Professional Documents
Culture Documents
Door Monitoring - Safety-At124 - En-P
Door Monitoring - Safety-At124 - En-P
Door Monitoring - Safety-At124 - En-P
IMPORTANT Identifies information that is critical for successful application and understanding
of the product.
BURN HAZARD: Labels may be on or inside the equipment, for example, a drive
or motor, to alert people that surfaces may reach dangerous temperatures.
ARC FLASH HAZARD: Labels may be on or inside the equipment, for example, a
motor control center, to alert people to potential Arc Flash. Arc Flash will cause
severe injury or death. Wear proper Personal Protective Equipment (PPE). Follow
ALL Regulatory requirements for safe work practices and for PPE.
Table of Contents
Important User Information ..........................................................................................2
General Safety Information .........................................................................................3
Introduction ..................................................................................................................3
Safety Function Realization: Risk Assessment ........................................................... 4
Door Monitoring Safety Function ................................................................................. 4
Safety Function Requirements ....................................................................................4
Functional Safety Description ......................................................................................5
Bill of Material ..............................................................................................................5
Setup and Wiring .........................................................................................................5
Configuration ...............................................................................................................7
Programming .............................................................................................................14
Calculation of the Performance Level ....................................................................... 16
Verification and Validation Plan .................................................................................19
Additional Resources ................................................................................................24
Introduction
This safety function application technique explains how to wire, configure, and
program a Compact GuardLogix® controller and POINT Guard I/O™ module to
monitor a Trojan™ 5 tongue switch mounted on a door. If the door is opened or a
fault is detected in the monitoring circuit, the GuardLogix controller de-energizes the
final control devices, in this case, the safe torque-off inputs on the PowerFlex® 525
drive.
This example uses a Compact GuardLogix controller, but is applicable to any
GuardLogix® controller. This example uses a Trojan 5 tongue switch, but is
applicable to any dual contact device with at least two N.C. contacts. The SISTEMA
software calculations shown later in this document must be recalculated if different
products are used.
24V DC
24V DC COMMON
Configuration
The Compact GuardLogix controller is configured by using RSLogix™ 5000 software,
version 17 or later. First, you must create a new project and add the I/O modules,
then configure the I/O modules for the correct input and output types. A detailed
description of each step is beyond the scope of this document. Knowledge of the
RSLogix programming environment is assumed.
Configure the Controller and Add I/O Modules
1. In RSLogix 5000 software, create a new project.
2. Choose a controller.
a. From the Type pull-down menu, choose 1768-L43S CompactLogix 5343S
Safety Controller.
b. From the Revision pull-down menu, choose the appropriate revision for
the controller.
c. In the Name box, type an appropriate name for the controller.
d. Click OK.
3. In the Controller Organizer, right-click 1768 Bus and choose New Module.
9. Click Change.
11. In the Controller Organizer, right-click PointIO 3 Slot Chassis and choose
New Module.
13. In the New Module dialog box, name the device IB8S and click Change.
16. Repeat steps 11…15 to add the 1734-OB8S safety output module with these
steps:
a. Name the module OB8S.
b. Set the module to slot 2.
c. Set the Input Status to Combined Status-Readback-Power.
4. Click OK.
5. In the Controller Organizer, right-click the 1734-OB8S module and choose
Properties.
7. Click OK.
Programming
The Dual Channel Input Stop with Test (DCST) instruction monitors dual-input safety
devices whose main function is to stop a machine safely, for example, a safety gate.
When a test function is requested, programatically or manually, the operation of the
machine is halted until a proper cycle of the safety gate occurs.
The DCST instruction monitors dual-input channels for consistency (Equivalent –
Active High) and detects and traps faults when the inconsistency is detected for
longer than the configured Discrepancy Time (ms).
The automatic restart type lets the DCST output (O1) reset automatically after a
demand. The manual action typically required for safety is provided in rung 1 to reset
the safety output enable.
Input status typically represents the channel status of the two input channels. In this
example, the Combined Input Status bit goes low (0) if any of the eight input
channels on the 1734-IB8S has a fault.
In this example, the DCST reset acts as a fault reset. Even when configured for
automatic restart, a reset is required to recover from a fault.
The output (O1) of the DCST is used as a safety interlock in the seal-in rung to drive
the output enable tag. If the DCS output drops out, so does the output enable, and it
remains off until a manual reset action is carried out.
The Configurable Redundant Output (CROUT) instruction controls and monitors
redundant outputs. Since there is no feedback from the PowerFlex 525 drive, the
feedback in the instruction is the output tag of the CROUT instruction. The CROUT
instruction is being used only for the input and output status functionality.
The two output tags from the CROUT instruction are used to drive outputs 0 and 1
on the 1734-OB8S module. These two outputs control the PowerFlex 525 safe
torque-off (STO) inputs.
Trojan 5
Channel A
Trojan 5 PowerFlex
1734-IB8S 1768-L43S 1734-OB8S 525
(FE)
STO
Trojan 5
Channel B
Calculations are based on one operation of the safety guard door per hour or 8760
operations of the safety function per year.
The data given, including fault tolerance is based on the use of fault exclusion at
some single-fault mechanical failure points, for example: actuator, cam, contact
plunger, lock mechanism. Because of the inherent strength and simplicity of those
parts, they have an extremely low likelihood of failure and those faults are excluded
in accordance with EN ISO 13849-2: 2008, Clause A.5.2, Table A4. In some
configurations, the use of fault exclusion can limit the maximum PL to PLd (see
EN ISO TR 23849 for details).
The PL has been limited to PLd because of the fault exclusion. Therefore, the
MTTFd, DC, and CCF for the door switch are marked by SISTEMA as being not
relevant.
The measures against Common Cause Failure (CCF) are quantified using the
scoring process outlined in Annex F of ISO 13849-1. For the purposes of the PL
calculation, the required score of 65 needed to fulfill the CCF requirement is
considered to be met. The complete CCF scoring process must be done when
implementing this example.
GuardLogix Door Monitoring Safety Function Verification and Validation Checklist (continued)
Additional Resources
These publications contain additional information concerning related products from
Rockwell Automation.
Resource Description
Compact GuardLogix Controllers Provides information on configuring, operating, and
User Manual, publication maintaining Compact GuardLogix controllers.
1768-UM002
POINT Guard I/O Safety Modules Provides information on installing, configuring, and
Installation and User Manual, operating POINT Guard I/O modules.
publication 1734-UM013
GuardLogix Controller Systems Contains detailed requirements for achieving and
Safety Reference Manual, maintaining safety ratings with the GuardLogix
publication 1756-RM093 controller system.
GuardLogix 5570 Controller Contains detailed requirements for achieving and
Systems Safety Reference maintaining safety ratings with the GuardLogix 5570
Manual, publication 1756-RM099 controller system in Studio 5000® projects.
GuardLogix Safety Application Provides detailed information on the GuardLogix
Instruction Set Reference Manual, Safety Application Instruction Set.
publication 1756-RM095
PowerFlex 520-Series Adjustable Provides information on installing, programming, and
Frequency AC Drive User Manual, operating PowerFlex 525 drives.
publication 520-UM001
Safety Accelerator Toolkit for Provides a step-by-step guide to using the design,
GuardLogix Systems Quick Start programming, and diagnostic tolls in the Safety
Guide, publication IASIMP-QS005 Accelerator Toolkit.
Safety Products Catalog, Provides an overview of products, product
publication S117-CA001 specifications, and application examples.