K-WANG

+086-15305925923
Service expert in industrial control field!
NameDescriptionContent
Adequate Inventory, Timely Service
pursuit of excellence 
Ship control system
Equipment control system
Power monitoring system
Current position:
新闻动态
newS
   
Brand

SCHNEIDER Modicon Quantum Safety PLC safety programmable logic controller

From: | Author:Wang | Time :2026-01-20 | 282 visit: | 🔊 Click to read aloud ❚❚ | Share:


SCHNEIDER Modicon Quantum Safety PLC safety programmable logic controller

Modicon Quantum Safety PLC is a safety programmable logic controller launched by Schneider Electric, which complies with the IEC 61508 standard and has a certification level of SIL3. Its core revolves around the implementation of safety functions, covering four dimensions: hardware configuration, programming specifications, communication mechanism, and fault diagnosis. It supports two deployment modes: independent/hot standby (HSBY), and ensures functional safety through dual processor execution, redundant I/O design, strict memory partitioning (safe/non restricted area), and dedicated programming software Unity Pro XLS. It is suitable for industrial safety scenarios such as emergency shutdown, burner management, and fire and gas monitoring. At the same time, it provides a complete verification and testing process and maintenance specifications to ensure that the system meets PFD/PFH index requirements in low/high demand modes.


1、 Document Fundamentals and Compliance

(1) Core information of the document

Document Name: Modicon Quantum Safety PLC Safety Reference Manual (Version 10/2017)

Applicable software: Unity Pro XLS V7.0 and above

Target users: Professional technicians with knowledge of functional safety and experience operating Unity Pro

Core objective: To standardize the hardware selection, programming, deployment, and maintenance process of SIL3 level security systems

(2) Compliance and Certification Standards

Standard Name Core Requirements Applicable Scenarios

IEC 61508 (2.0 version) SIL3 level, supports low/high demand mode for general industrial safety systems

IEC 61511 Safety Instrumented Systems (SIS) for Process Industries such as Chemical and Petroleum

EN 54 Fire Detection and Alarm System Fire and Gas Monitoring Scenarios

EN 298 Automatic Gas Burner Control System Burner Management

NFPA 85/86 Boiler Protection Standard Boiler Safety Control


2、 Hardware configuration and core features

(1) Secure CPU module

Model deployment mode core parameter fault detection mechanism

140CPU65160S independently deployed MTBF=600000 hours, supporting 8 secure I/O modules with dual processors (Pentium+application processor) for comparison and memory CRC verification

140CPU67160S hot standby deployment has the same parameters as the standalone version, supporting fiber link synchronization, automatic switching between primary and backup, and application consistency verification

(2) Safety I/O module

Module type, model, core characteristics, diagnostic function

Digital input 140SDI95300S, 32 points, 24Vdc, MTBF=900000 hours, disconnection detection, power monitoring, channel short circuit detection

Digital output 140SDO95300S 32 point, 24Vdc, MTBF=10000000h overload detection, circuit disconnection, timeout state configuration

Analog input 140SAI94000S 8-channel, 4-20mA, MTBF=700000 hours, over range detection, wire breakage detection, measurement linear verification

(3) Auxiliary hardware requirements

Power module: Only supports 140CPS12420 (AC redundancy) and 140CPS22400 (DC redundancy), requiring dual module deployment to ensure availability

Non interfering modules: including backplane (140XBP series), Ethernet module (140NOE77111), remote I/O adapter (140CRP93200/140CRA93200), not involved in safety functions but must meet compatibility requirements

Wiring specifications: The digital output module needs to be connected in series with a 10A fast fuse, and the analog input needs to be shielded and grounded (recommended STB XSP3000 grounding kit)

3、 Programming standards and software operations

(1) Programming software and language limitations

Unique programming software: Unity Pro XLS (requires secure firmware support)

Language allowed: Function Block Diagram (FBD), Ladder Diagram (LD) only

Disable features: FAST/NTERRUPT tasks, jump statements, ST expressions, derived data types (DDT)

(2) Core programming requirements

Specific requirements and purposes for standardized categories

Task configuration only allows MAST tasks, with a minimum cycle of 20ms to ensure consistency in execution between dual CPUs

The data type only supports basic types such as BOOL/INT/FLOAT+simple arrays to avoid security risks caused by complex data structures

The use of function blocks only allows secure FFB libraries (such as S-AND_ * * *, S-DISIL2, etc.) to ensure the security of logical execution

Memory partition: secure area (write protected), unrestricted area (data transfer only through S2SMOVE-FB), isolated secure/non secure data

(3) Security protection mechanism

Application password: Protect project access, support permission grading (configuration/debugging/maintenance)

Auto lock: After 10 minutes of inactivity (default), the software will be locked and requires a password to unlock

Version stamping: Record the build time when generating binary files for version traceability

Project backup: Regular backup is required (recommended combination of full and incremental backup), with CRC checking for integrity


4、 Operation mode and fault handling

(1) Two operating modes

Mode core feature operation restrictions

Safe mode (default) executes safety functions, prohibits program modification of non downloadable programs, non mandatory variables, and non debuggable

Maintenance mode (temporary) allows program modification, variable forcing, debugging requires unlocking key switch+password, diagnostic results do not automatically execute security actions

(2) Fault diagnosis and handling

CPU failure: When a memory error/inconsistent execution is detected, it enters an error state, and all safety outputs are set to a safe state (power loss). It is necessary to power off and restart, and read the% SW125 error code

I/O module failure: When a channel fails, the single channel is set to a safe state. When a module fails, it automatically restarts and performs a power on self-test. If it fails three times, the module needs to be replaced

Communication failure: When the secure Ethernet communication timeout (configurable) occurs, the HEALTH position is 0, and the receiving end needs to trigger a security action


5、 Communication mechanism

(1) Communication types and restrictions

Core requirements for communication scenario support methods

PC-PLC communication Modbus TCP/RS485/USB requires Unity Pro XLS, verify application password

PLC-PLC communication security requires NTP time synchronization between Ethernet nodes, with unique ID parameters

PLC-HMI communication Modbus TCP/Modbus Plus only allows reading of secure data and writing to restricted non restricted areas

(2) Secure Ethernet point-to-point communication

Synchronization requirement: NTP server polling cycle of 20s, master-slave PLC time difference ≤ 2s

Configuration components: sender end s_WR-ETH FFB, receiver end s_RD-ETH FFB

Timeout configuration: SAFETY VNet ONTROL_TIMEOUT needs to be greater than 2 times (sending cycle+network delay+receiving cycle)


6、 Verification and maintenance

(1) Verification testing requirements

Verification cycle (PTI): up to 10 years, requiring full system testing to be performed in accordance with SIL3 requirements

Verification content: power cycling test, I/O channel verification, safety function triggering test

Document requirements: Keep verification records, fault logs, and project backup files

(2) Maintain standards

Module replacement: Supports hot swapping, and after replacement, a power on self-test (about 30 seconds) needs to be performed

Mandatory operation: Only maintenance mode is allowed, and operation logs need to be recorded and the mandatory operation should be lifted in a timely manner

Firmware upgrade: Only maintenance mode can be executed, and the hot standby system needs to upgrade the backup CPU first

  • Woodward 8272-796 - Real Power Sensor Module 115/230v-ac
  • Woodward 5463-873 - NetCon Output Module
  • Woodward 8271-567 - Load Sensor Module 120/208v-ac
  • Woodward Type UG-8 P/N 8522-300 EG - Governor R.P.M 1075-1650 With Motor Groschopp
  • WOODWARD 9905-971 REV J - LINKNET 16 CHANNEL DISCRETE INPUT MODULE
  • WOODWARD 8280-3014 - 723 PLUS DIGITAL CONTROL REV NEW
  • Woodward 505DE - Digital Control System
  • Woodward 5453-750 - Ethernet Interface FTM
  • Woodward 9907-018 Rev H - 2301A Load Sharing & Speed Control
  • WOODWARD 5420-1080 V4.3 - BOARD-PPA WITHBOX
  • Woodward b 8271-347SP - 2301 speed control
  • Woodward 9905-795 Rev B - Digital Synchronizer and Load Control
  • Woodward 9905-377 Rev. A - 2301A Load Sharing and Speed Control
  • WOODWARD 8272-582 - Generator speed control module
  • WOODWARD 9907-247 REV K - 828 DIGITAL CONTROL UNIT
  • WOODWARD 5466-353 REV C - NETCON MAIN CHASSIS TRANSCEIVER
  • Woodward Type UG-8 P/N 8524-708 - Governor 760-1560 Governor R.P.M
  • WOODWARD 9907-247 REV K - 828 DIGITAL CONTROL UNIT
  • WOODWARD 8440-1831 REV. H - EASYGEN3000 3200-5 - WITHOUT ACCESSORIES
  • WOODWARD 8444-1002 REV G - UMT1 MEASURING TRANSDUCERS
  • Woodward 5410-312C - Digital Marine Control Printed Circuit Board
  • Woodward 9905-799 REV F - Digital Synchronizer & Load Control , V#456
  • Woodward 9907-014 - 2301A for controller
  • Woodward Type UG-8 P/N B522-446 - Governor R.P.M 500-1200
  • WOODWARD 8272-221 REV.B - DIGITAL REFERENCE UNIT
  • Woodward 8901-037 - Booster Servomotor Single
  • WOODWARD 8444-1019 REV G - UMT 1 MEASURING TRANSDUCER
  • WOODWARD 1767-367 Z21 WK 0920702 - GOVERNOR MOTOR 2700 RPM KM 58-20 K 230V
  • WOODWARD 9905-972 Rev:G - LINKNET 6 CHANNEL 4-20mA OutPut
  • Woodward E8250-501 - Actuator Governor
  • LTI Drives CDF30.002.C0.7 Compact Servo Controller 08685963 DC 24V Industrial Module
  • LUST LTI Drives CDB32.008.W2.4.BR.PC1 Servo Drive Industrial Motion System
  • LUST LTI Drives CDB34.003.C2.4.PC1.H15 Servo Motor Driver Industrial Control Unit
  • LUST LTI Drives CDA32.004.C1.4.H08.B0 Servo Drive Mat. 3084456 Industrial Control
  • LUST LTI Drives CDE34.005.W2.2 Industrial Servo Drive Motion Control Unit
  • LUST LTI Drives CDA34.006.W3.0 Servo Drive Software V3.70-04 Industrial Controller
  • LTI Drives CDB32.004.C2.4.SH Servo Drive Compact Motion Controller
  • Woodward 9905-373 - Digital Synchronizer And Load Controller
  • WOODWARD MAGNETIC PICKUPS - Sensor
  • WOODWARD GCP-30 - Steuertafel for Industrial Regulator Genset Control Package
  • WOODWARD GOVERNOR 9907-1183 REV A - 505 ENHANCED TURBINE CONTROL
  • WOODWARD 9907-173 REV B - Module Load Sharing 120 Volt
  • WOODWARD 9907-014 - 2301A controller
  • Woodward 9905-029 - SPM-A Synchronizer Module Rev C
  • WOODWARD 8440-1799 EASYGEN-350 REV B - Genset Controller
  • WOODWARD 5466-258 REV M - SIMPLEX DISCRETE I/O MODULE
  • Woodward 8440-1884 C - Controller Easygen 2500-5
  • Woodward 8441-1153 - Monitoring Unit 250VAC
  • WOODWARD 8406-120 REV G - EGCP-2 DIGITAL CONTROL
  • Woodward 8273-584 - Atlas-ii Digital Control
  • Woodward 8272-582 - APM Motor Control 8272582
  • Woodward 9905-377 Rev. A - 2301A Load Sharing and Speed Control
  • WOODWARD 8272-517 - Pm Motor Control
  • WOODWARD 9905-797 REV.B - DIGITAL SYNCHRONIZER AND LOAD CONTROL DSLC-D
  • WOODWARD 8272-582 - APM MOTOR CONTROL
  • Woodward Seg FP2-8-24 - Emergency Power Telecommunications Module NP2
  • WOODWARD 2001-12E2U1B1S1A - Fuel Shut Off Valve Stop Solenoid Valve 2000-4505
  • Woodward 8440-1884 K - Genset Controller Easygen-2500-5
  • Woodward 9905-760 - Linknet Termination Module
  • Woodward 8404-009 - Proact Digital Plus Front Panel Rev. H
  • Woodward 8271-651 - Digital Speed Reference
  • Woodward 3077-474C - 8605895 5501-031 D Circuit Module
  • WOODWARD 5466-257 REV.-C - NETCON 5000 MODEL REMOTE TRANSCEIVER I/O MODULE
  • Woodward 8273-101 Rev: A - 2301D Digital Load Sharing and Speed Control
  • WOODWARD 8272-799 - 2301A SPEED CONTROL WITH REMOTE REFERENCE REV:C
  • Woodward 8272-517 - PM Motor Control
  • Woodward 8290-048 8290048 Rev. F - Generator Load Sensor
  • woodward 8273-1012 rev c - 2301e Load Sharing and Speed Control
  • WOODWARD 9905-797 - DIGITAL SYNCHRONIZER AND LOAD CONTROL FOR 3 PHASE GENERATORS
  • WOODWARD 8280-3014 - 723 PLUS DIGITAL CONTROL REV NEW
  • WOODWARD 8440-1884 REV G - GENSET CONTROLLER EASYGEN-2500-5/P1
  • Woodward 8272-683 K - Digital Reference
  • WOODWARD 9907-014 - SPEED CONTROL 2301A REV H
  • Woodward Type UG-8 P/N 037260 - Governor R.P.M 1075-1650 Motor KM58-20
  • WOODWARD 9905-970 - LINKNET 6 CHANNEL 100 OHM RTD Rev:J
  • Woodward 9907-1183 Rev C - Steam Turbine Digital SCREEN 505E Turbine Control
  • Woodward 8440-1614 - GCP-30 Genset Control Package, Rev: F, Type 1, E231544
  • Woodward DC11006-304-024 - ACTUOTOR DYNA ACTUATOR - BARBER-COLMAN
  • Woodward 9905-971 - LINKNET 6 CHANNEL 100 OHM RTD Rev:K
  • Woodward DYNK-10249 - Actuator Controller Kit - DYNA 2000
  • Woodward LR21035 - MFR1 MULTI FUNCTION RELAY REV F
  • Woodward 8440-1831 - EASYGEN 3200-5 P/N: REV. G Gererator Controller
  • Woodward 8272-516 - PM MOTOR CONTROL REV J
  • Woodward 8440-2080 - EASYGEN 2000 genset controller EASYGEN-2300-5/P1
  • Woodward 505DE - Digital Control System
  • Woodward 701 - Digital Speed Control 18-40 VDC 4-20 MA
  • Woodward 8440-1799 - EASYGEN-350 REV B
  • Woodward 8272-582 - Apm Motor Control 100-220v AC/DC
  • Woodward 5501-031 D - 3077-474C 8605895 Circuit Module
  • Woodward XD1-T - XD1T55SAT TRANSFORMER DIFFERENTIAL PROTECTION RELAY
  • Woodward 8272-517 - PM Motor Control 220vac
  • Woodward 8934-658 - Repair Kit UG8D Governor
  • Woodward 5437 18 - module netcon derivative analog rev.A
  • Woodward 8272-171 A - Pm Motor Control
  • Woodward MRN3-1/2 - SEG mains uncoupling relay MRN314D mains decoupling relay
  • Woodward 9905-373 - Digital Synchronizer and Load Control 18-40 VDC Rev P
  • Woodward 5431-640 C - Dual Dynamics 1000 Series Speed Control Module
  • Woodward 5501-031 D - 3077-474C 8605895 Circuit Module
  • Woodward 9907-247 - 828 DIGITAL CONTROL
  • Woodward 8440-1855-G - EASYGEN-2200-5 /P1 12/24VDC GENSET CONTROLLER
  • Woodward NC3-2-8 (NO) - GENERATOR CONTROLLER
  • Woodward 8271-467 K - 2301 LOAD SHARING AND SPEED CONTROL PART NO:
  • Woodward 8440-2177 A - SPM-D2-10 Digital Synchronising Controller
  • Woodward LXMG1614E-14-11 - CCFL and UV Lamps Inverter Module
  • Woodward 8270-990 - signal converter
  • Woodward 9905-068 - LOW VOLTAGE 2301A LOAD SHARING & SPEED CONTOL P/N:
  • Woodward 8901-051 - BOOSTER SERVOMOTOR, SINGLE CYLINDER, 2:1
  • Woodward 8444-1024 D - MWS4-55M CONTROL MODULE UNIT
  • Woodward 5448-914 - GCP-20 Genset Control GCP-20 REV D P/n:
  • Danfoss BHA-1 018-1942 - Hydraulic Actuator
  • Woodward 9905-001 L - SPM-A SYNCHRONIZER
  • Woodward 5464-850 - Module
  • Woodward 5501-371 - Micronet Simplex Mpu Aio Rev C
  • Woodward 8272-132 B - POWER SENSOR
  • Woodward 9907-028 - SPM-A Synchronizer
  • Woodward SA-3678-AM-2 - Overspeed Electric Governor, Model ESSE2-AM
  • Woodward E8250-502 - GOVERNOR ACTUATOR
  • Woodward 8440-1884 J - Controller EASYGEN-2500-5
  • Woodward 5441-693 - DIGITAL I/O MODULE -MISSING PART
  • Woodward SA-4450 - Speed Controller APECS 3100 For Magnetic Pickup
  • Woodward 9903-466 - 701 DIGITAL SPEED CONTROL REV G
  • Woodward 1765-843 - Governor Speed Adjusting Motor P/N Type: SMM40 220V AC 50/60Hz
  • Woodward 9905-760 - Linknet Termination Module
  • Woodward 9907-247 - 828 DIGITAL CONTROL UNIT REV K
  • Woodward 5484-721 - motor
  • Woodward 8440-1734 - MFR-2 Rev.A Multi Function Relay MFR-2
  • Woodward CSC3SUWA - Controller
  • Woodward 8440-1667 - REV B SPM-D1010B/XN