+086-15305925923

K-WANG

Service expert in industrial control field!
NameDescriptionContent
Adequate Inventory, Timely Service
pursuit of excellence 
Ship control system
Equipment control system
Power monitoring system
Current position:
新闻动态
newS
   
Brand

SCHNEIDER Modicon Quantum Safety PLC safety programmable logic controller

From: | Author:Wang | Time :2026-01-20 | 11 visit: | Share:


SCHNEIDER Modicon Quantum Safety PLC safety programmable logic controller

Modicon Quantum Safety PLC is a safety programmable logic controller launched by Schneider Electric, which complies with the IEC 61508 standard and has a certification level of SIL3. Its core revolves around the implementation of safety functions, covering four dimensions: hardware configuration, programming specifications, communication mechanism, and fault diagnosis. It supports two deployment modes: independent/hot standby (HSBY), and ensures functional safety through dual processor execution, redundant I/O design, strict memory partitioning (safe/non restricted area), and dedicated programming software Unity Pro XLS. It is suitable for industrial safety scenarios such as emergency shutdown, burner management, and fire and gas monitoring. At the same time, it provides a complete verification and testing process and maintenance specifications to ensure that the system meets PFD/PFH index requirements in low/high demand modes.


1、 Document Fundamentals and Compliance

(1) Core information of the document

Document Name: Modicon Quantum Safety PLC Safety Reference Manual (Version 10/2017)

Applicable software: Unity Pro XLS V7.0 and above

Target users: Professional technicians with knowledge of functional safety and experience operating Unity Pro

Core objective: To standardize the hardware selection, programming, deployment, and maintenance process of SIL3 level security systems

(2) Compliance and Certification Standards

Standard Name Core Requirements Applicable Scenarios

IEC 61508 (2.0 version) SIL3 level, supports low/high demand mode for general industrial safety systems

IEC 61511 Safety Instrumented Systems (SIS) for Process Industries such as Chemical and Petroleum

EN 54 Fire Detection and Alarm System Fire and Gas Monitoring Scenarios

EN 298 Automatic Gas Burner Control System Burner Management

NFPA 85/86 Boiler Protection Standard Boiler Safety Control


2、 Hardware configuration and core features

(1) Secure CPU module

Model deployment mode core parameter fault detection mechanism

140CPU65160S independently deployed MTBF=600000 hours, supporting 8 secure I/O modules with dual processors (Pentium+application processor) for comparison and memory CRC verification

140CPU67160S hot standby deployment has the same parameters as the standalone version, supporting fiber link synchronization, automatic switching between primary and backup, and application consistency verification

(2) Safety I/O module

Module type, model, core characteristics, diagnostic function

Digital input 140SDI95300S, 32 points, 24Vdc, MTBF=900000 hours, disconnection detection, power monitoring, channel short circuit detection

Digital output 140SDO95300S 32 point, 24Vdc, MTBF=10000000h overload detection, circuit disconnection, timeout state configuration

Analog input 140SAI94000S 8-channel, 4-20mA, MTBF=700000 hours, over range detection, wire breakage detection, measurement linear verification

(3) Auxiliary hardware requirements

Power module: Only supports 140CPS12420 (AC redundancy) and 140CPS22400 (DC redundancy), requiring dual module deployment to ensure availability

Non interfering modules: including backplane (140XBP series), Ethernet module (140NOE77111), remote I/O adapter (140CRP93200/140CRA93200), not involved in safety functions but must meet compatibility requirements

Wiring specifications: The digital output module needs to be connected in series with a 10A fast fuse, and the analog input needs to be shielded and grounded (recommended STB XSP3000 grounding kit)

3、 Programming standards and software operations

(1) Programming software and language limitations

Unique programming software: Unity Pro XLS (requires secure firmware support)

Language allowed: Function Block Diagram (FBD), Ladder Diagram (LD) only

Disable features: FAST/NTERRUPT tasks, jump statements, ST expressions, derived data types (DDT)

(2) Core programming requirements

Specific requirements and purposes for standardized categories

Task configuration only allows MAST tasks, with a minimum cycle of 20ms to ensure consistency in execution between dual CPUs

The data type only supports basic types such as BOOL/INT/FLOAT+simple arrays to avoid security risks caused by complex data structures

The use of function blocks only allows secure FFB libraries (such as S-AND_ * * *, S-DISIL2, etc.) to ensure the security of logical execution

Memory partition: secure area (write protected), unrestricted area (data transfer only through S2SMOVE-FB), isolated secure/non secure data

(3) Security protection mechanism

Application password: Protect project access, support permission grading (configuration/debugging/maintenance)

Auto lock: After 10 minutes of inactivity (default), the software will be locked and requires a password to unlock

Version stamping: Record the build time when generating binary files for version traceability

Project backup: Regular backup is required (recommended combination of full and incremental backup), with CRC checking for integrity


4、 Operation mode and fault handling

(1) Two operating modes

Mode core feature operation restrictions

Safe mode (default) executes safety functions, prohibits program modification of non downloadable programs, non mandatory variables, and non debuggable

Maintenance mode (temporary) allows program modification, variable forcing, debugging requires unlocking key switch+password, diagnostic results do not automatically execute security actions

(2) Fault diagnosis and handling

CPU failure: When a memory error/inconsistent execution is detected, it enters an error state, and all safety outputs are set to a safe state (power loss). It is necessary to power off and restart, and read the% SW125 error code

I/O module failure: When a channel fails, the single channel is set to a safe state. When a module fails, it automatically restarts and performs a power on self-test. If it fails three times, the module needs to be replaced

Communication failure: When the secure Ethernet communication timeout (configurable) occurs, the HEALTH position is 0, and the receiving end needs to trigger a security action


5、 Communication mechanism

(1) Communication types and restrictions

Core requirements for communication scenario support methods

PC-PLC communication Modbus TCP/RS485/USB requires Unity Pro XLS, verify application password

PLC-PLC communication security requires NTP time synchronization between Ethernet nodes, with unique ID parameters

PLC-HMI communication Modbus TCP/Modbus Plus only allows reading of secure data and writing to restricted non restricted areas

(2) Secure Ethernet point-to-point communication

Synchronization requirement: NTP server polling cycle of 20s, master-slave PLC time difference ≤ 2s

Configuration components: sender end s_WR-ETH FFB, receiver end s_RD-ETH FFB

Timeout configuration: SAFETY VNet ONTROL_TIMEOUT needs to be greater than 2 times (sending cycle+network delay+receiving cycle)


6、 Verification and maintenance

(1) Verification testing requirements

Verification cycle (PTI): up to 10 years, requiring full system testing to be performed in accordance with SIL3 requirements

Verification content: power cycling test, I/O channel verification, safety function triggering test

Document requirements: Keep verification records, fault logs, and project backup files

(2) Maintain standards

Module replacement: Supports hot swapping, and after replacement, a power on self-test (about 30 seconds) needs to be performed

Mandatory operation: Only maintenance mode is allowed, and operation logs need to be recorded and the mandatory operation should be lifted in a timely manner

Firmware upgrade: Only maintenance mode can be executed, and the hot standby system needs to upgrade the backup CPU first

  • HIMA F60MI2401 PLC Module | Modular Safety Automation
  • HIMA F8603 PLC Module | Safety Automation Control Module
  • HIMA K1412A PLC Module | Industrial Safety Automation Module
  • HIMA K9203 PLC Module | Safety Control System Module
  • HIMA F60AI801 PLC Module | Analog Input Module
  • HIMA F60MI2401 PLC Module | Modular Safety Automation
  • HIMA F8603 PLC Module | Safety Automation Control Module
  • HIMA K1412A PLC Module | Industrial Safety Module
  • HIMA K9203 PLC Module | Safety Automation Module
  • X-DO1201 HIMA Control Pulse Card | Digital Output Module
  • F6705 HIMA Analog Output Module | Safety Control Output Module
  • HIMA B9361 PLC Module | Safety Automation System Module
  • HIMA H41Q-HRS / H41QX PLC Module | Safety Automation Module
  • HIMA F3003 Controller Unit | HIMAtrix Compact Safety Controller
  • HIMA HIMatrix F1DI1601 PLC Module | Digital Input Module for Safety Systems
  • HIMA X-DI 64 51 PLC Module | Digital Input Module for Safety Automation
  • HIMA F30 Controller Unit HIMAtrix 01 OPEN | Safety PLC Controller
  • HIMA K9202B PLC Module | Safety-Oriented Control Module
  • HIMA F3DIO20802 Controller PLC Module | Digital I/O Control for Safety Automation
  • HIMA F8627-1 F8627X Communication Module | Safety System Communication Interface
  • HIMA B4237-2 PLC Module | Safety Control and Logic Processing Module
  • HIMA X-DO2401 PLC Module | Digital Output Module for Safety Automation
  • HIMA 22100 PLC Module | Industrial Safety Control and Logic Processing
  • HIMA 90100 PLC Module | Safety-Oriented Industrial Control Module
  • HIMA 895210001 PLC Module | Industrial Safety Control and Processing Module
  • HIMA 157528-0 PLC Module | Industrial Safety Control and Processing Module
  • HIMA B5322 PLC Module | Industrial Safety Control and Processing Module
  • HIMA BV7032 PLC Module | Industrial Safety Control and Processing Module
  • HIMA F3300 PLC Module | Industrial Safety Control and Processing Module
  • HIMA F7105A PLC Module | Industrial Safety Control and Processing Module
  • HIMA F7150 PLC Module | Industrial Safety Control and Processing Module
  • HIMA F7508 PLC Module | Industrial Safety Control Processing Module
  • HIMA F8627 984862765 PLC Module | Industrial Safety Control Module
  • HIMA M3410 PLC Module | Industrial Safety Control Processing Module
  • HIMA Z7308 PLC Module | Safety Control System Processing Module
  • F8640 HIMA Central Module | Safety System Core Controller
  • HIMA F8630 Module | Safety System Functional Module
  • F8651X HIMA Central Module | Safety System Core Controller
  • F3236 Digital Input Module | HIMA Safety System Input Interface
  • F7131 HIMA Power Monitoring Module | Safety System Power Supervision
  • F8627X HIMA Communication Module | Safety System Network Interface
  • HIMA F8560X PLC Module | Safety-Related Control System Component
  • HIMA P8403 PLC Module – Industrial Safety Control Processor
  • HIMA F8628X Communication Module – Industrial Safety System Interface
  • HIMA F8621A Communication Module – Safety System Communication Interface
  • HIMA 984865066 PLC Module – Safety Control Processing Unit
  • HIMA F60CPU01 PLC Module – Safety Control Processing Unit
  • HIMA F8650E PLC Module – Safety Control Processing Unit
  • HIMA F8652E Central Module – Safety Control Processing Unit
  • HIMA F8650X Card – Safety Central Processing Module
  • F8652X HIMA Central Module – Safety Control Central Processing Unit
  • HIMA 99-7105233 B5233-1 Safety Module – Industrial Safety Control Component
  • KEBA KeTop T70-rqa-AK0-LK Teaching Device – Industrial Robot Teach Pendant
  • KEBA KETOP T50-T41-CPU 2495D-0 – Industrial CPU Module
  • KEBA E-CON-CC100/A/ 22178 – Industrial Controller Module
  • KEBA Kemro K2-200 CP 250/X 71580 CPU-MODULE – Industrial Control CPU Module
  • KEBA D3‑DA 330/A‑1211‑00 Drive – KeDrive D3 Axis Controller Industrial Servo Drive
  • KEBA KETOP O70‑bra‑A0a‑F Demonstrator – Industrial Automation Control Module
  • KEBA KETOP O70-BRA-A0A-F Demonstrator | Industrial HMI Operating Terminal
  • KEBA SO84.012.0083.0101.2 Servo Drive | Industrial Motion Control Solution
  • HIMA X-AO1601 Termination Boards
  • HIMA X-AI3251 Digital Output Module
  • HIMA X-DO3251 Digital Output Module
  • HIMA X-DI3202 Termination Board
  • HIMA X-DI6451 Digital Input Module
  • XYCOM 96574-001 - Circuit Board Card Rev A
  • XYCOM 99212A-001 - Control Board Card CPX-7
  • XYCOM 99222-001 - Circuit Board Card Rev A
  • XYCOM 97780-002 - Circuit Board for Operator Panel Screen
  • XYCOM XVME-164/1 - Circuit Board 61116
  • XYCOM CMX-7D - Power Supply Circuit Board PN99865-001
  • XYCOM 10330-00800 - Digital I/O Board Circuit Card
  • XYCOM 8450-HU - Husky Monitor 98916-001
  • XYCOM XVME-428/2 - IASCM Communication Board
  • XYCOM 3512KPT - Industrial PC Operator Interface
  • XYCOM Checkpoint Cognex - Inspection Machine Vision Camera
  • XYCOM XVME-080 - IPROTO Intelligent Prototyping Module
  • XYCOM IV-1653 - Ironics VMEbus CRT Circuit Board
  • XYCOM M032000220 - Control Board
  • XYCOM 4850A - Operator Interface Panel 91855-001
  • XYCOM 9462 - HMI Operator Interface Panel 9462-016214001
  • XYCOM 9465 KPM - Monitor Industrial PC 9465-219114103
  • XYCOM 9486 - Monitor-Miniflex Portrait 9486-0343
  • XYCOM MVME-490/1 - Circuit Board Tegal 6550 Etcher
  • XYCOM 1300 - Node Module 1300-000100000
  • XYCOM 3510 T - Operator Interface
  • XYCOM 3512 KPM - Operator Interface Part No 3512-A1F114103
  • XYCOM 4615KPM - Operator Interface
  • XYCOM 8320 - Operator Interface Display Panel 94321-002
  • XYCOM 4105 - Operator Interface P/N 91904-001
  • XYCOM PM101683E - Operator Interface PM101683 E
  • XYCOM 301993 - Operator Panel 89086-501 Raycon
  • XYCOM 2000 - Operator Panel 97957-001
  • XYCOM 9410KP - Operator Touchscreen HMI 51338-STN
  • XYCOM 9987 - Operator Workstation CPU Board
  • XYCOM 94144-002 - CPU Board Rev V
  • XYCOM 9487 - Programmable Interface HMI Panel PC
  • XYCOM 70956-411 - PLC Module Card Ethernet Card MESA 4I29X
  • XYCOM PM101587 - Operator Panel
  • XYCOM XT1502-BB-RB - Display Panel XT 1502
  • XYCOM PM3510 - Operator Interface Terminal
  • XYCOM PM8450 - Operator Interface Repair Evaluation
  • XYCOM PM8480 - Operator Interface PM101269
  • XYCOM 8000-SKM - Power Supply Board Module
  • XYCOM 510084 - Power Supply Board
  • XYCOM 1546 - Proface Industrial Workstation 1546-102031013
  • XYCOM 86864-002-E - Processor Board Module
  • XYCOM 3112T - Pro-face Operator Interface
  • XYCOM 3712 KPM - Pro-face Operator Panel
  • XYCOM 4615KPMT - Proface Industrial PC Display Panel PM-070007
  • XYCOM 5015T - Pro-Face Touch Monitor 100-240 VAC
  • XYCOM 5015T/R2 - Industrial Flat Panel Touch Monitor 5015R2-0100000
  • XYCOM 1341 - Proface Embedded Computer TF-AEC-6920-C2
  • XYCOM GLC150-BG41-DN - Graphic Logic Controller M-24V
  • XYCOM GP2301H-SC41-24V - Pro-face Operator Interface 5.7" w/ Cable
  • XYCOM 1547 - Pro-face Industrial PC Model 1547-00113101
  • XYCOM ST401-AG41-24V - Graphic Touchscreen Operator Interface
  • XYCOM 3310T - Pro-face Operator Panel 3310-001101001
  • XYCOM 5015 KPMT - Proface Operator Panel Display
  • XYCOM XVME-684 - PC Module VME Bus Processor 70684-201
  • XYCOM 3300 MT - Screen Monitor Display
  • XYCOM SXT1811T - Touch Panel Monitor 100/240VAC
  • XYCOM XT-1502 - Touch Screen Monitor Flat Panel Display Interface
  • XYCOM SXT1811 - Viewtronix SXGA Flat Panel Monitor 18.1" Display
  • XYCOM VT1040T - ViewTronix Touch Screen Monitor
  • XYCOM WS2786291 - Industrial Workstation PC
  • XYCOM XCME-540 - Analog I/O Module VMEbus 70540-001
  • XYCOM XVME-682 - CPU PCB Processor Module 70682-101