29 Real-Time ISA-95: Determinism and Technology Mapping
29.1 Start With the Decision
A fast average link can still miss a control deadline when jitter spikes. Determinism, clock error, and deadline class decide which network belongs at each ISA-95 level.
29.2 Route Overview
This is part 2 of 3. Review Real-Time ISA-95: Timing Foundations for the preceding evidence.
29.3 Learning Objectives
- Distinguish hard, firm, and soft real-time deadlines.
- Map jitter, synchronization, and network technology to ISA-95 levels.
29.4 Chapter Roadmap
- Determinism vs. Throughput
- Hard vs Soft Real-Time Summary
- Checkpoint: Deadline Classes
- Jitter and Synchronization
- Jitter Impact Calculator
- Knowledge Check: Real-Time Requirements
- Answer
- Answer
- Answer
- Technology Mapping
- Technology Mapping Summary
- Checkpoint: Technology Placement
- ISA-95 Level Selector Tool
- Knowledge Check: Technology Mapping
- Answer
- Answer
29.5 Determinism vs. Throughput
With the level timing ladder in place, the next question is what kind of promise each deadline needs. Some deadlines are hard failures; others are quality-of-service targets.
Industrial systems distinguish between different real-time guarantees:
Look at Figure 29.1 for what changes when a deadline is a failure rather than a target.
The two timelines in Figure 29.1 carry the same task under different promises. On the upper track the intervals are even and a bound sits at the end of each one, because the guarantee is about the worst case rather than typical behaviour. On the lower track the intervals stretch and shrink around an average, and a late arrival is marked as acceptable. The panels underneath name the consequence. Miss the bounded deadline and the system has failed, so it must be sized for the slowest path through the code. Miss a soft target and the result is only degraded, so average load is enough to design for.
Hard real-time paths are engineered around bounded worst-case behavior; soft real-time paths are judged by usefulness under expected delay and jitter.
29.5.1 Hard Real-Time (Deterministic)
Definition: Must respond within guaranteed time; missing deadline is system failure.
Characteristics:
- Worst-case execution time (WCET) must be bounded
- Jitter must be minimal (<1μs for synchronized motion)
- Preemptive, priority-based scheduling
- Often requires specialized hardware
Examples:
- Safety systems (emergency stop)
- Motion control (coordinated axes)
- Process control (exothermic reactions)
Implementation approaches:
- Dedicated real-time networks (EtherCAT, PROFINET IRT)
- Real-time operating systems (VxWorks, QNX, RTAI)
- FPGA-based control
- Time-triggered architectures
29.5.2 Soft Real-Time
Definition: Should respond quickly but occasional delays acceptable; results in degraded performance, not failure.
Characteristics:
- Average response time matters more than worst-case
- Some deadline misses tolerable
- Standard operating systems acceptable
- Statistical quality of service
Examples:
- HMI updates
- Data logging
- Trend analysis
- Operator notifications
29.5.3 Best Effort
Definition: No timing guarantees; response when resources available.
Examples:
- Historical data analysis
- Business reporting
- Email notifications
- Non-critical analytics
Checkpoint: Deadline Classes
You now know: Begin with hard real-time means a missed deadline is a failure, which is why safety systems and coordinated motion need bounded worst-case execution time. Next consider soft real-time fits HMI updates, data logging, trend analysis, and operator notifications where delay degrades usefulness. Then test best-effort paths belong to historical analysis, business reporting, email notifications, and other work where completeness matters more than millisecond delivery.
29.6 Jitter and Synchronization
For coordinated motion and distributed control, jitter (timing variation) is often more critical than absolute latency:
Figure 29.2 shows why an average latency figure can hide a missed deadline.
The two axes in Figure 29.2 are aligned on purpose, and both streams average 20 ms. On the upper axis the five arrivals sit between 18 and 22 ms, so every one lands before the 30 ms deadline with margin to spare. On the lower axis the same average is built from arrivals at 8 ms and 32 ms, and the late one crosses the deadline. The panel on the right shows what that costs a machine: steady arrivals keep two axes in step, while variable arrivals push them out of position. The closing line is the definition to carry forward. Jitter is variation in arrival timing, not the mean and not packet loss.
Jitter requirements by application:
| Application | Cycle Time | Max Jitter | Nodes |
|---|---|---|---|
| Simple I/O | 10 ms | 1 ms | 10-100 |
| Process control | 100 ms | 10 ms | 100-1000 |
| Packaging machinery | 1 ms | 100μs | 10-50 |
| Printing press | 125μs | 1μs | 20-100 |
| Semiconductor handling | 62.5μs | 100ns | 10-30 |
- Simple I/O: 10 ms cycle time, 1 ms max jitter, 10-100 nodes
- Process control: 100 ms cycle time, 10 ms max jitter, 100-1000 nodes
- Packaging machinery: 1 ms cycle time, 100μs max jitter, 10-50 nodes
- Printing press: 125μs cycle time, 1μs max jitter, 20-100 nodes
- Semiconductor handling: 62.5μs cycle time, 100ns max jitter, 10-30 nodes
Synchronization mechanisms:
- IEEE 1588 (PTP): Precision Time Protocol for sub-microsecond sync
- Distributed clocks: EtherCAT’s hardware-based synchronization
- Time-triggered protocols: Deterministic message scheduling
- GPS timing: Absolute time reference for wide-area systems
The chapter now has two timing ideas on the table: response time and consistency. The jitter calculator isolates the second one so you can see why a smaller average delay is not enough for synchronized axes.
29.7 Jitter Impact Calculator
Try it: Adjust the actual jitter value to see how different applications tolerate timing variation. Notice that printing presses and semiconductor handling require sub-microsecond precision, while simple I/O can tolerate milliseconds of jitter.
Question 1: A printing press requires a cycle time of 125 microseconds with maximum jitter of 1 microsecond. Which type of real-time guarantee does this require?
a) Best effort b) Soft real-time c) Hard real-time d) Near real-time
c) Hard real-time — A printing press with a 125 microsecond cycle time and 1 microsecond maximum jitter tolerance is a classic hard real-time application. Missing a deadline would cause visible print defects (color misregistration, smearing). Hard real-time requires guaranteed worst-case execution time (WCET) and minimal jitter, typically implemented with specialized hardware like EtherCAT with distributed clocks.
Question 2: At which ISA-95 level would you place a SCADA system that displays alarm conditions to plant operators?
a) Level 0 — Field Devices b) Level 1 — Basic Control c) Level 2 — Supervisory d) Level 3 — Operations
c) Level 2 — Supervisory — SCADA (Supervisory Control and Data Acquisition) systems operate at ISA-95 Level 2, which handles monitoring and supervision of production processes. Level 2 includes HMI displays, alarm management, historical data logging, and recipe management. The timing requirement is soft real-time (100 ms-1s), which is appropriate for human-operator interfaces.
Question 3: Why is jitter often more critical than absolute latency for synchronized motion control?
a) Jitter is easier to measure than latency b) Coordinated axes need to arrive at positions at exactly the same time, so timing consistency matters more than speed c) Jitter only affects wireless networks d) Lower jitter always means lower latency
b) Coordinated axes need to arrive at positions at exactly the same time, so timing consistency matters more than speed — In a multi-axis robot, all servo motors must receive their position commands at precisely the same instant. If one axis is consistently 5 ms late but all axes have the same 5 ms delay, the motion is perfectly coordinated. But if one axis varies randomly between 1 ms and 9 ms (high jitter), the axes become unsynchronized, causing mechanical stress, poor surface finish, or collisions.
29.8 Technology Mapping
The following diagram shows how protocols, platforms, and network architectures align with ISA-95 levels:
Read Figure 29.3 to see how the timing promise tightens as you move down the stack.
Start at the bottom of Figure 29.3, where sensors and actuators meet controllers. That interface is measured in microseconds and labelled hard real-time, so the protocol choice there is not a preference. Climb one step and the budget opens to a few milliseconds with a soft real-time promise. Two steps higher, supervisory and operations traffic runs in tens to hundreds of milliseconds on best effort, and the enterprise link at the top is slower still. The pattern is the argument: each level buys reach by giving up timing. The notes add the working rule. Measure the response end to end, and keep control that must not slip at the level that owns it.
Technology choices should follow the level’s deadline, authority, and failure consequence rather than a single preferred protocol.
29.8.1 Protocol Selection by Level
| Level | Typical Protocols | Latency | Determinism |
|---|---|---|---|
| 0-1 | EtherCAT, PROFINET IRT | <100μs | Hard real-time |
| 1-2 | PROFINET, EtherNet/IP | 1-10 ms | Soft real-time |
| 2-3 | OPC-UA, Modbus TCP | 10-100 ms | Best effort |
| 3-4 | REST APIs, MQTT | 100 ms-1s | Best effort |
- Level 0-1: EtherCAT or PROFINET IRT, <100μs latency, hard real-time
- Level 1-2: PROFINET or EtherNet/IP, 1-10 ms latency, soft real-time
- Level 2-3: OPC-UA or Modbus TCP, 10-100 ms latency, best effort
- Level 3-4: REST APIs or MQTT, 100 ms-1s latency, best effort
29.8.2 Computing Platform by Level
| Level | Platform | OS | Processing |
|---|---|---|---|
| 0-1 | PLC, PAC, IPC | RTOS, bare metal | Deterministic scan cycle |
| 2 | Industrial PC | Windows, Linux | Standard scheduling |
| 3 | Server | Windows Server, Linux | Virtualization OK |
| 4 | Cloud/Enterprise | Any | Containerization, serverless |
- Level 0-1: PLC, PAC, or IPC running RTOS or bare metal for deterministic scan cycles
- Level 2: Industrial PC running Windows or Linux for standard supervisory scheduling
- Level 3: Server hardware running Windows Server or Linux with virtualization
- Level 4: Cloud or enterprise platforms using containerized or serverless workloads
29.8.3 Network Architecture by Level
| Level | Network | Redundancy | Segmentation |
|---|---|---|---|
| 0-1 | Dedicated industrial | Ring, dual-port | Air-gapped from IT |
| 2 | Industrial Ethernet | RSTP, PRP/HSR | VLAN separated |
| 3 | Converged IT/OT | Standard HA | DMZ between zones |
| 4 | Corporate/cloud | Internet standards | Firewall protected |
- Level 0-1: Dedicated industrial networks with ring or dual-port redundancy and air gaps from IT
- Level 2: Industrial Ethernet with RSTP or PRP/HSR and VLAN separation
- Level 3: Converged IT/OT networks with standard high availability and DMZ zoning
- Level 4: Corporate or cloud networks using internet standards and firewall protection
Checkpoint: Technology Placement
You now know: Begin with level 0-1 control can need EtherCAT or PROFINET IRT below 100μs, while Level 1-2 traffic can often use PROFINET or EtherNet/IP in the 1-10 ms range. Next consider oPC-UA fits the Level 2-3 boundary because MES and historian consumers need semantic context, not drive-cycle ownership. Then test rEST APIs and MQTT belong at Level 3-4 integration when the path is planning, analytics, or dashboards rather than machine control.
29.9 ISA-95 Level Selector Tool
Try it: Adjust the response time requirement and safety criticality to see how the recommended ISA-95 level changes. The tool applies the decision framework to match your requirements to the appropriate automation level.
Question 4: An engineer needs to connect 100 PLCs to a Manufacturing Execution System (MES) for production scheduling. Which protocol and ISA-95 level boundary does this cross?
a) EtherCAT at Level 0-1 boundary b) OPC-UA at Level 2-3 boundary c) PROFINET IRT at Level 1-2 boundary d) MQTT at Level 3-4 boundary
b) OPC-UA at Level 2-3 boundary — Connecting PLCs (Level 1-2) to an MES (Level 3) crosses the Level 2-3 boundary, which is exactly where OPC-UA excels. OPC-UA provides the semantic data modeling needed for MES integration (production orders, quality data, genealogy), built-in security for the IT/OT boundary, and platform-independent communication.
Question 5: A factory floor network uses air-gapped segmentation. Which ISA-95 level does this practice primarily protect?
a) Level 4 — Enterprise systems need air gaps from the internet b) Level 0-1 — Critical control networks must be physically isolated from IT networks c) Level 3 — MES systems require air gaps from SCADA d) All levels equally use air-gapped segmentation
b) Level 0-1 — Critical control networks must be physically isolated from IT networks — Air-gapped segmentation is primarily used at Level 0-1, where dedicated industrial networks (EtherCAT, PROFINET IRT) carry safety-critical and hard real-time control traffic. These networks must be physically isolated from IT networks to prevent cyberattacks from reaching PLCs, safety controllers, and field devices. A compromised Level 0-1 network could cause physical damage, equipment destruction, or endanger human life.
29.10 Continue to the Next Part
Carry this evidence into Real-Time ISA-95: System Design and Practice, which begins with Assembly Line Design Case.
