Summa Series Servodrive Product Manual
STO
Document Version: V1.01
(Dec, 2019)
© 2019 ESTUN Automation Co., Ltd. All right reserved.
11-2
Figure 11-2
Reliability block diagram
Power
Supply
Common
Cause
Input 1
Input 2
Actuator 1
Actuator 2
Functions and Features
The functions or features of STO are as follows:
The safe state is the hardware shutdown of all PWMs, which make the Motor torque off.
The architecture of the system is 1oo1 + 1oo2.
The STO works in high demand mode of operation, and systematic capability is SC3.
The PFH may amount to 0.018% of the complete safety loop, and and it is 1.8*10
-11
.
MTTFd of each channel is 3184 years.
According to IEC 61508-6: 2010, MRT and MTTR are both 0.
Failure rates are: λ (total failures) = 355.80 fit; λ
S
(safe failures) = 283.38 fit;
λ
DD
(dangerous detected failures) = 71.69 fit;
λ
DU
(dangerous undetected failures) = 0.73 fit.
[
NOTE
] The unit for failure rates is 1
fit
(failures in time) = 1*10
-9
h
-1
, meaning one failure in 10
9
operation hours of the device.
The safety integrity level is SIL3 (IEC 62061: 2015), the performance level is PLe, the category is
Cat.4 (ISO 13849-1: 2015).
According to IEC 61508:2010 and IEC62061:2015, the SFF is no less than 99% for dual channel part
(1oo2), and is no less than 99% for signal channel part (1oo1).
According to ISO 13849-1: 2015, DC is no less than 99%.
(*)
The response time of STO is no more than 30ms.
Response time of STO is the time frame from the STO signal is triggered to the PWM signal is
removed.
(*)
The diagnose test interval is less than 20ms for HFT=0, and is less than 1h for HFT>0.
(*)
According to IEC61326-3-1 for the DS definition, the Motor will stop within 200ms.
According to ISO 13849: 2015, the CCF score is better than 65.
(*)
All detected faults will lead to safe state.
(*)
In single channel, diagnostic test in fault reaction time < 30ms.
(*)
Input signal filtering time definition: when the input signal keeps low level more than 2ms, turns
HWBB1 and HWBB2 OFF and the system will enter safe state.
CAUTION
In order to prevent the accumulation of faults, based on the risk
assessment of the machine or device, it is confirmed at a fixed time
whether the function is lost.
Regardless of the system safety level, the safety confirmation test is
performed at least once in 20 years. The inspection items mainly include
the items (*) added to the above characteristics.