Internal diagnostics, 16 safety networks – Rockwell Automation AADvance Controller Safety Manual User Manual
Page 50

3-16
Document: 553630
ICSTT-RM446K-EN-P Issue: 10
_C
Safety Manual (AADvance Controller)
Internal Diagnostics
The AADvance controller embodies sophisticated internal diagnostic systems
to identify faults that develop during operation and raise appropriate alarm and
status indications. The diagnostic systems run automatically and check for
system faults associated with the controller (processor and I/O modules), and
field faults associated with field I/O circuits.
Safety wiring principles shall be employed for field loops if it is
necessary for the user to guard against short circuit faults between I/O
channels (e.g. to comply with NFPA-72 requirements). The AADvance
controller internal diagnostics do not detect external short cicuits between
channels.
The diagnostic systems report a serious problem immediately, but filter non-
essential safe failures to avoid spurious alarms. The diagnostic systems monitor
such non-essential items periodically, and need a number of occurrences of a
potential fault before reporting it as a problem.
The internal diagnostics detect and reveal both safe and dangerous failures. A
dual module arrangement, for example, diagnostics can address dangerous
failures and help redress the balance between failure to respond and spurious
responses. A dual system could therefore be 1oo2D reverting to 1oo1D on
the first detected fault and reverting to fail-safe when both modules have a
fault.
Safety Networks
AADvance provides two safety network functionality that will allow data
exchanges across a SIL 3 rated safety communication across the Ethernet
communications link:
SNCP (Safety Network Protocol)
Peer-to-Peer
SNCP Safety Networks
SNCP (Safety Network Control Protocol) is the Safety Protocol that
allows elements of an AADvance System to exchange data. AADvance SNCP is
a SIL 3 certified protocol which provides a safety layer for the Ethernet
network making it a "Black Channel". Data is exchanged by creating a
relationship between variables in different AADvance controllers; this is called
"Binding Variables". Once variables are bound between controllers the SNCP
protocol provides a transparent SIL 3 Certified layer allowing safety related
data to be passed between AADvance controllers.