SAFETY CIRCUIT FOR FAIL-SAFE SWITCHING OFF OF A HAZARDOUS TECHNICAL SYSTEM
Patent Information
- Application Number
- DE502017017024
- Authority / Receiving Office
- DE · DE
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2016-09-21
- Filing Date
- 2017-08-28
- Publication Date
- 2025-09-11
- Estimated Expiration
- 2037-08-28
AI Technical Summary
Existing safety circuits for fail-safe shutdown in technical systems with multiple switchable modules are complex and costly due to the need for intricate wiring and unidirectional information flow, which can lead to inefficiencies and potential safety hazards.
A safety circuit with a series-connected monitoring circuit of safety switching devices, each equipped with a fail-safe control unit, current flow changing devices, and measuring devices, allowing bidirectional communication and reliable shutdown of system modules upon detection of safety requirements, such as emergency stop signals, without complex wiring.
Enables a simple, reliable, and cost-effective bidirectional communication and fail-safe shutdown of multiple system modules, ensuring simultaneous shutdown of hazardous components upon emergency stop signals, while meeting Category 4 (Performance Level e) of the European standard EN ISO 13849-1-2009.
Description
[0001] The present invention relates to a safety circuit for the fail-safe shutdown of a dangerous technical system with a number n ≥ 2 switchable system modules.
[0002] In modern technical systems, such as industrial production plants and production lines, transport and conveyor systems, operational processes are increasingly automated. Such systems feature a central operational control system that receives the system's target and process variables and, based on these, generates corresponding control signals using a control program implemented in the operational control system. These signals can be used to operate the system's actuators.
[0003] In addition to controlling the actual operating sequence of the technical system, safety aspects also play a significant role. In this context, the aim is to prevent the hazards posed by the individual system components for people who are in the vicinity of these components. For example, system components capable of automated movements are shielded using suitable protective barriers, light barriers, safety mats, or the like. Furthermore, safety doors, protective flaps, or the like can be used to protect people. These include an actuator-sensor combination that can reliably detect an opening process, so that the entire system, or at least one hazardous system component within the system, can be shut down or converted to a state that is safe for people.Furthermore, it is also known to equip technical systems with emergency off or emergency stop buttons / switches, the actuation of which can shut down the entire system or at least one of the hazardous system components or otherwise convert it into a state that is safe for humans. For this purpose, corresponding safety circuits are used in the prior art, such as those known from EP 1 363 306 A2 or DE 10 2004 020 995 A1.
[0004] In production lines, it is often necessary for several safety relays to be interconnected. These relays monitor individual hazardous system components and, in the event of a hazard, initiate a safe shutdown of the relevant system component or transfer it to an operating state that is safe for humans. One objective in the design of the individual safety relays is that all connected system components shut down simultaneously when an emergency stop button / switch is actuated on one of the system components. Faults in the wiring between the safety relays or in the safety relays themselves must not lead to a loss of this safety function or to a hazardous operating state of the entire system or individual system components.
[0005] In the current state of the art, the individual safety relays were connected to each other, for example, via a safe data bus or by means of conventional wiring of multi-channel inputs and outputs of the safety relays. This involves a relatively high level of complexity and, consequently, high costs.
[0006] In safety relays marketed by the applicant under the name "PNOZ ®< elog," a star-shaped cascading system is provided using a pulse signal on a data transmission line. In this case, information, in particular safe shutdown information, can only be transmitted via the data transmission line by a transmitter in a specific information flow direction. In other words, this means that the information is transmitted by a transmitter in a specific information flow direction and received by one or more receivers.
[0007] EP 2 720 094 A1 discloses a safety circuit with a single safety switching device. DE 100 11 211 A1 discloses a safety circuit with multiple safety switching devices.
[0008] The object of the present invention is to provide a safety circuit for the fail-safe shutdown of a dangerous technical system with a number n ≥ 2 switchable system modules, which enables a safe shutdown of a dangerous system or a safe transfer of a dangerous system into a state that is safe for people in a particularly simple manner when a safety requirement exists in a system module, in particular when an emergency stop button / switch is actuated.
[0009] The solution to this problem is provided by a safety circuit of the type mentioned at the outset with the features of the characterizing part of claim 1. The subclaims relate to advantageous developments of the invention.
[0010] A safety circuit according to the invention for fail-safe shutdown of a dangerous technical installation with a number n ≥ 2 of switchable installation assemblies comprises a plurality of safety switching devices which are in communication with one another and each have a fail-safe control unit, wherein at least one of the installation assemblies is assigned to each of the fail-safe control units and wherein each of the fail-safe control units is configured to acquire and evaluate information about a current operating state of the at least one installation assembly assigned to it, wherein the safety switching devices are electrically connected in series to one another to form the communication connection and form a monitoring circuit, so that when the monitoring circuit is closed, an electrical monitoring current can flow through the safety switching devices,wherein each of the safety switching devices comprises at least one current flow changing device which is configured to change the current flow within the monitoring circuit, in particular to interrupt the monitoring circuit, when a safety requirement, in particular an emergency off or emergency stop information, is detected by the safety switching device in question, and wherein each of the fail-safe control units is configured to generate a shutdown signal in the event of a change, in particular an interruption, in the current flow within the monitoring circuit, which can cause the fail-safe shutdown of the system module connected to the respective fail-safe control unit and which has not already been switched off, wherein at least one safety switching element is connected to each of the fail-safe control units, which safety switching element is in turn connected to at least one of the system modules and is configured toto switch off the system assembly upon receipt of the switch-off signal from the fail-safe control unit, and wherein each of the safety switching devices has a measuring device that is connected to the fail-safe control unit and is designed to monitor the electrical current flow within the monitoring circuit and to provide a first input signal to the fail-safe control unit of the respective safety switching device when the monitoring circuit is closed and the monitoring current is measured, and a second input signal when the monitoring circuit is interrupted, and wherein the fail-safe control units are configured such that, upon receipt of the first input signal, they each generate a switch-on signal that causes the safety switching element connected to the respective fail-safe control unit to close, and upon receipt of the second input signal, they each generate the switch-off signal,which causes the safety switching element connected to the respective fail-safe control unit to open. The switch-on signal and the switch-off signal, which form the output signals of the fail-safe control unit, can preferably be machine-readable binary signals.
[0011] The safety switching devices are electrically connected in series to form the communication connection and form a monitoring circuit so that an electrical monitoring current can flow through the safety switching devices when the monitoring circuit is closed, wherein each of the safety switching devices comprises at least one current flow changing device which is designed to change the current flow within the monitoring circuit, in particular to interrupt the monitoring circuit, when a safety request, in particular emergency off or emergency stop information, is detected by the safety switching device in question, and wherein each of the fail-safe control units is designed to generate a shutdown signal in the event of a change, in particular an interruption, in the current flow within the monitoring circuit,which can cause the fail-safe shutdown of the system module connected to the respective fail-safe control unit that has not already been switched off.
[0012] The idea is that a safe electrical connection between several safety switching devices, designed in the form of an electrical series circuit, allows safe information, such as safe activation and deactivation information, to be transmitted. All safety switching devices can send and receive the safe information equally via the monitoring circuit. Information therefore flows not only in a fixed direction. When the safety circuit is activated and without a safety requirement, in particular emergency off or emergency stop information, a defined monitoring current flows through the monitoring circuit.If one of the safety relays receives a safety request, particularly an emergency stop or emergency shutdown signal, from the connected system component, such as a machine or robot, and this information is to be transmitted to all other safety relays, the current flow within the monitoring circuit is changed using the current flow modification device of the relevant safety relay. By changing the current flow within the monitoring circuit, the fail-safe control units of the other safety relays can each generate a shutdown signal, which can be used to safely shut down the connected system components of the hazardous system.The safety circuit according to the invention has the advantage of enabling safe and equal, particularly bidirectional, communication without complex wiring of the individual safety switching devices, so that switch-on and switch-off information can be transmitted reliably. The safety switching devices of the safety circuit are preferably designed to meet the requirements for classification in Category 4 (Performance Level e) of the European standard EN ISO 13849-1-2009.
[0013] Preferably, the current flow changing devices can be designed as switching devices which are designed to selectively close or interrupt the monitoring circuit.
[0014] At least one safety switching element is connected to each of the fail-safe control units. This safety switching element, in turn, is connected to at least one of the system modules and is configured to shut down the system module upon receiving the shutdown signal from the fail-safe control unit. The safety switching elements can be designed, for example, as safety relays.
[0015] Furthermore, it is provided that each of the safety switching devices has a measuring device that is connected to the fail-safe control unit and is designed to monitor the electrical current flow within the monitoring circuit and to provide the fail-safe control unit of the respective safety switching device with a first input signal when the monitoring circuit is closed and the monitoring current is measured, and with a second input signal when there is a change, in particular an interruption, in the current flow within the monitoring circuit. The change in the current flow within the monitoring circuit can be achieved by measuring an electrical quantity, in particular by measuring a current change or by measuring a voltage change. The input signals provided to the fail-safe control units can preferably also be binary input signals.
[0016] In a practical embodiment, each of the measuring devices can comprise at least one resistor and an evaluation unit connected to it, which is designed to determine an electrical voltage drop across the at least one resistor and to generate the first or second input signal depending on the magnitude of the voltage drop. A voltage drop can be determined very easily using measurement technology and enables not only the detection of whether the monitoring circuit has been interrupted by one of the safety switching devices, but also the detection of line breaks, short circuits, or external electrical voltages.
[0017] The current flow changing devices can preferably be designed as transistors, in particular as field-effect transistors, or as relays. This creates a technically robust and operationally reliable design for the current flow changing devices.
[0018] To achieve a defined current flow within the monitoring circuit, a preferred embodiment proposes that a first safety switching device of the safety circuit comprise a constant current source configured to generate a constant current. This ensures that a defined monitoring current flows through the monitoring circuit, preventing possible current fluctuations that could potentially be considered a fault in the safety circuit.
[0019] In an alternative embodiment, it can also be provided that a first safety switching device of the safety circuit has a constant voltage source designed to provide a constant voltage. This advantageously prevents effects resulting from fluctuations in the electrical supply voltage, which can also be interpreted as errors.
[0020] In an advantageous further development, it is possible for each of the safety switching devices to have at least one storage device connected to the evaluation unit of the measuring device of the respective safety switching device, wherein a first reference voltage value U ref,1 of a reference voltage upstream of the resistor and a second reference voltage value U ref,2 of a second reference voltage downstream of the electrical resistor are stored in the storage device in a retrievable manner. The two reference voltage values U ref,1 and U ref,2 of all safety switching devices can be initialized ("taught") during commissioning of the safety circuit and each stored in the storage device of the safety switching devices in a retrievable manner.If the actual voltages before or after the resistance of the respective measuring device deviate from the reference voltage values U ref,1 and U ref,2 stored in the memory, the evaluation units of the measuring devices can generate corresponding input signals, which are made available to the fail-safe control unit of the respective safety switching device. The fail-safe control unit of each safety switching device generates a shutdown signal, which causes the connected system module to be shut down, in particular, the opening of the safety switching element connected to the fail-safe control unit and to the system module.
[0021] To further simplify the detection of faults in the safety circuit, a particularly advantageous embodiment proposes that the first safety switching device of the safety circuit comprise a voltage pulse generator connected to the constant voltage source and configured to generate defined voltage pulses, in particular 0 V voltage pulses, and that each of the safety switching devices comprise a voltage pulse evaluation means configured to detect and evaluate the voltage pulses. In other words, the voltage is modulated in a defined manner.If a voltage pulse evaluation device of at least one of the safety switching devices does not detect any voltage pulses, which may in particular be 0 V voltage pulses, or does not detect the expected ("taught") voltage pulses, a fault also occurs, so that the safety switching devices can initiate a safe shutdown process of the system components of the dangerous system.
[0022] To further increase the operational reliability of the safety circuit, an advantageous development can provide for each of the safety switching devices to comprise a number of series-connected current flow modifiers. The current flow modifiers, which can be configured, for example, as transistors, in particular field-effect transistors, or as relays, can preferably be tested when the safety circuit is activated. To synchronize these tests, addressing of the safety switching devices, which can occur automatically or be initiated by a first safety switching device, is advantageous.
[0023] Further features and advantages of the present invention will become clear from the following description of preferred embodiments with reference to the accompanying drawings. Fig. 1 is a schematically highly simplified representation illustrating the basic principle of a safety circuit designed according to the present invention, Fig. 2 is a schematically simplified representation of a safety circuit designed according to a first embodiment of the present invention, Fig. 3 is a schematically simplified representation of a safety circuit designed according to a second embodiment of the present invention, Fig. 4 is a schematically simplified representation of a safety circuit designed according to a third embodiment of the present invention, Fig. 5 is a schematically simplified representation of a safety circuit designed according to a fourth embodiment of the present invention.
[0024] With reference to Fig. 1A safety circuit 1, which is designed for the fail-safe shutdown of a hazardous installation 3 with a number n ≥ 2 switchable installation assemblies 4a, ..., 4n, in particular machines or robots, comprises a plurality of safety switching devices 2a, ..., 2n. These safety switching devices 2a, ..., 2n are preferably designed such that they meet the requirements for classification in Category 4 (Performance Level e) of the European standard EN ISO 13849-1-2009. Preferably, the number of safety switching devices 2a, ..., 2n corresponds to the number of installation assemblies 4a, ..., 4n of the hazardous installation 3, so that each of the installation assemblies 4a, ..., 4n is assigned one of the safety switching devices 2a, ..., 2n. The individual safety switching devices 2a, ..., 2n are electrically connected in series with one another by means of electrical connecting cables 5.The safety circuit 1 preferably has a modular and scalable design, so that the number n of safety switching devices 2a, ..., 2n can be easily changed even subsequently. Due to the modular design of the safety circuit 1, each of the safety switching devices 2a, ..., 2n has a voltage terminal 20 for supplying a supply voltage, a ground terminal 21, an input terminal 22, and an output terminal 23.
[0025] The voltage terminal 20 of the first safety switching device 2a is connected to an external voltage supply device that can supply the safety circuit 1 with a supply voltage that can, in particular, be between 20 volts and 30 volts (DC). The voltage terminal 20 of the first safety switching device 2a is connected to the input terminal 22 of the first safety switching device 2a. The output terminal 23 of the first safety switching device 2a is connected to the input terminal 22 of the second safety switching device 2b. The output terminal 23 of the second safety switching device 2b is connected to the input terminal 22 of the third safety switching device 2c, and so on. The output terminal 23 of the nth safety switching device 2n is connected to the ground terminal 21 of the nth safety switching device 2n.In this way, an electrical monitoring circuit of the safety circuit 1 is formed, which is closed by a common ground line of the external voltage supply device (not explicitly shown here) and the last (n-th) safety switching device 2n.
[0026] Each of the safety switching devices 2a, ..., 2n further comprises a measuring device 6a, ..., 6n, by means of which an electrical quantity, such as an electrical voltage or an electrical current, can be measured, as well as a current flow changing device 7a, ..., 7n. In this and all other embodiments presented here, the current flow changing devices 7a, ..., 7n are designed as switching devices that can be selectively opened and closed. When these current flow changing devices 7a, ..., 7n are closed, a defined monitoring current flows through the monitoring circuit. When one of the current flow changing devices 7a, ..., 7n is opened, the monitoring circuit is opened, so that no current flows within the monitoring circuit.
[0027] Each of the safety switching devices 2a, ..., 2n of the safety circuit 1 is configured to transmit a safety request, in particular an emergency off or emergency stop message, from the switchable system modules 4a, ..., 4n connected to the respective safety switching device 2a, ..., 2n to the other safety switching devices 2a, ..., 2n of the safety circuit 1 or to receive a safety request, in particular an emergency off or emergency stop message, from one of the other safety switching devices 2a, ..., 2n. As will be explained in more detail below, in the normal operating state of the safety circuit 1, all current flow modification devices 7a, ..., 7n are closed, so that the presence of an electrical monitoring current flowing through the series-connected safety switching devices 2a, ..., 2n can be detected by measuring the electrical quantity using the integrated measuring device 6a, ...,6n each of the safety switching devices 2a, ..., 2n can be detected in a suitable manner.
[0028] In order to forward a safety request, in particular an emergency off or emergency stop information, which one of the safety switching devices 2a, ..., 2n has received, to the other safety switching devices 2a, ..., 2n of the safety circuit 1, the current flow change device 7a, ..., 7n of the relevant safety switching device 2a, ..., 2n is opened. This interruption of the electrical monitoring current flow within the monitoring circuit of the safety circuit 1 can be detected by the measuring devices 6a, ..., 6n of the other safety switching devices 2a, ..., 2n, so that they can also initiate a safety request, in particular an emergency off or emergency stop function, in the system modules 4a, ..., 4n connected to the relevant safety switching devices 2a, ..., 2n, in the manner described below.
[0029] With reference to Fig. 2 to 5This basic operating concept of the safety circuit 1, which has only been briefly outlined above, will now be explained in more detail using four exemplary embodiments. In order to keep the following presentation clear, the Fig. 2 to 5 Each of the safety circuits 1 shown comprises three safety switching devices 2a, 2b, 2c, which are electrically connected in series with one another in the manner described above. One of the system modules 4a, 4b, 4c is connected to each of these safety switching devices 2a, 2b, 2c.
[0030] With reference to Fig. 2In this exemplary embodiment, the first safety switching device 2a has a constant current source 8, which is connected to the input terminal 22 of the first safety switching device 2a, to which the supply voltage of the safety circuit 1, which in this case is 24 V, is applied. The measuring devices 6a, 6b, 6c of the safety switching devices 2a, 2b, 2c each comprise an electrical resistor 60 and an evaluation unit 61, which in this case is designed as a microcontroller with a first A / D input 610 and a second A / D input 611. During operation of the safety circuit 1, a voltage drop ΔU across the electrical resistor 60 can be detected by means of the first A / D input 610 and the second A / D input 611 of the evaluation unit 61 of each measuring device 6a, 6b, 6c and evaluated by the evaluation unit 61.
[0031] In this embodiment, as well as in the other embodiments described below, the current flow changing devices 7a, 7b, 7c are each designed as field-effect transistors (FETs). Alternatively, the current flow changing devices 7a, 7b, 7c can also be designed as conventional transistors or relays.
[0032] Each of the safety switching devices 2a, 2b, 2c further comprises a fail-safe control unit 9a, 9b, 9c, which is connected on the input side to the evaluation unit 61 of the measuring device 6a, 6b, 6c of the respective safety switching device 2a, 2b, 2c and forms an AND gate. As will be explained in more detail below, the evaluation units 61 are configured to transmit a binary input signal (U1, U2, U3 = 0 or U1, U2, U3 = 1) to the respective fail-safe control unit 9a, 9b, 9c.
[0033] The fail-safe control unit 9a, 9b, 9c of each safety switching device 2a, 2b, 2c further has one or more inputs. Via these inputs, input signals from one or more sensor means can be made available to the respective fail-safe control unit 9a, 9b, 9c, which can be evaluated by the fail-safe control unit 9a, 9b, 9c. This makes it possible for the fail-safe control unit 9a, 9b, 9c of each of the safety switching devices 2a, 2b, 2c to receive information about the operating state of the system module 4a, 4b, 4c connected to it, a safety request, in particular an emergency shutdown or emergency stop information. The results of the internal input signal processing also form a binary input signal (E1, E2, E3 = 0 or E1, E2, E3 = 1) for the AND gate of the fail-safe control unit 9a, 9b, 9c.
[0034] Furthermore, in the exemplary embodiments shown here, each of the safety switching devices 2a, 2b, 2c has a safety switching element 10a, 10b, 10c, which is connected on the output side to the fail-safe control unit 9a, 9b, 9c of the respective safety switching device 2a, 2b, 2c. Each of these safety switching elements 10a, 10b, 10c is connected to a system module 4a, 4b, 4c of the hazardous system 3. By means of the safety switching elements 10a, 10b, 10c, which are preferably designed as safety relays, the connected system modules 4a, 4b, 4c can be switched on and off in a fail-safe manner. The fail-safe control unit 9a, 9b, 9c of each safety switching device 2a, 2b, 2c is configured to transmit a binary output signal (A1, A2, A3 = 0 or A1, A2, A3 = 1) to the respective safety switching element 10a, 10b, 10c.The output signals A1 = 0, A2 = 0, and A3 = 0 each represent a shutdown signal for switching off the respective safety switching element 10a, 10b, 10c. In contrast, the output signals A1 = 0, A2 = 0, and A3 = 1 each represent a switch-on signal for switching on the respective safety switching element 10a, 10b, 10c. In the fail-safe control units 9a, 9b, 9c, all safety requirements of the connected system modules 4a, 4b, 4c of the hazardous system 3 are processed, so that the safety switching elements 10a, 10b, 10c of the safety switching devices 2a, 2b, 2c can be controlled depending on the results of the evaluations.
[0035] Using a dimensioning example, various operating conditions of the Fig. 2The safety circuit 1 shown will be explained in more detail. It is assumed that the constant current source 8 provides an electrical monitoring current I = 2 mA and that the electrical resistance 60 has a value R = 500 ohms. Condition No. 1: Normal operation
[0036] In a fault-free (normal) operating state of all system assemblies 4a, 4b, 4c of the hazardous system 3, all safety relays 2a, 2b, 2c are switched on. The internal evaluation of the input signals from the sensors of the system assemblies 4a, 4b, 4c of the hazardous system 3 provides a value E1 = E2 = E3 = 1 for the input side of the AND gate of each fail-safe control unit 9a, 9b, 9c. The fail-safe control unit 9a, 9b, 9c is also configured to open or close the current flow modification device 7a, 7b, 7c of the respective safety relay 2a, 2b, 2c.
[0037] This can be done via a binary control signal S1, S2, S3, where S1, S2, S3 = 1 represents a closed current flow changing device 7a, 7b, 7c and S1, S2, S3 = 0 represents an open current flow changing device 7a, 7b, 7c.
[0038] In the normal operating state of all system modules 4a, 4b, 4c connected to the safety switching devices 2a, 2b, 2c, the following applies: E1 = E2 = E3 = 1 and S1 = S2 = S3 = 1. This means that all current flow changing devices 7a, 7b, 7c of the safety switching devices 2a, 2b, 2c and thus also the monitoring circuit are closed, so that the electrical monitoring current can flow from the first safety switching device 2a via the second safety switching device 2b to the third safety switching device 2c. This results in a voltage drop ΔU across the electrical resistance 60 of each of the measuring devices 6a, 6b, 6c of the safety switching devices 2a, 2b, 2c, where ΔU = 1 V applies in each case. The measuring devices 6a, 6b, 6c transmit an input signal U1 = U2 = U3 =1 to the fail-safe control unit 9a, 9b, 9c, which represents that the voltage drop ΔU corresponds to the expected value in trouble-free operation of all system modules 4a, 4b, 4c.
[0039] Furthermore, because E1 = E2 = E3 = 1 and U1 = U2 = U3 = 1, all safety switching elements 10a, 10b, 10c, which are preferably designed as safety relays, are closed (ie, the following applies to the output signals generated by the fail-safe control unit 9a, 9b, 9c of each safety switching device 2a, 2b, 2c: A1 = A2 = A3 = 1), so that all system modules 4a, 4b, 4c connected to them can be supplied with their electrical operating voltage. Condition No. 2: Safe shutdown of the system components
[0040] For example, if an emergency stop button / switch is actuated in the second system module 4b, thus opening the safety switching element 10b of the second safety switching device 2b, this emergency stop or emergency stop information should also be made available to the two remaining safety switching devices 2a, 2c of the safety circuit 1, so that the system modules 4a, 4c connected to them can also be safely shut down simultaneously. The result of the internal signal processing of the fail-safe control unit 9b of the second safety switching device 2b then provides a value E2 = 0, which represents the emergency stop or emergency stop information.To ensure safe shutdown of the system modules 4a, 4c of the two remaining safety switching devices 2a, 2c, the fail-safe control unit 9b of the second safety switching device 2b controls the current flow modifier 7b of the second safety switching device 2b such that it opens and the electrical monitoring current flow from the first safety switching device 2a to the third safety switching device 2c is interrupted. The current flow modifier 7b of the second safety switching device 2b receives a control signal S2 = 0, which causes the respective current flow modifier 7b to open and leads to an interruption of the monitoring circuit of the safety circuit 1.
[0041] Then, the following applies to the voltage drop ΔU across the resistors 60 of the measuring device 6a of the first safety switching device 2a and the measuring device 6c of the third safety switching device 2c: ΔU = 0 V. This voltage drop ΔU = 0 V is detected by the evaluation units 61 of the measuring devices 6a, 6c of the first and third safety switching devices 2a, 2c. The evaluation units 61 of the measuring devices 6a, 6c of the first safety switching device 2a and the third safety switching device 2c each generate an input signal U1 = 0 or U3 = 0 for the AND gate of the fail-safe control unit 9a, 9c of the first and third safety switching devices 2a, 2c. Since the input signal of the fail-safe control unit 9a of the first safety switching device 2a is U1 = 0, the fail-safe control unit 9a generates an output signal A1 = 0, which causes the safety switching element 10a of the first safety switching device 9a to be switched off.Since the following also applies to the input signal of the fail-safe control unit 9c of the third safety switching device 2c: U3 = 0, the fail-safe control unit 9c generates an output signal A3 = 0, which causes the safety switching element 10c of the third safety switching device 9c to be switched off. Condition No. 3: Restart
[0042] If, starting from the operating state described above, the safety switching element 10b of the second safety switching device 2b is switched on again so that the second system module 4b is put into operation again, the internal signal processing of the fail-safe control unit 9b of the second safety switching device 2b delivers the result E2 = 1. A switching signal S2 = 1 is then generated, which closes the current flow changing device 7b of the second safety switching device 2b.Since the current flow changing device 7a of the first safety switching device 2a and the current flow changing device 7c of the third safety switching device 2c were not opened during the earlier shutdown process and are therefore still in a closed state, the electrical monitoring current can again flow through the closed monitoring circuit of the safety circuit 1 from the first safety switching device 2a to the third safety switching device 2c. Thus, a voltage drop ΔU = 1 V can again be measured across the resistors 60 of all measuring devices 6a, 6b, 6c, so that the fail-safe control unit 9a, 9b, 9c of each safety switching device 2a, 2b, 2c receives an input signal U1 = U2 = U3 = 1 and, because E1 = E2 = E3 = 1, delivers corresponding output signals A1 = A2 = A3 = 1.The output signals A1 = 1 and A3 = 1 result in the safety switching elements 10a, 10c of the first and third safety switching devices 2a, 2c also being closed, so that the system modules 4a, 4c of the dangerous system 3 connected to them can also be supplied with their operating voltage again. Condition No. 4: Wiring error
[0043] If, for example, due to a wiring error, no electrical monitoring current flows through the safety switching devices 2a, 2b, 2c, no voltage drop ΔU can be measured across the resistors 60 of all measuring devices 6a, 6b, 6c. Therefore, ΔU = 0 V applies. In this fault situation, the fail-safe control unit 9a, 9b, 9c of each safety switching device 2a, 2b, 2c receives an input signal U1 = U2 = U3 = 0. The fail-safe control unit 9a, 9b, 9c of each safety switching device 2a, 2b, 2c provides corresponding output signals A1 = A2 = A3 = 0, which cause the safety switching elements 10a, 10b, 10c to open and thus safely shut down the system modules 4a, 4b, 4c connected to them.
[0044] If the measurements of the voltage drop ΔU show that ΔU > 1 V or 0 V < ΔU < 1 V, a fault has occurred. The evaluation units 61 of the measuring devices 6a, 6b, 6c also generate an input signal U1 = U2 = U3 = 0, so that the fail-safe control unit 9a, 9b, 9c of each safety switching device 2a, 2b, 2c each provides a corresponding output signal A1 = A2 = A3 = 0. These output signals A1 = A2 = A3 = 0 cause the safety switching elements 10a, 10b, 10c to open and thus the system modules 4a, 4b, 4c connected to them to shut down.
[0045] With reference to Fig. 3A second exemplary embodiment of a safety circuit 1 will be explained in more detail below. In contrast to the first exemplary embodiment, the first safety switching device 2a has a constant voltage source 11 that maintains the voltage constant at a predetermined value regardless of the fluctuating supply voltage provided by the external power supply device. For example, the constant voltage source 11 can maintain the voltage at a constant value UV = 15 V. In this exemplary embodiment, the resistors 60 again have a value R = 500 ohms.
[0046] The following applies to the voltage drop ΔU across the respective resistor 60 measured by the measuring devices 6a, 6b, 6c and the binary input signals provided by the evaluation units 61: U = 1, if ΔU = 5 V U = 0, if ΔU = 0 V Error, if ΔU > 5 V or 0 V < ΔU < 5 V.
[0047] Various operating states of the safety circuit 1 will be explained in more detail below. Operating states 1 to 4 correspond from a technical perspective to those of the first embodiment, so they are described below in abbreviated form. Condition No. 1: Normal operation
[0048] During normal operation, as in the first embodiment, all safety switching devices 2a, 2b, 2c and the system modules 4a, 4b, 4c connected to them are switched on. A voltage drop ΔU = 5 V can be measured across each resistor 60 of the measuring devices 6a, 6b, 6c, so that, analogously to the first embodiment, the following applies to the binary input signals U1, U2, U3: U1 = U2 = U3 = 1. Since no emergency off or emergency stop has been initiated, the following also applies: E1 = E2 = E3 = 1, so that all current flow modification devices 7a, 7b, 7c are closed. Therefore, S1 = S2 = S3 = 1. Furthermore, the following applies to the output signals A1, A2, A3 of the fail-safe control unit 9a, 9b, 9c of each safety switching device 2a, 2b, 2c: A1 = A2 = A3 = 1. This means that all safety switching elements 10a, 10b, 10c are closed. Condition No. 2: Safe shutdown of the system components
[0049] For example, if an emergency stop button / switch of the second system assembly 4b is actuated and the safety switching element 10b of the second safety switching device 2b is opened, the internal signal processing in the fail-safe control unit 9b leads to the result E2 = 0. This causes the fail-safe control unit 9b to provide a shutdown signal S2 = 0 to the current flow modifier 7b of the second safety switching device 2b. The current flow modifier 7b of the second safety switching device 2b is opened, so that the monitoring current flow within the electrical monitoring circuit of the safety circuit 1 from the first safety switching device 2a to the third safety switching device 2c is interrupted.
[0050] The following then applies to the voltage drop ΔU across the resistor 60 of the measuring devices 6a, 6c of the first safety switching device 2a and the third safety switching device 2c: ΔU = 0 V. This means that the fail-safe control unit 9a of the first safety switching device 2a receives an input signal U1 = 0 and, in turn, generates an output signal A1 = 0, which leads to the opening of the safety switching element 10a of the first safety switching device 2a. Similarly, the fail-safe control unit 9c of the third safety switching device 2c receives an input signal U3 = 0 and generates an output signal A3 = 0, which leads to the opening of the safety switching element 10c of the third safety switching device 2c. State No. 3: Restarting the system modules
[0051] If, starting from the previously described state, the safety switching element 10b of the second safety switching device 2b is switched on again so that the second system module 4b is put into operation again, the internal signal processing of the fail-safe control unit 9b of the second safety switching device 2b delivers the result E2 = 1. The fail-safe control unit 9b of the second safety switching device 2b then generates a switching signal S2 = 1, which closes the current flow changing device 7b of the second safety switching device 2b again.Since the current flow changing device 7a of the first safety switching device 2a and the current flow changing device 7c of the third safety switching device 2c were not opened during the previous shutdown process and thus remain in a closed state, the electrical monitoring current can flow again from the first safety switching device 2a to the third safety switching device 2c after the current flow changing device 7b of the second safety switching device 2b is closed. Thus, a voltage drop ΔU = 5 V can be measured across the resistors 60 of all measuring devices 6a, 6b, 6c, so that the fail-safe control unit 9a, 9b, 9c of each safety switching device 2a, 2b, 2c receives an input signal U1 = U2 = U3 = 1 and, due to E1 = E2 = E3, delivers corresponding output signals A1 = A2 = A3 = 1.The output signals A1 = 1 and A3 = 1 cause the safety switching elements 10a, 10c of the first and third safety switching devices 2a, 2c to also be closed, so that the system modules 4a, 4c of the dangerous system 3 connected to them can be supplied with their operating voltage again. Condition No. 4: Wiring error
[0052] If, for example, due to a wiring error, no electrical monitoring current flows through the safety switching devices 2a, 2b, 2c, no voltage drop ΔU can be measured across the resistors 60 of all measuring devices 6a, 6b, 6c. Therefore, ΔU = 0 V applies. In this fault situation, the fail-safe control unit 9a, 9b, 9c of each safety switching device 2a, 2b, 2c receives an input signal U1 = U2 = U3 = 0. The fail-safe control unit 9a, 9b, 9c of each safety switching device 2a, 2b, 2c provides corresponding output signals A1 = A2 = A3 = 0, which cause the safety switching elements 10a, 10b, 10c to open and thus safely shut down the system modules 4a, 4b, 4c connected to them. State No. 5: Error state 0 V voltage at the output terminal 23 of the second safety switching device 2b or at the input terminal 22 of the third safety switching device 2c
[0053] If a voltage U = 0 V is present at the output terminal 23 of the second safety switching device 2b or at the input terminal 22 of the third safety switching device 2c, a voltage drop ΔU = 7.5 V is detected by the measuring devices 6 in the first safety switching device 2a and in the second safety switching device 2b. The evaluation units 61 of the first and second safety switching devices 2a, 2b generate an input signal U1 = 0 and U2 = 0, which are made available to the fail-safe control unit 9a, 9b of the first and second safety switching devices 2a, 2b, so that output signals A1 = 0 and A2 = 0 can be generated, which cause the safety switching elements 10a, 10b of the first and second safety switching devices 2a, 2b to open. In addition, an error message is output.
[0054] In the third safety switching device 2c, the voltage drop across the resistor 60 results in a value of ΔU = 0 V. This leads to an input signal U3 = 0 for the fail-safe control unit 9c of the third safety switching device 2c, which generates an output signal A3 = 0, which causes the safety switching element 10c of the third safety switching device 2c to open. State No. 6: Error state 24 V voltage at the output terminal 23 of the second safety switching device 2b or at the input terminal 22 of the third safety switching device 2c
[0055] If a voltage U = 24 V is applied to the output terminal 23 of the second safety switching device 2b or to the input terminal 22 of the third safety switching device 2c, a voltage drop ΔU = -4.5 V is detected by the measuring devices 6 in the first safety switching device 2a and the second safety switching device 2b. The evaluation units 61 of the measuring devices 6a, 6b of the first and second safety switching devices 2a, 2b generate an input signal U1 = 0 and U2 = 0, which are made available to the fail-safe control unit 9a, 9b of the first and second safety switching devices 2a, 2b, so that output signals A1 = 0 and A2 = 0 are generated, which cause the safety switching elements 10a, 10b of the first and second safety switching devices 2a, 2b to open. In addition, an error message is output. Within the third safety switching device 2c, the voltage drop across resistor 60 is ΔU = 24 V.This results in an input signal U3 = 0 for the fail-safe control unit 9c of the third safety switching device 2c, which generates an output signal A3 = 0, which causes the safety switching element 10c of the third safety switching device 2c to open. Additionally, an error message is output.
[0056] With reference to Fig. 4A third exemplary embodiment of the safety circuit 1 will be explained in more detail below. This exemplary embodiment differs from the second exemplary embodiment in that each of the safety switching devices 2a, 2b, 2c additionally has a storage means 12a, 12b, 12c, which is connected to the evaluation unit 61 of the measuring device 6a, 6b, 6c of the respective safety switching device 2a, 2b, 2c. Within the storage means 12a, 12b, 12c, two reference voltage values U ref,1 and U ref,2 can be retrievably stored for each safety switching device 2a, 2b, 2c. A first reference voltage value U ref,1 indicates the magnitude of the voltage across the resistor 60 of the measuring device 6a, 6b, 6c of the respective safety switching device 2a, 2b, 2c. A second reference voltage value U ref,2 indicates the magnitude of the voltage behind the resistor 60 of the measuring device 6a, 6b, 6c of the respective safety switching device 2a, 2b, 2c.The two reference voltage values U ref,1 and U ref,2 of all safety switching devices 2a, 2b, 2c are initialized ("taught") during commissioning of the safety circuit 1 and are stored in the storage means 12a, 12b, 12c of the safety switching devices 2a, 2b, 2c in a retrievable manner.
[0057] The operating states No. 1 to No. 4 correspond to those of the second embodiment, so that they will not be discussed again here. State No. 5: Error state 0 V voltage or 24 V voltage at the output terminal 23 of the second safety switching device 2b or at the input terminal 22 of the third safety switching device 2c
[0058] If, for example, a voltage U = 0 V (operating state no. 5 of the third exemplary embodiment) or a voltage U = 24 V (operating state no. 6 of the third exemplary embodiment) is present at the output terminal 23 of the second safety switching device 2b or at the input terminal 22 of the third safety switching device 2c, deviations of the actual voltages in front of or behind the resistor 60 of the respective measuring device 6a, 6b, 6c from the reference voltage values U ref,1 and U ref,2 stored in the storage means 12a, 12b, 12c occur in all safety switching devices 2a, 2b, 2c. These deviations result in the evaluation units 61 of the measuring devices 6a, 6b, 6c generating corresponding input signals U1 = U2 = U3 = 0, which are made available to the fail-safe control unit 9a, 9b, 9c of the respective safety switching device 2a, 2b, 2c.The fail-safe control unit 9a, 9b, 9c of each safety switching device 2a, 2b, 2c generates an output signal A1 = A2 = A3 = 0. These output signals A1, A2, A3 cause the safety switching elements 10a, 10b, 10c of the safety switching devices 2a, 2b, 2c to open.
[0059] With reference to Fig. 5 A fourth exemplary embodiment of the safety circuit 1 will be explained in more detail below. This exemplary embodiment differs from the third exemplary embodiment in that the first safety switching device 2a additionally has a voltage pulse generator 14. Furthermore, each of the safety switching devices 2a, 2b, 2c comprises a voltage pulse evaluation means 13a, 13b, 13c, which is configured to detect and evaluate the voltage pulses generated by the voltage pulse generator 14, which can in particular be 0V voltage pulses.
[0060] Each of the safety switching devices 2a, 2b, 2c in turn comprises a storage device 12a, 12b, 12c, which is connected to the evaluation unit 61 of the measuring device 6a, 6b, 6c of the respective safety switching device 2a, 2b, 2c. Within the storage device 12a, 12b, 12c, two reference voltage values U ref,1 and U ref,2 can be stored for each safety switching device 2a, 2b, 2c in a retrievable manner. A first reference voltage value U ref,1 indicates the magnitude of the voltage across the resistor 60 of the measuring device 6a, 6b, 6c of the respective safety switching device 2a, 2b, 2c. A second reference voltage value U ref,2 indicates the magnitude of the voltage behind the resistor 60 of the measuring device 6a, 6b, 6c of the respective safety switching device 2a, 2b, 2c.The reference voltage values U ref,1 and U ref,2 of all safety switching devices 2a, 2b, 2c are again initialized ("taught") during commissioning of the safety circuit 1 and stored in the storage means 12a, 12b, 12c of the safety switching devices 2a, 2b, 2c in a retrievable manner.
[0061] If the measured voltage values before or after the resistor 60 of the measuring device 6a, 6b, 6c of the safety relays 2a, 2b, 2c deviate from the "taught" and stored reference voltage values U ref,1 and U ref,2, an error message is generated. These deviations cause the evaluation units 61 to generate corresponding input signals U1 = U2 = U3 = 0, which are made available to the fail-safe control unit 9a, 9b, 9c of the respective safety relay 2a, 2b, 2c. The fail-safe control unit 9a, 9b, 9c of each safety switching device 2a, 2b, 2c generates an output signal A1 = A2 = A3 = 0. These output signals A1, A2, A3 cause the safety switching elements 10a, 10b, 10c of the safety switching devices 2a, 2b, 2c to open. This corresponds to operating state 5 of the third embodiment.
[0062] The operating states No. 1 to No. 4 also correspond to those of the third embodiment, so that they will not be discussed again here. State No. 6: Error state 5 V voltage at the output terminal 23 of the second safety switching device 2b or at the input terminal 22 of the third safety switching device 2c
[0063] If a voltage U = 5 V is present at the output terminal 23 of the second safety switching device 2b or at the input terminal 22 of the third safety switching device 2c, no voltage pulses, which may in particular be 0 V voltage pulses, are detected by the voltage pulse evaluation means 13c of the third safety switching device 2c. The evaluation unit 61 of the third safety switching device 2c generates a corresponding input signal U3 = 0 for the fail-safe control unit 9c of the third safety switching device 2c, which in turn generates an output signal A3 = 0, which causes the safety switching element 10c of the third safety switching device 2c to open. Furthermore, a switching signal S3 = 0 is generated, which opens the current flow changing device 7c of the third safety switching device 2c.This opens the electrical monitoring circuit, so that the voltage drop across the resistors 60 of the measuring devices 6a, 6b of the first and second safety switching devices 2a, 2b is: ΔU = 0 V. The evaluation units 61 of the measuring devices 6a, 6b of the first and second safety switching devices 2a, 2b generate an input signal U1 = U2 = 0, which is made available to the fail-safe control unit 9a, 9b of the respective safety switching device 2a, 2b. The fail-safe control unit 9a of the first safety switching device 2a generates an output signal A1 = 0, which causes the safety switching element 10a of the first safety switching device 2a to open and thus the system module 4a connected to it to shut down.Similarly, the fail-safe control unit 9b of the second safety switching device 2b generates an output signal A2 = 0, which causes the safety switching element 10b of the second safety switching device 2b to open and thus shuts down the system module 4b connected to it. These measures, in turn, enable a fail-safe shutdown of the system modules 4a, 4b, 4 of the hazardous system in the event of a fault.
Claims
1. Safety circuit (1) for the fail-safe shutdown of a hazardous technical installation (3) with a number n ≥ 2 of installation assemblies (4a, ..., 4n) that are able to be shut down, comprising a plurality of safety switching devices (2a, ..., 2n) that are communicatively connected to one another and each have a fail-safe control unit (9a, 9b, 9c), wherein at least one of the installation assemblies (4a, ..., 4n) is assigned to each of the fail-safe control units (9a, 9b, 9c), and wherein each of the fail-safe control units (9a, 9b, 9c) is configured to capture and evaluate information regarding a present operating state of the at least one installation assembly (4a, ..., 4n) assigned thereto, wherein the safety switching devices (2a, ..., 2n) are electrically connected in series with one another to form the communication connection and form a monitoring circuit, with the result that an electric monitoring current is able to flow through the safety switching devices (2a, ..., 2n) when the monitoring circuit is closed, wherein each of the safety switching devices (2a, ..., 2n) comprises at least one current flow changing apparatus (7a, ..., 7n) that is configured to change the current flow within the monitoring circuit, in particular to interrupt the monitoring circuit if a safety demand, in particular an item of emergency switch-off or emergency stop information, is captured by the relevant safety switching device (2a, ..., 2n), and wherein each of the fail-safe control units (9a, 9b, 9c) is designed, in the event of a change, in particular an interruption, to the current flow within the monitoring circuit, to generate a shutdown signal that is able to effect the fail-safe shutdown of the installation assembly (4a, ..., 4n) that is connected to the respective fail-safe control unit (9a, 9b, 9c) and has not already been shut down, wherein each of the fail-safe control units (9a, 9b, 9c) has at least one safety switching element (10a, 10b, 10c) connected thereto, which in turn is connected to at least one of the installation assemblies (4a, ...,4n) and is configured to shut down the installation assembly (4a, ...,4n) upon receiving the shutdown signal from the fail-safe control unit (9a, 9b, 9c), and wherein each of the safety switching devices (2a, ..., 2n) has a measuring apparatus (6a, 6b, 6c) that is connected to the fail-safe control unit (9a, 9b, 9c) and is designed to monitor the electric current flow within the monitoring circuit and to provide the fail-safe control unit (9a, 9b, 9c) of the relevant safety switching device (2a, ..., 2n) with a first input signal in the event of the monitoring circuit being closed and the monitoring current being measured and with a second input signal in the event of the monitoring circuit being interrupted, and wherein the fail-safe control units (9a, 9b, 9c) are configured in such a way that, upon receiving the first input signal, they each generate a swich-on signal that effects closing of the safety switching element (10a, 10b, 10c) connected to the respective fail-safe control unit (9a, 9b, 9c), and, upon receiving the second input signal, they each generate the shutdown signal that effects opening of the safety switching element (10a, 10b, 10c) connected to the respective fail-safe control unit (9a, 9b, 9c).
2. Safety circuit (1) according to Claim 1, characterized in that each of the measuring apparatuses (6a, 6b, 6c) comprises at least one resistor (60) and an evaluation unit (61) connected thereto that is designed in such a way that it is able to determine a voltage drop across the at least one resistor (60) and is able to generate the first or second input signal depending on the magnitude of the voltage drop.
3. Safety circuit (1) according to either of Claims 1 and 2, characterized in that the current flow changing apparatuses (7a, ..., 7n) are in the form of switching apparatuses that are designed to selectively close or interrupt the monitoring circuit.
4. Safety circuit (1) according to one of Claims 1 to 3, characterized in that the current flow changing apparatuses (7a, ..., 7n) are in the form of transistors, in particular field-effect transistors, or relays.
5. Safety circuit (1) according to one of Claims 1 to 4, characterized in that a first safety switching device (2a) of the safety circuit (1) has a constant current source that is configured to generate a constant current.
6. Safety circuit (1) according to one of Claims 2 to 5, characterized in that each of the safety switching devices (2a, ..., 2n) has at least one storage means (12a, 12b, 12c) that is connected to the evaluation unit (61) of the measuring apparatus (6) of the relevant safety switching device (2a, 2b, 2c), wherein a first reference voltage value (Uref,1) of a reference voltage upstream of the resistor (60) and a second reference voltage value (Uref,2) of a reference voltage downstream of the electrical resistor (60) are stored in the storage means (12a, 12b, 12c) so as to be able to be retrieved.
7. Safety circuit (1) according to one of Claims 1 to 6, characterized in that a first safety switching device (2a) of the safety circuit (1) has a constant voltage source (11) that is designed to provide a constant voltage.
8. Safety circuit (1) according to Claim 7, characterized in that the first safety switching device (2a) of the safety circuit (1) has a voltage pulse generator (14) that is connected to the constant voltage source (11) and is configured to generate defined voltage pulses, in particular 0 V voltage pulses, and in that each of the safety switching devices (2a, 2b, 2c) comprises a voltage pulse evaluation means (13a, 13b, 13c) that is configured to capture and evaluate the voltage pulses.
9. Safety circuit (1) according to one of Claims 1 to 8, characterized in that each of the safety switching devices (2a, ..., 2n) comprises a number of current flow changing apparatuses (7a, ..., 7n) connected in series.