2
Description of the safety function STO
14
Festo – GDCP-CMMP-AS-M0-S1-EN – 1412a – English
Discrepancy time
The transition between the safe and the unsafe state is initiated via level changes at the control ports
STO-A and STO-B of the motor controller. According to the safety function specification, the two levels
must be identical otherwise an error message will be generated. The finite state machine in the motor
controller internally monitors the driver supply voltage after the control ports have been activated. Due
to component tolerances or bouncing safety controller ports, for example, these level changes do not
normally occur precisely at the same time. The firmware tolerates this for as long as the second input
occurs within a defined time, the so-called discrepancy time. If this time is exceeded, the motor control
ler generates an error message.
A discrepancy time of 100 ms is specified.
Always switch STO-A and STO-B simultaneously.
Test pulse
Test pulses from safety controls are tolerated within a certain range and therefore do not cause a re
quest of the STO function.
The tolerance to test pulses from sensors with OSSD signals is rated for the operating range specified
in accordance with Appendix A.1.3, Tab. A.6. The permissible test pulse length is dependent upon the
control voltage level at inputs STO-A and STO-B.
Example:
Input voltage for STO-A and STO-B = 24 V
è
OSSD signals with a max. test pulse length of 3.5 ms are tolerated.
2.2.4
Acknowledgment contact C1, C2 [X40]
In the event of a
non-active STO function
the acknowledgment contact is open. This is the case, for
example, if the control voltage is present at STO-A and STO-B, if only one of the two control voltages
STO-A or STO-B is present, if the 24 V logic power supply is switched off, or if the supply voltage fails.
In the event of an
active STO function
the relay contact is closed.
The acknowledgment contact has a single channel and should only be used for monitoring
purposes.
Tab. A.7 in appendix A.1.3 describes the electrical data, Tab. A.6 the time response of the
acknowledgment contact.
When the 24 V supply to the basic device is turned on and off, the switching status of the
relay may - due to the internal supply voltages powering up at a different speed - deviate
briefly (approx. 100 ms) from the state of the control ports STO-A and STO-B.
In order to guarantee the DC and SFF values specified in appendix A.1.1, the state of the
C1/C2 acknowledgment contact needs to be registered for each request of the safety
function.
When the safety function has been requested, a change in signal must occur at the
acknowledgment contact within an application-specific time. A safety-related response
must be initiated in the event of a violation.