Automation system safety devices
By adopting a dual safety channel architecture in the 1oo2D safety system and using the second channel for supervisory operations, the problem of increased cost and performance impact of external comparator components is solved, safety and reliability are improved, and diagnostic functions are integrated.
Patent Information
- Application Number
- CN202010847466.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2019-08-23
- Filing Date
- 2020-08-21
- Publication Date
- 2025-09-16
- Estimated Expiration
- 2040-08-21
AI Technical Summary
In existing functional safety systems, the use of external comparison or voting components increases component costs and may affect system performance, and lacks effective diagnostic functions.
The 1oo2D safety system architecture uses two parallel safety channels for input processing. The second safety channel is used for supervisory operations, detecting errors in the first channel and converting it to a safe state when necessary. This avoids external comparison components and integrates diagnostic functions within the channel.
It improves system safety and reliability, reduces component costs, enhances system performance, and integrates internal diagnostic functions.
Smart Images

Figure CN112417453B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a safety device for an automation system, and in particular to a safety system architecture with a diagnostic function. Background Art
[0002] Industrial automation systems control industrial processes through various field devices connected to the system, such as regulators, control devices, sensors, and transmitters. A typical field device is a control valve with a valve controller. Field devices are typically controlled by a process controller using appropriate control algorithms based on process measurements and setpoints.
[0003] Functional safety systems can be applied in automation systems to detect potentially hazardous conditions and generate outputs for activating protective or corrective devices or procedures / mechanisms to prevent hazardous events from occurring or to provide mitigation measures to reduce the consequences of such events. Computer-based safety systems (often referred to as programmable electronic safety systems) have been used to perform safety functions in many application areas. A safety instrumented (or integrity) system (SIS) generally refers to a system consisting of components (e.g., sensors, logic solvers, and final elements) designed to automatically bring an industrial process to a safe state when specified conditions are violated, and to allow the process to proceed in a safe manner when specified conditions permit (permissible functions); and / or to take measures to mitigate the consequences of industrial hazards.
[0004] Standards have been established for functional safety systems, such as ISO 13849 and IEC 61508, which specify requirements for designing, implementing, operating, and maintaining systems to provide the required safety integrity level (SIL) or safety category. For example, IEC 61508 defines four SILs based on the risks involved in the system application, with SIL 4 being used to protect against the highest risk.
[0005] To achieve various reliability and safety goals, safety system mechanisms have been developed that define configurations of safety system components (e.g., programmable electronic controllers (PECs)), for example, based on two-of-two (2oo2) and one-of-two (1oo2) architectures. Summary of the Invention
[0006] The invention is defined by the features of the independent claims. Some specific embodiments are defined in the dependent claims.
[0007] According to a first aspect of the present invention, there is provided an apparatus comprising: an interface for connecting to an automation system network; a first safety channel connected to the interface for receiving input from the system network and sending output to the system network; and a second safety channel configured to at least receive input from the system network, wherein the first safety channel comprises a first safety application configured to process input from the system network and send a first output to the system network based on the processing of the input, and the second safety channel comprises a second safety application configured to process input from the system network and to: perform a supervisory operation based on the processing of the input and the first output sent by the first safety channel, and to cause at least the first safety channel to transition into a safe state in response to the supervisory operation indicating an error.
[0008] According to a second aspect of the present invention, a method for controlling a safety system output in an automation system is provided, the method comprising: receiving input from an automation system network via a first safety channel; receiving input from the automation system network via a second safety channel; processing the received input via a first safety application included in the first safety channel; processing the received input via a second safety application included in the second safety channel; sending a first output to the system network via the first safety channel based on the processing of the received input; performing a supervisory operation via the second safety channel based on the processing of the input by the second safety application and the first output from the first safety channel; and transitioning at least the first safety channel into a safe state in response to the supervisory operation indicating an error.
[0009] According to a third aspect, a device is provided, comprising: at least one processing core; at least one memory containing computer program code, wherein the at least one memory and the computer program code are configured to, through the at least one processing core, enable the device to at least execute the method according to the second aspect or an embodiment of the method.
[0010] According to a fourth aspect, there is provided a computer program product, a computer-readable medium or a non-transitory computer-readable medium comprising program instructions for causing an apparatus to at least perform the method according to the second aspect or an embodiment of the method.
[0011] According to an embodiment of any of the aspects, the second security application generates a second output based on processing the input, the supervisory operation includes comparing the first output and the second output, and the supervisory operation indicates an error in response to the first output and the second output not matching.
[0012] According to an embodiment of any of the aspects, the input is an input message and the (first / second) output is an outgoing secure message.
[0013] According to an embodiment of any of the aspects, the security system is a 1oo2D based security system.
[0014] According to an embodiment of any of the various aspects, the first secure channel and the second secure channel are connected via a synchronous interface. BRIEF DESCRIPTION OF THE DRAWINGS
[0015] Figure 1 shows an example of an industrial automation system,
[0016] Figure 2 shows an example of a safety system or device for an automation system according to an embodiment,
[0017] Figure 3a and Figure 3b shows an additional security system architecture according to some embodiments,
[0018] Figure 4 illustrates the interaction between instances of a first secure channel and a second secure channel according to an embodiment,
[0019] Figure 5 shows a method according to some embodiments,
[0020] Figure 6a and Figure 6b Additional safety system examples are shown; and
[0021] Figure 7 An apparatus according to an embodiment is shown. DETAILED DESCRIPTION
[0022] Industrial automation systems can be used to control industrial processes such as manufacturing, production, power generation, machining, and refining. The controlled processes can be fixed in place or mobile, such as ships. Industrial processes can operate in a continuous, batch, repetitive, or discrete manner. Industrial automation systems can also be used to monitor shipments or transportation related to industrial processes. Industrial automation systems can be distributed across several layers or levels, such as the automation platform level and the automation application level.
[0023] Figure 1An overall view of an example automation system is provided. The automation system includes field devices 1 and an IO system 2, which are connected to a (process) controller 6 via wiring. The wiring can be direct wiring 3, a star network 4, or a ring network 5. The controller is connected to a system bus 7, which can be redundant. Operator stations 8, safety systems or subsystems 9, and a configuration server 10 can be connected to the system and system bus 7. It should be understood that there can be multiple safety (sub)systems or units / modules in the automation system, and that safety system features can be implemented by / within the automation system devices. The system can include other devices, such as a historical database connected to the bus 7.
[0024] A firewall 11 can be used to protect the system bus 7 from other networks 12. The firewall 11 can be redundant. For example, maintenance, enterprise resource planning (ERP), configuration, and / or simulation servers 13 can be located in these networks. These networks can be based on standard Internet protocols over Ethernet technology. Another firewall 14 can be used to connect to other networks 15.
[0025] Automation platforms are generally generic and can be used similarly across many deployments. They can include engineering and configuration tools, which engineers can use to design automation applications. Automation platforms can also include runtime components, such as process control stations (PLCs) and human-machine interfaces (HMIs), which can be used to execute automation applications and visualize them for users.
[0026] On the other hand, an automation application can include a configuration that has been created using the automation platform's tools. An automation application can include at least one of the following: a function block diagram, a structured text program, and a user interface design. Depending on the embodiment, an automation application can be unique and completely dedicated to a customer deployment, or it can be reused across different customers and deployments.
[0027] Such as Figure 1 The operational components of the automation system of the system may include a user interface component, a process component, and components supporting the former and the latter. The process component may include one or more process controllers 6, and the user interface component may be implemented in and directed to a user device 8. The user device may provide a user interface for an operator to initiate a user session in the automation system and perform operations on components of the automation system.
[0028] The safety system 9 may include two (or even more) parallel safety channels to perform one or more safety functions. 1oo2D is a functional safety system architecture that favors safety over availability. 1oo2D may generally mean that only a single input or two checks need to be met to perform a safety action. For example, in the case of a dual safety channel system, a safety action may be triggered by determining a dangerous event through only one of the channels. D refers to a diagnostic or self-test performed on the safety channel to verify correct operation. A fault in one channel (or the safety system unit providing the channel) can be detected by the other channel and the faulty channel can be disabled. In a 1oo2D system, an external comparison or voting component monitors the safety channel. Such a component means additional component cost and may affect the performance of the system.
[0029] An improved security system architecture is now provided that helps avoid external comparison or voting components and minimizes message passing between entities. In some embodiments, the security system includes a 1oo2D-based architecture. However, it will be appreciated that the application of the features currently disclosed is not limited to this architecture.
[0030] Figure 2 A safety system or device 20 is shown for providing safety services in an automation system, for example as Figure 1 safety (sub)system 9 or part thereof.
[0031] The system or device 20 includes or is connected to an interface 30 (in some embodiments, a network switch (SW)) for connecting to an automation system network 80, such as a similar Figure 1 The first secure channel 40 is connected to the interface 30 and is configured to receive input from the system network and send output to the system network. The second secure channel 50 can be connected to the interface 30 and is configured to receive at least input from the system network. Although a switch is mentioned in this example embodiment, it should be understood that the input and output between the secure channel and the system network 80 can be arranged by another type of interface.
[0032] The first secure channel 40 includes a first secure application SA1 42 configured to process input from the system network 80 and send a first output to the system network based on the processing of the input.
[0033] The second secure channel 50 includes a second secure application SA2 52 configured to process input from the system network. SA2 52 is configured to receive input from the system network and a first output from the first secure channel 40.
[0034] The first safety channel 40 may be a primary safety channel, and the second safety channel 50 may be a secondary safety channel. Thus, the first safety channel 40 may be the only safety channel used for and utilizing the system network for system safety control. Both channels 40 and 50 may be configured to receive messages from the system network 80. It should be noted that channels 40 and 50 may be implemented by a specific safety system processing unit that may be connected to other units via a bus (e.g., via Ethernet-based communication).
[0035] The second safety channel 50 is configured to perform a supervisory operation based on processing of inputs and a first output. In response to a supervisory operation indicating an error, at least the first safety channel is controlled by the second safety channel 50 to transition to a safe state. The supervisory operation may be implemented by or within a specific (diagnostic) module connected to SA2 52, or by a diagnostic instance of SA2 52. The inputs may include one or more input messages received by the safety system 20 from the automation system network 80, and the first output may be an output safety (action) message. Thus, external comparison or voting components are now avoided, and appropriate diagnostic functionality is integrated into the safety channel.
[0036] like Figure 2 As further shown, there can be an interface 44 between channels 40 and 50, such as a synchronization path for exchanging information between the channels. Thus, both security applications 40 and 50 can check the status of the other security application via the synchronization path. However, in some embodiments, no such interface exists between channels 40 and 50.
[0037] like Figure 3a As shown, the second safety channel 50 can be connected to a deactivation or shutdown unit, module, or path 60 to disconnect the first safety channel from the system network. Such an entity can be referred to as a secondary shutdown path (SSP). Therefore, in response to the detection of the second safety channel 50 and its supervisory operation indicating an error, the channel can send a control signal to the deactivation entity 60.
[0038] like Figure 3b As shown, the second secure channel 50 may be directly connected to an output interface of the first secure channel 40 or a path from the first secure channel 40 and configured to intercept the output (message) of SA1 42 to perform supervisory operations.
[0039] In some embodiments, SA2 52 is configured to generate a second output based on processing the input. The supervisory operation includes comparing the first output and the second output. In response to a mismatch between the first output and the second output, the supervisory operation indicates an error. Thus, SA2 52 can be configured to perform the same input processing operations as SA1 42 and prepare a second output that is not sent to the system network but is used solely for diagnosing SA1 operation through the supervisory operation. For example, SA2 can be configured to calculate a complete datagram to be sent to system network 80 based on the output from system network 80, the complete datagram pre-populated with appropriate fields. The supervisory operation can compare the datagram with the datagram from SA1.
[0040] In some embodiments, the first safety channel 40 includes a diagnostic or inspection module or instance connected to the interface 44, which is configured to check the output of the second safety channel 40 to further improve the safety level. In an example embodiment, a second cycle check value based on the processing of the first input by SA252 is sent to the first safety channel 40. The first safety channel 40 is configured to compare the first cycle check value with the second cycle check value based on the processing of the input by SA1 42. The first safety channel 40 is configured to send the first output to the system network in response to the first cycle check value matching the second cycle check value. If the check values do not match, the first safety channel can cause a transition to a safe state. In some embodiments, this is performed by stopping communication (and outputting messages) to the system network 80.
[0041] The cyclic value check can be configured to be performed before SA1 sends an output to the system network 80, thereby preventing output associated with an unmatched check value. The cyclic check value can be a cyclic redundancy check (CRC) value. Therefore, through such CRC check and / or other check processes, the first secure channel can detect anomalies in the operation of the second secure channel.
[0042] refer to Figure 4 In an example embodiment of the present invention, the supervisory operation can be performed by a communication monitoring stack module or instance 54 that is connected to an application I / O that is connected to an SA2 runtime instance 56. The monitoring stack instance 54 can be connected to a bus to which the first secure channel 40 is connected and / or to a network switch (30) that connects the first secure channel 40 and the second secure channel 50 to the system network 80. The monitoring stack instance 54 is configured to receive input from the system network 80 and the SA1 first output (based on processing the input) to perform the supervisory operation. The monitoring stack instance 54 can also be connected to the first secure channel 40 and its communication stack instance to provide a CRC.
[0043] Figure 5A method according to some embodiments is shown. The method may be performed by an apparatus (eg, apparatus 20 or another controller or computing unit thereof) configured to provide a safety application for an automation system.
[0044] The method includes:
[0045] - receiving (500) input from the automation system network via a first secure channel,
[0046] - receiving (502) input from the system network via a second secure channel,
[0047] - processing (504) input received via a first secure application included in a first secure channel,
[0048] - processing (506) the input received via a second secure application included in a second secure channel,
[0049] - sending (508) a first output to the system network via a first secure channel based on processing the input,
[0050] - performing (510) a supervisory operation via the second secure channel based on processing of the input by the second secure application and the first output from the first secure channel, and
[0051] - causing (512) at least a first secure channel to transition into a secure state in response to the supervisory operation indicating an error.
[0052] Will realize, Figure 5 The method can be used with various other embodiments, some of which are shown above. In addition, it should be understood that some blocks of the method can be performed in a different order, for example, block 506 can be performed before block 504, or they can be performed substantially simultaneously. In addition, blocks 500 and 502 can occur substantially simultaneously or in a different order. The second channel 50 can be configured to be Figure 4 The runtime instance 56 in the example configuration of performs blocks 502 and 506 , and the monitoring stack instance 54 performs blocks 508 through 512 .
[0053] Figure 6a and Figure 6b Some further exemplary embodiments of systems with redundant automation networks are shown, wherein redundant networks are applied. The redundancy used can be based on the Parallel Redundancy Protocol (PRP), wherein the automation system network 80 is made redundant by applying another physical network 82. Figure 6a In the exemplary embodiment of , the security system includes another switch 32, via which the first security channel 40 and the second security channel 50 are connected to another physical network 82. Figure 6bIn the exemplary embodiment, the first secure channel 40 and the second secure channel 50 are connected to the automation system network 80 and the other physical network 82 via the switch 30 using different virtual LANs.
[0054] The features disclosed herein can be applied to safety systems in conjunction with various types and configurations of automation systems, for example to provide a SIS functional safety program for an industrial automation system of the type described at the beginning of this section. Some other application examples include: a) liquid level control, where the safety system controls the closing of an input valve, and b) controlling the stopping of a mobile machine due to the tripping of a channel control unit (e.g., a photoelectric trip device).
[0055] An electronic device including an electronic circuit may be a means for implementing at least some embodiments. Figure 7 A schematic diagram of an apparatus 700 according to one embodiment is shown. The apparatus can be configured to operate as or comprise a security system 9, 20. The apparatus includes a computing unit 701 and can include or be connected to other units, such as one or more user interface (UI) units 707. The apparatus can be connected to (other) automation system control units 708, other locally or remotely connectable devices 709, and / or networks / services 710, such as cloud services. Examples of processors suitable for implementing the features and architectures described above include ARM A5 (or higher) class processors, such as the Atmel SAMA5D3.
[0056] The computing unit 701 may include a processor 702, a communication unit 703, and a memory 704. The communication unit 703 may include at least one transmitter and a receiver, which may be configured to operate according to a wired or wireless communication standard, such as a cellular communication system, a wireless local area network, an industrial bus, and / or an Ethernet standard.
[0057] The memory 704 may store computer program code 705 and parameters 706 such that when the processor executes the computer program code, the computing unit performs at least some of the features disclosed herein, such as the second secure channel 50 and Figure 5 Thus, the memory, processor, and computer program code may be the means by which the computing unit 701 performs at least some of the presently disclosed safety system diagnostic functions, such as executing the methods in blocks 508-512.
[0058] The UI unit 707 may include one or more user interface devices, such as a display and one or more devices such as a keyboard, a touch screen, a mouse, a gesture input device, or other types of input / output devices. The UI unit may be configured to provide user input for controlling the computing unit 701, for example, to set the Figures 1 to 5It will be appreciated that various information related to the security system (and possibly the automation system 80 ), such as trends, reports, and alarms, may be displayed and / or controlled via the UI unit 707 .
[0059] It should be understood that the embodiments of the present invention disclosed herein are not limited to the specific structures, process steps or materials disclosed herein, but are extended to equivalents thereof that can be recognized by those skilled in the relevant art. It should also be understood that the terminology used herein is only for the purpose of describing specific embodiments and is not intended to be limiting.
[0060] In one or more embodiments, the various described features, structures, or characteristics may be combined in any suitable manner. Although the above examples illustrate the principles of the present invention in one or more specific applications, it will be apparent to those skilled in the art that various modifications may be made to the form, usage, and implementation details without inventive effort and without departing from the principles and concepts of the present invention. Therefore, the present invention is not intended to be limited except as defined by the claims set forth below.
[0061] The verb "to comprise" is used in this document as an open limitation that neither excludes nor requires the presence of unrecited features. Unless expressly stated otherwise, the features recited in the dependent claims are freely combinable with each other. Furthermore, it should be understood that, as used throughout this document, the singular forms "a" or "an" do not exclude a plurality.
Claims
1. A safety system device, comprising: - an interface for connecting to an automation system network (80), - a first secure channel (40), connected to the interface, for receiving input from the system network and sending output to the system network, and - a second secure channel (50) configured to receive input from at least the system network, wherein The first secure channel includes a first secure application (42) configured to process input from the system network and send a first output to the system network based on the processing of the input, and The second secure channel includes a second secure application (52) configured to process input from the system network and configured to: - performing (510) a supervisory operation based on the processing of the input and the first output sent via the first secure channel, and - causing (512) at least a first secure channel to transition into a secure state in response to the supervisory operation indicating an error.
2. The device according to claim 1, wherein The second security application is configured to generate a second output based on processing an input, the supervisory operation includes comparing the first output and the second output, and the supervisory operation indicates an error in response to the first output and the second output not matching.
3. The device according to claim 1 or 2, wherein: The second secure channel is configured to send a second cyclic check value to the first secure channel based on processing of the input by the second secure application, The first secure channel is configured to compare the first cyclic check value with the second cyclic check value based on processing of the input by the first secure application, and The first secure channel is configured to send a first output to a system network in response to the first cyclic check value matching the second cyclic check value.
4. The device according to claim 1 or 2, wherein: The apparatus is configured to send a signal from the second safety channel to a shutdown unit (60) in response to the supervisory operation indicating an error, to disconnect the first safety channel from the system network.
5. The device according to claim 1 or 2, wherein: The security system is a 1oo2D-based security system, and the first security channel and the second security channel are connected via a synchronization interface (44).
6. The device according to claim 1 or 2, wherein: The supervisory operation is configured to be performed by a communication monitoring instance or module (54) connected to the second application and configured to receive the first output, to connect to a bus, or to connect to a network switch, the bus connected to the first secure channel, the network switch connecting the first secure channel and the second secure channel to the system network.
7. An automation system comprising an automation system network and a safety system device according to any preceding claim.
8. A method for controlling a safety system output in an automation system, comprising: - receiving (500) input from the automation system network via a first secure channel, - receiving (502) input from the system network via a second secure channel, - processing (504) input received via a first secure application included in a first secure channel, - processing (506) the input received via a second secure application included in a second secure channel, - sending (508) a first output to the system network via a first secure channel based on processing the received input, - performing (510) a supervisory operation via the second secure channel based on processing of the input by the second secure application and the first output from the first secure channel, and - causing (512) at least a first secure channel to transition into a secure state in response to the supervisory operation indicating an error.
9. The method according to claim 8, wherein The second security application generates a second output based on processing the input, the supervisory operation includes comparing the first output and the second output, and the supervisory operation indicates an error in response to the first output and the second output not matching.
10. The method according to claim 8 or 9, further comprising: - sending a second cyclic check value to the first secure channel via the second secure application based on processing of the input by the second secure application, - comparing the first cyclic check value to the second cyclic check value based on processing of the input by the first security application, and - sending the first output to the system network in response to the first cycle check value matching the second cycle check value.
11. The method according to claim 8 or 9, wherein: In response to the supervisory operation indicating an error, a signal from the second safety channel is sent to the shutdown unit to disconnect the first safety channel from the system network.
12. The method according to claim 8 or 9, wherein: The supervisory operation is performed by a communication monitoring instance or module connected to the second application and used to receive the first output, connected to a bus or connected to a network switch, the bus being connected to the first secure channel, the network switch connecting the first secure channel and the second secure channel to the system network.
13. The method according to claim 8 or 9, wherein: The input is an input message and the output is an output secure message.
14. A computing device comprising a processor and a memory storing computer program code, wherein when the computer program code is executed in the processor, the computing device is caused to at least perform the method according to any one of claims 8 to 13.
15. A non-transitory computer-readable medium comprising computer program code for, when executed in a processor of a computing device, causing the computing device to at least perform the method according to any one of claims 8 to 13.
Citation Information
Patent Citations
Switching device utilizing requests indicating cumulative amount of data
US20050135356A1
Method for reducing uncorrectable errors of a memory device regarding error correction code, and associated memory device and controller thereof
US20110138254A1