beautypg.com

1 fault detection – Rockwell Automation 8000 Series TMR System  User Manual

Page 24

background image

OPERATOR AND MAINTENANCE MANUAL

D o c N o 5 5 2 8 6 4

P a g e 1 4 o f 2 2

I s s u e 0 2 J u n e 2 0 0 4

5.1 FAULT DETECTION

There are three levels of fault detection used in the 8000 Series

System:

1. Discrepancy logic in each I/O module compares the 8000 Series TMR

Processor output data on each bus cycle. A fault is recorded whenever the
data in one processor disagrees with the other two processors of the 8000
Series
TMR Processor.

2. Loopback logic on Interfaces and I/O modules is exercised by the 8000

Series TMR Processors on a background basis to detect output data faults.

3. Self-test circuitry in the 8000 Series TMR Processor and 8000 Series TMR

Interface. In addition, power supplies contain circuits for checking their
output voltages.

The 8000 Series TMR Processor is responsible for sorting the fault information
received from the various levels and alerting the operator when system repair is
required. Faults are categorised as transient or permanent based on the rate at
which they occur. A separate filtering algorithm is applied to each fault type,
preventing nuisance alarms from occurring on a transient fault. Figure 1 illustrates
this filtering algorithm.

Transient

Transient Reset

Permanent Error Threshold

Permanent

Latched Until Reset

Test Cycle

Transient

Transient

Transient

Figure 1 Fault Filtering

The system checks its fault status on a cyclic basis and if a fault is detected during
that cycle, it increments a fault counter and records a transient fault. If a fault is not
detected, the counter is decremented. If the counter value exceeds a threshold, a
permanent fault is recorded and the counter state is held until the operator
executes a reset. Whilst in the permanent state, the operator is alerted to the
failure by various system annunciators. The 8000 Series

System allows

approximately four faults in succession before a permanent fault is recorded. If a
fault is detected on a 8000 Series TMR Processor, a recovery process is
automatically initiated to re-synchronise the module and update its memory. If the
recovery process fails after the fourth attempt, no further attempts are made and
the fault is annunciated.