Trusted TMR Expander Interface: Product Overview
Trusted TMR Expander Interface: Product Overview
Trusted TMR Expander Interface: Product Overview
Features:
• Triple Modular Redundant (TMR), fault tolerant (3-2-0) operation.
• Dedicated hardware and software test regimes which provide very fast fault recognition and
response times.
• Hot replacement.
PREFACE
In no event will Rockwell Automation be responsible or liable for indirect or consequential damages
resulting from the use or application of this equipment. The examples given in this manual are
included solely for illustrative purposes. Because of the many variables and requirements related to
any particular installation, Rockwell Automation does not assume responsibility or reliability for
actual use based on the examples and diagrams.
No patent liability is assumed by Rockwell Automation, with respect to use of information, circuits,
equipment, or software described in this manual.
DISCLAIMER
It is not intended that the information in this publication covers every possible detail about the
construction, operation, or maintenance of a control system installation. You should also refer to
your own local (or supplied) system safety manual, installation and operator/maintenance manuals.
This document is based on information available at the time of its publication. The document
contents are subject to change from time to time. The latest versions of the manuals are available at
the Rockwell Automation Literature Library under "Product Information" information "Critical
Process Control & Safety Systems".
TRUSTED RELEASE
For the latest information about this product review the Product Notifications and Technical Notes
issued by technical support. Product Notifications and product support are available at the Rockwell
Automation Support Centre at
http://rockwellautomation.custhelp.com
At the Search Knowledgebase tab select the option "By Product" then scroll down and select the
Trusted product.
Some of the Answer ID’s in the Knowledge Base require a TechConnect Support Contract. For more
information about TechConnect Support Contract Access Level and Features please click on the
following link:
https://rockwellautomation.custhelp.com/app/answers/detail/a_id/50871
This will get you to the login page where you must enter your login details.
IMPORTANT A login is required to access the link. If you do not have an account then you can create one
using the "Sign Up" link at the top right of the web page.
DOCUMENTATION FEEDBACK
Your comments help us to write better user documentation. If you discover an error, or have a
suggestion on how to make this publication better, send your comment to our technical support
group at http://rockwellautomation.custhelp.com
SCOPE
This manual specifies the maintenance requirements and describes the procedures to assist
troubleshooting and maintenance of a Trusted system.
This manual is for plant maintenance personnel who are experienced in the operation and
maintenance of electronic equipment and are trained to work with safety systems.
SYMBOLS
In this manual we will use these notices to tell you about safety considerations.
This symbol identifies items which must be thought about and put in place when
designing and assembling a Trusted controller for use in a Safety Instrumented
Function (SIF). It appears extensively in the Trusted Safety Manual.
IMPORTANT Identifies information that is critical for successful application and understanding of
the product.
TIP Tips give helpful information about using or setting up the equipment.
Do not connect or disconnect equipment while the circuit is live or unless the area is
known to be free of ignitable concentrations or equivalent
Ne pas connecter ou déconnecter l’équipement alors qu’il est sous tension, sauf si
l’environnement est exempt de concentrations inflammables ou équivalente
MAINTENANCE
Maintenance must be carried out only by qualified personnel. Failure to follow these
instructions may result in personal injury.
CAUTION:
The module PCBs contains static sensitive components. Static handling precautions
must be observed. DO NOT touch exposed connector pins or attempt to dismantle a
module.
ISSUE RECORD
9 Oct 05 Format
10 Nov 06 Specification
15 Apr 18 New look front panel. Reformatted and updated Specifications table.
Table of Contents
1. Description ............................................................................................................. 3
2. Application ............................................................................................................. 5
3. Operation ............................................................................................................... 9
4. Operation ............................................................................................................. 16
6. Specifications........................................................................................................ 22
1. Description
1.1. Overview
The TMR Expander Interface is a fault tolerant design based on TMR architecture arranged
in a lock-step configuration. Figure 1 shows, in simplified terms, the basic structure of the
TMR Expander Interface.
The Module has three main fault containment regions (FCR A, B and C). Each of the main
FCRs contains interfaces to the Expander Bus and Inter-Module Bus (IMB), an active/standby
interface to the other TMR Expander Interface in the Chassis, control logic, communications
transceivers and power supplies.
Communication between the Module and the TMR Processor is via the IMB on the
Backplane of the Controller Chassis. The IMB provides fault tolerance and high bandwidth
communications between the Interface Modules and the TMR Processor. All transactions
are voted, localising faults to the IMB should they occur.
Communication between the Interface Module and the TMR Expander Processor in the
Expander Chassis is via the Expander Bus. The Expander Bus is triplicated, point-to-point
architecture. Each channel of the Expander Bus comprises separate command and response
media. Voting is provided at the Expander Bus Interface to ensure that cable faults are
tolerated, and the remainder of the Expander Processor operates in a fully triplicated mode,
even in case of cable faults occurring.
A fourth FCR (FCR D) provides the non-critical monitoring and display functions and is also
part of the inter-FCR Byzantine voting structure.
Isolation is provided between FCRs wherever interfaces are required, to ensure that faults
cannot propagate between them.
2. Application
CAUTION:
The Expander Interface Module must reside in one of the I/O slots within the
Controller Chassis. Modules must be configured as a pair in the System Configuration
Tool, in adjacent slots, and with the left hand slot an odd numbered slot. An even
numbered slot can only be configured as an Expander Interface Module if the
preceding odd numbered slot is already configured as an Expander Interface Module.
To provide redundancy the Modules can be installed in pairs, but can also be installed
singly, in either configured slot. If a single Module is installed the adjacent slot in the
configured pair must be empty. Expander Interface Modules must not be fitted in the
triple-width Main Chassis Processor slots as this may cause damage to the Modules.
The two Interface slots must be interconnected using the Expander Interface Adapter Unit
T8312.
The Expander Interface Modules are connected to the Expander Processor Modules by the
Expander Interface Hot Link Cable TC-301 via the Trusted Expander Interface Adapter Unit
T8312.
The connection to remote Expander Chassis is via the Trusted Fibre Optic Tx/Rx Unit using
the Expander Interface Adapter to Fibre Tx/Rx Unit (Remote Expanders) Cable TC-302.
CAUTION:
The module contains static sensitive parts. Static handling precautions must be
observed. Specifically ensure that exposed connector pins are not touched. Under no
circumstances should the module housing be removed.
Before installation, visually inspect the module for damage. Ensure that the module housing
appears undamaged and inspect the I/O connector at the back of the module for bent pins.
If the module appears damaged or any pins are bent, do not install the module. Do not try
to straighten bent pins. Return the module for replacement.
Ensure that the module is of the correct type.
Record the module type, revision and serial number of the module before installation.
If the module is to reside in a new chassis, or the system is being configured for the first
time, ensure that the chassis address has been set correctly before installing the modules.
See Controller Chassis Product Description (PD-T8100) for further details.
To install the module:
1. Ensure that the cable assembly is correctly located.
2. Release the ejector tabs on the module using the release key. Ensure that the ejector
tabs are fully open.
3. Holding the ejectors, carefully insert the module into the intended slot.
4. Push the module fully home by pressing on the top and bottom of the module fascia.
5. Close the module ejectors, ensuring that they click into their locked position.
If the original module has reported faults, the TMR Processor may automatically initiate the
changeover to the newly installed module. Manual changeover may be initiated either using
the ejector tabs on the original module or using commands via the diagnostic interface. To
initiate the changeover using the ejector tabs use the following sequence:
1. Release both the top and bottom ejector tabs on the original module using the
ejector release tool. DO NOT remove the module.
2. Wait until the original module indicates that it is in the standby mode of operation
and the newly installed module is in the active mode.
3. Remove the original module.
Note: Under no circumstances remove a module that is indicating ACTIVE mode. Removal of an Active Module
may result in Modules within the Chassis adopting their default (shutdown) state, and initiate shutdown states
via the application program.
In Hot-standby configurations, with both Expander Interface Modules installed, the faulted
module may be either the active or the standby module. In most cases the system will
automatically switch to the healthiest module, therefore only the standby module will
require replacement. To replace the active module follow the steps described above. To
replace the standby module:
1. Release both the top and bottom ejectors tabs on the standby module using the
ejector release tool.
2. Ensure that the other module is indicating the active mode of operation.
3. Remove the standby module.
In Hot-standby configurations, the replacement module should then be installed in the
position where the previous module was removed. This module will become the standby
module.
Where it is critical to maintain system operation additional chassis may be installed and
on-line operation maintained by transferred control to modules within that chassis using the
I/O modules Smart Slot capability.
Cable Exit
Polarising/Keying
Pins. Trusted Smart Swap
Connector
(Remove using Cable hood if Fitted
side cutters where
identified below)
12
Release button
For Cables with Companion Slot installations both keying strips must be polarised.
For this Module (T8311) remove keying pins 1, 2, 6.
3. Operation
• System Watchdog
As with the message forwarding, these signals are re-synchronised and majority voted, i.e.
Byzantine voted at the TMR Expander Interface and TMR Expander Processor Modules. The
signals are synchronous within the Expander Chassis even in the case of a fault within the
Processor Chassis.
OEM PARAMETERS
TICS_CHASSIS 1 This value is fixed (Expander Interface Modules may only be placed in
the Processor Chassis) and is included for consistency with other
Modules in the Trusted range.
TICS_SLOT 1 - 8 (Chassis 1) The Processor Chassis slot number in which the primary Expander
Interface Module is placed. By definition, this must be an odd
numbered slot. The secondary Module, if configured, resides in an
even numbered slot adjacent, and to the right of the primary.
CONFIGURATION
Physical Module:
APPENDIX:
Bit 1 AM slice B:
1 - Slice is responding and there are no slice errors.
0 - Slice is either NOT responding or there is a slice error.
Bit 2 AM slice C:
1 - Slice is responding and there are no slice errors.
0 - Slice is either NOT responding or there is a slice error.
Bit 4 SM slice A:
1 - Slice is responding and there are no slice errors.
0 - Slice is either NOT responding or there is a slice error.
Bit 5 SM slice B:
1 - Slice is responding and there are no slice errors.
0 - Slice is either NOT responding or there is a slice error.
Bit 6 SM slice C:
1 - Slice is responding and there are no slice errors.
0 - Slice is either NOT responding or there is a slice error.
Bit
15 14 13 12 11 10 9 8 7 6 5 4 3 2 1 0
To scale the value arithmetically simply divide the returned ‘integer’ by 512 to return the
voltage as either a REAL or INTEGER as required.
The input conversion tables may be used to convert the input value to engineering units, in
this case voltage. This is the recommended method where the value is not to be used
directly. The full-scale range for this number format is decimal ±256, corresponding to
physical range –32768 to +32767.
• Expander Bus link quality, including receive error counts for each communications
link and link status.
• Received message error, on a per link/FCR basis, including frame error, checksum
error and discrepancy.
• HIFT Clock, master and slave clock status, and master/slave switching.
PIN E D C B A
10
16 GND
19
25 GND
28
PIN E D C B A
34 GND
37
4. Operation
4.1.2. Active
In the Active Mode, the Module is responsible for the forwarding of messages from the
Controller Chassis IMB to the Expander Bus, and response messages from the Expander Bus
to the Controller Chassis IMB. The Module also provides all of the functions available within
the Standby Mode of operation.
5.2. Troubleshooting
Symptom Possible Cause Solution
All front panel Lack of power If all other modules within the chassis also show no indicators, check
indicators off the power distribution and connection to the chassis.
Front Panel interface Check if other modules within the chassis have LEDs illuminated.
(FCR D) failure Check if it is possible to communicate with other modules within the
chassis – using either the chassis board type (T8300) or the
diagnostic utility. If communications is possible and this is the only
Expander Processor installed, the failure is within FCRD and the
module should be replaced,
If another Expander Processor module is installed, check its status
indication. If the other module is indicating active mode, check if
communications with the potentially faulty module is possible (again
using either the Expander Chassis board or diagnostic utility). If
communications is possible, note the information returned as part of
the Expander Processor board and then initiate the module
replacement.
Single FCR indicator Single main FCR The module will continue to provide communications between the
flashing RED failure. expander bus and the modules within the chassis. However, the
module should be replaced as soon as practical.
Multiple FCR Multiple failure. This condition may be indicated briefly during module power-up, but
indicating flashing in other circumstances, this indicates a failure beyond the modules
RED fault tolerant capabilities.
If the failed module is not the active module, it should be removed
immediately. A replacement module should be installed as soon as
practical.
If the module was the active module, the system will attempt to
switch to the standby, if it is installed and if the failures do not occur
simultaneously.
Flashing standby Software detected This indicates that the TMR Processor has detected a fault within the
indicator fault module and has switched to the previously standby module. The
faulted module should be removed as soon as possible and a
replacement installed as soon as practical.
Both active or LED failure This condition may be indicated briefly during module power-up.
standby LEDs OFF If another Expander Processor module is installed within the same
chassis, use its indicators to verify the active/standby mode of this
module. To avoid confusion it is recommended that this module be
replaced at some convenient time, initiating the active/standby
changeover to the other module if necessary.
All other modules TMR Processor not Verify the condition of the TMR processor and start the application
within the chassis running (faulted, or as necessary.
indicate standby application not
mode. started).
Expander Processor Verify the Expander Processor is faulty by checking the reported
Fault condition within the T8300 chassis board or the diagnostic utility. If
the module is shown not to be responding, replace the module
immediately.
Expander Bus Fault Verify that the fault is not the result of a failed Expander Processor
(see above).
Check that the Expander Bus is connected correctly at both the
Processor and Expander Chassis.
Check that the Expander Processor(s) are installed in the correct
slot(s).
Minor BIU errors Interface Module The error counters for a single module will be incrementing. Check
counters Fault the values using the diagnostic utility. If the count exceeds a defined
incrementing limit, the system will attempt to indicate this fault by setting the
corresponding healthy LED on the module to red flashing.
Replace the faulty interface module.
Expander Processor The error counters for all the modules within the corresponding
Fault chassis will be incrementing. Check the values using the diagnostic
utility. If the count exceeds a defined limit, the system will attempt
to indicate this fault by setting the corresponding healthy LED on the
module to red flashing.
Replace the faulty Expander Processor module as soon as possible.
6. Specifications
Dimensions