11.1 Introduction to this chapter
This chapter mainly introduces the settings of xCore safety related functions.
11.2 Safety password
A password is required to unlock the safety module, and it is "safety" by default.
-
To access the safety module, the user must enter the password and click "Unlock" to operate the safety interface.
-
After unlocking, the user can enter other interfaces of the safety module without re-entering the password.
-
Re-unlocking is required when the user switches back to the safety module from other modules.
-
After modifying the settings of the safety module, the user needs to click the "OK" button to confirm the safety parameters.
-
Regardless of the user permission, operators and other low-permission users are allowed to modify the safety module parameters after logging in.
The safety password can be changed through Settings —> User Group —> Safety Password.
11.3 Joint limit
11.3.1 Highlights
The joint limit monitors the parameters of robot joints. When the joint exceeds the threshold, the robot will immediately stop running, and the RSC robot will enter a safe stop state.
The joint limit mainly includes joint position limit, joint velocity limit, joint torque limit, and joint power limit. Each limit can be configured with two parameters for users to determine the threshold based on the current mode (normal mode or reduced mode).
The user has the flexibility to enable or disable specific functionalities as required.
11.3.2 Joint position
11.3.2.1 Highlights
The joint position limit is used to set the maximum motion range of each joint at the software level to avoid interference or collision between the robot and peripheral equipment.
During the drag process, the joint angles are also protected by the joint position limit. Drag near the joint position limit will give the manipulator a rebound force against the direction of the joint position limit. The range of the drag rebound force is within 10° of the upper and lower joint position limits set by the HMI interface. Assuming that the joint 1 position limit is −170° to 170°, then the range of the drag rebound force is [−170° to −160°] and [160° to 170°].
① |
The "Enable" switch controls whether the joint position limit is enabled; |
② |
The lower limit of joint positions in normal mode shall be less than the upper limit. |
③ |
The joint position limit in reduced mode shall be less than or equal to that in normal mode. |
④ |
They are the maximum and minimum limits of joint positions for the robot. |
|
11.3.2.2 Handling for moving beyond the joint position limit
In some rare cases, the robot may move beyond the joint position limit, such as triggering an emergency stop when moving to the limit, and exceeding the joint position limit when executing STOP 0.
In xCore V2.1 and earlier versions, when the robot has one or more joints outside the joint position limit, it will be unable to jog or run programs. At this point, it is necessary to first cancel the joint position limit, then jog the out-of-limit joint back within the joint position limit, and finally enable the joint position limit again.
In xCore V2.2 and later versions, for non-RSC robots, when the robot moves beyond the joint position limit, it is allowed to jog the robot back within the joint position limit.
For RSC robots, when the robot moves beyond the joint position limit, it will enter the safe stop state. At this point, it is necessary to first cancel the joint position limit, then click "emergency reset", jog the out-of-limit joint back within the joint position limit, and finally enable the joint position limit again.
|
Cancellation of the joint position limit can only be used to jog the out-of-limit joint back within the normal range when the robot joint exceeds the joint position limit, and the program is unable to run when the joint position limit is canceled. |
11.3.3 Joint velocity
Joint velocity limit: The joint velocity limit can be turned on/off by an enable switch. When it is enabled, the angular velocity of robot joints will be monitored in real time. Depending on the current mode (normal mode or reduced mode), different monitoring parameters are used to determine the threshold. If any joint angular velocity exceeds the threshold, the robot will immediately plan to stop and power off, and the RSC robot will enter a safe stop state.
11.3.4 Joint torque
Joint torque limit: The joint torque limit can be turned on/off by an enable switch. When it is enabled, the torque of robot joints will be monitored in real time. Depending on the current mode (normal mode or reduced mode), different monitoring parameters are used to determine the threshold. If any joint torque exceeds the threshold, the robot will immediately plan to stop and power off, and the RSC robot will enter a safe stop state.
11.3.4 Joint power
Joint power limit: The joint power limit can be turned on/off by an enable switch. When it is enabled, the power of robot joints will be monitored in real time. Depending on the current mode (normal mode or reduced mode), different monitoring parameters are used to determine the threshold. If any joint power exceeds the threshold, the robot will immediately plan to stop and power off; and the RSC robot will enter a safe stop state.
11.4 Robot limits
① |
Velocity limit: The velocity limit covers TCP linear velocity, TCP angular velocity, elbow linear velocity, and elbow angular velocity. Additionally, each velocity limit can be turned on/off by an independent enable switch. When it is enabled, the velocity of robots will be monitored in real time. Depending on the current mode (normal mode or reduced mode), different monitoring parameters are used to determine the threshold. For example, "TCP linear velocity" is used as the threshold in normal mode, and "reduced TCP linear velocity" is used as the threshold in reduced mode. When any monitored value exceeds the threshold, the robot will immediately plan to stop and power off, and the RSC robot will enter a safe stop state. |
② |
Reduced velocity: If the user turns on the reduced velocity, in the reduced mode, the robot will move at the set TCP velocity and joint velocity. |
③ |
Robot power limit: The robot power limit can be turned on/off by an enable switch. When it is enabled, the power of robots will be monitored in real time, and different monitoring thresholds will be used based on the current mode (normal mode or reduced mode). If the robot power exceeds the threshold, the robot will immediately plan to stop and power off, and the RSC robot will enter a safe stop state. |
④ |
Momentum limit: The momentum limit can be turned on/off by an enable switch. When it is enabled, the momentum of robots will be monitored in real time, and different monitoring thresholds will be used based on the current mode (normal mode or reduced mode). If the momentum exceeds the threshold, the robot will immediately plan to stop and power off, and the RSC robot will enter a safe stop state. |
⑤ |
Drag velocity limit: The drag velocity limit can be turned on/off by an enable switch, which is special for RSC robots. When it is enabled, if the drag velocity of the collaborative robot exceeds 250 mm/s, the robot will be stopped and powered off instantly to enter a safe stop state. |
11.5 Virtual wall
11.5.1 Highlights
The virtual wall is specifically designed to confine the working area at the end of the flange in the Cartesian space (translation only) drag scene of the xMate collaborative robot. As users approach this virtual barrier, they will encounter a reactive force exerted by it.
The typical usage scenario involves medical professionals utilizing xMate collaborative robots as auxiliary tools for surgical operations through dragging actions. In order to enhance safety and prevent any potential misoperations, establishing a virtual wall becomes crucial to restrict the operational space of the robot’s flange.
① |
The "Enable" switch controls whether the virtual wall is enabled; Click “OK” to take effect; |
② |
Introduction to the steps for using the virtual wall function; |
③ |
Virtual wall types, including sphere and cuboid; |
Note: In the extreme case of excessive drag force and speed, the robot may exceed the range of the virtual wall, and the system will provide corresponding prompts.
11.6 Collision detection
11.6.1 Highlights
Collision detection is a passive function that relies on the estimation of the robot’s dynamic model. It enables timely identification of unexpected collisions with the external environment during robot operation, allowing for prompt implementation of pre-set measures to mitigate any potential damage.
11.6.1.1 Setting mode
The "whole setting" and "single joint setting" are available, and at least one of them shall be checked.
According to different setting modes, the sensitivity of the whole robot or single joint can be adjusted. The higher the percentage, the higher the sensitivity, and the easier it is for the robot to detect collisions. The factory default sensitivity is set to 100%, which can be adjusted by the user according to their needs.
Different sensitivity thresholds will be used based on the current mode (normal mode or reduced mode).
11.6.1.2 Impact limit
Impact limit (including TCP impact and elbow impact): The impact limit can be turned on/off by an enable switch (collision detection is also turned on). When it is enabled, the TCP impact and elbow impact of the robot will be monitored in real time. Depending on the current mode (normal mode or reduced mode), different monitoring parameters are used to determine the threshold.
When any monitored value exceeds the threshold, the robot will enable the trigger behavior of collision detection, and the RSC robot will enter a safe stop state.
11.6.1.3 Trigger behavior
The trigger behavior only includes a soft stop.
Soft stop: a collision detection stop method for robots and high stiffness environments. The greater the soft, the faster the response of the robot, and the greater the load of the robot joint; soft generally uses the default 0. After a safe stop, the robot will automatically power off. In this state, the robot supports direct power-on and continues to run the program along the current path.
11.6.1.4 Driving torque limit
The driving torque limit is used to limit the maximum driving torque of the reducer and protect the important parts of the driving chain and the mechanical zero.
The driving torque limit is available for collision protection*. When the controller detects that the driving torque exceeds the limit, the robot will trigger an error message indicating that the driving torque exceeds the limit. For the first start, the robot will use the default driving torque limit.
The side switch button can be used to manually deactivate the collision protection function, which is enabled by default. For collaborative models, it is necessary to obtain the "overload operation" authorization to disable this function, while for industrial robot models, manual deactivation and reactivation can be performed without any authorization.
11.6.1.5 Parameter identification
Collision detection parameter identification is used to identify and set the internal parameters of the collision detection algorithm to improve the accuracy of impact monitoring, reduce the probability of false alarms, and optimize collision detection performance.
Collision detection parameter identification supports "delay compensation parameter" identification and setting.
The detailed steps for enabling collision detection parameter identification are as follows:
| Step | Graphical Representation | Explanation |
|---|---|---|
1. Disable collision detection and collision protection. |
The user needs to turn off the collision protection on the production interface. |
|
1. Click the "Start Identification" button. |
|
The dynamic feedforward needs to be enabled in advance for the collision detection parameter identification. |
2. Switch to automatic mode and power on. |
||
3. Run the RL program for identification. |
The user can use a dedicated identification program or any RL program that has collision detection. |
|
4. After the identification result converges, stop the identification. |
||
5. Save the identification result and set the delay compensation parameters. |
|
The delay compensation parameters take effect immediately after clicking "OK". |
The detailed steps for manually setting delay compensation parameters are as follows:
| Step | Graphical Representation | Explanation |
|---|---|---|
1. Input delay compensation parameters. |
|
The manual settings of delay compensation parameters cannot exceed the range. |
2. Click the "OK" button to confirm parameters. |
|
|
11.6.1.6 Maximum output torque monitoring
The maximum output monitoring is used to monitor the maximum output torque of the motor of each joint during the period from enabling to disabling. Users can adjust the driving torque limit of each joint according to the maximum output torque monitoring parameters.
|
The maximum output torque monitoring is disabled by default after the controller is restarted. |
11.6.2 Notes
1. During program execution, if the robot collides with external devices while moving at high speed and the collision force exceeds a certain threshold, triggering an alarm and stopping the servo driver, the robot can only resume operation after clearing the collision, restarting itself, and resetting the servo alarm.
2. Incorrect sensitivity mode selected may cause a false collision alarm. Please select different sensitivity thresholds for each application scenario.
3. The collision detection sensitivity is affected by the robot hardware, and there are differences in sensitivity thresholds between different robots. Currently, the three sensitivity modes only provide a set of nominal values. The user with higher requirements for collision detection sensitivity can fine-tune the sensitivity of each axis based on specific application scenarios through the single-axis setting or adjust the detection sensitivity online through RL commands.
4. After collision detection and safety monitoring are triggered, a pop-up window will appear, and you must click "Confirm" to manually clear the alarm before continuing to run.
5. Collision detection is enabled by default at the factory for collaborative robots.
6. For the description of the collision protection*, see the user manual of the production interface.
|
Before using collision detection, the user must ensure that the following parameters are set correctly. Otherwise, the controller may fail to calculate the correct output torque, resulting in a false alarm.
|
11.7 Safe region
11.7.1 Highlights
Safe regions are used to set the behavior of the end-effector and elbow in and out of a region.
The user can define several safe regions in the space (currently supports up to 10). When the robot enters and exits the safe region, it selectively triggers the preset safety behavior, and automatically modifies the register value (binding the register function code of the safe region).
The safe region retraction function is described in 11.7.3.
① |
"Overall Switch": Turns on or off the safe region function, when this switch is off, all safe regions are invalid. |
② |
"Signal Control": After opening, a register signal can be used to control whether a certain safe region is turned on. |
③ |
Region monitoring: The relationship between the tool checked and regions are displayed. |
④ |
"Is the base frame consistent with the world frame": This button is displayed only when the RSC safeboard is in use. If enabled, it indicates that the world frame is consistent with the base frame, and the RSC will perform safe region detection. Otherwise, it indicates the world frame is inconsistent with the base frame, and the RSC will not perform safe region detection. |
➀ |
Different shapes for region selection support different types of region settings, as shown in the table below. |
Region Shape |
Region Type |
Cuboid |
|
Working region, forbidden region, and shared region |
|
Plane |
Working region and forbidden region |
Sphere |
|
Working region, forbidden region, and shared region |
|
Cone |
Forbidden region for the inner part of the cone and working region for the outer part of the cone |
Shared region: For a shared region, it is required to bind DIDO. If the DI is true, it indicates that the region is occupied and the robot will pause and wait outside the region when it is about to enter the region. When the DI is false, it indicates that the region is unoccupied, the robot will continue to move into the shared region, and the DO is set to true. It is unnecessary to set the trigger behavior of the shared region. When the robot is about to enter the occupied shared region, its behavior is to pause and wait. When the robot has entered the occupied shared region, its behavior is to slow down and stop at maximum capability. Note: To ensure safety, the occupancy signal of the shared region will be triggered when the robot is about to enter or has already entered the shared region. The occupancy signal will only be released when the robot actually moves out of the shared region. |
|
② |
Region teaching: For cuboid regions, there are two teaching methods, namely center point teaching and two-point teaching. Center point teaching: Click to get the current TCP pose (TCP relative to the world frame) to determine the center point pose of the region, and then manually set the length, width, and height of the cuboid. Two-point teaching: Teach two points (two points on the cuboid diagonal) to determine the cuboid region, and then click "Confirm Point 1" —> "Confirm Point 2" —> "Confirm". The orientation of the safe region shall be based on the last point position orientation. |
③ |
Trigger behaviors include no behavior, normal mode enabled, reduced mode triggered, reduced mode enabled, and normal/reduced mode enabled. No behavior: the robot has no specific action; Normal mode enabled: In the normal mode, when the tool is about to enter the forbidden region, the planning to stop will be triggered; and when the tool has entered the forbidden region, the maximum capacity to slow down and stop will be triggered. Reduced mode triggered: When the tool enters the forbidden region, the reduced mode will be triggered. Reduced mode enabled: In the reduced mode, when the tool is about to enter the forbidden region, the planning to stop will be triggered; and when the tool has entered the forbidden region, the maximum capacity to slow down and stop will be triggered. Normal/Reduced mode enabled: In the normal/reduced mode, when the tool is about to enter the forbidden region, the planning to stop will be triggered; and when the tool has entered the forbidden region, the maximum capacity to slow down and stop will be triggered. |
④ |
The state of the region-bound register after triggering includes True/False. |
11.7.2 Association of safe region and register
11.7.2.1 Safe region status output
| Step | Graphical Representation | Explanation |
|---|---|---|
1. First, create a new register, and select the type as write-only; |
|
The left figure is for example only; |
2. Select the function code "sta_safeRegion01−sta_safeRegion10", indicating binding the triggering status of the corresponding safe region to the current newly-created register. |
11.7.2.2 Register control safe region enable
| Step | Graphical Representation | Explanation |
|---|---|---|
1. First, create a new register, and select the type as read-only; |
|
The left figure is for example only; |
2. Select the function code "enable_safe_region01−enable_safe_region10", indicating binding the control switch of the corresponding safe region to the current newly-created register; |
11.7.3 Safe region retraction function
11.7.3.1 Retraction function introduction
The safe region retraction function refers to the capability that when the robot is within a forbidden region, activating the safe region retraction button will directly move the robot out of the forbidden region without requiring deactivation of all safe regions.
➀ |
The button is the retraction activation button. When region monitoring shows the current position is within the forbidden region of a planar safe region and the region is in an active mode (normal mode active, reduced mode active, or both normal and reduced modes active), the retraction button is allowed to be enabled. In all other cases, the retraction button is not permitted to be enabled. |
② |
Among all region shapes, only planar safe regions support the retraction function [cols="35%,65%"] |
| Region Shape | Support Safe Region Retraction | | Cuboid | Not supported | | Plane | Supported | | Sphere | Not supported | | Cone | Not supported |
③ |
|
④ |
The retraction status is divided into two types: one is "In Retraction", indicating that the current region is undergoing retraction, where multiple regions can simultaneously be in retraction; the other status is "Idle", indicating that the current region is either waiting or does not require retraction. |
11.7.3.2 Retraction function operation procedure
➀ |
|
② |
|
③ |
|
④ |
When retraction is completed, the retraction button will automatically deactivate and the retraction status will change to "Idle". Upon completion of retraction, all safe regions will resume normal monitoring operations. |
11.8 Tool setting
11.8.1 Tool position
The tool position limit is available to limit the positions of flanges, elbows, real-time tools, and two fixed tools simultaneously. An envelope can be specified for each position. When the envelope of any position exceeds the setting of the safe region, the behavior of the safe region will be triggered (normal mode enabled, reduced mode triggered, etc.).
Tool envelope: The tool envelope includes three shapes, namely no envelope, cuboid, and sphere.
Real-time tool: When RL runs motion commands, the real-time tool is the tool in the command. When there is no motion command, the real-time tool is the tool selected on the upper right of the HMI. The envelope of the real-time tool can be set when editing the tool (global tool list in the frame calibration and tool list in the project).
11.8.2 Tool orientation
① |
The "Enable" switch can turn on/off orientation limits; |
② |
The orientation limit function only monitors one object at a time, and can select one from flange, tool 1, or tool 2; |
③ |
Angle: When the orientation function is enabled, the orientation of the selected object is used as a reference, and a cone formed according to the set angle is used as the allowable range of the attitude; when the attitude of the selected object exceeds the range of the cone, a safe stop will be triggered; |
11.9 Safety position
11.9.1 Highlights
The safety position function refers to the binding register outputting a signal indicating the robot’s presence in the predetermined safety position. Through this function, users can ascertain the relative positioning of the robot with respect to the safety position.
The xCore control system supports up to 8 safety positions with joint angles as reference. Each safety position corresponds to a register function code (type: bool or int16, read/write: write only, sta_safe_jnt_pos1~sta_safe_jnt_pos8). When the current joint angle of the robot and the additional axis and the joint angle set for a safety position are within the allowable error, the value of the register to which the corresponding register function code for the safety position is bound to will be modified automatically (when within the allowable error of the safety position, if the register type is bool, the register value is true; if the register type is int16, the register value is 1). If there is no additional axis, only the safety position of the robot will be judged.
The safety Home is special for RSC robots, and a safety position can be checked as the safety Home. After it is checked, a safety DO signal can be output if each joint of the robot reaches the set range. If none is checked, the safety Home is disabled. If there are additional axes, the safety Home cannot be checked.
① |
Enable: A safety position can be enabled or not. |
② |
Safety Home: A safety position can be checked as a safety Home. |
③ |
No.: After clicking, the user can set the parameters for the safety position on the right side. |
④ |
"Joint Coordinate" corresponding to the safety position of the robot; It can be manually updated; you can also click "Update Position" to update the current joint position data of the robot; |
⑤ |
The "Allowable Error" corresponding to the safety position of the robot, when the current joint angle and "Joint Coordinate" of the robot are less than the "Allowable Error", the robot is considered to be in the safety position; |
⑥ |
"Joint Coordinate" and "Allowable Error" corresponding to the safety position of the additional axis; When there are additional axes, "Joint Coordinate" and "Allowable Error" can be configured here. The coordinate can be manually updated; you can also click "Update Position" to update the current joint position data of the additional axis. When the current joint angle and "Joint Coordinate" of the additional axis are less than the "Allowable Error", the additional axis is considered in the safety position; |
11.9.2 Association of safety position and register
| Step | Graphical Representation | Explanation |
|---|---|---|
1. First, create a new register, and select the type as write-only; |
|
The left figure is for example only; |
2. Select the function code "sta_safe_jnt_pos1−sta_safe_jnt_pos 8", indicating binding the feedback status of the corresponding safety position to the current newly-created register. |
11.10 Safety checksum
To modify the safety settings, click the "OK" button at the lower right of the interface and confirm the settings after the safety checksum.
The "Safety Checksum" icon displays a combination of four digits of "number + letter" to allow the user to understand the status of safety-related settings. When there is a change in safety-related settings, it will automatically calculate and generate a new combination of four digits of "number + letter".
After clicking the icon, the current safety settings will be available, including the joint limit, robot limit, virtual wall, collision detection, safe region, tool settings, and safety position.
After modifying the parameters of these items, clicking the "OK" button will trigger a pop-up window displaying the safety checksum. After clicking the "OK" button, the safety parameters will be set successfully, and the safety checksum will also change accordingly.
11.11 Safety controller
The xCore control system can be optionally equipped with an RSC safety controller, which is a safety module that complies with functional certification and performs various internal safety-related calculations and protections. The safety functions of the xCore control system are processed in parallel, forming a dual safety architecture.
To ensure the data and parameter integrity of the safety controller, real-time data transmission adopts the FSoe communication mechanism for accurate transmission, while non-real-time data utilizes a secure synchronization mechanism with a synchronization time of 5s−10s.
For robots equipped with safety controllers, the safeboard type is ROKAE_RSC as depicted in the figure below.
11.11.1 Changes after equipping safety controllers
In addition to the functions displayed on the subsequent safety controller configuration interface, there are several changes in the use of robots equipped with safety controllers.
11.11.1.1 Changes to robot motor state
"Safety stop state" is added to the robot state to indicate the safety state caused by the limits of the safety controller.
Safe stop state |
The robot is in a safe stop state, which means that the safety controller detects that the work or communication is abnormal, or a parameter exceeds the safety threshold set by the safety controller, and the robot cannot be powered on. |
11.11.1.2 Added robot reset
When the robot is in any of the "emergency stop state", "safety gate state" or "safe stop state", to reset it to the "power-off state", you must complete the following 2 steps:
Step 1: Eliminate the operation or condition that triggers the above three states, such as rotating the emergency stop button to "OFF" position, clearing the safety gate trigger signal, removing the safety overrun factor, or disabling the corresponding safety limit;
Step 2: Click "Reset" button on the interface, and the robot will reset to the "power-off state".
11.11.1.3 Changes to the safety gate logic
For robots without safety controllers, when the robot is in automatic mode and receives the signal of safety gate closed, the robot will be powered off immediately.
For robots with safety controllers, when the robot is in automatic mode and receives a signal of safety gate closed, the RL program will be suspended, and the robot will not be powered off. In this situation, the robot is unable to run the RL program or step through the RL program. If you want to restore the robot’s status, you can: execute the signal to disconnect the safety gate, and click on the "Reset" signal on the HMI.
11.11.1.4 Time difference between zero calibration and friction parameter setting
The zero information and the friction parameter information of the robot need to be synchronized to the safety controller to ensure the basic safety restriction function of the safety controller to be used normally. Therefore, when the user performs zero calibration or sets friction parameters, the controller will actively synchronize the updated parameters with the safety controller, which takes about 5s−10s to wait. At this point, the interface is as shown in the figure below, and the user is unable to operate and use the robot.
11.11.2 Safety DO configuration
The safety controller has four channels of safety DO signals. The user can map several safety state signals to the four safety DOs.
① |
E-stop output: When the robot is in the E-stop state, the output is true. Otherwise, it is false. |
② |
Robot in motion: When the robot RL program is in operation, the output is true, but when it is not in operation, the output is false. |
③ |
Safety Home point: When the robot is within the range of the safety Home point of safety controller, the output is true. Otherwise, it is false. |
④ |
Reduced mode: When the robot is in reduced mode, the output is true. Otherwise, it is false. |
⑤ |
Drag mode: The robot is in drag mode. |
⑥ |
Robot still on: Provided that the robot RL program is in operation (i.e., "Robot in motion" is true), if the robot joints are in motion, the output is true. Otherwise, it is false. |



















