7. Safety

7.1. Background

As a key execution unit in the development of industrial intelligent manufacturing, the safety performance of industrial robots has become a core element in the full lifecycle management of equipment. Currently, the industry generally requires that safety function-related parameters be固化 and tamper-proof, and that a complete and traceable verification mechanism be established to meet stringent safety compliance audit requirements. System integrators and end users in Europe have further put forward clear requirements for transparency and verifiability of safety configurations in actual project acceptance. Specifically, after safety function debugging is completed, the system should be able to automatically generate a safety configuration report containing a complete checksum, and this checksum must be displayed in real-time on the device’s web management interface. This mechanism is designed to ensure that any modifications to safety parameters can be effectively identified and recorded, thus providing a reliable basis for equipment safety status assessment, on-site acceptance, and subsequent operation and maintenance. In view of this, the safety architecture design of this device not only complies with relevant international safety standards but also has built-in safety configuration export and checksum real-time display functions, to assist operators and safety managers in conveniently and reliably completing configuration confirmation and compliance certification work.

7.2. Safety Configuration Checksum

Open the web page. The safety checksum is located in the upper right corner of the page, represented by an 8-digit hexadecimal number. The safety checksum is unique; when safety configuration parameters change, the safety checksum changes accordingly.

../_images/00113.png

Figure 7.1-1 Safety Configuration Checksum Display

Click on the safety checksum to display the set of safety configuration parameters represented by the current safety checksum.

../_images/00213.png

Figure 7.1-2 Safety Configuration Parameters

Safety configuration parameters support exporting PDF reports. Click Download to preview the PDF report, and it also supports export. Click the Save button to download the PDF report.

../_images/00314.png

Figure 7.1-3 Safety Configuration Report PDF Preview

7.3. Safety Configuration Parameter Management

All robot-related safety configuration parameters are maintained uniformly on the web page under “Initial Setup” -> “Safety”. Modifying safety configuration parameters requires first entering the “Safety Configuration Password” for verification. Only after successful verification can safety parameter configuration modifications be made.

../_images/00414.png

Figure 7.2-1 Safety Configuration Password Verification

After modifying the safety configuration parameters, click “Apply”. A second confirmation of the modified safety configuration parameters is required. Click “Confirm” to apply the parameters. After the parameters are successfully applied, the safety configuration checksum will be updated accordingly.

../_images/00514.png

Figure 7.2-2 Safety Configuration Parameters Second Confirmation

7.4. Cybersecurity Functions

7.4.1. Security Password Management

7.4.1.1. Security Password Modification

The default security password is “12345678”. The security password can be modified on the “Safety” page. Click the “Modify Security Password” button to open the security password modification window. Enter the old password and the new password respectively to complete the security password modification.

../_images/00614.png

Figure 7.3-1 Security Password Modification Button

../_images/0478.png

Figure 7.3-2 Security Password Modification Window

The new and old security passwords must not be the same. The security password must be at least 8 characters long and must contain uppercase and lowercase letters, digits, and special characters.

../_images/0488.png

Figure 7.3-3 Security Password Complexity Verification

7.4.1.2. Security Password Protection

The robot security password input unlock has an anti-brute-force function. If an incorrect password is entered 5 consecutive times and the interval between each attempt is less than 1 minute, the security password input will be locked for 1 minute. During this 1 minute, the password cannot be entered to unlock, and a countdown is displayed in the WebApp.

../_images/0498.png

Figure 7.3-4 Security Password Anti-Brute-Force Lockout

7.4.2. Cybersecurity

The robot cybersecurity functions include encrypted communication of command protocols, default disabling of non-encrypted communication ports, software upgrades, integrity verification during startup, etc., which are used for identity authentication, anti-eavesdropping and anti-tampering, resisting network attacks, and ensuring controllable and secure communication.

7.4.2.1. Network Security Environment Information

Users must meet the following environmental requirements to ensure that the collaborative robot network security functions are effective; if the environment does not meet the requirements, the collaborative robot’s security protection capability may be reduced, and security risks may exist.

7.4.2.1.1. Physical Security Environment

① The robot controller and any switches it passes through must be installed in a control cabinet equipped with a locking device. Unauthorized personnel are strictly prohibited from opening the cabinet door. Without authorization, it is forbidden to touch the controller’s Ethernet ports and safety I/O ports or any other interfaces.

② The robot controller Ethernet port is only used to connect to an industrial computer. It is forbidden to connect a personal computer directly or to connect to the controller network port through a switch. Unauthorized personnel are prohibited from touching the industrial computer that has a network connection with the robot. Set a login password for the industrial computer.

③ The robot teach pendant and button box should both be placed in a safe working area. Unauthorized personnel are prohibited from entering this area.

7.4.2.1.2. Robot Security Configuration

① Set WebApp login accounts with corresponding permissions for personnel with different permissions, especially permissions for software/firmware upgrades and security parameter configuration;

② Change the robot WebApp administrator login password and security configuration password; keep the passwords properly to avoid leakage;

③ When using command protocol communication, enable encryption, and keep properly any network communication encryption certificates downloaded from the robot. Leakage of certificates is strictly prohibited.

④ Keep non-encrypted communication ports disabled by default; do not enable them unless necessary.

7.4.2.2. Network Security Function Version Requirements

Robot software version V4.0.0 and above supports network security functions. Robot software lower than this version number does not support network security functions.

7.4.2.3. WebApp Communication Encryption

Robot WebApp communication uses TLS 1.2 HTTPS encrypted communication. When using the WebApp, a certificate must be installed (if the certificate is not installed, the browser will display an insecure connection). The specific steps are as follows:

① Enter the robot IP address in the browser, such as 192.168.58.2, and press Enter to access the robot WebApp page. At this time, the browser will display an insecure connection prompt.

../_images/0509.png

Figure 7.3-5 Insecure Connection Displayed

② Click “Not secure” on the left side of the IP address input box to open the connection details window.

../_images/0518.png

Figure 7.3-6 Connection Details Window Opened

③ In the window, click “Certificate details” to open the certificate details window. Select “Details” in the upper tab and click the “Export” button to download the certificate. The downloaded certificate name is usually the robot IP address. You need to rename the file and add the extension “.crt”, for example, change “192.168.58.2” to “192.168.58.2.crt”.

../_images/0527.png

Figure 7.3-7 Certificate Details Window

../_images/0537.png

Figure 7.3-8 Certificate File Name

④ Double-click the certificate file to open the certificate installation window, and click “Install Certificate”.

../_images/0547.png

Figure 7.3-9 Certificate Installation Window

⑤ In the certificate installation wizard that pops up, select the storage location as Local Machine, and click Next.

../_images/0557.png

Figure 7.3-10 Select Storage Location as Local Machine

⑥ In the certificate wizard window, select “Place all certificates in the following store”, click the “Browse” button, and select “Trusted Root Certification Authorities”. Click Next.

../_images/0569.png

Figure 7.3-11 Select Trusted Root Certification Authorities

⑦ Click “Finish”.

../_images/0579.png

Figure 7.3-12 WebApp Certificate Installation Complete

Restart the browser and log in to the WebApp, and it will display as a normal secure connection.

../_images/0588.png

Figure 7.3-13 Secure Connection Displayed After Installing WebApp Certificate

7.4.2.4. Command Protocol Encryption

The robot 8080-TCP and 20007-UDP command protocols can be configured to communicate via TLS 1.2 mutual authentication encryption. Users download the root certificate, client certificate, and client private key from the robot. Each robot has its own separate root certificate, and client certificates and private keys downloaded from different robots cannot be mixed. A single robot supports only one set of client certificate and private key.

In the robot WebApp, click “Initial Setup”, “Safety”, “Cybersecurity” in sequence, enter the security password to unlock, and find “Command Protocol Certificate” in “Cybersecurity”.

../_images/0597.png

Figure 7.3-14 Command Protocol Certificate Configuration Page

Click the “No certificate yet, please create first” button, and enter the number of valid days for the command protocol certificate starting from the current day. Click the “Create” button. After the certificate is successfully created, the client certificate name, serial number, and expiration time calculated based on the valid days will be displayed.

../_images/0607.png

Figure 7.3-15 Command Protocol Certificate Validity Period Configuration

../_images/0617.png

Figure 7.3-16 Command Protocol Certificate Information

Click the download button on the right to download the “client_certs.tar.gz” archive. The archive contains three files: “ca.crt”: root certificate; “client.crt”: client certificate; “client.key”: client key.

Click “Enable” and click the “Apply” button. In the robot safety configuration confirmation window that pops up, confirm the enablement of command protocol certificate encryption, and click the “Confirm” button again to enable command protocol encryption.

../_images/0627.png

Figure 7.3-17 Command Protocol Certificate Enablement Confirmation

../_images/0637.png

Figure 7.3-18 Command Protocol Certificate Encryption Enabled

Click the “Delete” button on the right side of the certificate information box to disable the certificate corresponding to that serial number. Before deleting the certificate, the command protocol encryption must first be set to disabled.

7.4.2.5. Non-Encrypted Network Communication Function Enablement Configuration

Some non-encrypted network communication functions of the robot can be configured to be enabled or disabled, and are disabled by default.

Note

Note: The robot communication port disabling function only takes effect when “Functional Safety” is enabled. In non-“Functional Safety” mode, all robot network communication functions are enabled!

In the robot WebApp, click “Initial Settings”, “Safety”, and “Network Security” in sequence, then find “Communication Ports”. The functions of each port are described as follows:

../_images/0648.png

Figure 7.3-19 Communication Port Enablement Configuration

  • Control via SDK: Control the robot through the XMLRPC communication port in the robot SDK. When not enabled, the robot cannot be controlled via XMLRPC.

  • Control via ModbusTCP: When the robot acts as a ModbusTCP slave, the robot DO output, program start/stop, manual/auto switching, reduced mode, etc. can be controlled through “Function Digital Input (Coil)”. After disabling “Control via ModbusTCP”, the above control functions through “Function Digital Input (Coil)” are all disabled.

  • Control via ModbusRTU: When the robot acts as a ModbusRTU slave, the robot DO output, program start/stop, manual/auto switching, reduced mode, etc. can be controlled through “Function Digital Input (Coil)”. After disabling “Control via ModbusRTU”, the above control functions through “Function Digital Input (Coil)” are all disabled.

  • Control via CNDE: The robot CNDE input can be configured for robot DO output, AO output, running speed, and other controls. After disabling “Control via CNDE”, the CNDE client cannot control the above functions.

  • Button Box IP Reset Function: The robot button box V2.0 has an IP reset button. Disabling the “Button Box IP Reset Function” will prevent the robot IP from being reset through the button box.

Enter the security password on the safety configuration page and unlock it, set the communication ports to be enabled to “On”, click “Apply”, confirm the enabled functions in the safety configuration confirmation window that pops up, and click the “Confirm” button.

../_images/0658.png

Figure 7.3-20 Communication Port Enablement Confirmation

../_images/0668.png

Figure 7.3-21 Communication Ports Enabled

7.4.2.6. Robot Software Integrity Verification

Robot software upgrade and software startup will perform integrity verification of the software package to prevent the robot software package from being tampered with.

Robot software upgrade integrity verification: During robot software upgrade, the integrity of the software package to be upgraded will be verified. If the software package is incomplete, an error message will be reported during the upgrade and the upgrade will be stopped.

../_images/0678.png

Figure 7.3-22 Software Upgrade Integrity Verification Failure Error

Robot software startup integrity verification: During robot software startup, the integrity of the software package in the current system will be verified. If the software package is complete, the robot software will start normally; otherwise, the robot software will not start, and an error prompt will be displayed in the WebApp.

../_images/0688.png

Figure 7.3-23 Integrity Verification Failure Error During Software Startup

7.4.2.7. Cybersecurity Residual Risk Statement

Table 2-1 Cybersecurity Residual Risks and User Compensatory Measures

No.

Residual Risk

Mitigation Measures Taken

User Compensatory Measures

1

Robot SDK - XMLRPC communication protocol is transmitted in plaintext

① SDK control robot function is disabled by default;
② The SDK inherently integrates 8080-TCP and 20007-UDP command protocols, and the command protocols have TLS 1.2 encryption; if the command protocol encryption handshake fails, the SDK cannot connect to the robot normally.
① SDK communication between the host computer and the robot shall only be deployed in a trusted isolated network environment; connection to untrusted networks is not allowed; physical protection shall be provided for network links and network ports to prevent unauthorized access;
② The SDK integrates 20007-UDP command protocol communication and provides the SendUDPFrame() interface for sending custom command frames. At the same time, 20007-UDP command protocol communication has DTLS encryption. Sensitive information must be sent to the robot through this interface;
③ When not necessary, disable the SDK control robot function in the WebApp “Safety” and “Cybersecurity” modules;

2

Robot 20005 - TCP / 20006 - UDP configurable data exchange CNDE communication is transmitted in plaintext

① CNDE control robot function is disabled by default;
① CNDE communication between the host computer and the robot shall only be deployed in a trusted isolated network environment; connection to untrusted networks is not allowed; physical protection shall be provided for network links and network ports to prevent unauthorized access;
② When not necessary, disable the CNDE control robot function in the WebApp “Safety” and “Cybersecurity” modules;

3

Robot ModbusTCP communication is transmitted in plaintext

① ModbusTCP control robot function is disabled by default;
① ModbusTCP communication between the host computer and the robot shall only be deployed in a trusted isolated network environment; connection to untrusted networks is not allowed; physical protection shall be provided for network links and network ports to prevent unauthorized access;
② When not necessary, disable the ModbusTCP control robot function in the WebApp “Safety” and “Cybersecurity” modules;

4

Robot ModbusRTU communication is transmitted in plaintext

① ModbusRTU control robot function is disabled by default;
① ModbusRTU communication between the host computer and the robot shall only be deployed in a trusted isolated network environment; connection to untrusted networks is not allowed; physical protection shall be provided for network links and network ports to prevent unauthorized access;
② When not necessary, disable the ModbusRTU control robot function in the WebApp “Safety” and “Cybersecurity” modules;

5

Attackers may use the default WebApp administrator login account and password to modify robot safety configuration parameters

No

① Users must modify the robot WebApp default administrator login password and keep the password properly;
② Users must set corresponding WebApp login accounts and passwords for personnel with different safety configuration permissions and keep the passwords properly;

6

Attackers may use the default WebApp login account and password to modify the robot software/firmware version

No

① Users must modify the robot WebApp default administrator login password and keep the password properly;
② Users must set corresponding WebApp login accounts and passwords for personnel with different software/firmware upgrade permissions and keep the passwords properly;

7

Attackers may use the default security password to modify safety configuration parameters

No

① Users must modify the robot security password and are prohibited from using the default security password;

8

Attackers may physically damage the robot LAN1 / LAN2 Ethernet ports, causing the robot Ethernet communication to fail

None

① Users must install the robot control box in a control cabinet with a locking device and prohibit unauthorized personnel from touching the robot control box;

9

Attackers may physically damage the robot RS-485 communication port, causing the robot extended axis control and ModbusRTU communication to fail

None

① Users must install the robot control box in a control cabinet with a locking device and prohibit unauthorized personnel from touching the robot control box;

10

Attackers may physically damage the emergency stop button on the robot button box, causing the robot emergency stop button to fail

None

① Users must place the robot button box in a safe working area and prohibit unauthorized personnel from entering the area;

11

Attackers may physically damage the emergency stop button on the robot teach pendant, causing the robot emergency stop button to fail

None

① Users must place the robot teach pendant in a safe working area and prohibit unauthorized personnel from entering the area;

7.4.3. Permission Management

Table 3-1 Permission Details

../_images/0697.png ../_images/0707.png

Figure 7.3-24 Setting Role Permissions

7.5. Safety Configuration Parameters

7.5.1. Robot Safety Parameters

7.5.1.1. Robot Speed

Click the menu bar “Initial Setup” -> “Safety”, and click the “Robot Speed” submenu to enter the configuration interface.

Robot speed is used to limit the robot’s maximum linear velocity, linear acceleration, and joint angular acceleration.

../_images/00714.png

Figure 7.4-1 Robot Speed

7.5.1.2. Stop Deceleration Planning

Click the menu bar “Initial Setup” -> “Safety”, and click the “Stop Deceleration Planning” submenu to enter the configuration interface.

  • Free Stop: When entering stop, the angular velocity of each axis decelerates and stops according to the set stop deceleration percentage multiplied by the joint maximum acceleration;

  • Synchronized Stop: When entering stop, the TCP pose velocity decelerates and stops according to the set stop deceleration percentage multiplied by the pose maximum acceleration;

Stop deceleration is a percentage of acceleration.

../_images/00812.png

Figure 7.4-2 Robot Stop Deceleration Planning

7.5.1.3. Safety Stop

Click the menu bar “Initial Setup” -> “Safety”, and click “Safety Stop” to enter the configuration interface to set the safety stop mode and safety stop strategy parameters.

When the safety stop trigger mode is set to “Dual Channel”, both channels must be cleared and the warning must be manually cleared on the operation interface before the robot can be reset. In addition, a reduced mode option is added to the strategy configuration. When the user selects this strategy, the robot will enter reduced mode motion.

Step1: Click “Initial Setup” -> “Safety” -> “Safety Stop”. The trigger mode can be selected as “Default” or “Dual Channel”. The difference between the two is: in “Default” mode, the interface error is automatically cleared after triggering and recovery; in “Dual Channel” mode, the interface error must be manually cleared after triggering and recovery. “Safety Stop Strategy” can be selected as “Stop”, “Pause”, “Level 1 Reduced Mode”, and “Level 2 Reduced Mode”. The detailed descriptions are as follows: When “Stop” is selected, the robot will stop the current motion; when “Pause” is selected, the robot will pause the current motion, and after recovery and error clearing, it will resume the pause; when “Level 1 Reduced Mode” is selected, the robot will enter Level 1 reduced mode motion; when “Level 2 Reduced Mode” is selected, the robot will enter Level 2 reduced mode motion.

../_images/00912.png

Figure 7.4-3 Robot Stop Deceleration Planning

Step2: When the trigger mode is set to “Default”, the interface error can be automatically cleared after trigger recovery. When the trigger mode is set to “Dual Channel”, the operation is: after trigger recovery, manually click the “Clear” operation in the upper right corner to reset the robot.

7.5.1.4. Safety Speed

Click the menu bar “Initial Setup” -> “Safety”, and click “Safety Speed” to enter the configuration interface to set the safety speed. The TCP manual speed range is 1-1500mm/s.

The robot safety speed function is used in human-robot collaboration or dynamic environments to actively limit the robot’s operating speed, controlling kinetic energy and impact force within safety thresholds, thereby preventing personnel injury in accidental contact and effectively protecting equipment and workpieces from collision damage.

Step1: Click “Initial Setup” -> “Safety” -> “Safety Speed” to set the safety speed parameters, mainly including three parts: “Function Enable”, “Speed Limit”, and “Post-Overspeed Mode”.

Among them, Function Enable can be selected as “Disable”, “Manual Mode Enable”, and “All Modes Enable”;

In Speed Limit, set the speed limit. When the robot’s linear speed reaches this limit, it will be processed according to the parameters set in “Post-Overspeed Mode”. “Post-Overspeed Mode” can be selected as “Stop and Alarm”, “Auto Speed Limit”, and “Disable After Stop and Alarm”. Auto speed limit is only available in “Manual Mode Enable”.

After setting the required parameters, no further operation is needed. The robot’s motion will be processed according to the set parameters. The parameter settings are shown in the figure.

../_images/01012.png

Figure 7.4-4 Safety Speed Parameter Settings

7.5.1.5. Emergency Stop

Click the menu bar “Initial Setup” -> “Safety”, and click “Emergency Stop” to enter the configuration interface.

Emergency stop types 0, 1a, 1b, 2 can be set, stop time limit can be set, and stop distance limit can be set.

Through the controller sending to the control box board, emergency stop type 0 directly cuts off power to the control box board;

  • Emergency stop type 1a: after deceleration stop, cuts off power to the robot body;

  • Emergency stop type 1b: after deceleration stop, does not cut off power to the robot body, but disables the robot body;

  • Emergency stop type 2: when emergency stop is pressed, the robot decelerates to a stop and remains enabled. After releasing the emergency stop, the robot should be able to operate normally.

../_images/01110.png

Figure 7.4-5 Emergency Stop Settings

7.5.1.6. Protective Stop

Click the menu bar “Initial Setup” -> “Safety”, and click the “Protective Stop” submenu to enter the configuration interface.

Protective stop types 0, 1, 2. Protective stop type 0 directly cuts off power to the control box board. Protective stop type 1: the control box board first notifies the controller to control the robot to stop, then the controller feeds back to the control box board to cut off power. Protective stop type 2: the control box board notifies the controller to control the robot to stop.

../_images/01210.png

Figure 7.4-6 Protective Stop Configuration

7.5.1.7. Auto Enable on Power-On

Click the menu bar “Initial Setup” -> “Safety”, and click the “Robot Enable” submenu to enter the configuration interface. You can choose whether the robot automatically enables on power-on or not.

../_images/01310.png

Figure 7.4-7 Auto Enable on Power-On

7.5.1.8. Tool Orientation Limit (Only used in LA system)

Click the menu bar “Initial Setup” -> “Safety”, and click the “Tool Orientation Limit” submenu to enter the configuration interface.

The tool orientation limit is a protective function acting on the robot’s tool end Cartesian space to limit the robot’s end posture motion range, including function enable setting, reference tool direction setting, and maximum deviation angle setting. The maximum deviation angle defines the maximum angular limit between the Z-axis of the tool end Cartesian coordinate system and the reference tool direction, which can usually be understood as a conical space.

../_images/0149.png

Figure 7.4-8 Tool Orientation Limit

7.5.1.9. Robot Limits (Only used in LA system)

Click the menu bar “Initial Setup” -> “Safety”, and click the “Robot Limits” submenu to enter the configuration interface.

Robot limits include momentum and power, where the momentum limit is used to limit the robot’s maximum momentum, and the power limit is used to limit the mechanical work done by the robot.

../_images/0159.png

Figure 7.4-9 Robot Limits

7.5.2. Joints

7.5.2.1. Joint Soft Limits

Under the menu bar “Initial Setup” -> “Safety” -> “Joints”, click “Joint Soft Limits” to enter the soft limit interface.

There may be other equipment within the robot’s travel range. The limit angles can perform soft limiting on the robot, preventing the robot from moving beyond certain coordinate values and avoiding collisions. Triggering a soft limit causes the robot to stop automatically, with no stopping distance.

Administrators can use default values or enter angle values. By entering angle values, the positive and negative angles of the robot’s joints can be limited separately. When the entered value exceeds the robot joint soft limit angle values listed in the robot basic parameters table in Section 2.1-Basic Parameters, the limit angle will be adjusted to the maximum settable value. When the robot reports a joint command out-of-limit error, it is necessary to enter drag mode and drag the robot joint back within the limit angle.

The joint soft limit protection function is an active protection mechanism that monitors the motion state of the robotic arm joints in real time and dynamically restricts the operator from exceeding the set soft limit range during drag teaching. This function makes soft limits meaningful even in drag teaching, thereby enhancing human-robot collaboration safety.

  • Step1: Log in to the web interface and click “Initial Setup” -> “Safety” -> “Joints” -> “Joint Soft Limits” in sequence to enter the robot soft limit setting module.

  • Step2: Based on the robot’s actual working range, reasonably set the soft limits for each joint. At this time, check whether the current angular position of each robot joint is within the preset soft limit range. If yes, click “Apply” to send the preset soft limits. If not, move each joint within the preset range; otherwise, an over-limit prompt will appear when clicking “Apply”, as shown in the figure below. At this time, you can jog or drag the over-limit joint in the direction toward the soft limit range to clear the error.

  • Step3: After the soft limit range is successfully set, select “Enable” for “Joint Soft Limit Protection” to activate this function, as shown in the figure below. In drag mode, the set soft limits will take effect, and resistance will be felt when dragging near the soft limits.

  • Step4: To disable the joint soft limit protection function, click “Joint Soft Limit Protection” to turn it off.

../_images/01610.png

Figure 7.4-10 Joint Soft Limits

7.5.2.2. Collision Level

Under the menu bar “Initial Setup” -> “Safety” -> “Joints”, click “Collision Level” to enter the collision level interface. Collision levels are divided into levels 1 to 10. Levels 1 to 3 are more sensitive, and the robot needs to run at the recommended speed. You can also choose custom percentage settings, with 100% corresponding to level 10. As shown in the figure below:

../_images/01711.png

Figure 7.4-11 Collision Level Diagram

Collision strategies are “Stop on Collision”, “Pause on Collision”, and “Continue Motion”. To avoid extrusion force between the robot and objects after collision, strategies “Gravity Torque Mode”, “Oscillation Response Mode”, and “Collision Rebound Mode” have been added. When triggered, all three strategies will switch from automatic or manual mode to drag mode, and then back to manual mode. The gravity torque mode will move away from the collision point based on the magnitude and direction of the collision force; the oscillation response mode will return to the collision position after moving away from it; the collision rebound mode will accelerate away from the collision point according to the set parameters.

In the “Collision Strategy” section, click the drop-down box to select “Collision Rebound Mode”, and set the safety time to 1000ms, safety distance to 150mm, safety speed to 150mm/s, and safety factor for each joint to 5. The specific interface is shown in the figure below.

../_images/01811.png

Figure 7.4-12 Collision Strategy: Collision Rebound Mode

Meaning of each parameter:

  • Safety Time: Indicates the duration in drag mode after switching from automatic mode to drag mode, range [1000-2000]ms;

  • Safety Distance: Indicates the position where the robot moves away from the collision point after collision, range [150-200]mm;

  • Safety Speed: Indicates the maximum TCP speed at which the robot moves away from the collision point after collision. Exceeding this speed limit will constrain the rebound force, range [50-250]mm/s;

  • Safety Factor: Indicates the decay rate of the rebound force. The smaller the coefficient, the faster the decay and the faster the rebound speed; the larger the coefficient, the slower the decay. Range [1-10], dimensionless.

  • Before the robot enters drag mode, torque detection is required. This function is designed to prevent abnormal phenomena such as lifting or dropping after the robot enters drag mode due to incorrect load parameters or installation mode settings by the operator. If the joint torque is detected to exceed the allowable range, the controller will immediately report an error and prohibit the robot from entering drag mode.

Steps to enable the linear rack and pinion rail collision detection function:

  • Step1: Ensure that both the rail and robot installation methods are front-mounted. Before enabling the linear rack and pinion rail collision detection function, check whether the installation method is front-mounted. Specifically, first ensure that the rail and robot installation methods are front-mounted. Then, click “Initial Setup” -> “Basic” -> “Installation” in sequence to enter the free installation page. If both “Base Rotation” and “Base Tilt” are 0, the software is set to front-mounted; otherwise, they must be changed to 0. If they are not 0, the interface will prompt an error.

  • Step2: Enable the linear rack and pinion rail collision detection function and set parameters. Click “Initial Setup” -> “Safety” -> “Joints” -> “Collision Level” in sequence to enter the collision level setting page. After clicking the “Linear Rack and Pinion Rail Collision Detection” function slider, set the gear radius and slider mass. The gear radius can be calculated from the lead and reduction ratio. The slider mass does not include the robot and its end load. There are 11 rail level options, where Level 1 is the easiest to trigger collision and Level 10 is the most difficult. When the controller is first powered on and before the adaptation program is executed, the collision level should first be set to “Off”.

../_images/01910.png

Figure 7.4-13 Linear Rack and Pinion Rail Collision Detection Function

  • Step3: Execute the “Rail_Adaptation_Program.lua” program to adapt to the current rail. After each controller restart, the “Rail_Adaptation_Program.lua” program must be executed (to prevent changes in robot type and other factors from affecting the rail’s dynamic characteristics). Before executing the program, ensure that the rail collision level is set to “Off”. In automatic mode, run the LUA program at 100% interface speed. After one loop of the program is completed, the adaptation is complete and execution can be stopped.

../_images/02010.png

Figure 7.4-14 Execute “Rail_Adaptation_Program.lua” to Adapt to the Current Rail

  • Step4: Reasonably set the rail collision level and execute tasks. Users can reasonably set the rail collision level based on the motor driver performance and task running speed. If the rail and robot operate asynchronously, collision with the robot or rail can trigger an “8-axis collision fault, resettable”. At this time, the rail stops running, as shown in Figure 2-9. If the rail and robot operate synchronously, collision with the robot can trigger an alarm, causing the rail to stop running, while the robot reacts according to the set collision strategy.

7.5.2.3. Reduced Mode

Click the menu bar “Initial Setup” -> “Safety”, and click the “Reduced Mode” submenu to enter the configuration interface. Select “Level 1/Level 2 Mode” to configure joint speed and end TCP speed.

../_images/02110.png

Figure 7.4-15 Reduced Mode

7.5.3. I/O

Click the menu bar “Initial Setup” -> “Safety”, and click the “I/O” submenu to enter the configuration interface.

HMI provides the ability to set the safety state for 16 digital inputs and 16 digital outputs, which can be set to valid or invalid states. When the controller determines that it is in a safety state, the 16 digital inputs and 16 digital outputs are set to the safety state.

../_images/02210.png

Figure 7.4-16 I/O Safety State Configuration

Under the LA system:

“I/O Safety” provides DIO safety functions. The safety function is dual-channel DI or DO. When a safety DI signal or safety state flag is triggered, the DO is output.

../_images/02310.png

Figure 7.4-17 I/O Safety Function Configuration

7.5.4. Hardware

7.5.4.1. ServoJT Power Detection (Only used in QX system)

Click the menu bar “Initial Setup” -> “Safety”, and click the “Power Detection” submenu to enter the configuration interface.

When directly acting on the robot’s current loop (servoJT only), it is used to limit the work done by the robot. When the integral of robot speed and torque is detected to exceed the limit, power protection is activated.

../_images/02410.png

Figure 7.4-18 ServoJT Power Detection

7.5.5. Planes

7.5.5.1. Safety Wall

Click the menu bar “Initial Setup” -> “Safety”, and click the “Safety Wall Configuration” submenu to enter the configuration interface.

  • Safety Wall Configuration: Click the Enable button to enable the corresponding safety wall. When a safety wall has not been configured with a safety range, an error will be prompted. Click the configuration button in the upper right corner, select the safety wall you want to set, automatically bring up the safety distance (optional, default is 0), and then click the “Set” button to set successfully.

  • Safety Wall Reference Point Configuration: After selecting a safety wall, four reference points can be set. The first three points are plane reference points, used to confirm the plane of the set safety wall. The fourth point is the safety range reference point, used to confirm the safety range of the set safety wall.

If the reference points are set successfully, a green light will be displayed. Otherwise, a yellow light will be displayed until the reference points are successfully set and turn green. When all four reference points are successfully set, the safety range can be calculated. After successful calculation, the safety range parameter point status returns to default.

../_images/02510.png

Figure 7.4-19 Safety Range Reference Point Settings

  • Application Effect: Enable the successfully configured safety wall. Drag the robot. If the robot’s end TCP is within the set safety range, the system is normal. If it is outside the set safety range, an error will be prompted.

../_images/02611.png

Figure 7.4-20 Effect After Successful Safety Range Settings

7.5.5.2. Interference Zone

Under the menu bar “Initial Setup” -> “Safety” -> “Interference Zone”, click the “Single” submenu item to enter the interference zone configuration interface.

We need to configure the interference method and the operation upon entering the interference zone. Interference methods are divided into “Axis Interference” and “Cuboid Interference”.

../_images/02711.png

Figure 7.4-21 Interference Zone Methods

Click the interference zone icon, use the switch to control whether it is enabled, and click the configuration button in the upper right corner for parameter configuration.

../_images/02810.png

Figure 7.4-22 Interference Zone Configuration

First, configure the interference zone motion as “Continue Motion” or “Stop”. Next, set the drag configuration upon entering the interference zone. Users can set the strategy after entering the interference zone in drag mode according to their needs: no drag restriction, impedance return, or switch back to manual mode.

When selecting Axis Interference, the axis interference parameters need to be configured. The detection method can be “Command Position” or “Feedback Position”. The interference zone mode can be “Interference Within Range” or “Interference Outside Range”. Next, set the range for each joint and whether the range for each joint is enabled. You can enter values, or use the “Refresh” icon after “Min” and “Max” to record the current robot position, and finally click Configure.

../_images/02910.png

Figure 7.4-23 Axis Interference Configuration

When selecting Cuboid Interference, the cuboid interference parameters need to be configured. The detection method can be “Command Position” or “Feedback Position”. The interference zone mode can be “Interference Within Range” or “Interference Outside Range”. The reference coordinate system can be “Base Coordinate” or “Workpiece Coordinate”, selected according to actual usage. Next, set the range. There are two methods for range setting. The first method is the “Two-Point Method”, which uses two diagonal vertices of the cuboid. Positions can be entered or recorded through robot teaching. Finally, click Apply.

../_images/0309.png

Figure 7.4-24 Cuboid Interference Configuration

The second method is the “Center Point + Side Length” method, where the center point of the cuboid and the side length of the cuboid form the interference zone. Positions can be entered or recorded through robot teaching. Finally, click Apply.

../_images/0319.png

Figure 7.4-25 Cuboid Interference Configuration

7.5.6. Safety Log Storage Function

7.5.6.1. Background

The CE certification for FR series robots requires that all safety operation-related logs of the equipment be recorded and maintained separately. It also explicitly requires that the log storage include at least the last intervention evidence for each intervention type, that the tracking log data records for each intervention be kept for at least 5 years, and that the logs be protected against tampering.

7.5.6.2. Safety Log Management

Safety log management is maintained on the web page under “Initial Setup” -> “Safety”. The “Safety Configuration Password” must be entered for verification first, and safety log management can only be performed after successful verification.

../_images/04410.png

Figure 7.4-26 Safety Log Management

Safety logs are managed uniformly. To prevent an excessive log volume caused by abnormal operations, the current log storage volume can be seen intuitively on the page. Safety logs only retain the most recent 5 years, and each year’s logs are stored uniformly in separate files according to log type. Click Export to export all logs.

Log types are divided into the following three categories:

Table 1-2 Safety Log Classification

Log Category

Log File Name

Description

Parameter Modification

safetylog_params_2026.log

Robot safety configuration parameter modification, robot safety password modification

Software/Firmware Version

safetylog_version_2026.log

Software/firmware version upgrade

Log Operation

safetylog_operate_2026.log

Safety log deletion, export

Since safety logs must be kept for 5 years and cannot be deleted, to prevent abnormal writes from causing storage memory anomalies that affect system operation, safety logs adopt a tiered rate-limiting strategy based on used capacity. Before writing, the current used log space is checked, and the write frequency is dynamically adjusted.

Table 1-3 Safety Log Rate-Limiting Strategy

Stage

Used Capacity

Write Frequency

Description

1

<500M

Unlimited

Normal use (about 200M for 5 years)

2

500M-1G

1 second/entry

Slight rate limiting, no impact on experience

3

1G-2.5G

5 seconds/entry

Obvious anomaly, proactive speed reduction

4

2.5G-4G

30 seconds/entry

Severe anomaly, extreme delay time

5

>4G

Stop writing

Quota exhausted, no further log writing

In normal use, at a write volume of 1000 entries per day, the estimated usage over 5 years is within 200M. Therefore, when the memory exceeds 1G, there is clearly an abnormal situation. After exceeding 1G, the controller will proactively report a warning. It is necessary to proactively export and back up logs and recommend timely log cleanup.

../_images/04510.png

Figure 7.4-27 Safety Log Abnormality Warning

The log export time depends on the total log size. Theoretically, the total log volume over 5 years will not exceed 200M. When logs exceed 1G, the download time exceeds 1 minute, and at the upper limit of 4G, the download time is about 5 minutes. After export, log cleanup can be performed. To ensure that abnormal evidence is not cleaned up, the current log deletion function only deletes logs from years other than the current year.

../_images/0469.png

Figure 7.4-28 Safety Log Deletion

7.6. Functional Safety Functions

7.6.1. Functional Safety Description

This device is equipped with a safety-related control system used to automatically execute safety actions (such as emergency stop, guard door interlocking, etc.) when a hazardous situation is detected. These safety functions have been designed and verified in accordance with EN ISO 13849-1 / EN IEC 62061 standards and are an important part of achieving CE compliance.

To ensure that the safety functions remain effective, please note:

  • Do not bypass or shield any safety device (such as removing interlock switches, short-circuiting safety circuits, blocking light curtains, etc.), otherwise it may cause serious personal injury.

  • Do not modify safety-related components or software programs without authorization. Any modification, parameter change, or software update to the safety control system must be performed by the manufacturer or its authorized personnel, and a risk assessment must be carried out again.

  • Network security: Do not connect the safety control system of this device to an unauthorized network; unauthorized digital access may cause the safety functions to fail.

  • Maintenance and faults: If any safety device operates abnormally or fails, stop the machine immediately and contact the manufacturer or authorized service personnel. Only trained and authorized personnel may perform maintenance.

This device is conformity assessed in accordance with the EU Machinery Regulation (EU) 2023/1230. Safety function components are listed in the technical documentation for reference. The following is the specific list of safety functions.

Table 1-1 Safety Function List

SF ID

Function Name

Level

Description

MTTFd*

SF01

E-STOP on TPU-Teach Pendant Emergency Stop

PL d

Execution monitoring of the emergency stop
Includes trigger logic for different trigger sources:
1. In any mode, when the teach pendant emergency stop switch is triggered, it is converted to a control box emergency stop signal, and Cat.0 or Cat.1 stop action is executed according to the configured type, with interlocked position holding function
2. In any mode, when the control box safety DI is triggered, it is converted to a control box emergency stop signal, and Cat.0 or Cat.1 stop action is executed according to the configured type, with interlocked position holding function
[Trigger event]: Emergency stop signal triggered
[Robot response]:
If the stop type is 0, the body power is cut off, the joints execute a safe brake, and position holding is monitored
If the stop type is 1, deceleration stop is performed, the body power is cut off, the joints execute a safe brake, and position holding is monitored

202.0512143

SF02

Safeguard Stop

PL d

Execution monitoring of the safeguard stop
In any mode, the safety stop function is triggered according to the control box safety stop signal. According to the configured safety stop level, the corresponding Cat.0, Cat.1, Cat.2 stop functions and the corresponding interlocked position holding function detection (Cat.0, Cat.1) or standstill detection + stopping distance + stopping time detection (Cat.2) are executed.
[Trigger event]: Safety stop signal triggered;
[Robot response]:
If the stop type is 0, the body power is cut off, the joints execute a safe brake, and position holding is monitored;
If the stop type is 1, deceleration stop is performed, the body power is cut off, the joints execute a safe brake, and position holding is monitored;
If the stop type is 2, deceleration stop is performed, the body power is maintained, the joints do not execute a safe brake and remain enabled, and standstill detection + stopping distance + stopping time detection are performed;

191.3170862

SF03

Joint Position Limit

PL d

Monitoring of the joint position limit
[Joint soft limits can be set for each joint. The safety board detects the joint position in real time. If the limit is exceeded, a Cat.2 stop action is executed, with interlocked standstill detection + stopping distance + stopping time detection.
[Trigger event]: The joint moves outside the limit position range;
[Robot response]: Fault alarm - soft limit exceeded, Cat.2 stop action is executed, with interlocked standstill detection + stopping distance + stopping time detection;

158.5302637

SF04

Joint Speed Limit

PL d

Monitoring of the joint speed limit
A joint speed limit can be set for each joint. According to the corresponding safety speed of the controller, the safety circuit detects whether the real-time speed of each robot joint exceeds the limit. If the limit is exceeded, a Cat.1 stop with interlocked position holding monitoring, or a Cat.2 stop with interlocked standstill detection + stopping distance + stopping time detection is performed.
[Trigger event]: The joint speed exceeds the set value;
[Robot response]: Fault alarm - speed exceeded. Optionally perform a Cat.1 stop with interlocked position holding monitoring, or by default perform a Cat.2 stop with interlocked standstill detection + stopping distance + stopping time detection;

158.5302637

SF05

Joint Torque Limit

PL d

Monitoring of the joint torque limit
A joint torque limit can be set for each joint. According to the corresponding safety torque of the controller, the safety circuit detects whether the real-time torque of each robot joint exceeds the limit. If the limit is exceeded, a Cat.2 stop is performed, with interlocked standstill detection + stopping distance + stopping time detection
[Trigger event]: The joint torque exceeds the set torque value
[Robot response]: Fault alarm - joint x torque exceeded, Cat.2 stop is performed, with interlocked standstill detection + stopping distance + stopping time detection

67.48193213

SF06

TCP Pose Limit (safety plane, tool direction)
(Dynamic Limit can be adjusted dynamically; stop type not required)
(Corresponding limits are dynamically adjusted through configurable IO, dual circuit)

PL d

Monitoring of the TCP pose limit
The TCP limit range and corresponding DI (up to 8 can be set) are set in advance on the corresponding controller page. When the DI is turned on, the corresponding limit is activated. When the TCP exceeds the limit range, a Cat.2 stop is performed, with interlocked standstill detection + stopping distance + stopping time detection
[Trigger event]: The TCP pose exceeds the set range
[Robot response]: Fault alarm - safety plane/tool direction exceeded, Cat.2 stop action is executed, with interlocked standstill detection + stopping distance + stopping time detection

70.07272665

SF07

manual mode, reduced-speed

PL d

Monitoring of reduced-speed manual mode
When the controller mode is in manual reduced-speed mode, it detects whether the TCP speed is ≤250mm/s. If the speed is exceeded, a Cat.0 or Cat.1 stop action is executed, with interlocked position holding monitoring.
[Trigger event]: The TCP speed exceeds the set speed
[Robot response]: Fault alarm - TCP overspeed, Cat.0 or Cat.1 stop action is executed, with interlocked position holding monitoring.

70.07272665

SF08

TCP Force Limit

PL d

Monitoring of the TCP force limit
The controller can configure the TCP force limit. The safety circuit monitors the robot TCP force in real time. If the TCP force exceeds the limit value, a Cat.2 stop is performed, with interlocked standstill detection + stopping distance + stopping time detection
[Trigger event]: The TCP force exceeds the set limit
[Robot response]: Fault alarm - joint x collision fault, Cat.2 stop is performed, with interlocked standstill detection + stopping distance + stopping time detection

124.720124

SF09

Momentum Limit

PL d

Monitoring of the momentum limit
The controller can configure the robot momentum limit. The safety circuit monitors the robot momentum in real time. If the robot momentum exceeds the limit value, a Cat.2 stop is performed, with interlocked standstill detection + stopping distance + stopping time detection
[Trigger event]: The momentum exceeds the set momentum limit
[Robot response]: Fault alarm - momentum exceeded, Cat.2 stop is performed, with interlocked standstill detection + stopping distance + stopping time detection

67.48193213

SF10

Power Limit

PL d

Monitoring of the power limit
The controller can configure the robot power limit. The safety circuit monitors the robot power in real time. If the robot power exceeds the limit value, a Cat.2 stop is performed, with interlocked standstill detection + stopping distance + stopping time detection
[Trigger event]: The power exceeds the set power limit
[Robot response]: Fault alarm - power exceeded, Cat.2 stop is performed, with interlocked standstill detection + stopping distance + stopping time detection

67.48193213

SF11

System Emergency Stop Output

PL d

Monitoring of the System Emergency Stop Output
When the emergency stop signal is triggered, the controller outputs an emergency stop signal DO.
[Trigger event]: Emergency stop signal triggered
[Robot response]:
Emergency stop type 0: System emergency stop signal output
Emergency stop type 1: System emergency stop signal output

191.3170862

SF12

Robot Moving State Output

PL d

Monitoring of the Robot Moving State Output
When the robot is in the moving state, the controller outputs a motion signal DO
[Trigger event]: The robot is in the moving state
[Robot response]: Robot moving signal output

68.7283255

SF13

Robot Not Stopping State Output

PL d

Monitoring of the Robot Not Stopping State Output
When the robot is in the not stopping state, the controller outputs a not stopping signal DO
[Trigger event]: The robot is in the not stopping state
[Robot response]: Robot not stopping signal output

68.7283255

SF14

Reduced Mode State Output

PL d

Monitoring of the Reduced Mode State Output
When the robot is in the reduced state, the controller outputs a reduced signal DO
[Trigger event]: The robot is in reduced mode
[Robot response]: Reduced mode signal output

68.7283255

SF15

Not Reduced Mode State Output

PL d

Monitoring of the Not Reduced Mode State Output
When the robot is in the not reduced state, the controller outputs a not reduced signal DO
[Trigger event]: The robot is in not reduced mode
[Robot response]: Not reduced mode signal output

68.7283255

SF16

3P enabling function

PL d

3P enabling function
When the 3-position enabling switch is in position 1 or 3, the robot executes a Cat.2 stop, with interlocked standstill detection + stopping distance + stopping time detection
When the 3-position enabling switch is in position 2, the robot is enabled, with interlocked activation of manual reduced-speed mode and manual reduced-speed detection
[Trigger event]: In physical teach pendant mode, the 3-position enabling button is pressed to the middle position (position 2)
[Robot response]: Joints are enabled, joint safe brakes are released, the robot enters manual reduced-speed mode, with interlocked activation of manual reduced-speed mode and manual reduced-speed detection

68.7283255

SF17

monitored-standstill (after Cat.2 stop)

PL d

Monitored standstill
After the Cat.2 stop is completed, the safety circuit detects joint position changes according to the robot command and actual position. If the deviation exceeds the limit, a Cat.0 or Cat.1 stop is executed
[Trigger event]: When standstill and not running, the robot position changes abnormally
[Robot response]: The robot position change range exceeds the set value, and a Cat.0 or Cat.1 stop action is executed

60.05290188

SF18

stopping time limiting (after Cat.2 stop)

PL d

Monitoring of stopping time limit
After the Cat.2 stop signal is triggered, the safety circuit detects the stopping time according to the robot stop completion signal time. If the deviation exceeds the limit, a Cat.0 or Cat.1 stop is executed
[Trigger event]: When the robot triggers a stop
[Robot response]: When the robot triggers a stop, if the stopping time exceeds the set time, a Cat.0 or Cat.1 stop action is executed

60.05290188

SF19

stopping distance limiting (after Cat.2 stop)

PL d

Monitoring of stopping distance limit
When the Cat.2 stop signal is triggered, the robot position is recorded. The safety circuit obtains the stopping distance by subtracting the recorded position from the real-time actual position of the robot. If the deviation exceeds the limit, a Cat.0 or Cat.1 stop is executed
[Trigger event]: When the robot triggers a stop
[Robot response]: When the robot triggers a stop, if the stopping distance exceeds the set stopping distance, a Cat.0 or Cat.1 stop action is executed

60.05290188

SF20

hold-to-run control

PL d

Hold-to-run control
When the 3-position enabling switch enters the middle position and the controller is in manual mode, after the end button is pressed, the robot enters the dragging state
When the 3-position enabling switch enters the middle position and the controller is in manual mode, after the end button is released, the robot enters a Cat.2 stop, with interlocked standstill detection + stopping distance + stopping time detection
[Trigger event]: The 3-position enabling switch enters the middle position, the controller is in manual mode, and the end button is pressed
[Robot response]: The robot enters the dragging state
[Trigger event]: The 3-position enabling switch enters the middle position, the controller is in manual mode, and the end button is released
[Robot response]: The robot enters a Cat.2 stop, with interlocked standstill detection + stopping distance + stopping time detection

68.7283255

SF21

start/restart interlock

PL d

Start/restart interlock
On start/restart/mode switching, the Cat.2 safety stop state is triggered. After the stop is executed, the controller cannot move, with interlocked standstill detection. The stop state must be reset by resetting the safety stop through DI before further operations can be performed
[Trigger event]: Controller start/restart/mode switching
[Robot response]: Interlock triggered, entering Cat.2 safety stop

191.3170862

SF22

reset safety

PL d

Reset safety
When in the safety stop triggered state, first perform error/fault reset through DI. After the error/fault reset passes, perform stop state reset again through DI, and then the robot can exit the stop state
[Trigger event]: Safety stop state reset DI triggered
[Robot response]: The robot exits the safety stop

191.3170862

SF23

normal stop

PL d

Normal stop
During robot motion, a normal stop is triggered through a DI signal. According to the configured safety stop type, a Cat.0 or Cat.1 stop action is executed
[Trigger event]: Stop motion triggered
[Robot response]: The robot executes a Cat.0 or Cat.1 stop action, with interlocked position holding monitoring

191.3170862

SF24

mode activation

PL a

Mode activation
The controller mode can enter different modes through the software interface mode switch and the end button switch, including manual reduced-speed/manual high-speed/automatic/dragging
[Trigger event]: Software interface switch toggled
[Robot response]: The robot can switch between manual reduced-speed/manual high-speed/automatic modes, with interlocked manual reduced-speed monitoring/manual high-speed monitoring + manual high-speed time monitoring/manual reduced-speed monitoring/joint speed monitoring
[Trigger event]: End dragging switch toggled
[Robot response]: The robot can switch between manual reduced-speed/dragging modes, with interlocked manual reduced-speed monitoring/dragging speed monitoring/standstill monitoring

/

SF25

Position Holding Monitoring

PL d

Monitoring of the Position Holding
When the controller changes from the enabled state to the disabled state, the position is recorded during brake engagement, and it continuously detects whether the difference between the robot joint position and the recorded position exceeds the limit threshold. If the threshold is exceeded, a Cat.0 operation is executed
[Trigger event]: During brake engagement, the robot joint position change exceeds the threshold
[Robot response]: Cat.0 operation is executed

60.05290188

SF26

single-point-of-control (local/remote control mode)

PL a

single-point-of-control
The controller local mode and remote control mode are mutually exclusive. The mode is switched manually on the controller interface, and only one of them can be selected for control
[Trigger event]: Manually switch the control mode on the controller interface
[Robot response]: The controller can only select one mode at a time, shielding the operation of the other control source

/

SF27

external control enable

PL a

external control enable
The controller has a remote control mode. Entering and exiting the remote mode are both performed manually and locally on the controller interface. In this mode, other local control functions are shielded
[Trigger event]: Switch the remote control mode on the local interface
[Robot response]: The controller enters remote mode, shielding the operation of the local control source

/

SF28

manual mode, high-speed

PL d

Monitoring of high-speed manual mode
Click the manual high-speed switch button on the manual reduced-speed page. The controller can switch from manual reduced-speed to manual high-speed mode. The safety circuit detects whether the TCP speed is ≤1000mm/s. If the speed is exceeded, a Cat.0 or Cat.1 stop action is executed, with interlocked position holding monitoring
[Trigger event]: In high-speed mode, the TCP speed exceeds the set limit
[Robot response]: Deceleration stop is performed, fault alarm - TCP overspeed, Cat.0 or Cat.1 stop action is executed, with interlocked position holding monitoring

60.05290188

SF29

manual mode, high-speed time limitation

PL d

Monitoring of high-speed manual mode time limitation
When the controller mode is in manual high-speed mode and the 3-position switch exits the middle position, the safety circuit detects the duration. If it exceeds 5 min, the control box lowers the manual high-speed global speed to 25% (TCP speed 250mm/s), with interlocked corresponding speed monitoring (TCP speed ≤250mm/s)
[Trigger event]: In manual high-speed mode, the 3P switch is released for more than 5 min
[Robot response]: The control box lowers the manual high-speed speed to 250mm/s, with interlocked 250mm/s monitoring

49.81517752

SF30

hand-guided control

PL d

Monitoring of hand-guided control
When the 3-position switch is in the middle position and the end dragging button is pressed, the controller mode enters dragging mode. The safety circuit detects whether the TCP speed is ≤250mm/s (configurable speed limit), each joint speed is ≤45°/s (monitored through SF04, configurable speed limit, configurable Cat.0/Cat.1), each joint position limit (monitored through SF03, configurable range, Cat.2), and TCP pose limit (monitored through SF06, configurable range, Cat.2). If the speed is exceeded, a Cat.0 or Cat.1 stop action is executed, with interlocked position holding monitoring
[Trigger event]: The TCP speed exceeds the dragging limit speed (default 250mm/s, adjustable)
[Robot response]: Deceleration stop is performed, fault alarm - TCP overspeed, Cat.0 or Cat.1 stop action is executed, with interlocked position holding monitoring

49.81517752

SF31

Speed and separation monitoring (SSM)

PL d

Speed and separation monitoring
When the controller mode is in automatic mode, the photoelectric switch/distance sensing switch externally connected through the control box DI detects the relative position of the machine and personnel. When the corresponding distance DI receives a signal, the control box performs a safety response. According to the corresponding distance, it enters level 1 reduction (configurable speed, default 200mm/s), level 2 reduction (configurable speed, default 100mm/s), or level 3 reduction (stop motion). At the same time, the safety circuit enters speed and separation monitoring. If the speed after entering reduction exceeds the speed corresponding to the corresponding reduction level, a Cat.0 or Cat.1 stop action is executed, with interlocked position holding monitoring
[Trigger event]: The TCP speed exceeds the set speed
[Robot response]: Deceleration stop is performed, fault alarm - TCP overspeed, Cat.0 or Cat.1 stop action is executed, with interlocked position holding monitoring

60.05290188

Note

Note: *MTTFd: Mean Time to Dangerous Failure (unit: years).

7.6.2. Joint Speed Limit

After functional safety is enabled, this function monitors the robot’s joint feedback speed. When the motion speed exceeds the set value, a safety stop is executed.

The joint limit speed range is 1-180°/s, and the default is 45°/s.

../_images/03410.png

Figure 7.5-1 Joint speed limit monitoring

Note

Note: When disabled, the function does not take effect; after being enabled, the function takes effect and monitoring begins.

7.6.3. Manual Mode - Reduced Speed

After functional safety is enabled, this function monitors the robot’s feedback TCP speed in manual reduced-speed mode. When the motion speed exceeds the set value, a safety stop is executed.

The TCP limit speed range is 1-1000mm/s, and the default is 250mm/s.

../_images/03510.png

Figure 7.5-2 Manual mode - reduced-speed monitoring

7.6.4. Manual Mode - High Speed

After functional safety is enabled, this function monitors the robot’s feedback TCP speed in manual high-speed mode (using the TCP speed corresponding to the interface global speed as the limit). When the motion speed exceeds the set value, a safety stop is executed. After a speed exceeding 250mm/s is set, the disable time in manual high-speed mode is monitored. When the disable time exceeds the set value, the manual speed is reduced to 250mm/s.

The speed timeout range is 1-1000min, and the default is 5min.

../_images/03610.png

Figure 7.5-3 Manual mode - high-speed monitoring

7.6.5. Dragging Speed Monitoring

After functional safety is enabled, this function monitors the robot’s feedback TCP speed in dragging mode. When the dragging speed exceeds the set value, a safety stop is executed.

The TCP limit speed range is 1-1000mm/s, and the default is 250mm/s.

../_images/03710.png

Figure 7.5-4 Dragging speed monitoring

7.6.6. Position Holding Monitoring

After functional safety is enabled, this function is used to monitor the robot position after it is disabled. When the change amount of each joint exceeds the set value, a safety stop is executed.

The TCP limit speed range is 1-1000mm/s.

../_images/0389.png

Figure 7.5-5 Position holding monitoring

7.6.7. Manual High-Speed Mode

After functional safety is enabled, on the manual reduced-speed interface, click the “Enter Manual High Speed” button to enter manual high-speed mode. In this mode, the speed of JOG motion and command motion is not reduced.

../_images/0399.png

Figure 7.5-6 Manual high-speed mode

7.6.8. Normal Stop

After functional safety is enabled, on the safety CI page, the “Normal Stop” digital input option can be selected. When the corresponding CI is triggered, the robot stops according to the configured protective stop level.

../_images/0409.png

Figure 7.5-7 Normal stop

7.6.9. Safety Wall

After functional safety is enabled, on the safety CI page, the digital input options “Safety Wall 1” to “Safety Wall 8” can be selected. When the corresponding CI is triggered, the robot activates the corresponding safety wall monitoring. If it enters the safety wall limit range, the robot stops according to the configured protective stop level.

../_images/0418.png

Figure 7.5-8 Safety wall

7.6.10. Reset Safety Stop State

After functional safety is enabled, on the safety CI page, the “Reset Safety Stop State” digital input option can be selected. When the corresponding CI is triggered, the robot clears the safety stop error code, and the controller can perform operations.

../_images/0429.png

Figure 7.5-8 Reset safety stop state

7.6.11. Joint Torque Limit

Joint torque limit is a safety monitoring function. After it is enabled, the system monitors the torque of each joint in real time. When the actual torque of any joint exceeds the set torque limit percentage, the robot immediately stops running, and the interface prompts a joint torque limit exceeded fault.

The setting percentage range is 1%-100%, and the default is 100%;

../_images/04310.png

Figure 7.5-9 Joint torque limit percentage

Corresponding fault handling suggestions:

  1. If the limit exceeded fault is still frequently triggered under the 100% limit, it indicates that the current working condition is close to the robot’s performance limit. It is recommended to first reduce the running speed or reduce the load/inertia.

  2. If the fault still occurs after adjustment, it indicates that the task requirements may exceed the physical capability of the robot, and the operation plan needs to be re-evaluated.