METHOD AND SYSTEM FOR RELEASING A SAFETY-CRITICAL FUNCTION OF A MACHINE

DE502023002258D1Active Publication Date: 2025-12-04TRUMPF WERKZEUGMASCHINEN GMBH & CO KG
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
DE502023002258
Authority / Receiving Office
DE · DE
Patent Type
Patents
Current Assignee / Owner
Priority Date
2022-03-03
Filing Date
2023-02-13
Publication Date
2025-12-04
Estimated Expiration
2043-02-13

AI Technical Summary

Technical Problem

Existing systems require manual visual inspection to release safety-critical machines after detecting risks, which is inefficient and may lead to erroneous reactivation due to malfunctions or operator unavailability.

Method used

A method and system that utilize monitoring sensors to detect risks, combine sensor signals with identifiers to form messages, and verify these messages using cryptographic signatures to ensure safe reactivation of safety-critical functions, including periodic updates to account for changing conditions.

Benefits of technology

Ensures reliable and automated release of safety-critical functions by preventing erroneous reactivation through chronological verification and secure message authentication, enhancing safety and efficiency.

✦ Generated by Eureka AI based on patent content.
Patent Text Reader
Need to check novelty before this filing date? Find Prior Art

Description

[0001] The invention relates to a method for enabling a safety-critical function of a machine.

[0002] Furthermore, the invention relates to a system for enabling a safety-critical function of a machine.

[0003] It is known to monitor spatial areas using sensors and to stop machines if the sensors detect a risk in the area. A risk could be, for example, a person or object that is not expected in that area.

[0004] Typically, the machine is stopped or otherwise brought to a safe state as soon as one of the sensors detects a risk. Any processing unit used to evaluate the sensor signals is considered part of the sensor in this context. Releasing the stopped machine is typically only possible after a visual inspection of the monitored area. Therefore, a person must be in close proximity to the monitored area to authorize the release.

[0005] From DE 10 2016 226 133 A1 a control device is known which can be switched from an alarm state to a normal state by a transmitter with a light signal.

[0006] A method for the secure transmission of image data is known from DE 10 2018 115 233 B3.

[0007] A method for configuring a monitoring device is known from DE 10 2005 063 217 A1.

[0008] The invention is based on the objective of providing a system and a method mentioned above that simplifies the release of the machine.

[0009] This problem is solved by a method according to claim 1 and a system according to claim 8.

[0010] According to the invention, a method for enabling a safety-critical function of a machine is provided, wherein a monitoring system monitors a safety-critical area of ​​the machine, the monitoring system comprising at least one monitoring sensor, the safety-critical function being disabled when the monitoring system detects a first risk in a signal from the monitoring sensor, the first signal from the monitoring sensor being combined with a first identifier at a first time to form a first message, the first message being sent by the monitoring system to an enabling unit, the enabling unit checking whether the risk is detectable in the first signal or whether the risk is not present or no longer present, the enabling unit sending a second message with an enabling signal and the first identifier if no risk is detectable in the first signal.where, at a second time, the monitoring system receives the second message containing the release signal and the first identifier, verifies the second message, and releases the safety-critical function if the verification of the second message is successful. Possible sensors for monitoring the area include, for example, light barriers, contact sensors on doors, ultrasonic sensors, radar sensors, or cameras. The sensors can monitor a boundary of the area and / or the area itself.

[0011] For transmission in the first message, the signal from a camera or other imaging sensor, i.e., an image or, preferably, a stream of images, is preferably used. This is particularly advantageous if a person is to assess the situation at the release unit.

[0012] The identifier allows the monitoring system to associate the second message with the first. This is advantageous when sending multiple messages containing signals from the monitoring sensor over a network where the chronological order of messages is not guaranteed, such as the internet.

[0013] A verification of the second message is considered successful if it does not fail for at least one reason. Possible reasons for a verification failure are listed below.

[0014] Preferably, at a third time point, a second signal from the monitoring sensor is combined with a second identifier to form a third message, the third time point being after the first time point, the second identifier being different from the first identifier, and the temporal sequence of the signals being determinable via the identifiers.

[0015] The second signal is the same as the first, except that it was generated by the monitoring sensor at a later time, preferably an image or sequence of images captured at that later time. The third message can therefore be treated by the release unit like the first message.

[0016] It goes without saying that further messages can be sent, each containing the latest signals from the monitoring sensor. This allows the release unit to assess a situation that has changed after the function was locked. Each of these additional messages receives its own unique identifier. The messages are preferably sent periodically. This is particularly advantageous if each message contains one or more images from a camera's image stream.

[0017] The identifier is preferably a timestamp. Timestamps make it particularly easy to determine the chronological order of messages.

[0018] Preferably, the first identifier is a cryptographically signed timestamp, whereby the release signal verification fails if validation of the first cryptographically signed timestamp from the second message fails. Cryptographically signed timestamps are known, for example, from the RFC 3161 standard or the ANSI ASC X9.95 standard.

[0019] Further information can also be found at https: / / en.wikipedia.org / wiki / Trusted timestamping

[0020] Cryptographically signed timestamps are advantageous because release signals with an arbitrary timestamp would cause the verification to fail. This prevents malfunctions of the release unit from leading to an erroneous release of the safety-critical function.

[0021] Preferably, the second message is provided with a second cryptographic signature from the release unit, whereby verification of the second message fails if validation of the second cryptographic signature fails. The second signature can be created, for example, with a private key of the release unit, with the corresponding public key stored in the monitoring system for verifying the second signature. The cryptographic signature ensures that the second message originates from the release unit and not from an unknown entity.

[0022] Preferably, the verification of the second message fails if the monitoring system detects a second risk between the first and second time points. This second risk, like the first, is detected from the signals of the monitoring sensor or another monitoring sensor. The safety-critical function is only enabled if the message containing the enable signal has an identifier that refers to a time point after the last detected risk. Verifying enable signals with other identifiers results in a verification failure.

[0023] In a preferred embodiment, the first message is additionally sent to a second release unit. This second message, containing a release signal and the first identifier, is treated by the monitoring system in the same way as the second message from the first release unit. Sending the first message to a second release unit enables the activation of the function of both release units. This is advantageous if one release unit fails or if an operator is unable to operate a manually controlled release unit.

[0024] A second aspect of the invention relates to a system for enabling a safety-critical function of a machine, in particular a machine tool, comprising the machine, a monitoring system and an enabling unit, wherein the monitoring system has at least one monitoring sensor for monitoring a safety-critical area of ​​the machine, wherein the monitoring system and the enabling unit are communicatively connected, wherein the monitoring system includes a computing unit, wherein the computing unit is provided and configured to evaluate a first signal from the monitoring sensor and to disable the safety-critical function of the machine when the computing unit detects a first risk in the first signal from the monitoring sensor.wherein the monitoring system is designed and configured to combine the first signal of the monitoring sensor with a first identifier and transmit it in a first message to the release unit, wherein the release unit is designed and configured to check whether the risk is detectable in the first signal, or whether the risk is not present or no longer present, wherein the release unit is designed and configured to send a second message with a release signal and the first identifier if no risk is detectable in the first signal, wherein the monitoring system is designed and configured to receive a second message with a release signal and the first identifier from the release unit, wherein the monitoring system is designed and configured to check the second message and release the safety-critical function of the machine.if the verification of the second message is successful.

[0025] The computing unit can comprise a processor, an FPGA, an ASIC, a controller, or another arithmetic unit. The computing unit can be part of the machine or a standalone unit.

[0026] The system is preferably designed and configured to carry out preferred embodiments of the method according to the invention.

[0027] The monitoring sensor is preferably a camera. Signals from a camera are particularly easy for a person to check.

[0028] A particularly preferred additional monitoring sensor is a light barrier, a contact sensor, an ultrasonic sensor, a radar sensor or a lidar sensor.

[0029] Additional sensors increase safety because more potential risks can be detected.

[0030] Preferably, the timestamp is a cryptographically signed timestamp, wherein the monitoring system is designed and configured to validate the timestamp received in the second message and to cause the verification of the second message to fail if the validation fails.

[0031] Preferably, the monitoring system is designed and configured to compare a second time of receipt of the second message with a first time defined by the first identifier from the second message and to cause the verification of the second message to fail if the difference between the first time and the second time is greater than a predetermined limit.

[0032] Preferably, the monitoring system is designed and configured to fail the verification of the second message if the monitoring system detects a second risk in a second signal from the monitoring sensor between the first time and the second time.

[0033] Preferably, the second message is provided with a cryptographic signature of the release unit, and the monitoring system is designed and configured to validate the cryptographic signature of the second message and to cause the verification of the second message to fail if the validation of the cryptographic signature fails.

[0034] The following description of preferred embodiments, in conjunction with the drawings, serves to explain the invention in more detail.

[0035] They show: Fig. 1 a schematic view of a monitoring system; Fig. 2 a schematic sequence of communication between monitoring system and release unit; and Fig. 3 a temporal sequence of a method according to the invention.

[0036] Identical or functionally equivalent elements are designated with the same reference numerals in all embodiments. The embodiments are described using a release unit. If multiple release units are used, the first messages from the monitoring system are sent to all release units, and the second messages from the release units are treated equally by the monitoring system.

[0037] A schematic view of a monitoring system 2 is shown in Fig. 1As shown, an area around a machine 1, here a laser cutting machine, is monitored by a monitoring sensor 3, here a camera. The monitoring sensor 2 sends a signal 4, here a sequence of images, to a processing unit 5. If the processing unit 5 detects a risk in the signal 4, it disables a safety-critical function of machine 1 to prevent damage. Preferably, the entire machine 1 is stopped or brought into a safe state.

[0038] The processing unit 5 combines the signal 4 with a first identifier to form a first message 6. The processing unit 5 sends the first message 6 to a release unit 7. In this case, the release unit 7 is a smartphone. The release unit 7 checks whether the risk is detectable in the signal 4, or whether the risk is not present or no longer exists. In this example, an operator 71 of the release unit checks the signal 4. If no risk is detectable in the signal 4, either due to a faulty detection by the processing unit 5 or because the risk was temporary, the release unit 7 generates a second message 8 with a release signal and the first identifier and sends the second message 8 to the processing unit of the monitoring system 2. The processing unit 5 checks the second message 8. If the check is successful, the processing unit 5 enables the safety-critical function of machine 1.If the verification of the second message 8 fails, the function remains locked.

[0039] The processing unit 5 generates, preferably periodically, further messages 6 with current signals 4 from the monitoring sensor 3 and each with an individual identifier. This allows the release unit 7 to check whether the risk has disappeared at a later time and then send a release signal with the identifier of the message 6 in which the risk is no longer detectable.

[0040] In Fig. 2Figure 1 shows a schematic sequence of communication between a monitoring system and a release unit. In a first step 101, the monitoring system 2 detects an initial risk. In a second step 102, the monitoring system 2 disables a safety-critical function of machine 1. In a third step 103, the monitoring system 2 generates a signed timestamp as an identifier. In a fourth step 104, the monitoring system creates an initial message 6, which contains both the signal 4 and the identifier. In a fifth step 105, the monitoring system 2 sends the initial message 6 to a release unit 7 at a specific time. Since the steps are typically performed in rapid succession by a processing unit, the time defined by the timestamp is considered the initial time.

[0041] In a sixth step (106), the release unit 7 receives the first message 6. In a seventh step (107), the release unit 7 checks whether a risk is detectable in signal 4. If the release unit 7 detects a risk in signal 4 in the seventh step, the process ends. If the release unit 7 does not detect a risk in signal 4, it creates a second message 8 in an eighth step (108). The second message 8 contains a release signal and the identifier of the first message 6 in which no risk was detected. The release unit 7 signs the second message 8 in a ninth step (109). In a tenth step (110), the release unit 7 sends the signed second message 8 to the monitoring system 2.

[0042] Monitoring system 2 receives the second message 8 at a second time point in an eleventh step 111. In a twelfth step 112, monitoring system 2 verifies the second message 8. During the verification, monitoring system 2 checks the signature of the second message 8. If the signature is not from the release unit 7, the verification fails and the procedure ends. If the first identifier is a signed timestamp, the monitoring system checks whether the timestamp signature is valid. If the timestamp signature is invalid, the verification fails and the procedure ends. Monitoring system 2 checks whether a second risk was detected in signal 4 of monitoring sensor 2 between a first time point, determined by the first identifier, and the second time point.Since the steps are typically performed in rapid succession by a processing unit, the second time point is equated with the time of the verification. If a second risk is detected, the verification fails and the procedure ends. If the verification does not fail, it is successful and, in a thirteenth step, the monitoring system enables the safety-critical function of machine 1.

[0043] In Fig. 3Figure 1 illustrates a temporal sequence of a method according to the invention. At time t1, the monitoring system 2 detects a first risk in a signal 4 from the monitoring sensor 3, disables the safety-critical function of the machine, and sends a first message 6 containing the signal from time t1 and a first identifier to a release unit 7. At time t2, the release unit 7 receives the first message 6. After checking the signal and determining that no risk exists, the release unit 7 sends a second message 8 containing a release signal to the monitoring system 2 at time t3.

[0044] At time t4, which is after time t1, the monitoring system detects a second risk in a signal from the monitoring sensor and sends a third message to the release unit 7 containing signal 4 from time t4 and a second identifier. The safety-critical function was already disabled at time t1. Time t4 is after time t3, but could also be before time t3 or before time t2.

[0045] At time t5, which is after time t4, monitoring system 2 receives the second message 8. The verification of the second message 8 fails because a second risk was detected at time t4, between times t1 and t5. The safety-critical function therefore remains disabled.

[0046] At time t6, the release unit 7 receives the third message 6. After checking the signal and determining that there is no risk, the release unit 7 sends a fourth message 8 with a release signal to the monitoring system 2 at time t7. At time t8, the monitoring system 2 receives the fourth message 8. After successful verification of the fourth message, the monitoring system releases the safety-critical function of the machine.

[0047] It is evident that the third message is equivalent to the first message, and the fourth message is equivalent to the second message. Accordingly, the monitoring system and the release unit treat the third and fourth messages in the same way as the first and second messages. Likewise, time t4 is equivalent to time t1, and time t8 is equivalent to time t5. Reference symbol list

[0048] 1 Machine 2 Monitoring system 3 Monitoring sensor 4 Signal 5 Processing unit 6 First message 7 Release unit 7 Operator 8 Second message t1 - t8 Time points

Claims

1. A method for enabling a safety-critical function of a machine (1), wherein a monitoring system (2) monitors a safety-critical region of the machine (1), wherein the monitoring system (2) comprises at least one monitoring sensor (3), wherein the safety-critical function is blocked if the monitoring system (2) detects a first risk in a signal (4) of the monitoring sensor (3), wherein the first signal (4) of the monitoring sensor (3) is combined with a first identifier at a first point in time (t1) to form a first message (6), wherein the first message (6) is sent from the monitoring system (2) to an enabling unit (7), wherein the enabling unit (7) verifies whether the risk in the first signal (4) is recognizable or whether the risk is not, or is no longer, present, wherein the enabling unit (7) sends a second message (8) with an enabling signal and the first identifier if there is no risk recognizable in the first signal (4), wherein at a second point in time (t5), the second message (8) with the enabling signal and the first identifier is received from the monitoring system (2), wherein the second message (8) is verified by the monitoring system (2), wherein the safety-critical function is enabled by the monitoring system (2) if the verification of the second message (8) goes successfully.

2. The method according to claim 1, characterized in that at a third point in time (t4) a second signal of the monitoring sensor (3) is combined with a second identifier to form a third message, wherein the third point in time (t4) is after the first point in time (1), wherein the second identifier is different from the first identifier, wherein the chronological order of the signals can be established via the identifiers.

3. The method according to one of the preceding claims, characterized in that the first identifier is a time stamp.

4. The method according to one of the preceding claims, characterized in that the first identifier is a cryptographically signed time stamp, wherein the verification of the second message (8) fails if a validation of the first cryptographically signed time stamp from the second message (8) fails.

5. The method according to one of the preceding claims, characterized in that the second message (8) is provided with a second cryptographic signature from the enabling unit (7), wherein the verification of the second message (8) fails if a validation of the second cryptographic signature fails.

6. The method according to one of the preceding claims, characterized in that the verification of the second message (8) fails if a second risk is detected (t4) by the monitoring system (2) between the first point in time (t1) and the second point in time (t5).

7. The method according to one of the preceding claims, characterized in that the first message (6) is also sent to a second enabling unit (7), wherein a second message (8) from the second enabling unit (7) with an enabling signal and the first identifier is treated by the monitoring system (2) exactly the same as the second message from the first enabling unit (7).

8. A system for enabling a safety-critical function of a machine (1), in particular a machine tool, comprising the machine (1), a monitoring system (2) and an enabling unit (7), wherein the monitoring system (2) has at least one monitoring sensor (3) for monitoring a safety-critical region of the machine (1), wherein the monitoring system (2) and the enabling unit (7) are communicatively connected, wherein the monitoring system (2) comprises a computing unit (5), wherein the computing unit (5) is provided and configured to evaluate a first signal (4) of the monitoring sensor (3) and to block the safety-critical function of the machine (1) if the computing unit (5) detects a first risk in the first signal (4) of the monitoring sensor (3), wherein the monitoring system (2) is provided and configured to combine the first signal (4) of the monitoring sensor (3) with a first identifier and to transmit the same to the enabling unit (7) in a first message (6), wherein the enabling unit (7) is provided and configured to verify whether the risk in the first signal (4) is recognizable or whether the risk is not, or is no longer, present, wherein the enabling unit (7) is provided and configured to send a second message (8) with an enabling signal and the first identifier if there is no recognizable risk in the first signal (4), wherein the monitoring system (2) is provided and configured to receive a second message (8) with an enabling signal and the first identifier from the enabling unit (7), wherein the monitoring system (2) is provided and configured to verify the second message (8) and to enable the safety-critical function of the machine (1) if the verification of the second message (8) is successful.

9. The system according to claim 8, characterized in that the monitoring sensor (3) is a camera.

10. The system according to one of claims 8 or 9, characterized in that a further monitoring sensor (3) is a light barrier, a contact sensor, an ultrasonic sensor, a radar sensor, or a lidar sensor.

11. The system according to one of claims 8 to 10, characterized in that the first identifier is a time stamp.

12. The system according to claim 11, characterized in that the time stamp is a cryptographically signed time stamp, wherein the monitoring system (2) is provided and configured to validate the time stamp received in the second message (8) and to allow the verification of the second message (8) to fail if the validation fails.

13. The system according to one of claims 8 to 12, characterized in that the monitoring system (2) is provided and configured to compare a second point in time (t5) of the receiving of the second messages (8) with a first point in time (t1) which is defined by the first identifier from the second message (8), and to allow the verification of the second message (8) to fail if the difference between the first point in time (t1) and the second point in time (t5) is greater than a predetermined limit value.

14. The system according to one of claims 8 to 13, characterized in that the monitoring system (2) is provided and configured to allow the verification of the second message (8) to fail if the monitoring system (2) detects (t4) a second risk in a second signal of the monitoring sensor between the first point in time (t1) and the second point in time (t5).

15. The system according to one of claims 8 to 13, characterized in that the second message (8) is provided with a cryptographic signature from the enabling unit, and the monitoring system (2) is provided and configured to validate the cryptographic signature of the second message (8), and to allow the verification of the second message (8) to fail if the validation of the cryptographic signature fails.