In the medical robot system, KUKA Sunrise Cabinet Med is not an isolated control cabinet, but the core control unit in the LBR Med robot components. It is responsible for driving, communication, security interfaces, power management, and interaction with smartPAD. For medical device manufacturers and system integration engineers, the real challenge is often not "how to program", but how to quickly determine the fault level and restore operation without compromising safety integrity when the device experiences a safe stop, power failure, LED alarm, fuse failure, or battery aging. This article focuses on the composition, interfaces, security logic, maintenance cycle, troubleshooting, and medical integration risks of KUKA Sunrise Cabinet Med, and summarizes a set of troubleshooting ideas for engineering practice.
System positioning and core composition
KUKA Sunrise Cabinet Med is a robot controller designed specifically for LBR Med lightweight robots, typically integrated into medical devices, and completed by medical device manufacturers for overall system risk management and compliance assessment. It consists of a control PC, smartPAD control panel, connection panel, low-voltage power supply, battery pack, cooling fan, and CCU_SR.
Among them, CCU_SR stands for Cabinet Control Unit, Small Robot, which is the central power distribution and communication interface. It consists of two core boards, CIB-SR and PMB-SR. CIB_SR is a Cabinet Interface Board, Small Robot, responsible for safety input/output, contactor activation, floating output, smartPAD connection, fan monitoring, internal temperature detection, etc. PMB_SR is the Power Management Board, Small Robot, involved in power management and battery backup. If the main power supply fails, the battery will continue to supply power to the control components until the position data is saved and the controlled shutdown is completed. The charging and health status of the battery will be checked through load testing.
Control PC includes motherboard, processor, heat sink, memory, hard drive LAN、 Dual network cards, etc. The low-voltage power supply provides 48 V DC for the controller components and robot drivers. The cooling system draws in ambient air through two fans to dissipate heat from control and power electronic components. Special attention should be paid: installing filter cotton upstream of the ventilation opening can cause temperature rise and shorten equipment life.
The common interfaces on the front panel of the robot controller include: X11 safety interface, X19 smartPAD interface, X65 KUKA Extension Bus, X69 service interface, X21 robot interface, X66 KUKA Line interface, X1 power connection, F1/F2 power fuse, PE connection, and control PC interface. All contactors, relays, and valve coils connected by users must be equipped with suitable freewheeling diodes, RC components, and varistors are not applicable.
Security interface X11 and stop logic
One of the security cores of KUKA Sunrise Cabinet Med is the X11 security interface. X11 is a 50 pin D-Sub interface that is internally connected to CCU_SR. By default, Safe input 1 is used for external emergency stop dual channel connection; Safe input 2 is used for operational safety, such as safety door locks; Safe input 3 is used for safe stop 1; Output 12 is the local emergency stop channel, output 13 is the test mode, and output 14 is the automatic mode. The input and output allocation can be configured, but the default settings are consistent with the security configuration.
The secure input adopts a dual channel design and comes with external testing. Test outputs A and B will be alternately turned off to detect the switching capability of the input channel. The typical parameters are: t1 shutdown pulse length of 625 μ s, t2 shutdown cycle of 106 ms per channel, t3 two channel shutdown pulse offset of 53 ms. The input channel SIN_x_A must be powered by the test signal TA_S, SIN_x_B must be powered by TA_S, and no other power sources are allowed. Only sensors that can accept test signals and provide floating contacts are allowed to be connected.
The safety output is a dual channel floating relay output, which can be used for external safety PLCs or safety switch devices. To meet SIL2 and Cat.3 requirements, wiring must follow the principles of dual channel, external testing, and cross connection monitoring. The plugging and unplugging of X11 must be done when the robot controller is turned off, as live plugging and unplugging may cause damage.
In terms of stopping reactions, KUKA Sunrise Cabinet Med supports Safe Stop 0, Safe Stop 1, and Safe Stop 1 (path preservation). Stopping 0 will immediately cut off the safety driving energy and apply braking; Stop 1 will brake first, then disconnect the drive and hold the brake after coming to a stop; Stopping 1 (path maintenance) will keep the robot braking on the programmed path. The default triggers include: switching modes during operation, enabling switch release, enabling switch pressed to panic position, local emergency stop pressed, safety controller error, etc. In T1, T2, and CRR modes, the robot can only move if the enable switch is kept in the middle position. In T2 and AUT modes, loss of operation safety signal will trigger safety stop 1 (path maintenance).
It should be emphasized that security features cannot be bypassed. If the safety door automatically resumes operation after being closed, it may pose a risk of personnel still being in the danger zone. The operation safety signal must be reset by an additional confirmation device, and cannot be restored to automatic mode solely by closing the safety door.
Installation, power supply, and electrical planning
KUKA Sunrise Cabinet Med can be installed in a 19 inch rack or as a standalone device. The rack depth must be at least 600 mm. During installation, a 70 mm cooling air gap must be maintained on both sides. When installed vertically, the fan opening and ventilation duct cannot face upwards and must be fixed with screws. The protection level is IP20, suitable for environments with a pollution level of 2; If the pollution level is 3, an additional IPX4 enclosure is required.
In terms of power supply, the controller can only be connected to a power system with a neutral grounding point. The rated voltage is 110 V/230 V AC, single-phase, allowing ± 10% fluctuation, with a frequency of 50 Hz ± 1 Hz or 60 Hz ± 1 Hz. The rated power is about 1 kVA, and the maximum heat dissipation is about 370 W. The power side fuse is 2 × 16 A slow melting, and the equipment side is 2 × 10 A slow melting. PE equipotential connection must be reliable.
If residual current circuit breakers are used, it is recommended to use 300 mA universal current sensitive type for each controller. The power connection can be completed through cables with or without main connectors. When connecting, it is necessary to confirm that the green/yellow wire is connected to the PE, the light blue wire is connected to the neutral wire, and the black wire is connected to the phase wire. All connections must be made in a power-off state.
Pay attention to condensation before starting. If the temperature inside the control cabinet differs greatly from the ambient temperature, condensation may form. Should wait for temperature equilibrium. Before the first startup, it is necessary to insert the X305 connector into the CCU_SR to release the battery discharge protection. After inserting the smartPAD into X19, if the smartPAD is disconnected, an emergency stop will be triggered. Therefore, if medical devices allow smartPAD to be pluggable, an external emergency stop device that is always accessible must be installed.
In terms of EMC, the controller complies with Class B, Group 1 of EN 55011. To meet system level EMC requirements, robots must be connected to PE equipotential conductors. If connected to smartPAD-2, it may not achieve Class B emissions and may cause radio interference during residential use.

Key points for preventive maintenance and replacement
The maintenance of KUKA Sunrise Cabinet Med must be carried out on a periodic basis, and the controller must be turned off, power disconnected, locked, and tagged before maintenance to prevent unauthorized re powering. ESD protection must run through all board and electronic component operations.
The recommended maintenance cycle includes:
Check the relay output function of CCU_SR that has been used annually. Default output 12 is local emergency stop, output 13 is test mode, and output 14 is automatic mode. The contact status can be checked by triggering the corresponding function.
Clean and protect the grille and fan with a brush every year based on the installation environment and pollution level.
Replace the motherboard battery every 5 years.
Replace the fan every 5 years during the three shift operation.
The battery should be replaced according to the monitoring display, at the latest every 2 years.
When storing the battery, if the temperature is ≤ 20 ° C, charge it every 9 months; 20-30 ° C every 6 months; 30-40 ° C every 3 months. Otherwise, it may be damaged due to deep discharge.
When replacing the motherboard battery, first open the outer shell, unlock the lithium button battery fixing mechanism, remove the old battery, install the new battery, and clip it into the locking mechanism. When replacing a hard drive, first unplug the power and data cables, remove the fixing screws, install a new hard drive, and then reconnect it. When replacing the battery block, both must be replaced together. Remove the battery connection cable and connect G3.2 and G3.1 according to the label. When replacing the fan, remove the fixing screws of the fan bracket, unplug the fan connector, and be careful not to confuse the motherboard CPU fan connector.
Visual inspection must be conducted after maintenance to ensure that fuses, contactors, plugs, and boards are securely fastened; Whether the cable is damaged; Is the PE equipotential reliable; Are all system components worn or damaged. The safety functions must be retested, including emergency stop, enable switch, mode selection switch, safety output shutdown capability, etc.
CCU_SR LED and common troubleshooting
The LED on CCU_SR is the first entry point for fault location. The common states are as follows:
PHY4, SW-P0 green: off indicates a fault, usually requiring replacement of CCU_SR module; Lighting up or flashing indicates normal operation.
RUNSION EtherCAT Safety nodes: When turned off, it is Init; when turned on, it is operational; when flashing at 2.5 Hz, it is Pre Op; when a single signal is Safe Op; when flashing at 10 Hz, it is boot.
L/A network LED: When turned off, it indicates no physical connection; when turned on, it indicates connection; and when flashing, it indicates data traffic.
PWR/3.3V, PWR/2.5V, PWR/1.2V: Off indicates no power supply. Check F17.3, X308 jumper, F308, and external 24V power supply. If the PWR/3.3V is on but there are other abnormalities, it may be necessary to replace the CCU_SR.
STAS1 and STAS2 orange: Off indicates no power supply, 1 Hz flashing indicates normal, 10 Hz indicates boot, and other flashing indicates fault codes. Check the X309, X310, and X312 cables, disconnect them if necessary, and restart the test.
FSoE green: Off indicates inactive, lit indicates running, flashing indicates fault code.
RUN CIB_SR EtherCAT AT μ C I/O node: The meaning of the state is similar to that of an EtherCAT node.
STA1 (CIB_SR), STA2 (FPGA node) orange: off indicates no power supply, 1 Hz is normal, 10 Hz boot, other flashing indicates internal fault code.
27 V, PS1, PS2, PS3 green: represent main power supply, short-term battery backup, medium time battery backup, and long-term battery backup, respectively. Check the X1 incoming line, drive bus shutdown status, Sleep status, etc. when turning off.
Temp Fault red: Illuminates to indicate that the R1 brake resistor is overheating. Check X501, control cabinet cooling, and temperature sensors.
PWR_+12V5 green: Off indicates a loss of power to the brake chopper. Check the X500 and low-voltage power connectors.
Fuse LEDs in red: When lit, it indicates a fuse malfunction and needs to be replaced.
Common fuses include: F306 for smartPAD power supply 2 A; F4-1 for KPC with battery backup 10 A; F17-2 for CCU_SR input 2 A; F17-4 for safety input and relay 2 A; F17-1 for contactor output 5 A; F17-3 for logic 2 A; F21 for PDS power supply 3 A; F305 for battery feed 15 A; F301 for battery free backup 10 A; F15 for power fan 2 A; F308 for external power supply 7.5 A. Power supply connection fuses F1 and F2 are 10 A slow melting/250 V AC. The secondary fuse F21.1 of the DC/DC converter is 3 A/32 V DC. The low-voltage power supply unit F1 is 5 A/80 V, and F2 is 7.5 A/80 V.
A typical fault tree can be established as follows: If the entire machine is without power, first check the X1 incoming line F1/F2、 Equipment switch and grounding neutral; SmartPAD has no display, check F306, X19, and SmartPAD cables; The safety circuit cannot be reset. Check X11 emergency stop, operation safety, external safety stop, enable switch, and F17-4; Abnormal output of contactor, check F17-1; Logical exception, check F17-3; PDS abnormality, check F21; The battery cannot be backed up. Check F305, battery block, and charging status; Fan abnormality, check F15 and fan connector; External power supply abnormality, check F308.
Special risks in medical integration
KUKA Sunrise Cabinet Med is aimed at medical device manufacturers and therefore must be evaluated under the IEC 60601-1 system. The interface isolation should meet at least 2 x MOOP and 1 x MOPP, corresponding to approximately 3.4 mm electrical clearance, 5.0 mm creepage distance, and 3000 V withstand voltage. The devices connected to the controller must meet the corresponding isolation requirements. Medical device manufacturers must verify the overall system leakage current and consider the requirements of the ME system.
The robot controller cannot come into contact with patients or be accessed by unauthorized personnel. If the medical product requires a sterile environment, additional casing or protection is required. The robot body and flange are not part of the application, but may come into contact with patients, and it is necessary to evaluate whether to handle them according to the B, BF, or CF application part in risk management. The robot body and media flange can meet the requirements of B-type application.
In addition, it is necessary to evaluate the risks of liquid accumulation and infection, discomfort caused by vibration, unexpected shutdowns, single fault safety, brake as a safety measure, pinch risk, sensor accuracy, strong magnetic field influence, unverified absolute accuracy risk, and PEMS access to IT networks. The braking test cannot be shut down by the system integrator, and the system will enforce regular execution. If not executed, the system will stop. Medical equipment manufacturers must incorporate brake testing into their application and maintenance plans.
