Safety system and method for protecting a machine
By combining safety sensors and non-safety assessment units, and utilizing protective field grids and rationality verification techniques, the problem of existing safety 3D camera systems being unable to achieve object tracking and positional accuracy has been solved, realizing efficient and low-cost safety function expansion.
Patent Information
- Application Number
- CN202510583671.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2024-06-05
- Filing Date
- 2025-05-07
- Publication Date
- 2025-12-05
AI Technical Summary
Existing safety 3D camera systems cannot perform complex safety functions, such as object tracking and position accuracy assessment, fail to meet machine safety standards, and traditional safety controllers lack sufficient computing power.
The system detects environmental data using a first safety sensor and generates a safety output signal. Combined with a non-safety assessment unit, it performs a complex assessment and utilizes a protective field grid and rationality verification technology to achieve accurate location and tracking of the object.
It enables complex object tracking and location assessment while meeting safety standards, improving system reliability and security and reducing costs.
Smart Images

Figure CN121069417A_ABST
Abstract
Description
[0001] The present invention relates to a safety system and method for protecting a machine according to the generic concept of claims 1 and 14.
[0002] Optoelectronic sensors are often used for non-contact monitoring in order to protect against hazards, for example machines in industrial environments or vehicles in logistics applications. In particular for more complex applications, laser scanners and cameras, in particular 3D cameras, are mentioned here first. 3D cameras measure distances and thus obtain depth information. The detected three-dimensional image data with individual pixel distance values or spacing values are also referred to as 3D images, distance images or depth maps. There are various technologies for 3D cameras, including light time-of-flight methods, stereo vision and projection methods or plenoptic cameras. In the light time-of-flight (TOF - Time of Flight) cameras, which are to be considered in more detail here, the scene is illuminated with amplitude-modulated light. The light returning from the scene is received and demodulated with the same frequency (phase-locked method), which is also used to modulate the emitted light. From the demodulation, an amplitude measurement is obtained, which corresponds to a sample value of the received signal.
[0003] Conventionally, a protection zone is usually monitored, into which an operator must not enter during machine operation. If the sensor recognizes an unauthorized protection zone disturbance, for example the leg of an operator, the machine goes into a safe state. In addition, simultaneous monitoring of multiple protection zones and switching of the protection zones are known. The sensors used in safety technology must work particularly reliably, so that higher safety requirements must be met, for example the standard EN 13849 on machine safety and the equipment standard EN 61496 on non-contact protection devices (BMS). In order to meet these safety standards, a series of measures must be taken, for example a secure electronic evaluation by means of redundant, diversified electronics or various functional monitoring, in particular monitoring of the contamination of optical components including the front window.
[0004] Safety laser scanners or safety cameras that meet these criteria and are designed for the protection field evaluation internally process large amounts of information of the scanned point cloud or depth map. However, only highly compressed binary information can be reliably provided externally, i.e. whether the protection field is violated or not. For this purpose, a safety output (OSSD, Output Signal Switching Device) is usually used. More complex safety evaluations, such as the determination of the position of an object or object tracking, are not possible with conventional systems. Algorithms for object tracking with optical detection have been known for a long time, which are based on classic image processing, Kalman filters or also increasingly on artificial intelligence. For risk-reducing functions, it is significantly more valuable to reliably know the exact position of persons and other objects than to only know the presence of an object in the protection field. But no suitable product is available that is certified for safety technology. Rather, today's safety 3D camera systems specifically do provide the 3D data of all information required for object localization. However, a sufficiently high-performance controller or other computing unit cannot meet the safety requirements, and vice versa, a safety controller cannot provide sufficient computing power.
[0005] EP 3 470 879 A1 configures at least partially overlapping monitoring fields in a laser scanner. This results in monitoring sections, which differ in which monitoring fields overlap there. Thus, the number of monitoring fields provided in terms of hardware is refined into monitoring sections.
[0006] EP 3 709 106 A1 proposes a safety system that verifies complex non-safety evaluations by less complex safety evaluations.
[0007] In DE 10 2017 105 174 B4, training data for an artificial neural network are generated. The image data are evaluated as safety-critical or non-safety-critical depending on whether a safety-relevant protection was triggered by a safety sensor at the point in time at which the image data were recorded. However, the safety sensor does not have special properties beyond the protection field function in its evaluation.
[0008] EP 4 325 308 A1 describes a safety system in which the result signals of the control and evaluation units of the safety sensors and the programmable controller are compared with each other. This is a cross comparison of two equally functional units, so that more complex safety functions such as object tracking cannot be realized.
[0009] The unpublished European patent application with the file reference 23162021.2 relates to a monitoring device for safety object tracking. Here, the protection field is configured with sub-protection fields, which realizes a discrete variant of safety object tracking. Thus, the resolution is limited and multiple objects cannot be tracked at the same time.
[0010] It is therefore an object of the present application to enable more complex safety functions.
[0011] This object is achieved by the safety system and method for protecting a machine according to claims 1 and 14. A first safety sensor detects sensor data in the surrounding of the machine and monitors at least one protection field based on these sensor data. Thereby, a safety output signal is generated at a safety interface (OSSD) of the first sensor and the state of the output signal gives information whether the protection field is violated, i.e. whether an unallowed object is present in the protection field. The violation of the protection field does not necessarily or directly lead to a safety response of the machine, the safety output signal can be processed in other ways. The first sensor further has a non-safety interface for outputting the sensor data, e.g. possibly pre-processed two- or three-dimensional image data or point clouds.
[0012] A non-safety evaluation unit, e.g. a standard controller, an edge device or an industrial PC, receives the sensor data from the non-safety interface and determines the object position in a non-safety evaluation or object localization. Here, complex evaluations can be performed which require a high performance of the non-safety evaluation unit which is not possible in existing certified safety controllers.
[0013] As throughout this specification, "safety" and "safety-related" refer to taking measures to control errors within a specified safety class or to comply with the provisions of the relevant safety standards for machine safety or protective devices for non-contact work, some of which have been mentioned in the introduction. "Non-safety" is the opposite of "safety", so for non-safety devices, transmission paths, evaluations, etc. the mentioned requirements for fault safety are not met or at least not required, so that individually considering the respective non-safety units or evaluations, no diagnostic and protective mechanisms for meeting a certain safety class can be guaranteed.
[0014] The basic idea on which the present application is based is that the protection field monitoring is used to reasonably verify or check the initially non-safety object position. Thereby, the object position can be used in a safety context, in particular to derive a safety-related object position.
[0015] An advantage of the present application is that the protection field functionality, which has already been certified as safety, is in a sense repurposed in order to check the position evaluation. Thus, with the existing safety components, the object position can be made available for safety technology applications in a simple and low-cost architecture by a system approach with a comparison or diagnostic mechanism at runtime according to the specifications of the relevant safety standards. The test can be implemented using different architectures and detection logics.
[0016] Preferably, a plurality of protection fields is stored in the first safety evaluation unit, which together form a grid of possible object positions in the detection area. This means that by recognizing a violated protection field, a safe object position can be detected within the resolution of the grid. The grid can be set in arbitrary coordinates, for example, as a ring of polar coordinates, and / or can be irregular, for example, denser as the machine is approached. A refinement of the grid can be achieved by a kind of superimposed protection fields like a fingerprint, as described in EP 3 470 879 A1 mentioned in the introduction. The protection fields are stored in the memory of the safety evaluation unit itself or in the memory of a sensor accessible to the safety evaluation unit. Here, the protection fields can be preconfigured and / or generated or adjusted dynamically.
[0017] Preferably, for each object position in the grid, there is a protection field that excludes the object position. This is a special way of forming the grid. Figuratively speaking, the protection field has a "hole" at the object position, the size of which is the size of the person or the body part identified according to the detection capability plus a possible tolerance or margin, in particular calculated according to the relevant safety standards. With such a protection field, the object position is coded in such a way that the protection field excluding the object position is violated exactly. Within the framework of object tracking, this can also be distinguished from the case in which there is no object in the detection area at all. Alternatively, another protection field can also be activated at the same time for this distinction, which also includes the excluded area, for example, covering the entire detection area.
[0018] Preferably, the non-safety evaluation unit is designed to continuously select a protection field on the basis of the respective object position, which is not violated by the object at the object position. It can thus be said that the protection field "gives way" to the object. In fact, this adjustment is preferably achieved by switching to a protection field of another geometry, in particular as described in the previous paragraph, with an exclusion zone at the object position. Errors in the non-safety position evaluation are then discovered in a reliable manner, i.e. the protection field is violated because the object is not at the expected object position.
[0019] Preferably, the non-safety evaluation unit is designed to continuously select a protection field on the basis of the respective object position, which is violated by the object at the object position. In this way, the logic is reversed, the protection field does not "give way" to the object, but rather moves with the object to the expected object position. The expectation for a correct position evaluation is now that the protection field is violated at all times.
[0020] Preferably, the non-safety evaluation unit is designed to continuously select a silent zone on the basis of the respective object position. This is a third alternative to the "yielding" protection field and the protection field that moves together. In principle, the silent zone is also an exclusion zone in the protection field, only its implementation is different, i.e. not by the geometry of the protection field, but by silencing or deactivating the protection field in the area of the exclusion zone, wherein the silent zone here moves together with the expected object position.
[0021] Preferably, the safety system has a safety controller that compares the object position with the monitoring result of the at least one protection field. In contrast, the previous variants do not require a safety controller. In this embodiment, the safety controller with diagnostic function complements the high-performance non-safety evaluation unit with position evaluation. The safety controller refers to a safety evaluation unit implemented in any hardware, in particular a safety controller as a controller that is allowed for safety applications in the narrow sense.
[0022] Preferably, the non-safety evaluation unit is designed to predict which protection field is violated on the basis of the object position and to transmit this prediction to the safety controller. The prediction of the protection field that is violated can then be compared in the safety controller with the protection field that is actually violated, wherein a consistent result only occurs when the position evaluation determines the correct object position.
[0023] Preferably, the safety system has a second safety sensor for detecting sensor data in the surroundings of the machine, which has a second safety evaluation unit for monitoring the at least one protection field by a safety-protected protection field evaluation of the sensor data of the second safety sensor, a second safety interface for outputting the monitoring result of the at least one protection field, and a second non-safety interface for outputting the sensor data to the non-safety evaluation unit. By using two or more sensors, a higher safety level can be achieved by means of redundancy, or even by diversity redundancy in the case of structurally different sensors.
[0024] Preferably, the safety system is designed to perform plausibility verification of the object position of the sensor data of the first sensor on the basis of monitoring of at least one protection field of the second sensor and / or to perform plausibility verification of the object position of the sensor data of the second sensor on the basis of monitoring of at least one protection field of the first sensor. This means that the two sensors crosswise plausibility verify their protection field monitoring and the position evaluation of the respective sensor data. According to all described embodiments, plausibility verification is possible only for one sensor, i.e. in particular by means of the protection field "yielding" on the basis of the object position or the protection field or the quiet zone being moved together. In particular, a crosswise comparison of the predicted protection field infringement and the actual protection field infringement in the safety controller can be considered.
[0025] Particularly preferably, the non-safety evaluation unit is designed to perform object tracking of the object in the detection area. Thus, not only is the current object identified, but the object is also tracked over time. This is much more reliable and allows a more finely coordinated safety concept. For example, it is not possible for an object to suddenly appear or disappear in the middle of the detection area, and the safety reaction of the machine derived from the object movement is more nuanced than that derived from the instantaneous object position. The instantaneous object position is always included, however, so that object tracking is also a form of position evaluation. The algorithms themselves are known, for example based on Kalman filters or machine learning, in particular neural networks. The particularity of the present invention is that, although the initial object tracking is non-safety, thanks to the plausibility verification, a safe object tracking is possible.
[0026] Preferably, the first safety sensor is a 3D camera, in particular a light time-of-flight camera. Thus, high-quality sensor data is generated, which enables complex evaluations in the non-safety evaluation unit. The same applies to other sensors, if present, wherein a combination of sensors of the same structure, sensors based on the same sensor principle or purposefully different sensors can be considered.
[0027] Preferably, the safety system is designed to store or output sensor data with associated object position and / or protection field evaluation results as annotated training data, triggered in particular by successful plausibility verification, protection field violation and / or end of protection field violation. By means of position evaluation or protection field monitoring, the respective sensor data is automatically associated with important information about the objects currently located in the detection area. In this embodiment, this is used to automatically annotate the sensor data. In this way, high-quality training data is obtained and the otherwise necessary tedious manual annotation or labeling is dispensed with. Examples of labels are object positions, object lists, past and / or future object trajectories, violated and non-violated protection fields, and a binary overall assessment as to whether a safety response is required due to an imminent accident. The training data can be generated periodically or in any other time grid, on request or triggered by specific situations. Interesting trigger conditions are successful plausibility verification, which ensures that the labels are correct, and / or when a protection field is violated or no longer violated, because then the probability of interesting things happening in the machine's surroundings increases and the method to be trained should respond particularly precisely to this.
[0028] If the object is in a dangerous position and / or in a dangerous movement, the safety system preferably triggers a safety response of the machine. Although it is not excluded that a protection field violation is included in this danger judgment, the real advantage of the invention is that the protection field monitoring only plays an indirect role, because it ensures a safe object position. Preferably, the danger judgment itself is based on the results of the position evaluation. A dangerous position can be too close to the machine or a component of the machine, it can be time-dependent or related to the machine's work flow. An additional evaluation can be made by means of the movement, because for example a movement parallel to the machine or even with a subcomponent moving away from the machine is less dangerous than a movement directly towards the machine. The speed can also play a role (Speed-and-Separation-Monitoring). The protection can include avoidance, deceleration or stopping of the machine or taking other safety states.
[0029] Preferably, the safety system is designed as a safe personnel counter. Objects are safely detected and distinguished based on their object position. Thus, in particular it can be very simply calculated how many objects are located in the detection area. If only personnel-sized objects trigger a protection field violation, this means that personnel can be distinguished from objects. Furthermore, any complex personnel model can be checked in the non-safety evaluation unit.
[0030] The method according to the application can be further developed in a similar manner and at the same time shows similar advantages. This advantageous features are exemplarily but not exhaustively described in the dependent claims which are subordinate to the independent claim. BRIEF DESCRIPTION OF DRAWINGS
[0031] Further features and advantages of the present application will be explained in more detail below exemplarily based on embodiments and with reference to the drawings. In the drawings:
[0032] Figure 1 A schematic diagram of a 3D camera is shown;
[0033] Figure 2 An exemplary captured image of a scene is shown, in which there are persons, a monitored machine and a configured protection field;
[0034] Figure 3 A diagram of a safety architecture with one safety sensor and one non-safety controller is shown;
[0035] Figure 4 A diagram of a safety architecture with one safety sensor, one non-safety controller and one safety controller is shown;
[0036] Figure 5 A diagram of a safety architecture with two safety sensors and one non-safety controller is shown; and
[0037] Figure 6 A diagram of a safety architecture with two safety sensors, one non-safety controller and one safety controller is shown.
[0038] Figure 1 A schematic block diagram of a camera 10 is shown, which is preferably designed as a 3D light time-of-flight camera and is described as a representative of a photosensor which can be used in connection with the present application. An illumination unit 12 emits an emission light 16, which is modulated by an emission optics 14, into a detection area 18. Lasers or LEDs in the form of edge emitters or VCSELs are considered as light sources. The illumination unit 12 is controlled such that the amplitude of the emission light 16 is modulated with a frequency which is usually in the range of 1 MHz to 1000 MHz. The modulation is, for example, sinusoidal or rectangular, but in any case a periodic modulation. This frequency leads to a limited range of sharpness of the distance measurement, so that for a camera 10 with a large effective range a small modulation frequency is required. Alternatively, the measurement is carried out at two to three or more modulation frequencies in order to expand the range of sharpness in combination with the measurement.
[0039] If the emitted light 16 hits the object 20 in the detection area 18, a portion is returned as received light 22 to the camera 10 and is guided there by a receiving optics 24, for example a single lens or a receiving objective, onto an image sensor 26. The image sensor 26 has a plurality of receiving elements or receiving pixels 26a, for example arranged in a matrix or rows. The resolution of the image sensor 26 can range from two or a few receiving pixels 26a to several thousand or several million receiving pixels 26a. Therein, the demodulation takes place according to the lock-in method. By repeated detection of the slightly offset modulated emitted light 16 in the course of the repetition, a plurality of sample values is generated, on the basis of which the phase shift between the emitted light 16 and the received light 22, and thus the light flight time, can ultimately be measured. The pixel arrangement is typically a matrix, resulting in a lateral position resolution in the X and Y directions, supplemented by the distance measurement in the Z direction, to form three-dimensional image data. When speaking of a 3D camera, a 3D light flight time camera or three-dimensional image data, 3D detection is preferably meant. However, other pixel arrangements can in principle also be considered, for example selected pixels in a matrix or rows of the entire image sensor forming a line camera.
[0040] In a control and evaluation unit having at least one digital computing module, for example a microprocessor or the like, the image data are used for protection field monitoring. The control and evaluation unit 28 has at least one evaluation circuit and preferably at least one digital computing module, like a microprocessor or CPU (Central Processing Unit), FPGA (Field Programmable Gate Array), DSP (Digital Signal Processor), ASIC (Application-Specific Integrated Circuit), AI processor, NPU (Neural Processing Unit), GPU (Graphics Processing Unit), VPU (Video Processing Unit) or the like. The protection field can be defined by geometric specifications of subareas of the detection area 18, which are configured, for example, in a CAD program or in any other way by means of the control and evaluation unit 28 or input via an interface not shown. The object interference in the protection field is monitored and, in the event of a protection field violation, a safety output signal is output at a safety output 30 associated with the protection field. The state of the safety output thus reflects in binary form whether an object is present in the associated protection field.
[0041] Figure 2An exemplary captured image of the camera 10 with some evaluation results is shown. The depth values are represented by gray values only. As explained in more detail below, a protection field monitoring as well as a position evaluation or object localization, preferably object tracking, is carried out. In the surrounding of the machine 32 under monitoring, two persons 34 are recognized and framed (Bounding Box) and the past movement path 35 of one person 34 is recognized and highlighted by the object tracking. Furthermore, the protection fields 36, 38 under monitoring are marked, which overlap each other to form a grid, wherein some sub-areas or grid elements are covered by the protection fields 36, 38 and others are neglected by the protection fields 36, 38. Furthermore, the individual strips shown can be either individual protection fields or mutually spaced sub-protection fields of a common protection field. The geometric shape of the protection fields is to be understood as purely exemplary; in particular, a more fine-grained, irregular or non-orthogonal grid can be formed. Furthermore, switching between protection fields or dynamic adaptation of the protection fields can be carried out.
[0042] Figure 3 A diagram of a safety architecture with one safety sensor 10 and one non-safety controller 40 is shown for explaining the test concept in the embodiments of the application. According to Figure 1 The camera 10 according to the introduction is preferably used as safety sensor 10, so the same reference signs are continued to be used. Alternatively, other 3D sensors can be used, some 3D camera types have already been mentioned in the introduction, further possibilities are multi-layer laser scanners or laser scanners with variable scanning planes. Furthermore, two-dimensional cameras or laser scanners are also conceivable, or completely different sensor principles, like radar.
[0043] The safety sensor 10 as a whole is a safety sensor in the sense of the definition in the introduction, i.e. the safety sensor 10 complies with a clearly defined safety level, in particular a clearly defined safety level of the safety standards for cameras, machine safety and non-contact protective devices. The already mentioned protection field monitoring 42 and the generated sensor data 44 are provided as functional modules in the safety sensor 10. The protection field monitoring 42 is a kind of safety evaluation, while the external access to the sensor data 44 itself and the forwarding of the sensor data 14 to the non-safety controller 40 is non-safety. So in other words, the safety sensor 10 is a certified safety sensor with a protection field function and a non-safety data interface for outputting sensor data.
[0044] The non-safety controller 40 is for example an industrial PC, an edge device or a computer box such as a Nvidia Jetson. It is important here to provide sufficient computing power and storage capacity as well as data bandwidth in order to be able to perform more complex evaluations of the sensor data 44 in the position evaluation 46 at the location of the non-safety controller, wherein the position evaluation 46 preferably performs an object tracking. For example, the position evaluation 46 provides a so-called object list, which can contain information such as all detected objects, their position, ID, bounding box and similar data.
[0045] The basic idea of the application is to verify the plausibility of the position evaluation 46 based on the protection field monitoring 42 in order to this way find error situations in the position evaluation 46 with a sufficiently high probability in order to achieve the pursued safety level. In the embodiment according to Figure 3 This is achieved in the embodiment according to Fig. 1 by the safety sensor 10 having different protection field configurations which alternately cover different areas in the detection area 18 with the protection fields 36, 38. In particular, each area has a protection field 36, 38 which excludes this area. In the non-safety controller 40, it is derived from the result of the position evaluation 46 which protection field configuration must be selected in order to ensure that no protection field triggering occurs at the found object position.
[0046] When the person 34 moves through the detection area 18, the protection field configuration is always dynamically selected in the case of a proper functioning of the position evaluation 46 so that the protection fields 36, 38 are not infringed. In this concept, the protection fields 36, 38 actually “give way” to the person 34, the OSSD always remains in the “ON” state. Conversely, in the reverse logic, the protection fields 36, 38 can be selected so that they are infringed at every current object position, i.e. the protection fields move with the person 34, wherein the OSSD always remains in the “OFF” state. As an alternative, the “giving way” of the protection fields can be implemented by a silent area which moves with the person 34. Here, the protection fields 36, 38 are crossed at the respective object position so that the protection fields 36, 38 are not recognized as being infringed despite the presence of the person 34.
[0047] As a result, in addition to the protected field status, the object position is obtained, which can be used for subsequent safety-relevant hazard determination due to plausibility verification. As part of the object tracking, further values such as speed, previous or predicted object position can be obtained. If a hazard is identified, a safety-relevant signal is output to the machine being monitored. The machine 32 then reduces the speed or switches to a work step that does not constitute a hazard at least in the case of the identified object movement, and the machine only switches to a safe state if necessary. Overall, a high availability and productivity are thus achieved. The result quality of the position evaluation 46 or object tracking is higher compared to pure protected field monitoring, in particular the knowledge of the position of all persons in the field, can also be used for future safeguarding solutions, which have an influence on a higher level on automated processes in larger areas up to the entire workshop or factory.
[0048] Figure 4 A diagram of the safety architecture is shown with one safety sensor 10, one non-safety controller 40 and now in this embodiment one additional safety controller 48, where the safety controller is initially understood broadly as a safety evaluation of a computing unit in any hardware and only preferably understood narrowly as a safety controller. In the non-safety controller 40, the appropriate protected field status is now determined in addition to the position evaluation 46 and transmitted to the plausibility verification 50 in the safety controller 48. For this purpose, the geometry for the protected field monitoring 42 is also transferred to the non-safety controller 40, preferably during the setup process.
[0049] In this way, the plausibility verification 50 can compare the protected field status predicted by the non-safety controller based on the object position determined there with the actual protected field status of the protected field monitoring 42. In order to confirm whether the function of the position evaluation 46 is correct, it does not have to be completely identical at every point in time, since the protected field monitoring 42 is determined based on individual pixel information, while the position evaluation 46 works using model assumptions (e.g. center of gravity and predetermined radius or bounding box). Therefore, especially for the edges of the protected fields 36, 38, a certain tolerance should be allowed in the comparison of the plausibility verification 50, in particular determined based on a correlation measure of the OSSD changes over time. Only if the plausibility verification is successful, the result of the position evaluation 46 can be used in the subsequent hazard determination.
[0050] Figure 4Another optional function of the non-safety controller 40 is also shown, which can also be used in all other embodiments, namely data collection for storing or providing annotated training data. Here, the training data are sensor data, the results of the protection field monitoring 42 and / or the position evaluation are automatically associated with these sensor data as relevant labels. This training data can then be used to train a machine learning method or an AI model (artificial intelligence) or a neural network. After successful training, this method is able to emulate the original function, which can then be used elsewhere and in other applications or take over or supplement the original function in safety applications. In order to ensure that the training data are relevant and not misleadingly annotated, these training data are only generated when triggered, respectively. The plausibility verification 50 each time a successful one is particularly suitable for this, since it can then be explicitly stated that the sensor data were correctly evaluated at that moment and thus also correctly labeled. Additional conditions can be set so that training data are only generated after a minimum change in the object position, in a specific protection field state or if the overall assessment of the situation is dangerous or not.
[0051] By means of the described method and plausibility verification, relevant error scenarios can be reliably discovered and mastered:
[0052] • In the case of a complete failure of the position evaluation 46, no expected signal of the protection field violation, the mute signal or the dynamic switching of the protection fields 36, 38 occurs. Correspondingly, no consistency is found in the plausibility verification 50 or the protection field 36, 38 that was not switched is violated and this violation is identified in the protection field monitoring 42.
[0053] • In the case of a delayed execution or freezing of the position evaluation 46, the expected signal, the mute signal or the dynamic switching is delayed or does not occur at all, with the same consequences as in the previous case.
[0054] • In the case of an inaccurate object localization in the position evaluation 46, the expected signal, the mute signal or the dynamic switching does not match the actual object position, with the same consequences as in the previous case.
[0055] • In the case of an error in the data transfer of the sensor data to the non-safety controller 40, the error is either only slight and therefore does not result in a relevant functional failure or has the same consequences as in the other error cases.
[0056] • Preferably, in order to prevent errors in the data transmission of the results of the non-safety controller 40 (e.g. object positions, object lists, etc.) to the downstream units, additional measures are also taken, such as checksums, timestamps and data packet IDs. Alternatively, in embodiments with a safety controller 48, plausibility verification elements for the data transmission can be transmitted via a separate plausibility verification channel of the safety controller 48. In particular when a secure field bus is used here, redundant information or additional plausibility verification elements can be added to the transmission.
[0057] When there are multiple persons 34 in the detection area 18, it is not possible in some cases to configure free zones for all persons 34 without completely deactivating the protection fields 36, 38. However, from a safety technology point of view, this situation is problematic, so it is preferable not to allow this situation at all. This problem can be mitigated to some extent by monitoring the protection fields 36, 38 at the same time, in which case there is a limitation when there are too many persons 34 in the detection area 18. However, this merely means that the machine 32 cannot be used as long as there are too many persons 34 in the surroundings of the machine 32.
[0058] Figure 5 A diagram showing a safety architecture in another embodiment of the application is shown, which has two safety sensors 10a-10b and one non-safety controller 40. In the previous embodiment with only one safety sensor 10, a common cause failure can occur which affects both system channels. Although the safety sensor 10 is able to withstand this failure to some extent due to its safety suitability, in any case the limitations of the individual components also represent limitations of the entire system. Therefore, in particular, the safety level of the system function is limited to the safety level of the individual safety sensor 10.
[0059] In an extension of the concept with two safety sensors 10a-10b, plausibility verification can be carried out by the other safety sensor 10b-10a respectively using its independent data basis, hardware and perspective. The diversity of this approach makes safety-related error cases extremely unlikely, thus enabling a higher safety level for the overall solution.
[0060] In an embodiment according to Figure 5 In this embodiment, the sensor data of the first sensor 10a is processed in the first position evaluation 46a and thereby triggers a protection field switch for the second protection field monitoring 42b in the second safety sensor 10b. Conversely, the sensor data of the second safety sensor 10b is processed in the second position evaluation 46b and thereby triggers a protection field switch for the first protection field monitoring 42a in the first safety sensor 10a. This embodiment does not require a safety controller.
[0061] Figure 6 A diagram of a security architecture is shown, which includes two security sensors 10a-10b, a non-security controller 40, and in this further embodiment, [the following is related to...]. Figure 5 Different additional safety controllers 48. The results of the two location assessments 46a-46b are cross-validated with the results of the protected field monitoring 42b-42a of another safety sensor 10b-10a in the first and second rationality verifications 50a-50b, respectively. This system can provide diversity for safety considerations on a larger scale.
Claims
1. A safety system for guarding a machine (32), wherein, The safety system has at least a first safety sensor (10) for detecting sensor data (44) of a detection area (18) in the surroundings of the machine (32) and a non-safety evaluation unit (40), wherein the first safety sensor (10) has a first safety evaluation unit (28) for monitoring at least one protection field (36, 38) by a safety-guarded field evaluation (42) of the sensor data (44), a first safety interface (30) for outputting the monitoring result of the protection field (36, 38), and a first non-safety interface for outputting the sensor data (44) to the non-safety evaluation unit (40), and wherein the non-safety evaluation unit (40) is designed to determine an object position of an object (20, 34) located in the detection area (18) by a non-safety position evaluation (46) of the sensor data (44), characterized in that the safety system is further designed to plausibly verify the object position on the basis of the monitoring of the at least one protection field (36, 38).
2. The safety system of claim 1, wherein, A plurality of protection fields (36, 38) is stored in the first safety evaluation unit (28), which together form a grid of possible object positions in the detection area (18).
3. The safety system of claim 2, wherein, For each object position in the grid, there is a protection field (36, 38) that excludes the object position.
4. The safety system of any of the preceding claims, wherein, The non-safety evaluation unit (40) is designed to continuously select a protection field (36, 38) on the basis of the respective object position which is not infringed by an object (20, 34) at the object position, or wherein the non-safety evaluation unit (40) is designed to continuously select a protection field (36, 38) on the basis of the respective object position which is infringed by an object (20, 34) at the object position, or wherein the non-safety evaluation unit (40) is designed to continuously select a quiet zone on the basis of the respective object position.
5. Safety system according to any of the preceding claims, having a safety controller (48) which compares the object position with the monitoring result of the at least one protection field (36, 38).
6. The safety system of claim 5, wherein, The non-safety evaluation unit (40) is designed to predict on the basis of the object position which protection field (36, 38) is infringed and to transmit this prediction to the safety controller (48).
7. Safety system according to one of the preceding claims, having a second safety sensor (10b) for detecting sensor data (44b) in the surroundings of the machine (32), having a second safety evaluation unit (28) for monitoring at least one protection field by a safety protection field evaluation (42b) of the sensor data of the second safety sensor, a second safety interface for outputting the monitoring result of the at least one protection field (36, 38), and a second non-safety interface for outputting the sensor data (44b) to the non-safety evaluation unit (40).
8. The safety system of claim 7, wherein, The safety system is designed to, based on the monitoring of the at least one protection field (36, 38) of the second sensor (10b), plausibly verify the object position of the sensor data (44a) of the first sensor (10a), and / or based on the monitoring of the at least one protection field (36, 38) of the first sensor (10a), plausibly verify the object position of the sensor data (44b) of the second sensor (10b).
9. The safety system of any of the preceding claims, wherein, The non-safety evaluation unit (40) is designed to perform object tracking of objects (20, 34) in the detection area (18).
10. The safety system of any of the preceding claims, wherein, The first safety sensor (10a) is a 3D camera, in particular a light time-of-flight camera.
11. Safety system according to one of the preceding claims, designed to store or output sensor data (44) with associated object position and / or result of the protection field evaluation (42) as annotated training data, in particular triggered by a successful plausibility verification, a protection field infringement and / or a conclusion protection field infringement.
12. Safety system according to one of the preceding claims, which triggers a safety response of the machine (32) if an object (20, 32) is located at a dangerous position and / or is in a dangerous movement.
13. Safety system according to one of the preceding claims, designed as a safe person counter.
14. A method for safeguarding a machine (32), wherein, Sensor data of a detection area (18) in the surroundings of the machine (32) are detected using at least one first safety sensor (10) and evaluated by the first sensor (10) by a safety protection field evaluation (42) to monitor at least one protection field (36, 38), sensor data (44) are output to a non-safety evaluation unit (40) and there an object position of an object (20, 32) located in the detection area (18) is determined by a non-safety position evaluation (46) of the sensor data (44), characterized in that the object position is plausibly verified based on the monitoring of the at least one protection field (36, 38).
Citation Information
Patent Citations
Method for generating training data for monitoring a hazard source
DE102017105174B4
Optoelectronic sensor and method for securely detecting objects
EP3470879A1
Security system and method with a security system
EP4325308A1