Safety control device, contactor with the device and method of processing control signals
By using safety control equipment and dual safety verification processing circuits, the problems of electromagnetic interference and emergency stop reliability in contactor control are solved, thus achieving reliable control and safety protection of the contactor.
Patent Information
- Application Number
- CN202011350156.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2019-11-28
- Filing Date
- 2020-11-26
- Publication Date
- 2025-11-04
- Estimated Expiration
- 2040-11-26
AI Technical Summary
Existing technologies struggle to effectively prevent unnecessary commands caused by electromagnetic interference when controlling contactors, and lack dual safety verification to ensure the reliability of the emergency stop function.
Safety control equipment is adopted, including control input terminal, protection circuit, coupler, switch, pulse generator and processing circuit. Electrical isolation is achieved through optocoupler, and dual safety control commands are generated by pulse generator and processing circuit, which are then verified and authorized by logic circuit.
It effectively prevents unnecessary commands caused by electromagnetic interference, ensures the reliable emergency stop function of the contactor, and provides dual safety verification, thereby improving the safety and reliability of the equipment.
Smart Images

Figure CN112865024B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present invention relates to a safety control device, in particular for controlling a contactor. The invention also relates to a method of safely processing a control signal for closing or opening a contactor, and to a contactor having a safety control device. BACKGROUND
[0002] Many devices have one or more contactors for controlling the energization or de-energization of an electrical unit, for example production machines, electric motors, welding devices, etc. Some devices that are dangerous to operate require increased safety for their control, in particular they must have an emergency stop member in order to interrupt the operation in the event of a hazard. In order to strengthen the safety of goods and persons, the command to start the operation of an electric motor can be verified in order to avoid any unnecessary commands, for example caused by electromagnetic interference. In this case, when the command is not valid, the device must enter a safety state, which usually corresponds to the device being stopped.
[0003] Document EP 1 538 651 A2 is known and relates to an emergency stop circuit having two lines operating in parallel, each line having a contact, the actuation of which is controlled by a central unit. When an emergency stop is requested, the power supply for the command to the contact is disconnected.
[0004] Patent application US 2004 / 0199 837 A1 describes a method and a device for safely transmitting information between an input and an output unit of a safety system.
[0005] Patent application US 2011 / 0169345 A1 describes a control system that prevents the start of a load when a command for the load or the power supply for the load presents an anomaly. SUMMARY
[0006] The present invention relates to a safety control device for processing a control signal and generating a first safety control command, the safety control device comprising:
[0007] a control input having at least a first connection point and a second connection point, the control input being designed to receive a control signal,
[0008] a first protection circuit,
[0009] a first coupler having:
[0010] a first transmitter circuit connected in series with the first protection circuit, the assembly formed by the first transmitter circuit and the first protection circuit being connected between the first connection point and the second connection point, the first transmitter circuit being designed to emit a second signal when the control signal is present on the control input, and
[0011] a first receiver circuit designed to receive the second signal and to provide a third signal formed of at least one pulse,
[0012] a first switch connected in parallel across the first transmitter circuit,
[0013] a pulse generator connected to the first switch and designed to cyclically control the opening and closing of the first switch, and
[0014] a first processing circuit connected to the first receiver circuit to receive the third signal, said first processing circuit being designed to process the third signal and to provide a first safety control command, said first safety control command being able to take at least two of the following states:
[0015] a first start safety control command, or
[0016] a first stop safety control command.
[0017] Advantageously, the first transmitter circuit and the first receiver circuit are electrically isolated from each other.
[0018] Advantageously, the first coupler has at least one optical coupler, the first transmitter circuit has a transmitting diode, the first receiver circuit has a phototransistor, the transmitting diode emits radiation through an electrically insulating wall transparent to radiation, the radiation forming a medium for transmitting the second signal to the phototransistor.
[0019] Advantageously, the pulse generator generates pulses having a predefined duty cycle less than or equal to 50%.
[0020] Preferably, the pulse generator generates pulses at a frequency between 100 Hz and 10 kHz.
[0021] Advantageously, the first protection circuit has a current limiting circuit for limiting the current flowing through said protection circuit.
[0022] Advantageously, the first protection circuit has a current threshold detection circuit connected to the current limiting circuit, so as to limit the current flowing through said protection circuit to a predefined maximum intensity when the amplitude of the control signal is greater than a predefined maximum voltage threshold.
[0023] In one particular embodiment, the voltage threshold detection circuit is connected in series with the first protection circuit and the first transmitter circuit, so as to limit the current flowing through said transmitter circuit to a predefined minimum intensity when the amplitude of the control signal is less than a predefined minimum voltage threshold.
[0024] In one particular embodiment, the first switch is connected in series with the first protection circuit and the first transmitter circuit.
[0025] According to one variant, the safety control device also has:
[0026] a verification input with a third connection point, the verification input being designed to receive a verification signal,
[0027] a second protection circuit,
[0028] a second coupler having:
[0029] a second transmitter circuit connected in series with the second protection circuit, the assembly formed by the second transmitter circuit and the second protection circuit being connected between a third connection point and a second connection point of the safety control device, the second transmitter circuit being designed to emit a fourth signal when the verification signal is present on the verification input, and
[0030] a second receiver circuit designed to receive the fourth signal and to provide a fifth signal,
[0031] a second switch first connected in parallel across the second transmitter circuit and second connected to the pulse generator so that the pulse generator cyclically controls the opening and closing of the second switch,
[0032] a second processing circuit connected to the second receiver circuit in order to receive the fifth signal, the second processing circuit being designed to process the fifth signal and to provide a second safety control command, the second safety control command being able to take at least two of the following states:
[0033] a second start safety control command, and
[0034] a second stop safety control command
[0035] a logic circuit having:
[0036] a first binary input connected to the first processing circuit in order to receive the first safety control command,
[0037] a second binary input connected to the second processing circuit in order to receive the second safety control command, and
[0038] a second binary output for providing a third safety control command.
[0039] Advantageously, the third safety control command takes at least two of the following states:
[0040] a third start safety control command when the first safety control command provided by the safety control device is a first start safety control command and when the second safety control command is a second start safety control command, or
[0041] The third stop safety control command is adopted when the first safety control command provided by the safety control device is a first stop safety control command or when the second safety control command is a second stop safety control command.
[0042] The application also relates to a contactor having:
[0043] at least one electrical contact connected to the upstream current circuit and to the downstream current circuit, said electrical contact being designed to allow the current flow between the upstream current circuit and the downstream current circuit to be admitted or blocked,
[0044] an actuator designed to actuate the at least one electrical contact,
[0045] a safety control device as described above, connected to the actuator in order to provide the actuator with a first safety control command, thereby controlling the actuation of the at least one electrical contact,
[0046] a first connection terminal connected to a first connection point of the safety control device, and
[0047] a second connection terminal connected to a second connection point of the safety control device,
[0048] the contactor being such that the safety control device controls the actuator:
[0049] in order to perform the closing of the at least one electrical contact when the first safety control command is a first start safety control command, or
[0050] in order to perform the opening of the at least one electrical contact when the first safety control command is a first stop safety control command.
[0051] Advantageously, the contactor also has a third connection terminal connected to a third connection point of the safety control device. The safety control device is connected to the actuator via a second binary output in order to provide the actuator with a third safety control command, said third safety control command being able to adopt at least the following two states:
[0052] a third start safety control command, or
[0053] a third stop safety control command.
[0054] The safety control device controls the actuator by providing it with a third safety control command:
[0055] in order to perform the closing of the at least one electrical contact when the third safety control command is a third start safety control command, or
[0056] in order to perform the opening of the at least one electrical contact when the third safety control command is a third stop safety control command.
[0057] The application also relates to a method for securely processing a third signal formed by at least one pulse provided by at least a first receiver circuit of a safety control device as described above, said method comprising iteratively counting the number of pulses provided by the first receiver circuit during a time interval of a predefined duration.
[0058] Advantageously, the first counter is incremented when the number of pulses counted during the time interval is between a predefined minimum number of pulses and a predefined maximum number of pulses.
[0059] Preferably, a first start safety control command is generated when the first counter is equal to or greater than a predefined validation threshold.
[0060] Preferably, the second counter is incremented when the number of pulses counted during the time interval is not between the minimum number of pulses and the maximum number of pulses.
[0061] Preferably, a first stop safety control command is generated when the second counter is equal to or greater than a predefined invalidation threshold. BRIEF DESCRIPTION OF DRAWINGS
[0062] Other advantages and features will become more apparent from the following description and specific embodiments of the application, given by way of non-limiting example and shown in the attached drawings, in which:
[0063] Figure 1 A safety control device according to the application is shown in block diagram form;
[0064] Figure 2a and Figure 2b Different embodiments of a protection circuit forming part of a safety control device are shown;
[0065] Figure 2c A combination of a voltage threshold detection circuit and a first coupler circuit is shown;
[0066] Figure 2d A variation curve of the current flowing in the protection circuit is shown;
[0067] Figure 2e A variation curve of the current flowing in the first transmitter circuit is shown;
[0068] Figure 3 A connection variant of a first switch in a safety control device is shown in block diagram form;
[0069] Figure 4 A safety control device with a validation input is shown in block diagram form;
[0070] Figure 5aA contactor with a safety control device is shown in block diagram form;
[0071] Figure 5b A contactor with a safety control device comprising a verification input is shown;
[0072] Figures 6a to 6d is a timing diagram of signals received by a processing circuit forming part of a safety control device;
[0073] Figure 7a is a flowchart of a method for safety processing signals executed by a processing circuit; and
[0074] Figure 7b is a flowchart of a preferred variant of the safety processing method executed by a processing circuit. DETAILED DESCRIPTION
[0075] Figure 1 A safety control device 1 is shown in block diagram form, which is intended to process a control signal Sig1 and to generate a first safety control command. The safety control device 1 comprises at least a control input E, a first protection circuit 10, a first coupler 20, a first switch 30, a pulse generator 40, a first processing circuit 50, and a first binary output S1.
[0076] The control input E has at least a first connection point E1 and a second connection point E2. Between the first point E1 and the second point E2 is applied the control signal Sig1. The control signal Sig1 is preferably a continuous voltage level or voltage level whose amplitude Vsig1 is between 1 volt and 30 volts, preferably whose duration is between 5 milliseconds and 100 milliseconds.
[0077] The first protection circuit 10 is designed to clamp the control signal Sig1 when the control signal Sig1 has an abnormally high amplitude Vsig1 and / or to limit the current i flowing in the safety control device 1 when the control signal Sig1 is applied. A first embodiment of the first protection circuit 10 is shown in Figure 2a and has a current limiter 11, for example constituted by at least one resistor R. The size of the resistor R is preferably such that the current i is limited to a predefined maximum intensity Imax between 1 milliampere and 100 milliampere.
[0078] As a variant, the first protection circuit 10 has a current limiter 11 connected to a current threshold detection circuit 12, as shown in Figure 2b . Figure 2dThe variation of the current i flowing in the first protection circuit 10 as a function of the amplitude Vsigl of the control signal Sigl is shown. When the intensity of the current i is less than the maximum current intensity IMax, the current threshold detection circuit 12 does not act and the current i is set according to Ohm's law by the ratio between the amplitude Vsigl of the control signal Sigl and the value of the resistance R. For example, for an amplitude Vsigl of the control signal Sigl equal to 24 volts and a resistance R equal to 2000 ohms, the amplitude of the current i will be equal to 12 mA. When the amplitude Vsigl of the control signal Sigl exceeds the predefined maximum voltage threshold Umax, the current threshold detection circuit 12 acts on the current limiter 11 so as to increase the value of the resistance R, thus keeping the intensity of the current i at the predefined maximum current intensity IMax. Therefore, in the case of a constant current i, the power dissipated in the current limiter 11 and the heat generated thereby vary only according to a linear law as a function of the amplitude Vsigl of the control signal Sigl.
[0079] Optionally, as shown in Figure 2c the voltage threshold detection circuit 13 is connected in series with the first protection circuit 10 and the first coupler 20. In this configuration, the voltage threshold detection circuit 13 detects a predefined minimum voltage threshold Umin. As long as the amplitude Vsigl of the control signal Sigl is less than said minimum voltage threshold Umin, the voltage threshold detection circuit 13 limits the current i flowing in the first transmitter circuit 21 of the first coupler 20 to a predefined minimum intensity Imin. When the amplitude Vsigl of the control signal Sigl is greater than the minimum voltage threshold Umin, the voltage threshold detection circuit 13 does not act and the current i is limited only by the current limiter 11. Figure 2e The curve representing the variation of the current i flowing in the first protection circuit 10 as a function of the amplitude Vsigl of the control signal Sigl in this operating mode is shown in
[0080] Optionally, for example in order to comply with the recommendations of the IEC 60947-1 standard, annex S, regarding digital inputs of low voltage electrical apparatus, a bypass resistor Rd is connected in parallel between the threshold detection circuit 13 and the first coupler 20, as shown in Figure 2c so that the current i is always present even when the first switch 30 is open and when the amplitude Vsigl of the control signal Sigl is less than the minimum voltage Umin. The bypass resistor Rd can also be connected in parallel across the first switch 30.
[0081] In a preferred embodiment, the current limiter 11 limits the amplitude of the current i to a predefined maximum current intensity Imax between 8 milliampere and 20 milliampere, to a predefined minimum current intensity Imin between 0 milliampere and 8 milliampere, to a predefined maximum voltage threshold UMax between 12 volts and 30 volts, to a predefined minimum voltage threshold Umin between 0 volts and 12 volts.
[0082] As shown in Figure 1 The first coupler 20 has a first transmitter circuit 21 connected in series with the first protection circuit 10, the assembly formed by the first transmitter circuit 21 and the first protection circuit 10 being connected between a first connection point El and a second connection point E2. The first transmitter circuit 21 is designed to emit a second signal Sig2 when a control signal Sigl is present on the control input E and when a current i is flowing in said first transmitter circuit 21. The first coupler 20 also has a first receiver circuit 22 designed to receive the second signal Sig2 and to provide a third signal Sig3. Said third signal Sig3 is formed by at least one pulse, as will be described later. The first transmitter circuit 21 and the first receiver circuit 22 of said first coupler 20 are electrically isolated from each other.
[0083] Preferably, the first coupler 20 has at least one optocoupler: the first transmitter circuit 21 has an emitting diode D, the first receiver circuit 22 has a phototransistor Tr, the emitting diode D emits radiation towards the phototransistor Tr through a wall Sc transparent to radiation, said wall being arranged between the emitting diode D and the phototransistor Tr, said radiation forming a medium for transmitting the second signal Sig2. The phototransistor Tr provides the third signal Sig3 in the same way as the second signal Sig2. The wall Sc also has electrically insulating properties, that is to say, it does not conduct current, thereby providing electrical isolation between the first transmitter circuit 21 and the first receiver circuit 22.
[0084] The first switch 30 is connected in parallel across the first transmitter circuit 21 so as to short-circuit the first transmitter circuit 21 when said first switch 30 is closed. Thus, the first transmitter circuit 21 is only able to emit when the first switch 30 is in an open state. The first switch 30 is preferably a bipolar transistor or a field effect transistor. The advantage of this configuration is that the constant flow of the current i is guaranteed whatever the open or closed state of the first switch 30, provided that the control signal Sigl is present on the control input E. The first switch 30 is controlled by the pulse generator 40.
[0085] The pulse generator 40 is connected to the first switch 30 and generates pulses to cyclically control the opening and closing of the first switch 30. Preferably, the pulses control the closing of the first switch 30, the first switch 30 being open during the time interval between two successive pulses. The control signal Sigl is thus modulated by the pulses delivered by the pulse generator 40.
[0086] The pulse generator 40 generates pulses, preferably rectangular, having a predefined duty cycle less than or equal to 50%, the frequency preferably being between 100 Hz and 10 kHz. The pulse generator 40 is preferably a free oscillator, not synchronized with any other signal present in the safety control device 1.
[0087] In the presence of the control signal Sigl, when the first switch 30 is open, the emission diode D of the first emitter circuit 21 emits radiation towards the phototransistor Tr of the first receiver circuit 22. Said phototransistor Tr then provides a pulse forming the third signal Sig3, as Figure 6a When the first switch 30 is closed, the first emitter circuit 21 no longer emits radiation towards the phototransistor Tr and the third signal Sig3 becomes zero. Thus, when the control signal Sigl is present and the pulse generator 40 generates a pulse, the third signal Sig3 contains at least one pulse P.
[0088] The first processing circuit 50 is connected to the first receiver circuit 22 to receive the third signal Sig3. Said first processing circuit 50 is designed to perform the safety processing method 500 described later, to process the third signal Sig3 and provide a first safety control command Sig4. Said first safety control command Sig4 can take at least two states: a first start safety control command Sig4 ON, or a first stop safety control command Sig4 OFF.
[0089] The first start safety control command Sig4 ON corresponds to a start safety command, the first stop safety control command Sig4 OFF corresponds to a stop safety command, which is particularly suitable for a safety emergency stop command.
[0090] According to a connection variant of the first switch 30, said first switch 30 is connected in series with the first protection circuit 10 and the first emitter circuit 21, as Figure 3 shown. In this case, when the control signal Sigl is present on the input E and when the first switch 30 is closed, the third signal Sig3 is formed by a pulse P. The processing performed by the first processing circuit 50 on the third signal Sig3 is unchanged.
[0091] In safety installations, it is often necessary to implement a double safety command. This double command comprises a first safety command, the role of which is to control activation, and a second safety command, the role of which is to verify or authorize, the second safety command usually corresponding to an emergency stop command. To meet this requirement, the application also relates to a safety control device 1 as shown in Figure 4 the safety control device 1 as described above, and also having: a verification input V with a third connection point E3, the verification input V being designed to receive a verification signal Sig10 applied between the second connection point E2 and the third connection point E3; a second protection circuit 110; a second coupler 120 with a second transmitter circuit 121 and a second receiver circuit 122 connected in series with the second protection circuit 110, the assembly formed by the second transmitter circuit 121 and the second protection circuit 110 being connected between the third connection point E3 and the second connection point E2, the second transmitter circuit 121 being designed to emit a fourth signal Sig20 when the verification signal Sig10 is present on the verification input V, the second receiver circuit 122 being designed to receive the fourth signal Sig20 and to provide a fifth signal Sig30; a second switch 130, firstly connected in parallel across the second transmitter circuit 121 so as to short-circuit the second transmitter circuit 121 when the latter is closed, and secondly connected to the pulse generator 40 so that the pulse generator 40 cyclically controls the opening and closing of the second switch 130; a second processing circuit 150 connected to the second receiver circuit 122 to receive the fifth signal Sig30, the second processing circuit 150 being designed to process the fifth signal Sig30 and to provide a second safety control command Sig40 capable of adopting at least two of the following states: a second activation safety control command Sig40_ON and a second stop safety control command Sig40_OFF; and a logic circuit 160 having a first binary input L1 connected to the first processing circuit 50 so as to receive the first safety control command Sig4, a second binary input L2 connected to the second processing circuit 150 so as to receive the second safety control command Sig40, and a second binary output S2 for providing a third safety control command Sig50.
[0092] The third safety control command Sig50 can take at least two states: a third start safety control command Sig50_ON when the first safety control command Sig4 provided by the safety control device 1 is the first start safety control command Sig4_ON and when the second safety control command Sig40 is the second start safety control command Sig40_ON, and a third stop safety control command Sig50_OFF otherwise when the first safety control command Sig4 provided by the safety control device 1 is the first stop safety control command Sig4_OFF or when the second safety control command Sig40 is the second stop safety control command Sig40_OFF.
[0093] The third start safety control command Sig50_ON is given when the first processing circuit 50 and the second processing circuit 150 provide the first start safety control command Sig4_ON and the second safety control command Sig40, respectively. The third stop safety control command Sig50_OFF is provided when the first processing circuit 50 provides the first stop safety control command Sig4_OFF or when the second processing circuit 150 provides the second stop safety control command Sig40_OFF.
[0094] The second protection circuit 110 is similar to the first protection circuit 10, the second coupler 120 is similar to the first coupler 20, the second switch 130 is similar to the first switch 30, and the second processing circuit 150 is similar to the first processing circuit 50.
[0095] The application also relates to a contactor 100 shown in a block diagram in Figure 5a The contactor 100 has at least one electrical contact 310 connected to at least one upstream current line 320 and to one downstream current line 330, the electrical contact 310 being designed to allow the current flow between the upstream current line 320 and the downstream current line 330 to be admitted or blocked, an actuator 2 designed to actuate the at least one electrical contact 310, a safety control device 1 as described above, a first connection terminal Cl connected to the first connection point El of the safety control device 1, and a second connection terminal C2 connected to the second connection point E2 of the safety control device 1, between which first and second connection terminals Cl and C2 the control signal Sigl is applied. Thus, the safety control device 1 receives the control signal Sigl at its safety control input E.
[0096] The safety control device is connected to the actuator 2 via a first binary output S1 in order to provide a first safety control command Sig4 to said actuator 2, so as to control the actuation of the at least one electrical contact 310 when a control signal Sig1 is received at its safety control input E. The safety control device 1 controls the actuator 2 so as to perform the closing of the at least one electrical contact 310 when the first safety control command Sig4 is a first start safety control command Sig4_ON, or so as to perform the opening of the at least one electrical contact 310 when the first safety control command Sig4 is a first stop safety control command Sig4_OFF.
[0097] According to a preferred embodiment, in Figure 5b The contactor 100, shown in block diagram form in
[0098] This contactor 100 has two safety control inputs: the control signal Sig1 applied between the first and second connection terminals (C1 and C2 respectively), received at the control input E of the safety control device 1, corresponds to a start command. The verification signal Sig10 applied between the second connection terminal C2 and the third connection terminal C3, received at the verification input V of the safety control device 1, corresponds to a verification or authorization of the command transmitted by the control signal Sig1. The absence of said verification signal Sig10 corresponds to an emergency stop request. The verification signal Sig10 is preferably a continuous voltage interval or voltage level with an amplitude of between 1 and 30 volts.
[0099] The safety control device 1 is connected to the actuator via a second binary output S2 in order to provide a third safety control command Sig50 to the actuator 2, said third safety control command Sig50 being able to take the following two states, as mentioned above: a third start safety control command Sig50_ON, or a third stop safety control command Sig50_OFF.
[0100] The contactor 100 is designed so that the safety control device 1 provides to the actuator 2 a third start safety control command Sig50_ON in order to control the actuator 2 so that the closing of the at least one electrical contact 310 is performed when the first safety control command Sig4 is a first start safety control command Sig4_ON and when the second safety control command Sig40 is a second start safety control command Sig40_ON; or the safety control device 1 provides to the actuator 2 a third stop safety control command Sig50_OFF in order to control the actuator 2 so that the opening of the at least one electrical contact 310 is performed when the first safety control command Sig4 is a first stop safety control command Sig4_OFF or when the second safety control command Sig40 is a second stop safety control command Sig40_OFF.
[0101] Thus, when the first processing circuit 50 has verified the compliance of the control signal Sig1 and the second processing circuit 150 has verified the compliance of the verification signal Sig10, the control signal Sig1 is validated. If the control signal Sig1 or the verification signal Sig10 is not compliant, the contactor 100 will be put in a safety state, corresponding to the opening of the at least one electrical contact 310, to protect the people and prevent or limit the damage to the hardware.
[0102] Other operating modes of the contactor 100 are also possible, in particular the following mode: the control signal Sig1 is a limited duration pulsed signal and the role of the verification signal Sig10 is to authorize / validate said command to close the actuator 2. The verification signal Sig10 is applied first or simultaneously with the control signal Sig1, then the actuator 2 is actuated and the at least one electrical contact 310 is closed. The actuator 2 remains actuated even if the control signal Sig1 has disappeared. On the contrary, as soon as the verification signal Sig10 disappears, the actuator 2 is deactivated and the at least one electrical contact 310 is opened. This operation can easily be implemented by the logic circuit 160.
[0103] The contactor 100 can have a single electrical contact 310 connected between an upstream current line 320 and a downstream current line 330, or two electrical contacts 310 connected between two upstream current lines 320 and two downstream current lines 330, the two electrical contacts 310 being isolated from each other, the upstream current lines 320 and the downstream current lines 330 also being isolated from each other, as shown in Figure 5a and Figure 5b The contactor 100 can also be designed to operate on a three-phase network and have three electrical contacts 310, three upstream current lines 320 and three downstream current lines 330.
[0104] The first processing circuit 50 executes a safety processing method 500 in order to process the third signal Sig3 and to generate a first safety control command Sig4. The second processing circuit 150 also similarly executes the safety processing method 500 in order to process the fifth signal Sig30 and to generate a second safety control command Sig40. Thus, only the safety processing method 500 executed by the first processing circuit 50 is described below.
[0105] The safety processing method 500 comprises iteratively counting the number of pulses P forming the third signal Sig3, said pulses P being provided by the first receiver circuit 22 during a time interval of a predefined duration T, as illustrated in the following figure. Figure 6a
[0106] Figure 7a A first embodiment of the safety processing method 500 is illustrated. In an initialization step 510, a first stop safety control command Sig4 OFF is issued in order to initialize the first safety control command Sig4. A first counter Ql and a second counter Q2 are also initialized. Next, in a counting step 520, the method counts the number Q of pulses P received within the predefined time interval T. At the end of the counting step 520, there is a step 530 comparing the counted number Q of pulses with a predefined minimum number of pulses Qmin and a predefined maximum number of pulses Qmax. When the counted number Q of pulses is outside the interval between the minimum number of pulses Qmin and the maximum number of pulses Qmax, the method continues with a step 540, incrementing the second counter Q2. Then, in a step 550, the second counter Q2 is compared with a predefined invalidation threshold Qinv. When the second counter Q2 is equal to or greater than the invalidation threshold Qinv, the method considers that the counted number Q of pulses is not compliant and the method returns to the initialization step 510, corresponding to a safety state, and in particular, the first stop safety control command Sig4 OFF is generated. Conversely, when the counted number Q of pulses is within the interval between the minimum number of pulses Qmin and the maximum number of pulses Qmax, the method continues with a step 560, incrementing the first counter Ql. Next, in a step 570, the first counter Ql is compared with a predefined validation threshold Qval. When the first counter Ql is less than said validation threshold Qval, then the method returns to the counting step 520 to perform an additional iteration. When the first counter Ql is greater than or equal to the validation threshold Qval, the method continues with a step 580, comprising generating a first start safety control command Sig4 ON and reinitializing the first counter Ql and the second counter Q2. The method then returns to the counting step 520 to perform a new iteration.
[0107] Figure 7b A second embodiment of the safety processing method 500 is shown. The initialization step 510, the counting step 520, the comparison step 530, the step of incrementing the second counter Q2 in step 540, the step of comparison with the invalid threshold in step 550 and the step of incrementing the first counter Q1 in step 560 are identical. Instead, after said step 560 of incrementing the first counter Q1, a second counting step 561 is performed, followed by a step 562 of comparing the counted number of pulses Q with the minimum number of pulses Qmin and the maximum number of pulses Qmax. When the counted number of pulses is less than the minimum number of pulses Qmin or greater than the maximum number of pulses Qmax, the method proceeds to step 563, incrementing the second counter Q2, and then comparing said second counter Q2 with the invalid threshold Qinv in step 564. When the second counter Q2 is equal to or greater than the invalid threshold Qinv, the method considers that the counted number of pulses Q is not compliant and the method returns to the initialization step 510, corresponding to the safety state. When the second counter Q2 is less than the invalid threshold Qinv, the method returns to the second counting step 561. When the counted number of pulses Q is between the minimum number of pulses Qmin and the maximum number of pulses Qmax in step 562, the method proceeds to step 565, incrementing the first counter Q1, and to a new loop for monitoring the number of pulses P received during the time interval T in the comparison step 566, the incrementing step 567 and the comparison step 568. In particular, in the comparison step 568, when the second counter Q2 is less than the invalid threshold Qinv, the method returns to the second counting step 561. The second embodiment of the safety processing method 500 thus described requires that the number of pulses P counted in two consecutive time intervals T be within the interval between the minimum number of pulses Qmin and the maximum number of pulses Qmax. The second embodiment is therefore more precise than the first embodiment of the method shown and is more suitable for implementation in industrial environments subject to significant electromagnetic interference. Figure 7a Other method variants for counting the number of pulses Q and decision criteria for generating the first safety control command can be constructed on the basis of the method described above in order to adapt the method to specific environments.
[0108] Preferably, the minimum number of pulses Qmin is between 2 and 5, the maximum number of pulses Qmax is between 3 and 50, the validation threshold Qval is between 2 and 10, the invalid threshold Qinv is between 2 and 5, the duration of the time interval T is between 1 millisecond and 10 milliseconds. Figure 6bAn example of the counting of the number Q of pulses P forming the third signal Sig3 and the evolution of the first counter Q1 and of the second counter Q2 over time is illustrated in the form of a timing diagram. In this example, Qmin = 2, Qmax = 3, Qval = 3, Qinv = 3. At the initial time, the first counter Q1 and the second counter Q2 are initialized to zero. In the first time interval T corresponding to the first iteration STEP1, two pulses P are counted, thus Q = 2, and the first counter Q1 is incremented, Q1 = 1, because Q is between Qmin and Qmax. In the next period T corresponding to iteration STEP2, three pulses P are counted, thus the first counter Q1 is incremented again, Q1 = 2. In the next period T corresponding to iteration STEP3, a single pulse P is counted, thus Q = 1. The first counter Q1 is not incremented because the number of counted pulses is outside the interval between the minimum number of pulses Qmin and the maximum number of pulses Qmax, as verified in the comparison step 530. On the contrary, the second counter Q2 is incremented. In the next period T corresponding to iteration STEP4, four pulses P are counted, and the first counter Q1 is not incremented, while the second counter Q2 is incremented because the number of counted pulses Q is outside the interval between the minimum number of pulses Qmin and the maximum number of pulses Qmax. In the next period T corresponding to iteration STEP5, two pulses are counted, and the first counter Q1 is incremented and takes the value 2. In the next period T corresponding to iteration STEP6, the first counter Q1 is incremented because two pulses P are counted in the period T. The first counter Q1 reaches the value 3 corresponding to the validation threshold Qval chosen in this example, thus the command is safe, the first start safe control command Sig4_ON is issued, the first counter Q1 and the second counter Q2 are reinitialized to zero, and the method returns to the counting step 520 to perform a new iteration.
[0109] Figure 6cA second example of the counting of the number Q of pulses P forming the third signal Sig3 and the evolution over time of the first counter Q1 and of the second counter Q2 is shown. At the initial time, the first counter Q1 and the second counter Q2 are both zero. In the first time interval T corresponding to the first iteration STEP1, two pulses P are counted, so the first counter Q1 is incremented. In the next period T corresponding to the iteration STEP2, a single pulse P is counted. The first counter Q1 is not incremented, but the second counter Q2 is incremented because the number Q of counted pulses is outside the interval between the minimum number of pulses Qmin and the maximum number of pulses Qmax. This applies as well to the next period T corresponding to the iteration STEP3, because a single pulse P is counted, the second counter Q2 is equal to 2. In the next period T corresponding to the iteration STEP4, two pulses P are counted, the first counter Q1 is incremented, so Q1 = 2. In the next period T corresponding to the iteration STEP5, no pulse P, and the second counter Q2 is incremented and reaches a value 3 equal to the invalid threshold Qinv chosen in this example. Therefore, the safety command is invalid and the method returns to the initialization step 510 corresponding to the safe state. The first stop safety control command Sig4 OFF is generated, the first counter Q1 and the second counter Q2 are reinitialized to zero and the method continues with the counting step 520 to perform a new iteration.
[0110] Figure 6d A third example is shown in which the number Q of pulses counted in 3 iterations STEP2, STEP3 and STEP4 is equal to 0. Then, at the end of the iteration STEP4, the second counter Q2 reaches the value 3, the first stop safety control command Sig4 OFF is generated. This example illustrates the operation of the safety emergency stop command.
[0111] Therefore, the first counter Q1 counts the number of iterations STEP1, STEP2, STEP3, etc. of the number Q of pulses P within the interval of the expected value, and the second counter Q2 counts the number of iterations STEP1, STEP2, STEP3, etc. of the number Q of pulses P outside the interval of the expected value. The response time of this method makes it possible to verify the safety control command within a period greater than or equal to (Qval x T) after the appearance of the third signal Sig3. For example, when Qval = 3 and T = 3 ms, the response time is greater than or equal to 9 ms, whether for the first start safety control command or for the first stop safety control command.
[0112] The safety control device 1 and the safety processing method on which the present invention is based facilitate monitoring and verification of the start or stop command of the contactor, thus firstly avoiding any unwanted command initialized for example by electromagnetic disturbances, and secondly reliably executing an emergency stop request. The first and second couplings also provide electrical isolation between the input and the output. Finally, the implementation of at least one first switch 30 in combination with the pulse generator 40 allows the formation of a circuit of the safety control device 1 or a self-control of the safety control device 1. Such safety control circuits and the safety processing method they comprise can also be implemented in order to remotely control a circuit breaker or any other safety element. They are particularly suitable for installations requiring SIL1 certification.
Claims
1. A safety control device (1) for processing a control signal (Sigl) and generating a first safety control command (Sig4), the safety control device (1) being characterized in that it comprises: a control input (E) having at least a first connection point (El) and a second connection point (E2), the control input (E) being designed to receive a control signal (Sigl), a first protection circuit (10), a first coupler (20) having: a first transmitter circuit (21) connected in series with the first protection circuit (10), the assembly formed by the first transmitter circuit (21) and the first protection circuit (10) being connected between the first connection point (El) and the second connection point (E2), the first transmitter circuit (21) being designed to emit a second signal (Sig2) when the control signal (Sigl) is present on the control input (E), and a first receiver circuit (22) designed to receive the second signal (Sig2) and to provide a third signal (Sig3) formed by at least one pulse (P), a first switch (30) connected in parallel across the first transmitter circuit (21), a pulse generator (40) connected to the first switch (30) and designed to cyclically control the opening and closing of the first switch (30), and a first processing circuit (50) connected to the first receiver circuit (22) so as to receive the third signal (Sig3), the first processing circuit (50) being designed to process the third signal (Sig3) and to provide a first safety control command (Sig4), the first safety control command (Sig4) being able to take at least two of the following states: a first start safety control command (Sig4_ON), or a first stop safety control command (Sig4_OFF).
2. The safety control device (1) according to claim 1, characterized in that The first transmitter circuit (21) and the first receiver circuit (22) are electrically isolated from each other.
3. The safety control device (1) according to claim 1 or 2, characterized in that The first coupler (20) has at least one optocoupler, the first transmitter circuit (21) has an emission diode (D), the first receiver circuit (22) has a phototransistor (Tr), the emission diode (D) emits radiation through an electrically insulating wall (Sc) transparent to the radiation, the radiation forming a medium for transmitting the second signal (Sig2) to the phototransistor (Tr).
4. The safety control device (1) according to claim 1 or 2, characterized in that The pulse generator (40) generates pulses having a predefined duty cycle less than or equal to 50%.
5. The safety control device (1) according to claim 1 or 2, characterized in that The pulse generator (40) generates pulses having a frequency between 100 Hz and 10 kHz.
6. The safety control device (1) according to claim 1 or 2, characterized in that The first protection circuit (10) has a current limiting circuit (11) for limiting the current (i) flowing through the protection circuit (10).
7. The safety control device (1) according to claim 6, characterized in that The first protection circuit (10) has a current threshold detection circuit (12) connected to the current limiting circuit (11) so as to limit the current (i) flowing through the protection circuit (10) to a predefined maximum intensity (Imax) when the amplitude (Vsigl) of the control signal (Sigl) is greater than a predefined maximum voltage threshold (Umax).
8. The safety control device (1) according to claim 7, characterized in that - a voltage threshold detection circuit (13) connected in series with the first protection circuit (10) and the first emitter circuit (21) so as to limit the current (i) flowing through said emitter circuit (21) to a predefined minimum intensity (Imin) when the amplitude (Vsigl) of the control signal (Sigl) is less than a predefined minimum voltage threshold (Umin).
9. The safety control device (1) according to claim 1 or 2, characterized in that - a first switch (30) connected in series with the first protection circuit (10) and the first emitter circuit (21).
10. The safety control device (1) according to claim 1 or 2, characterized in that It also comprises: - a verification input (V) having a third connection point (E3), said verification input (V) being designed to receive a verification signal (SiglO), - a second protection circuit (110), - a second coupler (120) having: - a second emitter circuit (121) connected in series with the second protection circuit (110), the assembly formed by the second emitter circuit (121) and the second protection circuit (110) being connected between a third connection point (E3) and a second connection point (E2) of the safety control device (1), said second emitter circuit (121) being designed to emit a fourth signal (Sig20) when the verification signal (SiglO) is present on the verification input (V), and - a second receiver circuit (122) designed to receive the fourth signal (Sig20) and to provide a fifth signal (Sig30), - a second switch (130) connected first in parallel across the second emitter circuit (121) and secondly to the pulse generator (40) so that said pulse generator (40) cyclically controls the opening and closing of said second switch (130), - a second processing circuit (150) connected to the second receiver circuit (122) so as to receive the fifth signal (Sig30), said second processing circuit (150) being designed to process the fifth signal (Sig30) and to provide a second safety control command (Sig40), said second safety control command (Sig40) being able to take at least two of the following states: - a second start safety control command (Sig40_ON), and - a second stop safety control command (Sig40_OFF), - a logic circuit (160) having: - a first binary input (LI) connected to the first processing circuit (50) so as to receive the first safety control command (Sig4), - a second binary input (L2) connected to the second processing circuit (150) so as to receive the second safety control command (Sig40), and - a second binary output (S2) for providing a third safety control command (Sig50).
11. The safety control device (1) according to claim 10, characterized in that said third safety control command (Sig50) taking at least two of the following states: - a third start safety control command (Sig50_ON) when the first safety control command (Sig4) provided by the safety control device (1) is a first start safety control command (Sig4_ON) and when the second safety control command (Sig40) is a second start safety control command (Sig40_ON), or - a third stop safety control command (Sig50_OFF) when the first safety control command (Sig4) provided by the safety control device (1) is a first stop safety control command (Sig4_OFF) and when the second safety control command (Sig40) is a second stop safety control command (Sig40_OFF). The third stop safety control command (Sig50 OFF) is used when the first safety control command (Sig4) provided by the safety control device (1) is a first stop safety control command (Sig4 OFF) or when the second safety control command (Sig40) is a second stop safety control command (Sig40 OFF).
12. A contactor (100) having: at least one electrical contact (310) connected to an upstream current line (320) and to a downstream current line (330), said electrical contact (310) being designed to allow the current flow between the upstream current line (320) and the downstream current line (330) to be admitted or blocked, an actuator (2) designed to actuate the at least one electrical contact (310), a safety control device (1) according to any one of the preceding claims, connected to the actuator (2) in order to provide the actuator (2) with a first safety control command (Sig4) so as to control the actuation of the at least one electrical contact (310), a first connection terminal (C1) connected to a first connection point (E1) of the safety control device (1), and a second connection terminal (C2) connected to a second connection point (E2) of the safety control device (1), said contactor (100) being characterized in that the safety control device (1) controls the actuator (2): so as to perform the closing of the at least one electrical contact (310) when the first safety control command (Sig4) is a first start safety control command (Sig4 ON), or so as to perform the opening of the at least one electrical contact (310) when the first safety control command (Sig4) is a first stop safety control command (Sig4 OFF).
13. The contactor (100) according to the preceding claim, characterized in that It also has a third connection terminal (C3) connected to a third connection point (E3) of the safety control device (1), said safety control device (1) being connected to the actuator (2) via a second binary output (S2) in order to provide the actuator (2) with a third safety control command (Sig50) so as to control said actuator (2): so as to perform the closing of the at least one electrical contact (310) when the third safety control command (Sig50) is a third start safety control command (Sig50 ON), or so as to perform the opening of the at least one electrical contact (310) when the third safety control command (Sig50) is a third stop safety control command (Sig50 OFF).
14. A method for the safe processing of a third signal (Sig3) formed from at least one pulse (P) provided by at least a first receiver circuit (22) of a safety control device (1) according to any one of the preceding claims, said method being characterized in that it comprises iteratively counting the number (Q) of pulses (P) provided by the first receiver circuit (22) during a time interval (T) of predefined duration.
15. The method for securely processing a third signal (Sig3) according to the preceding claim, characterized in that, The first counter (Q1) is incremented when the number (Q) of pulses (P) counted during the time interval (T) is between a predefined minimum number of pulses (Qmin) and a predefined maximum number of pulses (Qmax).
16. The method for securely processing a third signal (Sig3) according to the preceding claim, characterized in that, The first start safety control command (Sig4_ON) is generated when the first counter (Q1) is equal to or greater than a predefined validation threshold (Qval).
17. The method for securely processing a third signal (Sig3) according to claim 15 or 16, characterized in that, The second counter (Q2) is incremented when the number (Q) of pulses (P) counted during the time interval (T) is not between the minimum number of pulses (Qmin) and the maximum number of pulses (Qmax).
18. The method for securely processing a third signal (Sig3) according to the preceding claim, characterized in that, The first stop safety control command (Sig4_OFF) is generated when the second counter (Q2) is equal to or greater than a predefined invalidation threshold (Qinv).
Citation Information
Patent Citations
Emergency stop circuit
EP1538651A2
Single-signal transmission of safe process information
US20040199837A1
Control system
US20110169345A1
Intelligent control driver for electric eddy speed damper and its control method
CN101239590A
Safety control device based on double 2-vote-2 safety redundant system, and system
CN102789166A