Overview Safety over EtherCAT. EtherCAT Technology Group



Similar documents
EtherCAT Cutting Costs with High-speed Ethernet

High Speed Industrial Ethernet for Semiconductor Equipment

Generic term for using the Ethernet standard in automation / industrial applications

Virtual KNX/EIB devices in IP networks

I.S. 1 remote I/O system Redundant coupling via PROFIBUS DP

Beckhoff TwinCAT. Configuring the TwinCAT I/O System

Complete Power-Line Narrow Band System for Urban- Wide Communication

FOUNDATION Fieldbus High Speed Ethernet Control System

Safety Integrated. SIMATIC Safety Matrix. The Management Tool for all Phases of the Safety Lifecycle. Brochure September Answers for industry.

DATA COMMUNICATION BETWEEN PROGRAMMABLE LOGIC CONTROLLERS IN THE INDUSTRIAL DISTRIBUTION APPLICATIONS

User manual Compact Web PLC WP240 series IEC-line

EtherCAT Communication Manual

Overview and Applications of PROFINET. Andy Verwer Verwer Training & Consultancy Ltd

LOCAL INTERCONNECT NETWORK (LIN)

Real-time Ethernet with TwinCAT network variables

In-Vehicle Networking

524 Computer Networks

Linear Motion and Assembly Technologies Pneumatics Service. Industrial Ethernet: The key advantages of SERCOS III

Getting Started with CANopen Version Application Note AN-AON

How To Design A Layered Network In A Computer Network

DeviceNet Bus Software Help for Programming an Allen Bradley Control System

PROFINET the Industrial Ethernet standard. Siemens AG Alle Rechte vorbehalten.

Positioning Controller

How To Write A Profibus Dpl (Profibus) Program

Absolute rotary encoder GEL 235EC

CPU PN/DP: Configuring an ET. 200S as PROFINET IO device SIMATIC. PROFINET CPU PN/DP: Configuring an ET 200S as PROFINET IO device

From Fieldbus to toreal Time Ethernet

BECKHOFF. Application Notes. BC9000: Getting Started Guide. For additional documentation, please visit.

Application of RT-Preempt Linux and Sercos III for Real-time Simulation

Industrial Requirements for a Converged Network

19 Comparison of Ethernet Systems

Welcome. People Power Partnership PROFIdag 2013 Peter Van Passen Sales & Business Development Manager HARTING Electric 1/44

DeviceNet Communication Manual

Configuration of Fieldbus Devices with Remote Access

Funktionale Sicherheit IEC & IEC 62443

ZME_05459 Wall Blind Control Set for Busch-Jaeger DURO 2000 Firmware Version : 1.8

PRESENCE DETECTOR PD-C360i/24 KNX ECO (EP )

Introduction to RACE FUELS Hans-Christian von der Wense Munich, Germany

SAFETY MANUAL SIL Switch Amplifier

Process Control and Automation using Modbus Protocol

APNT#1168 Modbus - Establishing Communications Hints

4511 MODBUS RTU. Configuration Manual. HART transparent driver. No. 9107MCM100(1328)

Quality of Service in Industrial Ethernet Networks

Programmable set for Ethernet Modbus/TCP in IP20 TI-BL20-PG-EN-8

Machineontwerp volgens IEC 62061

Industrial IT Ó Melody Composer

Degree programme in Automation Engineering

ModBus Server - KNX. Gateway for integration of KNX equipment into Modbus (RTU and TCP) control systems.

LIN (Local Interconnect Network):

Link Layer. 5.6 Hubs and switches 5.7 PPP 5.8 Link Virtualization: ATM and MPLS

Brake module AX5021. Documentation. Please read this document carefully before installing and commissioning the brake module!

Table of Contents. Creating a VC1000 Network... 3

GAM900/GAM900S. Acceleration precisely measured and safely monitored

Programmable set for Ethernet Modbus/TCP in IP67 TI-BL67-PG-EN-2

High Availability and Safety solutions for Critical Processes

Hirschmann Networking Interoperability in a

ETS4 Diagnostics. KNX Association

DVPPF02-H2. PROFIBUS DP Slave Communication Module Application Manual

OSI Layers in Automotive Networks

How To Understand The Internet Of S (Netware)

Internet of things (IOT) applications covering industrial domain. Dev Bhattacharya

Hardware safety integrity Guideline

CODESYS in Mobile Automation

Ponto Series. A new concept for automation

EE4367 Telecom. Switching & Transmission. Prof. Murat Torlak

Internet Architecture and Philosophy

Fieldbus Protocol For Secured Wireless Sensor Network Communication in Process Automation

LENORD. +BAUER... automates motion. Fieldbus connection absolute encoders CANopen. Reference. Communication profile DS-301 Device profile DS-406

The OSI Model and the TCP/IP Protocol Suite

Internet Packets. Forwarding Datagrams

Optimize your simple machines... Modicon M218 Selection Guide

Overview of Network Hardware and Software. CS158a Chris Pollett Jan 29, 2007.

IntesisBox KNX Modbus TCP master

applicomio Profibus-DP

Remote control of CAN-based industrial equipment using Internet technologies

Documentation for. KL2602 and KL2622. Two-channel Relay Output Terminals for 230 V AC / 30 V DC. Version: 1.4 Date:

Value Paper Author: Edgar C. Ramirez. Diverse redundancy used in SIS technology to achieve higher safety integrity

SIMATIC NET. CP AS-Interface Master B C. Preface Contents. Technical Description and Installation Instructions Interface to the User Program

Manual. MOVIAXIS MX Multi-Axis Servo Inverter XFE24A EtherCAT Fieldbus Interface. Edition 08/ / EN

Series: IDAM Servo Drive E Digital Motor Drive - DMD

Inwall 4 Input / 4 Output Module

Light scene push button 8gang comfort flush-mounted xx

Fiessler Programmable Safety Center. Flexible Hard- and Software concept. Available with a safe bus system or/and two counter inputs

Chapter 13. PIC Family Microcontroller

PROFIBUS diagnostics and network monitoring

LIN (Local Interconnected Network)

An enhanced communication scheme for 4DIAC

PROFINET IO Diagnostics 1

4 non-safe digital I/O channels 2 IO-Link Master V1.1 slots. Figure 1. Figure 2. Type code. TBPN-L1-FDIO1-2IOL Ident no

Foxboro Evo Process Automation System

Computer Networks. Definition of LAN. Connection of Network. Key Points of LAN. Lecture 06 Connecting Networks

Machine Safety Design: Safety Relays Versus a Single Safety Controller

ELEC3030 (EL336) Computer Networks. How Networks Differ. Differences that can occur at network layer, which makes internetworking difficult:

Z-TWS4. Multifunction Straton / LINUX Controller.

Why SIL3? Josse Brys TUV Engineer

Set for PROFINET IO in IP20 TI-BL20-EN-PN-4

Features and application fields for the CANopen Safety Chip CSC01

CIA405.lib. Contents. WAGO-I/O-PRO 32 Library

CANtrol EC Modular Control System Powerful and versatile

Application Note: AN00121 Using XMOS TCP/IP Library for UDP-based Networking

Transcription:

Overview EtherCAT Technology Group

Technology Architecture Definitions State Machine Telegram Summary EtherCAT Technology Group 2

International Standards for Safetybus Systems BGIA Test principles GS-ET-26 Test principles of the German Institute for Occupational Safety and Health Scope: Bus systems for safety related communication IEC 61784-3 DIGITAL DATA COMMUNICATIONS FOR MEASUREMENT AND CONTROL Part 3: Profiles for functional safety communications in industrial network - General rules and profile definitions EtherCAT Technology Group 3

IEC 61784-3 EtherCAT Technology Group 4

Safety communication as part of a safety system Safety communication 1% Safety Function Safety communication Sensor(s) Bus Logic Bus Actor(s) 1% Probability of failure for the safety system: PFH Safetyfunction = PFH Sensor + PFH Logic + PFH Actor + 2x PFH Bus < 10-8 10-7 /h for SIL 3 (IEC 61508) The IEC 61784-3 highly recommends that the safety communication channel does not consume more than 1 % of the maximum PFD or PFH of the target SIL for which the functional safety communication profile is designed: PFH Bus < 10-9 /h for SIL 3 More than 100.000 years communication without an undetected Error! EtherCAT Technology Group 5

(FSoE) defines a safety communication layer for the transportation of safety process data between safety over EtherCAT devices. FSoE is an open technology within the EtherCAT Technology Group (ETG). The protocol is approved by an independent Notified Body (TUV Sued Rail GmbH). EtherCAT Technology Group 6

Hardware Architecture 1-channel communication system Model A according to IEC 61784-3 Annex A Controller A Safety Protocol Controller A Safety Protocol Device 1 Controller B Safety Protocol Controller B Safety Protocol EtherCAT Slave Controller Controller B Safety Protocol Controller A Safety Protocol EtherCAT Slave Controller Device 2 Controller A Safety Protocol Controller B Safety Protocol PHY PHY PHY PHY Magnetics Magnetics Magnetics Magnetics RJ45 RJ45 RJ45 RJ45 EtherCAT Technology Group 7

Software Architecture Black channel approach with safety and non-safety data on the same bus Safety Application Device 1 Standard d Application Standard d Application Device 2 Safety Application Safety over EtherCAT Protocol Safety over EtherCAT Protocol Safety over EtherCAT EtherCAT Communication Interface EtherCAT Communication Interface EtherCAT DLL and AL EtherCAT Telegram Safety data container (FSoE Frame) EtherCAT Technology Group 8

System Example Decentralized Safety-Logic Standard PLC routes the safety messages Standard PLC Safety Inputs Safety Sensors Safety Outputs Safety Drives Safety Logic EtherCAT Technology Group 9

FSoE Master / Slave Connection FSoE Master Master of a FSoE Connection. The Master initiates the communication. The FSoE Master sends a FSoE Master Frame, which contains the SafeOutputs. A FSoE Master can manage one or many FSoE Slaves. SafeOutputs in FSoE Master Frames FSoE Master EtherCAT Technology Group 10

FSoE Master / Slave Connection FSoE Slaves SafeInputs in FSoE Slave Frames FSoE Slave Slave of a FSoE Connection. The FSoE Slave sends a FSoE Slave Frame, after receiving a valid FSoE Master Frame. The FSoE Slave Frame contains the SafeInputs. A FSoE Slave belongs to one FSoE Master. SafeOutputs in FSoE Master Frames FSoE Master EtherCAT Technology Group 11

FSoE Communication Cycle FSoE Cycle The FSoE Cycle consists of the FSoE Master Frame confirmed by a FSoE Slave Frame. The FSoE Master sends a FSoE Master Frame to the FSoE Slave. FSoE Master Frame With sending the FSoE Master Frame the Master starts a Watchdog-Timer for guarding the FSoE Slave EtherCAT Technology Group 12

FSoE Communication Cycle FSoE Cycle FSoE Slave Frame FSoE Cycle The FSoE Cycle consists of the FSoE Master Frame confirmed by a FSoE Slave Frame. The FSoE Master sends a FSoE Master Frame to the FSoE Slave. With sending the FSoE Master Frame the Master starts a Watchdog-Timer for guarding the FSoE Slave The FSoE Master only generates a new FSoE Master Frame after receiving a valid FSoE Slave Frame. This starts a new cycle. EtherCAT Technology Group 13

FSoE Watchdog Time FSoE Watchdog Time FSoE Watchdog Time Every device guards that the partner sends a new FSoE Frame within the configured FSoE Watchdogzeit If the Watchdog expires, the devices change to the Reset State. EtherCAT Technology Group 14

FSoE Connections Connection-ID 1 Connection-ID 3 Connection-ID 2 FSoE Connection The FSoE Connection is a logical connection between an FSoE Master and an FSoE Slave. It shall be a unique Connection-ID in the system. This must be checked within the configuration. EtherCAT Technology Group 15

FSoE Unique Address FSoE Slave Address FSoE Slave Address Beside the Connection- ID every FSoE Slave has in the scope of the system a unique 16-Bit FSoE Slave Address This address can be adjusted at the Device, e.g. via a DIP-Switch. Up to 65.535 Devices can be addressed. EtherCAT Technology Group 16

FSoE State Machine per Connection Reset_ok Reset Every FSoE Connection is handled by an FSoE State Machine. The FSoE Master manages a Session Session_ok Connection Conn_ok Parameter single FSoE State Machine per FSoE Slave. After Power-On the FSoE Master and the FSoE Slave are in the State Reset. The Safe Outputs can only be set in the state Data. Param_ok Data EtherCAT Technology Group 17

FSoE State Machine Error Session Reset In case of an error the devices change to the Reset state. Master: An internal detected Error (communication error or application error) Connection Parameter Slave: An internal error is detected or after receiving a Reset telegram from the Master Data EtherCAT Technology Group 18

FSoE Frame Ethernet-Telegram Ethernet Header EtherCAT Header 1. Datagram 2. Datagram FSoE Frame FSC FSoE Frame The FSoE Frame is mapped as a Container in the process data of the device. CMD Safe Data CRC_0 Safe Data CRC_1 Safe Data CRC_n Conn ID Each device detects a new FSoE Frame, if at least one Bit in the FSoE Frame is changed. Every 2 Byte SafeData are checked by a 2 Byte CRC The maximum number of SafeData is therefore not restricted by the protocol. EtherCAT Technology Group 19

Safety Measures Error Measure Sequence Number Watchdog Connection ID CRC Calculation Unintended repetition Loss Insertion Incorrect sequence Corruption Unacceptable delay Masquerade Repeating memory errors in Switches Incorrect forwarding between segments EtherCAT Technology Group 20

Features The FSoE specification has no restrictions according to: Communication layer and interface Transmission speed Length of safe process data Routing via unsafe gateways, fieldbus systems or backbones is possible. EtherCAT Technology Group 21

Features Residual Error Probability R (p) < 10-9 /h The protocol is developed according to IEC 61508 Safety Integrity Level SIL 3 The protocol is approved by TÜV Süd Rail GmbH (Notified body) Certified products with are available since 2005 Safety-over-EtherCAT is submitted to IEC 61784-3 Functional safety fieldbuses Release date 2010 EtherCAT Technology Group 22

Features FSoE Frame is mapped in the cyclic PDOs Minimum FSoE Frame-Length: 6 Byte Maximum FSoE Frame-Length: Depending on the number of safe process data of the Slave Device Therefore the protocol is suitable for safe I/O as well as for functional safe motion control Confirmed transfer from the FSoE Master to the FSoE Slave and vice versa. Safe Device Parameter can be downloaded from the Master to the Slave at Boot-Up of a FSoE Connection EtherCAT Technology Group 23

Test Protocol test for the devices Connection via EtherCAT Interface Black box Test Test suite available for device manufactures Test suite can be used during device development No special Hardware necessary Independent Test Laboratory for confirmation of conformity EtherCAT Technology Group 24

Certification Process Proposal Device Development with (FSoE) according to IEC 61508 or relevant Product Norm EMC Tests (Increased Levels) FSoE Test IEC 61508 Approval EMC-Lab EtherCAT Test Center Notified Body Device Certification Notified Body EtherCAT Technology Group 25

FSoE Test FSoE Slave FSoE Slave Information File (ESI) XML Equipment under Test (EuT) XML Test Configuration FSoE Slave Test Logic EtherCAT EtherCAT Slave EtherCAT Master Test Report EtherCAT Technology Group 26

Safety engineering in modern automation Mixed network for standard and safety functions Standard network with a decentralized safety island Separate networks for standard and safety functions EtherCAT Technology Group 27

Safety engineering in modern automation FSoE Master Frame FSoE Slave Frame S M FSoE Slave device FSoE Master device M S Connection-ID 1 Configured Master-Slave Connections Communication routed via Standard-PLC EtherCAT Technology Group 28

Safety engineering in modern automation FSoE Master Frame FSoE Slave Frame S M FSoE Slave device FSoE Master device M S Connection-ID 2 S Configured Master-Slave Connections Communication routed via Standard-PLC EtherCAT Technology Group 29

Safety engineering in modern automation S M FSoE Slave device FSoE Master device S Conn-ID 4 S Conn-ID 3 Conn-ID 1 M S Conn-ID 2 S M Multi Master networks Safety groups with group failsafe possible. EtherCAT Technology Group 30

Safety engineering in modern automation S M FSoE Slave device FSoE Master device M S Conn-ID 5 M "Master-Master" Communication possible with Master & Slave implementation in the Master device Unique Conn-ID Used for plant concatenation EtherCAT Technology Group 31

Application Tire and wheel testing machine EtherCAT Technology Group 32

Application Tire and wheel testing machine Advantages for the costumer: Integration of Safety functions in the TwinSAFE system Emergency stop Safety fence monitoring Small switch box directly at the safety fence Optimum interaction between standard automation and safety technology Reduced engineering and hardware costs Simplified wiring Modifications are easy to implement Only one tool needed for Standard and Safety functions TwinSAFE software editor conveniently integrated in the TwinCAT system EtherCAT Technology Group 33

www.ethercat.org EtherCAT Technology Group Dr. Guido Beckmann Ostendstr. 196 90482 Nuremberg, Germany g.beckmann@ethercat.org EtherCAT Technology Group 34