DP0016633 - 02-EPHTT2 - FIBER AREA and MACHINE DESCRIPTIVE SAFETY LOGICS
DP0016633 - 02-EPHTT2 - FIBER AREA and MACHINE DESCRIPTIVE SAFETY LOGICS
DP0016633 - 02-EPHTT2 - FIBER AREA and MACHINE DESCRIPTIVE SAFETY LOGICS
ESSITY MONTERREY
PM2 (EPHTT2)
DESCRIPTIVE LOGIC
SAFETY FUNCTION
FIBER AREA and
MACHINE
SUMMARY
1 SAFETY ____________________________________________________________________________________________ 4
2.3 00412-BF5 Chain conveyor operator access safety light curtain (E-STOP CHAIN CONVEYOR) _____________ 12
2.3.1 Description ___________________________________________________________________________ 12
2.3.2 “Light curtain violated” signal definition ____________________________________________________ 12
2.3.3 Light curtain safety groups cutting _________________________________________________________ 13
2.3.4 Condition to reset the light curtain ________________________________________________________ 13
3 MACHINE ________________________________________________________________________________________16
1 SAFETY
1.1 General indication
1.1.1 Safety device
The status of all the safety devices must be visible on the touch panel/DCS:
• Green colour OK
• blinking red/yellow colour not OK
The limit switches or the sensors in use in this logic, can be NC (normally close) or NO (normally open)
contacts.
For ex:
For a NO contact, the sensor is engaged when the signal is ON (sensor is sensing)
For a NO contact, the sensor is not engaged when the signal is OFF (sensor is not sensing, sensor free)
For a NC contact, the sensor is engaged when the signal is OFF (sensor is sensing)
For a NC contact, the sensor is not engaged when the signal is ON (sensor is not sensing, sensor free)
2 Fiber Area
2.1 Flotation area emergency stop
2.1.1 Description
The emergency stop function makes the following actions:
• stops all the involved drives with the minimum time
• stops all the involved motors
When the emergency stop function is called, the outputs are de-energized.
The circuit is in Pl d (for each emergency stop there are two inputs that have to match, with two contactors for
the output and single feedback made by the series of one contact for each safety contactor)
Sensor
Safe Input Sensor Tag Sensor Type
Location/Connection
Emergency pushbutton
2 DI 40021-SBE1-1&2 +CP40025
(two channels connection)
Emergency pushbutton
2 DI 40051-SBE1-1&2 +CP40005
(two channels connection)
For each push button, two safety channels (signals) are available to process the emergency safety function. The
two channel signals switch OFF when the corresponding push button is pressed. The two channel signals switch
ON when the corresponding push button is released. These actions are surveyed by the safety plc (not by
software, just by plc firmware): the signal commutation ((0 → 1 and 1 → 0)) must respect the discrepancy time
configured (default several msec, time matching supervision) otherwise the safety plc detect an error and the
signal “EmergencyPushButton” is OFF. The architecture to use must be 1oo2.
The software signal (for programming) to take in consideration with 1oo2 architecture is the 1 st one. For this
reason, for each push button the signal “EmergencyPushButton” is ON only when:
• Push button channel #1 is ON (emergency stop function is not calling)
In all the other cases the signal “EmergencyPushButton” is OFF (emergency stop function is calling)
Actuator
Safe Output Actuator Tag Actuator Type
Location/Connection
Contactor group E-STOP
2 DO +40051-KM1-A & B +EB88570 FLO_ZONE (Flotation
Unit)
The output circuit is in Pl d (two outputs on two contactors with one feedback made by the series of one
contact for each safety contactor)
When:
• Any one of “EmergencyPushButton” signal is OFF (see 2.1.2 Errore. L'origine riferimento non è
stata trovata.)
all the above safety outputs are immediately de-energized (reset), and the Flotation Unit emergency function is
activated.
The following safety input signal are involved in the flotation unit reset function:
Sensor
Safe Input Sensor Tag Description
Location/Connection
1=Contactor group E-STOP
1 DI 40051-FKM1 +EB88570 FLO ZONE (Flotation Unit)
de-energized
Emergency reset pushbutton
1 DI 40051-SB2-S +CP40005
(1=reset)
It’s possible to reset the emergency stop when the following conditions are satisfied:
• No “EmergencyPushButton” signal is OFF (no emergency stop pushbuttons pushed)
• (40051-FKM1 “Feedback group E-STOP FLO ZONE” is ON)
When the above conditions are satisfied and the operator pushes the reset pushbutton 40051-SB2-S, the safety
output are energized (set).
1. When the emergency stop is not reset and the condition above are satisfied, the reset lamp 40051-SB2-H is
BLINKING.
2. When the emergency stop is not reset but the condition above is not satisfied, the reset lamp 40051-SB2-H
is switched OFF.
3. When the emergency stop is reset the reset lamp 40051-SB2-H is switched ON.
2.2.1 Description
The emergency stop function makes the following actions:
• stops all the involved drives with the minimum time
• stops all the involved motors
When the emergency stop function is called, the outputs are de-energized.
The circuit is in Pl d (for each emergency stop there are two inputs that have to match, with two contactors for
the output and single feedback made by the series of one contact for each safety contactor)
Sensor
Safe Input Sensor Tag Sensor Type
Location/Connection
Emergency pushbutton
2 DI 00453-SBE1-1&2 +CP00453
(two channels connection)
Emergency pushbutton
2 DI 00411-SBE1-1&2 +CP00411
(two channels connection)
For each push button (or rope), two safety channels (signals) are available to process the emergency safety
function. The two channel signals switch OFF when the corresponding push button is pressed. The two channel
signals switch ON when the corresponding push button is released. These actions are surveyed by the safety plc
(not by software, just by plc firmware): the signal commutation ((0 → 1 and 1 → 0)) must respect the
discrepancy time configured (default several msec, time matching supervision) otherwise the safety plc detect an
error and the signal “EmergencyPushButton” is OFF. The architecture to use must be 1oo2.
The software signal (for programming) to take in consideration with 1oo2 architecture is the 1 st one. For this
reason, for each push button the signal “EmergencyPushButton” is ON only when:
• Push button channel #1 is ON (emergency stop function is not calling)
In all the other cases the signal “EmergencyPushButton” is OFF (emergency stop function is calling)
Actuator
Safe Output Actuator Tag Actuator Type
Location/Connection
Contactor group E-STOP
2 DO 00402-KM1-A&B +EB88570 PULPER ZONE (Pulper
Zone)
Contactor group E-STOP
2 DO 00411-KM1-A&B +EB88570
CONVEYORS
The output circuit is in Pl d (two outputs on two contactors with one feedback made by the series of one
contact for each safety contactor)
When:
• Any one of “EmergencyPushButton” signal is OFF (see 2.2.2)
all the above safety outputs are immediately de-energized (reset), and the Flotation Unit emergency function is
activated.
The following safety input signal are involved in the flotation unit reset function:
Sensor
Safe Input Sensor Tag Description
Location/Connection
1=Contactor group E-STOP
1 DI 00402-FKM1 +EB88570 PULPER ZONE (Pulper
Zone) de-energized
1=Contactor group E-STOP
1 DI 00411-FKM1 +EB88570 CHAIN CONVEYOR de-
energized
Emergency reset pushbutton
1 DI 00411-SB6-S +CP00411
(1=reset)
It’s possible to reset the emergency stop when the following conditions are satisfied with a total of 10s delay:
• No “EmergencyPushButton” signal is OFF (no emergency stops pushbuttons pushed)
• (00402-FKM1 “Feedback group E-STOP PULPER ZONE” is ON)
• (00411-FKM1 “Feedback group E-STOP CONVEYORS” is ON)
When the above conditions are satisfied and the operator pushes the reset pushbutton 00411-SB6-S, the safety
output are energized (set).
1. When the emergency stop is not reset and the condition above are satisfied, the reset lamp 00411-SB6-H is
BLINKING.
2. When the emergency stop is not reset but the condition above is not satisfied, the reset lamp 00411-SB6-H
is switched OFF.
3. When the emergency stop is reset the reset lamp 00411-SB6-H is switched ON.
2.3 00412-BF5 Chain conveyor operator access safety light curtain (E-
STOP CONVEYORS)
2.3.1 Description
The safety light curtain is posed on the access that the operator can use to go and cut the wires on the bales.
The safety input signals involved in this function are the following:
Sensor
Safe Input Sensor Tag/signal Sensor Type
Location/Connection
Chain Conveyor Safety
2 DI 00412-BF5 (chA & chB) +FIELD_PULPER Light Curtain 0=light
curtain intercepted
The safety output signals involved in this function are the following:
Actuator
Safe Output Actuator Tag Actuator Type
Location/Connection
00411-KM1-A Contactor group E-STOP CHAIN
2 DO Cabinet (+EB88570)
00411-KM1-B and BELT CONVEYORs
Sensor
Safe Input Sensor Tag Description
Location/Connection
1=Contactor group E-STOP
1 DI 00411-FKM1 +EB88570 CHAIN CONVEYOR de-
energized
1 DI 00411-SB7-S +CP00412 Reset pushbutton
It’s possible to reset the emergency stop when the following conditions are satisfied with a total of 10s delay:
• No “EmergencyPushButton” signal is OFF (no emergency stops pushbuttons pushed)
• (00411-FKM1 “Feedback group E-STOP CHAIN AND BELT CONVEYORS” is ON)
• (00412-BF5 “Chain conveyor operator access safety light curtain” is ON)
When the above conditions are satisfied and the operator pushes the reset pushbutton 00411-SB7-S, the safety
output are energized (set).
1. When the safety function is not reset and the condition above are satisfied, the reset lamp 00411-SB7-H is
BLINKING.
2. When the safety function is not reset but the condition above is not satisfied, the reset lamp 00411-SB7-H is
switched OFF.
3. When the safety function is reset the reset lamp 00411-SB7-H is switched ON.
For drives equipment connected in the Profisafe network (where is available) it is possible to use Profisafe communication
to lock the drives (using STO, SS1 safety function1). For MCC equipment it is necessary to cut the safety relay physically
(safety digital output needed).
2.4.2 Group E-STOP PULPER ZONE (Emergency safety function for MD Pulper
Area)
This group is composed by the following devices:
3 Machine
The circuit is in Pl d (for each emergency stop there are two inputs that have to match, with two contactors for
the output and a single feedback made by the series of one contact for each safety contactor)
Sensor
Safe Input Sensor Tag Description
Location/Connection
Emergency pushbutton
2 DI 23701-SBE1-1&2 CP23701
(two channel connection)
Emergency pushbutton
2 DI 50001-SBE1-1&2 CP50019
(two channel connection)
Emergency pushbutton
2 DI 50001-SBE4-1&2 CP50020
(two channel connection)
Emergency pushbutton
2 DI 50001-SBE5-1&2 CP50021
(two channel connection)
Emergency pushbutton
2 DI 50001-SBE6-1&2 CP50022
(two channel connection)
Emergency pushbutton
2 DI 50001-SBE7-1&2 CP50023
(two channel connection)
Emergency pushbutton
2 DI 51001-SBE1-1&2 CP51001
(two channel connection)
Emergency pushbutton
2 DI 51001-SBE3-1&2 CP51021
(two channel connection)
Emergency pushbutton
2 DI 51001-SBE7-1&2 CP51026
(two channel connection)
Emergency pushbutton
2 DI 51001-SBE9-1&2 CP51027
(two channel connection)
Emergency pushbutton
2 DI 52001-SBE1-1&2 CP52020
(two channel connection)
Emergency pushbutton
2 DI 53001-SBE1-1&2 CP53001
(two channel connection)
Emergency pushbutton
2 DI 53001-SBE2-1&2 CP53020
(two channel connection)
Emergency pushbutton
2 DI 53001-SBE3-1&2 CP53021
(two channel connection)
Emergency pushbutton
2 DI 56001-SBE1-1&2 CP56001
(two channel connection)
Emergency pushbutton
2 DI 80301-SBE1-1&2 CP80320
(two channel connection)
Emergency pushbutton
2 DI 85501-SBE1-1&2 CP85504
(two channel connection)
For each push button, two safety channels (signals) are available to process the machine emergency safety
function. The two channel signals switch OFF when the corresponding push button is pressed. The two channel
signals switch ON when the corresponding push button is released. These actions are surveyed by the safety plc
(not by software, just by plc firmware): the signal commutation (0 > 1 and 1 > 0) must respect the discrepancy
time configured (default several msec, time matching supervision) otherwise the safety plc detect an error and
the signal “EmergencyPushButton” is OFF. The architecture to use must be 1oo2.
The software signal (for programming) to take in consideration with 1oo2 architecture is the 1 st one. For this
reason, for each push button the signal “EmergencyPushButton” is ON only when:
• Push button channel #1 is ON
Actuator
Safe Output Actuator Tag Description
Location/Connection
Contactors group
2 DO 50001-KM1-A&B +EB88580
MAC_ESTOP
Contactors group
2 DO 50002-KM1-A&B +EB88580
MAC_ESTOP
Contactor group
2 DO 50005-KM1-A&B +EB88580
MAC_ESTOP_DELAYED
Contactors group
2 DO 54529-KM1-A&B +EB88580 EMERGENCY STOP
BROKE CHUTE
TURN UP (PAPRIMA)
85705-SX13 and 85705- EMERGENCY STOP
2 DO cabinet
SX14 (safety stop to turn up
system)
Contactors group MILL
2 DO 89040-KM1-A&B +EB88580
FIRE EMERGENCY
Contactors group
2 DO 55070-KM0-1&2 +EB88580 EMERGENCY STOP
BURNER WET
Contactors group
2 DO 55080-KM0-1&2 +EB88580 EMERGENCY STOP
BURNER DRY
2 DO 53002-KM1-A&B +EB53005 Contactors group REEL-S1
2 DO 53002-KM2-A&B +EB53005 Contactors group REEL-S2
2 DO 53002-KM3-A&B +EB53005 Contactors group REEL-S3
2 DO 53002-KM4-A&B +EB53005 Contactors group REEL-S4
2 DO 53002-KM5-A&B +EB53005 Contactors group REEL-S5
2 DO 53002-KM6-A&B +EB53005 Contactors group REEL-S6
2 DO 53002-KM7-A&B +EB53005 Contactors group REEL-S7
The cutting circuit is in Pld or Plc according with the items involved in the safety function (two outputs with
one feedback made by the series of one contact for each safety contactor)
When:
• Any one of “EmergencyPushButton” signal is OFF (see 3.1.2)
all the above safety outputs are immediately de-energized (reset) and the machine emergency function is
activated.
The following safety input signal are involved in the machine emergency function:
Sensor
Safe Input Sensor Tag Description
Location/Connection
1=Contactor group
1 DI 50001-FKM1 +EB88580
MAC_ESTOP de-energized
1=Contactor group
1 DI 50002-FKM1 +EB88580
MAC_ESTOP de-energized
1=Contactor group
1 DI 50005-FKM1 +EB88580 MAC_ESTOP_DELAYED
de-energized
1=Contactor group
1 DI 55070-FKM0 +EB88580 BURNER WET de-
energized
1=Contactor group
1 DI 55080-FKM0 +EB88580 BURNER DRY de-
energized
1 DI EB53005, 2 NC contact in 1=Contactor group REEL-
53002-FKM1
series S1 de-energized
1 DI 53002-FKM2 EB53005, 2 NC contact in 1=Contactor group REEL-
series S2 de-energized
1 DI 53002-FKM3 EB53005, 2 NC contact in 1=Contactor group REEL-
series S3 de-energized
1 DI 53002-FKM4 EB53005, 2 NC contact in 1=Contactor group REEL-
series S4 de-energized
1 DI 53002-FKM5 EB53005, 2 NC contact in 1=Contactor group REEL-
series S5 de-energized
1 DI 53002-FKM6 EB53005, 2 NC contact in 1=Contactor group REEL-
series S6 de-energized
1 DI 53002-FKM7 EB53005, 2 NC contact in 1=Contactor group REEL-
series S7 de-energized
1 DI EB88580, 2 NC contact in 1=Contactor group BROKE
54529-FKM1
series CHUTE de-energized
1 DI EB88580, 2 NC contact in 1=Contactor group MILL
89040-FKM1
series FIRE EMERG de-energized
1 DI 1=Contactor group TURN
85705-SX09 and 85705- EB88580, 2 NC contact in UP (PAPRIMA) de-
SX11 (in series) series energized (safety feedback
from turn up)
Emergency reset pushbutton
1 DI 53001-SB3-S +CP53001
(1=reset)
It’s possible to reset the emergency stop when the following conditions are satisfied:
All the above reset conditions must be visible on the Operator Station touch screen close to the Pope Reel and on
the DCS, so that the operator can see what is missing to reset the function.
When the above conditions are satisfied and the operator pushes the reset pushbutton 53001-SB3-S, the safety
output are energized (set).
1. When the emergency stop is not reset and the condition above are satisfied, the reset lamp 53001-SB3-H is
BLINKING.
2. When the emergency stop is not reset but the condition above are not satisfied, the reset lamp 53001-SB3-H
is switched OFF.
3. When the emergency stop is reset the reset lamp 53001-SB3-H is switched ON.
• In the DCS pages must be visible the condition to reset the machine emergency function to help the
operator to understand why it is not possible to restore the safety groups.
• In the DCS pages must be visible all contactor groups status involved in the machine emergency
function.
When the gate is open (or as soon as 54550-SB2-S is pushed with the ok condition to open the gate), the
involved outputs are de-energized.
This safety function is in Performance Level “c” (Pl c): it is composed by single channel sensors (Safety Digital
Inputs, SDI) with high MTTF and by single channel Coil (Safety Digital Outputs, SDO). DiagnosticCoverage
safety function is applied.
It’s possible to open the gate when the following conditions are satisfied:
• (54529-ZQ1-A &-B double channel limit switch “Broke Pulper movable hatch closed”) is ON, TON 6s
In this situation the software signal 54550-LimitSwitchesCondition signal is ON, otherwise is OFF
When it’s possible to open the gate, the open lamp 54550-SB2-H is switched ON.
When the above conditions are satisfied and the operator pushes the open pushbutton 54550-SB2-S, the safety
output are immediately de-energized but the unlock coil 54550-ZQ1-IN is energized after 3s that the pushbutton
54550-SB2-S is maintained pushed, so that it’s possible to open the gate.
When the gate is open (or 54550-SB2-S is already pushed with the ok condition to open the gate), the outputs are
de-energized.
Sensor
Safe Input Sensor Tag Sensor Type
Location/Connection
54550-ZQ1-Y1 Safety Gate UTM broke
2 DI Gate Closed
54550-ZQ1-Y2 pulper T.S.
1=Broke Chute
1DI 54529-PS1 +VB54501
movements locked
1 DI 54550-SB2-S +CP54550 Open pushbutton
1 DI 54550-SB3-S +CP54550 Reset pushbutton
When:
• 54550-ZQ1-Y1 “Gate Closed and Locked channel #1” is ON
AND
55450-ZQ1-Y2 “Gate Closed and Locked channel #2” is ON
the gate is close and locked
When:
• 54550-ZQ1-Y1 “Gate Closed and Locked channel #1” is OFF
OR
54550-ZQ1-Y2 “Gate Closed and Locked channel #2” is OFF
the gate is not closed or not locked.
It’s possible to reset the gate when the following conditions are satisfied:
When the above conditions are satisfied and the operator pushes the reset pushbutton 54550-SB3-S, the gate is
reset and the safety output are energized.
1. When the gate is not reset and the condition above are satisfied, the reset lamp 54550-SB3-H is BLINKING.
2. When the gate is not reset but the condition above are not satisfied, the reset lamp 54550-SB3-H is switched
OFF.
3. When the gate is reset the reset lamp 54550-SB3-H is switched ON.
Actuator
Safe Output Actuator Tag Actuator Type
Location/Connection
Contactors group Broke
2 DO 54529-KM1 and KM2 +EB88570
Chute
When the gate is not closed or not locked or the machine emergency function is active the safety Contactor groups
are de-energized according with the following logic:
• Gate not closed or not locked
OR
Machine emergency function is active
OR
GateOpenRequest signal is ON
• In the DCS pages must be visible the condition to reset the machine emergency function to help the
operator to understand why it is not possible to restore the safety groups.
In the DCS pages must be visible all contactor groups status involved in the machine emergency function.
Sensor
Safe Input Sensor Tag Sensor Type
Location/Connection
- Machine emergency stop - Machine emergency stop
89040-SX1 Extinguisher signal from
2 DI Mill interconnection
89040-SX2 Mill
Steam Condensate from
1 DI 83633-TS1 On Field
R0, 0= high temperature
When the machine emergency stop is active or the extinguisher signal from mill is OFF, all the contactor group
for burner wet and burner dry are immediately cut:
Actuator
Safe Output Actuator Tag Actuator Type
Location/Connection
Contactor group
2 DO 55070-KM0-A & B Cabinet
BURNER WET
Contactor group
2 DO 55080-KM0-A & B Cabinet
BURNER DRY
The cutting circuit is in Pld (two outputs with one feedback made by the series of one contact for each safety
contactor)
The logic for the outputs cutting is the following.
When:
• Machine emergency function is active
OR
(89040-SX1 ‘0= MILL EMERGENCY FIRE ACTIVE CH1’ is OFF
OR
89040-SX2 ‘0= MILL EMERGENCY FIRE ACTIVE CH2’ is OFF)
OR
83633-TS ‘Steam Condensate from R0, 0= high temperature’ is OFF
Sensor
Safe Input Sensor Tag Description
Location/Connection
1=Contactor group
1 DI 55070-FKM0 +EB88580 BURNER WET de-
energized
1=Contactor group
1 DI 55080-FKM0 +EB88580 BURNER DRY de-
energized
Steam Condensate from R0,
1 DI 83633-TS1 On Field
0= high temperature
It’s possible to reset Burner stop safety function when the following conditions are satisfied:
When the above conditions are satisfied and the operator reset the machine emergency stop function, the safety
output are automatic energized again (set).
Note 1:
After this safety stop function, both burners need a local reset before to start again.
• In the DCS pages must be visible the condition to reset the machine emergency function to help the
operator to understand why it is not possible to restore the safety groups.
In the DCS pages must be visible all contactor groups status involved in the machine emergency function.
Sensor
Safe Input Sensor Tag Sensor Type
Location/Connection
89040-SX1 Extinguisher signal from
2 DI Mill interconnection
89040-SX2 Mill
- Machine emergency stop - Machine emergency stop
When:
• (89040-SX1 ‘0= MILL EMERGENCY FIRE ACTIVE CH1’ is OFF
OR
89040-SX2 ‘0= MILL EMERGENCY FIRE ACTIVE CH2’ is OFF)
OR
Machine emergency function is active
The extinguisher safety function is active and the involved safety output are immediately cut (see 3.4.1.4)
The extinguisher function reset is done by the following situation (coming from mill signal):
All the above signals must be visible on the DCS, so that the operator can see what is missing to start again the
production.
Note:
After this safety stop function, both burners need a local reset before to start again.
Actuator
Safe Output Actuator Tag Actuator Type
Location/Connection
Contactor group
2 DO 55070-KM0-A & B Cabinet
BURNER WET1
Contactor group
2 DO 55080-KM0-A & B Cabinet
BURNER DRY
Contactors group MILL
2 DO 89040-KM1-A & B Cabinet
FIRE EMERGENCY
3.4.1.7 Note
When all the reset conditions are satisfied:
- The hoods open (the force close condition is removed and the StockOnWire signal is OFF)
- The valve 55338-AV1 “Wet Yankee hood roof washing valve” close (Force open is removed)
- The valve 55348-AV1 “Dry Yankee hood roof washing valve” close (Force open is removed)
All the other devices involved in the extinguisher function do not change their status (the devices take back the
automatic control)