Method and apparatus for implementing safety applications associated with process control systems

By combining pre-programmed safety trip devices with I/O signal sets, flexible safety application configuration is achieved, solving the problems of high complexity and vulnerability in existing technologies and improving system reliability and safety.

CN112526941BActive Publication Date: 2025-09-09FISHER ROSEMOUNT SYST INC
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202010988092.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2019-09-18
Filing Date
2020-09-18
Publication Date
2025-09-09
Estimated Expiration
2040-09-18

AI Technical Summary

Technical Problem

In existing process control systems, safety trip devices have the problems of high programming and configuration complexity, susceptibility to human errors and cyber attacks, and insufficient flexibility and redundancy.

Method used

It uses pre-programmed safety trip devices and provides a variety of optional safety applications. By combining I/O signal sets with pre-programmed instructions, users can select configuration settings and implement safety applications through I/O scanners. It supports different types and quantities of I/O signals and has redundant designs and communication interfaces.

Benefits of technology

It reduces the configuration complexity of safety trip devices, reduces human errors, improves system flexibility and reliability, enhances network security, and simplifies the system setup process.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN112526941B_ABST
    Figure CN112526941B_ABST
Patent Text Reader

Abstract

A method and apparatus for implementing safety applications associated with a process control system are disclosed. The apparatus includes a configuration controller configured to: provide a plurality of available safety applications to a user for selection, the safety applications being implemented via a safety trip device; a first safety application being associated with a first set of I / O signals, a second safety application being associated with a second set of I / O signals, the first safety application being implemented based on first pre-programmed instructions stored in a memory of the safety trip device, and the second safety application being implemented based on second pre-programmed instructions stored in a memory of the safety trip device; and, in response to user selection of the first safety application, prompting the user to specify values ​​for configuration settings associated with the first safety application. The apparatus also includes an I / O analyzer configured to implement the first safety application.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates generally to safety instrumented systems and, more particularly, to methods and apparatus for implementing safety applications associated with process control systems. Background Art

[0002] Many process control applications (e.g., distributed control systems (DCS), supervisory control and data acquisition (SCADA) systems, etc.) include triggering a safety trip when one or more monitored parameter values ​​exceed a corresponding trip limit and / or some other safety condition is met. Such safety trips can be implemented using different types of devices (depending on the number of inputs / outputs (I / O) of the safety system and / or the relative complexity of the system). For example, in complex implementations, a safety logic solver can be configured to handle a variable number of I / O points (potentially thousands) of different types and can do so in a fully configurable (e.g., programmable) manner. At the other end of the spectrum, relatively simple devices, often called trip amplifiers or safety relays, typically receive a single input signal and compare it to a limit value that trips an output signal (usually a discrete output). Summary of the Invention

[0003] A method and apparatus for implementing a safety application associated with a process control system are disclosed. The apparatus includes a configuration controller configured to: provide a user with a plurality of available safety applications associated with the process control system for selection, the safety applications being implemented by a safety trip device; a first safety application associated with a first set of I / O signals, and a second safety application associated with a second set of I / O signals, the first I / O signal set being different from the second I / O signal set, the first safety application being implemented based on first pre-programmed instructions stored in a memory of the safety trip device, and the second safety application being implemented based on second pre-programmed instructions stored in a memory of the safety trip device; and, in response to user selection of the first safety application, prompting the user to specify values ​​for configuration settings associated with the first safety application, the first pre-programmed instructions defining the configuration settings; and an I / O analyzer configured to implement the first safety application based on the values ​​of the configuration settings specified by the user and based on the first pre-programmed instructions.

[0004] A non-transitory computer-readable medium comprising instructions that, when executed, cause a safety trip device to at least: provide a user with a plurality of available safety applications associated with a process control system for selection, the safety applications being implemented by the safety trip device; a first safety application of the safety applications being associated with a first set of I / O signals, and a second safety application of the safety applications being associated with a second set of I / O signals, the first I / O signal set being different from the second I / O signal set, the first safety application being implemented based on first pre-programmed instructions stored in a memory of the safety trip device, and the second safety application being implemented based on second pre-programmed instructions stored in a memory of the safety trip device; in response to user selection of the first safety application, prompting the user to specify values ​​for configuration settings associated with the first safety application, the first pre-programmed instructions defining the configuration settings; and implementing the first safety application based on the values ​​of the configuration settings specified by the user and based on the first pre-programmed instructions.

[0005] An exemplary method includes: providing a user with a plurality of available safety applications associated with a process control system for selection, the safety applications being implemented by a safety trip device; a first safety application of the safety applications being associated with a first set of I / O signals, and a second safety application of the safety applications being associated with a second set of I / O signals, the first I / O signal set being different from the second I / O signal set, the first safety application being implemented based on first pre-programmed instructions stored in a memory of the safety trip device, and the second safety application being implemented based on second pre-programmed instructions stored in a memory of the safety trip device; in response to user selection of the first safety application, prompting the user to specify values ​​for configuration settings associated with the first safety application, the first pre-programmed instructions defining the configuration settings; and implementing the first safety application based on the values ​​of the configuration settings specified by the user and based on the first pre-programmed instructions.

[0006] The safety trip device includes: a housing including a base plate; a terminal block including corresponding slots; the slots, the slots being used to receive a first set of terminal modules for communicating with a first set of field devices associated with a first safety application (which is associated with a process control system), the slots being used to receive a second set of terminal modules for communicating with a second set of field devices associated with a second safety application (which is associated with a process control system); and an I / O scanner, the I / O scanner being used to communicate with the terminal modules in the slots of the terminal block via the base plate, the I / O scanner including a memory, the memory being used to store first pre-programmed instructions defining the operation of the first safety application, and for storing second pre-programmed instructions defining the operation of the second safety application. BRIEF DESCRIPTION OF THE DRAWINGS

[0007] Figure 1 An exemplary process control system is shown in which the teachings of the present disclosure may be implemented.

[0008] Figure 2 Shown are exemplary safety trip devices in different arrangements Figure 1 An exemplary process control system is provided.

[0009] Figure 3 Shown Figure 1 and / or Figure 2 Any one of the exemplary safety trip devices of .

[0010] Figure 4 It shows Figure 3 A block diagram of an exemplary implementation of an I / O scanner in an exemplary I / O scanner.

[0011] Figure 5 It means that it can be executed to achieve Figure 4 A flow chart of machine-readable instructions for an exemplary I / O scanner.

[0012] Figure 6 is constructed to execute Figure 5 Instructions to achieve Figure 4 Block diagram of an exemplary processing platform of an exemplary I / O scanner.

[0013] The drawings are not necessarily drawn to scale. However, the thickness of layers or regions may be exaggerated in the drawings. Generally, the same reference numerals will be used throughout the drawings and the accompanying written description to refer to the same or similar components. As used in this patent, describing any component (e.g., layer, film, region, area, or plate) as being located (e.g., located, positioned on, disposed on, or formed on) another component in any way means that the referenced component is in contact with the other component, or that the referenced component is above the other component, wherein one or more intermediate components are located between them. Unless otherwise specified, connection references (e.g., attachment, coupling, connection, and combination) should be interpreted broadly and may include intermediate members between a set of elements and relative movement between elements. Thus, connection references do not necessarily infer that two elements are directly connected and in a fixed relationship with each other. Describing any component as "in contact" with another component means that there are no intermediate components between the two components. Although the drawings show layers and regions with clear lines and boundaries, some or all of these lines and / or boundaries may be ideal. In practice, boundaries and / or lines may be unobservable, mixed, and / or irregular.

[0014] When identifying multiple elements or components that can be referenced separately, the descriptors "first", "second", "third", etc. are used in this article. Unless otherwise specified or understood based on the context of use, such descriptors are not intended to give any meaning in terms of priority, physical order, arrangement in a list, or chronological order, but are merely used as labels to reference multiple elements or components, respectively, so that the disclosed examples are easy to understand. In some examples, the descriptor "first" can be used to refer to an element in the detailed description, while different descriptors such as "second" or "third" can be used to refer to the same element in the claims. In this case, it should be understood that such descriptors are used only for ease of reference to multiple elements or components. DETAILED DESCRIPTION

[0015] The equipment used to implement safety applications associated with process control systems can range from very complex logic solvers (which can process a large number of I / O signals in a flexible manner) to single-purpose safety relays that monitor a specific type of input and generate one output. Although complex safety devices (e.g., logic solvers) provide a high degree of flexibility for many different applications in a fully configurable manner, such devices are relatively expensive and difficult to implement due to the complexity involved in programming and / or configuring the safety application(s) to be implemented. Not only does the complexity in programming and / or configuring the safety application lead to the possibility of human error, but the flexibility of a fully programmable system also creates the possibility of tampering with the safety application after it has been correctly configured (either accidentally or maliciously (e.g., via a cyber attack)).

[0016] In contrast, low-complexity safety trip devices (e.g., safety relays) have the advantage of being relatively inexpensive and easy to set up due to their limited, fixed functionality. In addition, the limited functionality reduces the likelihood of human error in the configuration of such devices and also prevents the implementation of such devices from being tampered with by cyberattacks. The simple design and functionality of safety relays make their operation very reliable. However, many safety relays do not provide redundancy, so that if there is a fault in the system, there is no built-in backup to respond to the problem. In addition, many safety relays are stand-alone devices that do not allow communication with other monitoring systems (e.g., wellhead applications that require the trigger (trip) to be relayed to a master station).

[0017] Some safety applications may involve several different I / O signals (e.g., voting logic-based applications). In some such cases, several different safety relays can be hardwired together to provide the required functionality associated with the application. While this adds complexity relative to using a single safety trip device, it may be less complex than having to acquire, set up, and maintain a complex, fully programmable logic solver. Furthermore, when the I / O count of such a safety application remains relatively small (e.g., less than 25), the simplicity of the application may not justify the cost of a fully programmable logic solver. For certain safety applications involving multiple, but relatively small, I / O signals, dedicated safety trip devices have been developed to avoid the need to hardwire multiple single-input safety relays. These dedicated safety trip devices typically have a fixed number of predefined I / O types corresponding to the specific safety application. While such devices provide convenience in setting up and configuring the system, they are often rigid or limited in their operation and functionality based on the specific application for which they were developed. Therefore, beyond the limited limitations imposed by the design and manufacture of such devices, such devices cannot be easily adapted to new situations and / or different types of safety applications (e.g., associated with different types of I / O signals). In addition, like many safety relays, such dedicated safety trip devices typically do not provide redundancy.

[0018] The example safety trip devices disclosed herein can be adapted for different types of safety applications associated with different types and / or numbers of I / O signals without requiring the end user to expend time and money programming the device for each different safety application. Instead, in some examples, machine-readable instructions (e.g., software and / or firmware) for implementing the relevant safety application are pre-installed and / or pre-programmed and are available for the user to select and implement on the example safety trip device. As used herein, the term "pre-programmed" is expressly defined as programming performed by someone other than the end user before the end user uses the example safety trip device for the corresponding safety application. In some examples, the machine-readable instructions associated with a particular safety application are pre-programmed by the manufacturer of the example safety trip device and installed at the time of manufacture. Furthermore, in some examples, pre-programmed instructions for a particular safety application can be developed by a third-party entity (e.g., an original equipment manufacturer (OEM)) for easy installation at the time of manufacture. Additionally or alternatively, in some examples, the pre-programmed instructions (developed by the manufacturer or another third party) can be provided to the end user for download and installation after the safety trip device is manufactured.

[0019] While the examples disclosed herein relate to "pre-programmed" instructions for a specific safety application, such instructions can be programmed with the ability to define and / or specify specific values ​​for relevant safety parameters and / or other configuration settings. Exemplary safety parameters and / or other configuration settings associated with a specific safety application may include a trip limit (e.g., a set point), the units for the trip limit, the direction of the trip (e.g., high or low), a delay time associated with a trip, and the like. While the end user may be provided with the ability to set such configuration settings, the remaining operation and functionality of the associated safety application is pre-defined in the pre-programmed instructions. In other words, the specific types and quantities of input and output signals, as well as the procedures for analyzing and / or processing the I / O signals, are already defined. In some examples, the safety trip devices disclosed herein include a communication interface for enabling communication with monitoring and / or other systems using any suitable communication protocol (e.g., Modbus). In some such examples, the mapping of communication addresses (e.g., registers) for different I / O parameters and / or signal values ​​is also defined by the pre-programmed instructions, so that the user only needs to specify basic communication port settings (e.g., Modbus port settings) to complete system setup. Thus, setting up a safety application using the exemplary safety trip device disclosed herein is much faster and easier than with a fully programmable logic solver and is less prone to human error. Furthermore, the ability for a user to select different pre-programmed safety applications makes the exemplary safety device more flexible than fixed-function safety relays and / or dedicated safety trip devices.

[0020] Another advantage of pre-programmed instructions developed by manufacturers and / or other third-party entities is that such entities can obtain certification of the pre-programmed instructions from relevant safety compliance agencies or regulatory bodies. Thus, end users can confidently rely on such pre-programmed instructions that meet all necessary safety requirements and / or code without having to spend the time and money to write their own applications and seek appropriate certifications each time a new application is developed. In addition, the exemplary safety trip devices disclosed herein provide redundancy, thereby improving reliability compared to other relatively low I / O count safety trip devices (e.g., safety relays and dedicated safety trip devices). In addition, unlike fully programmable logic solvers that are more susceptible to tampering, some disclosed examples prevent end users and / or malicious attackers from modifying the underlying (pre-programmed) instructions for a particular safety application. Furthermore, in some examples, end users and / or malicious attackers are prevented from changing the particular safety application being implemented and / or the associated configuration settings of that application without having to physically confirm the user's presence, thereby improving the network security of such devices.

[0021] Turning to the accompanying drawings in detail, Figure 1 An exemplary process control system 100 is shown in which the teachings of the present disclosure may be implemented. This particular example corresponds to a stand-alone safety instrumented system (SIS), such as may be implemented at a wellhead. This example is provided for illustrative purposes only. The teachings disclosed herein may be implemented in conjunction with safety applications for any type of process control system (e.g., a distributed control system (DCS), a supervisory control and data acquisition (SCADA) system, etc.) of greater or lesser complexity than that shown in the illustrated example.

[0022] like Figure 1 As shown in the example of , the exemplary system 100 includes a remote terminal unit (RTU) 102 that communicates with one or more field devices 104, 106. Figure 1 As shown, the RTU 102 also communicates with a system host 108 (e.g., an existing SCADA network) associated with the exemplary system 100. In the illustrated example, communication between the RTU 102 and the system host 108 can be accomplished via any suitable communication device and / or medium. In this example, the RTU 102 and associated field devices 104, 106 implement the non-safety aspects of the exemplary process control system 100.

[0023] Figure 1The exemplary system host 108 allows operators, engineers, and / or other plant personnel (any of whom may be referred to herein as a user) to view and / or interact with one or more operator display screens and / or applications that enable the user to view system variables, states, conditions, and / or alarms associated with the exemplary control system 100; change control settings of the exemplary control system 100 (e.g., set points, operating states, clear alarms, silence alarms, etc.); configure and / or calibrate devices within the exemplary control system 100; perform diagnostics on devices within the exemplary control system 100; and / or otherwise interact with devices within the exemplary control system 100.

[0024] Figure 1 The exemplary system host 108 can be implemented using one or more workstations and / or any other suitable computer systems and / or processing systems. For example, the system host 108 can be implemented using a single-processor personal computer, a single-processor or multi-processor workstation, a portable laptop computer, etc. The host 108 can be configured with one or more application stations to execute one or more information technology applications, user interaction applications, and / or communication applications. For example, an application station can be configured to primarily execute applications related to process control, while another application station can be configured to primarily execute applications that enable the control system 100 to use any desired communication medium (e.g., wireless, hardwired, etc.) and protocol (e.g., HTTP, SOAP, etc.).

[0025] Figure 1The exemplary system 100 includes one or more safety trip devices 110, 112, 114, each of which communicates with one or more field devices 116, 118, 120, 122. Although the safety trip devices 110, 112, 114 are shown and described as being associated with the process control system 100, in some examples, the safety trip devices 110, 112, 114 can be implemented as part of one or more safety instrumented systems that operate independently of the rest of the system 100. In some examples, one or more of the field devices 116, 118, 120, 122 can communicate with one or more of the safety trip devices 110, 112, 114. Additionally or alternatively, in some examples, one or more of the field devices 116, 118, 120, 122 that communicate with one or more of the safety trip devices 110, 112, 114 can correspond to one or more field devices that communicate with the RTU 102. In some examples, at least some of the example field devices 104, 106, 116, 118, 120, 122 may be smart field devices such as Fieldbus-compatible valves, actuators, sensors, etc., in which case the smart field devices 104, 106, 116, 118, 120, 122 communicate with the RTU 102 and / or the safety trip devices 110, 112, 114 via any of a wired or wireless communication medium using the known Foundation Fieldbus protocol. Of course, other types of smart field devices and communication protocols may be used instead. For example, the smart field devices 104, 106, 116, 118, 120, 122 may be replaced with and / or Compatible devices (which use known and communication protocol with the RTU 102 and / or safety trip devices 110, 112, 114). Additionally or alternatively, in some examples, the communication protocol may be based on WirelessHART. TM The protocol communicatively couples the field devices 104, 106, 116, 118, 120, 122 via a local wireless network. In addition, in some examples, at least some of the field devices 104, 106, 116, 118, 120, 122 may be non-intelligent field devices, such as conventional 4-20 milliamp (mA) or 0-24 volt direct current (VDC) devices that communicate with the RTU 102 and / or safety trip devices 110, 112, 114 via corresponding hardwired links. Figure 3More details regarding the communication of the example field devices 116 , 118 , 120 , 122 with the example safety trip devices 110 , 112 , 114 are further provided.

[0026] In the example shown, the safety trip devices 110, 112, 114 communicate with the RTU 102 via a primary network 124 via a first switch 126 and a redundant network 128 via a second switch 130. In some examples, the switches 126, 130 may be omitted. In this example, the networks 124, 128 are implemented using the known Modbus protocol. However, in other examples, other communication protocols may be used. Figure 1 In the example shown, each of the exemplary safety trip devices 110, 112, 114 is independently connected to two networks 124, 128 to provide independent safety instrumented functions (SIFs). Communicating the safety trip devices 110, 112, 114 to the RTU 102 enables SIS information to be shared with personnel at workstations associated with the system host 108.

[0027] Figure 1 The exemplary process control system 100 of the illustrated example also includes a human-machine interface 132 to enable display of information associated with the operation of the process control system 100 including the RTU 102 and / or the safety trip devices 110, 112, 114. Additionally, in some examples, a configuration tool 134 may be communicatively coupled to the safety trip devices 110, 112, 114 to enable a user to configure and / or set up each safety trip device 110, 112, 114 to implement a particular safety application. In some examples, such as Figure 1As shown in FIG, configuration tool 134 communicates with safety trip devices 110, 112, 114 via primary network 124 via first switch 126. Additionally or alternatively, in some examples, configuration tool 134 can be directly connected to a specific one of safety trip devices 110, 112, 114. As described above and further below, in some examples, safety trip devices 110, 112, 114 include pre-programmed instructions associated with different safety applications, which are stored in memory and available for selection and configuration by a user. In some examples, a user selects a specific safety application via configuration tool 134 and further specifies values ​​for related configuration parameters and / or settings via configuration tool 134. Furthermore, in some examples, a user can use configuration tool 134 to download a different (e.g., new) pre-programmed application from a website (e.g., maintained by the safety trip device manufacturer and / or a third-party entity) and then install the new application on safety trip devices 110, 112, 114. Configuration tool 134 may be a laptop, notebook, smartphone, handheld device, and / or any other computing device.

[0028] In some examples, the safety trip devices 110, 112, 114 can be configured to handle any suitable number of I / O points and / or channels up to the limits defined by the size of the trip device. In some examples, the safety trip devices 110, 112, 114 are configured to handle up to twelve I / O channels, which is sufficient to provide flexibility to address many relatively low I / O count safety applications. In cases where the I / O count of a particular safety application involves more I / O channels than are available for one safety trip device, multiple devices can be combined, such as Figure 2 shown. Specifically, Figure 2 Shown Figure 1 The exemplary process control system 100 is reconfigured so that the second safety trip device 112 functions as a slave node and the first safety trip device 110 functions as a master node. Combining the two safety trip devices in this manner doubles the available I / O count for a single SIF (e.g., using 24 I / Os instead of 12). Although the exemplary safety trip device described herein includes 12 I / O channels, other exemplary trip devices may have more or fewer than 12 I / O channels.

[0029] Additionally, while the exemplary safety trip devices 110, 112, 114 are described as including up to 12 I / O channels, the actual number of channels used in any particular application can be configured by the user based on the requirements of the particular application being implemented. In other words, in one application, only 4 of the channels may be used, while another application may involve using 11 of the channels. Furthermore, the specific type of I / O signal associated with any of the channels can be tailored to the particular application being implemented. For example, in one application, a first I / O channel may be designated as a 4-20mA analog input. In a second, different application, the first I / O channel may be designated as a thermocouple input. The different types of I / O signals compatible with the exemplary safety trip devices 110, 112, and 114 include 4-20mA analog input signals, 4-20mA analog output signals, 0-10V analog input signals, 0-10V analog output signals, thermocouple signals, resistance temperature detector (RTD) signals, dry or NAMUR discrete input signals, high-end discrete output signals, isolated discrete input signals or discrete output signals for higher current or higher VAC voltage, relay contact output signals, and the like. The ability to implement any number of these different types of I / O signals in any combination up to the structural capacity of the safety trip device (or more if multiple trip devices are combined) provides greater flexibility in adapting the safety trip device to different uses and applications than using existing dedicated safety trip devices designed for specific applications. Furthermore, providing users with pre-programmed instructions corresponding to specific applications for selection makes the configuration and setup of such devices significantly less complex than with fully programmable logic solvers.

[0030] Figure 3 Shown Figure 1 and / or Figure 2 A more detailed view of the first exemplary safety trip device 110 is provided. Although the following discussion is provided with respect to the first safety trip device 110, Figure 1 and / or Figure 2 The second safety trip device 112 and the third safety trip device 114 can be similar or identical to the first safety trip device 110. The exemplary safety trip device 110 of the illustrated example includes a housing 302 that carries one or more I / O scanners 304, 306. In this example, there are two I / O scanners, with the first I / O scanner 304 serving as a primary I / O scanner and the second I / O scanner 306 serving as a redundant I / O scanner. The I / O scanners 304, 306 are communicatively coupled to respective I / O ports 308, 310 through which the I / O scanners 304, 306 can communicate with the Figure 1The first network 124 and the second network 128 are shown as being communicatively coupled. Additionally or alternatively, the I / O ports 308, 310 may be used to communicatively interconnect a plurality of safety trip devices, such as Figure 2 In some examples, the I / O scanners 304, 306 are communicatively coupled to the I / O ports 308, 310 via a backplane housed within the housing 302.

[0031] In some examples, I / O scanners 304, 306 are selectively removable from housing 302, thereby enabling a specific I / O scanner to be replaced with a different scanner. In some such examples, when coupled to housing 302, I / O scanners 304, 306 are secured in place using clips or latches 312 and / or other locking mechanisms. In other examples, I / O scanners 304, 306 are integrated with housing 302. Like I / O scanners 304, 306, in some examples, I / O ports 308, 310 are selectively removable from housing 302, thereby enabling a specific I / O port to be replaced with a different port (e.g., including multiple communication plugs rather than just one (multiple) port(s) as shown in the illustrated example). In some examples, clips or latches 314 and / or other locking mechanisms secure I / O ports 308, 310 to the housing. In other examples, I / O ports 308, 310 are integrated with housing 302.

[0032] As shown in the illustrated example, the safety trip device 110 also includes a plurality of terminal blocks 316. In this example, there are twelve terminal blocks 316. In other examples, the number of terminal blocks 316 may be greater or less than twelve. The example terminal blocks 316 provide a first physical interface (e.g., a wire termination point 318) to which one or more wires from the field devices 116, 118, 120, 122 may be placed. In addition, the example terminal blocks 316 include a second physical interface (e.g., a slot or receptacle 320 containing electrical contacts 322) to receive and retain one of a plurality of different types of I / O terminal modules 324. In the illustrated example, the I / O terminal modules 324 are inserted into the slots 320 of the first terminal block 316, the second terminal block 316, the third terminal block 316, the fifth terminal block 316, and the twelfth terminal block 316. In some examples, the terminal modules are CHARMs (Characterization Modules) developed by Emerson Process Management.

[0033] In the example shown, safety trip device 110 also includes an address plug 326. In some examples, address plug 326 may correspond to one of two types that can be selectively interchanged with one another in corresponding slots in housing 302 of safety trip device 110. A first type of address plug 326 is a runtime address plug, which is a standard type of address plug that provides addressing information for different terminal modules 324 to I / O scanners 304, 306. A second type of address plug 326 is a configuration address plug that can be used specifically when safety trip device 110 is configured for a specific safety application (as discussed more fully below).

[0034] In some examples, the terminal block 316 can be selectively removed from the housing 302 to enable replacement with a different terminal block (e.g., having a different number and / or type of terminal points 318 to connect to different types of field devices). In some such examples, the I / O terminal module 324 can be integrated with the corresponding terminal block 316 so that different I / O terminal modules 324 and terminal blocks 316 can be selectively removed and / or replaced from the safety trip device 110. In other examples, the terminal block 316 can be integrated with the housing 302, with the I / O terminal module 324 being selectively removable.

[0035] In the example shown, electrical contacts 322 on the terminal block 316 are electrically coupled to the terminal points 318 to enable communication between the field devices 116, 118, 120, 122 (connected to the terminal points 318) and the I / O terminal modules 324 inserted into the slots 320 of the corresponding terminal blocks 316. Furthermore, the electrical contacts 322 of the terminal blocks 316 are electrically coupled to the backplane of the housing 302 to enable communication between the I / O scanners 304, 306 and the corresponding I / O terminal modules 324 inserted into the terminal blocks 316. More specifically, in some examples, the backplane of the housing 302 includes a common I / O bus (e.g., a common or shared communication bus) that communicatively couples the I / O terminal modules 324 in any one of the terminal blocks 316 to the I / O scanners 304, 306.

[0036] In some examples, the types of I / O signals sent to or received from different field devices 116, 118, 120, 122 can differ based on the type of field device involved. As a result, the I / O signals may not be directly compatible with the universal I / O bus because they are based on different communication protocols. Therefore, in some examples, transmissions associated with different types of I / O signals (transmitted based on different communication protocols) from different types of field devices 116, 118, 120, 122 are handled by different types of I / O terminal modules 324 configured to handle the corresponding types of I / O signals. In other words, the different types of I / O terminal modules 324 include different logic circuits to receive field device information from the corresponding field devices based on a specific communication protocol and transmit the field device information to the I / O scanners 304, 306 using different protocols associated with the universal I / O bus. Similarly, the I / O scanners 304, 306 can transmit field device information to the I / O terminal modules 324 based on the communication protocol associated with the universal I / O bus, and then the logic circuits in each I / O terminal module 324 can extract the field device information and transmit it to the corresponding field device based on the specific type of I / O signal and the associated communication protocol for each specific field device.

[0037] The ability to use different I / O terminal modules 324 configured to handle different types of I / O signals (associated with different communication protocols) enables safety trip device 110 to adapt to different safety applications by selecting the appropriate type of I / O terminal module 324 corresponding to the specific type of I / O signal involved in each desired application and inserting such module 324 into terminal block 316. Of course, in order for I / O scanners 304, 306 to properly analyze and / or process the I / O signals of a given safety application, I / O scanners 304, 306 need to be programmed and / or configured to do so. In some examples, I / O scanners 304, 306 include memory for storing pre-programmed instructions associated with different types of safety applications, eliminating the need for the end user to program the I / O scanner each time safety trip device 110 is adapted for a new safety application. In some examples, the pre-programmed instructions are stored in memory at the time of manufacture, prior to the sale of safety trip device 110. Additionally or alternatively, pre-programmed instructions may be downloaded by the end user and stored on the I / O scanners 304 , 306 after purchasing the safety trip device 110 .

[0038] Providing pre-programmed instructions for a particular safety application that the end user does not need to develop significantly reduces the complexity of setting up the safety trip device 110 for such a safety application. For example, in some examples, the pre-programmed instructions define the number and type of I / O signals involved in the particular safety application, as well as the interrelationships of such signals and how to handle and / or process them. Furthermore, in some examples, the pre-programmed instructions not only define the logical sequence(s) of operations for the particular safety application, but also provide instructions for operations involving interfacing with external components (e.g., Figure 1 324) for communicating with the host system 108 in the safety trip device 110. Consequently, when an end user desires to configure the safety trip device 110 to implement a particular safety application, the user selects the associated pre-programmed instructions, inserts the associated I / O terminal block 324, and defines certain configuration settings and / or communication port settings. In some examples, the configuration settings include defining values ​​for associated safety parameters, such as the value of a trip limit (e.g., a set point), the units for the trip limit, the direction of the trip (e.g., high or low), a delay period associated with the trip, etc. In some examples, the communication port settings (e.g., Modbus port settings) include defining an Internet Protocol (IP) address, subnet mask, port number, etc. associated with the terminal block 316, and / or associated I / O signals associated with the safety application.

[0039] In some examples, the pre-programmed instructions may be certified by a relevant safety compliance agency or regulatory body. This certification only needs to be performed once and can then be reliably used by any number of end users on any number of safety trip devices 110. To ensure that the certification remains valid, in some examples, the end user is prevented from modifying the pre-programmed instructions. In other words, although the user can select and provide appropriate configuration settings for the specific implementation of the associated safety application, the user may be prevented from accessing, viewing, and / or modifying the underlying logic sequence and the association and interaction of I / O signals as defined in the pre-programmed instructions. Although the end user may not be able to modify the pre-programmed instructions stored on the I / O scanners 304, 306, in some examples, the end user may develop his or her own program to be implemented by the I / O scanners 304, 306, for example, when there are no pre-programmed instructions for a specific safety application. In such examples, the end user is able to update and / or modify the program as needed.

[0040] In some examples, selection of a particular safety application associated with the pre-programmed instructions stored on I / O scanners 304, 306 and the associated configuration for implementing such instructions is limited to when configuration address plug 326 is inserted into safety trip device 110 in place of standard runtime address plug 326. Limiting modification of the configuration and settings for a particular safety application to when configuration address plug 326 is inserted into safety trip device 110 effectively provides a test of user presence for enhanced security before modifications can be made, as the user must physically insert configuration address plug 326. Once safety trip device 110 is set up and configured for the particular safety application, and the standard runtime address plug has replaced configuration address plug 326, safety trip device 110 operates as configured without the risk of someone accidentally or maliciously tampering with the configuration settings of the application (and / or switching the operation of safety trip device 110 to correspond to a different safety application associated with a different set of pre-programmed instructions). In other words, the configuration address plug 326 places the safety trip device 110 in a configuration mode in which safety applications can be modified but not implemented. On the other hand, the runtime address plug 326 places the safety trip device in a run mode in which safety applications can be implemented but not modified.

[0041] Figure 4 It shows Figure 3 4. Although the following discussion is provided with respect to the primary I / O scanner 304, the redundant I / O scanner 306 can be similar or identical to the primary I / O scanner 304. As shown in the illustrated example, the primary I / O scanner 304 includes an exemplary external communication interface 402, an exemplary I / O communication interface 404, an exemplary configuration controller 406, an exemplary I / O analyzer 408, and an exemplary memory 410.

[0042] The example external communication interface 402 allows for communication with components external to the safety trip device 110. In other words, in this example, the external communication interface 402 interfaces with the corresponding I / O ports 308, 310 to allow for communication with the networks 124, 128 and / or with other safety trip devices 110. For example, in addition, a user may access the Figure 1 and Figure 2 Configuration tool 134 is used to select and / or configure a specific safety application on safety trip device 110 , ie, to communicate with safety trip device 110 via external communication interface 402 of I / O scanner 304 .

[0043] The exemplary I / O communication interface 404 allows for communication with various I / O terminal modules 324 plugged into the terminal block 316 on the safety trip device 110. In this example, the I / O communication interface 404 communicates with the I / O terminal modules 324 via the backplane of the housing 302 using the universal I / O bus described above. In some examples, the I / O communication interface 404 also allows for communication between the primary I / O scanner 304 and the redundant I / O scanner 306. As a result, in some examples, modifications and / or changes made to one of the I / O scanners 304, 306 are automatically communicated to the other of the I / O scanners 304, 306. Although the external communication interface 402 is shown separately from the I / O communication interface 404, in some examples, the external communication interface 402 can be integrated and / or combined with the I / O communication interface 404.

[0044] Figure 4 An exemplary configuration controller 406 of the I / O scanner 304 manages user selection and configuration of safety applications to be implemented by the safety trip device 110. In some examples, the configuration controller 406 determines whether the address plug 326 is a configuration address plug or a runtime address plug. If the plug 326 is a runtime address plug, the configuration controller 406 prevents the user from selecting (e.g., changing) the designation of a safety application for implementation on the safety trip device 110. Furthermore, if the address plug 326 is a runtime address plug, the configuration controller 406 may also prevent the user from modifying the configuration settings of the currently designated safety application. On the other hand, if the address plug 326 is a configuration address plug, the configuration controller 406 may enable the user to select and / or configure a safety application for implementation by the safety trip device 110. However, due to its inherent lack of valid address information, the configuration address plug 326 prevents the safety application from actually being implemented. The designated safety application can only be implemented when the standard runtime address plug 326 is reinserted into the safety trip device 110.

[0045] As described above, in some examples, a user uses configuration tool 134 to select and configure a particular security application. Thus, in some examples, configuration controller 406 communicates with configuration tool 134 via external communication interface 402 to provide prompts and / or options for the user to select and / or provide feedback during the configuration process. More specifically, in some examples, configuration controller 406 provides the user with available security applications for selection, which are presented on a display screen of configuration tool 134. In some examples, configuration controller 406 can generate a graphical user interface with relevant user selections, which are presented via a display screen on configuration tool 134. In other examples, configuration controller 406 can send relevant information to enable configuration tool 134 to generate a suitable graphical user interface to display information to the user. The available security applications can be displayed in any suitable manner (e.g., in a drop-down list, in a table, etc.).

[0046] In some examples, the available safety applications provided to the user for selection correspond to all safety applications associated with the pre-programmed instructions stored in the memory 410 of the I / O scanner 304. Additionally or alternatively, in some examples, the available safety applications provided to the user may include applications that the user (or a different end user) has previously developed and stored in the memory 410. In some examples, the available safety applications provided to the user for selection may correspond to a subset of all safety applications with the pre-programmed instructions stored in the memory 410. For example, in some examples, only safety applications associated with a particular type of process control system (e.g., wellhead safety applications) may be provided to the user.

[0047] In some examples, the available security applications may include pre-programmed instructions that are not already stored in memory 410. In such examples, the user may be provided with an option to obtain such pre-programmed instructions by downloading them from a website using configuration tool 134. Once downloaded, configuration tool 134 may send the pre-programmed instructions to I / O scanner 304 for storage in memory 410. In some examples, configuration controller 406 may not specifically identify pre-configured instructions that are not stored in memory 410, but still provide the user with the option to examine new and / or different security applications beyond those that may be available stored in memory 410.

[0048] Available safety applications can correspond to any suitable type of application that can be implemented in a safety instrumented system. Different exemplary safety applications that can have pre-programmed instructions stored in the memory 410 include burner management system (BMS) applications, emergency shutdown (ESD) applications, automatic overfill protection system (AOPS) applications, high integrity pressure protection system (HIPPS) applications, single voter applications (e.g., 1 out of 2 voters (1oo2), 2 out of 3 voters (2oo3), etc.), multi-iteration voter applications (e.g., two iterations of a 2oo3 voter, three iterations of a 1oo2 voter, etc.), wellhead applications, etc.

[0049] In some examples, once a user selects a particular safety application to be implemented, the configuration controller 406 retrieves the associated instructions stored in the memory 410 and prompts the user (e.g., via the configuration tool 134) to provide values ​​for relevant parameters and other configuration settings (e.g., trip limits, trip directions, time delays, etc.). In some examples, the configuration controller 406 may provide the user (e.g., via the configuration tool 134) with a list of the types of I / O signals involved in the selected safety application to enable the user to confirm that the correct I / O terminal modules 324 are inserted into the terminal blocks 316 of the safety trip device 110. In some examples, the user may specify the types of terminal modules 324 installed in the safety trip device 110 and their locations in the various terminal blocks 316 to enable the configuration controller 406 to confirm that the correct I / O terminal modules 324 are to be used based on the I / O signals associated with the selected application as defined in the pre-programmed instructions. Furthermore, the user specifying the location (e.g., I / O channel) for each I / O terminal module 324 enables the configuration controller 406 to appropriately configure the communication addresses of these I / O terminal modules 324. In some examples, the configuration controller 406 can automatically scan the I / O terminal modules 324 to confirm that the modules are the correct type corresponding to the I / O signals (defined in preprogrammed instructions associated with the safety application selected by the user) and / or to determine the specific terminal block 316 into which to plug each I / O terminal module 324. In some examples, if an incorrect I / O terminal module 324 is detected and / or the relevant I / O terminal module 324 is not detected, the configuration controller 406 can generate an alarm or error message to notify the user of the detected error.

[0050] Once the configuration controller 406 has received all configuration settings and communication port settings from the user, the configuration controller 406 can monitor the removal of the configuration address plug 326 from the safety trip device 110 and its replacement with the runtime address plug. Once the runtime address plug 326 is inserted, control and / or operation of the I / O scanner 304 is transferred to the exemplary I / O analyzer 408. The I / O analyzer 408 implements pre-programmed instructions to control the implementation of the user-selected safety application. In other words, the I / O analyzer 408 generates field device information to be transmitted to the intended field devices 116, 118, 120, 122, and also receives and processes field device information received from the field devices 116, 118, 120, 122. More specifically, the I / O analyzer 408 compares the relevant I / O signals to the user-configured trip limits and / or processes the I / O signals according to the operational logic sequence(s) specified in the pre-programmed instructions to enable the associated safety application.

[0051] Despite the realization Figure 3 The I / O scanner 304 is shown in FIG. Figure 4 shown in, but Figure 4 One or more of the elements, processes, and / or devices shown in the example may be combined, divided, rearranged, omitted, eliminated, and / or implemented in any other manner. In addition, the example external communication interface 402, the example I / O communication interface 404, the example configuration controller 406, the example I / O analyzer 408, the example memory 410, and / or more generally, Figure 3The example I / O scanner 304 may be implemented in hardware, software, firmware, and / or any combination of hardware, software, and / or firmware. Thus, for example, any of the example external communication interface 402, the example I / O communication interface 404, the example configuration controller 406, the example I / O analyzer 408, the example memory 410, and / or more generally, the example I / O scanner 304 may be implemented by one or more analog or digital circuits, logic circuits, programmable processor(s), programmable controller(s), graphics processing unit(s) (GPU(s), digital signal processor(s) (DSP(s), application specific integrated circuit(s) (ASIC(s), programmable logic device(s) (PLD(s), and / or field programmable logic device(s) (FPLD(s)). When any of the apparatus or system claims of this patent are read to cover pure software and / or firmware implementations, at least one of the example external communication interface 402, the example I / O communication interface 404, the example configuration controller 406, the example I / O analyzer 408, and / or the example memory 410 is thus expressly defined to include a non-transitory computer-readable storage device or storage disk (such as a memory, a digital versatile disk (DVD), a compact disk (CD), a Blu-ray disk, etc.), including software and / or firmware. Further, Figure 3 An exemplary I / O scanner 304 may include in addition to or in lieu of Figure 4 , and / or may include one or more elements, processes, and / or devices other than those shown in , and / or may include more than one of any or all of the elements, processes, and devices shown. As used herein, the phrase "in communication," including variations thereof, encompasses direct communication and / or indirect communication through one or more intermediate components, and does not require direct physical (e.g., wired) communication and / or constant communication, but additionally includes selective communication at periodic intervals, scheduled intervals, non-periodic intervals, and / or one-time events.

[0052] Indicates the implementation Figure 3 and / or Figure 4 Flowcharts of exemplary hardware logic, machine-readable instructions, hardware implementing a state machine, and / or any combination thereof for the I / O scanner 304 are provided in Figure 5 The machine-readable instructions may be one or more executable programs or instructions for execution by a computer processor (such as the following combined Figure 6The program may be embodied in software stored in a non-transitory computer-readable storage medium such as a CD-ROM, floppy disk, hard drive, DVD, Blu-ray disk, or memory 612 associated with the processor, but the entire program and / or portions thereof may alternatively be executed by devices other than the processor 612 and / or embodied in firmware or dedicated hardware. Furthermore, although reference is made to Figure 5 The flowchart shown in describes an exemplary program, but many other methods of implementing the exemplary I / O scanner 304 may be used instead. For example, the order of execution of the blocks may be changed, and / or some of the blocks described may be changed, eliminated, or combined. Additionally or alternatively, any or all of the blocks may be implemented by one or more hardware circuits (e.g., discrete and / or integrated analog and / or digital circuits, FPGAs, ASICs, comparators, operational amplifiers (op-amps), logic circuits, etc.) that are configured to perform the corresponding operations without executing software or firmware.

[0053] The machine-readable instructions described herein may be stored in one or more of a compressed format, an encrypted format, a segmented format, a compiled format, an executable format, a packaged format, and the like. The machine-readable instructions described herein may be stored as data (e.g., a portion of an instruction, a code, a representation of the code, and the like) that can be used to create, manufacture, and / or generate machine-executable instructions. For example, the machine-readable instructions may be segmented and stored on one or more storage devices and / or computing devices (e.g., a server). The machine-readable instructions may require one or more of installation, modification, adaptation, updating, combination, supplementation, configuration, decryption, decompression, unpacking, distribution, redistribution, compilation, and the like to make them directly readable, interpretable, and / or executable by a computing device and / or other machine. For example, the machine-readable instructions may be stored in multiple parts that are separately compressed, encrypted, and stored on separate computing devices, wherein the parts, after decryption, decompression, and combination, form a set of executable instructions that implement a program such as described herein.

[0054] In another example, the machine-readable instructions may be stored in a state in which they can be read by a computer, but require the addition of a library (e.g., a dynamic link library (DLL)), a software development kit (SDK), an application programming interface (API), etc., in order to execute the instructions on a particular computing device or other device. In another example, the machine-readable instructions and / or corresponding program(s) may need to be configured (e.g., stored settings, data inputs, recorded network addresses, etc.) before the machine-readable instructions and / or corresponding program(s) can be executed in whole or in part. Thus, the disclosed machine-readable instructions and / or corresponding program(s) are intended to encompass such machine-readable instructions and / or program(s) regardless of the particular format or state of the machine-readable instructions and / or program(s) when stored, at rest, or in transport.

[0055] The machine-readable instructions described herein may be represented by any past, present, or future instruction language, scripting language, programming language, etc. For example, the machine-readable instructions may be represented using any of the following languages: C, C++, Java, C#, Perl, Python, JavaScript, Hypertext Markup Language (HTML), Structured Query Language (SQL), Swift, etc.

[0056] As mentioned above, Figure 5 The exemplary processes of can be implemented using executable instructions (e.g., computer and / or machine readable instructions) stored on a non-transitory computer and / or machine readable medium (e.g., a hard drive, flash memory, read-only memory, compact disk, digital versatile disk, cache, random access memory, and / or any other storage device or storage disk that stores information for any duration (e.g., for an extended period of time, permanently, for a transient instance, for temporary buffering, and / or for caching information). As used herein, the term non-transitory computer readable medium is expressly defined to include any type of computer readable storage device and / or storage disk and to exclude propagating signals and to exclude transmission media.

[0057] "Include" and "comprising" (and all their forms and tenses) are used herein as open-ended terms. Thus, whenever a claim adopts any form of "include" or "comprising" (e.g., comprises, including, comprising, including, having, etc.) as a preamble or within any kind of claim recitation, it should be understood that additional elements, terms, etc. may be presented without exceeding the scope of the corresponding claim or recitation. As used herein, when the phrase "at least" is used as a transition term, such as in the preamble of a claim, it is open-ended in the same manner that the terms "include" and "comprising" are open-ended. The term "and / or," when used, for example, in a form such as A, B, and / or C, refers to any combination or subset of A, B, and C, such as (1) only A, (2) only B, (3) only C, (4) A and B, (5) A and C, (6) B and C, and (7) A and B and C. As used herein in the context of describing structures, components, items, objects, and / or things, the phrase "at least one of A and B" is intended to refer to embodiments that include any of the following: (1) at least one A, (2) at least one B, and (3) at least one A and at least one B. Similarly, as used herein in the context of describing structures, components, items, objects, and / or things, the phrase "at least one of A or B" is intended to refer to embodiments that include any of the following: (1) at least one A, (2) at least one B, and (3) at least one A and at least one B. Similarly, as used herein in the context of describing structures, components, items, objects, and / or things, the phrase "at least one of A or B" is intended to refer to embodiments that include any of the following: (1) at least one A, (2) at least one B, and (3) at least one A and at least one B. As used herein in the context of describing the execution or performance of processes, instructions, actions, activities, and / or steps, the phrase "at least one of A and B" is intended to refer to embodiments that include any of the following: (1) at least one A, (2) at least one B, and (3) at least one A and at least one B. Similarly, as used herein in the context of describing the execution or performance of processes, instructions, actions, activities, and / or steps, the phrase "at least one of A or B" is intended to refer to embodiments that include any of the following: (1) at least one A, (2) at least one B, and (3) at least one A and at least one B.

[0058] As used herein, singular references (e.g., "a," "an," "first," "second," etc.) do not exclude a plurality. As used herein, the term "a" or "an" entity refers to one or more of that entity. The terms "a" (or "an"), "one or more," and "at least one" are used interchangeably herein. Furthermore, although listed separately, a plurality of devices, elements, or method actions may be implemented by, for example, a single unit or processor. Additionally, although individual features may be included in different examples or claims, these features may be combined, and inclusion in different examples or claims does not mean that a combination of features is not feasible and / or advantageous.

[0059] Figure 5 The example configuration controller 406 begins at block 502, where the example configuration controller 406 determines whether the I / O scanner 304 is communicatively coupled to the configuration tool 134. If so, control proceeds to block 504, where the example external communication interface 402 determines whether a request to modify the current safety application has been received. If so, control proceeds to block 506, where the example configuration controller 406 determines whether a configuration address plug 326 is present in the safety trip device 110. If so, control proceeds to block 508, where the example configuration controller 406 presents the user with available safety applications for selection. Upon receiving the user selection, at block 510, the example configuration controller 406 determines whether the selected safety application is already installed on the I / O scanner 304. If not, control proceeds to block 512, where the example configuration controller 406 prompts the user to download and install the selected safety application. In some examples, the user may download the safety application independently without being prompted to do so (e.g., before beginning the process of setting up a particular safety application). In some such examples, the user may simply indicate that the user desires to install a new security application on the I / O scanner 304 .

[0060] Once the application is installed, control proceeds to block 514. Returning to block 510, if the selected security application is already installed, control proceeds directly to block 514. At block 514, the example configuration controller 406 prompts the user to specify values ​​for configuration settings associated with the selected security application. At block 516, the example configuration controller 406 prompts the user to specify communication port settings associated with the selected security application. Thereafter, control proceeds to block 518.

[0061] Returning to block 502, if the I / O scanner 304 is not communicatively coupled to the configuration tool 134, control proceeds directly to block 518. Similarly, returning to block 504, if the external communication interface 402 has not received a request to modify the current safety application, control proceeds directly to block 518. Similarly, returning to block 506, if the example configuration controller 406 determines that the configuration address plug 326 is not present (e.g., the runtime address plug is in the safety trip device 110), control proceeds directly to block 518. At block 518, the example IO analyzer 408 determines whether to implement the safety application. In some examples, this determination is made based on feedback from the user indicating that configuration of the application is complete and / or that the user desires to implement the application after continuing to execute blocks 508-516. This determination may additionally or alternatively be made based on the state of the system, allowing for skipping blocks 508-516 based on a decision in any of blocks 502-506. If the safety application is not to be implemented, control proceeds to block 524. If a safety application is to be implemented, control proceeds to block 520 where the example configuration controller 406 again determines whether a configuration address plug 326 is present in the safety trip device 110. This determination is made at block 506 to prevent accidental changes to the selection and / or configuration of the safety application, while this same determination is made at block 520 to prevent unintended implementation of the currently selected and configured safety application. If a configuration address plug 326 is present, the safety application is not implemented and control proceeds to block 524. If a configuration address plug 326 is not present (e.g., the runtime address plug is in the safety trip device 110), control proceeds to block 522 where the example I / O analyzer 408 executes instructions associated with the safety application. Thereafter, control proceeds to block 504 where it is determined whether to continue the process. If so, control returns to block 502. Otherwise, Figure 5 The exemplary process ends.

[0062] Figure 6 is constructed to execute Figure 5 Instructions to achieve Figure 3 and / or Figure 4 The processor platform 600 can be, for example, a server, a personal computer, a workstation, a self-learning machine (e.g., a neural network), a mobile device (e.g., a cell phone, a smartphone, a tablet computer (such as an iPad), or a computer system. TM ) or any other type of computing device.

[0063] The processor platform 600 of the illustrated example includes a processor 612. The processor 612 of the illustrated example is hardware. For example, the processor 612 can be implemented by one or more integrated circuits, logic circuits, microprocessors, GPUs, DSPs, or controllers from any desired family or manufacturer. The hardware processor can be a semiconductor-based (e.g., silicon-based) device. In this example, the processor implements the exemplary configuration controller 406 and the exemplary I / O analyzer 408.

[0064] The processor 612 of the illustrated example includes a local memory 613 (e.g., a cache). The processor 612 of the illustrated example communicates with a main memory including a volatile memory 614 and a non-volatile memory 616 via a bus 618. The volatile memory 614 may be comprised of synchronous dynamic random access memory (SDRAM), dynamic random access memory (DRAM), Dynamic Random Access Memory The non-volatile memory 616 may be implemented by flash memory and / or any other desired type of memory device. Access to the main memories 614 and 616 is controlled by a memory controller. In this example, the non-volatile memory 616 includes the memory 410.

[0065] The processor platform 600 of the illustrated example also includes an interface circuit 620. The interface circuit 620 may be connected to the processor platform 600 through any type of interface standard (such as an Ethernet interface, a universal serial bus (USB), interface, near field communication (NFC) interface and / or PCI Express interface).

[0066] In the example shown, one or more input devices 622 are connected to the interface circuitry 620. The input device(s) 622 allow a user to input data and / or commands to the processor 612. The input device(s) may be implemented by, for example, an audio sensor, a microphone, a camera (still or video), a keyboard, buttons, a mouse, a touch screen, a trackpad, a trackball, an isopoint mouse, and / or a voice recognition system.

[0067] One or more output devices 624 are also connected to the interface circuit 620 of the illustrated example. The output device 624 can be implemented, for example, by a display device (e.g., a light emitting diode (LED), an organic light emitting diode (OLED), a liquid crystal display (LCD), a cathode ray tube display (CRT), an in-place switch (IPS) display, a touch screen, etc.), a tactile output device, a printer, and / or a speaker. Thus, the interface circuit 620 of the illustrated example typically includes a graphics driver card, a graphics driver chip, and / or a graphics driver processor.

[0068] The interface circuitry 620 of the illustrated example also includes communication devices, such as transmitters, receivers, transceivers, modems, residential gateways, wireless access points, and / or network interfaces, to facilitate data interaction with external machines (e.g., any type of computing device) via a network 626. Communication can be via, for example, an Ethernet connection, a digital subscriber line (DSL) connection, a telephone line connection, a coaxial cable system, a satellite system, a field-wireless system, a cellular telephone system, etc. In this example, the interface circuitry 620 implements the example external communication interface 402 and the example I / O communication interface 404.

[0069] The processor platform 600 of the illustrated example also includes one or more mass storage devices 628 for storing software and / or data. Examples of such mass storage devices 628 include floppy disk drives, hard disk drives, compact disk drives, Blu-ray disk drives, redundant array of independent disks (RAID) systems, and digital versatile disk (DVD) drives. In this example, the mass storage device 628 includes the memory 410.

[0070] Figure 5 The machine-executable instructions 632 may be stored in the mass storage device 628, in the volatile memory 614, in the non-volatile memory 616, and / or on a removable, non-transitory computer-readable storage medium (eg, a CD or DVD).

[0071] Based on the foregoing, it will be appreciated that example methods, apparatus, and articles of manufacture have been disclosed that enable the setup and configuration of safety trip devices to be performed with significantly less time and effort than using existing fully programmable logic solvers, as the examples disclosed herein provide users with the ability to select pre-programmed instructions corresponding to specific safety applications. Such pre-programmed instructions can be certified by relevant safety compliance agencies, thereby providing end users with greater confidence in the reliability of such safety applications and / or reducing the complexity and cost of developing their own applications and seeking their own certification. Furthermore, some example safety trip devices can only be configured and set up when a configuration module is inserted therein, and only after the configuration module is removed, thereby providing greater security than existing fully programmable logic solvers, which are more susceptible to tampering. While the examples disclosed herein provide a simpler end-user experience based on pre-programmed instructions, the examples also provide for other specialized safety trip devices and / or safety relays, as the example safety trip devices disclosed herein can store multiple different sets of instructions associated with different types of safety applications. This flexibility may be achieved by implementing the exemplary safety trip device with selectively removable terminal modules that can handle different types of I / O signals such that any particular safety application can be implemented simply by inserting the appropriate terminal modules corresponding to the I / O signals involved in the particular safety application in the area of ​​interest.

[0072] Example 1 includes an apparatus comprising: a configuration controller for providing a user with a plurality of available safety applications associated with a process control system for selection, the safety applications being implemented by a safety trip device; a first safety application of the safety applications being associated with a first set of I / O signals, a second safety application of the safety applications being associated with a second set of I / O signals, the first set of I / O signals being different from the second set of I / O signals, the first safety application being implemented based on first preprogrammed instructions stored in a memory of the safety trip device, the second safety application being implemented based on second preprogrammed instructions stored in the memory of the safety trip device, and in response to user selection of the first safety application, prompting the user to specify a value for a configuration setting associated with the first safety application, the first preprogrammed instructions defining the configuration setting; and an I / O analyzer for implementing the first safety application based on the value of the configuration setting specified by the user and based on the first preprogrammed instructions.

[0073] Example 2 includes the apparatus of Example 1, wherein the first set of I / O signals corresponds to a first I / O count and the second set of I / O signals corresponds to a second I / O count, the first I / O count being different than the second I / O count.

[0074] Example 3 includes the apparatus of Example 1, wherein the first set of I / O signals corresponds to a first subset of I / O signals of different types, and the second set of I / O signals corresponds to a second subset of I / O signals of different types, the first subset of I / O signals of different types being different from the second subset of I / O signals of different types.

[0075] Example 4 includes the apparatus of Example 3, wherein the first set of I / O signals is transmitted between the processor of the safety trip device and the field device via a first set of terminal modules carried by the housing of the safety trip device, the first set of terminal modules including different types of terminal modules corresponding to a first subset of the different types of I / O signals.

[0076] Example 5 includes the apparatus of Example 4, wherein the terminal modules of the first terminal module set are selectively replaceable within the housing by terminal modules of the second terminal module set, the second terminal module set including terminal modules of different types corresponding to a second subset of the different types of I / O signals.

[0077] Example 6 includes the apparatus of Example 1, wherein the plurality of available secure applications comprises a first set of applications stored in the memory and a second set of applications available for download.

[0078] Example 7 includes the apparatus of Example 1, wherein the security application of the plurality of available security applications is certified by a security compliance authority before being provided to the user for selection.

[0079] Example 8 includes the apparatus of Example 1, wherein the configuration controller is to: in response to a configuration address plug being inserted into a slot of a housing of the safety trip device, provide the plurality of available safety applications to the user for selection and enable the user to specify a value for a configuration setting associated with the first safety application; and in response to a runtime address plug being inserted into the slot of the housing of the safety trip device, prevent the user from changing the configuration setting or switching from the first safety application to the second safety application.

[0080] Example 9 includes a non-transitory computer-readable medium comprising instructions that, when executed, cause a safety trip device to at least perform the following operations: provide a user with a plurality of available safety applications associated with a process control system for selection, the safety applications being implemented by the safety trip device; a first safety application of the safety applications being associated with a first set of I / O signals, a second safety application of the safety applications being associated with a second set of I / O signals, the first set of I / O signals being different from the second set of I / O signals, the first safety application being implemented based on first pre-programmed instructions stored in a memory of the safety trip device, the second safety application being implemented based on second pre-programmed instructions stored in the memory of the safety trip device; in response to a user selection of the first safety application, prompting the user to specify a value for a configuration setting associated with the first safety application, the first pre-programmed instructions defining the configuration setting; and implementing the first safety application based on the value of the configuration setting specified by the user and based on the first pre-programmed instructions.

[0081] Example 10 includes the non-transitory computer-readable medium of Example 9, wherein the first set of I / O signals corresponds to a first I / O count and the second set of I / O signals corresponds to a second I / O count, the first I / O count being different than the second I / O count.

[0082] Example 11 includes the non-transitory computer-readable medium of Example 9, wherein the first set of I / O signals corresponds to a first subset of I / O signals of different types, and the second set of I / O signals corresponds to a second subset of the different types of I / O signals, the first subset of the different types of I / O signals being different from the second subset of the different types of I / O signals.

[0083] Example 12 includes the non-transitory computer-readable medium of Example 11, wherein the first set of I / O signals is transmitted between the processor of the safety trip device and the field device via a first set of terminal modules carried by the housing of the safety trip device, and the first terminal module set includes different types of terminal modules corresponding to the first subset of the different types of I / O signals.

[0084] Example 13 includes the non-transitory computer-readable medium of Example 12, wherein a terminal module in the first terminal module set is selectively replaceable within the housing by a terminal module in a second set of terminal modules, the second terminal module set including terminal modules of different types corresponding to a second subset of the different types of I / O signals.

[0085] Example 14 includes the non-transitory computer-readable medium of example 9, wherein the plurality of available secure applications comprises a first set of applications stored in the memory and a second set of applications available for download.

[0086] Example 15 includes the non-transitory computer-readable medium of example 9, wherein the security application of the plurality of available security applications is certified by a security compliance authority before being provided to the user for selection.

[0087] Example 16 includes the non-transitory computer-readable medium of Example 9, wherein the instructions further cause the safety trip device to: in response to a configuration address plug being inserted into a slot of a housing of the safety trip device, provide the plurality of available safety applications to the user for selection and enable the user to specify a value for a configuration setting associated with the first safety application; and in response to a runtime address plug being inserted into the slot of the housing of the safety trip device, prevent the user from changing the configuration setting or switching from the first safety application to the second safety application.

[0088] Example 17 includes a method comprising providing a user with a plurality of available safety applications associated with a process control system for selection, the safety applications being implemented by a safety trip device; a first safety application of the safety applications being associated with a first set of I / O signals, a second safety application of the safety applications being associated with a second set of I / O signals, the first set of I / O signals being different from the second set of I / O signals, the first safety application being implemented based on first preprogrammed instructions stored in a memory of the safety trip device, the second safety application being implemented based on second preprogrammed instructions stored in the memory of the safety trip device; in response to user selection of the first safety application, prompting the user to specify a value for a configuration setting associated with the first safety application, the first preprogrammed instructions defining the configuration setting; and implementing the first safety application based on the value of the configuration setting specified by the user and based on the first preprogrammed instructions.

[0089] Example 18 includes the method of Example 17, wherein the first set of I / O signals corresponds to a first I / O count and the second set of I / O signals corresponds to a second I / O count, the first I / O count being different than the second I / O count.

[0090] Example 19 includes the method of Example 17, wherein the first set of I / O signals corresponds to a first subset of I / O signals of different types, and the second set of I / O signals corresponds to a second subset of I / O signals of different types, the first subset of I / O signals of different types being different from the second subset of I / O signals of different types.

[0091] Example 20 includes the method of Example 19, wherein the first set of I / O signals is transmitted between the processor of the safety trip device and the field device via a first set of terminal modules carried by the housing of the safety trip device, and the first terminal module set includes different types of terminal modules corresponding to the first subset of the different types of I / O signals.

[0092] Example 21 includes the method of Example 20, wherein the terminal modules in the first terminal module set are capable of being selectively replaced within the housing by terminal modules in a second terminal module set, and the second terminal module set includes different types of terminal modules corresponding to a second subset of the different types of I / O signals.

[0093] Example 22 includes the method of Example 17, wherein the plurality of available secure applications comprises a first set of applications stored in the memory and a second set of applications available for download.

[0094] Example 23 includes the method of Example 17, wherein the security application of the plurality of available security applications is certified by a security compliance authority before being provided to the user for selection.

[0095] Example 24 includes the method of Example 17, further comprising: in response to a configuration address plug being inserted into a slot of the housing of the safety trip device, providing the multiple available safety applications to the user for selection and enabling the user to specify a value for a configuration setting associated with the first safety application; and in response to a runtime address plug being inserted into the slot of the housing of the safety trip device, preventing the user from changing the configuration setting or switching from the first safety application to the second safety application.

[0096] Example 25 includes a safety trip device comprising: a housing including a base plate; a terminal block including corresponding slots; the slots being used to receive a first set of terminal modules for communicating with a first set of field devices associated with a first safety application (which is associated with a process control system), the slots being used to receive a second set of terminal modules for communicating with a second set of field devices associated with a second safety application (which is associated with a process control system); and an I / O scanner being used to communicate with the terminal modules in the slots of the terminal block via the base plate, the I / O scanner comprising a memory for storing first preprogrammed instructions defining the operation of the first safety application and for storing second preprogrammed instructions defining the operation of the second safety application.

[0097] Although certain example methods, apparatus, and articles of manufacture have been disclosed herein, the scope of coverage of this patent is not limited thereto. On the contrary, this patent covers all methods, apparatus, and articles of manufacture fairly falling within the scope of the claims of this patent.

[0098] The following claims are hereby incorporated into this Detailed Description, with each claim standing on its own as a separate embodiment of the disclosure.

Claims

1. A device comprising: Configure the controller to: providing a plurality of available safety applications for selection to a user in response to a configuration address plug being inserted into a slot of a housing of a safety trip device associated with a process control system, the safety applications being implemented by the safety trip device, a first safety application being associated with a first set of I / O signals, a second safety application being associated with a second set of I / O signals, the first set of I / O signals being different from the second set of I / O signals, the first safety application being implemented based on first preprogrammed instructions stored in a memory of the safety trip device, and the second safety application being implemented based on second preprogrammed instructions stored in the memory of the safety trip device; and in response to user selection of the first security application, prompting the user to specify a value for a configuration setting associated with the first security application, the first pre-programmed instructions defining the configuration setting; as well as An I / O analyzer is configured to implement the first safety application based on the value of the configuration setting specified by the user and based on the first pre-programmed instructions.

2. The device according to claim 1, wherein The first set of I / O signals corresponds to a first I / O count and the second set of I / O signals corresponds to a second I / O count, the first I / O count being different than the second I / O count.

3. The device according to claim 1, wherein The first set of I / O signals corresponds to a first subset of I / O signals of different types, and the second set of I / O signals corresponds to a second subset of the different types of I / O signals, the first subset of the different types of I / O signals being different from the second subset of the different types of I / O signals.

4. The device according to claim 3, wherein The first I / O signal set is transmitted between the processor of the safety trip device and the field device via a first terminal module set carried by the housing of the safety trip device, and the first terminal module set includes different types of terminal modules corresponding to the first subset of the different types of I / O signals.

5. The device according to claim 4, wherein The terminal modules of the first terminal module set are selectively replaceable within the housing by terminal modules of a second terminal module set, the second terminal module set including terminal modules of different types corresponding to a second subset of the different types of I / O signals.

6. The device according to claim 1, wherein The plurality of available secure applications includes a first set of applications stored in the memory and a second set of applications available for download.

7. The apparatus according to claim 1, wherein A security application among the plurality of available security applications is authenticated by a security compliance authority before being provided to the user for selection.

8. The device according to claim 1, wherein The configuration controller is used to: enabling the user to specify a value for a configuration setting associated with the first safety application in response to the configuration address plug being inserted into the slot of the housing of the safety trip device; and In response to a runtime address plug being inserted into the slot of the housing of the safety trip device, the user is prevented from changing the configuration settings or switching from the first safety application to the second safety application.

9. A non-transitory computer-readable medium comprising instructions that, when executed, cause a safety trip device associated with a process control system to at least: providing a plurality of available safety applications for selection to a user in response to a configuration address plug being inserted into a slot of a housing of the safety trip device, the safety applications being implemented by the safety trip device, a first safety application being associated with a first set of I / O signals, a second safety application being associated with a second set of I / O signals, the first set of I / O signals being different from the second set of I / O signals, the first safety application being implemented based on first pre-programmed instructions stored in a memory of the safety trip device, and the second safety application being implemented based on second pre-programmed instructions stored in the memory of the safety trip device; in response to user selection of the first security application, prompting the user to specify a value for a configuration setting associated with the first security application, the first pre-programmed instructions defining the configuration setting; and The first security application is implemented based on the value of the configuration setting specified by the user and based on the first pre-programmed instructions.

10. The non-transitory computer-readable medium of claim 9, wherein: The first set of I / O signals corresponds to a first I / O count and the second set of I / O signals corresponds to a second I / O count, the first I / O count being different than the second I / O count.

11. The non-transitory computer-readable medium of claim 9, wherein: The first set of I / O signals corresponds to a first subset of I / O signals of different types, and the second set of I / O signals corresponds to a second subset of the different types of I / O signals, the first subset of the different types of I / O signals being different from the second subset of the different types of I / O signals.

12. The non-transitory computer-readable medium of claim 11, wherein: The first I / O signal set is transmitted between the processor of the safety trip device and the field device via a first terminal module set carried by the housing of the safety trip device, and the first terminal module set includes different types of terminal modules corresponding to the first subset of the different types of I / O signals.

13. The non-transitory computer-readable medium of claim 12, wherein: The terminal modules of the first terminal module set are selectively replaceable within the housing by terminal modules of a second terminal module set, the second terminal module set including terminal modules of different types corresponding to a second subset of the different types of I / O signals.

14. The non-transitory computer-readable medium of claim 9, wherein: The plurality of available secure applications includes a first set of applications stored in the memory and a second set of applications available for download.

15. The non-transitory computer-readable medium of claim 9, wherein: A security application among the plurality of available security applications is authenticated by a security compliance authority before being provided to the user for selection.

16. The non-transitory computer-readable medium of claim 9, wherein: The instructions further cause the safety trip device to: enabling the user to specify a value for a configuration setting associated with the first safety application in response to the configuration address plug being inserted into the slot of the housing of the safety trip device; and In response to a runtime address plug being inserted into the slot of the housing of the safety trip device, the user is prevented from changing the configuration settings or switching from the first safety application to the second safety application.

17. A method comprising: providing a plurality of available safety applications for selection to a user in response to a configuration address plug being inserted into a slot of a housing of a safety trip device associated with a process control system, the safety applications being implemented by the safety trip device, a first safety application being associated with a first set of I / O signals, a second safety application being associated with a second set of I / O signals, the first set of I / O signals being different from the second set of I / O signals, the first safety application being implemented based on first preprogrammed instructions stored in a memory of the safety trip device, and the second safety application being implemented based on second preprogrammed instructions stored in the memory of the safety trip device; in response to user selection of the first security application, prompting the user to specify a value for a configuration setting associated with the first security application, the first pre-programmed instructions defining the configuration setting; and The first security application is implemented based on the value of the configuration setting specified by the user and based on the first pre-programmed instructions.

18. The method according to claim 17, wherein The first set of I / O signals corresponds to a first I / O count and the second set of I / O signals corresponds to a second I / O count, the first I / O count being different than the second I / O count.

19. The method according to claim 17, wherein The first set of I / O signals corresponds to a first subset of I / O signals of different types, and the second set of I / O signals corresponds to a second subset of I / O signals of different types, the first subset of I / O signals of different types being different from the second subset of I / O signals of different types.

20. The method according to claim 19, wherein The first I / O signal set is transmitted between the processor of the safety trip device and the field device via a first terminal module set carried by the housing of the safety trip device, and the first terminal module set includes different types of terminal modules corresponding to the first subset of the different types of I / O signals.

21. The method according to claim 20, wherein The terminal modules of the first terminal module set are selectively replaceable within the housing by terminal modules of a second terminal module set, the second terminal module set including terminal modules of different types corresponding to a second subset of the different types of I / O signals.

22. The method according to claim 17, wherein The plurality of available secure applications includes a first set of applications stored in the memory and a second set of applications available for download.

23. The method according to claim 17, wherein A security application among the plurality of available security applications is authenticated by a security compliance authority before being provided to the user for selection.

24. The method of claim 17, further comprising: enabling the user to specify a value for a configuration setting associated with the first safety application in response to the configuration address plug being inserted into the slot of the housing of the safety trip device; and In response to a runtime address plug being inserted into the slot of the housing of the safety trip device, the user is prevented from changing the configuration settings or switching from the first safety application to the second safety application.

Citation Information

Patent Citations

  • Process control system with embedded safety system

    CN101807074A