
PRODUCT DESCRIPTION REMOTUS CU9600 92 3159-980 Rev. F Page 7(16)
Datum: 02.10.24
780 45 BJÖRBO, TEL. + 46 241 25 000, TELEFAX. +46 241 232 90
3.1 Safety
The safety level of this receiver is normally category 3. Category 5 is available during design
with dual CPU-board which works in parallel channels design and a large number of safety tests.
3.1.1 DUAL channel approach.
With only one CPU-board (category 3) the MC-relays activates via two separate control signals.
With two CPU-boards (category 5) the MC relays activates differentiate of both
microprocessors-channels i.e. both must be agreed for activate the MC-relays. Output data from
the both channels are compared of respective CPU before it transmits out via the fieldbus.
3.1.2 Check of output devices.
Test of driver outputs:
One side of the relay-coil is driven by cpu-A through a positive driver (source) and the other side
is driven by cpu-B through a negative driver (sink). When the main contactor is deactivated all
source drivers is monitored for not being in high state by cpu-A and all sink drivers is monitored
for not being in low state by cpu-B. In case of failure the main contactor is prevented to be
activated by the respective cpu. The respective cpu:s also clears the outputs which transmits to
the fieldbus.
3.1.3 Under voltage protection.
This consists of one device for each channel. The trip voltage is 4,65 V.
o Fault -> hardware reset.
3.1.4 Over voltage protection.
This consists of one device (MAX921) for each channel. The trip voltage is set to 5,5 V.
o Fault -> hardware reset.
3.1.5 Watch-dog.
A watchdog timer is used to monitor microprocessor function. This watchdog must be constantly
"patted" or it will "bite". "Patting" is the task of the microprocessor, which sends pulses regularly
to the watchdog. If the time between pulses is too long, the dog will "bite", which results in a
hardware reset.
There are one device for each CPU-board. It monitors a separate signal from the CPU.
o Fault -> hardware reset (indicated on a led).
The watch-dog is only maintained if an exact number of program-modules has been executed
during a ”software-cycle”.
The signal feeding the respective watch-dog is also fed to the opposite cpu which enables the
cpu:s to monitor each other. This is done all the time the receiver is running.
o Fault after the fault-tolerance-time -> All outputs cleared and main contactor off.
CPU-A
WDT-A
CPU-A CPU-B
WDT-A WDT-B
1 CPU-board 2 CPU-board