CONTROL DEVICE
Patent Information
- Application Number
- DE502019014262
- Authority / Receiving Office
- DE · DE
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2019-08-16
- Publication Date
- 2026-01-22
- Estimated Expiration
- 2039-08-16
Description
[0001] The invention relates to an arrangement with a control device and a control system.
[0002] Such systems typically form safety systems used in the field of machine safety.
[0003] Such a safety system generally includes a control system that controls a machine, whereby the term "machine" also encompasses equipment and the like. The machine can pose a danger to people within a hazardous area.
[0004] As a safety measure, this danger zone is monitored, with the machine having a safety controller as a control system for controlling and monitoring safety-relevant functions.
[0005] For example, the machine's danger zone is secured with a protective cover or fence. This fence contains a safety door or flap. Monitoring ensures that a person can only enter the danger zone through the safety door if the machine poses no danger.
[0006] As a further safety element, an access control system connected to the control system, i.e., the safety controller, can be provided, by means of which controlled access to safety-relevant areas, in particular hazardous areas, is monitored. Such an access control system can, for example, consist of an electronic key system. This electronic key system comprises a key insert and at least one key assigned to it.
[0007] The data from the access control system must be evaluated in the security controller. This requires appropriate programming of the security controller.
[0008] Such safety systems still allow for several operating modes. Depending on the operating mode, the machine can be operated differently and / or the monitoring function of the safety system can be configured differently.
[0009] One problem with such security systems is that, due to legal regulations, switching the operating mode must be restricted to authorized personnel. Furthermore, the switching process requires a level of security that cannot be achieved with just any conventional system, but necessitates the use of specialized security technology.
[0010] In known safety systems, the safety controller is therefore integrated into the operating mode selection. This also requires corresponding programming of the safety controller for the operating mode selection.
[0011] Such programming of a safety controller is generally very complex and costly.
[0012] Typical safety controllers, especially for NC machines, have limited memory and do not allow for such complex programming. Furthermore, a safety-critical, i.e., error-checked, program must be created, which then requires extensive testing and validation.
[0013] German patent DE 101 52 349 A1 relates to a security device that enables controlled access to restricted security areas by authorized persons in a simple manner. For this purpose, the security device is equipped with a bus system that connects a central control unit to several actuators, each assigned to at least one of the security areas. Access authorization is verified and controlled using a personal identification device.
[0014] EP 1 288 870 A2 relates to a control device for means of transport or access control, as well as a system for the security screening of persons / goods or for the transport of persons / goods. At least one response signal is issued by at least one identification transmitter. This response signal is received by at least one recognition device and recognized by the recognition device using a recognition protocol. For each recognized response signal, the recognition device issues a control signal according to a control protocol. The control device reads control signals according to at least two different control protocols. The control device recognizes these control signals and issues at least one secondary control signal for each recognized control signal.
[0015] EP 0 539 763 A2 relates to a control system used for access control, with the aim of allowing only authorized persons access to specific buildings or rooms. The control system includes data carriers (transponders) worn by the individuals concerned and brought into close proximity to a reader so that the data on the carrier can be wirelessly transmitted for reading. The reader forwards the received authorization data to a central evaluation unit, where this authorization data is verified. If the authorization data matches the verification data, the evaluation unit releases a door, allowing the authorized person to enter a room.
[0016] US 2008 / 0218330 A1 concerns a Power-Over-Ethernet controller and an access control system.
[0017] German patent DE 103 60 789 A1 relates to an optical sensor for monitoring a detection area on a piece of work equipment. The sensor has a redundant, dual-channel evaluation unit.
[0018] The invention is based on the objective of granting access rights and operating modes for systems, in particular security systems, in the safest, simplest and most flexible way possible.
[0019] The features of claim 1 are provided to solve this problem. Advantageous embodiments and expedient further developments of the invention are described in the dependent claims.
[0020] The invention relates to an arrangement comprising a control device and a safety controller for the operation of a machine, wherein the control device includes an evaluation unit and at least one acquisition unit connected to the evaluation unit. The at least one acquisition unit is part of an access control system. The acquisition unit is a reading unit designed to read signals from a transponder. Depending on the input parameters entered into the acquisition unit, the evaluation unit selects the operating mode and assigns access authorization. The resulting output parameters are sent to the safety controller via an output stage of the control device. At least one input / output unit is connected to the evaluation unit.The access control system connected to the evaluation unit of the control device is integrated into the operating mode selection process. This access control system is a physical access control system that regulates and monitors access to hazardous areas on machines and equipment. Depending on input parameters from the access control system, the evaluation unit is granted authorization to select an operating mode. A user can then enter the desired operating mode at the input / output unit. The operating mode entered by a user at the input / output unit is checked for validity in the evaluation unit. This check uses an authorization for operating mode selection entered via the reading unit and activated in the evaluation unit. The verified operating mode is read back from the evaluation unit to the input / output unit, where the user confirms the entered operating mode, thus ensuring a secure operating mode selection.
[0021] The basic idea of the invention is that the control device forms an independent unit separate from the control system, with which, on the one hand, the function of an access control system and / or, on the other hand, the function of an operating mode selection system is realized.
[0022] Since, according to the invention, these functionalities are outsourced from the system's control unit, no provisions or expenditures are required in the control unit for these functionalities. In particular, complex programming of the control unit to implement such functionalities is eliminated. Instead, a selected operating mode or even granted access authorizations can be fed to the control unit as output variables as results of the evaluation in the control device, where they can be used directly and without further evaluation.
[0023] According to the invention, the system is a safety system that is controlled by a safety controller.
[0024] In this case, the time-consuming creation of error-checked and validated programs is eliminated, since the necessary software for granting access rights and / or selecting operating modes is completely integrated into the control device.
[0025] To meet the security requirements, i.e. to ensure a fail-safe access control system and a fail-safe operating mode selection, the evaluation unit of the control device has a fail-safe, in particular redundant, design, which is advantageously achieved by the evaluation unit having a two-channel design.
[0026] Furthermore, the output stage is designed as a safe output stage, via which a safe signal output is sent to a safety controller that controls a safety system.
[0027] In the simplest case, the safe output stage consists of a number of digital outputs.
[0028] A secure output stage is particularly advantageous when it forms a secure bidirectional interface. A secure bus system is especially suitable for this secure output stage.
[0029] Examples of such safe bus systems are Profisafe, IO-Link Safety or CIP-Safety.
[0030] According to the invention, at least one detection unit is provided, which is part of an access system.
[0031] The term access system encompasses physical access systems that regulate and control access to hazardous areas on machines and equipment. Furthermore, the term access system also includes systems that control access to secure, particularly safety-relevant, data sets such as process or access data, access authorizations, and the like.
[0032] According to the invention, the or each detection unit forming an access system is a reading unit which is designed to read signals from a transponder.
[0033] The reading unit, which forms the data capture unit, and its associated transponders constitute an electronic key system. Generally, in such an electronic key system, multiple transponders can be assigned to a single reading unit, each containing different data.
[0034] The transponders contain stored data fields, which are preferably secured with checksums. When a transponder is within the reading range of the reader unit, the data fields are read into the reader unit as input values and checked for validity. If valid input values are found, an access authorization is granted in the evaluation unit.
[0035] In particular, it is possible to define different authorization levels. For example, different data fields can be stored in the individual transponders, defining different authorization levels. Depending on the authorization level, the evaluation unit grants access corresponding to that level.
[0036] A user with a low authorization level can only access a hazardous area via a safety door if the equipment located there is shut down. In contrast, a user with a high authorization level can access the equipment even when it is running, for example, to perform maintenance work.
[0037] It is advantageous for each or every recording unit to be connected to the evaluation unit via a wired or contactless interface.
[0038] For example, these interfaces can be designed as RS485, WLAN, Ethernet, Bluetooth or CAN bus interfaces.
[0039] A key advantage of these interfaces is that the position of the respective acquisition unit is largely independent of the evaluation unit of the control device, thus allowing for flexible adaptation to different applications.
[0040] This makes it particularly advantageous to implement complex applications in which several access system-forming acquisition units are connected to the evaluation unit of the control device.
[0041] The individual access systems, especially electronic key systems, can be used, for example, for access control at security doors that provide access to hazardous areas. Unlike conventional security devices, the evaluation of signals from the individual detection units can be performed in a central evaluation unit of the control device, resulting in a significant efficiency gain.
[0042] The access systems can be spatially distributed. It is also possible to use different access systems. For example, various reading units of electronic key systems can be used, operating at different frequencies.
[0043] Furthermore, acquisition units for reading various physical signals are possible using a wide range of technologies. These can be used in parallel.
[0044] According to the invention, at least one input / output unit is connected to the evaluation unit.
[0045] The input / output unit can be, for example, a PC or a touch panel.
[0046] The input / output unit is used by a user to input a desired operating mode of the security system.
[0047] The entered operating mode is checked for validity in the evaluation unit of the control device and read back to the input / output unit, where the user confirms the entered operating mode. The evaluation unit of the control device thus ensures reliable operating mode selection, especially if it has a fail-safe, redundant design.
[0048] According to the invention, an access system connected to the evaluation unit of the control device is included in the operating mode selection, in which, depending on input variables of the access system, an authorization to select an operating mode is activated in the evaluation unit, whereupon a user can then enter the desired operating mode at the input / output unit.
[0049] The operating mode, as tested and approved in the control device, is output as a variable via the output stage to the control system, in particular the safe output stage to the safety control system, so that the control system or safety control system can then immediately commence operation in the selected operating mode.
[0050] The functionality of the control device can be extended to include one or more acquisition units designed for data transfer.
[0051] For example, electronic key systems can be used to transfer data.
[0052] For example, user data, configurations, process data, or backup data can be read into the evaluation unit of the control device. In particular, so-called blacklists or whitelists can be loaded into the evaluation unit, with blacklists containing blocked user accounts and whitelists containing authorized user accounts.
[0053] Finally, it is possible to load firmware into the evaluation unit via data transfer in order to implement application-specific evaluation.
[0054] According to an advantageous further development, the evaluation unit has at least one interface for connecting additional components.
[0055] Such additional components can include operating elements, limit switches, warning lights, and the like. Because these additional components no longer need to be connected to the control system, the latter can be further relieved of its load.
[0056] The invention will be explained below with reference to the drawings. The drawings show: Figure 1: Schematic representation of a safety system for hazardous area protection. Figure 2: Exemplary embodiment of the control device for the safety system according to the invention. Figure 1 .
[0057] Figure 1 Figure 1 schematically shows a safety system 1 for the safe operation of a machine 2. The machine 2 can pose hazards, particularly to people. Accordingly, a danger zone 3 around the machine 2 is secured by a fence 4. The fence 4 contains two safety gates 5 through which people can access the danger zone 3.
[0058] A safety controller 6, which controls the operation of machine 2, is an essential component of safety system 1. Safety switches are typically included as further components of safety system 1; these monitor whether the safety doors 5 are closed or not. The safety controller 6 controls the operation of machine 2, in particular based on the signals generated by the safety switches.
[0059] Figure 2 shows an embodiment of the control device 7 according to the invention, which is used for the safety system 1 according to Figure 1 can be used.
[0060] The control device 7 forms a unit independent of the safety control 6 of the safety system 1.
[0061] The control device 7 can be connected to the safety controller 6 via a safe output stage 8. In this case, the safe output stage 8 has a number of digital outputs 8a and an output circuit 8b for controlling the digital outputs 8a. The output circuit 8b is a one-out-of-n circuit, which ensures that only one digital output 8a is active at any given time, through which safe output signals can be sent to the safety controller 6.
[0062] Alternatively, the safe output stage 8 can also be provided by a safe bus system. Examples of this are Profisafe, IO-Link Safety, or CIP Safety.
[0063] The safe output signals are generated in an evaluation unit 9 of the control device 7. The safe output stage 8 is connected to the evaluation unit 9 for this purpose.
[0064] In this case, the evaluation unit 9 of the control device 7 has a fail-safe, redundant design. The evaluation unit 9 comprises two computer units 10a and 10b, each of which can be a single processor. The computer units 10a and 10b of the evaluation unit 9 are connected via data lines 11, enabling bidirectional data exchange between them, particularly for mutual monitoring.
[0065] In principle, the control device 7 can also have a single-channel evaluation unit 9. The control device 7 has a predetermined number of acquisition units 17a, 17b connected to the evaluation unit 9.
[0066] In the present case, the acquisition units 17a, 17b and the reading units 12a, 12b are provided, which are components of an access system in the form of an electronic key system. The two reading units 12a, 12b typically consist of a CPU and an antenna. Several transponders (not shown) are assigned to each reading unit 12a, 12b to form an electronic key system.
[0067] In the present case, each of the electronic key systems forms an access system for one of the protective doors 5 of the security system 1 according to Figure 1 .
[0068] The electronic key system can also be configured as an access system for a safety door 5. Each transponder can, for example, contain authentication codes that define under which conditions the safety doors 5 may be opened with the respective transponder, thus granting a person access to the danger zone 3.
[0069] The reading units 12a, 12b can also be used for data transfer, in particular to transfer user data, configurations, backup data, process data or firmware to the evaluation unit 9.
[0070] Each reading unit 12a, 12b is connected to the evaluation unit 9 via an interface 13. In this case, the interfaces 13 are designed as RS485 interfaces. Generally, wired or contactless interfaces 13 are possible. These are designed so that the reading units 12a, 12b can be arranged spatially separate from the evaluation unit 9. This allows the security system 1 to be monitored from a central evaluation unit 9. Figure 1 Each reading unit 12a, 12b shall be arranged in the area of one of the protective doors 5.
[0071] Reading units 12a and 12b can be identical or different. Generally, more than two reading units can be connected to evaluation unit 9.
[0072] In the two-channel version of the evaluation unit 9, as Figure 2 shows that the RS485 interface is connected to one of the computer units 10a of the evaluation unit 9.
[0073] In general, other interfaces are also possible, such as WLAN, Ethernet, Bluetooth or CAN bus.
[0074] In evaluation unit 9, the transponder signals acquired by reading units 12a and 12b are evaluated, and access authorizations are checked and granted during this evaluation. The resulting secure output signals in evaluation unit 9 are fed to the safety controller 6 via the secure output stage 8.
[0075] Furthermore, an input / output unit, in this case a PC 14 (personal computer), is connected to the evaluation unit 9. The connection is made via a communication interface 15, which can be an RS485, USB, Profinet interface, or the like. In general, the control device 7 can have several different communication interfaces 15.
[0076] In general, the control device 7 can also have interfaces 13 for connecting additional components such as operating elements, limit switches, warning lights and the like.
[0077] The PC 14 has, in the usual manner, input / output devices 16 such as keyboards, displays and the like.
[0078] The input / output unit, i.e., the PC 14, is used in this case for selecting the operating mode. To do this, a user first enters authentication data into the input / output unit, which in the simplest case can be a password. Entering biometric data is also possible.
[0079] The user then enters the desired operating mode into the input / output unit, which is then checked for validity in evaluation unit 9. In particular, authorization for an operating mode selection, entered via a read unit 12a or 12b and activated in evaluation unit 9, can also be used for this purpose. The checked operating mode is then read back from evaluation unit 9 to the input / output unit, where the user verifies whether the operating mode selection was correct.
[0080] In this way, a fail-safe operating mode selection is carried out entirely in the control device 7. The selected operating mode is then output to the safety controller 6 via the safe output stage 8. Reference symbol list
[0081] (1) Safety system (2) Machine (3) Danger area (4) Enclosure (5) Safety door (6) Safety control (7) Control device (8) Output stage (8a) Digital output (8b) Output circuitry (9) Evaluation unit (10a, 10b) Computer unit (11) Data line (12a, 12b) Read unit (13) Interface (14) PC (15) Communication interface (16) Input / output device (17a, 17b) Acquisition unit
Claims
1. Arrangement with a control device (7) and a safety control (6) controlling the operation of a machine, characterised in that the control device has an evaluation unit (9) and at least one detection unit (17a, 17b) connected to the evaluation unit (9), that said at least one detection unit (17a, 17b) is part of an access system, and that the detection unit (17a, 17b) is a reading unit (12a, 12b) designed to read signals from a transponder, whereby, depending on the input variables entered into the detection unit (17a, 17b), an operating mode selection is performed in the evaluation unit (9) and an access authorisation is assigned, and output variables generated thereby are output via an output stage (8) of the control device (7) to the security control (6), that at least one input / output unit is connected to the evaluation unit (9), and that the access system connected to the evaluation unit (9) of the control device (7) is included in the operating mode selection, wherein the access system is a physical access system that regulates and controls access to hazardous areas on machines and systems, in which, depending on input variables of the access system in the evaluation unit (9), whereupon a user can then enter the desired operating mode at the input / output unit, wherein an operating mode entered by a user into the input / output unit is checked for validity in the evaluation unit (9), wherein for this purpose an authorisation for an operating mode selection entered via the reading unit (12a, 12b) and activated in the evaluation unit (9) is used for this purpose, and wherein the checked operating mode is read back from the evaluation unit (9) into the input / output unit, where the user acknowledges the entered operating mode, thereby ensuring a secure operating mode selection.
2. Arrangement according to claim 1, characterised in that the evaluation unit (9) has a two-channel structure, wherein the evaluation unit has two computer units which are connected via data lines, via which a bidirectional data exchange between the computer units takes place, thereby enabling mutual monitoring of the computer units.
3. Arrangement according to one of claims 1 or 2, characterised in that the or each detection unit (17a, 17b) is connected to the evaluation unit (9) via a wired or contactless interface (13).
4. Arrangement according to one of claims 1 to 3, characterised in that several detection units (17a, 17b) are provided, which form different and / or spatially separated access systems.
5. Arrangement according to one of claims 1 to 4, characterised in that authentication data can be entered into the evaluation unit (9) via the input / output unit.
6. Arrangement according to one of claims 1 to 5, characterised in that an operating mode checked and approved in the evaluation unit (9) is output to the safety control (6) via the output stage (8).
7. Arrangement according to one of claims 1 to 6, characterised in that the one or more detection units (17a, 17b) are designed for data transfer.
8. Arrangement according to one of claims 1 to 7, characterised in that the evaluation unit (9) has at least one interface (13) for connecting additional components.