SIMATIC S7-400F/FH safety-related automation systems are used in plants with increased safety requirements. They control processes where immediate shutdown presents no danger to personnel or the environment. Two designs are available and they differ as follows:
The additional use of standard modules makes it possible to establish a fully integrated control system for a plant where non-safety-related tasks and safety-related tasks co-exist. The overall plant is configured and programmed with the same standard tools.
You can also find information about SIMATIC S7-400 in Catalog ST 70:
http://www.automation.siemens.com/salesmaterial-as/catalog/en/simatic-st70-chap06-english-2015.pdf
Different design versions can be implemented according to requirements. These are illustrated below using the example of ET 200M distributed I/O:
The plant requires a safety-related controller. Fault tolerance is not required. The following are required:
In the event of a fault, the I/O is no longer available. The safety-related signal modules are passivated.
The plant requires a safety-related controller. Fault tolerance is required on the CPU side. The following are required:
If the CPU, IM 153-2 or PROFIBUS DP line fails, the controller remains available. Failure of the safety-related signal modules or the ET 200M station means the I/O is no longer available. The safety-related signal modules are passivated.
The plant requires a safety-related controller. Fault tolerance is required on the CPU side and the I/O side. The following are required:
In the event of failure of the CPU, IM 153-2, PROFIBUS DP line, safety-related signal modules or ET 200M station, the controller remains available.
Standard and safety-related communication between the central controller and the ET 200M takes place via PROFIBUS DP or PROFINET. The PROFIsafe profile specially developed for safety-related communication supports the transfer of user data for the safety functions within the standard data message frame. Additional hardware components such as special safety buses are not required. The necessary software is either integrated in the hardware components as an expansion of the operating system or loaded into the CPU later as a certified software block.
S7-400F/FH meet the following safety requirements:
The safety functions of the S7-400F/FH are contained in the F program of the CPU and in the safety-related signal modules (F-modules).
The signal modules monitor output and input signals by means of discrepancy analyses and test signal injections.
The CPU checks the proper operation of the controller with regular self-tests, command tests, and logical and chronological program execution checks. In addition, the I/O is checked by means of sign-of-life requests.
If a fault is diagnosed in the system, the system is brought to a safe state.
F-Runtime license
The S7 F-Runtime license must be loaded onto the CPU S7-400H to operate the S7-400F/FH. One license is required for each S7-400F/FH.
The S7-400F/FH is programmed in the same way as the other SIMATIC S7 systems. The user program for non-safety-related plant sections is created with time-tested programming tools such as STEP 7.
S7 F Systems option package
The option package "S7 F Systems" is required for programming the safety-related program sections. The package contains all the necessary functions and blocks for creating the F program. The following software packages must be loaded onto the PG/PC for S7 F Systems to run:
For the F program with the safety functions, special function blocks from the F library are called up with CFC and interconnected. The CFC simplifies the configuring, programming and the acceptance testing of the system. Programmers can concentrate fully on the safety-related application without having to use additional tools.