Transcription of Functional Safety Application Guide - Danfoss
1 ENGINEERING TOMORROWF unctional Safety Application GuideEncoder-less Safety Functions SLS, SSR using DOLD FrequencyMonitorVACON and VLT Abbreviations22 Safety Functions SLS and SSR33 SLS and SSR Circuit Safety Function Operation and Initial Fault SLS SSR Parameters and Configuration134 Ordering Data for DOLD Frequency Monitor165 Functional Safety -related SIL Calculation17 Index18 ContentsFunctional Safety Application GuideMN91A102 Danfoss A/S 04/2017 All rights PurposeThis manual describes how to implement the safetyfunctions Safely Limited Speed (SLS) or Safe Speed Range(SSR) using DOLD UH 6937 frequency monitor DOLD module can be used with the followingproducts: VLT HVAC Drive FC 102 VLT Refrigeration Drive FC 103 VLT AQUA Drive FC 202 VLT Midi Drive FC 280 VLT AutomationDrive FC 301 VLT AutomationDrive FC 302 VACON 100 Industrial VACON 100 Flow VACON NXP Liquid Cooled VACON NXP System Drive VACON NXP Air Cooled VACON NXP Common DC Bus VACON NXP Liquid Cooled Enclosed Drive VACON NXP Liquid Cooled Common DC ScopeThis manual is intended for Application designers, forrealizing safe speed functions of frequency converterswithout encoder feedback, using an external AbbreviationsPLPerformance LevelSILS afety Integrity LevelSLSS afely Limited SpeedSSRSafe Speed RangeSTOSafe Torque OffTable List of AbbreviationsIntroductionEncoder-less Safety Functions SLS, SSR using DOLD Frequency Monitor2 Danfoss A/S 04/2017 All rights Functions SLS and SSRThe Safely Limited Speed (SLS)
2 Function monitors thespeed to a set limit value without any encoder feedback,see Illustration The frequency of the motor is measuredand compared to the limit value. If the measured value ismore than the set value, then the Safety output relay isdeactivated to trigger the STO SLS FunctionThe Safe Speed Range (SSR) function monitors the speedwithin a given range or outside a given range. SeeIllustration upper limitSSR lower SSR FunctionMonitoring within the given range:If the frequency is within the given speed range, the STOsignal is not active. If the measured frequency is outsidethe given speed range, the relay output triggers the STOfunction of the frequency outside the given range:If the frequency is outside the defined speed range, theSTO signal is not active. If the measured frequency liesinside the limits, the relay output triggers the STO functionof the frequency the standard module variant 0, 1 of the followingmonitoring functions is selected: Over frequency Under frequency Inside range Outside rangeThe variant 1 module has extra selection inputs forselecting 4 frequency modes during the the frequency converter does not have an integratedSTO function, the relay outputs can be used to activatethe motor contactors to cut off the power to the Functions SLS and Safety Application GuideMN91A102 Danfoss A/S 04/2017 All rights and SSR ImplementationThe SLS Safety function implementation is based on theSTO function and the following Safety -related components: Frequency monitor (3rd party DOLD UH 6937)The UH 6937 frequency module does not havesafe inputs to activate and deactivate the safetyfunctions.
3 In variant 0, the module alwaysmonitors the frequency. The monitoring can onlybe muted by selecting the parameter in thedisplay. In variant 1, there are 4 digital safe inputsavailable to select different frequency modes, and1 of the combinations is the muting function. Noise suppression filter for measuring relays (3rdparty DOLD LG 5130), optionalThese filters are only required if there ismeasurement errors after complete installation. Third-party Functional Safety system or fail-safePLC ( SIL2), optionalA fail-safe PLC is required to implement the safetylogic based on the status of the relay outputs ofa frequency module. One of the use cases is, thatthe relay output status is ignored as long as thesafety door is locked for SLS speed. Once thedoor is opened, the Safety relay output is used toactivate the STO of the frequency converter forspeed limit circuit example in chapter Circuit Diagram showsthe DOLD UH 6937 used with a Danfoss frequencyconverter FC-series or VACON auxiliary voltage 24 V is connected to terminals A1 24 V PELV or SELV supply can be used.
4 If no additionaldevices are supplied via terminal 12 or 13 (+24 V), A1 canbe connected to terminal 12 or 13. A2 can be connectedto terminal 20 (0 V).Terminals E1a, E1b, E2L, E2H, E3L, and E3H form themeasuring input. For low voltages (AC 8 280 V), themeasuring voltage is connected to E1a E2L and E1b higher voltages (AC 16 600 V), the measuring voltageis connected to E1a E2H and E1b monitoring single-phase AC voltage, the terminalsE1a E2L or E1a E2H should be connected directly to thefrequency converter. The terminals E1b E3L or E1b E3 Hshould be connected directly to the motor wires in separate cables with spacing inbetween have to be used for each of the frequencyinputs. When monitoring 3-phase AC voltages, theseterminals have to be wired directly to the motorconnection OF DEATH AND SERIOUS INJURYIf external forces act on the motor, for example in caseof vertical axis (suspended loads) the motor must beequipped with extra measures for fall protection.
5 Forexample, install extra mechanical noise filter (LG 5130) has 4 inductances connected inseries in each path for the 3 phases (input L1/L2/L3). Thisprovides broad band filtering up to high frequencies. If thePE is connected, a Y-capacitor connected to PE is activatedand provides increased filtering (T-filter).The noise filter is connected via its input terminalsL1/L2/L3 to the frequency converter output and thefrequency monitor device to the filter outputs L1 /L2 /L3 .By connecting the noise filter between the frequencyconverter and the measuring frequency monitor device,the current flowing via the coupling capacitances isreduced. The reduction happens because the filterelements create a rising impedance with a risingfrequency. This prevents disturbance or damage on theconnected device. Protection as shown in Illustration is not mandatory to connect the PE to the frequencymonitor device terminals, but it increases the filter Safety Function Operation and Timing includesthe SLS operation and and SSR ImplementationEncoder-less Safety Functions SLS, SSR using DOLD Frequency Monitor4 Danfoss A/S 04/2017 All rights Circuit DiagramIllustration shows the UH 6937 Circuit diagram.
6 The relay contacts 13 14 and 23 24 can be used as STO input to thefrequency the jumper wire between control terminals 12, 37, 38 in the frequency +FIELD+FIELDE nsure that the STO cables are shielded if theyare longer than 20 m ( ft) or outside the 1 VLT FC 280 FrequencyconverterPE/GNDPE/GNDPE/GNDPE/G NDPE/GNDGNDPE/GNDL1L2L3F-FC1_95(PE)91(L1 )92(L2)93(L3)98(W)97(V)96(U)99(PE)123738 55U-U2 VWUNSGAF U kVBKmin. mm2 (14 AWG)-WD1-MA1M3~BNBKGYU1V1W1E1aE2LE2HE1bE 3LE3H131314142324A1+A2 REST1T2RF4838UH6937E-FC311224 V DC0 V FC 280 and UH 6937 Wiring DiagramSLS and SSR ImplementationFunctional Safety Application GuideMN91A102 Danfoss A/S 04/2017 All rights +FIELDL1L2L3123456-FC1PE/GND-TA1NX SeriesFrequencyConverterL1L2L3U V WPE/ GNDUVUPE/GND-MA1-WD1PE/GNDPE/GND3~MSHU1 BNW1V1 BKGY-U2E1aE2LE2HE1bE3LE3 HGND14241323A1+A2 REST1T2RF3848PE/GND-WGB1 SHPE/GND14322SD1-1SD1+23RO1 NO22RO1 C21RO1 NC43SD2+25RO2 C26RO2 NO29TI1-28TI1+-AG2 OPTAFIFS+2 XRO+PTCSLOT BX10 ONX12 UNCUTT hermistorshort circuitsupervision12-FC3112-FC3212-FC331 314-SF8 RESET24 V DC0 V DCUH6937+ NSGAF U kVBKmin.
7 Mm2 (14 AWG)WIllustration NX Drive, OPT-AF, and UH 6937 Wiring DiagramSLS and SSR ImplementationEncoder-less Safety Functions SLS, SSR using DOLD Frequency Monitor6 Danfoss A/S 04/2017 All rights short-circuit protected cable(if not inside an IP54 installation cabinet)Remove the jumper wire betweencontrol terminals 37 and 12 or 13in the frequency ( L1)92( L2)93( L3)96(U)97( V)98(W)99( PE)-TA1 VLT FC 302frequency converterU1PE/GND-MA13~MPE/GND-WD1 BNSH-U2E1aE2LE2HE1bE3LE3 HUVUW1323A1+A212-FC 31T11314-SF8 RESETT2RF3848 GNDPE/GND+FIELD+FIELDPE/GNDPE/GND95( PE)PE/GND142412 or 1337L1L2L324 V DC0 V DCGYBKV1 W1130BF790 .10 NSGAF U kVBKmin. mm (14 AWG)Illustration FC 302 and UH 6937 Wiring DiagramSLS and SSR ImplementationFunctional Safety Application GuideMN91A102 Danfoss A/S 04/2017 All rights +FIELDL1L2L3123456-FC1PE/GND-TA1 VACON 100frequencyconverterL1L2L3U V WPE/ GNDUVUPE/GND-MA1-WD1PE/GNDPE/GND3~MSHU1 BNW1V1 BKGY-U2E1aE2LE2HE1bE3LE3 HGND14241323A1+A2 REST1T2RF3848PE/GND-WGB1 SHPE/GND143212-FC3112-FC3212-FC331314-SF 8 RESET24 V DC0 V DCUH6937+FIELDS upervision ON ( default)Short cir cuit supervisionSupervision OFFX23 STO b oard n ot activatedSTO board activationX10 STO b oard activated ( default)-AB1 SLOT C, D, EOPT-BJContactRO1 Thermistor InputTI11 STO1+2 STO1-3 STO2+4 STO2-25CO26NO29TI1-28TI1+ U kVBKmin.
8 (14 AWG)Illustration VACON 100, OPT-BJ, and UH 6937 Wiring DiagramSLS and SSR ImplementationEncoder-less Safety Functions SLS, SSR using DOLD Frequency Monitor8 Danfoss A/S 04/2017 All rights shows the LG 5130 Circuit Diagram with noise filtering between the 3 phases of the frequency converter andthe frequency monitor UH ProtectionFUL1L2L1L3L1 L2 L1 L3 E1aE2HE1bE3 HUH6937LG5130LG5130M3~ LG 5130 Circuit DiagramSLS and SSR ImplementationFunctional Safety Application GuideMN91A102 Danfoss A/S 04/2017 All rights +A1A2 GNDE2HE2aE2LE3HE3LE1b+1423T1 RFRES38 GND4813T2241423T1 RFRES38 GND4813T224A1+ASW1SW2SW3SW4M10823_dM1082 3_dUH6937UH6937 Terminal designationSignal designationA1+24 V DCA20 VE1a, E1b, E2L, E2H, E3L, E3 HFrequency measuring inputsGNDR eference potential for semiconductor monitoring output and control outputs13, 14, 23, 24 Forcibly guided NO contacts for release circuit38, 48 Semiconductor-monitoring outputT1, T2 Control outputRES, RF, SW1, SW2, SW3, SW4 Control inputA+, A GNDA nalog outputIllustration Terminals DescriptionSLS and SSR ImplementationEncoder-less Safety Functions SLS, SSR using DOLD Frequency Monitor10 Danfoss A/S 04/2017 All rights Safety Function Operation and TimingThe safe speed monitoring has to be configured for thespeed limits in the frequency converters applications.
9 Thecustomer is responsible for defining the speed limits onthe risk assessment. The commissioning test report is madeavailable for the final assessment and for future ConditionsIf the safe speed limit monitor is configured without thestart-up delay and the RF feedback circuit is closed, it isactive immediately after the HandlingWhen faults are detected on or in the device, they areindicated with a message in the display. If the faultrequires a reset of the device, the alarm and the associateddiagnostic message has to be acknowledged first. Press theleft key for approximately 3 s to initiate a reset of a system failure is detected again after restart, thedevice must be replaced and sent back to OperationTypically, the SLS Safety function is used for safe speedmonitoring according to a defined speed limit. In this case,the SLS function defines the speed limit where it isconsidered safe for personal interaction with the long as the frequency of the frequency converter iswithin the defined limit, the STO function is not the output frequency goes beyond the limit value,STO is immediately activated so the motor coasts andcomes to a standstill.
10 This coasting time must beconsidered before allowing the access to the safe output on the frequency monitor UH 6937 isactive and the output relays remain closed, as long as theactual speed is lower than the safe speed limit parameter(SLS limit).If the actual speed exceeds the safe speed limit parameter(SLS limit), speed output relays are opened, and the safeoutput signal is an internal fault occurs, the SLS Safety function can beconfigured for automatic reset. If the function is configuredfor a manual reset, the RESET input should be provided fornormal operation after removing the limit module UH 6937 always monitors the configuredfrequency limits. The frequency module does not have itsown safe inputs, therefore a third-party Functional safetysystem, for example a fail-safe PLC system, is used. Itactivates the safe function when a safe function isdemanded. This means that more Safety logic can beprepared based on the status of the frequency modulerelays in the PLC.