LOGO! 8.3 Cloud Service: Why 8.2 Cannot Be Firmware Upgraded

David Krause12 min read
Other TopicSiemensTechnical Reference
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

LOGO! 8.3 Cloud Service: Why LOGO! 8.2 Cannot Be Firmware-Updated to 8.3

The Siemens LOGO! logic module line reached a structural turning point with the introduction of the LOGO! 8.3 series. The new generation adds native cloud connectivity, an extended on-board web server, and a redesigned communications stack that is not backward compatible with the LOGO! 8.1 or LOGO! 8.2 hardware. This reference explains why a firmware update on an existing LOGO! 8.2 FS4 cannot unlock 8.3 features, what the 8.3 cloud service actually requires at the hardware level, and how to integrate older LOGO! 8.2 nodes into a cloud topology without replacing them.

Engineer field note: The cloud feature in LOGO! 8.3 is bound to a new communications ASIC and a different on-board Ethernet MAC/firmware partition. Siemens has explicitly published that no firmware update path exists for 8.1 or 8.2 to inherit 8.3 features. Plan hardware, not firmware, when scoping a cloud migration.

1. LOGO! 8.2 vs LOGO! 8.3: Feature and Hardware Comparison

The 8.2 generation and the 8.3 generation share the same form factor and the same program format (.lsc / .lma) in LOGO! Soft Comfort, but the on-board silicon, the Ethernet controller, and the secure element differ. The differences are summarized below.

Capability LOGO! 8.2 (6ED1052-2xx08-0BA1 / FS4) LOGO! 8.3 (6ED1052-2xB08-0BA2)
Cloud connector to AWS IoT Core Not available Native, integrated
Direct MQTT 3.1.1 / 5.0 publish No Yes (via cloud block)
Extended web server with TLS HTTP only HTTPS with TLS 1.2/1.3
Program blocks (function blocks max) 400 400 (same program limit)
Analog inputs (0-10 V) 4 (of 8 digital inputs) 4 (of 8 digital inputs)
Ethernet 10/100 Mbit, RJ45 10/100 Mbit, RJ45, secure element on module
SD card slot Yes Yes
Firmware update path from prior gen 8.1 → 8.2 supported 8.2 → 8.3 not supported
LOGO! Soft Comfort version 8.2.x or 8.3.x 8.4.x (recommended)

The order code suffix change from -0BA1 (8.2) to -0BA2 (8.3) reflects the hardware revision. The MLFBs 6ED1052-1CC08-0BA1 (LOGO! 8.2 FS4) and 6ED1052-1CC08-0BA2 (LOGO! 8.3) cannot be cross-flashed; the bootloader rejects firmware images from the other generation.

2. Why LOGO! 8.2 Cannot Be Firmware-Updated to 8.3

Siemens has stated that the LOGO! 8.3 release is a new series of devices, not a feature drop into prior hardware. Three concrete technical reasons prevent a usable firmware migration.

2.1 Secure Element and Trust Anchor

LOGO! 8.3 performs mutual TLS authentication with AWS IoT Core. This requires a hardware secure element (a discrete TPM/secure-IC on the module) that holds the device private key and the AWS IoT certificate. The 8.2 module does not have a populated secure element footprint, so it cannot store or use a per-device X.509 client certificate. A firmware update cannot add a missing cryptographic co-processor.

2.2 Ethernet MAC and PHY Bring-Up

The 8.3 firmware configures the Ethernet controller for an additional low-level DMA path used by the TLS accelerator and the cloud connector block. The 8.2 silicon revision (revision B0 of the integrated MCU) does not expose the required DMA channels. Boot code cannot relocate the missing hardware.

2.3 Bootloader Signature Policy

LOGO! 8.3 firmware images are signed with a new Siemens signing key that is bound to the 8.3 secure element. The 8.2 bootloader will refuse the image at verification time. This is by design, to prevent downgrade and cross-generation flashing.

Bottom line: The hardware delta is not "just an Ethernet upgrade." It is a different trust model, a different crypto anchor, and a different bootloader policy. Treat LOGO! 8.3 as a separate device family for the purposes of spare parts, asset lists, and project bills of material.

3. LOGO! 8.3 Cloud Service Architecture

The cloud connector in LOGO! 8.3 is documented in the Siemens application note "LOGO! – Connection to a cloud," available as PDF attachment 109781025 on the Siemens Industry Online Support portal. The reference architecture is straightforward.

LOGO! 8.2 FS4 Modbus TCP slave no cloud block LOGO! 8.3 (Gateway) Cloud connector Modbus TCP master AWS IoT Core MQTT broker X.509 mutual TLS Modbus TCP MQTT/TLS LOGO! TDE / HMI Web server (HTTPS) Display data LAN / Switch / Router with outbound 8883

3.1 Cloud Block in LOGO! Soft Comfort 8.4

The cloud function block is added in the toolbox under Network → Cloud. Drag it onto the program sheet and configure:

  • Enable: Boolean enable input (typically a digital input or a derived condition).
  • AWS endpoint: The AWS IoT Core custom endpoint, e.g. a1b2c3d4-ats.iot.us-east-1.amazonaws.com.
  • Port: 8883 (MQTT over TLS, default).
  • Client ID: Must match the AWS IoT Thing name.
  • Topic prefix: Root topic for publish/subscribe (e.g. plant/line3/logo).
  • Publish interval: 1 s to 3600 s.

The block publishes a JSON payload of up to 8 process variables per instance. Up to 2 cloud blocks can be placed in a single LOGO! 8.3 program, allowing 16 published variables per device.

3.2 AWS IoT Core Provisioning

  1. Create an IoT Thing in AWS IoT Core with a name matching the LOGO! client ID.
  2. Generate a device certificate and a private key. The private key is loaded into the LOGO! 8.3 secure element during commissioning using LOGO! Soft Comfort 8.4 → Tools → Cloud → Provision Device.
  3. Attach an IoT policy that allows iot:Connect, iot:Publish, iot:Subscribe, and iot:Receive on the configured topic ARN.
  4. Download the Amazon Root CA 1 and the device certificate; transfer them to the LOGO! SD card in the /cloud/ directory.
Security note: The device private key never leaves the LOGO! 8.3 secure element. The SD card only holds the certificate, the CA chain, and configuration. Removing the SD card does not erase the key.

4. Prerequisites for Using LOGO! 8.3 Cloud

  • Hardware: One LOGO! 8.3 base module (6ED1052-...-0BA2) with firmware ≥ V1.0.0.
  • Engineering: LOGO! Soft Comfort 8.4 or later installed on Windows 10/11.
  • Network: DHCP or static IP on the LOGO! Ethernet port, with outbound TCP 8883 to the AWS endpoint reachable. NAT/port forwarding on the router is the typical plant configuration.
  • Cloud account: AWS account with IoT Core activated in the desired region.
  • Credentials: X.509 device certificate, private key (provisioned on first use), Amazon Root CA 1.

5. Step-by-Step: Commissioning LOGO! 8.3 Cloud Service

  1. Set the LOGO! IP address. In LOGO! Soft Comfort 8.4, go to Tools → Ethernet Connections. Assign a static IP (e.g. 192.168.0.10/24) and the gateway of the plant network.
  2. Transfer the program to the LOGO! 8.3 module via Ethernet or SD card. The program must contain the cloud function block configured as in §3.1.
  3. Prepare the SD card. Format as FAT32. Create the folder /cloud/. Place inside: device.crt.pem, AmazonRootCA1.pem, and the config.json exported from LOGO! Soft Comfort.
  4. Insert the SD card into the LOGO! 8.3 with the power off. Power on. The status LED sequence green-green-amber indicates the secure element is initialized.
  5. Provision the private key. In LOGO! Soft Comfort 8.4, Tools → Cloud → Provision Device. Connect via USB or Ethernet. The tool generates a keypair inside the secure element and uploads the CSR to AWS IoT Core. Sign the CSR in AWS, download the signed certificate, and write it back to the device.
  6. Verify connectivity. In the LOGO! web server (https://<logo-ip>), open Diagnostics → Cloud. The status field should read CONNECTED within 30 s of boot if the network path is open.
  7. Subscribe a test client. From any host, run aws iot-data publish --topic "plant/line3/logo/test" --payload "hello" --region us-east-1 (or use the MQTT test client in the AWS console) and confirm receipt on the LOGO! side via the cloud block's status output.

6. Using LOGO! 8.2 as a Modbus Gateway to a LOGO! 8.3 Cloud Node

For installations where a fleet of LOGO! 8.2 devices is already deployed, a single LOGO! 8.3 can act as a Modbus TCP gateway, polling the 8.2 nodes and republishing their values to the cloud. This is the practical workaround for the lack of an 8.2 firmware upgrade path.

6.1 Logical Data Flow

[LOGO! 8.2 #1] --+
[LOGO! 8.2 #2] --+--> [LOGO! 8.3 (Modbus master + cloud)] --> AWS IoT Core
[LOGO! 8.2 #3] --+        |
                           +--> LOGO! TDE / web dashboard

6.2 Configuration of the 8.3 Master Block

In LOGO! Soft Comfort 8.4, the Modbus master block (under Network → Modbus) is configured for each 8.2 slave. Set:

  • Connection type: Modbus TCP
  • Remote IP: static IP of the 8.2 device
  • Port: 502 (default for LOGO! 8.2 Modbus server)
  • Slave unit ID: 1 (LOGO! uses 1 by default)
  • Read function: 03 (Read Holding Registers)
  • Register range: 0000-0029 (LOGO! Modbus mapping, see §6.3)
  • Poll interval: ≥ 1000 ms per slave to avoid overwhelming the 8.2 server

6.3 LOGO! Modbus Register Map (8.2 server side)

Register Content Type
0000-0007 Digital inputs I1..I8 Coil / bit
0008-000F Digital outputs Q1..Q8 Coil / bit
0010-0017 Flags M1..M8 Coil / bit
0020-0027 Analog inputs AI1..AI4 Holding register, 16-bit signed
0028-002F Analog outputs AQ1..AQ2 Holding register, 16-bit signed
0030-003F Variable memory VW0..VW15 Holding register, 16-bit signed
The Modbus server is enabled on the 8.2 side via Tools → Ethernet Connections → Modbus Server = On. The 8.2 module can serve up to 8 simultaneous Modbus TCP connections; the gateway architecture must respect this limit.

6.4 Cloud Publish Mapping

Each Modbus read populates a LOGO! variable memory word. The cloud function block on the 8.3 then publishes a JSON object such as:

{
  "device": "logo-8-2-node-1",
  "ts": 1730000000,
  "di": {"I1": 1, "I2": 0, "I3": 1, "I4": 0, "I5": 1, "I6": 0, "I7": 1, "I8": 0},
  "ai": {"AI1": 412, "AI2": 768, "AI3": 1023, "AI4": 256},
  "vw": {"VW0": 12, "VW1": 34}
}

The topic naming convention is recommended as plant/<area>/<line>/<device-id>/telemetry to keep the AWS IoT registry organized.

7. Firmware and Boot Loader Behavior

On both 8.2 and 8.3, the firmware update is performed from LOGO! Soft Comfort via Tools → Update Firmware, or by placing a *.bin file on the SD card. The relevant behaviors are:

Scenario 8.2 module response 8.3 module response
8.2 firmware image flashed to 8.2 Accepted, normal update Rejected, signature invalid
8.3 firmware image flashed to 8.2 Rejected, signature invalid Accepted, normal update
8.2 firmware image flashed to 8.3 Rejected, hardware ID mismatch Rejected, hardware ID mismatch
Downgrade attempt Blocked by signature policy Blocked by signature policy

The hardware ID mismatch is what protects the 8.2 user from bricking the module with the wrong firmware. There is no recovery if the firmware is interrupted during a flash; the only mitigation is to keep the SD card with a known-good image always present in the module.

8. Field-Commissioning Checklist

  1. Verify the MLFB ends in -0BA2 for 8.3 modules. The label is on the side of the module.
  2. Confirm the firmware version in the LOGO! menu under Diagnostics → Module → Firmware. Cloud connector requires ≥ V1.0.0.
  3. Verify the SD card is inserted and contains the /cloud/ folder with the three files.
  4. Check the secure element status in the web server. OK is required; UNINITIALIZED means provisioning has not been done.
  5. Ping the AWS endpoint <custom-endpoint> on TCP 8883 from a host on the same VLAN to validate the firewall rules.
  6. Subscribe to the LOGO! topic in the AWS IoT MQTT test client and confirm a payload arrives within one publish interval.
  7. Document the AWS Thing name, certificate ARN, and the LOGO! serial number in the plant asset register.

9. Common Faults and Diagnostics

Symptom Likely root cause Corrective action
Cloud status = NO_CERT Device certificate missing or corrupt on SD card Re-export certificate from AWS and rewrite to /cloud/device.crt.pem
Cloud status = TLS_FAIL System clock out of range, CA chain mismatch Sync NTP, verify AmazonRootCA1.pem is the correct region
Cloud status = DNS_FAIL LOGO! cannot resolve AWS endpoint Set DNS server in Ethernet config; verify outbound UDP 53
Cloud status = AUTH_DENIED AWS IoT policy does not allow the Thing to connect Review attached policy; allow iot:Connect on the client ID
Status LED red-red-amber repeating Secure element not initialized Re-run provisioning with LOGO! Soft Comfort 8.4
Modbus gateway reads return 0 8.2 Modbus server disabled, or slave unit ID wrong Enable Modbus server on the 8.2; verify unit ID = 1

10. Recommendations and Migration Path

  • New cloud projects: Specify LOGO! 8.3 (6ED1052-...-0BA2) from the start. Do not assume a 8.2 unit can be repurposed later via firmware.
  • Existing 8.2 fleets: Keep the 8.2 firmware up to date within the 8.2 train (e.g. FS4 → FS5 service releases), but do not expect new 8.3 features.
  • Hybrid topologies: Use a single 8.3 as a Modbus TCP master to publish 8.2 telemetry. This is the lowest-cost migration path.
  • Spare parts policy: Stock 8.2 spares for installed 8.2 assets and 8.3 spares for new projects. Do not mix in a spare 8.2 where an 8.3 program is required.
  • Documentation: The official cloud connection guide is Siemens support entry 109781025. Always cross-check the firmware release notes for the 8.3 module you are using before commissioning.
Engineer field note: Several integrators have attempted to solder a secure element onto 8.2 PCBs. This violates the warranty, breaks the EMC certification, and is explicitly not supported. Always use the factory 8.3 hardware for cloud.

FAQ

Can I flash LOGO! 8.2 FS4 to get the LOGO! 8.3 cloud features?

No. The cloud connector requires a hardware secure element, a different Ethernet DMA path, and a new bootloader signing key that are only present on LOGO! 8.3 (MLFB suffix -0BA2). The 8.2 bootloader rejects 8.3 firmware images, and even if it accepted them, the missing silicon would cause TLS handshakes to fail.

What is the difference between LOGO! 8.2 and 8.3 for cloud connectivity?

LOGO! 8.3 has an integrated cloud connector block that publishes process data via MQTT 3.1.1/5.0 over mutual TLS to AWS IoT Core. LOGO! 8.2 has no native cloud block; it can only act as a Modbus TCP slave and be polled by a downstream 8.3 module.

Which LOGO! Soft Comfort version is required to program the cloud block?

LOGO! Soft Comfort 8.4 or later. Earlier versions do not expose the cloud function block and cannot open 8.3 program features. The official cloud setup guide is Siemens support PDF 109781025.

Can multiple LOGO! 8.2 nodes be brought into AWS IoT Core without replacing each one?

Yes. Use one LOGO! 8.3 as a Modbus TCP master that polls each 8.2 (Modbus server on port 502) and republishes the values to AWS IoT Core. Up to 8 Modbus TCP clients can connect to a single 8.2, and a 8.3 can poll several 8.2 slaves serially. Respect a minimum 1 s poll interval per slave to stay within the 8.2 server capacity.

Does the LOGO! 8.3 cloud feature work with cloud providers other than AWS?

The integrated cloud block is configured for AWS IoT Core endpoints. Other MQTT 5.0 brokers can be used in principle, but the provisioning flow in LOGO! Soft Comfort 8.4 is AWS-specific (CSR signing, IoT policy attachment, X.509 chain). For Azure IoT Hub or Google Cloud IoT, a third-party MQTT broker gateway is required.

Back to blog