XC2 Hardware Manual
Chapter 2: Installation and Configuration
2.4.1. STO Standards
Table 2-24:
STO Standards
Standard
Maximum Achievable Safety
EN/IEC 61800-5- 2:2016
SIL 3
EN/IEC 61508-1:2010
SIL 3
EN/IEC 61508-2:2010
SIL 3
EN ISO 13849-1:2015
Category 4, PL e
EN/IEC 62061:2005 with Amendments
SIL 3
Table 2-25:
STO Standards Data
Standard
Value
EN ISO 13849-1:2015
MTTF
D
> 1000 years,
DC
AVG
99%
Maximum PL e, Category 4
EN ISO 13849-1:2015
EN/IEC 61508
Lifetime = 20 years
No proof test required
Interval for manual STO test:
l
Once per year for SIL2/PL d/category 3
l
Once per three months for SIL3/PL e/category 3
l
Once per day for SIL3/PL e/category 4
EN/IEC 61508
SIL3
PFH < 3 FIT
SFF > 99%
2.4.2. STO Functional Description
The motor can only be activated when voltage is applied to both STO 1 and STO 2 inputs. The STO state will
be entered if power is removed from either the STO 1 or the STO 2 inputs. When the STO state is entered,
the motor cannot generate torque or force and is therefore considered safe.
The STO function is implemented with two redundant channels in order to meet stated performance and SIL
levels. STO 1 disconnects the high side power amplifier transistors and STO 2 disconnects the low side
power amplifier transistors. Disconnecting either set of transistors effectively prevents the XC2 from being
able to produce motion.
The XC2 software monitors each STO channel and will generate an Emergency Stop software fault when
either channel signals the stop state. Each STO channel contains a fixed delay which allows the XC2 to
perform a controlled stop before the power amplifier transistors are turned off.
A typical configuration requiring a controlled stop has the Emergency Stop Fault mask bit set in the
FaultMask, FaultMaskDecel, and FaultMaskDisable parameters. This stops the axis using the rate
specified by the AbortDecelRate parameter. The software will disable the axis as soon as the deceleration
ramp is complete. This is typically configured to occur before the STO channel turns off the power amplifier
transistors.
The software controlled stop functionality must be excluded when considering overall system safety. This is
because the software is not safety rated and cannot be included as part of the safety function.
The XC2 will tolerate short diagnostic pulses on the STO 1+ and STO 2+ inputs. The parameter
"STOPulseFilter" specifies the maximum pulse width that the XC2 will ignore.
www.aerotech.com
53
PENDING