146 Safe torque off function
performed and the drive trips. An attempt to use the STO in a non-redundant manner, for
example activating only one channel, will trigger the same reaction.
See the drive firmware manual for the indications generated by the drive, and for details on
directing fault and warning indications to an output on the control unit for external
diagnostics.
Any failures of the Safe torque off function must be reported to ABB.
Safety data (SIL, PL)
The safety data for the Safe torque off function is given below.
* according to Table E.1 in EN/ISO 13849-1
• This temperature profile is used in safety value calculations:
• 670 on/off cycles per year with T = 71.66 °C
• 1340 on/off cycles per year with T = 61.66 °C
• 30 on/off cycles per year with T = 10.0 °C
• 32 °C board temperature at 2.0% of time
• 60 °C board temperature at 1.5% of time
• 85 °C board temperature at 2.3% of time.
• The safety data is calculated for redundant use, and does not apply if both channels
are not used.
• The STO is a type A safety component as defined in IEC 61508-2.
• Relevant failure modes:
• The STO trips spuriously (safe failure)
• The STO does not activate when requested
A fault exclusion on the failure mode “short circuit on printed circuit board” has been
made (EN 13849-2, table D.5). The analysis is based on an assumption that one
failure occurs at one time. No accumulated failures have been analyzed.
• STO reaction time (shortest detectable break): 1 ms
• STO response time: 2 ms (typical), 5 ms (maximum)
• Fault detection time: Channels in different states for longer than 200 ms
• Fault reaction time: Fault detection time + 10 ms
• STO fault indication (parameter 31.22) delay: < 500 ms
• STO warning indication (parameter 31.22) delay: < 1000 ms
Frame SIL/
SILCL
SC PL SFF
(%)
PFH
(T
1
= 20 a)
(1/h)
PFD
(T
1
= 2 a)
MTTF
d
(a)
DC*
(%)
Cat. HFT CCF
(%)
Lifetime
(a)
U
1
= 380…480 V
R10, R11 3 3 e 99.88 1.05E-9 1.61E-6 12779 >
90 3 1 80 20
3AXD10000410558 REV B