Sc300E Functional Overview - ABB Triguard SC300E Safety Manual

Triple modular redundant safety controller
Hide thumbs Also See for Triguard SC300E:
Table of Contents

Advertisement

2.3.2

SC300E Functional Overview

A Triguard SC300E system has a fully triplicated architecture from input modules to output
modules. All Triguard SC300E input and output modules interface to three isolated I/O
communications buses, each being controlled by one of the three processor modules.
At the input modules, field signals are filtered and then split, via isolating circuitry, into three
identical, signal processing paths. Each path is controlled by a microcontroller that co-ordinates
signal path processing, testing and signal status reporting to its respective processor, via one of
the triplicated I/O communications buses.
Each of the processors communicates with its neighbours via read only, serial communications
links. The processors synchronise at least once per application logic execution cycle, and each
reads the input, output and diagnostic status of its neighbours. Each processor correlates and
corrects its memory image of the current state of the system using a 2-oo-3 software vote,
logging any discrepancies found in a local diagnostic history table.
Each processor then executes its programmed application logic and sets its respective outputs,
via the I/O communications bus, to the required state.
Commanded output states are received by an output module's microcontrollers which, using
2-oo-3 hardware voters, set the outputs to the field. Any discrepancy between a commanded
output state and the field output is detected by the microcontrollers and reported to the
appropriate processor.
All input and output modules can be configured to use a hot spare partner module. In the event
of a fault on the main I/O module its duty can be taken over by the hot spare partner, allowing
repairs to be effected.
In maximum configuration a single SC300E system can support a main chassis and 14
extension or remote chassis. Each chassis can be populated with 10 modules each containing
up to 32 I/O channels, however, for safety configurations all outputs are configured for dual slot
hot repair. Input modules may be configured for single slot hot repair only where the input
configuration or process safety time allows.
Issue 5 - September 2006
Page 9 of 65

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents