Professional Documents
Culture Documents
Overview
Requirements
Safety over
EtherCAT
Architecture
Definitions
EtherCAT
State machine
Technology Group
Frame structure
Summary
Conformance
Applications
Safety over EtherCAT
Requirements
Requirements
Safety over
EtherCAT
Safety over EtherCAT Technology
Architecture
Architecture
Definitions
Definitions
State machine
State Machine
Frame structure
Telegram
Summary
Summary
Conformance
Applications
Conformance
Applications
Requirements
Functional Safety
Safety over
EtherCAT Protection against malfunction of machines
Architecture Protection of the machine operator against
Definitions dangerous movements
State machine
Frame structure
Summary
Safety functions (Examples)
Conformance Monitoring of the workspace of a machine
Applications Door guarding (with interlocking)
Protection with light curtain / laser scanner
Safe feeding of material
Muting
Safe movement with manual intervention
Two-Hand control
Emergency Stop
Safe operating stop
Safely-limited speed
12.2019 Safety over EtherCAT Seminar 3
Safety in industrial automation
Requirements
Material feeding
Safety over Muting
EtherCAT
Architecture Two-Hand control
Definitions
State machine Protection of workspace
e.g. with Laser scanner
Frame structure
Summary
Conformance
Emergency
Applications stop
Operator
Diagnosis
Safely-limited
Position / Speed Setup /
Maintenance
Requirements
Safety over
EtherCAT
Architecture
Definitions
State machine
Frame structure
Summary
Conformance
Applications
Requirements
Fast reaction
Safety over
EtherCAT applicable for high dynamic drive architecture
Architecture
Definitions
Simplified System
State machine
Frame structure
better clarity
Summary simple cabling
Conformance simple extension of the system
Applications better diagnosis
and therefore: higher safety
Lower costs
Requirements
German approach: BGIA Test principles GS-ET-26
Safety over
EtherCAT Test principles of the German Institute for
Architecture Occupational Safety and Health
Definitions Bus systems for the transport of safety-related
State machine messages
Frame structure
Assessment requirements of the BGIA to evaluate
Summary
safety bus systems
Conformance
Applications
Basis of the IEC 61784-3
IEC 61784-3
DIGITAL DATA COMMUNICATIONS FOR
MEASUREMENT AND CONTROL
Part 3: Profiles for functional safety
communications in industrial network - General
rules and profile definitions
Based on Black Channel approach (see below)
Requirements
Safety over
EtherCAT
Architecture
Definitions
State machine
Frame structure
Summary
Conformance
Applications
Requirements
Safety over Safety Safety logical connection Safety
EtherCAT Communication Communication
Architecture Layer Layer
Definitions Application Black channel Application
State machine
Layer (opt.) Layer (opt.)
Physical
Layer
Repeater,
Switch
Fieldbus, Backplane Fieldbus Fieldbus
Requirements
Safety over Safety Function
EtherCAT
Architecture
Definitions Logical connection Logical connection
State machine
Frame structure 1%
Summary
Sensor(s) Bus Logic Bus Actuator(s)
Conformance
Applications
Probability of failure for the safety function, according to
IEC 61508:
PFHSafetyFunction < 10-8…10-7/h for SIL 3
Requirements
Safety-over-EtherCAT defines a safe communication
Safety over
EtherCAT
layer, to transfer safe process data between Safety-over-
Architecture
EtherCAT devices.
Definitions
State machine FSoE is an open technology
Frame structure
Supported by EtherCAT Technology Group (ETG)
Summary
Conformance
Part of IEC 61784-3 international standard
Applications
The protocol is approved by an independent Notified
Body (TÜV Süd Rail GmbH).
Requirements
1-channel standard communication system
Safety over
EtherCAT Redundant hardware for safety protocol and
Architecture safety-related application
Definitions
State machine
Device
Frame structure
Summary
Controller A Controller B
Conformance
Safety Protocol Safety Protocol
Applications
EtherCAT Slave
Magnetics
Magnetics
In controller Out
RJ45
RJ45
PHY
PHY
Port Port
Requirements
Device 1 Device 2
Safety over
EtherCAT
Safety Safety
Architecture
Application Application
Definitions
State machine
Standard Standard
Frame structure Application Application
Summary
Safety over Safety over
Conformance Safety over
EtherCAT EtherCAT
EtherCAT
Applications Protocol Protocol
EtherCAT Telegram
Requirements
Centralized or decentralized Safety-Logic
Safety over
EtherCAT Standard PLC routes the safety messages
Architecture
Standard Safety Inputs Safety Sensors
Definitions PLC
State machine
Frame structure
Summary
Conformance
Applications Centralized Safety Outputs
Safety Logic
Decentralized
Safety Drives Safety Logic
SafeOutputs
in the FSoE
Master Frames
FSoE
Master
SafeOutputs
in the FSoE
Master Frames
FSoE
Master
Start Watchdog
FSoE Watchdog Time
Connection-ID 2
Parameter
Data
FSoE
FSoE
FSoE
HDR
Process Data FCS
2. Datagram of SafeData is therefore
Header Header gram not restricted by the
protocol.
FSoE Frame
Requirements
The FSoE specification has no restrictions according to:
Safety over
EtherCAT Communication layer and interface
Architecture Transmission speed
Definitions
Length of safe process data
State machine
Frame structure
Summary Routing via unsafe gateways, fieldbuses or backbones is
Conformance possible, even wireless.
Applications
Requirements
FSoE Frame is mapped in the cyclic PDOs
Safety over
EtherCAT Minimum FSoE Frame-Length: 6 Byte
Architecture Maximum FSoE Frame-Length: Depending on the
Definitions number of safe process data of the Slave Device
State machine
Therefore the protocol is suitable for safe I/O as well
Frame structure
as for functional safe motion control
Summary
Conformance
Applications Confirmed transfer from the FSoE Master to the FSoE
Slave and vice versa.
Requirements
Probability of failure PFH < 10-9/h
Safety over
EtherCAT Based on Bit Error Probability of 10-2 of underlying
Architecture communication channel
Definitions no restrictions for device manufacturers and end user
State machine
Frame structure
Summary
The protocol is developed according to IEC 61508
Conformance
Safety Integrity Level (SIL) 3
Applications
The protocol is approved by TÜV Süd Rail GmbH
(Notified body)
Requirements
FSoE is disclosed within the ETG.5100
Safety over
EtherCAT
and part of IEC 61784-3 Functional Safety Fieldbuses
Architecture FSoE is recommended Chinese Standard
Definitions GB/T 36006-2018
State machine
Frame structure
Safety over EtherCAT Implementation Support
Summary
Conformance
Support for planning, implementation and
Applications
certification
Requirements
ETG.9001 Safety over EtherCAT Policy
Safety over
EtherCAT defines FSoE conformance testing rules and policies
Architecture
Definitions
FSoE Devices shall fulfil following requirements:
State machine
Frame structure
Compliance to
Summary IEC 61508 and / or relevant sector / product
Conformance standards
Applications IEC 61784-3 general part
ETG.5100 Safety over EtherCAT Specification
EtherCAT Conformance Test Policy (if
applicable)
Passing Functional Safety Assessment and approval
of the FSoE Device by a Notified Body
Requirements
Vendor If applicable
Safety over FSoE EtherCAT
EtherCAT
Test Center Test Center
Device development with Safety over EtherCAT
Architecture
(according IEC 61508 or appropriate product norm)
Definitions Perform FSoE Perform EtherCAT
State machine
Conformance Test Conformance Test
Frame structure
EMC Tests
passed FSoE passed EtherCAT
Summary
(increased immunity) Overall safety FSoE Test
lifecycle process passed
Conformance Conformance
Conformance Test Test
EMC Test Lab
Applications
Performed
by TÜV Süd
Notified Body
Pass of safety
data through
backbone
Fieldbus Machine-wide
Option
safety functions,
e.g. Emergency
Stop or Safe
Standstill
Safety
Option
Connection ID 1
S
Connection ID 2
S S
Applications Conn ID 4
M
Conn ID 1
Conn ID 2
S S M
Conn ID 5
M
Requirements
Safety over
EtherCAT
Architecture
Definitions
State machine
Frame structure
Summary
Conformance
Applications
Requirements
Advantages for the costumer:
Safety over
EtherCAT Integration of Safety functions in the TwinSAFE system
Architecture Emergency stop
Definitions
Safety fence monitoring
State machine
Frame structure
Small switch box directly at the safety fence
Summary Optimum interaction between standard automation and
Conformance safety technology
Applications Reduced engineering and hardware costs
Simplified wiring
Modifications are easy to implement
Only one tool needed for Standard and Safety functions
TwinSAFE software editor conveniently integrated in
the TwinCAT system
Requirements
Safety over www.ethercat.org
EtherCAT
Architecture
Definitions
State machine
Frame structure
Summary
Conformance
Applications