Safety monitoring and linkage alarm system and method

By using a dual-channel monitoring mechanism, the "heartbeat signal" and fault signal of the equipment's local control system are monitored, which solves the problem of silent faults caused by the failure of the equipment's local control system, realizes full-domain linkage alarm and rapid emergency response, and improves the safety and production stability of distributed equipment.

CN121907884APending Publication Date: 2026-04-21FEV POWERTRAIN TECH CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
FEV POWERTRAIN TECH CO LTD
Filing Date
2026-01-16
Publication Date
2026-04-21

AI Technical Summary

Technical Problem

Existing technologies cannot effectively detect and handle "silent failures" caused by the complete failure of the local control system of the equipment, creating a blind spot in safety monitoring. This can lead to the equipment continuing to operate in an uncontrolled state, causing losses or accidents.

Method used

A dual-channel monitoring mechanism is adopted. The first monitoring channel monitors the "heartbeat signal" of the local control system of the equipment to detect its survival status, while the second channel monitors the equipment fault signal. When an abnormality is detected in either channel, a global linkage alarm is triggered, including emergency stop control and audible and visual alarms independent of the local control system.

Benefits of technology

It enables proactive detection and response to failures in the local control system of the equipment, ensuring that alarm information is transmitted without delay in high-noise environments, thereby improving the safety of equipment operation and the speed of emergency response.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121907884A_ABST
    Figure CN121907884A_ABST
Patent Text Reader

Abstract

The invention provides a safety monitoring and linkage alarm system and method, belongs to the technical field of industrial safety monitoring, and aims to solve the problem of a'silent fault 'monitoring blind area caused by function failure of a local control system of equipment. The system comprises a central control unit, a plurality of monitored equipment units distributed in a plurality of working areas, and an alarm device. The central control unit monitors through two channels: a first monitoring channel monitors a first state signal output by a local control system of each equipment unit, and sends an emergency stop control signal to the corresponding equipment unit when the signal is lost within a preset duration; the second monitoring channel receives the second state signals output by all the equipment units, and when any second state signal is received, the alarm devices in all the working areas are triggered to carry out linkage alarm. The system can actively detect and deal with a silent fault, guarantees the early warning reliability in a severe environment through global linkage alarm, and improves the overall safety.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of industrial safety monitoring, and particularly to a safety monitoring and linkage alarm system and method for distributed devices. Background Art

[0002] In modern industrial production and test environments, such as engine test workshops, automated production lines, etc., a large number of distributed device units are usually deployed. These device units are often grouped and set in different working areas that are physically isolated or far apart. During the operation of the devices, there is usually high-intensity environmental noise on-site, which makes it difficult for operators to effectively identify the device fault alarm sounds from remote working areas through hearing, forming a safety monitoring blind spot.

[0003] To solve the above problems, some centralized monitoring systems have been proposed in the prior art, such as the patent document CN117369376A. Such systems can collect the conventional fault signals reported by each distributed device and perform unified monitoring in the central control room. When a fault signal is detected from a certain device, the system can trigger the alarm devices set in all working areas to achieve linkage alarm, thus solving to a certain extent the problem of poor transmission of alarm information caused by physical isolation or environmental noise. However, the existing centralized monitoring systems of this kind generally rely on the normal operation of the device local control system and the active reporting of fault signals. Once the local control system of a certain device fails completely due to reasons such as program crash, hardware damage, etc., that is, it falls into the so-called "silent fault" state, it will lose the ability to send any fault signals. At this time, the central monitoring system cannot receive any abnormal information and thus cannot trigger an alarm, forming an extremely dangerous hidden safety risk, which may cause the device to continue running in an out-of-control state, leading to more serious losses or safety accidents. Summary of the Invention

[0004] Aiming at the defects in the prior art, the purpose of the present invention is to provide a safety monitoring and linkage alarm system and method, aiming to solve the technical problem in the prior art that it is impossible to effectively detect and handle the "silent fault" caused by the complete failure of the device local control system, so as to eliminate the safety monitoring blind area.

[0005] To achieve the above objectives, the present invention provides a security monitoring and alarm linkage system applicable to scenarios comprising multiple physically dispersed work areas. The system includes: at least one central control unit; a plurality of monitored device units distributed across the plurality of work areas, each monitored device unit having a local control system; and alarm devices installed in the plurality of work areas. The central control unit monitors the plurality of monitored device units through a first monitoring channel and a second monitoring channel. The first monitoring channel is used to: receive and monitor a first status signal output by the local control system of each monitored device unit, indicating that its own operating status is normal; and, when it is determined that the first status signal of any monitored device unit is interrupted or lost within a preset time period, send an emergency stop control signal to that monitored device unit. The second monitoring channel is used to: receive a second status signal output by each monitored device unit, the second status signal indicating that the monitored device unit has malfunctioned; and, upon receiving the second status signal of any monitored device unit, trigger the alarm devices installed in all work areas.

[0006] Furthermore, the central control unit is a programmable logic controller or an industrial control computer.

[0007] Furthermore, the monitored equipment unit is an engine test bench.

[0008] Furthermore, the first state signal is a periodic pulse signal.

[0009] Furthermore, the alarm device is an audible and visual alarm, and the audible and visual alarm satisfies at least one of the following: the sound pressure level of the audible alarm is not less than 110dB; the visual alarm is a high-brightness lamp with multiple flashing modes.

[0010] Furthermore, the central control unit transmits signals to each monitored device unit via hardwiring or an industrial network.

[0011] This invention also provides a safety monitoring and alarm linkage method, applied to a scenario where several monitored equipment units distributed across multiple physically dispersed work areas are monitored. The method includes the following steps: receiving and monitoring a first status signal output by the local control system of each monitored equipment unit, which indicates that its own operating status is normal; when it is determined that the first status signal of any monitored equipment unit is interrupted or lost within a preset time period, sending an emergency stop control signal to the monitored equipment unit; receiving a second status signal output by each monitored equipment unit, which indicates that the monitored equipment unit has malfunctioned; and triggering an alarm device installed in all work areas when the second status signal of any monitored equipment unit is received.

[0012] Further, the method satisfies at least one of the following: the method is executed by a central control unit, and the central control unit is a programmable logic controller or an industrial control computer; the monitored device unit is an engine test bench.

[0013] Further, the first status signal is a periodic pulse signal, and the step of monitoring the first status signal specifically includes: detecting whether the periodic pulse signal stops flipping within a preset duration.

[0014] Further, the step of triggering the alarm device includes performing at least one of the following: starting an audible alarm with a sound pressure level not lower than 110 dB; starting a light alarm with a high brightness and multi-flashing mode.

[0015] Compared with the prior art, the present invention has the following beneficial effects:

[0016] 1. By creating an independent first monitoring channel separate from the conventional fault reporting to monitor the first status signal (i.e., the heartbeat signal) representing the survival status of the local control system, the present invention can actively detect this "silent fault" state when the local control system itself completely fails and is unable to report any information, and forcefully send an emergency stop signal from the outside to stop the device. This compensates for the defect of the prior art that can only passively respond to reported faults, provides dual safety protection, and fundamentally avoids the risk of device out-of-control caused by the failure of the controller function.

[0017] 2. Through the second monitoring channel, when receiving the conventional fault signal of any device, the present invention can synchronously trigger the alarm devices in all working areas to achieve global linkage alarm. This ensures that even in a harsh industrial environment with long distances and high noise, the alarm information can be clearly perceived by all on-site personnel without delay, effectively solving the problem of "unable to hear clearly and see" the alarm signal in the traditional monitoring method.

[0018] 3. The global synchronous alarm of the present invention enables all staff at scattered points to simultaneously learn about the occurrence of the fault, without the need to transmit and confirm information through means such as intercoms, shortening the overall emergency response time and winning valuable time for quickly troubleshooting and resuming production. BRIEF DESCRIPTION OF THE DRAWINGS

[0019] By reading the detailed description of the non-restrictive embodiments with reference to the following drawings, other features, objectives, and advantages of the present invention will become more apparent: Figure 1 It is a schematic structural diagram of a safety monitoring and linkage alarm system provided by an embodiment of the present invention; Figure 2 It is a schematic flow diagram of a safety monitoring and linkage alarm method provided by an embodiment of the present invention; Figure 3 This is a schematic diagram of signaling interaction timing provided for an embodiment of the present invention. Detailed Implementation

[0020] The present invention will now be described in detail with reference to specific embodiments. These embodiments will help those skilled in the art to further understand the present invention, but do not limit the invention in any way. It should be noted that those skilled in the art can make several changes and improvements without departing from the concept of the present invention. These all fall within the scope of protection of the present invention.

[0021] Example 1 This embodiment provides a safety monitoring and alarm linkage system based on hardwiring, which can be applied to scenarios involving multiple physically dispersed engine testing workshops. Please refer to... Figure 1 The figure is a schematic diagram of the overall structure of a safety monitoring and linkage alarm system provided in an embodiment of the present invention. The system includes a central control unit, which in this embodiment may be a central programmable logic controller system; several monitored equipment units, which in this embodiment are specifically engine test benches distributed in multiple working areas; and alarm devices installed in each working area, which in this embodiment are specifically audible and visual alarms.

[0022] Specifically, the central programmable logic controller (PLC) system, as the core of the entire monitoring system, is responsible for receiving and processing signals from all monitored device units and issuing control commands according to preset logic. As a specific implementation, a Siemens S7-1200 series PLC can be used as the central PLC system, which features stability, reliability, ease of programming, and expandability. This central PLC system includes digital input modules and digital output modules for signal interaction with external devices.

[0023] The engine test benches are the monitored objects, and they are grouped and set up in multiple physically isolated or geographically distant work areas, such as in separate test workshops "Area A" and "Area N". Each engine test bench is equipped with an independent local controller, which is responsible for the bench's own operation control, parameter acquisition, and basic fault diagnosis. It should be noted that in industrial settings, especially in engine testing environments, background noise is often above 100dB, making it extremely difficult for operators to detect local alarms from distant test benches.

[0024] To address the aforementioned issues, the system of this invention constructs a dual-channel monitoring and response mechanism, which is realized through signal interaction between the central programmable logic controller system and each engine test bench.

[0025] The first monitoring channel is used to monitor "silent faults," which are faults where the local controller of the test bench completely fails (e.g., program crash or hardware damage) and cannot send any signals. This channel is implemented as follows: the local controller of each engine test bench is programmed to periodically output a first status signal indicating its normal operating status through a digital output point during normal operation. In this embodiment, this first status signal can be a periodic pulse signal, such as a square wave signal with a frequency of 1 Hz and a voltage of 24 volts DC; this signal can also be called a "heartbeat signal." This heartbeat signal is hardwired to a digital input channel of the central programmable logic controller (PLC) system. Accordingly, the PLC system allocates an independent input channel to each connected engine test bench to receive its heartbeat signal.

[0026] Please refer to the following: Figure 2 This figure is a flowchart illustrating a security monitoring and alarm linkage method provided by an embodiment of the present invention. After system startup (step S100), the internal program of the central programmable logic controller (PLC) system begins to execute cyclically. For the first monitoring channel, the program executes step S110, which monitors the heartbeat signal. Specifically, the PLC program sets an independent timer for each heartbeat signal input channel and sets a preset duration, such as 1 second. In each scan cycle, the program detects whether the level state of the input channel has changed (i.e., from high level to low level, or from low level to high level). If the local controller of the test bench is working normally, its output heartbeat signal will change regularly, and the program will continuously reset the corresponding timer. Then, in step S111, if a local controller of the test bench malfunctions, its heartbeat signal output will stop changing and remain at a constant high or low level. If the central PLC system fails to detect the level change of the channel within the preset duration of 1 second, the corresponding timer will time out. At this time, the system determines that the heartbeat signal of the test bench is lost, that is, it is considered that the local controller of the test bench has malfunctioned. Once the determination is correct, the system immediately executes step S112, sending an emergency stop signal. This involves sending an emergency stop control signal A2 to the engine test bench that has experienced a malfunction through an output channel of its digital output module. This emergency stop control signal A2 typically drives a relay whose contacts are connected in series in the engine test bench's external emergency stop circuit. Thus, regardless of the state of the test bench's local controller, this external emergency stop signal can physically force the disconnection of critical power supplies or actuators from the test bench, bringing it to a safe shutdown state.

[0027] Accordingly, the second monitoring channel is used to monitor routine faults, namely faults that can be detected by the local controller of the engine test bench, such as overheating, overspeeding, and low oil pressure. This channel is implemented as follows: when the local controller of each engine test bench detects a fault in the equipment it manages, it outputs a second status signal to indicate that the monitored equipment unit has failed. In this embodiment, the second status signal is specifically a fault shutdown signal, for example, output through the normally open contact of a fault relay. Under normal circumstances, this contact is open; when a fault occurs, the contact is closed. The output of this fault shutdown signal is also hardwired to another independent digital input channel of the central programmable logic controller system.

[0028] Same reference Figure 2 During system operation, the central programmable logic controller (PLC) system executes the fault signal monitoring step S120 in parallel. Its program continuously scans all connected fault signal input channels. In the step S121 of determining whether a fault signal has been received, once the input level of any channel changes from low to high (indicating that the fault relay contact of the corresponding test bench is closed), the system determines that a second status signal from a certain engine test bench has been received. Once this is determined, the system immediately executes the step S122 of sending a linkage alarm signal. In this step, the system simultaneously drives the audible and visual alarms connected to all working areas (e.g., area A and area N) through its digital output module, sending alarm trigger signals A3 to them.

[0029] It should be noted that, to ensure the alarm signal remains clearly identifiable even in high-noise environments up to 100dB, this embodiment preferably employs a high-performance audible and visual alarm. This alarm is a combined unit; its audible alarm has a sound pressure level of no less than 110dB, capable of penetrating strong background noise; its visual alarm is a high-brightness red strobe light that attracts the operator's attention through a strong visual flashing signal. When the linked alarm is triggered, all audible and visual alarms in the workshop simultaneously emit a high-dB alarm sound and a conspicuous red flashing light, ensuring that regardless of where the fault occurs, all personnel in all areas can be notified of the fault immediately without delay, thus achieving a comprehensive linked alarm system.

[0030] After completing one monitoring cycle, regardless of whether an emergency stop or alarm action is triggered, the process will return to the monitoring heartbeat signal step S110 through the loop step S130 to start a new round of scanning, thereby achieving continuous and parallel monitoring of the two fault modes.

[0031] Please refer to the following: Figure 3This figure is a schematic diagram of the signaling interaction timing provided in an embodiment of the present invention, which more intuitively illustrates the working logic of the system. In a normal fault scenario, test bench A experiences a normal fault at time t1 and sends a fault signal to the central control unit. The central control unit immediately sends an alarm trigger signal to all alarms after a very short response time (time t2). In a silent fault scenario, test bench A continuously sends a heartbeat signal normally until time t3, but its local controller fails at time t3, and the heartbeat signal stops. After a preset timeout period Δt (e.g., 1 second), the central control unit determines that the heartbeat is lost at time t3+Δt and immediately sends an emergency stop signal to test bench A, forcing it to shut down.

[0032] It is understandable that the technical solution provided in this embodiment can not only effectively monitor and respond to routine faults reported by the device itself and achieve reliable early warnings that overcome environmental limitations, but more importantly, it solves the monitoring blind spot of "silent faults" caused by the controller "crashing" due to the independent heartbeat monitoring channel, providing dual security protection and greatly improving the overall security in a distributed device environment.

[0033] Example 2 As an optional implementation, this embodiment provides a variant of the security monitoring and alarm linkage system. Its core monitoring logic is the same as in Embodiment 1, but it demonstrates the system's adaptability to different hardware platforms and application scenarios. In this embodiment, the central control unit is no longer a programmable logic controller (PLC), but an industrial control computer equipped with a real-time operating system. Furthermore, the monitored equipment units are no longer engine test benches, but multiple stacker cranes used in automated storage and retrieval systems (AS / RS).

[0034] Specifically, in this embodiment, the central control unit can be a high-performance industrial control computer, on which a multi-channel digital input / output acquisition card is installed. This industrial control computer runs specially developed monitoring software that implements the same dual-channel monitoring logic as the programmable logic controller program in Embodiment 1.

[0035] The monitored equipment units are multiple stacker cranes distributed in different aisles of the automated warehouse (equivalent to the work area in Example 1). Each stacker crane has its own local control system, which is usually a programmable logic controller or a dedicated controller.

[0036] The first monitoring channel is implemented as follows: Each stacker crane's local control system is also configured to output a periodically toggling first status signal (heartbeat signal) during normal operation. This signal is connected via cable to the digital input terminal of the industrial control computer's input / output acquisition card. The monitoring software running on the industrial control computer reads the status of all input channels on the acquisition card through high-frequency polling. For example, the software checks the heartbeat signal channel corresponding to each stacker crane at a 500-millisecond cycle. Internally, the software maintains a timestamp for the last state toggle for each channel. If, during the check, the difference between the current time and the last toggle timestamp of a certain channel exceeds a preset duration (e.g., set to 1.5 seconds), the monitoring software determines that the stacker crane's local control system has malfunctioned. At this time, the software immediately sends an emergency stop control signal to the stacker crane's safety circuit through the digital output channel of the input / output acquisition card, forcing it to brake and lose power.

[0037] The second monitoring channel is implemented as follows: When the local control system of each stacker crane detects a fault (such as incorrect cargo positioning or motor overload), it outputs a second status signal (fault signal). This signal is also connected to another set of digital input terminals of the industrial control computer's input / output acquisition card. The monitoring software polls these fault signal input channels in real time. Once it detects that the status of any channel has become valid (e.g., changing from low to high), the software immediately determines that a stacker crane has experienced a routine fault. In response, the software immediately broadcasts an alarm command through the acquisition card's output channel to alarm devices (such as audible and visual alarm towers) installed in all warehouse aisles, entrances, and other critical locations, triggering all alarm devices to activate simultaneously to notify all staff and forklift drivers in all areas.

[0038] Therefore, this embodiment demonstrates that the dual-channel monitoring architecture proposed in this invention has good platform independence. Its core idea is not limited to using a programmable logic controller as the central control unit, but can also be applied to control systems based on industrial control computers or other types of microprocessors. Furthermore, its application scenarios are not limited to engine testing, but can be widely extended to automated warehouses, unmanned production lines, large equipment clusters, and other occasions requiring high-reliability and safety monitoring of distributed automated equipment.

[0039] Example 3 This embodiment further demonstrates a networked implementation of the technical solution of the present invention, which upgrades the hard-wired signal transmission in Embodiment 1 to network communication based on industrial Ethernet, thereby significantly improving the system's flexibility, scalability and simplifying field wiring.

[0040] In this embodiment, the system architecture is as follows: Figure 1As shown, the transmission medium for signals A1, A2, and A3 has changed from physical cables to industrial Ethernet. The central control unit is a high-performance programmable logic controller (PLC) that supports industrial Ethernet protocols (such as Profinet), such as the Siemens S7-1500 series PLC, which acts as the master station in the network.

[0041] Several engine test benches are distributed across various work areas. Their local controllers also need to support the corresponding industrial Ethernet protocol, acting as slave stations. All master programmable logic controllers and slave controllers are connected via industrial switches, forming an industrial Ethernet network.

[0042] Understandably, in this networked architecture, the transmission methods of the first and second state signals change accordingly. They are no longer independent physical level signals, but are encapsulated in data packets (or process images) periodically exchanged between the master and slave stations. The specific implementation is as follows: Each benchtop local controller acting as a slave station is configured with an output data area. The contents of this data area are automatically sent periodically (e.g., every 200 milliseconds) to the central programmable logic controller (PLC) system acting as the master station. For example, a "status word" in this data area can be used to transmit information required for monitoring. Bit 0 of this status word is defined as the "heartbeat bit," and the benchtop local controller's program inverts this bit in each scan cycle, creating a periodically toggling signal in the network packet. Bit 1 of this status word can be defined as the "fault bit," normally 0, and set to 1 when the local controller detects a routine fault.

[0043] The network implementation of the first monitoring channel (i.e., silent fault monitoring) is as follows: The central programmable logic controller system 100 acts as the master station. During configuration, a "watchdog" time or update time is set for each connected slave station (i.e., the engine test bench). This is equivalent to a preset duration at the network layer, for example, 500 milliseconds. During system operation, if the central programmable logic controller system does not receive a valid data packet from a slave station within 500 milliseconds, the system will determine that the slave station's communication has been interrupted or its local controller has completely "crashed." This process is equivalent to... Figure 2 The step S111, which determines whether a heartbeat has been lost, is shown. At this time, the central programmable logic controller (PLC) system 100 immediately executes step S112, which sends an emergency stop signal. This emergency stop control signal A2 is also sent via the network. For example, the PLC can send a set command to a safety input / output module installed near the faulty test bench, which also acts as a network slave. Upon receiving the command, the safety input / output module disconnects the test bench's safety loop through its physical output point.

[0044] Accordingly, the network implementation of the second monitoring channel (i.e., conventional fault monitoring) is as follows: the central programmable logic controller system 100 reads and parses the "status word" in the data packets received from all slave stations in each scan cycle, which corresponds to... Figure 2 The monitoring fault signal step S120 is described in the process. In step S121, which determines whether a fault signal has been received, the program checks the "fault bit" (i.e., the first bit) of each status word. Once the "fault bit" in any status word sent by a test bench is set to 1, the system determines that a regular fault has occurred on that test bench. In response, the system immediately executes step S122, which sends a linkage alarm signal. In this embodiment, the audible and visual alarm can also be an IP audible and visual alarm that supports the industrial Ethernet protocol. The programmable logic controller can achieve full-area linkage alarm by broadcasting or multicasting an alarm command (alarm trigger signal A3) to all IP audible and visual alarms in the network.

[0045] As a beneficial effect of this embodiment, the use of industrial network communication greatly simplifies the cabling cost and complexity of large-scale distributed systems. When adding new monitored devices, they only need to be connected to the network and configured in software, eliminating the need to lay a large number of signal cables, resulting in excellent system scalability. Furthermore, in addition to transmitting simple switch status signals, network messages can also transmit richer diagnostic information, such as specific fault codes and analog parameters, facilitating more advanced remote diagnostic and maintenance functions.

[0046] Example 4 Based on the previous embodiments, this embodiment further optimizes the form of the first status signal (i.e., heartbeat signal) in the first monitoring channel and proposes a security verification method based on a challenge-response mechanism to deal with the "fake dead" state where some local controller program logic has errors but the communication port is still not closed.

[0047] In this embodiment, the overall system architecture can adopt the hard-wiring method of Embodiment 1 or the networked method of Embodiment 3. The core difference lies in the interaction logic between the central control unit and the monitored device unit regarding the first state signal.

[0048] Unlike the previous embodiments where the monitored device unit sends heartbeat signals unidirectionally, the "heartbeat" interaction in this embodiment is a two-way challenge-response mode. Its working process is as follows: Challenge Phase: The central control unit (such as a central programmable logic controller system or industrial control computer) periodically (e.g., once per second) actively sends a "challenge" message to each monitored equipment unit (such as an engine test bench). This challenge message may contain dynamically changing data, such as a random number or an incrementing sequence number.

[0049] Response Phase: After receiving a "challenge" message from the central control unit, the local controller of the monitored device unit must complete two tasks within a very short preset response time (e.g., 200 milliseconds): First, perform a predefined, simple operation on the received challenge data, such as adding a specific constant to a random number or performing a bitwise XOR operation with a key; then, send the result of the operation back to the central control unit as a "response" message.

[0050] Verification Phase: After sending a "challenge" message, the central control unit starts a timer and waits for a "response" message. The central control unit not only checks whether a response has been received within the specified preset response time, but also verifies whether the calculation result carried in the response message is correct.

[0051] Understandably, under this mechanism, the determination of a "silent fault" in the first monitoring channel (corresponding to...) Figure 2 Step S111 will be based on one of the following two scenarios: Scenario 1: No response within timeout. If the central control unit does not receive a response message from a monitored device unit within a preset response time (e.g., 200 milliseconds), it is determined that the local controller of that unit has completely "crashed" or the communication link has been interrupted. Scenario 2: Incorrect response content. If the central control unit receives a response message, but the calculation result in the message does not match the expected result calculated locally by the central control unit according to the same rules, it is determined that although the local controller of that unit is still running, its program logic has malfunctioned or fallen into an unexpected state, i.e., it is in a "fake dead" state.

[0052] If either of the above two situations occurs, the central control unit will immediately determine that the monitored equipment unit has malfunctioned and execute the step of sending an emergency stop signal S112, sending an emergency stop control signal A2 to the unit to force it to stop safely.

[0053] The second monitoring channel, namely the monitoring of regular faults and the alarm linkage of the whole area, is implemented in the same way as the aforementioned embodiment. That is, by monitoring the second status signal (fault signal) actively reported by the monitored equipment unit, the audible and visual alarms of all working areas are triggered.

[0054] In summary, the "challenge-response" heartbeat mechanism proposed in this embodiment provides a higher level of security integrity verification. It can detect not only "hard crashes" caused by hardware damage or complete program collapse of the controller, but also, to a certain extent, "soft crashes" or "false crashes" caused by software defects, memory overflows, etc., resulting in program malfunctions, infinite loops, or situations where communication functions still exist. By verifying the correctness of the response content, it ensures that the local controller's program is still executing according to the expected logical path, thereby further improving the reliability and security of the entire security monitoring system.

[0055] Those skilled in the art will understand that, besides implementing the system and its various devices, modules, and units provided by this invention in the form of purely computer-readable program code, the same functions can be achieved entirely through logical programming of the method steps, making the system and its various devices, modules, and units of this invention function in the form of logic gates, switches, application-specific integrated circuits, programmable logic controllers, and embedded microcontrollers. Therefore, the system and its various devices, modules, and units provided by this invention can be considered as a hardware component, and the devices, modules, and units included therein for implementing various functions can also be considered as structures within the hardware component; alternatively, the devices, modules, and units for implementing various functions can be considered as both software modules implementing the method and structures within the hardware component.

[0056] Specific embodiments of the present invention have been described above. It should be understood that the present invention is not limited to the specific embodiments described above, and those skilled in the art can make various changes or modifications within the scope of the claims, which do not affect the essence of the present invention. Unless otherwise specified, the embodiments and features described in this application can be arbitrarily combined with each other.

Claims

1. A security monitoring and alarm linkage system, applied to scenarios comprising multiple physically dispersed work areas, characterized in that, include: At least one central control unit; Several monitored equipment units are distributed across the multiple work areas, and each monitored equipment unit has a local control system; Alarm devices installed in the multiple work areas; The central control unit monitors the plurality of monitored device units through a first monitoring channel and a second monitoring channel. The first monitoring channel is used to: receive and monitor the first status signal output by the local control system of each monitored device unit, which is used to characterize its own normal operating status; and send an emergency stop control signal to the monitored device unit when it is determined that the first status signal of any monitored device unit is interrupted or lost within a preset time period. The second monitoring channel is used to: receive a second status signal output by each monitored device unit, the second status signal being used to indicate that the monitored device unit has malfunctioned; and, upon receiving the second status signal of any monitored device unit, trigger the alarm device installed in all working areas.

2. The system according to claim 1, characterized in that, The central control unit is a programmable logic controller or an industrial control computer.

3. The system according to claim 1 or 2, characterized in that, The monitored equipment unit is an engine test bench.

4. The system according to claim 3, characterized in that, The first state signal is a periodic pulse signal.

5. The system according to claim 1, characterized in that, The alarm device is an audible and visual alarm, and the audible and visual alarm satisfies at least one of the following: The sound pressure level of the audible alarm is not less than 110 dB; The light alarm is a high-brightness lamp with multiple flashing modes.

6. The system according to any one of claims 1, 2, 4 or 5, characterized in that, The central control unit transmits signals to each monitored device unit via hardwire or industrial network.

7. A security monitoring and alarm linkage method, applied to a scenario of monitoring several monitored equipment units distributed across multiple physically dispersed work areas, characterized in that, Includes the following steps: Receive and monitor the first status signal output by the local control system of each monitored equipment unit, which is used to characterize its own normal operating status; When it is determined that the first status signal of any monitored device unit is interrupted or lost within a preset time period, an emergency stop control signal is sent to the monitored device unit. Receive a second status signal output by each monitored device unit, which indicates that the monitored device unit has failed; Upon receiving a second status signal from any monitored device unit, the alarm device installed in all work areas is triggered.

8. The method according to claim 7, characterized in that, Meet at least one of the following: The method is executed by a central control unit, which is a programmable logic controller or an industrial control computer. The monitored equipment unit is an engine test bench.

9. The method according to claim 7 or 8, characterized in that, The first state signal is a periodic pulse signal, and the monitoring step includes: detecting whether the periodic pulse signal stops flipping within a preset time period.

10. The method according to claim 7, characterized in that, Triggering an alarm device involves performing at least one of the following: Activate the audible alarm with a sound pressure level of not less than 110dB; Activate the high-brightness, multi-flicker mode light alarm.

Citation Information

Patent Citations

  • Unattended platform and method for large-scale production of inertial products

    CN117369376A

  • Ruggedized machine multi-machine system based on task monitoring and redundancy design method

    CN114355803A

  • Soft start cooperative control method and system for large industrial air conditioning unit

    CN120627311A

  • Ethernet communication monitoring system and domain controller

    CN221551100U

  • Motion control system and method, and control platform

    WO2025011616A1