20 Rockwell Automation Publication 843ES-UM001A-EN-P - February 2020
Chapter 2 Safety Concept
Average Frequency of a
Dangerous Failure
Safety-related systems are classified as operating in a high-demand/continuous
mode. The SIL value for a high-demand/continuous mode safety-related system
is directly related to the average frequency of a dangerous undetected failure per
hour (PFH). PFH calculation is based on the equations from IEC 61508 and
shows worst-case values.
For safety data, see Appendix A on page 79
.
Mount the Encoder
The connection of the encoder and the drive unit must be assessed from a safety-
related point of view. This assessment applies to both to the connection with the
rotary element (shafts connection) and to the stationary section (stator
connection).
The following are the mechanical designs of the shaft connections available in the
843ES CIP Safety encoders:
•Solid shaft with key
• Hollow shaft with clamping ring
For the stator connection, the provided tether arms, stator couplings, and torque
stops are assessed from a safety-related point of view.
The mechanical connections have been designed so that a fault exclusion can be
claimed due to over-dimensioning and/or diagnostics. Reference and comply
with the mechanical limits that are specified in the proper assembly that is
described in Chapter 3
, and publication 843ES-IN001.
Firmware Revision
The 843ES CIP Safety encoders are manufactured with module firmware
installed. If updated module firmware revisions are available in the future, you
can update the firmware.
If the module is configured for Exact Match, the controller checks to make sure
that the module has the correct firmware revision.
Updated firmware revisions are made available for various reasons, for example,
to correct an anomaly that existed in previous module firmware revisions.
IMPORTANT Determination of safety parameters is based on the assumption that the
system operates in high-demand mode and that the safety function is
requested at least once every three months.
IMPORTANT Verify that the firmware revision of the device is correct before commissioning
the system. Firmware information for safety I/O devices is available with the
safety certificates at rok.auto/certifications
.