Dual hand button synchronous interlock safety control module and control method

CN122652928APending Publication Date: 2026-08-28SHENZHEN YIPUXING TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202611113924.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-07-27
Publication Date
2026-08-28

AI Technical Summary

Technical Problem

[0006]为了解决现有技术中双手按钮安全控制模块存在的交叉故障检测不连续、关键逻辑可靠性不足以及单点故障容错能力差等问题,本申请提供了一种双手按钮同步互锁安全控制模块及控制方法

Benefits of technology

首先,通过设置在运行期间连续监测通道间电气隔离状态的交叉故障检测电路,本申请能够实时捕获输入通道间的短路故障并立即执行安全动作,解决现有技术中仅在上电时自检或完全无检测所带来的巨大安全隐患。其次,通过采用纯硬件的同步性检测电路,本申请将核心的同步性判断逻辑从易受干扰的软件实现中剥离,使其不受微处理器程序异常等因素的影响,保证了逻辑判断的可靠性和快速响应。再者,通过采用包含至少两个串联连接的强制导向式开关元件的冗余输出单元,并结合内部反馈监控电路,本申请实现了对单点故障(如单个开关元件触点熔焊)的有效容错,即使一个输出元件失效,另一个仍能可靠地断开安全回路,确保了在任何单一故障下安全功能不丧失,满足了高安全完整性等级的要求。最后,本申请集成了外部设备监控、可选复位模式等多种功能,提供了一个全面、灵活且集成化程度高的安全解决方案,提高了系统的整体安全性能和适用性。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122652928A_ABST
    Figure CN122652928A_ABST
Patent Text Reader

Abstract

The application relates to the technical field of industrial safety control, and discloses a double-hand button synchronous interlocking safety control module and a control method. The module comprises two input channels, a cross fault detection circuit, a synchronism detection circuit, a redundant output unit and an internal feedback monitoring circuit. The cross fault detection circuit continuously monitors the electrical isolation state between the channels during operation, and disconnects the output when an abnormality is found. The synchronism detection circuit measures the time difference when the two input signals become valid, and only allows the output when the time difference is not greater than a preset synchronization time window. The redundant output unit is composed of at least two series-connected forced direction switching elements, and cooperates with the feedback monitoring to ensure that the safety circuit can still be cut off under single-point fault. The application improves the safety and reliability and the response speed through real-time channel isolation monitoring, pure hardware synchronization judgment and redundant output fault-tolerant design, meets the requirements of high safety integrity level, and is suitable for safety application scenarios of various double-hand button control.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of industrial safety control technology, and in particular to a two-hand button synchronous interlocking safety control module and control method. Background Technology

[0002] In industrial production, especially in the operation of high-risk equipment such as stamping machines, injection molding machines, and high-speed presses, a two-hand start device is typically used as a core safety measure to ensure the personal safety of operators. This device requires the operator to simultaneously press two buttons spaced a certain distance apart with both hands to initiate the dangerous action of the equipment, thereby ensuring that the operator's hands are in a safe position during equipment operation and avoiding accidental injury.

[0003] The core component enabling this function is the two-button safety control module, typically a safety relay. Its basic working principle is: it receives input signals from both buttons and determines whether these two signals simultaneously become active within a preset time window (usually 500 milliseconds). Only when the two signals arrive synchronously will the safety control module close its output contacts, allowing the device to start.

[0004] However, existing two-hand button safety control modules still have several safety hazards and design flaws. Firstly, there is a lack of or insufficient cross-fault detection capability. When the external wiring of the two input channels short-circuits due to wear, moisture, or misoperation (i.e., a cross-fault), traditional safety control modules may misinterpret this short-circuit signal as a valid signal of "both hands pressed simultaneously," thus bypassing the safety function, causing the device to start unexpectedly, and resulting in a serious safety accident. While some existing products have cross-fault detection capabilities, they typically only perform a self-test once when the system is powered on, failing to provide continuous online monitoring during device operation. Secondly, there are reliability issues with critical logic. The synchronization judgment and internal logic control of some products rely on a microprocessor (MCU) and software program. Although software can implement complex functions, it inherently has unpredictable failure modes, such as program runaway or clock anomalies, introducing uncertainty into safety functions with high integrity requirements. Furthermore, it has insufficient tolerance for single-point failures. For example, if the output relay contacts become welded together, without effective monitoring and redundancy mechanisms, the safety circuit cannot be reliably disconnected, causing the safety function to completely fail during the next operation. This does not meet the requirements of high-level safety standards (such as Category 4 / PL e in ISO 13849-1).

[0005] Therefore, the industry urgently needs a new type of two-hand button safety control solution that can provide continuous cross-fault monitoring, has highly reliable hardware logic, and has comprehensive single-point fault protection capabilities. Summary of the Invention

[0006] To address the problems of discontinuous cross-fault detection, insufficient reliability of key logic, and poor single-point fault tolerance in existing dual-button safety control modules, this application provides a dual-button synchronous interlock safety control module and control method.

[0007] According to a first aspect of the embodiments disclosed in this application, this application provides a two-hand button synchronous interlocking safety control module, which adopts the following technical solution: A two-hand button synchronous interlocking safety control module includes: The first input channel is used to receive the first input signal from the first two hands button; A second input channel, independent of the first input channel, is used to receive a second input signal from the second two-hand buttons; A cross-fault detection circuit is configured to continuously monitor the electrical isolation status between the first input channel and the second input channel during operation of the safety control module; A synchronization detection circuit is used to measure the time difference between the first input signal and the second input signal becoming valid. A redundant output unit includes at least two independent forced-direction switching elements, the outputs of which are configured to be connected in series to a safety loop of an external device; and An internal feedback monitoring circuit is configured to monitor the state of the forced-direction switching element; The cross fault detection circuit is configured to disconnect the redundant output unit when an abnormal electrical isolation state is detected. The safety control module is configured to only respond to the first input signal and the second input signal, and output a safety output signal to the safety circuit of the external device through the at least two series-connected forced-guided switching elements, when the cross fault detection circuit does not detect the abnormal electrical isolation state, the time difference is not greater than the preset synchronization time window, and the internal feedback monitoring circuit confirms that the at least two forced-guided switching elements are in a non-conducting state.

[0008] Optionally, the cross fault detection circuit is used to monitor the electrical isolation status by continuously monitoring the impedance between the first input channel and the second input channel, and when the impedance is lower than a preset impedance threshold, the cross fault detection circuit controls the redundant output unit to disconnect.

[0009] Optionally, the preset impedance threshold is 500 ohms, and the continuous monitoring period is no more than 1 millisecond.

[0010] Optionally, the synchronization detection circuit includes: An XOR gate, wherein the two input terminals of the XOR gate are electrically connected to the signal output terminals of the first input channel and the second input channel, respectively; and A pulse width to voltage conversion circuit, the input of which is connected to the output of the XOR gate, is composed of resistors and capacitors. It is used to convert the pulse width corresponding to the time difference into a voltage amplitude through capacitor charging and discharging, so as to compare it with a reference voltage representing the preset synchronization time window.

[0011] Optionally, for the safety control module, its input terminal is used to adapt to the dual-contact redundant wiring method, wherein the normally open contacts of the first two-hand buttons and the second two-hand buttons are respectively connected to the first input channel and the second input channel, and their normally closed contacts are connected to the feedback monitoring circuit of the safety control module.

[0012] Optionally, the safety control module further includes an external device monitoring feedback loop for connecting the normally closed auxiliary contact of the controlled external contactor; the safety control module is configured to check the status of the external device monitoring feedback loop before each safety output signal is generated to confirm that the external contactor has not experienced contact welding.

[0013] Optionally, the safety control module further includes a reset mode selection terminal for selecting between an automatic reset mode and a monitored manual reset mode by shorting or disconnecting an external wiring connection.

[0014] According to a second aspect of the embodiments disclosed in this application, this application provides a method for synchronous interlocking safety control of two-hand buttons, which adopts the following technical solution: A method for synchronous interlocking safety control of two-hand buttons, comprising: The first input signal is received from the first two hands buttons through the first input channel; A second input signal from the second two-hand buttons is received through a second input channel that is independent of the first input channel. During operation, the electrical isolation status between the first input channel and the second input channel is continuously monitored, and at least two independent forced-guided switching elements are disconnected when an abnormality in the electrical isolation status is detected. Measure the time difference between the first input signal and the second input signal becoming valid; Before responding to the first input signal and the second input signal to generate a safety output signal, the state of the at least two forced-direction switching elements is checked by an internal feedback monitoring circuit. Only when the cross fault detection circuit does not detect any abnormality in the electrical isolation state, the time difference is not greater than a preset synchronization time window, and the internal feedback monitoring circuit confirms that at least two forced-guided switching elements are both in a non-conducting state, is it permitted to respond to the first input signal and the second input signal and output a safety output signal to the safety circuit of the external device through the at least two forced-guided switching elements connected in series.

[0015] Optionally, the step of continuously monitoring the electrical isolation status between the first input channel and the second input channel includes: continuously monitoring the impedance between the first input channel and the second input channel, and disconnecting the forced-direction switching element when the impedance is less than 500 ohms.

[0016] In summary, this application provides a two-hand button synchronous interlocking safety control module and control method. Compared with the prior art, this application has the following advantages: First, by incorporating a cross-fault detection circuit that continuously monitors the electrical isolation status between channels during operation, this application can capture short-circuit faults between input channels in real time and immediately execute safety actions, thus resolving the significant safety hazards caused by existing technologies that only perform self-tests upon power-up or have no detection at all. Second, by employing a purely hardware-based synchronization detection circuit, this application separates the core synchronization judgment logic from the easily interfered software implementation, making it unaffected by factors such as microprocessor program anomalies, ensuring the reliability and rapid response of the logic judgment. Third, by employing a redundant output unit containing at least two series-connected forced-guided switching elements, combined with an internal feedback monitoring circuit, this application achieves effective fault tolerance for single-point faults (such as the welding of a single switching element contact). Even if one output element fails, the other can still reliably disconnect the safety loop, ensuring that the safety function is not lost under any single fault, meeting the requirements of a high level of safety integrity. Finally, this application integrates multiple functions such as external device monitoring and optional reset modes, providing a comprehensive, flexible, and highly integrated safety solution, improving the overall safety performance and applicability of the system.

[0017] Other features and advantages disclosed in this application will be described in detail in the following detailed description section. Attached Figure Description

[0018] The accompanying drawings are provided to further illustrate the present disclosure and form part of the specification. They are used together with the following detailed description to explain the present disclosure, but do not constitute a limitation thereof. In the drawings: Figure 1 This is a functional block diagram of a two-hand button synchronous interlock safety control module according to an exemplary embodiment.

[0019] Figure 2 This is a typical application wiring diagram of a two-hand button synchronous interlock safety control module according to an exemplary embodiment.

[0020] Figure 3 This is a schematic diagram illustrating the cross-fault detection circuit of a two-hand button synchronous interlock safety control module according to an exemplary embodiment.

[0021] Figure 4 This is a timing diagram illustrating the synchronization time window detection of a two-hand button synchronous interlock safety control module according to an exemplary embodiment.

[0022] Reference numerals: 10, Cross fault detection circuit; 20, Synchronization detection circuit; 30, Logic processing unit; 40, Redundant output unit; 50, Internal feedback monitoring circuit; 60, External device monitoring feedback loop. Detailed Implementation

[0023] The specific embodiments disclosed in this application will be described in detail below with reference to the accompanying drawings. It should be understood that the specific embodiments described herein are for illustration and explanation only and are not intended to limit the scope of this disclosure.

[0024] Please see Figure 1 This illustration demonstrates the overall functional architecture of a two-hand button synchronous interlock safety control module in one embodiment of this application. The module is designed to provide safe start-up control for high-risk industrial equipment in compliance with ISO 13849-1 Category 4 / PL e standards. The overall signal flow begins with the operator's operation of the external two-hand buttons, the signal entering the module through two hardware-independent input channels: the first input channel CH1 and the second input channel CH2. These two channels are connected to input terminals S11 and S21, respectively. After entering, the signals undergo a series of rigorous safety checks in parallel, including continuous monitoring of the inter-channel electrical isolation status performed by the cross-fault detection circuit 10, and measurement of the synchronicity of the two-hand operation performed by the synchronicity detection circuit 20.

[0025] The verification result is sent to a logic processing unit 30, which comprehensively evaluates all safety conditions. Only when all conditions are met will the logic processing unit 30 drive a redundant output unit 40. This redundant output unit 40 contains at least two series-connected forced-direction switching elements, such as relays K1 and K2. Before output action, an internal feedback monitoring circuit 50 checks the current state of relays K1 and K2 to ensure they are not faulty. Simultaneously, an external device monitoring feedback loop 60 is also checked to confirm that external devices controlled by the module (such as contactors) are in a safe state. Finally, reliable control of dangerous actions is achieved by supplying or cutting off power to external loads via safety output contacts 13-14, 23-24, and 33-34.

[0026] According to one aspect of this application, a two-hand button synchronous interlocking safety control module is provided. The module includes a first input channel CH1 and a second input channel CH2, which are hardware-independent, for example, employing independent power supplies, signal conditioning circuits, and logic processing paths. This design ensures that a single failure in either channel will not affect the safety function of the other channel, thus forming the basis of a redundant safety architecture. The first input channel CH1 and the second input channel CH2 are respectively used to receive first and second input signals from the first and second two-hand buttons, realizing independent acquisition of the operator's hand movements.

[0027] The module also includes a cross fault detection circuit 10. Unlike traditional solutions that only perform self-tests upon power-up, this cross fault detection circuit 10 is configured to continuously monitor the electrical isolation status between the first input channel CH1 and the second input channel CH2 throughout the entire operation of the safety control module. An abnormal electrical isolation status can occur when the external wiring of the two input channels is worn, damp, or when the internal circuitry is short-circuited. This circuit can detect such an anomaly immediately and force the redundant output unit 40 to disconnect, thus preventing the extreme danger of being misjudged as "both hands pressing simultaneously" due to a short circuit between channels, greatly improving safety integrity.

[0028] To ensure operational synchronization, a synchronization detection circuit 20 is incorporated into the module. A key feature is that this synchronization detection circuit 20 is a purely hardware circuit, independent of a microprocessor (MCU) executing software instructions for timing. It directly measures the time difference between the first and second input signals becoming valid using discrete components or fixed logic gates. In electrical and safety control, "valid" refers to the instant (rising edge) when a button switches from an open (not pressed) state to a closed (pressed) state. The valid time difference is the time interval between the moment the first button is pressed and the moment the second button is pressed. This purely hardware implementation avoids the risks of infinite loops, logical errors, or tampering that can occur with software, resulting in extremely fast and reliable synchronization judgments, and making fault modes easier to predict and manage.

[0029] The module's core safety output is implemented by a redundant output unit 40. This output stage includes at least two hardware-independent forced-direction switching elements, such as forced-direction relays K1 and K2. The outputs of these switching elements are configured to be connected in series to the safety loop of an external device. The characteristics of the forced-direction switching elements ensure that their normally open and normally closed contacts will not close simultaneously under any circumstances (including contact welding). Connecting two such elements in series means that even if one element fails to disconnect due to contact welding, the other independent element can still disconnect the entire safety loop, thus ensuring that the safety function does not fail after a single fault occurs. This is a core requirement for meeting Category 4 safety level.

[0030] To achieve complete self-diagnosis and closed-loop control, the module also integrates an internal feedback monitoring circuit 50. This circuit is configured to monitor the state of at least two forced-direction switching elements K1 and K2 within the redundant output unit 40 before each drive operation. Specifically, it checks the normally closed feedback contacts of these elements to confirm that they are indeed in a non-conductive state before being driven. If any element fails to reset properly due to contact welding or other reasons, the module will reject the safety output request. This pre-start self-check mechanism ensures that every safety output operation is performed under the premise that the output stage itself is intact.

[0031] The safety control logic of this application is designed as a multi-condition AND gate. Specifically, the safety control module only allows the response to an input signal to generate a safe output signal when all safety preconditions are met. These preconditions include: first, the cross-fault detection circuit 10 does not detect any abnormality in the electrical isolation between input channels; second, the time difference between the two input signals measured by the synchronization detection circuit 20 is not greater than a preset synchronization time window; and third, the internal feedback monitoring circuit 50 confirms that all forced-direction switching elements K1 and K2 in the redundant output unit 40 are in the expected non-conducting state. This multi-factor, independent checking mechanism works together to form a robust defense against various potential faults and misoperations.

[0032] In a preferred embodiment, the method for detecting cross-faults is specifically defined. For example... Figure 3 As shown, the cross-fault detection circuit 10 monitors the electrical isolation status by continuously monitoring the impedance between the first input channel CH1 and the second input channel CH2. Under normal circumstances, since the two channels are powered by internal isolation power supplies ISO1 and ISO2 respectively, they should present extremely high impedance. When a short circuit occurs between the channels, this impedance drops sharply. A comparator CMP is included in the circuit, which compares the voltage corresponding to the actual impedance between the channels sensed by the detection resistor R_detect with a reference voltage V_ref. When the detected impedance is lower than a preset impedance threshold, the comparator CMP outputs a signal indicating an abnormal electrical isolation status, thereby triggering the disconnection of the redundant output unit 40.

[0033] To ensure timely and effective detection, the preset impedance threshold is set to 500 ohms. This threshold takes into account the significant difference between normal cable insulation impedance and actual short-circuit fault impedance, resulting in high accuracy. More importantly, the continuous monitoring cycle is designed to be no more than 1 millisecond. This means that the module performs a cross-fault check every millisecond during operation, ensuring that any insulation damage or conductive contamination between terminals that occurs at any time can be promptly detected and addressed, achieving true full-time online monitoring and fundamentally eliminating the existence of fault latency.

[0034] For the specific implementation of the pure hardware synchronization detection circuit 20, such as Figure 4The timing diagram shows that it includes an XOR gate and an RC circuit connected to it. The two inputs of the XOR gate are connected to the output signals of the first and second input channels, respectively, after shaping. When the two input signals S11_active and S21_active are not in the same state (one is high and the other is low), the output XOR_out of the XOR gate is high. Therefore, when the two buttons are pressed one after the other, the XOR gate will output a pulse, the width of which is exactly equal to the time difference Δt between the two signals becoming active.

[0035] Next, the pulse signal is fed into an RC circuit. The RC circuit utilizes the charging and discharging characteristics of a capacitor to convert this pulse with a width of Δt into a peak voltage value, which is proportional to the pulse width. This voltage value is then compared with a reference voltage representing a preset synchronization time window. If the voltage output by the RC circuit is lower than the reference voltage, it indicates that the time difference Δt is within the allowable range; otherwise, it indicates that the operation is asynchronous. This scheme, based on XOR gates and RC circuits, has a simple structure, fast response speed (reaching the microsecond level), and eliminates the risk of software-level failures.

[0036] In terms of specific parameter settings, the preset synchronization time window is set to 500 milliseconds. This value is determined based on ergonomics and relevant safety standards (such as EN 574). It can accommodate the slight delay of two-handed movements during normal operation, while effectively preventing the operator from attempting to "trick" the safety system by pressing two buttons sequentially with one hand. When the measured time difference Δt is greater than 500 milliseconds, the synchronization detection circuit 20 will output an invalid signal, thereby preventing the logic processing unit 30 from generating a safety output.

[0037] In a specific hardware implementation, the at least two forced-direction switching elements are preferably two independent forced-direction relays K1 and K2. These relays have an internal mechanical interlocking structure to ensure that the operating states of their normally open (NO) and normally closed (NC) contact groups are strictly opposite. Even in extreme cases such as coil failure or contact welding, it is guaranteed that the NO and NC contacts will not close simultaneously. Using such relays as output elements provides a reliable hardware foundation for implementing high-level safety functions (such as PLe). For example, relays with AgSnO2 contact material can be selected, which have excellent anti-welding properties and a long electrical life, for example, an electrical life of over 100,000 cycles under an AC 250V / 5A resistive load.

[0038] To further enhance the ability to detect input terminal faults, the input terminal of the safety control module in this application is adapted to a dual-contact redundant wiring method. For example... Figure 2As shown, when connecting the two-hand buttons B1 and B2, the normally open (NO) contacts of each button are connected to the first input channel S11 and the second input channel S21 of the module, respectively, while their normally closed (NC) contacts are connected in series to another feedback monitoring loop of the module. Through this wiring method, the module can not only detect the button being pressed (NO contact closed), but also monitor whether the button is stuck or its contacts are welded (NC contacts fail to open or close as expected). This integrity monitoring of the input devices themselves extends the safety protection chain from the control module to the operating buttons themselves.

[0039] The security monitoring scope of this application can also be extended to the final actuator. To this end, the security control module M also includes an external device monitoring feedback loop 60, with dedicated terminals S33 and S32. For example... Figure 2 As shown, this circuit is used to connect the normally closed auxiliary contacts of external contactors K3 and K4 controlled by this module. Before generating a safety output signal each time, the module's logic processing unit 30 first checks the status of the external device monitoring feedback circuit 60. If the circuit is open, it indicates that the main contacts of the external contactor K3 or K4 may have been welded and failed to release properly. In this case, the module will lock in a safe state and refuse to output a start signal, thereby effectively preventing danger caused by failure of external actuators.

[0040] To adapt to different application scenarios and operating habits, the safety control module of this application also provides a flexible reset mode selection function. The module is equipped with reset mode selection terminals Y1 and Y2. Users can select between the two modes by shorting or disconnecting the external wiring. When terminals Y1 and Y2 are shorted, the module operates in automatic reset mode; when terminals Y1 and Y2 remain open, the module operates in monitored manual reset mode, which requires an external reset button RST. This design allows the same module to be used in both production lines requiring rapid cycles (automatic reset) and in situations requiring explicit safety confirmation by the operator after each cycle (manual reset), greatly enhancing the product's applicability.

[0041] This application also provides a two-hand button safety control method corresponding to the above-described module. The method first includes receiving first and second input signals from the first and second two-hand buttons respectively through hardware-independent first and second input channels. This step ensures the redundancy and independence of input signal acquisition.

[0042] Next, the core safety monitoring steps of the method are executed in parallel. One of these steps is to continuously monitor the electrical isolation status between the first and second input channels throughout the entire operation of the device. Once an abnormality in the electrical isolation status is detected, such as low impedance due to a short circuit, the method will immediately perform a protective action, namely disconnecting at least two hardware-independent forced-direction switching elements and cutting off the safety output.

[0043] Another parallel execution step is to use pure hardware circuitry to measure the time difference between the first and second input signals becoming valid. This step utilizes the inherent characteristics of hardware for timing, ensuring the real-time performance and high reliability of the synchronization determination, and eliminating uncertainties at the software level.

[0044] Before generating a safe output, the method includes a critical self-test step: checking the status of the at least two forced-direction switching elements. This step confirms that the switching elements are in the expected non-conducting position in standby mode by reading the feedback contacts of the switching elements, preventing dangerous startup in the event of a fault in the output stage.

[0045] Finally, the method uses a strict conditional decision-making step to determine whether to output a safety signal. Only when all preconditions are met simultaneously—namely, no abnormal electrical isolation is detected, the measured time difference is not greater than a preset synchronization time window, and the inspection results indicate that all forced-guided switching elements are in a non-conducting state—will the method output a safety signal to the safety circuit of the external device through the at least two series-connected forced-guided switching elements.

[0046] In one specific embodiment, the step of continuously monitoring the electrical isolation status includes more specific parameterized operations. This step is achieved by continuously monitoring the impedance between the first and second input channels. When the monitored impedance value falls below a defined threshold of 500 ohms, the system determines that a crossover fault has occurred. At this point, the method immediately executes safety measures, disconnecting the at least two forced-direction switching elements to ensure the device enters a safe stop state. This specific numerical limitation makes the fault diagnosis criteria clear, easy to implement, and highly reliable.

[0047] To more clearly illustrate the technical solution of this application, a general embodiment is described below. A two-button synchronous interlocking safety control module is provided, which has two physically completely isolated input channels for receiving signals from two independent buttons. The module integrates a cross-fault detection circuit that continuously detects whether there is an abnormal electrical short circuit between the two input channels at any time the module is powered on. Simultaneously, the module also includes a synchronization detection circuit based on fixed hardware logic (rather than software program) for accurately measuring the time difference between the two input signals changing from an invalid to an valid state.

[0048] The module in this general embodiment also has a redundant output unit 40, which consists of two forced-guided switching elements connected in series, whose contact states are mechanically guaranteed to be opposite. Before the module decides to output a safety signal, an internal feedback monitoring circuit checks the normally closed contacts of the two switching elements to confirm that they are both in the open state, proving that the output stage itself is intact. Its basic workflow is as follows: upon receiving two input signals, the module simultaneously performs a triple check: a cross-fault check, a synchronization check, and an internal feedback check. Only if all three checks pass will the module's logic unit drive the two series-connected switching elements to conduct, thereby outputting a valid safety signal to an external device. This embodiment does not limit the specific circuit implementation or parameter thresholds, aiming to establish the broadest possible protection range.

[0049] The preferred embodiments of this application are described in detail below with reference to the accompanying drawings and specific application scenarios. In a specific embodiment for the protection of two-hand operation of a stamping machine, a two-hand button synchronous interlock safety control module M of model ESRH-3A1B is used. This module can be easily installed on a 35mm standard DIN rail inside the equipment control cabinet. Figure 2 As shown, the left and right two-hand buttons B1 and B2 on the press control panel adopt a dual-contact redundant wiring method. Their normally open contacts are connected to the module's safety input terminals S11 and S21 respectively, while their normally closed contacts are connected in series to the module's feedback monitoring circuit, realizing comprehensive monitoring of the button's status.

[0050] In this stamping press application, to monitor the external actuators, the normally closed auxiliary contacts of the controlled main contactors K3 and K4 are connected to the module's external device monitoring feedback loop terminals S33 and S32. Simultaneously, to ensure explicit manual safety confirmation before each operating cycle, a monitored manual reset mode is selected. This is achieved by keeping the reset mode selection terminals Y1 and Y2 open and connecting an external, independent reset button RST. This configuration ensures maximum safety and prevents any accidental automatic restarts.

[0051] The working process of this stamping machine protection scheme is as follows: First, in the system standby state, the operator presses the reset button RST, and the module performs a self-test and is ready. Then, the operator must simultaneously press both left and right buttons B1 and B2 with both hands. The synchronization detection circuit 20 inside the module will immediately measure the arrival time difference Δt between the two input signals S11 and S21 and confirm whether it is less than or equal to the preset 500-millisecond synchronization time window. Figure 4 As shown. Meanwhile, the cross-fault detection circuit 10 continuously monitors the impedance between channels S11 and S21 at a period of no more than 1 millisecond, ensuring that it is always above the 500-ohm threshold, as... Figure 3 As shown.

[0052] After confirming that the input signals are synchronized and there is no crossover fault, the module's logic processing unit 30 then checks the external device monitoring feedback loop 60 to confirm that terminals S33-S32 are conductive. This indicates that external contactors K3 and K4 are indeed in the released state and no contact welding has occurred. Next, the internal feedback monitoring circuit 50 checks the normally closed feedback contacts of the two internal forced-direction relays K1 and K2 to confirm that they are also in the normally open state. Only when all the above conditions (synchronization, no crossover fault, no welding of external contactors, and no welding of internal relays) are met will the module drive relays K1 and K2 to engage.

[0053] After relays K1 and K2 are energized, their series-connected safety output contacts 13-14, 23-24, and 33-34 close, thereby energizing the coil circuits of external main contactors K3 and K4. Main contactors K3 and K4 then energize, driving the press load to perform one stroke. During or after a stroke, if the operator releases any or all of the two-hand buttons, the input signal disappears, and the module immediately disconnects relays K1 and K2, cutting off the safety output and stopping the press. Because a manual reset mode is provided, to start the next stroke, the complete sequence of "pressing the reset button" and "pressing the start button simultaneously with both hands" must be repeated, providing a high level of safety for the operator. This embodiment has a response time of less than 20 milliseconds, a power-on start-up time of less than 1 second, power consumption of less than 3 watts, and reliable performance.

[0054] In another embodiment applied to mold closing protection of a vertical injection molding machine, the flexibility of this application in different reset modes is demonstrated. In this scenario, the operator needs to manually place and remove inserts before initiating mold closing. To accommodate fast production cycles, the application selects an automatic reset mode. In specific deployment, the reset mode selection terminals Y1 and Y2 of the two-hand button synchronous interlock safety control module M are short-circuited by external wires. The two-hand buttons B1 and B2 are also connected to S11 and S21, and the external device monitoring feedback loop 60 is also connected as needed.

[0055] In this automatic reset mode, the workflow is simplified. After placing the insert, the operator simply presses both start buttons simultaneously. Once the module completes all internal safety checks (cross-fault, synchronization, feedback monitoring), it immediately outputs a safety signal and starts the injection molding machine to close the mold. When the operator releases their hands, the safety output immediately disconnects, and the equipment stops. At this point, the system automatically resets and enters standby mode, eliminating the need to press any reset buttons again for the next two-hand start operation. This mode is ideal for workstations already equipped with other safety features (such as safety light curtains) and where high productivity is required, fully demonstrating the practical value and design flexibility of this application, which allows for changes to the operating logic through simple external wiring.

[0056] It should be understood that the technical solutions of this application are not limited to the embodiments described above. For example, in an alternative embodiment, the synchronization detection circuit 20 can be designed with an adjustable synchronization time window. Specifically, the fixed resistor used to generate the reference voltage can be replaced by a digital potentiometer. This digital potentiometer can be controlled by a microcontroller (MCU) via a serial bus such as I²C, thereby enabling the synchronization time window to be adjustable in steps, for example, from 100 milliseconds to 500 milliseconds, with a step size of 50 milliseconds. This design allows the safety control module to better adapt to the specific needs of different workstations, different operating habits, or different risk levels.

[0057] In an alternative implementation, the input channel can be designed to receive secure wireless signals from the wireless two-button control. In this approach, the two physical buttons incorporate a wireless transmitter module, such as Bluetooth Low Energy (BLE) or Sub-1GHz RF technology, to transmit the button signals to the wireless receiver of the security control module. To ensure the secure integrity of the wireless communication link reaches the equivalent wired SIL 3 level, the wireless communication protocol must incorporate stringent security mechanisms, such as periodic heartbeat signals, incrementing sequence numbers, CRC cyclic redundancy checks, and precise timestamps, to prevent attacks such as signal replay, loss, delay, or spoofing.

[0058] Furthermore, the concept of "both hands" in this application can be further generalized. In a more advanced alternative implementation, the input signal source may no longer be a physical button, but rather a safety-grade machine vision system. For example, a 3D vision camera or stereo camera can be configured to monitor the operating area. When the vision system, through image processing algorithms, recognizes that the operator's hands simultaneously enter and remain in two predefined virtual "button" areas, it generates two independent safety signals as inputs to the safety control module of this application. This approach requires a high-reliability vision processing system compliant with IEC 61508 SIL 3 or similar standards, but it enables more flexible, contactless, and safe interaction.

[0059] In summary, this application constructs a multi-layered, deeply redundant safety control architecture by integrating continuous online cross-fault detection, pure hardware synchronization detection, redundant cascaded forced-guided output stages, and comprehensive internal and external feedback monitoring. This architecture not only effectively prevents safety function failures caused by various typical faults and misuses such as external circuit short circuits, operator deception with one hand, and output component welding, but also provides strong scenario adaptability through flexible reset mode selection and expandable input methods. The two-hand button synchronous interlocking safety control module and method disclosed in this application can meet the most stringent safety standards in the industrial field with high reliability, providing a solid technical guarantee for protecting operator safety.

[0060] The preferred embodiments of the present disclosure have been described in detail above with reference to the accompanying drawings. However, the present disclosure is not limited to the specific details of the above embodiments. Within the scope of the technical concept of the present disclosure, various simple modifications can be made to the technical solutions of the present disclosure, and these simple modifications all fall within the protection scope of the present disclosure.

[0061] It should also be noted that the various specific technical features described in the above specific embodiments can be combined in any suitable manner without contradiction. In order to avoid unnecessary repetition, this disclosure will not describe the various possible combinations separately.

[0062] Furthermore, various different embodiments of this disclosure can be combined in any way, as long as they do not violate the spirit of this disclosure, they should also be regarded as the content disclosed in this disclosure.

Claims

1. A two-hand button synchronous interlocking safety control module, characterized in that, include: The first input channel is used to receive the first input signal from the first two hands button; A second input channel, independent of the first input channel, is used to receive a second input signal from the second two-hand buttons; A cross-fault detection circuit is configured to continuously monitor the electrical isolation status between the first input channel and the second input channel during operation of the safety control module; A synchronization detection circuit is used to measure the time difference between the first input signal and the second input signal becoming valid. A redundant output unit includes at least two independent forced-direction switching elements, the outputs of which are configured to be connected in series to a safety loop of an external device; and An internal feedback monitoring circuit is configured to monitor the state of the forced-direction switching element; The cross fault detection circuit is configured to disconnect the redundant output unit when an abnormal electrical isolation state is detected. The safety control module is configured to only respond to the first input signal and the second input signal and output a safety output signal to the safety circuit of the external device through the at least two series-connected forced-guided switching elements when the cross fault detection circuit does not detect the abnormal electrical isolation state, the time difference is not greater than the preset synchronization time window, and the internal feedback monitoring circuit confirms that the at least two independent forced-guided switching elements are both in a non-conducting state. The synchronization detection circuit includes: An XOR gate, wherein the two input terminals of the XOR gate are electrically connected to the signal output terminals of the first input channel and the second input channel, respectively; and A pulse width to voltage conversion circuit, the input of which is connected to the output of the XOR gate, is composed of resistors and capacitors. It is used to convert the pulse width corresponding to the time difference into a voltage amplitude through capacitor charging and discharging, so as to compare it with a reference voltage representing the preset synchronization time window.

2. The two-hand button synchronous interlocking safety control module according to claim 1, characterized in that, The cross fault detection circuit is used to monitor the electrical isolation status by continuously monitoring the impedance between the first input channel and the second input channel, and when the impedance is lower than a preset impedance threshold, the cross fault detection circuit controls the redundant output unit to disconnect.

3. The two-hand button synchronous interlocking safety control module according to claim 2, characterized in that, The preset impedance threshold is 500 ohms, and the continuous monitoring period is no more than 1 millisecond.

4. The two-hand button synchronous interlocking safety control module according to claim 1, characterized in that, For the safety control module, its input terminal is used to adapt to the dual-contact redundant wiring method, wherein the normally open contacts of the first two-hand buttons and the second two-hand buttons are respectively connected to the first input channel and the second input channel, and their normally closed contacts are connected to the feedback monitoring circuit of the safety control module.

5. The two-hand button synchronous interlocking safety control module according to claim 1, characterized in that, The safety control module also includes an external device monitoring feedback loop for connecting the normally closed auxiliary contact of the controlled external contactor; the safety control module is configured to check the status of the external device monitoring feedback loop before each safety output signal is generated to confirm that the external contactor has not experienced contact welding.

6. The two-hand button synchronous interlocking safety control module according to claim 1, characterized in that, The safety control module also includes a reset mode selection terminal, which is used to select between an automatic reset mode and a monitored manual reset mode by shorting or disconnecting an external wiring connection.

7. A method for synchronous interlocking safety control of two-hand buttons, applied to the synchronous interlocking safety control module of two-hand buttons as described in any one of claims 1 to 6, characterized in that, include: The first input signal is received from the first two hands buttons through the first input channel; A second input signal from the second two-hand buttons is received through a second input channel that is independent of the first input channel. During operation, the electrical isolation status between the first input channel and the second input channel is continuously monitored, and at least two independent forced-guided switching elements are disconnected when an abnormality in the electrical isolation status is detected. Measure the time difference between the first input signal and the second input signal becoming valid; Before responding to the first input signal and the second input signal to generate a safety output signal, the state of the at least two forced-direction switching elements is checked by an internal feedback monitoring circuit. Only when the cross fault detection circuit does not detect any abnormality in the electrical isolation state, the time difference is not greater than a preset synchronization time window, and the internal feedback monitoring circuit confirms that at least two forced-guided switching elements are both in a non-conducting state, is it permitted to respond to the first input signal and the second input signal and output a safety output signal to the safety circuit of the external device through the at least two forced-guided switching elements connected in series.

8. The two-hand button synchronous interlocking safety control method according to claim 7, characterized in that, The step of continuously monitoring the electrical isolation status between the first input channel and the second input channel includes: continuously monitoring the impedance between the first input channel and the second input channel, and disconnecting the forced-direction switching element when the impedance is less than 500 ohms.