Download as docx, pdf, or txt
Download as docx, pdf, or txt
You are on page 1of 3



Exclusive Features of ABB Safety System - 800M HI (High Integrity)

1. SIL Certified in non-redundant configuration


The High Integrity Safety system is certified for SIL 3 in a single configuration. i.e. non redundant CPU and
non redundant IO modules

2. SIL Level does not Degrade on Component Failure


In the event of any redundant hardware component failure, High Integrity Safety system continues to function
at same SIL level (no degradation). Which means, any single failure does not affect system reliability.

3. Long Distance Remote IO Configuration

I/o modules can be placed at a distance of 20km from CPU in SIL-3 configuration.

4. Built in SOE Functionality


The Digital Input Module hasbuilt in Sequence of Event functionality which enables time tagging of process
events with 1 msresolution at IO module level instead of Controller scan time. The DI module has capability to
store 512 x 16 Alarm messages on the IO module itself, which means, in case of communication failure
between Controller & IO module or Controller & SOE server (Connectivity server), the events will not be lost
and will be republished automatically upon resumption of communication.
This is a standard feature and comes with no additional cost and is a powerful tool to carry out root cause
analysis, should a shutdown or hazardous event occurs in the plant.

5. IEC 61131-3 Compliant Engineering


High Integrity Safety system engineering tool is compliant to IEC 61131-3 and supports z Function Block,
Structured Text and Sequential Flow Chart languages for SIL applications.
As DCS and Safety System controllers belongs to same controller family, it is possible to have
common engineering tool running on common engineering station with different level of password
protection to prevent un-authorized access.
6. Integrated SOE
800xA based High Integrity Safety system has integrated Sequence of event functionality with 1msec
resolution. The SOE event list (which is separate from DCS alarm / events) by default can be accessed on all
Operator stations, thereby offering flexibility in plant operation and abnormal situation analysis. Besides this, it
helps in optimizing system hardware requriements.

7. Integrated Safety System


High Integrity Safety system is certified to run DCS and Safety applications in to one controller without
jeopardizing the SIL. This unique configuration offers possibility of proper sensor validation (one sensor
running in DCS application and other sensor running in Safety application)

Page 1


8. Partial Stroke Testing


High Integrity Safety system has integrated Partial Stroke functionality, which can be initiated either from DCS
or Safety system itself. Partial Stroke testing is supported for all major vendors like Dresser, Metso and
Fischer, thereby offering choice to end user to select field components as per process requirement rather than
what suits control system

9. Peer to Peer Communication


Generally, data exchange between two safety controllers is implemented using safety certified read and write
function blocks configured in two safety controllers. However, in High Integrity Safety system, tag / variable
can be declared global type so that it can be accessed by any safety controller on the network with out any
additional programming, thereby simplifying and improving engineering efficiencies.

10. Proven and Tested Solution


We have supplied High Integrity Safety system across different industry verticals ranging from Oil & Gas,
Chemical, mining, Pulp & Paper to semiconductor. Globally we have more than 250 systems installed in Safety
Applications. A Partial Global list is attached herewith.

11. Diverse Technology


Earlier DCS and Safety system were supplied by two different organizations with the intention in mind
that the two different organizations will follow different design, development, testing etc. procedures,
thereby minimizing common cause of failure.

ABB has adopted alternative approach and incorporated embedded diversity in HI Safety system design.
Our Processor and Safety modules are developed by two different teams working independently of each
other at different locations and these two modules uses different operating systems. Testing is carried
out by a third team located at different location.

Besides this, each channel of an IO module comprises of two internal channels developed using two
different technologies (FPGA and micro controller).

Which means, HI system utilizes diversity rather than redundancy so as to minimize the common cause
failures and achieve SIL-3 in single configuration (non redundant logic solver and non redundant IO
modules)

12. 4-3-2-0 Operation Mode


Generally, in a quad system, logic solvers / CPUs operate in pair and hence offers 4-2-0 operation mode
only. In case of High Integrity safety system, each logic solver comprise of two physical CPUs (one is
referred as processor module and another is referred as safety module). As a redundant safety system
has two logic solvers, the safety system continues to function in SIL-3 configuration (with out any
degradation) provided one processor module and one safety module is functional in any of the logic
solver. Such an arrangement provides 4-2-0 and 4-3-2-0 operation modes, which is unique to ABB’s High
Integrity Safety system.

Page 2


13. Digital Output Module


The Safety Digital Output Module is a 16-channel module and support both Normally Energized and
Normally de-energized outputs. Which means, same module is suitable for both ESD and F&G
applications.

The output circuitry for each channel consists of four output-switches organized in two parallel legs. The
two switches in each leg are built with different technologies. One switch is controlled by the MCU
(micro controller unit) and other switch is controlled by the FPGA (Field programmable gate array).This
ensure uninterrupted output diagnostics and correct operation even in the event of one failure and
therefore, output circuitry has hardware fault tolerance of one.

14. 1:1 Hot Slot for IO Modules


As High Integrity Safety system is certified for SIL-3 in single configuration (both logic solver and IO
modules), it offers flexibility to engineer the system in a way so that critical I/Os will have redundant IO
modules with redundant termination unit and non critical I/Os can have single IO module with
redundant termination unit. In case of failure of a non redundant I/O module, a new module can be
inserted on empty slot on redundant termination unit and subsequently, faulty IO module can be
replaced without shutting down plant operation. This can help in optimizing safety system hardware.

15. IO Modules
High Integrity Safety system has one I/o module of each type (AI, DI & DO), which is suitable for both
redundant and non-redundant application. This helps our customer to optimize inventory requirements.

Page 3

You might also like