- Fixture safety consists of two independent propositions:Can be clamped when needed、Cannot be released when safety conditions are not met;The latter belongs to the issue of release permission and status control.
- The release action should beLoad state machine (S0–S8)Constraint, only in S6 allows releaseStateful execution, S1–S5 and S8 simultaneously block release channels at the software and hardware layers.
- The placement criterion should not only look at height:Height, position, support contact and load transfer must all work together, where load transfer confirmation (Fs/W ≥ η and lasting τ) is closest to the safety essence of “no falling after release”.
- Pneumatic interlock, vacuum pressure holding, air cut holding, pressure/vacuum monitoring, double button and abnormal locking areDefense in depth covering different failure paths, rather than repeated configuration; the threshold must be determined based on project verification.
Organization: Jiangsu Aurek Intelligent Technology Co., Ltd. · Engineering Research Center (Lianyungang, Jiangsu) · Document category: Enterprise Engineering Research White Paper · Version: V1.1. This document addresses the engineering design, solution review, and acceptance validation of custom handling tooling. Its thresholds and example parameters illustrate the method,do not constitute a universal performance commitment for all projects or operating conditions;The actual project should be determined based on the workpiece, working conditions, risk assessment and verification records. The full text of the PDF can be downloaded in the upper right corner or at the end of the text.
00Abstract
In the non-standard automated handling system, the fixture is responsible for key actions such as grabbing, lifting, transporting, positioning and releasing the workpiece. The safety of the clamp not only depends on "clamping when needed", but also depends on "not releasing when safety conditions are not met". In scenarios where the workpiece is suspended in the air, has not been stabilized, the load has not been transferred, the operator accidentally touches the button, or the air path or vacuum status is abnormal, unexpected release may directly cause the load to fall or the equipment to be damaged.
This article addresses release safety in custom handling tooling. It establishes a load-state model and a release-permissive logic comprising height confirmation, position confirmation, support-contact confirmation, and load-transfer confirmation. It combines that logic with pneumatic interlocks, vacuum retention, loss-of-air protection, dual-button release, press-and-hold confirmation, abnormal-state lockout, and multi-sensor fusion to form a "Non-permitted status is not released"engineering control method. The article also provides formula variable descriptions, design points for different fixture types, FMEA risk analysis, test methods, acceptance items and engineering design checklists. Relevant thresholds, times and qualification criteria should be determined based on project risk assessment and actual measurement verification; the examples in the article are used to illustrate methods and do not replace project-level safety assessments.
01Introduction
1.1 Research Background
custom handling tooling are widely used in scenarios such as mechanical processing loading and unloading, automobile parts handling, battery module transfer, sheet metal handling, and heavy-duty logistics. Compared with standard fixtures, custom tooling are usually customized based on workpiece shape, quality, surface state, handling cycle and equipment boundary conditions, so their structural forms, sensor configurations and control logic are quite different. In engineering practice, tooling safety is often simplified to whether the clamping force, vacuum holding force or magnetic force is sufficient. ButThe release phase is also a high-risk phase: If the load is still in the air, or if it contacts the support surface but has not yet completed the load transfer, the release action may transform the "clamped" workpiece into a "unsupported" workpiece. Therefore, confirmation of release conditions should be included in the core scope of the clamp safety design.
1.2 "Clampable" does not mean "safe"
The safety of the clamp includes two independent propositions: first, it must be clamped when it needs to be clamped; second, it cannot be released when the safe release conditions are not met. The former belongs to the problem of clamping ability and holding ability, and the latter belongs to the problem of release permission and status control. Failure of either of the two may cause the load to be out of control.
1.3 Scope and Boundaries
The object of this article is to prevent accidental release and load placement confirmation methods of custom handling tooling, focusing on mechanical clamps, vacuum gripping, electro-permanent magnet clamps and their combinations. This article does not replace project safety assessment, equipment risk assessment, functional safety calculation or third-party certification; in specific projects, verification should be combined with the consequences of workpiece failure, handling actions, personnel accessible areas, control system architecture and relevant standard requirements.
02Misrelease risk definition and control objectives
2.1 Definition of Inadvertent Release
This article defines false release as: when the safe release conditions are not met, the clamp loosens the clamp, releases pressure, breaks the vacuum, demagnetizes, blows to release, or other actions that cause the holding force to decrease. Inadvertent release is different from clamping failure: clamping failure is "unable to grasp", and incorrect release is "unable to grasp".I got loose when I shouldn't have loosened up.". The control objectives of preventing accidental release can be summarized as three points: not releasing in the air, not releasing when it is not stable, and not releasing in abnormal conditions. To meet this goal, the system needs to confirm the load status, release permission, operation intention and safety chain status at the same time.
2.2 Inadvertent-Release Risk Categories
| No. | Risk type | Typical situation | Main control measures |
|---|---|---|---|
| R1 | release while suspended | The load is still suspended and the release valve or clamp unclamping mechanism receives a release request. | State machine blocking, placement/transfer confirmation, pneumatic or electrical release interlock |
| R2 | Release before the load is fully seated | The load has contacted the support surface, but the support is insufficient or the weight has not been transferred | Contact force confirmation, load transfer confirmation, stabilization time determination |
| R3 | Release by accidental touch | Mis-pressing of a single button, mis-operation of HMI or mis-operation of maintenance | Double buttons, long press to confirm, permission management, operation log |
| R4 | Air cut loose clamp | The compressed-air supply is interrupted and the pressure is lower than the threshold, causing the clamping force to decrease. | Normally closed/self-locking, one-way valve, pressure maintaining valve, gas tank, pressure switch |
| R5 | Vacuum pressure release | Vacuum leakage, suction-cup failure, or interruption of the compressed-air supply reduces the vacuum level | Vacuum tank, vacuum switch, one-way valve, independent circuit, pressure loss lock |
| R6 | Sensor misjudgment | Height, position, contact or load sensors affected by contamination, drift, shock | Multi-source fusion, 2oo3 voting, self-diagnosis, exception locking |
Table 1 Risk classification and main control measures for accidental release
2.3 Top-Event Logic
Taking "unexpected load loss of support" as the top event T, the main cause path can be described by the following formula:
where Eair Represents an air release event, Eunstable Represents an unsettled release event, Epressure Indicates a holding force reduction event caused by abnormal air pressure or vacuum, Econtrol Indicates control malfunction or human misoperation event. Since top events are usually in an "OR" relationship, any critical failure path may lead to dangerous consequences. Therefore, protection cannot rely on a single measure, and reasonable engineering methods should be used.Combination of status constraints, sensor acknowledgments, hardware interlocks and fail-safes。
03load state model
3.1 Need for a State Model
Inadvertent release often occurs when the control system does not accurately distinguish the load status. If the release valve only responds to "button pressed" or "release bit is true" without confirming whether the load has been placed, whether it is stable, and whether the load transfer has been completed, the release action may occur at any stage. The function of the load state model is to constrain the release action as "It can only be executed when the release is allowed."controlled behavior.
3.2 State Definitions
| Status | Name | meaning | release constraints |
|---|---|---|---|
| S0 | No load | Fixture not holding workpiece | No load release action; malfunction still needs to be prevented |
| S1 | Clamping confirmation | the tooling has been clamped/adsorbed/magnetically held but has not been lifted yet | Release prohibited except during controlled access or maintenance procedures |
| S2 | lifting | The workpiece leaves the scraping surface and enters the lifting process | Inhibit release |
| S3 | carry | The workpiece moves with the fixture and is suspended or held by the fixture | Inhibit release |
| S4 | Approach and placement | The workpiece drops to near the target support area | Inhibit release |
| S5 | load shifting | The workpiece contacts the support surface and the load is transferred from the fixture to the support surface. | Release prohibited until transfer is complete and stable |
| S6 | allow release | Positioning, support, load transfer and safety chain conditions are met | The only normal release-permissive state |
| S7 | Release completed | The clamp is released and the load is borne by the support structure | The release action ends and the exit or reset process is entered. |
| S8 | Exception lock | Loss of pressure, vacuum abnormality, sensor inconsistency, emergency stop or logic abnormality detected | Release prohibited; hold or controlled reset after safe handling |
Table 2 Load state definition and release constraints
3.3 State-Transition Principles
In the formula, State(t) is the current state, Sensor(t) is the sensor signal set, Logic(t) is the state machine and release permission logic, and Safety(t) is the safety chain signal such as emergency stop, safety door, safety PLC or safety relay. Normal operations can proceed along S0→S1→S2→S3→S4→S5→S6→S7. In any state, if abnormal pressure, vacuum, sensor contradiction, communication abnormality, emergency stop or safety chain disconnection is detected, S8 abnormal lock should be entered. State advancement should rely on sufficient sensing evidence; when the evidence is insufficient, it should stay in the current state or enter the safe side state.
04Release-permissive logic and control architecture
4.1 Multi-condition "AND" logic
The basic principle of safety release is multi-condition "AND" logic: height, position, contact, load transfer, operation request, safety chain and fault-free status must be met simultaneously.No single sensor, single button, or single software variable should have the ability to independently trigger a release.
4.2 Four-Factor Release Permission
In the formula, R is the release permissive; Hs Highly confirmed; Ls For horizontal/attitude position confirmation; Ps Confirmation for support contact;Os Confirm for load transfer. Release permission is established when all four items are true. This criterion emphasizes "irreplaceability": the height in place cannot replace load transfer, the position in place cannot replace support contact, and the operation request cannot replace safety confirmation.
4.3 Final Release-Command Synthesis
In the formula, Operator_Request is the release request after inadvertent-operation prevention; Safety_OK indicates a valid safety chain; No_Fault means there is no abnormal lockout, sensor fault, insufficient pressure, insufficient vacuum, or unauthorized maintenance bypass. Release shall not drive the release valve directly; enable it indirectly through a safety output, pilot permissive, or hardware interlock. This prevents a single logic fault in the supervisory controller or standard PLC from bypassing hardware release constraints.
4.4 Dual-Channel Permissive Architecture and Diversity
where Rsensor is the judgment result from the physical sensing channel, Rlogic It is the judgment result of the state machine and control logic channel. The two channels should use different principles as much as possible to reduce the risk of common cause failure. For example, the sensor channel can be composed of a height sensor, a support side weighing module and a pressure/vacuum switch; the logic channel can be composed of a state machine, action sequence, time window and safety chain status. If the conclusions of the two channels are inconsistent, the system should prohibit release and prompt diagnosis.
4.5 Separation of Software and Hardware Responsibilities
Software is suitable for completing state machines, signal fusion, diagnosis and recording; hardware interlocking is suitable for assuming the last line of defense that "even if the software mistakenly sends a release request, it cannot be released". It is recommended to decompose the release action into "Software permissive, hardware enable, valve actuation, actuation-feedback confirmation"Four links and set up diagnoses respectively.
05Position confirmation and load transfer confirmation
5.1 Height Confirmation
In the formula, H is the measured height, Hset To set the landing height, ΔH is the height deviation, EH It is a high allowable error, which can be determined based on positioning accuracy, support structure and sensor repeatability, and is not suitable as a universal fixed value. Height confirmation can only indicate that the load is close to the target height.It cannot be proven independently that the load is supported by the supporting surface.。
5.2 Position and Orientation Confirmation
In the formula, X, Y, θ are the measured horizontal position and attitude angle;0、Y0、θ0 is the target position and orientation; EX、EY、Eθ is the allowable error. If necessary, the Z-direction position, positioning pin entry status or pallet grid status should also be confirmed. The goal of position confirmation is to ensure that the load falls within the effective support area to avoid the risk of partial suspension, offset loading or overturning when the total weight is in contact.
5.3 Support-Contact Confirmation
where Fc is the contact force or the effective contact signal detected on the support side, Fmin is the minimum effective contact threshold. Fmin It should be greater than sensor noise, vibration disturbance and no-load drift, and be determined through no-load/load tests.
5.4 Load-Transfer Confirmation (Core Criterion)
The core of the placement confirmation is not "the height is low enough", but "Whether the weight has been given to the supporting structure". The load transfer confirmation directly corresponds to the safety goal of "no falling after release".
In the formula, W is the design load, m is the mass of the workpiece, g is the gravity acceleration, az Vertical design acceleration that needs to be considered for placement or transportation (can be taken as 0 for static calculations, and dynamic loads should be included when there is impact, rapid descent or emergency stop); Fg is the load still borne by the fixture, Fs It is the load borne by the supporting surface, and it settles with the load Fs Increase, Fg Decrease; Os is the load transfer confirmation result, η is the load transfer proportion threshold (usually 0.85~0.95 As the starting point of the project and determined by verification), τ is the stability confirmation time, which is used to filter short-term shocks or jitters. For multi-point supports or long workpieces, it is only judged that the total support force may be insufficient, and the load distribution and overturning risk of each support point should also be checked, such as adding "any key support point F"si ≥ Fsi,min” “Support moment |Mx|、|My| does not exceed the limit" and other conditions.
5.5 Multisource Fusion and Confidence
Load transfer can be evidenced by support-side weighing modules, gripper-side pressure/force sensors, lifting axis current changes, suction cup vacuum changes, or contact switches. For key decisions, it is recommended to include at least two different types of physical principles.
In the formula, 2oo3 represents a two-out-of-three vote, that is, the conclusion is adopted only when at least two of the three independent judgment signals are confirmed to be valid (the occasional failure of a sensor can be tolerated, but it does not replace sensor diagnosis and project risk assessment); Si is the normalized result of the i-th sensor or decision channel, wi is the weight, C is the comprehensive credibility, Cth is the credibility threshold. Weights and thresholds should be determined experimentally and their basis documented.
5.6 Combined Seating Criterion
This equation shows that height, position, contact and load transfer must all be satisfied.Transfer_OK is a requirement that cannot be replaced; If there is insufficient evidence of transfer, the release should be refused instead of requesting compensation with height or buttons.
06Pneumatic, vacuum and fail-safe design
6.1 Interlock Layers
To prevent accidental release, it is recommended to useDefense in depth at three levels: mechanical, electrical/safety control, and pneumatic/vacuum circuits. The mechanical layer is used for self-locking or limiting, the electrical layer is used for status determination and safety output, and the pneumatic/vacuum layer is used to block unauthorized release actions in the execution loop.
6.2 Pneumatic Release Interlock
This logic means the release-valve pilot or enable circuit may actuate only when the complete release permissive is true, the safety chain is valid, and no fault is present. Do not reduce the interlock to Position_OK, because position alone does not prove load transfer. Use a valve-manifold design that maintains gripping or inhibits release after loss of power or air. If standard PLC outputs coexist with safety outputs, control the release-valve energy path with a safety output or safety relay; use the standard output only for the operator request or motion command.
6.3 Loss-of-Air Protection and Pressure Retention
The goal of air-supply shutoff protection is not to allow the equipment to continue handling normally, but to keep the load under control when the compressed-air supply is abnormal, and to allow the system to enter a safe shutdown, controlled descent, or abnormal lockout process.
- Grippers should use a normally closed, self-locking, or mechanically wedged structure so that loss of air or power does not actively release the load.
- Install a check valve, pressure-holding valve, or locking valve on the clamping or vacuum chamber to reduce the rate of abnormal pressure loss.
- Where necessary, provide an air receiver or energy-storage unit, with clearly defined holding time, minimum pressure, and response strategy.
- The pressure switch should be an independent hardware input to the release-inhibit chain. If pressure falls below the threshold, release must be inhibited and an alarm generated.
- Pressure-retention capability must be validated through leakage, holding-time, and minimum-gripping-force tests; the mere presence of a valve does not establish that the safety requirement is met.
6.4 Vacuum Retention and Vacuum-Release Control
Vacuum fixtures should consider two types of risks at the same time: one is insufficient vacuum leading to a decrease in holding force, and the other is vacuum breaking or air blowing release when the placement conditions are not met.Vacuum release, blow, and exhaust valve actions should be included in the S6 release permission as well as mechanical release.
- Provide a vacuum switch or sensor to monitor whether the vacuum level meets the gripping-permission and handling-retention thresholds.
- Use a vacuum reservoir, check valves, and segmented circuits to reduce the effect of a single-point leak on all suction cups.
- Leak testing should cover static retention, handling acceleration, suction-cup aging, and variation in workpiece surface condition.
- The vacuum-break/blow-off release valve must be governed by Release permission. Unauthorized bypass in maintenance or commissioning mode is prohibited.
- The vacuum holding time, vacuum drop rate and alarm threshold should be determined on a project basis; if indicators such as "the drop rate does not exceed 10% within 30 s" are used, they should be supported by test records.
6.5 Abnormal-State Lockout and Reset
Abnormal locking S8 should also include action locking, alarm prompts, status recording and controlled reset. Reset should not directly restore the release capability, but should re-complete status confirmation, pressure/vacuum confirmation, sensor consistency confirmation and operation authority confirmation.
07Methods to prevent accidental release of different clamp types
7.1 Mechanical-Gripper Tooling
Mechanical grippers mainly rely on form fit, clamping force and friction to hold the workpiece. For vertical handling conditions that rely on friction to maintain, the clamping force can be checked as follows:
In the formula, n is the number of effective friction contact surfaces, μ is the friction coefficient under the most unfavorable working condition, FN is the normal clamping force of a single contact surface, K is the safety factor, m, g, az The meaning is the same as before. If there is horizontal acceleration, eccentric load or impact, anti-skid and overturning should also be checked separately. Key points to prevent accidental release include: normally closed/self-locking structure, clamping in place and opening feedback, clamping pressure monitoring, air cutoff maintenance, release valve interlocking, and prohibiting clamp unclamping in abnormal conditions. For form-fit fixtures, confirm the insertion depth, positioning pins and locking parts, not just the cylinder.
7.2 Vacuum Tooling
where Fvac is the available vacuum holding force, ΔP is the vacuum pressure difference, Aeff is the effective effective suction areas, λ is the correction coefficient after considering the impact of suction cup compression, surface roughness, leakage and orientation; S is the vacuum gripping safety margin, Favailable is the available vacuum holding force under the most unfavorable vacuum degree and effective area, Frequired In order to consider the workpiece weight, acceleration, attitude and the required force after disturbance, Smin Determined by project risk assessment. The key points to prevent accidental release include: the vacuum is allowed to increase only when it reaches the threshold, the vacuum degree is monitored in real time during transportation, the maintenance/alarm/safety disposal process is entered when the vacuum is insufficient, and the vacuum-breaking release is only executed in the S6 release state. Multi-cup systems should be evaluated for residual holding capacity after failure of a single suction cup, single branch, or single vacuum source.
7.3 Magnetic Tooling (Electro-Permanent Magnet)
The electro-permanent magnet clamp is powered on to complete the magnetization or demagnetization action. It can usually maintain its magnetic force after the power is turned off, and is suitable for handling materials that can be magnetized. Its safety concerns are not only power-off release, but also include poor fit, air gap changes, material differences, misjudgment of residual magnetism and false triggering of demagnetization action.
where Fmag Effective magnetic retention under the most adverse air gap, material and fit conditions. Magnetic parameters should be confirmed through sample testing or supplier's valid data, rather than just the ideal suction value. Key points to prevent accidental release include: magnetization completion feedback, suction or bonding status confirmation, demagnetization action included in release permission, maintenance and demagnetization authority management, and load disposal process after abnormal power outage.
7.4 Comparison of Tooling Types
| Gripper Type | Main principles of maintenance | Main failure modes | Key points to prevent accidental release |
|---|---|---|---|
| Mechanical Gripper | Clamping force, friction, form fit | The air is cut off and the clamp is loose, insufficient clamping, slipping, and not locked in place. | Normally closed/self-locking, pressure monitoring, opening feedback, release valve interlock |
| Vacuum Handling | Pressure difference between inside and outside of suction cup | Leakage, aging of the suction cup, vacuum breaking malfunction, defective surface | Vacuum monitoring, vacuum tank, one-way valve, partitioned circuit, vacuum breaking permit |
| Electro permanent magnet | Magnetic circuit holding force | Poor fit, material differences, false triggering of demagnetization, misjudgment of residual magnetism | Charging/demagnetizing status restriction, suction confirmation, demagnetizing authority management |
| Combination fixture | Multi-hold principle superposition | Single retention mode failure, logic switching error | Clarify the primary/auxiliary hold relationship, and maintain at least one effective hold when switching |
Table 3: Holding principles, failure modes and key points to prevent accidental release of various tooling units
08Ergonomics and misuse protection
Ergonomic measures reduce the likelihood of inadvertent actuation and operating error, but must not replace the state machine, sensor confirmation, or hardware interlocks.Even if the operator issues a release request, the system should still deny the release as long as the release permission is not established.
8.1 Two-Button and Press-and-Hold Confirmation
In the formula B1、B2 For two independent button signals, Tsync is the synchronization window, Tpress is the continuous pressing time, Thold is the long press threshold. Tsync and Thold It should be determined based on operating cycle time, ergonomics and risk assessment. Double buttons and long presses can reduce the probability of single-point false touches. However, if you need to meet safety level requirements, you should choose input devices and safety control architectures with corresponding safety levels instead of just writing logic in ordinary PLCs.
8.2 HMI Secondary Confirmation and Status Indication
HMI can be used to display statuses such as "release prohibited, approaching placement, load transfer in progress, release allowed, abnormal locking", and provide secondary confirmation at key workstations. The role of HMI validation is to enhance operational visibility and traceability,Cannot bypass R, Safety_OK and No_Fault。
8.3 Maintenance Mode and Access Control
Bypass operations such as maintenance release, manual vacuum breaking, and manual demagnetization should be restricted through permissions, key switches, low speed/jogging, area clearing, and operation logs. Release in maintenance mode should still retain load support confirmation or manual tooling support confirmation as much as possible to avoid "maintenance bypass" becoming a new mistaken release path.
09FMEA risk analysis
The following table is an example of FMEA to prevent accidental release of custom handling tooling. The scoring is only used to illustrate the method and should be re-evaluated during project implementation based on workpiece quality, personnel exposure, cycle time, historical faults, diagnostic coverage and actual test data.
| failure mode | main reason | Consequences | S/O/D/RPN | control measures | Verification points |
|---|---|---|---|---|---|
| release while suspended | State machine error, release valve malfunction, bypass uncontrolled | Falling load, equipment damage, personnel risk | 10/3/4/120 | S1~S5 inhibit release; safety interlock on the release valve; S6 is the sole release-permissive state | Inject a release request in the floating state, confirm that the valve does not operate and record an alarm |
| Release before the load is fully seated | The height is in place but the support is insufficient; partial load; transfer is not completed | Tipping, slipping, fixture or workpiece damage | 9/4/4/144 | Contact confirmation, load transfer confirmation, stabilization time, eccentric load monitoring | Create boundary positioning, eccentric loading and partial support conditions, and confirm that the dangerous side is not allowed |
| Air cut loose clamp | Main compressed-air supply interruption, pipeline leakage, valve leakage | Reduced holding force and loss of load control | 10/2/5/100 | Normally closed/self-locking, one-way valve, pressure maintaining valve, pressure switch, gas tank | Cut off the air supply and measure the holding time, minimum pressure and clamping force |
| Vacuum pressure loss | Suction cup leakage, abnormal vacuum source, surface contamination | The vacuum holding force decreases and the load drops. | 10/3/4/120 | Vacuum tank, one-way valve, vacuum monitoring, partitioned circuit, pressure loss lock | Simulate different leak rates to verify alarm, hold and release blockade |
| Release by accidental touch | Single button accidental touch, HMI misclick, maintenance misoperation | Unexpected release request enters the system | 8/5/3/120 | Double button, long press, secondary confirmation, permission management | Single button, short press, and unauthorized operation shall not trigger Release. |
| Sensor misjudgment | Contamination, drift, cable failure, reflection or vibration | Mistakenly believed to have been placed or transferred | 8/4/4/128 | Multi-source fusion, 2oo3, self-diagnosis, signal consistency check | Disconnect/short/drift injection, confirm entry inhibit release or abnormal lockout |
| Software or communication abnormality | Program defects, communication delays, variable writing errors | Release-permissive logic error or state inconsistency | 10/2/5/100 | Safety PLC, watchdog, dual-channel permissive, version control | Communication outages, watchdog timeouts, and version regression testing |
Table 4 Failure mode and impact analysis of prevention of accidental release (example, RPN is the internal evaluation model of the enterprise)
Projects with higher RPN or severity of 9 to 10 should be implemented with priorityHardware interlocking and experimental verification. Even if the RPN is reduced by measures, higher severity failures should still retain periodic verification and maintenance inspections.
10Test methods and acceptance items
10.1 Validation Principles
Validation should be centered around "No accidental release, no misjudgment of dangerous sides, and abnormalities can be diagnosed” is expanded through boundary operating conditions, fault injection, repeatability testing, and traceable records. Claims such as “100% inhibition,” “zero inadvertent releases,” or “one hundred thousand fault-free cycles” may be published as project results only when supported by a complete test report, sample definition, and statistical basis.
10.2 Functional and Interlock Test Matrix
| test category | Test method | expected result | Acceptance record |
|---|---|---|---|
| Status blocked | Send release requests one by one in S1~S5 | Release is not established, the release valve does not operate, and the system gives the prohibition reason. | Record status, request, valve output, alarm information |
| allow release | Send a release request when all S6 conditions are met | The release actions are executed in sequence, and S7 is entered after the release is completed. | Record Hs/Ls/Ps/Os, safety chain, action feedback |
| Pneumatic interlock | Send a normal release command after disconnecting the pilot permissive or safety output | The release valve has no action and the air path remains blocked. | Record pilot pressure or valve position feedback |
| safety chain | Trigger emergency stop, safety door or safety relay disconnection | Immediately inhibit release; maintain clamping or perform safe disposal if necessary | Logging security chain inputs and state machine transitions |
| Abnormal reset | Create conflicting sensor signals or insufficient pressure, then reset | After reset, all diagnostic and permissive conditions must be re-established; direct release is prohibited. | Record fault codes, reset people and reset conditions |
Table 5: Function and interlock test matrix
10.3 Seating and Load-Transfer Tests
| Project | Test method | Suggestions on eligibility criteria |
|---|---|---|
| height confirmed | Tested separately at target height, boundary height and out-of-tolerance height | Height_OK is only allowed if the height is within the threshold; rejected if it exceeds the tolerance. |
| location confirmation | Set working conditions such as X/Y/orientation deviation, positioning pin not entering, pallet offset, etc. | Position_OK is false when the deviation exceeds the limit or the positioning is not in place. |
| Contact confirmation | Set up contact, light contact, no contact and sensor noise working conditions | Contact force less than Fmin Or refuse to release when the signal is not credible |
| load shifting | Measure transfer ratio using weighing, gripper side force or current trends | Fs/W reaches η and lasts for τ before setting Transfer_OK |
| Unbalanced load/multi-point support | Creating a single suspended point, excessive load on one side or abnormal support point | The total support force is satisfied but the eccentric load still refuses to be released when it exceeds the limit. |
| Misjudgment of dangerous side | Count the number of false permissions for all working conditions that should be rejected | Dangerous side false permission should be 0; conservative rejection should be recorded and optimized |
Table 6: Placement and load transfer tests
10.4 Loss-of-Air, Pressure-Loss, and Holding Tests
| Project | Test method | Record content | Acceptance concerns |
|---|---|---|---|
| loss-of-air retention | Shut off the compressed-air supply at rated load | Pressure curve, clamping force, holding time, state transfer | The holding time meets the needs of safe disposal; no loosening will occur |
| slow leak | Artificially set up small leaks and continuously monitor them | Pressure/vacuum drop rate, alarm time, lock time | Alarm thresholds are appropriate and the trend is diagnosable. |
| rapid loss of pressure | Disconnect main air or vacuum source | Valve position, pressure, load status, alarm | System goes into hold/lock, no release allowed |
| Restore compressed-air supply | After the abnormality, restore the compressed-air supply and try the operation | Whether it is necessary to reset and whether to re-confirm the status | Restoration must not automatically release the load or clear the fault. |
Table 7: Gas cut-off, pressure loss and maintenance tests
10.5 Human-Factor Incorrect-Operation Tests
| Test items | Test method | expected result |
|---|---|---|
| single button | Just press B1 or B2 | Release is not established |
| Asynchronous press | Two buttons past Tsync press | Release is not established |
| Short press | duration less than Thold | Release is not established |
| Maintenance release without permission | Unauthorized user performs manual release or vacuum breaking | Deny the operation and log it |
| Allow release prompt | Operator performs release at S6 | Clear status indication and correct sequence of actions |
Table 8 Human-machine misoperation test
10.6 Documentation and Acceptance Outputs
- Risk-assessment and FMEA records;
- calculations for gripping force, vacuum holding force, or magnetic holding force;
- release-permissive logic diagram, state-machine diagram, and safety I/O list;
- pneumatic, vacuum, and electrical schematics with interlock descriptions;
- test records, fault-injection records, and abnormal-reset records;
- maintenance-inspection items and a periodic pressure-retention/leakage validation plan;
- operating instructions and maintenance-mode access-control instructions.
11Engineering Design Checklist
| Category | Check items | Acceptance criteria |
|---|---|---|
| Clamping capacity | Clamping/vacuum gripping/magnetic force calculation | The most unfavorable working condition parameters are adopted, and the safety factor and basis are clear |
| Clamping capacity | Dynamic load considerations | Consider additional loads caused by lifting, lowering, emergency stops, swings or impacts |
| Placement confirmation | Height and location confirmation | The threshold basis is clear and the boundary test is passed |
| Placement confirmation | Support contact confirmation | The contact signal is greater than the noise and drift, and the failure can be diagnosed |
| load shifting | Transfer ratio confirmation | Fs/W reaches the project threshold η and maintains τ; multi-point support eccentric load is controlled |
| release logic | four factor licensing | R = Hs ∧ Ls ∧ Ps ∧ Os, single point substitution is not allowed |
| release logic | final command synthesis | Operator_Request, R, Safety_OK, No_Fault are established at the same time |
| Pneumatic interlock | pilot permissive | Release valve is enabled by the full permission chain, loss of power/gas guidance inhibits release |
| Air-supply shutoff protection | Keep pressure and maintain | The maintenance time after cutting off the compressed-air supply meets the requirements for safe disposal, and there are test records |
| Vacuum system | Vacuum monitoring and leakage prevention | Complete range of vacuum switches/sensors, vacuum tanks, check valves and leak tests |
| Ergonomics | Dual button/long press/permissions | Single-point accidental touch, short press, and unauthorized operation cannot trigger the release. |
| Corrective Action | Abnormal lock and reset | S8 fully documented with lockout, fault codes, controlled resets and operations |
| Verification information | Testing and Traceability | Complete testing methods, sample sizes, qualification criteria, original records and closed-loop questions |
Table 9 custom handling tooling anti-accidental release engineering design checklist
12Engineering conclusion
The safety design of custom tooling should cover both the propositions of "clamping" and "cannot be released at the wrong time". The former is a matter of maintaining capabilities, and the latter is an issue of release permission and state security. The release action should be constrained by the load state machine,Release state execution is only allowed in S6, S1 ~ S5 and S8 and other states should block the release channel at the software and hardware layers at the same time.
Placement confirmation should not rely solely on height or position.Height, position, support contact and load transfer must all work together, among which the load transfer confirmation is closest to the safety essence of "no falling after release". Pneumatic interlocking, vacuum pressure holding, air cut holding, pressure/vacuum monitoring, double buttons, long press confirmation and abnormal locking are not repeated configurations, but in-depth defense covering different failure paths.
The thresholds, synchronization windows, holding times, transfer ratios and safety factors involved in this article should be determined through project-level risk assessment, prototype testing and acceptance records. Upgrade the fixture control from simple "action control" to "State-based safety control” helps reduce the risks caused by aerial release, unsteady release, pressure loss release and human misoperation, and provides an executable framework for the engineering design, design review and acceptance of custom handling tooling.
