Safety Function Guide
Safety Function Guide
Safety Function Guide
Introduction
Safety function Guide Index
4 Safety Function
5 Planning Installation
6 Installation
7 Commissioning
10 Maintenance
Please refer to the following link for downloading the latest Please note that the Basic Guide, User’s Guide, the Safety
documentation. function Guide and the guides for each optional product to
be used should be delivered to the end user of the inverter.
Hitachi Industrial Equipment Systems’ Website
http://www.hitachi-ies.co.jp/english/index.htm
0-1
Introduction Introduction
0-2
Introduction Introduction
M
Term / Description
Abbreviation
*) Trademark Power supply necessary for
Main power supply
Some proper nouns such as product name or function operation of inverter
names may be registered as trademark or registered MFG No. Manufacturing No.
trademark. Particularly this documentation does not Mean time to dangerous failure
describes ® mark or TM mark. MTTFd Expectation of the mean time to
dangerous failure
D O
Term / Description Term / Description
Abbreviation Abbreviation
Failure of a component and/or The keypad mounted on the
subsystem and/or system that inverter used for configuration
Dangerous failure Operator keypad
plays a part in implementing the of parameters and monitoring of
safety function inverter's state
Diagnostic coverage (%) (EN ISO P
DC Term / Description
13849-1)
E Abbreviation
Term / Description Protected extra-voltage
PELV
Abbreviation (EN/iEC60204)
EMC Electromagnetic compatibility Probability of dangerous failure
PFD
on demand (IEC61508)
EUC Equipment Under Control
Average frequency of a
F PFH dangerous failure (EN/IEC61800-
Term / Description 5-2)
Abbreviation Performance level (a-e) (EN ISO
Part of the overall safety PL
13849-1)
relating to the EUC and the PLC Programmable logic controller
EUC control system that PWM Pulse width modulation
depends on the correct
Functional Safety R
functioning of the E/E/PE
safety-related systems and Term / Description
other risk reduction Abbreviation
measures.(IEC61508) Risk remaining after protective
Residual risk
measures have been taken
Delay time inside of the inverter
H from a request of activation of a
Term / Description Response time
function until actual execution
Abbreviation of the function
Hardware fault tolerance Probability and severity of
HFT Risk
(IEC61508) hazard
S
I Term / Description
Term / Description Abbreviation
Abbreviation Safety functions to achieve safe
I/O Input / Output state of system such as STO
IGBT Insulated gate bipolar transistor Safety Function
function defined in IEC61800-5-
The model code written on the 2.
Inverter model
specification label of the Whole system including inverter,
code
inverter. Safety-Related sensor, switch and safety relay
System etc. that achieves safety
function(s)
Safety extra-low voltage
SELV
(EN/IEC60950)
Safe failure fraction (%)
SFF
(IEC61508)
0-3
Introduction Introduction
S
Term / Description
Abbreviation
Safety integrity level (1-3)
SIL
(IEC61508)
SILCL SIL claim limit (EN/IEC62061)
Signal is recognized as ON when
current flows out from signal
Sink logic
terminal. That may differ
depending on systems.
A type of logic that signal is
recognized as ON when current
Source logic flows into the terminal. This logic
may differ depending on region
or system.
The label affixed on the
Specification label product, on which specification
of the inverter is written
Safe torque off (EN/IEC61800-5-
STO
2)
A type of stop category defined
in EN/IEC60204-1.
Stop category 0 Stopping by immediate removal
of power to the machine
actuator.
U
Term / Description
Abbreviation
The documentation that
provides the detailed
User's Guide
information to handle the
inverter
V
Term / Description
Abbreviation
Confirmation by examination
and provision of objective that
Validation the safety system meets the
requirements set by the
specification
Confirmation by examination
and provision of objective
Verification
evidence that the requirements
have been fulfilled
0-4
Index Index
S.5 Index
● Introduction ............................................................ 0-1 ● Relevant document…… ........................................ ….0-2
● Precaution ............................................................... 0-1 ● List of Abbreviation and Technical Terms ................ 0-2
1.1 Contents in this chapter .......................................... 1-1 1.2 Safety Precaution .................................................... 1-1
Chapter 6 Installation
6.1 Contents in this chapter .......................................... 6-1 6.3 Wiring example ....................................................... 6-1
6.2 Installation .............................................................. 6-1 6.4 External device ........................................................ 6-2
Chapter 7 Commissioning
7.1 Contents in this chapter .......................................... 7-1 7.3 Enabling STO function ............................................. 7-1
7.2 Considerations ........................................................ 7-1 7.4 Disabling STO function ............................................ 7-1
0-5
Index Index
Chapter 10 Maintenance
10.1 Contents in this chapter ...................................... 10-1 10.3 Daily and periodical inspection ........................... 10-1
10.2 Planning of maintenance .................................... 10-1 10.4 Periodical functional test..................................... 10-1
0-6
Chapter 1 Safety Precaution/Risk
1-1
Chapter 1 Safety Precaution/Risk
1.2.6 Others
1-2
Chapter 2 Introduction to the Safety function Guide
Chapter 2 Introduction to
the Safety function Guide
2
2.1 Contents in this chapter 2.5 Recommended readings
This chapter describes the applicable product, required The Safety function Guide is based on the following
knowledge, target audience, purpose and general standards. It is recommended you to read and familiarize
information of this documentation. with these standards before implementing safety-related
systems.
2-1
Chapter 2 Introduction to the Safety function Guide
(Memo)
2-2
Chapter 3 Safety-Related information and consideration
Chapter 3 Safety-related
information and consideration 3
3.1 Contents in this chapter
This chapter describes safety-related information and
considerations. 3.4.2 Response time
3.2 Requirement of The response time is defined as a time from input of Safety
request to actual activation of safety function.
Machinery Directive
In case of STO function, it is a time from input of STO signals
In order to fulfill the requirements of the Machinery
until power to a motor is shut off.
Directive, all requirements in the applicable standards
must be satisfied and SJ-P1 inverters must be used in The response time of the STO function of the SJ-P1 is less
accordance with the instructions provided in this Safety than 10ms.
function Guide and the User’s Guide of the SJ-P1.
A safety-related system must be designed in consideration
Before using the inverter, the risk assessment of whole of the above mentioned response time so that this delay
system must be conducted and appropriate measures must time may not lead to any hazardous situation.
be taken.
3.4.3 Self-Diagnosis of internal path
3.3 Intentional misuse
The SJ-P1 is equipped with the self-diagnosis function
The SJ-P1 is not designed to protect against intentional
which detects a fault in the internal safety paths.
misuse/interference for STO function.
When an internal fault has been detected, the safety paths
3.4 Safety consideration are maintained shut-off regardless of the states of the STO
inputs to the SJ-P1.
3.4.1 Safety function
3.4.4 STO Input
The SJ-P1 inverter supports the STO function which is
equivalent to STO (Safe Torque Off) function defined in The STO inputs of the SJ-P1 are redundant and the both
EN/IEC61800-5-2 as well as Category 0 Stop defined in input signals must be input. The two STO inputs must be
EN/IEC60204-1. appropriately separated from each other. If only one of the
inputs is used, the conformities to the applicable norms
The SJ-P1 inverter shuts off power to a motor when STO become invalid.
inputs are given.
3-1
Chapter 3 Safety-Related information and consideration
3-2
Chapter 4 Safety function
I/O terminal
STO input terminal STO input terminal
*: Depending on the inverter type. Refer to the User’s Guide of the SJ-P1.
4-1
Chapter 4 Safety function
■Wiring Example
■Internal power supply with “Source” logic
■Internal power supply with “Sink” logic
ST2 STC ST1
ST2 STC ST1
External DC24V power supply (SELV or PELV) External DC24V power supply (SELV or PELV)
4-2
Chapter 4 Safety function
4-3
Chapter 4 Safety function
Output to
Output allowed Shut off
EDM terminal motor
ED+ ED-
EDM OFF ON
Load 10ms
Wiring
example
Please refer to the signal matrix for the behavior of the STO
state monitor (EDM signal) corresponding to STO state and
internal failure detection state. The EDM signal turns ON
only when both of the STO inputs are given and no internal
failure in the safety paths has been detected.
■Signal matrix
Signal / #1 #2 #3 #4 #5
Item
ST1*1) OFF ON OFF ON *2)
ST2*1) OFF OFF ON ON *2)
Internal No No No No Yes
Failure
detection
EDM ON OFF OFF OFF OFF
Output to Shut Shut Shut Permitted Shut
motor off off off off
4-4
Chapter 4 Safety function
4-5
Chapter 4 Safety function
■Error Display
Item Code Condition*1) Description
STO shut off error [E090] <9> In case of [bd-01] = 02, both ST1 and ST2 are OFF (STO).
STO internal error [E091] <10> Internal failure is detected
STO path 1 error [E092] <11> In case of [bd-04] = 02, and in the status of [P-1b]
STO path 2 error [E093] <12> In case of [bd-04] = 02, and in the status of [P-2b]
*1) Refer to the state transition diagram for the
conditions.
4-6
Chapter 4 Safety function
<1>
00: Non
<2>
<3>
<1> [E090]
05: P-1C 06: P-2C
01: P-1A 02: P-2A
<9>
<4> <7>
<8>
<4> <4>
07: STO
<10>
[E091]
<11> <12>
4-7
Chapter 4 Safety function
(Memo)
4-8
Chapter 5 Planning Installation
Designers and installers (installation supervisor) who All of the cables and signal lines must be protected, routed
design and install safety-related system must have been and fixed appropriately.
trained to have the specialist knowledge of the essential
principles for designing and installing safety-related
systems. 5.4.2 STO input
Designers and those who maintenance safety-related
The two STO inputs (ST1 and ST2) must be appropriately
system must have been trained to understand the cause
separated and protected from each other to avoid mutual
and consequences of the common cause failure (CCF)
interference. (E.g. separated cables, protection, double-
shield cable)
5.3 Installation environment
The length of the cablings connected to STO terminals (ST1,
The product must be installed in a place where ST2, P24S, CMS and STC) must be twenty (20) meters or
environmental condition such as temperature, humidity, shorter.
corrosive gas, dust, vibration, is within the specification of
the product without external environmental controls. Please refer to the wiring examples in Chapter 4 for wirings
Please refer to the User’s Guide of SJ-P1 for the on STO terminals.
requirements and specification for installation as well as
At least one of the measures 1 to 3 below must be adapted
the environmental specification provided in chapter 11 in
to STO input wirings for the protection against grounding
this documentation.
fault:
The SJ-P1 must be installed in an enclosure (cabinet) having
a protection rating of IP54 or higher for protection against 1. Grounding STO signal power line (STC)
conductive dust and contamination.
In case of use of the internal power supply
Ground STC terminal
5-1
Chapter 5 Planning Installation
5.4.4 EMC
The system must only be used in the EMC environment that
it is designed for, or necessary mitigations must be applied.
5-2
Chapter 6 Installation
Chapter 6 Installation 6
6.1 Contents in this chapter 6.3 Wiring example
This chapter describes the items to be taken into The figure below is a wiring example under the following
consideration for installation. conditions.
2. Even after the safety switch has been released, the STO
inputs to ST1/ST2 on SJ-P1 are held by the safety relay.
6-1
Chapter 6 Installation
Wiring Example
Reset
Switch
+24V
A2 P24S
STC
G9SX-GS226-T15-RC CMS
STO output ST1
Safety Switch S14
(E.g. Emergency switch) S24
T21 ST2
SJ-P1
T22
Safety unit
※Compatible standard
(IEC61508, ISO13849) Physical separation or appropriate cable
protection (e.g. double-shielded cable)
M
6-2
Chapter 7 Commissioning
Chapter 7 Commissioning 7
7.1 Contents in this chapter 7.3 Enabling STO function
The STO function is automatically activated when SJ-P1 is
This chapter describes the items to be considered for
energized and established according to this Safety function
commissioning.
Guide and the User’s Guide of the SJ-P1 inverter.
7.2 Considerations
After completion of installation, commission of whole 7.4 Disabling STO function
system must be conducted.
To disable the STO function, please connect the short-
Commissioning of the system must be conducted by only wiring as shown in the figure below. (The same wiring
competent electricians who have sufficient knowledge on condition as the factory default)
functional, machine and process safety.
The system must not be considered safe until all the safety
functionality is verified and validated.
I/O terminal
STO input terminal STO input terminal
*: Depending on the inverter type. Refer to the User’s Guide of the SJ-P1.
7-1
Chapter 7 Commissioning
(Memo)
7-2
Chapter 8 Verification and Validation
8-1
Chapter 8 Verification and Validation
(Memo)
8-2
Chapter 9 Error and Troubleshooting
9.2 Error After generation of this error, the internal safety paths are
held on STO state until powered down.
An error is generated when the internal diagnosis function
What to do
detects a failure in the internal safety paths or when
configured by related parameters. Please refer to the When this error is generated, it is likely that a fault
sections below for the error contents and their exists in the internal safety paths of the SJ-P1.
troubleshooting.
Please ensure to stop the operation of the system and
shut off the power supply, and then conduct the
9.2.1 [E090] STO shut off error functional test.
If this error is not released even after releasing STO This error is generated when inconsistent input state of ST1
inputs to SJ-P1 and then cycling power, please check and ST2 continues for the time specified by the parameter
wirings and signals of the STO inputs. [bd-02].
If this error is generated in an unintentional condition, Refer to Chapter 4 for the details of the conditions
please perform the functional test of the STO function generating [E092] and [E093].
of SJ-P1 to check proper functionality of the STO
function. What to do
If the generation of this error is not desired in the Check the wiring and signal on STO input.
system, it can be disabled by setting [bd-01] to other
Set the parameter [bd-02] suitable for the system.
than “02”.
When adjusting the time, please ensure the specified
time is appropriate for the system.
9-1
Chapter 9 Error and Troubleshooting
9-2
Chapter 10 Maintenance
Chapter 10 Maintenance 10
10.1 Contents in this chapter The procedure of the functional test is as below:
This chapter describes the items related to maintenance.
(1) Check if the EDM terminal (ED+ and ED-) is OFF (open)
10.2 Planning of maintenance when power to SJ-P1 is not supplied.
(State 1)
The maintenance on a safety system is critical importance
for safety reasons. (2) Power up SJ-P1 and set both ST1/ST2 to ON (Allow
operation: short), and then start motor operation.
You must plan and perform maintenance accordingly. (State 5)
The SJ-P1 requires conducting the functional test at least (3) Set both ST1 and ST2 to OFF (STO: open), and check if
once in a year. When planning maintenance of the system, the output to the motor is shut off and EDM terminal
this functional test must be considered. (ED+ and ED-) is ON (Conducted).
(State 2)
10.3 Daily and periodical inspection (4) Set both ST1 and ST2 to ON (Allow operation) and
then restart the motor operation.
The SJ-P1 requires daily and periodical inspection in
(State 5)
addition to the functional test of the STO function. Please
perform inspections as instructed in the User’s Guide of SJ- (5) Set only ST1 to OFF (STO: open) and check if the
P1. output to the motor is shut off and EDM terminal (ED+
and ED-) is OFF. (State 3)
(6) Set both ST1 and ST2 to ON (Allow operation) and
10.4 Periodical functional test then restart motor operation. (State 5)
A periodical STO functional test must be performed at least (7) Set only ST2 to OFF (STO: open) and check if the
once in a year in order to maintain the intended safety output to the motor is shut off and EDM terminal (ED+
performance level of the STO function. and ED-) is OFF. (State 4)
This periodical STO function test is one of the conditions When finding any state not following the signal matrix
for the STO function of SJ-P1 to meet PLe of EN ISO13849- below, there may be a fault in the safety path of the SJ-P1.
1 and SIL 3 of IEC61800-5-2. In that case, stop using the inverter immediately and
contact Hitachi distributor.
In the functional test, it is to be verified that output to the
motor is appropriately shut off and EDM signal is output as
intended (see the signal matrix in the following page)
10-1
Chapter 10 Maintenance
State
State 1 State 2 State 3 State 4 State 5
Main power supply OFF ON ON ON ON
ON(Allow ON(Allow
ST1 ‐ OFF(STO) OFF(STO)
operation) operation)
ON(Allow ON(Allow
ST2 ‐ OFF(STO) OFF(STO)
operation) operation)
Shut-off Shut-off Shut-off Shut-off
Outout to motor Permitted
(Disabled) (Disabled) (Disabled) (Disabled)
EDM OFF(Open) ON(Conducted) OFF(Open) OFF(Open) OFF(Open)
10-2
Chapter 11 Specification・Technical data
11-1
Chapter 11 Specification・Technical data
11-2
Appendix EC Declaration of Conformity
Appendix
EC Declaration of
Conformity (Copy) A
1
<Remark>
・Purpose of this chapter is to provide necessary information related to EC declaration of conformity
・The original version is available separately. Please contact Hitachi distributor for the original.
EC-DECLARATION OF CONFORMITY
We, Hitachi Industrial Equipment Systems Co., Ltd.
1-1 Higashinarashino 7-chome, Narashino-shi, Chiba 275-8611, Japan, declare in our sole responsibility that the
following products conform to all the relevant provisions.
Models Covered:
Model P1, maybe followed by -, followed by 00044, 00080, 00104, 00156, 00228, 00330, 00460, 00600, 00800,
00930,01240, 01530, 01850, 02290 or 02950, maybe followed by -, followed by L, followed by B or F, maybe
followed by C, E or U, maybe followed by F, maybe followed by any letters or numbers.
Model P1, maybe followed by -, followed by 00041, 00054, 00083, 00126, 00175, 00250, 00310, 00400, 00470,
00620, 00770, 00930, 01160, 01470, 01760, 02130, 02520 or 03160 maybe followed by -, followed by H,
followed by B or F, maybe followed by C, E or U, maybe followed by F, maybe followed by any letters or
numbers.
A-1
Contacts:
Hitachi Europe GmbH
Niederkasseler Lohweg 191, 40547 Dusseldorf, Germany.
Phone: +49-211-5283-0
Fax: +49 211 204 9049