The FSoE slave stack (FSoE SubInstance) implements the Fail-Safe over EtherCAT safety protocol on the device side of a safety network. It responds to an FSoE master (MainInstance) and exchanges safe inputs and outputs with the integrity required for functional safety, on top of a standard EtherCAT connection.
What the FSoE slave stack does
As an FSoE SubInstance, the FSoE slave stack terminates the safety connection at your device: it validates every safety frame, manages the FSoE state machine (Reset, Session, Connection, Parameter, Data), and delivers safe process data to your application through a clean, documented API. Watchdog, sequence-number and connection monitoring detect any loss, delay, repetition, insertion or corruption of safety data and drive the device to a safe state.
Black channel and safety integrity
Built on the black-channel principle of IEC 61784-3, the FSoE slave stack treats the underlying EtherCAT transport as untrusted. It adds its own CRC, unique connection IDs, timing supervision and cyclic redundancy so that the transport does not need to be certified. This is what lets a single safe protocol run over standard EtherCAT hardware while reaching SIL3 / PLe integrity, independently assessed by an independent certification body.
Portable, hardware-independent design
The FSoE slave runs on virtually any MCU, any RTOS or bare metal, with no third-party dependencies and no vendor lock-in. It is adaptable to Beckhoff EtherCAT slave (SSC) stacks.
Applications
The FSoE slave stack suits safe I/O modules, safety sensors, safe drives and actuators, and any EtherCAT SubInstance that must exchange safe inputs and outputs. It is used across machinery, robotics, factory automation, intralogistics and process industries governed by IEC 61508 and ISO 13849, wherever a device has to carry safety data over EtherCAT.
Standards and conformance
The FSoE slave stack is built to IEC 61784-3 and assessed to SIL3 / PLe under IEC 61508 and ISO 13849.