Safety I/O used to mean yellow cable everywhere. PROFIsafe ends that: safety telegrams ride the ordinary Profinet, and the protocol itself guarantees integrity — the “black channel” principle. The network needs no safety pedigree; the endpoints carry it.
What holds it together
Each safety participant gets an F-address — the unique identity that prevents telegram mixups; assignment (switches or tool-based) is a commissioning act with a checklist line. Every safety connection runs a watchdog (F_WD_Time): telegram not renewed in time → safe state. Sizing it is real engineering: too tight and network micro-hiccups (a ring reconfiguration!) trip safety; too loose and the reaction-time calculation in the risk assessment lies. Compute from the update-time chain plus margin — and document the calculation, because auditors ask exactly this.
The safety reaction-time chain is the design deliverable: sensor → F-input processing → network → F-CPU cycle → network → F-output — the sum, worst case, feeds your safety distances. Siemens tooling calculates it; your job is honest inputs.
Commissioning checks that separate pros
Force each safety function physically and measure actual response where distances are tight; provoke telegram loss (pull the cable) and watch the passivation and — important — the reintegration behavior (operator acknowledgment where required); verify the F-collective signature is recorded; and confirm device replacement re-assigns F-addresses per your procedure, not by improvisation.
FAQ
Can safety and standard data share a device? Yes — fail-safe I/O stations carry both; the F-modules are the certified part. That mixing is the cost saving.
Does a network fault stop the machine? It passivates the affected safety I/O to safe state — design zones so “safe” and “productive elsewhere” can coexist where the risk assessment allows.
Zone Otomasyon engineers PROFIsafe retrofits replacing relay pyramids — with reaction-time files auditors accept. Safety network engineering.