Implementation of safety requirements from applicable standards

The safety-related function block has been developed according to the safety requirements (from applicable standards) listed in this section. All other requirements from these standards must be observed when implementing the safety-related function.

This section describes either how the function block meets the requirements of the standards or what measures need to be taken to meet the requirements of the standards.

Standards

Context/Requirement

Implementation

EN 60204

Enabling device

The function block evaluates the signals of a three-stage, manually actuated enable switch.

  • Switching stage 1: Off function for the switch (manual control not actuated)

  • Switching stage 2: Enabling function (manual control actuated as far as central position)

  • Switching stage 3: Off function for the switch (manual control actuated past the central position)

The enable switch you use must meet the specified requirements (refer also to "Requirements to the enable switch" in the topic titled "Functional description").

Only when a signal change from switching stage 1 to switching stage 2 is detected at inputs S_EnableSwitchCh1 and S_EnableSwitchCh2, the S_EnableSwitchOut output switches from SAFEFALSE to SAFETRUE and retain this state until switching stage 2 is no longer detected.

EN 60204

Suspension of safeguarding

You must select the corresponding operating mode (limitation of the speed of motion, kinetic energy or range of motion) outside of the SF_EnableSwitch function block.

The state of the selected operating mode is evaluated by the function block at input S_SafetyActive.

Only when the state SAFETRUE is signaled at the S_SafetyActive input, the S_EnableSwitchOut output can switch to SAFETRUE depending on the signal combination at the inputs S_EnableSwitchCh1 and S_EnableSwitchCh2.

EN ISO 13849-1

Manual reset device

The Reset input supports the function of the manual reset device.

NOTE:

Resetting does not occur with a negative (falling) edge, as specified by the EN ISO 13849-1 standard, but with a positive (rising) edge.

EN ISO 12100-2

Start-up after failure of supply voltage/spontaneous restart

The function block supports a restart inhibit after a valid signal combination has returned at inputs S_EnableSwitchCh1 and S_EnableSwitchCh2, i.e., if S_EnableSwitchCh1 and S_EnableSwitchCh2 show the signal combination for switching stage 1.

To remove an active restart inhibit, a signal change from FALSE to TRUE is required at the Reset input (positive edge).

You are responsible for planning and implementing the restart behavior according to your risk analysis.

To prevent an unintended restart, you may need to perform an additional function start once the safety-related function has been reset. This will depend on both the results of the risk analysis and the signal path of the reset signal.

A SAFETRUE signal at the S_EnableSwitchOut output alone must not be used to initiate the start of the machine. An additional intentional start command, which is independent of the enable switch(es), is required for this. Every person inside the zone of operation must carry an enable switch, which can be used to help prevent a machine state change.

Refer to the hazard message below this table.

EN ISO 13849-1

Category B to 4

Single-channel or two-channel connection must be established depending on the category.

NOTE:

Cross-circuit monitoring is not performed by the function block. It is your responsibility to perform this monitoring function outside of this function block in the safety-related control system.

EN 60204

Stop functions

The safety-related function block (S_EnableSwitchOut enable signal) executes stop category 0.

 WARNING

NON-CONFORMANCE TO SAFETY FUNCTION REQUIREMENTS

  • Verify that an additional intentional start command, which is independent of the enable switch (i.e, independent of a SAFETRUE signal at the S_EnableSwitchOut output), is used to start the operation of the machine.

  • Ensure that every person inside the zone of operation carries an enable switch.

Failure to follow these instructions can result in death, serious injury, or equipment damage.