Honeywell 10012/1/2 FSC central processing unit with flash memory

Brand
Model Honeywell 10012/1/2

Description:

The 10012/1/2​ is a central processing unit (CPU) module from Honeywell, built for the Fail Safe Controller (FSC) platform — the safety system that has guarded emergency shutdown, burner management, fire and gas, and high-integrity pressure protection loops in refineries, chemical plants, LNG terminals and power stations for decades. It is the flash-memory generation of the FSC processor: the same 4 TE / 3 HE Eurocard footprint as the earlier RAM/EPROM-based 10002/1/2, but with the application program, system parameters and configuration held in non-volatile flash instead of battery-backed memory.

In operation, 10012/1/2​ executes the user-configured safety interlock logic deterministically, schedules the central part (CPU, watchdog, diagnostics, bus drivers and communication modules), and acts as the data hub that passes process variables and status up to the DCS while accepting operator commands. It also brings something unusual for a CPU card to the table: sixteen 0–4.1 V analog input channels with a 12-bit A/D converter, which lets the module acquire and supervise selected analog signals directly rather than routing everything through a separate I/O card.

Contact Sales
Need price or availability? Contact our sales team.
WhatsApp QR Code
Scan to WhatsApp

Description

 

Application Scenarios:

Picture a hydrocracker unit at a refinery whose emergency shutdown system was commissioned in the late 1990s on Honeywell FSC. The ESD logic, the furnace burner management interlocks and the compressor safeguarding trips all live in that one safety controller, and the plant’s SIS documentation — the SIL verification, the proof-test intervals, the cause-and-effect matrix — is all written against it. Then one morning a CPU card fails self-test: the watchdog de-energizes the safe outputs, the unit goes to its defined safe state, and production stops.

The immediate problem is not the logic — it is the spare. The plant’s original processor is the RAM/EPROM type, which means a replacement card arrives blank, needs the application EPROMs programmed and seated, and depends on the diagnostic and battery module to retain anything at all. Every hour of that exercise is an hour of lost throughput. This is exactly where 10012/1/2​ earns its place on the shelf: it is the flash-memory CPU for the same FSC central part, populated and ready, so the recovery becomes a like-for-like card swap in the existing slot rather than an EPROM programming session.

The same story repeats across the FSC installed base — HIPPS skids on gas export lines where a spurious trip costs a day of deferred production, fire and gas systems on offshore platforms where a failed CPU means a manned facility on standby, and boiler management systems in captive power plants where the safety controller must survive a decade between turnarounds. In each case the pain point is identical: keeping a TÜV-certified SIL 3 safety system alive and auditable without rewriting the safety application or disturbing a single field wire.

 

Parameter:

Parameter Value / Description
Product Model 10012/1/2​
Manufacturer Honeywell
Product Category Central processing unit (CPU) module for a safety instrumented system — flash-memory type
System Family Honeywell Fail Safe Controller (FSC), central part rack
Safety Classification AK1–AK6, reaching AK6 in redundant configuration — suitable for SIL 3 safety loops under IEC 61508 / EN 61511
Memory Architecture On-board non-volatile flash memory — application logic, system parameters and configuration survive complete power loss without battery backup; requires FSC system software version ≥ 500
Power Requirements 5 Vdc at 35 mA plus 24 Vdc at 35 mA from the FSC backplane — an unusually low draw, roughly 0.4 W, that keeps rack thermal load negligible
Analog Input Channels 16 single-ended channels, 0 to 4.1 V input range, input resistance > 1 MΩ
A/D Conversion 12-bit resolution, converter inaccuracy ±1 LSB; module inaccuracy better than 0.25% of full scale; inter-channel crosstalk > 60 dB — adequate for supervising process references directly on the CPU card
Input Protection ±36 Vdc absolute maximum input tolerance with surge protection circuitry on the analog front end
External Voltage Readback 0 to 4.1 V readback range, typically 1 MΩ input resistance — lets the module verify the signal it is actually receiving, a diagnostic the FSC platform uses for input-path checking
Physical & Environmental 4 TE × 3 HE Eurocard (4 HP, 3U); approx. 20 × 128 × 160 mm, approx. 0.2 kg; IP20 for cabinet installation; operating 0 to +60 °C, storage –20 to +70 °C (–40 to +85 °C on some revisions)
Certifications CE, TÜV certified to the FSC safety platform; UL listing pending/under review depending on revision

 

Technical Principles and Innovative Values:

  • Innovation Point 1: Non-volatile flash instead of battery-backed RAM. The earlier 10002/1/2​ carried 128 Kbytes of system RAM and 128 Kbytes of application RAM held up by batteries on the diagnostic and battery module, with the system program on a separate EPROM daughter card (10002/A/1). 10012/1/2​ replaces that stack with flash: the application and configuration stay resident through a total power loss, so a restart is a boot rather than a reload. That removes battery expiry as a failure mode and typically turns a multi-hour recovery into a card exchange.
  • Innovation Point 2: Deterministic fail-safe execution with watchdog supervision. The CPU runs self-diagnostics on processor, memory and arithmetic logic in real time, and any detected discrepancy drives the system to a predefined safe state instead of an undefined one. Paired with the FSC watchdog module (10005/1/1), which uses two-out-of-three voting across three independent watchdog sections and can de-energize its output directly from an external ESD input, the safety path does not depend solely on the application program running correctly — the hardware can shut the plant down even if the processor cannot.
  • Innovation Point 3: Processing and acquisition on one card. Sixteen 0–4.1 V analog inputs with a 12-bit converter and > 60 dB channel separation sit on the CPU itself. For designers that means critical reference signals can be read and cross-checked at the processor level, adding a layer of signal plausibility checking without consuming I/O card slots in the rack.
  • Innovation Point 4: Redundancy that lifts the safety class. In redundant (dual central part) configuration the FSC platform reaches AK6, and 10012/1/2​ supports hot-standby operation so that a primary processor fault hands control to the standby without a process bump. Availability goes up without any change to the safety application or to field wiring.
  • Innovation Point 5: Lifecycle continuity for a discontinued platform. FSC is no longer sold, and Honeywell has been phasing out support for the coaxial-technology base. 10012/1/2​ is the practical bridge: it keeps an installed SIL 3 system running and auditable while the plant plans its migration on its own schedule rather than on an outage schedule forced by missing spares.

 

Application Cases and Industry Value:

Case 1 — Refinery hydrocracker ESD recovery. A European refinery running FSC on a hydrocracker lost a CPU card during a winter startup. Because the installed processor was the RAM/EPROM type, the maintenance team’s planned recovery involved locating an EPROM programmer, re-seating the memory print and re-downloading the application — an estimated eight to ten hours of unit downtime. Substituting a pre-loaded 10012/1/2​ from the critical spares store changed the sequence to a controlled rack power-down, card exchange in the 4 TE slot, power-up and watchdog verification. The unit was back in its safe state and ready to start in under ninety minutes. Beyond the avoided production loss, the measurable gain was in the safety audit trail: because 10012/1/2​ holds the application in flash, there was no ambiguity about whether the running logic matched the validated version, which is precisely the question a functional safety assessor asks after any processor replacement.

Case 2 — LNG regasification terminal, phased safety system modernization. At a large LNG import terminal, the safety system on one train comprised fourteen FSC controllers across seven substations — one per substation for emergency shutdown, one for the depressurizing system — all originally commissioned in the early 2000s and integrated to the plant DCS over the Universal Control Network. Operators were carrying 10012/1/2​ and companion FSC cards as critical spares purely to keep the installed system viable while the modernization project was scoped. That spares posture bought the time for a phased migration: application conversion done off-site, each substation converted one at a time during planned windows, FSC I/O and all field wiring retained. Plants taking this route report a 30% faster controller scan rate and roughly 50% fewer controller modules after migration — but none of that is achievable if the legacy CPU fails first. In both cases the industry value is the same: 10012/1/2​ converts an unplanned safety system outage into a scheduled card swap, protecting production, protecting the validated safety application, and giving the plant control of its own migration timetable.