3 Safety-Related Functions
11.03
3.10 Safe programable logic (SPL) (840D SW 4.4.18)
© Siemens AG 2003 All Rights Reserved
3-166
SINUMERIK 840D/SIMODRIVE 611 digital SINUMERIK Safety Integrated (FBSI) - Edition 11.03
The following is permissible:
•
A "full 4-terminal concept" (two-channel test signal for two-channel useful
[net] signal), or
•
the "3-terminal concept" suggested above, or
•
a "2 terminal concept
without
test signals" if the two-channel useful (net)
signal to be tested automatically changes its level dynamically as a result
of the process and this can be verified using other useful signals. In this
case, the useful signals assume the function of test signals. For example, a
typical application could be a protective door evaluation function.
2. The signals "
external STOPs
" and "
test stop
" are handled differently
internally:
•
In order to increase the probability that a requested "external STOP" takes
effect, the STOPs between the two channels are exchanged internally.
Failure of the stop control in
one
channel does
not
cause an error for
these signals (in contrast to the operating mode switchover signals, e.g.
"SG/SBH active") in the crosswise data comparison.
Whereas other channels can be subjected to a forced checking procedure
in both channels in parallel (and should be - in order to avoid errors being
triggered by the data cross-check), the "external STOPs" and the "test
stop" must be subjected to a checking procedure
one after the other
in
both channels. As an alternative, simultaneous checking procedure of the
external STOPs is also possible, but in this case, two-channel checkback
signals must be used.
•
The test stop itself may not be subject to a forced checking procedure in
both channels in parallel because there is only
one
common hardware
response and checkback signal "pulse cancellation" for both channels (as
before).