Functional Safety Application Guide
Functional Safety Application Guide
vlt-drives.danfoss.com
Contents Functional Safety Application Guide
Contents
1 Introduction 2
1.1 Purpose 2
1.2 Scope 2
1.3 Abbreviations 2
Index 18
1 1 1 Introduction
1.1 Purpose
This manual describes how to implement the safety
functions Safely Limited Speed (SLS) or Safe Speed Range
(SSR) using DOLD UH 6937 frequency monitor without
encoder.
1.2 Scope
This manual is intended for application designers, for
realizing safe speed functions of frequency converters
without encoder feedback, using an external frequency
monitor.
1.3 Abbreviations
PL Performance Level
SIL Safety Integrity Level
SLS Safely Limited Speed
SSR Safe Speed Range
STO Safe Torque Off
The Safely Limited Speed (SLS) function monitors the Monitoring within the given range:
2 2
speed to a set limit value without any encoder feedback, If the frequency is within the given speed range, the STO
see Illustration 2.1. The frequency of the motor is measured signal is not active. If the measured frequency is outside
and compared to the limit value. If the measured value is the given speed range, the relay output triggers the STO
more than the set value, then the safety output relay is function of the frequency converter.
deactivated to trigger the STO function. Monitoring outside the given range:
If the frequency is outside the defined speed range, the
STO signal is not active. If the measured frequency lies
130BF781.10
Speed
inside the limits, the relay output triggers the STO function
of the frequency converter.
In the standard module variant 0, 1 of the following
SLS limit monitoring functions is selected:
Time • Over frequency
• Under frequency
Illustration 2.1 SLS Function
• Inside range
• Outside range
The Safe Speed Range (SSR) function monitors the speed The variant 1 module has extra selection inputs for
within a given range or outside a given range. See selecting 4 frequency modes during the operation.
Illustration 2.2.
NOTICE
If the frequency converter does not have an integrated
130BF782.10
Time
Terminals E1a, E1b, E2L, E2H, E3L, and E3H form the
Chapter 3.2 Safety Function Operation and Timing includes
measuring input. For low voltages (AC 8–280 V), the
the SLS operation and timing.
measuring voltage is connected to E1a–E2L and E1b–E3L.
For higher voltages (AC 16–600 V), the measuring voltage
is connected to E1a–E2H and E1b–E3H.
3 3
130BF784.10
+FIELD
PE/GND L1 L2 L3 24 V DC 0 V DC
1 3 5
-FC1
_F
PE/GND
Ensure that the STO cables are shielded if they
-TA1 are longer than 20 m (65.6 ft) or outside the cabinet.
95(PE)
VLT FC 280
91(L1)
92(L2)
93(L3)
Frequency 12
converter
37 1
-FC31
38 2
55 13
99(PE)
98(W)
97(V)
96(U)
-SF8 E
RESET 14
PE/GND -U2
U E1a 13 14 23 24 A1+ A2 RES T1 T2 RF
E2L
V E2H
UH6937
U E1b
E3L
GND 38 48
W E3H
PE/GND
+FIELD
BN BK GY
-WD1
SH
U1 V1 W1
NSGAFÖU 1.8/3 kV
-MA1 M BK
3~
PE/GND min. 2.5 mm2 (14 AWG)
PE/GND
130BF789.10
+FIELD
PE/GND L1 L2 L3 24 V DC 0 V DC
1 3 5
3 3 -FC1
2 4 6
NSGAFÖU 1.8/3 kV
BK
min. 2.5 mm2 (14 AWG)
-TA1 L1 L2 L3
NX Series
Frequency
Converter
1 1 1
-FC33 -FC32 -FC31 13
2 2 2
-SF8
PE/GND U V W RESET 14
PE/GND -U2
U E1a 13 23 A1+ A2 RES T1 T2 RF
E2L
V E2H
UH6937
U E1b
E3L
GND 14 24 38 48
W E3H
PE/GND
1 2 3 4
-WGB1
SH
PE/GND
+FIELD
-WD1 BN BK GY
SH 28 29
1 2 3 4 21 22 23 25 26
U1 V1 W1 SD1+ SD1- SD2+ SD2- RO1 NC
RO1 C
RO1 NO RO2 C RO2 NO TI1+ TI1-
-MA1 M ON UNCUT
3~ -AG2 X10 X12
130BF790 .10
+FIELD
PE/GND L1 L2 L3 24 V DC 0 V DC
1 3 5
-FC1
91(L1)
92(L2)
93(L3)
98(W)
-SF8
96(U)
97(V)
RESET 14
PE/GND
U -U2 E1a 13 14 23 24 A1+ A2 RES T1 T2 RF
E2L
V E2H UH6937
U E1b
E3L
38 48
W E3H GND
PE/GND
+FIELD
-WD1 BN BK GY
SH NSGAFÖU 1.8/3 kV
U1 V1 W1 BK
M
-MA1 3~ min. 2.5 mm² (14 AWG)
PE/GND
PE/GND
130BF791.10
+FIELD
PE/GND L1 L2 L3 24 V DC 0 V DC
1 3 5
3 3 -FC1
2 4 6
NSGAFÖU 1.8/3 kV
BK
-TA1 min. 2.5mm2 (14 AWG)
L1 L2 L3
VACON 100
frequency
converter
1 1 1
-FC33 -FC32 -FC31 13
2 2 2
-SF8
PE/GND U V W RESET 14
PE/GND -U2
U E1a 13 23 A1+ A2 RES T1 T2 RF
E2L
V E2H
UH6937
U E1b
E3L
GND 14 24 38 48
E3H
PE/GND
1 2 3 4
-WGB1
SH
PE/GND
+FIELD
-WD1 BN BK GY -AB1 1 2 3 4
STO1+ STO1- STO2+ STO2-
25 26
NO
28
TI1+
29
TI1-
SH CO
SLOT C, D, E RO1 TI1
U1 V1 W1 Contact Thermistor Input
OPT-BJ
-MA1 M STO board not activated
3~ Supervision ON (default) X23 X10
Supervision OFF STO board activated (default)
PE/GND Short circuit supervision STO board activation
PE/GND
Illustration 3.5 shows the LG 5130 Circuit Diagram with noise filtering between the 3 phases of the frequency converter and
the frequency monitor UH 6937.
130BF783.10
PE L1 L2 L3
3 3
Motor Protection
FU
L1 L1’ E1a
LG5130
L2 L2’ E2H
UH6937
L1 L1’ E1b
LG5130
L3 L3’ E3H
M
3~
130BF788.10
E2H E2L E2a E2H E2L E2a
A1 A1
+ A2 GND E3H E3L E1b A2 GND E3H E3L E1b
+
3 3
13 23 13 23
K1 K1
K2 K2
14 24 14 24
T1 RES T2 RF T1 RES T2 RF
A1 A
13 14 23 24 GND 38 48 13 14 23 24 + GND 38 48
M10823_d M10823_d
UH6937 UH6937/__1
3.2 Safety Function Operation and Timing The module UH 6937 always monitors the configured
frequency limits. The frequency module does not have its
The safe speed monitoring has to be configured for the own safe inputs, therefore a third-party functional safety
speed limits in the frequency converters applications. The system, for example a fail-safe PLC system, is used. It
customer is responsible for defining the speed limits on activates the safe function when a safe function is
the risk assessment. The commissioning test report is made demanded. This means that more safety logic can be
available for the final assessment and for future references. prepared based on the status of the frequency module 3 3
relays in the PLC. For example, the PLC logic controls the
3.2.1 Initial Conditions access to the dangerous zone via its output signal (door
control). The SLS output (relays) is connected to the fail-
If the safe speed limit monitor is configured without the safe PLC’s safety input. The access is allowed as long as the
start-up delay and the RF feedback circuit is closed, it is frequency is below the SLS limit. If the speed limit is
active immediately after the power-on. exceeded, the STO of the frequency converter is
immediately activated via the fail-safe PLC output to bring
the system to a safe state.
3.2.2 Fault Handling
The input frequency is compared to the setting value. As
When faults are detected on or in the device, they are
the device measures the cycle duration, the fastest
indicated with a message in the display. If the fault
frequency measurement is possible. Should the overfre-
requires a reset of the device, the alarm and the associated
quency function be set, the output relay switches to the
diagnostic message has to be acknowledged first. Press the
alarm mode when the set response parameter value
left key for approximately 3 s to initiate a reset of the
exceeds the defined value in the alarm-delay function (tV).
device.
Should the frequency decrease to a value below the
response parameter, minus the set hysteresis, the output
NOTICE relay is activated after the expiry of the reset delay time
If a system failure is detected again after restart, the period(tF). It then returns to its preset allowed supervisory
device must be replaced and sent back to the state. The underfrequency function means that the output
manufacturer. relay switches to the alarm mode when the set response
parameter value drops below the set alarm-delay
3.2.3 SLS Operation function(tV) time period. When the frequency returns to
the range governed by the response parameter, plus the
Typically, the SLS safety function is used for safe speed set hysteresis, the output relay returns to the preset
monitoring according to a defined speed limit. In this case, allowed state after the expiry of the reset-delay time
the SLS function defines the speed limit where it is period(tF).
considered safe for personal interaction with the machine.
As long as the frequency of the frequency converter is 3.2.4 SSR operation
within the defined limit, the STO function is not active.
When the output frequency goes beyond the limit value, The SSR function is used for speed monitoring within or
STO is immediately activated so the motor coasts and outside of a defined speed range.
comes to a standstill. This coasting time must be
considered before allowing the access to the dangerous In the internal window function mode, the output relay
zone. switches to the alarm setting when the frequency exceeds
the preset allowed range of both the upper and lower
The safe output on the frequency monitor UH 6937 is response parameters, minus and/or plus the preset
active and the output relays remain closed, as long as the hysteresis values (upper response parameter minus and/or
actual speed is lower than the safe speed limit parameter the lower response parameter plus the relative hysteresis
(SLS limit). values). The output relay again switches back to the preset
allowed range after the expiry of the reset-delay time
If the actual speed exceeds the safe speed limit parameter period (tF).
(SLS limit), speed output relays are opened, and the safe
output signal is removed. In the external window function mode, the monitoring
function acts inversely to the internal window function.
If an internal fault occurs, the SLS safety function can be
configured for automatic reset. If the function is configured Should the manual reset function be activated, the output
for a manual reset, the RESET input should be provided for relay remains in alarm mode when the frequency returns
normal operation after removing the limit violations. to the preset allowed range. A reset of the saved
parameter is possible when the reset input is activated or the output relays remain at the preset allowed setting. The
the auxiliary voltage is shut down. start-up delay function can, for example, override an alarm
message during the start-up stage of a generator or
When a start-up delay time period (tA) is set, the set start- electric motor. Should the feedback circuit not be closed
up delay time period expires initially when the auxiliary after a reset (in the manual reset mode), the equipment
voltage of the equipment is switched on and the “RF” goes into a safe error state.
3 3 feedback circuit is closed. The start-up delay time period
also expires after a reset of the manual reset mode. During The frequency monitoring operation is shown in
this time period, a frequency evaluation is disabled and Illustration 3.7.
130BF785.10
n
Overfrequency
} Threshold
Hysteresis
}
Hysteresis
Underfrequency
Threshold
U
UH
(A1/A2)
Alarm memory
Monitoring function tA tV tF tV tF
“Overfrequency”
Output relay
K1/K2
Monitoring function tA tV tF
“Underfrequency”
tA tV tF tV tF tF
Monitoring function
“Inside range”
M11332
tA = Start-up delay, tV = Alarm delay, t F = Response delay
3.3 Parameters and Configuration Follow the installation guide from the manufacturer for a
detailed description. Table 3.1 shows a default configu-
The equipment can be configured via the display and the ration of the frequency monitor.
setting keys on the display. See Illustration 3.8.
The safe speed limit parameter (SLS limit) is configured to
To enter the parameterization-mode on the device, the upper limit parameter of frequency mode 1. The lower
follow these steps: limit is configured to 0.0 Hz. 3 3
1. Press and hold the [OK] key.
2. Press the [Reset] key.
3. A display test follows and has to be
acknowledged using the [OK] key, when it was
successful.
4. It is now possible to change the parameterization.
Before the device adopts changed parameters,
they must be confirmed once more for safety
reasons.
130BF786.10
E
D S
safemaster
DOLO UH6937
ON K1/K2 ERR t
actual frequency
100Hz
3 2
4 1
13 23 +
K1
f
K2
14 24 38
1 OK
2 ▲
3 ▼
4 Reset
1. Parameterization
1.1 Monitoring function
Overfrequency X
Underfrequency –
Inside range –
3 3 1.2 Limits
Outside range –
Frequency mode 1
Upper limit 400.0 Hz
Lower limit 200.0 Hz
Frequency mode 2
Upper limit 400.0 Hz
Lower limit 200.0 Hz
Frequency mode 3
Upper limit 400.0 Hz
Lower limit 200.0 Hz
Frequency mode 4
Upper limit 400.0 Hz
Lower limit 200.0 Hz
1.3 Hysteresis
5%
1.4 Time Delay
Start-up delay 0.0 s
Response Delay 0.0 s
Alarm delay 0.1 s
Changeover bridging 0.0 s
1.5 Alarm memory
Alarm memory X
Automatic reset –
1.6 Muting function
Activate –
Deactivate X
2. Display settings
2.1 Languages
English X
Deutsch –
Francais –
2.2 Contrast
50 %
2.3 Backlight
OFF –
10 s X
1 min –
5 min –
2.4 Status indicator
Manual X
10 s –
1 min –
5 min –
3. Factory settings
Parameters
Display settings
Parameter + display settings
4. Change tracking
5. About UH 6937
Activate
3 3
Table 3.1 Frequency Monitor Configuration
4 4
130BF787.10
UH 6937 .02 _ _ /_0_ DC 24 V
Nominal voltage
0 = Standard
1 = with different frequency mode
and analogue output
Type o terminals
PS (plug-in screw)
pluggable terminal blocks,
with screw terminals
Contacts
Type
The values for the fail-safe PLC must be at least the shown
5 5
values in Table 5.3.
Index
D
DIN EN/ISO 13849: 2006..................................................................... 17
DOLD LG 5130.......................................................................................... 4
DOLD UH 6937......................................................................................... 4
E
EN 61800-5-2.......................................................................................... 17
EN 62061.................................................................................................. 17
External window function................................................................. 11
F
Fail-safe PLC............................................................................................... 4
Fault handling........................................................................................ 11
Frequency monitor configuration.................................................. 13
I
IEC 61508................................................................................................. 17
Inside range.............................................................................................. 3
Internal window function.................................................................. 11
O
Outside range........................................................................................... 3
Overfrequency......................................................................................... 3
P
PFH............................................................................................................. 17
S
Safe Torque Off......................................................................................... 3
SIL calculation........................................................................................ 17
SLS operation......................................................................................... 11
SSR operation......................................................................................... 11
STO............................................................................................................... 3
see also Safe Torque Off
T
Terminal 12................................................................................................ 4
Terminal 13................................................................................................ 4
Terminal 20................................................................................................ 4
Terminal description.............................................................................. 5
Terminals E1a, E1b, E2L, E2H, E3L, E3H............................................ 4
U
Underfrequency...................................................................................... 3
Danfoss A/S
Ulsnaes 1
DK-6300 Graasten
vlt-drives.danfoss.com
*MN91A102*
130R0800 MN91A102 04/2017