Crane Safety Monitoring System: SIL3 Dual-Channel & Data Black Box
The crane safety monitoring system is built on a SIL3 dual-channel safety PLC architecture (Siemens S7-1500F + S7-1200F), covering all nine mandatory monitoring functions specified in Table 1, Clause 5.1 of GB/T 28264-2017 Safety Monitoring and Management System for Lifting Appliances — including load limiting, hoisting height limiter, travel limit switch, door limit switch, emergency stop, overspeed protection, differential speed protection, wind/anti-skid protection, and interlock protection. The system comes standard with a tamper-proof encrypted data recorder (30-day loop recording plus 100 event logs). Safety response time is under 100 ms, with dual-channel diagnostic coverage of ≥99%.
A crane safety monitoring system is the last line of defense for both equipment and personnel. GB/T 28264-2017 Safety Monitoring and Management System for Lifting Appliances and TSG Q7014-2016 define the nine mandatory monitoring functions and system architecture requirements. This article provides a full engineering breakdown of the crane safety monitoring system — from SIL3 dual-channel safety PLC design and technical implementation of the nine monitoring functions, to data recorder hardware selection, data security design, remote supervision platform capabilities, system performance indicators, and certification requirements.
SIL3 Dual-Channel Safety PLC Architecture
The safety PLC is the core of any safety monitoring system. Kelude Heavy Industry uses a dual-channel redundant architecture built on Siemens S7-1500F (Channel A) and S7-1200F (Channel B): Channel A handles seven of the nine monitoring functions (load, hoisting height, travel, door limit, emergency stop, overspeed protection, and interlock protection), while Channel B handles the remaining two (differential speed protection and wind/anti-skid protection) and serves as backup for Channel A — if Channel A's self-diagnostics detect a fault, Channel B automatically takes over all seven functions. The two channels run on independent CPUs, independent I/O modules, and independent power supplies, exchanging diagnostic status exclusively via Profisafe communication.
The cross-diagnostic cycle between channels is ≤10 ms — within each cycle, both channels exchange safety telegrams (F-Communication via Profisafe) to confirm that each other's CPU, I/O, power supply, and communication link are functioning normally. If a telegram is not received within one cycle, the channel is declared faulty and a safe shutdown is triggered. The dual-channel architecture achieves a PFHd (probability of dangerous failure per hour) of ≤10⁻⁸, meeting SIL3 requirements (IEC 61508-2010 Part 2 Table 2 / EN 62061-2021 Table 6). Kelude Heavy Industry's safety control system holds a SIL3 functional safety certificate issued by TÜV Süd (Certificate No.: Z10 23 04 03847 001). Compared to a single-channel PLC (SIL2, PFHd ≤10⁻⁷), the probability of dangerous failure is reduced by 90%.
What it takes to achieve SIL3: Under IEC 61508/EN 62061, SIL3 requires a PFHd (probability of dangerous failure per hour) of ≤10⁻⁸ — meaning the probability of a safety function failing dangerously is less than one in one hundred million per hour. A single-channel PLC typically has a PFHd in the range of 10⁻⁷ to 10⁻⁶, which falls short of SIL3. In a dual-channel redundant architecture, the probability of both channels failing simultaneously is the square of the single-channel probability (PFHd ≈ 10⁻¹²), but due to common-cause failure (CCF), the actual PFHd is approximately 10⁻⁸. Per the CCF scoring table in IEC 61508-6-2010 Appendix D, CCF mitigation measures (100 points total, ≥65 required) include: using CPUs from different production batches for the two channels, independent power supply circuits, independent I/O modules with wiring spacing of ≥50 mm, and conformal coating on PCBs for moisture and dust protection.
Engineering criteria for safety PLC selection: Kelude Heavy Industry chose the Siemens F-series (S7-1200F/1500F) for the following reasons — ①Profisafe safety communication protocol integrates seamlessly with Profinet, eliminating the need for a separate safety bus; ②TIA Portal provides a unified programming environment for both standard and safety PLCs, improving commissioning efficiency; ③F-I/O modules support 1oo1 and 1oo2 mixed configurations, balancing cost and safety; ④With over 80% market share in China, spare parts are readily available. How the Profisafe black channel works: the safety PLC does not rely on the underlying Profinet security — every F-telegram contains a 24-bit CRC, a 32-bit timestamp, and an 8-bit sequence number, so even if the underlying network is compromised, data tampering is still detected.
Safety response time chain breakdown per GB/T 28264-2017 Clause 5.1.3 and TSG Q7014-2016 Clause 4.2: The complete loop from sensor to safety PLC to actuator must complete within ≤100 ms. Measured breakdown: safety sensors ≤10 ms or ≤50 ms (analog), safety PLC scan cycle ≤10 ms, Profisafe delay ≤5 ms (1 ms in IRT mode), safety relay ≤20 ms (SICK UE43), contactor/brake ≤30 ms. At a crane speed of 1 m/s, 100 ms corresponds to a stopping distance of ≤100 mm — well within the 1.5 m safety clearance margin.
Nine Mandatory Monitoring Functions: Technical Implementation
GB/T 28264-2017 Safety Monitoring and Management System for Lifting Appliances specifies the sensor selection, trip thresholds, and commissioning procedures for the nine mandatory monitoring functions. Each function follows a three-tier architecture of "sensor + dual-channel safety PLC + actuator": sensors acquire physical signals, the dual-channel safety PLC cross-verifies signal integrity, and the actuator executes the safety action. The table below covers sensor selection, actuating elements, safety trip thresholds, and on-site commissioning points for each function — an essential technical reference for TSG Q7014-2016 inspection.
| Monitoring Item | Sensor Selection | Actuator | Safety Action | Commissioning Points |
|---|---|---|---|---|
| Lifting Capacity Limiter / Load Limiter | Pin-type/Column Load Cell | Safety Relay Cut-off Hoisting / Lifting | 110%Alarm125%Cut-off | Calibration Test Weight Verification±1% |
| Hoisting Height Limiter | Latch-type/Photoelectric | Contactor Cut-off Hoisting / Lifting Main Circuit | Upper Limit Distance≥200mm Safety Action | No-load Height Test, Margin Reserve |
| Travel Limit Switch | Proximity Switch / Inductive Sensor/Machinery Pin-type | Frequency Inverter / VFDDeceleration Stop | Distance Buffer stop≥500mm Safety Action | Deceleration/Two-stage Stop Setting |
| Door Limit Switch Interlock | Reed Switch/Travel Switch / Proximity Switch | Safety Relay Run Prohibit | Run Prohibit with Door Open | Check Magnet Alignment |
| Emergency stop | Push-button Type(Red Mushroom Head) | Hardwired Direct Connection Contactor Coil | Immediate Main Power Cut-off on Press | Twist-to-Release, Manual Reset Only |
| Overspeed Protection | Encoder Speed Measurement | PLCSafety Relay Cut-off | ≥Rated Start Button120%Safety Action | No-load Full Speed Testing Threshold |
| Speed Difference Protection | Dual Encoder Comparison | PLCCut-off after Logic Judgment | Two Encoder Difference Value≥5%Alarm | motor shaft+One at Each Wheel End |
| Anti-wind Anti-slip | Anemometer+Rail clamp | Rail clamp Automatic Clamping+Cut-off | Wind Speed≥6Level(13.8m/s) | Outdoor Gantry Crane/Tower Crane Mandatory |
| Interlock Protection | PLCInter-communication+Li DAR | Multi-crane Interlock System | Spacing≤Safety Threshold Shutdown | Multiple Unitsoverhead crane Enable in Collaborative Mode |
Data Recorder Hardware Selection and Technical Specifications
The crane data recorder is a mandatory device under Clause 5.4 of GB/T 28264-2017, functioning like an aircraft black box—it continuously logs crane operating data and safety events in a tamper-proof manner. Kelude's data recorder is built on an industrial-grade ARM Cortex-M4 processor (STM32F407, 168MHz clock speed), with data stored on an industrial SD card (SLC NAND, rated for ≥100,000 program/erase cycles). It features power-loss protection (supercapacitor backup sustains power for ≥30 seconds to complete the final data write). Storage capacity is 64GB, holding over 30 days of continuous operating data (covering 128 data points including lifting capacity, lifting height, travel position, travel speed, motor currents, mechanism status, and safety device states, logged once per second).
Event-triggered recording: when any of the nine safety monitoring functions is activated (overload at 110%, height limit, travel limit switch, etc.), the recorder automatically captures high-speed data from 30 seconds before to 30 seconds after the trigger event (sampling rate increases to 100Hz). It stores up to 100 independent event records, each with full contextual data. Data export options: ①USB direct export (requires administrator UKey verification); ②remote platform network export (requires mutual TLS authentication plus administrator credentials); ③physical SD card extraction (requires breaking the tamper seal and using a dedicated card reader). Data files are in encrypted binary format (.kdr), readable only by Kelude's proprietary analysis software, with exported reports automatically converted to both PDF and CSV formats.
Data security design reference standards: GB/T 22239-2019 "Information Security Technology—Baseline for Cybersecurity Classified Protection" (Level 3), GB/T 25069-2022 "Information Security Technology—Terminology," and GB/T 32918.4-2016 "SM2 Elliptic Curve Public Key Cryptography Algorithm." Data signatures use the SM2 national cryptographic algorithm (256-bit key length); data is admissible as legal evidence only after SM2 signature verification passes.
Remote Supervision Platform Architecture and Communication Options Compared
The remote supervision platform serves as the data aggregation and management hub for the crane safety monitoring system, uploading data from on-site safety PLCs and data recorders to a cloud server or on-premises server via MQTT or OPC UA protocols. Core platform features include: real-time monitoring dashboard (crane position, operating status, alarms, and safety device states displayed on instrument panels and 3D maps), alarm notifications (overload, limit switch, overspeed, and the other six monitoring triggers push alerts via SMS/APP/email with a response time of ≤30 seconds), data analytics and reporting (daily/weekly/monthly operating reports with charts, automatically emailed to administrators), and video integration (safety alarms automatically link to the corresponding crane's AI camera feed, replaying footage from 30 seconds before and after the event).
The choice of remote communication method directly impacts data real-time performance and security. Below is an engineering comparison of four remote communication options:
| Comparison Parameter | 4G/5GPublic Network | Factory LAN | Industrial Wireless(Wi Fi6) | Fiber Optic Dedicated Line |
|---|---|---|---|---|
| Transmission Protocol | MQTT over TLS | OPC UA/TCP | MQTT/Profinet | OPC UA/Gig E |
| Typical Latency | 50~200ms(4G) | 1~10ms | 5~30ms(Wi Fi6) | 0.1~1ms |
| Security | Medium(TLS+Certification) | High(Physical Isolation) | Medium(WPA3Encryption) | Highest(Physical Isolation) |
| Monthly Data Fee | 30~80CNY/Multi-crane | 0(In-plant Network) | 0(In-plant Network) | 500~2000CNY/Month |
| Equipment Cost | 1500~3000CNY | 500~1000CNY | 2000~5000CNY | 3000~8000CNY |
| Coverage Distance | Unlimited(Base Station Coverage) | ≤100m(Ethernet Cable) | ≤100m/AP | ≤10km(Single-mode) |
| Kruud Recommended | Multi-plant Remote Monitoring | Single-plant Standard | Mobileoverhead crane/Retrofit Item | Large-scale Plant/Core Data |
Kelude Heavy Industry: Typical Delivery Case Study
A project to retrofit 16 overhead cranes with safety monitoring systems in the continuous casting bay of a steel mill stands as a benchmark deployment for Kelude Heavy Industry. A site survey conducted in June 2025 revealed that 6 of the cranes were equipped with S7-300 PLCs requiring an upgrade to S7-1200F, while the remaining 10 units with S7-1200 PLCs could be directly fitted with F-I/O modules. The retrofit plan involved replacing the PLCs on 6 cranes, installing sensors across all units, upgrading control cabinets, adding data black boxes, and setting up a remote monitoring platform. The cost per crane was approximately $5,200, bringing the total for all 16 units to roughly $82,800. A total of 128 sensors were installed, comprising 16 lifting capacity limiters, 16 height limit switches, 32 pairs of travel limit switches, 32 door limit switches, 16 overspeed encoders, 8 anemometers, and 32 emergency stop buttons, with a combined cabling length of approximately 4,800 meters (15,750 feet).
The safety PLC programming involved approximately 280,000 lines of FBD logic code, with Profisafe communication configured for 48 F-devices. On-site commissioning took 12 days, during which 117 safety function points were individually tested, achieving a first-pass rate of 94%. The 6 non-conforming points—3 loose wiring connections, 2 sensor calibration deviations, and 1 Profisafe message timeout—were all rectified and re-inspected within 3 days. The Henan Provincial Special Equipment Inspection Institute (Report No. 2025-SP-0384~0399) conducted a 3-day on-site inspection covering static load, dynamic load, and braking tests, all of which passed. All 27 sampled safety functions passed inspection, and the data black box records were found to be fully consistent with the on-site PLC logs. According to the steel mill's equipment department operational statistics from July 2025 to June 2026 (Report No. KL-2025-SAFETY-001~012), unplanned downtime decreased by 75% after project commissioning, annual equipment failure losses dropped from approximately $118,300 to $29,600, and the payback period for the safety monitoring system investment was approximately 11 months.
Construction safety management: The entire construction period spanned 42 days (excluding a 7-day wait for TSG inspection scheduling), with 12 construction personnel working continuously in strict compliance with the Safety Specification for Lifting Appliance Retrofit Construction. Work at height (main girder/end carriage sensor installation) was protected by a three-tier system comprising safety belts, safety ropes, and safety nets. Electrical work followed a four-step procedure: power isolation, voltage verification, lockout/tagout, and grounding. Zero safety incidents occurred during construction, and the post-retrofit customer satisfaction survey scored 9.2/10 from the client's on-site operators. Kelude Heavy Industry provides full life-cycle support for the safety monitoring system, including quarterly remote inspections, annual on-site testing, sensor replacement reminders 3 months before expiration, and free lifetime software upgrades.
Frequently Asked Questions
Q: What is the fundamental difference between a SIL3 crane safety monitoring system and a standard PLC control system?
A: The fundamental difference between a SIL3 safety system and a standard PLC control system lies in the fail-safe design. When a standard PLC fails, its outputs may remain in any state (random failure), whereas a safety PLC must return its outputs to a predefined safe state (such as cutting power or applying the brake) upon failure. The specific differences are: ① The safety PLC's CPU, I/O modules, and power supply are all designed with dual-channel or redundant architecture, ensuring that a single point of failure cannot compromise safety functions; ② Both the hardware and software of the safety PLC carry TÜV certification (SIL3 rating), with certification covering the entire chain of safety integrity from chip level to application logic; ③ The safety PLC executes the F-Communication (Profisafe) safety protocol, where messages include sequence numbers, timestamps, and CRC checksums to prevent data tampering or replay attacks. The safety PLCs used in Kelude Heavy Industry's crane safety monitoring systems are Siemens F-series units that have passed TÜV Süd's SIL3 certification.
Q: How is encryption and tamper-proofing implemented in the data black box? Can it be used as evidence in legal disputes?
A: Kelude Heavy Industry's data black box employs a three-layer tamper-proof design: ① Hardware layer—data is stored on a dedicated secure SD card (with write-protect switch and physical locking), and the card slot is sealed with tamper-evident tape. Removing the SD card breaks the seal irreversibly; ② Data layer—each data record contains a timestamp, device ID, and HMAC-SHA256 signature, with the key stored in the safety PLC's tamper-resistant memory area (protected by TÜV certification). Modifying any single record causes signature verification to fail for all subsequent records; ③ Application layer—when exporting black box data, a data fingerprint (SHA256 hash) is generated, and the exported report is accompanied by a digital signature certificate issued by Kelude Heavy Industry's TSM (Timestamp Server). In a 2023 steel mill crane accident analysis, black box data was accepted by the court as valid electronic evidence. We recommend that customers export and archive black box data regularly (quarterly) to prevent data loss due to SD card aging or accidental damage.
Q: What is the response time of the safety monitoring system, and what does TSG inspection require?
A: TSG Q7014-2016 (Rules for Supervision Inspection of Lifting Appliances Installation, Retrofit and Repair) does not specify a numerical response time requirement, but it does require that "after a safety device is activated, the relevant mechanism shall stop operation within a specified time." The typical response time for Kelude Heavy Industry's safety monitoring system is ≤100ms for the complete cycle from sensor signal acquisition through safety PLC logic processing to actuator operation. The breakdown is as follows: sensor delay ≤10ms (discrete signals) or ≤50ms (analog/communication signals), safety PLC scan cycle ≤10ms, Profisafe communication message delay ≤5ms, safety relay actuation time ≤20ms, and contactor/brake actuation time ≤30ms. During inspection, the response time of each safety device is measured to ensure that all mechanisms stop promptly after safety device activation. We recommend that customers measure response times during acceptance testing using an oscilloscope or PLC online monitoring, and record the data in the Acceptance Report.
Q: What procedures are required to retrofit an aging overhead crane with a safety monitoring system?
A: Retrofitting an aging overhead crane with a safety monitoring system constitutes a major modification (changing the safety protection system) and requires modification notification and supervision inspection in accordance with TSG Q7016-2016. The process is as follows: ① Commission a qualified construction unit (Kelude Heavy Industry holds Class A lifting appliance installation, retrofit, and repair qualification) to prepare the retrofit plan; ② The construction unit files a modification notification with the local market supervision authority (submitting qualification certificates and the retrofit plan); ③ Perform the retrofit construction (installing sensors, safety PLC, black box, and remote platform); ④ After completion, engage an inspection body for supervision inspection (including document review, physical inspection, functional testing, and load testing); ⑤ Obtain the retrofit supervision inspection certificate upon passing; ⑥ The user unit updates the registration information within 30 days. The entire process takes approximately 30–60 days. Note: Installing a safety monitoring system does not change the registered information (lifting capacity, span, etc.), so a full machine type test is not required. Kelude Heavy Industry offers full-service agency support throughout the process.