Method for inspecting function integrity of safety control part

The method for verifying the functional integrity of safety control units through automatic or user-initiated test routines addresses the lack of reliable verification of start-up tests, ensuring safe operation by confirming complete safety function execution.

JP2025166814APending Publication Date: 2025-11-06PILZ GMBH & CO KG
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
JP2025071207
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-04-24
Filing Date
2025-04-23
Publication Date
2025-11-06

AI Technical Summary

Technical Problem

Existing safety control units lack a reliable method to verify that mandatory start-up tests have been performed by users after installation or system changes, potentially leading to incomplete or absent safety function execution.

Method used

A method for checking the functional integrity of safety control units, involving automatic or user-initiated test routines to ensure all safety functions are tested within a predetermined time frame, with instructions stored in non-volatile storage to enforce compliance.

Benefits of technology

Ensures that mandatory start-up tests are consistently performed, verifying the functional integrity of safety controls before and after system changes, ensuring safe operation.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025166814000001_ABST
    Figure 2025166814000001_ABST
Patent Text Reader

Abstract

To allow inspection on whether or not an operation start test has been actually executed by a user.SOLUTION: A method includes: a) a step (100) of switching on a safety control part; b) a step (101) of inspecting a machine-readable command concerning whether or not a user of the safety control part should execute an operation start test; c) a step (104) of visualizing information indicating that the operation start test should be executed; d) a step (105) of starting an inspection routine executable by the safety control part and of automatically inspecting using the inspection routine whether or not the user has successfully performed inspection within a predetermined period, which is caused by a trigger of a corresponding safety function of different safety functions of n-number of safety control parts (where n is equal to or larger than 1) provided; and e) a step (106) of erasing the command that the operation start test should be executed if the inspection has been successful.SELECTED DRAWING: Figure 2
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to a method for checking the functional integrity of a safety control, which is configured for one machine or for a technical installation with several machines with n≧1 safety functions available and which further comprises a central evaluation and control unit for operating the safety control. [Background technology]

[0002] Various embodiments of safety control devices conforming to the international standard IEC 61508 are known from the prior art. Such safety control devices are used, inter alia, to provide appropriate safety functions in the event of a hazardous situation, thereby reliably and safely transitioning technical equipment or machinery to a state that is safe for humans. For this purpose, on the input side, corresponding input signals are received and reliably evaluated by a number of safety inputs from signal generators or notification devices, which may be, for example, emergency-off switches, emergency-hold switches, light grids, light curtains, pedaling mats, guard door position switches, 3D laser scanners, safety cameras, sensors, etc. On the output side, corresponding safety outputs of an output circuit are activated. Via these safety outputs, actuators in the output circuit, such as caps or valves, are activated by the output signal in the event of a hazardous situation, so that machinery in the output circuit connected to these actuators can be transitioned to a state that is safe for humans.

[0003] The basic functions of the safety control unit, in particular the safety functions, can be defined by corresponding programming of the safety control unit. A corresponding operating system, which is executed by the evaluation and control unit during operation of the safety control unit, is stored in a callable manner in non-volatile storage means. The operating system is usually pre-programmed by the manufacturer of the safety control unit so that the safety control unit can be operated at the site of use. The operating system particularly includes program code means that can directly address the hardware components of the safety control unit.

[0004] A programmable safety control also allows a user to adapt the logical combination of input signals to specific requirements, particularly safety requirements, for example, using an application program. For this purpose, a programmable safety control implemented in this way has an operating system that is separate from the application program and defines the basic functional scope of the safety control. Furthermore, safety-oriented control rules are typically implemented in the operating system, which the user can call using the application program, for example, in the form of predefined function modules that can be parameterized by the input and output signals of the safety control. For example, the operating system may include predefined function modules for error-free evaluation of a two-channel emergency stop key or a two-channel guard door. In the application program, the user only needs to specify how the provided modules, i.e., the emergency stop key and the guard door, should be logically connected to one another.

[0005] Furthermore, safety controls known from the prior art also allow manual hardware configuration, which allows adaptation of certain operating parameters without the need to reprogram the operating system. These variable operating parameters include, in particular, the switch-on or switch-off delay of the safety outputs. To enable these hardware configurations to be performed by the user, physical configuration elements such as potentiometers and / or DIP switches are provided.

[0006] After the safety control is initially installed at the operating location or after the programming of the safety control's operating system has been changed, a start-up test of the safety control must first be performed before production operations can begin. The start-up test is used to check whether the safety control can actually perform all the safety functions implemented therein. In other words, the start-up test checks whether the safety control's functional integrity is provided.

[0007] From the manufacturer's point of view, the execution of such start-up tests is specified for the user. However, the user cannot conclusively check whether such pre-specified start-up tests have actually been executed before the first production operation of the safety control unit is started after manufacturing or after changing the operating system. If the start-up tests are not executed contrary to the manufacturer's settings, a problem may occur in which the safety control unit cannot execute the safety functions implemented therein at all or can execute them only insufficiently. Summary of the Invention [Problem to be solved by the invention]

[0008] Therefore, the object of the present invention is to provide a method for checking the functional integrity of a safety control unit, so that it is possible to check whether predefined start-up tests have actually been performed by the user before starting a productive operation. [Means for solving the problem]

[0009] The solution to the above problem provides a method for checking the functional integrity of a safety control unit having the features of claim 1. The respective dependent claims relate to advantageous developments of the invention.

[0010] A method for testing the functional integrity of a safety control unit according to the invention, comprising the steps of: the safety control unit is configured so that n≧1 safety functions are available for one machine or for a technical installation with several machines and further has a central evaluation and control unit for operating the safety control unit, The method is a) switching on a safety control; b) checking, by the evaluation and control unit, machine-readable instructions stored in the non-volatile storage means of the safety control unit as to whether a user of the safety control unit should perform an initiation test; If no, exit the method; If yes, proceed to method step c). Steps and c) visualizing, by means of a display means of the safety control section, information that a start-up test should be performed; d) starting a check routine executable by the safety control unit, by means of which the evaluation and control unit automatically checks, for each safety function of the provided n≧1 safety control unit, whether the user has successfully checked the triggering of the corresponding safety function within a predetermined or predeterminable period of time; e) if all safety functions of the provided n≧1 safety functions of the safety control unit have been successfully tested in method step d), erasing the instruction to perform a start-up test from the non-volatile storage means, or f) storing in the non-volatile storage means an instruction to carry out a new commissioning test if all safety functions have not been successfully checked in method step d); A method is provided which includes:

[0011] The method according to the invention advantageously allows the functional integrity of the safety control to be verified by ensuring that the mandatory startup tests of the safety control specified by the manufacturer are successfully performed at least after the initial installation at the site of use, and preferably after each change of the operating system. In this context, "successfully performed or successfully tested" should be understood to mean that tests of all n≧1 provided safety functions have been performed in the first place and that all these tests lead to the desired results for the safety functions. Only in this case can it be assumed that the functional integrity of the safety control has actually been achieved.

[0012] If, during execution of the method, it is determined that the start-up test has already been successful, the method ends since the functional integrity of the safety control has been given, in which case the safety control can function in production operation.

[0013] However, if it is detected that the start-up test has not yet been performed or has not yet been completed and successful, the user is prompted to stop in order to perform it. If the start-up test has been successfully performed and the instruction to perform the start-up test is erased from the non-volatile storage means in method step e), the functional integrity of the safety control is provided, so that the safety control can operate in production operation.

[0014] In one embodiment, it is proposed that the test routine is started automatically by the evaluation and control unit in method step d), so that no operational intervention by the user is required to start the test routine.

[0015] In an alternative embodiment, the test routine in method step d) can also be initiated by a user action, for example by changing the rotational position of a potentiometer in the safety control, by operating a physical switching element in the safety control or by remote control.

[0016] According to an advantageous embodiment, it is proposed that the safety control is automatically switched off after execution of method step f), and after the safety control is switched on again, a stop instruction is given to the user to perform the start-up test again, since machine-readable instructions for performing the start-up test are subsequently stored in the non-volatile storage means.

[0017] In an alternative embodiment, there is the possibility that the safety control is automatically transferred to a stopped state after execution of method step f), in which the safety control remains switched on but does not provide any safety functions. Preferably, in the stopped state of the safety control, the information that a start-up test should be performed can be visualized by a display means of the safety control.

[0018] In one embodiment, it is proposed that the check routine is started again in method step d) in the stopped state of the safety control by a user action, which can be effected, for example, by changing the rotational position of a potentiometer of the safety control, by operating a physical switching element of the safety control or by remote control.

[0019] In one embodiment, the maximum duration for which all safety functions of the safety control are triggered is set to a defined value, from which the maximum allowable duration for the entire start-up test is derived, and if this maximum allowable duration is exceeded, the start-up test is interrupted and must be re-run by the user.

[0020] In another embodiment, there is the possibility that the maximum duration for the triggering of each individual safety function of the safety control unit is set to a specific defined value, from which the maximum permissible duration for the triggering of each individual safety function is derived. If the maximum permissible duration for the triggering of one of the safety functions is exceeded, the start-up test is interrupted and must be performed again by the user.

[0021] To ensure that the start-up test is performed not only after initial installation but also after any subsequent changes or reprogramming of the safety control's operating system, a particularly advantageous embodiment proposes that, before method step b) is performed, the evaluation and control unit reads machine-readable information from the non-volatile storage means as to whether the operating system has been changed since the last time the start-up test was performed. This machine-readable information may in particular be time information indicating when the operating system was last changed, thus forming a kind of "timestamp" for the operating system, or other version information for the operating system. If it is determined that the operating system has been changed, machine-readable instructions are stored in the non-volatile storage means of the safety control, instructing the user of the safety control to perform the start-up test. In this case, the method continues from method step b).

[0022] Further features and advantages of embodiments of the present invention are described below with reference to the drawings. [Brief explanation of the drawings]

[0023] [Figure 1] FIG. 2 is a highly simplified schematic diagram of a safety control section; [Figure 2] 2 is a schematic diagram showing the basic flow of a method for inspecting the functional integrity of the safety control section shown in FIG. 1. DETAILED DESCRIPTION OF THE INVENTION

[0024] 1, a safety control unit 1 is configured to provide n≧1 safety functions for a machine 20 or a technical installation having multiple machines, and includes a central evaluation and control unit 2 that operates the safety control unit 1. The central evaluation and control unit 2 is processor-based and may include, for example, at least one microcontroller. Preferably, the central evaluation and control unit 2 is configured as a redundant means and therefore includes two microcontrollers. This ensures that the central evaluation and control unit 2 remains functional even if one of the two microcontrollers is defective.

[0025] The safety control unit 1 further comprises non-volatile storage means 3 in which, inter alia, an operating system is stored so as to be executed by the central evaluation and control unit 2 during operation of the safety control unit 1. After switching on the safety control unit 1, the operating system is loaded into volatile storage means, not explicitly shown here, in particular a RAM memory, of the evaluation and control unit 2 and executed by the evaluation and control unit 2. The evaluation and control unit 2 and the non-volatile storage means 3 are accommodated in a housing 4 of the safety control unit 1.

[0026] In this embodiment, the safety control unit 1 has two safety inputs 5a, 5b, each configured as a redundant means, i.e., a double channel, each with two separate inputs. A signal generator 6a, 6b is connected to each of the safety inputs 5a, 5b before the safety control unit 1 is first activated. The type of signal generator 6a, 6b used depends, inter alia, on the operating conditions of the machine 20 or technical installation. These types of signal generators 6a, 6b can be, but are not to be construed as definitive examples, emergency-off switches, emergency-hold switches, light grids, light curtains, pedaling mats, protective door position switches, safety cameras, or 3D laser scanners. Sensors for detecting safety-critical physical measurands can also be used as the signal generators 6a, 6b.

[0027] Furthermore, the safety control 1 in this embodiment is also redundant, i.e., configured as a double channel, and has at least one safety output 7 with two separate outputs. An actuator 8 is connected to the safety output 7, which is itself connected to the machine 20 and thereby cooperates with the machine 20. The actuator 8 is configured to bring the machine 20 into a state that is safe for the surroundings and, in particular, for humans, when a dangerous situation occurs and the safety control 1 appropriately controls the actuator 8. The actuator 8 can, for example, include at least one protection element or at least one valve. Preferably, the actuator 8 is also configured as redundant. In many cases, the safety control 1 has several such safety outputs 7, each connected to one actuator 8, so that several actuators 8, and therefore, in particular, several machines 2, can be connected to the safety control 1.

[0028] Via a bus line 11 the safety inputs 5 a, 5 b and the safety outputs 7 are communicatively connected to the evaluation and control unit 2 .

[0029] Furthermore, the safety control 1 has several potentiometers 9a, 9b, by means of which the user can parameterize certain functions of the safety control 1, for example, the switch-on delay or switch-off delay of the safety output 7. Two potentiometers 9a, 9b are provided here by way of example. Furthermore, the safety control 1 has one or more display means 10, in particular one or more colored light-emitting diodes, by means of which the current operating state of the safety control 1 can be visualized by means of a corresponding lighting color. Alternatively or additionally, there is also the possibility of using a display device as the display means 10, by means of which information relating to the current operating state of the safety control 1 and possibly further information can be displayed graphically and / or textually.

[0030] In principle, the safety control unit 1 can be configured modularly, whereby the safety control unit 1 has a number of function modules with corresponding safety inputs 5a, 5b and / or safety outputs 7.

[0031] When the safety control 1 shown in FIG. 1 receives a signal from one of the signal generators 6 a, 6 b during production operation indicating the existence of a dangerous situation, it controls the actuator 8 connected to the safety output 7 in the output circuit without error, and the machine 20 is shut down or otherwise put into a state that is not dangerous to personnel. If the actuator 8 includes, for example, at least one protection element, a shut-down signal is generated, so that the control current no longer flows through the magnetic coil of the protection element. As a result, the switching contacts of the protection element are opened, and the connected machine 20 is current-free (i.e., the machine 20 is in an emergency-off state). From a functional standpoint, the safety control 1 in this case forms a safety switching device that provides a switching output signal (here, a switch-off signal). In principle, the safety control 1 can also be configured to generate other output signals in addition to the switching output signal.

[0032] After the initial installation of the safety control 1 at the operating site or after any changes to the programming of the safety control's 1 operating system, a start-up test must first be performed before production operations can begin. The start-up test here is used to check whether the safety control 1 can actually perform all the safety functions implemented therein with the desired / required results. In other words, the start-up test checks whether the safety control 1 has functional integrity that allows it to be used in production operations.

[0033] From the viewpoint of the manufacturer of the safety control unit 1, it is specified that the user should perform such a start-up test. However, it is not possible to conclusively monitor whether such a start-up test has actually been performed before the production operation of the safety control unit 1 is first recorded after the initial installation or after an operating system change. If the start-up test is not performed contrary to the manufacturer's specification, a problem may arise in which the safety control unit 1 cannot perform the safety functions implemented therein at all or can only perform them insufficiently.

[0034] To address the above-mentioned problems, a method for checking the functional integrity of the safety control 1 will be described in more detail below with further reference to Figure 2. This method makes it possible to ensure that the start-up tests required by the manufacturer have indeed been successfully performed before the safety control 1 can be used in production operation.

[0035] A method for testing the functional integrity of a safety control 1, the safety control 1 being configured so that n≧1 safety functions are available in a machine 20 or in a technical installation with several machines 20, The method is a) Step 100 of switching on (and thus operating) the safety control unit 1; b) checking 101 by the evaluation and control unit 2 the machine-readable instructions stored in the non-volatile storage means 3 of the safety control unit 1 as to whether the user of the safety control unit 1 should perform an initiation test; If no, exit the method 102; If yes, proceed to step c) 103; Steps and c) Step 104 of visualizing information that a start-up test should be performed using the display means 10 of the safety control unit 1; d) a step 105 of starting a test routine executable by the safety control unit 1, in which the evaluation and control unit 2 automatically checks, by means of the test routine, whether the user has successfully tested each of the n≧1 safety functions of the safety control unit 1 provided by the trigger of the corresponding safety function within a predetermined period of time; e) a step 106 of erasing from the non-volatile storage means the instruction to carry out a start-up test if all safety functions of the provided n≧1 safety functions of the safety control unit 1 have been successfully checked in method step d), or f) step 107 of storing in the non-volatile storage means 3 an instruction to carry out a new commissioning test if all safety functions have not been successfully checked in method step d); The present invention relates to a method comprising:

[0036] If, when the above method is executed, it is determined that the start-up test has already been successful previously, the functional integrity of the safety control unit 1 is provided and the method ends. In this case, the safety control unit 1 can operate unrestricted in production operation. However, if it is detected that the start-up test has not yet been performed or has not yet been completed, the user is instructed to stop and run the test again before the safety control unit 1 can operate in production operation.

[0037] In one embodiment of the method presented herein, the test routine in method step d) can be started automatically by the evaluation and control unit 2. This means that no additional user intervention is required to start the test routine. In alternative embodiments, there are also means by which the test routine in method step d) can be started by a user's input. For example, the operating instruction can be executed by changing the rotational position of one of the potentiometers 9a, 9b of the safety control 1, by operating a physical switching element of the safety control 1, or by remote control.

[0038] In one embodiment of the method, the safety control unit 1 can be automatically shut down after execution of method step f), and after the safety control unit 1 is switched on again, the user is prompted to stop and perform the start-up test again, since the non-volatile storage means 3 of the safety control unit 1 still contains machine-readable instructions to perform the start-up test.

[0039] In an alternative embodiment, the safety control 1 can be automatically transferred to a stopped state after execution of method step f), in which the safety control 1 remains switched on but does not provide any safety functions. Preferably, the information that a start-up test should be performed can be visualized using the display means 10 of the safety control 1 in the stopped state of the safety control 1.

[0040] In one embodiment, it is proposed that the check routine is started again by a user's operating input in the stopped state of the safety control 1 in method step d), for example, by changing the rotational position of one of the potentiometers 9a, 9b of the safety control 1, or by operating a physical switching element of the safety control 1, or by remote control.

[0041] In one embodiment, the maximum duration for which all safety functions of the safety control unit 1 are triggered is set to a defined value, from which the maximum allowable duration for the entire start-up test is derived. If this maximum allowable duration is exceeded, the start-up test is interrupted and the user must perform it again. Machine-readable instructions that the user of the safety control unit 1 should perform the start-up test remain stored in the non-volatile storage means 3.

[0042] In another embodiment, the maximum duration for which each individual safety function of the safety control 1 is triggered can be configured to be set to a uniquely defined value. If the maximum allowable duration for triggering one of the safety functions is exceeded, the start-up test is interrupted and must be performed again by the user. Machine-readable instructions that the user of the safety control 1 should perform the start-up test remain stored in the non-volatile storage means 3.

[0043] In order to ensure that the start-up test of the safety control unit 1 is performed not only after initial installation but also at a later time after a change of the operating system of the safety control unit 1 has been made, the evaluation control unit 2 is preferably arranged to read machine-readable information from the non-volatile storage means 3 after switch-on 100 and before execution of method step b) and to evaluate accordingly whether the operating system has been changed since the last time the start-up test was made. The machine-readable information here can in particular be time information indicating when the operating system was last changed (i.e. a kind of "timestamp" of the operating system) or other version information of the operating system, in particular for tamper protection.

[0044] If the check performed by the evaluation and control unit 2 detects that the operating system has been changed, the non-volatile storage means 3 of the safety control unit 1 stores machine-readable instructions that a user of the safety control unit 1 should perform a start-up test. The method then continues with method step b).

[0045] The above-described method advantageously ensures that the mandatory manufacturer-specified startup tests of the safety control unit 1 are successfully performed at least after the initial installation, and preferably also after each change of the operating system, thereby enabling the functional integrity of the safety control unit 1 to be checked. The method actually checks all safety functions provided by the safety control unit 1 and makes it possible to verify whether all tests are successful.

Claims

1. A method for testing the functional integrity of a safety control unit (1), comprising the steps of: The safety control unit (1) is configured so that n≧1 safety functions are available for one machine (20) or for a technical installation with several machines (20), and further has a central evaluation and control unit (2) that operates the safety control unit (1), The method comprises: a) switching on the safety control unit (1) (100); b) checking (101) by the central evaluation and control unit (2) the machine-readable instructions stored in the non-volatile storage means (3) of the safety control unit (1) as to whether the user of the safety control unit (1) should perform an initiation test; If no, the method ends (102); If yes, proceed to method step c) (103); c) visualizing (104) information that the start-up test should be performed using the display means (10) of the safety control unit (1); d) starting (105) a test routine executable by the safety control unit (1), using which the central evaluation and control unit (2) automatically checks, for each safety function of the n≧1 safety control units (1) provided, whether the user has successfully tested the safety function within a predetermined period of time by triggering the corresponding safety function; e) if all of the n≧1 safety functions provided by the safety control unit (1) have been successfully tested in method step d), erasing (106) from the non-volatile storage means (3) the instruction to perform the start-up test, or f) if all safety functions have not been successfully checked in method step d), storing (107) in the non-volatile storage means (3) an instruction to carry out the start-up test again; A method comprising:

2. the test routine in method step d) is started automatically by the central evaluation and control unit (2), The method of claim 1.

3. The test routine in method step d) is initiated by a user input. The method of claim 1.

4. the safety control (1) is automatically switched off after execution of method step f), 4. The method according to any one of claims 1 to 3.

5. the safety control (1) is automatically transferred to a stop state after execution of method step f), in which the safety control (1) remains activated but none of the safety functions are provided; 4. The method according to any one of claims 1 to 3.

6. The information that the start-up test should be performed is visualized using the display means (10) of the safety control unit (1) when the safety control unit (1) is in a stopped state. The method of claim 5.

7. The inspection routine in step d) is started again by a user's operation input when the safety control unit (1) is in a stopped state.

7. The method according to claim 5 or 6.

8. The maximum duration for triggering all safety functions of the safety control unit (1) is set to a defined value.

8. The method according to any one of claims 1 to 7.

9. the maximum duration for triggering each individual safety function of the safety control unit (1) is set to an individually defined value; 9. The method according to any one of claims 1 to 8.

10. before executing the method step b), the central evaluation and control unit (2) reads from the non-volatile storage means (3) machine-readable information as to whether the operating system has been modified since the last execution of the start-up test, If yes, the non-volatile storage means (3) of the safety control unit (1) stores a machine-readable instruction that the user of the safety control unit (1) should perform an operation start test.

10. The method according to any one of claims 1 to 9.