop category 2
n Defined braking
ramp
Safe Stop 2 (SS2) t
t Safe Operating Stop (SOS)
(at full torque)
SITRAIN
ST-PPDS/Sensor-actuator interfacing Page 18 Siemens AG © 2010
F-DO DI
Feedback
Electronic output - M
SITRAIN
ST-PPDS/Sensor-actuator interfacing Page 19 Siemens AG © 2010
Note The safety class achieved also depends on the number of switching cycles of the
contactors. In the event of frequent switching, the safety level achieved can be
lower than Cat. 3/PLe/SIL3.
Notes
....................................................................................................................................
....................................................................................................................................
....................................................................................................................................
....................................................................................................................................
....................................................................................................................................
....................................................................................................................................
....................................................................................................................................
....................................................................................................................................
....................................................................................................................................
....................................................................................................................................
....................................................................................................................................
....................................................................................................................................
....................................................................................................................................
PROFIBUS
with
PROFIsafe
230V AC
Actuation via F-DO
(electronic output) 1F-RO
IN M IN M
OUT 2 (24) OUT 2 (24)
Looping
Looping for deactivation
for group group
deactivation of further 1 F-
of further 1 F-ROs
ROs
SITRAIN
ST-PPDS/Sensor-actuator interfacing Page 20 Siemens AG © 2010
Notes
....................................................................................................................................
....................................................................................................................................
....................................................................................................................................
....................................................................................................................................
....................................................................................................................................
....................................................................................................................................
....................................................................................................................................
....................................................................................................................................
....................................................................................................................................
....................................................................................................................................
....................................................................................................................................
....................................................................................................................................
....................................................................................................................................
....................................................................................................................................
Circuit breakers
Emergency
stop (1) Motor M1 and motor M2
in a star circuit
Emergency
Start M1 Start M2 stop (2)
Emergency
Stop all
Acknowledge- Acknowledge-
ment (1) ment (2)
Groups 1 Groups 2
Acknowledge- Motor M1
ment all Contactor Contactor
Contactor K1 Contactor K3
K2 K4
Readback signals
Motor M2
SITRAIN
ST-PPDS/Sensor-actuator interfacing Page 21 Siemens AG © 2010
Function Frequently, the following behavior is required when several actuators are used
within a system: it should be possible to safely deactivated one single actuator
(independently of other actuators). Additionally, it should be possible to safely
deactivate all actuators together.
The example here shows single and group deactivation of actuators. To this end,
two three-phase asynchronous motors are used that can be activated
independently of one another. Each motor is assigned an Emergency Stop button,
which deactivates it safely (single deactivation). There is also an Emergency Stop
button that is used to safely deactivate all motors (group deactivation).
Evaluating the To enable detection of contactor welding, their feedback or readback signals
feedback signals must be evaluated in the safety program. The Distributed Safety function block
library provides a certified function block for this purpose.
A group is deactivated if a readback error is detected in it. The other group can
continue to be activated operationally and can be safely deactivated.
24V
24V
External 24V
supply
PROFIBUS or PROFINET
with PROFIsafe
SITRAIN
ST-PPDS/Sensor-actuator interfacing Page 22 Siemens AG © 2010
STO in Cat. 4 The SINAMICS G120 and G120D with their safety functions STO, SS1 and
PLe/SIL3 SLS are certified in compliance with Cat. 3/PLd/SIL2.
To realize STO in compliance with Cat. 4/PLe/SIL3, it is necessary to install an
additional line contactor in the 400V supply line to the SINAMICS G120/G120D.
Function STO is activated by the F-CPU in the SINAMICS G120/G120D via PROFIsafe (by
means of PROFIBUS or PROFINET). The 400V supply voltage of the SINAMICS
G120/G120D is also deactivated via the line contactor. This deactivation is
monitored via the safe acknowledgement signals of the SINAMICS G120/G120D
(PROFIsafe) and the signaling contact of the line contactor (digital input) in the
safety program.
Contents Attainable
SITRAIN
ST-PPDS/Sensor-actuator interfacing Page 23 Siemens AG © 2010
Notes
....................................................................................................................................
....................................................................................................................................
....................................................................................................................................
....................................................................................................................................
....................................................................................................................................
....................................................................................................................................
....................................................................................................................................
....................................................................................................................................
....................................................................................................................................
....................................................................................................................................
....................................................................................................................................
....................................................................................................................................
....................................................................................................................................
....................................................................................................................................