Methods for detecting communication disorders in a master-slave system

By defining a limit value for data reception and synchronizing safety buses with control communication, the method and control unit improve fault response times and error detection in master-slave systems, enhancing robustness and availability.

DE102021204679B4Active Publication Date: 2025-12-04ROBERT BOSCH GMBH
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
DE102021204679
Authority / Receiving Office
DE · DE
Patent Type
Patents
Current Assignee / Owner
Filing Date
2021-05-10
Publication Date
2025-12-04
Estimated Expiration
2041-05-10

AI Technical Summary

Technical Problem

In master-slave systems, safety buses communicate asynchronously, leading to undefined fault response times and the need for extended safety margins, which can be improved by detecting communication disturbances on the safety bus.

Method used

A method and control unit for detecting communication disturbances on a safety bus by defining a limit value for data reception time, checking for data receipt during safety cycles, and initiating safety-related actions if the limit is exceeded, with synchronization to control communication for precise value transmission.

Benefits of technology

This approach enhances the robustness and availability of the safety bus by quickly and easily detecting communication errors, minimizing error response times and ensuring precise safety-related reactions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000012_0000
    Figure 00000012_0000
  • Figure 00000013_0000
    Figure 00000013_0000
  • Figure 00000014_0000
    Figure 00000014_0000
Patent Text Reader

Abstract

Method for detecting communication disturbances in a master-slave system (20), wherein the master-slave system (20) comprises a master unit (21) and at least one slave unit (22, 23, 24), wherein the at least one slave unit (22, 23, 24) is connected to the master unit (21) via a communication system (25), wherein the communication system (25) has a safety bus (26), and wherein the at least one slave unit (22, 23, 24) has a safety module (27), wherein the master unit (21) communicates with the at least one slave unit (22, 23, 24) via the safety bus (26) in safety cycles, wherein during a safety cycle the master unit (21) transmits data to be processed by the safety module (27) of the at least one slave unit (22, 23, 24) to the at least one slave unit (22, 23, 24), and wherein the method (1,10) has the following steps: - Defining a limit value for a time during which each slave unit (22,23,24) cannot receive any data to be processed by the safety module (27) of the slave unit (22,23,24) without an error message being issued (2,11); and for each slave unit (22, 23, 24), check whether the slave unit (22, 23, 24) has received data to be processed by the security module (27) of the slave unit (22, 23, 24) from the master unit (21) during the safety cycle (3, 12), wherein, if the slave unit (22, 23, 24) has not received any data to be processed by the security module (27) of the slave unit (22, 23, 24) from the master unit (21) during the safety cycle, a period is determined which indicates how long the slave unit (22, 23, 24) has not received any data to be processed by the security module (27) of the slave unit (22, 23, 24) from the master unit (21) (4, 13), wherein the period is compared with the limit value (5,14), and wherein, if the period is greater than the limit value, it is determined that a communication fault has occurred (6, 15), wherein the procedure (10) further comprises the following step: synchronizing the safety bus (26) to a master communication (17); and wherein a last slave unit (22, 23, 24) in a communication ring has master functionality, and wherein the step (17) of synchronizing the safety bus (26) to the master communication comprises the following step: specifying a start time for a new safety cycle by the last slave unit (22, 23, 24) based on the master communication.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] The invention relates to a method for detecting communication disturbances in a master-slave system and in particular a method for detecting communication disturbances on a safety bus in a master-slave system.

[0002] Systems are known in which a control unit or master unit communicates with one or more sensors, actuators or drives, so-called slave units, via a communication system, in particular a bus system.

[0003] In such master-slave systems, safety functions, such as those designed to protect people, are increasingly being implemented. Each slave unit has its own safety modules or control units configured to execute corresponding safety-related functions or applications. Data processed by these modules or control units is communicated via one or more safety buses, which are separate from a general control communication system used to transmit data for controlling the slave units. A distinction is generally made between safety monitoring and control communication.During safety monitoring, a "safety function" can be activated, which could be, for example, a "reduced speed" function. This safety function can also activate a safety parameter such as "maximum permissible axle speed / engine speed".

[0004] The control communication system, in turn, constantly checks the activated safety functions of the drives or slave units and adjusts the target specifications, such as target speed, to the limit values ​​of the activated safety function.

[0005] However, since in this case the synchronization of the individual communication participants or the master unit and the slave units is managed by the non-secure command communication, the one or more separately trained safety buses cannot use the corresponding synchronization mechanism of the command communication.

[0006] However, this means that one or more safety buses must communicate asynchronously, resulting in undefined fault response times. To prevent such errors, a safety margin must usually be factored in, and the guaranteed fault response time must be extended accordingly.

[0007] From the publication DE 10 2009 042 354 A1, a method for safety-related communication in the communication network of an automation system is known, wherein safety functions of a system are divided into small, manageable, locally limitable and easily verifiable module groups in order to simplify the installation and design of safety-related modules in the communication network.

[0008] DE 10 2018 101 103 A1 describes a system with communication components that communicate via a data bus based on events. A monitoring instance regularly checks the functionality of the components. Furthermore, cyclical communication takes place with other monitoring instances, possibly via the same data bus. Error indications can be sent and recordings can be made.

[0009] DE 196 43 092 A1 relates to a serial bus system with a central and an active bus participant that send status messages to the bus. The bus lines are physically looped to detect interruptions. An error message is displayed if a status message is faulty or missing. Transmission occurs cyclically, and the central bus participant controls the communication.

[0010] DE 102 11 284 A1 discloses a bus system consisting of at least two data buses, wherein the first data bus has a first number of participants and the second data bus has a second number of participants, wherein at least two TTCAN buses are used as data buses, which are connected to each other by participants simultaneously connected to both TTCAN buses in such a way that fewer participants than the sum of the number of participants of the first TTCAN bus and the number of participants of the second TTCAN bus are simultaneously connected to both TTCAN buses, wherein means are included by which a scalable fault tolerance in the bus system is generated depending on the number of participants simultaneously connected to the at least two TTCAN buses. The invention is therefore based on the objective of providing a method for detecting communication disturbances on a safety bus in a master-slave system, with which fault response times can be improved accordingly.

[0011] The problem is solved by a method for detecting communication disturbances in a master-slave system with the features of claim 1.

[0012] Furthermore, the problem is solved by a control unit for detecting communication disturbances in a master-slave system with the features of claim 5.

[0013] The problem is further solved by a master-slave system with the features of claim 8. Disclosure of the invention

[0014] According to one embodiment of the invention, a method for detecting communication disturbances in a master-slave system is provided, wherein the master-slave system comprises a master unit and at least one slave unit, wherein the at least one slave unit is connected to the master unit via a communication system, wherein the communication system has a security bus, and wherein the at least one slave unit has a security module, wherein the master unit communicates with the at least one slave unit via the security bus in security cycles, wherein during a security cycle the master unit transmits data to be processed by the security module of the at least one slave unit to the at least one slave unit.

[0015] The method involves defining a limit value for a time period during which each slave unit cannot receive any data to be processed by its security module without an error message being issued. For each slave unit, it is checked whether it has received any data to be processed by its security module from the master unit during a safety cycle. If the slave unit has not received any data to be processed by its security module from the master unit during the safety cycle, a period is determined indicating how long the slave unit has not received any data to be processed by its security module from the master unit. This period is compared to the limit value, and if the period is greater than the limit value, it is determined that a communication fault has occurred.

[0016] In this context, the term safety cycle refers in particular to a time window during which the master unit communicates with at least one slave unit via the safety bus, or communicates the data to be processed by the safety module of the respective slave unit to at least one slave unit or places it on the safety bus.

[0017] The data to be processed by the security module of the respective slave unit can be transmitted in particular in the form of data telegrams, wherein such a data telegram has data spaces, and wherein each data space is intended for specific data information.

[0018] This method allows for m transmission or telegram failures, thereby increasing the robustness and availability of the safety bus. Furthermore, corresponding communication errors can be detected quickly and easily, minimizing the error response time and the time until a safety-related response is initiated.

[0019] Overall, a method for detecting communication faults in a master-slave system is thus specified, which combines maximum tolerance with the shortest possible response time, and thus a method for detecting communication faults on a safety bus in a master-slave system, in which fault response times can be improved accordingly.

[0020] If it is determined that a communication disruption exists, a security-related action can be initiated.

[0021] A safety-related action is understood to be an action initiated to react appropriately and prevent complications arising from a communication error in the master-slave system, particularly communication disruptions on the safety bus, or to react to the communication error itself. This safety-related action could, for example, involve issuing a corresponding error message. Furthermore, a safety-related action could also include, for example, completely shutting down the master-slave system.

[0022] Furthermore, the step of defining a limit value can include defining the limit value such that it corresponds to an integer multiple of the safety cycle. This ensures that the corresponding monitoring is only triggered after a safety cycle has elapsed, thus easily taking into account, in particular, beat frequency effects.

[0023] The master unit and the at least one slave unit can also be connected to each other in such a way that a closed communication ring is formed, i.e., the master unit and the at least one slave unit are connected in a ring configuration.

[0024] Furthermore, a large number of slave units can be provided, and a summary frame telegram from the master unit can contain data for a large number of slave units. This means that a data telegram sent to the safety bus can be received sequentially by several, or preferably every, slave unit connected to the safety bus. A slave unit can extract the data packet segments or input data assigned to it in the data telegram and insert its output data as data packet segments into the data telegram. Each slave unit forwards the modified data telegram to the next slave unit, with all slave units typically proceeding in the same way.The last slave unit can send the data telegram back to the master unit if a closed communication ring exists, or to the previous slave unit in a branched (i.e., non-ring) bus architecture. Furthermore, a separate telegram can be generated and sent for each information transmission. Each slave unit is assigned a period within a corresponding cycle during which no other participant may transmit. At the beginning of this period, each slave unit sends its response telegram, which can be forwarded to the subsequent slave units and the master unit.

[0025] In one embodiment, the master unit and the at least one slave unit each use the same frequency for their safety applications, thereby achieving semi-synchronous operation, especially since the data transmission via the safety bus is synchronous with the safety application of the master unit.

[0026] Security applications are defined as security-relevant functions stored or running in the respective security module.

[0027] Furthermore, the procedure also involves synchronizing the safety bus with a management communication.

[0028] In this context, "control communication" refers to the communication of data between the master unit and the at least one slave unit that is necessary for the execution of the control functionalities of the at least one slave unit.

[0029] Synchronizing the safety bus with the control communication system offers the advantage that both actual and corresponding target values, as well as actual and target values ​​contained in response telegrams from the slave units, can be transmitted within constant time windows. This eliminates the need for additional timestamps to compare actual and target values. Since the actual and target values ​​are aligned accordingly, fault response times can be further reduced, and the calculation of values ​​derived from them can be simplified. Furthermore, for monitoring applications such as kinematic monitoring, a constant time interval between the acquisition of each measurement and its evaluation is advantageous, as it allows for a more precise definition of the threshold for triggering the monitoring system.

[0030] In this context, a last slave unit in a corresponding closed communication ring can have a master functionality, whereby a start time for a new security cycle is specified by the last slave unit based on the leading communication.

[0031] The term "last slave unit" refers, for example, to the slave unit in the closed communication ring that sends the data telegram back to the master unit if a summary frame telegram of the master unit contains data for a large number of slave units, including the last slave unit.

[0032] Especially when a closed communication ring exists, all slave units are connected to the same master communication, so that even the last slave unit knows the cycle of the master communication and synchronization can be implemented in a simple way, even though the safety module of the master unit or a safety controller of the master unit does not know the cycle of the master communication, or is shielded from the master communication.

[0033] In a further embodiment of the invention, a control unit for detecting communication disturbances in a master-slave system is also provided, wherein the master-slave system comprises a master unit and at least one slave unit, wherein the at least one slave unit is connected to the master unit via a communication system, wherein the communication system has a safety bus, and wherein the at least one slave unit has a safety module, wherein the master unit communicates with the at least one slave unit via the safety bus in safety cycles, wherein during a safety cycle the master unit transmits data to be processed by the safety module of the at least one slave unit to the at least one slave unit.

[0034] The control unit comprises a first unit configured to define a limit value for a period of time during which each slave unit cannot receive any data to be processed by the slave unit's safety module without an error message being issued, and the control unit further comprises a detection unit for each slave unit, each detection unit being configured to check whether the corresponding slave unit has received data to be processed by the slave unit's safety module from the master unit during a safety cycle, and each detection unit being further configured to determine a period of time if the corresponding slave unit has not received any data to be processed by the slave unit's safety module from the master unit during the safety cycle.which indicates how long the slave unit has not received any data from the master unit that is to be processed by the security module of the slave unit, wherein each detection unit is further trained to compare the period with the limit value, and wherein each detection unit is further trained to determine that a communication fault exists if the period is greater than the limit value.

[0035] The control unit is designed to allow for m transmission or telegram failures, thereby increasing the robustness and availability of the safety bus. Furthermore, corresponding communication errors can be detected quickly and easily, minimizing the error response time and the time until a safety-related reaction is initiated. Overall, this provides a control unit for detecting communication faults in a master-slave system, designed to combine maximum tolerance with the shortest possible response time. This control unit effectively improves error response times on a safety bus within a master-slave system.

[0036] The control unit can further include a safety unit for each slave unit, which is configured to initiate a safety-related action if the corresponding detection unit determines that a communication fault has occurred. A safety-related action is understood to be an action initiated to react appropriately and prevent complications arising from a communication error in the master-slave system, particularly communication faults on the safety bus, or to react to the communication error itself. This safety-related action could, for example, involve issuing a corresponding error message. Furthermore, the safety-related action could also include, for example, a complete shutdown of the master-slave system.

[0037] Furthermore, the first unit can be configured to define the limit value such that it corresponds to an integer multiple of the safety cycle. This ensures that the corresponding monitoring is only triggered after a safety cycle has elapsed, thus easily taking into account, in particular, beat frequency effects.

[0038] Another embodiment of the invention also provides a master-slave system which includes a control unit as described above.

[0039] In particular, a master-slave system is specified, comprising a master unit and at least one slave unit, wherein the at least one slave unit is connected to the master unit via a communication system, the communication system comprising a safety bus, and wherein the at least one slave unit comprises a safety module, wherein the master unit communicates with the at least one slave unit via the safety bus in safety cycles, and wherein, during a safety cycle, the master unit transmits data to be processed by the safety module of the at least one slave unit to the at least one slave unit. The master-slave system also includes a control unit as described above.

[0040] The master-slave system thus features a control unit designed to allow for m transmission or telegram failures, thereby increasing the robustness and availability of the safety bus. Furthermore, corresponding communication errors can be detected quickly and easily, minimizing the error response time and the time until a safety-related reaction is initiated. Overall, this describes a master-slave system with a control unit for detecting communication faults. This control unit is designed to combine maximum tolerance with the shortest possible response time and to detect communication faults on the safety bus in such a way as to improve error response times.

[0041] In this system, at least one slave unit can be connected to the master unit via the communication system in such a way that a closed communication ring is formed. Such closed communication rings have the advantage that, for example, breaks in the communication ring can be automatically located and repaired. Furthermore, each slave unit can be easily addressed based on its position within the communication ring.

[0042] Furthermore, the master-slave system can have multiple slave units, with a summary frame telegram of the master unit containing data for a multitude of slave units.

[0043] In one embodiment, the master unit and the at least one slave unit are configured to each use the same frequency for their safety applications, thereby achieving semi-synchronous operation, especially since the data transmission via the safety bus is synchronous with the safety application of the master unit.

[0044] In another embodiment, the control unit further comprises a synchronization unit configured to synchronize the safety bus with a command communication. Synchronizing the safety bus with the command communication has the advantage that both actual and corresponding setpoint values, or actual and setpoint values ​​contained in response telegrams from the slave units, can be transmitted within constant time windows, thus eliminating the need for additional timestamps to compare the actual and setpoint values. Since the actual and setpoint values ​​are aligned accordingly, corresponding fault response times can be further reduced, and the calculation of quantities derived from the actual and setpoint values ​​can be further simplified.Furthermore, in the case of appropriate monitoring, for example kinematic monitoring, it is advantageous if a constant time elapses between the acquisition of the individual measured quantity and the evaluation of the measured quantities, especially since this allows a limit value for the response of such monitoring to be defined more precisely.

[0045] In this scenario, a final slave unit in the communication ring can have master functionality, with the synchronization unit configured such that the start time for a new security cycle is determined by the final slave unit based on the master communication. Particularly in a closed communication ring, all slave units are connected to the same master communication, meaning that even the final slave unit is aware of the master communication cycle and synchronization can be easily implemented, even though the master unit's security module or security applications are not aware of the master communication cycle.

[0046] In summary, the present invention provides a method for detecting communication disturbances on a safety bus in a master-slave system, which can improve error response times accordingly.

[0047] The procedure can be designed in such a way as to combine maximum tolerance with the shortest possible response time, thus improving error response times accordingly.

[0048] Furthermore, the safety bus can be synchronized with the management communication, so that both actual and corresponding target values, or data to be processed by safety applications, can be transmitted in constant time windows, so that no additional timestamps need to be transmitted to compare the actual and target values.

[0049] The described configurations and training programs can be combined in any way desired.

[0050] Further possible embodiments, developments and implementations of the invention also include combinations of features of the invention described previously or subsequently with regard to the exemplary embodiments that are not explicitly mentioned. Brief description of the drawings

[0051] The accompanying drawings are intended to provide a further understanding of the embodiments of the invention. They illustrate embodiments and, in conjunction with the description, serve to explain the principles and concepts of the invention.

[0052] Other embodiments and many of the aforementioned advantages become apparent with reference to the drawings. The elements depicted in the drawings are not necessarily shown to scale.

[0053] They show: Fig. Figure 1 shows a flowchart of a method for detecting communication disturbances in a master-slave system according to a first embodiment of the invention; Fig. Figure 2 shows a flowchart of a method for detecting communication disturbances in a master-slave system according to a second embodiment of the invention; Fig. Figure 3 shows a block diagram of a master-slave system according to embodiments of the invention.

[0054] In the figures of the drawings, identical reference symbols denote identical or functionally equivalent elements, parts or components, unless otherwise stated.

[0055] Fig. Figure 1 shows a flowchart of a method 1 for detecting communication disturbances in a master-slave system according to a first embodiment of the invention.

[0056] Systems are known in which a control unit or master unit communicates with one or more sensors, actuators or drives, so-called slave units, via a communication system, in particular a bus system.

[0057] In such master-slave systems, safety functions, such as those designed to protect people, are increasingly being implemented. Each slave unit has its own safety modules or control units configured to execute corresponding safety-related functions or applications. Data processed by these modules or control units is communicated via one or more safety buses, which are separate from the main communication system used to generally control the slave units. A safety-related function might, for example, involve reducing the speed of a drive or the respective slave unit in response to certain conditions.

[0058] However, since in this case the synchronization of the individual communication participants or the master unit and the slave units is managed by the non-secure command communication, the one or more separately trained safety buses cannot use the corresponding synchronization mechanism of the command communication.

[0059] However, this means that one or more safety buses must communicate asynchronously, resulting in undefined fault response times. To prevent such errors, a safety margin must usually be factored in, and the guaranteed fault response time must be extended accordingly.

[0060] According to the invention, the master-slave system comprises in particular a master unit and at least one slave unit, wherein the at least one slave unit is connected to the master unit via a communication system, wherein the communication system has a security bus, and wherein the at least one slave unit has a security module, wherein the master unit communicates with the at least one slave unit via the security bus in security cycles, wherein during a security cycle the master unit transmits data to be processed by the security module of the at least one slave unit to the at least one slave unit.

[0061] The master-slave system is thus designed to enable corresponding data exchange on the safety bus. A fixed cycle time is defined for data exchange on the safety bus, or corresponding safety cycles are specified, whereby the safety bus usually operates synchronously with a safety application of the master unit, the safety controller. However, the safety application of the at least one slave unit is not synchronized to the safety bus.

[0062] How Fig. Figure 1 shows that the method according to the first embodiment includes a step 2 of defining a limit value for a time during which each slave unit cannot receive any data to be processed by the security module of the slave unit without an error message being issued, wherein in a subsequent step 3, it is checked for each slave unit whether the slave unit has received data to be processed by the security module of the slave unit from the master unit during a safety cycle, wherein, if the slave unit has not received any data to be processed by the security module of the slave unit from the master unit during the safety cycle, in a subsequent step 4, a period is determined which indicates how long the slave unit has not received any data to be processed by the security module of the slave unit from the master unit.wherein the time period is compared with the limit value in a subsequent step 5, and wherein, if the time period is greater than the limit value, it is determined in a step 6 that a communication disruption has occurred.

[0063] If, in step 3, it is determined that the slave unit has received data from the master unit to be processed by the slave unit's safety module during a safety cycle, or if, in step 5, it is determined that the period is greater than the limit value, the procedure terminates and returns to step 3, whereby, after a subsequent safety cycle, it is again determined whether the slave unit has received data from the master unit to be processed by the slave unit's safety module during the following safety cycle.

[0064] Thus, by comparing the time elapsed since the last received telegram with a defined threshold, in particular by comparing the time elapsed since the last received telegram in real time units with a defined threshold in real time units, it is determined whether a communication disruption exists.

[0065] According to Method 1, a transmission or telegram failure is permitted m times, thereby increasing the robustness and availability of the safety bus. Furthermore, corresponding communication errors can be detected quickly and easily, minimizing the error response time and the time until a safety-related reaction is initiated. Overall, Method 1 for detecting communication faults in a master-slave system is presented, combining maximum tolerance with the shortest possible response time. This method effectively improves error response times on a safety bus within a master-slave system.

[0066] The described procedure also includes a step 7 initiating a safety-related action if a communication fault is detected. This safety-related action could, for example, involve issuing a corresponding error message. Furthermore, the safety-related action could also include, for example, completely shutting down the master-slave system.

[0067] Step 2 of defining a limit value further includes defining the limit value such that it corresponds to an integer multiple m of the safety cycle. Preferably, the corresponding integer m is chosen to be 1.

[0068] According to the first embodiment, the master unit and the at least one slave unit each use the same frequency for their safety applications, so that semi-synchronous operation is given.

[0069] In such semi-synchronous communication, the time limit can be chosen to be larger than in synchronous communication, since slight frequency differences between a clock on the safety bus and a safety application of the at least one slave unit lead to beat effects, which can be further amplified by telegram and sampling jitter.

[0070] Fig. Figure 2 shows a flowchart of a method 10 for detecting communication disturbances in a master-slave system according to a second embodiment of the invention.

[0071] The method according to the second embodiment again includes a step 11 defining a limit value for a time during which each slave unit cannot receive any data to be processed by the slave unit's safety module without an error message being issued, wherein in a subsequent step 12, it is checked for each slave unit whether the slave unit has received data to be processed by the slave unit's safety module from the master unit during a safety cycle, wherein, if the slave unit has not received any data to be processed by the slave unit's safety module from the master unit during the safety cycle, in a subsequent step 13, a period is determined which indicates how long the slave unit has not received any data to be processed by the slave unit's safety module from the master unit.wherein the period is compared with the limit value in a subsequent step 14, and wherein, if the period is greater than the limit value, it is determined in a step 15 that a communication disruption has occurred.

[0072] The described procedure also includes a step 16 of initiating a safety-related action if it is determined that a communication disruption exists.

[0073] The difference between procedure 20 according to the in Fig. 2 second embodiment shown and method 10 according to the in Fig. The first embodiment shown in Figure 1 consists in the fact that the method 20 according to the second embodiment further comprises a step 17 of synchronizing the safety bus to a control communication.

[0074] Synchronizing the safety bus with the control communication system offers the advantage that both actual and corresponding target values, as well as actual and target values ​​contained in response telegrams from the slave units, can be transmitted within constant time windows. This eliminates the need for additional timestamps to compare actual and target values. Since the actual and target values ​​are aligned accordingly, fault response times can be further reduced, and the calculation of values ​​derived from them can be simplified. Furthermore, for monitoring applications such as kinematic monitoring, a constant time interval between the acquisition and evaluation of each measurement is advantageous, as it allows for a more precise definition of the threshold for triggering the monitoring system.

[0075] Fig. Figure 3 shows a block diagram of a master-slave system 20 according to embodiments of the invention.

[0076] How Fig. Figure 3 shows that the master-slave system 20 comprises a master unit 21 and three slave units 22, 23, 24, wherein the slave units 22, 23, 24 are connected to the master unit 21 via a communication system 25, wherein the communication system 25 has a safety bus 26, and wherein the slave units 22, 23, 24 each have a safety module 27, wherein the master unit 21 communicates with the slave units 22, 23, 24 via the safety bus 26 in safety cycles, wherein during a safety cycle the master unit 21 transmits data to be processed by the safety module 27 of the slave units 22, 23, 24 to the individual slave units 22, 23, 24.

[0077] A safety controller 28 is provided, which forms the actual communication master in a corresponding safety bus system, which is formed by the safety controller and the slave units 22, 23, 24 as safety participants.

[0078] The data to be processed by the safety modules 27 of the individual slave units 22,23,24 are transmitted cyclically during an operating phase, the operating phase being preceded by an initialization phase.

[0079] As can be seen, the master-slave system, according to the embodiments of the Fig. 3 further a control unit 29, wherein the control unit 29 has a first unit 30 configured to define a limit value for a time during which each slave unit 22, 23, 24 cannot receive any data to be processed by the safety module 27 of the slave unit 22, 23, 24 without an error message being issued, and wherein the control unit 29 further has a detection unit 31 for each slave unit 22, 23, 24, wherein each detection unit 31 is configured to check whether the corresponding slave unit 22, 23, 24 has received data to be processed by the safety module 27 of the slave unit 22, 23, 24 from the master unit 21 during a safety cycle, and wherein each detection unit 31 is further configured to determine a period which indicates how long the corresponding slave unit 22, 23, 24 has not received any data to be processed by the safety module 27 of the slave unit 22, 23,24 more data to be processed from the master unit 21, if the slave unit 22, 23, 24 has not received any data to be processed by the security module 27 of the slave unit 22, 23, 24 from the master unit 21 during the safety cycle, wherein each detection unit 31 is further configured to compare the period with the limit value, and wherein each detection unit 31 is further configured to determine that a communication fault exists if the period is greater than the limit value.

[0080] The components of the control unit 29 can be distributed across the master-slave system 20. Alternatively, the control unit 29 can, for example, be integrated into the safety controller or designed as a separate device, whereby the control unit can have interfaces to the individual slave units 22, 23, 24.

[0081] How Fig. As further shown in Figure 3, the control unit 29 further provides for each slave unit 22, 23, 24 a safety unit 32 which is designed to initiate a safety-related action if the corresponding detection unit 31 determines that a communication fault is present.

[0082] According to the embodiments of the Fig. 3. The slave units 22, 23, 24 are further connected to a communication controller 34 via the communication system 25 in such a way that a closed communication ring is formed. As can be seen, the safety bus system in particular forms a closed communication ring.

[0083] According to the embodiments of the Fig. 3 also contains a summary frame telegram of the master unit 21 data for a plurality of slave units, wherein the summary frame telegram according to the embodiments of the Fig. Contains 3 data for all slave units 22, 23, 24.

[0084] Furthermore, the control unit 29 shown also has a synchronization unit 33, which is designed to synchronize the safety bus 26 to a command communication, whereby the command communication is specified by a control unit 33 trained in the master unit.

[0085] In particular, the last slave unit 24 in the closed communication ring according to the embodiments of the Fig. 3 a master functionality, wherein the synchronization unit 33 is designed such that a start time for a new security cycle is specified by the last slave unit 24 based on the command communication.

[0086] Each subsequent slave unit 22, 23 is assigned a start time for a response telegram to a corresponding master telegram by the last slave unit 24. In particular, the last slave unit 24 can assume the role of a so-called clock master, whereby the last slave unit 24 can define a start time for a new safety cycle in which it sends a response telegram to the master unit in response to a corresponding master telegram, with the safety controller 29 then taking over the clock signal specified by the clock master.

Claims

[1] Method for detecting communication disturbances in a master-slave system (20), wherein the master-slave system (20) comprises a master unit (21) and at least one slave unit (22, 23, 24), wherein the at least one slave unit (22, 23, 24) is connected to the master unit (21) via a communication system (25), wherein the communication system (25) has a security bus (26), and wherein the at least one slave unit (22, 23, 24) has a security module (27), wherein the master unit (21) communicates with the at least one slave unit (22, 23, 24) via the security bus (26) in security cycles, wherein during a security cycle the master unit (21) transmits data to be processed by the security module (27) of the at least one slave unit (22, 23, 24) to the at least one slave unit (22, 23, 24), and the procedure (1,10) comprises the following steps: - Defining a limit value for a time during which each slave unit (22,23,24) cannot receive any data to be processed by the safety module (27) of the slave unit (22,23,24) without an error message being issued (2,11); and for each slave unit (22, 23, 24), check whether the slave unit (22, 23, 24) has received data to be processed by the security module (27) of the slave unit (22, 23, 24) from the master unit (21) during the safety cycle (3, 12), wherein, if the slave unit (22, 23, 24) has not received any data to be processed by the security module (27) of the slave unit (22, 23, 24) from the master unit (21) during the safety cycle, a period is determined which indicates how long the slave unit (22, 23, 24) has not received any data to be processed by the security module (27) of the slave unit (22, 23, 24) from the master unit (21) (4, 13), wherein the period is compared with the limit value (5,14), and wherein, if the period is greater than the limit value, it is determined that a communication fault has occurred (6, 15), wherein the procedure (10) further comprises the following step: synchronizing the safety bus (26) to a master communication (17); and wherein a last slave unit (22, 23, 24) in a communication ring has master functionality, and wherein the step (17) of synchronizing the safety bus (26) to the master communication comprises the following step: specifying a start time for a new safety cycle by the last slave unit (22, 23, 24) based on the master communication. [2] The method of claim 1, wherein the method (1,20) further comprises the following step: - Initiating a safety-related action if it is determined that a communication disruption is present (7,16). [3] Method according to claim 1 or 2, wherein step (2) of defining the limit value comprises defining the limit value such that it corresponds to an integer multiple of the safety cycle. [4] Method according to any one of claims 1 to 3, wherein the master unit (21) and the at least one slave unit (22, 23, 24) each use the same frequency for their safety applications. [5] Control unit (29) for detecting communication faults in a master-slave system, wherein the master-slave system (20) comprises a master unit (21) and at least one slave unit (22, 23, 24), wherein the at least one slave unit (22, 23, 24) is connected to the master unit (21) via a communication system (25), wherein the communication system (25) has a safety bus (26), and wherein the at least one slave unit (22, 23, 24) has a safety module (27), wherein the master unit (21) communicates with the at least one slave unit (22, 23, 24) via the safety bus (26) in safety cycles, wherein during a safety cycle the master unit (21) transmits data to be processed by the safety module (27) of the at least one slave unit (22, 23, 24) to the at least one slave unit (22, 23, 24) transmits, wherein the control unit (29) has a first unit (30) which is configured to set a limit value for a time,during which each slave unit (22, 23, 24) cannot receive any data to be processed by the safety module (27) of the slave unit (22, 23, 24) without an error message being issued, and wherein the control unit (29) further comprises a detection unit (31) for each slave unit (22, 23, 24), wherein each detection unit (31) is configured to check whether the corresponding slave unit (22, 23, 24) has received data to be processed by the safety module (27) of the slave unit (22, 23, 24) from the master unit (21) during the safety cycle, and wherein each detection unit (31) is further configured to define a period of time if the corresponding slave unit (22, 23, 24) has not received any data to be processed by the safety module (27) of the slave unit (22, 23, 24) from the master unit (21) during the safety cycle. determine which indicates how long the slave unit (22,23,24) has already received no more data to be processed by the safety module (27) of the slave unit (22, 23, 24) from the master unit (21), wherein each detection unit (31) is further configured to compare the period with the limit value, and wherein each detection unit (31) is further configured to determine that a communication fault exists if the period is greater than the limit value, wherein the control unit (29) is configured to synchronize the safety bus (26) to a leading communication (17); and wherein a last slave unit in a communication ring has a master functionality, and wherein the control unit (29) is configured to specify a start time for a new safety cycle by the last slave unit based on the leading communication. [6] Control unit (29) according to claim 5, wherein the control unit (29) further comprises a safety unit (32) for each slave unit (22, 23, 24) which is configured to initiate a safety-related action if the corresponding detection unit (31) determines that a communication fault is present. [7] Control unit (29) according to claim 5 or 6, wherein the first unit (30) is configured to define the limit value such that it corresponds to an integer multiple of the safety cycle. [8] Master-slave system (20), wherein the master-slave system (20) comprises a master unit (21) and at least one slave unit (22, 23, 24), wherein the at least one slave unit (22, 23, 24) is connected to the master unit (21) via a communication system (25), wherein the communication system (25) has a safety bus (26), and wherein the at least one slave unit (22, 23, 24) has a safety module (27), wherein the master unit (21) communicates with the at least one slave unit (22, 23, 24) via the safety bus (26) in safety cycles, wherein during a safety cycle the master unit (21) transmits data to be processed to the at least one slave unit (22, 23, 24) via the safety module (27), and wherein the master-slave system (20) a control unit (29) according to one of claims 5 to 7, wherein the control unit (29) further comprises a synchronization unit (33) which is configuredto synchronize the safety bus (26) to a command communication, wherein a last slave unit (24) in a communication ring has a master functionality, and wherein the synchronization unit (33) is configured such that a start time for a new safety cycle is specified by the last slave unit (24) based on the command communication. [9] Master-slave system (20) according to claim 8, wherein the at least one slave unit (22, 23, 24) are connected to the master unit (21) via the communication system (25) such that a closed communication ring is formed. [10] Master-slave system (20) according to claim 8 or 9, wherein the master-slave system (20) comprises multiple slave units (22, 23, 24), and wherein a summary frame telegram of the master unit (21) contains data for a plurality of slave units (22, 23, 24). [11] Master-slave system (20) according to one of claims 8 to 10, wherein the master unit (21) and the at least one slave unit (22, 23, 24) are configured to each use the same frequency for their security applications.

Citation Information

Patent Citations

  • Method and device for safety-oriented communication in the communication network of an automation system

    DE102009042354A1

  • Methods and computer programs for a monitoring instance and a communication component, monitoring instance, communication component, system and vehicle

    DE102018101103A1

  • Bus system e.g. for communication system in vehicle, has fault tolerance scaled in dependence on number of subscribers connected simultaneously to both data busses of data bus system

    DE10211284A1

  • Field data bus system

    DE19643092A1