The equipotential connection must be completed before power on: a 4 mm ² cable is used between the robotic arm and the controller; An additional PE conductor of 4 mm ² is recommended to be used between the central PE row of the power supply cabinet and the PE connection of the controller. Two PE connection points are provided on the front or back of the controller.
Pre power on inspection: visually inspect for no condensation or damage; Install strain relief plates; Connect equipotential; Connect motor cables, data cables, and power cables; Insert smartPAD; Configure and connect security interfaces XG11.1 and XG58 (must be plugged in and out when the controller is turned off); Connect Ethernet and EtherCAT interfaces; Connect optional interfaces. Power on steps: Release the emergency stop on the smartPAD, turn on the device switch, and control the PC to start. The startup sequence is recovery stick, external hard drive, and internal hard drive; If an external hard drive is detected, the internal hard drive will be disabled; If no external hard drive is detected, it will not automatically switch to an internal hard drive. The robot controller can only run with the connected smartPAD.
Functional testing must be performed: after all connected emergency stop devices are pressed, smartPAD displays that the emergency stop has been triggered and does not display any emergency stop device errors; After all enable switches are released in test mode, the robot stops without displaying any enable device errors; Press and hold the panic function of all enable switches for 3 seconds, and the robot will stop without any errors; Safety output shutdown capability test, after turning off and then turning on the controller, smartPAD does not display safety output errors; The brake test is performed on each axis during initial start-up and re commissioning, and every 48 hours during operation, unless otherwise specified in the risk assessment.
IT Security and iiQKA.OS Features
KUKA iiQKA.OS is based on Linux, and IT security is an important component of product usage. System integrators and users must ensure that the system operates in an IT environment that complies with current security standards and establish an overall IT security concept. KUKA strongly recommends implementing an information security management system. Active support must be maintained throughout the product support lifecycle, and discontinued components must not be used. The latest information is provided and updated in KUKA Xpert.
Physical access protection: Only authorized and trained personnel can physically access the system and components. Network connectivity: The system has IT and OT network interfaces, and when crossing trust boundaries, threats and risks must be considered and additional measures taken. Access management: The default password must be changed immediately after delivery, and passwords that are easy to guess must not be used. User role automatic logout: User 30 minutes, Administrator 10 minutes, Safety Commissioning Engineer 5 minutes. All user roles must use strong passwords, adhere to the minimum privilege principle, and regularly check permissions.
Software updates: KUKA provides software updates and upgrades, and security updates if necessary, which must be implemented according to specific customer requirements. Data backup: It is necessary to establish the concept of data backup to ensure that data can be recovered in case of loss. USB interface: Only allows connection to trusted USB devices, only writes content from trusted sources, checks with antivirus software if necessary, backup data may contain sensitive information, and appropriate IT security measures need to be taken. Customer Service Access: The system has emergency SSH access to the Linux kernel system, which is not enabled by default and can only be used by customers and KUKA customers when accessing locally. Temporary activation through HMI or KSI interface requires administrator privileges. After activation, SSH service is activated on TCP port 22 and automatically disabled after 30 minutes. SSH access is used for emergency analysis or repair and may no longer be available in future versions. Developer mode: can be activated through the administrator role, and after activation, SSH services can be accessed on port 22. Users can log in through SSH and install specially signed extensions. After exiting developer mode, SSH access is disabled and the system is reset.
Firewall: The system has a firewall that blocks unexpected network access. The standard installation allows inbound connections including: KLI IT interface TCP 22 (SSH client service access), TCP 80 (HTTP license information); The KLI OT interface is the same; KONI interface TCP 22; KSI interfaces TCP 22, TCP 80, TCP 49162 (enable customer service access). Starting from system software 1.1, firewall configuration can be viewed in system settings, and the KLI OT interface also allows TCP 44818 and UDP 2222 (EtherNet/IP, can be disabled). The optional toolbox may open additional ports. Encryption communication: HTTPS is used for my.kuka.com and KUKA update services, SSH is used for local client PCs or client service PCs, except for DHCP, DNS, and HTTP license information. Use TLS 1.2/1.3, SSH 2.0, chacha20-poly1305, AES series, curve25519, eccdh, diffie hellman group exchange, 4096 bit RSA and SHA-256, Argon2 cryptographic hashing. Software update check: Check for integrity and valid encrypted signatures before installation, only accepting software with KUKA signatures. Preventing the installation of old software: can only be upgraded, not downgraded. System segmentation: Isolate software components and services, restrict permissions. Remove non essential components: reduce attack surface. System shutdown: Currently, the function of securely deleting the complete system is not provided. You need to contact KUKA customer support or remove the hard drive and logically erase and physically destroy it according to local IT security policies.