Self-recovery laser safety system with automatic diagnostic system
By designing a diagnostic system in a laser safety system, monitoring and responding to interlock failures, and using backup interlocks to ensure safe operation, the problem of the ineffectiveness of multiple interlock failures in the prior art is solved, and higher reliability and safety are achieved.
Patent Information
- Application Number
- CN202380059516.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2022-07-07
- Filing Date
- 2023-07-06
- Publication Date
- 2025-05-02
AI Technical Summary
Existing laser safety systems may not adequately or effectively protect users and the environment in the event of multiple interlock failures or combination failures, resulting in the security system not working.
A diagnostic system is designed to detect and respond to interlock failures by monitoring the function of safety interlocking, ensuring that the laser system enters a safe state and restores normal operation in the event of a transient failure. The system uses backup interlock to ensure that the laser system can operate safely in the event of a main interlock failure.
Effectively prevent users from being exposed to potentially dangerous laser beams, ensure that the laser system can safely resume normal operation in the event of failure, and improve the reliability and safety of the laser safety system.
Smart Images

Figure CN119923635A_ABST
Abstract
Description
Technical Field
[0001] This disclosure describes technology related to the field of safety systems in laser systems, and in particular to the problem of ensuring the functionality of such safety systems. Background Art
[0002] High-power laser systems that are accessible to general users without specific training in laser safety should be protected by multiple safety interlocks, each of which is configured so that it provides a warning or performs a corrective action if a condition occurs that would enable a system user, a bystander, or even an animal or inanimate object to access or come into contact with a high-power and therefore dangerous laser beam. Such interlocks together form part of a safety system (also called automatic emission control), and a typical laser system may have several interlocks, each detecting a specific safety threat that may occur. In the absence of an interlock, a user may access a dangerous laser beam, or the beam may be released into the space surrounding the laser system. An interlock may be understood as a circuit comprising sensors, logic elements, and output systems, the function of which is to ensure that the conditions under which the laser system operates are safe. Thus, they provide a warning or corrective action for external threats. Several such safety systems are described in many patents and patent applications, including, for example, "Optical wireless power system" in US11,356,183, "Optical wireless power system" in US 9,866,075, "Flexible optical wireless power management system" in US11,322,991, "Fail-safe optical wireless power supply" in US 110,70,298, and "Laser power transmission system in an environment with gas heating or cooking" in patent application IL 291878, all of which are assigned to the present applicant.
[0003] In some cases, laser safety systems should be redundant in that there should be at least two interlocks protecting against the same safety threat so that if one interlock fails to operate, there will always be at least another backup interlock to protect the user or environment from threats created by a safety system failure. Some prior art systems do incorporate such redundancy provisions. However, even with built-in redundancy, there may be situations where an interlock fails, or a combination of such failures occur, which would render the safety system inadequate or even inoperative.
[0004] The disclosure of each publication mentioned in this section and other sections of the specification is incorporated herein by reference in its entirety. Summary of the invention
[0005] The present disclosure attempts to provide new systems and methods that overcome at least some of the shortcomings of prior art systems and methods. In particular, the present disclosure provides a monitoring or diagnostic system that monitors the function of the safety interlock itself to ensure that a failure of the interlock or a combination of such interlock failures is detected. Such a failure will render the safety system inadequate, or even inoperative. Such a fault detection mechanism or diagnostic system is known from that part of ISO 13849, which is intended to provide guidance in the design and evaluation of machine control systems and should issue a warning and take positive safety actions to control the operation of the laser system in the event of such a failure of the safety system. In addition, if the diagnostic system determines that the interlock failure is caused by a transient fault, the diagnostic system should be able to execute and monitor methods to safely return the laser system to normal operation, which transient fault itself may be accompanied by the condition of the laser system or the surrounding environment returning to its normal level.
[0006] Thus, the present disclosure describes a new exemplary system for a diagnostic system that detects and responds to failures in sensors, components, or overall circuits in various interlocks of a laser safety system, such that in the event of a failure in one of the interlock circuits, the diagnostic system can indicate changes to the operating conditions of the laser, or even shut down the laser, to prevent the user from being exposed to a potentially dangerous laser beam. Thus, in situations where the reliability of the laser safety system may be compromised by the failure of one or more interlocks, which, if they were functioning properly, would cause the safety system to take necessary safety measures, the diagnostic system performs functions that the laser safety system itself should perform, sometimes similar functions. Thus, although the interlock system typically performs these actions to protect the user or the environment only when a hazard occurs, the diagnostic system performs these actions in response to a sensor or component or circuit failure rather than in response to the hazard, as the safety system should do if there is no detected interlock failure. Thus, the diagnostic system itself is not a safety system, but rather a system that checks whether all interlocks that make up the safety system are functioning properly and are free of failures. The diagnostic system typically does this by monitoring sensors, circuit outputs, and measurements used as inputs to the various interlocks, as well as sensors that indicate the good working condition of the logic elements of the safety system. When the monitor displays a value outside of the acceptable range or when there is no output at all, the diagnostic system indicates a system fault and operates to ensure the continued safety of the laser system. One way the diagnostic system can accomplish this is by ensuring that the laser system switches to a safe state with limited output designed to prevent any potentially harmful beam delivery, and optionally and additionally ensuring that the laser system is prevented from switching to its high power normal state. The circuitry, software, or control elements that achieve this result may also be referred to as safety interlocks because they provide inputs to the laser system to ensure the safety of its users.
[0007] Failures in the interlock system can be divided into two categories. Some such failures may be caused by physical component failures. Some examples of such component failures may include burnout of electronic components such as sensors or transistors, short circuits, interrupted wiring, or damaged reflectors or windows. Such failures are usually permanent, at least until repaired, and should prevent the laser system from continuing to operate until the component problem is corrected, usually by means external to the system. So, for example, a damaged or broken mirror will remain that way until a technician repairs or replaces the mirror. Or, in the case of these problems, the problem will remain until an automated repair system performs some operation, such as automated self-cleaning of the optical surfaces, to repair the surface degradation.
[0008] Other failures may be caused by transient events, such as environmental conditions including temperature, dust, humidity, radiation, electronic or acoustic noise or vibration, and other influences that cause temporary faulty readings, or temporarily prevent the detection system, logic system, or switch from operating, thereby temporarily preventing the interlock system from functioning properly. These failures are usually related to external influences on the system. Some examples of such external influences include parameter measurement sensors, lasers or their power supplies, or photovoltaic cells, or sensors blocked by sunlight, or electronic noise interference, gamma particles emitted by the sun, transient external magnetic field effects on circuits or components, or external mechanical shocks, which cause vibratory motion of the mirror but do not permanently damage or move the mirror, or any similar external influences.
[0009] It is often difficult for diagnostic systems to determine whether a fault event is temporary or permanent. Thus, for example, components may be subjected to external conditions until they reach a physical state that is outside their operating specifications, such as exposure to excessively high or low temperatures. Such events can be described as transient events because when the temporary condition passes, the component will resume normal operation and fulfill its circuit function.
[0010] The diagnostic system is configured to monitor the operational status of the interlocks and respond if a problem in the interlock is detected that is severe enough to be considered to have failed to provide a warning signal. The default response is to place the laser system into a safe state, typically by reducing laser power or shutting down the laser completely, to prevent the laser system from entering a state that could involve a hazard even in the safe state. Once in a safe state, when the problem detected is a transient fault, it is necessary to determine whether the transient fault has passed. Since laser power may be required to detect whether the transient problem has ended, the question is how to restore the laser system to safe operation if the diagnostic system finds at least one faulty interlock that may or may not be able to provide a hazard warning. Any attempt to restore the laser system to operation may be accompanied by a safety problem. Without a properly functioning interlock, there is no way to determine whether the laser system will operate safely, and without turning on the laser, there may be no way to ensure that the transient problem has passed.
[0011] To overcome this problem, the diagnostic system described herein uses a new configuration in which a procedure is employed to use a second, independent system check and control procedure to operate as a backup interlock. This may be a temporary interlock whose function is simply to determine that the laser system is in a safe state and operation can be commenced again, even if the initial primary interlock that warned of a laser system fault does not provide permission to commence laser system operation again. Once the primary interlock is clearly determined to be operating normally, because its fault condition has subsided or has been repaired, the backup interlock procedure can be abandoned and the primary interlock can be relied upon to perform its function again.
[0012] Interlocks can therefore be divided into two groups. Primary interlocks are generally those that analyze the operating characteristics of the system, as well as provide warning indications and take action if a system malfunction results in a beam transmission that is harmful to the user or the surroundings. Such interlocks are referred to as complex interlocks due to their generally more complex operating modes, and include interlocks such as power accounting systems that check the difference between the transmitted beam power and the received beam power to calculate whether an intrusion into the beam has occurred. Other interlocks, such as those based on the measurement of certain operating parameters of the laser power supply, such as the measurement of the laser current, or on the monitoring of the beam level reflected by the receiver, and others, also direct interlocks, whose function is generally to directly monitor the correct operation of the system and intervene if a hazardous situation arises.
[0013] Other types of interlocks are those that, once a system failure is detected, are used to ensure that the laser is prevented from operating in a manner that produces hazardous radiation even in the event of a system failure, when one or more of the primary interlocks may not be operational. Such interlocks are therefore temporary interlocks that are only implemented if the primary interlocks are inoperative due to a system failure. Therefore, these interlocks may be referred to as backup interlocks or simple interlocks, as their functionality is generally less complex than that of the primary interlocks.
[0014] There are a number of procedures that can be used as simple and temporary interlocks. Of these procedures, two are particularly easy to apply because they involve only the control of the laser beam power exposure and do not require the manipulation of any other parameters or system components. The first simple interlock involves the diagnostic system imposing a limit on the power at which the laser is allowed to operate, to or below the permitted or accessible exposure limit (AEL), so that no hazardous situation can be created even if the original failed portion of the primary interlock system remains inoperative. The second temporary interlock can be implemented by limiting the time that the laser is allowed to emit its beam to a duration less than the permitted integrated exposure limit. Of course, a combination of these two temporary interlocks can be used. One or two of these temporary interlocks or one or more alternative temporary backup interlocks can be applied until the diagnostic system receives confirmation that the event that caused the primary interlock to indicate a fault has been resolved. Once this condition is reached, the operation of the laser system can be restored to its full original level. Other alternative temporary backup interlocks can use a variety of functions, such as rapidly scanning the laser beam across a patterned array so that even if the laser is emitted at high power, it will not expose areas on the trespasser for a long enough time to enter an overexposure situation. Another backup interlock may be the activation of a beam blocking function, which absorbs the beam. Another backup interlock could be attenuation or diffusion of the laser beam power so that it is below the permitted power limit. Finally, beam steering capabilities could be used to direct the beam into a cleared area where it is known that humans cannot enter the area.
[0015] These simple or alternate interlocks are used to ensure that under fault conditions, the laser can be operated, but in a controlled low output state, or in a configuration that does not expose the user or any point in the environment to laser power for a duration longer than permitted by the laser beam power above. Under these conditions, the fault can be investigated and self-corrected or restored to normal as described below.
[0016] If the diagnostic system does not receive confirmation that the system has resumed correct operation, the laser will not fire at higher power levels. This is a procedure used for persistent or more accurately non-transient faults, such as damaged components, shorted or open electronic functions, damaged lenses, etc., which will not correct themselves until the problem that caused the fault is repaired. Once this is completed, usually by maintenance personnel, the maintenance personnel should issue a confirmation signal that the fault has ended and can restart the laser system based on this confirmation signal.
[0017] The diagnostic system must be run even if there are multiple interlocks in operation, for example if, in addition to the interlock currently being tested, there is at least one additional interlock providing a safety function.
[0018] Such a safety diagnostic system should be an important adjunct to the safety system of any high power laser system, because without such a diagnostic system, the laser system will cease to operate in many seemingly trivial events, such as the loss of digits in a computer routine due to a noise spike in the power supply. In a laser wireless charging system, which does not require charging or replacing batteries and should be able and expected to operate for a long time without further attention after setup, the need for a safety system that can self-recover from transient events is extremely important. The safety diagnostic system of the present disclosure is intended to achieve such a reliable safety system for a laser power wireless transmission system.
[0019] In the common case of a user blocking the beam, the interlock system should respond and put the system in a safe state. These operations are well described in several prior art references and patents, as well as in industry implemented safety standards, such as 21CFR1040.10 in the United States and IEC60825-1 in many other countries.
[0020] As previously mentioned, the safety system should be provided with multiple interlocks to provide backup protection in the event that one interlock fails to provide warning of a system failure. Backup interlocks may operate on different physical features of the laser system to provide diverse coverage in the event of a circuit or component failure. In addition, backup interlocks may be provided that operate in the same manner as the first interlock.
[0021] Thus, the redundancy in the safety system also allows the system to remain safe when one interlock fails. However, if two interlocks fail, the system may become unsafe. Even if the probability of two interlocks failing simultaneously is extremely low, if one of these interlocks fails permanently and remains in a failed state for a long period of time, which is not monitored by the diagnostic system, for example through periodic testing of the system, then the system will remain protected for a considerable additional time, but only by the remaining single interlock. During the same long period of time, the probability of a second interlock failing is now higher because the second interlock has been operating for the entire period of time until the failure of the first interlock was discovered. The present diagnostic system limits the maximum time that an interlock is in a failed state while allowing the system to remain operational by using a time criterion for a fault-finding routine or by a counting routine that counts the frequency with which the fault-finding routine is executed, which is scheduled to run at predetermined intervals.
[0022] Therefore, the system requires a self-diagnostic function that periodically or continuously monitors the interlocks to verify whether they are in good working condition. According to one embodiment of the diagnostic system of the present application, this can be achieved by comparing the output of one interlock with another interlock, or comparing the input signal of one interlock with the input signal of another interlock. Under normal working conditions, the response needs to be similar, that is, both point to similar dangers at similar times, but if one interlock fails, the response will be different, and a danger warning should be issued and appropriate action should be taken.
[0023] The above-described subsystem that performs self-diagnostic testing of various aspects of the safety system interlocks is referred to in this disclosure as a diagnostic system.
[0024] When the diagnostic system detects a malfunction in the safety system, the diagnostic system should bring the laser system to a safe state, for example according to functional safety standards such as ISO 13849. This is usually achieved by terminating the laser beam and issuing a warning signal to the user.
[0025] In particular, such a diagnostic system should also be able to recover from a safe state and resume normal operation in the event that the fault is determined to be a transient fault. For such transient faults, the diagnostic system should use at least a second interlock to ensure that when the laser system is started again, it operates under a safe procedure. Once operating again, the diagnostic system can determine whether the transient fault has passed and whether the main interlock has operated again, so that the laser system can be restarted or allowed to reach a higher power without waiting for an external signal to be issued, as in the case of a permanent fault that is repaired by maintenance actions. Therefore, this restart process is performed without risk to the user or the environment.
[0026] Transient faults can be caused by noise, so comparing the output of a sensor to the output of another sensor or to a fixed or calculated value can cause the comparison criteria to temporarily exceed the allowed boundaries that define correct function. This causes a transient diagnostic event to occur, causing the system to enter a safe mode. Similarly, this can occur if the output of a sensor appears to be outside the set limits that define correct operation. These limits can be predetermined or calculated based on the operating parameters of the laser system.
[0027] Other transient conditions caused by external influences on the system should mean that transient diagnostic coverage events are assumed, such as components being exposed to temperatures outside their operating specifications, or signals from sensors may be affected by light, magnetic fields, electric fields, or electromagnetic waves, which may temporarily change the readings.
[0028] Another class of such transient events may occur in software errors, where a software anomaly (e.g., a race condition between different software threads, or a random change in a bit) may cause, for example, a temporary problem in reading data from a memory cell. Similarly, a warning signal from a watchdog that a CPU has failed may be considered a transient fault, which will be corrected at the next cyclic watchdog check of the system, typically by reloading the relevant data from memory and measuring the input again, or by restarting.
[0029] Transient faults can also be caused by mechanical shock to a component. Thus, for example, a mechanical vibration may temporarily "bend" an optical component from its position without causing permanent damage. Once the external mechanical shock has passed, the optical component will usually return to its correct position and the transient fault will cease.
[0030] Other examples involve environmental or weather conditions, as changes in air pressure, humidity, or dust content may alter the optical paths in the system.
[0031] In the event that an interlock is tested without operating the laser, the system should generally do so. For example, if an interlock fails or may fail due to excessive component temperature, the current temperature of the component causing the interlock failure or potential failure can be determined without turning on the laser. In this case, the diagnostic system prevents the laser from turning on until the temperature returns to within normal limits.
[0032] However, in many cases, it is not possible to test the interlocks of a laser-based wireless power system without operating the laser. The present diagnostic system includes procedures for safely handling such transient fault conditions by using a temporary safety system to enable operation of the laser at limited laser power or laser time, or in this case limit another laser parameter to allow the laser to be safely turned on until the main interlock has restored normal operation. Such a temporary safety system is generally implemented by the diagnostic system described in the present disclosure.
[0033] To summarize the differences between the pre-existing interlock protection scheme and the interlock protection scheme of the present application, it can be noted that depending on the interlock level applied to the system, the laser system will accordingly enter a safer state.
[0034] Therefore, if the laser is intentionally turned off and remains off, the system is inherently safe in what can be referred to as State 1.
[0035] If the laser is turned on, in a low power safety state, and maintained at that low power by the dual power limiting circuits, the system is fail-safe, that is, if one of the power limiting circuits fails, the other power limiting circuit will take over protection, which can be called State 2.
[0036] If the laser is on, in a high power safety state, and maintained safe by at least two interlocks preventing user exposure to dangerous levels, this is a safe state typically shown in the high level safety interlock system described previously, which can be called State 3.
[0037] Finally, the diagnostic system of the present disclosure describes a system where, if a fault occurs in one of the interlocks of a system providing state 3 protection, the current diagnostic system enables the system to safely test whether the faulty interlock begins to become operational again, even though this test may only make sense by operating the laser at full power. This is achieved by applying a temporary additional interlock to ensure that at least two interlocks are operational and to allow safe testing of the faulty system at high power, a situation referred to as state 4.
[0038] Thus, according to an exemplary embodiment of the apparatus described in the present disclosure, there is provided a method for diagnostic supervision of a laser system including a plurality of essential interlocks that enable a safety system to ensure safe transmission of laser power, the method comprising the following steps:
[0039] (i) monitoring data from sensors that provide information about the operation of the primary interlocks to detect erroneous outputs that fall outside a normally expected output range, such erroneous outputs indicating a fault in the primary interlock associated with the sensor that exhibited the erroneous output;
[0040] (ii) upon detection of a fault in at least one essential interlock, place the laser system in a safe state by limiting the delivered laser power level or shutting down the laser, and
[0041] (iii) determining from a predetermined list of fault classifications whether the at least one interlock fault is characteristic of a persistent fault requiring external intervention to calibrate, or a transient fault that is expected to resolve over time, wherein:
[0042] (a) if the interlock failure is determined to be characteristic of a persistent fault, maintain the laser system in a safe state, and
[0043] (b) If it is determined that the interlock failure is characteristic of a transient fault, temporarily applying at least one backup interlock to enable safe operation of the laser until the fault in the at least one primary interlock disappears, and deactivating the temporarily applied at least one backup interlock.
[0044] In this method, the determination as to whether a fault in at least one basic interlock has disappeared can be performed at successive predetermined times until the fault has disappeared. In addition, the at least one backup interlock can include any one of maintaining the transmitted laser power at a limited level or limiting the time that the transmitted laser power is emitted.
[0045] Furthermore, in the above method, if the fault in the basic interlock does not disappear after a predetermined number of consecutive times, it can be concluded that the fault of the basic interlock is not temporary but permanent. In this case, the method should provide a warning that external intervention is required, should wait for receipt of an external indication that the fault has been corrected, and if received, should enable the laser system to be restored from a safe state to normal operation.
[0046] The above method may also provide a step of preventing the laser system from entering a high output state if at least one basic interlock failure is detected. Such basic interlock may be adapted to detect a failure of at least one of an electronic circuit, a sensor, a control system logic circuit, an electronic component, and an optical component.
[0047] Furthermore, according to another embodiment of the method of the present application, diagnostic supervision of the laser system may include the step of monitoring all laser system basic interlocks before determining that the fault in the basic interlock has disappeared and the laser system can operate in a high output state.
[0048] Furthermore, in any of these methods, the at least one backup interlock that is temporarily applied may also include any of the following:
[0049] (i) scanning the laser beam so that it is not pointed in any direction for a period of time that would exceed the safe exposure time for the beam power level,
[0050] (ii) blocking or diffusing the laser beam,
[0051] (iii) attenuating the laser beam, and
[0052] (iv) Direct the laser beam in a direction known to be safe.
[0053] In case a failure in at least one primary interlock is detected, any of the temporarily applied backup interlocks should be adapted to provide redundant safety so that the laser system can be operated without limiting the transmitted laser power level.
[0054] According to another embodiment of the method of the present disclosure, there is also provided a method for ensuring transient fault recovery in a master interlock of a safety system from a laser transmitter, the method comprising the following steps:
[0055] switching the laser transmitter to a safe state with limited output power,
[0056] Apply at least one backup interlock to perform at least one of the following:
[0057] (i) ensuring that the laser transmitter is in a limited power output state,
[0058] (ii) limiting the duration of said laser transmission to a safe level of said power output being transmitted,
[0059] (iii) scanning the laser beam to prevent the laser beam from impinging on any location for more than a predetermined time,
[0060] (iv) blocking the propagation of the laser beam,
[0061] (v) attenuating the laser beam, and
[0062] (vi) directing the laser beam in a safe direction,
[0063] After carrying out at least one of said steps (i) to (vi), increasing the laser output and checking the correct function of at least said master interlock with said transient fault, and allowing normal full operation of said laser system if at least said master interlock with said transient fault shows correct function,
[0064] However, if at least the master interlock with the transient fault does not show correct function, returning the laser system to a safe state with limited output, waiting a predetermined time, increasing the laser output and re-performing at least one of steps (i) to (vi), and repeating the step of checking the correct function of at least the master interlock with the transient fault.
[0065] In the method, the step of checking the correct function of at least the main interlock with the transient fault may comprise:
[0066] checking that the interlock sensor is performing correctly, which indicates that the transient fault in the interlock has been mitigated,
[0067] Check the logic circuits that oversee the operation of the interlocks to ensure correct operation, and
[0068] Check the correct function of the control system to bring the laser system into a safe state.
[0069] In the former method, after the laser emitter is switched to a safe state with limited output power, the system can be prevented from switching to its normal full power state. In addition, the step of blocking the propagation of the laser beam can be performed by an opaque object or a diffusive object.
[0070] Furthermore, it is permitted to increase the laser output of the laser system after implementing at least one of steps (i) to (vi) because the system is now protected by at least one backup interlock to provide redundancy in the absence of the main interlock showing the transient fault. In this case, if checking the correct function of at least the main interlock with the transient fault shows correct operation, normal full operation of the laser system is permitted because the system is now protected by at least one backup interlock in the temporary backup interlock to provide redundancy for the main interlock in the absence of the main interlock showing the transient fault.
[0071] Additionally, in any of these methods, if at least the primary interlock with the transient fault exhibits correct function, at least one backup interlock may be deactivated. Additionally, in these methods, the step of checking the correct operation of the logic circuitry supervising the operation of the interlock may be accomplished by using a watchdog circuit. Furthermore, the step of checking the logic circuitry supervising the operation of the interlock may be accomplished by observing whether the sensor output is within the expected logic range of the slave sensor.
[0072] Finally, as an illustration, the diagnostic system described in this disclosure uses various types of secondary interlocks to enable the laser system to be operated to test whether a primary interlock fault has been corrected. Throughout this disclosure, such secondary interlocks may be variously referred to as backup interlocks, or temporary interlocks, or redundant interlocks, or similar descriptions, and it should be understood that all of these terms refer to the same functional interlock entity. BRIEF DESCRIPTION OF THE DRAWINGS
[0073] The present invention will be more fully understood and appreciated from the following detailed description taken in conjunction with the accompanying drawings, in which:
[0074] Figure 1 An exemplary flow chart of a method is shown by which a diagnostic system monitors the presence of a fault in an interlock of a high power laser system and, upon detection of such a fault, controls operations necessary to ensure system safety and restore normal operation; and
[0075] Figure 2 An exemplary flow chart of a method by which a diagnostic system safely restores a high power laser system to normal operation when the laser system requires operation of the laser in order to achieve a return to normal operation is shown. DETAILED DESCRIPTION
[0076] Reference now Figure 1, which schematically illustrates an overview of an exemplary method by which a diagnostic system may be used to (i) monitor the presence of a fault in an interlock of a high power laser system, and (ii) control operations required to ensure system safety after detection of such a fault, and (iii) return the laser system to safe operation after detection of such a fault indication without endangering the user or anything else in the vicinity of the laser system. The normal operating state of the laser system is referred to as the "interlock protection state", i.e., normal protective operation using an interlock to alert the user of a potentially hazardous situation caused by a fault or condition until the fault is cleared, or until the user removes him / herself from the hazardous situation.
[0077] In step 102, the laser system is brought into a safe, limited output state and, further, is prevented from switching to its normal output operating state due to suspected danger of continued operation of the laser system with a non-functional interlock.
[0078] In step 103, the diagnostic system controller then determines whether the dissident reading is suspected to be caused by a potential transient problem, such as excessive noise levels, or extreme temperatures, or noise in the electronic environment or other external problems. This determination typically involves comparing whether the parameters of the dissident reading meet specific criteria, usually predefined, known to be likely to indicate a transient problem, but also unrelated to a fault that may cause common persistent faults in multiple safety-related subsystems. This step is a predictive estimate because the diagnostic system only knows that a rogue reading has been obtained and now the true source must be determined. An initial determination can be made by checking whether the detected fault is compatible with faults listed on a database list of predetermined problems, which are typically found to be transient problems. If the specific fault detected does not match a fault on this list, it is assumed that the fault does not indicate a transient problem and is likely to be a "persistent" fault because it will not disappear without intervention.
[0079] In step 104, the diagnostic controller then maintains the laser system in a safe limited output state, or even shuts down the laser for certain types of faults that may suggest taking this action, and may generate a warning signal to indicate that external intervention is required. Optionally, a service call is also activated so that repair or maintenance work can be performed. At the same time, the diagnostic system controller continues to prevent the laser system from switching to its regular output, or even continues to keep the laser off so that no laser output is produced. This state is maintained until an external signal is received in the diagnostic system controller from a service or maintenance person or from an automated external system (such as a cleaning robot or a software patch) to indicate that the fault has now been repaired, and the laser system can then be restored to normal operation in step 104.
[0080] On the other hand, if in step 103, the database list or the system's programming routine indicates that the associated fault may be related to a transient problem, then in step 105, the system remains in its safe, limited output state for a predetermined time, even with the laser turned off. Then, by waiting for the predetermined time in step 105 to observe whether the deviation reading remains at an unacceptable level, which may indicate that a permanent fault has occurred in the system, or whether the deviation reading has changed, which may indicate that there has been a fluctuation due to external factors and therefore an impact on the component, circuit, measurement device or sensor, etc., so that a temporary problem has occurred, providing additional clues to determine whether the fault is a fixed fault or a transient fault.
[0081] After waiting a predetermined time in step 105, before continuing the process of determining whether the transient problem has passed, the operating status of the diagnostic system should be checked in step 106 to ensure that it is properly monitoring all required parameters of the laser system interlocks. Thus, for example, testing the output of a suspect sensor that produced an out-of-range reading against a known and valid reference level will confirm whether the suspect sensor and its associated interlock have been restored to a proper operating state.
[0082] If, in step 106, it is found that the diagnostic system itself may not be functioning properly, it is deemed dangerous to continue executing the procedure for determining when the transient fault of the laser system has ended - if it is indeed a transient fault - and the controller restores the system to step 104 and waits in a safe state or shutdown state until confirmation is received in step 104 that the fault has been repaired.
[0083] If, on the other hand, in step 106, confirmation has been received that the diagnostic system is in a correct operating state, then in step 107, a system counter is started. The function of the counter is to keep track of the number of times or time increments that have passed in repeatedly performing such a fault test. The counter may be a counter that determines the number of iterative attempts that have been made to determine whether the fault has been cleared, or it may be a timing counter that is sequentially incremented at fixed time intervals as determined in step 105, in which case the "counter" would be a timer that measures the time that has elapsed since the fault test was applied in the previous sequential test cycle.
[0084] Since in step 106, the diagnostic system is considered to be operational, and therefore the system is safely monitored, in step 108, additional spare or redundant interlocks are implemented, and the laser power can be increased, wherein the interlocks (both the main interlock and the spare interlock) are known to be in the correct working order, and the interlocks are applied when the laser power level is increased. Therefore, a test can be performed on whether the original fault still exists. These spare or redundant interlocks can be, for example, the operation of the laser at a reduced power level or within a limited duration, so that the exposure of the laser beam is limited to acceptable safety conditions. Any other interlocks that ensure that the emitted light beam does not have danger (such as fast scanning light beams, or blocking light beams, or activating beam attenuators or diffusers, or directing light beams to safe directions) can also be used as spare interlocks to ensure the safe operation of the laser when its power is increased. In the case of laser operation, the diagnostic system now has the opportunity to determine whether the system failure problem still exists, such as by determining whether the deviation reading still deviates from the limit of its expected level.
[0085] If it is determined in step 108 that there is no indication that the fault problem has been resolved, then in step 109 the laser is turned down to a limited output state, or turned off completely and is prevented from switching to a high state, and a counter or timer is advanced to indicate that another system test cycle has been performed. Since a finite number of test cycles should be performed, in order to avoid infinite test iterations, then in step 110 the system interrogates the counter / timer system to determine if a maximum number of cycles have been performed. If not, the method returns to step 105, waits a predetermined time and starts the test cycle process again from step 106 onwards. If the maximum number of test cycles have been performed, then in step 111 the system is interrogated to determine if the fault has been cleared, and if not, the fault is assumed to be a persistent fault and the laser is turned off in step 112 to await a technical repair, as in step 104.
[0086] If, on the other hand, in step 108 the method determines that there is a positive indication that the problem has been resolved, then even before the maximum number of iterations has been performed, the diagnostic system no longer prevents the laser from operating at its full power, although an interlock or operating parameter of the system may still prevent it from doing so, depending on other parameters that are not related to the fault found in the system and that are now remedied. The system is therefore considered to be fully operational again, so that the operation of the backup interlock can now be stopped, and in step 113 the laser system is enabled at its full power.
[0087] Reference now Figure 2, which schematically illustrates an exemplary method by which a diagnostic system can safely test whether a transient fault in a primary interlock has passed and the interlock has returned to normal monitoring function, thereby allowing the laser system to resume its full functionality.
[0088] In step 201 , a diagnostic system determines that a fault problem has been detected in a primary interlock, typically by receiving outputs from one or more sensors and comparing the output levels to predetermined or calculated limits.
[0089] In step 202, after a fault is detected based on the test results in step 201, the system enters a safe state, either with a limited output level or with the laser turned off. The system must have at least one safe state, and at least one state that is guaranteed safe by the interlock system, but this will be unsafe without a sufficient number of interlocks operating.
[0090] Then in the safe state, in step 203, the system is prevented from entering the "interlock protection state", ie, normal protection operation using the main interlock to warn of a potentially hazardous situation, until the fault is cleared.
[0091] In step 204, the diagnostic system controller checks whether the problem found is on a predetermined database list of problems that may be transient faults. If the problem is not on the "transient list", it is considered to be of a more permanent nature and requires external intervention to resolve. In step 220, the diagnostic system may optionally wait a predetermined time and then briefly increase the laser power for a period shorter than exceeding the allowable exposure limit of the beam to test whether the fault persists. If the fault persists, or if the previously mentioned fault confirmation test has not been performed, a warning is issued that the fault may be permanent, and the laser system will continue to be blocked from switching to the high power state of the "interlock protection state" until an external event occurs, such as maintenance or user attention.
[0092] Only if it is identified in step 204 that the fault may be transient, will the system wait for a predetermined time in a safe, limited performance state, or wait for a predetermined time when entering a shutdown state, in step 205, and then, before enabling the laser to resume its full power output capability, perform at least one of the following operations, all of which operate as backup interlocks to ensure safety in the event of a primary interlock failure:
[0093] 206 limits the laser output power.
[0094] 207 limits the duration that the laser emits its beam.
[0095] 208 continuously changes the alignment direction of the beam unit, for example by performing a scanning motion process, so that the laser is not pointed in one direction for a period of time, which may exceed the safe exposure time for the power level.
[0096] 209 Block the light beam with an opaque object or diffuse the collimated light beam with a diffusing object.
[0097] 210 attenuates the light beam.
[0098] 211 directs the beam to a known safe beam absorbing target or beam block, or to a direction where the beam is known to be non-harmful.
[0099] In step 212, once at least one of the previous steps 206 to 211 has been implemented, the laser can now be turned on at its increased power level, i.e., the interlock protection state is now implemented because the system is now protected by at least one of the temporary backup interlocks of steps 206 to 221 to provide redundancy for the main interlock in the absence of a failed main interlock.
[0100] Now that at least one of these safeguards is in place, the diagnostic system typically performs a series of tests to ensure that each interlock is operable in all aspects of its functionality. The tests may advantageously include an evaluation of the following three aspects of interlock functionality:
[0101] (a) sensor functionality, such as a temperature monitor, which will be checked by comparing its value to the result of another test of the temperature;
[0102] (b) logic functions, such as determining whether the indicated temperature is outside the conceivable range for the measurement, which logic functions are typically tested by a watchdog; and
[0103] (c) Output functions, such as the action of turning off a laser, can be tested by attempting to turn off the laser to see if the output function is operational.
[0104] Apply this process to Figure 2 The method will take the following steps:
[0105] In step 213, a test is performed to ensure that a previously failed interlock sensor designed to provide a risk indication is performing properly, typically by measuring a sensor response (eg, a temperature monitor output) against a reference response.
[0106] In step 214, a test is performed to determine whether the entire interlock function component is operating correctly in providing logically acceptable results, that is, whether the sensors and sensor outputs are operating correctly, and whether the logic circuit or analog circuit that performs the "logical operation" ("logic" can be a simple comparison of a value with a threshold) is working properly, which usually uses a watchdog on the controller and detects whether the output function of the circuit is normal.
[0107] In step 215, a test is performed to determine whether the switch or control function that allows the system to enter a safe state is operating correctly. As is known, this is correct at this stage because the system is already in a safe state, but procedural circumstances may arise that make this test necessary.
[0108] All three of the above tests are checked in step 216, and if the problem is found to have passed or automatically corrected, then in step 217, the diagnostic system controller provides instructions for enabling the laser system to resume normal operation up to its full power output, and the temporary backup interlock applied in steps (i) to (vi) may be deactivated.
[0109] On the other hand, if in step 216 it is determined that any of the tests 213, 214, 215 are unsuccessful and the fault problem has not subsided, then the system is restricted to a low power state in step 218 and is prevented from switching to a normal operating state in step 219, and the diagnostic control algorithm returns the system to step 205 where the system is instructed to wait in its limited performance state before the safety process of steps 206 to 216 is started again.
[0110] To illustrate the above process, an example scenario of how the diagnostic system operates in an exemplary real-world situation uses an exemplary wireless power laser system that is protected from inadvertent intrusion by a user through two primary or basic interlocks, both of which are known from the previously described systems. The first interlock is an intrusion detection system that uses an optical sensor (such as a camera) to detect when a person approaches or moves within the beam path. The second interlock is a "power accounting system" that compares the power emitted by the laser to the power received by the receiver to determine if the power lost during transmission exceeds a limit that may indicate that the beam has been intruded.
[0111] The system includes an interlock diagnostic system of the type described in this disclosure that is capable of monitoring a variety of fault conditions.
[0112] Some typical faults that the diagnostic system of the present application can handle are now described.For camera-based systems, if the image is completely black, white, gray, or has white noise or static interference, it indicates a camera interlock problem.
[0113] If the watchdog of the controller used to process the image does not re-stabilize regularly, this indicates a further problem.
[0114] Another problem could be that the switch controller or circuit used to turn the laser off is not working properly. This can be tested by periodically turning the laser off.
[0115] For power accounting systems, a diagnostic fault indication will exist when the power measured by the transmitter's power output meter does not match the laser power expected based on the laser controller power setting, or when the system controller's watchdog does not periodically re-stabilize, or when the switch used to shut down the laser does not operate. Upon receipt of any such indication, the system will be switched to a limited performance, safe state. There is usually at least one additional switch to perform this function so that the loss of the first switch function does not leave the system unprotected.
[0116] If a switch or its control circuit designed to allow the system to shut down the laser does not function, this failure is not usually considered a transient problem, so the system will be permanently blocked from switching to the normal power state of the interlock protection until an external event occurs, such as maintenance intervention. In this case, the diagnostic system usually uses another switch to keep the laser off.
[0117] If the controller watchdog is not being reset periodically, the controller should be restarted and this may resolve the issue. This restart should be performed without turning on the laser.
[0118] If the camera shows a defective image, such as described above, the test should be retested, optionally without turning on the laser.
[0119] As another example of the diagnostic system of the present disclosure, one particular fault that should require more specific action is a fault of a power meter that is indicated as being faulty. In this case, the system will preferably perform an exemplary process such as:
[0120] (i) Place temporary limits on the laser output, typically exposure time limits or power limits, or application of scanning operations, either of which ensure that the laser does not exceed safe exposure limits.
[0121] (ii) The test is performed on the power meter, obviously with the laser beam switched on. Since safe exposure limits need to be adhered to, the test must be performed within a limited time, limiting the laser beam exposure time accordingly.
[0122] (iii) If the test does not indicate that the power meter is in good working order, the system is again restored to a safe state and after a predetermined time, during which it can be expected that if the power meter problem is a transient fault, it will subside during the predetermined time, the process of steps (i) to (iii) is repeated.
[0123] (iv) Assuming everything else is in order, the laser system can be restored to normal operation only when the power meter is tested as "operational".
[0124] Example embodiments are provided so that the present disclosure will be thorough and the scope will be fully conveyed to those skilled in the art. Many specific details, such as examples of specific components, devices and methods, are set forth to provide a thorough understanding of the embodiments of the present disclosure. It will be apparent to those skilled in the art that specific details need not be adopted, and the example embodiments may be embodied in many different forms, and none of them should be construed as limiting the scope of the present disclosure. In addition, it will be appreciated by those skilled in the art that the present invention is not limited to the contents specifically shown and described above. On the contrary, the scope of the present invention includes combinations and sub-combinations of the various features described above and variations and modifications thereto that those skilled in the art will expect when reading the above description and that are not in the prior art.
Claims
1. A method for diagnostic supervision of a laser system, the laser system comprising a plurality of basic interlocks enabling a safety system to ensure safe transmission of laser power, the method comprising the steps of: monitoring data from a sensor providing information regarding the operation of said essential interlock for an erroneous output that falls outside a normally expected range of outputs, such erroneous output indicating a fault in said essential interlock associated with said sensor showing said erroneous output; upon detection of a fault in at least one essential interlock, placing the laser system into a safe state by limiting the delivered laser power level or by shutting down the laser; and It is determined according to a predetermined list of fault classifications whether the at least one interlock fault has the following characteristics: (i) a persistent failure requiring external intervention to correct, or (ii) transient faults that are expected to decay over time; in: (a) if the interlock fault is determined to be characteristic of a permanent fault, maintaining the safe state of the laser system; and (b) if it is determined that the interlock fault has the characteristics of a transient fault, then: temporarily applying at least one backup interlock to enable the laser to be safely operated until the fault in the at least one primary interlock has disappeared; and deactivating the temporarily applied at least one backup interlock.
2. The method according to claim 1, wherein: The determination as to whether the fault in the at least one basic interlock has disappeared is performed at successive predetermined times until the fault has disappeared.
3. The method according to any one of claims 1 and 2, wherein: The at least one backup interlock includes any of maintaining the transmitted laser power at a limited level or limiting the time that the transmitted laser power is emitted.
4. A method according to any one of the preceding claims, wherein: If the fault in the basic interlock has not disappeared after a predetermined number of consecutive predetermined times, it is concluded that the fault in the basic interlock is not a transient fault but a permanent fault.
5. A method according to any one of the preceding claims, wherein: If the fault is determined to be characteristic of a persistent fault, a warning is provided that external intervention is required, an external indication is awaited that the fault has been corrected, and if received, the laser system is enabled to return to normal operation from its safe state.
6. The method according to any one of the preceding claims, further providing the step of preventing the laser system from entering a high output state if at least one basic interlock fault is detected.
7. A method according to any one of the preceding claims, wherein: The basic interlock is adapted to detect a malfunction in at least one of an electronic circuit, a sensor, a control system logic circuit, an electronic component, and an optical component.
8. A method according to any one of the preceding claims, wherein: The diagnostic supervision of the laser system includes the following steps: monitoring all laser system basic interlocks in the laser system basic interlocks before determining that the fault in the basic interlock has disappeared and the laser system is able to operate in a high output state.
9. A method according to any one of the preceding claims, wherein: The at least one backup interlock of the temporary application further comprises any of the following: scanning the laser beam so that it is not pointed in any direction for a time that may exceed a safe exposure time for the power level of the beam; blocking or diffusing the laser beam; attenuating the laser beam; as well as The laser beam is directed in a direction that is known to be safe.
10. A method according to any one of the preceding claims, wherein: The temporarily applied at least one backup interlock is adapted to provide redundant safety in case of detection of said failure in at least one essential interlock, such that the laser system can be operated without limiting the transmitted laser power level.
11. A method for ensuring recovery from a transient fault in a primary interlock of a safety system for a laser transmitter, the method comprising the steps of: Switching the laser transmitter to a safe state with limited output power; Apply at least one backup interlock to perform at least one of the following: (i) ensuring that the laser transmitter is in a limited power output state; (ii) limiting the duration of said laser transmission to a safe level of said power output transmitted; (iii) scanning the laser beam to prevent the laser beam from impinging on any location for longer than a predetermined time; (iv) blocking the propagation of the laser beam; (v) attenuating the laser beam; as well as (vi) directing the laser beam into a safe direction; After carrying out at least one of said steps (i) to (vi), increasing the laser output and checking said correct function of said main interlock with at least said transient fault; as well as (a) allowing full operation of the laser system if the primary interlock with at least the transient fault exhibits correct function; but (b) if at least the master interlock with the transient fault does not show correct function, returning the laser system to a safe state with limited output, waiting a predetermined time, increasing the laser output and re-performing at least one of steps (i) to (vi), and repeating the step of checking the correct function of at least the master interlock with the transient fault.
12. The method according to claim 11, wherein: The step of checking the correct function of at least the main interlock with the transient fault comprises: checking that the interlock sensor is performing properly, indicating that the transient fault in the interlock has been mitigated; checking logic circuitry overseeing said operation of said interlock to ensure proper operation; and The correct function of the control system is checked for bringing the laser system into a safe state.
13. The method according to any one of claims 11 and 12, wherein: After switching the laser transmitter to a safe state with limited output power, the system is prevented from switching to its normal full power state.
14. The method according to any one of claims 11 to 13, wherein: The step of blocking the propagation of the laser beam is performed by an opaque object or by a diffusive object.
15. The method according to any one of claims 11 to 14, wherein: The laser output of the laser system is allowed to be increased after performing at least one of steps (i) to (vi) because the system is now protected by at least one backup interlock to provide redundancy in the absence of the primary interlock showing a transient fault.
16. The method according to claim 15, wherein: If checking the correct functionality of at least the main interlock with the transient fault shows correct operation, normal full operation of the laser system is permitted because the system is now protected by at least one of the temporary backup interlocks to provide redundancy to the main interlock in the absence of the main interlock showing the transient fault.
17. The method according to any one of claims 11 to 16, wherein: If at least the primary interlock having the transient fault exhibits correct functionality, the at least one backup interlock may be deactivated.
18. The method according to any one of claims 11 to 17, wherein: The step of checking the correct operation of the logic circuit supervising the operation of the interlock is achieved by using a watchdog circuit.
19. The method according to any one of claims 11 to 17, wherein: The step of checking the logic circuitry overseeing the operation of the interlock is accomplished by observing whether the sensor output is within a logic range expected from the sensor.
Citation Information
Patent Citations
Laser based gas detector
IL291878A
Fail-safe optical wireless power supply
US11070298B2
Flexible management system for optical wireless power supply
US11322991B2
System for optical wireless power supply
US11356183B2
System for optical wireless power supply
US9866075B2