KUKA Sunrise Cabinet Med is a robot controller launched by KUKA for medical device manufacturers, specifically designed for operating LBR Med lightweight robots. It adopts a 19 inch chassis, weighs about 23 kg, has a protection level of IP20, and an average noise of about 54 dB (A). The power supply is 110 V/230 V AC single-phase, with an allowable deviation of ± 10%. The frequency is 50 Hz ± 1 Hz or 60 Hz ± 1 Hz, and the rated power is about 1 kVA. The maximum heat dissipation is 370 W. It is recommended to use 2x16 A slow melting on the power supply side and 2x10 A slow melting on the equipment side. The control cabinet must be connected to a power system with a grounded neutral point, which belongs to Class I protection equipment. The operating environment temperature is from+5 ° C to+45 ° C, the storage and transportation with batteries is from -25 ° C to+40 ° C, and without batteries is from -25 ° C to+70 ° C, with a relative humidity of 5% to 85%. Below an altitude of 1000 meters, there is no need to reduce the rating. Below 3000 meters, the rating will be reduced by 5% per 1000 meters. The controller can be installed in a 19 inch rack with a depth of at least 600 mm, and a 70 mm cooling air gap must be left on both sides. When installed vertically, the fan opening and ventilation duct must not face upwards. For medical equipment manufacturers and on-site engineers, mastering their medical integration requirements, safety interfaces, maintenance cycles, LED diagnostics, fuse specifications, and component replacement processes is key to ensuring the safe and reliable operation of the system.
Key points of system architecture and medical integration
KUKA Sunrise Cabinet Med consists of a control PC, CCU_SR, low-voltage power supply, battery, fan, interface, and connection panel. The control PC adopts D3445-K motherboard, providing 4 USB 2.0, 2 USB 3.0, Display Port, DVI-D, and LAN Onboard interfaces. CCU_SR stands for Small Robot Cabinet Control Unit, consisting of CIB_SR and PMB_SR. It is the central power distribution and communication interface, responsible for safety input and output, contactor activation, 3 floating outputs, 7 safety inputs, teaching pendant connection, power fan monitoring, and temperature detection inside the control box. The low-voltage power supply supplies power to the control cabinet components and provides 48 V DC for the robot drive, with two green and two red LEDs indicating the working status. The battery maintains a controlled shutdown in case of power failure, charges through CCU_SR, and checks the battery level.
In terms of medical integration, KUKA Sunrise Cabinet Med is only allowed to operate LBR Med and is integrated into medical devices by medical device manufacturers. It has passed the CB system test and comes with a CB test certificate, and only the software components specified in the CB test report are compatible with each other. Medical equipment manufacturers must ensure that devices connected to the controller interface meet the isolation requirements of IEC 60601-1: 2 x MOOP and 1 x MOPP, based on a maximum 230 V AC power supply voltage, corresponding to at least 3.4 mm electrical clearance, 5.0 mm creepage distance, and 3000 V dielectric strength. When connecting devices, medical equipment manufacturers must verify that the leakage current limit complies with IEC 60601-1 and consider the requirements of the ME system. The controller interface only allows connections to devices that meet the operator's protective measures, and devices that require patient protection measures must not be connected to the controller interface. Medical device manufacturers must also evaluate the entire system, including all devices connected to interfaces, during the risk management process. The controller must not be accessed by patients or unauthorized personnel, and an additional cover plate should be used, which can only be opened by maintenance personnel using tools. The controller is not suitable for direct operation in a sterile environment. If the intended use of the medical device requires it, the medical device manufacturer must take additional measures, such as attaching a casing.
Security features and X11 interface
The safety oriented function of KUKA Sunrise Cabinet Med complies with EN ISO 13849-1 Category 3 and Performance Level d, as well as EN 62061 SIL 2. The safety oriented function is used to protect personnel and must be tested at least once a year, unless otherwise specified in the workplace risk assessment. The test objects include local emergency stop devices, teaching pendant enabling devices, manual guidance enabling devices, external enabling devices, smartPAD mode selection switches, and safety oriented outputs of discrete safety interfaces. The non safety oriented function is used to protect the machine, including mode selection, T1 speed monitoring, and software limit switches. The speed monitoring limit in T1 mode is 250 mm/s, and 250 mm/s is pre configured for manual guidance, but can be adjusted according to risk management. The software limit switch is only used for machine protection, and stops under servo control when the axis exceeds the limit.
The safety stop categories include Stop 0, Stop 1, and Stop 1 (path preservation). Stop 0 immediately disconnect the safety guidance drive energy and apply the brake; Stop 1: Brake in a path keeping manner, disconnect the drive and apply the brake after stopping; Stop 1 (path maintenance) is triggered and monitored by the safety controller, and the brake should be applied and the drive disconnected no later than 1 second later. After the emergency stop device is pressed, the robot stops with safe stop 1 (path maintenance). Enable the switch to release or press to the bottom, triggering safety stop 1 (path maintenance). The operator safety signal is used to monitor the safety door and is valid by default in T2 and automatic modes. Loss of signal triggers safety stop 1 (path maintenance). Before restoring automatic operation, it must be confirmed through an external confirmation button, and cannot be restored solely by closing the safety door. The external emergency stop device is connected through a secure interface and triggers secure stop 1 (path maintenance). External security stop 1 (path hold) is triggered through a security interface input. When the signal is False, it remains stopped, and when it is True, it can be moved without confirmation. External enabling devices are used for multiple people entering hazardous areas or manual guidance, where the robot can only move at a reduced speed during manual guidance. The external safety operation stop is a static monitoring function that does not stop movement, only monitors whether the axis is stationary.
The X11 security interface is a 50 pin D-Sub connector, which is internally connected to CCU_SR. In the default configuration, safety input 1 is external emergency stop, safety input 2 is operator safety, safety input 3 is safety stop 1, safety output 12 is local emergency stop, output 13 is test mode, and output 14 is automatic mode. Test outputs A and B provide pulse voltage, which is only used for the safety input of the corresponding channel and cannot be used as a regular power supply. During dynamic testing, the test output is alternately turned off, with a turn off pulse length t1 of 625 μ s and a range of 125 μ s to 2.375 ms. The time t2 between two turn off pulses on the same channel is 106 ms, and the offset t3 between two turn off pulses on the same channel is 53 ms. The input channel SIN_X_A must be powered by TA_S, and SIN_X_B must be powered by TA-B. The safety output is a dual channel floating relay output, and the power supply must come from a power source that meets 2 x MOOP safety isolation. When wiring, input signals and test signals, output signals and test signals must be separated to prevent cross connections. The wiring example can achieve SIL2 and Cat. 3.

Maintenance cycle and inspection
The maintenance work of KUKA Sunrise Cabinet Med should be carried out on a periodic basis. Check annually whether the relay outputs used by CCU_SR are normal. Default output 12 is local emergency stop, output 13 is test mode, and output 14 is automatic mode; After triggering the corresponding function, if there is no error message, it indicates that the relay output is normal. Clean the fan protective grille and fan at least annually based on installation conditions and pollution levels. Replace the motherboard battery every 5 years; Replace the fan every 5 years under 3 operating conditions. The battery replacement cycle is based on the battery monitoring display, with a latest of 2 years. After maintenance, visually inspect the fuses, contactors, plugs, and boards for secure installation, no damage to cables, reliable PE equipotential connections, and no wear or damage to system components.
When cleaning the control cabinet, it is necessary to turn off the power and prevent accidental restarts, disconnect the power cable, and comply with ESD regulations. Wipe the casing with a mild cleaner and clean the cables, plastic parts, and hoses with a solvent-free cleaner. Do not use compressed air, do not spray water, and do not allow cleaning agents to enter electrical components. Replace damaged or unreadable labels and nameplates after cleaning. The battery should be charged every 9 months when the storage temperature is not higher than+20 ° C, every 6 months when the temperature is between+20 ° C and+30 ° C, and every 3 months when the temperature is between+30 ° C and+40 ° C to prevent deep discharge damage. Fuses may corrode after prolonged transportation or storage at temperatures below 0 ° C and high humidity, and their functionality must be checked after transportation and storage.
CCU_SR LED diagnosis
The LED on CCU_SR is the first-hand information for fault diagnosis. PHY4 and SW-P0 are green, constantly on or flashing indicates normal, and off indicates a fault. Usually, CCU_SR needs to be replaced. RUNSION EtherCAT safety node is green, off indicates initialization, constantly on indicates normal operation, flashing at 2.5 Hz indicates Pre Op, single signal indicates Safe Op, flashing at 10 Hz indicates firmware update boot. L/A green or orange indicates physical connection and data traffic: green constantly on indicates physical connection, off indicates no connection, flashing indicates data traffic; Orange represents 1 Gbit, green represents 100 Mbit. PWR/3.3 V, PWR/2.5 V, and PWR/1.2 V are green power indicators. When turned off, check the F17.3, X308 jumper plugs, F308, and external 24V power supply; If PWR/3.3 V is on and PWRS/3.3 V is off, consider replacing CCU_SR. When PWRS/3.3 V is turned off, check F17.3. If PWR/3.3 V is on, replace CCU_SR.
STAS2 and STAS1 are orange safety node indicator lights: check F17.3 when they are off, and replace CCU_SR if PWR/3.3 V is on; 1 Hz flicker is normal, 10 Hz flicker is the guiding phase; When the fault code flashes, check the X309, X310, and X312 cables. You can disconnect these cables and restart the controller. FSoE green indicates EtherCAT security protocol: off indicates inactive, constantly on indicates running, flashing indicates internal fault. KSB smartPAD_SC green/orange indicates smartPAD connection. RUN CIB_SR green indicates EtherCAT I/O node: normally on for running, off for initialization, flashing at 2.5 Hz for Pre Op, single signal for Safe Op, flashing at 10 Hz for firmware update. STA1 is an orange microcontroller I/O node: check F17.3 when turned off, and replace CCU_SR if PWR/3.3 V is on; 1 Hz flashing is normal, 10 Hz flashing guides, flashing is a fault code. STA2 is an FPGA node: check the X1 incoming line when it is turned off, and replace CCU_SR if PWR/3.3 V is on. 27 V, PS1, PS2, PS3 are green power indicators: when 27 V is turned off, check whether X1 is at 27.1 V; when PS1 is turned off, check whether X1 or the drive bus is at BusPowerOff; Check if X1 or controller is in Sleep state when PS2 is turned off; PS3 turn off and check X1. STA1 (PMB_SR) is an orange microcontroller USB: check X1 when turned off, and replace CCU_SR if PWR/5V is on. PWR/5V is powered by the green PMB: check the 27.1 V of X1 when it is turned off. Temp Fault: red indicates that the ballast resistor R1 is overheating: off indicates no overheating, constant light indicates overheating. Check the X501 connection, control cabinet cooling, and temperature sensor. PWR+12V5 green indicates brake chopper power supply: check X500 connection and low-voltage power supply connection when turned off. The red color of Fuse LEDs indicates the status of the fuse: if it is off, it is normal; if it is constantly on, it is damaged. Replace the fuse with the same specification.
Fuses and Low Voltage Power Supply
When the CCU_SR fuse is damaged, the red LED next to it lights up. The replacement must use the same specifications. F306 is a smartPAD power supply, 32 V/2 A; F302 unused, 32 V/5 A; F3-1 unused, 32 V/15 A; F5-1 unused, 32 V/15 A; F4-1 is KPC with battery backup, 32 V/10 A; F307 unused, 32 V/2 A; F4-2 unused, 32 V/2 A; F22 unused, 32 V/7.5 A; F5-2 unused, 32 V/7.5 A; F3-2 unused, 32 V/7.5 A; F17-2 is CCU_SR input, 32 V/2 A; F17-4 is CCU_SR safety input and relay, 32 V/2 A; F17-1 is CCU_SR contactor output 1 to 4, 32 V/5 A; F17-3 is CCU_SR logic, 32 V/2 A; F14 unused, 32 V/7.5 A; F6 is a 24 V battery free backup option, 32 V/7.5 A; F21 is a PDS power supply, 32 V/3 A; F305 is battery powered, 32 V/15 A; F301 is a backup without battery, 32 V/10 A; F15 is a power fan, 32 V/2 A; F308 is an external power supply with 32 V/7.5 A. The power connection fuses F1 and F2 are 10A slow melting/250 V AC. The secondary fuse F21.1 of the DC/DC converter is 3 A/32 V DC. The low voltage power supply fuse F1 is 5 A/80 V, F2 is 7.5 A/80 V, and the red LED next to it indicates a fault. When troubleshooting, first check the fuse LED, then measure the voltage, and finally consider module replacement.
Component replacement process
When replacing the motherboard battery, first turn off the controller and prevent restarting, disconnect the power, open the casing, unlock the button battery locking mechanism, remove the old battery, install the new battery and lock it. When replacing the hard drive, open the casing, disconnect the power and data cables of the hard drive, remove the fixing screws, replace the hard drive with a new one, restore the connection and fix it. When replacing the battery pack, open the casing, loosen the Velcro strap, unplug the battery connection wire. Both battery blocks must be replaced at the same time, paying attention to polarity. G3.2 and G3.1 correspond to the positive and negative poles. Reinstall the Velcro strap and restore the connection. When replacing the fan, open the casing, remove the fixing screws of the fan bracket, unplug the fan connection, remove the inner and outer grilles, install the new fan, reinstall the fan bracket and connect it. Start the controller after replacement and observe for any abnormalities. Repairs can only be carried out by KUKA customer support or trained customers, and module repairs can only be completed by KUKA trained personnel. Original spare parts must be used, otherwise it may cause damage, premature wear, and module failure. After replacing components, functional testing must be conducted, especially for safety functions.
