
Description:
The 52100 is a time delay module from HIMA Paul Hildebrandt GmbH, built as a timing element within the Planar4 hardwired safety control system. It is not a controller or a programmable logic solver — it is a dedicated, certified hardware timer that inserts one precisely defined delay into a safety circuit, so that a trip or permissive action happens after a set interval rather than instantly.
Used as a single certified element, 52100 supports SIL 3 logic; arranged in 1oo2 or 2oo3 redundancy it contributes to SIL 4 architectures, which is the level Planar4 was designed around. The module runs on 24 VDC, occupies a single Eurocard slot in the Planar4 subrack, and follows the de-energize-to-trip principle: the protective response is triggered by loss of the energized state, so a power interruption or internal fault drives the output to its safe condition rather than leaving the circuit in an indeterminate state. Its adjustable range of 0.1 to 600 seconds covers everything from a few hundred milliseconds of debounce to a ten-minute controlled vent sequence.
Application Scenarios:
Consider a high-integrity pressure protection system on a gas export pipeline. Two pressure transmitters watch the inlet header; when both see high-high pressure, the logic closes the block valve and isolates the downstream facility. The engineering problem is that a genuine overpressure event and a momentary transient — a slug passing, a survey instrument bumping a transmitter, a lightning-induced spike — look identical to a 2oo3 voting gate. Trip instantly on every transient and the pipeline defers production constantly; trip too slowly and the valve closes after the damage is done.
52100 is how that gap is closed in hardware. The voting logic still detects the condition, but the 52100 delays the final de-energization by a defined, certifiable interval — long enough to ride out a transient, short enough that the valve still closes well inside the process safety time. Because the delay is hardwired rather than a software timer in a scanning PLC, its behaviour is deterministic and its value is visible to whoever walks up to the cabinet, which is exactly what a proof-test technician and a functional safety assessor both need.
The same need appears across the Planar4 installed base: offshore drilling platform emergency stops where shutdown stages must be sequenced rather than simultaneous, burner management systems where purge and flame-failure timing must be provable, reactor interlocks in chemical plants that need a stabilization window before final shutdown, fire and gas systems that escalate an alarm before releasing an extinguishing agent, and primary plant trips where a timed stage prevents mechanical damage during a controlled rundown.
Parameter:
| Parameter | Value / Description |
|---|---|
| Product Model | 52100 |
| Manufacturer | HIMA Paul Hildebrandt GmbH + Co KG (Germany) |
| Product Category | Time delay element / timing function module for a hardwired safety control system |
| System Family | HIMA Planar4 — SIL 4-capable hardwired safety logic; also referenced in HIMatrix-era spares listings |
| Safety Integrity | SIL 3 as a single certified element per IEC 61508; SIL 4 capability obtained from a complete 1oo2 or 2oo3 redundant architecture rather than from the card alone |
| Time Delay Range | 0.1 to 600 seconds, one dedicated timing function per module — the certified build covers the standard range; extended-range variants exist |
| Operating Principle | De-energize-to-trip: loss of the energized state initiates the protective response defined by the surrounding circuit, so supply loss or internal fault fails safe |
| Supply Voltage | 24 VDC nominal; module-level consumption is low (single-digit watts), consistent with a hardwired logic card |
| Input / Output | Safety-rated input stage with galvanic isolation from the field loop; safety relay output stage for driving the downstream trip path or final element circuit |
| Mechanical Format | Single Eurocard plug-in module for the Planar4 subrack; approx. 5.1 × 20.3 × 15.2 cm, approx. 0.4 kg; rack-mounted inside the safety cabinet |
| Environmental | Industrial cabinet environment, 5–95% relative humidity non-condensing; designed for continuous duty in process and offshore installations |
| Standards & Certification | IEC 61508 functional safety; equipment standard EN 50178; EMC immunity/emission to EN 61000-6-2 / EN 61000-6-4; ATEX Zone 2 (T4) suitability within the certified Planar4 scope; hardware revision 20 is the referenced valid build |
Technical Principles and Innovative Values:
- Innovation Point 1: Timing as a certified element, not a software variable. In a scanning safety PLC, a delay is a value in a function block whose behaviour depends on scan time, task priority and firmware revision. 52100 makes the delay a hardware property of a TÜV-assessed component. The interval is set in the circuit, verified at proof test, and traceable in the safety documentation — which removes an entire class of questions from an IEC 61511 assessment.
- Innovation Point 2: De-energize-to-trip as the failure philosophy. 52100 operates so that the safe state is the de-energized state. If the 24 VDC supply fails, if the card is withdrawn, or if an internal fault occurs, the timing function cannot hold the circuit in the running condition — the output goes to its safe state within the defined safety time. That is the opposite of a conventional industrial timer, where loss of supply simply stops the clock and can leave a process unprotected.
- Innovation Point 3: One function, deliberately. 52100 provides a single timing function. That is not a limitation; it is a safety strategy. A dedicated single-function card means one failure affects one delay, the fault is unambiguous to diagnose, and the spare is simple to qualify. Planar4’s low-density philosophy spreads risk across cards rather than concentrating many functions in one module.
- Innovation Point 4: Redundancy by architecture, not by card. 52100 is SIL 3 as a single element and supports 1oo2 or 2oo3 arrangements where SIL 4 is required. The higher integrity comes from the complete redundant design — channel independence, separate wiring, the selected voting relationship — not from any special property of one timer. This is honest engineering: the certificate follows the architecture, and the card is a known, characterized building block inside it.
- Innovation Point 5: Transparency for maintenance and proof testing. A hardwired delay can be challenged directly: inject the input, start a stopwatch, and confirm the output changes when it should. Each timer channel and the final voting result are tested independently during the scheduled loop test. There is no software to load, no laptop to connect, and no question of whether the running configuration matches the validated one.











