nyban1
You are here: Home » Systems » Emergency Shutdown System » Trusted TMR Modules » T8451 Trusted TMR 24 Vdc Digital Output Module
Leave Us A Message

loading

T8451 Trusted TMR 24 Vdc Digital Output Module

  • Rockwell ICS

  • T8451

  • In Stock

  • T/T

  • Xiamen

Availability:
Quantity:
facebook sharing button
twitter sharing button
line sharing button
wechat sharing button
linkedin sharing button
pinterest sharing button
whatsapp sharing button
kakao sharing button
snapchat sharing button
telegram sharing button
sharethis sharing button

The Trusted TMR 24 Vdc Digital Output Module T8451 is a high-integrity, Triple Modular Redundant (TMR) output interface device designed for critical control applications requiring the highest levels of safety and availability. This module interfaces with up to 40 field devices, providing comprehensive diagnostic coverage and fault tolerance through its advanced TMR architecture. Each output channel incorporates triplicated diagnostic testing, including continuous measurements of current and voltage on every portion of the voted output channel, ensuring that the system can detect and withstand single faults without interruption to the controlled process.

The Trusted TMR 24 Vdc Digital Output Module T8451 is a member of the Trusted range of Input/Output Modules, all of which share common functionality and form. At the most general level, all Trusted I/O Modules interface to the Inter-Module Bus (IMB), which provides power and enables communication with the Trusted TMR Processor. The module features a field interface that connects to module-specific signals in the field, and all modules within the Trusted range are constructed with Triple Modular Redundant architecture to ensure the highest levels of system integrity and reliability.

The Trusted TMR 24 Vdc Digital Output Module T8451 has been certified by TüV to IEC 61508 Safety Integrity Level 3 (SIL 3), making it suitable for use in safety-critical applications across a wide range of industries, including oil and gas, chemical processing, power generation, and transportation. The module is designed to operate in demanding industrial environments and provides comprehensive automatic line monitoring to detect both open circuit and short circuit failures in field wiring and load devices.

Key Features

The Trusted TMR 24 Vdc Digital Output Module T8451 offers an extensive array of features that make it an ideal choice for high-integrity output control applications. These features include 40 Triple Modular Redundant output points per module, providing exceptional density and fault tolerance. The module performs comprehensive automatic diagnostics and self-test functions that continuously verify the operational integrity of all critical circuits.

Automatic line monitoring is provided for each individual point, enabling the detection of open circuit and short circuit field wiring and load faults. This feature significantly reduces troubleshooting time and enhances system availability by providing immediate feedback on field wiring conditions. The module incorporates a 2500V impulse withstand opto/galvanic isolation barrier, ensuring robust protection against voltage transients and maintaining isolation between the control system and field circuits.

Automatic overcurrent protection is provided per channel, eliminating the need for external fuses and simplifying system design while enhancing reliability. The Trusted TMR 24 Vdc Digital Output Module T8451 includes onboard Sequence of Events (SOE) reporting with 1 millisecond resolution, enabling precise time-stamped logging of output state changes for detailed process analysis and troubleshooting.

The module supports hot-replacement online using dedicated Companion Slot or SmartSlot configurations. In Companion Slot configurations, two adjacent slots are configured for the same module function, with one slot serving as the primary position and the other as a dedicated secondary or spare position. SmartSlot configurations allow a single spare slot to be shared among multiple primary modules, maximizing slot density in the chassis.

Front Panel output status Light-Emitting Diodes (LEDs) are provided for each point, indicating output status and field wiring faults. Module status LEDs indicate module health and operational mode, including Active, Standby, and Educated states. The module outputs are powered in isolated groups of eight, with each such group designated as a Power Group.

System Architecture

The Trusted TMR 24 Vdc Digital Output Module T8451 is constructed from four principal sections that work together to provide comprehensive functionality and fault tolerance. These sections are the Host Interface Unit, the Field Interface Unit, the Field Termination Unit, and the Front Panel Unit.

Host Interface Unit

The Host Interface Unit serves as the point of access to the Inter-Module Bus for the module. It provides power distribution and local programmable processing power, and is the only section of the I/O Module to directly connect to the IMB Backplane. The Host Interface Unit is common to most high integrity I/O types and performs both type-dependent and product range common functions. Each Host Interface Unit contains three independent slices, commonly referred to as A, B, and C, with all interconnections between the three slices incorporating isolation to prevent any fault interaction between slices. Each slice is considered a Fault Containment Region, as a fault on one slice has no effect on the operation of the other slices.

The Host Interface Unit provides high-speed fault tolerant communications with the Trusted TMR Processor via the IMB interface. An FCR Interconnect Bus between slices enables voting of incoming IMB data and distribution of outgoing I/O Module data to the IMB. The unit provides a galvanically isolated serial data interface to the Field Interface Unit slices, and redundant power sharing of the dual 24 Vdc chassis supply voltage with power regulation for logic power to Host Interface Unit circuitry. Magnetically isolated power is provided to the Field Interface Unit slices, and a serial data interface connects to the Front Panel Unit for module status LEDs.

The SmartSlot link between Active and Standby Modules provides coordination during module replacement activities. Digital Signal Processing capabilities perform local data reduction and self-diagnostics, while local memory resources store module operation data, configuration information, and field I/O data. Onboard housekeeping functions monitor reference voltages, current consumption, and board temperature.

Field Interface Unit

The Field Interface Unit contains the specific circuits necessary to interface to the particular types of field I/O signals. Each Trusted TMR 24 Vdc Digital Output Module T8451 has three Field Interface Units, one per slice. For this digital output module, the Field Interface Unit contains one stage of the output switch structure and a sigma-delta output circuit for each of the 40 field outputs. Two additional sigma-delta circuits provide optional monitoring of the external field I/O supply voltage.

The Field Interface Unit receives isolated power from the Host Interface Unit for logic operations, and provides additional power conditioning for the operational voltages required by its circuitry. An isolated 6.25 Mbit per second serial link connects each Field Interface Unit to one of the Host Interface Unit slices. The Field Interface Unit also measures a range of onboard housekeeping signals that assist in monitoring the performance and operating conditions of the module. These signals include power supply voltages, current consumption, onboard reference voltages, and board temperature.

Field Termination Unit

The Field Termination Unit is the section of the I/O Module that connects all three Field Interface Units to a single field interface. The Field Termination Unit provides the Group Fail-Safe Switches and passive components necessary for signal conditioning, overvoltage protection, and EMI/RFI filtering. When installed in a Trusted Controller or Expander Chassis, the Field Termination Unit field connector interconnects to the Field I/O Cable Assembly attached at the rear of the Chassis.

The SmartSlot link is passed from the Host Interface Unit to the field connections via the Field Termination Unit. These signals go directly to the field connector and maintain isolation from the I/O signals on the Field Termination Unit. The SmartSlot link provides the intelligent connection between Active and Standby Modules for coordination during module replacement.

Front Panel Unit

The Front Panel Unit contains the necessary connectors, switches, logic, and LED indicators for the Front Panel. For every type of Trusted I/O Module, the Front Panel Unit contains the Slice Healthy, Active/Standby, and Educated LED indicators, along with the module removal switches. Additional bicolor LEDs provide status indication for the individual I/O signals. Serial data interfaces connect the Front Panel Unit to each of the Host Interface Unit slices to control the LED status indicators and monitor the module removal switches.

Line Monitoring and Output States

The Trusted TMR 24 Vdc Digital Output Module T8451 automatically monitors the output channel current and voltage to determine the state of the output channel. The numerical output state and line fault status are reported back to the application and provide comprehensive diagnostic information. The line monitoring fault status conditions include field short circuit, output energized with no load, field open circuit, output de-energized, and no field supply voltage.

It is recommended to fit a dummy load resistor to unused outputs so that a current is drawn that exceeds the no-load threshold. This practice helps prevent the module from signaling a no-load fault condition and ensures accurate line monitoring for unused channels.

Fault Detection and Testing

Extensive diagnostics provide automatic detection of module faults within the Trusted TMR 24 Vdc Digital Output Module T8451. The TMR architecture of the output module and the diagnostics performed verify the validity of all critical circuits. Using the TMR architecture provides a fault tolerant method to withstand the first fault occurrence on the module and continue normal output controls without interruption to the system or process.

Faults are reported to the user through the Healthy status indicators on the Front Panel of the module and through the information reported to the Trusted TMR Processor. Under normal operations, all three Healthy indicators are green. When a fault occurs, one of the Healthy indicators will be flashing red, indicating that investigation is recommended. If the cause is within the module, the module should be replaced.

From the Inter-Module Bus to the field connector, the I/O Module contains extensive fault detection and integrity testing. As an output device, most testing is performed in a non-interfering mode. Data input from the IMB is stored in redundant error-correcting RAM on each slice portion of the Host Interface Unit. Received data is voted on by each slice, and all data transmissions include a confirmation response from the receiver.

Periodically, the Trusted TMR Processor commands the onboard Digital Signal Processors to perform a Safety Layer Test. This test results in the Digital Signal Processor verifying with the Trusted TMR Processor its ability to process data with integrity. In addition, the Digital Signal Processor uses Cyclical Redundancy Checks to verify the variables and configuration stored in Flash memory.

Between the Host Interface Unit and Field Interface Unit are a series of galvanically isolated links for data and power. The datalink is synchronized and monitored for variance. Both Field Interface Unit and Host Interface Unit have onboard temperature sensors to characterize temperature-related problems. The power supplies for both the Host Interface Unit and Field Interface Unit boards are redundant, fully instrumented, and testable, forming a Power Integrity Subsystem.

Output Switch Structure

The Trusted TMR 24 Vdc Digital Output Module T8451 provides a TMR switch topology where the load is driven by a total of three fully monitored, fail-safe switch channels, one physically resident on each Field Interface Unit in the module. Any single switch or entire slice failure is designed to leave two of the three fail-safe switch channels operational to power the load.

The upper switches are denoted as Normally Open and are controlled by the Field Interface Unit on which they are physically resident. The lower switches are depicted as Normally Closed and are controlled by the upstream neighboring Field Interface Unit. In this context, Normally Open is defined as being in the off state in the absence of control signal power, and similarly, Normally Closed is the on state in the absence of control signal power. These switches are constructed from enhancement mode MOSFETs and are guaranteed to be off in the absence of module power to create gate voltage signals to bias them on.

The reason that the lower switches are specified to be on in the absence of control signal power is to allow two channels to power the load should an entire slice fail. Even if an entire slice fails, the surviving output circuits will carry the necessary control current to the load.

Switch Diagnostics

During normal operation, Switch 1 and Switch 2 are maintained on. In this state, both switches exhibit a low resistance. To determine the ability of the system to control the load via these switches, their gate voltages are modulated one at a time. As the gate voltages are modulated, the monitoring signals synchronously change in a predictable fashion. The local Digital Signal Processor analyses the relative amplitude and phase of these small AC signals to determine the on resistance and threshold voltages of each switch.

The current to the load does not need to be completely interrupted in order to obtain a level of confidence in the ability of the transistors to turn off. For the TMR switch configuration in the on state, only one fail-safe switch at a time needs to be modulated while the other two bear the load current.

Short Circuit Protection

Output channels of the Trusted TMR 24 Vdc Digital Output Module T8451 are classified as protected under IEC 61131-2, specifically fulfilling the Protected Outputs Requirements. While energized, the channel output current is monitored to protect the channel switches from damage by a sustained overcurrent condition. Having detected a sustained overcurrent condition, a short-circuit fault state is latched and the output is de-energized.

While de-energized, the output may optionally be configured to detect short-circuit field faults through System.INI file configuration. The detection of short-circuits while de-energized relies upon a partial energizing of the field circuit to determine the channel load resistance. The partial energizing of a field circuit is designed to constrain any change in field voltage or current to less than 2 volts or 100 milliamperes, respectively.

A latched short-circuit fault state can be cleared by operating the system Fault Reset button or by transitioning the commanded channel state. The output also includes a non-replaceable fusible link for absolute protection against catastrophic fault conditions.

Group Fail-Safe Switches

To support safe operation, the Trusted TMR 24 Vdc Digital Output Module T8451 is equipped with a series of switches that provide source power to a group of eight output channels, designated as a Power Group. The Output Module Group Fail-Safe Switch is intended as a final control switch which can de-energize any outputs that cannot be de-energized in the normal way. For safety, the presence of two or more faults within the Output Module will cause the Group Fail-Safe Switches to de-energize, resulting in all of the outputs in its group becoming de-energized.

There are three switches in parallel which comprise the Group Fail-Safe Switch, one associated with each slice of the power group. The Group Fail-Safe Switches are controlled via a signal from one of the other two neighboring slices. This means that if one slice determines from the output states that an output is not in a de-energized state when it should be, then it can command its own Group Fail-Safe Switch and those of the other slices Group Fail-Safe Switches to de-energize. This results in two of the three elements of the Group Fail-Safe Switch structure becoming de-energized, leaving only one element energized.

If two slices perform the same action, then the last Group Fail-Safe Switch output will de-energize. This would occur if two or more output switch elements fail in a stuck-on state such that the output cannot de-energize. The Group Fail-Safe Switch control signal is generated by a charge pump driven from the communications clock to the slice power group. If the clock fails, then the Group Fail-Safe Switch bias collapses, ensuring that even if the ability of the slice to communicate with a power group is lost, the Group Fail-Safe Switch can still be de-energized by stopping the communications clock. If a slice fails, the watchdog on the Host Interface Unit will time out and reset the slice, which will shut down the Field Interface Unit power supply and the associated Group Fail-Safe Switch control signal will also de-energize.

Installation and Configuration

Module Insertion and Removal

The Trusted TMR 24 Vdc Digital Output Module T8451 contains static sensitive parts, and static handling precautions must be observed. Specifically, exposed connector pins must not be touched, and under no circumstances should the module housing be removed. Before installation, the module should be visually inspected for damage, ensuring that the module housing appears undamaged and the I/O connector at the back of the module has no bent pins. If the module appears damaged or any pins are bent, it should not be installed and bent pins should not be straightened. The module should be returned for replacement.

To install the module, the field cable assembly must be installed and correctly located. If I/O Module keys are used, all keys must be verified as installed in the correct positions and properly seated in their slots. The ejector tabs on the module are released using the release key, ensuring that the ejector tabs are fully open. Holding the ejectors, the module is carefully inserted into the intended slot. The module is pushed fully home by pressing on the top and bottom of the module fascia, and the module ejectors are closed, ensuring that they click into their locked position.

The module should mount into the chassis with a minimum of resistance. If the module does not mount easily, it should not be forced. The module should be removed and checked for bent or damaged pins. If the pins have not been damaged, reinstalling the module may be attempted.

Cable Selection

I/O cables suitable for use with the Trusted TMR 24 Vdc Digital Output Module T8451 are detailed in the Trusted I/O Companion Slot Cables Product Description and the Trusted I/O SmartSlot Cables Product Description. These product descriptions also detail the types of Field Termination Assembly or Versatile Field Termination Assembly which may be used with this type of module. Custom length multi-core FTA cables are 0.5 square millimeters with a resistance of 40 ohms per kilometer. For example, a 50 meter cable will have 4 ohms loop impedance at 0.5 amperes, which equates to a 2 Vdc volt drop.

Termination

Unused outputs should be commanded off in the application and wired through a 4K7 ohm 0.5 watt resistor to zero volts to maintain proper line monitoring functionality and prevent false fault indications.

Module Pinout Connections

The Trusted TMR 24 Vdc Digital Output Module T8451 utilizes a field connector with multiple rows of connections. The pinout arrangement provides for SmartSlot link connections, output channel connections for all 40 channels organized by Power Group, and Power Group supply and return connections. Each Power Group includes eight output channels with associated positive supply and return connections.

Module Polarization and Keying

All Trusted Modules have been keyed to help prevent insertion into the wrong position within a Chassis. The polarization comprises two parts: the module and the associated field cable. Each module type has been keyed during manufacture. The organization responsible for the integration of the Trusted System must key the cable by removing the keying pieces from the cable so that they correspond with the bungs fitted to the associated module before fitting. For cables with Companion slot installations, both keying strips must be polarized. For the Trusted TMR 24 Vdc Digital Output Module T8451, keying pins 1, 5, and 6 must be removed.

Module Configuration

There is no configuration required to the physical Output Module itself. All configurable characteristics of the module are performed using tools on the Engineering Workstation and become part of the application or System.INI file that is loaded into the Trusted TMR Processor. The Trusted TMR Processor automatically configures the Output Module after applications are downloaded and during Active/Standby changeover.

The IEC 61131 TOOLSET provides the main interface to configure the Output Module. Three procedures are necessary to configure the Output Module: defining the necessary I/O variables for the field output data and module status data using the Dictionary Editor of the IEC 61131 TOOLSET; creating an I/O Module definition in the I/O Connection Editor for each I/O Module, which defines physical information including Chassis and Slot location and allows variables to be connected to the I/O channels of the module; and using the Trusted System Configuration Manager to define custom LED indicator modes, per-channel default or fail-safe states, and other module settings.

Complex Equipment Definition

The T8451 I/O Complex Equipment Definition includes eight I/O boards, referenced numerically by Rack number. These boards include the DO board for OEM parameters and field output status, the STATE board for field output state, the AI board for output voltage, the CI board for output current, the LINE_FLT board for line fault status, the DISCREP board for channel discrepancy, the HKEEPING board for housekeeping registers, and the INFO board for I/O Module information.

Sequence of Events Configuration

Each Boolean Output Variable of the Trusted TMR 24 Vdc Digital Output Module T8451 can be configured for automatic Sequence of Events logging. This applies to the Output Status and Line Fault Status variables. A Boolean variable is configured for SOE during the variable definition in the Data Dictionary Editor. To select SOE, the Extended Button in the Boolean Variable Definition Dialog Box is pressed to open the Extended Definition Dialog, and the box for Sequence of Events is checked to enable the variable for automatic SOE logging.

During operation, the Output Module automatically reports time-stamped change of state information for the output data. The Trusted TMR Processor automatically logs change of state for configured SOE variables into the system SOE Log. The SOE Log can be monitored and retrieved using the SOE and Process Historian Package running on the Engineering Workstation.

Front Panel Operation

Status indicators on the Front Panel of the Trusted TMR 24 Vdc Digital Output Module T8451 provide visual indications of the module's operational status and field output status. Each indicator is a bicolor LED. At the top and bottom of each module is an ejector lever that is used to remove the module from the Chassis. Limit switches detect the open and closed position of the ejector levers. The ejector levers are normally latched closed when the module is firmly seated into the Controller or Expander Chassis.

Module Status LEDs

There are six module status indicators on the Module Front Panel: three Healthy indicators, one Active indicator, one Standby indicator, and one Educated indicator. The Healthy indicators are controlled directly by each module slice. The Active, Standby, and Educated indicators are controlled by the Front Panel Unit. The Front Panel Unit receives data from each of the module slices, performs a 2003 vote on each data bit from the slices, and sets the indicators accordingly.

The Healthy indicators can display various states including Off when no power is applied to the module, Amber when the slice is in the startup state, Green when the slice is healthy, Red flashing when a fault is present on the associated slice but the slice is still operational, Red momentarily upon installation when power is applied to the associated slice, and Red when the associated slice is in the fatal state with a critical fault detected and the slice disabled.

The Active indicator displays Off when the module is not in the Active state, Green when the module is in the Active or Maintain state, Red flashing when the module is in the shutdown state if the Standby LED is off, and Red flashing when the module is in the fatal state if the Standby LED is also flashing.

The Standby indicator displays Off when the module is not in the Standby state, Green when the module is in the Standby state, and Red flashing when the module is in the fatal state with the Active LED also flashing red.

The Educated indicator displays Off when the module is not educated, Green when the module is educated, Green flashing when the module is recognized by the Processor but education is not complete, and Amber flashing when an Active/Standby changeover is in progress.

Output Status Indicators

There are 40 output channel status indicators on the Module Front Panel, one for each field output. These indicators are controlled by the Front Panel Unit, which receives data from each of the module slices and performs a 2003 vote on each data bit from the slices before setting the indicators accordingly. The output status indicator mode is dependent upon the numerical state of the output channel. Each output state can be defined to have a particular indicator mode including off, green, red, flashing green, or flashing red.

The configurable indicator modes allow users to customize the output status indications to suit individual application requirements. Without customization, the default indicator modes indicate Output Off, Output On, No Load output open circuit, Field short circuit output overcurrent protection triggered and output channel latched off, and Channel fault or no field supply voltage.

Fault Finding and Maintenance

Fault Reporting

Output Module faults of the Trusted TMR 24 Vdc Digital Output Module T8451 are reported to the user through visual indicators on the Front Panel of the module and through status variables which may be automatically monitored in the application programs and external system communications interfaces. There are generally two types of faults that must be remedied by the user: external wiring faults and module faults. External wiring faults require corrective action in the field to repair the fault condition, while module faults require replacement of the Output Module.

Field Wiring Faults

By measuring the output channel voltage and current, the module automatically detects field wiring and load faults. When a field signal fails open circuit, short circuit, or there is no field supply voltage connected, the output status indicator will display the configured LED mode, the corresponding output state will be reported, and the line fault status for that channel will be set to 1. All other output channels will be unaffected, except in the case of common cause wiring and supply voltage faults in the field. The field output voltage and current variables can be monitored to determine the actual operating conditions of each output channel, assisting the user in determining the specific type of wiring fault. Once the specific field wiring fault has been identified and corrected, the output status variables and output status indicator will display the normal on/off status of the field device.

Module Faults

Extensive diagnostics provide automatic detection of module faults. The TMR architecture of the Output Module and the diagnostics performed verify the validity of all critical circuits. Using the TMR architecture provides a fault tolerant method to withstand the first fault occurrence on the module and continue normal output controls without interruption to the system or process. Faults are reported to the user through the Healthy status indicators on the Front Panel of the module and through the INFO and HKEEPING variables. Under normal operations all three Healthy indicators are green. When a fault occurs, one of the Healthy indicators will be flashing red. It is recommended that this condition is investigated and if the fault is within the module, it should be replaced.

Companion Slot Configuration

For a Companion Slot configuration, two adjacent slots in a Trusted Chassis are configured for the same Output Module function. One slot is the primary slot and the other a unique secondary or spare slot. The two slots are joined at the rear of the Trusted Chassis with a double-wide I/O Interface Cable that connects both slots to common field wiring terminations. During normal operations, the primary slot contains the Active Module as indicated by the Active indicator on the Front Panel of the module. The secondary slot is available for a spare Module that will normally be the Standby Module as indicated by the Standby indicator on the Front Panel of the module.

Depending on the installation, a hot-spare Module may already be installed, or a Module blank will be installed in the Standby slot. If a hot-spare Module is already installed, transfer to the Standby Module occurs automatically when a Module fault is detected in the Active Module. If a hot-spare is not installed, the system continues operating from the Active Module until a spare Module is installed.

SmartSlot Configuration

For a SmartSlot configuration, the secondary slot is not unique to each primary slot. Instead, a single secondary slot is shared among many primary slots, providing the highest density of Modules to be fitted in a given physical space. At the rear of the Trusted Chassis, a single-wide I/O Cable connects the secondary slot directly to the I/O Cable connected to the failed primary Module. With a spare Module installed in the SmartSlot and the SmartSlot I/O Cable connected to the failed primary Module, the SmartSlot can be used to replace the failed primary Module.

Active/Standby Changeover

The Trusted TMR Processor is responsible for managing a pair of I/O Modules through an Active/Standby changeover. The user must define the primary, and optionally the secondary, I/O Module location for each I/O Module pair. Each primary Module location must be unique and is defined as part of the complex equipment definition within the IEC 61131 TOOLSET. Secondary Module locations can be unique or shared between multiple secondary Modules and are defined within the Module's section within the System.INI file. The system will automatically determine the secondary Module position if the primary Module is installed and is operable.

On initial startup, if the primary Module is installed, it will become the Active Module by default. If the secondary Module has been defined within the System.INI file and no primary Module is present, and if the secondary Module location is unique, the secondary Module will become the Active Module by default. If the secondary Module is installed with no primary Module present, and the secondary Module location is not unique as in a SmartSlot configuration, then no Module for that Module pair will become Active.

In order for a Module to become the Active Module, the Trusted TMR Processor will verify that the Module is the correct I/O Module type and that both Module Removal switches are closed. At this point, the I/O Module is configured and eventually placed in the Active state. A Module in the Active state should never be removed. When a fault occurs on the Active Module, the Trusted TMR Processor will be informed and will attempt an Active/Standby changeover.

Specification Category

Parameter

Value / Description

General Specifications

Product Name

Trusted TMR 24 Vdc Digital Output Module

Product Number

T8451

Number of Output Channels

40

Architecture

Triple Modular Redundant (TMR)

Safety Certification

TüV Certified IEC 61508 SIL 3

Isolation Barrier

2500V impulse withstand opto/galvanic isolation

Sequence of Events Resolution

1 ms

Hot Replacement Support

Yes, with Companion Slot or SmartSlot configurations

Output Power Grouping

Isolated groups of eight channels per Power Group

Electrical Specifications

Nominal Supply Voltage

24 Vdc

Output Type

Digital Output, Protected under IEC 61131-2

Short Circuit Protection

Automatic overcurrent protection per channel, no external fuses required

Fusible Link

Non-replaceable fusible link for absolute protection

Field Supply Voltage Monitoring

Optional monitoring via dedicated sigma-delta circuits

Output Voltage Measurement

Integer value, units of 1/500V, full-scale range ±32000

Output Current Measurement

Integer value, units of 1/1000A, full-scale range ±32000

Current Tolerance

±5 mA up to 1.8 A, thereafter ±5%

Environmental Specifications

Operating Temperature

As specified in current product documentation

Relative Humidity

As specified in current product documentation

Storage Temperature

As specified in current product documentation

Physical Specifications

Module Construction

Four sections: Host Interface Unit, Field Interface Unit, Field Termination Unit, Front Panel Unit

Front Panel Indicators

3 Healthy LEDs, 1 Active LED, 1 Standby LED, 1 Educated LED, 40 Output Status LEDs

Module Removal Mechanism

Ejector levers with limit switches

Keying/Polarization

Module and cable keying, pins 1, 5, 6 removed for T8451

Diagnostic Features

Line Monitoring

Automatic per-point open circuit and short circuit detection

Self-Test

Comprehensive automatic diagnostics with Safety Layer Test

Fault Detection

Stuck-on and stuck-off failure detection

Housekeeping Monitoring

Power supply voltages, current consumption, reference voltages, board temperature

Channel Discrepancy Reporting

Bit-packed status for 40 channels

Fault Reporting

Visual LEDs and status variables (INFO and HKEEPING)

Communications

Interface to Processor

Inter-Module Bus (IMB)

Serial Link to FIU

Isolated 6.25 Mbit/sec per slice

SmartSlot Link

Intelligent connection between Active and Standby Modules

Data Integrity

Redundant error-correcting RAM, CRC verification, voted data transmission

Configuration

Configuration Method

IEC 61131 TOOLSET and System Configuration Manager

OEM Parameters

TICS_CHASSIS and TICS_SLOT for primary module position

Configurable Items

LED indicator modes, per-channel default states, fail-safe states

Short Circuit Detection

Configurable while de-energized via System.INI file

I/O Connection

Field Connector

Multi-row connector with Power Group organization

Cable Type

0.5 mm² multi-core FTA cable, 40 Ω/km resistance

Cable Length Example

50m cable: 4Ω loop impedance, 2Vdc drop at 0.5A

Unused Output Termination

4K7 ohm 0.5W resistor to zero volts

Module Status Indication

Healthy - Off

No power applied to the module

Healthy - Amber

Slice in startup state

Healthy - Green

Slice is healthy

Healthy - Red Flashing

Fault present, slice still operational

Healthy - Red Momentary

Power applied on installation

Healthy - Red

Fatal state, critical fault detected, slice disabled

Active - Green

Module in Active or Maintain state

Active - Red Flashing

Module in shutdown or fatal state

Standby - Green

Module in Standby state

Standby - Red Flashing

Fatal state

Educated - Green

Module is educated

Educated - Green Flashing

Recognized but education not complete

Educated - Amber Flashing

Active/Standby changeover in progress

Output Status Indication

Off

Output is Off

Green

Output is On

Green Flashing

No Load, output open circuit

Red

Field short circuit, overcurrent protection triggered, output latched off

Red Flashing

Channel fault, or no field supply voltage

Compliance

Safety Standard

IEC 61508 SIL 3

Output Protection Standard

IEC 61131-2 Protected Outputs Requirements

Electromagnetic Compatibility

EMI/RFI filtering provided

Revision History

Latest Issue

Issue 15, August 2021

Updates in Issue 15

Updated TechConnect support contract access link, removed By Product search instruction, updated branding

Previous Updates

Specification updates, Front Panel design update, rebranding, typographical corrections

Previous: 
Next: 

Related Products

content is empty!

Quick Links

PRODUCTS

OEM

Contact Us

 Telephone: +86-181-0690-6650
 WhatsApp: +8618106906650
 Email:  sales2@exstar-automation.com / lily@htechplc.com
 Address: Room 1904, Building B, Diamond Coast, No. 96 Lujiang Road, Siming District, Xiamen Fujian, China
Copyright © 2025 Exstar Automation Services Co., Ltd. All Rights Reserved.