
NOTE
Recommendation: For vertical lifting or hoisting
applications ensure that the load can be stopped in an
emergency or a malfunction of a single part such as a
contactor.
When the frequency converter enters alarm mode or an
over voltage situation, the mechanical brake cuts in.
NOTE
For hoisting applications, make sure that the torque limit
settings do not exceed the current limit. Set torque limits
in
4-16 Torque Limit Motor Mode
and
4-17 Torque Limit
Generator Mode
. Set current limit in
4-18 Current Limit
.
Recommendation: Set
14-25 Trip Delay at Torque Limit
to
[0]
,
14-26 Trip Delay at Inverter Fault
to
[0]
and
14-10 Mains
Failure
to
[3] Coasting
.
4.9 Safe Stop
The frequency converter can perform the safety function
Safe Torque Off
(STO, as defined by EN IEC 61800-5-2
1
) and
Stop Category 0
(as defined in EN 60204-1
2
).
Danfoss has named this functionality
Safe Stop
. Before
integration and use of Safe Stop in an installation, perform
a thorough risk analysis to determine whether the Safe
Stop functionality and safety levels are appropriate and
sufficient. Safe Stop is designed and approved suitable for
the requirements of:
-
Safety Category 3 in EN 954-1 (and EN ISO
13849-1)
-
Performance Level "d" in EN ISO 13849-1:2008
-
SIL 2 Capability in IEC 61508 and EN 61800-5-2
-
SILCL 2 in EN 62061
1) Refer to EN IEC 61800-5-2 for details of Safe torque off
(STO) function.
2) Refer to EN IEC 60204-1 for details of stop category 0
and 1.
Activation and Termination of Safe Stop
The Safe Stop (STO) function is activated by removing the
voltage at Terminal 37 of the Safe Inverter. By connecting
the Safe Inverter to external safety devices providing a safe
delay, an installation for a safe Stop Category 1 can be
obtained. The Safe Stop function can be used for
asynchronous, synchronous, and permanent magnet
motors.
WARNING
After installation of Safe Stop (STO), a commissioning test
must be performed. A passed commissioning test is
mandatory after first installation and after each change to
the safety installation.
Safe Stop Technical Data
The following values are associated to the different types
of safety levels:
Reaction time for T37
-
Typical reaction time: 10 ms
Reaction time=delay between de-energizing the STO input
and switching off the frequency converter output bridge.
Data for EN ISO 13849-1
-
Performance Level "d"
-
MTTF
d
(Mean Time To Dangerous Failure): 24816
years
-
DC (Diagnostic Coverage): 99%
-
Category 3
-
Lifetime 20 years
Data for EN IEC 62061, EN IEC 61508, EN IEC 61800-5-2
-
SIL 2 Capability, SILCL 2
-
PFH (Probability of Dangerous failure per
Hour)=7e-10FIT=7e-19/h
-
SFF (Safe Failure Fraction) >99%
-
HFT (Hardware Fault Tolerance)=0 (1oo1
architecture)
-
Lifetime 20 years
Data for EN IEC 61508 low demand
-
PFDavg for one year proof test: 3, 07E-14
-
PFDavg for three year proof test: 9, 20E-14
-
PFDavg for five year proof test: 1, 53E-13
SISTEMA Data
Functional safety data is available via a data library for use
with the SISTEMA calculation tool from the IFA (Institute
for Occupational Safety and Health of the German Social
Accident Insurance), and data for manual calculation. The
library is permanently completed and extended.
Abbrev. Ref.
Description
Cat.
EN 954-1
Category, level “B, 1-4”
FIT
Failure In Time: 1E-9 hours
HFT
IEC 61508
Hardware Fault Tolerance: HFT=n means,
that n+1 faults could cause a loss of the
safety function
MTTFd
EN ISO
13849-1
Mean Time To Failure - dangerous. Unit:
years
PFH
IEC 61508
Probability of Dangerous Failures per
Hour. Consider the PFH value when the
safety device is operated in high
demand (more often than once per
year); or operated in continuous mode,
where the frequency of demands for
operation made on a safety-related
system is greater than one per year.
Application Examples
VLT
®
Decentral Drive FCD 302
MG04H102 - VLT
®
is a registered Danfoss trademark
67
4
4