Problem Overview: S5 Timer BI/BCD Output Above 999 Seconds on S7-313C
When using the legacy S5 timer instructions (S_ODT, S_PULSE, S_PEXT, S_ODTS, S_OFFDT) on a Siemens SIMATIC S7-313C CPU, the binary (BI) and BCD outputs of the timer do not return the current elapsed time in seconds once the preset time exceeds 999 seconds. Instead, the value returned is scaled to the largest time base of the selected range, producing a 1/10 (or smaller) factor that confounds HMI display logic.
For example, when the operator preset is 24 m 20 s (1460 s) entered as S5TIME#24M20S on an S_ODT block, the BI output reads 146 rather than 1460. The same value appears in the BCD output when interpreted as BCD. If you scale the HMI tag by a factor of 10 to recover 1460, the display then decrements in 10-second steps instead of 1-second steps because the underlying integer only changes every 10 s.
This is not a bug; it is the documented behavior of the S5TIME data type. The BI and BCD outputs of S5 timers always reflect the time value divided by the time base embedded in the 16-bit S5TIME word, and the time base is selected automatically by the compiler based on the magnitude of the preset.
Root Cause: S5TIME Word Format and Time Base Resolution
The legacy S5TIME format occupies one 16-bit word with the structure shown below. Two time-base bits (12 and 13) encode the resolution, and the remaining 12 bits hold the BCD time value (0-999):
| Bit 15 | Bit 14 | Bit 13 | Bit 12 | Bits 11-0 |
|---|---|---|---|---|
| Reserved (0) | Reserved (0) | Time base code (2 bits) | BCD value (0-999) | |
The two time-base bits encode the resolution of the BCD value according to the following table:
| Time Base Bits (12,13) | Time Base | Range |
|---|---|---|
| 00 | 10 ms | 0.00 s - 9.99 s |
| 01 | 100 ms | 0.0 s - 99.9 s |
| 10 | 1 s | 0 s - 999 s |
| 11 | 10 s | 0 s - 9990 s |
For the S5TIME literal S5TIME#24M20S (1460 s), the compiler selects the 10 s time base (bits 12-13 = 11) and stores the BCD value 146 in the low 12 bits. The CPU evaluates the timer by multiplying the time base by the BCD value, so the internal representation is consistent. However, the BI output of S_ODT is the time value divided by the time base, not by 1 s. This means BI returns 146 (in 10 s units) for any preset in the 10 s base, including the full range 0 s to 9990 s.
The BCD output returns the same 146 in BCD form, which is why the INT conversion of the BCD output also yields 146. Neither output is suitable for an HMI that requires a 1-second-resolution countdown across the full 0-3600 s range.
Solution Architecture: Three Viable Approaches
Three approaches resolve the issue cleanly on a TIA Portal V12 SP1 / S7-313C / KTP600 Color DP station:
| Approach | CPU Block | HMI Logic | Pros | Cons |
|---|---|---|---|---|
| IEC timer + T_CONV + HMI linear scaling | TONR / TP / TON / TOF, T_CONV | Linear scale ms → s, format as decimal | Resolution independent of preset; supports 0-2^31 ms | Single conversion rung required |
| S5 timer with T_CONV to TIME then DINT | S_ODT, T_CONV (S5TIME → TIME), T_CONV (TIME → DINT) | Linear scale ms → s | Keeps S5 timer block, no extra instance DB | Two conversion steps; S5 timer is legacy |
| Manual decode of S5TIME word + HMI scaling | Direct MW read, bit masking, integer math | Already in seconds if base = 1 s | No CPU conversion work | Brittle; fails for multi-range presets |
Siemens recommends the IEC timer path in current documentation. IEC timers output a TIME value (32-bit DINT, milliseconds) regardless of preset magnitude, and a single T_CONV delivers an integer in milliseconds that the KTP600 Color DP can scale to seconds with its built-in linear scaling. The IEC timer family is documented in the Siemens Industry Online Support manual library under the SIMATIC S7-300 / S7-400 software documentation set.
Prerequisites and Engineering Environment
Confirm the following before changing the program:
- CPU: SIMATIC S7-313C (6ES7 313-5BF03-0AB0 or later), firmware V3.3 minimum. Earlier firmware revisions of the 313C do not support all TONR / TP blocks reliably; verify the exact order number and firmware against the Siemens product support entry for the 31xC series.
- HMI: KTP600 Basic mono PN/DP or KTP600 Basic color DP. The Color DP variant supports linear scaling on numeric tags via WinCC Comfort/Advanced V12 SP1 and later. Earlier HMI images restrict format strings and require the format to be entered as a string literal.
- Engineering: TIA Portal V12 SP1 (6AV2 103-...). Service Pack 1 is required for the TIME→DINT conversion in SCL on the 300-series CPUs; without SP1 the IEC timer blocks may not appear under "Instructions → Timers". Verify in Help → About TIA Portal that the build number is ≥ V12.0.0.1100 with the SP1 update installed.
- Support packages: Install the S7-300 CPU 31xC support package (Options → Support Packages) before dragging the TONR block into the project. The HMI support package for KTP600 Basic is also required and is usually installed by default with TIA Portal V12 SP1.
- Connection: PROFINET or PROFIBUS between the S7-313C and the KTP600 Color DP, configured in the Devices & Networks editor. The HMI must be assigned to the same subnet as the PLC; the S7-313C DP variant connects via PROFIBUS, the PN variant via PROFINET.
Step 1: Insert and Wire an IEC TONR Timer
The IEC timer family on the S7-300 (and S7-400) includes four blocks: TP (pulse), TON (on-delay), TOF (off-delay), and TONR (retentive on-delay). For an operator-preset countdown where power failure must not reset the elapsed time, use TONR. For a simple on-delay that the HMI displays and that should start from zero on each cycle, use TON.
- In the TIA Portal project tree, expand the S7-313C station and open the program block (OB1) for the cycle.
- Navigate to Instructions → Basic operations → Timers. Drag
TONorTONRinto the chosen network. If the folder is empty, install the S7-300 support package (Options → Support Packages). - Right-click the timer instance, choose "Change instance DB", and let the compiler generate a single-instance DB, e.g.
DB_Timer1. The instance DB is essential; the IEC timer requires a DB to hold the elapsed time, the start time, and the running flag. - Wire the inputs:
| Ton input | Source | Type | Description |
|---|---|---|---|
| IN |
%I0.0 (operator start) |
BOOL | Start the timer; on TON, falling edge stops and resets; on TONR, falling edge freezes (does not reset). |
| PT | HMI tag PresetTimeMs or constant T#24m20s
|
TIME | Preset time as TIME literal or HMI variable. |
| R (TONR only) |
%I0.1 (reset pushbutton) |
BOOL | Resets the elapsed accumulator. |
- Wire the outputs:
| Ton output | Destination | Type | Description |
|---|---|---|---|
| Q | %Q0.0 |
BOOL | TRUE while ET ≥ PT (timer expired). |
| ET | Tag "DB_Timer1".ET
|
TIME | Current elapsed time in milliseconds; this is the value you display. |
The ET output is the single source of truth. Because it is a TIME (DINT in ms) it carries no time-base ambiguity. Even if the operator sets the preset to 3600 s (T#1h), ET simply grows up to 3 600 000 ms without any scaling jump at 1000 s or 999 s.
Step 2: Convert TIME to DINT with T_CONV
WinCC on the KTP600 Color DP cannot directly read a TIME value; it expects INT, DINT, or REAL. Add a T_CONV block in the next network:
- From Instructions → Basic operations → Conversion, drag
T_CONV(also calledCONVERTin the help text) into a new network. - Set IN to
"DB_Timer1".ET. This is a TIME in milliseconds. - Set OUT to a tag in a global DB, e.g.
"DB_Display".ElapsedMsof typeDINT. T_CONV is signed; DINT holds the full 32-bit range, sufficient for any practical countdown (up to 24 d 20 h 31 m 23 s 647 ms).
The equivalent SCL source for the conversion network is:
// Network 2: convert TIME elapsed to DINT milliseconds
"DB_Display".ElapsedMs := DINT_TO_DINT("DB_Timer1".ET); // implicit T_CONV
Or using the explicit LAD/FBD T_CONV:
IN "DB_Timer1".ET ─┐
├─[ T_CONV ]─► "DB_Display".ElapsedMs (DINT)
OUT (auto) ─┘
The T_CONV block accepts a TIME source and any numeric target type on the S7-300 with firmware V3.3 or higher. The output equals the input time value expressed in milliseconds. If the firmware revision is below V3.3, use the indirect path: BTI (BCD to Integer) is not appropriate for TIME; instead route the conversion through the IEC standard function TIME_TO_DINT from the standard library, which is available in TIA Portal V12 SP1 without additional support packages.
Step 3: Configure the KTP600 HMI Tag and Linear Scaling
- In the HMI project (KTP600 Color DP), add a new tag, e.g.
ElapsedTime. Point its PLC tag to"DB_Display".ElapsedMs. The default type isDInt; leave it. - Open the tag properties and select "Linear scaling" (Properties → Value → Scaling). Configure the scaling as follows:
| Field | Value | Meaning |
|---|---|---|
| PLC value range start (raw) | 0 | 0 ms elapsed |
| PLC value range end (raw) | 3 600 000 | 3 600 000 ms = 1 h maximum |
| HMI value range start (scaled) | 0 | 0 s displayed |
| HMI value range end (scaled) | 3600 | 3600 s displayed |
- Set the I/O field format to
9999(no decimal point) for plain seconds, or999.9if you prefer tenths. For minutes-and-seconds display, compute a separate string tag on the PLC (see Step 4) and display it in a text field; the KTP600 Basic runtime does not support format strings likemm:ssdirectly on numeric tags. - Place an I/O field on the desired screen. Link its process value to
ElapsedTime. Set the "Output format" property to decimal. Disable the input mode if the value is read-only. - Set the HMI tag acquisition cycle to 500 ms (Connection → Tags → ElapsedTime → Acquisition cycle). A 1 s cycle is acceptable for plain second display but a 500 ms cycle produces a smoother visual countdown.
Because the linear scale is anchored at 0 → 0 and 3 600 000 → 3600, the I/O field now decrements exactly one unit per real second, regardless of the preset value, and there is no ambiguity at the 999 / 1000 boundary that caused the original S5 timer problem.
Step 4: Optional mm:ss String Display
For a minutes-and-seconds readout, add a string tag in the global DB and populate it from the SCL block that owns the timer:
// SCL in FB_TimerCtrl
"DB_Display".ElapsedSec := "DB_Display".ElapsedMs / 1000;
"DB_Display".Minutes := "DB_Display".ElapsedSec / 60;
"DB_Display".Seconds := "DB_Display".ElapsedSec MOD 60;
IF "DB_Display".Minutes < 10 THEN
"DB_Display".MinStr := '0' + INT_TO_STRING("DB_Display".Minutes);
ELSE
"DB_Display".MinStr := INT_TO_STRING("DB_Display".Minutes);
END_IF;
IF "DB_Display".Seconds < 10 THEN
"DB_Display".SecStr := '0' + INT_TO_STRING("DB_Display".Seconds);
ELSE
"DB_Display".SecStr := INT_TO_STRING("DB_Display".Seconds);
END_IF;
"DB_Display".MmSsString := "DB_Display".MinStr + ':' + "DB_Display".SecStr;
Link the HMI text field's process value to "DB_Display".MmSsString as a STRING tag. The KTP600 Basic runtime supports STRING display fields in the Tools → Text Field palette.
Alternative: S5 Timer with T_CONV Path
If the program must retain the existing S5 timer (for example, because it is in a library shared with other stations that still use S5 timers), the BI/BCD problem can be mitigated with two T_CONV calls:
- Keep the existing
S_ODTblock. The S5TIME input is the operator preset; do not change it. - Add a network that copies the S5TIME preset into a temporary
S5TIMEtag in a global DB, then convert it with T_CONV toTIME, and then with T_CONV toDINT:
S5TIME_to_TIME : "DB_Display".PresetTime := S5TIME_TO_TIME("DB_Timer1".S5TimeIn);
TIME_to_DINT_ms : "DB_Display".ElapsedMs := TIME_TO_DINT("DB_Display".PresetTime);
Note that this gives the preset in milliseconds, not the live remaining time. For the live remaining time with an S5 timer you must compute Preset − Elapsed, but the S5 timer does not expose the elapsed time in seconds either. The cleanest path forward is therefore to migrate the timer block to an IEC timer; S5 timers are documented as legacy and not recommended for new development.
"DB_Timer1".ET.Code Examples: STL, LAD, and SCL Equivalents
LAD / FBD representation
Network 1: Start condition and TONR instance
| %I0.0 "DB_Timer1".IN T#24m20s "DB_Timer1".PT |
|----|/|--------------------| TONR |--------------------| Q→%Q0.0 |
| %I0.1 "DB_Timer1".R ET→Tag |
|----| |--------------------| (reset) ----------------|
Network 2: T_CONV TIME → DINT
| "DB_Timer1".ET T_CONV "DB_Display".ElapsedMs (DINT) |
|----------------|------►|-----------------------------|
STL representation
// Network 1
A %I0.0
S "DB_Timer1".IN // for TONR, set the start latch
L S5TIME#24M20S
T "DB_Timer1".PT // not used with IEC; use TIME literal
// Network 2 - T_CONV
L "DB_Timer1".ET
T "DB_Display".ElapsedMs
SCL representation (preferred for S7-300 / 400 with TIA Portal V12 SP1)
// Block: FB_TimerCtrl
IF "StartButton" THEN
"DB_Timer1".IN := TRUE;
ELSE
"DB_Timer1".IN := FALSE;
END_IF;
"DB_Timer1".PT := T#24m20s; // operator-controlled in production
"DB_Timer1"(IN := "DB_Timer1".IN,
PT := "DB_Timer1".PT,
R := "ResetButton",
Q => "TimerQ",
ET => "ElapsedTime");
"DB_Display".ElapsedMs := DINT#0;
IF "ElapsedTime" >= 0 THEN
"DB_Display".ElapsedMs := DWORD_TO_DINT("ElapsedTime");
END_IF;
Verification and Commissioning Procedure
Walk through the following cases in online mode with the KTP600 Color DP attached. Each test must be performed with the CPU in RUN-P and the HMI in transfer mode.
- Preset
T#0s. ConfirmElapsedMson the watch table reads 0. Confirm the HMI field shows 0 s. - Preset
T#1s. Start the timer. Confirm the HMI field decrements 1 → 0 in exactly 1 s. - Preset
T#999s. Confirm the HMI field shows 999 and decrements 1 s per second through the entire range. This is the historical edge case where the S5 BI output was correct. - Preset
T#1000s(16 m 40 s). Confirm the HMI field shows 1000 and decrements 1 s per second. With the S5 timer this case was the first to show 100 / 1 s instead of 1000 / 1 s. - Preset
T#1460s(24 m 20 s). Confirm the HMI shows 1460 and decrements 1 s per second down to 0. - Preset
T#3600s(1 h). Confirm the HMI shows 3600 and decrements 1 s per second. - Trigger a power cycle during a
TONRcountdown. Confirm the elapsed time resumes at the last value, not at zero. The S5 timer would have lost the elapsed time on power-down. - Disconnect the HMI cable. Confirm the PLC program continues to run and the ET output remains correct; the HMI tag is read-only and does not affect the timer.
For each test, add a watch-table row in TIA Portal with the format "DB_Timer1".ET %MW100:ETIME to display the time value in human-readable form (e.g., T#00:24:20.000). Pair this with the raw DINT row "DB_Display".ElapsedMs DEC to confirm the integer matches the displayed seconds × 1000.
Troubleshooting Matrix
| Symptom | Probable Cause | Diagnostic Step | Corrective Action |
|---|---|---|---|
| HMI shows 146 for a 1460 s preset | Still using S5 timer BI output, no T_CONV | Inspect the program block; confirm TONR is in use | Replace S_ODT with TONR; add T_CONV network |
| HMI decrements in 10 s steps | HMI tag scaled by 10 because BI was 146 | Open HMI tag properties; check linear scaling end value | Change raw end to 3 600 000 and scaled end to 3600 |
| HMI shows 0 immediately on start | Instance DB not updated; ET = T#0ms | Monitor "DB_Timer1".ET in watch table |
Confirm IN is set; check that the TONR block is called in OB1 |
| HMI shows negative time near 0 | Linear scale anchored at non-zero start | Verify PLC value range start = 0 | Set both ranges to start at 0 |
| Timer not visible in TIA Portal instruction list | S7-300 support package not installed | Options → Support Packages → check S7-300 CPU 31xC | Install package, restart TIA Portal |
| T_CONV compiler error: "Type conversion not allowed" | TIA Portal pre-SP1; SP1 not installed | Help → About TIA Portal; check SP level | Update to TIA Portal V12 SP1 or later |
| HMI field shows ### | Display width insufficient or value out of range | Check the I/O field length property | Increase field length to 4 digits; check scaling end values |
| Time appears to lose seconds under HMI update | HMI acquisition cycle longer than 1 s | Connection properties → Update cycle | Set acquisition cycle to 500 ms for the ElapsedTime tag |
| CP 342-5 communication fault during PROFIBUS transfer | Bus address conflict between S7-313C and KTP600 DP | Online & Diagnostics → PROFIBUS nodes | Set unique PROFIBUS addresses; CPU typically 2, HMI typically 1 |
| Timer continues counting after PT reached | TONR used without a R signal after expiry | Monitor Q output on TONR | Add R logic in OB1 to clear IN at Q rising edge |
Process Visualization: Conversion and Scaling Flow
The following inline diagram illustrates the data path from the IEC timer through T_CONV to the KTP600 Color DP I/O field. It emphasizes that the time-base ambiguity of the S5 timer is eliminated the moment an IEC timer is selected, because ET is always expressed in milliseconds regardless of preset magnitude.
Field-Engineering Notes
- For very long countdowns (above 24 days 20 hours), the DINT range is still adequate because the IEC TIME value is 32-bit signed. The corresponding ms value remains below 2 147 483 647 ms (about 24.86 days). For countdowns beyond this, use a real-time clock block (SFC0 / SFC1) and compute the difference; the IEC TONR / TON path is not appropriate.
- If the operator preset is entered as BCD from a numeric input panel, convert with
BCD_TO_DINTbefore assigning to the PT input. Conversely, do not useS5TIMEas a parameter for an IEC timer; the PT input isTIME, notS5TIME. - When the program must expose the remaining time (preset minus elapsed) rather than the elapsed time, add a subtraction in SCL:
"DB_Display".RemainingMs := TIME_TO_DINT("DB_Timer1".PT) - "DB_Display".ElapsedMs. The HMI linear scale becomes 0 → 0 and 3 600 000 → 3600 again, but the HMI field is wired toRemainingMs. - For redundant or fail-safe programs, consider using a retentive instance DB (attribute "Retain" = true) so the timer state survives a CPU restart. This is the default for the IEC TONR instance DB; verify by opening the DB properties in TIA Portal.
- If the KTP600 Color DP is replaced with a KTP700 or KTP900, the linear scale and format properties are identical. Migrating screens between Comfort Panels and Basic Panels requires no change to the scaling configuration.
- When deploying to multiple stations, export the timer block as a master copy in the project library. TIA Portal V12 SP1 supports the type-instance model for IEC timers, so changes to the master automatically propagate to all instances on recompile.
- Diagnostic indicator for the field engineer: if the CPU SF (System Fault) LED illuminates after a T_CONV compile, the ET tag is in an unreachable DB. Check the DB number assignment in the TIA Portal cross-reference and confirm the instance DB is not optimized (S7-300 requires standard DBs for IEC timer compatibility).
FAQ
Why does the BI output of my S5 timer show 146 for a 24 m 20 s preset?
The S5TIME format S5TIME#24M20S (1460 s) uses the 10 s time base because the BCD value (146) must fit in 12 bits. The BI output returns the time divided by the time base, so 1460 s ÷ 10 s = 146. The BCD output yields the same 146 in BCD. This is documented Siemens behavior, not a defect. Migrate the timer to an IEC TONR or TON block to obtain an unambiguous TIME (DINT, ms) value.
Can I keep the S5 timer and just multiply BI by 10 on the KTP600 HMI?
No. The scaling factor required (×0.01, ×0.1, ×1, or ×10) depends on the time base of the active preset. A panel-side multiplier that is correct for a 1460 s preset will be wrong for a 9 s preset, where the time base is 10 ms and the BI value is 900. Use an IEC timer with T_CONV plus a single linear scale on the HMI.
Where do I find the IEC TONR block in TIA Portal V12 SP1?
Open the program block, then navigate to Instructions → Basic operations → Timers. The folder lists TP, TON, TOF, and TONR. If the folder is empty, install the S7-300 CPU 31xC support package from Options → Support Packages. Once installed, drag TONR into the network and let TIA Portal generate a single-instance DB for the timer.
How do I display the remaining time in mm:ss instead of plain seconds?
Compute the minutes and seconds in SCL using integer division and modulo: minutes := ElapsedSec DIV 60; seconds := ElapsedSec MOD 60; Concatenate as a STRING with leading zeros via INT_TO_STRING conversion, and display the string in a text field on the KTP600. The Basic Panel runtime supports the String I/O field for this purpose.
Does the IEC timer retain its value across a CPU power cycle?
Yes, the TONR (retentive on-delay) timer stores its elapsed time in the instance DB, which is retentive by default. Powering off the S7-313C does not reset the elapsed time. The non-retentive TON timer does reset on power loss. Choose TONR for countdowns that must survive a brown-out; choose TON for countdowns that must start from zero on every power-up.