Profisafe (usually styled as ''PROFIsafe'', as a
portmanteau
In linguistics, a blend—also known as a blend word, lexical blend, or portmanteau—is a word formed by combining the meanings, and parts of the sounds, of two or more words together. for
Profinet or
Profibus
safety)
is a standard for a communication protocol for the transmission of safety-relevant data in automation applications with
functional safety
Functional safety is the part of the overall safety of a system or piece of equipment that depends on automatic protection operating correctly in response to its inputs or failure in a predictable manner (fail-safe). The automatic protection system ...
. This standard was developed jointly by several automation device manufacturers in order to be able to meet the requirements of the legislator and the
IFA
IFA or Ifa may refer to:
Organisations
Economics
* Independent financial adviser, a type of financial services professional in the UK
* Index Fund Advisors
* Institute and Faculty of Actuaries, representing actuaries in the UK
* Institute of Act ...
for safe systems. The required safe function of the protocol has been tested and confirmed by
TÜV Süd. The PROFIBUS Nutzerorganisation e.V. in Karlsruhe supervises the standardization for the partner companies and organizes the promotion of this common interface.
System structure
Profisafe
defines how safety-related devices (
emergency stop buttons,
light curtain
A light curtain is a safety device that detects when a beam of infrared light has been broken by a person passing through an area.
Light curtains, now more commonly known as opto-electronic devices, are used to safeguard personnel in the vicinit ...
s, overfill prevention devices, ...) communicate safely with safety controllers via
Profinet
Profinet (usually styled as PROFINET, as a portmanteau for Process Field Network) is an industry technical standard for data communication over Industrial Ethernet, designed for collecting data from, and controlling equipment in Automation#Indus ...
,
Profibus
Profibus (usually styled as ''PROFIBUS'', as a portmanteau for Process Field Bus) is a standard for fieldbus communication in automation technology and was first promoted in 1989 by BMBF (German department of education and research) and then u ...
or a
backplane
A backplane or backplane system is a group of electrical connectors in parallel with each other, so that each pin of each connector is linked to the same relative pin of all the other connectors, forming a computer bus. It is used to connect s ...
in such a way that they can be used in safety-related automation tasks up to SIL3 (
Safety Integrity Level). Due to the specification of Profisafe, products of different manufacturers
[Examples of applications with products from different manufacturers can also be found here: ] can be combined to a safe system.
Market relevance
The first version of Profisafe was released as early as 1998.
A second version in 2005 also enabled use via the Ethernet-based Profinet. According to the PROFIBUS Nutzerorganisation e.V., by 2023 a total of almost 21,7 million devices with Profisafe will be placed on the market by the various manufacturers, and a further 2.8 million devices will be added each year.
In the database of the PROFIBUS Nutzerorganisation e.V., 106 different products from 31 different manufacturers are entered in October 2022.
Operating principle
With Profisafe, secure communication is implemented via a profile, i.e., via a special format of the user data and an additional protocol.
Safety-relevant data are transported with Profisafe
as F-messages between an F-Host (safety controller) and its F-Device (safety device) as payload in a telegram of an industrial network. In the case of a modular F-Device with several F-modules, the payload consists of several F-messages. In this case Profisafe has no further requirements for the transmission channel, this is considered as a black channel. Therefore different transport protocols like Profibus or Profinet can be used. Different transmission channels such as copper cable,
fiber optic
An optical fiber, or optical fibre, is a flexible glass or plastic fiber that can transmit light from one end to the other. Such fibers find wide usage in fiber-optic communications, where they permit transmission over longer distances and at ...
cable (FOC),
backplane
A backplane or backplane system is a group of electrical connectors in parallel with each other, so that each pin of each connector is linked to the same relative pin of all the other connectors, forming a computer bus. It is used to connect s ...
bus or
wireless
Wireless communication (or just wireless, when the context allows) is the transfer of information (''telecommunication'') between two or more points without the use of an electrical conductor, optical fiber or other continuous guided transm ...
systems
such as
WLAN
A wireless LAN (WLAN) is a wireless computer network that links two or more devices using wireless communication to form a local area network (LAN) within a limited area such as a home, school, computer laboratory, campus, or office buildin ...
can be used. Neither the transmission rates nor the respective error detection of the transport protocol play a role for safety.
The following figure shows the format of the payload of a "Safety Protocol Data Unit (SPDU)":
The
cyclic redundancy check
A cyclic redundancy check (CRC) is an error-detecting code commonly used in digital networks and storage devices to detect accidental changes to digital data. Blocks of data entering these systems get a short ''check value'' attached, based on ...
(CRC signature) is calculated over all local security parameters, the transmitted data and the locally stored monitoring number of the SPDU. This ensures that all information from the sender and the receiver is consistent without having to always transmit all parameters.
The monitoring number enables the recipient to check whether he has received all the messages in the correct sequence. With the acknowledgement, the monitoring number is returned to the sender for checking within a defined maximum delay time (timeout). Since some bus components, such as switches, have a buffer memory, a 32-bit monitoring number was selected for Profisafe.
The 1:1 communication relationship between F-Host and F-Device simplifies the detection of misdirected F-messages. For this purpose, the sender and receiver require a unique identifier (code name) throughout the network, which is used to verify the authenticity of F-messages. In Profisafe, the code name is also called "F-Address".
The following table shows which errors can be detected by which measure:
Specification
The international standard
IEC 61508
IEC 61508 is an international standard published by the International Electrotechnical Commission (IEC) consisting of methods on how to apply, design, deploy and maintain automatic protection systems called safety-related systems. It is titled '' ...
''Functional safety of electrical/electronic/programmable electronic safety-related systems''.
IEC 62061
IEC/EN 62061, ”Safety of machinery: Functional safety of electrical, electronic and programmable electronic control systems”, is the machinery specific implementation of IEC/EN 61508. It provides requirements that are applicable to the syste ...
''Safety of machinery - Functional safety of safety-related electrical, electronic and programmable electronic control systems'' and
ISO 13849
ISO 13849 is a safety standard which applies to parts of machinery control systems that are assigned to providing safety functions (called safety-related parts of a control system). The standard is one of a group of sector-specific functional safe ...
''Safety of machinery — Safety-related parts of control systems'' are also the basis for Profisafe.
The international standard IEC 61784-3
defines different protocols for safe systems with comparable properties. Profisafe is part 3 of this collection of standards and is thus defined as IEC 61784-3-3:2021 CPF 3.
See also
*
Functional safety
Functional safety is the part of the overall safety of a system or piece of equipment that depends on automatic protection operating correctly in response to its inputs or failure in a predictable manner (fail-safe). The automatic protection system ...
*
IEC 61784-3 Industrialcommunication networks – Profiles – Functional safety fieldbuses
*
IEC 61508
IEC 61508 is an international standard published by the International Electrotechnical Commission (IEC) consisting of methods on how to apply, design, deploy and maintain automatic protection systems called safety-related systems. It is titled '' ...
Functional safety of electrical/electronic/programmable electronic safety-related systems
*
IEC 62061
IEC/EN 62061, ”Safety of machinery: Functional safety of electrical, electronic and programmable electronic control systems”, is the machinery specific implementation of IEC/EN 61508. It provides requirements that are applicable to the syste ...
Safety of machinery - Functional safety of safety-related electrical, electronic and programmable electronic control systems
*
ISO 13849
ISO 13849 is a safety standard which applies to parts of machinery control systems that are assigned to providing safety functions (called safety-related parts of a control system). The standard is one of a group of sector-specific functional safe ...
Safety of machinery - Safety-related parts of control systems
References
[{{cite conference , url = https://www.researchgate.net/publication/224196805 , title = Enabling safety-critical wireless communication using WirelessHART and PROFIsafe , last1 = Akerberg , first1 = Johan , last2 = Reichenbach , first2 = F. , last3 = Björkman , first3 = Mats , date = 2010 , publisher = IEEE , location = , conference = Emerging Technologies and Factory Automation (ETFA) , id = 10.1109/ETFA.2010.5641253 ]
Industrial automation