Professional Documents
Culture Documents
Safety At122 en P
Safety At122 en P
IMPORTANT Identifies information that is critical for successful application and understanding
of the product.
BURN HAZARD: Labels may be on or inside the equipment, for example, a drive
or motor, to alert people that surfaces may reach dangerous temperatures.
ARC FLASH HAZARD: Labels may be on or inside the equipment, for example, a
motor control center, to alert people to potential Arc Flash. Arc Flash will cause
severe injury or death. Wear proper Personal Protective Equipment (PPE). Follow
ALL Regulatory requirements for safe work practices and for Personal Protective
Equipment (PPE).
Table of Contents
Important User Information ....................................................................................... 2
General Safety Information ....................................................................................... 3
Introduction ............................................................................................................... 3
Safety Function Realization: Risk Assessment ......................................................... 4
Safety Mat Safety Function ....................................................................................... 4
Safety Function Requirements .................................................................................. 4
Functional Safety Description ................................................................................... 5
Bill of Material ........................................................................................................... 6
Setup and Wiring ...................................................................................................... 6
Installation................................................................................................................. 7
Safety Distance Calculation ...................................................................................... 8
Configuration ............................................................................................................ 9
Calculation of the Performance Level...................................................................... 10
Verification and Validation Plan............................................................................... 16
Additional Resources .............................................................................................. 22
Introduction
This safety function application technique explains how to wire and configure a
Guardmaster® dual-input safety relay (GSR DI) to monitor a pair of 440F safety mats
and an E-stop. When someone steps on the safety mat, presses the E-stop, or a
fault is detected in the monitoring circuit, the GSR DI de-energizes the final control
devices, in this case, a pair of 100S safety contactors. E-stops are required in most
applications. Safety systems requiring both a sensing device, like a safety mat, and
E-stop combination are common. The dual-input relay makes this easy to implement
in a single safety-relay.
For purposes of this application technique, the safety functions stop the system once
an hour, 24 hours a day, 365 days a year, for a total of 8760 times a year, per safety
function.
The safety functions in this application technique each meet or exceed the
requirements for Category 3, Performance Level d (CAT. 3, PLd), per
EN ISO 13849-1 and control reliable operation per ANSI B11.19.
Functional Safety Description
Stepping on the safety mat stops and prevents the hazardous motion from restarting
until the person moves off the safety mat, the Guardmaster dual-input safety relay
(GSR DI) is reset, and the Start button is pressed.
Similarly, pressing the E-stop button stops and prevents hazardous motion from
restarting until the E-stop is released, the GSR DI is reset, and the Start button is
pressed.
Bill of Material
This application uses these products.
Cat. No. Description Quantity
440F-M2036BYNN Safety mat – yellow 1000 mm x 1800 mm (39.4 in. x 2
70.9 in.), 2-4.5 m (15 ft) 2-wire cables, exit out B
corners, no trim, no controller
440F-T3210 Standard, aluminum perimeter trim, 2 m (6.6 ft), 4
square end
440F-T3012 External corner perimeter trim 4
440F-T3220 Active uniting trim – 2 m (6.6 ft) length 1
800F-1YP8 800F 1-hole enclosure E-stop station, plastic, PG, 1
twist-to-release 60 mm (2.4 in.), non-illuminated, 1
N.O. contact, 2 N.C. contacts
400R-D22R2 Guardmaster dual-input safety relay, 2-dual channel 1
universal inputs, 1 N.C. contact, solid-state auxiliary
outputs
800FP-R611PX10 800F reset, round plastic, type 4/4 x /13, IP66, blue, 1
R, plastic latch mount, 1 N.O. contact, 0 N.C.
contacts, standard, standard pack (quantity 1)
800FP-U2E4F3PX11 800F 2-position momentary multi-function – red 1
plastic, type 4/4 x /13, IP65, position A – red exterior
push button, position C – green flush push button,
plastic latch mount, 1 N.O. contact, 1 N.C. contact,
standard, standard pack (quantity 1)
100S-C23EJ14BC MCS 100S-C safety contractor, 23 A, 24V DC with 2
electrical coil, bifurcated contact
The safety distance (S) required varies from installation to installation and, therefore,
must be calculated for each specific application. This application technique uses the
formula taken from EN ISO 13856-1.
S = (K * T) + C
Symbol Value
K The standard approach speed of 1600 mm/s (63 in./s).
T Stopping time
In this case, the stopping time is the summation of the following:
• Stopping time of the hazardous motion (Ts)
• Response time of the safety relay
• Response time of the safety contactors (Tc)
C Distance a standard hand could possibly move toward the hazard before the
safety mat is stepped on. 1200 mm (47.25 in.)
In this application technique example, these are the values:
K 1600 mm/s (63 in./s) (taken from EN ISO 13856-1)
Ts 250 ms (measured by the user or from the machine maker documents in any
actual application)
Tc 55 ms (40 ms [DI] + 15 ms [K1/K2]) taken from the product documentation)
C 1200 mm (47.25 in.) (taken from the product documentation)
S = (1600 * 0.305) + 1200 mm (47.25 in.) = 1688 mm (66.5 in.)
The edge of the safety mat farthest from the hazardous motion must be mounted no closer
than 1688 mm (66.5 in.) from the hazardous motion.
In this application, two 1000 mm x 1800 mm (39.4 in. x 70.9 in.) safety mats are placed
side-by-side, creating a single 2000 mm x 1800 mm (78.8 in. x 70.9 in.) monitored area to be
sure of an adequate distance.
Status
to PLC
E-stop LOGIC
Status
to PLC
Black
Black Black
Reset
Status
to PLC
Start Stop
Status
to PLC
Status
to PLC
FAULT
INPUT EXCLUSION LOGIC OUTPUT
(FE)
100S
K1
Safety Mat
Safety Mat
#1 GSR DI
#1
(FE)
100S
K2
FAULT
INPUT EXCLUSION LOGIC OUTPUT
(FE)
100S
K1
Safety Mat
Safety Mat
#2 GSR DI
#2
(FE)
100S
K2
100S
K1
E-stop
FE GSR DI
Included
100S
K2
In this case, the fault exclusion (FE) is selected in the Mean Time to Failure,
dangerous (MTTFd) section. E-stops are the most common safety input device. The
typical, almost universal, possibility of mechanical failure is recognized and widely
accepted. In this case, the FE is addressed in this manner; however, it could also
have been entered as a separate subsystem as was performed for the safety mats.
E-stop Safety Function Logic Subsystem
Because these are electro-mechanical devices, the safety mats and the safety
contactors data includes the following:
• MTTFd
• Diagnostic Coverage (DCavg)
• CCF
Electro-mechanical devices’ functional safety evaluations include the following:
• How frequently they are operated
• Whether they are effectively monitored for faults
• Whether they are properly specified and installed
SISTEMA software calculates the MTTFd by using B10d data provided for the
contactors along with the estimated frequency of use, entered during the creation of
the SISTEMA project.
The DCavg (90%) for the safety mats was based on the Guardmaster dual-input
safety relay being configured to interpret a cross-channel wiring/shorting fault as a
normal step on a safety mat, not as a fault and a no-channel welded-closed fault. An
actual cross-channel wiring and/or short fault trips the relay, sending the system to a
safe de-energized state. That system does not reset until the cross-channel fault is
corrected.
The DCavg (99%) for the E-stop was selected from the Input Device table of
EN ISO 13849-1 Annex E, Cross Monitoring.
Additional Resources
These publications contain additional information concerning related products from
Rockwell Automation.
Resource Description
Guardmaster Safety Relays Safety Provides information on the safety applications
Applications and Wiring Diagrams, and wiring guides for the Guardmaster Safety
publication SAFETY-WD001 Relays.
Next Generation Guardmaster Safety Provides information on the functionality of the
Relays, publication EUSAFE-BR009 Guardmaster safety relays.
Guardmaster Safety Relay SI Provides guidance on installing and operation
Installation Instructions, publication Guardmaster safety relays.
440R-IN042
See the Knowledgebase Answer ID Provides guidance on troubleshooting a 440F
548370 at safety mat.
http://rockwellautomation.custhelp.com
Safety Products Catalog, publication Provides an overview of products, product
S117-CA001 specifications, and application examples.