Overview
1.9 Fail-safe operation of KP8F and KP32F
KP8, KP8F, KP32F
22 Operating Instructions, 11/2011, A5E03284305-02
Fail-safe operation of KP8F and KP32F
KP8F and KP32F are PROFINET IO devices in an Industrial Ethernet.
In fail-safe mode the HMI device registers the signal states of compatible emergency stop
buttons and transmits corresponding safety frames to the controller. The controller and the
HMI device communicate with each other using the fail-safe protocol, PROFIsafe.
The HMI device can operate in fail-safe mode corresponding to SIL3, Performance Level e
and category 4 if the safety functions are appropriately configured in STEP 7 with the "S7
Distributed Safety" add-on package.
Fail-safe mode of the HMI devices differs from standard mode essentially in that during
communication, the signals are checked for being fault-free. In the event of a fault, the HMI
device is placed in a safe state.
The fail-safe connection fulfills the following requirements:
● Single-channel mode with 1oo1 parameterization
– Safety category SIL2 corresponding to IEC 61508
– Safety category Performance Level d corresponding to IEC 13849-1
– Safety category category 3 corresponding to EN 954:1996
● Two-channel mode with 1oo2 parameter assignment
– Safety category SIL3 corresponding to IEC 61508
– Safety category Performance Level e corresponding to IEC 13849-1
– Safety category category 4 corresponding to EN 954:1996
Diagnostic function of KP8F and KP32F
KP8F and KP32F offer non-programmable diagnostics functions. The diagnostics functions
are always active. The diagnostics result is automatically made available by the HMI device
in STEP 7 and passed on to the fail-safe controller in the event of a fault.