2 General Information about Integrated Safety Systems
11.03
2.6 Basics of SINUMERIK Safety Integrated
© Siemens AG 2003 All Rights Reserved
2-34
SINUMERIK 840D/SIMODRIVE 611 digital SINUMERIK Safety Integrated (FBSI) - Edition 11.03
The forced checking procedure is used to detect errors in the software and
hardware of the two monitoring channels. In order to do this, the safety-relevant
parts in both channels must be processed in all safety-relevant branches at
least once during a defined period. Any errors in the monitoring channel will
cause deviations and will be detected by the crosswise data comparison.
The forced checking procedure of the shutdown path (test stop) must be
triggered by the user or integrated in the process as an automatic procedure,
e.g.:
•
for stationary axes after the system has been powered-up
•
when the protective door is opened
•
in defined cycles (e.g. in 8-hour cycles)
•
in the automatic mode – dependent on the time and event.
The forced checking procedure also includes testing the safety-relevant
sensors and actuators. In this case, the entire circuit including the "safe
programmable logic" (SPL) is tested for correct functioning.
Note
A defined 8-hour cycle is not mandatory in the automatic mode (when the
protective door is closed). A forced checking procedure after an 8-hour period
has elapsed can be combined with the next opening of the protective door.
Any errors in the monitoring channel result in deviations and are detected by
the crosswise data comparison.
Dormant errors in the safety-relevant data of the two monitoring channels are
discovered in the course of the crosswise data comparison.
In the case of "variable" data, there are tolerance values defined using machine
data by which amount the results of the two channels may deviate from one
another without initiating a response (e.g. tolerance for crosswise data
comparison of actual positions).
Note
Errors that are discovered as a result of the forced checking procedure or
crosswise data comparison lead to a STOP F response (refer to Chapter 3,
"Stop responses") and initiate a further stop response when Safety Integrated
is active.
Forced checking
procedure with Safety
Integrated
Error in the monitoring
channel
Crosswise data
comparison