User Manual

Table Of Contents
Safe Torque-Off (STO)
Advanced Digital Motor Controller User Manual 39
The controller must have the Power Control input wired to the battery so that it can oper-
ate and communicate independently of the power stage. The controller’s processor will
then activate the contactor coil through a digital output configured to turn on when the
“No MOSFET Failure” condition is true. The controller will automatically deactivate the
coil if the output is expected to be off and the battery current is above 500mA to 2.5A (de-
pending on the controller model) for more than 0.5s.
The contactor must be rated high enough so that it can cut the full load current. For even
higher safety, additional precaution should be taken to prevent and to detect fused contac-
tor blades.
This contactor circuit will only detect and protect against damaged output stage condi-
tions. It will not protect against all other types of fault. Notice therefore, the presence of
an emergency switch in series with the contactor coil. This switch should be operated
manually or remotely, as discussed in the Manual Emergency Power Disconnect the Re-
mote Emergency Power Disconnect and the Protection using Supervisory Microcomputer
earlier in this section of the manual.
Using this contactor circuit, turning off the controller will normally deactivate the digital
output and this will cut the power to the controller’s output stage.
Important Warning
Fully autonomous and unsupervised systems cannot depend on electronics alone to
ensure absolute safety. While a number of techniques can be used to improve safety,
they will minimize but never totally eliminate risks. Such systems must be mechani-
cally designed so that no moving parts can ever cause harm in any circumstances.
Safe Torque-Off (STO)
Safe Torque Off is a safe method for switching controller in a state where no torque is
generated, regardless whether the controller is operating normally or is faulty. This func-
tion is a mechanism that prevents the drive from restarting unexpectedly. STO has the
immediate effect that the drive cannot supply any torque-generating energy. STO can be
used wherever the drive will be brought to a standstill in a sufficiently short time by the
load torque or friction or where coasting down of the drive is not relevant to safety. STO
enables safe working and has a wide range of use in motion control/ systems with moving
axes. The advantage of the integrated STO safety function compared with standard safety
technology using electromechanical switchgear is the elimination of separate components
and the effort that would be required to wire and service them. Because of the rapid elec-
tronic switching times, the function has a shorter switching time than the electromechani-
cal components in a conventional solution.
Specific motor controllers implement Safe Torque-Off (STO) circuitry, which is under cer-
tification from TUV (T-version - Certification No. M6A 104504 0001 Rev. 00). STO is the
most common safety function, meant for motor controllers, ensuring that upon trigger no
torque will be generated even after the controller power cycle. For controllers without the
specific circuit the STO is implemented in firmware alone and digital inputs 1 and 2 are
usually used (check controllers datasheet).