Automation Glossary • PROFIsafe

What Is PROFIsafe?

Merobix Engineering • • 7 min read

PROFIsafe lets a safety function - an emergency stop, a light curtain, a safe torque off - run over the very same PROFINET or PROFIBUS cable as ordinary control traffic, without a separate safety bus. It does this with an extra safety layer that trusts the network to fail in detectable ways. This page explains what PROFIsafe is and how the black-channel principle works, at a conceptual level.

Back to Blog

PROFIsafe in one line: PROFIsafe is the functional-safety profile that carries safety-rated I/O over a standard PROFINET or PROFIBUS network. It adds a safety layer on top of the normal communication that detects the errors a network can introduce - loss, delay, repetition, wrong sequence, corruption - using measures like a consecutive number, a timeout, a safety code, and a safety address, so the standard network is treated as an untrusted black channel.

The Black-Channel Principle

The central idea of PROFIsafe is the black channel. Rather than certifying the whole network to a safety standard, PROFIsafe treats the underlying PROFINET or PROFIBUS transport as untrusted - a black channel that may lose, delay, repeat, reorder, or corrupt a message. It then wraps each safety message in an additional safety layer whose job is to detect every one of those failure modes. If the safety layer cannot confirm a message arrived correctly and in time, the receiving device goes to its safe state.

This is powerful because it means safety and standard data share the same cable, switches, and controllers, cutting hardware and wiring, while the safety integrity comes from the endpoints, not the network. It is the same reason a shared device can carry standard submodules for the PLC and safety submodules for a safety controller on one rack. Because this is safety-instrumented territory, the design, validation, and any parameter choices must follow the applicable functional-safety standards and be carried out by qualified personnel to the site's safety procedures.

What the Safety Layer Adds

The safety layer adds a handful of measures, each aimed at a specific network failure. A consecutive number lets the receiver detect a lost, repeated, or out-of-order message. A timeout, watched by a safety watchdog, catches a message that arrives too late - a delay that could otherwise leave a stale command in force. A safety code (a checksum over the safety data) catches corruption. And a unique safety address, the F-address, ensures a safety message is accepted only by its intended device, so a misrouted frame cannot be acted on.

The F-address is worth singling out because it is a common commissioning task and a common mistake: each safety device is assigned a unique F-address, and it must match between the safety program and the device or the connection will not run. This resembles a stricter version of ordinary station naming, and errors in it fail safe rather than silently. A monitoring platform such as Merobix may trend non-safety status a controller exposes about a safety system, but it is not part of the safety function itself; the safety loop lives entirely in the certified safety devices and their PROFIsafe layer.

Commissioning Steps and the F-Parameters

Bringing a PROFIsafe device online involves a small set of safety-specific settings beyond ordinary network configuration. Alongside the F-address, each device carries F-parameters - chief among them the watchdog time - plus device-specific safety parameters that shape its behavior. These live in the safety configuration, are protected by checksums and a program signature, and changing any of them changes the safety function itself, so edits go through the site's management-of-change process and revalidation by qualified personnel rather than casual retuning.

  1. Assign every safety device a unique F-address and record it in the safety documentation.
  2. Enter the F-parameters exactly as the safety design specifies, including the watchdog time taken from the response-time calculation.
  3. Download the safety program and verify its signature matches the validated version on record.
  4. Functionally test each safety function end to end, from initiator to final actuator, and record the result.
  5. Deliberately provoke a passivation - for example by briefly breaking communication - and confirm the device fails safe and reintegrates as designed.

Passivation and Reintegration

When the safety layer detects any of the errors it guards against - a watchdog expiry, a consecutive-number discrepancy, a safety-code failure, an F-address mismatch - the affected device is passivated: its safety outputs stop using process data and substitute their safe values instead. The process consequence is whatever the safety design intends, an axis stopping or a section de-energizing. Once the fault clears, the device is reintegrated, and PROFIsafe supports requiring an explicit operator acknowledgment first, so a machine does not spring back to life on its own the moment a flaky cable reconnects.

For a maintenance team, the passivation history is a diagnostic goldmine. A device that passivates repeatedly is almost always reporting a network problem, not a safety logic problem: marginal cabling, excessive load on the PROFINET segment, update rates mismatched to the watchdog, or electrical noise. The black-channel design means these issues cannot corrupt the safety function - they degrade availability instead - so chasing them is standard network troubleshooting: check diagnostics, port statistics, cabling, and topology, with the safety layer acting as an unusually strict quality monitor.

Where the Watchdog Time Comes From

The watchdog time is the F-parameter people are most tempted to adjust by feel, and the one least suited to it. Set it too short and normal network jitter causes nuisance passivations that stop production for no safety reason. Set it too long and the safety function reacts more slowly, because the watchdog is one term inside the total time from a demand - a person breaking a light curtain - to the actuator reaching its safe state. It is a value that must be long enough for honest communication timing and short enough for the required response, and both bounds are calculated, not guessed.

That calculation belongs to the safety engineering for each safety instrumented function: the demanded response comes from the risk assessment, and the verification that the loop achieves its required safety integrity level uses the watchdog and device safety times as inputs. The working rule for technicians is simple - the watchdog value in the configuration is an output of the safety calculation, and any change to it means the calculation is redone and revalidated by qualified personnel under the applicable functional-safety standards.

Frequently Asked Questions

What is the black channel in PROFIsafe?

The black channel is the standard PROFINET or PROFIBUS network, treated by PROFIsafe as untrusted. PROFIsafe assumes the network may lose, delay, repeat, reorder, or corrupt messages, and adds a safety layer at the endpoints that detects all of those failures. Safety integrity comes from the endpoints, so safety and standard data can share the same cable.

What is an F-address in PROFIsafe?

The F-address is the unique safety address assigned to each PROFIsafe device. It ensures a safety message is accepted only by its intended device, so a misrouted frame cannot be acted on. It must match between the safety program and the device, and a mismatch fails safe by preventing the connection rather than running with the wrong target.

Can PROFIsafe and standard traffic share one network?

Yes, that is the point. Because PROFIsafe's safety measures live in the endpoints and treat the network as a black channel, safety-rated I/O runs over the same cable, switches, and controllers as standard traffic. This cuts hardware and wiring. Design and validation must still follow the applicable functional-safety standards and be done by qualified personnel.

What does passivation mean in PROFIsafe?

Passivation is the fail-safe reaction: when the safety layer detects a communication error, the affected device substitutes safe values for its safety I/O instead of using process data, so the safety function's protective state applies. After the fault clears the device is reintegrated, optionally only after an operator acknowledgment, which prevents equipment from restarting by itself when an intermittent fault heals.

Do I need special switches or cables for PROFIsafe?

No - that is the point of the black channel. PROFIsafe runs over standard PROFINET or PROFIBUS infrastructure, and the safety integrity is provided entirely by the certified endpoints. Network quality still matters, but for availability: marginal cabling or overloaded segments cause nuisance passivations and downtime, not undetected safety failures. Design and validation of the safety functions themselves remain subject to the applicable functional-safety standards.

More in Safety & Protective Systems
Functional safety assessment (FSA)  •  Functional Safety  •  IEC 61508 (functional safety)  •  1oo2 Voting  •  2oo3 Voting  •  All Safety & Protective Systems →
Free SCADA operator training
Merobix University - 70 video lessons & 261 quiz questions, from first login to compliance reporting. No demo call required.
Start free →