Method and mobile hand control device for operating a machine

A dual-device system with separate communication networks for safety and non-safety functions addresses interference and flexibility issues, enabling reliable and fast safety signal transmission, enhancing user comfort and reducing device redundancy.

DE102017108316B4Active Publication Date: 2025-08-28NINGBO SCHLEICHER TECH GRP CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
DE102017108316
Authority / Receiving Office
DE · DE
Patent Type
Patents
Current Assignee / Owner
Filing Date
2017-04-19
Publication Date
2025-08-28
Estimated Expiration
2037-04-19

AI Technical Summary

Technical Problem

Existing mobile control devices in industrial automation face challenges with radio transmission interference, lack of flexibility, and inability to meet safety standards, particularly in ensuring reliable communication for safety functions like emergency stop buttons, and are not compatible with modern user expectations for comfort and functionality.

Method used

A dual-device system is employed, where a first device handles non-safety-related control and a second device handles safety-related control, connected via separate communication networks, with the second device using a wireless real-time transmission system to ensure reliable and secure exchange of safety signals.

Benefits of technology

This approach enhances safety and flexibility by allowing standard devices like tablets to be used for non-safety functions while ensuring reliable and fast transmission of safety signals, reducing the need for multiple devices and maintaining clear machine assignments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

Method of operating a machine, comprising the following steps: - Providing a first hand-held control device (2) for non-safety-related machine control (11); - Providing a second hand-held control device (3) for safety-related machine control (10), which is formed separately from the first hand-held control device (2); - forming a first data communication connection between the first handheld control device (2) and a non-safety-related control device (11) of a machine in a first data communication network; - forming a second data communication connection between the second handheld operating device (3) and a safety-related control device (10) of the machine, wherein the second data communication connection is formed separately from the first data communication connection in a second data communication network which is designed as a wireless real-time transmission system (6) of the broadcast type, separate from the first data communication network, and in which a unique device identifier is assigned to the second handheld operating device (3); - exchanging non-safety-related control signals between the first handheld control device (2) and the non-safety-related control device (11) and controlling the operation of the machine in accordance with the non-safety-related control signals, and - Exchanging safety-related control signals between the second handheld control device (3) and the safety-related control device (10).
Need to check novelty before this filing date? Find Prior Art

Description

[0001] The invention relates to a method and a mobile handheld control device for operating a machine. background

[0002] Mobile machine and system control devices are used in industrial automation. They assist the machine user in typical activities such as setting up a machine directly at the process. With many machines and systems, this requires the user to be close to the processing in order to be able to observe it better. For their own safety, they then carry mobile control devices such as emergency stop buttons or enabling buttons (often referred to as dead man's switches). In the event of danger, the user can then stop the machine and thus switch it to a safe state. The control devices are typically linked to a handheld control device on which machine messages are displayed, inputs can be made, and the machine can be operated.

[0003] Operating elements that serve functional safety must transmit their status data (button pressed / not pressed) using secure transmission technology to an evaluation unit, which then ensures that the machine or system enters the safe state (stop) when either the request (emergency stop) is triggered or when an error occurs, for example, if the status of the button cannot be clearly identified. Thus, all forms of communication errors immediately lead to a machine stop.

[0004] Industrial automation would love to take advantage of the benefits of wireless devices. Mobile devices are now used wirelessly in many areas of life. Cables are cumbersome, hinder work, are fragile, and must be replaced if damaged. Nevertheless, wireless data technology has not been able to establish itself in the use of handheld devices with safety functions.

[0005] The reason for this is the interference-prone nature of radio transmission. Naturally, radio telegrams, which are used by all common radio standards for data transmission, can be subject to interference during transmission; none of the radio standards can reliably prevent this. When used in the described type of mobile operating devices, such transmission interference is detected. As soon as the evaluation station has not received any valid data telegrams within a defined time frame, it will trigger a machine stop. The machine is therefore unavailable if interference occasionally prevents data transmission. However, this cannot be accepted by the operators of machines and systems. Ultimately, this is the reason why radio technology has not become established for the described application.

[0006] There is a trend in mobile operating devices towards standard devices of the digital world. Today, standard tablets and even smartphones are suitable for displays, user information, input, etc. The innovation cycles of these mobile devices are very short. While operating devices used to be optimized for a specific machine, in the future it can be assumed that the operating devices will be replaced several times over the service life of the machine and will have new functions that were not even available when the machine was commissioned. Users who naturally use high-tech devices in their free time expect the same level of convenience and innovation from operating devices. The membrane keyboards and small, low-resolution displays that are still common today no longer meet the expectations of young users. However, standard devices such as tablets cannot perform the task of safety functions (emergency stop buttons, etc.).

[0007] In typical configurations, mobile operator devices are permanently connected to a machine via a cable. If several machines of the same or similar design are present in a manufacturing facility, then just as many operator devices are present, each one permanently linked to a specific machine. Typical user tasks such as setup, troubleshooting, etc., are usually performed by a very small group of people (set-up operators). The operating time of the operator devices is therefore typically very short.

[0008] Roaming is often offered for mobile devices. Roaming allows a mobile device to move in an area with multiple access points. The mobile device automatically connects to the most convenient access point whenever it moves. Roaming is familiar from mobile networks (GSM), but is also supported in local networks (Wi-Fi). The user typically does not need to actively control this; the roaming process is completely automated and requires no user intervention. Roaming allows the logical connection established by the mobile device (e.g., a phone call) to continue uninterrupted when changing access points.

[0009] Roaming is also desirable when using handheld control devices, so that the most convenient access point is always used, even when the user moves. Nevertheless, it is very important that the safety function's assignment and effect are clear at all times. If there are multiple machines in a line, for example, the emergency stop function should affect precisely one of the machines, and this assignment must be clear to the user at all times. Therefore, a mechanism that allows a user to switch from one machine to another is desirable, allowing the safety function to change with it and displaying the current assignment to the user.

[0010] The sale and installation of machinery and equipment often requires compliance with safety rules and regulations. For example, according to the European Machinery Directive, machinery and equipment can only be placed on the European market with a CE mark. To be permitted to affix the CE mark, the person placing the machinery on the market (manufacturer or importer) must be able to demonstrate that the machinery does not pose unreasonable risks to users. To reduce the risk to an acceptable level, the machine can be equipped with safety devices.

[0011] A safety device could, for example, be a light barrier that detects a user entering a hazardous work area and transmits this information to a control unit, which then stops the hazardous movement. In this case, the control unit is also a safety device because it contributes to the safety function. Safety devices themselves must perform their function with a high degree of safety, meaning that a dangerous failure of safety devices must occur with only a very low probability.

[0012] Safety devices can exchange information with each other. In the example above, the signal from the light barrier is transmitted to the safety controller. The transmission of safety information is also part of the safety function and must meet the same high requirements, i.e., a dangerous transmission error must only occur with a very low probability. For all signals and information transmitted in a machine automation system, a clear decision must be made as to whether they are to be assigned to a safety function. Safety devices are developed, certified, and manufactured according to specific standards (e.g., IEC 61508). Devices such as commercially available tablet computers are therefore not part of a safety device.When it comes to control devices, a distinction is usually made between safety controllers (safety-related control devices), which specifically operate the safety functions of an automation solution, and functional controllers (non-safety-related control devices), which handle the other control tasks, for example sequence control, motor control, displays and / or data transmission in networks.

[0013] The safety-related part of a control system (also known as SRP / CS - "Safety-Related Parts of Control System") refers to parts of machine control systems that perform safety tasks. In other words, these are components that respond to safety-related input signals and generate safety-related output signals. It is the part of a control system that responds to safety-related input signals and generates safety-related output signals (see also DIN EN ISO 13849-1:2016-06; Safety of machinery - Safety-related parts of control systems - Part 1: General principles for design).A combination of safety-related or safety-directed parts of a control system starts at the point in the control system where safety-related / safety-directed signals are generated (including, for example, the actuator and roller of a position switch) and ends at the outputs of power control elements (including, for example, the main contacts of a contactor).

[0014] A broadcast-type wireless real-time transmission system is known from document DE 10 2012 206 529 A1. The term "broadcast-type," as used herein, indicates that nodes of the wireless real-time transmission system can receive tokens and / or user data from at least some of the other nodes of the wireless real-time transmission system. A method for the wireless real-time transmission system is described, in which the system comprises at least two nodes N1, N2. Each node N1, N2 has an associated transmitting device TX and a receiving device RX. The real-time transmission system has a logical bus structure, wherein a first node N1 is logically arranged upstream of a second node N2. Each of the at least two nodes N1, N2 maintains a channel quality matrix G1, G2, wherein the channel quality matrix G1, G2 comprises at least one connection quality to neighboring nodes N1, N2.A token T is sent from the first node N1 to the second node N2, wherein the token T contains information about at least parts of the channel quality matrix G1 of the first node N1. The token T from the first node N1 is received at the second node N2, wherein the second node N2 receives parts of the channel quality matrix G1 of the first node N1.

[0015] The receiving node determines a channel quality between the receiving node and the sending node. The channel quality matrix is ​​then revised using the received parts of the channel quality matrix G1 of the first node N1. Based on the revised channel quality matrix G'2 of the second node, the second node N2 determines whether a direct transmission of data or tokens to a third node N3, which is logically subsequent to the second node N2, is possible with a specified probability. If forwarding is possible with an unspecified probability, one or more relay nodes are determined.

[0016] US 2015 / 0128205 A1 discloses methods and systems for secure network connections. Summary

[0017] The object of the invention is to provide a method and a mobile hand-held control device for operating a machine, with which the safety and flexibility of machine operation are improved.

[0018] The object is achieved by a method and a mobile hand-held control device according to independent claims 1 and 11. Alternative embodiments are the subject of the dependent subclaims.

[0019] According to one aspect, a method for operating a machine is provided, comprising the following steps: providing a first handheld operating device for non-safety-related machine control; providing a second handheld operating device for safety-related machine control, which is formed separately from the first handheld operating device; forming a first data communication connection between the first handheld operating device and a non-safety-related control device of a machine in a first data communication network;Forming a second data communication connection between the second handheld operating device and a safety-related control device of the machine, wherein the second data communication connection is formed separately from the first data communication connection in a second data communication network, which is implemented as a wireless real-time broadcast transmission system separate from the first data communication network and in which a unique device identifier is assigned to the second handheld operating device; Exchanging non-safety-related control signals between the first handheld operating device and the non-safety-related control device, as well as controlling the operation of the machine according to the non-safety-related control signals, and exchanging safety-related control signals between the second handheld operating device and the safety-related control device.

[0020] According to a further aspect, a mobile handheld control device for operating a machine is provided. The mobile handheld control device comprises a first handheld control device for non-safety-related machine control and a second handheld control device for safety-related machine control, which is formed separately from the first handheld control device. The first and second handheld control devices are configured to perform the following steps: forming a first data communication connection between the first handheld control device and a non-safety-related control device of a machine in a first data communication network;Forming a second data communication connection between the second handheld operating device and a safety-related control device of the machine, wherein the second data communication connection is formed separately from the first data communication connection in a second data communication network, which is implemented as a wireless real-time broadcast transmission system separate from the first data communication network and in which a unique device identifier is assigned to the second handheld operating device; Exchanging non-safety-related control signals between the first handheld operating device and the non-safety-related control device, as well as controlling the operation of the machine according to the non-safety-related control signals, and exchanging safety-related control signals between the second handheld operating device and the safety-related control device.

[0021] The machine to be operated can be part of a system that includes several machines. Depending on the application, the mobile handheld control unit can connect to one or more of the machines in the system.

[0022] The first handheld control device and the second handheld control device can be provided in a mobile control device unit. Housings of the first and second handheld control devices can be connected to each other detachably or non-detachably. In one embodiment, the second handheld control device is removable from the first handheld control device, thus providing two mobile and detachable handheld control devices.

[0023] The first handheld control unit and / or the second handheld control unit can be removably accommodated in the mobile control unit.

[0024] Forming the second data communication connection may further comprise: registering the second handheld device in the wireless real-time transmission system when it is determined in the wireless real-time transmission system that the second handheld device is located within a local communication range assigned to the machine in the wireless real-time transmission system.

[0025] Registering the second handheld operating device may further comprise: transmitting registration information data from the safety-related control device to the non-safety-related control device, wherein the registration information data indicates a requested registration of the second handheld operating device in the wireless real-time transmission system; transmitting at least part of the registration information data from the non-safety-related control device to the first handheld operating device; outputting user information to the first handheld operating device regarding the requested registration of the second handheld operating device in the wireless real-time transmission system for forming; detecting a user input via a user interface on the machine; forming the second data communication connection upon detecting the user input;Capturing a user confirmation input via a user interface on the second handheld control device and providing the second data communication connection for exchanging the safety-related control signals between the second handheld control device and the safety-related control device upon capturing the user confirmation input. The user confirmation input can be captured on the second handheld control device via a confirmation button on the user interface.

[0026] The exchange of safety-related control signals can comprise a cyclic exchange of the safety-related control signals between the second handheld terminal and the safety-related control device. Cyclical exchange can, in particular, involve a periodic transmission of status data at a specified time interval. The status data is transmitted repeatedly. The repetitions occur after a specified period of time. The transmitting and receiving devices ensure that the time between repetitions does not exceed a specified maximum time. This ensures that the receiver always knows the current signal states, which are at most one time period out of date.

[0027] The first handheld control device, the second handheld control device and / or the machine can be used to indicate to the user via a respective output device by means of optical and / or acoustic output signals when the second data communication connection is established.

[0028] The second handheld control device can be deregistered from the wireless real-time transmission system if the wireless real-time transmission system determines that the second handheld control device is leaving the local communication range assigned to the machine. In this way, an automatic deregistration of the second handheld control device from the wireless real-time transmission system is realized. Deregistration can be followed by a registration process in which the second handheld control device registers itself in the wireless real-time transmission system with another machine that is integrated into the wireless real-time transmission system in a similar way to the machine. The registration and / or deregistration from the other machine can be carried out in a similar manner to that explained in connection with the registration and deregistration of the second handheld control device from the machine.In this way, a method can be carried out in which the second hand-held control device in a machine park with several machines connects to one of the several machines for data communication depending on the situation.

[0029] The second handheld terminal can be deregistered from the wireless real-time transmission system if a user abort input is detected via the user interface on the second handheld terminal and / or the user interface on the machine. In this embodiment, the deregistration of the second handheld terminal in the wireless real-time transmission system can occur while the second handheld terminal is still within the local communication range of the machine.

[0030] After the second handheld control device has been logged off, the processing of safety-related control signals received in the safety-related control device from the second handheld control device can be blocked by the safety-related control device in the machine.

[0031] In conjunction with the mobile hand control device, the explanations for alternative designs apply accordingly. Description of implementation examples

[0032] The following examples of embodiments are explained in more detail with reference to the figures of a drawing. Herein: Fig. 1 a schematic representation of a mobile hand-held control device with a first and a second hand-held control device, wherein the two hand-held control devices are connected to one another; Fig. 2 a schematic block diagram with the mobile hand control device and Fig. 3 a schematic representation to explain a method for operating a machine with the mobile hand control device.

[0033] Safety information, such as the emergency stop button being pressed / not pressed, is typically transmitted via simple electrical signal lines. High transmission reliability is achieved through redundancy (dual-channel design) and, if necessary, test pulses. When transmitting multiple signals (emergency stop, operating mode selector, etc.), a large number of electrical lines are quickly required. Installation costs and the risk of errors are then high. This can be countered by the use of secure communication. Data is captured at the point of origin (sensor, button, switch) by electronic circuits with microcontrollers, translated into secure communication protocols, and transmitted via networks to an evaluating unit. Such protocols have proven themselves and are established and standardized in safety technology. Examples include "PRO-Flsafe" (IEC 61784-3-3) and "CIP Safety" (IEC 61784-3-2).What these protocols have in common is that while the requirements for the transmission medium define the required transmission quality and time, they do not dictate the physical properties of the medium. For example, a signal transmitted using the PROFIsafe protocol can be transmitted via Ethernet, a two-wire cable (RS485), or even a radio signal. As long as the requirements for error rate and transmission time are met, a high level of security is guaranteed. This is also referred to as the black channel; the evaluating unit does not check the type of transmission, but only the result.

[0034] Timing requirements depend on the application. In mechanical engineering, for example, monitoring times of 20 ms are common. A signal must be transmitted correctly within this time. A change in the signal state (e.g., key not pressed -> key pressed) can then be detected by the evaluating device after this time delay.

[0035] A solution for wireless mobile operation of machines is described here. Fig. Figure 1 shows a mobile handheld control device 1 with a first handheld control unit 2 and a second handheld control unit 3, wherein the two handheld control units 2, 3 are connected to each other. The second handheld control unit 3 is a standalone device, which in the embodiment shown is arranged, for example, on the back of the first handheld control unit 2, which can be a standard tablet computer, for example. The second handheld control unit 3 is not electrically connected to the first handheld control unit 2. It is battery-powered, has control elements such as an emergency stop button 4 and / or an approval or confirmation button 5, and has its own radio connection to an evaluation unit.

[0036] Fig. Figure 2 shows a schematic block diagram of the mobile handheld control device 1. A wireless real-time transmission system 6 of the broadcast type is provided, which is schematically shown in Figure 1 by means of a circle 7. An embodiment of the wireless real-time transmission system 6 as such is described in document DE 10 2012 206 529 A1. Using this technology, data can be transmitted very reliably from the second handheld control device 3 to the evaluation unit within a defined short transmission time.

[0037] The states of the control elements in the device are reliably recorded with a sufficiently high safety integrity level, in accordance with functional safety. The signals are then embedded, using suitable microprocessor circuitry and software, into a data transmission protocol suitable for safety-related data transmission. This could be, for example, the standardized PROFIsafe protocol.

[0038] The data is transmitted to a receiving station using the technology described in patent DE 10 2012 206 529 A1 (wireless real-time transmission system of the broadcast type - "EchoRing"). This enables the data from the second handheld terminal 3 to be transmitted very reliably to the receiving unit within a defined short transmission time. The transmitting unit and receiving unit are designed as nodes in the wireless real-time transmission system. Both convert the serial data telegrams of the transmission protocol into message telegrams of the wireless real-time transmission system, and vice versa. The receiving unit, in turn, is connected via Ethernet to a safety evaluation unit, for example, a safety controller. Additional nodes in the wireless real-time transmission system support the transmission quality.

[0039] The wireless real-time transmission system of the broadcast type is suitable for meeting the safety requirements required in mechanical and plant engineering. In typical applications in industrial environments, the wireless real-time transmission system can achieve transmission times of less than 10 ms to 20 ms with very high transmission quality (telegram losses < 10 -6 ). This ensures the fast response times of the safety devices required in the machine application, even with a high level of safety integrity.

[0040] The structure of the arrangement is Fig. 2. The second handheld terminal 3 is spatially connected to the first handheld terminal 2, but does not exchange data directly with it. The second handheld terminal 3 is connected to a receiving unit 8a of the wireless real-time transmission system 6. The wireless real-time transmission system 6 is supported by a relay node 9. The receiving unit 8a is connected via a wired connection, for example, an Ethernet-based PROFInet connection, to a safety-related control device 10, which evaluates the safety signals from the second handheld terminal 3.

[0041] In the embodiment shown, the first handheld terminal 2 is also connected to a receiving station or unit 8b via a standard WLAN connection. This can be a standard WLAN router. This is connected to the controller via standard Ethernet (TCP / IP), but to a non-safety-related control device 11, which is a non-safety-related functional part of the machine controller. Various protocols and services are available for this type of connection. For example, an application can be installed in the first handheld terminal 2 that can access data from the machine controller, in particular from the non-safety-related control device 10, via web services and protocols such as OPC.

[0042] The safety-related control device 10 and the non-safety-related control device 11 are part of a control system of the machine or form the final part of this.

[0043] This type of separation of safety-related and non-safety-related data from the safety-related control device 10 and the non-safety-related control device 11 into two different devices, namely the first and second handheld control devices 2, 3, makes it possible to use standard devices such as tablets, with all their advantages in terms of user comfort, for the first handheld control device 2. The required safety application is independent of this, and even a malfunction in the operation of the first handheld control device 2 cannot affect the safety application, which is controlled by the second handheld control device 3.

[0044] A particular advantage of using this technology arises when the second handheld control device 3 is not rigidly coupled to a machine. The approach described here can significantly reduce the number of required second devices. Each employee can carry a second handheld control device 3 and, as needed, connect it to a machine on which work is to be performed. It is important that the connection of the second handheld control device 3 to exactly one machine is always unambiguous and clear to the user at all times. For this purpose, a login and logoff process is explained below as an example.

[0045] The process of coupling and separation is in Fig. 3 shown schematically.

[0046] The broadcast-type wireless real-time transmission system 6 is always active in the machine structure and transmits regularly (step 20). Even in the absence of payload data, the wireless real-time transmission system 6 can remain active, meaning that the participants in the wireless real-time transmission system 6 continue to exchange management data, for example, performing token passing and determining the transmission quality between all participants. Only when the number of participants in the wireless real-time transmission system 6 falls below two does the ring and communication cease. For proper operation and to achieve high transmission quality, at least three participants are required in the wireless real-time transmission system 6.

[0047] The second handheld device 3 has a unique identifier for the wireless real-time transmission system 6. As soon as the user approaches a machine with the second handheld device 3, the second handheld device 3 automatically contacts the wireless real-time transmission system 6 in step 21 and is integrated into the wireless real-time transmission system 6 on the machine (step 22). The machine can be one machine in a group of machines (machine park).

[0048] The second handheld terminal 3 can immediately function as a relay station or node in the wireless real-time transmission system 6 and is integrated into a token ring of the wireless real-time transmission system 6. The information is forwarded to the non-safety-related control device 11 (step 23). The non-safety-related control device 11 initiates an information output to the user, for example, via a display of the first handheld terminal 2 (step 24).

[0049] The user must now approach the machine for connection and operate a control device (button, key switch, or similar) directly on the machine (step 25). The safety-related control device 10 will then attempt to establish a secure connection to the selected second handheld control device 3 in step 26 within the wireless real-time transmission system 6. The user on the second handheld control device 3 confirms the connection by pressing and releasing a button 12 in step 27. From then on, the safety-related control device 10 (step 28) and the second handheld control device 3 (step 100) begin a cyclical exchange of safety signals. The safety device for the machine is now active and can be used, in particular for transmitting safety signals within the wireless real-time transmission system 6.

[0050] The second hand-held control unit 3 has, according to Fig.1 an emergency button 13. This can be designed according to DIN EN61850.

[0051] This process is secure and prevents a handheld terminal from connecting to the wrong machine. A display on the connected machine (indicator light or similar) can additionally visualize the connected status between the second handheld terminal 3 and the safety-related control device 10. The user is then always aware that their second terminal 3 is connected to the machine.

[0052] The logoff process is similar, but simpler. By activating a control device on the machine, for example, removing the key from the key switch, or simply logging off via a menu on the display, the connection can be disconnected to separate the second handheld control unit 3 from the wireless real-time transmission system 6. The safety-related control device 10 ensures that the safety signals of the second handheld control unit 3 are no longer evaluated after this time and that this status is properly displayed.

[0053] After logging out, the user can log in again using the second handheld control unit 3, for example on another machine.

[0054] At any given time, the second handheld control device 3 can connect to a maximum of one safety-related control device 10. It is therefore either not connected or securely connected to exactly one safety-related control device 10.

[0055] In an alternative arrangement, several combinations of handheld control devices, for example by several employees, each carrying a combination with a safety-related handheld control device, can be connected to or disconnected from one or more safety controllers (i.e. machines).

[0056] The features disclosed in the above description, the claims and the drawings may be important for the realization of the various embodiments both individually and in any combination.

Claims

[1] Method of operating a machine, comprising the following steps: - Providing a first hand-held control device (2) for non-safety-related machine control (11); - Providing a second hand-held control device (3) for safety-related machine control (10), which is formed separately from the first hand-held control device (2); - forming a first data communication connection between the first handheld control device (2) and a non-safety-related control device (11) of a machine in a first data communication network; - forming a second data communication connection between the second handheld operating device (3) and a safety-related control device (10) of the machine, wherein the second data communication connection is formed separately from the first data communication connection in a second data communication network which is designed as a wireless real-time transmission system (6) of the broadcast type, separate from the first data communication network, and in which a unique device identifier is assigned to the second handheld operating device (3); - exchanging non-safety-related control signals between the first handheld control device (2) and the non-safety-related control device (11) and controlling the operation of the machine in accordance with the non-safety-related control signals, and - Exchanging safety-related control signals between the second handheld control device (3) and the safety-related control device (10). [2] Method according to claim 1, characterized by that the first handheld control device (2) and the second handheld control device (3) are provided in a mobile control device unit. [3] Method according to claim 2, characterized by that the first hand-held control device (2) and / or the second hand-held control device (3) are releasably received in the mobile control device unit. [4] Method according to at least one of the preceding claims, characterized byin that the formation of the second data communication connection further comprises the following: registering the second handheld control device (3) in the wireless real-time transmission system (6) when it is determined in the wireless real-time transmission system (6) that the second handheld control device (3) is arranged within a local communication area (7) which is assigned to the machine in the wireless real-time transmission system (6). [5] Method according to claim 4, characterized by that logging on the second handheld control unit still includes the following: - transmitting login information data from the safety-related control device (10) to the non-safety-related control device (11), wherein the login information data indicates a requested login of the second handheld control device (3) in the wireless real-time transmission system (6); - transmitting at least part of the registration information data from the non-safety-related control device (11) to the first handheld control device (2); - Outputting user information to the first handheld control device (2) relating to the requested registration of the second handheld control device (3) in the wireless real-time transmission system (6) for training; - Capturing user input via a user interface on the machine; - forming the second data communication connection to detect the user input; - capturing a user confirmation input via a user interface on the second handheld control unit (3) and - Providing the second data communication connection for exchanging the safety-related control signals between the second handheld control device (3) and the safety-related control device upon detection of the user confirmation input. [6] Method according to at least one of the preceding claims, characterized by that the exchange of the safety-related control signals comprises a cyclical exchange of the safety-related control signals between the second hand-held control device (3) and the safety-related control device (10). [7] Method according to at least one of the preceding claims, characterized by that the user is informed on the first handheld control device (2), the second handheld control device (3) and / or the machine via a respective output device by means of optical and / or acoustic output signals when the second data communication connection is formed. [8] Method according to at least one of the preceding claims, characterized bythat the second hand-held control device (3) is deregistered in the wireless real-time transmission system (6) when it is determined in the wireless real-time transmission system (6) that the second hand-held control device (3) leaves the local communication area (7) assigned to the machine. [9] Method according to at least one of the preceding claims, characterized by that the second handheld control device (3) is logged out of the wireless real-time transmission system (6) when a user cancellation input is detected via the user interface on the second handheld control device (3) and / or the user interface on the machine. [10] Method according to claim 8 or 9, characterized bythat after the second hand-held control device (3) has been logged off, the processing of safety-related control signals received in the safety-related control device (10) from the second hand-held control device (3) is blocked by the safety-related control device (10) in the machine. [11] Mobile hand-held control device for operating a machine, comprising a first hand-held control device (2) for non-safety-related machine control (11) and a second hand-held control device (3) for safety-related machine control (10), which is formed separately from the first hand-held control device (2), wherein the first and the second hand-held control device (2, 3) are configured to carry out the following steps: - forming a first data communication connection between the first handheld control device (2) and a non-safety-related control device (11) of a machine in a first data communication network; - forming a second data communication connection between the second handheld operating device (3) and a safety-related control device (10) of the machine, wherein the second data communication connection is formed separately from the first data communication connection in a second data communication network which is designed as a wireless real-time transmission system (6) of the broadcast type, separate from the first data communication network, and in which a unique device identifier is assigned to the second handheld operating device (3); - exchanging non-safety-related control signals between the first handheld control device (2) and the non-safety-related control device (11) and controlling the operation of the machine in accordance with the non-safety-related control signals, and - Exchanging safety-related control signals between the second handheld control device (3) and the safety-related control device (10).

Citation Information

Patent Citations

  • Methods and systems for secure network connections

    US20150128205A1