ICS Triplex System Triple‑Modular Redundant Fault‑Tolerant SIS System Full Technical Brief
1. What is the ICS Triplex System
Now part of Rockwell Automation, ICS Triplex delivers a hardware‑native triple‑modular redundant Safety Instrumented System (SIS). Its flagship product line is the Trusted TMR series, purpose‑built for high‑risk process‑industry conditions. Typical deployments include plant safety interlocks, emergency shutdown and critical machinery safety protection.
Conventional industrial PLCs mostly adopt single‑processor or dual‑hot‑standby redundant architectures, featuring fail‑stop behaviour upon component faults. This cannot satisfy continuous safety protection requirements for high‑hazard operations. The key differentiator of the ICS Triplex system is its Fail‑Operational capability. Built on native TMR triple‑modular‑redundant hardware and certified to IEC 61508 SIL 3, it mitigates major hazards such as equipment damage, hazardous‑media release, fire and explosion triggered by single‑point control‑system failures.
Key Distinction: This system is not a conventional process‑control DCS. It does not execute continuous regulatory control; it functions exclusively as a plant‑equipment safety layer. It also differs from standard dual‑redundant PLCs. Its fault tolerance is implemented via three fully independent hardware paths running in parallel with hardware‑level voting, rather than simple dual‑unit master‑standby software‑synchronised backup. It delivers far superior fault tolerance and safety integrity compared with traditional redundancy schemes.
2. Operating Principle of TMR (Triple Modular Redundancy)
TMR forms the technical foundation of the ICS Triplex platform. It implements full‑link hardware‑based triple physical isolation — not software‑emulated redundancy across three separate PLCs. Triple‑modular design extends across controllers, high‑speed internal buses and I/O modules.
Core operating logic:
- Synchronous operation across three physically‑isolated channelsThree fully segregated hardware processing channels acquire field process signals simultaneously and execute identical safety control logic. Circuits, power supplies and memory are mutually isolated to minimise common‑cause‑failure risk.
- Hardware‑level 2‑out‑of‑3 voting mechanismThis is the heart of fault tolerance. Dedicated hardware voting circuits compare outputs from the three channels for discrete signals. For analogue signals, the system automatically selects the median valid value as the final output. The rule: a result is deemed valid when at least two channels agree, preventing spurious trips caused by single‑channel anomalies.
- Automatic fault isolation with uninterrupted operationUpon hardware damage, transient field interference or computational errors in any single channel, the system identifies and isolates the faulty channel in real time. The remaining two healthy channels maintain full safety‑control functionality without spurious interlock trips or loss of protection. Fault alarms are logged for targeted maintenance.
- Online hot‑swap maintenanceModules associated with a faulty channel can be replaced online without plant shutdown. Safety interlocks and protection remain active throughout maintenance, eliminating safety gaps introduced by repair work.
Simplified analogy: Three independent, isolated referees perform identical evaluations. Majority‑rule logic discards the output of any single faulty referee, while the other two preserve correct decisions without interrupting overall operation.
3. Four‑Tier System Architecture
The ICS Triplex Trusted system uses a clear four‑layer architecture covering acquisition, execution, voting, communication and configuration, delivering stable safety performance for long‑term high‑risk industrial operation.
- Triple‑modular controller rack (core processing unit)Houses TMR triple‑redundant main processors and the dedicated Trusted Bus high‑speed internal triplicated bus. It provides high‑precision clock synchronisation across channels, cross‑data validation and result voting, serving as the core for logic execution, fault discrimination and command output.
- Triple‑modular I/O module layer (field signal interface)Digital input, digital output and analogue I/O implement channel‑level triple redundancy. All I/O modules include built‑in intelligent diagnostics for open‑circuit, short‑circuit and signal‑anomaly detection. Millisecond‑timestamped Sequence‑of‑Events (SOE) logging preserves interlock and fault records to support post‑incident root‑cause analysis.
- Redundant communication interface layer (data‑exchange bridge)Equipped with industrial Ethernet and serial ports, natively supporting Modbus TCP and Modbus RTU. It enables reliable data exchange with DCS, HMI and third‑party monitoring devices. Redundant communication links avoid data loss from single‑link failures.
- Standardised software configuration layer (logic‑management platform)Fully compliant with IEC 61131‑3 international programming standards. Dedicated configuration software handles safety‑logic development, program download, online monitoring and fault‑log retrieval. After download, the system automatically validates logic consistency across the three channels to eliminate hazards from channel‑to‑channel program mismatch.
4. Comparison: TMR System versus Conventional PLC / Dual‑Redundant Systems
In functional‑safety applications, dual hot‑standby redundancy and TMR triple redundancy represent fundamentally different technologies, a key selection criterion distinguishing high‑hazard from general‑purpose scenarios.
| Comparison Item | ICS Triplex TMR Triple‑Modular System | Standard PLC / Dual Hot‑Standby PLC |
|---|---|---|
| Redundancy Implementation | Three fully physically‑independent hardware paths; real‑time hardware‑level voting; no software‑synchronisation drift | Single‑CPU or dual‑unit master‑standby; relies on software data synchronisation with potential synchronisation offset |
| Fault‑mode Behaviour | System continues stable operation after single‑point hardware fault; no shutdown or spurious trips | Failure of the primary unit triggers switchover; switch‑over may induce data disturbance; some faults cause immediate shutdown |
| Safety Certification | Native IEC 61508 SIL 3 (commercial‑grade highest safety integrity level), purpose‑built for SIS | Geared toward regular process control; most lack high‑level SIL certification; limited fault tolerance |
| I/O Redundancy | Channel‑level triple redundancy; per‑channel diagnostics; fault tolerance extends to field signal terminals | No channel‑level redundancy; only whole‑unit redundancy; single‑point I/O fault causes signal loss |
| Maintenance | Faulty modules hot‑swappable online; safety protection remains active throughout repair | Requires whole‑unit switch‑over for maintenance; many interventions demand shutdown, creating safety gaps |
| Typical Application | ESD emergency shutdown, machinery protection, fire‑and‑gas interlocks, high‑hazard plant safety loops | General‑purpose production lines, ordinary process regulation, low‑risk equipment logic control |
Engineering Note: Dual hot‑standby only addresses whole‑unit faults and cannot mitigate component‑ or channel‑level failures. TMR triple redundancy delivers multi‑layer fault tolerance covering components, channels and complete units, offering substantially deeper safety protection.
5. Major Industries and Typical Operating Scenarios
The ICS Triplex TMR system is not intended for low‑risk general‑purpose automation lines. It targets high‑hazard process industries where loss of protection could trigger severe accidents.
- Oil & Gas: ESD emergency‑shutdown systems, fire‑and‑gas (F&G) interlocks for production sites and refineries; safety protection for large compressors and booster units, mitigating risks of hydrocarbon release, fire and explosion.
- Chemical & Petrochemical: Interlock protection for high‑hazard reaction processes in fine‑chemical and petrochemical plants; monitoring of high‑temperature / high‑pressure equipment; emergency‑isolation protection for hazardous process units.
- Power Generation: TSI interlock protection for gas and steam turbines; safety interlocks for boiler pressure and temperature; protection for critical generator auxiliaries, preventing overspeed, over‑pressure and over‑temperature equipment damage.
- Other high‑risk industrial sectors: Coal‑to‑chemical plants, hydrogenation units, energy‑storage chemical facilities and nuclear auxiliary systems requiring strict safety integrity and stability.
Typical safety actions executed: interlock feed cut‑off on over‑temperature / over‑pressure; emergency closure of hazardous‑media valves; automatic machinery trip on overspeed / excessive vibration; interlock activation upon fire or toxic‑gas detection.
6. Key Engineering Implementation & Operational Considerations
Practical design, commissioning and maintenance best practices to prevent performance degradation caused by improper implementation.
- Mitigate common‑cause failures: Although three hardware channels are physically isolated, shared external power supplies, poor earthing, lightning‑induced surges and corrosive ambient conditions can trigger simultaneous multi‑channel faults. Engineering practice must implement independent power feeds for each channel, dedicated surge‑protected earthing and field‑side isolation to realise full TMR fault‑tolerance benefits.
- Control degraded‑mode runtime: Following a single‑channel fault the system enters dual‑channel degraded operation, losing 2‑out‑of‑3 voting capability and substantially reducing safety integrity. Maintenance teams must diagnose and replace faulty modules promptly; prolonged degraded‑mode operation is prohibited.
- Leverage SOE for root‑cause analysis: Built‑in high‑resolution millisecond SOE logging records the exact sequence of interlock and fault events. Export SOE logs immediately after plant trips or interlock actions for incident investigation and hazard identification.
- Firmware‑version governance: Different hardware revisions carry firmware‑compatibility differences. When replacing spares or expanding the system, ensure firmware versions exactly match the existing installation. Arbitrary firmware upgrades or downgrades may induce channel‑synchronisation anomalies and logic malfunctions.
- Respect functional boundaries: Per functional‑safety standards, the ICS Triplex system is a safety‑protection platform dedicated to safety interlocks and emergency protection. Avoid loading extensive continuous regulatory‑control logic. Follow industry‑standard design philosophy: DCS handles process control; SIS handles safety protection.
7. Frequently‑Asked Industry Questions
Q1: Can the TMR triple‑modular system achieve zero trips and zero failures?A: Absolute zero‑trip performance cannot be achieved. TMR’s core value is to avoid spurious trips or loss of protection caused by single‑point hardware faults. When process parameters cross safety thresholds or two‑or‑more channels experience coincident faults, the system executes designed safety‑trip logic to safeguard personnel and assets.
Q2: Can the ICS Triplex SIS directly replace a conventional DCS?A: This is not recommended and violates industry safety specifications. While TMR excels in fault tolerance and high‑reliability interlock protection, it has lower throughput for process computation, limited HMI visualisation capability and inferior continuous regulatory‑control performance compared with purpose‑built DCS platforms. Standard architecture: DCS performs routine process control; the ICS Triplex SIS acts as an independent safety layer to establish dual‑layer process‑control plus safety‑protection defence.
Q3: Is program re‑download required after hot‑swap spare‑module replacement?A: No program re‑download is needed when using genuine matching spare modules for online hot‑swap. Complete system self‑diagnostics after replacement confirming three‑channel synchronisation and zero fault alarms is sufficient to restore normal operation.
Q4: What practical engineering meaning does SIL 3 carry?A: SIL 3 represents the highest commercially‑viable safety‑integrity level under IEC 61508 functional‑safety standards for process‑industry equipment. It defines stringent limits for average probability of dangerous failure and fault‑tolerance performance, satisfying compliance requirements for long‑term operation in oil, gas, chemical and power‑sector high‑hazard installations, and constitutes a core selection metric for plant SIS specifications.
8. Trusted TMR Full‑Range Model Portfolio
Triple‑Modular Main Processors (CPU Core)
T8110B, T8111, T8100, T8123 Note: T8110B / T8111 are the primary triple‑modular processors for the platform. They execute three‑channel logic, hardware voting and system diagnostics as the SIS computational core. Suffix letters denote hardware revisions; cross‑revision mixing‑and‑matching is not permitted.
Communication Processor & Interface Modules
T8151B, T8150, T8153, T8120, T8121, T8310, T8311 Note: T8151B is the primary Ethernet communication card supporting Modbus TCP for HMI and DCS interfacing. T8310 / T8311 are high‑speed bus‑expansion interfaces for rack expansion and I/O‑bus repeaters, maintaining three‑channel synchronisation across multi‑rack installations.
System Power‑Supply Modules
T8200, T8231 Note: Redundant power‑supply units designed for the TMR architecture, supporting dual‑redundant power inputs to maintain independent, stable power for the three CPU channels and mitigate common‑cause power‑loss risks.
Digital Input (DI) Modules
T8402, T8403, T8424, T9402 Note: Full series provides channel‑level triple‑isolated discrete‑input for field status, valve‑position, equipment‑run and interlock signals, with built‑in open‑/short‑circuit diagnostics for standard 24 Vdc industrial environments.
Digital Output (DO) Modules
T8431, T8433, T8451, T8453 Note: Triple‑modular safety‑output channels for emergency shut‑down valves, trip circuits, audible‑visual alarms and interlock outputs. Supports fail‑safe logic complying with SIL 3 safety‑loop requirements.
Analogue I/O (AI / AO) Modules
T8461, T8462, T8480 Note: 4‑20 mA standard analogue triple‑modular input and output for temperature, pressure, level and flow‑signal monitoring. Hardware median‑value voting prevents spurious interlocks from single‑point signal drift.
Dedicated Racks, Backplanes and Base Units
T8800 (12‑slot rack), T8810 (8‑slot rack), T8700 (backplane assembly), T8300 (expansion rack) Note: Trusted‑specific TMR backplane bus. Standard‑PLC racks cannot substitute. The backplane incorporates three independent channel buses, forming the physical foundation for hardware‑level voting.
Fire‑and‑Gas Dedicated Interface Module
T8448 Note: Multi‑channel zone‑interface module dedicated for F&G systems, for flame, combustible‑gas and toxic‑gas interlock protection in large‑scale refineries and oil‑gas facilities.
System Configuration Software
T8081 Trusted Toolset Software Suite Note: Official dedicated software for programming, configuration, download, diagnostics and SOE‑log analysis. Exclusively for the T8000 TMR platform; mandatory tool for compliant maintenance.
9. Critical Engineering Knowledge for Model‑Portfolio Application
- System integrity requirement: Individual modules cannot deliver TMR fault tolerance. A complete 2‑out‑of‑3 safety system requires three independent CPU channels, triple‑modular I/O and dedicated TMR backplane racks.
- Revision‑suffix compatibility: Suffixes A/B/C denote hardware revisions. Form‑factor is identical but firmware logic differs. Mixing different suffix revisions causes three‑channel synchronisation failure and voting malfunction.
- Product‑line distinction: All above‑listed items belong to the Trusted TMR T8000 series (SIL 3 triple‑hardware‑redundant). Do not confuse with the separate ICS Triplex AADvance distributed‑safety platform. Architecture, redundancy logic and firmware are completely non‑interoperable.
- Selection principle: For safety‑compliant applications, deploy a homogeneous full T8000‑series solution. Cross‑product‑line mixing is prohibited to preserve complete fault‑tolerance architecture and safety‑integrity rating.




