An extensive FMEA process led to the available safety architecture. Three key mechanisms are part of the
resulting safety concept: redundancy, diagnostic functions, monitoring functions.
Function safety specification
Identification of configurations
JS1-H Steer by Wire does not support different configurations. All functions are as specified and
described within this document and the data sheet. No configuration necessary.
Safety functions declaration
1. Safe Transmission of Joystick Angle Position
2. Safe Finger Function (Button Auto-Guidance)
Safety monitoring functions declaration
1. Monitoring of Force Feedback Direction
2. Monitoring of Operator Notification
Safe states
The following Safe States exist for each of the four processing units within JS1-H Steer by Wire:
1. Signal Safety Error
•
The joystick notifies the connected EHD controller about an internal error via CAN messages.
Affected functions may be abandoned. Unaffected functions remain operable, basic joystick
functionality (steering, button input) is still given.
2. Communication Stop
•
The affected processor interrupts the communication to the EHD controller. No messages are sent
to the CAN bus from the corresponding CAN Node. Due to the second CAN channel, the joystick
functionality is still given.
3. Force Feedback Safe Stop
•
The Force Feedback comfort function is disabled. Other functions remain operable, joystick
functionality is still given.
Upon entering one of the Safe States, JS1-H Steer by Wire can only be reset by performing a power
down/up.
Safety function response time
The safety response time is defined as the period of time between a failure is first observed by the
diagnostics and the time by which the corresponding safe state is entered.
Safety Function
Fault Reaction / Risk Mitigation Safety Response Time
1. Safe Transmission of Joystick Angle Position
1. Signal Safety Error
3. Force Feedback Safe Stop
80 ms
2. Provide a Safe Finger Function (ButtonAuto-Guidance) 1. Signal Safety Error
80 ms
Safety monitoring function response time
The monitoring function response time is defined as the period of time between a failure is first observed
by the monitoring and the time by which the corresponding safe state is entered.
User and Safety Manual
PLUS+1® JS1-H Steer by Wire
Functional Safety
©
Danfoss | December 2022
AX436683569858en-000101 | 17