Functionally safe high speed fail-safe counter module

By designing a fault-safe counter module independent of the PLC, and utilizing external encoder sensors and built-in safety monitoring functions, SIL 3, CAT 4, and PLE safety ratings were achieved. This solves the problem of strong dependence on the PLC in existing technologies and improves safety response time.

CN115885154BActive Publication Date: 2025-11-25SIEMENS AG
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202080103256.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2020-08-19
Publication Date
2025-11-25
Estimated Expiration
2040-08-19

AI Technical Summary

Technical Problem

In the prior art, the fail-safe counter module relies on the safety-rated programmable logic controller (PLC), which makes the implementation of safety monitoring functions highly dependent and difficult to achieve a high level of functional safety rating independently.

Method used

A fault-safe counter module independent of the PLC was designed. It uses an external encoder sensor to calculate speed and position, achieves high-speed counting through a Sin/Cos line differential electrical interface, and has built-in safety monitoring function. It can independently complete SIL 3, CAT 4, and PLE safety ratings.

Benefits of technology

It enables high-level functional safety rating to be completed independently within the fail-safe counter module, simplifies the control program, improves safety response time, and reduces reliance on PLC.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115885154B_ABST
    Figure CN115885154B_ABST
Patent Text Reader

Abstract

A failsafe counter module includes a controller that includes a processor and memory and circuitry for failsafe counting. The failsafe counter module also includes computer readable safety rating support code stored in the memory that, when executed by the processor, causes the controller to provide an international standard level of safety rating, such as Safety Integrity Level (SIL) 3, Category (CAT) 4, Performance Level (PL) e. The failsafe counter module also includes computer readable "safety monitoring" function code stored in the memory that, when executed by the processor, causes the controller to work with a user interface to select and configure a "safety monitoring" function. The failsafe counter module is a functional safety rated device with the intended rating for SIL 3, CAT 4, PL e applications and is designed to calculate position and / or speed with an external quadrature encoder sensor that produces a waveform that allows counting of specific electrical pulses.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates generally to a functionally safe high-speed fail-safe counter module configured to perform fail-safe counting of specific electrical pulses. Background Technology

[0002] Counters are used to count numbers up or down. Counter circuits typically consist of multiple flip-flops cascaded or connected by software code. Counters are widely used components in digital circuits and are manufactured as standalone integrated circuits as well as integrated into larger integrated circuits.

[0003] In engineering, the term "fail-safe" refers to a design feature or practice that, in the event of a specific type of failure, inherently responds in a manner that causes no harm or minimal harm to other equipment, the environment, or personnel. A system being "fail-safe" does not mean that failure is impossible or unlikely, but rather that the system is designed to prevent or mitigate the unsafe consequences of system failure. Fail-safe means that equipment failure will not endanger life or property (see international standards IEC 61508, EN 13849, and IEC 62061).

[0004] Safety monitoring functionality is independent of any external dependency (safety-rated programmable logic controller (PLC)). Other manufacturers address this by implementing redundant and / or diverse measurements within the application of a safety-rated PLC. Therefore, functional safety ratings are primarily achieved through libraries that rely on additional capabilities residing within the safety-rated PLC.

[0005] Therefore, a better fail-safe counter module is needed to simplify implementation in the control program and improve safety response time by allowing the module to identify violations in external applications. Summary of the Invention

[0006] In summary, aspects of the present invention relate to a fail-safe counter module that is a functionally safe rated device having the desired level for Safety Integrity Level (SIL) 3, Category (CAT) 4, Performance Level (PL)e applications. It is designed to utilize an external encoder sensor to calculate speed and / or position, the external encoder sensor generating waveforms that allow counting of specific electrical pulses. The module is wired to an external quadrature encoder using a Sin / Cos 4-line differential electrical interface. These electrical signals are used to establish high-speed counting, which can be used to indicate position and / or speed. The module independently implements SIL 3, CAT 4, PL e safety ratings without any external dependency on the application running within a safety-rated programmable logic controller (PLC). Furthermore, the module can perform separate safety monitoring functions within the module. The operation of these safety monitoring functions (which are configured by a PC via the PLC) is also independent of any external dependency (safety-rated PLC). The fail-safe counter module reports events and status based on configured parameters in a distributed I / O system and external movement operations. It provides a Sin / Cos encoder interface, which can safely count maximum speeds up to 200kHz. Leveraging these features of the module and its updated firmware, functional safety ratings are implemented entirely within the fail-safe counter module, and safety monitoring functions are performed internally. No programmable logic controller (PLC) dependency is required to achieve functional safety ratings.

[0007] According to one illustrative embodiment of the invention, the fail-safe counter module includes a controller comprising a processor, memory, and circuitry for fail-safe counting. The fail-safe counter module also includes computer-readable safety rating support code stored in memory, which, when executed by the processor, causes the controller to provide a safety rating to international standard levels such as Safety Integrity Level (SIL) 3, Category (CAT) 4, or Performance Level (PL)e. The fail-safe counter module also includes computer-readable "safety monitoring" function code stored in memory, which, when executed by the processor, causes the controller to work with a user interface (provided by a PC) to select and configure the "safety monitoring" function. The fail-safe counter module is a functional safety rated device with intended ratings for SIL 3, CAT 4, PLe applications and is designed to calculate position and / or velocity using an external quadrature encoder sensor that generates waveforms that allow counting of specific electrical pulses.

[0008] According to an illustrative embodiment of the present invention, a method for fault-safe counting is provided. The method includes the step of providing a controller including a processor and a memory. The method also includes the step of providing circuitry for fault-safe counting. The method further includes the step of providing computer-readable safety rating support code stored in the memory, which, when executed by the processor, causes the controller to: provide a safety rating to an internationally standardized level such as Safety Integrity Level (SIL) 3, Category (CAT) 4, Performance Level (PL)e. The method also includes the step of providing computer-readable "safety monitoring" function code stored in the memory, which, when executed by the processor, causes the controller to: work with a user interface (provided by a PC) to select and configure a "safety monitoring" function. The fault-safe counter module is a functional safety-rated device with an intended rating for applications of Safety Integrity Level (SIL) 3, Category (CAT) 4, Performance Level (PL)e, and is designed to calculate position and / or velocity using an external quadrature encoder sensor that generates waveforms that allow counting of specific electrical pulses. Attached Figure Description

[0009] Figure 1 A block diagram of a fail-safe counter module coupled to an external quadrature encoder sensor according to an exemplary embodiment of the present invention is shown.

[0010] Figure 2 A hardware diagram of a fail-safe counter module coupled to an external quadrature encoder sensor according to an exemplary embodiment of the present invention is shown.

[0011] Figure 3 Prototype views A, B, and C of a fail-safe counter module according to an exemplary embodiment of the present invention are shown.

[0012] Figure 4 A schematic diagram of the output image register of a fail-safe counter module according to an exemplary embodiment of the present invention is shown.

[0013] Figure 5 A schematic diagram of the input image register of a fail-safe counter module according to an exemplary embodiment of the present invention is shown.

[0014] Figure 6 A schematic diagram of a general parameterized page for fail-safe counting according to an exemplary embodiment of the present invention is shown.

[0015] Figure 7 A schematic diagram of a TM-C parameterized page for fail-safe counting according to an exemplary embodiment of the present invention is shown.

[0016] Figure 8 A schematic diagram of a safety monitoring function for fail-safe counting according to an exemplary embodiment of the present invention is shown.

[0017] Figure 9 A schematic diagram of the measured value of the fail-safe count – velocity – according to an exemplary embodiment of the present invention is shown.

[0018] Figure 10 A schematic diagram of the measured frequency of fail-safe counting according to an exemplary embodiment of the present invention is shown.

[0019] Figure 11 A schematic diagram of the measurement value - cycle duration of the fail-safe count according to an exemplary embodiment of the present invention is shown.

[0020] Figure 12 Schematic diagrams of SIL and PL according to exemplary embodiments of the present invention are shown in Tables 1 and 2.

[0021] Figure 13 A schematic diagram of the common board and counter input board of a fail-safe counter module according to an exemplary embodiment of the present invention is shown.

[0022] Figure 14 A schematic diagram showing additional details of the common board of a fail-safe counter module according to an exemplary embodiment of the present invention is provided.

[0023] Figure 15 A schematic diagram showing additional details of the counter input board of a fail-safe counter module according to an exemplary embodiment of the present invention is provided.

[0024] Figure 16 A schematic diagram of the software architecture of a fail-safe counter module according to an exemplary embodiment of the present invention is shown.

[0025] Figure 17 A schematic diagram of a user interface for a safety monitoring function of a fail-safe counter module according to an exemplary embodiment of the present invention is shown.

[0026] Figure 18 A schematic diagram of a flowchart of a method for fault-safe counting according to an exemplary embodiment of the present invention is shown. Detailed Implementation

[0027] To facilitate understanding of the embodiments, principles, and features of the present invention, they are explained below with reference to implementations in illustrative embodiments. In particular, they are described in the context of a functionally safe high-speed fail-safe counter module configured to perform fail-safe counting of specific electrical pulses. However, the embodiments of the present invention are not limited to use in the described apparatus or method.

[0028] The components and materials described below that constitute various embodiments are intended to be illustrative and not limiting. Many suitable components and materials that perform the same or similar functions as the materials described herein are intended to be included within the scope of embodiments of the invention.

[0029] The following refers to this article. Figures 1 to 18 These and other embodiments of the fail-safe counter module according to the present invention are described. The same reference numerals used in the drawings denote similar or identical elements in several views. The drawings are not necessarily drawn to scale.

[0030] According to one embodiment of the present invention, Figure 1 This is a block diagram illustrating a fail-safe counter module 105 coupled to an external quadrature encoder sensor 107 according to an exemplary embodiment of the present invention. The fail-safe counter module 105 is configured to perform fail-safe counting of specific electrical pulses. The fail-safe counter module 105 reports events and status based on configuration parameters in the distributed I / O system and external movement operations. It provides a SIN / COS encoder interface, which can safely count maximum speeds up to 200 kHz. Utilizing the new attributes of module 105 and its updated firmware, functional safety ratings (e.g., safety ratings for international standard levels such as Safety Integrity Level (SIL) 3, Category (CAT) 4, and Performance Level (PL)e) are fully implemented within the fail-safe counter module 105, and safety monitoring functions (e.g., providing a user interface to select and configure a "safety monitoring" function) are performed internally within the fail-safe counter module 105.

[0031] The fail-safe counter module 105 provides safety monitoring functions for monitoring speed, position, and / or direction. These safety monitoring functions can be optionally enabled to report safety events if configured safety limits are exceeded. The safety monitoring functions include: Safe Direction (SDI) for monitoring direction of movement, Safe Speed ​​Limit (SLS) for monitoring that movement does not exceed preset speed limits, and Safe Operation Stop (SOS) for monitoring unexpected movement.

[0032] Safety monitoring features are inherently included within module 105. These functions can be performed (monitored) up to Safety Integrity Level 3 (SIL 3) independently of any other device. This monitoring does not rely on a safety PLC. Depending on the customer configuration, module 105 compares the currently calculated count and / or speed with the configured limits. If a violation is detected, module 105 reports the violation to the customer's PLC safety program. The safety program can then take any action necessary to bring the process to a safe state. The customer can freely use three different functions: when external movement should stop (SOS), but then moves beyond the configured limit, module 105 detects and reports a violation; when external movement should move only in one direction (SDI), but then moves beyond the configured limit in the opposite direction, module 105 detects and reports a violation; and when external movement is in progress (SLS), but its speed is too fast (moving too fast), module 105 detects and reports a violation.

[0033] Module 105 can optionally (based on customer choice) safely monitor speed, direction, or deviation from the stop position. Module 105 does this exclusively, meaning it does not depend on any other logic or device. This capability is contained solely in the module's firmware. Customers can enable and disable this function (safety monitoring). Then, when safety monitoring is required based on the customer's application needs, the customer's safety control program 110 can enable and disable it. For example, when movement should stop, the customer's safety control program 110 can notify module 105 that it should not move. If it does move, module 105 can report the violation to the customer's safety control program 110. The customer does not need to create logic to accomplish this behavior.

[0034] Functional safety-related systems primarily concern applications where failures could affect the safety of people and / or the environment. Therefore, safety-related systems are used to mitigate hazards or failures that could lead to physical damage. Their aim is to achieve a level of safety with acceptable risk. Fail-safe systems are used to control processes and ensure a safe state when a failure is detected. Faults are detected using a very high level of diagnostic coverage. Upon detection of a fault, actions are taken to attempt to bring the corresponding application to a safe state. Fail-safe systems provide improved fault detection and fault location through detailed diagnostic identification and reporting. This is the main difference between fail-safe systems and standard systems. Fail-safe systems should be considered for applications where hazards are inherent and could lead to physical damage. Module 105 meets the safety ratings defined in international standards; for example, it supports safety-related applications of SIL CL3 conforming to EN 62061 or Category 4, PL e conforming to EN 13849-1.

[0035] The fail-safe counter module 105 includes a controller 112, which includes a processor 115(1) and a memory 115(2). The fail-safe counter module 105 also includes circuitry 117 and computer-readable security rating support code 120(1) stored in the memory 115(2), which, when executed by the processor 115(1), causes the controller 112 to provide security ratings to international standard levels such as Security Integrity Level (SIL) 3, Category (CAT) 4, and Performance Level (PL)e 121. The fail-safe counter module 105 also includes computer-readable "security monitoring" function code 120(2) stored in the memory 115(2), which, when executed by the processor 115(1), causes the controller 112 to work with a user interface 122 to select and configure the "security monitoring" function 125. The user interface 122 should be located in a portal 126 for configuring security functions. The fail-safe counter module 105 is a functionally safe rated device with expected ratings for Safety Integrity Level (SIL) 3, Category (CAT) 4, Performance Level (PL) e applications, and is designed to calculate position 127(1) and / or speed 127(2) using an external quadrature encoder sensor 107 that generates a waveform 130 that allows counting of specific electrical pulses 132. The portal and corresponding user interface are executed on a PC connected to the PLC via downloaded configuration and programming information. The module including this F-TM-C module is connected to the PLC and receives its parameterization from the PLC, which originates from the TIA portal user interface. The only dynamic user interface inherent in the module is LEDs.

[0036] The fail-safe counter module 105 also includes a safety-rated high-speed counter input channel 135. The fail-safe counter module 105 also includes computer-readable firmware code 120 (3) stored in memory 115 (2) that, when executed by processor 115 (1), causes controller 112 to provide a 32-bit resolution, signed integer representation 137, and a count value 140 scaled to engineering units. The fail-safe counter module 105 also includes a Sin / Cos interface 142. The fail-safe counter module 105 also includes a Sin / Cos 4-wire differential electrical interface 145 that wires the fail-safe counter module 105 to an external quadrature encoder sensor 107. Electrical signals from the external quadrature encoder sensor 107 are used to establish a high-speed count that can be used to indicate position 127 (1) and / or speed 127 (2).

[0037] The failsafe counter module 105 independently implements Safety Integrity Level (SIL) 3, Category (CAT) 4, and Performance Level (PL)e safety ratings without any external dependency on the application program 147 executing within the Safety Rated Programmable Logic Controller (PLC) 150. Because the "Safety Monitoring" function 125 is independent of any external monitoring dependency from the Safety Rated Programmable Logic Controller (PLC) 150, the failsafe counter module 105 executes a separate "Safety Monitoring" function 125 within itself. Therefore, the "Safety Monitoring" function 125 is executed entirely within the failsafe counter module 105, which also independently implements Safety Integrity Level (SIL) 3, Category (CAT) 4, and Performance Level (PL)e safety ratings. The "Safety Monitoring" function 125 includes the configuration of "Measurements" 155. The "Measurements" 155 include a frequency measurement (FMV) 155 (1), a period measurement (PMV) 155 (2), and a speed measurement (VMV) 155 (3).

[0038] For measurement determination, the user can select one of the following reported measurements at a time: frequency measurements in millihertz (-8000000000 to +800000000 means -800000.0000 to +800000.000 Hz), period measurements in microseconds (-25000000 to +25000000 means 25.000000 to +25.000000 seconds), and velocity measurements calculated as velocity × 1000, including the fractional part of the calculation (-2147483648 to 2147483647 means -2147483.648 to +2147483.647 velocity units). All measurements are returned as scaled integers with the above units. Negative values ​​are reported when the count is below 0, and positive values ​​are reported as the count increases.

[0039] For speeds in feet per second, set the "Speed ​​Measurement Time Base" field to the value "1 second" and the "Counts per Speed ​​Unit" to how many counts the encoder will generate per engineering unit. The speed value returned to the safe procedure will be the engineering unit value per second × 1000. Multiplying the feet per second value by 1000 ensures the speed value has sufficient resolution to display the calculated fractional portion. The fail-safe counter module 105 evaluates the input frequency. When the encoder signal frequency reaches the maximum frequency rating (200 kHz), a reintegrable frequency error is generated.

[0040] refer to Figure 2This diagram illustrates a hardware representation of a fail-safe counter module 205 coupled to an external quadrature encoder sensor 207 according to an exemplary embodiment of the present invention. A rack 210 is shown, on which a PLC 212 with a CPU and the fail-safe counter module 205 are mounted. The rack 210 includes an input (I / P) module (safety) 215 connected to a safety emergency stop button 217 and an output (O / P) module 220 connected to a motor 222. The rack 210 includes functional safety modules and non-functional safety modules. The rack 210 is connected to a display monitor 225, which displays a user interface 230, etc., for the fail-safe counter module 205.

[0041] Now go to Figure 3 The diagram shows three prototype views A305(1), B305(2), and C305(3) of a fail-safe counter module 205 according to an exemplary embodiment of the present invention. The fail-safe counter module 205 has a 15mm wide module housing. The input and output values ​​of the safety-related fail-safe counter module 205 are addressed using process mapping. The fail-safe counter module 205 uses a fail-safe CPU for safety processing. The fail-safe counter module 205 reports to the F-CPU when parameter limits are exceeded. The firmware code in the safety program (this is safety application code created and downloaded from a PC, which is not truly "firmware" code in the conventional sense) checks safety monitoring event data from module 205 and takes necessary actions to produce appropriate results (e.g., slowing down or stopping movement).

[0042] The fail-safe counter module 205 monitors encoder signals and evaluates them as quadrature encoded signals. The counting direction is determined by the phase relationship of the encoder signals. The fail-safe counter module 205 can be configured to configure the behavior of the counter at a counting limit. The counting limit defines the range of counter values ​​used. The user can configure a starting value within the counting limit.

[0043] To configure the parameters of the fail-safe counter module 205, various parameters can be used to specify the properties of the fail-safe counter module 205. Depending on the settings, not all parameters are available. You will set the module's parameters as follows: 1. Insert the CPU, PROFINET, or PROFIBUS interface module from the hardware catalog; 2. Insert the fail-safe counter module 205 from the hardware catalog under "Technical Modules -> Counting -> F-TM Counting"; 3. Select the fail-safe counter module 205 (in the device view or device overview) and view the module's "Properties" tab; 4. In the "Properties" view, on the "General" tab, select the drop-down arrows for "Module Parameters" and "TM-C Parameters" and view the attribute subsets of "F-Parameters" and "TM-C Parameters"; 5. Select one of the "F-Parameters" or "TM-C Parameters" attributes in the left-hand attribute tree, and then set the value in the attribute field on the right; 6. Successfully compile and download the hardware configuration to the fail-safe CPU to automatically configure the fail-safe counter module 205.

[0044] Figure 4 A schematic diagram of the output image register 405 of a fail-safe counter module 205 according to an exemplary embodiment of the present invention is shown. The SW gate is a user program control bit that allows the counter to start counting when enabled (open). Setting to start value is a user program command that resets the current counter value to the configured start value. Safety direction enabled is a user program command for performing "Safety Direction" monitoring (SDI). Safety direction is the specification of the safety direction. Stop status enabled is a user program command for performing "Safe Operation Stop" monitoring (SOS). Speed ​​monitoring enabled is a user program command for performing "Safe Speed" monitoring (SLS). Reset event is a user program command that clears the event and status bits.

[0045] like Figure 5 The diagram illustrates an input image register 505 of a fail-safe counter module 205 according to an exemplary embodiment of the present invention. The input image register 505 contains counter values, various status and event information. For example, HSC counter values, 32-bit integer counts, and corresponding HSC scaling values ​​(speed, frequency, ...). It further includes statuses: set to indicate various status activities and actions. It further includes safety function events: set when a safety function is violated. It further includes up / down flow events: set whenever a corresponding counter limit is exceeded. It further includes zero-crossing events: set at positive / negative count transitions.

[0046] like Figure 6As shown, it illustrates a schematic diagram of a general parameterization page 605 for a fail-safe counter according to an exemplary embodiment of the present invention. The general parameterization page 605 includes the Sin / Cos HF (high characteristic) properties of the fail-safe counter module 205.

[0047] exist Figure 7 The diagram illustrates a schematic of a TM-C parameterization page 705 for fail-safe counting according to an exemplary embodiment of the present invention. The TM-C parameterization page 705 includes counting type: active (always enabled because there is only one channel), counting pulse (always returns), and measurement engineering units (always returns): - frequency (default), -- or -- speed, -- or -- cycle duration.

[0048] about Figure 8 This diagram illustrates a safety monitoring function 805 for fail-safe counters according to an exemplary embodiment of the present invention. The safety monitoring function 805 is configured and executed in the fail-safe counter module 205. The safety monitoring function 805 includes safety limits for speed (moving too fast), safety stops for operation (complete movement), and safety directions (unintentional movement in an unsafe direction).

[0049] about Figure 9 This diagram illustrates a measured value—velocity—of a fail-safe count according to an exemplary embodiment of the present invention. The measured values ​​are selected as follows: update time is the minimum interval between each calculated measurement; time base is an optional time unit used in the velocity calculation; and count is the specification of the total count per unit distance measured (500 counts / meter). The ranges are: update time: 5 milliseconds to 25000 milliseconds (5ms estimation module scan); time base: 1 millisecond, 10 milliseconds, 100 milliseconds, 1 second, 60 seconds; and count per unit: 1 to 64K. The algorithm is: Velocity = (Total Count / Update Time) × (Time Base) / (Count per Unit). The velocity is returned in fixed integer notation, with the least significant 3 bits representing a precision of 3 decimal places, and a signed 32-bit number representing the velocity unit × 1000.

[0050] Figure 10 A schematic diagram of the measured value-frequency of a fail-safe count according to an exemplary embodiment of the present invention is shown. The measured value is selected as follows: the update time is the interval between measured values ​​(Note: the actual unit is Hertz × 1000 (millihertz). The range is: update time: 5 milliseconds to 25000 milliseconds (5ms estimation module scan). The algorithm is: frequency = (current count at update time) / (update time), the frequency is returned in fixed integer notation, the least significant 3 bits represent a precision of 3 decimal places, and the signed 32-bit number represents Hertz × 1000.

[0051] Figure 11A schematic diagram of the measured value-cycle duration of a fail-safe count according to an exemplary embodiment of the present invention is shown. The measured value is selected as follows: the update time is the interval between measured values ​​(note: the actual unit is seconds). The range is: time: 5 milliseconds to 25000 milliseconds (5ms estimation module scan). The algorithm is: cycle duration = 1 / (frequency), the cycle is returned with a fixed integer sign, the least significant 6 digits represent a precision of 6 decimal places, and the signed 32-bit number represents microseconds.

[0052] Figure 12 Tables 1 and 2 illustrate Safety Integrity Levels (SIL) and Performance Levels (PL) according to exemplary embodiments of the present invention. Table 1 shows SIL levels 1-3 and their hourly probabilities of hazardous failures. Table 2 shows PL levels a-e and their average hourly probabilities of hazardous failures.

[0053] Figure 13 A schematic diagram of a common board 1305 and a counter input board 1307 of a fail-safe counter module 1310 according to an exemplary embodiment of the present invention is shown. The common board 1305, with minor deviations, can be common to all modules. The counter input board 1307 is unique to each module. The common board 1305 includes a redundant microprocessor and supporting logic. The counter input board 1307 includes circuitry for interfacing with an externally provided encoder.

[0054] Figure 14 A schematic diagram showing additional details of a common board 1305 of a fail-safe counter module 1310 according to an exemplary embodiment of the present invention is shown. The additional details of the common board 1305 include a first microcontroller 1405 (1) and a second microcontroller 1405 (2). ROM and RAM are contained within the microprocessors of the first microcontroller 1405 (1) and the second microcontroller 1405 (2). The common board 1305 also includes a temperature monitor, power supply, and crystal for each microprocessor.

[0055] Figure 15 A schematic diagram showing additional details of the counter input board 1307 of a fail-safe counter module 1310 according to an exemplary embodiment of the present invention is provided. The counter input board 1307 includes the circuitry necessary to interface with externally provided encoder signals and monitor the accuracy of these signals. These signals are then routed to a microprocessor that performs the actual counting.

[0056] Figure 16 A schematic diagram of the software architecture 1605 of the fail-safe counter module 1310 according to an exemplary embodiment of the present invention is shown. Figure 16The overall software architecture of the fail-safe counter module 1310 is shown. The "ET200SpFtmc" section 1610 of software architecture 1605 is the only addition to this module. This section 1610 of software architecture 1605 is responsible for ensuring that the counts are consistent with fail-safe requirements. It also performs the calculation and monitoring of "counter measurements". These capabilities are one of the unique and novel features of the fail-safe counter module 1310. Measurements specify one of three possible conversions in engineering units as follows: Frequency: average counts per second, in millihertz (Hz × 1000); Period duration: average period between two counts (microseconds) (seconds × 1000000); Speed: speed of movement in a given direction. Speed ​​is expressed as measurement units per time base × 1000.

[0057] The SOS function monitors the count value and notifies the user when the encoder / counter deviates from the stop position by a specified amount. SLS monitoring is initiated whenever the "Enable Safe Speed" bit is set in the control interface and subsequently processed by the fail-safe counter module 1310. SLS monitoring terminates whenever the "Enable Safe Speed" bit is reset in the process output image and subsequently processed by the module. A "Safe Speed ​​Event" is set whenever the calculated speed in either direction exceeds the configured "Speed ​​Limit". Once set, the "Safe Speed ​​Event" bit remains set and continues counting after the event is triggered. The "Safe Speed ​​Event" remains set until the "Reset Safe Speed" control bit is 1, until a power cycle, or until a new parameterization is loaded. Configuring the "Speed ​​Limit" value to 0 causes the "Safe Speed ​​Event" to be set immediately after the first pulse in either direction.

[0058] SDI monitoring is initiated whenever the "Enable Safe Direction" bit is set in the control interface and subsequently processed by the fail-safe counter module 1310. SDI monitoring terminates whenever the "Enable Safe Direction" bit is reset in the process output image and subsequently processed by the module. Each time safe direction monitoring is initiated, the current position and the specified safe direction are stored. The "Safe Direction Event" bit is set whenever movement in an unsafe direction is detected and exceeds the configured "Monitoring Tolerance". The "Monitoring Tolerance" is measured from the farthest position reached in the safe direction. The movement tolerance in the unsafe direction should be measured from this farthest position as movement proceeds along the safe direction. Configure the monitoring tolerance in the count. Specify the safe direction in the process output image. Once set, the "Safe Direction Event" bit remains set and continues counting after the event is triggered. The "Safe Direction Event" remains set until the "Reset Safe Direction" bit is set to 1, until a power cycle, or until a new parameterization is loaded. Configuring a value of 0 for the monitoring tolerance causes the "Safe Direction Event" to be set immediately after the first pulse in the unsafe direction.

[0059] Figure 17A schematic diagram of a user interface 1705 for a safety monitoring function of a fail-safe counter module 1310 according to an exemplary embodiment of the present invention is shown. The user interface 1705 should be provided in a portal for configuring safety functions. The user interface 1705 should be provided for selecting and configuring "safety monitoring" functions. These functions include the configuration of "measured values". Note that only one of the three possible measured values ​​can be returned. However, the following requirements specify the behavior of all three selections. The user interface 1705 should be provided in a portal for configuring frequency calculation. The user interface 1705 should be provided in a portal for configuring cycle calculation. The user interface 1705 should be provided in a portal for configuring speed calculation. Safety-related parameterization can be performed by transferring safety-related configuration parameters to module 1310 via any fail-safe input / output (FI / O) module.

[0060] Figure 18 A schematic flowchart of a method 1800 for fail-safe counting according to an exemplary embodiment of the present invention is shown. (See attached diagram.) Figures 1 to 17 The components and features described herein. It should be understood that some steps do not need to be performed in any particular order, and some steps are optional.

[0061] Method 1800 includes step 1805 of providing a controller including a processor and memory. Method 1800 also includes step 1810 of providing circuitry for fail-safe counting. Method 1800 further includes step 1815 of providing computer-readable safety rating support code stored in memory, which, when executed by the processor, causes the controller to: provide a safety rating at an international standard level, such as Safety Integrity Level (SIL) 3, Category (CAT) 4, Performance Level (PL)e. Method 1800 further includes step 1820 of providing computer-readable "safety monitoring" function code stored in the memory, which, when executed by the processor, causes the controller to: provide a user interface for selecting and configuring the "safety monitoring" function. The fail-safe counter module is configured as a functional safety rated device with a desired rating for Safety Integrity Level (SIL) 3, Category (CAT) 4, Performance Level (PL)e applications, and is designed to calculate position and / or speed using an external quadrature encoder sensor that generates waveforms that allow counting of specific electrical pulses.

[0062] While a functionally safe high-speed fail-safe counter module configured to perform fail-safe counting for specific electrical pulses has been described herein, the invention also contemplates the scope of one or more other types or forms of modules. For example, other types of modules may be implemented based on one or more features presented above without departing from the spirit of the invention.

[0063] The techniques described herein are particularly useful for the specific configuration and programming software of a portal. Although specific embodiments are described with reference to the specific configuration and programming software of a portal, the techniques described herein are not limited to such limited configuration and programming software, but can also be used with other configuration and programming software.

[0064] While embodiments of the invention have been disclosed by way of example, it will be apparent to those skilled in the art that many modifications, additions and deletions may be made therein without departing from the spirit and scope of the invention and its equivalents as set forth in the following claims.

[0065] The embodiments and their various features and advantageous details are explained more fully with reference to the non-limiting embodiments illustrated in the accompanying drawings and detailed in the following description. Descriptions of well-known starting materials, processing techniques, components, and equipment have been omitted to avoid unnecessarily obscuring the details of the embodiments. However, it should be understood that the detailed descriptions and specific embodiments, while indicating preferred embodiments, are given by way of illustration only and not by way of limitation. Various substitutions, modifications, additions, and / or rearrangements within the spirit and / or scope of the basic inventive concept will become apparent to those skilled in the art based on the content of this invention.

[0066] As used herein, the terms “comprising,” “including,” “including,” “having,” “comprising,” or any other variation thereof are intended to cover non-exclusive inclusion. For example, a process, article, or apparatus that comprises a list of elements is not necessarily limited to those elements, but may include other elements not expressly listed or inherent to such process, article, or apparatus.

[0067] Furthermore, any examples or descriptions given herein should not be construed as limiting, defining, or expressing the definition of any term or term used in any way. Rather, these examples or descriptions should be considered as descriptions relative to a particular embodiment and are illustrative only. Those skilled in the art will understand that any one or more terms used with these examples or descriptions will cover other embodiments that may or may not be given with them or elsewhere in the specification, and all such embodiments are intended to be included within the scope of such one or more terms.

[0068] The invention has been described in the foregoing specification with reference to specific embodiments. However, those skilled in the art will understand that various modifications and changes can be made without departing from the scope of the invention. Therefore, the specification and drawings are to be considered illustrative rather than restrictive, and all such modifications are intended to be included within the scope of the invention.

[0069] Although the invention has been described with reference to specific embodiments thereof, these embodiments are merely illustrative and not intended to limit the invention. The description of the illustrated embodiments herein is not intended to be exhaustive or to limit the invention to the precise forms disclosed herein (in particular, the inclusion of any particular embodiment, feature, or function is not intended to limit the scope of the invention to such embodiments, features, or functions). Rather, this description is intended to describe illustrative embodiments, features, and functions to enable those skilled in the art to understand the invention, without limiting the invention to any particularly described embodiments, features, or functions. While specific embodiments and examples of the invention have been described herein for illustrative purposes only, various equivalent modifications can be made within the spirit and scope of the invention, as will be recognized and understood by those skilled in the art. As noted, these modifications can be made to the invention according to the foregoing description of the illustrated embodiments, and these modifications will be included within the spirit and scope of the invention. Therefore, while the invention has been described herein with reference to specific embodiments thereof, modifications, various changes, and substitutions are intended in the foregoing disclosure, and it should be understood that in some cases, certain features of embodiments of the invention will be adopted without correspondingly using other features, without departing from the scope and spirit of the invention. Therefore, many modifications can be made to adapt particular situations or materials to the basic scope and spirit of the invention.

[0070] The phrases “in one embodiment,” “in an embodiment,” or “in a particular embodiment,” or similar terms appearing in different places throughout the specification, do not necessarily refer to the same embodiment. Furthermore, a particular feature, structure, or characteristic of any particular embodiment may be combined with one or more other embodiments in any suitable manner. It should be understood that other variations and modifications of the embodiments described and illustrated herein are possible in accordance with the teachings herein and are considered part of the spirit and scope of the invention.

[0071] Throughout this description, numerous specific details, such as examples of components and / or methods, are provided to provide a thorough understanding of embodiments of the invention. However, those skilled in the art will recognize that embodiments may be implemented without one or more of these specific details, or using other means, systems, components, methods, parts, materials, etc. In other instances, well-known structures, parts, systems, materials, or operations have not been specifically shown or described in detail to avoid obscuring various aspects of the embodiments of the invention. While the invention may be illustrated using specific embodiments, this is not and does not limit the invention to any particular embodiment, and those skilled in the art will recognize that other embodiments are readily understood and are part of the invention.

[0072] It should also be understood that one or more elements depicted in the accompanying drawings may also be implemented in a more discrete or integrated manner, or even removed or rendered inoperable in some cases, which may be useful depending on the specific application.

[0073] The benefits, other advantages, and solutions to problems have been described above with respect to specific embodiments. However, any benefits, advantages, solutions to problems, and any components that may cause any benefit, advantage, or solution to occur or become more significant should not be construed as critical, essential, or necessary features or components.

Claims

1. A fail-safe counter module, comprising: a controller comprising a processor and a memory; circuitry for fail-safe counting; computer readable safety rating support code stored in the memory that, when executed by the processor, causes the controller to: provide an international standard level of safety rating, including Safety Integrity Level SIL 3, Category CAT 4, Performance Level PLe; and computer readable "safety monitoring" function code stored in the memory that, when executed by the processor, causes the controller to: select and configure "safety monitoring" functions with a user interface, wherein the fail-safe counter module is a functionally safe rated device with an intended rating for Safety Integrity Level SIL 3, Category CAT 4, Performance Level PLe applications, and the fail-safe counter module is designed to calculate position and / or velocity with an external quadrature encoder sensor that produces a waveform that allows counting of specific electrical pulses, the fail-safe counter module further comprising: a Sin / Cos 4 wire differential electrical interface configured to wire the fail-safe counter module to the external quadrature encoder sensor, and the Sin / Cos 4 wire differential electrical interface is configured to safely count up to a maximum speed of 200 kHz, wherein the fail-safe counter module performs separate "safety monitoring" functions inside the fail-safe counter module that are independent of any external monitoring dependencies from a safety rated programmable logic controller (PLC) such that the "safety monitoring" functions are performed entirely within the fail-safe counter module, which also independently implements Safety Integrity Level SIL 3, Category CAT 4, Performance Level PLe safety ratings.

2. The failsafe counter module of claim 1, further comprising: safety rated high speed counter input channels.

3. The fail-safe counter module of claim 1, further comprising: computer readable firmware code stored in the memory that, when executed by the processor, causes the controller to: provide 32-bit resolution, signed integer representation, and count values scaled to engineering units.

4. The failsafe counter module of claim 3, wherein, electrical signals from the external quadrature encoder sensor are used to establish high speed counts that can be used to indicate the position and / or velocity.

5. The failsafe counter module of claim 1, wherein, the fail-safe counter module independently implements Safety Integrity Level SIL 3, Category CAT 4, Performance Level PLe safety ratings without any external dependencies on applications executing within a safety rated programmable logic controller (PLC).

6. The failsafe counter module of claim 1, wherein, the "safety monitoring" functions include configuration of "measured values".

7. The failsafe counter module of claim 6, wherein, the "measured values" include frequency measured values, period measured values, and velocity measured values.

8. A method for fail-safe counting, the method comprising: providing a controller comprising a processor and a memory; providing circuitry for fail-safe counting; providing computer readable safety rating support code stored in the memory that, when executed by the processor, causes the controller to: provide an international standard rated safety rating, including Safety Integrity Level SIL 3, Category CAT 4, Performance Level PLe; providing computer readable "safety monitoring" function code stored in the memory that, when executed by the processor, causes the controller to: select and configure "safety monitoring" functions with a user interface, wherein the fail-safe counter module is a functionally safe rated device with an expected rating for Safety Integrity Level SIL 3, Category CAT 4, Performance Level PLe applications, and the fail-safe counter module is designed to calculate position and / or velocity with an external quadrature encoder sensor that produces a waveform that allows counting of specific electrical pulses, the method further comprising: providing a Sin / Cos 4 wire differential electrical interface to wire the fail-safe counter module to the external quadrature encoder sensor, and the Sin / Cos 4 wire differential electrical interface is configured to safely count up to a maximum speed of 200 kHz, wherein the fail-safe counter module performs separate "safety monitoring" functions inside the fail-safe counter module that are independent of any external monitoring dependencies from a safety rated programmable logic controller (PLC) such that the "safety monitoring" functions are performed entirely within the fail-safe counter module, which also independently implements Safety Integrity Level SIL 3, Category CAT 4, Performance Level PLe safety ratings.

9. The method of claim 8, further comprising: providing a safety rated high speed counter input channel.

10. The method of claim 8, further comprising: providing computer readable firmware code stored in the memory that, when executed by the processor, causes the controller to: provide a 32 bit resolution, signed integer representation, and count values scaled to engineering units.

11. The method of claim 10, wherein, electrical signals from the external quadrature encoder sensor are used to establish high speed counts that can be used to indicate the position and / or velocity.

12. The method of claim 8, wherein, the fail-safe counter module independently implements Safety Integrity Level SIL 3, Category CAT 4, Performance Level PLe safety ratings without any external dependencies on applications executing within a safety rated programmable logic controller (PLC).

13. The method of claim 8, wherein, the "safety monitoring" functions include configuration of "measured values".

14. The method of claim 13, wherein, the "measured values" include frequency measured values, period measured values, and velocity measured values.

Citation Information

Patent Citations

  • Frequency synthesizer output cycle counter including ring encoder

    CN107112999A

  • Anti-interference design method for program counter of CPU

    CN1274113A

  • Test Functionality Integrity Verification for Integrated Circuit Design

    US20130074023A1

  • Implementing counters in a system with limited primary memory

    US6065130A