Functional Safety Technology for Industrial Automation Equipment

By disabling the communication flow between the controller and the power module in industrial automation equipment and preventing power from being provided to the motor, the complex and costly functional safety mechanisms in the prior art are solved, and a simple and low-cost functional safety solution is achieved.

CN114844438BActive Publication Date: 2025-06-24ROCKWELL AUTOMATION TECH INC
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202210108809.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2021-02-02
Filing Date
2022-01-28
Publication Date
2025-06-24
Estimated Expiration
2042-01-28

AI Technical Summary

Technical Problem

Existing functional safety mechanisms enable complex and expensive circuit board designs in industrial automation equipment and require a lot of work to meet functional safety standards.

Method used

This is achieved by implementing a functional safety mechanism between the controller and the power module of an industrial automation device, disabling communication flow and preventing power from being delivered to the motor, using non-transitory computer-readable media and processors to execute instructions.

Benefits of technology

It realizes a simple and low-cost functional safety mechanism, can effectively disable industrial automation equipment and comply with functional safety standards, and provides multi-level redundant safety measures.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114844438B_ABST
    Figure CN114844438B_ABST
Patent Text Reader

Abstract

The present invention provides functional safety techniques for industrial automation equipment. A method may include receiving, by corresponding processing circuitry of one or more power modules of an industrial automation equipment, a control signal from a controller of the industrial automation equipment. The power module may include a driver circuitry and a power converter, and the power converter may supply power to a motor based on a signal. The method may further include: detecting, by the corresponding processing circuitry, based on the signal, whether there is a lack of communication from the controller; in response to detecting the lack of communication from the controller, sending, by the corresponding processing circuitry, a first command to a strobe signal enabling circuitry, the first command being for disabling the driver circuitry; and sending, by the corresponding processing circuitry, a second command to a driver power circuitry, the second command being for preventing power from being supplied to the driver circuitry.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure generally relates to controlling, monitoring, and disabling industrial automation equipment. More specifically, embodiments of the present disclosure relate to systems and methods for implementing a functional safety mechanism to prevent power from being supplied to industrial automation equipment and for verifying whether a circuit system for implementing the functional safety mechanism is operating properly. Background Art

[0002] Industrial automation equipment, such as medium voltage drives, is used in various environments. In some cases, these industrial automation equipment may be disabled and placed in a safe state. Accordingly, certain functional safety mechanisms can be designed to reliably disable industrial automation equipment in such cases. The design of such a functional safety mechanism can be designed to comply with certain functional safety standards, such as the International Electrotechnical Commission (IEC) 61508. One such functional safety mechanism involves using a black channel to send complex safety messages between a controller of an industrial automation equipment and one or more power units of the industrial automation equipment. However, the implementation of the black channel may require the use of multiple intelligent devices, such as field programmable gate arrays (FPGAs), in the circuit board design of the industrial automation equipment. This may result in a complex and expensive circuit board design. In addition, the development of safety messages may require a large amount of work to meet the functional safety standards. For example, the code for configuring intelligent devices in the circuit board design can be verified before implementation. Accordingly, it is desirable to develop a simple, low-cost functional safety mechanism that can disable certain industrial automation equipment and comply with the functional safety standards.

[0003] This section is intended to introduce to the reader various aspects of technologies that may be related to various aspects of the present technology described and / or claimed below. This discussion is believed to be helpful in providing the reader with background information to facilitate a better understanding of various aspects of the present disclosure. Accordingly, it should be understood that these statements should be construed in this light and not as an admission of prior art. Summary of the Invention

[0004] An overview of certain embodiments disclosed herein is presented below. It should be understood that these aspects are presented merely to provide a brief overview of these specific embodiments to the reader and that these aspects are not intended to limit the scope of the present disclosure. Indeed, the present disclosure may cover various aspects that may not be recited below.

[0005] In one embodiment, a non-transitory computer-readable medium associated with an industrial automation device may include instructions that, when executed by one or more processors, cause the processors to perform operations. The operations may include: receiving one or more inputs indicating to turn off one or more power modules of the industrial automation device. The operations may further include: in response to receiving the input, sending a first command to a driver control circuitry, the first command for disabling a driver communicatively coupled to one or more transmitters; and sending a second command to a transmitter control circuitry, the second command for preventing power from being supplied to the transmitters. The driver may send control signals to one or more respective power modules via the transmitters to control the operation of a power converter that may supply power to a motor. Each power module may receive a control signal from the driver via the transmitter, monitor the control signal for a lack of communication from the driver, and in response to detecting a lack of communication based on the control signal, disable a driver circuitry of the power module, the driver circuitry of the power module may control the operation of the power converter to supply power to the motor and prevent power from being supplied to the driver circuitry.

[0006] In another embodiment, a method may include: receiving, by respective processing circuitry of one or more power modules of an industrial automation device, a control signal from a controller of the industrial automation device. The power module may include a driver circuitry and a power converter that may supply power to a motor based on the signal. The method may further include: detecting, by the respective processing circuitry, whether there is a lack of communication from the controller based on the signal; in response to detecting a lack of communication from the controller, sending, by the respective processing circuitry, a first command to a strobe signal enabling circuitry, the first command for disabling the driver circuitry; and sending, by the respective processing circuitry, a second command to a driver power circuitry, the second command for preventing power from being supplied to the driver circuitry.

[0007] In yet another embodiment, a system may include a controller that includes a driver and first processing circuitry communicatively coupled to one or more transmitters. The driver may send control signals to one or more corresponding power modules via the transmitters. The first processing circuitry may: receive one or more inputs indicating to turn off the corresponding power modules; in response to receiving the inputs, send a first command to driver control circuitry communicatively coupled to the driver, and send a second command to transmitter control circuitry communicatively coupled to the transmitters. The first command may disable the driver, and the second command may prevent power from being supplied to the transmitters. The system may further include a power module that may control the operation of a power converter to supply power to a motor. The power module is communicatively coupled to a first transmitter. The power module includes: driver circuitry that may control the operation of the power converter; and second processing circuitry that may receive a control signal from the first transmitter, detect whether communication from the controller is missing based on the control signal, in response to detecting the missing communication, send a third command to a gating signal circuitry, the third command for disabling the driver circuitry, and send a fourth command to a driver power circuitry, the fourth command for preventing power from being supplied to the driver circuitry. BRIEF DESCRIPTION OF THE DRAWINGS

[0008] These and other features, aspects, and advantages of the present invention will become better understood when the following detailed description is read with reference to the accompanying drawings, in which like reference numerals represent like parts throughout the drawings, wherein:

[0009] Figure 1 is a block diagram of an exemplary medium voltage drive according to an embodiment, the medium voltage drive including control circuitry of the medium voltage drive and one or more power modules, the medium voltage drive being capable of implementing a functional safety mechanism to prevent power from being transferred from the medium voltage drive to a motor;

[0010] Figure 2 is according to an embodiment of Figure 1 block diagram of control circuitry of an exemplary medium voltage drive; and

[0011] Figure 3 is according to an embodiment of Figure 1 block diagram of circuitry of a power module of an exemplary medium voltage drive. DETAILED DESCRIPTION

[0012] One or more specific embodiments of the present disclosure will be described below. To provide a concise description of these embodiments, not all features of an actual implementation may be described in the specification. It should be understood that in the development of any such actual implementation, as in any engineering or design project, numerous implementation-specific decisions must be made to achieve the developer's specific goals, such as compliance with system-related and business-related constraints, which may vary from one implementation to another. In addition, it should be understood that although such development efforts may be complex and time-consuming, they would still be a routine task of design, fabrication, and manufacture for those of ordinary skill in the art that have benefited from the present disclosure.

[0013] When introducing elements of the various embodiments of the present disclosure, the articles "a", "an", "the", and "said" are intended to mean that there is one or more of the elements. The terms "comprising", "including", and "having" are intended to be inclusive and mean that there may be additional elements other than the listed elements. One or more specific embodiments of the embodiments described herein will be described below. To provide a concise description of these embodiments, not all features of an actual implementation may be described in the specification. It should be understood that in the development of any such actual implementation, as in any engineering or design project, numerous implementation-specific decisions must be made to achieve the developer's specific goals, such as compliance with system-related and business-related constraints, which may vary from one implementation to another. In addition, it should be understood that although such development efforts may be complex and time-consuming, they would still be a routine task of design, fabrication, and manufacture for those of ordinary skill in the art that have benefited from the present disclosure.

[0014] Industrial automation devices such as medium voltage drives are used in various environments. In some cases, these industrial automation devices can be disabled and placed in a safe state. Certain functional safety mechanisms can be designed to reliably disable industrial automation devices. One such functional safety mechanism involves using a black channel to send complex safety messages between the controller of an industrial automation device and one or more power units of the industrial automation device to disable the industrial automation device. However, the implementation of the black channel may involve using multiple intelligent devices, such as field programmable gate arrays (FPGAs), in the circuit board design of the industrial automation device, which may result in a complex and expensive circuit board design. In addition, to meet functional safety standards such as IEC 61508, the development of complex safety messages may involve a large amount of work. For example, the code used to configure intelligent devices in the circuit board design may need to be verified before implementation.

[0015] Accordingly, the present disclosure generally relates to a functional safety mechanism for industrial automation equipment that can stop the communication flow between a controller of the industrial automation equipment and one or more power modules of the industrial automation equipment to disable the industrial automation equipment (e.g., place the power modules of the industrial automation equipment in a safe state). In certain embodiments, the industrial automation equipment can include a medium-voltage drive having a controller and one or more power modules that can control the operation of one or more corresponding power converters to supply power to a motor. Although certain embodiments of the present disclosure are described herein with reference to a functional safety mechanism implemented within a medium-voltage drive (e.g., a supply voltage of 2.3 kilovolts (kV) to 11 kV), it should be understood that the functional safety mechanism can be used with other industrial automation equipment. For example, the industrial automation equipment can include a low-voltage drive (e.g., a supply voltage below 2.3 kV), a high-voltage drive (e.g., a supply voltage above 11 kV), a multi-axis motion servo drive, a current source drive, or any other industrial automation equipment that can utilize a communication flow and can be placed in a functional safety state without using dedicated safety messages).

[0016] During normal operation of the medium-voltage drive, the controller of the medium-voltage drive can send one or more messages (e.g., (one or more) data or commands) to the (one or more) power modules of the medium-voltage drive via a serial-based communication link. After receiving the message from the controller, the (one or more) power modules can control the operation of one or more corresponding power converters to supply power to the motor based on the specific message received. In certain cases, the controller of the medium-voltage drive can trigger the functional safety mechanism to place the (one or more) power modules in a safe state. For example, the controller of the medium-voltage drive can receive a command to initiate the functional safety mechanism from various devices communicatively coupled to the controller, such as an emergency stop button, a programmable logic controller (PLC), a light curtain, etc. In response to the functional safety mechanism being triggered, the controller of the medium-voltage drive can: (1) disable the corresponding transmitter that relays messages between the controller and the (one or more) power modules (e.g., turn off the power to the transmitter); and (2) disable the generation of a gating signal (e.g., an enabling signal) that controls the drive of the controller to send one or more messages to the corresponding transmitter to relay the message to the (one or more) power modules.

[0017] In addition, each power module may include a communication monitoring circuitry, such as a communication watchdog timer, which monitors communication gaps from the controller (e.g., a period of time during which message transmissions are missing). In response to the communication monitoring circuitry of the power module detecting a communication gap from the controller (i.e., after the functional safety mechanism has been triggered), the power module may: (1) disable the driver circuitry of the power module (e.g., turn off power to the driver circuitry), where the driver circuitry of the power module may generate one or more signals for controlling the operation of one or more corresponding power converters that supply power to the motor; and (2) disable the generation of one or more strobe signals (e.g., one or more enable signals) that would control the driver circuitry of the power module to generate signals for controlling the operation of the corresponding power converter to supply power to the motor. Thus, the power module of the medium voltage drive can be disabled and placed in a safe state.

[0018] In this way, the functional safety mechanism provides multi-level redundancy by implementing different methods of preventing signals from being transmitted from the controller to the (one or more) power modules and different methods of preventing power from being supplied to the motor. That is, to prevent signals from being transmitted from the controller to the (one or more) power modules, the controller of the medium voltage drive may: (1) disable the transmitter (e.g., turn off power to the transmitter); and (2) disable the generation of strobe signals (e.g., enable signals) that would control the driver of the controller to send one or more messages to the corresponding transmitter to relay the messages to the (one or more) power modules. In addition, to prevent power from being supplied to the motor, the power module may: (1) disable the driver circuitry of the power module (e.g., turn off power to the driver circuitry); and (2) disable the generation of strobe signals (e.g., enable signals) that would control the driver circuitry of the power module to generate signals for controlling the operation of the corresponding power converter to supply power to the motor.

[0019] In addition, one or more diagnostic tests can be implemented within the medium voltage drive to verify the integrity of the circuitry that can be used to implement a functional safety mechanism in the controller of the medium voltage drive, in each power module of the medium voltage drive, or in a combination thereof. In particular, a short test pulse (e.g., less than 100 nanoseconds) can be sent to one or more components of the controller of the medium voltage drive (e.g., the transmitter control circuitry), one or more components of the (one or more) power modules of the medium voltage drive (e.g., the drive control circuitry), or a combination thereof, to verify whether such components can deactivate the integrity or capabilities of the corresponding circuitry of the controller and the (one or more) power modules when requested. The controller of the medium voltage drive can receive data indicating whether the diagnostic test of the corresponding components of the controller or the (one or more) power modules was successful. If the data indicates that the diagnostic test was not successful, the controller can initiate the functional safety mechanism described herein.

[0020] In view of the above, Figure 1 is block diagram 100 of a medium voltage drive 102 that includes a controller 104 and one or more power modules 106 that can control the operation of one or more corresponding power converters 108 to supply power to a motor 110. Generally, each power converter 108 can receive a three-phase alternating current (AC) voltage from a voltage source 112 or a direct current (DC) voltage from the voltage source 112 and convert the AC voltage or DC voltage into a voltage suitable for powering a load. In this manner, the power converter 108 can supply the voltage source 112 to the motor 110 via one or more inverters. For example, the medium voltage drive 102 can control the speed, torque, or other suitable operation of the motor 110 by controlling the characteristics (e.g., amplitude or frequency) of the voltage supplied to the motor 110 via the inverter.

[0021] As described above, during normal operation of the medium voltage drive 102, the controller 104 of the medium voltage drive 102 can send one or more messages (e.g., (one or more) data or commands) to the (one or more) power modules 106 of the medium voltage drive 102 via a serial-based communication link. After receiving the message from the controller 104, the (one or more) power modules 106 can generate one or more signals (e.g., pulse width modulation signals) based on the specific message received, and the one or more signals (e.g., pulse width modulation signals) are used to control the operation of the (one or more) corresponding power converters 108 to supply power to the motor 110. In some embodiments, the motor 110 can be coupled to one or more fans, one or more pumps, one or more compressors, etc. and drive one or more fans, one or more pumps, one or more compressors, etc.

[0022] The controller 104 of the medium voltage drive 102 can receive a command to initiate a functional safety mechanism to shut down the medium voltage drive 102. As described herein, the term "shut down" can refer to the situation where the power module(s) 106 of the medium voltage drive 102 are placed in a safe state or shut down such that the power module(s) 106 do not generate signals that control the power converter corresponding to the power module(s) 106 to supply power to the motor 110. In some embodiments, the controller 104 of the medium voltage drive 102 can receive a command to initiate the functional safety mechanism from various devices communicatively coupled to the controller 104 via a network. For example, such devices can include an emergency stop button, a programmable logic controller (PLC), a light curtain, etc. It should be noted that any suitable network can be employed in the embodiments described herein. For example, the network can include any wired or wireless network that can be implemented as a local area network (LAN), a wide area network (WAN), etc. In fact, other industrial communication network protocols can also be used, such as Ethernet / IP, Common Industrial Protocol (CIP) Safety, ProfiSafe, etc.

[0023] In response to receiving a command to initiate the functional safety mechanism, the controller 104 of the medium voltage drive 102 may send one or more corresponding commands to the corresponding circuitry in the controller 104 of the medium voltage drive 102, the one or more corresponding commands being for: (1) disabling one or more transmitters of the controller 104, the one or more transmitters being capable of relaying messages between the controller 104 and the power module(s) 106; and (2) disabling the generation of a strobe signal (e.g., an enable signal), the strobe signal being configured to control the driver of the controller 104 to send one or more messages to the transmitter to relay the message to the power module(s) 106. Each power module 106 may include communication monitoring circuitry that monitors communication gaps from the controller 104 to initiate the functional safety mechanism. For example, the power module(s) 106 may initiate the functional safety mechanism in response to detecting a communication gap from the controller 104 (e.g., a period of time during which no transmission occurs) to: (1) disable the driver circuitry of the power module 106, the driver circuitry being capable of generating one or more signals (e.g., pulse width modulation signals) for controlling the operation of the corresponding power converter to supply power to the motor 110; and (2) disable the generation of a strobe signal (e.g., an enable signal), the strobe signal being configured to control the driver circuitry of the power module 106 to generate signals that control the operation of the corresponding power converter. In some embodiments, the period of the communication gap may be greater than or equal to 100 milliseconds. However, it should be noted that any suitable period may be used to trigger the power module 106 to initiate the functional safety mechanism. For example, the period of the gap may be based on the data transfer rate between the controller 104 and the power module(s) 106 and the required safety response time. In this way, the functional safety mechanism provides multi-level redundancy when disabling the medium voltage drive 102 by preventing messages from being sent from the controller 104 to the power module(s) 106 and preventing power from being supplied to the motor 110.

[0024] In some embodiments, the medium voltage drive 102 may have up to twenty-seven or more power modules 106. However, it should be noted that during normal operation of the medium voltage drive 102, the medium voltage drive 102 may have any suitable number of power modules 106 that transfer power to the motor 110. Additionally, for each power module 106 of the medium voltage drive 102, the controller 104 may have a corresponding transmitter for sending messages from the controller 104 to the corresponding power module controller 107, the corresponding power module controller 107 controlling the operation of its corresponding power converter 108 to supply power to the motor 110.

[0025] In addition, during normal operation of the medium voltage drive 102, the controller 104 may periodically initiate one or more diagnostic tests to verify the integrity (e.g., capability) or operability of circuitry that can be used to implement a functional safety mechanism in the controller 104 of the medium voltage drive 102, circuitry that can be used to implement a functional safety mechanism in each power module 106 of the medium voltage drive 102, or a combination thereof. In some embodiments, the controller 104 may initiate diagnostic tests at 250 millisecond intervals, at 500 millisecond intervals, at one second intervals, or at any other suitable interval. Each diagnostic test may include: sending a test pulse to circuitry of the controller 104 that can disable the transmitter of the controller 104; sending a test pulse to circuitry of the controller 104 that can disable the generation of an enable signal that will control the driver of the controller 104 to send a message to the transmitter; sending a test pulse to circuitry of the power module(s) 106 that can disable the driver circuitry of the power module 106, the driver circuitry of the power module 106 generating one or more signals that are used to control the operation of the corresponding power converter to supply power to the motor 110; sending a test pulse to circuitry of the power module(s) that can disable the generation of an enable signal that will control the driver circuitry of the power module 106 to generate a signal that controls the operation of the corresponding power converter; or a combination thereof. In some embodiments, the test pulse may be less than or equal to 100 nanoseconds, less than or equal to 80 nanoseconds, less than or equal to 60 nanoseconds, or any other suitable length such that the diagnostic test can determine whether the circuitry of the controller 104 and / or the circuitry of the power module(s) can perform the functional safety mechanism without triggering the functional safety mechanism. That is, diagnostic tests of the circuitry of the controller 104 and the power module(s) 106 can be performed while the medium voltage drive 102 continues to operate to supply power to the motor 110.

[0026] The controller 104 may receive data indicating the results of each diagnostic test. If one or more of the diagnostic tests return an unsuccessful result, the controller 104 may initiate a functional safety mechanism to place the power module(s) 106 of the medium voltage drive 102 in a safe state. For example, if a diagnostic test of one of the power modules 106 of the medium voltage drive 102 determines that the circuitry of the power module 106 cannot: (1) disable the drive circuitry of the power module 106 or (2) disable the generation of an enable signal that controls the drive circuitry of the power module 106 or both, the controller 104 may initiate the functional safety mechanism described herein to place each power module 106 in a safe state.

[0027] In view of the above, Figure 2 FIG. 200 is a block diagram of the controller 104 of the medium voltage drive 102, Figure 3 and FIG. 300 is a block diagram of a single power module 106 of the medium voltage drive 102. As Figure 2 shown, the controller 104 may include processing circuitry 202, and the processing circuitry 202 includes a processor 204 and a memory 206. The processor 204 may be any suitable type of computer processor or microprocessor capable of executing computer-executable code, including but not limited to one or more field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), programmable logic devices (PLDs), programmable logic arrays (PLAs), etc. In some embodiments, the processor 204 may include multiple processors. The memory 206 may include any suitable article of manufacture that serves as a medium for storing processor-executable code, data, etc. The memory 206 may store non-transitory processor-executable code used by the processor 204 to perform the presently disclosed techniques.

[0028] During normal operation of the medium voltage drive 102, the processing circuitry 202 of the controller 104 may generate one or more messages that may be sent to the driver 208 of the controller 104 (e.g., drive circuitry 208) to be provided to one or more power modules 106 of the medium voltage drive 102 via one or more respective transmitters 210, 212, 214. For example, the power module controller 107 may generate one or more signals based on the messages received from the controller 104, and the one or more signals are used to control the operation of its corresponding power converter to supply power to the motor 110. As Figure 2As shown, the processing circuitry 202 may include a communication engine 216 that generates messages to be sent to the driver 208 based on data received by the processing circuitry 202 from one or more input sources. In some embodiments, the input sources may include one or more sensors associated with the medium voltage driver 102, one or more sensors associated with the motor 110, one or more user inputs, and the like. After the driver 208 of the controller 104 receives a message from the processing circuitry 202, the driver 208 may send the message to the power module 106 via the transmitters 210, 212, 214. In certain embodiments, when the driver 208 sends a message to the power module(s) 106 via the transmitters 210, 212, 214, the communication engine 216 of the controller 104 may act as a buffer that temporarily stores the message. Additionally, the transmitters 210, 212, 214 may convert the message received from the driver 208 (e.g., a digital signal) into a format compatible with the power module(s) 106. In some embodiments, the transmitters 210, 212, 214 may convert the message into an optical fiber signal before relaying the optical fiber signal to the power module(s) 106. Although three transmitters 210, 212, 214 are shown in Figure 2 FIG. 1, it should be understood that any suitable number of transmitters 210, 212, 214 may be included in the controller 104. For example, the number of transmitters 210, 212, 214 may correspond to the number of power module(s) 106 of the medium voltage driver 102. In this way, the controller 104 may individually control each power module 106 via the respective transmitters 210, 212, 214 of the controller 104.

[0029] As Figure 3As shown, the power module controller 107 of the power module (106) may include processing circuitry 302, and the processing circuitry 302 may receive a message from the controller 104 via a receiver 304. In some embodiments, the receiver 304 may receive the message as an optical fiber signal and convert the optical fiber signal into a digital signal that can be interpreted by the processing circuitry 302. Similar to the processing circuitry 202 of the controller 104, the processing circuitry 302 of the power module controller 107 includes a processor 306 and a memory 308. The processor 306 may be any suitable type of computer processor or microprocessor capable of executing computer-executable code, including but not limited to one or more field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), programmable logic devices (PLDs), programmable logic arrays (PLAs), etc. In some embodiments, the processor 306 may include multiple processors. The memory 308 may include any suitable article of manufacture that serves as a medium for storing processor-executable code, data, etc. The memory 308 may store non-transitory processor-executable code used by the processor 306 to perform the presently disclosed techniques.

[0030] After the processing circuitry 302 of the power module controller 107 receives a message from the controller 104, the processing circuitry 302 may control the operation of its power converter 108 to supply power to the motor 110 based on the message received from the controller 104. For example, a communication engine 310 of the processing circuitry 302 may interpret the message received from the controller 104 and send a command to a driver circuitry 312 to generate one or more signals (e.g., pulse-width modulation signals) for controlling the operation of its corresponding power converter 108 to supply power to the motor 110.

[0031] During normal operation of the medium voltage drive 102, the processing circuitry 202 of the controller 104 may receive a command to initiate a functional safety mechanism to shut down the medium voltage drive 102. For example, the processing circuitry 202 of the controller 104 may receive a command to initiate the functional safety mechanism from an emergency stop button, a programmable logic controller (PLC), a light curtain, etc. In response to receiving the command to initiate the functional safety mechanism, the processing circuitry 202 of the controller 104 may send one or more corresponding commands to the corresponding circuitry of the controller 104, the one or more corresponding commands being for: (1) disabling one or more transmitters 210, 212, 214 of the controller 104, the one or more transmitters 210, 212, 214 being able to relay messages between the controller 104 and the power module(s) 106; and (2) disabling the generation of an enable signal that would control the drive 208 of the controller 104 to send messages to the power module(s) 106 via the transmitters 210, 212, 214. In particular, the processing circuitry 202 of the controller 104 may send a first command to the transmitter control circuitry 218, the first command being for shutting off the power supplied to the transmitters 210, 212, 214. Additionally, the processing circuitry 202 of the controller 104 may send a second command to the drive control circuitry 220, the second command being for disabling the drive 208 to prevent messages from being sent from the drive 208 to the transmitters 210, 212, 214. In some embodiments, the processing circuitry 202 of the controller 104 may send the first command to the transmitter control circuitry 218 and the second command to the drive control circuitry 220 substantially simultaneously or simultaneously. In other embodiments, the transmitter control circuitry 218 and / or the drive control circuitry 220 may directly receive the command to initiate the functional safety mechanism (e.g., from an emergency stop button, a PLC, a light curtain, etc.).

[0032] During normal operation of the medium voltage drive 102, the power module 106 can continuously monitor communication gaps from the controller 104 via a communication monitoring circuitry 314 (e.g., a communication watchdog timer) to initiate a functional safety mechanism. For example, the receiver 304 can send a message (e.g., a digital signal including the message) from the controller 104 to the processing circuitry 302 and the communication monitoring circuitry 314. The communication monitoring circuitry 314 can detect communication gaps from the controller 104 by analyzing the digital signal from the receiver 304. In some embodiments, a sufficient time period for a communication gap from the controller 104 to trigger the functional safety mechanism can be greater than or equal to 100 milliseconds. In certain embodiments, the power module 106 can monitor for loss of communication (e.g., messages) from the controller 104 or an irregular frequency of communication transmissions from the controller 104 (e.g., an increase or decrease in the frequency of received messages). In such embodiments, the communication monitoring circuitry 314 can detect the loss of communication or the irregular frequency of communication transmissions and trigger the functional safety mechanism.

[0033] In response to the communication monitoring circuitry 314 detecting a communication gap from the controller 104, the communication monitoring circuitry 314 can send data indicating the detected gap to the processing circuitry 302 of the power module 106. The processing circuitry 302 of the power module can then send one or more corresponding commands to the corresponding circuitry of the power module 106, the one or more corresponding commands for: (1) disabling the drive circuitry 312 of the power module 106; and (2) disabling the generation of an enable signal that would control the drive circuitry 312 to generate and send one or more signals (e.g., pulse width modulation signals), the one or more signals (e.g., pulse width modulation signals) for a corresponding power converter 108 to supply power to a motor 110. Specifically, the processing circuitry 302 of the power module 106 can send a first command to the drive power circuitry 316, the first command for turning off the power supplied to the drive circuitry 312. Additionally, the processing circuitry 302 of the power module 106 can send a second command to the strobe control circuitry 318, the second command for disabling the drive circuitry 312 to prevent the drive circuitry 312 from generating and sending signals for controlling the operation of the corresponding power converter 108 to supply power to the motor 110. Thus, the power module 106 of the medium voltage drive 102 can be disabled and placed in a safe state.

[0034] In some embodiments, the processing circuitry 302 of the power module 106 may send a first command to the driver power circuitry 316 and a second command to the strobe control circuitry 318 substantially simultaneously or simultaneously. In other embodiments, the driver power circuitry 316 and / or the strobe control circuitry 318 may receive a command to initiate the functional safety mechanism directly (e.g., from the communication monitoring circuitry 314 in response to detecting a gap).

[0035] As described above, during normal operation of the medium voltage driver 102, the controller 104 may periodically initiate one or more diagnostic tests (e.g., enable tests and power tests) to verify the integrity or operability of the circuitry that may be used to implement the functional safety mechanism in the controller 104 of the medium voltage driver 102, the circuitry that may be used to implement the functional safety mechanism in each power module 106 of the medium voltage driver 102, or a combination thereof. Return reference Figure 2 , the processing circuitry 202 of the controller 104 may periodically initiate a diagnostic test to determine whether the transmitter control circuitry 218 can successfully turn off the power provided to the transmitters 210, 212, 214. For example, the processing circuitry 202 of the controller 104 may send the following command to the transmitter control circuitry 218: generate a test pulse via the power control circuitry 222 and provide the test pulse to the power hold circuitry 224. The transmitter control circuitry 218 may monitor whether the test pulse causes an interruption of the power signal provided to the transmitters 210, 212, 214. It should be noted that the power hold circuitry 224 provides a hold circuit that provides an additional power signal (e.g., a functional safety power signal) to the transmitters 210, 212, 214 to maintain the operation of the transmitters 210, 212, 214 when the diagnostic test is implemented. It should be noted that the functional safety power signal is different from the power signal through which the test pulse is sent from the power control circuitry 222 to the power hold circuitry 224. In this way, the communication between the controller 104 and the power module(s) 106 is not interrupted during the diagnostic test of the transmitter control circuitry 218.

[0036] In some embodiments, the power hold circuitry 224 may include a pulse test latch disposed in the power hold circuitry 224 prior to the hold circuitry. The pulse test latch may receive a test pulse from the power control circuitry 222 before the test pulse is sent to the hold circuitry. In response to receiving the test pulse, the clock input of the pulse test latch may switch to logic one, causing the output of the pulse test latch to switch to logic zero. The hold circuitry may then receive the detected test pulse from the pulse test latch to verify the ability of the power hold circuitry 224 to turn off power to the transmitters 210, 212, 214. It should be understood that the test pulse does not cause an interruption of the power signal from the hold circuitry to the transmitters 210, 212, 214 because the capacitors in the hold circuitry do not allow the test pulse to pass through the transmitters 210, 212, 214.

[0037] In response to the output of the pulse test latch switching to logic zero, the transmitter control circuitry 218 may send data indicating a successful diagnostic test of the transmitter control circuitry 218 to the processing circuitry 202 of the controller 104. The processing circuitry 202 of the controller 104 may then store the successful diagnostic test result in the memory 206. However, if the pulse test latch does not switch to logic zero, the transmitter control circuitry 218 may send data indicating an unsuccessful diagnostic test of the transmitter control circuitry 218 to the processing circuitry 202 of the controller 104. If the processing circuitry 202 of the controller 104 receives an unsuccessful diagnostic test result from the transmitter control circuitry 218, the processing circuitry 202 of the controller 104 may initiate the functional safety mechanism described herein.

[0038] The processing circuitry 202 of the controller 104 may also periodically initiate a diagnostic test to determine whether the driver control circuitry 220 can successfully turn off the generation of an enable signal that will control the driver 208 of the controller 104 to send a message to the transmitters 210, 212, 214, and the transmitters 210, 212, 214 relay the message to the power module(s) 106. For example, the processing circuitry 202 of the controller 104 may send the following command to the driver control circuitry 220: generate a test pulse to disable the generation of the enable signal of the driver 208 through the enable signal circuitry 226. The driver control circuitry 220 may monitor whether the test pulse causes an interruption of the enable signal of the enable signal circuitry 226.

[0039] Similar to the power hold circuitry 224, the enable signal circuitry 226 can include a pulse test latch that receives a test pulse. In response to receiving the test pulse, the clock input of the pulse test latch can switch to logic one, causing the output of the pulse test latch to switch to logic zero. In response to the output of the pulse test latch switching to logic zero, the driver control circuitry 220 can send a disable signal to the driver 208 of the controller 104. After the driver 208 receives the disable signal and subsequently shuts down, the driver 208 can send a signal indicating successful shutdown to the driver control circuitry 220, and the driver control circuitry 220 sends data indicating a successful diagnostic test of the driver control circuitry 220 to the processing circuitry 202 of the controller 104. Additionally, the driver control circuitry 220 can send an enable signal to the driver 208 shortly after receiving the signal indicating successful shutdown of the driver 208. In this way, the driver 208 experiences a brief shutdown so that the driver can be re-enabled before any data being sent is lost. The processing circuitry 202 of the controller 104 can then store the successful diagnostic test result in the memory 206.

[0040] However, if the driver 208 receives the disable signal and does not successfully shut down, the driver 208 can send a signal indicating unsuccessful shutdown to the driver control circuitry 220, and the driver control circuitry 220 sends data indicating an unsuccessful diagnostic test to the processing circuitry 202 of the controller 104. After the processing circuitry 202 of the controller 104 receives the unsuccessful diagnostic test result from the driver control circuitry 220, the processing circuitry 202 of the controller 104 can initiate the functional safety mechanism described herein.

[0041] Additionally, with reference to Figure 3, the processing circuitry 302 of the power module(s) 106 may periodically initiate one or more diagnostic tests to determine whether the drive power circuitry 316 can successfully turn off the power provided to the drive circuitry 312. For example, the processing circuitry 302 of the power module(s) may send the following command to the drive power circuitry 316: generate a test pulse via the power control circuitry 322 and provide the test pulse to the power hold circuitry 320. The drive power control circuitry 316 may monitor whether the test pulse causes an interruption of the power signal provided to the power hold circuitry 320. It should be noted that the power hold circuitry 320 provides a hold circuit that provides an additional power signal (e.g., a functional safety power signal) to the drive circuitry 312 to maintain the operation of the drive circuitry 312 when the diagnostic test is being implemented. It should also be noted that the functional safety power signal may be different from the power signal through which the test pulse is sent from the power control circuitry 322 to the power hold circuitry 320. In this way, during the diagnostic test of the drive power circuitry 316, the drive circuitry 312 can still generate one or more signals for controlling the operation of the corresponding power converter 108 to supply power to the motor 110.

[0042] Similar to the power hold circuitry 224 of the controller 104, in some embodiments, the power hold circuitry 320 may include a pulse test latch disposed in the power hold circuitry 320 before the hold circuit. The pulse test latch may receive the test pulse from the power control circuitry 322 before the test pulse is sent to the hold circuit. In response to receiving the test pulse, the clock input of the pulse test latch may switch to logic one, causing the output of the pulse test latch to switch to logic zero. The hold circuit may then receive the detected test pulse from the pulse test latch to verify the ability of the power hold circuitry 320 to turn off the power to the drive circuitry 312. It should be understood that the test pulse does not cause an interruption of the power signal from the hold circuit to the drive circuitry 312 because the capacitor in the hold circuit does not allow the test pulse to pass through the drive circuitry 312.

[0043] In response to the output of the pulse test latch switching to logic zero, the driver power circuitry 316 may send data indicating a successful diagnostic test of the driver power circuitry 316 to the processing circuitry 302 of the power module 106. The processing circuitry 302 of the power module 106 may then send data indicating a successful diagnostic test to the processing circuitry 202 of the controller 104 via the transmitter 324. The processing circuitry 202 of the controller may then store data indicating a successful diagnostic test of the driver power control circuitry 316 in the memory 206 of the processing circuitry 202. In some embodiments, the processing circuitry 302 of the power module 106 may also store data indicating a successful diagnostic test of the driver power circuitry 316 in the memory 308.

[0044] If the pulse test latch does not switch to logic zero, the driver power circuitry 316 may send data indicating an unsuccessful diagnostic test of the driver power circuitry 316 to the processing circuitry 302 of the power module 106. After the processing circuitry 302 receives an unsuccessful diagnostic test result from the driver power circuitry 316, the processing circuitry 302 may send data indicating an unsuccessful diagnostic test of the driver power circuitry 316 to the processing circuitry 202 of the controller 104 via the transmitter 324. After the processing circuitry 202 of the controller 104 receives data indicating an unsuccessful diagnostic test via the corresponding receivers 228, 230, 232 and receiver circuitry 234, the processing circuitry 202 may then initiate a functional safety mechanism as described herein.

[0045] (One or more) The processing circuitry 302 of the power module 106 may also periodically initiate diagnostic tests to determine whether the gating signal enabling circuitry 319 of the driver control circuitry 318 can successfully turn off the generation of an enabling signal that will control the driver circuitry 312 of each power module 106 to generate one or more signals for controlling the operation of its corresponding power converter 108 to supply power to the motor 110. For example, the processing circuitry 302 of the power module 106 may send the following command to the gating signal enabling circuitry 319: generate a test pulse to disable the generation of the enabling signal of the driver circuitry 312. The gating signal enabling circuitry 319 may monitor whether the test pulse causes an interruption of the enabling signal of the gating signal enabling circuitry 319.

[0046] Similar to the power hold circuitry 320, the strobe signal enabling circuitry 319 can include a pulse test latch that receives a test pulse. In response to receiving the test pulse, the clock input of the pulse test latch can switch to logic one, causing the output of the pulse test latch to switch to logic zero. In response to the output of the pulse test latch switching to logic zero, the strobe signal enabling circuitry 319 can send a disable signal to the driver circuitry 312 of the power module 106. After the driver circuitry 312 receives the disable signal and subsequently shuts down, the driver circuitry 312 can send a signal indicating successful shutdown to the strobe signal enabling circuitry 319, which sends data indicating a successful diagnostic test of the strobe signal enabling circuitry 319 to the processing circuitry 302 of the power module 106. The processing circuitry 302 can then send data indicating a successful diagnostic test of the strobe signal enabling circuitry 319 to the processing circuitry 202 of the controller 104. The processing circuitry 202 can then store the data in the memory 206 of the processing circuitry 202. In some embodiments, the processing circuitry 302 of the power module 106 can also store the data in the memory 308 of the processing circuitry 302.

[0047] Additionally, the strobe signal enabling circuitry 319 can send an enable signal to the driver circuitry 312 shortly after receiving a signal indicating successful shutdown of the driver circuitry 312. In this manner, the driver circuitry 312 experiences a brief shutdown such that the driver circuitry 312 can be re-enabled before any data loss to the power converter 108.

[0048] However, if the driver circuitry 312 receives the disable signal and does not successfully shut down, the driver circuitry 312 can send a signal indicating unsuccessful shutdown to the strobe signal enabling circuitry 319, which sends data indicating an unsuccessful diagnostic test to the processing circuitry 302 of the power module 106. The processing circuitry 302 of the power module 106 can then send data indicating the unsuccessful diagnostic test to the processing circuitry 202 of the controller 104 via the transmitter 324. The processing circuitry 202 can then initiate a functional safety mechanism as described herein.

[0049] In some embodiments, each diagnostic test can be implemented for the controller 104 and / or corresponding circuitry of the power module(s) 106 simultaneously or substantially simultaneously. In other embodiments, the execution time of each diagnostic test can overlap with at least one other diagnostic test.

[0050] In addition, the controller 104 may have a power monitoring circuit system 236, and each power module 106 may have a corresponding power monitoring circuit system 326 that continuously verifies whether each power supply provides power to the corresponding circuit system that can be used to implement a functional safety mechanism in the controller 104 of the medium-voltage drive 102 and the corresponding circuit system that can be used to implement a functional safety mechanism in each power module 106 of the medium-voltage drive 102 within an appropriate range. For example, the appropriate range may be the minimum voltage to the maximum voltage that allows the circuit system to operate within its operating limits. If at least one of the power supplies that provide power to the corresponding circuit system that can be used to implement a functional safety mechanism in the controller 104 or the corresponding circuit system that can be used to implement a functional safety mechanism in each power module 106 deviates from the range, the power monitoring circuit system 236 and / or the power monitoring circuit system 326 may send data indicating the deviation to the controller 104 of the medium-voltage drive 102. The controller 104 may then initiate the functional safety mechanism described herein.

[0051] The technical effects of the present disclosure include: providing multi-level redundancy by implementing different methods for preventing signals from being transmitted from the controller to the power module(s) and different methods for preventing power from being supplied to the motor. That is, to prevent signals from being transmitted from the controller to the power module(s), the controller of the medium-voltage drive may: (1) disable the transmitter (e.g., turn off the power to the transmitter); and (2) disable the generation of a gating signal (e.g., an enabling signal) that would control the driver of the controller to send one or more messages to the corresponding transmitter, which relays the messages to the power module(s). In addition, to prevent power from being supplied to the motor, the power module may: (1) disable the driver circuit system of the power module (e.g., turn off the power to the driver circuit system); and (2) disable the generation of a gating signal (e.g., an enabling signal) that would control the driver circuit system of the power module to generate a signal that controls the operation of the corresponding power converter to supply power to the motor. In addition, one or more diagnostic tests may be implemented within the industrial automation device to verify the integrity of the circuit system that can be used to implement a functional safety mechanism in the industrial automation device without interrupting the communication between the power module(s) and the controller. In this way, the industrial automation device can continue to operate during the diagnostic test while meeting certain functional safety standards. In addition, compared to the black-channel communication design, the functional safety mechanism described herein provides a simple and cost-effective design.

[0052] The technology proposed and claimed herein is cited and applied to specific examples of physical objects and practical properties, which significantly improves the present technical field and thus is not abstract, intangible or purely theoretical. In addition, if any claim appended to this specification contains one or more elements designated as "means for [performing] [function]..." or "steps for [performing] [function]...", such elements are intended to be construed in accordance with 35 U.S.C. 112(f). However, for any claim containing elements designated in any other way, such elements are not intended to be construed in accordance with 35 U.S.C. 112(f).

[0053] Although only certain features of the invention have been shown and described herein, many modifications and variations will occur to those skilled in the art. It is, therefore, to be understood that the appended claims are intended to cover all such modifications and variations that fall within the true spirit of the invention.

Claims

1. A non-transitory computer-readable medium associated with industrial automation equipment, wherein, The non-transitory computer-readable medium includes instructions that, when executed by one or more processors, cause the one or more processors to perform operations, the operations including: Receiving one or more inputs indicating to turn off one or more power modules of the industrial automation device; In response to receiving the one or more inputs: Sending a first command to a driver control circuitry, the first command for disabling a driver communicatively coupled to one or more transmitters, wherein the driver is configured to send control signals to one or more corresponding power modules via the one or more transmitters to control operations of a power converter, the power converter being configured to supply power to a motor; and Sending a second command to a transmitter control circuitry, the second command for preventing power from being supplied to the one or more transmitters; Wherein each of the one or more corresponding power modules is configured to: Receive the control signal from the driver via the one or more transmitters; Monitor the control signal for lack of communication from the driver, and In response to detecting lack of communication based on the control signal, disable a driver circuitry of the power module, the driver circuitry being configured to control operations of the power converter to supply power to the motor and prevent power from being supplied to the driver circuitry.

2. The non-transitory computer-readable medium according to claim 1, wherein, The first command is sent to the driver control circuitry and the second command is sent to the transmitter control circuitry simultaneously.

3. The non-transitory computer-readable medium according to claim 1, wherein, Each of the one or more corresponding power modules is configured to: disable the driver circuitry of the power module and simultaneously prevent power from being supplied to the driver circuitry.

4. The non-transitory computer-readable medium according to claim 1, wherein, The period of lack of communication is based on a transmission rate of the control signal and a safety response time.

5. The non-transitory computer-readable medium according to claim 1, wherein, The industrial automation device includes a voltage source driver or a current source driver.

6. A method for controlling an industrial automation device, including: Receiving, by corresponding processing circuitry of one or more power modules of the industrial automation device, a control signal from a controller of the industrial automation device, wherein the one or more power modules include a driver circuitry and a power converter, the power converter being configured to supply power to a motor based on the control signal; Detecting, by the corresponding processing circuitry, lack of communication from the controller based on communication interruption between the control signal and the power module; and At the power module, in response to detecting communication interruption between the control signal and the power module: Sending, by the corresponding processing circuitry, a first command to a strobe signal enabling circuitry, the first command for disabling the driver circuitry; and Sending, by the corresponding processing circuitry, a second command to a driver power circuitry, the second command for preventing power from being supplied to the driver circuitry.

7. The method according to claim 6, comprising sending, by a controller of the industrial automation device, the control signal to each of the one or more power modules.

8. The method according to claim 6, comprising receiving, by a controller of the industrial automation device, one or more inputs indicating to turn off the one or more power modules.

9. The method according to claim 6, comprising disabling, by a controller of the industrial automation device, a driver of the controller, the driver of the controller being configured to send the control signal to each of the one or more power modules via one or more respective transmitters of the controller.

10. The method according to claim 6, comprising preventing, by a controller of the industrial automation device, power from being supplied to one or more respective transmitters of the controller, the one or more respective transmitters of the controller being configured to send the control signal to each of the one or more power modules.

11. The method according to claim 6, comprising initiating, by the respective processing circuitry, one or more diagnostic tests, the one or more diagnostic tests being configured to: verify a first ability of the strobe signal enabling circuitry to disable the driver circuitry, verify a second ability of the driver power circuitry to prevent power from being supplied to the driver circuitry, or verify the first ability of the strobe signal enabling circuitry to disable the driver circuitry and verify the second ability of the driver power circuitry to prevent power from being supplied to the driver circuitry.

12. The method according to claim 11, comprising: receiving, by the processing circuitry, data indicating an unsuccessful diagnostic test among the one or more diagnostic tests; and sending, by the processing circuitry, the data indicating the unsuccessful diagnostic test to a controller of the industrial automation device.

13. The method according to claim 12, comprising: receiving, by a controller of the industrial automation device, the data indicating the unsuccessful diagnostic test; disabling, by a controller of the industrial automation device, a driver of the controller, the driver of the controller being configured to send the control signal to each of the one or more power modules via one or more respective transmitters of the controller; and preventing, by a controller of the industrial automation device, power from being supplied to one or more respective transmitters of the controller, the one or more respective transmitters of the controller being configured to send the control signal to each of the one or more power modules.

14. An industrial automation device, comprising: a controller, comprising: a driver communicatively coupled to one or more transmitters, wherein the driver is configured to send a control signal to one or more respective power modules via the one or more transmitters; and a first processing circuitry configured to: Receive one or more inputs indicating to turn off the one or more corresponding power modules; In response to receiving the one or more inputs: Send a first command to a driver control circuitry communicatively coupled to the driver, wherein the first command is configured to disable the driver; and Send a second command to a transmitter control circuitry communicatively coupled to the transmitter, wherein the second command is configured to prevent power from being supplied to the one or more transmitters; and A power module among the one or more corresponding power modules, wherein the power module is configured to control the operation of a power converter to supply power to a motor, wherein the power module is communicatively coupled to a first transmitter among the one or more transmitters, and wherein the power module includes: Driver circuitry configured to control the operation of the power converter; and A second processing circuitry configured to: Receive the control signal from the first transmitter; Detect whether communication from the controller is missing based on the control signal; In response to detecting missing communication: Send a third command to a strobe signal enabling circuitry, the third command for disabling the driver circuitry; and Send a fourth command to a driver power circuitry, the fourth command for preventing power from being supplied to the driver circuitry.

15. The industrial automation device according to claim 14, wherein, Each power module among the one or more corresponding power modules includes a communication timer configured to monitor the control signal for whether communication is missing.

16. The industrial automation device according to claim 14, wherein, The controller is configured to: initiate one or more diagnostic tests to verify the ability of the driver control circuitry to disable the driver.

17. The industrial automation device according to claim 14, wherein, The controller is configured to: initiate one or more diagnostic tests to verify the ability of the transmitter control circuitry to prevent power from being supplied to the one or more transmitters.

18. The industrial automation device according to claim 14, wherein, Each power module among the one or more corresponding power modules is configured to initiate one or more diagnostic tests configured to verify the ability of the strobe signal enabling circuitry to disable a second driver.

19. The industrial automation device according to claim 14, wherein Each power module among the one or more corresponding power modules is configured to initiate one or more diagnostic tests configured to verify the ability of the driver power circuitry to prevent power from being supplied to the driver circuitry.

20. The industrial automation device according to claim 14, wherein, Indicating to turn off the one or more inputs of the one or more corresponding power modules is associated with an emergency stop button, a programmable logic controller (PLC), a light curtain, or a combination of an emergency stop button, a programmable logic controller (PLC), and a light curtain.

Citation Information

Patent Citations

  • Robot control system based on universal computer

    CN111736514A

  • Power converter disable verification system and method

    US20100088047A1

  • Power structure diagnostic method and apparatus for improved motor drive diagnostic coverage

    US20160141865A1