Method for carrying out a transformation process of an automation control system
The method transforms standard controllers into safety controllers using a safe software package and transformation guide, overcoming recertification delays and costs, ensuring efficient and timely compliance with safety regulations.
Patent Information
- Authority / Receiving Office
- DE · DE
- Patent Type
- Applications
- Current Assignee / Owner
- IFM ELECTRONIC GMBH
- Filing Date
- 2024-10-22
- Publication Date
- 2026-04-23
AI Technical Summary
Existing standard controllers face significant delays and costs due to strict regulations and complex recertification processes when transforming into safety controllers, lacking an efficient method for timely implementation of safety-related modifications.
A method involving a predefined safe software package and transformation guide converts standard controllers into safety controllers using safe firmware and function libraries, allowing conversion without recertification, facilitated by a secure development environment and cloud-based documentation access.
Enables rapid and cost-effective transformation of standard controllers to safety controllers, enabling efficient compliance with safety regulations and reducing administrative burdens.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
[0001] The invention relates to a method for carrying out a transformation process in an automation control system. The invention further relates to a control system.
[0002] It is well established in the art that safety controllers are subject to strict regulations and require recertification after any modifications before they can be put back into operation. This recertification is a time-consuming and costly process that significantly hinders the rapid implementation of changes and expansions.
[0003] Regulations governing safety controllers include, among others, the Electromagnetic Compatibility (EMC) Directive and the Machinery Directive. These differing regulations mean that safety-related modifications and enhancements for standard controllers cannot be made available in a timely manner, as they too must meet the stringent requirements of safety controllers.
[0004] Furthermore, there is currently no efficient method for flexibly transforming standard controllers into safety controllers. This leads to a significant delay in the implementation of safety-related functions and increases the administrative burden of complying with various regulations.
[0005] In summary, the main problems with the state of the art are that changes and extensions for standard controllers cannot be made available in a timely manner due to strict regulations and the complex recertification process, and that there is no efficient method for transforming standard controllers into safety controllers.
[0006] The object of the present invention is to provide a method for transforming an automation control system, which can be made available quickly and without costly recertification, while avoiding the disadvantages known from the prior art. Furthermore, the object relates to the specification of a control system.
[0007] The problem is solved by the features of claim 1. With regard to the control system, the problem is solved by the features of claim 6.
[0008] Advantageous embodiments of the invention are specified in the dependent claims.
[0009] According to the invention, a method for carrying out a transformation process of an automation control system is claimed, wherein the control system comprises control hardware designed for functionally safe operation, which in an initial state is operated as a standard control system by means of standard firmware. wherein subsequently, in particular after an operation has already commenced, the standard controller is transformed into a safety controller according to the specifications of a transformation guide by using a predefined safe software package, wherein the safe software package comprises a safe firmware, safe function libraries and a safe development environment, wherein the safe firmware is read from the standard controller, and wherein the safe development environment accesses the safe function libraries and is used to create a safe application.
[0010] This method makes it possible to convert a standard controller, for example one used in field operations or for control tasks, into a safety controller without requiring recertification or replacement of the entire controller. Advantageously, the predefined software package and the transformation guide include all the necessary safety functions.
[0011] The invention offers the advantage that a standard controller can be efficiently transformed or converted into a safety controller if it is already qualified as a safety controller in its initial state, thereby avoiding a time-consuming and costly recertification process. In particular, the transformation can be carried out by an untrained operator, and the controller can be converted at the point of use.
[0012] Preferably, the secure development environment, in particular a secure operating system, is run on an external computing unit. Alternatively or additionally, the secure development environment can also be a secure extension for a standard development environment.
[0013] According to a preferred embodiment, the predefined software package for an operator of the standard controller is provided by the manufacturer of the standard controller, wherein the transformation instructions include a description for installing the software package and instructions for using the safe function libraries and the safe development environment to perform the transformation process. This ensures that a transformation can be performed safely by an operator.
[0014] Furthermore, it may be preferable to link the secure software package to specific control hardware for traceability purposes. In particular, this allows for reliable tracking of the awarding of certifications.
[0015] After further training, it may also be preferable for the secure firmware to replace the standard firmware on the standard controller and for the secure function libraries to extend the standard functions of the standard controller with security functions.
[0016] Preferably, after the transformation process, internet-based and / or cloud-based security documentation for the converted security controller can be accessed, or the availability of the security documentation can be activated.
[0017] For standard controllers, a CE declaration, for example according to the EMC Directive, is required in the initial state and when placing them on the market. For safety controllers, a CE declaration according to a different directive, in particular the Machinery Directive or the Machinery Ordinance, may be required. Cloud-based availability advantageously allows the safety documentation to be made available immediately even after the conversion.
[0018] For example, a valid CE declaration can be found in the cloud and / or on the internet using the product name and the device's serial number. A landing page can be accessed via: directly from the product page by entering the device's serial number; or via the manufacturer's global homepage, then navigating to the product page and entering the device's serial number there.
[0019] Preferably, the controller can have a label with an access code for retrieving safety documentation for the converted safety controller, which is read by an operator after the transformation in order to retrieve the safety documentation.
[0020] In particular, according to the Machinery Directive or the Machinery Regulation, the CE marking for a standard controller and a safety controller can have different meanings, which is why applying a new CE mark with an identification number would be necessary after a conversion. However, applying a new CE mark would have the disadvantage of logistical effort and a high susceptibility to errors. By scanning the access code, the current safety documentation can be accessed at any time, which is advantageous.
[0021] Preferably, this can be a CE marking with a pictogram, in particular a QR code. Advantageously, the original CE marking on the standard controller manufacturer's system is replaced by a "CE" together with a pictogram. The pictogram preferably indicates that information about the conformity assessment is available and can be retrieved from the cloud and / or the internet via a defined procedure. Most preferably, a QR code can be scanned by an operator, which then opens a landing page for the safety documentation.
[0022] The invention further relates to a control system for automation technology, in particular for machine and / or plant control, wherein the control system is programmable and in an initial state is designed as a standard control system, which has standard firmware and the hardware requirements of a safety control system, wherein the standard control system can be transformed into a safety control system or is transformed into a safety control system according to the aforementioned method.
[0023] According to a preferred embodiment, the controller in its initial state may have a marking and / or an access indicator to allow the retrieval of cloud-based safety documentation. Preferably, this may be a CE marking with a pictogram, wherein the pictogram provides an access indicator and / or access information to retrieve cloud-based information from the transformed safety controller.
[0024] The invention will now be explained in more detail using exemplary embodiments and with reference to the drawings.
[0025] It shows schematically: Fig. 1: Block diagram of a transformation process of a control system.
[0026] The Fig. Figure 1 shows a standard controller 10, which is operated in an initial state using standard firmware, particularly for plant and machine control in automation applications. An operator performs a transformation process 100, whereby, according to the specifications of a transformation guide 14 and using a safety software package 12, the standard controller 10 is transformed or converted into a safety controller 16.
[0027] Preferably, the secure software package 12 comprises secure firmware, secure function libraries for use in secure applications, and a secure development environment for creating the secure application. The secure development environment can also be a secure extension to a standard development environment. During the transformation, the secure firmware preferably replaces the standard firmware on the controller.
[0028] The secure development environment enables the use of secure function libraries in conjunction with secure firmware.
[0029] Transformation Guideline 14 describes, preferably, the steps necessary for an operator to transform the standard controller 10 into the safety controller 16. This includes uploading the safe firmware, preferably with the required configuration data, using the safe function libraries and the safe development environment, as well as documenting the identification of the transformed controller, in particular a serial number. Transformation Guideline 14 also describes restrictions on handling transformed controllers, especially during the subsequent lifecycle of the safety controller 16.
[0030] In addition to the transformation guide 14, further documents can be used for the transformation process 100, in particular a regulatory-required documentation of the safety controller 16. This may include an original operating manual and a CE declaration of conformity for the safety controller 16.
[0031] Furthermore, Transformation Guideline 14 can describe the use of the safe function libraries, in particular function blocks and their function. Transformation Guideline 14 and / or additional manuals can also specify the functions of the safe firmware and the use of the safe development environment, especially for configuration and the creation of safe applications. Reference symbol list 10 Standard control 12 Software Package 14 Transformation Guide 16 Safety control 100 Transformation process
Claims
[1] Method for carrying out a transformation process (100) of an automation control system, wherein the controller has control hardware designed for functionally safe operation, which in an initial state is operated as a standard controller (10) using standard firmware, wherein the standard controller (10) is subsequently transformed into a safety controller (16) according to the specifications of a transformation guide (14) by using a predefined safe software package (12), wherein the safe software package (12) includes safe firmware, safe function libraries and a safe development environment, wherein the secure firmware is read from the standard controller (10), and wherein the secure development environment accesses the secure function libraries and is used to create a secure application. [2] Control according to claim 1,characterized by , that the predefined software package (12) is provided to an operator of the standard control (10), wherein the transformation guide (14) includes a description of how to install the software package (12) and instructions for using the safe function libraries and the safe development environment to carry out the transformation process (100). [3] Control according to claim 1 or 2, characterized by , that the secure firmware replaces the standard firmware on the standard controller (10) and the secure function libraries extend the standard functions of the standard controller (10) with security functions. [4] Method according to any one of claims 1 to 3, characterized by, that after the transformation process (100) a cloud-based security documentation for the transformed security controller (16) is available or is accessed, and / or the availability of the security documentation is enabled. [5] Method according to any one of claims 1 to 4, characterized by , that the controller in the initial state has a label with an access code for retrieving safety documentation for the converted safety controller (16), which is subsequently read by an operator after the transformation in order to retrieve the safety documentation. [6] Control of automation technology, in particular for machine and / or plant control, wherein the control is programmable and in an initial state is designed as a standard control (10) which has standard firmware and the hardware requirements of a safety control (16), wherein the standard control (10) can be transformed or is transformed into a safety control (16) according to the method according to one of claims 1 to 5. [7] Control according to claim 6, characterized by that the controller in its initial state has a marking and / or an access indicator, in particular a CE marking with a pictogram, in order to be able to retrieve cloud-based and / or internet-based safety documentation.
Citation Information
Patent Citations
Wireless time-sensitive networking
EP4109937A1
Protecting a hydrocarbon fluid piping system
US10570712B2
US000010570712B2