The safety stop categories include Stop 0, Stop 1, and Stop 1 (path preservation). Stop 0: Immediately disconnect the drive and apply the brake; Stop 1: Brake in a path keeping manner, disconnect the drive and apply the brake after stopping; Stop 1 (path maintenance) is triggered and monitored by the safety controller, and the brake should be applied and the drive disconnected no later than 1 second later. After the emergency stop device is pressed, the robotic arm stops with safe stop 1 (path maintenance). Enable the switch to release or press to the bottom, triggering safety stop 1 (path maintenance). The operator safety signal is used to monitor the safety door and is valid by default in T2 and automatic modes. Loss of signal triggers safety stop 1 (path maintenance). Before restoring automatic operation, it must be confirmed through an external confirmation button, and cannot be restored solely by closing the safety door. The external emergency stop device is connected through a secure interface and triggers secure stop 1 (path maintenance). External security stop 1 (path hold) is triggered through a security interface input. When the signal is False, it remains stopped, and when it is True, it can be moved without confirmation. External enabling devices are used for multiple people entering hazardous areas or manual guidance, where the robot can only move at a reduced speed during manual guidance. The external safety operation stop is a static monitoring function that does not stop movement, only monitors whether the axis is stationary.
The X11 security interface is a 50 pin D-Sub connector, which is internally connected to CCU_SR. In the default configuration, safety input 1 is external emergency stop, safety input 2 is operator safety, safety inputs 3 and 4 are safety stop 1, safety output 12 is local emergency stop, output 13 is test mode, and output 14 is automatic mode. Test outputs A and B provide pulse voltage, which is only used for the safety input of the corresponding channel and cannot be used as a regular power supply. During dynamic testing, the test output is alternately turned off, with a turn off pulse length t1 of 625 μ s and a range of 125 μ s to 2.375 ms. The time t2 between two turn off pulses on the same channel is 106 ms, and the offset t3 between two turn off pulses on the same channel is 53 ms. The input channel SIN_X_A must be powered by TA_S, and SIN_X_B must be powered by TA-B. The safety output is a dual channel floating relay output, and the power supply must come from a safety isolated PELV power supply. When wiring, input signals and test signals, output signals and test signals must be separated to prevent cross connections. The wiring example can achieve SIL2 and Cat. 3.

Maintenance cycle and inspection
The maintenance work of KUKA Sunrise Cabinet should be carried out on a periodic basis. Check annually whether the relay outputs used by CCU_SR are normal. Default output 12 is local emergency stop, output 13 is test mode, and output 14 is automatic mode; After triggering the corresponding function, if there is no error message, it indicates that the relay output is normal. Clean the fan protective grille and fan at least annually based on installation conditions and pollution levels. Replace the motherboard battery every 5 years; Replace the fan every 5 years under 3 operating conditions. The battery replacement cycle depends on the battery monitoring indication. After maintenance, visually inspect the fuses, contactors, plugs, and boards for secure installation, no damage to cables, reliable PE equipotential connections, and no wear or damage to system components.
When cleaning the control cabinet, it is necessary to turn off the power and prevent accidental restarts, disconnect the power cable, and comply with ESD regulations. Wipe the casing with a mild cleaner and clean the cables, plastic parts, and hoses with a solvent-free cleaner. Do not use compressed air, do not spray water, and do not allow cleaning agents to enter electrical components. Replace damaged or unreadable labels and nameplates after cleaning. The battery should be charged every 9 months when the storage temperature is not higher than+20 ° C, every 6 months when the temperature is between+20 ° C and+30 ° C, and every 3 months when the temperature is between+30 ° C and+40 ° C to prevent deep discharge damage.
CCU_SR LED diagnosis
The LED on CCU_SR is the first-hand information for fault diagnosis. PHY4 and SW-P0 are green, constantly on or flashing indicates normal, and off indicates a fault. Usually, CCU_SR needs to be replaced. RUNSION EtherCAT safety node is green, off indicates initialization, constantly on indicates normal operation, flashing at 2.5 Hz indicates Pre Op, single signal indicates Safe Op, flashing at 10 Hz indicates firmware update boot. L/A green or orange indicates physical connection and data traffic: green constantly on indicates physical connection, off indicates no connection, flashing indicates data traffic; Orange represents 1 Gbit, green represents 100 Mbit. PWR/3.3 V, PWR/2.5 V, and PWR/1.2 V are green power indicators. When turned off, check the F17.3, X308 jumper plugs, F308, and external 24V power supply; If PWR/3.3 V is on and PWRS/3.3 V is off, consider replacing CCU_SR. When PWRS/3.3 V is turned off, check F17.3. If PWR/3.3 V is on, replace CCU_SR.