Dual-system redundancy safety circuit and self-diagnosis method
By introducing a dual-system redundancy structure of electromagnetic relays and solid-state PLCs into the elevator safety circuit, real-time online diagnosis and seamless switching of the elevator safety circuit are realized, solving the problems of contact aging and imperfect fault switching in the existing elevator safety circuit, and improving the safety and reliability of the elevator.
Patent Information
- Application Number
- CN202511878555.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-12-12
- Publication Date
- 2026-01-30
AI Technical Summary
Existing elevator safety circuits suffer from issues such as aging contacts, inability to monitor in real time, lack of proactive verification capabilities, and imperfect fault switching mechanisms, resulting in insufficient safety and reliability.
The first safety system, which uses electromagnetic relays and hard-wired logic, and the second safety system, which uses a solid-state PLC that has passed safety certification, achieve active diagnosis and seamless switching of the first safety system by generating encrypted diagnostic trigger pulse sequences and sampling current waveforms in real time.
It enables real-time online diagnosis of elevator safety circuits, proactively identifies potential hazards, and ensures seamless switching to the secondary safety system in case of failure, thereby improving elevator safety and operational continuity.
Smart Images

Figure CN121433201A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of industrial safety control technology, and in particular to a dual-system redundant safety loop and self-diagnosis method. Background Technology
[0002] As the most critical vertical transportation equipment in high-rise buildings, the operational safety of elevators is directly related to the safety of people's lives. Elevator safety control systems typically rely on safety components such as safety relays, safety links, electromagnetic braking devices, and emergency stop valves, using hard-wired logic to implement core safety functions such as overspeed protection, rope breakage protection, and brake holding. During long-term operation, due to frequent actions, electrical shocks, high humidity, and high temperatures, safety relay contacts may experience aging problems such as wear, carbonization, increased contact resistance, and increased engagement delay. This could lead to potential risks such as delayed brake action, accidental breakage or misconnection of the safety chain.
[0003] Existing elevator safety circuits still generally suffer from significant technical shortcomings: First, elevator safety chains rely on mechanical contact structures, making it impossible to determine in real time whether contact actions are delayed or stuck, relying solely on periodic manual inspections, which cannot meet the requirements for online health monitoring; Second, although some elevators have introduced dual-channel controllers, the second system is usually used as a passive redundancy channel, lacking the ability to actively and in real-time verify the main safety circuit, resulting in the inability to dynamically guarantee the health status of the hardware safety chain; Third, traditional safety devices lack the ability to sample and analyze the waveform of the brake's operating current, making it impossible to identify potential hazards such as abnormal brake engagement, coil aging, and power fluctuations; Fourth, existing elevator fault switching mechanisms mostly rely on simple logical judgments, lacking hardware interlocking and output locking functions, posing a safety risk of fault propagation causing simultaneous output from both channels. Summary of the Invention
[0004] This invention provides a dual-system redundant safety loop and self-diagnosis method that is applicable to the elevator industry, has real-time online diagnostic capabilities, and can autonomously trigger tests and achieve safety redundancy switching, thereby comprehensively improving the reliability and intelligence level of elevator safety systems.
[0005] The dual-system redundant safety loop includes a first safety system, a second safety system, a test load, and a switching unit, wherein: The first safety system is a hardware safety circuit consisting of an electromagnetic relay and hard-wired logic. The second safety system is a solid-state programmable logic controller (PLC) that has passed safety certification. The test load is connected to the main circuit through a test contactor in the first safety system. The input terminal of the switching unit is connected to the power output terminals of the first and second safety systems respectively. The output terminal of the switching unit is connected to a safety device. The second safety system includes an analog input module for high-precision sampling of the circuit current. The safety device is a safety brake, a safety contactor, or an emergency stop valve.
[0006] A self-diagnostic method for diagnosing the dual-system redundant safety loop includes the following steps: S1: The second security system generates an encrypted diagnostic trigger pulse sequence and sends the encrypted diagnostic trigger pulse sequence to the input terminal of the first security system; S2: In response to the encrypted diagnostic trigger pulse sequence, the first security system closes a test contactor in its main security circuit to connect a test load to the circuit, simulating a real security action current. S3: The second safety system uses its analog input module to sample the safety action current waveform flowing through the test load in real time, and compares the safety action current waveform with the pre-stored ideal current waveform template to generate a status diagnosis result of the contact response delay and load capacity of the first safety system. S4: Based on the status diagnosis results, the second security system controls a dedicated solid-state switching output point to drive the switching unit to perform an action, thereby seamlessly switching the control of the system from the first security system to the second security system itself. Optionally, S1 includes: S11: The second security system calls its internal security pseudo-random number generation algorithm to generate a random number sequence for the current period; S12: The second security system calculates the pulse width parameter and pulse interval parameter required for this diagnostic trigger based on the random number sequence and a preset mapping rule; S13: The second security system uses its hardware timer to generate an encrypted diagnostic trigger pulse sequence with a defined timing based on the pulse width parameter and the pulse interval parameter; S14: The second security system adds a cyclic redundancy check code to the end of the frame of the encrypted diagnostic trigger pulse sequence to form a complete encrypted diagnostic trigger pulse sequence data frame; S15: The second security system sends the complete encrypted diagnostic trigger pulse sequence data frame to the input of the first security system through its isolated digital output channel.
[0007] Optionally, the second security system calls its internal secure pseudo-random number generation algorithm to generate a random number sequence for the current period. Specifically, the second security system uses the SM4 algorithm, which conforms to the national cryptographic standard, as the secure pseudo-random number generation algorithm, and uses the system running time and hardware serial number as the mixed entropy source to generate a random number sequence for the current period with a length of 128 bits.
[0008] Optionally, S2 includes: S21: The first security system receives an encrypted diagnostic trigger pulse sequence from the second security system through its input interface, and performs signal conditioning and level conversion on the encrypted diagnostic trigger pulse sequence; S22: The first security system uses its decoding logic circuit to decode and verify the encrypted diagnostic trigger pulse sequence after signal conditioning and level conversion, and generates a test contactor drive command; S23: The first safety system amplifies the power of the test contactor drive command through its relay drive circuit and outputs the test contactor drive signal. S24: The first safety system uses the test contactor drive signal to control the electromagnetic coil of the test contactor to be energized, so that the main contacts of the test contactor are closed. S25: The first safety system connects the test load to the main safety circuit by closing the main contact of the test contactor, and generates a safety action current in the main safety circuit that simulates a real safety action.
[0009] Optionally, the first security system uses its decoding logic circuit to decode and verify the encrypted diagnostic trigger pulse sequence after signal conditioning and level conversion, and generates a test contactor drive instruction. Specifically, the first security system uses a hard-wired decoding logic circuit composed of shift registers and logic gates to perform Manchester decoding and CRC check verification on the encrypted diagnostic trigger pulse sequence after signal conditioning and level conversion. When the verification is successful, a valid test contactor drive instruction is generated.
[0010] Optionally, S3 includes: S31: The second safety system acquires the safety action current waveform flowing through the test load in real time through its analog input module at a sampling rate of not less than 100ksps, and performs anti-aliasing filtering and ADC conversion processing on the safety action current waveform to obtain a digital safety action current waveform. S32: The second safety system performs moving average filtering and baseline calibration on the digitized safety action current waveform to obtain a pre-processed safety action current waveform. S33: The second safety system performs cross-correlation calculation and rise time extraction on the pre-processed safety action current waveform and the pre-stored ideal current waveform template read from the non-volatile memory to obtain waveform similarity index and measured response delay data. S34: The second safety system compares the waveform similarity index with the first preset threshold and the measured response delay data with the second preset threshold. Based on the dual comparison results, it generates a status diagnosis result that includes contact response delay assessment and load capacity assessment.
[0011] Optionally, the second safety system performs moving average filtering and baseline calibration on the digitized safety action current waveform to obtain a pre-processed safety action current waveform. Specifically, the second safety system uses a moving average filter with a window length of 11 points to perform time-domain smoothing on the digitized safety action current waveform, and performs baseline calibration based on the average value of the 100 sampling points before the start of waveform acquisition as the baseline value to obtain a pre-processed safety action current waveform with zero baseline accuracy.
[0012] Optionally, S4 includes: S41: The second security system parses the status diagnosis result, and when the status diagnosis result indicates that the first security system has a fault, it generates a switching control decision; S42: The second security system prepares a switching execution instruction based on the switching control decision and verifies the legality of the switching execution instruction through internal security logic; S43: The second security system sends the verified switching execution command to its dedicated solid-state switching output point, driving the solid-state switching output point to generate a switching drive signal; S44: The second safety system controls the switching unit to perform mechanical switching action through the switching drive signal, and after the switching is completed, confirms that the second safety system has taken over control through the status feedback loop, and locks the output of the first safety system.
[0013] Optionally, the second safety system parses the status diagnosis results. When the status diagnosis results indicate that the first safety system has a fault, it generates a switching control decision. Specifically, the second safety system parses the contact response delay assessment and load capacity assessment data in the status diagnosis results through its safety state machine. When any assessment result is marked as unqualified, it generates a switching control decision containing an immediate switching instruction and a switching reason code.
[0014] The beneficial effects of this invention are: 1. This invention employs a first safety system composed of electromagnetic relays and hard-wired logic as the main safety chain for the elevator, offering advantages such as fast response and controllable physical structure. Simultaneously, a safety-certified solid-state PLC is introduced as the second safety system, enabling data acquisition, waveform processing, and logic judgment. The two systems form a safe redundancy structure through an optocoupler-isolated communication interface and a mechanical interlock switching unit. This not only avoids the risk of simultaneous output from both channels of the brake circuit but also allows for safe takeover in case of contact lag or operational failure in the main safety chain, providing a higher level of system integrity protection for the elevator brake, safety contactor, and emergency stop valve.
[0015] 2. The second safety system of this invention drives a test contactor by generating an encrypted diagnostic trigger pulse sequence, connecting the test load to the elevator safety circuit to simulate the actual operating current of the elevator brake coil. Through high-speed sampling, anti-aliasing filtering, moving average processing, Pearson correlation analysis, and 10%-90% rise edge extraction, this invention can accurately identify safety hazards such as brake engagement delay, power supply distortion, poor relay contact, and reduced load capacity, achieving real-time monitoring capabilities that traditional manual inspections cannot cover. Compared to the passive safety chain structure of existing elevators, this invention can actively verify the status of the main safety chain, enabling the elevator to maintain safe operating capabilities during long-term operation.
[0016] 3. In this invention, when the self-diagnostic method detects a contact response delay or insufficient load capacity in the first safety system, the second safety system verifies the legality of the switching command through a dual-core architecture and outputs a 24VDC / 2A switching drive signal through the MOSFET solid-state output point to control the mechanical interlock contactor to cut off the main safety chain and close the second safety chain. After the switching action is completed, the second safety system confirms control takeover through auxiliary contact feedback and sends a hard-wired output disable signal to the first safety system, fundamentally eliminating the risk of dual output, malfunction, or loss of control in the elevator under fault conditions. This mechanism enables the elevator to maintain reliable brake operation even when the safety chain fails, significantly improving the overall safety and operational continuity of the elevator. Attached Figure Description
[0017] To more clearly illustrate the technical solutions in this invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only for this invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0018] Figure 1 This is a schematic diagram of the dual-system redundant safety loop structure according to an embodiment of the present invention; Figure 2 This is a schematic diagram of the self-diagnosis method according to an embodiment of the present invention. Detailed Implementation
[0019] The present invention will now be described in detail with reference to the accompanying drawings and specific embodiments. It should also be noted that, to make the embodiments more comprehensive, the following embodiments are the best and preferred embodiments, and those skilled in the art can use other alternative methods to implement some well-known technologies; moreover, the accompanying drawings are only for more specific description of the embodiments and are not intended to specifically limit the present invention.
[0020] It should be noted that the use of terms such as "an embodiment," "an embodiment," "an exemplary embodiment," and "some embodiments" in the specification indicates that the described embodiment may include a specific feature, structure, or characteristic, but not every embodiment necessarily includes that specific feature, structure, or characteristic. Furthermore, when a specific feature, structure, or characteristic is described in connection with an embodiment, implementing such a feature, structure, or characteristic in conjunction with other embodiments (whether explicitly described or not) should be within the knowledge of those skilled in the art.
[0021] Generally, terms can be understood at least partly from their use in context. For example, depending at least partly on the context, the term "one or more" as used herein can be used to describe any feature, structure, or characteristic in a singular sense, or a combination of features, structures, or characteristics in a plural sense. Additionally, the term "based on" can be understood not necessarily to convey an exclusive set of factors, but rather, alternatively, depending at least partly on the context, to allow for the presence of other factors that are not necessarily explicitly described.
[0022] like Figure 1 As shown, the dual-system redundant safety loop includes a first safety system, a second safety system, a test load, and a switching unit, wherein: The first safety system is a hardware safety circuit consisting of electromagnetic relays and hard-wired logic. The first safety system employs a hardware safety circuit consisting of electromagnetic relays and hard-wired logic. The first safety system includes multiple safety relays for operating the main safety circuit, as well as test contactors for performing self-diagnostic tests.
[0023] The test contactor adopts a magnetic latching relay structure, with a coil drive voltage of 24VDC and a contact capacity of not less than 50A / 250VAC. It is arranged in an electrically and mechanically isolated manner from other relays to eliminate electrical interference to the main circuit caused by the test.
[0024] To ensure independent monitoring of the second safety system, the first safety system is equipped with a watchdog monitoring circuit. This circuit operates independently of the second safety system and is used to monitor the heartbeat signal from the second safety system in real time. Once the watchdog detects a loss or abnormal frequency of the heartbeat from the second safety system, the first safety system will maintain its control over the switching unit to prevent the system from entering an uncontrolled state.
[0025] The first and second security systems are connected via an optocoupler-isolated communication interface that uses the RS-485 differential signal transmission protocol. A signal conditioning circuit is installed on the first security system side to enhance anti-interference capabilities and improve the quality of the differential communication signal.
[0026] The second safety system is a certified solid-state programmable logic controller (PLC) with high-speed data acquisition and waveform comparison capabilities. It is internally equipped with an analog input module for high-precision real-time sampling of the current flowing through the test load.
[0027] The analog input module employs 16-bit resolution and differential input, with a sampling rate of no less than 100 kSPS to ensure complete capture of the dynamic characteristics of the safety operating current waveform. Its input front-end is equipped with an anti-aliasing filter and necessary signal conditioning circuitry to ensure that the input signal has achieved bandwidth limitation and noise suppression before acquisition.
[0028] The second safety system is equipped with non-volatile memory to store ideal current waveform templates, diagnostic threshold parameters, and historical diagnostic records, enabling the system to perform long-term trend analysis and safety circuit aging assessment.
[0029] The test load is connected to the main circuit through the test contactor in the first safety system. The test load is a power alloy resistor with a resistance accuracy of ±1% and a power capacity of not less than 500W. It is installed on an aluminum heat sink with heat dissipation fins to ensure that it can withstand high current for a long time during the test without thermal runaway.
[0030] Based on the rated operating current of the safety device, the resistance of the test load is set such that the test current passing through it is within the range of 80%–120% of the rated operating current, thereby simulating the electrical load conditions of the safety device when it is actually operating, and providing highly realistic current characteristics for subsequent waveform comparison.
[0031] The input terminal of the switching unit is connected to the power output terminals of the first safety system and the second safety system respectively, and the output terminal of the switching unit is connected to the safety device. The switching unit adopts a mechanically interlocked double contactor structure, including a first system contactor and a second system contactor.
[0032] The coil of the first system contactor is driven by the first safety system, and the coil of the second system contactor is driven by the second safety system. The two contactors are physically interlocked by a lever-type mechanical interlock mechanism. When either contactor is in the closed position, the mechanical interlock device will prevent the other contactor from closing through a physical blocking structure, ensuring that the two safety controls are not energized simultaneously and cause circuit conflict.
[0033] With this design, even if the second safety system produces a software malfunction or an output control error, it will not cause the system to enter a failure state where both contactors are closed simultaneously, thus ensuring that the safety circuit is always in single-point control mode.
[0034] To ensure secure and reliable data transmission between the first and second safety systems, an optically isolated RS-485 differential communication interface is used. The first safety system is equipped with a signal conditioning circuit for receiving differential signals; the second safety system uses an isolated transceiver to maintain electrical isolation between the PLC system and external hard-wired circuits, improving the overall system's tolerance to high-voltage pulses and common-mode interference.
[0035] Under normal operating conditions, both systems are operational, but the first safety system maintains primary control over the safety devices via its driven first system contactor. When the second safety system completes its self-diagnosis of the current waveform and determines that the first safety system is operating normally, the switching unit remains inactive. When an abnormal contact delay or load capacity is detected in the first safety system, the second safety system drives its second system contactor via a dedicated solid-state switching output point, seamlessly switching system control from the first safety system to the second safety system.
[0036] The safety device is a safety brake, a safety contactor, or an emergency stop valve.
[0037] like Figure 2 As shown, a self-diagnostic method for diagnosing dual-system redundant safety loops includes the following steps: S1: The second security system generates an encrypted diagnostic trigger pulse sequence and sends the encrypted diagnostic trigger pulse sequence to the input terminal of the first security system, specifically: S11: The second security system calls its internal security pseudo-random number generation algorithm to generate a random number sequence for triggering diagnostics in this cycle.
[0038] The second security system employs the SM4 algorithm, compliant with national cryptographic standards, as its secure pseudo-random number generation algorithm. The SM4 algorithm operates as an independent security module within the second security system to ensure the unpredictability and irreversibility of the random number sequence. The second security system uses the real-time count value of the system's runtime counter as a time entropy source and the internally stored hardware serial number as a fixed entropy source. These two entropy sources are mixed and processed before being used as input to the SM4 algorithm. The second security system performs a complete SM4 encryption operation, outputting a 128-bit random number sequence for the current period, and stores this random number sequence in the second security system's internal register.
[0039] S12: The second safety system calculates the pulse width and pulse interval parameters required for this diagnostic trigger based on the random number sequence obtained in S11 and through a preset mapping rule.
[0040] The second safety system first reads the first 64 bits of the random number sequence as the raw pulse width data. This raw pulse width data is then input into a nonlinear transformation function, which performs a fixed polynomial transformation on the input value, mapping the result to a preset pulse width range. The second safety system uses this mapping result as the pulse width parameter and writes it into the pulse width parameter register.
[0041] Subsequently, the second security system reads the last 64 bits of the random number sequence as the original pulse interval data. The second security system then segments the original pulse interval data into high and low bits, and maps the segmented data to a preset pulse interval range using a lookup table method.
[0042] The lookup table used in the lookup method is stored in the non-volatile memory of the second security system. The second security system searches the lookup table for the corresponding target interval value based on the segmented values of the original pulse interval data, and uses the found target interval value as the pulse interval parameter. The second security system writes the pulse interval parameter into the period register, providing a time basis for the subsequent generation of the encrypted diagnostic trigger pulse sequence.
[0043] S13: The second security system calls its hardware timer to generate an encrypted diagnostic trigger pulse sequence with a defined timing based on the pulse width and pulse interval parameters obtained in S12.
[0044] The second safety system first writes the pulse width parameter to the pulse width register of the hardware timer and the pulse interval parameter to the period register of the hardware timer. The hardware timer operates in PWM mode. The second safety system configures the hardware timer to single-trigger mode, so that after triggering, the timer outputs only a single-cycle PWM pulse sequence determined by the pulse width and pulse interval parameters. Driven by an internal clock reference, the second safety system starts the hardware timer. The hardware timer generates an encrypted diagnostic trigger pulse sequence based on the preset register contents and outputs this sequence stably to the digital output control module for subsequent processing.
[0045] S14: The second security system performs verification and encoding processing on the encrypted diagnostic trigger pulse sequence generated in S13.
[0046] The second security system uses the CRC-16-CCITT standard to perform a verification operation on the encrypted diagnostic trigger pulse sequence. The second security system reads the complete encrypted diagnostic trigger pulse sequence and performs a byte-by-byte verification operation according to the polynomial parameters of CRC-16-CCITT to obtain the cyclic redundancy check code.
[0047] The second security system appends a cyclic redundancy check (CRC) code to the end of the pulse sequence, making the encrypted diagnostic trigger pulse sequence a complete encrypted diagnostic trigger pulse sequence data frame containing a frame header, command word, pulse parameters, and CRC code. The second security system buffers this data frame in its communication buffer.
[0048] S15: The second security system sends the complete encrypted diagnostic trigger pulse sequence data frame generated in S14 to the input of the first security system.
[0049] The second security system utilizes its optocoupler-isolated digital output channel to perform Manchester encoding on the data frame. The second security system continuously outputs the Manchester-encoded encrypted diagnostic trigger pulse sequence data frame at a fixed rate of 125 kbps through its digital output channel. This digital output channel is connected to the input of the first security system via an RS-485 differential signal interface. Throughout the transmission process, the second security system maintains stability in its output drive current and drive voltage to ensure that the first security system can correctly receive, parse, and execute subsequent test actions.
[0050] S2: In response to the encrypted diagnostic trigger pulse sequence, the first security system closes a test contactor in its main security circuit to connect a test load to the circuit, simulating a real security action current, specifically: S21: The first security system receives, conditions, and converts the encrypted diagnostic trigger pulse sequence sent by the second security system.
[0051] The first security system receives the encrypted diagnostic trigger pulse sequence through its optocoupler-isolated input interface with Schmitt trigger characteristics. The optocoupler-isolated input interface utilizes an opto-isolation structure to achieve electrical isolation between the two systems and uses a Schmitt trigger input stage to ensure the edge transition rate and jitter resistance of the input signal. The first security system feeds the input signal into an RC low-pass filter circuit, which filters out high-frequency noise in the encrypted diagnostic trigger pulse sequence through rigorously calculated resistor and capacitor parameters, stabilizing the signal waveform. Subsequently, the first security system uses an internal comparator circuit to perform level conversion on the RC low-pass filtered signal, converting the conditioned signal into an encrypted diagnostic trigger pulse sequence that conforms to the internal logic level standard of the first security system, thus providing a reliable input for subsequent decoding verification.
[0052] S22: The first security system decodes and verifies the received encrypted diagnostic trigger pulse sequence based on its fixed hardware decoding structure.
[0053] The first security system uses a hard-wired decoding logic circuit composed of a shift register and logic gates to perform Manchester decoding on the encrypted diagnostic trigger pulse sequence. The shift register synchronously shifts in the level-converted pulse data based on a fixed clock signal, and the logic gates parse the level sequence output by the shift register bit by bit according to the Manchester encoding rules. After decoding, the first security system immediately performs CRC verification on the decoded data. The CRC verification uses the same CRC-16-CCITT verification rules as the second security system, and is calculated byte-by-byte with a 0x1021 polynomial as a fixed parameter. When the CRC verification result matches the checksum appended to the end of the encrypted diagnostic trigger pulse sequence, the first security system determines that the pulse sequence is valid and generates a test contactor drive command; when the CRC verification fails, the first security system does not generate a test contactor drive command and keeps the main security circuit in a safe standby state.
[0054] S23: The first safety system amplifies the power of the test contactor drive command generated in S22 to form a test contactor drive signal with actual drive capability.
[0055] The first safety system incorporates a relay drive circuit composed of a Darlington transistor array, which features high current gain. The first safety system uses the test contactor drive command as the input signal to the Darlington transistor array, which amplifies the input current to ensure the output can drive the electromagnetic coil of the magnetic latching relay-type test contactor. The test contactor drive signal output by the first safety system has a fixed voltage level of 24VDC, a drive current of not less than 2A, and is sent to the test contactor coil terminals through an independently isolated output interface. This output signal meets the minimum operating requirements specified by the test contactor in terms of current amplitude, duration, and rise rate, thereby ensuring reliable closure of the test contactor during each diagnostic trigger.
[0056] S24: The first safety system uses the test contactor drive signal generated in S23 to activate the test contactor.
[0057] The first safety system applies a test contactor drive signal to the electromagnetic coil of the magnetic latching relay-type test contactor, energizing the coil and causing it to engage. The electromagnetic engagement mechanism switches the main contacts of the test contactor from a normally open state to a closed state, maintaining reliable contact with stable contact pressure. The rated current-carrying capacity of the main contacts of the test contactor is not less than 150% of the normal operating current of the safety device, ensuring that no contact welding, contact chattering, or abnormal temperature rise occurs when simulating real safety operating current flow, providing a safe and reliable conduction path for current generation in subsequent steps.
[0058] S25: The first safety system connects the test load to the main safety circuit through the main contacts after the test contactor is closed, so that the main safety circuit generates a safety action current that simulates the real safety action.
[0059] The first safety system connects a test load with a resistance of 5 ohms and a power of not less than 500W to the main safety circuit based on the conduction state of the main contacts of the test contactor. The main safety circuit is a 220VAC power supply circuit. After the test load is connected, a safety operating current of not less than 44A is generated in the main safety circuit. The amplitude, waveform, and rise time characteristics of this safety operating current accurately reflect the electrical parameters of the safety device during actual operation, enabling the second safety system to accurately capture the current characteristics representing the availability and health status of the first safety system during subsequent sampling, providing basic data for subsequent diagnostic logic.
[0060] S3: The second safety system, through its analog input module, samples the safety action current waveform flowing through the test load in real time, and compares the safety action current waveform with a pre-stored ideal current waveform template to generate a status diagnosis result of the contact response delay and load capacity of the first safety system. Specifically: S31: The second safety system uses its analog input module to perform high-precision acquisition, anti-aliasing filtering, and ADC conversion on the safety action current waveform flowing through the test load to obtain a digital safety action current waveform.
[0061] The second safety system utilizes its 16-bit high-precision differential input analog input module, setting the sampling rate to 200ksps to meet the sampling requirement of no less than 100ksps. The second safety system acquires the safety action current waveform flowing through the test load via differential input, ensuring the input signal maintains high common-mode rejection capability even under high-frequency interference. Before sampling, the second safety system uses a Butterworth anti-aliasing filter with a cutoff frequency of 20kHz to bandwidth-limit the input current signal's spectrum, ensuring the signal entering the ADC fully meets the Nyquist frequency requirement. After anti-aliasing filtering, the second safety system performs analog-to-digital conversion on the filtered analog signal using its internal 16-bit ADC converter, outputting a digitized safety action current waveform data sequence with a quantization resolution of 16 bits. The second safety system buffers this data in the internal waveform buffer according to the sampling order.
[0062] S32: The second safety system performs digital preprocessing on the digital safety action current waveform obtained in S31, including moving average filtering and baseline calibration after smoothing.
[0063] The second safety system invokes an 11-point moving average filter to smooth the waveform data sequence in the time domain, eliminating high-frequency sampling jitter and suppressing local spikes caused by electromagnetic interference. During the moving average process, the second safety system calculates the average value point-by-point using a fixed-length window and replaces the original sampling point at each location with the calculated result, generating a smoothed waveform sequence.
[0064] Subsequently, the second safety system performs baseline calibration on the smoothed waveform. The second safety system reads the data from the first 100 sampling points before sampling begins, calculates the arithmetic mean of these sampling points as the baseline value, and uses this baseline value as the zero-point reference. The second safety system subtracts this baseline value from all sampling points in the smoothed waveform, ensuring that the waveform's reference level is strictly aligned to the zero baseline, thus obtaining a pre-processed safety operating current waveform, providing a consistent amplitude reference for subsequent cross-correlation comparisons.
[0065] S33: The second safety system extracts waveform features from the waveform processed by S32, including cross-correlation coefficient calculation and rise time extraction.
[0066] The second safety system first reads a pre-stored ideal current waveform template from its non-volatile memory. Using the Pearson correlation coefficient algorithm, it cross-correlates the pre-processed safety action current waveform with the ideal current waveform template. The system then performs mean normalization and covariance calculations point-by-point on both waveform sequences, ultimately generating a cross-correlation coefficient ranging from -1 to 1 as a waveform similarity index. This similarity index is stored in a temporary register for subsequent comparisons.
[0067] Subsequently, the second safety system extracts the rise time to determine the contact response delay. The second safety system uses a 10%-90% amplitude threshold method to read the amplitude sequence of the pre-processed safety action current waveform. By scanning the waveform data, it finds the sampling point timestamp where the waveform rises from its initial stable value to 10% of the peak amplitude as the rise start point, and then finds the sampling point timestamp where the waveform reaches 90% of the peak amplitude as the rise end point. The time difference between these two timestamps is used as the measured response delay data. This delay data reflects the actual operating speed of the tested contactor.
[0068] S34: The second safety system, based on the waveform similarity index obtained in S33 and the measured response delay data, performs a dual judgment in combination with a preset threshold to generate a status diagnosis result that includes contact response delay assessment and load capacity assessment.
[0069] The second safety system compares the waveform similarity index obtained from S33 with the first preset threshold of 0.95. When the waveform similarity index is less than 0.95, the second safety system determines that the consistency between the current waveform after the test load is connected and the ideal current waveform template is insufficient, and generates an evaluation result that the load capacity is unqualified.
[0070] A first preset threshold of 0.95 is used to determine the similarity between the pre-processed safety action current waveform and the ideal current waveform template. By sampling the current waveforms of multiple batches of safety devices operating over long periods and calculating correlation coefficients, it was found that the cross-correlation coefficients of waveforms under healthy conditions mainly fall between 0.97 and 0.995, with some waveforms affected by environmental factors falling within the range of 0.95 to 0.97. Based on this statistical distribution, 0.95 was determined as a significant dividing point between normal and abnormal waveforms, effectively identifying waveform distortions caused by contact wear, increased contact resistance, or incomplete engagement. Furthermore, in accordance with the requirements for safety function consistency indicators in ISO 13849 and IEC 61508, 0.95 is used as the minimum waveform similarity threshold, ensuring that both the false positive and false negative rates of diagnosis remain within safe limits.
[0071] Meanwhile, the second safety system compares the measured response delay data with the second preset threshold of 10ms. When the measured response delay data is greater than 10ms, the second safety system determines that the contactor's contact action speed is insufficient and generates an evaluation result that the contact response delay is unqualified.
[0072] The second preset threshold of 10ms is used to determine whether the contact response delay of the test contactor meets the safety operation performance requirements. Analysis of the operating characteristics of industrial-grade electromagnetic relays, magnetic latching relays, and safety contactors shows that the pull-in time under healthy conditions is typically between 3ms and 8ms, with a maximum allowable pull-in time generally not exceeding 10ms. According to the technical requirements of IEC / EN 60947 and IEC 61810 regarding the operating time of safety functional components, a performance degradation should be considered when the actual operating time exceeds approximately 40% of the nominal operating time. Furthermore, sampling tests on a large number of aged or potentially faulty safety devices revealed that devices with contact response delays exceeding 10ms are often accompanied by magnetic circuit degradation, mechanical blockage, or contact wear. Therefore, setting 10ms as the upper limit threshold for contact response delay effectively distinguishes between normal pull-in states and performance degradation states, ensuring the accuracy and timeliness of switching decisions.
[0073] The second safety system performs comprehensive processing based on the above two judgment results to form a status diagnosis result that includes contact response delay assessment and load capacity assessment. The status diagnosis result is then written into the internal diagnostic register of the second safety system to provide a basis for the subsequent S4 switching decision.
[0074] S4: Based on the status diagnosis results, the second security system controls a dedicated solid-state switching output point to drive the switching unit to perform an action, thereby seamlessly switching the control of the system from the first security system to the second security system itself, specifically as follows: S41: The second safety system analyzes the status diagnosis results from S34 and generates a switching control decision when a fault is detected in the first safety system.
[0075] The second safety system invokes its internal safety state machine to parse the contact response delay assessment data and load capacity assessment data from the state diagnostic results. The safety state machine first determines whether the contact response delay assessment is marked as unqualified, and then determines whether the load capacity assessment is marked as unqualified. When either assessment data is marked as unqualified, the second safety system immediately generates a switching control decision. This switching control decision includes an immediate switching instruction field and a switching reason code field. The immediate switching instruction field instructs the system to enter the safe takeover process, and the switching reason code field identifies the specific fault type of abnormal contact response delay or insufficient load capacity. The second safety system records the above switching control decision in its internal decision register as input for the generation of subsequent switching execution instructions.
[0076] S42: The second security system generates a switching execution instruction based on the switching control decision and performs strict security logic verification on the switching execution instruction.
[0077] After reading the switching control decision generated in S41, the second safety system constructs a switching execution instruction containing a target system identifier and switching timing parameters according to its internal safety protocol specifications. The target system identifier is used to indicate that the second safety system will take over control, and the switching timing parameters are used to define the specific execution sequence and time interval of the switching unit from disconnecting the first safety system contactor to closing the second safety system contactor.
[0078] After generating the switchover execution instruction, the second security system invokes the cross-validation mechanism of its dual-core processor architecture. The two processing cores independently calculate and verify the legality of the instruction, checking its format, field integrity, parameter range, and security protocol consistency. When both processing cores output a verification pass signal, the switchover execution instruction is confirmed as valid; when either processing core outputs a verification failure signal, the second security system blocks the instruction issuance process and maintains the control privileges of the first security system.
[0079] After the above security logic verification, the switching execution instruction is stored in the security output buffer of the second security system to prepare for subsequent output to the solid-state switching output point.
[0080] S43: The second safety system outputs the verified switching execution command to a dedicated solid-state switching output point, causing the solid-state switching output point to generate a switching drive signal for driving the switching unit.
[0081] The second safety system first invokes its safety digital output module to transmit the switching execution command to the optocoupler-isolated MOSFET solid-state switching output point. Because the solid-state switching output point uses a MOSFET drive structure, it has a fast switching speed and stable output electrical characteristics. The second safety system controls the solid-state switching output point to output a switching drive signal with a 24VDC voltage level and a 2A drive current, and continues to output this signal for a preset duration to ensure reliable operation of the switching unit. The entire drive process is monitored by an independent hardware safety timer, which provides precise timing during the drive process to prevent switching failures caused by insufficient or excessive drive signal duration.
[0082] S44: The second safety system uses the switching drive signal output by S43 to control the switching unit to perform mechanical switching action, and confirms the successful switching through the status feedback loop, while locking the output of the first safety system.
[0083] The second safety system applies a switching drive signal to the coil of the second safety system contactor in the switching unit, causing the contactor to close. At the start of the switching operation, due to the mechanical interlocking structure of the switching unit, the first safety system contactor automatically remains open under the constraint of the line's mechanical structure. The second safety system confirms the switching operation by reading the state combination of the auxiliary contacts of the two contactors in real time. When it detects a state combination where the auxiliary contacts of the first safety system contactor are open and the auxiliary contacts of the second safety system contactor are closed, the second safety system determines that the switching operation has been successfully completed.
[0084] After confirming the completion of the switching action, the second safety system immediately sends an output disable signal to the first safety system. This output disable signal is a continuous low-level signal that acts directly on the enable circuit of the first safety system through hard-wiring, thereby forcibly disabling all output drive circuits of the first safety system. This prevents the first safety system from exerting any control over the switching unit, ensuring that control is completely taken over by the second safety system.
[0085] The second security system records the successful switch status in its non-volatile memory, providing data support for subsequent diagnostic analysis and security incident tracing.
[0086] This invention encompasses any substitutions, modifications, equivalent methods, and solutions made within the spirit and scope of this invention. To provide the public with a thorough understanding of this invention, specific details are described in detail in the following preferred embodiments; however, those skilled in the art will fully understand the invention even without these details. Furthermore, to avoid unnecessary misunderstanding of the essence of this invention, well-known methods, processes, procedures, components, and circuits are not described in detail.
[0087] The above description is only a preferred embodiment of the present invention. It should be noted that for those skilled in the art, several improvements and modifications can be made without departing from the principle of the present invention, and these improvements and modifications should also be considered within the scope of protection of the present invention.
Claims
1. A dual system redundant safety circuit, characterized in that, The first safety system, the second safety system, a test load and a switching unit are included, wherein: The first safety system is a hardware safety circuit composed of an electromagnetic relay and a hard-wired logic, the second safety system is a solid-state programmable logic controller certified by safety, the test load is connected to a main circuit through a test contactor in the first safety system, the input end of the switching unit is connected to the power output end of the first safety system and the second safety system respectively, and the output end of the switching unit is connected to a safety device.
2. A self-diagnosis method for diagnosing the dual-system redundant safety circuit according to claim 1, characterized in that, The method comprises the following steps: The second safety system generates an encrypted diagnostic trigger pulse sequence and sends the encrypted diagnostic trigger pulse sequence to the input end of the first safety system; The first safety system closes a test contactor in the main safety circuit in response to the encrypted diagnostic trigger pulse sequence, so that a test load is connected to the circuit to simulate a real safety action current; The second safety system samples the safety action current waveform flowing through the test load in real time through the analog input module, compares the safety action current waveform with a pre-stored ideal current waveform template, and generates a state diagnosis result of the contact response delay and load capacity of the first safety system; The second safety system controls a dedicated solid-state switching output point based on the state diagnosis result to drive the switching unit to perform an action, so that the control right of the system is seamlessly switched from the first safety system to the second safety system.
3. The dual system redundant safety circuit and self-diagnostic method of claim 2, wherein, The second safety system generates an encrypted diagnostic trigger pulse sequence and sends the encrypted diagnostic trigger pulse sequence to the input end of the first safety system, specifically comprising: The second safety system calls a security pseudo-random number generation algorithm in the second safety system to generate a random number sequence of the current period; The second safety system calculates the pulse width parameter and the pulse interval parameter required for this diagnosis trigger according to the random number sequence through a preset mapping rule; The second safety system uses a hardware timer to generate an encrypted diagnostic trigger pulse sequence with a determined time sequence based on the pulse width parameter and the pulse interval parameter; The second safety system adds a cyclic redundancy check code at the end of the encrypted diagnostic trigger pulse sequence to form a complete encrypted diagnostic trigger pulse sequence data frame; The second safety system sends the complete encrypted diagnostic trigger pulse sequence data frame to the input end of the first safety system through an isolated digital output channel.
4. The dual system redundant safety circuit and self-diagnostic method of claim 3, wherein, The second safety system calls a security pseudo-random number generation algorithm in the second safety system to generate a random number sequence of the current period, specifically: the second safety system uses the SM4 algorithm conforming to the national standard as the security pseudo-random number generation algorithm, and uses the system running time and the hardware serial number as the hybrid entropy source to generate a random number sequence of the current period with a length of 128 bits.
5. The dual system redundant safety circuit and self-diagnostic method of claim 4, wherein, The simulated real safety action current specifically comprises: The first safety system receives the encrypted diagnostic trigger pulse sequence from the second safety system through its input interface, and performs signal conditioning and level conversion on the encrypted diagnostic trigger pulse sequence; The first safety system decodes and verifies the signal-conditioned and level-converted encrypted diagnostic trigger pulse sequence using its decoding logic circuit to generate a test contactor drive instruction; The first safety system power amplifies the test contactor drive instruction through its relay drive circuit to output a test contactor drive signal; The first safety system controls the energization of the electromagnetic coil of the test contactor using the test contactor drive signal, causing the main contact of the test contactor to close; The first safety system connects the test load to the main safety circuit through the closed main contact of the test contactor, generating a safety action current in the main safety circuit that simulates a real safety action.
6. The dual system redundant safety circuit and self-diagnostic method of claim 5, wherein, The first safety system uses its decoding logic circuit to decode and verify the signal-conditioned and level-converted encrypted diagnostic trigger pulse sequence to generate a test contactor drive instruction, specifically: the first safety system uses a hardwired decoding logic circuit composed of a shift register and a logic gate circuit to perform Manchester decoding and CRC verification on the signal-conditioned and level-converted encrypted diagnostic trigger pulse sequence, and generates a valid test contactor drive instruction when the verification is passed.
7. The dual system redundant safety circuit and self-diagnostic method of claim 5, wherein, Generating the state diagnosis result of the contact response delay and load capacity of the first safety system specifically includes: The second safety system collects the safety action current waveform flowing through the test load in real time through its analog input module at a sampling rate of no less than 100ksps, and performs anti-aliasing filtering and ADC conversion processing on the safety action current waveform to obtain a digitized safety action current waveform; The second safety system performs sliding average filtering and baseline calibration processing on the digitized safety action current waveform to obtain a preprocessed safety action current waveform; The second safety system calculates the cross-correlation coefficient and extracts the rising edge time of the preprocessed safety action current waveform and the pre-stored ideal current waveform template read from the non-volatile memory to obtain a waveform similarity index and a measured response delay data; The second safety system compares the waveform similarity index with a first preset threshold value, and simultaneously compares the measured response delay data with a second preset threshold value, and based on the double comparison results, generates a state diagnosis result including contact response delay evaluation and load capacity evaluation.
8. The dual system redundant safety circuit and self-diagnostic method of claim 7, wherein, The second safety system performs sliding average filtering and baseline calibration processing on the digitized safety action current waveform to obtain a preprocessed safety action current waveform, specifically: the second safety system performs time domain smoothing processing on the digitized safety action current waveform using a sliding average filter with a window length of 11 points, and performs baseline calibration based on the average value of the first 100 sampling points before waveform collection as the baseline value to obtain a zero-baseline accurate preprocessed safety action current waveform.
9. The dual system redundant safety circuit and self-diagnostic method of claim 8, wherein, The driving switching unit performs an action specifically including: The second safety system analyzes the state diagnosis result, and generates a switching control decision when the state diagnosis result indicates that the first safety system has a fault; The second safety system prepares a switching execution instruction according to the switching control decision and verifies the legality of the switching execution instruction through internal safety logic; The second safety system sends the switching execution instruction that passes the verification to a solid-state switching output point dedicated to the second safety system, and drives the solid-state switching output point to generate a switching driving signal; The second safety system controls the switching unit to perform a mechanical switching action through the switching driving signal, and confirms that the second safety system has taken over the control right after the switching is completed through a state feedback loop, and locks the output of the first safety system at the same time.
10. The dual system redundant safety circuit and self-diagnostic method of claim 9, wherein, The second safety system analyzes the state diagnosis result, and generates a switching control decision when the state diagnosis result indicates that the first safety system has a fault, specifically: the second safety system analyzes the contact response delay evaluation and load capacity evaluation data in the state diagnosis result through its safety state machine, and generates a switching control decision containing an immediate switching instruction and a switching reason code when any evaluation result is marked as unqualified.
Citation Information
Patent Citations
Elevator function safety control system
CN112978524A
Platform door redundancy control system
CN117250851A
Defect fault detection method and device for electric wire and cable
CN119716405A
Wall-mounted power supply and intelligent monitoring system thereof
CN120511791A
But self -diagnosis and redundant control's illumination control device
CN207692118U
Cited By
Integrated verification platform and verification method
CN121977848A