RAS-07REV A.6RAS

Safety, Redundancy & Standards Alignment

Triple-redundant sensor architecture, Category 3 PL d functional safety, ISO 13482 / IEC 60601-1 compliance, and watchdog-MCU brownout detection.

Safety, Redundancy & Standards AlignmentFIG RAS-07
Safety system schematic block diagram
FIG · BLUEPRINT
DARK · 16:9
Engineering DescriptionRAS-07 · DESC

Safety functions are partitioned across a dedicated dual-channel safety MCU running a SIL-2-rated micro-kernel. The primary E-stop circuit (Category 1 stop, IEC 60204-1) is wired in series across both safety relays; loss of either channel forces the manipulator brakes engaged within 25 ms.

The collision-avoidance layer fuses (a) per-joint motor current observers — a 2σ deviation triggers a Cartesian stop, (b) a capacitive proximity skin around joints 5–7 with detection range 5–20 mm, and (c) the F/T sensor with 0.4 N collision threshold. All three are wired into the safety MCU’s 2oo3 voting logic.

The system targets Performance Level d (PL d) per ISO 13849-1 with hardware fault tolerance HFT = 1. It is being qualified to IEC 60601-1 third edition (general medical electrical equipment) plus the 60601-2-77 collateral for robotic surgical equipment.

Technical ParametersRAS-07 · TABLE
ParameterValueUnitTolerance / Note
Functional safety targetPL dISO 13849-1
Hardware fault tolerance1HFT
Safety MCUDual-channel lockstepSIL-2 micro-kernel
E-stop category1IEC 60204-1
Brake engage time<25ms
Collision threshold (F/T)0.4N
Capacitive prox. range5–20mm
Encoder redundancy2× abs. per joint
StandardsIEC 60601-1, 60601-2-77, ISO 13482, ISO 14971
Cyber-securityIEC 81001-5-1Premarket
Watchdog cascadeNOTE-1

Three independent watchdogs: motion controller (1 ms), safety MCU (200 µs), and supervisor PC (50 ms). A single watchdog timeout demotes the system to a configurable safe-state; two within 100 ms forces a hard E-stop.