Description

Application Scenarios:
A refinery ESD system is only as trustworthy as its ability to fail safely. The logic solver can be perfectly programmed, but if the application loop hangs, the 5 V DC rail drifts out of tolerance, or a memory error appears in the CPU, the processor can no longer be trusted to decide anything — and a safety controller that freezes while its outputs stay energized is the one failure mode no operator can accept.
That is the gap the 10005/0/3 is built to close. It supervises the controller’s execution independently of the application program: maximum loop time to catch a hang-up, minimum loop time to catch skipped program parts, 5 V DC supply monitoring, and memory-error logic from the CPU, COM and MEM modules. When the supervised parameters leave their window, the watchdog output is de-energized and the plant is driven to its defined safe state by hardware, not by software that may already be compromised.
The second scenario is distributed I/O. In an FSC architecture the central part talks to I/O racks over a vertical bus and horizontal bus structure, and the watchdog signal has to reach every output module for the fail-safe behaviour to be complete. The 10005/0/3 handles watchdog monitoring and horizontal bus distribution in one card, which removes a separate interface layer, reduces internal wiring, and gives maintenance crews a single, identifiable point where the safety-supervision path can be verified. Its “no ESD key switch” configuration suits installations where emergency shutdown is initiated elsewhere — a hard-wired plant ESD input, a remote shutdown panel, or a Safety Manager layer — rather than by a local key on the controller rack.
Parameter:
| Main Parameters | Value/Description |
|---|---|
| Product Model | 10005/0/3 (watchdog family; “0” variant without ESD key switch) |
| Manufacturer | Honeywell — FSC / Safety Manager safety platform |
| Product Category | Watchdog + horizontal bus module (FSC Central Part rack card) |
| Core Function | Processor-health supervision with integrated horizontal bus distribution; no local ESD key switch |
| Supervision Scope | Application loop max/min execution time, 5 V DC over/undervoltage, CPU/COM/MEM memory errors, ESD inputs |
| Voting Architecture | 2-out-of-3 watchdog voting — three sections, action only on agreement |
| Supply Requirement | 5 V DC via FSC rack backplane, approx. 175 mA excluding WDGOUT load; ripple < 50 mV p-p |
| Watchdog Output | WDGOUT 5 V DC, max 900 mA, protected by a 1 A fuse; 10302/1/1 repeater required above this load |
| Signal Inputs | ESD1 24 V DC / 5 mA (galvanically isolated), ESD2 5 V DC / 10 mA, reset input 24 V DC / 10 mA |
| Supply Monitoring | 5 V DC ±5% window for overvoltage and undervoltage detection |
| Form Factor | Standard FSC module format — 4 TE, 3 HE (4 HP, 3U); approx. 20 × 13 × 2 cm, 0.14–0.3 kg |
| Environmental Rating | 0 °C to +60 °C operating; −40 °C to +85 °C storage; 5–95% RH non-condensing |
| Approvals | CE, TÜV, UL; applied within SIL 3 (IEC 61508) certified FSC architectures |
| Service Rule | Not hot-swappable — 5 V DC on the central-part backplane must be switched off before insertion or removal |
| Variant Note | 10005/0/3 = no ESD key switch; 10005/0/2 = with ESD key switch; 10005/1/1 = standalone watchdog |
Technical Principles and Innovative Values:
Innovation Point 1: Supervision that does not depend on the thing it supervises.
The 10005/0/3 implements watchdog supervision in hardware, independent of application-program execution. The logic solver cannot “vote itself healthy,” because the watchdog decision is formed from timing, supply and memory-fault evidence gathered outside the program flow. This is the architectural property that makes fail-safe behaviour credible to a TÜV assessor rather than merely claimed.
Innovation Point 2: Both directions of loop-time monitoring.
Most watchdogs only catch a program that stops. The 10005/0/3 supervision concept checks maximum execution time (hang-up detection) and minimum execution time (skipped-program detection), so a controller that jumps over part of its safety logic is caught just as reliably as one that freezes.
Innovation Point 3: 2-out-of-3 voting inside the watchdog itself.
The watchdog is a 2-out-of-3 system in its own right. Three independent sections evaluate the same parameters and action is taken only on agreement, which suppresses spurious shutdowns from a single monitoring-channel fault while preserving genuine fail-safe response — availability and safety balanced in the same circuit.
Innovation Point 4: Watchdog and bus distribution merged into one card.
By combining watchdog supervision with horizontal bus distribution, the 10005/0/3 removes a discrete interface stage between the central part and the I/O layer. Fewer cards, fewer internal connections and fewer connectors means fewer latent failure points in exactly the part of the system that is hardest to test during a short turnaround.
Innovation Point 5: A hardware ESD path that bypasses the processor entirely.
The galvanically isolated 24 V DC ESD input can de-energize the watchdog output independently of the processor. Even in the worst credible software failure, a plant-level shutdown demand still reaches the outputs through a path that never asks the CPU for permission.
Innovation Point 6: Deliberate variant discipline instead of one-size-fits-all.
Honeywell splits the watchdog family by function: 10005/0/3 without a key switch, 10005/0/2 with one, 10005/1/1 as standalone watchdog. That is not marketing fragmentation — it lets a site match the hardware to its real shutdown philosophy, and avoid carrying a local key-switch capability that its safety case does not authorise.





