Safety interlock control method and system for dismounting process of limit switch

By verifying identity and comparing dual-channel signals, the signal change rate during the disassembly and assembly of limit switches is monitored, which solves the problem of insufficient safety in the disassembly and assembly process of limit switches in the existing technology, realizes accurate identification and interlocking control, and improves the safety and reliability of equipment operation.

CN121541538BActive Publication Date: 2026-06-09DALIAN ZHONGQI GENERAL MASCH EQUIP CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
DALIAN ZHONGQI GENERAL MASCH EQUIP CO LTD
Filing Date
2025-11-21
Publication Date
2026-06-09

Smart Images

  • Figure CN121541538B_ABST
    Figure CN121541538B_ABST
Patent Text Reader

Abstract

The application discloses a safety interlocking control method and system for dismounting process of limit switch, and relates to the technical field of industrial automation control and equipment safety. The method comprises the following steps: verifying the identity of the operator before performing the dismounting operation; collecting the electrical signal parameters of the limit switch and calculating the signal change rate during the dismounting process, and collecting the physical output signal and the communication confirmation signal for double-channel consistency comparison; prohibiting the device actuator from running when the signal change rate exceeds the stable threshold or the double-channel state is inconsistent; and automatically restoring the device operation when the signal change rate is lower than the threshold and the double-channel state is consistent after the installation is completed. The technical problems of the prior art, such as inability to distinguish between device failure and artificial dismounting state due to dependence on single-channel signal monitoring, inability to predict risks due to lack of dynamic signal analysis, inability to achieve precise interlocking due to lack of double-channel verification, and security management loopholes due to lack of identity verification, are solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of industrial automation control and equipment safety technology, and in particular to a safety interlock control method and system for the disassembly and assembly of limit switches. Background Technology

[0002] Limit switches, as key components in industrial automation systems used for position detection and travel control, directly affect the safety and stability of equipment operation due to their reliability. During maintenance, replacement, or debugging of limit switches, their electrical connections are typically in an unstable state. Existing safety measures mainly rely on process-based management methods such as "power off and tagging," and passive safety control logic that only monitors a single mechanical contact signal.

[0003] These existing technical solutions suffer from systemic defects: First, they heavily rely on human factors for safety, making it impossible to technically eliminate the risks of accidental power supply and misoperation. Second, at the technical level, they lack precise identification and interlocking capabilities, and the control system cannot effectively distinguish between equipment malfunctions, signal interference, and human disassembly / reassembly operations. They cannot utilize dual-channel information for real-time consistency verification, nor can they predict risks based on the dynamic changes in signals, resulting in the inability to timely and reliably prevent dangerous actions of associated actuators during disassembly / reassembly. Furthermore, at the management level, they lack a traceable safety access mechanism, allowing any on-site personnel to access and operate the equipment, leading to potential risks of confused permissions and unclear responsibilities.

[0004] Therefore, existing technologies are insufficient to provide proactive, precise, and mandatory safety protection in the high-risk operation of limit switch installation and removal. There is an urgent need for a safety control method that integrates identity authentication, dual-channel dynamic monitoring, and interlocking control for the limit switch installation and removal process, so as to improve the inherent safety of the system operation from a technical perspective. Summary of the Invention

[0005] The purpose of this application is to provide a safety interlock control method and system for the installation and removal of limit switches. This addresses the technical problems of existing technologies: reliance on single-channel signal monitoring makes it impossible to distinguish between equipment malfunctions and human-caused installation / removal; lack of dynamic signal analysis makes it impossible to predict risks; lack of dual-channel verification prevents accurate interlocking; and lack of identity verification leads to security management vulnerabilities.

[0006] In view of the above technical problems, this application provides a safety interlock control method and system for the disassembly and assembly process of limit switches.

[0007] A first aspect of this application provides a safety interlock control method for the disassembly and assembly process of a limit switch, the method comprising:

[0008] Before disassembling and installing the limit switch, verify the operator's identity. Disassembly and installation are permitted only after the identity verification is passed.

[0009] During the disassembly and assembly process, the electrical signal parameters of the limit switch are collected, the signal change rate is calculated based on the electrical signal parameters, the physical output signal of the first signal channel is collected, the physical output signal is the switching signal generated by the mechanical contact opening and closing of the limit switch, and the communication confirmation signal of the second signal channel is collected. The communication confirmation signal is transmitted from the internal circuit of the limit switch to the current status information of the control system through the communication bus.

[0010] The physical output signal of the first signal channel is compared with the communication confirmation signal of the second signal channel to obtain the consistency status of the two channels.

[0011] When the signal change rate exceeds the preset stability threshold, or when the time for which the consistency status of the two channels is inconsistent reaches the second confirmation duration threshold, the operation of the device actuator associated with the limit switch is prohibited.

[0012] After installation, when the signal change rate is lower than the stability threshold and the time for the two channels to be in a consistent state reaches the third confirmation duration threshold, the normal operation of the device actuator will be automatically restored.

[0013] A second aspect of this application provides a safety interlock control system for the installation and removal process of limit switches, the system comprising:

[0014] An identity verification module is used to verify the identity of the operator before performing the disassembly and installation of the limit switch. When the identity verification is successful, the disassembly and installation operation is allowed.

[0015] The signal acquisition and rate of change calculation module is used to acquire electrical signal parameters of the limit switch during disassembly and assembly, calculate the signal rate of change based on the electrical signal parameters, acquire the physical output signal of the first signal channel, which is the switching signal generated by the mechanical contact opening and closing of the limit switch, and acquire the communication confirmation signal of the second signal channel, which is transmitted from the internal circuit of the limit switch to the current status information of the control system through the communication bus.

[0016] A two-channel consistency determination module is used to compare the physical output signal of the first signal channel with the communication confirmation signal of the second signal channel to obtain the consistency status of the two channels.

[0017] The operation prohibition control module is used to prohibit the operation of the device actuator associated with the limit switch when the signal change rate exceeds a preset stability threshold, or when the time when the consistency status of the two channels is inconsistent reaches a second confirmation duration threshold.

[0018] The operation recovery control module is used to automatically restore the normal operation of the device actuator after installation operation when the signal change rate is lower than the stability threshold and the time when the consistency status of the two channels is consistent reaches the third confirmation duration threshold.

[0019] One or more technical solutions provided in this application have at least the following technical effects or advantages:

[0020] The system achieves accurate identification and intelligent diagnosis of disassembly and assembly status. By integrating dual-channel signal consistency comparison and electrical signal change rate monitoring, the system can accurately distinguish between normal equipment continuity, line faults, and human disassembly / assembly operations, solving the problem of high misjudgment rate with single signal monitoring methods. An anti-interference and anti-malfunction active safety interlock mechanism has been constructed. By introducing an acknowledgment timer and acknowledgment duration threshold, abnormal states are continuously judged, effectively filtering instantaneous signal interference and ensuring the reliability of safety interlock triggering and release, avoiding accidental equipment shutdowns and restarts. The system's recovery operation safety and reliability have been improved. During automatic recovery, a verification step for the health of electrical parameters such as current and impedance has been added, ensuring that the interlock is only released when the electrical connection is truly stable and reliable, preventing secondary risks caused by hidden faults such as "loose connections." Standardization and traceability of safety management have been achieved. Through a digital certificate-based identity verification and temporary operation authorization mechanism, personnel permissions, work duration, and specific operations are strongly bound, eliminating unauthorized operations and fully recording the entire operation process, meeting the stringent requirements of modern industry for safety auditing and accountability. This has created an inherently safe closed loop covering the entire process from personnel access and status awareness to decision-making and execution.

[0021] The above description is merely an overview of the technical solution of this application. In order to more clearly explain the technical means of this application, and to enable its implementation in accordance with the contents of the specification, and to make the above and other objectives, features and advantages of this application more apparent and understandable, specific embodiments of this application are described below. Attached Figure Description

[0022] To more clearly illustrate the technical solutions of the embodiments of this disclosure, the accompanying drawings of the embodiments of this disclosure will be briefly described below. Flowcharts are used in this application to illustrate the operations performed by the system according to the embodiments of this application. It should be understood that the preceding or following operations are not necessarily performed precisely in sequence. Instead, various steps can be processed in reverse order or simultaneously as needed. Furthermore, other operations can be added to these processes, or one or more steps can be removed from these processes.

[0023] Figure 1 A flowchart illustrating the safety interlock control method for the disassembly and assembly process of the limit switch provided in this application embodiment;

[0024] Figure 2 A schematic diagram of the safety interlock control system for the limit switch disassembly and assembly process provided in this application embodiment.

[0025] Figure labeling: Authentication module 10, signal acquisition and rate of change calculation module 20, two-channel consistency determination module 30, operation prohibition control module 40, operation recovery control module 50. Detailed Implementation

[0026] This application provides a safety interlock control method and system for the installation and removal of limit switches, which solves the technical problems of existing technologies that cannot distinguish between equipment failure and human installation / removal due to reliance on single-channel signal monitoring, cannot predict risks due to lack of dynamic signal analysis, cannot achieve accurate interlocking due to lack of dual-channel verification, and have security management vulnerabilities due to lack of identity verification.

[0027] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of this application, and not all of them. All other embodiments obtained by those skilled in the art based on the embodiments of this application without creative effort are within the scope of protection of this application.

[0028] It should be noted that the terms “comprising” and “having”, and any variations thereof, are intended to cover non-exclusive inclusion, for example, a process, method, system, product, or server that includes a series of steps or units is not necessarily limited to those steps or units that are explicitly listed, but may include other steps or modules that are not explicitly listed or that are inherent to such processes, methods, products, or devices.

[0029] Example 1, as Figure 1 As shown, this application provides a safety interlock control method for the disassembly and assembly process of limit switches, wherein the method includes:

[0030] Before disassembling and installing the limit switch, verify the operator's identity. Disassembly and installation are permitted only after the identity verification is passed.

[0031] Furthermore, the verification of the operator's identity includes:

[0032] Perform digital signature verification and validity period check on the digital identity certificate provided by the operator;

[0033] Extract the device operation permission level identifier from the verified digital identity certificate;

[0034] In response to the fact that the device operation permission level identifier meets the permission requirements for limit switch disassembly and assembly operations, a temporary operation authorization certificate containing a unique authorization identifier, authorization effective time, and authorization termination time is generated;

[0035] During the installation and removal of the limit switch, the timing relationship between the current system time and the authorized termination time is continuously monitored;

[0036] The removal or installation of the limit switch is permitted only when the system is currently within the valid time interval from the authorization effective time to the authorization termination time;

[0037] When the current system time exceeds the authorization termination time, the valid operation permissions of the temporary operation authorization certificate will be automatically revoked.

[0038] Specifically, before performing the disassembly and installation of the limit switch, the system first verifies the operator's identity. Once the identity verification is successful, the disassembly and installation operation is permitted. Further, the operator identity verification includes: collecting the operator's digital identity certificate through an identity recognition device, which can be a card reader, fingerprint recognition module, or facial recognition camera. The system is an industrial automation control system, including a main controller, a communication interface module, and a human-machine interface, used for identity verification, permission judgment, and disassembly / installation operation control. The system performs digital signature verification and validity period check on the digital identity certificate. The digital signature verification uses a Public Key Infrastructure (PKI) algorithm to ensure the authenticity and integrity of the identity information. Subsequently, the system extracts the device operation permission level identifier from the verified digital identity certificate to determine whether the operator has the permission to perform the limit switch disassembly / installation operation. When the device operation permission level identifier meets the permission requirements for the limit switch disassembly / installation operation, the system generates a temporary operation authorization credential containing a unique authorization identifier, the authorization effective time, and the authorization termination time. The temporary operation authorization credential is stored in the controller and updated synchronously with the human-machine interface through the communication interface for real-time disassembly / installation operation judgment. During the installation and removal of the limit switch, the system continuously monitors the time relationship between the current system time and the authorization termination time. Only when the current system time falls within the valid time interval between the authorization activation and termination times is the system sending a permission signal to the actuator via the control interface, authorizing the installation or removal of the limit switch. If the current system time exceeds the authorization termination time, the system sends a prohibition signal via the control interface, automatically revoking the validity of the temporary operation authorization certificate and recording the event in the security audit log. In this embodiment, the identity verification may include single-factor or multi-factor verification methods, preferably a combination of digital identity certificate verification and biometric comparison to enhance security. The control interface may be an industrial fieldbus interface, relay contacts, or a digital output module, used to directly control the operation or stop of the actuator, achieving physical controllability of the installation and removal operation. Through the above measures, this embodiment achieves controllable identity, verifiable permissions, and controllable operation time for the limit switch installation and removal operation, ensuring security and traceability during the installation and removal process.

[0039] During the disassembly and assembly process, the electrical signal parameters of the limit switch are collected, the signal change rate is calculated based on the electrical signal parameters, the physical output signal of the first signal channel is collected, the physical output signal is the switching signal generated by the mechanical contact opening and closing of the limit switch, and the communication confirmation signal of the second signal channel is collected. The communication confirmation signal is transmitted from the internal circuit of the limit switch to the current status information of the control system through the communication bus.

[0040] Furthermore, the acquisition of electrical signal parameters of the limit switch, and the calculation of the signal change rate based on the electrical signal parameters, includes:

[0041] When the limit switch is in the process of disassembly and assembly, the electrical signal parameters are sampled synchronously at multiple points according to the preset sampling period, and the electrical signal parameters are filtered and denoised. The filtering and denoising process includes moving average filtering or median filtering.

[0042] For the electrical signal parameters after filtering and denoising, calculate the rate of change of the signal, which is the rate of change of voltage, the rate of change of current, and the rate of change of impedance.

[0043] Specifically, when performing the disassembly or installation of the limit switch, the system uses a data acquisition module configured on the device to collect the electrical signal parameters of the limit switch in real time, including voltage, current, and impedance parameters. These electrical signal parameters are physically or wirelessly acquired through a signal acquisition circuit configured on or near the limit switch. The data acquisition module actively polls or generates sampling requests in response to changes in the limit switch's state according to a preset sampling period. The acquired signals are converted into a processable data format via an analog-to-digital converter or communication interface and transmitted to the buffer of the control system. Simultaneously, the system acquires the physical output signal of the first signal channel, which is directly generated by the opening and closing of the mechanical contacts of the limit switch and is a switching signal. Specifically, the first signal channel directly drives the digital input port by closing or opening the limit switch contacts. The high and low levels of the digital input port correspond to the on / off state of the mechanical contacts, which are periodically read and buffered by the data acquisition module as standardized logic states. The system also acquires the communication confirmation signal of the second signal channel, which is transmitted to the control system from the internal circuitry or control module of the limit switch via a wired or wireless communication bus. During transmission, the system performs frame verification, reception integrity check, and timeout detection on each message to determine communication validity. Only when a communication message passes verification is the signal mapped to a standardized logic state; otherwise, it is considered a logic "0" indicating communication failure. The acquisition module reads the signal in each sampling cycle and caches it in the control system for subsequent comparison. Further, the step of acquiring the electrical signal parameters of the limit switch and calculating the signal change rate based on these parameters includes: during disassembly and assembly, the data acquisition module actively triggers or synchronously samples the electrical signal parameters according to a preset sampling cycle and stores the acquired data in the buffer of the control system. Subsequently, the acquired electrical signal parameters are filtered and denoised (e.g., moving average filtering or median filtering) to eliminate transient interference and ensure the accuracy of the signal change rate calculation. Based on the filtered and denoised data, the system calculates the signal change rate, which includes at least one of voltage change rate, current change rate, and impedance change rate; preferably, the voltage change rate, current change rate, and impedance change rate are monitored in parallel. By comprehensively utilizing the change rates of multiple electrical parameters, the system can capture sudden state changes of limit switches during disassembly and assembly from different dimensions. Compared to relying on a single parameter, this multi-parameter fusion strategy greatly improves the robustness and reliability of state recognition. For example, in scenarios where loose wiring leads to increased contact resistance, voltage and current changes may not be obvious, but the impedance change rate will exhibit significant characteristics. Furthermore, in the presence of transient electrical interference, a single voltage or current surge may cause misjudgment, but the impedance change rate may remain stable. By comprehensively monitoring these change rates, the system can effectively distinguish between genuine mechanical disassembly and assembly operations and ordinary line interference or equipment malfunctions.

[0044] The physical output signal of the first signal channel is compared with the communication confirmation signal of the second signal channel to obtain the consistency status of the two channels.

[0045] Furthermore, comparing the physical output signal of the first signal channel with the communication confirmation signal of the second signal channel to obtain the consistency status of the two channels includes:

[0046] The physical output signal of the first signal channel is subjected to anti-jitter filtering to obtain the first standardized logic state characterizing the mechanical contact state of the limit switch.

[0047] Simultaneously, the communication validity of the communication confirmation signal of the second signal channel is detected to obtain a second standardized logic state characterizing the communication status of the limit switch;

[0048] Under the set sampling period, a logical XOR operation is performed on the first standardized logic state and the second standardized logic state. When the operation result is true, an inconsistency trigger signal is generated.

[0049] In response to the inconsistency trigger signal, an acknowledgment timer is started to monitor the duration.

[0050] When the duration of the inconsistency trigger signal reaches a preset first confirmation duration threshold, the consistency status of the two channels is determined to be inconsistent. The first confirmation duration threshold is specifically used for determining the consistency status of the two channels.

[0051] If the inconsistency trigger signal disappears before the first confirmation duration threshold is reached, the consistency status of the two channels is determined to be consistent.

[0052] Furthermore, the communication validity detection includes:

[0053] Within each sampling period, the integrity of the received communication message, the correctness of the frame verification, and the reception time are all within a preset timeout threshold.

[0054] If all tests pass, the communication is considered valid;

[0055] If any test fails, the communication is deemed to have failed.

[0056] Specifically, when comparing the physical output signal of the first signal channel with the communication confirmation signal of the second signal channel to obtain the consistency status of the two channels, the system first performs anti-jitter filtering on the physical output signal of the first signal channel. This includes continuously sampling the switch signal using digital filtering circuits or software algorithms to remove high-frequency jitter and transient interference, thereby obtaining a first standardized logic state characterizing the mechanical contact status of the limit switch. Simultaneously, the system performs communication validity detection on the communication confirmation signal of the second signal channel. This includes checking the reception integrity, frame verification, and reception time of the communication message within each sampling period to determine if the communication is within a preset timeout threshold. When all checks pass, the communication confirmation signal is mapped to a logic "1" of the second standardized logic state; if any check fails, it is mapped to a logic "0" to reflect the validity or failure status of the limit switch communication state. Within a set sampling period, the control system performs a logical XOR operation on the first and second standardized logic states. That is, it compares the logic states of the two channels simultaneously at each sampling point. When they are inconsistent, the XOR operation result is true, generating an inconsistency trigger signal. In response to the inconsistency trigger signal, the system starts an acknowledgment timer to record the duration of the inconsistency state and continuously monitors the signal status. If the inconsistency trigger signal persists after the duration reaches a preset first acknowledgment duration threshold, the two channels are determined to be inconsistent; if the inconsistency trigger signal disappears before reaching the first acknowledgment duration threshold, the two channels are determined to be consistent. The first acknowledgment duration threshold is specifically used for determining the consistency state of the two channels. The sampling period can be set according to the mechanical action characteristics of the limit switch and the signal change rate, for example, between 1 millisecond and 100 milliseconds; the first acknowledgment duration threshold can be set as the cumulative time of several sampling periods to prevent misjudgment caused by instantaneous interference. For example, when the mechanical contact state of the first signal channel is closed logic "1", while the communication acknowledgment signal of the second signal channel is mapped to logic "0" due to message loss, and the inconsistency persists for 5 consecutive sampling periods, the system determines it to be inconsistent and triggers corresponding interlocking measures. Furthermore, the communication validity detection ensures the reliability of the dual-channel comparison. It verifies message integrity, frame checksum, and reception time in each sampling period, guaranteeing that even with single-transmission packet loss or brief jitter, misjudgment will not occur. It also provides an implementation method operable by ordinary engineers, such as reading messages and performing software verification through the microcontroller's communication interface. Through these steps, the system achieves real-time, accurate, and reliable dual-channel consistency determination during limit switch assembly and disassembly, thereby ensuring the safety of the assembly and disassembly operations.

[0057] When the signal change rate exceeds the preset stability threshold, or when the time for which the consistency status of the two channels is inconsistent reaches the second confirmation duration threshold, the operation of the device actuator associated with the limit switch is prohibited.

[0058] Furthermore, when the signal change rate exceeds a preset stability threshold, or when the time for which the consistency status of the two channels is inconsistent reaches a second confirmation duration threshold, the operation of the device actuator associated with the limit switch is prohibited, including:

[0059] When the rate of change of the signal is detected to exceed a preset stability threshold, or when the consistency status of the two channels is inconsistent, an abnormal flag signal is generated.

[0060] After generating the anomaly flag signal, a confirmation timer is started for continuous monitoring;

[0061] When the duration of the abnormal flag signal reaches the second confirmation duration threshold preset in the confirmation timer, a device actuator prohibition command is triggered. The second confirmation duration threshold is used to trigger the device actuator prohibition command.

[0062] In response to a prohibition command from the device actuator, a safety control operation is performed, which includes sending a stop lock signal to the driver of the device actuator or cutting off the power supply to the device actuator.

[0063] Specifically, when the signal acquisition and rate of change calculation module detects that the signal rate of change exceeds a preset stability threshold, the stability threshold can be set based on the statistical characteristics of the electrical signal rate of change of the limit switch under normal conditions, taking 2 to 3 times its standard deviation as the stability threshold. Alternatively, when the two-channel consistency determination module determines that the consistency states of the two channels are inconsistent, the operation prohibition control module will immediately generate an abnormal flag signal. After generating the abnormal flag signal, the system will start a confirmation timer to monitor the duration of the abnormal state. This confirmation timer can be set independently or reused with the timer in the consistency determination module, but uses an independent second confirmation duration threshold. This second confirmation duration threshold aims to filter out transient, non-continuous abnormalities, such as brief signal glitches or communication jitter, to ensure the reliability of interlock triggering. When the duration of the abnormal flag signal reaches the preset second confirmation duration threshold in the confirmation timer, the second confirmation duration threshold is used to trigger the device actuator prohibition command. The second confirmation duration threshold can be determined based on the device response time and communication refresh cycle, preferably 100-500ms, to filter out transient, non-continuous abnormalities (such as signal glitches or communication jitter) and ensure the reliability of interlock triggering. This indicates that the abnormal state is stable and not a transient interference, and the operation prohibition control module immediately triggers the device actuator prohibition command. In response to the device actuator prohibition command, the system performs the final safety control operation to achieve mandatory protection of the device. The safety control operation includes, but is not limited to, the following two methods: 1) Sending a stop lock signal to the driver of the device actuator. The stop lock signal can be a digital high-level signal (such as 24V DC), or triggering the driver's safe torque off (STO) interface through the closure of the safety relay contacts, causing the driver to enter a safe stop state. 2) Directly cutting off the power supply to the device actuator, for example, by controlling a safety relay or contactor to disconnect the main circuit power supply. Through the above process, the system achieves real-time, reliable, and mandatory safety interlocking for abnormal states during the disassembly and assembly of limit switches, effectively preventing the risk of equipment malfunction. This solution balances response speed and anti-interference capability in the decision-making process for anomaly detection and operational prohibition, achieving adaptability and robustness of the safety protection logic.

[0064] After installation, when the signal change rate is lower than the stability threshold and the time for the two channels to be in a consistent state reaches the third confirmation duration threshold, the normal operation of the device actuator will be automatically restored.

[0065] Furthermore, the automatic restoration of the normal operation of the device actuator includes:

[0066] After detecting that the rate of change of the signal is lower than the stability threshold and that the consistency status of the two channels is consistent, the confirmation timer is started;

[0067] When the confirmation timer reaches a preset third confirmation duration threshold and the electrical safety conditions are met, a safety recovery command is generated.

[0068] The electrical safety conditions include the signal change rate being consistently lower than the stability threshold, the consistency state of the two channels being consistently consistent, the current value of the electrical signal parameter being consistently higher than the preset minimum current threshold, and the impedance value of the electrical signal parameter being consistently lower than the preset maximum impedance threshold.

[0069] In response to the security recovery command, the prohibition on the operation of the device actuator is lifted.

[0070] Specifically, after the limit switch installation is completed, the system enters the signal stability and consistency monitoring phase. When the signal change rate is detected to be lower than the stability threshold and the consistency status of the two channels is consistent, the control system determines that the limit switch installation status is stable and reliable, and automatically initiates the normal operation recovery process of the equipment actuator. Specifically, after the control system detects that the signal change rate is lower than the stability threshold and the consistency status of the two channels is consistent, it immediately starts a confirmation timer and continuously monitors various safety parameters within a third confirmation duration threshold. The timing process of the confirmation timer is implemented by the timing management program module inside the programmable logic controller (PLC) or industrial computer (IPC), and its timing accuracy can reach the millisecond level to ensure real-time tracking of the status changes after the limit switch installation. Within the third confirmation duration threshold, the system determines whether electrical safety conditions are met. These electrical safety conditions include: the signal change rate continuously being lower than the stability threshold, the consistency status of the two channels continuously being consistent, the current value of the electrical signal parameter continuously being higher than a preset minimum current threshold, and the impedance value of the electrical signal parameter continuously being lower than a preset maximum impedance threshold. The system synchronously samples the above parameters at a sampling period of 100 milliseconds within the third confirmation time threshold and performs real-time judgment through a logical AND operation module. If any electrical safety condition is not met in any sampling period, the timing is immediately interrupted, maintaining the equipment in a prohibited state. The values ​​of the minimum current threshold and maximum impedance threshold can be set by the operator through the system configuration interface to adapt to the rated current characteristics and wiring impedance characteristics of different models of limit switches. When the control system detects that all the above electrical safety conditions are continuously met throughout the entire confirmation time period, the system generates a safety recovery command. The safety recovery command is output through the logic control module (which can be implemented in the PLC program or MCU control logic), driving the output port of the digital output module (DO module) to send a recovery permission signal to the equipment actuator. The recovery permission signal can be a 24V DC high-level signal or a relay contact closing signal, used to release the operation prohibition state of the actuator. After receiving the recovery permission signal, the equipment actuator switches to normal operation mode, thereby achieving automatic recovery. If any electrical safety condition is not continuously met within the third confirmation time threshold, the system interrupts the recovery process, maintains the operation prohibition state, and issues an alarm prompt on the control interface. For example, in a specific application, after the limit switch is installed, the system detects that the rate of change of the current parameter is stable below 0.5 mA / s (below the set stability threshold of 1 mA / s), the impedance value is maintained below 50 Ω (below the maximum impedance threshold of 100 Ω), and the consistency state of the two channels remains consistent.Under these conditions, the control system starts a confirmation timer for 2 seconds, during which all parameters are collected synchronously with a sampling period of 100 milliseconds. After confirming that all electrical safety conditions are continuously met, the system generates a safety recovery command and outputs a 24V high-level recovery permission signal through the digital output module. After receiving the signal, the equipment actuator automatically resumes normal operation.

[0071] The automatic recovery process described in this embodiment is achieved through hardware and software collaboration. The signal acquisition section provides real-time parameter input, the timing management program module performs safety condition judgment and timing control, and the logic control module and digital output module complete the electrical output of the recovery command, thereby ensuring the safety, traceability and verifiability of the entire process of limit switch disassembly and assembly.

[0072] The automatic recovery process described in this embodiment is achieved through hardware and software collaboration. The signal acquisition part provides real-time parameter input, the logic control module performs safety condition judgment and timing control, and the output control interface completes the electrical control of the actuator, thereby ensuring the safety and traceability of the entire process of limit switch disassembly and assembly.

[0073] In summary, the embodiments of this application have at least the following technical effects:

[0074] Before disassembling and installing the limit switch, the operator's identity is verified. Disassembly and installation are permitted only after successful verification. During disassembly and installation, electrical signal parameters of the limit switch are collected, and the signal change rate is calculated based on these parameters. The physical output signal of the first signal channel (the switching signal generated by the mechanical contact opening and closing of the limit switch) is collected, and the communication confirmation signal of the second signal channel is collected. This communication confirmation signal is transmitted from the internal circuit of the limit switch to the current status information of the control system via a communication bus. The physical output signal of the first signal channel is compared with the communication confirmation signal of the second signal channel to obtain the consistency status of the two channels. When the signal change rate exceeds a preset stability threshold, or when the time for the two channels to be inconsistent reaches a second confirmation duration threshold, the operation of the device actuator associated with the limit switch is prohibited. After installation, when the signal change rate is lower than the stability threshold and the time for the two channels to be consistent reaches a third confirmation duration threshold, the normal operation of the device actuator is automatically restored.

[0075] Example 2, based on the same inventive concept as the safety interlock control method for the limit switch assembly and disassembly process in the aforementioned examples, such as... Figure 2 As shown, this application provides a safety interlock control system for the assembly and disassembly of limit switches. The system and method embodiments in this application are based on the same inventive concept. The system includes:

[0076] The identity verification module 10 is used to verify the identity of the operator before performing the disassembly and installation of the limit switch. When the identity verification is successful, the disassembly and installation operation is allowed.

[0077] The signal acquisition and rate of change calculation module 20 is used to acquire electrical signal parameters of the limit switch during disassembly and assembly, calculate the signal rate of change based on the electrical signal parameters, acquire the physical output signal of the first signal channel, which is the switching signal generated by the mechanical contact opening and closing of the limit switch, and acquire the communication confirmation signal of the second signal channel, which is transmitted from the internal circuit of the limit switch to the current status information of the control system through the communication bus.

[0078] The two-channel consistency determination module 30 is used to compare the physical output signal of the first signal channel with the communication confirmation signal of the second signal channel to obtain the consistency status of the two channels.

[0079] The operation prohibition control module 40 is used to prohibit the operation of the device actuator associated with the limit switch when the signal change rate exceeds a preset stability threshold, or when the time when the consistency status of the two channels is inconsistent reaches a second confirmation duration threshold.

[0080] The operation recovery control module 50 is used to automatically restore the normal operation of the device actuator after installation operation when the signal change rate is lower than the stability threshold and the time when the consistency status of the two channels is consistent reaches the third confirmation duration threshold.

[0081] It should be noted that the order of the embodiments described above is merely for descriptive purposes and does not represent the superiority or inferiority of the embodiments. Furthermore, specific embodiments have been described above. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps described in the claims can be performed in a different order than that shown in the embodiments and still achieve the desired result. Additionally, the processes depicted in the drawings do not necessarily require a specific or sequential order to achieve the desired result. In some embodiments, multitasking and parallel processing are also possible or may be advantageous.

[0082] The above description is only a preferred embodiment of this application and is not intended to limit this application. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the protection scope of this application.

[0083] This specification and accompanying drawings are merely illustrative examples of this application and are intended to cover any and all modifications, variations, combinations, or equivalents within the scope of this application. Clearly, those skilled in the art can make various alterations and modifications to this application without departing from its scope. Therefore, if such modifications and modifications fall within the scope of this application and its equivalents, this application intends to include such modifications and modifications.

Claims

1. A safety interlock control method for the disassembly and assembly process of limit switches, characterized in that, include: Before disassembling and installing the limit switch, verify the operator's identity. Disassembly and installation are permitted only after the identity verification is passed. During the disassembly and assembly process, the electrical signal parameters of the limit switch are collected, the signal change rate is calculated based on the electrical signal parameters, the physical output signal of the first signal channel is collected, the physical output signal is the switching signal generated by the mechanical contact opening and closing of the limit switch, and the communication confirmation signal of the second signal channel is collected. The communication confirmation signal is the current status information transmitted from the internal circuit of the limit switch to the control system through the communication bus. The physical output signal of the first signal channel is compared with the communication confirmation signal of the second signal channel to obtain the consistency status of the two channels. The step of comparing the physical output signal of the first signal channel with the communication confirmation signal of the second signal channel to obtain the consistency status of the two channels includes: The physical output signal of the first signal channel is subjected to anti-jitter filtering to obtain the first standardized logic state characterizing the mechanical contact state of the limit switch. Simultaneously, the communication validity of the communication confirmation signal of the second signal channel is detected to obtain a second standardized logic state characterizing the communication status of the limit switch; Under the set sampling period, a logical XOR operation is performed on the first standardized logic state and the second standardized logic state. When the operation result is true, an inconsistency trigger signal is generated. In response to the inconsistency trigger signal, an acknowledgment timer is started to monitor the duration. When the duration of the inconsistency trigger signal reaches a preset first confirmation duration threshold, the consistency status of the two channels is determined to be inconsistent. The first confirmation duration threshold is specifically used for determining the consistency status of the two channels. If the inconsistency trigger signal disappears before the first confirmation duration threshold is reached, the consistency status of the two channels is determined to be consistent. When the signal change rate exceeds the preset stability threshold, or when the time for which the consistency status of the two channels is inconsistent reaches the second confirmation duration threshold, the operation of the device actuator associated with the limit switch is prohibited. After installation, when the signal change rate is lower than the stability threshold and the time for the two channels to be in a consistent state reaches the third confirmation duration threshold, the normal operation of the device actuator will be automatically restored.

2. The safety interlock control method for the disassembly and assembly process of the limit switch according to claim 1, characterized in that, The acquisition of electrical signal parameters of the limit switch, and the calculation of the signal change rate based on the electrical signal parameters, include: When the limit switch is in the process of disassembly and assembly, the electrical signal parameters are sampled synchronously at multiple points according to the preset sampling period, and the electrical signal parameters are filtered and denoised. The filtering and denoising process includes moving average filtering or median filtering. For the electrical signal parameters after filtering and denoising, calculate the rate of change of the signal, which is the rate of change of voltage, the rate of change of current, and the rate of change of impedance.

3. The safety interlock control method for the disassembly and assembly process of the limit switch according to claim 1, characterized in that, The communication validity detection includes: Within each sampling period, the integrity of the received communication message, the correctness of the frame verification, and the reception time are all within a preset timeout threshold. If all tests pass, the communication is considered valid; If any test fails, the communication is deemed to have failed.

4. The safety interlock control method for the disassembly and assembly process of the limit switch according to claim 1, characterized in that, When the signal change rate exceeds a preset stability threshold, or when the time for which the consistency status of the two channels is inconsistent reaches a second confirmation duration threshold, the operation of the device actuator associated with the limit switch is prohibited, including: When the rate of change of the signal is detected to exceed a preset stability threshold, or when the consistency status of the two channels is inconsistent, an abnormal flag signal is generated. After generating the anomaly flag signal, a confirmation timer is started for continuous monitoring; When the duration of the abnormal flag signal reaches the second confirmation duration threshold preset in the confirmation timer, a device actuator prohibition command is triggered. The second confirmation duration threshold is used to trigger the device actuator prohibition command. In response to a prohibition command from the device actuator, a safety control operation is performed, which includes sending a stop lock signal to the driver of the device actuator or cutting off the power supply to the device actuator.

5. The safety interlock control method for the disassembly and assembly process of the limit switch according to claim 1, characterized in that, The automatic restoration of the normal operation of the device actuator includes: After detecting that the rate of change of the signal is lower than the stability threshold and that the consistency status of the two channels is consistent, the confirmation timer is started; When the confirmation timer reaches the preset third confirmation duration threshold and the electrical safety conditions are met, a safety recovery command is generated. The electrical safety conditions include the signal change rate being consistently lower than the stability threshold, the consistency state of the two channels being consistently consistent, the current value of the electrical signal parameter being consistently higher than the preset minimum current threshold, and the impedance value of the electrical signal parameter being consistently lower than the preset maximum impedance threshold. In response to the security recovery command, the prohibition on the operation of the device actuator is lifted.

6. The safety interlock control method for the disassembly and assembly process of the limit switch according to claim 1, characterized in that, The verification of the operator's identity includes: Perform digital signature verification and validity period check on the digital identity certificate provided by the operator; Extract the device operation permission level identifier from the verified digital identity certificate; In response to the fact that the device operation permission level identifier meets the permission requirements for limit switch disassembly and assembly operations, a temporary operation authorization certificate containing a unique authorization identifier, authorization effective time, and authorization termination time is generated; During the installation and removal of the limit switch, the timing relationship between the current system time and the authorized termination time is continuously monitored; The removal or installation of the limit switch is permitted only when the system is currently within the valid time interval from the authorization effective time to the authorization termination time; When the current system time exceeds the authorization termination time, the valid operation permissions of the temporary operation authorization certificate will be automatically revoked.

7. A safety interlock control system for the assembly and disassembly of limit switches, characterized in that, The system is used to implement the safety interlock control method for the disassembly and assembly process of the limit switch as described in any one of claims 1 to 6, and the system includes: An identity verification module is used to verify the identity of the operator before performing the disassembly and installation of the limit switch. When the identity verification is successful, the disassembly and installation operation is allowed. The signal acquisition and rate of change calculation module is used to acquire electrical signal parameters of the limit switch during disassembly and assembly, calculate the signal rate of change based on the electrical signal parameters, acquire the physical output signal of the first signal channel, which is the switching signal generated by the mechanical contact opening and closing of the limit switch, and acquire the communication confirmation signal of the second signal channel, which is the current status information transmitted from the internal circuit of the limit switch to the control system through the communication bus. A two-channel consistency determination module is used to compare the physical output signal of the first signal channel with the communication confirmation signal of the second signal channel to obtain the consistency status of the two channels. The step of comparing the physical output signal of the first signal channel with the communication confirmation signal of the second signal channel to obtain the consistency status of the two channels includes: The physical output signal of the first signal channel is subjected to anti-jitter filtering to obtain the first standardized logic state characterizing the mechanical contact state of the limit switch. Simultaneously, the communication validity of the communication confirmation signal of the second signal channel is detected to obtain a second standardized logic state characterizing the communication status of the limit switch; Under the set sampling period, a logical XOR operation is performed on the first standardized logic state and the second standardized logic state. When the operation result is true, an inconsistency trigger signal is generated. In response to the inconsistency trigger signal, an acknowledgment timer is started to monitor the duration. When the duration of the inconsistency trigger signal reaches a preset first confirmation duration threshold, the consistency status of the two channels is determined to be inconsistent. The first confirmation duration threshold is specifically used for determining the consistency status of the two channels. If the inconsistency trigger signal disappears before the first confirmation duration threshold is reached, the consistency status of the two channels is determined to be consistent. The operation prohibition control module is used to prohibit the operation of the device actuator associated with the limit switch when the signal change rate exceeds a preset stability threshold, or when the time when the consistency status of the two channels is inconsistent reaches a second confirmation duration threshold. The operation recovery control module is used to automatically restore the normal operation of the device actuator after installation operation when the signal change rate is lower than the stability threshold and the time when the consistency status of the two channels is consistent reaches the third confirmation duration threshold.

Citation Information

Patent Citations

  • CN103472795A

  • CN107526003A