SAFETY-ORIENTED AUTOMATION SYSTEM

AT1888744TActive Publication Date: 2026-03-15SIEMENS AG
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
AT2017165756T
Authority / Receiving Office
AT · AT
Patent Type
Patents
Current Assignee / Owner
Filing Date
2017-04-10
Publication Date
2026-03-15
Estimated Expiration
2037-04-10

AI Technical Summary

Technical Problem

Existing automation systems lack reliable methods to establish and verify functionally safe connections between devices without unique identifiers like DIL switches, leading to potential errors in communication between robots and tools in production cells.

Method used

Incorporating a point-to-point communication line between coupling points, enabling automation devices to securely check connections through a challenge-response method or functionally safe IO-Link point-to-point coupling, ensuring accurate pairing and preventing erroneous connections.

Benefits of technology

This solution ensures reliable and secure communication between automation devices, preventing errors and ensuring functional safety by verifying correct connections, thus enhancing the safety of automation systems like tool changers and robot systems.

✦ Generated by Eureka AI based on patent content.
Patent Text Reader

Abstract

In order to increase the functional safety of an automation system (1), it is proposed to install additional point-to-point communication lines (11, 12) in addition to the fieldbus (FB).
Need to check novelty before this filing date? Find Prior Art

Description

[0001] The invention relates to an automation system comprising a fieldbus with at least three coupling points, which are designed in such a way that automatic coupling and uncoupling of automation devices to the fieldbus is possible, wherein the respective coupled automation devices are designed to establish functionally safe connections to each other via the fieldbus, wherein the functional safety achieved thereby serves to avoid dangerous malfunctions due to errors.

[0002] For the purposes of this invention, functional safety means the safety of a part of an automation system that depends on the correct functioning of the safety-related systems and external risk-minimizing devices. Functional safety is achieved when every risk is mitigated by safety functions in such a way that the machine or the associated automation system can be considered safe. In this case, one speaks of safety-related automation systems.

[0003] Functional safety is required, for example, in a tool changer. In a manufacturing cell, for instance, several robots work alternately with different tools (e.g., welding guns). When a robot picks up a tool, a functionally safe connection is established between the tool and the controller that manages the robot. Tools used infrequently are shared among the robots and can therefore be used interchangeably on different robots. A secure communication link to the tool must only be established for controlling the robot that is currently using that tool. Physical separation is not an option, as the robot controllers must be able to communicate with each other.

[0004] The coupling points could, for example, be the flanges of the robots in this case.

[0005] DE 10 2013 003 166 A1 discloses a safety module for a fieldbus participant and an automation system. To define a safety-related identification address, a setting device is provided for in the housing of a safety module. A unique identification address is set in this setting device, for example, a DIP switch.

[0006] The object of the present invention is to provide an automation system with a slot-dependent structure of functionally safe fieldbus connections, while dispensing with an adjustment device such as a DIL switch.

[0007] For the aforementioned automation system, the task is solved by providing a point-to-point communication line in addition to the fieldbus between at least a first and a second connection point. This creates a paired relationship between the automation devices that can be connected to and disconnected from the fieldbus, for a first automation device that can be connected to and disconnected from the first connection point and for a second automation device that can be connected to and disconnected from the second connection point. Each of the connectable and disconnectable automation devices has a point-to-point communication endpoint configured to establish point-to-point communication via the point-to-point communication line in addition to fieldbus communication. Furthermore, at least one of the connectable and disconnectable automation devices has a test device configured to...The additional communication made possible by the extra point-to-point communication line can be used to reliably verify whether the desired functionally safe connection between the automation devices has been established and whether the desired automation device is indeed located at the opposite end of the point-to-point communication line, and whether a functionally safe connection is being erroneously established with an automation device located at a different connection point that does not correspond to the paired relationship.

[0008] In simplified terms, according to the invention, in addition to the fieldbus or a fieldbus communication line, an additional communication line is arranged between the automation devices, with an additional connector for the automated coupling of the interchangeable device to the coupling point. Accordingly, an additional communication line could be added to the same cable as the fieldbus communication line and to the same connector, which functionally only allows "point-to-point" communication. The use of a point-to-point connection ensures that there is no error scenario for this communication protocol in which a telegram sent by the sender could be received by a receiver other than the intended one. Such a point-to-point coupling can be set up so that the first automation device can reliably communicate with the second automation device via the connector connection available at a given time X.The connector used for point-to-point communication at time X therefore determines which communication connections are permitted. This allows the two automation devices to reliably verify whether they are currently connected or not. Once this verification is complete, a secure fieldbus connection between the automation devices can be established via the fieldbus.

[0009] In another embodiment, four coupling points are available, and in addition to the fieldbus between a third coupling point and a fourth coupling point, a second point-to-point communication line is available, thus providing a further pair relationship between automation devices that can be connected to and disconnected from the fieldbus for an automation device that can be connected to and disconnected from the third coupling point and for an automation device that can be connected to and disconnected from the fourth coupling point.

[0010] In an initial configuration, the testing equipment also includes means for performing a challenge-response procedure. A reliable test of the existing communication link between two connectable and disconnectable automation devices can then be carried out using a challenge-response procedure. The first automation device uses the challenge-response mechanism to formulate a different request (challenge) at each point in time, which the second automation device, or the partner automation device in the pair, must answer appropriately (response) as soon as the connection is established. For each new connection, the first automation device modifies the request. This ensures that the request cannot be answered erroneously by a storage network component, such as a router, using an outdated message.

[0011] In this configuration, the first point-to-point communication line and the second point-to-point communication line, and the corresponding point-to-point communication endpoints arranged in the automation devices, are designed as a standardized IO-Link point-to-point coupling.

[0012] A second design option proposes configuring the first and second point-to-point communication lines, along with the corresponding point-to-point communication endpoints located in the automation devices, as a functionally safe IO-Link point-to-point coupling using a functionally safe protocol. For this purpose, the point-to-point communication endpoints are additionally designed as functionally safe point-to-point communication endpoints.

[0013] Furthermore, it is advisable that the automation devices have functionally safe fieldbus communication endpoints for functionally safe communication.

[0014] Particularly with regard to automation devices designed as tool changers, robot systems or clamping frames, it is advantageous if the automation devices are assigned to a handling and / or machining system, and if at least one automation device is designed as an interchangeable tool with a fieldbus participant that is designed for controlling actuators on the tool.

[0015] The drawing shows an embodiment of the invention, wherein the FIG 1 an automation system with a fieldbus and coupling points according to the state of the art, FIG 2 the automation system according to FIG 1 with the illustration of a false connection, FIG 3 an automation system according to the invention with additional point-to-point communication lines and FIG 4 the automation system according to the invention with additional point-to-point communication lines using a functionally safe point-to-point coupling.

[0016] According to the FIG 1 This illustrates the fundamental problem of establishing functionally safe connections between connectable and disconnectable automation devices. The communication between a first automation device G1 and a second automation device G2, or between a third automation device G3 and the second automation device G2, is functionally safety-relevant. For example, the second automation device G2 may contain safe sensors and / or actuators that need to communicate with the first automation device G1 or the third automation device G3 via a safe channel. This safe communication should also serve to reliably identify which devices are currently connected. For example, the second automation device G2 should be permitted to perform certain actions as long as it is connected to the first automation device G1.However, the same actions are to be prohibited for safety reasons when the second automation device G2 is connected to the third automation device G3.

[0017] Regarding the safety of automation devices, the following problem arises, for example: For functional safety reasons, an error in the use of the second automation device G2 by the automation devices G1 and G3 must be detected with a high probability and lead to a safe state. For example, an error could occur in which the second automation device G2, which is connected to the first automation device G1, establishes a logical connection between the third automation device G3 and the second automation device G2 due to a fault (see [reference]). FIG 2 A faulty connection 20 was erroneously established between the third automation device G3 and the second automation device G2. A common mechanism for detecting incorrectly established connections or addressing errors is the use of unique identifiers for the individual connections in the safe communication layer (e.g., "codename" in PROFIsafe). However, in this case, the identifier "codename" does not provide the necessary error detection required for the described scenario in a fieldbus used in a functionally safe communication layer (as described in IEC 61874-3X). This is because the identifier "codename" in the second automation device G2 can be visible to both other automation devices G1 and G3, even if the automation devices are not connected at the corresponding interface points.The goal is therefore to find a solution that reliably detects the establishment of a false connection and manages with a single identifier or "codename" for the connection, which can also be used interchangeably.

[0018] With the FIG 3 Figure 1 shows an automation system 1 according to the invention with a fieldbus FB. The first automation device G1 is assigned a first coupling point S1 and the second automation device G2 is assigned a second coupling point S2. The second automation device G2 is docked at the second coupling point S2 in such a way that it can establish a communication connection to the fieldbus FB as well as a communication connection to a first point-to-point communication line 11 laid in addition to the fieldbus FB between the first automation device G1 and the first coupling point S1 or the second coupling point S2.In addition to the fieldbus FB, a point-to-point communication line 11 is therefore available between the first coupling point S1 and the second coupling point S2, thus providing a pair relationship between automation devices G1 and G2 that can be connected to and disconnected from the fieldbus FB for a first automation device G1 that can be connected to and disconnected from the first coupling point S1 and for a second automation device G2 that can be connected to and disconnected from the second coupling point S2.

[0019] To reliably detect the presence of an automation device G2 at the fourth connection point S4, the third connection point S3 has a second point-to-point communication line 12 in addition to the fieldbus FB. This second point-to-point communication line 12 leads from the third connection point S3 to the fourth connection point S4 via a connector.

[0020] If the second automation device G2 is now connected to the second connection point S2, a second point-to-point communication endpoint P2 located in the second automation device G2 can connect via the additional point-to-point communication line 11 to a first point-to-point communication endpoint P1 located in the first automation device G1. Using a first test device PM1, which is configured to use the additional communication via the first point-to-point communication line 11, it can be reliably verified whether the second automation device G2 is connected to the second connection point S2 assigned to the first automation device G1.

[0021] The third automation device G3 also has a second test device PM2, which is designed to reliably verify whether the second automation device G2 is connected at the fourth connection point S4. The second point-to-point communication line 12 is used for this reliable test.

[0022] In the embodiment according to FIG 3 The test equipment PM1 and PM2 also include means for carrying out a challenge-response procedure. An example of this procedure involves using a sufficiently unique numerical value (e.g., generating an N-bit random value) in the first automation device G1 and the third automation device G3. A random number generator (RND) is available for this purpose. The generated random number is communicated to the second automation device G2 via the newly introduced first point-to-point communication line 11. The second automation device G2 modifies the random value in a predefined manner (e.g., bitwise inversion or multiplication by an odd N-bit constant) and sends the result back. If the first automation device G1 receives the result, the second automation device G2 then sends the result back.Since the third automation device G3 returns the expected value, it can be concluded that a mechanical connection to the second automation device G2 has been established. Safety-related data can then be exchanged via the functionally safe connection between the first automation device G1 and the second automation device G2 using the fieldbus FB. For this purpose, both the first automation device G1 and the second automation device G2 have a first functionally safe fieldbus communication endpoint F1 and a second functionally safe fieldbus communication endpoint F2. The second automation device G2 has the corresponding counterpart for functionally safe communication via the fieldbus FB with its second functionally safe fieldbus communication endpoint F2.Using the aforementioned functionally safe fieldbus communication endpoints F1, F2, F3, functionally safe communication 21 can now be carried out between the two automation devices G1 and G2.

[0023] According to FIG 4One configuration variant is shown, in which functionally safe point-to-point communication is used. Functionally safe point-to-point communication can be achieved, for example, through a functionally safe IO-Link point-to-point coupling with a functionally safe protocol. For this functionally safe point-to-point communication, the first automation device G1 has a first functionally safe point-to-point communication endpoint FP1, and the second automation device G1 has a second functionally safe point-to-point communication endpoint FP2. The third automation device G3 accordingly has a third functionally safe point-to-point communication endpoint FP3.For functionally safe additional communication between the first automation device G1 and the second automation device G2, the additional functionally safe point-to-point communication endpoints FP1 and FP2 are used for communication via the first point-to-point communication line 11.

Claims

1. Automation system (1) comprising a fieldbus (FB) with at least three coupling points (S1, S2, S3) which are designed in such a way that automatic coupling and uncoupling of automation devices (G1, G2, G3) to the fieldbus (FB) is possible, wherein the respective coupled automation devices (G1, G2, G3) are designed to establish functionally safe connections to each other via the fieldbus (FB), wherein the functional safety achieved thereby serves to prevent dangerous malfunctions due to faults, characterized by the fact thatIn addition to the fieldbus (FB), a point-to-point communication line (11) is provided between at least a first coupling point (S1) and a second coupling point (S2), thereby establishing a pair relationship between automation devices (G1, G2, G3) that can be connected to and disconnected from the fieldbus (FB) for a first automation device (G1) that can be connected to and disconnected from the first coupling point (S1) and for a second automation device (G2) that can be connected to and disconnected from the fieldbus (FB), wherein the connectable and disconnectable automation devices (G1, G2, G3) each have a point-to-point communication endpoint (P1, P2, P3) which are configured to establish point-to-point communication via the point-to-point communication line (11) in addition to the fieldbus communication, and furthermore, at least one of the connectable and disconnectable automation devices (G1, G2, G3) a testing device (PM1, PM2) which is designed toUsing the additional communication made possible by the additional point-to-point communication line (11), it is possible to reliably check whether the desired functionally safe connection between the automation devices (G1, G2, G3) has been established and whether the desired automation device (G1, G2, G3) is also located at the opposite end of the point-to-point communication line (11), and whether a functionally safe connection is not erroneously established to an automation device (G1, G2, G3) that is located at a different coupling point (S3) which does not correspond to the pair relationship.

2. Automation system (1) according to claim 1, wherein four coupling points (S1, S2, S3, S4) are provided, and in addition to the fieldbus (FB) between a third coupling point (S3) and a fourth coupling point (S4) a second point-to-point communication line (12) is provided, whereby for an automation device (G1, G2, G3) that can be connected to and disconnected from the third coupling point (S1) and for an automation device (G1, G2, G3) that can be connected to and disconnected from the fourth coupling point (S4) there is a further pair relationship between automation devices (G1, G2, G3) that can be connected to and disconnected from the fieldbus (FB).

3. Automation system (1) according to claim 1 or 2, wherein the testing means (PM1, PM2) comprise means for performing a challenge-response procedure.

4. Automation system (1) according to claim 2 or 3, wherein the first point-to-point communication line (11) and the second point-to-point communication line (12) and the corresponding point-to-point communication endpoints (P1, P2) arranged in the automation devices (G1, G2, G3) are designed as a standardized IO-Link point-to-point coupling.

5. Automation system (1) according to claim 2 or 3, wherein the first point-to-point communication line (11) and the second point-to-point communication line (12) and the corresponding point-to-point communication endpoints (P1, P2) arranged in the automation devices (G1, G2, G3) are designed as a functionally safe IO-Link point-to-point coupling with a functionally safe protocol.

6. Automation system (1) according to any one of claims 1 to 5, wherein the automation devices (G1, G2, G3) have functionally safe fieldbus communication endpoints.

7. Automation system according to one of the preceding claims, characterized by the fact that the automation devices (G1, G2, G3) are assigned to a handling and / or processing system, and at least one automation device (G1, G2, G3) is designed as an interchangeable tool with a fieldbus participant that is designed to control actuators on the tool.