Implementing Function Blocks for Safety Systems using Inovance InoProShop / AutoShop requires translating a control narrative into code, tests, and commissioning checks. This hands-on guide focuses on practical implementation steps, an illustrative code example, and decisions that should be recorded during design review.
The guide uses InoProShop / AutoShop terminology and Function Blocks because process control, continuous operations, modular programming, and signal flow visualization. Confirm language support for the selected controller and software release, then map the example's 5 sensor inputs and 4 actuator outputs to the project's reviewed I/O list.
Real Safety Systems projects in Universal face practical challenges including safety integrity level (sil) compliance, redundancy requirements, and integration with existing systems. Success requires balancing visual representation of signal flow against can become cluttered with complex logic, while meeting 4-8 weeks project timelines typical for Safety Systems implementations.
This guide provides step-by-step implementation guidance, an illustrative example, practical design patterns, and troubleshooting scenarios. Compile and test the adapted logic in an isolated environment, verify fail-safe behavior with the responsible controls and safety reviewers, and complete site acceptance checks before production use.
Inovance InoProShop / AutoShop for Safety Systems
InoProShop / AutoShop is a programming environment associated with Inovance controller families such as AM600, AM610, H5U. This guide uses Function Blocks terminology from the supplied guide dataset, but controller capabilities and language support can change by model, firmware, software edition, and license.
Verify Before You Start:
- The selected controller supports the required Function Blocks constructs
- The project version matches the installed InoProShop / AutoShop release
- Required communications, motion, safety, and simulation options are licensed
- Firmware and device-description files are compatible with the project
- The vendor manuals used for the design match the exact hardware revision
Application Planning:
For a Safety Systems exercise, map the required inputs and outputs before writing logic. The example considers 5 sensor types, including Safety light curtains, Emergency stop buttons, Safety door switches, and 4 actuator types.
Control Equipment for Safety Systems:
- Safety PLCs (fail-safe controllers)
- Safety relays (configurable or fixed)
- Safety I/O modules with diagnostics
- Safety network protocols (PROFIsafe, CIP Safety)
Controller-family references used in this guide include:
- AM600: Confirm CPU, I/O, memory, communications, and Function Blocks support in the current selection guide
- AM610: Confirm CPU, I/O, memory, communications, and Function Blocks support in the current selection guide
- H5U: Confirm CPU, I/O, memory, communications, and Function Blocks support in the current selection guide
- AC800: Confirm CPU, I/O, memory, communications, and Function Blocks support in the current selection guide
Hardware Selection Checklist:
- Count local and remote I/O, including planned expansion
- Measure the required task and communications update rates
- Identify memory, data-retention, diagnostics, and cybersecurity requirements
- Treat safety functions as a separate, standards-led design activity
- Confirm lifecycle status, regional availability, licensing, and support
Source and Validation Note:
This page does not represent a vendor certification or a hardware acceptance test. Use current Inovance manuals, release notes, and safety documentation as the authority for product-specific behavior. Validate adapted logic in a simulator or isolated test setup before connecting it to equipment.
Investment Considerations:
For Safety Systems projects, compare hardware, software licensing, training, engineering, test equipment, commissioning, spares, and ongoing support. Obtain current pricing and lifecycle information directly from the vendor or an authorized regional supplier.
Understanding Function Blocks for Safety Systems
Function Block Diagram (FBD) is a graphical programming language where functions and function blocks are represented as boxes connected by signal lines. Data flows from left to right through the network.
Execution Model:
Blocks execute based on data dependencies - a block executes only when all its inputs are available. Networks execute top to bottom when dependencies allow.
Core Advantages for Safety Systems:
- Visual representation of signal flow: Critical for Safety Systems when handling advanced control logic
- Good for modular programming: Critical for Safety Systems when handling advanced control logic
- Reusable components: Critical for Safety Systems when handling advanced control logic
- Excellent for process control: Critical for Safety Systems when handling advanced control logic
- Good for continuous operations: Critical for Safety Systems when handling advanced control logic
Why Function Blocks Fits Safety Systems:
Safety Systems systems in Universal typically involve:
- Sensors: Emergency stop buttons (Category 0 or 1 stop), Safety light curtains (Type 2 or Type 4), Safety laser scanners for zone detection
- Actuators: Safety contactors (mirror contact type), Safe torque off (STO) drives, Safety brake modules
- Complexity: Advanced with challenges including Achieving required safety level with practical architecture
Programming Fundamentals in Function Blocks:
StandardBlocks:
- logic: AND, OR, XOR, NOT - Boolean logic operations
- comparison: EQ, NE, LT, GT, LE, GE - Compare values
- math: ADD, SUB, MUL, DIV, MOD - Arithmetic operations
TimersCounters:
- ton: Timer On-Delay - Output turns ON after preset time
- tof: Timer Off-Delay - Output turns OFF after preset time
- tp: Pulse Timer - Output pulses for preset time
Connections:
- wires: Connect output pins to input pins to pass data
- branches: One output can connect to multiple inputs
- feedback: Outputs can feed back to inputs for state machines
Best Practices for Function Blocks:
- Arrange blocks for clear left-to-right data flow
- Use consistent spacing and alignment for readability
- Label all inputs and outputs with meaningful names
- Create custom FBs for frequently repeated logic patterns
- Minimize wire crossings by careful block placement
Common Mistakes to Avoid:
- Creating feedback loops without proper initialization
- Connecting incompatible data types
- Not considering execution order dependencies
- Overcrowding networks making them hard to read
Typical Applications:
1. HVAC control: Directly applicable to Safety Systems
2. Temperature control: Related control patterns
3. Flow control: Related control patterns
4. Batch processing: Related control patterns
Understanding these fundamentals prepares you to implement effective Function Blocks solutions for Safety Systems using Inovance InoProShop / AutoShop.
Implementing Safety Systems with Function Blocks
Safety system control uses safety-rated PLCs and components to protect personnel and equipment from hazardous conditions. These systems implement safety functions per IEC 62443 and ISO 13849 standards with redundancy and diagnostics.
This walkthrough demonstrates practical implementation using Inovance InoProShop / AutoShop and Function Blocks programming.
System Requirements:
A typical Safety Systems implementation includes:
Input Devices (Sensors):
1. Emergency stop buttons (Category 0 or 1 stop): Critical for monitoring system state
2. Safety light curtains (Type 2 or Type 4): Critical for monitoring system state
3. Safety laser scanners for zone detection: Critical for monitoring system state
4. Safety interlock switches (tongue, hinged, trapped key): Critical for monitoring system state
5. Safety mats and edges: Critical for monitoring system state
Output Devices (Actuators):
1. Safety contactors (mirror contact type): Primary control output
2. Safe torque off (STO) drives: Supporting control function
3. Safety brake modules: Supporting control function
4. Lock-out valve manifolds: Supporting control function
5. Safety relay outputs: Supporting control function
Control Equipment:
- Safety PLCs (fail-safe controllers)
- Safety relays (configurable or fixed)
- Safety I/O modules with diagnostics
- Safety network protocols (PROFIsafe, CIP Safety)
Control Strategies for Safety Systems:
1. Primary Control: Safety-rated PLC programming for personnel protection, emergency stops, and safety interlocks per IEC 61508/61511.
2. Safety Interlocks: Preventing Safety integrity level (SIL) compliance
3. Error Recovery: Handling Redundancy requirements
Implementation Steps:
Step 1: Perform hazard analysis and risk assessment
In InoProShop / AutoShop, perform hazard analysis and risk assessment.
Step 2: Determine required safety level (SIL/PL) for each function
In InoProShop / AutoShop, determine required safety level (sil/pl) for each function.
Step 3: Select certified safety components meeting requirements
In InoProShop / AutoShop, select certified safety components meeting requirements.
Step 4: Design safety circuit architecture per category requirements
In InoProShop / AutoShop, design safety circuit architecture per category requirements.
Step 5: Implement safety logic in certified safety PLC/relay
In InoProShop / AutoShop, implement safety logic in certified safety plc/relay.
Step 6: Add diagnostics and proof test provisions
In InoProShop / AutoShop, add diagnostics and proof test provisions.
Inovance Function Design:
InoProShop strongly favours function-block reuse via the Library Manager — Inovance ships standard libraries for motion, drives, HMI, OPC UA, and industry-specific applications (lithium-battery, EV, elevator). AutoShop reuse is open-coded via P-label subroutines. OEM machine-builders increasingly default to InoProShop / AM600 to access the FB libraries.
Common Challenges and Solutions:
1. Achieving required safety level with practical architecture
- Solution: Function Blocks addresses this through Visual representation of signal flow.
2. Managing nuisance trips while maintaining safety
- Solution: Function Blocks addresses this through Good for modular programming.
3. Integrating safety with production efficiency
- Solution: Function Blocks addresses this through Reusable components.
4. Documenting compliance with multiple standards
- Solution: Function Blocks addresses this through Excellent for process control.
Safety Considerations:
- Use only certified safety components and PLCs
- Implement dual-channel monitoring per category requirements
- Add diagnostic coverage to detect latent faults
- Design for fail-safe operation (de-energize to trip)
- Provide regular proof testing of safety functions
Performance Metrics:
- Task and I/O timing: Record minimum, average, and maximum values under a defined test load
- Accuracy: Define an acceptable tolerance and compare it with calibrated reference measurements
- Throughput: Count completed cycles over a fixed interval and record rejected or incomplete cycles
- Fault response: Measure detection, safe-state, alarm, and recovery behavior for each test case
- Resource use: Record memory, communications load, and diagnostic-buffer behavior
Inovance Diagnostic Tools:
InoProShop online mode with full POU monitoring and breakpoint debug,EtherCAT diagnostics page with topology and slave status,Trace tool for analogue / motion signal capture,OPC UA server diagnostics page,Modbus communication trace utility,AutoShop online mode for legacy AC800 / Easy series,Inovance HMI integrated diagnostics for HMI-PLC binding faults,Servo-drive panel diagnostics with InoProShop drive-monitor view,EtherCAT slave-firmware update tool,Project compare tool for change tracking
Use the monitoring and diagnostic functions available in your InoProShop / AutoShop version, and record the software, firmware, hardware, workload, and test procedure with every result.
Inovance Function Blocks Example for Safety Systems
Illustrative Function Blocks example for Safety Systems using Inovance terminology. Adapt the syntax to your InoProShop / AutoShop release, compile it, and verify it in an isolated test environment before use on equipment.
(* Inovance InoProShop / AutoShop - Safety Systems Control *)
(* Reusable Function Blocks Implementation *)
(* InoProShop strongly favours function-block reuse via the Lib *)
FUNCTION_BLOCK FB_SAFETY_SYSTEMS_Controller
VAR_INPUT
bEnable : BOOL; (* Enable control *)
bReset : BOOL; (* Fault reset *)
rProcessValue : REAL; (* Emergency stop buttons (Category 0 or 1 stop) *)
rSetpoint : REAL := 100.0; (* Illustrative value; replace with a reviewed requirement *)
bEmergencyStop : BOOL; (* Safety input *)
END_VAR
VAR_OUTPUT
rControlOutput : REAL; (* Safety contactors (mirror contact type) *)
bRunning : BOOL; (* Process active *)
bComplete : BOOL; (* Cycle complete *)
bFault : BOOL; (* Fault status *)
nFaultCode : INT; (* Diagnostic code *)
END_VAR
VAR
(* Internal Function Blocks *)
fbSafety : FB_SafetyMonitor; (* Safety logic *)
fbRamp : FB_RampGenerator; (* Soft start/stop *)
fbPID : FB_PIDController; (* Process control *)
fbDiag : FB_Diagnostics; (* InoProShop alarms are typically defined in the visualisation alarm-configuration page with severity, latching, and acknowledgement behaviour configured per alarm. The runtime maintains active and historical alarm lists. AutoShop projects fall back to M-flag banks with HMI-side alarm logging. *)
(* Internal State *)
eInternalState : E_ControlState;
tonWatchdog : TON;
END_VAR
(* Safety Monitor - Use only certified safety components and PLCs *)
fbSafety(
Enable := bEnable,
EmergencyStop := bEmergencyStop,
ProcessValue := rProcessValue,
HighLimit := rSetpoint * 1.2,
LowLimit := rSetpoint * 0.1
);
(* Main Control Logic *)
IF fbSafety.SafeToRun THEN
(* Ramp Generator - Prevents startup surge *)
fbRamp(
Enable := bEnable,
TargetValue := rSetpoint,
RampRate := 20.0, (* Illustrative value; tune and verify for the process *)
CurrentValue => rSetpoint
);
(* PID Controller - Process regulation *)
fbPID(
Enable := fbRamp.InPosition,
ProcessValue := rProcessValue,
Setpoint := fbRamp.CurrentValue,
Kp := 1.0,
Ki := 0.1,
Kd := 0.05,
OutputMin := 0.0,
OutputMax := 100.0
);
rControlOutput := fbPID.Output;
bRunning := TRUE;
bFault := FALSE;
nFaultCode := 0;
ELSE
(* Safe State - Implement dual-channel monitoring per category requirements *)
rControlOutput := 0.0;
bRunning := FALSE;
bFault := NOT bEnable; (* Only fault if not intentional stop *)
nFaultCode := fbSafety.FaultCode;
END_IF;
(* Diagnostics - InoProShop on AM600 / H5U supports SD-card logging via library FBs, plus OPC UA streaming for cloud / on-premises historians. Inovance HMIs add CSV logging at HMI tier. AutoShop projects rely on HMI-tier logging exclusively. *)
fbDiag(
ProcessRunning := bRunning,
FaultActive := bFault,
ProcessValue := rProcessValue,
ControlOutput := rControlOutput
);
(* Watchdog - Detects frozen control *)
tonWatchdog(IN := bRunning AND NOT fbPID.OutputChanging, PT := T#10S);
IF tonWatchdog.Q THEN
bFault := TRUE;
nFaultCode := 99; (* Watchdog fault *)
END_IF;
(* Reset Logic *)
IF bReset AND NOT bEmergencyStop THEN
bFault := FALSE;
nFaultCode := 0;
fbDiag.ClearAlarms();
END_IF;
END_FUNCTION_BLOCKCode Explanation:
- 1.Encapsulated function block follows InoProShop strongly favours function-blo - reusable across Universal projects
- 2.FB_SafetyMonitor illustrates status checks and high/low limits; it is not a certified safety function
- 3.FB_RampGenerator prevents startup issues common in Safety Systems systems
- 4.FB_PIDController tuned for Universal: Kp=1.0, Ki=0.1
- 5.Watchdog timer illustrates one way to flag an unchanged output for diagnosis
- 6.Diagnostic function block enables InoProShop on AM600 / H5U supports SD-card logging via library FBs, plus OPC UA streaming for cloud / on-premises historians. Inovance HMIs add CSV logging at HMI tier. AutoShop projects rely on HMI-tier logging exclusively. and InoProShop alarms are typically defined in the visualisation alarm-configuration page with severity, latching, and acknowledgement behaviour configured per alarm. The runtime maintains active and historical alarm lists. AutoShop projects fall back to M-flag banks with HMI-side alarm logging.
Best Practices
- ✓Follow Inovance naming conventions: On InoProShop projects, conventions follow CODESYS / IEC norms — PascalCase for
- ✓Inovance function design: InoProShop strongly favours function-block reuse via the Library Manager — Inova
- ✓Data organization: InoProShop uses GVLs and persistent variables for shared data. AutoShop uses D /
- ✓Function Blocks: Arrange blocks for clear left-to-right data flow
- ✓Function Blocks: Use consistent spacing and alignment for readability
- ✓Function Blocks: Label all inputs and outputs with meaningful names
- ✓Safety Systems: Keep safety logic simple and auditable
- ✓Safety Systems: Use certified function blocks from safety PLC vendor
- ✓Safety Systems: Implement cross-monitoring between channels
- ✓Debug with InoProShop / AutoShop: Use InoProShop's online mode to set breakpoints in POUs and step throu
- ✓Safety: Use only certified safety components and PLCs
- ✓Use a compatible simulator or isolated test rig to test Safety Systems logic before deployment
Common Pitfalls to Avoid
- ⚠Function Blocks: Creating feedback loops without proper initialization
- ⚠Function Blocks: Connecting incompatible data types
- ⚠Function Blocks: Not considering execution order dependencies
- ⚠Inovance common error: EtherCAT slave order mismatch after physical re-cabling — slave addressing break
- ⚠Safety Systems: Achieving required safety level with practical architecture
- ⚠Safety Systems: Managing nuisance trips while maintaining safety
- ⚠Neglecting to validate Emergency stop buttons (Category 0 or 1 stop) leads to control errors
- ⚠Insufficient comments make Function Blocks programs unmaintainable over time
Related Certifications
Applying Function Blocks to Safety Systems using Inovance InoProShop / AutoShop requires understanding the platform, the process, and the project's acceptance criteria. This guide has covered implementation structure, an illustrative code example, verification practices, and common pitfalls for a advanced Safety Systems exercise.
Use the practices outlined here to create a design that can be reviewed and tested. Define performance targets in the project requirements and confirm them with repeatable measurements.
Next Steps:
1. Check Sources: Read the current InoProShop / AutoShop help, controller manual, release notes, and relevant standards
2. Practice Safely: Adapt the example in a simulator or isolated training setup
3. Review: Have the I/O map, state behavior, faults, and recovery steps reviewed
4. Test: Record normal, boundary, fault, restart, and communications test results
Function Blocks Foundation:
Function Block Diagram (FBD) is a graphical programming language where functions and function blocks are represented as boxes connected by signal line...
Project duration depends on scope, reviews, hardware availability, software and firmware versions, testing, commissioning, and site constraints. Remember: Keep safety logic simple and auditable
For further learning, explore related topics including Temperature control, Emergency stop systems, and Inovance platform-specific features for Safety Systems optimization.