Servo Controller - SIL Operation Manual - CAT
Servo Controller - SIL Operation Manual - CAT
SIL means “Safety Integrity Level” and is based on the Standard IEC 61508 as well as IEC 61511. It serves
as evaluation of electric systems in relation of reliability in safety functions.
The safety integrity levels are divided in 4 steps. Level one is the lowest safety level.
The highest level we use on our excavators is safety integrity level 2 (SIL2)
SIL 1:
SIL 2:
Monitoring Monitoring
and or cyclically
Monitoring
Monitoring
• no error detection between test interval
• no error detection in testing device
necessary Testing 2nd switch Output
• 2nd switch off path Device off path Testing
2
SIL on Caterpillar HM Excavators: Service Training
Only the swing function is SIL 2 relevant (see risk assessment down below)
3
How does it work on HM Excavators? Service Training
The SIL System is monitoring the whole swing system with all its components like joysticks, proportional
valves etc.
In case of a problem regarding the swing system (missing hydraulic pressure, short circuit on sensor,
missing CAN-BUS signal etc.) the control lines from the swing pump will be interrupted and the swing
pump goes into neutral position which slows down the swing movement.
-2Y30 -2Y31
x1 x2
A B
4
Swing Circuit: Neutral Service Training
25/1
Servo Control Block (LH – side- /26)
From 35 bar
Servoline
Charge
Tank Pump
Swing Pump
Swing
Motor
50 - 352 bar
22 bar Servo
35 bar Servo
Tank
5
Safety Integrity Level – SIL Service Training
From 35bar
Servoline
-2B33
Servo Controlblock 26
-2B32
-2B17 -2B18
-2B31 Charge
Pump
Swing
Motor
CAMP 1
and 3
Swing Pump
SIL Contoller 2
1
-2Y31
3
2
-2Y30
-2B41 -2B39
-2B36
-2Y23 6
SIL System Overview Service Training
swing_press_lh
SIL2 / PLd components 400 bar (-2B17)
pressure_sensor = p
pressure_sensor_swi
_pump_control
100 bar (-2B31)
100 bar (-2B39)
= p = p
seat contact LH prop valve swing_pump_ctrl
(2S6) (-2Y15) releasing_valve
(-2Y30)
Y2 X5 X1
servo on
(2Y18)
= p balance valve swing pump 1st switch off
servo_press_30bar path
Y1 X6 X2
100bar (-2B33) swing_pump_ctrl
releasing_valve
servo_press _35bar
100 bar (-2B7)
= p
RH prop valve
(-2Y31)
(-2Y16)
= = p
p
CAN Servo
lever Controller
pressure_sensor
= pressure_sensor_swi
safety 100 bar (-2B32) p _pump_control
100 bar (-2B41)
swing_press_rh
swing park 400 bar (-2B18)
brake sw
(2S3, 2S3/1)
swing/tram
CV2 (-2Y23) = p
brake
cylinder
multi-disk
brake 2nd switch off
override sw
(2S5)
path
pressure_sensor
100 bar (-2B36)
ladder prox
switch (2B2) gearbox
7
SIL System on BCS Screen Service Training
(green) – OK
(yellow) – minor fault detected, 48 hours to solve problem before status changes to red and
safe stop sequence is initiated
(red) – major fault detected, safe stop sequence is initiated
The all-over status (green, yellow, red) of the swing circuit is displayed at the end of the chain
and correlates with the 3 conditions mentioned above
8
SIL System on BCS Screen Service Training
You can enter the SIL monitoring screen by using the first level password……………
9
SIL System on BCS Screen Service Training
10
Functional Modules Service Training
The following pages describe the interconnection inside the servo controller via software.
And module:
The output is “high” if input 1 is “high” and input 2 is “high”
Input 1
Output
Input 2 &
Or module:
The output is “high” if input 1 is “high” or input 2 is “high”
Input 1
OR Output
Input 2
11
Functional Modules Service Training
15s
Input 1 Output
Delay
Negation module:
The incoming signal will be swapped from “high” to “low” or from “low” to “high”
The output is “high” if input 1 is “low”/ The output is “low” if input 1 is “high”
Input 1 1 Output
12
Functional Modules Service Training
Memory module:
Input 1 sets the output. Input 2 will reset the output.
Input 1 S
Output
Q
Input 2
R
13
Swing Circuit Lock-Out Lever Service Training
Pedals
p/n:3743030
RH Lever
p/n:3743012
LH Lever
p/n:3743011
Attention:
– SIL2 compliant levers have no rotary
switch for address setting
– thumb wheel faces to the seat
– it is recommended to stock LH and RH
lever in case of a machine break down
– if box turns red, it is necessary to reset
the system by ignition switch or reset
button on the BCS
14
Swing Circuit Lock-Out Lever Service Training
-timing problems
15
Swing System Lock-Out CAN Safety Bus Service Training
16
Swing System Lock-Out CAN Safety Bus Service Training
17
Swing System Lock-Out PLC Servo Controller internal Error Service Training
Servo Controller is
housed in X1 cabinet
in the cascade room
18
Swing System Lock-Out PLC Servo Controller internal Error Service Training
-controller hardware failures -safe stop sequence is activated (event code 1680)
-event code 1681 is reported
-over temperature
OR & (Servo Controller - Program Logic Error)
-all outputs are switched off by internal safety relays
-controller starts to beep (3 times 4kHz for 500ms)
-under voltage
-over voltage
-software problems
-wrong firmware
19
Swing System Lock-Out Swing Parking Brake Switch Service Training
20
Swing System Lock-Out Swing Parking Brake Switch Service Training
21
Swing System Lock-Out Swing Parking Brake Valve Service Training
-2B36
-2Y23
22
Swing System Lock-Out Swing Parking Brake Valve Service Training
-2Y23 swing park brake solenoid & -event code 1659 is reported
(Safety relevant warning: Slewing
OR
-2Y23 swing park brake solenoid
1
-2B36 pressure sensor > 15bar
&
23
Swing System Lock-Out Swing Parking Break Sensor Service Training
-2B36
24
Swing System Lock-Out Swing Parking Break Sensor Service Training
OR
-2B36 pressure sensor < 3mA
25
Swing System Lock-Out Ladder Initiator Service Training
-2B2
26
Swing System Lock-Out Ladder Initiator Service Training
27
Swing System Lock-Out Service Lift Proximity Switch Service Training
-2B38
28
Swing System Lock-Out Service Lift Pressure/ Proximity Switch Service Training
29
Swing System Lock-Out Servo Pressure Sensor Service Training
Caused by:
– cable break or short circuit of pressure tranducer 2B7
exist for more than 10 seconds
Reaction:
– set yellow status
– error code 1659 and 1668 or 1669 is reported
– start countdown of 48 hours to fix the problem
Checks function of pressure transducer 2B7
Box turns red if:
– problem with pressure transducer 2B7 was not fixed
within 48 hours
Reaction:
– safe stop sequence is activated
– event code 1680 is reported
30
Swing System Lock-Out Servo Pressure Sensor Service Training
OR
-2B7 pressure sensor < 3mA
31
Swing System Lock-Out Servo Valve Service Training
-2Y18
-2B7
32
Swing System Lock-Out Servo Valve Service Training
-2Y15
34
Swing System Lock-Out Swing Pilot Valve (too high pressure) Service Training
300ms
-2B32 pilot pressure sensor > 4bar & Delay
35
Swing System Lock-Out Swing Pilot Valve (too low pressure) Service Training
300ms
-2B32 pilot pressure sensor < 4bar & Delay
36
Swing System Lock-Out Swing Pilot Pressure Sensor Service Training
-2B31
-2B32
37
Swing System Lock-Out Swing Pilot Pressure Sensor Service Training
38
Swing System Lock-Out Balance Valve Pressure Supply Service Training
-2B33
39
Swing System Lock-Out Balance Valve Pressure Supply Service Training
Q
-2Y18 solenoid valve
1 R
40
Swing System Lock-Out Balance Valve Pressure Supply Sensor Service Training
-2B33
41
Swing System Lock-Out Balance Valve Pressure Supply Sensor Service Training
OR
-2B33 pressure sensor < 3mA
42
Swing System Lock-Out Control Pressure X1/ X2 Service Training
-2Y31 -2Y30
-2B39 -2B41
43
Swing System Lock-Out Control Pressure X1/ X2 Service Training
44
Swing System Lock-Out Control Pressure X1/ X2 Service Training
-2Y31 -2Y30
-2B39 -2B41
45
Swing System Lock-Out Control Pressure X1/ X2 Service Training
Reason
47
Swing System Lock-Out Control Pressure Sensor X1/ X2 Service Training
-2B39
-2B41
48
Swing System Lock-Out Control Pressure Sensor X1/ X2 Service Training
49
Wrap Up – Safe Stop Sequence Service Training
Joystick Fault
50