when STO is activated from the switched off state "
ReadyToSwitchOn
".
This state is left without reset, if the STO is inactivated.
The error state "
FaultPending/STO-Active
" is entered
when STO is activated from the switched on state "
Operational
".
This state is left only with a reset command. The next state is either a warning state "
Not-Ready-
ToSwitchOn
" if a warning condition is still active (i.e., STO-active, temperature, bridge-voltage) or
the ready state, if the STO is inactivated.
Serious case
: In addition to these standard "Safe-States", there are a couple of "Safe-Error-States".
These require a user initiated reset for recovery. During recovery, there is a power-up test of the inter-
nal diagnostic circuit which takes about 40ms. The important causes from a user perspective are:
If the logic levels of the two channels are not equal during more than
t
Inconsistent
STO
, the drive enters the
safe error state
STO-Inconsistent
.
Internal diagnostic startup test failure: The drive enters the safe error state
startup test of the
safety circuit failed
.
Internal periodic pulse test failure: The drive enters the safe error state
STO-PulseTestFailure
.
If the internal diagnostic circuit temperature is out of range, the drive enters the safe error state
STO-Temperature-Limit
.
The following hardware considerations justify a special note:
A spontaneous defect of two power semiconductors may cause a maximum movement of 120° (electri-
cally), but this is very unlikely.
Voltages outside of the specifications:
The STO inputs are protected up to voltages of 40V by a thermal (recoverable) fuse.
If the 24V Supply voltages exceed 29V, the drive will enter and remain in the safe state. For Rev. 1
an irreversible fuse will break and the drive requires factory maintenance. For Rev. 2 and higher, the
internal power supply switches off and the drive requires a 24V power cycle.
Too small 24V supply voltages also cause entering the safe state.
5.5.4 Safety characteristic data
The safety specifications (in addition to the electrical STO specs in chapter 5.2.1) are
Safety level
SIL 3
PLe CAT 3
PFH
3E-9 h
-1
PFD
2E-4
(Proof-Test Interval = Mission Time)
SFF
95%
STO (Hardware Fault Tolerance HFT1)
96%
Diagnostics (Hardware Fault Tolerance HFT0)
Type
A
(according to 61508-2)
DC
92%
MTTFd
100a
Mission time TM
20a
HWTSD80-TSD130_4_HardwareManual_EP006
2022-01-27
20/49