Stop functionality and safety levels are appropriate and
sufficient. Safe Stop is designed and approved suitable for
the requirements of:
-
Safety Category 3 according to EN ISO 13849-1
-
Performance Level "d" according to EN ISO
13849-1:2008
-
SIL 2 Capability according to IEC 61508 and EN
61800-5-2
-
SILCL 2 according to EN 62061
1)
Refer to EN IEC 61800-5-2 for details of Safe torque off
(STO) function.
2)
Refer to EN IEC 60204-1 for details of stop category 0
and 1.
Activation and Termination of Safe Stop
The Safe Stop (STO) function is activated by removing the
voltage at Terminal 37 of the Safe Inverter. By connecting
the Safe Inverter to external safety devices providing a safe
delay, an installation for a safe Stop Category 1 can be
obtained. The Safe Stop function can be used for
asynchronous, synchronous, and permanent magnet
motors.
WARNING
After installation of Safe Stop (STO), a commissioning test
as specified in
2.5.2 Safe Stop Commissioning Test
must be
performed. A passed commissioning test is mandatory
after first installation and after each change to the safety
installation.
Safe Stop Technical Data
The following values are associated to the different types
of safety levels:
Reaction time for T37
-
Maximum reaction time: 10 ms
Reaction time = delay between de-energizing the STO
input and switching off the adjustable frequency drive
output bridge.
Data for EN ISO 13849-1
-
Performance Level "d"
-
MTTF
d
(Mean Time To Dangerous Failure): 14,000
years
-
DC (Diagnostic Coverage): 90%
-
Category 3
-
Lifetime 20 years
Data for EN IEC 62061, EN IEC 61508, EN IEC 61800-5-2
-
SIL 2 Capability, SILCL 2
-
PFH (Probability of Dangerous failure per
Hour)=1e-10FIT=7e-19/h-9/h>90%
-
SFF (Safe Failure Fraction) >99%
-
HFT (Hardware Fault Tolerance)=0 (1001
architecture)
-
Lifetime 20 years
Data for EN IEC 61508 low demand
-
PFDavg for one year proof test: 1E-10
-
PFDavg for three year proof test: 1E-10
-
PFDavg for five year proof test: 1E-10
No maintenance of the STO functionality is needed.
Security measures have to be taken by the user, e.g.,
installation in a closed cabinet that is only accessible for
skilled personnel.
SISTEMA Data
Functional safety data is available via a data library for use
with the SISTEMA calculation tool from the IFA (Institute
for Occupational Safety and Health of the German Social
Accident Insurance) and data for manual calculation. The
library is complete and continually extended.
2.5.1 Terminal 37 Safe Stop Function
The adjustable frequency drive is available with safe stop
functionality via control terminal 37. Safe stop disables the
control voltage of the power semiconductors of the
adjustable frequency drive output stage. This in turn
prevents generating the voltage required to rotate the
motor. When the Safe Stop (T37) is activated, the
adjustable frequency drive issues an alarm, trips the unit,
and coasts the motor to a stop. Manual restart is required.
The safe stop function can be used as an emergency stop
for the adjustable frequency drive. In normal operating
mode when safe stop is not required, use the regular stop
function instead. When automatic restart is used, ensure
the requirements of ISO 12100-2 paragraph 5.3.2.5 are
fulfilled.
Liability Conditions
It is the responsibility of the user to ensure that qualified
personnel installs and operates the safe stop function:
•
Read and understand the safety regulations
concerning health and safety/accident prevention
•
Understand the generic and safety guidelines
given in this description and the extended
description in the relevant
Design Guide
•
Have a good knowledge of the generic and safety
standards applicable to the specific application
Installation
VLT
®
AutomationDrive Instruction
Manual
MG33AM22 - VLT
®
is a registered Danfoss trademark
2-13
2
2