CIP Safety is based on the Black Channel concept defined in IEC 61784‑3, where the communication path is treated as unknown and potentially faulty, and safety integrity is achieved through end‑to‑end mechanisms in the Safety Communication Layer (SCL). These mechanisms provide a SIL 3 compatible residual error rate independent of the underlying network and lower protocol layers. However, current applications of IEC 61508-3 standard’s non‑interference requirements can impose stringent architectural constraints when integrating SIL 3 capable CIP Safety stacks into devices whose safety functions require only SIL 1 or SIL 2 to meet application needs.
This paper examines the implications of applying mixed‑criticality non‑interference rules—originally intended to prevent interference between safety‑related software elements—within a Black Channel communication model. It shows that requiring Systematic Capability (SC) 3 non‑interference down to supporting software, operating systems, and hardware can inadvertently mandate full SIL 3 platforms, even when system‑level risk analysis does not justify such integrity levels.
The recently adopted closed communication system option in CIP Safety resolves this tension. In closed systems where the system integrator controls the complete communication network, responsibility for achieving appropriate Systematic Capability shifts to the integrator—aligning with IEC 61508:2010 system design principles. This enables device developers to integrate CIP Safety onto platforms with SC levels proportional to their individual safety functions, while the integrator ensures overall system integrity. The paper concludes by outlining areas investigated within ODVA, including conformance policy interpretation and guidance.
Authors Arun K Guru, Systems Architect/Principal Engineer, Rockwell Automation Steven Seidlitz, Principal Engineer, Rockwell Automation Jim Grosskreuz, Technology Manager, Safety, Rockwell Automation Stina Hornstrom, ABB Robotics David Crane, Senior Staff Engineer, ODVA