The KUKA KR C5 micro is a controller platform designed for small robots, compact workstations, and limited installation spaces. It is equipped with the KUKA iiQKA.OS operating system, supports up to 6 servo axes, weighs approximately 9.8 kg, has an IP20 protection level, and produces noise levels below 54 dB (A). Unlike large cabinet controllers, the KR C5 micro integrates the control box, drive box, safety logic, interface board, and cooling system into a flat or vertical housing, which can be placed independently, stacked, wall mounted, 19 inch rack mounted, or used as a panel mounted variant. For on-site engineers, the most important concerns are how to identify the control box and drive box, how to configure safety chains, how to wire, how to power on, how to replace modules, and where to start checking after an alarm. This article revolves around these practical issues.
System architecture: division of labor between control box and drive box
The KR C5 micro consists of a control unit and a power unit. The control unit, also known as the control box, contains a mini CSP, button battery, SSD hard drive, system board, IFBstd interface board, internal SSD storage, and fan. The system board is responsible for controlling the computer, including graphical interfaces, program creation and modification, path planning, sequence control, drive loop control, monitoring, safety equipment communication, and external device communication. The IFBstd interface board provides non secure digital I/O and is connected to the system board through a ribbon cable; The system board is connected to KSP through ICT plug and is powered by KSP. Mini CSP is a status display component that provides feedback on operating mode, operating status, errors, and sleep status through LED1 to LED4 and a soft power button.
The drive box, also known as the drive box, includes a fan, main filter, braking resistor, radiator, and KSP-300 drive controller. KSP-300 consists of FCU-300 and SCU-6-1S, responsible for generating intermediate circuit voltage and system voltage, controlling motors, controlling brakes, and checking intermediate circuit voltage in braking mode. It should be noted that the power unit of the drive box cannot be opened arbitrarily, otherwise it may cause serious injury or property damage.
The rated power supply of KR C5 micro is AC 1 × 200 V to 240 V, single-phase or two-phase, with an allowable deviation of ± 10%. The rated connection power is 1.30 kVA, the system impedance is not greater than 300 m Ω, the ground leakage current is not greater than 10 mA, the main power side fuse is 1 × 16 A slow melting C-type, the frequency is 50 to 60 Hz, and the maximum thermal output is 250 W. The equipment side fuse is 2 × 10 A slow melting C-type. The operating temperature is -5 ℃ to+45 ℃, and the storage and transportation temperature is -20 ℃ to+60 ℃. Humidity level 3K4, maximum temperature change of 1 K/min, no derating below 2000 m altitude, 5% derating every 1000 m from 2000 to 3000 m, pollution level 2. In terms of vibration, the continuous vibration during operation and transportation is 3 g, with a frequency of 10 to 2000 Hz; the impact operation is 10 g, with a half sine of 11 ms. If the mechanical stress is greater, anti vibration components must be installed.
Security Chain: STOP, CRR, and Security Interface
The safety features of KR C5 micro comply with Category 3 and Performance Level d of EN ISO 13849-1, while also meeting SIL 2 of EN 62061. The premise is that all safety related mechanical and electromechanical components undergo functional testing at start-up and at least once every 12 months, including emergency stop devices on smartPAD, external emergency stop devices, enable devices on smartPAD, enable devices on Commander, external enable devices, and safety outputs of discrete safety interfaces.
Safe stops are divided into STOP 0, STOP 1 (HRC), STOP 1 (path marking), and STOP 2. STOP 0 immediately cuts off the drive and applies the brake, and the robot stops in a path guided manner. STOP 1 (HRC) is used for human-machine collaboration, where the robot switches to soft control with enhanced damping to reduce external forces and stop. The robot will deviate from its path, cut off the drive and apply the brake after coming to a stop; The safety controller monitors the Cartesian speed and external shaft torque, and applies the brake and cuts off the drive no later than 1 second later. STOP 1 (path marking) maintains path braking, cuts off the drive and applies the brake when stationary, and applies the brake and cuts off the drive no later than 1.5 seconds later. STOP 2 does not cut off the drive, does not apply the brake, and maintains a braking ramp deceleration path.
CRR, also known as Controlled Robot Retraction, is an optional operating mode when the safety controller stops the robot due to the following reasons: the robot violates the axis specific or Cartesian monitoring space, the tool direction exceeds the allowable range, the robot violates collision detection or maximum TCP force monitoring, one or more axes are not mastering, one or more axis positions are not mastering confirmed, one or more joint torque sensor calibration is not confirmed, the maximum Cartesian speed is exceeded, and the axis maximum torque is exceeded (such as in compression situations). After switching to CRR mode, the robot can move again. If the reason for stopping no longer exists and there are no further stop requests within 4 seconds, the operation mode will automatically switch to T1. The speed limit in CRR mode is the same as T1: program validation maximum 250 mm/s, jog maximum 250 mm/s, manual guidance does not limit speed but is limited by the safety guidance speed monitoring in the safety configuration.
In terms of security interface, XG11.1 provides 2 security inputs and 1 security output. The default configuration is: security output 1 is for local emergency stop, security input 1 is for external emergency stop, and security input 2 is for operational safety. XG58 provides 2 safety inputs for external enable switches and additional emergency stops. The secure input adopts a dual channel design with external testing and loop detection shutdown capability. The test outputs TA_S and TA_S are alternately turned off, with a turn off pulse length of 600 μ s, a single channel turn off period of less than 1 second, and a 50 ms offset between the two channels. The input channel N_A [x] must be powered by TA_S, and N_B [x] must be powered by TA_S, and no other power sources must be used. Only sensors that can access test signals and provide floating contacts are allowed to be connected.
The safety rule set includes Operator Devices (emergency stop, enable), Velocity Monitoring (T1/CRR maximum 250 mm/s, manual guidance default 500 mm/s or 900 mm/s, global maximum 2000 mm/s default disabled), Standard Safety Interface (safety door, external emergency stop), HRC (transient contact) (collision detection 30 Nm, speed 500 mm/s). The operation safety signal is used to monitor physical protection such as safety doors. In automatic mode, it can only move when the operation safety signal is set or the robot is manually guided. Operation safety is not activated by default in T1 and CRR modes, and signals are not evaluated. If there is no physical protection, the collaborative operation requirements of EN ISO 10218 must be met.
Interface layout and wiring
The interfaces of KR C5 micro are concentrated on the front and rear panels. The front panel includes XFUSB1 and XFUSB2 for USB 3.0; XF1 to XF8 are Ethernet and EtherCAT interfaces, and the specific allocation depends on the system software; XGDP is DisplayPort DP 1.2; XGSD is used for microSD cards; XG19 is used for smartPAD connection; XD12 and XD12.1 are 24V power supplies; XG12 provides 16 digital inputs and 16 digital outputs; XD20.1 is used for motor interfaces of axes A1 to A3; XD20.2 is used for motor interfaces of axes A4 to A6; XG33 provides 3 fast measurement inputs and 1 Drive ready light output; XF21 is used for RDC or TPC; XG58 is a secure interface; XG11.1 is a secure interface.
The rear panel includes: device switches, fuses F1 and F2, power connection interface XD1, and interface XD2 for UPS 24V power supply and daisy chain connection. XD1 pins are L1, N, and PE. The power connection uses the inlet C15 of the 3-pole high-temperature appliance, and the equipment within the supply scope must be connected with cables or main power connectors. Single phase power supply is AC 200 to 240 V ± 10%, single-phase TN system or single-phase three wire system; Two phase power supply is 208 Y/120 V or 240 Y/131 V, solidly grounded wye, three-phase four wire, must be connected to two phases, ensuring that the power supply voltage is within the range of 200 to 240 V ± 10%, and the two phases are as symmetrical as possible. Device side fuse 2 × 10A slow melting C-type.
XG12 digital I/O can be configured in high side or low side mode. Jumpers 1 to 2 switch inputs 1 to 8 to low side, jumpers 3 to 4 switch inputs 9 to 16 to low side, jumpers 5 to 6 switch outputs 1 to 8 to low side, and jumpers 7 to 8 switch outputs 9 to 16 to low side. Default high side. The power supply is provided through XD12 and must use a safely isolated PELV/SELV power supply, rated at 24 V ± 10%, with a maximum fuse of 10 A.
In XF1 to XF8, XF1 is the KSI service interface, XF2 is the KLI IT, XF3 and XF4 are daisy chains, XF5 and XF6 are the KLI OT, XF7 is KONI, and XF8 is KEI. The KSI interface must not be connected to IT networks, with a maximum cable length of 100 m. The KLI interface can be connected to OT or IT networks for terminal, update services, diagnostics, with a maximum cable length of 100 m. The KEI interface is used to connect external EtherCAT slave stations. The maximum cable length for XGDP is 5 meters. The maximum cable length for the Drive ready light output of XG33 is 50 meters. The maximum cable length for the RDC/TPC connection of XF21 is 50 meters.
The motor interfaces XD20.1 and XD20.2 have the same design, but are distinguished by different non interchangeable codes (Type A and Type B). XD20.1 connects M1 to M3, XD20.2 connects M4 to M6. The brake interface is also integrated into it. The connecting cable must be laid separately from the data cable, with a fixed installation bending radius of 3 to 5 times the cable diameter, and a drag chain installation radius of 7 to 10 times. The length of motor cables and data cables between the controller and the robot must not exceed 25 meters. After replacing the data cables, it is necessary to re master or perform master tests on all axes.

Installation, power on, and initial debugging
The KR C5 micro can be installed horizontally or vertically, with or without a bracket, stackable, can be installed in a 19 inch rack, wall mounted, or as a panel mounted variant. The minimum distance must be observed during installation: at least 150 mm between the front (air inlet) of the robot controller and the housing, and at least 100 mm between the rear (air outlet) and the housing. If wall mounted, additional fire protection measures must be taken and can only be used or equipped with drip protection inside the fireproof housing. The front and rear must always be able to come into contact with cooling air. Stacking up to 3 controllers, the lower controller should be fixed on the ground, and the upper controller should be installed diagonally using 4 brackets. 19 inch rack installation requires the use of an installation frame with a minimum insertion depth of 700 mm. When installing the bracket, M5 screws are used for horizontal installation and M6 screws are used for vertical installation.
The equipotential connection must be completed before power on: a 4 mm ² cable is used between the robotic arm and the controller; An additional PE conductor of 4 mm ² is recommended to be used between the central PE row of the power supply cabinet and the PE connection of the controller. Two PE connection points are provided on the front or back of the controller.
Pre power on inspection: visually inspect for no condensation or damage; Install strain relief plates; Connect equipotential; Connect motor cables, data cables, and power cables; Insert smartPAD; Configure and connect security interfaces XG11.1 and XG58 (must be plugged in and out when the controller is turned off); Connect Ethernet and EtherCAT interfaces; Connect optional interfaces. Power on steps: Release the emergency stop on the smartPAD, turn on the device switch, and control the PC to start. The startup sequence is recovery stick, external hard drive, and internal hard drive; If an external hard drive is detected, the internal hard drive will be disabled; If no external hard drive is detected, it will not automatically switch to an internal hard drive. The robot controller can only run with the connected smartPAD.
Functional testing must be performed: after all connected emergency stop devices are pressed, smartPAD displays that the emergency stop has been triggered and does not display any emergency stop device errors; After all enable switches are released in test mode, the robot stops without displaying any enable device errors; Press and hold the panic function of all enable switches for 3 seconds, and the robot will stop without any errors; Safety output shutdown capability test, after turning off and then turning on the controller, smartPAD does not display safety output errors; The brake test is performed on each axis during initial start-up and re commissioning, and every 48 hours during operation, unless otherwise specified in the risk assessment.
IT Security and iiQKA.OS Features
KUKA iiQKA.OS is based on Linux, and IT security is an important component of product usage. System integrators and users must ensure that the system operates in an IT environment that complies with current security standards and establish an overall IT security concept. KUKA strongly recommends implementing an information security management system. Active support must be maintained throughout the product support lifecycle, and discontinued components must not be used. The latest information is provided and updated in KUKA Xpert.
Physical access protection: Only authorized and trained personnel can physically access the system and components. Network connectivity: The system has IT and OT network interfaces, and when crossing trust boundaries, threats and risks must be considered and additional measures taken. Access management: The default password must be changed immediately after delivery, and passwords that are easy to guess must not be used. User role automatic logout: User 30 minutes, Administrator 10 minutes, Safety Commissioning Engineer 5 minutes. All user roles must use strong passwords, adhere to the minimum privilege principle, and regularly check permissions.
Software updates: KUKA provides software updates and upgrades, and security updates if necessary, which must be implemented according to specific customer requirements. Data backup: It is necessary to establish the concept of data backup to ensure that data can be recovered in case of loss. USB interface: Only allows connection to trusted USB devices, only writes content from trusted sources, checks with antivirus software if necessary, backup data may contain sensitive information, and appropriate IT security measures need to be taken. Customer Service Access: The system has emergency SSH access to the Linux kernel system, which is not enabled by default and can only be used by customers and KUKA customers when accessing locally. Temporary activation through HMI or KSI interface requires administrator privileges. After activation, SSH service is activated on TCP port 22 and automatically disabled after 30 minutes. SSH access is used for emergency analysis or repair and may no longer be available in future versions. Developer mode: can be activated through the administrator role, and after activation, SSH services can be accessed on port 22. Users can log in through SSH and install specially signed extensions. After exiting developer mode, SSH access is disabled and the system is reset.
Firewall: The system has a firewall that blocks unexpected network access. The standard installation allows inbound connections including: KLI IT interface TCP 22 (SSH client service access), TCP 80 (HTTP license information); The KLI OT interface is the same; KONI interface TCP 22; KSI interfaces TCP 22, TCP 80, TCP 49162 (enable customer service access). Starting from system software 1.1, firewall configuration can be viewed in system settings, and the KLI OT interface also allows TCP 44818 and UDP 2222 (EtherNet/IP, can be disabled). The optional toolbox may open additional ports. Encryption communication: HTTPS is used for my.kuka.com and KUKA update services, SSH is used for local client PCs or client service PCs, except for DHCP, DNS, and HTTP license information. Use TLS 1.2/1.3, SSH 2.0, chacha20-poly1305, AES series, curve25519, eccdh, diffie hellman group exchange, 4096 bit RSA and SHA-256, Argon2 cryptographic hashing. Software update check: Check for integrity and valid encrypted signatures before installation, only accepting software with KUKA signatures. Preventing the installation of old software: can only be upgraded, not downgraded. System segmentation: Isolate software components and services, restrict permissions. Remove non essential components: reduce attack surface. System shutdown: Currently, the function of securely deleting the complete system is not provided. You need to contact KUKA customer support or remove the hard drive and logically erase and physically destroy it according to local IT security policies.
Maintenance and module replacement
Maintenance work must be carried out after the controller is turned off, tagged and locked, and the power cable is unplugged. After a power outage, there may be residual voltage of 60 to 800 V in the intermediate circuit for up to 5 minutes, and at least 5 minutes must be waited for. KSP、 Motor connectors and connected motor cables may remain energized. The homework must comply with ESD regulations. Maintenance table requirement: Conduct annual cyclic functional testing on operational safety and all emergency stop devices; Test all enable switches; Test external enabling devices; Test the Drives ready light before entering the danger zone each time; Clean the fan protective grille according to the degree of pollution; Replace the system board battery every 10 years. Check if the plug connection is secure and inspect all system components for wear or damage.
Module replacement includes: replacing strain relief board, replacing 19 inch mounting frame, replacing SSD hard drive, replacing system board battery, replacing input fuse, replacing system board, replacing interface board, replacing microSD card and internal SSD. General steps: Turn off the device switch and unplug the power cable; Wait for 5 minutes; Open the shell cover; Disconnect the plug connection; Replace components; Install the housing cover and tighten with a torque of 0.6 Nm; perform a power on inspection. When replacing the system board, be careful not to damage it by connecting it to the power unit through a vertically installed connection board. When replacing the interface board, disconnect the ribbon cable X1000. After replacing the battery, you need to plug in the USB keyboard, enter the BIOS to set the date and time, load the default values, and perform a functional test. After replacing the SSD, it is necessary to check the settings and perform functional testing. Replace fuses F1/F2 with 10 A 250 V slow melting 5 × 20 mm.
Troubleshooting: System board LED and common problems
There is an LED on the system board that lights up in red when there is a malfunction, which can be seen through the opening of the cooling system air inlet. If the system board LED lights up red, the controller should be turned off, the power cable should be unplugged, and the cable should be stored out of sight and reach. Contact KUKA customer support.
Common problem troubleshooting: Controller unable to power on: Check device switch, fuse F1/F2, power cable, XD1 connection. Startup failure after power on: Check the recovery stick, external hard drive, and internal hard drive. If an external hard drive is detected, the internal hard drive will be disabled. If there is no external hard drive, it will not automatically switch. The safety stop cannot be cancelled: check the emergency stop device, enable switch, operation safety signal, external emergency stop, and safety interface configuration. CRR mode cannot be switched: check if the reason for stopping still exists, if so, it cannot be switched to CRR; If the cause disappears and there is no stop request within 4 seconds, it will automatically switch to T1. The enable switch is invalid: check the smartPAD enable switch, Commander enable switch, security configuration, and XG58 external enable connection. The drives ready light is not on: check the XG33 connection, drive enable signal, and safety controller. Communication interruption: Check if the XF1 to XF8 interfaces and KSI interface are mistakenly connected to the IT network, KLI interface, KEI interface, firewall rules, cable length, and shielding. Heat dissipation issues: Check the fan, protective grille, minimum spacing, and ambient temperature. Battery failure: Replace the system board battery every 10 years and set the BIOS date and time after replacement.
