5. STO
5.1 Overview
This product has the "Safe Torque Off" (STO) function in accordance with IEC 61800-5-2, which is equivalent to the uncontrolled stop (stop category 0) according to IEC 60204-1, which can protect workers from dangerous movements of moving parts of machinery and reduce the risk when using machinery. The function provides a way to prevent the drive from generating torque in the motor, and the safety function of the motor output torque is turned off by the safety input signal by forcibly turning off the drive signal of the power transistor inside the driver.
STO does not provide galvanic isolation, so it is not equivalent to the "safe shut-off" function of IEC 60204- 1, which means that a drive in the STO state may still have dangerous voltages at its motor terminals.
Functional block diagram
The operation of the safety function circuit is shown in below.
When the switch is closed, HWBB1 and HWBB2 are ON, and the signal blocking circuit allows the PWM signal to pass through, that is, the torque output is allowed.
When the switch is open, HWBB1 or HWBB2 is OFF, and the signal blocking circuit does not allow PWM signals to pass, that is, the torque output is turned off.
The reliability block diagram is shown below:
5.1.1 Features
STO safety features include the following:
The safe state refers to the shutdown of all PWM signals of the hardware, causing the motor torque to turn off.
The system structure is single channel + dual channel (1oo1 + 1oo2).
STO operates in demanding operating modes with SC3 system capability.
PFH can reach 0.018% of the entire safety loop, that is, 1.8*10-11.
The MTTFd per channel is 3184 years.
Follows IEC 61508-6:2010 with 0 MRT and MTTR.
Total failure rate λ = 355.80 fit; Safe failure rate λS = 283.38 fit; Dangerous failure rate λDD = 71.69 fit;
No dangerous failure rate λDU = 0.73 fit.
Note: The failure rate unit 1 fit (failures in time) = 1*10-9 h-1, that is, the device fails once in 109 working hours.
Safety class SIL3 (IEC 62061: 2015) and performance class PLe in category Cat.4 (ISO 13849-1: 2015).
In accordance with IEC 61508:2010 and IEC 62061:2015, the SFF of single channel (1oo1) is not less than 99%, and the SFF of dual channel section (1oo2) is not less than 90%.
Follows ISO 13849-1: 2015 with a DC of not less than 99%.
The response time to enable STO does not exceed 30ms.
The response time of the STO is the time interval from when the STO signal is triggered and when the PWM signal is turned off.
(*) When HFT=0, the diagnostic test interval is less than 20ms;When HFT > 0, the diagnostic test interval is less than 1h.
(*) Following the definition of DS in IEC61326-3-1, the motor will stop within 200ms.
Following ISO 13849-1: 2015, the CCF score is better than 65 points.
(*) All detected faults will cause the drive to enter a safe state.
(*) In a single channel, the diagnostic test interval + fault reaction time < 30ms.
(*) Input signal filtering time definition: When the input signal remains low for more than 2ms, the HWBB1 and HWBB2 signals will be set to OFF and the driver will enter a safe state.
5.1.2 Risk
The plant manufacturer is responsible for all residual risks associated with the risk assessment. The following are the residual risks associated with STO function. The Company shall not be liable for any damage, injury, etc. caused by residual risks.
5.1.3 Alarm Description
If an A.30 (STO module disconnection) or A.31 (STO hardware circuit failure) alarm occurs on the drive, it means that the STO function circuit may have been damaged and should be troubleshooted before using the STO function.
5.1.4 Applicable Standards
The standards followed by the STO function are shown in the table below.
5.2 Environmental Description
5.3 Port Definition
5.3.1 Terminal Arrangement
5.3.2 Signal Description
5.3.3 Signal Specifications
The input specifications for HWBB1 signals (CN6-3, -4) and HWBB2 signals (CN6-5, -6) are as follows:
The electrical characteristics of the EDM (CN6-7, -8) output signal are as follows:
5.4 Function Description
5.4.1 Peripheral monitoring (EDM)
Peripheral device monitoring (EDM) is a circuit that monitors whether the STO function is working properly, and please connect it with feedback such as safety devices.
The logical relationship between EDM signal, HWBB1 signal and HWBB2 signal is shown in Table 5-1.
Table 5-2 Logical relationship between EDM and HWBB1 and HWBB2
When the STO function is enabled by setting the input signals HWBB1 and HWBB2 to OFF, the EDM output signal will be built into ON at 5ms when the safety function is operating normally.
5.4.2 SAF state
After turning off the servo motor torque output using the STO function, the servo operating status will change to "SAF", and the digital tube on the operation panel will display:
The logical relationship between the SAF state and the HWBB1 signal and HWBB2 signal is shown in Table 5-2.
The logical relationship between the servo state and HWBB1 and HWBB2
When the STO function is enabled by setting the input signals HWBB1 and HWBB2 to OFF, the power to the motor is cut off within 5ms.
The safety input signal may contain L pulses for self-diagnosis of safety equipment, and it should be ensured that the L pulse does not exceed 1ms, otherwise it may be treated as an OFF signal and enter a safe state.
5.4.3 S-RDY signal
In the SAF state, the servo prepares the S-RDY signal to OFF.
If the HWBB1 and HWBB2 signals are set to ON and the servo is OFF, the servo preparation S-RDY signal will be set to ON, and the servo will enter the servo preparation state.
5.4.4 Brake Output Control
When the STO function is enabled, the brake control output (/BK) signal is set to OFF (brake action). At this point, the motor will immediately enter a power-on state and Pn506 (servo OFF waiting time) is invalid.
5.4.5 Stop Method
When the STO function is enabled, the motor stops running by inertia when the servo enters the SAF state.
5.4.6 Deviation Counter Clearing Method
When the STO function is enabled, when the servo enters the SAF state, the deviation counter is cleared according to the setting of Pn004.1 (deviation counter clearing method).
5.5 Connection of Security Devices
5.5.1 When security devices are not connected
If you do not need to connect a security device, you should keep the secure port connector plugged into the secure interface CN6 and the short-connect setting on the connector in factory condition.
Note
If the short wiring plug on the safety port connector is removed without connecting the safety device, the servo will enter the SAF state and will not supply current to the motor and will not output motor torque.
At this point, the digital tube in the operation panel will display "SAF".
5.5.2 When connecting a security device
Remove the secure jumper connector.
Remove the secure jumper connector from the STO connection port.
Connect safety device.
Follow the wiring example shown below to connect the safety device to the STO port for the connection of the safety device.
Under normal circumstances, when the safety light barrier is blocked, the HWBB1 and HWBB2 signals are OFF at the same time, and the EDM signal is ON, entering the safe state. If the safety light barrier is not blocked, the HWBB1 and HWBB2 signals enter an actionable state after ON.
Verify safety function.
After start-up, maintenance, drive replacement or wiring of the unit, be sure to perform the following tests to verify the safety function (it is recommended to document and retain the verification results).
Make sure that when the HWBB1 and HWBB2 signals are set to OFF, "SAF" is displayed on the operator panel and the motor stops.
Monitor the ON/OFF status of HWBB1 and HWBB2 signals.
If the ON/OFF status of the signal is inconsistent with the display of Un006, the following factors must be considered:
The external device is malfunctioning.
The external wiring is disconnected or short-circuited.
The drive has failed.
Please find out the cause and take appropriate action.
Troubleshooting
Either of the input signals HWBB1 or HWBB2 is set to OFF,The servo will enter the SAF state, and if another signal is still ON within 10s, an alarm of "A.30 (safety function input signal out of synchronization)" will be generated. At this point, the following factors must be considered:
The circuit or equipment used to input the HWBB1 and HWBB2 signals may be faulty.
The cable to the input signal has been disconnected.
Please find out the cause and take appropriate action.
5.6 Usage Procedure
Taking the wiring of the safety controller shown in Figure 5-4 as an example, follow the steps below to use the STO function.





























No comments to display
No comments to display