Accelerator safety interlocking system based on hardware interlocking and application method

The hardware interlocking system monitors the status of the accelerator laboratory in real time and directly controls the start, stop and opening and closing of the controlled units, solving the problem of software control errors in the accelerator system and improving safety and reliability.

CN120676519APending Publication Date: 2025-09-19CHINA INST FOR RADIATION PROTECTION
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510897430.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-01
Publication Date
2025-09-19

AI Technical Summary

Technical Problem

The existing accelerator system has complex networks and many on-site interference signals, which leads to software protocol control errors and cause personnel or facility accidents.

Method used

A hardware interlocking system is used to monitor the status of the accelerator laboratory in real time through the safety interlock monitoring unit, and the start, stop and opening and closing of the controlled unit are directly controlled by hardware switches, avoiding data transmission and software control.

Benefits of technology

The execution error rate of interlocking actions is reduced, the safety of personnel and facilities is improved, and the accident rate is reduced.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120676519A_ABST
    Figure CN120676519A_ABST
Patent Text Reader

Abstract

The invention relates to an accelerator safety interlocking system based on hardware interlocking and an application method.The accelerator safety interlocking system is characterized in that a safety interlocking monitoring unit is used for monitoring the working state in an accelerator laboratory in the current time period; the on-off output unit is connected with the safety interlocking monitoring unit through a wired circuit, a hardware switch is arranged in the on-off output unit, the safety interlocking monitoring unit controls interlocking actions of the hardware switch based on the working state, and the interlocking actions comprise opening and closing of the hardware switch; and the controlled unit is connected with the on-off output unit, the controlled unit changes the interlocking state based on the interlocking action of the hardware switch, and the interlocking state comprises operation and stop of the controlled unit. The purposes of directly controlling the on-off output unit and triggering the interlocking state of the controlled unit based on the connection of the leading-out line of the safety interlocking monitoring unit are achieved, and therefore the technical effects that the process of data transmission and software control is not needed, the execution error rate of interlocking actions is reduced, and the accident rate of personnel or facility operation is reduced are achieved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of accelerators, and in particular to an accelerator safety interlocking system based on hardware interlocking and an application method thereof. Background Art

[0002] Accelerator facilities are operated by personnel and work stably through control systems. However, due to the high radiation level around the beamline during operation and the need to prevent machine failures and perform machine safety protection during operation, a safety interlock design is required. When unsafe behavior occurs, the safety of personnel and machines is prioritized, and coordinated control is performed between the control system and the safety interlock system of the facility operation.

[0003] At present, the mainstream method is to implement graded responses to the control system and interlocking system through software protocols. However, due to the complexity of the accelerator system network system and the large number of on-site interference signals, data loss or communication interference is prone to occur, resulting in execution errors or unexecuted control errors, leading to serious personnel or facility operation accidents.

[0004] The above problems need to be solved urgently. Summary of the Invention

[0005] The present invention discloses an accelerator safety interlock system based on hardware interlock and an application method thereof, aiming to solve the technical problems existing in the prior art.

[0006] The present invention adopts the following technical solutions:

[0007] On the one hand, the present invention provides an accelerator safety interlock system based on hardware interlock, which includes: a safety interlock monitoring unit, used to monitor the working status in the accelerator laboratory in the current period; an on-off output unit, connected to the safety interlock monitoring unit through a wired line, a hardware switch is provided in the on-off output unit, and the safety interlock monitoring unit controls the interlocking action of the hardware switch based on the working status, wherein the interlocking action includes the opening and closing of the hardware switch; a controlled unit, connected to the on-off output unit, and changes the interlocking state based on the interlocking action of the hardware switch by the controlled unit, wherein the interlocking state includes the start and stop and / or opening and closing of the controlled unit.

[0008] Optionally, the controlled unit includes a power-off control type and an on-off control type, wherein the power-off control type is used to indicate that the controlled unit is directly circuit-connected to the on-off output unit, and the interlocking action of the hardware switch of the on-off output unit directly controls the interlocking state of the controlled unit; the on-off control type is used to indicate that the controlled unit is not circuit-connected to the on-off output unit, and indirectly controls the interlocking state of the controlled unit based on detecting the interlocking action of the hardware switch of the on-off output unit.

[0009] Optionally, in the case where the controlled unit is of the power-off control type, the accelerator safety interlock system also includes a power supply, and a series circuit is formed between the power supply and the power-off control type controlled unit through the on-off output unit; the interlocking action of the hardware switch in the on-off output unit controls the on-off of the series circuit, thereby directly controlling the interlocking state of the controlled unit.

[0010] Optionally, the power supply includes a positive power pole and a negative power pole; the hardware switch of the on-off output unit is two first hardware switches; the two first hardware switches are respectively connected to the positive power pole and the negative power pole of the power supply, and jointly control the on-off of the series circuit.

[0011] Optionally, when the controlled unit is of the on-off control type, the accelerator safety interlock system further includes an on-off detection unit; the on-off detection unit and the on-off output unit form a series circuit, and the on-off detection unit is communicatively connected with the controlled unit; the on-off detection unit is used to determine the interlocking action of the hardware switch in the on-off output unit, and control the interlocking state of the controlled unit based on the interlocking action of the hardware switch in the on-off output unit.

[0012] Optionally, the hardware switch of the on-off output unit is a second hardware switch; the second hardware switch is connected in series with the on-off detection unit to control the on-off of the series circuit.

[0013] Optionally, the on-off output unit also includes a manual reset button, which includes a button, a spring and a micro switch; the button is connected to the spring; the spring is located on one side of the micro switch, and the micro switch senses the pressing force of the spring to generate an electrical signal; the micro switch is connected to the hardware switch, and the electrical signal controls the hardware switch to trigger an interlocking action.

[0014] According to another aspect of an embodiment of the present invention, a method for applying an accelerator safety interlock system based on hardware interlock is provided. Applied to the hardware interlock system, a safety interlock monitoring unit monitors the working status of the accelerator laboratory in real time during the current period. When the working status is abnormal, the interlocking action of the hardware switch in the on-off output unit is triggered, disconnecting the series circuit. The controlled unit stops operating or closes.

[0015] Optionally, when the working state is converted to a safe state, the interlocking action of the hardware switch in the on-off output unit is triggered to connect the series circuit; and the controlled unit starts to run or turn on.

[0016] Optionally, the standard for the working state to change from an abnormal state to a safe state is that the working state remains in the safe state for at least 1 minute.

[0017] The technical solution adopted by the present invention can achieve at least one of the following beneficial effects:

[0018] In an embodiment of the present invention, a safety interlock monitoring unit is used to monitor the safety status within the accelerator laboratory during the current period; an on-off output unit is connected to the safety interlock monitoring unit via a wired line, the on-off output unit is provided with a hardware switch, and the safety interlock monitoring unit controls the interlocking action of the hardware switch based on the safety status, wherein the interlocking action includes opening and closing the hardware switch; and a controlled unit is connected to the on-off output unit, and the controlled unit changes the interlocking state based on the interlocking action of the hardware switch, wherein the interlocking state includes running and stopping the controlled unit. This achieves the purpose of directly controlling the on-off output unit based on the wired connection of the safety interlock monitoring unit and triggering the interlocking state of the controlled unit, thereby achieving the technical effect of reducing the execution error rate of the interlocking action and the rate of personnel or facility operation accidents without the need for data transmission and software control. This further solves the technical problem that due to the complex accelerator system network system and the large number of on-site interference signals, data loss or communication interference is easily caused when the software protocol responds to the control system and interlocking system in a hierarchical manner, resulting in execution errors or unexecuted control errors, leading to serious personnel or facility operation accidents. BRIEF DESCRIPTION OF THE DRAWINGS

[0019] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following briefly introduces the drawings required for describing the embodiments, which constitute a part of the present invention. The exemplary embodiments of the present invention and their descriptions are provided to explain the present invention and do not constitute an undue limitation of the present invention. In the drawings:

[0020] Figure 1 This is a power-off control structure diagram of an accelerator safety interlock system based on hardware interlock in Example 1 of the present invention;

[0021] Figure 2 This is a structural diagram of an on / off control class in an accelerator safety interlock system based on hardware interlock in Example 1 of the present invention;

[0022] Figure 3 This is a structural diagram of a manual reset button in an accelerator safety interlock system based on hardware interlock in Example 1 of the present invention;

[0023] Figure 4 is a flowchart of an accelerator safety interlock system application method based on hardware interlock in Example 3 of the present invention;

[0024] Figure 5 This is a logic process diagram of an application method of an accelerator safety interlock system based on hardware interlock in Example 3 of the present invention.

[0025] Description of reference numerals:

[0026] 1. Safety interlock monitoring unit; 21, 22. On / off output unit; 31, 32. Controlled unit; 4. Power supply; 5. On / off detection unit; 6. First hardware switch; 7. Second hardware switch; 8. Manual reset button; 9. Push button; 10. Spring; 11. Micro switch. DETAILED DESCRIPTION

[0027] To make the objectives, technical solutions, and advantages of the present invention more clear, the technical solutions of the present invention will be clearly and completely described below in conjunction with specific embodiments of the present invention and corresponding drawings. In the description of the present invention, it should be noted that the term "or" is generally used in the sense of including "and / or" unless the content clearly indicates otherwise.

[0028] In the description of the present invention, it should be noted that, unless otherwise clearly specified and limited, the terms "installed", "connected", and "connected" should be understood in a broad sense. For example, it can be a fixed connection, a detachable connection, or an integral connection; it can be a mechanical connection or a magnetic connection; it can be a direct connection, or it can be indirectly connected through an intermediate medium, or it can be a connection between the two elements. For ordinary technicians in this field, the specific meanings of the above terms in the present invention can be understood according to the specific circumstances. In addition, in the description of this application, the terms "first", "second", etc. are only used to distinguish the description, and cannot be understood as indicating or implying relative importance. In the description of the present invention, the meaning of "plurality" is at least two, such as two, three or more, etc., unless otherwise clearly specified and limited.

[0029] Obviously, the embodiments described are only some of the embodiments of the present invention, not all of them. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.

[0030] First, to facilitate understanding of the embodiments of the present invention, some of the terms or nouns involved in the present invention are explained below:

[0031] Hardware interlocking, also known as hard interlocking, is an interlocking mechanism implemented directly through physical devices or circuits. It does not rely on software or control systems, but instead uses hardware devices such as relays, switches, and mechanical devices to ensure that operations are executed only when specific conditions are met.

[0032] An accelerator is a device that uses artificial methods to generate high-energy charged particle beams. Its core function is to accelerate charged particles through electric or magnetic fields to achieve high speed or high energy.

[0033] To solve the problems existing in the related art, the embodiments of the present application provide an accelerator safety interlock system and application method based on hardware interlock.

[0034] Example 1

[0035] This embodiment provides an accelerator safety interlock system based on hardware interlocking, comprising: a safety interlock monitoring unit 1, configured to monitor the working status within an accelerator laboratory during the current period, wherein the working status includes a safe state and an abnormal state; an on-off output unit, connected to the safety interlock monitoring unit 1 via a wired line, wherein a hardware switch is provided within the on-off output unit, and wherein the safety interlock monitoring unit 1 controls the interlocking action of the hardware switch based on the working status, wherein the interlocking action includes opening and closing the hardware switch; and a controlled unit, configured to change the interlocking state based on the interlocking action of the hardware switch of the on-off output unit, wherein the interlocking state includes starting, stopping, and / or opening and closing of the controlled unit.

[0036] Optionally, the safety interlock monitoring unit 1 is a monitoring sensor responsible for monitoring the current safety status of the accelerator laboratory. The monitoring sensor can obtain a variety of safety data, such as radiation level, access control status, and the status of the emergency stop button 9. The safety interlock monitoring unit 1 needs to collect these data in real time and determine whether it is in a safe state. It should be noted that the safe state is a state that does not harm the body of the staff, or a state that can ensure the life safety of the staff. For example, when the radiation level is below 1 millisievert (mSv), the safety door is in an open state, allowing the staff to evacuate safely, which is a safe state. The emergency stop button 9 is in a normal use state and will not be unable to stop the equipment after being triggered. It is a safe state. When it is harmful to the body of the staff, or when the detected device cannot ensure the life safety of the personnel, it is an abnormal state, wherein the abnormal state and the safe state have opposite probability distributions.

[0037] The on / off output unit contains a hardware switch. Safety interlock monitoring unit 1 directly controls the opening or closing of the hardware switch based on the current safety status. The hardware switch is physically controlled and independent of software, resulting in high reliability. This is especially true in emergency situations where software system failures may occur. The hardware switch can still execute the interlocking action.

[0038] Optionally, the monitoring sensor corresponding to the safety interlock monitoring unit 1 has a built-in "AND gate" logic. After the monitored safety status data passes through the "AND gate" logic, it is output to the on-off output unit in a high or low level state. The high level and the low level are equivalent to the "on-off quantity". The high level corresponds to the open state of the hardware switch, and the low level corresponds to the closed state of the hardware switch. The safety interlock monitoring unit 1 is connected to the on-off output unit by wire. When the safety interlock monitoring unit 1 is at a high level, the hardware switch of the on-off output unit is forced to pop open, causing the entire circuit to form an open circuit state, thereby achieving safety protection. Among them, the hardware switch can be a relay.

[0039] Optionally, the controlled unit is connected to an on / off output unit. The interlocking status of the controlled unit depends on the state of the hardware switch. When the hardware switch is closed, the controlled unit can operate normally; when the switch is open, the access to the controlled unit is physically cut off, and operation stops. This effectively ensures that if the safety state is not met, the controlled unit can be stopped immediately to prevent danger.

[0040] Optionally, the safety interlock monitoring unit 1 monitors the safety status in the accelerator laboratory in real time. When a danger is detected, a high level is output to the hardware switch, and the hardware switch is quickly disconnected. The whole process does not exceed 10ms. The safety status is ensured by the hardware interlock device, and there is no need to transmit the monitoring data to the CPU processor. It can effectively avoid the erroneous execution or non-execution caused by bit errors or code loss, reduce the execution error rate of the interlocking action, and reduce the accident rate of personnel or facility operation.

[0041] In some preferred embodiments, the controlled unit includes a power-off control type and an on-off control type, wherein the power-off control type is used to indicate that the controlled unit 31 is directly circuit-connected with the on-off output unit 21, and the interlocking action of the hardware switch of the on-off output unit 21 directly controls the interlocking state of the controlled unit 31; the on-off control type is used to indicate that the controlled unit 32 is not circuit-connected with the on-off output unit 22, and the interlocking action of the hardware switch of the on-off output unit 22 indirectly controls the interlocking state of the controlled unit 32.

[0042] Optionally, in an accelerator laboratory, a variety of experimental devices may be potentially dangerous. These experimental devices include controlled units 31 (power-off control type) that can be directly driven by the power supply 4, and controlled units 32 (on-off control type) that cannot be directly driven by the power supply 4. Among them, the high-voltage steel cylinder power supply 4 is responsible for generating the high voltage required for accelerating particles. It is directly connected to the power supply 4. When the high-voltage steel cylinder power supply 4 fails, the high voltage in the steel cylinder cannot reach the required high voltage, which may cause the direction of the particles to deflect, thereby causing the particles to bombard the wall of the steel cylinder, causing damage to the steel cylinder. When the safety interlock monitoring unit 1 detects that the high-voltage steel cylinder power supply 4 is abnormal, the power supply 4 is cut off. The high-voltage steel cylinder power supply 4 will also lose high voltage and cannot accelerate the particles, avoiding particle direction deviation. The high-voltage steel cylinder power supply 4 is quickly cut off by triggering the hardware switch. The response speed of the whole process is within 10ms, and there is no error or loss of code caused by erroneous execution or non-execution.

[0043] Optionally, the electric beam gate is a gate set on the beam path. It can quickly cut off or conduct the beam path by opening and closing the gate, protecting equipment such as magnets and targets from accidental high-energy particle bombardment. The electric beam gate is not directly connected to the power supply 4 and cannot be controlled by cutting off the power supply 4. Therefore, it is necessary to detect the on-off state of the on-off output unit 22, that is, to determine whether the on-off output unit 22 has triggered an interlocking action. When the on-off output unit 22 triggers an interlocking action, the electric beam gate is controlled to close to block the beam path. The on-off detection unit 5 is triggered by a triggering hardware switch, and the on-off detection unit 5 triggers the electric beam gate. The entire process is a triggering process, without data processing and communication transmission process, so there is no erroneous execution or non-execution caused by error or loss of code.

[0044] In some preferred embodiments, Figure 1 As shown, Figure 1 This is a power-off control type structure diagram of an accelerator safety interlock system based on hardware interlocking in Example 1 of the present invention. When the controlled unit is a power-off control type, the accelerator safety interlock system also includes a power supply 4. A series circuit is formed between the power supply 4 and the power-off control type controlled unit 31 through the on-off output unit 21; the interlocking action of the hardware switch in the on-off output unit 21 controls the on-off of the series circuit, thereby directly controlling the interlocking state of the controlled unit 31.

[0045] Optionally, all controlled units 31 of the power-off control type are connected to the power supply 4, forming a series circuit with the controlled units 31. When the safety interlock monitoring unit 1 detects a danger, it immediately triggers the on / off output unit 21 to initiate an interlocking action, i.e., the hardware switch is disconnected, thereby controlling the series circuit to form an open circuit, thereby controlling the controlled unit 31 to be powered off and unable to operate normally, causing the controlled unit 31 to stop. The entire process takes less than 10ms, and the interlocking action change is triggered by the triggering, without any data communication process. Therefore, there is no erroneous execution or non-execution caused by error or loss of code, thus reducing the execution error rate of the interlocking action and the accident rate of personnel or facility operation.

[0046] In some preferred embodiments, the power supply 4 includes a positive power pole and a negative power pole; the hardware switch of the on-off output unit 21 is two first hardware switches 6; the two first hardware switches 6 are respectively connected to the positive power pole and the negative power pole of the power supply, and jointly control the on-off of the series circuit.

[0047] Optionally, first hardware switches 6 are installed at the positive and negative poles of the power supply to prevent a transient current from flowing through the first hardware switch 6 and entering the series circuit at the moment the positive pole of the power supply 4 is disconnected, thereby preventing the current from flowing through the first hardware switch 6 and entering the series circuit and reaching the negative pole through the loop, thereby delaying the power-off of the controlled unit 31. Furthermore, if a transient current is generated at the moment the positive pole of the power supply 4 is disconnected, the transient current will be greater than the current output by the power supply 4, and flowing into the series circuit may potentially break down the controlled unit 31. Therefore, two first hardware switches 6 are required to disconnect both the positive and negative poles of the power supply 4.

[0048] Optionally, two first hardware switches 6 are provided to simultaneously disconnect the positive electrode of the power supply 4 and the negative electrode of the power supply 4. At the moment of disconnection, if a transient current is generated, when the transient current reaches the negative electrode of the power supply 4 through the loop, since the negative electrode has been disconnected, the transient current cannot reach the negative electrode of the power supply 4, and thus cannot form a complete current loop. Therefore, at the moment of disconnection, the controlled unit 31 has already completed the power-off state, effectively improving the safety of the power-off protection.

[0049] In some preferred embodiments, Figure 2 As shown, Figure 2 This is a structural diagram of the on-off control type in an accelerator safety interlock system based on hardware interlock in Example 1 of the present invention. When the controlled unit is of the on-off control type, the accelerator safety interlock system also includes an on-off detection unit 5; the on-off detection unit 5 forms a series circuit with the on-off output unit 22, and the on-off detection unit 5 is communicatively connected with the controlled unit 32; the on-off detection unit 5 is used to determine the interlocking action of the hardware switch in the on-off output unit 22, and controls the interlocking state of the controlled unit 32 based on the interlocking action of the hardware switch in the on-off output unit 22.

[0050] Optionally, the on-off detection unit 5 detects the interlocking action of the on-off output unit 22 in real time. The on-off detection unit 5 and the on-off output unit 22 are connected in series through a wired line, and there is no need for wireless transmission of data. The wired connection makes the trigger signal of the interlocking action transmitted faster and more stably, avoiding data loss.

[0051] Optionally, the on-off detection unit 5 and the controlled unit 32 can be connected by wire or by wireless connection. No processor is set in the middle, and the controlled unit 32 is directly controlled by the on-off detection unit 5. In the case of a wired connection, the bit error rate is effectively avoided. When the on-off output unit 22 is interlocked, the on-off detection unit 5 is immediately triggered. At the same time, the on-off detection unit 5 will immediately trigger the controlled unit 32 after receiving the trigger signal transmitted in the line. There is no data transmission, and the trigger signal is directly transmitted through the line, which effectively improves the trigger efficiency and reduces the code loss in data transmission.

[0052] In some preferred embodiments, the hardware switch of the on-off output unit 22 is a second hardware switch 7 ; the second hardware switch 7 is connected in series with the on-off detection unit 5 to control the on-off of the series circuit.

[0053] Optionally, when the controlled unit 32 is of the on-off control type, the on-off output unit 22 is not connected to the power supply 4, so the on-off output unit 22 will not generate instantaneous current at the moment of disconnection, thereby not causing breakdown of the controlled unit 32 or the on-off detection unit 5. In order to save the cost of the on-off output unit 22, the on-off output unit 22 is set to a second hardware switch 7. The second hardware switch 7 can trigger an interlocking action in the safety interlock monitoring unit 1, and the on-off detection unit 5 can detect the interlocking action of the second hardware switch 7 in real time, thereby effectively realizing the entire triggering process and saving costs.

[0054] In some preferred embodiments, Figure 3 As shown, Figure 3 This is a structural diagram of manual reset button 8 in an accelerator safety interlock system based on hardware interlock, according to Example 1 of the present invention. The on / off output unit also includes manual reset button 8, which includes a button 9, a spring 10, and a microswitch 11. Button 9 is connected to spring 10, which is located on one side of microswitch 11. Microswitch 11 senses the pressure of spring 10 and generates an electrical signal. Microswitch 11 is connected to a hardware switch, and the electrical signal controls the hardware switch to trigger the interlock.

[0055] Optionally, after the safety interlock monitoring unit 1 detects a danger, it will trigger the hardware switch in the on-off output unit to be disconnected. After the danger is eliminated and the hardware switch does not close automatically, the hardware switch can be closed by manually resetting the button 8.

[0056] Optional, take the on-off control class as an example to form Figure 3 The manual reset button 8 includes a button 9 for pressing. The button 9 is located on the outermost side. When the staff presses the button 9, the button 9 will generate pressure on the spring 10. It should be noted that the spring 10 is fixedly connected to the button 9. The spring 10 presses the micro switch 11 under the action of pressure, and the micro switch sensing spring 10 exerts pressure on the micro switch 11, thereby forming an electrical signal in the path. The electrical signal indicates that the hardware switch is reset.

[0057] Optionally, the micro switch 11 is connected to the hardware switch. After the micro switch 11 generates an electrical signal, the electrical signal will be transmitted to the hardware switch, triggering the hardware switch to perform an interlocking action, thereby achieving the closing or opening of the hardware switch, effectively achieving the effect of manually resetting the on-off output unit.

[0058] Example 2

[0059] Based on the above embodiment, the present invention further proposes an optional implementation of an accelerator safety interlock system, which includes:

[0060] During the operation of the accelerator laboratory facilities, the control system of the accelerator laboratory controls the entire accelerator laboratory facilities. Once unsafe behaviors such as personnel entering by mistake or equipment failure occur, the safety interlock protection mechanism will be immediately triggered. The normal control functions of some components of the accelerator laboratory will be replaced by the control of the safety interlock system. The safety interlock function will be implemented first to ensure the safety of personnel and machines. The control system of the accelerator laboratory can only control all controlled units normally after the safety interlock state is released.

[0061] The controlled units in the accelerator safety interlock system that are preferentially controlled by the safety interlock system are divided into two categories. One category is to directly control the power supply 4 input of the controlled unit 31 (power-off control type), that is, to cut off the power supply 4 input of the controlled unit 31 to disable it when unsafe behavior occurs. The accelerator safety interlock system can be connected in series to the power supply 4 input system of the controlled unit 31 based on the on-off quantity output by the safety interlock monitoring unit 1, such as the ion source power supply 4 input of the accelerator for personnel radiation safety protection, the magnet power supply 4 input for machine safety protection, etc. Figure 1 As shown, the safety interlock monitoring unit 1 outputs a set of "on-off quantities". When no unsafe behavior is detected, the output is "on". At this time, the controlled unit 31 in the accelerator laboratory is powered normally and can accept normal control of the control system in the accelerator laboratory. When unsafe behavior is detected, the output is "off". At this time, the controlled unit 31 is powered off for protection, and the settings of the accelerator laboratory's control system will not be executed, thereby achieving the purpose of protecting personnel or machines.

[0062] Another type of method that uses the power-off method of the controlled unit 32 cannot meet the safety interlock requirements (on-off control type), such as a Faraday cup or a beam gate and other cut-off devices, which control the controlled unit 32 to open or close through a motor. When an unsafe behavior is detected, the front-stage device should be pushed into the center of the beam pipe to achieve the purpose of cutting off the beam. For this control method, the safety interlock monitoring unit 1 outputs a "on-off value". The control of this type of controlled unit 32 needs to first judge the "on-off signal" given by the safety interlock monitoring unit 1 and then decide whether to be controlled by the control system of the accelerator laboratory. Figure 2 , for the accelerator laboratory control system to detect. When the safety interlock protection is triggered, if the controlled unit 32 in the control system detects that the output signal of the safety interlock monitoring unit 1 is "off", the controlled unit 32 directly executes the preset action. On the contrary, when the signal is detected as "on", the controlled unit 32 reaches the interlock state according to the requirements of the accelerator laboratory control system, thereby achieving the purpose of protecting personnel or machines.

[0063] Through the above structure, a hardware interlocking method can be used to achieve stable operation of the facility while ensuring the safety of personnel and machines, improve the reliability and response speed of personnel safety, and prevent safety accidents between personnel and machines during operation.

[0064] Example 3

[0065] Based on the above embodiment, an embodiment of an application method of an accelerator safety interlock system based on hardware interlock is also provided. Figure 4 is a flowchart of an accelerator safety interlock system application method based on hardware interlock in embodiment 3 of the present invention, Figure 5 This is a logic process diagram of an accelerator safety interlock system application method based on hardware interlock in Example 3 of the present invention, such as Figure 4 and Figure 5 As shown, the method includes:

[0066] Step S102, the safety interlock monitoring unit 1 monitors the working status of the accelerator laboratory in real time during the current period;

[0067] Optionally, the safety interlock monitoring unit 1 serves as a monitoring sensor to monitor the working status of the accelerator laboratory in real time. There is a self-judgment module in the safety interlock monitoring unit 1, which can independently determine whether the current accelerator laboratory is in a safe state. There is no need to transmit the collected data to the cloud service end for judgment and processing at the cloud service end, which effectively reduces the possibility of data loss during transmission.

[0068] Optionally, when the working state is a safe state, it is necessary to determine in real time whether the current controlled unit is in a safe state, and to ensure that the on / off output unit where the controlled unit is located is in a safe state.

[0069] Step S104: When the working state is abnormal, trigger the interlocking action of the hardware switch in the on-off output unit to disconnect the series circuit, wherein the abnormal state and the safe state have opposite probability distributions;

[0070] Optionally, the safety interlock monitoring unit 1 monitors in real time, and when it detects that the safety status is abnormal, that is, when there is a danger, it will immediately trigger the on-off unit to perform the interlocking action. The triggering process transmits the trigger signal through a wired line. There is no need to transmit monitoring data, nor is there any need for the processor to judge and process the monitoring data. This improves the triggering speed and avoids the phenomenon of code loss or error during data transmission.

[0071] It should be noted that the opposite probability distribution means that there is no other state except the safe state and the abnormal state. The opposite probability event of the safe state is the abnormal state, and the opposite probability event of the abnormal state is the safe state.

[0072] In some preferred embodiments, when the working state is changed to a safe state, the interlocking action of the hardware switch in the on-off output unit is triggered to connect the series circuit; the controlled unit starts to run or turn on.

[0073] Optionally, after maintenance or inspection, the danger in the accelerator laboratory is eliminated, and when the safety status detected by the safety interlock monitoring unit 1 becomes normal, the experimental process in the accelerator laboratory needs to be carried out normally, so the interlock status needs to be changed to the state required for normal experiments. At this time, the on-off output unit needs to be released from the interlock, that is, when the safety status is normal, the on-off output unit will be triggered to perform the interlock action again, which is opposite to the interlock action in the abnormal situation, so that the experimental process in the accelerator laboratory can be carried out normally.

[0074] In some preferred embodiments, the criterion for the working state to change from an abnormal state to a safe state is that the working state remains in the safe state for at least 1 minute.

[0075] Optionally, the safety state monitored by the safety interlock monitoring unit 1 needs to ensure that the normal state is maintained for one minute or more before it can be determined to be in the normal state, effectively avoiding the instantaneous normal state misleading.

[0076] Step S106: The controlled unit stops running or closes.

[0077] Through the above steps S102 to S106, the purpose of directly controlling the on-off output unit based on the line connection of the safety interlock monitoring unit 1 and triggering the interlock state of the controlled unit is achieved, thereby realizing a process without the need for data transmission and software control, reducing the execution error rate of the interlock action, and reducing the accident rate of personnel or facility operation. The technical effect is solved, and the problem of data loss or communication interference when the software protocol responds to the control system and the interlock system in a hierarchical manner due to the complexity of the accelerator system network system and the large number of on-site interference signals is solved, resulting in execution errors or unexecuted control errors, leading to serious personnel or facility operation accidents.

[0078] According to an embodiment of the present application, an embodiment of a non-volatile storage medium is also provided. Optionally, in this embodiment, the non-volatile storage medium includes a stored program, wherein, when the program is executed, the device containing the non-volatile storage medium is controlled to execute any of the aforementioned application methods of the hardware interlock-based accelerator safety interlock system.

[0079] Optionally, in this embodiment, the non-volatile storage medium may be located in any computer terminal in a computer terminal group in a computer network, or in any mobile terminal in a mobile terminal group, and the non-volatile storage medium includes a stored program.

[0080] Optionally, when the program is running, the device where the non-volatile storage medium is located is controlled to perform the following functions: the safety interlock monitoring unit 1 monitors the safety status in the accelerator laboratory in real time during the current period; when the safety status is abnormal, the on-off output unit is triggered to perform an interlocking action; based on the interlocking action, the controlled unit reaches an interlocking state.

[0081] According to an embodiment of the present application, a processor embodiment is further provided. Optionally, in this embodiment, the processor is used to run a program, wherein when the program is run, any of the above-mentioned application methods of the accelerator safety interlock system based on hardware interlock is executed.

[0082] According to an embodiment of the present application, an embodiment of a computer program product is also provided. Optionally, in this embodiment, the computer program product includes a computer program that, when executed by a processor, implements any of the steps of the aforementioned method for applying a hardware interlock-based accelerator safety interlock system.

[0083] Optionally, the above-mentioned computer program product, when executed on a data processing device, is suitable for executing an initialization program having the following method steps: the safety interlock monitoring unit 1 monitors the safety status in the accelerator laboratory in real time during the current period; when the safety status is abnormal, the on-off output unit is triggered to perform an interlocking action; based on the interlocking action, the controlled unit reaches an interlocking state.

[0084] An embodiment of the present invention provides an electronic device, which includes a processor, a memory, and a program stored in the memory and executable on the processor. When the processor executes the program, the following steps are implemented: a safety interlock monitoring unit 1 monitors the safety status of an accelerator laboratory in real time during the current period; when the safety status is abnormal, an on / off output unit is triggered to perform an interlocking action; and based on the interlocking action, a controlled unit reaches an interlocking state.

[0085] The above sequence of the embodiments of the present invention is for description only and does not represent the superiority or inferiority of the embodiments.

[0086] In the above embodiments of the present invention, the description of each embodiment has its own focus. For parts that are not described in detail in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.

[0087] The above are only preferred embodiments of the present invention. It should be pointed out that for ordinary technicians in this technical field, several improvements and modifications can be made without departing from the principles of the present invention. These improvements and modifications should also be regarded as the scope of protection of the present invention.

Claims

1. An accelerator safety interlock system based on hardware interlock, characterized in that: include: A safety interlock monitoring unit (1) is used to monitor the working status of the accelerator laboratory during the current period, wherein the working status includes a safe state and an abnormal state; An on-off output unit (21, 22) is connected to the safety interlock monitoring unit (1) via a wired line, a hardware switch is provided in the on-off output unit (21, 22), and the safety interlock monitoring unit (1) controls the interlocking action of the hardware switch based on the working state, wherein the interlocking action includes opening and closing of the hardware switch; The controlled unit (31, 32) changes the interlocking state based on the interlocking action of the hardware switch of the on-off output unit (21, 22), wherein the interlocking state includes the start, stop and / or opening and closing of the controlled unit (31, 32).

2. The accelerator safety interlock system based on hardware interlock according to claim 1, characterized in that: The controlled units (31, 32) include a power-off control type and an on-off control type, wherein the power-off control type is used to indicate that the controlled unit (31) is directly connected to the on-off output unit (21), and the interlocking action of the hardware switch of the on-off output unit (21) directly controls the interlocking state of the controlled unit (31); and the on-off control type is used to indicate that the controlled unit (32) is not connected to the on-off output unit (22), and the interlocking action of the hardware switch of the on-off output unit (22) indirectly controls the interlocking state of the controlled unit (32).

3. The accelerator safety interlock system based on hardware interlock according to claim 2, characterized in that: In the case where the controlled unit is a power-off control type, the accelerator safety interlock system further comprises a power supply (4), wherein a series circuit is formed between the power supply (4) and the power-off control type controlled unit (31) via the on-off output unit (21); The interlocking action of the hardware switch in the on-off output unit (21) controls the on-off of the series circuit, thereby directly controlling the interlocking state of the controlled unit (31).

4. The accelerator safety interlock system based on hardware interlock according to claim 3, characterized in that: The power supply (4) comprises a positive power supply electrode and a negative power supply electrode; The hardware switches of the on-off output unit (21) are two first hardware switches (6); The two first hardware switches (6) are respectively connected to the positive pole of the power supply and the negative pole of the power supply, and jointly control the on-off of the series circuit.

5. The accelerator safety interlock system based on hardware interlock according to claim 2, characterized in that: In the case where the controlled unit is of the on-off control type, the accelerator safety interlock system further comprises an on-off detection unit (5); the on-off detection unit (5) and the on-off output unit (22) form a series circuit, and the on-off detection unit (5) is communicatively connected with the controlled unit (32); The on-off detection unit (5) is used to determine the interlocking action of the hardware switch in the on-off output unit (22), and to control the interlocking state of the controlled unit (32) based on the interlocking action of the hardware switch in the on-off output unit (22).

6. The accelerator safety interlock system based on hardware interlock according to claim 5, characterized in that: The hardware switch of the on-off output unit (22) is a second hardware switch (7); The second hardware switch (7) is connected in series with the on-off detection unit (5) to control the on-off of the series circuit.

7. An accelerator safety interlock system based on hardware interlock according to any one of claims 1 to 6, characterized in that: The on / off output unit (21, 22) further includes a manual reset button (8), and the manual reset button (8) includes a button (9), a spring (10), and a micro switch (11); The button (9) is connected to the spring (10); The spring (10) is located on one side of the micro switch (11), and the micro switch (11) senses the pressing force of the spring (10) and generates an electrical signal; The micro switch (11) is connected to the hardware switch, and the electrical signal controls the hardware switch to trigger an interlocking action.

8. An application method of an accelerator safety interlock system based on hardware interlock, applied to an accelerator safety interlock system based on hardware interlock according to any one of claims 3 to 6, characterized in that: include: The safety interlock monitoring unit (1) monitors the working status of the accelerator laboratory in real time during the current period; When the working state is abnormal, the interlocking action of the hardware switch in the on-off output unit (21, 22) is triggered to disconnect the series circuit; The controlled units (31, 32) stop operating or are closed.

9. The application method of the accelerator safety interlock system based on hardware interlock according to claim 8, characterized in that: Also includes: When the working state is changed to a safe state, the interlocking action of the hardware switch in the on-off output unit (21, 22) is triggered to connect the series circuit; The controlled units (31, 32) start operating or are turned on.

10. The application method of the accelerator safety interlock system based on hardware interlock according to claim 9, characterized in that: The standard for the working state to change from an abnormal state to a safe state is that the working state remains in the safe state for at least 1 minute.

Citation Information

Patent Citations

  • Elevator control system with gate interlock automatic detection

    CN201287997Y

  • Safety interlocking device of ion implanter

    CN222813547U